# Atlantic.Net - Full Content > The entire site as markdown for AI ingestion. Use allowed with attribution to Atlantic.Net. See /ai-policy/. # Atlantic.Net Internet Now Available in Jacksonville > URL: https://www.atlantic.net/press-releases/atlantic-net-blog-atlantic-net-internet-now-available-jacksonville/ | Published: 1997-07-01 | Updated: 2024-06-03 | Author: Editorial Team GAINESVILLE (July 1, 1997) — Internet Connect Company (ICC), one of the fastest-growing Internet service [providers](https://www.atlantic.net/hosting-services-provider/) in Florida, is increasing its coverage area to include local access in Jacksonville, Orange Park, and Fernandina effective immediately. The First Coast has always been high on ICC’s target list of potential markets, and recent strategic moves by the company have made it possible to open in Jacksonville sooner than expected. “We are happy to be able to make an impact on the Jacksonville market at this early stage in our growth cycle,” says ICC sales manager James Lamb, “Our reputation for quality and exceptional service should allow us to do very well here.” ICC’s Atlantic.Net service has a flat monthly fee of $19.95. Standard accounts feature unlimited access to the World Wide Web, electronic mail, newsgroups, and Internet Relay Chat (IRC). All subscribers also receive space for a personal or commercial home page and shell access at no additional charge. ICC’s online service is compatible with the Windows 3.1, Windows 95, Macintosh, and UNIX operating systems. Customers in the Jacksonville area will pay no activation fees and be the first to receive ICC’s new start-up software package, based on the Microsoft Internet Explorer client. ICC also offers a variety of high-speed [dedicated](https://www.atlantic.net/dedicated-server-hosting/) Internet solutions such as frame relay and ISDN, as well as Web hosting services for businesses. Internet Connect Company’s [Atlantic.Net](https://www.atlantic.net/) service is available throughout much of Florida. Anyone who would like more information can call the customer service department at 1-866-618-3282, or visit ICC’s web page at [https://www.atlantic.net](https://www.atlantic.net/). --- # Internet Connect Company Cans “SPAM” > URL: https://www.atlantic.net/press-releases/internet-connect-company-cans-spam/ | Published: 1997-10-02 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE FLA. (October 2, 1997) – Internet Connect Company (ICC), one of Florida’s fastest-growing Internet services, has already developed a reputation for protecting its customers against unwanted commercial e-mail, or SPAM. But last night they had a hand in protecting much of the Internet community as well against this menace. When someone attempted to host one of the biggest SPAM clearinghouses on ICC’s servers without permission, ICC technicians quickly stepped in and pulled the plug on the entire operation. This move effectively saved millions of people, at least temporarily, from waking up this morning with electronic inboxes overflowing with unwanted mail. SPAM is the Internet equivalent of junk mail, and it is a much bigger problem than many people think. It is also a serious breach of the Internet protocol, or “netiquette”, that most conscientious Internet service providers and users follow. SPAM costs consumers money by tying up their costly online time and hard drive space, and the [servers](https://www.atlantic.net/dedicated-server-hosting/) and routers that make up the backbone of the global Internet are frequently bogged down trying to process the millions of unsolicited messages that are sent every day. This huge volume of traffic results in bottlenecks at various points throughout the world’s networks, slowing down access speeds for everyone. “We have a strict policy against using our facilities for mass e-mail,” says ICC network engineer Chris Wilson, “So anytime someone tries to circumvent that policy we come in immediately and put a stop to it. It’s just that in this case, the violator was one of the largest bulk e-mail distributors in the country. “It’s a small victory in the war against SPAM,” Wilson continued, “But we’re happy to do our part and join the growing number of Internet service providers taking a stand against it.” ### About Internet Connect Co. Gainesville, FL-based Internet Connect Company,[https://www.atlantic.net.](https://www.atlantic.net) a recognized leader in the highly competitive Internet access field, offers service in 15 locations throughout Florida. The company is committed to providing the highest possible level of service at a reasonable cost to all of its customers. ICC also offers a variety of high-speed [dedicated](https://www.atlantic.net/dedicated-server-hosting/) Internet solutions and Web hosting services for businesses. To learn more about ICC’s complete line of service offerings, call (866) 618-3282 or visit ICC’s web page at [https://www.atlantic.net.](https://www.atlantic.net) --- # Internet Connect Company Buys Worldwide Internet > URL: https://www.atlantic.net/press-releases/internet-connect-company-buys-worldwide-internet/ | Published: 1997-11-11 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla. (November 11, 1997) – Internet Connect Company (ICC), one of the fastest-growing Internet service providers in Florida, is announcing the purchase of Worldwide Internet Services of Melbourne. This is the company’s third acquisition this year, involving more than 400 net new subscribers to ICC’s service. The terms of the deal were not disclosed. “We’re looking forward to the opportunity to serve these new customers,” says ICC sales executive James Lamb, “I think everyone will be quite pleased by what we have to offer.” ICC has made plans to make the transition process for current Worldwide Internet customers as simple as possible. All Worldwide Internet customers are being contacted via e-mail with instructions on how to access ICC’s[Atlantic.Net](https://www.atlantic.net)service, and users may call the ICC customer support department directly at (866)618-3282 with any questions. All activation fees will be waived for Worldwide Internet subscribers and software will be provided to those who would like it. All new customers should be switched over by mid-November. New subscribers will receive access to ICC’s standard account features, as well as seven-day-a-week [technical assistance](https://www.atlantic.net/support/) and toll-free support. ICC’s Atlantic.Net service is $19.95 per month and includes unlimited access to the World Wide Web, electronic mail, newsgroups, and chat rooms. All accounts also receive space for a commercial or personal Internet home page at no extra cost. The service is compatible with the Windows 3.1, Windows 95, Macintosh, and UNIX operating systems. “This is a critical time in our company’s growth cycle,” says ICC President/CEO Manoj (Marty) Puranik, “Maneuvers such as this allow us to establish ourselves in emerging markets and offer higher levels of service to existing consumer and business subscribers.” ### About Internet Connect Co. Gainesville, FL-based Internet Connect Company,[https://www.atlantic.net.](https://www.atlantic.net) a recognized leader in the highly competitive Internet access field, offers service in 15 cities throughout Florida. The company is committed to providing the highest possible level of service at a reasonable cost to all of its customers. ICC also offers a variety of high-speed dedicated Internet solutions and [Web hosting](https://www.atlantic.net/vps-hosting/) services for businesses. To learn more about ICC’s complete line of service offerings, call (866) 618-3282 or visit ICC’s web page at [https://www.atlantic.net.](https://www.atlantic.net) --- # Internet Connect Company Hosts WRRX’s Web Site > URL: https://www.atlantic.net/press-releases/internet-connect-company-hosts-wrrxs-web-site/ | Published: 1997-11-24 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla. (November 24, 1997)– Internet Connect Company, Inc. (ICC) is pleased to announce an agreement with WRRX-97.7 FM to host the radio station’s Internet Web site. WRRX offers Gainesville and Ocala listeners the most diverse radio format in the area, playing a wide variety of music and offering exclusive local coverage of the NFL’s Tampa Bay Buccaneers and the NBA’s Orlando Magic. ICC Sales director James Lamb said [Web hosting](https://www.atlantic.net/vps-hosting/) provides communications companies with the opportunity to broaden their exposure. WRRX joins ICC’s other media clients like the Gainesville Sun, the Florida Times-Union, the Independent Florida Alligator, and WYKS-Kiss 105. “The Internet is becoming increasingly important in today’s business world,” Lamb said. “Companies with the foresight to keep up with emerging technologies will be better prepared for the future.” WRRX station manager John Starr agrees that the Internet is a good marketing tool and can help WRRX get an edge on the competition. “We believe our Web page reaches a good portion of our listeners,” Starr said. “We cater to a sophisticated audience, and that’s the type of people using the Internet. The station’s Web site, located at http://www.wrrx97x.com, offers Web surfers the opportunity to sign up to receive a newsletter through their e-mail, chat online about sports, and link to information on local and national bands. Special online promotions are being planned to encourage listeners to visit the site. Starr said the station is still trying to find new ways to expand its Internet presence. The station is looking into the possibility of providing live broadcasts over the Internet using RealAudio technology. Switching the site to ICC’s network has ensured that the station will receive fast connections and good service, Starr said. ### About Internet Connect Co. Gainesville, FL-based Internet Connect Company, [Atlantic.Net](https://www.atlantic.net/) a recognized leader in the highly competitive Internet access field, offers service in 15 cities throughout Florida. ICC offers a variety of high-speed dedicated Internet solutions and Web hosting services for businesses. To learn more about ICC’s complete line of service offerings, call (866)618-3282 or visit ICC’s Web page at [https://www.atlantic.net.](https://www.atlantic.net) --- # Atlantic.Net Internet Service Upgraded to 56K in Leesburg > URL: https://www.atlantic.net/press-releases/atlantic-net-internet-service-upgraded-56k-leesburg/ | Published: 1998-06-22 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE (June 22, 1998) — [Atlantic.Net](https://www.atlantic.net/): Internet Connect Company, Inc., one of Florida’s most popular Internet [service providers](https://www.atlantic.net/hosting-services-provider/), is pleased to announce that 56K Internet access is now available to subscribers in both the Leesburg and Mount Dora calling areas. The Atlantic.Net Internet service is available for the first time in Mount Dora, Eustis, and Tavares. Users with 56K-compatible modems will be able to access Web pages and use other Internet utilities at nearly twice the speed of a standard 28.8Kbps modem, at no additional cost. “People in smaller communities like Leesburg and Mount Dora will benefit from the 56K technology the most, ” says Atlantic.Net president and CEO Marty Puranik, “Because the digital modems overcome many of the technical deficiencies found in rural phones lines, which normally result in slow connection speeds and unexplained disconnects for Internet users.” Customers already using 56K modems will see an immediate improvement in connection speeds, others will notice more reliable connections due to the clarity of the digital signal. And because it is a digital service, customers may also use dial-up 64Kbps ISDN terminal adapters to access the Internet at higher speeds for the same monthly fee. Dial-up 128Kbps ISDN access is also available for an additional charge. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over its first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long-distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL, and ISDN access, Web hosting, Web design, and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and has been recognized both Nationally and in Florida as one of the fastest-growing private companies. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/). --- # Atlantic.Net Upgrades Central Florida Coverage Area to 56K > URL: https://www.atlantic.net/press-releases/atlantic-net-internet-service-upgrades-central-florida-coverage-area-56k/ | Published: 1998-07-01 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE (July 1, 1998) — [Atlantic.Net](https://www.atlantic.net/): Internet Connect Company, Inc., one of Florida’s most popular Internet service providers, is pleased to announce that 56K Internet access is now available throughout the Orlando metro area, including Kissimmee, Lake Buena Vista, and Sanford. Atlantic.Net is one of the few Internet providers to offer local access in Kissimmee and Sanford. Prior to this upgrade, many Internet users have had to incur toll charges to Orlando in order to use an online service. With this announcement, all of Central Florida is now included in the local calling area. Users with 56K-compatible modems will be able to access Web pages and use other Internet utilities at nearly twice the speed of a standard 28.8Kbps modem, at no additional cost. “People in these communities will see an immediate benefit from the 56K technology,” says Atlantic.Net president and CEO Marty Puranik, “Digital modems overcome many of the technical deficiencies found in traditional analog phones lines, which could result in slow connection speeds and unexplained disconnects for Internet users— regardless of the provider they used.” Customers already using 56K modems will see an immediate improvement in connection speeds, others will notice more reliable connections due to the clarity of the digital signal. Because it is a digital service, customers may also use dial-up 64Kbps ISDN terminal adapters to access the Internet at higher speeds for the same monthly fee. Dial-up 128Kbps ISDN access is also available for an additional charge. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over its first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long-distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL, and ISDN access, Web hosting, Web design, and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and has been recognized both Nationally and in Florida as one of the fastest-growing private companies. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/). --- # Atlantic.Net 56K Internet Service Now Available in Starke, FL > URL: https://www.atlantic.net/press-releases/atlantic-net-56k-internet-service-now-available-starke/ | Published: 1998-07-07 | Updated: 2024-03-01 | Author: Editorial Team GAINESVILLE (July 7, 1998) — [Atlantic.Net](https://www.atlantic.net/): Internet Connect Company, Inc., one of Florida’s most popular Internet service providers, is pleased to announce that its 56K Internet access is now available in Starke and the surrounding communities. Atlantic.Net is one of the only Internet providers to offer access in the local Starke calling area. Prior to this announcement, many Internet users have had to incur toll charges to Gainesville in order to use an online service. All of Bradford County is now included in the Atlantic.Net calling area. Users with 56K-compatible modems will be able to access [Web pages](https://www.atlantic.net/hipaa-compliant-hosting/how-to-make-website-hipaa-compliant/) and use other Internet utilities at nearly twice the speed of a standard 28.8Kbps modem. “People in these communities will see an immediate benefit using our 56K access,” says Atlantic.Net president and CEO Marty Puranik, “Digital modems overcome many of the technical deficiencies found in traditional analog phones lines, which could result in slow connection speeds and unexplained disconnects for Internet users— regardless of the provider they used.” Atlantic.Net subscribers using 56K modems will get fast, reliable Internet connections thanks to the clarity of the signal in the digital modems. Because it is a digital service, customers may also use dial-up 64Kbps ISDN terminal adapters to access the Internet at higher speeds for the same monthly fee. Dial-up 128Kbps ISDN access is also available for an additional charge. Dial-up 56K Internet accounts start at just $9.95 per month; including access to the World Wide Web, electronic mail, discussion groups, and other easy-to-use features. The Atlantic.Net software startup kit, featuring Microsoft’s Internet Explorer Web browser, is available for the Windows and Macintosh operating systems. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over its first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long-distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL, and ISDN access, Web hosting, Web design, and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and has been recognized both Nationally and in Florida as one of the fastest-growing private companies. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/). --- # Atlantic.Net Launches 56K Internet Service on Space Coast > URL: https://www.atlantic.net/press-releases/atlantic-net-launches-56k-internet-service-space-coast/ | Published: 1998-07-22 | Updated: 2024-03-01 | Author: Editorial Team GAINESVILLE (July 22, 1998) — Atlantic.Net: Internet Connect Company, one of Florida’s most popular Internet service providers, is pleased to announce that its 56K Internet access is now available in Melbourne, Palm Bay, and Titusville local calling areas. [Atlantic.Net](https://www.atlantic.net/) members with 56Kbps modems will be able to access Web pages and use other Internet utilities at nearly twice the speed of a standard 28.8Kbps modem, with no additional cost. Current subscribers should call the Member Services Department at 1-866-618-3282 for the new 56K access number. All customers have been sent an e-mail message containing details of the change and instructions on how to begin using the 56K service. “People in these communities will see an immediate benefit when using our 56K access,” says Atlantic.Net president and CEO Marty Puranik, “Digital modems overcome many of the technical deficiencies found in traditional analog phones lines, which could result in slow connection speeds and unexplained disconnects for Internet users— regardless of the provider they used.” Atlantic.Net members using 56K-capable modems will get fast, reliable Internet connections thanks to the clarity of the signal in the digital modems. Because it is a digital service, customers may also use dial-up 64Kbps ISDN terminal adapters to access the Internet at higher speeds for the same monthly fee. Dial-up 128Kbps ISDN access is also available for an additional charge. Dial-up 56K Internet accounts start at just $9.95 per month; including access to the World Wide Web, electronic mail, discussion groups, and other easy-to-use features. The Atlantic.Net software startup kit, featuring Microsoft’s Internet Explorer Web browser, is available for the Windows and Macintosh operating systems. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over its first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long-distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL, and ISDN access, [Web hosting](https://www.atlantic.net/vps-hosting/), Web design, and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and has been recognized both Nationally and in Florida as one of the fastest-growing private companies. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/). --- # Atlantic.Net Launches 56K Internet Service in Ocala > URL: https://www.atlantic.net/press-releases/atlantic-net-launches-56k-internet-service-ocala/ | Published: 1998-08-14 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE (August 14, 1998) — [Atlantic.Net](https://www.atlantic.net/): Internet Connect Company, one of Florida’s most popular Internet [service providers](https://www.atlantic.net/hosting-services-provider/), is pleased to announce that 56K Internet access is now available to subscribers in the Ocala local calling area. Atlantic.Net members with 56Kbps modems will be able to access Web pages and use other Internet utilities at nearly twice the speed of a standard 28.8Kbps modem, with no additional cost. Current subscribers should call the Member Services Department at 1-866-618-3282 for the new 56K access number. All customers have been sent an e-mail message containing details of the change and instructions on how to begin using the 56K service. “People in Ocala will see an immediate benefit when using our 56K access,” says Atlantic.Net president and CEO Marty Puranik, “Because digital modems overcome many of the technical deficiencies found in traditional analog phones lines. These could result in slow connection speeds and unexplained disconnects for Internet users— regardless of the provider they used.” Atlantic.Net members using 56K-capable modems will get fast, reliable Internet connections thanks to the clarity of the signal in the digital modems. Because it is a digital service, customers may also use dial-up 64Kbps ISDN terminal adapters to access the Internet at higher speeds for the same monthly fee. Dial-up 128Kbps ISDN access is also available for an additional charge. Dial-up 56K Internet accounts start at just $9.95 per month; including access to the World Wide Web, electronic mail, discussion groups, and other easy-to-use features. The Atlantic.Net software startup kit, featuring Microsoft’s Internet Explorer Web browser, is available for the Windows and Macintosh operating systems. ### About Atlantic.Net: Internet Connect Co. Gainesville, FL-based [Atlantic.Net](https://www.atlantic.net/) is a leader in the highly competitive Internet access industry committed to providing the highest possible level of service at a reasonable cost to all of its customers. Atlantic.Net operates in 25 cities throughout Florida, including Gainesville, Lake City, and Leesburg. In addition to over 10,000 dial-up subscribers, Atlantic.Net offers a variety of high-speed dedicated access solutions and Web hosting services for businesses. To learn more about Atlantic.Net’s complete line of services, call 1-866-618-3282 or visit the corporate Web site at https://www.atlantic.net. --- # Atlantic.Net is among the 100 fastest growing companies in Florida > URL: https://www.atlantic.net/press-releases/atlantic-net-recognized-top-100-private-florida-company/ | Published: 1998-08-25 | Updated: 2024-03-04 | Author: Editorial Team GAINESVILLE (August 25, 1998) — [Atlantic.Net,](https://www.atlantic.net/) one of Florida’s most popular Internet service providers, is pleased to announce that it has been recognized as one of the Florida 100, a compilation of high-growth privately held companies in the state of Florida. The list is compiled by the University of Florida’s Center for Entrepreneurship and Innovation (CEI), and Accounting Research and Professional Education (CARPE), in the College of Business Administration. The annual project identifies the 100 fastest-growing private companies in Florida. Recipients must meet four strict requirements to be eligible: be an independent, privately held corporation or proprietorship, but not a subsidiary or division; show a three-year sales history with an increase in fiscal 1997; has sales of more than $100,000 but less than $25 million in fiscal 1995, and be headquartered in the state of Florida. For more information on the Florida 100, please visit http://www.cba.ufl.edu/florida100 on the University of Florida Web site. President Manoj “Marty” Puranik attributes Atlantic.Net’s success to proven technological innovation, dedicated employees, and a commitment to customer satisfaction. “We’re very proud of this designation,” Puranik said, “It affirms our belief that it is possible to succeed in this industry while offering premium levels of service at a reasonable cost to our customers.” Atlantic.Net representatives will attend a business conference and awards banquet to be held in December to honor the recipients. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over its first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long-distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL, and ISDN access, Web hosting, Web design, and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and has been recognized both Nationally and in Florida as one of the fastest-growing private companies. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/). --- # Atlantic.Net Acquires Citrus County Internet Service Provider > URL: https://www.atlantic.net/press-releases/atlantic-net-acquires-citrus-county-internet-service-provider/ | Published: 1998-09-29 | Updated: 2024-03-04 | Author: Editorial Team GAINESVILLE (September 29, 1998) — [Atlantic.Net:](https://www.atlantic.net/) Internet Connect Company is pleased to announce that they have purchased the dial-up subscriber base of Citrus County’s Citrus.Net Internet service. Effective immediately, former Citrus.Net customers will be able to take advantage of all of Atlantic.Net’s features, including 56Kbps Web browsing and e-mail service. Subscribers will also have access to the Atlantic.Net software startup kit, featuring Netscape Communicator, is available for Windows and Macintosh operating systems. All previous Citrus.Net subscribers should call 1-866-618-3282 as soon as possible for instructions on how to begin using Atlantic.Net’s 56K Internet service. To make the transition as seamless as possible, Atlantic.Net will honor all service agreements customers may have had with Citrus.Net. Atlantic.Net members using 56Kbps-capable modems will get fast, reliable Internet connections due to the clarity of the signal in the digital modems. Because it is a digital service, customers may also use dial-up 64Kbps ISDN terminal adapters to access the Internet at higher speeds for the same monthly fee. Dial-up 128Kbps ISDN access is also available for an additional charge. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over its first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long-distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL, and ISDN access, Web hosting, Web design, and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and has been recognized both Nationally and in Florida as one of the fastest-growing private companies. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/). --- # Atlantic.Net Launches 56K Internet Service in Jacksonville > URL: https://www.atlantic.net/press-releases/atlantic-net-launches-56k-internet-service-jacksonville/ | Published: 1998-10-16 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE (October 16, 1998) — [Atlantic.Net:](https://www.atlantic.net/) Internet Connect Company, one of Florida’s most popular Internet service providers, is pleased to announce that 56K Internet access is now available to subscribers in Jacksonville local calling area. Atlantic.Net members with 56Kbps modems will be able to access Web pages and use other Internet utilities at nearly twice the speed of a standard 28.8Kbps modem, with no additional cost. Current subscribers should call the Member Services Department at 1-866-618-3282 for the new 56K access number. All customers have been sent an e-mail message containing details of the change and instructions on how to begin using the 56K service. “People in Jacksonville will see an immediate benefit when using our 56K access,” says Atlantic.Net president and CEO Marty Puranik, “Because digital modems overcome many of the technical deficiencies found in traditional analog phones lines. These could result in slow connection speeds and unexplained disconnects for Internet users— regardless of the provider they used.” Atlantic.Net members using 56K-capable modems will get fast, reliable Internet connections thanks to the clarity of the signal in the digital modems. Because it is a digital service, customers may also use dial-up 64Kbps ISDN terminal adapters to access the Internet at higher speeds for the same monthly fee. Dial-up 128Kbps ISDN access is also available for an additional charge. Dial-up 56K Internet accounts start at just $9.95 per month; including access to the World Wide Web, electronic mail, discussion groups, and other easy-to-use features. The Atlantic.Net software startup kit, featuring Microsoft’s Internet Explorer Web browser, is available for the Windows and Macintosh operating systems. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over its first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long-distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL, and ISDN access, Web hosting, Web design, and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and has been recognized both Nationally and in Florida as one of the fastest-growing private companies. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/). --- # Atlantic.Net Acquires North Florida Internet Service Provider > URL: https://www.atlantic.net/press-releases/atlantic-net-acquires-north-florida-internet-service-provider/ | Published: 1998-10-19 | Updated: 2024-03-01 | Author: Editorial Team GAINESVILLE (October 19, 1998) — [Atlantic.Net](https://www.atlantic.net/): Internet Connect Company is pleased to announce that they have purchased the dial-up subscriber base of Hankins Internet Services, which operated in Lake City and the Live Oak areas of North Florida. Effective immediately, former Hankins customers will be able to take advantage of all of Atlantic.Net’s features, including 56Kbps Web browsing and e-mail service. Technical support is available seven days a week and subscribers will have access to the Atlantic.Net [software](https://www.atlantic.net/hipaa-compliant-hosting/top-10-server-monitoring-software-solutions/) startup kit, featuring Netscape Communicator, which is available for Windows and Macintosh operating systems. Hankins subscribers will not need to make any immediate network changes in their computers. However, Atlantic.Net recommends that all subscribers begin notifying friends and family of the impending change in their e-mail addresses, which will take effect in two months. Anyone with questions regarding this change should call the Atlantic.Net Member Services department at 1-866-618-3282 or send an e-mail to service@atlantic.net. Atlantic.Net members using 56Kbps-capable modems will get fast, reliable Internet connections due to the clarity of the signal in the digital modems. Because it is a digital service, customers may also use dial-up 64Kbps ISDN terminal adapters to access the Internet at higher speeds for the same monthly fee. Dial-up 128Kbps ISDN access is also available for an additional charge. This is Atlantic.Net’s second acquisition in the Lake City area. The first involved First Coast On-line and was completed in 1997. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over its first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long-distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL, and ISDN access, Web hosting, Web design, and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and has been recognized both Nationally and in Florida as one of the fastest-growing private companies. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/). --- # Atlantic.Net 56K Internet Service Now Available in Crescent City > URL: https://www.atlantic.net/press-releases/atlantic-net-56k-internet-service-now-available-crescent-city/ | Published: 1998-12-02 | Updated: 2024-03-04 | Author: Editorial Team GAINESVILLE (December 2, 1998) — [Atlantic.Net](https://www.atlantic.net/): Internet Connect Company, one of Florida’s most popular Internet service providers, is pleased to announce that its 56K Internet access is now available to subscribers in the Crescent City local calling area. Atlantic.Net is known for its fast, reliable access and friendly customer service representatives. The company maintains a user-to-modem ratio of 10:1 to help ensure that subscribers can log into the network without the inconvenience of busy signals. Dial-up 56K Internet accounts start at just $9.95 per month; including access to the World Wide Web, electronic mail, discussion groups, and other easy-to-use features. The Atlantic.Net software startup kit, featuring the latest version of Netscape Communicator, is available for the Windows and Macintosh operating systems. Helpful customer service representatives are available seven days a week to answer questions about the service or to solve technical problems. “We’re excited to be launching our service in Crescent City,” says Atlantic.Net president and CEO Marty Puranik, “We know Internet users here will appreciate our fast access and easy-to-use [software](https://www.atlantic.net/hipaa-compliant-hosting/top-10-network-monitoring-software-solutions/).” Anyone who would like more information or would like to receive a copy of Atlantic.Net’s free Internet Starter Kit should call 1-866-618-3282. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over its first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long-distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL, and ISDN access, Web hosting, Web design, and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and has been recognized both Nationally and in Florida as one of the fastest-growing private companies. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/). --- # Atlantic.Net CEO Honored at Entrepreneur of the Year Banquet > URL: https://www.atlantic.net/press-releases/atlantic-net-ceo-honored-entrepreneur-year-award-banquet/ | Published: 1999-06-28 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla. (6/28/99) — Manoj “Marty” Puranik, president and CEO of Gainesville-based [Atlantic.Net](https://www.atlantic.net/), was one of 27 Florida entrepreneurs honored last night at the Ernst & Young Entrepreneur of the Year®awards. The event recognized the achievements of Florida entrepreneurs who have demonstrated extraordinary success in their businesses and communities. Puranik, one of the founders of Atlantic.Net, was a finalist in the Young Entrepreneur category. This is the first year Puranik has been nominated for the award. While he did not win, being among the top three was another milestone in what has been a busy year for Atlantic.Net, Florida’s largest privately held Internet service provider. Under Puranik’s leadership, Atlantic.Net has launched service in five new cities and acquired three smaller Internet access companies since January. Last week, the company opened a new office in Ft. Lauderdale and launched a new Web design division, Atlantic.Net Studios. On Wednesday, the company announced the expansion of its Internet access and [Web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) services to the South Florida market. “The event last night was great and I was honored to be a part of it,” said Puranik. “I’d like to thank my employees for all their hard work and dedication to our company, and Ernst & Young for the recognition.” Atlantic.Net is one of the top 100 fastest-growing private companies in Florida. Revenues have doubled every year since the company was founded. Atlantic.Net’s subscriber base has grown to 22,000 members, and 60 employees have been added to the staff in less than three years. Since 1996, Puranik and his management team have made nine acquisitions and launched services in more than 30 cities. By the end of 1999, Atlantic.Net’s network is expected to span nine states in the southeastern United States. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over its first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long-distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL, and ISDN access, Web hosting, Web design, and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and has been recognized both Nationally and in Florida as one of the fastest-growing private companies. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/dedicated-server-hosting/). --- # Atlantic.Net Nominated for 1999 Florida 100 > URL: https://www.atlantic.net/press-releases/atlantic-net-nominated-1999-florida-100/ | Published: 1999-06-29 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla. (6/29/99) — Gainesville-based Atlantic.Net, Florida’s largest privately held Internet service provider, is pleased to announce that for the second year in a row it has been nominated for the Florida 100, the 100 fastest-growing private companies in the state of Florida. Atlantic.Net was number 79 in the 1998 Florida 100, with an 88% increase in sales from 1995-1997. This year the company expects to be much closer to the top of the list. The Florida 100 is an annual program organized by the University of Florida’s Warrington College of Business Administration and Fisher School of Accounting to identify and honor Florida’s one hundred highest growth firms. Recipients must meet four strict requirements to be eligible: be an independent, privately held corporation or proprietorship, but not a subsidiary or division; show a three-year sales history with an increase over the three year period; have sales of more than $100,000 but less than $25 million in fiscal 1996, and be located in the state of Florida. Atlantic.Net has more than 22,000 subscribers in 34 locations across Florida. Between 1996 and 1998 the company added 50 employees, launched service in 21 cities, and purchased the dial-up Internet subscribers, dedicated access accounts, and Web hosting clients of six [Internet access companies](https://www.atlantic.net/) across the state. In the past six months, Atlantic.Net has established a new Web development division, Atlantic.Net Studios, launched service in five new cities, opened an office in South Florida, and acquired three more Internet access providers. By the end of 1999, Atlantic.Net’s network is expected to span nine states in the southeastern United States. ### About Atlantic.Net [Atlantic.Net](https://www.atlantic.net/)is a leader in the highly competitive Internet access industry. Members get fast, reliable Internet connections and access to toll-free technical support seven days a week, starting at $9.95 per month. 56K access is standard with all accounts, but the service is also compatible with 14.4Kbps, 28.8/33.6Kbps modems as well as 64Kbps ISDN terminal adapters. 128Kbps ISDN is available for an additional monthly fee. Atlantic.Net also offers Web design services, high-speed dedicated access, and [Web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) services for businesses. Atlantic.Net Studios offers. To learn more about Atlantic.Net’s complete line of services, call 1-866-618-3282 or visit the corporate Web site at https://www.atlantic.net. --- # Atlantic.Net Introduces New Feature to Internet Access Service > URL: https://www.atlantic.net/press-releases/atlantic-net-introduces-new-feature-internet-access-service/ | Published: 1999-07-08 | Updated: 2024-03-01 | Author: Editorial Team Gainesville, Fla (7/8/99) – [Atlantic.Net](https://www.atlantic.net/vps-hosting/), one of Florida’s fastest-growing companies, today announced it has added a new feature to its Internet access service — free virtual domain names for customers with personal Web pages. The new feature gives members a place to store their personal pages on Atlantic.Net’s server and assigns a virtual domain name that is easy to remember: http://username.members.atlantic.net. “Personal Web pages are a fast-growing Internet application,” said Brian Bess, marketing director for Atlantic.Net. “First, they are easier to create than ever before. Secondly, more and more people are recognizing the benefits of being able to post information in one place where it can be seen by family, friends, and clients anywhere in the world. Our service makes it easy for people to create a Web page, store that Web page and find that Web page.” Atlantic.Net’s software kit includes Netscape Composer, part of the Netscape Communicator Internet application utility. Composer provides step-by-step instructions on how to create a Web page and publish it on the Internet. Atlantic.Net’s online technical support also includes information on setting up a personal Web page and provides links to subjects such as Web page design and transferring HTML files. The company provides each member with five megabytes of server space to store Web pages as part of its $19.95 Unlimited Account offering. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over it’s first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting , Web design and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net offers the very best in [cloud hosting](https://www.atlantic.net/vps-hosting/) solutions, one click WordPress cloud hosting, [Linux and Windows Cloud hosting](https://www.atlantic.net/vps-hosting/), and many other services. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # Atlantic.Net Offers 56K Internet in New Smyrna Beach/Edgewater > URL: https://www.atlantic.net/press-releases/atlantic-net-launches-56k-internet-service-new-smyrna-beachedgewater/ | Published: 1999-07-13 | Updated: 2024-03-04 | Author: Editorial Team Atlantic.Net Launches 56K Internet Service in New Smyrna Beach/Edgewater; Provides Fastest Connection in Area GAINESVILLE, Fla (7/13/99)- [Atlantic.Net](https://www.atlantic.net/), one of Florida’s fastest-growing companies, is pleased to announce that its 56K Internet access is now available in the New Smyrna/Edgewater calling area. This new service feature makes Atlantic.Net the fastest Internet connection available to residents and businesses in and around New Smyrna and Edgewater. “Atlantic.Net is focused on providing its customers with the features they want and the technical support they need at a competitive price,” said Marty Puranik, president and CEO of Atlantic.Net. “We are proud to be the first company to make 56K access available to Internet users in New Smyrna and Edgewater and proud to show our continued commitment to Atlantic.Net members in every part of Florida.” Atlantic.Net members get fast, reliable Internet connections and access to toll-free technical support seven days a week. Atlantic.Net dial-up 56K Internet accounts start at just $9.95 per month and include access to the World Wide Web, electronic mail, discussion groups, and other easy-to-use features. Customers with ISDN service may access the Internet at 64Kbps for the same monthly fee. Dial-up 128Kbps ISDN access is available at an additional charge. The Atlantic.Net software startup kit, featuring the latest version of Netscape Communicator, is available for the Windows and Macintosh operating systems. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over its first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long-distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL, and ISDN access, Web hosting, Web design, and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and has been recognized both Nationally and in Florida as one of the fastest-growing private companies. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # Atlantic.Net CEO Named to Board of Directors Florida ISP Association > URL: https://www.atlantic.net/press-releases/atlantic-net-ceo-named-board-directors-florida-isp-association/ | Published: 1999-07-16 | Updated: 2026-03-02 | Author: Editorial Team Gainesville, Fla. (7/16/99) – Marty Puranik, president and CEO of [Atlantic.Net](https://www.atlantic.net/vps-hosting/), one of Florida’s fastest-growing companies, has been named to the Board of Directors of the Florida Internet Service Providers Association (FISPA). Current FISPA activities include working with other organizations to lobby the Federal Communications Commission and local regulatory bodies for open and fair access to cable systems. Puranik welcomed the recent ruling by the Broward County Board of Commissioners to open its cable network. “The Broward County Board of Commissioners made the right decision,” said Puranik. “Open access will give consumers a choice, allow ISPs such as Atlantic.Net to remain competitive and provide cable companies with a much quicker return on their investment in infrastructure. The decision will have nothing but a positive effect on Broward County’s economy.” In his new role, Puranik will work with executives from 11 other Internet companies statewide to implement quality standards and practices for Internet related businesses in Florida, the mission of FISPA. Made up of 67 Internet companies, the association was instrumental in helping thwart state municipalities’ efforts to impose Internet taxes in 1996. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over it’s first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting , Web design and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net offers industry leading [Cloud hosting](https://www.atlantic.net/vps-hosting/),[one-click WordPress Cloud Hosting](https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/), and many other services. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # Atlantic.Net Enters Five New Markets in Florida > URL: https://www.atlantic.net/press-releases/atlantic-net-enters-five-new-markets-florida/ | Published: 1999-07-20 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla. (7/20/99) – Atlantic.Net, one of Florida’s fastest growing companies, has expanded its Internet service into five additional calling areas. Atlantic.Net’s 56K access is now available in Tallahassee, Ft Myers, Vero Beach, Palm Coast and Deland. With these additions, Atlantic.Net now has a presence in 40 locations throughout the state. “We’re right on track,” said Marty Puranik, president and CEO of Atlantic.Net. “The launch of five new service territories makes our statewide coverage almost complete. We are proud to provide so many Florida communities with reliable and friendly Internet service and we are excited to be growing so quickly.” [Atlantic.Net](https://www.atlantic.net)dial-up accounts start at $9.95 per month; including access to the World Wide Web, electronic mail, discussion groups and other features. The Atlantic.Net software startup kit, [featuring Netscape Communicator](https://www.atlantic.net/dedicated-server-hosting/), is available for the Microsoft Windows and Apple Macintosh operating systems. 56K access is standard with all accounts, but the service is also compatible with older 14.4Kbps, 28.8/33.6Kbps modems as well as 64Kbps ISDN terminal adapters. 128Kbps ISDN is available for an additional monthly fee. Atlantic.Net’s business services include high-speed dedicated access, Web hosting and Web development and design. [Atlantic.Net](https://www.atlantic.net) was founded in 1994 by two University of Florida students, Marty Puranik and Jose Sanchez. After being denied Internet access through the university in 1995, Puranik and Sanchez launched one of the first commercial Internet services in Florida, serving Gainesville and Ocala. Since then, the company has been rapidly expanding its coverage areas, acquiring smaller access providers and enhancing its service offerings. Revenues have doubled every year since inception and in 1998 Atlantic.Net was recognized as one of Florida’s 100 fastest-growing private companies by UF’s Center for Entrepreneurship and Innovation. During the past six months, the company has launched service in 11 new cities and purchased the dial-up Internet subscribers, dedicated access accounts and Web hosting clients of three Internet access companies. By the end of 1999, Atlantic.Net’s network is expected to span nine states in the southeastern United States. To learn more about Atlantic.Net’s complete line of services, call 1-866-618-3282 or visit the corporate Web site at https://www.atlantic.net. --- # Atlantic.Net Becomes CLEC Certified > URL: https://www.atlantic.net/press-releases/atlantic-net-becomes-clec-certified/ | Published: 1999-07-28 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla. (7/28/99) — Atlantic.Net, one of Florida’s fastest-growing companies, announced today that it has been certified by the Florida Public Service Commission as a competitive local exchange carrier (CLEC). CLEC certification gives Atlantic.Net Broadband Inc., a wholly-owned subsidiary of Atlantic.Net, statewide authority to provide [local exchange telecommunication services](https://www.atlantic.net/managed-services/). [Atlantic.Net](https://www.atlantic.net)Broadband, Inc. plans to use its CLEC status to bundle voice and data services and to work with incumbent local exchange carriers to co-locate high speed DSL Internet switches throughout Florida. “The combination of bundled services and increased competition in the telecommunications industry should continue to lower telecomm costs, and we’re happy to be part of the action,” said Marty Puranik, president and CEO of Atlantic.Net. “The Florida Public Service Commission’s recognition of our technical, financial, and managerial capabilities allows us to take our business to the next level. Instead of serving solely as an Internet provider, we can now serve as a Telecommunications provider and everyone stands to benefit.” ### About Atlantic.Net [Atlantic.Net](https://www.atlantic.net) was founded in 1994 by two University of Florida students, Marty Puranik and Jose Sanchez. After being denied Internet access through the university in 1995, Puranik and Sanchez launched one of the first commercial Internet services in Florida, serving Gainesville and Ocala. Since then, the company has been rapidly expanding its coverage areas, acquiring smaller access providers and enhancing its service offerings. Revenues have doubled every year and in 1998 Atlantic.Net was recognized as one of Florida’s 100 fastest-growing private companies by UF’s Center for Entrepreneurship and Innovation. Atlantic.Net now has 22,000 subscribers in 40 locations throughout Florida. By the end of 1999, Atlantic.Net’s network is expected to span nine states in the southeastern United States. To learn more about Atlantic.Net’s complete line of services, call 1-866-618-3282 or visit the corporate Web site at https://www.atlantic.net. For company information, check out http://newsroom.atlantic.net. --- # Atlantic.Net Introduces WebMail > URL: https://www.atlantic.net/press-releases/atlantic-net-introduces-webmail/ | Published: 1999-08-02 | Updated: 2026-03-02 | Author: Editorial Team Gainesville, Fla. (8/2/99) – Atlantic.Net, one of Florida’s fastest-growing companies, today announced it has added a new feature to its Internet access service – Web Mail. The new feature allows members to access and manage their Atlantic.Net e-mail accounts using any Internet-connected computer anywhere in the world. To access e-mail from anywhere, members simply enter their user name and password at Atlantic.Net’s new [WebMail Web site](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/), http://webmail.atlantic.net. “With this new feature, Atlantic.Net has taken a big step toward establishing a national presence,” said Brian Bess, marketing director for Atlantic.Net. “Our members now have a free, secure connection to their Atlantic.Net e-mail no matter where they are or how they are connected to the Internet. This is great news for our subscribers.” Atlantic.Net members get fast, reliable Internet connections and access to toll-free technical support seven days a week, starting at $9.95 per month. 56K access is standard with all accounts, but the service is also compatible with 14.4Kbps, 28.8/33.6Kbps modems as well as 64Kbps ISDN terminal adapters. 128Kbps ISDN is available for an additional monthly fee. Atlantic.Net also offers high-speed dedicated access, [Web hosting and Web design services](https://www.atlantic.net/vps-hosting/) for businesses. To learn more about Atlantic.Net’s complete line of services, call 1-866-618-3282 or visit the corporate Web site at https://www.atlantic.net ### About Atlantic.Net [Atlantic.Net](https://www.atlantic.net) was founded in 1994 by two University of Florida students, Marty Puranik and Jose Sanchez, who started the company by selling computers. After being denied Internet access through the university in 1995, Puranik and Sanchez launched one of the first commercial Internet services in Florida, serving Gainesville and Ocala. Since then, the company has been rapidly expanding its coverage areas, acquiring smaller access providers and enhancing its service offerings. The company now has 22,000 subscribers in 40 locations statewide. For more company information, check out http://newsroom.atlantic.net. --- # Atlantic.Net is 15th Fastest-Growing Private Company in Florida > URL: https://www.atlantic.net/press-releases/atlantic-net-named-15th-fastest-growing-private-company-florida/ | Published: 1999-09-01 | Updated: 2023-12-05 | Author: Editorial Team [Atlantic.Net](https://www.atlantic.net/vps-hosting/)Named 15th Fastest-Growing Private Company in Florida; Revenues Increase 328% from 1996 to 1998 GAINESVILLE, Fla. (9/1/99) — Gainesville-based Atlantic.Net, one of Florida’s leading Internet Service providers, is pleased to announce that for the second year in a row it has been named one of Florida’s 100 fastest-growing private companies. Atlantic.Net is number 15, jumping from number 79 in the 1998 listing, with a 328% increase in revenues from 1996 to 1998. The Florida 100 is an annual program organized by the University of Florida’s Warrington College of Business Administration and Fisher School of Accounting to identify and honor Florida’s one hundred highest growth firms. Recipients must meet four strict requirements to be eligible: be an independent, privately held corporation or proprietorship, but not a subsidiary or division; show a three-year sales history with an increase over the three year period; have sales of more than $100,000 but less than $25 million in fiscal1996; and be located in the state of Florida. ## About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over it’s first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting , Web design and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net has state of the art fast [SSD Fast Cloud servers](https://www.atlantic.net/vps-hosting/)offering the very best in [cloud hosting](https://www.atlantic.net/vps-hosting/) solutions, one click WordPress cloud hosting and many other services. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/cloud-platform/). --- # Atlantic.Net Introduces New Service: Webcare Solutions > URL: https://www.atlantic.net/press-releases/atlantic-net-introduces-new-service-webcare-solutions/ | Published: 1999-09-21 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla. (9/21/99) – [Atlantic.Net,](https://www.atlantic.net) one of Florida’s leading Internet Service Providers, today introduced Webcare Solutions, a new service for day care facilities that enables parents to see their children from any Internet-connected computer any time of the day. “Many parents are simply unable to drop by a child care center during the day,” said Jim Lamb, sales director at Atlantic.Net in Ft. Lauderdale. “Thanks to the Internet, we are now able to offer a service that allows parents to see their kids anytime they want without having to leave the office.” As part of the Webcare Solutions package, Atlantic.Net installs and maintains a Web server and Web cameras at the day care facility, provides the facility with 24 hour dedicated Internet access to Atlantic.Net’s multi-homed network and develops and designs a [password-protected Web site](https://www.atlantic.net/managed-services/). Parents can then log on to the day care facility’s Web site at any time of the day to observe their children participating in daily activities from the angle of the Web cameras. ### About Atlantic.Net [Atlantic.Net](https://www.atlantic.net), recently named Florida’s 15th fastest-growing private company, was founded in 1994 by two former University of Florida students. The company, previously known as Internet Connect Company, launched one of the first commercial Internet services in Florida in 1995. Today, Atlantic.Net has 22,000 subscribers in 50 cities across Florida, Mississippi and Louisiana. Dial-up accounts start at $9.95 per month; including access to the World Wide Web, electronic mail, discussion groups and other features. The Atlantic.Net software startup kit, featuring Netscape Communicator, is available for the Microsoft Windows and Apple Macintosh operating systems. 56K access is standard with all accounts, but the service is also compatible with older 14.4Kbps, 28.8/33.6Kbps modems as well as 64Kbps ISDN terminal adapters. 128Kbps ISDN is available for an additional monthly fee. Atlantic.Net’s business services include high-speed dedicated access, Web hosting and Web development and design. To learn more about Atlantic.Net’s complete line of services, call 1-866-618-3282 or visit the corporate Web site at https://www.atlantic.net. --- # Atlantic.Net Opens New Call Center, Adds Jobs > URL: https://www.atlantic.net/press-releases/atlantic-net-opens-new-call-center-adds-jobs/ | Published: 2000-03-24 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla. (3/24/00) – Atlantic.Net, one of the Southeast’s most reliable Internet Service Providers, today announced the opening of its new and expanded Member Services call center. The expansion, which comes in response to the company’s rapidly growing subscriber base, includes hiring 30 additional Member Services representatives in the Gainesville headquarters over the next year. The Member Services department handles all customer service and technical support calls from Atlantic.Net subscribers. “[Exceeding customer expectations](https://www.atlantic.net/about-us/high-touch-approach/) is our primary concern,” said Brian Bess, director of marketing at Atlantic.Net, “and we do that by maintaining service levels as we grow.” The new Member Services call center is 2800 square feet and can accommodate 50 Member Services representatives. Atlantic.Net’s previous center was 600 square feet and could accommodate 17 representatives. By the end of April, Atlantic.Net expects to be offering customer service and technical support to Atlantic.Net members 24 hours a day, 7 days a week. With “24/7″ customer service, Atlantic.Net will be joining an elite group among the 7,000 Internet Service Providers nationwide. ### About Atlantic.Net [Atlantic.Net](https://www.atlantic.net/)was founded in 1994 by two University of Florida students, Marty Puranik and Jose Sanchez, who started the company by selling computers. After being denied Internet access through the university in 1995, Puranik and Sanchez launched one of the first commercial Internet services in Gainesville and Ocala, Florida. Today, Atlantic.Net offers service in 46 locations across the state, more than any other ISP. The company has 40,000 subscribers in five states. Revenues have doubled every year since inception and in 1999 Atlantic.Net was recognized as Florida’s 15th fastest-growing private company. To learn more about [Atlantic.Net’s](https://www.atlantic.net/) complete line of services, call 1-866-618-3282 or visit the corporate Web site at https://www.atlantic.net. --- # Atlantic.Net Begins Offering 24/7 Customer Service > URL: https://www.atlantic.net/press-releases/atlantic-net-begins-offering-247-customer-service/ | Published: 2000-04-17 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla. (4/17/00) – Atlantic.Net, one of the Southeast’s most reliable Internet service providers, today begins offering customer service and technical support to Atlantic.Net members 24 hours a day, 7 days a week. Atlantic.Net joins a select group among the 7,000 providers nationwide with “24/7″ customer service. “We’re happy to be able to offer our members this service,” said Brian Bess, marketing director at Atlantic.Net. “Providing 24/7 customer support reinforces our commitment to our members and our goal of offering [pure and complete Internet access](https://www.atlantic.net/vps-hosting/).” Last month Atlantic.Net opened a new 2800-square-foot customer service call center that can accommodate 50 customer service representatives. The company’s old facility was 600 square feet and had capacity for 17 representatives. The company expects to hire at least 30 additional customer service representatives in the Gainesville headquarters over the next year to accommodate its rapidly growing subscriber base. [Atlantic.Net’s](https://www.atlantic.net/) $19.95 Unlimited Account service plan includes access to the World Wide Web, electronic and Web mail, discussion groups, toll free technical support 7 days a week, a monthly electronic newsletter, personal Web space with virtual domain name and convenient payment options. The company also has a Basic Account service plan for $9.95 per month. The Atlantic.Net software startup kit, featuring Netscape Communicator, is available for the Microsoft Windows and Apple Macintosh operating systems. 56K access is standard with all accounts, but the service is also compatible with older 14.4Kbps, 28.8/33.6Kbps modems as well as 64Kbps ISDN terminal adapters. 128Kbps ISDN is available for an additional monthly fee. Atlantic.Net’s business services include high-speed dedicated access, Web hosting and Web development and design. To learn more about Atlantic.Net’s complete line of services, call 1-866-618-3282 or visit the corporate Web site at https://www.atlantic.net. ### About Atlantic.Net Atlantic.Net was founded in 1994 by two University of Florida students, Marty Puranik and Jose Sanchez, who started the company by selling computers. After being denied Internet access through the university in 1995, Puranik and Sanchez launched one of the first commercial Internet services in Gainesville and Ocala, Florida. Today, Atlantic.Net offers service in 46 locations across the state, more than any other ISP. The company has 40,000 subscribers in five states. Revenues have doubled every year since inception and in 1999 Atlantic.Net was recognized as Florida’s 15th fastest-growing private company. --- # Atlantic.Net Launches Service in Eight Cities > URL: https://www.atlantic.net/press-releases/atlantic-net-launches-service-eight-cities/ | Published: 2000-06-06 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla. (6/6/00) – Atlantic.Net[,](https://www.atlantic.net/)Florida’s 15th fastest-growing private company, today announced service launches in Boca Raton, Belle Glade, Key Largo, Islamorada, Marathon and Key West, Florida, and Valdosta and Lake Park, Georgia. Local access numbers are available to Atlantic.Net subscribers in all new locations. Recognized for its direct, reliable and uncluttered Internet access, Atlantic.Net’s $19.95 [Unlimited Account service plan](https://www.atlantic.net/vps-hosting/) includes access to the World Wide Web, electronic mail, discussion groups, a monthly electronic newsletter, personal Web space with virtual domain name, convenient payment options and toll-free technical support 24 hours a day, 7 days a week. The company also has a Basic Account service plan for $9.95 per month. The Atlantic.Net software startup kit, featuring Netscape Communicator, is available for the Microsoft Windows and Apple Macintosh operating systems. 56K access is standard with all accounts, but the service is also compatible with older 14.4Kbps, 28.8/33.6Kbps modems as well as 64Kbps ISDN terminal adapters. 128Kbps ISDN is available for an additional monthly fee. Atlantic.Net’s business services include high-speed dedicated access, Web hosting and Web development and design. ### About Atlantic.Net [Atlantic.Net](https://www.atlantic.net/) was founded in 1994 by two University of Florida students, Marty Puranik and Jose Sanchez, who started the company by selling computers. After being denied Internet access through the university in 1995, Puranik and Sanchez launched one of the first commercial Internet services in Gainesville and Ocala, Florida. Today, Atlantic.Net offers service in 49 locations across the state, more than any other ISP. The company has 40,000 subscribers in five states. Revenues have doubled every year since inception and in 1999 Atlantic.Net was recognized as Florida’s 15th fastest-growing private company. To learn more about Atlantic.Net’s complete line of services, call 1-866-618-3282 or visit the corporate Web site at [https://www.atlantic.net](https://www.atlantic.net/). --- # Atlantic.Net Launches Service in North Carolina > URL: https://www.atlantic.net/press-releases/atlantic-net-launches-service-north-carolina/ | Published: 2000-06-21 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla. (6/21/00) – [Atlantic.Net,](https://www.atlantic.net/) Florida’s 15th fastest-growing private company, today announced it has launched service in Charlotte and Concord, North Carolina. This completes the second phase of the company’s nine state network expansion. Recognized for its direct, reliable and uncluttered Internet access, Atlantic.Net’s $19.95 [Unlimited Account service plan](https://www.atlantic.net/vps-hosting/) includes access to the World Wide Web, electronic mail, discussion groups, a monthly electronic newsletter, personal Web space with virtual domain name, convenient payment options and toll-free technical support 24 hours a day, 7 days a week. The company also has a Basic Account service plan for $9.95 per month. The Atlantic.Net software startup kit, featuring Netscape Communicator, is available for the Microsoft Windows and Apple Macintosh operating systems. 56K access is standard with all accounts, but the service is also compatible with older 14.4Kbps, 28.8/33.6Kbps modems as well as 64Kbps ISDN terminal adapters. 128Kbps ISDN is available for an additional monthly fee. Atlantic.Net’s business services include high-speed dedicated access, Web hosting and Web development and design. ### About Atlantic.Net [Atlantic.Net](https://www.atlantic.net/) was founded in 1994 by two University of Florida students, Marty Puranik and Jose Sanchez, who started the company by selling computers. After being denied Internet access through the university in 1995, Puranik and Sanchez launched one of the first commercial Internet services in Gainesville and Ocala, Florida. Today, Atlantic.Net offers service in 49 locations across Florida, more than any other ISP. The company has 40,000 subscribers throughout the southeastern United States. Revenues have doubled every year since inception and in 1999 Atlantic.Net was recognized as Florida’s 15th fastest-growing private company. To learn more about Atlantic.Net’s complete line of services, call 1-866-618-3282 or visit the corporate Web site at [https://www.atlantic.net](https://www.atlantic.net/). --- # Atlantic.Net Launches Service in Atlanta and Charlotte > URL: https://www.atlantic.net/press-releases/atlantic-net-launches-service-atlanta-charlotte/ | Published: 2000-06-29 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla (6/29/00) – Atlantic.Net, one of the Southeast’s fastest-growing Internet Providers, today announced it has launched its e-business services and 56K and ISDN consumer services in Atlanta and Charlotte. Atlantic.Net’s e-business services include designing, installing and managing customized wide area networks, fractional T-1 through DS-3 connectivity, DSL and ISDN access and Web hosting. Managed dial-up services are also available to other Internet service providers. [Atlantic.Net’s](https://www.atlantic.net/) consumer dial-up services run on a Cisco Powered Network. Cisco is the worldwide leader in networking for the Internet. All Atlantic.Net consumer accounts include access to the World Wide Web, electronic mail and toll-free technical support 24 hours a day, 7 days a week. The company owns and operates its entire network and is known for its direct, reliable and uncluttered Internet access. Atlantic.Net was founded in 1994 by two University of Florida students, Marty Puranik and Jose Sanchez, who started the company by selling computers. After being denied Internet access through the university in 1995, Puranik and Sanchez launched one of the first commercial Internet services in Gainesville and Ocala, Florida. Today, Atlantic.Net serves over 40,000 subscribers in 70 locations throughout the Southeastern United States. Revenues have doubled every year since inception and in 1999 Atlantic.Net was recognized as Florida’s 15th fastest-growing private company. The company is one of the rare Internet access service providers that can claim to be profitable. To learn more about Atlantic.Net’s complete line of services, call 1-866-618-3282 or visit the corporate Web site at https://www.atlantic.net. --- # Atlantic.Net Adds Free E-Mail Accounts > URL: https://www.atlantic.net/press-releases/atlantic-net-adds-free-e-mail-accounts/ | Published: 2000-07-13 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla. (7/13/00) – [Atlantic.Net,](https://www.atlantic.net/) one of the Southeast’s fastest-growing Internet Providers, today announced it has added a feature to its service that allows subscribers up to six different e-mail addresses on one account. This enhancement is free to subscribers on Atlantic.Net’s $19.95 Unlimited Access Plan. [Atlantic.Net](https://www.atlantic.net/)subscribers can add up to five additional e-mail accounts by going to http://controlpanel.atlantic.net and logging in with their primary Atlantic.Net username and password. For step-by-step instructions, subscribers can visit http://controlpanel.atlantic.net/multimailhelp.html. Atlantic.Net’s consumer dial-up services run on a Cisco Powered Network. Cisco is the worldwide leader in networking for the Internet. All Atlantic.Net consumer accounts include access to the World Wide Web, electronic mail and toll-free technical support 24 hours a day, 7 days a week. The company owns and operates its entire network and is known for its direct, reliable and uncluttered Internet access. Atlantic.Net’s e-business services include designing, installing and managing customized wide area networks, fractional T-1 through DS-3 connectivity, DSL and ISDN access and Web hosting. Managed dial-up services are also available to other Internet service providers. ### About Atlantic.Net Atlantic.Net was founded in 1994 by two University of Florida students, Marty Puranik and Jose Sanchez, who started the company by selling computers. After being denied Internet access through the university in 1995, Puranik and Sanchez launched one of the first commercial Internet services in Gainesville and Ocala, Florida. Today, Atlantic.Net serves over 40,000 subscribers in 70 locations throughout the Southeastern United States. Revenues have doubled every year since inception and in 1999 Atlantic.Net was recognized as Florida’s 15th fastest-growing private company. The company is one of the rare Internet access service providers that can claim to be profitable. To learn more about Atlantic.Net’s complete line of services, call 1-866-618-3282 or visit the corporate Web site at https://www.atlantic.net. --- # Atlantic.Net Acquires South Carolina Internet Provider > URL: https://www.atlantic.net/press-releases/atlantic-net-acquires-south-carolina-internet-provider/ | Published: 2000-07-25 | Updated: 2026-03-01 | Author: Editorial Team GAINESVILLE, Fla. (7/25/00) – [Atlantic.Net](https://www.atlantic.net/), one of the Southeast’s most reliable Internet service providers, today announced it has completed the purchase of Aiken, S.C.-based Duesouth/SCescape. With this agreement, Atlantic.Net acquires Duesouth’s dedicated access accounts, Web hosting clients and dial-up subscribers in Columbia and Aiken, South Carolina, and Augusta, Georgia. In addition, Atlantic.Net has retained two of Duesouth’s employees who will run the Aiken office. Specific terms of the deal are not being disclosed. This is Atlantic.Net’s first acquisition outside Florida and fourth in the past 12 months. [Atlantic.Net](https://www.atlantic.net/)owns and operates its entire network, which spans more than 70 cities across the Southeastern United States. E-business services include designing, installing and managing customized wide area networks, fractional T-1 through DS-3 connectivity, DSL and ISDN access and Web hosting. Managed dial-up services are also available to other Internet service providers. A[tlantic.Net’s](https://www.atlantic.net/) consumer dial-up services run on a Cisco Powered Network. Cisco is the worldwide leader in networking for the Internet. All Atlantic.Net consumer accounts include access to the World Wide Web, electronic mail and toll-free technical support 24 hours a day, 7 days a week. Consumer accounts start at $9.95 per month. Atlantic.Net’s most popular account, the Unlimited Plan, costs $19.95 per month. ### About Atlantic.Net [Atlantic.Net](https://www.atlantic.net/)was founded in 1994 by two University of Florida students, Marty Puranik and Jose Sanchez, who started the company by selling computers. After being denied Internet access through the university in 1995, Puranik and Sanchez launched one of the first commercial Internet services in Gainesville and Ocala, Florida. Today, Atlantic.Net serves more than 40,000 subscribers in seven states. Revenues have doubled every year since inception and in 1999 Atlantic.Net was recognized as Florida’s 15th fastest-growing private company. To learn more about Atlantic.Net’s complete line of services, call 1-866-618-3282 or visit the corporate Web site at https://www.atlantic.net. For company information, check out https://newsroom.atlantic.net. Atlantic.Net’s new office in Aiken is located at 125 Laurens Street. The office phone is (803) 649-0015. --- # Atlantic.Net Launches Service in South Carolina > URL: https://www.atlantic.net/press-releases/atlantic-net-launches-service-south-carolina/ | Published: 2000-08-17 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla (8/17/00) – Atlantic.Net, one of the Southeast’s fastest-growing Internet Providers, today announced it has launched its e-business services and 56K and ISDN consumer services in Spartanburg, Cowpens and Pacolet, South Carolina. Atlantic.Net’s e-business services include designing, installing and managing customized wide area networks, fractional T-1 through DS-3 connectivity, DSL and ISDN access and Web hosting. Managed dial-up services are also available to other Internet service providers. Atlantic.Net’s consumer dial-up services run on a Cisco Powered Network. Cisco is the worldwide leader in networking for the Internet. All Atlantic.Net consumer accounts include access to the World Wide Web, electronic mail and toll-free technical support 24 hours a day, 7 days a week. The company owns and operates its entire network and is known for its direct, reliable and uncluttered Internet access. ### About Atlantic.Net [Atlantic.Net](https://www.atlantic.net/) was founded in 1994 by two University of Florida students, Marty Puranik and Jose Sanchez, who started the company by selling computers. After being denied Internet access through the university in 1995, Puranik and Sanchez launched one of the first commercial Internet services in Gainesville and Ocala, Florida. Today, [Atlantic.Net](https://www.atlantic.net/) serves over 40,000 subscribers in 70 locations throughout the Southeastern United States. Revenues have doubled every year since inception and in 1999 Atlantic.Net was recognized as Florida’s 15th fastest-growing private company. The company is one of the rare Internet access service providers that can claim to be profitable. To learn more about Atlantic.Net’s complete line of services, call 1-866-618-3282 or visit the corporate Web site at https://www.atlantic.net. --- # Atlantic.Net Makes Inc. 500 List-2 > URL: https://www.atlantic.net/press-releases/atlantic-net-makes-inc-500-list-2/ | Published: 2000-10-10 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla. (10/10/00) – [Atlantic.Net,](https://www.atlantic.net/) one of the Southeast’s most reliable Internet service providers, is proud to announce it has been named one of America’s fastest-growing companies by Inc. magazine. Atlantic.Net ranks number 350 on the 2000 Inc. 500 list, a comprehensive guide to the [country’s fastest-growing private companies](https://www.atlantic.net/) based on the percentage increase in sales from 1995 through 1999. Noteworthy Inc. 500 alumni include Microsoft, E-Trade, Oracle, The Sharper Image and Domino’s Pizza. “This recognition represents our employees’ unwavering dedication to our customers and to our company,” said Marty Puranik, president and CEO of Atlantic.Net. “I am very proud to be a part of this team.” ### About Atlantic.Net [Atlantic.Net](https://www.atlantic.net/)was founded in 1994 by two University of Florida students, Marty Puranik and Jose Sanchez, who started the company by selling computers. After being denied Internet access through the university in 1995, Puranik and Sanchez launched one of North Florida’s first commercial Internet services in Gainesville and nearby Ocala. Over the past five years, Atlantic.Net has expanded its network throughout seven Southeastern states, acquired 13 Internet service providers and augmented its e-business services to include customized wide area networks, fractional T-1 through DS-3 connectivity, DSL and ISDN access and Web hosting. Atlantic.Net’s staff has grown to more than 100 employees in its Gainesville headquarters, with additional offices in Ft. Lauderdale and Tampa, FL, and Aiken, SC. Revenues have doubled every year since inception. **Atlantic.Net Services** [Atlantic.Net](https://www.atlantic.net/) owns and operates its entire network, which spans more than 70 cities across the Southeast. Consumer dial-up services run on a Cisco Powered Network. Cisco is the worldwide leader in networking for the Internet. All Atlantic.Net consumer accounts include access to the World Wide Web, electronic mail and toll-free technical support 24 hours a day, 7 days a week. Consumer accounts start at $9.95/month. Atlantic.Net’s most popular account, the Unlimited Plan, costs $19.95/month. E-business services include designing, installing and managing customized wide area networks, fractional T-1 through DS-3 connectivity, DSL and ISDN access and Web hosting. Managed dial-up services are also available to other Internet service providers. To learn more about Atlantic.Net’s complete line of services, call 1-866-618-3282 or visit the corporate Web site at https://www.atlantic.net. --- # Atlantic.Net to Offer High-Speed DSL Service Across Florida > URL: https://www.atlantic.net/press-releases/atlantic-net-offer-high-speed-dsl-service-across-florida/ | Published: 2000-11-03 | Updated: 2026-03-02 | Author: Editorial Team Gainesville, FL (11/3/00) – Atlantic.Net, one of the Southeast’s fastest-growing Internet service providers, is bringing high-speed Digital Subscriber Line (DSL) Internet access to businesses and residents across Florida. DSL uses ordinary phone lines and a special modem to provide high-speed, dedicate servers, ‘always on’ Internet connections. Atlantic.Net is offering three DSL service options with speeds up to 50 times faster than a conventional 28.8Kbps modem. Business and residential customers who sign a one-year contract will receive free activation and a free modem until December 31, 2000. While monthly charges vary according to speed and service features, the cost of DSL is a fraction of the cost of traditional high-speed access options. “DSL is the answer for businesses that need an affordable way to provide high-speed Internet access to multiple users in the same office,” said Brian Bess, marketing director at Atlantic.Net. “For residents, DSL offers the opportunity to be online and on the phone at the same time, without an additional phone line.” Atlantic.Net is offering Symmetrical DSL (or SDSL) and ISDN DSL (or IDSL) service to business customers and Asymmetrial DSL (or ADSL) service to residents, with prices starting at $49.95. All DSL service options allow users to transmit large files faster and easier, while SDSL and IDSL service are essential for businesses that want to establish networks and share files. Because Atlantic.Net is partnering with a number of different providers to offer DSL service, businesses and residents that did not previously qualify for DSL service because of distance requirements may be able to qualify through [Atlantic.Net.](https://www.atlantic.net/) To learn more about DSL, users can visit https://www.atlantic.net/dsl or call 1-866-618-3282. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over it’s first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting , Web design and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net has state of the art fast [SSD Fast Cloud servers](https://www.atlantic.net/vps-hosting/)offering the very best in [cloud hosting](https://www.atlantic.net/vps-hosting/) solutions, one click WordPress cloud hosting and many other services. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit [Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # Atlantic.Net Makes Florida 100 for Third Year in a Row > URL: https://www.atlantic.net/press-releases/atlantic-net-makes-florida-100-third-year-row/ | Published: 2001-01-12 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla. (1/12/01) – [Atlantic.Net](https://www.atlantic.net/), one of the southeast’s most reliable Internet Service Providers, is pleased to announce for the third year in a row that it has been named one of Florida’s fastest-growing private companies. Atlantic.Net is number 11 in the Florida 100, jumping from number 15 in the 1999 listing and number 79 in the 1998 listing. Company revenues increased 372% from 1997-1999. The Florida 100 is an annual program organized by the University of Florida’s Warrington College of Business Administration and Fisher School of Accounting to identify and honor Florida’s one hundred highest growth firms. Recipients must meet four strict requirements to be eligible: be an independent, privately held corporation or proprietorship, but not a subsidiary or division; show a three-year sales history with an increase over the three year period; have sales of more than $100,000 in fiscal 1997; and be headquartered in the state of Florida. ### About Atlantic.Net [Atlantic.Net](https://www.atlantic.net/) was founded in 1994 by two University of Florida students, Marty Puranik and Jose Sanchez, who started the company by selling computers. After being denied Internet access through the university in 1995, Puranik and Sanchez launched one of the first commercial Internet services in Gainesville and nearby Ocala. Atlantic.Net today serves businesses and consumers throughout seven Southeastern states. In September, Inc. magazine named Atlantic.Net the nation’s 350th [fastest-growing private company](https://www.atlantic.net/vps-hosting/). Atlantic.Net’s network spans more than 70 cities. E-business services include designing, installing and managing customized wide area networks, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting and wholesale services. Atlantic.Net’s consumer dial-up services run on a Cisco Powered Network. Cisco is the worldwide leader in networking for the Internet. All Atlantic.Net consumer accounts include access to the World Wide Web, electronic mail and toll-free technical support 24 hours a day, 7 days a week. Consumer accounts start at $9.95 per month. Atlantic.Net’s most popular account, the Unlimited Plan, costs $19.95 per month. To learn more about Atlantic.Net’s complete line of services, call 1-866-618-3282 or visit the corporate Web site at https://www.atlantic.net. For more information about this release, call Doreen Sabina at (904) 249-3946 or e-mail [doreen@atlantic.net](mailto:doreen@atlantic.net). For company information, check out http://newsroom.atlantic.net. --- # Atlantic.Net Extends Free Equipment & Activation for DSL Service > URL: https://www.atlantic.net/press-releases/atlantic-net-extends-free-equipment-free-activation-offer-dsl-service/ | Published: 2001-05-15 | Updated: 2024-03-01 | Author: Editorial Team Gainesville, Fla (5/15/01) — Atlantic.Net, one of the Southeast’s most reliable and fastest-growing IP (Internet Protocol) carriers, announced it is extending indefinitely its offer to provide free equipment and free activation to businesses that sign a one-year contract for Atlantic.Net’s Digital Subscriber Line (DSL) Internet access. This offer is being extended to support former NorthPoint customers in Florida, whose DSL service was terminated when AT&T bought NorthPoint’s assets late last month. [Atlantic.Net](https://www.atlantic.net/vps-hosting/) can turn up the DSL circuits within fifteen business days after a contract is signed. In addition, Atlantic.Net is offering temporary dial-up connections to businesses until their Atlantic.Net DSL connections are established. “We are proud to offer a solution to former NorthPoint customers,” said Adnan Raja, product manager at Atlantic.Net. “It’s also a perfect opportunity for Atlantic.Net to demonstrate why we are one of the fastest-growing companies in Florida and the nation.” To sign up for DSL, businesses can call 1-866-618-3282. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over it’s first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting , Web design and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net offers the very best in [cloud hosting](https://www.atlantic.net/vps-hosting/) solutions, managed cloud hosting, [Linux Cloud Hosting](https://www.atlantic.net/vps-hosting/), and many other services. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # Atlantic.Net Enters Licensing Agreement with Jones Lang LaSalle > URL: https://www.atlantic.net/press-releases/atlantic-net-enters-licensing-agreement-jones-lang-lasalle/ | Published: 2001-06-12 | Updated: 2024-03-04 | Author: Editorial Team Orlando, Fla. (6/12/01) – [Atlantic.Net](https://www.atlantic.net/), one of the Southeast’s fastest-growing and most reliable IP-carriers, today announced an agreement with real estate management services company Jones Lang LaSalle to deliver and market its services to business tenants in Ella Park Centre, a 15-story commercial building in downtown Orlando. The telecommunications agreement allows Atlantic.Net to install the equipment necessary to provide high-speed Internet services to 169,000 square feet of space and more than 47 tenants. “Atlantic.Net is fortunate to be working with Jones Lang LaSalle,” said Marty Puranik, president and CEO of Atlantic.Net. “Many of the Internet providers that originally signed agreements with property management companies have gone out of business, giving Atlantic.Net the opportunity to differentiate itself with its business model. Being in business for seven years is testimony to how well we execute, and we will continue to do the same in the real estate arena.” Atlantic.Net’s current agreement with Jones Lang LaSalle is for DSL service. DSL technology uses existing telephone wires to enable high-speed Internet access and “always- on” connections, at costs much lower than other high-speed options, such as a T-1 line. To learn more about Atlantic.Net’s service, visit https://www.atlantic.net/dsl. To sign up for Atlantic.Net DSL, businesses can call 1-866-618-3282. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over it’s first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting , Web design and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net offers the very best in [cloud hosting](https://www.atlantic.net/vps-hosting/), [windows cloud Hosting](https://www.atlantic.net/vps-hosting/), and many other services. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # Atlantic.Net Offers Relief to Former BlueStar Customers in Florida > URL: https://www.atlantic.net/press-releases/atlantic-net-offers-relief-former-bluestar-customers-across-florida/ | Published: 2001-06-27 | Author: Editorial Team Gainesville, FL (6/27/01) – Atlantic.Net, an IP (Internet Protocol) carrier and one of the nation’s fastest-growing companies, announced today a special offer for former BlueStar customers across Florida. Atlantic.Net is offering free equipment and free activation to businesses that sign a one-year contract for Atlantic.Net’s Digital Subscriber Line (DSL) Internet access, and free installation to businesses that sign a two-year agreement for a high-speed T-1 connection. BlueStar Communications, an [Internet service provider](https://www.atlantic.net/vps-hosting/) serving small and mid-sized businesses in the Southeastern United States, ceased operations on Monday. [Atlantic.Net](https://www.atlantic.net/vps-hosting/) can turn up the DSL circuits within 15 business days after a contract is signed and typically installs a T-1 line in 30 days. In addition, Atlantic.Net is offering alternative connections to businesses until their Atlantic.Net DSL or T-1 connections are established. “Atlantic.Net is in the fortunate position to be able to offer excellent service to customers who are in the unfortunate position of having to find a new Internet provider,” said Marty Puranik, president and CEO of Atlantic.Net. “Our optimistic but cautious approach has allowed us not only to sustain but to grow our business, and we are proud of that.” To sign up for DSL or a T-1 connection, businesses can call 1-866-618-3282. To learn more about Atlantic.Net’s services, visit https://www.atlantic.net. ## About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over it’s first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting , Web design and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net has state of the art fast [SSD Cloud servers](https://www.atlantic.net/vps-hosting/) offering the very best in [cloud hosting](https://www.atlantic.net/vps-hosting/) solutions,[one click WordPress cloud hosting](https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/) and many other services. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit [Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # Atlantic.Net Provides Internet Access to 9 area radio stations > URL: https://www.atlantic.net/press-releases/atlantic-net-signs-agreement-pamal-broadcasting-ltd/ | Published: 2001-08-17 | Author: Editorial Team Gainesville, FL (8/17/01) – Atlantic.Net, one of the Southeast’s fastest-growing and most reliable Internet Protocol Carriers, today announced an agreement with Pamal Broadcasting to provide dedicated Internet access to its nine radio stations in the Gainesville/Ocala area. “We are impressed by Atlantic.Net’s network operations and reputation,” said Bruce Cherry, operations manager at Pamal. “We are excited to be partnering with Atlantic.Net and feel it’s only fitting for the largest broadcasting company in the area to be doing business with the largest Internet provider in the area. It’s a win/win/win for Pamal, Atlantic.Net and our clients.” Established in 1996 as a sister company to Albany Communications, Pamal Broadcasting owns radio stations in primarily medium-sized markets in the eastern United States. Headquartered in Albany, NY, Pamal’s stations in the Gainesville/Ocala market include: Lite 106.9, Z100, Magic101.3, Sports/Talk AM1430 The Team, WDJY101.7, FUN102.7 and the KOZY Radio Group: WRZN, WLUS and WDFL. The agreement with Pamal Broadcasting represents Atlantic.Net’s third alliance with a major radio broadcasting group. Atlantic.Net signed similar agreements with Renda Broadcasting and Infinity Broadcasting earlier this year. ### About Atlantic.Net Atlantic.Net was founded in 1994 by University of Florida students, Marty Puranik and Jose Sanchez, who started the company by selling computers. In September 2000, the company was named to Inc. magazine’s annual list of the 500 fastest-growing private companies in the country. Today, Atlantic.Net is an industry leading provider of [cloud hosting](https://www.atlantic.net/vps-hosting/) solutions and a variety of one click applications like wordpress and [CPanel cloud Hosting](https://www.atlantic.net/hipaa-compliant-hosting/cpanel-ideal-cp-cloud-hosting/).   Atlantic.Net’s complete line of services, call 1-866-618-3282 or visit the corporate Web site at [www.atlantic.net](https://www.atlantic.net/vps-hosting/). --- # Atlantic.Net Signs Agreement with Asterisk Communications > URL: https://www.atlantic.net/press-releases/atlantic-net-signs-agreement-asterisk-communications/ | Published: 2001-09-25 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, FL (9/25/01) – [Atlantic.Net,](https://www.atlantic.net/) one of the Southeast’s fastest-growing and most reliable Internet Protocol Carriers, today announced an agreement with Asterisk Communications to provide broadband and Web hosting to its five radio stations in the Gainesville/Ocala area. “High speed connectivity and state-of-the-art data technology are becoming important in every phase of our business,” said Tim Ingham, vice president at Asterisk. “We’re excited to have the expertise and proven capabilities of Atlantic.Net at our disposal.” A family-owned and operated Florida media company incorporated in 1983, Asterisk Communications owns five radio stations in the Gainesville/Ocala market: Thunder Country 102.3 WTRS, Q 92.9 WMFQ, GC-101 WYGC, Smooth Jazz 104.9 WXJZ, and Star 99.5 WBXY. The agreement with Asterisk Communications represents Atlantic.Net’s fourth alliance with a major radio broadcasting group. Atlantic.Net signed similar agreements with Renda Broadcasting, Infinity Broadcasting and Pamal Broadcasting earlier this year. To learn more about Atlantic.Net’s services, visit https://www.atlantic.net. or call 1-866-618-3282. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over it’s first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting , Web design and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net offers the very best in [cloud hosting solutions](https://www.atlantic.net/vps-hosting/), one-click application cloud hosting like WordPress and [C-Panel cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/cpanel-ideal-cp-cloud-hosting/)among others. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # Atlantic.Net Makes Inc. 500 List > URL: https://www.atlantic.net/press-releases/atlantic-net-makes-inc-500-list/ | Published: 2001-10-11 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, FL (10/11/01) – Atlantic.Net, one of the Southeast’s most reliable Internet-Protocol carriers, is proud to announce it has been named one of America’s fastest-growing companies by Inc. magazine for the second year in a row. Atlantic.Net ranks number 223 on the 2001 Inc. 500 list, a comprehensive guide to the country’s fastest-growing private companies based on the percentage increase in sales from 1996 through 2000. Atlantic.Net was number 350 on last year’s list. Noteworthy Inc. 500 alumni include Microsoft, The Sharper Image and Domino’s Pizza. “I am very proud of our employees,” said Marty Puranik, president and CEO of Atlantic.Net. “To be recognized two years in a row is testimony to our team’s ability to work smart, be innovative, move quickly and adapt to change.” ### About Atlantic.Net [Atlantic.Net’s](https://www.atlantic.net/) services include broadband, e-commerce, Web solutions and dial-up. The company was founded in 1994 by two University of Florida students, Marty Puranik and Jose Sanchez, who launched one of North Florida’s first commercial Internet services in Gainesville and nearby Ocala in 1995. Over the past six years, Atlantic.Net has acquired 13 Internet service companies and augmented its e-business services to include true private networks, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting and Web design. Atlantic.Net’s staff has grown to more than 100 employees in its Gainesville headquarters, with additional offices in Ft. Lauderdale and Tampa, FL. Since 1998, Atlantic.Net has been recognized annually as one of Florida’s fastest-growing private companies, last year ranking number 11 in the state. To learn more about [Atlantic.Net’s complete line of services](https://www.atlantic.net/vps-hosting/), call 1-866-618-3282 or visit the corporate Web site at https://www.atlantic.net. --- # Atlantic.Net Introduces True Private Networks > URL: https://www.atlantic.net/press-releases/atlantic-net-introduces-true-private-networks/ | Published: 2001-10-31 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, FL (10/31/01) – [Atlantic.Net](https://www.atlantic.net/), one of the nation’s fastest–growing Internet-Protocol (IP) companies, today announced the official launch of its True Private Network service. Atlantic.Net’s True Private Network (TPN) allows companies to exchange data, documents and other confidential information between locations without crossing the Internet. Whereas other private networks, such as Virtual Private Networks, encrypt data and pass it over the Internet along with public traffic, Atlantic.Net’s True [Private Network service](https://www.atlantic.net/vps-hosting/) uses multi-protocol label switching technology to transfer data over a private network that runs parallel to public traffic. “There are three big advantages to True Private Networks–security, quality and cost,” said Cameron Clayton, consumer services product manager at Atlantic.Net. “With True Private Networks, data passes through a completely private segment on the Atlantic.Net pipe. Our technology works with a variety of dedicated access methods, and there are no limitations on the number of locations and no additional configuration changes necessary as a network expands. Because the service is network-based, it does not require new hardware or upgrades, decreasing the cost and the chances of equipment failure.” To learn more about [Atlantic.Net’s](https://www.atlantic.net/) True Private Network, call 1-866-618-3282 or visit the corporate Web site at https://www.atlantic.net. ### About Atlantic.Net [Atlantic.Net](https://www.atlantic.net/), recently named number 223 on the 2001 Inc. 500 list of the nation’s fastest-growing private companies, offers broadband, e-commerce, Web solutions and dial-up services. The company was founded in 1994 by two University of Florida students, Marty Puranik and Jose Sanchez, who launched one of North Florida’s first commercial Internet services in Gainesville and nearby Ocala in 1995. Over the past six years, Atlantic.Net has acquired 13 Internet service companies and augmented its e-business services to include true private networks, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting and Web design. The company has offices in Gainesville, Tampa and Ft. Lauderdale. --- # Atlantic.Net Makes Florida 100 for Fourth Year in a Row > URL: https://www.atlantic.net/press-releases/atlantic-net-makes-florida-100-fourth-year-row/ | Published: 2002-02-11 | Updated: 2026-03-02 | Author: Editorial Team Gainesville, FL (2/11/02) – [Atlantic.Net](https://www.atlantic.net/), one of the nation’s fastest-growing companies and most reliable Internet Service Providers, is pleased to announce for the fourth year in a row that it has been named one of Florida’s [fastest-growing private companies](https://www.atlantic.net/vps-hosting/). Atlantic.Net is number 22 on the Florida 100 list for 2001. Last year the company was number 11, jumping from number 15 in the 1999 listing and number 79 in the 1998 listing. The Florida 100 is an annual program organized by the University of Florida’s Warrington College of Business Administration and Fisher School of Accounting to identify and honor Florida’s one hundred highest growth firms. Recipients must meet four requirements to be eligible: be an independent, privately held corporation or proprietorship, but not a subsidiary or division; show a three-year sales history with an increase over the three year period; have sales of more than $100,000 in fiscal 1998; and be headquartered in the state of Florida. ### About Atlantic.Net [Atlantic.Net](https://www.atlantic.net/) was founded in 1994 by two University of Florida students, Marty Puranik and Jose Sanchez, who started the company by selling computers. After being denied Internet access through the university in 1995, Puranik and Sanchez launched one of the first commercial Internet services in Gainesville and nearby Ocala. Today Atlantic.Net serves businesses and consumers throughout the nation, offering broadband, telecommunications, e-commerce, Web solutions and dial-up Internet access. In October, Inc. magazine named Atlantic.Net the nation’s 223rd fastest-growing private company, up from number 350 last year. Over the past seven years, Atlantic.Net has acquired 13 Internet service companies and augmented its e-business services to include true private networks, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting and Web design. Atlantic.Net’s staff has grown to more than 100 employees. To learn more about [Atlantic.Net’s](https://www.atlantic.net/) complete line of services, call 1.866.618.3282 or visit the corporate Web site at https://www.atlantic.net. For company information, check out http://newsroom.atlantic.net. --- # Atlantic.Net Enters Partnership with Clear Channel Broadcasting > URL: https://www.atlantic.net/press-releases/atlantic-net-enters-strategic-partnership-clear-channel-broadcasting/ | Published: 2002-04-26 | Updated: 2024-03-04 | Author: Editorial Team GAINESVILLE, FL (4/26/02) – [Atlantic.Net](https://www.atlantic.net/), https://www.atlantic.net, a nationwide provider of Internet and telecommunications services and one of the nation’s fastest-growing companies, today announced it has entered into a strategic partnership with Clear Channel Broadcasting (NYSE: CCU) to become Clear Channel Orlando’s official Internet Provider. As official Internet Provider, Atlantic.Net’s services for Clear Channel’s seven radio stations in the Orlando area will include programming and Web development assistance, e-commerce capabilities, streaming video services, hosting for special project and/or client sites and broadband and dial-up connections for Clear Channel of Orlando employees. “We’re ecstatic to be working with Atlantic.Net,” said Mike Spry, director of engineering at Clear Channel Orlando. “We need the reliability and dedication of a hard working team of Internet professionals to grow our efforts here, and we are extremely delighted to have created a mutually beneficial partnership with Atlantic.Net.” As part of Atlantic.Net’s strategy to become the Internet services industry leader in Orlando, the company will invest significantly in Clear Channel Orlando’s radio, outdoor and Internet advertising channels. For example, Atlantic.Net commercials will be aired on all seven of Clear Channel Orlando’s radio stations starting in May. In addition, Atlantic.Net will be given the opportunity to participate in all Clear Channel Orlando Entertainment promotional events, including remote appearances and other broadcasting events. “We have been successful for the past seven years because we have focused on perfecting our technology, enhancing our services and exceeding the expectations of our customers,” said Marty Puranik, president and CEO of Atlantic.Net. “Now the time is right to get the word out. By partnering with the market leader in advertising and promotion, Atlantic.Net is reinforcing its commitment to being the number one Internet service provider in Orlando and across Florida.” ### About Clear Channel Clear Channel Communications, Inc., (NYSE: CCU) headquartered in San Antonio, Texas, is a global leader in the out-of home advertising industry with radio and television stations, outdoor displays, and entertainment venues in 63 countries around the world. Including announced transactions, Clear Channel operates approximately 1,224 radio and 19 television stations in the United States and has equity interests in over 240 radio stations internationally. Clear Channel also operates approximately 770,000 outdoor advertising displays, including billboards, street furniture and transit panels across the world. Clear Channel Entertainment is one of the world’s largest diversified promoters, producers and presenters of live entertainment events and is a leading fully integrated sports marketing and management company. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over it’s first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting , Web design and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net offers the very best in [cloud hosting](https://www.atlantic.net/vps-hosting/) solutions, managed cloud hosting, [cPanel cloud Hosting](https://www.atlantic.net/hipaa-compliant-hosting/cpanel-ideal-cp-cloud-hosting/), and many other services. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # Atlantic.Net Opens Office in Orlando > URL: https://www.atlantic.net/press-releases/atlantic-net-opens-office-orlando/ | Published: 2002-05-21 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE (5/21/02) – Gainesville-based Atlantic.Net, a nationwide provider of Internet and telecommunications services and one of the nation’s fastest-growing companies, today announced it has opened an [office in Orlando](https://www.atlantic.net/orlando-colocation-hosting-data-center/). The company, ranked number 223 on this year’s Inc. 500 list of the fastest-growing private companies in America, opens its Orlando office with five employees and plans to grow as quickly as possible, but according to the needs of the business. Atlantic.Net has appointed Adnan Raja, formerly director of business development, as general manager of the Orlando office. Raja brings experience in the technology industry and knowledge of the Central Florida market. “[Atlantic.Net](https://www.atlantic.net/) has kept a low profile for the last eight years and now it’s time to demonstrate our best technologies and excellent customer service in the Central Florida market, particularly because so many businesses are in need of a stable, reliable Internet provider,” said Adnan Raja, general manager, Orlando market. “Not only will we provide the newest and highest-quality products available, we plan to create jobs in Orlando. Our overall plan is to implement our proven methods of doing business for the benefit of companies in Orlando and the surrounding areas.” [Atlantic.Net’s](https://www.atlantic.net/) new office is located at 2500 Maitland Center Parkway Suite 401 Maitland, FL 32751. Adnan Raja can be reached at 407.916.8338. ### About Atlantic.Net Atlantic.Net’s services include broadband, telecommunications, e-commerce, Web solutions and dial-up. The company, ranked number 223 on this year’s Inc. 500 list of the fastest-growing private companies in America, was founded by two University of Florida students in 1995. Over the past seven years, Atlantic.Net has acquired 13 Internet service companies and augmented its e-business services to include long distance services, true private networks, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting and Web design. Atlantic.Net’s staff has grown to more than 100 employees who regularly participate in the Alachua County Guardian Ad Litem drive to provide toys for needy children at Christmas and in local United Way and March of Dimes charity events. For four years in a row, Atlantic.Net has been recognized as one of Florida’s fastest-growing private companies, last year ranking number 22 in the state. In 2001 the company established a business scholarship in the Decision and Information Sciences Department at the University of Florida’s College of Business. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the corporate Web site at https://www.atlantic.net. --- # Atlantic.Net Introduces JetStream Service to Orlando Area > URL: https://www.atlantic.net/press-releases/atlantic-net-introduces-jetstream-service-orlando-area/ | Published: 2002-06-20 | Updated: 2026-03-02 | Author: Editorial Team ORLANDO, FL (6/20/02) – [Atlantic.Net](https://www.atlantic.net/), a nationwide provider of Internet and telecommunications services and one of America’s fastest-growing companies, today announced the debut of JetStream, the company’s new, high-speed dial-up Internet service. Atlantic.Net is the first ISP in Orlando to introduce high-speed dial-up service, which features Internet connection speeds up to 60% faster than the standard 56k dial-up access and the ability for users to take phone calls without being knocked offline. “Our Jetstream service is perfect for anyone who wants a fast and constant connection to the Internet, but doesn’t want to pay the high monthly fee for broadband or a second phone line,” said Adnan Raja, general manager of Atlantic.Net’s Orlando office. “JetStream will provide Orlando residents with a great introduction to Atlantic.Net’s reliable Internet service and excellent customer support.” Atlantic.Net’s announcement coincides with the start of phase two of the company’s extensive marketing campaign in the greater Orlando area. For the past two weeks, 32 billboards around Orlando have been part of the Atlantic.Net “‘Do you love…?’ teaser” campaign. These billboards are being changed today to promote the company’s introductory offer for its Jetstream service: $9.95 per month for the first three months for new Atlantic.Net members. Atlantic.Net’s standard monthly rate for JetStream service is $19.95 per month. New members can sign up for Atlantic.Net’s JetStream service online by visiting https://www.atlantic.net or by calling Member Services at 866.618.3282, 24 hours a day, seven days a week. JetStream users get Atlantic.Net’s full-featured Internet service, including: • Internet connection speeds up to 60% faster than the standard 56k dial-up access • The ability to take phone calls without being knocked offline • Up to 10 e-mail accounts • 15 MB of Web space for a personal home page • 24/7 toll-free customer service and technical support • Monthly newsletter and members-only portal • Web-based e-mail accessible around the world • Free service for referring friends and family • Instant Messenger compatibility with all platforms Atlantic.Net’s Jetstream service runs on a V92 modem. The company plans to begin offering Jetstream service outside the Orlando area over the next few months. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over it’s first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting , Web design and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net offers the very best in [cloud hosting](https://www.atlantic.net/vps-hosting/) solutions, [managed cloud hosting](https://www.atlantic.net/vps-hosting/), Linux and Windows Cloud hosting, and many other services. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # Atlantic.Net Pursues WorldCom Customers > URL: https://www.atlantic.net/press-releases/atlantic-net-pursues-worldcom-customers/ | Published: 2002-07-10 | Updated: 2026-03-02 | Author: Editorial Team Gainesville, Fla. (7/10/02) – [Atlantic.Net](https://www.atlantic.net/) (https://www.atlantic.net), one of the nation’s fastest-growing Internet service providers, today announced a special offer for current WorldCom customers looking for a financially stable company to meet their voice and data communications needs. Atlantic.Net is offering free installation to businesses that sign a minimum one-year contract for digital subscriber line (DSL) Internet service. In addition companies that commit to a two-year agreement for DSL get free equipment. [Atlantic.Net](https://www.atlantic.net/)also is waiving installation fees for businesses that sign a two-year contract for a T-1 connection. [Atlantic.Net](https://www.atlantic.net/)can have DSL circuits up and running within 20 business days after a contract is signed and typically installs a T-1 line in 30 days. In addition Atlantic.Net is offering businesses temporary connections until the new DSL or T-1 circuits are established. This is the fifth time during the past year [Atlantic.Net](https://www.atlantic.net/)has extended this offer, as companies such as Broadslate, Verio and BlueStar have announced the discontinuation of service in select areas due to factors including acquisition and bankruptcy. To sign up for DSL or a T-1 connection call (866) 618-3282. To learn more about Atlantic.Net business services visit https://www.atlantic.net. ### About Atlantic.Net Launched in 1994 Atlantic.Net is an Internet service provider offering high-speed Internet access, Web site solutions, telecommunications and dial-up. Atlantic.Net [business services feature](https://www.atlantic.net/dedicated-server-hosting/) a 99.9 percent uptime guarantee, 24/7 network monitoring and connection to an optimized Cisco Powered Network-a designation reserved for the world’s top 1 percent of ISPs. In 2001 Atlantic.Net was named to the Inc 500 list of the nation’s fastest-growing private companies for the second consecutive year, moving up from a rank of 350 to 223. During the past eight years Atlantic.Net has acquired 13 Internet companies, has doubled or tripled revenues annually and has remained profitable every year since inception. To learn more about Atlantic.Net call (866) 618-3282 or visit https://www.atlantic.net. --- # Atlantic.Net Wins 2002 HostIndex.com Top Web Host Award > URL: https://www.atlantic.net/press-releases/atlantic-net-wins-2002-hostindex-com-top-web-host-award/ | Published: 2002-07-18 | Updated: 2026-03-02 | Author: Editorial Team Gainesville, Fla. (7/18/02) – Atlantic.Net (https://www.atlantic.net), one of the nation’s fastest-growing Internet service providers, is the recipient of a 2002 HostIndex.com Top Web Host award. Evaluation criteria for the award include hosting plan breadth and value, customer service levels, network reliability and HostIndex.com user feedback. Atlantic.Net was chosen from a field of more than 5,000 Web hosts worldwide. “[Atlantic.Net](https://www.atlantic.net/) is a stable, [growing Web host](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/) that offers strong hosting breadth to customers on a very consistent basis,” said Ryan Kalt, site editor for HostIndex.com. “The company is deserving of recognition and we are pleased to have HostIndex.com, the Internet’s most trusted hosting authority, be a part of that industry acknowledgement.” The annual award recognizes hosting companies that consistently rank among the Top 20 on the monthly HostIndex.com Top 25 list during a yearlong evaluation period. The 2002 awards honor Web hosts that earned at least six months of placement from June 1, 2001 through June 1, 2002. “We are honored to be recognized by HostIndex.com and proud to have earned the trust and loyalty of their site’s visitors,” said Josh Simon, Atlantic.Net’s Website services director. “We are especially pleased to have received an award for our customer service efforts. Atlantic.Net is committed to delivering superior customer service and helping our clients and their businesses thrive. This award truly belongs to all Atlantic.Net employees, particularly our outstanding Web support team and network engineers for their dedication to serving our customers and making sure they win every day.” Along with Web design and development, Atlantic.Net offers hosting plans that include shared hosting, [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/), [colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/) and application hosting. New customers who sign up for any of [Atlantic.Net’s](https://www.atlantic.net/)award-winning hosting plans get a month of free service. To learn more call (866) 618-3282 or visit https://www.atlantic.net. ### About Atlantic.Net Launched in 1994 [Atlantic.Net](https://www.atlantic.net/) is an Internet service provider offering high-speed Internet access, Web site solutions, telecommunications and dial-up. Atlantic.Net business services feature a 99.9 percent uptime guarantee, 24/7 network monitoring and connection to an optimized Cisco Powered Network-a designation reserved for the world’s top 1 percent of ISPs. In 2001 [Atlantic.Net](https://www.atlantic.net/) was named to the Inc 500 list of the nation’s fastest-growing private companies for the second consecutive year, moving up from a rank of 350 to 223. During the past eight years Atlantic.Net has acquired 13 Internet companies, has doubled or tripled revenues annually and has remained profitable every year since inception. To learn more about [Atlantic.Net](https://www.atlantic.net/)call (866) 618-3282 or visit https://www.atlantic.net. --- # Atlantic.Net Expands Internet Services in Southeast > URL: https://www.atlantic.net/press-releases/atlantic-net-expands-internet-services-southeast/ | Published: 2002-09-17 | Updated: 2026-03-02 | Author: Editorial Team Gainesville, Fla (9/17/02). – Atlantic.Net (https://www.atlantic.net), Florida’s largest privately held Internet service provider, today announced an agreement with Progress Telecom, a provider of leading-edge wholesale broadband services throughout the Eastern Seaboard. The agreement increases the size of Atlantic.Net’s network by providing the company with dedicated bandwidth within a portion of Progress Telecom’s fiber-optic network in Florida and other Southeastern states. Because of the agreement with Progress Telecom, Atlantic.Net is able to pass along to its customers benefits including cost savings, faster provisioning, greater scalability and priority customer support. “In essence, this deal means Atlantic.Net is a carrier that’s capable of providing affordable, high-speed Internet access to businesses in even the most remote regions of Florida and the Southeast, where broadband services may not have been available before,” said Marty Puranik, president and CEO of Atlantic.Net. “If you think of the telecom infrastructure in the Southeastern United States as a highway, Atlantic.Net now has its own lane because of this agreement,” Puranik said. “We’re pleased to collaborate with a company that shares our goal to provide businesses and consumers with superior customer service and fast, reliable Internet access.” Paul Aiello, Progress Telecom’s vice president of sales and marketing, said: “Because our company is a metro player with dense reach into Tier 2 and Tier 3 cities, we have the capability of enabling providers to serve retail customers in those often underserved markets.” Both Atlantic.Net and Progress Telecom are financially stable, established companies. Progress Telecom is a subsidiary of Progress Energy (NYSE: PGN), a Fortune 250 diversified holding company that includes two major electric utilities, CP&L and Florida Power. Twice named one of the nation’s fastest-growing private companies by Inc magazine, Atlantic.Net has acquired 13 Internet companies, has doubled or tripled revenues annually and has remained profitable every year since its inception in 1994. “Our agreement with Progress Telecom better positions us to serve customers who seek to nurture a long-term relationship with an established, financially stable Internet service provider, or who may be sensitive to the corporate malfeasance of other telecom companies,” Puranik said. “Atlantic.Net has always been a technology company. We have always owned and operated our own network, and the alliance with Progress Telecom is another step toward our becoming an Internet supercarrier. Besides dramatically increasing our network’s size, we’ve boosted its capacity and made it more redundant, which further strengthens its overall speed and reliability.” Atlantic.Net offers high-speed access, Web site services, telecommunications and dial-up. Dedicated access options include DSL, ISDN, frame relay and point-to-point T-1/T-3 connectivity. Atlantic.Net can have DSL circuits up and running within 20 business days after a contract is signed and typically installs a T-1 line in 30 days. To learn more about Atlantic.Net Business Services, call 1-866-618-3282 or visit https://www.atlantic.net. ### About Atlantic.Net Launched in 1994 Atlantic.Net is an [Internet service provider](https://www.atlantic.net/) offering high-speed Internet access, Web site solutions, telecommunications and dial-up. Atlantic.Net business services feature a 99.9 percent uptime guarantee, 24/7 network monitoring and connection to an optimized Cisco Powered Network – a designation reserved for the world’s top 1 percent of ISPs. In 2001 Atlantic.Net was named to the Inc 500 list of the nation’s fastest-growing private companies for the second consecutive year, moving up from a rank of 350 to 223. During the past eight years Atlantic.Net has acquired 13 Internet companies, has doubled or tripled revenues annually and has remained profitable every year since inception. To learn more about Atlantic.Net call 1-866-618-3282 or visit https://www.atlantic.net. ### About Progress Telecom Founded in 1998, Progress Telecom is a provider of wholesale telecommunications services throughout the eastern United States. Progress Telecom incorporates approximately 137,000 fiber miles and more than 8,400 route miles in its network including over 155 Points-of-Presence (POPS). The fiber network serves as the backbone of OC-192 transport that allows customers enhanced data transport capabilities in the eastern United States from New York to Miami, FL, in first, second and third tier growth markets and access to Latin America through its International Gateways. The network’s utility-based infrastructure also offers fast local loop access through metropolitan fiber rings that move broadband capacity closer to the customer with 10 gigabit dense wave division multiplexing (DWDM) technology. For more information about Progress Telecom, visit the company’s Website at http://www.progresstelecom.com. Progress Energy (NYSE: PGN) is a Fortune 250 diversified holding company headquartered in Raleigh, N.C., with more than 21,500 megawatts of generation capacity and $8 billion in annual revenues. The company’s diverse portfolio includes two major electric utility companies, CP&L and Florida Power, as well as NCNG, Progress Rail, Progress Telecom and Progress Ventures, which manages the company’s non-regulated energy operations including fuel extraction, manufacturing and delivery; merchant generation; and energy marketing and trading. These companies serve 2.9 million customers across the Southeast, providing electricity, natural gas, energy services and broadband capacity. For more information about Progress Energy, visit the company’s Web site at http://www.progress-energy.com/. --- # Atlantic.Net Takes Strategic Step in Pursuit of Central Florida Market > URL: https://www.atlantic.net/press-releases/atlantic-net-takes-strategic-step-pursuit-central-florida-market/ | Published: 2002-10-16 | Author: Editorial Team Orlando, Fla. (10/16/02) – Atlantic.Net (https://www.atlantic.net), Florida’s largest privately held Internet service provider, today announced the company has doubled the size of its Orlando sales force and has added a sales manager to lead its sales efforts in the region. The new additions to Atlantic.Net’s sales team bring more than 35 combined years of experience and industry knowledge to the company, as well as vast regional knowledge of the Central Florida market. “This important step enhances Atlantic.Net’s ability to offer businesses in Orlando and surrounding areas a choice for their business-class Internet services,” said Cameron Clayton, director of sales and marketing for Atlantic.Net. “We are very pleased to add this talented group to our existing sales teams. It is a positive development for Orlando business customers citywide.” The new sales team members include Sales Manager Elizabeth Hall and Business Account Executives James Bowman, Colleen Guay and Jim Weber. • Sales Manager Elizabeth Hall brings 13 years of experience to Atlantic.Net and her team. Previously, she served as sales manager for Volaris Online and held various executive positions at Covad Communications, BlueStar and AT&T. • Prior to joining Atlantic.Net, James Bowman worked as an account manager at Teligent and Covad. He is a graduate of Nyack College in New York and has lived in Orlando for 25 years. • Colleen Guay began her career with Orlando-based companies PageNet and Metrocall before moving on to ITC DeltaCom and Volaris. • Jim Weber has more than 10 years of sales and management experience. He holds a degree from Indiana University and served in the U.S. Air Force. “We’re pleased to welcome Elizabeth and her team to the [Atlantic.Net](https://www.atlantic.net/vps-hosting/) family,” Clayton said. “Their extensive experience in the region, knowledge of Internet technologies, plus their focus on customer support and service is a tremendous asset to our Orlando business clients and to our company.” The new Orlando sales staff and the existing team will focus initially on welcoming former Volaris customers to Atlantic.Net, ensuring those customers and their services are supported during the transition period. “With industry-leading Internet, Web site and telecommunications services, plus our compelling high-speed dial-up services, Atlantic.Net is well-positioned to fill the void opened by last week’s announcement of Volaris’ sellout to Earthlink,” Clayton said. Today’s announcement coincides with the launch of Atlantic.Net’s new advertising campaign that reminds Central Florida business customers they have “the power to choose” their provider of business-class services. This marks the sixth time during the past year that Atlantic.Net has stepped in to support customers in need, as companies such as Broadslate, WorldCom, Verio and BlueStar have announced the discontinuation of service in select areas due to factors including acquisition and bankruptcy. This latest news follows a recent string of growth announcements from Atlantic.Net. Last month, the company announced an agreement with Progress Telecom, a Florida-based provider of leading-edge wholesale broadband services and a subsidiary of Progress Energy. Along with increasing Atlantic.Net’s network reach in the Southeast, the agreement enables the company to pass along customer benefits including cost savings, faster provisioning, greater scalability and priority customer support. Atlantic.Net offers high-speed Internet access, Web site services, telecommunications and dial-up. To learn more about Atlantic.Net Business Services, call 1-866-618-3282 or visit https://www.atlantic.net. ### About Atlantic.Net Launched in 1994 Atlantic.Net is an Internet service provider offering high-speed Internet access, Web site solutions, telecommunications and dial-up. Atlantic.Net business services feature a 99.9 percent uptime guarantee, 24/7 network monitoring and connection to an optimized Cisco Powered Network – a designation reserved for the world’s top 1 percent of ISPs. In 2001 Atlantic.Net was named to the Inc 500 list of the nation’s fastest-growing private companies for the second consecutive year, moving up from a rank of 350 to 223. During the past eight years Atlantic.Net has acquired 13 Internet companies, has doubled or tripled revenues annually and has remained profitable every year since inception.  As times change, we stay ahead of the curve in providing the very best for our customers.   Currently, we have implemented state of the art fast [cloud servers](https://www.atlantic.net/vps-hosting/) to fully cater to our growing cloud computing demands at our six international [cloud hosting](https://www.atlantic.net/vps-hosting/) locations.  To learn more about Atlantic.Net call 1-866-618-3282 or visit https://www.atlantic.net. --- # Atlantic.Net Among Inc 500’s Fastest-Growing Private Companies > URL: https://www.atlantic.net/press-releases/atlantic-net-named-among-inc-500-fastest-growing-private-companies-america/ | Published: 2002-10-23 | Author: Editorial Team GAINESVILLE, Fla. (10/23/02)– Atlantic.Net (https://www.atlantic.net), Florida’s largest privately held Internet service provider, has been named one of America’s fastest-growing private companies by Inc magazine for the third year in a row. This year, Atlantic.Net ranks number 269 on the Inc 500, a roster of the country’s fastest-growing private companies based on sales growth from 1997 through 2001. Noteworthy Inc 500 alumni include Microsoft, Timberland and Domino’s Pizza. During the past 20 years, fewer than 6 percent of the winners have been named to the list three times. Atlantic.Net is one of only 31 Florida-based companies to make the 2002 Inc 500 and is the state’s only Internet service provider to be honored. “This honor is especially meaningful to us because it recognizes the fact that our company has grown despite the many challenges we’ve faced in our industry during the past 12 months,” said Marty Puranik, president and CEO of Atlantic.Net. “The market difficulties of this past year have required us to adapt to change and have helped us focus even more closely on creating real value for our customers. This recognition proves that while many of our competitors have gone out of business and faded away, we’ve successfully maneuvered through the tough times and survived, stronger and smarter.” The Inc 500 award is one of several recent growth announcements from Atlantic.Net. Last week, the company announced it had doubled its sales presence and added a sales manager in its Orlando office. In September, the company announced it had expanded its Southeastern network reach through an agreement with Progress Telecom, a Florida-based provider of wholesale broadband services and a subsidiary of Progress Energy. The agreement also enables the company to pass along additional customer benefits including cost savings, faster provisioning, greater scalability and priority customer support. “We’re extremely excited about the opportunities that lie ahead,” said Cameron Clayton, the company’s director of sales and marketing. “We’re financially stable and profitable, we offer technologically superior products and outstanding customer service and we have shown a unique ability to adapt quickly to changes in the marketplace in order to meet our customers’ needs. More than ever before, we’re in a position to give customers across Florida and the Southeast the power to choose an Internet provider that will be around to serve their needs today and tomorrow.” Atlantic.Net offers high-speed Internet access, Web site services, telecommunications and dial-up.  To learn more about Atlantic.Net, call 1-866-618-3282 or visit https://www.atlantic.net. ## About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over it’s first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting , Web design and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net has state of the art fast [SSD Fast Cloud servers](https://www.atlantic.net/vps-hosting/)offering the very best in [cloud hosting](https://www.atlantic.net/vps-hosting/) solutions, one click WordPress cloud hosting and many other services. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [www.atlantic.net](https://www.atlantic.net/vps-hosting/). --- # Atlantic.Net Launches SpamScope to Help Eliminate Junk E-mail > URL: https://www.atlantic.net/press-releases/atlantic-net-launches-spamscope-help-customers-eliminate-junk-e-mail/ | Published: 2002-11-21 | Updated: 2023-12-05 | Author: Editorial Team GAINESVILLE, Fla. (11/21/02) – Atlantic.Net (https://www.atlantic.net), one of the nation’s fastest-growing private companies and Florida’s largest privately held Internet service provider, today announced the launch of SpamScope, a powerful tool that filters out unwanted messages such as advertisements, hoaxes and pornography. The new feature is available exclusively to Atlantic.Net subscribers at no additional charge. Members can activate SpamScope or learn more about the tool by visiting http://www.spamscope.com. “SpamScope is a spammer’s worst nightmare,” said Marty Puranik, president and CEO of Atlantic.Net. “Now, Atlantic.Net members don’t have to waste time looking through junk e-mails to find the messages they really want to read. Plus, parents will appreciate that SpamScope filters out content that may be offensive or inappropriate for children.” Unlike spam-fighting tools offered by other national Internet service providers, Atlantic.Net’s SpamScope empowers subscribers to customize the way the tool works for them. Using a simple Web-based interface, [Atlantic.Net](https://www.atlantic.net/) members can login and access SpamScope’s many features: • Users can choose from a range of 20 different levels of protection to adjust SpamScope’s filtering strength to meet their needs. • Atlantic.Net members decide what happens to spam. They can send it to their inbox, route it to a separate folder to view later or destroy it forever. • SpamScope users can opt to receive a “Possible Spam” warning in the subject line of a junk e-mail. • When used along with Atlantic.Net Webmail, SpamScope helps members block computer viruses from unknown contacts. • With SpamScope, Atlantic.Net subscribers can blacklist spammers or ensure that messages from friends and family always get through. Atlantic.Net dial-up Internet service is available in more than 1,100 cities across the nation and in Canada. Atlantic.Net’s “Unlimited” account is just $19.95 per month and features 24/7 toll-free technical support, 10 e-mail accounts, personal Web space, a monthly newsletter and a portal. For more information or to sign up for an account, call 1-866-618-3282 or visit www.atlantic.net. ## About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over it’s first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting , Web design and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net has state of the art fast [SSD Fast Cloud servers](https://www.atlantic.net/vps-hosting/)offering the very best in [cloud hosting](https://www.atlantic.net/vps-hosting/) solutions, one click WordPress cloud hosting and many other services. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/cloud-platform/). --- # Atlantic.Net Offers High Speed Internet to Gainesville Residents > URL: https://www.atlantic.net/press-releases/atlantic-net-invites-gainesville-residents-try-high-speed-internet/ | Published: 2002-12-13 | Updated: 2024-03-04 | Author: Editorial Team GAINESVILLE, Fla. (12/13/02) – Atlantic.Net, Florida’s largest privately held Internet service provider, today announced an open invitation to Gainesville-area residents to be among the first to try the company’s new residential DSL service, a [high-speed Internet access](https://www.atlantic.net/vps-hosting/) offering for the home. Only the first 50 qualified households will get to participate in Atlantic.Net’s DSL “beta test,” a month-long trial period that enables a select group to try out the product before its release to the general public. Atlantic.Net DSL features speeds up to 2.3 Mbps — about 70 times faster than dial-up. The high-speed connection enables users to download Web pages faster, send large files and photos via e-mail and access rich content such as videos, games and music. When the product debuts in February 2003, service plans will range from $24.95 to $34.95 per month. However, during the trial period beta testers will enjoy the fastest speed available at the lowest rate. “Eight years ago, we were one of Gainesville’s first Internet service providers, bringing dial-up into the homes of local residents here and throughout North Central Florida,” said Marty Puranik, president, cofounder and CEO of Atlantic.Net. “It seems only natural for us to introduce our new DSL offering right here in our hometown, so our neighbors have the first chance to enjoy affordable high-speed Internet access.” Other standard features of Atlantic.Net DSL and dial-up accounts include 10 e-mail addresses, 15MB of personal Web space, a monthly newsletter and 24/7 toll-free technical support. Last month, Atlantic.Net announced another new member benefit called “SpamScope,” a tool that filters out unwanted e-mail messages such as advertisements, hoaxes and adult content. To sign up for Atlantic.Net’s DSL beta test, call 224-0136 in Gainesville or visit https://signup.atlantic.net/dsl. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over it’s first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting , Web design and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net offers the very best in [cloud hosting](https://www.atlantic.net/vps-hosting/) solutions, [one click WordPress cloud hosting](https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/), Linux and Windows Cloud hosting, and many other services. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # Atlantic.Net Opens Data Center in Orlando > URL: https://www.atlantic.net/press-releases/atlantic-net-opens-data-center-orlando/ | Published: 2003-02-06 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla. (2/6/03) – [Atlantic.Net](https://www.atlantic.net/) (https://www.atlantic.net), Florida’s largest privately held Internet service provider, today announced the company has opened a data center in Orlando, Fla. The facility, will serve as the hub of Atlantic.Net’s network operations and will be the company’s second largest employee base in Florida. “Our new data center is one of the premier colocation facilities in central Florida,” said Marty Puranik, president and chief executive officer of Atlantic.Net. “The center rounds out the total package Atlantic.Net provides its business customers — a complete suite of the highest-quality business solutions, backed by superior technology and responsive customer service. The data hub also allows us to bring a higher level of data services to the Orlando area, so businesses are no longer forced to look elsewhere in the U.S. to find a world-class facility to secure the information that is critical to their business.” “For us, this step is the culmination of our efforts this past year to introduce ourselves to central Florida and prove our commitment to serving the Orlando community,” Puranik said. “The center is a physical representation of the caliber of service Atlantic.Net has provided to residents and business customers for the past nine years. When customers visit this impressive facility, they’ll be able to see for themselves what Atlantic.Net is all about.” Built in 2000 at a cost of $14.5 million, the 25,000-square-foot facility combines sophisticated technology infrastructure with high-end hosting services to meet customers’ advanced online business needs. Among the numerous advancements in the facility are locking colocation cabinets, chain link cages and roof rights for antenna systems, as well as a state-of-the-art network operations center, a conference room and offices for Atlantic.Net staff. Atlantic.Net’s data center is secured 24 hours a day, seven days a week. Biometric palm scanners and proximity card readers control access to the facility and the colocation floor. The property is monitored via closed circuit digital cameras with 24-hour recording and 30-day digital video storage. Advanced monitoring devices constantly check the facility’s critical systems, and a VESDA air-sampling system and dry-pipe pre-action system provide zoned fire detection and suppression. Redundant AC/DC power and uninterruptible power supply (UPS) systems ensure that customer equipment is up and running even in the event of an extended utility failure. In addition, the center’s two-megawatt generator can run the entire site at full load for at least 24 hours without refueling. Environmental controls include heating, ventilation and air conditioning (HVAC) systems that regulate temperature and humidity throughout the facility. “The addition of the new data center in Orlando strengthens our presence in a significant market for technology and e-business,” said Cameron Clayton, director of sales and marketing. “As is our focus with all of our business solutions, we will continue to do our best to assist our customers with streamlining their hosting operations and eliminating the need to integrate multiple platforms and vendors, all in order to give them an edge in a very competitive marketplace.” [Atlantic.Net’s](https://www.atlantic.net/) data center is a “carrier neutral” facility, offering access to a variety of major service providers including Level 3 Communications, Time Warner Telecom, BellSouth, Progress Telecom, FPL FiberNet, Sprint, WorldCom and Cable & Wireless. In addition, customers can connect to Atlantic.Net’s own Cisco Powered Network, featuring multiple redundant connections to the Internet backbone. Headquartered in Gainesville, Fla., Atlantic.Net began establishing a presence in Orlando last year when the company opened an office in Maitland and was the first Internet service provider to introduce high-speed dial-up to the central Florida area. Last fall, Atlantic.Net doubled its local sales force and added a sales manager to the company’s growing Orlando team. Recently, [Atlantic.Net](https://www.atlantic.net/) was named the top Internet service provider in the Orlando Business Journal’s Book of Lists 2003. Atlantic.Net offers high-speed Internet access, Web site services, telecommunications and dial-up. To learn more about Atlantic.Net, call (866) 618-3282 or visit https://www.atlantic.net. ### About Atlantic.Net Launched in 1994 by two University of Florida students, Atlantic.Net is an Internet service provider offering high-speed Internet access, Web site solutions, telecommunications and dial-up. Atlantic.Net business services feature 24/7 network monitoring and connection to an optimized Cisco Powered Network — a designation reserved for the world’s top 1 percent of ISPs. Atlantic.Net has been named to the Inc 500 list of the nation’s fastest-growing private companies for three consecutive years. During the past nine years Atlantic.Net has acquired 13 Internet companies, has doubled or tripled revenues annually and has remained profitable every year since inception. Atlantic.Net’s staff has grown to nearly 100 employees who regularly participate in the Alachua County Guardian ad Litem drive to provide toys for needy children at Christmas and in local United Way and March of Dimes charity events. Atlantic.Net is headquartered in Gainesville, Fla. --- # Atlantic.Net Unveils New Web Site > URL: https://www.atlantic.net/press-releases/atlantic-net-unveils-new-web-site/ | Published: 2003-03-20 | Updated: 2026-03-02 | Author: Editorial Team GAINESVILLE, Fla. (3/20/03) – [Atlantic.Net](https://www.atlantic.net/) (https://www.atlantic.net) Florida’s largest privately held Internet service provider, today announced its newly redesigned Web site. The site’s new features include keyword search functionality and improved navigation. “Atlantic.Net has always had a reputation for providing fast, reliable Internet services to residents, and as our company becomes increasingly focused on our suite of business solutions, we felt our Web site should show visitors that Atlantic.Net can help them get connected at home and at work,” said Cameron Clayton, sales and marketing director. “With more graphics, improved navigation and interactive features, our site is more representative of Atlantic.Net’s personality and the direction we’re taking.” The site’s navigation has a “choose your own adventure” feel designed to help visitors find information quickly and easily. The home page gives customers a choice between services they can use at home or at work, yet all main sections are accessible from any page on the site. Perhaps the most exciting new feature, “Live Chat” is a tool that enables customers to get immediate answers to their questions while they browse the site. Visitors can send an instant message to an account executive to inquire about Atlantic.Net business services, and current members can get technical support or answers to billing questions. “The new user-friendly design reflects the company’s commitment to customer satisfaction, providing improved channels of communication for our partners,” said Clayton. “The new design and features make accessing Atlantic.Net and its expert staff easier than ever.” Atlantic.Net offers high-speed Internet access, Web site services, telecommunications and dial-up. To learn more about Atlantic.Net, call (866) 618-3282 or visit https://www.atlantic.net. ### About Atlantic.Net Launched in 1994 by two University of Florida students, [Atlantic.Net](https://www.atlantic.net/)is an Internet service provider offering high-speed Internet access, Web site solutions, telecommunications and dial-up. Atlantic.Net business services feature 24/7 network monitoring and connection to an optimized Cisco Powered Network — a designation reserved for the world’s top 1 percent of ISPs. Atlantic.Net has been named to the Inc 500 list of the nation’s fastest-growing private companies for three consecutive years. During the past nine years Atlantic.Net has acquired 13 Internet companies, has doubled or tripled revenues annually and has remained profitable every year since inception. [Atlantic.Net’s](https://www.atlantic.net/) staff has grown to nearly 100 employees who regularly participate in the Alachua County Guardian ad Litem drive to provide toys for needy children at Christmas and in local United Way and March of Dimes charity events. Atlantic.Net is headquartered in Gainesville, Fla. --- # Atlantic.Net CEO Named as Finalist in American Business Awards > URL: https://www.atlantic.net/press-releases/atlantic-net-ceo-named-finalist-american-business-awards/ | Published: 2003-04-03 | Updated: 2024-03-04 | Author: Editorial Team GAINESVILLE, Fla. (4/3/03) – [Atlantic.Net](https://www.atlantic.net/)President and CEO Manoj “Marty” Puranik was named a finalist today in the Best Executive category of the first-ever American Business Awards. Other Best Executive honorees include leaders of IBM, Ask Jeeves, Nextel Communications and Black Entertainment Television. Hailed as “the business world’s own Oscars” by the New York Post (September 22, 2002), The American Business Awards are the first national, all-encompassing business awards program honoring great performances in the workplace. “I am honored to be included among the distinguished business leaders named as finalists for this award,” Puranik said. “Their stories inspire me and their achievements challenge me every day. I want to thank the American Business Awards for celebrating all that is positive and promising in companies across our country.” Puranik co-founded Atlantic.Net (https://www.atlantic.net) in 1994 while he was a student at the University of Florida. Today, the company provides high-speed Internet access, Web services, telecommunications and dial-up to business and residential customers across the Southeast. Atlantic.Net is Florida’s largest privately held Internet service provider and is one of the nation’s fastest-growing private companies. “Individual awards never truly belong to an individual,” Puranik said. “I share this recognition with the entire Atlantic.Net team for their hard work and commitment, and for believing that together we can achieve great things. I am also grateful to the Atlantic.Net family of customers for their loyalty and for trusting us to keep them connected at home and at work. When I hear our customers talk about how the Internet has changed their lives, or how our business services are helping their employees work more efficiently, that’s when I really feel like Atlantic.Net is doing something special.” Nicknamed the Stevies™ for the Greek word “crowned,” the awards will be presented at a nationally broadcast show on Wednesday, April 30, at the Sheraton New York Hotel & Towers in New York City. The ceremony will be hosted by Charles Osgood, host of CBS News Sunday Morning and commentator for the CBS Radio Network, and will be broadcast nationwide on radio, and worldwide via the Internet, by Business TalkRadio. Members of the Awards’ Board of Distinguished Judges & Advisors and their staffs will select Stevie winners from among the finalists. The Board includes business luminaries such as Rich Karlgaard, publisher of Forbes, Bruce Nelson, chairman & CEO of Office Depot, marketing gurus Don Peppers and Martha Rogers, Anthony Robbins, Chairman & CEO of The Anthony Robbins Companies, Drew Schutte, publisher of Wired Magazine, Jeffrey Tarr, chairman & CEO of Hoover’s Inc., and Donald Trump, chairman, president and CEO of The Trump Organization. “We began The American Business Awards last year when the public perception of companies and business people was at a low point,” said Stevie Awards president and founder Michael Gallagher. “Our goal was to create a showcase for the best of American business, where the people and companies who don’t get enough recognition for their good work can be singled out and celebrated. We are so pleased that so many companies, large and small, participated in our first year and we look forward to honoring those who make American business the envy of the world.” ### About The American Business Awards A celebration of great performances in the workplace, The American Business Awards are the first national, all-encompassing business awards program. Honoring companies of all types and sizes and the people behind them, the Awards recognize outstanding leadership, innovation, perseverance, creativity, teamwork, and integrity through more than 40 categories. The first American Business Awards – nicknamed The SteviesTM from the Greek word for “crowned” – will be presented at an awards show in New York City on April 30. The program is overseen by a Board of Distinguished Judges & Advisors, which includes leading business executives, authors, and academics. Sponsors of the 2003 American Business Awards include Business TalkRadio, DHR International, Empire Media, Forbes, Hoover’s Online, Inc. Magazine, Miller Heiman, Selling Power Magazine, and Wired Magazine. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over it’s first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting , Web design and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net offers industry leading [Cloud hosting](https://www.atlantic.net/vps-hosting/), [Windows Cloud Hosting](https://www.atlantic.net/vps-hosting/), and many other services. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/vps-hosting/).   --- # Atlantic.Net Upgrades Service in Crystal River > URL: https://www.atlantic.net/press-releases/atlantic-net-upgrades-service-crystal-river/ | Published: 2003-04-25 | Updated: 2026-03-02 | Author: Editorial Team CRYSTAL RIVER, Fla. (4/25/03) – [Atlantic.Net](https://www.atlantic.net/), Florida’s largest privately held Internet provider, today announced upgrades in the Crystal River area that offer local residents faster and more versatile Internet access. “These improvements are the direct result of feedback we received from our members in Crystal River, and we are excited about delivering what they have asked for,” said Marty Puranik, Atlantic.Net president and CEO. “Because of these enhancements, Crystal River residents can finally get the speed they want, along with the superior customer service that Atlantic.Net is known to provide.” The upgrades utilize V.92 technology to give users faster connections and download times. The service also enables customers to put the Web “on hold” to answer incoming phone calls without disconnecting from the Internet. Besides saving members time, the “modem on hold” feature saves customers money by eliminating the need for a second phone line. To take advantage of Atlantic.Net’s upgrades, customers must use a V.92 modem and connect via a Crystal River local access number. For more information or to sign up for an Atlantic.Net Internet account, call (866) 618-3282 or visit www.atlantic.net. ### About Atlantic.Net Launched in 1994, [Atlantic.Net](https://www.atlantic.net/) is an Internet service provider offering high-speed Internet access, Web services, telecommunications and dial-up. Atlantic.Net business services feature 24/7 network monitoring and connection to an optimized Cisco Powered Network — a designation reserved for the world’s top 1 percent of ISPs. Atlantic.Net has been named to the Inc 500 list of the nation’s fastest-growing private companies for three consecutive years. During the past nine years Atlantic.Net has acquired 13 Internet companies, has doubled or tripled revenues annually and has remained profitable every year since inception. Atlantic.Net’s staff has grown to nearly 100 employees who regularly participate in the Alachua County Guardian ad Litem drive to provide toys for needy children at Christmas and in local United Way, American Cancer Society and March of Dimes charity events. [Atlantic.Net](https://www.atlantic.net/) is headquartered in Gainesville, Fla. with an office and tier-one data center in Orlando. --- # Atlantic.Net Acquires Feature Price, a Florida web hosting provider > URL: https://www.atlantic.net/press-releases/atlantic-net-acquires-feature-price-florida-based-web-hosting-service-provider/ | Published: 2003-05-22 | Updated: 2024-03-04 | Author: Editorial Team GAINESVILLE, Fla. (5/22/03) – [Atlantic.Net](https://www.atlantic.net/), Florida’s largest private Internet service provider and one of the nation’s fastest-growing private companies, today announced it has acquired a customer base of 40,000 and other assets of Feature Price, a Web hosting service provider based in Ft. Myers, Fla. Terms of the transaction were not disclosed. “In Feature Price, we saw an opportunity to grow our Web hosting customer base and to improve the level of service and the overall experience for Feature Price customers,” said Marty Puranik, president and CEO. “We are excited about providing reliable hosting services and responsive customer support for our new customers during the transition period and in the future, and we look forward to serving all their Web hosting needs.” Atlantic.Net is providing two months of free Web hosting service for all Feature Price customers and honoring the prepaid service for customers on the company’s Premium and Platinum hosting plans. Feature Price customers can learn more about switching to Atlantic.Net by visiting https://www.atlantic.net. Today’s news follows an announcement in February that Atlantic.Net had opened a tier-one data center in Orlando, Fla. Built in 2000 at a cost of $14.5 million, the 25,000-square-foot facility combines sophisticated technology infrastructure with high-end hosting services to meet customers’ advanced online business needs. Atlantic.Net offers high-speed Internet access, Web services, telecommunications, and dial-up. For more information, visit www.atlantic.net or call toll-free (877) GO-ATLANTIC (462-8526). ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over it’s first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting , Web design and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net offers state of the art [cloud servers](https://www.atlantic.net/vps-hosting/), one-click applications like WordPress, [Windows Cloud Hosting](https://www.atlantic.net/vps-hosting/), among many other services. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # AAA and Atlantic.Net Team Up to Offer Discounted Internet Access > URL: https://www.atlantic.net/press-releases/aaa-atlantic-net-team-offer-discounted-internet-access/ | Published: 2003-07-01 | Updated: 2024-03-04 | Author: Editorial Team TAMPA, Fla. (7/1/03) – AAA Auto Club South (aaa.com) today announced a major partnership with [Atlantic.Net](https://www.atlantic.net/)(atlantic.net), a national Internet service provider and one of the nation’s fastest-growing private companies. Through the alliance with AAA’s Show Your Card & Save® program, AAA members will enjoy a reduced rate of $15.95 monthly on Atlantic.Net’s Unlimited Dial-Up account, which represents a savings of 20% savings off the regular $19.95 per month. “We’re very excited to partner with Atlantic.Net,” said Bill Latta, vice president of AAA member benefits and financial services. “Discounted internet service perfectly complements the other products and services available through our Show Your Card & Save program.” Atlantic.Net’s Unlimited Dial-Up account features 10 e-mail addresses, 15 MB of personal Web space, a portal, monthly newsletter, Web-based e-mail and SpamScope, a junk e-mail filter. Member Services representatives provide technical support and customer service for Atlantic.Net members 24 hours a day, seven days a week. Atlantic.Net has local access numbers in more than 3,500 cities across the United States and in Canada. “We are proud to be the Internet provider AAA Auto Club South has chosen to recommend to members,” said Marty Puranik, Atlantic.Net president and CEO. “We look forward to a long-term relationship with the AAA team and to serving its members with fast, reliable Internet services and exceptional customer care.” To take advantage of Atlantic.Net’s exclusive offer for AAA members, please visit aaa.com and click on ‘Savings’, or call toll-free 1-866-618-3282. ### About AAA Auto Club South AAA Auto Club South is the third-largest affiliate of the AAA federation. The Show Your Card & Save program offers AAA members discounts on shopping, dining, entertainment, and more at over 60,000 locations in the U.S., Canada, Mexico, and Europe. Its more than 3.5 million members are located in Florida, Georgia, and the western two-thirds of Tennessee. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over its first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long-distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting, Web design, and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award-winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net offers state of the art [Cloud Hosting](https://www.atlantic.net/vps-hosting/) Solutions, one-click applications like WordPress, and [Managed Cloud Hosting](https://www.atlantic.net/vps-hosting/), among many other services. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # Atlantic.Net chose to use Progress Telecom’s Enhanced Ethernet > URL: https://www.atlantic.net/press-releases/progress-telecom-enhanced-ethernet-chosen-atlantic-net/ | Published: 2003-08-26 | Author: Editorial Team ST. PETERSBURG, Fla (8/26/03) — Progress Telecom, a leading provider of broadband services, has announced that Atlantic.Net, one of the nation’s fastest-growing private Internet service providers, has purchased the company’s new Fast Ethernet service. [Atlantic.Net](https://www.atlantic.net/) worked with Progress Telecom to develop the initial product requirements and is now using the service to connect three Orlando metro sites to its new tier-one data center. The order closely follows the launch of Progress Telecom’s newly expanded Ethernet portfolio. Progress Telecom now can provide point-to-point, high speed Ethernet transport at rates ranging from 10Mbps to 1 Gbps, offering customers maximum flexibility. Services are offered throughout the company’s expansive network, both metro and long haul. “Our Ethernet services package, combining the simplicity of traditional Ethernet service with the speed and reliability of an optical network, is available throughout our extensive East Coast network, ” said Ron Mudry, president and CEO. “We’re delighted Atlantic.Net has signed on for Fast Ethernet, becoming the first company to take advantage of our expanded portfolio. Our Ethernet services are scaleable, giving our customers flexibility to grow bandwidth along with their businesses—quickly, simply and efficiently. We anticipate that the package will be popular with carriers, ISPs and ASPs, as well as high-end enterprises that face the need to transport large volumes of data.” The applications for Progress Telecom’s Ethernet services are numerous, enabling high speed Internet access and interconnection between switches, as well as connectivity between data centers and carrier hotels.Notably, they provide cost-effective, reliable connectivity between Storage Area Networks within a metro.Such networks are growing rapidly. “Progress Telecom’s Fast Ethernet provides the perfect combination of decreased latency, improved speed, cost-effectiveness and a simpler configuration to accommodate our growth and to ease network management,” said J. Neal Hiscock, Atlantic.Net’s director of operations. “Atlantic.Net is a fast-growing, innovative technology company and has a large customer base with demanding bandwidth requirements. We are excited to have the opportunity to collaborate with the Progress Telecom team to develop this new product which is well-suited for our needs.” Progress Telecom’s Ethernet services are backed by industry-leading Service Level Agreements (SLAs), including a network reliability of 99.9 percent. The company’s hurricane-hardened Network Operations Center is fully redundant and staffed around the clock with highly trained and experienced technicians ensuring industry-leading trouble resolution and repair intervals. ### About Progress Telecom Founded in 1998, Progress Telecom provides broadband telecommunications services throughout the Eastern United States. Progress Telecom incorporates approximately 135,000 fiber miles and 8,230 route miles in its network including over 165 Points-of-Presence (POPs). The fiber network serves as the backbone of OC-192 transport that allows customers enhanced data transport capabilities in the Eastern United States from New York to Miami, FL, in first, second and third-tier growth markets and access to Latin America through its International Gateways. The network’s utility-based infrastructure also offers fast local loop access through metro fiber rings that move broadband capacity closer to the customer with 10 gigabit dense wave division multiplexing (DWDM) technology.The company is headquartered in St. Petersburg, FL; it has a sales presence in Miami and an office in Raleigh, N.C., which provides sales, engineering, IT and field personnel serivces. Progress Telecom is owned by Progress Energy (NYSE: PGN), a Fortune 250 diversified energy company headquartered in Raleigh with more than 23,000 megawatts of generation capacity and $8 billion in annual revenues. For more information about Progress Telecom, visit the company’s website at http://www.progresstelecom.com ### About Atlantic.Net Launched in 1994, [Atlantic.Net](https://www.atlantic.net/)is an Internet service provider offering high-speed Internet access, Web services, telecommunications and dial-up. Atlantic.Net business services feature 24/7 network monitoring and connection to an optimized Cisco Powered Network — a designation reserved for the world’s top 1 percent of ISPs. [Atlantic.Net](https://www.atlantic.net/) has been named to the Inc 500 list of the nation’s fastest-growing private companies for three consecutive years. During the past nine years Atlantic.Net has acquired 15 Internet companies, has doubled or tripled revenues annually and has remained profitable every year since inception. Atlantic.Net’s staff has grown to nearly 100 employees who regularly participate in the Alachua County Guardian ad Litem drive to provide toys for needy children at Christmas and in local United Way, American Cancer Society and March of Dimes charity events. [Atlantic.Net](https://www.atlantic.net/) is headquartered in Gainesville, Fla. with a tier-one data center in Orlando and a sales office in Tampa. --- # Atlantic.Net Offers Low Cost High Speed Internet for Gainesville > URL: https://www.atlantic.net/press-releases/atlantic-net-launches-low-cost-high-speed-internet-service-gainesville-residents/ | Published: 2003-10-07 | Updated: 2024-03-04 | Author: Editorial Team GAINESVILLE, Fla. (10/7/03) — [Atlantic.Net](https://www.atlantic.net/vps-hosting/) (https://www.atlantic.net), Florida’s largest privately held Internet service provider, today announced the launch of its new High Speed Internet access available only to Gainesville residents. Priced at $24.95 monthly, the service features speeds up to 2.3 Mbps – about 70 times faster than dial-up. Utilizing DSL (Digital Subscriber Line) technology, the high-speed connection enables users to download Web pages faster, send large files and photos via e-mail and access rich content such as videos, games and music. “We are excited about launching this service in our hometown of Gainesville and bringing our neighbors what we believe is the fastest, most competitively priced high speed Internet offering around,” said Adnan Raja, Atlantic.Net product manager. Other standard features of Atlantic.Net DSL and dial-up accounts include 10 e-mail addresses, 15 MB of personal Web space, a monthly newsletter and 24/7 toll-free technical support. The service also includes Atlantic.Net’s exclusive “SpamScope,” a tool that filters out unwanted e-mail messages such as advertisements, hoaxes and content that may be inappropriate for children. Customers can sign up for the service online at https://www.atlantic.net or by calling (352) 375-2912. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over it’s first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting , Web design and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net offers the very best in [cloud hosting](https://www.atlantic.net/vps-hosting/) solutions, one click WordPress cloud hosting [Fast SSD Cloud Hosting services](https://www.atlantic.net/vps-hosting/), and many others. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # Atlantic.Net Introduces “Groove” > URL: https://www.atlantic.net/press-releases/atlantic-net-introduces-groove/ | Published: 2005-04-26 | Updated: 2026-03-02 | Author: Editorial Team [Atlantic.Net](https://www.atlantic.net/) Introduces “Groove” — The New Communication Solution for Market Leading Businesses Everywhere - New services allow companies to do business in entirely new ways - Saves money on direct telecommunications costs and other hidden costs associated with legacy communication solutions - Extremely flexible, allowing customers to focus on growing and expanding their business instead of managing multiple products from multiple vendors - Integrated Intelligence includes Voice-over-IP (VOIP) standard, and disaster recovery at no additional cost - Service is available in any mix of PBX Service, Local/Long-Distance Service (VOIP or traditional voice such as PRI/PSTN), ISP, and Web-Based Services   Orlando, Fla. (4/26/05) — Atlantic.Net (https://www.atlantic.net) today announced the launch of its new communications solution “Groove” to the business marketplace. Groove, available in various configurations, is composed of telephones, a PBX, Web-based communication services, and back-office support. When purchased as a total solution, Groove unifies and simplifies communications by providing four major telecom services under one umbrella: Internet service, local telephone service, long-distance telephone service, and PBX (Business Telephone System) services. Groove is designed to be extremely flexible, allowing customers to purchase only the services they need. For example, a business can maintain local telephone service with a traditional voice company while using Groove for VOIP (“Voice over IP”) to lower long-distance costs. “When we designed Groove, we addressed many of the irritations of how telephony is used today”, stated Marty Puranik, Atlantic.Net CEO. “Because traditional telephony was designed inside a monopoly environment, it wasn’t customer-centric. We have completely reinvented how communications works. Whats really exciting is that for the first time in history we have a company and product in telecom that is designed around the customer – meaning it allows you to do things you couldn’t do before, with flexibility and less hassle than you had in the past. What we’re about is changing telecom from a service you have to suffer through into something that becomes a competitive advantage. It really is encapsulated in the name Groove – a product that makes business run smoother, eliminates hassles and hidden costs, and is flexible enough to address new technologies like VOIP without having to pay extra or continuously upgrade. It’s really exciting to bring a solution to market that addresses so many of the challenges that exist today and delivers real bottom line savings. Most importantly, instead of dealing with the mental pain associated with telecom, businesses can focus on being more productive – selling more, marketing more effectively, and doing more with what they’ve got.” How are businesses using Groove today? A key employee is in need of flexible scheduling. Using Groove, her employer is able to accommodate this employee by allowing her to take her phone home. Using VOIP (at no additional charge) customers, vendors, and other employees continue to conduct business with her without interruption. The employee is pleased with the company’s flexibility and the business gains a competitive advantage in the marketplace by [attracting and retaining the best and brightest employees](https://recruitcrm.io/blogs/high-employee-retention-strategies/). Using a software based web phone, sales consultants turn their laptops into ‘virtual’ phones to connect to the office PBX and transparently make and receive calls to important clients from remote locations such as airports or coffee shops. Employees are able to change offices, simply by taking their phone and plugging in at the new location, literally a 30 second process. Normally, companies would have to schedule a PBX vendor to move/add/replace the current configuration and pay associated fees with the truck-roll and re-wiring. A company is interested in hiring an individual who won’t be moving to the local market for a few months. The company is able to hire the employee today by mailing a phone to them. The employee commences work several months before moving to the local office and is able to seamlessly continue working without interruption. “Cloning”, or allowing a phone to ring in multiple places at the same time, allows busy professionals to work from multiple locations. One executive cloned her desk phone to use at her home office as well as a branch location. This allowed the executive to continue to conduct business from any location, independent of where she physically is located. Groove is available today. For more information please visit www.gogroove.com or call toll-free at 1-866-55-GROOVE. ### About Atlantic.Net Launched in 1994 by two University of Florida students, Atlantic.Net is a IP-based solutions provider operating a Tier-1 Data Center in Orlando, Florida. Atlantic.Net business services feature 24/7 network monitoring. Atlantic.Net’s vision is to be “the intelligence behind the network” and focus on providing innovative solutions at a competitive price with fantastic service. --- # Atlantic.Net’s Revenue Rockets up 38 Percent in 1st Quarter > URL: https://www.atlantic.net/press-releases/atlantic-net-data-center-revenue-rockets-38-percent-first-quarter/ | Published: 2008-04-22 | Updated: 2024-03-01 | Author: Editorial Team Orlando, Fla. (April 22, 2008) – Avoiding the national trend of a struggling economy, [Atlantic.Net](https://www.atlantic.net/vps-hosting/), a leading data center and managed services provider with headquarters in Maitland, Fla., has announced a 38 percent increase in core data center revenue during the first quarter of 2008. The privately owned company, founded in 1994, first burst onto the national scene in 2000 when fast-paced growth landed it on Inc. magazine’s “Inc. 500” list of America’s fastest-growing private businesses, a distinction the company would go on to repeat multiple times. While other dot-com era companies eventually became victims of unsound business principles, Atlantic.Net has continued to thrive and grow by staying one step ahead in the ever-changing technology game. Originally focused solely on providing Internet access, Atlantic.Net has broadened its offerings for businesses to simplify implementation of the latest technology. “To continue to be a leader in the industry, we believe that you have to have a strong vision of the future and always be looking around the corner for the next big thing,” said Marty Puranik, company founder, president and CEO. “Our profitability has enabled us to invest in new product initiatives when our competitors can’t.” Atlantic.Net moved its primary operations from Gainesville to Orlando in 2003, opening a 25,000-square-foot secure data center, and shifted its focus to the fast-growing business of dedicated servers, server colocation and managed services. A recent $250,000 data center power upgrade demonstrates Atlantic.Net’s constant commitment to deliver the technologically advanced infrastructure and scalability that is critical in today’s marketplace. “Our sound business principles have allowed us to remain debt free and generate the capital to make continued investments in the company,” Puranik said. “We offer a colocation facility that is unequaled in terms of power, cooling and bandwidth anywhere in Central Florida and by only a handful of locations across the country. This is an important part of our long term business plan, and we are committed to continuing to grow this portion of our business.” As it looks toward the future, Atlantic.Net continues to fulfill the technology needs of its business customers, offering digital business phone systems, data backup, security, Internet connectivity and business continuity. The company also continues to have an eye toward the future. “We are developing a series of new products that we think are really going to knock people’s socks off,” Puranik said. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over it’s first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting , Web design and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net offers industry leading[cloud hosting](https://www.atlantic.net/vps-hosting/), [managed cloud Hosting](https://www.atlantic.net/vps-hosting/), and many other services. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # HD Publishing Group Selects Atlantic.Net For Data Center Services > URL: https://www.atlantic.net/press-releases/hd-publishing-group-selects-atlantic-net-data-center-services/ | Published: 2008-10-29 | Author: Editorial Team Orlando, FL (October 29, 2008) – [Atlantic.Net](https://www.atlantic.net/) (www.atlantic.net), a privately-owned high performance data center services company, today announced a multi-year agreement with HD Publishing Group, an online leader in search service intelligence. Under the terms of the agreement, [Atlantic.Net](https://www.atlantic.net/) will provide HD Publishing Group with a fully redundant server colocation platform to support mission-critical applications in Atlantic.Net’s world class data center facility. “HD Publishing Group’s experience at providing highly-available and cost-effective online public record search services is unmatched,” said Neal Hiscock, Atlantic. Net’s chief operating officer. “We are proud to have earned HD Publishing Group’s trust to help protect their intelligent systems which are essential for any search technology company. This is a perfect partnership between two dedicated and growing Florida businesses.” HD Publishing Group (www.hdpublishinggroup.com), based in Deland, FL, exemplifies the new generation of information technology companies. To cope with its fast growth and the need for a scalable solution, HD Publishing Group required a technology partner that could provide a reliable and secure network infrastructure and guarantee 100% uptime and network availability. “The engineers at Atlantic.Net are top notch,” said Roy Johnson, Chief Information Officer of HD Publishing Group. “Our business relies on 100% network uptime and Atlantic. Net’s world class data center facility right in our backyard; operates at a level we haven’t seen in other facilities. The fact Atlantic.Net has been around since 1994 and operates a profitable business with extremely low debt adds an extra layer of security in today’s tough business environment.” ### About Atlantic.Net Established in 1994, Atlantic.Net is a market-leading business data services provider known for exceptional service, simplifying complex technologies and building a brand that people trust. Atlantic.Net operates a 25,000-square-foot colocation data center in Central Florida and helps businesses around the globe with their advanced online needs through services including dedicated servers, server colocation, Internet connectivity, business continuity, and managed services such as data backup, security and private networks. Atlantic. Net’s services enable companies to focus on their core business and forgo the expense of capital equipment purchases and ongoing IT management costs. The company’s technological savvy and strategic acumen have been the foundation for the company’s reputation and profitability since 1994. ### About HD Publishing Group Since 1996, HD Publishing Group has offered the most comprehensive public record search services available, providing customers with high-quality results for people searches, reverse phone number searches, background checks, financial information and court records, to name a few. Long before individual states made “Sex Offender” databases available, HD Publishing Group’s dedicated programmers had created a searchable database with maps and new alerts that was the leader in bringing this information to the general public. Still today, it remains the premier database for a “one stop” view of the country’s registered sex offenders. --- # Atlantic.Net Launches Business Partner Program > URL: https://www.atlantic.net/press-releases/atlantic-net-launches-business-partner-program/ | Published: 2008-11-25 | Updated: 2026-03-02 | Author: Editorial Team Orlando, FL (November 25, 2008) – Atlantic.Net ([www.atlantic.net](https://www.atlantic.net/)), a privately owned high-performance Data Center services company, is pleased to announce the launch of its Worldwide Business Partner Program. The program enables technology integrators, application service providers, and other technology firms to grow their business and expand and enhance their product lines. Atlantic.Net’s services include [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/), [server colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/), and managed services. By joining Atlantic.Net’s program, Business Partners can benefit from an unmatched technical expertise and the most competitive commission structures in the industry. “Atlantic.Net is the absolute best Data Center operation we have ever worked with,” said Bill Harris, president of Trade Web, an Information Solutions Company and Atlantic.Net Reseller Partner. “Atlantic.Net brings much more to the table than just revenues and commissions. They bring the essential expertise and intellect to help Partners with value added products, which is hard to come by. We trust Atlantic.Net; we always know they will take care of us and our customers.” Among the benefits of becoming an Atlantic.Net Business Partner are the ability to leverage Atlantic.Net’s multi-million dollar Data Center facility and the opportunity to work with a growing, financially stable and efficient company. To learn more or to apply, visit www.atlantic.net or call 866.618.DATA. “[Atlantic.Net](https://www.atlantic.net/) stands behind its commitment to strengthen business alliances and partnerships with technology minded companies around the globe,” said Adnan Raja, Atlantic.Net’s business development director. We recognize the key role our partners play in our success and much of Atlantic.Net’s business is referral and this program recognizes and rewards our clients’ loyalty. With the goal of becoming the best team in the industry, we’re creating a win-win-win scenario for the end customer, our business partners and Atlantic.Net.” ### About Atlantic.Net Established in 1994, Atlantic.Net is a market-leading business data services provider known for exceptional service, simplifying complex technologies and building a brand that people trust. Atlantic.Net operates a 25,000-square-foot colocation Data Center in Central Florida and helps businesses around the globe with their advanced online needs through services including dedicated servers, [server colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/), Internet connectivity, business continuity, and managed services such as data backup, security and private networks. Atlantic.Net’s services enable companies to focus on their core business and forgo the expense of capital equipment purchases and ongoing IT management costs. Atlantic.Net’s technological savvy and strategic acumen have been the foundation for its reputation and profitability since 1994. --- # NBA’s Orlando Magic Selects Atlantic.Net as Official Server Host > URL: https://www.atlantic.net/press-releases/orlando-magic-selects-atlantic-net-official-server-host/ | Published: 2009-03-18 | Updated: 2023-11-15 | Author: Editorial Team Orlando, FL (March 18th, 2009) – [Atlantic.Net](https://www.atlantic.net), a privately owned high performance Data Center services company, is proud to announce a newly formed partnership with the National Basketball Association’s (NBA) Orlando Magic. Under the terms of the agreement, Atlantic.Net will provide the Orlando Magic with a fully redundant server hosting platform in its world class Data Center. As the official server host of the Orlando Magic, Atlantic.Net will support and protect the data operations of the popular NBA franchise. “We are excited to have joined forces with Atlantic.Net,” said Jason Coleman, Orlando Magic’s VP of Information Technology. “After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge. Atlantic.Net’s Data Center is very impressive, and their experience in providing a high-level of managed services is what our organization was looking for.” The Orlando Magic plans a significant deployment of server and network hardware at Atlantic.Net, including a Storage Area Network (SAN), and therefore requires a hosting partner capable of providing the highest quality infrastructure, bandwidth and redundancy. Such large scale, high-performance operations require 100% uptime and the kind of complex, high-end infrastructure found in Atlantic.Net’s Data Center. “Atlantic.Net respects and admires the Orlando Magic for their innovation and their commitment to staying ahead of the game in technology,” said Marty Puranik, president and CEO of Atlantic.Net. “We are honored that the Orlando Magic put their trust in Atlantic.Net and look forward to working as a team to supply the critical backend infrastructure that guides the ongoing success of the Magic’s operations.” As a service provider that owns and operates its own network and Data Center, Atlantic.Net provides fully redundant connections to the Internet backbone and guarantees 100% uptime by providing uninterruptible power feeds in a secure and fully redundant Data Center that is staffed 24/7/365. ### About The Orlando Magic Orlando’s NBA franchise since 1989, the Magic’s mission is to be world champions on and off the court, delivering legendary moments every step of the way. On the court, Orlando has won three division championships (1995, 1996, 2008), had four 50-plus win seasons, and won the Eastern Conference title in 1995. Off the court, on an annual basis the Orlando Magic gives more than $2 million to the local community by way of sponsorships of events, donated tickets, autographed merchandise, scholarships and grants. Orlando Magic community relations programs impact an estimated 75,000 kids each year, while a Magic staff-wide initiative provides more than 4,000 volunteer hours annually. In addition, over the last 19 years nearly $14 million has been distributed to local non-profit community organizations via The Orlando Magic Youth Fund (OMYF) that serve at risk and disadvantaged youth. The Orlando Magic is also the developer of the new downtown Events Center which will compete to host major national events, concerts and family shows. Opening in October 2010, the facility will be operated by the City of Orlando and owned by the Central Florida Community. ### About Atlantic.Net Established in 1994, Atlantic.Net is a market-leading business data services provider known for exceptional service, simplifying complex technologies and building a brand that people trust. Atlantic.Net operates a world class [cloud hosting](https://www.atlantic.net/vps-hosting/)Center in Orlando, Florida, and helps businesses around the globe with their data needs through services including managed servers, server colocation,[managed cloud hosting](https://www.atlantic.net/vps-hosting/), Internet connectivity, business continuity, and managed services such as data backup, security and private networks. Atlantic.Net’s services enable companies to focus on their core business and forgo the expense of capital equipment purchases and ongoing IT management costs. The company’s technological savvy and strategic acumen have been the foundation for the company’s reputation and profitability since 1994. For more information about Atlantic.Net, please visit www.atlantic.net. --- # Announcement: BarCamp Orlando 2009 > URL: https://www.atlantic.net/announcements/barcamp-orlando-2009/ | Published: 2009-04-20 | Updated: 2026-01-09 | Author: Alexander Wise This was a fantastic BarCamp event.  It feels so good to be involved in such a [good grass-roots technology platform](https://www.atlantic.net).  Josh and I spent most of the day attending various presentations and seminars.  There were 300 people registered for this year’s event, and  more than 400 people showed up.  This was a huge success for Central Florida’s digital media scene.* * I personally liked the SEO seminar and the seminar by Etan of the [Orlando Sentinel](http://www.orlandosentinel.com/) .  Etan did a great job speaking on the future of newspapers and was able to put it in perspective; the future is the web and print media is pretty much history. This particular session was heavy on information, yet interactive.  Etan was able to engage the audience in more of a discussion rather than just give another drab lecture.  It was quite interesting learning about the future of our local newspaper.  Attending BarCamp felt as if most local businessmen and technology gurus had come together to offer their personal advice for improving our newspaper.  One of the ideas discussed was: creating a forum which would allow a discussion platform for our readers, taking the comments section to a whole new level! Another good idea was to allow printable coupons, helping the local community, while creating a profitable channel for the Sentinel to increase traffic to their site.  I also offered an idea about the local sponsored events, which was heavily promoted by the local paper.  Such events can bring the community together and take the forum and discussions to the next level. We enjoyed free food and nice weather.  We took pleasure in the food and sun! We also attended a seminar about Healthcare IT and how this will be the future.  It was interesting to see the enthusiasm of the speaker, but deep down in my heart, I realized private enterprise does not want to get involved in a regulated industry where the rules can change overnight destroying business models. This event was held on a Saturday morning at the “Wall-Street Plaza” in Downtown Orlando.  I was surprised with two parking tickets courtesy of The Great City of Orlando.  As I was leaving the area; I saw a busy crew printing tickets like there was no tomorrow!  I later called Josh and he reported having received tickets as well.  I think the city must have changed the free Saturday parking.  At any rate, I must congratulate the management of BarCamp Orando on putting together such a great event.  I look forward to many more in the near future! Atlantic.Net has been serving the Orlando area’s web hosting, internet access, and now, state-of-the-art cloud hosting for over 30 years.   As technology innovates and changes so do we and our cloud servers are the[industry-leading fast SSD servers](https://www.atlantic.net/vps-hosting/) delivering 100 percent uptime and making one-click cloud applications like LAMP cloud hosting,  as easy as possible.   We are proud to be an Orlando resource.  Contact Atlantic.Net for all of your hosting needs. --- # Atlantic.Net and the Orlando Magic – A Winning Combination! > URL: https://www.atlantic.net/announcements/atlanticnet-and-the-orlando-magica-winning-combination/ | Published: 2009-05-22 | Updated: 2026-01-09 | Author: Alexander Wise Earlier this year, Atlantic.Net announced a formal partnership with the Orlando Magic. Atlantic.Net became the official server host of the Orlando Magic, powering key IT infrastructure of the Orlando Magic. Everyone at Atlantic.Net was very excited and proud to be named the Official Server Host of the Orlando Magic and to  protect their data in our world class data center facility. ## **The Excitement around town!** As you can imagine, all of Orlando is gearing up for the first home game of the Eastern Conference Finals. It seems like everywhere you turn around town, you see “Go Magic!” signs and Godzilla-sized banners of Hedo Turkoglu, Dwight Howard, and Rashard Lewis adorning the downtown skyscrapers. ## **Great Opportunities!** Thanks to the partnership, we were able to network with the international basketball players and had a lot of fun! As a proud partner of the Orlando Magic, we are often involved in special events with the organization. At one of the recent events, we had the opportunity to hangout and get to know our team during a fun filled night of casino games and shenanigans. Whether we were playing blackjack, roulette, or just rolling the dice, everyone had a great time and the Magic players were nothing short of awesome to hang out with. ## **Go Magic!** Hedo Turkoglu and Mike Wilks were on fire at the roulette table, Jameer Nelson, who was celebrating his birthday, could do no wrong at the black jack table, and Dwight Howard, Superman himself, was cutting up the rug and singing on the dance floor. You just don’t know how funny and humble this group of guys is until you spend some time with them. They are truly Champions on and off the court. ## **Eastern Conference Champions!** Game 1: Orlando 107, Cleveland 106 Game 2: Orlando 95, Cleveland 96 Update: 05/26/09 Game 3: Orlando 99, Cleveland 89 Game 4: Orlando 116, Cleveland 114 Update: 05/29/09 Game 5: Orlando 102, Cleveland 112 Update: 06/01/09 Game 6: The Orlando Magic Won the Eastern Conference Title! Orlando 103, Cleveland 90 Next Stop: The NBA Finals! Go Magic!   Atlantic.Net has been serving the Orlando area’s web hosting, internet access and now, [state-of-the-art VPS hosting](https://www.atlantic.net/vps-hosting/) for over 30 years.   As technology innovates and changes so do we, and our cloud servers are the industry-leading fast SSD servers delivering 100 percent uptime and making one-click cloud applications like cPanel Hosting as easy as possible.   We are proud to be an Orlando resource.  Contact Atlantic.Net for all of your hosting needs including managed, dedicated and [HIPAA compliant](https://www.atlantic.net/hipaa-compliant-hosting/)solutions. --- # Server Disposal: How to Dispose of Old Computers and Servers > URL: https://www.atlantic.net/hipaa-data-centers/server-disposal/ | Published: 2009-07-09 | Updated: 2026-03-01 | Author: Alexander Wise Several weeks ago, it was decided across the board that I needed a fast computer for my daily activities here in our corporate office.  I contacted our NOC, told them what I wanted, and a few days later, a shiny new desktop sat atop my desk. I took care of all of the necessary transfer of data and whatnots and politely asked the guys, “So what do you want me to do with this dinosaur? Toss it?” They looked at me like I had a third eye and quickly informed me that there are “proper” ways to dispose of your computer. Gently removing it from my death grip, they carried it out of my office, never to be seen again. ## So what actually happens to old IT equipment? So there I stood, with empty hands, and I began to wonder what in the world they were going to do with it. What about all of that customer data (possibly the reason they refused to leave it)? I’ve seen Forensic Files one time too many, where some ridiculously smart computer guru can retrieve data from a suspect’s computer, uncovering hard-core evidence which implicates the suspect.  I also began to think about what would happen if that information got into the wrong hands (flashback to the 1995 film [The Net](http://www.imdb.com/title/tt0113957/) with Sandra Bullock). Were they going to try to rebuild it? “Gentlemen, we can rebuild. We have the technology. …. Better than before…. Better, stronger, faster.”- anyone remember [The Six Million Dollar Man](http://www.imdb.com/title/tt0071054/)?  Since my inquiring mind and overactive imagination wanted to know, I spoke with Joe Cosmano, Director of Engineering, and Josh Simon, Director of Data Center Services at Atlantic.Net, to find out what to do with old computers to ensure that they are either disposed of properly or rebuilt to become the Six Million Dollar Machine. Below are some of the questions I asked and the answers I received. ## What methods are considered best for the disposal of outdated or unwanted computer hardware, and what are the main considerations for businesses evaluating those options? ### Outsourcing to a disposal company Numerous companies specialize in recycling and disposal of equipment. Organizations that decide to outsource should use caution to ensure that all the data is securely wiped from all storage devices. Proper documentation should be requested from the disposal company to ensure effective controls are in place to guarantee compliance with all state and federal regulations. Additionally, there are paid services that will handle the pickup, and there are some pickup services that actually pay for outdated or unneeded computers. Negligence of disposal and improper disposal can become a serious liability for your company even if the disposal service contractor does not deliver on its promise. ### Donating the parts to charity/non-profit Easy and commonsense steps to ensure all data is securely wiped can help avoid security breaches that may otherwise compromise business security.  Local charities with experience reconstituting used computer equipment are often the best and easy option. Sometimes local charities can help save high shipping costs and provide you with a tax write-off for the donation. ### Storing it While you may find a spare part in a clutch situation, most of the equipment will remain untouched well past its realistic lifetime. Not only is there a cost to store the equipment, but there are also inherent security risks associated with data sitting around that could be compromised. If you decide to store the old machines, make sure you have proper controls to ensure data protection. ## What kind of third party exists to help disburse this equipment, and what should businesses look for in going with a third party? Some of the third-party options are listed on EPA’s website. You may also want to spend some time at [computerhope.com](http://computerhope.com) to get in-depth knowledge and information. ## How do environmental regulations affect businesses getting rid of technological equipment? Environmental regulations put specific requirements in place to help protect our environment. You cannot just decide to haul the computers and dump them into a landfill. It is highly recommended to use recycling services to properly dispose of the equipment and help with green initiatives. Regulations will vary from state to state, so it is recommended that you check with your state’s department of environmental protection. More information on the regulations can be found online. ## What are the options for donating used equipment? What kind of liabilities or responsibilities do businesses have? How should they prepare their machines for re-use by non-profit or charity? The National Christina Foundation works with data center operators like Atlantic.Net and large corporations to distribute the used equipment to the charity of your choice. I also recommend working with any local causes you find important. Joe recommends using DD (a degaussing device) to handle that task. Atlantic.Net actually utilizes a USB-> SATA/IDE device that allows us to hot-swap old drives onto a running system and then use DD to wipe the data. There is a standing challenge from 2008 for any commercial data recovery company to attempt to recover data off of a drive that was wiped with DD. For more information on how to do this, you can visit the following link: [How to wipe a hard drive clean in Linux](http://howto.wikia.com/wiki/Howto_wipe_a_hard_drive_clean_in_Linux). ## What steps should businesses take to secure their data when disposing of old equipment? What legal requirements must they fulfill? Per Joe Cosmano, numerous steps must be taken to ensure that data is correctly disposed of with: •    Management needs to contact the systems administrator when a device or system is to be removed. •    Outdated equipment must not be discarded in dumpsters or trash containers (needs to be recycled via the third party) •    Proper procedures must be taken to destroy data partitions (magnetic erasure by system administrators, DD, degaussing)). •    Companies should consider setting up logs and step-by-step procedures to stay ahead of compliance issues and ensure all the procedures are followed. Legal requirements may differ depending on which compliance your organization falls under (HIPAA, Sox, GLBA). For instance, HIPAA requires that electronic storage media and devices containing patient health information should have that information deleted by persons with adequate technical knowledge to ensure irreversible removal. ## What alternatives are there for server disposal? Lease a dedicated server or managed hosting server!  According to Josh Simon, you are never the owner of the record (the lessor/provider is). Your administrators have full access and can wipe the data before you turn it back over to the hosting provider (this can usually be done remotely in the case of dedicated servers ). Your systems always remain up to date, and you never have to worry about the headaches with the disposal. Companies like Atlantic.Net operate Data Center facilities that are fully secure and are designed to help businesses avoid data loss and prevent security breaches.  Instead of buying servers with a capital outlay, smart companies are now leasing dedicated servers and/or managed [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) servers that are secured in World Class[HIPAA-Compliant Data Centers](https://www.atlantic.net/hipaa-data-centers/) like the one operated by Atlantic.Net. This smart-sourcing helps save significant time, money, and resources and adds another line of defense when it comes to protecting your data. There are quite a few other interesting articles written about the subject matter, and you can easily look those up online at Google, Bing, or Yahoo. We hope you benefited from this article and have learned new ways of disposing of old computers and servers. Atlantic.Net has many Cloud Server options to keep up with current technology like [VPS Hosting](https://www.atlantic.net/vps-hosting/), Linux and Windows Cloud Hosting, and Docker Cloud hosting, among others.   --- # Atlantic.Net Completes SAS 70 Certification > URL: https://www.atlantic.net/press-releases/atlantic-net-completes-sas-70-certification/ | Published: 2009-10-22 | Updated: 2026-03-02 | Author: Editorial Team Orlando, Fl (October 22, 2009 – Atlantic.Net (www.atlantic.net) is pleased to announce the completion of Statement of Auditing Standard Number 70 (SAS 70) certification for Service Organizations. SAS 70 certification confirms the reliability, security, availability, and processing integrity of Managed Server Hosting, [Dedicated Hosting](https://www.atlantic.net/dedicated-server-hosting/), and [Server Colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/) provided by Atlantic.Net through its World Class Data Center operations. The SAS 70 certification was developed by the American Institute of Certified Public Accountants (AICPA) to audit and report on the effectiveness of operations and controls of a service provider. Atlantic.Net’s Data Center control objectives were closely examined in the areas of organizational structure, administration, physical and environmental controls, and physical and logical security. Atlantic.Net invested significant time and resources into the SAS 70 certification process to ensure the security, controls, and processes in its Data Center operations are closely followed and monitored. The audit also enhances Atlantic.Net’s ability to support companies facing Sarbanes Oxely requirements when they outsource their data center needs through [Server Colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/), [Dedicated Hosting](https://www.atlantic.net/dedicated-server-hosting/), or Managed Server Hosting. “SAS 70 certification allows our clients to rest easy knowing that Atlantic.Net’s operational processes, system controls, and infrastructure meet stringent requirements to ensure the reliability, security, and service customers have come to expect from Atlantic.Net,” said Josh Simon, Director of Data Center Services at Atlantic.Net. “This certification provides clients of Atlantic.Net the ability to utilize our SAS 70 report as an alternative to conducting their own testing for Data Center compliance requirements.” SAS 70 certification further reinforces Atlantic.Net’s enterprise level offerings with its World Class Data Center operations and 100% uptime service level guarantee. ### About Atlantic.Net Established in 1994, Atlantic.Net is a market-leading business data services provider known for exceptional service, simplifying complex technologies and building a brand that people trust. Atlantic.Net operates a world-class colocation Data Center in Orlando, Florida, and helps businesses around the globe with their data needs through services including Managed Servers, [Server Colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/), Dedicated Servers, Internet connectivity, Business Continuity, and managed services such as Data Backup, Security and Private Networks. Atlantic.Net’s services enable companies to focus on their core business and forgo the expense of capital equipment purchases and ongoing IT management costs. The company’s technological savvy and strategic acumen have been the foundation for the company’s reputation and profitability since 1994. For more information about Atlantic.Net, please visit www.atlantic.net. --- # Dedicated Hosting, Cloud Computing or Virtualization? > URL: https://www.atlantic.net/dedicated-server-hosting/dedicated-server-managed-server-or-cloud-computing-how-to-choose-the-service-that-fits-your-companys-needs/ | Published: 2009-12-18 | Updated: 2026-01-09 | Author: Glenn In the world of gigabits and terabytes, there is a lot going on – new products are being developed and the plethora of information that you have been told about securing your data as a business owner can be, from time to time, overwhelming. ## How Do You Choose a Data Security Solution? You aren’t the CIO and you don’t employ an arsenal of IT staff to help guide you through the decision of migrating your data into a secure Data Center. You’re inundated with choices and weary of company salesmen who may or may not be trying to oversell you. Every web hosting service has its own unique advantages and disadvantages. It is crucial for every business owner to familiarize themselves with the different types of services a Hosting Provider offers before researching your data center. So how do you know what service is the right fit for your company?  Continue to read and see where you feel your company fits best before signing on the dotted line. ## Hosting Basics Many data centers offer [Dedicated Servers](https://www.atlantic.net/dedicated-server-hosting/), Managed Servers, and some have even begun to offer cloud hosting, also known as virtual computing or cloud computing. Let’s start with the basics. You are researching because you have noticed that your operations aren’t running so smoothly. Your website is slow and sluggish, and you have thought about disaster recovery or that centralizing your core business data would be a great idea.  You probably need a dedicated server. ## Dedicated Servers A dedicated server is a server in which you can host your website, your email, or any other software. You may even run your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) as a backup server in the event your other provider or in-house server were to fail.  These servers are not owned by you but by the hosting company and are leased to you.  If you choose to go with a dedicated server you will not have physical access to the server and will only be able to control your server remotely. Much like purchasing a car, you are responsible for the maintenance of the server and if you need assistance with a project or repairs you can contact the provider for assistance.  This could get costly with most consulting agreements starting around $150 an hour or more, depending on the skill level of the technician. Consulting agreements also typically include a minimum estimation of work time.  Management and maintenance of the server could serve to become a burden if your organization is not staffed with a skilled IT department. ## Managed Servers This is where managed servers come into play. Much like the dedicated server, the equipment is not owned by you but leased to you for a monthly fee. With managed servers, your provider installs security patches and updates, completes backups, provides technical support, and other actions that fall under the managed hosting scope of support.  Managed server hosting will allow you to employ a smaller IT staff or, even none at all. Many small to mid-size businesses find this option to be better than using a dedicated server, as it allows their operations to run more efficiently with less money being spent on IT salaries and more on development with little out-of-pocket expenses. ## Cloud Servers If you are looking for a flexible platform that allows you to easily scale your computing resources and is often costs less than dedicated or managed servers, you could always consider “the cloud”. Cloud hosting typically allows multiple users to share computing resources and scale up to fully dedicated systems in a seamless manner.  It is often offered in a pay-as-you-go or contracted monthly structure.  As of now, the cloud is somewhat new to the market and is not widely in use. ## Get Help from the Experts In general, if you are a small to mid-sized business, any of these options can work for you.  Before signing a contract, it is important to take into consideration your IT budget, [applications for cloud server use](https://www.atlantic.net/vps-hosting/), and the investment you wish to make.  Being in this industry for 30 years truly gives us an edge and expertise in helping prospective customers determine the best solution to meet their needs. Best of all, we offer this consulting service for free. So feel free to contact us today. --- # Thoughts.com selects Atlantic.Net for Colocation Service > URL: https://www.atlantic.net/press-releases/thoughts-com-selects-atlantic-net-colocation-service/ | Published: 2010-01-27 | Updated: 2026-03-02 | Author: Editorial Team **Orlando, FL (January 27, 2010) **– [Atlantic.Net](https://www.atlantic.net/) (www.atlantic.net) a privately–held high performance data center services company, today announced a multi-year agreement with Thoughts.com. Thoughts.com is a new social media networking platform that requires a fully redundant and [highly scalable server colocation solution](https://www.atlantic.net/orlando-colocation-hosting-data-center/). Under the terms of the agreement, Atlantic.Net will power Thoughts.com’s social networking engine with its fully redundant and robust infrastructure backed by its World Class Data Center operations. “We are pleased to have the opportunity to partner with a new breed of social media networking company like Thoughts.com,” says Neal Hiscock, Chief Operating Officer of Atlantic.Net. “Thoughts.com not only has a unique concept but they also utilize cutting edge technology. Atlantic.Net is honored to help facilitate this extremely high traffic network to keep the discussions flowing on Thoughts.com.” “Our Social Media platform requires 100% uptime and we feel that Atlantic.Net provides the best solution to host our server colocation platform” says Ben Ogden, Founder and CEO of Thoughts.com. “Atlantic.Net’s dedication to 100% network uptime, to their customers, and their long standing reputation in Florida are all key factors in our decision. As Thoughts.com grows we are confident that Atlantic.Net’s superior infrastructure will continue to provide a scalable and robust solution. We also strongly believe that doing business locally helps support our local community staying true to our mission to engage our community.” ### About Atlantic.Net Established in 1994, Atlantic.Net is a market-leading business data services provider known for exceptional service, simplifying complex technologies and building a brand that people trust. Atlantic.Net operates a world class colocation Data Center in Orlando, Florida, and helps businesses around the globe with their data needs through services including Managed Servers, Server [Colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/), [Dedicated Servers](https://www.atlantic.net/dedicated-server-hosting/), Internet connectivity, Business Continuity, and managed services such as Data Backup, Security and Private Networks. [Atlantic.Net’s](https://www.atlantic.net/) services enable companies to focus on their core business and forgo the expense of capital equipment purchases and ongoing IT management costs. Atlantic.Net’s technological savvy and strategic acumen have been the foundation for its reputation and profitability since 1994. ### About Thoughts.com Thoughts.com is a growing, one-of-a-kind blog community that drives social conversation and connects like-minded people through its community forums and live discussions. The site is host to personal and engaging blogs and provides unlimited bandwidth for photo and video hosting, all 100% free. Founder and Chief Executive Officer Benjamin Ogden launched the website in June 2007. Through a dedicated following and word of mouth, the site now has over 200,000 members. The website began as a place for people to share their thoughts, but has quickly developed into a worldwide community of passionate individuals. Whereas other social networking sites seem designed to help members meet people and collect “friends,” Thoughts.com is more interested in facilitating engaging discussions. In addition to becoming one of the up and coming free blogging and discussion communities, Thoughts.com endeavors for social progress and unity, while promoting charitable giving and passionate debate. Thoughts.com “One Love Philosophy”, acts as a vehicle for making positive changes in the world by supporting groups such as UNICEF, Habit for Humanity and Mission Make it Right. --- # Atlantic.Net to sponsor California Linux Expo 2010 > URL: https://www.atlantic.net/press-releases/atlantic-net-sponsor-california-linux-expo-2010/ | Published: 2010-02-19 | Updated: 2026-03-02 | Author: Editorial Team **Orlando, FL (February 19, 2010**) – [Atlantic.Net](https://www.atlantic.net/) (www.atlantic.net) a privately–held high performance data center services company, today announced its participation as a sponsor for the California Linux Show 2010. Since inception, Atlantic.Net has been a major supporter of grass root organizations within the technology industry. The recent announcement of Atlantic.Net’s sponsorship of the Southern California Linux Expo (SCALE), to be held February 19-21, 2010, comes on the heels of the sponsoring the Florida Linux Show, held in November 2009. “Atlantic.Net has always taken great pride in supporting the technology community,” said John Rossiter, Director of Channel Development with Atlantic.Net. “It is an honor to provide ongoing support and encouragement to these grass root technology platforms such as SCALE and we look forward to continuing to do so for many years to come. The role these organizations play in providing engineers with the opportunities to learn and grow cannot be understated and is one of the driving forces behind our participation because it is so huge for our industry,” Rossiter said. In addition to the Southern California Linux Expo, Atlantic.Net actively supports and sponsors the Central Florida Information and Technology Society, Florida Linux Show and the BarCamp Community in Orlando, Tampa, Miami, and Fort Meyers. Atlantic.Net also sponsors online communities such as DOTNETNUKE, which is dedicated to the education and promotion of open source software. “It’s encouraging to see leading technology companies such as Atlantic.Net help support our initiatives” says Ilan Rabinovitch of the Southern California Linux Expo. “We credit our sponsors and friends, like Atlantic.Net, who have enabled us to be where we are today. Being able to hold our 8th annual expo this year proves how well supported we are by the technology community; allowing us to continue to promote and educate the IT community.” ### About the Southern California Linux Expo The Southern California Linux Expo’s mission is to evangelize the advantages of Open Source software throughout the IT industry. The Southern California Linux Expo is geared toward both current and potential users of OSS, which is comprised of the individual computer users, educational institutions and businesses. The Expo’s educational focus is composed of technical seminars and booths where, among other things, both commercial software and hardware vendors, and local non-profit groups (for example, Linux Users Groups), participate in product display, software demonstrations and tutorials and education, respectively. ### About Atlantic.Net Established in 1994, Atlantic.Net is a market-leading business data services provider known for exceptional service, simplifying complex technologies and building a brand that people trust. Atlantic.Net operates a [world-class colocation Data Center](https://www.atlantic.net/orlando-colocation-hosting-data-center/) in Orlando, Florida, and helps businesses around the globe with their data needs through services including Managed Servers, Server Colocation, [Dedicated Servers](https://www.atlantic.net/dedicated-server-hosting/), Internet connectivity, Business Continuity, and managed services such as Data Backup, Security and Private Networks. Atlantic.Net’s services enable companies to focus on their core business and forgo the expense of capital equipment purchases and ongoing IT management costs. Atlantic.Net’s technological savvy and strategic acumen have been the foundation for its reputation and profitability since 1994. --- # Atlantic.Net announces participation in the annual CFO Conference > URL: https://www.atlantic.net/press-releases/atlantic-net-announces-participation-annual-cfo-conference/ | Published: 2010-03-05 | Author: Editorial Team **Mar 05, 2010 – Orlando, FL –** Atlantic.Net [(](https://www.atlantic.net/)www.atlantic.net[)](https://www.atlantic.net/) a privately–held leading Managed IT Service Provider, today announced its participation as a sponsor for The 17th annual CFO Rising Conference & Expo, scheduled for March 7-10, 2010, at the Hilton Grand Convention Center in Orlando Florida. Atlantic.Net is offering free evaluations to help attendees recognize huge savings with Atlantic.Net’s Fully Managed IT Services. In today’s economy every organization is looking to streamline their processes and cut expenses. Atlantic.Net is taking proactive steps to educate financial decision makers on how to reduce their IT spending without sacrificing the integrity of their IT infrastructure. “For over 15 years Atlantic.Net, in its role as an Internet Service Provider, Competitive Local Exchange Carrier and a Managed Computer Server Hosting provider, has helped thousands of businesses obtain more for less”, said Adnan Raja, Director of Business Development at Atlantic.Net. “Our Fully Managed IT Services are designed to help Financial Executives deploy newer and more cost effective IT strategies allowing them to refocus on their core business”. ### About Atlantic.Net Established in 1994, Atlantic.Net is a market-leading business data services provider known for exceptional service, simplifying complex technologies and building a brand that people trust. Atlantic.Net operates a world class colocation Data Center in Orlando, Florida, and helps businesses around the globe with their data needs through services including Managed Servers, Server Colocation, Dedicated Servers, Internet connectivity, Business Continuity, and managed services such as Data Backup, Security and Private Networks. Atlantic.Net’s services enable companies to focus on their core business and forgo the expense of capital equipment purchases and ongoing IT management costs. Atlantic.Net’s technological savvy and strategic acumen have been the foundation for its reputation and profitability since 1994. For more information, please visit us online at www.atlantic.net ### About The CFO Group CFO magazine, CFO.com, CFO Conferences, and CFO Research Services together make up CFO Publishing Corporation, which is an Economist Group business. CFO Financial Benchmarks is an editorial product of CFO, the leading business publication for C-level and senior financial executives. --- # HIMSS Conference- A Fresh Prospective on Healthcare IT > URL: https://www.atlantic.net/hipaa-compliant-hosting/himss-healthcare-information-and-management-systems-society-9th-annual-conference-exhibition/ | Published: 2010-03-06 | Updated: 2024-10-31 | Author: Glenn With the passage of Healthcare Reform by Congress, there is a lot of talk about healthcare in the IT business community.  Healthcare already accounts for about $2 trillion in federal spending each year; almost one out of every seven dollars spent in the U.S is related to healthcare.  It looks as if billions more will be funneled into the healthcare IT segment, thanks to the new federal initiatives requiring healthcare providers to maintain medical records electronically.  This explains why almost every technology vendor is evaluating and exploring opportunities within the health care sector. ## Atlantic.Net’s Sam G. Visits HIMSS: His Experience We sent Sam G. to the Healthcare Information and Management Systems Society Expo (HIMSS) in Atlanta, Georgia, earlier this month to do some investigating. Sam spent three jam-packed days touring the World Congress Center in Atlanta and has supplied us with the following account of the conference: *“The conference was amazing! It took up almost the entire World Congress Center venue. Although it’s not as vast as the Orange County Convention Center, it is still very large, and the exhibits took up every square inch of space at this show.  There were 250+ exhibitors split between two different exhibit halls, and it was almost impossible to completely tour one hall in a day!* *I could not help but notice an extraordinarily large number of people from all over the world, about 27,000, I was told.  This is by far the largest conference I have ever attended, and a much bigger crowd is expected next year at the 10th annual conference in Orlando, Florida.* *This show revealed a side of the healthcare industry I had never seen before.  There was a remarkable mix of companies that supply thousands of products and services.  While companies such as Microsoft and Google made a very strong presence, there were companies I had never heard of prior to the event.  Some of these names I would have never thought serviced the healthcare industry”.* *“National Cash Register had one of the largest exhibits, and they told me that 50% of their revenue is now driven by the health care industry.”* ## HIMSS and Tech Trends We want to thank Sam for his synopsis of the HIMSS Conference.  He came back with valuable information about the companies that are now branching out to the health care industry and ideas on how to best capitalize on the trend. Technology trends within the health care industry point toward increased use of Electronic Health Records/ Electronic Medical Records (EHR/EMR) by the hospitals and health care providers.  As EHR/EMR becomes more prevalent in the industry, security and availability become more of a concern.  Organizations are ushering in new technology like Cloud Servers to assist with business continuity planning initiatives and implement heightened security protocols to strengthen the privacy of patient records. ## How Atlantic.Net Can Help with Healthcare Technology As the times change, so does Atlantic.Net!  We welcome the opportunity to come together with the health care world to provide the most secure and cost-effective IT solutions.  We are well-positioned to help EHR/EMR providers, insurance, billing, and even medical practices outsource their IT infrastructure.  Atlantic.Net stands ready to meet this increasing demand to help ease the hassles associated with IT infrastructure with services like [HIPAA Cloud Hosting](https://www.atlantic.net/hipaa-compliant-hosting/).  As a SAS70 certified, HIPAA, and HITECH-compliant Data Center, we have the right experience, security, and technical credentials to provide fully managed and turnkey solutions to the health care industry.  Even with the new HITECH Act passed in February 2010, we are infrastructure-ready to help providers cope with regulatory challenges and complexities. With this valuable information from Sam on the growing demand for IT in health care and [HIPAA Hosting](https://www.atlantic.net/hipaa-compliant-hosting/), I am certain we will make an appearance at the Orlando Expo next year.  We look forward to getting ourselves in front of this growing industry and welcome the opportunities it will bring! --- # Atlantic.Net to Be the Official Server Host of the Disaster Recovery Journal > URL: https://www.atlantic.net/press-releases/atlantic-net-official-server-host-disaster-recovery-journal/ | Published: 2010-03-15 | Author: Editorial Team **Orlando, Fl (March 15, 2010)** – [Atlantic.Net](https://www.atlantic.net/) (www.atlantic.net), a privately held leading global Managed IT Service Provider, is pleased to announce, a highly anticipated, partnership with the world’s largest Disaster Recovery and Business Continuity publication, the Disaster Recovery Journal. Under the terms of the agreement Atlantic.Net will provide the critical technology platform and Fully Managed IT infrastructure to the Disaster Recovery Journal, backed by Atlantic.Net’s 100% uptime guarantee. With the combined efforts of Atlantic.Net and the Disaster Recovery Journal entities such as Government, Non-profit and Enterprise Businesses can be better prepared for business continuity and disaster protection. “It is vital for our operation to stay up and running 100% of the time to ensure absolute availability of our information in the event of unforeseen circumstances like a natural disaster or simply a hardware or network performance issue” said Bob Arnold, President of the Disaster Recovery Journal, “with our own disaster protection strategies in place, backed by Atlantic. Net’s world class Fully Managed IT infrastructure, Business Continuity and Disaster Recovery experts can now rest assured that they can depend on DRJ more than ever!” “We are committed to delivering the most current information to help organizations prepare for disaster protection. In partnering with Atlantic.Net, we are certain that DRJ will continue to deliver comprehensive business continuity resources to our users” he added.“The Disaster Recovery Journal has put its trust and confidence in our abilities and we are privileged to power the Disaster Recovery Journal,” says Marty Puranik, Founder, President, and CEO of Atlantic.Net. “Atlantic.Net considers this relationship with DRJ invaluable as there is much to learn about business continuity plans beyond the realm of data. Atlantic.Net embraces this opportunity to promote this knowledge with other businesses.” “Even companies with the most thorough contingency plans are at risk, in the event a disaster occurs, if that plan isn’t accessible,” Puranik added. “Atlantic.Net works hard to see that companies, large or small, have the resources available to them to ensure their contingency plans are readily accessible.” ### About Atlantic.Net Established in 1994, Atlantic.Net is a market-leading business data services provider known for exceptional service, simplifying complex technologies and building a brand that people trust. Atlantic.Net operates a [world-class colocation Data Center](https://www.atlantic.net/orlando-colocation-hosting-data-center/) in Orlando, Florida, and helps businesses around the globe with their data needs through services including Managed Servers, [Server Colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/), [Dedicated Servers](https://www.atlantic.net/dedicated-server-hosting/), Internet connectivity, Business Continuity, and managed services such as Data Backup, Security and Private Networks. [Atlantic.Net’s](https://www.atlantic.net/) services enable companies to focus on their core business and forgo the expense of capital equipment purchases and ongoing IT management costs. Atlantic.Net’s technological savvy and strategic acumen have been the foundation for its reputation and profitability since 1994. ### About Disaster Recovery Journal Disaster Recovery Journal, founded in 1987, delivers how-to, in-depth knowledge into business continuity planning more than any other business publication. DRJ delivers the most informative and up-to-date information available in the business continuity industry to over 58,000 business continuity professionals. Since 1995, the Disaster Recovery Journal has been a dominant leader of disaster recovery and business continuity information on the web with over 104,000 registered users around the globe. Disaster Recovery Journal is the main source of most up to date information and knowledge to government agencies and very large enterprises. --- # Announcement: Atlantic.Net Sponsors Orlando’s 3rd Annual Walk-For-Wishes > URL: https://www.atlantic.net/announcements/walk-for-wishes/ | Published: 2010-03-19 | Updated: 2026-01-09 | Author: Glenn I would like to thank our staff and our local community who pulled together to help support the Make-A-Wish Foundation’s 3rd annual “Walk-For- Wishes” at Lake Eola in Orlando Florida. I woke up thinking that the weather was going to ruin this event, but I was pleasantly surprised by the beautiful, usually unpredictable, Florida weather which contributed to a fantastic evening walk!  Attendance for this event far surpassed my expectations and this truly was a fun-filled event!  There were food, fun, games, and giveaways!  The best surprise of all was a special appearance by the Orlando Predator cheerleaders who got the crowd involved in an impromptu show of football skills, something I couldn’t do in heels!  Before the walk, 98.9 WMMO played the best hits of yesterday and today, and a tough competition of “Corn Hole” ensued!  I am sure some of the folks took advantage of the FREE 10 minute massages by another sponsor! There were half a dozen corporate sponsors, ranging from local educational institutes to wellness facilities, who were given booths to show their support.  [Atlantic.Net](https://www.atlantic.net) took over a corner booth (with a great view of the Predator Cheerleaders — I’m sure our tech guys appreciated that one!).  While the guys were busy flirting with the cheerleaders, I was passing out candy to the kids and apologizing to the parents for the sugar rush that was about to follow!  It felt so good to be in a fun, happy environment seeing the community come together to bring much-needed smiles to the children and families. The *Atlantic.Net-izens* raced around Lake Eola with pride (and a sugar rush), taking note of the many groups who banned together for one great cause, walking for wishes.  With in-kind [donations from local companies](https://donorbox.org/nonprofit-blog/getting-donations-from-companies) and individual donations, this event was a huge success.  The Make-A-Wish Foundation was able to raise over $29,000.00, enabling them to grant many more wishes for children and families affected by terminal illnesses.  The Make-A-Wish Foundation has touched the lives of so many families in our community, allowing them to forget about the doctors’ offices, treatments, and illness, even if for just one day.  Atlantic.Net is proud to have been a part of such a meaningful organization and we know our contributions are going towards a wonderful cause. We look forward to getting involved in the Make-A-Wish Foundation’s next event and we hope you will join us! Atlantic.Net, an Orlando-based company, has 6 industry-leading [VPS hosting](https://www.atlantic.net/vps-hosting/) centers around the world offering managed cloud VPS hosting, one-click cloud applications, [HIPAA compliant](https://www.atlantic.net/hipaa-compliant-hosting/) hosting and many other solutions.  Contact Atlantic.Net today! --- # News Update: ITT Technical Institute Tours Data Center > URL: https://www.atlantic.net/voip-cloud-servers/itt-tours-data-center/ | Published: 2010-04-23 | Updated: 2026-01-09 | Author: Glenn The ITT Technical Institute contacted us to help turn theory into practice for one of their classes.  We welcomed this opportunity to help educate the future Engineers of Central Florida. We set up Daniel Poremba, Professor at the School of Information Technology, and his class of roughly twenty with Preston C, the Senior Linux Engineer at Atlantic.Net. Preston took the class on a tour of Atlantic.Net and explained the significance of each component, from the fastest cloud Server to the industrial-grade generator and UPS’s.  Preston explained the various systems powered by Linux and why Atlantic.Net chooses to use open source products over some commercial products.  He also explained the applications of Linux in addition to that of an Operating System. He was able to demonstrate further how these systems integrate with other non-Linux systems. For example, Atlantic.Net uses many Linux systems and applications to run a portion of our infrastructure due to its power, flexibility, stability, robustness, and cost. These factors are invaluable when considering the integrity and cost efficiency of operating a cloud hosting center Center like ours. Throughout the two-hour tour of our facility, these future engineers asked many thorough, well-thought-out questions, and Preston was happy to help them understand the reasoning and logic with his technical insight. We want to thank Daniel Poremba and his class for visiting our Center and allowing us to give this invaluable experience back to the community. Preston had nothing but good things to say about the group, and he was very impressed with their quality and intellect! We look forward to exploring other opportunities to give similar rich experiences back to the community that has made us what we are today!  If you or your school would like to schedule a tour of Atlantic.Net to further enhance your curriculum, please e-mail us to set up a tour.  Our world-class fast enterprise-class [VPS hosting](https://www.atlantic.net/vps-hosting/) is only second to our knowledgeable and courteous staff. Atlantic.Net also offers [VOIP cloud hosting](https://www.atlantic.net/voip-cloud-servers/) solutions – contact us today for a consultation. --- # Atlantic.Net to Present at Web2.0 Expo > URL: https://www.atlantic.net/press-releases/atlantic-net-present-web2-0-expo/ | Published: 2010-05-03 | Updated: 2026-03-02 | Author: Editorial Team **Orlando, FL – May 3, 2010** – Atlantic.Net [(www.atlantic.net)](https://www.atlantic.net/), a privately held high performance data center services company, announced today that Adnan Raja, Director of Business Development, will be presenting at the Web 2.0 Expo in San Francisco, California. “This presentation will highlight our stance and encouragement of continuous development for cloud computing and its benefits to the social media networks. Innovators face funding obstacles which often keeps them from launching their product, social media site or the development of their ideas” said Raja. “Our goal is to educate entrepreneurs about their options, and give them hope that the new cloud technology can be easily scaled to the needs of their infrastructures based upon the demand for their product or services.” Raja’s presentation is focused on key benefits and considerations that are vital before selecting a cloud solution and cloud provider. “Atlantic.Net is thrilled to have the opportunity to speak before our peers at Web 2.0 this year, as we feel our topic will hit home for many of the participants.” Raja continued, “Our goal is to help organizations choose the right platform to get their initiatives off the ground, in cost efficient and easily manageable methods.” This presentation comes just weeks before the launch of the highly anticipated cloud offering from Atlantic.Net, which will change the way cloud is defined in the marketplace. ### About Atlantic.Net Established in 1994, Atlantic.Net is a market-leading business data services provider known for exceptional service, simplifying complex technologies and building a brand that people trust. Atlantic.Net operates a 25,000-square-foot [colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/) Data Center in Central Florida and helps businesses around the globe with their advanced online needs through services including [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/), server colocation, managed hosting, Internet connectivity,business continuity,and managed services such as data backup,security and private networks. Atlantic.Net’s services enable companies to focus on their core business and forgo the expense of capital equipment purchases and ongoing IT management costs. [Atlantic.Net’s](https://www.atlantic.net/) technological savvy and strategic acumen have been the foundation for its reputation and profitability since 1994. --- # Atlantic.Net to sponsor Governor’s Hurricane Conference > URL: https://www.atlantic.net/press-releases/atlantic-net-sponsor-governors-hurricane-conference/ | Published: 2010-05-23 | Updated: 2026-03-02 | Author: Editorial Team **Orlando, FL – May 23, 2010** – Atlantic.Net (www.atlantic.net), a privately held data center company specializing in Fully Managed IT Solutions, today announced its participation in the Governor’s Hurricane Conference and Expo. The upcoming Governor’s Hurricane Conference and Expo will be held May 23rd – 28th, 2010 in Fort Lauderdale, Florida and the focus this year is on training and education for hurricane and disaster preparedness. If the devastation of past hurricane seasons has taught us anything, it is that as a community, we need to be better prepared. Atlantic.Net has long been an advocate in Data Management and Disaster Recovery, through the utilization of hardened facilities as well as fully redundant data centers. Atlantic.Net stands uniquely positioned and readily available to help businesses operate without any interruption in the event of a natural disaster. “In today’s technologically driven world, we need to explore every available means at our disposal to educate our business communities,” says John Rossiter, Director of Channel Development with Atlantic.Net. “Through these events we can review what worked in prior years as well as strategize solutions for areas that may not have worked as well. By taking these types of actions we can constantly fine tune our initiative to ensure the safety of our citizens and the longevity of our businesses,” he added. “Ensuring that a community gets back on its feet after a natural disaster is much like a NASCAR pit stop. If one area is having difficulties the whole process will be out of synch, that is what this event is all about and Atlantic.Net is proud to participate and help add to the systems already in place.” ### About Atlantic.Net Established in 1994, Atlantic.Net is a market-leading business data services provider known for exceptional service, simplifying complex technologies and building a brand that people trust. Atlantic.Net operates a 25,000-square-foot [colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/) Data Center in Central Florida and helps businesses around the globe with their advanced online needs through services including [Dedicated Servers](https://www.atlantic.net/dedicated-server-hosting/), [Server Colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/), Managed Hosting, Internet Connectivity, Business Continuity, and managed services such as Data Backup, Security and [Private Networks](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/). Atlantic.Net’s services enable companies to focus on their core business and forgo the expense of capital equipment purchases and ongoing IT management costs. Atlantic.Net’s technological savvy and strategic acumen have been the foundation for its reputation and profitability since 1994. --- # Electronic Medical Records Made Easy With Managed Hosting > URL: https://www.atlantic.net/hipaa-compliant-hosting/electronic-medical-records-made-easy-with-managed-server-hosting/ | Published: 2010-06-01 | Updated: 2026-02-28 | Author: Glenn EMR/EHR systems enable healthcare practitioners to view a patient’s complete health event summary, historical reports and previous treatment records. This has resulted in an enormous gain in productivity in practices staffed with multiple physicians, and can also help practitioners with patients with multiple aliments and in emergency medical situations. ## How Can EMR/EHR Help with Operational Efficiency? With the adoption of EMR/EHR there is still plenty of room to increase operational efficiency, cost savings and productivity gains. Electronic Medical Records are gaining in popularity because of the paperless approach. At the same time this creates an effective demand for HIPAA compliant data storage centers to host such records in secure facilities. Secure facilities are a must due to the highly sensitive nature of the data being hosted combined with the fact that strict security procedures and practices must be maintained. EMR can be handled in a variety of ways; some of the common methodologies are: 1.  The Electronic Medical Records are hosted in the office environment; which is the traditional approach that has been in practice for many years, even before the latest push by Congress for EMR. 2.  Colocation servers are installed in data centers while existing server infrastructure is utilized efficiently to save on operational costs. This service is often referred to as “server colocation” or “colocation hosting.” This is a step in the right direction towards veering away from the traditional mindset. Colocation utilizes the latest and greatest data center infrastructures which can significantly help reduce costs associated with similar legacy environments. 3.  Managed Server Hosting is the latest idea that is designed to take advantage of the human capital available at the data centers for cross subsidization. This greatly helps practitioners’ focus their efforts on their patients and practices rather than worrying about their day-to-day server hassles. For many, this could be the better option when deciding to implement an EMR Solution. Managed Server Hosting can yield expected results with reduced risk and cost.  This service is also referred to as a “Managed Server” or as “Managed Dedicated Server Hosting”. However, there is another service that is intermediary to Managed Server Hosting and Colocation Servers; namely Dedicated Servers, often referred to as “Dedicated Server Hosting.” This is similar to a Managed Service as far as hosting goes, but lacks some bells and whistles such as managed backups and security. 4. Selecting a new breed of Service Providers who specialize in not only hosting the EMR applications, but managing it as well could be the ultimate solution that provides maximum gains and peace of mind. These service providers are referred to as “ASPs” or “Application Service Providers.”  Not only do they maintain and host your equipment, they also manage your software. If you have already adopted EMR or a similar solution, or are considering investing in protecting your critical data, Managed Server Hosting could be the best option to save you time, money and hassle. Implementing Electronic Medical Records can be very easy with Managed Server Hosting for various reasons. Once you secure a suitable EMR solution and begin hosting your EMR with your service provider, your EMR strategy is largely complete, assuming that you choose the right Service Provider. You do not need to think about how to manage your data, how to safeguard that data, how to prepare for natural disasters, or the ongoing IT Management costs. Managed Server Hosting promises to deliver most of this and helps make your EMR strategy scalable, yet affordable, by reducing the operational and ongoing infrastructure costs as well as IT management and maintenance costs. It saves you valuable time that can instead be invested in the operation of core EMR applications, rather than focusing on the hosting aspect. When adopting an EMR strategy, the following four components must be carefully considered and thought through before making critical decisions: ## EMR standards Privacy and Security policies must be maintained in order to protect the patient’s privacy and safeguard critical data. There are new laws and regulations in place ensuring such standards are implemented accordingly. In fact, security is the most critical aspect since a data breach could mean hefty fines being levied in accordance with the Healthcare reform Act and the HITECH Act, which amended the HIPAA laws. ## Infrastructure Infrastructure can dictate how well the EMR strategy is built for effectiveness, sustainability and robustness. Emergencies happen around the clock, illnesses do not wait for downtime, and therefore ensuring 24x7x365 availability is crucial. In addition to physical infrastructure security, access to the Infrastructure should be closely monitored. Ensuring unique identifiers for each patient, in addition to each physician, nurse, or individual who may require access to such records should be tightly administered. This is a proactive step to thwart off unwanted security breaches. ## Information The most elaborate Electronic Medical Records systems should contain historic data and records of past treatments and prescriptions, in addition to current treatment solutions, all of which should be available to every practitioner in order to save time and streamline the process of cross-checking for critical and life-threatening errors. This is in no way a foolproof system, as it is still in early development, and records should be double-checked for human error. ## Change Management There should be a skilled workforce for maintaining the records in the EMR system. It should be updated in a timely manner, as well as accessible to both physicians and patients. All of the above listed components should be considered before implementing an EMR Solution with Managed Hosting. Various health care providers grant access to their health information systems to their affiliated physicians, which only control one part of patient care. For truly synchronized care, physicians and their patients must be associated with those seeking information before such access is granted.  Health care providers play a crucial role in assisting physicians by hastening the use of health information technology, improving patient safety, and reducing the health care costs incurred. Managed Hosting has been proven to yield enhanced results with EMR, which significantly helps health care providers to focus on their core business. It is the comprehensive solution that simplifies EMR implementation and management, allowing you to put a spotlight on the mission of improving patient care. Over the next few years, EMR Software implementation is expected to grow considerably, partially due to the Federal stimulus money earmarked for the provision of electronic medical records systems nationwide. ## EMR in a Data Center Environment Physicians today are faced with many obstacles due to recent regulations created by Health Care Reform. Some practitioners are asking themselves, “How do I provide outstanding quality health care in the face of an increasingly complex regulatory system? Where am I going to find the time and resources to implement an EMR system?” Many doctors are in the precarious position of having to manage and troubleshoot complex IT, EMR and billing systems. Keeping up to date with the latest HIPAA Compliant Hosting and HITECH compliance and security requirements is expensive, time consuming, and difficult. Atlantic.Net believes that the business of health care exists to facilitate the practice of good medicine. Efforts should be focused on and directed towards healing the sick, not managing their IT infrastructure. As physicians in the community become tasked with the technical aspect of running their practices, they are focusing less on healing the sick. With more resources becoming available to practitioners, however, the opportunities for their practice’s growth is increasing exponentially. With an increase in patients and a decreased interest in managing their data, many are considering outsourcing their EMR and other IT strategies to Service Providers in order to shift focus back onto the patient. Fortunately, Atlantic.Net can help. We have worked with various medical groups across the country and have experienced firsthand the increasing challenges that health care providers face. Atlantic.Net understands how health care professionals, now more than ever, can benefit by saving their Electronic Medical Records and patient health information using HIPAA-compliant cloud storage in our secure HIPAA data center. Physicians can leverage the expertise of our engineering staff in order to keep their records safe, secure and fully operational 24 hours a day. Medicare providers stand to receive $44k in tax rebates by implementing EMR /paperless office technology into their practice. Whether you are an individual physician, group practice, or a hospital with multiple physicians, full compliance with the new HIPAA EMR requirements will pay for itself. The time to begin instituting EMR technology into your practice is now – reimbursements from the government will decrease over the next few years, with your full opportunity for reimbursement available only in 2010. Give us a call at (866) 618-3282 for a free consultation or to consider Atlantic.Net’s [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) Solutions with 100% uptime on SSD Cloud Servers.   Learn more about our [HIPAA compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. --- # Five Quick Tips For Improving SQL Server Performance > URL: https://www.atlantic.net/vps-hosting/five-quick-tips-for-improving-sql-server-performance/ | Published: 2010-06-22 | Updated: 2026-03-02 | Author: Glenn Database servers are a cornerstone of modern businesses ranging from Google to 7-Eleven. When you run your credit card at a convenience or grocery store, your purchase is registered at a point of sale system backed by a database. Your credit card company registers the fund’s transfer into a database server containing your financial records. If you use a discount card, yet another database server comes into play. Databases enable businesses to track inventory, perform margin analysis, automate purchases, and identify customer trends—and to do all of this much more quickly and efficiently than ever before! It has been a long time since I visited any business that did not rely on some type of database server if only to track purchases and expenses. But I constantly communicate with businesses that lack a plan to ensure these databases function properly on an ongoing basis. SQL Hosting at Atlantic.Net data center helps your database remain a vital component of your business infrastructure, rather than a time-wasting black hole for IT resources. We recently sat down with our engineering team to provide you a few tips on how we help accomplish just that: ## Tip 1: Host in a Data Center Simple power quality issues such as brownouts, blackouts or even a mere voltage fluctuation can result in your server powering down. SQL-based database systems are sensitive to these unanticipated shutdowns, resulting in errors in transaction logs and database instability. Hosting that same database server in a secure data center —where power quality is monitored every second of every day by trained engineers—helps ensure 100% uptime. So when you are ready to start your business day, your SQL database will be ready to start as well! ## Tip 2: Maximize IOPS One vital performance metric for database systems is Input/Output Operations Per Second (IOPS). IOPS is important here as a measurement of how fast storage devices can read and write, which is the primary operation metric of database systems such as SQL. Remember that in reading from and writing to a database, most hard disks must physically move, which takes time—especially if you need to read and write from separate physical areas of your disk. By making the read and write tasks concurrent you can speed up this process with almost no administrative effort. Instead of a single disk array handling both your operating system and application, opt for two arrays to handle each task on separate disks. Choosing serial-attached SCSI drives with high RPMs for your database, and enterprise-level SATA drives, for your operating system will drastically improve the read and write performance. ## Tip 3: RAID: It does more than kill bugs If you are a server administrator, you are probably familiar with the concept of a [redundant array of independent disks (RAID)](https://www.atlantic.net/vps-hosting/). Using a RAID algorithm, administrators can spread a set of data across multiple drives. Depending on which RAID algorithm is used, RAID can provide redundancy (via mirroring), improve performance (via striping), or a combination of both. At Atlantic.Net, we recommend the use of RAID 10 for SQL applications. RAID 10 uses mirroring and striping to provide significant protection against hardware failure while maximizing IOPS. Microsoft agrees with us. Always use a hardware RAID card with a dedicated coprocessor when deploying SQL in a RAID environment; doing so will free your CPU to focus on cycle-intensive applications, as opposed to doing time-consuming RAID math. ## Tip 4: Computers Only Want One Thing Having various types of applications running on the same server typically makes servers less efficient. We recommend segmenting services to get the best possible performance. For instance, run a web server on one set of boxes and a database server on another set, using dedicated appliances for firewalls and load balancing. ## Tip 5: Cache One way to prevent the need to physically move hard disks, and in the process improve performance, is to cache commonly used data in memory, thus reducing the number of steps necessary to complete a database transaction. You could run one or more [proxy servers](https://www.heimdalldata.com/overview/), or even a caching application on your SQL server, to serve requests for cached data and significantly reduce the load on your SQL-based system. There are great open-source applications available to provide this functionality such as Memcached, which can be obtained from [Memcached.org](http://memcached.org/). Hardware-enabled write caching is also typically supported by hard disk or RAID controller cards. Hardware write caching may actually degrade I/O performance, though, depending on the block size, database software, RAID algorithm, and the type of controller being used. Additionally, when using certain types of tables combined with certain types of hardware-enabled write caching, an administrator can risk serious database recovery issues in the event of an unexpected application or server shutdown. Database and SQL servers require high availability; therefore, [ensuring 100% uptime](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/) is generally accepted as best practice for businesses. Availability is so critical that it can have a deep impact on productivity by negatively affecting staff members, users, and operations throughout the organization. If you choose an in-house hosting solution for your SQL Server, it could mean little to no security, poor reliability, and scalability. Alternatively, hosting your SQL Server with a Service Provider can yield increased uptime, scalability, and performance for your databases. SQL Hosting server solutions can even provide optimal performance by outsourcing server management to the service provider. For optimal server hosting, as well as the right SQL setup, choose a service provider that can maximize your productivity with a 100% uptime guarantee. Give us a call at **1-866-618-3282** to discuss your upcoming SQL and our award-winning [VPS Hosting](https://www.atlantic.net/vps-hosting/) solutions. --- # Healthcare IT – A Guide to the Cloud & Managed Server Hosting > URL: https://www.atlantic.net/hipaa-compliant-hosting/health-care-it-a-decision-makers-guide-to-cloud-computing-and-managed-server-hosting/ | Published: 2010-07-01 | Updated: 2026-01-09 | Author: Alexander Wise Virtualization has created new possibilities and opportunities for the health care segment of technology. Healthcare IT Professionals specializing in virtualization technologies are now finding more attractive and lucrative opportunities, especially with the new Health Care Reform and health care IT initiatives introduced by the new Administration. Virtualization is the technology behind cloud computing, and it makes such a pool of network resources a genuine possibility. ## **Managed Hosting** Managed hosting is a phrase used to describe the way a hosting plan is designed to function. Managed hosting is the better way to host your critical infrastructure, providing high security and fully redundant backup power supplies, 24/7 monitoring and access, round-the-clock engineers, and much more. Managed hosting revolutionized the way organizations established their working presence on the Internet, which enabled them to conduct commerce online. Managed hosting handled by the Service Provider is ideal for organizations that don’t have the time, resources, or operational expertise to handle server operations, applications, and upkeep of their key infrastructure. Organizations that need dedicated resources generally choose the managed server hosting option. ## Dedicated Virtualization and the Structure of a Private Cloud Private cloud technologies have revolutionized the way the Internet accesses information over the Internet. Using VMware, Xen, or Hyper-V, a private network is set up with an operating system that uses minimal system resources. This creates the possibility to include more than one virtual server on one physical hardware server. It creates a more efficient usage of system resources and delivers content faster than other dedicated server solutions. It’s all a matter of receiving as many resources as you need. Server A might only need one core and 3 GB of RAM to function properly, while server B might need a custom-tailored cloud hosting solution. Grouping more than one virtual server per physical hardware server also keeps costs affordable and within the spending budget of almost everyone! There’s no need to overpay for resources that you do not need at a certain point. The scalability cloud hosting creates is unprecedented. Public clouds are also created using virtualization technology and utilize the same shared hardware, providing a more cost-efficient way to use cloud hosting as a business solution. Public and private clouds only differ in how they use physical hardware. Public clouds share their resources, while private clouds are linked to dedicated hardware designed to serve a single purpose. With a public cloud, you can opt to only pay for the services you use and none of what you don’t. You can pay per hour, day, week, month, or even year. Less resource-intensive server applications will be able to take advantage of the functionality of cloud hosting without any exorbitant fees. ## **Understand What Your Hosting Needs Are and How They Relate to Cloud Computing** Cloud computing, by the right Service Provider, offers a higher level of security and the ability to alleviate the problem of multiple physical server locations. All server resources are shared on the cloud, making any maintenance efforts and customizations faster than ever. Private clouds are much more reliable and robust than public clouds. Public clouds have to serve a great majority, while private clouds are designed to serve a select few. Even though cloud computing is a much more efficient and faster way of doing business, public clouds fall short in ability when compared to private clouds. If you are an enterprise-class business or an organization with large computing resources and bandwidth requirements, you may want to choose a private cloud. However, although they more easily meet compliance requirements and have higher uptime guarantees,  they generally cost more than the public clouds, which is something to consider when deciding which cloud option to choose. Organizations that demand less resource-intensive applications and are simply looking for a low-cost infrastructure and online presence will be more attracted to a public cloud hosting solution. Public clouds are relatively inexpensive and offer the same features as a private cloud without the need for resource-intensive dedication. All users of public clouds are provided the resources they need according to the current server resource demand. Everyone shares the same resources, and unless your application is extremely taxing on the server, public clouds are a perfectly viable solution to help your organization prosper. If your organization is currently using dedicated hosting solutions such as under-utilized servers running only a few programs, you will love cloud computing. Cloud computing has all of the resources and system processes running through a shared medium. Even on the private cloud, resources are allocated according to the current demand on the server configuration. If you have deployed a huge server infrastructure in the past and had no choice but to deploy multiple physical servers,  you now have a new option with cloud computing. Cloud computing groups together everything you need to run your server applications and do it more efficiently than ever. No more wasted system resources and hardware or employees with nothing to do. Cloud computing makes sure everything is streamlined and handled with extreme efficiency. ## **The Versatility of Cloud Computing, Private and Public Clouds** Because everything about cloud computing is based on a virtual schematic, scalability, upgrades, and downgrades are much simpler. Scalability doesn’t require any physical labor that was once a big part of dedicated server solutions. Instead, upgrading and downgrading of virtual servers and feature includes are done with the click of a button. New virtual servers can be brought online to serve a growing demand and escalating requirements with ease. Cloud computing is the new hosting definition of flexibility, scale, and cost-effectiveness. While server upgrades and the addition of new servers used to be a manual process, cloud computing changed all that. In association with current server demands, cloud servers automatically create new virtual servers to handle the increase in resource demands. This keeps employees from performing repetitive tasks and operations that a cloud configuration is capable of handling by itself. As new virtual servers are added to keep up with the increase in demand, new machines are enabled and put into use. This keeps any growth in demand from ever being able to affect the overall performance of the cloud network. ## **Which to Choose? Managed Hosting, Public Cloud, or Private Cloud?** As an overview, managed hosting is much more expensive than public and private clouds. Usually reserved for organizations with exacting standards and resource requirements, managed hosting solutions still hold a great deal of the market consumers. However, public and private clouds have all the features of a managed hosting solution without the servers’ continual upkeep.  There is simply no availability to take part in the expansion operations, or at least, much less than that which would be required with dedicated server solutions. Large organizations with rigorous requirements should opt for a private cloud.  While more expensive, it has the most options and features available for your dollar.  Larger organizations are not designed for a public cloud, as they require too many system resources to be a viable solution.  Although there is no such thing as one-size-fits-all in cloud computing, a lot also depends upon the applications being provisioned and the utilization of machines. Small organizations that require fewer resources could be better suited for the public clouds, as they can more adequately share system resources without causing a conflict.  If your application doesn’t need a large-scale private cloud and you can save money using a public one, this would be an effective option.  That, or choose to go with a managed hosting solution.  Just be sure to put the positive aspects of each Hosting option against any negative possibilities. As far as the Healthcare Industry is concerned, cloud hosting represents the future because scaling up or down sometimes becomes a necessity.  For example, with open enrollment for insurance and new patient registration, flexibility is of the utmost importance, and cloud hosting represents a crucial step in the right direction.  As a Health care professional, understanding that even standard managed dedicated hosting is sometimes not able to satisfy the needs of your project is a must.  You also want to make sure you have considered all regulatory and compliance requirements. With so many requirements, including The Health Insurance Portability and Accountability Act (HIPAA) of 1996, Health Information Technology for Economic and Clinical Health Act (HITECH) compliance, Statement on Accounting Standards (SAS 70), and Payment Card Industry (PCI) compliance, there are serious considerations to be made towards security and implementation of controls; these should be the key objectives. With the fast adoption of electronic medical records (EMR) and Electronic Health Records (EHR), there are also serious considerations to ensure patients’ privacy and the protection of records; HIPAA data storage is essential for managing such electronic records. Multi-practice data management can represent a challenge for quite a few reasons, and cloud hosting is a solution that provides the right balance of reliability, flexibility, and scalability. Because cloud hosting is a relatively new type of [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) service and not all providers are equally knowledgeable, it’s important to establish partnerships only with companies that have proven themselves. ## **Data Centers and Savings** In the past, most organizations opted to handle the hosting aspect of their business in-house, but now with more options and choices, traditional methods are a thing of the past.  More importantly, the cost could be the driving factor in comparing traditional internal solutions versus new and innovative and cost-effective hosting solutions in a data center environment.  There are serious costs involved with traditional in-house hosting, and many logistical challenges will need to be taken into consideration.  How much will it cost to train and remunerate your staff?  How much will it cost to replace broken hardware?  These are just two of the questions you need to ask yourself to determine if handling everything internally is worth the effort. Data centers put a lot on the table regarding reliability, affordability, and features (such as advanced cooling systems and regulatory compliance).  Since they operate a large number of servers, they can keep costs reasonable and pass the savings on to customers.  At the end of the day, numbers do all of the speaking. If you want to host your applications in-house, those numbers might not add up. ## **Future Hosting Solutions** The future of hosting solutions in our current day and age is definitely exciting.  What may seem to be a perfect solution today might not work tomorrow.  Bear in mind that there is always a new wave of technological advancements that could be more efficient, robust, and cost-effective.  Six months down the road, you may find yourself loathing the contract you signed and desire the features and options of new technologies.  Because technology is continually changing, signing a long-term contract could hinder your future growth objectives and impact your organization’s overall profitability. What can you do to safeguard yourself against making a mistake? You’ll need to calculate all the potential and foreseeable avenues of possibility. You now know what public and private clouds are and how they can improve your current online efforts.  Understanding how these hosting solutions convert to your health care applications is critical to your overall success. All in all, which hosting solution you choose should be decided by the level of resources and features you need.  Public and private clouds are all about virtual resource management.  All aspects of cloud computing are designed to be more efficient than dedicated server solutions.  Not a drop of water is wasted on your journey, and the lower cost of the [HIPAA Cloud Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) option will reflect this. --- # Atlantic.Net signs partnership agreement with Complete Healthcare Solutions > URL: https://www.atlantic.net/press-releases/atlantic-net-signs-partnership-agreement-complete-healthcare-solutions/ | Published: 2010-08-04 | Author: Editorial Team **Orlando, FL- August 4, 2010** – Today, Atlantic.Net (www.atlantic.net), a privately held, high-performance[managed hosting](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/) provider announced a multi-year partnership agreement with Complete Healthcare Solutions (www.completehealthcaresolutions.com), a global leader in medical software solutions. Under the terms of the agreement, Atlantic.Net will power CHS’ medical software with turnkey managed hosting backed by SAS 70 certified infrastructure. “We are pleased to enter into such an intricate health care IT deployment with Complete Healthcare Solutions. As health care continues to evolve and make use of increasingly complex and advanced technology, the combined efforts of companies like CHS and Atlantic.Net will be required to keep sensitive health care information secure and available to the medical professionals around the clock,” said Josh Simon, Director of Data Center Services at Atlantic.Net.” He added, “We consider CHS as a key strategic partner to serve the growing needs of the healthcare segment, and such partnerships are very important to our growth.” “Combining our medical software expertise with Atlantic.Net’s SAS 70 compliant data center facility, we are positioned well to become the medical software solution of choice for health care providers for all of their EMR/EHR data needs. Healthcare providers can now focus on their core business and leverage our expertise and software solutions to comply with the HIPAA and HITECH compliance requirements.” said Joseph Nompleggi, VP of Product Development of Complete Healthcare Solutions, “Atlantic.Net’s reputation for 100% uptime, their secure infrastructure and expertise in Healthcare IT were key components in finalizing our partnership. Our partner’s financial strength and proven track record are something we view with great confidence.” ### About Atlantic.Net Established in 1994, Atlantic.Net is a market-leading business data services provider known for providing exceptional service, simplifying complex technologies and building a brand people trust. Atlantic.Net operates a world-class data center in Central Florida and helps businesses around the globe with their advanced online needs through a number of services. These include Dedicated Servers, Server Colocation, Internet connectivity, Business Continuity, Healthcare IT and managed services such as data backup, security and private networks. Atlantic.Net’s services enable companies to focus on their core business and forgo the expense of capital equipment purchases and ongoing IT management costs. The company’s technological savvy and strategic acumen have been the foundation for the company’s reputation and profitability since 1994. ### About Complete Healthcare Solutions Since 1994, Complete Healthcare Solutions, Inc. has been a global leader in medical software solutions. Founded by Michael A. Penna, CHS’s core mission is to improve the quality of healthcare. CHS helps health care providers focus on their medical practice by providing turnkey software solutions designed specifically with health care providers in mind. The CHS mission is to improve the level of care patients receive from health care professionals by providing software solutions to address every level of patient care and practice management. Complete Healthcare Solutions, Inc. is headquartered in Palmer, Mass. and serves health care providers throughout the United States. With exclusive partnerships with McKesson Corporation and Atlantic.Net, CHS is well positioned to cope with growing demand for electronic medical and health records. For more information, visit [www.completehealthcaresolutions.com](http://www.completehealthcaresolutions.com/). --- # Hosting Solutions Powerhouse Launches Cloud Computing Platform > URL: https://www.atlantic.net/press-releases/hosting-solutions-powerhouse-launches-cloud-computing-platform/ | Published: 2010-12-16 | Author: Editorial Team **Orlando, FL – December 16, 2010** – Today, Atlantic.Net (www.atlantic.net), a privately held hosting solutions provider, announced the launch of “Atlantic.Net Cloud Servers,” an industrial-grade, massively scalable, secure and robust cloud computing platform. Atlantic.Net offers several variations of its easy-to-set up cloud product, including public cloud for self-serve provisioning, private [Cloud Hosting](https://www.atlantic.net/vps-hosting/) for individual companies, and hybrid solutions, mixing cloud with an array of the latest web technologies. Cloud Servers put an end to constant upgrade cycles and reduce capital expenditures for corporations, allowing computing resources to scale up and down with demand. Atlantic.Net Cloud Servers enable organizations of all sizes to build, test, and deploy Windows or Linux servers instantly and enjoy the benefits of pay-as-you-go billing, free set-up, no contracts, and no commitments. “With over 16 years of industry experience, we optimized our cloud computing platform to deliver the best experience with today”s hottest applications on the web,” says Marty Puranik, Founder, President, and CEO of Atlantic.Net. Josh Simon, Director of Data Center Services, states, “Our product development team worked tirelessly to deliver a unique, robust, one-of-a-kind solution tuned for web applications. We studied what was available and decided to make the leap to the next generation of computing technology. From the ground up, our cloud platform implements many innovative features not available in any other platform. We addressed storage, computing capacity, provisioning, and even billing in a whole new way. The resulting computing experience is totally different and more secure than anything that”s been available.” Atlantic.Net Cloud Servers provision instantly, provide very fast disk performance, bill by the second versus monthly or hourly and can be customized to the specific needs of our clients. In addition, Atlantic.Net”s core [Cloud Server](https://www.atlantic.net/vps-hosting/)infrastructure operates at 40 gigabits per second, between four and 400 times faster than competing products. “Our platform is designed to surpass all of the hype and uncertainty and clear up the confusion surrounding Cloud Computing,” said Mr. Simon. For a limited time, Atlantic.Net is offering a free trial of its public cloud platform to show organizations the benefits of moving to the cloud — savings, simplicity, flexibility, security, speed and live expert support 24x7x365! To learn about how Atlantic.Net can provide a custom Cloud Solution for your organization, please visit us on the web at www.atlantic.net ### About Atlantic.Net Established in 1994, Atlantic.Net is a market-leading Hosting Solutions Provider renowned for providing exceptional Infrastructure as a service, simplifying complex technologies and building a brand that people trust. Atlantic.Net operates a SAS 70 Type II audited and certified hosting solutions platform to assist businesses around the globe with their advanced IT needs. Atlantic.Net has long been recognized as a trusted advisor to the global community for its innovative, industry-specific hosting solutions. Atlantic.Net is dedicated to implementing custom tailored hosting solutions to enable organizations to enjoy the benefits of cost savings that reinvigorate their own bottom line. Atlantic.Net’s technological savvy and strategic acumen have been the foundation for its reputation and profitability since 1994. --- # Atlantic.Net Announces Cloud Affiliate Program > URL: https://www.atlantic.net/press-releases/atlantic-net-announces-cloud-affiliate-program/ | Published: 2011-01-10 | Updated: 2026-03-02 | Author: Editorial Team **ORLANDO, Florida — January 10, 2011** – Today, [Atlantic.Net](https://www.atlantic.net/) announces the launch of its Cloud Affiliate Program to coincide with this year’s Affiliate Summit West in Las Vegas, Nevada. The program makes Atlantic.Net’s industrial-grade cloud hosting service available to affiliates. This enables affiliates to take advantage of the hottest and most in-demand technology products on the market today and turn their websites into a cash machine while leveraging Atlantic.Net’s 16 years of hosting excellence. The affiliate program enables affiliates to receive a generous 5% commission, paid out monthly, for as long as referred customers remain with Atlantic.Net. Additionally, there are no caps on earnings made through the program, enabling affiliates to build large monthly revenue streams. “We are very excited about the launch of our Cloud Affiliate Program,” said John Rossiter, Director of Channel Development for Atlantic.Net. “For the first time in our industry, affiliates will be able to refer business unimpeded by any type of cap on commission earnings, making the program into an annuity-building platform for the affiliates.” The program does not require any commitments or advanced technical knowledge and there is no cost to join. Atlantic.Net’s Cloud Affiliate program is simple and straightforward – affiliates can simply register online at https://www.atlantic.net/Affiliates/cloud-affiliate-program.html, choose which banners work best and place them on their blog or website. When a new customer signs up for Atlantic.Net’s Cloud service by clicking through the affiliate’s link, the affiliate starts to earn commissions for the life of the account. **About Atlantic.Net:** Established in 1994, Atlantic.Net is a market-leading hosting solutions provider renowned for providing exceptional infrastructure as a service and simplifying complex technologies. The company operates a SAS 70 Type II audited and certified hosting solutions platform to assist businesses around the globe with their advanced IT needs. [Atlantic.Net](https://www.atlantic.net/) has long been recognized as a trusted advisor to the global community for its innovative, industry-specific hosting solutions. Atlantic.Net is dedicated to implementing custom tailored hosting solutions to enable organizations to enjoy the benefits of cost savings that reinvigorate their own bottom line. Atlantic.Net’s technological savvy and strategic acumen have been the foundation for its reputation and profitability since 1994. Visit: [www.atlantic.net](https://www.atlantic.net/) **Media Contact:** M. Adnan Raja, Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) (321) 206-1371 --- # Cloud Computing Risks in Comparison to Other Data Options > URL: https://www.atlantic.net/hipaa-data-centers/cloud-security/ | Published: 2011-01-22 | Updated: 2025-03-06 | Author: Alexander Wise ## Cloud Security Concerns In speaking to customers over the years, we’ve noticed that one of the most common concerns about cloud computing or IaaS (Infrastructure as a Service) is the fear that transmitting your data and storing it offsite will expose you to security breaches or other risks. We should be clear: cloud computing does involve some risks. Any time you transmit or store data, there’s the chance that something will go wrong. But we believe very strongly that in comparison to other data storage options, *including in-house hardware and networks*, cloud computing offers the best security and ease of use. ### Why Is Cloud Storage the Best Option? To explain this idea, we want to make two main points: 1) Cloud computing is as risky or as safe as the provider makes it. Reputable cloud computing providers like Atlantic.Net use advanced security measures that make it extremely unlikely that data will be lost or stolen. We’ll go into more detail in the next post, but for now, we’ll say that Atlantic.Net has been around for 16 years, and we haven’t survived that long by exposing our clients to unacceptable risk. Our clients include hospitals, hotels, defense contractors, and businesses in other demanding fields. As with any service, professionalism and expertise are critical. 2) *Every* computing option, including in-house data storage, involves risks. Keeping your data in-house isn’t some magic security solution. ### Why Isn’t In-House Data Storage More Secure? The second point above is an important point to remember when thinking about your data security. In-house data gets lost or stolen *all the time*though oftentimes, these events aren’t thought of as ‘data loss.’  Blackberries get dropped, files corrupted, roofs leak, servers crash, and hard drives fail. A 2008 study revealed that 12,000 laptops are lost in US airports *every week*. Viruses, malware, and malicious attacks are constant threats. In-house data is often much *more* exposed than data stored in the cloud servers, and it’s often not properly backed up or encrypted. We’ve seen it repeatedly: in-house storage, particularly for small businesses, means your data is stored unencrypted on consumer hardware (rather than commercial hardware), is not backed up, and is only as physically secure as your front door lock or your fire alarm. Moving your data into the cloud means accepting some known, managed risks in order to eliminate a whole slew of risks that you may not have thought about. ## State-of-the-Art Measures Ensure Data Security There are four main facets to a comprehensive data security approach, and Atlantic.Net has years of experience implementing each of them. You want to ensure that data can’t be intercepted during transmission, can’t be read if it is somehow obtained, is stored in a safe environment, and is backed up in case the primary storage hardware fails. ### Secure Sockets Layer (SSL) First, we use industry-standard Secure Sockets Layer (SSL) encryption on all connections to protect communication between client and datacenter computers. This can be taken further to create Virtual Private Networks (VPN), which use full tunneling to make data transmissions between devices as secure as possible. SSL is a standard security technology for web-based communications; VPN offers even greater security and can be particularly useful for mobile devices and offsite workers. Over the years, Atlantic.Net deployed numerous data networks by utilizing Multiprotocol Label Switching (MPLS). MPLS has proven to provide secure point-to-point tunnels over the network, enabling clients to get the best secure connections available on the market! ### Public Key Encryption (PKE) If desired, any and all of your data can be stored in encrypted format using Public Key Encryption (PKE). This means that the files would be meaningless even if someone did manage to obtain them. ### Securing the Environment The third point, maintaining a secure environment, is more complicated. This kind of security means protection from both hacking and hardware malfunction. Protection from attacks requires you to be vigilant and stay up-to-date on the latest threats, which is difficult to do if you’re not a security professional. You would also need to devote considerable time and money to secure the physical environment for the storage hardware. ### Backups And as to the fourth point, backup: by definition, your most recent data is probably the most useful to you at the moment, so backups also need to be continuous to be valuable. All these steps take time and effort to do yourself, which is why many businesses don’t bother…until after their first major security breach. ## Secure Hosting with Atlantic.Net In contrast, hosting your data with Atlantic.Net means you have a reliable partner with industry experience and knowledge of the latest threats. We’re constantly monitoring and upgrading our systems to ensure that your data is as safe as possible. Our physical facility itself is secure: SAS 70 Type II compliant, with concrete walls, palm scanners, keycard, and eye-scan verification, and CCTV monitoring. To conclude, we believe that storing your data in-house is much like keeping your money under the mattress…it’s fine until it’s not. Cloud computing lets you contract with a professional security resource while also saving money on your IT needs. We encourage our clients and prospective clients to learn more about the real risks and real benefits of in-house data and cloud storage. If you have additional specific security needs, please talk to one of our sales engineers about how we can best serve you. You can always try our [VPS Hosting](https://www.atlantic.net/vps-hosting/) risk-free at www.atlantic.net! Atlantic.Net also offers [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions; learn more about our [HIPAA Data Centers](https://www.atlantic.net/hipaa-data-centers/). --- # Atlantic.Net Enhances Cloud Computing Offerings Through Partnership With cPanel > URL: https://www.atlantic.net/press-releases/atlantic-net-enhances-cloud-computing-offerings-partnership-cpanel/ | Published: 2011-01-27 | Author: Editorial Team **ORLANDO, Florida — January 27, 2011** – [Atlantic.Net](https://www.atlantic.net/), a privately held hosting solutions provider, announced today that it has enhanced its cloud computing offerings by teaming up with [cPanel](https://www.atlantic.net/vps-hosting/), a leading Web hosting control panel software provider. As a result of this partnership, cPanel/WHM is now available on Atlantic.Net’s cloud computing and hosting platform, complementing its existing cloud server offerings and resulting in an efficient, powerful combination that makes Web hosting and managing individual servers easy. “We’re excited to continue to expand our cloud computing offerings,” said Josh Simon, Director of Data Center Services for [Atlantic.Net](https://www.atlantic.net/). “Combining our cloud servers with cPanel/WHM truly simplifies the management of standalone servers, allowing Web hosting resellers and Webmasters across the globe to focus more time on their core business and less time managing their infrastructure.” cPanel/WHM is designed with multiple administrative levels, offering different user interfaces for administrators, resellers, and end users, as well as email-based interfaces. These multiple levels provide security, ease of use, and flexibility for everyone, from server administrators to email account users. Speed is another result of this partnership. cPanel/WHM combined with Atlantic.Net’s world-class hosting service enables users to turn up cPanel/WHM-ready servers in seconds, as opposed to the 60-90 minutes required for self-installation on onsite physical or offsite dedicated servers. “We recognize this is a great opportunity to work with an established and savvy technology company like[Atlantic.Net](https://www.atlantic.net/),” said Aaron Phillips, Vice President of Operations at cPanel. “cPanel/WHM has gained major market share on cloud computing platforms because of its speed, ease of deployment and security options. We look forward to delivering Web hosting automation to Atlantic.Net’s cloud computing platform.” By offering cPanel/WHM, Atlantic.Net is providing an efficient, cost-effective product that will help businesses manage their Web hosting and cloud computing needs. A free trial, including free setup with no contract or commitment, is available at https://www.atlantic.net/cloud. **About Atlantic.Net:** Established in 1994, Atlantic.Net is a market-leading hosting solutions provider renowned for providing exceptional infrastructure as a service and simplifying complex technologies. Serving as a trusted advisor to the global community with its innovative, industry-specific hosting solutions, the company is dedicated to implementing custom-tailored solutions that allow organizations to reinvigorate their bottom line. It operates a SAS 70 Type II audited and certified hosting solutions platform to assist businesses with their advanced IT needs. For more information, visit www.atlantic.net. **About cPanel** Since 1997, cPanel has been a leading innovator and developer of control panel software for the Web hosting industry. Headquartered in Houston, Texas, cPanel builds software that allows Web host professionals to transform standalone servers into fully automated point-and-click Web hosting platforms. cPanel-licensed software allows owners of servers and Websites, along with resellers and developers, to optimize their technical resources and replace tedious shell-oriented tasks with dynamic, intuitive Web-based interfaces. **Atlantic.Net Media Contact:** M. Adnan Raja, Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) (321) 206-1371 --- # Atlantic.Net Adds Cloud Computing API > URL: https://www.atlantic.net/press-releases/atlantic-net-adds-cloud-computing-api/ | Published: 2011-03-03 | Updated: 2026-03-02 | Author: Editorial Team **Users Gain Efficiency, Automation and Flexibility** **ORLANDO, Florida — March 3, 2011** – [Atlantic.Net](https://www.atlantic.net/), a privately held leading hosting solutions provider, announced today that it has released a free application programming interface (API) for its world-class cloud computing platform, allowing customers to more efficiently utilize its robust functionality. Tasks such as provisioning new servers, deleting existing servers, and turning power on and off can now be handled with a few lines of code, rather than having to access a web interface. “Our RESTful API provides developers, system administrators, and resellers the freedom to control and automate their Atlantic.Net cloud services via the programming language of their choice,” said Josh Simon, Director of Data Center Services for Atlantic.Net. “Combined with our easy-to-use point-and-click web-based cloud portal, users of any technical ability can now efficiently manage their cloud resource in the way that’s most comfortable and useful for them.” cPanel/WHM is designed with multiple administrative levels, offering different user interfaces for administrators, resellers, and end users, as well as email-based interfaces. These multiple levels provide security, ease of use, and flexibility for everyone, from server administrators to email account users. Cloud computing has revolutionized the way businesses address their server and computing needs, eliminating the time and expense formerly associated with server management and provisioning. The cloud API is just the latest way Atlantic.Net is adding value to its industry-leading hosting solutions. [Atlantic.Net](https://www.atlantic.net/)is offering a free trial credit of $15 for new customers who commit to trying out its cloud computing suite by March 31. The free trial, including free setup with no contract or commitment, is available at [https://www.atlantic.net/cloud-platform](https://www.atlantic.net/cloud-platform/). **About Atlantic.Net:** Established in 1994, Atlantic.Net is a market-leading hosting solutions provider renowned for providing exceptional infrastructure as a service and simplifying complex technologies. Serving as a trusted advisor to the global community with its innovative, industry-specific hosting solutions, the company is dedicated to implementing custom-tailored solutions that allow organizations to reinvigorate their bottom line. It operates a SAS 70 Type II audited and certified hosting solutions platform to assist businesses with their advanced IT needs. For more information, visit [www.atlantic.net](https://www.atlantic.net/). **Atlantic.Net Media Contact:** M. Adnan Raja, Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) (321) 206-1371 --- # Enterprise Checklist: How to Best Utilize the Cloud > URL: https://www.atlantic.net/hipaa-data-centers/enterprise-checklist-a-look-at-how-it-departments-can-best-utilize-the-cloud/ | Published: 2011-04-07 | Updated: 2026-01-09 | Author: Alexander Wise ***Some factors to consider when deciding if cloud hosting services are a good fit for your business*** ## 1) Determine which IT activities take up the most time and money An internal audit is the first step in transitioning to cloud services. You need to understand where your IT budget is going, but more importantly, where your IT staff feels overwhelmed. Cloud-based resources are not necessarily replacements for an internal IT team; some tasks and functions can be done more effectively by people on-site. But in many cases, tasks like server maintenance, security patching, and backup/recovery can be made part of a cloud services package and free up your IT staff to help with other tasks on-site. ## 2) Talk to a cloud services provider to see if cloud-based services can meet your needs It may seem like this step comes too early, but we find that many customers – and potential customers – don’t really know about recent advances in cloud hosting capabilities. For instance: security, data privacy, plan flexibility, and price have all changed significantly in the past few years, and only a professional cloud hosting resource like Atlantic.Net can give you the most current information. ## 3) Determine the potential time and cost savings of moving some or all of your computing resources to a cloud-based solution This cost-benefit analysis will be unique for your company, your desired slate of services, and the comparative costs of doing it all in-house. The numbers are necessary but not sufficient for the decision, as you can see in step 4. ## 4) Assess the risks and necessary changes to current procedures This last point is an intangible one; you need to decide how open your company culture is to cloud services and to decide the costs, if any, of changing the way you do business. Any big change in business services and business culture will involve an adjustment period. Only you can decide if cloud services are the right fit for your company.  Still, a detailed look at the financial consequences of a change, together with a discussion with current cloud provision experts, can make sure you’re deciding based on the best information available. ## Why the Cloud? Because Scalable Computing Grows with Businesses One of the main advantages of cloud server hosting is its scalability. This is just another way of saying that it’s easy to add or remove computing capacity, bandwidth, storage, and user accounts. Since you don’t need to have any hardware or software installed locally, it’s extremely easy to add more capacity when you need it or decommission capacity when it’s sitting idle.  The model is very flexible! Flexibility and ease of use are important advantages and ones that are often undervalued. If you’re trying to grow your business, your computing needs will frequently change. Imagine, for instance: - you have an interview on a drive-time radio show, and suddenly you’re expecting a lot more website hits - you produce a new demonstration video and want to host it - you want to add an inventory-management tool to organize your supply chain All of these scenarios will place additional demands on your capacity or processing capacity. Using cloud server hosting, you can set up a new virtual or Cloud Server in as little as 30 seconds to handle these needs.  And if you find you have excess capacity you’re not using, you can take those servers offline just as quickly. You’ll never be caught with too little capacity, and you’ll never need to watch a valuable piece of hardware depreciate as it sits unused. The flexibility we discussed also leads to several opportunities for cash savings, which we’ll explore in a future post. From the usability side, scalability means easier management of your people and easier organization of your growth. If you bring in new personnel to support a major product launch or a temporary team to do an internal audit in preparation for an IPO, you can set them all up with user accounts, network access, e-mail, and scheduling – and manage security clearances and automatic expiration – all through a centralized interface, and all without installing any new hardware or software on-site. Cloud computing scalability means that you can have the capacity you need as quickly as you decide you need it. Certain resources can even be set up to scale *automatically* in response to demand (e.g., processing capacity for running large data sets). With flexible modern cloud servers, computing scalability has become easily available to the business world, and smart companies around the globe are learning how to use it to facilitate growth. Atlantic.Net offers an array of services, including managed, dedicated, and [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions – contact us for a consultation today. --- # Atlantic.Net’s New Website Reflects Company’s Evolution > URL: https://www.atlantic.net/press-releases/atlantic-nets-new-website-reflects-companys-evolution/ | Published: 2011-08-03 | Updated: 2026-03-02 | Author: Editorial Team ### Hosting Solutions Provider Enhances Customer Experience **Orlando, FL — August 03, 2011 –** [Atlantic.Net](https://www.atlantic.net/), a privately held leading hosting solutions provider, announced today that it has launched a new website to showcase its cloud computing and virtualization services, highlight its stability and experience, and serve as a resource for those seeking information on the latest hosting technologies. The site was designed with a high-tech look and straightforward navigation, allowing visitors easy access to the latest cutting-edge hosting solutions that can be customized to suit their needs. “Our new website loads faster and provides concise information to our clients with improved navigation. Our goal is to enhance the customer experience and make it as easy as possible for clients to interact with us,” said Adnan Raja, Director of Business Development for Atlantic.Net. “This is the next step forward in helping transform our clients’ vision with powerful and award-winning hosting solutions.” One of the differentiators Atlantic.Net seeks to highlight on the website is its longevity in the industry. The company has thrived over the past 17 years, evolving from an Internet Service Provider to a premier provider of revolutionary hosting technologies. #### About Atlantic.Net Atlantic.Net is a market-leading hosting solutions provider renowned for offering exceptional infrastructure as a service, simplifying complex technologies, and building a brand businesses have trusted since 1994. Serving as a trusted advisor to the global community with its innovative, industry-specific hosting solutions, the company is dedicated to implementing custom-tailored technology that enables organizations to enjoy cost savings that reinvigorate their bottom lines. Atlantic.Net operates SAS 70 Type II audited and certified hosting solutions platforms to assist businesses around the globe with advanced IT services including cloud computing and virtualization. To learn more, please visit [https://www.atlantic.net](https://www.atlantic.net/). # # # **Atlantic.Net Media Contact:** M. Adnan Raja, Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) (321) 206-1371 --- # Atlantic.Net Expands Across the U.S. > URL: https://www.atlantic.net/press-releases/atlantic-net-expands-across-u-s/ | Published: 2011-11-14 | Updated: 2026-03-02 | Author: Editorial Team ### Hosting Solutions Provider Expands Data Center Presence to Five Major Cities **Orlando, FL — November 14, 2011 –** [Atlantic.Net](https://www.atlantic.net/), a privately held leading hosting solutions provider, announced today that it has expanded its U.S. footprint by adding five new data center locations to its portfolio near major Internet arteries and exchange points. Dedicated servers, [colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/), and [virtualization](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/)services are now available through Atlantic.Net in Dallas, New York, Phoenix, Los Angeles, Orlando and Chicago. “We’ve been successfully serving our global clients for 17 years and this expansion gives us the opportunity to provide more geographic redundancy options,” said Adnan Raja, Director of Business Development for Atlantic.Net. “We’re excited to bring the high touch approach that continues to define Atlantic.Net to the new markets and look forward to continued growth for many years to come.” Atlantic.Net offers clients the unique combination of experience and innovation. The company has been operating since 1994, surviving the industry turbulence that’s seen many competitors come and go. Listed on the Inc. 500 list for three years in a row, Atlantic.Net is focused on staying ahead of the curve to provide cutting-edge hosting services to clients that value stability, security and convenience. #### About Atlantic.Net [Atlantic.Net](https://www.atlantic.net/) is a market-leading hosting solutions provider renowned for offering exceptional infrastructure as a service, simplifying complex technologies, and building a brand that businesses have trusted since 1994. Serving as a trusted advisor to the global community with its innovative, industry-specific hosting solutions, the company is dedicated to implementing custom-tailored technology that enables organizations to enjoy cost savings that reinvigorate their bottom lines. Atlantic.Net operates SAS 70 Type II audited and certified hosting solutions platforms to assist businesses around the globe with advanced IT services, including cloud computing and virtualization. To learn more, please visit [atlantic.net](https://www.atlantic.net/). # # # **Atlantic.Net Media Contact:** M. Adnan Raja, Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) (321) 206-1371 --- # Six Cloud Computing Myths > URL: https://www.atlantic.net/hipaa-compliant-hosting/five-cloud-computing-myths/ | Published: 2011-11-18 | Updated: 2026-09-15 | Author: Alexander Wise Separating the myths from the facts of cloud computing is a good place to start when you are trying to figure out the best solution for your business.  Let’s take a look at five popular cloud computing myths and the realities behind them so that you can make intelligent and informed decisions about the cloud. ## My Data Won’t Be Secure in the Cloud Any public or private Cloud Hosting solution will ultimately be as secure as it is engineered to be.  So, ask your cloud provider what steps they have taken to ensure your data’s security.  Reputable cloud providers understand that any serious security breaches will receive publicity and ultimately damage their reputation.  This is why public cloud provider security is often better than that of even most large enterprise data centers. When it comes to specific features to ask about, secure hosting companies will offer features such as a managed firewall, edge protection, intrusion detection and/or prevention, data encryption, multi-factor authentication, and other such security measures. These types of security measures may come standard or maybe add-on services; confirm these security features with the hosting company to ensure you’re satisfied that your data is protected. ## I Won’t Have Full Ownership of My Cloud-Based Data You can have full data ownership if you choose your cloud provider carefully and pay attention to contract terms.  Negotiate contracts that give you full ownership of your data, including your right to choose where the data is stored, if necessary. Essentially, your data ownership situation can be as flexible as the cloud hosting company you choose to engage with. If you can outline the type of control you’d like to have over your data, you can make an informed decision about the data ownership policies of your hosting company or the hosting plan you choose to move forward with. ##  The Cloud Is Always Less Expensive Whether or not the cloud is more costly than other options depends on several factors: the other hosting solutions you are contemplating trying, network and bandwidth requirements, hardware needs, and the cloud service and application being considered.  When comparing the cost of a cloud deployment, make sure you consider the costs of power, cooling, staffing, and data center real estate for deploying the same application in-house or in traditional hosting. Additionally, some types of hosting are more complicated than others, such as managed hosting plans with special hardware or security requirements, or compliance hosting that meets standards outlined in HIPAA regulations or PCI DSS. Every hosting situation is different and therefore may be priced differently. When comparing hosting plans, make sure to consider not just the bottom-line price, but also what’s included in the hosting, as this can help you make the best-informed decision. ##  Cloud Computing Is For Small Businesses, Not Enterprises Studies have shown that the biggest growth in cloud usage is currently coming from enterprises *because the benefits are often greatest for enterprise-sized businesses.* Larger companies are using the cloud for a variety of applications ranging from highly customized websites to social applications and employee collaboration. As economies of scale for hosting companies continue to improve, competitive pricing for enterprise-level cloud hosting packages has become even more viable, meaning switching to the cloud can be as beneficial for a big company as a small one. ##  Cloud Is Not Reliable Top-quality cloud providers have backups in place to prepare for downtime and improve overall reliability. Well-planned backups and redundancies help reduce the effect caused by potential outages. Also, there is little to zero downtime with a proper fail-over installed. Atlantic.Net offers industry-leading service levels backed by a 100% up-time guarantee for our cloud servers. As a general rule, you can check the reliability of your cloud provider by asking about their downtime and uptime statistics, backup policies and offerings, disaster recovery plans, and other such industry standards. ## Implementing the Cloud Will Completely Eliminate the Need for Internal IT Departments There is no question that two types of staffing shifts will occur because of the cloud: individuals working in IT today will need to learn new skills to remain effective in the industry, and certain jobs will shift from the company to the cloud service provider. Additionally, many new IT jobs will be created due to the cloud, including cloud developers, integration specialists, etc. Most organizations will need help from IT to choose, migrate, configure, integrate, and monitor cloud services properly.  The cloud, in turn, can help make IT much more responsive in delivering the applications and data required by the company. Also, cloud-based systems do not manage themselves.  In a cloud hosting environment, the company will need personnel who understand your company’s software applications and how they relate to the business.  Additionally, because security issues become more important when a cloud provider manages data and/or infrastructure rather than internally, IT departments will need individuals who understand the company’s security issues at a deep level. You may find that fewer people are needed to manage your servers with the cloud, but you will still need project managers, network administrators, and business analysts.  With fewer IT resources required for the core tasks, the IT department will have more time to spend on the strategic aspect of its role: delivering business value to the company. ## Better Cloud Hosting with Atlantic.Net At Atlantic.Net, our cloud servers are supported by our industrial-grade, scalable, secure, and robust cloud hosting platform.  Whatever your hosting needs, we have the infrastructure, service, and expertise to serve you.  Our machines can support multiple database-driven sites, streaming media, complex e-commerce sites, and more! Atlantic.Net provides a full line of cloud hosting solutions that give you flexibility and control, backed by almost three decades of experience in connectivity, advanced computing, hosting, and web technologies.  Give your IT department the availability, security, and scalability they demand from their infrastructure by choosing Atlantic.Net’s flexible and affordable [VPS hosting](https://www.atlantic.net/vps-hosting/). Atlantic.Net even supports [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/). Call 1-866-618-3282 today to get started! --- # Atlantic.Net Announces Successful IPv6 Implementation > URL: https://www.atlantic.net/press-releases/atlantic-net-announces-successful-ipv6-implementation/ | Published: 2012-08-06 | Updated: 2026-03-02 | Author: Editorial Team *Atlantic.Net announces that its data center network infrastructure now supports the use of IPv6 to meet the growing bandwidth requirements of its clients.* **Orlando, FL – August 06, 2012 –** Atlantic.Net ([Atlantic Net/](https://www.atlantic.net/)), a privately held leading hosting solutions provider, is pleased to announce the successful implementation of IPv6 (Internet protocol version 6) to their data center infrastructure. IPv6 is a 128 bit long address that offers a plethora of advantages including the allowance for the allocation of many more IP addresses than previously available with IPv4. IPv6 readiness will allow for more efficient network routing, enhanced security, increased resiliency, higher quality connectivity services, and an improved end user experience when accessing content hosted in [Atlantic.Net’s data center environment](https://www.atlantic.net/vps-hosting/). The ever-increasing usage of the Internet over the past decade has gradually reduced the available IPv4 resources to service providers. Therefore, it is becoming essential for service providers to accelerate the adoption to the next generation Internet protocol, IPv6. IPv6 is seen as the “future of the Internet” and will soon become the standard Internet protocol used globally. “We are excited to enhance our infrastructure with IPv6 because we are a futuristic company, always looking to stay ahead of the curve,” said Brett Haines, Director of operations for Atlantic.Net. “Our IPv6 update to our data center infrastructure demonstrates our company’s forward-looking nature.” Compared to IPv4, IPv6 includes enhanced security, which provides increased data confidentiality, integrity and authentication at the network layer. For more information about the cloud hosting services offered by Atlantic.Net, please visit [Atlantic Net/](https://www.atlantic.net/), or call 1-866-618-3282. **About Atlantic.Net** Atlantic.Net is a market-leading Hosting Solutions Provider recognized for providing exceptional business hosting service, simplifying complex technologies, and building a brand that businesses trust since 1994. Atlantic.Net specializes in providing Cloud Servers, Colocation, [Dedicated Servers](https://www.atlantic.net/dedicated-server-hosting/) and [Virtualization Hosting](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/)Services. Atlantic.Net owns and operates a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited and certified data center infrastructure and is dedicated to implementing tailored hosting solutions that enable clients to enjoy the benefits of cost savings. **Atlantic.Net Media Contact:** M. Adnan Raja, Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) [(321) 206-1371](tel:%28321%29%20206-1371) --- # Cloud Industry Leaders Announce Formation of the Cloud Advisory Council > URL: https://www.atlantic.net/press-releases/cloud-industry-leaders-announce-formation-cloud-advisory-council/ | Published: 2012-08-27 | Author: Editorial Team *Teaming to build and enable the next-generation cloud architecture* **SUNNYVALE, CALIF, August 27, 2012 – **The Cloud Advisory Council, an innovative not-for-profit organization dedicated to develop and enable the next-generation cloud architecture, today announced the organization’s formation and directive to provide cloud designers and IT managers with the tools needed to enable computing in the cloud, to strengthen the qualification and integration of cloud solutions and to provide best practices. The Cloud Advisory Council is an industry collaboration of original equipment manufacturers (OEMs), strategic technology suppliers, independent software vendors (ISVs), and end-users across the entire range of the Cloud market segment. Founding members include: AMAX, AMD, Atlantic.Net, Check Point Software, Colfax, DDN, Eucalyptus, Mellanox Technologies, Nanjing Standard Communication, ProfitBricks, SGI, Sugon, Supermicro, and Xeround. Through this organization, new cloud architectures will be researched, defined and specified as a basis for next-generation cloud infrastructures. The council main objectives are: - Definition of the next generation of cloud architecture - Providing open specification for cloud infrastructures - Publications of best practices for optimizing cloud efficiency and utilization - Enable ease-of-use with comprehensive cloud management and tools “The Cloud Advisory Council has been established by industry leaders to develop a cloud specification and best practices for building the most efficient cloud infrastructures. This is critical for vendors as well as for the cloud users,” said Eli Karpilovski, chairman of the Cloud Advisory Council. “The Cloud Advisory Council will assist and provide resources for industry and community organizations to better leverage their infrastructure and improve productivity and efficiency.” “AMAX shares the vision of the Cloud Advisory Council and is dedicated to developing the next generation of cloud architectures in an effort to strengthen the qualification and integration of cloud solutions and give cloud architects and IT managers the tools they need to enable computing in the cloud,” said Jean Shih, President of AMAX. “Our 30 years of award-winning x86 engineering and manufacturing expertise, along with our open architecture approach, affords us maximum flexibility to establish best practices & reference architectures for designing, building and deploying high-quality, cost-effective cloud infrastructures.” “The Cloud Advisory Council represents the best technology vendors and we are excited to be a part of the future. With our twenty years of industry experience being a service provider, this forum will enable us to work closer with leading technology hardware vendors to define the next generation of cloud, “ said Marty Puranik, President of Atlantic.Net, Inc. (https://www.atlantic.net). “Being a leading [cloud hosting provider](https://www.atlantic.net/), we have already developed one of the fastest cloud platforms on the market. Now, working with this elite group of hardware vendors will provide collaborative opportunities to further enhance and strengthen our massively scalable and industrial grade cloud infrastructure.” “For over 13 years DDN has been a leader in storage performance, density and efficiency in the most content intensive storage environments. That is why we are proud to be a founding member of the Cloud Advisory Council and join in its mission that so closely aligns with ours, extending into cloud storage,” said Jeff Denworth, VP of Marketing for DDN. “Our Web Object Scaler product is the ideal cloud storage platform designed for today and tomorrow’s web scale demands and will make a great contribution to the specifications and best practices for building efficient cloud infrastructure.” “Mellanox, as a founding member of the Cloud Advisory Council, is dedicated to develop and collaborate with industry leaders in developing next generation cloud architectures. Together, we share the vision of a simplified and a higher efficient cloud infrastructure that will deliver the best return-on-investment for cloud providers and users,” said David Barzilai, vice president of marketing at Mellanox Technologies. “Mellanox’s end-to-end 10/40GbE and FDR 56Gb/s InfiniBand cloud interconnect solutions have been proven to provide the best interconnect technology to enable cloud deployments of tomorrow. “ProfitBricks is a second generation Cloud Computing IaaS provider. Our vision, formed in 2009, of an IaaS 2.0 platform was launched in 2012 and now we look forward to sharing and learning from other progressive technology providers in the Cloud Advisory Council,” said Conrad Wood, Deputy CTO, Head of Infrastructure at ProfitBricks. “Businesses of all sizes are replacing physical data centers with virtual ones, and it’s key that all of us in the industry deliver on the promise of performance, flexibility, reliability and data security in the cloud.” “SGI is proud to be a founding member of the Cloud Advisory Council,” said Bill Mannel, VP of Product Marketing, SGI, “We welcome the opportunity to apply our leadership and expertise in public cloud solutions to private cloud challenges. SGI has been powering public and government cloud deployments in traditional and mobile datacenter environments, leading the market in design-to-order capabilities, innovative cooling and management software.” “Xeround is excited to be joining the Cloud Advisory Council and take an active role in designing the future of database solutions and data services for the cloud era,” said Razi Sharir, CEO of Xeround. “Xeround’s unique native cloud database technology, distributed architecture, and our extensive experience delivering a zero-management database-as-a-service solution to thousands of cloud users – all put us at a unique vantage point to lead the way we transform data management in the cloud.” The Cloud Advisory Council recognizes also the importance of establishing metrics for Cloud sustainability and performance. For this reason, the Cloud Advisory Council will propose the use of a new metrics, Cloud Center Efficiency (CCE) and Power Consumption Efficiency (PCE), to address inefficient utilizations associated with cloud centers. The impact of efficient usage is emerging as extremely important in the design, location, and operation of current and future cloud centers. **Become a Member of the Cloud Advisory Council Today:** Help influence the direction of the Cloud by becoming a member of the Cloud Advisory Council. Membership to the Council is free. More information can be found on our website: [www.cloudadvisorycouncil.com](http://www.cloudadvisorycouncil.com/). **Visit the Cloud Advisory Council at VMworld San Francisco (August 26-29, 2012):** During VMworld, visit us at our member booths: AMD (Booth #801) and Mellanox Technologies (Booth #2029) for more information about the Cloud Advisory Council, its activities, and membership information. **About the Cloud Advisory Council** The Cloud Advisory Council is a not-for-profit organization with the mission to develop the next generation cloud architecture, to provide cloud designers and it managers with the tools needed to enable computing in the cloud, to strengthen the qualification and integration of cloud solutions and to provide best practices. The Cloud Advisory Council is led by a broad coalition of industry practitioners and corporations. For more information, visit [www.cloudadvisorycouncil.com](http://www.cloudadvisorycouncil.com/), or follow us on Twitter: @Cloud_Advisory. --- # Atlantic.Net Technology Upgrades and Product Enhancements Result in Cost Savings > URL: https://www.atlantic.net/press-releases/atlantic-net-technology-upgrades-product-enhancements-result-cost-savings/ | Published: 2012-09-10 | Updated: 2024-06-11 | Author: Editorial Team *Atlantic.Net slashes its cloud server prices by up to 43%, in addition to lowering outbound bandwidth pricing and offering in-bound bandwidth for free.* **Orlando, FL – September 10, 2012 –** Atlantic.Net ([Atlantic.Net](https://www.atlantic.net/)), a privately held leading cloud hosting solutions provider, is pleased to announce a sharp price reduction for its cloud hosting services for both new and existing customers that utilize its industrial-grade cloud infrastructure.  Effective immediately, Atlantic.Net cloud servers are now discounted up to 43% due to efficiencies gained by leveraging new technologies and a business model based on providing the best possible value, while maintaining the highest level of service. Accommodating high-traffic websites is a specialty of Atlantic.Net.  Therefore, the company is reducing its outbound bandwidth pricing to only 11 cents per Gigabyte.  In addition, Atlantic.Net has lowered its in-bound cloud server bandwidth price to zero (FREE), effective immediately.  Atlantic.Net’s Cloud Servers now start as low as 1.3 cents per hour or $9.49 per month. “This is one more way of saying that we appreciate our clients, as we give them more for less while continuing to provide speed, quality, reliability, and value.” said Josh Simon, Director of Data Center Services for [Atlantic.Net.](https://www.atlantic.net/) “The efficiencies and cost savings we have gained from adopting the latest technologies have allowed us to continue to provide the best value at affordable prices for our customers.” As a hosting solutions provider that owns and operates its own network, Atlantic.Net prides itself in being able to provide clients with world-class infrastructure at a competitive price.  The efficiencies gained from utilizing new technologies have enabled Atlantic.Net to offer even more benefits to its cloud server customers, which will be announced in the coming weeks. For more information about the cloud hosting services offered by Atlantic.Net, including a risk-free trial, please visit [Atlantic.Net](https://www.atlantic.net/) or call [1-866-618-3282](tel:1-866-618-3282). **About Atlantic.Net** Atlantic.Net is a market-leading Cloud Hosting Solutions Provider recognized for providing exceptional business hosting service, simplifying complex technologies, and building a brand that businesses trust since 1994.  Atlantic.Net specializes in providing Cloud Servers, Colocation, Dedicated Servers and Virtualization Hosting Services.  Atlantic.Net owns and operates a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited and certified data center infrastructure and is dedicated to implementing tailored hosting solutions that enable clients to enjoy the benefits of cost savings. **Atlantic.Net Media Contact:** M. Adnan Raja, Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) [(321) 206-1371](tel:(321)%20206-1371) --- # Atlantic.Net Selects Mellanox’s InfiniBand Solutions > URL: https://www.atlantic.net/press-releases/atlantic-net-selects-mellanoxs-infiniband-solutions/ | Published: 2012-09-27 | Updated: 2026-03-02 | Author: Editorial Team ***Cloud hosting powerhouse utilizes Mellanox’s QDR 40Gb/s InfiniBand solution to build one of the most optimized, cost-effective clouds on the market.*** SUNNYVALE, CA. and YOKNEAM, ISRAEL – September. 27, 2012 – Mellanox® Technologies, Ltd. (NASDAQ: MLNX; TASE: MLNX), a leading supplier of high performance, end-to-end interconnect solutions for data center servers and storage systems, today announced that its end-to-end InfiniBand solutions have been selected to interconnect [Atlantic.Net’s](https://www.atlantic.net/) (www.atlantic.net) cloud infrastructure. Atlantic.Net is a leading cloud hosting provider that operates an industrial-grade, massively scalable, secure and robust cloud hosting platform. Utilizing the high performance, cost-effectiveness and scalability provided by Mellanox’s QDR 40Gb/s InfiniBand, Atlantic.Net cloud servers deliver performance-optimized application services at lower costs. “Mellanox’s InfiniBand server and storage interconnect solution is a great compliment to our industrial-grade cloud infrastructure to provide the fastest and most robust cloud on the market. Using QDR InfiniBand, we are able to perform server provisioning in just seconds and provide extremely fast disk performance at 40Gb/s,” said Adnan Raja, Director of Business Development at Atlantic.Net. “Mellanox’s InfiniBand has enabled us to dramatically reduce our cloud infrastructure costs and therefore provide better services to our customers. We will continue to enhance our offerings with many new features in development to provide a unique cloud experience that offers speed, reliability and ease of use.” “Mellanox’s InfiniBand solutions lead the industry with performance, enterprise-class reliability and high availability, improving cloud infrastructure return-on-investment, while helping providers to reduce their capital and operational expenses,” said Gilad Shainer, Vice President of Market Development at Mellanox Technologies. “Leveraging InfiniBand’s performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform.” For a limited time, Atlantic.Net is offering a free trial of its public cloud platform to demonstrate the fastest server provisioning and data processing, along with all the benefits of moving to the cloud — savings, simplicity, flexibility, security, speed and live expert support 24x7x365! Visit https://www.atlantic.net/cloud to learn more. **About Mellanox** Mellanox Technologies is a leading supplier of end-to-end InfiniBand and Ethernet interconnect solutions and services for servers and storage. Mellanox interconnect solutions increase data center efficiency by providing the highest throughput and lowest latency, delivering data faster to applications and unlocking system performance capability. Mellanox offers a choice of fast interconnect products: adapters, switches, software and silicon that accelerate application runtime and maximize business results for a wide range of markets including high performance computing, enterprise data centers, Web 2.0, cloud, storage and financial services. More information is available at www.mellanox.com. ### Mellanox, BridgeX, ConnectX, CORE-Direct, InfiniBridge, InfiniHost, InfiniScale, PhyX, SwitchX, Virtual Protocol Interconnect and Voltaire are registered trademarks of Mellanox Technologies, Ltd. Connect-IB, FabricIT, MLNX-OS, ScalableHPC, Unbreakable-Link, UFM and Unified Fabric Manager are trademarks of Mellanox Technologies, Ltd. All other trademarks are property of their respective owners. **About Atlantic.Net** Atlantic.Net is a market-leading Hosting Solutions Provider recognized for providing exceptional business hosting service, simplifying complex technologies, and building a brand that businesses trust since 1994. Atlantic.Net specializes in providing Cloud Servers, [Colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/), Dedicated Servers and [Virtualization Hosting Services](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/). Atlantic.Net owns and operates a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited and certified data center infrastructure and is dedicated to implementing tailored hosting solutions that enable clients to enjoy the benefits of cost savings. --- # Cloud Services Newsletter – September 2012 > URL: https://www.atlantic.net/announcements/cloud-services-newsletter-september-2012/ | Published: 2012-10-05 | Updated: 2026-09-15 | Author: Alexander Wise Atlantic.Net appreciates your business and wants to keep you updated on the latest Cloud Hosting news at Atlantic.Net.   We are pleased to announce some exciting developments:   **Last Month – Recap:**   - We dramatically lowered the hourly/monthly cost of our industry-leading [Virtual Private Servers](https://www.atlantic.net/vps-hosting/) by up to 43%. - We dropped the price on inbound bandwidth to zero (free!). - We reduced the price of outbound bandwidth to $0.11 per GB (Gigabyte) transferred. - On-Demand Additional IP addresses became available! - Various updated server images became available. - Atlantic.Net is a founding member of The Cloud Advisory Council!   **Atlantic.Net is recognized as one of the Top 20 Cloud Service Providers!** The Cloud Directory has named Atlantic.Net as one of the Top 20 Cloud Service Providers worldwide. Check out our top 20 position on this month’s. **Community Service** We recently sponsored a number of grassroots technology initiatives including iSummit, PHP User Group, CodeCamp and BarCamp. Please visit our Community Involvement page to see if we supported your favorite organizations. [https://www.atlantic.net/About-Us/Community-Involvement.html](https://www.atlantic.net/about-us/) Is your organization looking for support? Email us at [marketing@atlantic.net](mailto:marketing@atlantic.net) to see how Atlantic.Net can help support your initiatives.   **Atlantic.Net Selects Mellanox Infiniband Solutions** We are pleased to announce that we are utilizing Mellanox’s QDR 40Gb/s Infiniband solution to interconnect with our cloud platform. This announcement was made this week at the ISC Cloud’12 event in Mannheim, Germany. Read more about this announcement here at [Mellanox](http://www.mellanox.com/content/pages.php?pg=press_release_item&rec_id=871).   **We would love to hear from YOU!** We truly value your business and your opinions! Do you have a suggestion on how we can improve? Comments and feedback are always appreciated! We strive every day to keep improving our products and services. So, if you have any thoughts regarding something you’d like, improvements we can make, or just some general feedback, please let us know by emailing us at[comments@atlantic.net](mailto:comments@atlantic.net). We would also greatly appreciate referrals, encouraging testimonials and your participation on our [Twitter](https://twitter.com/atlanticnet), [Facebook](http://www.facebook.com/AtlanticNet?v=wall), Google+, and[LinkedIn](http://www.linkedin.com/company/atlantic.net-inc.) pages! We have a number of new features in development that we will be announcing shortly. We want to thank you for your support, and we appreciate your business. That’s all for this month’s newsletter and stay tuned as we roll out more features in the coming weeks. **Atlantic.Net Cloud Team** This monthly newsletter updates you on the latest happenings of the Atlantic.Net Cloud, you can unsubscribe at any time by sending an email to [cloudnews-unsubscribe@atlantic.net](mailto:cloudnews-unsubscribe@atlantic.net). --- # Atlantic.Net Sponsors Upcoming BarCamp and Code Camp in Tampa > URL: https://www.atlantic.net/press-releases/atlantic-net-sponsors-upcoming-barcamp-code-camp-tampa/ | Published: 2012-10-10 | Author: Editorial Team *Atlantic.Net participates in technology-oriented grass roots initiatives by sponsoring BarCamp and Code Camp in Tampa.* Orlando, FL – October 10, 2012 – [Atlantic.Net](https://www.atlantic.net/) (https://www.atlantic.net/), a privately held leading cloud server hosting solutions provider, is pleased to sponsor and support the upcoming BarCamp and Code Camp hosted at the University of South Florida in Tampa on October 13th. Both BarCamp and Code Camp are grass roots technology initiatives, community-driven by dedicated volunteers and financially supported by local businesses like Atlantic.Net. This year, Tampa Code Camp and BarCamp Tampa are co-locating their activities in order to educate, share, promote, and build a bigger technology community in the area. Both events are free and expected to have approximately one thousand software developers, web designers, programmers, service providers, copy writers, educators, and business owners in attendance. “We are excited to be a part of this grass roots initiative because we recognize the long-term effects that these types of local initiatives have on innovation,” said Adnan Raja, Director of Business Development for Atlantic.Net. “Sponsoring BarCamp and Code Camp provides us with a platform to support innovative ideas and help start-up companies advance their business to the next level.” Atlantic.Net has been in business since 1994 and sees the value in lending a hand to local entrepreneurs. Atlantic.Net also plans to support other chapters of BarCamp and Code Camp, as they have supported many other grass roots technology initiatives, as well as local charities. For more information about [Atlantic.Net](https://www.atlantic.net/), or to propose a partnership with your community initiative, call 1-866-618-3282 or email [marketing@atlantic.net](mailto:marketing@atlantic.net). **About Atlantic.Net** Atlantic.Net is a market-leading Cloud Hosting Solutions Provider recognized for providing exceptional business hosting service, simplifying complex technologies, and building a brand that businesses trust since 1994. Atlantic.Net specializes in providing Cloud Servers, Colocation, Dedicated Servers and Virtualization Hosting Services. Atlantic.Net owns and operates a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited and certified data center infrastructure and is dedicated to implementing tailored hosting solutions that enable clients to enjoy the benefits of cost savings. --- # Atlantic.Net Offers Newer Cloud Servers with 40Gigabit Infiniband > URL: https://www.atlantic.net/hipaa-data-centers/newer-cloud-servers-with-40gigabit-infiniband-vs-1gb-or-10gb-correlate-to-faster-and-better-performance/ | Published: 2012-10-24 | Updated: 2026-01-09 | Author: Alexander Wise If you’re starting to notice a system slowdown as your busy server and cloud connections struggle to handle your ever-increasing data volume, you’re ready to upgrade. Newer cloud servers with 40Gigabit InfiniBand vs. 1GB or 10GB can take you to higher bandwidth and lower latency (Latency is another word for the noticeable lag time between server and client. Low latency is important in user interface applications as well as processing large amounts of data backup.) ## 40Gigabit Products Give an Extra “Kick” Your IT data center may be coping with cloud applications that need the extra switching capacity of high-performance [InfiniBand connectors](http://en.wikipedia.org/wiki/InfiniBand). The lower capacity of the 1Gb or 10GB is slowing down data transfer. Upgrading to 40Gigabit switching solutions can provide that extra kick to keep up with the competition. This is especially important for small to medium-sized businesses that rely on the cloud to keep IT costs down and scalability up. ## End-to-End Solutions High capacity InfiniBand technology delivers a higher density bandwidth with a low port-to-port latency measured in just 230 nanoseconds. (One nanosecond is one billionth of a second. So latency here would not be an issue. For example, the blink reaction of the human eye is about 6,000 times slower than that.) For example, Mellanox Technologies markets a 40 Gigabit Ethernet end-to-end switch array that promises a latency of 250 nanoseconds “while providing optimal performance for enterprise data center, financial services, web 2.0, high-performance computing and cloud computing applications.” ## 40Gigabit NICs (Network Interface Controllers) Needed The latest 40Gigabit NICs rest right on the computer motherboard, require low power with high acceleration for hungry cloud applications. The higher bandwidth overcomes the need for previous multiple Ethernet connections to the server. Mellanox Technologies also markets a 40Gigabit Infiniband adapter card that is ideal for applications that compete for bandwidth (clustered databases, applications that work in parallel, etc.). ## New Is Better Atlantic.Net’s Cloud Hosting solution offers the higher capacity 40Gigabit technology that can process more data backup, handle more network traffic, and give better service to clients. Contact us to learn more about our 40Gigabt InfiniBand services. Atlantic.Net also offers [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions; learn more about our [HIPAA Data Centers](https://www.atlantic.net/hipaa-data-centers/). --- # Atlantic.Net achieves SSAE 16 Certification > URL: https://www.atlantic.net/press-releases/atlantic-net-achieves-ssae-16-certification/ | Published: 2012-10-25 | Updated: 2026-03-01 | Author: Editorial Team ### Hosting Solutions Provider’s Data Center achieves internationally recognized standard. ORLANDO, FL – October 25, 2012 – [Atlantic.Net](https://www.atlantic.net/), a privately held leading hosting solutions provider, announced today that it has achieved SSAE 16 (SOC 1) Type II certification for its data center. This certification, an internationally recognized standard developed by the American Institute of Certified Public Accountants (AICPA) and the recognized mark of IT service quality, effectively replaces SAS 70 Type II, Atlantic.Net’s previous certification. “The renewal of this independent third-party certification reflects our continued commitment to operate at the highest standards and demonstrate to our clients that the security of their information and equipment is paramount to us,” said Brett Haines, Director of Operations for Atlantic.Net. “The controls used during the SSAE 16 re-certification process allow us to provide peace of mind to our clients so they can concentrate on growing their business.” Independent accounting firm, Reckenen, Inc., performed an attestation of Atlantic.Net’s colocation data center facilities that included controlled environment, physical security, logical security, and computer operations. Atlantic.Net was awarded Type II certification, which is more comprehensive than Type I, to reflect the auditor’s judgment on how efficiently controls functioned during the defined one-year examination period. **About Atlantic.Net** Atlantic.Net is a market-leading hosting solutions provider renowned for offering exceptional infrastructure as a service, simplifying complex technologies, and building a brand businesses have trusted since 1994. Serving as a trusted advisor to the global community with its innovative, industry-specific hosting solutions, the company is dedicated to implementing custom-tailored technology that enables organizations to enjoy cost savings that reinvigorate their bottom lines. Atlantic.Net operates SSAE 16 Type II audited and certified hosting solutions platforms to assist businesses around the globe with advanced IT services including [cloud hosting](https://www.atlantic.net/vps-hosting/) and [virtualization](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/). To learn more, please visit https://www.atlantic.net. **About Reckenen** Reckenen provides assurance, accounting and consulting services to middle-market and closely held companies as well as non-profit institutions. It offers a sophisticated array of services and capabilities to clients, combined with the personal attention of experienced professionals. Its professional staff is driven to understand each client’s business and fully prepare it to meet unique challenges in a manner that’s personal, proactive, and progressive. To learn more, please visit [www.reckenen.com](http://reckenen.com/outsourced-accounting/).   --- # Atlantic.Net offers Free Cloud to those affected by Hurricane Sandy [Offer has ended] > URL: https://www.atlantic.net/press-releases/atlantic-net-offers-free-cloud-services-affected-data-center-issues/ | Published: 2012-11-03 | Updated: 2026-04-01 | Author: Editorial Team **Atlantic.Net offers relief to businesses affected by data center outages due to Hurricane Sandy.** Orlando, FL – November 3, 2012 – Atlantic.Net (https://www.atlantic.net/), a privately-held leading hosting solutions provider announced today that they will be offering relief to those affected by the Northeastern US data center outages caused by Hurricane Sandy. [Atlantic.Net](https://www.atlantic.net/vps-hosting/) is offering free cloud server hosting services to businesses that rely on data centers currently experiencing issues due to the storm. “Atlantic.Net is offering free cloud server hosting to allow businesses to get back on their feet until they can establish a more permanent solution for their business hosting needs, “ said Marty Puranik, President and CEO of Atlantic.Net. “With the free service, businesses can use our cloud service for a couple of days or a couple of months with no strings attached. We’re trying to be helpful during this catastrophic event,” said Mr. Puranik. While the aftermath of the storm continues to affect many businesses in and around the Northeastern US, Atlantic.Net’s world-class infrastructure allows for cloud servers to be provisioned in a matter of minutes, enabling businesses to get back online in no time. With Atlantic.Net’s offer, there is no required contract and no payment. In order to expedite recovery because each business has different needs, Atlantic.Net is requesting that those affected send an e-mail outlining the services they need to the email address, [sandyrescue@atlantic.net](mailto:sandyrescue@atlantic.net), which has been set up specifically for this offer. **About Atlantic.Net** Atlantic.Net is a market-leading Cloud Hosting Solutions Provider recognized for providing exceptional business hosting service, simplifying complex technologies, and building a brand that businesses trust since 1994. Atlantic.Net specializes in providing [Cloud Servers](https://www.atlantic.net/vps-hosting/), Colocation, Dedicated Servers and Virtualization Hosting Services and multiple[cloud hosting](https://www.atlantic.net/vps-hosting/)options like cPanel and Linux Cloud Hosting.   Atlantic.Net owns and operates a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited and certified data center infrastructure and is dedicated to implementing tailored hosting solutions that enable clients to enjoy the benefits of cost savings. Atlantic.Net Media Contact: M. Adnan Raja, Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) (321) 206-1371 --- # News Update: Atlantic.Net offers Free Cloud Services after Hurricane Sandy > URL: https://www.atlantic.net/disaster-recovery/atlantic-net-offers-free-cloud-services-to-those-affected-by-data-center-issues-in-northeastern-us/ | Published: 2012-11-05 | Updated: 2026-01-09 | Author: Joel ***Atlantic.Net offers relief to businesses affected by data center outages due to Hurricane Sandy.*** Atlantic.Net, a privately-held leading hosting solutions provider, announced today that they will be offering relief to those affected by the Northeastern US data center outages caused by Hurricane Sandy. Atlantic.Net is offering free cloud server hosting services to businesses that rely on data centers currently experiencing issues due to the storm. “Atlantic.Net is offering free cloud server hosting to allow businesses to get back on their feet until they can establish a more permanent solution for their business hosting needs, “ said Marty Puranik, President and CEO of Atlantic.Net. “With the free service, businesses can use our cloud service for a couple of days or a couple of months with no strings attached. We’re trying to be helpful during this catastrophic event,” said Mr. Puranik. While the aftermath of the storm continues to affect many businesses in and around the Northeastern US, Atlantic.Net’s world-class infrastructure allows for Cloud Servers to be provisioned in a matter of minutes, enabling businesses to get back online in no time. With Atlantic.Net’s offer, there is no required contract and no payment. In order to expedite recovery because each business has different needs, Atlantic.Net is requesting that those affected send an e-mail outlining the services they need to the email address [sandyrescue@atlantic.net](mailto:sandyrescue@atlantic.net), which has been set up specifically for this offer. ## **About Atlantic.Net** Atlantic.Net is a market-leading Cloud Hosting Solutions Provider recognized for providing exceptional business hosting service, simplifying complex technologies, and building a brand that businesses trust since 1994. Atlantic.Net specializes in providing Cloud Server Hosting, Managed Cloud Servers, One-click applications, and [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) with [HIPAA disaster recovery](https://www.atlantic.net/disaster-recovery/) services.  Atlantic.Net owns and operates an SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited and certified data center infrastructure and is dedicated to implementing tailored Cloud Server Hosting solutions that enable clients to enjoy the benefits of cost savings. Atlantic.Net Media Contact: M. Adnan Raja, Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) (321) 206-1371 --- # Mellanox, ProfitBricks and Atlantic.net to Host Webinar on Efficient Cloud Infrastructure > URL: https://www.atlantic.net/press-releases/mellanox-profitbricks-atlantic-net-host-webinar-efficient-cloud-infrastructure/ | Published: 2012-11-06 | Updated: 2024-03-01 | Author: Editorial Team **SUNNYVALE, CA. and YOKNEAM, ISRAEL – November 6, 2012 – Mellanox® Technologies, Ltd. (NASDAQ: MLNX; TASE: MLNX),** a leading supplier of high-performance, end-to-end interconnect solutions for data center servers and storage systems, today announced a live, interactive joint webinar with industry-leading cloud server hosting providers ProfitBricks and Atlantic.Net, Inc. on [technology and ROI](https://www.atlantic.net/)considerations for deploying scalable and faster cloud computing infrastructures. The webinar will address several aspects of cloud computing including the main advantages of moving a business into the cloud, compared to running their own hardware. **What:** Enhancing Cloud Providers to Deliver Revolutionary Throughput Performance and Efficiency with Mellanox InfiniBand **When:** Tuesday, November 13, 2012 at 10:00 am Pacific Time / 1:00 pm Eastern Time Register Today “Mellanox is delighted to collaborate with two innovative and promising public cloud providers: Atlantic.Net, Inc. and ProfitBricks on this joint webinar,” said Gilad Shainer, vice president of market development at Mellanox Technologies. “Our end-to-end cloud solution has been adopted by a growing number of public cloud providers to increase infrastructure performance while reducing CAPEX and OPEX. This allows for a better service with a more cost-effective package to their end user.” “Our participation in the free webinar demonstrates our ongoing commitment to help educate our community about the latest technologies available to them,” said Josh Simon, Director of Data Center Services at Atlantic.Net, Inc. “This is a perfect opportunity for organizations to learn about the latest trends in cloud computing and how it relates to enhancing their computing power by getting more for less.” “The cloud empowers businesses of all sizes to rapidly access computer and networking technology that was once only available to the Fortune 50,” said Bob Rizika, CEO, ProfitBricks USA. “ProfitBricks is pleased to support Mellanox in championing high-performance software defined networks in cloud computing infrastructures.” **Supporting Resources:** • Learn more about Mellanox’s complete FDR 56Gb/s InfiniBand solution • Follow Mellanox on Twitter and Facebook **About Mellanox** Mellanox Technologies is a leading supplier of end-to-end InfiniBand and Ethernet interconnect solutions and services for servers and storage. Mellanox interconnect solutions increase data center efficiency by providing the highest throughput and lowest latency, delivering data faster to applications and unlocking system performance capability. Mellanox offers a choice of fast interconnect products: adapters, switches, software and silicon that accelerate application runtime and maximize business results for a wide range of markets including high performance computing, enterprise data centers, Web 2.0, cloud, storage and financial services. More information is available at www.mellanox.com. ### *Mellanox, BridgeX, ConnectX, CORE-Direct, InfiniBridge, InfiniHost, InfiniScale, PhyX, SwitchX, Virtual Protocol Interconnect and Voltaire are registered trademarks of Mellanox Technologies, Ltd. Connect-IB, FabricIT, MLNX-OS, ScalableHPC, Unbreakable-Link, UFM and Unified Fabric Manager are trademarks of Mellanox Technologies, Ltd. All other trademarks are property of their respective owners.* **About Atlantic.Net** [Atlantic.Net](https://www.atlantic.net/) is a market-leading hosting solutions provider renowned for offering exceptional infrastructure as a service, simplifying complex technologies, and building a brand businesses have trusted since 1994. Serving as a trusted advisor to the global community with its innovative, industry-specific hosting solutions, the company is dedicated to implementing custom-tailored technology that enables organizations to enjoy cost savings that reinvigorate their bottom lines. Atlantic.Net operates SSAE 16 Type II audited and certified hosting solutions platforms to assist businesses around the globe with advanced IT services including cloud hosting, [colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/) and [virtualization](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/). To learn more, please visit https://[www.atlantic.net](https://www.atlantic.net/). --- # Atlantic.Net Announces its Sponsorship of Orlando Startup Weekend > URL: https://www.atlantic.net/press-releases/atlantic-net-announces-sponsorship-orlando-startup-weekend/ | Published: 2012-11-07 | Updated: 2024-11-22 | Author: Editorial Team **Atlantic.Net supports local entrepreneurs and startup companies by sponsoring Orlando Startup Weekend on November 9th, 2012.** Orlando, FL – November 7, 2012 – Atlantic.Net (https://www.atlantic.net/), a [privately-held leading hosting solutions](https://www.atlantic.net/vps-hosting/) provider today announced its participation as a Gold Sponsor in this year’s Orlando Startup Weekend beginning on November 9th, 2012 at Voxeo. Startup Weekend is a global grassroots movement of aspiring entrepreneurs passionate about learning how to successfully launch new business ventures. This weekend-long event brings together people from all over the world to pitch their startup ideas and receive feedback from their peers. Teams form based on the top business ideas and the innovation gets kick-started with the creation of business models, design, coding, and market validation. Whether event participants found companies, find a co-founder, make connections with peers, or learn a new skill, attendees are guaranteed to leave the event better prepared to navigate the unique world of startups. “This fantastic initiative really drives innovation in our community,” said Josh Simon, Director of Data Center Services for Atlantic.Net. “Because of its risk-free environment, Startup Weekend allows entrepreneurs to test the waters to see if their ideas would be successful in today’s business world, giving them an advantage in the market.” Atlantic.Net was founded in 1994 by aspiring entrepreneurs Manoj “Marty” Puranik and Jose Sanchez, then both college students at the University of Florida. As once a startup itself, Atlantic.Net has always recognized the value of innovation-oriented grassroots initiatives like Orlando Startup Weekend and therefore consistently strives to support these types of endeavors in the community. For more information regarding the community initiatives in which Atlantic.Net participates, visit their Community Involvement page, https://www.atlantic.net/About-Us/Community-Involvement.html. To propose a partnership with your community initiative, call 1-866-618-3282 or email [marketing@atlantic.net](mailto:marketing@atlantic.net). **About Atlantic.Net** Atlantic.Net is a market-leading Cloud Hosting Solutions Provider recognized for providing exceptional business hosting service, simplifying complex technologies, and building a brand that businesses trust since 1994. Atlantic.Net specializes in providing Cloud Servers, Colocation, Dedicated Servers and Virtualization Hosting Services. Atlantic.Net owns and operates a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited and certified data center infrastructure and is dedicated to implementing tailored hosting solutions that enable clients to enjoy the benefits of cost savings. Atlantic.Net Media Contact: M. Adnan Raja, Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) (321) 206-1371 --- # Cloud – Perfect Solution for Forex, SEO, ASP’s & Engineering Firms! > URL: https://www.atlantic.net/vps-hosting/cloud-perfect-solution-for-forex-seo-asps-engineering-firms/ | Published: 2012-11-12 | Updated: 2026-01-09 | Author: Alexander Wise Strategizing and deploying a strong computing backbone for your company requires an approach that is both sophisticated and affordable. Because keeping budgetary requirements low is crucial for business development, many firms are shifting from dedicated servers to cloud hosting or [VPS hosting](https://www.atlantic.net/vps-hosting/) plans. Atlantic.Net has fully embraced the cloud hosting model, boasting innovative technologies in packages that fit every budget. ## Cloud Server Hosting for SEO Companies and Advertising Agencies Organizations in the fields of advertising, marketing, SEO, and SEM look for high availability and consistently strong speed in hosting solutions. The stress of deadlines can be reduced if network systems are dependable. Plus, load times from any location must be optimized so that potential clients are always impressed. Cloud hosting allows advertising and SEO agencies better flexibility and reliability than is available in any other type of hosting. It’s also cost-effective. Atlantic.Net offers cloud server hosting to streamline your business growth, aware that scalability is essential for advertising and marketing firms as they gain stronger footholds in the market. You can create and deploy brand-new, virtual cloud hosting servers through our user-friendly interface in as little as 30 seconds. ## Cloud Server Hosting for Application Service Providers (ASPs) Application service providers require the most sophisticated and advanced computing tools to process large amounts of data, accessible from any location. A reliable, stable, and easily adaptable system makes it possible for ASPs to optimize efficiency internally and externally. Cloud Server hosting creates an environment in which an organization can develop its solutions and service its clients seamlessly while enjoying cost savings over dedicated servers. Atlantic.Net’s Cloud Server hosting plans are appreciated by application service providers for several reasons: strong performance, unbeatable reliability, and the latest innovations in server elasticity. When businesses need to grow fast, the scalability of the cloud is a particularly enticing feature. With cloud server hosting, billing is “on-demand” – you only pay for the resources you need. In fact, Atlantic.Net adjusts your rate every second depending on use. If you ever need an additional Cloud Server, you can have one running live in 30 seconds through our easy-to-use platform. ## Cloud Server Hosting for Engineering Firms Engineering firms need access to the most cutting-edge technologies to handle and store large files, with the ability to access them quickly from anywhere. An infrastructure with high availability allows the company to complete work effectively and on time while also establishing a strong front to maintain client relationships. Cloud Server hosting provides that infrastructure with a reduction in cost versus dedicated servers. The Cloud Server hosting offered at Atlantic.Net meets the needs of engineering businesses in several core ways: it’s fast, its reliability is based on manifold redundancies, and it is highly scalable. No business wants its infrastructure to slow down its growth. Scalability allows your business to expand quickly without paying extra for a cushion. Atlantic.Net only bills you for what you are using during each individual second. Plus, you can create new Cloud Servers whenever you need them, and you can have them online almost immediately: it takes under a minute to complete the process. ## Cloud Server Hosting for Forex and Stock Trading Currency analysts recognize the foreign exchange market as a field typified by careful timing and, frequently, huge amounts of capital. The strength of an application hosting plan – its performance and reliability – is fundamental to well-executed Forex trading. Cloud server hosting provides Forex professionals a speedy and secure system for easy accessibility to trading data. The plethora of redundancies characteristic of cloud server hosting, with virtualization distributing the server across a wide variety of devices, allows your trading software to run seamlessly around the clock (even while you sleep). Cloud hosting is also more affordable than a dedicated server. Best of all, the cloud server hosting solutions at Atlantic.Net allow immediate scalability: in just 30 seconds, you can create and implement a new cloud server. Forex trading should also be conducted within a computing platform in which security is the utmost priority. Atlantic.Net has the experience to spare, with 2014 marking our platinum anniversary (20 years in business). A two-pronged focus has driven us forward throughout our history: exceeding expectations in both technological advancement and client support. In the industry of Forex trading, your ability to outpace the competition is often dictated by the quality of your cloud server hosting provider (CHP). Atlantic.Net wins the business of many investing and trading organizations because we don’t require a contract or upfront fees. Plus, we guarantee 100% up-time in our SLA (service level agreement). When an engineering firm selects a provider for Cloud Server hosting, it can be a daunting decision due to the widespread competition for its business. Atlantic.Net stands out for engineering companies because there is an upside: we guarantee your site will constantly be running, and we don’t need a commitment. Our SLA promises 100% uptime, and you don’t sign a contract or incur upfront fees. Call us now at 1.866.618.3282 to speak with an advisor about Cloud Server hosting for your business. Call 866.618.3282 today to speak to an advisor and sign up. Build, test, and deploy SSD Cloud Hosting in seconds on a highly redundant hardware platform, try our SSD cloud servers, and see what all the buzz is about! See Atlantic.Net’s [VPS hosting price.](https://www.atlantic.net/vps-hosting/pricing/)   --- # What Exactly Does Uptime Mean in the Cloud Hosting Industry? > URL: https://www.atlantic.net/disaster-recovery/what-exactly-does-uptime-mean-in-the-cloud-hosting-industry/ | Published: 2012-12-14 | Updated: 2024-10-22 | Author: Eddie ## What Is Uptime? The dictionary definition of uptime constitutes the time during which a piece of equipment, such as a computer, is functioning or able to function.  In terms of cloud hosting, uptime is defined as the percentage of time that your server or website is active and able to function during the course of a year.  For example, if a Cloud Server has an uptime average of 99.5%, this means that for all but 1.83 days per year, you can expect that your website/server will remain active. ## Understanding Uptime Guarantees Many cloud hosting companies create aggressive SLAs around their uptime guarantee, whether it’s a 99%, 99.9%, or 100% uptime guarantee.  Having a hosting provider that guarantees uptime is much better than one that doesn’t.  Keep in mind – uptime guarantees do not include scheduled outages or maintenance. ### Examples of Uptime Guarantees and the Equivalent Expected Downtime Some common uptime guarantees are broken down into a mathematical translation of expected downtime include: - 98% uptime = 28.8 minutes/day or 3.4 hours/week or 14.4 hours/month or 7.3 days/year - 99% uptime = 14.4 minutes/day or 1.7 hours/week or 7.2 hours/month or 3.65 days/year - 99.5% uptime = 7.2 minutes/day or 0.84 hours/week or 3.6 hours/month or 1.83 days/year - 99.9% uptime = 1.44 minutes/day or 0.17 hours/week or 0.72 hours/month or 8.8 hours/year Uptime is very important for businesses that rely heavily on their websites or whose customers rely on them.  If customers start thinking your business’ website is unreliable, they may stop coming back, resulting in a loss of sales.  Even more, if search engines like Google start to think that your website is unreliable, they will stop visiting as well, resulting in poor search engine results. ## Atlantic.Net’s Uptime SLA At Atlantic.Net, our industry-leading cloud hosting services are backed by a 100% Uptime Guarantee.  This means that we guarantee all critical infrastructure components will be available 100% of the time in a given month, excluding scheduled maintenance.  No one can guarantee that nothing will ever go wrong, but with a 100% uptime SLA, we set the expectation to do the very best possible.  Atlantic.Net’s Cloud Hosting is faster – take it for a test drive!  Call 866-618-3282 today to take advantage of the free $25 trial of our cloud servers! Atlantic.Net also offers [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions with [HIPAA disaster recovery](https://www.atlantic.net/disaster-recovery/) – contact us today for a consultation. --- # Atlantic.Net Announces Partnership with Zenergy Works > URL: https://www.atlantic.net/press-releases/atlantic-net-announces-partnership-zenergy-works/ | Published: 2012-12-27 | Updated: 2026-03-02 | Author: Editorial Team *Zenergy Works to assist Atlantic.Net in further establishing their business presence in California.* **Orlando, FL – December 27, 2012 –** Atlantic.Net ([Atlantic Net/](https://www.atlantic.net/)), a privately-held leading hosting solutions provider, today announced its partnership with Zenergy Works, a local marketing agency based in Santa Rosa, California. As a part of the marketing strategy, Atlantic.Net initially contracted billboards through Clear Channel Outdoor. Zenergy Works will assist Atlantic.Net with their marketing initiatives to help establish local presence in San Francisco, California with online marketing in and around Silicon Valley. “Zenergy Works is excited about our partnership with [Atlantic.Net](https://www.atlantic.net/) to promote their business hosting services in the California marketplace,” says Eric Van Cleave, Managing Partner and CEO for Zenergy Works. “Zenergy Works has a proven track record of success and we are confident in their abilities to help strengthen our brand recognition in California”, said Adnan Raja, Marketing Director of Atlantic.Net. As companies move towards doing more business online, opportunities are created for Atlantic.Net to provide a reliable platform that enables them to do just that and much more. To learn more about the cloud hosting solutions offered by Atlantic.Net, please visit https://www.atlantic.net. **About Atlantic.Net** [Atlantic.Net](https://www.atlantic.net/) is a market-leading Cloud Hosting Solutions Provider recognized for providing exceptional business hosting service, simplifying complex technologies, and building a brand that businesses trust since 1994. Atlantic.Net specializes in providing Cloud Servers, Colocation, Dedicated Servers and [VirtualizationHosting Services](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/). Atlantic.Net owns and operates a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited and certified data center infrastructure and is dedicated to implementing tailored hosting solutions that enable clients to enjoy the benefits of cost savings. **About Zenergy Works** Zenergy Works is a California website design company, Search Engine Optimization Company, Social Media Optimization Company, and a National Internet Marketing Company based in Santa Rosa. For more information, please visit www.zenergyworks.com. **Atlantic.Net Media Contact:** M. Adnan Raja, Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) [(321) 206-1371](tel:%28321%29%20206-1371) --- # What Is On-Demand Computing, and What Are Its Advantages? > URL: https://www.atlantic.net/life-sciences-pharma-biotech/on-demand-computing-advantages/ | Published: 2013-01-15 | Updated: 2026-03-01 | Author: Alexander Wise ![](https://www.atlantic.net/wp-content/uploads/2013/01/icon_on-demand-computing-e1624124314641.png) ## What Is On-Demand Computing? On-demand computing is a business computing model in which computing resources are made available to the user on an “as needed” basis.  Rather than all at once, on-demand computing allows cloud hosting companies to provide their clients with access to computing resources as they become necessary. ![](https://www.atlantic.net/wp-content/uploads/2013/01/on-demend-graphic-05.jpg) ![](https://www.atlantic.net/wp-content/uploads/2013/01/icon_advantages-e1624124426359.png) ## What Are the Advantages of On-Demand Computing? The on-demand computing model was developed to overcome the common challenge that enterprises encountered of not being able to meet unpredictable, fluctuating computing demands efficiently.  Businesses today need to be agile and need the ability to scale resources easily and quickly based on rapidly changing market needs.  Because an enterprise’s demand for computing resources can vary dramatically from one period to another, maintaining sufficient resources to meet peak requirements can be costly.  However, with on-demand computing, companies can cut costs by maintaining minimal computing resources until they run into the need to increase them while only paying for their use. Industry experts predict on-demand computing to soon be the most widely used computing model for enterprises.  In fact, IBM’s vice-president of technology and strategy stated, “The technology is at a point where we can start to move into an era of on-demand computing.  I give it between two and four years to reach a level of maturity.” Another [important customer service objective](https://www.dialpad.com/blog/customer-service-objectives/) achieved through on-demand computing is immediate support and assistance to customers, which can improve customer satisfaction and retention. ![](https://www.atlantic.net/wp-content/uploads/2013/01/icon_manufacturing-industry-e1624124486180.png) ## **On-Demand Cloud Computing Success Stories** [According to a recent article in Forbes](http://www.forbes.com/sites/louiscolumbus/2013/05/06/ten-ways-cloud-computing-is-revolutionizing-manufacturing/), many in the manufacturing industry seek cloud-based services to increase efficiency from a supply chain, distribution, and services standpoint. In fact, more than a few manufacturers have already adopted cloud-based applications throughout their companies. According to MintJutras, a research-based consulting firm specializing in analyzing enterprise applications’ business impact, SaaS applications make up 22% of all manufacturing and distribution software installed today. Additionally, this number is expected to grow to 45% within ten years. The main goal of manufacturers is to make themselves easier to work with both externally and internally. Manufacturers are constantly facing pressure to increase accuracy, improve process speed, and effectively utilize their internal intelligence to make every supplier, distributor, and service interaction worthwhile.  Cloud-based services are helping to give these companies the chance to do just this. ## **Benefits of On-Demand Cloud Computing** Experts say that cloud-based services have the potential to streamline key areas of business so that manufacturers have more time to sell their products and invest in new ones. As mentioned in the Forbes article, here are just a few of the ways that cloud computing is revolutionizing the manufacturing industry: - Capturing and applying company-wide data through the use of analytics, business intelligence, and rules engines. - Piloting and quickly moving to a full launch of supplier portals and collaboration platforms, complete with quality management dashboards and workflows. - Accelerating new product development and introduction strategies to attain time-to-market objectives. - Managing indirect and direct channel sales from a single cloud platform tracks sales results at the individual, group, and divisional levels. - Automating customer service, support, and common order status inquiries online. - Increasing reliance on two-tier [ERP software](https://project-management.com/erp-software/) strategies to gain greater efficiencies in material planning and supplier management and reduce logistics costs. Cloud computing is seen as the future of the Internet as more and more industries are starting to see the potential that the cloud offers different aspects of business. ![](https://www.atlantic.net/wp-content/uploads/2013/01/icon_here-to-stay-e1624124564753.png) ## Future of On-Demand Cloud Computing Once you move to the Cloud, you’ll be wowed! You probably won’t go back to your old, clunky hosting solution, either. After switching to the Cloud, companies both large and small are unlikely to switch back to a less evolved solution. Here are some reasons why cloud computing is here to stay. One of the most common reasons companies move to the Cloud is to provide employees with the ability to utilize many devices and applications that they are familiar and comfortable with to get the job done more productively. Organizations are eliminating device regulations and allowing employees to use their own, a move that wouldn’t have been possible without the Cloud. IBM recently published a study in which they questioned approximately 2,000 midsized businesses about their implemented IT practices. An astonishing 70 percent said they actively pursued cloud-based analytics for greater efficiency, upgrades, and insights! According to Intel, as smartphones and tablets are purchased by consumers at a rapid pace, the number of servers necessary to support the devices skyrockets. In fact, for every 600 smartphones or every 120 tablets, a new server will need to be deployed to handle the data load. If you are using a smartphone or a tablet, you’re helping to keep the Cloud alive! In 2011, 90% of Microsoft’s research and development budget–$9.6 billion in all— was spent on cloud computing strategy and products. That’s incredible! There’s no doubt that Microsoft wouldn’t be spending that money if the technology wasn’t a sure thing. **Advantage of On-Demand Cloud Computing** Recent studies have shown that the greatest growth in cloud usage is currently coming from enterprises. Enterprises are using the cloud for a variety of applications, including highly scalable company websites, social applications, grid computing for scientific research, employee collaboration, and several other web-based services. In the enterprise, cloud hosting can take various forms, including: - Software as a Service (SaaS) – This area is seeing the highest level of adoption, especially in the fields of Customer Relationship Management (CRM), Human Resource Management System (HRMS), etc. - Infrastructure as a Service (IaaS) – IaaS is finding a moderate level of adoption in development and preproduction environments. - Platform as a Service (PaaS) – This area has high potential. Still, it remains at a relatively low level of adoption due to barriers such as limits on expansion and difficult integration. ## **Real Advantages of On-Demand Cloud Computing** There are many reasons for an enterprise to shift to IT solutions that include cloud hosting.  First of all, capital and operating costs can be drastically reduced by utilizing resources solely when you need them and paying only for what you use. In addition, with a managed Cloud Hosting solution, the burden associated with managing various IT resources across the enterprise is given to the cloud hosting provider so that IT personnel can focus on delivering value to the company. Finally, cloud hosting provides for business dexterity since the entire IT infrastructure can be scaled up or down to meet demand. Companies can quickly and easily respond to the needs of the rapidly changing markets to ensure they are always providing value to their customers. ## **Conclusion:** Like any other project within the enterprise, project management principles such as estimation accuracy, project planning, requirements management, and quality management are all important for cloud projects. Adopting [VPS hosting](https://www.atlantic.net/vps-hosting/) should be well thought out as part of an enterprise-wide strategy so that each stakeholder understands the benefits of the cloud and where it fits into the overall IT goals of the enterprise. Moving your business into the cloud offers many advantages due to the on-demand nature of cloud server hosting. At Atlantic.Net, we can provide your business with the scalability, accessibility, and financial savings that cloud hosting provides. Our goal is to help our clients save time and money by operating their business more efficiently. Atlantic.Net specializes in research-oriented cloud solutions – learn more about our solutions for life sciences, [pharma hosting](https://www.atlantic.net/life-sciences-pharma-biotech/), and [biotech hosting](https://www.atlantic.net/life-sciences-pharma-biotech/).   --- # On Target Web Solutions Enters into a Strategic Marketing Partnership with Atlantic.Net > URL: https://www.atlantic.net/press-releases/on-target-web-solutions-partners-with-atlantic-net/ | Published: 2013-01-31 | Author: Editorial Team On Target Web Solutions has been chosen by Atlantic.Net to assist with content syndication and online marketing initiatives. Orlando, FL (January 31, 2013) – On Target Web Solutions, a leading Internet Marketing & SEO company in Orlando, has announced that it has entered into a strategic partnership with [Atlantic.Net](https://www.atlantic.net/) to assist with their online marketing initiatives. As a part of the agreement, On Target Web Solutions will assist [Atlantic.Net](https://www.atlantic.net/) with content syndication, as well as help enhance their search engine visibility by leveraging their expertise as a full-service online marketing agency. In addition, On Target will assist with Atlantic.Net’s overall PR and social media marketing initiatives. “Our company is focused on creating valuable partnerships with our clients to not only set higher goals, but also to achieve them,” said Tom Jelneck, President and Founder of On Target Web Solutions. “We are very excited to work with Atlantic.Net to assist them with growing their business online.” “We are confident in On Target Web Solutions’ ability to deliver quality service. We had many options to choose from and we picked them for their strong reputation and work ethic,” said Adnan Raja, Marketing Director of Atlantic.Net. “With higher online visibility, we can increase our competitive edge in the hosting market.” For more information about the SEO and content marketing services offered by On Target Web Solutions, please visit http://ontargetwebsolutions.com/content-marketing/ or call 407-830-4550, nationwide at 866-998-6886. **About On Target Web Solutions, Inc.** On Target Web Solutions was founded by Tom Jelneck in July 2005 in Orlando, Florida. Specializing in Search Engine Optimization (SEO), Internet Marketing, Social Media Marketing and Web Design, On Target engages online tools to achieve successful growth for businesses while educating clients about ethical online business practices. About Atlantic.Net Atlantic.Net (https://www.atlantic.net/) is a market-leading Cloud Hosting Solutions Provider recognized for providing exceptional business hosting service, simplifying complex technologies, and building a brand that businesses trust since 1994. Atlantic.Net specializes in providing Cloud Servers, Dedicated Servers and [Virtualization Hosting Services](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/). Atlantic.Net owns and operates a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited and certified data center infrastructure and is dedicated to implementing tailored hosting solutions that enable clients to enjoy the benefits of cost savings. --- # FREE DNS with Cloud Server Hosting Now Available > URL: https://www.atlantic.net/press-releases/free-dns-cloud-server-hosting-now-available/ | Published: 2013-02-13 | Updated: 2026-03-02 | Author: Editorial Team *Atlantic.Net announces a new self-service Cloud DNS management feature.* **Orlando, FL – February 13, 2013 –** Atlantic.Net ([Atlantic.Net](https://www.atlantic.net/)), a privately held leading hosting solutions provider, is pleased to announce the availability of Cloud DNS, a new Cloud feature designed to increase efficiency by offering self-service DNS record management backed by a geographically diverse, redundant, and replicating architecture. Cloud DNS (Domain Name Service) is available with both new and existing Atlantic.Net Cloud Server hosting accounts at no extra cost. Cloud DNS enables self-management of DNS records for controlled domain names and DNS PTR records for Atlantic.Net-owned Cloud IPs. “Built from the ground-up, our Cloud DNS is a great addition to the growing features that complement our cloud server hosting service.” said Josh Simon, Director of Data Center Services for Atlantic.Net. “Providing the convenience and tools that allow our clients more control and flexibility demonstrates our ongoing commitment to continually enhance our customer experience.” There is no limit to the amount of DNS records that customers can manage via Cloud DNS and live support is available 24/7/365. For more information about the cloud hosting services offered by Atlantic.Net, please visit [Atlantic.Net](https://www.atlantic.net/) or call 1-866-618-3282. **About Atlantic.Net** Atlantic.Net is a market-leading Hosting Solutions Provider recognized for providing exceptional business hosting service, simplifying complex technologies, and building a brand that businesses trust since 1994. Atlantic.Net specializes in providing award-winning [Cloud Hosting](https://www.atlantic.net/vps-hosting/), Colocation, Dedicated Servers and [VPS Hosting](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/). Atlantic.Net owns and operates a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited and certified data center infrastructure and is dedicated to implementing tailored hosting solutions that enable clients to enjoy the benefits of cost savings. **Atlantic.Net Media Contact:** M. Adnan Raja, Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) [(321) 206-1371](tel:%28321%29%20206-1371) --- # Atlantic.Net Becomes Latest IP Network Gateway to South America > URL: https://www.atlantic.net/press-releases/atlantic-net-becomes-latest-ip-network-gateway-south-america/ | Published: 2013-02-28 | Author: Editorial Team *Advanced network peering will improve IP access to Latin America.* **Orlando, FL – February 28, 2013 – Atlantic.Net (https://www.atlantic.net),** a privately-held leading hosting solutions provider, today announced expansion of their network peering and Internet carriers via interconnecting their Data Center network to the Miami Internet exchange hub. This expansion will greatly enhance the company’s backbone infrastructure, as well as enable Atlantic.Net to provide critical overseas connectivity to Latin America. This upgrade will not only add [significant additional bandwidth](https://www.atlantic.net/), but it will also enable the service provider to scale-up their network bandwidth on an on-demand basis. With this latest peering arrangement, Atlantic.Net will have access to additional premier network facilities, as well as the lowest latency route to Brazil, enabling Atlantic.Net to become a network gateway to South America. With Atlantic.Net’s recent investment in the latest networking infrastructure, the company is positioned to serve their clients’ hosting needs, who are looking to expand into South American markets. Atlantic.Net will offer dedicated managed hosting, colocation, and virtualization hosting services to major Latin American markets including Brazil. “The new network peering in Miami, Florida is a strategic addition to Atlantic.Net’s world-class data center infrastructure,” said Marty Puranik, President and CEO of Florida based Atlantic.Net Hosting Solutions Provider. “The rapidly growing connectivity demands and strong economic potential of Brazil present an attractive opportunity for Atlantic.Net to continue to expand its network to better serve clients in these growth markets.” Along with its network extension to Miami, Florida, Atlantic.Net will continue to maintain a strong local footprint in Orlando, Florida. To learn more about the hosting solutions offered by Atlantic.Net, please visit https://www.atlantic.net. **About Atlantic.Net** Atlantic.Net is a market-leading Hosting Solutions Provider recognized for providing exceptional business hosting service, simplifying complex technologies, and building a brand that businesses trust since 1994. Atlantic.Net specializes in providing Cloud Servers, Colocation, Dedicated Servers and Virtualization Hosting Services. Atlantic.Net owns and operates a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited and certified data center infrastructure and is dedicated to implementing tailored hosting solutions that enable clients to enjoy the benefits of cost savings. **Atlantic.Net Media Contact:** M. Adnan Raja, Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) (321) 206-1371 --- # Atlantic.Net’s Network Expansion Results in Cost Savings for Cloud Customers > URL: https://www.atlantic.net/press-releases/atlantic-nets-network-expansion-results-cost-savings-cloud-customers/ | Published: 2013-03-19 | Updated: 2024-06-11 | Author: Editorial Team *All cloud servers now include 1 GB free out-bound data transfer and additional transfer fee has been reduced to only 5 cents per GB!* **Orlando, FL – March 19, 2013 –** Atlantic.Net, a privately held [Cloud Hosting](https://www.atlantic.net/vps-hosting/) solutions provider, is pleased to announce a sharp price reduction for its out-bound bandwidth prices for both new and existing cloud customers. 1 GB free out-bound data transfer is now included with all cloud servers. The out-bound data transfer rate has been also reduced to 5 cents per GB from 11 cents per GB. In addition, all in-bound data traffic is always free for Atlantic.Net cloud customers. Atlantic.Net recognizes that serious businesses require considerable bandwidth, which Atlantic.Net is equipped to accommodate. Last month, Atlantic.Net announced expansion of their network peering to enhance its backbone infrastructure and add additional bandwidth. This expansion has enabled the company to pass along cost savings to their customers. “Our latest network peering and infrastructure enhancements have enabled us to provide our clients the best value without compromising quality,” said Josh Simon, Director of Data Center Services for Atlantic.Net. “Our greatly reduced out-bound data transfer rate offers fantastic savings over the competition, at 58% less expensive than our competitors.” Atlantic.Net’s award winning cloud servers offer high-performance at very competitive pricing. Atlantic.Net’s cloud hosting plans start from only 1.3 cents per hour (or $9.49 per month). Atlantic.Net’s cloud servers are provisioned in real time within seconds, thus boosting efficiency and affordability. For more information about the cloud server hosting services offered by Atlantic.Net or to sign up for a free cloud server trial, please visit [Atlantic.Net](https://www.atlantic.net/) or call 1-866-618-3282. **About Atlantic.Net** Atlantic.Net is a market-leading Hosting Solutions Provider recognized for providing exceptional business hosting service, simplifying complex technologies, and building a brand that businesses trust since 1994. Atlantic.Net specializes in providing [Cloud Servers](https://www.atlantic.net/vps-hosting/), Colocation, Dedicated Servers and Virtualization Hosting Services. Atlantic.Net owns and operates a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited and certified data center infrastructure and is dedicated to implementing tailored hosting solutions that enable clients to enjoy the benefits of cost savings. **Atlantic.Net Media Contact:** Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) [(321) 206-1371](tel:%28321%29%20206-1371) --- # Do You Know the Difference between a Gigabit and a Gigabyte? > URL: https://www.atlantic.net/hipaa-compliant-hosting/do-you-know-the-difference-between-a-gigabit-and-a-gigabyte/ | Published: 2013-03-29 | Updated: 2026-02-28 | Author: Eddie Many people confuse the terms “gigabit” and “gigabyte” by either using them synonymously or confusing their meanings. While both are units of measurement describing digital data, how much they measure and how they are used are different. We explain these different meanings to define them clearly. ## A Bit A bit is the most basic unit used in computing and telecommunications. A bit is a binary unit, meaning it can have one of two values: a 1 or a 0. In computers, this value can indicate expressions such as “true” or “false,” “yes” or “no,” “come hither,” or “ain’t gonna happen.” (Just kidding with that last one!) ## A Byte A byte is 8 bits*. Werner Buchholz, an American computer scientist, coined the term “byte” in 1956 during the construction of the IBM Stretch computer. He deliberately spelled the term differently to avoid confusion with the term “bit.” ## The Difference When we need to refer to numbers of bits or bytes as those numbers get larger and larger, we use the prefixes from the metric system (see table below for examples). To distinguish between the two when abbreviating them, the lower-case “b” traditionally represents “bit”, whereas the upper-case “B” represents “byte”. | prefix | multiplier† | bits-to-bytes | bytes-to-bits | | --- | --- | --- | --- | | kilo- (K) | 1,000x | 1Kb = 125B | 1KB = 8Kb | | mega- (M) | 1,000,000x | 1Mb = 125KB | 1MB = 8Mb | | giga- (G) | 1,000,000,000x | 1Gb = 125MB | 1GB = 8Gb | | tera- (T) | 1,000,000,000,000x | 1Tb = 125GB | 1TB = 8Tb | They are also different in how they are used as units of measurement. Bits are generally used when measuring the rate of data transfer. When we talk about network throughput (or what is often called “bandwidth”) or internal data transfer (such as in describing SATA or USB speeds), we use [megabits per second](https://thewordcounter.com/meaning-of-mb/) or gigabits per second. Bytes are generally used when describing data capacity. We measure the sizes of our files and the hard drives that store them in gigabytes and terabytes (and, perhaps soon, petabytes!). At Atlantic.Net, you do not have to worry about staying up-to-date with confusing terminology because our expert technicians will handle all of the work for you! To learn more about our cloud hosting services, contact our team of hosting professionals today by calling 1-866-618-3282. Right now, we are offering dedicated server hosting plans from just $64 a month every month and no contractual commitments. * Fun Fact: 4 bits, or half a byte, is called a nibble. It’s rarely used, but it’s official! † Kind of. In actual usage, particularly in measurements of RAM or hard disk space, the metric prefixes aren’t decimal-based but binary-based. This table shows the differences between these two types of calculations. | prefix | decimal | multiplier | binary | multiplier | | --- | --- | --- | --- | --- | | kilo- (K) | 103 | 1000x | 210 | 1024x | | mega- (M) | 106 | 1,000,000x | 220 | 1,048,576x | | giga- (G) | 109 | 1,000,000,000x | 230 | 1,073,741,824x | | tera- (T) | 1012 | 1,000,000,000,000x | 240 | 1,099,511,627,776x | You can see how that numbering scheme can grow to be confusing! ![Difference between a Gigabit and a Gigabyte](https://www.atlantic.net/wp-content/uploads/2013/03/gigabit-vs-gigabyte-infographic.jpg) Learn more about our [HIPAA compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. Explore our [HIPAA compliance guide](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). --- # Atlantic.Net Offers Huge Discounts on Dedicated Server Hosting Plans > URL: https://www.atlantic.net/press-releases/atlantic-net-offers-huge-discounts-dedicated-server-hosting-plans/ | Published: 2013-03-31 | Updated: 2024-06-11 | Author: Editorial Team #### *No-Contract Dedicated Servers now start at only $64 a month!* **Orlando, FL – March 31, 2013 –** Atlantic.Net ([Atlantic.Net](https://www.atlantic.net/)), a privately held leading hosting solutions provider, today announced a promotion offering heavily discounted pricing on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/). For a limited time, Atlantic.Net customers can take advantage of no-contract dedicated server hosting plans starting at only $64 a month. Atlantic.Net [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) provide a cost effective solution to organizations looking to spend less and get more. Fully equipped with top features and backed by 10 Terabytes of data transfer, Atlantic.Net dedicated servers are offered without any term agreement. ““We are focused on providing exceptional value to our customers, not just for a month or two, but every month. That is why our dedicated servers come with 10 Terabytes of data transfer, start at $64 per month, and are available free from contracts or term commitments.” said Josh Simon, Director of Data Center Services for [Atlantic.Net](https://www.atlantic.net/). “For nearly 20 years, Atlantic.Net has helped thousands of organizations with industry-leading dedicated server solutions and we look forward to doing the same for decades to come.” ” Clients can customize and configure their dedicated servers online and instantly place an order for a fast deployment at [https://www.atlantic.net/dedicated-server-hosting](https://www.atlantic.net/dedicated-server-hosting/). Additionally, Atlantic.Net customers can add cPanel & WHM (WebHost Manager) to a dedicated server for only $35 per month. All dedicated servers are hosted at Atlantic.Net’s world-class data center facility and backed by a 100% uptime guarantee. For more information about the dedicated server hosting services or other server hosting solutions offered by Atlantic.Net, please visit [Atlantic.Net](https://www.atlantic.net/) or call 1-866-618-3282 24/7/365. **About Atlantic.Net** [Atlantic.Net](https://www.atlantic.net/) is a market-leading Hosting Solutions Provider recognized for providing exceptional business hosting service, simplifying complex technologies, and building a brand that businesses trust since 1994. Atlantic.Net specializes in providing Cloud Servers, Colocation, Dedicated Servers and Virtualization Hosting Services. Atlantic.Net owns and operates a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited and certified data center infrastructure and is dedicated to implementing tailored hosting solutions that enable clients to enjoy the benefits of cost savings. **Atlantic.Net Media Contact:** Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) [(321) 206-1371](tel:%28321%29%20206-1371) --- # Atlantic.Net Offers up to 50% off on all Cloud Server Hosting Plans > URL: https://www.atlantic.net/press-releases/atlantic-net-offers-50-off-cloud-server-hosting-plans/ | Published: 2013-04-24 | Author: Editorial Team ## ***Atlantic.Net offers 1 GB RAM Cloud Servers for only $14.00 a month with no term commitment!*** **Orlando, FL – April 24, 2013 –** Atlantic.Net, a privately held leading hosting solutions provider, today announced a steep price reduction of up to 50% off on all Windows and Linux Cloud Server hosting plans. Both new and existing customers of Atlantic.Net can take advantage of this reduced pricing on all new Cloud Server deployments. Backed by SSD accelerated redundant storage housed on separate disk arrays, Atlantic.Net Cloud Servers offer much faster build times and performance than traditional cloud servers. Coupled with Mellanox’s Infiniband technology, Atlantic.Net Cloud Servers are an effective cloud solution for organizations looking to increase efficiency and in turn, reduce their overall IT costs. “Not only have we reduced our [Cloud Server](https://www.atlantic.net/vps-hosting/) pricing by up to 50%, we are continuing to offer per-second billing, which is extremely beneficial for organizations with large server deployments.” said Josh Simon, Director of Data Center Services for Atlantic.Net. “The efficiencies gained by the recent expansion of our infrastructure has allowed us to pass along a huge savings to our customers, while maintaining our high quality of service.” ” In addition to the new reduced pricing, Atlantic.Net’s Cloud offers many innovative features such as API Access, 24/7/365 support, free DNS management, additional IP addresses, cPanel & WHM, and much more! Clients can provision Cloud Servers online within seconds. To get started, please visit  our [Cloud Hosting](https://www.atlantic.net/vps-hosting/) page. **About Atlantic.Net** Atlantic.Net is a market-leading Hosting Solutions Provider recognized for providing exceptional business hosting service, simplifying complex technologies, and building a brand that businesses trust since 1994. Atlantic.Net specializes in providing Cloud Servers, Colocation, [Windows Cloud Hosting](https://www.atlantic.net/vps-hosting/),  Dedicated Servers and Virtualization Hosting Services. Atlantic.Net owns and operates a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited and certified data center infrastructure and is dedicated to implementing tailored hosting solutions that enable clients to enjoy the benefits of cost savings. **Atlantic.Net Media Contact:** Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) [(321) 206-1371](tel:%28321%29%20206-1371) --- # Atlantic.Net Adds Cogent to its Network Providers > URL: https://www.atlantic.net/press-releases/atlantic-net-adds-cogent-network-providers/ | Published: 2013-04-30 | Updated: 2026-03-02 | Author: Editorial Team ***Carrier neutral data center in Orlando adds Cogent to available networks.*** **Orlando, FL – April 30, 2013 –** Atlantic.Net ([Atlantic Net/](https://www.atlantic.net/)), a privately held hosting solutions provider, announced the expansion of their network peering by adding Cogent to their carrier neutral data center. Cogent is one of the world’s largest Internet Service Providers and operates one of the largest Tier 1 optical IP networks with over 27,500 Gbps of internetworking. This addition enhances Atlantic.Net’s ability to meet clients’ increasingly large bandwidth requirements. “Adding Cogent to our network is a great compliment to our infrastructure, which means more options and cost-effective bandwidth for our clients,” said Brett Haines, Director of Operations at [Atlantic.Net](https://www.atlantic.net/). “We are always striving to find ways to make our service even more affordable, so that we can continue to provide the utmost value to our customers.” Atlantic.Net currently operates a carrier neutral facility with carriers including TW Telecom, Level 3 Communications, Verizon, AT&T, Bright House Networks, Windstream, FPL Fibernet, and Cogent. Atlantic.Net’s Data Center is SSAE 16 Certified, which proves ideal for organizations looking to house their infrastructure in a secure facility that meets compliance requirements. Additionally, customers can take advantage of cost savings by colocating in a world-class data center facility. To learn more about the hosting solutions offered by Atlantic.Net, please visit [https://www.atlantic.net](https://www.atlantic.net/). **About Atlantic.Net** Atlantic.Net is a market-leading Hosting Solutions Provider recognized for providing exceptional business hosting service, simplifying complex technologies, and building a brand that businesses trust since 1994. Atlantic.Net specializes in providing Cloud Servers, Colocation, Dedicated Servers and Virtualization Hosting Services. Atlantic.Net owns and operates a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited and certified data center infrastructure and is dedicated to implementing tailored hosting solutions that enable clients to enjoy the benefits of cost savings. **Atlantic.Net Media Contact:** Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) [(321) 206-1371](tel:%28321%29%20206-1371) --- # Atlantic.Net Announces 1TB Of Free Data Transfer With All VPS And Cloud Servers > URL: https://www.atlantic.net/press-releases/atlantic-net-announces-1tb-free-data-transfer-vps-cloud-servers/ | Published: 2013-05-15 | Updated: 2024-06-11 | Author: Editorial Team *All Atlantic.Net customers can now send 1000 times more outbound data from their VPS and Cloud Servers at no additional cost!* **Orlando, FL – May 15, 2013 –** Atlantic.Net (https://www.atlantic.net/), a privately held leading hosting solutions provider, announced today that all [VPS Hosting](https://www.atlantic.net/vps-hosting/) & Cloud Servers have been upgraded to include 1TB of free outbound data transfer. All inbound data transfer continues to be free. This upgrade means customers can now send 1000 times more outbound data from their VPS and [Cloud Servers](https://www.atlantic.net/vps-hosting/) at no additional cost. This effectively eliminates the bandwidth costs for most VPS & Cloud Servers hosted on the Atlantic.Net platform. “We are excited to provide this significant additional bandwidth at no extra cost to our customers,” said Marty Puranik, President and CEO of Atlantic.Net. “As our clients continue to require increased bandwidth, our company is paving the way for accelerated demand for VPS and Cloud Servers.” Atlantic.Net’s award winning VPS and Cloud Server hosting plans start at only $0.007 per hour (or $5.11 per month). For more information about the cloud server hosting services offered by Atlantic.Net, or to sign up for a free cloud server trial, please visit [Atlantic net](https://www.atlantic.net/) or call 1-866-618-3282. **About Atlantic.Net** Atlantic.Net is a market-leading Hosting Solutions Provider recognized for providing exceptional business hosting service, simplifying complex technologies, and building a brand that businesses trust since 1994. Atlantic.Net specializes in providing affordable Cloud Servers, Colocation, Dedicated Servers and Virtualization Hosting Services. Atlantic.Net owns and operates SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited and certified data center infrastructure and is dedicated to implementing tailored hosting solutions that enable clients to enjoy the benefits of cost savings. **Atlantic.Net Media Contact:** Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) [(321) 206-1371](tel:%28321%29%20206-1371) --- # 1TB Transfer Speed – How Much Is 1TB of Bandwidth? > URL: https://www.atlantic.net/vps-hosting/1tb-bandwidth-how-really/ | Published: 2013-06-17 | Updated: 2024-11-09 | Author: Joel Early last month, Atlantic.Net officially announced that all virtual private servers received an upgrade that provides an increased outbound data transfer capacity of 1 terabyte (TB), absolutely free. This gives our customers the ability to send 1,000 times more outbound data from their cloud servers than previously available. This essentially eliminates bandwidth costs, ultimately saving you more money. But, what does the phrase “1TB of outbound data transfer” actually mean? ## What Is a Terabyte? First, let us explore the concept of the terabyte. A terabyte (TB) is a unit of measurement for digital information. For comparison purposes, one terabyte equals one trillion bytes, or 1,000 gigabytes (GB). When the first hard disk drives were created in the 1950s, they were the astonishing size of a household refrigerator. Even though they were massive in size, they only had the capacity of a few megabytes (MB). In 1982, the first IBM PC was released, and this computer had a storage capacity of just 5 MB. Three decades later, a major improvement was released to the general public—a 1TB disk drive that is just 2.5 inches wide—perfect for a laptop computer. In 2012, a 1TB USB flash drive was created—a concept that would have baffled the inventor of the original hard drives in the 1950s. ## How Much Does a 1TB Hard Disk Cost? In 2007, 1TB hard disks cost over $350. Just five years later, you can find the same capacity for under $100. For just a little more money, you can purchase a 4TB hard drive at $179. To imagine how much information a terabyte of storage can hold, consider the following information. One terabyte of audio recorded at studio quality will contain around 2,000 hours of audio. The same amount of storage will hold around 620,000 photos. This is surely enough space, even for most professional photographers. With a 1TB hard drive, you can store 2,000 hours of digital videos and around 1,000 hours’ worth of DVD-quality movies. Near the end of May, tech company Yahoo! unveiled a new interface for its popular high-quality image and video hosting site, Flickr. This update included a new key feature in the hopes of reeling in new visitors from across the world—a whole terabyte of free space per user! This is approximately 70 times bigger than the storage capacity offered by other image hosting websites. ## About Data Transfer Next, let us investigate the concept of data transfer. In a self-explanatory fashion, data transfer references the volume of information transferred to and from your website. For example, every time a customer looks at your inventory in your online store, data is transferred. Each time a visitor purchases an item, more data is being transferred. Additionally, any email sent to you at your domain name consumes data. Essentially, the concept of data transfer and allocated amounts should be a key factor in choosing a hosting provider. With the increase of 1TB of outbound data transfer, you can rest assured knowing that your information will continue running steadily and at a good price; Atlantic.Net’s award-winning cloud server hosting plans start at only $0.007 per hour. That’s just $5.11 per month! ## Why Cloud Servers Are Ideal A cloud hosting solution is perfect for businesses that need more dedicated services. An Atlantic.Net cloud server allows customers to build, test and deploy Windows or Linux servers powered by cloud technology in just seconds. Our cloud server hosting solutions offer simplicity, security, scalability, and reliability backed by the most up-to-date platforms available. With a cloud server, you are guaranteed to receive the full amount of allocated memory, CPU, network, and other features that you are paying for, and you have the ability to scale your resources as necessary. ## Benefits of Cloud Hosting with Atlantic.Net Additionally, with a cloud server hosted by Atlantic.Net, you will see the benefits of free nightly backup, no contracts, continuously running power systems, and live technical support available 24 hours a day, seven days a week for 365 days a year. In addition to our award-winning cloud server hosting solutions, we offer private cloud hosting capabilities unseen elsewhere. With almost three decades of experience in connectivity, advanced computing, hosting, and web technologies, our cloud servers are truly the best in the industry. We realize that a one-size-fits-all approach to cloud computing practically never works, so we offer private and hybrid cloud options that are completely customizable depending on your personal or business needs. Our proven cloud server hosting guarantee includes a 100% guaranteed network uptime, 100% guaranteed cloud server hardware, and a 100% guaranteed infrastructure. Do you see a pattern yet? With Atlantic.Net cloud servers, you only pay for what you use—nothing more. Our cloud server hosting also reduces the costs associated with sites that receive high traffic and maintain large databases. Try Atlantic.Net industry-leading [VPS hosting](https://www.atlantic.net/vps-hosting/)today and receive a free $10 trial credit! There are no commitments or contracts, and setup is completely free. Now that Atlantic.Net has increased the previous capacity of outgoing data transfers to 1TB, you can clearly see that this is a big deal. What are you waiting for? Contact Atlantic.Net today and see [VPS hosting prices](https://www.atlantic.net/vps-hosting/pricing/). --- # How the Cloud Makes Analyzing Big Data More Efficient > URL: https://www.atlantic.net/vps-hosting/cloud-analyzing-big-data-efficient/ | Published: 2013-06-21 | Updated: 2026-01-09 | Author: Joel Have you ever waited until the last minute to complete a critical project, only to find out that you have to process significantly more information than you can actually handle? You watch the clock count the hours and then minutes down to your deadline, but there is still so much material in front of you that you still have left to analyze that you want to just pull out your hair. If you answered yes, you have experienced the concept of big data first hand. ## What Is Big Data? The term “big data” refers to data sets that are so incomprehensively large and complex that they are practically impossible to process, even when using database management tools or other traditional data processing applications. Scientists in many fields—including genomics, physics, and biological research, to name a few—continuously encounter obstacles in their research due to having to handle extensive sets of data. These obstacles result in budget and time management setbacks and can be incredibly frustrating. There is positive news, though: as of 2012, limits on the size of data sets that are feasible to process in a moderate amount of time were as high as a few exabytes of data. If you are unfamiliar with the concept of the exabyte, it is the equivalent of *one quintillion*bytes. That’s pretty massive! ## How Is Big Data Changing? Big data is growing exponentially larger every day. This is partly because data is being collected on mobile devices, remote sensors, software logs, cameras, microphones, and wireless networks, to name a few. And the number of devices collecting data continues to increase at an impressive pace. Consider how much information you collect daily; you call coworkers, text friends, take pictures of your dog and check Facebook before going to bed. Amazingly, the world’s technological ability to store information has practically doubled every forty months since the 1980s. In 2012, 2.5 quintillion bytes of data were created ***every day***! What is considered to be big data varies greatly depending upon the capabilities of the organization in question that is managing the set and on the capabilities of the applications that will be used to process and analyze the data set. ## Big Data in Action An example of the concept of big data in science is the Large Hadron Collider. This collider is famous for being the world’s largest and highest-energy particle accelerator; 150 million sensors deliver data 40 million times per second, and there are approximately 600 million collisions per second. That’s a lot of data! Researchers filter out 99.999% of the unnecessary collected data, but this still creates 100 collisions of interest per second. If all data were to be collected for analysis, it would exceed 500 exabytes per day. To put this number into perspective, this is equivalent to 500 quintillion bytes per day—almost 300 times higher than all other sources in the world combined. We live in an age where having a title such as “Data Scientist” is not far from reality. The convergence of two groundbreaking technologies—big data and cloud computing—are creating far-reaching implications that will soon change the world. ## The Potential of Big Data Big data is essential in allowing organizations to better anticipate and react to consumer demands. But when unprocessed data accounts for at least 80% of the world’s information, many companies make critical decisions with just 20% of the data they have analyzed. This certainly is not ideal. ## How the Cloud Helps with Big Data The cloud hosting computing model provides a perfect match for big data since cloud computing provides absolutely unlimited resources on demand. Cloud-based solutions purchased from providers allow companies to access processing applications on remote networks that were not previously available and allow them to access these applications via web browsers or even mobile applications. The Cloud helps corporations to save money by providing a means to store massive quantities of data without a massive cost. In the Cloud, hardware and software do not need to be purchased or even stored in-house, improving both the company budget and available office space. Cloud solutions reduce the energy consumption of servers, thus lowering overhead and reducing carbon footprints. Also, storing data within the cloud allows the information to be accessed across various devices—desktops, tablets, mobile phones, and more, all while being strongly protected against natural disasters and malicious attacks. When cloud computing and big data are combined to create a convenient, versatile, and automated solution, profit generation opportunities are sky-high. ## How Can Atlantic.Net Help? Since 1994, Atlantic.Net has been providing premier hosting services to corporations, small businesses, and personal clients, as well as [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. We have always been one step ahead of the latest trends in technology, and we have taken advantage of this stronghold by offering scalable, secure, and budget-friendly cloud servers. To learn more about how you can try a cloud server with absolutely no commitment, contact us today at 866-618-3282. Explore Atlantic.Net’s [VPS hosting prices](https://www.atlantic.net/vps-hosting/pricing/).   --- # How Can Cloud Hosting Help SEO? > URL: https://www.atlantic.net/hipaa-compliant-wordpress-hosting/how-can-cloud-hosting-help-seo/ | Published: 2013-06-24 | Updated: 2026-01-09 | Author: Eddie If you are at all familiar with the foundations of search engine optimization (SEO), you may be aware that hosting a website in the cloud provides benefits in the form of search engine rankings and online reputation. However, it is also important to understand exactly why this occurs and what other benefits hosting your website on a reliable and affordable cloud server provides for you and your business. Search engine optimization, more commonly known in the marketing and advertising industries simply as SEO, is the process of affecting the visibility of a website or web pages in a search engine’s natural (organic) search results. ![Comic How Can Cloud Hosting Help SEO?](https://www.atlantic.net/wp-content/uploads/2014/01/Comic-Strips-Atlantic-16-001.jpg) To maximize results, Internet marketing firms analyze how particular search engines work, what people are most likely to search for at any given time, and which search engines are preferred by the client’s target demographic. Optimizing a website typically involves incorporating meta tags and manipulation of coding and the publication of engaging and relevant content regularly. Corporations and small businesses are transitioning to the cloud at an astonishing pace and are often left questioning how the move will affect their search engine rankings. There’s good news here, though: the cloud affects [SEO](https://nomadseo.com/) in a very positive way. With a cloud hosting solution, all the necessary hardware and software is rented through a provider. These rented computers allow customers to run their own applications in an environment that provides limitless space. Additionally, this information can be accessed anywhere and anytime, straight from any device. Individual web pages are locally hosted in the cloud. A large multinational corporation may have different versions of their site, for the United States, United Kingdom, and Australia, for example, initially created to target specific countries. These websites are all practically identical and will soon begin competing for the highest authority value. This makes a user in the United States is more likely to see the US version, and a user in the United Kingdom will more than likely see the UK version at the top of their search engine. For SEO purposes, the speed in which a web page loads is extremely critical. Load speed is one of the factors Google considers when determining page authority and ranking. Websites hosted in the cloud have been proven to load faster when compared to other hosting solutions because the servers are typically close to the IP location of the user. So, websites hosted in the cloud will have a higher authority in this regard. As more companies and individuals make the switch to the cloud, search engines will have to continue to tweak and update their algorithms as necessary to follow the latest trends and most effective ways of ranking authority. Those who are familiar with SEO are likely already aware that the location of the server as well at Top Level Domain (TLD) plays a decisive role in attracting geographically targeted visitors. The domain (IP) also plays a key role as search engine bots look at the site’s IP address to determine the server’s location. For example, consider .COM sites versus .UK. When is the last time you accidentally got redirected to a .UK site when there was a .COM one available? If you own an Internet marketing firm or are interested in starting one, you may want to consider starting a reseller hosting agreement with a hosting provider. Reseller hosting is a form of web hosting in which the account owner and manager has the ability to deviate hard drive space to host websites and other applications on behalf of third parties. So, instead of going directly to a large company that provides hosting services, customers who are interested in your reseller hosting plans will be able to receive one-on-one friendly contact and service. The reseller has two different hosting options: they can rent a dedicated server and allocate to third parties as necessary or resell shared hosting services with a cloud solution. In the latter case, the reseller is permitted to sell an agreed-upon amount of hardware and resources instead of handling a physical server, which can be difficult and time-consuming. The typical web hosting reseller is often a marketing firm, web development company, or a systems integrator looking to offer web hosting as an additional service. However, reseller hosting is also a great, inexpensive way for entrepreneurs to start their own companies. The data center operator is responsible for maintaining network infrastructure and hardware, and the reseller is responsible for attracting and maintaining a customer base. Even better, reseller hosting doesn’t require extensive knowledge of the technical aspects of web hosting. Atlantic.Net is a trusted [HIPAA hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions provider and has been in the business since 1994. Now, you and your organization can reap the benefits of our award-winning reputation by becoming a solutions referral partner. If you don’t have the time to dedicate to a reseller program, our referral program allows you to pass on referrals, and as long as the customer stays within good standing, you get paid. If you’re interested in joining our partnership, contact us today at partners@atlantic.net or 1-866-618-3282. Atlantic.Net also offers [HIPAA WordPress](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/) hosting solutions. --- # Common Mistakes Made During Cloud Hosting Migration > URL: https://www.atlantic.net/hipaa-data-centers/common-mistakes-made-during-cloud-migration/ | Published: 2013-07-01 | Updated: 2025-03-06 | Author: Alexander Wise ## *Cheaper *Rather than *Better* Atlantic.Net CEO Marty Puranik notes that companies have been more focused on cheaper solutions in recent years, especially given the Great Recession’s impact. Still, excessive focus on price is a mistake. All of the great advancement that humanity has achieved arose from a focus on *better* rather than *cheaper*, he stresses. Having tunnel vision for anything but the price is just one of the mistakes made by organizations when they migrate to the cloud. Tech reporter Jeff Bertolucci talked about typical problems that arise in his *InformationWeek* article “[10 Cloud Migration Mistakes to Avoid](http://www.informationweek.com/cloud/10-cloud-migration-mistakes-to-avoid/d/d-id/1318829?image_number=1).” Four of the errors he highlights are throwing out traditional equipment, failing to make applications cloud-ready, not taking big data into account, and assuming all clouds are the same. ## Throwing Out Traditional Equipment Many organizations don’t know exactly what to do with their hardware once they switch systems over to the cloud. “A common mistake that enterprises make is either to throw out their old hardware or pay someone to remove it,” said Bertolucci. “[Since] the market for used IT computers and gear is north of $300 billion, … enterprises should try a hardware exchange to recoup some IT budget cash.” ## Failing to Make Applications Cloud-Ready Often companies don’t perform the testing to see how they might need to adjust applications for optimal cloud server hosting performance. Recognize that you may need to make some tweaks to get the most out of your new environment. ## Not Taking Big Data into Account We are constantly reminded in the technology press that big data is extraordinarily valuable. However, transferring cumbersome apps and huge amounts of data can be tricky. Some firms even mail their disks to the hosting provider, says Bertolucci. “Another thorny issue is finding the most affordable way to sync on-premises and cloud environments,” he adds. “The bottom line: Pre-move preparation is the best way to achieve smooth cloud migration.” ## Assuming All Clouds Are the Same Finally, you want to be aware that there really is no “the cloud.” Cloud computing is an infrastructural approach that is implemented in different ways by different providers. For example, Puranik explains how Mellanox technology helps us keep prices 30-40% lower than the competition while delivering about twice the performance. Atlantic.Net also offers [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions; learn more about our [HIPAA Data Centers](https://www.atlantic.net/hipaa-data-centers/). --- # 10 Things Your Hosting Company May Not Tell You > URL: https://www.atlantic.net/vps-hosting/10-things-your-hosting-company-may-not-tell-you/ | Published: 2013-07-15 | Updated: 2025-03-06 | Author: Alexander Wise When searching the market for a cloud solution, make sure you ask vendors for the whole story. As we all probably already know, not all cloud servers are created equal. It is highly recommended that you look beyond marketing claims, search the fine print, and ask the right questions. Here are ten critical points you should bring up when talking to potential providers, especially because they probably won’t bring it up first. ## 1. Initial integration If your company is looking to implement a cloud hosting solution, you need to be aware, step-­by-­step, how this is actually going to happen, especially when it comes to software and products. For instance, what will happen if you already have a particular business management software application that you’d like to put on the cloud, but another branch of your organization tries to use another one? Make sure the process of integration and implementation is one of your first questions. ## 2. Hidden costs A Cloud Server is infamous for being extremely cost-­effective, but it is important to note that some companies will take advantage of this by incorporating hidden costs into their subscription plans. Make sure you completely understand their pricing model and what you can expect to see on your monthly bill, explained by the vendor down to the cent. Additionally, you should ask if upgrades to new versions of their software are included. ## 3. Real uptime numbers All providers want to list ideal numbers, if possible, especially when it comes to uptime. To be clear, all networks will eventually go down. What’s important is how they will recover. While a few vendors will completely disclose their statistics regarding uptime, you can also ask for reports generated within the past few months about maintenance schedules. ## 4. How responsible are you for security? All vendors should have best practices implemented for security—from data to infrastructure and personnel—but don’t assume that you have zero responsibility in keeping your information safe. Make sure to ask who is responsible for what in terms of security. Keep in mind that you will most likely be responsible for implementing encryption policies and other similar factors. ## 5. Encryption keys As discussed above, the security of your information is one of the most important factors when it comes to choosing a hosting provider. It is important to make sure your information is encrypted at all times. Also, find out how the vendor manages encryption keys and the rules and policies they have regarding managing these keys. This is a critical issue to bring up no matter what industry you work in, especially if you are in a regulated industry such as healthcare or finance. ## 6. Data restoration Once your data is in the Cloud, how quickly can you get this information back in the instance of network downtime or a disaster? Ask the vendor for any data they may have that shows real-­‐world examples. ## 7. Multi-­tenancy One of the fundamental reasons the Cloud creates such a cost-­effective solution is that the Cloud architecture is essentially a single machine with several clients renting out a portion of that machine. Since the machine isn’t dedicated to one single user, costs are lowered. If installed correctly, multi-­tenancy is a great way for multiple companies to use a single platform with the utmost security and privacy. However, if done incorrectly, you can lose sensitive information or have your data infiltrated by someone with malicious intent. As discussed in previous points, you need to be proactive and utilize full disk encryption. ## 8. How to move your information to another cloud or hosting solution Moving from one hosting type to another is never easy, but it is often catastrophic with the Cloud. Ensure you are informed ahead of time how to get your data from the Cloud and how easy or difficult it will be to move to another solution, such as a dedicated hosting plan. If you decide to move from the Cloud down the road, you will need to know how to easily manage this with minimal data loss. ## 9. Privacy When it comes down to the privacy of your data, the type of Cloud utilized by the vendor can greatly affect the privacy rules. For instance, if the vendor’s Cloud relies on advertising for revenue, they will likely want to use your information to give to advertisers. On the other side, if the revenue comes from end-users, the vendor will want to keep your information protected. Make sure you read the fine print! ## 10. Environmental concerns According to a recent Greenpeace report, nearly $450 billion is spent annually on new data center facilities. The Environmental Protection Agency (EPA) has warned that approximately two percent of North American electricity consumption comes from data centers. This number is only expected to increase exponentially as the years go by. If you are environmentally conscious, be sure to ask how “green” the vendors’ cloud solution is. ## Conclusion As you can see, you will need to ask potential vendors a large number of questions before you should officially sign a contract. Some will disclose this information upfront, and some will want to withhold this information. Ideally, you should choose a company that wants to create a genuine relationship with its clients, not one that simply looks at customers as a money source. At Atlantic.Net, we pride ourselves on the fact that we create full transparency with our clients. To learn more about the cloud server hosting services we provide, including [VPS hosting](https://www.atlantic.net/vps-hosting/), contact us today. See Atlantic.Net’s [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # Are You Guilty of Shadow IT Practices? > URL: https://www.atlantic.net/hipaa-compliant-hosting/are-you-guilty-of-shadow-it-practices/ | Published: 2013-07-22 | Updated: 2025-03-06 | Author: Alexander Wise ## What Is Shadow IT? It’s a new term, but an old concept: the phrase “shadow IT” refers to employees using computing methods not previously approved by the company to work more efficiently. Sometimes used interchangeably with the term “stealth IT,” IT departments are often kept in the dark about these methods, only finding out once it’s too late. But if employees are getting their work done, what can be so bad about it? ## How Does Shadow IT Impact Organizations? Shadow IT is looked upon by many as being an initial source of innovation as such means occasionally evolve into prototypes for future approved IT solutions. However, many of these measures are out of line with the organization’s control, documentation, and security requirements. This is particularly important for companies in the finance and healthcare industries, where the use of **unofficial data devices** compromise compliance-centric initiatives such as the Health Insurance Portability and Accountability Act (HIPAA) and the International Financial Reporting Standards (IFRS). ### What Are Unofficial Data Devices? The term “unofficial data devices” covers a wide range of implementations, from portable storage devices, online messaging software, unapproved online e-mail services, document sharing utilities and self-developed databases, and even undocumented spreadsheets. ## Security Risks of Shadow IT Security risks most often present themselves when sensitive data and applications are moved outside their designated protected networks. For example, if Human Resource Manager Carol exports a secure Excel spreadsheet from its designated location within the company’s cloud server and saves it to a folder within Google Drive, this would technically be considered an act of shadow IT. Most commonly, employees use shadow IT measures because they assume that there are no other ways to perform their job more effectively. As such, countless individuals send documents via email to their personal address to continue working from home, even if they know that this is likely not allowed by their organization’s policy standards. If employees are efficient and productive, what could be wrong with shadow IT? Besides the security risks stated above, some other implications of shadow IT include wasted time, investment, and inefficiencies. So let’s discuss this more thoroughly. ## Other Shadow IT Risks ### Inefficiency and Errors If Carol updated her spreadsheet from Google Drive and sent it to her assistant, who then edited and sent it back, Carol would more than likely have to spend some time verifying the accuracy of the data included and fixing inconsistencies in formatting. This is a significant amount of time wasted. Furthermore, as more individuals view, modify and re-upload the document through various means, errors will increase exponentially due to a lack of stringent testing and control. This is a simply illogical business practice. ### Wasted Resources The use of shadow IT applications restricts an organization’s return on investment (ROI). For example, if an IT department spends $1,000 on new software hosted within their in-house server environment with the sole purpose of scheduling meetings, and Secretary Rachel uses Google Calendar, the ROI is next to nothing. This wasted money will either be passed onto customers through increased prices or to the employees through decreased wages. No one wins. ### Data Loss and Leaks Because applications used by those performing shadow IT are not frequently audited, there is a high risk of data loss, or even worse, data leaks. Additionally, shadow IT can serve as a barrier to the adoption of new technology. ## How to Avoid Shadow IT Practices If your company has implemented new software or applications and strictly disapproves of other programs, give the regulated ones a try. It can certainly be hard to try new things, especially if you are set in your ways, but more often than not, the employees within your IT department know what they’re doing. If you find that these new implementations do not work and you would like to go back to old applications, say something! If anything, you’ll be appreciated in the [corporate world](https://lensa.com/insights/surviving-corporate-world/) for inputting suggestions and speaking your mind. If you are a business owner and have problems with employees performing acts of shadow IT, consider moving to the Cloud if you have not done so already. Embrace the cloud! Why? Most employees utilize cloud-based applications—most often Google Drive, email applications, and Slack, to name a few—when participating in Shadow IT. By moving to the Cloud, your applications and commonly used software will be hosted in the readily available Cloud environment. So, for example, Carol will be able to access and manipulate the same spreadsheet from her home office on the weekends that she can edit from the office during the workweek. Also, your data will remain secure and compliant with industry standards. ## About Atlantic.Net Atlantic.Net’s [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions provide corporations with peace of mind knowing that employees will have a secure and private environment for all of their storage needs. Our private Clouds are configured using the most high-tech hardware and software, utilizing custom configurations to increase portability and flexibility for you. In addition, your applications will reside on architecture custom-tailored and dedicated to your individual use. Our state-of-the-art data center is SSAE 16 (SOC 1) TYPE II (formerly SAS 70) compliant, monitored via multiple security measures 24/7, and climate-controlled. To see how you can start  [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) in seconds, give our web hosting professionals a call today at 1-866-618-3282. --- # A Broad View of Redundancy > URL: https://www.atlantic.net/disaster-recovery/what-is-redundancy-a-broad-view/ | Published: 2013-07-26 | Updated: 2026-05-04 | Author: Eddie   No one wants to be redundant in conversation, but everyone wants a redundant network. Redundancy allows your system to keep operating smoothly even if something goes wrong. By creating additional instances – through active-active or active-passive networking mechanisms – you can make your network more solid and less prone to being knocked offline due to failure. Redundancy of HLR, case: two HLRs, both are active. Every HLR uses half capacity for its own data and a half for backup of the second HLR.   In a nutshell, an active-active solution runs two different instances simultaneously that are identical. It’s called active-active, as you can imagine, because both parts of the network involved are engaged. Active-passive solutions, on the other hand, involve one piece of the network that’s running. At the same time, another one waits to jump in if there is a problem (similar to second-string players on a sports team, with the advantage that the backup components are just as strong as the active ones). ![asymmetry, reliability, redundancy](https://www.atlantic.net/wp-content/uploads/2013/11/Comic-Strip-1-001.jpg) Redundancy technology essentially enables greater reliability of the network. You may be familiar with the concept of “high-availability.” A highly available network is accessible at almost every moment. By their nature, failures are unexpected, so building the possibility for failures into your network – protections that account for their possibility – can give your network and site high availability. The uptime of the site, then, is directly related to the network’s redundancies. Typically hosting companies will guarantee 99.9% or higher uptime. A quality hosting service can make this promise because it is completely confident the redundancies are in place to keep its customers running almost all of the time. In our case, though, we guarantee 100% uptime because we consider any moment of downtime unacceptable. ## **Redundancy: An Insurance Policy** Mike Hughes views redundancy as essentially an insurance policy for any engineering company that wants to make sure its systems remain active at all times. Essentially, for engineering firms, redundancy is a question of investment: “weighing risk versus value,” according to Mike. In other words, is it worth the cost it takes to implement the redundancies, or is it better to save the money and risk something going wrong? You can see how redundancy applies broadly to every company. No company wants to lose productivity and frustrate customers or users. In a hosting environment, this technology is critical because websites are the virtual face of a company. If the site goes down for any reason, it looks like the owner has closed up shop, which can be devastating for business. ## **Redundancy: Mission Critical** FileBound looks at redundancy as the basis for business continuity concerning document accessibility. When multiple users must have the ability to view and analyze documents from several different locations, the redundancies of the underlying system allow that access to be failproof: any failures become irrelevant because the system is designed to automatically reroute the network as needed. In the case of document storage, redundancy involves multiple instances of documents in a variety of locations. FileBound offers a checklist to ensure that redundancies shift into place immediately so that no data is lost and no users are left in the cold. In hosting, companies offering high uptime rates have confidence in the redundancies of their systems so that whatever is being stored or presented online is always available and populating correctly. ## **Redundancy: Preliminary Networking Strategies** Here are several pieces of advice from Robert J. Shimonski specific to the redundancy of a network: 1. *Action plan* – He recommends looking at your network’s infrastructure as it is now and using that information to develop a concrete plan to enable redundancy, complete with steps to deploy and test any new components to ensure they account for failures. 2. *Testing* – Specifically, Robert views testing as the “key to your success.” Setting up automated recovery mechanisms in the event of failure is not enough. If the backup system does not take over immediately, the redundant system is not worth much. Whether a redundant network is automated or manual, you need alternate plans of action should redundancies not work: “redundancy-redundancies,” in a sense. 3. *Analysis* – Beyond testing, Robert underscores the need to conduct a risk analysis assessment. He also emphasizes the need to focus heavily on the core site where most of your resources are in place. When you start thinking about specific redundancy scenarios, the primary tools you will want to consider are load-balancing, failover protocols, and clustering. That last concept is widely used to bring together multiple system components into a single unit, an industry-standard way to mitigate risk. **Conclusion** As you can see, redundancy is a concept that has been adopted in every field with a heavy technological basis. When a cloud hosting service has tested its systems extensively and knows its redundancies will appropriately back up the core components as needed, it can advertise high uptime without the fear that systems will ever go down. At Atlantic Hosting, we are confident enough in our redundancies to offer 100% uptime in the Service Level Agreement (SLA) with all our managed cloud hosting and public hosting. We also offer [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions with [HIPAA disaster recovery](https://www.atlantic.net/disaster-recovery/) services. Contact us today for a consultation. by Kent Roberts --- # The History of Cloud Computing > URL: https://www.atlantic.net/hipaa-compliant-hosting/the-history-of-cloud-computing/ | Published: 2013-08-04 | Updated: 2025-03-06 | Author: Alexander Wise Believe it or not, the concept of cloud computing technologies has actually been around since the mid-1990s; back then, it had a more complex name: “on-demand infrastructure.” How has this technology evolved over the past two decades to become the immensely powerful phenomenon it is today? ## The Beginnings of Web Hosting From basic web server architecture to simple database management and from less-than-technical email applications to minimal disk space, the original web hosting services was born around the 1990s. It then exploded in popularity during the dot-com era (1995-2001). Some of the earliest shared hosting companies included ValueWeb, Interland, and HostGator. The first shared hosting solutions offered multi-tenancy capability, automated provisioning, a monthly billing cycle, and an easy-to-use interface for maintaining resources. However, these solutions did not inherently provide infrastructure on demand, resource-size flexibility, or scalability. It was a simplistic offering but helped to create the foundation for the cloud hosting industry. ## Virtual Private Servers & Dedicated Hosting Arrive Around 1998, virtual private servers (VPS) arrived on the scene. By offering some more flexibility and administrative root access, VPS solutions offered a significant step up from shared hosting capabilities of the past. Early VPS hosting companies provided servers that offered occasional infrastructure on demand, slight resource-size flexibility, multi-tenancy, automated provisioning, and the convenience of monthly, quarterly or annual billing cycles. For businesses that needed stricter security measures and more stable resources, dedicated hosting solutions that were developed soon after the release of VPS did the trick. These servers offered more power along will complete administrative access and control of server resources. These dedicated servers did not provide multi-tenancy, network flexibility, or scalability. However, providers supplied both managed and unmanaged dedicated hosting options, giving customers the ability to choose between relying on professionals to maintain the architecture or employing an IT department to handle it. ## Amazon Web Services Launches in 2006 The launch of Amazon Web Services in 2006 really began to change the industry. Between 2007 and 2010, several managed hosting companies developed and released a more scalable and more virtualized Infrastructure as a Service (IaaS) offering. Today, this is referred to as grid/utility computing. IaaS providers offer computers—whether physical or virtual—and other resources to customers. The earliest providers of utility computing included Layered Technologies, NaviSite, and Savvis. These hosts offered infrastructure on demand, partial resource-size flexibility, multi-tenancy, occasional automated provisioning, partial scalability, a monthly, quarterly, or annual billing rate, and a slightly easy-to-use interface. As discussed before, the development of Amazon’s Web Services really kicked things off in the way of cloud computing. In fact, the AWS system transitioned from a grid/utility computing model and moved toward what we can only call “Public Cloud Computing 1.0.” Between 2008 and 2009, developers and startup hosting companies alike had the ability to compute and store data like never before. With time, they were able to scale this data and infrastructure resources at a whim eventually. Along with Amazon, Rackspace Hosting was the main component of this transition. ## New Models of Cloud Server Pricing and Provisioning Cloud servers infrastructure on demand, partial resource size flexibility, multi-tenancy, automated provisioning, slight scalability, hourly billing (the first of its kind!), and a fairly easy-to-use interface. The introduction of hourly billing in cloud computing 1.0 was a big deal for both providers and customers. This model gave customers the ability to pay what they really should—not some previously agreed-upon subscription price. By narrowing the billing down to the hour, customers saved money, and this made them happy. ## True Flexibility in Cloud Computing 2.0 Today, we are witnessing a progression into the Cloud Computing 2.0 era. The next generation of cloud computing will need to be easier, more flexible, and billed based upon a true utility model (like electricity and water) to provide customers with the services and products they need. Current cloud 2.0 companies, such as Atlantic.Net, offer infrastructure on-demand, fully customizable resource-size flexibility, multi-tenancy, applications on-demand, network flexibility, automated provisioning, complete scalability, billing down to the minute or second, and a simple drag-and-drop interface control for ease of use. Sure, cloud computing 2.0 companies are offering services that speak truer to the definition of the cloud than ever before, but we’re still not quite there. In the future, the Cloud and the technologies serving as the backbone of the Cloud will need to cross the metaphorical river of development to attract a wider audience beyond that of organizations and enterprises. Small successful startups are driving innovation today. Cloud computing will need to become more saleable, more flexible, and more based on a true utility model to further drive this innovation. ## About Atlantic.Net Since 1994, Atlantic.Net has stayed above the competition to fuel innovation and move technologies to new environments never previously imaginable. As the technology continues to evolve from 2.0 into 3.0 and beyond, you can rest assured knowing that you rely on the most up-to-date architecture and standards in the business. To learn more about the Atlantic.Net business model, see our full line of one-click cloud applications, and see how transitioning to a [VPS hosting](https://www.atlantic.net/vps-hosting/) service can help transform your business, contact us today. We also offer [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions – contact us for a consultation. --- # How APIs Make Data More Valuable > URL: https://www.atlantic.net/vps-hosting/how-apis-make-data-more-valuable/ | Published: 2013-08-07 | Updated: 2026-01-09 | Author: Alexander Wise  The principles that power application programming interfaces (APIs) can be difficult to comprehend due to their ambiguity. What exactly is an API? How can they be used by developers and consumers alike? How does the utilization of APIs make everyday data more valuable? ## What Is an API? To put it simply, an application programming interface (API) is a set of instructions for how software components should interact with one another. An API is a language library that includes specifications for data structures, routines, object classes, and variables in a more technical sense. ## API Examples APIs can take several forms. One such example is that of the Portable Operating System Interface (POSIX). POSIX is a group of standards created by the Institute of Electrical and Electronics Engineers (IEEE) in the 1990s to maintain compatibility between operating systems (i.e., Windows and Mac). Another example is that of the Windows API. Commonly referred to by developers simply as WinAPI, Microsoft’s core programming interface is available solely for Windows operating systems. In fact, practically all Windows applications interact with the Windows API at one time or another. Oracle, a multinational computer technology corporation, also offers the core Java API in three flavors: Micro Edition (ME), Standard Edition (SE), and Enterprise Edition (EE). ## APIs vs. ABIs Application programming interfaces are not to be confused with application binary interfaces (ABIs), which are primarily binary in programming nature. APIs are traditionally source-code-based. In its most simple form, an API can be used to define a set of functions that accomplish a specific task or allow interaction with a specific software component. For example, Amazon’s API allows web and software developers to design products that are ultimately powered by Amazon’s services. If you’re on a blog and see an “Add to Amazon Wish List” button, this is an example of the Amazon API in action. ## APIs in Web Development Let’s explore the concept of APIs in a web development environment a little further. Usually, developers will define an API as a set of Hypertext Transfer Protocol (HTTP) requests combined with a definition of the structure of response messages—usually in an Extensible Markup Language (XML) or JavaScript Object Notation (JSON) format. Although APIs have primarily been associated with online services, Web 2.0 trends have moved away from this and towards more direct representational state transfer (REST) system web resources and resource-oriented architecture. ## APIs and Compatibility Traditional API standards require the source code to be re-compiled when implementing on each platform (Windows, Mac, Linux, etc.). Today, though, APIs are being coded so that they can continue to function without any changes to the system implementing the API. Object-oriented programming for APIs is incredibly beneficial for both software providers (because they can release components of their software across multiple platforms with little to no manipulation) and users (because they can install older software and newer systems without having to purchase upgrades or install specific applications). Everyone wins! Fun fact: in 2010, Oracle took Google to a judicial court because they believed Google distributed a new implementation of the Java language within their own Android operating system. Google did not receive any permission to do so, but projects such as OpenJDK allowed such usage. The judge ruled for Google and enforced the principle that APIs cannot legally be copyrighted within the United States. ## Real World Applications of APIs Now that we know exactly what an [application programming interface](https://www.atlantic.net/docs/api/) is, what are some real-world applications for its use? How does it correlate to the phenomenon of big data? The average computer user does not equate the purchase of everyday products or the search for services with the production of data. But the data really is there, and the variety of uses this data creates is infinite with endless possibilities. Consider this: you have decided that you’d like to purchase a new desktop computer. You search Google for the most reputable sellers, compare wish lists, and send emails to your peers asking for advice. Each of these steps utilized APIs without your knowledge, and each action produced a decent amount of data! APIs are a tangible concept because they are real, programmed objects. However, “big data” is just an ambiguous term. Together, they can achieve amazing things. Netflix supports over one thousand devices with its uniquely engineered API. Amazingly, around 20,000 developers are registered to use the Netflix API with the hopes of expanding this reach even further, which, in the long term, poses the added benefit of promoting innovation. By itself, software has limited value; but once you connect the two, the software turns the API into programmable nodes. Similarly, data is irrelevant on its own. Connect it with APIs, and transformations occur that were simply just not possible before! ## Conclusion To conclude, pure data has practically no value. When you begin thinking of data in the context of application programming interfaces, that’s where the real magic begins to happen.  Atlantic.Net understands the value of having reliable cloud hosting solutions and encourages customers to control their hosting options by fully utilizing the [Atlantic.Net API](https://www.atlantic.net/docs/api/). We also offer managed services and [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. Contact us today for a consultation! --- # Cloud Advisory Council One-Year Anniversary: Mission Overview > URL: https://www.atlantic.net/hipaa-compliant-hosting/cloud-advisory-council-one-year-anniversary-mission-overview/ | Published: 2013-08-09 | Updated: 2026-07-23 | Author: Glenn At Atlantic.Net, we hold various certifications (such as SSAE 16, Type II), titles (such as Official Server Host of Disaster Recovery Journal), and organizational memberships (such as the Cloud Advisory Council). Our history of [Atlantic.Net accolades and achievements](https://www.atlantic.net/about-us/) is not just an effort to show credibility. Integrating ourselves with the hosting world, general IT world, and overall marketplace helps us learn and grow synergistically with expertise from our industry and all walks of life. In this article, as the Cloud Advisory Council approaches its first anniversary, we will explore the organization’s role pertaining to cloud computing. Essentially, many hosting, data centers, other web infrastructures, high-tech organizations, and professionals work together to make cloud computing as predictable and secure as possible (similarly to the [Cloud Security Alliance](https://cloudsecurityalliance.org/)). Below, we will look at what the organization is, along with its membership, published content, events, and a sample issue targeted by the CAC. Note that we covered the initial founding of the [Cloud Advisory Council](https://www.atlantic.net/press-releases/cloud-industry-leaders-announce-formation-cloud-advisory-council/) last year. Here we will give general information and updates on what has happened in the first 12 months. ![Diagram showing overview of cloud computing](https://www.atlantic.net/wp-content/uploads/2013/08/Cloud_computing.svg_.png) ## **History, Mission & Membership** On August 27, 2012, the Cloud Advisory Council announced its formation. The council is a nonprofit intended to chart and guide the progress of cloud infrastructure. By drawing from the expertise of cloud practitioners across a broad spectrum, the CAC seeks to educate web designers and IT personnel, facilitating standards and best practices throughout the industry. The specific, stated goals of the CAC are as follows: 1. determine how the cloud will structurally develop 2. issue free and transparent guidelines for the cloud 3. publish advice for tools and processes to streamline cloud technology 4. provide resources that improve the cloud administrative experience. Membership in the Cloud Advisory Council is not limited to large organizations. Rather, it is based on expertise and interest in the objectives of the CAC. Original equipment manufacturers (OEMs), independent software vendors (ISVs), and companies supplying technological products and services comprise the foundation of the CAC. Currently, the organization has 45 corporate members. However, end-users can also apply for membership, providing a broader perspective that extends to all angles of the cloud rather than just the supply side. ## **Publications** To present its findings and offer educational support on the cloud to the broader community, the Cloud Advisory Council publishes papers of the following three types (listed along with the first articles in each category): - *Best practices.* Sample: With cloud-based applications, storage performance is one of the greatest issues. One confusing aspect is how it fluctuates. Users can also impact the experience of other users, and monitoring is complex as well. What are the best solutions? - *Case studies.* Sample: If you understand the basics of redundancy, you can see why RAID – a redundant array of independent disks – is so commonly used. If any of the disks becomes damaged, the data is backed up across multiple drives. However, at hyper-scale (scaling to thousands of computers, typical for filtering big data across enterprises), RAID is no longer an effective solution. - *White papers.* Sample: Understanding energy efficiency for cloud computing, or any aspect of web infrastructure, is difficult to ascertain. Data centers often do not provide information related to their power use, and if they do, it may not be reliable. It’s private information a company can choose not to disclose. Plus, as new hardware develops, efficiency models must evolve with them to be accurate. How do we work with the information available to improve efficiency? ## **Events** The Cloud Advisory Council has taken part in numerous events, primarily via webinars. These events allow the CAC to showcase its aggregate knowledge and present with partners in the field to benefit attendees. The Council’s first live event will appear at [VMworld 2013](http://www.vmworld.com/community/conference/us/) (August 25-29 in San Francisco, California). Previous live webinars have been conducted with Mirantis, Eucalyptus Systems, Big Switch Networks, and Stanford University. ## **Sample Issue: The Open-Source Enterprise** Cloud Advisory Council Co-Chairman David M. Fishman addressed an issue recently for the CAC: how to take an open-source cloud and get it into the hands of IT managers within enterprises. Though Fishman describes the current climate for IT professionals as “a blizzard of challenges,” he argues that the cloud is perhaps the most daunting adaptation taking place in the world of computing. Open source has changed the nature of cloud accessibility. OpenStack, initially developed by RackSpace and NASA, allows enterprises – or anyone – to see the internal workings of cloud infrastructure. OpenStack is an IaaS (Infrastructure as a Service) model, just like Amazon Web Services (AWS). Because OpenStack is open source, though, it’s much more exciting to organizations from a customization and developmental perspective. ## **Conclusion** We are proud to be a part of the Cloud Advisory Council. The work of the organization during the first year of operation has been phenomenal. We’re excited to see how it will grow and the innovations it will bring to the marketplace. As industry leaders in cloud computing, including [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/), you might be interested in checking out what we have to offer. --- # Global Standards and Regulation of Cloud Data Portability > URL: https://www.atlantic.net/hipaa-compliant-hosting/global-standards-and-regulation-of-cloud-data-portability/ | Published: 2013-08-23 | Updated: 2025-03-06 | Author: Alexander Wise Some of the most popular applications available on the market, including LinkedIn(social networking for businesses), TripIt (all-in-one travel organizer), and Dropbox (storage solutions for individuals and businesses), are designed by developers for one-way use, leaving little to no way to leave with your personal data. ## The Problem with One-Way Personal Data This poses a massive problem for consumers, according to Manas Kumar, Chief Executive Officer (CEO) of Optimizer HQ, a New Zealand-based company that develops cloud solutions for companies around the world. According to Kumar, numerous cloud hosting service providers and application developers do not allow their customers and clients to export their own personal data into a practical, usable format. This means that consumers are significantly more vulnerable to monetary loss due to being locked into a long-term contract and even face the risk of having their personal information used for a malicious reason, such as identity theft. ## Should There Be Industry Standards for Data Portability? Kumar believes that in the same way governments around the world have the ability to regulate phone number portability (being able to change phone numbers without issue), a set of industry standards should be required to ensure that the data uploaded through cloud-based applications are portable and can easily be downloaded to a usable format. “Most consumers do not have the technical knowledge required to manage the transfer of data from one provider to another, let alone cope with the complexities of exporting data which is not available in a common format,” Kumar says. Storing important files in cloud-based applications (such as Dropbox) has become a prevalent information technology solution for small and small businesses in the past few years. Still, such solutions pose a real security threat. Additionally, switching from one cloud storage provider to another can be incredibly difficult. “Little has been publicized about the issues around exporting data from one provider to another of moving the business from one provider to another using a common language of exchange,” said Kumar. ## What to Look for in Terms of Use Agreements There are other issues consumers need to be aware of and make themselves thoroughly knowledgeable about the stability of servers and uptime guarantees quoted by most cloud providers. Kumar warns, “Beware of the classic ‘force Majeure or ‘act of God’ clause that most cloud application providers have in their Terms of Use agreement.” It is essential that you completely read the terms and conditions carefully and understand the impact any downtime will have on your business. It would also be beneficial to compare cloud solutions offered by other competitors to get an idea of the products available on the market. Don’t compromise to save a few dollars in the short term! Do the right research, and your business will be saving money in the long term. Additionally, many cloud providers offer premium services with guaranteed uptime, so it is important to consider all available options. ## Have a Data Backup and Migration Strategy Regarding the risk of losing data in the Cloud, consumers should have a scrupulous backup plan and exit strategy for each application. The first step in doing this would be to research the background of the company you are looking to work with and ask them about their network infrastructure and measures to ensure the security of customer’s data. If they truly desire your business, they will answer all your questions without a problem. Also, you can request that your data be hosted through a local server. This ensures that you will be able to easily access your information in the case of a disaster or some other emergency. ## Future Solutions for Data Portability By taking action and researching your cloud service providers and application developers, you can take a role in making the Cloud safer and ultimately better. Kumar, however, still believes that the ultimate responsibility lies with each country’s federal government: “I believe the Government, in conjunction with industry experts, needs to develop an ISO standard design for data portability and management and have top-tier cloud vendors to conform to that standard.” Part of that conformance would measure the reliability, scalability, uptime, and service of cloud providers. It would analyze whether or not the vendor offers data exported in user-friendly formats such as Extensible Markup Language (XML) or Open Document Format (ODF). After these standards are established and regulated, Kumar believes that cloud vendors will adhere to an ultimate gold standard. This standard will give consumers factors to look out for in their search for providers and help keep the industry honest and true. ## About Atlantic.Net At Atlantic.Net, we are known for our outstanding reputation. Since 1994, we have strategically and honestly evolved into a market-leading cloud hosting provider. Our cloud solutions are comprehensive, customizable, and affordable. With no contract and no commitments, you can rest easy knowing you won’t be snared into any malicious obligation. To learn more about how you can try out our cloud servers and [VPS hosting](https://www.atlantic.net/vps-hosting/) in just seconds, contact us today at 1.866.618.3282. We also offer managed services and [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. --- # Hosting Voice and Data is Beneficial for Small Businesses > URL: https://www.atlantic.net/voip-cloud-servers/hosting-voice-data-beneficial-smb/ | Published: 2013-09-05 | Updated: 2026-01-09 | Author: Alexander Wise Small and medium-sized businesses need to be adaptable to stay competitive and grow. The ability to change and adapt due to economic or market changes is a characteristic of a smart business, which allows for economic growth and new opportunities. A fast-growing trend is enabling organizations to move their server infrastructure and telecommunication services to a hosted environment. The rate at which SMB is adapting new voice and data technologies is growing at a phenomenal rate. The trend is to move data and voice into a data center environment, most recently into a cloud or virtual server commonly referred to as cloud computing or [VOIP cloud servers](https://www.atlantic.net/voip-cloud-servers/). ##  VPS and Cloud Service Cloud-hosted VPS is a virtual server that is located on a larger physical server. The machine can have several separate virtual systems, each one with its own allocated, non-guaranteed resources. On the flip side, cloud servers are provisioned in a large distributed chain of physical servers and computing nodes, making it easy to scale up and provide dedicated resources. The result is the consumer’s ability to leverage their data with a hosted solution, which can be very affordable! Both solutions are multi-tenant and can be ideal for unique requirements. A VPS or cloud-based business phone service is a revolutionary technology that allows companies to outsource their communication system while expanding the capability to stay in touch with clients and employees. ## Flexibility With a Cloud or cloud VPS system, a company has all of its data in one central location, which makes it easily accessible. If a business has several offices or a mobile workforce, each location can access, upload and download data from the hosted server. Similarly, cloud-based [phone systems](https://www.atlantic.net/voip-cloud-servers/hosting-voice-data-beneficial-smb/) offer the same flexibility. A call to one phone number can ring simultaneously on three different phones in three different offices. The same system can also be best utilized to collaborate with remote employees or clients. ## Scalability A cloud-based or virtual solution can enable infinite scaling with a hosted solution. As your business continues to grow, so does your data and voice capabilities. Best of all, the new technology does not require a whole lot of up-front capital, and you only pay for what you use! ## Cost A hosted phone system can help save businesses money. It costs less money to install and operate a hosted phone system than traditional business phone systems, including enterprise mobile solutions. They have the added benefit of having multiple users accessing one phone number with multiple routing options. Utilizing hosted systems for voice and data allows companies to use one central location for their data storage and communication. The voice and data applications can be accessed simultaneously from multiple locations, and changes to data can occur in real-time. These systems are often more cost-effective for small businesses, especially cloud-based phone systems. Hosted phone systems also allow businesses to upgrade their plans when their company is ready to grow. ## Uptime, Accessibility, and Security Hosting data and voice in a secure data center facility with multiple redundant connections to the Internet and backup UPS and generators enables 100% uptime and accessibility 24/7/365. It is important for all of the company’s sensitive data to remain secure and for stakeholders to be able to access the information when needed. If organizations opt to keep their data at their office premises, thoughtful planning and consideration are expected to secure the premises from fire, natural disasters, or theft.  By taking advantage of the external hosting facility, vital business information can be secured to ensure that the business can survive and thrive. Small businesses should stay flexible so that they can adapt to the needs of their market. Cloud-based phone and data systems offer this flexibility while allowing businesses to offer services that customers want.  Explore different [VOIP Cloud Server](https://www.atlantic.net/voip-cloud-servers/) options available for voice and data to see which option may suit your organization’s needs. * Kevin Lee is with CallRingTalk, which provides VOIP services to SMB.*   --- # What is Server Load Balancing? How Load Balancing Servers Works > URL: https://www.atlantic.net/hipaa-data-centers/server-load-balancing/ | Published: 2013-09-10 | Updated: 2024-06-08 | Author: Kent Roberts The reliability of a system is measured in uptime, the percentage of time throughout a given window that a site is up and fully operational.  Network reliability and high uptime figures are crucial to keeping users happy. One important way reliability is enhanced is with redundancies – safeguards so that if anything fails, the client still won’t experience a problem. A strong system will always have multiple redundancies in place. Another simple way to ensure strong performance within a network is to ensure that every piece of machinery holds up its weight (and this actually has a redundancy component as well – see below). Whenever possible, it’s better to split work up among all of your devices rather than letting one piece perform all the work. Otherwise, you see the strain on one machine as the others sit nearby, daydreaming. Server load balancing is the practice of dividing work evenly between various servers. ## **Basics of load-balancing & how clustering is related** When a load balancer is put into place, incoming traffic requests information from the servers from user web browsers – routes through the device before hitting the cloud servers. At that point, all the traffic is reaching, where the load balancer is located, is one network address. As a load balancer receives the requests, it divides work evenly throughout a server cluster. The servers are a cluster because a cluster is several computers operating in the same basic manner to achieve the same objectives. In a basic load balancing set-up, all of the load balancer servers perform the same basic function – equal work based on what comes through the load balancer. ## **Advantages of load balancing** In the absence of a [load balancer](http://www.fortinet.com/products/fortiadc/index.html), anyone who accesses a site is hitting the same server. That server is essentially being inundated with requests (during peak times or as the site is becoming more popular). When an upswing in traffic occurs, people visiting the site will either experience slow page loads or the server will start denying requests. Not only will these issues make those accessing the site frustrated, but search engines will punish the site as well. Installing a server load balancer allows the speed at which the site functions to remain high even during times of exceptional traffic. Even if a server fails (and here’s the redundancy aspect mentioned above), it has backup. All of your resources are utilized to their utmost capacity. Another major advantage of load balancing is that it’s a simple, easily deployable process, and it’s built for scalability. If you need to add more servers to your infrastructure, you plug them in. The load balancer recognizes any new devices and continues to balance appropriately, with any new machines taken into account. ## **How more complex load balancers differ from simpler ones** Essentially, the range of load balancers can be understood in terms of how well they process different types of data. These data types can be understood in terms of the OSI (Open Systems Interconnects) model. Here are the seven layers, with the top layer representing the most sophisticated and working down toward the most basic: - Application (Layer 7) - Presentation (Layer 6) - Session (Layer 5) - Transport (Layer 4) - Network (Layer 3) - Data Link (Layer 2) - Physical (Layer 1) Every load balancer can accurately process OSI layers 2 and 3. As the devices become more sophisticated, they become capable of handling the top four layers. The reason load balancers must be more sophisticated to handle application information is that the data itself is more complex. Figuring out the degree of workload needed by a particular request requires a more intelligent load balancer. It does not accidentally overload one of the servers by misunderstanding incoming packets. ## **Other functions of load balancers** Generally speaking, load balancers use network address translation (NAT) so that the IP of the exact server being accessed is unclear to the client. This relates to the “one network address” aspect discussed above. The IP address listed with the load balancer appears to the client (browser asking for information) to be the server. In this way, the load balancer cloaks locations, providing a security function. Depending on how its owner configures the load balancer, the load balancer sends it out to a server. The server processes the request and sends data back through the load balancer to the client’s browser. In other words, the load balancer is not just in charge of balancing traffic; it also properly organizes requests and responses so that nothing goes to the wrong server or client. ## **Conclusion** Load balancing is one of the many safeguards we have in place for high redundancy and 100% uptime. Read our article on how it works. As you can see, load balancing is fairly simple, but using high-quality equipment and implementing the practice correctly is crucial to a strong infrastructure to learn more about load balancing. If you are in the market for cloud hosting or any other hosting solution, including [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/), find out why Atlantic.Net is the ideal choice; learn more about our [HIPAA Data Centers](https://www.atlantic.net/hipaa-data-centers/). --- #### Read More About Load Balancing - [Load Balanced Servers](https://www.atlantic.net/managed-services/load-balancing/) from Atlantic.Net - How to Check Your [Server Load](https://www.atlantic.net/vps-hosting/how-to-check-your-server-load-in-linux/) in Linux --- --- # 5 Security Tips for Cloud Computing > URL: https://www.atlantic.net/hipaa-compliant-hosting/5-security-tips-cloud-computing/ | Published: 2013-09-11 | Updated: 2026-01-09 | Author: Alexander Wise Cloud adoption has been growing over the last couple of years, primarily driven by cost reduction and speed of adoption. However, according to a survey performed by KPMG, the top barriers to cloud adoption remain related to security and compliance.  Data security is projected to remain the most important SLA parameter in 3 years. Fundamentally, data and network security are about three control objectives, i.e., confidentiality, integrity, and availability. ## Know Where Your Data Lives Knowing where your data is physically, goes a long way in establishing your cloud security and risk assessment. The data center location is also critical in evaluating latency impacts on the application you are communicating with. Some cloud providers could have data centers in international locations, which may be subject to laws and policies of that jurisdiction. International data centers often suffer a reduced latency that may pose a risk for your business applications on the cloud. ## Have a Disaster Recovery and Business Continuity Plan In 2009, a lightning strike triggered an [Amazon EC2 outage](http://www.datacenterknowledge.com/archives/2009/06/11/lightning-strike-triggers-amazon-ec2-outage/), and the cloud services were offline for about 4 hours as an aftermath. Data backup and availability are critical and one of the main challenges facing the service providers. Take a long-term view of your hosting services and make sure that you backup your data at appropriate times to ensure that the customer data is not lost. Understand the risks associated with data availability and disaster recovery issues that may impact your business. Big companies have lost their data due to improper backup procedures, and it is one of the growing concerns for moving your services to the cloud. ## Understand How Your Data is Protected Understand and solicit clear information around how your cloud server hosting provider protects your data with encryption and firewall security, especially if you need [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/). Encryption is a must-have on public cloud SaaS solutions, and the need to be secure and encrypted. Cloud computing resources should be sheltered with a mandatory inbound firewall. Devise plans for how you are going to monitoring network attacks or hostile system activity even if you are on the cloud. You will only be able to understand the sufficiency of your security if your cloud provider is willing to disclose its security practices. Some providers treat the security practices as confidential, which can become more challenging. ## Third-Party Audits: Service Organization Control Reports Curious if your provider is serious about security? Research to see if they have been audited by third parties to build trust and confidence. In February 2013, Cloud Security Alliance (CSA) released their position paper stating the purpose of SOC 1 and SOC 2 reports for cloud service providers appropriating SOC 2 as the de facto standard for cloud security.   SOC 2 audits conducted by AT 101 cover controls relevant to security, availability, processing integrity, or privacy. In 2013, the number of data centers and CSPs which underwent a SOC 2 attestation increased by 100% YOY from 7% in 2012 to 14% in 2013. Aside from SOC 2, PCI Compliance, HIPAA Compliance, and ISO certifications are important indicators for the dedication your cloud service provider has for security. Hassan Sultan is a partner at Reckenen, which provides accounting and assurance services to privately held companies.  Atlantic.Net offers reliable and cost-effective [VPS hosting](https://www.atlantic.net/vps-hosting/) for a wide range of business opportunities. Atlantic.Net offers [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. Contact us today for a consultation. --- # Why the Cloud is Raising Climate Questions > URL: https://www.atlantic.net/hipaa-data-centers/cloud-raising-climate-questions/ | Published: 2013-09-26 | Updated: 2026-01-09 | Author: Alexander Wise As we all are very well aware by now, the architecture behind the cloud consists of extremely complex and technically evolved data centers that serve to store, process, and deliver information instantaneously over the Internet. The cloud also allows users to access information that would have previously been stored locally; instead of being forced to access a critical file from a work computer, employees have access to all of the information they need from their favorite library or coffee show. But with the convenience of such technology comes a price. How has the rapid adoption of cloud server hosting affected the state of our global climate? How can we, both IT professionals and average users, change the current downhill course into a more positive one? ## New Beginnings The Industrial Revolution marked a critical turning point in history. Between 1760 and 1840, companies began transitioning from using hand production methods of creating products to highly productive machines. Steam power and the improved efficiency of water power were also introduced during this time. This evolution in the way workers manufactured products paved the road for new regulations in wages and worker conditions. Similarly, the introduction of cloud computing solutions has changed how IT vendors and business owners alike handle and provide their services. ## The Cloud and Climate Change There is absolutely no doubt that cloud computing is changing how we do business and interact with our peers. The cloud is helping us innovate new products and ideas in an extremely convenient platform. However, it is important to note that powering such technology can be costly: it is estimated that data centers are currently responsible for nearly 1.5 percent of global electricity use. This may seem like a small percentage in the grand scheme of things, but this percentage has steadily increased despite the economic slowdown, and there is no doubt that this number will increase exponentially over the years. ## How Data Centers Are Responding Many data centers have realized the environmental concern related to cloud computing. They have adopted new energy efficiency methods, such as machines that use low energy in extreme climates and chiller-­‐less servers. Traditionally, data center operators tend to build their facilities where the energy is cheap, and with these lower costs comes dirtier methods. In fact, according to Greenpeace, more than half of all top recognized data centers rely on coal for the vast majority of their energy needs. Coal can be very dirty and has a less-­‐than-­‐ desirable reputation in regards to climate control. Additionally, data center owners don’t often reveal their site locations; this helps keep sensitive customer information secret but doesn’t help make their carbon footprint information transparent. ## The Importance of Carbon Impact Transparency Transparency concerning local carbon impacts has become a critical factor in determining corporate climate responsibility. Over the next few years, companies will be held under increasing pressure to disclose more about their impact. If they can’t disclose such information, they will be expected to explain why. When viewing information technology as a whole, determining the carbon footprint and environmental responsibility can be incredibly complex due to the wide variety of sub-­‐industries, from Internet marketing companies to telecommunication and service providers. ## How Providers Can Protect the Environment One of the greatest opportunities for IT service providers to reduce their environmental footprint is by carefully analyzing possible site locations through the help of consultants and contractors. The companies building data centers have an inherent responsibility to educate clients on the potential carbon impact they could face with each site location. Additionally, they can offer comprehensive insights and services to help clients find the most economical and environmentally friendly location. Because data centers are massive energy consumers, developers and center operators can influence local policymakers and utility companies to invest in more appropriate sustainable energy sources. You may not know it, but countless companies already use this influence to their advantage by negotiating electricity prices with utility companies and engaging with local governments on a wide range of policy issues. ## How the Carbon Disclosure Project Helps Datacenter operators need to understand the power of transparency. By reporting as much as possible about carbon impacts through the Carbon Disclosure Project and clearly explaining what can and cannot be disclosed due to its sensitive nature, companies become more trusted by local businesses and even the general population. The more information companies can provide, the more tools researchers will have to establish general metrics and specific public policies that will, in the long term, improve incentives for investments in energy and carbon-­‐efficient operations. ## Conclusion As new data centers are built due to overwhelming popularity over the coming years, the decisions that are made in the building process will prove critical for future generations. Because the information technology industry must reinvent its systems every two or three years, data center operators need to remind themselves of corporate responsibility in continuously supporting sustainable development. At Atlantic.Net, we have always made aware of our climate impact a critical concern. To learn more about how we’re changing the notions of corporate responsibility and our cloud servers[,](https://www.atlantic.net/vps-hosting/) give us a call today. Atlantic.Net also offers [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions; learn more about our [HIPAA Data Centers](https://www.atlantic.net/hipaa-data-centers/). --- # Improving Collaboration with the Cloud > URL: https://www.atlantic.net/vps-hosting/improving-collaboration-cloud/ | Published: 2013-09-30 | Updated: 2026-01-09 | Author: Alexander Wise Years ago, managing projects consisted of executives overseeing a group of teammates working together to achieve a common goal—a new innovation or improved process. Not anymore! Now, project management is very much a social system. According to Mattias Hallstrom, author at The Guardian, the social approach to running companies, process and projects are here to stay. And just what is powering these social applications of management? You won’t have to look much farther than the highly popular cloud hosting. ## Social Project Management & the Cloud Social project management has revolutionized the way businesses view the most efficient ways to run a project. Incorporating the cloud into this management strategy can boost communication and collaboration to dramatic levels. For a project to witness long-term success, the influence lies within the people behind it. Applying this train of thought and combining it with web-based collaboration tools increase the potential for success tenfold. Your team can move its [project management](https://project-management.com/top-10-project-management-software/) process into the cloud by utilizing cloud-based email, storage, and other useful collaboration applications. When all of this information is accessible in the cloud, transparency is established. Without transparency, trust between teammates is compromised, and the ultimate project goal becomes ambiguous. ## Sales Demonstrations, Presentations & Collaborations ### Ascending cloud & sales urgency In case you haven’t heard, the cloud keeps ascending. In January, TJ McCue of *Forbes* reported that American businesses were likely to spend $13 billion on the technology in 2014, including managed hosting packages for cloud servers. He cites an IBM infographic that gives five reasons the cloud has become so commonplace: 1. file-sharing and collaborative potential 2. real-time analytics from anywhere 3. better efficiency and output 4. greater affordability 5. faster development. The speed of the cloud is unprecedented, generally faster than a supercomputer. Your power and reliability are further enhanced with SSDs (solid-state drives). Many people say that a major component of successful sales is the creation of a sense of urgency. With the power of almost limitless speed in your hands, you can better create urgency by being able to move incredibly fast yourself. ## Sales Apps Real-World Scenario The below interaction is based on messages between one of our hosting consultants and a client. The client is a current customer of our Windows Cloud server plans interested in an additional system to optimize sales demos and related applications. Consultant: Welcome to Atlantic.Net. Would you please tell us about your hosting needs? Client: I’m working with a software company that has consultants in various locations in the US.  We already have a Windows Server cloud on Atlantic.Net, which we use for sales demos and testing.  We have a couple of software packages that need to be installed in individual environments.  Currently, I have them on a local ESXi server, but I would like to transfer them to a hosted environment where I can pass control to whoever is performing a demo. I tried installing Hyper-V and VMware, but neither works in that environment. Do you have a solution where we can host an ESXi server or equivalent so we can manage different environments? Secondly, this can be used as a collaboration tool. Consultant: Yes. One of the core technologies we use is VMware ESX/ESXi 4.0. Also, our private cloud hosting is unmanaged (unless you choose to add managed hosting to your package). We don’t dictate what you do with the server other than following the basic ground rules within our AUP (acceptable use policy). Other than that, basically, you spin up the server and use it any way you like. You can even set it up so that your staff in the field can update their sales or other information remotely from their mobile devices. By improving collaboration through the incorporation of cloud hosting, employees will feel more motivated to immerse themselves deeper within projects, ultimately creating new and more effective ways to be creative. Atlantic.Net also offers [VPS hosting](https://www.atlantic.net/vps-hosting/) services.  See our [VPS hosting pricing.](https://www.atlantic.net/vps-hosting/pricing/)   --- # More Healthcare Organizations are Embracing Cloud Computing > URL: https://www.atlantic.net/hipaa-compliant-hosting/healthcare-organizations-embracing-cloud-computing/ | Published: 2013-10-03 | Updated: 2026-07-24 | Author: Alexander Wise *Updated: July 22, 2026* Healthcare organizations move to cloud computing because the workloads that define modern clinical practice- electronic health records, telehealth, medical images, and analytics- have outgrown the server rooms they started in. Making that move lawful requires a hosting provider that will sign a Health Insurance Portability and Accountability Act (HIPAA) Business Associate Agreement (BAA), encrypt electronic Protected Health Information (ePHI) in transit and at rest, log administrative access, and keep patient records recoverable after an outage or ransomware event. HIPAA has no certification program for cloud platforms, so the healthcare organization verifies what a provider’s audits cover. Cloud computing in healthcare has already reshaped the record itself. By 2024,[99.4% of non-federal acute care hospitals had adopted a certified electronic health record](https://healthit.gov/data/data-briefs/non-federal-acute-care-hospital-electronic-health-record-adoption-2008-2024/), per ASTP/ONC. Those EHR systems produce imaging archives, interface engines, and reporting databases that grow whether or not a practice has room for them. At the same time, the hardware underneath depreciates on a five-year replacement cycle. Electronic medical records outlast the servers they were bought for. Telehealth settled into steady clinical use instead of fading after the pandemic peak. FAIR Health’s[Quarterly Telehealth Regional Tracker](https://www.fairhealth.org/fh-trackers/telehealth) recorded it rising from 5.01% of medical claim lines in Q4 2025 to 5.51% in Q1 2026, with 18.4% of insured patients filing a telehealth claim. Video consultations, remote patient monitoring, and patient engagement tools need capacity that arrives in days, and few healthcare providers want to buy a rack to find out whether a service line works. Cloud adoption settles capacity, and it does not settle compliance. A provider’s audit reports cover its own cloud-based systems and staff. The clinical application, the accounts inside it, workforce training, and chart-access policy stay with the healthcare organization, and any provider should put that split in writing. ## Which Healthcare Organizations Need HIPAA-Compliant Hosting HIPAA obligations follow the data, and cloud computing in healthcare does not change that. The rule reaches across the healthcare industry, from a two-room clinic to a national payer. Any organization that creates, receives, maintains, or transmits ePHI is a covered entity or a business associate, and both are directly liable under the Security Rule. | Organization Type | Typical HIPAA Status | What Usually Lives in the Cloud | | --- | --- | --- | | **Hospitals and health systems** | Covered entity | EHR modules, imaging archives, and disaster recovery replicas | | **Physician practices and clinics** | Covered entity | Practice management systems, patient portals, and backups | | **Telehealth platforms** | Business associate | Video services, scheduling systems, and recordings | | **Medical billing and claims processing vendors** | Business associate | Claims files and clearinghouse interfaces | | **Health SaaS and digital health startups** | Business associate | Application servers, databases, and object storage | | **Pharma, biotech, and research groups** | Varies by data type | Genomic pipelines, trial data, and GPU workloads | | **Health plans and third-party administrators** | Covered entity | Member data and care management systems | The organizations caught out are usually business associates. A scheduling vendor or an appointment-reminder tool becomes one the moment identifiable healthcare data passes through it, and its cloud solutions fall under the same rules that health systems follow. Atlantic.Net covers that boundary in its guide to[what HIPAA-compliant cloud hosting involves](https://www.atlantic.net/hipaa-compliant-hosting/what-is-hipaa-cloud/). ## What HIPAA Requires From a Cloud Provider HIPAA governs cloud computing in healthcare by naming obligations and leaving the products open. OCR states plainly that it[does not endorse, certify, or recommend specific technology](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html), which is why “HIPAA-compliant hosting” is a phrase with nothing behind it. Four requirements do most of the work when healthcare organizations compare cloud providers and healthcare cloud platforms. ### A Signed BAA When a covered entity engages a cloud provider to process or store ePHI, that provider is a business associate. OCR is explicit that this holds even when the provider stores only encrypted data and holds no decryption key. The postal-service “conduit” exception covers transmission-only services, so it does not apply to persistent cloud data storage. Holding ePHI without a BAA violates 45 CFR §§164.308(b)(1) and 164.502(e), and OCR has settled with a covered entity that stored more than 3,000 individuals’ records on a cloud server with no agreement signed. ### Encryption of Patient Data in Transit and at Rest Encryption turns a breach of sensitive data into a non-reportable event, provided it meets the HHS standard for rendering PHI unusable. Current practice is AES-256 at rest and TLS 1.2 or 1.3 in transit. Encryption is a data privacy control, and OCR adds a warning worth repeating: encryption “does not maintain the integrity and availability of the ePHI”, so it cannot stand in for contingency planning. ### Audit Logging and Access Control The Security Rule requires mechanisms that record and examine activity in the cloud systems holding ePHI: administrative action logging on the hosting side, application-level access logs on the customer side, retention long enough to reconstruct an incident, and role-based access management so a billing clerk cannot open a clinical note. Atlantic.Net’s breakdown of[HIPAA log retention requirements](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-log-retention-requirements/) covers the periods. ### Backup, Contingency Planning, and Incident Reporting A business associate must report security incidents to its customer, and breaches of unsecured PHI under the Breach Notification Rule. Backup and recovery belong in the service level agreement alongside availability and data return at termination, and that agreement must never block a customer from its own ePHI. The proposed[HIPAA Security Rule update](https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information) would make several of these express requirements: encryption at rest and in transit, multi-factor authentication, vulnerability scanning every six months, annual penetration testing, network segmentation, a yearly-reviewed asset inventory and network map, and written procedures to restore affected systems within 72 hours. Published in January 2025, it has not been finalized, and the timetable now points to 2027. Designing cloud systems to the 72-hour target is still sensible, because it is the number regulators have put in writing. ## What Healthcare Organizations Gain From Cloud Computing The case for cloud computing in healthcare rests on four things: data security, recovery, capacity, and cost. ### Ransomware Resilience and Healthcare Data Security 2025 was the worst year on record for health data breaches across the healthcare industry.[772 data breaches of 500 or more records reached OCR](https://www.hipaajournal.com/healthcare-data-breach-statistics/), affecting roughly 138 million individuals, with hacking and other IT incidents behind more than 80% of them. The Change Healthcare ransomware attack alone reached 192.7 million people, the largest healthcare breach in US history. Cloud computing changes what recovery looks like. Off-site encrypted backups, snapshot replication into a second data center, and immutable copies turn an encrypted production estate into a restore job. Managed cloud services supply the security solutions most practices cannot staff alone: a FortiGate firewall with intrusion prevention, Trend Micro Deep Security Suite, file integrity monitoring, and 24/7 SOC monitoring. ### Disaster Recovery Without a Second Building The traditional answer to a failed server room was another server room.[Disaster recovery](https://www.atlantic.net/disaster-recovery/) built on cloud technology replaces that with replication into a second region, which costs less and tests more easily. A plan nobody has rehearsed is a document, and OCR treats contingency planning as a Security Rule obligation in its own right, because an outage in mission-critical systems halts healthcare operations and patient care. ### Capacity for AI and Data Analytics Workloads Models that score deterioration risk or triage referrals to improve patient outcomes now sit inside patient care itself. ASTP/ONC found that[71% of non-federal acute care hospitals used predictive AI with their electronic health records in 2026](https://healthit.gov/data/data-briefs/hospital-trends-use-evaluation-and-governance-predictive-ai-2023-2024/), up from 66% a year earlier, with half running models they built themselves. Home-built models need GPUs, and cloud technology makes renting them the clearest option. An NVIDIA L40S with 48 GB of memory or an H100 NVL with 94 GB, running inside a[HIPAA-compliant GPU environment](https://www.atlantic.net/gpu-server-hosting/hipaa-gpu-hosting/), handles imaging reconstruction and digital pathology work that would otherwise wait on a purchasing cycle. Data analytics workloads have the same shape: a quality report that runs six hours a quarter needs the cores for six hours, then stops costing money. ### Cost Savings, Operational  and Fewer Data Silos Cost savings in healthcare cloud computing come from the capacity you stop buying in advance. A practice that sized its data storage for five years of medical images bought four years of idle disk. Consolidating patient records onto shared[cloud storage](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-cloud-storage/) also clears the silos that block data sharing when every department buys its own appliance, giving clinicians and other healthcare professionals real-time data access at the point of patient care. Healthcare organizations get the comparison wrong when they set monthly cloud spend against last year’s hardware invoice. The honest version adds what an on-premises estate hides: the replacement cycle, the second site, power and cooling, licensing, and the administrative tasks that keep a small IT team patching hypervisors. Cloud computing collects those into one budget line that is easier to forecast. ## How to Migrate From Standard Hosting to a HIPAA-Compliant Cloud Environment Cloud migration for patient records follows a fixed sequence across the healthcare sector, and a skipped step usually surfaces during the first risk assessment. The friction in a data migration seldom comes from the main application; it comes from the edges of the existing systems: an interface engine nobody documented, a reporting database with a hardcoded IP address, a scanner that writes to a file share. 1. **Inventory where ePHI lives.** Every database, file share, log destination, backup target, and third-party interface. 2. **Run a risk analysis.** OCR requires this of both parties, and it decides which controls the provider owns. 3. **Sign the BAA before any data moves.** The obligation attaches the moment ePHI arrives, test migrations included. 4. **Build the target cloud deployment.** Private hosts, segmentation, encrypted data storage, managed VPN, MFA on every administrative account, logging with retention. 5. **Migrate a non-production copy first.** Validate application behavior, interface engines, and restore times against real data volumes. Interfaces between on-premises healthcare systems and cloud-based systems, HL7 feeds, FHIR endpoints, and DICOM routes, are the last thing tested and the first thing to break. 6. **Cut over and verify.** Confirm encryption is active, audit logs are landing, backups run to both sites, and access controls survived. 7. **Decommission the old environment.** Sanitize the disks and document it. Old ePHI on a retired server is still your ePHI. Atlantic.Net includes four hours of[migration service](https://www.atlantic.net/managed-services/migration-services/) with its HIPAA plans and bills additional hours at $160. Most single-application moves fit inside that. A multi-system health record cutover does not, and scoping it honestly beats discovering it mid-window. ## Where Hybrid Cloud Still Makes Sense Cloud computing in healthcare rarely ends up all-in. Some workloads should stay put: imaging modalities with hard latency requirements, lab instruments tied to local controllers, and legacy systems whose vendors will not support virtualization. A hybrid arrangement puts patient-facing services, data analytics, and business continuity workloads on public cloud platforms w. At the same time, those legacy systems stay inside healthcare facilities, connected over a[virtual private cloud](https://www.atlantic.net/cloud-platform/virtual-private-cloud/) with IPsec or OpenVPN tunnels. The trade-off is that hybrid costs operational and doubles the compliance surface: two sets of access controls, two logging pipelines, two contingency plans. Hybrid by accident is what a stalled migration looks like, so design it deliberately. ## Choosing a Healthcare Cloud Hosting Provider Five questions separate the cloud solutions that hold up from the ones that market well. - **Will you sign a BAA as standard, or is it an upgrade?** If the agreement costs extra, those cloud solutions were not built for ePHI. - **What did your last independent cloud security audit cover?** Ask for the scope, the auditor, and the report. SOC 2 Type II usually comes under NDA; SOC 3 is public. - **Which controls do I still own?** A provider that cannot draw the shared-responsibility line has not thought about it. - **Where is the data stored, and who reaches the hypervisor?** OCR permits offshore storage with a BAA but expects that risk in your risk analysis. - **What is the restore path, and how long does it take?** Ask for a tested number, and ask who answers at 3 am. Outsourced first-line support logs compliance incidents as routine tickets. Several cloud providers specialize in cloud computing in healthcare. Atlantic.Net, ClearDATA, US Signal, LightEdge, TierPoint, DataBank, and Armor all sell healthcare cloud services with a BAA behind them. Atlantic.Net compares these cloud solutions in its[HIPAA hosting buyer’s guide](https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-hosting/) and its[review of HIPAA hosting for smaller practices](https://www.atlantic.net/hipaa-compliant-hosting/top-hipaa-hosting-provider-for-small-businesses-in-2026/). For an anchor on what these cloud-based healthcare solutions cost, a Fortress Developer plan from Atlantic.Net provides 6 vCPU, 16 GB RAM, 200 GB SSD, and 10 TB of transfer from $492.31 per month on Linux, with the BAA, a managed FortiGate firewall, encrypted on-site and off-site backups, MFA, a managed VPN,[server management](https://www.atlantic.net/managed-services/), and a[100% uptime SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/). A three-clinician practice running an EHR, a patient portal, and a PACS archive of medical images lands on that tier. ## Frequently Asked Questions ### Which Types of Healthcare Organizations Are Most Commonly Required to Use HIPAA-Compliant Hosting? Hospitals and health systems, physician practices, telehealth platforms, medical billing and claims processors, health plans, and digital health vendors handling ePHI for healthcare providers. The requirement follows the data: healthcare systems and smaller practices that transmit or store patient data electronically need cloud-based solutions backed by a BAA. ### How to Migrate From Standard Hosting to a HIPAA-Compliant Environment? Inventory every location holding ePHI, run a risk analysis, sign the BAA before any data moves, build the target environment with encryption, segmentation, and MFA, migrate a non-production copy to validate the application, cut over and verify logging and backups, then sanitize the old servers. ### Which Hosting Providers Specialize in HIPAA-Compliant Private Clouds? Atlantic.Net, ClearDATA, US Signal, LightEdge, TierPoint, DataBank, and Armor all offer healthcare-focused private cloud hosting with BAAs. The differences between these cloud solutions sit in audit scope, whether the environment is single-tenant, and how much the provider manages. ### What Are the Best HIPAA Hosting Platforms for Telehealth Applications? Telehealth is the most demanding form of cloud computing in healthcare. It needs capacity that absorbs session peaks, low-latency paths near the patient population, and encrypted storage for recorded consultations and feeds from remote monitoring devices. Look for cloud services with regional data centers, a managed VPN and firewall, and load balancing. Atlantic.Net’s[HIPAA virtual desktop guidance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-virtual-desktops-remote-clinics/) covers remote access for medical professionals alongside a telehealth service. ### How Does Disaster Recovery Planning Relate to HIPAA Hosting Requirements? Disaster recovery plans are a HIPAA obligation in their own right. The Security Rule’s contingency plan standard requires a data backup plan, a disaster recovery plan, and an emergency mode operation plan. The proposed Security Rule update would add a written procedure to restore affected systems within 72 hours. ### What Is a BAA and Why Is It Required? A BAA is a contract between a covered entity and any vendor handling ePHI on its behalf. It sets the permitted uses of the data, requires Security Rule safeguards, obliges the vendor to report incidents and breaches, and governs return or destruction of the data at termination. HIPAA holds both parties liable, and hosting ePHI without one is a violation. ## Working With Atlantic.Net Atlantic.Net has hosted regulated workloads for the healthcare industry since 1994 and runs[HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) on privately audited cloud infrastructure across eight data centers, backed by independent HIPAA, HITECH, SOC 2 Type II, and SOC 3 Type II audits. Every plan includes the BAA, encrypted backups, a managed firewall with intrusion prevention, MFA, and US-based engineers on the phone at any hour. If you are moving patient data, an[EHR platform](https://www.atlantic.net/hipaa-compliant-hosting/top-10-hipaa-compliant-ehr-solutions/), or a telehealth application onto healthcare cloud computing and want the shared-responsibility line drawn before anything migrates,[contact the Atlantic.Net solutions team](https://www.atlantic.net/about-us/corporate-contact/). We will review your application stack, your recovery targets, and which controls sit on our side of the agreement and which stay on yours. --- # What is a WAF (Web Application Firewall)? Types of WAFs > URL: https://www.atlantic.net/vps-hosting/waf-web-application-firewall/ | Published: 2013-10-11 | Updated: 2024-05-15 | Author: Kent Roberts Firewalls come in essentially three varieties: hardware firewalls, software firewalls, and web application firewalls (WAFs).   Typically a cloud hosting company or data center infrastructure will take advantage of both of the first two types of firewalls for general use. The third type – the focus of this article – started gaining prominence about a half-decade ago (though there is an overlap of these categories, as discussed below). According to the nonprofit Open Web Application Security Project (OWASP[)](https://www.owasp.org/index.php/Category:OWASP_Best_Practices:_Use_of_Web_Application_Firewalls), web application firewalls became more prevalent as hackers started focusing their efforts on apps (e-commerce stores, sales systems, etc.). Essentially, the apps provide different entry points for intruders, so hackers started zoning in on them. That point of focus has often allowed them to enter without being noticed (because standard firewalls have been centered on general network activity rather than the range of issues specific to web apps). ## Why is a web application firewall necessary? The basic need for firewalls specific to web apps is that Hypertext Transfer Protocol (HTTP) is relatively simplistic. Obviously, that protocol defines the back-and-forth of Internet interaction. Web applications, meanwhile, have become more and more sophisticated as time has gone on. The apps have outgrown the language used to communicate them in a sense, security-wise. Specialized protective software – the web application firewall – bridges the divide so that apps aren’t as vulnerable. There is an additional disconnect between HTTP and web app security related to the state. HTTP is stateless, and web apps are typically stateful. In other words, the latter utilizes previous processing information, whereas the former does not. This disparity means an additional incompatibility between the two, beyond general complexity: essentially, a web app is “on its own” to establish its parameters and protect itself (enter the WAF). ## What exactly is a web application firewall? By definition (per OWASP), a WAF is a piece of software intended to protect a web app that is on the level of the application. Nonetheless, a WAF is not defined by the web app: it’s not a customized solution specific to that application but – similarly to a general software firewall – one that contains parameters to protect against intrusion in a wide variety of frameworks and scripts. To be clear, there is an overlap between the different types of firewalls. Software and hardwall firewalls are used in their own right to protect networks. They can be implemented either as hardware devices, installed as an actual physical piece of infrastructure, or used as software, installed on servers, or integrated into other devices (e.g., they can be loaded onto hardware firewalls to enhance their protection with WAF capabilities). However, with their specialized function for web applications, WAFs can take the form of either of those two main types. ## The overall function of web application firewalls in an enterprise Although an enterprise will typically consider the strength of some WAFs more important than others (based on the role played by the app it is protecting), it’s wise to remember that a system may only be as strong as its weakest link. Often a company is running dozens of web apps at the same time. Hackers could be able to access the network, potentially, through any of the firewalls. For that reason, apps that may generally be less vital to business operations should still be reasonably secure. That said, systems administration often must place greater or lesser weight on the firewalls protecting certain apps because of budgetary concerns. Here are a few questions that can be asked to strike the proper balance and understand which apps must have the highest degrees of protection: - Does the app grant availability to sensitive details of any users of the system, whether internal or external parties? - Does it allow access to proprietary documents or data? - Does the app play a crucial function in the enterprise? How bad would it be if it went down? - Is the app itself involved in network or any system protection? ## App development & function of individual web application firewalls Clearly, the strength of each firewall should be as strong as possible, as discussed above. However, ideally, a firewall is not crucial at the outset. Security should be a major factor for custom apps during their development. Loopholes in applications are patched as weaknesses become known, but problems discovered when an app had been used for a lengthy period can often mean more time and money for a fix. A web application firewall comes in handy when it is impossible or difficult to make changes to the application or when the necessary revisions are extensive. The firewall is used when the app itself cannot be changed. Standardly a firewall uses a blacklist, protecting against an individual, previously logged attacks. Additionally, it can also use a white list, providing allowable users and instances of interaction for the application. ## Conclusion Web application firewalls play an important role for companies worldwide as well as our [VPS hosting](https://www.atlantic.net/vps-hosting/) service. We believe strongly in our own firewalls and cloud hosting security at Atlantic.Net. In fact, we believe so much in our reliability that we guarantee a complete absence of downtime. Learn more about what makes us different and why our [VPS hosting](https://www.atlantic.net/vps-hosting/) is world-class! --- #### Read More About Firewalls - [Managed Firewall](https://www.atlantic.net/managed-services/firewall/) Service from Atlantic.Net - [Cloud Data Breaches](https://www.atlantic.net/vps-hosting/are-data-breaches-in-the-cloud-getting-better-or-worse/) - [Top 10 Firewalls](https://www.atlantic.net/hipaa-compliant-hosting/top-10-firewalls/) --- By Kent Roberts --- # Migrate to a New WordPress Host in 5 Steps With No Downtime > URL: https://www.atlantic.net/vps-hosting/migrate-wordpress-website-downtime-5-steps-1-day/ | Published: 2013-10-15 | Updated: 2026-01-09 | Author: Kent Roberts Some of us are experts at moving sites from one web host or server to another. For those of us who are not in that category, it’s often a task that makes us procrastinate. For a good reason, too. Once everything gets set up and is functioning correctly on our site, it’s natural to be concerned that switching over to a different hosting service could cause downtime, glitches, and other headaches. The advice on WordPress itself, furthermore, is comprehensive but complicated. ## Migration is easier than ever Like all other aspects of the CMS (content management system), WordPress migration has come a long way over the years. Various software makes the task so easy that we will soon wonder what we were worried about in the first place… until it takes as much as three days for your DNS servers to update with your domain registrar. Then you will be pulling your hair out. Here is a set of instructions for WordPress migration divided into five basic steps, primarily using advice from the design and blogging site Hongkiat.com. The focus of these tactics is preparation so that you will not experience any downtime or any outwardly facing indication that the site is replanting its roots. ## Migrate to a new WordPress host – 5 steps Performing the transfer correctly and without any hitches will require a basic comprehension of three basic technologies/protocols. If you don’t feel comfortable in these areas, it might be time to sweet-talk the computer science kid who lives next door: - cPanel - IP (Internet protocol) addresses - FTP (file transfer protocol). The steps are as follows: ## 1. Hold your horses. Whatever you do, don’t cancel with the old hosting service until everything is completely solid with the new one. Canceling ahead of time won’t only mean downtime. It could also mean you lose your site’s files. Then you won’t have anything to migrate anyway. The reason the hosting company could quickly get rid of all of your site’s “stuff” isn’t spiteful. Rather, it’s typically an indication that they’ve stopped charging on that day and will return any unused portion of your subscription fee for the remaining days of the month. Hence, your data goes in the trash. Obviously, if you have it all backed up, you’re fine … So copy it all over to the other hosting service. Ideally, though, you want to ensure that everything is working perfectly before cancellation – maybe 72 hours. ## 2. Grab those files. You can see a lot of safe migration is about preparation. Before moving to a new host, make sure that they have the same website admin panel, usually either cPanel or Parallels Plesk. It is possible to migrate to another control panel (cPanel to Plesk; Plesk to cPanel), but one thing at a time: focus on switching hosts for now. Remember that your core concern is getting your files able to run on a new host seamlessly. If using cPanel, go to your domain, tying it to port 2082 yourfabulouswebsite.com:2082; if that doesn’t work, try yourfabulouswebsite.com/cpanel. Look for the Backup section; within that, look for Download Backups. Go ahead and download everything. You want the compressed version. If you are using a Mac, make sure that it won’t automatically decompress and open the files in the Safari options. [Migration instructions for Plesk. CPanel is assumed moving forward.] ## 3. Switch accounts. Now jump over to your new administrative account (new hosting company). You should have the IP addresses from the host (from the email when you signed up for your account); if not, get them. Use the IP address with the same types of endings used above, either 2082 or /cPanel. One of those two should work. Go into the backup area again. Now find where you can back up your entire site. Typically it’s labeled Backup Restore. Restore the file that contains your complete website. The upload is finished when you see a list of all your site files on a new page. Then go back to the general backups page, and do the same thing with your databases. Now all your basic site information is in place. ## 4. Is your data in order? Using cPanel, you will need to reenter all login details for your MySQL databases: those details do not transfer. Within cPanel, go to the MySQL Databases section to reestablish those parameters. Look at the prefixes for each of the databases (what comes before the underscore in the filename). Every software that accesses those databases will need to be reconfigured to look for the correct prefixes. To do that, go through the IP address again, and get into FTP. Using FTP, you can reconfigure system files as needed. Though this may sound complex to some, don’t let it stress you out too much. All traffic is still seeing your “old” site. It’s just laying the groundwork. ## 5. Diving in. Now it’s time to flip the switch: changing your DNS (domain name system) servers. At the registrar (where you purchased the domain), go to the domain registration section of your account to do so. You should see information entered in this format for your domain name servers: - ns1.host-you-are-leaving - ns2.host-you-are-leaving In the same email that contained your IP information, you should also see your DNS servers. Those servers need to be changed. If not, retrieve them through support. It may take a day or two for everything to switch over properly, which is fine – you are essentially serving the same content through the two different sites. Try not to change anything on your website during this period. Test everything, ensuring everything is looking all right with your site on the new web host over a couple of days. Finally, cancel with the old hosting company. ## Conclusion Well, you’ve done it… Wait, are you switching to the right hosting company, though?   After all, the right hosting company would be Atlantic.Net, and we offer excellent [CPanel VPS](https://www.atlantic.net/vps-hosting/) Hosting, among many others.  In business since 1994, find out why our secure and sophisticated hosting solutions might be right for you. Kent Roberts **Try our [WordPress VPS Hosting](https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/) and be up and running in less than 30 seconds!** --- #### Read More About Data Migration - [Migration Services](https://www.atlantic.net/managed-services/migration-services/) from Atlantic.Net - What Is the Best [Cloud Data Migration](https://www.atlantic.net/vps-hosting/best-cloud-migration-solution/) Solution? --- --- # Atlantic.Net is offering up to 30% off on all Cloud VPS Hosting Plans > URL: https://www.atlantic.net/press-releases/atlantic-net-offering-30-off-cloud-vps-hosting-plans/ | Published: 2013-10-15 | Updated: 2024-06-11 | Author: Editorial Team ***For a limited time, Atlantic.Net Cloud VPS plans now start at only $0.99 a month with no long term commitment!*** Orlando, FL – October 15, 2013 – Atlantic.Net ([Atlantic.Net](https://www.atlantic.net/)), a privately held leader in providing hosting solutions, announced today, a new promotion, which offers users up to 30% off on all newly created Windows and Linux Cloud VPS servers. All cloud VPS plans include per second billing, 1TB of outbound and free unlimited inbound data transfer. Users can provision servers in less than 30 seconds and take advantage of the promotional pricing along with free setup, free backup and free DNS. “We have a huge cost advantage by leveraging the latest technology, open source solutions and about two decades of networking and computing experience,” said M. Adnan Raja, Director of Business Development for Atlantic.Net. “With our latest price reduction, we are simply making it even more affordable for users to switch to a cloud based infrastructure and to help accelerate adoption to the latest cloud technology.” Atlantic.Net’s Cloud VPS also includes an API Access, 24/7/365 live support, optional additional IP addresses and cPanel & WHM. You can simply provision a new server online at https://www.atlantic.net/promotions/vps-up-to-30-percent-off/ ** About Atlantic.Net** Atlantic.Net is a market-leading Hosting Solutions Provider recognized for providing exceptional business hosting service, simplifying complex technologies, and building a brand that businesses trust since 1994. Atlantic.Net specializes in providing Cloud Servers, VPS Hosting, Colocation, Dedicated Servers and Virtualization Hosting Services. Atlantic.Net owns and operates a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited and certified data center infrastructure and is dedicated to implementing tailored hosting solutions that enable clients to enjoy the benefits of cost savings. ** Atlantic.Net Media Contact:** Media Relations [pr@atlantic.net](mailto:pr@atlantic.net) (321) 206-1371 --- # How to use the Cloud for marketing and SEO agencies > URL: https://www.atlantic.net/hipaa-compliant-wordpress-hosting/cloud-marketing-seo-agencies-comic/ | Published: 2013-10-16 | Updated: 2026-03-01 | Author: Kent Roberts Cloud server hosting is a field that is, well, a bit nebulous, as expressed in the below comic. ![How to use the Cloud for marketing and SEO agencies ](https://www.atlantic.net/wp-content/uploads/2013/10/04_1.png) The cloud can be instrumental, though, for web prominence. Whether a company is doing its own SEO and marketing or using an outside service for those purposes, cloud computing can play an important role in the success of campaigns. ## What is cloud hosting? Of course, we understand that the Internet is not a physical object. However, we have gotten used to the idea that websites are stored on individual servers. Get dedicated hosting, and you have your own server. Get shared hosting, and you share a server with lots of people. Get [VPS hosting](https://www.atlantic.net/vps-hosting/), and you share, but your section functions as its own server. Cloud server hosting, however, removes the storage of your website [from a specific physical space](http://www.hongkiat.com/blog/cloud-hosting-how-does-it-work/). Instead, your site is stored throughout a server cluster designed by the hosting company. Rather than talking about one server or a piece of a server or multiple dedicated servers, you have a group of computers all storing and delivering your website. It’s efficient, affordable, and scalable. ## Cloud’s relationship to SEO A major advantage of the cloud for delivering content is that you are not tied to one location. Understanding how search engine rankings and geographical location relate to a sense of why this gets complex for [SEO](https://kevinmiller.com/). The reason location of the server is important to your ranking on the search engines is because services like Google use a person’s physical location in the world to determine results. That’s one way that the search engines try to make results more relevant to the user. Forgetting servers and just considering content, it’s the reason why you can enter “order sushi” into search in Albuquerque, and many of the top results will be from your local area. Search engines don’t just look at where the user is located, though. Google and Bing also check the server’s IP address delivering the site to determine the physical hosting location. Regardless of the top-level domain (TLD) – such as .com or .uk – your site will show up in searches for that country. TLD’s are by no means irrelevant to SEO. The server’s location is not as crucial for a site with a local TLD (such as .com.au in Australia) as it is for generic top-level domains (such as .org). However, it’s also possible within Webmaster Tools to specify a site’s location, at least for Google. In the past, it has made sense to have your server located in the nation where you most want to do business; this practice lowers latency for you and your users (the interval between sending a request to a server and receiving a response). With cloud server hosting, though, your website is served internationally. The search engines have yet to completely catch up with the cloud in two core ways: 1. different pages of your site can start to compete against each other in the rankings (because search engines think it’s multiple sites – due to the multiple IP’s) 2. when a site and a server are in different geographical locations (a key component of the worldwide nature of cloud computing), Google does not allow the site as much geographical specificity. Regarding the first of those two issues, when your site competes, over time, the version with the most authority will get better positioning on the SERPs (search engine result pages) than the local site. For example, a site that has both UK and an AU version compete against itself. Even if the AU version is intended for Australians, the UK version could get better rankings based on the confusion created by cloud hosting. Regardless of these two ways in which the search engines need to improve, significant emphasis is placed by Google and Bing on page load speed. It first became a recognized optimizer in Google Caffeine, creating a much more sophisticated site indexing system. That’s good news for those using the cloud. The nature of cloud infrastructure makes it much easier to deliver a webpage quickly. A faster site means better search rankings. ## Google’s general stance toward cloud computing More than anything, it’s illuminating to get a sense of Google’s perspective toward the cloud. It’s certainly not dismissive. Matt Cutts, head of webspam at Google, wrote a post on his site in 2008 entitled, “[Why cloud services rock](https://www.mattcutts.com/blog/why-cloud-storage-and-computing-rocks/).” The following year, he spoke in a video about how cloud storage [is positive for search](http://www.youtube.com/watch?v=IZF13_4obbQ). ## Conclusion Again – as seen in the above comic – cloud server hosting can be all over the place. Much of the reason why the quality of a given cloud system is difficult to determine is because of the strengths of the cloud: its diversification and lack of physical specificity are exactly what make it more flexible, scalable, reliable, and affordable. If you want real, dependable, secure cloud server hosting solutions, we’ve got you covered. We also offer managed and [HIPAA compliant WordPress hosting](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/) solutions. By Kent Roberts --- # How BYOD is Changing Technology in the Workplace > URL: https://www.atlantic.net/vps-hosting/byod-changing-technology-workplace/ | Published: 2013-10-17 | Updated: 2025-03-06 | Author: Alexander Wise Without a doubt, you probably own a smartphone, tablet, or laptop. You may also own two or all three of these devices. With the introduction of smarter mobile technology comes smarter ways of conducting business, and companies are beginning to see the correlation and implementing its benefits like never before. How has the concept of bringing your own device (BYOD) impacted the corporate world? What benefits can employers reahtp from the BYOD policy? How does BYOD merge with cloud computing technologies? ## What is BYOD? Bring your own device (BYOD) refers to the policy of allowing employees to bring and regularly use personally-­‐owned mobile devices, such as laptops, tablets, and smartphones, to their respective workplaces and utilize those devices to access controlled and privileged company information and applications. For employers, understanding how the transition to a BYOD policy will affect your business and your employees is extremely vital. ## Why incorporate a BYOD policy? In a recent study conducted by IBM, 82 percent of respondents expect smartphones to play a “critical role in business productivity in the next two years,” and 36 percent of those surveyed deemed laptops critical to overall productivity. Alone, [VPS Hosting](https://www.atlantic.net/vps-hosting/) and the concept of BYOD offer some real advantages. But when combined, cloud computing and the establishment of BYOD becomes an even more useful means of conducting business. ## Sensitive information and the BYOD model Although, the BYOD model is not without its faults: security is one of the biggest objections employers have with personal devices. If a worker’s smartphone, tablet, or laptop falls into the wrong hands—whether accidentally or on purpose—employers fear that their sensitive corporate information will fall into those hands as well. However, there is hope; even if this sensitive information is accessed from an employee’s device, it can still be safe and secure within a cloud environment. The employee can quickly and easily access the data from their next device. With all vital data stored within a cloud environment, this process is seamless.  Employees will be held more accountable for their personal devices—they don’t want to shell out a thousand dollars for a new laptop! Since they’re held more responsible for their devices, they are likely to take better care of them, saving you both time and a headache down the road. Through the cloud, all storage and data processing occurs on mobile devices, but the data isn’t actually stored on the employees’ local hard drives, ensuring supreme levels of security. ## Mobile device management Perhaps you’re worried about these mobile devices obtaining a virus. Mobile device management, a service offered by many cloud hosting providers, helps secure workers’ devices from outside malicious attacks by using the cloud as a centralized headquarters. Additionally, mobile device management tools allow IT team members to remotely wipe lost or stolen devices to ensure the security of sensitive information. Mobile device management tools are essential when establishing a BYOD policy because hackers view personal devices as incredibly easy access points. These tools aid in preventing data breaches that could otherwise bring a company down to its knees. ## Other BYOD benefits Another benefit of utilizing the cloud for employee’s devices is that it can minimize time-­‐wasting behaviors, such as online messaging, surfing, and playing games. It provides greater visibility into employee activity. Additionally, some cloud server hosting plans provide URL filtering, keeping track of the websites employees visit in real-time. Of course, organizations should always maintain open lines of communication with their employees. Discuss appropriate workplace activities when on the business network, and provide information regarding monitoring measurements are in place to ensure productivity. As your employees’ devices age, you continue to save money, as you no longer need to shell out copious sums of money maintaining, updating, and repairing these devices. There is no need for complex in-­‐house architecture, so there is no need for an extensive IT department. Simply hire a few individuals to maintain day-­‐to-­‐day operations, and you’ll be set. The cloud enables your employees to store all necessary files and other information in a secure storage center. Since they can access this information from any device in practically any location, they won’t need to waste paper and ink by printing out large documents. If you have ever bought printer ink, you know that this means significant savings! ## Conclusion Together, BYOD and a cloud computing solution have the potential to save companies unbelievable amounts of money. Employers no longer need to worry about investing in expensive mobile technology—that responsibility now lies on the employee. However, you may want to implement a reimbursement program to keep your employees happy. Employees love using their own devices, and happy employees mean productive employees. If you have not yet considered the bring your own device method, you may want to think again. When combined with the power of cloud computing, BYOD can maintain a productive, positive workplace. If you are interested in learning more about how [VPS Hosting](https://www.atlantic.net/vps-hosting/) can help your business, contact Atlantic.Net today. We also offer managed and [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions.   --- # Cloud Hosting vs. VPS Hosting: Whats the Difference? > URL: https://www.atlantic.net/vps-hosting/cloud-hosting-vs-vps-hosting/ | Published: 2013-10-23 | Updated: 2026-01-09 | Author: Kent Roberts Cloud server hosting and virtual private server (VPS) hosting are increasingly popular ways to deliver a website. These two options appear similar at first glance because they both represent a complete physical dedicated server while being something different. Cloud server hosting is woven into a network, a structure that divides work between servers. A VPS is much closer to being that physical piece of equipment, but it’s actually a piece of one. ## VPS Hosting vs. Cloud Hosting – The Basics Cloud and VPS each have [advantages and disadvantages for hosting](https://www.atlantic.net/blog/). A virtual private server is a middle ground between a dedicated server and shared hosting. Using virtualization software on a server, several different companies can each experience the basic advantages of a dedicated server without having to undergo the expense of a complete server. For companies that desire stronger security and delineation from other clients of a hosting company and that want a greater sense of control over the parameters of their services, VPS is a great option. Hosting via cloud computing is on-demand, meaning the amount of storage you have, the bandwidth you need, and the CPU you require are all changeable on a moment-by-moment basis. VPS can be adjusted as well, just like any hosting package, but not immediately. Also, VPS allows bursting – popping up into unused resources when a flood of traffic hits and the apportioned resources max out – but that capability is limited. Cloud is designed in a way that is truly optimized for scale; it’s virtually unhindered. A primary concern of those choosing a virtual private server over the cloud is security. Though the technology that secures cloud server hosting has advanced incredibly since its inception, there are still those who prefer the reliability of a physical location for the site’s data and files. Knowing precisely where that Virtual Private Server is located, and its specific parameters make it possible to build a security fortress around a VPS. ** *Note, however, that the same can be said of private cloud hosting.* Quality cloud servers have undergone thorough evaluation to clear the structure is sound and all data is secure. Although the cloud does not offer the safety of a specific physical location, it’s highly redundant and reliable because instances are replicated across numerous devices. The cloud is woven into a network in a way that no other hosting solution allows, and that means you are less vulnerable to systemic failure. ## VPS Hosting vs. Private Cloud Hosting – Specific Features & Attributes Along with the general differences described above, cloud and VPS hosting can be understood in terms of parameters such as server configuration, the location of the physical equipment, how easy it is to scale, and the expense. [ClubCloudComputing](http://www.clubcloudcomputing.com/2013/06/4-key-differences-between-a-virtual-private-server-a-private-cloud/) looks specifically at private clouds, which may or may not apply to your situation; either way, it gives us a window into those particular infrastructures (which we offer at Atlantic.Net), the opposite end of the spectrum from worldwide services such as Amazon and Google. *1.    Servers – VPS vs. cloud* A VPS is one machine divided into sections for several different hosting customers. A VPS is like shared hosting except for the following characteristics: a.) you have a larger piece of the server; b.) you have much greater freedom to do what you want with your section, and c.) you are much less vulnerable to security and other issues caused by the server’s other users. A private cloud, much like a public cloud, uses various devices to serve as one ” cloud server together.” Because various servers are involved, reliability and redundancy are a huge benefit. A cloud server is similar to a server cluster, but it is more loosely coupled. *2.    Physical location – VPS vs. cloud* A VPS is typically situated in the data center of a hosting service. A private cloud is often located at a business’s own data center. That’s the case because if you have a server on-site at your company, you’re probably using the whole thing as a dedicated server, not partitioning it off for various companies. However, sophisticated cloud service providers (CSPs) now offer private clouds for their clients, using a cloud framework with equipment dedicated to one company. *3.    Scaling* Whenever you run into a resource limitation in modern cloud computing, you go into your administrative interface and request the changes, which occur automatically. Changes to the limits of a VPS require manual intervention by the support staff, which is not always fast enough when traffic suddenly peaks. *4.    Expense* A VPS is significantly less expensive. You are only paying for a part of one server rather than multiple servers as in a private cloud setup. To reduce cost with the cloud, you could use general cloud server hosting instead, which does not designate your own servers. ## And Another Choice: Cloud-VPS Hybrid Based on the above, it’s up to you whether VPS or cloud is best. Actually, you don’t have to decide. You can also go with Atlantic.Net’s [VPS hosting](https://www.atlantic.net/vps-hosting/) services. Because we specialize in both services at Atlantic.Net, we eventually decided to combine the best of both worlds and create cloud-based [VPS hosting](https://www.atlantic.net/vps-hosting/) packages. By Kent Roberts --- # Mobile Apps are Shifting to Cloud Servers > URL: https://www.atlantic.net/vps-hosting/cloud-mobile-apps/ | Published: 2013-10-28 | Updated: 2026-01-09 | Author: Kent Roberts The parameters of cloud server hosting, like any form of cloud computing, can be foggy and unsure. The below comic expresses the dangers that can be found in a cloud’s gray areas. ![cloud servers- cartoon](https://www.atlantic.net/wp-content/uploads/2013/10/03_1.png) Regardless of misunderstandings and a range of quality provided by various cloud service providers (CSPs), there is a legitimate reason why so many enterprises are shifting their attention and resources to the cloud. Beyond its general positive aspects (and we will discuss the little-mentioned ones below), cloud technology has different implications for different businesses. Industries such as investing, marketing (both covered previously in this blog), and mobile applications can benefit in different ways. Mobile apps will be the focus today. We will briefly review broad cloud advantages – typical and atypical – and then specifically explore the relevance to companies in the business of mobile applications. ## Advantages of cloud computing – obvious & not so obvious Joe McKendrick of Forbes mentions several of the main benefits of the cloud that are typically the point of focus. He also covers several unexpected cloud benefits that are conveyed less often. Several of the standard cloud computing advantages are the following: 1. Economical 2. Systemic flexibility 3. Highly scalable 4. Excess RAM available as needed 5. Excess storage available as needed 6. Extremely reliable regarding uptime and backups 7. Low latency. Here are several less frequently discussed but similarly compelling benefits: - *Agility* – The cloud makes it extremely easy to get into new business lines or avoid lines of business wisely, having conducted the applicable testing. Because cloud services can expand at a moment’s notice, you can test something right away with no long developmental window. - *Less caution when merging* – One reason why many companies choose not to merge is because it’s so costly and labor-intensive to combine two huge pools of data. Data entry clerks are hired in some cases because performing the task with technology is viewed as prohibitively complicated. Cloud data is much more easily accessible. - *Tapping the popular mind* – There is concern that cloud computing is so widely used that it has become a dumbed-down version of legitimate business IT. However, it’s precisely that wide net that now makes it so strong due to a steady flow of ideas and improvements. - *Getting high-level* – Pushing technology to the cloud allows tech executives to focus their time and money on crafting and planning, so they can lead rather than put out fires. Four out of every five IT dollars currently go to infrastructural maintenance, a focus that can be directed forward with the cloud. ## Two approaches to cloud-based mobile apps Matthew Mombrea of ITworld suggests two basic approaches to [developing and deploying a mobile app](http://www.itworld.com/cloud-computing/312635/cloud-or-not-cloud-horizontal-scaling-web-applications). These different avenues are not specific to the cloud, but cloud computing is a reliable framework for either angle. 1. *Quick/dirty* – This strategy means you are moving fast, with your main focus being a general test run with the public. You aren’t concerned upfront with availability to a massive audience. You want to make sure that the app is well-received before you think about potential problems of popularity. 2. *Slow/clean* – On the other hand, you can painstakingly develop the app and ensure it is optimized to scale rapidly. You are investing the time up front to make sure there are no hitches along the way. However, you are investing time – and potentially resources – that could have otherwise gone elsewhere if the app proves to be dead-on-arrival anyway. Interestingly enough, Mombrea generally uses the first of the two-game plans. It’s certainly a more reasonable approach that considers how biased we can be in favor of our billion-dollar ideas, which in many cases are actually thousand-dollar ideas. ## Specific viability of cloud server hosting for mobile apps Kurt Marko of Network Computing believes the cloud is the new frontier for mobile applications. He believes this because the Cloud Server can resolve many of the issues that arise with mobile apps. The cloud is, in fact, just what IT needs to keep mobile app development manageable at a time when 70% of enterprises are currently developing or planning to develop branded mobile apps. Part of the difficulty with mobile apps, says Marko, is that because cell phones differ and so little fits on the screen, native apps – ones designated specifically for certain devices – are desirable. This realization has been frustrating to the computer world because the web already went through a native application phase previously on PCs. Web-based applications were found to be better integrated, better optimized for syncing, and more secure. The cloud, however, is righting the boat again for mobile apps. Tying a native mobile application to the cloud – via mobile backend-as-a-service (MBaaS) or general cloud app hosting – offers the following advantages: - data is located in the cloud, in the realm of the tech staff rather than on the user’s device - ability to place limitations on the transfer of information, such as disabling the ability to paste into an email client or another application - automatic synchronization to the cloud.   ## Mobile application hosting on the cloud Choose wisely when selecting an SSD Cloud Hosting partner for your cloud-based mobile applications.  As suggested by the above comic, don’t go with the cumulonimbus cloud. Generally, you want a hosting service where cloud expertise isn’t an afterthought but a point of focus. Host your mobile web application with Atlantic.Net, where the cloud is king. *By Kent Roberts* Cloud server hosting is just one of many services that Atlantic.Net offers – we also provide managed, dedicated, and [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. See our [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # HIPAA Overview and Four Questions for Web Hosts About Compliance > URL: https://www.atlantic.net/hipaa-compliant-wordpress-hosting/hipaa-overview-4-questions-web-hosts-compliance/ | Published: 2013-11-06 | Updated: 2024-06-08 | Author: Sam Guiliano For those in healthcare IT, HIPAA has been a major concern since it was passed in 1996. The Health Insurance Portability and Accountability Act has two main sections – Title I and Title II. Title I is about portability. In a nutshell, it deals with individual rights related to health insurance, especially group health insurance, when a person is laid off or switching employers. Title II is the one that is of interest to all healthcare entities, not just insurance companies and HR departments. That section of HIPAA primarily deals with [issues of privacy and security](http://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act). All of the act has ramifications for many individuals, but Title II has broader applications for the entire medical industry, especially regarding how data is handled. The digital age makes data handling more critical and, sometimes, complex than was the case with physical documents. A hosting company defining itself as HIPAA-compliant specifically references the privacy and security provisions established in Title II. ## **Covered entity versus business associate** The relationship between you and your hosting company regarding [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) will help you understand your responsibilities and the role of the hosting service. The rules of HIPAA apply to “covered entities” and “business associates.” *Covered entities* –  A covered entity, if you are in the healthcare field, is your organization. Covered entities include the following: - Companies involved in health coverage – health insurance organizations, government services such as Medicaid and Medicare, medical plans provided by private companies to their employees, etc… - Providers of healthcare services – physicians, dentists, medical practices, pharmacies, nursing homes, etc. (assuming that the practitioner or company deals with electronic medical records, a.k.a. EMR, in ways detailed by the US Department of Health standards & Human Services). - Companies holding or transferring data – organizations that serve as clearinghouses of health information, typically transitioning data back and forth between physical and electronic media. *Business associates* – The privacy and security rules transition to these parties, such as hosting companies, when any of the covered entities listed above use a third party to assist in any way with medical records and related information. Utilizing a business associate involves the following contractual relationship: - Business associate agreement – a document completed between the two parties detailing the role of the business associate related to the data. - Specific compliance language – terms stating that the business associate must comply with the privacy and security rules of HIPAA regarding the data. Be aware that the contract is not the only protection for healthcare information related to business associates. These third-party companies are also automatically held accountable for various stipulations listed in HIPAA. Due to this assumed liability, note that some hosting companies protect themselves by stating outright that healthcare organizations may not use their services to store or handle electronic medical records. In contrast, others welcome all medical business, having adopted full compliance measures. ## HIPAA Web Hosting Compliance **Ask your host: four questions regarding HIPAA compliance** Consider asking a [HIPAA compliant WordPress hosting](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/) provider the following questions. These questions will help to establish whether or not the host is truly compliant with current HIPAA expectations: 1. Have you passed an OCR HIPAA Audit? Since the passage of a related bill called the Health Insurance Technology for Economic and Clinical Health Act (HITECH), covered entities must undergo auditing. If your hosting provider is processing data on your behalf, it should have undergone an audit as well. 2. What happens if something goes wrong? Your hosting provider must notify you promptly if there is any data breach. A business associate is held liable for getting you that information promptly so that your organization (the covered entity) can quickly alert any patients whose information was compromised. Ask for the specific policies the company has in place for breaches affecting healthcare accounts. 3. What is your policy toward Business Associate Agreements (BAAs)? Ensure that the hosting company has a high degree of familiarity with these contracts and is prepared to sign them promptly. The business associate agreement ensures that the hosting company understands its responsibility to treat patient health information (PHI) with the highest degree of security. 4. Are you also compliant with SSAE 16 Type II? Auditing for the rules established by the Statement on Standards for Attestation Engagements 16 goes beyond the requirements of HIPAA, providing you a better assurance of security protocols. SSAE 16 contains stronger, more widespread security guidelines and checks the hosting company’s system over a lengthier time span. ## **Choosing a HIPAA-compliant hosting provider** As you may have gathered while reading the above, we would not detail the provisions of HIPAA and recommend questions you can use to grill hosting companies if we were not confident in our own services. Some cloud hosting providers [struggle with security](https://www.atlantic.net/vps-hosting/), but at Atlantic.Net, we are HIPAA compliant both with HIPAA and with SSAE 18 – contact us today about [HIPAA WordPress](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/). --- # How to manage the Black Friday Holiday Web Traffic > URL: https://www.atlantic.net/vps-hosting/managing-black-friday-holiday-web-traffic/ | Published: 2013-11-08 | Updated: 2024-11-14 | Author: Sam Guiliano If you’re in business online, one of your primary considerations should be – and probably is – making sure that your website will be prepared for peak load. Exactly what peak load means, in terms of real numbers, will always be a matter for debate; but you know that you do not want your site to go down at times when your business is achieving its highest levels of success. Because of this concern, you look at the figures – how much space is there in certain hosting packages, how much memory is there, etc… What you’re probably thinking about, though, is not the amount of data flowing through your hosting account but the sales that could potentially mean. You don’t want to lose any sales. That is [especially crucial during the holidays](http://online.wsj.com/news/articles/SB10001424127887324894104578114763862550902) because shopping for presents creates a massive influx of capital for all types of businesses, making up ground for any slow months. Simple techniques can be used to ensure that your holidays run smoothly, not just for you and your loved ones and your mother-in-law, but for your business as well. ## Black Friday & the insanity of the shopping season Perhaps the word “insanity” is a little extreme, but certainly, the traffic spike during the holidays for many websites can be pleasantly uplifting while also bordering on the absurd. *InformationWeek* reported last year that one payment processing company experienced more than one-third of its total yearly transaction dollars during the holidays. That’s a staggering statistic when you consider that it’s really only about a month in length. Is your company ready for four times its average traffic? If the answer is “maybe,” you aren’t alone. The fact is, no one really knows what to expect during the year’s biggest shopping season. Here is how to protect yourself: ### 1. The human element Forget the computers for a moment. Needless to say, companies cannot run themselves. Create an action plan for your company, so you know what happens when any potential overflows occur. The last thing you want is not to fulfill transactions and make new customers happy because you have too many orders coming in. Make sure that proper communication channels are established between any IT people you have on staff, your [web hosting company](https://www.atlantic.net/), and the company behind your e-commerce software, as applicable. You need to be able to act quickly and, above all, to know what’s going on in real-time. Figure out whose responsibility it is to monitor which systems. Also, consider a blanket approval of certain actions, such as allowing your e-commerce company to interact with the web hosting company on your behalf. All departments and parties also need to be aware of the timing and nature of any promotional efforts. ### 2. Be careful, be very careful… But don’t be too careful Scammers do big business during the holidays as well, so security is of special concern. Look into adding malware protections, and consider purchasing an Extended Validation SSL certificate. These two tools both protect you from illicit activity and provide additional degrees of assurance to potential customers. The Extended Validation SSL, for instance, turns the address bar green. That may sound ridiculous from an IT perspective. Still, it’s an impressive indicator to customers that they are on a legitimate site (not one created by a phishing imposter), and it’s okay to move forward with their purchase. Now, be aware that you also don’t want to go too far. *InformationWeek* references a KEMP Technologies executive, Jon Braunhut, who emphasizes that distributed denial of service (DDoS) protection should be reconsidered. DDoS safeguards can prove too extreme on Black Friday because they are based on preventing unexpected, sudden increases in traffic – which is exactly what you want to happen during the holiday shopping blitz. ### 3. Don’t go it alone Maybe you would prefer to go it alone and the weather the incoming traffic yourself. However, it’s worth considering that managed services from a hosting provider or another third party might be useful for the holidays. E-commerce Times make that [recommendation especially for SMBs](http://www.ecommercetimes.com/story/31644.html), noting that good hosting companies have thorough understandings of handling the bursts of traffic that are common toward the end of the year. ## What hosting packages make the most sense In the past, the amounts of resources (storage, memory, bandwidth, etc.) available within hosting packages were not exactly set in stone, but they weren’t straightforward to adjust either. Cloud hosting has changed all of that. Basically, rather than thinking about how much room you have on a particular server, the cloud approach allows you access to several different servers. It’s not exactly limitless, but you won’t hit the ceiling for most situations. Managed hosting makes the situation even easier. You essentially have an IT team on hand 24/7, alerted of any issues and resolving them as quickly as possible. That said, businesses have to operate on budgets and be conscientious with every dollar they spend. Whatever Black Friday traffic solutions you choose, we at Atlantic.Net hope that your season is bright and that our [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions are your first choice for reliable peak load server reliability.  See our [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # Add 2-Factor Authentication to Your Website > URL: https://www.atlantic.net/hipaa-compliant-wordpress-hosting/adding-2-factor-authentication-site/ | Published: 2013-11-15 | Updated: 2024-11-09 | Author: Sam Guiliano A great way to increase the security of your site is to deploy  two-factor authentication. Of course, you want to have complex passwords because it makes it difficult for someone to guess the correct login credentials. However, today, hackers have a number of different ways in which to locate the passwords, [including the following:](https://www.twilio.com/blog/2013/04/add-two-factor-authentication-to-your-website-with-google-authenticator-and-twilio-sms.html) 1. on a PC that has been stolen or discarded 2. on other sites, if an identical password is used there 3. via key-logging malware installed on the PC. ## SSL & encryption In addition to passwords, to heighten your security, you can install SSL certificates on your server and use other forms of encryption, such as the Point-to-Point Tunneling Protocol (PPTP) used for remote access to  virtual private networks (VPNs). A simple way to target the login process specifically, though, is to add an additional step, another “factor.” This method – two-factor authentication, or TFA – is now [available and recommended](http://www.pcworld.com/article/2036252/how-to-set-up-two-factor-authentication-for-facebook-google-microsoft-and-more.html) for accounts with Google, Microsoft, Facebook, and others. With two-factor authentication, in addition to inputting a username and password, another piece of login information is required. The most common way to utilize TFA is with temporary codes sent to the user’s cell phone. That obviously makes intrusion into the account significantly more difficult, avoiding data theft and possible lawsuits. ## Setting up two-factor authentication for internal server logins You can establish TFA for a variety of your own internal credentials and also for your customers’ accounts. Here are options [to enable a second factor](http://www.techmagz.com/securing-your-website-using-two-factor-authentication-how-why-you-should-do-it/) for your website’s administrators and content managers on various systems. Bear in mind before setting up any of these solutions that you will need all those who add content to your site or manage it to be prepared for the new system. ### Two-factor authentication by CMS *WordPress* – If you use WordPress for your content management system (CMS), setting up TFA is incredibly simple. [There is a plug-in](http://wordpress.org/plugins/google-authenticator/) called Google Authenticator Application. Obviously, it was coded by a powerhouse tech company. All you need to do is install the plug-in. Keep in mind, you want all mobile devices of users to have the Google Authenticator app installed as well. However, the most important thing is having correct phone numbers. If the app is not installed correctly, it is possible to receive the temporary codes via text message or automated phone call from Google. *Joomla!* – If you use Joomla! for your CMS, you have a number of [different extension options](http://extensions.joomla.org/extensions/access-a-security/site-security/login-protection/24822). Because Joomla! is organized similarly to WordPress [cloud hosting](https://www.atlantic.net/vps-hosting/), it’s the same basic process to get TFA up and running. *Drupal* – Finally regarding CMS logins, developers have [created various modules](https://drupal.org/node/28032) for Drupal as well. Be sure to check the reviews for modules to ensure that you don’t run into any issues, which of course could be a major setback for your business. *cPanel/Plesk* – Typically you will have the option within your hosting account CP to set up TFA as well. Much of the time, the authentication program that is available is the Google system. Again, make sure you are fully prepared for this change as adding a level of security makes it more difficult for legitimate users to access their accounts as well. ## Setting up TFA for customer accounts For two-factor authentication of customer accounts, you have two basic options: 1. Paid solution – You can use heavy-duty TFA programs created by organizations [specializing in security](http://www.symantec.com/verisign/vip-authentication-service), such as Symantec. With any enterprise application you choose for your customers, you have the option to make two-factor mandatory or optional. Google and Facebook, for instance, allow users to decide for themselves. Depending on how sensitive the data is on your site, you may want to consider making it a necessary part of getting into accounts. Just as with preparing those within your own company for TFA, you want your customers to be notified in every possible way. You also want simple but thorough documentation and easy support access if anyone has trouble. 2. *Develop your own system* – If you work with developers or have them on staff, you may want to consider developing your own system. Potentially this option could be less expensive over time, and you can design exactly as desired. If you do go with the a paid or customized high-grade solution, the advantages are the following: 1. TFA can be *implemented for everyone* – customers, site administrators, and all employees. 2. You have a *greater degree of options* so you can figure out exactly how you want the two-factor authentication system to work for various scenarios. Perhaps two-factor authentication logins are more important to you when users are accessing specific areas of the site. Obviously, your degree of control over the TFA program is particularly enhanced when you develop it yourself. *** Using TFA is wise, but it isn’t everything. At Atlantic.net, we also recommend these best practices for e-commerce security, many of which have broader implications for any type of websites including those that are using Atlantic.Net’s secure [HIPAA compliant WordPress hosting](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/) solutions. --- # What to look for in a Cloud Hosting Provider > URL: https://www.atlantic.net/vps-hosting/cloud-hosting-provider/ | Published: 2013-11-18 | Updated: 2024-11-14 | Author: Kent Roberts Cloud server hosting is a topic that is not easy to evaluate as a consumer. When you attempt to look into how to compare one cloud server hosting provider to another, it’s challenging to determine what parameters you should be reviewing. All in all, finding the right cloud server hosting provider is about knowing the right questions to ask. A solid hosting company that specializes in the cloud will not hesitate to provide you with the answers. The cloud, like any vague business concept, can be a dangerous terrain to explore without a reasonable amount of knowledge. With a firm understanding of how the cloud operates, though, you can find the correct solution for your company. ## What Is “the Cloud” or “Cloud Hosting?” As its name suggests, *the cloud* is a virtual concept. Any form of cloud computing with a cloud server involves removing physical objects – on the server side – from the computing equation. Rather than relying on one server that is delivering data, or even a traditional cluster of servers responsible for the same task, the cloud is a digital framework that disperses the storage and transmission of data across a broad set of machines. In the data center of a cloud server hosting provider, a pool of servers, rather than one server (dedicated) or a part of a server (shared), is responsible for both storage and processing, performing – in the latter role – as the central processing unit (CPU) does [in a single computer](http://www.hongkiat.com/blog/cloud-hosting-how-does-it-work/). All of the website’s files are stored in several different hard drives. A large cluster of servers allows cloud computing to have much higher limits; limits still exist but become irrelevant in most cases. The basic underpinnings of cloud hosting, for that reason, allow for incredible scalability. ## Cloud & Internet Similarities The cloud is not the Internet, but it certainly [takes a page from its playbook](http://en.wikipedia.org/wiki/Cloud_computing). You can think of the Internet as one massive cloud and a cloud server hosting provider as a small chunk of that ecosystem. The difference between the public and private cloud follows a similar line of thinking. The Internet is public for the most part, but you run into private situations. The same is true in everyday life. You have to pay to go in certain doors before entry and have codes to access gated communities. That is true on some websites as well. Public and private cloud versions are modeled in the same general way, with private clouds chosen by those who need higher security and customization features. ## Specific Elements of a Cloud Hosting Provider Here are several aspects of a cloud server hosting situation to better [understand how it works](http://www.webhostingsecretrevealed.net/blog/web-hosting-guides/a-brief-on-cloud-hosting/): 1. *Dynamic IT structure* – The structure of a cloud is dynamic or highly flexible. It is built in a fluid way that optimizes access to resources. Previously, relationships within a network were much more rigid. Accessing a plethora of virtual machines, a cloud hosting provider can put specific physical hardware into use without being confined to the individual limitations of each device. 2. *Specificity* – Cloud computing also is built around delivering a specific application or site to users in the best possible manner. Previous models of computing were centered on services or systems in a broad sense. On the other hand, a cloud hosting provider uses an infrastructure that optimizes the connection possibilities between one site or app and its audience. 3. *Freedom of management* – Control within a cloud server hosting environment is versatile. It’s easy to spread out responsibilities and to automate whatever tasks can be left relatively unattended. Automated features minimize the labor needs for the administration of the website environment. 4. *Pay to play* – Anytime you take out a cell phone contract, it can be confusing to figure out parameters, such as the size of the data plan you need. With a cloud hosting provider, you pay for what you use. In this sense, cloud hosting returns to a traditional model, much like the per-minute billing of home landlines. 5. *Built to scale* – A cloud server hosting provider has an architecture that is optimized for scale. When your business grows, you don’t need to add servers. You click a button in your admin panel. It’s also possible to understand your resource needs within one system and calculate over the time span you choose. 6. *Resource aggregation* – The resources of a cloud hosting provider, at least as far as its public cloud goes, are a single unit accessible to its entire community. Resources are interchangeable so that when one site hits peak load, it doesn’t drop offline; the same goes for all the other sites. *** The cloud may be a bit obtuse, but it is changing the landscape of the Internet, and Atlantic.Net is on the front lines of this growing industry of cloud server hosting solutions. We also offer [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions.  See our [VPS hosting pricing](https://www.atlantic.net/vps-hosting/pricing/). By Kent Roberts --- # What is Operating Systems Management? > URL: https://www.atlantic.net/vps-hosting/operating-systems-management/ | Published: 2013-11-20 | Updated: 2026-01-09 | Author: Sam Guiliano As we all know, information technology is a vast field with many different facets. Staying abreast of all pertinent information and prioritizing all aspects appropriately is a tall order. Often, enterprises and SMBs find that certain tasks are better handled by an outside entity specializing in specific aspects of tech and have the tools available to quickly and accurately diagnose and solve problems. Even if a company has an IT specialist, that person is sometimes so busy handling day-to-day needs that broader issues, such as network maintenance and security, cannot be given the focus they deserve. Hosting companies often provide various managed services to fit these situations. Operating systems management, aka managed OS, is one such service. OS management allows an organization to stay current on patches, upgrades, and other OS elements while keeping its own in-house IT professionals free to handle tasks specific to the operation of the business. Below are several of the standard activities involved in business OS management. ## **Patch management** Patch management is a core component of systems management. It involves locating or creating the best possible code – which is then used as a patch for a specific part of the site – to generally increase [usability and efficiency](http://www.wisegeek.com/what-is-patch-management.htm). A particularly crucial part of patch management is the testing phase. Still, it’s just as important to monitor the site following the patch to determine if it works completely as intended (an aspect of configuration management, as described below). A couple of other core concerns are involved with patch management as well. One is continuing education: an administrator should be an expert on all patches and elements of code throughout the system. Expertise is necessary to prevent any patches – a new one and one applied months ago – from conflicting. Needless to say, patch management also involves careful installation. If the code is placed at the wrong point in the string, severe headaches and lost business can result. A skilled patch manager is extraordinarily conscientious about placing the patch in the precise location used when conducting tests. ## **Configuration Management** Configuration management, broadly speaking, refers to the deployment and maintenance of software or hardware so that everything functions cohesively and uniformly throughout the infrastructure. The hardware and software applications of the term involve different practices but [are identical in theory](http://www.wisegeek.com/what-is-configuration-management.htm). Each aims for an organized and coherent setup of all elements of a computing system. Configuration management for a business’s OS means that when changes occur, [monitoring must follow](http://serverfault.com/questions/12415/what-configuration-items-do-you-track-for-proper-configuration-management). All aspects of configuration should be stored and easily accessible in a repository, with an individual or team who has a full understanding of its contents. Examples of configuration changes include the following: - Deployment of patches - Application installation - New users or changes to user accounts/permissions - Any maintenance elements. Proper monitoring of systems configuration involves automated applications that present any adjustments as they occur. The repository mentioned above allows the manager to see any adjustments that have occurred over time to various system elements. ## **Proactive monitoring** [Proactive monitoring](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/) is again a broad IT term, with specific concerns for each subfield of computing. It is the responsibility of the engineers performing the monitoring to locate and fix any possible issues at all hours of the day or night. Proactive monitoring ensures that the system is operating smoothly, efficiently, and without any errors. Using applications that track data on the network, an individual proactively monitoring a system both reduces risk and develops insight into the performance that can be used to [further bolster the infrastructure](http://smallbusiness.chron.com/proactive-monitoring-73438.html). Essentially, proactive monitoring is a form of surveillance across the entire operating system that – true to its name – solves problems before they have time to develop. It enables businesses to stay a step ahead of risk and protects sensitive data from corruption. ## **Infrastructure lifecycle management** In business, as in life, everything has a lifecycle. The goal of infrastructure lifecycle management, when managing the OS for your business, is to make sure that all aspects of the infrastructure are both in line with the goals of the business and allow appropriate degrees of protection. Management of the infrastructure’s lifecycle – both regarding its pieces and its entirety – is primarily a function of monitoring, much like the other managed services described above. Proper infrastructure lifecycle management is not just about getting rid of old machines and buying new ones. Optimization of the infrastructure and the security of all data it contains are core aspects of lifecycle management. If you need to destroy data that is no longer of use and do not want it to get into the wrong hands, engineers handling lifecycle management can also help. *** Managed services become especially of interest to many organizations as the holidays approach, which can often entail a tripling or even more dramatic impact on traffic. Atlantic.Net understands a reliable cloud server’s value and offers the best technical support and one-click cloud-hosted applications.   Why not spin up one of the industry-best [VPS hosting](https://www.atlantic.net/vps-hosting/) plans today.   It will only take 30 seconds to launch the cloud!  See our [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How Next Generation Data Centers Can Help Solve Healthcare Compliance Issues > URL: https://www.atlantic.net/hipaa-data-centers/solving-hipaa-hitech-ssae16-server-compliance-issues-generation-datacenters/ | Published: 2013-12-04 | Updated: 2025-03-06 | Author: Alexander Wise HIPAA stands for Health Insurance Portability and Accountability Act, and HITECH stands for Health Information Technology for Economic and Clinical Health Act. Both acts have to do with how health records and data are handled. SSAE 18 is similar. It’s an accounting standard created by the Auditing Standards Board (ASB) of the American Institute of Certified Public Accountants (AICPA). The parameters of all three have enormous implications both for healthcare and for web hosting. Dedicated server and managed hosting services that use next-generation data centers must ensure that they can meet the requirements as outlined in the compliance requirements of each one of them. ## Start with a Compliant Data Center It is important to ensure that you are using a data center that will comply with the standards of HIPAA, HITECH, and SSAE 18 (formerly SSAE 16). When discussing your needs with a data center, such as Atlantic.Net, you should confirm that the data centers conform to the standard contingency plan, data backup plan, disaster recovery plan; emergency mode operation plan, testing and revision procedures, and applications; and data criticality analysis. Data servers have their own compliance requirements when managing your [HIPAA database](https://www.atlantic.net/hipaa-compliant-hosting/), and you need to ensure that their performance standards can match up with your compliance requirements. Achieving SSAE 18 Type II Certification to ensure that SSAE 18 will not present a problem for the server in the current time or immediate future is important. If you are in healthcare, you are probably familiar with the increasing demand for server and data center compliance. The new generation of [HIPAA data centers](https://www.atlantic.net/hipaa-data-centers/) has helped to pave the way for many healthcare IT companies that needed to find a rock-solid solution for their businesses’ hosting solution needs. HIPAA was designed to provide better access to health insurance, reduce fraud and abuse, and lower the cost of obtaining health care in the USA. HITECH further reinforces the HIPAA regulations and provides some additional rules for you to follow. The data center you choose should help make the transition to become a fully compliant business, at least through your online presence. This may raise a few eyebrows, and some people are even a bit nervous about whether or not their business can meet the demand in time for compliance testing. With the proper structure completed ahead of time, the hard part is done; all you need to do is plug into the tools and features available for you to use. ## What Do HIPAA, SSAE 18, and HITECH Compliance in Hosting Require? Being HIPAA, SSAE 18, and HITECH compliant means going the extra mile in server colocation, delivering dedicated servers, managed server hosting, and compliance through a credible data center. A data center must be reliable, with certified and trained staff who know how to handle customer problems and inquiries. HIPAA, HITECH, and SSAE 18 compliant are vital in today’s environment, and everyone is fully aware of the legal boundaries in which healthcare organizations must operate. More efficient cooling procedures ensure that the compliance sequences are followed without a possibility for failure. Dynamic allocation of resources where they are needed helps solve many resource issues. Additionally, the resources are used in the coolest parts of the data center, meaning more efficient use of the resources. Optimizing application performance is one of the main advancements that next-generation data centers do incredibly well. These next-generation data centers brought into operation have data security as one of their incredible strong points. The new healthcare reform mandates implement even tighter security with HITECH, and service providers have vested large amounts in these regulations. Ample controls and checks/balances will be ensured for obvious reasons to help the patients and healthcare providers. The government understands that companies need to be encouraged to take things to the next level, and as a result, there are tax incentives to deploy EMR/EHR (Electronic Medical Records and Electronic Health Records). Using cloud servers, you can scale up and scale out according to what your business needs. Even more so, quality data centers can keep your healthcare organization safe! Using virtualization, companies have dedicated themselves to the continued success of your business. This means they have left no stone unturned to bring you an unprecedented level of services from which you can choose. Being HIPAA compliant is partly the job of the hosting company and partly yours as well. They provide you with the services – the data center, the managed hosting, and the tech support to ensure you have what you need to bring your healthcare business to the compliance level. They can only offer you the required services by the HIPAA, HITECH, and SSAE 18 regulations. They need your help to make sure both parties are up to speed in the quest to keep your business in complete compliance. Cloud computing is a huge part of next-generation data centers. Virtualization technology has made it possible for everyone to have their resources delivered at the most optimum moment through more efficient handling of server resources. If you are new to cloud computing, you should know that this technology in no way endangers your ability to stay HIPAA, HITECH, and SSAE 18 compliant. Cloud computing is simply the new way of handling server requests and scaling additional resources up and out. Have you ever stopped to consider what would happen if you were tagged with a violation of the HIPAA, HITECH, or SSAE 18 compliance standards? It would be a catastrophic blow to your business that would land you in court! Additionally, the people affected by the violation could sue for damages. SSAE 18 web hosting services are now structured around ensuring that everything in the facility is certified to the new standards of operation. Being in business for over 15 years, since 1994, has given us a chance to really perfect the art of cloud hosting, server virtualization, data security, compliance, and the ability to provide a carrier-neutral data center. ## HIPAA Compliant Hosting with Atlantic.Net Atlantic.Net and other serious hosting companies have been a step ahead of the compliance standards from day one. Business expertise has allowed us to keep the [healthcare IT](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/) businesses that we already have under our wing and ahead of the flames. We can help your business stay in line with these compliance standards as well. All in all, [HIPAA web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) server issues won’t be much of a big deal once you realize what they are all about. The compliance issues would generally arise from a data center not having sufficient hardware or software to accommodate regulatory compliance. The customer may not be able to get the business into a state of compliance by themself. Either way, a next-generation data center must offer the services in demand to meet the compliance requirements to be compliant with the regulations themselves. --- # Cloud Hosting Providers: A Comparison Chart > URL: https://www.atlantic.net/hipaa-compliant-hosting/cloud-hosting-providers-comparison-chart/ | Published: 2013-12-23 | Updated: 2024-10-22 | Author: Kent Roberts One of the most difficult things for companies is figuring out which hosting provider to choose because there are so many different factors to consider. They may know they want cloud server hosting, but exploring different services can sometimes get complicated and confusing. Comparison charts allow a simple, side-by-side view of various parameters offered by several different companies so that you can easily determine what you are getting for the price. Let’s look at basic features for three of the most prominent cloud server hosting providers (CHPs), along with [Atlantic.Net](https://www.atlantic.net). (Note that our “Medium” cloud hosting package at Atlantic.Net is one of the options listed, but all information is current to the best of our knowledge, obtained through third-party comparison pages and the sites of the hosting companies themselves.) ## Basic Cloud Server Hosting Provider Features – Chart & Explanation The below comparison chart gives basic parameters for each of the three major cloud hosting providers. (Note the 24/7 support described in the chart below to understand the prices within that row better.) Not everything is included here for the sake of efficiency, but you will find these patterns hold true, in a general sense, for other features as well. | | **Atlantic.Net** | **Linode** | **Amazon Web Services** | **Rackspace** | | --- | --- | --- | --- | --- | | **Monthly Price** | $19.94 (Lin.)$29.94 (Win.) | $40 | $43.20 | $58.40 | | **RAM** | 2 GB | 2 GB | 1.7 GB | 2 GB | | **Disk Space** | 80 GB | 96 GB | 160 GB | 80 GB | | **Billing Timeframe** | Per Second | Per Hour | Per Hour | Per Hour | | **24/7 Support** | Free | Free | $100 | Free | ## Understanding Feature Comparisons The above gives you an idea of how the top hosting services compare price, memory (RAM), bandwidth, disk space, billing timeframe, and 24/7 support. Now let’s analyze each feature separately before looking directly at comparison costs for the amount of RAM and disk space available: - *Monthly price* – The price obviously covers a broad range, from $19.94 to $87.60. It helps to know upfront what the monthly charge will be for each of these services. However, the resources are what’s really important. Each of these cloud server hosting providers offers different prices for different sizes of accounts. In this chart, RAM serves as the stabilizing feature to compare the same basic type of account. - *RAM* – As stated above, this feature is just about even. Obviously, there is a little discrepancy, but all the hosting services are right around the 2 GB mark for these specific solutions. Disk Space – Two of the hosting solutions stand out in this category, with significantly more disk space than the other two companies offer. - *Billing Timeframe* – Most cloud server hosting providers contain language on their sites explaining that you will be billed for the full hour for each partial “instance-hour” during which you consume a resource. In other words, if you need more during the hour, you pay for those resources for the entire hour, whether you need them or not. The problem for customers regarding the pricing with that policy is that there is a lot of “rounding up” involved on an hour-by-hour basis. A company that bills for each second does not bill for the full hour based on the highest amount of resource use. - *24/7 Support* – Typically, people want support questions answered almost immediately. Because the support team is available 24/7 at Atlantic.Net for free and immediate assistance, the prices for support listed for the other hosting packages are for personal customer support that is available right away. ## Comparing Features & Rates What really gets helpful here to better gauge price is to look at the amount you will be paying for certain amounts of RAM and disk space on a couple of the different plans. Since Atlantic.Net is obviously at the low-end on price but also has high resource figures, we will use it as the basis for comparison for a couple of “what-if” scenarios. At the $43.20 rate offered by Amazon Web Services, how much would you be paying if the RAM were to be equivalent to that offered by Atlantic.Net (2 GB rather than 1.7 GB)? To get the same amount of RAM Atlantic.Net provides from AWS offered at their per-gigabyte rate, you’d have to pay $52.04 each month (all other factors remaining equal). That allows a clear comparison between the prices and parameters of the two cloud server hosting providers. At the $58.40 rate offered by Rackspace, how much would you have to pay to get disk space that equals what is offered in the Atlantic.Net plan (80 GB rather than 80 GB)? To get the same amount of disk space from Rackspace as Atlantic.Net offers at Rackspace’s price for each gigabyte in its plan, your cost would be $116.80 (all else remaining equal). Again, comparing in this way gives a better sense of the true difference between prices for the two solutions. ## Conclusion The important thing when you choose a cloud hosting provider is to know exactly what you’re getting. For example, you might get a little irritated if you sign up for an account with a big-name cloud service and then realize you will have to pay $1200 per year to get the 24/7 support offered standardly with many hosting services. As you can generally see from the above, Atlantic.Net has worked hard to develop extremely competitive cloud servers at a cost-effective level for any business – including businesses that must operate with [HIPAA compliance.](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) By Kent Roberts Cloud server hosting is just one of four services offered by Atlantic.Net – we also offer managed, dedicated, and [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. --- # VPS Hosting Providers: Comparison Chart > URL: https://www.atlantic.net/vps-hosting/vps-hosting-providers-comparison-chart-comic/ | Published: 2014-01-07 | Updated: 2024-11-14 | Author: Kent Roberts Many companies are transitioning from dedicated servers to virtual private servers (VPSs) to take advantage of advances in virtualization technology. VPS software allows servers to be created and configured from a single or multiple machines. In other words, you can either divide one server up into several different virtual servers (standard VPS), or you can combine parts of numerous servers to create the virtual machine (cloud hosting VPS). ## How Do You Choose the Best VPS Hosting? Finding the best VPS hosting providers can be challenging because there are so many different features and benefits to explore – and of course, every company says its solution is best. Some companies build their services specifically on outdoing the competition “by the numbers,” which is particularly common in IT and other quantitative fields: decision-makers want to be able to look at the data and compare it. For those in the field of information, the numbers really do often speak for themselves. *(Note that this piece covers much of the same ground as our article on cloud hosting providers or CHPs. The largest companies providing cloud hosting are also the largest VPS hosting providers, and any cloud server package is by default a VPS package. Although not every VPS is cloud-based, VPSs at most major companies are in the cloud. It’s also possible to use a private rather than public cloud for added security.)* ## Basic Features of VPS Hosting Providers – Chart & Discussion Let’s take a look at the parameters for a similarly sized account at the largest VPS hosting providers, alongside the one offered by Atlantic.Net. Although we include our own service here, everything listed is accurate and up-to-date as far as our research of each company’s website could reveal. Though the chart is not exhaustive regarding VPS account parameters, the general trends indicated by the categories listed are largely applicable to the full spectrum of hosting features. *(The “24/7 Support” column requires further clarification, which you can find in the discussion of that feature below the chart.)* | | **Atlantic.Net** | **Linode** | **Amazon Web Services** | **Rackspace** | | --- | --- | --- | --- | --- | | **Price Per Month** | $19.94 (Lin.)$29.94 (Win.) | $40 | $43.20 | $58.40 | | **Memory (RAM)** | 2 GB | 2 GB | 1.7 GB | 2 GB | | **Disk Space** | 80 GB | 96 GB | 160 GB | 80 GB | | **Billing Rate Adjustments** | Per Second | Per Hour | Per Hour | Per Hour | | **24/7 Support** | Free | Free | $100 | Free | This chart shows you how the most well-known VPS hosting providers match up in the areas of price (base per month), memory, storage limits, the frequency with which billing rates are updated, and availability of 24/7 support. Let’s look at each row independently and then specifically review RAM, storage room (disk space), and total annual costs: - *Price per month* – Prices of these VPS hosting providers vary considerably, with the costliest option 193% more expensive than the most affordable one.  The Price comparison is helpful, but resources provide a much clearer picture of the VPS. - *RAM* – Since providers have different sizes of virtual servers based on client needs, one factor must be held fairly constant for comparison. RAM, as you can see, serves that purpose, with all plans at approximately 2 GB. - *Disk space* – This category is essentially a 50/50 divide, with two plans offering 67-100% more than the other two. - *Billing rate adjustments* – VPS hosting providers typically will often charge you for what’s called instance-hours dependent on your highest level of need. In other words, you are charged at the rate based on your greatest resource use during each hour. Changing your billing rate more often – such as each second –reduces your costs significantly because your rate can drop throughout each hour when your resource demand is lower. - [*24/7 support*](https://www.atlantic.net/support/) – We all want our questions answered by support staff ASAP. Technicians at three of the above services are accessible to customers at all times. The $100 charge for one plan is to get questions answered within an hour. ## Comparing VPS Hosting Scenarios To get a clearer direct comparison between these services, we can create hypothetical scenarios to tell us what costs would be to bump resources of one plan up to the amount offered by another plan. Atlantic.Net provides a good source of comparison here because, relatively, the price is low, and the resource caps are high. ### To get the same RAM as the Atlantic.Net package (boosting it from 1.7 GB to 2 GB), how much would that raise the Amazon Web Services price? Holding everything else constant, if you wanted the equivalent memory to the Atlantic.Net offering, your monthly cost would rise to $52.04. ### To get the same disk space as the Atlantic.Net package, how much would that raise the Rackspace price? Holding everything else constant, if you wanted equivalent storage room to the Atlantic.Net offering, your monthly cost would rise to $116.80. When assessing various VPS hosting providers, you want to know upfront what the size and specifications of the virtual server are. Support is probably the best example in the chart above. If you switched to the company that charges for its support from one that offers it for free, that could be extraordinarily frustrating. As the above analysis demonstrates, Atlantic.Net designates substantial resources to its clients at rates affordable for businesses of all sizes.  Our award-winning cloud hosting solutions are complemented by offering the most popular one-click applications like [WordPress VPS Hosting](https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/) and cPanel Cloud Hosting. Atlantic.Net also offers [VPS hosting](https://www.atlantic.net/vps-hosting/) services. ![web hosting surprise comic, vps hosting](https://www.atlantic.net/wp-content/uploads/2014/01/Comic-Strips-Atlantic-9-001.jpg) Article by Kent Roberts; comic words by Kent Roberts & art by Leena Cruz. --- # Cloud Hosting Offers Unique Options For Real Time Applications > URL: https://www.atlantic.net/life-sciences-pharma-biotech/cloud-computing-application-forklift-weight-usage-data/ | Published: 2014-01-15 | Updated: 2024-11-09 | Author: Kent Roberts The speed and agility of cloud-based web hosting have changed the playing field in many industries, expanding the possibilities of technological applications. One obvious example is medical research. Phys.org reports that the growing cloud server hosting option is being used in genetic profiling research to allow for much faster and less costly analysis of DNA sequences. Wu Feng, a computer scientist at Virginia Tech, notes that data analysis generally has become more sophisticated because of the speed and scope of the cloud. Businesses are slowly beginning to grasp the vast potential of the cloud and how it might be applied for a competitive advantage in their industry. In a completely different corner from medical research, freight software and technology company Integrated Visual Data Technology, Inc. recently approached us about a cloud-based solution for their business. Let’s explore the nature of the business and how our hosting solution was effective. ## Weight analysis & employee monitoring Integrated Visual Data creates software and devices that log weight and other usage data for various freight-handling trucks: pallet trucks, lift trucks, and various kinds of tilt and level indicators. The machines allow information about the usage of the trucks to be monitored by operators and stored and accessed by management. ### How real-time weight data can help Weight data is helpful for general operational analysis and record-keeping, but the systems created by IVDT are useful in a completely different way. The company has an additional feature that can be added to any of its equipment as desired: an alert system for “rough vehicle handling.”  This system notifies management of the following parameters related to each lift truck: - excessive speed - overloads - extended periods of idling - windows during which the truck is underused - integration with scheduled break time In fact, Integrated Visual Data’s customers can add whatever parameters they want to capture and analyze. The company customizes the software so that individual business needs are met. ### About SkidWeigh SkidWeigh is the general umbrella name for IVDT’s product offerings. The system is based on an organized system of modules, which are basically packaged chunks of code that are easily moved in or out of a system (similar to a desktop application on a PC). Building the system based on modules makes tailoring the technology simple, and it also makes operating the system friendlier to the end-user. The SkidWeigh system is also apparently unique. According to Integrated Visual Data, its devices are the only ones that show the user of freight equipment a slew of information related to the material handling on a moment-by-moment basis. That same breadth and detail of information, plus additional analysis and notifications, is accessible to management. This feature allows those in supervisory positions to monitor forklift utilization at a distance, alerted of any problems in real-time. ## Crafting a cloud server hosting solution Integrated Visual Data contacted us in December to help make its data delivery more efficient and cost-effective. They wanted to use a cloud server to upload data from the forklift onboard weighing systems. Using the cloud would allow the end-user to access the data much more quickly. It also would allow real-time analysis to get more complex because slow load times (i.e., high latency) are much less of an issue with the cloud. Management would have access to all weight and usage information – including rough handling details – in real-time. IVDT asked for our input so that we could customize a solution based on the parameters they described. Integrated Visual Data has over 200 different algorithms for its technology, and it customizes its software regularly for customers. Our business has a similar approach to clients. We have a wide range of hosting plans with pre-established parameters, but we can also tailor infrastructures. In other words, it was a synergistic partnership because the two organizations held similarly adaptive philosophies. ## Public cloud vs. private cloud Cloud technology is itself highly adaptable. However, when businesses use cloud computing solutions – with what’s often thought of as “the cloud” – they are taking advantage of the public cloud. Just as traditional cloud servers are sections of one physical machine, the virtual machines of the cloud are made up of multiple sections of a variety of physical machines. In that scenario, many different businesses share the same servers, with the cloud technology keeping all of the server requests organized and distinct. Integrated Visual Data, due to the sensitive nature of its data, needed its own private cloud. The company required its own firewall and virtual private networks (VPNs). They wanted managed hosting services so that our team of security and efficiency experts could monitor their system and keep it running smoothly. The best option was a private virtual machine (VM), connecting multiple physical servers with cloud technology so that data computation and analysis could be as fast and complex as possible. IVDT is just one of the many companies that Atlantic.Net assists with custom private cloud hosting solutions every day.   At Atlantic.Net, we have been in business for 20 years and continue to grow because our technological focus is matched only by our customer focus. We also offer managed, [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) and [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. Contact us today! ![Cloud Computing Applications - Comic](https://www.atlantic.net/wp-content/uploads/2014/01/cloud-computing-application.jpg) By Kent Roberts; comic words by Kent Roberts & art by Leena Cruz. --- # cPanel Cloud Hosting – Why cPanel Is the Ideal Control Panel for the Cloud > URL: https://www.atlantic.net/hipaa-compliant-hosting/cpanel-ideal-cp-cloud-hosting/ | Published: 2014-01-20 | Updated: 2024-10-21 | Author: Sam Guiliano Per WebHosting.info, almost 2/3 of the world’s most prominent web hosting services used cPanel or WHM (with the latter, aka Web Host Manager, an integrated part of the same system) in 2011. .cpanel.net/hosting-providers. It’s a particularly common administrative panel for Linux servers, an open-source alternative to Windows, and the most common UNIX server OS (operating system). Linux hardware represented 21% of [server revenue in 2012](http://thejournal.com/articles/2012/06/05/linux-based-systems-lead-server-growth.aspx). Still, the OS actually is installed on a much larger share of machines: it’s freely available, and many companies download one of the many Linux distributions ([Ubuntu, Fedora, Mint Linux, etc.](http://www.zdnet.com/the-5-most-popular-linux-distributions-7000003183/)) independently. PC World reported in 2011 on the [scope of Linux](http://www.pcworld.com/article/238321/after_20_years_linux_looks_better_than_ever.html): - used by 3 out of every 4 global stock exchanges; - used by 19 out of every 20 supercomputers; - used by Facebook, Amazon, and Google for their infrastructures. Created in the 1990s to service Linux servers (originally those of the now out-of-business firm Speed Hosting by developer [John Nick Koston](http://en.wikipedia.org/wiki/CPanel)), cPanel is not just an option but the standard for managing any Linux server: “real” (physical) or virtual (whether a cloud server or a private server on a standalone piece of hardware). ## Why cPanel? As the world transitions away from physical servers toward cloud hosting machines, developers, designers, and resellers utilize cPanel to manage their open-source virtual cPanel environments. Here are 5 reasons why cPanel is such a great choice for the needs of a wide variety of web professionals and others who administer sites. (The basic framework below is courtesy of Blog Basics.) ### Popularity As described above, Linux is widely used, and Cpanel is, in turn, commonplace. For the same reason that WordPress is the most reasonable place to initially turn if considering a content management system (CMS) or MS Word if considering a word processor, cPanel is the mainstream option for a website or server control panel. It’s not just popular among individuals but among experts: as noted above, 3 out of every 5 major web hosts use the platform. ### Diversity/Simplicity Managing a website should not feel highly technical, whether using a cloud server or any server. cPanel offers a broad feature set and intuitive, user-friendly interface. Through a central hub, you can manage e-mail, organize and monitor databases, enter back-end components of the public-facing site, check analytic user stats, and perform a range of tasks geared toward the tech-savvy with specific management requirements. Additionally, it’s easy for a hosting company or independent user of cPanel to add modules accessible in the cPanel cloud hosting panel. Although the applications are not extensively vetted or certified by cPanel and require testing before deployment, functionalities can be expanded to fit the needs of cloud hosting clients and other users. Examples include the email marketing program [CakeMail](https://www.cakemail.com/) and the VoIP (voice over Internet protocol) application Siter. ### Control cPanel is a control panel, allowing you to control aspects of your site and/or server. Now, control is relative. An expert sysadmin (system administrator) might not want to use a control panel at all because it’s a layer with parameters in between them and the machine that can at times feel arbitrary or rigid. However, cPanel does offer a real control advantage: once you get used to the GUI (graphical user interface), you will not have to learn a new system if and when you switch to another web hosting company. Transferring your site to another cloud provider or any hosting service can be a stressful hassle, but if you are switching from one cPanel environment to another one, getting the site up and running will be familiar, and management with the new host will be virtually identical. ### Easy App Installation Not only are cPanel apps easy to find in the central catalog, but they are also easy to install. Typically a cloud service or hosting provider has several apps already available within cPanel. Generally, one of those applications itself – usually called Fantastico or Softaculous (Installatron is an alternative that is one of the top 5 rated programs in the app catalog) – helps you install any other app speedily and easily. Any of these script installer programs allow you to automatically install over a hundred open-source apps. It’s wise to know that you have an auto-installer available when needed. However, be careful with these installers when upgrading to a new app version. You can cause errors on your site and lose information if you aren’t backed up properly. User beware. ### Support Whether you are using a hosting service and have access to support or not, it’s good to know that you can quickly get the answers to many questions yourself. That’s the case with cPanel, another benefit of its widespread adoption. Google the problem, and you can find the answer to just about any question. If something comes up that you don’t see discussed anywhere, you can ask for help on a forum like [DaniWeb](http://www.daniweb.com/). ## Why Atlantic.Net? Finding a strong control panel that’s easy to use and adaptive is critical for online success. You also want to make sure that your cloud hosting service provides reliable and trusted servers to meet your every need.  Atlantic.Net offers a 100% uptime guarantee in our SLA, and we standardly customize our services to satisfy each of our individual clients. Cloud hosting is just one of four services Atlantic.Net offers – we also offer managed, [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/), and [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. ![Why cPanel is the ideal CP for cloud hosting. WordPress humor. ](https://www.atlantic.net/wp-content/uploads/2014/01/Comic-Strips-Atlantic-December-1-001.jpg) Comic words by Kent Roberts and art by Leena Cruz.   --- # Network Attached Storage (NAS) and Storage Area Networks (SAN) – What’s the Difference? > URL: https://www.atlantic.net/vps-hosting/nas-and-san-whats-the-difference/ | Published: 2014-01-22 | Updated: 2024-03-02 | Author: Sam Guiliano When two technologies have a similar function and a similar name, like NAS (network-attached storage) and SAN (storage area network), they can easily be confused. These common storage solutions connect with a network and store files and databases for machines in the network. Cloud server versions of the two perform the same function virtually rather than physically. Although the similarities between this pair of concepts are obvious, significant factors are separating them as well. We will discuss each storage framework in its basic (non-cloud) form to keep things simple below. ## NAS (network-attached storage) A NAS is, theoretically, incredibly simple. It comprises a hard drive or number of hard drives, an OS (operating system, typically Linux or Windows), and Ethernet connecting the hard drives to a network. A NAS has various benefits. A user or network administrator can share devices (such as printers), files and other data, and gigabytes of backup storage room using network-attached storage. *File sharing* – Let’s say you have NAS set up for your home computers, Computer A and Computer B. If you save a file to Computer A and have the NAS configured to save the file as well, you can access a folder within the NAS on Computer B and immediately have access to the most recent version of the file. Infrastructurally in this situation, the NAS is connected directly to the router so that each of your devices can access it. Like an external hard drive or thumb drive, adding and removing items from the NAS can be conducted manually as well by grabbing files and dragging them into and out of the network-attached storage folder. *Device sharing* – Many of us use a printer with a Wi-Fi connection, but sometimes we connect the device – let’s say a cell phone – to Computer A that we want available to Computer B. You can plug the cell phone directly into a NAS system such as GoFlex Home, and both Computer A and Computer B can connect directly to the cell phone to access photos, music, etc… *Backup storing* – No one wants to lose their files, and most of us have experienced a devastating computer crash. Backup on a consistent and regular basis is critical. Nonetheless, Greg Falgiano, a senior product marketing manager at the hard drive and storage company Seagate, notes that backing up our devices is “like flossing”: it’s something we know is essential but is easy to overlook. NAS makes the backup process consistent and predictable when it is configured to occur automatically. ## SAN (storage area network) A storage area network, as noted above, is virtually identical to network-attached storage functionally. The Storage Networking Industry Association (SNIA) defines a SAN as a network that facilitates the transmission of data between machines [used for storage and other devices](http://www.snia.org/education/storage_networking_primer/san/what_san). SNIA notes the finer points of how a SAN should be understood: - It is not necessarily limited to performing storage-related activities. A storage area network can respond to other user requests and serve additional system management duties as well. - A SAN does not necessarily have to be connected to other devices via Ethernet or Fibre Channel (FC). However, the latter is a standardized method used by many enterprises for their storage area networks. - The machines used for storage can be of various types, such as disk drives, file servers, or RAID subsystems. Innovation in the SAN field produces groundbreaking storage strategies and technologies, ideas, and products that arise from needs for the fastest, most reliable, and most affordable SAN possible. Not all of these concepts will become commonplace, but the most viable ones are enhancing options for the storage of data. ## Differences between a SAN & NAS system Here are a few direct distinctions between SAN and NAS technology, courtesy of Everything VM: 1. *OS perception of storage* – If the operating system on your computer perceives the storage framework as remote, typically network-attached storage is involved. Network drives in Microsoft Windows are examples of NAS, accessible to just one user and limited functionality. When a storage area network is accessed through Windows, on the other hand, Windows is unaware that the storage system is network-based. The SAN is perceived as if it were plugged directly into the computer, broadly accessible and capable of general drive functionalities. 2. *File-level versus block-level* – When using NAS, access is at the file level. You can ask the NAS for something by name, and it will retrieve it. SAN access, though, is at the block level. A specific location of a file must be identified, and this is performed in terms of blocks. The client asks for blocks 5111-5133, for example. All data stored on those blocks are then transmitted. 3. *The complexity of shared access* – Network-attached storage can easily be connected to more than one server, but performing the same setup for a storage area network is more complicated. This particular ease-of-use scenario is due to the file-level versus block-level difference. With a NAS sharing data at the file level, common issues such as checks for consistency and locks on files can be verified and resolved. Because SAN shares in terms of blocks, it leaves the OS responsible for specifics related to each block. That means file system configuration for a SAN must be completed carefully to avoid problems. As you can see, SAN and NAS technology are generally similar, but the systems are far from identical. It’s not always a matter of choosing which one is best. Many organizations use hybrids of the two or combinations of each for storage. Talk to Atlantic.Net’s specialists today if you have any questions about how to set up storage for your IT infrastructure. We offer a managed cloud hosting storage service that is state of the art. ![Difference Between NAS And SAN - Comic](https://www.atlantic.net/wp-content/uploads/2014/01/difference-between-nas-and-san.jpg) Comic words by Kent Roberts and art by Leena Cruz. Atlantic.Net offers [VPS hosting](https://www.atlantic.net/vps-hosting/) as well as [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/). Contact us today for more information. --- # Developing a Business Optimization Edge with Cloud Computing > URL: https://www.atlantic.net/pci-compliant-hosting/cloud-computing-business-optimization-developing-competitive-edge-improved-customer-engagement-faster-innovation-comic/ | Published: 2014-01-28 | Updated: 2026-03-01 | Author: Kent Roberts Let’s face it: the cloud is growing. Why is the cloud so hot in the technology world and the business world generally? And is it developing as strongly and quickly as we think? The term *cloud* is so widely used and frequently misunderstood – with 51% of people thinking the cloud is impacted by [changing weather patterns](http://www.businessinsider.com/people-think-stormy-weather-affects-cloud-computing-2012-8) – that it seems at times to resemble a fad. It is anything but. **Just how fast is the cloud growing?** The following statistics, courtesy of Cesar Orosco of NetApp, paint a clear picture of just how powerful cloud server hosting is becoming: - Technology market analyst IDC made an early prediction that 2013 public cloud technology spending would top $47 billion. It also suggested that three years from now, that same spending will exceed $107 billion, placing growth at 24%. The company predicts the general IT sector to grow at 1/5 that rate over the same period. - According to a 2013 survey conducted by [Gartner’s](https://www.gartner.com/en/newsroom) technology research firm, which surveyed more than 2000 CIOs on their top business and tech priorities, the third-highest IT priority for businesses was utilizing the cloud. Only intelligence/analytics and mobile capabilities ranked higher. Below, we will explore implications for two critical business growth and sustained success components: innovation and engagement. **The cloud & engaging customers** John Dillon describes several ways the cloud helps accelerate a business’s engagement with its customers. Put simply, the cloud is incredibly efficient. It is both cost-effective and reduces the time frames required for strong customer interaction. Dillon’s basic argument is that resources should be directed toward technological development to [enhance engagement with customers](http://www.forbes.com/sites/ciocentral/2012/07/16/how-to-use-the-cloud-to-improve-customer-engagement/2/) (a macroscopic approach) rather than focusing on more isolated engagement scenarios (a microscopic approach). He suggests that the cloud is built to meet the needs of organizations throughout all verticals, regardless of their size, with the following capacities: - *Boosted innovative potential to outpace rivals* One way in which the cloud is helpful is in its capacity to reduce the need for filtering. Many businesses suffer from a ballooning store of ideas generated by their creative team and their customers. The challenge, then, is not brainstorming but fast and inexpensive implementation so that ideas can be deployed and tested. There is less need for lengthy analysis about whether something is worth the expense. - *Incredibly fast scaling* You want scalability so that you don’t hit limitations if your idea is indeed a massive success. With the cloud, all you have to do is click a few buttons, and any limits that you have placed on your account rise to meet the incoming demand. - *Improves targeting of niche demographics* If you want to go after a small section of your general target audience, the cloud makes it possible to test your approach quickly and without a huge investment. To put it another way, the cloud can allow your users to be delivered a more personalized experience. Dillon provides the example of specifying a campaign toward young mothers. The cloud allows you to create a forum for them to share their ideas and engage with each other: test-marketing that is cost-effective to complete. **Accelerating innovation with the cloud** [In another article](http://www.forbes.com/sites/ciocentral/2012/04/30/how-you-can-use-the-cloud-for-rapid-fire-innovation/), Dillon references a couple of pieces of research that underscore how crucial innovation is for companies and how difficult it is to conduct. In 2010, McKinsey questioned business executives around the world on the topic and found that 84% of them cite innovation as a key factor for business success. Nonetheless, only 94% think that their organization’s strategies are working sufficiently. Here are ways cloud server hosting can sharpen a business’s innovative age: - *Independence* One of the typical problems with innovative maneuvering is that it can disrupt what is currently working for an organization. A cloud project can exist on its own. However, the cloud can be an offshoot of your business rather than the complete structure. - *Redefines relationships to innovation* Because change is difficult for many organizations, they don’t prioritize it. However, it becomes more difficult because there is no framework in place to organize projects geared toward novel adaptation because they don’t prioritize it. The cloud can serve as that framework, provided the company also creates goals and guidelines to accompany it. - *Refreshes the technological perspective* The IT staff of a business is often so focused on defense – blocking security threats and preventing bugs and other systemic breakdowns – that the offense never takes the field. If apps and innovation are transferred into cloud environments, the IT team can use that atmosphere to be proactive and score some points on your rivals. The cloud server hosting options are certainly growing quickly. The real question for each business is the extent to which they will be a part of that process. As seen above, there are strong and specific advantages of using a cloud server as a part of your infrastructure. Atlantic.Net can be your partner in the process. [VPS hosting](https://www.atlantic.net/vps-hosting/) is just one of many services Atlantic.Net offers – we also offer managed, dedicated, and [PCI compliant hosting](https://www.atlantic.net/pci-compliant-hosting/) solutions. Contact us today for a consultation. ![Developing a Business Optimization Edge with Cloud Computing - Comic](https://www.atlantic.net/wp-content/uploads/2014/01/Comic-Strips-Atlantic-6-001.jpg) By Kent Roberts; comic words by Kent Roberts, and art by Leena Cruz. --- # How Does a Load Balancer Work? What Is Load Balancing? > URL: https://www.atlantic.net/vps-hosting/how-does-load-balancing-work/ | Published: 2014-01-30 | Updated: 2024-10-21 | Author: Sam Guiliano Cloud structure that is built fundamentally to optimize the balance of loads on the individual devices that make up the cloud network. Load balancing methods have expanded and increased in sophistication tremendously since the advent of cloud computing. However, this piece is more of an introduction, so we will focus on the basic idea of load balancing and extrapolation into three sample types: *perceptive*, *fastest response time*, and *weighted round-robin*. Finally, we will get into a basic explanation of the primary load balancing challenge in a cloud environment: *heterogeneity*. ## What Is Load Balancing? Load balancing allows you to easily balance the amount of work performed on several different pieces of equipment or sections of hardware. Typically loads are balanced across many different servers or – within a single VPS – across its hard drives and CPUs. If you use more than one device or piece of software to accomplish load-balancing, that backup equipment will make your system more reliable via redundancy. Probably the most common way in which load-balancing is understood is to meaningfully separate the incoming requirements of Internet protocol (IP) visitors accessing a website or application. Load-balancing was invented and refined for various reasons: better performance and speed of each device, making under-utilization (failure to take advantage of the resources on each machine) less of a problem, and keeping individual machines from hitting their threshold and potentially starting to drop requests. Load-balancing is critical for a busy site or network when it’s difficult to know the amount of traffic accessing the servers. (You can see how this process relates to cloud computing and its focus on the wide distribution of resources and work.) ## **How Does a Load Balancer Work?** Usually, the structure of load-balancing involves multiple web servers. If one of them gets overstressed with too much of the overall load, the requests move to another machine to be fulfilled. You can see how this decreases latency – processing lag time – because you’re essentially turning a bunch of disparate servers into one big balanced whole, like a super server (but perhaps not quite as heroic). The load balancer determines which servers have the most capacity to handle incoming requests. The request for data comes in from the end-user to the router. (In some situations, the router itself functions as the load balancer; however, the router is not enough for a high-volume organization.) The request is sent from the router to the load balancer. The load balancer then forwards it to whichever device is most likely to fulfill the request fastest. That machine (server) sends the information to the load balancer, which is then transferred by the router back to the end-user. Another major function of load balancing is that it allows continued operations even in the event of problems which would otherwise be interruptions: routine maintenance or failures (note, however, that you do have the option of 100% uptime). If you have several servers powering your site or application and one of them breaks, your end-users will not know that has happened because they won’t experience a problem. Your backend solves the problem by sending the request out to another machine in your server farm. ## Global Server Load Balancing One type of broader load-balancing is called Global Server Load Balancing, or GSLB. With this strategy, the work is sent out to server farms in various regions of the world. Again, we see major similarities to the core concepts of cloud computing. ## Three Load Balancing Strategies Three types of load-balancing are Perceptive, Fastest Response Time, and Weighted Round Robin. The first method takes data from the past and the present to determine which device is the most likely to be available in the given situation. Obviously, “Perception” only works well if the algorithm is extremely sophisticated, and it’s always possible to run into problems because there’ll always be exceptions to the rule. Fastest Response Time is a real-time strategy. The load balancer basically pings each server to determine which one is performing at the highest level. It’s sort of like asking for a volunteer to handle the work. The Weighted Round Robin approach allows one server after another to perform the work, but it also “weights” each device according to its power. Again, you can see how the concept of *weighting* applies to cloud computing. ## Load Balancing: the Special Issue of Cloud Computing Load-balancing in a homogeneous environment is relatively simple because everything is standardized. The atmosphere is controlled, and the math is simple. The nature of heterogeneous architecture, which is typical of a cloud, makes load-balancing much more complicated. It gets more complicated because of the discrepancy between different devices: how healthy they are, how much capacity they have, and where they are located. Success with load balancing, whether you are using reliable [VPS hosting](https://www.atlantic.net/vps-hosting/) or not, is all about having a strong team of experts on your side, such as the certified engineers at Atlantic.Net. Contact us today for a consultation. For more information on load balancing, check out our article [What is Server Load Balancing? The Function of a Load Balancer](https://www.atlantic.net/vps-hosting/). ![What Is Load Balancing and how does it Really Work? - Comic](https://www.atlantic.net/wp-content/uploads/2014/01/Comic-Strips-Atlantic-8-001.jpg) Comic words by Kent Roberts and art by Leena Cruz. --- # Encryption for HIPAA Compliance: A Quick Primer > URL: https://www.atlantic.net/hipaa-compliant-hosting/encryption-for-hipaa-compliance/ | Published: 2014-01-31 | Updated: 2024-06-08 | Author: Sam Guiliano If you are an IT professional or otherwise know Internet standards, you are probably familiar with SSL (secure sockets layer) security certificates and the concept of encryption. Essentially, any encryption method scrambles data using an intricate codification system and decoding protocol. For example, in the case of SSL certificates, a public key is held by the server, and a private key is provided to each user. Let’s look specifically at how data encryption applies to protected health information (PHI), which, in a fundamental sense, means EHR/EMR (electronic health/medical records). Clearly, this type of data must be kept under digital “lock and key” due to its profoundly private nature. ## Is data encryption mandatory? As Donald F. Lee III of Algonquin Studios establishes, encryption is not necessary – technically – under the HIPAA Security Rule (the section that addresses encryption standards). Lee points out that the Rule does not state outright that data must be encrypted at any stage of the process. Both of the subsections that address encryption specifications (each contained in the Technical Safeguards section of the Security Rule) list the encryption recommendations as “Addressable” rather than “Required.” Regardless of Lee’s initial argument, he points out that Health & Human Services clarifies on the Frequently Asked Questions (FAQ) section of their site that lack of encryption would necessitate a sound explanation. Since it would be challenging to argue that data should not be encrypted for its protection, Lee makes clear his central thesis: *Yes, you do need to encrypt, even if the Security Rule is somewhat confusing in this regard.* ## What HIPAA itself states regarding encryption parameters HHS describes acceptable methods for protecting unsecured data in its advice to comply with the Breach Notification Rule. The guidance lists two different ways to protect data: encryption and destruction. Since the general concern of those with PHI is creating a secure environment for data currently being stored or processed, encryption is the relevant method. HHS, citing the Security Rule, notes that encryption is described as a process to change data into a different state. It is highly unlikely that it can be understood without the applicable decryption tool. HHS also points out that whatever is being used to decrypt the data must be on a separate machine or somewhere off-site. The stipulations for [HIPAA database](https://www.atlantic.net/hipaa-compliant-hosting/) storage and data transmission are both subject to the specifications of the National Institute of Standards and Technology (NIST). ## Specific suggestions for encryption You may have heard across-the-board suggestions such as, “Don’t store or process any PHI on a laptop.” According to Mike Semel of 4Medapproved, that’s not necessarily the case. It would be best if you had proper protection. Semel suggests that you can either encrypt files individually or do the entire hard drive as a whole. To do the latter, you can use software that automatically encrypts all the data on the drive, called full disk encryption (FDE). Specifically, Semel recommends using an encryption program on a laptop with a solid-state drive (SSD). You can convert an existing laptop to solid-state for this purpose. He notes that even if the computer were stolen, you still would not be in violation because the new owner would not be able to access the data. He also specifically suggests setting up a virtual private network (VPN) to access the data remotely so that the Internet connection is not vulnerable. He points out that even if someone can see the data passing back-and-forth on the VPN, none of it will be in a recognizable form. ## Mobile devices vs. servers Any mobile device, including a laptop, needs to be encrypted. Specific issues with this “client-side” of HIPAA infractions are critical and have received significant focus from the HHS. The other place where you may have an issue is the server-side. That may seem obvious to you, but Lee believes that mobile encryption is more widely applied than is server encryption. For the most part, HIPAA breaches have occurred because a computer has been stolen that did not have the data properly encrypted. Hacking (commonly considered a true “data breach”) has not been as common as a threat. Unfortunately, more widespread hacking is probably on the horizon, says Leon Rodriguez, who directs the Office of Civil Rights, the branch of the HHS that oversees HIPAA compliance. Again, though, if the data is encrypted within the server, the thief won’t have any usable data. As you can see, data encryption is not just important at your facility but also in your server infrastructure. Atlantic.Net can walk you through the process of [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/). With three decades in the hosting business and a full range of security and auditing certifications, including SSAE 16 (SOC 1) TYPE II (Formerly SAS 70), we know how to keep your patients secured, prevent fines, and protect your reputation with award-winning Dedicated Hosting and Cloud Hosting. ![HIPAA compliant hosting joke](https://www.atlantic.net/wp-content/uploads/2014/01/Comics-January-11-001.jpg) Comic words by Kent Roberts and art by Leena Cruz.   --- # Atlantic.Net Makes Entrepreneur Magazine .Net 100 List > URL: https://www.atlantic.net/press-releases/atlantic-net-makes-entrepreneur-magazine-net-100-list/ | Published: 2014-02-06 | Updated: 2026-03-02 | Author: Editorial Team *Atlantic.Net selected as one of the Top 100 .net domain names worldwide by Entrepreneur Magazine & Verisign* ** ORLANDO, FL –****February 6, 2014 –**Atlantic.Net ([https://www.atlantic.net](https://www.atlantic.net/)), a hosting solutions provider specializing in cloud, VPS, virtualization and managed hosting, has been named one of the top 100 websites featuring the .net extension. The list, developed by Entrepreneur Magazine in partnership with security and domain name services giant Verisign, is computed through a combination of web traffic (Alexa rankings), voting by Entrepreneur’s business-minded readership, and social prominence (Facebook, Twitter, and Klout). “We are proud to have made this list, and we feel honored that such industry heavyweights have taken note of our efforts,” said Marty Puranik, CEO and President of Atlantic.Net. “With a track record spanning two decades, we continue to help companies of all sizes manage the shift to new technologies such as cloud, VPS and virtualization.” Atlantic.Net has been recognized repeatedly for its rapid growth, both in its home state and throughout the United States. The company received four back-to-back inclusions in the Florida Fast 100, along with three repeated rankings in the Inc. 500, developed by Inc. Magazine. The Entrepeneur ranking represents worldwide recognition by trusted names in business media and Internet security. **About Atlantic.Net:** [Atlantic.Net](https://www.atlantic.net/) is a web hosting provider with a range of security certifications and a  SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited data center that the company owns and operates. The firm specializes in providing cloud server hosting, HIPAA compliant and hybrid hosting, private virtualization, and VPS hosting in the cloud. Atlantic.Net has been honored repeatedly in the Florida Fast 100 and Inc. 500 lists. The firm is also known for its reliability, as dictated by its 100% uptime service-level agreement (SLA). For more information, please visit [www.atlantic.net](https://www.atlantic.net/) . **Media Contact:** Media Relations pr@atlantic.net (321) 206-1371   --- # How To Get HIPAA Compliant Hosting for Your Business? > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-server-hosting-business-real-world-scenario/ | Published: 2014-02-10 | Updated: 2024-03-01 | Author: Sam Guiliano Compliance with the Health Insurance Portability and Accountability Act (HIPAA) is necessary for a wide variety of medical organizations. Covered entities to which the law applies include healthcare providers, healthcare plans, and healthcare clearinghouses. Covered entities have the option to work with third parties – termed business associates – to meet their HIPAA compliance needs. We have written several blog posts on HIPAA compliance to spread knowledge on the subject. We also have a broad spectrum of HIPAA information elsewhere on our site. All of this information is intended to provide a general idea of how to achieve compliance. However, a real-world scenario can help to give you an idea of what the search for [HIPAA Compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) Hosting is like for an individual organization. The below dialogue is based on an actual interaction between a new client and a hosting consultant. **HIPAA Compliance: healthcare firm seeks assistance** Client: I am looking for HIPAA-compliant hosting. My business is a startup and requires a bare-bones solution upfront. Then we will scale it as needed. Consultant: Do you need Linux or Windows? Client: Windows, outfitted with SQL Server Express. Consultant: Below are the basics of our proposal for the smallest Windows HIPAA Compliant Server hosting we have available, which has 500 GB of storage. Note that Microsoft SQL Server Express is included with the package at no additional charge. - Windows Based / Dual Core Processor w/ Hyperthreading / 4 GB of RAM (expandable to 32 GB) / 2 X 500 GB SATA Hard Drives set up in a RAID (redundant array of independent disks) 1 configuration - Fully Managed Hardware Firewall with five (5) encrypted VPNs (virtual private networks) - Fully Managed Daily Backup of all files and databases - 10 TB of monthly data transfer with a 1 Gbps Port - 100% uptime SLA (service level agreement) - 24/7/365 Technical support by phone or email - SSAE 16 (SOC 1) TYPE II audited data center (stronger security parameters than HIPAA). Client: Your proposal lists two hard drives, each with 500 GB. Does that mean 1 TB? Consultant: The two hard drives are set up in RAID 1 configuration, which is the standard configuration for Windows hosting. One of the drives mirrors the other for redundancy. That gives you a total of 500 GB. Client: Can you provide a discount on the price? We only want a small package for now but will likely be increasing its size, possibly even next month. Consultant: You can be billed each month if you want, but it is more cost-effective to choose a 12-month or 24-month term. Unfortunately, we cannot discount any month-to-month plan. Client: What healthcare organizations currently use your HIPAA-compliant services? I’m concerned about credibility. Consultant: We have been in business for three decades and have a wide variety of HIPAA clients. We are ultimately concerned with customer privacy, but a few of our customers have permitted us to use them as references. [Complete HealthCare Solutions](http://www.completehealthcaresolutions.com), one of the largest healthcare providers in the northeastern United States, is one such organization. You are welcome to contact them. Client: To what extent will we be able to adjust the system’s resources as we grow? Consultant: The hardware in the above proposal can be expanded to 32 GB of RAM and 3 TB of storage capacity. You can upgrade the bandwidth as well. However, keep in mind that 10 TB of monthly data transfer is equivalent to 30 Mbps (megabits per second), a substantial amount at the outset. If you grow too big for this infrastructure, we will recommend a larger hosting environment. Don’t worry about contracts if you need to expand your system. We understand that customers need to grow, and we are always willing to work with them. With this plan, you can keep your cost low at the start without having to migrate to a platform that is too sizable for your immediate needs. Client: Do you handle migration, or how does that work? We can assist with the migration, but that is completed by our engineering department through an hourly consulting agreement. If you want, I can have them contact you to provide a quote for migration. If you decide to proceed, this is the information I’ll need for the business associate agreement: - Full company name - Billing address - Tax ID number (if readily available) - State of incorporation (if readily available) - Name, phone number, and email address for primary, billing, and technical contacts. Client: I understand that we need to have a log of our activities to be HIPAA compliant. Does this package include log management? Consultant: Yes, it does. Client: Okay, I’m ready to move forward. I’m sending the BAA to my attorney to review. I will get back to you as soon as I hear back from him. How long does it take for you to set up the environment? Is one week good enough? Consultant: Yes, that should be fine. Please let me know if you have any further questions. *** Atlantic.Net can answer all your HIPAA compliance questions as well. Contact our highly trained and experienced team of consultants to request a quote for a [HIPAA Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) Server solution today. ![How To Get HIPAA Compliant Hosting - Comic](https://www.atlantic.net/wp-content/uploads/2014/02/how-to-get-hipaa-compliant-hosting.jpg) Comic words by Kent Roberts and art by Leena Cruz. --- # Google+ Local Pages vs. Google+ Business Pages vs. Google Local Listings > URL: https://www.atlantic.net/hipaa-compliant-hosting/google-local-vs-google-business-pages-vs-google-local-listing/ | Published: 2014-02-10 | Updated: 2024-10-31 | Author: Alexander Wise Google+ pages officially launched in November of 2011, but two years later, they still have a long way to go. One of the main areas that could benefit from some improvement is local Google+ pages – arguably the most confusing page types. Google+ Local pages can be compelling if you know how to use them. With that being said, I’m going to clear the smoke on this often confusing digital marketing tool so that you can make proper use of it! ## The history of Google+ Local Pages First, let’s dive into a bit of history. Did you know that Google+ Local pages started as Google Places in April of 2010? With the [launch of Google+ pages](http://googleblog.blogspot.com/2011/11/google-pages-connect-with-all-things.html) in November of 2011, Google had a bit of redundancy – businesses had two pages to represent themselves with Google. This was a problem. To fix this, Google quickly began to merge the two. Now all pages that were previously Google Places listings are a part of Google+ with the Google+ design, and they are now called Google+ Local listings. However, there are different types of Google+ Local listings. First, there are the unverified listings which are essentially Google Places with a redesigned look to fit the Google+ interface. They provide general business information (address, phone number, website, and hours of operation) that Google has scraped from the Internet, display on Google Maps, and allow Google+ users to write and leave reviews. However, the business owner has not yet verified the listing and the information provided by going through the verification process. The listings will look very similar to the page below: ![Google+ Local vs. Google+ Business Pages vs. Google Local Listing](https://www.atlantic.net/wp-content/uploads/2014/02/googlelocal.png) You will notice the absence of the “follow” button on the top right of the page. The “Posts” tab is also missing. Both of these missing icons point to the fact that the page is just a local listing. The fact that there is no verified checkmark next to the business’s name denotes that it is not yet verified. The other type of Google listing is a verified listing. Verified listings give you the features of an unverified listing with the addition of a few social features, such as the ability to share posts and engage with others on Google+. Your listing also includes a “Videos” or “YouTube” tab (if you choose in your settings that you want it to appear) along with the new “Posts” tab. In addition, verified listings receive a verified checkmark icon to let others know that it has been verified. ## Example of a verified Google+ Local verified listing Atlantic.Net’s Google+ Local page below is the perfect example of a verified listing: ![Atlantic.Net’s Google+ Local page](https://www.atlantic.net/wp-content/uploads/2014/02/googlelocalpage2.png) You can see that this listing has a “Follow” button on the top right, a verified checkmark next to the name, “Posts” tab, “YouTube” tab, and sections on the “About” page for people that follow Atlantic.Net and the Google+ Communities in which they have created. ## Verifying a Google+ Local page If you would like to verify a Google+ Local page already set up for your business, you can do so by following [these steps](https://support.google.com/plus/answer/1713911?hl=en&rd=1). Also, if you would like to create and verify a new Google+ Local page for your business, you can do so by following the [same steps](https://support.google.com/plus/answer/1713911?hl=en&rd=1). The most important step is making sure you choose “Local Business or Place” when given the below options: ![google local listings](https://www.atlantic.net/wp-content/uploads/2014/02/googlelocallistings.png) You will not be able to change the category of your page after it is created, so you’ll want to make sure you choose the correct category the first time. Your only option will be to delete the page and start over again with a new page. Take my advice – get it right the first time. ![google brand page](https://www.atlantic.net/wp-content/uploads/2014/02/googlebrandpage.png) Now, when you compare a verified Google+ Local page to a Google+ Business page (seen above), you will notice some distinct differences. A general Google+ Business page is not as focused on the location. The address is not as prominent, and the verified checkmark, reviews, map, hours of operation, and photos are all missing from the “About” page.  Furthermore, a Google+ Local page allows you to connect a Google Business Photos tour to your page to give visitors a 360-degree virtual tour of your business. This is not an option for a more general Google+ Business page. Since a Google+ Local page gives you more features over a general Google+ Business page, you should always use a Google+ Local page if you service a certain geographical area or are open to having visitors to your building, even as a rare occasion. This is especially true even if you are a home-based business as Google+ Local allows you to indicate that you serve people at their locations by setting up a service area. Your exact address will not appear on your page – just your city and state. Your listing will look similar to the one below: ![google local listing](https://www.atlantic.net/wp-content/uploads/2014/02/googlelocallisting.png) In addition to having important features such as a verified checkmark and reviews from your previous clients, your business is also eligible to appear in local Google search results (like below). It can often be easier to appear in the local listings than the general search results, so a filled and optimized Google+ Local page can indeed be very powerful. ![google maps listing](https://www.atlantic.net/wp-content/uploads/2014/02/googlemapslisting.png) ## When to use a Google+ Business page However, if your business is a large national or international corporation and you do not want your customers seeing your office, then a general Google+ Business page may be the better fit for you. This is because your headquarters’ location and hours of operation are generally not of interest to your customers. Also, you may not be as interested in reviews since you generally do not need them to persuade customers to choose you. However, it would help if you used Google+ Local pages for individual branches/franchises. In addition, you may be able to have your Google+ page verified by working with Google employees. The one tricky area is if you are a purely online business (your location doesn’t matter to your customers, and they will never visit your location) because you may still want the reviews on your page to persuade others to choose you over your competition. In this case, I would suggest using a Google+ Local page that services customers at their location using the service area option. With continuous innovation, Google has undoubtedly proven itself to be an industry leader. Knowing which Google + pages to utilize effectively can be valuable for any business person looking to market themselves commendably. Hopefully, Google will eventually make the process of choosing and setting up the right Google+ page for your business easier. ## About Atlantic.Net Atlantic.Net can help you reach your customers and clients with affordable, state-of-the-art cloud hosting services, including [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/), and one-click applications like [WordPress VPS Hosting](https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/). --- # Why you should select Atlantic.Net as your cloud hosting provider > URL: https://www.atlantic.net/hipaa-data-centers/compare-atlantic-net-cloud-hosting-important-considerations-comic/ | Published: 2014-02-20 | Updated: 2024-10-21 | Author: Kent Roberts A typical question one of our customers asks us is, “What is your advantage over other cloud providers?” We know at Atlantic.Net that we are just one of many options for cloud hosting. There are numerous ways in which we set ourselves apart. Here are some of the hallmarks of the service that makes Atlantic.Net the best cloud hosting provider in the industry: **We give you your own kernel.** With our Cloud Hosting, every server created has its own kernel. In contrast, many providers offer their users a shared kernel, significantly reducing customers’ control over their server environments. **We bill on a per-second basis.** Per-second billing is especially beneficial for large server deployments. However, per-second billing is an advantage to every customer. The cloud is incredibly elastic, which means that you have access to additional resources on a moment-by-moment basis. If you need additional resources beyond the limits of your plan, you bump up the parameters within your control panel. What’s important is how long that higher rate remains in effect. The second you start needing additional resources with us is the second you start paying at a higher rate. Based on the second you ramp your resources back down, you stop paying at the higher rate. In contrast, many cloud hosting providers charge per hour, so a higher rate would remain in effect throughout whatever hours they are needed. **We provide optional backup.** We back up your entire site, applications, and any other elements of your network. **We provide Windows servers.** Many cloud hosting providers only offer Linux servers, which doesn’t meet the needs of many organizations. Now, to be clear, Linux is extraordinarily popular and is used by companies as large and powerful as Facebook, Google, and Amazon. However, some businesses want to use Microsoft for reasons such as the following: - integration with the broad spectrum of Microsoft applications; - ability to incorporate pages created via ASP and your database into FrontPage; and - resilient, high-performance SQL server databases. **We provide additional IP Addresses.** Sometimes businesses need more than one IP address, and we can accommodate them. A sample situation in which you might want to have [an additional IP](http://www.webhostingtalk.com/showthread.php?t=1189771): - 2 nameservers should have two different IP addresses, according to Request for Comments (an Internet Engineering Task Force publication); - the second IP can be used when installing SSL certificates - the second IP can also be used for IP-based hosting (hosting an additional site using the same cloud). **We have been in business for three decades.** When you look for affordable hosting, you may be afraid of doing business with fly-by-night companies. Atlantic.Net has been in business since 1994, with a long and impressive history of rapid growth and other accomplishments. **We provide other hosting solutions in addition to Cloud.** It’s good to know that you can create a hybrid solution as needed. For example, you can use the cloud in combination with colocation or dedicated servers. You can also combine a cloud with managed services. You can even transfer your system from the public cloud to a private cloud, or vice versa. **We offer easy and highly secure server deletion.** If you need to take a server offline, you can delete a server with us in less than 10 seconds. We have tested other hosting providers in which it took about 17 minutes for the server to clear. Not only does that mean the task is completed more quickly, but you also aren’t paying for the extra time. Beyond time and money, your provider should have strong security practices concerning server deletions. Some hosting providers use outdated security protocols such as LVM (logical volume manager). Atlantic.Net has state-of-the-art security for server deletions that are clean and total. **We have competitive pricing.** Our reasonably-priced Cloud Servers start at only $0.00135 per hour. **We own and operate an SSAE 16 TYPE II certified data center.** Many hosting companies are not in control of the data center itself. We are. Furthermore, our facility has been professionally audited and is highly secure through stipulations set by the American Institute of Certified Public Accountants (AICPA). **We offer cPanel.** We previously covered why cPanel is [such a great tool](https://www.atlantic.net/vps-hosting/)for those administrating a cloud hosting account. Here are a few highlights: - *Prominent and familiar* – Either cPanel or its integrated cousin WHM are used by almost 2/3 of hosting companies as of 2011. - *User-friendly* – It offers a feature-rich platform, controlled through an interface designed for ease of use. Modules can be added as needed. - *Control* – Because cPanel is widely used, it’s easy to switch from one hosting provider to another. You don’t get stuck in a single hosting company’s proprietary software. - *Support* – Beyond the support provided by Atlantic.Net, you can also use cPanel’s knowledge base or the broad online community of cPanel users. You can visit cPanel support [directly](http://cpanel.net/support/) or try an online forum such as [DaniWeb](http://www.daniweb.com/). **We provide 24/7/365 live support.** Have a question now about lightning-fast cloud servers or other hosting solutions. Contact us by phone, email, or live chat anytime. ![Why you should select Atlantic.Net as your cloud hosting provider- comic- humor](https://www.atlantic.net/wp-content/uploads/2014/02/Comic-Strips-Atlantic-6-001.jpg) By Kent Roberts Atlantic.Net also offers [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions; learn more about our [HIPAA Data Centers](https://www.atlantic.net/hipaa-data-centers/). --- # Predictive Analytics & Predictive Modeling on the Cloud > URL: https://www.atlantic.net/pci-compliant-hosting/predictive-analytics-predictive-modeling-parameters-predictive-cloud-business/ | Published: 2014-02-21 | Updated: 2024-10-21 | Author: Sam Guiliano Certainly, cloud computing is growing astronomically, much of it in the public cloud (the standard model). However, a trend has emerged: businesses are shifting from the public cloud to a managed private cloud (not always necessary, as described below). The reason that is occurring is that the companies desire more predictability, both in costs and performance. This new trend is not just about reliability and the IT budget but also a broader focus on prediction throughout the business community. The tools made possible by predictive analytics and predictive modeling allow businesses to develop in more sophisticated and conscientious ways than ever before. **Predictive analytics and predictive modeling** Predictive analytics, [according to TechTarget](http://searchcrm.techtarget.com/definition/predictive-analytics), is a form of data mining that helps you predict how your business and your industry will develop. In predictive analytics, you take a predictor – any measurable factor – and analyze it to determine how it will likely change over time. Sample fields in which predictive analytics are used are insurance and finance. Predictors for [car insurance](https://www.autoinsurance.org/online-car-insurance-quotes-without-personal-info/) companies, such as the driving record and gender of the driver, help insurers quantify risk. The same is true for investment companies looking at predictors to gauge stock market trends. Predictive analytics becomes more complex when an organization uses predictive modeling. A predictive model takes several different predictors and analyzes them using a specific model (essentially a formula to generate future data as accurately as possible). As data is fed through the statistical model and predictions are generated, the system is tested and adapted as needed. Predictive models are not always set up as straightforward formulas. In some cases, software is used to allow a neural network (a network of computers designed to approximate the human brain) to analyze the data in a [more refined way](http://searchdatamanagement.techtarget.com/definition/predictive-modeling). An example of predictive modeling is in the field of spam filtering. Gmail uses an algorithmic model to make an educated guess about whether an incoming message should be marked as spam. **Why predictive analytics is important** Predictive analytics is by no means a new practice (as indicated by the insurance and finance application above). Still, the ability to use it wisely creates a more significant competitive advantage in the age of big data. As [Predictive Analytics Times](http://www.predictiveanalyticsworld.com/patimes/what-is-predictive-analytics/) indicates, the data about your business can tell you what fails and what succeeds so you can move forward with a carefully calculated approach. You can use it for your entire business. Customer needs can be met more quickly and with less error. You can streamline your operations. You can use it to determine what individuals will do – customers and employees – as well as what organizations will do – your own, affiliates, and competitors. Overall, you won’t make many mistakes if your business is guided by a predictive model that is strong, versatile, and flexible. **How to use predictive analytics** To take advantage of predictive analytics, you don’t need to create your own software unless you have specialized requirements. SAS, SAP, and IBM all have predictive analytic tools, as do many other software companies. Each program works by assessing all of your data – sales, operational, and even social media numbers – and then plugs it into prebuilt predictive models. The vendors listed above have robust solutions that can meet the needs of enterprises. However, not every company needs an enterprise solution. Small businesses can take advantage of scaled-down, cost-effective predictive offerings from Emanio and Angoss. Both of those solutions can be run on a PC rather than a server. **Interesting predictive situations** Information Management provides two interesting scenarios in which predictive analytics have been used: - The US Special Forces utilized Dean Abbot’s predictive models to garner a better understanding of recruits. An expert in analytics, Abbot says the primary consideration is how much to weigh different factors. Balance is best achieved by looking at the results: look at the data for various successful staff members to create a predictive model for hiring new employees. - Geolocation of users allows you to develop a better predictive understanding of your customers’ behavior. Social media companies use location data to determine the prominence of posts and better tailor advertising. **The predictive cloud** Probably the main reason some businesses have become frustrated with the public cloud is that many cloud hosting providers (CHPs) are not transparent. Bills can seem erratic: it’s difficult to understand what they will be from one month to the next. Here are several features that allow Atlantic.Net to provide our customers with a predictive cloud so that their hosting environment is always consistent: - real-time billing information - per-second billing - no hidden fees or stealth upcharges - no charge for inbound traffic - 1 TB of free outbound data transfer. The above parameters apply to all our [VPS hosting](https://www.atlantic.net/vps-hosting/) plans. Predictive spending comes standard, and you can utilize our managed cloud services, including [PCI compliant hosting](https://www.atlantic.net/pci-compliant-hosting/), for your infrastructure as desired. ![Predictive Analytics & Predictive Modeling on the Cloud- Comic.](https://www.atlantic.net/wp-content/uploads/2014/02/Atlantic-Comic-February-01-001.jpg) Predictive Analytics & Predictive Modeling on the Cloud Comic words by Kent Roberts & art by Leena Cruz. --- # IBM and Cisco are investing in the cloud > URL: https://www.atlantic.net/pci-compliant-hosting/signs-were-headed-cloud-ibm-cisco-cases-point/ | Published: 2014-02-24 | Updated: 2024-11-14 | Author: Sam Guiliano As the cloud grows, major tech companies are struggling to rapidly reorganize their companies and stay competitive in the IT marketplace. Two primary examples are IBM and Cisco. After years spent focusing primarily on the physical server model, each of the companies is investing heavily in the cloud – with a special focus on the Internet of Things from Cisco. ## The cloud & the case of IBM IBM spent $1 billion last year on layoffs, and the company will spend just as much on “restructuring” its workforce in 2014.  Approximately 15,000 jobs will be terminated across the world, primarily in [Europe, Brazil, and India](http://timesofindia.indiatimes.com/tech/tech-news/hardware/IBM-to-cut-15000-jobs-India-operations-to-be-affected/articleshow/30404151.cms). In January, IBM announced that its leadership would not receive bonuses. The organization prepared to begin the widespread layoff process during the first quarter measures necessary due to decreasing revenue from physical hardware – servers and storage systems. ### Layoffs at IBM Martin Schroeter, IBM’s CFO for finance and enterprise transformation, first mentioned the layoffs during January, presenting its [fourth-quarter report](http://www.theregister.co.uk/2014/02/05/ibm_job_cuts_q4_2014_preview/). Schroeter stated that the company would be doing more than making layoffs: - redirecting funds to stronger developmental areas; - shutting down departments and selling unprofitable businesses; and - repositioning itself in the market with a new set of growth priorities (referred to by Schroeter as “acquir[ing] key capabilities”). Specifically, IBM is selling its customer service business with an ownership transition contract expected to be in place by the end of Q1. That effort follows the sale of IBM’s server business at the beginning of January. Schroeter mentioned that the layoffs would bolster company profits, but that gain won’t be felt until late 2014 (although clearly, it’ll be immediately felt by the terminated employees). ### Are the layoffs because of a move towards cloud? IBM has not directly stated that the layoffs are connected to the growth of cloud computing, but that certainly appears to be the case. In January, news also arrived that IBM is investing $1.2 billion to build more than a dozen data centers.  IBM is planning to broaden its capabilities as a cloud provider. The company is aiming to double the strength of SoftLayer, the former hosting company that is now IBM’s cloud brand, following its $2 billion [acquisition by IBM in 2013](http://www.fool.com/investing/general/2014/01/22/how-ibm-plans-to-win-cloud-space.aspx). Once the new facilities are completed, IBM will own a total of 40 data centers. The amount of money pouring into the cloud part of its business – $3.2 billion just covering those two aspects listed above – is astronomical, representing IBM’s effort to take advantage of the growing cloud marketplace. In total, IBM expects business cloud computing to be a $200 billion global industry by the end of the decade. ### IBM’s twofold cloud strategy IBM is targeting the cloud hosting market from two distinct but convergent angles. One aspect of its approach is to earn the business of public cloud users, who need cost-effective solutions that fall within their tech budgets. Needless to say, IBM will not be the most affordable cloud hosting provider. It will go head-to-head with Amazon Web services (AWS), which generated about $2 billion for Amazon in 2012 (a figure expected to be almost 3 times as large this year). By purchasing SoftLayer and building its cloud infrastructure with new data centers, IBM is positioned well to challenge the dominance of AWS. SoftLayer’s strategy was centered on SMB before the acquisition, so IBM now has a toolset better suited for that segment. However, IBM is not turning its back on physical hardware and the specialized needs of corporations and government agencies. Essentially, the company is trying to become more versatile. By shifting focus toward the cloud, IBM will migrate its customers’ systems from mainframes to the private cloud without significant friction. A company that is only cloud-focused, such as Amazon, doesn’t have that same capability; however, Atlantic.Net and various other hosting providers offer similar integration and expertise when switching between systems. ## The cloud & the case of Cisco Cisco is turning toward the cloud as well, specifically the Internet of Things (IoT), as covered in our recent post, “[Marketing in the Internet of Things](https://www.atlantic.net/vps-hosting/).” Cisco CEO John Chambers noted in January, at the International Consumer Electronics Show (CES) in Las Vegas, that the Internet of Things was shaping into a [$19 trillion market](http://www.bloomberg.com/news/2014-01-08/cisco-ceo-pegs-internet-of-things-as-19-trillion-market.html). Cisco is particularly interested in how consumers will be affected as the Internet of Things because more prevalent. The company is bargaining that as the environment around us (the physical component of the IoT) becomes better equipped to understand and analyze our preferences, we will be driven more successfully toward purchases. Cisco turns toward this new business venture, also known as Web 3.0, because its hardware sales are in a nosedive. According to Bloomberg, revenue for Cisco’s physical equipment is expected to drop more than 4% this year. ## Moving your business to the cloud As Cisco and IBM developments suggest, you’re not alone if you’re considering business cloud server hosting. Try out Atlantic.Net’s award-winning [VPS hosting](https://www.atlantic.net/vps-hosting/) today, with a server online in 30 seconds and support for [PCI compliant hosting](https://www.atlantic.net/pci-compliant-hosting/). ![IBM and Cisco are investing in cloud hosting- Comic.](https://www.atlantic.net/wp-content/uploads/2014/02/Comics-Strips-Atlantic-17-001.jpg) Comic words by Kent Roberts & art by Leena Cruz. --- # Interview: Affordable HIPAA Compliant Hosting Real World Scenario — LAMP Box in a HIPAA Compliant Platform > URL: https://www.atlantic.net/hipaa-compliant-hosting/affordable-hipaa-compliant-hosting-scenario/ | Published: 2014-02-26 | Updated: 2024-11-09 | Author: Sam Guiliano As healthcare organizations are well aware, it’s necessary to make sure all technology meets the Health Insurance Portability and Accountability Act (HIPAA) rules. Providers, medical plans, and clearinghouses of EMR data are all considered covered entities under HIPAA, meaning they must be compliant or undergo hefty fines. Any covered entity has the option of working with a business associate, an outside organization that handles data and can be held responsible for certain aspects of compliance. Because HIPAA compliance is a common IT concern we specialize in, we regularly discuss its guidelines and related information in our blog. We provide additional information and resources to educate our customers. We’ve also started publishing articles based on real-world dialogues between our hosting consultants and HIPAA clients. Below is a basic interaction concerning an affordable HIPAA solution and a general discussion of LAMP for the cheapest HIPAA compliance. ## **Cheap HIPAA Compliant Hosting: Cutting Costs by Using LAMP Technology** **Consultant:** Tell us about your hosting needs. **Client:** I need a LAMP box in a HIPAA Server platform to run a small pharmacist website. 2 gigs of RAM will be plenty. **Consultant:** Attached is the pricing proposal based on your requirements. The least amount of RAM we can provide is 4 GB, and the smallest hard drives are 500 GB. We have also attached a copy of our business associate’s agreement (BAA) for your review. The equipment would be located in an SSAE-16 audited data center. Our pricing is based on either a 12-month or 24-month term. These are the highlights of our proposal: - Fully Managed Hardware Firewall with 5 VPN’s - Fully Managed Daily Backup for all files and databases - Linux Centos with LAMP Stack - 4 GB of RAM - 500 GB of Storage space set up in a RAID 1 configuration - 10 TB of Monthly Data Transfer with a 1 Gbps Port - 24 X 7 X 365 Live Technical Support by phone or email - 100% Uptime SLA. **Client:** The price seems reasonable. Is the data encrypted at rest? **Consultant:** Yes, the data is encrypted both at rest and in motion. Regarding price, we try to present customers with the best cost possible based on what their [HIPAA hosting](https://www.atlantic.net/hipaa-compliant-hosting/) requirements are. If you decide to move forward with what we have proposed, we will require answers to the following questions, along with the term you want to select. If you have any other questions, please send them to us. - Full Company Name - Billing Address - Tax ID Number (if available) - State of Incorporation (if available) - Main Contact with phone number and email address - Billing Contact with phone number and email address - Technical Contact with phone number and email address. ## Why LAMP Represents a Strong, Affordable Choice A LAMP box is a platform appreciated by web developers for its efficiency, reliability, and stability. It’s also a technology that can be integrated into an existing system. A LAMP box is actually a stack or bundle of software made up of four components: Linux, Apache, MySQL, and PHP. Each of the individual pieces of software can be replaced by alternatives as needed (such as Perl or Python in place of PHP). The entire stack is open source, and all of its elements are free, making it both fully customizable and cost-effective. ## The 4 Parts of LAMP - Linux – The world’s most popular open-source operating system, Linux comes in many different flavors (such as Ubuntu and Debian) and is a version of UNIX. It generally enhances efficiency and compatibility. - Apache – This application is a Web server, meaning that it properly delivers your application over the web. Almost 2/3 of sites worldwide use Apache, according to the mobile app development company PLAVEB, primarily due to its stability. Along with PHP, Apache allows an application to be dynamic, increasing the ability of visitors to interact with your site. - MySQL – This software organizes your data for storage. It can be used to create databases of various levels of sophistication, depending on the organization’s needs. It uses the SQL language, optimizing the system’s ability to retrieve data accurately and quickly. - PHP – This language really intertwines all the elements of a LAMP bundle in a meaningful way. It is the language in which the various dynamic aspects of your application are coded, so that information from your MySQL database is immediately accessible. Many developers prefer LAMP over alternatives for three primary reasons: 1. It’s free, and you have full control; 2. Coding is fast and predictable because the likelihood of bugs is reduced; and 3. Deployment doesn’t present a compatibility challenge because PHP is a pre-set module within Apache. A LAMP HIPAA Cloud Server offers a stable and affordable option as a platform for your healthcare company. However, your specific needs may be different. Atlantic.Net customizes [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/), made-to-order for your organization. ![cheap HIPAA hosting - Comic](https://www.atlantic.net/wp-content/uploads/2014/02/Comic-Strips-Atlantic-8-001.jpg) Comic words by Kent Roberts & art by Leena Cruz. --- # SSD Cloud Hosting FAQ – A Real World Scenario > URL: https://www.atlantic.net/vps-hosting/ssd-cloud-hosting-faq/ | Published: 2014-03-07 | Updated: 2024-11-14 | Author: Kent Roberts Our blog functions, in part, to present typical interactions between our hosting consultants and individual clients. The users of our hosting solutions often have similar questions, and this “Real World Scenario” series allows us to highlight helpful information provided in these discussions. The below dialogue is based on an exchange between our staff and a potential customer interested in our cloud hosting solutions. ## Real World Scenario: Client Needs SSD Cloud Hosting for .aspx Apps, RabbitMQ, & Elasticsearch Consultant: Please tell us about your hosting needs. Client: Hi, I am considering your cloud service. What I would like is to run some simple .aspx applications. I also need to install a couple of services: RabbitMQ and Elasticsearch. Those applications are not .Net-based, but they can be installed and run as Windows Services. Is that allowed? Further, I would like to have some TCP ports open for these services. Will that be possible as well? Thank you. Consultant: Our cutting-edge Cloud Servers come with full administrative access. You will be able to accomplish everything you listed. All ports are open for our cloud except for SMTP, which can be opened by request. ### SSL Certificates Client: Some providers optionally include SSL certificates with the cloud. I wonder if Atlantic.Net has similar features. Would I incur an extra cost? Consultant: Unlike other providers, our cloud servers are full-fledged virtual servers to which customers have root access. We do not offer SSL certificates as part of the package for these servers since they are not managed. We do not have access to passwords to the internal customer servers at all. ### SSD Storage Client: The site mentions 100% SSD. Does it mean the 80/100G data also uses SSD? Or is the data in SAN or SATA? What’s the RAID configuration? Also, can you give me some information on how backup works? I imagine that your system would copy our cloud entirely to another disk location. Can backup and restore be managed through your set of tools (with Cpanel or without Cpanel)? Consultant: Our clouds are comprised of extensive storage nodes and computing nodes. These nodes use SSD’s in a RAID 10 configuration. The data on the cloud is stored in the virtual hard disk (size based on the plan chosen). Backup snapshot images are taken once a week. The backup feature is not implemented into our cloud control panel yet but is planned for the future. For the time being, a request can be made from within the cloud control panel to roll back an instance. The management interface is of our own design and not affiliated with cPanel. Our cloud control panel provides an interface to create, remove, and manage cloud servers. Client: Are there a list of components available specifically for a .aspx environment? We are using IIS URL Rewrite now. Do you provide something similar? Consultant: Since our clouds are unmanaged, you are free to install any components needed to run the services you require. You have full access to the server via SSH, RDP, and VNC. ### VPN Options Client: I can set up a VPN from our office to the server directly and easily, am I correct? Consultant: As mentioned before, our cloud is a set of private virtual machines that allow you complete control. The configuration of the server is the responsibility of the owner of the server. This means that you are free to choose whatever VPN solution is easiest for you to configure. Client: Using a single Windows cloud, are there any limitations on the number of domains (websites) we can put on the server? Consultant: It is important to note that we provide hosting solutions and are not a web hosting provider specifically. There are no limits on the number of domains you can host because you can access the Windows cloud as if it were a physical computer via the remote desktop protocol and VNC. You are only charged for the hourly operation of the virtual server and outbound data transfer. We do not control what you decide to do with it (such as hosting websites). Some customers use our cloud to run forex trading software, for example. ### Firewalls Client: Is there something like a Firewall where we can open/close ports? Consultant: All of our clouds have a dedicated public IP with no firewall in front of it. All ports are unblocked on our end, except for port 25, by default. Each cloud does come with the native firewall built into the OS, though. ### Control Panel Client: We are not familiar with cPanel. I understand it may incur additional costs. I also understand it is an admin panel with tools that we can use to manage sites and their feature provisioning easily. Can you give me more info or point me to a URL about its functions (especially how it can add value to a Windows system)? Consultant: You have the option of provisioning a server with cPanel pre-installed, but it runs only on Linux. There is no Windows version of cPanel. If you choose to use Windows, you would need to configure IIS as the webserver and manage it accordingly. ### Reporting Client: Are there any website traffic or access reports that come with the service? What are the options? Consultant: As we are not a website hosting provider such as GoDaddy, we do not provide a web traffic report or anything along those lines. Our service provides servers for customers who need the ability to customize and manage features on their own. Some experience is needed for some operating systems and configurations needed to set up what is required. ### Networking Capabilities Client: Suppose I have a Linux cloud server with Atlantic.Net as well. Is there an easy way to connect the Linux and Windows servers, sort of like an internal network? Consultant: Yes, there is. We give an entire private IP range that can be used to set up a LAN between all cloud servers in your account. Client: Great! All clear! Thanks. I really appreciate the support. Consultant: Thank you for using Atlantic.Net. Please let us know if you have any further questions. Have a great day! *At Atlantic.Net, the thorough and conscientious support you see above is not a sales strategy. It’s the way we do business. You can have one of our [VPS Hosting](https://www.atlantic.net/vps-hosting/) plans up and running in 30 seconds, backed by ongoing, live 24/7 support.  See our [VPS hosting price.](https://www.atlantic.net/vps-hosting/pricing/)* ![ A Real World Scenario with Common Questions by SSD Cloud Users - Comic](https://www.atlantic.net/wp-content/uploads/2014/03/AtlanticComics-8-001.jpg) By Kent Roberts; comic words by Kent Roberts & art by Leena Cruz. --- # Benefits of Solid State Drives (SSDs) > URL: https://www.atlantic.net/hipaa-data-centers/benefits-ssd-cloud-solid-state-drives-enhance-computing-experience/ | Published: 2014-03-19 | Updated: 2024-08-29 | Author: Sam Guiliano The solid-state drive (SSD) has long been considered a preferable solution to the hard disk drive (HDD). However, SSD’s have not made sense for many companies until recently because their cost has been too high. Now that they are less expensive, all businesses can experience the various benefits of an infrastructure built on this advanced technology.  Atlantic.Net offers SSD Cloud Hosting running many of the most popular hosting solutions.  ## **Continuing Improvements of the SSD Design** An article by Lucas Mearian for Computerworld in 2012 indicates how rapidly the technology has been improving (a trend that has continued to the present), in tandem with a significant price reduction. According to Mearian’s analysis, between 2009 and 2012, the reliability and performance of the equipment were enhanced dramatically. In fact, their speed was as much as 200% better than it had been three years earlier. Although companies were intrigued by the hardware as soon as it became available, cost-consciousness made it an unlikely choice. However, SSD prices have dropped substantially since they were first introduced. Over Mearian’s three-year assessment period, costs for the drives dropped by more than 60%. These infrastructural components have been continually advanced over the last two years as well, making a case for solid-state adoption glaringly obvious. ## **Benefits of Solid State Drives** The revolutionary drive presents various benefits over the traditional technology, as discussed by Toshiba subsidiary OCZ Storage and PC Magazine: ### 1. Stability An SSD is 100% stationary, while the older model contains elements like a spindle, platter, and actuator arm. Moving parts within the traditional system render it more vulnerable to physical harm, while SSD’s are considered shock-resistant within reasonable parameters. Durability seems especially important for PC users because of mobility: with the new drive, data loss is less likely if a laptop falls to the floor. However, it’s also an added protection at hosting data centers: if an earthquake or other natural disaster assaults servers, the drives are less likely to fail. A hard drive is not excessively vulnerable when it is not in use, but when it is, the internal parts are zipping around to access various bytes at hundreds of mph. Even when the system is not in operation, moving parts are riskier than those permanently locked into place. ### 2. Speed The groundbreaking drive option operates much more strongly than its alternative, offering over 100 times the load rate. Specific advantages of its level of performance include the following: - data retrieval with almost no latency - expedited rebooting - transfer of files at a more rapid pace. The proximity of data to the read-write heads within an HDD determined the speed of accessibility. With an SSD, 100% of the drive is directly accessible. The traditional drive takes longer to get started and continues to lag behind the new drives when in action. As we all know, speed is half the battle in business, with particular emphasis on your IT system. PCMark consistently gives [better performance ratings](http://www.futuremark.com/hardware/ssd) to solid-state drives (with scores between 4700 and 5270 versus 3300 for the typical hard drive). ### 3. Energy-efficiency OCZ claims that an SSD does not require as much energy to run as does a hard drive. However, that claim is uncorroborated by PC Magazine. Part of the confusion over power consumption is that, apparently, there was not a valid argument for efficiency in the past. A [well-circulated](http://www.engadget.com/2008/07/01/ssds-save-battery-power-right-wrong/) 2008 study by Tom’s Hardware, called “The SSD Power Consumption Hoax,” suggested evidence was not there at the time for this supposed benefit. However, the technology (needless to say) developed over time and actually does now use less power (good both for environmental friendliness and cost savings). IT blogger Adrian Otto found in a 2013 analysis that – shockingly – SSD is 5.4 times more efficient than SATA, the format of standard hard drives. This is positive for several reasons: - reduction in power costs - alleviation of strain generated by excessive wattage flowing through the server - minimization of heat. Regarding the last point, heat is the enemy of anyone needing an affordable IT environment. Cooling typically represents the primary element of operating expenses for a data center. Using cooler systems allows hosting providers to pass energy savings on to their clients. ### 4. Disk fragmentation The design of the traditional drive means that it is optimized for large files that rest in adjacent blocks. That type of storage makes it simple for the drive head to read data swiftly. However, if room on the drive becomes scarce, files fragment into pieces stored in numerous places. Hard drive developers have gradually made fragmentation less of an issue. Still, it’s a nonissue for the new type of drive: all equipment is accessible to the same immediate degree. Fragmentation inevitably slows down computing. Avoiding it automatically improves your performance. ## **The Best Option** As you can see, this new type of drive represents a significant advancement compared to traditional drives. They offer greater stability, higher speed, optimal energy efficiency, and fragmentation from the equation. That’s why we switched all our drives to cloud server hosting clients to 100% enterprise-grade solid-state cloud servers housed in one of our world-class [HIPAA-compliant data centers](https://www.atlantic.net/hipaa-data-centers/).  Learn more about our [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/). ![How Solid State Drives Benefit Your Cloud Computing - Comic](https://www.atlantic.net/wp-content/uploads/2014/03/Comics-Strips-Atlantic-15-001.jpg) --- # HIPAA Compliant Hosting for a Web Application – A Real World Scenario > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-hosting-web-application-real-world-scenario-part-1-2/ | Published: 2014-03-25 | Updated: 2024-11-14 | Author: Sam Guiliano Medical organizations – including healthcare practitioners, plans, and clearinghouses – are considered *covered entities* under the Health Insurance Portability and Accountability Act (HIPAA) of 1996. HIPAA was enacted to safeguard the security and privacy of patients’ protected health information (PHI). Healthcare companies must be compliant with the law to avoid hefty fines. They can choose to work with HIPAA-compliant *business associates*, such as web hosting companies if they choose. Just as with any aspect of business, not all IT infrastructure needs are the same. Medical companies require [HIPAA compliant hosting solutions](https://www.atlantic.net/hipaa-compliant-hosting/) for a wide variety of scenarios. A storage environment, a real-time backup system, or a general website solution might be needed. A healthcare company might also want to run an application with all PHI expertly and redundantly secured. We offer broad information about HIPAA on our site and have covered the topic regularly on our blog. Occasionally, we report scenarios based on actual interactions between our hosting consultants and new customers in this “Real World Scenario” series. Today, we will discuss a client’s request for a HIPAA compliant web application environment. ## HIPAA compliant application hosting Client: We are looking for an appropriate, HIPAA-compliant hosting solution for a product that will provide a web application and web service interface for users to save and maintain [omitted for customer privacy] data. Do you have existing customers that have similar products? Consultant: We provide HIPAA compliant hosting platforms for our customers based on individual specifications. We cannot provide you with specific information concerning what our customers are hosting because we have NDA’s in place for all of our customers. Here is a case study on one customer, though. Client: How are you prepared to demonstrate to us that you are following [HIPAA Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) compliance? Consultant: We provide HIPAA-compliant platforms, and our healthcare customers host their services on the platform. We have attached a document that will provide you with the smallest environment based on Linux and Windows operating systems. The platform has all of the components that are required under the law. Client: How long have you been following HIPAA compliance? Consultant: We have been hosting compliant healthcare platforms for over 5 years, and we have been in business for 21 years. We have also attached a copy of our Business Associate Agreement for your review. Please list any other specific requirements that you require. We are also available for a conference call if you wish to discuss your needs by phone. Client: Thanks for your quick response. We want to run an ASP.NET web application and a WCF web service on the hosted web server, and we expect to connect to a hosted SQL Server instance – all of which necessitate a Windows platform. Consultant: I have attached the formal proposal. It is based on a Windows Hosted Platform. You have a choice of using either Windows Standard 2008 R2 or Windows Standard 2012 R2 as the operating system. If you would like the pricing for MS SQL, we will need to know what version you require. You also have the choice of using your own MS SQL license if you own one. Client: The difference between virtualized and non-virtualized is unclear to us for our solution – what advantage through your hosting is gained by using a non-virtualized platform as opposed to a virtualized one? Consultant: The advantage of using a Virtualized system is creating two Virtual Machines on one server. One would be the Web Server, and the other one would be the SQL server. This would save you money because you then do not have to deploy individual hardware for each application. Because you are using MS SQL, the one server will need to be a high-performance platform, or you will not operate properly. This means that we will need to maximize the amount of RAM at 32 GB, provide four hard drives in a RAID 10 configuration with a High-Performance LSI 9260 RAID Card. Client: Our total storage should initially require 200 Gigabytes at most (not including any backups). Consultant: To create the Web and SQL Virtual Machines on the same server, we need to use a RAID 10 configuration for the hard drives. This means that we will need to use ( 4 ) 500 GB hard drives so that you will have 1TB of Storage Space available to you – the smallest amount of storage capacity that we will provide with this configuration. The Fully Managed Daily Backup that we provide is not conducted on your server. We complete and store the backups on an external storage device and offer redundant backup on our SSD Cloud Server platforms. [**NEXT >>>**](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-hosting-web-application-real-world-scenario-part-2-2/) ## Conclusion We have similar conversations every day as a trusted [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) provider that serves medical companies, including Complete Healthcare Solutions. If you need to discuss any HIPAA compliant IT needs, our hosting consultants are available 24/7 to answer any questions. Fully customized solutions are available. ![Comic: comparison of PHI to phi (the golden ratio) - Comic](https://www.atlantic.net/wp-content/uploads/2014/03/Atlantic.net-Comic-March-1-001.jpg) Comic words by Kent Roberts & art by Leena Cruz. --- # Atlantic.Net Unveils SSD Cloud VPS Hosting Platform with 100 Times Faster Speed > URL: https://www.atlantic.net/press-releases/atlantic-net-unveils-ssd-cloud-vps-hosting-platform-100-times-faster-speed/ | Published: 2014-03-25 | Updated: 2024-06-11 | Author: Editorial Team Latest SSD Technology Delivers Superior Performance **ORLANDO, FL – March 25, 2014 –** Atlantic.Net, a world-class cloud VPS hosting solutions provider, is now offering an SSD Cloud Platform to new and existing customers. The Enterprise SSD’s (Solid State Drives) are up to 100 times faster than the previous storage solution provided to the company’s customers. This enables Atlantic.Net customers faster start-up time, random access time, data transfer rate and read performance. “Our customer’s ever increasing performance requirements require greater speeds and faster access, and solid state drives are the natural evolution,” said Josh Simon, Director of Data Center Services for Atlantic.Net. “This supports our goal to deliver a stellar, reliable and affordable product that ultimately exceeds our customers’ expectations.” Atlantic.Net’s Cloud VPS Hosting plans start at only $0.00135 per hour (or $0.99 per month), with usage calculated on a per second basis. For a limited time, Atlantic.Net is offering up to 30% off all Cloud VPS plans including backup and 1TB outbound data transfer included on every server. This new environment represents complete re-engineering, utilizing the latest and most stable virtualization technologies and Enterprise Solid State Drives. The new SSD Cloud Platform features updated core networking, with new switches and routers, and new 32 and 64-bit Operating System images for Windows and Linux Cloud Servers. **About Atlantic.Net:** Atlantic.Net is a web hosting provider specializing in offering cloud server hosting, HIPAA compliant and hybrid hosting, private virtualization, and VPS hosting in the cloud. With a range of security certifications and a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited data center that the company owns and operates, the company is also known for its reliability, as dictated by its 100% uptime service-level agreement (SLA). For more information, please visit www.atlantic.net[.](https://www.atlantic.net/) Connect with Atlantic.Net: Like us on Facebook: [Facebook](https://www.facebook.com/AtlanticNet?v=wall) Follow us on Twitter: [Twitter](https://twitter.com/atlanticnet) Connect on LinkedIn: [Linkedin](http://www.linkedin.com/company/atlantic.net-inc) Watch videos on YouTube: [Youtube](https://www.youtube.com/user/AtlanticHosting) Pin us on Pinterest: [Pinterest](http://www.pinterest.com/atlanticnet/) Read our blog: [Blog](https://www.atlantic.net/blog/) Media Contact: **Jan Jahosky** 407.331.4699 jan.jahosky@atlantic.net   --- # HIPAA Compliant Hosting for a Web Application – A Real World Scenario (Continued) > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-hosting-web-application-real-world-scenario-part-2-2/ | Published: 2014-03-26 | Updated: 2024-11-14 | Author: Sam Guiliano [**<<< PREVIOUS**](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-hosting-web-application-real-world-scenario-part-1-2/) This interaction between a hosting consultant and client, a two-part installment of our “Real World Scenario” series, continues from the previous post. The client is getting answers to questions regarding an [HIPAA compliant web hosted](https://www.atlantic.net/hipaa-compliant-hosting/) application environment. ## HIPAA compliant application hosting – continued dialogue Client: Our maximum number of users initially will not exceed 200 – we expect there to be very few users at the outset. Consultant: This system will be able to handle 200 users with no problem and most likely twice that amount, depending how much total Storage Space you will require in the future. It is simple to add more Storage Space when you need it. Client: Per our limited understanding of HIPAA, we expect that separate servers for the data (SQL) and the web server will be necessary (but correct us if that is not the case). Consultant: You will have separate servers, but they will be set up as Virtual Machines on one physical server. Client: We also understand that an SSL certificate is required on the web server for the web service and web application to encrypt data at the transport layer. Consultant: That’s correct. We have included pricing for the SSL certificate. The certificate is $150.00. $125.00 of it is the annual fee for the certificate, and $25.00 is a setup fee. We use GeoTrust to provide the SSL certificate, but if you want to use someone else and can find better pricing, you are welcome to provide your own SSL. Either way, we will install the SSL certificate for you. Client: Do we need to use Transparent Data Encryption on the database? Or do you believe that the server on which our SQL Server database resides will already be sufficiently protected with regard to HIPAA? Consultant: We are unable to answer this question, because we are unaware of what security protocols your company has in place for their applications, databases, and systems. The majority of our clients do not use TDE on their DBs. Client: What kind of connections/transactions should we track for the purposes of HIPAA? How much tracking can be done through the host’s provided system, and how much should be done through our own application code? Consultant: We provide logs that are necessary for the devices within our [HIPAA compliant systems](https://www.atlantic.net/hipaa-compliant-hosting/).  However, we are unable to answer the question completely, because we do not have complete knowledge of your specific application. Please supply us with more information on your systems, and we will provide specific information that fits your needs. These are the highlights of our proposal, and what we have proposed is the least expensive solution we can provide that will meet your requirements. HIPAA requires all of below components in order to host in a HIPAA compliant environment: 1. Fully Managed Hardware Firewall with Intrusion Detection and Log Management / Log Monitoring. Also ( 5 ) encrypted managed VPN’s 2. Fully Managed Daily Backup for all files and databases 3. Private Server Hardware with 32 GB of RAM and 1 TB of Storage, configured in a mirrored RAID 10 configuration 4. 10 TB of Monthly data transfer with a 100 Mbps Port 5. 24 X 7 X 365 Technical Support by Phone or email 6. 100% Uptime SLA (Service Level Agreement) 7. Business Associate Agreement 8. This Private HIPAA hosting platform will be in an SSAE 16 SOC II audited data center 9. SSL certificate 10. Kapersky Anti-Virus. I have also attached the document that details our Fully Managed Hardware Firewall, Intrusion Detection System, and Fully Managed Daily Backup. Client: How can you guarantee 100% uptime? Aren’t there situations in which the system will inevitably go down? Consultant: Our 100% uptime SLA expresses two commitments: - *Belief in our environments:* We believe so strongly in our core infrastructure and the solutions we design for our clients – the levels of redundancy in our networks – that we know downtime will be an extremely rare occurrence. - *Belief that any downtime is unacceptable:* For any of our dedicated hosting solutions, if it takes us more than a short window of time to resolve any issue once a trouble ticket is opened, we will start refunding your monthly fee. Full details are available in our SLA. Client: Thank you for answering all my questions. I will have the Business Associate Agreement to you later today. Take care. Consultant: Thank you for using Atlantic.Net for your hosting needs. Please let us know if you have any further questions. *** ## Conclusion If you are looking for a [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solution, Atlantic.Net has the expertise and conscientiousness to guide you through the process. We have many years of experience with healthcare compliance and a business track-record spanning three decades. Our solutions are characterized by  peace-of-mind, based on our extensive knowledge of IT hosting and 24/7 live support. ![Comic: comparison of PHI to phi (the golden ratio)](https://www.atlantic.net/wp-content/uploads/2014/03/Atlantic.net-Comic-March-1-001.jpg) Comic words by Kent Roberts & art by Leena Cruz. --- # Windows Server 2012 R2 Available for Cloud VPS from Atlantic.Net > URL: https://www.atlantic.net/press-releases/windows-server-2012-r2-available-cloud-vps-atlantic-net/ | Published: 2014-03-26 | Updated: 2024-06-11 | Author: Editorial Team *Offers per Second Billing for Windows Cloud VPS Hosting Plans * **ORLANDO, FL – March 26, 2014 –**[Atlantic.Net](https://www.atlantic.net/), a world-class cloud VPS hosting solutions provider, today announced support for Windows Server 2012 R2 operating system with its Cloud VPS Hosting Plans. Windows Server 2012 R2 comes with a new file system, ReFS, and includes dozens of new features, such as IP address management, enhanced user experience, the latest Windows Task Manager, and upgraded server administration for easier cloud computing. “Windows Server 2012 R2 offers advancements that can truly benefit those needing to deploy services on Windows based platforms,” said Josh Simon, Director of Data Center Services for Atlantic.Net. “We are excited to add this new offering to our customers further enhancing their user experience with cost-effective cloud VPS hosting solutions.” The Windows Server 2012 R2 is a great solution for customers needing power and speed to run applications remotely. Atlantic.Net Cloud VPS clients can test the new tools offered by the Windows 2012 R2 operating system and pay via a usage model on a per-second basis, without having to incur upfront licensing costs. Atlantic.Net’s Windows Cloud VPS Hosting plans start at only $0.0205 per hour (or $14.97 per month), with usage calculated on a per second basis. For a limited time, Atlantic.Net is offering up to 30% off all Cloud VPS plans and 3TBs outbound data transfer included on every server. For more information, please visit [VPS hosting](https://www.atlantic.net/vps-hosting/). **About Atlantic.Net:** [Atlantic.Net](https://www.atlantic.net/) is a web hosting provider specializing in offering cloud server hosting, HIPAA compliant and hybrid hosting, private virtualization, and VPS hosting in the cloud. With a range of security certifications and a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited data center that the company owns and operates, the company is also known for its reliability, as dictated by its 100% uptime service-level agreement (SLA). For more information, please visit [www.atlantic.net](https://www.atlantic.net/). Connect with Atlantic.Net: Like us on Facebook: [Facebook](https://www.facebook.com/AtlanticNet?v=wall) Follow us on Twitter: [Twitter](https://twitter.com/atlanticnet) Connect on LinkedIn: [Linkedin](http://www.linkedin.com/company/atlantic.net-inc). Watch videos on YouTube: [Youtube](https://www.youtube.com/user/AtlanticHosting) Pin us on Pinterest: [Pinterest](http://www.pinterest.com/atlanticnet/) Read our blog: [Blog](https://www.atlantic.net/blog/) Media Contact: **Jan Jahosky** 407.331.4699 [jan.jahosky@atlantic.net](mailto:jan.jahosky@atlantic.net) --- # Atlantic.Net Adds Latest Ubuntu LTS for All Linux Cloud VPS Hosting Plans > URL: https://www.atlantic.net/press-releases/atlantic-net-adds-latest-ubuntu-lts-linux-cloud-vps-hosting-plans/ | Published: 2014-03-28 | Updated: 2024-06-11 | Author: Editorial Team #### *Expands Live Technical Support 24x7x365* **ORLANDO, FL – March 28, 2014 –**[Atlantic.Net](https://www.atlantic.net/), a world-class cloud VPS hosting solutions provider, has added Ubuntu, 12.04.4 Long Term Support (LTS) to its Linux Cloud VPS Hosting Plans. Ubuntu is the most popular open-source Linux operating system, fully supported by Canonical and with a core focus on stability. “We are excited to introduce the latest Ubuntu LTS release to our user base,” said Josh Simon, Director of Data Center Services for Atlantic.Net. “We anticipate that the developer community will take advantage of the many powerful features offered by Ubuntu LTS operating system and will appreciate state-of-the-art SSD Cloud VPS Platform.” As an open source development project, the current release of Ubuntu LTS enhances stability, performance and security. Atlantic.Net customers benefit with faster start up time, increased flexibility and efficient computer commands. All Atlantic.Net Cloud virtual servers provision in less than 30 seconds and include a minimum of 1TB of outbound data transfer with 1GB port, unlimited inbound data transfer, DNS management and 24/7/365 live technical support. Atlantic.Net’s Linux Cloud VPS Hosting plans start at only $0.00135 per hour (or $0.99 per month), with usage calculated on a per second basis. For a limited time, Atlantic.Net is offering up to 30% off all Cloud VPS plans. For more information please visit [https://www.atlantic.net/vps-hosting/](https://www.atlantic.net/vps-hosting/). **About Atlantic.Net:** [Atlantic.Net](https://www.atlantic.net/) is a web hosting provider specializing in offering cloud server hosting, HIPAA compliant and hybrid hosting, private virtualization, and VPS hosting in the cloud. With a range of security certifications and a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited data center that the company owns and operates, the company is also known for its reliability, as dictated by its 100% uptime service-level agreement (SLA). For more information, please visit [www.atlantic.net](https://www.atlantic.net/). Connect with Atlantic.Net: Like us on Facebook: [Facebook](https://www.facebook.com/AtlanticNet?v=wall) Follow us on Twitter: [Twitter](https://twitter.com/atlanticnet) Connect on LinkedIn: [Linkedin](http://www.linkedin.com/company/atlantic.net-inc). Watch videos on YouTube: [YouTube](https://www.youtube.com/user/AtlanticHosting) Pin us on Pinterest: [Pinterest](http://www.pinterest.com/atlanticnet/) Read our blog: [Blog](https://www.atlantic.net/blog/)  # # #  Media Contact: Jan Jahosky 407.331.4699 jan.jahosky@atlantic.net --- # Securing PHI for Behavioral Healthcare Organizations – A Real World Scenario > URL: https://www.atlantic.net/hipaa-compliant-hosting/securing-phi-behavioral-healthcare-organizations-real-world-scenario/ | Published: 2014-03-31 | Updated: 2024-10-03 | Author: Sam Guiliano Our site shares a large amount of information with medical companies about finding viable [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and infrastructural solutions. We’ve found that the general information we provide meets the needs of many businesses. However, it also assists many professionals to be able to get a feel for the process through specific situations. Our Real-World Scenario series serves this function. We show actual discussions between our hosting consultants and clients as they get their questions answered about our services through this series. In this installment, a web developer works with our representative to determine the best solution for securing protected health information (PHI) of behavioral healthcare firms within a HIPAA-compliant environment. ## The Basics: HIPAA, PHI, and Behavioral Healthcare Before we look at an individual interaction related to these issues, it will help to understand the basic terms we are using. The *Health Insurance Portability and Accountability Act (HIPAA) of 1996* safeguards patients’ medical records, with a special focus on electronic medical records (EMR). The three basic categories of organizations that must meet the law’s specifications include healthcare practitioners, plans, and clearinghouses. All data that must meet the HIPAA requirements are referred to as *protected health information (PHI)*. PHI includes demographics, medical history, tests, insurance details, and other data that healthcare companies compile from patient documents, equipment, and practitioner observation. HIPAA places guidelines on the scope of protected health information that medical organizations can acquire, the extent to which it can be shared, and its usability for marketing purposes. PHI has to be fully accessible to the patient, who also has the right to correct any errors in the data. It cannot be sold except in situations that involve government projects or the sale of an entire healthcare organization. *Behavioral healthcare* is a multidisciplinary area of medicine that focuses on the mental and emotional state of the individual. Many people use it synonymously with the terms *psychological healthcare* or *mental healthcare*. Practitioners in this field understand the behaviors of a patient – called *biobehavioral interactions* within the specialty – as indications of the health of a patient’s mind. ![government compliance joke - comic](https://www.atlantic.net/wp-content/uploads/2014/03/Atlantic-Comic-March-8-001.jpg) ## HIPAA Compliant Behavioral Healthcare Solution The following is the interaction between our hosting consultant and a client who needs an IT environment for their PHI. Consultant: Tell us about your hosting needs. Client: I need an architecture for a Windows Forms SQL app for use by a behavioral healthcare company. I have a client with four locations that want to go this route over the traditional MPLS or hardware VPN combined with a local server. Consultant: One of our hosting specialties is HIPAA compliance and the protection of PHI. We can create a network of this type is to host the SQL server in our data center. Each location would then be connected to the SQL server through an Encrypted VPN. The hosting platform would be HIPAA compliant, and we would issue a Business Associate Agreement (BAA) for the hosting services. To provide you with a proposal, we require the following information: 1. How much Total Storage Space do you require for the data? 2. What version of MSSQL do you require? Client: We would need a minimum of 20GB of storage, and the MSSQL could be 2008 or above. Consultant: The smallest HIPAA-compliant hosting platform that we have available includes 500 GB of Storage Space. I have attached the formal proposal along with a copy of the Business Associate Agreement for your review. Please submit the SQL license, and we can then load it for you. We are not allowed by Microsoft to resell their licenses; it is also less expensive for you to purchase it outright than to lease it from us. Below are the highlights of the proposal: 1.) Windows Standard 2008 R2 64 Bit Operating System 2.) Dual-Core I3-3220 Processor w/HT / 8 GB of Ram / 500 GB of RAID Storage - Core I3 - 3220 3.3 GHz Dual Core w/HT - 8 GB of RAM (expandable to 32 GB) - 2 X 500 GB SATA 3 Black Raid 1 - LSI 9240 RAID Card – 10 TB  of Monthly Data Transfer, 100 Mbps Port 3 ) Fully Managed Hardware Firewall with ( 5 ) managed VPN’s 4 ) Intrusion Detection System with Log Monitoring and Management 5 ) Fully Managed Daily Backup 6 ) 100% Uptime SLA 7 ) 24 X 7 X 365 Live Technical Support by phone / email 8 ) SSAE 16 SOC II Data Center 9 ) Anti-Virus Protection 10 ) SSL Certificate. Client: Excellent. I will get the Business Associate Agreement to my client immediately and be in touch once I hear back from them. Thank you for the assistance. Consultant: Let us know if you have any additional questions. Have a great day. As indicated by the above interaction, Atlantic.Net is well prepared for those in need of [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) on a reliable HIPAA Server. We have been in business for three decades, with a five-year track record helping companies fulfill the parameters of healthcare regulations. Comic words by Kent Roberts & art by Leena Cruz. --- # FreeBSD Hosting – 9 Reasons to Use FreeBSD for Your Cloud Hosting Setup > URL: https://www.atlantic.net/hipaa-compliant-hosting/freebsd-hosting-ssd-cloud-vps-9-reasons/ | Published: 2014-04-08 | Updated: 2024-10-03 | Author: Kent Roberts Why choose FreeBSD for your operating system? When people consider operating systems for their hosting environments, the two most common choices are Windows and Linux, options under Atlantic.Net’s cloud hosting solutions. However, another OS has been steadily gaining traction since its initial development in 1993 – FreeBSD. FreeBSD, like Linux cloud hosting, is a spinoff of the UNIX® operating system. The benefits of the former OS are similar to those of the latter one. Both have proven popular because they are both free and open source. Because there are no licensing fees with either one, they are cost-effective. Because they are open source, they are built optimized for freedom and flexibility. Also, their popularity – in conjunction with their backing by the open-source community – has generated vast networks of support on forums and elsewhere. The lesser-known operating system offers particular benefits that have prompted some users to prefer it over the various Linux distributions. ## What Is FreeBSD? It is an OS primarily concerned with three [elements of computing](http://www.freebsd.org/about.html): stability, performance, and functionality. It is a variation of [BSD](https://en.wikipedia.org/wiki/Berkeley_Software_Distribution), which was developed at the University of California – Berkeley and distributed by the institution’s Computer Systems Research Group (CSRG) from 1977 to 1995. The operating system, like Linux, is developed on a community basis by a broad pool of users. ## 9 Benefits of FreeBSD Specific advantages of the operating system – garnered by comments from BSD users – include the following: 1. *Community* This OS is centered, first and foremost, on its community. Although corporations use the operating system and, at times, assist with its development, the integrity of the community approach is maintained at all times. Interaction occurs between veteran and rookie users on forums and through Internet Relay Chat (IRC). Advice is dispersed through email newsletters as well. A Core Team is elected by the community for monitoring and management, but it mostly resolves conflicts between developers rather than steering the direction of the OS. 2. *Stability* When people talk about *an operating system’s stability, they* mean that it is unlikely to crash. This OS goes beyond that expectation. When you upgrade the software, you don’t have to do the same for users. The appearance is never changed for aesthetic purposes; instead, it is adapted with a strong argument for making changes. Any new version of the OS is capable of running code from previous versions as well. All aspects of the system and kernel are developed as one package to avoid upgrading difficulties. 3. *Collaboration* FreeBSD was one of the first operating systems to adopt the LLVM infrastructure. Several developers within the community also contribute to LLVM, making both projects stronger and more integrated. Outgrowths of the OS, including the desktop offering PC-BSD and the firewall pfSense, are created in collaboration with the most recent operating system version. 4. *Ease-of-use* Every service contains a script that activates and deactivates it. The OS includes a file with simple commands for the initiation and configuration of various primary services. You can immediately know what services are enabled as the OS starts to run. The system understands the relationship between various services and will run them simultaneously or independently, as best fits the situation. 5. *Ports* You have full access to a library of independent applications. If the community disagrees about the latest versions of certain programs, you can choose which version you want. Unlike some competitive operating systems, there is a set folder for independently developed applications, making it simple to clean a server of all installations as desired. 6. *Security* Several of the security components of this operating system include the following: - Jails are components of the OS that allow you to run an application without affecting anything else on your system. - Mandatory Access Control makes it possible to determine limitations of control for all resources. - Capsicum allows you to isolate privileges so that potential negative effects of a maliciously altered script are minimized. 7. *GEOM* This tool enables robust storage within FreeBSD. With GEOM, you can use two servers for redundancy and reliability, adjusting your RAID configuration as desired. 8. *Sound* You can mix sound quickly and accurately with volume that can be adjusted within any program you run. 9. *Options* This OS is open and completely prepared for extensions, such as KDE or GNOME. You can run it through a serial port with full configuration capabilities. You can install whatever desktop you want as well. ![Why to Use FreeBSD for Your SSD Cloud Hosting? Comic](https://www.atlantic.net/wp-content/uploads/2014/04/Atlantic-Comic-March-5-001.jpg) ## Getting Started with FreeBSD Through a community-driven model, FreeBSD offers an operating system that serves as a strong alternative to Linux. Also free and open-source, the OS is known for its stability, ease-of-use, security, and collaboration with various third-party applications. Check out our helpful how-to on [getting started with your FreeBSD cloud server](https://www.atlantic.net/vps-hosting/how-to-get-started-freebsd-cloud-server/). Contact Atlantic.Net to learn more about 100% uptime cloud server hosting now to get started with your FreeBSD hosting environment today – or learn about our [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) options. By Kent Roberts; comic words by Kent Roberts & art by Leena Cruz. --- # HIPAA Web/Database Hosting Solution – A Real World Scenario > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-webdatabase-hosting-solution-real-world-scenario/ | Published: 2014-04-10 | Updated: 2024-11-14 | Author: Kent Roberts Healthcare companies must be in full compliance with federal regulations to avoid fines. The Health Insurance Portability and Accountability Act (HIPAA) contains laws applicable to handling protected health information (PHI) by healthcare plans, clearinghouses, and practices. Title II of the act includes a Privacy Rule and Security Rule, which are of special concern to covered entities when working with business associates – such as web hosting companies – on their IT architectures. Along with the general information we provide elsewhere on our site related to the act, we have previously reviewed requests for legal healthcare database hosting solutions in our Real World Scenario series. This series shares common situations experienced by our customers: we provide dialogues based on actual interactions between our hosting consultants and clients. The below installment will explore an additional HIPAA request to provide a further sense of the attainment of a 100% compliant system. ## HIPAA hosting solution Q & A Client: Hello, I need to obtain a price quote on a web/database platform that will be HIPAA Compliant and support the following resources: ### Web Server - Windows 2008 R2 - 1 CPU - 4GB RAM - Drive 1 – minimum 60GB HD - Drive 2 – minimum 100GB HD - SSL Certificate. ### Database Server - Windows 2008 R2 - 1 CPU - 4GB RAM - Drive 1 – minimum 60GB HD - Drive 2 – minimum 100GB HD - SQL Server 2008 R2. ### Disaster Recovery - Web/Database Server - Windows 2008 R2 - 1 CPU - 4GB RAM - Drive 1 – minimum 60GB HD - Drive 2 – minimum 100GB HD - SSL Certificate - SQL Server 2008 R2. Consultant: Thank you for contacting Atlantic.Net. The only questions we have are as follows: 1. Will you be providing the SQL license? 2. Will you be providing the SSL certificate? Client: Yes, we have a license for the SQL Server. We do not have an active SSL certificate, though. Please include one in the plan you are recommending. Consultant: Attached, you will find our formal proposal. Note that the SQL license is not included, but an SSL certificate is. We have also attached a document detailing our hardware firewall and intrusion detection system (IDS), along with a copy of our business associate agreement (BAA) for your review. Here are the highlights of our proposal: 1. Windows Enterprise 2008 R2 Operating System – which will allow for the creation of up to (4) virtual machines, one more than you require 2. Dual-Core i3-3220 processor with Hyperthreading (which will provide you with 4 virtual cores to work with for the VM’s) / 32 GB of Ram / 1 TB of RAIDed Storage Space 3. Fully Managed Hardware Firewall w/ 5 encrypted VPN’s 4. Intrusion Detection System with Log Management 5. Fully Managed Daily Backup – files/database / VM snapshots 6. 3220 3.3 GHz Dual Core w/HT 32 GB of RAM – 2 X 1TB 7. SATA 3 Black RAID 1 8. LSI 9240 RAID Card 1 9. 10 TB of Monthly Data Transfer 10. 100 Mbps Port Multi-Homed Bandwidth 11. SSL Certificate 12. 16 IP’s 13. Private Hosting Platform 14. Mail 15. 24 X 7 X 365 Live Technical Support by Phone or Email 16. 100 % uptime SLA on all of the services we are providing 17. Business Associate Agreement (BAA) for HIPAA compliance (based on the inclusion of all the hosting components we have listed) 18. 12- and 24-month term pricing. Please let us know if anything needs clarified or you have any further questions. Client: I’ve noticed that you have SSAE 16 (SOC 1) Type II certification listed as one of your HIPAA attributes. How is that relevant to healthcare computing? Consultant: That certification is from the Statements on Standards for Attestation Engagements (SSAE), the protocols and parameters designed and revised by the American Institute of Certified Public Accountants (AICPA). It’s a set of auditing guidelines that verifies the integrity of our infrastructure and the mechanisms in place to avoid breaches and/or corruption. It generally validates our security. Client: Okay, I’m also curious what type of SSL certificate you will purchase and install on our behalf. Consultant: We use GeoTrust. A 2010 Netcraft survey revealed that SSL certificates provided by GeoTrust are used more than any other brand among the Alexa 1 million (the 1 million sites that receive the most unique visits annually). GeoTrust QuickSSL Premium certificates are also backed by a $500,000 USD warranty. Client: Thank you for the assistance. I have submitted the BAA to our lawyer and will reach out to you as I know more. ## Affordable solutions for healthcare IT The necessity of healthcare organizations to achieve a [HIPAA compliant database](https://www.atlantic.net/hipaa-compliant-hosting/) requires specialized care from a [HIPAA hosting](https://www.atlantic.net/hipaa-compliant-hosting/) service. In business for three decades and serving medical organizations with their regulatory concerns for five years, Atlantic.Net has the experience to meet your needs with an SSD Cloud Server so that your patients’ PHI data remain secure and private at all times. By Kent Roberts; comic words by Kent Roberts & art by Leena Cruz. ![HIPAA humor PHI](https://www.atlantic.net/wp-content/uploads/2014/04/Atlantic-Comic-March-10-001.jpg) --- # Maintaining and Testing the Speed of a Website is Critical > URL: https://www.atlantic.net/vps-hosting/test-ip-address-gauge-cloud-vps-speed-real-world-scenario/ | Published: 2014-04-11 | Updated: 2024-10-21 | Author: Kent Roberts It’s sometimes difficult for hosting service customers to determine which plans and companies will best meet their needs. This challenge has become more pronounced in the era of virtual private servers (VPS’s) and cloud computing. Although distributed virtualization has strongly positive attributes – speed, reliability, redundancy, cost-effectiveness, etc. – it also can be unclear exactly what you are getting. One of the best ways to use a blog is to draw on customer questions and turn individual conversations into education for a broad audience. That way, we answer common concerns while always respecting the privacy and sensitivity of any information stated during the interaction. We call the series of articles derived from our specific user communications “Real World Scenarios” (RWS). In this installment of RWS, we look at speed as a factor for customers. Why is speed important? How do you determine the speed of a hosting environment? Let’s look at the issue both broadly and then in the context of an actual interaction between our [VPS Hosting](https://www.atlantic.net/vps-hosting/) consultant and a client. ## Why Speed Is Critical for Websites There are two basic reasons and one more complex reason why speed is crucial if you want to succeed with your site. Basic reasons: 1. *The data reason* – Your prominence on the search engines is determined, in part, by how fast it loads. 2. *The human reason (Part A)* – One of the top considerations of anyone who wants to optimize their site should be user experience (UX). Waiting for a site to load can make a person feel stuck in the technological vortex. Slow load times cause frustration, and that means poor UX and rapid flight from your site to one that won’t feel like it’s wasting the user’s time. Put another way, the people visiting your site like feeling control. Complex reason: 1. *The human reason (Part B)* – Our attention spans and memories are shorter and less reliable than we like to think. When we wait, the data in our short-term memories starts to deteriorate, and we become less capable of meaningfully connecting what we are experiencing. That’s the essential [argument offered](http://www.masternewmedia.org/why-website-speed-and-page-load-times-are-so-important-to-your-online-readers/) by Jakob Nielsen, Ph.D. of the Nielsen Norman Group, and it makes sense. ## How to Test a Live Site There are numerous tools online to determine the speed of your site in its current setting. One of the most reliable ones is [through Google](http://www.google.com/webmasters/tools/). Go to Webmaster Tools > Other Resources > PageSpeed Insights. You’ll get a score from 1 to 100, along with notes on why your site is slower than it could be and recommendations to optimize it. That’s for testing the speed of a live site, though. Things get trickier when you want to test the speed of a hosting service before you sign on as a client. The below discussion details a customer concerned with speed, along with the tool we recommend to showcase the strong performance of our network. ## Request to Test a Cloud VPS System Client: Hi, do you guys accept Visa debit cards? Consultant: Yes, we do. Client: Okay. I think I want to rent the XSmall package. Before I do that, though, I need to test one of the sites currently running on this type of server. Consultant: We do not provide free trials. You can create a server under the hourly rate. When you have finished your test, you can delete it. You will only be charged for the hours you have online. We use 100% SSDs (solid-state drives), which exhibit up to 100 times the speed of standard HDDs (hard disk drives). Client: Can you please give me the URL of a website currently running on your $4.97 per month server? Consultant: Unfortunately, we cannot provide you with information on any customers who use our data center. However, your response time should be comparable to [this test link](https://www.atlantic.net/speed-test/). Client: Great. Just one second. Let me test it right now if that’s OK. Consultant: Sure, let me know when you are finished. Client: OK, it looks good. Consultant: Our smallest plan currently costs as low as $0.99 a month. I would recommend signing up for that plan (XXSmall Linux) due to the low cost associated with the service. That way, you can test it while only incurring a small fee. Client: I appreciate it. Actually, I’m going to go ahead with the XSmall. I know I’m going to need those extra resources, and the speed looks fine. Thank you! Consultant: Thank you for using Atlantic.Net. Please let us know if you have any further questions. ## SSD Cloud VPS through Atlantic.Net If you are interested in any of our Cloud Hosting or  Cloud VPS, you can take advantage of our publicly available speed testing. If you choose us for your hosting needs, you will get access to live consultants 24/7, exhibiting the same expertise and courtesy experienced by the client above.  See our [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). ![Maintaining and Testing the Speed of a Website is Critical Article - Comic](https://www.atlantic.net/wp-content/uploads/2014/04/Atlantic-Comic-March-2-001.jpg) By Kent Roberts --- # 2 Real World Addition & Healthcare Startup Scenarios > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-heroin-epidemic-problem-healthcare-startup-private-hosting-platform-solution-2-real-world-scenarios/ | Published: 2014-04-17 | Updated: 2024-10-03 | Author: Sam Guiliano As providers of [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) infrastructures, we publish as much information as possible to help healthcare companies understand the law and find appropriate solutions, whether with another company or us. Along with describing this information generally on our site, we also publish Real World Scenario articles (such as this one) on our blog, allowing customers to see compliance in a real-life example interaction between our representatives and customers. However, there is also a compelling story in the news – as of NBC News [yesterday](http://www.nbcnews.com/news/investigations/police-officials-say-patient-privacy-law-pulls-shroud-over-drug-n82561) – regarding problems related to patient privacy and developing strong plans of action to understand drug abuse. That cultural issue generally relates to the topic of HIPAA and its Privacy Rule, so we will explore it before transcribing a HIPAA private hosting case study. ## Police Complain About Healthcare Privacy Laws Police departments are having difficulty targeting drug abuse, particularly heroin, because they can’t access overdose data. The heroin epidemic has been escalating for the last ten years, according to police officers at a conference on illegal street drugs that convened on Wednesday, April 16, in the American capital. The event was an inaugural effort by the Police Executive Research Forum to spread ideas and concerns related to drug abuse prevention. The message repeatedly delivered at the event was that OD information has become scarce in the US, with healthcare laws such as HIPAA to blame. One speaker, an active police professional, stated that the only way he could get access to autopsy information was through a subpoena. The Chief of Police in Philadelphia noted that personal identity was not the concern. What was needed was the general data so those police officers could better understand local trends. Growing concern over drug deaths within the law enforcement community is not misplaced: Center for Disease Control (CDC) data reveals that fatalities related to ODs have more than doubled since the turn of the millennium, with a 102% rise between 1999 and 2010. Heroin and other opioid compounds – such as those in Oxycontin and Oxycodone – have been responsible for many deaths. Representatives of the DC Medical Examiner and the NYPD argued that what was needed was a real-time system to provide health data to police officers nationwide. An application called Compstat, undoubtedly based on a cloud model for speed and affordability provides data on related crimes to officers, so they can have relevant information immediately and perform investigations much more rapidly and effectively. Although many officers feel that HIPAA and similar consumer protections are standing in the way of their ability to forecast crime patterns, some officials are adapting their approaches to get access to drug location information indirectly. The police in DC are using GPS technology in combination with naloxone (a common first-responder treatment intended to avoid an overdose) administration location data to determine central OD areas. ![HIPAA misunderstanding joke](https://www.atlantic.net/wp-content/uploads/2014/04/Atlantic-Comic-April2-001.jpg) ## Private HIPAA Compliant Solution for Startup Consultant: Welcome to Atlantic.Net. Please tell us about your hosting needs. Client: We are working on a healthcare startup and would like to know how much your HIPAA compliant hosting solutions cost. Consultant: We can build any size of [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) platform, but the smallest HIPAA compliant package that we can offer is attached, in the form of a pricing proposal. We have also attached a copy of our Business Associate Agreement (BAA) for your review. The hosting platform consists of the following components that are required to be HIPAA compliant: 1. Private Hosting Platform (No shared resources) 2. Fully Managed Hardware Firewall with encrypted VPN’s 3. Fully Managed Intrusion Detection System (IDS) 4. Fully Managed Daily Backup 5. SSL Certificate. Please contact us if you have any questions after you review our proposal (below). **PROPOSAL FOR Private [HIPAA Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)Platform** - 12 Month / 24 Month - Fully Managed Hardware Firewall w/ 5 VPN’s - Intrusion Detection System / Log Management - Private Hosting Platform - Windows Standard 2008 R2 64 Bit - Core I3 – 3220 3.3 GHz Dual Core w/HT 8 - GB of RAM (expandable to 32 GB) - 2 X 500 GB SATA 3 Black RAID 1 – LSI 9240 RAID Card - Multi-Homed bandwidth - 10 TB of Monthly Data Transfer - 100 Mbps Port - Fully Managed Daily Backup - SSL Certificate - 8 IPs ( included) - 100% Uptime SLA - 24 X 7 X 365 Live Technical Support by Phone or Email.   Client: Great. Thanks for the information. I will share it with my partners and proceed accordingly. Consultant: Thank you for contacting Atlantic.Net. Please let us know if you have any additional questions. ## Viable, Cost-Effective HIPAA Solutions Those in the healthcare field may experience HIPAA frustrations, as do those in law enforcement. However, compliance does not have to be stressful or confusing. Work with a hosting provider with the knowledge you need to assist you without unforeseen difficulties: Atlantic.Net. With five years of healthcare regulatory experience and twenty years in business, we have the expertise any client demands to protect their patients, as is their bottom line.  For a full lineup of popular applications and server options, please consider our [VPS Hosting](https://www.atlantic.net/vps-hosting/) solutions.   --- # SEO Optimized cloud server: Real World Scenario > URL: https://www.atlantic.net/hipaa-compliant-wordpress-hosting/seo-optimized-vps-real-world-scenario-helpful-strategies/ | Published: 2014-04-22 | Updated: 2025-03-06 | Author: Alexander Wise One of the primary concerns of any online business is search engine relevance. Various elements are involved in strong SEO, as discussed in our three-part guide, “[20 Steps to Make Your Content Rank Higher on Search Engines & Increase Conversions](https://www.atlantic.net/pci-compliant-hosting/20-steps-content-rank-higher-search-engines-increase-conversions-part-1/).” One common way to enhance your SERP (search engine result page) standing is to install applications on your server that make your site more attractive to the search engines. Many times our users want to know about the capabilities of our cloud hosting plans. In our Real World Scenario series, we look at common questions that clients ask our staff. The below interaction occurred between our hosting consultant and a client concerning adding SEO tools to a Cloud Server. We will explore that interaction and discuss various options for general search engine optimization with your private cloud server. ## Strong SEO with a cloud server Client: Hi, is it possible for me to add SEO tools to my private cloud server? Consultant: Our cloud server option is unmanaged so that you will have full root/administrative access to the server. You will be able to install any software you need. Please be aware of our Acceptable Use Policy when using the server. Generally speaking, though, you can install whatever you want. Client: Since latency is a factor in SEO, is there any way for me to test your system? Consultant: Yes, this is a [link to the speed test](https://www.atlantic.net/speed-test/), which will give you a sense of latency. If the speed of our cloud hosting environment meets your needs, we will need answers to the following questions to provide you with a proposal. 1. What Operating System do you need? (We offer Windows, Linux, and FreeBSD.) 2. How much RAM? (We offer resources for all sizes of projects and businesses.) 3. How much data storage space? 4. What level of management? (We offer fully managed services with all our infrastructural solutions.) Client: 1. Linux Centos 6.5 2. At least 8GB 3. At least 200GB 4. No need. Consultant: Excellent. Here is a link to our[ Hosting signup](https://cloud.atlantic.net/?page=signup). You will need to choose the XXL plan to meet your storage requirement. Client: Thank you! Consultant: You’re welcome. Have a great day. ## Great SEO strategies for your site You can use a hosting service that offers strong technology built for speed. Fast processing starts with the hardware: solid-state drives (SSDs) offer up to 100 times the speed of hard disk drives (HDDs). Additionally, cloud computing is a structure built to deliver sites in an efficient and streamlined manner. Beyond choosing a reliable service to host your site, you can use the following steps – according to [Justin James of TechRepublic](http://www.techrepublic.com/blog/software-engineer/improve-web-application-seo-with-these-five-tips/#.) – to get better SERP standings as well: 1. *Determine which URL is canonical* – If two URLs lead to the same content (in other words, if one page has two different URLs), the search engines will treat each URL as a separate page. When Google thinks your one page is two different pages, you lose half the power of each URL. A [Google system](http://www.google.com/support/webmasters/bin/answer.py?hl=en&answer=139394) allows you to choose which URL is canonical so that the search engines know which ones you want to be credited. 2. *Show the essential words* – Search engines used to be more susceptible to manipulation by spammers. Some text would be hidden from the typical site visitor, but it would appear in search engines. Search engines had to overcompensate to prevent this form of spam, so they typically do not process text invisible to the average user or only accessible via JavaScript. Don’t conceal the text that is most basic to your SEO efforts. 3. *Disability-conscious sites* – Some elements of site design are beneficial for users who are disabled so that they can understand the content without being able to see or hear it. Search engines also appreciate it when you fill in optional fields better to describe links, images, and other content components. 4. *Optimize your title* – Often, sites are set up to populate a standardized title and description for each page. Search engines have a much stronger preference for sites that display independent information in these fields, even when it’s automated. You can transfer the product name value from your database straight into the title field, for example. 5. *Better HTML* – Sometimes HTML is messy. If the code isn’t streamlined, the load times are increased, damaging your search rankings. James particularly recommends against ASP.NET WebForms if you want your HTML to be clean and quickly scannable. ## Next steps for SEO SEO can be enhanced with a strong cloud hosting service, but several strategies can also assist your Google efforts. By implementing a few simple tactics, you can improve your ranking so that your site reaches its intended audience. We also offer support for [WordPress VPS hosting](https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/) setups, including [HIPAA-compliant WordPress hosting](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/) – sign up today! ![SEO Optimized cloud VPS: Real World Scenario - Comic](https://www.atlantic.net/wp-content/uploads/2014/04/Atlantic-Comic-April1-001.jpg) --- # VPS Mail Server – SMTP for Cloud VPS: A Real World Scenario > URL: https://www.atlantic.net/vps-hosting/smtp-for-cloud-vps-mail-server-a-real-world-scenario/ | Published: 2014-04-24 | Updated: 2024-12-05 | Author: Kent Roberts Looking to set up a VPS mail server? Atlantic.Net can help. We do our best to learn from our customers and provide content in our blog relevant to their needs. While we have broad information available through our site, clients often turn to our support staff for detailed queries. By gathering questions from our hosting consultants, we can better tailor the information we provide to meet user needs. We call this series of everyday interactions between our clients and our consultants Real-World Scenarios. In the below transcript, the client is interested in SMTP for a cloud VPS environment. We will first review the questions and answers, then discuss email methods and another concern addressed – swap files. ## SMTP for a Mail Server Client: I’m looking at the possibility of setting up a new Cloud VPS with about 3 VPS instances: for mail, the web, and database. I have a few questions. I’m primarily looking at Cloud VPS options. First, is your cloud traffic metered or not? Consultant: Only outbound traffic is metered. Please take note that we do provide each cloud server with 1TB of free outbound transfer per month. Client: OK… Would the traffic between two VPS’s in the same data center be metered or slowed due to edge routing or similar? Consultant: Traffic between two VPS’s is not affected by edge routing. Client: Okay, good. Do your VPS’s provide any swap, or does that have to be set up manually as a swap file on the disk after the fact? Consultant: You would have to set up a swap file on the disk. Client: Assuming common VPS standards, do you control the kernel? Consultant: Atlantic.Net does not control the kernel. Client: Will the kernel support TUN/TAP, or is that disabled? Consultant: The kernel should support TUN/TAP: we do not disable it. Client: I notice that SMTP is blocked according to your Cloud VPS FAQ. As mentioned earlier, I intend to run a mail server. Would I be able to get this block lifted for that purpose? Consultant: In order to unblock SMTP traffic, you will need to provide our technical department with a brief description of your intended use. There should be no issues as long as you adhere to Atlantic.Net’s [AUP agreement](https://www.atlantic.net/acceptable-use-policy/). ## What Is SMTP? [SMTP](http://searchexchange.techtarget.com/definition/SMTP) stands for Simple Mail Transfer Protocol. It is a form of TCP/IP protocol used to enable incoming and outgoing email messages. TCP/IP, or Transmission Control Protocol/Internet Protocol, is the standard means of web interaction. Every computer or device capable of accessing the Internet sends and receives data through a [TCP/IP application](http://searchnetworking.techtarget.com/definition/TCP-IP). SMTP is not well suited to handle incoming messages, so it is typically combined with one of two other common email protocols – POP3 (Post Office Protocol 3) or IMAP (Internet Message Access Protocol). With POP3, all email remains on the server until the relevant user checks it; at that point, it is downloaded and deleted from the server. Typically POP3 is used for personal rather than business email. With IMAP, the use of which is more widespread in business settings, you can manage mail on your server without having to download it. It’s practical to use IMAP in conjunction with SMTP, with the former configured to receive messages and the latter configured to send them. The most popular SMTP application for Linux and [FreeBSD](http://www.freebsd.org/doc/en/books/handbook/sendmail.html) is send email. You can either use the open-source version or a proprietary offering – Sendmail – that is bundled with a POP3 program. If you’re using a Windows environment, Microsoft Exchange comes with SMTP functionality preinstalled. ## What Is a Swap File? A swap file enables a VPS or other server to designate a portion of the hard drive to serve as additional memory as needed. If the operating system needs RAM (random access memory) to run a certain application, it can transfer underutilized resources from an application onto the hard drive. In this manner, memory can be swapped back and forth, giving your environment greater flexibility. The creation of swap files is referred to as *virtual memory*. The practice makes it possible to run additional programs that would otherwise be possible without as many latency issues (although cloud systems generally optimize availability). Swap files can be either permanent or temporary. The former is generally the case with Windows systems: swapping occurs on a case-by-case basis, with files generated for one-time use. The latter is typically the case with Linux and FreeBSD: those systems set aside a section of the hard drive for swapping. Permanent files tend to result in higher performance, while temporary ones are better for keeping resources free on an ongoing basis. **![Hosting humor - security - passwords](https://www.atlantic.net/wp-content/uploads/2013/12/11-001.jpg)** ## Finding Cloud VPS Options for Mail Servers Atlantic.Net has been in business for 20 years. Throughout that time, we have remained on the cutting edge of IT equipment and practices. We now offer a full line of cloud VPS hosting packages, everyone utilizing solid-state drive (SSD) cloud hosting servers for up to 100 times the performance vs. standard HDD drives. We also offer [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) and [VPS hosting services](https://www.atlantic.net/vps-hosting/). Live support is available 24/7. By Kent Roberts ![SMTP for Cloud VPS Mail Server – A Real World Scenario - Comic](https://www.atlantic.net/wp-content/uploads/2014/04/AtlanticComics-6-723x1024.jpg) --- # HIPAA Compliant Dedicated Server – A Real World Scenario > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-dedicated-server-a-real-world-scenario/ | Published: 2014-04-25 | Updated: 2024-11-14 | Author: Sam Guiliano In our Real World Scenario (RWS) series, we review interactions between our consultants and clients considering various hosting options. One of our specialized focus points is healthcare IT, so our RWS articles have covered numerous situations in which medical organizations – practices, plans, or data clearinghouses – seek solutions that meet their needs. Specifically, these companies need hosting environments that fully comply with the Health Insurance Portability and Accountability Act of 1996, otherwise known as HIPAA. The vast majority of our information related to this topic is organized through a recently published (April 2014) HIPAA Server Master Index. This Real World Scenario installment is in two parts/pages, outlining a client’s interest in a dedicated server infrastructure. A transcript based on the conversation between the client and our consultant appears below. Following the transcript (on the second page of the article), we will assess a few of the key terms used by the two parties. ## In need of a HIPAA dedicated solution Client: We are looking for [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) for a HIPAA compliant service. Following are our specifications: - Server: Dual Processor Quad Core Xeon 5520 – 2.26 GHz (Nehalem) – 2 x 8 MB cache w/HT - Operating System: Windows Server 2012 R2 Standard Edition (64 bit) - RAM: 12 GB DDR3 Registered 1333 - Disk Controller: RAID - First Hard Drive: 150 GB SATA Raptor 10k - Second Hard Drive: 150 GB SATA Raptor 10k - (4) Hard Drives: 4.00 TB SATA III - Public Bandwidth: 20000 GB Bandwidth - Uplink Port Speeds: 100 Mbps Public & Private Networks - Remote Management: Reboot / KVM over IP - Primary IP Addresses: 1 IP Address - Public Secondary IP Addresses: 8 Public IP Addresses - Power Supply: Redundant Power Supplies - Anti-Virus & Spyware Protection - 100 Mbps Hardware Firewall. Please send your quote ASAP. Thank you. Consultant: Thank you for contacting Atlantic.Net concerning your hosting requirements. Attached you will find the official pricing proposal based on the specifications you have provided. We no longer use Dual Quad Core Xeon Processors because the Dual E5 Processors are of equal price and significantly more robust. We no longer provide Raptor Hard Drives, so we have included ( 2 ) Cachecade 240 GB SSD drives. We have also included the supporting documents that will detail the following services for this HIPAA compliant platform: - Business Associate Agreement (BAA) - Fully Managed Daily Backup - Fully Managed Hardware Firewall w/ Managed VPNs - Intrusion Detection System with Log Management and Log Monitoring. These are the highlights of our proposal: 1. Fully Managed Hardware Firewall with Intrusion Detection and Log Management / Monitoring. Also ( 5 ) encrypted, managed VPNs 2. Fully Managed Daily Backup for all files and databases 3. Dual E5 Hex Core Xeon Processors w/ HT / 16 GB of RAM / 2 X 240 GB SSD Cachecade / 4 X 4 TB ES3 Enterprise SATA RAIDed 4. 20 TB of monthly data transfer with a 1 Gbps Port 5. 24 X 7 X 365 Technical Support by phone or email 6. 100% Uptime SLA 7. Business Associate Agreement (BAA) 8. This Private HIPAA hosting platform will be located in an SSAE 16 audited data center 9. Trend Micro Deep Security If you would like to set up a call to go over our proposal, please send me the number to contact you; or send us any questions you may have concerning the proposal. Client: Good afternoon. Thank you for sending us the pricing proposal. We have received the documents. Could you also send us copies of your audit reports for HIPAA and SSAE 16? Consultant: Attached is a copy of our SSAE 16 report. I have asked our legal department to provide feedback concerning your question about the HIPAA audit report. I will send you their response as soon as I have it. Client: I have received the SSAE 16 report, but it is for the period of July 1, 2012, to June 30, 2013. I just wanted to check if you have an updated one. Thank you very much. Consultant: The SSAE 16 audits are completed in arrears. The next one will be completed by June 30 of this year. If a customer requires a certification that the data center is still in compliance while the new audit is being completed, we then issue a Bridge Letter. Bridge Letters can only be issued to existing customers. [*Client calls Consultant, and they further discuss options.*] Consultant: It was nice talking with you. I have updated the proposal based on our conversation. I added a second server, and I separated the bandwidth cost, demarcating it as its own line item. [*Continued on the [second page](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-dedicated-server-a-real-world-scenario-part-2/).*] ## Conclusion Atlantic.Net has been in business for 20 years and has been offering fully customizable healthcare [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) solutions for half a decade. See our [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) options to learn more about this topic and how we can be of assistance. ![Dedicated Server Comic](https://www.atlantic.net/wp-content/uploads/2014/04/Comic-Strips-Atlantic-3-001.jpg) --- # HIPAA Compliant Dedicated Server – A Real World Scenario – Part 2 > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-dedicated-server-a-real-world-scenario-part-2/ | Published: 2014-04-29 | Updated: 2024-11-14 | Author: Sam Guiliano [<<< Continued from Part 1](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-dedicated-server-a-real-world-scenario/) ## In need of a HIPAA dedicated solution – continued dialogue Consultant *(continued)*: By adding the second server, we also had to increase the cost of the daily backup since there is more storage involved. I also had to double the number of Trend Micro Deep Security licenses. I added 8 more Ips, but the IPs are free. You will now have 16 for the two servers. I also added another ( 5 ) VPNs at no extra charge. The updated proposal is attached and summarized below: 1.)  One Fully Managed Hardware Firewall with ( 10 ) Managed VPNs / Intrusion Detection System with Log Monitoring and Log Management. 2.) Two [servers](https://www.atlantic.net/dedicated-server-hosting/) with the following specs: - Dual Hex Core Xeon E5-2620V2 2.1 GHz w/ HT Processors - 24 Logical Cores per Server - 16 GB of RAM (expandable to 128 GB of RAM per server) - 2 X 240 GB SSD Cachecade Hard Drives - 4 X 4 TB SATA ES3  Enterprise Hard Drives – RAID 5, 6 or 10 - LSI Hardware RAID Card - Hot-Swappable Bays - Dual Power Supplies - IPMI (intelligent platform management interface). 3.) Fully Managed Daily Backup for all the Storage Space on the two servers 4.) 20 TB of Monthly Data Transfer, with a 1 Gbps Port 5.) Trend Micro Deep Security 6.) 16 Total Static IPs. If you so desire, we can virtualize the servers by using HyperV. Windows Standard Edition allows ( 2 ) VMs per server. We will set up the VMs for you when we first deploy the servers if you wish to virtualize. Also, our controller sent you an email this morning concerning your request for a HIPAA audit report. Please contact me if you have any questions concerning the email that he sent you or regarding this proposal. Client: Thank you for the details. I will be discussing your proposal with my management shortly. I have a few questions first, though: 1. How many hard disks can be added to each server? 2. What is the monthly charge for each additional TB of data transfer? Consultant: Great. Here are the answers to your questions: 1. You can add ( 2 ) more 4 TB hard drives to each server. 2. The charge is $0.05 per month per GB for overages. You would have to exceed the 20TB of data transfer in a 30 day period to incur the overage charge. Client: Hi – a few more questions: 1. If the data storage exceeds the maximum capacity of all 8 hard drives, can you add an additional external storage device? What would be the cost per TB? 2. Can you provide a Vulnerability Scan report? Thank you. Consultant: Okay, in response to your questions: 1. It is possible to add external storage, and the pricing is dependent on how much storage is required. We do not offer an On-Demand Storage solution, so I can only provide you with pricing based on the amount of total storage you wish to establish. 2. That is part of the Intrusion Detection System that is included in the proposal we presented to you. Client: Great that is all the information I need. I appreciate your answering all my questions so promptly. Once I speak with my management, what’s the next step? Consultant: You’re welcome. If you decide to move forward, please sign the BAA and send it back to us. Thank you for choosing Atlantic .Net. Let us know if you have any additional questions. ## Key terms Here are basic explanations for several of the key terms used in the above discussion: *Business Associate Agreement (BAA):* A business associate agreement is a contract between two parties, as established to fulfill [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). A *covered entity* – a healthcare provider, plan, or clearinghouse – enters the agreement with a *business associate* – any outside organization that handles protected health information (PHI). The document essentially stipulates the responsibilities of each party, such as the exact nature with which the associate will interact with PHI. *Trend Micro Deep Security:*  Trend Micro Inc. is a security software company founded in Los Angeles, California, with global headquarters in Tokyo, Japan, an R&D center in Taipei, Taiwan, and regional headquarters in Asia, Europe, and the Americas. The company develops security software for servers, cloud computing environments, consumers, and small, medium, and enterprise businesses. *RAID:* Short for a redundant array of independent disks, RAID is a standardized technique to store multiple instances of identical data on more than one HDD (hard disk drive) or SSD (solid-state drive). *SLA:* Short for service level agreement, an SLA defines the parameters with which a web hosting provider or similar third-party supplier will service its clients – such as our 100% uptime [VPS Hosting](https://www.atlantic.net/vps-hosting/)commitment. Offering IT solutions to healthcare organizations since 1994 – with specialized compliance strategies first developed in 2009 – Atlantic.Net is prepared to meet your organization’s needs. Please review our [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)  Master Index for an organized menu of our various materials related to this subject. ![dedicated server comic](https://www.atlantic.net/wp-content/uploads/2014/04/Comic-Strips-Atlantic-3-001.jpg) --- # HIPAA Compliant Colocation: Our Solution for Large Healthcare Computing Systems – A Real World Scenario > URL: https://www.atlantic.net/hipaa-data-centers/hipaa-colocation-solution-for-large-healthcare-computing-systems-a-real-world-scenario/ | Published: 2014-04-30 | Updated: 2024-10-21 | Author: Kent Roberts Healthcare companies must remain “HIPAA compliant” at all times. In other words, they must consistently meet the guidelines of the Health Insurance Portability and Accountability Act of 1996. The law, especially the Privacy Rule and Security Rule that are contained within Title II of the Act, have created an incredible challenge for medical organizations. Healthcare providers, plans, and clearinghouses – called covered entities under the law – must contract with any business associates that handled their patients’ protected health information (PHI). Essentially, compliance must be maintained via these outside parties as well. The following installment in our Real World Scenario series covers an interaction between our consultants and a potential client regarding [healthcare IT Colocation](https://www.atlantic.net/hipaa-data-centers/). Following the transcript of that discussion, we will review several key terms used by one of the two parties. ## HIPAA-Compliant Colocation Strategy Consultant: Tell us about your hosting needs. Client: I am considering moving 1500 square feet of healthcare computing systems to a colocation facility.  I’ll need HIPAA compliance and 30 kVA of power. Is this something you can help me with? If so, here is my phone number: [omitted]. Please call me soon. [*Consultant calls client, and the email exchange resumes.*] Consultant: Thank you for taking my call. I have two additional questions: - Do you require 120 Volt or 208 Volt Power (or a combination of both)? - If you require 208 Volt Power, do you require Single Phase or Three Phase Power? Client: Mostly 208V Single phase. Let’s say 20% 120V Single phase. Consultant: We will have the pricing over to you today. Thank you. Client: Okay, thanks for your quick attention. Consultant: We have attached the formal hosting proposal based on the requirements you provided to us. The basic parameters are highlighted at the end of this message. We were able to give you monthly pricing for the cage space along with the power. Note that the power pricing is based on providing both A & B sides power. Additionally, we have included the install charge for the power, but the install charge for the cage material is an item we do not yet have priced. We have also attached a copy of our Business Associate Agreement (BAA) for your review. Alternately, we are willing to sign a Business Associate Agreement from your side after our legal department reviews it if that’s preferable to you. We understand that at this point, you are looking for a budgetary number. We are willing to work with your organization – in any way that makes financial sense – to accommodate any changes you may require to the pricing model we have provided. Please contact me at any point with whatever questions you may have. Finally, I have attached a document that will provide you with information on the other hosting services we provide. HIPAA Compliant Colocation Data Center Parameters: - Term: 36-month term - Cage Space in Square Feet: 1500 - Electrical Supply: 30 kVA of Power, applicable each to Sides A & B. **Key terms used above** *kVA* Short for kilovolt-ampere, a kVa is a unit that measures the seeming power conducted through an electrical circuit. It is equivalent to 1000 [volt-amperes](http://en.wikipedia.org/wiki/Volt-ampere). A volt-ampere is understood to be the product of RMS (root-mean-square) current and RMS voltage. These units are only used when describing alternating current (AC) circuits. *Single-phase power* This type of power is exhibited by the alternating current transmitted through a residential electrical outlet. Direct current (DC) is a straight movement of electrons from the circuit’s positive to its negative node. Single-phase power allows electrons to move in either direction as the charge fluctuates – which occurs when power is supplied to any electrical item. Alternating current is used in homes because it is simple and enhances efficiency. Utility companies produce alternating current automatically. Essentially, you would have to change the circuit to allow for direct current, which would require tools and result in the underutilization of your [energy supply](http://www.ehow.com/info_10039604_single-phase-electricity.html). *Three-phase power* This is a way to transmit electricity that utilizes three wires, each with its own alternating current.  Each wire’s current only operates during one-third of the cycle. The stability of the power supply is enhanced – versus a system built on a single-phase model – using [this technique](http://www.wisegeek.org/what-is-three-phase-power.htm). **HIPAA guidance – DIY or with 24/7 support** ## Your HIPAA Compliant Colocation Hosting Plan We’ve served thousands of colocation clients over the past three decades, and we know exactly what our clients need. We’re confident that if you host with us, your data will be safe – and, more importantly, that it’ll be accessible exactly when and where you need it. That’s a promise. Thanks to our fully redundant infrastructure and high-quality on-site security, colocation has never given better peace of mind. Colocation clients enjoy an industry-leading service-level agreement that promises 100% uptime – hosting with us means neither your network nor your infrastructure will ever make your data inaccessible. Factor in our superior on-site security, and it’s clear why we’re the logical choice for colocation if you’re in the healthcare industry. We offer fully-secured, custom-sized cabinets and colocation cage space to be scaled up or down according to your needs. According to The Health Insurance Portability and Accountability Act (HIPAA), two different types of organizations must ensure compliance: covered entities and business associates. Atlantic.Net falls into the latter category, a third-party entity contracted to handle protected health information(PHI). To both comply with the law and assure our clients that we’re committed to keeping their information safe, we’ve drafted up a HIPAA Business Associate Agreement. This HIPAA-Compliant document is critical to our relationship with healthcare firms and medical practitioners alike, as it firmly establishes parameters for our use of PHI. The following three components are central to this contract: - **Business associate’s role** – the exact nature of the third party’s interaction with the healthcare data, including any forms of use and disclosure. - **Limitations** – the prohibition of the third party from any forms of use or disclosure not stated in the agreement. - **Security requirements** – the necessity for extensive security technologies and protocols to guard against any unauthorized use or disclosure. In conjunction with our SOC 2 and SOC 3 certified data centers, our BAA shows that we’re committed to keeping the private healthcare information of our clients both safe and secure. Moreover, it shows that we’re willing to go beyond the minimum compliance standards established in HIPAA. Healthcare businesses who choose us as a host have the peace of mind that can only come from knowing that they’ve partnered with a veteran – and one that’s completely committed to their best interests, at that. Get started with [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) from Atlantic.Net! ![HIPAA hipster comic](https://www.atlantic.net/wp-content/uploads/2014/04/Atlantic-Comic-April5-001.jpg) --- # Overview of Distributed Database Types and Security > URL: https://www.atlantic.net/vps-hosting/overview-of-distributed-database-types-and-security/ | Published: 2014-05-01 | Updated: 2025-03-06 | Author: Alexander Wise Many companies have moved from centralized databases to distributed databases, the latter cloud-based services that have significant advantages over the former, older model. However, any new technology within IT raises caution flags as the security concerns are encountered and rectified. The fact is, [distributed databases](https://www.atlantic.net/vps-hosting/about-distributed-databases-and-distributed-data-systems/) are not new. Companies that have experience and expertise in the field know proper, secure distributed database management, along with the tools you need for strong administration. This article will look briefly at the distributed model versus the centralized model, the primary types of distributed databases, and security basics. ## Centralized vs. Distributed Databases VirtualMV provides a basic overview of the two general types of database: centralized (or centralized, depending on English version) and distributed: *Centralized databases* reside in one place – in other words, all the hardware and other infrastructural elements that run and store the database are under one roof. It’s accessible through a web connection usually. Financial institutions will often use this type of database: Australia and New Zealand Banking Group (ANZ) is one example. It’s conventional and has its limitations, but it is an established standard. *Distributed databases* are located in the cloud. In other words, a network of computers in multiple physical locations is used for database storage, processing, and management. Clearly, the parameters of a database become more complex when the distributed model is used. However, many companies – including Google – have turned to data distribution to improve database redundancy, speed, scalability, and, in some senses, security (specifically, the latter improves by only permitting certain users to access specific sections of the distributed database). Google, for example, uses a distributed database to gather, hold, and retrieve search information at set intervals (perhaps once a minute or hour rather than moment by moment, although most distributed databases deliver data daily) because searching usually occurs in similar patterns in different areas across the globe. Whether a database is centralized or distributed, when it’s used, the database is the same in the sense that it’s one singular database. However, what an individual user might be accessing at one particular place is typically not the entire database. Instead, local access leads only to the part of the database applicable to the local area – what matters to that particular branch of the business, such as customers local to the area, which is why global businesses with numerous branches often choose this model. The branch’s section of the database updates the database of the main location – the entire database – usually daily, as described in the Google paragraph above. ## Types of Distributed Database Distributed databases are all designed a bit differently, and you can categorize them in different ways. To get a sense of a few major types of distributed databases, let’s look at the *duplicated*, *partition*, and *partition + index* approaches courtesy of ICT (information and communication technologies) [educational site Teach ICT](http://www.teach-ict.com/as_a2_ict_new/ocr/A2_G063/334_applications_ict/distributed_database/miniweb/index.htm). These categories give us a sense of how distributed databases can be compartmentalized (or not): - *Duplicated* – In a duplicated version of a distributed database, the whole database is stored in each of the various branches. That means you have a copy of the database that is fairly up-to-date (depending on how often updates occur) at all the local sites of the business. This solution works well if your database is not big and you are not concerned with scalability. - *Partitioned* – You divide the database into pieces, sectioning off what is needed for particular departments or situations. One obvious example in which partitioning makes sense is with local branches because typically, they don’t need everything in the national or international database at hand. Another situation for which partitioning can be used in different applications designated for specific tasks – the customer order application, for example, does not need to contain the same information as the inventory application (and vice versa; see the second paragraph in “distributed databases” section above). - *Partitioned + index* – A further evolution of the partitioned database keeps an index of database data stored in other locations. The indexes are updated typically every day (at a low-traffic hour) through a batch, in the same manner that the partitioned ones update the main database. In other words, the system is a compromise between the two other approaches. ## Potential Security Concerns of the Distributed Database As Oracle reminds us, you can set up the same type of security protections for your [distributed database as exist on a centralized one](http://docs.oracle.com/cd/B10501_01/server.920/a96521/ds_concepts.htm) – obviously engineered and/or configured in a way that fit the specifications of the distributed model: - passwords for every user, with specific permissions for each user type - additional software to cross-check user and type authentication - cryptographic technology to secure data packets between servers and when communicating with users. A distributed database can be extremely secure. It’s just a matter of appreciating where new vulnerabilities are created by changing the database model. Again, database partitioning allows you to segment your users into various categories of database access, which is a definite security benefit. Distributed databases are increasingly popular for a host of reasons. The primary one is that they significantly decrease strain on the network, specifically when a partitioned variety is deployed. The fact that Google uses one to organize its search data is a sign of how reliable and, therefore, trusted this database management model has become. Check back for more updates from Atlantic.Net, or learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) options. ## ![Overview of distributed database types and security- a comic](https://www.atlantic.net/wp-content/uploads/2014/05/distributed-database-1-comics.jpg) --- # Beyond HIPAA: International Health Data Protection in Europe and Canada > URL: https://www.atlantic.net/hipaa-compliant-hosting/beyond-hipaa-international-health-data-protection-europe-canada/ | Published: 2014-05-05 | Updated: 2024-10-22 | Author: Sam Guiliano HIPAA is the US’s answer to protecting vital patient data, but are there international “HIPAA” protections for Europeans, Canadians, and other countries – a sort of HIPAA in Europe or Canada? Although [healthcare hosting](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/) compliance is a major concern of any business handling, storing, or transferring healthcare data in the United States, working with personal patient data of Canadian or European patients is subject to different rules. Let’s look at how the European Union’s (EU’s) Directive on Data Protection and Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) regulate patient records and other sensitive information. Various organizations operating in the United States must comply with the Health Insurance Portability & Accountability Act (HIPAA), which has major ramifications for protecting every US citizen’s healthcare data. Not all of the Act has widespread relevance. Still, a broad spectrum of healthcare organizations is subject to the Privacy [Rule and Security Rule](http://www.hhs.gov/ocr/privacy/hipaa/understanding/) (as outlined by the US Department of Health & Human Services. Below, we explore how this same health privacy question is handled in other countries. ## Directive on Data Protection – Guidelines for Businesses in the European Union The European Union adopted the Directive on Data Protection in 1998. It outlaws disclosure of any personal details held by a European company to any foreign entities that do not meet the EU’s data safeguard guidelines (the basis of various efforts to meet EU standards, such as the United States’ Safe Harbor program). ### Differences between EU and US Law To understand the general EU policy in context, compared to the United States, the approach is more seamless and unified, as described by the US Department of Commerce. The US policy toward data is a piecemeal aggregate of different components: acts of Congress, regulatory agency code, and self-monitoring by businesses themselves. The approach by the European Union is more unified and far-reaching, including the following rules: - development of standalone agencies, the sole purpose of which is to safeguard personal information - the requirement to file any new or continuing sensitive databases with the government - consent from the government, in certain situations, before sensitive data may be gathered. ### Adherence to the Directive on Data Protection Digital technology lawyers Morrison & Foerster provide specific advice to businesses operating in European Union countries, as follows (though described in terms of labor law, these basic principles apply broadly within the EU): 1. *Focus on the specific data you need.* Because the EU standards and processes are stringent, it’s necessary to have a completely organized metadata system related to all the personal information you process. All data must be obtained and handled for an explicit and reasonable business purpose. In other words, streamline your personal information as much as possible within the EU. 2. *Analyze the way you process data.* You need to have a system in place to correct any errors in personal data and to discard any information that has become outdated and unuseful. Also, make sure those with access to data are properly trained. 3. *Consult a lawyer and/or legal codes.* Countries external to the EU that regularly handle personal data from the EU Member States should check legal requirements, such as Safe Harbor certification in the United States. 4. *Stay up-to-date with revisions.*The European Union has considered making changes to its data protection laws (with the 1998 Directive forming the basis). A primary concern is the [General Data Protection Regulation](http://www.lexology.com/library/detail.aspx?g=f3905d61-6bee-42a2-9648-ea301831d1dc) (albeit some sources say, is “on hold” until 2015). ## Canada’s Personal Information Protection and Electronic Documents Act – Overview PIPEDA is an Act passed by the Canadian government in 2000 that set parameters for businesses’ administration of personal data. The Act’s goal is to define a set of standards, as outlined by the [Office of the Privacy Commissioner of Canada](https://www.priv.gc.ca/leg_c/legislation/02_06_07_e.asp), that both safeguard the personal data of Canadian citizens and allow businesses reasonable access and use of the data to achieve business ends. ### Basic Stipulations of PIPEDA - *Freedom of information* – Individuals must be informed of any business’s reasoning to use personal data. It is also any Canadian’s right to review personal data and have any errors rectified. That right extends to EMR (electronic medical records) and applies to the full scope of sensitive information. - *Consent* – Organizations are required to obtain agreement from anyone to utilize personal details for almost any situation. However, criminal cases and emergencies allow access without a person’s approval. - *Complaints* – Canadian citizens also can contact the Privacy Commissioner, an official who reports directly to Parliament, with any grievances. ### Organizations Affected by PIPEDA This Canadian law, similarly to the EU one, is broader than the specific healthcare focus of HIPAA. Nonetheless, it does not cover all situations. Types of businesses and situations affected by this law include the following: - individuals conducting commerce - trade unions - nonprofit organizations (information related to donations and membership) - online transactions - face-to-face sales. ### PIPEDA Fair Information Principles The core of PIPEDA is its Fair Information Principles, which can be summarized as follows: - It is unlawful for a business to gather anything that is not immediately needed for the current transaction. If the company wants any additional information, they must provide their reasoning to the customer, how the data will be used, and what organizations will have access to it. The customer must then agree to those terms. - As stated above, a Canadian citizen has the right to review any data a business gathers and have any information changed that is incorrect. ## How Privacy Rights Affect You Clearly, the nations of the Western world have similar perspectives toward privacy rights. If your organization handles or is considering handling health data or other sensitive personal information of citizens outside your country, it’s crucial to check the laws (as detailed by Security and Privacy Firm Information Shield) to avoid problems. Atlantic.Net offers full [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) on full SSD Cloud Servers in a variety of cloud or [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) solutions. Looking for an international data center as an alternative? Contact us to find out about our world-class certified centers in [Toronto](https://www.atlantic.net/hipaa-data-centers/) and [London](https://www.atlantic.net/hipaa-data-centers/). Learn more about our [HIPAA compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. --- # Consequences of HIPAA: How HIPAA Affects Business Opportunities and the Economy > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-economic-impact-real-world-scenario-broad-view-of-business-opportunities/ | Published: 2014-05-06 | Updated: 2024-10-03 | Author: Sam Guiliano The healthcare industry is growing fast, and with it is the sector that specializes in Health Insurance Portability and Accountability Act compliance, a.k.a. HIPAA compliance. This form of compliance is critical for healthcare plans, providers, and clearinghouses: it allows the US Department of Health & Human Services to know businesses are safeguarding patient information. Specifically, HHS verifies that businesses closely interacting with protected health information (PHI) safeguard it in the manners described by the Privacy Rule and the Security Rule of law’s Title II. One obvious aspect of the field is [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and colocation, the direct supply of technological services to healthcare businesses. The IT infrastructure is sufficiently protected and free from liability concerns. However, the HIPAA compliance market – which represents growth opportunities for enterprises new and old – is more diverse than it may first appear. This article will look at three additional aspects of the HIPAA compliance arena, preceded by a Real World Scenario (RWS) and an explanation of one term used. Our RWS series highlights interactions between our hosting consultants and potential clients to provide readers with specific situations and requests related to compliance IT. ![HIPAA snacks comic](https://www.atlantic.net/wp-content/uploads/2014/05/Atlantic-Comic-April8-001.jpg) **HIPAA compliant physical therapy app** Client: I am in the process of developing an app for physical therapy. It will include 300+ videos, email between therapist and client within the app, and client data tracking. Here is a list of requirements for the server: 1. Dedicated server 2. Linux OS 3. Apache HTTP Server 4. PHP installed 5. MySQL database installed 6. Control Panel. Please let me know how you can help me. [*Consultant provides Client with Proposal and Business Associate Agreement (BAA).*] **What’s a business associate agreement?** A *business associate agreement*, or BAA, is a contract signed between a healthcare organization and a third party, which is supplying a solution for the organization that will involve patient data. In this arrangement, the healthcare firm is considered a *covered entity* by HIPAA, and the external party handling data on their behalf is considered a *business associate*. **HIPAA compliance field subcategory – content creation** One aspect of HIPAA compliance that is developing rapidly alongside the healthcare industry is marketing. Companies that perform marketing services for HIPAA compliance organizations – such as hosting companies like ours – generate marketing collateral, such as articles and videos to showcase expertise. In the age of “quality original content,” marketing companies are not the only organizations involved in producing collateral. Freelance writers are hired directly in some cases, as are illustrators and graphic artists. Video production companies can specialize in the production of HIPAA compliance pieces as well. **HIPAA compliance field subcategory – software development** Marketers are not the only professionals looking to take advantage of healthcare opportunities. Software developers can also create applications that abide by the parameters of the act. One example is the physical therapy application described above. Web applications can serve multiple purposes: they can be used internally or to enhance engagement between the business and patients (as with the above app). They are designed specifically as mobile applications in some cases, especially when patients are the primary users. **HIPAA compliance field subcategory – consulting** Consultants are also useful to covered entities at times. These specialists have a narrow focus on the specific needs organizations have related to the law. Possible aspects of business for which a consultant can provide guidance include the following: - risk analysis/vulnerability assessments - project management - contingency planning - establishment of a compliance officer with general management responsibility for any business components related to HIPAA. A consultant can review a healthcare facility’s policies and procedures, along with its technological architecture, to determine if anything needs to be updated or reorganized. Some companies use this consultation process to cut HIPAA compliant server costs and general compliance costs: consultants provide information that the company can then use to conduct an audit. **HIPAA compliance field subcategory – auditing** Organizations also can perform complete audits of companies to determine if they are 100% compliant. These audits can be useful both to covered entities and business associates. Covered entities can determine any elements of the business that might be problematic. In contrast, business associates can use an audit to make corrections and establish a third-party verification so clients can trust their system. Companies that perform audits should be experts on HIPAA generally, but they should especially have a strong understanding of the Security Rule. The three elements of the Security Rule that are of special concern are the following: - Risk Management Standard - Audit Controls Standard - Evaluation Standard. **Finding specialists that deserve your business** Atlantic.Net has been offering compliant [healthcare hosting](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/) solutions for half a decade, based on technological experience established throughout our 20-year history. Our [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) page provides you a roadmap for the extensive HIPAA information available through our site. --- # SugarCRM: Customer Relationship Management in the Cloud > URL: https://www.atlantic.net/pci-compliant-hosting/sugarcrm-customer-relationship-management-in-the-cloud/ | Published: 2014-05-20 | Updated: 2024-10-21 | Author: Kent Roberts Companies often consider SugarCRM, along with Salesforce and other alternatives, to communicate with their customers worldwide. The platform organizes any client interactions into a dependable and coherently organized system. Apps that perform this function are called customer relationship management (CRM) software. **What is a CRM?** [PC Magazine](http://www.pcmag.com/article2/0,2817,2391297,00.asp) explored the general topic of CRM tools. These tools are used particularly for marketing and sales purposes. They can be a good investment because they allow a company to improve its customer attraction and retention strategies. They also tend to help shorten the sales cycle (the step-by-step process experienced by a customer determines whether or not to make a purchase). A CRM manages both existing customers and prospects (which are essentially qualified leads that might turn into customers). It is primarily the territory of the salesforce of a business and the parts of the organization that is integrated with the sales department. This technology is applicable throughout the business world, although different organizations will find certain aspects of a CRM system more useful than others. Many organizations are unaware, though, that a CRM is not just about sales. It is useful for any form of customer interaction, including support and marketing. A CRM is similar to a personal information management (PIM) system such as Contact Wolf or Microsoft Outlook. However, PIM software is focused primarily on filtering contacts within a database. Full-featured CRM applications have much broader capabilities than PIM applications related to customer communication. **What is SugarCRM?** SugarCRM was created by a company of the same name located in Cupertino, California. The company, which originally started as an open-source project, has been incorporated since 2004. The software is available in two different open-source versions, one free (called the Community Edition) and the other paid. This February, the company stated that it would not produce any additional releases of the Community Edition. However, they would still be distributing patches for any newly discovered security vulnerabilities. **Why is the company so successful?** Before we get into the specific benefits of the SugarCRM software itself, it’s interesting generally to consider the software company’s rise to prominence. Business Insider explored its fight with Microsoft and Salesforce in 2012 when the company had just garnered over $30 million of venture capital to help it further overtake the market. The California company has been in the black since 2010, with over 1 million downloads. That makes it the #3 CRM worldwide. Its revenues increased almost 70% in 2011. The reason for the success of the company is straightforward: specialty. Customer relationship management is the only focus of the business. Essentially, Sugar offers a compelling alternative to the homogeneity of a Windows environment. Even Salesforce has created and marketed broader offerings, such as Heroku and Rypple. The other major difference between the three competitors is that Salesforce and Microsoft have their own clouds while Sugar has its users select their own cloud services provider (CSP). The app can run on any cloud system, Atlantic.Net’s cloud hosting business solutions including ours and the Windows Azure system (which Microsoft would, of course, prefer to be the territory of the Microsoft Dynamics CRM). **Specific benefits of Sugar** The reason the software has become so popular is in part because of the following reasons as listed at Loaded Technologies: 1. *Choose your own cloud* – With this app, you aren’t stuck with one option for hosting. You can use the company’s own cloud, your private data center, or (as stated above) whatever cloud computing host you select. 2. *Great features included by default* – Generally speaking, you don’t have to make any additional purchases of add-ons. It’s ready as an off-the-shelf solution: feature-rich tools to handle your sales, marketing, and support needs are all available immediately. Salesforce, in contrast, has separate packages that meet various business needs, so often, additional money must be spent. The structure of the license, based on the open-source philosophy, allows for much more fluidity and accessibility. Its customization capabilities allow it to fit the specific needs of any business. 3. *Lack of extra charges* – The way that the software is priced is straightforward. Some customer relationship management systems will charge you additional fees for full mobile compatibility or integrating the system with other software. You have all the functionality you need upfront with Sugar. 4. *Highly respected company* – Research and analysis giants Forrester and Gartner have recognized the company with rewards for their impressive efforts at technological innovation. 5. *Changeable to meet your needs* – Developers appreciate the open-source model of the application. It’s based on PHP code, so many professionals can change the script to fit particular requirements. Expertise isn’t necessary, though: the system is also designed for users who aren’t technically proficient (with its sophisticated settings menu). **Choosing a hosting provider** As with any website or application, your experience with SugarCRM is highly dependent on the cloud hosting provider you choose. At Atlantic.Net, we craft all our solutions using the strongest advances in software and cloud server technology. We generate environments that multiply redundant, incredibly fast, and optimally secure to support demanding hosting implementations, such as [PCI compliant hosting](https://www.atlantic.net/pci-compliant-hosting/).  Learn more about our [PCI hosting](https://www.atlantic.net/pci-compliant-hosting/). ![SugarCRM: Customer Relationship Management in the Cloud](https://www.atlantic.net/wp-content/uploads/2014/05/Comic-Strips-Atlantic-4-001.jpg) By Kent Roberts --- # What Is a Distributed Database, and What Are Distributed Data Systems For? > URL: https://www.atlantic.net/vps-hosting/about-distributed-databases-and-distributed-data-systems/ | Published: 2014-05-25 | Updated: 2025-03-06 | Author: Alexander Wise Distributed databases offer some key advantages over centralized databases. Many companies are switching to distributed databases (in which the database, as its name implies, is distributed throughout an array of servers in various locations) for a variety of reasons. Let’s look at some of the basic advantages of distributed databases, a typical scenario in which they are used, and the different formats in which data is distributed throughout the distributed data system. ## ![What are distributed databases- Comic](https://www.atlantic.net/wp-content/uploads/2014/05/distributed-database-comics.jpg) ## Why distributed databases are becoming increasingly popular Here are the basic reasons why many organizations are leaving behind the centralized model in favor of database distribution: 1. *Reliability* – Building infrastructure is similar to investing: diversify to reduce your chances of loss. Specifically, if a failure occurs in one distribution area, the entire database does not experience a setback. 2. *Security* – You can give permissions to single sections of the overall database for better internal and external protection. 3. *Cost-effective* – Bandwidth prices go down because users are accessing remote data less frequently. 4. *Local access* – Similarly to #1 above, if there is a failure in the umbrella network, you can still get access to your portion of the database. 5. *Growth* – If you add a new location to your business, it’s simple to create an additional node within the database, making distribution highly scalable. 6. *Speed & resource efficiency* – Most requests and other interactivity with the database are performed locally, decreasing remote traffic. 7. *Responsibility & containment* – Because any glitches or failures occur locally, the issue is contained. It can potentially be handled by the IT staff designated to handle that piece of the company. ## Who uses distributed databases? Often distributed databases are used by organizations that have numerous offices or [storefronts in different geographical locations](http://www.teach-ict.com/as_a2_ict_new/ocr/A2_G063/334_applications_ict/distributed_database/miniweb/pg3.htm). Typically an individual branch is interacting primarily with the data that pertain to its own operations, with a much less frequent need for general company data. There is an inconsistent need for any central information from the branches in that case. However, the company’s home office still must have a steady influx of information from every location. To solve that issue, a distributed database usually operates by allowing each company location to interact directly with its own database during work hours. During non-peak times, each day, the whole database receives a batch of data from each branch. ## Types of distributed data   *Replicated data* – Replication of data is used to create additional instances of data in different parts of the database. Using this tactic, a distributed database can avoid excessive traffic because identical data can be accessed locally. Distributed data can be divided into five basic types, as outlined below: This form of data is subdivided into two different types: read-only and writable data. Writable versions can be adjusted, which immediately changes the first instance, with various configurations for how and when all replications throughout the system experience the update. Read-only versions also allow revisions to the first instance, and then the replications are adjusted accordingly. In this distributed data system, updates can be configured based on how crucial it is that the database has the correct specifics moment by moment (or over whatever time period). Note that replication is especially valuable when you do not need revisions to appear throughout the distributed data system in real-time. This type of data makes it easy to supply data from any section to any other section of the larger database if the latter section’s data is compromised by any error. Be aware, though, that with replication, *collisions* can occur. Safeguards must be in place to prevent/resolve them. *Horizontally fragmented data* – This category of data distribution involves the use of primary keys (each of which refers to one record in the database). Horizontal fragmentation is commonly used for situations in which specific business locations usually only need access to the database of their specific branch. *Vertically fragmented data* – With vertical fragmentation, primary keys are again utilized. However, in this case, copies of the primary key are available within each section of the database (accessible to each branch). This type of format works well for situations where a branch of a business and the central location interact with the same accounts but perhaps in different manners (such as changes to client contact information vs. changes to financial figures). *Reorganized data* – Reorganization means that data has been adjusted in one way or another, as is typical for decision-support databases. In some cases,  there are two distinct systems handling transactions and decision-support. While decision-support systems can be trickier to maintain technically, online transaction processing (OLTP) often requires reconfiguration to allow for large amounts of requests. *Separate-schema data* – This category partitions the database and software used to access it to fit different departments and situations – user data vs. product data, for example. Usually, there is overlap between the various databases within this type of distribution. For more information on the types of distributed databases and security, [check out our blog post on this here](https://www.atlantic.net/vps-hosting/).  Atlantic.Net is committed to keeping up with the best new advancements in technology through our Resources page that contains How-to Guides, Articles, and FAQs. *** As you can see, distributed databases represent a huge technological advancement. It’s not surprising that companies are shifting away from centralized databases and embracing the distributed model.  Atlantic.Net has many hosting options for various companies, including Windows Private Cloud Hosting, [Virtual private servers](https://www.atlantic.net/vps-hosting/), managed cloud server hosting, HIPAA compliant hosting, and our award-winning super-fast SSD [VPS Hosting](https://www.atlantic.net/vps-hosting/) servers. By Moazzam Adnan of cloud server hosting provider [Atlantic.Net](https://www.atlantic.net). --- # Real World Scenario of HIPAA Compliant Hosting Solutions > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-hosting-solution-for-advanced-directive-and-durable-power-of-attorney-documents-a-real-world-scenario/ | Published: 2014-05-27 | Updated: 2024-11-14 | Author: Sam Guiliano Various marketing sites argue for the power of “customer-sourced content,” suggesting that individual remarks and questions can create great material for other users. After all, the details of a situation may be unique, but the general concerns tend to be shared by others, at least those within the same industry. ## How Customer Service Questions Can Highlight Problems and Solutions CopyPress outlines various instances in which companies have turned social media posts and comments from Facebook and Twitter into [promotional opportunities](http://www.copypress.com/blog/how-to-turn-customer-service-into-content/). Similarly, the Online Marketing Institute (OMI) discusses various strategies to incorporate customer service questions into general site information. In the same vein, several months ago, we formed a stronger partnership between our marketing and customer support teams to create our Real World Scenario series. The premise behind this new Atlantic.Net content brand is simple: review the chats and emails between our hosting consultants and clients to find situations that could be of interest to our broad user base. The below installment highlights a consultant/client interaction focused on HIPAA (Health Insurance Portability and Accountability Act of 1996) compliant hosting for legal documents related to healthcare. ## Quote for Healthcare IT Startup Client: We are a startup working on digitizing advanced directive planning and completion. We plan to pitch our idea to [omitted] Hospital in a couple of weeks, but our initial meetings with them indicate a high probability that they will fund our venture. We were hoping you could provide a quote for [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/). We would need storage for approximately 20,000 advanced directives and durable power of attorney documents. The database would have to be accessible at will by hospital employees as well. Please let me know what additional details you require. Consultant: Thank you for contacting Atlantic.Net. We need answers to the following questions to provide you with a proposal: 1. Do you require a Linux or Windows hosting environment? 2. How much total storage space do you require for the documents? In other words, what is the byte size of the 20,000 documents you need secured/stored? Client: Thank You. 1. We prefer Linux, but the hospital employees with direct access to the database will probably need a Windows client. 2. We need 100GB of space. Consultant: Thank you for your response. Attached you will find the formal proposal for the smallest HIPAA compliant hosting platform that we offer. There are 3 different pricing options, listed from most to least expensive per month: - month-to-month - 12-month term - 24-month term. The following supporting documents are also attached: - Fully Managed Hardware Firewall - Encrypted VPN’s - Intrusion Detection System (IDS) - Business Associate Agreement (BAA). These are the highlights of the proposal: 1. Linux CentOS 6.X 64 Bit or Windows Standard 2008 R2 or Windows Standard 2012 R2 2. Dual-Core Processor / 4 GB of RAM / 160 GB of RAIDed Storage 3. Fully Managed Hardware Firewall 4. ( 5 ) Managed VPN’s 5. Fully Managed Daily Backup 6. Intrusion Detection System (IDS) with Log Management / Log Monitoring 7. 24 x 7 x 365 Live Technical Support (Phone & Email) 8. 100% Uptime Service Level Agreement (SLA) 9. 10 TB of Monthly Data Transfer with a 100 Mbps Port. Please let us know if you have any questions concerning the [HIPAA Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) Solutions proposal, as presented in the attached file and supporting documents. Client: Just a little bit of advice, if you could provide it. Do you believe we will need to hire a database administrator, even if just part-time, in addition to the services you provide? We expect very few changes to the files in the database after they are initially created. Also, what would the costs be if we were to double the storage and number of client licenses? We plan to expand to other hospital networks, so twice the figure would give us an idea of how our costs will scale. Consultant: Hello again. Unfortunately, because we do not provide Database Administration (DBA) services, we do not feel comfortable answering your question concerning the database. Below are the extra monthly charges you requested: You can add an extra 10 VPNs for $ XX per month. That is the minimum we can add, and it will increase the total number of VPNs to 15. The next step up in storage is 500 GB. It will increase the monthly pricing as follows, dependent on the length of the agreement: - month-to-month: $ XX per month - 12-month contract: $ XX per month - 24-month contract: $ XX per month. Client: Great. We hope to have a decision from the hospital in June, and I will be in touch once they get back to us. ## Conclusion As you can see in the above discussion, Atlantic.Net can meet the needs of those seeking secure healthcare solutions. We have been in business since 1994, winning numerous service and growth awards from organizations including Inc. and Entrepreneur.  Our expert engineers and consultants have been designing and deploying fully customizable [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) systems for over 5 years, along with many other popular options like [VPS Hosting](https://www.atlantic.net/vps-hosting/). ![HIPAA humor - comic](https://www.atlantic.net/wp-content/uploads/2014/05/Atlantic-Comic-April10-001.jpg) --- # Solid State Drives are on the Rise due to Efficiency and Price > URL: https://www.atlantic.net/vps-hosting/efficiency-upfront-price-tco-solid-state-drives-are-on-the-rise/ | Published: 2014-05-31 | Updated: 2024-10-21 | Author: Sam Guiliano We recently drafted a piece for Wired on [VPS Hosting](https://www.atlantic.net/vps-hosting/)trends (submitted but not yet published at this writing). One of the trends we discussed in the article is the transition from hard disk drives (HDD’s) to solid-state drives (SSD’s) by cloud service providers. Although this development is still in the “early adopter” phase, we expect SSD’s to become a standard expectation by the end of 2014. This article looks at studies and other resources that compare the SSD format to SATA (Serial Advanced Technology Attachment, the format of a traditional hard drive). By looking at various data, we can better understand why the solid-state is the wave of the future for cloud environments. We’ve covered some of this terrain in the past in this blog, but this article represents a deeper dive into three main parameters: efficiency, upfront price, and total cost of ownership. **Efficiency study – Adrian Otto / Tom’s Hardware** Technology blogger, Adrian Otto, conducted an analysis last year to determine whether solid-state drives truly consume less power than their predecessors, HDDs. Initially, Otto was planning to test hundreds of hard drives himself. Instead, his research on the topic revealed that Tom’s Hardware has data on both types of drives, representing the expected electrical use for different processing categories. The benchmarks listed for SSD and SATA include more than four dozen drives of each type. To better understand the efficiency of the two types of drives, Otto first averaged the energy consumption for SSD and SATA based on the server’s type of work. He divided his analysis into the following workloads/statuses: - Idle: Electrical use once the server has been idle for 10 minutes - Read: Power consumption when playing a high-definition (HD) movie - Database: Energy use while performing database reading and writing - Max Write: Electrical consumption at Maximum Write Throughput level. The below chart demonstrates his findings. All figures are in Watts. ![SSD Table 1](https://www.atlantic.net/wp-content/uploads/2014/05/SSD-Table-1.jpg) It only takes a glance at that chart to see that SSD represents a significant improvement in efficiency/sustainability, and we can see that’s true in various scenarios. What Otto was really interested in, though, was a single statistic representing power consumption with SSD format versus SATA format. With the data available, he didn’t have any way to develop a “typical use” scenario other than approximating that scenario roughly. He crunched the numbers into general everyday data by assuming 50% mixed-use (represented by the database figure above) and 50% idle. The resulting energy use between the two types of drives is detailed in this second chart (again, the numbers are in Watts): ![SSD Table 2](https://www.atlantic.net/wp-content/uploads/2014/05/SSD-Table-2.jpg) Again, as would be expected, SSD is dramatically more efficient. The fascinating figure is the extent to which solid-state drives consume less energy as a multiple, and that’s a simple calculation between those two numbers. According to this 2013 report incorporating research and analysis from two independent sources, SSD is 5.4 times more efficient. **Price – Computerworld** In 2012, Lucas Mearian of [Computerworld](https://www.computerworld.com/article/2525605/computer-hardware/review-hard-disk-vs-solid-state-drive-is-an-ssd-worth-the-money.html) wrote a follow-up to a 2009 article in which he compared the two different types of drives. Although we are now two years beyond that sequel piece, it’s interesting to reveal the continual improvements made to the technology. He called the price “the single biggest change.” Mearian noted that in 2009, SSD’s cost approximately $3 USD per gigabyte. By 2012, that number had dropped to about $1 USD per gigabyte – a savings of about 67%. **TCO Study – Parity Research & Robert Frances Group** A study – published in March 2014 on [Wikibon.org](http://wikibon.org/wiki/v/Performance_Centric_Data_Storage_TCO_Study_Demonstrates_Cost_Advantages_of_Flash_Arrays) – looked at broad, long-range factors of the drives. The research was conducted by Gary MacFadden of Parity Research, with a methodology devised in conjunction with the Robert Frances Group. MacFadden’s goal was to determine the total cost of ownership (TCO) of HDDs versus SSD’s, a subject of great interest to data centers, but that also revealed alternative findings to that provided by Otto’s study. Here are several of the salient points highlighted in the report, comparing the cost of an average enterprise SSD array to that of an HDD array: - The five-year maintenance cost for hard disk drives was $500,000 more - The physical space necessary to house the two types of arrays was 8 times more extensive for HDD’s - Power consumption was more than 9 times as high for HDD’s (compared to the 5.4 figure in Otto’s study) - Labor cost for management of an HDD array was more than 5 times that of SSD - The cost to deploy HDD was more than 400% higher than SSD. **Conclusion** As demonstrated by the above information, there are numerous reasons to transition from hard disk drives to solid-state drives. One other primary feature of SSD’s that is not explored above is durability due to their lack of moving parts. As we discussed in our piece for Wired, we believe SSD adoption will expand rapidly in the near future as SATA gradually becomes a relic in most IT environments. At Atlantic.Net, the future is now. Get your industry-leading [VPS Hosting](https://www.atlantic.net/vps-hosting/) today. ![Cloud Server - comic](https://www.atlantic.net/wp-content/uploads/2014/05/Atlantic-Comic-April6-001.jpg) --- # Commonly Asked Questions and How-To’s About HIPAA Compliance: Part 2 > URL: https://www.atlantic.net/hipaa-compliant-hosting/commonly-asked-questions-and-how-tos-about-hipaa-compliance-2/ | Published: 2014-06-11 | Author: Sam Guiliano ![hippo hipaa compliance humor](https://www.atlantic.net/wp-content/uploads/2014/06/Atlantic-Comic-April7-001.jpg) Below is the conclusion of our two-part series covering HIPAA compliance so that healthcare plans, providers, and clearinghouses have ample information. We continue by addressing the remainder of six common questions, followed by a couple of “snapshot tutorials” that address the needs of those preparing to deploy HIPAA Compliant systems. **5. What is the monthly cost of HIPAA-compliant servers?** A HIPAA compliant Server is available at a wide range of prices throughout the industry. A brief description of our affordable dedicated server packages will provide a sense of the basic technologies involved and the monthly price for their use. If you need multiple servers, you can divide a dedicated server into several private cloud servers, which maintains your compliance while lowering your cost. As with any hosting, the two primary operating systems used for [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) environments are Linux and Windows. Of course, healthcare companies don’t always have the same needs. Still, the following technologies – with security features discussed separately – are included in our standard “starter” packages for each type of OS (within a fixed monthly plan, based on a 24-month agreement): - Dedicated Server – Core I3-3220 Dual Core 3.3 GHz w/HT - 4 GB of RAM - 160 GB of Storage - 10 TB of Monthly Data Transfer with a 100 Mbps Port - 2 IP Addresses. The following security features are included standardly in these packages (whether the Linux or Windows variety) as well: - Total Private Hosting Environment - Intrusion Detection System (IDS) - Managed Firewall - ( 5 ) Virtual Private Networks (VPNs). Each system also includes a Business Associate Agreement (BAA), a contract described in the HIPAA legislation that stipulates our roles and responsibilities as a business associate (third party) handling data for a covered entity (healthcare organization). The monthly price for the Linux system is $260.36 USD, while the monthly price for a Windows system is $275.69 USD. Trend Micro Deep Security and SSL certificates (GeoTrust) are available separately through our sales team. **6. How much should I pay for a HIPAA app server?** The above scenario (question #5) should give you an idea of a base price, and you could run a compliant application within either of those OS environments. An application server can be either dedicated or virtual (one of a few cloud servers – as detailed below). The fundamental concern is that the system should be 100% private and protected by the above security tools. The standard design of a HIPAA virtual environment includes the following three machines: Web server, database server, and application server. You could also choose to have individual dedicated machines serve each of those functions, although that would be costlier. Due to the need for a totally private environment, the starting price will be the same as is listed above: $260.36 USD for Linux, $275.69 USD for Windows (see question #5 for details of the system and further pricing parameters). **Two Snapshot Tutorials** **1. How to make a HIPAA compliant website** If you want your website to be HIPAA compliant, you need to protect all your data (specifically the protected health information, or PHI) with today’s standard security technologies. The best path is the following: - Sign a business associate agreement (BAA) with a trusted hosting provider (see “Choosing a provider” below). - Create your hosting environment so that the developer can have immediate access to install applications, upload files, test usability, and perform other tasks. The hosting environment must include secure sockets layer (SSL) certificates, encrypted virtual private networks (VPNs), a dedicated firewall, two-factor authentication, a managed intrusion detection system with log management, and anti-virus protection. - Many healthcare companies prefer a 100% Windows environment for compatibility and proprietary maintenance with updates and security patches. Linux is popular as well, though, due to control and continual optimization via an open-source community. The typical basis for development within a Linux environment is a LAMP stack – a bundle of software containing Linux (operating system), Apache (Web server), MySQL (database), and PHP (coding language) – with general administrative control through cPanel or an alternative. **2. How to become HIPAA compliant with software** To ensure that all your software is compliant with HIPAA, your concern is essentially the same as when building a website (see #1 above): making sure that the patient data – the PHI (protected health information) – is fully secured. Your basic steps are as follows: - Sign a business associate agreement (BAA) with a trusted hosting provider (see “Choosing a provider” below). - Create your hosting environment, which must include secure sockets layer (SSL) certificates, encrypted virtual private networks (VPNs), a dedicated firewall, two-factor authentication, a managed intrusion detection system with log management, and anti-virus protection. - Begin development. If the software is already in place, migrate your application and related data into the system – using secure protocols so that the PHI is safeguarded throughout. **Choosing a provider** When you select a [HIPAA hosting](https://www.atlantic.net/hipaa-compliant-hosting/) service, it is wise to choose one that is both experienced and validated by a reputable independent certification organization. Atlantic.Net has been in business for 20 years, specializing in healthcare compliance for the last 5 years. We own and operate a data center in Orlando, Florida, audited to meet the SSAE 16 Type II standard established by the American Institute of CPAs (AICPA).   We also offer a private Cloud Server with 100% uptime guarantee. --- # Web Development & HIPAA-Compliant Streaming Video: A Real World Scenario > URL: https://www.atlantic.net/hipaa-compliant-hosting/web-development-hipaa-compliant-streaming-video-a-real-world-scenario/ | Published: 2014-06-23 | Author: Kent Roberts The following article is part of Atlantic.Net’s “Real World Scenario” series, which outlines common concerns expressed by customers via true-life (anonymous and edited) interactions between our hosting consultants and clients. This report, like many in this series, is related to HIPAA compliance, a critical concern with healthcare industry technology. Today we cover a customer support interaction in which a web developer is seeking assistance with a [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solution for a server, strong enough to support secure and reliable streaming of video and audio. **HIPAA Compliant Streaming Video** Client: I am a web developer with a very small company (only 3 people) asked to create a web-based database application. The client is a financial services company that works with medical associations. Hundreds of doctors would need to log into the system at any one time from their individual locations. I am uncertain how many data records they would each create, and perhaps 30-50 each is a reasonable guess. However, the system has the potential to grow dramatically, so any hosting package would need to provide plenty of room to grow: perhaps 10-30K data of records to start. We presume we would use MySQL to create the database. We need to get a HIPAA server set up, but we need a 1000 Mbps Port. Could you tell me how fast we can have this deployed and what our commitment will be? Do we need a contract? Could we do this month-to-month? We need a server that can support video and voice streaming. My colleagues and I are concerned about HIPAA requirements. We are interested in finding a web host that would provide a BAA and another backup, encryption, and other requirements needed to comply with HIPAA. We have no experience creating this kind of application and need help. Consultant: Attached you will find the formal pricing for the smallest HIPAA platform we can provide. Without knowing what your actual data storage requirements are, we are only guessing if it will work. There is room to grow in the environment by adding more resources to the primary dedicated server as far as RAM and Storage Space. This proposal will at least provide you with pricing for the entry-level HIPAA platform. There are 2 different pricing options, 12 months and  24 months. The following supporting documents are also attached: Fully Managed HardwareFirewall, Encrypted VPNs, Intrusion Detection System, Fully Managed Daily Backup and the Business Associate Agreement. These are the highlights of the proposal: 1. Linux Centos 6.X 64 Bit Operating System 2. Dual-Core Processor / 4 GB of RAM / 160 GB of RAIDed Storage 3. Fully Managed Hardware Firewall 4. ( 5 ) Managed Encrypted VPN’s 5. Intrusion Detection System with Log Management / Log Monitoring 6. Fully Managed Hardware Firewall 7. cPanel w/WHM control panel for web hosting 8. 24 X 7 X 365 Live Technical Support / Phone / Email 9. 100 % SLA 10. 10 TB of Monthly Data Transfer with a 1 Gbps Port. Please especially note the inclusion of the 1 Gbps Port (#10 above), as you requested. Our pricing is based on either a 12- or 24-month agreement, but we can provide a Month-to-Month agreement (although that option incurs a small setup fee). To provide you with pricing, we need the following questions answered. Those answers will also help us establish the time required to set up the hosting platform. 1. What Operating System do you require? 2. How much total storage space do you require? 3. Are there any special software packages that you require? Client: 1. Linux Centos/Ubuntu 2. It will be video hosting but can be stored in an external location. So 1TB. 3. We have to configure a streaming media server on top of the system. Please let us know the setup fee for a month-to-month or any other fees for 12-month or 24-month contracts. Consultant: Here are the answers to your questions, and attached is the updated proposal. 1. I included Centos as the OS, but we can also use Ubuntu if you want it. 2. I increased the storage space to 1 TB, but it can only be internal to the server. 3. You will have to install the software yourself for the streaming media. I increased the amount of RAM to 8 GB because of your requirement for streaming media. We will be in touch soon regarding a timeframe for deployment. **HIPAA compliant IT business associate** When choosing a HIPAA-compliant web hosting service for your sensitive healthcare data (specifically your protected health information, aka PHI), you deserve an affordable partner with experience and expertise. Atlantic.Net has been in business since 1994, and we have continually increased our focus on [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) throughout the last five years. Best of all, our Florida-based data center (which we own and operate) is independently audited using a standard established by the American Institute of CPAs and offers [VPS Hosting](https://www.atlantic.net/vps-hosting/). ![operating systems- comic](https://www.atlantic.net/wp-content/uploads/2014/06/Atlantic-Comic-April9-001.jpg) By Kent Roberts --- # HIPAA Compliant Hosting: A Real World Scenario > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-net-web-based-application-hosting-a-real-world-scenario/ | Published: 2014-06-30 | Updated: 2024-11-14 | Author: Sam Guiliano Most healthcare organizations – including plans, providers, and clearinghouses – must be fully compliant with the Health Insurance Portability and Accountability Act of 1996 (HIPAA). One aspect of compliance is contracting with outside specialists that can handle specific data-related responsibilities. These technology partners are experts at hosting compliant websites and applications, serving as business associates (via business associate agreements, or BAAs) for healthcare clients and their affiliates. To deliver the type of content that will be the most useful to our audience, we (the blog staff) are sent interactions from the sales and customer support departments, which we then convert into articles. These articles, which find common points of interest in day-to-day situations, comprise our Real World Scenario series. *The interaction is between an Atlantic.Net hosting consultant and client (protected for anonymity) interested in HIPAA compliant .NET Web-based application hosting. (Took place during May 2014).* ## Ultra-secure application hosting for PHI Client: We are looking for HIPAA compliant .NET web-based application Cloud Hosting. Consultant: Thank you for contacting Atlantic.Net. We need to know how much storage space you require for the data in order to send you a formal proposal. Client: At this point, the database is small. Can additional storage be allocated on the fly, as we need more? Consultant: The smallest storage space we can provide to start is 160 GB, and it is very easy to add more storage space when you require it. Attached you will find the formal proposal for the smallest [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/)platform we can provide. There are three different pricing options: Month to Month / 12 months / 24 months. The following supporting documents are also attached: Fully Managed Hardware Firewall, Fully Managed Daily Backup,  Encrypted VPNs, Intrusion Detection System, and Business Associate Agreement for HIPAA. These are the highlights of the proposal: 1. Windows Standard 2008 R2 or 2012 R2 2. Dual-Core Processor / 4 GB of RAM / 160 GB of RAIDed Storage 3. Fully Managed Hardware Firewall 4. ( 5 ) Managed VPNs 5. Intrusion Detection System with Log Management / Log Monitoring 6. Fully Managed Daily Backup 7. Anti-Virus Software 8. 24 X 7 X 365 Live Technical Support (Phone / Email) 9. 100% Uptime SLA 10. 10 TB of Monthly Data Transfer with a 100 Mbps Port. Client: Thanks for your quick response. Can you provide a quote with two servers, one with MS SQL Server Web edition? Consultant: We can provide ( 2 ) physical servers, or we can provide ( 1 ) physical server with ( 2 ) Virtual machines on them. The Windows Standard edition 2012 R2 license allows us to create ( 2 ) Windows virtual machines inside the ( 1 ) physical server using HyperV. This would keep down the cost of the platform because we only need ( 1 ) physical server. The Virtual Machines can be either Windows Standard 2008 R2 or 2012 R2. Are you okay with this solution, or do you require ( 2 ) physical servers? Client: I would prefer the virtual approach. Can I have a little more powerful server with maybe 8 GB of RAM? Can you create one virtual machine with half the RAM for the Web server and put the SQL server on the base server (physical)? Consultant: The server will have 16 GB of RAM. 4 GB of RAM is allocated for the Hypervisor, and the rest can be used for the virtual servers. We can assign 8 GB to the virtual database server and 4 GB to the Web server. Because we will be hosting a virtual database server, we will need to create a RAID 10 configuration for the hard drives, and we will need to use a more powerful RAID card. This will provide you with superior performance for the database server. This is still less expensive than adding another physical server. The updated proposal is attached. Our pricing includes the creation of the ( 2 ) virtual servers but not the ongoing management of the virtual machines. If you want us to manage them on an ongoing basis, the charge is an extra $100.00 per month (regardless of the term of the agreement). I have attached the document that details the Virtualization hosting package for your review. Client: I like this. What would be performed for the ongoing management of the virtual machines? Consultant: Management includes: - System networking and virtualization environment – “Up-to-OS” management and support - VM Provisioning – VM creation, cloning, and removing - System Updates - Clustering - Replication and Manual Failover - Advanced Monitoring - Advanced Certifications - Additional Virtualization Management Services. Attached is a PDF document with the information on the Managed Virtualization package. Also attached is the formal updated proposal with the Managed Virtualization Hosting package added to it. Client: Thanks for your help. I will review with the business internally and let you know when we want to move forward. *** ## Why Atlantic.Net? Atlantic.Net, in the Internet infrastructure business for 20 years, has won numerous awards since its inception, including acknowledgment from Inc. and Entrepreneur. Developing [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions for healthcare companies for the last five years, Atlantic.Net can also answer all your questions, just as you see above, through our 24/7 phone and email support staff. ![Hybrid hosting comic](https://www.atlantic.net/wp-content/uploads/2014/06/AtlanticComics-6-001.jpg) --- # HIPAA Virtualization: A Real World Scenario > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-virtualization-a-real-world-scenario/ | Published: 2014-07-11 | Updated: 2025-03-06 | Author: Alexander Wise Healthcare organizations often contact us for hosting solutions that are fully compliant with the parameters of the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Particularly critical for this sector of companies – called *covered entities* within the law and comprising providers, plans, and clearinghouses – are the Privacy Rule, and Security Rule contained within the Act’s Title II. The two rules govern the methods used by business associates, such as hosting services to safeguard *protected health information* (PHI). The following article is part of our Real World Scenario series, which details interactions between our hosting consultants and clients, anonymously and in edited form. (If you are looking for a fuller HIPAA resources directory, see our HIPAA Compliance Master Index.) ## Initial discussion of a HIPAA Virtualization plan Client: We need a HIPAA-compliant server running SQL 2012. We have a couple of databases and need to host some web portals. Consultant: Thank you for contacting Atlantic.Net. Please provide us with answers to the following questions so we can provide you with a formal proposal: 1. What version of MSSQL 2012 do you require? 2. How much storage space do you require? 3. We recommend separate virtualized servers for the web and database. Client: 1. I am looking at the versions, but I think standard would work. 2. Initially, we will not have high storage needs. The databases will grow but will most likely be less than 50GB. As far as webspace, we would be looking at 10GB or less. 3. I would prefer not to pay for two servers right now. Consultant: We can take one Windows server and create ( 2 ) virtual machines inside it by using the Windows Standard 2012 license. We do not charge extra to virtualize the dedicated server that is part of the [HIPAA hosting](https://www.atlantic.net/hipaa-compliant-hosting/) platform. So the total monthly charge would cover both the web and database servers. What we do not have any control over is the cost of the MSSQL 2012 license, and our agreement with Microsoft only allows us to lease the license on a monthly basis. You have the option of providing the MSSQL license yourself instead of leasing it from us, and we will load it on the server for you. Client: We will provide the SQL license. How fast can we get hosting set up? Consultant: It takes three days or less to deploy the new hosting platform from the time we receive a signed agreement. Below is the information that we need to send you within the agreement. Also, if you can answer the questions concerning the VM’s, firewall, and VPNs (listed below the contact questions), it will expedite the deployment process. -Full Company Name -Billing Address -Tax ID Number ( if available ) -State of Incorporation ( if available ) -Main Contact with phone number and email address -Billing Contact with phone number and email address -Technical Contacts with phone numbers and email addresses. Please provide the following information concerning the VM’s: - Amount of Ram required per VM - Amount of Storage required per VM. Please provide the firewall rules and ports you want set up. We are providing you with ( 5 ) VPN’s. We need to know how many you want to set up initially and what you want the username and password to be for each VM. Client: What are your recommendations for an SQL server and a Web server as far as RAM and storage? We will need the following access to the servers: * HTTP traffic to the webserver * VPN connections: > * User 1: >> * Username: XXXXXXXXXXXXXX >> * Password: XXXXX@XXXX > * User 2: >> * Username: XXXX >> * Password: XXXXX * VM Usernames: > * User 1 (Administrator): >> * Username: XXXXX >> * Password: XXXXX > * User 2 (Administrator): >> * Username: XXXXX >> * Password: XXXXXXX Consultant: We are going to provide you with16 GB of total RAM for the same price because we need 4 GB of RAM for the overhead on the HyperV Hypervisor. This will leave you with 12 GB of RAM. Below is our recommendation for the Web and DB servers. The processor has ( 4 ) virtual cores. You will have 500 GB of storage space, but we need to use 40 GB for overhead, leaving you with 460 GB of storage space. Please see the server descriptions: Web Server - 2 Cores - 4 GB of RAM - 200 GB of Storage space DB server - 2 Cores - 8 GB of RAM - 200 GB of Storage space If this looks good to you, we can move forward. Please let us know. Client: That looks good. ## Choosing strong HIPAA business associates Understandably, healthcare companies are careful who they choose to enlist to set up [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) systems. Atlantic.Net has been a respected industry veteran in business since 1994 and the winner of numerous business growth awards from outlets including *Inc.* and *Entrepreneur*. See our [HIPAA Compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) Hosting list for access to a broad range of compliance-related resources and to spin up an SSD Cloud Server. By Moazzam Adnan --- # Discussion about Windows, Linux and cPanel VPS – Part II > URL: https://www.atlantic.net/vps-hosting/windows-vs-linux-or-cpanel-vps-hosting-part-ii-similarities-price-advantage-cpanel/ | Published: 2014-07-23 | Updated: 2024-03-04 | Author: Kent Roberts [**<<< Go to Part I – Scripting Languages & Windows**](https://www.atlantic.net/blog/) In the first part of this two-part series, we discussed the advantages and disadvantages of the two major operating systems used for hosting: Linux and Windows. The primary differentiation was that Linux is open source, more widely available, and usually much less expensive, but Microsoft is necessary for coding with .NET & ASP. After discussing the pros and cons of each OS, the first part took a closer look at Windows VPS hosting (specifically with Windows Server 2012 R2). Now that we have discussed the differences between the two operating systems, this second and final installment of the series will discuss what Microsoft and Linux have in common (such as usability and performance). Also, since we discussed Windows in more detail previously, we will provide a fuller description of the Linux environment below. Note that cPanel is the standard control panel used with Linux, so this series encompasses cPanel VPS hosting as well. **Commonalities between Windows & Linux** What is truly remarkable about the competition between Linux and [Windows VPS](https://www.atlantic.net/vps-hosting/) Hosting is what strong contenders both of them are, as indicated by the five shared characteristics listed below (courtesy of the previously referenced article from Host Shopper): 1. *Speed* – The two operating systems both excel with regard to performance: neither one stands out as preferable to the other. Your performance is more likely to be determined by the strength of your equipment, the quality of your hosting service, and how your environment is constructed and managed. 2. *Stability* – Windows hosting systems used to have a reputation for being “notoriously unstable,” according to Host Shopper. That is no longer the case: both systems are incredibly stable, multiply redundant, and unlikely to crash. 3. *Static pages* – Both of the systems are capable of static hosting of HTML files. 4. *Usability* – Typically, the method by which you interact with your VPS will be FTP (file transfer protocol) or the control panel (which is typically cPanel, Plesk, or the hosting provider’s platform). Windows gives users access to a UI, but most users ignore that interface anyway, accessed by the above means. 5. *Security* – This topic is one of heated debate between adherents of each of the two operating systems, partially because it gets to the core of the battle between proprietary software and open-source software. The fact is, security is similar. **Fuller exploration of Linux & cPanel VPS hosting** Like Windows or OS X, Linux is an operating system: it enables the user of a computer and desired applications to complete tasks and access hardware (such as communicating between an application and the device’s CPU). It is a primary infrastructural component of any computer – server or client – necessary for building, running, and managing environments and applications of all types. Linux.com notes that one way the operating system stands out is that it is open-source, built through collaboration without one individual owner. When we look at the OS in action, though, what makes the OS distinctive – says the official [Linux site](http://linux.com) – is the nature of each of its elements: the kernel, the operating system, the environments, the applications, and the distributions. - *Kernel* – Every operating system has a kernel, a central brain of core instructions to guide the behavior of the hardware. The kernel is the basis for layers of additional tools that are constructed as modules. With Linux, the kernel is highly adaptable because it is also built as a set of modules. - *Operating system* – Along with the kernel, the operating system is additionally composed of tools capable of communicating with the kernel and apps that make kernel interaction simple for third-party software. Linux is built in a developer-friendly way, making it easier to take the code and convert it to communicate with the kernel and do what a development team intends. Like the kernel, the entire OS has a modular design. - *Environments* – Many people think the operating system is separate layers called the desktop environment and the windowing system. In Linux, a user can determine what desktop environment or windowing system they want to use, whereas, in Windows, that is not possible. - *Applications* – There are two basic kinds of applications used within an operating system: core software and user-installed software. A closed, proprietary OS such as OS X or Windows does not allow users to determine the basic software, such as the compiler or windowing system. Linux gives you the flexibility to determine these components yourself. - *Distributions* – A distribution is considered the top layer of the OS. Its developers – part of a community that a for-profit organization sometimes sponsors – determine the kernel, OS tools, desktop environment, windowing system, and other tools to include in the Linux flavor or distro. **Choosing a VPS hosting provider** Whether you are interested in Windows or Linux with cPanel for your VPS hosting environment, Atlantic.Net offers a full range of solutions for your project or organization. We have been in business since 1994, and our data center in Orlando, Florida, is SSAE 16 Type II audited and certified. Here are our scalable [VPS Hosting](https://www.atlantic.net/vps-hosting/) options for your review. Atlantic.Net also offers [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/). By Kent Roberts --- # Cloud Scalability for a Limitless Application Launch > URL: https://www.atlantic.net/hipaa-data-centers/cloud-scalability-for-a-limitless-app-launch/ | Published: 2014-07-27 | Author: Sam Guiliano - **What is Scalability?** - **Tech Definition #1** - **Tech Definition #2** - **Scalable SSD Cloud** The above whiteboard animation discusses numerous benefits of using SSD cloud server hosting for the hosting of your app: ease, time-to-market, freedom, affordability, cost flexibility, and scalability. Scalability is one of the most exciting features of the cloud: distributed virtual servers make the resources available to each independent system essentially limitless. Tech writer Margaret Rouse explains this concept and how it is commonly applied to technology in her [*TechTarget* page](http://searchdatacenter.techtarget.com/definition/scalability) on the topic – entitled “scalability.” ### **What is Scalability?** Scalability – as a general characteristic – is continuing strong performance of a system (whether technological, organizational, or otherwise) regardless of how complex it gets or how many people are using it. There are a couple of basic ways that the notion of scalability is used within IT, as described below. ### **Tech Definition #1** In some cases, scalability “is the ability of a computer application or product (hardware or software) to continue to function well when it (or its context) is changed in size or volume to meet a user need,” says Rouse. Generally speaking, the change to which the technology must adapt is an increase in the amount of data and resource use. However, that change can also be to a different setting, such as an upgraded OS. Rouse mentions that mainframe computing author John Young uses scalability in this way when he describes an operating system that can continue delivering excellent speed and reliability when new CPUs are introduced. Similarly, fonts that are said to have scalability won’t degrade when they are expanded or shrunk. ### **Tech Definition #2** In other cases, Rouse notes, scalability refers to “the ability not only to function well in the rescaled situation but to actually take full advantage of it.” In other words, if you took an application and migrated it to a more robust OS that was quicker at task-handling and allowed broader user populations, the app would be considered *scalable* if it could make full use of those capabilities. It is often the case that you *scale upward* because developers frequently max out available resources during the initial design. *Downward scaling* typically means you want to achieve the same performance with tighter resources. ### **Scalable SSD Cloud** The above video promotes scaling within SSD cloud server hosting environments due to their limitless nature. As long as your application is cloud-ready, you can seamlessly scale it up to whatever size you need. Performance remains strong partly because the enterprise solid-state drives used for our market-leading [VPS Hosting](https://www.atlantic.net/vps-hosting/) platform are up to 100 times faster than our previous storage solution. Atlantic.Net also offers [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions; learn more about our [HIPAA Data Centers](https://www.atlantic.net/hipaa-data-centers/). --- # Private Company vs. Belly-Up Cloud Hosting > URL: https://www.atlantic.net/hipaa-compliant-hosting/privating-company-vs-belly-up-cloud-hosting/ | Published: 2014-07-28 | Updated: 2025-03-06 | Author: Alexander Wise ## **Financial Stability of Cloud Providers** This video – “Cloud Hosting Companies Are Dropping Like Flies” — discusses that many cloud hosting companies are shutting down. That makes sense. There has been a tremendous amount of money injected into the cloud hosting industry, which means there have been many startups. When it comes down to it, a startup is a test business, and they haven’t proven themselves capable of maintaining solvency. While you may want to run technological test projects yourself, you never want to serve as a guinea pig in an infrastructure experiment that might put your online presence at risk, especially if you’re hosting mission-critical information, such as that which may require [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/).  In the video, we mention that we are a private hosting company. Why should you go with a private company rather than a publicly traded one? Several positive characteristics set successful private companies apart, as discussed by tech writer Bruce Upbin in the 2013 *Forbes* article “[The Six Habits of Successful Private Companies](http://www.forbes.com/sites/bruceupbin/2013/06/30/the-six-habits-of-successful-private-companies/).” ## **Stats on Private Company Growth** How fast do the largest privately held companies grow? According to figures collected in 2011, says Upbin, the largest private companies grew at 12%, doubling the pace of the S&P 500. KPMG and *Forbes* released 2013 research revealing that almost 3 in 5 private outfits (58%) were forecast to expand at 6% or above during 12 months. What about the great private companies? Of the 473 private company leaders interviewed, 1 in 10 said sales would accelerate at least 20% over the ensuing year. Plus, private companies represent the vast majority of businesses. “Forbes … has … been covering non-public companies since its launch in 1917,” says Upbin. “We care about the health of private companies … because we sorta have to. They make up 99% of all businesses in the U.S.” ## **Characteristics of Private Companies – Highlights** According to Upbin, highlight benefits the most savvy private firms include: Sense of identity & meaning There is a vast body of research on the positive impact of meaning on productivity and job satisfaction. For instance, the identity and purpose of privately held Patagonia is sustainability. Worker loyalty The SAS Institute, a privately owned software company, based in North Carolina, has grown every year for almost four decades. They succeed by investing in their employees. By bestowing incredible worker benefits – from paternity leave to on-site daycare, from a company swimming pool to free tennis lessons – the company has a 96.7% employee retention rate, way outpacing the tech industry average of 78%. Yoga-like flexibility Although 42 of the 220 largest private companies in the U.S. are over 100 years old, they aren’t stuck. Hallmark is a great example, says Upbin: “[The company] started a line of Spanish-language greeting cards in the early 1990s, before Hispanic marketing took off,” he says. “It diversified smartly into cable T.V., embraced the Internet early with e-cards, and introduced some of the first cards with sound chips.” ## **The Private Hosting Advantage** Do you want to partner with a company that has a sense of mission, high customer satisfaction, and can adapt to meet the ever-changing threat landscape, compliance guidelines, and business expectations? As stated in the above video, many businesses come and go, but Atlantic.Net has the characteristics of a solid and adaptive private cloud hosting company with state-of-the-art cloud server hosting. Atlantic.Net also offers managed, dedicated, and [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. By Moazzam Adnan --- # Announcing New Data Centers in Dallas, Texas and Toronto, Canada > URL: https://www.atlantic.net/announcements/announcing-new-data-centers-in-dallas-texas-and-toronto-canada/ | Published: 2014-07-29 | Updated: 2025-03-06 | Author: Alexander Wise We are excited to announce not one but two new locations for our SSD Cloud VPS customers! These new locations have the same features and pricing you are already used to, so launching a new server is fast and easy. We want to thank you, our customers, for making this possible. As we continue to grow, we have many more surprises to share with you. Our goal is to delight and amaze you with the best Cloud VPS platform on the planet! ![Announcing New VPS Data Centers in Dallas, Texas and Toronto, Canada](https://www.atlantic.net/wp-content/uploads/2014/07/Dallas-Toronto-Illustration.jpg) **NEW! SSD Cloud VPS Hosting – Up in 30 Seconds!** Atlantic.Net is now offering an SSD-based Cloud Platform to new and existing customers. The Enterprise SSD’s (Solid State Drives) are up to 100 times faster than the previous storage solution provided to the company’s customers. This provides Atlantic.Net’s customers faster start-up time and significantly increased random read/write performance. Atlantic.Net’s Cloud VPS Hosting plans start at only $0.00135 per hour (equivalent to $0.99 per month), with usage calculated on a per-second basis. All Cloud VPS plans include a minimum of 1TB outbound data transfer on every server. For more information, please visit our [VPS Hosting](https://www.atlantic.net/vps-hosting/) page. This new environment represents Atlantic.Net’s commitment to providing the latest and most stable virtualization technologies, Enterprise Solid State Drives, updated core networking, and new 32 and 64-bit Operating System images for Windows and [Linux VPS](https://www.atlantic.net/vps-hosting/) Hosting.     --- # Atlantic.Net Launches First International Data Center in Toronto, Canada > URL: https://www.atlantic.net/press-releases/atlantic-net-launches-first-international-data-center-toronto-canada/ | Published: 2014-07-29 | Author: Editorial Team ***Cloud Hosting Provider Continues Expansion with a Third State-of-the-Art Facility*** ORLANDO, FL – July 29, 2014 –Atlantic.Net, a high-powered SSD cloud VPS hosting solutions provider, announced today the opening of their first international data center, located in Toronto, Canada. To assist in the expansion, a second center also launched in [Dallas, Texas](https://www.atlantic.net/hipaa-data-centers/dallas-texas-hosting/). These state of the art data centers offer integrated colocation for telecommunication companies headquartered around the world, affording customers access to domestic, around the clock support from the United States, and now, Canada. The [Toronto center](https://www.atlantic.net/hipaa-data-centers/toronto-canada-hosting/) is fully equipped with high-speed fiber connections and upstream connections to Tier-1 bandwidth providers, making for an unadulterated first step into international territory. The center is carrier-neutral, allowing customers to receive prioritized delivery, as well as providing an exceptional network and superior upkeep to Atlantic.Net’s large roster of Canadian customers, and international users alike. The building is operated by Cogeco, a billion dollar data center operator, which allows Atlantic.Net to employ natural resources, making the international data center an energy efficient and green facility. As these centers attest, Atlantic.Net is expanding their reach for customers who want a secure, reliable data center with a native backing. “We chose Toronto and Dallas because both locations ensure that our customers have a domestic location to provide the highest-quality support,” explained Marty Puranik, Founder, President and CEO of Atlantic.Net. In conjunction with the international center, the Dallas center is positioned in the heart of Dallas for stateside support for the international center. It is located at the Univision Tower, 2323 Bryan Street and boasts 4500 (kW) utility power capacity with 1450 (kW) UPS power capacity and 3890 (kW) generator power capacity. There is also an N-N+1 UPS redundancy and, N+1 cooling redundancy – all operated by Digital Realty Trust, a multi-billion dollar data center operator. Atlantic.Net will continue to focus on international expansion to better service their global consumers. Now, the company currently has three open facilities, with plans to continue expansion to hot spots of the cloud ecosystem in North America, Latin America, Europe, and Asia-Pacific countries. **About Atlantic.Net** Atlantic.Net is a web hosting provider specializing in offering cloud server hosting, HIPAA compliant and hybrid hosting, private virtualization, and VPS hosting in the cloud. With a range of certifications and a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited data center that the company owns and operates, the company is also known for its reliability, as dictated by its 100 percent uptime service-level agreement (SLA). For more information, please visit www.atlantic.net. # # # CONTACT: [marketing@atlantic.net](mailto:marketing@atlantic.net) --- # Why Buy a Windows 2012 License When You Can Lease It? > URL: https://www.atlantic.net/hipaa-compliant-hosting/why-buy-a-windows-2012-license-when-you-can-lease-it/ | Published: 2014-07-31 | Updated: 2025-03-06 | Author: Alexander Wise As we all know, what a particular business achieves day-to-day, on behalf of its customers and for internal purposes, is not all conducted by the company itself. Using third-party vendors and suppliers is reasonable for tasks with the following characteristics: - require niche expertise; - use a sophisticated infrastructure; - and/or don’t fulfill the needs of a cost-benefit analysis (in other words, that are unnecessarily costly to be performed by the business itself). One aspect of a business is that is often entrusted to external companies is web hosting and affiliated technology-related needs. Specifically, many companies choose to lease Windows 2012, using it within a dedicated architecture (preferred by some businesses) or cloud VPS environment (more affordable and popular). There’s a tendency among savvy businesspeople to want to accrue as many assets as possible for their business. That game plan makes sense in some situations, but it’s not the wisest choice in others, financially or strategically. Let’s explore this topic of leasing versus owning broadly, considering why it’s popular in the automotive world (per [The Motley Fool](http://www.fool.com/investing/general/2014/01/18/3-situations-when-leasing-a-car-makes-sense.aspx)) and looking at the cost-effectiveness of hosting a website out of your home (per [The Guardian](http://www.theguardian.com/technology/askjack/2011/feb/03/website-hosting-at-home-office-ask-jack)). ## When leasing is the right choice First, let’s look at leasing versus buying in general, using the example of the car market, and then relate it to leasing a Windows 2012 VPS Hosting service. A JD Power report released in July 2013 found that more than one in every five US-sold cars – 23% – were being leased rather than purchased outright. Leasing has one extreme negative: you don’t develop equity, so you are just renting in the same sense you would like office space or an apartment. Motley Fool blog contributor Sean Williams suggests three situations in which leasing is the best choice: ### 1. When money doesn’t matter Obviously, in this case, you will be paying for a car without developing an ownership stake, so you won’t be able to collect on it as a trade-in when you get a new car. You could also be responsible for extra-warranty repairs and mileage fees above a certain number designated in the contract. You will, however, be able to drive a new car every year or two, which certainly has its perks. Your upfront payment is reduced a bit from the typical down payment if you are buying. With a new car, you also won’t have to be inconvenienced with trips to the mechanic. You also don’t need to worry about selling the car or worrying about the generally poor resale values of luxury cars. ### 2. Access to first-generation features without the investment Another situation in which leasing can be the right choice is when you want access to a first-generation car’s cutting-edge technologies and innovative styles (an aspect that has particular relevance to Windows VPS hosting  – see below). New cars themselves that are the first generations of a model are not great investments, as evidenced by an MSN report. The MSN analysis argues that electric car shoppers should lease rather than buy so that the car isn’t made obsolete by future versions (a scenario experienced by Chevy Volt owners due to improvements to charging and price reduction of the new Volt). ### 3. Need a new car, but can’t afford the payments Of course, the idea of “needing” a new car is slippery – since it’s often conspicuous consumption more than fulfilling a necessity. Nonetheless, leasing could be your best choice if you feel a new car is essential, but you aren’t prepared for the high payments (down or monthly). Auto pricing company Edmunds.com released a study last year revealing that the average monthly payment for cars purchased with loans was $464, while the price on a leased vehicle was $418 (a different payment model from Windows VPS hosting  – see below). ## Relationship to Windows 2012 leasing As you can see, leasing is not always unwise. In fact, the above information clarifies that it’s generally the best tactic with first-generation cars. Additionally, it gives you access to robust features. That’s really what leasing Windows 2012 through a cloud VPS is about: giving your business access to cutting-edge hardware, security, and platforms without a high upfront investment or ongoing maintenance concerns. Like leasing a car, you are also less tied to a particular system. You can change your mind and switch to a different version of Microsoft or even transition to a Linux server. One way in which [Windows VPS](https://www.atlantic.net/vps-hosting/) Hosting is different from leasing a car, as established above, is that you only pay for what you use with the former. Unlike a fixed monthly payment when leasing a vehicle, you only pay for the max resources used each hour (or each second, for lower rates, as with our Windows VPS environments). ## What about buying your own server? It’s reasonable for an entrepreneur or startup to consider getting their own Cloud Server and setting up a hosting environment internally for their website and applications. However, typically it’s not the best choice, says IT expert and journalist Jack Schofield of The Guardian, due to the following traits of professional web hosting companies: - they can host an affordable website more efficiently than an individual can; - their speed will likely be better than a self-hosted environment; and - their uptime and general reliability will also typically be superior. Essentially that means your leased version of Windows 2012, the operating system for your cloud VPS, can be expected to be faster, operate with better consistency, and the more affordable than buying the operating system and installing it on your own server. ## Windows VPS hosting you can trust Beyond the decision to lease or own your operating system, if you use a web hosting company for some of your needs, you will want one that’s affordable and reputable. Atlantic.Net has been in business since 1994, winning awards throughout our 20 years in business from media outlets including Entrepreneur and Inc. Atlantic.Net offers [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. Contact us today for a consultation. --- # cPanel Cloud Servers are Available at a Low Hourly Rate > URL: https://www.atlantic.net/hipaa-compliant-hosting/why-install-cpanel-when-one-click-cpanel-cloud-servers-are-available-at-a-low-hourly-rate/ | Published: 2014-08-15 | Updated: 2025-03-06 | Author: Alexander Wise cPanel is a privately held company that was founded in 1997. Headquartered in Houston, Texas, the company originally designed what is considered by far the most popular Linux control panel for hosting websites and managed cloud servers. cPanel cloud hosting & WHM, the two integrated halves of the software, make server automation intuitive and straightforward so that website owners and hosting companies can spend less and reduce their manual workload. This system is widely considered to be the first server control panel available on the market. The laser focus by cPanel on its one (bipartite) continually improving application and widespread familiarity with the platform practically give the company a monopoly on the website control panel for those using Linux. Often web developers and system administrators think that if they want an unmanaged server with complete control to customize, it’s necessary to get a completely new server. One of the first steps on that new server would be to install cPanel using the command line. In other words, rather than having immediate access to the cPanel interface, you first need to install and configure the software through an SSH session. That’s not the only option, though. If you know you will want cPanel and prefer to already have it in place on your cloud server; you can sign up for a cPanel cloud server. Especially for those who want to get started immediately on a project or for those who don’t feel comfortable interacting directly with the OS and manipulating setup parameters, choosing a cPanel server is the most reasonable option. ## More About cPanel As the most commonplace control panel used in web hosting environments, cPanel is used to manage [millions of sites](http://cpanel.com/) through tens of thousands of servers across the globe. It gives those managing servers the ability to deliver an incredible hosting experience through an immediately recognizable platform. cPanel was designed to make it easier for website owners and server administrators to perform tasks related to their systems. Like many applications, it takes the esoteric and obtuse and simplifies it with an easily navigable interface. You can quickly take steps to modify your cloud – using point-and-click options – so that it meets your requirements, whether you have one site or server or hundreds of them. The core goal of the software is to make the user’s experience more streamlined and less tedious. Basic functions that can be automated through cPanel include the following: - Database creation - Organization of site files - Establishment of email users. ## What Is the Difference Between cPanel and WHM? Both of these control panel elements are part of the same package, with each of them representing a different interface with its own set of features. CPanel itself is geared toward web developers and website owners to organize and maintain their sites. WHM, on the other hand, offers a broad array of server automation capabilities for system administrators. The combined strengths and functionalities of the [two environments](http://cpanel.net/cpanel-whm/%20) help businesses tighten their budgets, making tasks easier to complete and giving end-users the ability to self-manage. ### cPanel – Website Owners cPanel, the side of the overall system that focuses on the needs of website owners, allows you to manage aspects of sites such as email, databases, security, and applications. The user interface, immediately recognizable to many web professionals, provides comfort and is the first step toward a more efficient experience. In a new hosting environment, rather than having to master a new UI, everything looks essentially the same when switching between two cPanel-equipped servers. Here is a cPanel basic features list: - Email management - Spam projection through SpamAssassin and a proprietary tool called BoxTrapper - File management through FTP and File Manager - Database administration via phpMyAdmin, PostgreSQL, and MySQL - DNS management and simplification of zone file maintenance - Analytics for your site. ### WHM – Server Administrators WebHost Manager (WHM) gives web hosting services an easy-to-use interface for server account management. The software allows system administrators to adjust security configurations; modify or add accounts; revise services, and change DNS and FTP parameters. Here is a WHM basic features list: - Configuration and adjustment of accounts - Notifications regarding downtime - Streamlined application and language package installation - Setup of hosting plans - Anti-spam tools - Integration with virtualization and other cutting-edge technologies - White-label changeability so that providers can brand with their own logos. ## Getting Your cPanel Cloud Server Not everyone wants to manage their sites and/or servers with cPanel, and some users prefer to install it themselves. At Atlantic.Net, we understand that a cPanel cloud is not for everyone, but we also make it extraordinarily compelling to choose this hosting option: - Plans have affordable, flexible options for every budget - We reduce your cost by charging based on real-time, per-second use - Setup and DNS are free - There is no contract - You can have the server deployed within 30 seconds - Performance is optimized with 100% enterprise-grade solid-state drives (SSDs). In other words, Atlantic.Net makes it easy for you to try out [cPanel VPS](https://www.atlantic.net/vps-hosting/) Hosting today – or learn more about our [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/). By Moazzam Adnan --- # What Makes Cloud Hosting Better Than Traditional VPS? > URL: https://www.atlantic.net/vps-hosting/what-makes-cloud-vps-better-than-traditional-vps/ | Published: 2014-08-22 | Updated: 2024-11-14 | Author: Kent Roberts In the early days of the Internet, the only option to have a website was to use your own dedicated server to host it. Quickly, a more affordable and widely accessible option emerged: shared hosting, which allowed the sharing of a single server by several different companies. Dedicated and shared hosting met the needs of many organizations. Still, a middle option was desirable to reduce costs (similar to shared) while customization and control could be maintained (similar to dedicated). The concept of virtualization, via a virtual private server (VPS), gradually became a popular way to structure a server. ## How the VPS has changed Initially, the VPS was associated with a single machine – one piece of hardware. That changed when cloud computing developed. The cloud took that same basic virtualization model for a server. It turned it into a structure that optimized performance and cost-effectiveness by utilizing the resources of many physical machines. Since a Cloud Server was amorphous – variable moment-by-moment – and constructed of many different pieces, it was capable of determining the hardware with the highest availability to most effectively handle a given request in real-time. Major backend technology hardware companies are reorganizing their businesses so that the cloud is the central component. Below, we will briefly explore the changing landscapes at IBM and Cisco to better understand how information technology is rushing toward the cloud. Why is this transition occurring, though, and what’s in it for us as VPS users? Lindsay LaManna of SAP, a German company that is one of the world’s largest software providers, recently published an article on six primary strengths of cloud computing. After looking at the transition from hardware to cloud, we will explore the benefits of the cloud outlined by LaManna. Overall, we will develop a better understanding of why cloud VPS is preferable to the traditional variety. ## IBM & Cisco – major tech companies buying into the cloud IBM estimated that US businesses would spend $13 billion on the cloud in 2014. IBM and Cisco – both of which have made significant profits producing server components for data centers – have now shifted their focus toward the cloud. That was partially out of necessity: both companies experienced a significant dive in revenue for their hardware components in 2013. Although it’s a bit oversimplistic, the primary reason is apparent: cloud computing is more efficient, so less hardware is needed. In other words, the cloud streamlines IT. How those two heavy-hitters are adapting to the age of the cloud provides a broader sense of the technology’s potential. Since the cloud distributes a server’s workload across several physical machines, deploying a cloud VPS that operates through a global network of data centers is possible. In recognition of that potential to improve performance by localizing content and reducing latency, [IBM](https://www.ibm.com/us-en?ar=1) is building 15 new cloud-focused data centers this year. Cisco, meanwhile, announced in January that it would be investing heavily in the Internet of Things, which CEO John Chambers predicted will grow into a $19 trillion industry by the end of the decade. ## Strengths of cloud VPS hosting Here are the primary advantages associated with the cloud, as highlighted by SAP: - *Agility & lower response time* – The actual storage of the equipment for cloud infrastructure is the realm of the cloud hosting provider (CHP) rather than the customer. Offloading that responsibility to an expert makes it easy to adjust when needed, immediately and accurately. Plus, cloud systems aren’t hardware, so that they can be ramped up or down instantly (unlike a traditional VPS). - *Updating & maintenance* – All software updates are performed by the CHP, too, as are any hardware tests and fixes. Not needing to worry about updates guarantees you strong security and less time spent managing your systems (a factor shared with an externally hosted traditional VPS). - *Immediate adoption* – You can have a cloud server up and running in 30 seconds, and your cloud platform is available to anyone you want, in any location. A traditional VPS could be tied to a cloud-hosted UI to benefit from high performance worldwide, but it is not as easy to create and destroy the VPS. - *More secure* – Many IT professionals have warned against security threats presented by the cloud. However, SuccessFactors notes that it increases security (over the traditional model) based on rigid ISO security standards followed by reputable providers. - *Speedier development* – LaManna estimates that a cloud system takes 25% as long to be realized – developmentally – as does an on-site solution (such as one utilizing traditional VPSs): 6-9 months versus 2-3 years. - *Minimized risk* – You can try out new projects without making your company financially vulnerable. Since cloud providers allow you to pay for resources on-demand, with no specified “space” that you are reserving (as is true of a traditional VPS), your costs are drastically reduced. ## Cloud: a no-risk option Despite all the other great aspects of the cloud, that last point made above is fundamental. Since the risk of trying out the cloud is so low, it’s easy to dabble and figure out what solution works best for you. Atlantic.Net offers “no contract, no commitment” Cloud VPS Hosting server plans, representing the freedom offered when choosing a flexible SSD [VPS hosting](https://www.atlantic.net/vps-hosting/) plan over a traditional one.  See our [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). By Kent Roberts --- # Lawyer Gives Recommendations for HIPAA Compliance > URL: https://www.atlantic.net/hipaa-compliant-hosting/lawyer-gives-recommendations-for-hipaa-compliance/ | Published: 2014-08-29 | Updated: 2025-03-06 | Author: Alexander Wise Like anything related to federal regulations, HIPAA compliance is not exactly a lighthearted and relaxing topic. However, the Security Rule and Privacy Rule of Title II establish strong standards to protect PHI (protected health information). Regardless of our perspectives toward the law, understanding it is critical for healthcare organizations so that they can avoid fines. ## James Wieland’s Advice for HIPAA Compliance Mike Miliard, the managing editor of Healthcare IT News, stated in March that the federal government would be cracking down on non-compliant healthcare organizations [this year](http://www.healthcareitnews.com/news/lawyer-offers-tips-hipaa-compliance%20). Specifically, he reported that Susan McAndrew of the US Department of Health and Human Services (HHS), speaking at the annual conference of the Health Information and Management Systems Society (HIMSS), said that 2014 would be a year in which compliance is “where the action is going to be.” In other words, getting properly aligned with the HIPAA omnibus rule (which went into effect September 23, 2013) is a must. Miliard interviewed James Wieland, an attorney, and principal at Ober|Kaler’s Health Law Group, to further understand healthcare compliance among IT executives. Wieland regularly works with healthcare firms, so he provided clarity on points of the law that have generated the most confusion for his clients. Here are Wieland’s five tips: ## 1. Electronic access is as much of a right as privacy. Consumers use their rights to information more commonly now since most records are available digitally, notes Wieland, with people of all demographics becoming more aware of their health care rights. That means more responsibility and costs for your business. There is a silver lining here, though. You can charge for the hardware. You probably don’t want a random USB drive from a patient plugged into your computers, which is reasonable. Wieland’s clients buy large amounts of thumb drives and then provide them at cost, which is entirely legal. ## 2. You must have approval in writing for transfers of PHI. Any confirmation that you can send protected health information must be in writing. It’s not enough to get verbal permission, and everything must be directly communicated in the written word to stay compliant. Interestingly, Wieland notes that PHI can be transferred via a method that is not secure, such as standard Web HTTP protocol. However, if you do send anything through unencrypted means, you must have a specific statement from the patient that they understand the security risk of unencrypted transmittal. ## 3. It’s wise to have a verifiable risk assessment. You want to have conducted a risk analysis and resolved any possible vulnerabilities. Wieland notes that risk assessment is particularly needed by healthcare providers that use third-party security solutions, adding that risk documentation will be the top item wanted by the HHS’s Office of Civil Rights (OCR) if they investigate your organization following a breach. Small organizations can perform the assessment without outside help, using guidance from the government published in 2012. The annual guidance covers the OCR’s risk analysis expectations. You need to analyze how PHI moves within your infrastructure, record a comprehensive explication of risks, and develop a mediation strategy at a fundamental level. ## 4. It’s not just about compliance but meaningful use. It helps to understand the compliance activities in a broader context, incorporating meaningful use. As Wieland mentions, “meaningful use” of the EHR goes beyond the EHR itself to include any risk analysis of your medical record system. Wieland also stresses that meaningful use audits are annual, while HIPAA risk analysis only needs to occur when significant data migration occurs. ## 5. Be on top of user settings. One mistake made by many healthcare providers that is entirely avoidable is making sure the user settings are appropriate. You need to be aware of the settings that users can change and prevent any users from accessing or adjusting elements that could put you at risk. ### Why the law changed & breach notification advice It also helps to consider what motivated the HIPAA modifications. Data loss has become more common recently as data has migrated to new technologies, according to Wieland, who says it’s reasonable to make the regulatory changes. He also thinks that the OCR didn’t think people were being careful enough under the old language. He notes that the new focus on individual harm is more complex and subjective, trumping the previous, objective focus on data compromise. Wieland also recommends sending out notices in the event of a breach. He argues that breaches are subject to accounting. If someone wants to look at the accounting, and they see that you had a breach and did not send out notifications, you will be in a terrible legal position – which he describes as “‘deep doodoo.’” ### Finding a strong business associate for healthcare hosting The above tips are great advice for healthcare providers to consider how PHI is handled at their office. While we make our healthcare clients’ data completely private and secure, all information on our HIPAA compliant systems is provided transparently so that you can understand the exact protections in place and oversee your data from every angle. Check out our [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) plans today and also consider one of our [VPS Hosting](https://www.atlantic.net/vps-hosting/) options. --- # Alternative operating system focused on features, speed and stability for startup and developer community > URL: https://www.atlantic.net/press-releases/alternative-operating-system-focused-features-speed-stability-startup-developer-community/ | Published: 2014-09-03 | Updated: 2024-03-01 | Author: Editorial Team ORLANDO, FL – September  03, 2014 — Atlantic.Net, a SSD cloud VPS hosting solutions provider, today announced the availability of FreeBSD, a complete operating system used to power modern servers, desktops and embedded platforms to its Orlando, Dallas and Toronto data centers. The new operating system will be made available system wide as part of Atlantic.Net’s full line of operating systems, including Windows Server 2012R, and various flavors of Linux. With FreeBSD, users receive an OS that is committed to delivering the best stability, performance, and functionality. Atlantic.Net is among the first of a new generation of hosting solutions providers to offer a reliable, yet regularly requested substitute for Linux. With this, startups and indie developers alike can now launch their idea for a fraction of the price typically charged – $0.00135 per hour – with usage calculated on a per second basis. FreeBSD is a win-win situation that will promote entrepreneurial innovation and the wellbeing of the digital ecosystem. “FreeBSD by design is open source, and is optimized for freedom and flexibility. With this new addition, we can pass these benefits onto our customers to deliver a robust BSD-based OS,” said Marty Puranik, President and CEO of Atlantic.Net. “FreeBSD will help push startup innovation and assist entrepreneurs in launching the next great idea.” FreeBSD provides users with access to a library of independent applications. Its advanced networking, security and storage features have made FreeBSD the platform of choice for many of the busiest websites and most pervasive embedded networking and storage devices. FreeBSD understands the relationship between various services and will run them simultaneously or independently, as it best fits the unique situation. In collaboration with [FreeBSD](https://www.atlantic.net/vps-hosting/), Atlantic.Net also announced today the availability of a new resize feature that will allow customers to enlarge their server and capabilities. Unlike many hosting solutions providers, resize allows users to enlarge the disk/RAM/processor, rather than just the RAM or processor. FreeBSD and resize features are just two new services on the roadmap for Atlantic.Net as the company continues to build and grow its infrastructure over the next 12 months. About Atlantic.Net Atlantic.Net is a web hosting provider specializing in offering cloud server hosting, HIPAA compliant and hybrid hosting, private virtualization, and VPS hosting in the cloud. With a range of certifications and a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited data center that the company owns and operates, the company is also known for its reliability, as dictated by its 100 percent uptime service-level agreement (SLA). For more information, please visit [www.atlantic.net](https://www.atlantic.net/). # # # CONTACT: [marketing@atlantic.net](mailto:marketing@atlantic.net) --- # Cloud Hosting for 100 Websites – a Real World Scenario > URL: https://www.atlantic.net/hipaa-compliant-wordpress-hosting/cloud-vps-hosting-for-100-websites-a-real-world-scenario/ | Published: 2014-09-05 | Updated: 2025-08-07 | Author: Kent Roberts I’m going to let you in on a little business secret: customers care about customer service. Hard to believe, isn’t it? Customer support software company Zendesk sponsored a research study in 2013, conducted by independent research outfit Dimensional Research. The findings were based on surveys of 1046 people in response to the customer support they received at midsized businesses. ## How do customer support interactions impact customer trust and business revenue? Here are the key findings of the customer support study that are related to revenue: - Survey respondents listed customer support as the factor most influencing their trust in a company. - Three out of every five (62%) B2B and two out of every five (42%) B2C customers made additional purchases following a positive support interaction. - Two out of every three (66%) of B2B and half (52%) of B2C customers never bought from a company again following a poor support experience. - Seven out of every eight (88%) have changed their purchasing behavior after reading customer reviews on the Internet. It’s clear from the above information that customer support strongly influences how customers feel about companies, which makes sense. It also makes sense that businesses with impressive customer support want to flaunt it, as 37 Signals did when they started publicly posting their customer satisfaction data in real-time (as reported by [KISSmetrics](https://blog.kissmetrics.com/customer-service-worth-stealing/) in March 2014). We like to show off our focus on customer support since many hosting companies and those in the tech field, in general, have often suffered in that department. We promote our 24/7 support consultants through our Real World Scenario series, which highlights specific customer/consultant interactions such as the below, in which a customer needs help modernizing the hosting for 100 websites. ## Transitioning 100 websites from legacy servers to private cloud hosting servers *Please note that the following transcript is edited for clarity, space, and privacy/anonymity.* Client: Hi, I need a call. We have over 100 sites with 2000 pages on old tech. Consultant: Thank you for contacting Atlantic.Net. Please call me at your convenience or send me your exact requirements by email. I can also call you if you want to provide me with a number and time to call. Client: We need to know what would work best. See below details: - 300 MB - 750 pages in one site - 5000 unique hits, maybe 15,000 pages a month - large home page, slow now on IPOWER shared. Which cloud server is best, or should we go with Shared? We may add 130 mini-sites as well, 1 to 3 pagers. May have 130 domains. I may need a few IP addresses. We are looking at Atlantic.Net, Bluehost, HostGator, and Rackspace. Our developer said iPage, but I noticed bad press. We also have a separate project doing video conferencing that will potentially need large dedicated processing once [developing business scenario omitted for customer privacy]. Consultant: How many IPs do you require? Client: Maybe three. Consultant: We no longer offer shared web hosting, so your only choice with us is our public cloud hosting platform. We recommend you use the medium plan with cPanel/WHM. - Linux medium plan – $19.94 per month - cPanel/WHM – $14.97 per month. ( 1 ) IP is included ( 2 ) extra IPs – $7.94 per month. Our public cloud server is an unmanaged platform, and you will have root access to load anything you require. If you would like us to set up a LAMP stack environment on the server for you, we can do it for a one-time charge of $75. When you’re ready to move forward with the videoconferencing project, we will need details on your hosting requirements. This type of project will require either a virtualized or non-virtualized dedicated server platform. Client: Sorry, what is a LAMP stack? I know how to use IPOWER and cPanel myself. The developers know more. I’d like it to be easy for me to upload some HTML mini-sites. Do we have unlimited domains to point at this? We have 230 in GoDaddy to point. This seems like a good deal. What else would we miss from Rackspace, or do you have everything they do? They are trying to sell us cloud. LAMP is Linux, right? We run WordPress, by the way. Consultant: A LAMP stack is the installation of Linux, Apache, MySQL, and PHP. It’s an incredibly popular open-source system used as a central platform for dynamic websites. We can install WordPress also for you under the $75 one-time charge. The cPanel control panel allows for unlimited domains. Client: All right, this plan sounds excellent. I’m ready to move forward. Consultant: Great, you can complete the signup process here: [SSD Cloud Hosting](https://cloud.atlantic.net/?page=signup) sign up, and then we can complete your requested work. ## Teaming up with strong customer support As seen in the above interaction, we care about helping our customers find the best solutions, and it doesn’t just apply to sales. Our courteous and reliable 24/7 support consultants are always available so that your Atlantic.Net experience exceeds your expectations. It’s affordable and simple to transition your legacy hosting to ultra-fast, ultra-efficient cloud server hosting. Atlantic.Net also offers managed and [HIPAA WordPress](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/) hosting solutions. By Kent Roberts --- # 5 Tips to Optimize Cloud Security for Developers > URL: https://www.atlantic.net/hipaa-compliant-hosting/5-tips-to-optimize-cloud-vps-security-for-developers/ | Published: 2014-09-12 | Updated: 2025-03-06 | Author: Alexander Wise If it’s a popularity contest, the cloud is winning. February 2014’s State of the Cloud Survey gathered information and perspectives on cloud computing from 1068 IT executives throughout a broad spectrum of economic sectors. 24% of those who completed the survey were from enterprises employing 1000+ people. This year’s results show that the cloud has exceptionally high acceptance, with 94% of companies either using cloud applications or Infrastructure as a Service (IaaS; also called Hardware as a Service, or HaaS). 87% of companies are partially integrated with a public cloud, while 74% either have a hybrid cloud in place or plan to transition to that model. ## Cloud Adoption Reaches Ubiquity As the survey report indicates, cloud adoption has “reached ubiquity.” Part of the reason that’s the case is that security concerns have receded. The percentage of survey respondents who view cloud security negatively fell in both the Cloud Beginners and Cloud Focused groups (terms used by the research team that refers to those starting their first cloud projects and those with business systems that rely on a substantial amount of cloud technology). In fact, many computing experts have considered the cloud – especially in its private sense – to be secure for years, assuming the correct configurations and safety protocols are in place: the US Department of Defense started using cloud computing in 2011. Regardless of how secure the cloud can be, the security of a particular cloud environment can be better or worse based on what protections are in place. John Grady of Developer.com, in an article published in June 2014, offers [five tips](http://www.developer.com/services/dev-cloud-5-tips-for-secure-environment.html) that can improve the security of a cloud-based development environment. ## 1. Data Breaches The biggest concern of developers, says Grady, is a data breach. Building an application that is fully compatible with all operating systems and devices is complicated enough without worrying about code theft. However, for developers, just a few lines of lost code could mean that the script must be regenerated from scratch and that – worst-case scenario – a copycat application is released using the leaked snippet. A trusted way to defend against a data breach incorporates encryption technology and the management of user permissions. You want to ensure that all data is encrypted, especially when it is in motion – moving from a client device to the cloud or between devices. Your cloud service provider (CSP) also should not be able to access any of your files or content. As Grady notes, “Oversight… Is the mandate of a reputable vendor.” ## 2. Problematic APIs Two major security issues arise from application programming interfaces (APIs). One is that CSPs use them to control access, but malicious parties can extend the interfaces to give themselves a full range of privileges.  A recent example of that was the discovery by a French computer scientist that you can perpetuate a brute-force attack via iOS to hack any Tesla Model S by manipulating the API that the carmaker engineered itself. Another security loophole could arise when open-source APIs are integrated with projects, giving users broader permissions accidentally. The standard rule of thumb for APIs, says Grady, is minimalism. It’s best to create the entire API yourself, but if you do use anything from an outside party, make sure you have a comprehensive understanding of the external code before integration. ## 3. Distributed Denial The dreaded distributed denial of service (DDoS) attack is one of the top concerns for any developer because it can completely shut you out of your system. You can’t know if your code will be corrupted or not until everything is back running correctly. However, a significant problem with DDoS is not the attack itself but its strength as a decoy.  Distributed denial of service causes a state of emergency, and many providers forget about other security tools such as firewalls while the attack is underway. Your cloud provider must have adequate brute-force detection systems in place, along with solid disaster recovery mechanisms. Research your CSP to know how often they have downtime and how quickly the cloud platform was fully recovered. ## 4. Resource Compromise Many developers benefit from the cost-effective performance of the public cloud, which disburses resources on-demand (as needed). Because of the cloud structure, some malicious parties now hack resources, claiming and using cloud power for their own purposes. This tactic can increase your latency and malware risk. Security and scanning tools that track resources and sense intrusion can be used both within private cloud hosting and on client devices by developers and their CSPs. ## 5. Multi-Tenancy Although a cloud computing system is much more sophisticated than shared hosting, it does have one major element in common with them: multi-tenancy. In a public cloud environment, it’s possible that your data could be stored in proximity to code that becomes corrupted or gets analyzed by the government. Know what your service-level agreement (SLA) stipulates in terms of information release to law enforcement. Apple specifically states that it doesn’t provide any data from its cloud to outside parties unless a warrant is presented. Still, some CSPs leave themselves with the right to comply, so they don’t risk a general shutdown. ## A CSP That Deserves Your Business From the above five tips, you can see that wisely selecting a cloud service provider is a fundamental step to increasing your security. Just because the cloud is new does not mean your hosting company should be. Atlantic.Net has been in business since 1994, and we offer best-in-class [VPS hosting](https://www.atlantic.net/vps-hosting/) with no contracts and no commitments, live in 30 seconds. We also provide [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) services. --- # A Brief History of Linux/Open Source Distributions > URL: https://www.atlantic.net/vps-hosting/a-brief-history-of-linux-distributions/ | Published: 2014-09-16 | Updated: 2023-10-25 | Author: Kent Roberts Like Windows or iOS, Linux is an operating system, and it serves as an interface between a computer’s hardware and the applications operating on it. Unlike the competitors mentioned above (proprietary software created by Microsoft and Apple), Linux is free and open-source. It was created using a kernel developed by Linus Torvalds while attending the University of Helsinki in Finland. ## History of Linux According to [Linux.org](https://www.linux.org/), Linus Torvalds was initially developing applications at the University of Helsinki with a version of UNIX called Minix. However, he became dissatisfied with that system because, when he and others sent ideas for revisions to Minix creator Andrew Tannenbaum, the user comments were often ignored. Torvalds opted to design a new operating system that would focus heavily on incorporating user modification suggestions. The notion of collecting community ideas to create better software had been around since the early 1970s when Richard Stallman of the Massachusetts Institute of Technology (MIT) started promoting the concept of collaborative development. Like Torvalds with Minix, Stallman had become disenchanted with the status quo, departing MIT in 1984 to find a GNU nonprofit. GNU’s mission was a direct extension of Stallman’s philosophy: the organization developed software that could be freely used, distributed, and modified. This approach fit perfectly with Torvalds’ concerns. In 1991, Torvalds had developed a kernel, but he did not yet have an operating system. To be clear, a kernel is a necessary component of an operating system, but it can’t achieve any tasks without programs (e.g., shell, library, compilers). Richard Stallman, meanwhile, had programs but lacked a functional kernel. A technological marriage was arranged between GNU, located in Cambridge, Massachusetts, and the Linux kernel, located in Helsinki, Finland. The code was transmitted through the Internet to allow the union between the two developers’ systems. In other words, Linux was born on the Internet, and that’s also where it continued to grow through developer comments. ## History of Linux Distribution (“Distros”) Speaking of its continued growth, Linux [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions quickly expanded into several “distributions,” which – also called distros or flavors – express the diverse ideas of different developers. Here is how several of the most common flavors arose. ### Ubuntu history Ubuntu, like other open-source offerings, is rooted in the idea of a technological community. In fact, per the [official Ubuntu site](https://ubuntu.com/), *ubuntu* is an ancient African word that expresses selfhood springing from group identity. Ubuntu was created by Mark Shuttleworth and a developmental team in 2004 to bring the Linux operating system to all PC users rather than just those administering servers. Shuttleworth recruited his team out of the community of another distribution, Debian, to design a user-friendly open-source desktop in addition to a server OS. ### CentOS & Fedora history In 1993, a startup called Red Hat was founded by Bob Young and Marc Ewing. The following year, they combined various open-source programs into one of the first distributions, Red Hat Linux 1.0. Red Hat continued to evolve over the next ten years, when, in 2004, Fedora and CentOS arrived – as detailed by Tumra CTO Michael Cutler. Red Hat was a for-profit business, making its money through ancillary services such as education and support for the OS. Not everyone who used Red Hat agreed on how it should develop, though. Some users, categorized by Cutler as “Linux enthusiasts,” wanted Red Hat to be focused on innovation. Though relying on Red Hat support, enterprises were more concerned with stability for use on thousands of servers. By 2004, it was decided that it made sense to have two different distributions, one for each type of user: Red Hat Enterprise Linux (RHEL) for the enterprise folks and Fedora for the enthusiasts. Fedora, rather than being managed by Red Hat, is governed by open-source developers. Nonetheless, Red Hat staffers still contribute to Fedora code. Another free distribution was created at the same time (first release [May 2004](http://en.wikipedia.org/wiki/CentOS)) called CentOS, so that a free option would be available for those who prioritize stability over innovation. This distribution was intended to be enterprise-grade, fully binary compatible with RHEL. The CentOS source code is almost identical to that of Red Hat Enterprise Linux, and its updates and versions are synchronized with those of its upstream source. ### Debian history Ian Murdock created the Debian Project in 1993 (the same year that Red Hat was formed). The development of the distribution was sponsored by GNU between 1994 and 1995. At its inception, Debian was the only Linux flavor that allowed any user to contribute ideas. According to the [official Debian site](https://www.debian.org/), it remains the only large, non-commercial project that includes policy documents, a constitution, and a social contract, serving as interactive guidelines for ongoing development. ### FreeBSD history FreeBSD is **not** a Linux operating system, but it’s discussed in the same general category because it is also Unix-based, accessible, and open source. The University of California, Berkeley, used UNIX source code it had acquired from AT&T in its computing classes, with students modifying it into Berkeley Unix or BSD (Berkeley Software Distribution). That project began in 1976. Unfortunately, because it used code from the AT&T version, it required a paid license. In 1989, work commenced on all of the AT&T code. The resulting operating system, released in 1992 by William and Lynne Jolitz, was called 386BSD. It was updated and renamed [FreeBSD](https://en.wikipedia.org/wiki/FreeBSD) in 1993. ### Be a part of history With the exception of RHEL, all of the Linux distributions featured above are available through Atlantic.Net, as is FreeBSD. History takes time and patience, but you don’t need that with us. Get your affordable [Virtual private server](https://www.atlantic.net/vps-hosting/) up and running in 30 seconds, with 24/7/365 live support and no contract. Thank you for reading. To learn more and for helpful how-to’s, we have an impressive variety of both Linux and FreeBSD articles available in our blog. By Kent Roberts   --- # The Rise of the 3D Printer: Hype or Revolution? > URL: https://www.atlantic.net/vps-hosting/the-rise-of-the-3d-printer-hype-or-revolution/ | Published: 2014-09-25 | Updated: 2024-10-21 | Author: Kent Roberts Electric self-driving cars, Suborbital space flights, cloud computing, content delivery networks, and 3-D printing. These tech concepts were seen as extraordinarily innovative when they were first introduced to a mass audience. Although some so-called “new” technologies have been in development by various parties for years, once they start to go mainstream, we are easily skeptical: “Is this as huge as the public and the press want to think it is,” we wonder, “or is it just hype?” 3-D printing is all over the place these days, and it appeared in many of the emerging tech trends lists for 2014. In his compilation of [10 hot trends](http://venturebeat.com/2013/12/06/top-10-tech-trends-for-2014-wearables-3d-printers-mobile-money-and-more/) for VentureBeat, John Koetsier predicted that, throughout 2014, 3-D printing would “increase significantly” as crucial players, including Microsoft, Samsung, and HP, entered the arena. The International Space Station even has a printing device [with an additional dimension](http://venturebeat.com/2013/05/28/nasa-3d-printing-international-space-station/) installed this year. This field is not new. *The Economist* called it a “third industrial revolution” in 2012 in an article that cited Paul Markillie’s perspective that the 3-D printer would be incredibly disruptive to the manufacturing world, shipping a sizable portion of production back [to wealthy nations](http://www.economist.com/node/21552901). Although it’s been on the table for some time, the 3-D printer has staying power. It’s even been dressed up for broader consumer awareness in the documentary *Print the Legend*, which debuted at the SXSW festival in Austin, Texas, earlier this year (above). Even President Obama has become involved. He said in his [State of the Union address](http://www.cnn.com/2013/02/13/tech/innovation/obama-3d-printing/) in 2013, “3-D printing has the potential to revolutionize the way we make almost anything.” Again, though, it’s trendy. As with any trend, it’s a little difficult to tell when it’s going to plateau. Where do we now stand in the uphill climb of this technology? Investment firm Motley Fool said on September 9 that stocks for 3-D printing firms “have a tremendous runway for growth.” According to the coverage on the [Fool.com blog](http://www.fool.com/investing/general/2014/09/09/why-3d-printing-stocks-could-have-a-tremendous-run.aspx), Wohlers Associates has been assessing the 3-D printing sector for three decades and significantly increased its projections in the Wohlers Report 2014. In last year’s report, Wohlers forecast that the industry would expand to $10.8 billion by 2021. This year they revised their prediction, speculating that the global market will grow from $3.1 billion (2013) to $21 billion in 2020. In other words, 3-D printing is growing twice as fast as expected, even just a year ago, based on an assumedly conservative estimate by a financial firm possessing long-term familiarity with the market segment. ## Are We There Yet? You may be able to make your own products with 3-D printers, as long as you’re doing a limited run. However, you have always needed one ingredient that no one seems to have enough of: patience. As Signe Brewster commented in a June report for Gigaom, 3-D printing is excruciatingly slow: in fact, “in the time it would take to print a screwdriver, you could just drive to the store and pick one up with a [half-hour to spare](https://gigaom.com/2014/06/19/the-rise-of-the-super-fast-industrial-3d-printer/).” Well, here’s the thing, noted Brewster: the apparatus is capable of speedier production. All it would require is the use of an extruder that dispenses more material per second, and that can be accomplished simply by thickening its output. Well, the best things come to those who wait: when you go with thicker material, your resolution starts to suffer: you can no longer conceal the transitions between layers. The convenience factor – time – is critical to determining which 3-D printing companies will end up on top, and major hurdles like this are common with developing technologies. Just like the electric car industry has been working furiously to expand the driving range of cars while reducing the cost of batteries (which all took a significant leap forward this summer when Tesla Motors made all its [technological details](http://www.extremetech.com/extreme/184302-tesla-open-sources-all-of-its-patents-and-technology-in-bid-to-kill-gas-powered-cars) open-source), companies in the 3-D printing world have been aggressively trying to increase the pace of their devices. Oak Ridge National Laboratory and 3D Systems are at the forefront of that effort. The lab has been studying and modifying the BAAM 3D printer, manufactured by Cincinnati Inc., with the goal of getting it to print as much as 500 times the rate of a typical mass-market 3D printer. The printer in use is enormous, capable of printing furniture. On a standard printer, chairs would have to be printed in segments and then assembled, and the printing process alone would take days. Using its modified version of BAAM, Oak Ridge could crank out chairs in under three hours apiece. 3D Systems uses a different model based on an assembly line of machines. It sets various printers on a track, each one focusing on specific colors and material types. Did you know that you can make a car with 3D printing? You can even make incredibly tacky jewelry. Heck, you can even do this: 3D printers are exciting. New technology is always fascinating, but stability is required when using hardware and software to run businesses and protect their mission-critical applications or even allow developmental projects to be 100% reliable and secure. With 20 years in business, we know technology, and we know stability. Get started today with one of our award-winning [VPS Hosting](https://www.atlantic.net/vps-hosting/) solutions. Atlantic.Net also offers managed, [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) and [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. By Kent Roberts --- # Atlantic.Net Launches $.99 Server “Go” Plan > URL: https://www.atlantic.net/announcements/atlantic-net-launches-99-server-go-plan-to-push-the-advancement-of-startup-innovation/ | Published: 2014-09-30 | Updated: 2025-03-06 | Author: Alexander Wise This plan is no longer available as of April 7, 2015 The  $.99 cloud Server “Go” plan includes a 256MB Linux or FreeBSD virtual machine, 10GB of SSD storage, and 1TB of outbound bandwidth which will dramatically reduce the cost of developing the next big idea We are pleased to announce the availability of our newly launched $.99 server “Go” plan. Aggressively priced, the new server includes a 256MB Linux or FreeBSD Cloud VPS (Virtual Private Server), 10GB of SSD storage, and 1TB of outbound bandwidth (unlimited inbound bandwidth). Also included is A+B redundant power on each server, enterprise SSDs, RAID redundant storage, multiple Internet uplinks, optional backup, and much more. [Atlantic.Net](https://www.atlantic.net/) is enabling early-stage and bootstrapped startups, along with indie developers, the opportunity to advance their business and give back to the ever-growing cloud ecosystem. By radically lowering the entry cost for a server, Atlantic.Net continues to encourage developers to use the power of the cloud to help imagine the next big thing for their business and the world. Atlantic.Net has effectively reduced the barrier of entry for people who want to learn to code, create apps and take advantage of virtual machines. When we started our business, the concept of the Internet was largely a dream. Similarly, we want to inspire developers to tinker, toy, and imagine the next big thing. We want to invest in our customers to help them get going with their ideas while at the same time growing the cloud market ten times and making this a global phenomenon. As well as the other valuable features, the $.99 server “Go” plan offers pay-as-you-go, per second billing with no term commitment and is up and running in just 30 seconds. These features make the $.99 server “Go” plan ideal for developers and entrepreneurs looking to unveil new concepts and grow their startups with reduced financial risk. Backed by Enterprise SSDs, the $0.99 servers can also take advantage of other features such as additional IPs, backup, DNS, SSH keys, multiple server locations, 40 gigabit Infiniband networking, and more. When a developer is ready to scale up or add additional capacity, users can resize existing servers into more extensive plans (including CPU, RAM, and disk space) or additional Linux, FreeBSD, or [Windows VPS](https://www.atlantic.net/vps-hosting/) hosting servers on-demand. The $.99 server “Go” plan is just one of the many innovative offerings Atlantic.Net is coming to market with as it continues to build and grow its infrastructure based on feedback from the community. --- # Atlantic.Net Launches $.99 Server “Go” Plan To Push the Advancement Of Startup Innovation > URL: https://www.atlantic.net/press-releases/atlantic-net-launches-99-server-go-plan-push-advancement-startup-innovation/ | Published: 2014-09-30 | Author: Editorial Team **The $.99 Server “Go” plan includes a 256MB Linux or FreeBSD virtual machine, 10GB of SSD storage, and 1TB of outbound bandwidth which will dramatically reduce the cost of developing the next big idea.** ORLANDO, FL – September 30, 2014 – Atlantic.Net, a global SSD cloud VPS hosting solutions provider, today announced the availability of their newly launched $.99 server “Go” plan. Aggressively priced, the new server includes a 256MB Linux or FreeBSD Cloud VPS (Virtual Private Server), 10GB of SSD storage, and 1TB of outbound bandwidth (unlimited inbound bandwidth). Also included is A+B redundant power on each server, enterprise SSDs, RAID redundant storage, multiple Internet uplinks, optional backup, and much more. Atlantic.Net is enabling early-stage and bootstrapped startups, along with indie developers the opportunity to advance their business and give back to the ever-growing cloud ecosystem. By radically lowering the entry cost for a server, Atlantic.Net is continuing to encourage developers to use the power of the cloud to help imagine the next big thing for their business and the world. Atlantic.Net has effectively reduced the barrier of entry for people who want to learn to code, create apps, and take advantage of virtual machines. “When we started our business, the concept of the Internet was largely a dream. Similarly, we want to inspire developers to tinker, toy, and imagine the next big thing,” said Marty Puranik, Founder and CEO of Atlantic.Net. “We want to invest in our customers to help them get going with their ideas while at the same time growing the cloud market ten times and making this a global phenomenon,” he said. As well as the other valuable features, the $.99 server “Go” plan offers pay-as-you-go, per second billing with no term commitment, and is up and running in just 30 seconds. It is these features that make the $.99 server “Go” plan ideal for developers and entrepreneurs looking to unveil new concepts and grow their startup with reduced financial risk. Backed by Enterprise SSDs, the $0.99 servers can also take advantage of other features such as additional IPs, backup, DNS, SSH keys, multiple server locations, 40 gigabit Infiniband networking, and more. When a developer is ready to scale up or add additional capacity, users can resize existing servers into larger plans (including CPU, RAM, and disk space) or provision additional Linux, FreeBSD, or Windows servers on-demand. The $.99 server “Go” plan is just one of the many innovative offerings Atlantic.Net is coming to market with as it continues to build and grow its infrastructure based on feedback from the community. About Atlantic.Net Atlantic.Net is a web hosting provider specializing in offering cloud server hosting, HIPAA compliant and hybrid hosting, private virtualization, and VPS hosting in the cloud. With a range of certifications and a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited data center that the company owns and operates, the company is also known for its reliability, as dictated by its 100 percent uptime service-level agreement (SLA). For more information, please visit [www.atlantic.net](https://www.atlantic.net/). # # # CONTACT: [marketing@atlantic.net](mailto:marketing@atlantic.net) --- # Censorship Workarounds: VPN as a Service and Other VM Options > URL: https://www.atlantic.net/vps-hosting/censorship-workarounds-vpn-as-a-service-and-other-vm-options/ | Published: 2014-10-07 | Updated: 2024-11-09 | Author: Sam Guiliano Internet censorship is common around the world. Although numerous regions block the content that web users can see, many people use a VPN service or a cloud service to regain access to materials and websites deemed sensitive or inappropriate by certain governments. People traveling will often want to use a VPN or similar so that they do not break the laws of any countries they are visiting. ## Countries Impacted by Web Censorship *USA Today* covered some of the top countries in terms of [web censorship](http://www.usatoday.com/story/news/world/2014/02/05/top-ten-internet-censors/5222385/) in February 2014, as elaborated in a report issued by the Committee to Protect Journalists (CPJ). - **North Korea** – The North Korean government runs every website that can be legally accessed, so essentially the Internet is another arm of the nation’s propaganda wing. Even so, only 1 in every 25 people can get online. - **Burma** – Email communication is strictly monitored. Users are blocked from any sites that post human rights information or state opposition to the country’s leadership. - **Cuba** – You can only get online by going to centers run by the state. All web access is controlled by blocking IPs, censoring keywords, and monitoring user activity to prevent an open political discourse. It is unlawful for anyone to post anything online that is critical of the Cuban government. - **Saudi Arabia** – Almost half a million websites are inaccessible, according to the CPJ. You specifically can’t view any web content that promotes or discusses cultural, societal, or spiritual subjects that are at odds with the Islamic perspective of the royal family. - **Iran** – To express yourself online, you first must become licensed through the Ministry of Art and Culture. Anyone who expresses sentiments that are in opposition to the mullahs in power are often threatened and imprisoned. - **China** – Although many US household products now say, “Made in China,” differences in the American and Chinese legal landscapes are apparent with web control. China has more strict and extensive censorship than any other nation, per CPJ analysis. Search filtration is used, as is direct removal of access to some websites. Any material the government determines is unsavory is deleted from state-controlled sites. One way China’s censorship is blatant is that any queries for content on Taiwanese independence or the violent events of Tiananmen Square are forwarded to sites promoting the regime. - **Syria** – Anyone who blogs in a manner that might imperil the interests of the country’s leadership is criminalized. Internet cafés collect picture IDs and save usage information on all customers, which is then provided to government agents. - **Tunisia** – Internet service providers (ISPs) are instructed to send data on the IPs and identifying characteristics of anyone who posts online. Anyone using the web must access it through a government hub. The state monitors and controls everything posted on the web and reads any email, as desired. - **Vietnam** – Google, Microsoft, Yahoo, and other companies that run blog hosting sites must supply the government with information on anyone posting into their environments. Any content is rendered inaccessible that is unfriendly to the government or that promotes democratic ideals, civil liberties, or separation of church and state. - **Turkmenistan** – The government of this country doesn’t bother to set rules for ISPs. Instead, it is the only ISP. Users cannot get to various websites. Any users of email through Gmail, Hotmail, and other free services are checked for anti-government content. Beyond the countries listed in *USA Today*, Turkey has proven itself particularly incompatible with the Open Internet in 2014. According to the nonprofit Human Rights Watch, Turkey blocked specific content on YouTube and Twitter [earlier this year](http://www.hrw.org/news/2014/09/15/turkey-strike-down-abusive-internet-measures). Following those two blockages, two anti-Internet measures were passed by parliament on September 10 and signed into law on September 12 by President Erdogan. The first law would allow the regulatory body that controls the Internet, the Telecom Directorate (TIB), to shut down sites at will, with only four hours’ notice. The second gives the government access to a broader range of metadata on users to bolster its surveillance tactics. ## Sidestepping Censorship with VPN & Cloud Servers For many people outside the United States, an American-based VPN is attractive because there is no overarching government censorship. It is an accepted belief that American citizens should have open access to the web. However, some users are not sure they want to use networks located in the United States due to eavesdropping from the National Security Administration (NSA), as exposed by the Edward Snowden case. *(Notably, Atlantic.Net offers virtual server access in both the United States and Canada.)* More and more people want to access the Internet through a virtual machine that protects their security and privacy so that they can remain anonymous. For some users, they simply want to stream a broader range of Netflix films. Netflix offers different movies in different nations, and using other locations gives users access to the Internet experience of various regions. The two tactics used by those interested in accessing the Internet through proxies in different locations are the creation of VPNs and the use of cloud servers. The latter option is typically based on Windows cloud server hosting or [Linux VPS](https://www.atlantic.net/vps-hosting/) hosting, which is available through Atlantic.Net. Get started now. It only takes 30 seconds. ## More About Atlantic.Net Atlantic.Net offers world-class hosting solutions, including [VPS hosting](https://www.atlantic.net/vps-hosting/) services. **[>>> Part 2 – Cloud Servers and VPN Setup](https://www.atlantic.net/vps-hosting/censorship-workarounds-part-2-how-to-set-up-a-vpn/)** --- # Spotlight on Biotech Hosting: A Real World Scenario > URL: https://www.atlantic.net/life-sciences-pharma-biotech/spotlight-on-biotech-hosting-a-real-world-scenario/ | Published: 2014-10-09 | Updated: 2025-03-06 | Author: Alexander Wise We recently had a biotech company contact us about setting up a dedicated system to be hosted at our data center. Although this particular request was for a relatively small, private infrastructure, research companies often need to conduct sophisticated calculations that can be best achieved through cloud computing. We will first look at the biotech connection to the cloud, then specifically discuss a dedicated, real-world scenario. ## Introduction – biotech and an “Aha” moment With the growing dependency of the biotechnology and pharmaceutical industries on cutting-edge cloud computing strategies, one can wager that we are nearing a future in which highly sophisticated, personally customized drugs will be available within days. Genomic testing has become much more advanced through the rapid-fire performance and availability of the cloud. When oncologists in search of a cancer cure and specialists throughout medical science have run data (for diagnostics, efficacy of treatment protocols, etc.), they have previously been largely dependent on how much processing and computing resources can be allocated for their projects. Now, power for any data algorithm is immediately accessible, along with much more affordable costs. It should be noted that excitement about cloud computing is not merely the realm of [VPS hosting](https://www.atlantic.net/vps-hosting/) providers and software-as-a-service companies: many researchers, data scientists, and business professionals from all segments have started to have an “Aha” moment, in which they are beginning to realize the full potential of cloud computing. A March 2013 report by the Association of American Medical Colleges (AAMC) argued that cloud computing should be taken very seriously by the biotech industry and biomedical scientists. Reporter Stephen G. Pelletier noted that it’s understandable how incredibly IT systems have grown within medical research, but running a massive data center internally may not always be the best choice. The legacy model can, in some cases, be prohibitively slow and expensive, and the cloud just makes sense. ### How fast is the cloud? In layman’s terms, just how fast is the cloud? The AAMC interviewed Geoffrey C. Fox, Ph.D., an associate dean of Indiana University’s informatics and computing college. Dr. Fox’s point of view is particularly noteworthy because Indiana University is the home of Big Red II, a supercomputer capable of handling one petaflop maximum, equivalent to one quintillion floating-point operations each second – 1 million billion calculations every single second. That rate matches IBM Roadrunner, the first supercomputer to achieve a petaflop in 2008. As of November 2012, per [Ars Technica](http://arstechnica.com/information-technology/2013/04/ius-petaflop-supercompter-is-the-first-to-be-a-dedicated-university-resource/), the speediest supercomputer in the world was the 17.6-petflop-capable Titan, located at the Oak Ridge National Laboratory in Oak Ridge, Tennessee. Dr. Fox told the AAMC that biotech was a perfect match for cloud computing since it didn’t require the particular configurations of supercomputers. The cloud is as elastic as you want it to be: you can have hundreds or thousands of servers process your request at once, on-demand. The availability of the cloud, though, is particularly compelling: “The cloud’s spare capacity often enables it to process a researcher’s data faster than a supercomputer, “said Fox, allowing researchers to minimize wait times. ## Real-World Scenario – custom dedicated biotech system We work with medical research teams and biotechnology professionals every day. Here is an interaction that occurred between one of our consultants and an anonymous biotech client: Client: We would like to purchase HPC servers according to our configuration (super micro with 1-2 TB RAM) and host it remotely with SSH access. I am looking for quotes for this project to be done in the next month or so. Thanks! Consultant: Thank you for contacting Atlantic.Net. Please provide us with the following information so we can supply you with a formal proposal. 1. Number of Cores in the processor required 2. Actual Amount of RAM required 3. Total Amount of Storage and type of storage ( SATA / SAS / SSD ). Client: Please find the detailed specs for servers we would like to buy and host: [omitted]. Consultant: Thank you for the information. We have attached the pricing for the computing nodes based on a 12- or 24-month agreement. Before we proceed, we would like for you to review the pricing we have prepared and provide us with your feedback. ## The promise of the biomedical cloud Johns Hopkins announced in January 2014 its involvement in a project to compile a massive digital library of pediatric MRI scans. The “Google-like” portal will allow doctors to diagnose children suffering from brain diseases more accurately, thereby improving treatments. That’s just one example of how recent cloud technologies are a game-changer for the biotech field. We are excited to be a functional part of this movement to find rapid-fire and potentially customized disease treatment methods and cures. For that, we have our un-managed Cloud systems, where you can build whatever data environment you want. However, if you need a custom system as the above firm did, we specialize in dedicated [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) Solutions. By Moazzam Adnan --- # Censorship Workarounds: How to Set Up a VPN – Part 2 > URL: https://www.atlantic.net/vps-hosting/censorship-workarounds-part-2-how-to-set-up-a-vpn/ | Published: 2014-10-10 | Updated: 2024-12-05 | Author: Sam Guiliano [**<<< Part 1 – Global Internet Censorship**](https://www.atlantic.net/vps-hosting/censorship-workarounds-vpn-as-a-service-and-other-vm-options/) Are you convinced that having a VPN is a good idea? Here’s one fundamental, incredibly compelling reason that has not yet been discussed: public Wi-Fi. Most people realize that Wi-Fi makes users extremely vulnerable. Casual hackers have software that gives them access to all the packets being passed back and forth on the network. In that case, a VPN is a no-brainer so that you are enforcing encryption and anonymity of your location, identity, and all data transmitted. ## Types of VPNs Eric Geier of [PCWorld](http://www.pcworld.com/article/2030763/how-and-why-to-set-up-a-vpn-today.html%20) recently discussed several simple ways to set up a VPN. They are the following: - basic Windows VPN setup - tapping into a VPN via a third-party application - getting your firmware on with a VPN router - using VPN-as-a-service through a knowledgeable provider. A step-by-step mini-guide for each scenario is described below. ## Windows VPN Every standard Windows installation includes a VPN client. Using it is easy. Simply go to the start menu, or search charm, and input “VPN.” When you select to set up a VPN, you are then directed through a wizard. The VPN client can connect with any other Windows PC and VPN servers compatible with PPTP and L2TP/Ipsec. Just supply it with the domain name or IP address of the machine that you want to visit. When you want access to the VPN of a business or one publicly available, ask the owner for the IP address if you can’t locate it. You also may want to determine the IP of a VPN server that you are operating through Windows. To identify your IP, enter “CMD” into the search box (as you did with “VPN”). Once the Command Prompt populates, input “ipconfig.” The information is helpful when you set up VPN capabilities and want to access the VPN from a second device located anywhere. Be aware that when you establish this type of VPN connection directly through the [Virtual Private Server](https://www.atlantic.net/vps-hosting/), you have to instruct the network router to send all VPN users to the Windows device you are entering from another location. Typically that is achieved by going into the control panel of the router and adjusting so that port 1723 forwards to the target Windows PC’s IP. Plus, your firewall settings must allow access to PPTP, but generally, that is considered default access. ## Third-party VPN Geier recommends a third-party application for anyone who wants a VPN to interconnect various devices so that resources and documents are commonly accessible, with no need for router adjustments or designation of a computer as the server for the VPN. Examples of standalone VPN software – all of which are relatively user-friendly, high-performative, and free – are TeamViewer, Gbridge, and Comodo Unite. Another option is LogMeIn Hamachi, which becomes a paid service once you go beyond five devices. If you do want to connect additional computers, Geier seems to be particularly fond of this solution, even putting on his tech-dandy hat and calling it “elegant.” ## Plug-in VPN If you want various computers to all be able to access your VPN server, or if you want multiple websites to communicate securely, use a router equipped with a VPN client and server. The most cost-effective way to establish a dedicated router is with used firmware – [DD-WRT](http://www.dd-wrt.com/) or Tomato. If you aren’t quite as worried about cost-cutting and need a convenient, trouble-free solution, you can buy a VPN router, which is a router with a preconfigured VPN. This type of device is available from brands such as [Netgear](http://www.netgear.com/business/products/security/UTM-series/UTM9S.aspx), [Cisco](http://www.cisco.com/en/US/products/ps11025/index.html), and [ZyXel](http://www.zyxel.com/us/en/products_services/zywall_usg_200_100_plus_100_50_20w_20.shtml?t=p). Whenever you are looking for either a prebuilt VPN router or firmware, you need to be sure that they are compatible with the VPN protocol required for your machines. You also want to know the number of users that can be accessing your VPN router at any one time. ## VPN-as-a-service Maybe you don’t care about connecting various computers but just want to conceal yourself at Wi-Fi hotspots or get to websites blocked in certain countries. The easiest way to establish a VPN for that situation is using a VPN service or setting up a private [VPS hosting](https://www.atlantic.net/vps-hosting/) server, both of which are surprisingly affordable. If you can’t afford a VPN subscription, try the [Onion Router](https://en.wikipedia.org/wiki/Onion_routing), which distributes your web access throughout a worldwide network. You can access it using the [TOR browser](https://www.torproject.org/projects/torbrowser.html.en). All your transmissions will be encrypted, and you will go online via one of many different servers (although the downside is that you will experience more latency, which of course, is more easily avoidable with a paid service). As hinted above, a virtual private network is just one way to browse anonymously and privately from various locations. You can also use [VPS hosting](https://www.atlantic.net/vps-hosting/), one of our hosting specialties. We will discuss that option next. **[>>> Part 3 – Windows Cloud Server for Anonymity](https://www.atlantic.net/hipaa-compliant-hosting/censorship-workarounds-part-3-windows-cloud-vps-for-anonymity/)** --- # Censorship Workarounds, Part 3: Windows Cloud Server for Anonymity > URL: https://www.atlantic.net/hipaa-compliant-hosting/censorship-workarounds-part-3-windows-cloud-vps-for-anonymity/ | Published: 2014-10-13 | Updated: 2024-06-04 | Author: Sam Guiliano [**<<< Part 2 – How to Set Up a VPN**](https://www.atlantic.net/vps-hosting/censorship-workarounds-part-2-how-to-set-up-a-vpn/) We started this series by talking about the extent to which censorship and site-blocking are common ways that the Internet is controlled around the world. For those who want to access sites that they otherwise could not, or those who wish to access the user experience in various areas (a great way to expand your comparison shopping by checking numerous regions), a VPN (virtual private network) is a viable solution. One way to surf the Internet encrypted and anonymously is with a more full-featured and robust option than a VPN service, a Windows cloud server. Below we will discuss how to get the most out of a cloud server with a Windows operating system to get online from whatever nation you want. **Setting up a Windows cloud server for global VPN surfing** Here’s the basic step-by-step process to use a Windows cloud server as a form of VPN-as-a-service. Note that this guide is intended for a small project. If you need to install a VPN for an enterprise, consider DirectAccess, which Microsoft Hyper-V MVP and [cloud architect Thomas Maurer](http://www.thomasmaurer.ch/2012/07/how-to-install-vpn-on-windows-server-2012/) says has been dramatically simplified in the Windows Server 2012 package. 1. [Sign up](https://cloud.atlantic.net/?page=signup) for a Windows cloud server. The setup is instantaneous, and you can potentially be inside your active server environment within 30 seconds. 2. Set up a VPN on a cloud server running Windows Server 2012 (go here for help with [Windows Server 2008 R2](http://www.thomasmaurer.ch/2010/10/how-to-install-vpn-on-windows-server-2008-r2/)), via the instructions of Maurer, by first setting up the server role Remote Access, using either Server Manager or PowerShell. 3. You should now be looking at the Role Services pane. Rather than “Routing,” choose the option “DirectAccess and VPN ([RAS](http://msdn.microsoft.com/en-us/library/bb416461.aspx)).” 4. When the next window pops open, which should say, “Confirm installation selections,” keep everything as it’s set by default. 5. Then you will add any features through the “Add Roles and Features Wizard.” 6. Finally, switching over to the Getting Started Wizard, you can get into your VPN configurations. 7. On the Configure Remote Access screen, either choose deployment of the VPN and DirectAccess or just the VPN, with the reason behind pairing the two technologies explored below in the “Why DirectAccess?” section. 8. If you chose only the VPN, you will now see the Routing and Remote Access window. You should see your server and right-click on it, selecting the configuration and Enable Routing and Remote Access option. 9. Now you are in a new wizard. Click Next. 10. Assuming only one network interface is on the cloud server, select the option for Custom configuration. 11. Choose VPN access. Proceed through the rest of the wizard, and the service should be running. 12. Within your firewall, you need to forward the appropriate VPN ports to the Windows operating system, which include the following three: •    PPTP – Protocol 47 GRE and 1723 TCP •    L2TP (IPsec) – 500 UDP and 1701 TCP •    SSTP – 443 TCP. 13. Now you want to think about individual users. Everyone has to be given privileges to allow Remote Access. Within a server, you can do that through Computer Management (within Microsoft Management Console, a.k.a. MMC). If you’re working with a specific domain, you can change properties within Active Directory. 14. At this point, you may be finished. However, you may also need to set up a static address pool if there is not a DHCP (dynamic host configuration protocol) server within the local network. That is often the case for companies using one Windows cloud server through a hosting company. To get started, right-click Remote Access Server, choosing Properties. 15. Go into the IPv4 menu and choose the option “Static address pool.” 16. Now set up whatever pool of IP addresses you want, such as 123.456.7.100 – 123.456.7.200. 17. If you are using a cloud server with just one public IP, you want to add another IP address in the network interface that shares the subnet with the pool you just created. **Why DirectAccess?** DirectAccess is specifically designed to connect all devices to the business network whenever the Internet is available. It allows users to operate remotely as if they were at the workplace, immediately connecting to the business’s content and performance. Additionally, the client PCs are more easily controlled through upgrades and other forms of management. Typically DirectAccess is used in conjunction with a VPN. [Benefits of DirectAccess](http://technet.microsoft.com/en-us/library/dd875522%28v=ws.10%29.aspx%20) are as follows, per Microsoft: - An automatic connection that requires no action by the user. - Functional regardless of any firewalls. - Configured for selected server access and IPsec directly with a network server. - Allows more seamless encryption that is truly end-to-end. - Permits administrators to manage remote PCs. VPNs, on the other hand, should be used for the following scenarios: - Earlier versions of Windows on client machines. - Any devices that are not using Microsoft. - Any devices that are not within your business’s domain. - Other operating systems on the cloud server besides Windows Server 2008 R2 or Windows Server 2012. **Why get started today?** All your resources are on-demand with a Windows cloud server: you only pay for what you use. You are in a protected environment that is free of malware and viruses. You don’t have to worry about problematic files: when you have completed any surfing, just delete the live cloud server, and any infections are obliterated. For safe browsing and peace of mind, [sign up](https://cloud.atlantic.net/?page=signup) for your Windows cloud server with Atlantic.Net now! *Atlantic.Net also offers managed, [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/), and [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions – contact us today for a consultation.* --- # A Real World Scenerio of Public & Private Cloud Hosting > URL: https://www.atlantic.net/vps-hosting/hybrid-hosting-combining-private-public-cloud-a-real-world-scenario/ | Published: 2014-10-14 | Updated: 2025-03-06 | Author: Alexander Wise It used to be the case that the media and IT industry just spoke of “the cloud,” a way to distribute resources to increase reliability, speed, and cost-effectiveness. However, security was a reasonable concern since all users share the same machines, even if they each have their own virtual private servers within the network. Soon the demand rose for solutions that combine the rapidity and agility of a distribution model with a core focus on data isolation. That concept was the private cloud, which has grown enormously: it had $8 billion of overall revenue in 2010 versus [$32 billion in 2013](http://www.computerworld.com/article/2490138/private-cloud/enterprises-increasingly-look-to-the-private-cloud.html). Now many organizations are looking to combine their public and private clouds into a hybrid system. The appeal of this type of environment is broad, with Gartner predicting that half of enterprises will have a hybrid cloud deployed by 2017. ## Real-World Scenario – Hybrid Cloud Below is a Real World Scenario (RWS) based on a transcript between one of our hosting consultants and a client in need of a hybrid cloud. Consultant: Welcome to Atlantic.Net. Would you please tell us about your hosting needs? Client: I’m in the pricing stages with [major cloud vendor] and just discovered you. I’m the VP of Engineering. We’re looking for a client-centered [VPS Hosting](https://www.atlantic.net/vps-hosting/) provider that has Sarbanes Oxley and SSAE 16 compliance.  We need ~30 VMs of various specs running a traditional Java stack with Postgres.  We have one custom appliance, a modified CentOS kernel that runs the iFax server.  Ideally, we need ~30 standard Ubuntu LTS or CentOS cloud VMs and one VMWare or Linux KVM hosted VM for the iFax appliance.  I would love to discuss pricing and technical requirements with you.  The sooner, the better. Consultant: Please call me at the number listed below, or provide me with your phone number, and I will contact you. Your application would work on our Public Cloud hosting platform, which is unmanaged. However, we do not offer a firewall solution on our Public Cloud Platform, so that is an issue since you have the Sarbanes Oxley requirement. We can also provide you with a proposal for a Managed Private Cloud platform that would meet all of your security requirements. We would need answers to the following questions to send you a proposal. [Questions included in reply (below)] Client: I’m new to working under the Sarbanes Oxley compliance; however, I’m familiar with running servers in public and private clouds.  My hope is that if we firewall each individual host, we can still be compliant.  If this is possible in the public cloud, that would probably be the most cost-effective.  If this cannot be achieved, then we would be interested in the private cloud options. ## 1.) How many virtual machines (VM) do you anticipate having to accommodate during the first year of this project? Our first year is estimated to have 30 VMs.  These include web servers, Postgres servers, and several lightweight clients that retrieve data.  See below for specifics. ## 2.) What are the specifications (RAM, CPUs, Hard Drives, Operating System, etc.) required for each VM? Here is an estimate of our needs: - Dev tools: 2 cores, 4GB RAM,  100GB storage. - Production Web 1: 4 cores, 8GB RAM, 60GB storage. - Production Web 2: 4 cores, 8GB RAM, 60GB storage. - Production Postgres: 8 cores, 16GB RAM, 160GB storage. - Staging Web: 4 cores, 8GB RAM, 60GB storage. - Staging Postgres: 4 cores, 8GB RAM, 160GB storage. - iFax: 2 cores, 4GB RAM, 160GB storage.  *Custom CentOS appliance (with tainted kernel), 32-bit.* - 20 Downloader VMs: 2 cores, 1GB RAM, 40GB storage. The [iFax](http://www.ifax.com) VM is a custom appliance built on 32-bit CentOS, but it uses a custom kernel.  For this reason, it needs to be hosted in VMWare or Linux KVM.  All the other VMs will run Ubuntu 14.04. (They could optionally run CentOS.)  The downloader VMs are very lightweight clients that use a browser that downloads information from the IRS website. ## 3.) What is the anticipated growth rate in VMs per year? Difficult to say.  I predict 5-10% VM growth year-to-year. ## 4.) What level of redundancy is required for this project? The storage should be redundant, and I assume you own the hardware replacement concerns.  I typically use RAID 10 to achieve good reads and writes, but I leave it to you to define your best redundancy/speed ratio.  The VMs don’t need to be redundant but should be backed up (see below). ## 5.) What is the budget for this project? This is a brand new project.  I don’t have actual numbers at the moment. We are a small and steadily growing company.  We are in talks with other hosting providers, so a competitive price quote is ideal. ## 6.) When do you need to have the project online? We would like to see the environment provisioned and available as quickly as possible. [Article continues through the link below] ## Rise of the hybrid cloud Cloud portfolio management firm RightScale released its annual State of the Cloud Report in April, based on interviews with 1068 IT executives from diverse business sectors. 74% are currently operating more than one cloud (a multi-cloud setup), and 48% are strategizing a hybrid solution. Discuss your options with Atlantic.Net, a company with industry-leading [VPS hosting](https://www.atlantic.net/vps-hosting/) and the flexibility to meet your specific needs, as demonstrated by this RWS. **[>>> Part 2 – Hybrid Hosting Real World Scenario](https://www.atlantic.net/vps-hosting/hybrid-hosting-combining-private-public-cloud-a-real-world-scenario-2/)** By Moazzam Adnan --- # Hybrid Hosting – Combining Private & Public Cloud: A Real World Scenario – Part 2 > URL: https://www.atlantic.net/vps-hosting/hybrid-hosting-combining-private-public-cloud-a-real-world-scenario-2/ | Published: 2014-10-16 | Updated: 2025-03-06 | Author: Alexander Wise [**<<< Part 1 – Hybrid Hosting Real World Scenario**](https://www.atlantic.net/vps-hosting/hybrid-hosting-combining-private-public-cloud-a-real-world-scenario/) Client: [continued] ## 7.) Do the VMs require high disk throughput? The only disk-sensitive VM is the production Postgres server.  All the other VMs have low to moderate demands on disk I/O. ## **8.) What type of data backups are required for the VMs? Options: Daily, None, or Other (If Other, please specify).** We’ll perform offsite backups of the database (and other critical data) hourly.  The VMs themselves should be backed up daily.  Our recovery plan would be to restore the failed VM from the most recent snapshot, then restore any critical data from the hourly archive. I hope this is helpful.  Let me know if you have any further questions. Consultant: I spoke to our senior engineering department. We can provide you with Linux Host Firewall and set it up under an hourly consulting agreement. This will allow you to utilize our Public trusted public Cloud server at the monthly pricing listed on our website. We believe that this is the best solution for your organization. You will be contacted by our senior engineering team very shortly. Client: I’ve entered the pricing information into a spreadsheet, and your offering is very compelling. I’d like to better understand the configuration of the Linux Host Firewall, and I look forward to discussing the details with the technical engineer.  How would the custom appliance work?  The pricing in your public cloud does not include uploading a custom .iso image.  What would be the price of running this custom appliance?  It requires 4GB of RAM, 100GB of storage, and a 32-bit container. Additionally, I have the following questions regarding this solution: [Questions included in reply] Thank you, and I’m looking forward to hearing back from you. Consultant: I wanted to follow up with you this afternoon regarding your recent request for a quote. However, before this, one of the items listed in your requirements was for an iFax system. At this time, we are not able to accommodate custom ISOs on our public cloud platform. This is a feature that we plan on implementing but is not something currently available. To answer the other questions that you provided to Sam Guiliano: ## Would our VMs each have a public IP address, or would they exist on a private vlan behind the firewall? Each system would use private IP addresses to communicate with each other and the firewall. All public IPs needed for system access would be assigned to the firewall, and NAT’d to the respective private IP. ## If they are on a private plan, would we have control over the firewall rules, or would we submit requests to Atlantic.Net for changes? If deployed on our public cloud hosting platform, we would be able to assist you with the initial setup and configuration, along with providing you the necessary documentation to be able to make changes following the deployment. Firewall changes, as well as additional network configurations needed if a new VM is added, would be done by you. ## Would we have the ability to spin up and down new VMs on our own, or would the customized firewall require us to contact Atlantic.Net for changes? All customers have a client portal that can be used for the creation, deletion, and re-provisioning of VMs. At this time, VM resizing (increasing the system specs for a VM) is handled directly by our support staff. If you did add a new VM, it would be necessary to make networking changes to the system (configuring the private IP on eth1), as well as updating the firewall to reflect the new VM. I’m sure that you have more questions. Please let either Sam or me know, and we will be happy to address them. Thank you, and have a great day! Client: Thank you.  Do you have any solution for hosting the iFax custom ISO?  My hope is that I could use your  [VPS hosting](https://www.atlantic.net/vps-hosting/) offering for all the other VMs, and host the iFax system with you in some other capacity (i.e., private cloud, co-lo, or any other way that you can host a custom ISO.)  Ideally, the machines could exist on a vlan, but I would be fine if they didn’t.  (I could secure the VMs independently and secure the communications between them.) **[Article continues below]** Various surveys and analyses – including the State of the Cloud and Gartner reports referenced in [Part 1](https://www.atlantic.net/vps-hosting/hybrid-hosting-combining-private-public-cloud-a-real-world-scenario/) – have suggested that hybrid cloud is growing enormously. The reasoning behind that is in a [*CIO* article](http://www.cio.com/article/2379957/cloud-computing/2014-forecast-for-cloud-computing.html) published last December: businesses have a better understanding of distributed virtual technology now. They are savvier consumers looking for a mix of public and private options. Atlantic.Net, in business since 1994 and in the Inc. 500 for three consecutive years, has hybrid hosting expertise that can match any company’s mission.  See our [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). **[>>> Part 3 – Hybrid Hosting Real World Scenario](https://www.atlantic.net/vps-hosting/hybrid-hosting-combining-private-public-cloud-a-real-world-scenario-part-3/)** By Moazzam Adnan --- # A Real World Scenario of Private & Public Cloud Hosting – Part 3 > URL: https://www.atlantic.net/vps-hosting/hybrid-hosting-combining-private-public-cloud-a-real-world-scenario-part-3/ | Published: 2014-10-22 | Updated: 2025-03-06 | Author: Alexander Wise   [**<<< Part 2 – Hybrid Hosting Real World Scenario**](https://www.atlantic.net/vps-hosting/hybrid-hosting-combining-private-public-cloud-a-real-world-scenario-2/) Client: [continued] The need to host the iFax system is a requirement for me.  Do you have a solution that could accommodate this? Consultant: We can provide you with world-class cloud Hosting on our Public / Private cloud hosting platform except for the iFax OS. We can provide you with a Virtualized Private Dedicated server for the iFax ISO and connect it to our Public Cloud / Private cloud platform through a VPN. Pricing is below for the Virtualized Dedicated Server, containing the following parameters: - Custom iFax ISO - I3-3240 Dual Core 3.4 GHz w/HT - 8 GB of RAM - 2 X 240 GB SSD RAID 1 - LSI Hardware RAID Card $ xxx per month on a month-to-month agreement with a $ xxxx setup fee (vs. $ xxx per month on a 12-month agreement). $ xxx setup fee to install the VPN connection with the Public Cloud / Private cloud platform. If you decide to proceed, please contact me so we can set up the account for you. On the Public Cloud / private cloud side, you will have to choose from the server configurations we have available because we cannot create custom configurations. Client: Excellent. Thank you for the discount when purchasing a 12-month contract.  We like this offer very much and would like to accept. What is the best way to proceed?  I can create an online account and include payment details there, or I’m happy to call and provide payment details over the phone.  Please advise on how you would prefer to continue forward.  Thank you for your assistance. I look forward to hosting our applications with you. Consultant: We need you to provide us with the Cloud servers you wish to deploy based on the configurations we have listed on our website. We also need to know if you wish to add daily backup to the cloud servers and also if you require cPanel on any of the servers. On the dedicated server that will host the iFax ISO, I did not include Daily Backup in the pricing. If you need daily backup, it will be an extra $45.00 per month. At this time, do not open an account online, but we also need the following information so we can put together the agreement: - Full Company Name - Billing Address - Tax ID Number (if available) - State of Incorporation (if available) - Main Contact with phone number and email address - Billing Contact with phone number and email address - Technical Contacts with a phone number and email addresses. Client: Excellent. I’ll compile this information and get it to you ASAP—one quick question regarding the private cloud servers.  I can submit that to you, or I’m happy to configure it myself online.  Which do you prefer?  How will this work going forward, given that we have the VPN to the iFax server?  Can I manually create additional VMs and add them to my cloud, or should I contact your support team?  Lastly, I have a number of servers I need now and more that I’ll need in 4-6 months.  If I send my configuration to you, rather than configure it manually, do you want the full list or the list of servers I need now? Consultant: Sure, sorry for the confusion. You will be using the Cloud server control panel to configure and manage your servers just like any other customer. The iFax server will be independent of the Cloud control panel, and it will be connected via VPN. After you sign up on our website, please contact me. Let me know if you have any questions pertaining to the dedicated server agreement. Client: No problems at all. It’s been a full day, but I’ve signed the document and received confirmation. Thank you, and have a great weekend! ## Meeting unique needs with hybrid cloud A new study by Avere Systems, based on surveys collected at two 2014 New York trade shows (Amazon Web Services Summit and Cloud Expo) confirmed the accuracy of Gartner’s prediction that the hybrid cloud is set to explode. Gartner had forecast in fall 2013 that almost 50% of enterprises would have active hybrid clouds by 2017, and this Avere analysis (released October 21, 2014) revealed that 58% of companies are building hybrid clouds. The study, which polled 205 executives, also found that leadership planning for the cloud was divided: 26% reported that high-level personnel were driving those initiatives, and 22% said that technology professionals directly managing data were the primary cloud decision-makers. When you build your [VPS hosting](https://www.atlantic.net/vps-hosting/) server, work with an organization that specializes in hosting customization and has been a member of the Inc. 500 three years in a row: Atlantic.Net.  See our [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). By Moazzam Adnan --- # Specialty Pharmacy Website – A Real World Scenario > URL: https://www.atlantic.net/life-sciences-pharma-biotech/specialty-pharmacy-website-a-real-world-scenario/ | Published: 2014-10-25 | Updated: 2024-11-09 | Author: Kent Roberts An innovative company recently contacted us for a hosting plan. The firm is a technology and customer service provider to the specialty pharma industry. They needed an architecture that would maintain the regulatory compliance of their new web marketing program for custom drug solutions. When the firm came to us, their infrastructure was located at another hosting provider. That company did not supply the startup with a business associate agreement (BAA) or otherwise have the proper mechanisms in place for [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). In this article, we will look at a few “big picture” topics and then discuss this specific “real world scenario”: ## What is the specialty pharma industry? According to the “Health Policy Brief” on the topic from the peer-reviewed *Health Affairs*, *specialty pharmaceuticals* is not a technical term. However, the typical description gives the drugs the following characteristics: - combination of medications and biologics (medicines that involve live cells); - sophisticated production process; - typically are high in cost, in excess of $500 per month; - often challenging for the patient to take; - often need additional patient follow-ups; and - often accompanied by specific FDA rules regarding usage. Specialty pharmaceuticals, since they are custom drugs that are sometimes more vulnerable to environmental conditions, need to be distributed in more cost-intensive ways. For example, transport methods may need to be modified, and storage may have to incorporate climate control. Due to this developing need from the drug manufacturers, specialty pharmacies have been built to provide expertise in tailored distribution. These companies transport the drug to the doctor and collect payment from the patient’s health insurance plan. *Broader cultural context* – The basic “issue” with specialty pharmaceuticals – per *Health Affairs* – is that they are often considered to be part of the reason that healthcare costs are skyrocketing. Some medicines in this category cost six figures for a 12-month supply. Generally, a generic form of the drug does not exist. Although cost is a matter of debate (how to handle rising costs and whether the drugs are unreasonably priced), the drugs often are the best hope for treatment and recovery of numerous debilitating health conditions. ## The cloud and medical research Many healthcare companies feel safer avoiding virtual infrastructures (virtual private servers), including distributed ones (cloud servers), when securing their [protected health information (PHI)](http://www.hipaa.com/2009/09/hipaa-protected-health-information-what-does-phi-include/). However, whenever discussing HIPAA compliance, it’s important to note the huge potential of the cloud for rapid-fire development and worldwide, real-time diagnostic systems. Geoffrey Fox, Ph.D. of Indiana University, expressed the cloud compared to supercomputers since Big Red II at IU is one of the world’s most powerful computers. Dr. Fox said that because the cloud has high availability that outdoes any other technology, in many cases, it can accomplish a data processing rate that is “faster than a supercomputer.” For more on that topic, see the section here entitled “[Introduction – Biotech and an ‘Aha’ moment](https://www.atlantic.net/life-sciences-pharma-biotech/spotlight-on-biotech-hosting-a-real-world-scenario/).” ## Common HIPAA compliance obstacles Maintaining compliance with Health Insurance Portability and Accountability Act requirements is critical for all “covered entities” under the law – healthcare plans, healthcare clearinghouses, and healthcare providers. It’s not always easy to stay compliant, though. According to organizational health and safety writer David Gitachu, five common HIPAA violations are as follows, based on actual mistakes made by healthcare organizations: 1. **Phone message with the wrong party** – The patient must be contacted via the channel that is approved by them (e.g., office phone rather than home phone). 2. **Issuance of extraneous information** – The provider should not accept makeshift forms from patients since they can result in disclosing details beyond what is acceptable to the patient. 3. **Lack of privacy document** – Every patient must be given a document that outlines privacy details, including data to be ascertained and where they can retrieve it, prior to any examination or treatment. 4. **Failure to wipe data from equipment** – Any machines that contain hard drives, such as photocopiers, must have all data removed prior to third-party exposure (as when returning leased equipment). 5. **Improperly secured web environment** – Any PHI contained within web applications must be secured with technologies and protocols that meet standard business expectations, such as virtual private networks (VPNs), secure sockets layer (SSL) certificates, IPsec (Internet protocol security), and SSH (secure shell). For more on that topic, [see here](https://www.atlantic.net/hipaa-compliant-hosting/common-hipaa-violations-tips-stay-compliant/). ## Specialty pharma real-world scenario Here is a short excerpt from our discussion with the customer, as we helped them deploy an architecture in which all their website data and backend was HIPAA compliant: Consultant: Do you need a Linux or Windows HIPAA hosting platform? The [Linux VPS Hosting](https://www.atlantic.net/vps-hosting/) Platform is $ xx per month on a 24-month agreement. The [Windows VPS Hosting](https://www.atlantic.net/vps-hosting/) Platform is $ xxx per month on a 24-month agreement. Client: We are interested in the Linux plan. Consultant: Okay, thank you. Will the customer need cPanel w/WHM? That will add $ xx per month to the hosting package. Client: Why would they need cPanel? Consultant: It’s for ease of use. Do they know how to operate a Linux Server using a command-line interface? If they do, they will not need cPanel. Client: Yes, they do. Consultant: Okay, I will not include cPanel. Client: Okay. We are ready to move forward. The signed BAA is attached. Atlantic.Net is one of the leading companies in the world at HIPAA Compliant Hosting and HITECH compliant hosting. Explore our [hosting options for life sciences research](https://www.atlantic.net/life-sciences-pharma-biotech/) today. By Kent Roberts --- # HIPAA Hosting Plans Comparison: Three Options > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-hosting-plans-comparison-three-options/ | Published: 2014-10-27 | Updated: 2024-10-31 | Author: Sam Guiliano In the healthcare industry, the need for regulatory compliance can sometimes feel daunting. As with anything that requires a sophisticated solution, you may find yourself unsure of how to get started. We have some ideas to make your HIPAA architecture selection process easy and smooth. We will not go into the technical complexities to keep our discussion streamlined. ## When colocation makes sense If you are a healthcare provider already in business and looking to become compliant with HIPAA, one option is to colocate your servers at an SSAE 16 Type II (Statement on Standards for Attestation Engagements 16 Type II) certified data center. Colocation is a basic idea: bring in your servers; and take advantage of a professional data center’s physical environment and HIPAA compliance knowledge. Once you have transferred your machines to the colocation facility, you need to implement the following technologies that characterize a multiply redundant and ultra-secure data environment. Together these technologies, built into an expertly engineered computing environment, will meet and exceed HIPAA expectations (although, as you know, securing PHI goes beyond the technology to the actions of your workforce, hardcopy paperwork, and nonelectronic communication): - daily backup - antivirus subscription - firewall - intrusion detection system - log management - virtual private network (VPN) - dedicated IP address - business associate agreement (BAA). If you choose this option for compliance, you will lease space in a cabinet ranging from 1U to 42U (with the latter representing a standard complete rack that has room for [6 feet of hardware](https://en.wikipedia.org/wiki/Rack_unit)); you might even need multiple cabinets or a private cage. You will pay for the **space**. The colocation company will provide the cabinet/cages. You’ll be responsible for **power** expenses, though. You should consider getting dual power feeds – alternately called A-side/B-side, A+B, A&B, and A/B – if your budget permits. Along with the power, you will be paying for **bandwidth** monthly. ## When vanilla servers make sense If your servers have a few years on them and need upgrading, or if you have a new project, there is no point in fronting the CAPX (capital expense). Use those funds instead to improve your applications and hire more people to excel in your specific applications. In other words, look into a hosting plan. When you sign up for a hosting service, rather than going out and accruing assets for your company, you’ll be leasing servers. There is no capital investment on your books, which is a wise choice to lower your company’s taxes. Our recommendation is to lease the servers with no buyout option (in other words, straight leasing rather than “lease-to-own”). When you choose to lease, you can get vanilla servers with no management. Just make sure the hardware is in a secure, SSAE 16 certified facility. Then make sure that all of the technologies from the bullet list in the colocation section are deployed, configured, and enabled. A hosting package includes the space, power, and Internet (the extra expenses from the above option) as components of the contracted services. ## When HIPAA-ready servers make sense If you want to allow your HIPAA technology partner to assist you with creating a “by-the-book” environment, you can use leased servers that are already HIPAA compliant and audited. This option, as with the vanilla servers described above, includes space, power, and Internet for the contracted services. It also includes some management. Examples of HIPAA-ready servers Since this option is prepackaged, unlike using your own servers with colocation or using unmanaged vanilla servers, it deserves further discussion via example. Here is what we standardly provide, which primarily reflects the requirements of the bullet list above, adding management: - Daily Backups - Trend Micro Deep Security - Atlantic.Net Managed Firewall - Atlantic.Net Managed IDS/IPS - Log Management - VPN - Dedicated IP Address - Business Associate Agreement Our plan offerings are as follows: 1. **HIPAA Starter Packages** – This plan type includes everything you need for a computer server with [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). However, it does not include encrypted storage and backup. This option can help you save money if you are on a tight budget. You can always set up backup at another location cost-effectively (provided that the facility meets compliance requirements). 2. **Affordable HIPAA Packages** – This category of plans includes everything you need for a computer server with HIPAA compliance. In this case, backup is included. However, it does not include encrypted storage. 3. **HIPAA Self-Encrypting Storage Packages** – These plans include everything you need for a computer server with HIPAA compliance. It also includes encrypted storage and backup. This approach can help you save management costs and meets all requirements, with no exceptions. ## HIPAA hosting with Atlantic.Net In business since 1994, Atlantic.Net has a long history of providing high-quality solutions tailored to specific industries. We have offered [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions for five years and many other [VPS Hosting](https://www.atlantic.net/vps-hosting/) solutions. Joseph Nompleggi, the VP of Product Development for Complete Healthcare Solutions, commented that our “financial strength and proven track record are something we view with great confidence.” Get started today! --- # HIPAA Questions Answered – A Real World Scenario > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-questions-answered-a-real-world-scenario/ | Published: 2014-10-28 | Updated: 2024-10-31 | Author: Sam Guiliano ## Topics: Cyber Liability Insurance, Patching, Disaster Recovery, Encryption at Rest & Data Destruction Healthcare companies around the United States know that they must meet the standards of two landmark pieces of healthcare legislation, HIPAA (Health Insurance Portability and Accountability Act of 1996) and HITECH (Health Information Technology for Economic and Clinical Health Act of 2009). Although, of course, many healthcare providers, plans, and data clearinghouses care about the privacy and security of their patient information, these regulations sought (in part) to make failing to protect sensitive medical data extremely unattractive. With HIPAA, healthcare organizations now have an additional incentive beyond medical ethics to safeguard their patients’ data, especially in electronic form: avoiding fines. According to the American Medical Association (AMA), fines can be as much as $50,000 per violation, with total annual fines per organization capped at $1.5 million. The statistics from the Health & Human Services (HHS) Department suggest a crackdown from this major branch of the federal government reminiscent of the enormous quantity of car recalls in 2014, a record-breaking year for the National Highway Traffic Safety Administration (NHTSA). A look at the numbers – total violations resolved by HHS - 2004 – 4799 resolutions - 2009 – 8106 resolutions - 2013 – 14,300 resolutions. Clearly, these numbers are rising. Furthermore, it’s just the beginning: Law360 reported on June 12, 2014, that a senior attorney with the HHS promised “aggressive punishment” for any violations. Jerome B. Meites, a top regional civil rights attorney for the agency, told attendees of an American Bar Association meeting held in Chicago that the HHS was planning to [increase its efforts](http://www.law360.com/articles/547721/big-year-ahead-for-hipaa-fines-hhs-atty-says) to police the healthcare industry and uphold consumer rights. Regardless of anyone’s opinions on the law, healthcare companies should be concerned with HIPAA. They should have lots of questions for any company they are considering as a business associate (such as a hosting service). Here is a real-world scenario in which one of our clients, the CEO of a medical laboratory on the market for a HIPAA package, asked one of our hosting consultants for pertinent information. ## Real-world scenario – HIPAA for healthcare lab Client: I am the COO of a small laboratory. We currently have two Windows servers. One is running IIS and hosts around a dozen websites that use a maximum of 1-2 MB of throughput per day. We also have 3 SQL Server Express databases that will NEVER go beyond the 10GB limit. What would be our total monthly cost using the HIPAA Starter Package? Thanks. Consultant: Thank you for contacting Atlantic.Net. Based on your requirement for having a separate database SQL Express server, we will have to increase the amount of RAM in the dedicated server in order to create ( 2 ) VM’s inside the dedicated server. I have attached the formal proposal. The pricing is the Starter Package pricing along with the extra RAM that is required to virtualize the server into ( 2 ) VM’s. Also attached are the following supporting documents: 1. Fully Managed Hardware Firewall 2. Encrypted VPN’s 3. Intrusion Detection System 4. HIPAA Business Associate Agreement (BAA). An overview of the technology is as follows: - Fully Managed Hardware Firewall w/ 5 VPN’s - Intrusion Detection System / Log Management / Log Monitoring - Windows Standard 2012 R2 - Hypervisor: HyperV - Core I3-3240 Dual Core 3.4 GHz w/HT - 24 GB of RAM - 2 X 160 GB SATA 3 RAID 1 - LSI Hardware RAID Card - ( 2 ) VM’s - 10 TB of Monthly Data Transfer with a100 Mbps Port - 100% Uptime SLA (service level agreement) - MS SQL Server Express - 24x7x365 support by live phone or email. Do you have any questions pertaining to this [HIPAA Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) proposal? Client: A colleague of mine has advised me to ask how Atlantic.Net handles the following: - Cyber Liability Insurance - Patching - Disaster Recovery - Encryption at Rest - Data Destruction. Consultant: Here are the answers to your questions: *Cyber Liability Insurance* We have cyber liability insurance through a major insurance carrier. *Patching* There are two options: 1. You can do your own patching. 2. You can purchase our fully managed hosting package, which is an extra $100.00 per month. We would perform the patches, along with additional managed services. I have attached the Managed Hosting Package document for your review. *Disaster Recovery* I have attached our DR plan for your review. *Encryption at Rest* Some customers require encryption at rest, and others do not. The Starter Package has SATA (serial ATA) hard drives that are not encrypted, but you can substitute Encrypted At Rest hard drives for an extra charge. The smallest Encrypted At Rest hard drives are 1 TB SAS (serial attached SCSI) drives. Those drives would increase the cost of the Starter Package by $25.00 per month. *Data Destruction* All used or damaged equipment is destroyed, and all hard drives have the data removed before their destruction. This is in accordance with HIPAA regulations. ## Choosing your business associates wisely We love it when our customers and potential customers ask us questions. It’s an opportunity to provide evidence that we are widely knowledgeable on the protection of PHI (protected health information) and technology systems in general. We have been in business since 1994. One of our healthcare clients, Complete Healthcare Solutions, said they chose us for our “secure infrastructure and expertise in healthcare IT.” Explore your [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) options along with our full line of [VPS Hosting](https://www.atlantic.net/vps-hosting/) Solutions.   --- # Compliance Climate & On-Demand HIPAA Real World Scenario > URL: https://www.atlantic.net/hipaa-compliant-hosting/compliance-climate-on-demand-hipaa-real-world-scenario/ | Published: 2014-10-30 | Updated: 2024-10-22 | Author: Kent Roberts ## Introduction – Rising Pressure The pressure on healthcare providers, plans, and clearinghouses is mounting. Data Privacy Monitor reported in June 2014 that HHS (Health and Human Services) enforcement was expected to increase, per a comment made by a legal official at a local meeting of the American Bar Association held in Chicago. Jerome B. Meites, who serves as Chief Regional Counsel for the Office of Civil Rights (OCR – the HHS branch that regulates and monitors HIPAA compliance), stated in an interview with Law360 that policing would be increasing astronomically. Between June 2013 and June 2014, $10 million in fines were issued by the agency. Although firms had paid out millions YOY (year-over-year) in violation of the law, Meites said the level of punitive actions against healthcare organizations during that period would “pale in comparison to the next 12 months.” The attorney mentioned that the rise in EMR-related fines was in large part an effort to set precedents for the lack of tolerance the federal government has regarding privacy and security violations. Meites referenced a comment made by Leon Rodriguez, the head of the OCR when the Final Rule was publicly introduced. Rodriguez wrote that the adjustments to the Privacy Rule and Security Rule (the fundamental elements of compliance for most healthcare companies) would expand “the ability of my office to vigorously enforce… protections.” ## Common Violations This crackdown is making healthcare firms around the nation nervous that all their systems are completely secured and error-free. To help you avoid some of the most common violations in clinical documentation, here are nine of them supplied by New England Medical Transcription: 1. CCing an incorrect party to an email that includes patient data 2. Choosing the wrong patient name 3. Choosing the incorrect dictator 4. Selecting the incorrect ID or number of the subject, EMR, or account 5. Supplying the false practitioner name 6. Offering PHI to a third party without a legitimate explanation 7. Delaying or neglecting to notify the company’s compliance officer when a possible data breach occurs 8. Discarding patient information inappropriately 9. Accessing EMR without a reasonable explanation. ## On-Demand Real-World Scenario The following transcript is based on an interaction between one of our hosting consultants and a client interested in our healthcare compliance solutions. Note that despite our inability to meet the specific request of this company, we do currently have private cloud plans for HIPAA clients. Consultant: Welcome to Atlantic.Net. Please tell us about your hosting needs. Client: We create and manipulate large SQL databases with trillions of rows from millions of patient records. Therefore our work is all performed on HIPAA Compliant Servers. Our current vendor is XXX. We are looking for on-demand power for 6-12 contiguous hours consisting of 1000 cores, 512 GB RAM, and SSD storage of about 200 GB. Aside from the burst needs, which occur about once a month, we need about 12 hours a day / 30 days a month / 12 months a year of power consisting of 16-32 cores, 64-128 GB RAM, and 200 GB SSD storage. Backup is needed as well. Please provide quotes on monthly fees. Consultant: Thank you for contacting Atlantic.Net concerning your [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) requirements. Atlantic.Net provides HIPAA hosting platforms based on Private Dedicated Hardware. We, unfortunately, cannot provide any type of On-Demand HIPAA hosting solution. Your requirement for On-Demand services would only be possible by using a Cloud Hosting platform. We do not consider that type of platform to be HIPAA compliant and cannot issue a BAA (business associate agreement) for it. If you want us to provide you with a proposal based on a HIPAA platform that has fixed resources, we can do so. Client: Can you explain this a little further please? I’m trying to figure out why I can’t get healthcare hosting that has the same characteristics as other systems. Consultant: We currently provide on-demand hosting for clients that require a non-compliant platform hosted in our SSAE 16 data center in Orlando, Florida. Those customers experience a distributed computing model with an array of computing nodes that interconnect in an industrial-grade fashion. We have the capability to do the same for HIPAA clients and create large private clouds, but the HIPAA market is in its infancy – not yet at a point where we could make developing such systems a priority. At some point in the future, as demand grows, this could become a reality. The future of computing is on-demand, but our focus is to provide it to the wider market – at least for now. Client: Thank you. Please send me information on your fixed resource plans. ## Healthcare Virtualization For those seeking virtual solutions for [HIPAA Hosting](https://www.atlantic.net/hipaa-compliant-hosting/), we recommend our private virtualization configurations – Complete Healthcare Solutions VP Joseph Nompleggi said that his company chose to work with ours due to their confidence in our “financial strength and proven track record.” Get your proposal today! By Kent Roberts --- # What Can You Do with a 256 MB Cloud VPS for $0.99? > URL: https://www.atlantic.net/vps-hosting/what-can-you-do-with-a-256-mb-cloud-vps-for-0-99/ | Published: 2014-11-03 | Updated: 2024-11-14 | Author: Kent Roberts *Note: This plan is no longer available as of April 7, 2015* You may think that ninety-nine cents won’t get you far these days. After all, it would only get you about a third a gallon of gas, enough to drive 10 miles in a 2014 Nissan Sentra. It can get you further than you’d think, though, on the web. Since virtual private servers are so incredibly efficient, they’ve made it possible for us to create small, 99-cent/month Cloud VPS solutions. However, many people are hesitant to choose that plan, unsure if it is powerful enough to meet their needs, offering just 256 MB of RAM (random access memory). People who are frequent users of cloud VPS plans often discuss what can be done with various amounts of server memory. Let’s explore how people can use a 256 MB cloud VPS. ## How are you using our 256 MB cloud VPS? A discussion started on LowEndTalk on October 21 in which one forum member, username chinmoy, asked specifically [how people were using](http://lowendtalk.com/discussion/36287/what-are-you-guys-using-the-atlantic-net-s-0-99-plan-for) the Atlantic.Net offering. He wanted to know what people were using the server for other than VPN (virtual private network) and SSH (secure shell) tunneling. Here are some of their responses to his question and other comments related to the plan: - W1V Lee said he was using the VPS as a “new point on my [Observium](http://www.observium.org/) map.” He also mentioned that he hadn’t experienced any downtime. - ginner159 said that he would “use it as [a] nameserver box” for monitoring if he had one. - LMS Smoke said that he was using the server to host a clan site for Battlefield 4, along with a TS3 server. He commented that he had experienced “absolutely no TS3 lag even when maxed out.” - Jar said that he was using it as a DNS slave. - nleibert wrote that he was using the VPS as a mail server. - yywudi commented that he was using it as one of his Radius servers, with “CloudFlare full SSL support in the web panel.” - Ree has not used the box yet, although he signed up for it about three weeks before commenting. He said that he wanted to monitor it first before he put it to use and that “there hasn’t been any downtime.” Based on that experience, he intends to migrate some of his sites to that plan, likely moving all of them to it over time. - Blanoz wrote that he had logged 19 days of 100% uptime thus far. He was using it for DNS, SSH, and email, commenting in conclusion: “Happy as hell with it.” - lossehelin noted that the server was “quite fast even when [using] GUI through VNC.” He did mention that he tried to run HitLeap on it and repeatedly ran into problems. That’s not surprising: the system requirements for that application include 1 GB of free RAM, four times what this VPS provides. Remember that this box is small. ## 256 MB server for academia & Drupal**** Here are two other scenarios in which 256 MB was considered sufficient, from around the web (both from posts published in 2010 but still valid): ### Academic site Akshar Prabhu Desai wrote [on Stack Overflow](https://stackoverflow.com/questions/3628734/is-256mb-ram-cloud-server-enough-to-run-a-simple-web-application-in-php) that he had developed an app “mostly full of static webpages with several YouTube embeddings,” along with a few forms. He explained that the site resembled Academic Earth, allowing YouTube to serve the videos. There were about 400 users at the time of his question, perhaps 35 of them active. The consensus in the comments was that Desai would be fine with a 256 MB server, provided that he correctly configured his system for a lightweight situation. - timdev said that he should compile LAMP from source and then streamline. - Serj Sagan recommended that he use LightTPD rather than Apache as a Web server. - Sagan also said that he felt Debian was “better at using less RAM out-of-the-box” than other popular Linux distributions. ### Drupal The user Patrick asked [on Server Fault](http://serverfault.com/questions/198332/running-drupal-on-a-256mb-vps%20) if Drupal would run well within a small VPS. He also wanted to know of any “important configuration settings” so that his performance would be as strong as possible. In the comments, sybreon said that he successfully ran Drupal with MySQL for two years on a VPS that had much less memory, 64 MB. He suggested basic adjustments: - Switching the settings of MySQL so that it is completely optimized. Within Debian, he suggested looking at my-small.cnf. - Use of a high-efficiency Web server, such as LightTPD or nginx, with a low ceiling for the number of PHP instances. (He said that he was able to support “2 PHP-CGI instances” within the 64 MB environment.) - Use of a stripped-down MTA (message transfer agent). - Disabling all unnecessary services. ## Going tiny The film *Tiny* covers the story of a couple building a house small enough to fit into a parking space in an effort to downsize their lives. The film has been viral since it taps into the needs of sustainability and continuing economic uncertainty. You may not want to move into a 256 square-foot home, but 256 MB could be **just the right size** to meet your [VPS hosting](https://www.atlantic.net/vps-hosting/) needs. By Kent Roberts Atlantic.Net also offers managed, dedicated, and [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) – contact us today for a consultation. --- # Avoiding HIPAA Compliance Issues While Staying on Budget. > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-for-hospitals-asps-avoid-the-wall-of-shame-stay-within-budget/ | Published: 2014-11-05 | Updated: 2024-10-31 | Author: Sam Guiliano ## The current enforcement landscape *“Knowing what’s in the pipeline, I suspect that that number will be low compared to what’s coming up.” – Department of Health & Human Services OCR Counsel Jerome B. Meites, referring to the $10 million collected in HIPAA settlements from June 2013 to June 2014* The above quote, which has been cited several times in this blog, should give us a sense of where HIPAA enforcement is headed: straight up. A June article in *Data Privacy Monitor* on a *Law360* interview with Meites, a regional attorney for the agency, at an American Bar Association meeting in Chicago. The ramifications for healthcare organizations, including hospitals and ASP’s (application service providers), are substantial since noncompliance is detrimental both financially and reputationally. To further underscore the amplification of enforcement, he noted that the $10 million – a substantial chunk of which was a single $4.8 million settlement announced by the OCR (Office of Civil Rights, the HHS subagency charged with enforcement activities) in May – would “pale in comparison to the next 12 months.” ## What increased enforcement by the OCR means Meites said that the crackdown by the OCR was intended to set examples so that healthcare organizations would take the law more seriously. He referenced a statement made by Leon Rodriguez, Director of the Office of Civil Rights, regarding the Final Omnibus Rule that went into effect [September 23, 2013](http://www.beckershospitalreview.com/legal-regulatory-issues/15-things-to-know-about-the-hipaa-omnibus-final-rule-before-sept-23.html). Rodriguez remarked that the language within the rule represented the broadest adjustments to the privacy and security parameters of HIPAA since it was first enacted. More notably regarding compliance, though, he said that the new regulations don’t just improve data protections “but also strengthen the ability of my office to vigorously enforce the HIPAA privacy and security protections.” Meites also hinted that the OCR will be going after some whales, commenting that HHS executives believe they can create a healthcare ripple effect via “high-impact cases.” *Data Privacy Monitor* hypothesizes that, although Meites didn’t mention this report (which is probably an embarrassing document for the HHS OCR), the recent crackdown could be primarily in response to a November 2013 paper by the Office of the Inspector General (another office within the HHS). The report – which has the damning title, “The Office of Civil Rights Did Not Meet All Federal Requirements in its Oversight and Enforcement of the Health Insurance Portability and Accountability Act Security Rule” – provides a relatively objective perspective that the OCR itself wasn’t compliant with the law, especially the Security Rule (which, like the Privacy Rule, falls under the more far-reaching Title II of the law). ## What to do – compliance nuts and bolts Last August, an excellent article was published by *Medical Economics* intended to help healthcare organizations protect themselves from hefty fines and loss of credibility. In the report, Jeffrey Bendix, MA, explains that the changes to the Omnibus Rule last year were brought about by the passage of HITECH (the Health Information Technology for Economic and Clinical Health Act of 2009), according to Robert Tennant, MA, policy chief at the MGMA-ACMPE (Medical Group Management Association-American College of Medical Practice Executives). That act incentivized a transition to EMR (electronic medical records), which led the government to reconsider the strengths of data protection. Health law attorney Kenneth Rashbaum of Rashbaum Associates (New York City) told Bendix that the reason HHS is “adamant about enforcement” has to do with the specific characteristics of computer information. Electronic data is unlike hardcopies in two core ways: 1. The information is broader in scope. 2. In a poorly protected environment, loss of information or accidental changes can occur instantaneously and without the organization even noticing. The OCR enforces the Privacy Rule and Security Rule through two mechanisms: - investigation of any complaints made by patients or other concerned parties - compliance audits of covered entities and their relationships with business associates. The agency flexes its muscles and publicly admonishes violators by presenting PHI (protected health information) security incidents involving 500+ patients. If a company is negligent with its security practices and a breach occurs, they could end up on that page, typically referred to as the “Wall of Shame” by security experts and policy specialists, per Tennant and [*Computerworld*](http://www.computerworld.com/article/2505546/data-security/-wall-of-shame--exposes-21m-medical-record-breaches.html). ## Keeping your hospital or ASP “off the wall” & within budget The primary advice from Bendix to keep your firm off the HIPAA Shame Wall is to “be proactive,” echoing Tennant’s encouragement to “be really aggressive.” Obviously, it makes sense not to get into a bad position in the first place so that you can avoid the horror of a federal investigation. Tennant is quick to argue that you do not need to bring in an outside security consultant for a risk assessment. Instead, take advantage of the free resources provided by HHS and professional associations. We explore specific advice and resources for DIY HIPAA compliance below, but for now, here is the official OCR Guidance on Risk Analysis. **See the below link for the continuation of this piece.** We believe that protecting information is primarily about having the best possible information yourself. That’s part of our value as a hosting service specializing in [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) solutions: reliable information. Check out our handy [**HIPAA Hosting**](https://www.atlantic.net/hipaa-compliant-hosting/)options to learn more. **[>>> Part 2: CYA’s, BAA’s & Cyber Insurance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-for-hospitals-asps-cyas-baas-cyber-insurance-part-2/)**   --- # HIPAA Compliant Hosting for Hospitals & ASP’s – Part 2 > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-for-hospitals-asps-cyas-baas-cyber-insurance-part-2/ | Published: 2014-11-08 | Author: Sam Guiliano [**<<< Part 1: Avoid the Wall of Shame & Stay Within Budget**](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-for-hospitals-asps-avoid-the-wall-of-shame-stay-within-budget/) **DIY HIPAA compliance strategy #1 – protect PHI** You have to ensure that none of the EMR undergoes loss or theft or is otherwise available to illegitimate third parties. Per Bendix in his August *Medical Economics* report, mobile computing generally represents the most significant risk for providers because it’s simple for a thief to grab a portable device and abscond with the patient data. That applies to laptops just as it does to thumb drives: the vulnerable characteristic is that they are “easily picked up and carried,” says Tennant of the MGMA-ACMPE. Encryption Although theft can often occur with mobile devices, you don’t want to have to hold back your organization’s transition to the third platform (the post-PC general computing environment that incorporates cloud, mobile, big data, and social networks). The solution is software that encrypts all mobile devices (“scrambling” and password-protecting the files). That doesn’t just protect the data but achieves compliance: if a cell phone or tablet is stolen, it isn’t technically a breach if the health records are encrypted. [Encryption software](https://www.esecurityplanet.com/products/best-encryption-software/) is affordable and commonplace. Tennant comments regarding implementing encryption mechanisms, “There’s no excuse not to do this.” Documentation It’s not enough to put the necessary safeguards in place, such as encryption (also accomplished for records access with SSL certificates and VPNs) and firewalls. The burden of proof is yours to demonstrate compliance. Create policies and procedures, in writing, for the protection of EMR, along with an action plan for any instance of breach. The OCR (the HHS’s Office of Civil Rights) looks favorably on firms that have conducted risk analyses and designated individuals as privacy and security officers (as demonstrated by Carnegie Mellon’s health data policy). Although documentation is essential, you also must have evidence that the policies are being followed. Training Needless to say, it isn’t easy to follow policies if you don’t know what they are. Your staff should understand the basic security protocols for healthcare information. It’s wise to conclude your training seminars with a quick test so you know your team comprehends expectations and so that you can prove you made an effort to educate them, says Angela Dinh Rose, an executive with the American Health Information Management Association. Your staff should be trained to send any patient concerns directly to the privacy or security officer (who may be the same person). It’s critical to move fast with any complaints so that the patient doesn’t go to the HHS with their problem. “Issue an apology if appropriate,” advises Tennant, “and of course identify and correct the problem.” **DIY HIPAA compliance strategy #2 – sign BAA’s** Sometimes healthcare organizations have to be concerned with the practices of third parties tasked with handling their data, such as hosting services. While a medical practice has always been considered a covered entity, these outside parties – billing companies, shredding firms, and anyone else with PHI access – have previously been considered business associates, approved under the law with BAA’s (business associate agreements). Now those companies officially fall under the umbrella of covered entities. In other words, Atlantic.Net puts its professionally standardized systems on the line financially by offering [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) plans. Bendix reports that the extent to which a healthcare company is liable when a business associate fails is not delineated, so be careful with contracts that involve anyone with health information access – electronic or hard copy. Have an attorney look over the agreement. The vendor should offer a business associate agreement, a good sign that they are experienced with healthcare solutions. **DIY HIPAA compliance strategy #3 – insure the data** After putting in all the protections you can, seriously consider adding an additional layer of protection: cyber insurance. (Atlantic.Net itself has a [cyber liability policy](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-questions-answered-a-real-world-scenario/) through a major carrier.) Dean Sorensen of Sorensen Informatics says your cyber policy should cover you for the following: - business downtime (so that you are compensated if you have to shut down temporarily in the event of a breach) - breach remediation, which includes the costs of notification to your patients and the press - noncompliance fines - any legal fees incurred. When you get a cyber insurance policy, an underwriting process will be initiated by the carrier. That generally involves filling out a questionnaire to confirm specific protections set up to protect the data reasonably. Underwriting can be time-intensive, but it helps firms to review their policies and practices systematically. By doing so, says Sorensen, practices can avoid “overlooking something as simple as not locking the door at night.” **Full-spectrum protection** Beyond protecting PHI within your practice, working with compliant business associates, and looking into cyber insurance, Sorensen suggests assessing your network through the payment card industry data security standard (PCI-DSS) parameters as well. In other words, you want to be sure your data protection is comprehensive. In our SSAE 16 certified datacenter, it is. Complete Healthcare Solutions chose us for our “100% up-time, secure infrastructure, and **expertise in** **Healthcare IT**.” Get experienced guidance today in compliant hosting along with many of our [VPS Hosting](https://www.atlantic.net/vps-hosting/) Solutions. --- # The Importance of HIPAA Final Rule, Backup And Disaster Recovery > URL: https://www.atlantic.net/hipaa-data-centers/hipaa-final-rule-disaster-recovery-business-associate-shared-liability/ | Published: 2014-11-15 | Updated: 2024-06-04 | Author: Sam Guiliano Every healthcare organization knows about the importance of the [Health Insurance Portability and Accountability Act of 1996](https://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act). That law has, of course, been updated over time, and the most recent change has been the HIPAA Omnibus Final Rule, which went into effect in September 2013. **What’s the context of the Final Rule?** Although the Final Rule creates revisions to HIPAA, it actually was created in response to the passage of HITECH (the Health Information Technology for Economic and Clinical Health Act of 2009). The latter law significantly impacted healthcare by incentivizing a transition to EMR (electronic medical records). Once the federal government was officially recommending and promoting the use of electronic data for patients, it made sense to re-explore the security and privacy parameters of HIPAA to make sure the protections were extensive enough to fit the current landscape. The Final Rule may sound relatively simple, but it created a seismic shift in the healthcare industry like any other healthcare law. As the law was about to go into effect, various security and infrastructure pundits offered guides on adapting. One of the best was from Neal Bradbury, writing for managed services informational site MSPmentor last August. **Three quick ideas for HIPAA adaptation** Here are Bradbury’s three broad tips for adapting to the Omnibus Rule and maintaining HIPAA compliance in 2014 and beyond: 1. Choose shared liability. One thing that changed with the Final Rule is that business associates are now treated as covered entities, so a hosting company or similar third-party organization (including shredding companies, billers, etc.) is expected to maintain the parameters of the law as well. However, some companies don’t entirely understand the law. It’s up to you to select a knowledgeable, credible organization and make sure a BAA (business associate agreement) is in place. Bradbury notes that some cloud healthcare services have told customers they don’t need these agreements because cloud providers are considered a “conduit exception” just as postal companies are. Clearly, data networks are more than simply a conduit, so that perspective is false – as indicated in June 2013 by Kimberly M. Wong of [Baker & Hostetler LLP](http://www.lexology.com/library/detail.aspx?g=b46ab4ba-73a1-47aa-b270-c93bcf9910f2). Before choosing a [HIPAA data center](https://www.atlantic.net/hipaa-data-centers/) of any type, or anyone that handles your PHI (protected health information) in any way, verify that what they are providing is a good fit for a healthcare setting. Once you have a general sense that an organization is healthcare-ready, look at the parameters of the BAA they offer specifically, so you know what they **contractually have to do** to safeguard patient data. As Bradbury notes, the BAA “should spell out several ‘What if?’ Scenarios, ranging from data breaches to the provider going out of business.” Look at the contract carefully. Clarify anything that needs clarifying. Don’t feel that you are stuck if you don’t like the agreement. You can always go somewhere else. Make sure that the IT vendor assumes significant responsibility. 2. Side with backup and security expertise. The healthcare industry currently feels pressure from all sides: data must be widely available to take advantage of current technology, but regulations require firm controls. Even though the law is strongly worded, 19 million patients and healthcare providers were influenced by data loss or theft between 2011 and 2013. Here are a few considerations regarding strong backup and security: - **What are your current backup policies?** Are you encrypting? Are you backing up manually? Bradbury notes that manual backups “almost always lead to backup inconsistency.” You want a provider with a robust system in place, specifically tailored to healthcare, such as our AES-256 (Advanced Encryption Standard-256) encrypted **HIPAA Backup Manager**. - **What about disaster recovery?** Do you currently have NAS (network-attached storage) implemented at your facility? Do you have a DR plan (disaster recovery plan) related to that device? Is all your information automatically backed up to a data center that’s in a safe location at a distance from your headquarters (in the event of a disaster at a single location)? - **How is everything secured at the data center?** You need to be concerned with the business associate treatment of data in two primary ways: encryption and security mechanisms of the facility. It’s noteworthy that Bradbury specifically recommends AES-256, the same technology the federal government employees to safeguard top-secret files, and SSAE 16 (Statements on Standards for Attestation Engagements 16 http://www.aicpa.org/Research/Standards/AuditAttest/DownloadableDocuments/AT-00801.pdf) certification – both comprehensively implemented in every Atlantic.Net [HIPAA Compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solution. 3. Prioritize recovery time. You should have a sense that multiple redundancies are implemented at a provider, that crashes are incredibly unlikely. The next thing you want to know is if there is systemic failure, how quickly can you get everything back up and running? As Bradbury notes, “This is where the conversation gets real.” Recovery can be complicated or straightforward, depending on what solution you’re using. Your data may be safe, but it could take up to 72 hours to recover from failure at some facilities, assuming they need to get new hardware, install drivers and an operating system, and transfer in all necessary files. **Why a healthcare specialist?** Bradbury is adamant that you do not want to choose a provider with weak healthcare experience. Atlantic.Net is at the forefront of this industry. Complete Healthcare Solutions chose us because of our “secure infrastructure and expertise in **Healthcare IT**.” Talk with us, and you will become even more confident that we are the right choice in this and [VPS Hosting](https://www.atlantic.net/vps-hosting/). --- # Four-Year HIPAA Breach: Don’t Let it Be You > URL: https://www.atlantic.net/hipaa-compliant-hosting/four-year-hipaa-breach-dont-let-it-be-you/ | Published: 2014-11-19 | Updated: 2024-10-22 | Author: Sam Guiliano Healthcare IT requires a similar approach to medicine: foundation plus innovation. We make sure you have the nuts and bolts, keeping you updated as the landscape adapts. We’ve extensively covered the HIPAA (Health Insurance Portability & Accountability Act of 1996) Omnibus Final Rule (the revision that went into effect in September 2013) in this blog. We’ve also repeatedly explored the expected rise in HIPAA fines by the HHS (Department of Health & Human Services) in 2014, as indicated by [comments from a lawyer](http://www.dataprivacymonitor.com/enforcement/hhs-attorney-major-hipaa-fines-and-enforcement-coming/%20) for the federal OCR (Office of Civil Rights). ## Who You Don’t Want to Be – 2009 Through Today You do not want to be one of the organizations on the HIPAA Wall of Shame. The number of violations provides a sense of why the HHS has amplified its compliance efforts: 21 million people were affected by healthcare data breaches between 2009 and 2012. Often those breaches would not have occurred if the healthcare practice had taken simple steps. Lucas Mearian of *Computerworld* reported in August 2012 that six healthcare incidents listed at that time on the Wall of Shame had each exposed the healthcare data of more than [1 million patients](http://www.computerworld.com/article/2505546/data-security/-wall-of-shame--exposes-21m-medical-record-breaches.html). Since it’s easy to view federal regulations as efforts by the government to constrain business rather than its own operations, the top organization on the Wall of Shame at that time was ironic: TRICARE Management Activity. The firm, which handles healthcare for the Pentagon, lost backup tapes that contained 4.9 million records. ## HIPAA Data Breach Causes One of the privacy officials at the OCR, Rachel Seeger, said that theft was the cause of breach in 54% of incidents. Meanwhile, hacking only represented 6% of data exposures. Here is how the breaches broke down by type: - theft – 54% - access/disclosure without authorization – 20% - lost devices/data – 11% - hacking – 6% - incorrect disposal of documents – 5% - other – 4% Seeger reported that theft was the most frequent cause of regulatory violations. Luckily, the thieves generally are not concerned with the content: “The thieves are not after the information in the laptop, but they‘re after the laptop,” said Seeger. Fast-forward to April 2014, and you see that theft of mobile devices is still a significant issue. That month, the HHS released a press release entitled, “Stolen laptops lead to important HIPAA settlements.” At that point, the OCR had reached settlements totaling $1.975 million. Notably, Susan McAndrew of the OCR mentioned in the press release that it was straightforward to comply with all device requirements: don’t leave everything easily accessible. She stated, “**Encryption is your best defense** against these incidents.” ## Four-Year Breach of Virginia Healthcare Provider Eric McCann of *Healthcare IT News* [reported in January](http://www.healthcareitnews.com/news/four-year-long-hipaa-data-breach-discovered%20) on a healthcare breach that was notable not so much for the number of patients involved. Still, the length of time the vulnerability continued. Riverside Health System, which includes five Virginia hospitals, confirmed in December 2013 that the data of almost 1000 patients had been exposed between September 2009 and October 2013. ### How It Happened During that time, an individual who Riverside had fired unlawfully entered the system and accessed pages containing Social Security numbers and medical data of people. The employee, a licensed practical nurse, had been entering the system undetected up to November 1. At that time, a random audit conducted by the company revealed the suspicious access. A month after that, Peter Glagola of Riverside issued an apology that pointed to detection of the incident as a sign of the company’s concern with security. Although Riverside has long had a “robust compliance program and ongoing monitoring in place,” the oversight was unacceptable, and monitoring efforts would be bolstered with “more automatic flags.” ### The Consequences McCann noted that both covered entities and business associates (as of the Omnibus) could be fined up to $50,000 per violation if the problem is not solved. In comparison, the offense is only $10,000 maximum if the problem is solved. ## What Can We Learn? Much of what the Wall of Shame teaches us is not a “too bad for them” attitude toward the healthcare companies listed. Instead, it shows how easy it is to become noncompliant. In other words, Riverside is far from alone. Last December, the OCR reached a settlement of $150,000 with Massachusetts-based Adult & Pediatric Dermatology. The practice was fined $150,000 for operating in violation of three core HIPAA rules: breach notification, security, and privacy. That violation stemmed from the theft of a thumb drive out of a car. When the OCR investigated the incident, they found that the practice had not performed a regular risk analysis of its systems or contacted patients whose information was compromised, both requirements under the law. Leon Rodriguez, who heads the OCR, said that the dermatology practice was indicative of an issue throughout the industry. According to Rodriguez, the most significant area of vulnerability for covered entities is “failure to perform a comprehensive, thorough risk analysis and then to apply the results of that analysis.” ## Protection Through Business Associates If you want to stay compliant with HIPAA and avoid the Wall of Shame, your best bet is to work with a business associate specializing in healthcare IT. According to Joseph Nompleggi, Vice President of Product Development for Complete Healthcare Solutions, our “secure infrastructure, and expertise in Healthcare IT” makes us an excellent choice for [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/)or our for scalable [VPS Hosting](https://www.atlantic.net/vps-hosting/). --- # Cloud Servers for Travelers On the Go > URL: https://www.atlantic.net/hipaa-compliant-hosting/cloud-vps-for-travelers-on-the-go/ | Published: 2014-11-21 | Updated: 2024-10-22 | Author: Kent Roberts Do you want to access the power of a strong network from anywhere? Your best bet is private cloud hosting. By connecting your PC to the power of distributed virtualization, you can benefit from groundbreaking cloud speed, no matter where you are. We find it often helps to look at examples from our current customers. While protecting the privacy of our customers and anonymizing any sensitive details, we hope that these Real World Scenarios can help you understand the best path better forward. ## Private Cloud Example Scenario Below is a request we received from a business professional regularly traveling between the United States and India. The customer submitted the request through our site’s [contact page](https://www.atlantic.net/support/). After looking at the potential of private cloud hosting for worldwide use, we will look at the field of development to get a better sense of the technology’s powerful speed. Client: I am looking for a solution to a problem that I am facing. I travel between the US and India frequently. I have trading software I run on my desktop and have a four monitor display. While in the US, it takes only 5-10 seconds initially for my charts to load when I run my trading application. However, when I open the same application in India – same setup, one desktop with four monitors – the same file takes anywhere from 1.5 minutes to 55 minutes to load. Please note the setup in India and the US are identical, and the files I run are also the same. The system in India is more powerful than the one in the US, so that is not the issue. However, I feel running the application remotely and viewing it locally might be the solution. I am interested to know more about your services. I am currently in India but have a US number. You can call me at 408-XXX-XXXX.  I am 10 hours and 30 minutes ahead of EST. If you provide me with a number and a contact person’s name, it will be easier to call than you to reach me. I appreciate your response at your earliest convenience. Thanks, XXX Consultant: Thank you for contacting Atlantic.Net. Based on your description, you seem to be experiencing latency issues. I would recommend conducting a speed test to determine whether or not our services will be a viable option for you. This can be done by visiting [Atlantic Net speed test/](https://www.atlantic.net/speed-test/). Once at the website, please select the location and use the test IP address. Should you have any further questions, please respond to this email. I’ve also listed several links below that may assist you with answering other questions. [VPS pricing](https://www.atlantic.net/vps-hosting/pricing/) page [VPS hosting FAQ](https://www.atlantic.net/faq/) page   ## How Fast? Fast Enough to Legitimize Daily Updates [VPS Hosting](https://www.atlantic.net/vps-hosting/) is allowing developers to improve the rate at which they deliver versions of software, per a survey completed earlier this year. Paul Krill of InfoWorld reported on the survey on January 23, noting how frequent the updates are becoming: - One in four (26%) developers releases updates once or more daily - Almost two out of three (63%) release updates once or more weekly. ### A Surprising Benefit of Cloud Adoption According to Developers The Cloud Development Survey, organized by Evans Data in late 2013, marked the 10th time the semiannual poll has been completed (every six months since early 2009). Evans Data gathered information from over 400 developers who use [VPS hosting](https://www.atlantic.net/vps-hosting/) to deploy their software or access SaaS (software-as-a-service) for development tools. Along with the tendency of developers to release updates and releases on a more regular basis, 51% of respondents agreed on an additional benefit: enhanced integration of development and operations so that [continuous delivery](http://www.infoworld.com/article/2612774/agile-development/continuous-delivery-revs-up-software-updates.html) can occur. Michael Rasalan of Evans said developers are starting to realize that releasing the freshest software versions immediately is rewarding. As Rasalan explains, the cloud effectively provides a real-time, high-flexibility solution: “A lot of this just comes down to the ability to efficiently provide updates and bug fixes dynamically.” ### Daily & Weekly Software Releases & Updates Empowered by the Cloud ISVs (independent software vendors) and corporate developers are at opposite ends of the spectrum when it comes to daily releases, but the numbers are similar at the weekly level: - 46% of ISVs publish updates each day, with 74% updating each week. - 13% of in-house corporate developers update daily, with 66% updating weekly. The reason for this is probably the flexibility of smaller organizations. Corporate developers are more likely to run into friction when they seek to achieve continuous delivery and condense the development cycle in general. As Rasalan put it, in some cases, “it’s just the scale of the organizations.” The smaller, more agile ISVs also seem better able to use the cloud to integrate development with operations: 77% think the cloud enhances that connection. In comparison, only 35% of internal corporate developers do. ## Supercharging Your Private Cloud Hosting Server As recommended in the Real World Scenario above, you always want to test-drive a private cloud hosting server before purchase. After all, not every cloud is created the same. Atlantic.Net also offers dedicated, managed and [HIPAA hosting](https://www.atlantic.net/hipaa-compliant-hosting/) – contact us today for a consultation. By Kent Roberts --- # Should You Get OS-Ready Cloud VPS Instead of reinstalling Windows? > URL: https://www.atlantic.net/vps-hosting/why-reinstall-windows-20082012-get-os-ready-cloud-vps-instead/ | Published: 2014-11-26 | Updated: 2024-11-14 | Author: Kent Roberts This report argues for the use of an **OS-ready cloud VPS** (virtual private server) to replace a crashed standard PC system. ## CIO: Cloud & Rise of the Third Platform You may be familiar with a concept called the third platform. IDC released a list of 2014 predictions that focused heavily on the emergence of the platform, with the research firm claiming it will be highly disruptive throughout the global marketplace. Prompted by the IDC announcement, renowned cloud expert Bernard Golden (called one of the top 10 cloud thought leaders by *Wired*) [penned an article](http://www.cio.com/article/2377568/cloud-computing/as-idc-sees-it-tech-s-third-platform-disrupts-everyone.html) for CIO in March, summarizing the third platform as including the following: - virtually distributed machines, a.k.a. cloud technology - mobile devices and usage - big data and the analytics surrounding vast stores of information - social media (online portals that allow internal and external brand stakeholders to interact, synergistically enhancing value). The report demonstrates a rapid-fire transition to the third platform, the fast-paced and efficient virtual model that serves as a follow-up to the first two platforms, which were mainframe computing and the PC (or, as Golden puts it, “client/server/Internet technology”). ### The future of the third platform Typically cloud hosting services focus on speed and efficiency, as we did above. After all, Geoffrey C. Fox, Ph.D., an associate dean in the Indiana University School of computing, told the Association of American Medical Colleges (AAMC) in 2013 that the cloud can often outperform a super-computer since wait times become [essentially obsolete](https://www.atlantic.net/life-sciences-pharma-biotech/spotlight-on-biotech-hosting-a-real-world-scenario/). However, the third platform goes beyond the product’s usefulness to reshape how and by whom IT services are provided and who deploys and manages them. The important note about the third platform is not that it’s starting to become competitive with the traditional model but that it represents an area of increased spending throughout the industry. According to the IDC prediction, almost all IT growth this year, a total of 5% will be generated through the third platform, representing 29% of total information technology expenses. Half of the spending on the third platform represents a replacement of legacy systems. ## Wall Street Journal: How Cloud Changes Our Lives Joe Mullich of the *Wall Street Journal* wrote an excellent article in 2011 that, though a bit dated now, offers some excellent insight into the potential of the technology. Here are several of the most exciting ways in which Mullich argued that the cloud would reframe life as we know it: ### Easier to repair & maintain electronics Part of what makes the cloud particularly compelling is that it is a fundamental component of the Internet of Things (IoT), which is – similarly to cloud computing – a general term referring to various networks of connected objects. As the Internet of Things grows with the cloud, we will get notified when batteries in our electric cars are depleting, household electronics need general servicing, and healthcare equipment parts fail. Daniel Burrus, the author of the *New York Times* bestseller [*Flash Foresight: How To See The Invisible and Do The Impossible*](http://www.burrus.com/flash-foresight-by-daniel-burrus/), notes that technicians will be able to access the cloud through apps on their tablets to get need-to-know information in real-time, epitomizing “a wave of just-in-time training.” ### Would you rather have flight or invisibility as a superpower? Well, the cloud may not be able to allow you to fly through the sky, but it can help you achieve another superpower: invisibility. When computer users look up information through a search engine such as Google, Mullich opines that “they usually don’t realize they are accessing billion-dollar computer networks.” As the cloud becomes more mainstream and hence increasingly affordable, we will be able to more easily access high-performing anonymous environments, which can enhance the privacy and security of anything we do. Plus, by checking with IP addresses from virtual machines in various locations, we can lower the cost of airline tickets. You can even create a new **OS-ready Windows cloud VPS** each time you browse. Invisibility will also be possible in that sensors will replace the need to use a computer mouse and keyboard directly. Dan Reed, head of the eXtreme Computing Group at Microsoft, notes that the type of technology used in its [Kinect system](https://en.wikipedia.org/wiki/Kinect) foresees a captivating futuristic scenario: we enter a building for a service, and “there could be hundreds of sensors in it that could respond.” ### They will have what you want in stock Mullich cites consumer polls revealing that shoppers often use the web-to-store model for purchasing larger items: they look for what they want online and then head to the brick-and-mortar location to buy. However, consumers have been frustrated with traditional systems, which don’t update inventory in real-time, resulting in sites displaying products that are no longer in stock. Cloud allows more accessible information that updates moment-to-moment. Furthermore, Mullich argues that catering to mobile shoppers in every possible way is essential to the continuing relevance of retail stores: “Retailers’ brand value will be dramatically affected by how they satisfy these mobile-savvy shoppers.” ## Atlantic.Net: Windows Cloud VPS Hosting When your computer crashes, don’t bother reinstalling Windows 2008 or Windows 2012. Get a Windows cloud VPS Hosting service that offers per-second pricing. Pay for the actual amount of resources you use rather than at the maximum per-hour rate. Get free setup, free inbound data transfer, free hosted cloud DNS, 100% enterprise solid-state drives, 24/7 support, and 30-second deployment with your Windows cloud hosting. By Kent Roberts Atlantic.Net also offers [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/), managed, and [VPS hosting](https://www.atlantic.net/vps-hosting/) – contact us today for a consultation! --- # You Have a Supercomputer in Your Hand > URL: https://www.atlantic.net/vps-hosting/you-have-a-supercomputer-in-your-hand/ | Published: 2014-12-01 | Updated: 2024-11-14 | Author: Kent Roberts This article recommends a [cPanel VPS](https://www.atlantic.net/vps-hosting/) Hosting plan to meet your cloud computing needs and have complete control of your server environment. First, though, we explore broad cloud technology impact on our lives through the following sections: ## Introduction: Where the Cloud Is Headed Although cloud technology is seen as a revolutionary alternative to traditional technology, the popularity of the virtualization system did not arise spontaneously. It’s been discussed by the media and major industry players for years. We started to explore a report by Joe Mullich of the *[Wall Street Journal](http://online.wsj.com/ad/article/cloudcomputing-changelives)* in [a previous article](https://www.atlantic.net/vps-hosting/why-reinstall-windows-20082012-get-os-ready-cloud-vps-instead/) on the OS-ready cloud server. Although the WSJ article was published in 2011 and did not address developments that have taken place over the past three years, it is “big picture” enough and contains strong enough ideas that it demands further review. It also helps that Mullich is looking toward the future, at where the cloud is headed. In some cases, it’s apparent that he was right, and changes have occurred, as he indicates. In others, it suggests possible areas for refocusing. ## Wall Street Journal: You Have a Supercomputer in Your Hand Several of the ways that the cloud would impact business in everyday life include the following, per Mullich (who in turn cites various tech experts): ### Hey, you know what you might like? One of the primary disruptions will involve personalization, according to John Hagel, who co-chairs the Deloitte Center for the Edge, a research facility located in Silicon Valley. Companies will legitimately think that they understand you better and can help narrow you in on solutions that best fit your preferences and situation. Mining big data and processing it through predictive analytics applications, companies will want a relationship with you based on their sense of your ongoing needs – “a key way retailers will fight against commoditization.” Figuring out just what consumers want will create a robust data science industry that studies our online behavior. We often get recommendations based on an analysis of our past behavior within one system, such as Netflix. However, more sophisticated, integrated algorithms will look at your activity across the Internet. By gauging it in real-time, a company can “suggest things [the consumer] didn’t even know [they] wanted to look at,” says Hagel. An example of this effort from advertising is retargeting. However, Internet-wide efforts to personalize your experience have probably been hampered by reluctance from individual organizations to disclose all their data and from consumers to be comfortable with a more interconnected, unified, and personalized user experience. ### Better, faster decision-making The cloud effectively boosts the capabilities of every smartphone, tablet, and PC so that, right now, you have a supercomputer in your hand. The resources of the cloud are, for all intents and purposes, infinite. You can use on-demand, per-second processing from a cloud system to store data in whatever way you want it. You could fuse real-time stock market information, changes to the weather, news reports, social media posts, and blog comments to measure small but noticeable shifts in the market environment and public perception. By connecting the data from all those sources and pulling them into a simulation you enter through your cell phone, you can instantly know what stocks to buy and sell. It will be much simpler to conduct research studies, as indicated by an Association of American Medical Colleges article on the topic that we often cite in this blog. ### The age of the overnight success In the cloud era, SMBs will be able to utilize the cloud to compete with enterprises. Mullich references David Dobson, a VP at hosting provider CA Technologies, who says that global reach will be instantly accessible. Startups will be able to scale and make a name for themselves within days. These companies will be able to reach the masses without the need for on-premises data centers or colocation, says Dobson: “Instead of deploying on-site infrastructure to run their operations, companies can access infrastructure-as-a-service.” ### Fewer problems with laptop security If you are in the healthcare industry, you are probably aware that unencrypted laptops and mobile devices represent one of the most common HIPAA (Health Insurance Portability and Accountability Act) violations. That’s unsurprising when you consider that 10,278 laptops are reported stolen each week at three dozen of the largest airports in the country. Greg Bell, auditing and tax security specialist at KPMG, notes that if you want to go the traditional route, “people can carry a laptop with all their secrets, like customer and payroll information.” You need to encrypt that data. However, many nations have made it illegal to bring unencrypted computers across their borders. The cloud does away with that issue by keeping all the data at a distance. You don’t have to store your information on the PC anymore. Instead, you use it just as you do the Internet – a device through which you access the information and manage it. ## Atlantic.Net: cPanel Cloud Hosting One of the most user-friendly, affordable ways to run on the cloud is with a cPanel [VPS Hosting](https://www.atlantic.net/vps-hosting/). You can move your business from the second platform of IT (PC-server computing) to the third platform (cloud, mobile, big data, social), with a system that has been trusted by Linux open-source users for many years. Get your **cPanel Cloud Server** up and running in 30 seconds! By Kent Roberts --- # The Entrepreneurial Era of Cloud Computing > URL: https://www.atlantic.net/pci-compliant-hosting/the-entrepreneurial-era/ | Published: 2014-12-04 | Updated: 2024-11-09 | Author: Kent Roberts This piece suggests a Linux cloud hosting VPS (virtual private server) to accelerate your company with cloud computing. However, what’s exciting about the cloud is not specific solutions, but how its speed and agility will change all of our lives, so we will explore that topic. Here’s our basic outline: ## Introduction: Scope of the cloud We hear that the cloud is fast. We hear that it’s cheap. We hear that it’s the future of everything from development (okay, sure) to personal computing (yeah, maybe) to security (wow). In January, Jack Woods of SiliconAngle compiled statistics from various research sources into a [simple report](http://siliconangle.com/blog/2014/01/27/20-cloud-computing-statistics-tc0114/) that ended up being probably one of the most widely cited cloud articles of the year (and we’ve referenced it in this blog repeatedly). *Note: The Woods article would be more helpful if it cited original source material rather than other publications and even its website. Nonetheless, the information appears to be legitimate.* *Here are five quick stats that define the scope of the cloud:* 1. The market for business and consumer cloud solutions (as a total figure) could exceed $180 billion by 2015 (InformationWeek). 2. Although the cloud is virtual, it still needs hardware to operate. The market on distributed virtual hardware is forecast to hit $79.1 billion in 2018. 3. American businesses will pay out over $13 billion for cloud environments and management packages during 2014 (CIOZone). 4. Everyone knows that the cloud is replacing legacy systems. Between 2014 and 2019, the workload performed by cloud providers will grow 44% per year (compounded), versus only a 9% rise for in-house server workloads (Barron’s). 5. Four out of five firms (82%) cut their costs via cloudification (NSK Inc.). ## Wall Street Journal: The entrepreneurial era Technology moves so quickly that online information seems to become almost immediately outdated. If a study or report wasn’t completed in the last couple of years, it’s typically tossed aside as irrelevant. We have new cloud predictions for 2015, after all! However, there is an excellent 2011 report by the Wall Street Journal’s Joe Mullich (covered, in part, twice previously), which predicted the following cloud impacts: ### Doctor-middleware-patient relationship A trend that was already evident in 2011 is assumedly continuing to grow in prominence. Between 2010 and 2011, there was a significant shift from standard Internet access to mobile app use for information-gathering among medical students: Web browsers declined to 33% from 52%, while mobile applications rose to 34% from 19%. Dan Shey of ABI Research notes that medical decision-making becomes nearly immediate when healthcare providers are “able to pull up a patient’s radiograph and zoom into particular areas… with the touch of a button.” The speed of the cloud combines with the nature of touch-screen mobile devices to allow doctors to access, zoom, and navigate images without a wait. ### Health in the house Along with patient care in the office and medical research, the cloud improves health in the home as well. Honorio J. Padrón III of consultancy the Hackett Group noted the growing field of home health monitoring. For instance, anyone who has sleep apnea can now be gauged wirelessly, with data amassed throughout the night. The system is, in turn, connected to a community of specialists to craft a treatment strategy. ### Pre-industrial straight to the cloud Developing countries such as China and Brazil can enter the cloud more rapidly because they don’t have well-developed legacy infrastructure. In other words, the challenge of migrating applications, integrating systems, and figuring out hybrid solutions is not as much of a concern as for the US, UK, etc. This general trend of globalization, in which a society jumps over an entire phase of a technology, is called**leapfrogging**. A perfect example is India, which went straight to cell phones, skipping mass adoption of landlines. ### Diversification of supply Until the cloud came along, it made sense for enterprises to use a limited quantity of suppliers simply for efficiency. However, the range of suppliers could broaden as firms can find viable solutions on the fly. Community clouds could allow various organizations to do business through a mutually agreeable platform (generally stunted but could progress). ### Now entering the entrepreneurial era. One major shift – due to the ability to collaborate with other individuals and develop software affordably and quickly – is seeing more entrepreneurs carve out niches for themselves. The co-chair of the Deloitte Center for the Edge, John Hagel, said that the sophisticated testing to which startups immediately have access is incredible, with the rate of innovation accelerating in tandem with “the speed at which you can identify what people are interested in, and what they will pay.” ### Voice recognition Finally, the cloud has injected power into the ability of speech-to-text applications to accurately transcribe a vast pool of users. ## Atlantic.Net: Linux VPS hosting in the cloud Now that we have discussed some broader possibilities of the cloud let’s briefly consider one way to get started: a Linux VPS from Atlantic.Net. Basic characteristics include the following: - Reliability and performance of the cloud - Less expensive than a dedicated environment - Keeps you agile in a similar manner to shared hosting - Allows direct SSH access. Spin up your own **budget-friendly cloud server** now: it takes just 30 seconds to get started. Cloud hosting is just one of several services that Atlantic.net offers – we also offer managed, [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/)and [PCI compliant hosting](https://www.atlantic.net/pci-compliant-hosting/). Contact us today for a consultation. By Kent Roberts --- # HIPAA Lawsuit: $1.4 Million Walgreens Love Triangle > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-lawsuit-1-4-million-walgreens-love-triangle/ | Published: 2014-12-06 | Updated: 2024-03-01 | Author: Sam Guiliano This piece argues for independently audited self-encrypting HIPAA storage as a service for healthcare companies. We review it within the broad enforcement and liability context, proceeding as follows: - **Data Privacy Monitor: Surge of fines expected this year** - **Indianapolis Star: $1.4 million Walgreens love triangle** - **Analysis: The case places further pressure on the industry** - **Defense: Walgreens perspective & vicarious liability** - **In it together: Business associates post-Omnibus** **Data Privacy Monitor: Surge of fines expected this year** The year-over-year background and forecast for healthcare compliance in June looked bleak in both directions. That became clear when a prominent lawyer for HHS OCR spoke with a legal magazine at a professional conference, as reported by [Data Privacy Monitor](http://www.dataprivacymonitor.com/enforcement/hhs-attorney-major-hipaa-fines-and-enforcement-coming/%20) earlier this year. According to DPM, Law360 interviewed the Chief Regional Counsel for the OCR, Jerome B. Meites,  at a Chicago meeting of the American Bar Association (ABA). He said that the year leading up to June would “pale in comparison to the next 12 months.’” That was not what the healthcare industry was hoping to hear since the actions of the OCR were already considered excessively aggressive and punitive by some. Between June 1, 2013, and June 13, 2014, nine settlements were posted on the HIPAA “Wall of Shame” (actually the OCR’s Breaches Affecting 500 or More Individuals announcement page, which does go soft on non-compliant companies by listing violations chronologically backward) that totaled more than $10 million. Mr. Meites said that based on upcoming settlements expected to be announced through 2014 and the first half of 2015, “‘I suspect that [the] number [from the last year] will be low compared to what’s coming up.’” **Indianapolis Star: $1.4 million Walgreens love triangle** Financial settlements with the federal government are just one side of the equation, though. Healthcare firms must also be concerned with civil lawsuits – especially since one recent high-profile judgment involving a major consumer brand places responsibility for employee wrongdoing with the employer. The Court of Appeals in Indiana decided on Friday, November 14, in favor of a customer whose health information was taken by a Walgreens pharmacist and shared with a third party – as reported by Tim Evans of the [Indianapolis Star](http://www.indystar.com/story/news/2014/11/14/m-award-upheld-walgreen-pharmacist-shared-patient-data/19035783/). Specifically, the pharmacist took the prescription information of her husband’s ex-girlfriend and shared it with her husband, who in turn shared it with at least three other parties. The victim in the healthcare data love triangle was awarded $1.44 million. According to the victim’s lawyer, Neal F. Eggeson, Jr., the decision was the first by an appellate court in the United States to place liability with a HIPAA-covered entity (Walgreens) for a data breach caused purely by employee wrongdoing. **Analysis: The case places further pressure on the industry** Eggeson and other healthcare attorneys said that the judgment would serve as a legal precedent for use in future court cases around the country. The Indiana Court of Appeals decision effectively “‘[confirms] that privacy breach victims may hold employers accountable for the HIPAA violations of their employees,’” said Eggeson. David Orentlicher, who co-heads the law and health center at Indiana University’s law school, noted that even though Walgreen Company has stated they plan to appeal this decision, it serves as a general warning to all healthcare companies that privacy must be maintained. Orentlicher said that protecting sensitive medical details is critical because if patients can’t be reasonably confident that their data won’t be misused, they may avoid seeking care altogether. **Defense: Walgreens perspective & vicarious liability** James W. Graham, writing on behalf of Walgreens, described what the corporation believes to be unfair about the decision: the pharmacist who unethically accessed and shared the health records “was aware of our strict privacy policy and knew she was violating it.” Graham said that the drugstore chain did not believe that the law should make a company responsible for the misdeeds of a single worker. The November verdict was in response to a request from Walgreens to overturn a July 2013 case decided in favor of Abigail Hinchy, the ex-girlfriend, a customer of the 6269 W. 38th St. location in Indianapolis. Walgreens was dealt a sound and swift blow by the Court of Appeals. Judge John Baker stated in a unanimous verdict that the Walgreens pharmacist, Audra Withers, had disregarded “one of her most sacred duties” when she looked at the details within the customer’s account and provided her findings to an unauthorized individual (the husband). Orentlicher noted that when Walgreens appeals at the Indiana Supreme Court, the idea of “vicarious liability” will be central to the debate. In the case of a workplace that made every effort to train its workers properly, the court sometimes places accountability with the employer nonetheless – because it decided to employ that particular individual. **In it together: Business associates post-Omnibus** Before the release of the Final Omnibus Rule in 2013, business associates were not held immediately responsible for healthcare privacy and security by the federal government. Now, all that has changed. According to the American Academy of Orthopaedic Surgeons, the adjustments to the law impact any individual or organization that handles protected health information (PHI). Today, business associates such as Atlantic.Net are “directly liable for compliance.” With a complex and refined privacy and security background that spans three decades, we can provide a broad range of [HIPAA Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)solutions. Many clients benefit from our self-encrypting storage plans, in which the entire hard drive is encrypted via a symmetrical key held in a separate location from the CPU (isolating it from any dangers of memory corruption).   We offer our [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)and blazing fast Cloud Servers with a 100 percent uptime guarantee. --- # Public Park PHI Featured on HIPAA Wall of Shame > URL: https://www.atlantic.net/hipaa-compliant-hosting/public-park-phi-featured-on-hipaa-wall-of-shame/ | Published: 2014-12-11 | Updated: 2024-06-05 | Author: Sam Guiliano This article looks at major HIPAA breaches last year and how your organization can avoid serving as an example of “what not to do” by the federal government. Note that some of these organizations were not directly responsible, as was true of a hospital in Fort Worth, Texas, that trusted the wrong shredding service with its files. The topics we will cover include: - **What is the Wall of Shame?** - **Most prominent 2013 cases** - **Analysis – Health records in a public park??** - **Tips to avoid the Wall** - **New business associate stipulations.** **What is the Wall of Shame?** Everyone in healthcare wants to avoid the HHS Office of Civil Rights’ Wall of Shame, where cases of noncompliance involving 500+ people are posted. However, some organizations reported by patients or audited by Health & Human Services are granted that ignoble designation. The OCR has kept a running list of these high-volume HIPAA offenses for the past five years (although the list is somewhat absurd because it’s chronologically backward, so the featured companies on the Wall of Shame are the first organizations that violated the law in 2009). **Most prominent 2013 cases** Stephanie D. Willis and Kimberly Gold of Health Law & Policy Matters reported on the most significant breaches of 2013 early in the year. They also provided tips to stay compliant yourself. The skinny Last year, more than 150 breaches of 500+ patients’ records were published on the OCR website. All told, the Wall of Shame indicates that **healthcare firms were responsible for the exposure of 6.8 million Americans’ protected health information (PHI).** Largest 2013 HIPAA breaches Although there were 160 large-scale breaches, the most devastating ones were concentrated at the top. Seven out of every eight exposed patient records (88%) were the result of the five largest breaches: - Advocate Health and Hospitals Corporation – 4.0 million - Horizon Blue Cross Blue Shield of New Jersey – 840,000 - AMHC Healthcare Inc. – 729,000 - Texas Health Harris Methodist Hospital Fort Worth – 277,000 - Indiana Family & Social Services Administration – 188,000. **Analysis – Health records in a public park??** Healthcare regulations protect the privacy and security of patients, but their mandates represent sources of stress and frustration for providers. Essentially, HIPAA seems to be a public means to control the private sector. However, the last item on that list suggests that the federal government is at least making an effort to adequately maintain public sector security under HIPAA. Three of the above cases had to do with a lack of encryption. Devices or computer files were stolen that contained unencrypted medical records. The other two cases were the fault of business associates (more on their responsibility below). One accidentally sent PHI to the incorrect recipient through a coding mistake. The other did not properly dispose of microfiches of patient records, and this incident was bizarre because it involved a public park. Texas Health Harris Methodist Hospital Fort Worth announced earlier this year that microfiche that it had transferred to Shred-it for destruction was found in a local park by an uninvolved party on May 11. Microfiche was found in “two other public areas” as well, per a report published in [HealthITSecurity.com](http://healthitsecurity.com). Although Shred-it was responsible in this case, they did not handle the microfiche as defined within their agreement with Texas Health Fort Worth. Although**the health records were for patient appointments from 1980 to 1990, the hospital still made the Wall of Shame.** **Tips to avoid the Wall** Three significant lessons learned from the top five HIPAA breaches of last year include the following, according to Willis and Gold (basically rectifying all the mistakes made): 1. Always encrypt (as with our *self-encrypting storage*) – Note that in one case, the healthcare company had encrypted all the laptops, but not its desktops and the latter were breached. **The problem is with unencrypted data: theft of encrypted data is not considered a violation.** 2. Know the location of records – If PHI goes to the wrong place (as with the coding error incident above), you can conduct a risk assessment per 45 CFR 164.402(2) if you know the party to which the data was incorrectly sent. 3. Require evidence from those who destroy – You want a documented policy of disposal procedures for hard-copy patient records. Get verification from the organization to reduce your liability if they don’t hold up their end of the bargain. **New business associate stipulations** You may be aware that the HIPAA Final Omnibus Rule that went into effect last fall changed the playing field for covered entities and business associates. Business associates now have both contractual obligations to their covered entities and legal obligations to the federal government. In other words, your protection as a covered entity is enhanced by the government placing more pressure on business associates. Learn more today about [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [VPS Hosting](https://www.atlantic.net/vps-hosting/) with Atlantic.Net! --- # The Fluff-Free, Research-Driven Cloud > URL: https://www.atlantic.net/life-sciences-pharma-biotech/the-fluff-free-research-driven-cloud/ | Published: 2014-12-15 | Updated: 2025-03-06 | Author: Alexander Wise This report will review five cloud predictions made earlier this year by IBM’s Gery Menegaz, as follows: - Setting aside the fluff - Prediction #1: Better software access - Prediction #2: Astronomical expansion - Prediction #3: Continuing shift to hybrid models - Prediction #4: Stronger development focus - Prediction #5: Disruptive levels of innovation - The research-driven cloud. **Setting aside the fluff** “Cloud gone wrong”: that’s how Chris Magiet of tech tutorial site [Pluralsight](http://blog.pluralsight.com/worst-cloud-computing-portrayals%20) described the bogus, misleading, or otherwise perplexing descriptions of cloud computing used by marketers. Chris argues convincingly that it’s often better to think of distributed virtual technology in terms of the particular purpose it serves – using the terms IaaS, PaaS, and SaaS (infrastructure, platform, and software-as-a-service) rather than the grandiose, overarching term cloud. It seems a bit extreme that we should feel we need always to designate the branch of the cloud. For instance, the third computing platform follows the mainframe (first) and PCs (second) with its four core technologies: mobile access, social networking, big data analytics, and the cloud. It would be preposterous to have to list six core technologies instead so that you can mention the three general services rather than the cloud itself. Regardless, Chris’s point is valid that the fluffy white image has been used to create hype for a technology that would otherwise be more challenging to visualize and sell. How, then, do we best see through the hype to understand its legitimate business trends? That’s the subject of a report written earlier this year by Gery Menegaz, a chief architect for IBM: centering in on the true direction of the cloud. **Prediction #1: Better software access** Gery notes that the majority of applications currently being introduced are designed for cloud distribution. Since so much new software is built specifically for virtual environments, he specifically forecasts that by 2016, consumers and businesses will be able to use one in four applications (25%, which amounts to almost 50 million) through the cloud. General interest in the cloud among large businesses further bolsters Gery’s perspective: - 56% of large companies believe the technology creates a competitive advantage. - 58% of large companies designate over one-tenth of their yearly expenses toward the technology. **Prediction #2: Astronomical expansion** The cloud is on the rise worldwide, per Gartner. A published technology outlook by the research firm forecasts that the market will reach a quarter of $1 trillion within three years. Gery notes that the behaviors of large firms around the world are evidence of the technology’s increasing dominance: “Enterprises [are] increasingly relying on cloud to develop, market and sell products, manage supply chains, and more.” The same Gartner report looks specifically at the explosion of SaaS offerings (as mentioned above): that industry will expand at 20% each year, from $18 billion to $46 billion between 2012 and 2017. **Prediction #3: Continuing shift to hybrid models** According to Gartner, fully half of large businesses are going to deploy hybrid clouds within three years. As cloud generally becomes more popular, CIOs are developing plans that feature the technology. Nonetheless, 100% cloud adoption is rare. As Gery describes comprehensive cloud migration, “It would be very difficult, if at all possible, to move everything wholesale to the cloud because of the complexity of today’s environments.” Hybrid clouds are integrated systems that include more than one cloud infrastructure, including in-house dedicated servers and public Cloud Servers. Although extreme infrastructural transitions to public cloud are uncommon, an announcement from General Electric that the company will be closing down its data centers in favor of third-party virtualization may prompt other enterprises to consider a similar strategy. **Prediction #4: Stronger development focus** Out of the 18 million application developers on the planet, fewer than one in four are building for SaaS environments, per Evans Data. Gery suggests, just using common sense based on the growth figures, that developers will increasingly turn toward the world of hyper-efficient virtual machines. 17 out of every 20 new apps are cloud-based, per IDC. **Prediction #5: Disruptive levels of innovation** To make this point, Gery references Geoffrey Moore’s book *Crossing the Chasm* as a flawed counterpoint. Moore believes that once a company introduces a revolutionary solution, the firm immediately becomes less innovative because it has its hands full guiding customers through adoption. The book’s title is a nod to Moore’s thesis that businesses must emulate their competition if they want to become mainstream. Again, Gery sees Moore’s ideas as inapplicable to the context of the cloud. He believes the almost cutthroat competition is leading to more innovation: “In fact, the pace at which organizations are innovating appears to have sped up – at least from my perspective.” **The research-driven cloud** A concept you sometimes hear in business, particularly in architecture and interior design, is the notion of “research-driven” solutions. A company’s offerings are neither oversimplistic nor superficial but rather are fundamentally based on cutting-edge knowledge and expertise. That’s true of our solutions at Atlantic.Net, which are based on 20 years of development and refinement. Get started now, in 30 seconds, with our [pharma hosting](https://www.atlantic.net/life-sciences-pharma-biotech/) or [VPS hosting](https://www.atlantic.net/vps-hosting/). --- # Announcement: 100% of Silicon Valley’s Cloud VPS revenue donated to the homeless > URL: https://www.atlantic.net/announcements/ssd-cloud-vps-now-in-silicon-valley-with-100-of-revenue-donated-to-helping-homeless/ | Published: 2014-12-16 | Updated: 2025-03-06 | Author: Alexander Wise **Atlantic.Net Expands Out West With New Silicon Valley Data Center & Partners with Project Homeless Connect To Donate 100% Of The First Month’s Revenue To Helping San Francisco’s Homeless!** Atlantic.Net is excited to announce the opening of our newest data center in Silicon Valley! Located near San Francisco, California, this facility offers the same features as our other locations, plus faster access and lower latency for west-coast customers. To send our launch into the stratosphere, we will be donating 100% of the revenue raised within the first month of operation to [Project Homeless Connect](http://www.projecthomelessconnect.org/), a homelessness awareness organization dedicated to connecting homeless San Franciscans with the care they need! Whether you need one market-leading [VPS hosting](https://www.atlantic.net/vps-hosting/)or 1000s, now is a great time to add servers in our Silicon Valley location. Not only do you get a great product, but with us donating your revenue to help homeless people this holiday season, you’re doing good for the community! Help us make this holiday season a bit brighter for someone who needs help the most – bring your workloads to us.  See our [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). **Try a new SSD Cloud VPS Server in any of our locations!** ![SSD Cloud VPS ](https://www.atlantic.net/wp-content/uploads/2014/12/Silicon-Valley1a.png) --- # Atlantic.Net Expands Out West With New Silicon Valley Data Center & Partners with Project Homeless Connect To Donate 100% Of The First Month’s Revenue To Helping San Francisco’s Homeless > URL: https://www.atlantic.net/press-releases/atlantic-net-expands-out-west-with-new-silicon-valley-data-center/ | Published: 2014-12-16 | Author: Editorial Team ***Cloud Hosting Provider Continues Expansion with Fourth State-of-the-Art Facility To Improve Provisioning To West Coast Customers*** ORLANDO, FL, December 16, 2014– Atlantic.Net, a global SSD cloud VPS hosting solutions provider, today announced the opening of its first West Coast data center, located in the heart of San Francisco, California. To meet the growing demand of the developer community within Silicon Valley and local communities throughout California, Atlantic.Net continues to grow its infrastructure and overall commitment to developers around the world with a fourth data center. In conjunction with the launch, and to give back to the local community, Atlantic.Net will be donating 100% of the revenue raised within the first month of operation to Project Homeless Connect, a homelessness awareness organization dedicated to connecting homeless San Franciscans with the care they need.  “We are so grateful for Atlantic.Net’s gift this holiday season. Their generosity will go a long way toward helping vulnerable members of our community stay warm, fed, and cared for.  In San Francisco, where we see innovation and success everywhere, I admire Atlantic.Net for committing to their community by generously giving to those who need it most,” said Kara Zordel, Executive Director of Project Homeless Connect. “The Valley is the heart of the developer ecosystem and it is our first priority to ensure that innovative startups in the area have the tools and support needed to further develop and grow their ideas and scale their platforms,” said Marty Puranik, President and CEO of Atlantic.Net. “Also, as excited as we are about the launch and growing in the Valley, it’s also really important to us to show that the broader tech industry understands that we’re all in this together, and we have to do our part by helping those that need it the most. Project Homeless Connect does amazing work throughout the Bay Area and we’re glad we can help out anyway we can.” This 40,000 sq.ft. data center in the heart of Silicon Valley boasts industry leading high-power density and 2N-redundancy. By partnering with Telx and Vantage Data Centers, customers will be able to connect to hundreds of the world’s leading carriers, ISPs, and content providers. Atlantic.Net will continue to grow its infrastructure as more facilities are added throughout the United States and around the globe. The company recently announced the opening of their first international data center in Toronto, Canada, as well as a new US-based center in Dallas, Texas with plans to add more data centers, internationally in the coming year. **About Atlantic.Net** Atlantic.Net is a web hosting provider specializing in offering cloud server hosting, HIPAA compliant and hybrid hosting, private virtualization, and VPS hosting in the cloud. With a range of certifications and a SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited data center that the company owns and operates, the company is also known for its reliability, as dictated by its 100 percent uptime service-level agreement (SLA). For more information, please visit www.atlantic.net. # # # CONTACT: [marketing@atlantic.net](mailto:marketing@atlantic.net) --- # Study: 24 Out of 25 Healthcare Firms Use Cloud > URL: https://www.atlantic.net/hipaa-compliant-hosting/study-24-out-of-25-healthcare-firms-use-cloud/ | Published: 2014-12-20 | Updated: 2024-11-09 | Author: Sam Guiliano We all know that the public cloud is associated with security concerns – as demonstrated by the hacks of the Sony cloud and iCloud this fall. However, like companies in any other industry, healthcare organizations are intrigued by the incredible performance of the cloud, which has given doctors, executives, and biomedical researchers affordable access to supercomputer power on demand. ## Is the cloud right for healthcare? It may seem at times that companies are being asked to risk the privacy of their patient’s medical records and the prospect of hefty HIPAA fines in exchange for the speed required to keep pace with modern business. That’s not the case, though. Healthcare now understands that third-platform virtualization doesn’t have to mean giving up data protections: private clouds have become more commonplace, and hybrid clouds allow organizations to develop software and conduct other non-sensitive tasks in a standard cloud setting while privatizing environments containing PHI. A recent study by Dell, the Global Technology Adoption Index, shows that 96% of healthcare companies (24 out of every 25) have either deployed a cloud system or are planning to do so. According to an analysis of the study by Jasmine Pennic in [HIT Consultant](http://hitconsultant.net/2014/12/17/dell-96-of-healthcare-organizations-turn-to-the-cloud/), the “healthcare industry is not only rapidly transforming but is more successfully closing the gap in cloud adoption” versus other verticals. ## Methodology of worldwide tech study Dell designed and conducted this study – healthcare was just one piece – through a partnership with research firm TNS, which surveyed 2038 respondents. The respondents were IT executives at midsize firms in both the public and private sectors across the planet. They were positioned throughout 11 global regions and represented a broad spectrum of industries. Results were then segmented into findings for each area of the world and field of business. Surveys were completed between July and September, and TNS gave the study a +/- 2.2% margin of error. ## What the study revealed - More than 4 out of 5 healthcare companies use a private or hybrid system, evenly divided between the two (43% each, totaling 86%). - However, fewer people were “very confident” in the security of private cloud data, a total of 64%. - Interestingly enough, affordability was not considered the top cloud benefit by respondents. Instead, enhanced resource distribution was chosen as its top strength, beating out cost-effectiveness (39%) with almost half of the vote (46%). As mentioned above, the Dell study looked broadly at the marketplace. Overall, 97% of midsize business IT executives said that their company would be utilizing the cloud in some manner, one point higher than healthcare. In other words, whether or not the public perception is that the cloud is unsafe for sensitive data, healthcare firms realize how to make it work FOR them, as is true throughout the global business world. Another key finding of the study revealed the technology priorities of healthcare companies: - Reducing costs - Making upgrades to the infrastructure - Bolstering the technologies and physical environments of data centers. Dr. Cliff Bleustein, CMO of Dell’s healthcare division, said that the desire of healthcare companies to become more “patient-centered” is met by the cloud since it releases technologists from mundane tasks so that they can provide their skills toward optimizing the patient experience and enriching it digitally. Dr. Bleustein said that the cloud helps midsize healthcare providers “by providing the flexibility and scalability that enables [them] to be more nimble in the face of constant change.” ## Cloud archiving Centegra Health System was one organization that took part in the Dell study. Centegra CIO David Tomlinson, interviewed by Pennic, said that the primary reason his company was adopting the cloud was to store and share patient imaging files at a reduced rate, with better performance and better (gasp) security. The Illinois-based healthcare provider did not jump from an on-premise image storage infrastructure to a cloud server overnight. Still, Tomlinson became convinced that it synergistically optimized efficiency and security, the two general top priorities of any technological solution. Tomlinson said that the provider was initially concerned about security and backups but was able to adapt cloud archiving “once we worked through the security component and established redundancy to ensure high availability.” Dr. Bleustein noted that archiving within the cloud allows image data to be “actionable,” as can be understood by processing workflow functions through analytic tools. ## Healthcare information services Texas hospital Comanche County Medical Center has found that a cloud environment is ideal for its healthcare information system (HIS). By using a private cloud solution, the hospital has been able to redirect its computer professionals to other tasks. Ismelda Garza, CIO for CCMC, commented that the company was careful to select a cloud provider with extensive experience in HIPAA compliance: “It’s critical that our data is safe and secure because we’re dealing with confidential patient health records.” ## HIPAA business associate Atlantic.Net has been in business for 21 years, during which time two points of focus have emerged: [VPS hosting](https://www.atlantic.net/vps-hosting/) and [HIPAA-Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. In other words, the healthcare cloud is the nexus at the center of our expertise. One of the most popular plans we offer is our **HIPAA Self-Encrypting Storage**. Get a quote today! --- # HIPAA 2015 Outlook > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-2015-outlook/ | Published: 2014-12-23 | Author: Kent Roberts This article looks at the year ahead for HIPAA enforcement: - Anchorage – First official case of HIPAA “neglect” - Stats & expectations for 2015 - Phase 2 auditing - Compliance tips **Anchorage – First official case of HIPAA “neglect”** Alaska’s Anchorage Community Mental Health Services has received a dubious distinction from the federal government, per Tim Mullaney of [McKnight’s Long-Term Care News](http://www.mcknights.com/hipaa-breach-leads-to-first-ever-neglect-settlement-for-a-healthcare-provider/article/389159/). In early December, the five-facility healthcare provider reached a settlement with the HHS OCR (the agency that polices the healthcare law). Tim writes that the ACMHS will pay the federal government $150,000 as a penalty for neglect of the Privacy and Security Rules contained within HIPAA Title II. This announcement is noteworthy mainly because it is the first time the OCR has punished a healthcare “covered entity” for lack of action regarding fundamental data safeguards, including: - disregard for software patching - failure to update applications consistently. According to OCR Dir, remaining compliant involves taking a practical perspective toward ongoing and vigilant ePHI vulnerability assessment. Jocelyn Samuels stated, “This includes reviewing systems for unpatched vulnerabilities and unsupported software that can leave patient information susceptible to malware and other risks.” The breach, dwarfed in mainstream media (for obvious reasons) by the Sony #GOP hack, was enabled by a malware infection. Almost 3000 patients’ records were compromised, per OCR analysis. The Anchorage behavioral health firm is working with the OCR to reach compliance and is taking steps to prevent the possibility of recurrence. The settlement between ACMHS and the United States does not explicitly make the provider liable for any patient loss resulting from the breach. **Stats & expectations for 2015** We have mentioned several times on this blog that HIPAA enforcement is on the rise, per comments made at a Chicago conference of the [American Bar Association](http://www.dataprivacymonitor.com/enforcement/hhs-attorney-major-hipaa-fines-and-enforcement-coming/%20). At the event, a senior attorney with the HHS, Chief Regional Civil Rights Counsel Jerome B. Meites, said that enforcement would be significantly amplified throughout the ensuing year (meaning that the period between June 2013 and June 2014 would involve greater fines than the $10 million of settlements logged between June 2012 and June 2013). We should reasonably expect severe enforcement activities in 2015, then. Let’s look at the bigger picture of healthcare breaches over the last half-decade. According to Lynsey Mitchel of the National Law Review, getting a sense of the last five years is helpful because September 2009 was the month it became legally required to notify the government of breaches. Here are the statistics she compiled: - 1170 data breaches, September 2009 – early December 2014 - 31 million health record exposures, September 2009 – early December 2014 - 4463 HIPAA complaints, year total for 2013. The 2013 complaint total is the highest yet, and the OCR has not yet posted 2014 figures. Looking at the situation from a statistical perspective, Mitchel comes to the same conclusion expressed directly by the OCR attorney above: “It doesn’t take a crystal ball to predict that these numbers in 2015 will continue to rise.” The federal budget for 2015 does not boost the budget of the Office of Civil Rights. Still, the OCR seems unfazed, advancing confidently with its efforts to enforce the various consumer protections of Title II (which apply to **business associates** such as Atlantic.Net as of September 2013). One state is especially hurting. Alaska is well aware of the OCR’s redoubled efforts, with a $150,000 settlement, discussed above, joining a $1.7 million monster agreement with the Alaska Department of Health and Human Services (which, like the fourth biggest breach of 2013 by the Indiana Family & Social Services Administration, shows that the OCR is targeting both the public and private sectors). **Phase 2 auditing** One specific project that is moving forward with the OCR is Phase 2 of auditing, according to Joseph J. Lazzarotti, also of the [National Law Review](http://www.natlawreview.com/article/data-security-2015-banks-hipaa-covered-entities-and-small-businesses-too). These audits of healthcare businesses, which will be underway soon if they aren’t already, are centered on three elements of healthcare law: - vulnerability assessment and risk administration - breach notification (contacting the OCR and patients) - privacy notices. These audits should extend beyond covered entities to include some business associates, the latter of which have been directly responsible for compliance since the Final Omnibus Rule went into effect last year. **Compliance tips** Repeatedly, companies have been found non-compliant for failing to encrypt laptops and mobile devices. So first and foremost, note that if you encrypt the data accessible on laptops, you will remain compliant even if the laptop is stolen. Beyond encryption, Lynsey provides a couple of quick suggestions to stay legal: - Review and update your organizational policies and procedures. - Perform vulnerability assessments frequently. You can also ease your burden by partnering with a [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) associate that Complete Healthcare Solutions praises for “secure infrastructure and expertise in Healthcare IT.” Get a quote and a free consultation today and consider any of our other [VPS hosting](https://www.atlantic.net/vps-hosting/) options**.** By Kent Roberts --- # Burn After Reading: Snapchat, Ephemerality & VPN > URL: https://www.atlantic.net/vps-hosting/burn-after-reading-snapchat-ephemerality-virtual-private-networks/ | Published: 2014-12-29 | Updated: 2024-11-09 | Author: Kent Roberts This report looks at the issues of self-deleting content and privacy via the following sections: ## The staying power of ephemerality We truly want to have it both ways online. We want full access to everything that the Internet has to offer, but we don’t want to be abused. Two of the best ways to avoid getting abused are for people not to know who we are and for certain sensitive content to destroy itself after a window of time. Probably all of us would rather our IP addresses be screened than not. If anything, you might want to show your IP address on specific sites as needed, but there is no reason to standardly stroll around the Web with any identifying data exposed. Enter the virtual private network, growing in popularity as described below. ### Why ephemerality is important to consumers Beyond VPNs, though, many people desire the ability to send a message or photo and know that it will not exist “forever,” the general sense of how long Internet data lasts. As Ben Zimmer notes in the *Wall Street Journal*, it has become possible to limit the amount of time the data exists via applications such as Snapchat, Mirage, and Frankly. Ben argues that the interest in data time limits through Snapchat and its rival “ephemeral messaging” environments has shown the reemergence of the concept of ephemerality. Text messages, images, and videos are all removed from the Web soon after sharing with another party. Just as special agents might be instructed to “burn after reading” a top-secret document they have been sent, these apps burn your communication automatically as soon as it has been “used.” As Ben notes, “Communication can be kept secret if no electronic data trail is left behind.” ### The Sony Pictures breach The breach of Sony Pictures, purportedly by North Korea (a nation that South Korea claims to have 5900 Internet-focused military personnel) drives us further toward the notion of ephemerality as we all realize how perilous our digital footprint is. This Sony incident is especially poignant regarding ephemerality because Evan Spiegel, who cofounded Snapchat, became pulled into the mire by publishing his confidential emails back and forth with Sony’s Michael Lynton. The messages contained specific information about the Snapchat trajectory, and their revelation sacrificed competitive advantage. ### What does ephemerality really mean? The so-called temporary communications that go through Snapchat can last for 10 seconds or even less. The concept of *ephemerality* used to be a bit more long-lived: its root word, the Latin *ephemerus*, was used in medieval medicine to denote a 24-hour fever, called a *febris ephemera*. Ephemerality was then applied to animals that lived (at least in their mature forms) for extraordinarily brief periods, such as the adult phase of mayflies. Similarly, the term *ephemeral* was attached to certain plants and streams. From the 1600s on, ephemerality was used to denote anything temporary that would not be around for long. Ephemeral publications such as pamphlets typically aren’t saved in libraries or museums but disappear with time instead. ## Uncle Sam’s giant funnel We also have tended to think of digital data as something that is throwaway and only represents a single moment in time, but our expectations have changed: it is automatically measured and quantified, and it often means interaction rather than simply presentation: “We increasingly expect that even the most fleeting of messages may end up stored somewhere,” writes Ben, “in the virtual server space of ‘the cloud.’” The desire for quick forms of communication has grown more intense as it became clear from the Edward Snowden leak that the NSA is collecting and assessing a mind-boggling amount of data related to everyone. Will our private messages be “funneled into massive data centers”? It’s beginning to seem naïve to think the government is not packing away our web trails. ## VPN for privacy No one wants someone to watch their every move, and it’s like someone is reading over our shoulders. We aren’t just talking about the government. The same is true of cybercriminals. The same is true of marketers, sometimes, as well: many would just as soon harass us as to provide us real value. Why should they get our information for free? General privacy online is best accomplished through a VPN – the acronym for virtual private network – established by Amadou Diallo of *Forbes*. [When you set up a VPN](http://www.forbes.com/sites/amadoudiallo/2014/03/07/want-privacy-on-the-internet-then-you-need-a-vpn/), you no longer go directly to the Web and operate online primarily through plain text (except HTTPS sites secured with SSL certificates). Instead, you access the virtual private network, which encrypts everything you do online. The one problem with VPNs is that they can quickly get expensive. However, it’s straightforward and affordable to set one up yourself on your own cloud server. Get Linux cloud server hosting and install OpenVPN or an alternative of your choice. Atlantic.Net also offers [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions.  See our [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). By Kent Roberts   --- # Gartner Rings in the New Year with 2015 Tech Forecast > URL: https://www.atlantic.net/vps-hosting/nowtrending-gartner-rings-in-the-new-year-with-2015-tech-forecast/ | Published: 2014-12-30 | Updated: 2025-03-06 | Author: Alexander Wise In this article, we look at how the technology world is changing through the eyes of Gartner Research: - **State of the hotlist** - **What is a strategic trend?** - **Mobility 2.0** - **Internet of Things** - **3-D printing** - **Pervasive analytics** - **Contextualization** - **Smart products** - **Cloudification** - **Software-defined environments** - **Web scalability** - **Risk-defined security.** **State of the hotlist** As the weeks and days leading up through the holidays to the new year, we see more and more “hotlists” from writers attempting to summarize some aspect of culture or business in the form of 2015 projections. These compilations of trends are not all fluff, and they offer an excellent glance of a field from a relatively objective perspective. Gartner Research is one of the most widely respected business analysis firms. It released its list of top technology trends at a conference a couple of months ago, the Gartner Symposium/IT 2014 in Orlando, Florida. **What is a strategic trend?** Gartner described its list of tech trends as “strategic” for the majority of companies in 2015. These technologies were chosen based on their “potential for significant impact on the organization in the next three years.” Strategic trends could cause disruption, require high-dollar spending, and that could give your competitor an advantage if you hesitate to adopt them. They represent developments within IT that are relevant now but also have far-reaching implications for the years ahead. Gartner VP David Cearley explains that the technologies included in the “top 10” are not necessarily essential to have today or tomorrow at your company, but that everyone should be creating plans to incorporate them by the end of 2017. The Gartner trends are as follows: **#1 – Mobility 2.0** When we think of mobility, we will no longer consider devices but the various environments in which the user operates. Phones and smartwatches are part of a broader computing experience, courtesy of the “third platform,” with screens connected between public and internal settings. “Increasingly,” Cearley states, “it’s the overall environment that will need to adapt to the requirements of the mobile user.” As that transition takes place, IT management will become more difficult because the devices will step farther outside the company’s jurisdiction. **#2 – Internet of Things** Four data usage models are emerging as digitization becomes more comprehensive: manage, monetize, operate, and extend. Enterprises should be wary of focusing on the Internet of Things in isolation when it comes to integrating these various uses of data. There are broad applications for all four models throughout the assets, services, people, locations, and technological structures involved. **#3 – 3-D printing** Expect a 3-D printer in the mail any time now. Why? 2015 will see a 98% rise in the sales of these incredible devices globally. That astronomical rise won’t hit a plateau, though, although growth will slow slightly in 2016 to a not-exactly-tepid 50%. Through 2017, the demand will skyrocket as industries begin to understand how to benefit from the machines by “[reducing] costs through improved designs, streamlined prototyping, and short-run manufacturing.” **#4 – Pervasive analytics** Analytics – along with the Internet of Things, mobility, and the cloud – is one of the four pillars of computing’s *third platform*, which is gradually becoming the dominant model. Data is increasing exponentially, and everyone wants to know what it means. We are entering an era in which analytics will be built into applications standardly. Firms must learn how to filter and assess big data, and the best way is to deploy as many automated systems as possible, embedding analysis throughout. **#5 – Contextualization** As applications and devices become more innovative and analytics become pervasive, devices will generate the output based on the environment. Context-defined security is one maturing example, but similar technologies are on the way. “By understanding the context of a user request,” explains David, “applications can not only adjust their security response but also adjust how information is delivered to the user.” **#6 – Smart everything** As analytics become more profound and intensive, products will become more intelligent with a building focus on contextualization. This is essentially progress in artificial intelligence, with machines “learning to learn” and developing autonomy. Google has received considerable publicity for its gradually evolving self-driving car, and a French company has released a commercially available autonomous buggy. Robots are becoming more sophisticated, and virtual administrative assistants and intelligent advisors are quickly being refined and improved. As machines become more intelligent and helpful, everyone will be scrambling to best use them to their organization’s advantage. **[>>> Next >>>](https://www.atlantic.net/vps-hosting/nowtrending-gartner-rings-in-the-new-year-with-2015-tech-forecast-cont/)** Consider how quickly the technological world is shifting. When we think about the pace at which data is virtualizing, contextualizing, and becoming self-aware, we know we need cutting-edge infrastructure to accelerate our strategies. Spin up a low-cost Virtual Private Server in 30 seconds with Atlantic.Net today. By Moazzam Adnan   Cloud hosting is just one of four services that we offer – we also offer managed, [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/), and [VPS hosting](https://www.atlantic.net/vps-hosting/). Contact us today for a consultation. --- # Gartner Rings In New Year with Tech Forecast (cont’d) > URL: https://www.atlantic.net/vps-hosting/nowtrending-gartner-rings-in-the-new-year-with-2015-tech-forecast-cont/ | Published: 2014-12-31 | Updated: 2025-03-06 | Author: Alexander Wise [**<<< Previous <<<**](https://www.atlantic.net/vps-hosting/nowtrending-gartner-rings-in-the-new-year-with-2015-tech-forecast/) **#7 – Cloudification** In the globally integrated enterprise, mobility and the cloud continue to become increasingly essential to business, prompting the proliferation of software that is managed centrally and accessible through various BYOD devices. Gartner’s David Cearley calls cloud “the new style of elastically scalable, self-service computing, [a style with which] both internal applications and external applications will be built.” He mentions that although companies may want to get the most out of the resources of client devices, such as storage, the administration will occur within **secure** [**VPS Hosting**](https://www.atlantic.net/vps-hosting/). In 2015, one central concern will be the synchronization of application states to move seamlessly between our various devices. Applications will become more portable between devices as well, and eventually, applications will be able to support real-time updating with multiple devices to enable simultaneous interaction. Today we speak of second-screen use in terms of TV Everywhere, watching television through mobile. Eventually, games and enterprise applications will incorporate two screens and wearable devices. **#8 – Software-defined environments** Building flexibility into the code of the software and the underlying infrastructure allows companies to be adaptable enough to embrace shifts in the marketplace. Software-defined environments are becoming more dominant in security, storage, data centers, and networking. Anything within the cloud can be controlled by software interacting with the API. Applications are now likelier to have robust, built-in APIs so that you can easily get the functionality you need. To accommodate the need for on-demand computing and split-second scalability, computing will no longer be formulated in terms of static structures, favoring dynamic models instead. Developers will create rules and scripts that can coordinate the tools and power from the network for use in individual applications. **#9 – Web scalability** Web-scale computing is an IT capability to deliver public [Virtual Private Server](https://www.atlantic.net/vps-hosting/) performance within an enterprise. More companies will begin to replicate the software and infrastructural models of the behemoth Internet corporations – Amazon, Facebook, and Google. Web scalability is a characteristic that is gradually integrated into an organization, explains David, “[evolving] over time as commercial hardware platforms embrace the new models, and cloud-optimized, and software-defined approaches reach mainstream.” DevOps will be a significant driver behind web scalability with the intersection of development and operations for seamlessly organized innovation. Development of both applications and services will increasingly be a part of everyday operations. **#10 – Risk-defined security** Security is the linchpin that allows for digital environments to flourish. It is utterly, fundamentally important but also should not stand in the way of new development. Firms will become more aware in 2015 that it’s not possible to create an environment that has impenetrable security. As companies can admit that they can’t be prepared for defense against every single type of threat, they will be able to assess risk and monitor vulnerabilities in more complex manners. Developers, recognizing that it is no longer sufficient to set up safeguards at the perimeter of the network, will create more attuned applications to security concerns. Testing of applications will become more dynamic and integrated, and applications will know the context, and access will be modified to meet diverse situations. Essentially, applications will better learn to protect themselves. This trend is in part an admission that you can’t just set up a firewall, and the component applications within your system must themselves be vigilant. **Importance of the third platform** Since the third platform is so central to the ten trends, it’s worth a quick review of that concept and its disruptive impact on business. In an article for CIO published in March, Bernard Golden of Dell says that he is typically unimpressed by industry analyst forecasts but gushes about the quality of the [2014 IDC prediction list](http://www.cio.com/article/2377568/cloud-computing/as-idc-sees-it-tech-s-third-platform-disrupts-everyone.html): “While understated, its analysis and predictions provide as much drama as any novel, and its denouement is the kind of cliffhanger that makes it, as the saying goes, *unputdownable*.” The specific topic Golden found most compelling was IDC’s argument that among the top 20 firms in all major industries, one in three will be disrupted by current competitors and startups who utilize the third platform (which includes mobile use, big data analytics, cloud computing, and social networking) to their advantage. Examples of this sort of disruption are already beginning to line up: - Uber disrupting the dominant taxi companies - Airbnb redefining what it means to get a room for the night - Facebook Whatsapp overriding SMS usage through phone carriers. What is happening, as Golden points out, is that the true potential of the Internet to adjust and re-create aspects of our society in profound ways is just becoming evident. Although the current market leaders may dig in their heels, they may quickly find themselves in indefensible positions. Conflicts will brew. Code will be written, both digital and legal. Hands will shake between unlikely parties. Various new trends are emerging, but the growing prominence of the third platform is a macro-trend that organizations will ignore at their peril. Golden writes, “IDC is spot-on in its assessment that the next decade will see a tremendous change in every part of our economy.” By Moazzam Adnan Cloud hosting is just one of four of our services – we also offer managed, dedicated, and [VPS hosting](https://www.atlantic.net/vps-hosting/). Contact us today. --- # HIPAA on the Highway: Tennessee Hospice > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-on-the-highway-tennessee-hospice/ | Published: 2015-01-02 | Updated: 2024-11-14 | Author: Sam Guiliano An important topic in the healthcare industry is the increasing focus on enforcement of HIPAA law and scale. Let’s look at how a Tennessee hospice serves as an example of making the news even when just a few records are compromised: - **Setting an example** - **HIPAA on the highway** - **Act locally first** - **Don’t be an example.** ## Setting an example In what seems to be a similar pattern to the DOT National Highway Traffic Safety Administration’s incredible uptick in car recalls during 2014, the HHS Office of Civil Rights legal team publicly predicted that the number and dollar amount of healthcare settlements would be increasing through this summer. Specifically, Chief Regional Civil Rights Counsel Jerome B. Meites said that the degree of enforcement that had occurred between June 2013 and June 2014 – which totaled $10 million in settlements, including a record $4.8 million agreement – would “[pale in comparison](http://www.dataprivacymonitor.com/enforcement/hhs-attorney-major-hipaa-fines-and-enforcement-coming/) to the next 12 months.” ### HIPAA Wall of Shame Many of the high-profile cases investigated by the federal government are featured on a public webpage that some healthcare technologists now call the “HIPAA Wall of Shame.” In that way, organizations that experience large-volume breaches (affecting 500 or more people) serve as examples of what not to do. However, sometimes a TV news report serves as a Wall of Shame, even for minor breaches. ## HIPAA on the highway An ex-employee of a hospice did not destroy protected health information as the law demands, resulting in a [critical investigative news segment](http://healthitsecurity.com). When Sandra Rambo found medical records while walking with her daughter at the side of a highway, she knew immediately that it violated patient healthcare protections. The pair found almost two dozen hard-copy documents from Amedisys, representing 17 different patients. Rambo called her local news station, WJHL, to discuss the documents, including name and contact information, medical diagnoses and symptoms, and various “other private patient details regarding hospice visits.” The documents were from 2010. A spokesperson for Amedisys, also interviewed by WJHL, said that a previous staff member hadn’t destroyed the documents per the hospice’s policy. ## Act locally first The news show also reached out to Rachel Seeger, senior advisor for public affairs and outreach at the HHS Department (which oversees the OCR). Seeger said that typically when an organization is noncompliant with healthcare law, the OCR helps guide them toward solutions that will keep their patient data secure. It is rare that a settlement must be signed between HHS and the violating party, but that does sometimes occur – see the $10 million of settlements indicated above. In these cases, a resolution agreement is signed by HHS and the healthcare company, stating that the latter will conduct specific tasks (such as employee education) and give updates regularly to the agency, typically for 36 months. Throughout that probationary window, the OCR carefully determines if the firm is taking proper steps toward compliance. Additionally, “a resolution agreement likely would include the payment of a resolution amount,” commented Seeger. “These agreements are reserved to settle investigations with more serious outcomes.” ### The importance of a small breach Although typically, the government focuses on cases in which hundreds or thousands of records are exposed, Rambo did not think that the seemingly accidental misplacement of a few files was trivial. She was incredibly passionate about the issue because one of the 17 files was that of a man who lived nearby and had recently passed away. Rambo told the news reporter that HIPAA was put into effect so that medical establishments would become hyper-aware of privacy and security, preventing these types of incidents. Referring to healthcare practices, she said, “They’re supposed to prevent this from getting in the public’s grasp.” ### Response from Amedisys According to a representative for Amedisys, the company gathered all the files in Rambo’s possession and is reviewing how the breach occurred to avoid additional exposure. The representative told WJHL that the organization is abreast of HIPAA law, with all medical records digitally encrypted since 2012. As healthcare security consultants advise, the hospice also has comprehensive data policies and procedures in place. The policy currently in writing at Amedisys demands that employees immediately shred all paperwork following any visit. The person who dumped the documents at the side of the road was acting in a rogue fashion, as could be guessed. Amedisys said, “It does not appear that this former employee followed our normal protocols.” The facility is giving patients affected by the breach free subscriptions to credit tracking services. They are also retraining their staff. ### What can you learn from this incident? Although the notion of a data breach may sound initially complex, like hackers carefully working their way into a system, HIPAA violations are often the result of simple, day-to-day mistakes. If a disgruntled staffer’s employment has been terminated, they may accidentally still log in or otherwise access records. Alternately, someone still on staff may not understand the need to shred immediately and completely. ## Don’t be an example You may want your company to be an example of healthcare success. Still, you don’t want it to be an example of healthcare violation, like a system of Minnesota healthcare providers that exposed almost 2000 identities after records were accidentally dumped in the trash rather than being shredded. Partner with a knowledgeable business associate, now fully responsible for compliance with the 2013 Final Omnibus Rule for your [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/).  We also offer many popular additional hosting options like [Windows VPS](https://www.atlantic.net/vps-hosting/) Hosting or Dedicated Hosting. --- # HIPAA Hosting for SQL DB > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-hosting-for-sql-db/ | Published: 2015-01-13 | Updated: 2025-03-06 | Author: Alexander Wise This article looks at recent high-profile HIPAA violations and a discussion about a hosting solution for a [HIPAA database](https://www.atlantic.net/hipaa-compliant-hosting/) using Windows SQL: ## Major Violations in Hollywood & the New Year HIPAA was recently in the news when it was discovered that some of the data compromised by the Guardians of Peace hackers who infiltrated Sony Pictures were protected health information (PHI). *Becker’s Health IT & CIO Review* noted that the PHI that was accessed “[[included] claim appeals submitted to Sony such as diagnosis and disability codes, health plan member IDs, and any health or medical information provided outside of Sony’s health plans](http://www.beckershospitalreview.com/healthcare-information-technology/sony-says-employees-hipaa-protected-health-information-may-be-compromised.html).” Sony is not the only organization coming under scrutiny by the HHS OCR at the beginning of 2015. Elizabeth Snell of Health IT Security mentioned [two major revelations](http://healthitsecurity.com) already in January: - BlueCross BlueShield of Tennessee used the contact information of 80,000 TRH Health Plan subscribers for unauthorized marketing. - Safeway Inc. had to pay a $9.87 million civil fine for improper dumping of consumer information such as healthcare records and hazardous waste. The court found that more than 500 Safeway stores had disregarded lawful disposal. ## Real-World Scenario – HIPAA Consultation Consultant: Tell us about your hosting needs. Client: We are investigating hosting solutions that are [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/). The solution needs to be a Windows-based Application Server, SQL Server, and Web Server. I see a starter option for $ xxx per month that looks like what we need for an application server. Does this include SQL Server and the Web Server? If not, what are the additions to this? Consultant: Thank you for contacting Atlantic.Net. The $ xxx package does not include MS SQL, and it also does not have enough RAM to create the ( 2 )  virtual machines we would need to create inside the dedicated server to provide you with SQL and web servers. Using the one dedicated server and virtualizing it [following best practices](https://www.sentryone.com/blog/strategies-best-practices-virtualizing-sql-server) would maintain HIPAA compliance at the lowest possible cost. We use Hyper-V to virtualize the dedicated server, and the Windows Standard Edition license allows for the creation of ( 2 ) VM’s on a dedicated server. There is one other thing to consider when using MS SQL, and it is how fast you need the I/O to be on the hard drives. If you need a very fast I/O for the database work, we would have to add ( 2 ) more hard drives and create a RAID 10 configuration. We would also have to add a high-performance RAID card to the dedicated server. If you do not require a fast I/O for the database work, then you can go with the ( 2 ) hard drives and the hardware RAID card we include automatically. This is the pricing if you DO NOT require the Fast I/O: 1. MS SQL Standard 2008 R2 or MSSQL 2012 – $ xxx per month 2. Add an extra 16 GB of RAM to the server – $ xxx per month This would increase the total monthly pricing to $ xxx per month on a 12-month agreement with no setup fee. This is the pricing if you DO require the fast I/O: 1. MS SQL Standard 2008 R2 or MS SQL 2012 – $ xxx per month 2. Add an extra 16 GB of RAM to the server – xxx per month 3. Two extra 500 GB hard drives – $ xxx per month 4. Upgrade to High-Performance RAID Card – $ xxx per month This would increase the total monthly pricing to $ xxx per month on a 12-month agreement with no setup fee. You do have the option of providing your own MSSQL License. If you do, it will remove the monthly charge of $ xxx per month for the license. Microsoft does not allow us to sell their licenses under our SPLA agreement; we can only lease them to customers under a monthly charge. Client: Thanks for the response. One other question: Do you provide SSL Certificates, or would this be something we would obtain and install? Consultant: You can purchase the SSL yourself and transfer it, or you can purchase it from us through our engineering department. I have attached the document that details the different SSL’s that we offer. If you purchase the SSL through us, then we will install it for you. ## How AssistRX Meets its Compliance Needs The above interaction is just one real-world example. We help healthcare organizations with their HIPAA-compliant needs every day. One of our newest HIPAA partners is [AssistRx](https://www.assistrx.com/). The company’s chief brand & business development officer, Edward Hensley, commented, “We see the unmatched potential and capabilities present in Atlantic.Net’s private hosting platform to build upon our latest innovations and services in a secure and efficient way.” By Kent Roberts --- # Montréal-Based Company Seeks HIPAA Compliant Hosting Solution with BAA > URL: https://www.atlantic.net/hipaa-compliant-hosting/montreal-based-company-seeks-hipaa-compliant-hosting-solution-with-baa/ | Published: 2015-01-20 | Author: Sam Guiliano This article explores[HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/)as follows: - **Must Canadian Firms Comply?** - **2015 Prediction from OCR Attorney** - **Conversation with Montréal Company** - **Finding Worry-Free Partners** **Must Canadian Firms Comply?** Many healthcare businesses operating in the United States are based in other countries, and there is often confusion about the extent to which those companies must meet HIPAA law. There are no exceptions: any business that processes, stores, or transfers protected health information (PHI) must follow the privacy, security, and breach notification rules described in Title II of the Health Insurance Portability and Accountability Act of 1996, regardless of where they are headquartered. “If you’re obligated to comply with HIPAA, and you have a data breach,” warns Ontario IT firm WW Works, “you could be facing very large fines or legal action from the United States.” **2015 Prediction from OCR Attorney** David Holtzman, who used to be an attorney for the HHS Office of Civil Rights, noted in *GovInfoSecurity* that he thinks the OCR will take [more “high-profile” enforcement actions this year](http://www.govinfosecurity.com/blogs/what-will-hipaa-enforcer-do-in-2015-p-1793). His perspective is based in part on the early December OCR settlement with Anchorage Community Mental Health Services. This Alaska provider was fined $150,000 for exposing 2700 patient records by failing to patch software properly. That settlement is the first since Jocelyn Samuels took over the director post. “This resolution agreement could signal that OCR is regaining its footing after the transition to a new leadership team and will be moving ahead more aggressively,” argues Holtzman. Currently, the OCR site states that there are 6000 complaints and audits under investigation. **Conversation with Montréal Company** The following conversation is based on an interaction with a client needing a HIPAA compliant system for their Canadian business. Consultant: Thank you for contacting Atlantic.Net. Please tell us about your hosting needs. Client: I’m looking for a cost-effective [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solution with a BAA. We are based in Montreal. Consultant: We can only provide a HIPAA Server out of our Orlando, Florida, datacenter. If you would like us to send you a formal proposal, we will need answers to the following questions. I have attached a copy of our BAA and HIPAA audits for your review. 1. Do you require a Linux or Windows-based platform? 2. How much storage space do you require for the data, and do you need Encrypted Storage? 3. How many internal users will be accessing the hosting platform? Client: Initially, we are developing a free app, essentially a pill reminder for iOS and Android. The online portion is an API, and data is encrypted by us. Linux server. Not sure whether we need encrypted storage, but let’s assume with and without. At this point, I don’t have an estimate for storage size.  The free app will have minimal needs, but our full product may need more. Give me some ideas for cost so I can budget this better. Internal users mean what?  Programmers?  Admins? Assume 1 of each, I guess. Consultant: If you are encrypting the data yourself, then you do not need Encrypted Storage. The smallest amount of storage we can provide is 500 GB. The pricing for this is actually on our website, but on our website, it says 160 GB of storage. We are providing 500 GB for the same price. This is the link to the pricing, and it would be $xxx per month on a 24-month agreement. You can add extra services to this package as follows: 1. Fully Managed Daily Backup (extra $xxx per month) 2. cPanel w/ WHM for Linux (extra $xxx per month) – You will need this if you are not familiar with operating a Linux hosting platform from the command-line interface level. 3. Trend Micro Deep Security (extra $xxx per month) – or you can install your own antivirus software. The hosting platform comes with ( 5 ) Encrypted VPNs, so if you only have two internal users, you have plenty of VPNs you can use to connect to the hosting platform. Our HIPAA hosting platforms include only Private Dedicated Hardware, so the Firewall. Intrusion Detection System and Dedicated server are allocated to each individual customer. I have attached two more documents for your review that encompass our Fully Managed Hardware Firewall, Intrusion Detection System, Encrypted VPNs, and Fully Managed Daily Backup. Client: This seems reasonable to me. I’ll discuss this with my team over the next week and will get back to you soon. Thanks for the speedy reply! **Finding Worry-Free Partners** As you can see above, we are highly familiar with HIPAA and business associate agreements, specializing in healthcare compliance solutions for the past six years. Complete Healthcare Solutions vice president Joseph Nompleggi said of our [**HIPAA Compliant Hosting**](https://www.atlantic.net/hipaa-compliant-hosting/), “Our partner’s financial strength and proven track record are something we view with great confidence.” Atlantic.Net also can offer [VPS hosting](https://www.atlantic.net/vps-hosting/) that offers 100% uptime. --- # GE Says its New Apps are “North of 90%” Public Cloud > URL: https://www.atlantic.net/hipaa-compliant-hosting/ge-says-its-new-apps-are-north-of-90-public-cloud/ | Published: 2015-02-02 | Updated: 2025-03-06 | Author: Alexander Wise General Electric’s head of IT [told *InfoWorld*editor Eric Knorr in October](http://www.infoworld.com/article/2824508/cloud-computing/ges-head-of-it-were-going-all-in-with-the-public-cloud.html) that the company was moving aggressively toward the public cloud, with 90% of new systems built within that environment and moving to 100% public cloud over the next 15 years: ## Why General Electric’s Announcement Is Important Although the incredible investments into cloud infrastructures – most prominently Amazon, Microsoft, Google, and IBM – have brought increasing attention to the public cloud, the technology often gets little respect. Many firms still don’t trust the multi-tenant environments of cloud service providers, at least not with their most sensitive applications. “That’s why it’s a fairly big deal when the CIO of General Electric, staple of the Fortune 10, says it’s ‘all-in’ for public cloud,” [explains Barb Darrow of *Gigaom*](https://gigaom.com/2015/01/18/ge-tech-guru-gives-public-cloud-a-big-high-five/). Although not everyone believes in reference accounts (accounts that can be contacted by potential customers to verify the quality of your service) – as when they were called “a bad idea” [by *Inc.* contributing editor Geoffrey James](https://www.inc.com/geoffrey-james/reference-accounts-are-a-bad-idea.html), General Electric is almost unbeatable in that role. Darrow notes that General Electric has a market capitalization (the complete value of the outstanding shares of any publicly traded firm) of almost a quarter of $1 trillion, with products and services ranging from home appliances to jet engines to financial products. Let’s look at the original *InfoWorld* interview, in which General Electric’s Chris Drumgoole, technically the COO of information technology, stated his organization’s firmly held commitment to the public cloud model. ## General Electric’s Vision – Beyond Hybrid Drumgoole explained why General Electric previously said that it would be doing away with nine out of every ten data centers and transitioning to the public, IaaS (infrastructure as a service) model. Essentially, the IT leadership at one of the world’s largest and most prestigious corporations has determined that cloud is a better way to provision resources: “We have a model where we’re operating outside of our four walls in someone else’s environment, but we’ve been able to ensure that GE data — compute, memory, and storage — remain single-tenant” within a data center that is used by many different businesses. That comment raises an important issue: terminology.  [Private cloud computing](https://www.atlantic.net/vps-hosting/)is commonly understood by cloud service providers to refer to single-tenant environments, whether they occur within hosting environments or within a client’s own data centers. Since General Electric is talking about the company’s data being partitioned off from everyone else’s, it’s referring to what many CSP’s list as a private cloud. In essence, what GE is really describing is their position that cloud service providers are **the ideal source of computing resources**. Drumgoole noted that although the enterprise does still have internal systems that are designed to operate in a similar manner to the cloud, they don’t see themselves using both third-party-hosted and internal servers for long. In fact, GE believes hybrid cloud is not the ultimate goal. It’s unclear exactly how many years it will be before the full transition is made to using outside providers, but Drumgoole said he sees “no reason why everything except the rarest of apps” would not be moved to a cloud service provider eventually. ## Tomorrow vs. 15 Years When Knorr expressed his shock about the announcement given the well-documented misgivings of many organizations toward the cloud, the IT chief confirmed that General Electric was completely onboard with migrating everything to cloud data centers. However, not everyone at the mega-corporation agrees when that transfer should be complete. Some advocate making the comprehensive switch immediately, while others say the transition should be piecemeal, gradually migrating through 2030. ## Big Data and the Massive Scale of GE Part of what is particularly interesting about the case is General Electric’s sheer scale, particularly in the age of big data. Recognizing that GE is not the first organization people think of when they consider information-age overload, Drumgoole provided an example: each one of its jet engines produces about 2 TB of information each time its plane is flown. “A flight with a GE engine takes off or lands every three seconds,” the COO explains. “All of a sudden, the data gets very, very large very, very fast.” ## Total Cost of Ownership A typical argument that people have against public cloud is that it represents an operating expenditure (opex) rather than a capital expenditure (capex). When Knorr asks the IT head about the internal discussions related to opex, Drumgoole explained that GE frames its IT needs instead in terms of total cost of ownership. Furthermore, General Electric doesn’t just concern itself with cost but adaptively reconceptualizes the role of computing in its business. ## Conclusion Is the perspective of General Electric intriguing in terms of your own business needs? Get a quote for public cloud hosting within our SSAE 16 certified data center today. By Moazzam Adnan *Atlantic.Net can also assist with dedicated, managed and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions – contact us today for a consultation.* --- # How to Install IIS on Windows Server 2012 R2 > URL: https://www.atlantic.net/vps-hosting/how-to-install-iis-windows-server-2012-r2/ | Published: 2015-02-03 | Updated: 2025-03-06 | Author: Alexander Wise ##### Verified and Tested 02/03/15 ### Introduction This how-to shows you how to install IIS 8.0 role on a Windows Server 2012 R2. ### Prerequisites Administrator access on the Windows Server 2012 R2 server. If you do not have a server already, you can spin up an Atlantic.Net [virtual private server](https://www.atlantic.net/vps-hosting/) in under 30 seconds. ## Installing IIS on Windows Server 2012 R2 Open the server manager by clicking **Server Manager** icon that should be located on your task-bar. If you are unable to find it, click the Windows start button and click Control Panel, and then click System and Security then click Administrative Tools then click Server Manager. In the server manager, click **Add roles and features**. ![Server Manager: Add Roles and Features](https://www.atlantic.net/wp-content/uploads/2018/01/iis1-1.png) The Add Roles and Features Wizard should open. Click **Next** on the before you begin section. Make sure**Role-based or feature-based installation** is selected in the Installation Type Section, then click **Next.** ![Select Role-based or feature-based installation](https://www.atlantic.net/wp-content/uploads/2018/01/iis2-1.png) Make sure **Select a server from the server pool** is selected. **Select your server in the server pool section**. Once done click **Next**. ![Select your server from the pool of servers](https://www.atlantic.net/wp-content/uploads/2018/01/iis3-1.png) Scroll down and click the **Web Server (IIS).**A popup window should appear**.** ![Select Web Server(IIS)](https://www.atlantic.net/wp-content/uploads/2018/01/iis4-1.png) Click the **Add Features** button on Add roles and features wizard popup. ![Include the management tools and select Add Features.](https://www.atlantic.net/wp-content/uploads/2018/01/iis5-1.png) Click **Next** on the Add Roles and Features Wizard. Select any additional features you may want to add and then click **Next**. ![Select any additional features you may want to add and then click Next.](https://www.atlantic.net/wp-content/uploads/2018/01/iis6-1.png) Click **Next** on the Web Server Role (IIS) information window. ![Select next](https://www.atlantic.net/wp-content/uploads/2018/01/iis7-1.png) Review the features being installed, you can install additional ones if you would like. Once done click **Next**. ![Review the features being installed](https://www.atlantic.net/wp-content/uploads/2018/01/iis8-1.png) Review what is being installed. Once done click **Install.** ![How to install IIS on Windows Server 2012 R2-09](https://www.atlantic.net/wp-content/uploads/2018/01/iis9.png) You should see a **progress bar**, once it is finished you can hit **Close.** ![Confirm Feature Installation](https://www.atlantic.net/wp-content/uploads/2018/01/iis10.png) IIS 8.0 is now installed. To bring up the Internet Information Services Manager go to the **Service Manager**, click **Tools** and the click **Information Services (IIS) Manager.** ![You may access Internet Information Services manager from the Server Manager tools](https://www.atlantic.net/wp-content/uploads/2018/01/iis11.png)   ![Sample IIS Manager](https://www.atlantic.net/wp-content/uploads/2018/01/iis12.png) Congratulations! You have just installed IIS. Check out [Configure IIS In Windows Server 2012](https://www.atlantic.net/vps-hosting/how-to-configure-iis-windows-server-2012/) for more information. ## Atlantic.Net [VPS hosting](https://www.atlantic.net/vps-hosting/) is just one of the many hosting services offered by Atlantic.Net – We also offer dedicated, managed and HIPAA compliant hosting services. In 20+ years of service, our solutions have been focused on providing the very best in web solutions to our valued customers! Contact us today for more information on any of our services! --- # How to Install and Configure GlusterFS on CentOS 7/CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-configure-glusterfs-centos-7-8/ | Published: 2015-02-04 | Updated: 2026-03-03 | Author: Andrew Mora ##### Verified and Tested 03/10/21 ### Introduction Quick installation of GlusterFS on Centos 7.x and 8.x. GlusterFS clusters together storage building blocks over Infiniband RDMA or TCP/IP interconnect, aggregating disk and memory resources and managing data in a single global namespace. ### Prerequisites You’ll need a separate hard disk(s) or virtual disk(s) to use as glusterfs storage mount point(s). ## Installing and Configuring GlusterFS on CentOS 7 Install XFS file system ``` yum install xfsprogs -y ``` Install and Enable GlusterFS official repository ``` yum -y install centos-release-gluster40 sed -i -e "s/enabled=1/enabled=0/g" /etc/yum.repos.d/CentOS-Gluster-4.1.repo ``` Install GlusterFS via YUM ``` yum --enablerepo=centos-gluster41 -y install glusterfs-server ``` Partition, format and mount your GlusterFS Volume. In this case our “extra harddisk/virtual disk” is /dev/sdb/. NOTE: I will not be going into detail about how to partition your harddisk, as it is out of the scope of this article. We will be using the FDISK utility to partition /dev/sdb. Also note that you may choose your partitioning scheme as you please. For the sake of simplicity, we’ll be creating a single large partition /deb/sdb1 ``` fdisk /dev/sdb ``` ![Sample Fdisk Operation](https://www.atlantic.net/wp-content/uploads/2018/01/glus1.png) Sample Fdisk Operation Create a new Primary or extended partition, write it to the disk and exit the FDISK utility. Proceed to format the disk in XFS. ``` mkfs.xfs /dev/sdb1 -f ``` Add your new disk to /etc/fstab so that the disk is mounted at boot time ``` echo "/dev/sdb1 /export/brick1 xfs defaults 1 2" >> /etc/fstab ``` ``` mount -a && mount ``` Start the GlusterFS daemon and make sure it starts upon boot time. ``` systemctl start glusterd systemctl enable glusterd ``` Now, verify the GlusterFS version with the following command: ``` gluster --version ``` Output: ``` glusterfs 4.1.9 Repository revision: git://git.gluster.org/glusterfs.git Copyright (c) 2006-2016 Red Hat, Inc. GlusterFS comes with ABSOLUTELY NO WARRANTY. It is licensed to you under your choice of the GNU Lesser General Public License, version 3 or any later version (LGPLv3 or later), or the GNU General Public License, version 2 (GPLv2), in all cases as published by the Free Software Foundation. ``` ## Installing and Configuring GlusterFS on CentOS 8 Install XFS file system ``` dnf install xfsprogs -y ``` Install and Enable GlusterFS official repository ``` dnf -y install centos-release-gluster8 sed -i -e "s/enabled=1/enabled=0/g" /etc/yum.repos.d/CentOS-Gluster-8.repo ``` Install GlusterFS via DNF ``` dnf --enablerepo=centos-gluster8,PowerTools -y install glusterfs-server ``` Partition, format and mount your GlusterFS Volume. In this case our “extra harddisk/virtual disk” is /dev/sdb/. NOTE: I will not be going into detail about how to partition your harddisk, as it is out of the scope of this article. We will be using the FDISK utility to partition /dev/sdb. Also note that you may choose your partitioning scheme as you please. For the sake of simplicity, we’ll be creating a single large partition /deb/sdb1 ``` fdisk /dev/sdb ``` ![Sample Fdisk Operation](https://www.atlantic.net/wp-content/uploads/2018/01/glus1.png) Sample Fdisk Operation Create a new Primary or extended partition, write it to the disk and exit the FDISK utility. Proceed to format the disk in XFS. ``` mkfs.xfs /dev/sdb1 –f ``` Add your new disk to /etc/fstab so that the disk is mounted at boot time ``` echo "/dev/sdb1 /export/brick1 xfs defaults 1 2" >> /etc/fstab ``` ``` mount -a && mount ``` Start the GlusterFS daemon and make sure it starts upon boot time. ``` systemctl start glusterd systemctl enable glusterd ``` Now, verify the GlusterFS version with the following command: ``` gluster --version ``` Output: ``` glusterfs 8.3 Repository revision: git://git.gluster.org/glusterfs.git Copyright (c) 2006-2016 Red Hat, Inc. GlusterFS comes with ABSOLUTELY NO WARRANTY. It is licensed to you under your choice of the GNU Lesser General Public License, version 3 or any later version (LGPLv3 or later), or the GNU General Public License, version 2 (GPLv2), in all cases as published by the Free Software Foundation. ``` Congratulations you have installed and configured GlusterFS on CentOS 7 and CentOS 8. We hope this article assisted you with the process. Thank you for following this How-To. Check back for updates and more interesting Centos how-to’s or learn more about our reliable [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. --- # Atlantic.Net Cloud – Getting started with Atlantic.Net Cloud Services > URL: https://www.atlantic.net/vps-hosting/atlantic-net-cloud-getting-started-with-atlantic-net-cloud-services/ | Published: 2015-02-04 | Updated: 2026-03-02 | Author: Alexander Wise ##### Verified and Tested 02/03/15 ## Introduction This How-To document will demonstrate how easy it is to get started with your first server. It will function as a full signup guide/explanation and ends with how to access the newly-created server. ## Prerequisites A valid email address. A modern internet browser. A valid credit or debit card (prepaid cards are not accepted during the signup process, but can be used after the after the successful payment of your first invoice). ## Getting started with Atlantic.Net Cloud Services Creating your first server with Atlantic.Net is easy! If you are a new customer, you will want to follow this short guide on setting up a new account. For returning customers who have an account with us but no current active servers, you can view this page on creating a new cloud server –[https://www.atlantic.net/cloud-hosting/how-to-create-new-atlantic-net-cloud-server/](https://www.atlantic.net/vps-hosting/how-to-create-new-atlantic-net-cloud-server/). There is no need to sign up with another account to create a new server if you already have an account with us. 1. The first step to creating a cloud server with Atlantic.Net would be to complete the signup process. You can begin that here: [https://cloud.atlantic.net/signup](https://cloud.atlantic.net/?page=signup) This process will ask you for your email address that the account will be under and your password for the new account. Once done, you will be re-directed to a page like below and instructed to check your email for a link. ![anet-GettingStarted-00](https://www.atlantic.net/wp-content/uploads/2018/01/anet-GettingStarted-00.jpg) Check your email 2. You will receive an automated verification email from our system. This email will come from “[cloudsupport@atlantic.net](mailto:cloudsupport@atlantic.net)” and have a subject line of “Please Verify Your Email Address.” If you do not receive the email after a few minutes, you will want to check any spam or junk folders/filters to see if it has been blocked. If necessary, you can contact our support department to assist you with completing the signup process. There will be a link in this email that takes you to the final stage of signup. On this page, you will need to enter in the billing information for the account. Having as much information and as much accuracy as possible will help to speed up the account verification process. For payment type, we accept all major credit cards and debit cards (prepaid cards are not accepted during the signup process, but can be used after the after the successful payment of your first invoice). At the moment we do not accept PayPal or similar services, but this may be an option in the future. Take a moment to read our Terms of Service before hitting “Complete Registration.” The ToS can be found here: [Cloud atlantic net](https://cloud.atlantic.net/?page=termsofuse). The page will look like the below. ![anet-GettingStarted-01](https://www.atlantic.net/wp-content/uploads/2018/01/anet-GettingStarted-01.jpg) Billing Information 3. Once completely filled out, click on “Complete Registration” to finish your registration. When your registration is complete, our automated system will work to verify the account. If all information provided is accurate, the credit card used is valid, and there are no issues with the signup, it will be approved. In cases where our system is unable to verify the account automatically, you may receive a telephone call to the phone number entered in either the signup or billing information. Our account verification team will work with you to make sure that the information provided is accurate. After this brief call, the account can then be verified. If the information provided is incorrect/mismatched, or we are unable to contact you by phone, our team may need to send an email to the email address provided during signup requesting further information. This may include: a photo of your passport, a photo of your driver’s license, or a photo/scan of your most recent credit card statement or bill with any information you do not want to release blacked out. This is necessary so that we can match the information provided to a real account or a real person. We do this to help prevent misuse of our network and servers and to maintain the highest quality of service for all customers. -Our automated system may place a holding charge on the credit card used during signup. This is a temporary charge and will disappear from the card after about 3 business days. You can always contact our billing department if the charge has not yet disappeared in a reasonable amount of time. They can be reached at [cloudbilling@atlantic.net](mailto:cloudbilling@atlantic.net) 5. You can now create a server. You may log into the Cloud Portal, https://cloud.atlantic.net, to start this process. If you are unfamiliar with it, you may view this link here: [https://www.atlantic.net/community/](https://www.atlantic.net/vps-hosting/how-to-create-new-atlantic-net-cloud-server/) 6. When you have completed creating a server, you will receive an email with the login information required to access the server. This email will also be from [cloudsupport@atlantic.net](mailto:cloudsupport@atlantic.net). Its subject line will include your server’s friendly name, its unique server ID (provide this during any interaction with our support team to help decrease troubleshooting time needed), and its IP address. The body will contain further information about the server including its root/administrator username and password. You will want to keep this email for your records at least until you are able to access the server and update the password to one unique for you. -There are two ways you can access your server. For Windows servers, you would primarily want to use Remote Desktop to connect to the server. Remote Desktop comes with all versions of Windows. You can find a guide on its usage here: [Connect using remote desktop connection](http://windows.microsoft.com/en-us/windows/connect-using-remote-desktop-connection) For Linux servers, the tool to use would be SSH. The most popular application for SSH on Windows is PuTTY which can be found here: [http://www.chiark.greenend.org.uk](http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html) Your alternative, if those are unavailable or non-functional, is to use our built-in VNC client. Please see here for more information on its usage: [How to using vnc access cloud server](https://www.atlantic.net/hipaa-compliant-hosting/how-to-using-vnc-access-cloud-server/) 7. At this point, the signup process is complete. Your new server begins adding to your bill at the hourly rate the moment it is provisioned. You can have multiple cloud servers under a single account. Creating and deleting servers is something you can do at any time from our cloud control panel: [https://cloud.atlantic.net/](https://cloud.atlantic.net/?page=userlogin) You can view these two knowledgebase articles to learn more: [How to delete atlantic net cloud server](https://www.atlantic.net/vps-hosting/how-to-delete-atlantic-net-cloud-server/) [https://www.atlantic.net/cloud-hosting/how-to-create-new-atlantic-net-cloud-server/](https://www.atlantic.net/vps-hosting/how-to-create-new-atlantic-net-cloud-server/) 8. If you require further clarification or assistance at any point in this process, do not hesitate to contact our support department by email at [cloudsupport@atlantic.net](mailto:cloudsupport@atlantic.net), by phone at 1.866.618.3282, or by chat on our main page (click the “Live Chat” link at the top of the page).   --- # How To Protect your Server Against the POODLE SSLv3 Vulnerability > URL: https://www.atlantic.net/disaster-recovery/how-to-protect-server-poodle-sslv3-vulnerability/ | Published: 2015-02-05 | Updated: 2026-02-28 | Author: Ariel Beltre ##### Verified and Tested 02/05/2015 ### Introduction On October 14th, 2014, a vulnerability was established in version 3 of the SSL encryption protocol. This vulnerability, known as POODLE (Padding Oracle On Downgraded Legacy Encryption), allows an attacker to read otherwise encrypted information with this version of the protocol in plain text using a man-in-the-middle attack. Although SSLv3 is an older version of the protocol, many pieces of software will still revert to SSLv3 if better encryption options are not available at the time. Also, It is important to keep in mind that an attacker can force SSLv3 connections if it is an available alternative for both participants attempting to connect. The POODLE vulnerability affects any services or clients that make it possible to communicate using SSLv3. As this is a flaw with the protocol design, every piece of software that utilizes SSLv3 is vulnerable. The POODLE vulnerability exists because the SSLv3 protocol does not properly check the padding bytes that are sent along with encrypted messages. An attacker can replace these and pass them on to the intended destination. When done, the modified payload will potentially be accepted by the recipient without complaint. ## Protecting Yourself from the POODLE SSLv3 Vulnerability There are actions that can be taken in order to ensure protection from this type of vulnerability. Since encryption is negotiated between clients and servers, this is an issue that effects both parties. Clients should take steps to disable SSLv3 support completely. Many of the applications today use better encryption by default, but even these applications use SSLv3 as a fallback option if none are available. This should be disabled, as an attacker can force SSLv3 communication if both parties allow it as an acceptable method of encryption. ## Apache Web Server To disable SSLv3 on the Apache Web server you will have to adjust the SSLProtocol directive provided by the mod_ssl module. This can be set either at the server level or in a virtual host configuration. Depending on your distributions Apache configuration, the SSL configuration maybe located in a separate file that is sourced. In Ubuntu, the server-wide specification for servers can be adjusted by editing the /etc/apache2/mods-available/ssl.conf file. If mod_ssl is enabled, a symbolic link will connect this file to the mods-enabled subdirectory: ``` sudo nano /etc/apache2/mods-available/ssl.confIn ``` CentOs, you can adjust this in the SSL configuration file located here (If SSL is enabled): ``` sudo nano /etc/httpd/conf.d/ssl.conf ``` Inside you can find the SSLProtocol directive. If it is not available, create it. Modify this to remove support for SSLv3: ``` SSLProtocol all -SSLv3 -SSLv2 ``` Save and close the file. Restart to enable the changes. On Ubuntu, you can type: ``` sudo service apache2 restart ``` On CentOS, this would be: ``` sudo service httpd restart ``` ## Nginx Web Server To disable SSLv3 on a Nginx web server, you can use the ssl_protocols directive. This will be located in the server or http blocks in your configuration. For example, in Ubuntu, you can either add this globally to /etc/nginx/nginx.conf inside of the http block, or to each server block in the /etc/nginx/sites-enabled directory. ``` sudo nano /etc/nginx/nginx.conf ``` To disable SSLv3, your ssl_protocols directive should be set like this: ``` ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ``` You should restart the server after the above modification has been made: ``` sudo service nginx restart ``` ## HAProxy Load Balancer To disable SSLv3 in an HAProxy load balancer, you will need to open the haproxy.cfg file.This is located at /etc/haproxy/haproxy.cfg: ``` sudo nano /etc/haproxy/haproxy.cfg ``` In your front end configuration, if you have SSL enabled, your bind directive will specify the public IP address and port. If you are using SSL, you will want to add no-sslv3 to the end of this line: ``` frontend name ``` ``` bind public_ip:443 ssl crt /path/to/certs no-sslv3 ``` Save and close the file. Restart to implement the changes: ``` sudo service haproxy restart ``` ## OpenVPN VPN Server Recent versions of OpenVPN don’t allow SSLv3. The service is not vulnerable to this specific problem, so you will need to adjust your configuration. ## Postfix SMTP Server If your Postfix configuration is set up to require encryption, it will use a directive calledsmtpd_tls_mandatory_protocols. You can find this in the main Postfix configuration file: ``` sudo nano /etc/postfix/main.cf ``` For a Postfix server set up to use encryption at all times, you can ensure that SSLv3 and SSLv2 are not accepted by setting this parameter. If you do not force encryption, you do not have to do anything: ``` smtpd_tls_mandatory_protocols=!SSLv2, !SSLv3 ``` Save your configuration. Restart to implement changes: ``` sudo service postfix restart ``` ## Dovecot IMAP and POP3 Server In order to disable SSLv3 on a Dovecot server, you will need to adjust a directive called ssl_protocols. Depending on your distributions packaging methods, SSL configurations may be kept in an alternate configuration file. For most Distros, you can adjust this directive by opening this file: ``` sudo nano /etc/dovecot/conf.d/10-ssl.conf ``` If you are using Dovecot 2.1 or higher, set the ssl_protocols directive to disable SSLv2 and SSLv3: ``` ssl_protocols = !SSLv3 !SSLv2 ``` If you are using a version of Dovecot lower than 2.1, you can set the ssl_cipher_list to disallow SSLv3 like this: ``` ssl_cipher_list = ALL:!LOW:!SSLv2:!EXP:!aNULL:!SSLv3 ``` Save and close the file. Restart in order to save changes: ``` sudo service dovecot restart ``` ## Additional Steps You Can Take You should always update any client applications. Most importantly, web browsers may be vulnerable to this issue because of their step down protocol negotiation. Ensure that your browsers do not allow SSLv3 as an acceptable encryption method. This may be adjustable in the settings or in the installation of an additional plugin. Learn more about Atlantic.Net’s hosting solutions, including [HIPAA compliant disaster recovery](https://www.atlantic.net/disaster-recovery/) services. --- # How to: Linux General – Basic IPTables via Command Line > URL: https://www.atlantic.net/vps-hosting/how-to-linux-general-basic-iptables/ | Published: 2015-02-05 | Updated: 2026-03-03 | Author: Atlantic.Net NOC ##### Verified and Tested 02/16/2015 ### Introduction A basic guide to securing access to your server with iptables. ### Prerequisites Server running CentOS 6.5 or earlier (these instructions could also work under other distributions of Linux, though with slight changes based on the distribution; this article will work from CentOS 6.5) If you do not have a server already, consider firing up a [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net iptables installed ## Starting with basic IPTables via Command Line First, let’s verify that iptables is installed and active (all of these commands will require root privileges, so ensure that your user has access to these privileges–or, if you’d prefer, elevate to root and obviate the need to preface all of your commands with ‘sudo’) ``` sudo service iptables status ``` ![Iptables status output](https://www.atlantic.net/wp-content/uploads/2018/01/linux1-1.png) service iptables status For this new server, iptables is not running, so it’s currently allowing all traffic in. Not good. Let’s fix that. To cover some basics, we’ll be setting the default behavior to drop all traffic and allow only certain traffic in (this is a security practice often called “whitelisting”). We’ll first do it all on the command line, and then we’ll set it up so those rules are persistent across reboots. First, let’s start the service and then check to see what’s running. ``` sudo service iptables start ``` ``` sudo service iptables status ``` ![anet - Basic IPTables - 2](https://www.atlantic.net/wp-content/uploads/2018/01/linux2-1.png) Note that the default policy in each of these chains is to accept traffic. Let’s change the default for INPUT to drop traffic. (WARNING: be sure you have at least one ACCEPT rule in the INPUT chain to allow either your workstation IP address or port 22 if you are accessing this server remotely over ssh. In the above output of the iptables status, note that TCP traffic to port 22 (“tcp dpt:22”) is accepted. If that rule weren’t there, we could lock ourselves out of this server!) ``` sudo iptables -P INPUT DROP ``` The ‘**-P**‘ indicates that we will be making a change to the overall policy, ‘**INPUT**‘ is the particular chain to edit, and ‘**DROP**‘ is the default policy target. ![anet - Basic IPTables - 3](https://www.atlantic.net/wp-content/uploads/2018/01/linux3-1.png) Now, let’s add some specific rules. First, we’ll allow access for HTTP and HTTPS traffic, which we’ll want accessible from any IP address. When adding rules to iptables, it’s important to pay attention to the order of those rules since iptables parses rules in order and will process traffic according to the target indicated in the rule and then exit the chain (in most cases). In the output above, note that the last rule will reject traffic. If we append an allow rule to the end of this chain, it will never be invoked, since the reject rule above it will reject the traffic and stop processing any following rules in the INPUT chain. So, let’s find out which at which line number we want to insert our new rule: ``` sudo iptables -nL INPUT --line-numbers ``` ![Running Iptables status](https://www.atlantic.net/wp-content/uploads/2018/01/linux4-1.png) Iptables status The ‘**-nL**‘ combines a couple of flags: ‘**n**‘ skips DNS resolution (so we can see which IPs each rule examines); ‘**L**‘ lists each rule in the indicated chain. The final option, ‘**–line-numbers**‘, appropriately enough, adds line numbers to each rule entry. (This output is similar to what you could get with ‘**sudo service iptables status**‘, but that command provides the rules for all chains, whereas the ‘**iptables**‘ command above gives us the means to narrow down the scope of the output by individual chain.) In this case, we’ll insert our rules just above the reject rule: ``` sudo iptables -I INPUT 5 -m tcp -p tcp --dport 80 -j ACCEPT ``` ``` sudo iptables -I INPUT 6 -m tcp -p tcp --dport 443 -j ACCEPT ``` ![Iptables list with line numbers](https://www.atlantic.net/wp-content/uploads/2018/01/linux5-1.png) Iptables list with line numbers What does all this mean? * ‘**-I**‘ indicates that we will be inserting this rule at the indicated line number (the number following the name of the chain within which we are inserting the rule). * ‘**-m tcp -p tcp –dport 80**‘ specifies that this rule will match TCP packets arriving in with a destination port of 80 (or 443, in the case of the second rule). * ‘**-j ACCEPT**‘ indicates that, if this rule is matched, then “jump” this packet to the ACCEPT target (which is the long way of saying it’s allowed through).   Note that once we enter the first command, the reject rule would be pushed down to line number 6, so that’s why the second rule inserts itself on line number 6.   Now, let’s add a rule to allow access from a particular IP, regardless of type of traffic or port. ``` sudo iptables -I INPUT 4 -s 192.168.0.1 -j ACCEPT ``` Here we’re inserting this rule just above the rule allowing all ssh traffic on line 4. The ‘**-s**‘ specifies source IP. We could just as easily have allowed a source IP range using CIDR notation as well, so to allow the entire 192.168.0.0/24 range: ``` sudo iptables -I INPUT 4 -s 192.168.0.0/24 -j ACCEPT ``` We could make this rule more specific–say we only want to be able to ssh into this server from that 192.168.0.1 address. Let’s also go ahead and throw in a comment! ``` sudo iptables -R INPUT 4 -s 192.168.0.1 -m tcp -p tcp --dport 22 -j ACCEPT -m comment --comment "Only home workstation can ssh in" ``` First, since this rule will replace our earlier on, note the ‘**-R**‘–this means ‘replace’ on the indicated line number instead of insert. This rule combines checking for source IP and destination port, so in order for it to allow traffic, we’ll have to match both. The final match option for the comment is optional, but it can be very helpful when listing iptables rules to indicate briefly why that rule is in place–which can be super helpful when your iptables rules get more involved, or when there are rules that aren’t immediately self-evident when listed (such as the one for the loopback interface, which I’d added the comment for earlier).   We could, at this point, remove the rule allowing any IP to access this server via ssh: ``` sudo iptables –D INPUT 5 ``` (The ‘**-D**’ specifies that the indicated line number in this chain will be deleted.) Once are done adding rules, be sure to save: ``` sudo service iptables save ``` This will save your currently running iptables rules in /etc/sysconfig/iptables so that, the next time you restart your server, it will automatically load the rules you’ve spent the time entering here. If you want to edit your iptables file with more descriptive comments (or manage a larger, more intricate set of firewall rules), see the article on [Basic IPTables File Configuration](https://www.atlantic.net/vps-hosting/how-to-basic-iptables-file-configuration/). --- # How to Install Nginx on Ubuntu 14.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-nginx-ubuntu-14-04-2/ | Published: 2015-02-05 | Updated: 2026-03-03 | Author: Jose Velazquez ### Introduction This how-to will help you with your Ubuntu 14.04 installation, so that you can successfully run a great performance based web server while easing the load of your system resources. Nginx is a powerful web server software that can be used on your server. It is also known for its high performance and low memory usage which will allow fewer resources to be used but getting the job done efficiently. ### What Do You Need? You need a Ubuntu 14.04 server that is configured with a static IP address. If you do not have a server already, you can visit our [VPS Hosting](https://www.atlantic.net/vps-hosting/) page and spin a new server up in under 30 seconds. ### Server Preparation To get started, log in to your Ubuntu 15.4 via SSH or the VNC Console in cloud.atlantic.net. Atlantic.Net Cloud servers are setup as minimal installations in order to avoid having unnecessary packages from being installed and never used.  Because of this, let’s make sure that your server is fully up-to-date. ``` sudo apt-get update ``` With the server up-to-date, we can continue the installation process of your server. ## Install Nginx In order to install Nginx, we will need to use the apt-get  command so we can install the software: ``` sudo apt-get install nginx ``` You will now have NGINX installed on your server and this can be verified typing in the following with your IP ADDRESS on your browser (http://YOUR.IP.ADD.RESS ). Your IP can be retrieved from the server following command: ``` ifconfig eth0 | grep inet | awk '{ print $2 }' ``` ![This is the default webpage when installing Nginx on Ubuntu 14.04](https://www.atlantic.net/wp-content/uploads/2018/01/How-to-Install-NGINX-on-Ubuntu-14.04-1.png) This is the default webpage when installing Nginx on Ubuntu 14.04 ## What Next? You now have a web server with Nginx installed, and you may now begin building high performance websites using your newly installed web server. Thank you for following along in this How-To and feel free to check back with us for any new updates soon! --- # How to Set Up Apache Virtual Hosts on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-set-apache-virtual-hosts-ubuntu-20-04/ | Published: 2015-02-05 | Updated: 2026-03-03 | Author: Michael Douse ##### Verified and Tested 03/10/21 ### Introduction In this article, we will go over how to add additional virtual hosts to a Linux cloud server with Apache installed. Each virtual host handles a specific website or domain that will be hosted on the server, including sub-domains. This is referred to as named-based hosting because it allows multiple websites to utilize one set of resources, such as a single IP. ### Prerequisites This article assumes that you have already installed Apache and performed the basic configuration of it. If you have not done so,[follow our how-to on this here](https://www.atlantic.net/vps-hosting/how-to-install-apache-ubuntu-20-04/). ## Setting up Apache Virtual Hosts on Ubuntu 20.04 All sites/hosts are located in the following directory: ``` /etc/apache2/sites-available/ ``` If you have just installed Apache, these are the only things you should see: ![Directory: /etc/apache2/sites-available/](https://www.atlantic.net/wp-content/uploads/2018/01/virtual1.png) Directory: /etc/apache2/sites-available/ Create a virtual host configuration file using your preferred text editor. In this example, nano is used. ``` nano /etc/apache2/sites-available/virtualhost.example.conf ``` Add a basic configuration to this file and save: ![Sample Virtual Host configuration](https://www.atlantic.net/wp-content/uploads/2018/01/virtual2.png) Sample Virtual Host configuration Some of the sections you may consider changing are: ``` ``` This is the port that this virtual host will be accessible from. If we were to change 80 to 8080 then we would type the following URL to access the host: *http:// virtualhost.example:8080* ``` ServerName virtualhost.example ``` ``` ServerAlias www.virtualhost.example ``` These values will indicate the domain that this virtual host will be representing and the alternate name for the host. ``` ServerAdmin webmaster@virtualhost.example ``` Update this with your applicable server admin email address. ``` DocumentRoot /var/www/virtualhost.example/public_html ``` This will be the location of the site files for the specified domain. Next enable the virtual host with the following command: ``` a2ensite virtualhost.example.conf ``` Your output should look like this: ![a2ensite sample output](https://www.atlantic.net/wp-content/uploads/2018/01/virtual3.png) a2ensite sample output Lastly, just restart Apache as indicated by the prompt ``` service apache2 reload ``` Congratulations! You have now successfully Set Up Apache Virtual Hosts on Ubuntu 20.04. Thank you for following along and feel free to check back with us for further updates. ## More About Atlantic.Net Atlantic.Net offers world-class hosting solutions, including [VPS hosting](https://www.atlantic.net/vps-hosting/) services. --- # How to Install Your Own VNC Server – Fedora / CentOS > URL: https://www.atlantic.net/vps-hosting/how-to-install-vnc-server-fedora-centos/ | Published: 2015-02-05 | Updated: 2026-03-03 | Author: Michael Douse ##### Verified and Tested 2/4/15 ### Introduction In this guide, we will go over how to install your own VNC server on a Fedora or CentOS [virtual private server](https://www.atlantic.net/vps-hosting/). This will allow you to connect and view common Linux desktop Graphical User Interfaces such as GNOME and KDE. ### Prerequisites A Fedora or CentOS VPS with root permissions. A Desktop Environment (GUI) such as GNOME or KDE ## Installing a VNC server Install the VNC server. In this example, we will use TigerVNC. For information on TigerVNC, visit the following site: [tigervnc.org](http://tigervnc.org/) ``` yum install tigervnc-server -y ``` If using a newer version of Fedora, use the DNF package manager: ``` dnf install tigervnc-server -y ``` `Set the VNC password for root` ``` vncpasswd ``` (Optional) If you want to set the VNC password for another user: ``` su ``` ``` vncpasswd ``` Start the VNC server, create a window (session), and choose output resolution: ``` vncserver :1 -geometry 1024x768 -depth 24 ``` ![vncserver :1 -geometry 1024x768 -depth 24](https://www.atlantic.net/wp-content/uploads/2018/01/fedora1.png) Set Display You can check current active VNC windows with the “vncserver –list” command. ``` vncserver -list ``` ![vncserver -list](https://www.atlantic.net/wp-content/uploads/2018/01/fedora2.png) vncserver -list Try connecting with a VNC client of your choice. Notice I am connecting using the server IP and the VNC window that I declared earlier. ![Sample VNC Viewer](https://www.atlantic.net/wp-content/uploads/2018/01/fedora3.png) Sample VNC Viewer ![Sample VNC Viewer Authentication](https://www.atlantic.net/wp-content/uploads/2018/01/fedora4.png) Sample VNC Viewer ![VNC Viewer Information](https://www.atlantic.net/wp-content/uploads/2018/01/fedora5.png) VNC Viewer Information In this example, I am connected to a private cloud server with GNOME installed. Thank you for following along with this how to install your own VNC server on a Fedora or CentOS cloud server. Learn more about our affordable [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions and be sure to check back with us again for updates and further tutorials, like [Using VNC to Access a Cloud Server](https://www.atlantic.net/hipaa-compliant-hosting/how-to-using-vnc-access-cloud-server/). --- # How to: Atlantic.Net Cloud – Using VNC to Access a Cloud Server > URL: https://www.atlantic.net/hipaa-compliant-hosting/how-to-using-vnc-access-cloud-server/ | Published: 2015-02-05 | Updated: 2026-03-01 | Author: Atlantic.Net NOC ##### Verified and Tested 02/17/2015 ### Introduction Atlantic.Net’s Cloud Servers Administration Interface includes a server management module (“Manage Servers”). You can use the VNC for many reasons, including but not limited to, if your server is not accepting remote connection attempts, networking is disabled or configured incorrectly, or you need to run commands as if connected directly to the servers console. ### Prerequisites You should have an Atlantic.Net account and cloud server that you are trying to VNC to. You should be able to log into the Atlantic.Net Cloud Control Panel at [https://cloud.atlantic.net](https://cloud.atlantic.net/?page=userlogin). ## Using VNC to Access a Cloud Server Once you are logged into the Net Cloud Control Panel, click on the server that you would like to console into. ![Select the server you'd liek to VNC into](https://www.atlantic.net/wp-content/uploads/2018/01/vnc1.png) Your Servers After selecting the server click S**tart console**. ![Select Start Console](https://www.atlantic.net/wp-content/uploads/2018/01/vnc2.png) Console selection It should open a new window/tab. ![Sample VNC Window](https://www.atlantic.net/wp-content/uploads/2018/01/vnc3.png) Sample VNC Window If you are using a Unix-like server and it has an all-black window on the screen, just click on the window and press any key. ![Sample VNC Window](https://www.atlantic.net/wp-content/uploads/2018/01/vnc4.png) Sample VNC Window You will see your cloud servers log in screen and you can log into your server with the credentials that were presented to you at sign up, or whatever the current password is if you have previously requested a password reset or changed it yourself. Learn more about hosting services from Atlantic.Net, including [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/). --- # How to Change the Server Hostname in Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-change-server-hostname-ubuntu/ | Published: 2015-02-05 | Updated: 2026-03-02 | Author: Chelsea Fieler ##### Verified and Tested 02/17/2015 ### Introduction In this article, we discuss how to change your server’s hostname in Ubuntu 12.04 or 14.04. Note: The scope of this article does not extend to updating your [DNS](https://www.atlantic.net/vps-hosting/what-is-dns-and-how-does-it-work/) name, so if you want your server reachable via its DNS name, you will still need to ensure DNS is configured correctly. ## Changing the server Hostname in Ubuntu If you’d like to change your Ubuntu server’s hostname, you’ll need to change it in a few places, the first of which being the /etc/hostname file. Open the /etc/hostname file with your text editor of choice. In this instance, we will be using “vim”. ``` sudo vim /etc/hostname ``` Simply change the name here to the hostname you’d like to use. See below for more information on valid hostnames. This change will take effect the next time you reboot your server. Before you do, however, you may also want to add the hostname to your /etc/hosts file, again with the text editor of your choice. ``` sudo vim /etc/hosts ``` In this instance, we will be changing the old hostname of “bespin” to “endor” at the line for the IP address configured on this server (in this case, 10.5.132.2).   ![Sample: /etc/hosts](https://www.atlantic.net/wp-content/uploads/2018/01/hostname1.png) Sample: /etc/hosts ![Sample: /etc/hosts](https://www.atlantic.net/wp-content/uploads/2018/01/hostname2.png) Sample: /etc/hosts It is possible here that you will have a loopback address (such as 127.0.1.1) instead of a routable address. If this is the case, just edit your hostname on that line instead. At this point, the next time you reboot your server your new hostname will show up in your command prompt. It will also show up by running the command: ``` hostname ``` If you would prefer not to reboot your server, you can instead change the hostname with the following command. In this example, we are changing the hostname to endor: ``` sudo hostname endor ``` ![Hostname command](https://www.atlantic.net/wp-content/uploads/2018/01/hostname3.png) Hostname command You may change the hostname with this command alone, however, the next time you reboot your server it will not persist, and will load whatever hostname is still established in the /etc/hostame file. This change is only temporary. Also, you may notice that the hostname in your command prompt hasn’t changed. In order to update this, simply log out of the current session and log back in. After a new login, the new hostname will show in the command prompt. One other caveat: until you do reboot your server after a hostname change, you may also notice that your logs still use the old hostname. ``` Valid Hostname Restrictions ``` In each of these configurations, you’ll need to be sure your hostname conforms to the standards for FQDNs (Fully Qualified Domain Names). The ASCII letters a – z, the digits 0 – 9, and the hyphen (‘-‘) are the only characters acceptable. The only limitation to this is that the first character cannot be a hyphen. You may also find it necessary or useful to include the domain name as well, in which case you would then use periods (dots) to separate the hostname and the domain name (and top-level domain). So the following would be examples of acceptable hostnames: bespin.the-empire.starwars endor.rebelalliance.starwars The whole hostname should be no more than 255 characters (see RFC1123). Congratulations! You now have a successfully changed the server hostname in Ubuntu. Thank you for following along and feel free to check back with us for further updates or learn more about our reliable [VPS hosting](https://www.atlantic.net/VPS-hosting/) servers. --- # How to Protect Your Server From the Shellshock Bash Bug > URL: https://www.atlantic.net/disaster-recovery/how-to-protect-server-shellshock-bash-bug/ | Published: 2015-02-05 | Updated: 2026-02-28 | Author: Atlantic.Net NOC ##### Verified and Tested 02/17/2015 ### Introduction This guide will cover how to check and fix your server if you are vulnerable to the Shellshock Bash bug. The Shellshock Bash bug effects ‘nix based operating systems, which allows attackers to remotely run commands on the server gaining unauthorized access to the server and further exploiting the server. This guide will show you how to test, and fix your server if it is vulnerable. ## Is My System Vulnerable? Run the following command: ``` env 'VAR=() { :;}; echo Bash is vulnerable!' 'FUNCTION()=() { :;}; echo Bash is vulnerable!' bash -c "echo Bash Test" ``` If you see the following in the output, your system is vulnerable to the Bash bug and it needs to be updated: Bash is vulnerable! Move to “System’s Vulnerable? No Worries.” If you, instead, receive the following output: Bash Test This means, your system is secure and no further work is required. ## System’s Vulnerable? No Worries. The fix is simple, run the following command: In CentOS/Fedora ``` yum update bash ``` In Debian/Ubuntu ``` sudo apt-get update && sudo apt-get install –only-upgrade bash ``` In FreeBSD ``` pkg upgrade bash ``` ## More from Atlantic.Net Learn more about Atlantic.Net’s hosting solutions, including [HIPAA compliant disaster recovery](https://www.atlantic.net/disaster-recovery/) services. --- # How to: Linux General – IPTables in General > URL: https://www.atlantic.net/vps-hosting/how-to-linux-general-iptables-general/ | Published: 2015-02-05 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 02/16/2015 ### Introduction IPTables is a firewall that is either installed already or can be installed onto any of our Linux Distributions for our Cloud service. IPTables is used to configure packet filter rule chains and enforce the built-in or user-defined rule chains for your server. IPTables has main components to it involving *Tables*, *Targets*, and *Options*. ## Tables Tables in IPTables are used to separate packets into their matching category. The table sorting depends on modules that your system has loaded and where the packet matches. Right now, there are five distinct tables for use. They are *filter*, *nat*, *mangle*, *raw*, and *security*. For the most part, basic IPTables use will just involve the *filter* table. If you are doing internal routing or more complicated networking, you will focus on using the other tables as well. This page will be going over only *filter* type rules. *filter* – This is the basic table as was mentioned and is typically the defaulted table. This table consists of the rule chains ACCEPT, FORWARD, OUTPUT. *nat* – This table is used for packets that will be creating new connections. Like routing a public IP to a private IP. It consists of the rule chains PREROUTING, POSTROUTING, and OUTPUT. *mangle* – This table is used for altering the way packets are handled. It consists of the rule chains INPUT, FORWARD, OUTPUT, PREROUTING, and POSTROUTING. *raw* – This table is used for configuring exemptions from connection tracking with the NOTRACK target. It consists of PREROUTING and OUTPUT. *security* – This table is for MAC (Mandatory Access Control) rules. It consists of INPUT, FORWARD, and OUTPUT   ## Targets Targets are defined as the value to the rule chain you are creating. They can contain the values *ACCEPT*, *DROP*, *QUEUE*, or *RETURN*. These values tell the rule how to proceed with a packet that matches the rule. *ACCEPT* – This is pretty straightforward and means to allow the packet through to your server. *DROP* – Also pretty straightforward in that it means to deny the packet through to your server. *QUEUE* – This target means to pass the packet into userspace so a user may define what to do with it. *RETURN* – This target stops the processing of the current chain and tells it to resume processing at the previous chain’s next rule.   ## Options There is a ton of options available for IPTables use. We will list some of the more common ones you will see. -A, –append – Appends your rule to a chain. -L, –list [chain] – This will list all the rules in the chain that you specify. If you don’t supply a chain, it will list all the rules. -F, –flush [chain] – This will remove any chains and rules in the given chain. If you don’t provide a chain, it will remove all rules and chains currently running. -h – This provides an output of all the options that you may do. -p, –protocol *protocol*– This is the packets protocol. These can be TCP, UDP, UDPlite, ICMP, ESP, AH, SCTP, all, number equivalents to these, or begin with a ! to invert the protocol check. -s, –source address[/mask][,…] – A source address. Can be the IP, IP range via netmask, network name, or hostname. -d, –destination address[/mask][,…] – A destination address. Same format as –s. -m, –match *match* – An extension module that tests for a property. –dport[s] [*port#*][,…] – A port you are looking for. –dports is used to specify more than one which are separated by comma. When using –dports make sure to set -m as multiport. To specify a port range, use a : such as 1000:1100 which would be ports 1000-1100. -j, –jump target – This is the option that allows you to specify the target for your rule. -i, –in-interface name – Specifies an interface that the packet should be received on. -o, –out-interface name – Specifies an interface that the packet will leave on. -v, –verbose – It makes the list command show interface names, rule options, and any masks. Also shows packet and byte counters.   ## Usage and Examples Here we will show some basic usage and examples. A typical IPTables rule will tend to follow these formats. Make sure all your rules are done above COMMIT as this is used to end a table. Rules for another table will follow their own end COMMIT. For allow established traffic: -A INPUT -m *match* –state ESTABLISHED,RELATED -j ACCEPT In use this would be: -A INPUT -m state –state ESTABLISHED,RELATED -j ACCEPT For allowing specific port[s]. -A INPUT -p *protocol* -m *match* –dport *port* -j ACCEPT In use, an example would be: -A INPUT -p tcp -m tcp –dport 80 -j ACCEPT Or -A INPUT -p tcp -m multiport –dports 80,443 -j ACCEPT This would allow web traffic through on port 80 (in the second example, port 443 too.) That’s not all you can do. You can also add the following like in the below examples. -A INPUT -s *IPADDR* -p tcp -m tcp –dport 22 -j ACCEPT This allows only the IP address (*IPADDR*) that you specify through on your port 22 (ssh.) You can use any form of IP addresses that the -s option allows. -A INPUT -p tcp -m tcp –dport 22 -j DROP Following in step with the above example, this will drop any and all TCP traffic traveling to you SSH port. It is a good rule of thumb to always have any DROP rules at the very bottom of your list of ACCEPT rules in the chain. For example: -A INPUT … -j ACCEPT -A INPUT … -j ACCEPT -A INPUT … -j ACCEPT -A INPUT … -j DROP -A FORWARD … -j ACCEPT -A FORWARD … -j ACCEPT -A FORWARD … -j ACCEPT -A FORWARD … -j DROP -A OUTPUT … -j ACCEPT -A OUTPUT … -j ACCEPT -A OUTPUT … -j ACCEPT -A OUTPUT … -j DROP You can also define the targets (like ACCEPT or DROP) up at the top of your IPTables for default behavior. When it’s a new install of IPTables, you always see the default behavior (defined at the top where it lists INPUT, FORWARD, and OUTPUT) as ACCEPT. A good rule of thumb for security is to change it to DROP and only make rules for the ports or traffic that you want to allow. Only change it though if you are sure you have made the exceptions you need. Also at the top of a table, you can define your own targets. Let’s say you have the following at the top of your IPTables: *filter :INPUT DROP [0:0] :FORWARD DROP [0:0] :OUTPUT DROP [0:0] COMMIT Now, as we have blocked everything, let’s start with adding our own targets like: *filter :INPUT DROP [0:0] :FORWARD DROP [0:0] :OUTPUT DROP [0:0] :APP – [0:0] :MyNewTarget – [0:0] COMMIT Now you can create a custom type rule chain like the below. *filter :INPUT DROP [0:0] :FORWARD DROP [0:0] :OUTPUT DROP [0:0] :APP – [0:0] :MyNewTarget – [0:0]   -A APP -p tcp -m multiport –dports 30:40,50:80 -j ACCEPT -A INPUT -s *IPADDR* -j MyNewTarget   -A MyNewTarget -j APP COMMIT Now what we have done in the above is create new targets, APP and MyNewTarget and assign to them options and targets. What the last rule (above COMMIT) does, is if the connection comes from your source IP and is attempting to hit ports 30-40 or 50-80, allow it through! It’s all defined in the chain above. This level of customization isn’t truly needed unless you are using multiple hosts or using ports you find yourself repeating and want more of a shorthand or “shortcut” to writing out rules. For example, any new rule you need coming from that source IP, you can now just use MyNewTarget. All in all, IPTables provides a lot of customization of rules and allows you to handle how your server handles incoming, outgoing, and internal traffic. Some rules can be confusing and hard to follow, but there is no doubt to the helpfulness they provide to server stability. --- # How to Limit Root User in CentOS > URL: https://www.atlantic.net/vps-hosting/how-to-limit-root-user-centos/ | Published: 2015-02-05 | Updated: 2026-03-03 | Author: Jason Mazzota ##### Verified and Tested 02/04/2015 ### Introduction What we’ll be doing in this tutorial is making it so that you can no longer SSH using your root user. This is done on a fresh install of CentOS 6.5 64bit in our Cloud. We will be making a new user on the server to use as our new SSH user, and we will be setting the user up to be a sudo access user. In other words, the new user will be able to access commands as if it were the root user! ## Limiting Root user in CentOS First, we will want to SSH into our server as the root user using your preferred SSH client. Now what we will want to do is run the below command to make a new user and their home directory. ``` useradd newusername –d /home/newusername ``` You will want to change newusername to be the new user that you wish to create. After running this, you will need to create a password for the user. You can do this by running: ``` passwd newusername ``` note* Remember to always use strong passwords* Where newusername is the new user you are creating. Now we will want to edit our sudoers file so that our new user can run commands like the root user. ``` visudo ``` In your sudoers file, you will need to locate the area that has the below information. This is where we will be adding our new user’s rights. In the picture below, it is the location under the green indicator. ![Sample Visudo Output](https://www.atlantic.net/wp-content/uploads/2018/01/centos1-3.png) Sample Visudo Output Right under the root entry, you will want to make the entry: ``` newusername ALL=(ALL) ALL ``` Here “newusername” is your new user. If you don’t know how to edit in vi, you will want to (on your keyboard) hit the Insert button. Then go to the location to add the new user information and type it out. When you are done hit the ESC key on your keyboard and then do “:wq!” to save your changes. Now the next thing to do… is test the new user! The best way to do this is to either log out or create a new SSH session using that new username and password to log in. Once you log in successfully, we can test your sudo access by going into the SSHD configuration file as the new user. This is because we still have one more change to do to prevent root log in. You can use your favorite editor for this part, we are using vi. note*To use other commands on the server “as root” you will need to preface it with sudo.* ``` sudo vi /etc/ssh/sshd_config ``` This command will open the SSHD configuration file like you are the root user. You will want to locate the “PermiteRootLogin” option indicated by the green indictor in this picture. ![Comment out PermitRootLogin sshd_config](https://www.atlantic.net/wp-content/uploads/2018/01/centos2-3.png) sshd_config You will want to remove the ‘#’ and change yes to no. In the end, the line should look like ``` PermitRootLogin no ``` Once done, save and exit the file. Then run: ``` sudo service sshd restart ``` You will now be unable to SSH to your server as the root user. --- # How to: Securing your Ubuntu or Debian Server with IPTables > URL: https://www.atlantic.net/vps-hosting/how-to-securing-ubuntu-debian-server-iptables/ | Published: 2015-02-05 | Updated: 2024-06-06 | Author: Jason Mazzota ### Introduction In this tutorial, we will be covering how to perform some basic IPTables changes that will greatly help secure your server. This is done on a fresh install of Ubuntu 14.04 64bit in our Cloud. This can also be done on any version of our Ubuntu 12.04 OS as well as Debian. All of our commands are run as root and file editing is done via vi. If you are using another user to do this, you will need sudo access. You may use any file editor you would like. ## Securing your Cloud server with IPTables Unfortunately, our Ubuntu 14.04 or 12.04 do not come with IPTables installed already. In Debian, IPTables is already installed so you may skip this. So our first step with Ubuntu is to install IPTables. To do this, simply run: ``` apt-get install iptables ``` After installing IPTables, you can check it out by running: ``` iptables –L ``` This will list out any rules you have running and verifies for you that you did install iptables and it is working. At this time, it’s just empty but you can see the three types of chains available. Next, we will install the iptables-persistent package. What this does is it will write out our current IPTables rules to a new file (/etc/iptables/rules.v4) and it will handle automatically applying our rules upon reboot. Pretty helpful! ![Sample: /etc/iptables/rules.v4](https://www.atlantic.net/wp-content/uploads/2015/02/iptables1.png) /etc/iptables/rules.v4 When you enter the file, it should look like the above picture. There are a few things that we will want to add before our first custom rule. This would be a rule for the loopback interface and one for traffic that is already established. You can see these below. The first custom rule we are going to add will allow SSH access to our server. We’ll want to add the rules above the COMMIT line as COMMIT delimits the end of our INPUT, FORWARD, and OUTPUT ruleset. To find out what all the IPTables segments mean and more information about them, please see our IPTables section. ``` -A INPUT -i lo -j ACCEPT ``` ``` -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT ``` ``` -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT ``` Note: If you have a custom SSH port like we set up in the Changing your SSH Port in Ubuntu tutorial, you will have to change the 22 to be your SSH port you configured. In our case 3389 ![Sample: /etc/iptables/rules.v4](https://www.atlantic.net/wp-content/uploads/2015/02/iptables2.png) /etc/iptables/rules.v4 Your rules should look similar to the above picture. Now before we finish here, there’s two more things we have to change. Where the rules say: ``` :INPUT ACCEPT and :FORWARD ACCEPT ``` We will want to make them have: ``` :INPUT DROP and :FORWARD DROP ``` What this does is it tells IPTables to block and drop all traffic that is not going to ports you specify to allow through. This will stop people trying to break in using services that you have running unless you have opened those ports to the public. When you’re finished, it should look similar to the above. Once there, just save the file and close it. The last thing we have to do is load these new rules into the current IPTables. To do this, you simply run: ``` iptables-restore < /etc/iptables/rules.v4 ``` To verify our rules are in place, simply run the same command from earlier: ``` iptables –L ``` You should see something similar to the below page. ![Sample: /etc/iptables/rules.v4](https://www.atlantic.net/wp-content/uploads/2015/02/iptables3.png) /etc/iptables/rules.v4 After this, that’s it! Your new rules are in effect immediately, and they’ll remain through reboots. If you want to get more restrictive with your IPtables, specifically access to SSH, you can do the following for each IP address that should be allowed through. This involves editing the SSH rule and adding more. Where it states the SSH rule we identified earlier, you want to change it to be: ``` -A INPUT -s IPADDR –m tcp –p tcp --dport 3389 –j ACCEPT ``` Where IPADDR is your IP address that you want to have SSH access to your server. If you did not set up a custom SSH port, you would want that to remain 22 and not 3389. To allow specific ports through say for web access to your website, all you need to do is know/find the port the service runs on (or you configured it on) and it’s protocol (TCP or UDP) and allow it through. For example, website access: ``` -A INPUT -m tcp -p tcp --dport 80 -j ACCEPT ``` And now the Internet has access to the web hosting you are doing. Keep in mind, when adding new rules to either INPUT or FORWARD sections, it is a great practice to keep the new rules lumped together with like rules. INPUTs with INPUTs and FORWARDs with FORWARDs. You will also want to make sure that any rules you add that allow a new port through are listed ABOVE any reject statements for that rule set. If they are listed after any reject lines, the rules will not take effect. To see output of what IPTables is doing and/or blocking with its rules, you can run the below. It will print out the rules you have and anything packet wise about dropping connections or allowing them through. ``` iptables -L -vn ``` To find out what all the IPTables segments mean and more information about them, please see our IPTables section (link). **Note: If using Atlantic.Net Cloud Services, You can always access your server via our VNC viewer in the Cloud Portal if you lock yourself out.** --- # How to Add a Swap File on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-add-swap-file-ubuntu-20-04/ | Published: 2015-02-05 | Updated: 2026-03-02 | Author: Kristopher Fieler ### Introduction In this article, we will go over how to create a swap file. A swap file is useful in instances where your cloud server does not have enough memory to perform the tasks or processes that are running. This can cause your server to start killing processes in order to free up some memory, some of which may be important such as a database or a web server! A swap file can help you avoid these issues by utilizing hard drive space as virtual memory when regular memory is not immediately available. ## Adding a Swap file on Ubuntu 20.04 We must first make sure that there is no current swap file in use. The easiest way to determine this is to run the following command: ``` free -m ``` Output: ``` total used free shared buffers cached Mem: 3834 3448 385 681 173 1424 ``` The output will show us how much memory the system has and how much, if any, the swap has been configured. In this case, the server has just been provisioned, and no swap has been configured. In the next step, we will choose the amount of space to allocate to swap. This can be accomplished by the following command: ``` dd if=/dev/zero of=/swapfile bs=1024 count=2048k ``` In this example, we will create a 2GB swap file. There are 1024 megabytes in 1 gigabyte, so in order to achieve 2GB, I will be using 2048k as the count. **NOTE**: Do not forget to include the “k” at the end, otherwise you will actually be creating a 2-megabyte swap file! This is because the byte size is being multiplied by the amount specified in the count block. Now we must assign the swap file we just created to the operating system: ``` mkswap /swapfile ``` ![mkswap /swapfile](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu3.png) mkswap /swapfile Enable the swap file and verify it is assigned: ``` swapon /swapfile free -m ``` Output: ``` total used free shared buffers cached Mem: 3834 3448 385 681 173 1424 Swap: 2017 0 2017 The output of “free -m” should now show the amount you configured for swap. Next, we need to configure the system to enable the swap file every time the server boots. Otherwise, you would need to manually enable it every time you reboot the server using the “swapon /swapfile” command. To accomplish this we will need to edit the /etc/fstab file using a text editor of your choice. Add the following line to the end of the file: ``` ``` /swapfile none swap sw 0 0 ``` ![/swapfile none swap sw 0 0](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu5.png) /swapfile none swap sw 0 0 Once this has been completed, save your changes and close the file. After this is completed, you will still need to set the “swappiness.” By default, most Linux deployments have swappiness default to 60. This means that if 40% of RAM is used and 60% is unused, the swap file will be used. Since our cloud servers are all on SSD, our default swappiness is set to 0. What this means is that if 100% of all RAM is used, then and only then does the swap file gets used. Run the command: ``` nano /etc/sysctl.conf ``` Then change or add this line: ``` vm.swappiness = 10 ``` If you need a slightly higher swap, you can play with this number. Try not to go higher than 20 or 30. We recommend swappiness be set low for multiple reasons. The first reason we recommend a low swappiness is that using it too aggressively will reduce the lifespan of the SSDs. The other reason is that if swappiness is set too high, the system uses the swap file too often. This can cause system input/output conflicts as the server is too busy swapping things in and out of the swap file, rather than using the RAM properly. On occasion, this can slow down the server more than a lack of RAM. Then you need to restart the swap file to take effect with the new settings. You can either reboot the server or run: ``` swapoff -a ``` and ``` swapon -a ``` That’s it! You now have a persistent swap file for your cloud server. *Note –These commands will work in a CentOS deployment as well* --- # How to use IPTables Instead of firewalld for Fedora 30-31-32 > URL: https://www.atlantic.net/vps-hosting/how-to-use-iptables-instead-firewalld-fedora-30-31-32/ | Published: 2015-02-05 | Updated: 2026-03-03 | Author: Michael Douse ##### Verified and Tested 03/10/21 ### Introduction As of Fedora 18, the iptables service has been replaced by firewalld. For those that prefer managing static firewall rules with iptables, follow these steps to revert back to iptables. ## Using IPTables instead of firewalld Disable firewalld and stop the service with the following commands: ``` systemctl disable firewalld ``` ``` systemctl stop firewalld ``` --- Now install the iptables-services package: ``` dnf install iptables-services -y ``` Enable iptables and start the service: ``` touch /etc/sysconfig/iptables ``` ``` systemctl start iptables ``` ``` systemctl enable iptables ``` --- Check to make sure iptables is now running: ``` systemctl status iptables ``` Your output should look like this: ![](https://www.atlantic.net/wp-content/uploads/2015/02/fedora-iptable-status.png) You’re finished! Now start adding your rules to the /etc/sysconfig/iptables file. Thank you for reading! [Check out some of the related articles here or below](https://www.atlantic.net/blog/) and thanks for trying our reliable [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions at Atlantic.Net. --- # How to: Resetting a Atlantic.Net Cloud Server Password > URL: https://www.atlantic.net/vps-hosting/how-to-resetting-atlantic-net-cloud-server-password/ | Published: 2015-02-05 | Updated: 2026-03-03 | Author: Atlantic.Net NOC ##### Verified and Tested 2/17/15 ### Introduction This is how to use the Atlantic.Net Cloud Control Panel to reset your Cloud server password. ### Prerequisites You should have an Atlantic.Net account and [virtual private server](https://www.atlantic.net/vps-hosting/)that you are trying to connect to. You should be able to log into the Atlantic.Net Cloud Control Panel at [https://cloud.atlantic.net](https://cloud.atlantic.net/?page=signup). ## Resetting your Cloud Server Password Once you are logged into the Net Cloud Control Panel, you should see your server list. Click on the name of the server that needs the password reset completed on. ![Select your server](https://www.atlantic.net/wp-content/uploads/2018/01/reset1.png) Select your server Find the row of icons towards the top of the Net Cloud Control Panel, and click on the Reset Password button. ![Select Reset Password from your servers menu](https://www.atlantic.net/wp-content/uploads/2018/01/reset2.png) Reset Password Read the message on the pop-up. If this applies to what you need, click Reset Password. ![Confirm Reset Password](https://www.atlantic.net/wp-content/uploads/2018/01/reset3.png) Confirm Reset Password Your new password will be displayed on the screen. ![New Password output](https://www.atlantic.net/wp-content/uploads/2018/01/reset4.png) New Password output --- # Atlantic.Net Cloud – How to Soft or Hard Reboot a Atlantic.Net Cloud Server > URL: https://www.atlantic.net/vps-hosting/atlantic-net-cloud-how-to-soft-or-hard-reboot-a-atlantic-net-cloud-server/ | Published: 2015-02-06 | Updated: 2026-03-02 | Author: Alexander Wise ##### Verified and Tested 02/17/2015 ## Introduction If you ever need a server rebooted because it locked up on you or you want to turn it off until it is time for it to go into production, you need to know how to use the Atlantic.Net Cloud Control Panel reboot feature. The reboot feature will allow you to hard reboot your server in the instance where you have powered the server off, and when it is not responsive to remote or local actions. The reboot feature will allow you to soft reboot you server which is designed to issue a clean shutdown to the server and restart it. If the server was unresponsive the soft reboot will not be able to restart the server and you will need to issue a hard reboot to bring it back online. ## Prerequisites You should have an Atlantic.Net account and Cloud server that you would like to reboot. You should be able to log into the Atlantic.Net Cloud Control Panel at [http://cloud.atlantic.net](https://cloud.atlantic.net/?page=userlogin). ## Rebooting your Cloud Server Once you are logged into the Net Cloud Control Panel, click on Servers in the menu. ![Anet Cloud Reboot](https://www.atlantic.net/wp-content/uploads/2021/03/anet-cloud-reboot-main.png) Sample Servers Menu   Click on the name of the server that you would like to reboot. ![](https://www.atlantic.net/wp-content/uploads/2021/03/anet-cloud-reboot-main-select.png) Select Server Find the row of icons towards the top of the Atlantic.Net Cloud Control Panel, and click on the Reboot button. ![](https://www.atlantic.net/wp-content/uploads/2021/03/anet-cloud-reboot-main-select-reboot.png) Select Reboot Choose the method of reboot you would like to perform. ![](https://www.atlantic.net/wp-content/uploads/2021/03/anet-cloud-reboot-main-select-reboot-confirm.png) Select hard or soft option Here is the outcome of a soft reboot. ![](https://www.atlantic.net/wp-content/uploads/2021/03/anet-cloud-reboot-notification.png) Sample soft reboot Here is the outcome of a hard reboot. ![](https://www.atlantic.net/wp-content/uploads/2021/03/anet-cloud-reboot-confirmation-02.png) Sample hard reboot Wait until the server status returns to Provisioned before attempting to reconnect or test your server. ![](https://www.atlantic.net/wp-content/uploads/2021/03/anet-cloud-reboot-01.png) Server Status --- # How to Lock Down Your Linux Cloud Server > URL: https://www.atlantic.net/hipaa-compliant-hosting/how-to-lock-linux-cloud-server-vps/ | Published: 2015-02-06 | Updated: 2026-03-01 | Author: Jason Mazzota ##### Verified and Tested 02/05/15 ### Introduction This tutorial will provide you some basic steps to help you lock down and secure your cloud Linux server with Atlantic.Net. By no means do these steps have to be used in order nor do you have to use all of the steps. They are recommendations on securing your server through simple means that take just a little of your time to set up or configure. ### Prerequisites For this tutorial, all that’s pre-required is that you have a Linux private cloud hosting with Atlantic.Net. ## Securing your Linux Cloud server **Changing the SSH Port** [Changing your SSH Port in CentOS](https://www.atlantic.net/vps-hosting/how-to-change-ssh-port-centos/) [Changing your SSH Port in Ubuntu and Debian](https://www.atlantic.net/vps-hosting/how-to-change-ssh-port-ubuntu-debian/)   **Let’s Limit the *root* User** [Limiting Your root User in CentOS](https://www.atlantic.net/vps-hosting/how-to-limit-root-user-centos/) [Limiting Your root User in Ubuntu and Debian](https://www.atlantic.net/vps-hosting/how-to-limit-root-user-access-debian-ubuntu/)   **IPTables** [Locking down your CentOS server with IPTables](https://www.atlantic.net/vps-hosting/how-to-lock-centos-server-iptables/) [Locking down your Ubuntu or Debian server with IPTables](https://www.atlantic.net/vps-hosting/how-to-securing-ubuntu-debian-server-iptables/) [IPTables in General](https://www.atlantic.net/vps-hosting/how-to-linux-general-iptables-general/)   **Let’s get those Brute Forcers! Using fail2ban** [Basic Use of fail2ban in CentOS](https://www.atlantic.net/dedicated-server-hosting/how-to-install-configure-fail2ban-centos/) [Basic Use of fail2ban in Ubuntu and Debian](https://www.atlantic.net/vps-hosting/how-to-install-fail2ban-ubuntu-debian/)   Learn more about Atlantic.Net’s hosting services, including [HIPAA-complaint cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/). --- # How to Create a pem For Your Existing SSL > URL: https://www.atlantic.net/vps-hosting/how-to-create-pem-existing-ssl/ | Published: 2015-02-06 | Updated: 2026-03-02 | Author: Jason Mazzota ##### Verified and Tested 02/05/15 ### Introduction This tutorial will go over how to create a .pem file for your SSL. These .pem files are for use with SSLs and while you do not need a .pem, some processes are made easier by having them and they allow for simple copy and pasting as they are designed to be safe for ascii or rich-text documents. For this tutorial, you will need an [SSL](https://www.atlantic.net/vps-hosting/what-is-ssl-certificate/), self-signed or Certified by another source, the Intermediate and/or Root CA (if Certified), and the SSL key file. We will also be using OpenSSL. ## Creating a pem for your existing SSL Creating a .pem is very simple. If you did not generate your key file for your SSL as a .pem to begin with, you could do so by running the following type of command. You will need to know what format you created your key file in. These can also be used on any part of your SSL files if you need to do conversion. DER to PEM ``` openssl x509 –inform der –in yourSSLFile.der –out yourSSLFile.pem ``` P7B to PEM ``` openssl pkcs7 –print_certs –in yourSSLFile.p7b –out yourSSLFile.pem ``` PFX to PEM ``` openssl pkcs12 –in yourSSLFile.p12 (or .pfx) –out yourSSLFile.pem ``` Now if you generated your key as a RSA value, you’re in luck and don’t need to perform any conversion. The only thing you may wish to do is strip the passphrase or password out of it and for that you may see the page. Your SSL (if you have it from a certified source) should come with an Intermediate and/or Root CA. You can actually download it from your certified source in the .pem format. If your SSL file is a .crt or .cert then it’s likely you don’t have to do any conversion. You can try the below to be sure if you do not know: ``` openssl x509 -in yourSSL.crt -out yourSSL.pem ``` If this fails, your .crt or .cert file is a different format (likely a DER) and you can use the method described above in the key section to convert it to a .pem. Now you can combine them all as a .pem file if you’d like or you can simply pick and choose which you’d like to combine. Since the formats are designed to be easy to use, there’s a few ways to combine them. You can simply create a new master .pem file and then open each of your .pem files and copy and paste them in the new master .pem file or cat them all into a single file. Keep in mind that some applications or software will want separate files for the SSL or key or even the Intermediate/Root CAs (like Apache.) ``` cat /path/to/SSLkey.pem /path/to/SSL.pem /path/to/Intermediate.pem /path/to/Root.pem > /path/to/master.pem ``` If you do choose the path to copy and paste, make sure you are grabbing everything (yes, even the —-BEGIN and ——END sections.) Congratulations you have created a .pem file for your SSL. We hope this article assisted you with the process. Thank you for following this How-To, check back for updates or learn more about our reliable [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions.   --- # How to: Basic IPTables File Configuration > URL: https://www.atlantic.net/vps-hosting/how-to-basic-iptables-file-configuration/ | Published: 2015-02-07 | Updated: 2026-03-02 | Author: Atlantic.Net NOC ##### Verified and Tested 02/07/2015 ### Introduction This article will discuss configuring iptables via the /etc/sysconfig/iptables file, which can be useful if you have an intricate set of rules to keep track of or if you’d prefer not to have to deal with all the flags and options involved with configuring iptables via the command line. ## Basic IPTables File Configuration One of the primary benefits of manually configuring the iptables file is comments. While you can utilize comments via the match module (‘-m comment –comment’), you can make more extensive use of comments in the iptables file itself using the ‘**#**‘ character at the beginning of the line: ``` # This is a comment and will be ignored when iptables is loaded ``` So we have a point of comparison, let’s take a look at what an iptables files might look like if we save via the **sudo service iptables save** command. ``` sudo service iptables save ``` ![Sample: Service iptables save](https://www.atlantic.net/wp-content/uploads/2018/01/config1.png) Sample: Service iptables save That might be fine when we have this small number of rules, but imagine if we had hundreds of rules to keep track of. It might be difficult for us to parse through those rules without a little commentary to help us remember what the intent of creating those rules was in the first place. So, let’s add a little commentary. Use your text editor of choice to open an editable copy of the iptables file (the following screenshots were taken from vim, but we’ll include nano in the command entry to make things easier for new learners): ``` sudo nano /etc/sysconfig/iptables ``` ![Sample Iptables File with Comments](https://www.atlantic.net/wp-content/uploads/2018/01/config2.png) Iptables File with Comments This is (with one exception) the same file as the one without comments above. If you’re not the sort used to reading through a bunch of iptables rules, this file can be a lot less intimidating (and if your comments are clear enough, they can even remind you how a particularly intricate rule is supposed to work!). The sharp-eyed may have noticed that the ssh rules in this iptables file are a little flimsy, in that the second line (in allowing all ssh traffic in) essentially invalidates the point of the first line specifying that one particular IP is allowed to ssh in. These rules are configured to demonstrate some basic rule formats. In production, you’d likely have a more restrictive set of rules in place. There is one rule change to take note of between the two iptables rules sets. In order to demonstrate another use of the comment character, we’ve added the “**#**” before the **INPUT** rule specifying that we reject traffic that doesn’t match any of the preceding rules and added a new rule that says we should log all traffic before taking the default action for this chain (**DROP**). (More information on logging iptables activity can be found in [this article on basic troubleshooting of iptables](https://www.atlantic.net/vps-hosting/how-to-basic-iptables-troubleshooting/)). Since we’ve only commented out the **REJECT** rule, if we wanted to, we could remove the one “**#**” character to reinstate that rule, instead of having to type it out again. This can be useful while testing various rules or for including a rule you might want to activate in the future or for a limited time. Note that each rule in the /etc/sysconfig/iptables file begins with the ‘**-A**‘ command. If you are familiar with adding using iptables on the command line, you may recognize that these rules look very similar to what follows the **sudo iptables** portion of the command when making iptables changes via the CLI. The ‘**-A**‘ command indicates that the rule should the appended to the end of the indicated chain. Note that no line number is required (as it might be for ‘**-I**‘ or **-R**‘) since ‘**-A**‘, by definition, will add the rule to the end of the list of rules in that chain. This is why the order of rules is important since iptables filters traffic by parsing these rules in the order they fall in the chain. Once you have completed any edits you want to make to this file and saved it, you’ll need to load the new rules. The simplest way to ensure that all changes are loaded is to restart the iptables service. This action will flush all current iptables rules running and then reload the rules as they currently exist in the /etc/sysconfig/iptables file. ``` sudo service iptables restart ``` ![Sample Service iptables restart Output](https://www.atlantic.net/wp-content/uploads/2018/01/config3.png) Service iptables restart Output Now, let’s add a new rule, and we’ll include an error so we can see what happens when we restart the iptables service: ![Sample Restart failure](https://www.atlantic.net/wp-content/uploads/2018/01/config4.png) Sample Restart failure Yep, “tco” is certainly an unknown protocol. This output is kind enough to provide the line number in the file at which it encounters the error and a brief description of the error, so that’s one benefit. But then this output also points to one disadvantage to making changes to your firewall rules via the /etc/sysconfig/iptables file and restarting the entire service. Note the first line of the output indicates that all chains are being set to **ACCEPT**. The following lines flush all the rules and unload all modules, all of which complete successfully, as indicated by the bracketed “OK”s. When the iptables service encounters the error while reloading, it fails to load the entire iptables file. So that means your server is left without any filtering in place, and all chains defaulting to **ACCEPT**. ![IPtables status](https://www.atlantic.net/wp-content/uploads/2018/01/config5.png) IPtables status If you also have **NAT** or **MANGLE** rules set up in your iptables file, then you’d also lose your address translations there, so that can be one big drawback to making changes to the file and restarting the service wholesale. Ideally, as your iptables rules set becomes more complicated, your best bet is to make any changes (with explanatory comments) in the /etc/sysconfig/iptables file and then to [manually add the new rule(s) via the command line](https://www.atlantic.net/vps-hosting/how-to-linux-general-basic-iptables/), especially if these changes are being performed on a production server. Your mileage may vary based on your needs. --- # How to Install and Secure phpMyAdmin in Ubuntu 14.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-secure-phpmyadmin-ubuntu-14-04/ | Published: 2015-02-07 | Updated: 2024-06-06 | Author: Jose Velazquez ##### Verified and Tested 01/31/2015 ### Introduction This document will help you install phpMyAdmin and describe some basic steps to take in order to secure it. ## Prerequisites You need an Ubuntu 14.04 server that is configured with a static IP address. You will also need to have LAMP (Linux, Apache, MySQL and PHP) installed on the server. ## Installing phpMyAdmin Install phpMyAdmin ``` sudo apt-get install phpmyadmin ``` phpMyAdmin is now installed on your server. Now we begin the Apache configuration.   Setup phpMyAdmin under Apache, edit the apache2.conf file. ``` sudo nano /etc/apache2/apache2.conf ``` Add the following code to the bottom of the apache2.conf file. ``` Include /etc/phpmyadmin/apache.conf ``` ![Add your config file for phpmyadmin](https://www.atlantic.net/wp-content/uploads/2018/01/php1-5.png) apache2.conf Save your changes by pressing **Ctrl + X** then **Y** to accept. Restart Apache. ``` sudo service apache2 restart ``` Verify that your installation works, type the following link in your browser http://YOURIP/myphpadmin **(Log in with the username and password that was created during the installation)** ## Securing myPHPAdmin Setup security for phpMyAdmin, edit the apache.conf file: ``` sudo nano /etc/phpmyadmin/apache.conf ``` Locate the **** and add the following rule under **DirectoryIndex index.php** ``` AllowOverride All ```   ![Add directive AllowOveride All to apache.conf](https://www.atlantic.net/wp-content/uploads/2018/01/php2-4.png) apache.conf Save your changes by pressing **Ctrl + X** then **Y** to accept. Create the .htaccess file that will handle the authentication. ``` sudo nano /usr/share/phpmyadmin/.htaccess ``` Paste the following text in the file: ``` AuthType Basic AuthName "Restricted Files" AuthUserFile /etc/apache2/.phpmyadmin.htpasswd Require valid-user ``` ![Sample: .htacess](https://www.atlantic.net/wp-content/uploads/2018/01/php3-4.png) Sample: .htacess Save your changes by pressing **Ctrl + X** then **Y** to accept. Create a user and password that you would like to use for security access by pasting the following code. Then you will enter and re enter your password. (Note:Replace username with the actual user that you want to create. I will be using admin). ``` sudo htpasswd -c /etc/apache2/.phpmyadmin.htpasswd username ``` Restart Apache. ``` sudo service apache2 restart ``` Verify that everything works by typing the following link in your browser http://YOURIP/myphpadmin and typing your security username and password ![Sample Login Prompt](https://www.atlantic.net/wp-content/uploads/2018/01/php4-4.png) Sample Login Prompt Congratulations! You have just installed and secured phpMyAdmin on your server. Thank you for following along in this How-To and feel free to check back with us for any new updates. ## Atlantic.Net Since 1995, Atlantic.Net has been providing internet services to customers, including managed, cloud, and [vps hosting](https://www.atlantic.net/vps-hosting/).  In 20+ years of service, our solutions have been focused on providing the very best in web solutions to our valued customers! --- # How to: Windows Server 2012 R2 – Install DHCP > URL: https://www.atlantic.net/vps-hosting/how-to-windows-server-2012-r2-install-dhcp/ | Published: 2015-02-08 | Updated: 2026-03-03 | Author: Andrew Mora ##### Verified and Tested 02/31/14 ### Introduction Installation procedure for installing a DHCP server onto Windows 2012R2 with Server Manager. ### Prerequisites Server must have access to the internet. ## Installing DHCP on Windows Server 2012 R2 Open the Add Roles and Features wizard Server Manager -> Manage -> Add Roles and Features ![Select Add roles and features from Server Manager](https://www.atlantic.net/wp-content/uploads/2018/01/dhcp1.png) Server Manager: Add roles and features Select the “Next” button until you reach “Server Roles” then proceed to select “DHCP server” ![Under Server roles select DHCP Server](https://www.atlantic.net/wp-content/uploads/2018/01/dhcp2.png) Server Roles: DHCP Server Select the Next button. A popup box will appear, proceed to select “Add Features”. Make sure the “Include management tools” check box is selected. ![Make sure the “Include management tools” checkbox is selected.](https://www.atlantic.net/wp-content/uploads/2018/01/dhcp3.png) Add features and select management tools Proceed to select the “Next” button until you arrive at the “Confirmation” selection page below and select “Install” ![Confirm and install](https://www.atlantic.net/wp-content/uploads/2018/01/dhcp4.png) Confirm and install ![Select “Complete DHCP” configuration”](https://www.atlantic.net/wp-content/uploads/2018/01/dhcp5.png) Select “Complete DHCP” configuration” Once the installation is complete, you’ll be presented with a new screen. Select “Complete DHCP” configuration” Select “Commit” as seen below. Then select “Complete DHCP” configuration”, and select “Commit”.   Your DHCP server is now installed and may be configured under Server Manager -> Tools -> DHCP ![anet-HowtoInstallaDHCPServerintoWindows2012R2-07](https://www.atlantic.net/wp-content/uploads/2018/01/dhcp6.png) --- # How to: Basic IPTables Troubleshooting > URL: https://www.atlantic.net/vps-hosting/how-to-basic-iptables-troubleshooting/ | Published: 2015-02-08 | Updated: 2026-03-02 | Author: Atlantic.Net NOC ##### Verified and Tested 2/8/15 ### Introduction In this article, let’s discuss some basic steps you can take to troubleshoot problems you may be having with getting your iptables rules to do what you might want them to do. ### Prerequisites Server running CentOS 6.x (or any distribution of Linux) iptables installed and configured (for basic configuration, see [Basic IPTables File Configuration](https://www.atlantic.net/vps-hosting/how-to-basic-iptables-file-configuration/)) ## Basic IPTables Troubleshooting One helpful addition to making your iptables rules is to set up logging. Logging uses a special target in the iptables toolbox that pipes select output to your operating system’s log files (dmesg or systemd). On the command line: ``` sudo iptables -A INPUT -j LOG --log-prefix DROPPED-INGRESS- ``` Or, in your /etc/sysconfig/iptables file: ![Sample logging syntax](https://www.atlantic.net/wp-content/uploads/2018/01/basic1.png) Sample logging syntax Let’s unpack the syntax: * ‘`-A INPUT`‘ appends this rule to the end of the INPUT chain. Remember, rule order is important, so if you place this rule after a rule that drops or rejects traffic, it will never be used. More on this when we discuss the `--log-prefix` below. * ‘`-j LOG`‘ jumps to the `LOG` target. This target is a special one called a “non-terminating” target. Unlike the targets most commonly used (such as `ACCEPT`, `DROP`, or `REJECT`), this one doesn’t stop iptables from parsing further rules. So, when this rule is invoked, it logs the packet (and may perform additional options, if specified in the options following it), and then continues evaluating rules in the same chain until it hits a matching rule with a terminating target or until it gets past the last rule in the chain and follows the default target. * ‘`--log-prefix DROPPED-INGRESS-`‘ adds the string “DROPPED-INGRESS-” to each log entry. This addition can be helpful to filter for or to search for in a long log file. The “`--log-prefix`” option can take a string of up to 256 characters. Since this rule is the final rule in this `INPUT` chain, this will log any packet that doesn’t match any of the above rules and gets handled with the default policy (in this case, `DROP`). If you want to see which of your rules are being invoked (and, perhaps equally importantly, which aren’t), you can take a look at your packet and traffic counters. Use the ‘`-v`‘ option to the ‘`iptables`‘ command to show counters (and some additional information, as well): ``` sudo iptables -vL INPUT ``` or ``` sudo iptables -nvL INPUT ``` The output from either of these commands will display on the left side columns for packet and byte counters for each rule. The ‘`-L`‘ option indicates that we want the rules listed (note that this particular option is capitalized). The ‘`-n`‘ indicates that we don’t want to resolve IPs to their hostnames (in longer lists this reverse name resolution can cause unnecessary server overhead and make your troubleshooting annoyingly slow). You may use each flag separately (`-n` `-v` `-L`, e.g.) or together, as above, but be careful: the ‘`L`‘ must be last since it looks for further input in the form of the name of the chain to list (if nothing is specified, the default is to list all chains in the filter table). ![iptables -nvL INPUT Output](https://www.atlantic.net/wp-content/uploads/2018/01/basic2.png) iptables -nvL INPUT Output Note here that I’ve got one packet hitting my allow-all ssh rule and several hitting the first allow `RELATED/ESTABLISHED` rule (this would correspond to my ssh session into this server). I can also see that my rules for allowing ssh traffic from the 192.168.50.0/24 range has no hits. So, for example, if I had someone saying they couldn’t access this server from that range, I could see that their attempts weren’t even making it to this server. It’s quite possible your packet byte counters will tick up high enough that the values will be abbreviated with a ‘K’, ‘M’, or even ‘G’ at the end, corresponding to 1000, 1,000,000, or 1,000,000,000, respectively. If you’d still like to see unabbreviated counts, include the ‘`-x`‘ flag: ``` sudo iptables -nvxL INPUT ``` If you’d prefer not to have to deal with large count numbers, you could reset (zero) your counts with the ‘`-Z`‘ command (again, note that this flag is capitalized). You can zero the counts for all chains, a specific chain, or for a specific line in a chain. Respectively: ``` sudo iptables -Z ``` ``` sudo iptables -Z INPUT ``` ``` sudo iptables -Z INPUT 1 ``` The final example would only zero the counters for line number 1 in the `INPUT` chain. The counters would also be reset any time you reload iptables (whether from a server reboot or performing sudo service iptables reload). These are not the most ideal ways to accomplish this task, though. You may also want to get a more real-time examination of your iptables counters. Here’s where the ‘`watch`‘ command comes in handy. ‘`Watch`‘ allows us to repeat the same commands and watch the output every so often (the default is every 2 seconds). ``` sudo watch iptables -nvL INPUT ``` While ‘`watch`‘ itself doesn’t require sudo access, if the command you’ll be watching does, you could prepend ‘`sudo`‘ to the ‘`watch`‘ command to have root privilege for the command you’d like to watch. Also, if you would like to pipe watched output through something like ‘`grep`‘, you’ll want to put the entire command string in single-quotes: ``` sudo watch 'iptables -nvL INPUT | grep tcp' ``` To exit out of ‘`watch`‘, press ``. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [Virtual private servers.](https://www.atlantic.net/vps-hosting/) --- # How to Install File Server Resource Manager (FSRM) on Windows 2012 R2 with Quota Enforcement > URL: https://www.atlantic.net/vps-hosting/how-to-install-file-server-resource-manager-fsrm-windows-2012-r2-quota-enforcement/ | Published: 2015-02-08 | Updated: 2024-06-05 | Author: Andrew Mora ### Introduction Installation procedure for File Server Resource Manager (FSRM) on Windows 2012 R2 and Quota Enforcement example. ## Installing File Server Resource Manager (FSRM) on Windows 2012 R2 with Quota Enforcement Open Server Manager -> Manage -> Add Roles and Features ![Select next at that Before you begin page](https://www.atlantic.net/wp-content/uploads/2018/01/quota1.png) Add roles and features wizard Select “Next” until you arrive at the “Server Roles selection”, expand “File and Storage Services” section and select “File Server Resource Manager”. A popup window will appear, simply leave the defaults and select “Add features”. At this time, you’ll be dropped back into the main window. ![Under Select Server Roles select Files Server Resouce Manager and add features.](https://www.atlantic.net/wp-content/uploads/2018/01/quota2.png) Select Server Roles ![anet-HowtoInstallFileServerResourceManager(FSRM)onWindows2012R2withQuotaEnforcement-03](https://www.atlantic.net/wp-content/uploads/2018/01/quota3.png) Select “Next” until you reach the “Confirmation” Page and select “Install” ![Confirm the components you've selected and select Install](https://www.atlantic.net/wp-content/uploads/2018/01/quota4.png) Confirm Installation Selection Once the installation completes, you may close the resulting Installation Summary window. Now we’ll setup “Quota Enforcement”. This function allows the server administrator to restrict the size of a folder so that it cannot grow past a certain size. This is useful for mitigating FTP users such that no one user consumes an excessive amount of storage space. ![Acesss the File Server Resource Manager through Server manager Tools](https://www.atlantic.net/wp-content/uploads/2018/01/quota5.png) Server Manager: File Server Resource Manager Open Server Manager -> Tools -> Select “File Server Resource Manager” Under File Server Resource Manager, expand “Quota Management” and select “Create Quota” as seen below: ![Under File Server Resource Manager expand “Quota Management”, select “Create Quota” as seen below.](https://www.atlantic.net/wp-content/uploads/2018/01/quota6.png) File Server Resource manager: Create Quota Select the folder you’d like to place a quota on under “Quota Path”. For this example a folder named “quota-test” has been created on the desktop. We will place a 100MB limit on this folder using this utility. ![Browse to the folder you'd like to set a quota on and select it.](https://www.atlantic.net/wp-content/uploads/2018/01/quota7.png) Create Quota Next Select “100MB Limit” Under “How do you want to configure Quota Properties” and select “Create” ![Select a quota template or create your own.](https://www.atlantic.net/wp-content/uploads/2018/01/quota8.png) Create Quota: Properties That’s it! You’ve now restricted the size of the folder to a maximum of 100MB. As you can see from above, you are not limited to the templates available within the drop down list for your quotas. You may create your own custom quotas as you please and even set up alert notifications. This functionality, however, goes beyond the scope of this article.   ![Sample Quota](https://www.atlantic.net/wp-content/uploads/2018/01/quota9.png) Sample Quota **Atlantic.Net** Since 1995, Atlantic.Net has been providing internet services to customers, including managed, [virtual private server hosting](https://www.atlantic.net/vps-hosting/pricing/) and dedicated hosting. In 20+ years of service, our solutions have been focused on providing the very best in web solutions to our valued customers! --- # How To Install Drupal on an Ubuntu 20.04 Server with Apache > URL: https://www.atlantic.net/vps-hosting/how-to-install-drupal-ubuntu-20-04-server-apache/ | Published: 2015-02-19 | Updated: 2026-03-03 | Author: Jose Velazquez ##### Verified and Tested 06/13/21 ### Introduction In this How-To, we will walk you through the install and configuration of Drupal with Apache. Drupal is a free content management system that will facilitate the way your content is organized and managed. It has a user-friendly interface that makes customizing your content easy and simple with little effort. ### Prerequisites - A cloud server with Ubuntu 20.04 and Apache already installed. - You will also need to have a Server with LAMP(Linux, Apache, MySQL, PHP) configured. See our “[How To Install LAMP on Ubuntu 20.04](https://www.atlantic.net/vps-hosting/how-to-install-linux-apache-mysql-php-lamp-ubuntu-20-04/)“. ## Install PHP Extensions First, you will need to install some required PHP extensions to your server. You can install all of them with the following command: ``` apt-get install php7.4-gd php7.4-common php7.4-mysql php7.4-apcu php7.4-gmp php7.4-curl php7.4-intl php7.4-mbstring php7.4-xmlrpc php7.4-gd php7.4-xml php7.4-cli php7.4-zip -y ``` Once all the packages are installed, edit the php.ini file and change some default settings. ``` nano /etc/php/7.4/apache2/php.ini ``` Change the following lines: ``` date.timezone = Asia/Kolkata memory_limit = 256M upload_max_filesize = 64M max_execution_time = 300 cgi.fix_pathinfo = 0 ``` Save and close the file when you are finished. ## Create Drupal Database Next, you will need to create a user and database for Drupal. First, connect to the MySQL shell with the following command: ``` mysql ``` Once you are connected, create a database and user with the following command: ``` create database drupaldb; create user drupaluser@localhost identified by 'password'; ``` Next, grant all the privileges to drupaldb with the following command: ``` grant all privileges on drupaldb.* to drupaluser@localhost; ``` Next, flush the privileges and exit from the MySQL with the following command: ``` flush privileges; exit; ``` ## Download Drupal Next, change the directory to Apache default root directory and download the latest version of Drupal with the following command: ``` cd /var/www/html wget -q https://www.drupal.org/download-latest/tar.gz -O drupal-latest.tar.gz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar -xf drupal-latest.tar.gz ``` Next, rename the extracted directory to drupal9: ``` mv drupal-9.1.10 drupal9 ``` Next, set proper ownership to the drupal9 directory: ``` chown -R www-data:www-data /var/www/html/drupal9 ``` ## Configure Apache Next, you will need to create an Apache virtual host configuration file for Drupal. You can create it with the following command: ``` nano /etc/apache2/sites-available/drupal.conf ``` Add the following lines: ``` ServerName drupal9.example.com ServerAdmin admin@example.com DocumentRoot /var/www/html/drupal9/ CustomLog ${APACHE_LOG_DIR}/access.log combined ErrorLog ${APACHE_LOG_DIR}/error.log Options Indexes FollowSymLinks AllowOverride All Require all granted RewriteEngine on RewriteBase / RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule ^(.*)$ index.php?q=$1 [L,QSA] ``` Save and close the file then activate the drupal9 site and enable the Apache rewrite module: ``` a2ensite drupal9 a2enmod rewrite ``` Next, restart the Apache service to apply the changes: ``` systemctl restart apache2 ``` ## Access Drupal Installation Wizard At this point, Drupal is installed and configured. Now, open your web browser and access the Drupal web installation wizard using the URL **http://drupal9.example.com**. You will be redirected to the Drupal installation wizard: ![Drupal installation](https://www.atlantic.net/wp-content/uploads/2015/02/p3-1024x491.png) You can now follow the required steps to complete the Drupal web installation. Congratulations! You have just installed and configured Drupal with Apache on your Ubuntu 20.04 [Virtual Private Server](https://www.atlantic.net/vps-hosting/). Thank you for following along in this How-To and check back with us for any new updates. --- # Atlantic.Net Cloud – How to enter single user mode for Centos Cloud servers > URL: https://www.atlantic.net/hipaa-compliant-hosting/how-to-atlantic-net-cloud-enter-single-user-mode-centos/ | Published: 2015-02-21 | Updated: 2026-02-28 | Author: Atlantic.Net NOC ##### **Verified and Tested 02/28/2015** ### Introduction This article will show you how to enter single user mode for maintenance of multi-user environments or changing/resetting a lost superuser password of Centos servers. ### Why do I need this? My cloud server will only enter read-only mode, FSCK complains about permissions, or I need to make sure no one can access my server while I make security changes. I forgot my cloud server password and I would not like to use the automated password reset feature (see [How to resetting atlantic net cloud server password/](https://www.atlantic.net/vps-hosting/how-to-resetting-atlantic-net-cloud-server-password/)). You will need to access your cloud server using the provided VNC. See the following URL on how to access the server: [How to using vnc access cloud server/](https://www.atlantic.net/hipaa-compliant-hosting/how-to-using-vnc-access-cloud-server/). ## Entering Single User mode for Centos Once you have decided that single user mode is the only way you can, or want to proceed, you will need to VNC to the server. Don’t worry about logging into the server at this point, since this process will need you to reboot the server. From the cloud portal issue a hard reboot, instructions here: [https://www.atlantic.net/dedicated-server-hosting/atlantic-net-cloud-how-to-soft-or-hard-reboot-a-atlantic-net-cloud-server/](https://www.atlantic.net/vps-hosting/atlantic-net-cloud-how-to-soft-or-hard-reboot-a-atlantic-net-cloud-server/) Once you issue the hard reboot, you will need to click refresh at the top right of the VNC screen since the hard reboot will reset that connection. You need to click this refresh very quickly otherwise you will miss the boot screen where you can interrupt the boot process. ## ![SUM_1](https://www.atlantic.net/wp-content/uploads/2018/01/cloud1-1.png) When the server starts to boot, you will see a GRUB menu/screen. You will need to interrupt the boot by pressing any key. ![SUM_2](https://www.atlantic.net/wp-content/uploads/2018/01/cloud2-1.png) Now you can edit the default kernel your system boots to. By default, the most recently added kernel is at the top of the list and is the default kernel. This kernel should already be highlighted for you. Press e to edit. ![SUM_3](https://www.atlantic.net/wp-content/uploads/2018/01/cloud3-1.png) Go to the line that starts with kernel, and press e to edit. ![SUM_4](https://www.atlantic.net/wp-content/uploads/2018/01/cloud4.png) Add the word “single”, no quotes needed, to the end of the line and then press Enter. ![SUM_5](https://www.atlantic.net/wp-content/uploads/2018/01/cloud5.png) ![SUM_6](https://www.atlantic.net/wp-content/uploads/2018/01/cloud6.png) Press b to boot into the newly edited kernel. ![SUM_7](https://www.atlantic.net/wp-content/uploads/2018/01/cloud7.png) Now you are in single user mode. You may perform actions such as FSCK, passwd, and other commands for maintenance. Check back for more information from Atlantic.Net, including content about our [HIPAA-compliant cloud hosting services](https://www.atlantic.net/hipaa-compliant-hosting/). --- # How To Configure vsftpd to use SSL/TLS on an Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-configure-vsftpd-use-ssl-tls-ubuntu-20-04/ | Published: 2015-02-23 | Updated: 2026-03-02 | Author: Atlantic.Net NOC ### Introduction FTP (file transfer protocol) is a popular way to transfer files between your computer and a remote computer. In this article, we will install and configure vsftpd to use SSL certificates on an Ubuntu 20.04. ## Configuring SSL with VSFTPD in Ubuntu First, we will make the directory where the SSL certificate keys will be stored. ``` mkdir /etc/ssl/certificates ``` Next, we will create the 2048 encryption key that will last for 365 days. ``` openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/ssl/certificates/vsftpd.pem -out /etc/ssl/certificates/vsftpd.pem ``` After creating the key, we will need to change some parameters in the default vsftpd configuration file. I will be using nano command again for the text editor. ``` nano /etc/vsftpd.conf ``` You will be editing the path for the **rsa_cert_file** and **rsa_private_key** and adding some others to the bottom of this file. The file should look like this at the bottom afterward: ``` rsa_cert_file=/etc/ssl/certificates/vsftpd.pem rsa_private_key_file=/etc/ssl/certificates/vsftpd.pem ssl_enable=YES allow_anon_ssl=NO force_local_data_ssl=YES force_local_logins_ssl=YES ssl_tlsv1=YES ssl_sslv2=NO ssl_sslv3=NO require_ssl_reuse=NO ssl_ciphers=HIGH ``` Save and close the file. Restart vsftpd with the command below: ``` systemctl restart vsftpd ``` Now we can connect to server using SSL/TLS encryption with Filezilla. Open Filezilla, **Go to File**>**Site Manager**. Click on **New** **Site**. Make sure to choose “**Require explicit FTP over TLS**” for the Encryption type. ![Sample Filezilla Site manager](https://www.atlantic.net/wp-content/uploads/2018/01/ftp1-1.png) Filezilla Site manager   Once you click on **connect**, you will be prompted with the window below to accept the unknown certificate. ![Certificate Warning](https://www.atlantic.net/wp-content/uploads/2018/01/ftp2-1.png) Certificate Warning Now you are connected to your server with SSL/TLS encryption! --- # How to Set Up VSFTPD on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-set-vsftpd-centos-8/ | Published: 2015-02-23 | Updated: 2026-03-03 | Author: Jose Velazquez ##### Verified and Tested 06/02/21 ### Introduction In this How-To, we will walk you through the VSFTPD install on your CentOS 8 Cloud Server. If you are using an Ubuntu Cloud Server instead,[check out the how-to for that here](https://www.atlantic.net/vps-hosting/how-to-install-vsftpd-ubuntu-cloud-server-vps/). VSFTPD is an FTP server that is built to be efficient and very secure. This is the default FTP server in the majority of Linux Operating Systems around today. With fast response and security, it reliably facilitates the job of uploading and downloading files with peace of mind. ## Install VSFTPD `sudo yum install vsftpd` ## Install the Client `sudo yum install ftp` ## Modify the Configuration File Make changes to the configuration file by the following: `sudo vi /etc/vsftpd/vsftpd.conf` Locate the Anonymous_enable to YES and change it to NO. It should look like the line below: # Allow anonymous FTP? (Beware – allowed by default if you comment this out). `anonymous_enable=NO` Locate the local_enable=YES line and remove the # in front of it. This will limit the users to their chroot and won’t have access to anywhere else in the server. ## Restart the Service to Refresh the Changes `sudo systemctl start vsftpd` Enable vsftpd to start when the server boots: `sudo systemctl enable vsftpd` To access your server via FTP over the web, type the following in your browser: **ftp://YOUR.IP.ADD.RESS** You will now be prompted to input your username and password. All Done! Congratulations! You have just installed VSFTPD on your CentOS 6 Cloud Server.  Thank you for following this how-to, check back for updates or learn more about our reliable [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. --- # How To Configure VSFTPD to Use SSL/TLS on a CentOS VPS > URL: https://www.atlantic.net/vps-hosting/how-to-configure-vsftpd-use-ssl-tls-centos-vps/ | Published: 2015-02-23 | Updated: 2026-03-02 | Author: Atlantic.Net NOC ### Introduction FTP (file transfer protocol) is a popular way to transfer files between your computer and a remote computer. In this article, we will install and configure vsftpd to use SSL certificates on a CentOS . ### Prerequisites VSFTPD installed ([How to install vs ftpd centos vps](https://www.atlantic.net/vps-hosting/how-to-install-vsftpd-centos-vps/)) ## Configuring SSL with VSFTPD in CentOS First, we will make the directory where the SSL certificate keys will be stored. ``` mkdir /etc/ssl/certificates ``` Next, we will create the 2048 encryption key that will last for 365 days. ``` openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/ssl/certificates/vsftpd.pem -out /etc/ssl/certificates/vsftpd.pem ``` After creating the key, we will need to change some parameters in the default vsftpd configuration file. I will be using nano command again for the text editor. ``` nano /etc/vsftpd/vsftpd.conf ``` You will be adding the paths for the rsa_cert_file and rsa_private_key and adding some others to the bottom of this file. The file should look like this at the bottom afterwards: ``` rsa_cert_file=/etc/ssl/certificates/vsftpd.pem rsa_private_key_file=/etc/ssl/certificates/vsftpd.pem ssl_enable=YES allow_anon_ssl=NO force_local_data_ssl=YES force_local_logins_ssl=YES ssl_tlsv1=YES ssl_sslv2=NO ssl_sslv3=NO require_ssl_reuse=NO ssl_ciphers=HIGH ``` Save and close the file. Restart vsftpd with the command below: ``` service vsftpd restart ``` Now we can connect to the server using SSL/TLS encryption with Filezilla. Open Filezilla, Go to File>Site Manager. Click on New Site. Make sure to choose “Require explicit FTP over TLS” for the Encryption type. ![Sample Filezilla: Site manager](https://www.atlantic.net/wp-content/uploads/2018/01/filezilla1.png) Filezilla: Site manager Once you click on connect, you will be prompted with the window below to accept the unknown certificate. ![Certificate Warning](https://www.atlantic.net/wp-content/uploads/2018/01/filezilla2.png) Certificate Warning Now you are connected to your server with SSL/TLS encryption! Check back for more updates from Atlantic.Net, or learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) options. --- # Compassion and Humanity: Ubuntu LTS for Linux SSD Cloud > URL: https://www.atlantic.net/hipaa-compliant-hosting/compassion-and-humanity-ubuntu-lts-for-linux-ssd-cloud/ | Published: 2015-02-23 | Updated: 2025-03-06 | Author: Alexander Wise Developed and managed in conjunction with the open source community and Canonical, Ubuntu is one of the most popular distributions of the Linux operating system. The name itself is a nod to the synergistic, “share and share alike” philosophy that is considered a pillar of the open source movement. Ubuntu is a word used in Xhosa and Zulu that is roughly translated as *humanity*, *compassion*, or *the whole is better than the sum of its parts*.  Atlantic.Net offers several Ubuntu distribution in one of our Linux cloud hosting options. Obviously, “Ubuntu” was a great language choice by the developers of the OS. It attempts to capture the passion of open source, a feeling shared by some of our staff. However, once you start looking at technical requirements, you want to know that you are getting what you need. One thing that you may want to do is use a version of Ubuntu that has LTS. ### **What is LTS?** LTS stands for “long-term support.” If your company is risk-averse, long-term support is crucial so you continue to receive security patches. Not all versions of Ubuntu are supported long-term. Since enterprises tend to be risk-averse, we offer LTS versions for all our SSD Ubuntu virtual machines. According to the [“LTS” Page](https://wiki.ubuntu.com/LTS) from the Ubuntu Wiki, Ubuntu Desktop and Ubuntu Server are released twice a year. That way you can have access to the most cutting-edge open source applications. Free security updates last for nine months on non-LTS versions of both systems. Here are the last 12 releases of Ubuntu (the last one due out late 2015) so you can see how this works: | **Operating System Version** | **Security Update Commitment** | | --- | --- | | Ubuntu 15.10 | nine months of updates | | Ubuntu 15.04 | nine months of updates | | Ubuntu 14.10 | nine months of updates | | **Ubuntu 14.04 LTS** | **five years of updates** | | Ubuntu 13.10 | nine months of updates | | Ubuntu 13.04 | nine months of updates | | Ubuntu 12.10 | nine months of updates | | **Ubuntu 12.04 LTS** | **five years of updates** | | Ubuntu 11.10 | nine months of updates | | Ubuntu 11.04 | nine months of updates | | Ubuntu 10.10 | nine months of updates | | **Ubuntu 10.04 LTS** | **five years Server, three years Desktop** | Five characteristics of LTS are: - Limited features, with user option, to download individually. - Lack of significant structural changes. - Designed to meet the needs of enterprises. - Device compatibility, as explained on the wiki: “We will make point releases throughout the development cycle to provide functional support for new server and desktop hardware.” - Longer Beta cycle, shorter development cycle. ### **LTS in 30 Seconds** If you love the Ubuntu operating system, we will always give you access to the latest LTS release. **As indicated in the above video**, you can provision a Cloud Server with us in less than 30 seconds, starting from $0.005 per hour.   *Atlantic.Net can also assist with dedicated, managed and [HIPAA-compliant cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions – contact us today for a consultation.* --- # Cloud Migration Tips for Attorneys > URL: https://www.atlantic.net/hipaa-compliant-hosting/cloud-migration-tips-for-attorneys/ | Published: 2015-02-23 | Updated: 2025-03-06 | Author: Alexander Wise - **ABA: Many Lawyers Migrating to Cloud** - **Why the Legal Cloud Trend?** - **Migration Checklist** - **Partnering with Experts** **ABA: Many Lawyers Migrating to Cloud** The 2014 Legal Technology Survey Report from the American Bar Association (ABA) revealed that attorneys are rapidly migrating to the cloud in 2015. Although only 30% of respondents said that they were currently using the cloud, 35% of non-cloud firms reported that they were planning [a cloud transition within 6 to 12 months](http://www.americanbar.org/publications/techreport/2014/cloud-computing.html). Recognizing how prevalent cloud technology is becoming in the legal profession, the ABA’s Legal Technology Resource Center (LTRC) released a [list of migration advice through its *Law Technology Today* blog](http://www.lawtechnologytoday.org/2015/01/a-cloud-migration-checklist/). Here are highlights from the report. **Why the Legal Cloud Trend?** Obviously, attorneys are not moving to enterprise cloud computing simply because that’s where the crowd is going. They are open to cloud because it meets a number of different needs: 1. Lawyers are able to use the newest, most innovative applications. 2. Firms with on-site data centers appreciate the chance to get rid of the servers and treat their technology systems as an operating expense. 3. Law offices are looking for help protecting their data. After all, the sophistication of hacker efforts is apparent with the growing list of intrusions at multinational enterprises such as Target, Home Depot, and Sony Pictures. Cybercriminals want your data, and if they make their way inside your network, they remain there unperceived for a long time – although [the final “bomb” the North Koreans planted](http://www.bloomberg.com/bw/articles/2014-12-03/sony-hackers-were-inside-the-company-network-for-a-long-time) at Sony slashed and burned the studio’s infrastructure in just 10 minutes, intruders had been waltzing around [undetected for months](http://www.bloomberg.com/news/articles/2014-12-19/sony-hackers-seen-having-snooped-for-months-planted-bomb). 4. Like other businesspeople, attorneys want to be able to access their files and systems on-the-go through their own laptops and tablets, with cloud server enabled “bring your own device” (BYOD) policies. “Fortunately, the right cloud provider can make these headaches disappear by offloading hardware, software, security and network maintenance,” the ABA explains, “and leave the firm to focus on what it does best—the practice of law.” **Migration Checklist** The ABA provides the following checklist as you strategize your move to cloud: - **Don’t give away your data.** At the beginning of the Internet, it was not uncommon for small businesses to build websites through third parties who exploited ignorance and bought the domain themselves. Although that practice seems hard to beat in terms of lock-in, it could be worse: you could end up accidentally ceding control of all your digital information. You must ensure that you would still own the data if you later decided to switch providers or if the cloud service went bankrupt. - **Where is the data center?**Where will your information be physically stored? Some services spread information worldwide. You want the protection of US law. Ask the provider about keeping all data **within American borders**. - **Check your service-level agreement.**The ABA notes that “most cloud providers only [offer a] 99.9% uptime agreement, with little in the way of financial incentive to ensure that SLA is met.” They recommend choosing a host that instead offers 99.999% uptime (which actually reduces acceptable unscheduled downtime 99%, [from almost 9 hours to 5 minutes annually](http://uptime.is/99.999)) **or above**. - **Understand the pricing.**You want to work with organizations that are customer-centric and transparent with costs, especially since [a high-profile 2014 survey](http://www.forbes.com/sites/joemckendrick/2014/07/19/what-cloud-computing-customers-want-clarity-simplicity-support/) found that clarity, simplicity, and support are top priorities for cloud clients. - **Verify that the hosting service can do anything.**Law offices understandably don’t want to have to spend their time patching security vulnerabilities. Your provider should allow you to build and develop your own infrastructure, with public and private components (the hybrid cloud model) as desired. - **Verify access neutrality.**Your provider should be device-neutral to facilitate full access. - **Verify software neutrality.**You also want to be able to continue to run the same programs rather than conducting a complete overhaul. “Choose a provider who will support your choices of practice management, time-tracking, accounting, collaboration and other tools,” the ABA advises. - **Check security mechanisms.**As discussed above, we live in a world in which hacking has become increasingly common, with law firms often targeted for mergers and acquisitions (M&A) details. The ABA specifically recommends providers that have been audited to meet **SSAE 16, Type 2**, the robust version of a standard developed by the American Institute of CPAs. - **Standard backup.** Backup should, at a minimum, occur automatically every 24 hours, says the ABA. You should also be able to quickly retrieve backups. - **Business continuity.** Backups of individual documents are small fish in the grand scheme of things. What if a “man-made” or natural disaster occurs? You want the data to be replicated at a second facility, also located in the United States. **Partnering with Experts** The above recommendations are just the beginning. You really must believe in the practices and reputation of your provider. Our client Roy Johnson, CIO of HD Publishing Group, explains [**why HD chose us**](https://www.atlantic.net/hosting-services-provider/atlantic-net-reviews-and-testimonials/): “The fact Atlantic.Net has been around since 1994 and operates a profitable business with extremely low debt adds an extra layer of security in today’s tough business environment.” By Moazzam Adnan   Atlantic.Net can assist with cloud, managed, dedicated and [HIPAA-compliant cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions – contact us today for a consultation. --- # How to Install .NET 3.5 In Windows Server 2012 R2 > URL: https://www.atlantic.net/vps-hosting/how-to-install-net-3-5-windows-server-2012-r2/ | Published: 2015-02-25 | Updated: 2026-03-03 | Author: Michael Douse ### Introduction Numerous applications will require Microsoft’s .NET framework to work correctly. By default, Windows Server 2012 R2 does not have .NET 3.5 installed. This article will explain how to install .NET 3.5 on your cloud server. ## Installing .NET on Windows Server 2012 R2 Find and open the “Add Roles and Feature Wizard” ![Open Server Manager](https://www.atlantic.net/wp-content/uploads/2018/01/net1.png) Server Manager The easiest way to get there is through the server manager window. ![In server manager select Add roles and features](https://www.atlantic.net/wp-content/uploads/2018/01/net2.png) Add roles and features Click on “Add roles and features”. This will open a new window as shown below. ![Select next](https://www.atlantic.net/wp-content/uploads/2018/01/net3.png) Before You Begin ![Select role-based or feature-based installation](https://www.atlantic.net/wp-content/uploads/2018/01/net4.png) Installation Type ![Under Server Selection select your server.](https://www.atlantic.net/wp-content/uploads/2018/01/net5.png) Server Selection You should see only one server under the “Server Selection” window. This will be the case for most users that are not managing multiple servers. Otherwise, you will need to make sure to select the applicable server you wish to install .NET 3.5 on. Click Next to proceed. The next window will drop you into the “Server Roles” category. You will need to click on the Features category to find “.NET Framework 3.5 Features”. Select the following and click Next to proceed with the installation confirmation. ![Locate .NET Framework 3.5 Features and add .NET Framework 3.5 ](https://www.atlantic.net/wp-content/uploads/2018/01/net6.png) Select feature ![Select install on Confirm Installation selection](https://www.atlantic.net/wp-content/uploads/2018/01/net7.png) Confirm Installation selection Click the Install button and monitor for completion. ![Verify Results](https://www.atlantic.net/wp-content/uploads/2018/01/net8.png) Verify Results You now have .Net Framework 3.5 installed! --- # How to Disable Internet Explorer Enhanced Security Configuration for Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-disable-internet-explorer-enhanced-security-configuration/ | Published: 2015-02-25 | Updated: 2024-06-05 | Author: Atlantic.Net NOC ##### **Verified and Tested 02/28/2015** ### Introduction Internet Explorer Enhanced Security Configuration is a Microsoft feature that for many non-techy users can all but stop you in your tracks to using your server successfully. It has a very valid use in helping to protect Administrators and users from downloading Viruses and Malware. It is so good, it will prevent you from downloading anything, even another browser! If this is frustrating you, like it does many, you will learn how to get around it now. ## Disabling Internet Explorer Enhanced Security Configuration For Windows Server 2012 > Note: If you have an [Atlantic.Net VPS with Windows Server 2012](https://www.atlantic.net/vps-hosting/)that was provisioned before Mid-February 2015, you can use this to configure it. If you provisioned your server after that, don’t worry about this since we have brought you our Windows Server Desktop Experience and it is already turned off. When you first log in, Server Manager should already open up for you. If not, click on icon you see here. ![Open Server Manager](https://www.atlantic.net/wp-content/uploads/2018/01/security1.png) Server Manager Once Server Manager is open, click on Local server shown below highlighted yellow. ![Select Local server](https://www.atlantic.net/wp-content/uploads/2018/01/security2.png) Server Manager: Dashboard Where it says “IE Enhanced Security Configuration” Click the “On”. If it says off, you may have already had this done for you. IE Enhanced Security Configuration” Click the “On” Now, how you configure this setting is up to you. However, since you are this far in, you will likely want to turn it off for Administrators. If you do not plan on creating any other accounts, or the other accounts that are created will be Administrator accounts, then the User section will not apply. ![Select the appropriate action for your environment](https://www.atlantic.net/wp-content/uploads/2018/01/security3.png) Internet Explorer Enhanced Security Configuration Click OK. That is all you need to do. If you already have IE open then you will need to close it and reopen it for these settings to take effect. Happy Browsing. --- # How to Disable Internet Explorer Enhanced Security Configuration for Windows Server 2008 > URL: https://www.atlantic.net/vps-hosting/how-to-disable-internet-explorer-enhanced-security-configuration-server-2008/ | Published: 2015-02-25 | Updated: 2024-06-05 | Author: Atlantic.Net NOC ##### **Verified and Tested 02/28/2015** ### Introduction Internet Explorer Enhanced Security Configuration is a Microsoft feature that for many non-techy users can all but stop you in your tracks to using your server successfully. It has a very valid use in helping to protect Administrators and users from downloading Viruses and Malware. It is so good, it will prevent you from downloading anything, even another browser! If this is frustrating you, like it does many, you will learn how to get around it now. ## **Disabling Internet Explorer Enhanced Security Configuration for Windows Server 2008** When you first log in, Server Manager should already open up for you. If not, click on icon you see here. ![Open Server Manager](https://www.atlantic.net/wp-content/uploads/2018/02/security1.png) Once Server Manager is open, click on the Configure IE ESC as shown below. ![Select Configure IE Sec](https://www.atlantic.net/wp-content/uploads/2018/02/security2.png) Now, how you configure this setting is up to you. However, since you are this far in, you will likely want to turn it off for Administrators. If you do not plan on creating any other accounts, or the other accounts that are created will be Administrator accounts, then the User section will not apply. ![Select your options as necessary](https://www.atlantic.net/wp-content/uploads/2018/02/security3.png) Click OK. That is all you need to do. If you already have IE open, then you will need to close it and reopen it for these settings to take effect. Happy Browsing. --- # How to Install FTP on Windows Server 2008 R2 > URL: https://www.atlantic.net/vps-hosting/how-to-install-ftp-windows-server-2008-r2/ | Published: 2015-02-25 | Updated: 2024-06-05 | Author: Atlantic.Net NOC ##### Verified and Tested 02/25/2015 ### **Introduction** We will show you how to install FTP on a Windows Server 2008 R2. ### Prerequisites - Web Server (IIS) – If you haven’t yet, check out our article [How to install IIS on Windows Server 2008 R2](https://www.atlantic.net/vps-hosting/how-to-install-iis-windows-server-2008-r2/). ## Installing FTP on Windows Server 2008 R2 Open Server Manager by going to Start>All Programs>Administrative Tools>Server Manager. ![Navigate to Start>All Programs>Administrative Tools>Server Manager.](https://www.atlantic.net/wp-content/uploads/2018/01/ftp1.png) *Server Manager* In Server Manager, select Roles and then click on Add Role Services. ![Select Roles and then click on Add Role Services.](https://www.atlantic.net/wp-content/uploads/2018/01/ftp2.png) *Server Manager: Roles* In **Select Role Services**, scroll down and check the box next to **FTP Server. **Once done, click **Next**. ![Check the box next to FTP Server.](https://www.atlantic.net/wp-content/uploads/2018/01/ftp3.png) *Role Services* Review what is being installed. Once ready, click **Install**. ![Confirm Installation](https://www.atlantic.net/wp-content/uploads/2018/01/ftp4.png) *Confirm Installation* You should then see a progress bar. Once complete, click **Close**. ![Installation Results](https://www.atlantic.net/wp-content/uploads/2018/01/ftp5.png) *Installation Results* Now FTP is installed. You can not yet connect to your Web Site via FTP. Next, you will need to Add a FTP Publishing to your site. Open IIS, expand your computer, expand Sites, right click on your Web Site and then click on **Add FTP Publishing…** ![Right click on your Web Site and then click on Add FTP Publishing](https://www.atlantic.net/wp-content/uploads/2018/01/ftp6.png) *IIS Manager: Add FTP Publishing* Once the Add FTP Site Wizard comes up: - Choose an IP address for your FTP site from the IP address drop-down, or choose to accept the default selection of “All Unassigned.” - Normally, you would enter the TCP/IP port for the FTP site in the port box. For this how-to, choose to accept the default port of 21. - For this how-to, we will not use a host name, so make sure that the Virtual Host box is blank. - Make sure that the Certificates drop-down is set to “Not Selected” and that the Allow SSL option is selected. - When you have completed these items, click Next. ![Fill out the appropriate fields and select Next](https://www.atlantic.net/wp-content/uploads/2018/01/ftp7.png) *Binding and SSL Setting* On the Authentication and Authorization Information page: - Select Basic for the Authentication settings. - For the Authorization settings: - Choose “Specified users” from the Allow access to drop-down - Type “Administrator” for the user name. - Select Read and Write for the Permissions option. - When you have completed these items, click Finish. ![Determine what users you'd like to have FTP access along with permissions and select Finish](https://www.atlantic.net/wp-content/uploads/2018/01/ftp8.png) *Authentication and Authorization* Last thing to make sure is if your Windows Firewall has a rule set for FTP default port 21. Open Windows Firewall with Advanced Security by going to Start>All Programs>Administrative Tools>Windows Firewall with Advanced Security. ![Start: Windows Firewall and Advanced Security](https://www.atlantic.net/wp-content/uploads/2018/01/ftp9.png) *Start: Windows Firewall and Advanced Security* Once opened, click on **Inbound Rules **and then click on **New Rule **under the Actions Pane. ![Open Windows Firewall with Advanced Security and select add new rule](https://www.atlantic.net/wp-content/uploads/2018/01/ftp10.png) *Windows Firewall with Advanced Security* The New Inbound Rule Wizard will pop up. You will select Port and click Next. ![New Inbound Rule Wizard will pop up. You will select Port and click Next.](https://www.atlantic.net/wp-content/uploads/2018/01/ftp11.png) *Rule Type* Since this is for the default port 21 for FTP, we will use the **TCP** protocol and 21 for the **Specific local ports**.  Once done, click Next. ![Use the TCP protocol and 21 for the Specific local ports](https://www.atlantic.net/wp-content/uploads/2018/01/ftp12.png) *Protocol and Ports* In the Action page, we will select to **Allow the connection** and click Next. ![Allow the connection](https://www.atlantic.net/wp-content/uploads/2018/01/ftp13.png) *Action* The next page is the **Profile** page, which we will check all the boxes and then click Next. ![Profile page: Check all the boxes and then click Next.](https://www.atlantic.net/wp-content/uploads/2018/01/ftp14.png) *Profile* On the last page, you will need to select a name for the new rule. Here, we will name it “FTP” and then click Finish. ![Name your FTP Connection](https://www.atlantic.net/wp-content/uploads/2018/01/ftp15.png) *Name* Now the firewall rule has been added for the default port 21. We can now test FTP connection to the Web Site. In this how-to, I will use FileZilla to show connection but there are many FTP clients out there to use. With FileZilla, we will need to fill in the Host/IP Address, Username, Password and Port # to connect. Earlier, I set up FTP to use a specific user (administrator) and also used the default FTP port 21. Once you hit Connect, you will be connected to your Web Site via FTP! ![Test your Connection with filezilla.](https://www.atlantic.net/wp-content/uploads/2018/01/ftp16.png) *Test Connection* Thank you for following along this how-to, we hoped you have enjoyed it. Please check back here for more updates or check out the many services offered by Atlantic.Net, including [VPS Hosting](https://www.atlantic.net/vps-hosting/), Private Cloud Hosting and PCI Hosting. --- # How to Enter Single User Mode for Ubuntu Atlantic.net Cloud Servers > URL: https://www.atlantic.net/hipaa-compliant-hosting/how-to-enter-single-user-mode-ubuntu-atlantic-net-cloud-servers/ | Published: 2015-02-25 | Updated: 2024-06-04 | Author: Atlantic.Net NOC ##### **Verified and Tested 02/28/2015** ### Introduction This article will show you how to enter single user mode for maintenance of multi-user environments or changing/resetting a lost superuser password of Ubuntu servers. ### Why do I need this? My cloud server will only enter read-only mode, FSCK complains about permissions, or I need to make sure no one can access my server while I make security changes. I forgot my cloud server password, and I would not like to use the automated password reset feature (see our article on [how to reset an Atlantic.Net cloud server password](https://www.atlantic.net/vps-hosting/how-to-resetting-atlantic-net-cloud-server-password/)). You will need to access your cloud server using the provided VNC. See our article on [how to access the server](https://www.atlantic.net/hipaa-compliant-hosting/how-to-using-vnc-access-cloud-server/). ## Entering Single User Mode for Ubuntu Once you have decided that single user mode is the only way you can or want to proceed, you will need to VNC to the server. Don’t worry about logging into the server at this point, since this process will need you to reboot the server. From the cloud portal issue a hard reboot, instructions here: [How To Soft Or Hard Reboot A Atlantic.Net Cloud Server](https://www.atlantic.net/vps-hosting/atlantic-net-cloud-how-to-soft-or-hard-reboot-a-atlantic-net-cloud-server/) Once you issue the hard reboot, you may need to click Refresh in the top right of the VNC screen since the hard reboot will reset that connection. You need to click this refresh very quickly otherwise you will miss the boot screen where you can interrupt the boot process. When the server starts to boot, you will see a GRUB menu/screen. You will need to interrupt the boot by pressing any key. ![Interrupt the boot by pressing any key.](https://www.atlantic.net/wp-content/uploads/2018/01/single1.png) Kernel Selection Now you can edit the default kernel your system boots to. By default, the most recently added kernel is at the top of the list and is the default kernel. Press e to edit. ![Select e to edit](https://www.atlantic.net/wp-content/uploads/2018/01/single2.png) Grub boot menu Go to the line that starts with “linux /boot/vmlinuz”. Replace the end of the line “ro \ console=ttyS0 console=tty0” with “rw init=/bin/bash”. ![Replace the end of the line “ro \ console=ttyS0 console=tty0” with “rw init=/bin/bash”.](https://www.atlantic.net/wp-content/uploads/2018/01/single3.png) Grub Menu Press F10 to boot into the newly edited kernel. ![Press F10 to boot into the newly edited kernel.](https://www.atlantic.net/wp-content/uploads/2018/01/single4.png) Boot to single user If you get an error like I did, just press enter. ![SUM_5](https://www.atlantic.net/wp-content/uploads/2018/01/single5.png) Now you are in single user mode. You may perform actions such as FSCK, passwd, and other commands for maintenance. Thank you for following along and feel free to check back with us for further updates or learn more about our reliable [HIPAA-compliant cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) servers. --- # How to Install FTP on Windows Server 2012 R2 > URL: https://www.atlantic.net/vps-hosting/how-to-install-ftp-windows-server-2012/ | Published: 2015-02-25 | Updated: 2026-03-03 | Author: Atlantic.Net NOC ##### Verified and Tested 02/25/2015 ### **Introduction** We will show you how to install FTP on a Windows Server 2012 R2. ### Prerequisites - Windows server with IIS – take a look at our helpful how-to on [installing IIS on your Windows Server](https://www.atlantic.net/vps-hosting/how-to-install-iis-windows-server-2012-r2/). If you need a server, you can spin up a [Windows VPS Hosting](https://www.atlantic.net/vps-hosting/) server in under 30 seconds with Atlantic.Net. ## Installing FTP on Windows Server 2012 R2 Open Server Manager by going to Start>Administrative Tools>Server Manager. ![Open Server Manager](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows1.png) *Server Manager* In Server Manager, click on **Add Roles and Features**. ![Add Roles and Features](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows2.png) *Add Roles and Features* The Add Roles and Features wizard should open. Click **Next** on the Before you begin section. Make sure **Role-based or feature-based installation** is selected in the Installation Type Section, then click **Next.** ![Select Role-based or features based installation](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows3.png) *Installation Type* Make sure **Select a server from the server pool** is selected. **Select your server in the server pool section**. Once done, click **Next**. ![Select your server](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows4.png) *Server Selection* Scroll down and click on the arrow next to **Web Server (IIS)**. Check **FTP Server** and click **Next**. ![Under Server Roles select FTP Server](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows5.png) *Server Roles* Select any additional features you want installed. Once done, click **Next**. ![Select any additional features you want installed. Once done, click Next.](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows6.png) *Features* Review what is being installed. Once ready, click **Install**. ![Confirm Installation](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows7.png) *Confirm* You should then see a progress bar. Once complete, click **Close**. ![Results Pane](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows8.png) *Results Pane* Now FTP is installed. You can not yet connect to your Web Site via FTP. Next, you will need to Add a FTP Publishing to your site. Open IIS, expand your computer, expand Sites, right click on your Web Site and then click on **Add FTP Publishing…** ![Open IIS, expand your computer, expand Sites, right click on your Web Site and then click on Add FTP Publishing](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows9.png) *IIS Manager* Once the Add FTP Site Wizard comes up: - Choose an IP address for your FTP site from the IP address drop-down, or choose to accept the default selection of “All Unassigned.” - Normally, you would enter the TCP/IP port for the FTP site in the port box. For this how-to, choose to accept the default port of 21. - For this how-to, we will not use a host name, so make sure that the Virtual Host box is blank. - Make sure that the Certificates drop-down is set to “Not Selected” and that the No SSL option is selected. - When you have completed these items, click Next. ![Bindings and SSL Settings](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows10.png) *Bindings and SSL Settings* On the Authentication and Authorization Information page: - Select Basic for the Authentication settings. - For the Authorization settings: - Choose “Specified users” from the Allow access to drop-down - Type “administrator” for the user name. - Select Read and Write for the Permissions option. - When you have completed these items, click Finish. ![Authentication and Authorization Information](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows11.png) *Authentication and Authorization Information* Last thing to make sure is if your Windows Firewall has a rule set for FTP default port 21. Open Windows Firewall with Advanced Security by going to Start>Administrative Tools>Windows Firewall with Advanced Security. ![Windows Firewall and Advanced Security](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows12.png) *Administrative Tools* Once opened, click on **Inbound Rules**and then click on **New Rule**under the Actions Pane. ![Windows Firewall and Advanced Security](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows13.png) *Windows Firewall and Advanced Security* The New Inbound Rule Wizard will pop up. You will select Port and click Next. ![New Inbound Rule Wizard Ports](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows14.png) *New Inbound Rule Wizard* Since this is for the default port 21 for FTP, we will use the **TCP** protocol and 21 for the **Specific local ports**. Once done, click Next. ![Since this is for the default port 21 for FTP, we will use the TCP protocol and 21 for the Specific local ports. ](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows15.png) *New Inbound Rule Wizard* In the Action page, we will select to **Allow the connection** and click Next. ![Select to Allow the connection and click Next](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows16.png) *New Inbound Rule Wizard* The next page is the **Profile** page, which we will check all the boxes and then click Next. ![Check all the boxes and then click Next](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows17.png) *New Inbound Rule Wizard* On the Last page, you will need to select a name for the new rule. Here, we will name it “FTP” and then click Finish. ![Select a name for the new rule](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows18.png) *New Inbound Rule Wizard* Now the firewall rule has been added for the default port 21. We can now test FTP connection to the Web Site. In this how-to, I will use FileZilla to show connection but there are many FTP clients out there to download. With FileZilla, we will need to fill in the Host/IP Address, Username, Password and Port # to connect. Earlier, I set up FTP to use a specific user (administrator) and also used the default FTP port 21. Once you hit Connect, you will be connected to your Web Site via FTP! ![2015-02-25 22_03_57-New site 6 - administrator@69.28.94.13 - FileZilla](https://www.atlantic.net/wp-content/uploads/2015/02/ftpwindows19.png) Thank you for reading! Be sure to check back for more updates, and to learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions and [Virtual private servers](https://www.atlantic.net/vps-hosting/). --- # How to install IIS on Windows Server 2008 R2 > URL: https://www.atlantic.net/vps-hosting/how-to-install-iis-windows-server-2008-r2/ | Published: 2015-02-25 | Updated: 2026-03-03 | Author: Atlantic.Net NOC ##### Verified and Tested 02/25/2015 ### Introduction This how-to will show you how to set up Internet Information Services (IIS) 7.0 on a Windows Server 2008 R2. ### Prerequisites A Windows Server with Administrator access. If you do not already have a server, you can spin up a [Windows VPS](https://www.atlantic.net/vps-hosting/) in under 30 seconds with Atlantic.Net. ## Installing IIS on Windows Server 2008 R2 Open the Server Manager by clicking on the **Server Manager** icon located at the bottom left of your task bar. If you are unable to locate the icon, click on the Windows start button, click Control Panel. In Control Panel, click System and Security, and then Administrative Tools and lastly click on **Server Manager**. In the Server Manager, click on Roles and then Add Roles. ![Open Server manager and select add roles](https://www.atlantic.net/wp-content/uploads/2018/01/iis1.png)   The Add Roles Wizard should open and you can click **Next** on the Before you begin section. ![Before You Begin](https://www.atlantic.net/wp-content/uploads/2018/01/iis2.png)   In Server Roles, check the box next to **Web Server (IIS)** and click **Next.** ![Select Web Server (IIS)](https://www.atlantic.net/wp-content/uploads/2018/01/iis3.png)   Click **Next** on the Web Server (IIS) information page unless you would like to read through it. ![Select next in Web Server (IIS) ](https://www.atlantic.net/wp-content/uploads/2018/01/iis4.png)   Review the Role Services being installed, you can install additional ones if you would like. Once ready, click **Next**. ![Add any additional roles you'd like to install.](https://www.atlantic.net/wp-content/uploads/2018/01/iis5.png) Review what is being installed. Once you are ready, click **Install**. ![Confirm installation Selections and select Install](https://www.atlantic.net/wp-content/uploads/2018/01/iis6.png)   You should see a progress bar. Once complete, then you can click on **Close**. ![Installation Results](https://www.atlantic.net/wp-content/uploads/2018/01/iis7.png) IIS 7 is now installed. To open IIS, open Server Manager, expand Roles then Web Server and click on Internet Information Services (IIS) Manager. ![Open server manager and verify IIS Manager has been installed](https://www.atlantic.net/wp-content/uploads/2018/01/iis8.png) You can also open IIS by searching for Inetmgr.exe and pressing Enter or going to Start>All Programs>Administrative Tools>Internet Information Services (IIS) Manager. ### Atlantic.Net Since 1995, Atlantic.Net has been providing internet services to customers. In 20+ years of service, our solutions have been focused on providing the very best in web solutions to our valued customers! [VPS hosting](https://www.atlantic.net/vps-hosting/) is just one of the many hosting services offered by Atlantic.Net – We also offer dedicated, managed and HIPAA-compliant hosting services. Contact us today for more information on any of our services! --- # How to Enable Audio on a Windows Server 2008 R2 > URL: https://www.atlantic.net/vps-hosting/how-to-enable-audio-windows-server-2008-r2/ | Published: 2015-02-26 | Updated: 2026-09-07 | Author: Atlantic.Net NOC ##### Verified and Tested 02/28/2015 ### Introduction Audio is not enabled by default on Windows Server 2008 R2, but it is capable of playing sound. We will learn how to enable audio on your server. ### Prerequisites - Administrative access ## Enabling Audio on Windows Server 2008 R2 First, we need to open **Services** by going to Start>All Programs>Administrative Tools>Services. You can also type “services.msc” in the search bar. ![Open Services by going to Start>All Programs>Administrative Tools>Services. You can also type "services.msc" in the search bar.](https://www.atlantic.net/wp-content/uploads/2018/01/audio1-1.png) Start: Services In Services, scroll down to **Windows Audio** and double click on it. ![Select Windows Audio](https://www.atlantic.net/wp-content/uploads/2018/01/audio2-1.png) Services: Windows Audio The Windows Audio Properties should open up. You will need to change the **Startup Type** to Automatic and then click on **Start** under the Service Status. Once done, click **OK**. ![You will need to change the Startup Type to Automatic and then click on Start under the Service Status. Once done, click OK.](https://www.atlantic.net/wp-content/uploads/2018/01/audio3-1.png) Windows Audio Properties.     We’re not quite done yet. Windows 2008 R2 disables remote audio playback by default. In order to enable this, you will need to enter your **Terminal Services Configuration**. To enter this, click on the **Start** button and search for this exact file: **tsconfig.msc** ![Search for tsconfig](https://www.atlantic.net/wp-content/uploads/2018/01/audio4.png) tsconfig Click on **tsconfig**to run your **Terminal Services Configuration**. Once here, right-click on **RDP-Tcp** under **Connections**and choose **Properties.** ![Click on tsconfig to run your Terminal Services Configuration. Once here, right-click on RDP-Tcp under Connections and choose Properties](https://www.atlantic.net/wp-content/uploads/2018/01/audio5.png) Remote Desktop Session Host Configuration In the properties, click on the **Client Settings** tab and un-check the **Audio and video playback**box under the redirection section. Then click **OK.** ![In the properties, click on the Client Settings tab and un-check the Audio and video playback box under the redirection section. Then click OK.](https://www.atlantic.net/wp-content/uploads/2018/01/audio6.png) RDP-Tcp Properties. Close **Terminal Services Config.**In order for this new setting to take effect, you will need to exit your current Remote Desktop Session. Once you reconnect to your server, audio will be enabled! You can test this by right-clicking on the speaker icon in the bottom-right of your server’s desktop and clicking **Sounds.** ![You can test this by right-clicking on the speaker icon in the bottom-right of your server's desktop and clicking Sounds.](https://www.atlantic.net/wp-content/uploads/2018/01/audio7.png) Test Sounds Click on any of the Windows sounds under **Program Events**and then click the **Test**button. You should hear the chosen sound. ![Click on any of the Windows sounds under Program Events and then click the Test button. You should hear the chosen sound.](https://www.atlantic.net/wp-content/uploads/2018/01/audio8.png) Sound Thank you for following along this how-to, we hoped you have enjoyed it. Please check back here for more updates or [click here to read some other interesting how-to’s for Windows](https://www.atlantic.net/tutorials/). Atlantic.Net offers [VPS hosting](https://www.atlantic.net/vps-hosting/) as well as managed hosting services which include a layer of business-essential managed services to your hosting packages. Contact us today for more information. --- # How to Install Locate on a Debian Cloud Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-locate-debian-vps/ | Published: 2015-02-26 | Updated: 2026-03-03 | Author: Atlantic.Net NOC ##### Verified and Tested 02/25/2015 ### **Introduction** This how-to will show you how to install locate on Debian. Locate command is often the easiest and fastest way to find the location of files and directories. ## Installing locate on Debian Cloud Server The command to install locate on a Debian is: ``` apt-get install locate ``` You are not able to locate anything yet until you have updated the database for locate. Run the below command to do this: ``` updatedb ``` Now, you are able to search for locations of files and directories. Check back for new updates. --- # How to Enable Audio on a Windows Server 2012 R2 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-enable-audio-windows-server-2012-r2/ | Published: 2015-02-26 | Updated: 2024-06-04 | Author: Atlantic.Net NOC ##### Verified and Tested 02/27/2015 ### Introduction This how-to will guide you through enabling audio in your Windows Server 2012 R2. This is a quick and easy process and should take less than five minutes. ## Enabling Audio on Windows Server 2012 R2 First, open **Server Manager** by going to Start>Server Manager. ![Open Server Manager by going to Start>Server Manager.](https://www.atlantic.net/wp-content/uploads/2018/01/audio1.png) Once Server Manager opens, click on **Tools** in the top right of the window and select **Services**. ![In Server Manager Dashboard tools, select Services](https://www.atlantic.net/wp-content/uploads/2018/01/audio2.png) Server Manager Dashboard In the right pane of Services, scroll down to **Windows Audio** and double click on it. In Windows Audio Properties, change **Startup Type** to Automatic and click on **Start** under Service Status. Once done, click **OK**. ![In Windows Audio Properties, change Startup Type to Automatic and click on Start under Service Status. Once done, click OK.](https://www.atlantic.net/wp-content/uploads/2018/01/audio3.png) Now you have audio enabled! Come back and check for new updates. Atlantic.Net offers [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) backed by World-class [VPS hosting](https://www.atlantic.net/vps-hosting/) infrastructure gives you the freedom to choose the plans that best fit your needs. Contact us today for more information. --- # How to Install Nginx in Debian 7 > URL: https://www.atlantic.net/vps-hosting/how-to-install-nginx-debian-7/ | Published: 2015-02-26 | Updated: 2024-06-06 | Author: Jose Velazquez ##### Verified and Tested 02/26/15 ## Introduction This how-to will help you with your Debian 7 installation to successfully run an outstanding performance-based web server while easing the load of your system resources. Nginx is a powerful web server software that can be used on your server. It is also known for its high performance and low memory usage, which will allow fewer resources to be used but get the job done efficiently. ## What Do You Need? You need a Debian 7 server that is configured with a static IP address. If you do not have a server already, you can visit our [VPS Hosting](https://www.atlantic.net/vps-hosting/) page and spin a new server up in under 30 seconds. ## Server Preparation To get started, log in to your Debian 7 via SSH or the VNC Console in cloud.atlantic.net. Atlantic.Net Cloud servers are set up as minimal installations to avoid having unnecessary packages from being installed and never used.  Because of this, let’s make sure that your server is fully up-to-date. `sudo apt-get update ` With the server up-to-date, we can continue the installation process of your server. ## Install Nginx To install Nginx, we will need to use the apt-get  command so we can install the software: `sudo apt-get install nginx` You will now have NGINX installed on your server and can be verified by typing in the following with your IP ADDRESS on your browser. Your IP could be retrieved from the server with the following command: `ifconfig eth0 | grep inet | awk '{ print $2 }'` ![This is the default webpage when installing Nignx on Debian 7](https://www.atlantic.net/wp-content/uploads/2018/01/Install-nginx-in-debian-7.jpg) This is the default webpage when installing Nginx on Debian 7   ## What Next? You now have your Debian 7  server with Nginx installed, and you may begin building high-performance websites using your newly installed web server. Thank you for following along in this How-To, and feel free to check back with us for any new updates soon! Check out our [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Locate on a Fedora Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-locate-fedora-vps/ | Published: 2015-02-26 | Updated: 2023-11-18 | Author: Atlantic.Net NOC ##### Verified and Tested 02/25/2015 ### **Introduction** The Locate command is often the easiest and fastest way to find the location of files and directories. This how-to will show you how to install locate on a Fedora server. ## Installing locate on Fedora Cloud Server The command to install locate on a Fedora is: ``` yum install mlocate ``` You are not able to locate anything yet until you have updated the database for locate. Run the below command to do this: ``` updatedb ``` Now, you can search for locations of files and directories. Check back for new updates.     Learn more about Atlantic.Net’s [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Locate on CentOS Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-locate-centos-server/ | Published: 2015-02-26 | Updated: 2024-06-06 | Author: Atlantic.Net NOC ##### Verified and Tested 02/25/2015 ### Introduction This how-to will show you how to install locate on a CentOS server. This command is often the easiest and fastest way to find the location of files and directories, and this is very useful when you’re working on a Linux system for which you are not well acquainted. When you install mlocate, it will install the two commands: locate and updatedb. It will also install a cron job that updates the database daily. ## Installing Locate on CentOS a Cloud Server The command to install locate on a CentOS is: **yum install mlocate** You are not able to locate anything yet until you have updated the database for locate. Run the below command to do this: **updatedb** The cronjob will update the database daily, but if you are installing many files and need to search for them, you should use the updatedb command again. Now, you can search for locations of files and directories. For example, if you forget the location of ifcfg-eth0 you would run the command: `locate ifcfg-eth0` ![Sample locate command](https://www.atlantic.net/wp-content/uploads/2018/01/anet-HowtoInstalLocateonCentOS-01.png) Sample locate command Congratulations! You may be interested in using the “find” command; alternatively, check out [Linux Find Command](https://www.atlantic.net/dedicated-server-hosting/how-to-use-linux-find-locate-commands/). Check back for new updates. --- # How to Setup FTP Server with VSFTPD on Debian 12 > URL: https://www.atlantic.net/vps-hosting/how-to-install-vsftpd-debian-vps/ | Published: 2015-02-26 | Updated: 2025-09-07 | Author: Atlantic.Net NOC File Transfer Protocol (FTP) is one of the oldest and most reliable ways to transfer files between computers over a network. Although newer methods like SFTP and cloud-based solutions are popular today, FTP remains widely used for sharing files, hosting websites, and providing remote access to directories in controlled environments. In this tutorial, we will show you how to set up FTP server with VSFTPD on Debian 12 server. ## Step 1 – Install VSFTPD Debian 12 includes VSFTPD in its default package repository, so installation is straightforward. Start by updating the package index and installing the vsftpd package. 1. Install the VSFTPD package. ``` apt install vsftpd -y ``` 2. Once installed, verify the version to confirm a successful setup. ``` vsftpd -version ``` Output. ``` vsftpd: version 3.0.3 ``` This confirms that VSFTPD is installed correctly on your Debian 12 system. ## Step 2 – Manage VSFTPD Service After installation, VSFTPD runs as a systemd service. You need to start it, enable it to run at boot, and check its status to make sure everything is working correctly. 1. Start the VSFTPD server. ``` systemctl start vsftpd ``` 2. Enable VSFTPD to start automatically when the system boots. ``` systemctl enable vsftpd ``` 3. Check the status of VSFTPD service. ``` systemctl status vsftpd ``` If everything is set up properly, you should see output similar to this: ``` ● vsftpd.service - vsftpd FTP server Loaded: loaded (/lib/systemd/system/vsftpd.service; enabled; preset: enabled) Active: active (running) since Sun 2025-09-07 06:30:32 CAT; 20s ago Process: 19885 ExecStartPre=/bin/mkdir -p /var/run/vsftpd/empty (code=exited, status=0/SUCCESS) Main PID: 19886 (vsftpd) Tasks: 1 (limit: 4620) Memory: 884.0K CPU: 6ms CGroup: /system.slice/vsftpd.service └─19886 /usr/sbin/vsftpd /etc/vsftpd.conf Sep 07 06:30:32 debian12 systemd[1]: Starting vsftpd.service - vsftpd FTP server... Sep 07 06:30:32 debian12 systemd[1]: Started vsftpd.service - vsftpd FTP server. ``` ## Step 3 – Configure VSFTPD The main configuration file for VSFTPD is stored at /etc/vsftpd.conf. Before making any changes, it’s a good practice to create a backup copy of the original file. 1. Backup the configuration file. ``` cp /etc/vsftpd.conf /etc/vsftpd.conf.orig ``` 2. Now, open the configuration file in a text editor. ``` nano /etc/vsftpd.conf ``` Replace or adjust the contents with the following lines. ``` listen=YES listen_ipv6=NO connect_from_port_20=YES anonymous_enable=NO local_enable=YES write_enable=YES allow_writeable_chroot=YES chroot_local_user=YES secure_chroot_dir=/var/run/vsftpd/empty pam_service_name=vsftpd pasv_enable=YES pasv_min_port=40000 pasv_max_port=45000 userlist_enable=YES userlist_file=/etc/vsftpd.userlist userlist_deny=NO ``` 3. After saving the file, restart VSFTPD to apply the changes. ``` systemctl restart vsftpd ``` ## Step 4 – Create FTP User Now that the server is configured, you need to create a dedicated FTP user who will have access to the server. 1. Run the following command to create a new user account. ``` adduser ftpuser ``` You will be asked to set a password and provide optional details (full name, phone, etc.). You can press Enter to skip the optional fields. 2. Since you enabled **userlist_enable=YES** in the configuration, only users listed in **/etc/vsftpd.userlist** will be allowed to log in. Add the new user to that list. ``` echo "ftpuser" | tee -a /etc/vsftpd.userlist ``` 3. Restart the VSFTPD service so the changes take effect. ``` systemctl restart vsftpd ``` ## Step 5 – Install FTP Client (FileZilla) and Test the Connection To verify that your FTP server is working correctly, you can use an FTP client. One of the most user-friendly tools available on Linux is FileZilla. 1. Install FileZilla on the client machine. ``` apt install filezilla -y ``` 2. Launch FileZilla. ![](https://www.atlantic.net/wp-content/uploads/2015/02/f1.png) 3. In the FileZilla interface: Enter the following details. **Host:** your server’s IP address (e.g., 192.168.1.100) **Username:** ftpuser **Password:** the password you set when creating the FTP user **Port:** 21 Click **Quickconnect.** 4. If the setup is correct, FileZilla will connect to your FTP server. You should see the ftpuser home directory (/home/ftpuser) in the remote site panel. ## Conclusion In this tutorial, you set up an FTP server on Debian 12 using VSFTPD (Very Secure FTP Daemon). Although the server works, keep in mind that FTP by default transmits data, including usernames and passwords, in plain text. For production use, you should enable FTPS (FTP over SSL/TLS) to encrypt your connections, configure a firewall to allow only the necessary ports such as 21 and the passive port range, use strong user passwords to defend against brute-force attacks, and regularly monitor logs located in /var/log/vsftpd.log for suspicious activity./ --- # How to Install VSFTPD on an Ubuntu Cloud server > URL: https://www.atlantic.net/vps-hosting/how-to-install-vsftpd-ubuntu-cloud-server-vps/ | Published: 2015-02-26 | Author: Atlantic.Net NOC ##### Verified and Tested 06/01/2021 ### Introduction VSFTPD (very secure file transfer protocol daemon) is a popular way to transfer files between your computer and a remote computer. In this article, we will install vsftpd on an Ubuntu 20.04. ### Prerequisites Root access to the server ## Installing VSFTPD on Ubuntu Cloud Server First, we will install vsftpd using the below command: ``` apt-get install vsftpd ``` Vsftpd is installed now, but we need to configure it in /etc/vsftpd.conf using your favorite text editor. I will use nano here. ``` nano /etc/vsftpd.conf ``` Once inside, you will need to change a couple of things. Below are the ones to change and why we will be changing them*.* ``` anonymous_enable=NO ``` This will disable the ability for users to log in anonymously ``` local_enable=YES ``` Since we disabled anonymous logins, we need to enable user logins that use the local authentication files. ``` write_enable=YES ``` This will enable users to make changes to the filesystem. ``` chroot_local_user=YES ``` This will restrict users to have access only to their home directories. Save and close the file, then restart the VSFTPD service to apply the changes: ``` systemctl restart vsftpd ``` After this is done, you can save and close the file. ## **Adding FTP User** Next, we have to create an FTP user. I will use the user “atlantic” in this example, but you can use any username. To add a user, run the following command. ``` adduser atlantic ``` Enter a password for the user and fill the rest out if you would like. You can also press enter through the rest. You must provide root ownership to the user’s home directory now. ``` chown root:root /home/atlantic ``` Next, for the user to upload files, we need to create a directory under their home directory. ``` mkdir /home/atlantic/folder ``` Then provide the user with this directory. ``` chown atlantic:atlantic /home/atlantic/folder ``` Now, this user is set up to log in and upload files to their folder directory. To access your server via FTP over the web, type the following in your browser: **ftp://** You will now be prompted to input your username and password. All Done! Check back for more updates from Atlantic.Net, or learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) options.  See our [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install LEMP In Debian 7 > URL: https://www.atlantic.net/vps-hosting/how-to-install-lemp-debian-7/ | Published: 2015-02-26 | Updated: 2024-06-06 | Author: Jose Velazquez ##### Verified and Tested 02/26/15 ### **Introduction** In this How-To, we will walk you through the LEMP install on your Debian 7 Cloud Server. LEMP is simply a software bundle that consists of 4 components. L (Linux) is the core of the platform, which will sustain the other components. E(Nginx)will be used for the web service. M(MySQL)will be used for database management, and P(PHP) will be the programming language. It is making the platform a LEMP. ### **Prerequisites** A cloud server with Debian already installed (which will take care of the L(Linux) aspect of the LEMP install).  If you do not already have a server, why not spin up a [Linux VPS](https://www.atlantic.net/vps-hosting/) Server from Atlantic.Net ## **Installing LEMP on Debian 7** Install Nginx with the following command to begin the install: ``` apt-get install nginx ``` Start nginx with the following command: ``` service nginx start ``` Verify if all is working by typing HTTP: //YOUR.IP.ADD.RESS ![Installing LEMP in Debian-1](https://www.atlantic.net/wp-content/uploads/2018/01/nginx1-2.jpg) Install MySQL with the following command to begin the install and set a MySQL root password: ``` apt-get install mysql-server ``` ![Installing LAMP in Debian-1](https://www.atlantic.net/wp-content/uploads/2018/01/nginx2-2.jpg) Secure MySQL from the default settings with the following command: ``` mysql_secure_installation ``` Note: You will be prompted with a series of questions. Type N for the change root password and Y for yes on all of them, see the screenshot below: ![Installing LAMP in Debian-2](https://www.atlantic.net/wp-content/uploads/2018/01/nginx3-2.jpg) Install PHP with the following command to begin the install: ``` apt-get install php5 php5-fpm php5-mysql ``` Then we must move the original sites file for backup purposes to a new file name: ``` mv /etc/nginx/sites-available/default /etc/nginx/sites-available/default.old ``` ``` nano /etc/nginx/sites-available/default ``` Copy the following into your text editor: ``` server { listen 80; server_name your_site_name.com; root /var/www/html; index index.php index.html index.htm index.nginx-debian.html; location / { try_files $uri $uri/ =404; } error_page 404 /404.html; error_page 500 502 503 504 /50x.html; location = /50x.html { root /var/www/html; } location ~ \.php$ { try_files $uri =404; fastcgi_pass unix:/var/run/php5-fpm.sock; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } } ``` Create a simple PHP page to test by using a text editor of your choice: ``` nano /var/www/html/info.php ``` Insert the following code in the space, then save and exit: ``` ``` We will need to restart Nginx, so all changes are updated. ``` service nginx restart ``` ![Installing LAMP in Debian-3](https://www.atlantic.net/wp-content/uploads/2018/01/nginx4.jpg) Congratulations! You have just installed LEMP on your Debian Cloud Server. Thank you for following along in this How-To, and check back with us for any new updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How To Install Apache in FreeBSD > URL: https://www.atlantic.net/vps-hosting/how-to-install-apache-freebsd/ | Published: 2015-02-26 | Updated: 2023-11-17 | Author: Jose Velazquez ##### Verified and Tested 02/26/15 ## Introduction This how-to will help you with your install and configuration of Apache on your FreeBSD server. Apache is a web server that is very popular in Linux systems and over the Internet. It is used by many Web Hosting companies worldwide because of its popularity and efficiency in hosting sites over the World Wide Web. ## Server Preparation To get started, log in to your FreeBSD via SSH or the VNC Console in cloud.atlantic.net. Atlantic.Net Cloud servers are set up as minimal installations to avoid having unnecessary packages from being installed and never used.  Because of this, let’s make sure that your server is fully up-to-date. `freebsd-update fetch freebsd-update install` ## **Installing Apache on FreeBSD** Install Apache with the following command: `pkg install apache24` To ensure that Apache will start automatically upon reboot, type the following command: `sysrc apache24_enable=yes` Start Apache with the following command: `service apache24 start` Verify if all is working by typing HTTP:  //YOUR.IP.ADD.RESS Your IP could be retrieved from the server with the following command: ![Installing Apache in FreeBSD-1](https://www.atlantic.net/wp-content/uploads/2015/02/Installing-Apache-in-FreeBSD-1-e1635013239440.jpg) This is the default page in FreeBSD after Apache has been installed. `ifconfig` ## What Next? With that, you now have a server installed and configured with Apache. You may now continue building your website. Thank you for following along, and feel free to check back with us for further updates. Check out our [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install VSFTPD on a CentOS Cloud Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-vsftpd-centos-vps/ | Published: 2015-02-26 | Updated: 2023-11-18 | Author: Atlantic.Net NOC ##### Verified and Tested 02/25/2015 ### Introduction VSFTPD (very secure file transfer protocol daemon) is a popular way to transfer files between your computer and a remote computer. In this article, we will install vsftpd on a CentOS cloud server. ## Installing VSFTPD on CentOS First, we will install vsftpd using the below command: ``` yum install vsftpd ``` Vsftpd is installed now, but we need to configure it in /etc/vsftpd.conf using your favorite text editor. I will use nano here. ``` nano /etc/vsftpd/vsftpd.conf ``` Once inside, you will need to change a couple of things. Below are the ones to change and why we will be changing them*.* ``` anonymous_enable=NO ``` This will disable the ability for users to log in anonymously ``` local_enable=YES ``` Since we disabled anonymous logins, we need to enable user logins that use the local authentication files. ``` write_enable=YES ``` This will enable users to make changes to the filesystem. ``` chroot_local_user=YES ``` This will restrict users to have access only to their home directories. After this is done, you can save and close the file. ``` Adding FTP User ``` Next, we have to create an FTP user. I will use the user “atlantic” in this example, but you can use any username. To add a user, run the following command. ``` adduser atlantic ``` Create a password for the user. ``` passwd atlantic ``` Now, this user is set up to log in. To access your server via FTP over the web, type the following in your browser: ftp:// You will now be prompted to input your username and password. All Done!   Check back for more updates from Atlantic.Net, or learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) options and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Apache In Fedora 20 > URL: https://www.atlantic.net/vps-hosting/how-to-install-apache-fedora-20/ | Published: 2015-02-27 | Updated: 2024-06-05 | Author: Jose Velazquez ##### Verified and Tested 02/27/15 ### **Introduction** In this How-To, we will walk you through the install of Apache in your Fedora 20 Cloud Server. Apache is a web server that is very popular in Linux systems and over the Internet. It is used by many Web Hosting companies worldwide because of its popularity and efficiency in hosting sites over the World Wide Web. ### **Prerequisites** A cloud server with Fedora 20 already installed.  If you don’t already have a server, please spin up a market-leading virtual private server in under 30 seconds. ## **Installing Apache in Fedora 20** Install Apache with the following command: ``` yum install httpd ``` Start Apache with the following command: ``` systemctl start httpd.service ``` You will want the Apache service to start on start-up/reboot with the following command: ``` systemctl enable httpd.service ``` Add the following commands in Apache to override in Firewall-cmd as follows: ``` firewall-cmd --set-default-zone=public ``` ``` firewall-cmd --permanent --zone=public --add-service=http ``` ``` firewall-cmd --permanent --zone=public --add-service=https ``` ``` firewall-cmd --reload ``` You can now verify that Apache is installed correctly by typing http:// and your IP on your browser. HTTP:  //YOUR.IP.ADD.RESS You should see the following screenshot in your browser: ![Fedora Test Page](https://www.atlantic.net/wp-content/uploads/2018/01/Installing-Apache-in-Fedora20.jpg) Fedora Test Page Congratulations! You have just installed Apache on your Fedora 20 Cloud Server. Thank you for following along in this How-To, and check back with us for any new updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to: Common Tasks In A Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-common-tasks-windows-server-2012/ | Published: 2015-02-27 | Updated: 2024-06-05 | Author: Ariel Beltre ##### Verified and Tested 2/27/2015 ### Introduction In this article, we will be reviewing a few common tasks that can be performed in your Windows 2012 server. Many administrators find themselves having trouble performing basic functions because the interface in Windows 2012 is so different from what they are used to. We will go over what some of these tasks are and how to complete them. ### Prerequisites A server with Windows 2012 already installed. ## How to reboot Windows Server 2012 Some administrators have a tough time figuring out how to reboot their server in Windows 2012. This is mainly due to the absence of the Start menu and also the shutdown option that has always existed on the start menu. To power down or reboot your server, move your mouse to the upper right-hand corner of the screen. Once done, Windows will display a series of icons along the right side of the screen. Click the Settings icon, and you will be taken to the Settings page, shown below. The bottom row of icons includes a power button. You can use this option to shut down or reboot the server. ![You can use this option to shutdown or reboot the server.](https://www.atlantic.net/wp-content/uploads/2018/01/windows1-768x598.png) Start: Power ## Accessing the Control Panel in Windows Server 2012 There are several different ways to access the control panel. Here, we will go over the two most common methods. The first method is to use the same set of icons explained in the previous step. Move your mouse to the upper right corner of the screen, and click on settings.  When the settings page appears, click on the Control Panel link. Another way to access the Control Panel is by going into Desktop mode and then moving your mouse to the lower-left corner of the screen. Once done, the start tile will appear. Right-click on this tile, and a menu will appear. This menu will contain an option to access the Control Panel. ## Accessing the Administrative Tools in Windows Server 2012 In Windows Server 2008 and 2008 R2, you can access the Administrative Tools by clicking on the start icon, going to All Programs, and clicking the Administrative Tools option. Since we know the start menu does not exist, you have to access the Administrative Tools differently. In Windows Server 2012, there is a couple of different ways to access the Administrative Tools, and one method involves using the server manager. As you can see below, the server manager’s tools menu contains all of the Administrative Tools that you are probably familiar with from Windows Server 2008. ![Open Server manager and select tools.](https://www.atlantic.net/wp-content/uploads/2018/01/windows2-878x682.png) Server Manager: Tools Sometimes Administrators might prefer not to go into the server manager every time they need to access an administrative tool. It would make it a lot easier if the tools were accessible from the start screen, and Thankfully, it is pretty easy to make that happen. To do so, make sure that you are looking at the Windows start screen. Please keep in mind that this technique WILL NOT work if you are in desktop mode. Now, move your mouse to the upper right corner of the screen, and click on the Settings icon. When the settings page appears, click on the Tiles link. As you can see below, there is a slide bar that you can use to control whether or not the administrative tools are shown on the start screen. ![Move your mouse to the upper right corner of the screen, and click on the Settings icon. When the settings page appears, click on the Tiles link. As you can see below, there is a slide bar that you can use to control whether or not the administrative tools are shown on the start screen.](https://www.atlantic.net/wp-content/uploads/2018/01/windows3-878x683.png) Start: Administrative Tools ## Accessing Your Applications in Windows Server 2012 One of the most frustrating aspects of the new interface is that applications are no longer bound to a centralized start menu. Some administrators have found that after upgrading from a previous version of Windows Server, their start screen only contains a small subset of the items that previously resided on their server’s start screen. These missing items still exist, and you just have to know where to look for them. To access all of the tiles that the start screen is hiding, click the small arrow at the bottom portion of the screen, as shown below. ![Click the small arrow at the bottom portion of the screen, as shown below.](https://www.atlantic.net/wp-content/uploads/2018/01/windows4-878x684.png) Start: Apps Once done, you will be taken to an apps screen similar to the one shown below. As you can see, the apps are categorized like how they might have been on the start menu. Apps are categorized like how they might have been on the start menu. ## The Run Prompt and the Command Line in Windows Server 2012 The run prompt and the command prompt are both easily accessible. To reach these items, navigate to your start screen. Once done, move your mouse to the lower-left corner of the screen. When the start tile appears, right-click on it, and you will see a menu listing option for run, command prompt, and command prompt (ADMIN). ![Move your mouse to the lower left corner of the screen. When the start tile appears, right click on it and you will see a menu listing options for run, command prompt, and command prompt (ADMIN).](https://www.atlantic.net/wp-content/uploads/2018/01/windows5-878x683.png) Start: Tools ## Changing Administrator Password in Windows Server 2012 To change the Administrator password, you must first access the server via a remote desktop. Once at the Start screen, click on Administrative Tools. This will open the Administrative Tools window from which you will want to double-click on Computer Management. Once done, expand Local Users and Groups, and click on Users from the drop-down. From here, you should see two options for Administrator and Guest, as shown below. Right-click on Administrator, and then click on Set Password > Proceed. Type your new password in both fields, then press OK. ![Front the computer management page, select Users from Local Users and Groups, then right click your user and select Set Password.](https://www.atlantic.net/wp-content/uploads/2018/01/windows6-878x694.png) Computer Management: Administrator ### Conclusion Although the interface may be confusing at first, the vast majority of the available items in the Windows Server 2008 R2 interface still exist. You just have to know where they are located. ## Atlantic.Net Atlantic.Net offers [VPS hosting](https://www.atlantic.net/vps-hosting/) and [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) services, which include a layer of business-essential managed services to your hosting packages. Contact us today for more information. --- # How to Enable Ping on Windows Server 2008 R2 > URL: https://www.atlantic.net/vps-hosting/how-to-enable-ping-windows-server-2008-r2/ | Published: 2015-02-27 | Updated: 2024-06-05 | Author: Atlantic.Net NOC ##### Verified and Tested 02/28/2015 ### Introduction In this how-to, we will learn how to enable ping on a Windows Server 2008 R2. ### Prerequisites Administrator control ## Enabling Ping on Windows Server 2008 R2 First, we will need to open Windows Firewall with Advanced Security. To do this, go to Start>All Programs>Administrative Tools>Windows Security with Advanced Security. ![Start>All Programs>Administrative Tools>Windows Security with Advanced Security.](https://www.atlantic.net/wp-content/uploads/2018/02/ping1.png) Once opened, click on **Inbound Rules** at the top left. Scroll down and select **File and Printer Sharing (Echo Request – ICMPv4 – In)**. Once selected, click on **Enable Rule**. ![Once opened, click on Inbound Rules at the top left. Scroll down and select File and Printer Sharing (Echo Request - ICMPv4 - In). Once selected, click on Enable Rule. />

When the rules are enabled, you will now be able to ping your server IP address. Come back and check for new updates.

 

Learn more about our URL: https://www.atlantic.net/vps-hosting/how-to-centos-7-creating-larger-2tb-partition-parted/ | Published: 2015-02-27 | Updated: 2023-11-16 | Author: Andrew Mora ##### Verified and Tested 04/04/21 ### Introduction This article will explain how to add two 3TB hard drives to an [existing CentOS 7 system](https://www.atlantic.net/blog/) using PARTED and place them into a RAID1 software raid mirror. PARTED, like fdisk, is a utility used to manipulate hard disk partitions. One advantage it has over fdisk is that it can handle provisioning disks whose volumes will span larger than ~1.9 TB in size. ## Creating 2TB or Larger Partition with PARTED We have to partition the drives using PARTED; regular fdisk can’t do it (it doesn’t know how to handle anything over 1.9 TB) and mark the drives as GPT. We then use MDADM to create the software raid mirror. For the example, the two new 3TB drives will be /dev/sdb and /dev/sdc Partition disks using PARTED ``` parted -a optimal /dev/sdb ``` This will load you into the Parted CLI on /dev/sdb. Run the following commands to make the disk GPT: ``` mklabel gpt ``` You should get a warning that says: ``` Warning: The existing disk label on /dev/sdb will be destroyed and all data on this disk will be lost.Do you want to continue? Yes/No? ``` Type `Y` and then run the following command to make your /dev/sdb disk set to ext4 and a primary disk starting at 0% and fill to 100%: ``` mkpart primary ext4 0% 100% ``` To see the partition that you made information, use the following command: ``` print ``` Depending on your setup, you will get something similar to the following: ``` Model: Msft Virtual Disk (scsi) Disk /dev/sdb: 3TB Sector size (logical/physical): 512B/512B Partition Table: gpt Number Start End Size File system Name Flags 1 1049kB 3TB 3TB primary raid ``` To flag your partition as Raid, run the following command:**** ``` set 1 raid on ``` Perform the same procedure above for /dev/sdc. Tell mdadm to create a RAID device called /dev/md0 by running the following command: ``` mdadm --create /dev/md0 --level=1 --raid-devices=2 /dev/sdb1 /dev/sdc1 ``` ``` mdadm: Note: this array has metadata at the start and may not be suitable as a boot device. If you plan to store '/boot' on this device please ensure that your boot-loader understands md/v1.x metadata, or use --metadata=0.90 Continue creating array? ``` Read the warning and hit `Y` and you should get an output like the following: ``` mdadm: Defaulting to version 1.2 metadata mdadm: array /dev/md0 started. ``` Wait for the system to complete the sync process. Once completed, create a new directory and mount your new MD device. To view your current partition set up run the following command: ``` cat /proc/mdstat ``` You should get an output like the following: ``` Personalities : [raid1] md0 : active raid1 sdc1[1] sdb1[0] 10475392 blocks super 1.2 [2/2] [UU] ``` Create a new raid 1 directory by running: ``` mkdir /raid1 ``` Then mount your Raid to your new raid 1 directory ``` mount /dev/md0 /raid1/ ``` Next, we need to update fstab and mdadm.conf With your favorite editor, open /etc/fstab and add the following to the last line of fstab file. ``` /dev/md0 /raid1 ext4 defaults 0 0 ``` It should look similar to the following once done ``` # # /etc/fstab # Created by anaconda on Fri Jun 20 09:39:24 2014 # # Accessible filesystems, by reference, are maintained under '/dev/disk' # See man pages fstab(5), findfs(8), mount(8) and/or blkid(8) for more info # UUID=bfc860b0-9d1c-41e9-984f-83166f20dc03 / ext4 defaults 1 1 UUID=e136ebe6-f2b8-4098-bd16-11a1fa6044e2 /boot ext4 defaults 1 2 UUID=911f21eb-7500-41cd-9c0d-e2d4ab822b55 swap swap defaults 0 0 tmpfs /dev/shm tmpfs defaults 0 0 devpts /dev/pts devpts gid=5,mode=620 0 0 sysfs /sys sysfs defaults 0 0 proc /proc proc defaults 0 0 /dev/md0 /raid1 ext4 defaults 0 0 ``` Update madam with the following command: ```  mdadm --detail --scan > /etc/mdadm.conf ``` Congratulations! You’ve created a new RAID1 device using MDADM with GPT partitioning. Thank you for following along with this how-to! Please check back here for more updates and to learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. See our [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # Atlantic.Net Cloud – How To Add An Additional Public IP to your Atlantic.Net Cloud Server > URL: https://www.atlantic.net/vps-hosting/atlantic-net-cloud-how-to-add-an-additional-public-ip-to-your-atlantic-net-cloud-server/ | Published: 2015-02-27 | Updated: 2025-08-04 | Author: Alexander Wise ##### **Verified and Tested 02/28/2015** ## Introduction This how-to will show you how to add an additional public IP to your Atlantic.Net Cloud Server. Many services on a server might ask for or require additional public IPs to work correctly. Creating private name servers, websites with SSLs, email generation, splitting services to different public IPs. The list goes on and on, and we encourage you to get more IPs and use them as you need. ## Adding an additional Public IP address to your Cloud Server You must be logged into your Atlantic.Net Cloud Control Panel at cloud.atlantic.net. Navigate to the “Public IPs” section of the cloud control panel. ![Login- Simply navigate to the "Public IPs" section](https://www.atlantic.net/wp-content/uploads/2015/02/anet-cloud-public-01-e1635012631190.png) From there, select “Reserve IP” and choose the location that matches the server you will be assigning the IP to. ![select "Reserve IP"](https://www.atlantic.net/wp-content/uploads/2015/02/public-2-300x192.png) To assign the IP to a server, click its check box and click “Assign IP.” ![click "Assign IP."](https://www.atlantic.net/wp-content/uploads/2015/02/anet-cloud-public-01-1.png) Be sure to select the server you want to assign the IP to, and then click Assign IP. ![Assign IP](https://www.atlantic.net/wp-content/uploads/2015/02/public-4-e1635012683276.png) Keep in mind that you will still need to add the IP manually to the server’s network interface. We will go over that in another How-To based on your OS choice. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Add an Additional Public IP address to Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-add-an-additional-public-ip-address-to-windows-server-2012/ | Published: 2015-02-28 | Updated: 2025-08-04 | Author: Alexander Wise ##### **Verified and Tested 02/28/2015** ## Introduction This how-to will show you how to add an additional IP address to Windows Server 2012. Many services on a server might ask for or require an additional public IP address to work correctly, such as creating private name servers, websites with SSLs, email generation, splitting services to different public IPs. ## Prerequisites You must first reserve and assign an additional public IP to your Windows Server 2012. For that guide, please visit 0ur [tutorials](https://www.atlantic.net/tutorials/) page. ## Adding an additional Public IP address to Windows Server 2012 Now, you want to log into your server. Open up the Networking and Sharing Center so we can edit the Network Interface. For that guide, please visit [How to open network sharing center windows server 2012](https://www.atlantic.net/vps-hosting/how-to-open-network-sharing-center-windows-server-2012/) Make sure to click on “Change adapter settings” if you have not done so already.   ![Adding an additional Public IP address to Windows Server 2012](https://www.atlantic.net/wp-content/uploads/2021/03/anet-windows-2008r2-public-ip-adapter-settings.png) Change adapter settings Click on Local Area Connection. Notice it highlights blue and adds some options in the above line. Let’s click on “Change settings of this connection.” ![Control Panel : Network Connection. Change settings of this connection](https://www.atlantic.net/wp-content/uploads/2021/03/anet-windows-2008r2-public-ip-local-area-connection.png) Control Panel: Network Connection Now double click on “Internet Protocol Version 4 (TCP/IPv4)”. If you do not like to double click, then select it and click “Properties.” ![Internet Protocol Version 4 (TCP/IPv4)](https://www.atlantic.net/wp-content/uploads/2021/03/anet-windows-2008r2-public-ip-ipv4.png) Internet Protocol Version 4 (TCP/IPv4) Since this is an additional IP address, we are going to click on “Advanced.” ![Internet Protocol Version 4 (TCP/IPv4), click on advanced](https://www.atlantic.net/wp-content/uploads/2021/03/anet-windows-2008r2-public-ip-properties.png) Internet Protocol Version 4 (TCP/IPv4) We are almost done. Now under the top section “IP addresses” click “Add…”. ![IP Settings, click add](https://www.atlantic.net/wp-content/uploads/2021/03/anet-windows-2008r2-public-ip-ip-settings-add.png) IP Settings Now, we are going to use the info that was provided in the Public IP section for the IP we reserved and Assigned. ![Manage Additional IPs](https://www.atlantic.net/wp-content/uploads/2021/03/PublicIP2008-6.png) Manage Additional IPs ![IP Address- manage](https://www.atlantic.net/wp-content/uploads/2021/03/anet-windows-2008r2-public-ip-tcp-ip.png) IP Address Press OK four times to return you to the Network Connections screen. Now, you can check to see if it is configured correctly. Right-click on Local Area Connection, click on Status, Click on Details…, and look at the multiple IPv4 Addresses and the Subnet mask for each one. ![Details and Status](https://www.atlantic.net/wp-content/uploads/2021/03/anet-windows-2008r2-public-ip-status.png) Status Learn more about Atlantic.Net’s [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](ttps://www.atlantic.net/vps-hosting/pricing/). --- # How to Open Network and Sharing Center in Windows Server 2008 > URL: https://www.atlantic.net/vps-hosting/how-to-open-network-sharing-center-windows-server-2008/ | Published: 2015-02-28 | Updated: 2024-06-06 | Author: Atlantic.Net NOC ##### **Verified and Tested 02/28/2015** ## **How to open Network and Sharing Center in Windows Server 2008** This guide will show you how to get to the Network and Sharing Center to edit your Network Interfaces. We usually use this to get to the Network Connections for configuration. ### **How do I do it?** Because this is Windows, there are many different ways to do this, and I will share some of the easiest ways to do it. Feel free to comment about this guide if you know another easy way that I overlooked! Most Servers will have the Network Monitor icon visible by default. ![Right click and select properties in the newtork tray icon](https://www.atlantic.net/wp-content/uploads/2018/01/server1-2.png) Network Tray Icon Right-click this and then click on “Open Network and Sharing Center.” The next option is to use search from the Start menu. Click on the Start button, and type one of the main words, “Network,” “Sharing,” “Center.” “Sharing” and “Center” will have the fewest options that pop up, so they will be your best bet, but any one of these will work. ![Search for network](https://www.atlantic.net/wp-content/uploads/2018/01/server2-2.png) Start Menu: Search If you already have the Server Manger open (see below), you can bypass the Network and Sharing Center. Click on “View Network Connections.” ![In server manager select view network connections.](https://www.atlantic.net/wp-content/uploads/2018/01/server3-2.png) Server Manager: View Network Connections Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Open Network and Sharing Center in Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-open-network-sharing-center-windows-server-2012/ | Published: 2015-02-28 | Updated: 2025-12-17 | Author: Atlantic.Net NOC ### Introduction The **Network and Sharing Center** is one of the most important tools in Windows Server. You use it to manage network adapters, change IP addresses, configure DNS, and troubleshoot connectivity issues. In this guide, you’ll learn **how to open the Network and Sharing Center in Windows Server 2008, 2012, 2016, 2019, 2022, and 2025**, using the easiest and fastest methods for each version. This tutorial focuses on **practical steps**, not theory, so you can get where you need to go without confusion. ## What Is the Network and Sharing Center? The Network and Sharing Center is the central place where you can: - View active network connections - Open **Network Connections** (Ethernet adapters) - Change IPv4 and IPv6 settings - Configure DNS and gateway values - Diagnose network problems Most administrators open it when they need to **edit network interfaces**, especially on servers with static IP addresses. ## Opening the Network and Sharing Center in Windows Server There are many different ways to do this; however, I will share some of the easiest ways. Feel free to comment about this guide if you know another easy way that I overlooked! ## Method 1: Using the Network Tray Icon (Quickest Way) Most Servers will have the Network Monitor icon visible by default. ![Sample Tray Icon](https://www.atlantic.net/wp-content/uploads/2018/01/open1.png) Sample Tray Icon Right-click this and then click on “Open Network and Sharing Center.” ## Method 2: Using the Start Screen (Recommended) **1. For Windows Server 2008, 2012 and 2016** The next option is to use search from the Start Screen. Click on the Start Screen button, and type one of the main words, **“Network,” “Sharing,” “Center.” “Center”** will have the fewest options that pop up, so it would be your best bet, but any one of these will work. Note that what you start to type will appear in the top right of the window. ![Start Button](https://www.atlantic.net/wp-content/uploads/2018/01/open2.png) Start Button ![Search](https://www.atlantic.net/wp-content/uploads/2018/01/open3.png) Search **2. For Windows Server 2019 and 2022** Microsoft changed the workflow in newer versions. You now start from **Ethernet Settings**. 1. Click the **Search bar** on the taskbar 2. Type **Ethernet Settings** 3. Open **Ethernet Settings** 4. Click **Network and Sharing Center** This method works the same way on both Server 2019 and Server 2022. **3. For Windows Server 2025** Windows Server 2025 continues the modern Settings-based approach. 1. Click the **Search bar** 2. Type **Ethernet Settings** 3. Open **Ethernet Settings** From here, you can manage adapters or navigate to advanced network options. ## Method 3: Using Server Manager (Direct Access to Network Connections) If you already have the Server Manger open, then you can bypass the Network and Sharing Center. Click on Local Server, which you see highlighted below. ![Server Manager Dashboard](https://www.atlantic.net/wp-content/uploads/2018/01/open4.png) Server Manager Dashboard Then you can click on the networking information. It is a link that will take you directly to the “Network Connections” page. ![Server Manager properties](https://www.atlantic.net/wp-content/uploads/2018/01/open5.png) Server Manager properties ## Final Thoughts **Although Microsoft has changed the interface over the years, the **Network and Sharing Center remains** essential** for Windows Server administration. Once you know the correct path for your server version, you can reach your network settings in seconds instead of clicking through menus. If you manage VPS or dedicated servers, this is one of those shortcuts you’ll use almost daily—so it’s worth remembering. Thank you for following along, and feel free to check back with us for further updates or learn more about our reliable [VPS hosting](https://www.atlantic.net/vps-hosting/) servers and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Hyper-V Role on a Windows Server 2008 R2 Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-hyper-v-role-windows-server-2008-r2-server/ | Published: 2015-02-28 | Updated: 2024-06-05 | Author: Atlantic.Net NOC ##### Verified and Tested 02/28/2015 ### Introduction This how-to will guide you through installing Hyper-V on your Windows Server 2008 R2. Hyper-V is used to manage Virtual Machines within your server. ## Installing Hyper-V Role on Windows Server 2008 R2 Server Hyper-V is installed as a service within the **Roles and Services Manager** in your **Server Manager. **You can open **Server Manager **by clicking the icon on the bottom-left side of the screen. ![Select Server Manager Try Icon](https://www.atlantic.net/wp-content/uploads/2018/01/hyper1.png) Server Manager Try Icon Once you are in **Server Manager**, click on **Roles **on the left panel to open your server’s Roles page. Then, click the **Add Roles **link on the right side of the window to open the **Add Roles Wizard.** ![Select next on the before you begin page. Add roles](https://www.atlantic.net/wp-content/uploads/2018/01/hyper2.png) Before you begin ****Click **Next **to continue the installation. The installer will provide a list of possible roles to install. Check the **Hyper-V** box and click **Next.** ![Under Select Server roles select Hyper-V](https://www.atlantic.net/wp-content/uploads/2018/01/hyper3.png) Select Server Roles The installer will then provide you with helpful links regarding the use and initial configuration of Hyper-V. You can read these first if you wish. Click **Next** when you are ready to move on. The following page will allow you to use a network adapter to allow a virtual network between your virtual machines. This will be useful if you intend to have your virtual machines communicate with each other. We can add this later, so for right now, let’s skip this step. Click **Next** to continue. ![Under Create Virtual Networks select your ethernet device.](https://www.atlantic.net/wp-content/uploads/2018/01/hyper4.png) Create Virtual Networks Click **Install **on the following page to finish installing the role. ![Confirm Install Selection](https://www.atlantic.net/wp-content/uploads/2018/01/hyper5.png) Confirm Install Selection The server will notify you that you will have to restart your server for the role to finish installing. Click **Close,**and a prompt will come up asking to restart the server. Click **Yes **to restart your server. ![Select reboot server once the installation has completed.](https://www.atlantic.net/wp-content/uploads/2018/01/hyper6.png) Restart the Server Once the server has restarted, the installation progress will automatically continue. Once done, click **Close**. ![View your installation results and close the window pane once done.](https://www.atlantic.net/wp-content/uploads/2018/01/hyper7.png) Installation Results Hyper-V is now successfully installed! You can access Hyper-V through your system’s **Start Menu**. ![You may now access the Hyper-V manager within your start menu.](https://www.atlantic.net/wp-content/uploads/2018/01/hyper8.png) Hyper-V manager Thank you for following along in this How-To. Take a look at the following article – [How to Expand a VM Hard Disk in Hyper-V on Windows Server 2012.](https://www.atlantic.net/dedicated-server-hosting/how-to-expand-vm-hard-disk-hyper-v-2012/) ## More About Atlantic.Net Atlantic.Net offers world-class hosting solutions, including [VPS hosting](https://www.atlantic.net/vps-hosting/) services.  See our [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Add an Additional Public IP to Windows Server 2008 > URL: https://www.atlantic.net/vps-hosting/how-to-add-additional-public-ip-windows-server-2008/ | Published: 2015-02-28 | Updated: 2024-06-04 | Author: Atlantic.Net NOC ##### **Verified and Tested 02/28/2015** ### Introduction This how-to will show you how to add an additional public IP to your Windows 2008 Server. Many services on a server might ask for or require additional public IPs to work correctly, such as creating private name servers, websites with SSLs, email generation, splitting services to different public IPs. ## Adding an additional Public IP address to Windows Server 2008 Now you want to log into your server. Open up the Networking and Sharing Center so we can edit the Network Interface. For that guide, please visit [https://www.atlantic.net/cloud-hosting/how-to-open-network-sharing-center-windows-server-2008/](https://www.atlantic.net/vps-hosting/how-to-open-network-sharing-center-windows-server-2008/) Make sure to click on “Change adapter settings” if you have not done so already. ![Under network and sharing center select Change adapter settings](https://www.atlantic.net/wp-content/uploads/2018/01/public1.png) Click on Local Area Connection. Notice it highlights blue and adds some options in the above line. Let’s click on “Change settings of this connection.” ![Select your network interface and Change settings of this connection](https://www.atlantic.net/wp-content/uploads/2018/01/public2.png) Now double click on “Internet Protocol Version 4 (TCP/IPv4)”. If you do not like to double click, then select it and click “Properties.” ![Double click Internet Protocol Version 4 (TCP/IPv4)](https://www.atlantic.net/wp-content/uploads/2018/01/public3.png) Since this is an additional IP address, we are going to click on “Advanced.” ![Select advanced](https://www.atlantic.net/wp-content/uploads/2018/01/public4.png) We are almost done. Now under the top section “IP addresses,” click “Add…”. ![Under IP Settings, select Add](https://www.atlantic.net/wp-content/uploads/2018/01/public5.png) Now, we will use the info provided in the Public IP section for the IP we reserved and Assigned. ![Manage Additional IPs](https://www.atlantic.net/wp-content/uploads/2018/01/public6.png) ![IP Address](https://www.atlantic.net/wp-content/uploads/2018/01/public7.png) Press OK four times to return you to the Network Connections screen. Now you can check to see if it is configured correctly. Right-click on Local Area Connection, click on Status, Click on Details…, and look at the multiple IPv4 Addresses and the Subnet mask for each one. ![Right click your interface and select Status.](https://www.atlantic.net/wp-content/uploads/2018/01/public8.png) Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # State of the Legal Cloud – Overview & Highlights > URL: https://www.atlantic.net/vps-hosting/state-of-the-legal-cloud-overview-highlights/ | Published: 2015-03-04 | Updated: 2025-03-06 | Author: Alexander Wise The American Bar Association focuses heavily on technology, with its Legal Technology Resource Center (LTRC) releasing the *ABA TechReport* every year. Technology author Dennis Kennedy wrote a report on cloud computing for the 2014 edition, revealing incredible growth in the legal cloud over the next 6-12 months:  35% of non-cloud firms expect to use web-based apps or deploy the ultra-reliable, supercomputer-trumping virtual machines themselves for the first time. - **Survey Nuggets** - **Application to Legal Work** - **Security Mechanisms Overlooked** - **Strengths of the Legal Cloud** - **The Future** **Survey Nuggets** Although the forecast into 2015 was incredibly promising, Kennedy noted that the 12 months leading up to the report did not indicate additional adoption. It was essentially a plateau year (or holding-pattern year, to maintain the cloud analogy), with 3 out of 10 law firms stating that they use the cloud, matching the 2013 number. Attorneys are mainly sold on software-as-a-service (SaaS) solutions such as Dropbox, used by 6 out of 10 attorneys. Understandably, Law firms are concerned with the security and privacy of their data. However, “the employment of precautionary measures is quite low, with no more than 40% of respondents taking any one of the standard cautionary measures listed in the*Survey*” (which included security best practices such as SSL encryption). Disturbingly, respondents were doing less to protect data than in 2013, with 1 in 5 attorneys not taking any of the data-safeguarding steps presented in the survey. Attorneys continue to enjoy the ability to retrieve and manipulate their files whenever and wherever they want. They also like the affordability. Security has become a more prominent consideration, with attorneys listing **vendor reputation** as the key differentiator. Attorneys currently working with cloud trusted it more than previously, with 78% saying they would keep using the technology, versus 70% in 2013. **Application to Legal Work** As stated above, the proportion of 2014 respondents who said they used cloud applications stayed at the same level, 30%. This holding pattern followed a year in which cloud ascended remarkably, from 20% to 30% adoption. Those relatively new to the field (with under 20 years practicing law) have proven to be the early adopters, but the veteran attorneys are now using the services to just as great a degree. The legal cloud is a little more prominent in the Midwest and West Coast, but usage is pretty balanced throughout the country. The primary branches of law that utilize cloud are: - Corporate – 37% - Commercial – 37% - Real estate – 36% - Family law – 36% Two unexpectedly low practice areas were intellectual property, down to 33% from 42% the previous year, and litigation. Kenny found the latter figure particularly shocking: “Given the significance of electronic discovery and the availability of cloud-based electronic discovery services,” he said, “ it is somewhat surprising that there is only a 28.5% usage in litigation practices.” As indicated above, this year, the disparity between older and younger attorneys exhibited in 2013 evaporated: those up to 49 years old were no likelier to use cloud than attorneys in their 50s, with both measuring 32%. **Security Mechanisms Overlooked** While attorneys reported they are skeptical of cloud data protection, most aren’t taking reasonable proactive steps themselves – perhaps due to a lack of technical knowledge. Precautionary usage was as follows: - Check provider service level agreement (SLA) – 32% - Survey privacy policy – 37% - Backups on own PC or server – 39% - SSL or other encryption – 29% As a side-note, specialized professionals such as doctors and lawyers are often unaware of how critical data encryption is to maintain their confidentiality. That’s clear in the high number of HIPAA violations medical practices experience each year due to unencrypted laptops and mobile devices. There are also tools with which you can encrypt cloud data, such as Boxcryptor, which was recently recommended in *TechRepublic*. Kennedy seemed baffled by the perceived lack of effort to protect data from cybercriminals or even theft by the cloud provider itself: “Particularly striking,” Kennedy observed, “is the ‘cobbler’s children’s shoes’ element of lawyers not reviewing cloud services agreements for their own usage.” **Strengths of the Legal Cloud** Attorneys were also asked to describe why they were using the cloud, what advantages they thought it offered. The top reason listed was the technology’s around-the-clock, real-time convenience, allowing attorneys to accomplish work on their terms. Cost-effectiveness was also prominently mentioned as a strong suit. Additional pluses cited by lawyers, to a lesser extent, were: - The financial upside of foregoing in-house IT - The convenience and security advantage of outsourcing patches and upgrades - The immediacy of cloud servers and applications **The Future** Undoubtedly, many attorneys will follow the path taken by the general business world to the Cloud Server model. This model combines a public cloud with a private cloud, designating services to each server as appropriate. Others will integrate a cloud server with a custom dedicated solution. Either way, as the security mechanisms section above suggests, you can use [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions without being at its mercy. **Take control today!** By Kent Roberts   Atlantic.Net can also assist with managed, [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) and [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions – contact us today for a consultation. --- # Building the Tax Cloud > URL: https://www.atlantic.net/vps-hosting/building-the-tax-cloud/ | Published: 2015-03-11 | Updated: 2024-11-09 | Author: Sam Guiliano It’s unseen, but it’s changing our lives. We can watch movies from any location and fill our phones with applications that offer data accessible “in real-time” because of the high speed and low cost of cloud technology. However, the accounting world has often not fully used the cloud, unaware of innovations in public cloud security and the emergence of the hybrid model, which allows companies to integrate public and private components. Four out of 10 (41%) accountants reported in a 2014 Network Management Group poll that they were not using any cloud computing services, while 3 in 10 (32%) said that they were converting, at least, one of their applications to the cloud by 2016. ## Why More Accountants Should Convert to the Cloud Christina E. Wiseman, the wireless tech product manager for the accounting branch of Thomson Reuters, is [not impressed](http://www.accountingtoday.com/news/technology-products/why-tax-and-accounting-professionals-should-take-a-walk-in-the-cloud-73783-1.html). Citing a Pew Research Center study, she notes that the web is used by nine out of 10 men and women (87%), while among adults under 30 years old (97%).*“*Given the connectivity of clients and prospects,” said Wiseman, “it’s unquestionably time for accounting firms to understand what the cloud is all about and take full advantage of its benefits. Wiseman describes the following benefits, which she finds to be overwhelmingly compelling in favor of cloud systems: ## Agility, Accessibility, and Productivity Using either software-as-a-service (web-based software directly through a third party) or your own applications stored on a cloud server that you control and manage, you can work within your systems from any device and any location at any time. That means your workforce can sign on from anywhere to complete projects. Cloud also makes it possible to point customers to your web portal to survey their own information, which is becoming a standard expectation. ## Affordability and Speed With the “opex” model of this form of distributed virtual hosting, there is a meager cost of entry to set up your computing network and keep it running. You also don’t have to worry about storing any servers if you go with a solution that utilizes a hosting provider for all its infrastructure. **“**Traditional business software typically requires a large upfront licensing fee, in addition to an annual maintenance fee and your own infrastructure costs,” Wiseman explains, “while most cloud service providers offer a pay-as-you-go model where you’re charged a monthly or annual fee for use.” You also don’t have to pay for your own technology professionals: cloud services take care of that. The software of whatever core services you order is patched and upgraded by the host. Wiseman says not to think of the cloud as an additional expense, and instead, it should replace the current tech services within your budget.  She stresses that you don’t want to forget to consider upgrading and patching labor (which you are now pushing to another company) in your cost analysis. You can sometimes save more when you use the cloud provider for backup, too, says Wiseman. ## Data Protection and Availability Although cloud sounds exciting in some ways, many risk-averse professionals worry about storing data in this form, says Wiseman. It’s easy to forget that Apple was believed to be hacked by someone stealing passwords and simply logging into various accounts, not by someone actually invading the computing giant’s network – at least according to Apple’s assessment. Furthermore, the hacks of Sony Pictures, Target, and Anthem are disturbing. However, none of those companies are technology-focused. Hosting providers base their reputations on security, so the investment in precautionary measures tends to be a much higher proportion of the overall budget than with other types of companies. ## Choosing a Cloud Provider Wiseman recommends that you choose a provider that was founded a minimum of three years ago (2012 or earlier) and check for SSAE 16 auditing. “[The SSAE 16 standard was] designed in part to test a vendor’s infrastructure—including hardware, software, procedures and personnel, and data,” Wiseman comments, “in areas including security, integrity, confidentiality, and ability to protect clients’ personal information.” Make sure the cloud service has a strong disaster recovery plan in place as well. You want them to have multiple data centers so that you can back up your information in a separate geographical location. Self-healing capabilities will allow you to jump over to backup data without any delay. ## Meeting Customer Needs Finally, the cloud allows you to meet the speed and access demands of clients and potential clients. Yes, you have to protect everyone’s data. Nonetheless, you must also exhibit never-before-seen reliability and supercomputer power (two characteristics of cloud) if you want to compete. Just as you must meet the needs of your clients, we can meet your needs. As noted above, Wiseman recommends gauging reputability by the number of years in business. We were founded in 1994, so we have over three decades of experience. Talk to us today about building a partially **cloud-based** **hybrid infrastructure** for your firm. ## How Atlantic.Net Can Help Atlantic.Net can assist with cloud, managed, [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/), and [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions – contact us today for a consultation. --- # How to Create a New Atlantic.Net Cloud Server > URL: https://www.atlantic.net/vps-hosting/how-to-create-new-atlantic-net-cloud-server/ | Published: 2015-03-18 | Updated: 2025-03-06 | Author: Alexander Wise ### Introduction This tutorial will show you how to create a Cloud Server through the Atlantic.Net Cloud admin portal. ## How to Create a New Cloud Server ![How to create a new Atlantic.Net Cloud Server](https://www.atlantic.net/wp-content/uploads/2018/01/create-new-server.gif) **1.**  Sign in to [cloud.atlantic.net](https://cloud.atlantic.net/?page=userlogin). **2.**  Click the “Add Server” button. On the initial “Add a Server” page, you will see a few options: **3.**  Enter what you would like your server’s name to be in the “Server Name.” **4.**  Click on the data center you would like your Cloud Server to be located under “Location.” **5.**  Select the type of server you would like under “Type.” Under the first tab, “Operating Systems,” there are vanilla versions of popular operating systems. Under the second tab, “Applications,” are the servers that come with popular applications, like WordPress, cPanel, and LAMP, already pre-installed. *Note: When selecting anything under “Applications,” this overwrites any OS you may have chosen on the Operation Systems page. Please note that cPanel does come at an extra cost found on our [VPS hosting pricing](https://www.atlantic.net/vps-hosting/pricing/) page.* **6.**  Select what plan size you want under “Plan.” *Note: The plans do change depending on the OS you have chosen. All available plans will be provided as well as the specifications and their pricing.* **7.**  Choose whether to enable backups for your new Cloud Server. Check the box next to “Enable Backups” if you would like to have daily snapshots of your server taken. Visit our [VPS Hosting](https://www.atlantic.net/vps-hosting/) page for pricing and details. **8.**  Finish creating your server by clicking the “Create Server” button.  It will take a few moments for your server to build. The credentials will be displayed at the top of the page in green and will also be emailed to you. After this, the server will be listed as ‘PROVISIONED,’ and you will be able to access it via [Remote Desktop Connection](https://www.atlantic.net/vps-hosting/how-to-remote-desktop-windows-server/), [SSH](https://www.atlantic.net/vps-hosting/how-to-ssh-linux-server-windows/), or [VNC](https://www.atlantic.net/hipaa-compliant-hosting/how-to-using-vnc-access-cloud-server/) using the credentials highlighted at the top of the page. **Note: Atlantic.Net does not keep your credentials on file, so please be sure to keep this information recorded for your convenience.** --- ## Contacting Atlantic.Net Support If the above step-by-step directions do not assist you in completing your task or an issue arises while following these steps, please feel free to contact our Support Department at 866.618.3282 (option 3) or email us directly at cloudsupport@atlantic.net. If you need assistance setting-up a [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) account, check out our dedicated server hosting page. --- # How to Delete a Atlantic.Net Cloud Server > URL: https://www.atlantic.net/vps-hosting/how-to-delete-atlantic-net-cloud-server/ | Published: 2015-03-18 | Updated: 2024-06-05 | Author: Chelsea Fieler ### Introduction This guide will show you how to delete an Atlantic.Net Cloud Server from your cloud.atlantic.net portal.  Please keep in mind that once a server has been removed, all data stored on that server is immediately deleted and irretrievable for security reasons.  Be sure that you want to remove the server you have selected, as this action can not be reversed. ## How to Delete a Cloud Server To delete your virtual private server, select the box next to the server you want to delete. The box should turn into a blue square with a white check. If you are ready to remove the server, click remove. ![Place a check mark next to the server you'd like to remove and select Remove](https://www.atlantic.net/wp-content/uploads/2018/01/cloud1.png)   ![Read the warning and continue](https://www.atlantic.net/wp-content/uploads/2018/01/cloud2.png) After you click remove, you will get a warning message saying that you are about to delete your server. If you are sure, click OK. After you click OK, you should see that your server’s status has changed to removed. ![Note the status of the server has changes to removed.](https://www.atlantic.net/wp-content/uploads/2018/01/cloud3.png) ## Contacting Atlantic.Net Support If the above step-by-step directions do not assist you in completing your task or an issue arises while following these steps, please feel free to contact our Support Department at 866.618.3282 (option 3) or e-mail us directly at cloudsupport@atlantic.net. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # Cloud Hosting – Getting Started with DNS Records > URL: https://www.atlantic.net/dedicated-server-hosting/cloud-hosting-getting-started-with-dns-records/ | Published: 2015-03-18 | Updated: 2025-08-04 | Author: Alexander Wise Atlantic.Net’s Cloud Portal includes a DNS management module that enables you to manage DNS records for your domains. DNS records tell people where your domain is hosted so they can reach it by name instead of just by server IP. This tutorial will show you how to manage these settings in the [Atlantic.Net Cloud Portal](https://cloud.atlantic.net/?page=userlogin). ## Pre-Setup First, we will want to make sure you have a domain to add to the DNS Manager. Domains can be purchased from domain registrars such as GoDaddy or Network Solutions, and they will also control which name servers can use your domain. In this case, the cloud name servers you want to point your domain to are: - ``` ns1.quickroutedns.com ``` - ``` ns2.quickroutedns.com ``` - ``` ns3.quickroutedns.com ``` To change the name servers for your GoDaddy account, [you can see their guide here](https://www.godaddy.com/help/set-custom-nameservers-for-domains-registered-with-godaddy-12317). To change the name servers for your Network Solutions account, [you can see their guide here](http://www.networksolutions.com/support/move-dns-to-a-new-server/). Once your name servers have been changed to the cloud, we can add the DNS records to the cloud name servers. Start by logging into the [Atlantic.Net Cloud Portal](https://cloud.atlantic.net/?page=userlogin).   ![Start by logging into the Atlantic.Net Cloud Portal.](https://www.atlantic.net/wp-content/uploads/2021/03/Cloud-Home-1.png) On the *Domain Names* page, click on ‘**Add Domain’**to get started adding your domain. ![Click Add Domain](https://www.atlantic.net/wp-content/uploads/2021/03/anet-manage-cloud-dns-records-02.png) As seen in the below image, a new entry field will appear. **Enter in your domain name** (in this example, example.net). Note: Only add the top-level domain name here. For example, you would enter in *example.net*, not *www.example.net.* ![Enter in your domain name](https://www.atlantic.net/wp-content/uploads/2021/03/Adding-a-Domain.png)   After adding your domain, you will get a popup that says ‘*Domain created successfully!*‘ like the picture below. ![Domain created successfully!](https://www.atlantic.net/wp-content/uploads/2021/03/Record-Saved-Successfully-Message.png)   After hitting **‘OK’** on the popup, you will go back to the *Domain Names* page with a list of your domains. There are buttons next to each labeled ‘*Manage*‘ and ‘*Delete*.’ ‘*Delete*‘ will delete the domain and all associated DNS records from the system, and’ *Manage*‘ will take you to the management page for that domain. This makes the DNS zone where all records are kept for that particular domain. However, our site isn’t accessible yet. To point people to our site appropriately, we’ll need to add DNS records in the DNS zone.   ## Common DNS Setups ## Basic Website For a basic website, we’ll be setting up two *A records* for your website. The two most common ways people access a website are *example.net* and *www.example.net*. We will need to add an *A record* for each one of these. We have to do this so anyone can access the site with or without the *www.* - **Log in** to [https://cloud.atlantic.net/](https://cloud.atlantic.net/?page=userlogin). - Click on ‘**DNS**.’ - Click on ‘**Manage.’** ![Click manage](https://www.atlantic.net/wp-content/uploads/2021/03/Manage-DNS-Records.png) - Click ‘**Add DNS Record**‘ to add a new record. ![Add DNS Record](https://www.atlantic.net/wp-content/uploads/2021/03/Default-Records.png) This page contains pre-made records. Do not change any of these records. - In the *Type* column, choose ‘**A/AAAA**‘. - Leave the *Host *field **empty.** - In the *Content *column, enter **your server IP address.** - Click ‘**Add’.** ![](https://www.atlantic.net/wp-content/uploads/2021/03/Adding-an-A-Record.png) The record is successfully added when you see the following popup: ![Success pop up](https://www.atlantic.net/wp-content/uploads/2021/03/Record-Saved-Successfully-Message.png) We’ll be doing the same thing for your ‘*www*‘ record. - Click on ‘**Add DNS Record**.’ - Choose in the *Type*column, choose ‘**A/AAAA’.** - In the *Host *field, type **‘www.’** - In the *Content *field, enter **your server IP address.** - Click ‘**Add**‘. You’ve successfully added records for your website. **Note**: The records may take a few minutes to make their way to the rest of the world or propagate. While our side knows the records were added, those records then have to propagate to all other name servers that any other computer is using. This process can take up to 72 hours to complete globally but is usually done locally within 5-15 minutes. We can test our newly created record by either going to the site or checking a DNS propagation tool such as [WhatsMyDNS](https://whatsmydns.net/). WhatsMyDNS checks an array of name servers across the globe for the requested record. While some may not pop up yet, give it some time, and the same IP should come up across all name servers. It can check a variety of records which we’ll cover in this guide. ## Mail Server Setting up a mail server will require one *A **record,* an *MX record,* an *SPF record*, and a *PTR* *record*. The *MX record* will tell other computers where to send mail being sent to your domain. The *SPF record* is used for the security of your emails and domain. - Click on ‘**DNS**.’ - Next to your domain, click ‘**Manage**.’ - Click on ‘**Add DNS Record**.’ - In the *Type *column, choose ‘**A/AAA****A**‘. - In the *Host *column, enter ‘**mail**.’ - In the *Content *column, enter **your server IP address.** - Click ‘**Add**‘. ![Add server IP address](https://www.atlantic.net/wp-content/uploads/2021/03/Adding-a-Mail-A-Record.png) To add an *MX record*: - Click on ‘**Add DNS Record**.’ - In the *Type* column, choose ‘**MX**.’ - In the *Host *column, enter ‘**@**.’ - In the *Content *column, enter the **host field** of the *A record* you just added. ![Add DNS record](https://www.atlantic.net/wp-content/uploads/2021/03/Adding-an-MX-Record-Updated.png)   To add an *SPF record*: - Generate an *SPF record* from **spfwizard net**. - Click on ‘**Add DNS Record**.’ - In the *Type** *column, choose ‘**TXT**.’ - In the *Host *column, enter ‘**mail**.’ - In the *Content *column, enter **the contents of your generated *SPF record***. - Click ‘**Add**‘. ![Add spf record](https://www.atlantic.net/wp-content/uploads/2021/03/Adding-an-SPF-Record-Proper.png) Make sure to include the quotation marks provided with your output. The *PTR record*, also known as a pointer record, works in reverse to the *A record*. Instead of pointing a domain to an IP, it points an IP to a domain. Because of this, a *PTR* will need to be set up on the ISP side to get the IP pointed to the domain when requested. To add a *PTR record:* - On the left-hand side of the cloud control panel, click on ‘**Server PTRs**.’ - **Locate** the IP address you need to set up a *PTR* for. - In the *Points To* section, enter **your mail domain name**. - Click ‘**Save Changes**.’   ![Save changes](https://www.atlantic.net/wp-content/uploads/2015/03/Mail-PTR-Record-e1635014583999.png) ![Successfully added your PTR record](https://www.atlantic.net/wp-content/uploads/2015/03/Mail-PTR-Record-Added-Successfully.png) You have successfully added your *PTR record. *To check if the PTR was added successfully, you can go directly to the server IP in a browser, and it should redirect to the domain immediately. **Note: **Atlantic.net’s cloud control panel can only control the IPs that Atlantic.Net controls. You’ve successfully added DNS records for your mail server. ## Advanced DNS Guide While most DNS records are relatively straightforward with entering something in the ‘Host’ field and something else in the ‘Content’ field, others require a bit more definition before using it. If you want to know about DNS regarding site security or have questions about the other records available, we’ll talk about those here. These are all extraneous records that aren’t necessary to keep a site up and running. ## The SRV Record The SRV record, also known as a Service record, is used to specify the hostname and port of an application or program running on a server. This is a more complicated setup and is only usually required by a handful of services such as SIP (Session Initiation Protocol) for VoIP services or any service that requires indication specifically through DNS prior to opening a communication channel. - Click on ‘**DNS**.’ - Next to your domain, click ‘**Manage**.’ - Click on ‘**Add DNS Record**.’ - In the *Type *column, choose ‘**A/AAA****A**‘. - In the *Host *column, enter **your server name**. - In the *Content *column, enter **your server IP address.** - Click ‘**Add**‘. ![Add server IP address](https://www.atlantic.net/wp-content/uploads/2021/03/Adding-a-Service-A-Record.png)To add the *SRV record*: - Click on ‘**Add DNS Record**.’ - In the *Type* column, choose ‘**SRV**.’ - In the *Service Name* field, enter your service in the **correct syntax: _service._proto.name** - In the *Weight* field, enter **10** (modify as needed). - In the *Port *field, enter **the port listening for that service.** - In the *Domain* field, enter **the A record you just entered.** - Click ‘**Add**‘. ![To add the SRV record](https://www.atlantic.net/wp-content/uploads/2021/03/Adding-an-SRV-Record-2-Proper.png) Remember, the SRV record requires an A/AAAA record to be attached to, and you will need to add that record first for the SRV record to work. You have successfully added your *SRV record*. ## The DKIM Record The DKIM record, more commonly known as a domain key, is another form of TXT record used to verify the sender of emails. Domain keys use an encryption method embedded into each email that should be sent only by the authorized server to authenticate with the DKIM record. It’s essentially a check and balance system for all emails that say they belong to a domain. - Create a **private key, a public key, and a text entry for the host field at [dkimcore org](http://dkimcore.org/).** - Configure your local mail server to use the provided private key. - Click ‘**Add DNS Record**.’ - In the *Type* field, choose ‘**TXT**.’ - In the *Host *field, enter **the previously provided text entry for the host field.** - In the *Content *field, enter **the previously provided public key in Bind9 format.** - Click ‘**Add**‘. ![Create a private key, a public key, and a text entry for the host field at http://dkimcore.org/.](https://www.atlantic.net/wp-content/uploads/2021/03/Adding-a-DKIM-Record-Proper.png) You can expand the ‘Content’ field by clicking and dragging on the two lines in the bottom right-hand corner of the field. You have successfully added a *DKIM record. * **Note: **Once the *DKIM record *is added, you can confirm the record’s validity by using an online tool such as [keycheck](http://dkimcore.org/tools/keycheck.html). ## The DMARC Record *DMARC* records are for email as well with an extra feature; *DMARC* is also a reporting record. *DMARC* will tell a mail server what to do *when *an email is blocked or rejected. This can include notifying the authenticated sender so they can look further into possible abuse of their domain. - Create a *DMARC* record from [**https://dmarcian.com/dmarc-inspector/**](https://dmarcian.com/dmarc-inspector/) - Click ‘**Add DNS Record**.’ - In the *Type *column, choose ‘**TXT**.’ - In the *Host* column, enter ‘**_dmarc**.’ - In the *Content *column, enter **the content of your generated DMARC record**. - Click ‘**Add**‘. ![Create a DMARC record from https://dmarcian.com/dmarc-inspector/](https://www.atlantic.net/wp-content/uploads/2021/03/Adding-a-DMARC-Record.png) **Note: ***DMARC* will only report based on the settings you chose in the questionnaire when creating the record. The same link provides a *DMARC* inspector where you can enter your domain to check your *DMARC* record, along with a breakdown of each section of that record. ## Troubleshooting ## Online Tools Many online sources can help determine whether DNS records are set up correctly, most notably [WhatsMyDNS](https://whatsmydns.net/) noted earlier in this how-to. Using WhatsMyDNS, you can check each record listed here. The only thing to note would be that WhatsMyDNS does not differentiate the TXT records (SPF, DKIM, and DMARC), and it will only provide the output for those records, not whether or not they are working as needed. [MXToolbox](https://mxtoolbox.com/) is another resource that will help in checking DNS records, mainly MX records. They also provide other services, including blacklist checks against a long list of blacklists, SMTP Diagnostics (some email providers require strict SMTP settings, including some DNS settings), and a Domain Health Report, which can determine what can be done to improve DNS configuration. ## Proprietary System Tools Another convenient tool is the default DNS tools that come with most operating systems. Windows comes with the ‘nslookup’ command, which can perform DNS queries directly from your system, and Linux systems also have the ‘dig’ command, which allows for similar requests. [You can find a guide on using ‘nslookup’ here](https://technet.microsoft.com/en-us/library/aa997324(v=exchg.65).aspx) and [one for ‘dig’ here](https://www.cyberciti.biz/faq/linux-unix-dig-command-examples-usage-syntax/). ## NS Records Not Set to Atlantic.Net’s Cloud DNS Servers When adding records, you may also come across the following message in the DNS Manager: ![NS records](https://www.atlantic.net/wp-content/uploads/2021/03/Incorrect-Nameservers-Message.png) This error is pretty straightforward. As mentioned earlier, for any record (except PTR) placed in the DNS Manager to work, you will need to set the nameservers for your domain to the cloud name servers in your domain registrar’s setting. Otherwise, our cloud name servers will not be the authoritative name servers for your domain and can’t respond to DNS queries unless specified. If you still see this message in your DNS Manager after you’ve changed the settings at your registrar, be patient, as changes at registrars may also take time to propagate. Should you have any trouble with the cloud DNS Manager, you can contact our technical support at any time via email at cloudsupport@atlantic.net, phone at 1-866-618-3282 option 2, or LiveChat anywhere on the site. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Enable RDP in Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-enable-rdp-windows-server-2012/ | Published: 2015-03-19 | Updated: 2024-06-05 | Author: Jose Velazquez ##### Verified and Tested 03/19/2015 ### Introduction In this how-to, we will walk you through How-To Enable RDP in Windows Server 2012. Remote Desktop Protocol (RDP) is a protocol expanded by Microsoft that allows you to connect and control another computer via an existing network making it a remote connection. ### Prerequisites – A Server with Windows Server 2012. ## Enable RDP in Windows Server Open the **Server Manager** from the taskbar/ Click on **Local Server**/ Locate Remote Desktop under **Properties** which is currently Disabled, and Click on **Disabled.** ![Note the Remote desktop status in the right pane.](https://www.atlantic.net/wp-content/uploads/2018/01/rdp1-1.jpg) Local Server   The System Properties window will appear. Select Allow remote connections to this computer, and it’s recommended to check the box below. ![Select Allow remote connection to this computer.](https://www.atlantic.net/wp-content/uploads/2018/01/rdp2-1.jpg) Properties   You can also add specific users in the **Select Users**tab. By default, the administrator is allowed. You can add other users by clicking **Select Users/**Click **Add/**insert a username and click OK. ![You may chose to only allow certain users to access this server remotely](https://www.atlantic.net/wp-content/uploads/2018/01/rdp3-1.jpg) Remote Desktop Scope   You can now verify that RDP is enabled, and you can see that the status went from **Disabled** to **Enabled**. ![Verify remote desktop is enabled](https://www.atlantic.net/wp-content/uploads/2018/01/rdp4-1.jpg) Verify   Congratulations! You have just Enabled RDP in Windows Server 2012. Thank you for following along in this How-To. Take a look at the following article – [How to: Custom RDP Port in Windows 2012.](https://www.atlantic.net/vps-hosting/how-to-custom-rdp-port-windows-2012/) Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [Virtual private servers.](https://www.atlantic.net/vps-hosting/) --- # Sharp Focus on HIPAA: Breach Notification Rule > URL: https://www.atlantic.net/hipaa-compliant-hosting/sharp-focus-on-hipaa-breach-notification-rule/ | Published: 2015-03-23 | Updated: 2024-06-05 | Author: Sam Guiliano Hacking news at the top of 2015 is driving the Health Insurance Portability and Accountability Act of 1996 (HIPAA) into the limelight. The news – that the second-largest insurer in the United States, Anthem, was breached, resulting in the compromise of 78.8 million patient records – makes the HIPAA breach notification rule more relevant. Many are aware that the [Final Omnibus Rule of 2013](http://www.beckershospitalreview.com/legal-regulatory-issues/15-things-to-know-about-the-hipaa-omnibus-final-rule-before-sept-23.html) modified the law so that business associates are now effectively considered covered entities, but how does that designation apply to notifications? In other words, what does anyone who handles sensitive protected health information (PHI) have to do post-hack in terms of alerting clients, the press, and the HHS? To answer these concerns, we will look at the expectations for communicating intrusions to affected parties and others, as explained by [Elizabeth Snell in *Health IT Security*](http://healthitsecurity.com). ## Basics of the HIPAA Breach Notification Rule The part of the HIPAA law that is the most significant focus of the healthcare industry is Title II, simply because that section influences the activities of every organization handling health data. The breach notification stipulations mandate that any organization that stores, transfers, or processes patient data must bring any breach to the attention of various individuals and organizations. Snell provides the example of a medical practice that experiences the theft of a laptop. If the information on the computer is encrypted, the organization is typically safe: no offense has been committed since the criminals can’t access the data. However, if there is no encryption in place, “suddenly several hundred patients’ PHI is potentially in criminals’ hands,” she explains. “The healthcare organization in question is required under HIPAA to notify the patients, the Department of Health & Human Services (HHS) and potentially the media.” One way that the healthcare firm can protect itself – both financially and credibly – is by conducting a risk assessment to determine these details: - The type of data that was on any breached device or system, along with the probability that a thief or intruder will be able to access it; - The identity of anyone who accessed or was incorrectly given data, as applicable; - A determination of whether the data was truly taken and exposed to third parties; and - Any actions that have been taken to make the patient data less vulnerable. Healthcare companies and their HIPAA-compliant vendors don’t have to conduct a risk assessment, notes the HHS. It’s just considered a best practice and allows you stronger legal ground. You should also be aware that it is only necessary to let customers and authorities know about a hack when the PHI is unencrypted. Hacks are of concern to the HHS when they involve data “that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology specified by the Secretary in guidance.” *(Example: Note that Anthem was not storing its records in encrypted form.)* Suppose a healthcare company or any third parties that handle its information does not safeguard confidential records with login credentials and two-factor authentication (2FA). In that case, HHS may consider it improperly protected, and physical protections should also be considered. **Specific Instructions for Notification** The extent of the breach is critical regarding notification. If the impacted patient population exceeds 500, major media must be contacted, along with the HHS Office of Civil Rights. That action must occur within a reasonable time frame and never beyond two months, and it should include the bulleted information described below. If less than 500 people are involved, the firm can wait until the end of the year to notify the HHS – technically by the end of February for any hacks occurring the previous year. Although small hacks don’t need to involve the media or be immediately reported to the government, patients must be contacted immediately (60 days, maximum). If contact details are incorrect for more than nine people, the information must be published on the company’s home page for three months. Alternately, the organization can submit information to prominent news media for broadcast. Breach notifications sent out to affected individuals must contain: - A short summary of the incident - Categories of compromised data - Step-by-step instructions so that patients can avoid problems related to the stolen data - A rundown of the procedure the company is following to assess the damage, reduce vulnerability, and prevent attacks in the future - Complete contact information for the breached company Note that in the case of a business associate, the vendor must contact the healthcare organization it services as soon as reasonably possible, 60 days maximum. **Operating within Proper Standards** If you experience a hack or any event that potentially compromises data, you need to be able to show the HHS records of your notification process or evidence that demonstrates why the data was not at risk. There are two forms of evidence you can show to verify that notification did not need to occur: 1. The findings of a vulnerability assessment that demonstrates a low likelihood of access and misuse 2. “The application of any other exceptions to the definition of ‘breach.’” (De Vivo) Furthermore, it is critical to have established policies and procedures related to hacks. Your staff must be trained on these parameters as well. The moral of the story: Be prepared so you can adequately protect yourself. Work with an experienced business associate that is HIPAA audited and meets the strict expectations of the American Institute of CPAs.   Atlantic.Net offers [HIPAA compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) on SSD Cloud Servers, which have a 100% uptime guarantee.  Learn more about [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/).     --- # How to: Password Reset via the Cloud Portal for cPanel & WHM > URL: https://www.atlantic.net/vps-hosting/how-to-password-reset-via-cloud-portal-cpanel-whm/ | Published: 2015-03-24 | Updated: 2024-06-10 | Author: Jason Mazzota ##### Verified and Tested 3/24/15 ### Introduction This guide will take you through resetting a password on cPanel and WHM via our Cloud Portal. ## Password Reset via the Cloud Portal for cPanel & WHM [The first step to do is to follow the password reset guide here](https://www.atlantic.net/vps-hosting/how-to-resetting-atlantic-net-cloud-server-password/). If you cannot connect with that new password, you will need to connect to the server via SSH or VNC. Once connected, you will need to run via command line: ``` ALLOW_PASSWORD_CHANGE=1 /scripts/realchpass root 'new_password' ``` Where new_password is the password, you would like to use. Once done, you may now log into WHM as you would typically with the new password. If it still does not work for you, chances are you are blocked by cPHulk, and to remedy this;[please see this guide here](https://www.atlantic.net/vps-hosting/how-to-locked-cpanel-whm-via-cphulk/). You will need to go to WHM’s “Change root password” section under “Server Configuration,” like the image below, and set the password again. Once done, you have successfully changed the password. ![Navigate to WHM's "Change root password" section under "Server Configuration"](https://www.atlantic.net/wp-content/uploads/2018/01/anet-cpanel-changepass-00.png) Change Root password Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Build a Static Website on IIS using Windows Server 2012 > URL: https://www.atlantic.net/hipaa-compliant-hosting/how-to-build-static-website-iis/ | Published: 2015-03-26 | Updated: 2024-06-04 | Author: Jose Velazquez ##### Verified and Tested 03/27/2015 ### Introduction In this How-To, we will walk you through Building a Static Website on IIS Windows Server 2012. Static content is considered to be HTML files.  These types of files have no movement and hardly change, such as pictures or text documents. ### Prerequisites – A Server with Windows Server 2012. – Internet Information Services(IIS) installed on your server. If you need to install IIS, follow our guide [Install IIS On Windows Server 2012 R2](https://www.atlantic.net/vps-hosting/how-to-install-iis-windows-server-2012-r2/). ## Build a Static Website on IIS using Windows Server 2012 Open **Server Manager**, select **IIS**, right-click your server, and select **Internet Information Services (IIS) Manager**. ![Open Internet Information Services (IIS) Manager](https://www.atlantic.net/wp-content/uploads/2015/03/iss1.jpg) Internet Information Services (IIS) Manager  In the **Connections** pane, right-click the **Sites** node in the tree, and then click **Add Website**. ![Open IIS, under Sites, select Add Website](https://www.atlantic.net/wp-content/uploads/2015/03/iss2.jpg) IIS: Add websiteIn the **Add Website** dialog box, enter a friendly name for your website in the **Site name** box. If you want to select a different application pool than the one listed in the **Application Pool** box, click **Select**. In the **Select Application Pool**dialog box, select an application pool from the **Application Pool** list and then click **OK**. In the **Physical path** box, enter the physical path of the website’s folder, or click the browse button (**…**) to navigate the file system to find the folder. (Note: It is best to make a folder in your C: specifically for your websites. I have named mine www) If the physical path that you entered in the previous step is to a remote share, click **Connect as** to specify credentials that have permission to access the path. If you do not use specific credentials, select the **Application user (pass-through authentication)** option in the **Connect As** dialog box. Select the protocol for the website from the **Type** list. If you must specify a static IP address for the website (by default, this is set to **All Unassigned**), enter the IP address in the **IP address** box. Enter a port number in the **Port** text box. Optionally, enter a host header name for the website in the **Host Header** box. If you do not have to make any changes to the site, and you want the website to be immediately available, select the **Start Website immediately** check box. Click **OK**. ![Fill in your site information accordingly.](https://www.atlantic.net/wp-content/uploads/2015/03/iss3.jpg) Add Website FormIn **Features View** of IIS Manager, double-click **Authentication.** ![Select your websites domain name and select Authentication](https://www.atlantic.net/wp-content/uploads/2015/03/iss4.jpg) Website Authentication Select **Anonymous Authentication**/right-click and select **Edit** to set the security principal (user credentials) under which anonymous users will connect to the site. ![Edit Anonymous Authentication](https://www.atlantic.net/wp-content/uploads/2015/03/iss5.jpg) Edit Anonymous Authentication In the **Edit Anonymous Authentication Credentials** dialog box, select one of the following options: If you want to configure a specific user account that IIS uses to access your site or application, select **Specific user**. Then click **Set** to open the **Set Credentials** dialog box and enter a user name and password for the identity. Then click **OK**. If you want IIS processes to run by using the account specified on the property page for the application pool, select **Application pool identity**. By default, this identity is the IUSR account. (**Recommended**: Change the default IUSR account to your username. If you leave it set to IUSR, you grant anonymous users all the internal network access associated with that account) Click **OK** to close the **Edit Anonymous Authentication Credentials** dialog box. ![Fill in your credentials](https://www.atlantic.net/wp-content/uploads/2015/03/iss6.jpg) Credentials FormIn **Features View** of IIS Manager, double-click **Default Document**. ![Default Document](https://www.atlantic.net/wp-content/uploads/2015/03/iss7.jpg) Default DocumentIn the **Actions** pane, click **Add**. In the **Name** box, enter the file name you want to add to the list of default documents and then click **OK**. This filename is added to the top of the default document list. *Optionally, select a default document in the list, and in the **Actions** pane, click **Move Up** or **Move Down** to change the file’s precedence.* *Optionally, select a default document in the list, and in the **Actions** pane, click **Remove** to remove any file names that you do not want to use as default documents.* ![Default Document](https://www.atlantic.net/wp-content/uploads/2015/03/iss8.jpg) Default DocumentIn **Features View** of IIS Manager, double-click **Compression**. ![Under your website domain name, select compression](https://www.atlantic.net/wp-content/uploads/2015/03/iss9.jpg) Configure compressionSelect **Enable static content compression** to configure IIS to compress static content/ Then click **Apply** ![Place a checkmark next to Enable staic content compression](https://www.atlantic.net/wp-content/uploads/2015/03/iss10.jpg) Static Content CompressionYou can now test your site by doing the following: Click on your site / in the Action pane select Browse *:80 (http) ![In the action pane of your website, select Browse *:80(http)](https://www.atlantic.net/wp-content/uploads/2015/03/iss11.jpg) View your website Congratulations! You have just Built a Static Site on IIS Windows Server 2012. Thank you for following along in this How-To, and check back with us for new updates soon. Learn more about our [HIPAA compliant web hosting,](https://www.atlantic.net/hipaa-compliant-hosting/) [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions, and see our [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) guide. --- # How to Expand a VM Hard Disk in Hyper-V on Windows Server 2012 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-expand-vm-hard-disk-hyper-v-2012/ | Published: 2015-03-30 | Updated: 2024-06-05 | Author: Jose Velazquez ##### Verified and Tested 03/31/2015 ### Introduction We often find ourselves running out of hard drive space, and now in Hyper-V 2012, we can expand our virtual hard drives. We are used to seeing that when we add storage space or anything that increases, we’ll see it immediately.  That is not the case when we choose to expand your virtual server’s hard disk in Hyper-V 2012. The amount of space that you have added will not be available for you to use right away. We need to use our windows disk management tool to expand/combine the existing Partition with the partition space created. With that being said, in this how-to, we will walk you through Expanding a VM Hard Disk in Hyper-V 2012. ### Prerequisites – A server with Windows Server 2012. – Hyper-V Role installed – An existing VM (Virtual Machine) ## Expanding a VM Hard Disk in Hyper-V 2012 Before we begin, we must make sure that your VM is completely turned off. Open your server manager/select Hyper-V/Right click your host server, and select Hyper-V Manager. Your Host server will be available, and when you click on it, you will see your VM or VM’s also available. Right-click your VM and select “Turn Off.” ## Expand your VM’s Hard Disk To expand the Hard Disk, Right Click on your **Virtual Machine/** click “**Settings**“/ Select SCSI/Select the **Virtual Hard Drive** that you want to extend and click Edit. ![This is the virtual Hard Drive settings while Expanding a VM Hard Disk in Hyper-V 2012](https://www.atlantic.net/wp-content/uploads/2018/01/vm1.jpg) This is the virtual Hard Drive settings while Expanding a VM Hard Disk in Hyper-V 2012   You will then be taken to the “**Edit Virtual Hard Disk**” wizard to locate the Virtual Hard disk. Click next to continue. ![This is the virtual Hard Drive Wizard screen while Expanding a VM Hard Disk in Hyper-V 2012](https://www.atlantic.net/wp-content/uploads/2018/01/vm2.jpg) This is the virtual Hard Drive Wizard screen while Expanding a VM Hard Disk in Hyper-V 2012   Following that, you will be asked to “Choose Action.” There are three choices to choose from, Compact, Expand, and Shrink. Select “**Expand,”**then Click **Next**to proceed.**** ![Selecting the Expand option Wizard screen while on the Actions options to Expand a VM Hard Disk in Hyper-V 2012](https://www.atlantic.net/wp-content/uploads/2018/01/vm3.jpg) Selecting the Expand option Wizard screen while on the Actions options to Expand a VM Hard Disk in Hyper-V 2012   Finally, you will be asked to “Expand Virtual Hard Disk.” This is where you Specify the size of your virtual hard drive. Do so and then click “**Finish”**to complete the expansion. ![Configuring your Disk while Expanding a VM Hard Disk in Hyper-V 2012](https://www.atlantic.net/wp-content/uploads/2018/01/vm4.jpg) Configuring your Disk while Expanding a VM Hard Disk in Hyper-V 2012   ## Extend your VM’s Hard Disk Once you have successfully expanded your Virtual Hard Disk, you will need to turn on your VM following the previous process to turn off your VM and log into the server. Open your server manager/Select “Local Server”/Click “Tools” and select “Computer Management.” Now,  Open “**Disk Manager**” on your Virtual Machine. You will see your current C: Drive Partition and along with an Unallocated Partition with the amount of hard disk space that you created earlier. ![This is the output of the expanded size as Unallocated space while Expanding a VM Hard Disk in Hyper-V 2012](https://www.atlantic.net/wp-content/uploads/2018/01/vm5.jpg) This is the output of the expanded size as Unallocated space while Expanding a VM Hard Disk in Hyper-V 2012   In conclusion, to finalize your expansion, you will need to complete your expansion with the following: Right-click on the volume you want to extend (in this case, C:\ Partition) and select “**Extend Volume**.” This will open up the Wizard screen for your extended volume and follow the on-screen instructions to complete the process. ![Select the Extend option while Expanding a VM Hard Disk in Hyper-V 2012](https://www.atlantic.net/wp-content/uploads/2018/01/vm6.jpg) Select the Extend option while Expanding a VM Hard Disk in Hyper-V 2012   Congratulations! You have just extended your VM’s Hard Disks in Hyper-V 2012.  Thank you for following along in this How-To, and feel free to check back with us for any new updates or take a look at the many services we offer, including [VPS hosting](https://www.atlantic.net/vps-hosting/) and [dedicated server hosting.](https://www.atlantic.net/dedicated-server-hosting/) --- # How to Tell Whether You Have a 32-Bit or 64-Bit Version of Linux > URL: https://www.atlantic.net/vps-hosting/how-to-tell-32-bit-64-bit-version-linux/ | Published: 2015-04-06 | Updated: 2025-03-06 | Author: Alexander Wise ##### Verified and Tested 10/28/15 ### Introduction You might be a new sysadmin with equipment installed by someone else, or you were just given a server with no clue of what is installed. If your software requires a system that is 32-Bit or 64-Bit you probably are going to need to find out if your system is 32 or 64 bit. This how-to will show you how to find out if you are using a 32-Bit or 64-Bit installation on Linux. ## Find out if your Linux installation is 32 bit or 64 bit There is a program called uname installed on Linux that can show us if the Linux system is 32 or 64 bit. To find out if your Linux installation is 32 bit or 64 bit, run the command: ``` uname -i ``` ![Uname -i 64bit](https://www.atlantic.net/wp-content/uploads/2018/01/bit1.png) If it says x86_64, you are using a 64 bit installation. ![32 bit](https://www.atlantic.net/wp-content/uploads/2018/01/bit2.png) If it says i368, you are using a 32 bit installation. Uname -i gives you the hardware-platform. If you are possibly getting unknown, you can use uname -a to get all the information to find if it is 32-Bit or 64-Bit. ``` Uname -a ``` Anything that is x86_64 is 64 bit and anything that i386, i686 or similar is 32 bit. Thanks for following along with this how-to. For more helpful articles and how-to’s about Linux, head over to our [blog](https://www.atlantic.net/blog/). Please check back here for more updates or to learn more about our reliable [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. --- # The Challenge and Promise of Big Data > URL: https://www.atlantic.net/vps-hosting/the-challenge-and-promise-of-big-data/ | Published: 2015-04-06 | Updated: 2025-03-06 | Author: Alexander Wise As the Internet has grown, so has the amount of data and the extent to which data is valued – most notably by the government and publicly traded companies, although even small businesses appreciate the insights they collect from Google Analytics and similar services. Stockpiling and scrutinizing data is considered an extraordinarily powerful way to deliver better products; understand how people use websites and applications; track employee performance; determine the most effective marketing language; and more. According to projections released by International Data Corporation, the big data market will maintain a CAGR of 26% through 2018, when sales of big data services will hit $42 billion. The value of the market tells us that businesses are investing large sums of money in companies that specialize in the collection, comprehension, and integration of vast pools of data – in other words, services that can turn the information into better results. How big of a focus is big data? Well, the spaceship people are in the game. [Chris Mattman of NASA says](http://www.informationweek.com/big-data/hardware-architectures/how-nasa-manages-big-data-/d/d-id/899791) of his employer’s research in this area, “NASA in total is probably managing several hundred petabytes, approaching an exabyte.” [*Forbes* contributor Joshua Steimle notes](http://www.forbes.com/sites/joshsteimle/2015/03/25/drowning-in-big-data-finding-insight-in-a-digital-sea-of-information/) that an exabyte is an extraordinarily vast amount of information, 1 billion gigabytes. ## Awash in a Sea of Numbers? With the technology we now have available, data can accrue so rapidly for enterprises that it amounts to overload for traditional databases – both in terms of keeping it and making any sense out of it. Companies don’t have to build rockets in order to feel somewhat overwhelmed by the sheer enormity of the data at their fingertips, argues *Steimle*. Chris Riquier, the Asia-Pacific head of Taylor Nelson Sofres, says he has seen the impact in another area: “Market research was founded on surveying and polling.” Now, instead, it is done in real time with information flowing in from social media, search engines, and numerous other sources. Thanks to the focus of technologists on data science and the continual refinement of analytics, Riquier believes that our “ability to react to the market and make decisions has changed drastically.” Finding meaningful patterns within big data has been a mystery to many firms. However, data engineers are building systems so strong that the trend toward amassing and processing data as quickly as possible is all but inevitable, [per a 2014 *Harvard Magazine* report](http://harvardmagazine.com/2014/03/why-big-data-is-a-big-deal). The article suggested that innovative “big algorithm” formulas will allow firms to benefit from connecting and integrating data stores, as well as converting the numbers into more robust and user-friendly imaging. Drawing on long-established research techniques from the fields of physics and astronomy, technologists and cultural experts bring their different perspectives to bear on the topic for mutual benefit. Big data authors Viktor Mayer-Schonberger and Kenneth Cukier note that data analytics isn’t just about individual choices but about completely altering the way that businesses make big-picture decisions – after all, predictive analytics is intended to live up to its name, giving those who use it a logically based, all-seeing crystal ball. ## Big Data Successes **Google** – Google hypothesized that certain search terms were probably indicators that people were beginning to have flulike symptoms. By applying their guesses to real-time searches, the company was able to figure out where the flu was spreading faster than the CDC could. **Canadian Bank** – Across the border, Canadian Bank is “using Hadoop, an open source software framework created by Apache,” *Steimle* explains, “to roll out a program that enables the identification of money laundering and fraud.” ## Data & Everyday Life NASA and Google are high-profile instances of the focus on big data, but its potential is much broader, extending to any business wanting to get attention online. It is the fuel that powers search engine optimization and social media optimization. Entrepreneurs can use Google’s Webmaster Tools, combined with analytic data from social software, to develop a more successful online presence. Joe Hall, who helps clients improve their Internet presence through his company Hall Analysis, comments that there are two different basic ways data can be analyzed to improve search engine results: 1. *Exploring the patterns within the voluminous data that is directly related to a particular business.* One of Hall’s clients had more than 15 million backlinks – meaning that many, many webpages were sending their traffic to his client. **“**At that level it changes the rules for backlink analysis,” Hall comments. Determining the patterns within the data become significantly more complex. 1. *Garnering a more sophisticated understanding of their business’s current position and the dynamics in the market as a whole.* Looking at the relationship between different variables through analytics software allows businesses to better understand how to rank prominently and how to get more people to respond to a listing when it does show up in the search engine. Two relevant fields of study are *correlation analysis* and *user behavior analysis*, says Hall. ## Revving Your Big Data Engines One technology that has been fundamental to data scientists and companies utilizing their services is premium cloud computing. After all, [turn-key VPS hosting solutions](https://www.atlantic.net/vps-hosting/)are based on optimizing speed, reliability, and efficiency through virtualized distribution of resources. Computer scientist Geoffrey Fox of Indiana University has even noted that the cloud is often faster than a supercomputer. By Kent Roberts --- # Atlantic.Net Announces Growth and Partnership in Its HIPAA Services > URL: https://www.atlantic.net/press-releases/atlantic-net-secures-healthcare-industry-with-hipaa-compliant-hosting-for-medical-companies/ | Published: 2015-04-07 | Author: Editorial Team ORLANDO, Fla., April 7, 2015 — Today, [Atlantic.Net](https://www.atlantic.net/) announced massive growth in its HIPAA Compliant healthcare hosting business, with regards to the changing landscape of the healthcare industry, the fastest-growing sector of the U.S. economy. The company also announced a partnership with [Genensys](http://genensys.com/), an electronic medical record company, to provide a secure infrastructure for critical patient data, backed by its HIPAA Compliant Hosting solutions. “We welcome Genensys in joining the ranks of thousands of growing companies that rely on efficient hosting infrastructure provided by Atlantic.Net,” said Marty Puranik, CEO and President of Atlantic.Net. “Our fully compliant and audited HIPAA Hosting platform is ideal for application service providers like Genensys enabling them to bring focus to their core business.” America’s healthcare companies must quickly adapt to rapid changes in technology to meet patients’ needs and to protect their privacy and Atlantic.Net is making inroads with medical companies and helping them to stay competitive with reliable, secure hosting solutions. “We are in the business of providing highly-regulated electronic medical records, which requires a secure hosting platform,” said Farhan Shamsi, Co-founder of Genensys. “Atlantic.Net provides a turn-key and secure hosting framework for our application compliance needs, offering excellent value in both price and service,” he added. Atlantic.Net offers competitive HIPAA Compliant Hosting pricing in affordable [HIPAA Linux and Windows cloud hosting packages](https://www.atlantic.net/hipaa-compliant-hosting/). All of the company’s solutions feature heightened security with a fully-managed firewall; VPNs with encryption; and an intrusion detection system.  This is all backed by an Infrastructure that has received a SOC 2 Type I audit report. **About Atlantic.Net:** Established in 1994, Atlantic.Net is a web hosting provider specializing in offering cloud server hosting, HIPAA compliant and hybrid hosting, private virtualization, and [VPS cloud hosting](https://www.atlantic.net/vps-hosting/). Our hosting services provide an isolated, secure environment for each customer’s applications and databases with a 100 percent uptime service-level agreement (SLA). This is all backed by an Infrastructure that has received SSAE 16 SOC 1 Type II and SOC 2 Type I reports.  The audit for the reports is based on the AICPA guidelines, including the Trust Service Principles. For more information, please visit www.atlantic.net. # # # CONTACT: [marketing@atlantic.net](mailto:marketing@atlantic.net) --- # How to: cPHulk Brute Force Protection on cPanel and WHM > URL: https://www.atlantic.net/vps-hosting/how-to-cphulk-cpanel-whm/ | Published: 2015-04-07 | Updated: 2026-03-03 | Author: Jason Mazzota ##### Verified and Tested 03/24/2015 ### Introduction This guide will take you through using cPHulk brute force protection in cPanel & WHM. ### Prerequisites An Atlantic.Net Cloud server with CentOS 6 and cPanel & WHM. If you do not have a [virtual private server](https://www.atlantic.net/vps-hosting/), why not spin one up from Atlantic.Net in under 30 seconds. ## Using cPHulk on cPanel and WHM The first step to using cPHulk on your cPanel & WHM server is to first log into the WHM side of the server. To do this, you would want to go to https://your_cloud_IP:2087 and log in using your root credentials. Once logged in, on the search bar at the top left (if you can’t find it, it looks like the image below), type “cphulk”. The side list should filter, and you will see a section called “cPHulk Brute Force Protection”. Click on this section to go to the cPHulk options. ![Search for CPHulk](https://www.atlantic.net/wp-content/uploads/2018/01/cpanel1-1.png) Search   The basic cPHulk page looks like the below image. We’ll go over the configuration settings page below. ![cPHulk](https://www.atlantic.net/wp-content/uploads/2018/01/cpanel2-1.png) 1. cPHulk state. This will tell you whether or not cPHulk is enabled on your server. You can also disable/enable it here. 2. Clear Failed Logins. This will clear the cPHulk database of failed logins. It’s not recommended unless you need to clear out some failed attempts and someone needs access that is locked out. 3. IP Based Brute Force Protection Period in minutes. This option is for how long an IP is blocked by cPHulk for brute forcing. 4. Brute Force Protection Period in minutes. This is the time period that cPHulk will gather and track failed connection attempts for. 5. Maximum Failures By Account. This is how many times someone can fail within the Brute Force Protection Period before the account is locked. 6. Maximum Failures Per IP. This is how many times someone can fail within the Brute Force Protection Period before the IP is blocked. 7. Maximum Failures Per IP before IP is blocked for two week period. This is self-explanatory. How many times an IP can fail before being blocked for 2 weeks. 8. Send a notification upon successful root login when IP is not whitelisted. The server will send you an email if an IP you have not whitelisted logs into the server as root. 9. Extend account lockout time upon additional authentication failures. This means the more you fail to log in after being blocked, the longer you will be blocked for. 10. Send notification when a brute force user is detected. This will send you an email as soon as cPHulk blocks someone trying to log in.   For the white/black list management page see the below. ![White/ Blacklist](https://www.atlantic.net/wp-content/uploads/2018/01/cpanel3-1.png) White/ Blacklist   1. White List Entry. This will allow you to input an IP or range of IPs into the whitelist. It is recommended that you only add IPs that will be accessing the server that you trust. Mainly your own IP. 2. Black List Entry. This will allow you to input an IP or range of IPs into the blacklist. If you know of an IP or range that you would like to add to the blacklist to stop them from accessing the server, you would enter them here. 3. Edit Whitelist. This will bring you to a new page where you can edit (add/remove) multiple IPs in the whitelist at once. When you are done, you simply click the “Save” button. 4. Edit Blacklist. This will bring you to a new page where you can edit (add/remove) multiple IPs in the blacklist at once. When you are done, you simply click the “Save” button.   The last configuration page is the Login/Brute History Report page. It provides a history of any failed logins or brute force attempts on your server as you can see below. ![View login/brute force Report](https://www.atlantic.net/wp-content/uploads/2018/01/cpanel4-1.png) Reporting   cPHulk allows for a good amount of customization to help secure your server from failed logins and brute force attempts. It is recommended that you have it enabled and put your IP in the whitelist. If you find that you have locked yourself out of your server via cPHulk, you can view [this page](https://www.atlantic.net/vps-hosting/how-to-locked-cpanel-whm-via-cphulk/) on how to remedy the issue. --- # How to: Locked out of cPanel and WHM via cPHulk > URL: https://www.atlantic.net/vps-hosting/how-to-locked-cpanel-whm-via-cphulk/ | Published: 2015-04-07 | Updated: 2024-06-10 | Author: Jason Mazzota ##### Verified and Tested 03/24/2015 ## Introduction You have locked yourself out of your server from too many login attempts that have failed due to a wrong password or other means. You know you have cPHulk running on the server, and there’s a good possibility it is now blocking you because you did not put your IP in the whitelist. How do you fix it? Follow the steps below! ## Prerequisites An Atlantic.Net virtual private server with CentOS 6 and cPanel & WHM. ## Unlock yourself from cPHulk The first thing to do, in this case, is to attempt to disable cPHulk via the web; however, this has a slim chance of working. To do this, append the below onto your web path. `/scripts2/doautofixer?autofix=disable_cphulkd` It should look something like: `https://your_Cloud_IP:2087/scripts2/doautofixer?autofix=disable_cphulkd`   If that does not work, confirm whether or not you can SSH into your server as root. If you can, then great! You can run the below command lines via SSH to stop and disable cPHulk and attempt to log into the website version of WHM or cPanel. If you cannot SSH, try to use the VNC viewer available in the Cloud Portal and login. If that fails, continue with the below options. `/usr/local/cpanel/etc/init/stopcphulkd``/usr/local/cpanel/bin/cphulk_pam_ctl --disable` [Find more whm scripts here](https://documentation.cpanel.net/display/ALD/WHM+Scripts). So the Web, SSH, and VNC options did not work for you. Do you have another IP or computer to attempt these options from? [You could also try resetting your password via the single-user mode found here](https://www.atlantic.net/hipaa-compliant-hosting/how-to-atlantic-net-cloud-enter-single-user-mode-centos/). Contact us for assistance, and we will be able to try it from our end.   Once access is regained by disabling cPHulk, remember to immediately add your IP to cPHulk’s whitelist and re-enable cPHulk.   Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to: NIC Teaming Windows Server 2012 R2 with Hyper-V > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-nic-teaming-windows-server-2012-r2/ | Published: 2015-04-08 | Updated: 2024-06-04 | Author: Jose Velazquez ### Introduction This How-To will walk you through Configuring Windows Server 2012 R2 NIC Teaming to a Hyper-V Virtual Machine. NIC Teaming is the name Microsoft gives for the process of combining multiple network interface controllers (NICs) for speed, redundancy, or both. ### Prerequisites – A Windows Server 2012 R2 server with the Hyper-V role installed. – Minimum 2 NIC cards installed on your server. ## Configuring Windows Server 2012 R2 NIC Teaming Open the Server Manager. Right-click on Hyper-V and select **Configure NIC Teaming**. ![From server manager select hyper-v, proceed to right click your host, and select Configure Nic teaming.](https://www.atlantic.net/wp-content/uploads/2018/01/nic1.jpg) Server Manager: Hyper-V Locate the Task drop-down and select **New Team**. (Note: You will see the available NICs in the Adapters and Interfaces section). ![Under teams Select New Team](https://www.atlantic.net/wp-content/uploads/2018/01/nic2.jpg) NIC Teaming For Team Name, please type the name that you want to set it up as. Check the NIC cards that you want to team. In the additional properties drop-down, change the Load Balancing Mode to Hyper-V Port. (Note: Teaming Mode should be defaulted to “Switch Independent,” and Standby Adapter should be defaulted to “None(all adapters Active).” ![Select the ethernet devices which you'd like to participate in the team.](https://www.atlantic.net/wp-content/uploads/2018/01/nic3.jpg) New Team You will get a red Fault alert on the status. Don’t worry, it will come right up shortly and change to a green OK status. ![Sample Team Status](https://www.atlantic.net/wp-content/uploads/2018/01/nic4.jpg) Team Status ![Team status](https://www.atlantic.net/wp-content/uploads/2018/01/nic5.jpg) Team status Click on the **Team Interface** tab. Right-Click on your Team Name and select Properties. ![Team interface properties](https://www.atlantic.net/wp-content/uploads/2018/01/nic6.jpg) Team interface properties In the Properties, you should see the Description set to “Microsoft Network Adapter Multiplexor Driver.” In the VLAN membership, verify that the Default option is selected and click OK. ![General Properties.](https://www.atlantic.net/wp-content/uploads/2018/01/nic7.jpg) General Properties. Go to Control Panel. Click **Network and Internet**. Click N**etwork Connections** and Right-Click on Your Team Name. Activate the “Microsoft Network Adapter Multiplexor Protocol (If it is not already checked). ![Team Properties](https://www.atlantic.net/wp-content/uploads/2018/01/nic8.jpg) Team Properties Go back to the Server Manager. Right-click on your server and select Hyper-V Manager.  Select the Virtual Switch Manager. Click **Create Virtual Switch.** Create a Name for the Virtual Switch. Select **External Network, and click** on the **Microsoft Network Adapter Multiplexor Driver**. Verify that the “Enable virtual LAN identification for management operating system” is checked. Then Click Apply and OK. ![Create a virtual switch from your New multiplexor team](https://www.atlantic.net/wp-content/uploads/2018/01/nic9.jpg) Virtual Switch Verify that NIC Teaming is working correctly. Unplug one of the Network Cables on the NIC and notice that the server will remain with the network connection. Plug the Network Cable back and try it with the other Network Cable. (Note: You can also open up the command prompt while having one of the Network Cables disconnected and PING the Server. You will get a reply from the server with no problem). Congratulations! You have just Configured Windows Server 2012 R2 NIC Teaming to a Hyper-V Virtual Machine. Thank you for following along in this How-To and check back with us for any new updates, or find out more about [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) and [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Install Ruby on Rails on Ubuntu 20.04 with RVM > URL: https://www.atlantic.net/vps-hosting/how-to-install-ruby-rails-ubuntu-20-04-rvm/ | Published: 2015-04-10 | Updated: 2024-10-21 | Author: Atlantic.Net NOC ##### Verified and tested 06/01/21 ### Introduction Installing Rails in Ubuntu has gotten much more accessible in recent days. The easiest way to do this is via installing RVM (Ruby Version Manager). ![Ruby on Rails by Walker Cahall http://www.waltronic.net/](https://www.atlantic.net/wp-content/uploads/2018/01/RAILSv1-01.png) *Ruby on Rails by [Walker Cahall ](http://www.waltronic.net/)* ## Install Required Dependency First, you will need to install some dependencies on your server. You can install all of them with the following command: ``` apt-get install gnupg2 curl wget -y ``` Once all the packages are installed, you can proceed to the next step. ## Installing Rails on Ubuntu In this section, we will show you how to install Ruby on Rails with RVM. First, download and add the GPG key with the following command: ``` gpg --keyserver hkp://keys.gnupg.net --recv-keys 409B6B1796C275462A1703113804BB82D39DC0E3 7D2BAF1CF37B13E2069D6956105BD0E739499BDB ``` Next, install the RVM with the following command: ``` curl -sSL https://get.rvm.io | bash -s stable ``` Next, activate the RVM using the following command: ``` source /usr/local/rvm/scripts/rvm ``` Next, install the latest stable version of Ruby with the following command: ``` rvm install 3.0.1 ``` Next, set the Ruby version as the default version: ``` rvm use 3.0.1 --default ``` Next, verify the installed version of Ruby with the following command: ``` ruby -v ``` Output: ``` ruby 3.0.1p64 (2021-04-05 revision 0fb782ee38) [x86_64-linux] ``` Next, install the bundler with the following command: ``` gem install bundler ``` Next, install the Rails using the gem command: ``` gem install rails ``` Once the Rails is installed, verify the installed version of Rails with the following command: ``` rails -v ``` You should get the following output: ``` Rails 6.1.3.2 ``` Congratulations! You should now have rails installed on your ubuntu server. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # The HIPAA Compliant Cloud: An Introductory Report > URL: https://www.atlantic.net/hipaa-compliant-hosting/the-hipaa-compliant-cloud-an-introductory-report/ | Published: 2015-04-13 | Updated: 2026-03-01 | Author: Sam Guiliano More and more healthcare companies are evaluating the cloud as a possible environment for data processing and storage. As more investment has been pumped into the cloud industry, systems have become substantially more robust and complex. However, federal law dictates that providers, health plans, and health data clearinghouses must keep all “protected health information” (PHI) secure and confidential – and the role of technology providers is critical. “The HIPAA Omnibus Rule had several changes in how CEs and business associates could handle patient data,” [explains Elizabeth Snell of *HealthIT Security*](http://healthitsecurity.com), “and what the ramifications will be if that data is compromised in a data breach.” ## HIPAA Compliance As of the Final Omnibus Rule, companies that provide any solution handling American patient data as “business associates” of healthcare companies – extending from paper shredders to cloud hosts and software developers – must comply with the same essential privacy, security, and breach notification rules established for healthcare firms (a.k.a “covered entities”). Keep in mind, though, that noncompliance is rampant. *FierceHealthIT* cited an Office of Civil Rights (HHS Department) attorney stating that the fines issued to healthcare companies failing to meet HIPAA stipulations would skyrocket between June 2014 and June 2015. Since it’s clear that not everyone is following the protective data measures required by the act, self-education is critical – and that’s the intent of this preliminary report on the cloud for health data. **What is Cloud Computing?** Virtual cloud servers allow businesses to store data and utilize resources located elsewhere while accessing from anywhere they want. Essential IT functions such as maintenance of servers and patching of operating software are entrusted to a third party, typically called a cloud service provider (CSP). One way [HIPAA Cloud Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) is used in healthcare is for imaging, taking advantage of the unprecedentedly affordable performance. “Cloud services can help healthcare organizations become more connected,” argues Snell, “which is beneficial in an increasingly digital industry.” As you consider how you want to interact with the cloud, it’s helpful to know that there are three primary categories of public cloud providers: - **Software as a service (SaaS)** – This cloud provider gives you specific software capabilities such as an email system or a customer service portal. - **Platform as a service (PaaS)** – You have access to external resources delivered through a platform established by the digital provider. Within reason, you can put whatever type of software you want on that platform. - **Infrastructure as a service (IaaS)** – This option gives you complete freedom and control. You are actually in charge of your own cloud server in this situation. **The “Final” Omnibus Rule & the Cloud** The Omnibus Rule, which went into effect in 2013, establishes that the health data of American citizens must remain private regardless of location. The rule states clearly that it doesn’t matter if a third party does not regularly look at the health data of its clients. All that matters is that the data is accessible to them. Essentially, any digital provider handling health data *in any way* must comply with the law. In a report on the intersection of the Omnibus Rule and the cloud, the Center for Democracy and Technology (CDT) noted that it was unclear previously if companies that did not regularly access the data needed to worry about HIPAA themselves. Now it’s clear that they do. The responsibilities of business associates range vastly based on how they are interacting with the protected health data, explains the CDT whitepaper. In a nutshell, though, a service provider that has properly blocked itself off from the data and “that adheres to HHS standards for encryption should have little liability risk as a business associate (except to ensure that it properly manages encryption).” Partially because the cloud has matured and because the relationship to HIPAA is more evident for all parties involved, cloud storage is now considered an option worth legitimately exploring – with many of the major hosting providers getting certified to prove their compliance to customers. Cloud companies typically provide advice to their clients to achieve full compliance. An Amazon Web Services whitepaper on the topic notes that HIPAA-compliant health data should be encrypted with 256-bit AES cryptography or similar. Additionally, the document argues that you can reduce your risk and improve your resource efficiency by omitting any nonessential patient data before sending anything through a cloud system. **Is the Cloud a Necessity?** Cloud is by no means necessary to operate in the current healthcare climate. Many of our HIPAA compliant customers use dedicated servers, even if they want to divide those servers up into numerous virtual machines. However, as Snell indicates, healthcare companies “might find that this storage option is ideal for them as it can cut down on certain operating or storage costs, and could streamline many services.” Finally, she stresses the importance of a solid business associate agreement. Do you need to maintain compliance with HIPAA, as with a *self-encrypted storage plan*? We offer comprehensive, fully audited [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions within our SSAE 16 certified datacenter, all backed by a transparent and fair business associate agreement.   --- # Atlantic.Net’s HIPAA compliance benefits companies and patients > URL: https://www.atlantic.net/press-releases/atlantic-net-offers-hipaa-audited-hosting-solution-to-give-medical-companies-and-patients-protection/ | Published: 2015-04-14 | Author: Editorial Team ORLANDO, Fla. April 14, 2015 — Atlantic.Net announces its designation as HIPAA audited to give medical companies and patients protection through [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions to better secure personal information in an environment built to safeguard ePHI (electronic protected health information.) Helping clients to realize the importance of compliance to HIPAA regulations and protecting patient health information, Atlantic.Net offers HIPAA Compliant Hosting solutions that have been certified to meet the HIPAA Security Rule by an independent third party, [A-lign](http://www.a-lign.com/), a full-service security, assurance and compliance solutions firm. “Our audit finds Atlantic.Net is in full compliance with the relevant controls and meets all HIPAA compliance standards and requirements for physical and environmental controls, and the management oversight of the environment,” said Gene Geiger, a Partner at A-lign. Colocation facilities are considered business associates under HIPAA and must implement the applicable safeguards to host their servers containing ePHI with a third party and are required to ensure that the company is HIPAA compliant. “Our HIPAA compliance certification by an independent third party auditor signifies our continued commitment to focus on providing affordable and reliable hosting solutions for the healthcare industry,” said Marty Puranik, President, and CEO of Atlantic.Net. “This goes hand in hand with our commitment to secure patients’ medical records backed by top-notch hosting operations.” Atlantic.Net offers competitive HIPAA Compliant Hosting pricing in affordable HIPAA Linux and Windows cloud hosting packages. All of the company’s solutions feature heightened security with a fully managed firewall; VPNs with encryption; and an intrusion detection system.  This is all backed by an Infrastructure that has received specialized reports.  The audit for the reports is based on the AICPA guidelines, including the Trust Service Principles, and included tests of operating effectiveness and controls relevant to security and availability principles. **About Atlantic.Net:** In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over its first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting, Web design, and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award-winning customer service and investment in cutting-edge technology is still a guiding force behind the company.  Today, Atlantic.Net has state of the art fast SSD cloud servers offering the very best in cloud hosting solutions, one-click WordPress cloud hosting, and many other services. To learn more about Atlantic.Net’s complete line of services including [healthcare hosting](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/), call 1.866.618.3282 or visit or visit [Atlantic.Net](https://www.atlantic.net/vps-hosting/). CONTACT: [marketing@atlantic.net](mailto:marketing@atlantic.net) --- # How to: WHM and cPanel Initial Basic Configuration on CentOS 7.x > URL: https://www.atlantic.net/vps-hosting/how-to-whm-cpanel-initial-configuration/ | Published: 2015-04-15 | Updated: 2026-03-02 | Author: Jason Mazzota ##### Verified and Tested 06/01/2021 ### Introduction In this guide, we will be reviewing the basic configuration options on first initializing your cPanel & WHM server. It will examine some essential areas that may need to be customized by you to get the whole experience and your needs out of cPanel & WHM. ## Initial Configuration of cPanel & WHM on CentOS 7 Once you have your cPanel & WHM server provisioned, you will want to log into the server. Upon fresh login, you should be presented with an End User Agreement license page like the one below. After review, click on the blue button “I Agree/Go to Step 2.” ![Accept License Agreement](https://www.atlantic.net/wp-content/uploads/2018/01/whm1-2.png) License Agreement   On this next page, you will be prompted to set up networking. The first section on this page is the Contact information. This is information so the server knows how to contact you should something go wrong. This section looks like the below, and the areas 1, 2, 3, and 4 are described as follows: ![Fill in Contact information, SMS address, AIM Name and ICQ Number accordingly.](https://www.atlantic.net/wp-content/uploads/2018/01/whm2-2.png) Contact Information   1. “Server Contact Email Address” – This first area is the server contact email address. This would be the email address the server will email should anything go wrong. It is recommended that you insert a contact address that you often check, as it is a required field. 2. “Server Contact SMS Address” – This is an optional field for putting in a phone or pager email that is capable of receiving SMS. 3. “Server Contact AIM Name” – This is an optional field for using an AIM username for the server to message. It will prompt you for a username and password should you enable this. 4. “Server Contact ICQ Number” – This is an optional field for an ICQ number, and it will ask you for the number and password should you enable this.   The next section is the Hostname section which defaults to the below image. For this field, you DO NOT want to use your base domain/website. You will want to use a subdomain of your domain. Something like “server1.domain.tld” or “webserver.domain.tld” where domain.tld is your domain/website. If you do not have a domain, you may make up/create a subdomain, but please note that this value will never resolve if there are no DNS records for it. As an additional note, please use a value here that you either have or will create an A record or other type of DNS record for. This will allow you to access your server by using that subdomain easily. ![Set your servers FQDN](https://www.atlantic.net/wp-content/uploads/2018/01/whm3-2.png) Hostname   The third section on this page is for Resolvers. These are important as they handle how your server will resolve traffic and where it will go. These should be left at the default value of 209.208.127.65 and 209.208.25.18. There is not a third resolver for our servers to use. ![Input primary and secondary DNS servers](https://www.atlantic.net/wp-content/uploads/2018/01/whm4-2.png) Resolvers The last section is the Main Network Device. This field should also be left as the default value, as eth0 is the primary network device. Once done, you can click on “Save & Go to Step 3.” ![Select primary network interface.](https://www.atlantic.net/wp-content/uploads/2018/01/whm5-2.png) Ethernet Device   The next page will be the “Setup IP Addresses” page. You do not have to do anything here unless you have already reserved and assigned an additional IP to this server. If you have not, you may click “Skip This Step and Use Default Settings.” If you have an additional IP address, add it to the field and click “Add IP(s).” ![Input IP addresses for which you will be hosting](https://www.atlantic.net/wp-content/uploads/2018/01/whm6-2.png) Setup IP Address   The next page will bring you directly to a Nameservers page. The first box here is Nameserver Configuration. It is important to note that if you are NOT using your server to host your own private or public DNS, you should choose the option “Disabled.” If you are using your own nameservers, pick the nameserver option that best applies to you. In most cases, the default BIND will work for your needs. ![If you chose to host your own DNS, select a DNS server to utilize.](https://www.atlantic.net/wp-content/uploads/2018/01/whm7-1.png) Name Server   After this, there is a section for choosing the nameservers that domains on this server will use. If you have your own nameservers for use, you will put these here. DO NOT leave the default values. Using our Cloud DNS for your domains, you will want to use ns1.quickroutedns and ns2.quickroutedns, as the picture below shows. ![Select the authoritative DNS servers for your domain.](https://www.atlantic.net/wp-content/uploads/2018/01/whm8-1.png) Authoritative DNS In the next section, you should leave it as is and click on the “Save & Go to Step 5.”   The next page deals with FTP, mail, and cPHulk services. In the first section for FTP, you can leave as the default, which is set to Pure-FTPD. If you’d rather use ProFTPD, you may do so. If you do not need FTP, you may disable it, but if you plan to upload files, it would be best to pick between Pure and Pro FTPD. ![Select your preferred FTP server.](https://www.atlantic.net/wp-content/uploads/2018/01/whm9.png) FTP Configuration   The following section deals with email and what you want to use for your mail on the server. If you won’t be using email, you can disable this. Otherwise, the default Dovecot is an excellent choice. You may use Courier if you prefer. There’s also the check box for Convert Mailbox Format. You can leave this checked, and it is only in play if you are migrating email from another server. ![Select your preferred MDA](https://www.atlantic.net/wp-content/uploads/2018/01/whm10.png) Mail Configuration   The following sections deal with cPHulk and Perl Modules. cPHulk is brute force protection built into cPanel & WHM. It’s a great idea to enable this and leave it on the default. Remember to add your IP to the whitelist for the service once this configuration is done. The standard set of perl modules is used if you use perl modules that reference /usr/bin/perl. Otherwise, it is not needed. You can click on “Save & Go to Step 6” when done here. ![Enable cPHulk brute force protection.](https://www.atlantic.net/wp-content/uploads/2018/01/whm11.png) cPHulk   The last page is for Quotas. This page lets you determine if you want to use quotas or not. If you do not, you can not keep track of the website’s quotas or email quotas. Once you decide, click “Finish Setup Wizard,” and we are done with the initial setup. This will bring you to the next page called Feature Showcase. ![Chose your quote enforment preference.](https://www.atlantic.net/wp-content/uploads/2018/01/whm12.png) Quotes   The first section on the Feature Showcase page deals with Recommended Features. It’s recommended to keep these enabled, but it is your choice. ![Recommended Features](https://www.atlantic.net/wp-content/uploads/2018/01/whm13.png) Recommended Features   After that is the New Features list. These are features you can enable or opt-out of. They mainly deal with email. If you would like to email clients to store a copy of messages, turn on the Archiving. If you would like users to use Auto-Discovery in their mail client for email settings, enable the Auto Discovery option. Query Apache for “nobody” senders is one that we highly recommend is enabled. This will allow you to track down compromised email accounts more easily. We also recommend the SMTP Restrictions options to block compromises. Trust X-PHP-Script should only be used if you’re positive no one on your system will be sending or being compromised. This should rarely be enabled. Once done, click the “Save Settings” button, and that will complete all of the configuration necessary to start using cPanel & WHM. ![You may chose to enable or disable any neeew features offered by WHM.](https://www.atlantic.net/wp-content/uploads/2018/01/whm14.png) New Features   Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Tomcat and Java on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-tomcat-java-centos-8/ | Published: 2015-04-16 | Updated: 2024-10-21 | Author: Jason Mazzota ##### Verified and Tested 6/01/21 ### Introduction This tutorial will take you through installing Tomcat 9 on CentOS 8 x86_64. Tomcat is an application server used to execute Java servlets and publish web pages that include Java coding. Tomcat requires Java to be installed, which will be covered in this tutorial. ![How to Install Tomcat and Java on CentOS 8](https://www.atlantic.net/wp-content/uploads/2018/01/tomcat1.png) *Illustration by [Walker Cahall](http://www.waltronic.net/)* ## Step 1 – Install Java Tomcat is a Java-based application, so Java must be installed on your server. If not installed you can install it with the following command: ``` dnf install java-11-openjdk-devel ``` Once the Java is installed, check the Java version using the following command: ``` java --version ``` Output: ``` openjdk 11.0.11 2021-04-20 LTS OpenJDK Runtime Environment 18.9 (build 11.0.11+9-LTS) OpenJDK 64-Bit Server VM 18.9 (build 11.0.11+9-LTS, mixed mode, sharing) ``` ## Step 2 – Download Tomcat First, you will need to create a user to run Tomcat. You can make it with the following command: ``` useradd -m -U -d /opt/tomcat -s /bin/false tomcat ``` Next, you only need to download Tomcat. You can find the latest version of Tomcat on the [Tomcat](https://tomcat.apache.org/download-90.cgi) website. At the time of this article, the latest version of Tomcat 9 is Tomcat 9.0.46. You can download it by running: ``` wget https: //downloads.apache.org/tomcat/tomcat-9/v9.0.46/bin/apache-tomcat-9.0.46.tar.gz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar -xvf apache-tomcat-9.0.46.tar.gz ``` Next, move the content from the extracted directory to the /opt/Tomcat: ``` mv apache-tomcat-9.0.46/* /opt/tomcat/ ``` Next, set proper permission and ownership to the /opt/tomcat directory: ``` chown -R tomcat: /opt/tomcat chmod -R 755 /opt/tomcat ``` ## Step 3 – Create a Systemd Service File for Tomcat Next, you will need to create a systemd service to manage the Tomcat service. You can create it with the following command: ``` nano /etc/systemd/system/tomcat.service ``` Add the following lines: ``` [Unit] Description=Tomcat 9 servlet container After=network.target [Service] Type=forking User=tomcat Group=tomcat Environment="JAVA_HOME=/usr/lib/jvm/jre" Environment="JAVA_OPTS=-Djava.security.egd=file:///dev/urandom" Environment="CATALINA_BASE=/opt/tomcat/" Environment="CATALINA_HOME=/opt/tomcat/" Environment="CATALINA_PID=/opt/tomcat//temp/tomcat.pid" Environment="CATALINA_OPTS=-Xms512M -Xmx1024M -server -XX:+UseParallelGC" ExecStart=/opt/tomcat/bin/startup.sh ExecStop=/opt/tomcat/bin/shutdown.sh [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the Tomcat service and enable it to start at system reboot: ``` systemctl enable --now tomcat ``` You can also check the status of the Tomcat service with the following command: ``` systemctl status tomcat ``` Output: ``` ● tomcat.service - Tomcat 9 servlet container Loaded: loaded (/etc/systemd/system/tomcat.service; enabled; vendor preset: disabled) Active: active (running) since Tue 2021-06-01 00:59:30 EDT; 4s ago Process: 1661 ExecStart=/opt/tomcat/bin/startup.sh (code=exited, status=0/SUCCESS) Main PID: 1668 (java) Tasks: 30 (limit: 12524) Memory: 155.5M CGroup: /system.slice/tomcat.service └─1668 /usr/lib/jvm/jre/bin/java -Djava.util.logging.config.file=/opt/tomcat//conf/logging.properties -Djava.util.logging.manager=o> Jun 01 00:59:30 centos systemd[1]: Starting Tomcat 9 servlet container... Jun 01 00:59:30 centos systemd[1]: Started Tomcat 9 servlet container. ``` ## Step 4 – Configure Tomcat Next, you will need to set Tomcat admin password and user for admin-gui and manager-gui. You can set it by editing the tomcat-users.xml file: ``` nano /opt/tomcat/conf/tomcat-users.xml ``` Add the following lines above the last line : ``` ``` Save and close the file when you are finished. By default, the Tomcat manager and Host manager apps are configured to access only from the localhost. So you will need to configure it to access from the outside network. To configure the Manager app, edit the context.xml file: ``` nano /opt/tomcat/webapps/manager/META-INF/context.xml ``` Remove the following lines: ``` ``` Save and close the file. To configure the Host Manager app, edit the context.xml file: ``` nano /opt/tomcat/webapps/host-manager/META-INF/context.xml ``` Remove the following lines: ``` ``` Save and close the file, then restart the Tomcat service to apply the changes: ``` systemctl restart tomcat ``` ## Step 5 – Access Tomcat Web UI Now, open your web browser and access the Tomcat using the URL HTTP: //your-server-ip:8080. You should see the following page: ![Tomcat Dashboard](https://www.atlantic.net/wp-content/uploads/2015/04/p1-1024x536.png) Now, click on the Manager App. You should see the following page: ![Tomcat Login](https://www.atlantic.net/wp-content/uploads/2015/04/p2.png) Provide your admin username, password and click on the Sign-in button. You should see the following page: ![Tomcat Manager App](https://www.atlantic.net/wp-content/uploads/2015/04/p3-1024x536.png) Now, go to the Tomcat main dashboard again and click on the Host Manager. You should see the following page: ![Tomcat Host Manager App](https://www.atlantic.net/wp-content/uploads/2015/04/p4-1024x538.png) Congratulations! You have just installed Tomcat and Java on your CentOS 8 Cloud Server. Thank you for following along in this How-To, and check back with us for any new updates. You may want to follow the guides on [changing the CentOS 8 hostname](https://www.atlantic.net/hipaa-compliant-hosting/how-to-change-hostname-centos-6-9-7-x-8-x/). Contact us today for a consultation for more information on our reliable [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Linux, Apache, MySQL and PHP (LAMP) on a Fedora 20 Cloud Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-lamp-fedora-20/ | Published: 2015-04-17 | Updated: 2024-06-06 | Author: Jose Velazquez ##### Verified and Tested 02/27/15 ### Introduction In this How-To, we will walk you through the install LAMP on your Fedora 20 Cloud Server. LAMP is simply a software bundle that consists of 4 components. L (Linux) is the core of the platform, which will sustain the other components. A(Apache)will be used for the web service. M(MySQL)will be used for database management, and P(PHP) will be the programming language. It is making the platform a LAMP. ## Install Lamp on Fedora 20 To install lamp, the first thing we need to do is install Apache with the following command: ``` yum install httpd ``` Start Apache with the following command: ``` systemctl start httpd.service ``` You will want the Apache service to start on start-up/reboot with the following command: ``` systemctl enable httpd.service ``` Add the following commands in Apache to override in Firewall-cmd as follows: ``` firewall-cmd --set-default-zone=public ``` ``` firewall-cmd --permanent --zone=public --add-service=http ``` ``` firewall-cmd --permanent --zone=public --add-service=https ``` ``` firewall-cmd --reload ``` You can now verify that Apache is installed correctly by typing http:// and your IP on your browser. http:// YOUR.IP.ADD.RESS You should see the following screenshot in your browser: ![Default apache test page](https://www.atlantic.net/wp-content/uploads/2018/01/cloud1.jpg) Default apache test page You can edit the main configuration file to your preference for one or many websites with the following commands: ``` vi /etc/httpd/conf/httpd.conf ``` or ``` nano /etc/httpd/conf/httpd.conf ``` Un-comment the line containing the text **NameVirtualHost *:80**and edit accordingly**** Save the file Restart the Apache HTTP ``` systemctl restart httpd.service ``` Install MySQL with the following command to begin the install: ``` yum install mysql mysql-server ``` Start the service with the following command: ``` systemctl start mysqld.service ``` Enable MySQL to start upon a reboot with the following command: ``` systemctl enable mysqld.service ``` Secure MySQL with the following command: ``` mysql_secure_installation ``` Note: When prompted with “Enter current password for root,” hit enter for none then Y(Yes) to set the MYSQL password. You will be prompted with a series of questions. Type Y for yes on all of them; see the screenshot below: ![Follow the on screen prompts and respond accordingly.](https://www.atlantic.net/wp-content/uploads/2018/01/cloud2.jpg) Mysql Secure Installation Install PHP with the following command to begin the install: ``` yum install php ``` Restart apache to take all the changes: ``` systemctl restart httpd.service ``` Create a test PHP file in the following directory with the following command: ``` sudo vi /var/www/html/info.php ``` Insert the following code in the space, then save and exit: ``` ``` Restart Apache, so all the changes take effect: ``` sudo service httpd restart ``` ![Sample info.php output.](https://www.atlantic.net/wp-content/uploads/2018/01/cloud3.jpg) info.php Test your page in your browser with the following hyperlink changed with your IP address: http:// YOUR.IP.ADD.RESS/info.php Congratulations! You have just installed LAMP on your Fedora 20 Cloud Server. Thank you for following along in this How-To, and check back with us for any new updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and V[PS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # What is cPanel/WHM? > URL: https://www.atlantic.net/vps-hosting/what-is-cpanel-whm/ | Published: 2015-04-20 | Author: Chelsea Fieler ## What is cPanel/WHM? cPanel is a leading web-based control panel that intuitively lets users manage all aspects of their website and creates valuable functionality by streamlining essential processes. From adding sub-domains and email accounts to installing scripts and checking bandwidth, the control and flexibility provided by cPanel are unsurpassed. By integrating cPanel with the impressive power of a Virtual Private Server from Atlantic.Net, the result is a truly efficient way to scale hosting solutions and manage individual servers from one user-friendly interface. ## Enhanced VPS Offering with cPanel cPanel/WHM is designed with several administrative levels and offers different user communication channels for administrators, resellers, and end-users with email-based interfaces. These various organizational levels provide security, ease of use, and flexibility for everyone, whether a server administrator or simply an email account user. A few of cPanel’s features include the ability to manage files via FTP, manage email accounts, control spam, view website statistics, and manage databases using MySQL, PostgresSQL, and phpMyAdmin. In addition, [cPanel VPS Hosting](https://www.atlantic.net/vps-hosting/) offers valuable services such as automated backups and intuitive DNS management. ## All VPS Plans Are Equipped With Cloud Features! cPanel/WHM is available on Atlantic.Net’s VPS in the Cloud platform, making web hosting and managing individual servers easy and effective. With Atlantic.Net’s world-class [VPS hosting](https://www.atlantic.net/vps-hosting/) service, users can provision cPanel/WHM-ready VPS in seconds, as opposed to the 60-90 minutes required for self-installation or on-site physical or off-site dedicated servers. Call 1.866.618.3282 today or email us at sales@atlantic.net for VPS in the Cloud! --- # How to Install Node.js on Ubuntu 14.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-node-js-ubuntu-14-04/ | Published: 2015-04-20 | Updated: 2024-06-06 | Author: Jose Velazquez ### Introduction Node.js is a popular platform that is used to build quick and upgradable network applications efficiently. It achieves maximum productivity with the minimum effort needed, often used in applications used throughout many devices. ## Install Nodejs There are several ways that we can install node.js in Ubuntu 14.04. We will go over the basic install, the PPM install, and the NVM install. ## The Basic install (Distro-Stable Version) To update the current packages, the command is: ``` sudo apt-get update ``` Install the node.js package, the command is: ``` sudo apt-get install nodejs ``` Install npm(Node Package Manager)as well for package management; the command is: ``` sudo apt-get install npm ``` Verify the current version of Node.js installed, the command is: ``` node -v ``` Congratulations! You have installed Node.js using The Basic(Distro-Stable Version) install. ## The PPA install (Personal Package Archive) Install the PPA to get access to its contents; the command is: ``` curl -sL https://deb.nodesource.com/setup | sudo bash - ``` If you get the following error message “-bash: curl: command not found,” run the following command to update the apt-get file: ``` sudo apt-get install apt-file && apt-file update ``` Update your local packages; the command is: ``` sudo apt-get update ``` Install the node.js, the command is: ``` sudo apt-get install nodejs ``` Install npm(Node Package Manager)to manage your package. ``` sudo apt-get install npm ``` Verify your version of Node.js is installed; the command is: ``` node -v ``` Congratulations! You have installed Node.js using The PPA(Personal Package Archive) install. ## The NVM install (Nodejs Version Manager) The NVM install is another way of installing Node.js ``` using apt. ``` Installed through a tool called, ``` nvm ``` (Node.js version manager). Using NVM will give you a selection of different versions of Node.js, from the latest to several previous ones. Update the system to build the source packages; the command is: ``` sudo apt-get update ``` Install the following to make your components with the nvm script that we’ll go over next: ``` sudo apt-get install build-essential libssl-dev ``` Download then install the nvm script with the following command or get them from https://github.com/creationix/nvm ``` curl https://raw.githubusercontent.com/creationix/nvm/v0.7.0/install.sh | sh ``` The software will install in a subdirectory of your home directory ``` ~/.nvm ``` and will add the necessary lines to your ``` ~/.profile ``` file to use the file. With the following command, source the ``` ~/.profile ``` for your session to know about these changes, and you can access the nvm functionality. ``` source ~/.profile ``` Nvm has been installed. Now you can install whatever version of Node.js is available. To view the versions that are currently available, the command is: ``` nvm ls-remote ``` ![Sample nvm output](https://www.atlantic.net/wp-content/uploads/2018/01/node1.jpg) Sample nvm output You should see something like the following; Install the version you want with the command: ``` nvm install [your version] ``` Example: ``` nvm install 0.11.16 ``` Configure nvm to use the version of Node.js that you just downloaded; the command is: ``` nvm use [your version] ``` Example: ``` nvm use 0.11.16 ``` To verify the current version of Node.js installed, the command is: ``` node -v ``` If you have a lot of Node.js versions, see what’s installed, the command is: ``` nvm ls ``` ![Sample nvm ls](https://www.atlantic.net/wp-content/uploads/2018/01/node2.jpg) Sample nvm ls To default one of the versions that are installed, the command is: ``` nvm alias default [your version] ``` Example: ``` nvm alias default 0.11.16 ``` You can also reference it by the following alias: ``` nvm use default ``` You can have ``` npm ``` install packages to the Node.js project’s ``` ./node_modules ``` directory by using the standard format: ``` npm install express ``` ![Install npm](https://www.atlantic.net/wp-content/uploads/2018/01/node3.jpg) Install npm If you’d like to install it globally (available to the other projects using the same Node.js version), you can add the ``` -g ``` flag: ``` npm install -g express ``` ![Install npm](https://www.atlantic.net/wp-content/uploads/2018/01/node4.jpg) Install npm This will install the package in: ``` ~/.nvm/node_version/lib/node_modules/package_name ``` Installing globally will let you run the commands from the command line, but you’ll have to use link the package into your locally to require it from within a program: ``` npm link express ``` ![npm Link Express](https://www.atlantic.net/wp-content/uploads/2018/01/node5.jpg) npm Link Express Other options are available with the following command: ``` nvm help ``` ![Sample nvm help page](https://www.atlantic.net/wp-content/uploads/2018/01/node6.jpg) NVM Help Congratulations! You have installed Node.js using The PPA(Personal Package Archive) install. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Active Directory in Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-install-active-directory-windows-server-2012/ | Published: 2015-04-21 | Updated: 2024-06-05 | Author: Jose Velazquez ##### Verified and Tested 03/12/2015 ### Introduction This How-To will walk you through Installing Active Directory in Windows Server 2012. Active Directory, also known as AD, is a service that comes with many Windows Server Operating Systems. It is used to manage Domain Networks distinguishing an administrator user and regular users. This is done by verifying the specified security boundaries and policies for each user to maintain the Network secure and restricted. ### Prerequisites – A Server with Windows Server 2012. If you do not have a server already, you can visit our [VPS Hosting](https://www.atlantic.net/vps-hosting/) page and spin a new server up in under 30 seconds. ## Installing Active Directory on Windows Server 2012 Open the **Server Manager** from the taskbar. From **Server Manager **Dashboard, select **Add roles and features**. This will launch the Roles and Features Wizard, allowing modifications to be performed on the Windows Server 2012 instance. ![From server manager selct add roles and features](https://www.atlantic.net/wp-content/uploads/2018/01/windows1-1.jpg) Server Manager   Select **Role-based or feature-based** installation from the Installation Type screen and click **Next**. ![Select Roles-based or feature-based installation](https://www.atlantic.net/wp-content/uploads/2018/01/windows2-1.jpg) Installation Type   By default, the current server is selected. Click **Next** to proceed to the Server Roles tab. ![Select your server](https://www.atlantic.net/wp-content/uploads/2018/01/windows3-1.jpg) Server Selection   From the Server Roles page, place a checkmark in the box next to Active Directory Domain Services. A notice will appear explaining that additional role services or features are also required to install domain services; click Add Features. ![Review your features and Include managementn tools](https://www.atlantic.net/wp-content/uploads/2018/01/windows4-1.jpg) Add roles and features wizard.   Review and select**optional features** to install during the AD DS installation by placing a check in the box next to any desired features; Once done, click **Next**. ![Add any additional optional features.](https://www.atlantic.net/wp-content/uploads/2018/01/windows5-1.jpg) Features   Review the information on the **AD DS tab** and click **Next**. ![Select next.](https://www.atlantic.net/wp-content/uploads/2018/01/windows6.jpg) AD DS   Once you click next, the following window will quickly come up. Review the installation and click **Install**. ![Confirm your installation and select Install](https://www.atlantic.net/wp-content/uploads/2018/01/windows7.jpg) Confirm   Congratulations! You have just Installed Active Directory in Windows Server 2012. If you would like to configure Active Directory, please Check our “[Configuring Active Directory in Windows Server 2012](https://www.atlantic.net/vps-hosting/how-to-configuring-active-directory-windows-server-2012/)” article. Thank you for following along in this How-To, and check back with us for any new updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How To Rollback A Cloud Server > URL: https://www.atlantic.net/vps-hosting/how-to-rollback-cloud-server/ | Published: 2015-04-23 | Updated: 2024-06-06 | Author: Ariel Beltre ##### Verified and Tested 04/20/2015 ### Introduction In this article, we will be going over how to rollback your server. Rolling back a server can be helpful when you have experienced performance issues, and the server will not boot or operate as it should. This process is similar to a system restore on a computer where the system will revert the settings to a point in time where the issue is no longer present. Here, we will review how to complete this process. ## What Do You Need? You will need an Atlantic.Net cloud server with backups enabled. Please refer to the articles “How To Create A New Atlantic.Net Cloud Server” as well as “Does Atlantic.Net Offer Data Backup For My Cloud Server” for more information. ## Rollback A Cloud Server To rollback, your server, first, log in to your Atlantic.net [account](https://cloud.atlantic.net/?page=signup) and click on “Servers” from the left-hand side, as shown below. ![Select Servers locate to the left of your screen.](https://www.atlantic.net/wp-content/uploads/2018/01/roll1.png) Manage Cloud Server Once done, a window will display a list of all the active servers on your account. You must click on the server you want to perform the rollback on from this list. ![Select Cloud server to manage](https://www.atlantic.net/wp-content/uploads/2018/01/roll2.png) Select Cloud server to manage After you have selected the desired server, the network information for that server will be displayed. Click on the button that reads “Backups” on the upper right-hand side. ![Select Backups](https://www.atlantic.net/wp-content/uploads/2018/01/roll3.png) Select Backups Lastly, you will be presented with a list of available dates from which you can revert your settings to. Scroll through the available rollback dates, and select a desired restore point from the drop-down box. Once you have chosen a date, click on the “Restore Backup” button. This will revert the server’s settings and, once completed, will reboot the server. The server will once again be accessible. ![Select Restore Backups](https://www.atlantic.net/wp-content/uploads/2018/01/roll4.png) Select Restore Backups ### Conclusion Having backups for your cloud server is an excellent feature to have enabled, as it can be used as a last resort to correct any issues the server may be experiencing at the time. Check back for more updates from Atlantic.Net, or learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to: Configuring Active Directory in Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-configuring-active-directory-windows-server-2012/ | Published: 2015-04-23 | Updated: 2024-06-05 | Author: Jose Velazquez ##### Verified and Tested 03/12/2015 ## Introduction In this how-to, we will walk you through Configuring Active Directory in Windows Server 2012. Active Directory, also known as AD, is a service that comes with many Windows Server Operating Systems. It is used to manage Domain Networks distinguishing an administrator user and everyday users. Once the AD DS role is installed, the server will need to be configured for your domain. ## Prerequisites – A Server with Windows Server 2012. If you do not have a server already, you can visit our [VPS Hosting](https://www.atlantic.net/vps-hosting/) page and spin a new server up in under 30 seconds. – Active Directory(AD) installed on your server. See the following article, “[Installing Active Directory in Windows Server 2012](https://www.atlantic.net/vps-hosting/how-to-install-active-directory-windows-server-2012/),” for more information. ## Configuring Active Directory Open the **Server Manager** from the taskbar. Open the Notifications Pane by selecting the **Notifications icon** from the top of the Server Manager. From the notification regarding configuring AD DS, click **Promote this server to a domain controller**. ![In server manager select Promote server to a domain controller](https://www.atlantic.net/wp-content/uploads/2018/01/configure1.jpg) Promote Server   From the Deployment Configuration tab, select **Add a new forest** from the radial options menu. Insert your root domain name into the **Root domain name** field. ![Under Deployment Configuration add a new forest and create your root domain name.](https://www.atlantic.net/wp-content/uploads/2018/01/configure2.jpg) Deployment Configuration   Review and **select a Domain and Forest functional level**. Once selected, **fill in a DSRM password** in the provided password fields. The DSRM password is used when booting the Domain Controller into recovery mode. ![Set you forest and domain level respective of your intrastructure requirements and create a password.](https://www.atlantic.net/wp-content/uploads/2018/01/configure3.jpg) Domain Controller Options   Review the warning on the DNS Options tab and select **Next**. ![Create a DNS delegation should you need.](https://www.atlantic.net/wp-content/uploads/2018/01/configure4.jpg) DNS Options   Confirm or enter a NetBIOS name and click **Next**. ![Under Additional Options create your NetBIOS domain name. This may be the same as your rood domain name.](https://www.atlantic.net/wp-content/uploads/2018/01/configure5.jpg) Additional Options   Configure the location of the SYSVOL, Log files, and Database folders and click **Next**. ![You may leave your paths default, or chose custom paths.](https://www.atlantic.net/wp-content/uploads/2018/01/configure6.jpg) Paths   Review the configuration options and click **Next**. ![Review your configuration and select Next](https://www.atlantic.net/wp-content/uploads/2018/01/configure7.jpg) Review Options   The system will check to ensure all necessary prerequisites are installed on the system before moving forward. If the system passes these checks, you will proceed by clicking **Install**. Then, the system will automatically reboot. ![Once you pass the prerequisite check you may proceed to complete the installation.](https://www.atlantic.net/wp-content/uploads/2018/01/configure8.jpg) Prerequisite checks Once the server has completed the reboot, reconnect via RDP. Congratulations! You have just Configured Active Directory in Windows Server 2012. Thank you for following along in this How-To, and check back with us for any new updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Apache on Debian 7 > URL: https://www.atlantic.net/vps-hosting/how-to-install-apache-debian-7/ | Published: 2015-04-23 | Updated: 2024-06-05 | Author: Jose Velazquez ##### Verified and Tested 02/26/15 ### Introduction In this How-To, we will walk you through the install of Apache on Debian 7. Apache is a web server that is very popular in Linux systems and over the Internet. It is used by many Web Hosting companies worldwide because of its popularity and efficiency in hosting sites over the World Wide Web. ### Prerequisites A cloud server with Debian already installed.  If you do not have a server already, spin up a new market-leading server from Atlantic.Net in under 30 seconds. ## Install Apache on Debian 7 Install Apache with the following command: ``` sudo apt-get install apache2 ``` Start Apache with the following command: ``` service apache2 start ``` Verify if all is working by typing http:// YOUR.IP.ADD.RESS ![Installing Apache on Debian-1](https://www.atlantic.net/wp-content/uploads/2018/01/Installing-Apache-in-Debian-1.jpg) Congratulations! You have just installed Apache on Debian 7 Cloud Server. Thank you for following along in this How-To, and check back with us for any new updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to: Installing Python 3 and Creating a Virtual Environment (venv) in CentOS 7 > URL: https://www.atlantic.net/vps-hosting/how-to-installing-python-3/ | Published: 2015-04-24 | Updated: 2024-06-04 | Author: Andrew Mora ##### Verified and Tested 04/04/21 ### Introduction This article covers the installation of Python 3.9 on a CentOS 7 operating system and how to create a Virtual Environment(venv) with pyvenv for which Python 3 can run. It is essential to note the directories that we are installing is Python 3.9. **CentOS 7.x is dependent on Python 2.x to function correctly, do not overwrite the Python 2 installation accidentally**. If you still need to install Python 2, follow our [how-to on this here](https://www.atlantic.net/vps-hosting/how-to-install-python-2-7-centos-anaconda/). ### Prerequisites You’ll need to yum install the following packets to meet all the Python 3 and PIP dependencies: – You need a CentOS 7 server. If you do not have a server already, you can spin up a dependable virtual private server from Atlantic.Net in under 30 seconds.  See our [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). – “Development Tools” “Development Libraries” – readline-devel – openssl-devel ## Installing Python 3 from source on CentOS 7 Install build tools ``` yum groupinstall "Development Tools" "Development Libraries" ``` Install readline-devel so that your keyboard arrow keys work when entering the Python3 interactive terminal ``` yum -y install readline-devel ``` Install OpenSSL-devel for pip3 ``` yum -y install openssl-devel ``` Download Latest source code from [Python](https://www.python.org/downloads/source), at the time of writing ``` cd /opt wget https://www.python.org/ftp/python/3.9.0/Python-3.9.0.tgz ``` Unpack and enter Python-3.9.0 directory ``` tar -xvzf Python-3.9.0.tgz ``` ``` cd Python-3.9.0 ``` Build compile environment ``` ./configure --prefix=/opt/Python-3.9.0 make && make install ``` ## Creating a Virtual Environment in CentOS 7 You’ll see that Python3 has been installed into /opt/Python3.9.0. Note that by installing Python3, you have not altered anything with your original Python. This is done purposely if you install Python3 on top of your current Python2.x installation, you’ll break your operating system. This is why we are going to build a Virtual Environment for which we can run python3. This allows you to make changes to your Python3 installation without altering the OS’s version of python3. This is useful if different apps require different versions of Python. It also keeps you from accidentally overwriting your OS’s Python2 files. Use the Python3 command to create your environment. We’ll make our environment in /home/ and call it py3venv; it will be created automatically if it doesn’t already exist. ``` python3 -m venv /home/py3venv ``` To start, enter into your virtual Python3 environment execute the following. Your command shell will change to reflect that you are in your virtual environment. ``` source /home/py3venv/bin/activate (py3venv) [root@centos7 Python-3.9.0]# ``` Once inside the virtual environment, you may use PIP to install any additional packages you may require without affecting the system-wide instance of your Python 3 installation. To exit the virtual environment perform the following to drop back into your normal shell: ``` (py3venv) [root@centos7 Python-3.9.0] deactivate [root@centos7 Python-3.9.0]# ``` Thank you for following along and feel free to check back with us for further updates or learn more about our reliable [VPS hosting](https://www.atlantic.net/vps-hosting/) servers. --- # What is Symmetric-Key Encryption (How VPNs Work, Part 1) > URL: https://www.atlantic.net/vps-hosting/what-is-symmetric-key-encryption-vpns-work-part-1/ | Published: 2015-04-24 | Updated: 2024-09-25 | Author: Mason Moody In this article, we will explore how symmetric-key encryption works. . If you’re completely new to the concept of VPNs, check out [this introduction.](https://www.atlantic.net/vps-hosting/what-is-vpn/) ## About Encryption and VPNs This article is part of a series on VPNs. If you already know a little about the how VPNs work and want to know a little more, this series is for you. Each article addresses one aspect of how a VPN helps secure data by telling a story that serves as a metaphor for the logical mechanisms involved. These stories involve Adam and Burt trying to keep a secret and a third person, Cesar, trying to discover their secret nefariously. Since VPNs have no perfect physical world equivalent, some elements may stretch the bounds of credibility (for example, Cesar has access to a duplicator ray). Remember, it’s just a story… ## Basic Symmetric-Key Encryption Let’s suppose that Adam and Burt are writing a comic book. Since they live in nearby towns and can’t meet in person all that often, they send drafts of their book to each other via the Greater Metropolitan Area Post Office. They don’t want anyone getting a peek at their book before it’s finished, so they use a lockbox (encryption) and make a copy of the key (encryption key) for each of them. Now, when Adam finishes a script, he can send it to Burt in this lockbox and be sure that only Burt can unlock it when he gets it in the mail. ![Adam_symmetric_key](https://www.atlantic.net/wp-content/uploads/2018/01/key1-212x300.png) ### How a Lockbox Is Like Basic Symmetric-Key Encryption This mechanism is analogous to one of the earliest widely-used encryption standards for computer data, DES (Digital Encryption Standard). DES is a symmetric-key encryption algorithm, meaning that the key that is used to encrypt the data is also used to decrypt it. On a simplified level, a symmetrical-key encryption algorithm is a method of applying a series of predefined mathematical steps, and the key is a sort of pivotal variable (one might say, a “key” variable) that plugs into that method to produce unique output–the encrypted data. This process can also be reversed by applying the same method in reverse, again with the same key. ## The Threat Now, Cesar enters the picture. Cesar is obsessed with Adam and Burt’s comic book and can’t wait to learn more about it. For the sake of this story, Cesar has a duplicator ray. He is also a master of disguise, so he uses his talents to pose as a postal worker. His ultimate goal is to find a way to intercept the box Adam and Burt send back and forth to get a peek inside. Soon Cesar insinuates his way deeply enough into the Greater Metropolitan Area Post Office that he gains access to the central mail sorting room, and he spots the box from Adam to Burt. Cesar doesn’t want to arouse suspicion from either Adam or Burt from delayed delivery, so he uses his duplicator ray to make a copy of the box. Sadly for Cesar, this box is also locked (encrypted), the same as the original. But, among his talents, he is a journeyman locksmith, so he takes this duplicate box to his lair to attempt to bypass the lock. ### ![Burt_symmetric_key](https://www.atlantic.net/wp-content/uploads/2018/01/key2.png) Man-in-the-Middle Attack Network traffic is sent in discrete units called packets. So, whether you are sending something small (a short email) or something large (a video), the data will be segmented into easily managed packets before being transmitted. It’s the equivalent of sending a jigsaw puzzle to someone a piece at a time. Once it arrives at its destination, it will be reassembled. This process of examining network traffic in transit is called “packet inspection” (sometimes more informally called “packet sniffing” or “sniffing the wire”). Packet inspection allows network administrators to identify and block much hostile traffic on their network. It can also be quite useful to help troubleshoot connectivity issues within a network. It can also be used for less constructive purposes, such as eavesdropping. In these circumstances, this sort of use is often called a Man-in-the-Middle (MitM) attack. For someone like Cesar, who manages to insert himself in the transit path these messages take, this attack allows an interloper to copy all passing traffic (without delaying it and potentially alerting either end that something might be amiss) in order to analyze it later. Traffic that is not encrypted can be easily reassembled, allowing anyone with the proper tools to read the email or see the web page requested. Encrypted data would require knowing or discovering the key to decrypt each packet before reassembling it. ## Brute Force Crack Let us say, then, that Cesar spends time working on this lock and manages to pick the lock finally. After some practice, he learns to cut this time down significantly. Then, he intercepts the next package Burt sends back to Adam, copies it, and sends the original back on its way to Adam. Now, Cesar can pick the lock at his leisure, and since Adam received the package without delay, he and Burt have no idea anything could be amiss. So imagine their surprise and dismay when Cesar posts all the spoiler details of their new comic book on his blog (called, naturally, “The Cesarian Section”). ![Cesar_symmetric_key](https://www.atlantic.net/wp-content/uploads/2018/01/key3.png) Adam and Burt realize they will need to develop a better way to securely exchange messages. If they were to re-key the lock, it would likely not take Cesar long to learn how to pick this new lock. They decide to invest in a lock with a much more complicated key (a stronger symmetric-key encryption algorithm). But how long might it take Cesar to crack this lock? ### Modern Symmetrical Encryption Standards DES is no longer considered a strong means of encryption, implemented on its own. In 2008, SciEngines GmbH announced they were able to break DES in less than a day. A variation called Triple Digital Encryption Standard (abbreviated 3DES, usually pronounced “triple-dez”) has, in many instances, supplanted DES. As its name implies, it functions using the DES algorithm but run three times. The key is three times as long, and in its strongest implementation, it is made up of three different DES keys, one for each iteration of the DES algorithm. It can be helpful to imagine this algorithm functioning as if it were an intricate puzzle box. The first key might be the combination of twists and machinations (as with a Rubik’s Cube) required to reveal a sliding-tile style puzzle, which, when solved (the second key), would expose a keyhole for your key (the third key). An even stronger symmetric-key encryption algorithm is AES (Advanced Encryption Standard, though you may also sometimes see it referred to by its original name “Rijndael”, pronounced “rain-doll”). The strength of these sorts of algorithms is measured by the effective lengths of their keys (in bits). 3DES uses 168-bit keys (in its strongest implementation), though certain attacks have been shown to reduce that strength equivalent to an 80-bit key. AES can use 128-, 192-, and 256-bit keys. As the length of each of these keys goes up, so does its associated strength and computational requirements. ## The Evolution of Encryption Naturally, Adam and Burt have concerns that maintaining this lockbox solution, even if it is top-of-the-line, may not be as secure as they would like. A ne’er-do-well such as Cesar has several means to attempt to defeat this system. He can attempt to illicitly obtain a copy of the key from either Adam or Burt, or from the means they use to exchange the key in the first place (especially if this exchange is over an unsecured medium). Finally, he may, after practice or technological advance, discover a way to more efficiently “guess” the key. If they want to stay ahead of Cesar, they’ll need to find some new ways to make it much more difficult for him to find a way around or through. ### ![strong symmetric-key encryption](https://www.atlantic.net/wp-content/uploads/2018/01/key4.png) ### More in the How VPNs Work Series: [Part 2: Public Key Cryptography](https://www.atlantic.net/vps-hosting/what-is-public-key-cryptography-vpn-part-2/) [Part 3: Shared Key Exchange](https://www.atlantic.net/vps-hosting/what-is-shared-key-exchange-vpns-work-part-3/) Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting prices](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Application Server on Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-install-application-server/ | Published: 2015-04-27 | Updated: 2024-06-05 | Author: Jose Velazquez ##### Verified and Tested 03/31/2015 ### Introduction This How-To will walk you through the Install of Application Server in Windows Server 2012. Application Server is a feature that allows a combination of business applications for deployments and mode of operation within a network. It is mainly used in businesses that use ASP.NET, .NET Frameworks, and other web applications like IIS. ## Installing Application Server on Windows Server 2012 Open the **Server Manager** from the taskbar. From **Server Manager **Dashboard, select **Add roles and features**. This will launch the Roles and Features Wizard, allowing modifications to be performed on the Windows Server 2012 instance. ![Select Add roles and Features](https://www.atlantic.net/wp-content/uploads/2018/01/server1.jpg) Server Manager   Note: If it is the first time you have entered this wizard, you will get a **Before you Begin** page. Review it, and you can check the Skip this page by default box, and then click **Next.**   Select **Role-based or feature-based installation** on the Installation Type screen and click **Next**. ![Select Role-based or feature-based installation](https://www.atlantic.net/wp-content/uploads/2018/01/server2.jpg) Installation type   You will now have the **Select destination server** page. Your server will be selected by default, so you can click **Next**to continue. ![Select your server](https://www.atlantic.net/wp-content/uploads/2018/01/server3.jpg) Server Selection   ![Under server roles select Application Server](https://www.atlantic.net/wp-content/uploads/2018/01/server4.jpg) Server Roles The Select Server Roles page appears. Select the **Application Server** check box, and then click **Next**. ![Under Role Services of Application server select any optional components you may need.](https://www.atlantic.net/wp-content/uploads/2018/01/server5.jpg) Application server: Role Services Click **Next** in the Features Screen/ click **Next** in the Application Server Screen/ Select any additional Role in the Role Services(I selected all of them just in case I need them later down the road) and click **Next**. ![We'll se issuing a self signed certificate in this example.](https://www.atlantic.net/wp-content/uploads/2018/01/server6.jpg) Server Authentication In the **Server Authentication** screen, you have three options to choose from. In this case, I will be using the **create a self-signed certificate**. If you have an existing SSL, select the first option, and if you plan to request one, later on, choose the third option. ![Select install to initiate the install process.](https://www.atlantic.net/wp-content/uploads/2018/01/server7.jpg) Confirm Installation Confirm your InstaInstallationclick **Install**. ![Verify that App Sever has appeared in the server manager dashboard](https://www.atlantic.net/wp-content/uploads/2018/01/server8.jpg) Server Manager You can now see that the **App Server** role is currently installed in your **Server Manager Screen**. Congratulations! You have just Installed the Application Server in Windows Server 2012. Thank you for reading! Check out more of our exciting Windows-related How-to’s, and learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and Virtual private servers. --- # How to Configure IIS in Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-configure-iis-windows-server-2012/ | Published: 2015-04-28 | Updated: 2024-06-05 | Author: Jose Velazquez ##### Verified and Tested 03/12/2015 ### Introduction In this How-To, we will Configure IIS in Windows Server 2012. Internet Information Services (IIS) Web server designed for Windows to host websites, mail, and web applications over the World Wide Web. See the following article, “[How To Install IIS in Windows Server 2012](https://www.atlantic.net/vps-hosting/how-to-install-iis-windows-server-2012-r2/),” for more information. Once the IIS role is installed, the server will need to be configured for your domain. ### Prerequisites – A Server with Windows Server 2012 Installed. If you do not have a server already, you can spin up an Atlantic.Net [Windows VPS](https://www.atlantic.net/vps-hosting/) in under 30 seconds. – Internet Information Services(IIS) installed on your server. ## Configure IIS in Windows 2012 Open the **Server Manager** from the taskbar. On the left side, under **Dashboard, Local Server, and All Servers,** Click **IIS**/ Right **Click** your server/ select **Internet Information Services (IIS) Manager.** ![Within server manager, under IIS, select Internet Information Services(IIS) Manager](https://www.atlantic.net/wp-content/uploads/2018/01/iis1-1.jpg) Under the**“Start Page” / Click** on your server’s drop-down menu/ Click **Yes** to continue. ![Get Started- click get started](https://www.atlantic.net/wp-content/uploads/2018/01/iis2-1.jpg) Click on the drop-down menu of the **Sites** / click on the **Default Web Site** / The section on the right under **Actions**on the**Browse Website,** click Browse *:80(HTTP) ![On the right window pane select your site, then from the pane on the left, select Browse *:80(http)](https://www.atlantic.net/wp-content/uploads/2018/01/iis3-1.jpg) You will know that the following screen configures IIS: ![Sample Default Website](https://www.atlantic.net/wp-content/uploads/2018/01/iis4.jpg) Congratulations! You have just Configured IIS in Windows Server 2012. Thank you for following along in this How-To, and feel free to check back with us for any new updates or learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services. --- # How to Fix Automatic Disconnects from WHM & cPanel > URL: https://www.atlantic.net/vps-hosting/how-to-fix-automatic-disconnects-whm-cpanel/ | Published: 2015-04-30 | Updated: 2024-06-05 | Author: Jason Mazzota ##### Verified and Tested 03/24/2015 ### Introduction You have noticed from using your cPanel & WHM server that you are constantly getting disconnected from the Web GUI and not being allowed back in. The following change below will remedy the issue. Please note that cPanel & WHM does have an automatic timeout logout period, but the fix we are applying is when you are actively using cPanel & WHM and are disconnected. ## Prerequisites A server with CentOS 6 and cPanel & WHM. If you do not have a server already, you can visit our [VPS hosting](https://www.atlantic.net/vps-hosting/) page and spin a new server up in under 30 seconds. ## Fix Automatic Disconnects from WHM & cPanel The fix is simply changing an option in the settings of WHM. To do this, log into WHM and find the “Tweak Settings” option on the left sidebar. If you do not see it, you may type “tweak” in the search bar, and it should filter the left bar so you can see it. Once in Tweak Settings, you will go to the “Security” tab. There, you can find the Cookie IP Validation segment. It should look similar to the below. ![Under the Security Setting of Tweak setting, select Cookie IP Validation to Disabled.](https://www.atlantic.net/wp-content/uploads/2018/01/anet-cpaneldisconnects-00.png)   This defaults to strict. You will want to set it to disabled and then scroll down and hit the “Save” button. This will stop the automatic disconnects you are receiving from WHM.   Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Generate and Use a SSH key using PuTTY > URL: https://www.atlantic.net/vps-hosting/how-to-generate-use-ssh-key-using-putty/ | Published: 2015-05-04 | Updated: 2026-03-02 | Author: Atlantic.Net NOC ##### Verified and Tested 2/8/15 ### Introduction This guide will show you how to generate and use SSH keys (public and private) using [PuTTYgen](https://www.puttygen.com/) and PuTTY for Linux servers. ## How to Generate and Use an SSH Key First things first. We must generate our public and private keys using PuTTYgen. PuTTYgen and PuTTY can be downloaded here: [PuTTY](http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html) Once they have been downloaded to a proper directory, open PuTTYgen first. Click on “Generate” to begin the key generation process. It will ask you to move your mouse around over the program window to help generate “random” data. ![Select your respective parameters and click Generate.](https://www.atlantic.net/wp-content/uploads/2018/01/ssh1.jpg) PuTTY Key Generator When the key is generated, the window will look like the picture below. ![Sample public Key](https://www.atlantic.net/wp-content/uploads/2018/01/ssh2.jpg) Sample public Key Most of the information presented here is superfluous except in special instances. All you will want to do is update the “Key comment” box with a better friendly name for the key. Once you have done that, select all of the text in the “Key” box and paste it into Notepad or Notepad++ (preferred). Save that text file somewhere safe. You will also need to click “Save private key” on this window. Name it something useful and place it somewhere secure as well. To use this key with a PuTTY connection, simply select the “Auth” menu on the left side of the program. This can be found under Connection -> SSH -> Auth. In this menu, there is a box titled “Private key file for authentication.” Click browse and find the .ppk file that you saved in the previous step. ![In Your PuTTY Configuration select Connection, then SSH, and Auth. Under Authentication parameters browse to the location fo your Private Key file.](https://www.atlantic.net/wp-content/uploads/2018/01/ssh3.jpg) SSH Key Authentication At this point, if you name and save your connection in the “Session” category, you won’t ever have to follow this process again for that server/IP. Otherwise, you would need to choose your key each time you connect. ## Creating a New Server with this SSH Key for Linux Servers Creating a cloud server that uses an SSH key is simple. You will first need to setup your key in the cloud portal. Click on “SSH Keys” on the left side under “Manage Servers.” From there, click “Add SSH Key.” When the window pops up, simply name your key, and paste the public key text (that you saved to a notepad file in a previous step) into the large box. ![Cloud Portal:Add SSH Key](https://www.atlantic.net/wp-content/uploads/2018/01/ssh4.jpg) Cloud Portal:Add SSH Key Click “Add Key.” If there were no issues with the key (inappropriate line breaks, errors, etc) it will save to the portal and be accessible for new servers. To create a server that utilizes this key for root login, simply follow the [“create server” steps found here.](https://www.atlantic.net/vps-hosting/how-to-create-new-atlantic-net-cloud-server/) -When choosing your server size and OS, you will see an option at the bottom that says “Pick SSH Key.” You will see the key we just created in that list. When the server comes online, simply use the previous PuTTY steps to connect to the server using that public key. The username will always be root when using our public key system. ## Adding the Public SSH Key to an Existing Server The steps for enabling public/private key login on a standard server that was not provisioned with a key originally is quite simple as well Simply use PuTTY to log into the server as usual using the root account and password. You may already want to save a PuTTY profile with your key, even though the server will reject it until it is configured. For all Linux-based operating systems, you only need to create root’s .ssh directory, and paste the public key into a file named “**authorized_keys**” From here, you can either use a text editing program to paste the key in (vi/vim/nano, etc), or you can use echo. The echo command would look something like this: ![Create a .ssh directory in your users home directory and place your public key into a new file called "authorized keys".](https://www.atlantic.net/wp-content/uploads/2018/01/ssh5.jpg) Authorized Keys At this point, you can log out of the server and log in using the previously stated method to open a PuTTY session with a private key attached. Upon entering the username “root”, the server should allow you to login without entering a password. If successful, you should see a message that states “Authenticating with public key.” The screenshot below has an example: ![Sample Log in](https://www.atlantic.net/wp-content/uploads/2018/01/ssh6.jpg) Sample Log in Done! At this point, if you plan to access the server often, you will definitely want to save a profile. You can also setup a username to auto-login with under Data -> “Auto-login username.” Simply type root into that box and save it along with the private key and IP address to a PuTTY profile, and you can have instant passwordless login access to your server! --- For more information about PuTTY, visit [www.putty.org](https://www.putty.org/). For more information about PuTTYgen, visit [www.puttygen.com](https://www.puttygen.com/). --- # Atlantic.Net Opens State-of-the-Art Cloud Center in NYC > URL: https://www.atlantic.net/press-releases/atlantic-net-continues-to-expand-with-the-opening-of-its-state-of-the-art-data-center-location-in-new-york-city/ | Published: 2015-05-04 | Updated: 2024-03-04 | Author: Editorial Team **Cloud Hosting Provider Adds Fifth Location To Provide Faster Service To Developers In The Northeast USA** ORLANDO, FL, May 4, 2015 – Atlantic.Net, a global [SSD cloud hosting](https://www.atlantic.net/vps-hosting/)service, today announced its expansion in the Northeast with the opening of its first New York City-based cloud hosting center. This new center, which is the fifth addition to the company’s rapidly growing infrastructure, is owned by Telx and was established to handle the increasing demands of New York City’s ever-evolving startup and developer-focused communities. The New York City cloud center will offer developer-friendly features that cater around simplicity and rapid deployment, including one-click apps such as WordPress, LAMP, LEMP, Docker, Node.js, and Django. These new features, in addition to superior network speeds, will be implemented into all of Atlantic.Net’s facilities, and will add great value to the developer community, making it easier for the startup ecosystem to grow in the Northeast region. With its proximity to Manhattan, this seven-floor, 179,000 square foot facility with diverse conduit entry points is an ideal location that provides access to hundreds of leading domestic and international carriers and complies with all International Telecommunication standards. Atlantic.Net has already established a significant presence in North America, with data centers in Dallas, TX, San Francisco, CA, Orlando, FL, and Toronto, Canada. “With all the investment that New York has made on its digital infrastructure and the technology industry overall, New York City was the next logical step for our company and where we need to be,” said Marty Puranik, President, and CEO of Atlantic.Net.  Marty further stated,“We have a lot of developers in major cities like Boston, Philadelphia and New York who asked for faster connections and quicker uploads, so the demand was naturally there to make the transition as smooth as possible.” The new center is co-located in a state-of-the-art Telx building, one of the most network rich, interconnected colocation centers in the New York City metro area. The facility has a power capacity of 4000 (kW), N+1 – 2N UPS redundancy, N+1 cooling, and 150 (W/sq.ft.) power density. Other key features of the center include biometric card key access, 24/365 manned security, and digital video monitoring to ensure a secure experience for Atlantic.Net customers. Atlantic.Net will continue to expand and grow alongside the developer community, to adapt to changes in the developer ecosystem and continue to provide simple solutions for hosting applications. The company recently announced a new West Coast center in Silicon Valley, with plans to add more data centers internationally, later this year. ### About Atlantic.Net In 1995, two University of Florida students launched one of North Florida’s first commercial Internet services, Atlantic.Net.   Over its first seven years, Atlantic.Net acquired 13 Internet service companies and augmented its e-business services to include long distance services, dial-up, broadband, web solutions, fractional T-1 through DS-3 connectivity, DSL and ISDN access, Web hosting, Web design, and e-commerce.   Atlantic.Net’s staff has grown to more than 100 employees and been recognized both Nationally and in Florida as one of the fastest-growing private companies.  Our award winning customer service and investment in cutting edge technology is still a guiding force behind the company.  Today, Atlantic.Net offers industry leading [cloud hosting](https://www.atlantic.net/vps-hosting/), [cPanel Cloud Hosting](https://www.atlantic.net/hipaa-compliant-hosting/cpanel-ideal-cp-cloud-hosting/), and many other services. To learn more about Atlantic.Net’s complete line of services, call 1.866.618.3282 or visit the Web site at [Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # How to Create a DNS Zone in cPanel & WHM > URL: https://www.atlantic.net/vps-hosting/how-to-create-dns-zone-cpanel-whm/ | Published: 2015-05-06 | Updated: 2026-03-02 | Author: Jason Mazzota ##### Verified and Tested 03/25/2015 ### Introduction This tutorial will show you how to create a DNS zone in cPanel & WHM. This is mainly useful for when you have your own nameservers and will be using the server to host the DNS for an off-server website. If you are using our Cloud DNS or not using DNS on your server at all, you do not need to use the DNS zone editor. ## Prerequisites A server with cPanel and WHM installed. If you do not have a server already, spin up a [cPanel WHM server](https://www.atlantic.net/vps-hosting/) in under 30 seconds. ## Create a DNS Zone in cPanel & WHM First, you will need to log into WHM for your server. Once you have logged in, go to the search bar and type “DNS.” Proceed to the “Add DNS Zone” section. Here, you will see at the top “Domain Selection.” You’d want to put in the IP of the server or the IP you want the domain to be on and then the domain itself. Once done, you go to “Domain Owner Information” and select the owner for the domain. If this is to be a stand-alone account, you can put it under system ownership. Once done, click “Add Zone.” ![Select Add a DNS zone under DNS functions and place your servers IP and domain name followed by "Add zone"](https://www.atlantic.net/wp-content/uploads/2018/01/anet-cpanel-addzone-00.png) Add a DNS Zone   And that’s it. You can edit the DNS Zone and add more records to it by going to “Edit DNS Zone” and selecting the new zone you made. --- # How to Install Active Directory Rights Management Services in Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-install-active-directory-rights-management-services/ | Published: 2015-05-07 | Updated: 2024-06-05 | Author: Jose Velazquez ### Introduction This how-to will walk you through the Install Active Directory Rights Management Services in Microsoft Windows Server 2012. Active Directory Rights Management Services or ADRMS is a feature that allows Active Directory to enable Active Directory to trade information-specific software that is compatible with ADRMS. It adds more security to documents, and permissions can be added to indicate who can control, execute, and update documents. ### Prerequisites – A Server with Microsoft Windows Server 2012. – Active Directory Installed. If you need to install an active directory, check out “[Installing Active Directory in Windows Server 2012](https://www.atlantic.net/vps-hosting/).” ## Install Active Directory Rights Management Services in Windows Server 2012 Open the **Server Manager** from the taskbar. From **the Server Manager**Dashboard, select **Add Roles and Features**. This will launch the Roles and Features Wizard, allowing modifications to be performed on the Windows Server 2012 instance. ![Select Add roles and features from Server Manager](https://www.atlantic.net/wp-content/uploads/2018/01/win1.jpg)   Note: If this is your first time entering this Wizard, you will get a **Before you Begin** page. Review it, and you can check the Skip this page by default box,  then click **Next.**   Select **Role-based or features-based** Installation from the Installation Type screen and click **Next**. ![Select Role-based or feature-based installation](https://www.atlantic.net/wp-content/uploads/2018/01/win2.jpg)   You will now have **the Select Destination Server** page. Your server will be selected by default, so you can simply click **Next**to continue. ![Select your server.](https://www.atlantic.net/wp-content/uploads/2018/01/win3.jpg) Server selection   ![Under server roles select Active Directory Rights Management Services](https://www.atlantic.net/wp-content/uploads/2018/01/win4.jpg) The Select Server Roles page appears. Select the **Active Directory Rights Management Services** check box, add features, and click **Next.** ![Under AD RMS Role Services select Active Directory Rights Management Server and Identity Federation Support.](https://www.atlantic.net/wp-content/uploads/2018/01/win5.jpg) Click **Next** in the **Features** Screen/ click Next in the **Active Directory Rights Management Services** Screen/ Select any additional Role in the Role Services (I selected all of them just in case I need them later down the road) and click Next. ![Confirm and install your software.](https://www.atlantic.net/wp-content/uploads/2018/01/win6.jpg) Confirm your Installation and click **Install**. ![AD RMS should now be visible in your server manager dashboard.](https://www.atlantic.net/wp-content/uploads/2018/01/win7.jpg) You can now see that the **Active Directory Rights Management Services** role is currently installed in your **Server Manager** Screen. Congratulations! You have just Installed the Active Directory Rights Management Services in Windows Server 2012. Thank you for following along in this How-To, and feel free to check back with us for any new updates. ## Atlantic.Net Atlantic.Net offers [VPS hosting](https://www.atlantic.net/vps-hosting/) and managed hosting services, including a layer of business-essential managed services to your hosting packages. Contact us today for more information. --- # How to : Linux or FreeBSD Basic Shell Commands – man, echo, cat, ls, cp, rm, mkdir, cd, clear, reset and exit > URL: https://www.atlantic.net/vps-hosting/how-to-linux-freebsd-basic-shell-commands/ | Published: 2015-05-08 | Updated: 2025-03-06 | Author: Alexander Wise ### Introduction This quick tutorial is for developers or system administrators new to Linux or FreeBSD. This is a quick run through of basic commands that you will need to know to get going setting up and administrating a Linux or FreeBSD server. We will review 9 of the most frequently used commands in the shell: ls, cp, mkdir, rm, cd, cat, echo, exit, and man. This tutorial is for beginners and someone who has never used a shell before. ### Prerequisites: You will need a server with Linux or [FreeBSD installed](https://www.atlantic.net/vps-hosting/). If you don’t have one, you can get an affordable [virtual private server](https://www.atlantic.net/vps-hosting/pricing/) from Atlantic.Net. In addition, you will need to be logged into the server and at the shell prompt. Typically, this involves using a ssh client to connect and login to the server. We will start assuming you are logged into the server. We will be using Ubuntu Linux for this demonstration, but any Linux variant will do. ### Getting Started: To begin, you should be at a prompt that looks like this: ![An example of what a shell prompt looks like.](https://www.atlantic.net/wp-content/uploads/2015/05/bsd1.png) An example of what a shell prompt looks like. Let’s understand what is going on here. In the example above, the username I chose for the account is “demo” and the name of my server is “demoserver”. So its showing demo@demoserver at the command prompt. Depending on your version of Linux, it may show something different. We are now at the command prompt. ## How to use the built-in manual for Linux or FreeBSD The first command we learn is the “man” command, short for manual. This is the first point of reference when trying to learn a new command in Linux. The manual pages are in-depth and show all the different features and “flags” (or options) available with each command. Let’s look at the man page (one of the pages in the built-in manual) for the next command we are going to learn called “echo” by typing “man echo” into the command prompt: `man echo` You will see a manual page that describes the echo command in great detail display on your screen. You can press spacebar to continue reading the whole article, or press q to quit and return to the shell (the command options are written at the bottom of the page). Tip: You can use the “-k” flag with the man command to search for keywords if you don’t know the actual command. For example, typing “man -k echo” shows several other commands that have echo in them. It is useful to try and find the command with the -k flag, then actually type in “man” to learn how to use it. ## Using echo to display text and create a file. Next, we will learn the echo command. Echo simply repeats whatever you send to it. For example, type the following into the shell prompt: `echo "Hello"` and you should see Hello repeated back in your terminal, as seen below: ![An example of what the command "echo" does.](https://www.atlantic.net/wp-content/uploads/2015/05/bsd2.png) An example of what the command “echo” does. ## Using echo, creating a file using echo, and using cat to view it Great, you’ve learned how to use the echo command! In Linux, you can use the > and >> operators to forward output somewhere else. In our case, we will use them to create a file. We use the > command to create a file, and the >> command to append to an existing file. We will now use the > operator to create a file called test: `echo "Hello" > test``` Now, we will use the >> operator to append some text to the file named test: `echo "World" >> test``` We will now use the cat command. Cat allows us to view what is in a file. `cat test` Your shell should have returned your Hello World text as seen below: ![An example of using the commands "echo" and "cat"](https://www.atlantic.net/wp-content/uploads/2015/05/bsd3.png) An example of using the commands “echo” and “cat” ## How to see the contents of your directory using ls Great! We’ve now learned how to use echo to create a file using > and >>, and we’ve learned how to view it using cat. In Linux, everyone gets their own directory that houses their private files. We created a file in our directory called test. Now, we will learn how to see what files are in our directory using the ls command. Type: `ls` and you will see your file named test. We can get a more descriptive view of the directory using the “-l” flag as follows: `ls -l` Now, you will see the test file with many other fields. Since this is a basic tutorial, we won’t cover those here, but you can always use “man ls” to see the options and what they mean. Here’s what you should have seen using the ls command: ![An example of using the command "ls"](https://www.atlantic.net/wp-content/uploads/2015/05/bsd4.png) An example of using the command “ls” ## Using cp to copy a file We’re making progress! You’ve now learned how to create a file, and list what is in your directory. Now, let us learn how to use the cp command to copy files. Type: `cp test newtest` This will make a duplicate file called “newtest” that has the same contents as “test”. You can verify this by using the cat command to see both files. In addition, if you use the ls command, you will now see two files one called “test” and one called “newtest”. If you follow this example, your output should look similar to what we have below: ![An example of using the command "cp"](https://www.atlantic.net/wp-content/uploads/2015/05/bsd5.png) An example of using the command “cp” ## Learning how to remove a file using rm Now, let’s learn how to delete a file. We will delete our newtest file by using the rm command as follows: `rm newtest` The newtest file is now gone, we can verify using the ls command. Give it a try, and your shell should look something like this: ![An example of using the command "rm"](https://www.atlantic.net/wp-content/uploads/2015/05/bsd6.png) An example of using the command “rm” ## How to create a directory (or subdirectory) and use cd (change directory) In order to organize files, we sometimes create directories, or subdirectory (directories within directories). We’ll make a directory by using the mkdir command. Let’s make a directory by typing: `mkdir shopping` You have now created a directory. You can use the “ls -l” command to see it. Note the “d” in the file permissions at the beginning of the listing, this denotes “directory”. Note that our “test” file doesn’t have that because it is not a directory. Now, let’s create a file called groceries in that directory that contains the word apple by typing the following: `echo "apple" > shopping/groceries` We have now created a file in the shopping directory. In order to see the file, we need to change directories so we are in the shopping directory. Let’s do that with the “cd” command by typing: `cd shopping` You can now use the ls command to see the groceries file, and using cat to view it. To move back up to the previous directory, you can use the command “cd ..”. Use ls to see we are back to the original directory. Give it a try and you should see the following: ![An example of using the command "mkdir"](https://www.atlantic.net/wp-content/uploads/2015/05/bsd7.png) An example of using the command “mkdir” That’s it! You have learned some basic functions and navigation for the Linux (or FreeBSD) shell. These are the most popular commands you will use on a day-to-day basis as you use the shell to administer your server. We hope you found this tutorial useful, and enjoy learning how to use a Linux or FreeBSD server. BONUS: clear, reset and exit The clear command allows you to clear the screen quickly and reset it. Sometimes you will want a clean screen and you can use the clear command: `clear` It will simply clear to screen. If, by chance your screen starts displaying strange characters, you can use the reset command to reset the display with the proper font: `reset` Finally, when you are finished and want to exit the shell, simply type exit to tell the Linux server to shutdown your session: `exit` Thank you for following along in this How-To and feel free to check back with us for any new updates or to learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services. --- # How to Install MySQL in Windows Server 2012 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-mysql-windows-server-2012/ | Published: 2015-05-11 | Updated: 2026-02-28 | Author: Jose Velazquez ##### Verified and Tested 03/12/2015 ### Introduction In this how-to we will walk you through Installing MySQL in Windows Server 2012 using the Microsoft Web Platform Installer (Web PI). MySQL is database management system that is widely used all over the world for its High-Availability and efficiency, in a number of cloud based companies including Atlantic.Net. Web PI is tool offered by Microsoft at no cost, facilitating the latest web applications in a single Web Gallery. ### Prerequisites – A Server with Windows Server 2012. – Microsoft Web Platform Installer (Web PI) Download the latest version in here: [http://www.microsoft.com/](http://www.microsoft.com/web/downloads/platform.aspx). ## Installing MySQL in Windows Server 2012 Launch the Web PI application by running the wpilauncher.exe file that you downloaded in the preceding section. In the Web Platform Installer window, search for MySQL in the search box. Select the most current version of MySQL Windows or MySQL Windows 5.1 , click Add, and then click Install to start the installation. ![Use Web Platform installer 5.0 to search for and add MySQL](https://www.atlantic.net/wp-content/uploads/2018/01/mysql1.jpg) Web Platform installer 5.0 Provide a password for the **root **account of the MySQL server. ![Set MySQL root password](https://www.atlantic.net/wp-content/uploads/2018/01/mysql2.jpg) Set MySQL root password Review the licensing agreement and click **I Accept**. ![Accept License Agreement](https://www.atlantic.net/wp-content/uploads/2018/01/mysql3.jpg) License Agreement After the installation is completed, click **Finish**. ![Select finish to close the Web Platform Installer](https://www.atlantic.net/wp-content/uploads/2015/05/anet-windows-2012-web-platform-installer-finish-e1635013704446.jpg) Installation Verification You can launch MySQL by running the mysqld.exe command from the installation directory. By default this is set to **C:\Program Files\MySQL\MySQL Server 5.5\bin**. Congratulations! You have just Installed MySQL in Windows Server 2012 . Thank you for following along in this How-To and check back with us for any new updates. Alternatively, check out other useful MySQL articles like [How to Multi-Master MySQL with Percona and Keepalived.](https://www.atlantic.net/vps-hosting/how-to-multi-master-mysql-percona-keepalived/) If you’re interested in installing MySQL on a HIPAA-compliant server with Windows Server 2012, contact Atlantic.Net for more information about [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/). --- # How to Install Apache, MySQL, PHP (LAMP) On Fedora 21 > URL: https://www.atlantic.net/vps-hosting/how-to-install-lamp-fedora-21/ | Published: 2015-05-12 | Updated: 2026-03-03 | Author: Jose Velazquez ### Introduction This how-to will help you with your LAMP installation in Fedora 21 so that you can successfully run a high available solid platform for your web environment. LAMP is simply a software bundle that consists of 4 components that work together to form a powerful web server.  However, in this setup the acronym’s are as follows: L (Linux) is the core of the platform which will sustain the other components. A (Apache) will be used for the web service. M(MySQL) will be used for database management,  and P(PHP) will be used as the programming language. Making the platform a LAMP. ### Prerequisites You need a Fedora21 server that is configured with a static IP address. If you do not have a server already, you can spin up a [SSD virtual private server](https://www.atlantic.net/vps-hosting/) in under 30 seconds. ## Install LAMP To get started, login to your Fedora21 server via SSH or the VNC Console in cloud.atlantic.net. Atlantic.Net Cloud servers are setup as minimal installations in order to avoid having unnecessary packages from being installed and never used.  Because of this, let’s make sure that your server is fully up-to-date. ``` yum update ``` With the server up-to-date, we can continue the process and secure your server. ## Install Apache We must first begin by installing Apache with the following command: ``` yum install httpd ``` Start the Apache service with the following command: ``` systemctl start httpd.service ``` You will also want the Apache service to start upon start-up/reboot with the following command: ``` systemctl enable httpd.service ``` Add the following commands in Apache to override the Firewall-cmd as follows: ``` firewall-cmd --set-default-zone=public ``` ``` firewall-cmd --permanent --zone=public --add-service=http ``` ``` firewall-cmd --permanent --zone=public --add-service=https ``` ``` firewall-cmd --reload ``` You can now verify that Apache is installed correctly by typing http:// and your IP address on your browser. http://YOUR.IP.ADD.RESS ![This is the default webpage when installing Apache on a Fedora21 LAMP Stack Server](https://www.atlantic.net/wp-content/uploads/2018/01/lamp1.jpg) This is the default webpage when installing Apache on a Fedora21 LAMP Stack Server To edit the main Apache configuration file for one or many websites according to your preference, enter one of the following: ``` vi /etc/httpd/conf/httpd.conf ``` or ``` nano /etc/httpd/conf/httpd.conf ``` Un-comment the line containing the text **#ServerName www.example.com:80**and edit accordingly with your domain or IP Address of the server.**** Save the file Restart the Apache HTTP service so the changes take affect. ``` systemctl restart httpd.service ``` ## Install MySQL We then want to continue installing MySQL with the following command: ``` yum install mysql mysql-server ``` Start the MySQL service with the following command: ``` systemctl start mysqld.service ``` You will also want the MySQL service to start upon start-up/reboot with the following command: ``` systemctl enable mysqld.service ``` To ensure the security of the default settings of MySQL, continue with the next command: ``` mysql_secure_installation ``` Note: When prompt with “Enter current password for root” hit enter for none then Y(Yes) to set MYSQL password. You will be prompt with a series of questions. Simply type Y for yes on all of them, see the screen shot below: ![This is the default webpage when installing MySQL on a Fedora21 LAMP Stack Server](https://www.atlantic.net/wp-content/uploads/2018/01/lamp2-1.jpg) This is the default webpage when installing MySQL on a Fedora21 LAMP Stack Server ## Install PHP Finally we will conclude the installing PHP with the following command: ``` yum install php ``` Restart the Apache HTTP service so the changes take affect. ``` systemctl restart httpd.service ``` In order to test and verify this installation create a test PHP file in the directory below with the following command: ``` sudo nano /var/www/html/info.php ``` Insert the following PHP code in the empty space then save and exit: ``` ``` Restart the Apache HTTP service one last time so all the changes take affect. ``` sudo systemctl enable httpd.service ``` You can now verify that PHP is installed correctly by typing the following on your browser. http://YOUR.IP.ADD.RESS/info.php ![This is the default webpage when installing PHP on a Fedora21 LAMP Stack Server](https://www.atlantic.net/wp-content/uploads/2018/01/lamp3-2.jpg) This is the default webpage when installing PHP on a Fedora21 LAMP Stack Server   ## What Next? Congratulations! You now have a server with a LAMP platform for your web environment. Thank you for following along and feel free to check back with us for further updates. --- # How to Install Active Directory Federation Services on Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-install-active-directory-federation-services-windows-server-2012/ | Published: 2015-05-12 | Updated: 2024-06-05 | Author: Jose Velazquez ##### Verified and Tested 03/31/2015 ## Introduction In this how-to will walk you through the Install of  Active Directory Federation Services Windows Server 2012. Active Directory Federation Services or ADFS is a feature in Windows Server 2012 that grants access to multiple devices using a single login, with specified credentials. ## Prerequisites – A Server with Windows Server 2012.  If you don’t have a server already, please consider a [reliable VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. ## Install Active Directory Federation Services Open the **Server Manager** from the task bar. From **Server Manager **Dashboard, select **Add roles and features**. This will launch the Roles and Features Wizard allowing for modifications to be performed on the Windows Server 2012 instance. ![Select Add roles and features](https://www.atlantic.net/wp-content/uploads/2018/01/dns1.jpg) Select Add roles and features   Note: If its the first time that you have entered this wizard, you will get a **Before you Begin** page. Review it and you can check the Skip this page by default box,  then click **Next**   Select **Role-based or features-based** installation from the Installation Type screen and click **Next**. ![Select Role-based or feature-based installation](https://www.atlantic.net/wp-content/uploads/2018/01/dns2.jpg) Select Role-based or feature-based installation   You will now have **Select destination server** page. Your server will be selected by default, so you can simply click **Next**to continue. ![Select your server](https://www.atlantic.net/wp-content/uploads/2018/01/dns3.jpg) Select your server   ![Select Active Directory Federation Services](https://www.atlantic.net/wp-content/uploads/2018/01/directory1.jpg) Select Role The Select Server Roles page appears. Select the **Active Directory Federation Services** check box, and then click **Next**. ![Confirm the services to be installed.](https://www.atlantic.net/wp-content/uploads/2018/01/directory2.jpg) Confirm Installation Click **Next** in the **Features** Screen/ click **Next** in the **Active Directory Federation Services** Screen/ Confirm your Installation and click **Install**. ![AD FS should now be visible via the Server Manager](https://www.atlantic.net/wp-content/uploads/2018/01/directory3.jpg) Verify InstallationWindow You can now see that the **Active Directory Federations Services** role is currently installed in your **Server Manager** Screen. Congratulations! You have just Installed the Active Directory Federation Services in Windows Server 2012. Thank you for following along in this How-To and feel free to check back with us for any new updates. --- # Update on VENOM (CVE-2015-3456) QEMU Vulnerability > URL: https://www.atlantic.net/announcements/update-on-venom-cve-2015-3456-qemu-vulnerability/ | Published: 2015-05-13 | Updated: 2025-03-06 | Author: Alexander Wise Earlier today, a security vulnerability, CVE-2015-3456 (VENOM), was publicly announced. This vulnerability affects the widely used KVM/QEMU virtualization hypervisor platform that we use to power our [SSD cloud hosting](https://www.atlantic.net/vps-hosting/) servers. We are rolling out the necessary security patches to address this vulnerability to all applicable infrastructure. In order to ensure that the patches are effective at resolving the vulnerability, you may see a very brief interruption in service (a few seconds) while your Cloud Server is switched to run on the updated version of our infrastructure. A very small percentage of Cloud Servers may require a reboot to complete this process. If this is necessary for one of your [cloud hosting](https://www.atlantic.net/vps-hosting/) servers, you will be contacted by our support team so this can be done with as little inconvenience as possible. We will keep you posted on progress.   UPDATE 05/14/15: Atlantic.Net has successfully mitigated the VENOM vulnerability in our USA-West-1 (San Francisco), USA-Central-1 (Dallas), USA-East-2 (New York) and Canada-East-1 (Toronto) Cloud locations.  USA-East-1 (Orlando) is almost complete, however, there is a small percentage of Cloud Servers that will need to be manually rebooted.  If you are one of the few affected, an email will be sent to you shortly with further instructions. UPDATE 05/14/15: Atlantic.Net sent notification to the small percentage of [cloud server](https://www.atlantic.net/vps-hosting/) hosting that needed to be manually rebooted in USA-East-1 (Orlando).  Those that were notified have until 11:59 pm ET on May 15, 2015 to power cycle their Cloud Servers per the instructions provided in the email. If they have not done so by the previously mentioned time, we will shutdown their Cloud Servers and power them back on. UPDATE 05/16/15: Atlantic.Net has now successfully mitigated the VENOM vulnerability in USA-East-1 (Orlando), and as previously noted, all other Cloud locations. [You can read more about VENOM](https://www.atlantic.net/vps-hosting/what-is-venom-security-vulnerability/). If you have any further questions, please contact our [Support team](https://www.atlantic.net/support/). --- # What Is Public Key Cryptography? (How VPNs Work, Part 2) > URL: https://www.atlantic.net/vps-hosting/what-is-public-key-cryptography-vpn-part-2/ | Published: 2015-05-13 | Updated: 2026-07-07 | Author: Mason Moody In this article, we will explore how public key cryptography (asymmetric encryption) works. If you’re completely new to the concept of VPNs, check out [this introduction](https://www.atlantic.net/vps-hosting/what-is-vpn/). ## Getting Started with VPNs This article is part of a series on VPNs. If you already know a little about the how VPNs work and want to know a little more, this series is for you. Each article addresses one aspect of how a VPN helps secure data by telling a story that serves as a metaphor for the logical mechanisms involved. Previously in this series, Adam and Burt have already discovered the weakness in using a lockbox with a [shared symmetric key](https://www.atlantic.net/vps-hosting/what-is-symmetric-key-encryption-vpns-work-part-1/) to keep things secure. So, Burt proposes they try a new method in which each of them has their own unique set of keys (asymmetric encryption). ## Public Key Cryptography Public Key Cryptography is an asymmetric encryption methodology that seeks to maintain confidentiality without having to ever share a secret key over an insecure channel (such as unencrypted email). In this explanation, Adam and Burt each have a unique lock, but for the remainder of this example, we’ll cover Burt’s lock and keys (Adam’s lock and keys will work in the same fashion). Each lock has two special properties: first, the lock has two distinct and related keys that can work with it, and second, each key that works with the lock can only turn in the lock in one direction–for the sake of this example, they only turn clockwise. ## Paired Keys The two keys in this asymmetric system only work as a pair. If Burt were to re-key this lock, he’d need to create two new keys. To make it simpler to distinguish the two keys, Burt color-codes them. One he makes green and the other red. Burt keeps the red key secured (his private key), but he can make the green key widely available to anyone who wants it (his public key). This may sound counterintuitive. But an important feature of these keys is that while they are related, it is virtually impossible to figure out one key based on knowledge of the other. As such, one key can be made publicly available without revealing anything about its counterpart. ![Public Key](https://www.atlantic.net/wp-content/uploads/2018/01/vpn1-1.png) ### Public Key Cryptography Systems These keys are, in actual use, called the public and private keys (the color designations are to help make the explanation a little easier to follow). The generation of these keys involves some pretty nifty and complicated mathematics. (These algorithms begin with calculations involving the product of two very large prime numbers and is [far beyond the scope of this example](http://en.wikipedia.org/wiki/RSA_%28cryptosystem%29#Key_generation).) Common algorithms used in public key cryptography include RSA (named for its creators, Rivest, Shamir, and Adleman), DSA/DSS (Digital Signature Algorithm/Digital Signature Standard), and ECDSA (Elliptic Curve Digital Signature Algorithm). This latter algorithm instead utilizes the mathematics around elliptic curves and is at least as intimidating to the math-averse as the RSA algorithm. ## The Clockwise Lock (How the Keys Work) Besides only working as part of a pair, these keys also only work in the lock in one direction. For example, Burt uses the green (public) key to secure the lock, which requires a half-turn in the lock. Since the lock only works in one direction, the green key can’t unlock the lock by reversing direction like an ordinary lock. At this point, because of the special nature of this locking mechanism, the only way to unlock it is to use the paired red (private) key. ![Private Key](https://www.atlantic.net/wp-content/uploads/2018/01/vpn2-1.png) In this fashion, when the lock is secured with the green (public) key, only the person who possesses the red (private) key can open it. This is how Burt can make the green key widely available to the public. He can send a copy of the green key to Adam (he could even make a copy available for public pickup or duplication). Anyone who has a copy of this green key can lock this lock, and at that point, only Burt–assuming he keeps his red (private) key secure–can open the lock. Now, when Adam wants to securely send something to Burt, he can use Burt’s green (public) key. Similarly, Adam would have his own key pair, and he could also make his green key available for Burt (or anyone else) to use. Now, if our ne’er-do-well Cesar were to try to crack this method of security, he’d need to crack two different locks in order to get the whole conversation. Even if he were able to get past just one, he’d only be able to see one half of the conversation. ### One-Way Encryption This usage of one-way encryption is employed in some secure email exchanges, such as with the use of PGP (Pretty Good Privacy) or GPG (Gnu Privacy Guard). If you’ve ever seen mention of someone’s PGP or GPG public key (and likely a block of random-looking text that was the key itself), you can see why it can be published as a part of an email signature or a publicly accessible website. With that key, anyone can encrypt an email that only the possessor of the private key (the recipient) can decrypt. ## A Twice-Locked Box Here’s where Burt gets a clever idea. He places some artwork for the comic book he and Adam are working on in a box, places his lock on the box, and secures it with his green (public) key. Now, he’s the only person (since he has the only copy of the red key) that can unlock this box. He sends this box to Adam. ![A Twice-Locked Box](https://www.atlantic.net/wp-content/uploads/2018/01/vpn3-1.png) Adam, not having a copy of Burt’s red (private) key, can’t unlock the lock. But he can place his own lock on the box. He secures this lock with his own green (public) key. Adam sends this twice-locked box back to Burt. Burt gets the box, and the only way he can open it is if he has both his own red key and Adam’s red key. But Adam is keeping his red key just as secret as Burt keeps his own red key, so Burt won’t be able to open the box. Burt, though, doesn’t want to open the box–remember, he started this process, so he wants Adam to get the art contained within the box. He can, though, unlock his own lock with his own red (private) key. When he does this, the only security on the box is the lock that Adam secured. Burt sends the box back to Adam, and now Adam, using his red key, unlocks the remaining lock. Burt has successfully and securely sent this package. This method adds a couple of layers of security, in that there are two layers of locking/encryption and in the fact that no shared key needs to ever be exchanged via a potentially insecure medium. However, it isn’t a very efficient system if they need to send more secure messages back and forth in a more timely manner. ### Double the Encryption This ability is one of the interesting features of the mathematics behind public key cryptography. A message can be encrypted multiple times; then, when decrypting it, that decryption can be done in any order. It works in a commutative way the way some simple mathematic functions work. For example, if you were to start with the number 10 and add three other numbers–say, 3, 5, and 7 (so, 10 + 3 + 5 + 7 to get 25), you could then subtract them from your total in any order to get back to the same original number (25 – 5 – 7 – 3 = 10). Of course, the mathematics behind this cryptography is significantly more intricate. ## A Complicated, Robust Lock So while Adam and Burt now have worked out a public-key cryptography method, it’s not without its drawbacks. This twice-locked box method of keeping communication secure takes three times as long per message. In addition, public-key cryptography methods tend to be more work-intensive when it comes to carrying out the encryption or decryption. In the example above, imagine that instead of each key turning in the lock one half turn, it requires 10 full rotations. That would mean 40 rotations (Burt locks (10) + Adam locks (10) + Burt unlocks (10) + Adam unlocks (10)) per message! ![Robust Lock](https://www.atlantic.net/wp-content/uploads/2018/01/vpn4-1.png) There is, however, one advantage to this inefficiency. If Cesar were to use a device that could simulate any key, and assuming that to open one of these locks requires the full 10 rotations just to see if that key works, then the time it would take him to try every key combination (a brute force attack) goes up by a factor of 10 as well. ### How Larger Keys Improve Security The length of an encryption key is measured in bits. The larger the bit length of the key, the more resistant that key is being discovered via brute-force cracking attempts. The larger the bit length of the key also means that the work required to perform encryption or decryption increases. However, since asymmetric and symmetric encryption algorithms work in different ways, their key lengths aren’t directly comparable. For example, an RSA (asymmetric) 1024-bit key has about the same strength as an 80-bit symmetric key. There are tools available to compare relative key lengths across the different encryption methods, such as [the one maintained by BlueKrypt](http://www.keylength.com/en/compare/), that can help illuminate the difference in computational cost between these methods. These differences highlight one of the primary conundrums of computer security: security vs. convenience. Work done to improve one often comes at the expense of the other. Increasing the bit-length of the encryption key increases its strength, but it also means that it will take longer to perform that encryption and decryption. When measures are made to improve convenience, such as increasing computing power or reducing the length of the key, those same measures also mean it requires less work to successfully guess the key through brute-force methods. ### More in the “How VPNs Work” Series [Part 1: Symmetrical Encryption Algorithms](https://www.atlantic.net/vps-hosting/what-is-symmetric-key-encryption-vpns-work-part-1/) [Part 3: Shared Key Exchange](https://www.atlantic.net/vps-hosting/what-is-shared-key-exchange-vpns-work-part-3/) Learn more about services from Atlantic.Net, including [VPS hosting](https://www.atlantic.net/vps-hosting/). --- # How to Add an Additional IP to Your Ubuntu or Debian Cloud Server > URL: https://www.atlantic.net/vps-hosting/how-to-add-an-additional-ip-to-your-ubuntu-or-debian-cloud-server/ | Published: 2015-05-13 | Updated: 2026-03-02 | Author: Alexander Wise ##### Verified and Tested 02/27/2021 ## Introduction This how-to will walk you through the process of adding an additional IP to your Ubuntu or Debian server. In order for an additional IP to work properly, it must be added to both the cloud interface and your server. ## Prerequisites – Root privileges – A reserved additional IP. You can find out how to [reserve an additional IP here](https://www.atlantic.net/tutorials/). ## Adding your Additional Public IP in the Cloud Control Panel We’ll start by logging in to the [Atlantic.Net Cloud Control Panel](https://cloud.atlantic.net/?page=userlogin). ![](https://www.atlantic.net/wp-content/uploads/2021/03/Cloud-Login-1.png)   Navigate to your ‘*Public IPs*‘ section. ![](https://www.atlantic.net/wp-content/uploads/2021/03/Public-IPs-Page-2.png) We begin by clicking on “**Reserve IP**“.  A popup box will appear asking for the *IP Location* and *Count* of public IPs to add. For *IP Location*, select the same location as your Atlantic.Net CentOS server. We only want to add one IP address, so we will enter “**1**” for *Count.*  Now click “**Reserve Public IP**.” ![](https://www.atlantic.net/wp-content/uploads/2021/03/Reserving-a-Public-IP.png) We can now see a new IP address displayed under “*Public IPs*.” ![](https://www.atlantic.net/wp-content/uploads/2021/03/Public-IP-Reserved-2.png) **Click on the checkbox** next to the newly reserved public IP address, and choose to “**Assign IP.**”  *(Note: You can assign the IP to any of the servers in the same location that IP was reserved. For this tutorial, we will assume you want to assign this IP to a CentOS server.)* ![](https://www.atlantic.net/wp-content/uploads/2021/03/Assigning-a-Public-IP-3.png) ![](https://www.atlantic.net/wp-content/uploads/2021/03/Assigning-a-Public-IP-2-2.png) Once the IP is assigned, it should look something like this: ![](https://www.atlantic.net/wp-content/uploads/2021/03/Public-IP-Assigned-2.png) Now we can move on to adding the IP to the actual server’s network interface. ## Add an Additional IP to Your Ubuntu Server To add this IP to your server’s network interface, you will need to edit your /etc/netplan/01-netcfg.yaml file, but first we should back it up in case of any mistakes. To do this, make sure you are on the root account on your server and use the following command: ``` cp /etc/netplan/01-netcfg.yaml /etc/netplan/01-netcfg.yaml.backup ``` Once copied, we can view and edit the file with nano: ``` nano /etc/netplan/01-netcfg.yaml ``` Once there, you should see something like this: ``` network: version: 2 renderer: networkd ethernets: eth0: addresses: - 208.117.86.35/24 gateway4: 208.117.86.1 nameservers: addresses: - 209.208.127.65 - 209.208.25.18 ``` We want to add our IP below the eth0 and name it eth1. It should look something like this: ``` network: version: 2 renderer: networkd ethernets: eth0: addresses: - 208.117.86.35/24 gateway4: 208.117.86.1 eth1: addresses: - 208.117.87.9/24 gateway4: 208.117.87.1 nameservers: addresses: - 209.208.127.65 - 209.208.25.18 ``` Save and close the file then run the following command to apply the changes: ``` netplan apply ``` You can now verify the newly assigned IP address with the following command: ``` ip addr ``` You should get the following output: ``` 1: lo: mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever inet6 ::1/128 scope host valid_lft forever preferred_lft forever 2: eth0: mtu 1500 qdisc fq_codel state UP group default qlen 1000 link/ether 00:00:d0:75:56:23 brd ff:ff:ff:ff:ff:ff inet 208.117.86.35/24 brd 208.117.86.255 scope global eth0 valid_lft forever preferred_lft forever inet6 fe80::200:d0ff:fe75:5623/64 scope link valid_lft forever preferred_lft forever 3: eth1: mtu 1500 qdisc fq_codel state UP group default qlen 1000 link/ether 00:00:0a:75:56:23 brd ff:ff:ff:ff:ff:ff inet 208.117.87.9/24 brd 208.117.87.255 scope global eth1 valid_lft forever preferred_lft forever inet6 fe80::200:aff:fe75:5623/64 scope link valid_lft forever preferred_lft forever ``` ## Add an Additional IP to Your Debian Server To add this IP to your server’s network interface, you will need to edit your /root/etc/network/interfaces file, but first, we should back it up in case of any mistakes. To do this, make sure you are on the root account on your server and use the following command: ``` cp /etc/network/interfaces /etc/network/interfaces.backup ``` Once copied, we can view and edit the file with nano: ``` nano /etc/network/interfaces ``` Once there, you should see something like this: ``` auto lo iface lo inet loopback ``` ``` auto eth0 iface eth0 inet static hwaddress ether 00:00:45:1c:5e:d6 address 192.168.0.1 netmask 255.255.252.0 gateway 192.168.0.1 ``` ``` ``` ``` dns-nameservers 209.208.127.65 209.208.25.18 ``` We want to add our IP below the eth0 and name it eth1. It should look something like this: ``` auto eth0 iface eth0 inet static hwaddress ether 00:00:45:1c:5e:d6 address 192.168.0.25 netmask 255.255.252.0 gateway 192.168.0.1 ``` ``` ``` ``` auto eth1 iface eth1 inet static address 192.168.0.26 netmask 255.255.252.0 ``` Once you have this set, save and restart the network service to apply the changes: ``` systemctl restart networking ``` Once the service is restarted, your new IP will be set! --- # What Is the VENOM Security Vulnerability? > URL: https://www.atlantic.net/vps-hosting/what-is-venom-security-vulnerability/ | Published: 2015-05-14 | Updated: 2026-03-04 | Author: Mason Moody ## Overview ![What Is a VENOM?](https://www.atlantic.net/wp-content/uploads/2018/01/What-Is-Guy.png)On May 13, 2015, security researcher Jason Geffner of CrowdStrike publicly disclosed a vulnerability in some virtualization platforms that could allow an attacker to jump out of the sandbox of a virtual machine (VM) and gain access to the protected virtualization host. The vulnerability has been christened “VENOM”, for Virtualized Environment Neglected Operations Manipulation ([CVE-2015-345](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3456)) and affects any unpatched virtualization host built on the open source QEMU emulator, including Xen, KVM, and Oracle’s VirtualBox. Technologies that don’t employ QEMU, such as VMWare, Microsoft’s Hyper-V, and Bochs, are unaffected. ### Virtualization Primer Virtualization, in broad terms, is a technology implementation which allows one large computer to subdivide its resources (processor, memory, hard drive space, e.g.) to run many smaller, virtual computers. Each of these VMs runs as though it is a discrete system, isolated from the other VMs running on the same host. This architecture allows server operators to more easily manage and deploy servers, since they can create a new VM in much less time than it would take to build out a physical version. It also allows data center operators and hosting providers to make more efficient use of their resources. A virtualization host running, for example, 10 VMs uses a fraction of the space, power, and cooling that 10 equivalent physical machines use. ### What Can an Exploit Against VENOM Do? One of the other benefits of a virtualization platform is the ability to segregate VMs. So, even though they may use the same shared hardware, the VMs are isolated. Such isolation allows a server administrator to provision different VMs, running different operating systems, for different customers. Those customers would never know that they were sharing resources on a virtualization host with other customers. And even if they had root or administrator privileges on their VMs, the containment prevents them from doing anything that would affect any other VM. This siloed infrastructure concept is what makes the idea of a vulnerability like VENOM so concerning. As Geffner describes on the CrowdStrike website: > This vulnerability may allow an attacker to escape from the confines of an affected virtual machine (VM) guest and potentially obtain code-execution access to the host. Absent mitigation, this VM escape could open access to the host system and all other VMs running on that host, potentially giving adversaries significant elevated access to the host’s local network and adjacent systems. For a provider who has relied on the security of VM isolation, such a vulnerability can cause quite a bit of alarm. ### How Much Alarm? While the announcement of this vulnerability has been compared, in some media outlets, to Heartbleed, it’s important to weigh what is known against what is possible and probable. According to Geffner, the “VENOM vulnerability has existed since 2004”, though no known exploit (as of this writing) has been documented in the wild. Geffner shared his findings with the major virtualization vendors who utilize QEMU on April 20, 2015. Once a patch was developed, he published his findings on the CrowdStrike website on May 13, 2015. To date, though, there has been no public proof of concept demonstrated. We don’t currently know how simple or difficult it is to craft code that can exploit VENOM. Since VENOM leaves a system open to attack via the hacker’s old friend, the buffer overflow, it could, at its simplest, be exploited to cause the host machine to crash, resulting in a denial of service. With more care and cleverness, an attacker could potentially gain access to the virtualization host itself and be able to compromise the other VMs running on that same host. ### What Can We Do To Protect Ourselves? Since VENOM was disclosed responsibly, giving the vendors time to produce a patch, it’s incumbent upon virtualization host administrators to apply the patch as quickly as they are able. Individuals whose services run on VMs running on a shared virtualization platform can do little on their own. They can, however, visit their provider’s website to see if they are vulnerable and what steps are being taken to address the vulnerability. If necessary, they can apply pressure to push their administrators to patch their systems before this potential threat becomes a functional exploit in wide use by the darker side of the Internet. To follow more about what Atlantic.Net is doing to address the VENOM vulnerability, check out [our blog](https://www.atlantic.net/announcements/update-on-venom-cve-2015-3456-qemu-vulnerability/) for the latest.  We constantly strive to offer the most secure [Virtual Private Servers](https://www.atlantic.net/vps-hosting/) offering the very best in one-click install applications like cPanel Hosting, among others. *Updated May 15, 2015, to include Atlantic.Net blog link* --- # Ensuring Cloud Compliance In Regulated Industries > URL: https://www.atlantic.net/hipaa-compliant-hosting/ensuring-cloud-compliance-in-regulated-industries/ | Published: 2015-05-14 | Author: Sam Guiliano - **Why is Cloud Computing Worth the Effort for Regulated Companies?** - **What Are You Up Against?** - **What Can You Do to Adopt Cloud Effectively?** - **Partners that Understand Compliance** The businesses that run into the most difficulties when transitioning to cloud computing solutions are strictly regulated, such as finance and healthcare. What are the challenges? How can they be overcome? And why is the effort worth it? Let’s start with the last of those questions. ### **Why is Cloud Computing Worth the Effort for Regulated Companies?** According to a presentation at the 2014 annual meeting of the IEEE Computer Society, there are four primary benefits of the cloud: - Software patching and updating are handled by the provider. - There is no need to worry about on-premise equipment maintenance. - Cloud is usually more affordable. - Virtual machines offer real-time scalability, adapting resource levels to meet your needs. These advantages are all compelling. After all, cloud computing isn’t just useful for startups: mega-enterprise [General Electric has said](http://www.infoworld.com/article/2824508/cloud-computing/ges-head-of-it-were-going-all-in-with-the-public-cloud.html) it is cutting down its data centers to 10% of their original size in favor of the public cloud. Even the Department of Defense is on board. “Procuring [cloud-based solutions and services] will allow the Army to focus resources more effectively to meet evolving mission needs,” [explained Gary Wang](http://www.federaltimes.com/story/government/it/cloud/2015/04/08/in-line-with-dod-cio-army-pushes-forward-with-new-cloud-policy/25470727/), Army deputy CIO. Let’s move on to those first two questions, though – cloud challenges and strategies – so that your organization has a clear path forward. ### **What Are You Up Against?** As the authors of the IEEE paper, Beckman Coulter and Iyyappan Pandiyan, see it, three features of cloud present obstacles to regulated companies: - Within a cloud solution, the information is processed and stored through a distributed network at a distance, and federal compliance mandates strict control of all data. - Cloud providers update their systems often without their users even being aware that changes have occurred, and firms concerned with regulations want to validate all their tools. - A cloud virtual machine can deliver memory elastically, and regulated bodies want to ensure that all data and memory are accurate and reliable. There is another, deeper challenge than any of the above, though. Adam Hughes of *TechTarget indicated that* regulated industries struggle with misinformation and confusion. “If I’m a customer, I need a deep understanding of the regulatory issues, how I will address them and what my priorities are,” commented regulation specialist Brian Benfer of ShareFile. “No one seems to understand the regulatory environment and what’s needed, and what the right steps are to take.” Larry Freedman, an attorney with Boston technology law firm Edwards Wildman Palmer, echoed Benfer’s sentiments. Plus, there’s a real-world challenge to these virtual systems in the public sector, according to data center expert Larry Veino of Presidio Corp.: politics. The various government departments each have strategic plans that may initially seem at odds with a “Cloud First” approach. Veino believes that government IT is experiencing the same growing pains that the healthcare segment did a few years back. ### **What Can You Do to Adopt Cloud Effectively?** Beckman and Pandiyan suggested the following strategies so that companies can migrate to the cloud while maintaining federal compliance: - You want to validate the cloud architecture when it’s first adopted. - You want all updates to occur at specific, predetermined times. - You want all modifications to be aggregated. - You want to re-validate every time updates are performed. ### **Partners that Understand Compliance** I discussed the general challenge of confusion above. That confusion is because cloud providers are trying to sell you a service, which can sometimes contradict clarity. How best to pick out a provider? Dan Kusnetzky, IT analyst and founder of the Kusnetzky Group, [recently outlined](http://www.zdnet.com/article/6-suggestions-connectria-hosting-for-evaluating-your-cloud-service-provider/) several characteristics that can help to establish that a cloud service provider deserves your business: 1. You want the company to prioritize security with the latest **industry standards**. Two of the primary ones are SSAE 16 and Safe Harbor. 2. You want to know that the provider has an established record of **data safety**. Breaches are too costly – $3.5 million per incident, according to the Ponemon Institute. 3. Make sure that the company has **private virtualization** options. Private Cloud Hosting gives you your own set of dedicated resources. 4. Your hosting company should have plenty of **experience meeting compliance** with federal regulations and other common standards such as PCI-DSS. 5. You want to know that the hosting company’s personnel includes a team of engineers with **specialized**cloud and regulatory compliance knowledge. 6. Finally, you want your cloud service provider to be **financially strong**. That last element is a characteristic that is often overlooked when reviewing providers. Your business may be just launching, argued Kusnetzky, but bankruptcy at your hosting provider is a huge threat to business continuity. Financial strength is just one of the many reasons why companies in regulated industries choose us as a partner. “Atlantic.Net’s reputation for 100% up-time, their secure infrastructure, and expertise in Healthcare IT were key components in finalizing our partnership,” commented Complete Healthcare Solutions VP Joseph Nompleggi. “Our partner’s financial strength and proven track record are something we view with great confidence.” ### Choosing a Compliant Hosting Provider for Your Regulated Industry When companies plan to move their existing IT services to a private cloud, security and compliance issues can seem a bit daunting.  However, moving to the right cloud-based system with a respectable cloud hosting provider could reduce your compliance exposure.  A private cloud does not have a public address and is connected directly into your existing corporate network via a secure connection, such as a VPN (Virtual Private Network).  Therefore, only people inside your corporate network can access those services. If your cloud service provide[r](https://www.atlantic.net/vps-hosting/) is flexible and will work with you on the connection, security, and monitoring, and authentication of applications in your cloud solution, the policies that you already have in place for protecting your data, authenticating user access, and distributing content can be used as they are.  Therefore, your company can receive the benefits of a private cloud without giving up security. The only major thing that changes when you move to private cloud hosting is the location of where your content is being stored.  If your company is like most enterprises, then you probably already have data being stored in several different locations – remote servers, backups, mobile devices, laptops, etc.  The advantage of having a reputable private cloud provider is that you will always know where your data is being stored. Your cloud hosting provider will be able to demonstrate the specific systems they have in place to ensure that your content is protected from unauthorized access.  If the location of the data center, backup systems, customer service, etc., meets the requirements of your business, moving to private cloud hosting with HIPAA-compliant online storage could easily enhance your compliance. Do you need a robust cloud infrastructure for healthcare? Get high-quality, proven **[HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)** today. Learn more about [HIPAA Compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). --- # How to Get Started with Arch Linux > URL: https://www.atlantic.net/vps-hosting/how-to-get-started-arch-linux/ | Published: 2015-05-14 | Updated: 2024-06-05 | Author: Atlantic.Net NOC ### Introduction Arch Linux is a Linux distribution composed predominantly of free and open-source software that expects a little more from its user. You must be willing to make some effort to understand the system’s operation. But, if you want more control over what gets installed on that system and how it runs, then this distribution might be for you. (This distribution is not ideal for Linux beginners unless you enjoy doing things the hard way!) Arch Linux uses a rolling release model, such that a regular system update is all that is needed to obtain the latest Arch software. For people who have run other Linux versions, some of the first differences users will notice are the setup/management of networking and package management. ## Basic Arch Linux Commands This article will cover some basics to give you start with Arch Linux, including setting the hostname, using basic network adapter functions, and using the Arch Linux package manager, called, simply enough, “pacman.” ## Setting the Arch Linux hostname: To change your server’s hostname, use the hostnamectl command (with most of these commands, you will likely need to either prepend sudo or already be logged in as root). `hostnamectl set-hostname "your hostname"` ![hostnamectl on Arch Linux](https://www.atlantic.net/wp-content/uploads/2018/01/arch1.png) Arch Linux change of hostname The quotation marks are only necessary if you use a hostname with a space in it. ## Using the Arch Linux network adapters #### Enabling and disabling interfaces: To verify which interfaces are on your server and what state they are in, you can use the ip link command: `ip link` ![ip link on Arch Linux](https://www.atlantic.net/wp-content/uploads/2018/01/arch2.png) Arch Linux network interface list To see the IP addresses configured on these interfaces, use ip addr instead. To enable or disable a particular interface, use the appropriate ip link command, substituting your interface name for the interface you want to affect. `ip link set eth0 up``ip link set eth0 down` (Pro-Tip: Remember which interface you are using to access this server, for example, if you are accessing this server remotely via ssh. If you disable the wrong interface, you could knock your session offline!) #### Network interface file location: If you’d like to make any changes to the interface file, open up the following file using your text editor of choice: `/etc/netctl/eth0` ![Arch Linux Interface Configuration](https://www.atlantic.net/wp-content/uploads/2018/01/arch3.png) Arch Linux: /etc/netctl/eth0 #### Restarting networking If you’ve made changes to your /etc/netctl/eth0 file, for example, you can get those changes to take effect by restarting networking on that interface: `netctl restart eth0`   ## Using the Arch Linux package manager (pacman) #### Refreshing the package list This command is similar to apt-get update in Debian/Ubuntu-based systems and should be run similarly before installing any new packages. `pacman -Sy` #### Installing a package If you know the name of a package, you can install it with just the -S option (think “synchronize”). `pacman -S ` ![pacman -S](https://www.atlantic.net/wp-content/uploads/2018/01/arch4.png) Arch Linux package installation * The ‘sl’ package is a fun little addition that, when installed and invoked, gives you an animated ASCII steam locomotive. It’s best utilized if you’re prone to mistyping ‘ls’ as ‘sl.’ #### Searching for available packages If you’re unsure of the package name, you can search with the -Ss options. `pacman -Ss ` #### Removing a package Removing a package requires the use of the -R option: `pacman -R ` ![pacman -R](https://www.atlantic.net/wp-content/uploads/2018/01/arch5.png) Arch Linux package removal   #### Upgrading all packages To update all packages installed on your system, the command takes the additional -u option. If, as above, you are familiar with Debian/Ubuntu, this command is the equivalent of apt-get upgrade. `pacman -Syu` Thank you for following along, and feel free to check back with us for further updates and related posts – like [How to Install Apache, MySQL, PHP (LAMP) On Arch Linux](https://www.atlantic.net/vps-hosting/how-to-install-lamp-arch-linux/) – or learn more about our reliable [VPS hosting](https://www.atlantic.net/vps-hosting/) servers. --- # How to Add an Additional IP to FreeBSD 10.1 > URL: https://www.atlantic.net/vps-hosting/how-to-add-an-additional-ip-to-freebsd-10-1/ | Published: 2015-05-15 | Updated: 2025-08-04 | Author: Alexander Wise ##### Verified and Tested 04/21/2015 ## Introduction This tutorial will take you through adding another IP to your FreeBSD 10.1 Atlantic.Net Cloud server. This tutorial will cover public and private IPs available in the Cloud Portal. ## Add an Additional IP to FreeBSD 10 To add an IP to FreeBSD, you need to first open /etc/rc.conf with an editor. In our case, we use vi here. ``` vi /etc/rc.conf ``` Once in, you should receive a screen like below. ![Add an Additional IP to FreeBSD 10.1](https://www.atlantic.net/wp-content/uploads/2021/03/anet-freebsd_10_add_ip.png) Sample rc.conf   **For public IPs:** For adding a public IP, you will want to add an alias to the *ifconfig_vtnet0* interface. To do this, we add a new line that begins with *ifconfig_vtnet0_alias1* under *ifconfig_vtnet0* and add your additional IP information. The line should look like this: ``` ifconfig_vtnet0_alias1="inet 209.208.108.170 netmask 255.255.252.0" ``` Where 209.208.108.170 is our additional IP. If you are adding more than one IP, you need to increment the alias segment (so *alias2*, *alias3*, and so forth.)   **For private IPs:** For adding a private IP, you will want to notice the spot that states *#ifconfig_vtnet1=”inet netmask ”*. You will first want to uncomment the line by removing the *#*. Once done, you will want to remove ** and insert the private IP address you will be using. You will want to do the same thing with ** and insert your netmask. The line should end up looking like this: ``` ifconfig_vtnet1="inet 10.0.208.2 netmask 255.255.255.0" ``` Where our private IP is 10.0.208.2. To add more than one private IP, you will want to follow the alias format in the public IP section above. You’d want to start a new line that begins with *ifconfig_vtnet1_alias1* and increment the alias as you need to.   Once you have made your changes, you need to save the file and restart networking on the server. To do this run: ``` ifconfig_vtnet1="inet 10.0.208.2 netmask 255.255.255.0" ``` The changes and routing will occur immediately, and you can begin using your new IP address(es). Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Linux, Apache, MySQL and PHP (LAMP) on a Ubuntu 20.04 Cloud Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-linux-apache-mysql-php-lamp-ubuntu-20-04/ | Published: 2015-05-15 | Updated: 2025-03-06 | Author: Alexander Wise ##### Verified and Tested 06/12/2021 ### Introduction In this How-To, we install LAMP on an Ubuntu 20.04 Cloud Server. LAMP is a simple software bundle of 4 components, Linux, Apache, MySQL, and PHP. **L**inux is the platform’s core; in this case, we are using Ubuntu 20.04 LTS. **A**pache is the webserver; most of the web servers globally are running Apache **M**ySQL, a database management system developed by Oracle. **P**HP is an extremely popular programming language widely used in web development. Altogether this forms LAMP or LAMP stack. ### Prerequisites A server with Ubuntu 20.04  installed. Get a reliable VPS from Atlantic.Net if you do not have one. ## Installing LAMP on Ubuntu 20.04 Before we begin the installation, your system must be up to date; you can do so with the following command: ``` apt-get update ``` Once updating, we can get to the first step of making a LAMP stack by installing Apache. ## Installing Apache on Ubuntu 20.04 Install Apache by running the following command: ``` apt-get install apache2 ``` Hit enter when it asks, “Do you want to continue?” during the install. After the install, you can check to see if Apache is running by running the command: ``` systemctl status apache2 ``` Also, you can verify if all is working by opening your browser and going to http://youripaddress If you do not know your IP address, you can run the following command: ``` ip addr show eth0 ``` In our case, we would put http://69.87.216.72 in your browser’s address bar and get the following page: ![The default page for Apache on Ubuntu 14.04](https://www.atlantic.net/wp-content/uploads/2018/01/linux2.png) The default page for Apache on Ubuntu 20.04 ## Installing MySQL on Ubuntu 20.04 Install MySQL with the following command: ``` sudo apt-get install mysql-server libapache2-mod-php php-mysql ``` After installing MySQL server, secure the MySQL server with the following command: ``` mysql_secure_installation ``` Note: You will be prompted with a series of questions. Just type N for the change root password and Y for yes on all of the rest; see the screenshot below: ![An example of what mysql_secure_installation looks like](https://www.atlantic.net/wp-content/uploads/2018/01/linux5.png) An example of what mysql_secure_installation looks like Verify that MySQL is running with the following command: ``` systemctl status mysql ``` ## Installing PHP on Ubuntu 20.04 Install PHP with the following command: ``` apt-get install php ``` Create a test PHP file called info.php in /var/www/html/. In this how-to, we will be using the text editor nano with the following command: ``` nano /var/www/html/info.php ``` Insert the following code in the text editor, then save and exit: ``` ``` Since we made changes, we need to restart Apache so that the changes take effect: ``` systemctl restart apache2 ``` Test your page in your browser with the following hyperlink changed with your IP address: http: //youripaddress/info.php ![Display PHP information](https://www.atlantic.net/wp-content/uploads/2015/05/p2-1024x619.png) Congratulations! You have just installed LAMP on your Ubuntu 20.04 Server. Thank you for following this How-To on installing LAMP; please check back for more updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # Change your SSH Port in Ubuntu and Debian > URL: https://www.atlantic.net/vps-hosting/how-to-change-ssh-port-ubuntu-debian/ | Published: 2015-05-17 | Updated: 2024-06-05 | Author: Jason Mazzota ##### Verified and Tested 4/21/15 ### Introduction In this tutorial, we will be showing you how to change the SSH port in Ubuntu and Debian. The operating system we created for this walkthrough is a brand new Ubuntu 14.04 64 bit Cloud server. This also works in our Ubuntu 12.04 OS and our Debian Cloud Servers. We will be using the vi editor for our file editing needs. Feel free to download and use any editor that you feel comfortable with. Believe it or not, one of the simplest things you can do to secure your server is to change the SSH port. Since SSH defaults to port 22, you will see a lot of brute force attacks occurring over that port as a lot of users do not change this default SSH port. ### Prerequisites An Ubuntu 14.04 64 bit server.  If you do not currently have a server, consider one of Atlantic.Net’s affordable [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions from Atlantic.Net. ## Change your SSH Port in Ubuntu and Debian The first thing we want to do is SSH into our server using your preferred SSH client. Be sure that if you are using a custom user, that you have sudo rights. Once you have logged into the server, let’s open our SSH configuration. ``` vi /etc/ssh/sshd_config ``` ![Edit "Port" directive accordingly.](https://www.atlantic.net/wp-content/uploads/2018/01/ssh1.png) Sample sshd_config For the above image, you can see where the configuration file states “Port 22.” To change the SSH port, you simply need to change the 22 to any number that you would like to use, provided it is a port another program does not run on.  For a list of common ports in use, you can check the following page.  In our example, we will be changing the SSH port to 922, so your new line should instead read “Port 922.” Once you have completed the change, exit and save the sshd_conf file, now all you need to run is the below command, and it will restart the SSH server. This means the next time you want to connect via SSH, you will need to do so on your new port, in our case, 922. ``` service ssh restart ``` Don’t forget to change the port 22 to your new port in your IPTables if you have it installed! You can check out the [Locking down your Ubuntu server with IPTables](https://www.atlantic.net/vps-hosting/how-to-securing-ubuntu-debian-server-iptables/) how-to on our blog for information on how to do that. **Please do not forget that you can always access your server via our VNC viewer in the Cloud Portal if you cannot access the port, you have changed this to.** Thank you for following along, and feel free to check back with us for further updates or learn more about our reliable [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Change the SSH Port in CentOS > URL: https://www.atlantic.net/vps-hosting/how-to-change-ssh-port-centos/ | Published: 2015-05-17 | Updated: 2024-06-05 | Author: Jason Mazzota ##### Verified and Tested 4/21/15 ### Introduction In this how-to, we will be showing you how to change your SSH port in CentOS. We created a brand new CentOS 6.5 64 bit Cloud server for the exact operating system. We will be using the vi editor for our file editing needs. Feel free to download and use any editor that you feel comfortable with. Believe it or not, one of the simplest things you can do to secure your server is to change the SSH port. Since SSH comes on a default port of 22, you will see a lot of brute force attacks occurring over that port because a lot of users do not change this default SSH port! ### Prerequisites A server installed with CentOS 6.5 x86_64.  If you currently do not have a server, please consider [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. ## Changing your SSH port in CentOS The first thing we want to do is SSH into our server using your preferred SSH client. Be sure that if you are using a custom user, that you have sudo rights. In this step, we will be performing commands as the root user. ![Log into Root shell](https://www.atlantic.net/wp-content/uploads/2018/01/ssh1-2.png) Once you have logged into the server, let’s open our SSH configuration. ``` vi /etc/ssh/sshd_config ``` Once you are in the configuration, you’ll want to look for the section that has “Port.” It should be near the top and shown as “#Port 22.” ![Edit "Port" directive in sshd_config ](https://www.atlantic.net/wp-content/uploads/2018/01/ssh2.png) We will be removing the ‘#’ so that it is a plain line of “Port 22”. Next, we will be changing the 22 in the line to be any number you’d like that another program does not run on. For a list of common ports in use, you can check the following MIT page. In our example, we will be changing the SSH port to 922, so your new line should read: Port 922 Once you have the change done, exit and save the sshd_conf file. Now all you need to run is the below command, and it will restart the SSH server. The next time you want to connect via SSH, you will need to do so on your new port, in our case, 922. ``` service sshd restart ``` Don’t forget to change the port 22 to your new port in your IPTables when done! You can check out the Locking down your CentOS server with IPTables section (link) for information on how to do that. Note: *If using Atlantic.Net Cloud services, You can always access your server via our VNC viewer in the Cloud Portal if you lock yourself out* Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install DNS Role on Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-install-dns-role-windows-server-2012/ | Published: 2015-05-18 | Updated: 2024-06-05 | Author: Jose Velazquez ##### Verified and Tested 03/18/2015 ### Introduction This how-to will walk you through the Install of DNS Server in Windows Server 2012. Domain Name System (DNS) is a system that translates a Domain name to the IP address that is associated with it over the World Wide Web. It is widely used to store the following records: A Records, AAA Records, MX Records, Name Servers, PTR/ Reverse Records, C Names, and more. It is what makes a Domain Name resolve. ## Install DNS Role on Windows Server 2012 Open the **Server Manager** from the taskbar. From **Server Manager **Dashboard, select **Add roles and features**. This will launch the Roles and Features Wizard, allowing modifications to be performed on the Windows Server 2012 instance. ![Install DNS Role on Windows Server 2012- Add roles and features](https://www.atlantic.net/wp-content/uploads/2018/01/dns1.jpg) Add roles and features   Note: If it’s the first time you have entered this wizard, you will get a **Before you Begin** page. Review it, and you can check the Skip this page by default box,  then click **Next.**   Select **Role-based or feature-based** installation from the Installation Type screen and click **Next**. ![Select Role-based or Feature-based installation](https://www.atlantic.net/wp-content/uploads/2018/01/dns2.jpg) Installation Type   You will now have the **Select destination server** page. Your server will be selected by default, so you can click **Next**to continue. ![Select your server](https://www.atlantic.net/wp-content/uploads/2018/01/dns3.jpg) Select your server   Select **DNS Server,** and the following page will come up. Click **Add Features**to continue. ![Select Add features in the Add roles and features wizard](https://www.atlantic.net/wp-content/uploads/2018/01/dns4.jpg) Add roles and features wizard   Click**Next** on the **Server Roles** page. Then review and **select optional features** to install during the DNS Server installation by placing a check in the box next to any desired features; Once done, click **Next**. ![Select any optional features that you may need.](https://www.atlantic.net/wp-content/uploads/2018/01/dns5.jpg) Select any optional features   Click Next on the **DNS Server** tab. Then Confirm the installation selections, then click **Install**. (Note: DNS Server doesn’t require a restart after the installation so that box can remain unchecked). ![Confirm and Install your your DNS server](https://www.atlantic.net/wp-content/uploads/2018/01/dns6.jpg) Confirm and Install your DNS server Once the installation is completed, you can click **Close** on the **Results** page, and you’re all set. Congratulations! You have just Installed DNS in Windows Server 2012. If you would like the configure DNS, please Check our “[Configure DNS in Windows Server 2012](https://www.atlantic.net/vps-hosting/how-to-configure-dns-windows-server-2012/)” article. Thank you for following along in this How-To, and feel free to check back with us for any new updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # What is Shared Key Exchange (How VPNs Work, Part 3) > URL: https://www.atlantic.net/vps-hosting/what-is-shared-key-exchange-vpns-work-part-3/ | Published: 2015-05-20 | Updated: 2024-09-25 | Author: Mason Moody In this article, we will explore how shared key exchange works. If you’re completely new to the concept of VPNs, check out [this introduction](https://www.atlantic.net/vps-hosting/what-is-vpn/). ## Getting Started with VPNs This article is part of a series on VPNs. If you already know a little about the how VPNs work and want to know a little more, this series is for you. Each article addresses one aspect of how a VPN helps secure data by telling a story that serves as a metaphor for the logical mechanisms involved. ## Shared Key Exchange In earlier adventures, our friends Adam and Burt have tried to keep their comic book project secret from Cesar’s snooping by securing the messages they exchange with [a shared key](https://www.atlantic.net/vps-hosting/what-is-symmetric-key-encryption-vpns-work-part-1/) and a more elaborate [public-/private-key pair system](https://www.atlantic.net/vps-hosting/what-is-public-key-cryptography-vpn-part-2/). Each system has its strengths and weaknesses. But the boys need a break from this project, and lucky for them, there’s a fair going on nearby. They enter the chili cook-off, and because they love keeping their creations secret, they devise a way of keeping their recipe secret, even as they prepare it in front of onlookers. The recipe will be so secure; even they won’t know it! ![Shared Key Exchange](https://www.atlantic.net/wp-content/uploads/2018/01/Chili_Cook_Off.png) ## A Well-Known Starting Point To pull this feat off, Adam and Burt will each need to develop a portion of the recipe without knowing anything about what the other has contributed. If neither of them knows the whole recipe, neither can reveal it. However, they agree on a common base of ingredients (a mixture of tomato base, chili seasoning, beef, and beans). There’s no need to keep this part secret–most of the other contestants start with a similar base, so they gain little in spending the effort to obscure these ingredients. ### Negotiating the Key Exchange The fact that the two parties can start with this negotiation over an insecure, public medium is one of the core and clever ideas behind this method of initiating encryption. Before any encryption can occur, there needs to be some unencrypted traffic between peers, otherwise, neither will know how to decrypt any future messages. This initial step lets one host tell another that it wishes to begin a negotiation of an encryption method by offering a couple of initial values to a well-known mathematical formula (which, in this example, is the base of the chili). The real magic comes in the next steps. ## Seeding the Key Adam and Burt have independently and secretly prepared a portion of seasoning and additional ingredients sealed in an opaque, rice-paper pouch that will dissolve once immersed in the chili. In this cook-off, Adam’s pouch contains tomatillos, chipotles, cayenne pepper, and cinnamon; Burt’s has Cajun seasoning, beer, cumin, oregano, and Worcester sauce*. Adam tosses his packet into his pot and stirs, tasting his chili until he is sure the pouch has dissolved and released its ingredients. Burt does the same with his pot. At this point, Adam and Burt have two different chilis. ![Diffie-Hellman key exchange start](https://www.atlantic.net/wp-content/uploads/2018/01/DH_Negotiation_start.png) **(in case you are wondering why this isn’t already dissolving from the beer, let’s say that Burt has pre-frozen any liquids before placing them in the dissolvable pouch.)* ### Generating the Shared Key In the actual key exchange process, these “ingredients” are actually very large prime numbers. In the key-exchange process, these large prime numbers are randomly generated. The larger the numbers used to input into this key exchange, the more difficult it is to use brute-force techniques to crack. The size of these numbers is called a bit group. A group of prime numbers of the same length in binary bits (e.g., 1024 or 2048 or even larger bit lengths) all belong to the same group. The larger the bit group, the more robust this key exchange process becomes and the more resistant it becomes to analysis and potential compromise. ## Completing the Exchange Now they switch the pots they are tending to, so Burt is at the pot Adam started, and vice versa. They each take another pouch identical to the one they started with and add this second pouch to the pot that the other had started (so Adam adds his tomatillos, chipotles, cayenne pepper, and cinnamon to the pot Burt started with the Cajun seasoning, beer, cumin, oregano, and Worcester sauce; and Burt adds his pouch to the pot Adam started). After each of them stirs their respective pots and dissolves the pouches to release the secret ingredients, they can be sure that each pot now contains identical chilis. ![Diffie-Hellman key exchange completion](https://www.atlantic.net/wp-content/uploads/2018/01/DH_Negotiation_next.png) ### The Diffie-Hellman Key Exchange In mathematical terms, the algorithm governing shared key exchange is commutative–it can be performed in any order and get to the same result. Also, note that neither Adam nor Burt have the means to reconstruct the key alone. Each of them only know the random value each contributed to the algorithm. And, since each also generates a copy of the key upon completion of the negotiation, each also has a copy of the final key without its having had been transmitted over a network. This shared key exchange or negotiation is called the Diffie-Hellman Key Exchange, named for the authors of the paper that first detailed this method, Whitfield Diffie and Martin Hellman. Their work built upon previous work done by Ralph Merkle, so it has been suggested ([by Hellman himself](http://en.wikipedia.org/wiki/Diffie%E2%80%93Hellman_key_exchange#Name)) this method be called the Diffie-Hellman-Merkle Key Exchange. In actual configurations, you will often see this method applied as DH Groups, different groups corresponding to keys of different lengths in binary bits. ## Complex Tastes During the preparation, any judges could have seen and sampled from the starting pots or the intermediate pots. Even if Cesar, intent on learning the secret recipe, poses as a judge, he wouldn’t be able to reliably reconstruct the final recipe Adam and Burt used. (This example assumes that Cesar doesn’t have the ability to distinguish all the individual flavors included in the chili. To attempt to identify the ingredients and their amounts via laboratory analysis would be expensive enough in time and energy invested in making it infeasible.) ### Potential Vulnerabilities If an attacker wanted to compromise any communication encrypted with this key, a typical man-in-the-middle eavesdropping attack would be insufficient. An attacker could, however, insert himself as a transit man-in-the-middle. If an attacker set himself up so that all communication between the two hosts had to go through him, he could perform a Diffie-Hellman negotiation with each peer. Each side of the connection would only know whether a successful key is negotiated, but not with whom. In this position, the man-in-the-middle would be able to see the whole conversation–in fact, he’d have to decrypt incoming traffic and re-encrypt it before sending it out the other side to maintain the impression that each end still has its “secure” connection. It’s also possible for an attacker to attempt to stage a man-in-the-middle attack to downgrade the DH group to a group whose bit length is much smaller and less secure. That attacker could then collect the weakly encrypted data and perform an offline brute force attack against the encryption to crack it in a reasonable amount of time. Attacks such as FREAK and [Logjam](https://www.atlantic.net/vps-hosting/what-is-the-logjam-vulnerability/) use some sort of downgrade methodology to weaken the Diffie-Hellman key exchange. ### More in the How VPNs Work Series [Part 1: Symmetrical Encryption Algorithms](https://www.atlantic.net/vps-hosting/what-is-symmetric-key-encryption-vpns-work-part-1/) [Part 2: Public Key Cryptography](https://www.atlantic.net/vps-hosting/what-is-public-key-cryptography-vpn-part-2/) Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting prices](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Active Directory Lightweight Directory Services Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-install-active-directory-lightweight-directory-services/ | Published: 2015-05-20 | Updated: 2024-06-05 | Author: Jose Velazquez ##### Verified and Tested 03/31/2015 ### Introduction This how-to will walk you through the Install Active Directory Lightweight Directory Services Windows Server 2012. Active Directory Lightweight Directory Services or AD LDS is a feature that allows you to assist applications that are directory-enabled without the restrictions of the Active Directory Domain Services. ### Prerequisites – A Server with Windows Server 2012. If you do not have a server already, consider an affordable [Windows VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net and be up and running in under 30 seconds. – Active Directory Domain Services.  If you need to install an active directory,  check out “[Installing Active Directory in Windows Server 2012](https://www.atlantic.net/vps-hosting/).” ## Install Active Directory Lightweight Directory Services Open the **Server Manager** from the taskbar. From **Server Manager **Dashboard, select **Add roles and features**. This will launch the Roles and Features Wizard, allowing modifications to be performed on the Windows Server 2012 instance. ![Install Active Directory Lightweight Directory Services Windows Server 2012-1](https://www.atlantic.net/wp-content/uploads/2018/01/light1.jpg) An example of the location of “Add roles and features.”   Note: If it’s the first time you have entered this wizard, you will get a **Before you Begin** page. Review it, and you can check the Skip this page by default box, and then click **Next.** Select **Role-based or feature-based** installation from the Installation Type screen and click **Next**. ![Install Active Directory Lightweight Directory Services Windows Server 2012-2](https://www.atlantic.net/wp-content/uploads/2018/01/light2.jpg) An example of where “Role-based or feature-based installation is located.   You will now have the **Select destination server** page. Your server will be selected by default, so you can click **Next**to continue. ![Install Active Directory Lightweight Directory Services Windows Server 2012-3](https://www.atlantic.net/wp-content/uploads/2018/01/light3.jpg) Click next after you have selected your server.   ![Install Active Directory Lightweight Directory Services Windows Server 2012-1](https://www.atlantic.net/wp-content/uploads/2018/01/light4.jpg) Check Active Directory Lightweight Directory Services The Select Server Roles page appears. Select the **Active Directory Lightweight Directory Services** check box, add features and click **Next** ![Install Active Directory Lightweight Directory Services Windows Server 2012-2](https://www.atlantic.net/wp-content/uploads/2018/01/light5.jpg) Click Install Click **Next** in the **Features** Screen/ click next in the **Active Directory Lightweight Directory Services** Screen/ Confirm your Installation and click **Install**. You can now see that the **Active Directory Lightweight Directory Services** role is currently installed in your **Server Manager** Screen. ![Install Active Directory Lightweight Directory Services Windows Server 2012-31](https://www.atlantic.net/wp-content/uploads/2018/01/light6.jpg) You can now see that Active Directory Lightweight Directory Services is installed. Congratulations! You have just Installed the Active Directory Lightweight Directory Services in Windows Server 2012. Thank you for following along in this How-To, and feel free to check back with us for any new updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Add a Custom Firewall Rule in Windows Server 2012 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-add-custom-firewall-rule/ | Published: 2015-05-21 | Updated: 2026-01-15 | Author: Jose Velazquez ##### Verified and Tested 03/24/2015 ## Introduction In this How-To, we will walk you through Adding a Custom Firewall Rule in Windows Server 2012. We will be adding a custom RDP Port for this tutorial. ## Prerequisites – A Server with Windows Server 2012. ## Adding a Custom Firewall Rule Open **Server Manager**/ Click on **Tools**/ Select **Windows Firewall with Advanced Security**/ Select **Inbound Rules** and click **New Rule**under actions.Select ![Adding a Custom firewall Rule in Windows Server 2012 ](https://www.atlantic.net/wp-content/uploads/2018/01/firewall1.jpg) Click new rule   Select **Custom** from the Rule Type radial button and click **Next**. ![Adding a Custom firewall Rule in Windows Server 2012-2](https://www.atlantic.net/wp-content/uploads/2018/01/firewall2.jpg) Click Custom   **Select the Program Association** for the Custom Firewall Rule, either All programs or the path to a program, and click **Next**. ![Adding a Custom firewall Rule in Windows Server 2012-3](https://www.atlantic.net/wp-content/uploads/2018/01/firewall3.jpg) Choose All Programs Select **TCP** for Protocol type/ Select **Specific Ports**in the **Remote port**  and type your custom RDP Port (I am currently using port 1050 for this tutorial), then click **Next** ![Adding a Custom firewall Rule in Windows Server 2012-4](https://www.atlantic.net/wp-content/uploads/2018/01/firewall4.jpg) Insert the port you want open; in this case, it is 1050   You can now specify if this rule applies to local IPs or Remote. (I will be leaving this blank so that I can access the server from anywhere through the specified port) ![Adding a Custom firewall Rule in Windows Server 2012-5](https://www.atlantic.net/wp-content/uploads/2018/01/firewall5.jpg) Choose the IPs you want to be allowed or blocked. In this case, we are keeping everything open.   You can leave the default or select your action and click **Next** ![Adding a Custom firewall Rule in Windows Server 2012-6](https://www.atlantic.net/wp-content/uploads/2018/01/firewall6.jpg) Choose Allow the connection You can allow this rule to **Domain**, **Private**, and **Public,** or specify accordingly. ![Adding a Custom firewall Rule in Windows Server 2012-7](https://www.atlantic.net/wp-content/uploads/2018/01/firewall7.jpg) Choose profiles that you want the rule to use. In this case, all. Type the name of your rule, and you can give it a description if you want, then click **Finish**. ![Adding a Custom firewall Rule in Windows Server 2012-8](https://www.atlantic.net/wp-content/uploads/2018/01/firewall8.jpg) Name your rule   You will now see that rule at the top of your list. ![Adding a Custom firewall Rule in Windows Server 2012-9](https://www.atlantic.net/wp-content/uploads/2018/01/firewall9.jpg) You can now see your custom rule.   Congratulations! You have just Added a Custom Port in Windows Server 2012 on your [Dedicated Server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! Thank you for following along in this How-To. Feel free to check back with us for any new updates. Also, learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # Linking Cloud Computing to Your Legacy Infrastructure > URL: https://www.atlantic.net/vps-hosting/side-stepping-the-roadblock-linking-cloud-computing-to-legacy-infrastructure/ | Published: 2015-05-21 | Updated: 2025-03-06 | Author: Alexander Wise According to a recent survey, almost four out of every five IT decision-makers feel hemmed in by traditional computing systems.  Companies that want to move confidently into the future – at least for now – must figure out how best to integrate their legacy architectures with the cloud. ## Survey: 80% of IT Leaders Call Legacy Infrastructure an Obstacle CIOs and IT directors say it’s difficult for them to meet business goals because of legacy servers, reductions in spending on computing, and a shortage of professionals who have the specialized knowledge and experience they need. That fact was revealed by a 2014 poll of 250 IT decision-makers. ### Why Is It Difficult to Move Forward? The study, designed and performed in conjunction by ControlCircle and Vanson Bourne, shows how substantially the legacy infrastructures of yesterday are making it difficult to expand and adapt today. 70% of survey participants said existing machines were holding them back. “With so much effort going into ‘keeping the lights on,’ and almost all businesses experiencing regular availability issues,” explained ControlCircle managing director, Carmen Carey, “it is hardly surprising that IT leaders are often unable to fulfill their ambitions.” 53% of CIOs and IT executives said that the diversification of infrastructures and software tracking systems to manage them decreases the consistency of service quality and makes high availability more elusive. Three in ten said that this current challenge would become increasingly intense as the third platform (cloud/mobile/social/big data) gradually becomes the standard for the IT landscape. ### Who Was Surveyed The authors of this report wanted to get a sense of the market. To that end, the executives’ opinions came from a broad spectrum of industrial types: - Banks - Consultancies - Healthcare providers - Manufacturing organizations - Public utilities - Tech companies - Telecommunications firms As Carey sees it, the findings suggest that CIOs are dealing with numerous obstacles that prevent them from maintaining service quality and gearing their attention toward development. The bigger a company is, she says, the more susceptible it is to problems with service quality since the legacy infrastructure is broader. However, “with enterprises also more focused on the reduction of capex,” Carey adds, “they need to identify specific areas for discrete IT projects that use innovative commercials and tools to help them achieve their strategic goals.” ## Migration – Are We Making Any Progress? Unfortunately, transitioning to the cloud is often more challenging than it first appears, hence the need for **strong and transparent support**. For a plethora of reasons, companies struggle. If all you had to do was grab the data and move it, the hybrid cloud would be the obvious model already, argued Arthur Cole in [*IT Business Edge* in 2013](http://www.itbusinessedge.com/blogs/infrastructure/look-forward-with-your-hybrid-cloud.html). In 2015, progress was made, but the ongoing transition is still tricky. Let’s look at Cole’s comments and others before fast-forwarding to a 2015 survey to determine if the problem is solved. “[M]any organizations are afraid to pull the plug until they are assured that this new paradigm is secure, reliable, and resilient enough to entrust with critical data and applications,” Cole suggested. ### Problem 1: Uncertain Costs One major problem was the lack of clarity upfront about how much the cloud would cost. Organizations sometimes didn’t factor in the expenses of migrating data and connecting systems, said Gregory Ness of CloudVelox. They may have assumed those costs were included, but they standardly aren’t. ### Problem 2: Integration Concerns Everyone wants the cloud to be fully accessible and to work intelligently with the legacy system for the greatest efficiency, remarked Cole, but that requires sophisticated management. Since migration and integration issues can be so vexing to IT decision-makers, everything should be built into the general system upgrade, according to blogger Rick Blaisdell. Ordinarily, companies think of those essential transition elements as tasks to complete to get to the cloud, while they should be considered a significant part of what it means to use cloud servers. Now, keep in mind, migration is becoming easier and more seamless all the time, partially because you get **better support expertise** than you did in the past. Migration tools are also becoming more robust and more full-featured. “Integrating [your cloud environment] with other cloud instances and legacy IT infrastructure … will be the single most challenging aspect of IT in the new millennium,” argued Cole. “Without that, the cloud will be too unwieldy and too ephemeral to provide any real productivity gains for the knowledge workforce.” ## Fast-Forward to 2015 Although this warning bell about migration was sounded as far back as a couple of years ago, the industry has not done enough to help businesses migrate as simply and efficiently as possible. Based on the perspectives of 1600 IT leaders in Europe and United States, the NTT Communications report[Cloud Reality Check 2015 revealed](http://www.channelweb.co.uk/crn-uk/news/2403970/cloud-migration-more-trouble-than-its-worth-survey) that 41% of tech decision-makers think that switching systems over to the cloud is “more trouble than it’s worth.” ## Cloud Hosting with Atlantic.Net The respondents to that survey have clearly not worked with Atlantic.Net and our [VPS hosting](https://www.atlantic.net/vps-hosting/), where we believe that our business thrives on the support we provide to our customers. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). By Moazzam Adnan --- # How to Install Active Directory Certificate Services Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-install-active-directory-certificate-services/ | Published: 2015-05-22 | Updated: 2026-01-15 | Author: Jose Velazquez ## Introduction This how-to will walk you through Install Active Directory Certificate Services Windows Server 2012 Active Directory Certificate Services or ADCS is a feature that provides certificates for user authentication. This feature aims to increase the network’s security by using the certificate that holds the users’ information and Private keys assigned. ## Install Active Directory Certificate Services Open the **Server Manager** from the taskbar. From **the Server Manager**Dashboard, select **Add Roles and features**. This will launch the Roles and Features Wizard, allowing modifications to be performed on the Windows Server 2012 instance. ![Add roles and features](https://www.atlantic.net/wp-content/uploads/2018/01/dns1.jpg) Click “Add roles and features.”   Note: If it’s the first time you have entered this Wizard, you will get a **Before you Begin** page. Review it, and you can check the Skip this page by default box,  then click **Next.**   Select **Role-based or Feature-based** Installation from the Installation Type screen and click **Next**. ![Install Active Directory Certificate Services Windows Server 2012-2](https://www.atlantic.net/wp-content/uploads/2018/01/active1.jpg) Select “Role-based or feature-based installation.”   You will now have the **Select Destination Server** page. Your server will be selected by default, so you can click **Next**to continue. ![Install Active Directory Certificate Services Windows Server 2012-3](https://www.atlantic.net/wp-content/uploads/2018/01/active2.jpg) Select the server you would like to install on.   ![Install Active Directory Certificate Services Windows Server 2012-1](https://www.atlantic.net/wp-content/uploads/2018/01/active3.jpg) Select “Active Directory Certificate Services” The Select Server Roles page appears. Select the **Active Directory Certificate Services** check box, and then click **Next**. Click **Next** in the **Features** Screen/ click **Next** in the **Active Directory Certificate Services** Screen/ Select any additional Role in the Role Services(I selected all of them just in case I need them later down the road) and click Next. ![Install Active Directory Certificate Services Windows Server 2012-2](https://www.atlantic.net/wp-content/uploads/2018/01/active4.jpg) ![Install Active Directory Certificate Services Windows Server 2012-3](https://www.atlantic.net/wp-content/uploads/2018/01/active5.jpg) Click Install Confirm your Installation and click **Install**. ![Install Active Directory Certificate Services Windows Server 2012-4](https://www.atlantic.net/wp-content/uploads/2018/01/active6.jpg) Active Directory Certificate Services is installed on the left side of the server manager. You can now see that the **Active Directory Certificate Services** role is currently installed in your **Server Manager** Screen. Congratulations! You have just Installed Active Directory Certificate Services in Windows Server 2012. Thank you for following along in this How-To, and feel free to check back with us for any new updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # What Is the Logjam Vulnerability? > URL: https://www.atlantic.net/vps-hosting/what-is-the-logjam-vulnerability/ | Published: 2015-05-22 | Updated: 2024-10-21 | Author: Mason Moody ## Overview of Logjam On May 20, 2015, a team of researchers announced a new vulnerability in the protocol that allows web servers to establish secure (HTTPS) connections to web browsers. Calling this exploit [the Logjam Attack](https://weakdh.org/), the team of computer scientists and security specialists from multiple universities and technology companies demonstrated how a man-in-the-middle attacker could downgrade a vulnerable TLS connection to use an encryption cipher that is “relatively easily” broken. This attack is the latest in a series of cipher downgrade attacks, such as [FREAK](http://freakattack.com/) and POODLE, that target implementations of the HTTPS protocol. ![The Logjam Vulnerability](https://www.atlantic.net/wp-content/uploads/2018/01/Logjam-lrg1.jpg) *Photo: [Sharon Mollerus](https://www.flickr.com/photos/clairity/9599693784) / licensed under [CC BY 2.0](https://creativecommons.org/licenses/by/2.0/)* ## SSL/TLS Overview To understand how this attack works, it might be helpful to review how TLS (Transport Layer Security, though this protocol is often still referenced by its predecessor’s initialism, SSL, Secure Sockets Layer) protects an HTTPS connection. When a web browser requests a webpage via an HTTPS connection, the host server will first offer its certificate to authenticate its identity, which uses asymmetric cryptography within the public key infrastructure. Once authenticated, the server then enters into a negotiation with the client browser over which cipher suite they will use for the connection. In most cases, they will use the most robust cipher suite they can agree upon. When they determine the encryption algorithm, they then negotiate their shared secret key via a process called the [Diffie-Hellman Key Exchange](https://www.atlantic.net/vps-hosting/what-is-shared-key-exchange-vpns-work-part-3/). ## Diffie-Hellman Key Exchange The Diffie-Hellman Key Exchange allows for the secure generation of a new shared key between parties to happen over an insecure medium. The larger the bit-length of the Diffie-Hellman group, the more resilient it is to being cracked by a brute force attack. Groups of 1024 bits are in wide use, though the researchers who discovered the Logjam vulnerability [posit that state-sponsored actors are within reach to crack the encryption of this strength](https://weakdh.org/imperfect-forward-secrecy.pdf). The Logjam vulnerability is exploited by forcing the two parties to downgrade the Diffie-Hellman group to a 512-bit group, which can be cracked in minutes. ## How Concerned Should We Be? Exploiting the Logjam vulnerability requires an attacker to occupy a man-in-the-middle position. In other words, an attacker would need to access the same network as the client, server, or any ISP in between. This access, which includes most wired connections, is generally walled off most garden-variety snoopers. If you access the Internet via an open public wi-fi access point, then you might have cause for concern, whether from an exploit of this vulnerability or a host of others. In that case, your best bet is to utilize a VPN (if you are concerned about security, then this is a prudent strategy in any case). If an attacker can pull off this exploit, it’s only the first step. It still requires that the attacker access a device with significant computational power to decrypt any intercepted and downgraded encrypted traffic successfully. As such, it’s not the most straightforward trick to execute, so it’s probably not a vulnerability that one should lose too much sleepover. However, a vulnerability is a vulnerability, so the sooner patched, the sooner you can knock it off the list of things to worry about. ## What To Do To Protect Yourself As of the release of the news of this discovery, only the latest version of Internet Explorer has been patched for this exploit (it should be noted that one of the researchers on this team works for Microsoft Research). Mozilla, Google, and Apple have announced that they are working on patches for their respective browsers, Firefox, Chrome, and Safari. When those patches are released, you should update your browser to those versions to enable protection from this vulnerability. In the meantime, though, if you are concerned about your exposure to this sort of attack, you might want to stick to IE for your secure browsing. Suppose you administer a web or email server. In that case, you can mitigate your vulnerability by removing the list of cipher suites export suites (old, intentionally weakened ciphers that were once the only encryption technology allowed to be exported outside the United States). The group who discovered this exploit also recommended the usage of Elliptic Curve Diffie-Hellman, Ephemeral (ECDHE) as preferred ciphers for their resilience to all known cryptographic attacks. See [their site where you can test your server and get guidance on making these configuration changes](https://weakdh.org/sysadmin.html). Atlantic.Net’s world-class [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions and technical staff work around the clock, ensuring that our customers’ data is secure and private.   Please feel free to contact our staff and check our community and blog pages for any further updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Nginx on Fedora 22 > URL: https://www.atlantic.net/vps-hosting/how-to-install-nginx-fedora-22/ | Published: 2015-05-26 | Updated: 2026-01-15 | Author: Atlantic.Net NOC ##### Verified and Tested 05/20/15 ## Introduction We will walk you through the Nginx install on your Fedora 22 Server in this How-To. Nginx is an HTTP and reverse proxy server and mail proxy server. It is used on many well-known sites such as Netflix and WordPress. ## Prerequisites A cloud server with Fedora 22 already installed. If you do not have a server already, you can spin up a virtual private server in under 30 seconds. ## Installing NGINX in Fedora 22 To get started, log into your Fedora 22 via SSH or the VNC Console in cloud.atlantic.net. Atlantic.Net Cloud servers are set up as minimal installations to avoid having unnecessary packages from being installed and never used.  Because of this, let’s make sure that your server is fully up-to-date. ``` dnf update ``` With the server up-to-date, we can continue the installation process on your Fedora 22 server. Install NGINX with the following command: ``` dnf install nginx ``` Start the service with the following command: ``` systemctl start nginx ``` Configure NGINX to start when the system is rebooted: ``` systemctl enable nginx ``` You will also need to add the following firewall rules to let HTTP and HTTPS ports through the local firewall. Run the following commands to add them to the firewall: ``` firewall-cmd --set-default-zone=public firewall-cmd --permanent --zone=public --add-service=http firewall-cmd --permanent --zone=public --add-service=https firewall-cmd --reload ``` You can then check the status by running: ``` systemctl status nginx ``` You will now have NGINX installed on your server and can be verified by typing in the following with your IP ADDRESS on your browser. Also, all configuration files are provided on the page. Your IP could be retrieved from the server with the following command: ``` ifconfig ``` http :// ip.ad.dre.ss ![anet-Installing Nginx on Fedora 22](https://www.atlantic.net/wp-content/uploads/2018/01/Test-Page-for-the-Nginx-HTTP-Server-on-Fedora1.png) The default page You can now insert your site in the /usr/share/nginx/html directory. This is the default web directory. You have now completed installing Nginx on your Fedora 22 server. Come back and check for updates! Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Linux, Nginx, MariaDB And PHP (LEMP) On Fedora 22 > URL: https://www.atlantic.net/vps-hosting/how-to-install-lemp-fedora-22/ | Published: 2015-05-26 | Updated: 2026-01-15 | Author: Atlantic.Net NOC ##### verified and Tested 05/20/15 ## Introduction We will walk you through the LEMP install on your Fedora 22 Server in this How-To. LEMP is simply a software bundle that consists of 4 components. L (Linux) is the platform’s core, which will sustain the other components. E(Nginx)will be used for the web service. M(MariaDB)will be used for database management, and P(PHP) will be the programming language, making the platform a LEMP. ## Prerequisites A cloud server with Fedora 22 already installed (which will take care of the L(Linux) aspect of the LEMP install).  If you do not have a server, why not spin up a Fedora 22 server from Atlantic.Net in under 30 seconds? ## Installing NGINX in Fedora 22 Install NGINX with the following command: ``` dnf install nginx ``` Start the NGINX service with the following command: ``` systemctl start nginx ``` Configure NGINX to start when the system is rebooted: ``` systemctl enable nginx ``` You will also need to add the following firewall rules to let HTTP and HTTPS ports through the local firewall. Run the following commands to add them to the firewall: ``` firewall-cmd --set-default-zone=public firewall-cmd --permanent --zone=public --add-service=http firewall-cmd --permanent --zone=public --add-service=https firewall-cmd --reload ``` You can then check the status of nginx by running: ``` systemctl status nginx ``` You will now have NGINX installed on your server and can be verified by typing in the following with your IP ADDRESS on your browser. Also, all configuration files are provided on the page. If you do not know your IP address, you can use the following command to grab it: ``` ifconfig ``` You should get an output similar to this: ![anet-install-lemp-fedora22-01](https://www.atlantic.net/wp-content/uploads/2018/01/linux1-2.png) Using ifconfig to show ip address In this server, our ip address shows 10.10.250.58, so we would put in our browser, http ://10.10.250.58 and get the following page: ![anet-install-lemp-fedora22-02](https://www.atlantic.net/wp-content/uploads/2018/01/linux2-2.png) Nginx default page ## Installing MariaDB on Fedora 22 Install MySQL with the following command to begin the install: ``` dnf install mariadb-server ``` Start the service with the following command ``` systemctl start mariadb ``` To have MariaDB start on boot, run the following command: ``` systemctl enable mariadb ``` You can then check the status of MariaDB to ensure it is running by using the command: ``` systemctl status mariadb ``` Set the MariaDB root password and secure MariaDB with the following command: ``` mysql_secure_installation ``` First, you will be prompted for the MariaDB root password. Since we installed MariaDB and did not set a root password, you would leave it blank and press Enter. You will then be asked if you would like to set the root password. Enter ‘Y’ for yes, and then create a password of your choice. Note: Afterwards, you will be prompted with a series of questions. Type Y for yes on all of them. See the screenshot below: ![anet-install-lemp-fedora22-03](https://www.atlantic.net/wp-content/uploads/2018/01/linux3-2.png) Series of questions to secure MariaDB ## Installing PHP on Fedora 22 Install PHP with the following command to begin the install: ``` dnf install php php-mysql php-fpm ```   We will want to make a security configuration change in php.ini. Open php.ini with your text editor: ``` nano /etc/php.ini ``` You will need to search for the following line; cgi.fix_pathinfo=1. Once there, delete the semi-colon and change the value from ‘1’ to ‘0’. ![anet-install-lemp-fedora22-05](https://www.atlantic.net/wp-content/uploads/2015/05/2015-05-20-12_15_48-root@Fedora22LEMP_-e1635014815998.png) PHP.ini configuration file This change will ensure you are not a victim of a well-known exploit in the Nginx environment. This changes how PHP files are interpreted.   Start php-fpm with the following command: ``` systemctl start php-fpm ``` To make sure it starts on boot, run the following: ![anet-install-lemp-fedora22-04](https://www.atlantic.net/wp-content/uploads/2018/01/linux4-2.png) PHP.ini configuration file ``` systemctl enable php-fpm ``` To check the status and make sure php-fpm is running: ``` systemctl status php-fpm ``` We will need to restart Nginx before testing PHP with all the configuration changes. ``` systemctl restart nginx ``` Now we are ready to test everything. We will create a simple PHP script to test it all. The path to adding the php script is located in the same place as the index.html we saw when installing Nginx. The path is /usr/share/nginx/html/ . We will open a new file under this path called test.php by running the following command. ``` nano /usr/share/nginx/html/test.php ``` Insert the following code in the space: ``` ``` Save and exit. In your browser, navigate to http :// ip.ad.dre.ss/test.php, and you will see information for your PHP installation. ![anet-install-lemp-fedora22-05](https://www.atlantic.net/wp-content/uploads/2018/01/linux5-2.png) PHP information page Since you have tested PHP to be working, you will want to remove the test.php from your server, showing your PHP information publicly. ``` rm /usr/share/nginx/html/test.php ``` You can also view this detailed information of your PHP installation by running “php -i.” Congratulations! You have just installed LEMP on your Fedora 22 Server. Check back with us for any new updates! Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Apache on Fedora 22 > URL: https://www.atlantic.net/vps-hosting/how-to-install-apache-fedora-22/ | Published: 2015-05-26 | Updated: 2026-01-15 | Author: Jose Velazquez ##### Verified and Tested 05/26/15 ## Introduction This how-to will help you with your install and configuration of Apache on your Fedora 22 server. Apache is a web server that is very popular in Linux systems and over the Internet. It is used by many Web Hosting companies worldwide because of its popularity and efficiency in hosting sites over the World Wide Web. ## Prerequisites You need a Fedora 22 server configured with a static IP address. If you do not have a server already, you can visit our [VPS Hosting](https://www.atlantic.net/vps-hosting/) page and spin a new server up in under 30 seconds. ## Install Apache To get started, log into your Fedora 22 via SSH or the VNC Console in cloud.atlantic.net. Atlantic.Net Cloud servers are set up as minimal installations to avoid having unnecessary packages from being installed and never used.  Because of this, let’s make sure that your server is fully up-to-date. ``` dnf update ``` With the server up-to-date, we can continue the installation process on your Fedora 22 server. Install Apache with the following command: ``` dnf install httpd ``` Start Apache with the following command: ``` systemctl start httpd.service ``` You will want the Apache service to start on start-up/reboot with the following command: ``` systemctl enable httpd.service ``` Additionally, you must add the following commands in your Firewall-cmd to allow Apache through: ``` firewall-cmd --set-default-zone=public firewall-cmd --permanent --zone=public --add-service=http firewall-cmd --permanent --zone=public --add-service=https firewall-cmd --reload ``` Verify if all is working by typing http :// YOUR.IP.ADD.RESS Your IP could be retrieved from the server with the following command: ``` ifconfig ``` ![This is the default page after installing Apache in Fedora 22](https://www.atlantic.net/wp-content/uploads/2018/01/Install-Apache-in-Fedora-22.jpg) This is the default page after installing Apache in Fedora 22 ## What Next? With that, you now have a server installed and configured with Apache. You may now continue building your website. Thank you for following along, and feel free to check back with us for further updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install WordPress on a Fedora 22 Cloud Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-wordpress-fedora-22/ | Published: 2015-05-26 | Updated: 2026-01-15 | Author: Alexander Wise ##### Verified and Tested 05/25/15 ## Introduction This how-to will show you how to install WordPress on Fedora 22. WordPress started as a blogging system but has become a whole content management system (CMS). It is a free, open-source program, which has become the most popular CMS on the Web. With thousands of plugins, your website is nearly limitless. ## Prerequisite – A Fedora 22 server running LAMP or LEMP is required. Please see our how-tos for Fedora 22 [LAMP](https://www.atlantic.net/vps-hosting/how-to-install-lamp-fedora-32/) or [LEMP](https://www.atlantic.net/vps-hosting/how-to-install-lemp-fedora-22/). ## Creating The WordPress Database In MariaDB on Fedora 22 We are going to start by setting up the database  in MariaDB by running the following commands: ``` mysql -u root -p ``` When prompted, enter your MariaDB root password that you set up when installing MariaDB. In MariaDB, enter the following commands: (Make sure you set your secure password where it says [insert-password-here]) ``` create database wordpress character set utf8 collate utf8_bin; grant all privileges on wordpress.* to wordpressuser@localhost identified by '[insert-password-here]'; flush privileges; exit ``` The commands above create a WordPress database, a dbuser named wordpressuser with a password [insert-password-here]. You can modify these settings to your liking. ## Downloading And Unpacking The Latest WordPress Install on Fedora 22 Since we created the database, we can now move on to the next step of downloading the latest WordPress install by running the following command: ``` wget http://wordpress.org/latest.tar.gz ``` Note: if Wget is not installed, install it by running the command: ``` dnf install wget ``` Wget will download the compressed WordPress install in the directory that you are currently in. We now need to unpack it by running the command: ``` tar -xzvf latest.tar.gz ``` ## Configuring the WordPress Install on Fedora 22 wp-config.php is where WordPress gets its base configuration. We need to make a wp-config.php by copying wp-config-sample.php and creating a new file. To do that, run: ``` cp wordpress/wp-config-sample.php wordpress/wp-config.php ``` Next, we need to edit wordpress/wp-config.php. In this how-to, we will be using the text editor nano. ``` nano wordpress/wp-config.php ``` For a simple setup, we need to edit the following values: define(‘DB_NAME’, ‘wordpress’); define(‘DB_USER’, ‘wordpressuser’); define(‘DB_PASSWORD’, ‘[insert-password-here]’); It should look like this when completed: ![An image showing the styling for the WordPress db info](https://www.atlantic.net/wp-content/uploads/2015/05/wordpress1.png)   We now need to move the config files to the web directory. For LAMP, run the command: ``` sudo cp -r ~/wordpress/* /var/www/html ``` For LEMP, run the command: ``` sudo cp -r ~/wordpress/* /usr/share/nginx/html ``` ## Finishing The WordPress Install In The Web Installation on Fedora 22 We now can go to the web installation by going to http: //yourhostname-or-ipaddress in your browser. If you are unsure what your IP address is, run the following: ``` ifconfig ``` ![An example of ifconfig showing the IP address 192.169.0.15](https://www.atlantic.net/wp-content/uploads/2015/05/wordpress2.png) In the above example, we would put http://192.68.0.15/ in the browser address bar and get the following page.   ![An example of the WordPress web installation](https://www.atlantic.net/wp-content/uploads/2015/05/wordpress3.png)   Congratulations, you have installed WordPress on Fedora 22. Please check back for more updates. The next step is to follow the web installation by submitting your information. For more information, you may want to check out the [WordPress Codex](https://codex.wordpress.org/). ## Atlantic.Net Atlantic.Net offers [VPS hosting](https://www.atlantic.net/vps-hosting/) as well as managed hosting services which include a layer of business-essential managed services to your hosting packages. Contact us today for more information. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Apache, MariaDB, PHP (LAMP) on Fedora 32 > URL: https://www.atlantic.net/vps-hosting/how-to-install-lamp-fedora-32/ | Published: 2015-05-26 | Updated: 2026-01-15 | Author: Ernest Coleman ##### Verified and Tested 03/10/21 ## Introduction We will walk you through the LAMP install on your Fedora 32 Server in this How-To. With the many changes of Fedora 32, a typical LAMP install is different than you may have seen in the past.   Fedora 32 still uses Apache and MariaDB, PHP, although they are using slightly updated versions of each. ## Install Lamp on Fedora 32 To start, we need to make sure the system is updated. To do that, run the command: ``` dnf update ``` We are now able to start the installation for Apache. ## Install Apache on Fedora 32 Install Apache with the following command: ``` dnf install httpd ``` Now that Apache is installed, we need to start Apache with the following command: ``` systemctl start httpd.service ``` You will want the Apache service to start on start-up/reboot with the following command: ``` systemctl enable httpd.service ``` Add the following commands in Apache to override in Firewall-cmd as follows: ``` firewall-cmd --set-default-zone=public firewall-cmd --permanent --zone=public --add-service=http firewall-cmd --permanent --zone=public --add-service=https firewall-cmd --reload ``` You can now verify that Apache is installed correctly by typing http:// and your IP or hostname on your browser. > Note: If you do not know your IP address, run the following command: > > ``` > ip addr show eth0 > ``` > > ![An example of ip addr showing the IP of 192.168.100.10](https://www.atlantic.net/wp-content/uploads/2018/01/fedora1-3.png) > > An example of ip addr showing the IP of 192.168.100.10 > > In our example we would put `http://192.168.100.10` into our browser’s address bar. ** ** ![The default Apache page for Fedora 22](https://www.atlantic.net/wp-content/uploads/2018/01/fedora2.jpg) The default Apache page for Fedora 32   ## Installing MariaDB on Fedora 32 Install MySQL with the following command to begin the install: ``` dnf install mariadb-server ``` Start the service with the following command ``` systemctl start mariadb ``` To have MariaDB start on boot, run the following command: ``` systemctl enable mariadb ``` You can then check the status of MariaDB to ensure it is running by using the command: ``` systemctl status mariadb ``` Set the MariaDB root password and secure MariaDB with the following command: ``` mysql_secure_installation ``` First, you will be prompted for the MariaDB root password. Since we installed MariaDB and did not set a root password, you would leave it blank and press Enter. You will then be asked if you would like to set the root password. Enter ‘Y’ for yes, and then create a password of your choice. Note: Afterwards, you will be prompted with a series of questions. Just type Y for yes on all of them. See the screenshot below: ![An example of the mysql_secure_installation for MariaDB on Fedora 22](https://www.atlantic.net/wp-content/uploads/2018/01/fedora3-2.png) An example of the mysql_secure_installation for MariaDB on Fedora 32 ## Install PHP on Fedora 32 Finally, we will conclude the installing PHP with the following command: ``` dnf install php php-mysqli ``` Restart the Apache HTTP service, so the changes take effect. ``` systemctl restart httpd.service ``` To test and verify this installation, create a test PHP file in the directory below with the following command: ``` sudo nano /var/www/html/info.php ``` Insert the following PHP code in the space, then save and exit: ``` ``` Restart the Apache HTTP service one last time, so all the changes take effect. ``` sudo systemctl enable httpd.service ``` You can now verify that PHP is installed correctly by typing the following on your browser. http: //ip.ad.dre.ss/info.php ![Verify that PHP is installed correctly](https://www.atlantic.net/wp-content/uploads/2015/05/fedora-32-php-info.png) ## What Next? Congratulations! You now have a server with a LAMP platform for your web environment. Thank you for following along, and feel free to check back with us for further updates or check out our guide on [installing WordPress](https://www.atlantic.net/vps-hosting/how-to-install-wordpress-fedora-22/). Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # A Story About a HIPAA-Compliant Website & Mobile App > URL: https://www.atlantic.net/hipaa-compliant-hosting/healthcare-hosting-story-hipaa-compliant-website-and-mobile-app/ | Published: 2015-05-26 | Updated: 2026-01-15 | Author: Alexander Wise Dell strategist Jim Stikeleather has argued that big data projects should tell a story.  [He said](https://hbr.org/2013/04/how-to-tell-a-story-with-data/) that by thinking similarly to journalists, data scientists could frame and communicate the information and filters they want to explore more deliberately and captivatingly. Storytelling can assist with the understanding of any situation, particularly technology – which often can seem obtuse, boring, and inhuman.  People breathe life into technological situations – as when stories are told of people problem-solving using the tools of the technological era. Since HIPAA-compliant hosting is one of our specialties, let’s look at a recent interaction with a client interested in hosting a healthcare site and mobile application. **** Note that various details are changed for privacy, clarity, etc. **** ## **Healthcare Client:** Hello, I have a client that requires a [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) service.  The client has a website and an app.  The app is for end-users to upload images of their doctor bills.  The website is where billing specialists review their claims and tell them if they were billed incorrectly.  This is a startup company with unknown needs as far as server size.  I would assume it would only require a small server, but we want to scale up quickly if this company takes off.  My job is to investigate hosting companies and recommend one to our client, who will establish the account independently. ## **Hosting Consultant:** Thank you for contacting Atlantic.Net.  We need answers to the following questions to provide you with a formal proposal.  In the meantime, I have attached a copy of our BAA and HIPAA Audit that you can review. - Does your client require a Linux or Windows platform? - How many internal users will be accessing the hosting platform? - Will there also be a database hosted on the platform?  HIPAA regulations require that a database and an application are hosted on separate servers. - Is 1 TB of storage space enough? ## **Healthcare Client:** - It will be a Linux platform. - Internal meaning users that access the servers themselves – correct?  There would be 1 or 2 users responsible for updating the website and web services required for the iPhone app.  The client might want their own account also, although I don’t know for sure.  Are there additional costs associated with the number of authorized internal users? - Yes, there will be a database.  I understand HIPAA requires the database to be on a separate server.  Does this requirement mean it needs to be on a different physical server, or is virtual enough? - How quickly can the servers be scaled?  I think initially, 1TB would be enough.  Again, we don’t know if this might be wildly successful and will require scaling.  If that is needed, can you provide information on costs to scale to more ample Storage and machines? Lastly, what kind of timeline is required to set up the account and go live with it? ## **Hosting Consultant:** Thank you for the information.  Attached you will find the formal pricing proposal.  We include ( 5 ) encrypted VPNs, so your internal users are covered.  We need a dedicated server environment for the Storage.  However, we can separate the dedicated server into ( 2 ) Virtual Machines, and it still meets HIPAA requirements concerning the separation of the application and the database server.  This is built into our proposal. The dedicated server we provide can hold up to ( 4 ) hard drives.  We are starting with ( 2 ) hard drives in a RAID 1 configuration (HIPAA platforms require RAID).  We can add another ( 2 ) hard drives at any time (again in a RAID configuration ), and the SAS Encrypted Hard drives come in either a 1TB or 2 TB size.  The dedicated server can hold 32 GB of RAM, and we are starting with 16 GB of RAM.  We need the 16 GB of RAM to create the ( 2 ) virtual machines, and we have to allow for RAM overhead for the Hypervisor (we use KVM / Proxmox) on [Linux VPS](https://www.atlantic.net/vps-hosting/) Platforms.  You can add another 16 GB of RAM at any time.  If you need more resources than we can add to the one dedicated server, we would have to deploy a second dedicated server.  The firewall and intrusion system can support unlimited dedicated servers behind them. The platform will take 5 to 7 days to deploy from the time we receive a signed agreement.  I have attached the following supporting documents for your review: - Fully Managed Hardware Firewall - ( 5 ) Encrypted VPNs - Intrusion Detection System - Fully Managed Daily Backup. Thank you for permitting Atlantic.Net to provide your organization with a custom proposal for a [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) Platform.  Below are the highlights of our proposal.  Please get in touch with us if you have any questions. 1.) Fully Managed Hardware Firewall 2.) ( 5 ) Managed Encrypted VPNs 3.) Intrusion Detection System 4.) Fully Managed Daily Backup 5.) Private Dedicated Server Platform – Linux Centos OS 6.5 64 bit or Ubuntu 12.04 - 4 Virtual Core Processor - 16 GB of RAM - 1 TB of Encrypted RAIDed Storage - ( 2 ) Virtual Machines (Web and App) 6.) 10 TB of Monthly Data Transfer with a 100 Mbps Port 7.) 100% Uptime SLA 8.) cPanel w/ WHM 9.) Kapersky Anti-Virus 10.) 24 X 7 X 365 Live Technical Support by email / chat / phone 11.) Business Associate Agreement 12.) HIPAA Audited Data Center with SSAE SOC 2 Certification *$ XXXX per month on a 12-month agreement, with no setup fee.* ## **Healthcare Client:** It looks good, but I have a couple of questions.  What do items 6 and 7 refer to?  I am not completely up to speed on the terminology here.  The price quoted on the Linux HIPAA Compliant Hosting Platform: is this the price our customer would pay on what you have quoted?  Also, if we need to scale, how would that affect the quoted price? ## **Hosting Consultant:** - Item 6 is the amount of data transfer per month that the customer can use without charging overage bandwidth.  10 TB of monthly data transfer is equal to 33 Mbps of bandwidth.  The 100 Mbps port is the amount of bandwidth the customer can burst to at any given time.  We have large HIPAA customers, and no one ever exceeds the 10 TB of monthly data transfer.  If by some chance your customer does, the overage charge is xxx cents per month per GB. - Item 7 refers to the fact that we warrant the HIPAA hosting platform will stay up 100% of the time.  It also means that we are 100% responsible for all of the hardware that has been deployed to make the hosting platform work.  Hardware pricing for dedicated servers changes very rapidly.  I can only provide you with the monthly pricing if you added extra server resources today.  Each additional 8 GB of RAM is $ xx per month.  Each extra 1 TB SAS Encrypted hard drive is $ xxx per month (they have to be added two at a time because of the required RAID configuration on the hard drives).  Each extra 1 TB SAS Encrypted hard drive is $ xxx per month (they have to be added two at a time because of the required RAID configuration on the hard drives).  To add a second dedicated server to the hosting platform would be $ xxx per month (this server would have the same starting configuration as what is on the proposal I sent you). - The $ xxx per month is what your customer would pay without any upgrades to the dedicated server. ## **Healthcare Client:** One more question.  Where are the hosting centers? ## **Hosting Consultant:** We are in (5) data centers, but the HIPAA hosting platforms can only be hosted in our data center in Orlando, FL.  It is the only data center that has the HIPAA audit certification. ## **Healthcare Client:** Ok, I am recommending you to our client.  Thank you for your quick responses. ## **Partnering with HIPAA-Compliant Expertise** As you can see above, we are happy to answer all questions related to HIPAA Web Hosting plans.  [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) is a significant area of focus for us at Atlantic.Net, so our established expertise allows us to guide you toward the right decision. ***Contact us now to explore your options!*** By Moazzam Adnan --- # Format Guide for Atlantic.Net How-To Articles > URL: https://www.atlantic.net/vps-hosting/format-guide-atlantic-net-how-to-articles/ | Published: 2015-06-01 | Updated: 2026-01-15 | Author: Atlantic.Net NOC ## Introduction If you think you’d like to write for Atlantic.Net, you should start by completing our [signup form](https://www.atlantic.net/write/). How-to articles for Atlantic.Net should conform to the standards indicated in the sections below: Sections (including Introduction, Prerequisites, and the Tutorial itself) Format (Markdown or simple HTML) Images/Screenshots Original Work Please also review our [style guide](https://www.atlantic.net/vps-hosting/how-to-style-guide-atlantic-net-articles/) for additional guidance. ## Sections Each How-To article should begin with the Introduction section, which briefly describes the scope of the article. The word “Introduction” should be contained within H3 headers. Following Introduction should be Prerequisites, indicated with H3 headers. Prerequisites should include which operating system the article is relevant to, including appropriate distribution (e.g., “Ubuntu 14.04 and earlier” or “Windows Server 2012 and Windows Server 2012 R2”). You should also include packages, roles, or features required and whose installation, and this article will not cover configuration. Check to ensure that an article covering that installation/configuration exists and include a link. Example: (excerpted from [Install WordPress on a Fedora 22 Cloud Server](https://www.atlantic.net/vps-hosting/how-to-install-wordpress-fedora-22/).) > ### Prerequisite > > – A Fedora 22 server running LAMP or LEMP is required. Please see our how-tos for Fedora 22 [LAMP](https://www.atlantic.net/vps-hosting/how-to-install-lamp-fedora-32/) or [LEMP](https://www.atlantic.net/vps-hosting/how-to-install-lemp-fedora-22/).   The bulk of the article, the tutorial, follows the Prerequisites section. ## Format How-To articles for Atlantic.Net can be submitted in [Markdown](http://daringfireball.net/projects/markdown/basics) or simple HTML. Supported text formatting: header text, code blocks, inline code (for commands and keystrokes), italics (for variables), and bold (for emphasis).   ### Headers H2 should be used for major sections of the tutorial. H3 should be used for “Introduction,” “Prerequisites,” and subsections of the tutorial.   ### Code Blocks Any code that needs to be entered as part of the tutorial should be included in a code block.   In most cases, inline code will be used to explain variables or options that commands may take. If referencing code inline, you may use the `code` tag. This use should be confined to referring to a portion of code already included in a nearby code block. Example: > Be careful when using the `-r` option with `rm`. It recursively attempts to delete all files subordinate to the path you indicate.   ### Variable/custom information format Placeholders for variables or custom configuration entries (such as hostnames) should be italicized. Our parser will also tint all italicized entries *green*.   ### Emphasis If you’d like to indicate emphasis, use **bold**.   ### Keystrokes When it comes to referencing keystrokes inline with the text, enclose them in a `code span`. Example: > Press the `Enter` key. For keystrokes requiring multiple keys to be pressed simultaneously, use a plus sign (+) between keys. Example: > To exit, press `Ctrl+C`. > > To switch users, first press `Ctrl+Alt+Del`.   . ## Images How-to should include appropriate screenshots, showing such visual elements as where to click or what a screen should look like (such as a phpinfo page, for instance). Images should have a maximum width of 730 pixels. Please include a link to the image using the URL where it is currently hosted. Articles accepted for publication will have all associated images downloaded and hosted on our servers. Along with images, we require the following: **Image Name**: format `anet-articlename-##` (where the `##` is replaced by a number, e.g., `anet-how_to_install_lamp_debian_8-01`). **Alt-Text**: a brief description of the image in case it does not load. **Caption**: brief description appearing beneath the image. Any uniquely identifiable information should be obscured, preferably through the use of prominent placeholder names (such as “example.com” or “192.168.0.2”). ## Original Work All articles written for Atlantic.Net must be original works. If you’ve already written a particular tutorial elsewhere and would like to do something similar with us, then take this opportunity to improve upon your initial effort! Atlantic.Net will not tolerate plagiarism nor the re-use of previously existing work. Similarly, all images and screenshots should also be unique. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to: Style Guide for Atlantic.Net Articles > URL: https://www.atlantic.net/vps-hosting/how-to-style-guide-atlantic-net-articles/ | Published: 2015-06-01 | Updated: 2026-01-15 | Author: Atlantic.Net NOC We at Atlantic.Net are so pleased that you are interested in writing articles for us. We look forward to the partnership between us to help provide the information that will help empower people to go out there and make and do cool and exciting things with technology. So, before you jump in, please take a moment to review this style guide. It should give you an idea of the tone and direction we are looking for in the submissions we receive. If you want to know how to format your submission, please consult our format guides for [How-To](https://www.atlantic.net/vps-hosting/) and [What-Is](https://www.atlantic.net/vps-hosting/format-guide-atlantic-net-what-is-articles/) articles. ## Target Audience If you find yourself interested in writing technical articles, you are likely the sort to be excited about learning and sharing that learning. This attitude is the sort we share at Atlantic.Net and the sort we expect quite a number of our readers share as well. As learners, we often find that the more we learn, the more we realize how much more there is to learn (and how little we knew before). Combine that experience with our having to keep up with continual upgrades, innovations, and the introduction of new structures, languages, and applications, and it’s not surprising to see the need for all sorts of reference documents. From this perspective, we presume our readers are approaching us and the view we would like to remind our writers to write toward. Imagine that the reader of your article has experience in some other field of technology or computers than the one you are writing about. It may also help to remember what it was like when you were first learning about what you’re writing about. What was tricky, or what mistakes did you make? Put that experience to work! ## How’s and Why’s Of course, the bulk of any how-to article is the series of steps to follow to accomplish the task that is the subject of the article. In addition to the how’s, though, we would like to see an Atlantic.Net article also include some explanations of why. A strong how-to article will provide additional information about optional or recommended practices. For example, in an article demonstrating how to manage an Ubuntu server, one might suggest running updates in the following fashion: ``` sudo apt-get update && sudo apt-get upgrade ``` > *This line is a concatenation of two commands that could be run separately. The `&&` indicates that the command that follows it should be run after the command preceding it successfully completes. It’s possible to shorten this command sequence by one keystroke by using `;` (semicolon) instead of `&&`, but `;` indicates that the command that follows it should run regardless of whether the preceding command successfully completes. In this instance, this usage is not a best practice, since you want to be sure you successfully update with your package repositories before trying to install upgrades.* > > *Of course, if you are logged in as root, you would omit the `sudo`, though, while often convenient, it is also not a best practice to remain logged in as root.* ## Style An Atlantic.Net article should primarily be informative, but that doesn’t mean it has to be dry. We encourage our writers to cultivate a friendly, personal style while still focusing on conveying information. It would be best if you avoided slang and colloquialisms. And, since a significant portion of our readership is likely to be international and for whom English may not be the first language, we recommend against the use of idiom as well. Likewise, it would help to refrain from inserting your opinions into articles. Where there is room for interpretation or preference, you should acknowledge which portion represents a subjective point of view. Supplying a link or references that support the point of view, if reputable, will be acceptable. When in doubt, though, prune the subjective portions of an article. ## Grammar An informative article is only as effective as the language through which it conveys its information. If a reader can’t understand what you are saying, that reader will go elsewhere. As such, all submitted articles should adhere as closely as possible to English grammar and spelling standards. Submissions with significant issues with grammar or spelling will be returned for rewriting. We reserve the right to make edits in the case of minor problems with either. A program may fail or run less than optimally if written poorly. The same applies to text written with little care taken to the rules and syntax of grammar and spelling. Strive to write simply and concisely to avoid most language pitfalls. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Nginx, MySQL, PHP (LEMP) On Arch Linux > URL: https://www.atlantic.net/vps-hosting/how-to-install-nginx-mysql-php-lemp-arch-linux/ | Published: 2015-06-02 | Updated: 2026-01-15 | Author: Jose Velazquez ##### Verified and Tested 05/29/15 ## Introduction This how-to will help you with your LEMP installation in Arch Linux so that you can successfully run a high available solid platform for your web environment. LEMP is simply a software bundle that consists of 4 components that work together to form a powerful web server. Linux (**L**) is the platform’s core, which will sustain the other components. Nginx (**E**) is used for the web service. MySQL (**M**) is used for database management, and PHP (**P**) is used as the file programming language. ## Getting Started To get started, [log in to your Arch Linux server via SSH or through the VNC Console here](https://cloud.atlantic.net/?page=userlogin). Atlantic.Net Cloud servers are set up as minimal installations to avoid having unnecessary packages from being installed and never used. If some software packages that you’re used to using aren’t installed by default, feel free to install them as needed. Let’s start to make sure that your server is fully up-to-date. ``` sudo pacman -Syu ``` We can continue the process and install LEMP on your server with the server up-to-date. ## Install Nginx On Arch Linux We must first begin by installing Apache with the following command: ``` sudo pacman -S nginx ``` Start the Nginx service with the following command: ``` sudo systemctl start nginx.service ``` To edit the main Nginx configuration file for one or many websites according to your preference, they are configured in the following directory: ``` sudo nano /etc/nginx/nginx.conf ``` You can now verify that Apache is installed correctly by typing http:// and your IP address on your browser. http:// YOUR.IP.ADD.RESS (To get your servers IP Address, type the following command:) ``` curl -s icanhazip.com ``` ![This is the default page after Installing Nginx on a LEMP Stack Arch Linux Server](https://www.atlantic.net/wp-content/uploads/2018/01/nginx1-1.jpg) This is the default page after Installing Nginx on a LEMP Stack Arch Linux Server Restart the Nginx service so the changes can take effect on your system. ``` sudo systemctl restart nginx.service ``` ## Install MySQL **On Arch Linux** We then would like to continue by installing MySQL. However, in Arch Linux, MySql is replaced with MariaDB. So, after running the following MySql command, hit enter to select one, then Enter, then confirm your installation by tapping Enter. ``` sudo pacman -S mysql ``` After the install, you must run the following command to complete the installation fully. ``` mysql_install_db --user=mysql --basedir=/usr --datadir=/var/lib/mysql ``` Make sure that the MySql/MariaDB service is on with the following command before proceeding: ``` sudo systemctl start ``` `mysqld.service` To ensure the security of the default settings of MySQL/MariaDB, continue with the command below: ``` sudo mysql_secure_installation ``` Note: When prompted with “Enter current password for root,” hit enter for none then Y(Yes) to set the MYSQL password. You will then be prompted with a series of questions. Type Y for yes on all of them. See the screenshot below: ![This is the secure installation of screen when installing MySql on an Arch Linux LEMP Stack server](https://www.atlantic.net/wp-content/uploads/2018/01/nginx2-1.jpg) This is the secure installation of the screen when installing MySql on an Arch Linux LEMP Stack server ## Install PHP On Arch Linux Finally, we will conclude the LEMP Stack by installing PHP with the following command: ``` sudo pacman -S php-fpm ``` Make sure that PHP has started with the following command: ``` sudo systemctl start ``` `php-fpm.service` We must change the PHP configuration file to activate the specified LEMP module. enabled: ``` sudo nano /etc/php/php.ini ``` Using  the Ctrl+w in your text editor(nano), locate the following line and remove the semicolon to activate ``` ;extension=mysqli.so ``` Now we can configure the Nginx configuration file so that it can recognize PHP files. ``` sudo nano /etc/nginx/nginx.conf ``` The following instructions are crucial and must be completed so  PHP and Nginx work correctly. Locate the following line **#location ~ \.php$ {** using Ctrl+w, tap enter to create a space in between the # and paste the following code in between: ``` location ~ \.php$ { fastcgi_pass unix:/var/run/php-fpm/php-fpm.sock; fastcgi_index index.php; root /srv/http; include fastcgi.conf; } ``` Fantastic! You can now save the file and restart Nginx and PHP so all your configuration takes effect. ``` sudo systemctl restart nginx.service ``` To verify and test the installation, create a test PHP file in the following directory with the command below: ``` sudo nano /srv/http/info.php ``` Insert the following PHP code in the empty file, then save and exit: ``` ``` Restart the Apache HTTP service one last time, so all the changes will be affected. ``` sudo systemctl restart httpd.service ``` You can now verify that PHP is installed correctly by typing the following on your browser. http:// YOUR.IP.ADD.RESS/info.php ![This is the default page after installing PHP on a LEMP Stack Arch Linux server](https://www.atlantic.net/wp-content/uploads/2018/01/nginx3-1.jpg) After installing PHP on a LEMP Stack Arch Linux server, this is the default page. ## What Next? Congratulations! You now have a server with a LEMP Stack platform for your web environment. Thank you for following along, and feel free to check back with us for further updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Docker on Ubuntu 20.04 LTS > URL: https://www.atlantic.net/vps-hosting/how-to-install-docker-ubuntu-20-04-lts/ | Published: 2015-06-02 | Updated: 2026-01-15 | Author: Jose Velazquez ##### Verified and Tested 06/02/21 ## Introduction This how-to will help you with your Docker setup on Ubuntu 20.04 LTS so that you can successfully build, ship, and run distributed applications quickly and effectively via its own Docker Engine. With technology on the rise and the popularity of Apps quickly rising, docker is preferred by many system admins and developers to maximize their creativity in an App production environment. ## What Do You Need? You need a Ubuntu 20.04 LTS server configured with a static IP address. If you do not have a server already, you can visit our [VPS Hosting](https://www.atlantic.net/vps-hosting/) page and spin a new server up in under 30 seconds. ## Server Preparation To get started, [log in to your Ubuntu 20.04 LTS server via SSH or the VNC Console located here](https://cloud.atlantic.net/?page=userlogin). Atlantic.Net Cloud servers are set up as minimal installations to avoid having unnecessary packages from being installed and never used. If some software packages that you’re used to using aren’t installed by default, feel free to install them as needed. Let’s make sure that your server is fully up-to-date. ``` apt-get update -y ; apt-get upgrade -y ``` With the server up-to-date, we can continue the installation process on your server. ## Install Docker on Ubuntu 20.04 LTS We will begin by installing with the following: ``` sudo apt-get install docker.io ``` We must then make a symbolic link between the original location of the Docker installation so the program knows where to look for it. ``` sudo ln -sf /usr/bin/docker /usr/local/bin/docker ``` ``` sudo sed -i '$acomplete -F _docker docker' /etc/bash_completion.d/docker.io ``` Furthermore, If you would like to install the latest version on your system, we will need to install additional dependencies in the following order to ensure everything checks out. ``` sudo apt-get install apt-transport-https ca-certificates curl software-properties-common -y ``` ``` sudo curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add - ``` ``` sudo add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu focal stable" ``` ``` sudo apt-get update ``` ``` sudo apt-get install docker-ce -y ``` Finally, you can verify that the latest version of docker is installed with the following: ``` sudo docker --version ``` Once done, you can create your first container and test the installation: ``` sudo docker run -i -t ubuntu /bin/bash ``` ## What Next? Congratulations! You now have a server with a Docker platform for your developing app environment. Thank you for following along with this how-to! Check back with us for further updates and reliable [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Set Up CentOS 7 Server > URL: https://www.atlantic.net/vps-hosting/how-to-initial-centos-7-server-setup/ | Published: 2015-06-03 | Updated: 2026-01-15 | Author: Jose Velazquez ##### Verified and Tested 05/9/15 ## Introduction System CentOS 7 is very different than its older predecessors.  With any server, the primary goal should always be security.  Many users are victims of malicious infiltrations on their servers due to the lack of security boundaries established from the beginning.  Let us begin on the right path by laying our foundation with security.  This how-to will help you with your initial setup on CentOS 7 so that you can successfully secure your server while giving you peace of mind knowing your server is protected. ## What Do You Need? You need a CentOS 7 server configured with a static IP address.  If you do not have a server already, consider a top-quality server from Atlantic.Net and be up in under 30 seconds. ## Server Preparation To get started, [log in to your CentOS 7 server via SSH or the VNC Console located here](https://cloud.atlantic.net/?page=userlogin).  Atlantic.Net Cloud servers are set up as minimal installations to avoid having unnecessary packages from being installed and never used.  If some software packages that you’re used to using aren’t installed by default, feel free to install them as needed. Let’s make sure that your server is fully up-to-date. ``` yum update ``` We can continue the process and secure your server with the server up-to-date. ## Update the CentOS 7 Root Password By default, your Atlantic.Net servers are automatically set with secure passwords.  However, we still recommend updating your password after creating your server and every 60-90 days after that to ensure it remains secure.  A minimum of 8 characters, including lowercase, uppercase, and numbers, are recommended to increase the level of security. Type the following command to activate your request and follow the on-screen instructions to update/confirm your root password: ``` passwd ``` ## Create a new user with sudo privileges After successfully updating your password, it’s recommended that you create a new user with sudo/root permissions.  Since the typical admin user for many Linux Operating Systems like CentOS 7  is “root,” we will make a new admin user that will be used for day-to-day administration tasks.  Creating a new user with root permissions will increase the security of your server is accessed.  Unwanted users target the root user because they know it’s the default admin user. Still, when you create a new user with sudo/root permissions and then disable the default root user, they will never know what user to log in with. Type the following command to create your new user replacing “user1” with your username, and confirm. ``` adduser user1 ``` Create a password for that user by typing the following command to activate your request and following the on-screen instructions to update/confirm your “user1” password: ``` passwd user1 ``` Once you have created a new user and the password, it is time to add the user to the sudo wheel group.  In CentOS 7, once you add them to the sudo wheel group, they are automatically assigned sudo/root permissions.  Run the following command to add the user to the sudo wheel group. ```  gpasswd -a user1 wheel ``` Finally, when you have created the user with sudo/root permissions,  you can exit your session and log back in with your “user1” to verify the changes made.  Alternatively, you can run the following command and switch users from root to “user1,” which will ask you for that user’sser’sword. ``` su - user1 ``` ## Configure SSH Access Port 22 is the default port for remote connections via SSH in Linux systems.  By changing the ssh port, you will increase the security of your server in preventing brute force attacks and unwanted users from reaching your server using the default port.  For this tutorial, I will use Port 5022 as an example. Open your SSH Configuration file, find the Port line, remove the # and change 22 number to your Custom port. Save and exit. ``` sudo vi /etc/ssh/sshd_config ``` ``` #Port 22 Port 5022 ``` For your system to update the settings from the SSH Configuration file, we must restart sshd. ``` sudo systemctl restart sshd.service ``` SSH has now been configured to use Port 5022, and if you attempt to login using Port 22, your l  gin will fail.  However, do not exit your session as we need to configure the custom port on the firewalls configuration part first, which we will configure in the upcoming steps. ## Limit Root Access Since we’ve vetted a new user with root permissions and created a custom ssh port, keep the actual root user available and vulnerable over SSH  on your server.  Let us restrict the root user’s access to the local server and grant permission to the new user over SSH only. Open the SSH Configuration file, find the PermitRootLogin line, remove the # and change it from yes to no. ``` sudo vi /etc/ssh/sshd_config ``` ``` #PermitRootLogin yes PermitRootLogin no ``` For your system to update the new settings in the SSH Configuration file, we must restart the sshd service. ``` sudo systemctl restart sshd.service ``` Note: You will now have the root user disabled in making those changes, so you must log in to your server with the “user “hat” you created.  However, do not exit your session; we must configure the custom port on the firewall in the upcoming steps. ## Create a Private SSH Key **Private/Public SSH Keys** are great additional features that increase security in a server’s method.  However, it takes a bit more effort to set up.  The question is, Is your server worth the extra security?  If you want to implement the following security features, you can continue with the next steps.  Let us proceed and generate the SSH Key. ``` ssh-keygen ``` If you want to change the location where the SSH Key will be saved,  you can specify it here.  However, the default location where it’s stored should be OK.  Press enter when prompted with the following question, then enter a passphrase, unless you don’t want one. ``` Enter file in which to save the key (/home/user1/.ssh/id_rsa): ``` ![This is the default page when installing SSH Keys on a CentOS 7 server](https://www.atlantic.net/wp-content/uploads/2018/01/setup1.jpg) Configuring the SSH Key is crucial. We must copy the entire key string to a  Word/ Notepad Document.  The Key can be viewed in the following location with the cat command. ``` cat ~/.ssh/id_rsa.pub ``` Copy the SSH key, beginning with ssh-rsa and ending with user1@yourserver, into a Word/ Notepad document to add it to the config file later on. ``` ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDNcnc3pMOytM7xgwZHUX0Wi/O78hDvLUmQVtKn8Qk1ijBY82jVftKXKRhf8toNkgm9jaZmfapLa7ynzUG4jbFjyy8H+iEs1R8P7eu+e8/fmGwjorbMFuWdoi7h2CldoqKTdMEb/dMNxjNMzBbovl3XtZviQGm4/TMVO1hHxy85JR8zAtNFu7liaP7IonexNrOGhY8CjqRcBsceQLkl1MlX7cWaWAMqd6jQnAvggTLerI9P286AP8Sk4uColj7GKOljj8X6J/2pcjp9v2IvJOqwC/zLwUKZ6qTEV6SrfdbjopoCVvpXkVhmcbHX5Xv1gwynO+vTkpPFwVTjSnAai71L jose@JVHServer ``` Once the SSH Key is stored safely, the directory for the SSH Keys needs limited permissions, which only the owner can read, write and execute the file. ``` chmod 700 .ssh ``` Within the SSH directory, a file containing the SSH Key must be added, simply using your editor (in this case VI) the following location: ``` vi .ssh/authorized_keys ``` Paste the SSH Key, then save and exit using the VI format. Finally, we have to limit the permissions of the authorized_keys file that we just created so only the owner can read and write. ``` chmod 600 .ssh/authorized_keys ``` We could now verify that the key is working by closing the session and typing user1@YOUR.IP.ADD.RESS or your servers hosted in your SSH Console. [Furthermore, you can click “here” to” ee our How To Generate and Use SSH Keys article for more information.](https://www.atlantic.net/vps-hosting/how-to-generate-use-ssh-key-using-putty/) ## Basic Firewall Rules By default, your Atlantic. Net’sNet’sOS 7 Server is loaded with a default firewall named **firewalld``**which uses the **firewall``-cmd**to configure its rules.  We must first start the Firewall service with the following: ``` sudo systemctl start firewalld ``` Next, we will add a rule to allow the custom SSH Port 5022 that was created earlier to access the server publicly.  At the same time, we will remove the previous default rule allowing SSH access on TCP/22. ``` sudo firewall-cmd --permanent --add-port=5022/tcp ``` ``` sudo firewall-cmd --permanent --remove-service=ssh ``` If you have a web server, you may want to allow the following rules to access your sites over the internet. ``` sudo firewall-cmd --permanent --add-service=http sudo firewall-cmd --permanent --add-service=https ``` You can use this for similar rules related to any systems you want to be publicly accessible.  This test server is set up to host a website and email services, so in addition to the updated SSH  and HTTP(S) rules, additional rules for secure POP3, IMAP, and SMTP have been added. ``` sudo firewall-cmd --permanent --add-service=pop3s sudo firewall-cmd --permanent --add-service=imaps sudo firewall-cmd --permanent --add-service=smtp ``` For Firewalld to accept those settings, you must restart the firewall. ``` sudo firewall-cmd --reload ``` Your settings will have been saved, and you are ready to proceed. To verify all the services/ports that are available, run the following: ``` sudo firewall-cmd --permanent --list-all ``` ![This is the default page after configuring the Firewalld rules on a CentOS 7 server](https://www.atlantic.net/wp-content/uploads/2018/01/setup2.jpg) ## NTP Time Sync The NTP (Network Time Protocol) is used to synchronize the time and date of computers over the network to remain accurate and up to date.  Let us begin by installing the NTP(If it hasn’t been installed) and configuring the service to synchronize with their servers. ``` sudo yum install ntp ``` Once the NTP service is installed, we need to ensure that the service is ON. ``` sudo systemctl start ntpd ``` Now that the service has started, let’s enable the NTP server to update the servers from the NTP server constantly. ``` sudo systemctl enable ntpd ``` ## Add Swap File A Swap file is simply a tiny amount of space created on a server hard drive to simulate Ram.  If the server is running low on memory, it will look at the hard drive and ease the load tricking the system into thinking it has more memory.  We will set up the swap file on the hard drive to increase the server’s performance just a little bit more. Begin by checking your resources to make sure we can add the file.  When you run the following command, you will see the percentage space on your Hard drive that is currently being used. ``` df -h ``` When creating a Swap file, you usually want to add half of your existing RAM up to 4GB(If you have 1GB of actual  Ram, you add a 512MB file).  In this part, I will be adding a 512MB swap file to the drive.  The way that this is calculated is by 1024 x 512MB = 524288 block size. ``` sudo dd if=/dev/zero of=/swapfile bs=1024 count=524288 ``` Now that we have added a swap file, an area needs to be created to proceed. ``` sudo mkswap /swapfile ``` With the Swap file created and the Swap file area added, we can add permissions to the file so that only the owner can read and write. ``` sudo chown root:root /swapfile sudo chmod 0600 /swapfile ``` Now that the swap file has the appropriate permissions, we can go ahead and activate it. ``` sudo swapon /swapfile ``` You can verify your newly added Swap file with the following. ``` sudo swapon -s ``` To make the Swap file always active even after a reboot, we must configure it accordingly. ``` sudo vi /etc/fstab ``` Paste the following command at the bottom of the file, save your work, and exit. ``` /swapfile swap swap defaults 0 0 ``` Finally, verify if your swapfile is activated by typing the following command: ``` free -m ``` ![This is the default page after creating a Swap File on a CentOS 7 Server](https://www.atlantic.net/wp-content/uploads/2018/01/setup3.jpg) ### What Next? With that, you now have a server with a strong security foundation, giving you peace of mind knowing that your server is protected.  You may now proceed with building your platform according to your needs.  Thank you for following along, and feel free to check back with us for further updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # Format Guide for Atlantic.Net What-Is Articles > URL: https://www.atlantic.net/vps-hosting/format-guide-atlantic-net-what-is-articles/ | Published: 2015-06-04 | Updated: 2026-01-15 | Author: Atlantic.Net NOC ## Introduction If you think you’d like to write for Atlantic.Net, you should start by completing our [signup form](https://www.atlantic.net/write/) if you haven’t already. What Is articles for Atlantic.Net should conform to the standards indicated in the sections below: Sections (including Introduction, Target Audience, and the Tutorial itself) Format (Markdown or simple HTML) Images/Screenshots Original Work Please also review our [style guide](https://www.atlantic.net/vps-hosting/how-to-style-guide-atlantic-net-articles/) for additional guidance. ## Sections Each What-Is article should begin with the Target Audience section, indicated with H5 headers. Target Audience should specify what level of experience or knowledge you assume the reader should possess to understand the topic you will be writing about. The minimum experience level for the Target Audience of a What-Is article should be entry-level IT professionals. Any topics that assume a reader is familiar with the material covered in another Atlantic.Net article can be linked here. Example: > ### Target Audience > > This article assumes you are familiar with the basic concepts behind the Public Key Infrastructure (PKI). For a refesher, check out this [primer on the basics of public key cryptography](https://www.atlantic.net/vps-hosting/what-is-public-key-cryptography-vpn-part-2/).   After the Target Audience should be the Introduction section, which briefly describes the scope of the article. The word “Introduction” should be contained within H3 headers. The bulk of the article follows the Introduction.   ## Format What-Is articles for Atlantic.Net can be submitted in [Markdown](http://daringfireball.net/projects/markdown/basics) or simple HTML. Supported text formatting: header text, code blocks, inline code (for commands and keystrokes), italics (for variables), and bold (for emphasis).   ### Headers H1 should be used for the title of the article. The title should always be the first part of any article. H2 should be used for significant sections of the article. H3 should be used for “Introduction,” “Target Audience,” and subsections.   ### Code Blocks What-Is articles should avoid using code or code blocks (this usage is more prevalent in a How-To article). However, if you highlight what code related to your topic looks like, it should be enclosed in a code block.   If referencing code inline, you may use the `code` tag. This use should be confined to referring to a portion of code whose form or function is relevant to the topic. Bear in mind that the goal of most What-Is articles is not to teach someone how to accomplish a task but to explain in a more general sense a concept related to technology. Example: > The common heritage of UNIX that many subsequent operating systems share is evident in some of the commands that they all share, such as `cp` for copy.   ### Variable/custom information format Variables or host-specific information should be rare in a What-Is article. However, variables or custom configuration entries (such as hostnames) should be italicized if the need arises. Our parser will also tint all italicized entries *green*.   ### Emphasis If you’d like to indicate emphasis, use **bold**.   ### Keystrokes When it comes to referencing keystrokes inline with the text, enclose them in a `code span`. Again, this sort of inclusion should be infrequent in a What-Is article. Example: > The `Enter` key may still be called the `Return` key on some keyboards, harkening back to its usage on typewriters to indicate a carriage return. For keystrokes requiring multiple keys to be pressed simultaneously, use a plus sign (+) between keys. Example: > The keystroke combination of `Ctrl+Alt+Del` gained, in some circles, the moniker of “the three-finger salute”.   ## Images We encourage using images and screenshots to help illuminate many of the points that may be brought up in a What-Is topic. Images should have a maximum width of 730 pixels. You may create the image yourself or use an image that is licensed for reuse under a license such as Creative Commons, for instance. Please include a link to the image using the URL where it is currently hosted. Articles accepted for publication will have all associated images downloaded and hosted on our servers. Along with images, we require the following: **Image Name**: format `anet-articlename-##` (where the `##` is replaced by a number, e.g., `anet-what_is_a_vpn-01`). **Alt-Text**: a brief description of the image if it does not load. **Caption**: a brief description appearing beneath the image. **Attribution**: if using an image licensed for reuse, including the appropriate attribution information (title, author, source, license, etc.) Any uniquely identifiable information should be obscured, preferably through the use of prominent placeholder names (such as “example.com” or “192.168.0.2”).   ## Original Work All articles written for Atlantic.Net must be original works. Atlantic.Net will not tolerate plagiarism or the reuse of previously existing work. Similarly, all images and screenshots should also be unique, excepting those images whose use properly abides by an appropriately attributed license. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to: Initial Fedora 21 Server Setup > URL: https://www.atlantic.net/vps-hosting/how-to-initial-fedora-21-server-setup/ | Published: 2015-06-04 | Updated: 2026-01-15 | Author: Jose Velazquez ##### Verified and Tested 05/12/15 ## Introduction With any server, the primary goal should always be security. Many users are victims of malicious infiltrations on their servers due to the lack of security boundaries established from the beginning. Let us begin on the right path by laying our foundation with security. This how-to will help you with your initial setup on Fedora 21 so that you can successfully secure your server while giving you peace of mind knowing your server is protected. ## What Do You Need? You need a Fedora 21 server configured with a static IP address. If you do not have a server already, consider a cost-effective server from Atlantic.Net and be up in 30 seconds. ## Server Preparation To get started,[log in to your Fedora 21 server via SSH or the VNC Console located here](https://cloud.atlantic.net/?page=userlogin). Atlantic.Net Cloud servers are set up as minimal installations to avoid having unnecessary packages from being installed and never used. If some software packages that you’re used to using aren’t installed by default, feel free to install them as needed. Let’s make sure that your server is fully up-to-date. ``` yum update ``` We can continue the process and secure your server with the server up-to-date. ## Update the Fedora 21 Root Password By default, your Atlantic.Net servers are automatically set with secure passwords. However, we still recommend updating your password after creating your server and every 60-90 days after that to ensure it remains secure. A minimum of 8 characters, including lowercase, uppercase, and numbers, are recommended to increase the level of security. Type the following command to activate your request and follow the on-screen instructions to update/confirm your root password: ``` passwd ``` ## Create a new user with sudo privileges After successfully updating your password, it’s recommended that you create a new user with sudo/root permissions. Since the typical admin user for many Linux Operating Systems like Fedora 21 is “root,” we will make a new admin user that will be used for day-to-day administration tasks. Creating a new user with root permissions will increase the security of the way your server is accessed. Individuals looking to target your system will target the root user because it’s known to be the default admin account. By creating a new user with sudo/root permissions and disabling the root user, you are increasing security by using a user that isn’t already publicly known. Type the following command to create your new user replacing “user1” with your username, and confirm. ``` adduser user1 ``` Create a password for that user by typing the following command to activate your request and following the on-screen instructions to update/confirm your “user1” password: ``` passwd user1 ``` Once you have created a new user and created the password for that user, it is time to add the user to the sudo wheel group. In Fedora 21, once you add them to the sudo wheel group, they are automatically assigned sudo/root permissions. Run the following command to add the user to the sudo wheel group. ``` gpasswd -a user1 wheel ``` Finally, when you have created the user with sudo/root permissions,  you can exit your session and log back in with your “user1” to verify the changes made. Alternatively, you can run the following command and switch users from root to “user1,” which will ask you for that user’s password. ``` su - user1 ``` ## Configure SSH Access Port 22 is the default port for remote connections via SSH in Linux systems. By changing the ssh port, you will increase the security of your server in preventing brute force attacks and unwanted users from reaching your server using the default port. For this tutorial, we will use Port 5022 as an example. Open your SSH Configuration file, find the Port line, remove the # and change 22 number to your Custom port. Save and exit. ``` sudo vi /etc/ssh/sshd_config ``` ``` #Port 22 Port 5022 ``` For your system to update the settings from the SSH Configuration file, we must restart the sshd service. ``` sudo systemctl restart sshd.service ``` SSH has now been configured to use Port 5022, and if you attempt to login using Port 22, your login will fail. However, do not exit your session as we need to configure the custom port on the firewalls configuration part first, which we will configure in the upcoming steps. ## Limit Root Access Since we’ve created a new user with root permissions and made a custom ssh port, there’s no need to keep the actual root user available and vulnerable over SSH on your server. Let us restrict the root user’s access to the local server and grant permission to the new user over SSH only. Open the SSH Configuration file, find the PermitRootLogin line, remove the # and change it from yes to no. ``` sudo vi /etc/ssh/sshd_config ``` ``` #PermitRootLogin yes PermitRootLogin no ``` For your system to update the new settings in the SSH Configuration file, we must restart the sshd service. ``` sudo systemctl restart sshd.service ``` Note: You will now have the root user disabled in making those changes, so you must log in to your server with the “user1” that you created. However, do not exit your session. We must configure the custom port on the firewall in the upcoming steps. ## Create a Private SSH Key **Private/Public SSH Keys** are great additional features that increase security in a server’s method. However, it takes a bit more effort to set up. The question is, Is your server worth the extra security? If you want to implement the following security features, you can continue with the next steps. Let us proceed and generate the SSH Key. ``` ssh-keygen ``` If you want to change the location where the SSH Key will be saved,  you can specify it here. However, the default location where it’s stored should be OK. Press enter when prompted with the following question, then enter a passphrase, unless you don’t want one. ``` Enter file in which to save the key (/home/user1/.ssh/id_rsa): ``` ![This is the default webpage when installing SSH Keys on a Fedora21 server](https://www.atlantic.net/wp-content/uploads/2018/01/fedora1.jpg) This is the default webpage when installing SSH Keys on a Fedora21 server Configuring the SSH Key is crucial. We must copy the entire key string to a Word/ Notepad Document. The Key can be viewed in the following location with the cat command. ``` cat ~/.ssh/id_rsa.pub ``` Copy the SSH key, beginning with ssh-rsa and ending with user1@yourserver, into a Word/ Notepad document to add it to the config file later on. ``` ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDbFd5OZFm8qDh21f28igkEVVb0rwkvyvxpH+LX9FBIgLfXTYZRz8PhCUi6NtugZMJ3F9vwq4Cq3zTYuwqhdb4Nt8z8MiS6sKX8JpgLyKreEwaxfK9IKBskyAkpln7zc7bHVCYsTJsvr/1B7kTvX4jIa0/EJQS7xvCTGdMDOD+Ux7bGJiA8ohc4DfELfJnlcURfNwB3PZ5ukdoul7/+yeabRsj18rc0yZfJ3/MgaipdSTwK/2mpaR0xlKGQhj47FsERKu6rztBL5lIQXWWZK71L8O2aprgsBBP+G2lKVKNNXeBfd+4Kx+4D980mWZlEdZ8KfgOZqCMXF3Jfjqcpvf0D user1@JVHServer ``` Once the SSH Key is stored safely, the directory for the SSH Keys needs limited permissions that only the owner can read, write and execute the file. ``` chmod 700 .ssh ``` Within the SSH directory, a file containing the SSH Key must be added, simply using your editor (in this case VI) the following location: ``` vi .ssh/authorized_keys ``` Paste the SSH Key, then save and exit using the VI format. Finally, we have to limit the permissions of the authorized_keys file that we just created so only the owner can read and write. ``` chmod 600 .ssh/authorized_keys ``` We could now verify that the key is working by closing the session and typing user1@YOUR.IP.ADD.RESS or your server’s hostname in your SSH console.[Furthermore, you can click “here” to see our How To Generate and Use SSH Keys article for more information.](https://www.atlantic.net/vps-hosting/how-to-generate-use-ssh-key-using-putty/) ## Basic Firewall Rules By default, your Atlantic.Net’s Fedora 21 Server is loaded with a default firewall named **firewalld``**that uses the **firewall``-cmd**to configure its rules. We must first start the Firewall service with the following: ``` sudo systemctl start firewalld ``` Next, we’re going to add a rule to allow the custom SSH Port 5022 that was created earlier to access the server publicly. At the same time, we will remove the previous default rule allowing SSH access on TCP/22. ``` sudo firewall-cmd --permanent --add-port=5022/tcp ``` ``` sudo firewall-cmd --permanent --remove-service=ssh ``` If you have a web server, you may want to allow the following rules to access your sites over the internet. ``` sudo firewall-cmd --permanent --add-service=http sudo firewall-cmd --permanent --add-service=https ``` You can use this for similar rules related to any systems you want to be publicly accessible. This test server is set up to host a website and email services, so in addition to the updated SSH  and HTTP(S) rules, additional rules for secure POP3, IMAP, and SMTP have been added. ``` sudo firewall-cmd --permanent --add-service=pop3s sudo firewall-cmd --permanent --add-service=imaps sudo firewall-cmd --permanent --add-service=smtp ``` For Firewalld to accept those settings, you must restart the firewall. ``` sudo firewall-cmd --reload ``` Your settings will have been saved, and you are ready to proceed. To verify all the services/ports that are available, run the following: ``` sudo firewall-cmd --permanent --list-all ``` ![This is the default webpage after completing the Firewalld rules on a Fedora21server](https://www.atlantic.net/wp-content/uploads/2018/01/fedora2-1.jpg) This is the default webpage after completing the Firewalld rules on a Fedora21server ## NTP Time Sync The NTP (Network Time Protocol) is used to synchronize the time and date of computers over the network to remain accurate and up to date. Let us begin by installing the NTP(If it hasn’t been installed) and configuring the service to synchronize with their servers. ``` sudo yum install ntp ``` Once the NTP service is installed, we need to ensure that the service is ON. ``` sudo systemctl start ntpd ``` Now that the service has started, let’s enable the NTP server to update the server’s time from the NTP server constantly. ``` sudo systemctl enable ntpd ``` ## Add Swap File A Swap file is simply a tiny amount of space created on a server hard drive to simulate RAM. If the server is running low on memory, it will look at the hard drive and ease the load tricking the system into thinking it has more memory. We will set up the swap file on the hard drive to increase the server’s performance just a little bit more. Begin by checking your resources to make sure we can add the file. When you run the following command, you will see the percentage space on your Hard drive that is currently being used. ``` df -h ``` When creating a Swap file, you usually want to add half of your existing RAM up to 4GB(If you have 1GB of actual Ram, you add a 512MB file). In this part, I will be adding a 512MB swap file to the drive. The way that this is calculated is by 1024 x 512MB = 524288 block size. ``` sudo dd if=/dev/zero of=/swapfile bs=1024 count=524288 ``` Now that we have added a swap file, an area needs to be created to proceed. ``` sudo mkswap /swapfile ``` With the Swap file created and the Swap file, area added we could go ahead and add permissions to the file so that only the owner can read and write. ``` sudo chown root:root /swapfile sudo chmod 0600 /swapfile ``` Now that the swap file has the appropriate permissions, we can go ahead and activate it. ``` sudo swapon /swapfile ``` You can verify your newly added Swap file with the following. ``` sudo swapon -s ``` To make the Swap file always active even after a reboot, we must configure it accordingly. ``` sudo vi /etc/fstab ``` Paste the following command at the bottom of the file, save your work, and exit. ``` /swapfile swap swap defaults 0 0 ``` Finally, verify if your swapfile is activated by typing the following command: ``` free -m ``` ![This is the default page after creating a Swap File on a Fedora21 Server](https://www.atlantic.net/wp-content/uploads/2018/01/fedora3.jpg) This is the default page after creating a Swap File on a Fedora21 Server ### What Next? With that, you now have a server with a strong security foundation that will give you peace of mind knowing that your server is protected. You may now proceed to build your platform according to your needs. Thank you for following along, and feel free to check back with us for further updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to set up a TeamSpeak server on CentOS 7 > URL: https://www.atlantic.net/vps-hosting/how-to-set-teamspeak-server-centos-7/ | Published: 2015-06-04 | Updated: 2026-01-15 | Author: Michael Douse ##### Verified and Tested 04/02/21 ## Introduction This article will go over how to set up a TeamSpeak (v3) server on a freshly provisioned CentOS 7 cloud server. ## Prerequisites -You will need to provision a CentOS 7 (32 bit or 64 bit) server. -SFTP Client such as WinSCP. ## Install TeamSpeak on CentOS 7 First, we will need to download the TeamSpeak Server files.[You can find them here](http://www.teamspeak.com/?page=downloads). Make sure to choose the correct architecture (x86 for 32-bit, amd64 for 64-bit): ![TeamSpeak Server files](https://www.atlantic.net/wp-content/uploads/2015/06/teamspeak-1024x451.png) Next, we will download an SFTP client to transfer the TeamSpeak Server file to our cloud server. [You can download WinSCP from HERE](http://winscp.net/eng/download.php). You can choose either the installation package or the portable version. ![Download WinSCP](https://www.atlantic.net/wp-content/uploads/2018/01/team2.png) Download WinSCP   --- Now to open up the required ports in the firewall. These are the default ports we will open: > UDP: 9987 – Default voice port. > TCP: 10011 – Default file transfer port. > TCP: 30033 – Default server-query port.   You can allow all those ports using the following command: ``` firewall-cmd --permanent --zone public --add-port 10011/tcp firewall-cmd --permanent --zone public --add-port 30033/tcp firewall-cmd --permanent --zone public --add-port 9987/udp ``` Once you are done,  reload the firewall service to apply the changes: ``` firewall-cmd --reload ``` That’s it for the firewall configuration. ---   Time to create a separate user for the TeamSpeak server. Call this user whatever you wish, but for the sake of this how-to, I will be using “ts3srv”: ``` useradd ts3srv passwd ts3srv ``` Now change to the home folder of the user we just created: ``` su ts3srv cd ``` At this point, we will need to upload the TeamSpeak server package we downloaded earlier. Open WinSCP and type your server IP in the “Hostname” input box along with the ts3srv username and password you chose. Then click on “Login”: ![WinSCP - Connect to your server.](https://www.atlantic.net/wp-content/uploads/2018/01/team5.png) WinSCP – Connect to your server. * Note: The first time you connect to your server, you will receive a warning that the host is unknown. Don’t worry, click “Yes” to accept the host key.* ![Host Key Warning - WinSCP](https://www.atlantic.net/wp-content/uploads/2018/01/team6.png) Host Key Warning – WinSCP Once you are connected, you will be dropped into the home directory of the ts3srv user we created. Just drag and drop the file we downloaded into the main window: ![Upload TeamSpeak server package.](https://www.atlantic.net/wp-content/uploads/2018/01/team7.jpg) Upload TeamSpeak server package. --- Time to install the package: ``` tar -xjf teamspeak3-server_linux_amd64-3.13.3.tar.bz2 ``` ``` cd teamspeak3-server_linux_amd64 ``` *Note: Your command may be slightly different depending on the version you downloaded or chose the 32-bit version.* Now, start the TeamSpeak server with the following command. ``` ./ts3server_startscript.sh start license_accepted=1 ``` *WARNING: Make sure to copy down all information that is shown. It WILL NOT be shown again.* Once you copy down the Server Query Admin Account password and the ServerAdmin privilege key, you can hit CTRL + C to exit out. The server will remain running in the background. --- Now open up your TeamSpeak client and join your server! You will need the password and privilege key that you should have copied down in the previous step: ![Connect to your TeamSpeak server](https://www.atlantic.net/wp-content/uploads/2018/01/team10.png) Connect to your TeamSpeak server   That’s it!  Now go ahead and edit the default channel and start adding new channels. Once you are ready, give your clients the IP address of the server to connect. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to: Initial Ubuntu 15.04 Server Setup > URL: https://www.atlantic.net/vps-hosting/how-to-initial-ubuntu-15-04-server-setup/ | Published: 2015-06-05 | Updated: 2024-06-10 | Author: Jose Velazquez ##### Verified and Tested 05/9/15 ### Introduction With any server, the primary goal should always be security. Many users are victims of malicious infiltrations on their servers due to the lack of security boundaries established from the beginning. Let us begin on the right path by laying our foundation with security. This how-to will help you with your initial setup on Ubuntu 15.04 so that you can successfully secure your server while giving you peace of mind knowing your server is protected. ## What Do You Need? You need a Ubuntu 15.04 server configured with a static IP address. If you do not have a server already, you can visit our industry-leading [VPS Hosting](https://www.atlantic.net/vps-hosting/) page and spin a new server up in under 30 seconds. ## Server Preparation To get started, log in to your Ubuntu 15.04 server via SSH or the VNC Console located [here. Atlantic.Net Cloud servers](https://cloud.atlantic.net/?page=userlogin)are set up as minimal installations to avoid having unnecessary packages from being installed and never used. If some software packages that you’re used to using aren’t installed by default, feel free to install them as needed. Let’s make sure that your server is fully up-to-date. ## Update the Ubuntu 15.04 Root Password By default, your Atlantic.Net servers are automatically set with secure passwords. However, we still recommend updating your password after creating your server and every 60-90 days after that to ensure it remains secure. A minimum of 8 characters, including lowercase, uppercase, and numbers, are recommended to increase the level of security. Type the following command to activate your request and follow the on-screen instructions to update/confirm your root password: ``` passwd ``` ## Create a new user with sudo privileges After successfully updating your password, it’s recommended that you create a new user with sudo/root permissions. Since the standard admin user for many Linux Operating Systems like Ubuntu 15.04 is “root,” we’re going to make a new admin user that will be used for day-to-day administration tasks. Creating a new user with root permissions will increase the security of the way your server is accessed.  Individuals looking to target your system will target the root user because it’s known to be the default admin account. By creating a new user with sudo/root permissions and disabling the root user, you are increasing security by using a user that isn’t already publicly known. Type the following command to create your new user replacing “user1” with your username, and confirm. ``` adduser user1 ``` Fill in the information that applies to the user and confirm the information: ``` root@JVHServer:~# adduser user1 Adding user `user1' ... Adding new group `user1' (1000) ... Adding new user `user1' (1000) with group `user1' ... Creating home directory `/home/user1' ... Copying files from `/etc/skel' ... Enter new UNIX password: Retype new UNIX password: passwd: password updated successfully Changing the user information for user1 Enter the new value, or press ENTER for the default Full Name []: user1 Room Number []: Work Phone []: Home Phone []: Other []: Is the information correct? [Y/n] y ``` Create a password for that user by typing the following command to activate your request and following the on-screen instructions to update/confirm your “user1” password: ``` passwd user1 ``` Once you have created a new user and created the password for that user, it is time to add the user to the sudo wheel group. In Ubuntu 15.04, once you add them to the sudo wheel group, they are automatically assigned sudo/root permissions. Run the following command to add the user to the sudo wheel group. ``` adduser user1 sudo ``` Finally, when you have created the user with sudo/root permissions,  you can exit your session and log back in with your “user1” to verify the changes made. Alternatively, you can run the following command and switch users from root to “user1,” which will ask you for that user’s password. It is important to remember that you will have to use sudo before running any command with the user. ``` su - user1 ``` ## Configure SSH Access Port 22 is the default port for remote connections via SSH in Linux systems. By changing the ssh port, you will increase the security of your server in preventing brute force attacks and unwanted users from reaching your server using the default port. For this tutorial, use Port 5022 as an example. Open your SSH Configuration file, find the Port line, remove the # and change 22 number to your Custom port. Save and exit. ``` sudo nano /etc/ssh/sshd_config ``` ``` # What ports, IPs and protocols we listen for Port 5022 ``` For your system to update the new settings from the SSH Configuration file, we must restart the sshd service. ``` sudo systemctl restart sshd.service ``` SSH has now been configured to use Port 5022, and if you attempt to login using Port 22, your login will fail. However, do not exit your session as we need to configure the custom port on the firewalls configuration part first, which we will configure in the upcoming steps. ## Limit Root Access Since we’ve created a new user with root permissions and made a custom ssh port, there’s no need to keep the actual root user available and vulnerable over SSH on your server. Let us restrict the root user’s access to the local server and grant permission to the new user over SSH only. Open the SSH Configuration file, find the PermitRootLogin line, remove the # and change it from yes to no. ``` sudo nano /etc/ssh/sshd_config ``` ``` #PermitRootLogin yes PermitRootLogin no ``` For your system to update the new settings in the SSH Configuration file, we must restart the sshd service. ``` sudo systemctl restart sshd.service ``` Note: You will now have the root user disabled in making those changes, so you must log in to your server with the “user1” that you created. However, do not exit your session. We must configure the custom port on the firewall in the upcoming steps. ## Create a Private SSH Key **Private/Public SSH Keys** are great additional features that increase security in a server’s method. However, it takes a bit more effort to set up. The question is, Is your server worth the extra security? If you want to implement the following security features, you can continue with the next steps. Let us proceed and generate the SSH Key. ``` ssh-keygen ``` If you want to change the location where the SSH Key will be saved,  you can specify it here. However, the default location where it’s stored should be OK. Press enter when prompted with the following question, then enter a passphrase, unless you don’t want one. ``` Enter file in which to save the key (/home/user1/.ssh/id_rsa): ``` ![This is the default page when installing SSH Keys on a Ubuntu 15.04 server](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu1.jpg) This is the default page when installing SSH Keys on a Ubuntu 15.04 server Configuring the SSH Key is crucial. We must copy the entire key string to a Word/ Notepad Document. The key can be viewed in the following location with the cat command. ``` cat ~/.ssh/id_rsa.pub ``` Copy the SSH key, beginning with ssh-rsa and ending with user1@yourserver, into a Word/ Notepad document to add it to the config file later on. ``` ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDNcnc3pMOytM7xgwZHUX0Wi/O78hDvLUmQVtKn8Qk1ijBY82jVftKXKRhf8toNkgm9jaZmfapLa7ynzUG4jbFjyy8H+iEs1R8P7eu+e8/fmGwjorbMFuWdoi7h2CldoqKTdMEb/dMNxjNMzBbovl3XtZviQGm4/TMVO1hHxy85JR8zAtNFu7liaP7IonexNrOGhY8CjqRcBsceQLkl1MlX7cWaWAMqd6jQnAvggTLerI9P286AP8Sk4uColj7GKOljj8X6J/2pcjp9v2IvJOqwC/zLwUKZ6qTEV6SrfdbjopoCVvpXkVhmcbHX5Xv1gwynO+vTkpPFwVTjSnAai71L jose@JVHServer ``` Once the SSH Key is stored safely, the directory for the SSH Keys needs limited permissions that only the owner can read, write and execute the file. ``` sudo chmod 700 .ssh ``` Within the SSH directory, a file containing the SSH Key must be added, simply using your editor (in this case NANO) the following location: ``` nano .ssh/authorized_keys ``` Paste the SSH Key, then save and exit using the nano format. Finally, we have to limit the permissions of the authorized_keys file that we just created so only the owner can read and write. ``` chmod 600 .ssh/authorized_keys ``` We could now verify that the key is working by closing the session and typing user1@YOUR.IP.ADD.RESS or your server’s hostname in your SSH Console. Furthermore, [you can click “here” to see our How To Generate and Use SSH Keys article for more information.](https://www.atlantic.net/vps-hosting/how-to-generate-use-ssh-key-using-putty/) ## Basic Firewall Rules By default, your Atlantic.Net’s Ubuntu 15.04 Server is not loaded with a firewall. However, depending on your preference, you may install any of the following: **firewalld, iptables,**etc. In this part, I will be using **Firewalld,** which uses the **firewall-cmd**tool to configure its rules. We must first install the Firewall service with the following: ``` sudo apt-get install firewalld ``` Next, we’re going to add a rule to allow the custom SSH Port 5022 that was created earlier to access the server publicly. At the same time, we will remove the previous default rule allowing SSH access on TCP/22. ``` sudo firewall-cmd --permanent --add-port=5022/tcp ``` ``` sudo firewall-cmd --permanent --remove-service=ssh ``` If you have a web server, you may want to allow the following rules to access your sites over the internet. ``` sudo firewall-cmd --permanent --add-service=http sudo firewall-cmd --permanent --add-service=https ``` You can use this for similar rules related to any systems you want to be publicly accessible. This test server is set up to host a website and email services, so in addition to the updated SSH  and HTTP(S) rules, additional rules for secure POP3, IMAP, and SMTP have been added. ``` sudo firewall-cmd --permanent --add-service=pop3s sudo firewall-cmd --permanent --add-service=imaps sudo firewall-cmd --permanent --add-service=smtp ``` For Firewalld to accept those settings, you must restart the firewall. ``` sudo firewall-cmd --reload ``` Your settings will have been saved, and you are ready to proceed. To verify all the services/ports that are available, run the following: ``` sudo firewall-cmd --permanent --list-all ``` ![This is the default page after configuring the Firewalld rules on Ubuntu 15.04 server](https://www.atlantic.net/wp-content/uploads/2015/06/ubuntu2-1-1-e1635039503538.jpg) This is the default page after configuring the Firewalld rules on Ubuntu 15.04 server ## NTP Time Sync The NTP (Network Time Protocol) is used to synchronize the time and date of computers over the network to remain accurate and up to date. Let us begin by installing the NTP(If it hasn’t been installed) and configuring the service to synchronize with their servers. ``` sudo apt-get install ntp ``` Once the NTP service is installed, we need to ensure that the service is ON. ``` sudo /etc/init.d/ntp start ``` ## Add Swap File A Swap file is simply a small space created on a server hard drive to simulate Ram. If the server is running low on memory, it will look at the hard drive and ease the load tricking the system into thinking it has more memory. We will set up the swap file on the hard drive to increase the server’s performance just a little bit more. Begin by checking your resources to make sure we can add the file. When you run the following command, you will see the percentage space on your Hard drive that is currently being used. ``` df -h ``` When creating a Swap file, you usually want to add half of your existing RAM up to 4GB(If you have 1GB of actual Ram, you add a 512MB file). In this part, I will be adding a 512MB swap file to the drive. The way that this is calculated is by 1024 x 512MB = 524288 block size. ``` sudo dd if=/dev/zero of=/swapfile bs=1024 count=524288 ``` Now that we have added a swap file, an area needs to be created to proceed. ``` sudo mkswap /swapfile ``` With the Swap file created and the Swap file, area added we could go ahead and add permissions to the file so that only the owner can read and write. ``` sudo chown root:root /swapfile sudo chmod 600 /swapfile ``` Now that the swap file has the appropriate permissions, we can go ahead and activate it. ``` sudo swapon /swapfile ``` You can verify your newly added Swap file with the following. ``` sudo swapon -s ``` To make the Swap file always active even after a reboot, we must configure it accordingly. ``` sudo nano /etc/fstab ``` Paste the following command at the bottom of the file, save your work, and exit. ``` /swapfile swap swap defaults 0 0 ``` Finally, verify if your swapfile is activated by typing the following command: ``` free -m ``` ![This is the default page after creating a Swap File on a Ubuntu 15.04 Server](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu3.jpg) This is the default page after creating a Swap File on a Ubuntu 15.04 Server ### What Next? With that, you now have a server with a strong security foundation, giving you peace of mind knowing that your server is protected. You may now proceed to build your platform according to your needs. Thank you for following along, and feel free to check back with us for further updates. Atlantic.Net is dedicated to providing the very best in technical support for our customers along with offering full line-ups of [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions for any sized business. --- # Cómo instalar Linux , Apache , MySQL y PHP (LAMP ) en Ubuntu 14.04 > URL: https://www.atlantic.net/vps-hosting/como-instalar-linux-apache-mysql-y-php-lamp-en-ubuntu-14-04/ | Published: 2015-06-08 | Updated: 2026-01-15 | Author: Jose Velazquez ##### Probado y verificado 06/5/15 ## Introducción En este Como-Hacer , instalaremos LAMP en un servidor usando Ubuntu 14.04. LAMP simplemente es un  paquete de software compuesto por cuatro componentes, Linux , Apache , MySQL y PHP. El núcleo de la plataforma es Linux y en este caso, estaremos usando Ubuntu 14.04 LTS . Apache es un servidor web y la mayoría de los servidores web en el mundo entero usan Apache. MySQL es un sistema de administración para base de datos que es desarrollado por Oracle . PHP es un lenguaje de programación muy popular que se utiliza ampliamente en el desarrollo de web . En total, esto forma LAMP  o una pila LAMP. ## Requisitos Un servidor con Ubuntu 14.04 instalado . Puedes obtener un servidor [aquí, si no tienes uno](https://cloud.atlantic.net/?page=signup) ## Instalación LAMP en Ubuntu 14.04 El primer paso de esta instalacion LAMP, es la instalación de Apache. ## Instalación de Apache en Ubuntu 14.04 Instala Apache ejecutando el comando siguiente: ``` apt-get install apache2 ``` Dale a Enter cuando te pregunte “Do you want to continue?” durante la instalación. Despues de la instalacion, puedes verificar que Apache este corriendo ejecutando el comando siguiente: ``` service apache2 status ``` Tambien puedes verificar que todo esta trabajando bien simplemente abriendo tu navegador y ir a http:// tudirecciónIP Si no sabes la dirección IP de tu servidor, puedes obtenerla ejecutando el comando siguiente: ``` ifconfig ``` ![Un ejemplo del comando ifconfig con la direccion IP 172.20.6.154](https://www.atlantic.net/wp-content/uploads/2018/01/instalar1-1.png) Un ejemplo del comando ifconfig con la direccion IP 172.20.6.154 En este caso pondremos http:// 172.20.6.154 en el navegador para obtener la página siguiente: ![Esta es la página por defecto de Apache en Ubuntu 14.04](https://www.atlantic.net/wp-content/uploads/2018/01/instalar2-1.png) Esta es la página por defecto de Apache en Ubuntu 14.04 ## Instalación de MySql en Ubuntu 14.04 Instala MySql ejecutando el comando siguiente: ``` sudo apt-get install mysql-server libapache2-mod-auth-mysql php5-mysql ``` Dale a enter cuando te pregunte “Do you want to continue?” durante la instalación. Durante la instalación , se le pedirá que introduzca una contraseña de root para MySQL. Establece cualquier contraseña que le gustaría a usted . Debe ser una contraseña segura. ![Introduzca la contraseña de su elección](https://www.atlantic.net/wp-content/uploads/2018/01/instalar3.png) Introduzca la contraseña de su elecciónDespués de introducir la contraseña de root para MySQL , tendrás que volver a introducirla. ![Vuelva a introducir la contraseña que estableció previamente](https://www.atlantic.net/wp-content/uploads/2018/01/instalar4.png) Vuelva a introducir la contraseña que estableció previamenteContinúe con la instalación de seguridad para MySQL ejecutando el comando siguiente: ``` mysql_secure_installation ``` Nota: Se le pedirá una serie de preguntas. Sólo tienes que escribir la contraseña de N para el cambio de root y Y para sí en todo lo demas, consulte la captura siguiente en la pantalla: ![ Un ejemplo de mysql_secure_installation como aparece](https://www.atlantic.net/wp-content/uploads/2015/06/instalar5-1-1536x962-1-1024x641.png) Un ejemplo de mysql_secure_installation como apareceDespues de la instalacion, puedes verificar que MySql esta corriendo ejecutando el comando siguiente: ``` service mysql status ``` ## Instalación de PHP en Ubuntu 14.04 Instala MySql ejecutando el comando siguiente: ``` apt-get install php5 ``` Dale a enter cuando te pregunte “Do you want to continue?” durante la instalación. Crea un archivo PHP de prueba llamada info.php en / var / www / html / . En este como-hacer vamos a utilizar el editor de textos nano ejecutando el comando siguiente: ``` nano /var/www/html/info.php ``` Inserte el código siguiente en el editor de texto a continuado por guardar y salir: ``` ``` Como hicimos cambios , tenemos que reiniciar Apache para que los cambios tengan efecto ejecutando el comando siguiente: ``` service apache2 restart ``` Ahora puedes verificar que todo esta trabajando bien simplemente abriendo tu navegador y ir a http:// tudirecciónIP/info.php ![El resultado del archivo php.info que hemos realizado.](https://www.atlantic.net/wp-content/uploads/2018/01/instalar6.png) El resultado del archivo php.info que hemos realizado.¡Felicidades! Usted acaba de instalar LAMP en su servidor Ubuntu 14.04. Gracias por seguir este Como-Hacer sobre la instalación de LAMP. Visitenos de nuevo para nuevas actualizaciones . Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # Cómo Instalar De Linux, Apache, MySQL, PHP, (LAMP) Con Debian 8 > URL: https://www.atlantic.net/vps-hosting/como-instalar-de-linux-apache-mysql-php-lamp-con-debian-8/ | Published: 2015-06-09 | Updated: 2026-01-15 | Author: Ariel Beltre ## Introducción En este artículo, le mostraremos como instalar LAMP en un servidor cloud con Debian 8. LAMP es simplemente un paqute de software que consiste de 4 componentes. Linux es la base de la plataforma; todos los componentes son instalados en el entorno Linux. En este caso, vamos a usar Debian 8 para el sistema operativo Linux. Vamos a usar Apache para el servicio web. MySQL se utilizará para la gestión de bases de datos, y PHP sera como el lenguaje de programacion. En total esto forma LAMP, que tambien se llama un LAMP stack. ## Requisitos Previos Un servidor con Debian 8 instalado. Si usted no tiene un servidor ya, usted puede visitar nuestra pagina de [VPS hosting](https://www.atlantic.net/vps-hosting/) y configurar un nuevo servidor en menos de 30 segundos. ## Instalación de LAMP En Debian 8 Primero vamos a empezar con la instalacion de Apache. Apache es el servidor web mas popular del mundo. ## Instalación de Apache En Debian 8 Primero vamos a instalar Apache utilizando el siguiente comando para comenzar la instalacion: ``` apt-get install apache2 ``` Para verificar que todo esta funcionando, abre su navegador de internet y visite la pagina http://youripaddress Si no sabes la direccion IP de tu servidor, ejecute el comando siguiente: ``` Ifconfig ``` ![Instalacion de Linux-Apache-MySQL Y PHP-LAMP-En-Debian-8](https://www.atlantic.net/wp-content/uploads/2018/01/Instalar1.png) Un ejemplo del comando ifconfig utilizando el IP 192.68.0.2 En nuestro ejemplo, pondriamos http:// 192.68.0.2 en la barra de direcciones para obtener la siguiente pagina: ![Instalacion de-Linux-Apache-MySQL- Y PHP-LAMP-En-Debian-8](https://www.atlantic.net/wp-content/uploads/2018/01/Instalar2.png) Un ejemplo de la página por defecto de Apache en Debian 8 ## Instalación De MySQL En Debian 8 Para instalar MySQL ejecute el siguiente comando: ``` sudo apt-get install mysql-server libapache2-mod-auth-mysql php5-mysql ``` Durante la instalacion, se le pedira que introduzca una contraseña de root para MySQL. Elije cualquier contraseña que le gustaria. ![Instalacion de-Linux-Apache-MySQL- Y PHP-LAMP-En-Debian-8](https://www.atlantic.net/wp-content/uploads/2018/01/Instalar3.jpg) Un ejemplo de la configuración de la contraseña de MySQL durante la instalación. Asegure MySQL desde la configuración predeterminada con el siguiente comando: ``` mysql_secure_installation ``` Nota: Se le pedira una serie de preguntas. Simplemente escriba N para el cambio de contraseña root y S para si en todos ellos, consulte la siguiente captura de pantalla: ![Instalacion de-Linux-Apache-MySQL- Y PHP-LAMP-En-Debian 8](https://www.atlantic.net/wp-content/uploads/2018/01/Instalar4.jpg) Un ejemplo de las preguntas durante la instalacion de MySQL ## Instalación de PHP en Debian 8 Para comenzar la instalacion de PHP utilice el siguiente comando: ``` apt-get install php5 ``` Crea un archivo PHP para prueba en el siguiente directorio con el siguiente comando: ``` nano /var/www/html/info.php ``` Inserte el siguiente código en el espacio vacio, y luego guardar y salir: ``` ``` Reinicie Apache para que todos los cambios surtan efecto: ``` service apache2 restart ``` Pon a prueba tu pagina en el navegador con el siguiente hipervínculo cambiado a su direccion de IP: http:// youripaddress/info.php ![Instalacion de-Linux-Apache-MySQL- Y PHP-LAMP-En-Debian 8](https://www.atlantic.net/wp-content/uploads/2018/01/Instalar5.png) Un ejemplo del archivo php.info que se creó en Debian 8. Enhorabuena! Usted acaba de instalar LAMP en su servidor Debian 8. Gracias por seguir adelante y por favor eche un vistazo a nuestro articulo de Instrucción para ‘[Instalación De WordPress En Debian 8](https://www.atlantic.net/vps-hosting/how-to-install-wordpress-debian-8/)”. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install LAMP on an Ubuntu 15.04 Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-lamp-ubuntu-15-04-server/ | Published: 2015-06-10 | Updated: 2026-01-15 | Author: Atlantic.Net NOC ##### Verified and Tested 05/06/15 ## Introduction We will walk you through installing LAMP on your Ubuntu 15.04 cloud server in this How-To. LAMP is simply a software bundle that consists of 4 components. Linux (**L**) is the core of the platform, which will sustain the other components. Apache (**A**) is used for the web hosting service. MySQL (**M**) is used for database management. PHP (**P**) is the application programming language. ## Prerequisites A server with Ubuntu 15.04 already installed. If you do not have a server already, consider [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net and be up in 30 seconds. ## Installing LAMP on Ubuntu 15.04 We will first start by installing Apache. Apache is an open-source web server and is the most popular web server globally. ## Installing Apache Install Apache with the following command to begin the install: ``` apt-get -y install apache2 ``` Verify if all is working by opening your browser and going to http:// If you are unsure what your IP address is, run the following: ``` ifconfig ``` ![anet-Installing LAMP on Ubuntu 15.04](https://www.atlantic.net/wp-content/uploads/2018/01/lamp1-1-1.png)   In this example, we would do http:// 192.168.0.1, which should open a page looking like this. ![anet-Getting Started with Ubuntu 14.04-LAMP](https://www.atlantic.net/wp-content/uploads/2018/01/lamp2-1-1.png) ## Installing MySQL (M) Next, we will install MySQL by running the following command: ``` apt-get install mysql-server mysql-client ``` You will be prompted to enter a new password for MySQL “root” user, enter what you would like. ![anet-Installing LAMP on Ubuntu 15.04](https://www.atlantic.net/wp-content/uploads/2018/01/lamp3-1.png) You are then asked to enter the password again. ![anet-Installing LAMP on Ubuntu 15.04](https://www.atlantic.net/wp-content/uploads/2018/01/lamp4-1.png)   Once complete, you can verify MySQL is installed by running the below command. ``` systemctl status mysql ``` It will show active(running) ![anet-Installing LAMP on Ubuntu 15.04](https://www.atlantic.net/wp-content/uploads/2018/01/lamp5-1.png) Next, you will want to secure MySQL by running the following command: ``` mysql_secure_installation ``` This command will first ask you for your current MySQL “root” user password, which we created earlier when installing MySQL. Enter the password and continue. If you would like to change the root password, type “n” and press enter unless you want to change it. You will say yes to the next couple of questions as it will secure your MySQL. The command will remove anonymous user access, disallow root login remotely, remove the test database, and access it. The last question is to reload the privilege tables, say yes, and press Enter. ![anet-Installing LAMP on Ubuntu 15.04](https://www.atlantic.net/wp-content/uploads/2018/01/lamp6-1.png) ## Installing PHP To install PHP, run the following command: ``` apt-get -y install php5 php5-mysql libapache2-mod-php5 ``` We will save a basic PHP script under the web root directory to test PHP. For Ubuntu 15.04, this is located in /var/www/html, so we would want to open a test file called something like test.php by running the following command: ``` nano /var/www/html/test.php ``` This will open an empty file, and we will add the following text: ``` ``` Save and close the file. You will now need to restart Apache for the changes to take effect. To restart Apache, run the following command: ``` systemctl restart apache2 ``` In this article, our server IP address from earlier is 192.168.0.1, and the PHP script is saved under the web root directory named test.php. We can now test php by opening up an internet browser and the PHP script we saved. We will now enter the URL http:// 192.168.0.1/test.php and press Enter. You will see the following screen if installed and working correctly. ![anet-Installing LAMP](https://www.atlantic.net/wp-content/uploads/2018/01/lamp7-1.png)   Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # Achieving HIPAA Compliance with Mobile Devices > URL: https://www.atlantic.net/hipaa-compliant-hosting/achieving-hipaa-compliance-with-mobile-devices/ | Published: 2015-06-10 | Updated: 2024-06-01 | Author: Sam Guiliano Last year, Google Fit and Apple Health brought health applications into the mainstream. While these devices can provide a wealth of data for app developers looking to help consumers get more out of their wearables, the data itself may fall under the scope of Federal laws protecting patient health information under HIPAA. Developers unfamiliar with this space must learn how to maintain HIPAA compliance. So, how can mobile app developers make sure that their applications protect personally identifiable health information and avoid incurring HIPAA violations (and the fines that come with them)? In this article, we’ll explore ways developers can get ahead of the curve and ensure that they’re making the right choices to protect patient data. ## **Study: Health IT Will Change Rapidly** Two major trends, a boost in cloud adoption among healthcare providers and a drop in the expenses to deploy systems, will significantly impact the American HIT market through 2018, per a whitepaper released last year. The report, created by the consultancy RNCOS, forecasts that health IT  will expand at a CAGR of almost 10%.  How good is 10%?  The creation of increasingly better technologies and public-sector promotion for this type of application (e-health applications) will contribute to the strong growth rate of this sector.  As an example, the Economist Intelligence Unit and International Monetary Fund agree that the US GDP growth rate will be around 3% over the same period. Remember, though, that this isn’t just a time of growth but a time of change.  For health, IT to be delivered as effectively as possible, resulting in better care and better ROI, a complex network of stakeholders (doctors, insurance companies, pharmaceutical firms, medical device manufacturers, drugstores, and patients) must work collaboratively. “The full value of health IT is realized when all parties come to the table to ensure data liquidity and ultimately, information and support flowing to people and patients,” advised health management consultant Sarasohn-Kahn. “More value can be derived when technologies don’t add costs but conserve costs and resources.” ## **Possible PHI Issues** If your technology handles personal health information that falls under the scope of Federal law, it can be critically important to protect your business from fines from the US Office for Civil Rights. If you are creating a mobile app (whether for wearables or standard smart devices), you want to know the parameters of HIPAA compliance. Compliance is necessary specifically for systems that have two characteristics: 1. Use health data that is personally identifiable (PII in some form). 2. Exchange the data with healthcare providers (PHI, much of it patient-generated health data). If your application meets those two criteria, you must be intimately familiar with the law – especially the privacy, security, and breach notification rules.  Consider the issues you can run into with protected health information in the mobile arena: 1. Mobile devices are often stolen.  If PHI is unencrypted, you could end up with a fine. 2. The device typically provides access to email and social media.  Accidental posting could occur. 3. Push notifications and other features could represent violations. 4. You could have instances of purposeful or accidental sharing of protected health information between users. 5. If a user turns off the password protection that locks the phone’s screen, anyone present could access immediately visible data. 6. Since mobile devices are often smaller, many users shorten their passwords (thereby making them less secure), so it’s easy to get online. Developers can’t control against all those scenarios, but they can ensure they maintain compliance on behalf of their customers and themselves (as of 2013). ## **Example: Mobile HIPAA Provider Selection Story** Below is a snippet from a developer selecting a solution for a [HIPAA-Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)mobile application, *anonymized and edited for privacy*.  The intention here is to look at questions and concerns rather than the specs of particular plans. Note that we’re looking at an excerpt from the middle of their back-and-forth, right after the Hosting Consultant has explained the 12-month agreement. Healthcare Client: 1. So what would be the penalty if we break the agreement or would like to move to a different establishment? 2. Do you have any referral incentives since this will be for our client? 3. The business associate agreement will be between the business owner and you folks? Hosting Consultant: Here are the answers to your questions. 1. You would be responsible for the balance of the term of the agreement.  So if you canceled after six months, you would owe us another six months. 2. Will the [HIPAA Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) agreement be under the name of your company or under the name of your client (which means that they would be paying the monthly bill)? 3. It will be if your client is signing the HIPAA hosting agreement and paying the bill. Healthcare Client: Since we are managing the application, we typically overlook the hosting as well.  However, the owner of the application is our client.  So is it possible that we will manage the application and hosting issues, but the business (application owner) signs the agreement and pays through us? Hosting Consultant: I have permission to provide you with pricing based on a 6-month agreement.  I have attached the updated pricing. ## **A Simple and Predictable Plotline** Do you need HIPAA compliance for an e-health application?  Work with the mobile HIT industry leader.  Make sure there aren’t any surprises in your success story. “[Atlantic.Net’s] financial strength and proven track record are something we view with great confidence,” commented Complete Healthcare Solutions VP Joseph Nompleggi. ***Choose Atlantic.Net, and you can mobilize healthcare with confidence.*** --- # How to Install Nginx, MySQL, and PHP (LEMP) on an Ubuntu 15.04 Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-lemp-ubuntu-15-04/ | Published: 2015-06-12 | Updated: 2026-01-15 | Author: Atlantic.Net NOC ##### Verified and Tested 05/06/15 ## Introduction We will walk you through installing LEMP on your Ubuntu 15.04 cloud server in this How-To. LEMP is simply a software bundle that consists of 4 components. Linux (**L**) is the core of the platform, which will sustain the other components. Nginx (**E**) is used for the web hosting service. MySQL (**M**) is used for database management. PHP (**P**) is the application programming language. ## Prerequisites A server with Ubuntu 15.04 already installed. You can spin up a dependable server from Atlantic.Net in under 30 seconds. ## Installing Nginx Install Nginx with the following command to begin the install: ``` apt-get -y install nginx ``` Verify if all is working by opening your browser and going to http:// If you are unsure what your IP address is, run the following: ``` ifconfig ``` ![anet-Install LEMP on an Ubuntu 15.04](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu1-1-1.png) ifconfig command In this example, we would do http:// 192.168.0.1, which should open a page looking like this. ![anet-Installing LEMP- welcome to nginx on Ubuntu](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu2-1.png) Default Nginx site ## Configure Nginx The Nginx configuration file is located in /etc/nginx/nginx.conf, so we will use our text editor (In this article, it would be nano) and open the file by running the following command: ``` nano /etc/nginx/nginx.conf ``` You will need to change the worker_processes to the amount of CPUs your server is running. The default is set to 4. ![anet-Installing LEMP default set to 4](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu3-1.png) Nginx configuration file   If you are unsure of the amount of CPUs your server is running, you can use the command “lscpu” to see the amount. ![anet-Installing LEMP](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu4-1.png) Lscpu command Next, we will need to edit the default vhost (server block) located in /etc/nginx/sites-available/default. Use your text editor to go into the file. This article uses nano for text editing, but you may use whichever program you’re most comfortable with. ``` nano /etc/nginx/sites-available/default ``` Under the server section, you will need to change the FQDN or IP address beside “server_name” as shown below. ![anet-Installing LEMP on Ubuntu 15.04](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu5-1.png) Configuration file for default vhost Scroll down a little farther to the section that starts with “location ~ \.php$ {“. Here you will need to uncomment the section and change the following lines to look like below. ![anet-Install LEMP on Ubuntu 15.04](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu6.png) Nginx default vhost configuration file Once done, save and exit the file. We will now test the Nginx configuration by running the following command. ``` nginx -t ``` You should see something like this if it is ok. ![anet-Install LEMP on Ubuntu 15.04](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu7.png) Testing Nginx Configuration   ## Installing MySQL Next, we will install MySQL by running the following command: ``` apt-get install mysql-server mysql-client ``` You will be prompted to enter a new password for MySQL “root” user, enter what you would like. ![anet-Installing LEMP on Ubuntu 15.04](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu8.png) MySQL root database password You are then asked to enter the password again. ![anet-Installing LEMP on Ubuntu 15.04](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu9.png) Re-enter MySQL root database password Once complete, you can verify MySQL is installed by running the below command. ``` systemctl status mysql ``` It will show active(running) ![anet-Installing LEMP on Ubuntu 15.04](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu10.png) MySQL status command Next, you will want to secure MySQL by running the following command: ``` mysql_secure_installation ``` This command will first ask you for your current MySQL “root” user password, which we created earlier when installing MySQL. Enter the password and continue. If you would like to change the root password, type “n” and press enter unless you want to change it. You will say yes to the next couple of questions as it will secure your MySQL. The command will remove anonymous user access, disallow root login remotely, remove the test database, and access it. The last question is to reload the privilege tables, say yes, and press Enter. ![anet-Installing LEMP on Ubuntu 15.04](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu11.png) MySQL secure installation questions ### Installing PHP To install PHP, run the following command: ``` apt-get -y install php5 php5-fpm php5-mysql ``` Before testing the install, we will need to configure PHP by opening the php.ini file. This is located in /etc/php5/fpm. Open this php.ini file with your text editor. ``` nano /etc/php5/fpm/php.ini ``` We need to change cgi.fix_pathinfo to equal 0 instead of 1. Below is how it would look. ![anet-Installing LEMP on Ubuntu 15.04](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu12.png) CGI.fix_pathinfo Save and exit the file. We will have to restart PHP5-FPM using the following command. ``` systemctl restart php5-fpm ``` After a restart, check the status of php5-fpm by running, ``` systemctl status php5-fpm ``` You will see an output similar to this, ![anet-Installing LEMP on Ubuntu 15.04](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu13.png) PHP5-FPM status We will save a basic PHP script under the web root directory to test PHP. For Ubuntu 15.04 with Nginx, this is located in /usr/share/nginx/html, so we would want to open a test file called something like test.php by running the following command: ``` nano /usr/share/nginx/html/test.php ``` This will open an empty file. We will add the following text: ``` ``` Save and close the file. You will now need to restart Nginx for the changes to take effect. To restart Nginx, run the following command: ``` systemctl restart nginx ``` In this article, our server IP address from earlier is 192.168.0.1, and the PHP script is saved under the web root directory named test.php. We can now test php by opening up an internet browser and the PHP script we saved. We will now enter the URL http:// 192.168.0.1/test.php and press Enter. You will see the following screen if installed and working correctly. ![anet-Installing LEMP on Ubuntu 15.04](https://www.atlantic.net/wp-content/uploads/2018/01/ubuntu14.png) PHP Information page You have now wholly installed LEMP on your Ubuntu 15.04 server. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install WordPress on a Ubuntu 14.04 LTS Cloud Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-wordpress-ubuntu-14/ | Published: 2015-06-15 | Updated: 2026-01-15 | Author: Alexander Wise ##### Verified and Tested 06/15/15 ## Introduction This how-to will take you through installing WordPress on Ubuntu 14.04 LTS. WordPress is a content management system that is free and open source. Since it is open-source, there are numerous themes and plugins readily available to you. Although it is typically used as a blogging platform, it can be used for many other uses. ![WordPress Illustration by Walker Cahall](https://www.atlantic.net/wp-content/uploads/2018/01/wp1-1.png) WordPress Illustration by [Walker Cahall](http://waltronic.net) ## Prerequisites A Ubuntu 14.04 server running LAMP or LEMP is required to install WordPress. Please see our how-to guide for installing [LAMP](https://www.atlantic.net/vps-hosting/how-to-install-linux-apache-mysql-php-lamp-ubuntu-20-04/) or [LEMP](https://www.atlantic.net/vps-hosting/how-to-install-lemp-ubuntu-14-04/). If you do not have a server, you can get a trusted virtual private server from Atlantic.Net, or use our One-Click WordPress installation. ## Step 1 – Set Up the MySQL Database in Ubuntu 14.04 We are going to start by setting up the MySQL database by running the following commands: ``` mysql -u root -p ``` When prompted, enter your MySQL root password that you set up when installing MySQL. In MySQL, enter the following commands: ``` create database wordpress character set utf8 collate utf8_bin; ``` Make sure you set your secure password where it says [insert-password-here] ``` grant all privileges on wordpress.* to wordpressuser@localhost identified by "[insert-password-here]"; ``` ``` flush privileges; ``` ``` exit ``` ## Step 2 – Get the Latest WordPress Install on Ubuntu 14.04 Now that the database is created, we can download the latest version with the following command: ``` wget http://wordpress.org/latest.tar.gz ``` The newest package will download to the directory you are in, with the file name latest.tar.gz. We need to decompress the file by running: ``` tar -xzvf latest.tar.gz ``` ## Step 3 – Configure WordPress on Ubuntu 14.04 Next, we need to copy wp-config-sample.php to wp-config.php, where it gets its base configuration. To do that, run: ``` cp wordpress/wp-config-sample.php wordpress/wp-config.php ``` In your favorite text editor, edit wordpress/wp-config.php For a basic setup, we need to have the following. define(‘DB_NAME’, ‘wordpress’); define(‘DB_USER’, ‘wordpressuser’); define(‘DB_PASSWORD’, ‘[insert-password-here]’); It should look like this when completed: ![What wp-config.php should look like once you have edited it](https://www.atlantic.net/wp-content/uploads/2018/01/wp2.png) What wp-config.php should look like once you have edited it Next, we need to move the WordPress folder to your web directory. ``` cp -r ~/wordpress/* /var/www/html ``` Note: Your web directory may be different based on your configuration. ## Step 4 – Finish The Installation Through The WordPress Web Installation Now, we can go to the WordPress web installation. In your browser, go to http:// yourhostname-or-ipaddress If you are unsure what your IP address is, run the following: ``` ifconfig ``` ![An example of using ifconfig to show the IP address of your server](https://www.atlantic.net/wp-content/uploads/2018/01/wp3.png) An example of using ifconfig to show the IP address of your server In our example, we would put http:// 172.20.6.154/ in the address bar and get the following page. ![An example of the WordPress web installation](https://www.atlantic.net/wp-content/uploads/2018/01/wp4.png) An example of the WordPress web installation From here, all that is needed to do is to follow along with the WordPress install and give the information required. Congratulations! You have just installed WordPress on Ubuntu 14.04. For more information, you may want to check out the [WordPress Codex](https://codex.wordpress.org/). Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [Virtual private servers.](https://www.atlantic.net/vps-hosting/) --- # How to Set Up a Mount & Blade: Warband Dedicated Server on CentOS > URL: https://www.atlantic.net/vps-hosting/how-to-set-mount-blade-warband-dedicated-server-centos/ | Published: 2015-06-16 | Updated: 2024-10-21 | Author: Michael Douse ##### Verified and Tested 04/27/15 ## Introduction This article will go over how to set up a Mount & Blade: Warband dedicated server in a freshly provisioned CentOS 6.5 virtual private server. ![2015-04-27 15_17_34-Mount&Blade Warband - TaleWorlds Entertainment](https://www.atlantic.net/wp-content/uploads/2018/01/warband1.png) ## Install Mount & Blade: Warband Dedicated Server on CentOS First, we will need to install the EPEL repository: ``` yum install epel-release -y ``` Now update system packages and EPEL database: ``` yum update -y ``` And finally, all the required packages: ``` yum install tmux nano wine unzip wget -y ``` *Note: Wine will take several minutes to install, so be patient.* --- Now to open up the required ports in the firewall. The default ports needed for steam and non-steam users are 7240 and 7241. Let us open these up in IPtables: ``` nano /etc/sysconfig/iptables ``` Add the following lines before the REJECT rules: ``` -A INPUT -p tcp --match multiport --dports 7240,7241 -j ACCEPT ``` ``` -A INPUT -p udp --match multiport --dports 7240,7241 -j ACCEPT ``` ![An example of the iptables file after adding the additional rules.](https://www.atlantic.net/wp-content/uploads/2018/01/warband2.png) *An example of the iptables file after adding the additional rules.* Once you are done, save your changes and exit from nano with CTRL O + Enter and CTRL X. Then restart IPtables: ``` service iptables restart ``` Verify that the rules are in place: ``` iptables -L ``` ![2015-04-28 00_30_27-104.245.38.202](https://www.atlantic.net/wp-content/uploads/2018/01/warband3.png) *An example of iptables -L* That’s it for the firewall configuration. --- Time to create a separate user for the dedicated server. Call this user whatever you wish, but for the sake of this how-to, I will be using “Warband”: ``` useradd Warband ``` ``` passwd Warband ``` Now let’s change to the home folder of the user we just created and make a directory for our server files: ``` su Warband ``` ``` cd ``` ``` mkdir Warband_Server ``` ``` cd Warband_Server ``` Download the Warband dedicated server files to the Warband_Server directory we just created. The most recent dedicated server can be found HERE under the “Other Downloads” section. ![2015-04-27 15_18_20-Mount&Blade Warband - TaleWorlds Entertainment](https://www.atlantic.net/wp-content/uploads/2018/01/warband.png) *An example of what the “Other Downloads” looks like* We can “wget” the zipped file by right-clicking on the link and selecting “Copy Link Address” (For Chrome) or “Copy Shortcut” (For Internet Explorer): ![2015-04-27 15_33_06-Mount&Blade Warband - TaleWorlds Entertainment](https://www.atlantic.net/wp-content/uploads/2018/01/warband4.png) *Getting the link to download to wget it on the server*![Getting the link to download so that we can wget it on the server.](https://www.atlantic.net/wp-content/uploads/2018/01/warband5.png) *An example when you wget the download link.* Now that we have the dedicated server files, we will need to unzip them: ``` unzip mb_warband_dedicated_1158.zip ``` Change into the Warband directory you just unzipped. You may need to use TAB to fill out the actual directory name: ``` cd Mount\&Blade\ Wardband\ Dedicated/ ``` Inside you will find many sample server configuration templates to use. The easiest thing to do is edit one of the pre-existing templates. After deciding what kind of game mode you want to host, open it with nano: ``` nano Sample_Team_Deathmatch.txt ``` Review this file for applicable settings. The first changes you will want to make are: ``` #set_pass_admin ADMINPASS #set_server_name SERVERNAME #set_welcome_message WELCOME MESSAGE ``` Remove the “#” and add the appropriate modifications to the admin password, server name, and welcome message. Also, keep in mind that the server name cannot have spaces or special characters. If you need to create a space, then use an underscore. NOTE: You can find additional commands to add to this file from the readme.txt. For instance, I highly recommend adding the following line: ``` set_control_block_direction 1 ``` If set to 1, blocking will have to be done manually by a mouse. Otherwise, directional blocking will be automatic…, and that’s no fun. Once you are done, save your changes and exit from nano with CTRL O + Enter and CTRL X. --- Now let’s take a minute to discuss the TMUX package we installed earlier. We are ready to run the dedicated server, but once we start it from the current terminal session, it will stop once we disconnect/exit from the session. This is where TMUX comes in. TMUX allows us to create a “Window” to run other applications. This will enable us to quit our current terminal session while leaving the window open to run whatever service we choose. *Note: TMUX is what is referred to as a Terminal Multiplexer. Both of which have very loyal user bases. It is a matter of preference on which one you decide to use. The most popular alternative to TMUX is SCREEN.* --- Open a new window: ``` tmux ``` Now start the dedicated server with Wine. Make sure you are still in the dedicated server files directory when you run this: ``` wineconsole --backend=curses Sample_Team_Deathmatch_start.bat ``` *Note: Each game mode template has an associated “.bat” file. Run the one that corresponds to the template you edited.* ![An example of the wineconsole.exe](https://www.atlantic.net/wp-content/uploads/2018/01/warband6.png) *An example of the wineconsole.exe* Once the dedicated server is finished loading, you can close the CTRL B + D window. *Note: You can re-open any active TMUX sessions with the “tmux attach” command.* --- Now check to make sure that the server is still running with the “top” command: ![An example of top](https://www.atlantic.net/wp-content/uploads/2018/01/warband7.png) *An example of top* Now go join your server! ![Anet ServerList](https://www.atlantic.net/wp-content/uploads/2018/01/warband8.png) *An example of the Game server that was created* Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # Dropbox set up for a Linux Cloud Server > URL: https://www.atlantic.net/vps-hosting/how-to-dropbox-set-linux-cloud-server-vps/ | Published: 2015-06-17 | Updated: 2026-01-15 | Author: Michael Douse ##### Verified and Tested 04/28/15 ## Introduction This article will go over how to set up Dropbox via the command line on a Linux Cloud Server. Dropbox is an excellent tool for making your files easy to share. ## Prerequisites -Any 32-bit or 64-bit Linux server. If you do not know if your system is 32-bit or 64-bit, [follow our guide here](https://www.atlantic.net/vps-hosting/how-to-tell-32-bit-64-bit-version-linux/), or if you need a secure and trusted Cloud server, consider one from Atlantic.Net. – You will also need a Dropbox account,[which you can sign up for one here](https://www.dropbox.com/). ## Install Dropbox on your Linux system Change to the root of your home directory and download the required files based on your architecture: The command `cd ~` takes you to your login directory, which is typically your home directory. 32-Bit: ``` wget -O - "https://www.dropbox.com/download?plat=lnx.x86" | tar xzf - ``` 64-Bit: ``` wget -O - "https://www.dropbox.com/download?plat=lnx.x86_64" | tar xzf - ``` If you run the `ls -a` command, you will see a newly created .dropbox-dist folder. To start the daemon, run the command: ``` .dropbox-dist/dropboxd ``` > This computer isn’t linked to any Dropbox account… > Please visit https:// YOUR-SPECIFIC-LINK to link this device. Paste the link provided into your desktop web browser and log in with your account information. Once logged in, recheck your terminal. You should see the following: > This computer is now linked to Dropbox. Welcome *YOUR-NAME* At this time, your files are being synced to the Dropbox folder created in your current user’s home folder. This can take a while, depending on how many files you have. Now verify that your files were all synced: ``` ls Dropbox/ ``` --- Next, we will download the command line management script. This script requires Python, so make sure you have it installed. You can see if Python is installed with `python -V` ``` wget https://www.dropbox.com/download?dl=packages/dropbox.py -O dropbox_manager.py ``` ``` chmod +x dropbox_manager.py ``` Run the script to review the available commands: ``` ./dropbox_manager.py ``` ![An example of the ./dropbox_manager.py for Dropbox](https://www.atlantic.net/wp-content/uploads/2018/01/Dropbox.png) An example of what the ./dropbox_manager.py looks like That’s it! You can now check the status of your synced files and manage other aspects of Dropbox. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to: Getting Started with Ubuntu 14.04 LTS with LEMP > URL: https://www.atlantic.net/vps-hosting/how-to-atlantic-net-cloud-getting-started-ubuntu-14-04-lts-lemp/ | Published: 2015-06-18 | Updated: 2026-01-15 | Author: Atlantic.Net NOC ##### Verified 05-06-2015 ## Introduction In this How-To, we will walk you through getting started with your Ubuntu 14.04 LTS with the LEMP cloud server and verify everything is installed correctly. LEMP is a software bundle that consists of four components. Linux (L) is the core platform on which the other components run. Nginx (E) is used to host web services. MySQL (M) is used for database management. PHP (P) is used for the back-end coding language. ## Prerequisites A server with Ubuntu 14.04 LTS with LEMP. If you do not have a server already, you can spin up a reliable and trusted server from Atlantic.Net. ## Getting Started with Ubuntu 14.04 – LEMP First, [we will want to sign in to our cloud control panel here](https://cloud.atlantic.net/?page=userlogin) ![anet-Getting Started with Ubuntu 14.04 LTS - LEMP- Login Page](https://www.atlantic.net/wp-content/uploads/2018/01/started1.png) Cloud control panel login page   Once logged in, we will see our list of servers. To add an Ubuntu 14.04 LTS with LEMP already installed, we click on “Add Server.”   ![Adding a Server](https://www.atlantic.net/wp-content/uploads/2018/01/started2.png) Adding a Server   You will be sent to a page to fill out the following: -Server Name: Name the server whatever you’d like. It’s a cosmetic choice that does not impact server functionality. It’s there to help you manage your servers. -Location: Select which Atlantic.Net Cloud Platform you want your server hosted on. For best overall best performance, select the location closest to you. 1) In this tutorial, we chose USA-East-1.   ![Choosing your Server location](https://www.atlantic.net/wp-content/uploads/2018/01/started3.png) Choosing your Server location   -Operating System you would want to choose for this article will be “Ubuntu 14.04 LTS Server 64-bit – LEMP.” 1) You would first click on “Applications.”   ![Choosing your OS Type](https://www.atlantic.net/wp-content/uploads/2018/01/started4.png) Choosing your OS Type   2) Then click on “LEMP.”   ![Choosing your OS Type](https://www.atlantic.net/wp-content/uploads/2018/01/started5.png) Choosing your OS Type   -Plan the size of your choice. This will depend on what you will be using the server for. You can scale up the server at any time but cannot scale down. You can view each plan’s details here on our [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/) page. 1) In this tutorial, we clicked on the “Small” plan size   ![Choosing your Plan size](https://www.atlantic.net/wp-content/uploads/2018/01/started6.png) Choosing your Plan size -If you would like to enable backups for your server, you check the box beside “Enable Backups”. Daily backups cost 20% of your server’s monthly price (minimum $1). Once enabled, you can restore your server to a previous date through the cloud control panel. You are able to enable/disable backups at any time as well. After you have completed filling everything out, click on “Create Server”   ![Creating the server](https://www.atlantic.net/wp-content/uploads/2018/01/started7.png) Creating the server   You will then be sent to a page with the server details including the server credentials. You are also emailed the server credentials.   ![Newly provisioned Server details](https://www.atlantic.net/wp-content/uploads/2018/01/started8.png) Newly provisioned Server details   Once your server is provisioned, you will need to SSH into your server. You can navigate to [here if you are not sure how to SSH into your server.](https://www.atlantic.net/vps-hosting/how-to-ssh-linux-server-windows/) Once you have logged into your server, you will see the provided LEMP Notes to help us verify everything. > NOTE: Make note of your current “root database password” as we will need it later to change it to a user-defined password for security reasons. ![LEMP Notes](https://www.atlantic.net/wp-content/uploads/2018/01/started9.png) LEMP Notes   You will want to verify everything was installed correctly and is working. To check Nginx, go to http://. If it is installed, then you will see this default Nginx page.   ![Nginx Default Page](https://www.atlantic.net/wp-content/uploads/2018/01/started10.png) Nginx Default Page   ## Verifying MySQL To verify MySQL is installed and working, run the following command ``` service mysql status ``` You will see this result if it is running ![MySQL Status](https://www.atlantic.net/wp-content/uploads/2018/01/started11.png) MySQL Status To make your MySQL more secure and to change the database root password from the provided one, run the following command: ``` mysql_secure_installation ``` You will first be prompted to enter the current root password for MySQL, provided in the LEMP Notes, when you log into your server. Once you have entered the correct password, you will be asked if you want to change the root password, you would type “y” and then enter if you would like to change it. After changing your password, you will be prompted to answer a couple more questions that will make your MySQL secure by removing anonymous users, disallowing root login remotely, removing the test database, and access to it (Ignore error as database does not exist), and then reload the privilege tables. Once done, you are complete with MySQL! ## Verifying PHP To verify PHP is installed and working properly, we will create a basic PHP script. In this article, we will save it under the web root directory as test.php. In Ubuntu 14.04, the web root directory is located at /usr/share/nginx/html. We will create the file at that location by running the following command: ``` nano /usr/share/nginx/html/test.php ``` This will open an empty file, we want to input the following text. `` Save and close the file. We will now test if the server can generate the PHP script. You will want to go to your browser and enter the following URL: ``` http:///test.php ``` If your server is able to translate the PHP script correctly, you will see something similar to the below picture.   ![PHP Information page](https://www.atlantic.net/wp-content/uploads/2018/01/started12.png) PHP Information page Once you have verified all components of the LEMP installation, you are able to begin configurations for your site! Come back and check for updates, and learn more about [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Install LAMP (Apache, MariaDB, PHP) on a CentOS 7.2 Cloud Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-lamp-centos-7/ | Published: 2015-06-18 | Updated: 2026-01-15 | Author: Alexander Wise ## Introduction This how-to will show you a basic LAMP installation on a CentOS 7.2 Cloud Server. LAMP, on CentOS 7.2, is a software bundle consisting of four components: Linux, Apache, MariaDB, and PHP. LAMP is the backbone for various web-based software, such as WordPress and other web-hosting platforms. We will be using CentOS 7.2 for our Linux installation in this how-to. CentOS 7.2 implements systems, which will make this guide very different than the CentOS LAMP articles you may have seen in the past. Additionally, the default database engine used by CentOS 7 is MariaDB and not MySQL. MariaDB is a forked version of MySQL, so most of the functionality that you may know from MySQL is built into MariaDB. We will be using Apache for our web server and PHP for our scripting language. ![LAMP Magic In Your Hands created by Walker Cahall](https://www.atlantic.net/wp-content/uploads/2018/01/stack1.png) LAMP Magic In Your Hands created by [Walker Cahall](http://www.waltronic.net/) ## Prerequisites A server with CentOS 7.2 installed is required, which will take care of the LAMP stack install Linux portion. If you do not have a CentOS 7.2 server, why not consider a CentOS SSD virtual private server from Atlantic.Net. This how-to requires a user with root credentials. If you are using the root user, then you can omit the `sudo` in front of commands. ## Install LAMP on CentOS 7.2 We need to take care of a few things before installing Apache. First, we should make sure the system is updated by running the following command: ``` sudo yum update ``` If this command finds updates to install, you will be prompted with ‘Is this ok?’ Hit Y and then enter. Next, we need to update our firewall to allow HTTP and HTTPS traffic. Check to see if your firewall is running by running ``` sudo systemctl status firewalld ``` If the firewall is not running, run the following command: ``` sudo systemctl start firewalld ``` If you want the firewall to start when CentOS 7.2 boots up, run the following command: ``` sudo systemctl enable firewalld ``` To allow HTTP and HTTPS, run the following commands: ``` sudo firewall-cmd --permanent --add-service=http sudo firewall-cmd --permanent --add-service=https ``` You need to run the following command so that the rules above take effect. ``` sudo firewall-cmd --reload ``` Now that we have taken care of those things, we can install Apache. ## Installing Apache on CentOS 7.2 We will install Apache with yum, the default package manager for CentOS 7.2. Apache is a free, open-source web server. Install Apache with the following command: ``` sudo yum install httpd ``` During the install, it will prompt, “Is this ok?” Hit Y and then enter. We now need to start Apache by running the command: ``` sudo systemctl start httpd.service ``` We can now verify Apache is working by opening your browser and entering the URL `http:// your-server's-address`. You should get a “Testing 123” page similar to the image below. > Note: If you do not know your IP address, run the following command: > > ``` > ip addr show eth0 > ``` > > ![An example of running the command: ip addr show eth0 and getting 192.168.100.10 for the IP address.](https://www.atlantic.net/wp-content/uploads/2018/01/stack2.png) An example of running the command: ip addr show eth0 and getting 192.168.100.10 for the IP address.In our example we would put `http:// 192.168.100.10` into our browser’s address bar.   ![The default web page when installing Apache on CentOS 7](https://www.atlantic.net/wp-content/uploads/2018/01/stack3.png) The default web page when installing Apache on CentOS 7   To have Apache enabled when your CentOS 7.2 systems startup, run the following command: ``` sudo systemctl enable httpd.service ``` Also, if you would like to check the status of Apache, you can run the following command: ``` sudo systemctl status httpd.service ``` If you would like to test your Apache configuration before restarting, use the following command: ``` sudo apachectl configtest ``` To restart Apache gracefully and avoid noticeable downtime, use the following command: ``` sudo apachectl graceful ``` If it becomes necessary, or if you aren’t worried about downtime, you can perform a hard restart of Apache using the following command: ``` systemctl restart httpd.service ``` To see the version of Apache that is installed, you can use the following command: ``` httpd -v ``` Now that Apache is installed, we can move on to installing MariaDB. ## Installing MariaDB on CentOS 7.2 We will also be using yum to install MariaDB. MariaDB is a free and open-source relational database management system. MariaDB has been designed so that its version number is compatible with the same version number of MySQL but with added features (i.e., MariaDB 5.5 is compatible with MySQL 5.5). Install MariaDB with the following command: ``` sudo yum install mariadb-server mariadb ``` During the install, it will prompt, “Is this ok?” Hit Y and then enter. Start the MariaDB service with the following command: ``` sudo systemctl start mariadb ``` We now need to set up MariaDB with the following command: ``` sudo mysql_secure_installation ``` This setup process will prompt you to answer a series of questions. First, it will ask you to enter the current root password. Since we have just set it up, there should not be one, so hit enter. ``` In order to log into MariaDB to secure it, we'll need the current password for the root user. If you've just installed MariaDB, and you haven't set the root password yet, the password will be blank, so you should just press enter here. Enter current password for root (enter for none): OK, successfully used password, moving on... ``` Next, it will ask you if you want to set a new root password. Press Y and then Enter. It will then ask you to enter a password. Then re-enter it. We recommend you select a strong root DB password different from any user’s password, including the root user. ``` Setting the root password ensures that nobody can log into the MariaDB root user without the proper authorisation. Set root password? [Y/n] y New password: Re-enter new password: Password updated successfully! ``` From there, you can typically just hit Y for each of the following questions, as below, unless you need something specific. ``` By default, a MariaDB installation has an anonymous user, allowing anyone to log into MariaDB without having to have a user account created for them. This is intended only for testing, and to make the installation go a bit smoother. You should remove them before moving into a production environment. Remove anonymous users? [Y/n] y ... Success! Normally, root should only be allowed to connect from 'localhost'. This ensures that someone cannot guess at the root password from the network. Disallow root login remotely? [Y/n] y ... Success! By default, MariaDB comes with a database named 'test' that anyone can access. This is also intended only for testing, and should be removed before moving into a production environment. Remove test database and access to it? [Y/n] y - Dropping test database... ... Success! - Removing privileges on test database... ... Success! Reloading the privilege tables will ensure that all changes made so far will take effect immediately. Reload privilege tables now? [Y/n] y ... Success! Cleaning up... All done! If you've completed all of the above steps, your MariaDB installation should now be secure. Thanks for using MariaDB! ``` To see if the MariaDB service is running, you can run the command: ``` sudo systemctl status mariadb ``` Now that MariaDB is set up, we will want it enabled on startup by issuing the following command: ``` sudo systemctl enable mariadb.service ``` To log into MariaDB, use the following command (note that it’s the same command you would use to log into a MySQL database): ``` mysql -u root -p ``` This same command will also display the version of MariaDB currently running once you’ve successfully logged in. Now that we’ve installed MariaDB, we can install PHP. ## Installing PHP on CentOS 7.2 Once again, we will be installing PHP from yum. PHP is a free and open-source server-side scripting language. Install PHP with the following command: ``` sudo yum install php php-mysql ``` During the install, it will prompt, “Is this ok?” Hit Y and then enter. Create a test PHP file in the following directory. We use nano, but you may use your preferred text editor. ``` sudo nano /var/www/html/info.php ``` Insert the following code, then save and exit: ``` ``` To save your work and close nano, hit Ctrl-X, confirm with “Y,” and then Enter. Restart Apache, so all the changes take effect: ``` sudo systemctl restart httpd.service ``` We can now test that PHP is working by opening up your browser and going to `http:// your-server's-address/info.php`. You should get a page similar to the image below.   ![A default php.info web page that shows when PHP is installed on CentOS 7](https://www.atlantic.net/wp-content/uploads/2018/01/stack4.png) A default php.info web page that shows when PHP is installed on CentOS 7   To see the version of PHP that is installed, you can use the following command: ``` php -v ``` Once you have verified that PHP works as expected, it is a good idea to remove the info.php file since it contains information that could make your server vulnerable. You can remove it by running the following command: ``` sudo rm /var/www/html/info.php ``` It will ask, “rm: remove regular file ‘/var/www/html/info.php’?” Hit Y and then enter. You now have a basic LAMP stack on CentOS 7.2. You can now start placing your site in the `/var/www/html/` directory. Below, you will find some optional settings that you may want to add to your LAMP server. ## Additional Modules for Apache and PHP (Optional) You may want to install some additional modules for Apache and PHP. You can search for basic modules via yum. For Apache: ``` yum search mod_ ``` For PHP: ``` yum search php- ``` To install packages, you may want to add use `yum install` followed by the package name. > Note: If you would like more information on a particular package, you can use the command: > > ``` > yum info package-name > ``` For a complete list of Apache modules, go to [httpd.apache.org](http://httpd.apache.org/docs/2.2/mod/directives.html). For a full list of PHP modules, go to [php.net](http://php.net/manual/en/extensions.alphabetical.php). ## Install phpMyAdmin (Optional) To efficiently manage your databases, you may want to add phpMyAdmin to your LAMP stack. phpMyAdmin is a free and open-source tool written in PHP. It is a web GUI with which you can add, delete, or modify databases and tables, among other things. To install phpMyAdmin easily on CentOS 7.2, we are going to install the Extra Packages for Enterprise Linux (EPEL) repo first by running the following command: ``` sudo yum install epel-release ``` During the install, it will prompt, “Is this ok?” Hit Y and then Enter. Now we can install phpMyAdmin. ``` sudo yum install phpmyadmin ``` During the phpMyAdmin install, it will prompt “Is this ok?” for the install and then the EPEL key. Hit Y and then Enter for each question. The phpMyAdmin installation process will make a configuration file in `/etc/httpd/conf.d/` called `phpMyAdmin.conf`. By default, phpMyAdmin is configured only to accept connections from the server it is installed on. If you want to allow other IPs, you’ll need to open the phpMyAdmin.conf file with your preferred text editor. ``` sudo nano /etc/httpd/conf.d/phpMyAdmin.conf ``` In this example, we are using Apache 2.4, so we only need to change the configurations for 2.4. There will be two places that say “Require ip 127.0.0.1,” Below each one, we are going to put “Require ip {your-public-IP}” For this example, we’ll say we want to grant phpMyAdmin access to a workstation with an IP of 192.168.0.2. In this case, we would put “Require ip 192.168.0.2” below “Require ip 127.0.0.1” If you do not know your public IP, [you can find it here](https://support.google.com/websearch/answer/1696588). The configuration file should be like the one below when completed. ``` # Apache 2.4 Require ip 127.0.0.1 Require ip 192.168.0.2 Require ip ::1 # Apache 2.2 Order Deny,Allow Deny from All Allow from 127.0.0.1 Allow from ::1 # Apache 2.4 Require ip 127.0.0.1 Require ip 192.168.0.2 Require ip ::1 # Apache 2.2 Order Deny,Allow Deny from All Allow from 127.0.0.1 Allow from ::1 ``` In Nano, to save a close, hit Ctrl+X and then Y and then Enter. > Note: When adding allowed IPs to this file, be sure you only add the IPs for users who require access. The more access you allow, you more you may also increase your server’s exposure to exploit. Now, we can restart Apache so that the changes take place: ``` sudo systemctl restart httpd.service ``` To get to the login page, you need to open your browser once again and go to `http:// your-server's-address/phpMyAdmin/`. You should get a page that looks like the image below. ![An example of the phpMyAdmin login page](https://www.atlantic.net/wp-content/uploads/2018/01/stack5.png) An example of the phpMyAdmin login page You can sign in with the root MariaDB credentials you set up earlier. Once logged in, you should get a page similar to the one below. ![An example of the phpMyAdmin default page.](https://www.atlantic.net/wp-content/uploads/2018/01/stack6.png) An example of the phpMyAdmin default page. You can now manage your databases on your LAMP server using this interface. Congratulations! You have just installed a LAMP stack on your CentOS 7.2 Cloud Server. Thank you for following along in this How-To, and check back with us for any new updates. You may want to follow the guides on [changing the CentOS 7.2. hostname](https://www.atlantic.net/hipaa-compliant-hosting/how-to-change-hostname-centos-6-9-7-x-8-x/) or spend some time learning the [basic setup tasks of CentOS 7.2](https://www.atlantic.net/vps-hosting/how-to-initial-centos-7-server-setup/). For more information on our reliable [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions, contact us today for a consultation. See our [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to: Getting Started with Ubuntu 14.04 LTS with LAMP > URL: https://www.atlantic.net/vps-hosting/how-to-get-started-ubuntu-14-04-lts-lamp/ | Published: 2015-06-18 | Updated: 2026-01-15 | Author: Atlantic.Net NOC ##### Verified 05-06-2015 ## Introduction In this How-To, we will walk you through getting started with your Ubuntu 14.04 LTS with LAMP cloud server and verify everything is installed correctly. LAMP is a software bundle that consists of four components. Linux (L) is the core platform the other components run. Apache (A) is used to host web services. MySQL (M) is used for database management. PHP (P) is used for the back-end coding language. ## Prerequisites A server with Ubuntu 14.04 LTS with LAMP. If you do not have a server already, visit our [VPS hosting](https://www.atlantic.net/vps-hosting/) page. ## Getting Started with Ubuntu 14.04 – LAMP First, [we want to sign in to our cloud control panel here](https://cloud.atlantic.net/?page=userlogin).   ![sign into our cloud control panel](https://www.atlantic.net/wp-content/uploads/2018/01/lamp1-3.png) Cloud control panel login page   Once logged in, we will see our list of servers. To add an Ubuntu 14.04 LTS with LAMP already installed, we click on “Add Server.”   ![Adding a Server](https://www.atlantic.net/wp-content/uploads/2018/01/lamp2-2.png) Adding a Server   You will be sent to a page to fill out the following: -Server Name: Name the server whatever you’d like. It’s a cosmetic choice that does not impact server functionality. It’s there to help you manage your servers. -Location: Select which Atlantic.Net Cloud Platform you want your server hosted on. For best overall best performance, select the location closest to you. 1) In this tutorial, we chose USA-East-1.   ![Choosing your Server location](https://www.atlantic.net/wp-content/uploads/2018/01/lamp3-2.png) Choosing your Server location   -Operating System you would want to choose will be “Ubuntu 14.04 LTS Server 64-bit – LAMP.” 1) You would first click on “Applications.”   ![Choosing your OS Type](https://www.atlantic.net/wp-content/uploads/2018/01/lamp4-2.png) Choosing your OS Type   2) Then click on “LAMP.”   ![Choosing your OS type](https://www.atlantic.net/wp-content/uploads/2018/01/lamp5-2.png) Choosing your OS type   -Plan the size of your choice. This will depend on what you will be using the server for. You can scale up the server at any time but cannot scale down. You can view more detail for each plan on our [VPS hosting pricing](https://www.atlantic.net/vps-hosting/pricing/) page. 1) In this tutorial, we clicked on the “Small” plan size   ![Choosing your Plan size](https://www.atlantic.net/wp-content/uploads/2018/01/lamp6-2.png) Choosing your Plan size   -If you would like to enable backups for your server, then you would check the box beside “Enable Backups.” Once enabled, you can restore your server to a previous date through the cloud control panel. You can enable/disable backups at any time as well. Daily backups cost 20% of your server’s monthly price (minimum $1). After completing filling everything out, click on “Create Server.”   ![Creating the server](https://www.atlantic.net/wp-content/uploads/2018/01/lamp7-2.png) Creating the server   You will then be sent to a page with the server details, including the server credentials. You are also emailed the server credentials.   ![Ubuntu 14.04 LTS - LAMP Server Details](https://www.atlantic.net/wp-content/uploads/2018/01/lamp8.png) Ubuntu 14.04 LTS – LAMP Server Details   Once your server is provisioned, you will need to SSH into your server. [You can navigate here](https://www.atlantic.net/vps-hosting/how-to-ssh-linux-server-windows/) if you are unsure how to SSH into your server. Once you have logged into your server, you will see the provided LAMP Notes. > Note: Make note of your current “root database password” as we will need it later to change it to a user-defined password for security reasons.   ![LAMP Notes](https://www.atlantic.net/wp-content/uploads/2018/01/lamp9.png) LAMP Notes   You will want to verify everything was installed correctly and is working. To check Apache, go to http://. If it is installed, you will see this.   ![Apache Default Page](https://www.atlantic.net/wp-content/uploads/2018/01/lamp10.png) Apache Default Page   To verify MySQL is installed and working, run the following command ``` service mysql status ``` You will see this result if it is running   ![MySQL status](https://www.atlantic.net/wp-content/uploads/2018/01/lamp11.png) MySQL status   To make your MySQL more secure and to change the database root password from the provided one, run the following command: ``` mysql_secure_installation ``` When you log into your server, you will first be prompted to enter the current root password for MySQL, provided in the LAMP Notes. Once you have entered the correct password, you will be asked to change the root password. You would type “y” and then enter if you would like to change it. After changing your password, you will be prompted to answer a couple more questions that will make your MySQL secure by removing anonymous users, disallowing root login remotely, removing the test database, and access to it (Ignore error as the database does not exist) and then reloading the privilege tables. Once done, you are complete with MySQL! ### Verifying PHP We will create a basic PHP script to verify that PHP is installed and working properly. We will save this article under the web root directory as test.php. In Ubuntu 14.04, the web root directory is located at /var/www/html. We will create the file at that location by running the following command: ``` nano /var/www/html/test.php ``` This will open an empty file, and we want to input the following text. `` Save and close the file. We will now test if the server can generate the PHP script. You will want to go to your browser and enter the following URL: ``` http:///test.php ``` If your server can translate the PHP script correctly, you will see something similar to the below picture.   ![PHP Information page](https://www.atlantic.net/wp-content/uploads/2018/01/lamp12.png) PHP Information page   Once you have verified all components of the LAMP installation, you can begin configurations for your site! Come back and check for updates! --- # How to Install Apache on Arch Linux > URL: https://www.atlantic.net/vps-hosting/how-to-install-apache-arch-linux/ | Published: 2015-06-19 | Updated: 2024-06-05 | Author: Jose Velazquez ##### Verified and Tested 05/29/15 ## Introduction Apache is a web server that is very popular in Linux systems and over the Internet. It is used by many web hosting companies worldwide because of its popularity and efficiency in hosting sites over the World Wide Web. This how-to will help you install and configure Apache on an Arch Linux server. ## Server Preparation To get started, log in to your Arch Linux server. Let’s make sure that your server is fully up-to-date. ``` sudo pacman -Syu ``` We can continue the process and install Apache on your Arch Linux server with the server up-to-date. ## Install Apache on Arch Linux We must first begin by installing Apache with the following command: ``` sudo pacman -S apache ``` Start the Apache service with the following command: ``` sudo systemctl start httpd ``` To edit the main Apache configuration file for one or many websites, according to your preference, open the configuration file located in the following directory: ``` sudo nano /etc/httpd/conf/httpd.conf ``` To test the installation, create a test HTML file in the following directory with the command below: ``` sudo nano /srv/http/index.html ``` Insert the following HTML code in the empty file, then save and exit: ```

CONGRATULATIONS

You have just installed Apache on your Arch Linux Server

``` You can now verify that Apache is installed correctly by typing `http://` and your IP address in your browser. ``` http:// YOUR.IP.ADD.RESS ``` To get your server’s public IP address, type the following command: ``` curl icanhazip.com ``` ![This is the test page created to verify the Apache install in Arch Linux.](https://www.atlantic.net/wp-content/uploads/2018/01/Install-Apache-on-Arch-Linux-1.jpg) This is the test page created to verify the Apache install in Arch Linux. ## What Next? Congratulations! You now have a server installed and configured with Apache. You may now continue building your website(s). Thank you for following along, and feel free to check back with us for further updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Nginx on a Arch Linux Cloud Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-nginx-arch-linux/ | Published: 2015-06-22 | Updated: 2026-01-15 | Author: Jose Velazquez ##### Verified and Tested 06/22/15 ## Introduction This tutorial shows you how to install Nginx on an Arch Linux Cloud Server. Nginx is known for its high performance and low memory usage, allowing fewer resources to be used while efficiently getting the job done. ## Prerequisites You need an Arch Linux server configured with a static IP address. If you do not have a server already, why not consider one of our SSD [VPS Hosting](https://www.atlantic.net/vps-hosting/) solutions. ## Server Preparation Let’s make sure that your server is fully up-to-date to get started. ``` sudo pacman -Syu ``` We can continue the process and install nginx on your server with the server up-to-date. ## Install Nginx on Arch Linux We begin by installing nginx with the following command: ``` sudo pacman -S nginx ``` Start the nginx service with the following command: ``` sudo systemctl start nginx.service ``` To edit the main Nginx configuration file for your website(s), open the `nginx.conf` file with your preferred text editor. This file is located in the following directory: ``` sudo nano /etc/nginx/nginx.conf ``` You can now verify that nginx is installed correctly by typing http:// and your IP address in your browser. ``` http:// YOUR.IP.ADD.RESS ``` > To get your servers IP Address type the following command: > > ``` > curl -s icanhazip.com > ``` ![This is the default page after Nginx has been installed in an Arch Linux server](https://www.atlantic.net/wp-content/uploads/2018/01/started10.png) This is the default page after Nginx has been installed in an Arch Linux server. ## What Next? Congratulations! You have now installed and configured nginx. Thank you for following along, and feel free to check back with us for further updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install and Use fail2ban in Ubuntu and Debian > URL: https://www.atlantic.net/vps-hosting/how-to-install-fail2ban-ubuntu-debian/ | Published: 2015-06-23 | Updated: 2026-01-15 | Author: Jason Mazzota ##### Verified and Tested 02/17/2015 ## Introduction Fail2ban is an excellent service primarily used to stop brute-forcers from accessing your system. Fail2ban works great at deterring your primary attackers away by blocking them when it determines an attack may be happening. We will be performing the steps below as the root user. You will need to sudo if you are using another user. For all editing of configuration files, we will be using vi; however, you can use any editor of your choice. This installation is performed on an Ubuntu 14.04 64bit Cloud server with IPTables installed per our IPTables guide. This guide is also applicable to our Ubuntu 12.04 OS and Debian. ## Prerequisites An Ubuntu 14.04 64bit server. If you do not have a server and would like one, consider SSD [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Alantic.Net. ## Install and Use fail2ban in Ubuntu and Debian Fail2ban is included in the default Ubuntu and Debian repository. To install, run: ``` apt-get install fail2ban ``` Once you have installed it, we need to make only a few changes to the configuration. When modifying configuration files like this, the best practice is always to copy out the original to a backup. In this case, you can leave the original alone as fail2ban does work with a duplicate .local file is also named jail. To do this, run: ``` cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local ``` Once you’ve made that .local file, it’s time to edit it with your editor. ``` vi /etc/fail2ban/jail.local ``` Now, as you’ll see when editing the file, there are A LOT of sections for you to “play” with and adjust. The main ones we’ll focus on are the ignoreip, bantime, findtime, maxretry, and specifically [ssh] sections. ![An example of what the /etc/fail2ban/jail.local file looks like](https://www.atlantic.net/wp-content/uploads/2015/06/fail2ban.png) An example of what the /etc/fail2ban/jail.local file looks like Note: In Ubuntu 12.04 and Debian, the configuration file looks slightly different from the above. You will only see ignoreip, bantime, and maxretry. As far as we are concerned here, the rest of the configuration is the same. In the picture above, at the green indicator at the top, you will find the ignoreip. The ignoreip is essential as you can tell fail2ban to IGNORE your IP address. Setting ignoreip to the correct IP will prevent you from ever locking yourself out of your server by fail2ban. We highly recommend you add your IP address to this field. To add it, all you need to do is add a space after the 127.0.0.1/8 and put your IP. Below the green indicator, you will find the bantime. As it states, this is how long a host is banned when triggered for banning. The bantime is the number of seconds that you want that IP address blocked from your system. We recommend that you set this to a high number if you are gunning for someone to be blocked. The default is 10 minutes. Adding a 0 will make it 6000 seconds or 100 minutes (just over an hour and a half.) That’s a good start. In Ubuntu 14.04, the next section is the findtime. As it states, this is the period fail2ban will look at for failed attempts. The default setting here of 10 minutes (600) is acceptable. Under the findtime (or bantime in Ubuntu 12.04), you will find the maxretry. As it sounds, this is how many times you’ll be allowed to fail the login within the findtime before the origin IP gets added to the ban for what you have set the bantime to be. 3 is a great number here to catch someone attempting to get in. The last section we’ll look at is for [ssh]. You can see the section in the picture below. The biggest thing here to edit is the maxretry (each section can re-write your default maxretry to its own value) and the “port =” section. Maxretry means how many times a person can fail to attempt SSH to your server before being blocked. The lower this number, the better, but you also want to be safe to allow some retries, just in case. In the “port =” section, you’ll see the port is set to “ssh.” If you have not changed your SSH port, this is fine. If you have configured a custom SSH port like described in [Changing your SSH Port In Ubuntu](https://www.atlantic.net/vps-hosting/), you will want to change the port= section. For example, using our custom SSH port: ``` port = 922 ``` ![The location on where you can set the ssh port](https://www.atlantic.net/wp-content/uploads/2015/06/fail2ban2.png) The location on where you can set the ssh port Once you have changed this configuration to your liking, you need to save the changes you made and exit the file. Once out, restart the fail2ban service to activate it. ``` service fail2ban restart ``` If you have installed IPTables like in our guide referenced at the beginning, then there is one more step you will need to take. It would help if you wrote your IPTables out to the IPTables rules.v4 file to save the changes that fail2ban has implemented. To do this, you run a: ``` iptables-save > /etc/iptables/rules.v4 ``` If you check your rules.v4 file, you will see that there is now a rule for fail2ban in place.  This is the rule fail2ban put in place when installed and is needed to stop anyone who fail2ban blocks. In the future, when adding new services on the server (like FTP, email, etc.), make sure you check your fail2ban configuration! Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to: Joining A Windows Server 2012 To A Domain > URL: https://www.atlantic.net/vps-hosting/how-to-joining-windows-server-2012-domain/ | Published: 2015-06-24 | Updated: 2026-01-15 | Author: Ariel Beltre ##### Verified and Tested 03/24/2015 ## Introduction In this article, we will be going over joining a Windows Server 2012 to an Active Directory Domain. Before you can complete this process, keep in mind that the server must first communicate with the domain. This means that the server’s IP address configuration must reference the domain’s DNS server. Here we will demonstrate how to complete this process. ## Joining A Windows Server 2012 To A Domain To join the server to a domain, move your mouse to the lower-left corner of the screen and then right-click on the Start tile. Select the System Command from the Start tile’s menu. When the System dialog box appears, click the Change Settings link, shown below. ![Screenshot of the "System" dialog box in Windows Server 2012](https://www.atlantic.net/wp-content/uploads/2018/01/domain1.png) Screenshot of the “System” dialogue box in Windows Server 2012 The server should now display the System Properties sheet. Ensure that the Computer Name tab is selected, and then click the Change button. When Windows displays the Computer Name/Domain Changes dialog box shown below, enter your domain name and click OK. Windows will locate the domain and then prompt you for a set of administrative credentials. When the domain join completes, you will be prompted to restart the server. ![Screenshot of the "Computer name/Domain changes" window in Windows Server 2012](https://www.atlantic.net/wp-content/uploads/2018/01/domain2.png) Screenshot of the “Computer Name/Domain changes” window in Windows Server 2012 ## Conclusion Joining a domain to a Windows Server 2012 is relatively straightforward. With just a few clicks, you can assign an active domain to your Windows server without issue. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install FAMP (FreeBSD 10, Apache, MySQL, PHP) on a Cloud or VPS Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-famp-freebsd-cloud-vps-server/ | Published: 2015-06-25 | Updated: 2026-01-15 | Author: Jose Velazquez ##### Verified and Tested 06/15/15 ## Introduction This how-to will help you with your FAMP installation in FreeBSD 10 so that you can successfully run a high available stable platform for your web environment. FAMP is simply a software bundle that consists of 4 components that work together to form a powerful web server.  However, in this setup, the acronyms are as follows: FreeBSD (**F**) is the platform’s core, which will sustain the other components. Apache (**A**) is used for the web service. MySQL (**M**) is used for database management,  and PHP (**P**) is used as the programming language. ## Prerequisites You need a FreeBSD server that is configured with a static IP address. If you do not have a server already, you can visit our [VPS hosting](https://www.atlantic.net/vps-hosting/) options page and spin a new server up in under 30 seconds. ## Install FAMP on FreeBSD 10 To get started, log in to your FreeBSD server via SSH or through the VNC Console [here. Atlantic.Net Cloud servers](https://cloud.atlantic.net/?page=userlogin)are set up as minimal installations to avoid having unnecessary packages from being installed and never used. If some software packages that you’re used to using aren’t installed by default, feel free to install them as needed. Let us download nano so we can simplify this tutorial. ``` pkg install nano ``` Let’s make sure that your server is fully up-to-date so we can complete the preparation. ``` freebsd-update fetch freebsd-update install ```   We can continue the process and install FAMP on your server with the server up-to-date. ## Install Apache on FreeBSD 10 Begin by installing Apache with the following command: ``` pkg install apache24 ``` Enable and start the Apache service with the following commands: ``` sysrc apache24_enable=yes service apache24 start ``` To edit the main Apache configuration file for one or many websites according to your preference, they are configured in the following directory: ``` nano /usr/local/etc/apache24/httpd.conf ``` To verify and test the installation, create/edit the test HTML file in the following directory with the command below: ``` nano /usr/local/www/apache24/data/index.html ``` Insert/replace the following code in the HTML file, then save and exit: ``` CONGRATULATIONS

You have just installed Apache on your FreeBSD Server

``` You can now verify that Apache is installed correctly by typing http:// and your IP address on your browser(http:// YOUR.IP.ADD.RESS ). To get your server’s IP Address, enter the following command: ``` ifconfig vtnet0 | grep "inet " | awk '{ print $2 }' ``` ![This is the test page created to verify Apache was installed correctly in FreeBSD](https://www.atlantic.net/wp-content/uploads/2018/01/famp1.jpg) This is the test page created to verify Apache was installed correctly in FreeBSD Restart the Apache service so the changes can take effect on your system. ``` service apache24 restart ``` ## Install MySQL on FreeBSD 10 We then would like to continue by installing MySQL. After running the following MySQL, command hit enter to select y to confirm your installation by tapping Enter. ``` pkg install mysql55-server ``` Enable and start the MySQL service with the following commands: ``` sysrc mysql_enable=yes service mysql-server start ``` To ensure the security of the default settings of MySQL, continue with the command below: ``` mysql_secure_installation ``` Note: When prompted with “Enter current password for root,” hit enter for none then Y(Yes) to set the MYSQL password. You will then be prompted with a series of questions. Just type Y for yes on all of them. See the screenshot below: ![This is the secure installation of screen when installing MySql on a FreeBSD FAMP Stack server](https://www.atlantic.net/wp-content/uploads/2018/01/famp2.jpg) This is the secure installation of the screen when installing MySql on a FreeBSD FAMP Stack server ## Install PHP on FreeBSD 10 Finally, we will conclude with the FAMP Stack by installing PHP and configuring it to work with Apache. ``` pkg install mod_php56 php56-mysql php56-mysqli ``` With PHP installed, we can begin the preparation to configure it with Apache. Copy the sample PHP configuration file to the correct location. ``` cp /usr/local/etc/php.ini-production /usr/local/etc/php.ini ``` Then run the following command to refresh the new changes to the system. ``` rehash ``` Update the Apache Configuration file with the following command: ``` nano /usr/local/etc/apache24/httpd.conf ``` Locate the DirectoryIndex line and add index.php to the existing index.html, so Apache reads the PHP files. The line should look like the following: ![This is how the Apache file output after adding index.php to the configuration](https://www.atlantic.net/wp-content/uploads/2018/01/famp3.jpg) This is how the Apache output should look after adding index.php to the DirectoryIndex line (note: use the Ctrl+w in nano to search **DirectoryIndex**) Add the following lines at the bottom of the configuration file so Apache can function PHP information accordingly. ``` SetHandler application/x-httpd-php SetHandler application/x-httpd-php-source ``` Fantastic! You can now save the file and restart Apache, so all your configurations take effect. ``` service apache24 restart ``` To verify and test the installation, create a test PHP file in the following directory with the command below: ``` nano /usr/local/www/apache24/data/info.php ``` Insert the following PHP code in the empty file, then save and exit: ``` ``` Restart the Apache HTTP service one last time, so all the changes take effect. ``` service apache24 restart ``` You can now verify that PHP is installed correctly by typing the following on your browser. http:// YOUR.IP.ADD.RESS/info.php ![This is the default page after installing PHP on an FAMP Stack FreeBSD server](https://www.atlantic.net/wp-content/uploads/2018/01/famp4.jpg) After installing PHP on a FAMP Stack FreeBSD server, this is the default page. ## What Next? Congratulations! You now have a server with a FAMP Stack platform for your web environment. Thank you for following along, and feel free to check back with us for further updates or learn more about services from Atlantic.Net, like [VPS hosting](https://www.atlantic.net/vps-hosting/). --- # How to Configure Apache and Create a Website Configuration on CentOS 7 > URL: https://www.atlantic.net/hipaa-compliant-wordpress-hosting/how-to-configure-apache-create-website-configuration-centos-7/ | Published: 2015-06-26 | Updated: 2026-01-15 | Author: Jason Mazzota ##### Verified and Tested 02/04/2021 ## Introduction This tutorial will show you how to configure a basic configuration (conf) file for Apache on CentOS 7 and create a website. For example, this will show where you can change the web path of your websites, how to assign a public IP to a website, how to enable extensions, and how to allow your site to pick up pages like .php for an index. ## Prerequisites A server running CentOS 7 has either Apache 2.2 or LAMP already installed. For information on Apache or LAMP installation, [please see this walk-through here](https://www.atlantic.net/vps-hosting/how-to-install-lamp-centos-7-2/). ## Configure Apache Basic Configuration So the first thing to realize is that your configuration file is located in “/etc/httpd/conf/httpd.conf” by default. The httpd.conf will be making most of the changes for websites without an SSL. Look for the SSL configuration lower in the tutorial for websites with an SSL. Before making any changes to the configuration, let’s go through and ensure that everything appears how we’d like it to for the base configuration of Apache. Go ahead and open /etc/httpd/conf/httpd.conf into a text editor of your choice. What you will want to do first is a search for the “Listen” field. This setting binds Apache to the port/IP you specify for websites. By default, your conf should state: ``` Listen 80 ``` This means that Apache is listening (binding) on all your IPs on the server on port 80. Now let’s say you have an additional IP and want ONLY that IP for websites. What you will need to do is change the Listen line to look like: ``` Listen x.x.x.x:80 ``` Where “x.x.x.x” is the IP, you want the websites to run on. Why is this viable? Say you have multiple IPs on your server, but you want to limit what each IP does on your system. This allows you to confine all basic (non-SSL) HTTP processes onto being handled on one IP. If you have multiple IPs (but not all IPs!) that you want Apache to bind to, you only need to add more “Listen x.x.x.x:80” lines for each IP. Also, you can change the port “80” to another port if you’d like. This is useful if you have port redirects in place or have a particular IP that needs to have Apache listening on a different port. By default, all browsers use port 80 to browse and pull up web pages. Unless you have a reason to change this, it’s best to leave the port at “80”. For now, we will keep this field the default of “Listen 80”.   Let’s now look at the following field you’d want to edit named “ServerAdmin.” ServerAdmin is simply the email address Apache will email if there is a problem. By default, it appears like below: ``` ServerAdmin root@localhost ``` If you want to receive notifications regarding Apache/httpd, put your email address there. If you don’t, you can either leave it how it is or put a “#” in front of the line to comment it out.   The following line we want to look at is pretty close after “ServerAdmin,” it’s called “ServerName.” ServerName is just how it sounds. It’s the name for the server to identify itself. Say you want server.yourdomain.tld to resolve to an http page. What you would do is set ServerName to something like: ``` ServerName server.yourdomain.tld:80 ``` If you do not have a domain or subdomain that you want to use for the ServerName, you can set this to be your IP like: ``` ServerName x.x.x.x:80 ``` Where x.x.x.x is your IP address. If you specified a Listen IP, you would also want to use that IP here. For both of these options, if you customize the Listen port, you will need to apply that value here instead of “80” as well.   By default, ServerName is commented out. You will want to remove the “#” in front of the line to put the value into play. No matter what you put here, you need to add either a subdomain or an IP address. If you do not, any type of server-generated redirection you do on the server will not take effect.   These are the main fields you will want to edit for a base configuration before adding anything additional. It confirms that Apache is running on the port and IPs you want. There are other configuration options available, of course, and each field has a block of text explaining what it is used for, but unless you have reason to edit these, it is best to leave them at their default values. To have the changes take effect, exit, save the conf file, and run: ``` systemctl restart httpd ``` Once restarted, all changes will take effect. We can now proceed to make a new configuration file for a website. ## Website configuration time! In our example here, we will be using VirtualHosts. What is a VirtualHost? It allows the IP address specified as a VirtualHost to host multiple websites on it! Super helpful if you have more than one site on your server. It also allows you to customize the fields of where to pull the site, what kind of permissions it’s granted in terms of overwriting default values, and so forth. So how do we set this up? The first thing to tell Apache what IP and port will be a VirtualHost. To do this, at the end of your Apache conf file, add: ``` NameVirtualHost x.x.x.x:80 ``` Where x.x.x.x is the IP address, you will have sites pulling on, and 80 is the port you have specified, each from the basic configuration above. If you have no additional IP addresses and have Apache running off your server and it’s main IP, put your primary IP address here. We have two options on how to proceed here. 1) We can keep all our VirtualHosts located in the Apache configuration file (httpd.conf) or 2) We can break sites into their own files. What you do is up to you. If you don’t have many sites, option 1 is perfectly fine. If you are planning to have a lot of websites, you may wish to consider option 2. Either way will work with the VirtualHost conf block, but this is how you will enable option 2. At the end of your httpd.conf, put: ``` Include /path/to/site/confs ``` And save and exit the file. “/path/to/site/confs” is your path where you will be putting all your website configuration files. With option 2 you will now want to make a new conf (/path/to/site/confs/domain.tld.conf) that contains the VirtualHost configuration for each website.   Regardless of the option, you choose above. This is how you will want to start your VirtualHost block. ``` ``` Below is a sample finished Apache configuration for mycooldomain.com. These are the outside brackets, so to say, of your website’s Apache configuration. We will fill in the space between information like user, directory location, and aliases. ``` SuexecUserGroup mycooldomain usergroup DocumentRoot /home/mycooldomain.com/html/ ServerName www.mycooldomain.com ServerAlias mycooldomain.com *.mycooldomain.com ScriptAlias /cgi-bin/ "/home/mycooldomain.com/html/cgi-bin/" Alias /adifferentlocation /home/adifferentlocation/html/   Options Indexes MultiViews Includes Order allow,deny Allow from all AddHandler cgi-script .cgi .pl Options ExecCGI AllowOverride None Order allow,deny Allow from all AllowOverride None Order deny,allow Allow from all DirectoryIndex index.php index.html index.htm   AddType application/x-httpd-php .php4 .php3 .phtml .php CustomLog /home/weblogs/mycooldomain.com.log combined ```   Now let’s take a look at what’s going on. First, we’ll take the section outside the tags at the top. *SuExecUserGroup* – This is the field your user and the user’s group for the website goes in. It’s a good idea to have the user be the user who belongs to this website to prevent confusion. This lets it know who to run CGI. *DocumentRoot* – This is pretty self-explanatory in that it is the root (parent) folder for your website files. This tells Apache where to direct the site to look for files. *ServerName* – This tells Apache the website to use about the rest of the fields. It is how Apache knows that it pulls all of the followed specified information for your website. *ServerAlias* – This is different names that Apache can use for the ServerName. They are alias’ to the ServerName. *ScriptAlias* – This is an alias used to mark a directory containing CGI scripts and essentially shortcutting it. We make the alias /cgi-bin/, so we don’t have to type the whole path every time we reference that directory. *Alias* – This is an alias for directory paths. It resolves like mycooldomain/adifferentlocation, but the “adifferentlocation” isn’t under or included in the original website director. In our case, we used it to shortcut an entirely different path to a simple /adifferentlocation.y.   Then the section at the very bottom. *AddType* – This maps the specified extensions to a specific MIME-type. In our case, we’re putting some common php file extensions mapped to the PHP MIME-type. This allows us to name our php files .php, .php4, and so on and have PHP process it correctly. *CustomLog* – This specifies a log location for only this website. The *combined* is a nickname if you wish to have a *LogFormat* specified to match this log. In our case, we do not have a specific *LogFormat.*   And now we’ll take the things in the tags. *AddHandler* – This allows you to list extensions (like .cgi, .pl) that will be handled by a specific handler, in our case, cgi-script. *Options* – This controls which server features are available in a given directory. They include: – All – This allows all options except Multiviews. This is the default setting. – ExecCGI – This allows for the execution of CGI scripts FollowSymLinks allows the server to follow symbolic links in the directory. – Includes – This allows the server to use includes. – IncludesNOEXEC – This allows the server to use includes with the exceptions of exec cmd and exec cgi. – Indexes – If the directory has no index page, it will list what is in the directory. – Multiviews – This allows for content negotiated Multiviews. SymLinksIfOwnerMatch allows the server to follow symbolic links if the “link to” location is owned by the website owner. If another user owns a file, it will not work. *AllowOverride* – This controls what overrides are allowed by a .htaccess file. This can be All or None (allows all or no overrides), AuthConfig (enables authorization directives to), FileInfo (allows document type controlling), Indexes (allows control over directory indexing), Limit (allows control over host access), and Options (allows control over directory features.) *Order* – This is an access control system. This has two real options. They are either “Allow,Deny” or “Deny,Allow.” The third option, “Mutual-failure,” is deprecated.  This order tells the system to process allows first and denies second, or vice-versa. You can specify these in the Allow From/Deny From that follow. *Allow from* / *Deny from *– This allows you to edit a list by hostname or IP, or just all regarding access. The order in the processing is determined by the *Order* option above. *DirectoryIndex* – This specifies which index-type pages you want to have behaved as the index page. Whether php or html or another format.   From this and changing the example config here to fit your needs, you can have a website up and running in any location you specify on your server.   ### SSL Configuration The SSL configuration file is similar to a standard Web configuration Virtualhost, but you want to make changes in the port and add a few things to it. The SSL configuration is in addition to the standard configuration file above and is treated as it’s own Virtualhost. ``` SuexecUserGroup mycooldomain usergroup DocumentRoot /home/mycooldomain.com/html/ ServerName www.mycooldomain.com ServerAlias mycooldomain.com *.mycooldomain.com ScriptAlias /cgi-bin/ "/home/mycooldomain.com/html/cgi-bin/" Alias /adifferentlocation /home/adifferentlocation/html/ SSLEngine on SSLCertificateFile /etc/httpd/conf/ssl.crt/www.2die4jewels.com.crt SSLCertificateKeyFile /etc/httpd/conf/ssl.key/www.2die4jewels.com.key SSLCACertificateFile /etc/httpd/conf/ssl.crt/thwate_intermediate.crt SSLCipherSuite ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP SSLOptions +StdEnvVars Options Indexes MultiViews Includes Order allow,deny Allow from all SSLOptions +StdEnvVars AddHandler cgi-script .cgi .pl Options ExecCGI AllowOverride None Order allow,deny Allow from all SSLOptions +StdEnvVars AllowOverride None Order deny,allow Allow from all DirectoryIndex index.php index.html index.htm SSLOptions +StdEnvVars   AddType application/x-httpd-php .php4 .php3 .phtml .php CustomLog /home/weblogs/mycooldomain.com.log combined ```   Now let’s take apart the additions which are italicized. *SSLEngine* – This tells Apache to turn on the SSL options for this VirtualHost. *SSLCertificateFile* – This is the path to your certificate (.CRT) file. *SSLCertificateKeyFile* – This is the path to your certificate’s key (.key) file. *SSLCACertificateFile *– This is the path to the Intermediate (CA) certificate (.CRT) file. This is typically provided by the company you purchased your SSL through. *SSLCipherSuite* – This string with cipher-specifications separated by colons configures the Cipher Suite the visitor is allowed to negotiate on. It tells Apache which SSL “formats” you could say to accept. *SSLOptions* – This is used to control various run-time operations. The option we used +StdEnvVars allows the standard set of CGI/SSI related to SSLs. Because of the number of tools, this has to load and the fact it is only used for CGI/SSI, we have put it in it’s own block that deals specifically with shtml and cgi pages.   And that’s it. Those are the basics you need for an Apache configuration file to get a standard website and SSL website up and running. You can always do more options and tweaks that I haven’t included,[and you can always read about them on the Apache page](http://httpd.apache.org/docs/2.2/). Thank you for following this how-to. Please check back here for more updates and consider a market-leading [HIPAA-compliant WordPress hosting](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/) server from Atlantic.Net. Learn more about [HIPAA Compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). --- # How to: Basic Bash Administration Tools On Linux (df, fdisk, top, free, iostat, ifconfig, sensors, stat, nmap, and netstat) > URL: https://www.atlantic.net/vps-hosting/how-to-basic-bash-administration-tools/ | Published: 2015-06-29 | Updated: 2023-11-18 | Author: Andrew Mora ##### Verified and Tested 02/26/15 ### Introduction This tutorial is a brief rundown of the BASH shell commands and tools that come in handy for the Linux administrator. Focus more on tools for administration, as opposed to the basic usage of Linux-based Operating Systems. While this article is being written in the context of distros based on RHEL 4+ and Debian 6+, many of these commands may also be found on BSD, FreeBSD, any other Unix systems. Depending on your Operating system, each command’s flag may differ or may not exist for the respective Operating System. ### Prerequisites RHEL 4+ and Debian 6+ based Operating Systems, including CentOS and Ubuntu. If you do not have a server, you can start up a reliable Linux server from Atlantic.Net in under 30 seconds. ## Basic Bash Administration Tools I will be providing a Need coupled with the BASH command that can satisfy this need. Keep in mind that each command may have many more functions and command-line options available than the examples I’ll show below. I’ll be sticking to the basic commands that attain the bare minimum output you desire. I encourage all of you to read the manual page for each command. I need to: ## Find out how much hard drive space I have left | Command: df ``` # df -h Filesystem Size Used Avail Use% Mounted on /dev/sda1 79G 2.2G 73G 3% / tmpfs 939M 0 939M 0% /dev/shm ``` ## List my available hard drives | Command: fdisk ``` # fdisk -l Disk /dev/sda: 85.9 GB, 85899345920 bytes 255 heads, 63 sectors/track, 10443 cylinders Units = cylinders of 16065 * 512 = 8225280 bytes Sector size (logical/physical): 512 bytes / 512 bytes I/O size (minimum/optimal): 512 bytes / 512 bytes Disk identifier: 0x00015f65 Device Boot Start End Blocks Id System /dev/sda1 1 10444 83884032+ 83 Linux ``` ## View my systems resources(running tasks, CPU utilization) | Command: top ``` # top top - 10:44:56 up 101 days, 25 min, 1 user, load average: 0.00, 0.01, 0.00 Tasks: 99 total, 1 running, 98 sleeping, 0 stopped, 0 zombie Cpu(s): 0.1%us, 0.0%sy, 0.0%ni, 99.8%id, 0.0%wa, 0.0%hi, 0.0%si, 0.0%st Mem: 1922380k total, 1627448k used, 294932k free, 164252k buffers Swap: 0k total, 0k used, 0k free, 1267812k cached PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND 8655 root 20 0 15032 1068 808 R 2.0 0.1 0:00.01 top 1 root 20 0 19232 1420 1140 S 0.0 0.1 0:35.85 init 2 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kthreadd 3 root RT 0 0 0 0 S 0.0 0.0 0:02.20 migration/0 4 root 20 0 0 0 0 S 0.0 0.0 0:02.05 ksoftirqd/0 5 root RT 0 0 0 0 S 0.0 0.0 0:00.00 migration/0 6 root RT 0 0 0 0 S 0.0 0.0 0:20.04 watchdog/0 ``` ## View my systems memory utilization | Command: free ``` # free -m total used free shared buffers cached Mem: 1877 1589 288 0 160 1238 -/+ buffers/cache: 190 1686 Swap: 0 0 0 ``` ## View my systems disk activity | Command: iostat ``` # iostat 2 Linux 2.6.32-431.el6.x86_64 (nginxs) 05/11/2015 _x86_64_ (2 CPU) avg-cpu: %user %nice %system %iowait %steal %idle 0.11 0.00 0.05 0.02 0.00 99.83 Device: tps Blk_read/s Blk_wrtn/s Blk_read Blk_wrtn sda 0.54 0.10 35.16 863199 306833368 avg-cpu: %user %nice %system %iowait %steal %idle 1.00 0.00 0.25 0.25 0.00 98.50 Device: tps Blk_read/s Blk_wrtn/s Blk_read Blk_wrtn sda 5.00 0.00 88.00 0 176 ``` ## View my network interfaces and IP’s | Command: ifconfig ``` # ifconfig eth0 Link encap:Ethernet HWaddr 00:00:D1:D0:61:AF inet addr:209.208.xx.xxx Bcast:209.208.xx.xxx Mask:255.255.255.0 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:6414823 errors:0 dropped:0 overruns:0 frame:0 TX packets:6864133 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:1325544537 (1.2 GiB) TX bytes:1155254908 (1.0 GiB) eth1 Link encap:Ethernet HWaddr 00:00:0A:D0:61:AF UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:296071 errors:0 dropped:0 overruns:0 frame:0 TX packets:5 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:13464542 (12.8 MiB) TX bytes:398 (398.0 b) lo Link encap:Local Loopback inet addr:127.0.0.1 Mask:255.0.0.0 inet6 addr: ::1/128 Scope:Host UP LOOPBACK RUNNING MTU:16436 Metric:1 RX packets:9813 errors:0 dropped:0 overruns:0 frame:0 TX packets:9813 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:0 RX bytes:775658 (757.4 KiB) TX bytes:775658 (757.4 KiB) ``` ## View my hardware’s temperature readings | Command: sensors ``` # sensors coretemp-isa-0000 Adapter: ISA adapter Core 0: +39.0°C (high = +76.0°C, crit = +100.0°C) coretemp-isa-0001 Adapter: ISA adapter Core 1: +39.0°C (high = +76.0°C, crit = +100.0°C) it8718-isa-0290 Adapter: ISA adapter in0: +1.07 V (min = +0.00 V, max = +4.08 V) in1: +1.92 V (min = +0.00 V, max = +4.08 V) in2: +3.31 V (min = +0.00 V, max = +4.08 V) in3: +2.91 V (min = +0.00 V, max = +4.08 V) in4: +0.34 V (min = +0.00 V, max = +2.10 V) in5: +4.08 V (min = +0.00 V, max = +4.08 V) ALARM in6: +4.08 V (min = +0.00 V, max = +4.08 V) ALARM in7: +3.15 V (min = +0.00 V, max = +4.08 V) Vbat: +3.25 V fan1: 1231 RPM (min = 0 RPM) fan2: 1268 RPM (min = 0 RPM) temp1: -55.0°C (low = +127.0°C, high = +127.0°C) sensor = thermistor temp2: -2.0°C (low = +127.0°C, high = +127.0°C) sensor = thermistor temp3: +20.0°C (low = +127.0°C, high = +127.0°C) sensor = thermal diode ``` ## Get permission level of a file/directory | Command: stat ``` # stat -c '%a' /home/testfile.txt 644 ``` ## Find what ports are open on a remote/local host | Command: nmap > NOTE: You’ll likely have to install the nmap package from your YUM/APT package manager. ``` # nmap -p- localhost Starting Nmap 5.51 ( http://nmap.org ) at 2015-05-11 11:07 EDT Failed to find device eth1 which was referenced in /proc/net/route Nmap scan report for localhost (127.0.0.1) Host is up (0.000011s latency). Other addresses for localhost (not scanned): 127.0.0.1 Not shown: 65528 closed ports PORT STATE SERVICE 21/tcp open ftp 22/tcp open ssh 25/tcp open smtp 80/tcp open http 139/tcp open netbios-ssn 445/tcp open microsoft-ds 9000/tcp open cslistener Nmap done: 1 IP address (1 host up) scanned in 1.52 seconds ``` ## Find out what ports my server is listening on | Command: netstat ``` # netstat -tulnp Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 0.0.0.0:139 0.0.0.0:* LISTEN 5573/smbd tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN 29209/nginx tcp 0 0 0.0.0.0:21 0.0.0.0:* LISTEN 3557/vsftpd tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 18608/sshd tcp 0 0 127.0.0.1:25 0.0.0.0:* LISTEN 9400/master tcp 0 0 0.0.0.0:445 0.0.0.0:* LISTEN 5573/smbd tcp 0 0 127.0.0.1:9000 0.0.0.0:* LISTEN 28996/php-fpm tcp 0 0 :::139 :::* LISTEN 5573/smbd tcp 0 0 :::22 :::* LISTEN 18608/sshd tcp 0 0 ::1:25 :::* LISTEN 9400/master tcp 0 0 :::445 :::* LISTEN 5573/smbd udp 0 0 209.208.x.x:137 0.0.0.0:* 5592/nmbd udp 0 0 209.208.x.x:137 0.0.0.0:* 5592/nmbd udp 0 0 0.0.0.0:137 0.0.0.0:* 5592/nmbd udp 0 0 209.208.x.x:138 0.0.0.0:* 5592/nmbd udp 0 0 209.208.x.x:138 0.0.0.0:* 5592/nmbd udp 0 0 0.0.0.0:138 0.0.0.0:* 5592/nmbd udp 0 0 0.0.0.0:1194 0.0.0.0:* 12988/openvpn ``` Thank you for following along with this guide on Basic Bash Administration Tools. I hope you enjoyed this guide; please check back for more updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to do a Tomcat to Tomcat SSL Transfer on CentOS > URL: https://www.atlantic.net/vps-hosting/how-to-tomcat-tomcat-ssl-transfer-centos/ | Published: 2015-06-30 | Updated: 2026-01-15 | Author: Jason Mazzota ##### Verified and Tested 03/24/2015 ## Introduction In this tutorial, we will be going over a basic way to transfer your SSL from one CentOS 6 x86_64 server running Tomcat to another CentOS 6 x86_64 server running Tomcat. This has been tested on Java 6 and Tomcat 6, as well as Java 8 and Tomcat 8. For the ease of this tutorial, the original server with the SSL will be Server A. The new server that we are transferring to will be Server B. ## Prerequisites You will need two servers with CentOS 6 x86_64 installed, and both servers need to have Java and Tomcat installed. One of the servers has to have an SSL already installed onto it. If you do not have a new CentOS server, you can get a virtual private server from Atlantic.Net. ## Tomcat to Tomcat SSL Transfer on CentOS The easiest way to transfer your certificate between servers is to create a pkcs12 file out of it. Assuming you have the .pem of your certificate, this can be quite easy. If you do not have the .pem, you will need to create one. You can see the [Creating a pem for your SSL](https://www.atlantic.net/vps-hosting/how-to-create-pem-existing-ssl/) page for this. You can copy the key file you generated for the SSL initially into a separate key.pem if it is not a .pem already. In our example, we have done this and have also stripped out the password for the key. To do this, you may view the [How to Remove the Password From Your SSL Key](https://www.atlantic.net/vps-hosting/how-to-remove-password-ssl-key/) page. We are now ready to export the SSL to a .pkcs12 file. To do this, on Server A you just run: ``` openssl pkcs12 –export –name NAME –in certificate.pem –inkey key.pem –out keystore.p12 ``` The keystore.p12 will ask you for a password. Please use a secure password you will remember. For NAME, you will want to use a name you will not forget. It would be best to use your domain name without the .tld (so no .com, .org, etc.) The certificate.pem would be the SSL .pem file you have or just created. The key.pem would be your SSL key in .pem format and they keystore.p12 is what we will be transferring to the new server. You can name all these files as you please. Just make sure you are keeping track of them. You may transfer the keystore.p12 to Server B using whatever method you would like. In our example, we use rsync. ``` rsync keystore.p12 username@IPADDR_of_Server_B:/directory/to/copy/to ``` Once copied, you can move the keystore.p12 to your SSL directory of Server B if you did not copy it there to begin with. We will now want to load the keystore.p12 with java’s keytool on Server B. ``` /path/to/java/keytool –importkeystore –destkeystore /path/to/ssl/directory/keystore.jks –srckeystore /path/to/ssl/directory/keystore.p12 –srcstoretype pkcs12 –alias NAME ``` It should prompt for a new password for the keystore (you may use the same password or create a new one) and the password you created for keystore.p12. NAME should be the same NAME you utilized in the keystore.p12 generation. Once this keystore is created, the hard work is done. To finish this off, you need to edit the Tomcat server.xml on Server B to use this keystore.jks and the passphrase, and you will be good to go. Inside the Tomcat server.xml, you will want to find the section with: “**” that section is surrounded in) and add in at the end (before “*/>*”): ``` keystoreFile=”/path/to/keystore.jks” keystorePass="PASSWORD" ``` Where keystore.jks is the keystore.jks we made, and the PASSWORD is the password you created for the keystore. After this is added, you can restart Tomcat, and your SSL will be in use for Tomcat. ![An example of a tomcat config with the new SSL](https://www.atlantic.net/wp-content/uploads/2018/01/tomcat1-1.png) An example of a tomcat config with the new SSL You will need further configuration for 8443 to be in use, but the SSL will be transferred, and if you log into your manager for Tomcat and check the SSL configuration, you should see that SSLs for 8443 is enabled. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Generate a Certificate Signing Request (CSR) for an SSL > URL: https://www.atlantic.net/vps-hosting/how-to-generate-certificate-signing-request/ | Published: 2015-07-01 | Updated: 2026-01-15 | Author: Alexander Wise ##### Verified and Tested 03/26/17 ## Introduction This article will explain how to generate a Certificate Signing Request (CSR). You will be required to submit a CSR when obtaining an SSL/TLS certificate from a certificate authority (CA). ## Prerequisites Any Linux distribution with OpenSSL installed. If you do not have a server, why not consider a [Linux VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net and be up and running in under 30 seconds. ## Generate a Certificate Signing Request (CSR) Both the CSR and the private key for your server can be generated in one easy step. Be sure to keep access to your private key as restricted as possible, as this unique identifier is used to verify the authenticity of your server. *Note: If you are having trouble running the command successfully, you may need to log in as sudo or root.* ``` openssl req -new -newkey rsa:2048 -nodes -keyout yourdomain.key -out yourdomain.csr ``` You will then be asked for the following information: ``` You are about to be asked to enter information that will be incorporated into your certificate request. What you are about to enter is what is called a Distinguished Name or a DN. There are quite a few fields but you can leave some blank For some fields there will be a default value, If you enter '.', the field will be left blank. ----- Country Name (2 letter code) [XX]: State or Province Name (full name) []: Locality Name (eg, city) [Default City]: Organization Name (eg, company) [Default Company Ltd]: Organizational Unit Name (eg, section) []: Common Name (eg, your name or your server's hostname) []: Email Address []: Please enter the following 'extra' attributes to be sent with your certificate request A challenge password []: An optional company name []: ``` *Note: The challenge password is not related to the private key password. Leave it blank unless required by your certificate authority. You may also leave the “optional company name” question blank.* --- You now have the “.csr” (Certificate Signing Request) file that will need to be submitted to a certificate authority (CA). Once the CA has signed the certificate, it will return a certificate file. The format of the issued certificate will vary depending on the certificate authority.  The most common type will be PEM format which utilize extensions such as **.crt**, **.key**, **.csr**, **.cer**, and **.pem**. --- Depending on the needs of your application or web server, you may need to convert one of these formats to other formats such as PKCS#7, PKCS#12, or DER. Here are a some useful file conversion commands: ## PEM → PKCS#7 (P7B) ``` openssl crl2pkcs7 -nocrl -certfile yourdomain.cer -out yourdomain.p7b -certfile CACert.cer ``` The `-nocrl` option indicates that you will not be including a certificate revocation list (CRL) in the PKCS#7 structure. Most new deployments will use this option, since there will be no older certificates to revoke. Each `-certfile` option indicates a certificate file that will be included in the output file, which is useful in creating a certificate chain including the server certificate and the certificate authority’s intermediate certificate (“yourdomain.cer” and “CACert.cer”, respectively, in the example above). The `-out` option indicates the file name to write the PKCS#7 output to. ## PEM → PKCS#12 (PFX) ``` openssl pkcs12 -export -out yourdomain.pfx -inkey yourdomain.key -in yourdomain.crt -certfile CACert.crt ``` The `-export` option indicates that this command will create a PKCS#12 file. The default behavior without the `-export` option is to parse the input. The `-in` option indicates the PEM-formatted file to be read from. If this file doesn’t also include the private key, you will need the `-inkey` option to indicate the private key file, as well. The `-certfile` option indicates additional certificates to include in the PKCS#12 file, such as intermediate certificates. The `-out` option indicates the file to write the output to, usually a “.pfx” file. ## PEM → DER ``` openssl x509 -outform der -in yourdomain.pem -out yourdomain.der ``` The `-in` option indicates the input certificate file to be converted. The `-out` option indicates the output file name. The `-outform` option indicates the file format for the output (in this example, the input file is in the PEM format, and this command would take that file and create a DER-formatted file). --- # How to Install phpMyAdmin on a CentOS 7 Cloud Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-phpmyadmin-centos-7-cloud-server-vps/ | Published: 2015-07-02 | Updated: 2026-01-15 | Author: Alexander Wise ##### Verified and Tested 07/2/15 ## Introduction This how-to will walk you through the installation process of phpMyAdmin. phpMyAdmin is a tool to directly manage your databases by allowing you to visually add, delete, or modify databases and tables, among other things. phpMyAdmin is written in PHP and is free and open source. ![phpMyAdmin Ship Illustration by Walker Cahall ](https://www.atlantic.net/wp-content/uploads/2018/01/php1-1.png) phpMyAdmin Ship Illustration by [Walker Cahall](http://www.waltronic.net/) ## Prerequisites A CentOS 7 LAMP server is required. If you do not have LAMP installed, [you can follow our guide here](https://www.atlantic.net/vps-hosting/how-to-install-lamp-centos-7/). You will need valid MariaDB credentials to log into your database once phpMyAdmin is installed. This how-to assumes you are using a user with root privileges. You do not have to append `sudo` to the commands below if you are logged in as the root user. ## Install phpMyAdmin on CentOS 7 To install phpMyAdmin quickly on CentOS 7, we are going to install the Extra Packages for Enterprise Linux (EPEL) repo first by running the following command: ``` sudo yum install epel-release ``` During the install, it will prompt “Is this ok?”. Hit “Y” and then Enter. Now we can install phpMyAdmin. ``` sudo yum install phpmyadmin ``` During the phpMyAdmin install, it will prompt “Is this ok?” for the install and then the EPEL key. Hit “Y” and then Enter for each question. The phpMyAdmin installation process will make a configuration file in `/etc/httpd/conf.d/` called `phpMyAdmin.conf`. By default, phpMyAdmin is configured only to accept connections from the server it is installed on. If you want to allow other IPs, you’ll need to open the `phpMyAdmin.conf` file with your preferred text editor. ``` sudo nano /etc/httpd/conf.d/phpMyAdmin.conf ``` In this example, we are using Apache 2.4, so we only need to change the configurations for 2.4. There will be two places that say “Require ip 127.0.0.1”. Below each one we are going to put “Require ip *{your-public-IP}*” For the purpose of this example, we’ll say we want to grant phpMyAdmin access to a workstation with an IP of 192.168.0.2. In this case, we would put “Require ip 192.168.0.2” below “Require ip 127.0.0.1” If you do not know your public IP, you can use [this tool](https://support.google.com/websearch/answer/1696588). The configuration file should like the one below when completed. ``` # Apache 2.4 Require ip 127.0.0.1 Require ip 192.168.0.2 Require ip ::1 # Apache 2.2 Order Deny,Allow Deny from All Allow from 127.0.0.1 Allow from ::1 # Apache 2.4 Require ip 127.0.0.1 Require ip 192.168.0.2 Require ip ::1 # Apache 2.2 Order Deny,Allow Deny from All Allow from 127.0.0.1 Allow from ::1 ``` In Nano to save a close, hit Ctrl+X and then Y and then Enter. > Note: When adding allowed IPs to this file, be sure you only add the IPs for users who require access. The more access you allow, you more you may also increase your server’s exposure to exploit. Now, we can restart Apache so that the changes take place: ``` sudo systemctl restart httpd.service ``` To get to the login page, you need open your browser and go to `http://{your-server's-address}/phpMyAdmin/`. You should get a page that looks like the image below. ![An example of the phpMyAdmin login page](https://www.atlantic.net/wp-content/uploads/2018/01/php2-1.png) An example of the phpMyAdmin login page > Note: If you do not know your IP address, run the following command: > > ``` > ip addr show eth0 > ``` > > ![An example of running the command: ip addr show eth0 and getting 192.168.100.10 for the IP address.](https://www.atlantic.net/wp-content/uploads/2018/01/php3-1.png) An example of running the command: ip addr show eth0 and getting 192.168.100.10 for the IP address.In our example we would put `http://192.168.100.10/phpMyAdmin/` into our browser’s address bar. You can sign in with the root MariaDB credentials that you set-up when installing LAMP. Once logged in, you should get a page similar to the one below. ![An example of the phpMyAdmin default page.](https://www.atlantic.net/wp-content/uploads/2018/01/php4-1.png) An example of the phpMyAdmin default page. Using this interface, you can now easily manage your databases on your CentOS 7 LAMP server. Congratulations! You have just installed phpMyAdmin on your CentOS 7 Cloud Server. Thank you for following along in this How-To! Check back with us for any new updates, and try our line of [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. --- # How to Install LEMP (Linux, Nginx, MySQL, PHP) on a Ubuntu 14.04 LTS Cloud Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-lemp-ubuntu-14-04/ | Published: 2015-07-03 | Updated: 2026-01-15 | Author: Alexander Wise ##### Verified and Tested 07/3/15 ## Introduction This how-to will show you how to install LEMP on a Ubuntu 14.04 cloud server. LEMP is a web service stack that consists of a **L**inux operating system, Nginx (pronounced “**e**ngine-x”), **M**ySQL, and **P**HP. The main difference between LAMP and LEMP is that LAMP uses Apache, and LEMP uses Nginx. LEMP has been gaining popularity in the last few years because it excels in speed and scalability. ![NGINX Car by Walker Cahall](https://www.atlantic.net/wp-content/uploads/2015/08/lemp1.png) NGINX Car by [Walker Cahall](http://www.waltronic.net/) ## Installing LEMP on a Ubuntu 14.04  Cloud Server First we want to make sure that your server is up to date by running the commands: ``` sudo apt-get update sudo apt-get upgrade ``` > Note: Depending on your installation you may need to remove apache2. You can do that by running the commands: > > ``` > sudo apt-get remove apache2* > ``` > > Followed by: > > ``` > sudo apt-get autoremove > ```   ## Installing Nginx on Ubuntu 14.04 To install Nginx, use the command: ``` sudo apt-get install nginx ``` When it asks “Do you want to continue?”, hit Enter. Start the Nginx service with the following command: ``` sudo service nginx start ``` We can now test Nginx by going to your hostname or IP address in your browser’s address bar. If you do not know your server’s IP address, you can run the following command: ``` ifconfig ``` You should get a result similar to the image below. ![An example of ifconfig showing the IP address of 192.168.0.192](https://www.atlantic.net/wp-content/uploads/2018/01/lemp1-1.png) An example of ifconfig showing the IP address of 192.168.0.192 In our example, 192.168.0.192 is the IP address. So in our browser we would go to `http://192.168.0.192`. You should see a web page that looks like the image below. ![This example is the default nginx web page on Ubuntu 14.04](https://www.atlantic.net/wp-content/uploads/2018/01/lemp2-1.png) This example is the default nginx web page on Ubuntu 14.04 Now that Nginx is installed, we can move on to installing MySQL. ## Installing MySQL on Ubuntu 14.04 Install MySQL with the command: ``` sudo apt-get install mysql-server ``` When it asks “Do you want to continue?”, hit Enter. Shortly after, a screen similar to the image below will appear.  You need enter a password for your MySQL root user. It should be a strong password. ![Insert your secure password for your new MySQL root password](https://www.atlantic.net/wp-content/uploads/2018/01/lemp3-1.png) *Insert your secure password for your new MySQL root password* Hit enter to continue. Once you have hit enter, a new screen will appear prompting you to re-enter the password you just picked. ![Retype your MySQL password](https://www.atlantic.net/wp-content/uploads/2018/01/lemp4-1.png) Retype your MySQL password Now that MySQL is installed we need to do the MySQL secure installation by running the command: ``` sudo mysql_secure_installation ``` Enter your MySQL root password. When it asks “Change the root password?”, type “N” followed by Enter. The rest of the questions are up to you. For standard installations, you can hit Enter for the defaults. ![An example of the MySQL secure installation](https://www.atlantic.net/wp-content/uploads/2018/01/lemp5-1.png) An example of the MySQL secure installation Now that MySQL is installed, we can now install PHP. ## Installing PHP on Ubuntu 14.04 Install PHP with the following command: ``` sudo apt-get install php5 php5-fpm php5-mysql ``` When it asks “Do you want to continue?”, hit Enter. For Nginx to work with PHP correctly, we need to edit an Nginx configuration file. In this how-to, we are going to use a simple Nginx config file. First, we need to move the original configuration file to a new file name. Run the command: ``` sudo mv /etc/nginx/sites-available/default /etc/nginx/sites-available/default.old ``` Using a text editor of your choice, we are going to make a file called default in /etc/nginx/sites-available. For nano use the command: ``` sudo nano /etc/nginx/sites-available/default ``` Copy the following into your text editor: ``` server { listen 80; server_name your_site_name.com; root /usr/share/nginx/html; index index.php index.html; location / { try_files $uri $uri/ =404; } error_page 404 /404.html; error_page 500 502 503 504 /50x.html; location = /50x.html { root /var/www/html; } location ~ \.php$ { try_files $uri =404; fastcgi_pass unix:/var/run/php5-fpm.sock; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } } ``` In nano, to exit and save, hit `Ctrl+x` , type “y”, and then Enter. Since we made changes to the configuration file, we need to restart Nginx, by running the command: ``` ``` ``` sudo service nginx restart ``` We are now going to make a simple PHP page to test. Using a text editor of your choice, we are going create a file called `info.php` in `/usr/share/nginx/html/`. ``` sudo nano /usr/share/nginx/html/info.php ``` Copy the following into your text editor. ``` ``` In your browser, you can go to `http://Your-Hostname/info.php` or `http://Your-IP-Address/info.php`. As above, in this example, we would use `http://192.168.0.192/info.php`. You should see a web page similar to the one below. ![An example of the info.php web page](https://www.atlantic.net/wp-content/uploads/2018/01/lemp6.png) *An example of the info.php web page* Once you are done testing, it is a good idea to remove the `info.php` file, since it may give a potential attacker information that can be used to craft a specific attack against your server. To do that run the command: ``` sudo rm /usr/share/nginx/html/info.php ``` Congratulations, you have installed LEMP on Ubuntu 14.04. Thank you for following this how-to. Please check back for more updates, to purchase a [cost-effective virtual private server](https://www.atlantic.net/vps-hosting/), or take a look at our how-to on [Installing WordPress on Ubuntu 14.04](https://www.atlantic.net/vps-hosting/how-to-install-wordpress-ubuntu-14/)! --- # How to Install WordPress on a Nginx LEMP Stack Using Ubuntu 14.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-wordpress-nginx-lemp-ubuntu-14-04/ | Published: 2015-07-06 | Updated: 2026-01-15 | Author: Alexander Wise ##### Verified and Tested 07/3/15 ## Introduction This how-to will show you how to install Nginx, MySQL, PHP and WordPress on an Ubuntu 14.04 cloud server. LEMP is a web service stack that consists of a **L**inux operating system, Nginx (pronounced “**e**ngine-x”) as the web server, **M**ySQL for database management, and **P**HP as the programming language. WordPress is a content management system that is free and open source. ![WordPress Illustration by Walker Cahall](https://www.atlantic.net/wp-content/uploads/2018/01/wp1-1.png) *WordPress Illustration by [Walker Cahall](http://waltronic.net)* ## Prerequisites A server with Ubuntu 14.04 installed. ## Install WordPress on an Nginx LEMP Stack Using Ubuntu 14.04 First we want to make sure that your server is up to date by running the commands: ``` sudo apt-get update sudo apt-get upgrade ``` > Note: Depending on your installation you may need to remove apache2. You can do that by running the commands: > > ``` > sudo apt-get remove apache2* > ``` > > Followed by: > > ``` > sudo apt-get autoremove > ``` ## Installing Nginx on Ubuntu 14.04 To install Nginx, use the command: ``` sudo apt-get install nginx ``` When it asks, “Do you want to continue?”, hit Enter. Start the Nginx service with the following command: ``` sudo service nginx start ``` We can now test Nginx by going to your hostname or IP address in your browser’s address bar. If you do not know your server’s IP address, you can run the following command: ``` ifconfig ``` You should get a result similar to the image below. ![An example of ifconfig showing the IP address of 192.168.0.192](https://www.atlantic.net/wp-content/uploads/2018/01/lemp1-2.png) *An example of ifconfig showing the IP address of 192.168.0.192* In our example, 192.168.0.192 is the IP address. So in our browser we would go to `http://192.168.0.192`. You should see a web page that looks like the image below. ![This example is the default Nginx web page on Ubuntu 14.04](https://www.atlantic.net/wp-content/uploads/2018/01/lemp2-2.png) *This example is the default Nginx web page on Ubuntu 14.04* Now that Nginx is installed, we can move on to installing MySQL. ## Installing MySQL on Ubuntu 14.04 Install MySQL with the command: ``` sudo apt-get install mysql-server ``` When it asks, “Do you want to continue?”, hit Enter. Shortly after, a screen similar to the image below will appear.  You need enter a password for your MySQL root user. It should be a strong password. ![Insert your secure password for your new MySQL root password](https://www.atlantic.net/wp-content/uploads/2018/01/lemp3-2.png) *Insert your secure password for your new MySQL root password* Hit Enter to continue. Once you have hit Enter, a new screen will appear prompting you to re-enter the password you just picked. ![Retype your MySQL password](https://www.atlantic.net/wp-content/uploads/2018/01/lemp4-2.png) *Retype your MySQL password* Now that MySQL is installed, we need to do the MySQL secure installation by running the command: ``` sudo mysql_secure_installation ``` Enter your MySQL root password. When it asks, “Change the root password?”, type “N” followed by Enter. The rest of the questions are up to you. For standard installations, you can hit Enter for the defaults. ![An example of the MySQL secure installation](https://www.atlantic.net/wp-content/uploads/2018/01/lemp5-2.png) *An example of the MySQL secure installation* Now that MySQL is installed, we can install PHP. ## Installing PHP on Ubuntu 14.04 Install PHP with the following command: ``` sudo apt-get install php5 php5-fpm php5-mysql ``` When it asks, “Do you want to continue?”, hit Enter. For Nginx to work with PHP correctly, we need to edit the Nginx configuration file. In this how-to, we are going to use a simple Nginx configuration. First, we need to move the original configuration file to a new filename. Run the command: ``` sudo mv /etc/nginx/sites-available/default /etc/nginx/sites-available/default.old ``` Using a text editor of your choice, we are going to make a file called default in /etc/nginx/sites-available. For nano use the command: ``` sudo nano /etc/nginx/sites-available/default ``` Copy the following into your text editor: ``` server { listen 80; server_name your_site_name.com; root /usr/share/nginx/html; index index.php index.html; location / { try_files $uri $uri/ =404; } error_page 404 /404.html; error_page 500 502 503 504 /50x.html; location = /50x.html { root /var/www/html; } location ~ \.php$ { try_files $uri =404; fastcgi_pass unix:/var/run/php5-fpm.sock; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } } ``` In nano, to exit and save, hit `Ctrl+x`, type “y”, and then Enter. Since we made changes to the configuration file, we need to restart Nginx, by running the command: ``` sudo service nginx restart ``` We are now going to create a simple PHP page to test. Using a text editor of your choice, we are going create a file called `info.php` in `/usr/share/nginx/html/`. ``` sudo nano /usr/share/nginx/html/info.php ``` Copy the following into your text editor. ``` ``` In your browser, you can go to `http://Your-Hostname/info.php` or `http://Your-IP-Address/info.php`. As above, in this example, we would use `http://192.168.0.192/info.php`. You should see a web page similar to the one below. ![An example of the info.php web page](https://www.atlantic.net/wp-content/uploads/2018/01/lemp6-1.png) *An example of the info.php web page* Once you are done testing, it is a good idea to remove the `info.php` file since it may give a potential attacker information that can be used to craft a particular attack against your server. To do that run the command: ``` sudo rm /usr/share/nginx/html/info.php ``` Also, we can remove the default index.html file with the following command: ``` sudo rm /usr/share/nginx/html/index/html ``` Now that LEMP is installed, we can install WordPress ## Setting up the MySQL database for WordPress on Ubuntu 14.04 We are going to start off by setting up the MySQL database by running the following commands: ``` sudo mysql -u root -p ``` When prompted, enter your MySQL root password that you set up when installing MySQL. In MySQL, enter the following commands: ``` create database wordpress character set utf8 collate utf8_bin; ``` Make sure you set a secure password where it says *[insert-password-here]*: ``` grant all privileges on wordpress.* to wordpressuser@localhost identified by "[insert-password-here]"; ``` ``` flush privileges; ``` ``` exit ``` ## Get the Latest WordPress Install on Ubuntu 14.04 Now that the database is created, we can download the latest version of WordPress with the following command: ``` sudo wget http://wordpress.org/latest.tar.gz ``` The latest package will download to the directory that you are currently in, with the file name `latest.tar.gz`. We need to decompress the file by running: ``` sudo tar -xzvf latest.tar.gz ``` ## Configure WordPress on Ubuntu 14.04 Next, we need to copy `wp-config-sample.php` to `wp-config.php`, which is where WordPress gets its base configuration. To do that, run: ``` sudo cp wordpress/wp-config-sample.php wordpress/wp-config.php ``` In your favorite text editor, edit `wordpress/wp-config.php`. ``` sudo nano wordpress/wp-config.php ``` For a basic setup, we need to have the following. ``` define(‘DB_NAME’, ‘wordpress’); define(‘DB_USER’, ‘wordpressuser’); define(‘DB_PASSWORD’, ‘[insert-password-here]’); ``` It should look like this when completed: ![What wp-config.php should look like once you have edited it](https://www.atlantic.net/wp-content/uploads/2018/01/lemp7.png) *What wp-config.php should look like once you have edited it* Next, we need to move the WordPress folder to your web directory. ``` sudo cp -r wordpress/* /usr/share/nginx/html ``` Note: Your web directory may be different based on your configuration. ## Finish Up Through The WordPress Web Installation Now, we can go to the WordPress web installation by entering your hostname or IP address in your browser’s address bar. ![An example of the WordPress web installation](https://www.atlantic.net/wp-content/uploads/2018/01/lemp8.png) *An example of the WordPress web installation* From here, all that is needed to do is to follow along with the WordPress install and give the information required. Congratulations! You have just installed WordPress on an Nginx LEMP stack using Ubuntu 14.04. Check back for more updates. For more information on WordPress, you may want to check out the [WordPress Codex](https://codex.wordpress.org/). ## Atlantic.Net Atlantic.Net offers [VPS hosting](https://www.atlantic.net/vps-hosting/) as well as managed hosting services which include a layer of business-essential managed services to your hosting packages. Contact us today for more information. --- # How to: Managing System Logs with Journalctl > URL: https://www.atlantic.net/vps-hosting/how-to-managing-system-logs-journalctl/ | Published: 2015-07-07 | Updated: 2026-03-03 | Author: Alexander Wise ## Introduction In some of the newer Linux distributions, “init.d” or “rsyslogd” has been replaced by a program called JournalCTL.  Previously, logs were typically found in a particular location for each separate log file, rather than being easy to locate, manage, and manipulate.  Systemd made these log files easier to access by centralizing them, logging all kernel and user processes in one “journal.”  Journalctl is the newest version of this, which makes it even easier to manage these files. In this guide, we will explain the basics of journalctl as well as a brief overview of suggested uses for the program. ## Prerequisites Must have a Linux distribution with journalctl as the system log management program, for example, CentOS 7.  If you do not have a server, consider a super fast SSD [virtual private server](https://www.atlantic.net/vps-hosting/pricing/) from Atlantic.Net. ## Setting System Time Before beginning with anything else, it is highly suggested to set the system time.  Since systemd logs as a binary journal, you can log your records in either UTC or local (server) time.  By default, systemd will display results in local time.  To avoid confusion later on, we will check to ensure that the time is set correct.  Systemd has a built in program called “timedatectl” that is for this purpose. First, check to ensure your time zone is available in the zone options: ``` timedatectl list-timezones ``` This shows all available timezones on your server.  After locating the one matching your location (or your server location), set it: ``` sudo timedatectl set-timezone (zone) ``` Then we will check to ensure this took effect properly: ``` timedatectl status ``` The first line will display the correct time. ## Access Control By default, journalctl users without root privileges can only see their own log files.  The system administrator can grant access to complete log files.  Perform the following command while logged in as the root user ``` usermod -a -G adm username ``` Replace “username” with the name of the user.  This user will receive the same journalctl access as the root user.  However, this control only works when persistent storage is enabled. ## Basic Log Viewing There are a few commands that can be issued at this point. The basic command will display an output of all general entries, displaying oldest entries first: ``` journalctl ``` Though this will give you all the log files, this will give you, well, all the log files.  This means that you will have hundreds or thousands, or more, of log lines displayed if given the chance.  This is similar to what you would see if you were to look in “/var/log/messages/” in previous versions. ## Current Boot Session We also have a command that will display logs that only occurred in the current boot. ``` journalctl -b ``` This means that any information from previous boot sessions will not be shown. ## Previous Boot Sessions Should you need to review logs for previous boot sessions, there is an option for that as well.  Some versions enable logging of previous boot sessions by default.  To ensure that yours is set to log these, we suggest enabling this feature.  This can be done by creating the directory ``` sudo mkdir -p /var/log/journal ``` or by editing the journal configuration file directly ``` sudo nano /etc/systemd/journald.conf ``` In the file, under [Journal], set the “Storage=” option to “persistent” so that persistent logging is enabled.  Save and exit this file and the settings will take effect going forward. Once this has been saved, to view available options for boot files to review, ``` journalctl --list-boots ``` You will see a line for each available boot session.  The offset ID is the first column while the boot ID is the second column.  You can use either the offset ID or boot ID to issue the command: ``` journalctl -b (offset/boot ID) ``` ## Specific Time Frame You may, instead, wish to review the log files by a specified time frame, which may span several boot sessions or limit it to a specified time window within one boot session.  The –since and –until limitations can be placed which will show only events after and prior to the specific log. For all time values, the following format should be used: ``` YYYY-MM-DD HH:MM:SS ``` If you would like to view the events that have happened since 10:00 AM on July 5th, 2015, we can achieve this by the following command: ``` journalctl --since “2015-07-05 10:00:00” ``` Please keep in mind that these will be based either on server time or UTC, depending on what you set in your preferences earlier in this tutorial. If the date is omitted, the journal will assume today’s date.  If the time is omitted, midnight (00:00:00) will be assumed.  You also do not have to include the seconds field, in which case “00” seconds will be assumed. There are also friendly commands, such as ``` journalctl --since yesterday ``` and ``` journalctl --since 02:00 --until “3 hours ago” ``` ## Filtering Options **By Unit** The most useful function available is the unit filtering.  The -u filtering gives the option to view only a specific “unit” allowing you to see things that have happened only in reference to a specific program or systems.  As always, you can add filters for time frames with this. ``` journalctl -u nginx.service ``` or ``` journalctl -u nginx.service --since yesterday ``` **By Process, User, or Group ID** If you have already reviewed enough information to retrieve the PID of the process you are looking for, you can filter for this instead.  This is run with _PID ``` journalctl _PID=4345 ``` **By Location** Filtering based on path locations is also available.  If you are selecting an executable path, journalctl will show all entries related to that executable.  If, for example, you are looking for logs involving bash, ``` journalctl /usr/bin/bash ``` This method usually includes more detailed information on processes and child processes, when available.  Sometimes this is not an option, however. **Kernel Messages** Kernel messages would typically be located in dmesg output, however we can use journalctl to retrieve these as well.  This would be with the -k or -dmesg filter. ``` journalctl -k ``` This will show kernel messages that have occurred during the current boot session.  Again, this can always be modified with the previously mentioned options.  If you wanted to review the kernel messages from the prior boot session, ``` journalctl -k -b -1 ``` **Priority** Priority is often the preferred method of reviewing logs.  Journalctl can be used to display messages only above a certain priority level.  The following is the priority levels: 0: emerg 1: alert 2: crit 3: err 4: warning 5: notice 6: info 7: debug You can use either the name of the priority level or the corresponding number.  If you only wish to see logs of warning priority or above, you can issue the command ``` journalctl -p warning -b ``` or ``` journalctl -p 4 -b ``` **Specified Field** To view the list of journals that occur within a specific field, use the -F modifier ``` journal -F fieldname ``` where “fieldname” is replaced by the field you are seeking.  You also have the option of displaying only log entries that fit a specific condition ``` journalctl fieldname=value ``` ### Truncate or Expand Output Journalctl can be modified to shrink or expand output data display.  By default, journalctl will display the entire entry, requiring you to scroll to the right with the arrow keys.  We can truncate this output instead, which will show an ellipsis for removed information with the –no-full option. ``` journalctl --no-full ``` Alternatively you can tell journalctl to display all of the information, regardless of it considering a character to be unprintable.  This is done with the -a modifier. ``` journalctl -a ``` ### Change to Standard Output By default, journalctl shows output in a pager to make it easier to review.  In the event of modifying or reviewing the information via text manipulation, it may be better and easier to use the standard output with the –no-pager modifier. ``` journalctl --no-pager ``` ### Output Formats If you are using a text editor on journal entries, as we discussed above, the journal can be viewed in other formats as needed.  This can be done with the -o modifier and a format specifier. For example, you can read the journal in JSON by typing ``` journalctl -b -u nginx -o json ``` You can use the following for display options: **cat**— Displays the message field itself **export**— Binary format for transferring or backing up **json** — standard JSON, one entry per line **json-pretty** — JSON format but is easier to read **json-sso**— JSON format wrapped to make add server-sent event compatible **short**— Default syslog output **short-iso** — Default output that shows ISO 8601 wallclock timestamps **short-monotonic** — Default output with monotonic timestamp **short-precise**— Default output with microsecond timestamp **verbose** — Shows all journal fields for that entry, includes hidden ### Active Process Monitoring Journalctl imitates which administrators use tail for monitoring.  This was built into journalctl allowing access to these features without having to pipe in additional tools. ### Displaying Recent Logs The -n option can be used to display a specific amount of records.  Not including a modifying number will display ten (10) results, by default. ``` journalctl -n ``` You can, instead, specify how many entries you would like to see ``` journalctl -n 20 ``` ### Following Logs The -f modifier can be used to follow logs as they are being written. ``` journalctl -f ``` ### Journal Maintenance There are a few commands that can be used to clean up some older logs for the sake of your hard drive space. First, you can find out just how much space is being taken up by journals by using the –disk-usage modifier. ``` journalctl --disk-usage ``` There are two different ways to clean this up.  The first is to shrink the journal based on the size.  This removes entries from oldest to newest until the desired disk space is reached. ``` sudo journalctl --vacuum-size-2G ``` The alternate way to shrink the journal is to a certain date.  The –vacuum-time option deletes any entries up to a certain date. To keep entries only from last year, you can type ``` sudo journalctl --vacuum-time-1years ``` ### Limiting Journal Size You have the ability to place limits on the amount of space journals can take up. ``` nano /etc/systemd/journald.conf ``` These changes can be made with any of the following field modifications **SystemMaxUse=**Maximum disk space **SystemKeepFree=** Amount of space that should be kept available **SystemMaxFileSize=**How large individual journal files can become before being rotated **RuntimeMaxUse=**Maximum disk space that can be used within volatile storage  (/run filesystem) **RuntimeKeepFree=**The amount of space that should be kept available for others in volatile storage (/run filesystem) **RuntimeMaxFilesize=**How large individual journal file can become in volatile storage (within /run filesystem) before being rotated   Thank you for following this how-to. Please check back here for more updates, and to consider a market-leading [VPS hosting](https://www.atlantic.net/vps-hosting/) server from Atlantic.Net. --- # HIPAA Software Certification: Should Application Developers Get HIPAA-Certified? > URL: https://www.atlantic.net/hipaa-compliant-hosting/should-application-developers-get-hipaa-certified/ | Published: 2015-07-07 | Updated: 2026-01-15 | Author: Alexander Wise Is it a good idea for a software developer to get certified for HIPAA? Not necessarily. However, if you want to take advantage of the astronomical growth that healthcare will experience through the end of the decade, then you might want to look into it. Five obstacles that you will encounter are discussed below. - **Would You Like Some Money?** - **Realize that HIPAA Certification Isn’t Everything** - **An Apple a Day Doesn’t Keep the Regulator Away** - **Five Obstacles in Getting HIPAA Certifications** - **How To Get HIPAA-Certified & Stay Compliant** ## **Would You Like Some Money?** Many freelance developers, entrepreneurs, and tech companies get interested in tapping into the potential of the American healthcare market. It may sound like a very specific, niche focus, but consider this for a moment: Research and Markets estimates that the healthcare industry will grow 9% CAGR through 2020. Well, after all, the baby boomers are getting older. If you don’t know about that demographic, those are the individuals who were born at a time of many US births, a stretch that followed World War II (1946 to 1964). In 2015, that population ranges in age from 51 to 69. Look at that simple fact, and you can understand why health IT is growing so rapidly. Here’s another thing to consider: it’s not just a matter of how many people will be accessing healthcare but how many people will themselves be using technology. *Does a substantial proportion of senior citizens use technology?* one might reasonably wonder. The short answer is yes, and that is a recent development. Look at these stats from Pew Internet – just to get a sense of how much the first baby boomers are turning toward technology: *Percentage of online American adults aged 65+ using key social network sites:* | | 2013 | 2014 | | --- | --- | --- | | Facebook | 45% | 56% | | Twitter | 5% | 10% | | Instagram | 1% | 6% | | Pinterest | 9% | 17% | | LinkedIn | 13% | 21% | It may look small, but it’s trending upward fast. Just watch what happens with the 2015 and 2016 percentages, once those stats are available. That number will just keep rising. The senior population is gradually becoming more and more tech-savvy. ## **Realize that HIPAA Software Certification Isn’t Everything** If you decide you do want to get HIPAA-certified, though, it’s useful to realize that although certification can itself be complex, a HIPAA certification test isn’t the same thing as compliance. In order to keep yourself financially safe working in the healthcare market, you should consider that your exact role is defined within the code of the HHS Office for Civil Rights, the agency that creates regulations and enforces the Health Insurance Portability and Accountability Act of 1996 (HIPAA): **business associate**. Business associates must be compliant with HIPAA. *What is HIPAA certification?*Let’s pause for a moment and discuss exactly what this term means. It means you are getting certified through a third-party organization (and the exact organization matters since it should be impartial and credible) to meet certain standards in safeguarding the protected health information (PHI) processed by you or your company. You need to be ready to be a business associate, meaning that you are maintaining the compliance of all data, in alignment with established standards, to meet the rigorous demands that have been established for PHI. If that sentence sounds like a mouthful, you should be prepared for that, essentially meeting the legalese demands of fine print. After all, that is what it truly means to be HIPAA-compliant – except to the extent that you entrust third parties (such as Atlantic.Net) with your core technologies. ## **An Apple a Day Doesn’t Keep the Regulator Away** Apple has interested developers with its HealthKit offering, which will integrate personal information and health record information, using health apps to serve as a connection between all parties. Although this sounds somewhat interesting, the platform is essentially dead in the water, according to health IT chief executive Dr. Michelle Longmire, who thinks that Apple purposely kept the potentials of the environment small enough that it wouldn’t be pegged for HIPAA violations and fines itself. “If HealthKit was to do more, it might invite regulatory scrutiny of iPhones,” she said. “Apple is making far too much money selling devices and doesn’t want to slow down its development schedule. So it’s highly unlikely Apple will play a role in connecting HealthKit data to the healthcare system.” ## **Five Obstacles in Getting HIPAA Software Certifications** For those wondering how to become HIPAA-certified, [*HIT Consultant* advised](http://hitconsultant.net/2014/10/28/5-hipaa-hurdles-health-app-developers/) considering these five issues that you might encounter (just so that you understand it isn’t entirely simple): 1. You need two sets of strengths. “Becoming HIPAA compliant requires a combination of technical infrastructure and administrative protocols and procedures,” said *HIT Consultant*. 2. It is a profitable niche market because relatively few people understand the landscape. 3. It could take as many as 16 to 24 months of work to develop an app that’s healthcare-compliant. 4. You need for compliance to be scalable. 5. Is it worth the effort? ## **How To Get HIPAA-Certified & Stay Compliant** Certification is accomplished through a legitimate, independent, objective third party. If you want to take it up a notch, you can get healthcare auditing, as we have. If you are a developer and want to get HIPAA-certified, that could be a great idea. However, that doesn’t mean you want to have to handle the technology’s infrastructure yourself. Get HIPAA certification if it makes sense to you. Just remember that certification isn’t compliance, and it will always makes sense to work with a [HIPAA Hosting Provider](https://www.atlantic.net/hipaa-compliant-hosting/) that provides a HIPAA-certified infrastructure within an SSAE-16-audited certification.   Our servers are all SSD Cloud Servers offering 100% uptime and redundant backup! By Moazzam Adnan --- # How to SSH into your Linux Server from Windows > URL: https://www.atlantic.net/vps-hosting/how-to-ssh-linux-server-windows/ | Published: 2015-07-08 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 03/22/2015 ## Introduction In this how-to we will walk you through on How-To SSH into your Linux Server from Windows. SSH is a cryptographic network protocol that was made to replace telnet and allows local computer to authenticate with a remote server. ## How to SSH into your Linux Server from a Windows Computer. The first step, is you will need to download an SSH client. There are many out there but in this tutorial, we will use PuTTY which is a free SSH and telnet client for Windows.[You can download it here](http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html). Once you have an SSH client downloaded, open it. You will be prompted to enter the Hostname or IP address of your Linux server. ![anet-How to SSH into your Linux Server from Windows](https://www.atlantic.net/wp-content/uploads/2018/01/putty1.png) Putty Main Screen Once you have the IP address, or hostname entered, click on **OK**. You will then be prompted to enter the Username and Password to enter the server. The Password will not show as you type for security reasons. ![anet-How to SSH into your Linux Server from Windows](https://www.atlantic.net/wp-content/uploads/2018/01/putty2.png) Main Server login Once you have completed, hit **Enter**, and you will be logged in! Thank you for following along in this tutorial, please check back for more updates and to see our lineup of [web hosting solutions](https://www.atlantic.net/vps-hosting/). --- # How to Install ownCloud on Ubuntu 14.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-owncloud-ubuntu-14-04/ | Published: 2015-07-09 | Updated: 2026-03-03 | Author: Alexander Wise ## Introduction ownCloud is a software system that provides file storage, synchronization, and sharing services. It can be compared to products such as Dropbox or Google Drive, with the advantage that it is a free and open source solution you can install and manage yourself. With ownCloud, it is possible to share files and folders on a local computer and have them synchronized with your server. Using the ownCloud Desktop Client (not covered in this guide), you can keep your files in sync across several devices, including smartphones and tablets. Or, you can use a browser to access your files from any computer connected to the web. This guide will show you how to install ownCloud and modify some configuration settings. > We will use “*example.com*” in this guide. Replace it with the domain name or IP address you have configured on your server. ## Installing ownCloud Before you begin, make sure your system is updated. From the command line, type: ``` sudo apt-get update sudo apt-get upgrade ``` Next, add the ownCloud repository to be able to install the newest version of the software. ``` sudo sh -c "echo 'deb http://download.opensuse.org/repositories/isv:/ownCloud:/community/xUbuntu_14.04/ /' >> /etc/apt/sources.list.d/owncloud.list" ``` Download and add the repository key. ``` wget -q http://download.opensuse.org/repositories/isv:ownCloud:community/xUbuntu_14.04/Release.key -O- | sudo apt-key add - ``` Update the repositories and install ownCloud: ``` sudo apt-get update sudo apt-get install owncloud ``` During the installation process, the package manager will install ownCloud along with all the software dependencies needed. > The MySQL database server is one of these dependencies. If MySQL is not already installed on your server, then the installer will prompt you for a password for the root MySQL user. Remember to choose a secure password, different from the server user’s.   ## Setting Up ownCloud You are almost done with the initial setup. Now, you need to create the administrator account. 1. Using a web browser, go to `http://example.com/owncloud`. It will ask you to set a username and password for the administrator account. You can choose any username you wish. In this example, we use *admin*. ![ownCloud initial login screen](https://www.atlantic.net/wp-content/uploads/2015/07/own1.jpg) ownCloud initial login screen 2. This screen also gives you the option to change the database backend from SQLite (default option) to MySQL/MariaDB or PostgreSQL. We will stick to the default option, although for larger deployments, it is preferable to use one of the alternatives. You can change this database option later, if needed. 3. Click on **Finish setup**. You will be taken to the ownCloud main screen for the administrator user. A popup window will appear once with links to download the ownCloud client for different platforms. ![ownCloud popup window featuring client download links](https://www.atlantic.net/wp-content/uploads/2015/07/own2.jpg) ownCloud popup window featuring client download links ## Managing Your ownCloud Your ownCloud server is ready to be used. In the following couple of steps, you will learn how to add users and how to enable and enforce secure connections. ### Add Users At the top right corner, check the menu that opens under *admin* (or whatever username you chose for the administrator account), and go to **Users** to create users for your ownCloud server. ![ownCloud menu to create or edit users](https://www.atlantic.net/wp-content/uploads/2015/07/own3.jpg) ownCloud menu to create or edit users When adding users, you can assign quotas for the storage space available to them. ![ownCloud user administration screen](https://www.atlantic.net/wp-content/uploads/2015/07/own4.jpg) ownCloud user administration screen   ### Enable HTTPS and Disable HTTP By default, ownCloud runs on HTTP. HTTP traffic is sent “in the clear”, so anyone who can access the network has the chance to see usernames and passwords. To protect your data, you should use the HTTPS protocol to access your server using an encrypted data channel. > In this example, we will use a self-signed certificate, but you could use a certificate issued by a recognized Certification Authority, if needed.   1. Enable SSL and install a default, self-signed certificate. From the command line, type: ``` sudo a2enmod ssl sudo a2ensite default-ssl sudo service apache2 reload ``` ![Output when enabling and installing self-signed SSL certificate in Apache](https://www.atlantic.net/wp-content/uploads/2015/07/own5.jpg) Output when enabling and installing self-signed SSL certificate in Apache 2. Using your preferred text editor, modify the `/etc/apache2/sites-available/default-ssl.conf` file, adding the following at the end, before the `
` and `` statements. ``` Options Indexes FollowSymLinks MultiViews AllowOverride All Order allow,deny Allow from all # add any possibly required additional directives here # e.g. the Satisfy directive (see below for details): Satisfy Any ``` After the modification, the bottom of that file will look like this: ![Modified /etc/apache2/sites-available/default-ssl.conf file](https://www.atlantic.net/wp-content/uploads/2015/07/own6.jpg) Modified /etc/apache2/sites-available/default-ssl.conf file 3. Enable the Apache rewrite module. ``` sudo a2enmod rewrite sudo service apache2 restart ``` 4. Access your ownCloud using HTTPS now. With your browser go to `https://example.com/owncloud` (note the http**s**). > The browser will show a warning. It appears because it cannot verify the authenticity of the self-signed certificate you created in step 1 of this section. In this case, it is safe to ignore the warning and to tell the browser to continue.   5. Log in as administrator, and go to the *admin* menu, again on the top right corner of the page. 6. Go to the **Security** section and click on **Enforce HTTPS**. After you select that option, another one will appear below: **Enforce HTTPS for subdomains**. Check that one, too. ![ownCloud Security options](https://www.atlantic.net/wp-content/uploads/2015/07/own7.jpg) ownCloud Security optionsNow, if you try to access your ownCloud via HTTP, it will automatically redirect you to use HTTPS, instead. ### Additional Features Congratulations, your ownCloud is ready for use. Now that it is up and working, take your time to learn about all its cool features. For a complete reference to these features, take a look at the following links: - [Official site](http://owncloud.org) - [Documentation](http://doc.owncloud.org) Also, when you log into your ownCloud as administrator, among the demo files there is a PDF of the user manual. This document contains more information and tips to help you understand all the features and capabilities available. Congratulations! You now have a successfully installed ownCloud. Thank you for following along and feel free to check back with us for further updates or learn more about our reliable [VPS hosting](https://www.atlantic.net/vps-hosting/). --- # How to: Custom RDP Port in Windows 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-custom-rdp-port-windows-2012/ | Published: 2015-07-10 | Updated: 2026-03-02 | Author: Alexander Wise ##### Verified and Tested 03/19/2015 ## Introduction In this How-To, we will walk you through changing the RDP Port in Windows Server 2012. Remote Desktop Protocol (RDP) is a protocol that allows you to connect and control another computer via an existing network making it a remote connection.  By default, Windows has assigned port 3389 as the default port to connect. To enable RDP on your Windows Server 2012, [you can click here for more information.](https://www.atlantic.net/vps-hosting/how-to-enable-rdp-windows-server-2012/) ## Prerequisites – A Server with Windows Server 2012.  If you do not have a server already, why not consider [Windows VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net and be up in 30 seconds or less. ## Change The RDP Port in Windows 2012 Connect to your server via Remote Desktop On your keyboard hold down the Windows logo + R  buttons which opens the “Run” dialog and execute the “cmd” command and click OK ![This is the Run command window in Windows Server 2012](https://www.atlantic.net/wp-content/uploads/2018/01/rdp1.jpg) This is the Run command window in Windows Server 2012 Type “regedit” and click enter ![This is the regedit command in Windows Server 2012](https://www.atlantic.net/wp-content/uploads/2018/01/rdp2.jpg) This is the regedit command in Windows Server 2012 Navigate to the following Registry key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\TerminalServer\WinStations\RDP-Tcp\PortNumber ![This is the registry path to change the RDP Port in Windows 2012](https://www.atlantic.net/wp-content/uploads/2018/01/rdp3.jpg) This is the registry path to change the RDP Port in Windows 2012   Find the “PortNumber” registry subkey and either right-click or double-click it. A box should pop that says “edit DWORD.” Find the value data (it should say 3389 for standard installations) and change it to the port that you would like. In this example, we chose port 1050.   ![This is the Port value field in the Windows Server 2012 Registry](https://www.atlantic.net/wp-content/uploads/2018/01/rdp4.jpg) This is the Port value field in the Windows Server 2012 Registry Exit the registry editor **IMPORTANT: **Before restarting your server, be sure that you have enabled your new RDP port on your Windows firewall. Take a look at our guide if you do not know how to add a custom firewall port “[Adding a custom firewall rule](https://www.atlantic.net/dedicated-server-hosting/how-to-add-custom-firewall-rule/).” Restart your server To access your server over the new port simply type in your IP  followed by :PORT (YOUR.IP.ADD.RESS:PORT / 192.168.10.25:1050) Congratulations! You have just changed RDP port in Windows Server 2012. Thank you for following along in this How-To, check back with us for any new updates and to learn more about our reliable [VPS hosting](https://www.atlantic.net/vps-hosting/) services. --- # How to: Disabling TCP Offloading in Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-disabling-tcp-offloading/ | Published: 2015-07-12 | Updated: 2026-03-02 | Author: Alexander Wise ## Introduction In this how-to we will walk you through Disabling TCP Offloading in Windows Server 2012. TCP Offload Engine (also known as TOE) is a type of mechanic used by network interface cards (NICs) to relieve the TCP/IP processing of the whole network controller. It is commonly used in network interfaces with high speeds that above the level processing is required. ### Prerequisites – A Windows Server 2012. If you do not have a server already, you can spin up a new [Windows server](https://www.atlantic.net/vps-hosting/) in under 30 seconds. ## Disabling TCP Offloading In the Windows server, open the Control Panel and select **Network and Internet**> **Network and Sharing Center>Change Adapter Settings**. ![Click on the Change adapter settings in Windows Server 2012](https://www.atlantic.net/wp-content/uploads/2018/01/tcp1.jpg) Click on the Change adapter settings in Windows Server 2012 Right-click on each of the adapters (**private **and **public**) > Properties > select **Configure **from the **Networking **menu, and then click the **Advanced **tab. ![Click the Advanced tab in the Adapter settings in Windows Server 2012](https://www.atlantic.net/wp-content/uploads/2018/01/tcp2.jpg) Click the Advanced tab in the Adapter settings in Windows Server 2012 The TCP offload settings are listed for the Red Hat VirtIO adapter. Disable the below offload settings, and then click **OK**: – IPv4 Checksum Offload – Large Receive Offload – Large Send Offload – TCP Checksum Offload ![Disabled Ethernet Adapter settings in Windows Server 2012](https://www.atlantic.net/wp-content/uploads/2018/01/tcp3.jpg) Disabled Ethernet Adapter settings in Windows Server 2012 That’s it! You have just disabled TCP Offloading in Windows Server 2012. Thank you for following along in this How-To, check back with us for any new updates and to learn more about our industry-leading [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. --- # HIPAA Security Software: HIPAA Compliant Encryption Software, Antivirus, Network Segregation and More > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-encryption-antivirus-software/ | Published: 2015-07-13 | Updated: 2026-01-09 | Author: Alexander Wise Rather than just listing HIPAA-compliant software, this report gives advice on all the fundamentals, along with a few misconceptions about the kind of robust security environment that is necessary to maintain [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/). ## **HIPAA Compliant Antivirus & Proper Network Segregation** *Security via obfuscation* is not a legitimate way for a healthcare company to do business. This tactic is primarily used by small practices that have historically been using their own servers. What is it? “On the commercial end of computer security, [security via obfuscation] comes in the form of (naively) believing that restricting internet access on portions of your computer network will keep you safer from malware and attackers,” explained Illinois IT consultant Derrick Wlodarz. “You can [read up](http://en.wikipedia.org/wiki/Network_cloaking) on how far debunked this practice has become, as even an amateur hacker can get around such lowly safeguards in a matter of minutes.” Segregate your network, and protect it with antivirus/anti-malware HIPAA-compliance software. Use a top antivirus/anti-malware application. Remember that the most important HIPAA-compliant software achieves security by identifying threats and encrypting your data. Free options for the former, such as those from Avast or AVG, are budget-friendly but are not intended for commercial environments. The antivirus must be effective and lightweight, both reasons why Trend Micro Deep Security is used for all Atlantic.Net hosting packages. ## **HIPAA Compliant Encryption Software** Along with segregating the PHI area of your network with antivirus HIPAA-compliant software, you also need all information to be encrypted. Tactics to achieve that include: - **Leveraging Windows BitLocker** – Here is one reason you might want Windows over Linux: BitLocker. BitLocker is a great piece of HIPAA-compliance software that was only available through the Enterprise or Ultimate versions of Windows 7 but started coming completely free with Windows 8 Pro. - **Verifying encryption of all backups** – All storage systems used for protected health information must be secured against cybercrime, and that includes all hard drives and flash drives used for backup. “Part of the reason I so heavily recommend cloud storage providers [such as Atlantic.Net] for backup today is because [using a provider that is outfitted with HIPAA-compliance software] saves some hassle on encrypting system backups locally,” commented Wlodarz. “But regardless of path chosen, ensure the endpoint of data storage has proper encryption safeguards in use.” Anything that is easily detachable and portable represents a significant danger for theft. - **Using Windows Remote Desktop Services (RDS) to minimize the chance of a leak**– Starting with Windows NT 4, Windows Server has included the tool Remote Desktop Services (originally known as Terminal Services). Within RDS, Session Based Desktops are basically the up-to-date version of Terminal Services, and they are the simplest to implement. Any authorized members of your staff will be able to manage patient health records from a user interface, but none of that data will leak to their PC. That means your maintenance is more affordable, your information is less exposed, and it’s less likely that protected health information will leak. *For more on encryption, read our article [Encryption for HIPAA Compliance: A Quick Primer](https://www.atlantic.net/hipaa-compliant-hosting/encryption-for-hipaa-compliance/).* ## **But That’s Not All…** There are two additional elements beyond these questions about piecing together the technology: 1. *Security best practices* – You should never have written passwords near any computer. You must have strong passwords on all systems, with no exceptions. Get cable locks for your computers. Use two-factor authentication. 2. *HIPAA-compliant web host* – Really the question with HIPAA is whether it makes sense to design your own system or to go with a [healthcare hosting](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/) expert so that all of your core environment, sectioned off as its own private infrastructure, is established within an SSAE-16-audited, HIPAA-audited system and continually monitored by experienced technicians. That also takes care of another major security best practice: patching and upgrading. HIPAA-compliance software should always be completely up-to-date if you wanted to operate effectively. The first element may require a culture shift at your organization. The second element is as simple as getting a quote from us today. We haven’t just jumped into the growing [HIPAA Compliance Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) market to build revenue. We are a part of the health IT community – exhibiting, for example, at the Health Information and Management Systems Society’s annual conference. We’d be happy to discuss any additional HIPAA Compliant software and other hosting options, like our award-winning cloud hosting solution, so that you can use it on your system to craft a solution that works best for your healthcare company. --- # Atlantic.Net Cloud – Do You Offer Data Backup For My Cloud Server > URL: https://www.atlantic.net/disaster-recovery/how-to-data-backup-cloud-server/ | Published: 2015-07-14 | Updated: 2026-01-09 | Author: Alexander Wise ##### Verified and Tested 04/20/2015 ## Introduction Daily server backups are available and can be enabled via the Atlantic.Net cloud control panel during the initial provisioning of a cloud server. The cost for this service is an additional 20% of the server’s hourly price. Go server backups are $1 per month. Snapshot backups of the server will be taken on a daily basis, and retained in our systems for 30 days. Backup restores can be initiated from within the cloud control panel.  In this brief article we will explain how to enable backups for your cloud server. ## Enabling Backups You can enable backups during the initial provisioning of a server. To do so, first log in to your account via cloud.atlantic.net. Once done, on the upper left corner click on “Add Server”. This will take you to the “Add a Server” window. Here you can edit the server name, choose the location, select your operating system, choose a plan, and lastly enable backups. After you have finished editing these fields click on the box next to “Enable Backups”, and then click on the “Create Server” button, as shown below. ![Does Atlantic.net Offer Data Backup for my cloud server-1](https://www.atlantic.net/wp-content/uploads/2018/01/backup1.png) You can also enable backups after you’ve created a server, if you forgot to or decided to add this feature after the fact.  Select “Servers” from the left, select your server, and click on either the “Backups” button (Server Backups) or the hyperlink that says “Disabled” under backups. ![Does-Atlantic.net-offer-data-backups-for-my-server-2](https://www.atlantic.net/wp-content/uploads/2018/01/backup2.png) It will bring up this message, regardless of which option you choose.  Select “Enable Backups” and your server will be backed up within the next 24 hours, and will continue to back up each day. ![Does-Atlantic.net-offer-data-backups-for-my-server-3](https://www.atlantic.net/wp-content/uploads/2018/01/backup3.png) Please note that if you decide you no longer want the backup feature enabled, you can disable it and it will stop adding the extra 20% to your monthly bill. Atlantic.Net has a industry leading selection of hosting options, one-click applications, and managed cloud hosting choices for your consideration. Learn more about Atlantic.Net’s hosting solutions, including [HIPAA compliant disaster recovery](https://www.atlantic.net/disaster-recovery/) services. --- # How to: Domain Name Server (DNS) Amplification Attack > URL: https://www.atlantic.net/vps-hosting/how-to-domain-name-server-dns-amplification-attack/ | Published: 2015-07-14 | Updated: 2026-03-02 | Author: Alexander Wise ## Introduction A Domain Name Server (DNS) Amplification attack is a popular form of Distributed Denial of Service (DDoS), in which attackers use publicly accessible open DNS servers to flood a target system with DNS response traffic. The primary technique consists of an attacker sending a DNS name lookup request to an open DNS server with the source address spoofed to be the target’s address. ref: [DNS Amplification Attacks](https://www.cisa.gov/news-events/alerts/2013/03/29/dns-amplification-attacks)   ## Disabling Recursion on Authoritative Name Servers Many of the DNS servers currently deployed on the Internet are exclusively intended to provide name resolution for a single domain. In these systems, DNS resolution for private client systems may be provided by a separate server and the authoritative server acts only as a DNS source of zone information to external clients. These systems do not need to support recursive resolution of other domains on behalf of a client, and should be configured with recursion disabled. #### Bind9 Add the following to the global options: ``` options { allow-query-cache { none; }; recursion no; }; ``` #### Microsoft DNS Server In the Microsoft DNS console tool: 1. Right-click the DNS server and click Properties. 2. Click the Advanced tab. 3. In Server options, select the “Disable recursion” check box, and then click OK. ## Limiting Recursion to Authorized Clients For DNS servers that are deployed within an organization or Internet Service Provider, the resolver should be configured to perform recursive queries on behalf of authorized clients only. These requests typically should only come from clients within the organization’s network address range. We highly recommend that all server administrators restrict recursion to only clients on the organization’s network. #### BIND9 In the global options, include the following: ``` acl corpnets { 192.168.1.0/24; 192.168.2.0/24; }; options { allow-query { any; }; allow-recursion { corpnets; }; }; ``` #### Microsoft DNS Server It is not currently possible to restrict recursive DNS requests to a particular client address range in Microsoft DNS Server. To approximate the functionality of the BIND access control lists in Microsoft’s DNS Server, a different caching-only name server should be set up internally to provide recursive resolution. A firewall rule should be created to block incoming access to the caching-only server from outside the organization’s network. The authoritative name server functionality would then need to be hosted on a separate server, but configured to disable recursion as previously described. ## Response Rate Limiting (RRL) There is currently an experimental feature available as a set of patches for BIND9 that allows an administrator to limit the maximum number of responses per second being sent to one client from the name server. This functionality is intended to be used on authoritative domain name servers only as it will affect performance on recursive resolvers. To provide the most effective protection, we recommend that authoritative and recursive name servers run on different systems, with RRL implemented on the authoritative server and access control lists implemented on the recursive server. This will reduce the effectiveness of DNS amplification attacks by reducing the amount of traffic coming from any single authoritative server while not affecting the performance of the internal recursive resolvers. #### BIND9 There are currently patches available for 9.8.latest and 9.9.latest to support RRL on UNIX systems. Red Hat has made updated packages available for Red Hat Enterprise Linux 6 to provide the necessary changes in advisory RHSA-2013:0550-1. On BIND9 implementation running the RRL patches, include the following lines to the options block of the authoritative views: ``` rate-limit { responses-per-second 5; window 5; }; ``` #### Microsoft DNS Server This option is currently not available for Microsoft DNS Server. --- # How to Install Hiawatha Web Server On CentOS 7 > URL: https://www.atlantic.net/vps-hosting/how-to-install-hiawatha-web-server-centos-7/ | Published: 2015-07-14 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 07/3/15 ## Introduction This tutorial will show you how to install Hiawatha Web Server on CentOS 7. Hiawatha is a web server built with the focus on security. It has built-in rules that can prevent cross-site scripting and forgery, SQL injections, and resource expenditure. Although its focus is on security, it also excels in performance due to its lightweight design. [jumpbox] ## Installing Hiawatha on CentOS 7 Before we install Hiawatha, we need to make sure that our firewall is in order. First, we need to update our firewall to allow HTTP and HTTPS traffic. Check to see if your firewall is running by running ``` sudo systemctl status firewalld ``` If the firewall is not running, run the following command: ``` sudo systemctl start firewalld ``` If you want the firewall to start when CentOS 7 boots up, run the following command: ``` sudo systemctl enable firewalld ``` To allow HTTP and HTTPS, run the following commands: ``` sudo firewall-cmd --permanent --add-service=http sudo firewall-cmd --permanent --add-service=https ``` You need to run the following command so that the rules above take effect. ``` sudo firewall-cmd --reload ``` Now that we have taken care of the firewall, we can install Hiawatha. In this how-to we are going to use the repo provided by [Anku](http://anku.ecualinux.com/). Download the RPM with the following command: ``` sudo wget http://anku.ecualinux.com/7/x86_64/anku-release-8-1.noarch.rpm ``` > Note: In some instances, you may not have wget installed, install it with the following command: > > ``` > sudo yum install wget > ``` Now that the RPM has been downloaded we can install it with the following command: ``` sudo rpm -ivh anku-release-8-1.noarch.rpm ``` Install Hiawatha with the following command: ``` sudo yum install hiawatha ``` Run the following command to start Hiawatha: ``` sudo service hiawatha start ``` We can now verify Hiawatha is working by opening your browser and entering the URL `http://your-server-address`. You should get an “Installation successful” page similar to the image below. > Note: If you do not know your IP address, run the following command: > > ``` > sudo ip addr show eth0 > ``` > > ![An example of using the ip addr command and getting the IP 192.168.100.10](https://www.atlantic.net/wp-content/uploads/2018/01/haiwatha1.png) > > An example of using the ip addr command and getting the IP 192.168.100.10 > > In our example, we would put `http://192.168.100.10` into our browser’s address bar.   ![An example of the Hiawatha installation web page](https://www.atlantic.net/wp-content/uploads/2018/01/haiwatha2.png) An example of the Hiawatha installation web page Using the default settings, you can put your web content in the following directory: ``` /var/www/hiawatha ``` For any configuration changes that you may want to make, you can go to the following directory: ``` /etc/hiawatha ``` Congratulations on installing Hiawatha webserver on a CentOS server. Thank you for following along in this How-To, and check back with us for any new updates. --- # How to Get Started With A FreeBSD Cloud Server > URL: https://www.atlantic.net/vps-hosting/how-to-get-started-freebsd-cloud-server/ | Published: 2015-07-14 | Updated: 2026-03-02 | Author: Alexander Wise ## Introduction FreeBSD is an operating system available in our Cloud environment.  FreeBSD is an open source operating system originating from a previous generation that was referred to as “BSD Unix” or “Berkeley Unix.”  Although FreeBSD is not part of the Unix family, and as such cannot use the name, it shares many features and qualities with the Unix/Linux operating systems. More information on the history and recent updates to FreeBSD can be found [on the direct website.](https://www.freebsd.org/) ## What you will need In order to start setting up your FreeBSD server, all you need to do is create a server in cloud.atlantic.net.  A tutorial on adding a new cloud server can be found here. ## System Configuration The FreeBSD system configuration information is contained all in one file: /etc/rc.conf You’ll find your network configuration in this file along with enabled daemons/system services. For example to configure a network device named vtnet0 with an IP of 1.2.3.4/24 with a router of 1.2.3.1, a hostname of “test” and have sshd enabled, one would add the following to /etc/rc.conf: ``` ifconfig_vtnet0="inet 1.2.3.4 netmask 255.255.255.0" defaultrouter="1.2.3.1" hostname="test" sshd_enable="YES" ``` For more information on how to configure FreeBSD and further options that can go in this file, view the [FreeBSD Handbook](http://www.freebsd.org/doc/en/books/handbook/). ## Package Management The default package manager on FreeBSD 10.0+ is ‘pkg’. In order to use this on a newly provisioned system, one should first run ‘pkg update’ **Some basic commands:** Ensure the package list is up-to-date: ``` pkg update ``` Determine if updates are available for already installed packages: ``` pkg upgrade ``` Install package(s): ``` pkg install ``` Search for package(s): ``` pkg search ``` Example: To install vim lite, sudo and tmux: ``` pkg update ``` pkg install vim-lite sudo tmux See below for more info: [www.freebsd.org](http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/pkgng-intro.html) ## Private Network Setup To configure a private network between two or more of your [FreeBSD Virtual Private Servers](https://www.atlantic.net/vps-hosting/), you’ll need to configure the second network interface on your device using the private network range provided in the Cloud Control Panel. You will also need to configure static routes between the images so that they can communicate properly. This will all be done in ‘/etc/rc.conf’. For example, to use the subnet 10.9.243.0/24, with one image having the IP 10.9.243.1 and the other having 10.9.243.2, you would configure the following within the /etc/rc.conf file in each Cloud Server respectively: ``` 1st Cloud Server: ifconfig_vtnet1="inet 10.9.243.1 netmask 255.255.255.0" static_routes="net1" route_net1="-net 10.9.243.0/24 10.9.243.1" ``` ``` 2nd Cloud Server: ifconfig_vtnet1="inet 10.9.243.2 netmask 255.255.255.0" static_routes="net1" route_net1="-net 10.9.243.0/24 10.9.243.2" ``` After the /etc/rc.conf changes, you must restart the network and routing services to bring up the private network: ``` service netif restart ``` ``` service routing restart ``` ## Partitions/Filesystems There are 3 partitions within your FreeBSD Cloud Servers: /dev/da0p1 – 64KB boot partition, is not mounted during OS operation and is only used to contain FreebBSD boot code /dev/da0p2 – 32MB Ext2 partition for Atlantic.Net use in configuring and interacting with your Cloud Server.  Empty and not mounted during normal OS operation /dev/da0p3 – (size variable) UFS partition, mounted as / --- # HIPAA Compliance Testing & Penetration Testing HIPAA Penetration Checklist > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-penetration-testing-checklist/ | Published: 2015-07-14 | Updated: 2026-01-09 | Author: Alexander Wise ## **HIPAA Penetration Checklist** We all want simplicity, but there’s no getting around that compliance with the Health Insurance Portability and Accountability Act of 1996 is complicated. However, you can use a couple of checklists along with penetration testing of your system to verify that you have hit all the bases. ## HIPAA Compliant Infrastructure Checklist Whether you are a covered entity or a business associate, [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) is critical. No one wants their patients to feel that their records are unsafe and could fall into the hands of state-sponsored Chinese hackers (believed responsible for both Anthem and Community Health Systems) or others. Also, no one wants the huge HHS fines associated with violations. One significant aspect of compliance and the first thing that everyone turns toward when looking at the law is IT systems. Here is an essential checklist for infrastructure and core technologies: - **Firewalls** – hardware firewalls, software firewalls, and web application firewalls. - **Two-factor authentication** – Set up 2FA on all aspects of your site. Everything requiring a username and password should also necessitate a second factor, typically a numerical code sent to a mobile device. - **Off-site backup** – Ensure that all ePHI is backed up at a distant geographical location. - **SSL certificates** – This technology should be site-wide, bare-minimum covering all domains and subdomains through which you can access protected information. - **SSL VPN** – This type of virtual private network (the standard alternative to an IPsec VPN) uses SSL certificates to facilitate a secure client-server connection through the browser. - **Encrypted VPN** – You want the VPN to be encrypted, especially considering whistleblower Edward Snowden’s revelation that the National Security Agency’s XKeyscore system can penetrate VPNs. Attackers could have similar tools. - **Private hosted environment** – No resources can be shared. - **SSAE 16 auditing (optional)** – If your hosting system meets this standard, it goes above and beyond the security expectations of HIPAA and meets the security parameters of the American Institute of Certified Public Accountants (AICPA). - **Business associate agreement (BAA)** – All outside organizations with which you partner must be in a contractual relationship with you, as outlined in a BAA. Additional resources related to the above: AICPA – [SSAE 16 guidelines](https://www.aicpa.org/home) HHS – Security Rule guidelines ## Compliance Policies & Procedures Checklist Not everything is technological, so it’s not just about entrusting a hosting company to build your system appropriately. You also need to make sure that you are operationally sound with appropriate policies and procedures: - Create a**security and privacy policy** - Appoint a**security and privacy officer** - Conduct regular**risk assessments** - Create an**email policy** that either encrypts all messages containing health data (preferred) or informs patients that emailing the data is risky. - Create a**policy for mobile devices and laptops.** Note that unencrypted laptops represent the most common HIPAA violation, while the theft of an encrypted laptop is not even considered a data breach. - Conduct regular**staff training.** - Create a**privacy notice** to post to your site and hand it out to all patients. - As established above, confirm that you have **business associate agreements** signed with all companies that come into contact with your health data. - Develop a **breach documentation and notification policy**. - Set up regular **enforcement reviews** to guarantee that all privacy and security policies are followed. ## Penetration Testing Atlanta security analyst and author Mike Rothman recommends penetration testing over vulnerability scanning to ensure compliance. What is *penetration testing* or *pen testing*? “I also call it ‘security assurance,’” [explained Rothman](http://searchsecurity.techtarget.com/tip/Penetration-testing-Helping-your-compliance-efforts), “and define it as anything and everything that tests where and how corporate networks, systems, and applications can be compromised, as opposed to flagging theoretical vulnerabilities.” You can think of professionals who make a living in the penetration testing field as white-hat hackers. They utilize the same software and methods, but they typically become much more diverse and granular in their attacks than a run-of-the-mill attacker looking for an easy target. Third-party penetration testing is required by various laws and standards such as HIPAA, SOX, and PCI-DSS. However, pen testers recommend that their services be performed much more regularly – which seems completely valid given the trend of hackers staying within systems for months (Sony, Anthem, US State Department, etc.). Rather than simply listing *what is vulnerable* as a vulnerability scanner does, a penetration test informs you *what could be compromised*. It goes beyond the technology to look at the human element, a typical target for criminal exploitation. Plus, vulnerability scanners sometimes turn up false leads. “There are lots of reasons why a vulnerable machine may not be exploitable,” said Rothman. “A scanner will tell security professionals it’s a problem. A pen test will assure them that it isn’t, and that provides a lot of value.” ## **HIPAA Compliant Hosting** Although you want to ensure that all your compliance bases are covered, that doesn’t mean that you want to maintain and monitor the entire infrastructure in-house. Certainly, you have other, more mission-specific things to do, and it’s much safer to trust the credibility of a provider staffed with security professionals who maintain and offer [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) 24/7/365. We provide complete HIPAA-compliant hosting services, including [HIPAA webhosting](https://www.atlantic.net/hipaa-compliant-hosting/). --- # How to Reset a Forgotten Windows Host Administrator Password > URL: https://www.atlantic.net/vps-hosting/how-to-reset-forgotten-windows-host-administrator-password/ | Published: 2015-07-15 | Updated: 2026-01-09 | Author: Alexander Wise ##### Verified and Tested 03/31/2015 ## Introduction People pay lots of money for password recovery. With so many different passwords that we use daily (email, desktop, servers, etc.), we tend to forget some of the crucial ones. However, we will recover our password with a Windows CD. That’s it! We will walk you through resetting your forgotten Windows Host Administrator password in this how-to. ## Prerequisites – A Windows CD (Windows Vista, Windows 7, Windows 8, Server 2008 R2, Server 2008, Server 2012, or a Server 2012 R2). ## Procedure Boot the server to your **Windows CD**/ Browse to the **Repair** section/ open up the **command-line** tool and type the following: ``` d: cd windows/system32 ren utilman.exe utilman.exe.old copy cmd.exe utilman.exe ``` ![Reset a Forgotten Windows Host Administrator Password-1](https://www.atlantic.net/wp-content/uploads/2018/01/windows1-1.jpg) Reboot the host and start it up normally. Click the ease of access button, which is located in the bottom left-hand corner. A new command prompt will appear. ![This is the output that you will see with the ease of access button highlighted](https://www.atlantic.net/wp-content/uploads/2018/01/windows2.jpg)   At this point, you can reset your current local Administrator account or make a new local administrator user and password. ## Reset the Local Administrator Password Change the local administrator password and activate the account by running the following commands: ``` net user administrator newpassword net user administrator /active:yes ``` ![This is the output that you will see after running the change administrator password and enabling the account](https://www.atlantic.net/wp-content/uploads/2018/01/windows3.jpg) ## Create a New Local Administrator Account and Password. To create an additional local administrator account, type the following command: ``` net user administrator newpassword net user administrator /active:yes ``` ![This is the output after running the additional user command and adding it to the admin group](https://www.atlantic.net/wp-content/uploads/2018/01/windows4.jpg) You can now log in with the account you set up in either method. Once you log in, make sure to revert the Ease of Access menu back to normal by typing the following command: ``` copy utilman.exe.old utilman.exe ``` ![This is the output of after completing the changes and reverting the Ease of Access menu back to normal](https://www.atlantic.net/wp-content/uploads/2018/01/windows5.jpg) Congratulations! You have just Reset your Forgotten Windows Host Administrator Password. Thank you for following along in this How-To, and feel free to check back with us for any new updates. ## Atlantic.Net Atlantic.Net offers [VPS hosting](https://www.atlantic.net/vps-hosting/) and managed hosting services that include a layer of business-essential managed services to your hosting packages. Contact us today for more information. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Protect Privacy While Maintaining HIPAA Compliance > URL: https://www.atlantic.net/hipaa-compliant-hosting/how-do-i-protect-privacy-with-hipaa-compliance-controls-and-safeguards/ | Published: 2015-07-15 | Updated: 2026-01-09 | Author: Alexander Wise There are plenty of checklists and guidebooks out there related to HIPAA compliance. However, it helps to go to the source to see what specific HIPAA controls are necessary to safeguard protected health information. Here are specific details on how to follow the Security Rule, as indicated directly by HHS guidelines: ## **Basic Guidelines** The Security Rule states that healthcare organizations must adequately protect ePHI using reasonable administrative, technical, and physical HIPAA safeguards. The following must be achieved: - All relevant patient data that your system touches should be kept confidential and consistently available. Its integrity should be maintained as well. - It would be best to defend against all common threats of data breach or manipulation. - You should make sure that any unlawful use or sharing is reasonably avoided. - Compliance should be maintained with your staff. *What exactly is meant by*confidentiality*?*“The Security Rule defines ‘confidentiality’ to mean that e-PHI is not available or disclosed to unauthorized persons,” says the HHS. “The Security Rule’s confidentiality requirements support the Privacy Rule’s prohibitions against improper uses and disclosures of PHI.” Beyond confidentiality, though, you also need to be concerned with integrity and availability issues. Availability is a characteristic of data that is accessible at all times for those with a legitimate need. For your data to have *integrity*, that means it hasn’t been manipulated or removed from the system. Although the HHS is strict about compliance, the Security Rule does not require explicitly defined solutions but instead stipulates that providers use established security standards to meet the legal expectations. The right choices for infrastructure and security software partially depend on how large a company is and its budget. When a healthcare organization is figuring out what security tools need to be in place, they should know the flexible variables listed by the agency: - Size of organization and what it does - The scope and components of your IT environment - The expenses related to security practices - Level of risk to your data It’s also necessary to adapt to the threat landscape rather than staying in one position for years. ## **Vulnerability Assessments** The Security Rule contains a specific section of Administrative Safeguards, which includes the need for regular vulnerability assessments. This element is crucial because, says the HHS, “by helping to determine which security measures are reasonable and appropriate for a particular covered entity, risk analysis affects the implementation of all of the safeguards contained in the Security Rule.” Your HIPAA risk analysis checklist should include these components: - Determine types and levels of risk - Put mechanisms in place to reduce each risk - Record the tools and processes you’ve implemented and why - Keep your safeguards in place on an ongoing basis. ## **Administrative HIPAA Controls** Proper management of security – As indicated above, it’s necessary to assess your organization’s vulnerabilities and mitigate them with industry-standard tools and techniques. Assignment of security role – You also want to have someone on staff who is the go-to person for these concerns. According to the HHS, “[a] covered entity must designate a security official who is responsible for developing and implementing its security policies and procedures.” Proper management of access – The HIPAA Privacy and Security Rules are consistent with access management. Aligned with the Privacy Rule’s stipulation that disclosure should be as limited as possible, the Security Rule directs the creation of policies and procedures that authorize role-based access, specifically defining what information users can see. Employee oversight and training – Healthcare companies need systems to authorize and manage their employees’ patient data interactions. Regular training must occur, and there must be consequences for anyone failing to abide by your policies. Regular review – It’s necessary to review policies and procedures regularly. ## **Physical HIPAA Controls** Your physical location – Take steps to ensure that no unauthorized parties access any offices containing health data. Desks & computers – You must devise specific guidelines regarding workstations and any digital devices. Additionally, the HHS delineates that “[a] covered entity also must have in place policies and procedures regarding the transfer, removal, disposal, and re-use of electronic media.” ## **Technical HIPAA Controls** Access – Healthcare organizations must develop policies that limit access to authorized individuals. Auditing – You have to deploy tools that monitor access and use of all PHI systems. Integrity – You have to put policies that reduce the likelihood of data manipulation and removal into place. Tools should also verify that no data is changed or deleted. Networks – Security tools should be used to prevent anyone from accessing patient records while it is being sent through the network. ## **The Role of Business Associates** The HHS also indicates that the role of business associates changed when HITECH passed in 2009. Those adjustments to the law made business associates directly responsible for safeguarding protected health information. However, just because business associates are now responsible and could be fined by the HHS just as covered entities can, your best protection is an experienced [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) like Atlantic.Net.  We offer 100 percent uptime on SSD Cloud Servers running the most popular applications. Learn more about [HIPAA Compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). --- # How to Install Mumble Server on Ubuntu 15.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-mumble-server-ubuntu-15-04/ | Published: 2015-07-16 | Updated: 2026-01-09 | Author: Alexander Wise ##### Verified and Tested 06/15/15 ## Introduction In this how-to, we will be installing a Mumble VoIP server on Ubuntu 15.04. Mumble is an open-source, low-latency, high-quality voice chat software primarily used while gaming. ## Install Mumble Mumble may not be available in the default Ubuntu repository. To add the repository– ``` sudo add-apt-repository ppa:mumble/release ``` ![An example of adding the repository in Ubuntu](https://www.atlantic.net/wp-content/uploads/2018/01/mumble1.png) ![An example of the process after hitting enter.](https://www.atlantic.net/wp-content/uploads/2018/01/mumble2.png) ``` sudo apt-get update ``` ``` sudo apt-get install mumble ``` or if that command does not work, you may do the following. — ![An example of the install process](https://www.atlantic.net/wp-content/uploads/2018/01/mumble3.png) ``` sudo apt-get install mumble ``` ``` sudo dpkg-reconfigure mumble-server ``` ## Advanced Config To configure, open up /etc/mumble-server.ini via nano or vi (user preference): ``` nano /etc/mumble-server.ini ``` To avoid users from affecting your Mumble server negatively, you may use Mumble’s global-ban system. The below configuration is set so that if someone attempts to connect to the server (unsuccessfully) 5 times within 60 seconds, they will be banned for 150 seconds. ##### autobanAttempts, autobanTimeframe and autobanTime ``` #autobanAttempts = 5 #autobanTimeframe = 60 #autobanTime = 150 ``` For these rules to occur, you must remove the # in front of each line. #### Serverpassword You will be able to choose a password for your server here. Be sure to use a strong password such as: f;Q=uS6/#BK5t<(9 ``` # Password to join server. serverpassword= ``` #### Welcometext This setting displays a message to the users every time they log in to the server. ``` # Welcome message sent to clients when they connect. welcometext=" Thank you for choosing Atlantic.Net! We hope you enjoy your stay " ``` #### Port The default port used by mumble is port 64738. ``` port=64738 ``` #### Users With this setting, you can limit the number of users allowed on the server at one time. ``` users=150 ``` #### Allowhtml Set Allowhtml to true to allow HTML to be used in messages. ``` allowhtml=true ``` Press Ctrl+X to exit /etc/mumble-server.ini Perfect, now your Mumble server is installed and configured! Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to: Exporting a VM in Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-exporting-vm-windows-server-2012/ | Published: 2015-07-17 | Updated: 2026-01-09 | Author: Alexander Wise ##### Verified and Tested 03/31/2015 ## Introduction In this how-to, we will walk you through Cloning/Exporting a VM in Windows Server 2012. The Windows Hyper-V term for cloning is called export. The Export feature in Hyper-V is the ability to make and export an exact image of a virtual machine and import it on another host.  This process can be done while the server is active, as it captures whatever the server has up to the point of the export. ## Prerequisites – A Server with Windows Server 2012 – A Virtual Machine that you want to be Cloned or Replicated ## Procedure ![Cloning/Exporting a VM in Windows Server 2012-1](https://www.atlantic.net/wp-content/uploads/2018/01/vm1-1.jpg) Open your **Hyper-V server** from Hyper-V Manager/Right-click on your **virtual machine** and select the **Export** option. ![This is the output that you will see in order to specify the Export location](https://www.atlantic.net/wp-content/uploads/2018/01/vm2-1.jpg) Select the directory location where you want to export your virtual machine, then click **Export**. ![This is the output that you will see after the Export. Confirm Snapshots, Virtual Disk and Virtual Machine.](https://www.atlantic.net/wp-content/uploads/2018/01/vm3-1.jpg) This is the output that you will see after the Export. Confirm Snapshots, Virtual Disk, and Virtual Machine. After the export is completed, you will see all export files in the folder. Congratulations! You have just cloned/Exported a VM in Windows Server 2012. Thank you for following along in this How-To, and feel free to check back with us for any new updates and related posts such as [How to Import a VM Export on Windows Server 2012](https://www.atlantic.net/vps-hosting/how-to-import-vm-export-windows-server-2012/). Atlantic.Net has various hosting solutions, including Windows cloud servers, managed cloud servers, and one-click install applications like WordPress Cloud Hosting. ## Atlantic.Net Atlantic.Net offers [VPS hosting](https://www.atlantic.net/vps-hosting/) and managed server hosting services that include a layer of business-essential managed services to your hosting packages. Contact us today for more information. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Import a VM Export on Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-import-vm-export-windows-server-2012/ | Published: 2015-07-17 | Updated: 2026-01-09 | Author: Alexander Wise ##### Verified and Tested 03/31/2015 ## Introduction In this how-to, we will walk you through importing a VM in Windows Server 2012. [Click here for more information](https://www.atlantic.net/vps-hosting/how-to-exporting-vm-windows-server-2012/) on how to export a Virtual Machine. ## Prerequisites – A Server with Windows Server 2012 running Hyper-V. – The exported VM must be copied to the local host server before starting the import. ## Importing a VM Export on Windows Server 2012 From Hyper-V Manager, Click on Hyper-V server and select Import Virtual Machine. ![Importing a Cloned VM in Windows Server 2012-1](https://www.atlantic.net/wp-content/uploads/2018/01/vm1-2.jpg) This is the output of the Import option in the Hyper-V Manager Select the virtual machine folder path (The folder contains the exported machine files). ![This is the output that you will see in order to specify the Import location](https://www.atlantic.net/wp-content/uploads/2018/01/vm2-2.jpg) This is the output that you will see to specify the Import location. Once you’ve selected the path, the next page will show the machine name on the Import Virtual Machine page. Select your VM and click next. ![This is the screenshot that you will see to select your virtual machine](https://www.atlantic.net/wp-content/uploads/2018/01/vm3-2.jpg) This is the screenshot that you will see to select your virtual machine Select the Import mode. Exported files can be reused to clone additional VMs only by using the “Copy The virtual machine (create a new unique ID)” option. ![This is the screenshot that you will see to Choose your Import Type](https://www.atlantic.net/wp-content/uploads/2018/01/vm4-1.jpg) This is the screenshot that you will see to Choose your Import Type – Register the virtual machine in-place – Restore the virtual machine – Copy the virtual machine (because we want to reuse the export, we’re using this option) ![This is the screen shot that you will see to specify the location that you want to import your VM](https://www.atlantic.net/wp-content/uploads/2018/01/vm5-1.jpg) This is the screenshot that you will see to specify the location that you want to import your VM Select the Virtual Machine storage path to store virtual machine files. We’re using the default values here, but if you want to keep your VMs in a specific folder, this is where you would make the change. ![This is the screenshot that you will see after you Choose your VM location](https://www.atlantic.net/wp-content/uploads/2018/01/vm6-1.jpg) This is the screenshot that you will see after you Choose your VM location Select the folder path to store the Virtual Machine hard disk. ![This is the screenshot that you will see after you review and confirmed your options](https://www.atlantic.net/wp-content/uploads/2018/01/vm7.jpg) This is the screenshot you will see after reviewing and confirming your options. Review your configuration selection, and click on Finish to complete the import. Congratulations! You have just Imported A VM in Windows Server 2012. Thank you for following along in this How-To! Check back for any new updates, and try a [VPS hosting](https://www.atlantic.net/vps-hosting/) solution. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # Strengthening Your HIPAA IT Audit & Compliance Department > URL: https://www.atlantic.net/hipaa-compliant-hosting/how-do-i-beef-up-my-hipaa-it-audit-and-compliance-department/ | Published: 2015-07-17 | Updated: 2026-01-09 | Author: Alexander Wise Have you been concerned with meeting the demands of the Health Insurance Portability and Accountability Act? Whether you are a covered entity or business associate, it’s essential to strengthen your HIPAA compliance IT mechanisms now. Let’s look at why compliance is increasingly important and how to quickly “beef up” your efforts. ## **The Debate over Healthcare Regulations** Healthcare companies and the companies that provide services for their protected health information should notice that we have entered a new, more aggressive world when it comes to the connection between HIPAA and technology. While everyone wants their private, protected health information to be safe, the HHS rules are a hotly debated topic, and for a good reason: - **Side #1 – Threat to innovation** – As indicated in *Fortune*, regulations tie the hands of the healthcare field, making it difficult for firms to take advantage of groundbreaking advances in technology. - **Side #2 – Ominous threat landscape** – The massive, long-term hacks of Anthem and Community Health Systems have made the federal government consider compliance a top priority. Innovation is certainly a legitimate concern: health researchers and data scientists could derive better diagnostics and treatments from taking full advantage of big data analytics and other technologies. However, security is fundamental, especially given Reuters’ revelation that health information is worth ten times what credit cards are on the black market. ## **Warnings from HHS OCR** Between June 2013 and June 2014, the Office for Civil Rights posted nine settlements totaling more than $10 million, one of which was of unprecedented size: $4.8 million. To highlight the fact that those fines were just the beginning, head OCR Chicago regional lawyer [Jerome B. Meites told *Law360*](https://www.bakerdatacounsel.com/enforcement/hhs-attorney-major-hipaa-fines-and-enforcement-coming/) the upcoming activity by the regulatory agency would “pale in comparison to the next 12 months.” He added, “Knowing what’s in the pipeline, I suspect that that number will be low compared to what’s coming up.” Fast-forward to June 2015, and we see the same scenario: *HealthITSecurity* reports that Health and Human Services is broadening its audit activities again. This time, the focus is business associates. Beginning in the summer or fall, the HIPAA audit process will start shifting into hyperdrive, with OCR director Jocelyn Samuels noting that both covered entities *and business associates* will now be under scrutiny to verify their HIPAA information technology (a change from previous audit efforts that focused exclusively on healthcare companies). ## **Misconception on HIPAA IT Requirements** You don’t have to be compliant with the healthcare laws if your company is a “mere conduit,” as with many telecoms and IT services. This exemption applies to situations where data is only being transmitted or temporarily stored, such as in a [healthcare hosting](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/) scenario. Any cases that go beyond pure transmission are not considered conduits. Examples include ISPs and paging companies. “The key difference between a conduit and a Business Associate is the transient versus persistent nature of the opportunity to view the PHI,” [said *HealthITSecurity*](https://healthitsecurity.com). “To qualify as a conduit, a service provider must ensure that PHI is only temporarily stored.  It is irrelevant whether the service provider actually views the PHI.” ## **HIPAA Compliance IT**** Surveys & Penalties** The OCR has mailed out initial questionnaires to be filled out by companies that could be audited, many of which are business associates. Based on the information provided by each organization, the Office for Civil Rights will decide whether to move forward with an audit. Some audits will occur directly at businesses, while others will be performed remotely. HIPAA violations can lead to costly penalties, as discussed above. HHS can hit entities with fines in excess of $50,000 for any instance of noncompliance, even if the company didn’t mean to neglect the rule. In more extreme situations, when the agency determines that a violation was intentional and that the organization did not take steps to rectify it, settlements can be as much as $1.5 million for the year. ## **Nutshell Business Associate HIPAA Audit Checklist** The primary concern for business associates is the HIPAA Omnibus Rule. Here is an essential checklist of its expectations: - Implement protections so that PHI is not accessed without authorization - Notify covered entities when data is compromised - Verify that any subcontractors follow the parameters of HIPAA - Complete business associate agreements (BAA’s) with all relevant clients and subcontractors - Record and retain documentation of all healthcare privacy and security efforts. ## **Beef Up HIPAA IT with a Trusted Provider** You are fully responsible for some aspects of [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/), such as staff training and the development of in-house policies and procedures. However, it’s a good idea to simplify the IT hosting aspect by working with an experienced, healthcare-ready provider – especially when beefing up compliance must be fast and error-free. “Atlantic.Net’s reputation for 100% up-time, their secure infrastructure, and expertise in Healthcare IT were key components in finalizing our partnership,” said Complete Healthcare Solutions VP of Product Development Joseph Nompleggi. “Our partner’s financial strength and proven track record are something we view with great confidence.”   Learn more about our [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and experience our fast [VPS Hosting](https://www.atlantic.net/vps-hosting/). --- # What Are HIPAA Compliance Rules and Guidelines? > URL: https://www.atlantic.net/hipaa-compliant-hosting/what-are-hipaa-compliance-rules-and-guidelines/ | Published: 2015-07-20 | Updated: 2025-03-06 | Author: Alexander Wise If you’re looking at IT requirements for healthcare systems, a term that you will come across repeatedly is “[HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/).” This article talks about HIPAA, summarizes the basic HIPAA compliance rules, and briefly addresses a related act, HITECH. ## HIPAA Explained The Health Insurance Portability and Accountability Act (HIPAA) was passed by both houses of US Congress and signed into law by President Bill Clinton in 1996. The act stated that regulations would be developed to serve a dual purpose: 1. Streamline healthcare administration. 2. Ensure that all US citizens’ health records are kept private and secure. “The Act required Congress to enact laws implementing these goals by 1999,” said the Oregon Association of Hospitals and Health Systems (OAHHS). “When Congress failed to do so, DHHS stepped in and began promulgating regulations.” ### What Does It Mean to Be HIPAA-Compliant? When an IT service or healthcare organization describes itself as “HIPAA compliant,” that means that it is following the HIPAA compliance guidelines established within the law to safeguard the medical records (precisely the *protected health information* (PHI) delineated by HIPAA) of American patients. ### Covered Entities & Business Associates Healthcare organizations must stay compliant because they are considered *covered entities*, while IT companies and others must be compliant as a *business associate* of healthcare organizations. Covered entities include healthcare providers (doctors, hospitals), healthcare plans (insurance carriers, company health plans), and health data clearinghouses. Meanwhile, business associates include organizations and individuals that contact the data, including technology service providers (e.g., web hosting firms), accountants, and shredding companies. ### Business Associate Agreements Covered entities and business associates must sign *business associate agreements* to solidify their relationship – the tasks to be performed by the business associate and its responsibilities about the protected health information. It should be noted that there is an exemption for certain companies, called the *mere conduit* exemption, that hosting companies and other organizations often wrongly believe applies to them. The exemption is for companies that temporarily store health data or make incidental contact with it while it is in transit, such as Internet service providers and paging businesses. “The key difference between a conduit and a Business Associate is the transient versus persistent nature of the opportunity to view the PHI,” [explained attorneys Linda McReynolds and Ronald Quirk](http://healthitsecurity.com). “To qualify as a conduit, a service provider must ensure that PHI is only temporarily stored.  It is irrelevant whether the service provider actually views the PHI.” ## HIPAA Compliance Rules There are three primary sections to the regulations, which are largely overseen by the Office for Civil Rights (OCR), an agency within the Department of Health and Human Services (DHHS or HHS): 1. Standards for healthcare transactions 2. The HIPAA Privacy Rule 3. The HIPAA Security Rule ### Standards for Healthcare Transactions These guidelines were essentially an effort to make transactions fit within a uniform framework. They became enforceable on October 16, 2000. However, the rules permitted that covered entities (the providers, plans, and clearinghouses described above) had until October 16, 2002, to develop an appropriate plan of action. The actual, final point at which HIPAA compliance became nonnegotiable was October 2003. ### The HIPAA Privacy Rule This rule, which is a broad set of guidelines, outlines the requirements of healthcare companies related to privacy, such as disclosure of health-related personally identifiable information and instructions for giving privacy notices to patients. According to OAHHS, it also detailed how organizations must “obtain consent and authorization for the use of information and tell how information is generally shared and how patients can access, inspect, copy, and amend their own medical record.” These stipulations became binding on April 2001. Here are a few of the most critical elements for providers: - Privacy notice guidelines - Rules related to patients opting out - “Requirements for minimum necessary.” - Administrative safeguards - The responsibilities of partner organizations (see HITECH information below). ### The HIPAA Security Rule Again, this rule (a set of regulations) specifically states what must be done administratively and what firms must implement HIPAA physical safeguards to maintain compliance. The objective of both the administrative and physical safeguards was to ensure that all PHI was of high integrity (i.e., not lost or manipulated) and was kept away from any unauthorized parties. April 2005 was when companies had to achieve compliance with this rule. ## What About HITECH Compliance? Similar federal legislation important to healthcare organizations is the Health Information Technology for Clinical and Economic Health Act of 2009 (HITECH). “It was passed as a monetary incentive plan for hospitals to begin converting to electronic health records,” [explained the American Bar Association](http://www.americanbar.org/groups/young_lawyers/publications/the_101_201_practice_series/hitech_101.html). Although “the idea was for any hospital to be able to access all of your medical records” – with the basic goal of *interoperability* – privacy and security concerns have limited that fundamental objective. ## HIPAA, HITECH, and Business Associates One section of HITECH that was particularly important created the HIPAA Omnibus Rule, which became effective in September 2013. That rule made business associates directly responsible for maintaining HIPAA compliance. You will notice on our site that HIPAA-compliant solutions are a primary point of focus for Atlantic.Net. We have extensive experience related to healthcare IT systems. Also, note that we’re an American company based in Orlando, Florida, offering [HIPAA Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) Services and blazing fast [VPS hosting](https://www.atlantic.net/vps-hosting/). By Moazzam Adnan --- # What is the CVE-2015-2426 Font Driver Vulnerability? > URL: https://www.atlantic.net/vps-hosting/what-is-cve-2015-2426-font-driver-vulnerability/ | Published: 2015-07-21 | Updated: 2026-01-09 | Author: Alexander Wise On July 20, 2015, Microsoft released a patch (specifically, [MS15-078](https://technet.microsoft.com/library/security/ms15-078)) for a newly announced security vulnerability, named CVE-2015-2426, that affects all supported [Windows VPS](https://www.atlantic.net/vps-hosting/) hosting systems to date. Microsoft has marked this vulnerability as critical and recommends patching all servers as soon as possible. The affected Windows versions include: - Windows Vista - Windows 7 - Windows 8 and 8.1 - Windows Server 2008 - Windows Server 2008 R2 - Windows Server 2012 - Windows Server 2012 R2 - Windows RT and RT 8.1 - Any Server Core Installation   ## What is the CVE-2015-2426 Font Driver Vulnerability? This vulnerability in Microsoft’s Font Driver would allow for remote code execution via specially crafted OpenType fonts. These OpenType fonts could be contained in specially formatted documents or embedded in non-secure web pages.   ## So what does this mean? Microsoft reserves “critical” for its most severe vulnerabilities. In these cases, an attack can bypass existing security measures. For example, if an email comes to you with a legitimate-looking document for you to open or download, or if you visit a website containing one of these embedded OpenType fonts, an attacker could execute malicious code that could install a keylogger, start network attacks against other people, or encrypt all of your files and demand ransom for the decryption key. Those are just a few scary examples of what can be done with remote code execution.   ## How do I get this fixed? Update! Microsoft released, via Windows Update, a patch outside of their regular monthly Patch Tuesday cycle. If you want this specific update, it is labeled [KB3079904](https://support.microsoft.com/en-us/kb/3079904). If you want to manually apply the update outside of Windows Update, see the [TechNet article](https://technet.microsoft.com/library/security/ms15-078) and follow their information for direct download links for each Operating System affected.   ## How does the KB3079904 fix this? The update changes how Windows Adobe Type Manager Library processes and handles OpenType fonts. Once you apply the update and restart your Windows device, you will be safe from the vulnerability. For more details on the MS15-078 patch, check out the [Microsoft Support article](https://support.microsoft.com/en-us/kb/3079904). Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Install Vesta Control Panel on Ubuntu 14.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-vesta-control-panel-ubuntu-14-04/ | Published: 2015-07-21 | Updated: 2026-01-09 | Author: Alexander Wise ## Introduction This tutorial will show you how to install Vesta Control Panel on Ubuntu 14.04. Vesta Control Panel is a free open source control panel that is an excellent alternative to cPanel. After the installation completes, you will have Web, DNS, Database, Mail, and FTP Server. Vesta installs Nginx on the front-end and Apache on the back-end, which essentially gives the best of both worlds. ![Vesta Control Panel Illustration by Walker Cahall](https://www.atlantic.net/wp-content/uploads/2015/07/vest1.png) Vesta Control Panel Illustration by [Walker Cahall](http://www.waltronic.net/) ## Installing Vesta Control Panel Download the Vesta Control panel install script with the following command: ``` curl -O http://vestacp.com/pub/vst-install.sh ``` Once downloaded, we can start the script by running the following command: ``` bash vst-install.sh ``` Your terminal should look similar to the one below. ![An example of the Vesta install. Hit Y and then enter](https://www.atlantic.net/wp-content/uploads/2015/07/vest2.png) An example of the Vesta install. Hit Y and then enter Type `Y` and then `enter` to proceed to the next step. ![Enter a valid email address and then hit enter.](https://www.atlantic.net/wp-content/uploads/2015/07/vest3.png) Enter a valid email address and then hit enter. Enter your email address and hit `enter`. > Note: It is important to enter the correct email address as your server will send important information to it. ![Either hit enter to accept the default hostname or set a new and then hit enter.](https://www.atlantic.net/wp-content/uploads/2015/07/vest4.png) Hit enter to accept the default hostname or set a new and then hit enter. At this step, you can set your hostname or keep your current hostname by hitting `enter`. After hitting enter, the install will begin.  Vesta says it can take up to 15 minutes; however, most of the time, it is much less. ![After selecting the hostname, the installation will begin.](https://www.atlantic.net/wp-content/uploads/2015/07/vest5.png) After selecting the hostname, the installation will begin. Once the installation is complete, you should get an email similar to the one below. It will have the Vesta control panel link, username, and password. ![Once the installation is complete, you will get a screen that has the control panel login](https://www.atlantic.net/wp-content/uploads/2015/07/vest6.png) Once the installation is complete, you will get a control panel login screen. Likewise, you should get an email like the email below, with the same information as above. ![An example of the email sent by Vesta to the email you set up earlier.](https://www.atlantic.net/wp-content/uploads/2015/07/vest7.png) An example of the email sent by Vesta to the email you set up earlier. We can now log in to the Vesta control panel by using one of the links from the terminal or email. ![An example of the Vesta login page](https://www.atlantic.net/wp-content/uploads/2015/07/vest8.png) An example of the Vesta login page Once you log in, you will get a screen similar to the one below. ![An example of the Vesta control panel after logging in](https://www.atlantic.net/wp-content/uploads/2015/07/vest9.png) An example of the Vesta control panel after logging in ## What Next? Congratulations on installing the Vesta Control panel on Ubuntu 14.04.  Please feel free to check back for further updates or[follow our guide on making a website on Vesta here](https://www.atlantic.net/vps-hosting/how-to-make-website-vesta-control-panel/). Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Make a Website on Vesta Control Panel > URL: https://www.atlantic.net/vps-hosting/how-to-make-website-vesta-control-panel/ | Published: 2015-07-23 | Updated: 2026-01-09 | Author: Alexander Wise ## Introduction This tutorial will show you how to make a website on the Vesta Control Panel. Vesta Control Panel is a free open source control panel that is an excellent alternative to cPanel. Creating a website on Vesta is a straightforward process, but it can be cumbersome if you have never done it. ## Prerequisites A server with Vesta Control Panel installed.  If you do not have one, you can follow this [guide](https://www.atlantic.net/vps-hosting/how-to-install-vesta-control-panel-ubuntu-14-04/). If you would like to use a domain name, log in to your registrar’s control panel and point the domain name to your server’s IP. Otherwise, you can use your server’s IP address. ## Create a Website on Vesta Control Panel After logging into the Vesta Control Panel, look towards the top of the Vesta dashboard and click the Web link like the picture below. ![Click Web on the top of the Vesta Control Panel dashboard.](https://www.atlantic.net/wp-content/uploads/2018/01/vesta1-1.png) Click Web on the top of the Vesta Control Panel dashboard. > Note: If this is the first time logging into your Vesta Control Panel, you may see a default web domain. You can delete it if you would like.   To add a new site, click the green plus icon to add a new Domain. ![Click the green plus to make a new domain.](https://www.atlantic.net/wp-content/uploads/2018/01/vesta2-1.png) Click the green plus to make a new domain. Now you can enter your domain name or your server’s IP address in the domain field.  In our example, we are going to use the IP address. Once you have entered your information, click Add. ![Add your domain name or IP address to the Domain field](https://www.atlantic.net/wp-content/uploads/2018/01/vesta3-1.png) Add your domain name or IP address to the Domain field We can now test your new site by going to your browser’s IP address or domain name. You should get a test page similar to the one below. ![An example of the Vesta default test page](https://www.atlantic.net/wp-content/uploads/2018/01/vesta4-1.png) An example of the Vesta default test page You can now FTP to your server and add your site to the public_html folder. Your public_html file should be located in the following directory: ``` /web/your-ip-domain-name/public_html ``` In our example, it is: ``` /web/192.168.100.10/public_html ``` You can get a simple FTP client called [Filezilla here if you need one.](https://filezilla-project.org/) Congratulations! You have just created a website on the Vesta control panel. Thank you for following this guide! Be sure to check back here for updates. ## Atlantic.Net Atlantic.Net offers [VPS hosting](https://www.atlantic.net/vps-hosting/) and [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) solutions, which include a layer of business-essential managed services to your hosting packages. Contact us today for more information. --- # How to Comply with HIPAA > URL: https://www.atlantic.net/hipaa-compliant-hosting/how-to-comply-with-hipaa/ | Published: 2015-07-23 | Updated: 2026-01-09 | Author: Alexander Wise How do you comply with the Health insurance Portability and Accountability Act (HIPAA)? This article covers the four essential elements of the regulations. It also discusses myths associated with the fundamental compliance testing method security risk analysis – most notably, a HIPAA risk analysis checklist is insufficient for compliance. Here are the three basic sections of the HIPAA rules that covered entities and business associates must follow to be considered in compliance with the law – although the third section is the most relevant one for business associates. ## **Transaction Standards** These standards direct healthcare organizations to use uniform standards for digital insurance claims, codes that directly match those used by other providers, and *unique identifiers* (sets of numbers that stand-in for the name of the provider or individual). ## **Privacy Regulations** These provisions, the initial effort to develop HIPAA safeguards, discuss access to and disclosure related to protected health information (PHI); establish expectations of providers for giving patients privacy policies, details on how data is shared, and instructions to access, look over, retrieve, and modify their health records; and talk about the need for permission from patients for any use of their data. ## **Security Regulations** The Oregon Association of Hospitals and Health Systems describes these HIPAA safeguards: “The security regulations dictate the kind of administrative procedures and physical safeguards covered entities must have in place to ensure the confidentiality and integrity of protected health information.” Again, this section is the most critical for business associates such as Web hosting businesses, accountants, and any other companies or individuals with access to protected health information, *regardless of whether they look at it*. As of the enactment of HITECH’s Final Omnibus Rule (September 2013), business associates have been responsible for meeting the so-called Security Rule – the quasi-official nickname that has been given to these HIPAA safeguards. Even business associates’ subcontractors now must meet the security guidelines enforced by the Office for Civil Rights. ## **Breach Notification Regulations** Finally, the Department of Health and Human Services stipulates that all providers, health plans, and data clearinghouses that handle PHI must immediately alert anyone whose health information is compromised. The HHS Secretary must be contacted, and major media outlets when people affected are 501 or more. “Breaches affecting fewer than 500 individuals will be reported to the HHS Secretary on an annual basis,” adds DHHS. “The regulations also require business associates of covered entities to notify the covered entity of breaches at or by the business associate.” ## **10 Myths About Security Risk Analysis** In its efforts to clarify proper HIPAA safeguards and refute the idea that a HIPAA risk assessment checklist suffices for compliance, HealthIT.gov discusses [common myths](http://www.healthit.gov/providers-professionals/top-10-myths-security-risk-analysis) related to these vulnerability tests on one of its SRA tool download pages. They are: Myth #1 – It’s unnecessary for small covered entities. Fact: It’s necessary for 100% of covered entities. Myth #2 – Implementing a federally certified EHR system meets the parameters of the security risk analysis MU. Fact: Regardless of your technology for electronic health records, protected health information includes data beyond EHRs. Myth #3 – EHR business associates are fully responsible for the compliance of their products. Fact: Business associates can give you guidance related to the technology’s HIPAA safeguards, and they must maintain compliance themselves. But you must double-check their products with a risk assessment. Myth #4 – Outside parties must conduct these analyses. Fact: You can achieve compliance by assessing vulnerability yourself, but it is wise to hire an expert to help if you don’t feel your internal team is knowledgeable about the process. Myth #5 – A HIPAA risk analysis checklist is acceptable for compliance. Fact: “Checklists can be useful tools, especially when starting a risk analysis,” says HealthIT.gov, “but they fall short of performing a systematic security risk analysis or documenting that one has been performed.” Myth #6 – There’s only one standard, accepted way to assess risk. Fact: Many methods meet compliance guidelines, but the OCR’s “Guidance on Risk Analysis Requirements” document can help to establish reasonable HIPAA safeguards. Myth #7 – Analyses can be limited to EHR. Fact: All computers and other hardware that comes into contact with PHI – including photocopiers – should be checked and tested. *Note that the most common violation is unencrypted laptops.* Myth #8 – Risk assessment is a one-time event. Fact: The Security Rule requires ongoing monitoring and adaptation. For further information, see the “Reassessing Your Security Practices” guide on HealthIT.gov. Myth #9 – To qualify for EHR incentives, you must correct vulnerabilities before attestation. Fact: Whatever problems are discovered during the risk assessment should be corrected during the reporting period. Myth #10 – The risk assessment must start over from scratch annually. Fact: You tweak it as you go. “Perform the full security risk analysis as you adopt an EHR,” explains HealthIT.gov. “Each year or when changes to your practice or electronic systems occur, review and update the prior analysis for changes in risks.” (Note that the MU incentives necessitate one analysis per reporting period for eligible professionals.) ## **Fully Qualified Business Associates** If you’ve reached the bottom of this article, you’re concerned that your organization doesn’t make any mistakes related to[HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/)or security risk analyses. One of the best ways to protect yourself is working with credible business associates with solid experience.   Atlantic.Net offers award-winning [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) on state-of-the-art SSD Cloud Servers. When asked why Complete Healthcare Solutions trusts *Atlantic.Net with its IT systems, VP of product development* **Joseph Nompleggi said,** “*Our partner’s financial strength and proven track record are something we view with great confidence.”* --- # How to Install WordPress on Vesta Control Panel > URL: https://www.atlantic.net/vps-hosting/how-to-install-wordpress-vesta-control-panel/ | Published: 2015-07-24 | Updated: 2026-05-04 | Author: Alexander Wise ## Introduction This tutorial will show you how to install WordPress on the Vesta Control Panel. Vesta Control Panel is a free open source control panel that is an excellent alternative to cPanel. WordPress is a content management system that is also free and open source. ## Prerequisites A server with Vesta Control Panel and website.  You can follow this [guide](https://www.atlantic.net/vps-hosting/how-to-install-vesta-control-panel-ubuntu-14-04/) to install Vesta, and you can follow this [guide](https://www.atlantic.net/vps-hosting/how-to-make-website-vesta-control-panel/) to make a website. ## Installing WordPress on Vesta Control Panel First, we need to make a Database for WordPress to use.  Log into your Vesta dashboard and click DB like the picture below:   ![Click DB on the top part of the Vesta dashboard.](https://www.atlantic.net/wp-content/uploads/2018/01/vesta1.png) *Click DB on the top part of the Vesta dashboard.*   ## Creating a MySQL database for WordPress After clicking DB, we can now create a database by clicking the green plus like the picture below. ![Click the Green Plus to add a new database](https://www.atlantic.net/wp-content/uploads/2018/01/vesta2.png) *Click Green Plus to add a new database.*   We now need to add the database name, user, and password. You can use anything you like, but save the information as we will need it later. > NOTE: As Vesta explains, the prefix of your user is added to the beginning of your database name and user. > >   ![Add your database name, user and password.Once done click add database](https://www.atlantic.net/wp-content/uploads/2018/01/vesta3.png) *Add your database name, user, and password. Once done, click add database.* ## Getting the WordPress Installation Get the latest WordPress installation by downloading from the WordPress [site](https://wordpress.org/download/). Once downloaded, unzip the files and find the file that says wp-config-sample.   ![An example of the WordPress files after extraction](https://www.atlantic.net/wp-content/uploads/2018/01/vesta4.png) + *An example of the WordPress files after extraction*   We need to rename the wp-confg-sample: right-click it and click Rename.   ![Click rename on the file name wp-config-sample](https://www.atlantic.net/wp-content/uploads/2018/01/vesta5.png) *Click rename on the file name wp-config-sample*   We need to rename wp-confg-sample to wp-confg.   ![Rename the file to wp-config](https://www.atlantic.net/wp-content/uploads/2018/01/vesta6.png) *Rename the file to wp-config* Once renamed, we need to edit wp-config. You can use any text editor that you would like. In this tutorial, we are using [notepad++](https://notepad-plus-plus.org/downloads/v6.8.7/). The following needs to be updated with the information you used when setting up the database. ``` define('DB_NAME', 'admin_wordpress'); /** MySQL database username */ define('DB_USER', 'admin_wpuser'); /** MySQL database password */ define('DB_PASSWORD', 'oeysvULuTm'); ``` Once done, it should look similar to the image below:   ![Edit wp-config](https://www.atlantic.net/wp-content/uploads/2018/01/vesta7.png) *An example of the wp-config file* ## Using FTP to move WordPress to your site Log into your FTP client of choice (in this case, [FileZilla](https://filezilla-project.org/)) and navigate to your WordPress folder on your local computer and the public_html folder on your server. ![FTP to your site and move to the public_html directory](https://www.atlantic.net/wp-content/uploads/2018/01/vesta8.png) *FTP to your site and move to the public_html directory*   Move all the WordPress files from your local computer to your server.   ![Move all of your WordPress files to the public_html file](https://www.atlantic.net/wp-content/uploads/2018/01/vesta9.png) *Move all of your WordPress files to the public_html file.*   Once all the files transfer, you can go to your domain name or IP address in your browser, and you should get the WordPress language page like the one below.   ![Navigate to your IP address or domain in your browser](https://www.atlantic.net/wp-content/uploads/2018/01/vesta10.png) *Navigate to your IP address or domain in your browser, pick your language*   Pick your Language and click Continue.   ![Follow the WordPress web installation.](https://www.atlantic.net/wp-content/uploads/2018/01/vesta11.png) *Follow the WordPress web installation.*   You can now follow along with the WordPress web installation. Congratulations! You have just installed WordPress on the Vesta Control Panel. Thank you for following along with this how-to; please feel free to check back for further updates. Atlantic.Net offers [VPS hosting](https://www.atlantic.net/vps-hosting/) and managed server hosting services that include a layer of business-essential managed services to your hosting packages. Contact us today for more information. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/).     --- # Do I Need to Be HIPAA Compliant? > URL: https://www.atlantic.net/hipaa-compliant-hosting/do-i-need-to-be-hipaa-compliant/ | Published: 2015-07-24 | Updated: 2026-01-09 | Author: Alexander Wise ## **Who needs to Be Compliant?** Business associates are a catch-all group that includes any company performing a service for covered entities that exposes it to protected health information (electronic health records or other data). Covered entities include health care providers, health care plans, and health care clearinghouses. If you are a covered entity or business associate, you need to be compliant with the Health Insurance Portability and Accountability Act. HIPAA Health Care Provider Definition A  HIPAA health care provider is an organization or individual that provides health care services and processes PHI in digital form. Examples include doctors, chiropractors, and pharmacies. Health Care Plan Definition A health care plan is a program set up for a person or business (such as an employer) that pays health care expenses. Examples include health insurance firms and Medicare. Health Care Clearinghouse Definition *What is a healthcare clearinghouse?*These companies convert nonstandard health data into standard health data or vice versa. A healthcare clearinghouse can be “a public or private entity, including a billing service, repricing company, community health management information system or community health information system, and ‘value-added’ networks and switches,” explained Ohio law firm Bricker & Eckler LLP. If you are unsure whether or not you fit one of those definitions, you can complete a short Q & A from the federal government. ## **The Role of the Healthcare Clearinghouse** People are often unfamiliar with that third category, the clearinghouse. The role that it serves is essentially a “middleman” that sends claim data from a provider (such as a clinic) to a payer (such as an insurance company). One of the primary activities conducted by health care clearinghouses is *claims scrubbing*, which essentially checks for any possible mistakes and makes sure the claim is formatted correctly for reading by the payer’s system. “The clearinghouse also checks to make sure that the procedural and diagnosis codes being submitted are valid and that each procedure code is appropriate for the diagnosis code submitted with it,” [said *For Dummies*](http://www.dummies.com/how-to/content/what-is-the-function-of-the-clearinghouse-in-medic.html). “The claim scrubbing edit helps prevent time-consuming processing errors.” ## **Interviewing Business Associates** The first business associates were getting audited in 2015. Your choice of a business associate should now focus even more on credibility since HITECH essentially means broader responsibility: your tech partners and others can now receive penalties as well. Here are several questions that were recently asked of us by a company thinking about switching to our HIPAA server hosting environment. Healthcare client: What is your business continuity plan for HIPAA? HIPAA hosting specialist: Please see our business continuity plan attached. Healthcare client: What is your backup plan for HIPAA? HIPAA hosting specialist: We provide Fully Managed Daily Encrypted Backup for all files and databases on separate Encrypted Storage Nodes. Other information is listed in the attached. Healthcare client: Is there any difference between regular data centers and HIPAA-compliant data centers? Please tell me why it is different. HIPAA hosting specialist: A HIPAA compliant Data Center has been audited for HIPAA and HITECH compliance. Healthcare client: What is your emergency plan? Do your technicians stand by 24/7? HIPAA hosting specialist: We operate a 24 X 7 X 365 Live Engineering support environment. Healthcare client: What is your plan to prevent data leakage? Like USB leakage (Both data center & our office). HIPAA hosting specialist: The documents I have attached cover this question. We are not involved in the customer’s HIPAA compliance in their office environment. This requires that the customer contract with a HIPAA consultant. Healthcare client: According to your website, you are HIPAA compliant, but is there any proof of evidence? (certification/audit) HIPAA hosting specialist: The documents I have attached include HIPAA certification. Healthcare client: As far as my understanding, virtual server hosting has some problems with HIPAA’s security rules. Is it safe to put our data into a virtual server? HIPAA hosting specialist: We will not issue a BAA based on the use of a Public Cloud / private cloud hosting environment (including our own). That does not mean that you cannot create a Private Virtualized environment by using Private Dedicated Server Hardware containing multiple private cloud servers. Healthcare client: What is the price for HIPAA compliant Windows Cloud Hosting?  (access from only one location) HIPAA hosting specialist: With 1 TB of Self-Encrypted Storage, it is $xxx per month on a 12-month agreement with no setup fee. ## **Making Strong HIPAA Choices** HIPAA audits are on the rise, with the DHHS reportedly ready to crack down on any violations. Violations and settlements aren’t just expensive and distracting. They can also be a publicity nightmare since any data compromises affecting 500 people or more must be reported to a major media outlet. Whatever your technical requirements, Atlantic.Net offers the industry-leading [HIPAA Compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solution, audited by a fully qualified and independent third party, among many other service options to support [healthcare hosting](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/). We also offer [HIPAA webhosting](https://www.atlantic.net/hipaa-compliant-hosting/). By Moazzam Adnan --- # How to Configure DNS in Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-configure-dns-windows-server-2012/ | Published: 2015-07-27 | Updated: 2025-03-06 | Author: Alexander Wise ###### Verified and Tested 10/16/23 ## Introduction Domain Name System (DNS) is a system that translates a Domain name to the IP address that is associated with it over the World Wide Web. Once the DNS Server role is installed, it needs to be configured for your domain. In this how-to, we will walk you through Configuring DNS in Windows Server 2012. ## Prerequisites – A Server with Windows Server 2012 – DNS Server Role installed on your server. See the following article, “[Install DNS in Windows Server 2012](https://www.atlantic.net/vps-hosting/how-to-install-dns-role-windows-server-2012/),” if you do not have the DNS role installed. ## Configuring DNS in Windows Server 2012 Open the **Server Manager** from the taskbar. Click on **DNS**/ Right Click **your server** / select **DNS Manager**/ Click the **Action** Tab/ Select **Configure a DNS Server.** ![Select Configure a DNS Server in Windows Server 2012](https://www.atlantic.net/wp-content/uploads/2018/02/dns1.jpg) Select Configure a DNS Server in Windows Server 2012   The **Configure DNS Server Wizard** will come up. Click **Next** to continue and select one of the following actions: – Create a forward lookup zone A**forward lookup zone** is a DNS function that takes a domain name and resolves it to an IP address. – Create forward and reverse lookup zones A**reverse lookup zone** is a DNS function that takes an IP address and resolves it to a domain name. – Configure root hints only **Root hints only**  Will have the IP addresses of DNS servers where records can be acquired. ![This is the Configure DNS Server Wizard screen output in Windows Server 2012](https://www.atlantic.net/wp-content/uploads/2018/02/dns2.jpg) This is the Configure DNS Server Wizard screen output in Windows Server 2012   Select where the DNS data will be maintained for your network resources, and then click **Next** ![Selecting a Primary Server location in Windows Server 2012](https://www.atlantic.net/wp-content/uploads/2018/02/dns3.jpg) Selecting a Primary Server location in Windows Server 2012   Enter your new zone name, in this case, your domain, and click **Next.** ![This is the zone name insert field when configuring DNS in Windows Server 2012](https://www.atlantic.net/wp-content/uploads/2018/02/dns4.jpg) This is the zone name insert field when configuring DNS in Windows Server 2012   Create a new zone file or use an existing one from a different DNS server ![Creating a Zone file when configuring DNS in Windows Server 2012](https://www.atlantic.net/wp-content/uploads/2018/02/dns5.jpg) Creating a Zone file when configuring DNS in Windows Server 2012   Next, you select how your server will respond to Dynamic Updates. ![Select the do not allow Dynamic Updates option while Configuring DNS in Windows Server 2012](https://www.atlantic.net/wp-content/uploads/2018/02/dns6.jpg) Select the do not allow Dynamic Updates option while Configuring DNS in Windows Server 2012   Select whether your DNS server should forward queries or not. If you choose **YES**, type the IP of the server and click **Next**. If **NO**, select No. It should not forward queries and Click **Next**. ![Select one of the options to configure forwarders when Configuring DNS in Windows Server 2012](https://www.atlantic.net/wp-content/uploads/2018/02/dns7.jpg) Select one of the options to configure forwarders when Configuring DNS in Windows Server 2012   Click **Finish,** and you’re all set. ![Completing the DNS configuration in Window Server 2012](https://www.atlantic.net/wp-content/uploads/2018/02/dns8.jpg) Completing the DNS configuration in Window Server 2012 Congratulations! You have just Configured DNS in Windows Server 2012. Thank you for following along in this How-To, and feel free to check back with us for any new updates on our [VPS Hosting](https://www.atlantic.net/vps-hosting/) solutions. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [VPS hosting price](https://www.atlantic.net/vps-hosting/pricing/). --- # How to Change Your Hostname in CentOS 6.9/7.x/8.x > URL: https://www.atlantic.net/hipaa-compliant-hosting/how-to-change-hostname-centos-6-9-7-x-8-x/ | Published: 2015-07-28 | Updated: 2026-01-09 | Author: Alexander Wise ##### Verified and Tested 03/10/2021 ## Introduction This article discusses how to change the hostname  on a server running CentOS 6.9/7.x/8.x. A hostname is a label given to a device that is connected on a network. ## Prerequisites A server with CentOS 6.9/7.x/8.x installed. ![Hostname Illustration by Walker Cahall http://www.waltronic.net/](https://www.atlantic.net/wp-content/uploads/2018/02/hostname1.png) Hostname Illustration by [Walker Cahall](http://www.waltronic.net/) ## Modify your hostname in CentOS 6.9 If you’d like to change your CentOS server’s hostname, you’ll need to change it in a few places. Open up the /etc/sysconfig/network file with your text editor of choice: ``` sudo vim /etc/sysconfig/network ``` Change the HOSTNAME argument to the hostname you’d like to use. Here, we’ll be changing the old hostname of ‘bespin’ to ‘endor’. See below for more information on valid hostnames: ![1](https://www.atlantic.net/wp-content/uploads/2018/01/host1.png) ![2](https://www.atlantic.net/wp-content/uploads/2018/01/host2.png) This change will take effect the next time you reboot your server. Before you do, though, you might want to also add the hostname to your /etc/hosts file. Again, with your text editor of choice: ``` sudo vim /etc/hosts ``` In this instance, we’ll add our new hostname ‘endor’ to the entry for the loopback address 127.0.0.1 (and for fun, for the IPv6 loopback). We might also add an entry for an IP address configured on this server: ![3](https://www.atlantic.net/wp-content/uploads/2018/01/host3.png)At this point, the next time you reboot your server, your new hostname would show up in your command prompt and would also show up with the ‘hostname’ command. If you would rather not reboot your server, you can change the hostname with the ‘hostname’ command: ``` sudo hostname yourhostname ``` ![4](https://www.atlantic.net/wp-content/uploads/2018/01/host4.png) You may change the hostname with this command alone, but the next time you reboot your server, it would not be persistent and would load whatever hostname is still in the /etc/sysconfig/network file. Also, you may notice that the hostname in your command prompt hasn’t changed. If you’re the sort who’s going to be annoyed by that (or, if you’d like to avoid the confusion of seeing the old hostname in the command prompt), then log out of the current session. When you log back in, the new hostname will show up in the command prompt. One other caveat: until you do reboot your server after a hostname change, you may also notice that your logs still use the old hostname. ## Changing your Hostname in CentOS 7.x and 8.x If you are used to how CentOS 6 or earlier handles the hostname, you may notice that the same procedure doesn’t quite work the same way in CentOS 7 and 8. If you’re new to CentOS, in general, then you have no baggage to worry about having to leave behind! In CentOS 7 and 8, hostname control is handled with the hostnamectl command. With this command, you can update three different hostnames–the static, transient, and pretty. To see what your hostname currently is, issue the **hostnamectl** status command. ``` hostnamectl ``` ![An example of the hostnamectl status command](https://www.atlantic.net/wp-content/uploads/2018/02/hostname2.png) *An example of the hostnamectl status command* Here, we only have the static hostname listed, which in this case, is identical to the transient and pretty hostnames. The static hostname is the one currently stored in /etc/hostname: ![An example of the cat /etc/hostname command](https://www.atlantic.net/wp-content/uploads/2018/02/hostname3.png) *An example of the cat /etc/hostname command* The static hostname is the default hostname the kernel references during boot, and in most instances, will be the one you want to concern yourself with. (We’ll briefly cover transient and pretty hostnames in a bit.) To change the hostname, issue the following command: ``` hostnamectl set-hostname "Your-Hostname" ``` In this case, we’ll be changing the current hostname of ‘bespin’ to ‘Endor’s Forest Moon’. Note what happens with the following comand: ``` hostnamectl status ``` ![An example of the hostnamectl set-hostname and hostnamectl command](https://www.atlantic.net/wp-content/uploads/2018/02/hostname4.png) *An example of the hostnamectl set-hostname and hostnamectl command* A couple of things to note here. First, when specifying the hostname, I enclosed the full hostname in double-quotation marks. This syntax is only required when using a hostname that contains characters not ordinarily allowed in a standard FQDN, such as a space or an apostrophe. They can be omitted if your hostname will conform to FQDN standard formatting (see below for more information on FQDN formatting). Next, also note how in the hostnamectl status output, we now have line entries for static and pretty hostnames. Hostnamectl automatically removes illegal hostname characters and also converts the name to all lowercase for the static (and transient) hostname. It also writes this information to the /etc/hostname file as well. You can see it by running the following command: ``` cat /etc/hostname ``` ![Sample /etc/hostname](https://www.atlantic.net/wp-content/uploads/2018/02/hostname5.png) *Sample /etc/hostname* One thing the hostnamectl command doesn’t do is modify the /etc/hosts file, so we’ll still need to do that. Just open up that file with the text editor you prefer and change the current hostname entry (‘bespin’) to the new static hostname (‘endorsforestmoon’): Using NANO ``` nano /etc/hosts ``` Using VIM ``` vim /etc/hosts ``` ![Sample /etc/hosts](https://www.atlantic.net/wp-content/uploads/2018/02/hostname6.png) *Sample /etc/hosts* ![Sample /etc/hosts](https://www.atlantic.net/wp-content/uploads/2018/02/hostname7.png) *Sample /etc/hosts* At this point, you are all set; your hostname is changed. If you are concerned that it’s not showing up in your command prompt, you will have to log out and log back in. Now, to help demonstrate some of the differences between types of hostname, let’s set the transient hostname and take a look at the output from hostnamectl status. It should be noted here that if you want to specify any particular hostname change, you would include which type of hostname (–static, –pretty, or –transient). This parameter can be included at nearly any point in the command, so long as it’s immediately preceded by the double hyphens. Any of the following would work:   ``` sudo hostnamectl --transient set-hostname coruscant ``` ``` sudo hostnamectl set-hostname --transient kashyyyk ``` ``` sudo hostnamectl set-hostname tatooine --transient ```   ![An example of the sudo hostnamectl set-hostname tatooine --transient command](https://www.atlantic.net/wp-content/uploads/2018/02/hostname8.png) *An example of the sudo hostnamectl set-hostname tatooine –transient command* Since we haven’t made any changes to the static hostname (or the contents of the /etc/hostname file), which remains the same, and should this server reboot, it will pick up this hostname. The pretty hostname remains “Endor’s Forest Moon”, which can be called in certain instances when presenting the hostname to the user. This configuration is stored in /etc/machine-info. The transient hostname changes the hostname in the running kernel, but unless that same change is also made to the static hostname, it won’t persist across reboots (or, if the transient hostname is assigned/maintained via something like DHCP, then also when network connectivity is lost). This example is more illustrative than practical, of course. ## Valid Hostname Restrictions In each of these configurations, you’ll need to be sure your hostname conforms to the standards for FQDNs (Fully Qualified Domain Names). The ASCII letters a – z, the digits 0 – 9, and the hyphen (‘-‘) are the only characters acceptable (the first character, however, cannot be a hyphen). You may also find it necessary (or useful) to include the domain name as well, in which case you would then also use periods (dots) to separate the hostname and the domain name (and top-level domain). So the following would be examples of acceptable hostnames: bespin.the-empire.starwars endor.rebelalliance.starwars The whole hostname should be no more than 255 characters (see RFC1123). ## What Next? With that, you now have a server with a hostname. Thank you for following along and feel free to check back with us for further updates, or check out our CentOS 7 initial setup up guide. Cloud hosting is just one of the many hosting services offered by Atlantic.Net – We also offer dedicated, managed and [secure HIPAA cloud hosting & storage](https://www.atlantic.net/hipaa-compliant-hosting/) services. Contact us today for more information on any of our services! --- # How to Install OpenVAS Vulnerability Scanner on CentOS 7 > URL: https://www.atlantic.net/disaster-recovery/how-to-install-openvas-vulnerability-scanner-centos-7/ | Published: 2015-07-29 | Updated: 2026-02-28 | Author: Alexander Wise ## Introduction This how-to will guide you on installing OpenVAS (Open Vulnerability Assessment System) on CentOS 7. The OpenVAS application is free and open source vulnerability scanner and vulnerability management solution. With the significant Vulnerabilities that have come out recently it is a good idea to have a scanner that can detect vulnerabilities on the systems that you manage. ## Prerequisites A server with CentOS 7 installed.  If you do not have a server, why not fire up an extremely fast SSD [cloud server](https://www.atlantic.net/vps-hosting/pricing/) from Atlantic.Net ## Install OpenVAS Vulnerability Scanner on CentOS 7 We first need to install the Atomic repo with the following command: ``` wget -q -O - http://www.atomicorp.com/installers/atomic | sh ``` > NOTE: If wget is not installed, install it with the following command: > > ``` > yum install wget > ``` Next we need to install bzip2, which is a high-quality data compressor that the OpenVAS setup uses. Install it with the following command: ``` yum install bzip2 ``` Now we  can install the OpenVAS application with the following command: ``` yum install openvas ``` Next we need to make some changes to the Redis configurations. You can use your favorite editor to change /etc/redis.conf In this example, we are using NANO. ```  nano /etc/redis.conf ``` Uncomment unixsocket /tmp/redis.sock and unixsocketperm 700. It should look similar to the following: ``` # Specify the path for the Unix socket that will be used to listen for # incoming connections. There is no default, so Redis will not listen # on a unix socket when not specified. # unixsocket /tmp/redis.sock unixsocketperm 700 ``` Once you have made the changes, you can save and exit. Now we need to restart and enable redis with the following commands: ``` systemctl enable redis ``` ``` systemctl restart redis ``` We can now run the openvas setup with the following command: ``` openvas-setup ``` At the start of the install, it will prompt you with the following question. ``` Once completed, this will be updated automatically every 24 hours Select download method * wget (NVT download only) * curl (NVT download only) * rsync Note: If rsync requires a proxy, you should define that before this step. Downloader [Default: rsync] ``` Click enter for rsync or choose wget or curl, rsync is the recommended choice. > Note: Dependng on the time of day the install may fail due to rysnc not being able to connect to certain NVT’s, if this happens just run openvas-setup again At the end of the install, it will prompt you with the following: ``` Step 3: Choose the GSAD admin users password. The admin user is used to configure accounts, Update NVT's manually, and manage roles. Enter administrator username [Default: admin] : Enter Administrator Password: Verify Administrator Password: ``` You can use admin as the default user or set your own, and then provide a secure password and verify it again. Now that OpenVAS is complete you can now test it by opening your browser and entering the URL `https://your-server's-address:9392` You should get a page similar to the image below. > Note: If you do not know your IP address, run the following command: > > ``` > ip addr show eth0 > ``` > > ![An example of running the command: ip addr show eth0 and getting 192.168.100.10 for the IP address. ](https://www.atlantic.net/wp-content/uploads/2015/07/anet-install-lamp-centos-7-03.png) An example of running the command: ip addr show eth0 and getting 192.168.100.10 for the IP address.In our example, we would put `https://192.168.100.10:9392` into our browser’s address bar.   ![An example of the connection is not private page, click Advanced and click proceed to yoursite (unsafe)](https://www.atlantic.net/wp-content/uploads/2018/01/centos2.png) An example of the connection is not private page, click Advanced and click proceed to yoursite (unsafe) Since there is no SSL installed on the server, we are going to get a warning that the connection is not private.  Proceed to the website and we should get a page similar to the one below. ![An example of the OpenVAS login page.](https://www.atlantic.net/wp-content/uploads/2018/01/centos3.png) An example of the OpenVAS login page. Login with the credentials you set up during the openvas-setup and you should get a page similar to the one below. ![Follow the quick start guide to get started.](https://www.atlantic.net/wp-content/uploads/2018/01/centos4.png) Follow the quick start guide to get started. Congratulations you now have OpenVAS vulnerability scanner installed on CentOS 7. Use the quick start guide on the dashboard to get yourself started. Be sure to check out the [OpenVAS](http://www.openvas.org/) site and join their [mailing list](http://lists.wald.intevation.org/mailman/listinfo/openvas-announce). ![An example of running the command: ip addr show eth0 and getting 192.168.100.10 for the IP address. ](https://www.atlantic.net/wp-content/uploads/2018/01/centos1.png) An example of running the command: ip addr show eth0 and getting 192.168.100.10 for the IP address. Thank you for reading this how-to! Be sure to check back for more updates, and to learn more about our cloud hosting solutions, including [HIPAA compliant disaster recovery](https://www.atlantic.net/disaster-recovery/) services. --- # How to Configure RDP in Windows Server 2008 R2 > URL: https://www.atlantic.net/vps-hosting/how-to-configure-rdp-windows-server-2008-r2/ | Published: 2015-07-30 | Updated: 2026-03-02 | Author: Alexander Wise ##### Verified and Tested: 3/24/15 ## Introduction This how-to will go over basic configurations for Remote Desktop Protocol (RDP) within Windows Server 2008 R2. ## Configure RDP in Windows Server 2008 R2 To access your Remote Desktop settings, click on the **Server Manager **icon in the lower-left corner of your desktop next to your **Start** button. ![How to Access Windows Server Manager](https://www.atlantic.net/wp-content/uploads/2018/01/rdp1.png) Windows Task Bar – Accessing Server Manager On the right side of your **Server Manager **window, you will see a link to **Configure Remote Desktop**under **Computer Information**. Click on this link to view your Remote Desktop settings. ![How to Access Remote Desktop Configuration in Server Manager](https://www.atlantic.net/wp-content/uploads/2018/01/rdp2.png) Server Manager Default Page Normally, all servers have Remote Desktop enabled for all users. While this works well, you may want to restrict remote desktop access to a few select users. To do this, click on the third option then click on the **Select Users… **button.   ![System Properties Remote Tab](https://www.atlantic.net/wp-content/uploads/2018/01/rdp3.png) System Properties found in Server Manager. It defaults to the Remote tab when accessed from the ‘Configure Remote Desktop’ link on the main page. Click on the **Add… **button to add another user to the list.   ![Remote Desktop Users](https://www.atlantic.net/wp-content/uploads/2018/01/rdp4.png)   Remote Desktop Users. Administrators have access by default. Type the user’s name in the text box, and then click **Check Name** for the server to locate them. Then click **OK.** ![Selecting a User for Remote Desktop Access](https://www.atlantic.net/wp-content/uploads/2018/01/rdp6.png) The ‘Check Names’ button will be clickable after entering a username. ![Remote Desktop Users Update List](https://www.atlantic.net/wp-content/uploads/2018/01/rdp7.png) All user access for Remote Desktop can be modified from here in the future. Once you see that the user is added to the list, click **OK.** Note that as long as Remote Desktop is enabled the Administrator account will always have access. You can then click **Apply **to apply the settings to the server and **OK** to exit the configuration. Congratulations! You have just Configured RDP in Windows Server 2008. Thank you for following along in this How-To. Feel free to check back with us for any new updates, related articles like [HIPAA Compliant RDP Servers: Is RDP HIPAA Compliant?](https://www.atlantic.net/hipaa-compliant-hosting/are-rdp-servers-hipaa-compliant/) Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [Virtual private servers.](https://www.atlantic.net/vps-hosting/) --- # How to Install Java (JRE or JDK) on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-java-ubuntu-20-04/ | Published: 2015-07-30 | Updated: 2026-01-09 | Author: Alexander Wise ![Java Illustration by Walker Cahall](https://www.atlantic.net/wp-content/uploads/2018/01/Ubuntu1.png) Java Illustration by [Walker Cahall](http://www.waltronic.net/) ##### Verified and Tested 06/02/21 ## Introduction If you had the option to choose between a base model car or a fully loaded model, which one would you choose? Both cars will take you from point A to point B, but with the fully-loaded car, you have additional features that can make rush hour a chill hour. Well, that’s the same concept when we take a closer look at Java. There are two standard types of installations, JRE (Java Runtime Environment) and JDK (Java Development Kit). Like the base model car, JRE enables the ability to create Java applications for different types of deployments using minimal core tools to accomplish the task. JDK is a fully loaded Development Kit that has everything that JRE has plus additional resources to create/secure Applications and Applets. ## Installing Java on Ubuntu 20.04 Before we begin, let make sure that the server is fully updated with the following command: ``` sudo apt-get update ``` After your server has been fully updated, you will need to know what version of Java is currently installed or if it is not installed, with the following command: ``` java -version ``` Once you have verified if Java is installed or not, choose the type of Java installation that you want with the following: ``` sudo apt-get install default-jdk sudo apt-get install default-jre ``` The above command will install the latest version of Java available in the Ubuntu default repository. ## Install Java Open JRE or JDK on Ubuntu 20.04 If you want to install the specific Java version, run the following command: ``` sudo apt-get install openjdk-8-jre sudo apt-get install openjdk-8-jdk ``` ## Install Java Oracle JRE or JDK on Ubuntu 20.04 Another alternative Java install is with Oracle JRE and JDK. By default, Oracle Java is not available in the Ubuntu default repository. So you will need to download it from the Oracle website. First, log in to the Oracle website and visit the [Oracle Download](https://www.oracle.com/java/technologies/javase-downloads.html) page. Then, pick your desired Java version and download it to your server. In this section, we will download **jdk-11.0.8_linux-x64_bin.tar.gz.** Once the download is completed, create a directory for Java installation: ``` sudo mkdir -p /var/cache/oracle-jdk11-installer-local ``` Next, copy the downloaded file to the directory: ``` sudo cp jdk-11.0.8_linux-x64_bin.tar.gz /var/cache/oracle-jdk11-installer-local/ ``` Next, install some required dependencies: ``` sudo apt-get install software-properties-common gnupg2 -y ``` Next, add the Java key with the following command: ``` sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys EA8CACC073C3DB2A ``` Next, add the Java repository with the following command: ``` sudo add-apt-repository ppa:linuxuprising/java ``` Next, update the repository and install the Oracle Java with the following command: ``` sudo apt-get update -y sudo apt-get install oracle-java11-installer-local -y ``` If you have multiple versions of Java installed on your server, then you have the ability to select a default version. Check your alternatives with the following command: ``` sudo update-alternatives --config java ``` Output: ``` There are 3 choices for the alternative java (providing /usr/bin/java). Selection Path Priority Status ------------------------------------------------------------ 0 /usr/lib/jvm/java-11-openjdk-amd64/bin/java 1111 auto mode 1 /usr/lib/jvm/java-11-openjdk-amd64/bin/java 1111 manual mode * 2 /usr/lib/jvm/java-11-oracle/bin/java 1091 manual mode 3 /usr/lib/jvm/java-8-openjdk-amd64/jre/bin/java 1081 manual mode Press to keep the current choice[*], or type selection number: 1 ``` Once you have viewed your alternatives, choose the version that you want by selecting the assigned number, and then hit enter. ## Setup JAVA_HOME on Ubuntu 20.04 Since many programs nowadays need a **JAVA_HOME** environment variable to work properly. We will need to find the appropriate path to make these changes. With the following command, you can view your installs and their path: ``` sudo update-alternatives --config java ``` A directory path listing for each installation is below: ``` /usr/lib/jvm/java-11-openjdk-amd64/ /usr/lib/jvm/java-11-oracle/ /usr/lib/jvm/java-8-openjdk-amd64/ ``` To edit the environment file use your text editor and edit the following file: ``` sudo nano /etc/environment ``` Now that you are in the environment file, add the following code along with the Path of your installation from the previous step. ( Example: JAVA_HOME=”YOUR_PATH”) ``` JAVA_HOME="/usr/lib/jvm/java-11-oracle/" ``` Reload the file so all your changes could take effect with the following command: ``` source /etc/environment ``` Verify that your implementations are correct with the following command. Confirm : ``` echo $JAVA_HOME ``` ## What Next? Congratulations! You now have successfully installed Java on your Ubuntu server. Thank you for following along and feel free to check back with us for further updates or check out other helpful Ubuntu How-to’s in our blog. Cloud hosting is just one of the many hosting services offered by Atlantic.Net – we also offer [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) services. Contact us today for more information! --- # Q & A: HIPAA Compliant Report Writer Control System > URL: https://www.atlantic.net/hipaa-compliant-hosting/q-a-hipaa-compliant-report-writer-control-system/ | Published: 2015-07-31 | Updated: 2026-03-01 | Author: Alexander Wise Since we focus so much on the healthcare industry, we regularly receive questions from HIPAA covered entities and their tech partners looking for compliant hosting services. We were recently contacted by a customer interested in encrypted storage, remote access, Web (Apache) and DB (MySQL) servers for a [HIPAA-compliant](https://www.atlantic.net/hipaa-compliant-hosting/) report writer control system (RWCS). Here is an excerpt of our interaction, sourced from the real transcripts. (*Note: Anonymity is maintained, and any intellectual property or other sensitive details are omitted.)* ## **Consultant:** Thank you for contacting Atlantic.Net. We need answers to the following questions in order to provide you with a formal proposal. It is possible that one of the packages on our website will meet your requirements based on the answers to our questions. In the meantime, I have attached our BAA and HIPAA audit for your review. 1 ) Do you require a Linux or Windows Platform? 2 ) How much Data Storage do you require, and will you be encrypting the data before it is stored? 3 ) How many internal users will be accessing the hosting platform? 4 ) Are you running both a Web / app server and a Database server? If you are, then HIPAA requires that they are hosted on separate servers. We accomplish this by creating separate Virtual Machines on the dedicated server. 5 ) Do you require any special software (eg, database software). ## **Client:** 1 ) Linux 2 ) 100 GB of data storage. Files will not be encrypted prior to being written to disk.  Will an encrypted disk partition suffice in this case? 3 ) We have one administrator who would be accessing the systems directly, via command line. 4 ) We will be running both web (Apache) and DB servers (MySQL).  Separate virtual machines are fine. 5 ) No special software.  Standard Red Hat or CentOS Linux operating system, with the ability for our administrator to install software as needed. **Consultant:** You will require the SAS (FIPS) encrypted hard drives. The smallest ones are 1 TB in size and they require a RAID 1 Configuration with a hardware RAID card. The Linux Cloud Hosting package for xxx per month that is on our website is the minimum HIPAA package we an offer. We can add some enhancements to it and still provide you with the same pricing. We will increase the RAM to 24 GB so that we have enough RAM to create the Web and DB VM’s. We will also add in cPanel w/ WHM for Linux at no extra charge to the Web VM. We can set up a Lamp Stack for you or you will have SSH access, and you install it yourself. If we install it, there is a one-time $xxx charge. The formal pricing proposal is attached, as well as supporting documents. Here are highlights: 1 ) Fully Managed Hardware Firewall 2 ) ( 5 ) Managed “Encrypted” VPN’s 3 ) Intrusion Detection System 4 ) Fully Managed Daily Backup 5 ) Private Dedicated Server Platform - Linux CentOS 6.5 64-bit - 4 Virtual Core Processors - 24 GB of RAM - 1 TB of “Encrypted” RAID Storage - ( 2 ) Virtual Machines (Web and DB) 6 ) 10 TB of Monthly Data Transfer with a 100 Mbps Port 7 ) 100% Uptime SLA 8 ) cPanel w/ WHM 9 ) Trend Micro Deep Security 10 ) 24 X 7 X 365 Live Technical Support by email / chat / phone 11 ) Business Associate Agreement 12 ) HIPAA Audited Data Center with SSAE SOC 2 Certification *$ xxx per month on a 12 month agreement with no setup fee.* **Client:** Thank you for the information. Just a few more questions… 1) For the VMs, what virtualization software do you use?  Can we have more VMs added to our server in the future? 2) For the Managed Firewall, what’s the typical support response time for getting firewall rules updated?  Is the “managed” firewall a HIPAA requirement, or can we self-manage? 3) For the IDS, how can we manage any exceptions that need to be considered (false positives, etc.)? 4) For the web VM, we do not require cPanel or WHM or the LAMP stack installed, just a base install of 64-bit CentOS. With that said, can we swap the cPanel/WHM add-on for a few more dedicated IP addresses? **Consultant:** Here are the answers to your questions: 1) We use KVM / Proxmox, and we will create the first 2 VM’s for you (and more if you want us to initially). We do not charge to create the VM’s at the time of the deployment, but after the deployment we charge $xxx per VM as a one-time charge. We also can hand the Hypervisor over to you, and you can create your own VM’s. If you plan on creating more VM’s we will change out the processor to an E3-1245 V2 Xeon 8-core processor and 32 GB of RAM at no extra charge. The processors we use can only hold 32 GB of RAM. The dedicated server can hold ( 2 ) more hard drives for future expansion because the RAID card is a 4-port card. 2) We can change firewall rules within 15 to 20 minutes of receiving the request, and we have 24 X 7 X 365 phone / email / chat support. The fully managed firewall is our requirement, and we will not allow customers to manage the firewalls. 3) You would work with our engineering department to manage this since the IDS is also managed by us. 4) We can do that, but the IP’s have to be justified, and I have attached the IP justification form. We can provide up to 32 IP’s but I cannot guarantee that the Justification will be approved. IPv4 IP’s are very tight. Attached you will find an updated proposal and the IP Justification form. **Client:** We would be comfortable having full access to the Hypervisor once the two initial VMs are setup by your team.  On the IP addresses, I only need another 29. Q: I have been with the same dedicated server provider for over 10 years, and switching to a new company will be a big move. Are there month-to-month terms or shorter (quarterly, etc…) that we could negotiate? **Consultant:** We can provide a month-to-month agreement, and the monthly pricing is $ xxx per month. **Client:** After discussions with my team, we have some modifications to our requirements for HIPAA-compliant hosting.  We will not need the self-encrypting disks as we will not be storing ePHI on the server. I will also not be storing any health information in a database. The database will only be used for user credentials.  So I would not necessarily need a separate virtual machine for the database. The server will act as an authentication point and a transit pipe for data, moving it from client to server (another server where the data will be stored at rest, not on your network). I will still need the access control (VPN), IDS, Firewall and BAA options you proposed.  Would you mind letting me know what the pricing would be in this case? **Consultant:** The month-to-month pricing, based on your updated specs, would be $ xxx per month. You will still have the option of changing to the 12-month pricing at a future date. ## **Getting Your Questions Answered** Is your business in the healthcare industry? We know that finding a strong, truly 100% compliant host can be a huge headache. As you can see above, we can work with you to build a system with the technical requirements for a [HIPAA-compliant server](https://www.atlantic.net/hipaa-compliant-hosting/) you need. Our extensive, state-of-the-art healthcare infrastructure has been comprehensively audited by a fully accredited independent third party.    We offer reliable [SSD Cloud Servers](https://www.atlantic.net/vps-hosting/) with 100 percent uptime guarantee. --- # Linux, Apache, MySQL, PHP (LAMP) auf Debian 8 oder 8.1 Cloud Server oder VPS installieren > URL: https://www.atlantic.net/vps-hosting/linux-apache-mysql-php-lamp-auf-debian-8-oder-8-1-cloud-server-oder-vps-installieren/ | Published: 2015-08-01 | Updated: 2026-01-09 | Author: Alexander Wise Überprüft und getestet am 26.4.2015 ## Einleitung In dieser Anleitung werden Sie erfahren, wie Sie LAMP auf Ihrem Debian 8 oder 8.1 Cloud Server oder VPS installieren LAMP ist ganz einfach ein Software-Bundle, das aus vier Komponenten besteht. Linux stellt dabei die Basis der Plattform dar, da alle Komponenten innerhalb der Linux-Umgebung installiert werden. In diesem Fall werden wir Debian 8 oder 8.1 als Linux-OS verwenden. Apache wird für den Webserver eingesetzt. MySQL nutzen wir für die Datenbankverwaltung und PHP als Programmiersprache. Diese Komponenten bezeichnet man zusammengenommen als LAMP-Stapel. ## Voraussetzungen Ein Server, auf dem Debian 8 installiert ist. Falls Sie noch keinen Server haben, können Sie hier unsere Cloudhosting-Seite besuchen und innerhalb von 30 Sekunden einen neuen Server einrichten. ## LAMP auf Debian 8 oder 8.1 installieren Fangen wir zunächst damit an, Apache zu installieren. Apache ist ein Open-Source-Webserver und wird weltweit am häufigsten als Webserver eingesetzt. ## Apache auf Debian 8 oder 8.1 installieren Installieren Sie Apache mit dem folgenden Befehl, um die Installation zu starten: ``` apt-get install apache2 ``` Überprüfen Sie, ob alles funktioniert, indem Sie Ihren Browser öffnen und auf http://ihreipadresse gehen Falls Sie unsicher sind, wie Ihre IP-Adresse lautet, führen Sie den folgenden Befehl aus: ``` ip addr show eth0 ``` ![Ein Beispiel, bei dem ip addr die IP-Adresse 192.168.100.10 ausgibt](https://www.atlantic.net/wp-content/uploads/2018/01/installieren1.png) Ein Beispiel, bei dem ip addr die IP-Adresse 192.168.100.10 ausgibt In unserem Beispiel würden wir dann also http://192.168.100.10 in die Adresszeile eingeben und die folgende Seite erhalten: ![Ein Beispiel für die Standard-Apache- Seite auf Debian 8](https://www.atlantic.net/wp-content/uploads/2018/01/installieren2.png) Ein Beispiel für die Standard-Apache- Seite auf Debian 8 ## MySQL auf Debian 8 oder 8.1 installieren Installieren Sie MySQL mit dem folgenden Befehl: ``` sudo apt-get install mysql-server libapache2-mod-auth-mysql php5-mysql ``` Während der Installation werden Sie dazu aufgefordert, ein Root-Passwort für MySQL einzugeben. Legen Sie ein beliebiges Passwort fest. ![Ein Beispiel für die Einstellung, die der MySQL- Kennwort während der Installation.](https://www.atlantic.net/wp-content/uploads/2018/01/installieren3.jpg) Ein Beispiel für die Einstellung, die der MySQL- Kennwort während der Installation. Sichern Sie Ihr MySQL ab, indem Sie mit dem folgenden Befehl die Standardeinstellungen überschreiben: ``` mysql_secure_installation ``` Hinweis: Sie werden dazu aufgefordert, eine Reihe von Fragen zu beantworten. Geben Sie einfach N bei der Änderung des Root-Passworts ein und Y für Ja bei allen weiteren Fragen, wie im folgenden Screenshot dargestellt: ![Ein Beispiel für die Fragen während mysql_secure_installation](https://www.atlantic.net/wp-content/uploads/2018/01/installieren4.jpg) Ein Beispiel für die Fragen während mysql_secure_installation ## PHP auf Debian 8 oder 8.1 installieren Installieren Sie PHP mit dem folgenden Befehl, um die Installation zu starten: ``` apt-get install php5 ``` Erstellen Sie eine PHP-Testdatei in dem folgenden Verzeichnis mit dem unten stehenden Befehl: ``` nano /var/www/html/info.php ``` Geben Sie den folgenden Code in das leere Feld ein. Speichern Sie den Code anschließend und schließen Sie das Programm. ``` ``` Starten Sie Apache neu, damit die Änderungen übernommen werden: ``` service apache2 restart ``` Testen Sie die Seite in Ihrem Browser mit dem folgenden Hyperlink, wobei Sie natürlich Ihre IP-Adresse einsetzen müssen: http://ihreipadresse/info.php ![Ein Beispiel für die php.info Datei, die auf Debian 8 erstellt wurde.](https://www.atlantic.net/wp-content/uploads/2018/01/installieren5.png) Ein Beispiel für die php.info Datei, die auf Debian 8 erstellt wurde.   Glückwunsch! Sie haben soeben LAMP auf Ihrem Debian 8 Server installiert. Vielen Dank, dass Sie dieser Anleitung gefolgt sind. Bitte besuchen Sie diese Seite wieder für neue Updates oder lesen Sie sich die Anleitung zur Installation von WordPress auf Debian 8 durch! --- # Cómo Instalar o Linux, Apache, MySQL, PHP (LAMP) No Debian 8 ou 8.1, Servidor Nuvem ou VPS > URL: https://www.atlantic.net/vps-hosting/como-instalar-o-linux-apache-mysql-php-lamp-no-debian-8/ | Published: 2015-08-01 | Updated: 2026-03-02 | Author: Alexander Wise Verificado e Testado 04/26/2015 ## Introdução Nesse Guia de Procedimentos, nós te guiaremos para instalar o LAMP no seu Debian 8 ou 8.1, Servidor Nuvem ou [VPS](https://www.atlantic.net/vps-hosting/). LAMP é simplesmente um pacote de software que consiste de 4 componentes. Linux é a base da plataforma; todos os componentes estão instalados dentro do ambiente Linux. Nesse caso, nós usaremos o Debian 8 ou 8.1 para Linux OS. Será usado o Apache para serviço na web. MySQL será usado para o gerenciamento do banco de dados, e o PHP será a linguagem de programação. Tudo junto forma-se o LAMP, que também é chamado de LAMP Stack. ## Pré-Requisitos Um servidor com o Debian 8 instalado. Se você ainda não tiver um servidor, você pode visitar a nossa página de Hospedagem de Nuvem aqui e gerar um novo servidor dentro de 30 segundos. ## Instalando o LAMP no Debian 8, 8.1 Primeiro instalaremos o Apache. Apache é um servidor de rede de código aberto e é o servidor de rede mais popular do mundo. ## Instalando o Apache no Debian 8, 8.1 Instale o Apache com o seguinte comando para começar a instalação: ``` apt-get install apache2 ``` Verifique se tudo está funcionando abrindo o seu navegador e acessando http://youripaddress Se você não souber qual é o seu endereço IP, execute o seguinte: ``` ip addr show eth0 ``` ![Um exemplo de ipaddr mostra o IP de 192.168.100.10](https://www.atlantic.net/wp-content/uploads/2018/01/instalando1.png) Um exemplo de ipaddr mostra o IP de 192.168.100.10 No nosso exemplo, nós colocaríamos http://192.168.100.10 na barra de endereços e obter a seguinte página: ![Um exemplo da página padrão do Apache no Debian 8](https://www.atlantic.net/wp-content/uploads/2018/01/instalando2.png) Um exemplo da página padrão do Apache no Debian 8 ## Instalando o MySQL no Debian 8. 8.1 Instale o MySQL com o seguinte comando: ``` sudo apt-get install mysql-server libapache2-mod-auth-mysql php5-mysql ``` Durante a instalação, ele solicitará que você digite uma senha de raiz do MySQL. Defina uma senha que você desejar. ![Um exemplo da definição da senha MySQL durante a instalação.](https://www.atlantic.net/wp-content/uploads/2018/01/instalando3.jpg) Um exemplo da definição da senha MySQL durante a instalação. Proteja o MySQL nas configurações padrão com o seguinte comando: ``` mysql_secure_installation ``` Nota: Será solicitada uma série de perguntas. Simplesmente digite N para mudar a senha de raiz e Y para sim em todos eles, consulte a captura de tela abaixo: ![Um exemplo das perguntas durante mysql_secure_installation](https://www.atlantic.net/wp-content/uploads/2018/01/instalando4.jpg) Um exemplo das perguntas durante mysql_secure_installation ## Instalando o PHP no Debian 8, 8.1 Instale o PHP com o seguinte comando para iniciar a instalação: ``` apt-get install php5 ``` Criar um arquivo de teste PHP no seguinte diretório com o seguinte comando: ``` nano /var/www/html/info.php ``` Insira o seguinte código no espaço vazio, em seguida, salve e saia: ``` ``` Reinicie o Apache para que todas as alterações façam efeito: ``` service apache2 restart ``` Teste a sua página no seu navegador com o seguinte hiperlink alterado com seu endereço IP: http://youripaddress/info.php ![Um exemplo do arquivo php.info que foi criado em Debian 8](https://www.atlantic.net/wp-content/uploads/2018/01/instalando5.png) Um exemplo do arquivo php.info que foi criado em Debian 8 Parabéns! Você acabou de instalar o LAMP no seu Servidor Debian 9. Obrigado por percorrer todo esse Guia de Procedimentos, por favor verifique novamente por mais atualizações ou de uma olhada no nosso Guia de Procedimentos de como instalar o WordPress no Debian 8! --- # Cómo Instalar Linux, Apache, MySQL, PHP (LAMP) sur le serveur cloud Debian 8 ou 8.1 Cloud Server ou VPS > URL: https://www.atlantic.net/vps-hosting/como-instalar-lamp-debian-8-cloud-server-vps/ | Published: 2015-08-01 | Updated: 2026-03-02 | Author: Alexander Wise Vérifié et testé le 26/04/2015 ## Introduction Dans ce guide, nous vous guiderons pendant l’installation de LAMP sur votre serveur cloud Debian 8 ou 8.1 ou votre VPS. LAMP est tout simplement un ensemble de logiciels qui comprend quatre composants. Linux sert de base pour la plate-forme; tous les composants sont installés dans l’environnement Linux. Dans ce cas-ci, nous allons utiliser Debian 8 ou 8.1 comme système d’exploitation de Linux. Nous allons nous servir d’Apache comme service web. MySQL sera utilisé pour la gestion de bases de données, et PHP servira de langage de programmation. Mis ensemble, tous ces éléments forment LAMP, aussi connu sous le nom de pile LAMP. ## Prérequis Un serveur avec Debian 8 doit être installé. Si vous ne disposez pas déjà d’un serveur, vous pouvez visiter notre page d’hébergement cloud ici et en installer un nouveau en moins de 30 secondes. ## Installer LAMP sur Debian 8 ou 8.1 Commençons d’abord par installer Apache. Apache est un serveur web disponible en open source, et il s’agit du serveur web le plus populaire au monde. ## Installer Apache sur Debian 8 ou 8.1 Installez Apache en effectuant la commande suivante pour commencer l’installation : ``` apt-get install apache2 ``` Vérifiez si tout fonctionne en ouvrant votre navigateur et en visitant l’adresse http://votreadresseIP Si vous ne savez pas quelle est votre adresse IP, exécutez la commande suivante : ``` ip addr show eth0 ``` ![Un exemple de ipaddr montrant l'adresse IP 192.168.100.10](https://www.atlantic.net/wp-content/uploads/2018/01/comoinstalar1.png) Un exemple de ipaddr montrant l’adresse IP 192.168.100.10 Dans notre exemple, en inscrivant http://192.168.100.10 dans la barre d’adresse, nous arrivons à la page suivante : ![Un exemple de la page par défaut d'Apache sur Debian 8](https://www.atlantic.net/wp-content/uploads/2018/01/comoinstalar2.png) Un exemple de la page par défaut d’Apache sur Debian 8 ## Installer MySQL sur Debian 8 ou 8.1 Installer MySQL avec la commande suivante : ``` sudo apt-get install mysql-server libapache2-mod-auth-mysql php5-mysql ``` Pendant l’installation, vous serez invité à entrer un mot de passe de racine MySQL. Inscrivez le mot de passe de votre choix. ![Un exemple de la mise en le mot de passe lors de l'installation de MySQL .](https://www.atlantic.net/wp-content/uploads/2018/01/comoinstalar3.jpg) Un exemple de la mise en le mot de passe lors de l’installation de MySQL . Sécurisez MySQL à partir des paramètres par défaut avec la commande suivante : ``` mysql_secure_installation ``` Remarque : Vous serez invité à répondre à une série de questions. Il suffit de taper N pour changer le mot de passe de racine et Y pour répondre oui à chaque question. Voir la capture d’écran ci-dessous : ![Ein Beispiel für die Fragen während mysql_secure_installation](https://www.atlantic.net/wp-content/uploads/2018/01/comoinstalar4.jpg) Ein Beispiel für die Fragen während mysql_secure_installation ## Installer PHP sur Debian 8 ou 8.1 Commencez l’installation de PHP en effectuant la commande suivante : ``` apt-get install php5 ``` Créez un fichier PHP de test dans le répertoire suivant avec la commande suivante : ``` nano /var/www/html/info.php ``` Insérez le code suivant dans l’espace vide, puis sauvegardez et quittez : ``` ``` Redémarrez Apache afin que tous les changements prennent effet : ``` service apache2 restart ``` Testez votre page dans votre navigateur avec l’hyperlien suivant modifié avec votre adresse IP : http://votreadresseIP/info.php ![Un exemple de fichier de php.info qui a été créé sur Debian 8 .](https://www.atlantic.net/wp-content/uploads/2018/01/comoinstalar5.png) Un exemple de fichier de php.info qui a été créé sur Debian 8 . Félicitations ! Vous venez d’installer LAMP sur votre serveur Debian 8. Merci d’avoir suivi ce guide. N’hésitez pas à revenir pour plus de mises à jour ou pour jeter un œil à notre guide d’installation de WordPress sur Debian 8 ! --- # Atlantic.Net Cloud – How Can I Update My Customer Information For My Cloud Account > URL: https://www.atlantic.net/vps-hosting/atlantic-net-cloud-how-can-i-update-my-customer-information-for-my-cloud-account/ | Published: 2015-08-02 | Updated: 2025-08-04 | Author: Alexander Wise ## Introduction In this article, we will be going over how to update customer information for your [cloud hosting](https://www.atlantic.net/vps-hosting/) account. Some of this information includes billing, password, account information, and credit card information. ## Prerequisites To update information, you will first need an active account. Please see “Getting Started With Atlantic.Net Cloud Services” for more info. ## Getting Started! Begin by logging into your account via cloud.atlantic.net. Be sure to use your full registered email address as your login followed by the password credentials that were emailed to you when you initially signed up for the services. Please refer to the image below. ![](https://www.atlantic.net/wp-content/uploads/2015/08/how-can-i-update-my-customer-information-formy-cloud-account-1.png) *Screenshot of the login page via cloud.atlantic.net* ## Updating Password Once logged into your account, on the upper right-hand corner next to your login there is a drop-down. Click on the drop-down arrow and click on “Settings” from the list of options. ![](https://www.atlantic.net/wp-content/uploads/2015/08/how-can-i-update-my-customer-information-formy-cloud-account-2.png) *Example of the “Settings” option via cloud.atlantic.net* When you click on this tab, you will be taken to a different window, shown below, where you will have the ability to update the password credentials for your account. Please keep in mind that you will have to enter your current password, followed by the new password, and end it by retyping the new password. Once done click on the “Update Password” button. ![](https://www.atlantic.net/wp-content/uploads/2015/08/how-can-i-update-my-customer-information-formy-cloud-account-3.png) *Example of the “Account Settings” page via cloud.atlantic.net* ## Change Account Information To edit your account information follow the same steps by logging into your account, and clicking the “Settings” tab. This will take you to the “Account Settings” window which is the same window used to update your password. Click on “Change Account Information”, and this will open up a drop-down that will allow you to edit this information. Once done editing, click on the “Update Account Information” button to apply changes (below image). ![](https://www.atlantic.net/wp-content/uploads/2015/08/how-can-i-update-my-customer-information-formy-cloud-account-4.png) *Example of the “Account Settings” page via cloud.atlantic.net* ## Change Billing Information You can update billing information for your account in the same window where you edited your password, and account information. Simply click on “Change Billing Information” to reveal the drop-down. Here you will be able to edit billing information for your account. Once done click on the “Update Billing Information” button. ![](https://www.atlantic.net/wp-content/uploads/2015/08/how-can-i-update-my-customer-information-formy-cloud-account-5.png) *Example of the “Account Settings” page via cloud.atlantic.net* ## Change Credit Card Information The last field you can edit on the “Account Settings” window is your credit card information. To do so click on “Change Credit Card Information”. Here you can update credit card type, credit card number, expiration date, and security code. Please be aware that this will be the card on file for your account that will be charged monthly for services rendered. Once you have completed filling out credit card details click on the “Update Credit Card Information” button, as referenced in the screenshot below. ![](https://www.atlantic.net/wp-content/uploads/2015/08/how-can-i-update-my-customer-information-formy-cloud-account-6.png) *Example of the “Account Settings” page via cloud.atlantic.net* ## Conclusion It is fairly simple to update any kind of information for your account. Everything is located in the same section, and the new control panel is very user-friendly just like all of our [affordable cloud hosting solutions](https://www.atlantic.net/vps-hosting/). --- # How To Add an Additional IP Address in WHM cPanel > URL: https://www.atlantic.net/vps-hosting/how-to-add-an-additional-ip-address-in-whm-cpanel/ | Published: 2015-08-03 | Updated: 2026-03-02 | Author: Alexander Wise ## **Introduction** This tutorial will walk you through adding an additional IP address to your WHM/cPanel server. Additional IP addresses can be used for services such as additional sites, mail handling, or DNS, to name a few. ## **Prerequisites** –  A server with cPanel installed. If you do not have a server, try our one-click [cPanel Hosting](https://www.atlantic.net/vps-hosting/). – Administrator-level credentials to the Web Hosting Management (WHM) interface. – An additional IP address to assign (see your network administrator if you’re not sure). ## **Adding an Additional IP Address to an Existing WHM/cPanel Installation** Open up your WHM administration interface (e.g., https://mysite.com:2087) from your web browser of choice. From the WHM home page, select “IP Functions”. (Alternatively, you could search “New” in the search bar in the upper left and select “Add a New IP Address” in the filtered menu options on the left.) ![](https://www.atlantic.net/wp-content/uploads/2015/08/anet-additional-ip-cpanel-01.png) WHM IP Options selection Choose “Add a New IP Address”. ![](https://www.atlantic.net/wp-content/uploads/2015/08/anet-additional-ip-cpanel-02.png) WHM Add a New IP Address option This page will allow you to add a single IP or a range of IPs. If you have just one IP to add, enter it in the box for “New IP or IP range to add:” and select the subnet mask for this IP. For example, we might enter the IP 192.168.10.21 as our additional IP, and if this IP is a part of the 192.168.10.0/24 subnet, then we would use the 255.255.255.0 subnet mask. If you’re not sure, please see your network administrator. ![](https://www.atlantic.net/wp-content/uploads/2015/08/anet-additional-ip-cpanel-03.png) WHM adding an additional IP address If you have a range of IPs to add, you may also do so via CIDR notation or by hyphenating the range as indicated on this WHM page. Note: as you enter the IP, you’ll see a red indicator warning you the IP or IP range is invalid. This indicator will turn into a green check when it recognizes a valid entry. When you click “Submit”, you will receive a green “Success” box float up from the lower right of the page. If you’d like to confirm that success (or that you entered the correct IP), you can select the “Show or Delete Current IP Addresses” menu option on the left side of this page to see what is currently assigned. ![](https://www.atlantic.net/wp-content/uploads/2015/08/anet-additional-ip-cpanel-04.png) WHM showing IPs currently assigned Now the new IP address is ready to be used. Congratulations on installing an additional IP on WHM/cPanel. Thank you for following this how-to, please be sure to check back here for more updates. --- # Atlantic.Net Cloud – How To Reprovision A Cloud Server > URL: https://www.atlantic.net/vps-hosting/atlantic-net-cloud-how-to-reprovision-a-cloud-server/ | Published: 2015-08-03 | Updated: 2026-03-02 | Author: Alexander Wise ## Introduction In this article, we will be reviewing how to reprovision a cloud server. Reprovisioning a cloud server will allow you to keep the current IP address assigned to your server, but choose a new plan or operating system. This walkthrough will show you how to complete this process. ## What Do You Need? In order to complete this process, you will first need an active [Atlantic.Net cloud server](https://www.atlantic.net/vps-hosting/). Please see “Getting Started With Atlantic.Net Cloud Services” for more information. ## Procedure Start by logging in to your account at cloud.atlantic.net. Once logged in, click on “Servers” located on the upper left-hand side. This will display all active servers on your account. Click on the server you wish to reprovision from the list, as shown below. ![](https://www.atlantic.net/wp-content/uploads/2015/08/How-To-Reprovision-A-Cloud-Server-1.png) When you click on the server you wish to reprovision, another window will appear, like the one pictured below. This window displays all the network information for your server. Click on the “Reprovision” button that appears in this window. ![](https://www.atlantic.net/wp-content/uploads/2015/08/reprovision-server1-1024x592-1.png) Next, the “Reprovision Your Server” window will pop up. This window will allow you to choose a different operating system for your server as well as a new hosting package. Once you have selected your new OS and plan, click on the “Reprovision Operating System” button located on the bottom right. This will reprovision the server with the new information. When the process is completed, the server will be accessible once again. ![](https://www.atlantic.net/wp-content/uploads/2015/08/reprovision-server2-1024x602-1.png)![](https://www.atlantic.net/wp-content/uploads/2015/08/reprovision-server3-1024x250-1.png) ## Conclusion By following these simple steps, you can reprovision an existing cloud server within minutes. The best aspect about this feature is you can reprovision at any time with no additional cost to our customers. --- # EMM, BYOD & Cloud – How the Cloud Improves Enterprise Mobility Management > URL: https://www.atlantic.net/vps-hosting/emm-byod-cloud/ | Published: 2015-08-03 | Updated: 2026-01-09 | Author: Alexander Wise Cloud computing and enterprise mobility management (EMM) are a perfect combination. A [VPS Hosting](https://www.atlantic.net/vps-hosting/) option can enable easier deployment, security, and control of EMM scenarios, particularly bring-your-own-device (BYOD). - **Why BYOD?** - **EMM Via the BYOD Cloud for Security** - **Cloud-Delivered EMM Prevents Time-Wasting** - **Cloud BYOD Optimizes Efficiency** - **Strong Cloud Partner for BYOD** Cloud computing and the gradual transition to a work environment without walls are related trends that create opportunities for businesses. Using cloud, companies can develop a stronger competitive edge and streamline their businesses with mobile, as long as they adopt strong and secure management of their employees’ devices. ## **Why BYOD?** BYOD gives your organization immediate access to cloud systems while empowering each individual member of your staff to log in through their own smartphones and tablets. This type of policy has become popular globally. One indication is a poll of United Kingdom CIOs asking if the workers could access their system remotely using mobile devices and laptops. “Over 500 CIOs were questioned for recent research about their attitudes to remote and flexible working,” [explains tech writer Antony Savvas](http://www.itproportal.com/2014/04/30/byod-and-cloud-computing/), “which found that 48 percent of office workers can now work from home and on the go.” The study also found that 7 in 10 companies believe creating broader IT options increases customer satisfaction and minimizes lost workdays. Research from the United States on the rise of BYOD through the cloud is similarly compelling. Already back in 2013, 3 out of 5 firms had a bring-your-own-device system in place, with 54% using the cloud in some manner. We all know that both of those technological approaches have grown massively over the last two years. ## **EMM Via the BYOD Cloud for Security** Cloud essentially enables strong security of BYOD. What if someone steals an employee’s cell phone? If that happens, the thief could get access to all sorts of company information. Actually, theft is only one of your concerns: 46% of people say that they sometimes allow others to use their work devices, says Miles Young of CloudTweaks. “With [cloud computing] services, all storage and data processing occurs outside the mobile devices,” he explains. “As information isn’t stored on any employee’s device, corporate documents enjoy greater security.” Furthermore, enterprise mobility management systems can make sure that all your BYOD-connected devices are free of malware and viruses. Another capability of EMM is to allow you to clear out all the data on a device if it goes missing. That’s critical because one out of every three people say that work data on their smart phones and tablets is *unencrypted*. It’s important to also remember that criminal hackers typically consider phones and tablets as prime locations for entry into a system. Still, be careful with the element of security. “To best protect end users and the enterprise, mobile security must go beyond the device,” says [Fernanda Aspe on TechTarget](http://searchcloudcomputing.techtarget.com/feature/Enterprises-see-clear-advantage-of-cloud-computing-and-BYOD-combo). “It is imperative for IT to ensure that the cloud provider offers centralized security in the cloud when end users use mobile-based applications to access corporate data.” ## **Cloud-Delivered EMM Prevents Time-Wasting** BYOD is essentially about access, and that access is both positive and negative. Just as your employees have access to the workplace from anywhere, they also will have many distractions on that BYOD-enabled personal device as well. Through cloud enterprise mobility management, you will better be able to see what employees are doing. Obviously that can quickly get invasive, but if you have cloud web traffic filters set up, you can see what your workers are doing while they are on the job – information that is clearly reasonable for you to know. Do you want to preserve your employees’ privacy? That’s noble, but consider workers may be taking advantage of the business. An example is provided by a case recently brought to a trade union’s legal team. Members of labor unions often have access to attorneys to avoid employer abuses, but sometimes people who contact those lawyers are clearly in the wrong. In 2015, a member of the International Brotherhood of Electrical Workers complained that he was wrongly fired. As a result, the IBEW state office opened an investigation. In its defense, the company sent GPS records to the lawyers showing that the electrician’s work vehicle spent about an hour a day at his home address when he was supposed to be working. The same basic principle applies online: do you really want to be paying someone to check their Instagram and play solitaire? By blending cloud with BYOD, you can minimize distraction among your employees. ## **Cloud BYOD Optimizes Efficiency** If the business picks out every device that’s used, that situation is obviously simpler to manage. You know that the computer is right there at their workstation, where it will always be. BYOD is more challenging to manage, but cloud systems make it much easier and less disruptive. “Should a worker’s preferred device become lost, stolen, or inoperable, they can simply start working on another machine,” explains Savvas. “With all vital data stored on the cloud, this process is seamless.” ## **Strong Cloud Partner for BYOD** Would you like a dependable Cloud Server to host your enterprise mobility management system? We offer per-second-billed, pay-as-you-go, developer-friendly cloud hosting. Cloud hosting services are only one of our offerings – we also offer dedicated hosting, managed hosting, and [VPS hosting](https://www.atlantic.net/vps-hosting/). By Moazzam Adnan --- # Atlantic.Net Cloud – Can I Scale Up My Cloud Server? > URL: https://www.atlantic.net/vps-hosting/atlantic-net-cloud-can-i-scale-up-my-cloud-server/ | Published: 2015-08-03 | Updated: 2026-03-02 | Author: Alexander Wise ##### Verified and Tested 03/26/2015 ## Getting Started! In this article, we will be going over how to scale up your server on the Atlantic.Net Cloud. This process can be done anytime you would like to upgrade your server. This will not harm any data currently stored on the server, and will upgrade your server specs to the next price plan. Scaling your server is a fairly simple task and should only take a few minutes to complete. ## Prerequisites A provisioned cloud server. See “How To Create Your First Atlantic.net Cloud Server” for more information. ## Step One First login to your Cloud account at cloud.atlantic.net. You want to sign in using your full registered email address as your login, and then input the password credentials that were emailed to you when you first activated your account, as shown below. ![](https://www.atlantic.net/wp-content/uploads/2015/08/can-I-scale-up-my-cloud-server-11.png) *Example of the Login page via cloud.atlantic.net* ## Step Two Once you have accessed your control panel, on the left-hand side there should be a tab that reads “Servers”. Click on the “Servers” tab and that will list all of the active servers on your account. From here you want to click on the server you wish to scale, as shown in the screenshot below. ![](https://www.atlantic.net/wp-content/uploads/2015/08/can-I-scale-up-my-cloud-server-2.png) *Example of the “Your Servers” window via cloud.atlantic.net* ## Step Three After you have selected the cloud server, you wish to scale you will be directed to a different window with a few options, such as the one pictured below. It is important before we proceed to make sure that you fully shut down the server for the changes to take effect properly. If the server is not entirely shutdown, the scaling could fail, and you will need to start the process over again. You can shutdown the server as you would any other computer. Once you have ensured that the server is shutdown you want to click on the button that reads “Resize”. ![](https://www.atlantic.net/wp-content/uploads/2015/08/can-I-scale-up-my-cloud-server-3.png) *Example of the “Resize” option via cloud.atlantic.net* ## Final Step For the last step, you want to choose the plan you would like to scale up to, and click on the “Scale Server” button. Please be advised that this process does not assign a new IP to the server. The previous IP assigned to the server will be the same IP allocated to it once the scaling process is completed. Please refer to the below screenshot. ![](https://www.atlantic.net/wp-content/uploads/2015/08/Can-I-scale-up-my-cloud-server-4.png) *Example of the “Scale Up Your Server” window via cloud.atlantic.net* ## Conclusion Scaling the server is a very simple process that can be done in minutes. This process makes adding resources to your server quick and painless just like all [Atlantic.Net cloud server solutions](https://www.atlantic.net/vps-hosting/). --- # How to Set up Nameservers via cPanel & WHM > URL: https://www.atlantic.net/vps-hosting/how-to-set-nameservers-via-cpanel-whm/ | Published: 2015-08-04 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 03/25/2015 ## Introduction This guide will take you through configuring Nameservers on a cPanel & WHM server. These Nameservers will be your name servers and will be usable for your domains. This guide assumes you have already gone through the initial configuration steps for your server and that you can log into WHM. We will be using BIND for our DNS services. ## Set up Nameservers via cPanel & WHM The first step to creating your name servers in cPanel & WHM is to obtain a secondary public IP address and assign it to your server. If you do not know how to do this,[you may follow the guide here](https://www.atlantic.net/vps-hosting/how-to-add-an-additional-ip-address-in-whm-cpanel/). It is recommended to reserve 2 IPs for this so that your Nameservers run on their IPs and your websites can run on a third. The second thing to do is make sure that BIND or your choice of DNS services is enabled. To do this in WHM type “nameserver” in the search bar and go to “Nameserver Selection.” Once there simply look to see if you have a service enabled. If not, we will be using BIND in this tutorial so select BIND and hit “Save.” This will install BIND. Once the check/installation of DNS services is complete, you will want to make sure you have your website or DNS zone created.[You can follow this guide here](https://www.atlantic.net/vps-hosting/how-to-add-a-website-in-cpanel-and-whm-on-centos-6-7/) [if you do not know how to make a website or this guide here](https://www.atlantic.net/vps-hosting/how-to-create-dns-zone-cpanel-whm/) if you do not know how to make a DNS zone. You only need to do one or the other. If you are hosting your website on this server, then create the website, otherwise if your website is elsewhere, just make the DNS zone. Once you have the website or zone made, you will need to edit it. To do this type “dns” in the search bar and go to the “Edit DNS Zone.” Once there select the website/zone you will be making the nameservers out of and click on Edit. ![anet-cpanel-ns-00](https://www.atlantic.net/wp-content/uploads/2018/01/nameservers1.png) Click edit DNS zone   In the edit you will be presented by a page similar to the below image. You will want to scroll down to the “Add New Entries Below this Line” section and insert your values for ns1 and ns2 as A records using your reserved IPs. If you did not reserve 2 IPs, you can use the server’s IP for one of the nameservers and the additional IP you reserved as the second. Once done, click “Save.” ![anet-cpanel-ns-01](https://www.atlantic.net/wp-content/uploads/2018/01/nameservers2.png) Insert values for ns1 and ns2   If you will be using your own nameservers to host the website they are named after, go back to edit the DNS Zone and edit where it has listed the NS records for your domain to be your new nameservers. Hit “Save” to make the changes. The last thing to do is if you will be using these nameservers for all websites you will create on this server, go to “Basic cPanel & WHM Setup” and scroll down to the bottom. You will find the Nameservers section and here you will want to put in your new nameservers. Once done, click on Assign IP address and it should correctly assign the IPs that you have assigned the nameservers. Then click “Save” to save the new changes. ![anet-cpanel-ns-02](https://www.atlantic.net/wp-content/uploads/2018/01/nameservers3.png) Click Assign IP address on each nameserver   And that is it. You have created your own nameservers and can make websites that can utilize them. Please note that after making your own nameservers, propagation throughout the Internet can take up to 48 hours so do expect some downtime while the nameservers propagate. Do not forget, in order to use the nameservers, you need to set your domains’ nameservers at the Registrar level to point to the nameservers you have created. This includes the nameservers for the domain the nameservers are made from. And as a last mention of note. If you would like to have proper nameservers that will not go down, it is recommended to have 2 servers with each server acting as one of the nameservers (you simply make a nameserver the IP of each server or additional IP for each server.) You would just need to replicate your DNS zones between the two servers. This is mainly useful if you will be using your nameservers to host websites that are not contained on the same server as your nameservers. --- # What Makes Cloud Computing Such a Powerful Technology? > URL: https://www.atlantic.net/vps-hosting/what-makes-cloud-computing-such-a-powerful-technology/ | Published: 2015-08-04 | Updated: 2026-01-09 | Author: Alexander Wise As we all know, technology moves fast. Cloud, which first started to gain prominence in 2006, has been gathering speed ever since. According to a forecast from Global Industry Analysts, Inc. (GIA), the worldwide market for cloud hardware alone will exceed $79 billion by 2018. Cloud has become so widespread behind the scenes that the vast majority of people probably have no idea how much they are relying on the technology. ## **Cloud – It’s About Getting Things Done** Okay, so cloud is big – but what exactly are we talking about here? Here’s my quick and dirty definition: it’s a construct for designing a server that virtualizes the machine so that it is using *immediately available resources* from a distributed pool of physical computers, often thousands of them, to increase speed, reliability, and affordability. TechTarget also talks of the cloud in terms of[resources](http://searchcloudcomputing.techtarget.com/definition/cloud-computing): “Cloud computing enables companies to consume computing resources as a utility — just like electricity — rather than having to build and maintain computing infrastructures in-house.” TechTarget adds that the cloud has three primary characteristics differentiating it from the physical, legacy, in-house architectures that it is quickly replacing: - Self-service provisioning, allowing customers to manage and design their own systems for fast deployment - Scalability, allowing customers to obtain more or less resources based on how much a system is being used - Near-real-time, variable pricing, allowing customers to pay based on how much power and space they require (for instance, our cloud systems use *per-second billing*). Why such a heavy emphasis on resources? Cloud Hosting is really all about delivery of resources. Who cares what else they are? There is a reason that cloud computing, despite its fluffy, physical name, is seen as incredibly boring by so many: it is the back end. Technologists may be able to discuss cloud more thoroughly and passionately, but when it comes down to it, it is fundamentally a vehicle for the functionality of the front end. That falls in line with the philosophy of  the Information Technology Infrastructure Library  (ITIL) certification: IT is essentially about delivering a service, not about establishing policy. ITIL says that IT should offer a portfolio or menu of services to **get things done** – allowing payroll, email, lead generation, etc., to be fast and accessible. Cloud can be considered the realization of that philosophy. The IT team gets out of the way and offers up platforms, infrastructure, and software *as a service*, immediately available, with the power of a supercomputer. ## **Parity of IT Access Throughout the Business World** The accessibility of cloud also has meant that the playing field is leveled. Previously only the largest enterprises could afford to set up such absurdly powerful systems. Now, as Jennifer Hutchinson of InfoStreet puts it, you can have amazing infrastructure if you can count to five (which is hopefully a requirement for going into business). In terms of the parity between SMB’s and large corporations that this technology allows, “[t]here’s much less investment and risk required to adopt and use new technology,” [says BT business development director John Brennan](http://thenextweb.com/insider/2015/04/07/why-2015-will-be-the-year-that-the-cloud-comes-of-age/). “[S]ervice agreements can be adapted to a company’s size through flexible pricing models, which has given all companies equal access to the latest … tools and capabilities.” ## **The Case of São Paulo, Brazil** São Paulo, Brazil, has been struggling with lack of water since rainfall has been much less plentiful than is historically the case. The primary water supply for the city, the Cantareira system, usually contains about 155 billion gallons of water in the summer, but now it is empty and drawing on emergency reserves. That is a huge problem – not just in terms of drinking water, plumbing, and other direct uses, but in terms of power. Much of the electricity for the city comes from hydroelectric sources: water running through huge dams keeps on the lights and runs the electronics in this massive metropolis of 20 million people. Forget the electricity for a minute, though:  this is truly a water emergency. People have sometimes not been able to go to work because there has not been enough water to flush the toilets. Some people are even drilling through their floors to access the water beneath their homes. São Paulo, like any major city worldwide, is dependent on indoor plumbing. No water and business cannot continue. Let’s go back to that idea of cloud computing as resources. Just as lack of water in São Paulo is threatening the economy and even people’s lives, lack of IT resources has made it difficult for businesses to compete in many cases. With the cloud, says City Network CEO Johan Christenson, you essentially have your systems up and running in a snap of your fingers. “Your project manager sets up 15 machines over five countries in two minutes during the meeting for a new project,” he says. “Cloud computing will soon be a basis for our everyday processes and without it, you will lose ground to your competitors.” ## **Partners to Compete in the Business World** Water is necessary for life and business: these droughts worldwide are humanitarian crises that must be addressed. Cloud is increasingly necessary too, an essential technology for innovation and resource delivery moving forward. With Atlantic.Net, you can have a [Virtual Private Server](https://www.atlantic.net/vps-hosting/) up and running in 30 seconds, with per-second billing of on-demand computing resources. Cloud hosting services are only one of our offerings – we also offer dedicated hosting, managed hosting, and [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/). --- # How to Install Apache on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-apache-ubuntu-20-04/ | Published: 2015-08-05 | Updated: 2026-03-03 | Author: Alexander Wise ## Introduction This how-to will help you with your install and configuration of Apache on your Ubuntu 20.04 server. Apache is a web server that is very popular in Linux systems and over the Internet. It is used by many Web Hosting companies worldwide because of its popularity and efficiency in hosting sites over the World Wide Web. ## Prerequisites You need a Ubuntu 20.04 server that is configured with a static IP address. If you do not have a server already, you can spin up a secure [virtual private server](https://www.atlantic.net/vps-hosting/) in under 30 seconds. ## Install Apache on Ubuntu 20.04 The first step is to install Apache with the following command: ``` sudo apt-get install apache2 ``` Start Apache with the following command: ``` service apache2 start ``` Verify if all is working by typing http://YOUR.IP.ADD.RESS Your IP could be retrieved from the server with following command: ``` ifconfig eth0 | grep inet | awk '{ print $2 }' ``` ![This image is the default web page when installing Apache on Ubuntu 20.04](https://www.atlantic.net/wp-content/uploads/2018/01/apache1.png) This image is the default web page when installing Apache on Ubuntu 20.04 ## Configure Apache (Single Host) We will now configure Apache by opening the main configuration file and edit ServerName and  ServerAdmin lines accordingly. ``` nano /etc/apache2/sites-available/000-default.conf ``` ``` # The ServerName directive sets the request scheme, hostname and port that # the server uses to identify itself. This is used when creating # redirection URLs. In the context of virtual hosts, the ServerName # specifies what hostname must appear in the request's Host: header to # match this virtual host. For the default virtual host (this file) this # value is not decisive as it is used as a last resort host regardless. # However, you must set it for any further virtual host explicitly. #ServerName www.example.com ServerAdmin webmaster@localhost DocumentRoot /var/www/html # Available loglevels: trace8, ..., trace1, debug, info, notice, warn, # error, crit, alert, emerg. # It is also possible to configure the loglevel for particular # modules, e.g. #LogLevel info ssl:warn ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined # For most configuration files from conf-available/, which are # enabled or disabled at a global level, it is possible to # include a line for only one particular virtual host. For example the # following line enables the CGI configuration for this host only # after it has been globally disabled with "a2disconf". #Include conf-available/serve-cgi-bin.conf # vim: syntax=apache ts=4 sw=4 sts=4 sr noet ``` Save the file and restart the Apache HTTP service, so the changes take effect. ``` service apache2 restart ``` Now you can create/upload your web content to the HTML directory of Apache.(Remember to replace the existing index.html file with your index.html which is your home page) ``` nano /var/www/html/index.html ``` ` ` ## Configure Apache (Multi-Host) If you would like to host multiple websites, proceed by opening the main configuration file, copy the existing Virtual Host entry and paste it underneath it. Then edit the ServerName, ServerAdmin, and  DocumentRoot lines accordingly. ``` nano /etc/apache2/sites-available/000-default.conf ``` Alternatively you can just copy the following entries and edit accordingly: ``` ServerAdmin youremail@address.com DocumentRoot /var/www/site1 ServerName site1.com ServerAlias www.site1.com ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined ServerAdmin youremail@address.com DocumentRoot /var/www/site2 ServerName site2.com ServerAlias www.site2.com ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined ``` We must now make directories for the sites that were just configured, site1 and site2. ``` mkdir /var/www/site1 mkdir /var/www/site2 ``` Now you may begin creating/uploading your web content in the sites directory of Apache. ``` nano /var/www/site1/index.html ``` ``` nano /var/www/site2/index.html ``` ## What Next? With that, you now have a server installed and configured with Apache. You may now continue building your website. Thank you for following along and feel free to check back with us for further updates, take a look at other Ubuntu related posts in our blog or learn more about our award-winning [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. --- # How to Install NGINX on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-nginx-ubuntu-20-04/ | Published: 2015-08-06 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 03/10/21 ## Introduction This tutorial will show you how to install Nginx on Ubuntu 20.04 so that you can successfully run a superior performance based web server while easing the load on your system resources. Nginx is a powerful web server software that can be used on your server. ## Install Nginx To install Nginx, we will need to use the apt-get  command so we can install the software: ``` sudo apt-get install nginx -y ``` You will now have NGINX installed on your server and can be verified typing in the following with your IP ADDRESS on your browser (http://YOUR.IP.ADD.RESS ) Your IP can be retrieved from the server with following command: ``` ip addr show wlan0 | grep inet | awk '{ print $2 }' ``` ![An example of the default webpage Nginx gives you when installed on Ubuntu 20.04](https://www.atlantic.net/wp-content/uploads/2018/01/anet-install-nginx-ubuntu-14-04-01.png) An example of the default webpage Nginx gives you when installed on Ubuntu 20.04 ## Configure Nginx We will now configure Nginx by opening the central configuration file and editing the server_name line with your domain. ``` nano /etc/nginx/sites-available/default ``` ``` server { listen 80 default_server; listen [::]:80 default_server ipv6only=on; root /usr/share/nginx/html; index index.html index.htm; # Make site accessible from http://localhost/ server_name YOURDOMAIN.com; location / { # First attempt to serve request as file, then # as directory, then fall back to displaying a 404. try_files $uri $uri/ =404; # Uncomment to enable naxsi on this location # include /etc/nginx/naxsi.rules } # Only for nginx-naxsi used with nginx-naxsi-ui : process denied requests #location /RequestDenied { # proxy_pass http://127.0.0.1:8080; #} #error_page 404 /404.html; # redirect server error pages to the static page /50x.html # #error_page 500 502 503 504 /50x.html; #location = /50x.html { # root /usr/share/nginx/html; #} # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000 # #location ~ \.php$ { # fastcgi_split_path_info ^(.+\.php)(/.+)$; # # NOTE: You should have "cgi.fix_pathinfo = 0;" in php.ini # # # With php5-cgi alone: # fastcgi_pass 127.0.0.1:9000; # # With php5-fpm: # fastcgi_pass unix:/var/run/php5-fpm.sock; # fastcgi_index index.php; # include fastcgi_params; #} # deny access to .htaccess files, if Apache's document root # concurs with nginx's one # #location ~ /\.ht { # deny all; #} } ``` Save the file and restart the Nginx service so the changes take effect. ``` systemctl restart nginx ``` Now you can create/upload your web content to the HTML directory of Nginx (Remember to replace the existing index.html file with your index.html which is your home page) The default directory for Ubuntu 20.04 is /usr/share/nginx/html/. Update the index with the following command: ``` nano /usr/share/nginx/html/ ``` ## What Next? You now have your Ubuntu 20.04 server with Nginx installed, you may now begin building high-performance websites using your newly installed web server. Thank you for following along and feel free to check back with us for further updates. --- # How to Install HHVM (HipHop Virtual Machine) on Ubuntu 20.04 using Nginx > URL: https://www.atlantic.net/vps-hosting/how-to-install-hhvm-ubuntu-20-04/ | Published: 2015-08-07 | Updated: 2025-03-06 | Author: Alexander Wise This guide will show you how to install HHVM (HipHop Virtual Machine) on an Ubuntu 20.04 server using Apache or Nginx. HHVM is a process virtual machine designed to execute Hack and PHP programs. HHVM runs programs at run time rather than prior, which gives HHVM high-caliber performance over a typical PHP install. HHVM was open-sourced and developed by Facebook. In this post, we will show you how to install HHVM with Nginx on Ubuntu 20.04. ## Prerequisites - A server with Ubuntu 20.04 installed. HHVM requires the 64-bit version.  If you do not have a server, try a market-leading [Virtual Private Server](https://www.atlantic.net/vps-hosting/) in under 30 seconds from Atlantic.Net - Nginx installed on your server. You can follow our guides on installing [Nginx](https://www.atlantic.net/vps-hosting/how-to-install-nginx-ubuntu-20-04/) if needed. ## Step 1 – Install HHVM By default, HHVM is not included in the Ubuntu 20.04 default repository. So you will need to add the HHVM repository to the APT. First, install the required dependencies with the following command: ``` apt-get install software-properties-common apt-transport-https ``` Once all the dependencies are installed, add the GPG key using the following command: ``` apt-key adv --recv-keys --keyserver hkp://keyserver.ubuntu.com:80 0xB4112585D386EB94 ``` Next, add the HHVM repository to the APT with the following command: ``` add-apt-repository https://dl.hhvm.com/ubuntu ``` Once the repository is added, install the HHVM with the following command: ``` apt-get install hhvm -y ``` Once installed, verify the installed version of HHVM using the following command: ``` hhvm --version ``` You should get the following output: ``` HipHop VM 4.110.0 (rel) Compiler: 1621283449_427599063 Repo schema: d1ae8e21bf3419a65f12a010527485564e719d07 ``` At this point, HHVM is installed in your server. ## Step 2 – Configure HHVM By default, HHVM is configured to listen on the IPv6 address only. So you will need to configure it to listen on the localhost. You can do it by editing the server.ini file: ``` nano /etc/hhvm/server.ini ``` Add the **“hhvm.server.ip = 127.0.0.1”** line as shown below: ``` pid = /var/run/hhvm/pid ; hhvm specific hhvm.server.port = 9000 hhvm.server.type = fastcgi hhvm.server.default_document = index.php hhvm.log.use_log_file = true hhvm.log.file = /var/log/hhvm/error.log hhvm.repo.central.path = /var/cache/hhvm/hhvm.hhbc hhvm.server.source_root = /var/www/html/ hhvm.server.ip = 127.0.0.1 ``` Save and close the file then start the HHVM service with the following command: ``` systemctl start hhvm ``` Now, check the HHVM listening port with the following command: ``` ss -antpl | grep 9000 ``` You should get the following output: ``` LISTEN 0 128 127.0.0.1:9000 0.0.0.0:* users:(("hhvm",pid=6064,fd=23)) ``` ## Step 3 – Start HHVM Server Next, create a sample PHP file to the Nginx web root directory: ``` nano /var/www/html/info.php ``` Add the following lines: ``` #!/usr/bin/env hhvm > function main(): void { print("Hello, World!\n"); exit(0); } ``` Save and close the file then change the directory to the Nginx root directory and start the HHVM server on port 8080: ``` cd /var/www/html/ hhvm -m server -p 8080 -vServer.AllowRunAsRoot=1 ``` Now, open your web browser and access your info.php file using the URL **http://your-server-ip:8080/info.php**. You should see the following page: ![HHVM Page](https://www.atlantic.net/wp-content/uploads/2015/08/hhvm.png) Now, press **CTRL+C** to stop the server. ## Step 4 – Configure HHVM to Run with Nginx and FastCGI HHVM comes with a script to install FastCGI based on the web server you have installed. You can run this script using the following command: ``` /opt/hhvm/4.110.0/share/hhvm/install_fastcgi.sh ``` This script will create a new **hhvm.conf** configuration file inside the Nginx conf directory: ``` cat /etc/nginx/hhvm.conf ``` You should see the following output: ``` location ~ \.(hh|php|hack)$ { fastcgi_keep_conn on; fastcgi_pass 127.0.0.1:9000; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } ``` Now, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` Now, you can access your PHP file using the URL **http://your-server-ip/info.php**. ## Conclusion Congratulations on installing HHVM on Ubuntu 20.04. Try it out with some of your favorite CMS’s like WordPress or Drupal and you should see a performance increase especially under load. Thank you for following along this how to, please check back for more updates. --- # How to Install Java (JRE or JDK) on CentOS 7 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-java-jre-jdk-centos-7/ | Published: 2015-08-10 | Updated: 2026-01-09 | Author: Alexander Wise ## Introduction There are two standard types of installations, JRE (Java Runtime Environment) and JDK (Java Development Kit). As the base model, JRE enables the ability to create Java Applications for different types of deployments using minimal core tools to accomplish the task. JDK is a fully loaded Development Kit that has everything that JRE has, plus additional resources to create/secure Applications and Applets. This how-to will take you through the installation of JRE and JDK on CentOS 7. ## Installing Java on CentOS 7 Before we begin, let’s make sure that the server is fully updated with the following command: ``` sudo yum update ``` In this tutorial, we will be using the wget command, so let us install this now to facilitate the process later on. ``` sudo yum insatal wget ``` ## Installing Java JRE on CentOS 7 Select one of the following versions of Java JRE, version 8 being the latest: ``` sudo yum install java-1.8.0-openjdk sudo yum install java-1.7.0-openjdk sudo yum install java-1.6.0-openjdk ``` ## Installing Java JDK on CentOS 7 Select one of the following versions of Java JDK, version 8 being the latest: ``` sudo yum install java-1.8.0-openjdk-devel sudo yum install java-1.7.0-openjdk-devel sudo yum install java-1.6.0-openjdk-devel ``` ## Installing Oracle Java JRE on CentOS 7 Another alternative Java install is with Oracle. However, we would need to download the file from the Oracle site. To keep things in order an prepare for the download, let us change the directory to /opt. ``` cd /opt ``` With the following command, you can download the latest version of Java Oracle JRE 8.51 from the Java site. ``` sudo wget --no-cookies --no-check-certificate --header "Cookie: gpw_e24=http%3A%2F%2Fwww.oracle.com%2F; oraclelicense=accept-securebackup-cookie" \ "http://download.oracle.com/otn-pub/java/jdk/8u51-b16/jre-8u51-linux-x64.tar.gz" ``` With the file downloaded to the /opt directory, We must extract the files with the following command: ``` sudo tar xvf jre-8u51-linux-x64.tar.gz ``` Now, to clean things as we go. Since we just extracted the file, we can go ahead and remove the download file with the following command: ``` sudo rm /opt/jre-8u25-linux-x64.tar.gz ``` Furthermore, we will change the ownership permissions of the extracted files with the following: ``` sudo chown -R root: jre1.8.0_51 ``` Finally, we will then be using the “Alternatives” commands to create symbolic links from the /opt location to the /usr/bin/java. This can be accomplished with the following command: ``` sudo alternatives --install /usr/bin/java java /opt/jre1.8.0_51/bin/java 1 ``` Note: Older versions of Oracle Java JRE can be installed by the previous steps and with the correct version links from the Java Website. ## Installing Oracle Java JDK on CentOS 7 To download the Java Oracle JDK file from the website, let us keep things in order and prepare for the download. Once you are ready to get started, change your directory to /opt with the following command: ``` cd /opt ``` With the following command, you can download the latest version of Java Oracle JDK 8.51 from the Java site. ``` sudo wget --no-cookies --no-check-certificate --header "Cookie: gpw_e24=http%3A%2F%2Fwww.oracle.com%2F; oraclelicense=accept-securebackup-cookie" \ "http://download.oracle.com/otn-pub/java/jdk/8u51-b16/jdk-8u51-linux-x64.tar.gz" ``` With the file downloaded to the /opt directory, We must extract the files with the following command: ``` sudo tar xvf jdk-8u51-linux-x64.tar.gz ``` Now, to clean things as we go. Since we just extracted the file, we can go ahead and remove the download file with the following command: ``` sudo rm /opt/jdk-8u51-linux-x64.tar.gz ``` Furthermore, we will change the ownership permissions of the extracted files with the following: ``` sudo chown -R root: jdk1.8.0_51 ``` Finally, we will then be using the “Alternatives” commands to create symbolic links from the /opt location to the /usr/bin/java. This can be accomplished with the following command: ``` sudo alternatives --install /usr/bin/java java /opt/jdk1.8.0_51/bin/java 1 ``` Note: Older versions of Oracle Java JDK can be installed by the previous steps and with the correct version links from the Java Website. ## Select your default Java Version on CentOS  7 If you have multiple versions of Java installed on your server, then you have the ability to select a default version. Check your alternatives with the following command: ``` sudo update-alternatives --config java ``` ![This is the output after running the Java Alternative script on CentOS 7](https://www.atlantic.net/wp-content/uploads/2018/01/Centos1.jpg) This is the output after running the Java Alternative script on CentOS 7 Once you have viewed your alternatives, choose the version that you want by selecting the assigned number and then hit enter. ## Setup JAVA_HOME on CentOS 7 Since many programs nowadays need a JAVA_HOME environment variable to work properly. We will need to find the appropriate path to make these changes. With the following command, you can view your installs and their path: ``` sudo update-alternatives --config java ``` A directory path listing for each installation is below: ``` /usr/lib/jvm/java-1.8.0-openjdk-1.8.0.51-1.b16.el7_1.x86_64 /usr/lib/jvm/java-1.7.0-openjdk-1.7.0.85-2.6.1.2.el7_1.x86_64 /usr/lib/jvm/jre-1.6.0-openjdk.x86_64 ``` To edit the environment file use your text editor and edit the following file: ``` sudo nano /etc/profile ``` Now that you are in the user profile file, add the following code, along with the Path of your installation from the previous step, to the bottom. ( Example: JAVA_HOME=”YOUR_PATH”) ``` export JAVA_HOME="/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.51-1.b16.el7_1.x86_64" ``` Reload the file so all your changes could take effect with the following command: ``` source /etc/profile ``` Verify that your implementations are correct with the following command. Confirm : ``` echo $JAVA_HOME ``` ## What Next? Congratulations! You now have a successfully installed Java on your CentOS 7 server. Thank you for following along and feel free to check out our blog for further updates or take a look at the many services we offer such as [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/). --- # How to Configure Logging in IIS Windows Server 2012 > URL: https://www.atlantic.net/vps-hosting/how-to-configure-logging-iis-windows-server-2012/ | Published: 2015-08-11 | Updated: 2026-03-02 | Author: Alexander Wise ##### Verified and Tested 08/11/2015 ## Introduction In this How-To, we will walk you through to Configure Logging in IIS Windows Server 2012. This feature is set up to store data HTTP request and errors from your website(s) and of your Web Server. Configuring this feature will make your site troubleshooting much easier because you will have logs that serve as a starting point. ## Configure Logging in IIS Initially, you want to access the IIS Manager to configure “Logging” on Windows Server 2012 following the following path: Open the **Server Manager** / Select **Local Server/**Under “All Servers” select “**IIS”**/ Right Click on your server and select the “**Internet Information Services (IIS) Manager”**option.****   ![Select IIS Manager in your Server Manager Dashboard](https://www.atlantic.net/wp-content/uploads/2018/01/iis1.jpg)   Select IIS Manager in your Server Manager Dashboard You will now be taken to the **Internet Information Services (IIS) Manager”** where you will see a  **Connections** panel to the left side of your screen.  There is a folder named “Sites” with a drop down arrow, and you can view all your sites that are available. Select your site and select the “**Logging**” option from the sites Home options.   ![Select Logging in the IIS Manager page](https://www.atlantic.net/wp-content/uploads/2018/01/iis2.jpg) Select Logging in the IIS Manager page ## Logging Page You will be taken to the-the **Logging** page to configure some settings. Under **Log file/** **Format.**Select one of the following log formats: - **IIS**– uses the Microsoft IIS log file format. - **NCSA **– uses the National Center for Supercomputing Applications common log file format. - **W3C **– uses the centralized W3C log file format. - **Custom**– use a customer logging module/file format. ## Directory Section Specify the location where the log file will be stored in the **Directory**section.  It should be set to the default path shown below. *%SystemDrive%*\inetpub\logs\LogFiles **Note:** It is recommended that all the log files that will be stored on your system be stored in any directory except the *systemroot* directory. ## Log File Rollover Section Additionally, there is a “**Log File Rollover**” section. This is where you can select a schedule and how the new files are created selecting one of the following options: - **Hourly** - **Daily** - **Weekly** - **Monthly** - **Maximum file size (in bytes)** - **Do not create a new log file** Further more, its recommended that you select “**Use local time for file naming and rollover”**to achieve a more accurate log reading based on your current server’s time stamp. If you do not select the “**Use local time for file naming and rollover”** option, the system will use the Coordinated Universal Time (UTC) to archive the file. You will then have to convert the UTC format to your local format when its time to review the logs. You will then finalize your configuration by saving all your information by clicking “Apply” in the “Actions panel.   ![Applying your settings in the Actions Panel](https://www.atlantic.net/wp-content/uploads/2018/01/iis3.jpg) Applying your settings in the Actions PanelCongratulations! You have just Configured Logging in IIS Windows Server 2012. Thank you for reading! Be sure to check back for more updates, and to learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. --- # How to Install Zabbix Server on a CentOS 7 Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-zabbix-server-centos-server/ | Published: 2015-08-12 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 05/19/21 ## Introduction This how-to will show you how to install the Zabbix 5.0 Server on a CentOS 7 installation. Zabbix is an open-source monitoring tool that is ideal for monitoring your cloud servers. However, it can monitor many other types of devices. Installing Zabbix can help you find issues with your server before an outage occurs. ## Prerequisite - A CentOS 7 server running LAMP. Please see [this post](https://www.atlantic.net/vps-hosting/how-to-install-lamp-centos-7-2/) for details on installing LAMP on CentOS 7. - If you do not have a CentOS 7 server, try a [Virtual Private Server](https://www.atlantic.net/vps-hosting/) today! ![Zabbix Vision by Walker Cahall](https://www.atlantic.net/wp-content/uploads/2018/01/zabbix1.png) Zabbix Vision by [Walker Cahall](http://www.waltronic.net/) ## Install Zabbix on CentOS 7 To install the Zabbix server, you will need to find out if your CentOS installation is 32-bit or 64-bit. To do this run the command: ``` uname -i ``` ![Install Zabbix](https://www.atlantic.net/wp-content/uploads/2018/01/Zabbix2.png) uname -i If it says x86_64, you are using a 64-bit installation. ![uname -a](https://www.atlantic.net/wp-content/uploads/2018/01/zabbix3.png) uname -a If it says i368, you are using a 32-bit installation. We will then need to install the Zabbix repository from Zabbix. For CentOS 7**64-Bit,**run the following command: ``` yum install -y centos-release-scl rpm -Uvh https://repo.zabbix.com/zabbix/5.0/rhel/7/x86_64/zabbix-release-5.0-1.el7.noarch.rpm ``` After installing the Zabbix repository, you can now install the Zabbix server. Do that by running the command: ``` yum install -y zabbix-web-mysql-scl zabbix-apache-conf-scl zabbix-server-mysql zabbix-agent --enablerepo=zabbix-frontend ``` Now, we need to make some configuration changes before going through the web installation. Edit the Zabbix config file and set the timezone. ``` nano /etc/opt/rh/rh-php72/php-fpm.d/zabbix.conf ``` Change the following line ``` php_value[date.timezone] = America/New_York: ``` Next, edit **/etc/php.ini** with your favorite editor and change the following: Under Resource limits ``` max_execution_time = 600 ``` ![php.ini max_execution_time](https://www.atlantic.net/wp-content/uploads/2018/01/zabbix4.png) php.ini max_execution_time ``` max_input_time = 600 ``` ![php.ini max_input_time](https://www.atlantic.net/wp-content/uploads/2018/01/zabbix5.png) php.ini max_input_time ``` memory_limit= 256M ``` ![php.ini memory_limit](https://www.atlantic.net/wp-content/uploads/2018/01/zabbix6.png) php.ini memory_limit Under Data Handling ``` post_max_size = 32M ``` ![php.ini post_max_size](https://www.atlantic.net/wp-content/uploads/2018/01/zabbix7.png) php.ini post_max_size Under File Uploads ``` upload_max_filesize = 16M ``` ![php.ini upload_max_filesize](https://www.atlantic.net/wp-content/uploads/2018/01/zabbix8.png) php.ini upload_max_filesize Under Module Settings ``` date.timezone = 'UTC' ``` ![php.ini date.timezone](https://www.atlantic.net/wp-content/uploads/2018/01/zabbix9.png) php.ini date.timezone You can change this to a timezone of your choice. In this example, we are using UTC. [For a complete list of PHP timezones, go here](http://php.net/manual/en/timezones.php). Once done with the php.ini configurations, we can set up the database. ``` mysql -u root -p ``` When prompted, enter your MySQL root password that you set up when installing MySQL. In MySQL, enter the following commands: ``` create database zabbix character set utf8 collate utf8_bin; ``` Make sure you set your own secure password where it says [insert-password-here] ``` grant all privileges on zabbix.* to zabbix@localhost identified by '[insert-password-here]'; ``` ``` flush privileges; ``` ``` exit ``` After creating the database, we need to add the initial Zabbix schema and data. To do that, run the following commands (for the MySQL commands, you will be prompted for the Zabbix password you set when you created the database): ``` cd /usr/share/doc/zabbix-server-mysql*/ zcat create.sql.gz | mysql -u zabbix -p zabbix ``` Once schema and data have been added to the database, we need to edit the Zabbix configuration file. Use a text editor to edit **/etc/zabbix/zabbix_server.conf** and make sure the following are set: ``` DBHost=localhost DBName=zabbix DBUser=zabbix DBPassword=[insert-password-here] ``` Once the conf file is set, you can now start the Zabbix server and restart Apache. ``` systemctl start rh-php72-php-fpm ``` ``` systemctl restart zabbix-server zabbix-agent httpd ``` Now, we can go to the web installation. In your browser, go to http://yourhostname-or-ipaddress/zabbix If you are unsure what your IP address is, run the following: ``` ifconfig ``` ![Sample ifconfig](https://www.atlantic.net/wp-content/uploads/2018/01/zabbix10.png) In our example, we would put http://192.68.0.2/zabbix in the address bar and get the following page. Click Next ![Zabbix Setup Page](https://www.atlantic.net/wp-content/uploads/2015/08/zabbix-setup.png) Make sure everything says OK. If not, look at your php.ini file and make the appropriate changes. Click next if everything is OK. ![Prerequisite Check](https://www.atlantic.net/wp-content/uploads/2018/01/zabbix12.png)   Input your database information that you set up earlier and click test connection. If it says OK click next, if not check your database information again to see if it is accurate. ![Enter your database information accordingly.](https://www.atlantic.net/wp-content/uploads/2018/01/zabbix13.png) For most installations, you can keep the defaults. If you would like, you can set a name for the installation. Once done, click next. ![Enter your localhosts information](https://www.atlantic.net/wp-content/uploads/2018/01/zabbix14.png) Verify your installation and click next. ![Review your settings and select Next](https://www.atlantic.net/wp-content/uploads/2018/01/zabbix15.png) Click finished to go to the login page. ![Install](https://www.atlantic.net/wp-content/uploads/2018/01/zabbix16.png) You can then log into Zabbix with the default logins. Username: Admin Password: zabbix ![First Log in](https://www.atlantic.net/wp-content/uploads/2018/01/zabbix17.png)   Congratulations! You have now installed Zabbix on Centos 7. Thank you for following along this how to! Come back for updates, and try a [VPS Hosting](https://www.atlantic.net/vps-hosting/) solution from Atlantic.Net. --- # How to Install a LAMP (Apache, MariaDB, PHP) stack on CentOS 7 > URL: https://www.atlantic.net/vps-hosting/how-to-install-lamp-centos-7-2/ | Published: 2015-08-13 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 02/04/2021 ## Introduction In this How-To, we will walk you through the installation of a LAMP stack on a CentOS 7 based server. Although we are writing this article in the context of CentOS 7, a Linux, Apache, MariaDB, PHP(LAMP) server is a common installation stack capable of being hosted on many different Operating Systems. Examples of such are Debian (see our [how-to on this here](https://www.atlantic.net/vps-hosting/how-to-install-lamp-on-debian-8/)) and Debian based distributions like Ubuntu (see our [how-to for Ubuntu here](https://www.atlantic.net/vps-hosting/install-lamp-server-with-lets-encrypt-free-ssl-on-ubuntu-18-04/)), or RHEL and RHEL based distributions such as Fedora or Scientific Linux. You’ll see these installations occurring on a variety of hosting platforms such as shared web hosting, dedicated hosting and cloud hosting. In the case of this article, we’ll be utilizing the YUM package manager associated with the RHEL distribution CentOS. ## Prerequisites A server with CentOS 7  installed will take care of the Linux aspect of the LAMP stack install. If you do not have a server, consider a reliable SSD [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. ## Installing Apache on CentOS 7 Install Apache with the following command to begin the install: ``` sudo yum install httpd ``` Start Apache with the following command: ``` sudo systemctl start httpd ``` We can now verify Apache is working by opening your browser and entering the URL `http://your-server's-address`. you should get a blue Apache 2 test page similar to the image below. > Note: If you do not know your IP address, run the following command: > > ``` > ip addr show eth0 > ``` > > ![An example of running the command: ip addr show eth0 and getting 192.168.100.10 for the IP address.](https://www.atlantic.net/wp-content/uploads/2018/01/lamp2-1.png) > > An example of running the command: ip addr show eth0 and getting 192.168.100.10 for the IP address.In our example we would put `http://192.168.100.10` into our browser’s address bar. > >   ![Apache 2 Test page](https://www.atlantic.net/wp-content/uploads/2018/01/lamp3.jpg) Apache 2 Test page ## Installing MariaDB on CentOS 7 Install MariaDB with the following command to begin the install: ``` sudo yum install mariadb-server ``` Start the service with the following command ``` sudo systemctl start mariadb ``` Set root MySQL password with the following command: ``` /usr/bin/mysql_secure_installation ``` Note: You will be prompted with a series of questions. Simply type Y for yes on all of them, see the screenshot below: ![Sample mysql_secure_installation](https://www.atlantic.net/wp-content/uploads/2018/01/lamp4.jpg) Sample mysql_secure_installation ## Installing PHP on CentOS 7 First, you will need to install EPEL and Remi repository in your system. You can install it with the following command: ``` sudo yum install epel-release sudo yum install http://rpms.famillecollet.com/enterprise/remi-release-7.rpm ``` Next, Install PHP with the following command to begin the install: ``` sudo yum --enablerepo=remi-php74 install php php-mysql ``` Create a test PHP file in the following directory with the following command: ``` sudo vi /var/www/html/info.php ``` Insert the following code in the empty space then save and exit: ``` ``` Restart apache so all the changes take effect: ``` sudo systemctl restart httpd ``` Test your page in your browser with the following hyperlink changed with your IP address: http://YOUR.IP.ADD.RESS/info.php ![php apache](https://www.atlantic.net/wp-content/uploads/2015/08/php-apache-1024x560.png) It is a good idea to remove your php.info file as it can be used to aid an attacker to compromise your server. You can do that with the following command: ``` sudo rm /var/www/html/info.php ``` If you would like Apache and MariaDB to start on boot, run the following commands: ``` sudo systemctl enable httpd ``` ``` sudo systemctl enable mariadb ``` Congratulations! You have just installed a LAMP stack on your CentOS 7 Server. Thank you for following along in this How-To and check back with us for any new updates, or to learn more about our industry-leading [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. --- # Reduce Your Cloud Computing Costs – Cut the Middleman > URL: https://www.atlantic.net/hipaa-data-centers/cloud-computing-costs/ | Published: 2015-08-14 | Updated: 2025-03-06 | Author: Alexander Wise If you want to get your cloud computing costs down to the level you expected when you initially made the transition, one expert argues that the solution is simple: cut out the middleman. ## IT Executives Reveal the Challenges of Shifting to Cloud When 150 top IT executives in the United Kingdom were asked about the challenges and costs of transitioning to cloud, the results (released in early 2015) were both predictable and startling. [Seven in 10 respondents](http://www.cloudcomputing-news.net/news/2015/mar/30/research-argues-hidden-costs-contribute-cloud-hangover-businesses/) said that cloud had introduced problems for IT staff. That’s a no-brainer: working with any new technology will mean some amount of problem-solving, no matter how smooth the transition. The real eye-opener was that UK companies were not consistently able to cut their budgets, with almost 3 in 10 (28%) noting that their anticipated cloud ROI evaporated entirely. ## Transitioning Doesn’t Always Result in Savings Where did the money go? One cloud executive says there is a simple and substantial way in which money is being misspent. His argument: As companies transition from legacy applications to cloud environments, IT departments have become accustomed to using consultants and support services. It’s understandable that organizations were hesitant to take on this huge technological transition themselves, but the expensive “training wheels” of paid expertise are about to be removed. After all, one of the main advantages of cloudification is cutting the IT budget. However, cloud total cost of ownership (TCO) is often bloated with huge consulting fees. ## Why Are Firms Paying Too Much for Cloud? The reason that firms are paying too much is that they are still using the same basic process and expectations to adopt cloud systems as they used for traditional implementation. Not wanting to change everything at once, the legacy methods have remained, and they’ve continued to unnecessarily use the consult/support model. With software that is purchased for on-site deployment, [says cloud executive Alok Misra](http://www.informationweek.com/cloud/software-as-a-service/how-to-reduce-it-service-costs-in-the-cloud/d/d-id/1096152), the advice of consultants has been used by companies to choose the right programs. “The vendor then cashes the license check, and consultants charge for customizing and implementing the system,” he adds. Once it’s deployed, support, upgrades and maintenance carry costs for years to come.” With that scenario, the business has hired a consultant prior to purchase of the software. They then spend additional money on consulting, support, or internal IT for the lifecycle of applicable programs. Has this system been helpful to avoid errors as people are transitioning to the cloud? Certainly. But it isn’t cheap. In order to choose, deploy, and support software, firms typically spend an additional 40% to 100% what they are paying for the applications themselves. ## Consulting & Support Costs More and Delivers Less As industry commits more and more to the *third platform* (cloud / mobile / social / big data), that model is increasingly irrelevant – for a couple major reasons. First, the expense is lower to test out a cloud offering than for on-premises solutions. Consultants have brought in substantial revenue assisting organizations in picking out software. The expert’s fee is typically in the neighborhood of $15,000 or $20,000 for 2 to 4 weeks. It’s no longer appropriate to be that painstaking with a selection. “In the cloud, for $6,000 to $8,000 you can buy an annual subscription to most cloud products that a team can pilot test for a year,” Misra explains. “If it works, you can expand usage to the rest of the organization.” Second, you have a huge spectrum of vendors at your fingerprints with the cloud. Service providers can use a public cloud machine, such as an Atlantic.Net cloud servers, to meet the specific needs of any B2B target. That software is then available to those customers so that they don’t have to customize cloud solutions themselves – which cuts consulting expenses considerably. Adoption of cloud software is 20% lower than it is for on-location solutions, says Misra. “That’s because cloud apps are multitenant, which means the IT platform – and costs – are shared by customers,” he explains. “Also, the great variety of commercial cloud products ensures a better fit out-of-the-box, which means implementation costs go down.” ## SaaS Companies Often Offer Support Natively Companies that offer software-as-a-service typically support their solutions free of charge, offering their services via subscriptions. These vendors are essentially passing on the flexibility of infrastructure-as-a-service vendors that offer per-second billing and no-contract Private Cloud Hosting, (Atlantic.Net Private Cloud Hosting). Customer satisfaction is essential in this scenario. Why, then, do businesses still buy systems integration and similar consulting plans? Since the field of cloud is new, it is in rapid flux, so it can be difficult for companies to fully understand the landscape. Systems integrators are also good at presenting their solutions in the comfortable language of the old model. As the world of cloud continues to grow and demand increasing attention from leaders, many businesses will be cutting out the middleman and experiencing greater savings. IT departments will realize that consulting and support services often don’t justify the expense. ## About Atlantic.Net At Atlantic.Net, we are proud of the 24/7 technical support we offer for our 100% pure SSD cloud servers. But we also make adoption and use incredibly simple so that you don’t have to hire outside experts. Test out our SSD Cloud Hosting – paying as you go, by the second. Cloud Server Hosting services are only one of our offerings – we also offer dedicated hosting, managed hosting, and HIPAA-compliant hosting in our [HIPAA data centers](https://www.atlantic.net/hipaa-data-centers/). ![If you want to get your cloud computing costs down cut out the middleman](https://www.atlantic.net/wp-content/uploads/2014/01/13-0012.jpg)By Moazzam Adnan --- # How to Add a Website in cPanel and WHM on CentOS 6.7 > URL: https://www.atlantic.net/vps-hosting/how-to-add-a-website-in-cpanel-and-whm-on-centos-6-7/ | Published: 2015-08-17 | Updated: 2026-03-02 | Author: Alexander Wise ##### Verified and Tested 08/17/2015 ## Introduction This guide will show you how to add a website in cPanel & WHM server. Adding a website to cPanel is an easy task that is critical for using cPanel. ## Prerequisites An Atlantic.Net Cloud server with CentOS 6.7 and cPanel & WHM. If you do not have a server already, you can visit our [cloud Hosting information page](https://www.atlantic.net/vps-hosting/) and spin a new server up in under 30 seconds. ## Add a Website in cPanel & WHM on CentOS 6.7 The first step to adding a new website to your cPanel & WHM server is to first log into the WHM side of the server. To do this, you would want to go to https://your_cloud_IP:2087 and log in using your root credentials. Once logged in, on the search bar at the top left, type “create” and the side list should filter. You will see a section called “Create a New Account.” Click on this section to create the new website. ![](https://www.atlantic.net/wp-content/uploads/2015/08/anet-centos-6-cpanel-addwebsite-00.png) Search   The first section on the Create a New Account page is for your domain information. ![](https://www.atlantic.net/wp-content/uploads/2015/08/anet-cpanel-addwebsite-011.png) Domain information 1. Domain. This is your domain for the website you are adding. You would add this without any www or other subdomain unless you are adding a subdomain to its own account. 2. Username. This is the username to log into the cPanel side of the server and manage the website. This will also be your FTP username. 3. Password. This is the field for the password for the account. 3a is for re-typing your password and 3b is the strength of your password. If you had set any password strength requirements, they will come into play here and you will need to meet the minimum strength for the system to accept the password. 4. Email. This would be the email address for the account. This will be used if there is something wrong with the website on the server.   The next section is to select a Package for the website. If you did not configure any packages, you may set these manually by choosing “Select Options Manually.” This will open a new box called Manual Resource Options which allow you to customize the quotas for the website. You can even save the new options as a new Package if you would like. ![](https://www.atlantic.net/wp-content/uploads/2015/08/anet-cpanel-addwebsite-02.png) Package selection   The next section deals with Settings. If you want the website to be on its own IP, check the Dedicated IP box. The IP will have to be an additional IP that has already been added to the server. If you want the account to have Shell (SSH) access, you can check that as well. If the site will be using FrontPage, you will need to enable the extensions here. CGI access is important if you have scripts running on the site. The theme is negligible and Locale is the language for the cPanel to be in. ![](https://www.atlantic.net/wp-content/uploads/2015/08/anet-cpanel-addwebsite-03.png) Settings   The next section is the Reseller options. If you want the account to be a Reseller (capable of making its own accounts), you would want to check this. You can give the account the ability to manage itself as well if you do enable the option. ![](https://www.atlantic.net/wp-content/uploads/2015/08/anet-cpanel-addwebsite-04.png) Reseller Settings     The next section is DNS settings. You can enable DKIM and SPF if you would like, but the main thing to enable is “Use the nameservers specified at the Domain’s Registrar.” This will make sure the domain pulls the correct records from the correct location. ![](https://www.atlantic.net/wp-content/uploads/2015/08/anet-cpanel-addwebsite-05.png) DNS settings     The last section deals with email. If you will be using the server for email, you may select Local Mail Exchanger. Otherwise, if email is elsewhere, use the Remote Mail Exchanger option. Once done, click on “Create.” ![](https://www.atlantic.net/wp-content/uploads/2015/08/anet-cpanel-addwebsite-06.png) DNS settings     Once created, you may go to https://your_cloud_IP:2083 and use the new credentials you just created to log into the cPanel for the website and start building the site. You can also connect to the site using FTP. The hostname would be the domain, but if you do not have records propagated for the domain, you may use the IP address for the hostname. One last thing is that you can still check the cPanel/make some changes regarding passwords and IP addresses via WHM. When you are logged into WHM, go to the search bar and type “list” and you will be presented with “List Accounts.” If you click on this it will show you your account and you can make changes or click the CP logo to go to the cPanel as your WHM user. --- # How to Install LEMP (Nginx, MariaDB, PHP) on Centos 7 > URL: https://www.atlantic.net/vps-hosting/how-to-install-lemp-nginx-mysql-php-centos-7/ | Published: 2015-08-17 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 04/02/2021 ## Introduction In this How-To, we will walk you through the LEMP install on your CentOS 7 Server. LEMP is a software bundle that is made up of four parts (Linux, Nginx, MariaDB, and PHP). This how-to will be using CentOS 7 which was released on July 7th, 2014. ![NGINX Car by Walker Cahall](https://www.atlantic.net/wp-content/uploads/2015/08/lemp1.png) NGINX Car by [Walker Cahall](http://www.waltronic.net/) ## Installing EPEL and Remi in CentOS 7 for LEMP In this how to we are going to install the Fedora epel release to quickly install Nginx and Remi for PHP using the following command: ``` sudo yum install epel-release sudo yum install http://rpms.famillecollet.com/enterprise/remi-release-7.rpm ``` ## Installing and Configuring NGINX in CentOS 7 for LEMP Install NGINX with the following command: ``` sudo yum install nginx ``` Start the NGINX service with the following command: ``` sudo systemctl start nginx ``` Configure NGINX to start when the system is rebooted: ``` sudo systemctl enable nginx ``` You will now have NGINX installed on your server. This can be verified by typing in the following with your IP ADDRESS on your browser. Also, all configuration files are provided on the page. We can now verify Apache is working by opening your browser and entering the URL `http://your-server's-address`. you should get a blue Nginx test page similar to the image below. > Note: If you do not know your IP address, run the following command: > > ``` > sudo ip addr show eth0 > ``` > > ![An example of running the command: ip addr show eth0 and getting 192.168.100.10 for the IP address.](https://www.atlantic.net/wp-content/uploads/2015/08/lemp2.png) > > *An example of running the command: ip addr show eth0 and getting 192.168.100.10 for the IP address.In our example we would put `http://192.168.100.10` into our browser’s address bar.* [![Sample Nginx Default Webpage](https://www.atlantic.net/wp-content/uploads/2015/08/lemp3.jpg)](http://www.waltronic.net/) [*Sample Nginx Default Webpage*](http://www.waltronic.net/) ## Installing and Configuring MariaDB on CentOS 7 for LEMP Install MariaDB with the following command to begin the install: ``` sudo yum install mariadb-server ``` Start the service with the following command: ``` sudo systemctl start mariadb ``` Set root MySQL password with the following command: ``` sudo /usr/bin/mysql_secure_installation ``` Note: You will be prompted with a series of questions. Just type Y for yes on all of them, see the screenshot below: [![Sample my_secure_installation output.](https://www.atlantic.net/wp-content/uploads/2015/08/lemp4.jpg)](http://www.waltronic.net/) [*Sample my_secure_installation output.*](http://www.waltronic.net/) Configure MariaDB to start when the system is rebooted: ``` sudo systemctl enable mariadb ``` ## Installing and Configuring php-fpm on CentOS 7 for LEMP Install php-fpm with the following command: ``` sudo yum --enablerepo=remi-php74 install php-fpm php-mysql ``` Start the php-fpm service with the following command: ``` sudo systemctl start php-fpm ``` Make sure php-fpm starts on boot with the following command: ``` sudo systemctl enable php-fpm ``` Using your favourite editor, edit the file `/etc/php-fpm.d/www.conf`  and change user and group from apache to nginx. It should look similar to the block below. ``` ; Unix user/group of processes ; Note: The user is mandatory. If the group is not set, the default user's group ; will be used. ; RPM: apache Choosed to be able to access some dir as httpd user = nginx ; RPM: Keep a group allowed to write in log dir. group = nginx ``` Now we need to make some changes to the Nginx configuration file so that php-fpm works correctly with Nginx. Using your favorite editor, edit the file `/etc/nginx/conf.d/default.conf` and carry out the following changes or copy the following block below into your conf file. 1) Add the index.php to the index location 2) Change the root location to /usr/share/nginx/html 3) Uncomment the Pass PHP scripts to FastCGI section. 4) Change the fastcgi_param  SCRIPT_FILENAME  to use /usr/share/nginx/html$fastcgi_script_name ``` # # The default server # server { listen 80 default_server; server_name _; #charset koi8-r; #access_log logs/host.access.log main; # Load configuration files for the default server block. include /etc/nginx/default.d/*.conf; location / { root /usr/share/nginx/html; index index.php index.html index.htm; } error_page 404 /404.html; location = /404.html { root /usr/share/nginx/html; } # redirect server error pages to the static page /50x.html # error_page 500 502 503 504 /50x.html; location = /50x.html { root /usr/share/nginx/html; } # proxy the PHP scripts to Apache listening on 127.0.0.1:80 # #location ~ \.php$ { # proxy_pass http://127.0.0.1; #} # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000 # location ~ \.php$ { root /usr/share/nginx/html; fastcgi_pass 127.0.0.1:9000; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME /usr/share/nginx/html$fastcgi_script_name; include fastcgi_params; } # deny access to .htaccess files, if Apache's document root # concurs with nginx's one # #location ~ /\.ht { # deny all; #} } ```   Create a test PHP file in the following directory with the following command: ``` sudo vi /usr/share/nginx/html/info.php ``` Insert the following code in the space then save and exit: ``` ``` Restart apache so all the changes take effect: ``` sudo systemctl restart nginx ``` Test your page in your browser with the following hyperlink changed with yourIP address: http://YOUR.IP.ADD.RESS/info.php ![PHP Info](https://www.atlantic.net/wp-content/uploads/2015/08/php-centos7-1024x564.png) You should remove the info.php file as it could be used against you by an attacker. Delete it with the following command: ``` sudo rm /usr/share/nginx/html/info.php ``` Congratulations! You have just installed LEMP on your CentOS 7 Server. Thank you for following along in this How-To! Check back with us for any new updates and browse our scalable [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions for any sized business. --- # How to: VRRP (Virtual Router Redundancy Protocol) Keepalived Configuration > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-vrrp-keepalived-configuration/ | Published: 2015-08-18 | Updated: 2026-01-09 | Author: Alexander Wise ## Introduction VRRP (Virtual Router Redundancy Protocol) is a commonly used protocol that offers high availability for a network (or subnetwork). Keepalived is a Linux package that uses VRRP to deliver high availability among Linux servers. It also delivers [load-balancing services](https://www.atlantic.net/hipaa-data-centers/server-load-balancing/), but this article concentrates on getting started with just the VRRP portion. ### Prerequisites – Linux installation on at least 2 hosts (be sure they are already updated). – At least 3 available IP addresses (1 for each of at least 2 peer keepalived servers, and 1 virtual IP shared amongst them). ## Install Keepalived Keepalived should be available through most Linux repositories, so use the appropriate package manager to your distribution to install it on each device that will be running the service. On CentOS/RedHat/Fedora: ``` sudo yum install keepalived ``` On Debian/Ubuntu: ``` sudo apt-get install keepalived ``` ### Example Topology Here’s a diagram of the topology we’ll be using in this example. ![VRRP Topology with IP assignments](https://www.atlantic.net/wp-content/uploads/2018/01/keepalived1.png) ## Configuring VRRP First, it’s prudent to back up the default configuration file, in case you’d like to use it later as a template or for reference. ``` sudo mv /etc/keepalived/keepalived.conf /etc/keepalived/keepalived.conf.original ``` Then, using the text editor you prefer, create a new configuration file: ``` sudo nano /etc/keepalived/keepalived.conf ``` You can paste in the following configuration block, though you’ll want to make the appropriate changes for your environment (including IPs and interfaces). > NOTE: If using private IP’s on the Atlantic.Net Public Cloud, replace eth0 with eth1 in all instaces.  eth0 is used as a public interface and not private. ``` ######################## ## VRRP configuration ## ######################## # Identify the VRRP instance as, in this case, "failover_link". vrrp_instance failover_link { # Initial state of the keepalived VRRP instance on this host # (MASTER or BACKUP). Once started, only priority matters. state MASTER # interface this VRRP instance is bound to. interface eth0 # Arbitrary value between 1 and 255 to distinguish this VRRP # instance from others running on the same device. It must match # with other peering devices. virtual_router_id 15 # Highest priority value takes the MASTER role and the # virtual IP (default value is 100). priority 110 # Time, in seconds, between VRRP advertisements. The default is 1, # but in some cases you can achieve more reliable results by # increasing this value. advert_int 4 # Authentication method: AH indicates ipsec Authentication Header. # It offers more security than PASS, which transmits the # authentication password in plaintext. Some implementations # have complained of problems with AH, so it may be necessary # to use PASS to get keepalived's VRRP working. # # The auth_pass will only use the first 8 characters entered. authentication { auth_type AH auth_pass 1nrRYh*j } # VRRP advertisements ordinarily go out over multicast. This # configuration paramter causes keepalived to send them # as unicasts. This specification can be useful in environments # where multicast isn't supported or in instances where you want # to limit which devices see your VRRP announcements. The IP # address(es) can be IPv4 or IPv6, and indicate the real IP of # other members. unicast_peer { 10.5.132.122 } # Virtual IP address(es) that will be shared among VRRP # members. "Dev" indicates the interface the virtual IP will # be assigned to. And "label" allows for clearer description of the # virtual IP. virtual_ipaddress { 10.5.132.120 dev eth0 label eth0:vip } } ``` You can paste the same configuration block into your other VRRP peers, just be sure to adjust the priority and unicast_peer (if using this option) as appropriate. Once you have completed editing this file, save and exit. Start the service on each device: ``` sudo service keepalived start ``` ### What’s next? Congratulations on installing and configuring VRRP and Keepalived! We have included some basic VRRP troubleshooting issues below, in case you run into some common issues. We hope that you enjoyed following along this tutorial. Please check out some of our other guides below or search using the search bar above. ## Basic VRRP Troubleshooting To verify that the VRRP virtual IP is operating on the correct host, check the interfaces on participating hosts (assuming eth0 is the interface bound by VRRP): ``` ip addr show eth0 ``` You should see your virtual IP (here’s where the “eth0:vip” label comes in handy) only under the host whose /etc/keepalived/keepalived.conf priority is the highest. ![VRRP VIP on master eth0](https://www.atlantic.net/wp-content/uploads/2018/01/keepalived2.png) ![VRRP backup does not have the VIP](https://www.atlantic.net/wp-content/uploads/2018/01/keepalived3.png) ## Split-Brain VRRP If multiple hosts take the virtual IP, then they are likely either not receiving VRRP advertisements from the host with the highest configured priority or have a misconfiguration in their /etc/keepalived/keepalived.conf files. First, check to ensure your /etc/keepalived/keepalived.conf files are correct and consistent. In particular, verify that your virtual_router*_*id, advert_int, and authentication configuration parameters match (the vrrp_instance name doesn’t have to be the same across hosts, but it does make things easier to verify if it is consistent). If you make any changes, to /etc/keepalived/keepalived.conf, you’ll need to restart the keepalived service. ``` sudo service keepalived restart ``` If your configuration files look good, then verify that your hosts participating in VRRP are able to talk to each other on via the interface bound to VRRP. From the host that should be backup but thinks it’s master, see if it’s receiving traffic from the primary host: ``` sudo tcpdump -i eth0 -nn 'host 10.5.132.121' ``` You might be getting a lot of extra traffic on this interface, so to help narrow it down to traffic related to VRRP, filter by the AH protocol header. ``` sudo tcpdump -i eth0 -nn 'host 10.5.132.121 and ah' ``` If you opted for PASS instead of AH as your authentication type, then try to filter by VRRP packets. ``` sudo tcpdump -i eth0 -nn 'host 10.5.132.121 and vrrp' ``` ## Virtual IP not responding In some Linux implementations, your virtual IP address may not respond if you don’t tell it that it can bind nonlocal IPs to real interfaces. To allow this behavior, add the following line to /etc/sysctl.conf: ``` sudo nano /etc/sysctl.conf ``` ``` net.ipv4.ip_nonlocal_bind = 1 ``` And then, to load this new parameter into the running kernel with the following shell command: ``` sysctl -p ```   Thank you for following along this how-to, we hoped you have enjoyed it. Please check back here for more updates or check out the many services offered by Atlantic.Net, including [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/), Private Cloud Hosting and PCI Hosting. --- # How to: An Introduction To Using Git > URL: https://www.atlantic.net/vps-hosting/how-to-introduction-using-git/ | Published: 2015-08-19 | Updated: 2025-03-06 | Author: Alexander Wise ### Introduction Git is a version-control system. It allows many files to be maintained, changed, backed up, and shared while automatically keeping records of all previous versions. These file types include, but are not limited to: code files, documents, contracts, HTML and CSS files, and more. Anything that is text-based is usable with Git. ### Why Use Git? Have you ever updated a program, a website, or a document only to wish that you had the previous version on hand? Maybe your changes broke the program or website, maybe you cut-and-pasted over some vial information. Either way, a timeline of changes would save you time and effort, which is exactly what the Git protocol was built for. Additionally, Git can be set up to create automatic backups of any file when saving (“committing”) a file or change to the system. It’s a rapid and lightweight system, as well: the Git protocol only saves the changes you’ve made to each file, not each file individually. Finally, Git is the industry standard when working with code. It allows multiple users to access and edit the same files without conflict, to bring a local copy (“clone”) of a project to a user’s computer, create a new copy for testing purposes that doesn’t affect the original (“branch”), or to create an entirely new version (“fork”) of your–or someone else’s–program for editing with a single click or command. You can even bring the changes in a branch back into the original (“merge”). ## Installing a Git Client Okay, to get started with Git, you’ll need to install some software. There are many clients out there, but we’re going to focus on one for each major operating system. ### Windows Installation Go to [msysgit.github.io](http://msysgit.github.io/), and click “Download” to install the program. ![Windows Git client download page](https://www.atlantic.net/wp-content/uploads/2015/08/git1.png) *Windows Git client download page* ### Mac OSX Installation [SourceForge](http://sourceforge.net/projects/git-osx-installer/files/) hosts the Max OSX installer. Click the version that matches your version of OSX to download, and then install the program. ![Mac OSX Git client download page](https://www.atlantic.net/wp-content/uploads/2015/08/git2.png) *Mac OSX Git client download page* ### Linux Installation For Debian/Ubuntu: ``` sudo apt-get install git ``` For CentOS/RedHat/Fedora: ``` sudo yum install git ``` > For other Linux or Unix distributions, check the [package installation options here](http://git-scm.com/download/linux). ## Understanding Git Before we get into the commands, we should review some of the major features and terminology used with Git. **Repository**: The main database where all of your files are stored for a given project. **Index** (Staging Area): The temporary holding space for the file changes you will be committing to the Repository. **HEAD**: Points to a current branch where your changes will be committed. > Note: HEAD is a command and a pointer within the git system. It is used to demarcate the ‘head’, a marker which indicates to the system the current branch you’d like to edit. **Blob**: the name for a file in Git. **Tag**: A note identifying the version number of a document or piece of code. **Message**: A description of changes made with a commit (file updates or tags) **History**: A record of all commits made to the branch or repository. ## Using Git Open the Git bash program you installed above: ![Git bash in Windows](https://www.atlantic.net/wp-content/uploads/2015/08/git3.png) *Git bash in Windows* If you would like to use something other than the default folder to store your repository, create the new folder, and then navigate your Git client to the correct folder. > Example of navigating to a folder: > > (Windows) > > ``` > cd C:/Users/username/foldername/ > ``` > > (Linux/Mac) > > ``` > cd /Users/username/foldername > ``` > > Where `username` is your user name on the computer, and `foldername` is the name of the folder you created.   ## Creating a Git Repository One way to get started is to create a new repository. To create a new repository, enter the command: ``` git init ``` ## Cloning a Git Repository Another way to get started is to clone another, existing repository. To clone an existing repository from GitHub (a popular site for storing and sharing projects using Git, discussed further below), enter the command: ``` git clone git://github.com/repositoryname ``` To clone a different online repository (to which you have access), enter the command: ``` git clone username@host:/path/to/repository.git ```   ## Committing Git Repositories Once you’ve made changes and would like to add those changes to your repository, there is a short process you will follow: 1. Place files to commit in the Index (Staging Area) 2. Commit to the local repository 3. Push the changes to the remote repository (if working with a remote repository).   #### Index You need to place the files you’ll be committing each round in the Index (or Staging Area) prior to updating. Your Git client will only update those files that have been placed there. To place a file in the Index, enter the command: ``` git add filename ``` > Note: You can use a period (.) in place of filename to add all of the current files in the directory. > > ``` > git add . > ```   #### Commit To commit the added files to your local repository enter the command: ``` git commit -m "message" ``` Where `message` is a description of your commit changes. Make sure to include quotation marks. **Tip:** > While we’re here, let’s touch on commits and messages. We saw an example above, adding all files to a commit. However, the best practice when using Git is to commit only a set of related changes each time. Commits should be small, discrete chunks that can be explained with a short message. This is what makes version control (the reason for Git’s existence) useful. Small changes can be undone if they cause problems or are later found to be unnecessary or in conflict with other changes. Committing large blocks of unrelated changes makes it difficult to identify what is causing a problem or bug, should one occur. A good rule of thumb: if it takes more than a sentence or two to describe your commit, you need to commit smaller pieces.   #### Push Now that your changes have been committed, you can push them to a remote repository (if you are using a remote repository): ``` git push origin master ``` Pushing to a remote repository allows other users to access and modify the changes you’ve made. ## Creating, Using, and Merging Git Branches We’ve discussed branches briefly, but let’s review them. A branch is a separate line of thought for your content or program. For instance, if you’d like to consider a new color palette for a website, you could create one or more branches of the website and test your various color palette concepts without affecting the Master. If you settled on a new orange theme, you could then merge the “orange” branch back into the Master and replace the old palette. Let’s see how this works. To create a new branch that will house your orange color palette, enter: ``` git checkout -b orange ``` `checkout` is a Git command that switches between branches. The `-b` option creates a new branch with the name following it–in this case, “orange”. > Note: Make sure you’ve saved any work you’ve done in your editor before creating a new branch to avoid losing it. If you’d like to switch back to working on the Master branch, enter: ``` git checkout master ``` > Note: Git requires that you commit all changes before allowing you to switch branches. In this example, we’ll be working with that new color palette, so we’ll stay with the new branch. You’ll commit the branch with the same command as the Master branch. ``` git commit -a -m "branch demonstrating an orange palette" ``` The `-a` flag automatically adds all tracked files-–that is, all files that were included in the last commit that have been modified. If you’d like to push your orange branch to the remote repository, use: ``` git push origin orange ``` If you’re satisfied with your testing and would like to include the changes in your primary version (your Master branch), you’ll want to merge. First, checkout to your Master branch. ``` git checkout master ``` Then, use the merge command to update the Master with your “orange” branch information. ``` git merge orange ``` After the merge, the branch still exists but is no longer needed. Delete the “orange” branch using the `-d` option: ``` git branch -d orange ```   ### Conflicts When Merging If you have two or more branches that have edits to the same file, you may have a conflict when merging them successively. An example of a conflict between a “test layout” branch of your website and your “orange” branch you recently merged into the Master might look like this: ``` $ git merge orange <<<<<<< HEAD:index.html ======= >>>>>>> test-layout:index.html ``` You will be responsible for changing the two files to match in the conflict areas, then running the command to finalize the merge: ``` git add index.html ``` You can always compare branches prior to a merge by utilizing the `diff` command. ``` git diff ```   ## Pulling & Fetching with Git We have gone over how to push changes to a remote repository, but what if you’re working with others and you need to access the changes they’ve made? That’s where the `pull` command comes in. Pulling retrieves any changes made to the remote repository since you last cloned or pulled it and copies the changes to your local repository. ``` git pull ``` If you want remote updates without automatically changing your local copy to reflect the changes, use `fetch`: ``` git fetch ``` You then have a chance to review changes and merge the updates into your Master. ## Forking & GitHub When using and learning Git, you will come across the term “fork” or “forking”. Forking is merely cloning someone else’s repository into your own space, where you can modify it and create your own version without disrupting theirs, thus creating an independent version or “fork”. You will also come across the name [GitHub](https://github.com). With GitHub, forking is made easy and can be done with the click of a button: ![Fork button on GitHub](https://www.atlantic.net/wp-content/uploads/2015/08/git4.png) *Fork button on GitHub* Primarily billed as a collaborative tool, GitHub is a service with which you can back up and share your repositories, or contribute and fork other people’s projects. There are other services similar to GitHub, but GitHub remains one of the most popular options. To download the client or learn more, go to [Github](https://github.com). ### Further Resources There are many sources from which to learn advanced options in Git. One of the most thorough sources is the Pro Git book, [available online](http://git-scm.com/book/en/v2). And there’s always [the official Git documentation](http://git-scm.com/documentation). GitHub also offers [a playlist of video lessons](https://www.youtube.com/user/github/playlists), as well. ## Atlantic.Net Atlantic.Net offers [VPS hosting](https://www.atlantic.net/vps-hosting/) as well as managed hosting services which include a layer of business-essential managed services to your hosting packages. Contact us today for more information. --- # How to Install Python 2.7 on CentOS 7.1 or 6.7 with Anaconda > URL: https://www.atlantic.net/vps-hosting/how-to-install-python-2-7-centos-anaconda/ | Published: 2015-08-20 | Updated: 2026-03-03 | Author: Alexander Wise ## Introduction CentOS is a popular Linux distribution because it’s free to use without the need for a license and because the feature-freeze practices applied during the release cycle guarantee long-term stability. The price for stability is that the operating system ships with certain libraries that are quite out of date. Such is the case for Python, which is found in CentOS distributions at versions 2.6 or even lower. If developers need a higher version of Python, they need to compile and install it themselves. However, it’s important to leave the already installed Python intact, too. The operating system requires it for internal use, such as for the yum package manager. The most common thing that can go wrong is that a developer, in trying to install the new Python version, manages to corrupt the system (just Google for “installing Python 2.7 on CentOS broke my yum”). For that reason, it makes sense to use an existing tool that manages Python installations without tampering with the system Python installed at `/usr/bin/python`, and installs the new version side-by-side with the old one. A relatively new but already widely-used tool for managing Python installations is Anaconda by [Continuum.io](http://www.continuum.io), which makes building Python quite easy. ![Python Illustration by Walker Cahall](https://www.atlantic.net/wp-content/uploads/2018/01/PYTHON_final-01.png) Python Illustration by [Walker Cahall](http://www.waltronic.net/about/) ## Prerequisites – wget and bzip2 installed. You can install them with `yum install wget bzip2` ## Installing Python on CentOS 7.1 or 6.7 First we need to choose a directory where the new Python binaries will be installed. In this tutorial, we’ll be using `/usr/local/miniconda`. We can install Python 2.7 using the Miniconda bash installer and installing to the above directory. Download the install script with the following command: ``` wget https://repo.continuum.io/miniconda/Miniconda-latest-Linux-x86_64.sh ``` Run the install script with the following command: (you may or may not need sudo depending on the file access settings of the target directory) ``` sh Miniconda-latest-Linux-x86_64.sh -b -p /usr/local/miniconda ``` These commands will install the latest version of Miniconda for 64-bit versions of Linux. For other specific versions, check with the [Miniconda repository](https://repo.continuum.io/miniconda/). ## Add Python 2.7 to the PATH If it is desirable for us to launch the newly installed Python version when typing `python` in the shell, then we need to add an export line to the `~/.bashrc` file of all the users that have a need for this behavior (for instance, the user our web server runs as). ``` export PATH=/usr/local/miniconda/bin:$PATH ``` After editing the `.bashrc` file, run the following to make the changes take effect immediately. ``` source ~/.bashrc ``` Users that don’t have this in their profiles will call system Python instead. Yum will always call system Python because the path `/usr/bin/python` is hardcoded in its source code. So, unless we a try to create a symlink to this path or replace the binary, the package manager will keep working fine. ## Create Aliases If we don’t want to override the `python` command, we can also create aliases in `.bashrc` for ‘python2.7’ and ‘python2.6’ (if your `.bashrc` points to `.bash_aliases`, you can add the aliases there instead). This method will require us to explicitly say which version we want to use every time. ``` alias python2.7="/usr/local/miniconda/bin/python" alias python2.6="/usr/bin/python" ``` ## Install Pip If our server houses a django application, chances are we also need to install pip for managing our packages. The goal is to have pip install the new packages for Python2.7 installed in `/usr/local/miniconda` and not for the system Python. It is possible to do this with one line (assuming we added python 2.7 in the path in the previous section). ``` conda install pip ``` To verify that it worked:   ``` which pip [output] /usr/local/miniconda/bin/pip ``` ## What’s Next? Congratulations on installing Python 2.7 on CentOS, and we thank you for following along this how-to! Please check back here for more updates, and to learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. --- # How to Install DenyHost on CentOS 6.7 > URL: https://www.atlantic.net/vps-hosting/how-to-install-denyhost-centos-6-7/ | Published: 2015-08-21 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 08/11/15 ## Introduction In this How-To, we will walk you through the install and configuration of DenyHost on a CentOS 6.7 Server. DenyHosts is used by many System Administrators to protect their servers/networks from Brute force attacks and hackers. It is simple and effective in getting the job done with little experience. Due to the simplicity of DenyHost and the ability to manually configure your rules it is widely used as an alternative to Fail2ban which is a bit more complicated to use and configure. We will now work on getting it installed on your server. ## Prerequisites You need a CentOS 6.7 server that is configured with a static IP address. If you do not have a server already, fire up a cheap and reliable [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. ## Server Preparation First, we need to make sure that your server is fully up-to-date by running the following command: ``` yum update ``` With the server up-to-date, we can continue and install DenyHost on CentOS 6.7. ## Install DenyHost on CentOS 6.7 Download the EPEL repository with the following command: ``` sudo rpm -Uvh http://mirror.metrocast.net/fedora/epel/6/i386/epel-release-6-8.noarch.rpm ``` Install the Deny Hosts package with the following: ``` sudo yum install denyhosts ``` We must make sure to allow your IP address to prevent yourself from being denied access. We do this editing the following: ``` nano /etc/hosts.allow ``` Add the following line all the way to the bottom of the description with your IP. In most cases,[you can use this link to find your IP address.](https://support.google.com/websearch/answer/1696588) ``` sshd: YOUR.IP.ADD.RESS ``` Next we need to block everything by editing the following file: ``` nano /etc/hosts.deny ``` Add the following line all the way to the bottom of the description: ```  sshd: ALL   ** ``` Save your work and restart DenyHosts with the following command: ``` /etc/init.d/denyhosts restart ``` You can further configure any settings in the DenyHosts.conf file by going to the following and updating according to your preference. ``` nano /etc/denyhosts.conf ``` Congratulations! You have just installed DenyHosts on your CentOS 6.7 Server. Thank you for following along in this How-To! Check back with us for any new updates, and browse our full lineup of our [VPS hosting](https://www.atlantic.net/vps-hosting/). --- # How to Install Java (JRE or JDK) on FreeBSD > URL: https://www.atlantic.net/vps-hosting/how-to-install-java-jre-jdk-freebsd/ | Published: 2015-08-21 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 08/18/15 ## Introduction If you had the option to choose between a base model car or a fully loaded model, which one will you choose? Both cars will take you from point A to point B, but with the fully loaded car you have additional features that can make rush hour a chill hour. Well, that’s the same concept when we take a closer look at Java. There are two standard types of installations, JRE (Java Runtime Environment) and JDK (Java Development Kit). As the base model car, JRE enables the ability to create Java Applications for different types of deployments using minimal core tools to accomplish the task. JDK is a fully loaded Development Kit that has everything that JRE has plus additional resources to create/secure Applications and Applets. This how-to will take you through the installation of JRE and JDK on your FreeBSD server. ## Prerequisites You need a FreeBSD server that is configured with a static IP address. If you do not have a server already, you can [set up a FreeBSD server](https://www.atlantic.net/vps-hosting/how-to-get-started-freebsd-cloud-server/) with one of Atlantic.Net’s award winning [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions in under 30 seconds. Before we begin, Let’s make sure that your server is fully up-to-date so we can complete the preparation. ``` freebsd-update fetch freebsd-update install ``` After your server has been fully updated you will need to know what version of Java is currently installed (or if it is installed at all), with the following command: ``` java -version ``` Once you have verified if Java is installed or not, run the following command to search the version and type of Java that you would like to install. ``` pkg search ^openjdk ``` You now have the option to choose any of the available packages. In this case the latest package is version 8. ``` openjdk-7.80.15_1,1 openjdk-jre-7.80.15_1,1 openjdk6-b36,1 openjdk6-jre-b36,1 openjdk8-8.51.16 openjdk8-jre-8.51.16 ``` ## Install Java Open JRE on FreeBSD Select your package version, and install it with one of the following commands: ``` pkg install openjdk6-jre pkg install openjdk-jre pkg install openjdk8-jre ``` ## Install Java Open JDK on FreeBSD Select your package version, and install it with one of the following commands: ``` pkg install openjdk6 pkg install openjdk pkg install openjdk8 ``` Once you have installed your package, you will see the following message on your screen. ``` This OpenJDK implementation requires fdescfs(5) mounted on /dev/fd and procfs(5) mounted on /proc. If you have not done it yet, please do the following: mount -t fdescfs fdesc /dev/fd mount -t procfs proc /proc To make it permanent, you need the following lines in /etc/fstab: fdesc /dev/fd fdescfs rw 0 0 proc /proc procfs rw 0 0 ``` To finalize the installation, type the following commands just like the message states. ``` mount -t fdescfs fdesc /dev/fd mount -t procfs proc /proc ``` Then to make the changes permanent use your text editor to edit the `fstab` file: ``` nano /etc/fstab ``` Add the following lines to the `fstab` file: ``` fdesc /dev/fd fdescfs rw 0 0 proc /proc procfs rw 0 0 ``` So all changes take effect, we must then refresh the system with the following command: ``` rehash ``` ## What Next? Congratulations! You now have a successfully installed Java on your FreeBSD server. Thank you for following along and feel free to check back with us for further updates or learn more about our reliable [virtual private servers](https://www.atlantic.net/vps-hosting/pricing/). --- # How to: FreeBSD User Administration > URL: https://www.atlantic.net/vps-hosting/how-to-freebsd-user-administration/ | Published: 2015-08-24 | Updated: 2026-03-02 | Author: Alexander Wise ##### Verified and Tested 08/18/15 ## Introduction Imagine that you give a copy of your house keys to all of your family members and all of your friends. You get home one day, and it’s been vandalized. Who will you go to for information? It would be chaotic! So you only give your house keys to special people who you trust. In the same way in a network user administration works the same way. It adds a level of security and the peace of mind that if something happens you know who has access to your systems. There are main two types of users commonly used worldwide. You have plain users that have limited access to what they can access and you have super users or admin users that have extra permissions to perform system updates, installs and many other management tasks that normal users can’t. In this how-to we will go through the basics of User Management in FreeBSD and make sure that only users we want to have keys have them. ## Prerequisites You need a FreeBSD server that is configured with a static IP address. If you do not have a server, try our [SSD VPS Hosting](https://www.atlantic.net/vps-hosting/) get going in under 30 seconds. ## Adding users in FreeBSD For server management, it is recommended that you at least have one user for the server besides the default root account. If you want, add a user or multiple users in FreeBSD you can accomplish this with the following command replacing **NAME**with the user that you want. (Note: You will be prompted to fill out information about that user, fill out whatever is applicable) ``` adduser NAME ``` ## Root Privileges to Users in FreeBSD You now have the option to select the type of account you want for your user. You can leave it as a regular user account, or you can add that user root permissions adding that user to the “super user” account with the following: ``` sudo pw groupmod wheel -m USER1 ``` ## Removing users in FreeBSD Once you have no use for a specific user, whether it was a previous employee, a colleague or any other type of user. You can simply remove them in FreeBSD with the following command replacing **NAME**with that user. ``` rmuser NAME ``` ## Changing user passwords in FreeBSD There are two ways to change a users password in FreeBSD. You can change it as the root user or the actual user. If you are the root user or have root privileges, you can change a specified users password with the following command replacing **NAME**with that user. ``` passwd NAME ``` If you are the actual user and want to change your current password, you can simply your password with the following command: ``` passwd ``` ## Locking users in FreeBSD In a networked environment when you have active users or customers, you have the ability to lock and unlock their accounts. To lock a user in FreeBSD, you can type the following command: ``` pw lock USER1 ``` If you want to reactivate a user in FreeBSD, this can be completed with the following command: ``` pw unlock USER1 ``` ## Active Users list in FreeBSD Since you could have more than one user logged in simultaneously, you have the ability to view a list of all the users that are currently logged in to the system with the following command: ``` who ``` ## Resetting the root password in FreeBSD In the event of an emergency and you forget or misplaced your systems root password. There is a way that you could manually change/update it by completing the following steps. 1. Log into the server selecting “single user mode.” 2. From the options available, select **shell,**and press **enter.** 3. Once in shell run the following command: ``` mount -a ``` 4. Then you can change your password with the following command: ``` passwd ``` 5. Finally, you will need to reboot the server to apply the changes with the following command: ``` reboot ``` ## What Next? Congratulations! You have just learned the basics of User Administration in FreeBSD. Thank you for following along this how-to!  Feel free to check back with us for further updates and browse our many different [VPS hosting options](https://www.atlantic.net/vps-hosting/). --- # Benefits of WordPress Cloud Hosting: About WordPress in the Cloud > URL: https://www.atlantic.net/hipaa-compliant-wordpress-hosting/benefits-of-wordpress-cloud-hosting/ | Published: 2015-08-24 | Updated: 2026-05-04 | Author: Alexander Wise ## **Why do WordPress and the cloud work so well together?** Content management systems (CMS’s) are now fundamental to website development. WordPress has proven especially popular. Originally designed as a blogging platform, people quickly started to realize it could be used to create entire sites. It is now used for 75 million projects (websites and blogs) worldwide. It is incredibly easy for users to make their site their own: - To give a site design and structure, thousands of themes are available through WordPress and third parties. - Plug-ins allow site builders to easily expand functionality. As of August 17, there are 39,529 plug-ins in the official directory. - Finally, the entire system is open source – meaning that you can manipulate the code however you want. Through this wide range of structured and unstructured options, you can build web pages, manage and respond to comments, create a web store, and do virtually anything else you need with a platform that is designed for search engine optimization (SEO): “WordPress, straight out of the box, comes ready to embrace search engines,” [the WordPress site explains](http://codex.wordpress.org/Search_Engine_Optimization_for_Wordpress). “Its features and functions guide a search engine through the posts, pages, and categories to help the search engine crawl your site and gather the information it needs to include your site within its database.” (One other element of the CMS that helps with SEO is that the vast majority of themes use responsive design so that mobile devices immediately know how to process your site.) WordPress is a well-trusted CMS. Who uses it? *TechCrunch*, *The* *New Yorker*, BBC America, eBay, Best Buy, and Xerox, to name a few. However, without hosting, WordPress can’t go anywhere. WordPress is a Ferrari, but you have to give it good gas. Would you really want to put cheap gas into your Ferrari? [Cloud Server](https://www.atlantic.net/vps-hosting/)technology is widely used for much the same reason as WordPress. It is extraordinarily easy to implement. There are many advantages of using cloud over traditional hosting systems. If you have heard that cloud is fast, that is a vast understatement. In fact, Geoffrey Fox, PhD, a computer scientist at Indiana University, points out that cloud is often faster than supercomputers. Because of cloud’s efficiency, it is also highly affordable. Flexibility is another big benefit: resources are delivered on- demand and in near real-time. (For instance, Atlantic.Net offers per-second billing.) SEO company manager and hosting advisor Om Thoke suggests using these two technologies together so that your site looks great, includes all the features you want, and is delivered fast and mobile-ready. “**WordPress cloud hosting** basically offers the amazing benefits of both WordPress CMS, and the cloud server hosting approach,” he says. “This service will basically help [you] scale up [your] WordPress website with all the advantages of cloud server hosting.” While you may be aware of the strengths of WordPress and cloud technology, consider why cloud-hosted WordPress is the best choice. Six reasons: ## **1. Easy to integrate managed hosting** – One of the reasons that cloud is popular is because you don’t have to worry about maintenance and technical administration. If you opt for a managed service, one-click-WordPress cloud-hosted providers can easily solve any problems you might have. ## **2. Uptime** – If a physical server crashes, your site crashes as well. Cloud isn’t a physical server, though. It’s a virtual server built using a vast distribution of machines. If a physical machine goes down, another one is immediately available. That way any outages are irrelevant: your performance remains strong throughout. For this reason, the cloud is considered highly reliable. ## **3. Content delivery network (CDN)** – CDNs quickly distribute content. Content delivery networks are built with the same basic principles as the cloud. You can use a CDN in conjunction with the cloud if you like, to further improve your speed. ## **4. Optimized servers** – The prevalence of WordPress is a good thing because it means that cloud providers are prepared to help. “All the cloud servers out there are completely optimized for running WordPress in a seamless and efficient manner,” says Thoke. “You should have [a] technical team that is well-versed with fixing server issues related to WordPress.” ## **5. Growth-ready** – No one wants to have to rebuild their systems, physically add and remove hardware, or buy and sell components whenever the company gets bigger or smaller. WordPress cloud server hosting allows you to scale to meet demand. If you get a spike in traffic, you can deliver resources immediately. It’s built for scalability. ## **6. Security** – Since WordPress is so widely used, it’s also often a target for cyber-attacks. By using a strong cloud host, you will get redundant firewalls, regular malware scans, strict access rules, DDoS defenses, and everything else that hosting experts have at their disposal. With WordPress cloud hosting, you can deliver a beautiful website at the speed today’s customer expects – *especially with a 100% SSD (solid-state drive) cloud*. With Atlantic.Net, you standardly get daily backup and per-second billing with any cloud account, and you don’t even have to sign a contract. You can deploy your WordPress cloud environment in 30 seconds. Try our One-Click WordPress [Cloud Hosting](https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/) and be up and running in less than 30 seconds! Cloud server hosting services are only one of our offerings – we also offer dedicated hosting, managed hosting, and [HIPAA-compliant WordPress hosting](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/). --- # How to Set up a Minecraft Server on CentOS 7 > URL: https://www.atlantic.net/vps-hosting/how-to-minecraft-server-centos-7/ | Published: 2015-08-26 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 02/04/2021 ## Introduction This guide will walk you through setting up a Minecraft (version 1.16.5) server on CentOS 7 64bit with nifty startup and shutdown scripts for easy management. ## Setting up a Minecraft Server on CentOS 7 First, we install our prerequisite software: ``` yum install nano java-1.8.0-openjdk screen wget -y ``` Now, we create and enter the directory that the server will reside in: ``` mkdir /Minecraft cd /Minecraft/ ``` Next, we download the actual Minecraft server application and make it executable: ``` wget https://launcher.mojang.com/v1/objects/1b557e7b033b583cd9f66746b7a9ab1ec1673ced/server.jar ``` ``` chmod +x server.jar ``` Agree to the EULA that you definitely read: ``` echo 'eula=true' > eula.txt ``` The next steps are to create a handy script that allows us to start the server without remembering any arbitrary Java or screen CLI syntax: ``` echo 'cd /Minecraft' > /usr/bin/startcraft ``` ``` echo '/usr/bin/screen -d -m sh -c "/usr/bin/java -Xmx768M -Xms768M -jar /Minecraft/server.jar nogui"' >> /usr/bin/startcraft ``` Depending on the size of the server, you may want to adjust the “**Xmx**” and “**Xms**” values. These are the amount of RAM allocated to the Minecraft server instance. Mojang recommends 1GB of dedicated RAM, but you can get away with less if there will be very few people on at once. If you end up upgrading the server in the future, or just wish to change the value after following this tutorial, simply use “**nano**” to edit the **startcraft** command: ``` nano /usr/bin/startcraft ``` Now we make “**startcraft**” executable: ``` chmod +x /usr/bin/startcraft ``` Now let’s test that this half of the setup is working: ``` startcraft ``` ``` screen –r ``` ![Sample Output](https://www.atlantic.net/wp-content/uploads/2018/01/anet-howtocreateaminecraftservercentos6-01.jpg) Sample Output You should now see some text detailing that the server is starting/has started. Use **Control + A** then **D**to detach from the screen. For the final step of the basic setup, we open up the default Minecraft port on the firewall: ``` firewall-cmd --permanent --zone public --add-port 25565/tcp ``` To stop the server process gracefully, we would need to enter the screen session: ``` screen –r ``` Although we are not at a prompt, we can still type Minecraft server commands here **(/give**, **/op**, etc). The command to stop the server is simply “**stop**.” When it has completed the shutdown process, the screen session will terminate. To run the server once again, just type “**startcraft**” Alternatively, we can setup a simple script to inject the “**stop**” command into the screen session: ``` echo 'screen -p 0 -X stuff "stop$(printf \\r)"' > /usr/bin/stopcraft chmod +x /usr/bin/stopcraft ``` To stop the server now, simply run “**stopcraft**” anytime: ``` stopcraft ``` Now you can start and stop the server with single commands without ever having to type out java stuff or jump into screen! Don’t forget to give your username OP status. This can be done without touching screen with the following command: ``` screen -p 0 -X stuff "op USERNAME$(printf \\r)" ``` Replace “**USERNAME**” with your username. Once you have it, you can perform any commands including **/op** while in-game. Depending on the circumstances, you may need to log into the server in the Minecraft game before you can OP yourself. If you wish to have the “**startcraft**” script run when the server starts, simply run this command: ``` echo '/usr/bin/startcraft' >> /etc/rc.d/rc.local ``` The next step you will likely want to take is to point a DNS record to your server’s IP for easy connecting/distribution. You can read about using our cloud DNS manager here: [https://www.atlantic.net/community/howto/manage-cloud-dns-records/](https://www.atlantic.net/dedicated-server-hosting/cloud-hosting-getting-started-with-dns-records/) Finished! This page details all of the options you can modify in your “`/Minecraft/server.properties`” file: [Server properties](http://minecraft.gamepedia.com/Server.properties) Happy crafting! Be sure to contact us for all of your [VPS hosting](https://www.atlantic.net/vps-hosting/) needs! --- # How to Install Nginx on CentOS 7 > URL: https://www.atlantic.net/vps-hosting/how-to-install-nginx-centos-7/ | Published: 2015-08-27 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 08/27/15 ## Introduction This how-to will walk you through installing Nginx on CentOS 7.  Nginx is a powerful web server software that can be used on your server. It is also known for its high performance and low memory usage which will allow fewer resources to be used but getting the job done efficiently. ## What Do You Need? You need a CentOS 7 server that is configured with a static IP address. If you do not have a server already, you can visit Atlantic.Net Cloud Hosting page and spin up a [reliable virtual private server](https://www.atlantic.net/vps-hosting/) in under 30 seconds ## Server Preparation To get started, login to your CentOS 7 via SSH or the VNC Console in cloud.atlantic.net. Atlantic.Net Cloud servers are set up as minimal installations in order to avoid having unnecessary packages from being installed and never used. Because of this, let’s make sure that your server is fully up-to-date. ``` sudo yum update ``` With the server up-to-date, we can continue the installation process of your server. ## Install EPEL and Nginx on CentOS 7 In order to install Nginx, we will need to use the apt-get command so we can install the software. Also, we will need to install EPEL in order for the Nginx installation installs correctly. Run the command to install the EPEL: ``` sudo yum install epel-release ``` Run the command to install Nginx: ``` sudo yum install nginx ``` Run the command to start the service: ``` sudo systemctl start nginx ``` To make sure that Nginx starts when rebooted, insert the following: ``` sudo systemctl enable nginx ``` You will now have NGINX installed on your server. This can be verified by typing in the following with your IP ADDRESS on your browser (http://YOUR.IP.ADD.RESS ) ![This is the default webpage when installing Nginx on CentOS 6.7](https://www.atlantic.net/wp-content/uploads/2018/01/How-to-Install-Nginx-on-CentOS-6-1.png) This is the default webpage when installing Nginx on CentOS 7 ### What Next? You now have your CentOS 7 server with Nginx installed. You can now begin building high-performance websites using your newly installed web server. Thank you for following along in this How-To! Check back with us for any new updates and try any of our [industry-leading VPS hosting solutions](https://www.atlantic.net/vps-hosting/). --- # What is: Javascript Frameworks – An Introduction > URL: https://www.atlantic.net/vps-hosting/what-is-javascript-frameworks-introduction/ | Published: 2015-08-28 | Updated: 2026-03-04 | Author: Alexander Wise ##### ***Target Audience:*** *This article assumes only a basic familiarity with front-end web development and serves as an introduction to JavaScript in modern web development.* ## Introduction The web is evolving. Websites, and more specifically, web design paradigms are changing constantly, and front-end developers must be aware of the latest trends in development to create the best projects. The tried and true languages of the web have been HTML, CSS, and JavaScript for nearly two decades. That still holds true today. How these languages are implemented has changed signficiantly, though, and none more so than JavaScript. JavaScript is seen the most today via web browsers, where client-side scripts interact with users. Modern websites and web apps rarely, if ever, utilize pure Javascript. Rather, developers have created new frameworks with JavaScript that speed up development, improve functionality, and allow for the [creation of agile, modern web apps](https://brainhub.eu/library/top-javascript-development-companies). This article serves as an introductory overview of the concept of frameworks. ![Javascript code](https://www.atlantic.net/wp-content/uploads/2018/01/javascript.jpg) *Photo: [Dmitry Baranovskiy](https://www.flickr.com/photos/dmitry-baranovskiy/2378867408) / licensed under [CC BY 2.0](https://creativecommons.org/licenses/by/2.0/)* ## JavaScript Frameworks vs. Libraries Understanding JavaScript frameworks necessitates an understanding of JavaScript libraries and the differences between the two. Often, the terms are used interchangeably, but each has its own particular role to play despite some overlap that may occur. ### What Is a JavaScript Library? A library is a set of pre-written code that acts as a toolkit for a developer. For example, jQuery–which aids in handling events or creating animations, among many other benefits–is one of the most used JavaScript libraries. Libraries, while useful, do not impose any structure onto a developer’s code. Frameworks, in contrast, impose structure and what this structure actually does will be discussed in the next section. ### What Is a JavaScript Framework? JavaScript frameworks are tools designed to speed up development and organize code used to build modern web apps. They exist to solve problems more directly rather than providing an open set of tools like most libraries do. The earliest frameworks were created to help manage what were becoming large and unwieldy codebases and to simplify the process of creating dynamic web apps that do not function like traditional server-side web apps. ## Why Are JavaScript Frameworks Important? Web apps have exploded in popularity over the past decade. Companies like Twitter and Airbnb don’t require you to download specific software to your devices (outside of mobile apps) to use their services. Rather, they have created web interfaces their users interact with. Web apps from these companies and countless others incorporate client-side loading to create a smoother user experience. Coding these modern web apps, even small ones, requires a large amount of JavaScript to create the desired client-side functionality. As web apps had increased in popularity, [javascript developers](https://relevant.software/javascript-development-services/) noticed that they were writing nearly the same code over and over again to produce the same basic features. They realized that it would be a lot more efficient to have tools to speed up this process. ### Modal View Controllers (MVCs) What JavaScript frameworks help create are MVCs. An MVC (Model View Controller) is a concept that is key in developing structured user interfaces with client-side loading functionality. Constructing complex user interfaces that run in a web browser is incredibly time consuming, and you’ll likely write similar code that has been written over and over again. JavaScript frameworks serve to organize JavaScript for apps looking to quickly perform tasks client-side without constantly going to a [virtual private server](https://www.atlantic.net/vps-hosting/). These Frameworks help give web applications structure and cut down time spent working to create new MVCs. They may contain several libraries attempting to simplify everything from templating to working with Document Object Models. Each framework contains different libraries and tools that best suit different types of web apps. Understanding why JavaScript frameworks were first developed is extremely helpful when trying to learn more about individual ones and comparing them to each other. ## Conclusion We hope you have enjoyed this introduction to Javascript frameworks. Please check back with us for new updates soon and check out our exciting cloud hosting solutions and our [one-click VPS hosted applications](https://www.atlantic.net/vps-hosting/). --- # How to: Vim Tips for Beginners (or, Help! I Have To Use Vim!) > URL: https://www.atlantic.net/vps-hosting/how-to-vim-tips-beginners/ | Published: 2015-08-31 | Updated: 2026-07-07 | Author: Alexander Wise ## Introduction Perhaps you are happily configuring a [virtual private server](https://www.atlantic.net/vps-hosting/) or following along in an online tutorial, and you end up, by accident or by necessity (I’m looking at you, Minimal Install), having to use a text editor like Vi or Vim. Do you break out into a cold sweat? Do you get the shakes? Do you feel the uncontrollable urge to flip the desk? ![Frustrated non-Vim user](https://www.atlantic.net/wp-content/uploads/2018/01/anet_help_vim-300x200-1.jpg) Photo: [Peter Hess](https://www.flickr.com/photos/peterhess/2976755407/in/gallery-mairin-72157626601919996/) / licensed under [CC BY 2.0](https://creativecommons.org/licenses/by/2.0/) It happens. Vim (I’ll be using “Vim” from here on out, since these tips can be used in either Vi or Vim) can be a confusing landscape to navigate. Devotees may swear by it, but for most of you, it is the text editor of the Beast and should be avoided at all costs. Except when it can’t. For those situations, this quick reference will try to help you navigate your way back to what must seem like much saner pastures. ## Prerequisites – New to Vim – Fear/hatred of Vim – Stuck in Vim – I don’t want to learn it, I just want to get on with life! ## Quick Links Typing Exiting Navigation Find/Replace Delete Undo . ## Why Can’t I Just Type in Vim? Vim works in different modes in which the keyboard keys can perform different actions based on the mode you’re in (kind of the way a game controller’s controls might behave differently in a game based on whether you are flying a plane or running through ancient ruins). Vim generally starts in “Normal” mode, where many of the keys are mapped to different actions (some of you may consider the name of this mode an oxymoron). To get to a mode where you can just start typing–called “Insert” mode in Vim world–type: ``` i ``` You should see “– INSERT –” show up in the lower left of your screen. ![Vim insert mode](https://www.atlantic.net/wp-content/uploads/2015/08/anet_vim_insert_mode.png) Vim insert mode > Most instances of Vim will provide this context clue to help you identify what mode you are in. Some older instances of Vi, though, do not present this clue. Even Vim users hate it when we find ourselves in this situation. > > For all you Vim grognards, yes, there are other ways to enter “Insert” mode. This is arguably the most straightfoward. And how did you get here?   To get back to “Normal” mode (which is important if you want to save, quit, or executate any of the other actions below), press ‘Esc’. > Note: The remaining tips will be executable in “Normal” mode, so remember to ‘Esc’ out of “Insert” mode before trying to complete these actions! . ## Exit Vim ## “I accidentally ended up in Vim and want to quit!” ``` :q [then press 'Enter] ``` ## “But I’ve made some changes I want to keep before I quit!” ``` :wq [then press 'Enter'] ``` ## “I just want to get out and I don’t care to save any changes I might have accidentally made while mashing keys!” ``` :q! [then press 'Enter'] ``` . ### Navigation in Vim Go to the top of the document: ``` gg ```   Go to the bottom of the document: ``` G ```   Navigation, measured by page: ``` Ctrl+u [Up by half a page] Ctrl+b [Back by a full page (equivalent to 'Page Up')] Ctrl+d [Down half a page] Ctrl+f [Forward by a full page (equivalent to 'Page Down')] ``` . ### Find and Replace in Vim “I need to find a particular string” (e.g., waldo): ``` /waldo [then press 'Enter'] ``` > To find the next occurrence of the string you are searching, press ‘n’ (as in “next”). If you’ve gone too far, you can cycle backwards through matches with a capital ‘N’ (as in…, “NO! Too far! Go back!”)   To replace all instances of one string with another (e.g., find all references to “waldo” and replace with “carmen sandiego”): ``` :%s/waldo/carmen sandiego/gc [then press 'Enter'] ``` > The ‘c’ at the end of this command will ask you for confirmation for each replacement before continuing (use the standard ‘y’ and ‘n’ to confirm or deny each substitution). If you leave the ‘c’ off, it will replace all instances without confirming. . ### Delete in Vim To delete a line of text, make sure your cursor is somewhere in the line you want to delete: ``` dd ``` > You can use this command to delete multiple adjacent lines, as well. Just place your cursor in the first line you’d like to delete, then prepend the number of lines to delete before the `dd` (e.g., to delete 10 lines, `10dd`). . ### Undo in Vim To undo the last thing you did, type: ``` u ``` > You can keep pressing ‘u’ to undo each previous action, at least as far back as your session’s buffer goes (so, for example, you could undo the changes you made, but not the changes you or another user made before last editing the file).   ### Care To Learn More? If you’ve made it this far, I hope you have found some of these tips useful. If you’re interested in perhaps dipping your toe a little further into the Vim pool, you can, on the command line of a Linux device with Vim installed, type `vimtutor` to start some guided lessons. Or, if you prefer something a little less intimidating, you could always try the game [Vim Adventures](http://vim-adventures.com/)! --- # How to : Authoritative BIND9 DNS Server on CentOS 7 : Install & Configuration > URL: https://www.atlantic.net/vps-hosting/how-to-authoritative-bind9-dns-server-centos-7-install-configuration/ | Published: 2015-09-02 | Updated: 2026-01-09 | Author: Alexander Wise ## Introduction In this how-to article, we will walk you through the installation of a secure BIND9 authoritative DNS server on CentOS 7 > #### What is BIND? > > BIND is open source software that implements the Domain Name System (DNS) protocols for the Internet. It is a reference implementation of those protocols, but it is also production-grade software, suitable for use in high-volume and high-reliability applications. > – [ISC (Internet Systems Consortium)](https://www.isc.org/downloads/bind/) ## Outline of Configuration Steps 1. Basic Server Preparation. 2. Installation of the BIND software packages. 3. Configuration of the BIND software packages. 4. Adding a test zone (domain) 5. Testing your DNS server ## Prerequisites Before you begin this how-to article, you will need to make sure that you have these prerequisites done first. – CentOS 7 Server – If you do not have a server available, you can spin one up in via our [VPS hosting](https://www.atlantic.net/vps-hosting/pricing/) services page. – Your preferred text editor installed – We will be using nano in this tutorial. . ## 1 – Basic Server Preparation First, make sure that you are logged in as the root user account. ``` sudo su - ``` Next, we are going to make sure the core operating system is fully updated. ``` yum update -y ``` Now that your system is fully updated, we will update the firewall (*enabled by default*) to allow DNS (TCP Port 53 / UDP Port 53) to access your server. ``` firewall-cmd --permanent --zone public --add-port 53/tcp firewall-cmd --permanent --zone public --add-port 53/udp firewall-cmd --reload ``` ## 2 – Installation of the BIND DNS Software Packages We are now ready to install the BIND software packages on your server. ``` yum install -y bind bind-utils bind-chroot ``` > - **bind** : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server > - **bind-utils** : Utilities for querying DNS name servers > - **bind-chroot** : A chroot runtime environment for the ISC BIND DNS server Now that you have the required BIND software packages installed, we are ready to start the BIND services and set them to start automatically upon a server reboot. ``` systemctl start named systemctl enable named ``` . ## 3 – Configuration of the BIND DNS Server Upon starting the BIND DNS server, the chroot package automatically mounts all the configuration files in the `/var/named/chroot` directory of your server. When you run BIND (or any other process) in a chroot jail, the process is simply unable to see any part of the filesystem outside the jail. For reference, the base directory you will be working in for any BIND configurations is `/var/named/chroot` First, let’s change to that directory for the remainder of these steps. ``` cd /var/named/chroot ``` Now, let’s create some directories and a configuration setting file for your new server and set the ownership.  These directories will be used to store forward and reverse zone files for your DNS server. ``` mkdir var/named/fwd-zones mkdir var/named/rev-zones chown -R named:named var/named/fwd-zones chown -R named:named var/named/rev-zones touch etc/zones.conf chown root:named etc/zones.conf ``` Next, we are going to edit the `etc/named.conf` configuration file.  We will walk you through the entire setup so that you understand what each option is doing for your server. ``` nano etc/named.conf ``` Upon initial installation, the default configuration file will be the below (if you would like to jump to final `etc/named.conf`, you can find it below): ``` // // named.conf // // Provided by Red Hat bind package to configure the ISC BIND named(8) DNS // server as a caching only nameserver (as a localhost DNS resolver only). // // See /usr/share/doc/bind*/sample/ for example named configuration files. // options { listen-on port 53 { 127.0.0.1; }; listen-on-v6 port 53 { ::1; }; directory "/var/named"; dump-file "/var/named/data/cache_dump.db"; statistics-file "/var/named/data/named_stats.txt"; memstatistics-file "/var/named/data/named_mem_stats.txt"; allow-query { localhost; }; recursion yes; dnssec-enable yes; dnssec-validation yes; dnssec-lookaside auto; /* Path to ISC DLV key */ bindkeys-file "/etc/named.iscdlv.key"; managed-keys-directory "/var/named/dynamic"; }; logging { channel default_debug { file "data/named.run"; severity dynamic; }; }; zone "." IN { type hint; file "named.ca"; }; include "/etc/named.rfc1912.zones"; include "/etc/named.root.key"; ``` The available configuration settings and options in BIND are very extensive. In this article we will be covering only the options to setup your server to be an authoritative DNS server and secure your server from recursive DNS amplification attacks. For a more in-depth explanation of all of these options, we recommend [the folks at Zytrax.com](http://www.zytrax.com/books/dns/). #### Listening Options The first configuration option we are going to change is the listening options for your server.  By default, the server is setup to listen only on the local loopback address (127.0.0.1).  We are going to change this to listen on all interfaces on your server.  Replace the following lines inside the `options { }` clause of the configuration file. ``` listen-on port 53 { any; }; listen-on-v6 port 53 { any; }; ```   #### ACLs (Access Control Lists) We are now going to add some ACL (Access Control List) rules to the configuration.  These ACLs will be used to extend the security settings for the query lookup options as well as the recursive query options. The first rule–which we’ll call “allowed-queries”–will be used to allow any source address to query your DNS server. The second rule–we’ll call this one “allowed-recursion”–will be used to restrict recursive lookup to only the localhost address. Add the below ACL policy rules just above the `options { }` clause. ``` // ACL - Allow queries from ANY source address acl "allowed-queries" { any; }; // ACL - Allow recursion from LOCALHOST only. acl "allowed-recursion" { 127.0.0.1; ::1; }; options { ... }; ``` Next, we are going to change the configuration value of the `allow-query` statement variable to use the new ACL we just created. The `allow-query` statement defines who (i.e., source networks) are allowed to query your DNS server.  Replace the following line inside the `options { }` clause of the configuration file. ``` allow-query { "allowed-queries"; }; ``` #### Restricting Recursion Now we need to secure the recursion lookup permission on your server.  Recursion is a technique in which a DNS server queries other DNS servers on behalf of the requesting client to fully resolve the name, and then sends an answer back to the client. Attackers can [use this technique to cause DNS servers with open recursion enabled to unwittingly participate in a DDoS (Distributed Denial of Service) attack](https://www.cisa.gov/news-events/alerts/2013/03/29/dns-amplification-attacks). Therefore, if a DNS server in your network is not intended to receive recursive queries, recursion should be disabled on that server or secured not to allow unauthorized sources to use this technique. By default, the BIND DNS server is configured to allow any source IP to request recursion. We are going to add a configuration variable to restrict who can use this server for recursive requests using the second ACL that we created– “allowed-recursion”.  Add the following statement inside the `options { }` clause of the configuration file, just below the statement `recursion yes;`. ``` recursion yes; allow-recursion { "allowed-recursion"; }; ``` We are now going to add an include statement to the configuration file.  This statement will be used to include the authoritative zone data (domains) that your server will be configured to respond to. Add the following line below the close of the `option { }` clause, just after the last include statement. ``` include "/etc/zones.conf"; ``` We have now completed the configuration changes in the `etc/named.conf` configuration file.  You can now save and exit your changes. . #### New named.conf File For review, your `etc/named.conf` configuration file should now look like the below: ``` // // named.conf // // Provided by Red Hat bind package to configure the ISC BIND named(8) DNS // server as a caching only nameserver (as a localhost DNS resolver only). // // See /usr/share/doc/bind*/sample/ for example named configuration files. // // ACL - Allow queries from ANY source address acl "allowed-queries" { any; }; // ACL - Allow recursion from LOCALHOST only. acl "allowed-recursion" { 127.0.0.1; ::1; }; options { listen-on port 53 { any; }; listen-on-v6 port 53 { any; }; directory "/var/named"; dump-file "/var/named/data/cache_dump.db"; statistics-file "/var/named/data/named_stats.txt"; memstatistics-file "/var/named/data/named_mem_stats.txt"; allow-query { "allowed-queries"; }; recursion yes; allow-recursion { "allowed-recursion"; }; dnssec-enable yes; dnssec-validation yes; dnssec-lookaside auto; /* Path to ISC DLV key */ bindkeys-file "/etc/named.iscdlv.key"; managed-keys-directory "/var/named/dynamic"; }; logging { channel default_debug { file "data/named.run"; severity dynamic; }; }; zone "." IN { type hint; file "named.ca"; }; include "/etc/named.rfc1912.zones"; include "/etc/named.root.key"; include "/etc/zones.conf"; ``` . ## 4 – Adding Your First Zone (Domain) We are now going to add your first zone that your DNS server will be authoritative for.  We will be using a testing domain (*example.tld*) for this step as the example. First, we will create a new file in the directory `var/named/fwd-zones` that we created earlier. ``` touch var/named/fwd-zones/example.tld.zone; chown named:named var/named/fwd-zones/example.tld.zone; ``` Next, we are going to add the example zone record data for this domain.  Edit the new file that we just created and add the zone data to the configuration file. ``` nano var/named/fwd-zones/example.tld.zone ``` **Zone Data** ``` ; zone file for example.tld $TTL 14400 ; 4 hours - default TTL for zone $ORIGIN example.tld. ;; SOA Resource Record @ IN SOA ns1.example.tld. hostmaster.example.tld. ( 2015010100 ; se = serial number 12h ; ref = refresh 15m ; ret = update retry 3w ; ex = expiry 3h ; min = minimum ) ;; Name Servers IN NS ns1.example.com. ns1           IN      A       192.0.2.3 ;; Mail Exchange Resource Records @ IN MX 10 mail.example.tld. ;; Web Server Resource Records @ IN A 192.0.2.3 www IN CNAME @ ;; FTP Server Resource Records ftp IN A 192.0.2.3 ``` Once you have made all the changes you need to make, save and exit. Now we are going to edit the `etc/zones.conf` configuration file to include the new domain we just created. ``` nano etc/zones.conf ``` Now add the below parameters to the configuration file. ``` zone "example.tld" in { type master; file "fwd-zones/example.tld.zone"; allow-transfer { none; }; }; ``` Once done, save and exit this file. We are now ready to restart your DNS services so that all the new configurations load. ``` systemctl restart named ``` If everything restarted successfully, without any errors, you should receive the following response: ``` Stopping named: . [ OK ] Starting named: [ OK ] ``` . ## 5 – Testing Your DNS Server We are now ready to test the functionality of your new DNS server.  First, we are going to confirm that your DNS server is responding for the zone (domain) that we just created.  Execute the following command: ``` dig example.tld -t ANY @localhost ``` You should see the below similar response output from your server.  The key response values to look for are the `;; ANSWER SECTION:` values.  This output lets you know that the server has responded to your request with the record data that you entered in the previous steps. ``` ; <<>> DiG 9.8.2rc1-RedHat-9.8.2-0.37.rc1.el6_7.2 <<>> example.tld -t ANY @localhost ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 61421 ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 1 ;; QUESTION SECTION: ;example.tld. IN ANY ;; ANSWER SECTION: example.tld. 14400 IN SOA ns1.example.tld. hostmaster.example.tld. 2015010100 43200 900 1814400 10800 example.tld. 14400 IN NS ns1.example.tld. example.tld. 14400 IN MX 10 mail.example.tld. example.tld. 14400 IN A 192.0.2.3 ;; ADDITIONAL SECTION: ns1.example.tld. 14400 IN A 192.0.2.3 ;; Query time: 0 msec ;; SERVER: 127.0.0.1#53(127.0.0.1) ;; WHEN: ;; MSG SIZE rcvd: 147 ``` The second test we are going to do is to check that your server is responding to recursive lookups from the localhost.  Execute the below command to begin the test: ``` dig google.com -t ANY @localhost ``` If the server is setup as expected, you should receive a similar recursive `;; ANSWER SECTION:` response. ``` ;; ANSWER SECTION: google.com. 86400 IN SOA ns1.google.com. dns-admin.google.com. 4294967295 7200 1800 1209600 300 google.com. 600 IN MX 50 alt4.aspmx.l.google.com. google.com. 600 IN MX 40 alt3.aspmx.l.google.com. google.com. 600 IN MX 10 aspmx.l.google.com. google.com. 600 IN MX 20 alt1.aspmx.l.google.com. google.com. 600 IN MX 30 alt2.aspmx.l.google.com. google.com. 3600 IN TXT "v=spf1 include:_spf.google.com ~all" google.com. 86400 IN TYPE257 \# 19 0005697373756573796D616E7465632E636F6D google.com. 300 IN AAAA 2607:f8b0:4008:804::200e google.com. 300 IN A 216.58.219.78 google.com. 172800 IN NS ns1.google.com. google.com. 172800 IN NS ns3.google.com. google.com. 172800 IN NS ns4.google.com. google.com. 172800 IN NS ns2.google.com. ;; AUTHORITY SECTION: google.com. 172800 IN NS ns4.google.com. google.com. 172800 IN NS ns1.google.com. google.com. 172800 IN NS ns3.google.com. google.com. 172800 IN NS ns2.google.com. ;; ADDITIONAL SECTION: ns2.google.com. 172800 IN A 216.239.34.10 ns1.google.com. 172800 IN A 216.239.32.10 ns4.google.com. 172800 IN A 216.239.38.10 ns3.google.com. 172800 IN A 216.239.36.10 ``` The last test that we are going to do is to validate that your server is **NOT** open to a DNS amplification attack. The folks at openresolver.com have set up a simple test you can use with `dig`: ``` dig +short test.openresolver.com TXT @1.2.3.4 (replace 1.2.3.4 with the IP address or domain name of the DNS server you are testing) ``` A response of `"open-resolver-detected"` indicates that you have recursion enabled. *No response, in this case, is a good thing*. The openresolver.com site also has [a browser-based tool](http://openresolver.com/) available for testing for this vulnerability. Upon testing with your public IP address, you should receive the following similar response: ![Successful Open Recursive DNS Resolver Test](https://www.atlantic.net/wp-content/uploads/2018/01/DNS1.png) Successful Open Recursive DNS Resolver Test   ### Congratulations! You now have an authoritative DNS server configured and running. Thank you for reading! Check out some of the related articles below and thanks for trying our reliable [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions at Atlantic.Net. --- # Why Businesses & Developers Choose WordPress > URL: https://www.atlantic.net/hipaa-compliant-wordpress-hosting/why-businesses-developers-choose-wordpress/ | Published: 2015-09-02 | Updated: 2026-03-01 | Author: Alexander Wise ## **The Incredible Scope of WordPress** Popularity certainly isn’t the only factor when choosing a content management system (CMS), but a quick look at the statistics shows that WordPress certainly has that base covered. In 2011, WordPress was used on 14.7% of the top 1 million sites worldwide. At that time, there were about 500,000 WordPress posts each day. According to *Technorati*, 48 of the top 100 blogs were using WordPress, and it was translated into 40 languages. Still today, WordPress is a massive presence on the Internet. ![Why Businesses & Developers Choose WordPress](https://www.atlantic.net/wp-content/uploads/2014/01/Comic-Strips-Atlantic-19-001.jpg) What that basically means is that companies both large and small are trusting WordPress as one of the fundamental tools of their business. There are many reasons why developers and businesses tend to prefer WordPress, deploying it with a one-click application through Cloud Hosting service providers. Here are 15 of them: ## **The Price is Right** For any business, but especially for startups and bloggers, the fact that WordPress is 100% free is definitely helpful. You don’t have to be concerned that there might be hidden software fees if you get a spike in traffic. ## **Ready to Use Off-the-Shelf** WordPress is ready to go as soon as you install it, which is not the case with some of the other CMS options, explains John Rampton in *Entrepreneur*. “This means that you don’t have to hunt down, install, and configure a long list of add-ons just to get many of the features WordPress considers core (comments, RSS feeds, revisions, etc.),” [he notes](http://www.entrepreneur.com/article/241535). ## **Choose Your Own Adventure** There are a couple of aspects related to the ability to customize when you deploy one-click application hosting of this flexible solution. First, WordPress is open source, which means that developers can go in and change the code to meet whatever specifics are needed for a business’s site. Second, you can easily and quickly add plug-ins to expand the features of your site – typically in less than 30 seconds. These two elements of flexibility mean that you can use WordPress for just about any purpose: blogging, selling products online, whatever. ## **SEO-Friendliness** The major search engines particularly like WordPress sites because it’s specifically designed for easy crawling, allowing Google and others to seamlessly feed your content into their algorithm, says Rampton. “In fact, Google’s Matt Cutts actually endorsed WordPress during WordCamp San Francisco 2009,” he says. “His personal blog is on WordPress.” ## **Security** There’s a good case that Apple operating systems are more secure than Windows platforms in large part because there are so many more Windows devices. The downside of popularity is that your system becomes a bigger focus of hackers. That’s true with WordPress, too, so you do see situations in which someone finds a vulnerability in the software, which is a threat to the security of your site. However, developers like WordPress because security is a primary concern of the open source community. “While you can practice some basic security measures, such as not downloading a theme or plugin from an untrusted site,” says Rampton, “WordPress constantly updates its software to prevent attacks.” Updates are sent out to users automatically, and email notices are sent to remind users to perform the update, making it easier to stay abreast of all security patches. You can further enhance your security with a cloud provider that has a long history in securing Web hosting networks. ## **User-Friendliness** Of course everyone wants their site to be of use to the search engines, but they also want people to be able to use the app without unneeded confusion. WordPress essentially has the user-friendly, intuitive feel of an everyday environment such as MS Word or Gmail. When you talk about speed with WordPress, you mean nearly instantaneous – especially if you use one-click WordPress hosting.You can deploy one-click WordPress hosting in 30 seconds. ## **Support When You Need It** The network of free support for WordPress is extensive, which means that developers can get answers to their questions quickly.  Primarily, that is because the WordPress community is essentially an interactive, open-source environment in which questions are considered and resolved through the [WordPress Forums](https://wordpress.org/support/). People can reach out to their cloud hosting providers for support as well. ## **Multimedia Integration** If a developer really wants to be able to improve the quality of the business’s website, they want to make it more engaging with [stunning quality photos](https://www.freepik.com/popular-photos), video, and PDFs (such as e-books, whitepapers, or any other documents). “Thankfully, WordPress makes it easy for you to insert multimedia files into a page or post,” says Rampton. “Not only is it easy for you to upload multimedia files, you can also edit files, like images, while in the Media Library Screen.” ## **Immediate Access to Fast WordPress Hosting** People like the accessibility and user-friendliness of WordPress because it means that they can build the environment they like and achieve immediate productivity and efficiency. Those are characteristics of Atlantic.Net as well. In business since 1994, we have the skills and expertise you need for fast and reliable one-click WordPress hosting. Cloud hosting services are only one of our offerings – we also offer dedicated hosting, managed hosting, and [HIPAA-compliant WordPress hosting](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/). --- # How to Install wget on CentOS 7 with a wget Cheat Sheet > URL: https://www.atlantic.net/vps-hosting/how-to-install-wget-centos-7/ | Published: 2015-09-03 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 02/04/2021 ## Introduction In this quick and simple article, we will install wget command on a CentOS 7 server and we have included a wget cheat sheet. Wget is a free software package for downloading files using HTTP, HTTPS and FTP. ## Prerequisites A CentOS 7 server with Root privileges. If you do no have a server, you can spin up an efficient and reliable SSD [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. ## Installing wget on a CentOS 7 Install wget using the following command: ``` yum install wget ``` You will be asked if it is okay to install the downloaded size, you would just type `y`for yes and press `Enter` to continue. I have a screenshot of a successful install below: ![anet-How to install wget on a CentOS 6](https://www.atlantic.net/wp-content/uploads/2018/01/2015-04-29-12_19_27-root@OpenVas_.png) Successful Installation of wget Once installed, you can use it to download files or even entire web sites. ## Quick wget Cheat Sheet To download a single file from a website using the following command: ``` wget http://sitename.com/file.jpg ``` If your web page requires a username and password use the following command: ``` wget --user=youruser --password=yourpassword http://sitename.com/file.jpeg ``` Download a file from an ftp site using the following command: ``` wget ftp://sitename.com/file.jpeg ``` If your ftp site requires a username and password use the following command: ``` wget ---ftp-user=youruser --ftp-password=yourpassword ftp://sitename.com/file.jpeg ``` Download and entire website using the following command: ``` wget -r http://sitename.com ``` Download and save it in a specific path using the following command: ``` wget --directory-prefix=folder/nextfolder sitename.com ``` Download a file and save it under a different name using the following command: ``` wget --output-document=filename.php sitename.com ``` Resume an interrupted file download using the following command: ``` wget --continue sitename.com/filename.mp4 ``` Limit download speed of a file using the following command: ``` wget --limit-rate=1000k http://sitename.com/file.iso ``` Now you have successfully installed wget and have some examples to work with! You can see the wget manual by running “wget -h”. Please check back here for more updates or to find out how to limit Root user in Centos check out our [how-to here](https://www.atlantic.net/vps-hosting/how-to-limit-root-user-centos/), or see below for other interesting related how-to’s. [VPS hosting](https://www.atlantic.net/vps-hosting/) is just one of the many hosting services offered by Atlantic.Net. Contact us today for more information! --- # Write for Atlantic.Net FAQ > URL: https://www.atlantic.net/vps-hosting/write-atlantic-net-faq/ | Published: 2015-09-03 | Updated: 2026-03-04 | Author: Alexander Wise   Frequently Asked Questions ## **Q**. I want to write an article on a certain topic, but how do I know that someone else isn’t already working on a very similar article? > **A**. First, verify that we haven’t already published an article covering same > topic on our [community site](https://www.atlantic.net/tutorials/) or [blog](https://www.atlantic.net/blog/). If your search there doesn’t turn up any published articles, email us at contentmanager@atlantic.net with your topic, and we’ll let you know if someone else might already be working on it. If not, we’ll give you exclusive rights for two weeks to complete the article. If it’s > not completed in that two-week period, we may open that topic up to any writer, so the sooner the better! . ## **Q**. Are there particular topics you would like covered? > **A**. We are always looking to expand the range of topics our community section covers. If you’d like some suggestions, let us know at contentmanager@atlantic.net, and we’ll send you a list of what topics we are looking for. . ## **Q**. I have an idea for an article, but I’m not sure if it’s a “How To” or a “What Is” article. How can I determine which section it should belong to? > **A**. Categorizing articles is an editorial decision, so you don’t > have to worry about making that determination yourself. We’ll take care of that! If you’re not sure how an article topic might fit, send us a pitch at contentmanager@atlantic.net, and we’ll evaluate it and see if we can give you a good starting point. . ## **Q**. What document format do you use? > **A**. We prefer files with as little extraneous formatting as possible, so plain old text, html, or .md files are sufficient. You can include them as an email attachment to contentmanager@atlantic.net, or provide us link to the file sharing service we can download it from. . ## **Q**. Do you offer a discount on server usage for writers to use as a testing platform for articles currently being written? > **A**. We do not currently offer a discount program for writers, but it is something we are considering in the future. If we do roll out this sort of program, we will let all of our writers know! . ## **Q**. Do articles need to be specifically relevant to the products and services that Atlantic.Net offers? > **A**. Not necessarily. While we do want to have a library of reference articles directly relevant to the services and platforms our customers are using, we are also tech nerds and welcome informative articles on a wide variety of technologies. We do draw the line, however, when it comes to topics which violate our [Acceptable UsePolicy](https://www.atlantic.net/acceptable-use-policy/). So, for example, we’re not likely to publish an article on how to DDoS your grandmother (and seriously, why would you do that?). . ## **Q**. Can I write an article in a language other than English? > **A**. We are actively looking into the possibility and logistics of publishingtranslations of our articles into other languages. If this sort of program becomes something we will be opening up to our writers, we’ll let interested writers now! .   --- # How to Use Grep Commands on Linux or FreeBSD > URL: https://www.atlantic.net/vps-hosting/how-to-use-grep-commands/ | Published: 2015-09-04 | Updated: 2026-03-03 | Author: Alexander Wise Verified and Tested 08/31/15 ## Introduction Few things are more frustrating than wanting to do something and not knowing how to do it.  In this How-to, we will be going over the  GREP commands so we could make our lives easier and work more effective in our sessions. ## Prerequisites You need a Linux server that is configured with a static IP address. If you do not have a server already, you can visit [VPS hosting page](https://www.atlantic.net/vps-hosting/) and spin a new server up in under 30 seconds. ## GREP in a Nutshell To understand how to work in GREP, we need to know what GREP is and what it does. An acronym for “Global Regular Expression Print”, GREP is a command that allows you to manipulate the way requested information is printed/viewed. ## Searching a Single File With the following grep command you can search for a single file from a specified location. It is simply read as getting MyText from MyFile, and the command reads as follows. ``` grep "MyText" MyFile ``` ## Searching Multiple Files With the following grep command you can search for multiple files from a specified location.Its is simply read as get MyText from MyFile in any format(tis could be TXT, JPEG, PHP, etc.) ``` grep "MyText" MyFile_txt ``` ## Searching and Ignoring Files With the following command, you could search for specific files at the same time ignore irrelevant ones. MyFile being the file that you want and the second grep text after the pipe is the one that is irrelevant, and you want to be ignored. ``` grep MyFile | grep -v IrrelevantFile ``` ## Counting Words in a Specified File With the -c variable, you can count how many of the same word or phrase in a specific file. Want to know how many times MyWord appears in myfile.txt? ``` grep -c "MyWord" myfile.txt ``` ## Searching Before and After With the –context= and -C command we can search words before and after a specified words or phrases in specific locations. Want to know how many lines are before and after MyWord? ``` grep --context=3 MyWord MyFile.txt grep -C 3 'MyWord' MyFile.txt ``` ## Searching Patterns With the egrep command, we can do an extended search using | (pipe) to search for wanted and unwanted words. Want to know where is a line that specifies multilple words from MyFile.txt? ``` egrep 'UnwatedWord|WantedWord' MyFile.txt ``` ## Searching Case Sensitive Words With the -i command we can find a specified word no matter if it’s in upper case or lower case letters. Want to know where is MyWord no matter how its written? ``` grep -i MyWord MyFile ``` ## Searching Patterns in gzip Files With the zgrep command, we can find a specified word no matter if it’s in upper case or lower case letters in the any .gz file. Want to know where is MyWord no matter how its written in all of my .gz files? ``` zgrep -i MyWord *.gz ``` ## Searching for Whole Words With the -w command, we can find whole specified words displaying their whole line. Want to know the lines that contain is MyWord withing MyFile? ``` grep -w MyWord MyFile.txt ``` To search a word ending with MyWord, anywhere, Run the following command: ``` grep 'MyWord>' * ``` ## Showing Specified File Names With this – l command we can see all files that end without specified name. In this case .myfile. You could accomplish this with the following command: ``` grep -l 'main' *.myfile ``` ## Showing Line Numbers With the -n command, we can view all of the numbers in lines of the specified words that the error appeared. ``` grep -n MyWord lg Myfile ``` ## Recursive Search With the -R command, you will be able to see all files in any directories and subdirectories. ``` grep -R store* ``` ## To View a File With the –color command, you could also search for a specific word and display it in color for easy reading. ``` grep --color MyWord MyFile.txt ``` Congratulations! This completes this tutorial on GREP Commands. We hope that you found this information useful just like it was to me.  Thank you for following along! Check back with us for further updates and try any of our [top VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. --- # Cloud hosting is an IT Skeleton Key for Developers > URL: https://www.atlantic.net/vps-hosting/cloud-it-skeleton-key-for-developers/ | Published: 2015-09-04 | Updated: 2026-03-02 | Author: Alexander Wise ## **Developers Hold the Keys to the Kingdom** Since innovation is so fundamental to success in today’s rapidly evolving economy, developers have an incredibly important role, creating the digital roadways to be traversed by consumers, businesses, and the public sector. Developers may seem to be a tiny population, but there are actually 18.5 million people who are employed in development, wrote Megan Swanson in *Wired*. “In a sign of the growing recognition of the value of developers,” [she said](http://www.wired.com/insights/2014/12/developers-hold-the-keys-to-unlocking-the-cloud/), “President Obama recently became the first sitting president to write a line of computer code, as part of the Hour of Code Campaign during Computer Education Week.” One major role in technology that makes coders’ lives easier is the meteoric rise of cloud computing. The many benefits of cloud for developers are generally explored below. First though, let’s look at the use of cloud specifically by enterprise developers. ## **How Cloud Benefits Enterprise Developers** In recent years, cloud computing became more and more prevalent throughout the business world but was more common in some segments than others.  [Virtual private server hosting](https://www.atlantic.net/vps-hosting/)was widely used by startups and by consumer-focused websites, but many enterprises were hesitating about transitioning to the cloud into 2014. In 2014, *Gigaom* released its survey of more than 400 IT executives in development roles at enterprises. The IT participants were asked several questions about software development at their organizations, especially related to the cloud. The results of the poll suggests that enterprises that were active with cloud had lower time-to-market and were more productive. It makes sense that cloud would have tangible benefits for enterprises. The flexibility of setting up cloud infrastructure and easily adapting to larger volumes of traffic is driving enterprises to embrace a technology favored by startups for its speed and agility. One finding of the *Gigaom* report was that *waiting* was costing enterprises a lot of money. According to the survey, waiting for infrastructure to be established usually took up a quarter of the time-to-market for a new application or environment. **“**With the majority of projects being longer than six months,” [said Ryan Shriver in *Gigaom*](http://research.gigaom.com/report/survey-enterprise-development-in-the-cloud/), “reducing time to market by developing in the cloud could shave weeks off project schedules while also saving hundreds of thousands of dollars.” This huge cash savings is assuming that cloud computing does save people time. The majority of the enterprise developers surveyed (53%) said that cloud was, in fact, resulting in better time-to-market and more substantial output. That majority of enterprise users said that they were completing projects three weeks faster than the typical timeframe (as established by an average of all developers polled). In June 2014, when the *Gigaom*report was released, just one in five enterprises (21%) had adopted cloud for development – despite the effectiveness, as described above. Enterprise use of the cloud got a huge boost late last year, though, when General Electric revealed that it was using the cloud for nine out of every ten new applications. When asked how much of computing at General Electric was performed through a public cloud, IT head Chris Drumgoole said the enterprise was currently making a huge push toward cloud adoption organization-wide. “It’s multiple millions of dollars in terms of annual spend,” Drumgoole told Eric Knorr of *InfoWorld*. “If you look at our new apps, north of 90 percent of what we deployed this year has gone into a public cloud environment.” ## **General Strengths for Development** The reason that General Electric is turning to the cloud for its application needs is similar to the reasons many other organizations have done the same. Cloud infrastructures allow developers immediate access to IT resources with a credit card. Unlike physical computing models, the cloud is without limitation essentially,  so developers can immediately get more resources at a moment’s notice to perform testing or work with huge datasets on-the-fly. Things didn’t use to be nearly so easy. In the legacy architecture world, the difficulty of getting programs to work with individual networks and servers created many development headaches. The task of figuring out each individual type of hardware and creating code that would work well for all elements of the infrastructure took time away from developers that could have been used to create better functionality. Now, that time is available. Another major trend that is typical with cloud computing environments as well is the use of open software, said Swanson. “Sharing the code … and contributing to debugging and troubleshooting means that individual developers can spend more effort on applications,” she explained. “This gives developers flexibility if they decide they want to change from one hosting company to another.” ## **Developer-Friendly Cloud** Are you looking for a developer-friendly cloud server hosting company? That’s our specialty at Atlantic.Net. Pay as you go, with per-second billing, and access [one-click VPS hosting applications.](https://www.atlantic.net/vps-hosting/) Cloud server hosting services are only one of our offerings – we also offer dedicated hosting, managed hosting, and HIPAA-compliant hosting. --- # How to Install Apache Web Server on Debian 12 > URL: https://www.atlantic.net/vps-hosting/how-to-install-apache-web-server-on-debian-12/ | Published: 2015-09-05 | Updated: 2026-03-03 | Author: Alexander Wise ## Introduction Apache HTTP Server is the most widely used open-source web server on the internet. It is known for its stability, flexibility, and ability to serve both static and dynamic web content. Apache supports a wide range of modules, making it highly customizable for different web hosting needs. In this tutorial, you will learn how to install and configure the Apache webserver on Debian 12. ## Step 1 – Install Apache Apache is available in the default Debian 12 repositories, so you can install it quickly using the APT package manager. 1. First, update your local package index to ensure you are installing the latest version available. ``` apt update -y ``` 2. Install the Apache web server. ``` apt install apache2 -y ``` This will download and install the Apache webserver along with its required dependencies. 3. After installation, confirm that Apache is installed correctly by checking its version. ``` apachectl -v ``` Output. ``` Server version: Apache/2.4.57 (Debian) ``` 4. By default, Apache starts automatically after installation. To verify, open your web browser and visit your server’s public IP address. ``` http://YOUR-SERVER-IP ``` If Apache is running, you should see the Apache2 Debian Default Page, which confirms that the web server is working properly. ![](https://www.atlantic.net/wp-content/uploads/2015/09/apache.png) ## Step 2 – Manage the Apache System Service On Debian 12, Apache runs as a systemd service, which means you can control it using the systemctl command. This gives you full control to start, stop, restart, or reload Apache whenever needed. 1. Enable the Apache service to start at boot. ``` systemctl enable apache2 ``` 2. If Apache is not already running, start the service manually. ``` systemctl start apache2 ``` 3. Verify that Apache is running correctly. ``` systemctl status apache2 ``` Output. ``` ● apache2.service - The Apache HTTP Server Loaded: loaded (/lib/systemd/system/apache2.service; enabled; preset: enabled) Active: active (running) since Sat 2025-09-06 08:53:59 UTC; 5s ago Docs: https://httpd.apache.org/docs/2.4/ Process: 16367 ExecStart=/usr/sbin/apachectl start (code=exited, status=0/SUCCESS) Main PID: 16371 (apache2) Tasks: 6 (limit: 4642) Memory: 12.7M CPU: 83ms CGroup: /system.slice/apache2.service ├─16371 /usr/sbin/apache2 -k start ├─16372 /usr/sbin/apache2 -k start ├─16373 /usr/sbin/apache2 -k start ├─16374 /usr/sbin/apache2 -k start ├─16375 /usr/sbin/apache2 -k start └─16376 /usr/sbin/apache2 -k start ``` If you see active (running), Apache is working properly. 4. To stop the Apache service, run. ``` systemctl stop apache2 ``` 5. Restart Apache when you make configuration changes. ``` systemctl restart apache2 ``` 6. If you’ve made changes that don’t require a full restart, reload Apache to apply them without interrupting connections. ``` systemctl reload apache2 ``` ## Step 3 – Create a new Apache Virtual Host Apache uses virtual hosts to serve multiple websites from a single server. Each virtual host configuration specifies a domain name, document root, and log files for a website. By default, Apache serves a test page from /var/www/html, but you can create your own custom configuration. 1. First, disable the default configuration to avoid conflicts. ``` a2dissite 000-default.conf ``` 2. Create a new configuration file for your domain (replace apache.example.com with your actual domain). ``` nano /etc/apache2/sites-available/apache.example.com.conf ``` Add the following configuration: ``` ServerAdmin admin@apache.example.com ServerName apache.example.com ServerAlias apache.example.com DocumentRoot /var/www/apache.example.com DirectoryIndex index.php index.html ErrorLog ${APACHE_LOG_DIR}/apache.example.com-error.log CustomLog ${APACHE_LOG_DIR}/apache.example.com-access.log combined ``` **Explanation:** - **ServerName** – The domain name for your site. - **DocumentRoot** – The directory containing your website files. - **ErrorLog** & **CustomLog** – Separate logs for easier troubleshooting. 3. Before enabling the new site, test for syntax errors. ``` apache2ctl configtest ``` If everything is fine, you’ll see: ``` Syntax OK ``` 4. Activate the new Apache virtual host. ``` a2ensite apache.example.com ``` 5. Now, create the directory to store your website files. ``` mkdir /var/www/apache.example.com ``` 6. Set proper ownership and permissions. ``` chown -R www:www /var/www/apache.example.com chmod -R 755 /var/www/apache.example.com ``` 7. Create a sample index.html file inside your web root. ``` nano /var/www/apache.example.com/index.html ``` Insert the following HTML: ``` Greetings from Atlantic.Net

Greetings from Atlantic.Net

``` 8. Restart Apache to apply the changes. ``` systemctl restart apache2 ``` 9. Access your domain in a web browser window and verify that Apache serves your index.html page. You should see the **“Greetings from Atlantic.Net”** message, which confirms your virtual host is working. ## Step 4 – Secure the Apache Web Server By default, Apache serves websites over HTTP (port 80), which is not encrypted. To protect user data and secure communication, you can enable HTTPS (port 443) using a free SSL certificate from Let’s Encrypt. We’ll use Certbot to automatically request, install, and configure the certificate for Apache. 1. Certbot is easiest to install using Snap. First, install Snapd. ``` apt install snapd -y ``` 2. Now install Certbot with Snap. ``` snap install certbot --classic ``` 3. Verify installation. ``` certbot --version ``` 4. Request and install an SSL certificate for your domain (replace with your domain and email). ``` certbot --apache -d apache.example.com -m admin@example.com --agree-tos ``` If successful, you will see the output below. ``` Account registered. Requesting a certificate for apache.example.com Successfully received certificate. Certificate is saved at: /etc/letsencrypt/live/apache.example.com/fullchain.pem Key is saved at: /etc/letsencrypt/live/apache.example.com/privkey.pem This certificate expires on 2025-012-06. These files will be updated when the certificate renews. Certbot has set up a scheduled task to automatically renew this certificate in the background. Deploying certificate Successfully deployed certificate for apache.example.com to /etc/httpd/conf.d/apache.example.com-le-ssl.conf Congratulations! You have successfully enabled HTTPS on https://apache.example.com ``` 5. Let’s Encrypt certificates expire every 90 days. Certbot handles renewals automatically, but you can test it with: ``` certbot renew --dry-run ``` If the test passes, your SSL renewal is working correctly. 6. Visit your domain in a new web browser using HTTPS URL **https://apache.example.com.** You should see your website load with a padlock icon, confirming that SSL is active. ## Conclusion In this tutorial, you installed and configured the Apache web server on Debian 12. With this setup, your Debian 12 server is now ready to host websites securely. You can expand this configuration to host multiple domains, add PHP or other application support, and fine-tune Apache for production workloads. --- # How to Install Nginx Webserver on Debian 12 > URL: https://www.atlantic.net/vps-hosting/how-to-install-nginx-on-debian-12/ | Published: 2015-09-05 | Updated: 2026-03-03 | Author: Alexander Wise ## Introduction Nginx (pronounced Engine-X) is a lightweight, high-performance web server that is also commonly used as a reverse proxy, load balancer, and caching server. It is known for handling thousands of concurrent connections while using fewer resources compared to other web servers like Apache. Because of its scalability and speed, Nginx powers some of the busiest websites in the world, including services like Netflix, Dropbox, and WordPress.com. In this tutorial, you will learn how to install and configure the Nginx webserver on Debian 12 (Bookworm). ## Step 1 – Install Nginx Nginx is available in the default Debian 12 package repositories, so installation is straightforward with the APT package manager. 1. Before installing, update your system’s package list to ensure you have the latest version available. ``` apt update -y ``` 2. Run the following command to install Nginx. ``` apt install nginx -y ``` This will download and install the Nginx web server and its dependencies. 3. After installation, check the installed version of Nginx with: ``` nginx -v ``` Output. ``` nginx version: nginx/1.22.1 ``` 4. By default, Nginx starts automatically after installation. To confirm that it is working, open your browser and visit your server’s IP address. ``` http://YOUR-SERVER-IP ``` If Nginx is running properly, you will see the Nginx default welcome page, confirming that the installation was successful. ![](https://www.atlantic.net/wp-content/uploads/2015/09/nginx.png) ## Step 2 – Manage the Nginx System Service On Debian 12, Nginx runs as a systemd service, which means you can control it using the systemctl command. This allows you to enable, start, stop, restart, or check the status of the Nginx web server. 1. Enable Nginx to start after the system reboot. ``` systemctl enable nginx ``` 2. Start the Nginx service. ``` systemctl start nginx ``` 3. Verify that Nginx is running. ``` systemctl status nginx ``` Output. ``` ● nginx.service - A high performance web server and a reverse proxy server Loaded: loaded (/lib/systemd/system/nginx.service; enabled; preset: enabled) Active: active (running) since Sat 2025-09-06 08:36:22 UTC; 8min ago Docs: man:nginx(8) Process: 16285 ExecStartPre=/usr/sbin/nginx -t -q -g daemon on; master_process on; (code=exited, status=0/SUCCESS) Process: 16286 ExecStart=/usr/sbin/nginx -g daemon on; master_process on; (code=exited, status=0/SUCCESS) Main PID: 16287 (nginx) Tasks: 3 (limit: 4642) Memory: 2.4M CPU: 18ms CGroup: /system.slice/nginx.service ├─16287 "nginx: master process /usr/sbin/nginx -g daemon on; master_process on;" ├─16288 "nginx: worker process" └─16289 "nginx: worker process" ``` 4. Stop the Nginx service. ``` systemctl stop nginx ``` 5. If you make configuration changes, restart Nginx to apply them. ``` systemctl restart nginx ``` ## Step 3 – Create a New Nginx Virtual Host Nginx uses server blocks (similar to Apache virtual hosts) to host multiple websites on a single server. Each server block defines the domain name, root directory, and configuration for a specific website. 1. Create a configuration file for your domain (replace nginx.example.com with your actual domain). ``` nano /etc/nginx/conf.d/nginx.example.com.conf ``` Add the following content: ``` server { listen 80; listen [::]:80; server_name nginx.example.com; root /var/www/html/nginx.example.com; index index.html; location / { try_files $uri $uri/ =404; } } ``` **Explanation:** - **server_name:** The domain name for the site. - **root:** The directory where your website files will be stored. - **index:** The default page to serve. - **location:** Handles requests and returns a 404 if the file doesn’t exist. 2. Create the document root for your new site. ``` mkdir -p /var/www/html/nginx.example.com ``` 3. Create an index.html file inside your document root. ``` nano /var/www/html/nginx.example.com/index.html ``` Insert the following content. ```

Greetings from Atlantic.Net

``` The above HTML web application displays a **Greetings from Atlantic.Net** message when you access it in a web browser. 4. Change ownership of the web root to the Nginx user (www-data). ``` chown -R www-data:www-data /var/www/html/nginx.example.com ``` 5. Check for syntax errors before restarting Nginx. ``` nginx -t ``` Output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` 6. Restart the Nginx to apply the changes. ``` systemctl restart nginx ``` Now visit your domain on a web browser and verify that your web application displays. ``` http://nginx.example.com ``` You should see the message: ``` Greetings from Atlantic.Net ``` This confirms your virtual host is working correctly. ## Step 4 – Secure the Nginx Webserver By default, Nginx only serves websites over HTTP (port 80), which is not secure because traffic is unencrypted. To protect your website, you can use a free Let’s Encrypt SSL certificate that enables HTTPS (port 443). 1. Install Certbot and Nginx plugin. ``` apt install python3-certbot-nginx certbot -y ``` 2. Request an SSL certificate for your domain (replace nginx.example.com with your domain name, and update the email). ``` certbot --nginx -d nginx.example.com -m admin@example.com --agree-tos ``` **Explanation.** - **–nginx:** Automatically edits your Nginx config for SSL. - **-d:** Specifies the domain name. - **-m:** Email address for renewal notices. - **–agree-tos:** Accepts Let’s Encrypt terms of service. If successful, Certbot will update your Nginx configuration and reload the service. 3. Let’s Encrypt certificates are valid for 90 days, but Certbot can renew them automatically. Test the renewal process with: ``` certbot renew --dry-run ``` This simulates renewal without making changes. 4. Restart Nginx to apply all SSL settings. ``` systemctl restart nginx ``` 5. Open your browser and visit your domain using HTTPS. ``` https://nginx.example.com ``` If everything is configured correctly, you’ll see your test web page with a secure padlock icon in the browser address bar. ## Conclusion In this guide, you installed and configured the Nginx web server on Debian 12. With this setup, your Debian 12 server is ready to host websites and web applications securely. You can now expand this configuration to support multiple domains, optimize performance, or integrate with backend applications. --- # How to Install Linux, Apache, MySQL, PHP (LAMP) on Debian 12 > URL: https://www.atlantic.net/vps-hosting/how-to-install-lamp-on-debian-12/ | Published: 2015-09-05 | Updated: 2026-01-09 | Author: Alexander Wise ## Introduction A LAMP stack is one of the most widely used open-source platforms for building and deploying dynamic websites and web applications. The term LAMP stands for: - **Linux** – the operating system - **Apache** – the web server - **MySQL** – the database server - **PHP** – the scripting language Together, these components create a powerful environment for running popular applications such as WordPress, Joomla, Drupal, phpMyAdmin, and many custom-built PHP applications. In this guide, you will learn how to install and configure the LAMP stack on Debian 12 (Bookworm). ## Step 1 – Install Apache Webserver Apache is the most popular open-source web server and is available in the default Debian 12 repositories. We’ll install Apache, start the service, and verify that it is running. 1. Install the Apache web server package. ``` apt install apache2 -y ``` 2. After the installation, check the installed version of Apache. ``` apachectl -v ``` Output. ``` Server version: Apache/2.4.57 (Debian) ``` 3. Now, start the Apache service and enable it to launch automatically at boot. ``` systemctl start apache2 systemctl enable apache2 ``` 4. Confirm that Apache is running properly by checking its status. ``` systemctl status apache2 ``` Output. ``` ● apache2.service - The Apache HTTP Server Loaded: loaded (/lib/systemd/system/apache2.service; enabled; preset: enabled) Active: active (running) since Fri 2025-09-05 13:00:39 UTC; 1s ago Docs: https://httpd.apache.org/docs/2.4/ Process: 11875 ExecStart=/usr/sbin/apachectl start (code=exited, status=0/SUCCESS) Main PID: 11879 (apache2) Tasks: 6 (limit: 4642) Memory: 12.5M CPU: 85ms CGroup: /system.slice/apache2.service ├─11879 /usr/sbin/apache2 -k start ├─11880 /usr/sbin/apache2 -k start ├─11881 /usr/sbin/apache2 -k start ├─11882 /usr/sbin/apache2 -k start ├─11883 /usr/sbin/apache2 -k start └─11884 /usr/sbin/apache2 -k start ``` ## Step 2- Install MySQL MySQL is a popular open-source relational database management system (RDBMS) used to store and manage data for web applications. Since MySQL is not included in the default Debian 12 repositories, we need to add the MySQL APT repository first, then install the server. 1. Download the MySQL APT repository configuration package. ``` wget https://dev.mysql.com/get/mysql-apt-config_0.8.34-1_all.deb ``` 2. Install the downloaded package. ``` apt install ./mysql-apt-config_0.8.34-1_all.deb ``` During installation, you will see a configuration screen. Select MySQL Server & Cluster option. ![](https://www.atlantic.net/wp-content/uploads/2015/09/l1.png) Use the arrow keys to select your preferred MySQL version (for example, mysql-8.4-lts). ![](https://www.atlantic.net/wp-content/uploads/2015/09/l2.png) Press Enter, then select Ok to save changes. ![](https://www.atlantic.net/wp-content/uploads/2015/09/l3.png) 3. After adding the repository, update your package list. ``` apt update -y ``` 4. Now install MySQL server. ``` apt install mysql-server -y ``` During installation, you will be prompted to set a password for the root database user. Enter a strong password and press Enter. 5. Check the installed version. ``` mysql --version ``` Output. ``` mysql Ver 8.4.6 for Linux on x86_64 (MySQL Community Server - GPL) ``` 6. Start MySQL and enable it to run automatically on system boot. ``` systemctl enable mysql systemctl start mysql ``` 7. Verify the MySQL service status. ``` systemctl status mysql ``` output. ``` ● mysql.service - MySQL Community Server Loaded: loaded (/lib/systemd/system/mysql.service; enabled; preset: enabled) Active: active (running) since Fri 2025-09-05 12:44:43 UTC; 19s ago Docs: man:mysqld(8) http://dev.mysql.com/doc/refman/en/using-systemd.html Main PID: 2175 (mysqld) Status: "Server is operational" Tasks: 35 (limit: 4642) Memory: 427.5M CPU: 852ms CGroup: /system.slice/mysql.service └─2175 /usr/sbin/mysqld ``` 8. Secure the MySQL installation. ``` mysql_secure_installation ``` Enter the root database user password you set earlier. ``` Enter password for user root: ``` Enter Y when prompted to setup the VALIDATE PASSWORD component. ``` VALIDATE PASSWORD COMPONENT can be used to test passwords and improve security. It checks the strength of password and allows the users to set only those passwords which are secure enough. Would you like to setup VALIDATE PASSWORD component? Press y|Y for Yes, any other key for No: Y ``` Set the preferred password strength policy for your MySQL database server. For example, enter 2 to enable the use of strong passwords on your server. ``` There are three levels of password validation policy: LOW Length >= 8 MEDIUM Length >= 8, numeric, mixed case, and special characters STRONG Length >= 8, numeric, mixed case, special characters and dictionary file Please enter 0 = LOW, 1 = MEDIUM and 2 = STRONG: 2 ``` Enter N when prompted to change the root database user password, or enter Y to change the password. ``` Using existing password for root. Estimated strength of the password: 50 Change the password for root ? ((Press y|Y for Yes, any other key for No) : N ``` Enter Y when prompted to remove anonymous users on your MySQL database server. Enter Y when prompted to disallow remote login for the root user. Enter Y when prompted to remove the test database from your MySQL database server. Enter Y to reload the MySQL privileges table and apply all configuration changes. ## Step 3 – Install PHP PHP (Hypertext Preprocessor) is a widely used scripting language designed for creating dynamic web pages and applications. In the LAMP stack, PHP works with Apache to serve dynamic content and connects with MySQL to manage data. 1. Install PHP and the PHP FastCGI Process Manager (PHP-FPM). ``` apt install php php-fpm -y ``` 2. Install additional PHP modules. ``` apt install php-mysql php-cli libapache2-mod-php -y ``` 3. Check the installed version of PHP. ``` php -v ``` Output. ``` PHP 8.2.29 (cli) (built: Jul 3 2025 16:16:05) (NTS) Copyright (c) The PHP Group Zend Engine v4.2.29, Copyright (c) Zend Technologies with Zend OPcache v8.2.29, Copyright (c), by Zend Technologies ``` 4. Now, start the PHP-FPM service and enable it to run automatically on system boot. ``` systemctl start php8.2-fpm systemctl enable php8.2-fpm ``` 5. Verify that PHP-FPM is running. ``` systemctl status php8.2-fpm ``` Output. ``` ● php8.2-fpm.service - The PHP 8.2 FastCGI Process Manager Loaded: loaded (/lib/systemd/system/php8.2-fpm.service; enabled; preset: enabled) Active: active (running) since Fri 2025-09-05 12:49:24 UTC; 12min ago Docs: man:php-fpm8.2(8) Process: 11836 ExecStartPost=/usr/lib/php/php-fpm-socket-helper install /run/php/php-fpm.sock /etc/php/8.2/fpm/pool.d/www.conf 82 (code=exited, status=0/SUCCESS) Main PID: 11833 (php-fpm8.2) Status: "Processes active: 0, idle: 2, Requests: 1, slow: 0, Traffic: 0.00req/sec" Tasks: 3 (limit: 4642) Memory: 10.1M CPU: 118ms CGroup: /system.slice/php8.2-fpm.service ├─11833 "php-fpm: master process (/etc/php/8.2/fpm/php-fpm.conf)" ├─11834 "php-fpm: pool www" └─11835 "php-fpm: pool www" ``` ## Step 4 – Configure PHP-FPM PHP-FPM (FastCGI Process Manager) is designed to handle PHP processes more efficiently than the traditional mod_php module. It allows Apache to process dynamic PHP files via the proxy_fcgi module. In this step, we’ll configure PHP-FPM and integrate it with Apache. 1. Enable the Apache proxy_fcgi module. ``` a2enmod proxy_fcgi ``` 2. Check if PHP-FPM is listening on its Unix socket. ``` ss -pl | grep php ``` Output. ``` u_str LISTEN 0 4096 /run/php/php8.2-fpm.sock 30695 * 0 users:(("php-fpm8.2",pid=11835,fd=10),("php-fpm8.2",pid=11834,fd=10),("php-fpm8.2",pid=11833,fd=8)) ``` This confirms that PHP-FPM is active and ready to process PHP requests. 3. Enable the PHP-FPM configuration for Apache. ``` a2enconf php8.2-fpm ``` This links Apache with the PHP-FPM socket. 4. To apply the changes, restart both Apache and PHP-FPM. ``` systemctl restart apache2 systemctl restart php8.2-fpm ``` ## Step 5 – Configure Apache With PHP-FPM Now that PHP-FPM is running and connected with Apache, we need to configure Apache to serve PHP files correctly. This is done by creating a Virtual Host configuration and linking it with PHP-FPM. 1. Create a new Apache virtual host. ``` nano /etc/apache2/sites-available/lamp.conf ``` Add the following content. ``` ServerAdmin webmaster@lamp.example.com ServerName lamp.example.com DocumentRoot /var/www/html DirectoryIndex index.html index.php Options Indexes FollowSymLinks AllowOverride All Require all granted SetHandler "proxy:unix:/run/php/php8.2-fpm.sock|fcgi://localhost/" ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined ``` **Explanation:** - **ServerName** – Replace lamp.example.com with your server’s domain name or IP. - **DocumentRoot** – Points to the web root directory /var/www/html. - **FilesMatch** – Ensures all .php files are processed by PHP-FPM. 2. Disable Apache’s default site and enable the new configuration. ``` a2dissite 000-default a2ensite lamp ``` 3. Check for syntax errors before restarting Apache. ``` apachectl configtest ``` Output. ``` Syntax OK ``` 4. Apply the changes by restarting Apache. ``` systemctl restart apache2 ``` 5. Create a PHP configuration file inside the web root. ``` echo "" | tee /var/www/html/index.php ``` 6. Now open a web browser and visit the below URL. ``` http://lamp.example.com/index.php ``` You should see the PHP information page showing PHP version, configuration, and enabled modules. This confirms that Apache is working with PHP-FPM. ![](https://www.atlantic.net/wp-content/uploads/2015/09/l5.png) ## Conclusion In this tutorial, you learned how to set up the complete LAMP stack on Debian 12. You installed Apache to serve web content, configured MySQL as the database engine, and set up PHP with PHP-FPM to handle dynamic requests efficiently. You then integrated Apache with PHP-FPM and confirmed the configuration by creating a simple phpinfo() test page. With this setup, your Debian 12 server is now capable of hosting dynamic web applications powered by PHP and MySQL. You can start deploying projects such as WordPress, Joomla, or even custom-built PHP applications by placing them in your web root or creating additional Virtual Hosts. --- # How to Set Up Debian 8.2 Server > URL: https://www.atlantic.net/vps-hosting/how-to-initial-debian-8-setup/ | Published: 2015-09-05 | Updated: 2026-07-23 | Author: Alexander Wise ## Introduction This how-to will help you with your initial setup on Debian 8.2 so that you can successfully secure your server while giving you the peace of mind knowing your server is protected. With any server, the primary goal should always be security. Many users are victims of malicious infiltrations on their servers due to the lack of security boundaries established from the beginning. Let us begin on the right path by laying our foundation with security. ## What Do You Need? You need a Debian 8.2 server that is configured with a static IP address. If you do not have a server already, you can visit our [virtual private server](https://www.atlantic.net/vps-hosting/) page  and spin a new server up in under 30 seconds. ## Server Preparation To get started, log in to your Debian 8.2 via SSH or the VNC Console in cloud.atlantic.net. Atlantic.Net Cloud servers are setup as minimal installations in order to avoid having unnecessary packages from being installed and never used.  Because of this, let’s make sure that your server is fully up-to-date and the sudo service is installed. ``` apt-get update ``` ``` apt-get install sudo ``` With the server up-to-date, we can continue the process and secure your server. ## Update Root Password on Debian 8.2 **Update the Root Password** as you will be the only person who will know it. We recommend a minimum of 8 characters, including lowercase, uppercase, and numbers. ``` passwd ``` ## Create a new user withsudo privileges on Debian 8.2 **Creating a new user** with sudo privileges will allow you to easily manage your server without having to worry about accidentally making unwanted changes. Let us create the **user1!** ``` adduser user1 ``` Fill in the information that applies to the user and confirm the information ``` root@JVHServer:~# adduser user1 Adding user `user1' ... Adding new group `user1' (1000) ... Adding new user `user1' (1000) with group `user1' ... Creating home directory `/home/user1' ... Copying files from `/etc/skel' ... Enter new UNIX password: Retype new UNIX password: passwd: password updated successfully Changing the user information for user1 Enter the new value, or press ENTER for the default Full Name []: user1 Room Number []: Work Phone []: Home Phone []: Other []: Is the information correct? [Y/n] y ``` In Debian 8.2 by simply adding your user to the sudo group, will grant sudo privileges for that user by typing sudo before running any command. Let us add the user are to the sudo group. ``` adduser user1 sudo ``` ![ID8S-1](https://www.atlantic.net/wp-content/uploads/2018/01/deb1-1.jpg) Upon completion, you can use the su – user1 command to change the user from root to user1. It is important to remember that you will then have to use sudo before running any command with the user. ## Configure SSH Access on Debian 8.2 In Linux systems port 22 is the default port for remote connections via SSH. By changing the ssh port you will increase the security of your server in preventing brute force attacks and unwanted users from reaching your server(I will use Port 5022 for this tutorial). Open your SSH Configuration file, find the Port line, and change Port 22 to your Custom port Save and exit. ``` sudo nano /etc/ssh/sshd_config ``` `# What ports, IPs and protocols we listen for` ``` Port 22 to 5022 ``` ` ` For your system to update the new settings from the SSH Configuration file, we must restart the sshd service. ``` sudo systemctl restart sshd.service ``` SSH has now been configured to use Port 5022 and if you attempt to login using Port 22, your login will fail. ## Limit Root Access on Debian 8.2 Since we’ve created a new user with root permissions, there’s no need keep the actual root user available and vulnerable over SSH on your server. Let us restrict the root users access to be available on the local server only and granting permission to the new user over SSH. Open the SSH Configuration file, find the PermitRootLogin line and change it from yes to no. ``` sudo nano /etc/ssh/sshd_config ``` ``` PermitRootLogin no ``` For your system to update the new settings in the SSH Configuration file, we must restart the sshd service. ``` sudo systemctl restart sshd.service ``` ## Create a Private SSH Key on Debian 8.2 **Private/Public SSH Keys** are great additional features that increase security in the method a server is accessed. However, it takes a bit more effort to setup. The question is, Is your server worth the extra security? If you would like to implement this security feature and additional measures you can continue with the following steps as well, let us proceed and generate the SSH Key. ``` ssh-keygen ``` If you want to change the location where the SSH Key will be saved,  you can specify it here, if not the default location is OK. Press enter when you are prompted with the following question then enter a passphrase, unless you don’t want one. ``` Enter file in which to save the key (/home/user1/.ssh/id_rsa): ``` You will then see the following information on the screen. ![ISST-1](https://www.atlantic.net/wp-content/uploads/2018/01/deb2-1.jpg) Configuring the SSH Key is crucial, we must copy the full key string to a Word/ Notepad Document. The Key can be viewed in the following location by using the cat command. ``` cat ~/.ssh/id_rsa.pub ``` Copy the SSH key beginning with ssh-rsa and ending with user1@yourserver into your Word/ Notepad document so we can add it to the config file. Once the SSH Key is stored safely, we must make more changes on the server. This is where the sudo privileges for your user1, steps in. ``` su - user1 ``` The directory for the SSH Keys needs limited permissions which only the owner can read, write and execute the file. ``` sudo chmod 700 .ssh ``` Within the SSH directory, a file containing the SSH Key must to be added, simply using your editor (in this case VI) the following location: ``` nano .ssh/authorized_keys ``` Paste the SSH Key then save and exit using the nano format. Finally, we have to limit the privileges of the authorized_keys file that we just created so only owner can read and write. ``` chmod 600 .ssh/authorized_keys ``` We can now verify that the key is working by closing your session and by typing the following in your SSH Console user1@YOUR.IP.ADD.RESS or your servers hostname. This can be accomplished with the following command: ``` ifconfig eth0 | grep inet | awk '{ print $2 }' ``` Furthermore,[you can click “here” to see our How To Generate and Use SSH Keys article.](https://www.atlantic.net/vps-hosting/how-to-generate-use-ssh-key-using-putty/) ## Basic Firewall Rules on Debian 8.2 By default your Atlantic.Net’s Debian 8.2 Server is not loaded with a firewall. However, depending on your preference you may install any of the following: **firewalld, iptables,**etc. In this part, I will be using **Firewalld** which uses the **firewall-cmd**tool in order to configure its rules. We must first install the Firewall service with the following: ``` sudo apt-get install firewalld ``` We must now allow our custom SSH Port that was created earlier in order to access the server publicly. Also, there are several other rules that’s can be used depending the type of server that you wish to deploy. ``` sudo firewall-cmd --permanent --add-port=5022/tcp ``` If you have a web server you may want to allow the following rules so your sites could be accessed over the internet. ``` sudo firewall-cmd --permanent --add-service=http ``` ``` sudo firewall-cmd --permanent --add-service=https ``` If you have a mail server, you may want to allow the following rules if you will be using your server for incoming POP3 settings. Port 110 is the standard port and port 995 is for a more secure connection using SSL. ``` sudo firewall-cmd --permanent --add-service=pop3s ``` Furthermore, you may want to allow the following rules if you will be using your server for outgoing SMTP settings. ``` sudo firewall-cmd --permanent --add-service=smtp ``` Finally, you may want to allow the following rules if you will be using your server with IMAP settings. ``` sudo firewall-cmd --permanent --add-service=imaps ``` Save your work and exit. In order for Firewalld to accept those settings you must restart the firewall. ``` sudo firewall-cmd --reload ``` Your settings will have been saved and you are ready to proceed by verifying all the services/ports that are available by  running the following: ``` sudo firewall-cmd --permanent --list-all ```   ## NTP Time Sync on Debian 8.2 The NTP (Network Time Protocol) is basically used to synchronize the time and date of computers over the network in order to remain accurate and up to date. Let us begin by installing the NTP service (if it hasn’t been installed already) and configure the service to synchronize with their servers. ``` sudo apt-get install ntp ``` Once the NTP service is installed, we need to make sure that the service is ON. ``` sudo /etc/init.d/ntp start ``` Having the service ON , it will automatically synchronize the server’s time information with NTP’s  server. ## Add Swap File on Debian 8.2 A Swap file is simply a small amount of space created on a servers hard drive to simulate Ram. In the event that the server is running low on memory it will look at the hard drive and ease the load tricking the system to think it has more memory. We will set up the swap file on the hard drive to increase the performance of the server just a little bit more. Begin by checking your resources to make sure we can add the file. When you run the following command you will see the percentage space on your Hard drive that is currently being used. ``` df -h ``` When creating a Swap file usually you want to add half of your existing RAM up to 4GB(If you have 1GB of actual Ram then you add a 512MB file). In this part I will be adding a 512MB swap file to the drive. The way that this is calculated is by 1024 x 512MB = 524288 block size. ``` sudo dd if=/dev/zero of=/swapfile bs=1024 count=524288 ``` Now that we have added a swap file, a Swap file area needs to be created in order to proceed. ``` sudo mkswap /swapfile ``` With the Swap file created and the Swap file area added we can go ahead and add permissions to the file so that only the owner can read and write. ``` sudo chown root:root /swapfile ``` ``` sudo chmod 600 /swapfile ``` Now that the swap file has the appropriate permissions we can go ahead and activate the it. ``` sudo swapon /swapfile ``` You can verify your newly added Swap file with the following. ``` sudo swapon -s ``` In order to make the Swap file always active even after a reboot, we must configure it accordingly. ``` sudo nano /etc/fstab ``` Paste the following command at the bottom of the file save your work and exit. ``` /swapfile              swap   swap     defaults     0 0 ``` Finally, verify if your swap file is activated by typing the following command: ``` free -m ``` ## ![ID8S-2](https://www.atlantic.net/wp-content/uploads/2018/01/deb3-1.jpg) ## What Next? You now have a server with a strong security foundation that will give you the peace of mind knowing that your server is protected. You could begin installing any additional software depending the purpose of the server. --- # How to Install WordPress on FreeBSD > URL: https://www.atlantic.net/vps-hosting/how-to-install-wordpress-freebsd/ | Published: 2015-09-08 | Updated: 2026-07-07 | Author: Alexander Wise ##### Verified and Tested 08/31/15 ## Introduction WordPress is a simple blogging system the helped maintain many blogs by making a simple interface that interacts with a database. Now, it has become a one of the most powerful content management systems (CMS) in the web, especially it being a free open source software. In this how-to, we will walk through the Installation of WordPress on a FreeBSD server. ## Prerequisites You need a FreeBSD server that is configured with a static IP address. You will also need to have a FAMP stacked server.[If you haven’t installed FAMP on your server click here](https://www.atlantic.net/vps-hosting/how-to-install-famp-freebsd-cloud-vps-server/) then proceed with this tutorial. ## Installing WordPress With the following command you could find the latest version of WordPress available. ``` pkg search wordpress ``` Once you find the version of WordPress you could install it with the following command: ``` pkg install wordpress-4.3,1 ``` With WordPress installed on your FreeBSD server, we need to move the files over to Apache’s web folder with the following command: ``` mv /usr/local/www/wordpress /usr/local/www/apache24/data/ ``` ## Configuring Apache We will need to make minor changes to the Apache configuration file to allow php files over http. Access the Apache configuration file with the following command: ``` nano /usr/local/etc/apache24/httpd.conf ``` Now, search the mime_module and add the following 2 lines under the TypesConfig etc/apache24/mime.types line. ``` AddType application/x-httpd-php .php AddType application/x-httpd-php-source .phps ``` It is a good idea to change the host name now, although this can be done anytime. ``` echo 'your.ip.add.ress wordpress.yourdomain.tld' >> /etc/hosts ``` Restart Apache so we all the changes to take affect. Do this with the following command: ``` service apache24 restart ``` ## Creating The MySQL Database We will need to create a Database for WordPress to function correctly. Access MySQL with the following command: ``` mysql -u root -p ``` Created the WordPress Database with the following command: ``` CREATE DATABASE wordpress; ``` We will also need to create a user so we can access the Database. This user can be created with the following command replacing mywpuser with your name and replacing ‘password’ with the password you want. ``` CREATE USER mywpuser@localhost IDENTIFIED BY 'password'; ``` We must now give permission for that user to access the WordPress Database. This can be completed with the following command. ``` GRANT ALL PRIVILEGES ON wordpress.* TO mywpuser@localhost; ``` Refresh the privileges in MySQL to make those permissions active. ``` FLUSH PRIVILEGES; ``` Exit your MySQL session with the following command: ``` exit ``` Finally, we need to edit WordPress’s configuration file to specify the database, user and password. Change directories to the WordPress location with the following command: ``` cd /usr/local/www/apache24/data/wordpress ``` Copy the sample configuration file and rename it wp-config.php, with the following command: ``` cp wp-config-sample.php wp-config.php ``` Now edit the Database name ‘wordpress’, ‘mywpuser’ and ‘password’. See the how it looks below: ``` // ** MySQL settings - You can get this info from your web host ** // /** The name of the database for WordPress */ define('DB_NAME', 'wordpress'); /** MySQL database username */ define('DB_USER', 'mywpuser'); /** MySQL database password */ define('DB_PASSWORD', 'password'); ``` Finally, the rest of the installation will be completed via your web browser. Go to your web browser and type your IP address and WordPress just like the command below: ``` http://10.50.2.10/wordpress ``` ![This is the welcome page for WordPress on your browser in FreeBSD](https://www.atlantic.net/wp-content/uploads/2018/01/wp1.png) This is the welcome page for WordPress on your browser in FreeBSD ## What Next? Congratulations! You now have a server with WordPress installed. Thank you for following along and feel free to check back with us for further updates. ## Atlantic.Net Atlantic.Net offers [VPS hosting](https://www.atlantic.net/vps-hosting/) as well as managed hosting services which include a layer of business-essential managed services to your hosting packages. Contact us today for more information. --- # How to: DRBD Replication and Configuration > URL: https://www.atlantic.net/vps-hosting/how-to-drbd-replication-configuration/ | Published: 2015-09-09 | Updated: 2026-03-02 | Author: Alexander Wise ## Introduction This how-to will help walk you through the DRBD replication and configuration process. Distributed Replicated Block Device (DRBD) is a block-level replication between two or more nodes and replaces shared storage by creating a networked mirror. DRBD is used in environments that require systems or data to be Highly Available. ## Prerequisites * Two servers running Debian GNU/Linux Distribution. Other Linux versions will also work, but the installation packages may be different. * Both servers should be cross-connected or have a separate Network Interface for private communication. * Both servers should have the same partitioning. This walkthrough assumes that both systems have a single /dev/sdb device that is going to be used as the DRBD volume. ## Network:**** The first part of the process is ensuring that both nodes can talk to each other. This can be done by configuring both nodes with a static private IP address. You can modify the network interface file directly. Here is an example of the /etc/network/interfaces file of one of our nodes: ``` # network interface settings auto lo iface lo inet loopback iface eth0 inet manual auto eth1 iface eth1 inet static address 10.0.10.10 netmask 255.255.255.0 auto vmbr0 iface vmbr0 inet static address 172.16.10.10 netmask 255.255.255.0 gateway 172.16.10.1 bridge_ports eth0 bridge_stp off bridge_fd 0 ``` In our setup, **host01**is configured to use IP 10.0.10.10, and **host02**is configured to use IP 10.0.10.11. After changing the /etc/network/interfaces file, restart networking or bring up the new interface and ensure both servers can communicate on their new private IP. ## Disk for DRBD: #### **Partitioning** Use parted, where /dev/sdb is the device we want to use: ``` parted /dev/sdb ``` Once done, the below commands will create your first partition on /dev/sdb and be used to make a 100GB volume for our first VM/DRBD device. This partition will be /dev/sdb1. ``` (parted) mkpart primary 0GB 100GB ``` It’s important to note that the sizes listed are the disk locations in Gigabytes. This tells parted to create a new partition at disk size location 0GB through disk size location 100GB. To add a second partition, your starting disk size location about be 100GB, see below: ``` (parted) mkpart primary 100GB 200GB ``` If you want to double-check and review your existing partitions to make sure that you using the right disk size locations, run the following and take a look at the results: ``` (parted) print all Number  Start   End     Size    File system  Name     Flags  1      0GB   100GB   100GB                primary   2      100GB   200GB   100GB                primary   3      200GB   300GB   100GB                primary   4      300GB   400GB   100GB                primary   5      400GB   500GB   100GB                primary ``` ## DRBD configuration: #### **Software installation:** Install the DRBD user tools. On ALL DRBD nodes, run: ``` apt-get update && apt-get install drbd8-utils ```   #### **Prepare DRBD configuration:** Replace /etc/drbd.d/global_common.conf with the following content: ``` global { usage-count no; } common { syncer { rate 30M; verify-alg md5; } handlers { out-of-sync "/usr/lib/drbd/notify-out-of-sync.sh root"; } } ``` #### **Configuring the rate of synchronization:** A good rule of thumb for this value is to use about 30% of the available replication bandwidth or IO. #### **Create a resource configuration file:** Create a new file, /etc/drbd.d/r0.res, on ALL DRBD nodes. ``` resource r1 { protocol C; startup { wfc-timeout 0; # non-zero wfc-timeout can be dangerous degr-wfc-timeout 60; become-primary-on both; } net { cram-hmac-alg sha1; shared-secret "my-secret"; allow-two-primaries; after-sb-0pri discard-zero-changes; after-sb-1pri discard-secondary; after-sb-2pri disconnect; } on host01 { device /dev/drbd1; disk /dev/sdb1; address 10.0.10.10:8001; meta-disk internal; } on host02 { device /dev/drbd1; disk /dev/sdb1; address 10.0.10.11:8001; meta-disk internal; } disk { no-disk-barrier; no-disk-flushes; } } ``` If you start adding additional resources, the following fields will need to be updated in your new resources: ``` resource r1 --> resource r2 ``` ``` device /dev/drbd1; --> device /dev/drbd2 disk /dev/sdb1; --> disk /dev/sdb2 address 10.0.10.10:8001; --> address 10.0.10.10:8002 ``` ``` device /dev/drbd1; --> device /dev/drbd2 disk /dev/sdb1; --> disk /dev/sdb2 address 10.0.10.11:8001; --> address 10.0.10.11:8002 ``` ## Bring DRBD Online: On both servers, start DRBD: ``` /etc/init.d/drbd start ``` Now create the device metadata, also on both nodes: ``` drbdadm create-md r1 ``` Bring the device up, also on both nodes: ``` drbdadm up r1 ``` Now you can check the current status of the new DRBD volume; it should look like this on both nodes: ``` host01:~# cat /proc/drbd version: 8.3.13 (api:88/proto:86-96) GIT-hash: 83ca112086600faacab2f157bc5a9324f7bd7f77 build by root@sighted, 2012-10-09 12:47:51 1: cs:Connected ro:Secondary/Secondary ds:Inconsistent/Inconsistent C r---- ns:0 nr:0 dw:0 dr:0 al:0 bm:0 lo:0 pe:0 ua:0 ap:0 ep:1 wo:b oos:2096348 ``` DRBD has successfully allocated resources and is ready for further configuration. Start the initial synchronization (**only on one node!!!**): ``` drbdadm -- --overwrite-data-of-peer primary r1 ``` Wait until the initial sync is finished (depending on the size and speed, this process can take some time): ``` host01:~# watch cat /proc/drbd ``` Once completed, check that your DRBD starts in Primary/Primary mode. To do this, stop DRBD service on both nodes: ``` /etc/init.d/drbd stop ``` And start again on both nodes: ``` /etc/init.d/drbd start ``` Now, DRBD should be in the Primary/Primary mode: ``` host01:~# cat /proc/drbd version: 8.3.13 (api:88/proto:86-96) GIT-hash: 83ca112086600faacab2f157bc5a9324f7bd7f77 build by root@sighted, 2012-10-09 12:57:41 1: cs:Connected ro:Primary/Primary ds:UpToDate/UpToDate C r----- ns:1192004977 nr:0 dw:1191846322 dr:705864868 al:282022 bm:32 lo:0 pe:0 ua:0 ap:0 ep:1 wo:d oos:0 ``` At this point, you have completed your DRBD setup, and the DRBD resource can be further configured for use as local storage. Thank you for following along, and feel free to check back with us for further updates or check out related articles like [Configuring LVM on DRBD](https://www.atlantic.net/vps-hosting/how-to-configure-lvm-drbd/) in our blog. [VPS hosting](https://www.atlantic.net/vps-hosting/) is just one of Atlantic.Net’s many hosting services offered by Atlantic.Net – We also offer dedicated, managed, and HIPAA-compliant hosting solutions. Contact us today for more information on any of our services! --- # Survey Says: How 267 Developers Use Node.js > URL: https://www.atlantic.net/vps-hosting/how-267-developers-use-node-js/ | Published: 2015-09-09 | Updated: 2026-03-02 | Author: Alexander Wise ## **Why do developers like this runtime environment?** Here are five main reasons why coders like Node.js: 1. It allows you to code in a dynamic language at speeds that far outpace Perl, Python, and Ruby. 2. It supports thousands of simultaneous connections without a major spike in resource consumption. 3. JavaScript is well-designed for event loops. 4. JavaScript is incredibly commonplace, possibly the most widely used development language. 5. The way that Node.js creates consistency between Web server and browser is also essential. “Using JavaScript on a web server as well as the browser reduces the impedance mismatch between the two programming environments,” [says postfuturist on Stack Overflow](http://stackoverflow.com/questions/1884724/what-is-node-js), “which can communicate data structures via JSON that work the same on both sides of the equation.” Another major reason developers turn to Node.js is that there are many, many packages to choose from, all of them allowing installation with a single command, notes Leah Hunter of O’Reilly. Actually, the amount of packages is exploding: - September 2014 – 74,000 - April 2015 – 132,000 - September 2015 – 182,000 ## **Survey: Who are these developers and how are they benefiting?** Now let’s look at the survey, which was [created](https://blog.risingstack.com/what-is-nodejs-used-for-the-2015-nodejs-overview-report/) by Gabor Nagy of Node.js consultancy RisingStack. **Experience & Education** Most users of Node.js are in their late 20s or early 30s (25-34), but that certainly doesn’t mean that they are all rookies. In fact, one in three have been coding for over a decade. In terms of school, just under half of these 267 people had a bachelor’s degree. **Languages Over Last Year** The vast majority of respondents, about 240 of them in both cases, had used both JavaScript (Node.js) and Java during the last 12 months. Meanwhile, PHP was used by about 90 of the developers, followed by just under 50 for both Python and C# / .NET. In terms of tools used in conjunction with Node.js, the top three were Express, Mongo, and MySQL. **Job Satisfaction** Job satisfaction increases based on the amount of time that developers have been working with Node.js. More than half of people who said that they had been using it for 3 to 5 years reported they “love” their jobs, while less than 40% of those who had been using it for less than a year said the same. “Obviously it doesn’t mean that you will automatically love your job if you use Node,” says Nagy, “but it can definitely increase your chances to get a better offer if you know a thing or two about it.” **Day-to-Day Work Lives** Nagy also looked at the typical day-to-day work lives of Node.js programmers. The top five activities currently making up 51 to 75% of developer time are as follows: 1. Programming new features 2. Working on bug fixes 3. Learning additional processes/tools 4. Improving quality/re-factoring (This question also revealed that one in three developers surveyed telecommute.) **Industries Using Node.js** Nagy wanted to know what industries were benefiting from Node.js the most. The top eight were education, government, software products, Web services, healthcare, consulting, manufacturing, and finance. Nagy specifically points out education for explanation since it’s a broad vertical. “[W]e are not talking about universities or colleges here,” he says. “Most of these companies are offering a SaaS platform with recurring billing or making money with direct sales in both B2B and B2C directions.” **Percent of Infrastructure Using Node.js** At this point, Node.js is still at the “dabbling” stage for many organizations. Nagy’s findings reveal that most organizations use it for less than 20% of their infrastructure. However, there aren’t a lot of companies that use it moderately: the second highest response was that it was used for more than 80% of the backend, suggesting that it is typically tested and then adopted system-wide. **Predominant Use** While Node.js has a wide variety of uses, the four main ones among this population are building REST APIs, building real-time services, creating microservices, and tooling. **Reasons for Using** Everyone always talks about speed and cost of any solution, but Nagy points out that, within reason, speed is the real deciding factor. The tope five reasons for using Node.js are: 1. Performance 2. General experimentation 3. Relationship to JavaScript 4. Updates released more regularly 5. Long-term cost savings “[P]erformance is in the first place for a reason,” says Nagy, because speed is simply the top priority when it comes to development. “When Google experimented with displaying a 30 search results instead of 10 with an extra 0.5 seconds loading time,” he recounts, “the site’s traffic dropped by 20%.”  Cloud Hosting is another way to greatly improve speed and efficiency. ## **One-Click Deployment of Node.js** Coders like Node.js for its incredible speed, both because performance is enhanced and because time-to-market is reduced. At Atlantic.Net, we appreciate what a critical factor time is for developers.  That’s why we offer one-click application hosting of Node.js and the best in [VPS Hosting](https://www.atlantic.net/vps-hosting/) to further increase your efficiency and productivity. --- # How to Install FEMP (FreeBSD 10, Nginx, MySQL, PHP) on a Cloud or VPS Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-femp-cloud-vps-server/ | Published: 2015-09-10 | Updated: 2025-03-06 | Author: Alexander Wise ##### Verified and Tested 09/02/15 ### Introduction This how-to will guide you through installing a FEMP stack. FEMP is simply a software bundle that consists of 4 components that work together to form a powerful web server.  However, in this setup the acronym’s are as follows: FreeBSD 10 (**F**) is the core of the platform which will sustain the other components. Nginx (**E**) is used for the web service. MySQL (**M**) is used for database management,  and PHP (**P**) is used as the programming language. ## Install FEMP on FreeBSD 10 To get started, login to your FreeBSD server via SSH or Console. If you are using the Atlantic.Net cloud service, note that they are setup as minimal installations to avoid having unnecessary packages from being installed and never used. If some software packages that you’re used to using aren’t installed by default, feel free to install them as needed. Let us download nano so we can simplify this tutorial. ``` pkg install nano ``` Let’s make sure that your server is fully up-to-date so we can complete the preparation. ``` freebsd-update fetch freebsd-update install ``` With the server up-to-date, we can continue the process and install FEMP on your server. ## Install Nginx on FreeBSD 10 Begin by installing Nginx with the following commands: ``` pkg install nginx ``` ``` Rehash ``` Enable and start the Nginx service with the following commands: ``` sysrc nginx_enable=yes ``` ``` service nginx start ``` You can now verify that Nginx is installed correctly by typing http:// and your IP address on your browser(http://YOUR.IP.ADD.RESS ). To get your servers IP Address enter the following command: ``` ifconfig vtnet0 | grep "inet " | awk '{ print $2 }' ``` ![This is the test page created to verify Nginx was installed correctly in FreeBSD](https://www.atlantic.net/wp-content/uploads/2018/01/femp1.jpg) This is the test page created to verify Nginx was installed correctly in FreeBSD ## Configure Nginx on FreeBSD 10 The first change to the configuration file is to make a backup of the original config, just in case anything ever happens and we want to revert back. We will accomplish this task by moving the file and renaming it nginx.conf.backup. ``` mv /usr/local/etc/nginx/nginx.conf /usr/local/etc/nginx/nginx.conf.backup ``` Now, we create the nginx.conf file with the following command: ``` nano /usr/local/etc/nginx/nginx.conf ``` Paste the following configurations to your empty file then save your session. Note: To simplify our configurations, this file contains the PHP configurations as well. ``` user www; worker_processes 1; error_log /var/log/nginx/error.log info; events { worker_connections 1024; } http { include mime.types; default_type application/octet-stream; access_log /var/log/nginx/access.log; sendfile on; keepalive_timeout 65; server { listen 80; server_name example.com www.example.com; root /usr/local/www/nginx; index index.php index.html index.htm; location / { try_files $uri $uri/ =404; } error_page 500 502 503 504 /50x.html; location = /50x.html { root /usr/local/www/nginx-dist; } location ~ \.php$ { try_files $uri =404; fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_pass unix:/var/run/php-fpm.sock; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $request_filename; include fastcgi_params; } } } ``` After, we will create the log file directory for Nginx and create the empty log files. This will allow the system o store errors and helpful information for troubleshooting. ``` mkdir -p /var/log/nginx ``` Create the access and error log files with the touch command: ``` touch /var/log/nginx/access.log touch /var/log/nginx/error.log ``` By default, Nginx has the web files going to the “nginx-dist” directory via a symbolic link. We must remove that link and point it to the correct location that is the “nginx” directory. ``` rm -rf /usr/local/www/nginx ``` Then remake the directory with the following command: ``` mkdir /usr/local/www/nginx ``` With the link broken/removed and the new directory made, we need to copy the index.html file to the new directory with the following command: ``` cp /usr/local/www/nginx-dist/index.html /usr/local/www/nginx ``` Finally, restart Nginx and the system, so  all the configurations take effect with the following commands: ``` service nginx restart ``` ``` rehash ``` ## Install MySQL on FreeBSD 10 We then would like to continue by installing MySQL. After running the following MySQL, command hit y and then enter to confirm your installation. ``` pkg install mysql55-server ``` Enable and start the MySQL service with the following commands: ``` sysrc mysql_enable=yes ``` ``` service mysql-server start ``` ## Configure MySQL on FreeBSD 10 To ensure the security of the default settings of MySQL, continue with the command below: ``` mysql_secure_installation ``` Note: When prompt with “Enter current password for root” hit enter for none then Y(Yes) to set MYSQL password. You will then be prompted with a series of questions. Just type Y for yes on all of them, see the screen shot below: ![This is the secure installation of screen when installing MySql on a FreeBSD FEMP Stack server.](https://www.atlantic.net/wp-content/uploads/2018/01/femp2.jpg) This is the secure installation of screen when installing MySql on a FreeBSD FEMP Stack server. Restart the MySQL and the system, so  all the configurations take effect with the following commands: ``` service mysql-server restart ``` ``` rehash ``` ## Install PHP on FreeBSD 10 Finally, we will conclude with the FEMP Stack by installing PHP and configuring it to work with Nginx. ``` pkg install php55-mysql php55-mysqli ``` With PHP installed, we can go ahead a begin the preparation to configure it with Nginx. Copy the sample PHP configuration file to the correct location. ``` cp /usr/local/etc/php.ini-production /usr/local/etc/php.ini ``` Enable and start the PHP-FPM service with the following commands: ``` sysrc php_fpm_enable=yes ``` ``` service php-fpm start ``` ## Configure PHP on FreeBSD 10 We will now have to make minor changes to the PHP-FPM configuration. Using your text editor, type the following command to access the configurations. ``` nano /usr/local/etc/php-fpm.conf ``` Locate the line that reads listen = 127.0.0.1:9000 and replace it with the following line, so it listens to php-fpm.sock: ``` #locate listen = 127.0.0.1:9000 #Replace listen = /var/run/php-fpm.sock ``` Then you will need to locate the following lines and uncomment(Remove the semi-colon) from them: ``` listen.owner = www listen.group = www listen.mode = 0660 ``` Go ahead and create the PHP file to make sure that it works with the following command: ``` nano /usr/local/www/nginx/info.php ``` Then insert the following PHP script to the empty info.php file with the following command: ``` ``` Additionally, restart the PHP-FPM, so  all the configurations take effect with the following command: ``` service php-fpm restart ``` Finally, restart Nginx and the system, so  all the configurations take effect with the following commands: ``` service nginx restart ``` ``` rehash ``` You can now verify that PHP is installed correctly by typing the following on your browser. Below is the default page after installing PHP on an FEMP Stack FreeBSD server when viewing the following URL: http://YOUR.IP.ADD.RESS/info.php ![This is the default page after installing PHP on an FEMP Stack FreeBSD server](https://www.atlantic.net/wp-content/uploads/2018/01/femp3.jpg) ## What’s Next? Congratulations! You now have a server with an FEMP Stack platform for your web environment. Thank you for following along and feel free to check back with us for further updates. --- # How to Install RTMP with Nginx on Ubuntu 14.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-rtmp-nginx-ubuntu-14-04/ | Published: 2015-09-11 | Updated: 2026-02-28 | Author: Alexander Wise ##### Verified and Tested 09/3/15 ## Introduction In this how-to we will walk you through the basic installation of an RTMP server using Ubuntu 14.04. RTMP stands for Real Time Messaging Protocol. This protocol has the ability to project or stream live videos, games, images and much more directly from your server and into the internet. ## Prerequisites You need a Ubuntu 14.04 server that is configured with a static IP address. We must make sure that the server is up to date with the following command: ``` sudo apt-get update ``` We will also need unzip which can be installed with the following command: ``` sudo apt-get install unzip ``` ## Installing Nginx for use with RTMP First, we need to get the correct build tools to lay the foundation. They can be installed with the following command: ``` sudo apt-get install build-essential libpcre3 libpcre3-dev libssl-dev ``` Once we have downloaded the build tools we need to begin with the web server. We will be using Nginx and it can be installed with the following command: ``` wget http://nginx.org/download/nginx-1.8.0.tar.gz ``` Now, unpack the tar.gz file that we just downloaded with the following command: ``` tar -zxvf nginx-1.8.0.tar.gz ``` Additionally, we need to install the RTMP module. This can be installed with the following command: ``` wget https://github.com/arut/nginx-rtmp-module/archive/master.zip ``` Now, unzip the module file with the following command: ``` unzip master.zip ``` Once both packages are extracted, let us change our current directory to the Nginx directory with the following command: ``` cd nginx-1.8.0 ``` To complete the installation, we will need to build Nginx with the RTMP module with the following commands: ``` ./configure --add-module=../nginx-rtmp-module-master ``` ``` make ``` ``` sudo make install ``` Finally, to conclude the installation, we must start Nginx so we can verify if there are no errors. Start nginx with the following command: ``` sudo /usr/local/nginx/sbin/nginx ``` Then stop the service with the following command: ``` sudo /usr/local/nginx/sbin/nginx -s stop ``` ## Configure Nginx with RTMP In order for Nginx to fully function with RTMP, we must configure it accordingly. Using you favorite text editor, open up your Nginx configuration file with the following command: ``` nano /usr/local/nginx/conf/nginx.conf ``` Now, since there are so many ways to configure RMTP, we will just cover enough information to get RTMP live and running forwarding the streams to anyone who requests it. Scroll to the bottom of the configuration file and pasted the following code: ``` rtmp { server { listen 1935; chunk_size 4096; application live { live on; record off; } } } ``` Now we must restart Nginx so all the configurations take effect with the following command: ``` sudo /usr/local/nginx/sbin/nginx -s reload ``` ### Additional Configurations At this point, your server is all set up and configured with RMTP. However, to begin  streaming, you can download “[Open Broadcaster Software](https://obsproject.com/)” software free of charge and configure the broadcast settings to the following: ``` Streaming Service: Custom Server: rtmp://your.ip.add.ress/live Play Path/Stream Key: mystreamkey ``` Finally, to request the RTMP, type the following link replacing the information with yours: ``` rtmp://your.ip.add.ress/live/mystreamkey ``` ## What’s Next? Congratulations! This completes our how-to Installing RTMP on Ubuntu 14.04. You are now ready to begin streaming live videos, games, images and much more. Thank you for following along this how-to! Check back with us for further updates. ### Atlantic.Net Atlantic.Net offers [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) services which include a layer of business-essential managed services as part of your hosting package. Contact us today for more information. --- # How to: FreeBSD Network Administration > URL: https://www.atlantic.net/vps-hosting/how-to-freebsd-network-administration/ | Published: 2015-09-14 | Updated: 2026-03-02 | Author: Alexander Wise ##### Verified and Tested 08/18/15 ## Introduction Networks are composed of two or more devices that form one group, and each device is assigned a unique IP, that identifies them to that specific group. In order to keep things organized and protected withing a network, Network Administration is very important. In this how-to we will walk through the Network Administration on a FreeBSD server. ## Prerequisites A FreeBSD server configured with a static IP address. If you do not have a server already,  spin up an Atlantic.Net [reliable SSD Virtual Private Server](https://www.atlantic.net/vps-hosting/). ## Set up your IP address in FreeBSD First of all,  let us look at your current active interface configurations so we can Identify some important settings that make it all work. To see your network configurations type the following command: ``` ifconfig ``` ![This is the output after running the ifconfig command in FreeBSD](https://www.atlantic.net/wp-content/uploads/2018/01/freebsd.jpg) This is the output after running the ifconfig command in FreeBSD Do not be alarmed of all the information that you see on the screen. We will need to identify the following two pieces of important information so we can properly verify and configure a network interface. **Interface:** Usually identified as ethX, our virtualized instance names the interfaces in the above output as **vtnet0** and **vtnet1**. These interfaces are the point of connection between the device and the private or public network that they are connected to.**inet: **This is the IP addressed configured for use on the interface. Above, you can see that IP **10.50.2.10** is configured on interface **vtnet0**. ## Static IP Address in FreeBSD Static IP’s are IP addresses that are assigned to specific devices and will remain assigned until the IP it is removed or changed. Adding a static IP address could be accomplished using two different methods.  You could set the IP so that it holds that address **temporary**, which will then be removed once the device or networking is restarted, or you can assign it permanently. To configure a **temporary** static IP address, you could run the following via command line: ``` ifconfig vtnet0 10.50.2.10 netmask 255.255.255.0 ifconfig vtnet0 10.50.2.10/24 ``` If you would rather **permanently** assign the IP address, you’ll need to make some changes to the network configuration files.  Unlike the temporary one, you could reboot the device, and once it’s turned back on, it will hold the IP address that you specifically assigned to it. Configuring a permanent IP can be done by editing the rc.conf file. First, open the rc.conf file using a text editor with the following command: ``` vi /etc/rc.conf ``` Locate the line that reads “**ifconfig_** “and replace IP address that is there with the one that you want the system to have permanently. Note: This can be done two different ways, depending entirely on your preference for subnet notation: ``` ifconfig_vtnet0="10.50.2.10 netmask 255.255.255.0" ``` or ``` ifconfig_vtnet0="10.50.2.10/24" ``` ## Default Gateway in FreeBSD You will also need to configure the default Gateway for your network interface. The default gateway is the next hop on your network and is typically a router or switch that handles network connectivity and routing. The gateway is usually the first IP address in an IP range which gives you access in and out of the network that it belongs to. Setting the default gateway (called defaultrouter in FreeBSD) is again done by editing the rc.conf file. ``` vi /etc/rc.conf ``` Locate the “**defaultrouter=**” line and adding the Gateway IP address. ``` defaultrouter="10.50.2.1" ```  Alternatively, you could also add a default gateway address with the following command, though this will only be a temporary addition: ``` route add default 10.50.2.1 ``` If you would like to remove the default gateway address, this can be accomplished via with the following command: ``` route delete default ``` ## Dynamic IP Address in FreeBSD Dynamic IP’s are random IP addresses that could be assign or leased to specific devices. They are held by the device for a period then released and then the device would grab another IP. Adding a Dynamic IP address could be accomplished using two different methods.  You could set that device  IP so that it holds that address temporary, which will then be removed once the device is restarted, or you can assign it permanently. To configure a temporary dynamic IP address, you could accomplish this using any one of with the following  command: ``` dhclient vnet0 ```  To set up you system so that it always receives a dynamic IP Addresses, we must configure the system manually. As before, first open the rc.conf file using a text editor with the following command: ``` vi /etc/rc.conf ``` Now, Locate the line that reads “**ifconfig_** “and replace IP address that is there with the DHCP setting that it will permanently have. This should look like the following: ``` ifconfig_vtnet0="DHCP" ``` ## DNS Servers in FreeBSD DNS servers are specific servers with large libraries of registered domains which directs your request when you search a domain in your web browser. These are public servers that can be used by anyone. Google has them available along with many other companies. However, we will be using Atlantic.Net’s name servers so that domain lookup can occur quickly. This can be completed by editing the **“resolv.conf”** file using your text editor with the following command: ``` vi /etc/resolv.conf ``` Add your name servers to the **“resolv.conf”** file using the following lines (each line representing one name server, these are used for Atlantic.Net Cloud Servers.). ``` nameserver 209.208.127.65 nameserver 209.208.25.18 ``` ## What Next? Congratulations! This completes our session on FreeBSD Network Administration. Thank you for following along! Check back with us for further updates and try one of our [top VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. --- # Atlantic.Net Opens their first European Cloud Center in London > URL: https://www.atlantic.net/press-releases/cloud-hosting-provider-continues-rapid-expansion-with-a-sixth-state-of-the-art-facility-in-london/ | Published: 2015-09-15 | Author: Editorial Team ORLANDO, FL – Sept. 15, 2015 – Atlantic.Net announced today the opening of its first international data center in Europe, located in the heart of the U.K. This new London data center, which is the sixth addition to the company’s infrastructure, is owned by Infinity. Customers can now launch cloud servers in less than 30 seconds, backed by SSD storage and 55GBPS infiniband technology. The new facility’s London location is ideal for serving startups and developers in the city, as well as providing an exceptional network and superior upkeep to Atlantic.Net’s large roster of clients in the U.K.’s IT corridor. The building is operated by Infinity, which allows Atlantic.Net to provide fast and flexible support to clients in the U.K. and surrounding countries throughout Europe. “We have seen expediential growth in Europe since we launched our cloud hosting service, and we are simply responding to our customers’ needs by expanding in growth markets. We have a large customer base in the U.K. who will now have better latency with a local data center”, said Marty Puranik, Founder, President, and CEO of Atlantic.Net. “We chose to partner with Infinity due to their world-class network and reputation, and are proud to introduce true cloud service, built to scale, to our growing roster of European clients.” With six data centers spanning the globe, including the U.S., Canada, and U.K., Atlantic.Net is continuing to multiply their reach for customers looking for scalable, reliable and secure hosting with live support 24/7/365. The company plans to continue expanding their geographic diversity with planned development in Asia and has many innovative features in the pipeline. ** About Atlantic.Net** Atlantic.Net is a web hosting provider specializing in offering windows, Linux and FreeBSD cloud server hosting. Atlantic.Net provides developer-friendly cloud hosting with emphasis on one-Click Application Hosting to include LAMP, LEMP, Docker, Node.js and other [one-click applications like WordPress](https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/), with hosting facilities in Silicon valley, New York, Toronto, Dallas and Orlando. With a range of certifications and an SSAE 16 (SOC 1) TYPE II (Formerly SAS 70) audited data center that the company owns and operates, the company is also known for its reliability, as dictated by its 100 percent uptime service-level agreement (SLA). For more information, please visit[www.atlantic.net](https://www.atlantic.net/vps-hosting/). --- # What Is RVM (Ruby enVironment Manager or Ruby Version Manager)? > URL: https://www.atlantic.net/vps-hosting/what-is-rvm-ruby-environment-manager/ | Published: 2015-09-15 | Updated: 2026-03-04 | Author: Alexander Wise ##### ***Target Audience:*** *This article is intended to be useful for anyone who has a need to deploy–or manage–multiple Ruby installations on a single machine. A reader should have a basic understanding of how Ruby and Ruby gems work within an operating system.* ### Introduction Managing multiple Ruby environments can be a challenge. Ruby is an open-source language, so new releases can be frequent, and those releases can introduce drastic functionality changes. Couple this potential with the use of third-party Gems that may depend on functionality within specific Ruby versions, and your application can quickly find itself struggling to meet all of the dependencies it needs just to execute. [RVM](https://rvm.io/) (alternately expanded as Ruby enVironment Manager or Ruby Version Manager) tackles this problem head-on by providing a set of command-line tools that allow you to actively control not only the version of Ruby your application uses but also the Gem sets and versions it uses. Below we’ll discuss what RVM is, touching on each of the benefits that it has to offer. ![Ruby logo](https://www.atlantic.net/wp-content/uploads/2018/01/500px-ruby_logo-svg-300x300-1.png) *Image: [Ruby Logo by Yukihiro Matsumoto, Ruby Visual Identity Team](https://commons.wikimedia.org/wiki/File%3ARuby_logo.svg) / licensed under [CC BY-SA 2.5](https://creativecommons.org/licenses/by-sa/2.5)* ## Managing Multiple Ruby Environments RVM enables you to install multiple versions of the Ruby programming language on a single machine. A native install of the Ruby programming language will install the language’s binaries into a common `bin` directory on the operating system; thus any change to those installed binaries will affect all Ruby applications hosted on the machine. Even relatively minor version increases–such as from 2.1.4 to 2.2.1–can introduce changes to the language that break existing language behavior. . RVM allows you to isolate these language binaries into separately-managed environments, which can be used at-will on your system. It accomplishes this isolation by encapsulating each installation into a separate set of directories and dependencies and providing easy-to-use command line tools to quickly switch between versions. RVM handles swapping out all relevant execution paths, environment variables, and installed third-party libraries, allowing developers to focus on developing their applications instead of managing their dependencies.. ## Why Is RVM Important? For a single small application, RVM may seem to be overkill. However, once a codebase reaches a certain level of complexity, it may be challenging to track exactly which dependencies the application relies on. Furthermore, as an application grows and leverages various Ruby Gems, these third-party libraries may introduce further dependencies, making a simple version change a complex event fraught with peril. For example, the release of version 2.1.0 introduced a [breaking change in the REXML parsers that many Gems use to provide SOAP functionality](https://github.com/ruby/ruby/blob/v2_1_0/NEWS#L250). This consideration is also crucial for [VPS hosted](https://www.atlantic.net/vps-hosting/) web servers, which may host multiple Ruby applications at once (such as a Resque-based delayed job server, a web server built on Rails, and a Sinatra-based admin console). Getting several different applications with several different sets of dependencies behaving properly can be a full-time job by itself. By encapsulating different Ruby language versions into separate environments, RVM allows the developer to test out new versions, deploy existing applications without worrying about breaking changes, and ensure that application infrastructure management takes as little time as possible.. ## Resolving Dependency Conflicts The most obvious benefit gained through the use of RVM is dependency management. By encapsulating the installations of the Ruby programming language into separate command-line-driven environments, you can more easily control version dependencies. RVM, coupled with a Gem management framework like [Bundler](http://bundler.io/), can make language-based dependency conflicts a thing of the past–you simply need to verify that there is a version of the Gem you are working with that is compatible with your current installation. Furthermore, using RVM allows you to be confident that only the Gems you need will be installed. Each Ruby environment managed by RVM has its own set of Gems, and as such there is no cross-contamination between apps that may use Gems that affect the Ruby execution environment itself.. ## Simplifying Deployment In addition to mitigating breaking changes and resolving dependency conflicts, RVM can ease the deployment process for Ruby applications. RVM offers features like “Named Gemsets”, which allow you to quickly and easily specify the dependencies for your Ruby application. Furthermore, Ruby uses a shared cache of gem versions, which reduces the overall disk space used by your Ruby deployment. Finally, RVM works to ensure that all of the specified dependencies are contained entirely within user space, reducing security risks and removing the need to run your application as the root user.. ## Conclusion The above article only scratches the surface of the functionality offered by RVM. By using RVM to manage your application’s environment, you can ease deployment concerns, mitigate upgrade issues, and create a reliable set of dependencies for your Ruby application. Coupled with tools like [Bundler](http://bundler.io/), RVM makes installing, running, and managing a Ruby application a simple and streamlined process. ## Atlantic.Net We offer many one-click [VPS hosted](https://www.atlantic.net/vps-hosting/) install applications which also offer a simple and streamlined process.   We have many popular applications like WordPress, cPanel Hosting and Docker Hosting. . --- # Atlantic.Net announces Cloud Location in London, UK > URL: https://www.atlantic.net/announcements/announcing-london-uk-first-european-cloud-location/ | Published: 2015-09-15 | Updated: 2026-02-28 | Author: Alexander Wise If you need low latency and fast access to the European market, with the same power, speed, and reliability Atlantic.Net is known for, our new London, UK Cloud location has you covered! You can now create and manage fast[SSD Cloud Hosting](https://www.atlantic.net/vps-hosting/)in our London, UK location via the control panel or API. ![Atlantic.Net Announces the First European Cloud Location in London](https://www.atlantic.net/wp-content/uploads/2015/09/London.png) Thanks to all our members who have made this possible and continue to grow with us. With the addition of our London location, members can now deploy [Cloud Servers](https://www.atlantic.net/vps-hosting/)and One-Click Applications in less than 30 seconds in six data center locations including New York, London, Toronto, San Francisco, Dallas, and Orlando. Try our SSD Cloud Hosting [   Signup Now   ](https://cloud.atlantic.net/?page=signup) --- # What Is I2C (Inter-Integrated-Circuit)? > URL: https://www.atlantic.net/vps-hosting/what-is-i2c-inter-integrated-circuit/ | Published: 2015-09-16 | Updated: 2026-01-07 | Author: Alexander Wise ##### ***Target Audience*** *This article assumes that the reader is familiar with basic electronics circuits and terminology.* ## **Introduction** The purpose of this article is to familiarize the reader with the basics of the I2C communications bus, including how it is set up, its physical properties, and where and why it is often used. ## **What Is I2C?** I2C is ordinarily pronounced “I-two-C”, though it is also sometimes written as IIC (and pronounced “I-I-C”) or I2C (pronounced “I-squared-C”). The acronym stands for Inter-Integrated-Circuit. It is a type of serial computer bus and communications protocol that was first introduced to the market by Philips Semiconductor in 1982. I2C is a way of allowing multiple electronic devices (most often low-speed, peripheral integrated circuits) to communicate with each other over a single pair of wires. These wires are also called data lines, or buses. The first of these buses is the data line and is called the SDA (**S**erial **DA**ta) line, and the other bus is the clock, or SCL (**S**erial **CL**ock) line. Since all devices on any I2C circuit are hooked to these two lines to communicate, most I2C-compatible devices have pins labeled SDA and SCL, as well as VIN and GND pins for positive and ground connections. ![I2C diagram](https://www.atlantic.net/wp-content/uploads/2018/01/i2c1.png) ## How Does I2C Work? Both the clock and data buses are open-drain lines. A resistor must be connected between each line and the circuit’s positive voltage supply (also referred to as Vcc) in order for the bus to work correctly. The size of these resistors can vary, from 1 kΩ all the way up to 47 kΩ, but they must be present between the bus and the system’s HIGH voltage. If they are not present, all lines will be pulled low, and the I2C bus will fail to work. Luckily, only one pair of resistors (one for each line) is necessary for the entire system, not a pair for each device–that could quickly get messy with a lot of devices. ### Attaching Devices Quite a few devices (also called nodes) can be attached to these buses. In fact, the number of devices that can practically be connected to any I2C circuit is normally limited only by space, the inherent capacitance of the lines, and the addresses of the connected devices. Most experts agree that this limit falls around 1008 devices. ### Types of Devices in I2C Communications There are two kinds of devices in I2C communications: masters and slaves. In most implementations of the protocol there is one master device connected to many slaves. It is possible to have more than one master communicating with various slave devices as well as other masters, but this form is less common and is a bit beyond the scope of this introduction. Many I2C devices can be configured as either a master or a slave, depending on the desired system results. The master node is the one device that controls the clock (SCL) line, and is the only device that can initiate a data transfer. The slave nodes are limited to listening for and responding to calls from the master node. Each node, including the master, has a unique (normally 7-bit) address that identifies it on the I2C network. In some cases the address can be 10 bits in length, allowing for more than 128 different devices, but this is not a normal setup. During the operation of an I2C system, the master node sends commands and requests on the data line. These signals are 8 bits in length, are only begun when the clock line is HIGH, and are started with a particular ‘start’ sequence and finished with a particular ‘stop’ sequence. The start sequence alerts all connected slave nodes that a data transfer request is imminent. The next sequence the master sends out is the address of the slave with which it wants to communicate. The named slave node then responds to the master, beginning at the next HIGH clock signal, and the other slaves go back to listening for their address to be called. The eighth bit that is sent with the command, after the 7-bit device address, is a simple read/write bit. It tells the addressed device whether the master device will be reading from or writing to it. This allows the receiving device to either prepare data to send or prepare to receive data along the SDA line at the next clock HIGH signal. ### Clock Speed The clock speed (and the associated signal transfers) on most I2C circuits normally falls somewhere between serial communications and SPI speeds, between 100kHz and 400kHz. I2C is commonly used in systems where simplicity, low cost, and low power are more important than speed. Some of these applications include analog-to-digital converters, LCD displays, real-time clocks, and many different sensors such as barometers, compasses, and even GPS receivers. ## I2C Applications I2C is a very useful communications protocol, though it may only be applicable to a small number of applications. It is ideal for small, low-power-consumption settings, and as a result has found a following among many hobbyists, who use it to interface sensors and controls with embedded devices and microcontrollers such as the Arduino and the Raspberry Pi. Two of the Pi’s GPIO pins are preset to interface with devices using the protocol, and the Arduino wire library allows communications with I2C devices. Learning and using I2C can significantly extend a hobbyist’s toolkit when it comes to building projects. ## About Atlantic.Net Atlantic.Net offers [VPS hosting](https://www.atlantic.net/vps-hosting/) as well as managed hosting services which include a layer of business-essential managed services to your hosting packages. Contact us today for more information. --- # Why is Everyone Using Docker? > URL: https://www.atlantic.net/vps-hosting/why-is-everyone-using-docker/ | Published: 2015-09-16 | Updated: 2026-01-07 | Author: Alexander Wise Docker has been a huge focus of IT conversation lately because it both boosts the number of applications you can power with the same servers and simplifies packaging and shipment of apps. *“Docker’s literally incredible. I’ve never been able to setup server networks for clients so quickly.” – [tweet from](https://twitter.com/olivervscreeper/status/623517032382861312)**[ Linux sysadmin Oliver Dunk, Jul 21, 2015](https://twitter.com/olivervscreeper/status/623517032382861312).* Last year, Docker was one of the technologies that really got everyone’s attention, kind of exploding onto the scene with many businesses starting to use it for the first time – including three major financial institutions, according to Docker VP James Turnbull. It’s amazing to think that banks, of all organizations, were willing to adopt version 1.0 of an application since security is so paramount to them. Well, it’s kind of shocking and it kind of isn’t, because the open-source Docker did quickly develop some important relationships – with Redhat, Canonical, and even Microsoft (compelling particularly because Microsoft is, of course, proprietary). ## **Why the Rush to Docker?** What is it that is fundamentally driving everyone to Docker and containers in general? Parallels virtualization chief James Bottomley says that the reason people are switching to Docker has to do with the nature of virtual machine hypervisors. Hypervisors are “based on emulating virtual hardware, [which means] they’re fat in terms of system requirements,” he notes. With containers, operating systems are shared, allowing them to use resources more efficiently. Rather than going the route of virtualization, containers use one Linux instance as their basis. With this tactic, organizations are able to “leave behind the useless 99.9% VM junk,” [explains Bottomley](http://www.zdnet.com/article/what-is-docker-and-why-is-it-so-darn-popular/), “leaving you with a small, neat capsule containing your application.” The impact of this different way of building systems is profound. If you have a container environment that you have configured properly, you can potentially improve the amount of server application instances by 300-500% over KVM or Xen virtual servers. Containers may sound like a revolutionary concept, but they actually aren’t. The technological approach has been around since at least FreeBSD Jails, which first appeared in 2000. Actually,  Steven J. Vaughan-Nichols of *ZDNet* points out that you have likely been a user of container systems for quite a while without knowing it. “Google has its own open-source, container technology [lmctfy (Let Me Contain That For You)](http://www.linuxplumbersconf.org/2013/ocw/system/presentations/1239/original/lmctfy%20%281%29.pdf),” he explains. “Anytime you use some of Google functionality — Search, Gmail, Google Docs, whatever — you are issued a new container.” ## **Docker’s Relationship with LXC** Docker was actually built using Linux Containers (LXC), OS-level virtualization through which you can run various containers through one control host. The main factor that separates VMs from containers is that the level of abstraction for a hypervisor is the entire computer while the level of abstraction for a container system is the OS kernel. Hypervisors have a distinct advantage here, as you might notice. You aren’t stuck with a single OS or kernel. Your Docker containers, on the other hand, are all sharing the same OS and the same kernel. You don’t necessarily need multiple operating systems, obviously. If you just want to get a bunch of apps running on the smallest number of physical servers, Docker makes sense. With Docker, [Cloud Hosting](https://www.atlantic.net/vps-hosting/) providers and data centers are able to slash their utility and equipment costs. Docker has been able to popularize the container approach in part because it’s improved the security and simplicity of container environments. Plus, interoperability is enhanced by its association with major companies – such as Google, Canonical, and Red Hat – on its open source element libcontainer. ## **Pack-and-Ship-Friendly** Bottomley notes that Docker is also useful for the packing and shipping of apps. You are immediately able to move your app wherever you need to get it. In this way, Docker really found a way to meet a need of the typical enterprise. Enterprises want their apps to be portable, and they want to be able to distribute them effectively, but that process is often a source of inconsistency, says 451 Research analyst Jay Lyman. “Just as GitHub stimulated collaboration and innovation by making source code shareable,” he notes, “Docker Hub, Official Repos and commercial support are helping enterprises answer this challenge by improving the way they package, deploy and manage applications.” Finally, it’s easy to deploy Docker containers in a cloud scenario. You can easily integrate it with typical DevOps environments seamlessly (Ansible, Puppet, etc.) or use it as a standalone. The main reason it’s so popular is simplification, says Ben Lloyd Pearson via opensource.com. You can do local development within a system that is identical to a live server; deploy various development environments from your host that each use their own software, OS, and settings; easily run tests on various servers; and create an identical set of configurations, so that collaborative work isn’t ever hindered by parameters of the local host. ## **Summary & Conclusion** In summary, there are three basic reasons for Docker’s success, according to Vaughan-Nichols. First, “[i]t can get more applications running on the same hardware than other technologies.” Second, “it makes it easy for developers to quickly create ready-to-run container applications.” And finally, “it makes managing and deploying applications much easier.” Everyone is interested in Docker, and it’s easy to see why. So how do you get started? With a one-click app, you can be up in 30 seconds. At Atlantic.Net, we offer SSD [VPS Hosting](https://www.atlantic.net/vps-hosting/) that utilizes international data centers and bills per second so you are never overcharged. --- # How to Test Responsive Design in Device Mode with Chrome Developer Tools > URL: https://www.atlantic.net/hipaa-compliant-wordpress-hosting/how-to-test-responsive-design-device-mode-chrome-developer-tools/ | Published: 2015-09-17 | Updated: 2026-03-01 | Author: Alexander Wise With the emergence of mobile devices as a significant source of online traffic, responsive design is rising as an important tool in a developer’s set of skills. ## Why Responsive Design? According to the tenets of responsive design, websites should adapt to different resolutions, supporting devices ranging from smartphones to desktops with full-sized monitors. Not only do websites have to look great, but they also have to perform well across the scope of connectivity options that mobile devices have introduced. Fortunately, Chrome has made it easier to test responsive design through Developer Tools by integrating a powerful emulation feature: device mode. Device mode can emulate a mobile environment to test a website’s responsiveness in different devices. This mode can change the resolution of your page to reflect the size of screens from devices like the Samsung Galaxy S4 and the Apple iPad. You can also test your site with different throttling options. . ### Prerequisites – Any modern version of Chrome. If you want a more developer-centric tool, try [Chrome Canary](https://www.google.com/intl/en/chrome/browser/canary.html). ## Toggle Device Mode in Chrome If you’ve never been inside Developer Tools before, click F12 or open Chrome’s menu > More Tools > Developer Tools. To activate device mode, simply click the device icon in the top left corner of the Developer Tools window. ![Toggle device mode](https://www.atlantic.net/wp-content/uploads/2018/01/design1.png) Click to the icon to toggle device mode. A toolbar will appear at the top of the page where Chrome will emulate different devices with viewport sizes, throttling options, and other features. ![Device Mode Toolbar](https://www.atlantic.net/wp-content/uploads/2018/01/design2.png) Navigating the device mode toolbar. . ## Select Device To emulate a device, select it from one of the preset devices in the drop-down menu. Depending on the device, users may be given the option to choose Landscape and Portrait orientations. You also have the option to enter your own pixel dimensions if you prefer. Refresh the page so that the right viewport size and user agent string is set. . ### What just happened? When you refresh the page, the viewport size immediately changes to reflect the selected device’s height and width. The console also activates touch events so that developers can test events like dragging and multi-touch. Note that this change deactivates certain CSS styling rules for mouse-based events. The browser’s user agent string updates as well under the UA section to the right. Now you can almost perfectly replicate how your page would look and function on a specific device. Let’s see what happens when we select the Apple iPhone 6 from the device list and refresh. ![Apple iPhone 6 emulation](https://www.atlantic.net/wp-content/uploads/2018/01/design3.png) Apple iPhone 6 emulation As we can see from above, the resolution changes to 667 x 375 (if your orientation is set to “Portrait”, the resolution will be 375 x 375), and the UA updates to match the default iPhone user agent string. . ## CSS Media Queries Now that we have changed the viewport, let’s take it one step further and learn how to inspect media queries. Media queries apply CSS styling to defined widths, heights, aspect ratios, orientations, and other properties. Through media queries, developers can add specific styling rules, or even assign different style sheets, to varying heights and widths to make sure the design looks great across all devices. To view media queries in device mode, click the following icon: ![Media Query Icon](https://www.atlantic.net/wp-content/uploads/2018/01/design4.png) Hovering over the icon will show the media queries detected. For each media query, a clickable bar will appear below the icon. ![Media Query Bars](https://www.atlantic.net/wp-content/uploads/2018/01/design5.png) Try clicking the bars or dragging the edges of the viewport to adjust the size. In the case of this particular web page, clicking each bar will expand the viewport within the ranges of the max-width or min-width specified in the media queries. ![Media query with max-width set to 619px.](https://www.atlantic.net/wp-content/uploads/2018/01/design6.png) Media query with max-width set to 619px. ![Media query of min-with set to 800px.](https://www.atlantic.net/wp-content/uploads/2018/01/design7.png) Media query of min-with set to 800px. In the two examples above, you can see how different style rules are applied according to media features. From there, you may right click the media query bar and select Reveal in Source Code. This option pulls up the style sheet associated with the media query in the Source panel. You can fiddle with the CSS to test out different styling options for the media query, making this a powerful resource for frontend development. . ## Network Throttling Now that we know how to test CSS against different devices, let’s investigate how the site performs at different speeds. Before device mode, Developer Tools already had a method for testing network performance in the Network panel. But with device mode, developers can select a device and choose from a variety of connectivity speeds to test with, such as 3G or 4G. Even offline connectivity is an option here. With the Network panel open, select the desired speed from the drop-down and refresh the page. Each asset that is loading appears in the waterfall view in the Network panel. When the page completes loading, you can compare the loaded assets between different device speeds to ensure that your website is optimized. ![Network Throttling at 2G connectivity](https://www.atlantic.net/wp-content/uploads/2018/01/design8.png) Network Throttling at 2G connectivity ![Network Throttling at 4G connectivity](https://www.atlantic.net/wp-content/uploads/2018/01/design9.png) Network Throttling at 4G connectivity In the screenshots above, you can see the difference between loading times for assets from the 2G connection vs. the 4G connection. Analyzing the size and loading time of each asset from the Network panel waterfall is a very useful method for identifying areas where you can improve or optimize the performance of your site. . ### Conclusion With powerful features like viewport sizing, media queries, and network throttling, device mode makes testing across devices easier than ever. Taking time to familiarize yourself with the Developer Tools device mode has the potential to save you hours of work and help you to make your site friendly to the increasing variety of devices people use to access the Internet. Try this article using your reliable [HIPAA-compliant WordPress hosting](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/) solution from Atlantic.Net. --- # How to Install hMailServer MTA on Windows > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-hmailserver-mta-windows/ | Published: 2015-09-18 | Updated: 2026-01-07 | Author: Alexander Wise ##### **Verified and Tested 09/18/15** ## Introduction HMailserver is a free software that will allow you handle e-mail delivery. MTA, mail transfer agent, is just another name for this process. Since Windows Server 2003, there have not been roles or feature included with the [Windows Server](https://www.atlantic.net/dedicated-server-hosting/) operating system to host an MTA, so if you’re looking to run a mail server on a Windows host you need to look at third-party applications, and hMailServer is one of the more popular choices. There are paid versions available, but licensing for them can be very expensive when you can use a free software that can manage multiple domains. ## Prerequisite We will be using a Windows 2008 R2 SP1 Datacenter 64-bit. This will also work on Windows 2012 R2 Datacenter 64-bit. Be sure to download the installation files by having the Internet Explorer security changed for the account you are logged in with. You can see a guide on that depending on your OS. [How to disable internet explorer enhanced security configuration server 2008/](https://www.atlantic.net/vps-hosting/how-to-disable-internet-explorer-enhanced-security-configuration-server-2008/) or [How to disable internet explorer enhanced security configuration/](https://www.atlantic.net/vps-hosting/how-to-disable-internet-explorer-enhanced-security-configuration/) ## Install hMailServer MTA on Windows Let’s get started. Visit the download page, [hmailserver download](https://www.hmailserver.com/download/) and get the Latest Version. Previous versions of the software are also available and [can be downloaded here](https://www.hmailserver.com/download_archive). In this example, we’re using the Latest Version, 5.6.4 – Build 2283, and we are using the default installation options. ![IE HMail download](https://www.atlantic.net/wp-content/uploads/2018/01/hmail1.png) hMail download Once you have chosen and downloaded the version, click run if you would like the file to start downloading, and run as soon as the download is finished. You can also click save, to install the program later. ![HMail run/save box](https://www.atlantic.net/wp-content/uploads/2018/01/hmail2.png) hMail run/save When the download has completed, and the install begins you are prompted with a Setup window. Click next to proceed. You are then prompted to accept the license agreement. Please be sure to read over the terms of the agreement, and if you accept, click the radio button that corresponds to your selection. Then click next. ![HMail license agreement](https://www.atlantic.net/wp-content/uploads/2018/01/hmail3.png) hMail license Next you are prompted for the location the program will install. The default is C:\Program Files (x86)\hMailServer. If you would like to change this, click on the browse button and choose the directory you want the program to be installed to. Once you have chosen a directory, click next. ![HMail install directory](https://www.atlantic.net/wp-content/uploads/2018/01/hmail4.png) hMail install folder Now you can select your components. The default setting is Full installation, providing the Server and the Administrative tools. You can change this by using the drop down at the Full installation line, and choosing Custom installation and only keep the components you want selected. When you have your desired components selected, click next ![HMail full or custom install](https://www.atlantic.net/wp-content/uploads/2018/01/hmail5.png) hMail install options Going with a standalone model, we will be using the built-in database engine. If you have another host configured as a database server, you can select “Use external database engine”. Keep in mind you will need to provide the database information at a later time to start using the external database. Click next to continue. ![hMail database option](https://www.atlantic.net/wp-content/uploads/2018/01/hmail6.png) hMail database option Choose whether or not you want a start menu folder. You can also change the name of the folder at this time. If you do not want a start menu folder click the check mark on the bottom left of the window. The folder name window will gray out if you do, this is expected. Click next. ![HMail start menu folder](https://www.atlantic.net/wp-content/uploads/2018/01/hmail7.png) hMail start folder Now you get to choose a secure password for the hMailServer program. Be sure to enter the same password in both fields. Click next when the password has been entered. ![HMail Secure password](https://www.atlantic.net/wp-content/uploads/2018/01/hmail8.png) hMail password Finally, review all of your settings, and go back to fix any errors. If there are no errors, click install. ![HMail settings confirmation](https://www.atlantic.net/wp-content/uploads/2018/01/hmail9.png) hMail settings When the install has completed, you can choose to run hMailServer Administrator now, or starting it later. If you do not want to run it now, remove the checkmark. Click Finish to end the installation. ![HMail installtion complete](https://www.atlantic.net/wp-content/uploads/2018/01/hmail10.png) hMail complete If you choose to run it now and see the following, your installation is successful and complete. ![HMailServer Admin](https://www.atlantic.net/wp-content/uploads/2018/01/hmail11.png) hMailServer Administrator --- # How to Multi-Master MySQL with Percona and Keepalived > URL: https://www.atlantic.net/vps-hosting/how-to-multi-master-mysql-percona-keepalived/ | Published: 2015-09-21 | Updated: 2026-03-03 | Author: Alexander Wise ## Introduction This how-to article will walk you through the procedures for installing and maintaining a single-site multi-master MySQL cluster solution with load-balancing services. We will use [Percona XtraDB Cluster Server](http://www.percona.com/software/percona-xtradb-cluster) as our base MySQL database platform, as it has all the necessary components and built-in support for an active/active, high-availability, and high-scalability open-source solution for MySQL clustering. It integrates Percona Server and Percona XtraBackup with the Galera library of MySQL high availability solutions in a single package, which enables you to create a cost-effective MySQL high availability cluster. We will be using Keepalived to handle the load-balancing. Percona provides [yum and apt repositories](http://www.percona.com/doc/percona-server/5.6/installation.html#using-percona-software-repositories?id=repositories:start) for Red Hat/CentOS and Ubuntu/Debian. These repositories include Percona Server, Percona XtraDB, Percona XtraBackup, and Percona Toolkit. Keepalived is open-source routing software that provides load-balancing via LVS (Linux Virtual Server) and high availability via VRRP (Virtual Router Redundancy Protocol). ## Prerequisites Before we begin, we will need to have the following in place first. - Three CentOS 6. x servers, all on the same local area network (LAN). (Two MySQL nodes and one load-balancing node.) - MySQL servers should have at least 2GB of RAM to enable sync services. - Three unique, secure passwords for the following MySQL users: - MySQL root user - SST (State Snapshot Transfer) services sync user (“sst-sync-user”) - Keepalived user (“keepalived”) - Secured CentOS 6. x firewall configuration (*This item is a best practice recommendation and not strictly required. We use iptables in this guide, so if you use an alternate solution, adjust as necessary.*) ## Outline of Packages and Configuration Steps - Essential Percona Server Preparation (Nodes #1 and #2) - MySQL Node #1: Configuration - MySQL Node #2: Configuration - Keepalived Node #3: Installation from Repository - Keepalived Node #3: (Optional) Compiling from Source . ### Setup Diagram Below is a diagram of the expected results once we complete this article. Please remember that all IP addresses used within this article and the diagram are [RFC 5737 – IPv4 Address Blocks Reserved for Documentation Purposes Only](https://tools.ietf.org/html/rfc5737). ![Multi-Master MySQL Cluster Network Diagram](https://www.atlantic.net/wp-content/uploads/2018/01/percona1.png) . ## Step 1 – Basic Percona Server Preparation (Nodes #1 and #2) First, we will ensure we are logged into your web server as the root user account. ``` sudo su - ``` Next, we will install the required Yum repositories to install and keep the Percona software packages updated easily. ``` yum install -y http://linux.mirrors.es.net/fedora-epel/6/i386/epel-release-6-8.noarch.rpm yum install -y http://www.percona.com/downloads/percona-release/redhat/0.1-3/percona-release-0.1-3.noarch.rpm yum clean all yum update ``` > - **EPEL**: [Extra Packages for Enterprise Linux](https://fedoraproject.org/wiki/EPEL) is a Fedora Special Interest Group that creates, maintains, and manages a high quality set of additional packages for Enterprise Linux. > - **Percona**: Percona XtraDB Software Repository. . We will disable SELinux (Security-Enhanced Linux kernel) since it conflicts with the Percona XtraDB cluster services. First, open the `/etc/selinux/config` configuration file with your text editor of choice (we’ll use Nano throughout this article). ``` nano /etc/selinux/config ``` Next, change the configuration variable `SELINUX=enforcing` to `SELINUX=disabled`, as below. ``` # This file controls the state of SELinux on the system. # SELINUX= can take one of these three values: # enforcing - SELinux security policy is enforced. # permissive - SELinux prints warnings instead of enforcing. # disabled - No SELinux policy is loaded. SELINUX=disabled # SELINUXTYPE= can take one of these two values: # targeted - Targeted processes are protected, # mls - Multi Level Security protection. SELINUXTYPE=targeted ``` Reboot your server for the change to take effect. Suppose you are running the iptables firewall services (*enabled by default on most CentOS 6. x installations*). In that case, you must enable the required service ports on each node server to allow MySQL connectivity and sync services between the clustered nodes. ``` iptables -I INPUT 5 -m state --state NEW -m tcp -p tcp -m multiport --dports 4567:4568 -j ACCEPT iptables -I INPUT 5 -m state --state NEW -m tcp -p tcp --dport 4444 -j ACCEPT iptables -I INPUT 5 -m state --state NEW -m tcp -p tcp --dport 3306 -j ACCEPT service iptables save ``` > **Note:** These commands will insert each of these firewall rules right after the default INPUT rules, at line number 5. If you have made any changes to your iptables rules before this step, be sure to adjust these commands with the line numbers relevant to your iptables configuration. See [our article on Basic IPTables](https://www.atlantic.net/vps-hosting/how-to-linux-general-basic-iptables/) if you need help or a refresher. . We are ready to install the Percona XtraDB Cluster packages on each MySQL server node. ``` yum install -y Percona-XtraDB-Cluster-56 ``` ## Step 2 – MySQL Node #1: Configuration First, be sure you have the MySQL user passwords (mentioned above in the prerequisites section) handy in the following steps. Now, we will need to create the `/etc/my.cnf` configuration file with the clustering configuration settings. ``` nano /etc/my.cnf ``` Next, copy and paste these base configuration settings into our configuration file. > **Note:** In the “CLUSTER CONFIGURATION” and “STATE SNAPSHOT TRANSFER” sections below, you’ll need to substitute the values relevant to your network/configuration: > > - **wsrep_cluster_name** – the cluster name must be the same across all nodes, but you may substitute your own naming convention. > - **wsrep_cluster_address** – use the IP addresses of each participating node (including this host). It must be preceded by “gcomm://”.) > - **wsrep_node_address** – use the IP address for this host. > - **wsrep_node_name** – you may substitute your own naming convention. > - **wsrep_sst_auth** – substitute the SST user account password from above after the username and colon in this field. You may also substitute your own naming convention for the SST user–just be sure to update the same username when adding the users to MySQL below.. ``` [mysqld] # GENERAL # datadir = /var/lib/mysql user = mysql # LOGGING # # log-error = /var/log/mysql/error.log # log-queries-not-using-indexes = 1 # slow-query-log = 1 # slow-query-log-file = /var/log/mysql/mysql-slow.log # DATA STORAGE # default_storage_engine = InnoDB binlog_format = ROW # CLUSTER CONFIGURATION # wsrep_cluster_name = mysql_clstr01 wsrep_cluster_address = gcomm://192.0.2.11,192.0.2.12 wsrep_node_address = 192.0.2.11 wsrep_node_name = mysql-node-01 wsrep_provider = /usr/lib64/libgalera_smm.so # STATE SNAPSHOT TRANSFER # wsrep_sst_method = xtrabackup-v2 wsrep_sst_auth = "sst-sync-user:<%sst generated password%>" # MyISAM Database Replication # # MyISAM storage engine has only experimental support at this time. # # wsrep_replicate_myisam = 1 # Settings / Tunning Options # innodb_locks_unsafe_for_binlog = 1 innodb_autoinc_lock_mode = 2 # innodb_flush_log_at_trx_commit = 2 # innodb_flush_method = O_DIRECT # innodb_file_per_table = 1 # innodb_buffer_pool_size = 1386971136 # innodb_buffer_pool_size = 6G # innodb_log_file_size = 256M # key_buffer = 208045670 # max_allowed_packet = 67108864 # thread_stack = 192K # thread_cache_size = 10 # query_cache_limit = 1M # query_cache_size = 16M ``` Many of these configuration settings are commented out. They are included if you want to tweak and debug database performance. When done, save the file and exit. We are now ready to “bootstrap” the primary node in the cluster. Bootstrapping refers to getting the initial cluster node initialized and running. By bootstrapping, we are defining which node has the initial information and which one all the other nodes should synchronize to (via SST). In the event of a cluster-wide crash (or shutdown), bootstrapping the primary node functions the same way. By picking the initial node, we decide which cluster node contains the database we want to proceed with. > Cluster membership is not defined by this setting, but is defined by the nodes that join the cluster with the proper `wsrep_cluster_name` variable setting. . ``` /etc/init.d/mysql bootstrap-pxc ``` We will also want to ensure that we set the MySQL services to auto-start upon a server reboot. ``` chkconfig mysql on ``` Our first node database service is now operational. We are now ready to secure your MySQL database installation. An initial MySQL database installation is not secured with a password by default. We will run the following command and follow the inline prompts to ensure our MySQL installation. During this process, we will be asked to enter a root password. Use the MySQL root password from above during this process. We can press Enter to accept the defaults for the remaining prompts to complete the secure installation. ``` /usr/bin/mysql_secure_installation ``` Now that we have secured our database server, we must set up several user accounts. The first account will be used for the SST synchronization services, and the second account will be used for the Keepalived service check script. Log in to the MySQL CLI console. ``` mysql -u root -p ``` Next, we will need to create the user accounts and grant security permissions to the accounts. ``` CREATE USER 'sst-sync-user'@'localhost' IDENTIFIED BY '<%sst generated password%>'; GRANT RELOAD, LOCK TABLES, REPLICATION CLIENT ON *.* TO 'sst-sync-user'@'localhost'; CREATE USER 'keepalived'@'%' IDENTIFIED BY '<%keepalived generated password%>'; FLUSH PRIVILEGES; ``` We are now ready to set up this node to directly respond to MySQL connections received from the Keepalived load-balancing server. In a direct routing Linux Virtual Server (LVS) setup, the LVS router (your Keepalived server) must receive the incoming MySQL connection requests and then send them to the proper real server for processing. The actual servers will then need to communicate the response data directly to the client requesting the data. To configure direct routing, each real server must have the VIP (virtual IP) address configured on the host but not respond to ARP requests on the local network. First, we will set up the server not to respond to any ARP requests for the VIP address. ``` echo "net.ipv4.conf.lo.arp_ignore = 1" >> /etc/sysctl.conf echo "net.ipv4.conf.lo.arp_announce = 2" >> /etc/sysctl.conf sysctl -p ``` Next, create a VIP address on the Loopback adapter. We’ll make the `lo:1` interface configuration file and set it to auto-start on boot. ``` nano /etc/sysconfig/network-scripts/ifcfg-lo:1 ``` Paste the following configuration into the interface configuration. *Make sure to replace the example VIP address with the address you’ll be using.* ``` DEVICE=lo:1 BOOTPROTO=static ONBOOT=yes IPADDR=192.0.2.10 NETMASK=255.255.255.255 ``` We can bring up the VIP address once we have saved the configuration file. ``` ifup lo:1 ``` Our first MySQL Cluster node is now completed. ## Step 3 – MySQL Node #2: Configuration Again, be sure you have the MySQL user passwords (mentioned above in the prerequisites section) handy in the following steps. Now, we will need to create the `/etc/my.cnf` configuration file with the clustering configuration settings. ``` nano /etc/my.cnf ``` Next, copy and paste these base configuration settings into our configuration file. > **Note:** In the “CLUSTER CONFIGURATION” and “STATE SNAPSHOT TRANSFER” sections below, you’ll need to substitute the values relevant to your network/configuration: > > - **wsrep_cluster_name** – the cluster name must be the same across all nodes, but you may substitute your own naming convention. > - **wsrep_cluster_address** – use the IP addresses of each participating node (including this host). It must be preceded by “gcomm://”.) > - **wsrep_node_address** – use the IP address for this host. > - **wsrep_node_name** – you may substitute your own naming convention. > - **wsrep_sst_auth** – substitute the SST user account password from above after the username and colon in this field. You may also substitute your own naming convention for the SST user–just be sure to update the same username when adding the users to MySQL below. . ``` [mysqld] # GENERAL # datadir = /var/lib/mysql user = mysql # LOGGING # # log-error = /var/log/mysql/error.log # log-queries-not-using-indexes = 1 # slow-query-log = 1 # slow-query-log-file = /var/log/mysql/mysql-slow.log # DATA STORAGE # default_storage_engine = InnoDB binlog_format = ROW # CLUSTER CONFIGURATION # wsrep_cluster_name = mysql_clstr01 wsrep_cluster_address = gcomm://192.0.2.11,192.0.2.12 wsrep_node_address = 192.0.2.12 wsrep_node_name = mysql-node-02 wsrep_provider = /usr/lib64/libgalera_smm.so # STATE SNAPSHOT TRANSFER # wsrep_sst_method = xtrabackup-v2 wsrep_sst_auth = "sst-sync-user:<%sst generated password%>" # MyISAM Database Replication # # MyISAM storage engine has only experimental support at this time. # # wsrep_replicate_myisam = 1 # Settings / Tunning Options # innodb_locks_unsafe_for_binlog = 1 innodb_autoinc_lock_mode = 2 # innodb_flush_log_at_trx_commit = 2 # innodb_flush_method = O_DIRECT # innodb_file_per_table = 1 # innodb_buffer_pool_size = 1386971136 # innodb_buffer_pool_size = 6G # innodb_log_file_size = 256M # key_buffer = 208045670 # max_allowed_packet = 67108864 # thread_stack = 192K # thread_cache_size = 10 # query_cache_limit = 1M # query_cache_size = 16M ``` Many of these configuration settings are commented out. They are included if you want to tweak and debug database performance. When done, save the file and exit. We are now ready to start the second node in the cluster. We will also want to ensure that we set the MySQL services to auto-start upon a server reboot. ``` service mysql start chkconfig mysql on ``` The second server starts synchronizing with the primary node during the initial startup. After a few minutes, our second node’s MySQL services will be operational. As with the primary node, we will now set up this node to directly respond to MySQL connections received from the Keepalived load balancing server. First, we will set up the server not to respond to any ARP requests for the VIP address. ``` echo "net.ipv4.conf.lo.arp_ignore = 1" >> /etc/sysctl.conf echo "net.ipv4.conf.lo.arp_announce = 2" >> /etc/sysctl.conf sysctl -p ``` Next, we will create a VIP address on the Loopback adapter. Create the `lo:1` interface configuration file and set it to auto-start on boot. ``` nano /etc/sysconfig/network-scripts/ifcfg-lo:1 ``` Paste the following configuration into the interface configuration file. *Make sure to replace the example VIP address with the address you’ll be using.* ``` DEVICE=lo:1 BOOTPROTO=static ONBOOT=yes IPADDR=192.0.2.10 NETMASK=255.255.255.255 ``` We can bring up the VIP address once we have saved the configuration file. ``` ifup lo:1 ``` Our second MySQL Cluster node is now completed. We are now going to validate that both servers are operational and synchronized. From each node, execute the following command (we’ll need our MySQL root password): ``` mysql -h localhost -u root -p -e "SHOW STATUS;" | grep "wsrep_ready" ``` We should receive the response “ON”. The node is not a cluster member if we receive any other answer. ## Step 4 – Keepalived Node #3: Installation from Repository This section covers installing Keepalived from the CentOS repository. This version of Keepalived trails several iterations behind the most recent version. While it will work for simple deployments, if you think you might need the latest version and the support fixes it offers (such as improved support for IPv6 and VRRPv3, for example), look at their [changelog](http://www.keepalived.org/changelog.html). Instructions for compiling the latest version from the source are included below. First, you must allow MySQL connectivity if you are running the iptables firewall services (*enabled by default on most CentOS 6. x installations*). ``` iptables -I INPUT 5 -m state --state NEW -m tcp -p tcp --dport 3306 -j ACCEPT service iptables save ``` > **Note:** These commands will insert each of these firewall rules right after the default INPUT rules, at line number 5. If you have made any changes to your iptables rules before this step, be sure to adjust these commands with the line numbers relevant to your iptables configuration. See [our article on Basic IPTables](https://www.atlantic.net/vps-hosting/how-to-linux-general-basic-iptables/) if you need help or a refresher. . Now, we can install the Keepalived package. ``` yum install keepalived ``` Next, we are going to create a new `/etc/keepalived/keepalived.conf` configuration file. You can delete the default configuration that is installed, or you can move it to a backup file for later reference if you would like. In this example, we will be moving it to a backup file. ``` mv /etc/keepalived/keepalived.conf /etc/keepalived/keepalived.conf.bak nano /etc/keepalived/keepalived.conf ``` Now copy and paste the below configuration into the `keepalived.conf` file. > Be sure to replace the example IP addresses below with the virtual and real IP addresses you configured in the steps above. Also, you’ll need to add your keepalived user password from above where indicated. . ``` ! Configuration File for keepalived global_defs { router_id LVS_MYSQL_CLSTR1 } ### VRRP Virtual IP Configuration vrrp_instance VI_1 { state MASTER interface eth0 virtual_router_id 51 priority 100 advert_int 1 authentication { auth_type PASS auth_pass keepalived } virtual_ipaddress { 192.0.2.10 } } ### LVS Configuration virtual_server 192.0.2.10 3306 { delay_loop 2 ## LB Mode : Round-Robin lb_algo rr ## Direct Routing Response lb_kind DR protocol TCP # Real Server to add when all real_servers are down # sorry_server real_server 192.0.2.11 3306 { weight 10 MISC_CHECK { misc_path "/etc/keepalived/check_scripts/check_db 192.0.2.11 keepalived <%keepalived password%>" misc_timeout 5 misc_dynamic } } real_server 192.0.2.12 3306 { weight 10 MISC_CHECK { misc_path "/etc/keepalived/check_scripts/check_db 192.0.2.12 keepalived <%keepalived password%>" misc_timeout 5 misc_dynamic } } } ``` We are now going to create the `MISC_CHECK` script this configuration invokes (it does not exist by default). First, we will make the directory, then the script file, and set the file mode to executable. ``` mkdir -p /etc/keepalived/check_scripts touch /etc/keepalived/check_scripts/check_db chmod +x /etc/keepalived/check_scripts/check_db nano /etc/keepalived/check_scripts/check_db ``` Now, copy and paste the bash code below into the file. `check_db`. ``` #!/bin/bash mysql_host="${1}"; mysql_user="${2}"; mysql_pass="${3}"; node_response=$(mysql -h ${mysql_host} -u ${mysql_user} -p${mysql_pass} -e "SHOW GLOBAL VARIABLES;" | grep "wsrep_node_address" | awk '{ print $2 }'); if [ "${node_response}" == "${mysql_host}" ] then # echo "Hostname matched"; exit 0; else # echo "Hostname not matched"; exit 1; fi ``` Save the file and exit. We are now ready to start the Keepalived services. We’ll also set them to auto-start upon a system reboot. ``` chkconfig keepalived on /etc/init.d/keepalived start ``` Our Keepalived server is now operational.   Please review the user guide for in-depth instructions on customizing your Keepalived configuration. We should now have a fully functional Multi-Master MySQL Cluster with a single VIP for connectivity. We can point client connections to our VIP address (192.0.2.10), and the connection will be passed to each real server in our cluster in round-robin mode. Because we used Keepalived with a VRRP VIP configuration, you can easily [add a second Keepalived server to the network](https://www.atlantic.net/dedicated-server-hosting/how-to-vrrp-keepalived-configuration/) to provide full redundancy of your Load-Balancer setup and MySQL Cluster. ## Keepalived Node #3: (Optional) Compiling from Source If we want the latest version of Keepalived, we must install the necessary tools to build the Keepalived package from the source. ``` yum install -y kernel-headers kernel-devel gcc make popt-devel openssl-devel ipvsadm net-snmp-devel git mysql; ``` > - popt-devel : Used for command line parsing > - OpenSSL : This library is needed for MD5 and SSL Support > - ipvsadm : Used to maintain or inspect the virtual server table in the Linux kernel > - net-snmp : Provides SNMP monitoring . With the dependencies now in place, we must download the most recent version of the source code. We can find the most current version on the [Keepalived.org download page](http://www.keepalived.org/download.html) or use the GIT Repository to download the latest build. We will be using the GIT repository for this installation. ``` mkdir -p /tmp/keepalived git clone https://github.com/acassen/keepalived.git /tmp/keepalived cd /tmp/keepalived ``` Now that the source code is downloaded and extracted, we are ready to compile the Keepalived package for our Linux kernel. ``` ./configure --enable-snmp make make install ``` After each command, we should double-check the output to ensure no errors during each process. Once everything compiles correctly, we will create the necessary symlinks. ``` ln -s /usr/local/etc/sysconfig/keepalived /etc/sysconfig/ ln -s /usr/local/etc/rc.d/init.d/keepalived /etc/init.d/ ln -s /usr/local/etc/keepalived/ /etc/keepalived ``` Next, we need to update the `/etc/init.d/keepalived` startup script to call the correct path for the daemon. ``` nano /etc/init.d/keepalived ``` Replace the application call line `daemon keepalived` with the full way to the application, as below. ``` #!/bin/sh # # Startup script for the Keepalived daemon # ... start() { echo -n $"Starting $prog: " daemon /usr/local/sbin/keepalived ${KEEPALIVED_OPTIONS} RETVAL=$? echo [ $RETVAL -eq 0 ] && touch /var/lock/subsys/$prog } ... ``` Now, we should be able to start the Keepalived daemon and resume configuration as above. ### Atlantic.Net Atlantic.Net offers [VPS hosting](https://www.atlantic.net/vps-hosting/) and managed server hosting services, including a layer of business-essential managed services to your hosting packages. Contact us today for more information. --- # How to Configure NGINX on a CentOS 7 Server > URL: https://www.atlantic.net/vps-hosting/how-to-configure-nginx-centos-7-server/ | Published: 2015-09-22 | Updated: 2026-03-02 | Author: Alexander Wise ##### Verified and Tested 02/04/2021 ## Introduction This how-to will help you install and configure NGINX so you can run high traffic websites while maintaining the high level of performance your customers expect. We are also going to install additional software in order to get the most out of NGINX, so this guide will also include the installation and configuration of MySQL, PHP-APC, and PHP-FPM. Why NGINX? There’s a long back and forth debate over whether you should use Apache or NGINX, and while the overall performance of the two web server platforms is roughly the same, NGINX’s event-based processing model shines by being simple, lightweight and simply better at handling large amounts of concurrent hits for static content without overly taxing your server hardware. ![NGINX Car by Walker Cahall](https://www.atlantic.net/wp-content/uploads/2018/01/balance1.png) NGINX Car by [Walker Cahall](http://www.waltronic.net/) ## What Do You Need? – You need a CentOS 7 server configured with a static IP address. If you do not have a server already, you can visit our [VPS Hosting](https://www.atlantic.net/vps-hosting/) page and spin a new server up in under 30 seconds. ## Server Preparation To get started, login to your CentOS server via SSH. Atlantic.Net Cloud servers are setup as minimal installations in order to avoid having unnecessary packages from being installed and never used. Because of this, we’re going to start out by installing a couple of packages not there by default. ``` yum install wget ``` ``` yum install nano ``` Once you are logged in, make sure that your server is fully up-to-date. ``` yum update ``` With the server up-to-date, we can continue the process and install NGINX. Since NGINX is not included in the default CentOS repositories, we’re going to use the Extra Packages for Enterprise Linux (EPEL) repo. We are also going to use packages from the REMI repositories further in the process, so let’s download and install that as well. You can install the latest version of EPEL using the following command: ``` yum install epel-release -y ``` Before we move on, we’re also going to make a new user and group that will be used by NGINX and PHP-FPM. If you leave users and groups using default settings, everything should still work for you, but to help provide that little bit of extra security we’ll be making the change. ``` groupadd www-data useradd -g www-data www-data ``` While we are working on server preparation, let’s go ahead and set up a new directory for our web server. Normally people use */var/www/html* for their sites, but I’ve always been more comfortable having site files in */home/domainname.tld/html*, so that’s what we’ll use. For the walkthrough, we will be using **example.tld** as our domain — make sure to update the bold entries so they match the domain that you are configuring. ``` mkdir -p /home/example.tld/html chown -R www-data:www-data /home/example.tld/ chmod -R 0755 /home/example.tld/html ``` Now that we have finished preparing the server, we can move on to the installation of our software packages. ## Install and Configure MariaDB on CentOS 7 First, install the MariaDB server package with the following command: ``` yum install mariadb-server -y ``` After installing MariaDB, start the MariaDB service and enable it to start at system reboot: ``` systemctl start mariadb systemctl enable mariadb ``` Next, secure the MariaDB installation with the following command: ``` mysql_secure_installation ``` The MySQL Secure Installation process will walk you through initial security changes that should be put into place for your new MySQL instance. Note: Chose a secure password and limit root access to localhost only. ![Sample mysql_secure_installation](https://www.atlantic.net/wp-content/uploads/2018/01/nginx1.jpg) *mysql_secure_installation* Edit the */etc/my.cf* file to match the following, limiting the server only to listen to local connections: ``` [mysqld] bind-address = 127.0.0.1 datadir=/var/lib/mysql socket=/var/lib/mysql/mysql.sock user=mysql # Disabling symbolic-links is recommended to prevent assorted security risks symbolic-links=0 [mysqld_safe] log-error=/var/log/mysqld.log pid-file=/var/run/mariadb/mariadb.pid ``` We’re going to restart all services at the end, so let’s move on. ## Install and Configure NGINX on CentOS 7 ``` yum install nginx ``` Once installed, we need to check to see how many CPU logical cores are available on your server. To do this, run the following command: ``` grep -c 'model name' /proc/cpuinfo ``` Make note of the result as this is what you are going to see the worker_processes setting too. Open */etc/nginx/nginx.conf* and replace the current contents with the following: ``` user    www-data; worker_processes  2; pid        /var/run/nginx.pid; events {         worker_connections  1024; } http {         include       /etc/nginx/mime.types;         default_type  application/octet-stream;         server_names_hash_bucket_size 64;         error_log  /var/log/nginx/error_log;         log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '                 '$status $body_bytes_sent "$http_referer" '                 '"$http_user_agent" "$http_x_forwarded_for"';         sendfile        on;         keepalive_timeout  30;         server_tokens off;         gzip on;         gzip_disable "MSIE [1-6]\.(?!.*SV1)";         gzip_http_version 1.1;         gzip_vary on;         gzip_proxied any;         gzip_comp_level 6;         gzip_buffers 16 8k;         gzip_types text/plain text/css application/json application/x-javascript text/xml application/xml application/xml+rss text/javascript application/javascript text/x-js;         # enabled sites         include /etc/nginx/conf.d/*.conf; } ``` Next, we need to set up our domain configuration file. This is done by creating a new file named */etc/nginx/conf.d/**example.conf**.*Again, make sure to update the bold entries to match the domain you are adding.** ``` server {         listen  80;         server_name     example.tld;         client_max_body_size 5m;         client_body_timeout 60;         access_log /var/log/nginx/example.tld_access;         error_log  /var/log/nginx/example.tld_error error;         root /home/example.tld/html/;         index  index.html index.php;         ### SEO sitemaps ###         rewrite ^/sitemap_index\.xml$ /index.php?sitemap=1 last;         rewrite ^/([^/]+?)-sitemap([0-9]+)?\.xml$ /index.php?sitemap=$1&sitemap_n=$2 last;         ### www directory ###         location / {                 try_files $uri $uri/ /index.php?$args;         }         ### security ###         error_page 403 =404;         location ~ /\. { access_log off; log_not_found off; deny all; }         location ~ ~$ { access_log off; log_not_found off; deny all; }         location ~* wp-admin/includes { deny all; }         location ~* wp-includes/theme-compat/ { deny all; }         location ~* wp-includes/js/tinymce/langs/.*\.php { deny all; }         location /wp-content/ { internal; }         location /wp-includes/ { internal; }         location ~* wp-config.php { deny all; }         ### disable logging ###         location = /robots.txt { access_log off; log_not_found off; }         location = /favicon.ico { access_log off; log_not_found off; }         ### caches ###         location ~* \.(jpg|jpeg|gif|css|png|js|ico|html)$ { access_log off; expires max; }         location ~* \.(woff|svg)$ { access_log off; log_not_found off; expires 30d; }         ### php block ###         location ~ \.php?$ {                 try_files $uri =404;                 include fastcgi_params;                 fastcgi_pass unix:/var/run/php-www.socket;                 fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;                 fastcgi_intercept_errors on;                 fastcgi_split_path_info ^(.+\.php)(.*)$;                 fastcgi_hide_header X-Powered-By;         } } ``` Because we changed the user that NGINX runs as, we need to make a change ownership permissions for the NGINX temp files. ``` chown -R www-data:www-data /var/lib/nginx/ ``` ``` chmod 700 /var/lib/nginx/ ``` Again, we’re going to restart all services at the end. Moving on, instead of installing a full version of PHP on the server, we’re going to PHP-FPM – an alternative PHP FastCGI implementation. ## Install and Configure PHP-FPM on CentOS 7 Note: After the install, we need to update the “cgi.fix_pathinfo” setting to disable a potential vulnerability that could allow a 3rd party to execute their own PHP code on your new server. First, install the Remi repository with the following command: ``` yum install http://rpms.famillecollet.com/enterprise/remi-release-7.rpm ``` Next, install PHP-FPM with other required extensions using the following command: ``` yum --enablerepo=remi-php74 install php-fpm php-mysql ``` ``` nano /etc/php.ini ``` Change ``` ;cgi.fix_pathinfo=1 ``` to ``` cgi.fix_pathinfo=0 ``` Open */etc/php-fpm.d/www.conf* and change the configuration to the following: ``` [www] listen = /var/run/php-www.socket user = www-data group = www-data listen.owner = www-data listen.group = www-data listen.mode = 0660 listen = /var/run/php-www.socket request_slowlog_timeout = 5s slowlog = /var/log/php-fpm/blogcms_log listen.allowed_clients = 127.0.0.1 pm = dynamic pm.max_children = 10 pm.start_servers = 3 pm.min_spare_servers = 2 pm.max_spare_servers = 4 pm.max_requests = 400 listen.backlog = -1 pm.status_path = /status request_terminate_timeout = 120s rlimit_files = 131072 rlimit_core = unlimited catch_workers_output = yes php_value[session.save_handler] = files php_value[session.save_path] = /var/lib/php/session php_admin_value[error_log] = /var/log/php-fpm/www-error_log php_admin_flag[log_errors] = on ``` Save your changes. ## Install and Configure PHP-APC on CentOS 7 The final piece of the puzzle is going to be installing a PHP accelerator to further improve static file load times. ``` yum --enablerepo=remi-php74 install php-pecl-apc ``` Once the install has been completed, open */etc/php.d/50-apc.ini* and replace the contents with the following: ``` extension = apc.so apc.enabled=1 apc.shm_segments=1 apc.shm_size=128M apc.num_files_hint=1024 apc.user_entries_hint=4096 apc.ttl=7200 apc.use_request_time=1 apc.user_ttl=7200 apc.gc_ttl=3600 apc.cache_by_default=1 apc.filters apc.mmap_file_mask=/tmp/apc.XXXXXX apc.file_update_protection=2 apc.enable_cli=0 apc.max_file_size=1M apc.stat=1 apc.stat_ctime=0 apc.canonicalize=0 apc.write_lock=1 apc.report_autofilter=0 apc.rfc1867=0 apc.rfc1867_prefix =upload_ apc.rfc1867_name=APC_UPLOAD_PROGRESS apc.rfc1867_freq=0 apc.rfc1867_ttl=3600 apc.include_once_override=0 apc.lazy_classes=0 apc.lazy_functions=0 apc.coredump_unmap=0 apc.file_md5=0 apc.preload_path ``` ## Final Touches Now that everything is done, we can verify our NGINX configuration by running: ``` nginx -t ``` If the configuration comes back with “nginx: configuration file /etc/nginx/nginx.conf test is successful”, we can start (or restart) all services and make sure that all services are set to start on system startup. ``` systemctl start mariadb ; systemctl enable mariadb systemctl start nginx ; systemctl enable mariadb systemctl start php-fpm ; systemctl enable php-fpm ``` As our final step, we’re going to verify that the configuration is working by making an info.php test page, and moving a copy of the default index.html to our sites home directory. As before, make sure to update the bold entries with the domain that you are setting up. ``` cp -R /usr/share/nginx/html/* /home/example.tld/html/ ``` ``` nano /home/example.tld/html/info.php ``` ``` ``` ## Testing Everything Visiting *http://**example.tld*** should show the default index.html file. Visiting *http://**example.tld**/info.php* should show information about PHP. ![PHP CentOS 7](https://www.atlantic.net/wp-content/uploads/2015/09/php-centos7-1024x564.png) With that, you now have a server running all the necessary components to run your website! Please check back here for more updates, and to consider a [market-leading virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # What Is a DDoS Attack? > URL: https://www.atlantic.net/disaster-recovery/what-is-ddos-attack/ | Published: 2015-09-23 | Updated: 2026-02-28 | Author: Alexander Wise ##### ***Target Audience*** *This article is aimed at non-expert computer users (without a background in network or systems administration).* ## Introduction DDoS stands for “Distributed Denial of Service” and, naturally enough, is a type of Denial of Service (DoS) attack. The basic aim of a DoS attack is to render a [virtual private server](https://www.atlantic.net/vps-hosting/), PC or network resource inaccessible or unusable–denying service to anyone trying to access it. It is a malicious attack designed to cause maximum inconvenience.. ## Are DDoS Attacks a New Thing? No, DDoS attacks are not a new phenomenon, but they have been making the headlines more in recent years as their scope has increased in size and as they have included higher profile targets. One recent example is the [attack on the Playstation Network and Xbox Live](http://www.techtimes.com/articles/53512/20150516/psn-and-xbox-live-go-down-and-lizard-squad-takes-credit.htm). A hacking group known as [‘Lizard Squad’](http://www.bbc.co.uk/newsbeat/article/30306319/who-are-lizard-squad-and-whats-next-for-the-hackers) used a DDoS attack to shut down the online gaming services on Christmas Day 2014, upsetting many gamers and causing financial and reputation damage to Microsoft and Sony. . ## How Do DDoS Attacks Work? In a Denial of Service attack, the attacker uses a computer to send an overwhelming amount of data to a target. This target receives so much traffic that it slows down and cannot respond to legitimate traffic, or, in the case of a Permanent Denial of Service (PDoS) attack, its hardware is damaged beyond repair. In this simple style of DoS attack, one computer directly targets another. It is a fairly simple attack to execute and requires minimal computer skills–an attacker can simply acquire and run a piece of software to conduct a DoS. The ‘distributed’ in DDoS refers to the multiple computers used in this type of attack. The attacker either launches a synchronized attack with collaborators or, more commonly, uses a botnet to execute a DDoS. A botnet (a shortened form of “robot network”) is a network of computers infected with malware that allows the attacker to remotely control them without the owner’s knowledge. Using a botnet, an attacker dramatically increases the effect of their attack. Another method attackers use to increase the effect of a DDoS is the “amplification attack”. Rather than directly bombarding a target with data, an attacker sends requests for data to multiple servers. The attacker spoofs the source IP address of each request so that it looks as though it comes from the target of the attack instead of from the attacker. As a result, all of the responses go to the IP address of the victim, flooding them with traffic. It’s essentially like signing your friend up to a load of unwanted junk newsletters. Attackers have found various ways to create these amplification attacks. The IP address spoofing is possible, in part, because they use the UDP protocol-–a protocol that doesn’t validate source IP addresses or connections. The amplification comes into play in the way attackers have found ways to cause the responding servers to return certain responses that are significantly larger than the requests. For example, DNS (Domain Name Service) servers can deliver a response 50-150 times larger than the response. Similarly, Character Generation Protocol (CharGEN) supported by various servers will respond to a character generation request with a response that is 200-1000 times larger. Similarly, the Network Time Protocol (NTP) used to sync clocks across machines, can return a response that can be up to 556.9 times larger than the request.. ## Why Do People Use DDoS Attacks? The motivations behind DDoS attacks vary. In the case of Lizard Squad, [it appeared to be a publicity stunt to promote their freelance hacking services](http://www.welivesecurity.com/2014/12/31/xbox-psn-lizard-squad-ddos/). Sometimes attackers target websites with a demonstration and send their owners [extortion letters demanding payment to prevent future attacks](https://securityintelligence.com/ddos-extortion-ransomwares-older-cousin/). One of the Internet’s more renowned and iconic hacking groups, Anonymous, has used these sorts of attacks as a tool for activism. In their ongoing fight against organizations such as [Scientology](https://www.youtube.com/watch?v=JCbKv9yiLiQ) and the [Westboro Baptist Church](https://www.youtube.com/watch?v=D3FeaSomJhQ), people acting under the Anonymous banner have used DDoS attacks to [take down their respective websites.](http://www.rawstory.com/2012/12/anonymous-vows-to-destroy-westboro-baptist-church-over-sandy-hook-picket-plans/). ## What Defenses Are There? DDoS attacks are difficult to fight, and mitigation is often the best a target can hope for. A big part of dealing with DDoS attacks is simply being prepared. Here are some techniques that can be used to mitigate the effects of a DDoS attack: Some organizations invest in more bandwidth for their servers. The more bandwidth the target has, the harder it is to DDoS. In principle, it’s the same idea as adding more lanes to a road–the wider the road, the more cars are needed to cause a traffic jam. ISPs (Internet Service Providers) may also offer services to help mitigate the effects of DDoS attacks. Since they generally have access to more powerful networking resources, ISPs may have DDoS mitigation plans in place that can help keep your servers safe. There are now many companies who provide help to those who might be targetted by DDoS attacks. During an attack, the target’s traffic is redirected to the mitigation company’s network, where they then “scrub” the data, identifying malicious traffic to drop and allowing through legitimate traffic which is then rerouted back to the target. Companies such as [CloudFlare](https://www.cloudflare.com/features-security), [Black Lotus](https://www.blacklotus.net/), [F5](https://f5.com/products/platforms/silverline/f5-silverline-ddos-protection), [Prolexic](http://www.prolexic.com/), and [Incapsula](https://www.incapsula.com/) offer such services in this growing sector.. ## Part of the Problem? Most of us will likely not be the target of a DDoS. So even if you might feel too small a target, your home computer, your multimedia server, your little home router, the cloud hosting server that hosts your website may, however, be a part of a vast botnet being used to DDoS, without your even realizing. For home systems, keeping up with security patches and changing default device passwords to something much more secure can help protect you exploitation. For web-facing servers (such as web servers or DNS name servers), you can take a little time to [close security vulnerabilities, such as those that can be exploited in amplification attacks](https://www.atlantic.net/vps-hosting/how-to-domain-name-server-dns-amplification-attack/). You can also monitor network traffic for any unusual traffic patterns with something like [Zabbix](https://www.atlantic.net/vps-hosting/how-to-install-zabbix-server-centos-server/) or with a more elaborate Intrusion Detection System (IDS) Suricata or [Security Onion](http://blog.securityonion.net/p/securityonion.html). ## More from Atlantic.Net Learn more about Atlantic.Net’s hosting solutions, including [HIPAA compliant disaster recovery](https://www.atlantic.net/disaster-recovery/) services. --- # How to: Using Basic SQL Syntax > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-using-basic-sql-syntax/ | Published: 2015-09-24 | Updated: 2026-02-28 | Author: Alexander Wise ## Introduction Behind every great web application is a database of some kind. Many of the widely used database systems (e.g., [MySQL](https://www.mysql.com/), [Percona](https://www.percona.com/), [PostgressSQL](http://www.postgresql.org/), [MariaDB](https://mariadb.org/), [MSSQL](http://www.microsoft.com/en-us/server-cloud/products/sql-server/)) use SQL (Structured Query Language) to pull data out and push data in. A lot of modern programming languages provide an ORM (Object-Relational Mapping) layer which loads data directly into code without needing to know SQL, but sometimes you just want to talk to the database directly. While SQL has a lot of keywords and can get very complex, this article goes through the basic CRUD (Create Read Update Delete) constructs. ## Using Basic SQL Syntax Every database system that uses SQL has a slightly different implementation. The differences do not show up in the basic commands that this guide covers, but it is good to know that there are potential differences across systems. In all of the examples here the SQL keywords are capitalized. While this is a common practice and helps make examples clear, most SQL databases don’t care. The same is true with the line breaks and spacing. SQL can be written all on one line if you prefer, but here we will write statements across multiple lines to help clarify some explanations. Different data values need to be entered differently depending on data type. Text values need to be encased (escaped) in single quotes. If you happen to have a value that itself contains a single quote, that interior quote needs to be doubled to make sure the statement will run. ``` WHERE lastname = 'O''niel' ``` Numeric types, integers, decimals and the like do not need any extra escaping. Boolean values like True and False also do not need to be escaped. Finally, many SQL implementations use a semicolon as a statement terminator. While this usage isn’t universal, many consider it a best-practice to ensure portabiility of SQL statements across different implementations. This article will use semicolons.. ## SELECT – Reading Data from the Database. Reading data is the most common task and illustrates the basic structure of a SQL statement nicely. This SELECT is (almost) the most basic SQL statement there is. ``` SELECT FROM WHERE = ; ``` SELECT, FROM and WHERE are SQL keywords. * is a comma-separated list of column names that you want to read. It can also be replaced with * to just return all columns of the table. Be aware that * can be quite slow if you have a lot of columns in a very large table. *<*table*>* is the name of the table you want to retrieve data from. indicates the name of the column which should contain the . The WHERE section is optional, but is so useful and idiomatic in SQL that it makes sense to include it. WHERE restricts the data set based on the criteria. Although depicted here with only a single criterion, it is possible to include several criteria with boolean operators AND and OR. See the UPDATE example below for something more complex. Example: ``` SELECT common_name, genus, species, type FROM animals WHERE type = 'mammal';. ``` ## UPDATE – Making a Change Sometimes it isn’t enough to just see what it is in the database. Sometimes you need a change. And when you do, UPDATE is there for you. ``` UPDATE
SET = WHERE = AND = ; ``` Again, UPDATE, SET, and WHERE are SQL keywords. * is the name of the table you want to update. Within the SET section, you can include one or more = pairs separated by commas. This portion of the statement is where you define the change to be made. The will be set with the given . The WHERE section is optional on UPDATE as well, but leaving it out will update the entire table. Occasionally this is what you want, but most of the time you only want to update a single row or a few rows. In these cases, updating the entire table would be disastrous, so it is good practice to always have a WHERE. This example shows using AND in the WHERE section. Example: ``` UPDATE animals SET have_seen = True, common_name='River Otter' WHERE Genus = 'Lontra' AND Species = 'Canadensis';. ``` ## DELETE – Making It Gone Sometimes you need to remove data from a table. This action is a DELETE. ``` DELETE FROM
WHERE = ; ``` Once again we have our SQL keywords and a * defining which table will be deleted from, and a WHERE section defining which rows are to be deleted. Again the WHERE clause is technically optional, but this statement will delete all rows in a table if it is missing. Example: ``` DELETE FROM animals WHERE have_seen = False;. ``` #### Delete Tip One best practice I find for doing manual deletes like this one is to make a SELECT first. The DELETE command shares a lot of structural similarity with SELECT and yet is far more destructive. First write the statement as a `SELECT * FROM
WHERE = ;` to make sure you know exactly which rows will be affected. Once you are happy with the output, swap out the `SELECT *` for the DELETE keyword and run it. In the example below, the DELETE statement is commented out. Two dashes `--` comment out the rest of the line. This practice can be really helpful when performing DELETEs to keep an accidental run of the query from removing data. Example: ``` SELECT * -- DELETE FROM animals WHERE have_seen = False; ``` > Note: The `--` comments out all text to the end of the line, not the end of the statement. If the `FROM animals WHERE have_seen = False` were on the same line as `-- DELETE`, SQL would only see the `SELECT *` portion of the statement.. ## INSERT – Bringing New Data to the Table The last piece of this puzzle is adding data into a table. There are two forms of INSERT in classic SQL. The one I’ll cover here allows you to add explicit data into a table. ``` INSERT INTO
() VALUES (); ``` The INSERT statement looks different than the rest. The * again defines the table where the data is going, though here it is followed by a comma-separated enclosed in parentheses. You only have to list the columns for which you have data to enter; however, if the table you are working with has required fields (defined as NOT NULL constraints), you will need to give data for all of those fields to avoid an error. The VALUES keyword introduces a  inside of parentheses. This list is the list of values to be inserted into the columns you defined above. The listed columns and values need to match each other’s order. The first value will be inserted into the first column name in the list, the second column to the second value and so on. This order in the statement may be different than the order of columns in the target table, but that is fine. Example: ``` INSERT INTO animals(common_name, species, genus) VALUES ('Sea Otter', 'Lutris', 'Enhydra'); ``` ## About Atlantic.Net Atlantic.Net offers world-class hosting services and solutions, including [HIPAA database](https://www.atlantic.net/hipaa-compliant-hosting/) hosting [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/). Contact us today for a quote! --- # LAMP vs. WAMP: Why do Startups Prefer LAMP to WAMP? > URL: https://www.atlantic.net/hipaa-compliant-hosting/lamp-vs-wamp/ | Published: 2015-09-24 | Updated: 2026-01-07 | Author: Alexander Wise ## **LAMP vs. WAMP: What’s the Difference?** A LAMP or WAMP stack is four pieces of software that are used in combination for open source web development. Components include: - L/W – **Linux/Windows**, the operating system - A – **Apache**, the Web server - M – **MySQL**, the database management system - P – **PHP**, **Python**, or **Perl**, the scripting language. A common variation of this Web stack is a LEMP or WEMP Cloud Hosting stack, which replaces Apache with Nginx. You will also frequently see the term WAMP, which replaces Linux with Windows. There are two main reasons that LAMP is such an extraordinarily common server environment, [explains Russell Kay of *Computerworld*](http://www.computerworld.com/article/2553939/app-development/lamp.html). One is that the applications work very well in tandem even though they were coded independently, due to the collaborative culture of the open-source community. The other is that they are all available 100% free. What is the particular attraction for startups, though? According to three IT professionals, some of the main reasons startups use this development platform are as follows: ## **1.Affordability** Senior systems engineer Marty Gottesfeld agrees with Kay that people choose LAMP in large part because it’s budget-friendly, especially in the case of startups. “Remember Windows Server Standard Edition costs about $700 a license,” [he says](https://www.quora.com/Why-do-most-startups-prefer-to-use-LAMP-stack-over-WAMP-stack). It is possible to cut your costs with Windows by getting a Windows Server Data Center license and creating a bunch of virtual machines. No matter what you do with Microsoft products, though, you’re using proprietary software that comes at a cost. “The backend systems commonly used by IIS web applications also usually cost money,” Gottesfeld adds, “i.e. Microsoft SQL Server, etc. Visual Studio, the main IDE used for IIS .NET Applications also costs a good deal of money” – and that cost is a concern *with every developer* that a company has on staff. Another aspect of cost that engineers appreciate is efficiency – specifically the need for fewer hosts, which in turn reduces the amount that must be spent on physical machines and data center leasing. ## **2.Security** Typically startups do not have IT people working for them full-time. That can create a problem because when you’re working with Windows servers, staying abreast of updates can be time-consuming, and there are “bad consequences for falling short,” Gottesfeld warns. “If you are running Windows IIS,” he adds, “it is a good idea to put a reverse proxy in between them and the Internet anyways.” ## **3.Smoother Operation** Web developer Tobias Hoffmann points out that programs such as Apache and PHP are best used with Linux because that’s the main OS environment in which they were developed. In other words, Windows is just not quite as compatible with these open-source projects. ## **4. Flexibility** To Testlauncher.com CEO Jason Hamilton-Mascioli, it’s all about flexibility and ease of configuration. He especially likes the .htaccess (hypertext access) files of Apache, which he finds to be much more user-friendly than working with IIS. Gottesfeld concurs, explaining that he believes it is simpler to use for programming, application launches, and keeping your environment up-to-date. Basically, coders are able to be efficient with the time and not run into many roadblocks. For instance, he says that even though PHP is now in version 5, his code written in PHP 3 continues to work well. Similarly, updating MySQL is a snap – a stark contrast to the hassles of Microsoft SQL Server. “Companies often spend a good amount of time planning an upgrade to newer version(s) of IIS, .NET, Visual Studio and SQL Server,” he says. “Each upgrade costs additional money, even with SA you are paying for the upgrade, you’re just paying beforehand.” ## **Use within Enterprises?** Sure, a LAMP stack might work well for startups, but is it the right choice for a large enterprise such as a university, government agency, or sizable company? It is, *provided it’s the right situation*. LAMP backs numerous websites that receive significant amounts of traffic, including technology resource O’Reilly Media. Large portions of Web giants such as Google and  Amazon run on LAMP as well. There are limitations to LAMP, though, notes Kay. “By itself, LAMP really only defines software for Web applications,” he says. “Although you can use it to build an application that connects to sophisticated middleware, the heavy-duty programming would likely have to be done in a different language.” Therein lies the reason why many enterprises choose to work with Java and .Net platforms, since they allow you to create sophisticated apps and Web scripts using one language. Nonetheless, LAMP is a great choice for any companies wanting to limit their expenses that are developing applications internally and don’t mind problem-solving themselves or looking for answers in the open-source community. ## **One-Click LAMP Cloud Hosting** As you can see, there are numerous reasons startups prefer to use a LAMP stack for web development, and why it often makes sense for enterprises too. Increasingly startups are looking for reliable** **LAMP Cloud Hosting specifically. At Atlantic.Net, you can get up and running in 30 seconds, on a cloud supported by 100% solid state drives hosted in international data centers. We also offer [HIPAA-compliant cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) services.   --- # How to: Troubleshoot WordPress Plugins by Disabling All of Them at Once > URL: https://www.atlantic.net/vps-hosting/how-to-troubleshoot-wordpress-plugins-disabling/ | Published: 2015-09-25 | Updated: 2026-01-07 | Author: Alexander Wise ## Introduction One of the aspects of WordPress that has made it so popular as a website framework is the vast number of plugins available to enhance and expand just about every aspect of the base install. Occasionally a plugin doesn’t play well with others. It can do so in such a spectacular way that it crashes your site. Other times a subtle bug can drive you mad looking for the source. In both of these cases, the common advice is to disable all of your plugins and re-enable them one by one to find the culprit. This article talks about how to disable all of your plugins at once even if you cannot get into your admin screen anymore. ## Prerequisites – You will need an install of WordPress with access and rights to that directory. > While this tutorial is largely system agnostic, the explanatory screenshots are from Windows. ## Step 1 – List Which Plugins To Reactivate Many of us have plugins installed that are inactive. This tutorial will disable all of the plugins at once, so you will need to know which plugins you want to reactivate. If you still have access to your admin screen, make a list of the plugins that are active. If things are broken enough that you are unable to access your admin screen, you’ll get another chance to make that list in step 3 below. ## Step 2 – Locate the Plugins Directory Find the root of your WordPress install on the [virtual private server](https://www.atlantic.net/vps-hosting/). The root will have a bunch of .php files and the directories `wp-content`, `wp-admin` and `wp-includes`. ![List of files in WordPress root directory](https://www.atlantic.net/wp-content/uploads/2018/01/trouble1.png) Go into the `wp-content` directory. Inside is a directory helpfully called `plugins`. This directory contains all of the PHP code for your plugins, activated or not. ## Step 3 – Rename the Plugins Directory Rename the directory from `plugins` to anything else. I like `plugins-disabled`, for clarity, but the method works fine with any name. By renaming the directory, we have removed the plugins from where WordPress looks for them without deleting any code. ## Step 4 – Reload WordPress Admin Screen This method relies on the way that WordPress checks to see if a plugin’s files exist before attempting to load it. When you reload the Admin screen, WordPress looks for plugins and cannot find them where it expects them to be (because we just renamed the directory). Because WordPress can’t find the plugins, it disables all of them in one fell swoop. You will see errors for each plugin deactivated this way (and here’s where you get that chance to list the plugins which were active if you didn’t or weren’t able to when you started this process). These are one-time errors. ![Disable plugin error example in WordPress Admin](https://www.atlantic.net/wp-content/uploads/2018/01/trouble2.png) ## Step 5 – Restore Plugins Rename the `plugins-disabled` directory back to `plugins`, and reload the admin page again. All of your plugins should reappear, but they will be in the deactivated state now. ## Step 6 – Activate Plugins Unless you to want to leave your site completely without active plugins, you can now activate them, one-by-one, testing the site until you find your problem. > #### Shortcut: Remove a Single Plugin > > If you know that a specific plugin is causing the problem, you can remove just its directory from the `/wp-content/plugins` directory to achieve the same effect on a smaller scale. ## Atlantic.Net Atlantic.Net offers [VPS hosting](https://www.atlantic.net/vps-hosting/) as well as managed hosting services which include a layer of business-essential managed services to your hosting packages. Contact us today for more information. --- # How To Upload Files with FileZilla > URL: https://www.atlantic.net/vps-hosting/how-to-upload-files-filezilla/ | Published: 2015-09-28 | Updated: 2026-03-03 | Author: Alexander Wise ## Introduction FileZilla is a very popular FTP client that has been around since 2001. Uploading and downloading large batches of files couldn’t be made any easier than by using an FTP client like FileZilla. ## Prerequisites – an FTP server that you have valid credentials to. If you need assistance setting up an FTP server, check out our [helpful how-to here](https://www.atlantic.net/dedicated-server-hosting/how-to-install-ftp-server/). ## Installing FileZilla To get started, you first have to [download the client version of FileZilla](https://filezilla-project.org/download.php) onto your computer. This link will take you to the recommended client installer for Windows. For most basic users, you can stick with the default options during installation. For Linux and Mac users, the above page also offers a link to download options appropriate to those platforms. ## Connect to FTP Server with FileZilla When you open the FileZilla client after installation, it will look similar to the image below. ![FileZilla Client Software](https://www.atlantic.net/wp-content/uploads/2018/01/firezilla1.png) FileZilla Client Software To connect to an FTP server, enter the domain name or the server IP address where it says “Host”. Next, enter your username and password into the “Username” and “Password” fields. The port number will be 21 if you want to use regular old FTP, or you can use 22 if you want to use SFTP. SFTP is the secured version of FTP. Once you’ve entered all of this information, click the “Quickconnect” button to the right of the “Port” field. After FileZilla connects, your screen should look similar to the one shown in the image below. ![FileZilla Client Connected to Remote Host](https://www.atlantic.net/wp-content/uploads/2018/01/firezilla2.png) FileZilla Client Connected to Remote Host On the left side of the screen, under “Local site”, you will see listings for the files and directories on your computer. On the right side of the screen, under “Remote site”, you will see the listings for the files and directories on the remote server you are connected to. . ## Transferring Files To upload a file to the remote server, find the file under “Local site” on the left side of the screen (your computer). Once you’ve located it, drag it to the right side of the screen under “Remote site” and drop it into the folder or directory you want to upload to. To download a file from the remote server to your computer, you will do the same as above except reversed. Find the file under “Remote site” and drag it to the “Local site” side and drop it int the folder you would like it to download to on your computer. That’s not the only way to upload or download files with FileZilla. Another option is to double-click the file you want to upload or download. FileZilla will add the file to the transfer queue, and the transfer process will automatically begin. To transfer directories or multiple files, select them (singly or as a group) and then right-click the selection. From the pop-up menu, select “Upload” or “Download”. . ## Saving Connections with FileZilla Site Manager FileZilla Site Manager allows you to save connection settings, so you don’t have to re-enter your information every time you need to connect. This feature is very convenient if you need to connect to the same server(s) regularly. Once you have connected to the FTP server, go to the “File” menu and select “Copy current connection to Site Manager”. You can also manually add the information into Site Manager. Just click the file menu and select “Site Manager” or Crtl+S. ![FileZilla Site Manager](https://www.atlantic.net/wp-content/uploads/2018/01/firezilla3.png) FileZilla Site Manager This connection’s name is highlighted. You may want to click on the “Rename” button change this connection’s name to something more meaningful than the default “New site”. You can also enter any further comments about this connection in the “Comments” box at the bottom right. If you chose the “Copy current connection to Site Manager” option, then your connection details will already be filled in. If not, you’ll need to manually enter Host, Port, Protocol, and User. When you’re done, click the “OK” button. > Note: With the default FileZilla settings, you won’t be able to save user account passwords. You may enable password-saving from the FileZilla client interface. Select Edit > Settings. On the next screen, select Interface from the left menu and uncheck “Do not save passwords” under “Behaviour”. **Be aware that FileZilla stores all connection information–including passwords–in clear text**. . Now, to use this connection in the future, click the Site Manager button (the button directly below File menu option). Select the name you gave this connection and click “Connect”. FileZilla is a must-have tool that should be in any one’s toolbox that is dealing with websites. It takes a potentially time-consuming and complicated process and makes it so much easier.  Atlantic.Net’s reliable and efficient [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions offer great results with 24/7 industry-leading technical support. --- # How to Set Up an Rsync Daemon on Your Linux Server > URL: https://www.atlantic.net/vps-hosting/how-to-setup-rsync-daemon-linux-server/ | Published: 2015-09-28 | Updated: 2026-01-07 | Author: Alexander Wise ##### Verified and Tested 09/28/2015 ## Introduction This tutorial will take you through setting up an rsync daemon on your Linux server. You might want an rsync daemon if you have files that you want available so anyone (or just yourself) can download existing files or upload new files. This guide will review both running rsync as its own daemon and running it via xinetd. ![Rsync Illustration by Walker Cahall http://www.waltronic.net/](https://www.atlantic.net/wp-content/uploads/2018/01/Rsync1.png) Rsync Illustration by [Walker Cahall ](http://www.waltronic.net/) ## Setting Up an Rsync Daemon First, using your preferred text editor, you’ll need to create the configuration file `/etc/rsyncd.conf`, if you do not have one already. Below is an example of our basic configuration parameters and explanations of each one. ``` pid file = /var/run/rsyncd.pid lock file = /var/run/rsync.lock log file = /var/log/rsync.log port = 12000 [files] path = /home/public_rsync comment = RSYNC FILES read only = true timeout = 300 ``` `pid file`: The process id file the daemon uses. `lock file`: The daemon lock file. `log file`: The location of the log file. `port`: If you do not want the rsync daemon to run on its default port (873) then you may specify a new port here. Make sure this port is open in your firewall. Rsync uses the TCP protocol for its transfers. `[files]`: This is the module name. The name used here is what you’ll be putting in the rsync pull command as the first part of the source (/files/../..). You can name it what you’d like and can have as many as you’d like. `path`: The file path for files associated with this module. `comment`: Descriptive comment for this module. `read only`: This tells the daemon the directory for this module is read-only. You cannot upload to it. For upload only, use upload only = true. `timeout`: In seconds, the rsync daemon will wait before terminating a dead conenction. This is just a basic configuration. For a more detailed list of options, see the [manual page](http://linux.die.net/man/5/rsyncd.conf). ## Running Rsync as a Daemon Now with this basic configuration we can start the daemon by itself by running the below: ``` rsync --daemon ``` You can verify the daemon is running with: ``` ps x | grep rsync ``` > If you have anything weird in the output, such as a statement stating unconfined, you may have SELinux blocking the daemon. You will need to work to add rsync to be accepted by SELinux in order for you to run the daemon. . Now that the rsync daemon is running, it’s ready to accept connections. If you are unsure how to do connect from an rsync client, review our guide on [connecting with rsync](https://www.atlantic.net/vps-hosting/how-to-use-rsync-copy-sync-files-servers/). To stop the daemon you can run a `kill` command. ``` kill `cat /var/run/rsyncd.pid` ``` ## Running Rsync via Xinetd If you are already using xinetd to manage services, you can add rsync daemon control as well. While xinetd provides greater central control over running processes, note that it doesn’t necessarily mean greater security. First, edit the xinet.d file for rsync, if it already exists (if not, you can create it and use the example configuration below). Change the `disabled` line to `no`. You will also want to add the `port` line with either the default (873) or your custom port. > Note: If you are using a custom port, you will also need to edit the rsync port in the service file (`/etc/services`) to your custom port. Using your preferred text editor, create or edit `/etc/xinetd.d/rsync` as below: ``` # default: off # description: The rsync server is a good addition to an ftp server, as it \ # allows crc checksumming etc. service rsync { disable = no flags = IPv6 socket_type = stream port = 12000 wait = no user = root server = /usr/bin/rsync server_args = --daemon log_on_failure += USERID } ``` Now you just need to restart xinetd, and the rsync daemon should run. ``` /etc/init.d/xinetd restart ``` ## Testing the Rysnc Directories To test your connection to the rsync daemon and find which paths are available to you, simply connect from your client to the rsync host using the following method. This method runs only part of a pull command but will reveal paths for you. ``` rsync -rdt rsync://IPADDR:RsyncPort/ ``` ![Find file path](https://www.atlantic.net/wp-content/uploads/2018/01/Rsync2.png) *Find file path* This command will show which directories are open to you. If you do not know the file name you can repeat the process (adding onto the file path) until you find the intended file(s). ``` rsync -rdt rsync://IPADDR:RsyncPort/DirectoryName ``` ![More file paths discovered](https://www.atlantic.net/wp-content/uploads/2018/01/Rsync3.png) *More file paths discovered* And once you find the file, you can complete the command and pull it in. ``` rsync -rdt rsync://IPADDR:RsyncPort/DirectoryName/File /DestinationDirectory/ ``` ![Full path found](https://www.atlantic.net/wp-content/uploads/2018/01/Rsync4.png) *Full path found* ## Adding Usernames and Passwords to the Rsync Daemon You can make your rsync daemon more secure by adding a username and password requirement in its configuration file. Open `/etc/rsyncd.conf` with your preferred text editor, and enter these parameters under the module. ``` [files] path = /home/public_rsync comment = RSYNC FILES read only = true timeout = 300 auth users = rsync1,rsync2 secrets file = /etc/rsyncd.secrets ``` `auth users`: List of users, separated by commas. They do not necessarily need to exist on the system, but they do need to exist in the secrets file. `secrets file`: File path to your secrets file containing the usernames and passwords list. Using your preferred text editor, open or create your `/etc/rsyncd.secrets` file. Use the following format `username:password`. ``` rsync1:9$AZv2%5D29S740k rsync2:Xyb#vbfUQR0og0$6 rsync3:VU&A1We5DEa8M6^8 ``` Once you have saved this file, secure it so only the root user can read or edit it. ``` chmod 600 /etc/rsyncd.secrets ``` Note that we added an rsync3 user, which we did not specify in the auth users parameter in `/etc/rsyncd.conf`. You’ll see why below. Now, when connecting to this rsync daemon, you’ll need to be sure to use the appropriate username. ![valid rsync user](https://www.atlantic.net/wp-content/uploads/2018/01/Rsync5.png) *Valid rsync user* If you try to connect with a user not permitted in the auth users, you will get the below error. ![invalid rsync user](https://www.atlantic.net/wp-content/uploads/2018/01/Rsync6.png) *Invalid rsync user* Just remember that authorized users must appear in both the `/etc/rsyncd.conf` and the `/etc/rsyncd.secrets` files. And that’s it for the basics of an rsync daemon. You should now be able to create a basic rsync daemon and have directories specified for uploading, downloading, or both! Please check back here for more updates and to consider a market-leading Linux VPS hosting server from Atlantic.Net. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [Virtual private servers.](https://www.atlantic.net/vps-hosting/) --- # What Is UART (Universal Asynchronous Receiver/Transmitter) > URL: https://www.atlantic.net/vps-hosting/what-is-uart-universal-asynchronous-receiver-transmitter/ | Published: 2015-09-28 | Updated: 2026-03-04 | Author: Alexander Wise ##### ***Target Audience*** *This article assumes that the reader has a basic understanding of electronic devices, circuits, and terminology.* ## Introduction In the world of embedded device communications, there is a small handful of protocols that are used for many different applications. It is often the case that more common protocols that are commonly used for everyday operations, such as FTP and TCP, either do not work with small embedded devices or are unsuitable (often due to power or space requirements). It is in cases like these that more basic, ‘down to the metal’ communications standards such as UART are very useful. ## What is UART? ![Example of UART Device](https://www.atlantic.net/wp-content/uploads/2015/09/uart1.png) Image [Exar16550onItronixPCB by Wikipedia user Myself248](https://commons.wikimedia.org/wiki/File:Exar16550onItronixPCB.jpg#/media/File:Exar16550onItronixPCB.jpg) / Licensed under [CC BY-SA 3.0](https://creativecommons.org/licenses/by-sa/3.0/) UART (Universal Asynchronous Receiver/Transmitter) is a small, efficient communications device, similar to [I2C](https://www.atlantic.net/vps-hosting/what-is-i2c-inter-integrated-circuit/). UART is most often installed in a piece of hardware, embedded in an IC (integrated circuit), that translates communicated data between serial and parallel forms. In other words, a UART device takes a stream of bits of data (most often designed for parallel communication), converts it to bits of serial data for transmission down a single wire, or bus, and then transmits it. At the other end of the wire, another UART device receives the serial bits and converts them back into parallel packages of data. The “Universal” portion of the name refers to the configurability of both the data format and the speeds at which it is transmitted/received. . UART is one of the oldest communication devices used by computers, dating its origins back to the 1960s when it was used to connect computers to teletypewriter keyboards, or “teletypes”. In the 1970s it was the protocol used to read and write data to cassette tapes, and later it was used to communicate with modems during the early dial-up days of BBS (Bulletin Board System) services and the Internet. It has since been supplanted with more complex devices that use protocols such as TCP and IP, but its design is still useful with embedded devices.. ## How UARTs Communicate As mentioned above, UART works by translating between parallel communication and serial communication. Why do this at all, since parallel communication is so much faster? While parallel communication is faster, it’s also much more expensive in terms of both power and the transmission medium. You can send the same batch of data in sequential serial bits, one by one, down a single wire, rather than in synchronized parallel bits, simultaneously, down a bunch of wires. If your application is starved for space, for instance, it may make much more sense to only use one wire. For this reason, UART devices come in very handy in low-power, low-profile situations, such as embedded systems. . So how does it work, exactly? The nice thing about asynchronous transmission is that the data can be transmitted without the sender and receiver having to share a clock signal–a signal that can take up valuable data space. Instead, timing is agreed upon in advance between both units, and special bits are added to each data package–each “word”. UARTs use these bits to synchronize to each other. When the transmitter is preparing to send a word, it adds a special START bit to the beginning of the package. This bit alerts the receiver that a data package is coming its way and synchronizes the receiver’s internal clock with the transmitter’s. (Normally, for other transmitter/receiver pairings, all that is necessary to synchronize the two device clocks is that they agree on a transmission speed in bits per second, or “baud”.) . After the START bit, the transmitter sends the word. Most UART systems use word lengths of five to ten bits. Bit transmission occurs over a consistent clock time, and the time-synchronized receiver looks at the bus exactly halfway through a designated ‘send’ time to determine if a 1 or a 0 is being sent (if the bus is HIGH, a ‘1’ is being sent; otherwise, it’s a ‘0’). Finally, the transmitter sends a parity bit (if the system has been configured that way) and an END bit. Then it starts another word with another START bit, and the process continues. The receiver, meanwhile, discards the START and STOP bits, uses the parity bit if necessary, records the word, and continues to listen for more data. If the circuit is a duplex (two-way communication) setup, then the same process can repeat in the opposite direction. In some UART systems, wires are not even necessary; infrared (IR) and Bluetooth devices are often set up to transmit and receive via the UART signaling scheme. > **Historical bit of trivia**: When nothing is being transmitted, the line is held HIGH by both devices, rather than LOW (unpowered.) This convention is a holdover from the days of the telegraph–telegraph lines were held high so each end user could tell that the line was unbroken.. ## Uses for UARTs Persist UART devices have been around for a long time, and have proven themselves still useful, even alongside devices capable of higher speed communications and gigabit transfer speeds made possible today with fast [VPS hosting](https://www.atlantic.net/vps-hosting/) servers and [managed server hosting](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/). . Most modern microcontrollers contain a UART device; single ICs can contain one, two, or even 8 UARTs on one chip (these last two designs are called DUARTs and OCTARTs, respectively). The Arduino — the popular hobbyist microcontroller IDE — has a UART interface built in on every one of its boards, even the smallest of them. The Raspberry Pi, another popular hobbyist device, can also interface with UART devices. For anyone interested in working with small embedded devices, it’s a worthy device to learn to use. . --- # Atlantic.Net Cloud – How to Add a Private IP on Fedora > URL: https://www.atlantic.net/vps-hosting/atlantic-net-cloud-how-to-add-a-private-ip-on-fedora/ | Published: 2015-09-30 | Updated: 2026-03-02 | Author: Alexander Wise ##### Verified and Tested 09/27/2015 ## Introduction This guide will take you through how to add a private IP address to a Fedora server. This guide has been tested with Fedora 30, 31, and 32. One thing to note before we start is that our [cloud hosting service](https://www.atlantic.net/vps-hosting/)automatically uses eth1 as the private interface. ## Prerequisites -A private IP to add to your server. If using an Atlantic.Net Cloud VM, this would be an IP from your assigned Private IP range. -A server with Fedora installed on it. ## Adding a Private IP on Fedora Log in to your cloud control panel and click on “Private IP’s” to see what private range has been allocated to you. ![Assigned Private range.](https://www.atlantic.net/wp-content/uploads/2021/03/How-to-add-a-private-IP-on-Centos.png) Assigned Private range. ## Assigning the IP in Fedora Assigning a Private IP on Fedora is pretty simple. You simply edit the configuration and restart networking. In our Cloud example below, the private interface is known as eth1. So we run: ``` nano /etc/sysconfig/network-scripts/ifcfg-eth1 ``` If you do not have nano installed, you may do so by running: ``` yum install nano -y ``` Once opened, add the below configuration to the bottom of the file. ``` IPADDR=x.x.x.x NETMASK=255.255.255.0 ``` Where *IPADDR=* your private IP address and the *NETMASK=* is the range’s netmask for your IP. In our Cloud, this would be a /24 private IP range so the netmask is 255.255.255.0. Once this is complete, simply restart networking with the below command and the IP will be active for use. ``` systemctl restart network ``` You can now verify your newly assigned IP address using the following command. ``` ifconfig eth1 ``` You should get your newly assigned IP address in the following output: ``` eth1: flags=4163 mtu 1500 inet x.x.x.x netmask 255.255.255.0 broadcast x.x.x.x inet6 fe80::200:aff:fef5:2467 prefixlen 64 scopeid 0x20 ether 00:00:0a:f5:24:67 txqueuelen 1000 (Ethernet) RX packets 1554 bytes 133751 (130.6 KiB) RX errors 0 dropped 0 overruns 0 frame 0 TX packets 41 bytes 2862 (2.7 KiB) TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0 ``` And that’s it. Configure another server on the private IP range and you will be able to communicate between the two. Make sure you add an exception for the IP/range to any firewall that may be on the server. --- # How to Add an Additional IP on Arch Linux > URL: https://www.atlantic.net/vps-hosting/how-to-add-an-additional-ip-on-arch-linux/ | Published: 2015-09-30 | Updated: 2026-03-02 | Author: Alexander Wise ##### Verified and Tested 08/12/2015 ## Introduction This guide will show you how to add an additional public and/or private IP on your Arch Linux server. ### Prerequisites -An [Arch Linux server](https://www.atlantic.net/vps-hosting/) and an additional public IP reserved and assigned to the server or a private IP chosen for your granted private IP range. -Netctl installed on the server. ## Adding an Additional IP on Arch Linux The first thing we will need to do is create a netctl file for eth0 (or edit the current one if it exists.) In our case the file /etc/netctl/eth0 exists, so we’ll edit that and add our additional IP address, y.y.y.y/xy. ``` nano /etc/netctl/eth0 ``` ``` Connection='ethernet' Description='Eth0 IPs' Interface='eth0' IP='static' Address=('x.x.x.x/xy' 'y.y.y.y/xy') Gateway='xg.xg.xg.xg' DNS=('209.208.127.65' '209.208.25.18') ``` *Connection* is the connection type. *Description* is a custom description for the connection. You can use what you’d like. *Interface* is the interface we will be using for the connection. *IP* is the type the IP will be. Usually this is static or DHCP if you have IP allocation by DHCP available. *Address* is the list of IP addresses and their associated subnets.  Each IP address needs to be contained inbetween a pair of ‘ ‘ and separated by a space. They need to contain their associated subnet in order to work. This is where you list your main IP and then any additional IP addresses. *Gateway* is the default gateway for the server. This should be the main IP’s gateway and no others. *DNS* would be the DNS servers. In this instance I used the Atlantic.Net DNS servers.   We then need to restart this by running: ``` netctl restart eth0 ``` Once up, you should be good to go and the additional IP should now respond.   ## Adding an Private IP on Arch Linux To do a private IP we would need to create a new netctl file that we’ll name eth1. It is essentially the same as adding a public IP only this uses the private interface. ``` nano /etc/netctl/eth1 ``` ``` Description='Private ethernet connection' Interface=eth1 Connection=ethernet IP=static Address=('x.x.x.x/xy') ``` You can add as many private IPs as you’d like following the IP addition example in the Public IP section. Simply add more IPs between a pair of ‘ ‘ and separated by a space. Once saved, just bring it up with: ``` netctl start eth1 ``` Once this is up, your private IP will start working.   That’s all there is to adding a new IP address on an Arch Linux system. --- # Atlantic.Net Cloud – How to Add a Private IP on Windows Server 2012 R2 > URL: https://www.atlantic.net/vps-hosting/atlantic-net-cloud-how-to-add-a-private-ip-on-windows-server-2012-r2/ | Published: 2015-09-30 | Updated: 2026-03-02 | Author: Alexander Wise ##### Verified and Tested 09/27/2015 ## Introduction This guide will take you through how to add a private IP address to a Windows Server 2012 R2 server. One thing to note before we start is that our [Cloud hosting](https://www.atlantic.net/vps-hosting/) service automatically uses the second interface as the private interface. ## Prerequisites -A private IP to add to your server. In our Cloud’s case, this would be an IP from your Private IP range. -A server with Windows Server 2012 R2 installed on it. ##  Add a Private IP on Windows Server 2012 R2 Login to your cloud control panel and click on “Private IP’s” to see what private range has been allocated to you. ![](https://www.atlantic.net/wp-content/uploads/2015/09/How-to-add-a-private-IP-on-Centos-11.png) ## Getting Started Assigning a Private IP on Windows Server 2012 R2 is pretty simple. Open up the Networking and Sharing Center so we can edit the Network Interface. For a guide on that,[please visit here](https://www.atlantic.net/vps-hosting/how-to-open-network-sharing-center-windows-server-2012/). Click on “Change adapter settings” ![](https://www.atlantic.net/wp-content/uploads/2015/09/anet-windows-2008r2-public-ip-adapter-settings.png) Right click on Local Area Connection 2 and enable it. You will then want to right click the interface again and go to Properties. ![](https://www.atlantic.net/wp-content/uploads/2015/09/anet-private2008-00.png) Now click on “Internet Protocol Version 4 (TCP/IPv4)” and click “Properties”. ![](https://www.atlantic.net/wp-content/uploads/2015/09/anet-windows-2008r2-public-ip-ipv4.png) Once in the Properties, select “Use the following IP address.” We are going to add the IP address that we have selected in the field for IP address. We will then add it’s associated Netmask to the Subnet mask field. Once done, click on Ok and you can close the other windows out because we are now done. ![](https://www.atlantic.net/wp-content/uploads/2015/09/anet-private2008-01.png) IPv4 for Private And that’s it. Configure another server on the private IP range and you will be able to communicate between the two. Make sure you add an exception for the IP/range to any firewall that may be on the server.  As always, Atlantic.Net offers the best [Windows Cloud hosting](https://www.atlantic.net/vps-hosting/) solutions to you. --- # How to: FreeBSD Remote Administration > URL: https://www.atlantic.net/vps-hosting/how-to-freebsd-remote-administration/ | Published: 2015-09-30 | Updated: 2026-03-02 | Author: Alexander Wise ##### Verified and Tested 08/31/15 ## Introduction Remote administration has become more popular, than ever before. Due to the rise of virtualization and Cloud VPS Servers, it has become a necessity in many small to large scale networks. In this How-to, we will be going over the Remote Administration in FreeBSD. ## Prerequisites You need a FreeBSD server that is configured with a static IP address. If you do not have a server already, visit our page for [fast and reliable VPS Hosting](https://www.atlantic.net/vps-hosting/) and spin a new server up in under 30 seconds. ## Verifying Open SSH in FreeBSD In order for you to access your FreeBSD server remotely, we must verify that the SSH service is currently enabled. To check if SSH is enabled on your server, you can accomplish this by typing the following command: ``` less /etc/rc.conf ``` ## Enabling SSH in FreeBSD If Open SSH is not enabled on your server, you could enable it by first opening the **/etc/rc.conf** file: ``` vi/etc/rc.conf ```  Than locate the sshd_enable line and set sshd_enable to YES. ``` sshd_enable="YES" ``` ## Starting Open SSH in FreeBSD After making the above change, we need to make sure that SSH is enabled and running. Start it with the following command: ``` /etc/rc.d/sshd start ``` ## Stopping Open SSH in FreeBSD If you wish to stop the Open SSH service, you could accomplish this with the following command: ``` /etc/rc.d/sshd stop ``` ## Restarting Open SSH  in FreeBSD If you would like to restart the Open SSH service, you could accomplish this with the following command: ``` /etc/rc.d/sshd restart ``` ## Allowing Root Login in FreeBSD To access your server using the root user, we must make sure that this is allowable in the Open SSH configuration file. Using your vi text editor open up the sshd_config configuration file with the following command: ``` vi /etc/ssh/sshd_config ``` With the sshd_config configuration file open, locate the line that reads “PermitRootLogin” and make sure that its set to yes. ``` PermitRootLogin yes ``` Once you have completed this, save your changes and restart the service with the following command: ``` /etc/rc.d/sshd restart ``` ## Testing OpenSSH in FreeBSD If you are using the a Linux server to remote into your FreeBSD server, you can accomplish this with the following command replacing the IP address with the IP of your FreeBSD server. ``` ssh root@10.50.2.10 ``` In like many Linux systems out there, the default Open SSH port is 22. However, this can be changed in the sshd_config configuration file to anything you want(I will be using my custom port 1050). To successfully accomplish this task,  you will have to add a **-p** followed by the custom port. ``` ssh root@10.50.2.10 -p 1050 ``` If you are using the a Windows system to remote into your FreeBSD server, you will need to download a 3rd party SSH client. [Putty is the most common Open SSH Windows Client and could be downloaded here.](https://www.putty.org) There are 3 things that you need to have in mind. The Host Name (IP address) section where your FreeBSD server’s IP will go, the Port section where by default is set to 22(it can be changed to your custom port also) and the Connection type section where SSH must be selected. Below is a screen shot of how the putty interface looks like. ![This is the Putty interface when using SSH in a Windows System](https://www.atlantic.net/wp-content/uploads/2018/01/FreeBSD-Remote-Administration.png) This is the Putty interface when using SSH in a Windows System ## Copying Files Securely FreeBSD Since security is a big concern nowadays, FreeBSD had a built-in feature that allows you to securely copy files from a private or public network using encryption. This feature is called SCP! There is a similar tool for use on Windows systems called [WinSCP](https://winscp.net/eng/index.php), make sure to check it out as well! Our first task is to copy a file from a remote location to my local root directory. Give it a try with the following command where Remote IP=10.50.2.10, Remote File=myremote.file and **/root/** being your local root directory. ``` scp root@10.50.2.10:/root/myremote.file /root/ ``` Our second task is to copy a file from a remote location to your current directory. Give it a try with the following command where Remote IP=10.50.2.10, Remote File=myremote.file and **./** being your current directory. ``` scp root@10.50.2.10:/root/myremote.file ./ ``` Alternatively, if you are using a custom port, simply add the**-P 1050** after scp to put the file in your current directory. ``` scp -P 1050 root@10.50.2.10:/root/myremote.file ./ ``` ## Copying Directories Securely in FreeBSD TO copy a directory from a remote location to your local root directory. Give it a try with the following command where **-r** =Directory variable, Remote IP=10.50.2.10, Remote File=myremotedb and **/root/** being your local root directory. How to copy a directory from another client to your machine ``` scp -r root@10.50.2.10:/root/myremotedb /root/ ``` Alternatively, if you want to accomplish the same task with a custom port, then you could complete this with the following command: ``` scp-rP 8000 root@10.50.2.10:/root/myremotedb /root/ ``` ## Copying Remote Files Securely in FreeBSD If you want to copy a file from another system into yours, you can accomplish this with the following command. To understand the command, Remote File=myremote.file, Remote IP=10.50.2.10 and **/root/** being your local root directory. ``` scp myremote.file root@10.50.2.10:/root/ ``` Alternatively, if you want to accomplish the same task with a custom port, then you could complete this with the following command: ``` scp -P 8000 database.backup root@10.50.2.10:/root/ ``` Furthermore, if you would like to copy multiple files from a remote location, then you could complete this with the following command adding each file separated with a space. ``` scp myremote.file myremote.file2 root@10.50.2.10:/root/ ``` ## Copying Remote Directories Securely in FreeBSD To copy a directory from another system into yours, you can accomplish this with the following command. To understand the command -r = Directory variable, Remote Directory=myremotedb, Remote IP=10.50.2.10 and **/root/** being your local root directory. ``` scp -r myremotedb root@10.50.2.10:/root/ ``` Alternatively, if you want to accomplish the same task with a custom port, then you could complete this with the following command: ``` scp -rP 8000 myremotedb root@10.50.2.10:/root/ ``` ### What Next? Congratulations! This completes this tutorial on FreeBSD Remote Administration. I hope that you find this information useful just like it was to me. Thank you for following along this how-to! Check back with us for further updates and, try a [reliable VPS](https://www.atlantic.net/vps-hosting/) solution from Atlantic.Net. --- # How to SSH to Server via Linux > URL: https://www.atlantic.net/vps-hosting/how-to-ssh-server-via-linux/ | Published: 2015-10-01 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 09/27/2015 ## Introduction In this article we will walk you through on how-yo SSH into your Linux Server from another Linux Server. SSH is a cryptographic network protocol that was made to replace telnet and allows local computer to authenticate with a remote server. ## Prerequisites Linux Server with SSH running. Second Linux server with SSH running. ## How to SSH into your Linux Server from another Linux Server. First, you will need to log into your first Linux Server.  If you are unsure on how to log into your Linux Server from your Windows computer,[please visit this article.](https://www.atlantic.net/vps-hosting/how-to-ssh-linux-server-windows/) You will then be prompted to enter your Username and Password for the server. For security reasons, the password is not shown as you type. Once logged into your first Linux server, to SSH into your second Linux server you will run the following command: ssh . Below is an example. ``` ssh 12.34.56.78 ``` *NOTE* By default, when a user is not specified, you will be connecting using your current user on the device initiating the SSH connection. If you want to connect to the second Linux server but with a different user other than the root user, you would run the following command: ssh user1@ ``` ssh user1@12.34.56.78 ``` When connecting to the second Linux server from the first Linux server for the first time, you will be prompted to add the server’s key fingerprint to the list of known hosts. ![SSHtoLinux](https://www.atlantic.net/wp-content/uploads/2018/01/ssh1-1.png) How to SSH into your second Linux server If you trust the second Linux server you are connecting to then you will type “yes” and press enter. Next, you will be prompted to enter the password of the user you are trying to use on the second Linux server. Once you enter the correct password, you will be logged into your second Linux server from the first Linux server. Other fun commands when using SSH. 1. If you are using a custom SSH port for the second Linux server, you would need to specify the port number. ``` ssh root@12.34.56.78 -p222 ``` 2.   Transfer SSH public key to another machine in one step ``` ssh-keygen; ssh-copy-id root@12.34.56.78; ssh root@12.34.56.78 ``` This will allow you to login to your second Linux server without having to use a password next time. Thank you for following along in this tutorial! Please check back for more updates and try one of Atlantic.Net’s [best VPS hosting solutions](https://www.atlantic.net/vps-hosting/). --- # How to Use Rsync to Copy Files from One Server to Another and Sync Servers > URL: https://www.atlantic.net/vps-hosting/how-to-use-rsync-copy-sync-files-servers/ | Published: 2015-10-02 | Updated: 2026-01-07 | Author: Alexander Wise ## Introduction Rsync is a great way to synchronize files between servers or move files between servers without needing FTP. It connects two servers via the SSH protocol, allowing for the transfer of data between them. The rsync daemon, covered later in this article, uses its own protocol and runs on a specified port. Below we’ll go over the basics; copying between servers, copying to/from rsync daemons, and keeping files in sync with each other on different servers. ## Prerequisites – 2 Linux servers that both have rsync installed. – The server initiating the transfer must be able to access the receiving server’s SSH port (or rsync port if connecting to a rsync daemon). – The user needs to have permission to use rsync (the examples below will be run as the root user). ## Basics of Rsync Rsync can push files to another server or pull files from another server. The difference between the two is in the syntax. If you specify your local file first, it will initiate a push. If you specify your remote host first, it will initiate a pull. Let’s see the exact type of syntax below. ``` rsync [-options] SOURCE user@x.x.x.x:DESTINATION ``` Pull: ``` rsync [-options] user@x.x.x.x:SOURCE DESTINATION ``` The `[-options]` are all the different options that can be used. Some I’ll reference and explain in examples below. For a full list of all the options, review the [manual page](http://linux.die.net/man/1/rsync). `SOURCE` stands for the `/directory/path/to/the/file/or/directory` which will be copied. `DESTINATION` stands for the `/directory/path/to/the/new/location` on the receiving host. The `user@` is the user on the remote host for rsync to connect with. `x.x.x.x` stands for the IP address of the remote host. It can also be a hostname if you have DNS configured. Now, say you need to specify a port outside of the default port 22 for rsync to connect to. You would do this with the option `-e`. See the example below (replace `PORT` it with the port number you need to connect to). Push: ``` rsync [-other options] -e 'ssh -p PORT' SOURCE user@x.x.x.x:DESTINATION ``` Pull: ``` rsync [-other options] -e 'ssh -p PORT' user@x.x.x.x:SOURCE DESTINATION ``` ## Simple File Transfer Examples First, we will initiate a push of a .txt file from one server to another. ``` rsync /home/simple.txt root@x.x.x.x:/home ``` This command will copy the file `simple.txt` from our local server to our remote server’s `/home` directory. ![Rsync Transfer between two servers.](https://www.atlantic.net/wp-content/uploads/2018/01/anet-rsync-001.png) Rsync Transfer between two servers. On the right, we did an `ls` before the rsync and then again after it was run, so we can see the file was copied. Here is an example of a pull: ``` rsync root@x.x.x.x:/home/pullme.txt /home ``` The file `pullme.txt` is on the remote server (x.x.x.x) in the `/home` directory. This command will copy the file to the local server’s `/home` directory. You can push/pull any single file you specify using this method. Now, let’s get into directories. ## Directory File Transfer Moving a directory is simple. Add the `-d` option, and it will move only the directory. If you want to move the directory and its contents, use `-r` instead to recursively copy over all files and subfolders. While we’re at it, let’s tack on the `-t` option. This option will copy the date and time that the file was last changed. Using `-t` is good for keeping accurate records of when a file was last edited. These options will work with pushing or pulling. In the below example, I have moved the `pullme.txt` file into a `/transfer_me` directory. I have also created the directory `/simple` (which contains the file `simple.txt`) inside `/transfer_me`. I then pushed the `/transfer_me` directory to the remote server. ``` rsync -rt /home/transfer_me root@x.x.x.x:/home ``` ![transfering a directory](https://www.atlantic.net/wp-content/uploads/2018/01/anet-rsync-021.png) As you can see, the remote (receiving) folder contains all the subdirectories and files that the local folder did on the initiating server. ## Connecting to an Rsync Daemon This section requires a server running a rsync daemon. To test these instructions out, see our article on [setting up a rsync daemon](https://www.atlantic.net/vps-hosting/how-to-setup-rsync-daemon-linux-server/). Now that we’ve gone over basic file/directory transferring with rsync, we can go over connecting to a rsync daemon. An rsync daemon runs constantly on a server, so you can push to and/or pull from that server’s assigned rsync daemon directory at any time. There are two formats for pulling and pushing to a rsync daemon. Pull: ``` rsync [-options] rsync://user@x.x.x.x[:PORT]SOURCE DESTINATION ``` Pull (note the double colons after the IP address/hostname): ``` rsync [-options] user@x.x.x.x::SOURCE DESTINATION ``` Push: ``` rsync [-options] SOURCE rsync://user@x.x.x.x[:PORT]DESTINATION ``` Push (note the double colons after the IP address/hostname): ``` rsync [-options] SOURCE user@x.x.x.x::DESTINATION ``` See below how I pulled from the rsync daemon (the use of port number 873 below is redundant since that’s the default rsync daemon connection port–I include it to demonstrate how you would format the command if you had set up a non-default port on your rsync daemon): ``` rsync -rt rsync://root@x.x.x.x:873/files/ /home/pulledfromdaemon ``` ![Rsync daemon pull](https://www.atlantic.net/wp-content/uploads/2018/01/anet-rsync-031.png) Here, `files` is the module name. Since we’re pulling everything in that directory (`pullme.txt` and `simple.txt`) We leave it at the module name for the source. ## Syncing Files with Rsync Now we’ll discuss how to sync files. You can perform a sync with a single rsync command with the right options. You can put this command in a script or cron job to run on demand or automatically. The command varies if you are pushing or pulling or using the daemon, but the options remain the same. ``` rsync -rtu --delete SOURCE root@x.x.x.x:/DESTINATION ``` In this example, pay attention to the `-rtu --delete` options. We have already discussed the `-r` and `-t` options–recursive copy and time stamp copy. The `-u` option tells rsync to update only different/changed/added files from the `SOURCE` to the `DESTINATION`. The option `--delete` will remove any files from  `DESTINATION` that the `SOURCE` may no longer have. With this (and other options, like `-l` for symlinks) you can keep directories in multiple locations up to date with the source. You can now rsync files between servers, rsync daemons, and keep files synced with each other easily. Thank you for following this how-to! Please check back here for more updates, or take a look at the many services we offer, including [VPS hosting](https://www.atlantic.net/vps-hosting/). Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [Virtual private servers.](https://www.atlantic.net/vps-hosting/) --- # What is MySQL vs. MariaDB vs. Percona > URL: https://www.atlantic.net/vps-hosting/what-is-mysql-vs-mariadb-vs-percona/ | Published: 2015-10-07 | Updated: 2026-07-23 | Author: Alexander Wise ##### ***Target Audience*** *This article assumes you have at least a passing familiarity with databases and some of the terminology around their features.* ## Introduction Databases back every application, and there are many choices. MySQL has long been a popular open source choice; however, MariaDB and Percona are two major code forks that can replace MySQL with enhanced features. This article offers a broad comparison of the three. ![Illustration by Walker Cahall](https://www.atlantic.net/wp-content/uploads/2018/01/mysql1.png) Illustration by [Walker Cahall](http://www.waltronic.net/) ## MySQL ![MySQL Logo](https://www.atlantic.net/wp-content/uploads/2018/01/mysql2.png) *Image: [MySQL](https://www.atlantic.net/wp-content/uploads/2015/10/Database-mysql.svg_.png) / Licensed under [CC BY-SA 3.0](http://creativecommons.org/licenses/by-sa/3.0)* MySQL is a widely known, very popular open source relational database management system (often abbreviated RDBMS). It was developed as a high-availability, reliable database for web-based applications in the 1990s. Although open source, it is owned by Oracle, who offers it as a free community edition under the GPL ([GNU General Public License](http://www.gnu.org/licenses/gpl.html)) and as a commercially licensed version. The Oracle version of MySQL is a common installation on many hosts, a part of the classic [LAMP and WAMP](https://www.atlantic.net/hipaa-compliant-hosting/lamp-vs-wamp/) stacks, and the default database for WordPress. Its strength lies in its longevity. The code base is very stable and reliable for the kind of web applications it was designed to support. There is a large community of MySQL users and administrators, and, as a result, a large collection of information published for MySQL, both on the web and in print. Its weaknesses, in comparison to the other two databases, lie in its governance. Many in the open source community consider Oracle a blocking force to the open source nature of the original project. Also, because of the dual licensing model, certain applications require a commercial license. ## MySQL vs MariaDB/Percona When MySQL was acquired by Sun and then Oracle, groups left to start their own forks of the MySQL code. That brings us to MariaDB and Percona. Both are built to be drop-in replacements of MySQL. Applications that work with MySQL should also work with either of these forks. Despite being competitors, each fork draws from the open source code of the other. For example, MariaDB offers the XtraDB engine from Percona. Percona has picked up some of the optimizations and thread pool improvements from MariaDB. Both have improved over the base MySQL, including fixing subqueries. ## MariaDB ![MariaDB Logo](https://www.atlantic.net/wp-content/uploads/2018/01/mysql3.png) *Image: [MariaDB](https://www.atlantic.net/wp-content/uploads/2015/10/Mariadb-seal-browntext.svg_.png) / Licensed under [CC BY-SA 3.0](http://creativecommons.org/licenses/by-sa/3.0)* The MariaDB fork leans toward expanding the breadth of MySQL’s capabilities and is less conservative about adding new features than Percona. MariaDB has pushed toward making advances with the query optimizer. It’s a potentially better choice if you cannot determine what kind of queries your project needs regularly. Some other features that distinguish MariaDB include the following: - MariaDB includes a larger array of storage engines than either MySQL base or Percona, including now a NoSQL option with Cassandra. It also includes Percona’s XtraDB as an option. - As of version 10.1, MariaDB offers on-disk database encryption. - MariaDB offers scalability features including multi-source replication, allowing a single server to replicate from several sources. - The interaction of the Global Transaction IDs between MariaDB and MySQL might require careful implementation if you plan to have complex replication schema bridging MySQL flavors. For example, it is possible to replicate from MySQL 5.6 into MariaDB 10.X, but not the reverse. Overall MariaDB is a mature future-looking branch of MySQL that aims to offer new features and advancements for the database. It is appropriate for large multi-server [VPS hosting](https://www.atlantic.net/vps-hosting/) applications, especially those with changing query patterns that can take advantage of MariaDB’s optimizer. ## Percona Server Percona has concentrated on very demanding applications with their own high-performance alternative to the InnoDB storage engine called XtraDB, including instrumentation tools to tune it. Their features tend toward performance, availability, and scalability improvements for the largest databases with the highest throughput. On their website, [Percona claims to be closer to the base MySQL code from a compatibility point of view and more conservative than MariaDB](https://docs.percona.com/percona-server/8.4/faq.html). Other features favoring Percona include the following: - In their push for performance, Percona offers more counters and diagnostics to measure performance and to tune the database. - Percona has scalability enhancements for large databases, including some features in their free Server product that are only available in the Enterprise level of MySQL. - Percona also has extra tools beyond the DB engine including an XtraDB Cluster and an XtraBackup utility. Like MariaDB, Percona is a mature open-source branch of MySQL. Their focus is more on the performance of the biggest and the most demanding databases with the tools to achieve and maintain that performance. ## So Which Is Actually Better? As in most things in tech, the answer is “it depends.” Much of the debate seems to be a two-stage argument rather than a three-way battle. The first stage is MySQL versus one of its replacements. You have to decide if you even need a change. The forks enhance the base MySQL with performance improvements and with additional features and tools. Performance becomes a bigger deal the larger your database is, so small databases are less likely to see much of that benefit in the forks. But there could be other reasons to head for a replacement, such as licensing or data flexibility. If you decide for a drop-in, then the discussion turns to which one. It would be too easy to look at even the comparison above and say that MariaDB doesn’t care about performance or that the optimizer in Percona is subpar. That is not at all true. Both forks excel at the basic database level. They differentiate more as you reach the edge of the envelope. Then what is more important? If it’s the ability to store flexible types of data across a number of different sources, check out MariaDB first. If you have a larger database that still requires snappy performance, start your search with Percona. Even still, don’t ignore the other branch fully. Some of their tools, because of the common MySQL root, can work with either branch and could be just the solution you need. If you have outgrown MySQL and want to reach into one of the forks, but you aren’t at the bleeding edge of size or flexibility, then the decision seems to be one of taste. Which company offers you the services or tools that you would use anyway? Still not sure, or want to do more in-depth reading? Take a look at some of following comparisons the MariaDB and Percona folks have put together. - [Percona Feature Comparison](https://www.percona.com/doc/percona-server/5.6/feature_comparison.html) - [MariaDB vs. MySQL Features](https://mariadb.com/kb/en/mariadb-vs-mysql-features/) - [Features of MariaDB 10](https://www.percona.com/live/mysql-conference-2013/sites/default/files/slides/mariadb10andwhatsnewwiththeproject-130426094744-phpapp01.pdf) --- # How to Try PHP7 in a LAMP Stack on Ubuntu 14.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-try-php7-lamp-stack-ubuntu-14-04/ | Published: 2015-10-08 | Updated: 2026-02-28 | Author: Alexander Wise ##### Verified and Tested 10/8/15 ## Introduction In this How-To, we will install a LAMP Stack on an Ubuntu 14.04 Cloud Server with PHP7. PHP7  should be released sometime in November 2015 and if you plan on adopting the new version, now is a great time to test your code. This guide will give you the option to install the Beta1 build or the newest nightly build of PHP7. If you’d like to learn more about PHP7, read our articles [What is PHP7 – Breaking Changes from PHP5](https://www.atlantic.net/dedicated-server-hosting/what-is-php7-breaking-changes-php5/) and [What is PHP7 – Performance Improvement](https://www.atlantic.net/hipaa-compliant-hosting/what-is-php7-performance-improvements/). > **NOTE: PHP7 is still in development and should not be used in production environments until it is fully released.** ![PHP7 Elephant created by Walker Cahall http://www.waltronic.net/](https://www.atlantic.net/wp-content/uploads/2018/01/php71.png) PHP7 Elephant created by [Walker Cahall](http://www.waltronic.net/) ### Prerequisites A server with Ubuntu 14.04  installed is required, which will take care of the Linux portion of the LAMP stack install. ## Installing LAMP on Ubuntu 14.04 with PHP7 To get PHP7 working we need to add the early access repo with the following command: ``` sudo echo "deb http://repos.zend.com/zend-server/early-access/php7/repos ubuntu/" >> /etc/apt/sources.list ``` Once added we should make sure our system is up to date with the following command: ``` sudo apt-get update ``` ## Installing Apache on Ubuntu 14.04 Install Apache by running the following command: ``` sudo apt-get install apache2 ``` Hit `enter` to when it asks “Do you want to continue?” during the install. After installing, check to see if Apache is running by running the command: ``` sudo service apache2 status ```  You can also verify if Apache is  working by opening your browser and going to http://youripaddress If you do not know your IP address,  run the following command: ``` ifconfig ``` ![An example of ifconfig showing the IP address of 172.20.6.154](https://www.atlantic.net/wp-content/uploads/2018/01/php72.png) An example of ifconfig showing the IP address of 172.20.6.154In our case, we would put http://172.20.6.154 in our browser’s address bar and get the following page: ![The default page for Apache on Ubuntu 14.04](https://www.atlantic.net/wp-content/uploads/2018/01/php73.png) The default page for Apache on Ubuntu 14.04 ## Installing MariaDB on Ubuntu 14.04 Install MariaDB with the following command: ``` sudo apt-get install mariadb-server ``` Hit `enter` when it asks “Do you want to continue?” during the install. During the install, it will prompt you to enter a MariaDB root password. Set any password that you would like. It should be a strong password. ![Enter a strong password of your choice](https://www.atlantic.net/wp-content/uploads/2018/01/php74.png) Enter a strong password of your choiceAfter you enter your MariaDB root password, you will need to re-enter it. ![Re-enter the password you set before](https://www.atlantic.net/wp-content/uploads/2018/01/php75.png) Re-enter the password you set beforeContinue with the MariaDB Security installation with the following command: ``` sudo mysql_secure_installation ``` Note: You will be prompted with a series of questions. Just type N for the change root password question and Y for yes on all of the rest, see the screen shot below: ![An example of what mysql_secure_installation looks like](https://www.atlantic.net/wp-content/uploads/2018/01/php76.png) An example of what mysql_secure_installation looks likeVerify that MariaDB is running with the following command: ``` sudo service mysql status ``` ## Installing PHP7 on Ubuntu 14.04 We can now go ahead and install either the beta or the nightly release for PHP7. I would suggest the nightly release as it has fixed more bugs than the beta. #### To install the PHP7 Nightly Build: ``` sudo apt-get install php7-nightly ``` #### To install the PHP7 Beta 1: ``` sudo apt-get install php7-beta1 ``` Hit `Enter` when it asks “Do you want to continue?” during the install. You will also get a warning similar to the following ``` WARNING: The following packages cannot be authenticated! php7-nightly Install these packages without verification? [y/N] ``` Type `Y` and then hit `Enter` to continue. ## Getting PHP7 to work with Apache We need to move the modules and libraries of PHP7 into the appropriate Apache directories with the following commands: ``` sudo cp /usr/local/php7/libphp7.so /usr/lib/apache2/modules/ ``` ``` sudo cp /usr/local/php7/php7.load /etc/apache2/mods-available/ ``` We now need to edit `/etc/apache2/apache2.conf` and add the following lines to the bottom of the file. ``` SetHandler application/x-httpd-php ``` Once added run the following command to enable the PHP mpm module and switch to mpm_prefork. ``` sudo a2dismod mpm_event && a2enmod mpm_prefork && a2enmod php7 ``` Since we made changes, we need to restart Apache so that the changes take effect: ``` sudo service apache2 restart ``` ## Testing PHP 7 on Ubuntu 14.04 To test out PHP7, we need to create a PHP file a named info.php in `/var/www/html/`  using your favorite editor and insert the following lines of code. ``` ``` Test out this  page in your browser with the following hyperlink with your IP address: http://youripaddress/info.php ![The result of the php.info file you made, using PHP7](https://www.atlantic.net/wp-content/uploads/2018/01/php77.png) The result of the php.info file you made, using PHP7Check the PHP version at the top of the page it should be 7.0 or higher. It’s a good idea to remove your info.php as hackers can set up attacks as they know more information about your server. Remove it with the following command: ``` sudo rm /var/www/html/info.php ``` Congratulations! You have just installed PHP7 with LAMP on your Ubuntu 14.04 Server. Thank you for following this How-To, and please check back for more updates or learn more about our reliable [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) and [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) solutions. --- # How to Install PHP 8 on Debian 12 > URL: https://www.atlantic.net/dedicated-server-hosting/install-php-8-debian12/ | Published: 2015-10-09 | Updated: 2026-02-28 | Author: Alexander Wise ## Introduction PHP is a powerful, server-side scripting language designed for web development. It’s the backbone of many popular platforms such as WordPress, Drupal, Joomla, and a wide range of modern web applications. Running the latest PHP version ensures better performance, access to new features, and improved security. By default, Debian 12 includes stable PHP packages in its official repositories, but they are not always the most recent releases. For developers who want the latest PHP version, the recommended option is to use the SURY repository, maintained by Ondřej Surý, the official Debian PHP package maintainer. This repository is widely trusted and provides up-to-date PHP versions for Debian systems. In this tutorial, you’ll learn how to install PHP 8.4 on Debian 12. ## Step 1 – Add the PHP PPA Repository Debian 12 ships with PHP packages in its official repositories, but these versions may not always include the latest release. To access the newest PHP builds, you need to enable the SURY repository, which is actively maintained and trusted by the Debian community. 1. First, update your package list and install the required dependencies. ``` apt update -y apt install -y lsb-release apt-transport-https ca-certificates ``` 2. Next, download and add the GPG key for the SURY repository. ``` wget -O /etc/apt/trusted.gpg.d/php.gpg https://packages.sury.org/php/apt.gpg ``` 3. Now, add the SURY repository to your system’s sources list. ``` echo "deb https://packages.sury.org/php/ $(lsb_release -sc) main" | tee /etc/apt/sources.list.d/php.list ``` 4. Update the package index again so your system recognizes the new repository. ``` apt update -y ``` 5. Check which PHP versions are available. ``` apt policy php ``` Output. ``` php: Installed: 2:8.2+93 Candidate: 2:8.4+96+0~20250402.56+debian12~1.gbp84a5b7 Version table: 2:8.4+96+0~20250402.56+debian12~1.gbp84a5b7 500 500 https://packages.sury.org/php bookworm/main amd64 Packages *** 2:8.2+93 500 500 http://deb.debian.org/debian bookworm/main amd64 Packages 100 /var/lib/dpkg/status ``` This confirms that PHP 8.4 is now available from the SURY repository. ## Step 2 – Install PHP 8 With the SURY repository enabled, you can now install PHP 8.4 directly on your Debian 12 system. 1. Run the following command to install PHP 8.4. ``` apt install -y php8.4 ``` 2. After installation, verify the PHP version. ``` php8.4 -v ``` Output. ``` PHP 8.4.11 (cli) (built: Aug 3 2025 08:49:56) (NTS) Copyright (c) The PHP Group Built by Debian Zend Engine v4.4.11, Copyright (c) Zend Technologies with Zend OPcache v8.4.11, Copyright (c), by Zend Technologies ``` 3. Your Debian server may have multiple PHP versions installed. To check, list the PHP directories. ``` ls /etc/php ``` You might see something like: ``` 8.2 8.4 ``` 4. If you want PHP 8.4 to be the default version for your system, configure it using update-alternatives. ``` update-alternatives --install /usr/bin/php php /usr/bin/php8.4 84 ``` 5. Now confirm the active PHP version. ``` php -v ``` Output. ``` PHP 8.4.11 (cli) (built: Aug 3 2025 08:49:56) (NTS) Copyright (c) The PHP Group Built by Debian Zend Engine v4.4.11, Copyright (c) Zend Technologies with Zend OPcache v8.4.11, Copyright (c), by Zend Technologies ``` 6. Finally, install common PHP extensions used by most applications, including MySQL, cURL, XML, and Mbstring. ``` apt install -y php8.4-mysql php8.4-curl php8.4-xml php8.4-mbstring ``` 7. To confirm the installed extensions, run: ``` php8.4 -m ``` This will list all active modules available with PHP 8.4. ## Step 3 – Install PHP 8 FPM PHP-FPM (FastCGI Process Manager) is a modern way to run PHP applications. Instead of embedding PHP inside Apache (mod_php), PHP-FPM runs as a separate service and communicates with the web server through a socket. This separation improves performance, scalability, and security. 1. Start by installing PHP 8.4 FPM. ``` apt install -y php8.4-fpm ``` 2. Next, edit the default pool configuration file. ``` nano /etc/php/8.4/fpm/pool.d/www.conf ``` Locate the listen directive and update it to use a Unix socket. ``` listen = /run/php/php8.4-fpm.sock ``` Set the correct ownership and permissions so Apache can access the socket. ``` listen.owner = www-data listen.group = www-data listen.mode = 0660 ``` 3. Now enable PHP-FPM to start automatically on boot. ``` systemctl enable php8.4-fpm ``` 4. Restart the service and check its status. ``` systemctl restart php8.4-fpm systemctl status php8.4-fpm ``` Output. ``` ● php8.4-fpm.service - The PHP 8.4 FastCGI Process Manager Loaded: loaded (/lib/systemd/system/php8.4-fpm.service; enabled; preset: enabled) Active: active (running) since Sun 2025-09-07 08:16:24 CAT; 4s ago Docs: man:php-fpm8.4(8) Process: 40083 ExecStartPost=/usr/lib/php/php-fpm-socket-helper install /run/php/php-fpm.sock /etc/php/8.4/fpm/pool.d/www.conf 84 (code=exited, status=0/SUCCESS) Main PID: 40080 (php-fpm8.4) Status: "Ready to handle connections" Tasks: 3 (limit: 4620) Memory: 13.3M CPU: 109ms CGroup: /system.slice/php8.4-fpm.service ├─40080 "php-fpm: master process (/etc/php/8.4/fpm/php-fpm.conf)" ├─40081 "php-fpm: pool www" └─40082 "php-fpm: pool www" Sep 07 08:16:24 debian12 systemd[1]: Starting php8.4-fpm.service - The PHP 8.4 FastCGI Process Manager... Sep 07 08:16:24 debian12 systemd[1]: Started php8.4-fpm.service - The PHP 8.4 FastCGI Process Manager. ``` This confirms that PHP-FPM is installed, configured, and running successfully. ## Step 4 – Test and Use PHP 8 With PHP-FPM installed and running, you can now integrate it with the Apache web server and verify that PHP 8.4 is working correctly. 1. If Apache is not already installed on your Debian 12 system, install it with below command. ``` apt install -y apache2 ``` 2. Enable the proxy_fcgi and setenvif modules, which allow Apache to communicate with PHP-FPM. ``` a2enmod proxy_fcgi setenvif ``` 3. Link Apache with the PHP 8.4 FPM configuration. ``` a2enconf php8.4-fpm ``` 4. Restart Apache to apply changes. ``` systemctl restart apache2 ``` 5. Create a simple PHP script inside the Apache web root directory. ``` nano /var/www/html/test.php ``` Add the following code: ``` ``` 6. Open your browser and navigate to: ``` http://SERVER-IP/test.php ``` If everything is configured properly, you’ll see the PHP information page, which displays details about your PHP version, loaded modules, and server configuration. ![](https://www.atlantic.net/wp-content/uploads/2015/10/php.png) ## Conclusion In this tutorial, you installed PHP 8.4 on Debian 12 using the SURY repository to access the latest release. You started by adding the repository and verifying that PHP 8.4 was available. Next, you installed PHP along with commonly used extensions and configured it as the default system version. You then set up PHP-FPM to improve performance and security by separating PHP from Apache, adjusted socket permissions, and ensured the service was running correctly. Finally, you integrated Apache with PHP-FPM and confirmed the setup by running a test PHP script in your browser. --- # How to Install a PHP7 LAMP Stack on CentOS 7 > URL: https://www.atlantic.net/vps-hosting/how-to-install-php7-lamp-stack-centos-7/ | Published: 2015-10-12 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 10/12/15 ## Introduction This how-to we will be installing PHP7  with a CentOS 7 LAMP stack. PHP7 is due to release sometime in November 2015, and it is a good time to try out PHP7 and test your code. > **NOTE: PHP is still in development, do not use this in a production environment, this is only to be used for testing purposes.** ![PHP7 Elephant created by Walker Cahall http://www.waltronic.net/](https://www.atlantic.net/wp-content/uploads/2018/01/php1-2.png) PHP7 Elephant created by [Walker Cahall](http://www.waltronic.net/) ## Install LAMP on CentOS 7 To start, we need to take care of a few things before installing Apache. We are going to add the PHP7 repo, go ahead and make the following file with your favorite editor. `nano /etc/yum.repos.d/php7-dev.repo` Inside of that file, we need to add the following: ``` [zend-php7] name = PHP7 nightly by Zend Technologies baseurl = http://repos.zend.com/zend-server/early-access/php7/repos/centos/ gpgcheck=0 ``` After saving and closing your new file, we can go ahead and update your system with the following command: ``` sudo yum update ``` You will see a prompt that says ‘Is this ok?’ Hit `Y` and then `Enter` to proceed. ## Installing Apache on CentOS 7 We are going to install Apache first by running the following command: ``` sudo yum install httpd ``` You will see a prompt that says ‘Is this ok?’ Hit `Y` and then `Enter` to proceed. To start Apache  run the following command: ``` sudo systemctl start httpd.service ``` Verify Apache is working by opening a browser and entering the URL `http://your-server's-address`. You will get a “Testing 123” page like the image below. > Don’t know your IP address? Run the following command: > > ``` > sudo ip addr show eth0 > ``` > > ![An example of ip addr showing eth0 and getting 192.168.100.10 for the IP address.](https://www.atlantic.net/wp-content/uploads/2018/01/php2-2.png) An example of ip addr showing eth0 and getting 192.168.100.10 for the IP address.In this example, we would put `http://192.168.100.10` in the browser’s address bar. ![The default web page when installing Apache on CentOS 7](https://www.atlantic.net/wp-content/uploads/2018/01/php3-2.png) An example of the CentOS 7 default Apache web page  7 If you would like Apache to  be enabled when your CentOS 7 systems boots, run the following command: ``` sudo systemctl enable httpd.service ``` ## Installing MariaDB on CentOS 7 If your testing does not require the need of a database, please feel free to skip this section. Install MariaDB with the following command: ``` sudo yum install mariadb-server mariadb ``` You will see a prompt that says ‘Is this ok?’ Hit `Y` and then `Enter` to proceed. To start the MariaDB service use the following command: ``` sudo systemctl start mariadb ``` Finish the installation of MariaDB with the following command: ``` sudo mysql_secure_installation ``` After running the above command, you will be prompted to answer a series of questions. It will ask you to enter the current root password, however since we have just set MariaDB up, there should not be one, so simply hit `Enter`. It will then ask you if you would like to set a new root password Hit `Y` and then `Enter`. It will then ask you to enter a password. Use a  strong root DB password that is different from any user’s passwords, including the root user. Then re-enter it. From there, you can typically just hit  `Y` and then `Enter` for each of the next questions, as below unless you need something specific. ![An example of the MySQL Secure Installation.](https://www.atlantic.net/wp-content/uploads/2018/01/php4-2.png) An example of the MySQL Secure Installation. If you want to have MariaDB enabled on boot, run the following command: ``` sudo systemctl enable mariadb.service ``` ## Installing PHP7 on CentOS 7 You have the option to install the PHP7 nightly or beta1 builds #### PHP7 Nightly Build Install: ``` sudo yum install php7-nightly ``` #### PHP7 Beta 1 Install: ``` sudo yum install php7-beta1 ``` You will see a prompt that says ‘Is this ok?’ Hit `Y` and then `Enter` to proceed. Once PHP7 is installed, we need to make some modifications to get it to work with Apache. Copy the PHP7 modules into the Apache directory with the following command: ``` sudo cp /usr/local/php7/libphp7.so /etc/httpd/modules/ ``` Using an editor of your choice, open `/etc/httpd/conf/httpd.conf `and add the following to the bottom of the file. ``` IncludeOptional conf.d/*.conf LoadModule php7_module /usr/lib64/httpd/modules/libphp7.so SetHandler application/x-httpd-php ``` Once added you can then save and exit. Now that we made some changes to Apache, we need to restart, so the changes we made take place. Run the following command to restart Apache. ``` sudo systemctl restart httpd.service ``` ## Testing PHP7 on CentOS 7 We are going to make a PHP file to test that PHP7 is working properly. Use your preferred text editor to make a new file `nano /var/www/html/info.php`. Insert the following code: ``` ``` You can then save and exit. Test that PHP7 is working by opening up a browser and going to `http://your-server's-address/info.php`. Check your PHP version number at the top left corner of the page, it should be higher than 7.0, it should look similar to the image below. ![An example of what the info.php file produces using PHP7](https://www.atlantic.net/wp-content/uploads/2018/01/php5-1.png) An example of what the info.php file produces using PHP7 Now, that you have verified that PHP7 is working. You should remove the info.php file since it contains information that hackers can use against you. Remove it by running the following command: ``` sudo rm /var/www/html/info.php ``` You should see “rm: remove regular file ‘/var/www/html/info.php’?” Hit `Y` and then `Enter`. You now have a basic PHP7 LAMP stack on CentOS 7. You can now start placing your site in the `/var/www/html/` directory. Congratulations and thank you for following along in this How-To. Check back with us for any new updates or to learn more about our reliable [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions. --- # How to Install ionCube Loader on CentOS 7.1 > URL: https://www.atlantic.net/vps-hosting/how-to-install-ioncube-loader-centos-7/ | Published: 2015-10-13 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 09/30/15 ## Introduction In this How-To, we will walk you through the install and configuration of ionCube on CentOS 7.1. The ionCube Loader provides additional security to your PHP files or websites; it’s a PHP module that encrypts basic PHP language making it more secure. ## Installing ionCube on CentOS 7 To get started, log in to your CentOS 7.1 server via SSH or Console. If you are using the Atlantic.Net cloud hosting service, note that they are setup with minimal installations to avoid having unnecessary packages from being installed and never used. If some software packages that you’re used to using aren’t installed by default, feel free to install them as needed. Let us download wget so we can simplify this tutorial. ``` sudo yum install wget ``` Let’s make sure that your server is fully up-to-date so we can complete the preparation. ``` sudo yum update ``` ## Downloading ionCube on CentOS 7 For this tutorial, I will be downloading the 64-bit version as my system is a 64bit server.  We will use the wget command to get the ionCube file from their website with the following command: ``` wget http://downloads3.ioncube.com/loader_downloads/ioncube_loaders_lin_x86-64.tar.gz ``` Extract the ionCube file with the following command: ``` tar xfz ioncube_loaders_lin_x86-64.tar.gz ``` Alternatively, if you have a 32-bit system you can download the 32-bit version from the site with the following command: ``` wget http://downloads3.ioncube.com/loader_downloads/ioncube_loaders_lin_x86.tar.gz ``` Extract the 32-bit ionCube file with the following command: ``` tar xfz ioncube_loaders_lin_x86.tar.gz ``` ## Configuring ionCube on CentOS 7 In order to configure ionCube correctly, we need to know what version of PHP is running on the server. The PHP version will tell us which extension to load. Let’s verify the version PHP by running the following comment: ``` php -v ``` The output of the command shows that the system we’re deploying on is running PHP 5.4. ``` PHP 5.4.16 (cli) (built: Jun 23 2015 21:17:27) Copyright (c) 1997-2013 The PHP Group ``` Next we need to locate where PHP is loading extensions; this can be done by running the below command and looking ``` php -i | grep extension_dir ``` ``` extension_dir => /usr/lib64/php/modules => /usr/lib64/php/modules ``` > Note: not all versions of PHP use the same location. On my test environment, the module location is **/usr/lib64/php/modules**, but on other servers it may be different. Now that we know the version of PHP and have located the PHP modules folder, we can work to make sure that the correct ionCube module is available. Run the ls (list) command on the ioncube folder to get that information. ``` ls ioncube ``` ``` ioncube_loader_lin_4.1.so     ioncube_loader_lin_4.4_ts.so  ioncube_loader_lin_5.2.so     ioncube_loader_lin_5.4_ts.so  ioncube_loader_lin_4.2.so     ioncube_loader_lin_5.0.so     ioncube_loader_lin_5.2_ts.so  ioncube_loader_lin_5.5.so     ioncube_loader_lin_4.3.so     ioncube_loader_lin_5.0_ts.so  ioncube_loader_lin_5.3.so     ioncube_loader_lin_5.5_ts.so  ioncube_loader_lin_4.3_ts.so  ioncube_loader_lin_5.1.so     ioncube_loader_lin_5.3_ts.so  ioncube_loader_lin_5.6.so     ioncube_loader_lin_4.4.so     ioncube_loader_lin_5.1_ts.so  ioncube_loader_lin_5.4.so     ioncube_loader_lin_5.6_ts.so ``` Since the installed version of PHP is 5.4, let’s copy the 5.4 version of the ionCube Loader to the PHP extensions directory we identified earlier: ``` cp ioncube/ioncube_loader_lin_5.4.so /usr/lib64/php/modules ``` Once the file has been copied to the extensions directory, we need to make sure that the PHP configuration file is updated to use the correct extension. Using your favorite text editor open the php.ini file with the following command: ``` nano /etc/php.ini ``` At the very top of the file  let’s add the following line: ``` zend_extension = /usr/lib64/php/modules/ioncube_loader_lin_5.4.so ``` Restart Apache so that the web server can load all the configuration changes that were made with the following command: ``` service httpd restart ``` Restart PHP-FPM (if installed)  so that the PHP can accept all the configuration changes that were made with the following command: ``` service php-fpm restart ``` ## Testing ionCube on CentOS 7 Now that PHP has been updated to use the ionCube PHP Loader, we need to double check that everything is working. This can be done in one of two ways. First, you can run the php -v command again. If everything is installed correctly, you will notice that a message stating ionCube Loader is enabled: ``` php -v ``` ``` PHP 5.4.16 (cli) (built: Jun 23 2015 21:17:27) Copyright (c) 1997-2013 The PHP Group Zend Engine v2.4.0, Copyright (c) 1998-2013 Zend Technologies with the ionCube PHP Loader (enabled) + Intrusion Protection from ioncube24.com (unconfigured) v5.0.18, Copyright (c) 2002-2015, by ionCube Ltd. ``` The second one is by opening up your browser and going to http://your-server’s-address/info.php. You should get a PHP Version page with the image below.(Note: if you followed the LAMP tutorial that was referenced at the beginning of this how-to, an info.php file was already created). ![This is the Zend Engine confirmation that ionCube Loader is currently enabled.](https://www.atlantic.net/wp-content/uploads/2018/01/Installing-IonCube-Loader-on-CenOS-7.jpg) This is the Zend Engine confirmation that ionCube Loader is currently enabled. ## What Next? Congratulations! You now have successfully installed and configured ionCube Loader on CentOS 7.1. Thank you for following along and feel free to check back with us for further updates. --- # LAMP vs. LEMP – tips on choosing Apache or nginx for your web server > URL: https://www.atlantic.net/vps-hosting/lamp-vs-lemp-choosing-apache-or-nginx-web-server/ | Published: 2015-10-13 | Updated: 2026-01-07 | Author: Alexander Wise ## LAMP vs. LEMP – what’s the difference? A LAMP or LEMP stack for a web server is made up of four pieces of software: - L – the **Linux** operating system - A/E – **Apache** or **nginx**Web Server - M – **MySQL** as the relational database management system - P – either **Perl**, **Python**, or **PHP** as the scripting language *When nginx is used instead of Apache, the LAMP stack becomes a LEMP stack – the “E” refers to the implied “E” in the word “engine,” as nginx is pronounced “engine-x.”* ## **Apache (LAMP) or nginx (LEMP)?** As of May 2014, these were the Netcraft statistics for Web server developers: - Apache – 38% - Microsoft – 33% - nginx – 15% - Google – 2% Keep in mind that Apache’s market share has been as high as 70% – which was in 2005, when nginx was three years old but right around 0% adoption. As the latter Web server has been increasingly adopted and Apache has lost a substantial amount of users, it’s easy for coders to think that nginx is the obvious best choice, explains software engineer Matthew Mombrea of *ITworld*. “Nginx has become popular due to its event-driven design which can make better use of today’s computer hardware than Apache’s process driven design,” [he says](http://www.itworld.com/article/2695421/choosing-a-linux-web-server-nginx-vs-apache.html). “The end result is that nginx can serve more concurrent clients with higher throughput than Apache on the same hardware.” However, Mombrea stresses, *that is only true some of the time*. ## **Pluses and Minuses** One fact of the matter is that nginx is more efficient at serving static content than Apache is. However, that’s not enough to make your decision. Think about how the server will be used. If the server is for one site, and it’s a dedicated Web server that you are using alongside a database server, Nginx will give you better performance for large amounts of traffic. Scalability is more user-friendly as well. Things can get fuzzy, though, when you are using the server to host multiple sites, says Mombrea. “In that case, PHP becomes much more of a bottleneck than either of the web server choices,” he notes. Beyond PHP creating performance parity if you have a bunch of sites running, there are also specific reasons to choose Apache. When you go with the older, more mature Web server, you will find that its features are usable immediately, while you will often have to look up how to reconfigure nginx. Similarly, there are reliable options for automated setup tools and user interfaces. Typically IT people are used to working with Apache and can better troubleshoot it. It has a web of technological and social support, in other words. In most cases, you won’t see much difference between the speed of the two Web servers. Think about what you really need and whether you want to take on the challenges of working with a less widely recognized one. You should feel more confident if you’re using nginx first in a testing environment, such as your personal blog, notes Mombrea. “If you’re setting up a cloud hosting server or a critical business application, weigh your options carefully,” he says. “Trying to force everything into nginx because you heard it will be drastically faster could be a mistake.” The Web server is not the end-all and be-all of your performance of course. For large sites, it’s a small piece of their architecture. For small-to-medium sites, consider your true needs along with your degree of familiarity. There is a reason that Apache is still the most prevalent server right now, as delineated above. As nginx matures and more IT staff understand it, it may well overtake the top position. ## **A Final Decision** Not everyone thinks this choice is difficult. Sukoon Shete, commenting on Quora, is one example. “Apache is like Microsoft Word, it has a million options but you only need six,” [he says](https://www.quora.com/Why-should-I-use-LEMP-instead-of-LAMP). “Nginx does those six things, and it does five of them 50 times faster than Apache.” Mombrea doesn’t think the decision is quite that easy though. You have to look at the specific hosting scenario, he says. For WordPress, they’ll both be fine. If you smartly cache your site, you will get better performance with nginx. However, you won’t have the immediate compatibility and broad user-friendliness of Apache. For PHP applications, get APC or a similar opcode cache to speed things up rather than switching out Web servers. ## **One-Click LAMP & LEMP** If you want strong performance and reliability, LEMP won’t solve all your problems. You also need a strong [VPS hosting](https://www.atlantic.net/vps-hosting/) service. At Atlantic.Net, we are developer-friendly, with one-click LAMP and LEMP stacks that feature: - 100% ultra-fast pure SSD drives; - Deployment in 30 seconds; and - 24/7 technical support For more interesting articles and helpful how-to’s on LAMP and LEMP, make sure you check out our [blog](https://www.atlantic.net/blog/). --- # HTTP vs. HTTPS : What is the difference? > URL: https://www.atlantic.net/vps-hosting/what-is-http-vs-https-difference/ | Published: 2015-10-14 | Updated: 2026-01-07 | Author: Alexander Wise ##### ***Target audience*** *This article is geared toward a general reader with a basic understanding of how the Internet works.* ## Introduction When you surf the Internet, most web pages are delivered to your computer using a communications protocol called HTTP, which serves the vast majority of web pages on the World Wide Web. However, it can be a vulnerable communications scheme, which is where HTTPS comes into play. ## HTTP When a user types a web address into the browser’s address bar and presses ‘Enter’, a lot happens behind the scenes before the web page is displayed in the browser window. The client computer first queries a DNS (Domain Name System) server for the actual numerical IP address of the web server associated with the web address. Once it knows the IP address, the client computer makes a request for the requested resource from the web server. The server then responds and the web page is delivered to the user’s computer. All of this usually happens within milliseconds and uses a protocol called HTTP. HTTP (HyperText Transfer Protocol) is the mechanism by which the vast majority of web pages are delivered over the World Wide Web. It is a server/client request protocol, in which the client (usually the user’s computer) requests a data package (usually a web page) from the server.   For Example, When a [virtual private server](https://www.atlantic.net/vps-hosting/) hears a request, it responds with a status response, normally “HTTP/1.1 200 OK”. It then follows with the requested data. So a request/response from a client to a server might look something like this: ``` CLIENT: GET /index.html HTTP/1.1 Host: www.example.com User-agent:Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:42.0) Gecko/20100101 Firefox/42.0 SERVER: HTTP/1.1 200 OK Date: Wed, 16 Sept 2015 23:59:59 GMT Server: Apache 1.3.3.3 (Unix) Content-Type: text/html Content-Length: 1922 Welcome to my site! This is a very simple web page, written in HTML. ``` . The protocol has been in use since 1991, and is a recognized, valid, useful communications protocol. However, it was never designed with security in mind. The exchange is unencrypted, meaning that if it is intercepted, anyone can read the contents of both the request and the response. It is particularly vulnerable to the ‘man-in-the-middle’ attack, in which an unauthorized computer acts as an intermediary between the user’s computer and the Internet, reading and logging all messages sent and received. ## Securing the Web with HTTPS There is another protocol, however, that works similarly to HTTP but is significantly more secure: HTTPS, which stands for HyperText Transfer Protocol Secure. HTTPS uses TLS (Transport Layer Security) to encrypt the communications between the client computer and the server, rendering the data useless and unreadable if it is intercepted. You may also hear TLS called SSL (Secure Socket Layer). SSL was the predecessor to TLS and many still use that term when talking about the technology that helps to secure HTTPS. TLS works via digital certificates. Upon request, a Certificate Authority (CA) issues a certificate to a server, which serves to authenticate that server to any connected clients. In an HTTPS transaction, a client contacts a TLS-enabled server and requests an encrypted session. The server then responds with a copy of its digital certificate. That certificate includes the trusted CA that issued it and the server’s public key for encryption. The client receives the server’s certificate information and can verify from the issuing authority that the certificate is valid. Once the client has satisfied itself that the server is authentic, it generates a random number. It then uses that random number to generate a session key. The client then encrypts the random number using the server’s public key, and sends it to the server. Because it’s encrypted using the server’s public key, the server is the only one able to decrypt the message with its private key. Once the server decrypts the client’s message, it has the same random number to generate the same session key client generated. From that point on, all communication between the server and the client is encrypted and decrypted using that session key. The information that is transmitted is just like the HTTP traffic, only now it is encrypted before sending, so if it should happen to be intercepted, the intercepting entity would be unable to decipher the information. Compare what the below HTTPS traffic looks like with the earlier example of HTTP traffic: ``` ...........s.....*...."..*.....r.].di.s0.$. .<...v.b..'.....O..Z|.~$..!N...X...+./. .......3.9./.5. .............www.atlantic.net...... .................#..zS...$z.W..0.......c...#.;qu..*...3...... -.E;W...@..../P.rU..0.....5P......#X...n.b.......C.&...tRgW.a.....{v.......)...-1..J9S.V..G.In......|..u..O0.....mU...|..q..Ja.O.n..G..E.W}8E.Q...0..k3t.........h2.spdy/3.1.http/1.1.......... ...........................c................................................................................................... ....Q...M..V.Q$._...9.&ye.L.i..T'.l.y..3`]| .<...v.b..'.....O..Z|.~$..!N...X./..................(.....WP.@..v..F...J.WF...m...a...#8....u ..........(...........[.......Kn......Im...@....Rdv .............g.m4..a..V&!B..d....bv.......3......&...c...... .....G...z..x.....SzV...H.P...L`...T.....s.{...ip....PY..)Z.[.........../.....^.....hc ..e.\..`.L.!.c.m.=`...[....An...c2.N..?......$.|....M.?WA.x......NCIk.....j+VUZ..p...\ZM....=.<....Ra..S..% .o...{....\ nc..~c=.......'.]...D.t..p0.-b.8*g$Yo....!c...y.#......d..H9.o.+..'..xn\.... q.....H}-....Q>..D!...~.yV..v.. \Vi.P.....K.FV-........W.>]y....M...A\....>....i/o.+..b.P.."..H..xP..:......'...VX.......j.........0D...J..Zw....b.;b. .....*.(..h.V.F.K..8..L.M.s...rwdc.{F%o.j....=.C...w.<.|..).3.. =32..g..>...h8(..;\}.h<....yP\6r.y..3.......592.W...r..pT.*.-D....e.]..)..... .....<.i..o`.8.0Q.Q.H@RI.c_d"....m..!L .G.{........U.....[..r..S....a)?.SY...%....>...jl..... .W.4.....X.Nd.....Z...%...a.;...om..mH..B.._...*......H..}(fi...,0..8..,}.[Z8.N..H...F....yj.N..b.^...].S.'......u..Z.j....spS.p.C.vhk...O..!..Y".|.w)El....t........R..h.....L.0i.M.)...E..V.C.....U........u..i.w......H..;.F.......u.. 2Op.%........Z.>2.N2),.o..M.. ...f.Z........7r9 ...... ``` ## Obtaining a TLS Certificate from a Certificate Authority Certificate Authorities offer a wide variety of TLS certificates. Prices vary depending on the extent of authentication desired. A very basic certificate (perhaps used to validate users within an organization, for example) is free. The three most common levels of validation are DV, or *Domain Validation*, OV, or *Organization Validation*, and EV, or *Extended Validation*. DV certificates are the most common, and are usually verified by emailing the controller of a domain name. OV certificates offer a bit more trust; the CA verifies not only control of the domain, but also the business uses that domain. EV certificates are the most trusted, and require significant documentation from the organization to prove that they are legitimate. These certificates are often used by organizations that want to present a secure web experience, particularly if they have a financial relationship with their visitors. While the encryption process is strong, making the HTTPS messages particularly secure compared to unsecured HTTP transactions, there is one weak link in the chain: the Certificate Authorities operate on trust. If a CA were to be hijacked, for example, it could issue a trusted certificate for any domain that would be accepted as valid and trusted by all browsers. An attacker with such a certificate could then set up a fraudulent copy of that domain that would appear to be trusted with the intention of intercepting traffic to that domain. Such an event happened in 2011, where a [Dutch CA was compromised by the government of Iran and used to intercept Iranian citizens’ browsing sessions](http://news.cnet.com/8301-27080_3-20098894-245/fraudulent-google-certificate-points-to-internet-attack/). It is not a common occurrence, but it is one that security-conscious users should definitely be aware of. . ## Identifying an HTTPS Connection The easiest way to verify your HTTPS connection is secure is to look at the address bar of your browser. Most browsers identify HTTPS connections with a padlock icon somewhere near the web address, while unencrypted HTTP connections have no such icon. Below is an example of a regular HTTP connection in Firefox, followed by example HTTPS connections in Firefox and Google Chrome. ![HTTP connection in Firefox](https://www.atlantic.net/wp-content/uploads/2018/01/https1.png) HTTP connection in Firefox ![HTTPS indicator in Firefox](https://www.atlantic.net/wp-content/uploads/2018/01/https2.png) HTTPS indicator in Firefox ![HTTPS indicator in Chrome](https://www.atlantic.net/wp-content/uploads/2018/01/https3.png) HTTPS indicator in Chrome You may also see a green lock icon that includes the organization or site name next to it. This more noticeable icon shows that the organization has acquired an EV certificate, as below. ![HTTPS indicator (with EV TLS Certificate) in Firefox](https://www.atlantic.net/wp-content/uploads/2018/01/https4.png) HTTPS indicator (with EV TLS Certificate) in Firefox . ## Conclusion HTTPS fulfills a need that HTTP leaves open — that of security. The exchanges and the protocol used are the same; only HTTPS adds an extra step of encryption that helps protect information passed across the Internet. While nothing is absolutely secure, it’s worth checking to make sure that a website is using HTTPS encryption before sending sensitive information such as passwords or credit card/bank account numbers across the wire. ## Atlantic.Net Since 1995, Atlantic.Net has been providing internet services to customers, including managed, cloud and dedicated hosting.   In 20+ years of service, our solutions have been focused on providing the very best in web solutions to our valued customers! --- # How to Install Drupal on CentOS 7 with Apache > URL: https://www.atlantic.net/vps-hosting/how-to-install-drupal-centos-7-apache/ | Published: 2015-10-15 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 09/28/15 ## Introduction In this How-To, we will walk you through the install and configuration of Drupal on CentOS 7 with Apache. Drupal is a free content management system that will facilitate the way your content is organized and managed. It has a user-friendly interface that makes customizing your content easy and simple with little effort. ## Prerequisites – You need a CentOS 7 server that is configured with a static IP address. – You will also need to have LAMP (Linux, Apache, MySQL, PHP) installed. If your server doesn’t have LAMP installed already, see our guide [here for a quick installation run through.](https://www.atlantic.net/vps-hosting/how-to-install-lamp-centos-7/) ## Installing Drupal on CentOS 7 with Apache To get started, log in to your CentOS 7 server via SSH or Console. If you are using the Atlantic.Net [VPS hosting](https://www.atlantic.net/vps-hosting/) service, note that they are setup with minimal installations to avoid having unnecessary packages from being installed and never used. If some software packages that you’re used to using aren’t installed by default, feel free to install them as needed. Let us download wget and unzip so we can simplify this tutorial. ``` sudo yum install wget unzip ``` Before moving on, let’s make sure the system is up to date: ``` sudo yum update ``` ## Creating a Database and User for Drupal on CentOS 7 For Drupal to function, we must create a database in MySQL. Let us begin access MySQL with the following command: ``` mysql -u root -p ``` Now, we must first begin creating the database that Drupal will use. This can be done by running the following command, replacing yourdbname with your desired database name: ``` CREATE DATABASE ``` **yourdbname** ``` ; ``` With the database created we must now create a user so it can access the Database. Again, this can be done by running the following command, replacing *yourdrupaluser* with your desired username and *yourdrupalpassword* with your desired password. ``` CREATE USER ``` **yourdrupaluser** ``` @localhost IDENTIFIED BY ' ``` **yourdrupalpassword** ``` '; ``` Now that we have a new database and database user, we must grant access to your recently created user so that it can make changes to your database. This is done by running the following command: ``` GRANT ALL PRIVILEGES ON ``` **yourdbname** ``` .* TO ``` **yourdrupaluser** ``` @localhost; ``` Additionally, we must refresh MySQL so the system can flush the newly added privileges and for the changes to take effect, then exit your session. This can be accomplished with the following commands: ``` FLUSH PRIVILEGES; exit ``` ## Installing Drupal on CentOS 7 The system is now ready for us to download and install Drupal. Start by downloading the latest version from the Drupal site: ``` wget http://ftp.drupal.org/files/projects/drupal-7.39.zip ``` Next, install the necessary PHP dependencies so that Drupal can function properly after the install is completed: ``` yum install php-mbstring php-gd php-xml php-pear php-fpm ``` After we have installed the requires dependencies, we can continue with the installation of Drupal. Run the following command to unzip the Drupal package that we downloaded. ``` unzip drupal-7.39.zip ``` Since, Drupal is currently in the root directory, let us copy the folder and move it into the default httpd directory: ``` cp -r ~/cp -r ~/drupal-7.39/* /var/www/html ``` Now to finalize the configurations on the servers side, we must change the create a settings file in the sites default directory. Let’s change to that directory with the following command: ``` cd /var/www/html/sites/default/ ``` Copy the default.settings.php file and rename it to settings.php with the following command: ``` cp -p default.settings.php settings.php ``` We need to modify the permissions so that the Drupal installer can edit ``` chmod 666 settings.php ``` We also need to make a files directory, do so with the following command: ``` mkdir files ``` Modify the permissions of files with the following command: ``` chmod 777 files ``` We need to restart Apache since we installed the PHP extensions. ``` systemctl restart httpd.service ``` ## Drupal’s Web Configuration on CentOS 7 Your server is now configured correctly to run the web-based installation by going to the following: ``` http://server_domain_or_IP ``` You will see the Drupal installation procedure’s initial page. Select the standard install. ![This is the Drupal's web installation wizard on CentOS 7](https://www.atlantic.net/wp-content/uploads/2018/01/drupal1.jpg) This is the Drupal’s web installation wizard on CentOS 7. Select the standard install. Choose the language of your choice. ![Select the language of your choice.](https://www.atlantic.net/wp-content/uploads/2018/01/drupal2.png) Select the language of your choice. On the next screen, we need to enter in the Database information that we created from before. Enter the Database name, username and password, once done hit “Save an continue.”   ![Add the MariaDB database, user and password into their designated fields.](https://www.atlantic.net/wp-content/uploads/2018/01/drupal3.png) Add the MariaDB database, user and password into their designated fields. After entering the Database info, all you need to do now is answer Drupal’s questions for your site. ![From here just follow along Drupal's install for site information.](https://www.atlantic.net/wp-content/uploads/2018/01/drupal4.png) From here just follow along Drupal’s install for site information. ## Whats Next? Congratulations! You have just installed and configured Drupal with Apache on your CentOS 7 Server. Thank you for following along in this How-To and check back with us for any new updates. ## Atlantic.Net Since 1995, Atlantic.Net has been providing internet services to customers, including managed, cloud and dedicated hosting.   In 20+ years of service, our solutions have been focused on providing the very best in web solutions to our valued customers! --- # How to Find The Location Of Your Servers with Traceroute and WHOIS > URL: https://www.atlantic.net/vps-hosting/how-to-find-location-servers-traceroute-whois/ | Published: 2015-10-16 | Updated: 2026-01-07 | Author: Alexander Wise ## Introduction One of the most important things to consider when deploying any servers for your business or development needs is to make sure that it’s in a location that works for you. Let’s say you’ve deployed a server and then used one of the IP geolocation websites and found that your server’s IP does not match its location, what do you do? Unfortunately, these sites, while convenient, can be very inaccurate. This how-to guide will show you some more accurate ways of finding where your server is located. ## Prerequisites A Linux, FreeBSD, or Windows VPS with a static IP address assigned. ## How Locations Are Assigned To IP Addresses The Internet Assigned Numbers Authority (IANA) handles splitting all the IPV4 and IPV6 addresses to 5 different Regional Internet Registries (RIR). The 5 RIR names and geographic responsibilities are as follows: `AFRINIC - Africa` ARIN – United States, Canada, Caribbean, and Antarctica APNIC – Asia, Australia, New Zealand RIPE NCC – Europe, Russia, Middle East, and Central Asia LACNIC – Latin America, some parts of the Caribbean Organizations can purchase blocks of IPs from the RIR that oversees the area in which that organization’s equipment is going to be located. The organization is then responsible for updating the RIR’s database indicating where (country, state/territory, city) they have assigned those blocks of IPs. IP geolocation sites use this information as their primary source of data. However, it’s not the only source they use; frequently, they use other sources like data mining and user-submitted updates. ## The Flaws With Geolocation Sites One of the biggest issues with geolocation sites is that it’s simply too hard to keep track of so many IPs. There is a combined total of 4,294,967,296 IPv4 possible addresses, a large portion of those are constantly being shifted around within an organization, being moved or sold to new organizations, etc. The databases that the geolocation sites have can get out of sync pretty quickly as a result of all of this movement. [IP2Location](http://www.ip2location.com/), which is one of the bigger IP geolocation services, says the following: **“In general, the accuracy will degrade by about 1%-5% for each month that an outdated database is being used.”**  At any given time, that is up to over 200 million IP addresses that are out of date. Other sites that are using IP2Location’s database may not have the most up-to-date database and can be over 6 months behind. Other issues include organizations that may not be up to date on updating their RIR, causing more data to be inaccurate. > Note: Atlantic.Net updates our direct allocations per ARIN and RIPE polices by updating the SWIP data within ARIN’s or RIPE’s WHOIS Database with the proper country, city and state data corresponding to where the IP allocation has been provisioned. It’s not that geolocation sites are bad–they do serve an important purpose for advertising and geoblocking. It should just be noted that they are not always accurate. Often this will not affect you when you are looking up your IP to see which region it’s located in. If, however, you believe your IP is incorrectly geoblocked, the best plan is to contact the geolocation site that is inaccurate. ## How To Find The Real Location Of Your Server If a geolocation site gives you conflicting information about the location of your server’s IP, you can verify your server’s location by following these steps. ## Checking Your IP Using WHOIS WHOIS is a tool that queries the database that stores the registered information for an IP address block or domain name. FreeBSD systems should have WHOIS installed by default. If you have a Linux system, you can install WHOIS with a simple command: ### For Debian and Ubuntu: ``` apt-get install whois ``` ### For Redhat/CentOS/Fedora: ``` yum install jwhois ``` ### For ArchLinux: ``` pacman -S whois ``` ### Windows: Unfortunately, Windows does not have a built-in WHOIS tool. You can find a third-party tool, or go to the RIR responsible for the region your server is located in and run their WHOIS tool. Links to each site are below. If you don’t know which RIR you need to go to, just select one and insert your IP, and it will tell you the correct RIR to use. [ARIN](https://www.arin.net/), [RIPE NCC](https://www.ripe.net/), [APNIC](https://www.apnic.net/), [LACNIC](http://www.lacnic.net/web/lacnic/ipv6) and [AFRINIC](http://www.afrinic.net/). With WHOIS now installed on your system, you can run the following command to check the WHOIS database: ``` whois your-ip-address ``` When you run the command, you will get output similar to the following: ``` NetRange: 209.208.0.0 - 209.208.127.255 CIDR: 209.208.0.0/17 NetName: ICC-1 NetHandle: NET-209-208-0-0-1 Parent: NET209 (NET-209-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: Atlantic.Net, Inc. (INCC) RegDate: 1998-04-13 Updated: 2012-02-24 Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE Ref: http://whois.arin.net/rest/net/NET-209-208-0-0-1 OrgName: Atlantic.Net, Inc. OrgId: INCC RegDate: Updated: 2014-10-20 Comment: Atlantic.Net used to be known as Internet Connect Company Inc. Comment: Please send any abuse/hacking/spam complaints to abuse@atlantic.net. Ref: http://whois.arin.net/rest/org/INCC ``` In this particular case, you can see this IP range has been assigned to Orlando, FL. However, this result only gives you so much information; the output could say it is in one location but could actually be in another. That’s why the next step is to run a traceroute. ## Running a Traceroute To Find Your Server Location The best way to see where your server is located is through a traceroute. A traceroute will give you the sequential list of network devices–devices potentially operated by different organizations–that traffic is routed through on its way to its destination. Here, we will be able to see the path that traffic takes from your server to the destination IP or hostname you enter. We can run a WHOIS on each IP address along the path to see the location is correct. To run a traceroute on Linux or FreeBSD, run the following command: ``` traceroute your-destination-site-or-IP ``` To run a traceroute on Windows, open your command prompt and  run the following command: ``` tracert your-destination-site-or-IP ``` On a traceroute from an Atlantic.Net Cloud server in London to Google.com, we get the following output. ``` traceroute to google.com (216.58.210.46), 30 hops max, 60 byte packets 1 vl223-ar-02.lon-uk.as59764.net (185.73.36.34) 0.401 ms 0.391 ms 0.464 ms 2 84.207.244.73.not-updated.eunx.net (84.207.244.73) 1.048 ms 1.028 ms 1.001 ms 3 195.66.224.125 (195.66.224.125) 1.410 ms 1.391 ms 1.372 ms 4 209.85.247.31 (209.85.247.31) 4.172 ms 1.329 ms 1.316 ms 5 72.14.238.21 (72.14.238.21) 1.290 ms 1.340 ms 1.323 ms 6 lhr14s23-in-f14.1e100.net (216.58.210.46) 1.221 ms 1.339 ms 1.318 ms ``` From here, you can do a WHOIS on the IPs that you see in the traceroute. Do a WHOIS on the first few IPs since they will be closer to your server than the last few IPs. Below, we have an example WHOIS from the second hop that shows that the location of that IP is in London. ![An example of a whois lookup using an IP from a the traceroute above.](https://www.atlantic.net/wp-content/uploads/2015/10/find1.png) An example of a whois lookup using an IP from a the traceroute above. See the “netname” entry indicates “UK-EUNETWORKS” and the “country” is “GB”–Great Britain. Again this relies on organizations updating their information appropriately. If any one IP lookup provides what appears to be inaccurate information, you should, with most traceroutes, have multiple hops you can check. ## Conclusion Thank you for following this How-to. We hope that this clears up any issues you may have with IP geolocation.  Please check back here for more updates. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [Virtual private servers.](https://www.atlantic.net/vps-hosting/) --- # How to Install Linux, Apache, MySQL And PHP (LAMP) On A Ubuntu 12.04 Cloud Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-lamp-ubuntu-12-04/ | Published: 2015-10-19 | Updated: 2026-01-07 | Author: Alexander Wise ##### Verified and Tested 10/15/15 ## Introduction In this How-To, we are installing a LAMP server using Ubuntu 12.04. LAMP is one of the most widespread and easy to install web server configurations out there. It consists of 4 elements; Linux (In this case Ubuntu), Apache, MySQL, and PHP. ## Installing LAMP Before installing Apache, we should make sure our system is up to date, by running the following command: ``` sudo apt-get update ``` ## Installing Apache Apache is the web server; its job is to serve web pages to your clients when they request them. Install Apache by running the following command: ``` sudo apt-get install apache2 ``` When is asks “Do you want to continue?” hit `Y` and then `Enter`. Verify Apache is running by running the following command: ``` service apache2 status ```  After the install, Apache creates a default web page that can be viewed by going to your servers IP address. > If you do not know your servers IP address, you can run the following command: > > ``` > ifconfig > ``` > > You should get an output that looks like the following. You need to look next to where it says “inet addr” for your IP address. > > ![An example of ifconfig showing the IP address 192.168.100.10](https://www.atlantic.net/wp-content/uploads/2018/01/php1.png) An example of ifconfig showing the IP address 192.168.100.10In our case, we would put http://192.168.100.10 in your browser’s address bar and get the following page: > > ![The default page for Apache on Ubuntu 12.04](https://www.atlantic.net/wp-content/uploads/2015/10/install-linux-apache-mysql-php-lamp-ubuntu-12-04-cloud-server-02-e1635037742977.png) The default page for Apache on Ubuntu 12.04 ## Installing MySQL MySQL is a relation database system, its job is to store data within databases, tables, and records. You can install MySQL with the following command: ``` sudo apt-get install mysql-server libapache2-mod-auth-mysql php5-mysql ``` During the install, when is asks “Do you want to continue?” hit `Y` and then `Enter`. It will then prompt you to enter a MySQL root password. You should set a strong password of your choice. ![Add a strong password of your choosing and hit Enter](https://www.atlantic.net/wp-content/uploads/2018/01/php2.png) Add a strong password of your choosing and hit EnterOnce you enter your MySQL password, it will prompt you to re-enter it. ![Re-enter the password you set before](https://www.atlantic.net/wp-content/uploads/2018/01/php3.png) Re-enter the password you set beforeBy default, MySQL has left a few things open to make it easier to set up. However, you do not need these open, and it is suggested to run the MySQL Security installation with the following command: ``` mysql_secure_installation ``` It will be prompting you a series of questions Type `N` for the change root password since you just set it, and most likely you want to hit `Y` for the rest. ![An example of what mysql_secure_installation looks like](https://www.atlantic.net/wp-content/uploads/2018/01/php4.png) An example of what mysql_secure_installation looks likeVerify that MySQL is running with the following command: ``` service mysql status ``` ## Installing PHP PHP is the scripting language, its job is to interrupt code and to produce outputs. Install PHP with the following command: ``` apt-get install php5 libapache2-mod-php5 ``` When is asks “Do you want to continue?” hit `Y` and then `Enter`. We are going to create a PHP test file called  info.php in /var/www/. For this how-to we are going to accomplish this using Nano, by running the following command: ``` nano /var/www/info.php ``` Insert the following code in the text editor: ``` ``` Save the file by hitting `Ctrl + X` then Hit `Y` and then `Enter`. Since we install PHP, we need to restart Apache so that the changes take effect: ``` service apache2 restart ``` You can now test your info.php file by using the following link below, updated with your IP address. http://youripaddress/info.php ![The result of the php.info file you made.](https://www.atlantic.net/wp-content/uploads/2018/01/php5.png) The result of the php.info file you made.Now that you verified PHP is working, it is a good idea to remove the info.php file since hackers can use this to plan attacks against you using this information. Remove it with the following command: ``` sudo rm /var/www/info.php ``` Congratulations! On installing LAMP on your Ubuntu 12.04 Server. Thank you for following this How-To, please check back for more updates. If you are running a newer version of Ubuntu, see our helpful how-to’s for [Ubuntu 14.04](https://www.atlantic.net/vps-hosting/how-to-install-linux-apache-mysql-php-lamp-ubuntu-20-04/), [Ubuntu 15.04](https://www.atlantic.net/vps-hosting/how-to-install-lamp-ubuntu-15-04-server/) and [Ubuntu 16.04](https://www.atlantic.net/vps-hosting/how-to-install-apache-mysql-php-lamp-stack-ubuntu-16-04/).   --- # How to Install WordPress on a Debian 12 > URL: https://www.atlantic.net/vps-hosting/how-to-install-wordpress-debian-12/ | Published: 2015-10-20 | Updated: 2026-03-03 | Author: Alexander Wise ### Introduction WordPress is the most popular content management system (CMS) used to build blogs, business websites, e-commerce stores, and more. It’s free, open source, and supported by a large community of developers who contribute plugins and themes to extend its functionality. Running WordPress on Debian 12 (Bookworm) gives you a stable, secure, and long-term environment for your website. In this tutorial, you’ll learn how to install WordPress on a fresh Debian 12 server ## Step 1 – Install LEMP Server To run WordPress on Debian 12, you need a LEMP stack – Linux, Nginx (web server), MariaDB (database), and PHP-FPM (scripting language processor). Each component plays a critical role in serving dynamic WordPress pages quickly and securely. 1. Update your system. ``` apt update -y ``` 2. Install Nginx. ``` apt install -y nginx ``` 3. Install the MariaDB database server. ``` apt install -y mariadb-server ``` 4. WordPress requires PHP to process dynamic content. Install it with additional extensions. ``` apt install php php-fpm php-mysql php-xml php-curl php-gd php-mbstring php-zip -y ``` ## Step 2 – Create a Database for WordPress WordPress stores all of its content, posts, pages, users, settings, and plugin data in a database. Before you can run the installer, you’ll need to set up a database and grant access to a dedicated user account. This ensures WordPress has the proper permissions to manage its own data while keeping your system secure. 1. Log in to MariaDB as the root user. ``` mysql ``` You’ll enter the MariaDB shell, where you can run SQL commands directly. 2. Create a new database named wordpressdb. ``` CREATE DATABASE wordpressdb; ``` 3. Now, create a user named wpadmin and assign it a secure password. ``` CREATE USER 'wpadmin'@'localhost' IDENTIFIED BY 'securepassword'; ``` 4. Give the new user full control over the wordpressdb database: ``` GRANT ALL ON wordpressdb.* TO 'wpadmin'@'localhost'; ``` 5. Then, apply the changes. ``` FLUSH PRIVILEGES; ``` 6. Type the following to leave the MariaDB shell. ``` EXIT; ``` ## Step 3 – Download WordPress With your database ready, the next step is to get the latest WordPress package, extract it, and move it into the proper web directory so Nginx can serve it. Let’s go through this step-by-step. 1. Use wget to fetch the compressed archive of WordPress. ``` wget https://wordpress.org/latest.tar.gz ``` 2. Unpack the tar.gz file into a directory. ``` tar -xvf latest.tar.gz ``` 3. Now, create a custom directory where your WordPress files will live. ``` mkdir -p /var/www/wp.example.com ``` Replace wp.example.com with your actual domain. 4. Transfer the extracted files into your webroot. ``` mv wordpress/* /var/www/wp.example.com ``` 5. Assign correct ownership to the Nginx user (www-data) so WordPress can manage its files. ``` chown -R www-data:www-data /var/www/wp.example.com ``` 6. Set secure permissions for directories and files. ``` find /var/www/wp.example.com -type d -exec chmod 755 {} \; find /var/www/wp.example.com -type f -exec chmod 644 {} \; ``` ## Step 4 – Create a Virtual Host Configuration for WordPress Now that the WordPress files are in place, the next step is to configure Nginx so it knows how to serve your domain, where the site files live, and how to handle PHP requests through PHP-FPM. This is done by creating a server block (sometimes called a virtual host). 1. Create a server block file for your domain under Nginx’s sites-available directory. ``` nano /etc/nginx/sites-available/wp.example.com.conf ``` Add the following configuration. ``` server { listen 80; server_name wp.example.com; root /var/www/wp.example.com; index index.php index.html index.htm; access_log /var/log/nginx/example.com.access.log; error_log /var/log/nginx/example.com.error.log; location / { try_files $uri $uri/ /index.php?$args; } location ~ \.php$ { include snippets/fastcgi-php.conf; fastcgi_pass unix:/run/php/php8.2-fpm.sock; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } location ~ /\. { deny all; } location ~* \.(jpg|jpeg|png|gif|ico|css|js|svg|woff|woff2|ttf|eot)$ { expires 30d; access_log off; add_header Cache-Control "public, no-transform"; } } ``` 2. Link the configuration file from sites-available to sites-enabled. ``` ln -s /etc/nginx/sites-available/wp.example.com.conf /etc/nginx/sites-enabled/ ``` 3. Remove the default configuration to avoid conflicts. ``` rm /etc/nginx/sites-enabled/default ``` 4. Check for syntax errors. ``` nginx -t ``` Output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` 5. If all is good, restart Nginx. ``` systemctl restart nginx ``` ## Step 5 – Configure WordPress With Nginx serving your domain and the WordPress files in place, the final step is to complete the setup through the web-based installer. This will connect WordPress to the database you created earlier and create your admin account. 1. Open your domain in a browser. ``` http://wp.example.com ``` If Nginx and PHP are configured correctly, you’ll see the WordPress Setup Wizard screen. ![](https://www.atlantic.net/wp-content/uploads/2015/10/w1.png) 2. The installer will first ask you to select the language you want WordPress to use. Pick your preferred language and click **Continue.** ![](https://www.atlantic.net/wp-content/uploads/2015/10/w2.png) 3. Click **Let’s** **Go** to begin entering your database information. ![](https://www.atlantic.net/wp-content/uploads/2015/10/w3.png) 4. Fill in the form with the credentials you created earlier. Click **Submit.** ![](https://www.atlantic.net/wp-content/uploads/2015/10/w4.png) 5. Click **Run the Installation** to initialize the WordPress database. ![](https://www.atlantic.net/wp-content/uploads/2015/10/w5.png) 6. Now, provide details for your WordPress site. Click **Install WordPress.** Once the installation completes, you’ll see a success message. ![](https://www.atlantic.net/wp-content/uploads/2015/10/w6.png) 7. Click **Login** to log in to the WordPress admin dashboard. ![](https://www.atlantic.net/wp-content/uploads/2015/10/w7.png) 8. Enter your admin username and password, then click **Log In.** You’ll land on the WordPress Dashboard. ![](https://www.atlantic.net/wp-content/uploads/2015/10/w8.png) ## Conclusion In this tutorial, you successfully installed WordPress on Debian 12 using the LEMP stack. At this stage, your WordPress site is live and ready for customization. You can now log in to the WordPress Dashboard to install themes, add plugins, and publish your first post. --- # 9 Preventable WordPress Mistakes to avoid > URL: https://www.atlantic.net/hipaa-compliant-wordpress-hosting/9-preventable-wordpress-mistakes/ | Published: 2015-10-20 | Updated: 2026-03-01 | Author: Alexander Wise It’s easy to make mistakes in any area of business. The key, really, is to avoid as many of them as we can and to make corrections along the way. When someone gets started with WordPress, they typically are enticed by the simplicity and speed of the CMS (content management system). You really want to slow yourself down a bit if you are racing to get the site online. You don’t want it to be vulnerable to hackers, not have the right plug-ins, or suffer from poorly organized content. If you set up the CMS well, on the other hand, you can make the best use of the technology and grow your business smartly and efficiently. Here are 9 common mistakes that there is no need for you to make: ## **#1 – Not paying attention to page load times.** Being conscientious about minimizing page load times will give you much better traffic and a significantly lower bounce rate. Keep in mind that speed is not just about compressing images, according to business consultant Richie Contartesi. “If you choose a WordPress theme that fails to take speed into consideration,” [he says](http://www.business2community.com/online-marketing/5-biggest-wordpress-mistakes-i-hope-you-arent-making-01323458#ALU38TwfhWsUx804.03), “you’ll end up installing too many plugins and graphics or video, killing your load time.” There are various tools to help you lower load times. Two of the most prominent ones are Google Analytics and Google PageSpeed Insights. ## **#2 – Failing to switch the admin username.** By default when you install WordPress, the CMS creates an account with administrator rights that is called “admin.” You want to change the name right away so that hackers won’t have a field day attacking your site with brute force. You can actually change the username right as you are installing. Just pay attention as you are working your way through the install. You want both the password *and the username* to contain a combination of letters, numbers, and special characters. ## **#3 – Using overly complex tagging and categorization.** Being able to organize your content with tags is a great feature of the CMS, and many website owners mistakenly think that more is better when creating them. A large number of tags, though, is not actually in your best interest, according to marketer Jeff Bullas. “Too much and complex categories not only make your site ugly and difficult to navigate,” [he warns](http://www.jeffbullas.com/2014/04/14/the-15-most-common-wordpress-mistakes-to-avoid/), “but also influence users to leave your website and affect everything from SEO to load time of your site.” Keeping your tags concise and limited will make it likelier that people stay and look around. ## **#4 – Letting comments go up unmoderated.** The amount of spam that typically hits the comment section of a WordPress site borders on the ridiculous. Allowing that to occur for any amount of time, even if it’s just a couple days, can have a terrible impact on your search engine results. You might even end up blacklisted by Google if you don’t filter your comments. Make sure that your settings require approval, and it’s also a good idea to get a plug-in to get rid of the bulk of the spam. One reliable way to verify the authenticity of commenters is a CAPTCHA plugin. ## **#5 – Keeping all the default plug-ins active.** Various plug-ins are enabled automatically when you install WordPress. You don’t want them on if you aren’t using them since they consume resources. ## **#6 – Neglecting to create a contact form.** You may think you just need a contact page with your email on it. “That’s not the right way to get your audience in touch with you,” says Bullas, “as after a few months you’ll notice that your inbox is getting flooded with an insane amount of SPAM.” All you need to do is grab a contact form plug-in, such as Gravity Forms. ## **#7 – Forgetting to install a plug-in to cache content.** Many new users of WordPress underestimate the importance of caching, unaware how critical seemingly small variations in the speed of the site are to Google rankings. Caching will also get you better prepared for spikes in traffic. ## **#8 – Selecting a theme with bad design.** It isn’t as easy as you might think to find a theme that is truly designed well. Your template may look good but be terrible in terms of SEO, notes Contartesi. “Some themes, for example, have a ton of small links in the footer, and you might assume those links are nofollow links,” he says. “Unfortunately, that’s not always the case, so it’s usually better to select a theme that does not include any credit links at all.” You also want to make sure that the theme is responsive so that it is coming through with correct formatting for mobile devices, another important Google ranking factor (especially as of the April 2015 “Mobilegeddon” update). ## **#9 – Getting low-quality web hosting.** It’s easy to just go out and grab the lowest priced hosting company you can find, especially if you are a startup and on a tight budget. That is a very questionable idea. Think about how much speed will be impacted by the quality of your hardware and Cloud Server Hosting networks – a fundamental aspect of your UX (user experience) and SEO. At Atlantic.Net, our one-click WordPress Cloud Servers are up in 30 seconds, backed entirely by 100% solid-state drives (offering significantly better performance than hard disk drives) that are distributed internationally. Cloud hosting services are only one of our offerings – we also offer dedicated hosting, managed hosting, and [HIPAA-compliant WordPress hosting](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/). --- # What Is PHP7? Breaking Changes from PHP5 > URL: https://www.atlantic.net/dedicated-server-hosting/what-is-php7-breaking-changes-php5/ | Published: 2015-10-21 | Updated: 2026-02-28 | Author: Alexander Wise ##### ***Target Audience*** *This article is geared toward readers with at least a working knowledge of PHP or a thorough knowledge of programming.* . ### Introduction PHP is one of those ubiquitous programming languages that underpins many of the most popular web platforms. With the release of PHP7–the first major revision to PHP in years–the governing body has taken the opportunity to add new features, deprecate others, and remove those that were previously deprecated. To make the transition from older versions to PHP7, developers will likely want to familiarize themselves with these changes to take advantage of the increased performance and to learn how these improvements may affect their code. In this article, we focus on some of the breaking changes from PHP5 to PHP7. !["PHP7](https://www.atlantic.net/wp-content/uploads/2018/01/php1-2.png) PHP7 Elephant created by [Walker Cahall](http://www.waltronic.net/) ## Uniform Variable Syntax Nested variables often resulted in code that was difficult to read as variable assignment was read right-to-left. Variable resolution now happens left-to-right in an effort to make code-writing and -reading a simpler task. | // code | // old evaluation | // new evaluation | | --- | --- | --- | | $$atlantic[‘dot’][‘net’] | ${$atlantic[‘dot’][‘net’]} | ($$atlantic)[‘dot’][‘net’] | | $atlantic->$dot[‘net’] | $atlantic->{$dot[‘net’]} | ($atlantic->$dot)[‘net’] | | $atlantic->$dot[‘net’]() | $atlantic->{$dot[‘net’]}() | ($atlantic->$dot)[‘net’]() | | atlantic::$dot[‘net’]() | atlantic::{$dot[‘net’]}() | (atlantic::$dot)[‘net’]() | . Old code can achieve the same effect in PHP7 with the use of braces ({}) as in the center column above. . ## Removal of ASP and Script Tags PHP7 will no longer recognize alternative tags such as `<%`, `<%=`, `%>`, and `** from your web browser. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/02/Forbidden-Error-Attack.png) To test ModSecurity’s rules against Nessus scans, use a curl command with Nessus scanners to send HTTP requests to the Apache server as shown below: ``` curl -i http://your-server-ip -A Nessus ``` You should get a 403 Forbidden response because ModSecurity has identified the User Agent as a Nessus scan: ``` HTTP/1.1 403 Forbidden Date: Sat, 21 Dec 2019 04:17:24 GMT Server: Apache/2.4.29 (Ubuntu) Content-Length: 278 Content-Type: text/html; charset=iso-8859-1 ``` ## Step 6 – Exclude a Specific Domain from ModSecurity In some cases, you need to exclude a specific domain from ModSecurity protection. To disable ModSecurity for a specific domain, open the Apache virtual host configuration file for a specific domain: ``` nano /etc/apache2/site-enabled/your-domain.conf ``` Add the following lines inside the block: ```    SecRuleEngine Off ``` Save and close the file. Then, restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` ## Conclusion We have reviewed how to install and configure ModSecurity to protect your Apache webserver from malicious attacks. For more information, visit the ModSecurity documentation at [ModSecurity](https://www.modsecurity.org/documentation.html). --- # How to Set Up Lighttpd Web Server on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-set-up-lighttpd-web-server-on-ubuntu/ | Published: 2020-02-25 | Updated: 2023-11-24 | Author: Hitesh Jethva Lighttpd is a free, open-source, and high-performance web server designed for speed-critical environments. It is lightweight, secure, fast, and consumes very few resources compared to other web servers.  Lighttpd also supports FastCGI, CGI, Output-Compression, Auth and URL-Rewriting, which makes it the perfect web server. Lighttpd can handle up to 10000 connections in parallel on a single server. If you are looking for a fast, efficient, and secure web server, then Lighttpd is the best choice for you. In this tutorial, we will explain how to install Lighttpd web server with PHP and PHP-FPM support on Ubuntu 18.04. ## Step 1 – Installing Lighttpd By default, Lighttpd is available in the Ubuntu 18.04 default repository. You can install it by just running the following command: ``` apt-get install lighttpd -y ``` Once the installation is completed, check the status of Lighttpd with the following command: ``` systemctl status lighttpd ``` If everything goes fine, you should get the following output: ``` ● lighttpd.service - Lighttpd Daemon   Loaded: loaded (/lib/systemd/system/lighttpd.service; enabled; vendor preset: enabled)   Active: active (running) since Sat 2019-05-25 09:18:47 UTC; 20s ago Main PID: 1860 (lighttpd)    Tasks: 1 (limit: 1114)   CGroup: /system.slice/lighttpd.service           └─1860 /usr/sbin/lighttpd -D -f /etc/lighttpd/lighttpd.conf May 25 09:18:47 ubuntu1804 systemd[1]: Starting Lighttpd Daemon... May 25 09:18:47 ubuntu1804 systemd[1]: Started Lighttpd Daemon. ``` You can check the version of the Lighttpd installed on your server with the following command: ``` lighttpd -version ``` You should see the following output: ``` lighttpd/1.4.45 (ssl) - a light and fast webserver Build-Date: Feb  6 2018 12:41:51 ``` You can also check Lighttpd by visiting the URL http://your-server-ip on your web browser. You should see the Lighttpd default page per the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/02/Placeholder-Page-Lighttpd.png) The main configuration file for Lighttpd is located at /etc/lighttpd/lighttpd.conf. ``` cat /etc/lighttpd/lighttpd.conf ``` Output: ``` server.modules = (            "mod_access",            "mod_alias",            "mod_compress",            "mod_redirect", ) server.document-root        = "/var/www/html" server.upload-dirs          = ( "/var/cache/lighttpd/uploads" ) server.errorlog             = "/var/log/lighttpd/error.log" server.pid-file             = "/var/run/lighttpd.pid" server.username             = "www-data" server.groupname            = "www-data" server.port                 = 80 index-file.names            = ( "index.php", "index.html", "index.lighttpd.html" ) url.access-deny             = ( "~", ".inc" ) static-file.exclude-extensions = ( ".php", ".pl", ".fcgi" ) compress.cache-dir          = "/var/cache/lighttpd/compress/" compress.filetype           = ( "application/javascript", "text/css", "text/html", "text/plain" ) # default listening port for IPv6 falls back to the IPv4 port ## Use ipv6 if available #include_shell "/usr/share/lighttpd/use-ipv6.pl " + server.port include_shell "/usr/share/lighttpd/create-mime.assign.pl" include_shell "/usr/share/lighttpd/include-conf-enabled.pl" ``` This is the main configuration file from where you can change default document root, port, and index file, and enable/disable any modules per your requirements. You can also see all the configuration files using the tree command. First, install the tree package with the following command: ``` apt-get install tree -y ``` Once installed, you can see all the configuration files as shown below: ``` tree /etc/lighttpd/ ``` You should see the following output: ``` /etc/lighttpd/ ├── conf-available │   ├── 05-auth.conf │   ├── 10-accesslog.conf │   ├── 10-cgi.conf │   ├── 10-dir-listing.conf │   ├── 10-evasive.conf │   ├── 10-evhost.conf │   ├── 10-expire.conf │   ├── 10-fastcgi.conf │   ├── 10-flv-streaming.conf │   ├── 10-no-www.conf │   ├── 10-proxy.conf │   ├── 10-rewrite.conf │   ├── 10-rrdtool.conf │   ├── 10-simple-vhost.conf │   ├── 10-ssi.conf │   ├── 10-ssl.conf │   ├── 10-status.conf │   ├── 10-userdir.conf │   ├── 10-usertrack.conf │   ├── 11-extforward.conf │   ├── 15-fastcgi-php.conf │   ├── 90-debian-doc.conf │   └── README ├── conf-enabled └── lighttpd.conf ``` Once you have finished, you can proceed to the next step. ## Step 2 – Enable PHP and PHP-FPM Support By default, Lighttpd does not support PHP. You will need to install PHP with PHP-FPM to work with Lighttpd. PHP-FPM stands for “FastCGI Process Manager” and is an alternative PHP FastCGI implementation with some additional features that can be used for sites of any size. You can install them by simply running the following command: ``` apt-get install php php-cgi php-fpm -y ``` **Note**: In Ubuntu 18.04, the default PHP version is 7.2. You can replace php7.2 with the PHP version installed on your operating system. Once the installation is completed,  the Apache web server also installed automatically along with PHP. So, you will need to remove the Apache package from your system. First, stop the Apache service with the following command: ``` systemctl stop apache2 systemctl disable apache2 ``` Next, remove the Apache package with the following command: ``` apt-get remove apache2  -y ``` Next, you will need to configure PHP-FPM to run a FastCGI server on port **9000**. By default, PHP listens on the UNIX socket **/run/php/php7.2-fpm.sock**. Edit the file **/etc/php/7.2/fpm/pool.d/www.conf** as shown below: ``` nano /etc/php/7.2/fpm/pool.d/www.conf ``` Find the following line: ``` listen = /run/php/php7.2-fpm.sock ``` And replace it with the following line: ``` listen = 127.0.0.1:9000 ``` Save the file then restart PHP-FPM service to apply the changes: ``` systemctl restart php7.2-fpm ``` Next, you will also need to configure PHP to work with Lighttpd. You can do it by editing the **php.ini** file: ``` nano /etc/php/7.2/fpm/php.ini ``` Find and uncomment the following line: ``` cgi.fix_pathinfo=1 ``` Save the file when you are finished. Next, configure PHP-FPM to run a FastCGI server on port **9000**. You can do this by editing the file **15-fastcgi-php.conf**: ``` nano /etc/lighttpd/conf-available/15-fastcgi-php.conf ``` Find the following lines: ``` "bin-path" => "/usr/bin/php-cgi", "socket" => "/var/run/lighttpd/php.socket", ``` Replace them with the following lines: ``` "host" => "127.0.0.1", "port" => "9000", ``` Save the file. Then, enable FastCGI and FastCGI-PHP modules using the following command: ``` lighty-enable-mod fastcgi lighty-enable-mod fastcgi-php ``` Next, reload the Lighttpd service the enable the changes: ``` service lighttpd force-reload ``` ## Step 3 – Testing Lighttpd At this point, Lighttpd is configured to work with PHP and PHP-FPM. It’s time to test it. First, create a sample **info.php** file in the Lighttpd default document root directory: nano /var/www/html/info.php Add the following lines: Save and close the file. Then, change the ownership of the **info.php** file to **www-data**: chown www-data:www-data /var/www/html/info.php Now, open your web browser and visit the URL http://your-server-ip/info.php. You will be redirected to the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/02/PHP-Lighttpd.png) ![](https://www.atlantic.net/wp-content/uploads/2020/02/PHP-Lighttpd-Configuration.png) That means PHP is working well with Lighttpd. **Note** : Don’t forget to remove the file /var/www/html/info.php after testing. rm -rf /var/www/html/info.php ## Conclusion Congratulations! You have successfully installed and configured Lighttpd on an Ubuntu 18.04 server. I hope you have now enough knowledge to deploy PHP applications with Lighttpd and PHP-FPM. Get started with Lighttpd today with a [VPS hosting](https://www.atlantic.net/vps-hosting/) plan from Atlantic.Net. --- # How to Manage Databases in MariaDB on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-manage-databases-in-mariadb-on-ubuntu-18-04/ | Published: 2020-02-26 | Updated: 2026-03-03 | Author: Hitesh Jethva MariaDB is free, open-source, and one of the most popular database servers in the world. It is a community-developed fork of the very popular MySQL database management system. MariaDB provides support for PHP and uses a standard and popular querying language. MariaDB comes with a wide range of storage engines and several optimizations that can be used to improve the database performance. In this tutorial, we will show you how to manage databases in MariaDB on Ubuntu 18.04. ## Step 1 – Install MariaDB By default, the latest version of MariaDB is not available in the Ubuntu 18.04 default repository. Therefore, it is recommended to install MariaDB from the MariaDB repository. First, download and add the MariaDB GPG key to your system with the following command: ``` apt-get update -y apt-get upgrade -y apt-key adv --recv-keys --keyserver hkp://keyserver.ubuntu.com:80 0xF1656F24C74CD1D8 ``` Next, add the MariaDB repository using the following command: ``` add-apt-repository 'deb [arch=amd64,arm64,ppc64el] http://ftp.utexas.edu/mariadb/repo/10.3/ubuntu bionic main' ``` Next, update the repository and install MariaDB using the following commands: ``` apt-get update -y apt-get install mariadb-server -y ``` After installing MariaDB, check the status of MariaDB with the following command: ``` systemctl status mariadb ``` You should see the following output: ``` ● mariadb.service - MariaDB 10.3.19 database server Loaded: loaded (/lib/systemd/system/mariadb.service; enabled; vendor preset: enabled) Drop-In: /etc/systemd/system/mariadb.service.d └─migrated-from-my.cnf-settings.conf Active: active (running) since Wed 2019-11-06 04:25:01 UTC; 24s ago Docs: man:mysqld(8) https://mariadb.com/kb/en/library/systemd/ Main PID: 4538 (mysqld) Status: "Taking your SQL requests now..." Tasks: 32 (limit: 1114) CGroup: /system.slice/mariadb.service └─4538 /usr/sbin/mysqld Nov 06 04:25:03 ubuntu1804 /etc/mysql/debian-start[4584]: Phase 6/7: Checking and upgrading tables Nov 06 04:25:03 ubuntu1804 /etc/mysql/debian-start[4584]: Running 'mysqlcheck' with connection arguments: --port='3306' --socket='/var/run/mysq Nov 06 04:25:03 ubuntu1804 /etc/mysql/debian-start[4584]: # Connecting to localhost... Nov 06 04:25:03 ubuntu1804 /etc/mysql/debian-start[4584]: # Disconnecting from localhost... Nov 06 04:25:03 ubuntu1804 /etc/mysql/debian-start[4584]: Processing databases Nov 06 04:25:03 ubuntu1804 /etc/mysql/debian-start[4584]: information_schema Nov 06 04:25:03 ubuntu1804 /etc/mysql/debian-start[4584]: performance_schema ``` ## Step 2 – Create a New Database To create a new database, first log in to MariaDB shell with the following command: ``` mysql -u root -p ``` Enter your root password when prompted, then create a database with the following command: ``` CREATE DATABASE db1; ``` After creating a new database, you can list all databases with the following command: ``` SHOW DATABASES; ``` You should see the following output: ``` +--------------------+ | Database           | +--------------------+ | db1                | | information_schema | | mysql              | | performance_schema | +--------------------+ 4 rows in set (0.002 sec) ``` ## Step 3 – Create a New User Account You can create a new MariaDB user account by running the following command: ``` CREATE USER 'dbuser'@'localhost' IDENTIFIED BY 'yourpassword'; ``` In this line, the variables are defined as follows: **dbuser**: The name of the MariaDB user. **localhost**: This option specifies that the user can connect to the MariaDB server only from the localhost. **yourpassword**: The password of the MariaDB user. If you want to change the MariaDB user account password, then run the following command: ``` ALTER USER 'dbuser'@'localhost' IDENTIFIED BY 'yournewpassword'; ``` To list all MariaDB user accounts, run the following command: ``` SELECT user, host FROM mysql.user; ``` You should get the following output: ``` +------------------+-----------+ | user             | host      | +------------------+-----------+ | root             | 127.0.0.1 | | root             | ::1       | | dbuser           | localhost | | debian-sys-maint | localhost | | root             | localhost | +------------------+-----------+ 5 rows in set (0.003 sec) ``` ## Step 4 – Grant Privileges to User Account You can grant multiple types of privileges to the MariaDB user account. To grant all privileges to a user (dbuser) over a specific database (db1), run the following command: ``` GRANT ALL PRIVILEGES ON db1.* TO 'dbuser'@'localhost'; ``` To grant all privileges to a user (dbuser) over all databases, run the following command: ``` GRANT ALL PRIVILEGES ON *.* TO 'dbuser'@'localhost'; ``` To grant only specific privileges to a user (dbuser) over a specific database (db1), run the following command: ``` GRANT SELECT, INSERT, DELETE ON db1.* TO dbuser@'localhost'; ``` You can see all the privileges granted to a specific user account with the following command: ``` SHOW GRANTS FOR 'dbuser'@'localhost'; ``` You should see the following output: ``` +------------------------------------------------------------------------------------------------------------------------+ | Grants for dbuser@localhost                                                                                            | +------------------------------------------------------------------------------------------------------------------------+ | GRANT ALL PRIVILEGES ON *.* TO 'dbuser'@'localhost' IDENTIFIED BY PASSWORD '*7F99F4477B835ED95816BC01E9823771AE2A3F1C' | | GRANT ALL PRIVILEGES ON `db1`.* TO 'dbuser'@'localhost'                                                                | +------------------------------------------------------------------------------------------------------------------------+ 2 rows in set (0.000 sec) ``` ## Step 5 – Deleting Databases and Users You can delete a database with the following command: ``` DROP DATABASE db1; ``` To delete a user account, run the following command: ``` DROP USER 'dbuser'@'localhost'; ``` ## Step 6 – Reset MariaDB Root Password If you have forgotten your MariaDB root password, then you can recover it easily by following the below steps. First, stop the running MariaDB service with the following command: ``` systemctl stop mariadb ``` Next, you will need to start MariaDB service with –skip-grant-tables option. This will allow you to connect to the database server without a password: You can start MariaDB service without loading the grant tables by running the following command: ``` mysqld_safe --skip-grant-tables & ``` ![](https://www.atlantic.net/wp-content/uploads/2020/02/Start-MariaDB.png) Now, you can connect to the MariaDB server as a root user without a password as shown below: ``` mysql -u root ``` ![](https://www.atlantic.net/wp-content/uploads/2020/02/Maria-DB-Connect.png) After successful login, run the following command to reset the root password: ``` ALTER USER 'root'@'localhost' IDENTIFIED BY 'your-new-password'; FLUSH PRIVILEGES; ``` If the above command doesn’t work, run the following command: ``` UPDATE mysql.user SET authentication_string = PASSWORD('your-new-password') WHERE User = 'root' AND Host = 'localhost'; FLUSH PRIVILEGES; ``` ![](https://www.atlantic.net/wp-content/uploads/2020/02/MariaDB-PW-Reset-2.png) Next, stop the MariaDB service and start it normally with the following commands: ``` mysqladmin -u root -p shutdown ``` ![](https://www.atlantic.net/wp-content/uploads/2020/02/Start-MariaDB-2.png) Provide your root password when prompted to stop the MariaDB service. Next, start the MariaDB service normally with the following command: ``` systemctl start mariadb ``` ## Conclusion In the above tutorial, we learned how to create and manage databases and user accounts in MariaDB. We also learned how to reset the MariaDB root password. For more information, visit the MariaDB official documentation at [MariaDB Doc](https://mariadb.com/kb/en/documentation/). --- # Initial Server Setup with Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/initial-server-setup-with-ubuntu-18-04/ | Published: 2020-02-27 | Updated: 2023-11-25 | Author: Hitesh Jethva After installing or setting up a new Ubuntu 18.04 server, you will need to perform some basic steps to increase the server’s security, performance and reliability. In this tutorial, we will show you some basic configuration steps you should perform after installing a new Ubuntu 18.04 server. ## Step 1 – Create an Atlantic.Net Cloud Server First, log in to your [Atlantic.Net Cloud Server](https://cloud.atlantic.net/?page=userlogin).  Create a new [server](https://www.atlantic.net/vps-hosting/how-to-create-new-atlantic-net-cloud-server/), choosing Ubuntu 18.04 as the operating system with at least 2GB RAM. Connect to your Cloud Server via SSH and log in using the credentials highlighted at the top of the page. Once you are logged into your Ubuntu 18.04 server, you should update and upgrade all installed packages on your Ubuntu 18.04 server to benefit from the latest security patches. You can update and upgrade your system by running the following commands: ``` apt-get update -y apt-get upgrade -y ``` Once your system is updated, restart it to apply all the changes. Just type: ``` reboot ``` ## Step 2 – Create a New Superuser Account By default, the root is an administrative user in Linux-based operating systems. Root user allows you to perform any task and can make very destructive changes within your system. Therefore, it is recommended to set up a separate user account with sudo (superuser) privileges. With sudo user, you can restrict users to run specific commands. You can also produce an audit of which user run what commands. First, create a new user with the following command: ``` adduser user1 ``` You will be prompted to provide a password and contact details as shown below: ``` Adding user `user1' ... Adding new group `user1' (1001) ... Adding new user `user1' (1001) with group `user1' ... Creating home directory `/home/user1' ... Copying files from `/etc/skel' ... Enter new UNIX password: Retype new UNIX password: passwd: password updated successfully Changing the user information for user1 Enter the new value, or press ENTER for the default            Full Name []: New User            Room Number []:            Work Phone []:            Home Phone []:            Other []: Is the information correct? [Y/n] Y ``` Once the new user is created, you will need to give superuser privileges to this user. You can do it by adding this user to sudo group as shown below: ``` usermod -aG sudo user1 ``` You should always log in to Ubuntu 18.04 with this user. Exit or close your SSH session and log in as your new user. Typically the command prompt changes when logged in as a user: ![](https://www.atlantic.net/wp-content/uploads/2020/02/Ubuntu-Command-Prompt.png) You can run any command by typing sudo before any commands you want to run. For example, if you want to install an Apache webserver run the following command: ``` sudo apt-get install apache2 -y ``` You will need to provide your user password in order to install Apache. ## Step 3 – Secure SSH Server By default, SSH is configured to listen on port 22. Therefore, it is recommended to change default ssh port and disable root login to secure your system from attackers. You can change the default SSH port by editing /etc/ssh/sshd_config file: ``` sudo nano /etc/ssh/sshd_config ``` Find and change the following lines: ``` Port 9807 PermitRootLogin no ``` ![](https://www.atlantic.net/wp-content/uploads/2020/02/SSHD-Config-1.png) Save and close the file, then restart SSH service to apply the configuration: ``` sudo systemctl restart ssh ``` It is also a good idea to configure your server to disable password login and use key-based login instead. You can disable password-based authentication by editing the file /etc/ssh/sshd_config: ``` sudo nano /etc/ssh/sshd_config ``` Find the following lines and change the value to “no”: ``` PasswordAuthentication no ChallengeResponseAuthentication no UsePAM no ``` ![](https://www.atlantic.net/wp-content/uploads/2020/02/SSHD-Config-2.png) Save and close the file, then restart SSH service to apply the configuration: ``` sudo systemctl restart ssh ``` Next, generate an SSH key-pair on your trusted client system: ``` ssh-keygen -t rsa ``` You will need to press **Enter** to accept the default file location and provide a passphrase to add an extra layer of security. ![](https://www.atlantic.net/wp-content/uploads/2020/02/SSH-Keygen.png) Next, you will need to copy the key from your trusted client system to your Ubuntu 18.04 server. As we changed the default port in the previous section, we need to ensure we ssh-copy-id to the new port using the -p extension. You can copy it with the following command: ``` ssh-copy-id user1@your-server-ip -p9807 ``` You are now able to log in to your Ubuntu 18.04 server from your trusted client system with a public key. ## Step 4 – Configure Firewall By default, Ubuntu uses UFW firewall to manage iptables rules. If you are connected to your server via SSH, then it is good idea to allow SSH connections so you don’t get locked out. You can allow SSH connections with the following command: ``` ufw allow OpenSSH ``` Next, enable the UFW firewall using the following command: ``` ufw enable ``` You can now allow other services like Apache, SMTP, FTP via UFW per your requirements. ## Conclusion That’s it! your server is now ready for production. You can now install and configure any additional applications per your needs. Ready to get started with an Ubuntu 18.04? Try [VPS Hosting](https://www.atlantic.net/vps-hosting/) with Atlantic.Net! --- # How To Install the Anaconda Python Distribution on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-the-anaconda-python-distribution-on-ubuntu-18-04/ | Published: 2020-02-28 | Updated: 2024-06-24 | Author: Hitesh Jethva Anaconda is a free and open-source distribution of the Python and R programming languages. It is used for scientific computing, machine learning, and data science that involves heavy calculations and predictive analysis. Anaconda Python offers over 1400 data packages, both free and paid. In this tutorial, we will explain how to install the Anaconda Python Distribution on Ubuntu 18.04. ## Step 1 – Install Anaconda Before starting, visit the Anaconda [downloads page](https://www.anaconda.com/distribution) as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/02/Anaconda-Installer.png) At the time of writing this article, the latest stable version for Anaconda is 2019.10. You can download the Anaconda installation script with wget command as shown below: ``` wget https://repo.anaconda.com/archive/Anaconda3-2019.10-Linux-x86_64.sh ``` Once the download is completed, check the data integrity of the script by running sha256sum command: ``` sha256sum Anaconda3-2019.10-Linux-x86_64.sh ``` You should see the following output: ``` 46d762284d252e51cd58a8ca6c8adc9da2eadc82c342927b2f66ed011d1d8b53 Anaconda3-2019.10-Linux-x86_64.sh ``` Next, visit the [Anaconda Linux](https://docs.anaconda.com/anaconda/install/linux/) page and check that the above hash matches with the one available in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/02/Anaconda-Hashes.png) If everything is correct, run the Anaconda installation script with the following command: ``` bash Anaconda3-2019.10-Linux-x86_64.sh ``` You should see the “Welcome” message in the following output: ``` Welcome to Anaconda3 2019.10 In order to continue the installation process, please review the license Please, press ENTER to continue >>> ``` Now, press **ENTER** to continue. You should see the following output: ``` Please answer 'yes' or 'no':' >>> yes ``` Type **yes** to continue. You should see the following output: ``` Anaconda3 will now be installed into this location: /root/anaconda3 - Press ENTER to confirm the location - Press CTRL-C to abort the installation - Or specify a different location below [/root/anaconda3] >>> ``` By default, Anaconda Python will be installed on the ~/anaconda3 directory in your user’s HOME directory. You can also choose your desired installation directory. Press the Enter button to install the Anaconda in the default location. You should see the following output: ``` Preparing transaction: done Executing transaction: done installation finished. Do you wish the installer to initialize Anaconda3 by running conda init? [yes|no] [no] >>> yes ``` Now, type **yes** to initialize Anaconda3. Once the installation has been completed, you should see the following output: ``` ==> For changes to take effect, close and re-open your current shell. <== If you'd prefer that conda's base environment not be activated on startup, set the auto_activate_base parameter to false: conda config --set auto_activate_base false Thank you for installing Anaconda3! =========================================================================== Anaconda and JetBrains are working together to bring you Anaconda-powered environments tightly integrated in the PyCharm IDE. PyCharm for Anaconda is available at: https://www.anaconda.com/pycharm ``` Next, activate Anaconda with the following command: ``` source ~/.bashrc ``` You should see the following output: ``` (base) root@ubuntu1804:~# ``` ## Step 2 – Verify Anaconda Python Installation Now that Anaconda Python is installed, you can run the following command to verify the installation. ``` conda info ``` You should get the following output: ``` active environment : base active env location : /root/anaconda3 shell level : 1 user config file : /root/.condarc populated config files : conda version : 4.7.12 conda-build version : 3.18.9 python version : 3.7.4.final.0 virtual packages : base environment : /root/anaconda3 (writable) channel URLs : https://repo.anaconda.com/pkgs/main/linux-64 https://repo.anaconda.com/pkgs/main/noarch https://repo.anaconda.com/pkgs/r/linux-64 https://repo.anaconda.com/pkgs/r/noarch package cache : /root/anaconda3/pkgs /root/.conda/pkgs envs directories : /root/anaconda3/envs /root/.conda/envs platform : linux-64 user-agent : conda/4.7.12 requests/2.22.0 CPython/3.7.4 Linux/4.15.0-66-generic ubuntu/18.04.3 glibc/2.27 UID:GID : 0:0 netrc file : None offline mode : False ``` You can also check the Anaconda version with the following command: ``` conda --version ``` You should see the following output: ``` conda 4.7.12 ``` You can list all the installed Anaconda Python packages by running the following command: ``` conda list ``` You should get the following output: ``` # packages in environment at /root/anaconda3: # # Name Version Build Channel _ipyw_jlab_nb_ext_conf 0.1.0 py37_0 _libgcc_mutex 0.1 main alabaster 0.7.12 py37_0 anaconda 2019.10 py37_0 anaconda-client 1.7.2 py37_0 anaconda-navigator 1.9.7 py37_0 anaconda-project 0.8.3 py_0 asn1crypto 1.0.1 py37_0 astroid 2.3.1 py37_0 astropy 3.2.2 py37h7b6447c_0 atomicwrites 1.3.0 py37_1 attrs 19.2.0 py_0 babel 2.7.0 py_0 backcall 0.1.0 py37_0 backports 1.0 py_2 backports.functools_lru_cache 1.5 py_2 backports.os 0.1.1 py37_0 backports.shutil_get_terminal_size 1.0.0 py37_2 backports.tempfile 1.0 py_1 : : ``` ## Step 3 – Configure Anaconda Environments To keep all your projects organized, it is recommended to create an Anaconda virtual environment for each project. You can easily select the required version of Python for your Anaconda Python environment. Check the available versions of Python by running the following command: ``` conda search "^python$" ``` You can see multiple versions of Python, including Python 2 and Python 3. Next, let’s create a new environment with name test_env using Python 3 as shown below: ``` conda create --name test_env python=3 ``` Type [Y] to proceed. Next, activate the newly created environment with the following command: ``` conda activate test_env ``` You should see the following output: ``` (test_env) root@ubuntu1804:~# ``` Now, check the version of Python with the following command: ``` python --version ``` The output will look like this: ``` Python 3.8.0 ``` Now, deactivate from your Anaconda environment with the following command: ``` conda deactivate ``` You can also list all your environments with the following command: ``` conda info --envs ``` You should get the following output: ``` # conda environments: # base * /root/anaconda3 test_env /root/anaconda3/envs/test_env ``` ## Step 4 – Update Anaconda You can update the Anaconda easily with a conda tool. First, you will need to update the conda tool using the following command: ``` conda update conda ``` Type **y** and press **Enter** to confirm the update. Next, update Anaconda by running the following command: ``` conda update anaconda ``` Type **y** and press **Enter** to update Anaconda. ## Step 5 – Uninstall Anaconda In this section, we will show you how to remove Anaconda from your system. First, remove the test_env with the following command: ``` conda env remove -n test_env ``` You should get the following output: ``` Remove all packages in environment /root/anaconda3/envs/test_env: ``` Next, install anaconda-clean module to uninstall Anaconda with all the configuration files. ``` conda install anaconda-clean ``` Type **yes** and hit **Enter** to complete the installation. Next, run the following command to remove the Anaconda from your system: ``` source .bashrc anaconda-clean ``` Type **y** and hit **Enter** to remove Anaconda: ``` Delete .conda? (y/n): y Backup directory: /root/.anaconda_backup/2019-11-28T094615 ``` Next, remove the Anaconda root directory with the following command: ``` rm -rf ~/anaconda3 ``` Next, open the ~/.bashrc file and remove the Anaconda environment variable: ``` nano ~/.bashrc ``` Remove the following lines: ``` __conda_setup="$('/root/anaconda3/bin/conda' 'shell.bash' 'hook' 2> /dev/null)" if [ $? -eq 0 ]; then eval "$__conda_setup" else if [ -f "/root/anaconda3/etc/profile.d/conda.sh" ]; then . "/root/anaconda3/etc/profile.d/conda.sh" else export PATH="/root/anaconda3/bin:$PATH" fi fi unset __conda_setup ``` [Before] ![](https://www.atlantic.net/wp-content/uploads/2020/02/Anaconda-Uninstall-1.png) [After] ![](https://www.atlantic.net/wp-content/uploads/2020/02/Anaconda-Uninstall-2.png) Save and close the file when you are finished. At this point, Anaconda is completely removed from your server. ## Conclusion Congratulations! You have successfully installed Anaconda Python on Ubuntu 18.04 server. You now have enough knowledge to create environments, perform updates, and manage large-scale data with Anaconda Python. Get started today with Anaconda on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Apache Subversion on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-apache-subversion-on-ubuntu-18-04/ | Published: 2020-02-29 | Updated: 2023-11-17 | Author: Hitesh Jethva Apache Subversion is an open-source version control system that stores previous versions of and changes to your files and directories. This will allow you to recover your older versions of files when you need it. You can also track the repository and identify who made specific changes. Subversion is very similar to Git with the key difference that Git is a distributed version control system while SVN is a centralized version control system. Subversion has a single central repository that makes it easier for you to maintain a top-down approach to control. In this tutorial, we will show you how to install and configure Apache Subversion on Ubuntu 18.04. ## Step 1 – Install Apache Subversion Before starting, Apache webserver must be installed on your server. If not installed, you can install it with the following command: ``` apt-get install apache2 apache2-utils -y ``` Once the installation has been completed, you can install the Subversion with the following command: ``` apt-get install subversion libapache2-mod-svn -y ``` After installing Apache Subversion, you will need to enable some SVN modules. You can enable them with the following command: ``` a2enmod dav a2enmod dav_svn a2enmod authz_svn ``` Once all the modules are enabled, restart the Apache service to implement the changes: ``` systemctl restart apache2 ``` At this point, Apache Subversion is installed. You can now proceed to create your first repository. ## Step 2 – Create the Subversion Repository In this section, we will create the Subversion repository and create a user to access this repository. First, create a directory for Subversion: ``` mkdir /svn ``` Next, create a repository named atlanticrepo inside the /svn directory: ``` svnadmin create /svn/atlanticrepo ``` Once the repository is created, change the ownership of the repository to www-data: ``` chown -R www-data:www-data /svn/atlanticrepo chmod -R 775 /svn/atlanticrepo ``` Next, create a new Subversion user with the following command: ``` htpasswd -cm /etc/svn-user atlantic ``` Provide your desired password, as shown below: ``` New password: Re-type new password: Adding password for user atlantic ``` ## Step 3 – Configure Apache for Subversion Next, you will need to create an Apache virtual host file to access Apache Subversion through a web browser. You can create it with the following command: ``` nano /etc/apache2/sites-available/svn.conf ``` Add the following lines: ``` ServerName svn.example.com DAV svn SVNParentPath /svn AuthType Basic AuthName "Subversion Repository" AuthUserFile /etc/svn-user Require valid-user ErrorLog ${APACHE_LOG_DIR}/svn-error.log CustomLog ${APACHE_LOG_DIR}/svn-access.log combined ``` Save and close the file when you are finished. Then, restart the Apache service to implement the changes: ``` systemctl restart apache2 ``` ## Step 4 – Access Apache Subversion Now, open your web browser and type the URL **http://svn.example.com/svn/atlanticrepo**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/02/Apache-Subversion-Login.png) Now, provide your username, password and click on the O**K b**utton. You should see your created repository in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/02/Apache-Subversion-Repository.png) ## Step 5 – Test Subversion In this section, we will install the Subversion client in the remote system, check out the repository from the Subversion server, create some files and directories, and add them to the Subversion repository. Go to the remote system and install Subversion with the following command: ``` apt-get install subversion -y ``` Once installed, create a directory for the local repository with the following command: ``` mkdir atlantic ``` Next, check out the atlanticrepo repository from the Subversion server to the local repository with the following command: ``` svn checkout http://svn.example.com/svn/atlanticrepo --username atlantic atlantic/ ``` You will be asked to provide a password for the user “atlantic” as shown below: ``` Authentication realm: Subversion Repository Password for 'atlantic': ***** Checked out revision 0. ``` Next, change the directory to the atlantic repository and create some files and directories: ``` cd atlantic touch file1.txt file2.txt mkdir dir1 dir2 ``` Next, add all the files and directories to the Subversion repository with the following command: ``` svn add file1.txt file2.txt dir1 dir2 ``` You should see the following output: ``` A         file1.txt A         file2.txt A         dir1 A         dir2 ``` Next, commit changes to the repository with the following command: ``` svn commit -m 'This is my first commit on Atlantic SVN server' ``` You should see the following output: ``` Adding         dir1 Adding         dir2 Adding         file1.txt Adding         file2.txt Transmitting file data .. Committed revision 1. ``` Now, open your web browser and access your repository using the URL **http://svn.example.com/svn/atlanticrepo**. You should see your newly added files and directories in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/02/Apache-Subversion-Directories-Files.png) ## Conclusion Congratulations! You have successfully installed and configured an Apache Subversion server on Ubuntu 18.04. You can now keep track of all your files and folders and recover any version of your files whenever you need it. Try Apache Subversion today on an Atlantic.Net [virtual private server](https://www.atlantic.net/vps-hosting/). --- # How to Install Joomla CMS on CentOS 8/RHEL 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-joomla-cms-on-centos-8-rhel-8/ | Published: 2020-03-01 | Updated: 2024-06-11 | Author: Hitesh Jethva Joomla is a free, open-source content management system (CMS). It is one of the most widely used content management systems. Joomla is written in PHP and can be used to build an eCommerce store, blog, or personal website with little coding knowledge. It comes with a simple and easy-to-use web interface that helps you create a dynamic and powerful website within a minute. Joomla’s 10,000+ add-ons help you to customize the appearance and functionality of your website. It supports several operating systems including Linux, Windows, Mac OS, FreeBSD, and Solaris, and easily integrates with Gmail and OpenID. In this guide, we will show you how to install Joomla CMS on CentOS 8 server. ## Prerequisites - A fresh CentOS 8 [VPS](https://www.atlantic.net/vps-hosting/). - A valid domain name pointed to your IP address. In this tutorial, we will use joomla.example.com. - A root password is configured on your server. **Note** : You can refer the Atlantic DNS Guide to manage the [DNS records](https://www.atlantic.net/dedicated-server-hosting/cloud-hosting-getting-started-with-dns-records/). ## Step 1 – Install LAMP Server Joomla runs on the Linux Apache webserver, and it is written in PHP and uses MariaDB for the database backend. Therefore, you will need to install the Apache, MariaDB, PHP and other PHP extensions to your system. You can install all of them with the following command: ``` dnf install httpd mariadb-server php php-cli php-common php-spl php-hash php-ctype php-json php-mbstring php-zip php-gd php-curl php-mysqli php-xml unzip -y ``` Once all the packages are installed, open the php.ini file and tweak some settings as per your requirements: ``` nano /etc/php.ini ``` Change the following values: ``` memory_limit = 256 output_buffering = Off max_execution_time = 300 date.timezone = Europe/London ``` Note that you should set your time zone to your local time zone (which you can find here [www.php.net](https://www.php.net/manual/en/timezones.php)) and that in our example, the default output_buffering setting is “off.” Save and close the file when you are finished. Then, start the Apache and MariaDB services and enable them to start after system reboot with the following command: ``` systemctl start httpd systemctl start mariadb systemctl enable httpd systemctl enable mariadb ``` At this point, the LAMP server is installed. You can now proceed to the next step. ## Step 2 – Configure the MariaDB Database By default, MariaDB is not secured. You can secure it using the following script: ``` mysql_secure_installation ``` This script will set the MariaDB root password, remove anonymous users, disallow root login remotely, and remove the test database, as shown below: ``` Enter current password for root (enter for none): Just Press Enter Set root password? [Y/n] Y Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` Once you are done, log in to the MariaDB shell with the following command: ``` mysql -u root -p ``` Provide your root password, then create a database and user for Joomla: ``` CREATE DATABASE joomladb; GRANT ALL PRIVILEGES ON joomladb.* TO 'joomla'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` Once the MariaDB is configured, you can proceed to the next step. ## Step 3 – Install Joomla First, you will need to download the latest version of Joomla from its official website. At the time of writing this article, the latest stable version of Joomla is 3.9.15. You can download it with the following command: ``` wget https://downloads.joomla.org/cms/joomla3/3-9-15/Joomla_3-9-15-Stable-Full_Package.zip?format=zip -O joomla.zip ``` Once downloaded, unzip the downloaded file to the Apache web root directory: ``` unzip joomla.zip -d /var/www/html/joomla ``` Next, give proper permissions to the Joomla directory: ``` chown -R apache:apache /var/www/html/joomla/ chmod -R 775 /var/www/html/joomla/ ``` Once you are done, you can proceed to the next step. ## Step 4 – Configure Apache for Joomla Next, you will need to configure the Apache virtual host to serve Joomla. You can create a new virtual host file using the following command: ``` nano /etc/httpd/conf.d/joomla.conf ``` Add the following lines: ```   ServerAdmin admin@example.com   DocumentRoot "/var/www/html/joomla"   ServerName joomla.example.com   ErrorLog "/var/log/httpd/example.com-error_log"   CustomLog "/var/log/httpd/example.com-access_log" combined   DirectoryIndex index.html index.php   Options FollowSymLinks   AllowOverride All   Require all granted ``` Save and close the file when you are finished. Then, restart the Apache web service to apply the changes: ``` systemctl restart httpd ``` ## Step 5 – Configure Firewall If the firewalld service is enabled on your system, you will need to allow HTTP/HTTPS port through firewalld. First, check the firewalld service using the following command: ``` systemctl status firewalld ``` You should see that firewalld service is not running: ``` ● firewalld.service - firewalld - dynamic firewall daemon   Loaded: loaded (/usr/lib/systemd/system/firewalld.service; disabled; vendor preset: enabled)   Active: inactive (dead)     Docs: man:firewalld(1) ``` You can start the firewalld service and enable it to start after system reboot with the following command: ``` systemctl start firewalld systemctl enable firewalld ``` Next, allow HTTP and HTTPS port through firewalld with the following command: ``` firewall-cmd --permanent --add-service=http firewall-cmd --permanent --add-service=https ``` Next, reload the firewalld to apply the changes: ``` firewall-cmd --reload ``` After this, firewalld is configured to allow Joomla accessible from the remote host. ## Step 6 – Access Joomla Web Interface Open your web browser and open the URL http://joomla.example.com. You will be redirected to the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Joomla-Web-Interface.png) Provide your site name, site information, email address, admin username, and password and click on the **Next** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Joomla-Database-Configuration.png) Provide your Joomla database credentials (which you created early) and click on the **Next** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Joomla-Configuration-Review-1.png) ![](https://www.atlantic.net/wp-content/uploads/2020/03/Joomla-Configuration-Review-2.png) Now, review the configuration and click on the **Install** button to start the installation. Once the installation has been completed, you should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Joomla-Installed.png) Next, click on the “**Remove installation folder**” button to completely remove the installation directory from your system. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Joomla-Installation-Directory-Removed.png) Next, click on the **Administrator** button. You will be redirected to the Joomla admin panel shown in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Joomla-Login.png) Provide your Joomla admin username and password and click on the **Log** **in** button. You should see the Joomla default dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Joomla-Control-Panel.png) You can also access the Joomla website by visiting the URL http://joomla.example.com as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Joomla-Site.png) ## Conclusion Congratulations! You have successfully installed Joomla CMS on CentOS 8 server. You can now able to build your own website or blog using the Joomla admin panel. Get started with Joomla on a [VPS Hosting](https://www.atlantic.net/vps-hosting/) plan from Atlantic.Net! --- # How to Install Jenkins on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-jenkins-on-ubuntu-18-04/ | Published: 2020-03-02 | Updated: 2023-11-18 | Author: Hitesh Jethva Jenkins is a free and open-source continuous integration (CI) and continuous delivery (CD) application written in the Java programming language. It is specially designed to monitor the execution of repetitive jobs and tests and while reporting any changes in the code to you in real-time. It is a cross-platform application that can be run on Windows, Linux, and any other operating system. Jenkins is very popular because of its simple interface, UI customization, support for different version control systems and great extensibility. Jenkins comes with a rich set of features, including support for more than 1000 plugins, bug detection, static code analysis, unit test execution, building projects and deploying applications. In this tutorial, we will show you how to install Jenkins on Ubuntu 18.04. ## Step 1 – Install Java 8 Jenkins is a Java-based application and does not support Java versions 10 and 11, so you will need to install the Java 8 OpenJDK package on your system. Run the following command to install Java 8 on your system. ``` apt-get install openjdk-8-jdk -y ``` Once the Java package is installed, you can verify the installed version of Java with the following command: ``` java -version ``` You should get the following output: ``` openjdk version "1.8.0_232" OpenJDK Runtime Environment (build 1.8.0_232-8u232-b09-0ubuntu1~18.04.1-b09) OpenJDK 64-Bit Server VM (build 25.232-b09, mixed mode) ``` ## Step 2 – Install Jenkins By default, Jenkins is not available in the Ubuntu 18.04 default repository, so you will need to add the Jenkins repository to your system. First, download and add the GPG keys of the Jenkins repository with the following command: ``` wget -q -O - https://pkg.jenkins.io/debian/jenkins.io.key | apt-key add - ``` ![](https://www.atlantic.net/wp-content/uploads/2020/03/Jenkins-GPG-Keys.png) Next, add the Jenkins repository with the following command: ``` sh -c 'echo deb http://pkg.jenkins.io/debian-stable binary/ > /etc/apt/sources.list.d/jenkins.list' ``` Once the repository is added, update the repository and install the Jenkins package with the following command: ``` apt-get update -y apt-get install jenkins -y ``` After installing the Jenkins package, verify the status of Jenkins with the following command: ``` systemctl status jenkins ``` You should get the following output: ``` ● jenkins.service - LSB: Start Jenkins at boot time   Loaded: loaded (/etc/init.d/jenkins; generated)   Active: active (exited) since Mon 2020-01-27 09:08:35 UTC; 51s ago     Docs: man:systemd-sysv-generator(8)    Tasks: 0 (limit: 1150)   CGroup: /system.slice/jenkins.service Jan 27 09:08:34 ubuntu1804 systemd[1]: Starting LSB: Start Jenkins at boot time... Jan 27 09:08:34 ubuntu1804 jenkins[4251]: Correct java version found Jan 27 09:08:34 ubuntu1804 jenkins[4251]:  * Starting Jenkins Automation Server jenkins Jan 27 09:08:34 ubuntu1804 su[4297]: Successful su for jenkins by root Jan 27 09:08:34 ubuntu1804 su[4297]: + ??? root:jenkins Jan 27 09:08:34 ubuntu1804 su[4297]: pam_unix(su:session): session opened for user jenkins by (uid=0) Jan 27 09:08:34 ubuntu1804 su[4297]: pam_unix(su:session): session closed for user jenkins Jan 27 09:08:35 ubuntu1804 jenkins[4251]:    ...done. Jan 27 09:08:35 ubuntu1804 systemd[1]: Started LSB: Start Jenkins at boot time. ``` At this point. Jenkins is installed and running on your server. ## Step 3 – Set Up Jenkins By default, Jenkins is listening on the port **8080**. You can access it by visiting the URL **http://your-server-ip:8080** in your web browser. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Unlock-Jenkins.png) From the above screen, copy the location of the initial password, open your terminal, and run the following command to display the password: ``` cat /var/lib/jenkins/secrets/initialAdminPassword ``` Output: ``` [YOUR UNIQUE PASSWORD] ``` Copy this password from the terminal, paste it into the above screen, and click on the **Continue** button. After a few minutes, you will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2020/03/Customize-Jenkins.png) From here, you can install suggested plugins or install your desired plugins. Click on **Install** **suggested** **plugins** to start the installation process. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Jenkins-Installation.png) Once the installation has been completed, you will be redirected to the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Jenkins-Admin.png) Provide your administrative username, password, and email and click on the **Save** **and** **Continue** button. You should see an Instance Configuration screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Jenkins-Configuration.png) Confirm the preferred URL for your Jenkins instance and click on the **Save** **and** **Finish** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Jenkins-Setup-Complete.png) Jenkins is now ready. You can click on the **Start** **using** **Jenkins** button. You will be redirected to the Jenkins dashboard as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Jenkins-Dashboard.png) ## Conclusion Congratulations! Jenkins is now installed and ready to automate the development tasks. You can now start exploring Jenkins and working with it as soon as possible – try it out on your [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Use pgAdmin on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-pgadmin-on-ubuntu/ | Published: 2020-03-03 | Updated: 2023-11-22 | Author: Hitesh Jethva pgAdmin is a free, open-source, and web-based tool for managing a PostgreSQL database server. It is written in Python and Jquery and runs on most popular operating systems, including Windows, Linux, and Mac OS. pgAdmin comes with a rich set of features, a few of which are listed below: - Multi-platform compatible with multiple deployment models - Monitoring dashboard - Supports desktop mode and server mode - User-friendly, with powerful graphical interfaces - Powerful query tool and syntax highlighting editor In this tutorial, we will show you how to install and configure pgAdmin on Ubuntu 18.04. ## Step 1 – Install PostgreSQL Server By default, the latest version of the PostgreSQL is not available in the Ubuntu 18.04 default repository. You will need to add the PostgreSQL repository in your system. First, download and add the Postgres key with the following command: ``` wget --quiet -O - https://www.postgresql.org/media/keys/ACCC4CF8.asc | apt-key add - ``` Next, add the PostgreSQL repository with the following command: ``` echo "deb http://apt.postgresql.org/pub/repos/apt/ `lsb_release -cs`-pgdg main" | tee  /etc/apt/sources.list.d/pgdg.list ``` Next, update the repository and install the PostgreSQL server with the following command: ``` apt-get update -y apt-get install postgresql postgresql-contrib -y ``` Once the installation is completed, verify the status of the PostgreSQL server with the following command: ``` systemctl status postgresql ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/03/PostgreSQL-Status.png) ## Step 2 – Set PostgreSQL User Password By default, the password of the PostgreSQL user is not set. To set it, log in to the Postgres user with the following command: ``` su - postgres psql ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Postgres-User.png) Next set the Postgres user password with the following command: ``` \password postgres ``` Provide your desired password as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Postgres-Password.png) Next, exit from the Postgres Shell with the following command: ``` exit ``` Next, exit from the Postgres user with the following command: ``` exit ``` ## Step 3 – Install pgAdmin Next, you can install the latest version of pgAdmin by running the following command: ``` apt-get install pgadmin4 pgadmin4-apache2 -y ``` During the installation, you will be asked to provide your initial email address to create an admin user, as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/03/pgAdmin-User-Email.png) **Note**: You will need these credentials later, so make sure to copy them down. Provide your email address and click on the **Ok** button. You will also need set an admin password, as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/03/pgAdmin-User-Password.png) Provide your desired password and click on the **Ok** button to start the installation process. Once the installation has finished, you can proceed to the next step. ## Step 4 – Access pgAdmin Web Interface Now, open your web browser and type the URL **http://YOUR_IP_ADDRESS/pgadmin4** – you will be redirected to the pgAdmin web interface in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/pgAdmin-Web-Interface.png) Provide your email address and password and click on the **Login** button. You should see the pgAdmin default dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/pgAdmin-Dashboard.png) Next, click on the **Add** **New** **Server** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/pgAdmin-Add-Server.png) In the General tab, provide the name of the server and click on the **Connection** tab. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/pgAdmin-Connection.png) Provide the Hostname or IP address of the server that you want to connect, as well as the Port number, PostgreSQL username, and password, and click on the **Save** button. Once the connection has been established, you should see the detailed information about your PostgreSQL database in the left pane: ![](https://www.atlantic.net/wp-content/uploads/2020/03/pgAdmin-PostgreSQL-Database.png) ## Conclusion Congratulations! You have successfully installed pgAdmin on Ubuntu 18.04. You have also accessed pgAdmin and connected it to the local PostgreSQL database. For more information, read the pgAdmin documentation at [pgAdmin doc](https://www.pgadmin.org/docs/). Get started with pgAdmin on a [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # How to Install OpenLiteSpeed Web Server with MariaDB and PHP > URL: https://www.atlantic.net/vps-hosting/how-to-install-openlitespeed-web-server-with-mariadb-and-php/ | Published: 2020-03-04 | Updated: 2024-06-04 | Author: Hitesh Jethva OpenLiteSpeed is an open-source version of the LiteSpeed Enterprise Web Server developed by LiteSpeed Technologies. It is a lightweight, high-performance, secure, easy-to-use, and low-resource-usage web server that can be used to manage hundreds of thousands of simultaneous connections. OpenLiteSpeed comes with a user-friendly web interface that helps you to create and manage your websites easily. It is highly optimized to run all kinds of scripts including Java, PHP, Ruby, Perl, and more, and supports various operating systems, including Linux, MacOS, FreeBSD and SunOS. **Features** - User-friendly web interface - Intelligent cache acceleration - Event-driven architecture with low resource overhead - Able to handle thousands of concurrent connections - Supports high-performance page caching - Support of third-party modules to enhance its functionality In this tutorial, we will show you how to install and configure the OpenLiteSpeed web server with PHP and MariaDB on an Ubuntu 18.04 VPS. ## Step 1 – Install OpenLiteSpeed By default, OpenLiteSpeed is not available in the Ubuntu 18.04 default repository. You will need to compile OpenLiteSpeed from their source. Before compiling OpenLiteSpeed, you will need to install required dependencies in your system. You can install all the dependencies with the following command: ``` apt-get install build-essential libexpat1-dev libgeoip-dev libxml2-dev rcs libpng-dev libpng-dev openssl autoconf g++ make openssl libssl-dev libcurl4-openssl-dev libcurl4-openssl-dev pkg-config libpcre3-dev libudns-dev zlib1g-dev libssl-dev libxml2 libsasl2-dev libzip-dev wget -y ``` Once all the required dependencies are installed, visit the [OpenLiteSpeed download page](https://openlitespeed.org)and download the latest version of OpenLiteSpeed using the wget command as shown below: ``` wget https://openlitespeed.org/packages/openlitespeed-1.6.4.tgz ``` Once the download is completed, extract the downloaded file using the following command: ``` tar -xvzf openlitespeed-1.6.4.tgz ``` Next, change the directory to the extracted directory with the following command: ``` cd openlitespeed ``` Next, install OpenLiteSpeed by running the following script: ``` sh install.sh ``` Once the installation has completed successfully, you should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/03/OpenLiteSpeed-Installation-Complete.png) At this point, you have OpenLiteSpeed installed in your system. ## Step 2 – Configure Administrative Password By default, the admin password for OpenLiteSpeed is set to 123456. It is always recommended to change the default password. You can change the default password with the following command: ``` /usr/local/lsws/admin/misc/admpass.sh ``` You will be asked to provide the administrative username as shown below: ``` Please specify the user name of administrator. This is the user name required to login the administration Web interface. User name [admin]: openadmin Provide your desired username and hit Enter to continue. You will be asked to provide the administrator's password: Please specify the administrator's password. This is the password required to login the administration Web interface. Password: Retype password: ``` Provide your desired password and hit Enter to set the password. You should get the following output: ``` Administrator's username/password is updated successfully! ``` Next, start the OpenLiteSpeed service and enable it to start after system reboot with the following command: ``` systemctl start lsws systemctl enable lsws ``` OpenLiteSpeed is now listening on port 7080 and 8088. You can verify it with the following command: ``` netstat  -ant ``` You should see the following output: ``` Active Internet connections (servers and established) Proto Recv-Q Send-Q Local Address           Foreign Address         State     tcp        0      0 0.0.0.0:7080            0.0.0.0:*               LISTEN    tcp        0      0 127.0.0.53:53           0.0.0.0:*               LISTEN    tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN    tcp        0      0 0.0.0.0:8088            0.0.0.0:*               LISTEN ``` You can also verify the OpenLiteSpeed installation by visiting the URL http://YOUR_IP_ADDRESS:8088. You will be redirected to the OpenLiteSpeed default web page: ![](https://www.atlantic.net/wp-content/uploads/2020/03/OpenLiteSpeed-Default-Webpage.png) ## Step 3 – Install MariaDB Database Server By default, MariaDB is available in the Ubuntu 18.04 default repository. You can install it by running the following command: ``` apt-get install mariadb-server mariadb-client -y ``` After installing MariaDB , you will need to secure it first. You can secure it by running the following script: ``` mysql_secure_installation ``` First, you will be asked to enter your current root password as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/03/MariaDB-Password.png) Just press the Enter button. You will be asked to change the root password as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/03/MariaDB-Change-Password.png) Type **n** and press **Enter** button. You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/03/MariaDB-Remove-Anonymous-Users.png) Type **Y** and press **Enter** button to remove the anonymous users: ![](https://www.atlantic.net/wp-content/uploads/2020/03/MariaDB-Disallow-Root-Login-Remotely.png) Type **Y** and press **Enter** button to disallow root login remotely: ![](https://www.atlantic.net/wp-content/uploads/2020/03/MariaDB-Remove-Test-Database.png) Type **Y** and press **Enter** button to remove the test database and access to it: ![](https://www.atlantic.net/wp-content/uploads/2020/03/MariaDB-Reload-Privilege-Tables.png) Finally, type **Y** and press **Enter** button to reload privilege tables. Once the MariaDB is secured, you should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/03/MariaDB-Secured.png) ## Step 4 – Access OpenLiteSpeed Administrative Interface In this section, we will learn how to download and compile PHP from the OpenLiteSpeed web interface and change the OpenLiteSpeed default port 8088. ## Step 5 – Install PHP for OpenLiteSpeed OpenLiteSpeed uses a different PHP version than the PHP version available in the Ubuntu repository. You will need to compile and configure PHP through their admin interface. First, open your web browser and type the URL https://example.com:7080. You will be redirected to the OpenLiteSpeed administrative login page: ![](https://www.atlantic.net/wp-content/uploads/2020/03/OpenLiteSpeed-Admin-Login.png) Provide your administrative username, password and click on the **Login** button. You should see the OpenLiteSpeed dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/03/OpenLiteSpeed-PHP-Version.png) In the left pane, click on the **Tools >> Compile PHP** button, then select your desired PHP version and click on the **Next** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/03/OpenLiteSpeed-PHP-Options.png) Now, select your desired options and click on the **Next** button to start the installation. Once the installation has been completed successfully, you should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/03/OpenLiteSpeed-PHP-Source-Code.png) ![](https://www.atlantic.net/wp-content/uploads/2020/03/OpenLiteSpeed-PHP-Compile.png) Now, open your terminal and run the following command to build PHP manually: ``` /usr/local/lsws/phpbuild/buildphp_manual_run.sh ``` Once the process has been completed, you should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/03/OpenLiteSpeed-PHP-Complete.png) You can also check the installation log with the following command: ``` tail -f /usr/local/lsws/phpbuild/buildphp_1574913605.2.log ``` You should get the following output: ``` copy compiled php binary to litespeed directory cd /usr/local/lsws//fcgi-bin ln -sf lsphp-7.3.11 lsphp7 ============================================== Finished building PHP 7.3.11 with LSAPI ============================================== Thu Nov 28 04:16:41 UTC 2019 **DONE** ``` At this point, you have PHP installed on your server. ## Step 6 – Change OpenLiteSpeed Port for the Default Site By default, OpenLiteSpeed uses port 8088. It is a good idea to change the default port from 8088 to 80. To do so, go to the OpenLiteSpeed admin interface and click on the **Listeners**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/03/OpenLiteSpeed-Listener-List.png) Next, click on the **Edit** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/03/OpenLiteSpeed-Listener-Edit.png) Next, change the port from 8088 to 80 and click on the **Save** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/03/OpenLiteSpeed-Listener-Port-Changed.png) ![](https://www.atlantic.net/wp-content/uploads/2020/03/OpenLiteSpeed-Restart.png) Next, you will need to perform a graceful restart to apply the changes. Click on the **green** button to restart the OpenLiteSpeed server. ## Step 7 – Validate PHP At this point, you have PHP installed on your server. It’s time to validate the PHP whether it is working or not. Open your web browser and visit the URL http://example.com/phpinfo.php. You should see your installed PHP version in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/03/OpenLiteSpeed-PHP-Confirmation.png) ## Conclusion Congratulations! you have successfully installed OpenLiteSpeed with PHP support on Ubuntu 18.04 VPS. You can now host your own high-performance website using OpenLiteSpeed – get started with an Atlantic.Net [VPS](https://www.atlantic.net/vps-hosting/). --- # How can remote working and business continuity planning mitigate the impact of the COVID-19 (Coronavirus)? > URL: https://www.atlantic.net/vps-hosting/how-can-remote-working-and-business-continuity-planning-mitigate-the-impact-of-the-covid-19-coronavirus/ | Published: 2020-03-06 | Updated: 2024-11-14 | Author: Richard Bailey The Novel Coronavirus – COVID-19 – is making headlines around the world.  Businesses are cautiously being advised to review business continuity plans (BCP) in the event the global virus outbreak is upgraded to a pandemic, and people are advised to self-isolate to reduce the spreading of the virus. Some estimates suggest that [up to one in five people “could be affected by this”](https://www.bbc.co.uk/news/uk-51718917) in the event of a pandemic. ### What Can We Expect? According to the Centers for Disease Control and the World Health Organisation (WHO), COVID-19 belongs to the same class of viruses like the common cold and MERS virus. At present, significant parts of Asia, Europe, and North America are on high alert, governments are outlining emergency preparations in direct response to the virus. It is advised that businesses do the same and review readiness guidelines and business continuity planning. There is a very real chance that government guidelines will be updated to advise US citizens to self-isolate to contain the virus. Some businesses (including Google and Twitter) are already taking preventative actions and [asking all employees to work from home](https://www.theguardian.com/world/2020/mar/04/coronavirus-google-tech-dublin-twitter-work-from-home). COVID-19 is also starting to affect day-to-day business; for example, a large number of companies initially pulled out of the HIMSS exhibition, a major Healthcare IT conference in Orlando, and today, the conference has been canceled. ## Remote Working A core element of any business continuity plan is the capability of remote working. Atlantic.Net is uniquely placed to help with remote working requirements.  As a tech company, we already have the ability to provide our workers with the technology to work remotely. We also have the infrastructure in place within our [cloud platform](https://cloud.atlantic.net/?page=userlogin) to help any business with their contingency planning. Atlantic.Net can provide consultancy services if needed, so please get in touch if you are looking for help. ### How Remote Work Can Mitigate COVID-19’s Operational Impact It is estimated that a large number of employees will potentially be off sick over the coming days, weeks, and even months. This could result in individuals, departments or entire offices being unable to travel to, or occupy, their place of work. Businesses cannot simply stop operating, core business operations must continue to function, for many, remote working is the key to providing a business-as-usual service. In such situations, it becomes crucial to efficiently manage remote payroll tasks, including the ability to [create paystubs](https://www.formpros.com/tax-forms/create-paystub/), ensuring financial processes remain smooth despite disruptions. Fortunately, we are working in the digital age, and the majority of office workers have a desktop or laptop computer. It is important to know which of your employees can take their laptop home and work remotely.  Not everyone may have a laptop, so can the business provide spare laptops to employees? Can your business allow employees to use personal laptops in an emergency? ### VPN for Security Homeworking will likely require a VPN connection to connect to the corporate network and access internal business services.  Does your business have a VPN? Do you have enough spare licenses and bandwidth to cope with the surge in demand? Is your phone system available over a VPN connection? Do procedures exist to train non-technical personnel on how to install and configure a VPN? The use of VPN software is increasingly popular and might be perfectly suited for an on-demand VPN requirement.  There are several open-source VPN software solutions available for [Virtual private servers](https://www.atlantic.net/vps-hosting/). But since cybersecurity is a major concern these days, most businesses are opting to get a little help from service providers like Atlantic.Net to ensure security, privacy, and compliance. Once the Remote Access VPN is established,  all your employees need is a computer, an internet connection, and the VPN client (or guest credentials to the Atlantic.Net VPS). Users can then remotely connect into the VPN tunnel and access business applications as if they were sitting at their desks. ### Using RDP for Access Windows Desktop Edition virtual servers can be deployed for every employee in our cloud to help provide a remote desktop service within seconds.  Users install a local agent to connect to an existing business platform. These products can also be stood up on an Atlantic.Net VPS, and although licensing costs may be higher than a VPN, the user experience is often improved for non-technical employees. ## Business Continuity Other core business continuity elements can be completed now in the event of a pandemic. Most importantly, test and secure remote access for any work-from-home situation. Ensure that the technology works, ensure everyone knows their user credentials, and ensure VPN accounts are not locked. ### Identify Permissions/Access Needs Consider any employee that might need access to data or onsite file shares. File shares can be rapidly migrated to the cloud, with access granted on predefined permissions.  It is vital to ensure data integrity, data protection, and data security are upheld during the entire process. Atlantic.Net engineers can advise on the best practices to follow to protect your data. Identify the key personnel that are needed to keep the lights on and the business functioning. Appoint at least one Business Continuity specialist,  or select team members responsible for coordinating pandemic readiness activities. Keep your employees updated on the latest news regarding COVID-19, including calm, practical advice cascaded from senior management. You may want to consider a “buddy system” where a primary employee has a backup buddy who will take on their workload in the event of prolonged sickness. ### Have a Communication Plan in Place Communication is the key to a successful BCP, and creating and testing an employee communication plan is a necessity. Ensure that all business mobile phone lists are current; in some circumstances, it might be useful to have critical employees personal contact numbers. Use technology such as Slack or secure messaging tools that encourage employees to interact. Coordinate with key vendors and third parties what your business continuity plans are, these might be suppliers, technical contractors or providers. Use any spare time to conduct staff training on remote working and BCP arrangements, this will help employees understand their roles and responsibilities during a business disruption. ## Conclusion These are uncharted waters we are entering with the Coronavirus. The difficulty is not knowing how the virus will mutate, and no one knows what impact will occur.  Because of these unknowns, Atlantic.Net is standing by, our business continuity planning is fully operational and we are prepared for any eventuality. [Contact us today](https://www.atlantic.net/about-us/corporate-contact/) about getting help with business continuity planning. If you’re interested in acquiring a VPS to support remote work or other efforts, Atlantic.Net is currently offering a [VPS hosting](https://www.atlantic.net/vps-hosting/) solution that includes a G2.1GB Cloud Plan, 50 GB of Block Storage, and 50 GB of Snapshots, all free-to-use for one year. [Sign up today!](https://cloud.atlantic.net/?page=signup) --- # How to Set Up Tomcat with Nginx as a Reverse Proxy on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-setup-tomcat-with-nginx-as-a-reverse-proxy-on-ubuntu/ | Published: 2020-03-09 | Updated: 2025-09-19 | Author: Hitesh Jethva Apache Tomcat is an open-source implementation of the Java Servlet and JSP technologies that can be used to deploy Java-based applications. It was created under the Apache-Jakarta subproject, but due to its popularity, it is now hosted as a separate Apache project. Tomcat also provides additional functionality that makes it easier to develop a complete web application solution. Tomcat is simple, easy-to-use, and one of the most widely used web servers in the world. If you are looking to run Java-based applications that operate seamlessly and fast, then Apache Tomcat is the best choice for you. In this tutorial, we will learn how to install and configure Apache Tomcat with Nginx as a reverse proxy on Ubuntu 24.04 VPS. ## Prerequisites - A fresh Ubuntu 24.04 [VPS](https://www.atlantic.net/vps-hosting/) on the Atlantic.Net Cloud Platform. - A valid domain name pointed at your VPS IP address. In this tutorial, we will use example.com. **Note**: You can refer to the Atlantic DNS Guide to manage the [DNS records](https://www.atlantic.net/dedicated-server-hosting/cloud-hosting-getting-started-with-dns-records/). ## Step 1 – Create Atlantic.Net Cloud Server First, log in to your [Atlantic.Net Cloud Server](https://cloud.atlantic.net/?page=userlogin).  Create a new [server](https://www.atlantic.net/vps-hosting/how-to-create-new-atlantic-net-cloud-server/), choosing Ubuntu 24.04 as the operating system with at least 2GB RAM. Connect to your Cloud Server via SSH and log in using the credentials highlighted at the top of the page. Once you are logged in to your Ubuntu 24.04 server, run the following command to update your base system with the latest available packages. ``` apt-get update -y ``` ## Step 2 – Install Java Apache Tomcat is a Java-based application, so Java must be installed on your system. You can install the latest version of Java with the following command: ``` apt-get install default-jdk -y ``` After installing Java, verify the Java version with the following command: ``` java --version ``` You should get the following output: ``` openjdk 21.0.7 2025-04-15 OpenJDK Runtime Environment (build 21.0.7+6-Ubuntu-0ubuntu124.04) OpenJDK 64-Bit Server VM (build 21.0.7+6-Ubuntu-0ubuntu124.04, mixed mode, sharing) ``` ## Step 4 – Create Tomcat User Next, you will need to create a Tomcat user and group to run the Tomcat service. First, create a group with the name tomcat using the following command: ``` groupadd tomcat ``` Next, create a new tomcat user and make this user member of the tomcat group with a /home/tomcat home directory. ``` useradd -s /bin/false -g tomcat -d /home/tomcat tomcat ``` At this point, the Tomcat user is created. ## Step 5 – Download Tomcat First, visit the [Apache Tomcat download](https://tomcat.apache.org/download-90.cgi) page. You should see the following screen:   ![](https://www.atlantic.net/wp-content/uploads/2020/03/t2.png) Next, download the latest version of Apache Tomcat with the following command: ``` wget https://dlcdn.apache.org/tomcat/tomcat-9/v9.0.105/bin/apache-tomcat-9.0.105.tar.gz ``` After downloading Apache Tomcat, extract the downloaded file with the following command: ``` tar -xvzf apache-tomcat-9.0.105.tar.gz ``` Next, move the extracted directory to /home/tomcat as shown below: ``` mv apache-tomcat-9.0.105 /home/tomcat ``` Next, change the ownership of the /home/tomcat directory to tomcat and give proper permissions with the following command: ``` chown -R tomcat:tomcat /home/tomcat chmod -R 755 /home/tomcat/ ``` ## Step 6 – Create a System Unit File for Tomcat Next, you will need to create a systemd service file to run Tomcat as a service. You can create it with the following command: ``` nano /etc/systemd/system/tomcat.service ``` Add the following lines: ``` [Unit] Description=Tomcat servlet container After=network.target [Service] Type=forking User=tomcat Group=tomcat Environment="JAVA_HOME=/usr/lib/jvm/default-java" Environment="JAVA_OPTS=-Djava.security.egd=file:///dev/urandom" Environment="CATALINA_BASE=/home/tomcat" Environment="CATALINA_HOME=/home/tomcat" Environment="CATALINA_PID=/home/tomcat/temp/tomcat.pid" Environment="CATALINA_OPTS=-Xms512M -Xmx1024M -server -XX:+UseParallelGC" ExecStart=/home/tomcat/bin/startup.sh ExecStop=/home/tomcat/bin/shutdown.sh [Install] WantedBy=multi-user.target ``` Save and close the file. Then, reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the Tomcat service and enable it to start after system reboot: ``` systemctl start tomcat systemctl enable tomcat ``` You can also check the status of the Tomcat service with the following command: ``` systemctl status tomcat ``` You should see the following output: ``` ● tomcat.service - Tomcat servlet container Loaded: loaded (/etc/systemd/system/tomcat.service; disabled; preset: enabled) Active: active (running) since Sat 2025-05-24 07:22:11 AST; 5s ago Process: 512822 ExecStart=/home/tomcat/bin/startup.sh (code=exited, status=0/SUCCESS) Main PID: 512829 (java) Tasks: 30 (limit: 4609) Memory: 122.5M (peak: 122.9M) CPU: 5.714s CGroup: /system.slice/tomcat.service └─512829 /usr/lib/jvm/default-java/bin/java -Djava.util.logging.config.file=/home/tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.ju> May 24 07:22:11 ubuntu systemd[1]: Starting tomcat.service - Tomcat servlet container... May 24 07:22:11 ubuntu startup.sh[512822]: Tomcat started. May 24 07:22:11 ubuntu systemd[1]: Started tomcat.service - Tomcat servlet container. ``` ## Step 7 – Access Tomcat Web Interface Tomcat is now installed and running on port 8080. You can verify the Tomcat port with the following command: ``` ss -ant ``` You should see the following output: ``` Active Internet connections (servers and established) Proto Recv-Q Send-Q Local Address           Foreign Address         State     tcp        0      0 127.0.0.53:53           0.0.0.0:*               LISTEN    tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN    tcp6       0      0 :::8009                 :::*                    LISTEN    tcp6       0      0 :::8080                 :::*                    LISTEN    tcp6       0      0 :::22                   :::*                    LISTEN    tcp6       0      0 127.0.0.1:8005          :::*                    LISTEN ``` Now, open your web browser and visit the URL **http://your-server-ip:8080**. You should see the Tomcat default web page:   ![](https://www.atlantic.net/wp-content/uploads/2020/03/t1.png) ## Step 8 – Configure Tomcat Web Management Interface Next, you will need to add a login to access the manager web application. You can add a user to access manager-gui and admin-gui by editing the file tomcat-users.xml: ``` nano /home/tomcat/conf/tomcat-users.xml ``` Add the following lines above the line : ``` ``` Save and close the file when you are finished. By default, Tomcat is configured to restrict access to the Manager and Host Manager apps only from the localhost, so you will need to remove this restriction. To remove the restriction for Manager app, edit the context.xml file as shown below: ``` nano /home/tomcat/webapps/manager/META-INF/context.xml ``` Comment out the Valve section as shown below: ```   URL: https://www.atlantic.net/vps-hosting/how-to-install-ruby-on-ubuntu-18-04/ | Published: 2020-03-13 | Updated: 2023-11-25 | Author: Hitesh Jethva Ruby is a free, open-source, dynamic programming language known for its simplicity and productivity. It is a general-purpose language commonly used for standard libraries, servers, web applications, and other system utilities. It is portable and works on most operating systems, including Linux, Windows, macOS, UNIX, DOS, BeOS, and many more. It has exception handling features that make it easy to handle errors. In this tutorial, we will show you several ways to install Ruby on Ubuntu 18.04. ``` ``` ## Option 1 – Install Ruby from Ubuntu Repository The simplest way to install Ruby in your system is using the Ubuntu repository. At the time of writing this article, the latest stable version of Ruby available in the Ubuntu repository is 2.5.1. You can run the following command to install Ruby in your system: ``` apt-get install ruby-full -y ``` Once the installation is completed, you can check the installed version of Ruby with the following command: ``` ruby --version ``` You should get the following output: ``` ruby 2.5.1p57 (2018-03-29 revision 63029) [x86_64-linux-gnu] ``` ## Option 2 – Install Ruby with RVM RVM, which stands for “Ruby Version Manager,” is a command-line tool that can be used to install and manage multiple versions of Ruby. First, you will need to install all the dependencies required to build Ruby from the source. You can install them with the following command: ``` apt-get install gcc autoconf curl g++  gnupg automake bison libc6-dev libffi-dev libgdbm-dev libncurses5-dev libsqlite3-dev pkg-config sqlite3 zlib1g-dev libtool libyaml-dev make libgmp-dev libreadline-dev libssl-dev ``` Once all the packages are installed, install the keys with the following command: ``` gpg --keyserver hkp://keys.gnupg.net --recv-keys 409B6B1796C275462A1703113804BB82D39DC0E3 7D2BAF1CF37B13E2069D6956105BD0E739499BDB ``` Next, run the following command to download the RVM installation script from the project’s website: ``` curl -sSL https://get.rvm.io | bash -s stable ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/03/RVM-Installation.png) Once the installation is completed, start using RVM with the following command: ``` source /etc/profile.d/rvm.sh ``` Next, install Ruby version 2.6.5 using the following command: ``` rvm install 2.6.5 ``` Once the installation is completed, you should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Ruby-Installation.png) Next, set the installed version as the default version with the following command: ``` rvm use 2.6.5 --default ``` You can now verify the Ruby version using the following command: ``` ruby -v ``` You should get the following output: ``` ruby 2.6.5p114 (2019-10-01 revision 67812) [x86_64-linux] ``` ## Option 3 – Install Ruby with Rbenv Rbenv is a Ruby version management tool that allows you to install multiple versions of Ruby in your system. It is very similar to RVM, with a focus on managing multiple Ruby versions. Before starting, you will need to install all the required packages to build Ruby from the source. You can install all of them using the following command: ``` apt-get install autoconf bison build-essential git curl libssl-dev libreadline-dev zlib1g-dev libyaml-dev libreadline-dev libncurses5-dev libffi-dev libgdbm-dev -y ``` Once all the packages are installed, run the following command to download rbenv and ruby-build repositories from GitHub. ``` curl -sL https://github.com/rbenv/rbenv-installer/raw/master/bin/rbenv-installer | bash - ``` Next, you will need to add the .rbenv/bin to the user PATH. You can do this by editing ~/.bashrc file: ``` nano ~/.bashrc ``` Add the following lines at the end of the file: ``` export PATH="$HOME/.rbenv/bin:$PATH" eval "$(rbenv init -)" ``` Save and close the file when you are finished. Then, activate the environment with the following command: ``` source ~/.bashrc ``` Before installing Ruby, you can list all available Ruby versions with the following command: ``` rbenv install -l ``` Next, run the following command to install the Ruby 2.6.5 in your system. ``` rbenv install 2.6.5 ``` **Note**: The installation will take several minutes to complete. Once the installation is completed, you should get the following output: ``` Downloading ruby-2.6.5.tar.bz2... -> https://cache.ruby-lang.org/pub/ruby/2.6/ruby-2.6.5.tar.bz2 Installing ruby-2.6.5... Installed ruby-2.6.5 to /root/.rbenv/versions/2.6.5 ``` Next, make this Ruby version global with the following command: ``` rbenv global 2.6.5 ``` Next, verify the installed version of Ruby with the following command: ``` ruby -v ``` You should get the following output: ``` ruby 2.6.5p114 (2019-10-01 revision 67812) [x86_64-linux] ``` ## Conclusion In the above tutorial, you learned how to install Ruby using different methods. You can now install Ruby using your desired method. Get started with Ruby today with a [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net! --- # How to Set Up a Seafile Server with Nginx on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-set-up-seafile-server-with-nginx-on-ubuntu-18-04/ | Published: 2020-03-14 | Updated: 2023-11-27 | Author: Hitesh Jethva Seafile is a free and open-source cloud-based file sharing platform that can be used for storing files and synchronizing the data across multiple devices. Seafile is a self-hosted and high-performance storage system that allows you to host on your own private servers. Seafile is free to use and very similar to other storage providers including OwnCloud, NextCloud, Google Drive and DropBox. With Seafile, you can access and sync your files, contacts and data across PC and mobile devices. Seafile comes with a rich set of features including support for client encryption, support for version control, LDAP authentication, two-factor authentication, antivirus  integration, Office web app integration, public link sharing, reliable file synicing, Drive Client support, and many more. In this tutorial, we will explain how to install and configure a Seafile server with Nginx as a reverse proxy on Ubuntu 18.04. ## Step 1 – Install Required Dependencies First, you will need to install all the dependencies needed for Seafile server installation. You can install all of them by running the following command: ``` apt-get update -y apt-get install python2.7 libpython2.7 python-setuptools python-pil python-ldap python-urllib3 ffmpeg python-pip python-mysqldb python-memcache python-requests unzip wget -y ``` Once all the dependencies are installed, you can proceed to the next step. ## Step 2 – Install Nginx and MariaDB Next, you will need to install the Nginx web server and MariaDB database server in your server. You can install them by running the following command: ``` apt-get install nginx mariadb-server mariadb-client -y ``` Once the installation is completed, start the Nginx and MariaDB service and enable it to start after system reboot: ``` systemctl start nginx systemctl start mariadb systemctl enable nginx systemctl enable mariadb ``` Once you are finished, you can proceed to the next step. ## Step 3 – Create a Database for Seafile Seafile consists of three main components: Seahub, Seafile server and Ccnet server. Each component requires a separate database to store its data. You will need to create a separate database for each of these components. To do so, login to the MariaDB shell with the following command: ``` mysql -u root -p ``` Provide your root password when prompt then create the required databases with the following commands: ``` CREATE DATABASE seafiledb character set = 'utf8'; CREATE DATABASE ccnetdb character set = 'utf8'; CREATE DATABASE seahubdb character set = 'utf8'; ``` Next, create the database user with the following command: ``` CREATE USER 'seafileuser'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the Seafile database user with the following command: ``` GRANT ALL ON seafiledb.* TO 'seafileuser'@'localhost' IDENTIFIED BY 'password' WITH GRANT OPTION; GRANT ALL ON ccnetdb.* TO 'seafileuser'@'localhost' IDENTIFIED BY 'password' WITH GRANT OPTION; GRANT ALL ON seahubdb.* TO 'seafileuser'@'localhost' IDENTIFIED BY 'password' WITH GRANT OPTION; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` At this point, you have created all the databases required to store the Seafile data. ## Step 4 – Install Seafile Server Next, download the latest version of Seafile from their official website with the wget command: ``` wget https://download.seadrive.org/seafile-server_7.0.5_x86-64.tar.gz ``` Once downloaded, extract the downloaded file with the following command: ``` tar -xvzf seafile-server_7.0.5_x86-64.tar.gz ``` Next, copy the extracted directory to the Nginx web root directory: ``` cp -r seafile-server-7.0.5 /var/www/html/seafile ``` Next, start the Seafile installation script with the following command: ``` cd /var/www/html/seafile ./setup-seafile-mysql.sh ``` During the installation, you will be prompted to answer several questions as shown below: ``` Checking python on this machine ... Checking python module: python-mysqldb ... Done. ----------------------------------------------------------------- This script will guide you to setup your seafile server using MySQL. Make sure you have read seafile server manual at        https://github.com/haiwen/seafile/wiki Press ENTER to continue ----------------------------------------------------------------- What is the name of the server? It will be displayed on the client. 3 - 15 letters or digits [ server name ] seafile What is the ip or domain of the server? For example: www.mycompany.com, 192.168.1.101 [ This server's ip or domain ] seafile.example.com Where do you want to put your seafile data? Please use a volume with enough free space [ default "/var/www/html/seafile-data" ] Which port do you want to use for the seafile fileserver? [ default "8082" ] ------------------------------------------------------- Please choose a way to initialize seafile databases: ------------------------------------------------------- [1] Create new ccnet/seafile/seahub databases [2] Use existing ccnet/seafile/seahub databases [ 1 or 2 ] 2 What is the host of mysql server? [ default "localhost" ] What is the port of mysql server? [ default "3306" ] Which mysql user to use for seafile? [ mysql user for seafile ] seafileuser What is the password for mysql user "seafileuser"? [ password for seafileuser ] verifying password of user seafileuser ...  done Enter the existing database name for ccnet: [ ccnet database ] ccnetdb verifying user "seafileuser" access to database ccnetdb ...  done Enter the existing database name for seafile: [ seafile database ] seafiledb verifying user "seafileuser" access to database seafiledb ...  done Enter the existing database name for seahub: [ seahub database ] seahubdb verifying user "seafileuser" access to database seahubdb ...  done --------------------------------- This is your configuration ---------------------------------     server name:            seafile    server ip/domain:       seafile.example.com     seafile data dir:       /var/www/html/seafile-data    fileserver port:        8082     database:               use existing    ccnet database:         ccnetdb    seafile database:       seafiledb    seahub database:        seahubdb    database user:          seafileuser --------------------------------- Press ENTER to continue, or Ctrl-C to abort --------------------------------- ``` Once the installation has been completed successfully, you should get the following output: ``` ----------------------------------------------------------------- Your seafile server configuration has been finished successfully. ----------------------------------------------------------------- run seafile server:     ./seafile.sh { start | stop | restart } run seahub  server:     ./seahub.sh  { start | stop | restart } ----------------------------------------------------------------- If you are behind a firewall, remember to allow input/output of these tcp ports: ----------------------------------------------------------------- port of seafile fileserver:   8082 port of seahub:               8000 When problems occur, Refer to         https://github.com/haiwen/seafile/wiki for information. ``` Next, give permissions to Seafile with the following command: ``` chown -R www-data:www-data /var/www/html/ ``` Next, you will need to add a FILE_SERVER_ROOT setting in the file seahub_settings.py: ``` nano /var/www/html/conf/seahub_settings.py ``` Add the FILE_SERVER_ROOT settings as shown below: ``` SECRET_KEY = "x)0=j*l6b+4amq2n^&)c=q5p==exn13%s&6x!*48u4p0p97k)4" FILE_SERVER_ROOT = 'http://seafile.example.com/seafhttp' DATABASES = {    'default': {        'ENGINE': 'django.db.backends.mysql', :        'NAME': 'seahubdb',        'USER': 'seafileuser',        'PASSWORD': 'password',        'HOST': '127.0.0.1',        'PORT': '3306'    } } ``` Save and close the file when you are finished. ## Step 5 – Create Admin User for Seafile Next, you will need to create an admin user and set a password for Seafile. To do so, change the directory to seafile and start the seafile service with the following command: ``` cd /var/www/html/seafile su -p -l www-data -s /bin/bash -c "./seafile.sh start" ``` Next, start the seahub service and create an admin account with the following command: ``` su -p -l www-data -s /bin/bash -c "./seahub.sh start" ``` You will be asked to provide your email address and admin password as shown below: ``` LC_ALL is not set in ENV, set to en_US.UTF-8 Starting seahub at port 8000 ... ---------------------------------------- It's the first time you start the seafile server. Now let's create the admin account ---------------------------------------- What is the email for the admin account? [ admin email ] admin@example.com What is the password for the admin account? [ admin password ] Enter the password again: [ admin password again ] ---------------------------------------- Successfully created seafile admin ---------------------------------------- Seahub is started Done. ``` Once you are done, stop the seafile and seahub services: ``` su -p -l www-data -s /bin/bash -c "./seafile.sh stop" su -p -l www-data -s /bin/bash -c "./seahub.sh stop" ``` ## Step 6 – Create a Systemd File for Seafile and Seahub Next, you will need to create a systemd unit file for Seafile and Seahub to manage the service. First, create a seafile service file with the following command: ``` nano /etc/systemd/system/seafile.service ``` Add the following lines: ``` [Unit] Description=Seafile After= mysql.service After=network.target [Service] User=www-data Group=www-data Type=forking ExecStart=/var/www/html/seafile-server-latest/seafile.sh start ExecStop=/var/www/html/seafile-server-latest/seafile.sh stop [Install] WantedBy=multi-user.target ``` Save and close the file. Then, create a systemd service file for Seahub with the following command: ``` nano /etc/systemd/system/seahub.service ``` Add the following lines: ``` [Unit] Description=Seafile After= mysql.service After=network.target [Service] User=www-data Group=www-data Type=forking ExecStart=/var/www/html/seafile-server-latest/seahub.sh start ExecStop=/var/www/html/seafile-server-latest/seahub.sh stop [Install] WantedBy=multi-user.target ``` Save and close the file. Then, reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, restart Seafile and Seahub service and enable them to start after system reboot with the following command: ``` systemctl start seafile systemctl enable seafile systemctl start seahub systemctl enable seahub ``` To verify the Seafile service, run the following command: ``` systemctl status seafile ``` Output: ``` ● seafile.service - Seafile   Loaded: loaded (/etc/systemd/system/seafile.service; disabled; vendor preset: enabled)   Active: active (running) since Thu 2019-11-28 08:48:31 UTC; 8s ago Process: 15487 ExecStart=/var/www/html/seafile-server-latest/seafile.sh start (code=exited, status=0/SUCCESS)    Tasks: 16 (limit: 1150)   CGroup: /system.slice/seafile.service           ├─15522 /var/www/html/seafile/seafile/bin/seafile-controller -c /var/www/html/ccnet -d /var/www/html/seafile-data -F /var/www/html/c           ├─15524 ccnet-server -F /var/www/html/conf -c /var/www/html/ccnet -f /var/www/html/logs/ccnet.log -d -P /var/www/html/pids/ccnet.pid           └─15527 seaf-server -F /var/www/html/conf -c /var/www/html/ccnet -d /var/www/html/seafile-data -l /var/www/html/logs/seafile.log -P Nov 28 08:48:28 ubuntu1804 systemd[1]: Starting Seafile... ``` To verify the Seahub service run the following command: systemctl status seahub Output: ``` ● seahub.service - Seafile   Loaded: loaded (/etc/systemd/system/seahub.service; disabled; vendor preset: enabled)   Active: active (running) since Thu 2019-11-28 08:50:49 UTC; 18s ago Process: 15547 ExecStart=/var/www/html/seafile-server-latest/seahub.sh start (code=exited, status=0/SUCCESS) Main PID: 15573 (python2.7)    Tasks: 6 (limit: 1150)   CGroup: /system.slice/seahub.service           ├─15573 python2.7 /var/www/html/seafile/seahub/thirdpart/gunicorn seahub.wsgi:application -c /var/www/html/conf/gunicorn.conf --prel           ├─15579 python2.7 /var/www/html/seafile/seahub/thirdpart/gunicorn seahub.wsgi:application -c /var/www/html/conf/gunicorn.conf --prel           ├─15580 python2.7 /var/www/html/seafile/seahub/thirdpart/gunicorn seahub.wsgi:application -c /var/www/html/conf/gunicorn.conf --prel           ├─15581 python2.7 /var/www/html/seafile/seahub/thirdpart/gunicorn seahub.wsgi:application -c /var/www/html/conf/gunicorn.conf --prel           ├─15582 python2.7 /var/www/html/seafile/seahub/thirdpart/gunicorn seahub.wsgi:application -c /var/www/html/conf/gunicorn.conf --prel           └─15583 python2.7 /var/www/html/seafile/seahub/thirdpart/gunicorn seahub.wsgi:application -c /var/www/html/conf/gunicorn.conf --prel Nov 28 08:50:43 ubuntu1804 systemd[1]: Starting Seafile... ``` ## Step 7 – Configure Reverse Proxy with Nginx Next, you will need to install and configure Nginx as a reverse proxy for Seafile to forward the client requests from ports 8000 and 8082 to the Nginx port 80. To do so, create an Nginx virtual host configuration file with the following command: ``` nano /etc/nginx/sites-available/seafile ``` Add the following lines: ``` server {    listen 80;    listen [::]:80;    root /var/www/html/seafile;    server_name  seafile.example.com;      client_max_body_size 100M;      autoindex off;     access_log /var/log/nginx/example.com.access.log;     error_log /var/log/nginx/example.com.error.log;      location / {            proxy_pass         http://127.0.0.1:8000;            proxy_set_header   Host $host;            proxy_set_header   X-Real-IP $remote_addr;            proxy_set_header   X-Forwarded-For $proxy_add_x_forwarded_for;            proxy_set_header   X-Forwarded-Host $server_name;            proxy_read_timeout  1200s;        }      location /seafhttp {            rewrite ^/seafhttp(.*)$ $1 break;            proxy_pass http://127.0.0.1:8082;            proxy_set_header   X-Forwarded-For $proxy_add_x_forwarded_for;            proxy_connect_timeout  36000s;            proxy_read_timeout  36000s;            proxy_send_timeout  36000s;            send_timeout  36000s;        }    location /media {            root /var/www/html/seafile-server-latest/seahub;        } } ``` Save and close the file when you are finished. Then, enable the Nginx virtual host with the following command: ``` ln -s /etc/nginx/sites-available/seafile /etc/nginx/sites-enabled/ ``` Finally, restart the Nginx service with the following command: ``` systemctl restart nginx ``` ## Step 9 – Access Seafile Web Interface Now, open your web browser and navigate the URL http://seafile.example.com. You should see the Seafile login page: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Seafile-Web-Interface.png) Provide your admin username, password and click on the **Log in** button. You should see the Seafile default dashboard: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Seafile-Default-Dashboard.png) ## Conclusion In the above tutorial, we learned how to install the Seafile server with Nginx as a reverse proxy on Ubuntu 18.04 VPS. I hope you have now enough knowledge to host your own file sharing server using Seafile. Get started with Seafile today on a [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Symfony Framework on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-symfony-framework-on-centos-8/ | Published: 2020-03-15 | Updated: 2026-03-03 | Author: Hitesh Jethva Symfony is a free, open-source, popular PHP framework with MVC architecture used to build web services, APIs, microservices, and high-performance, complex web applications. Symfony is compatible with other database systems and gives you full control over configuration. It comes with a set of reusable components and a user-friendly web interface, and its flexibility and high performance make it a top choice for developing an enterprise application. In this tutorial, we will learn how to install the Symfony framework on CentOS 8 server. ## Step 1 – Install LAMP Server First, you will need to install the Apache, MariaDB, PHP and other required PHP extensions in your server. You can install all of them with the following command: ``` dnf install httpd mariadb-server php php-cli php-common php-spl php-hash php-ctype php-json php-mbstring php-zip php-gd php-curl php-mysqli php-xml php-gmp php-intl php-xmlrpc php-bcmath php-soap php-ldap unzip -y ``` Once all the packages are installed, start the Apache and MariaDB service and enable them to start after system reboot with the following command: ``` systemctl start httpd systemctl enable httpd systemctl start mariadb systemctl enable mariadb ``` Once you are done, you can proceed to the next step. ## Step 2 – Secure MariaDB Database By default, MariaDB is not secured, but you can secure the MariaDB and set a MariaDB root password using the following command: ``` mysql_secure_installation ``` Answer all the questions as shown below: ``` Enter current password for root (enter for none): Just Press Enter Set root password? [Y/n] Y Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` Once you are finished, you can proceed to the next step. ## Step 3 – Install Symfony Before installing Symfony, you will need to install Composer in your system. Composer is a dependency manager for PHP that can be used to install PHP dependencies while building the project. You can install Composer with the following command: ``` wget https://getcomposer.org/installer -O composer-installer.php php composer-installer.php --filename=composer --install-dir=/usr/local/bin ``` Once installed, you should get the following output: All settings correct for using Composer ``` Downloading... Composer (version 1.9.3) successfully installed to: /usr/local/bin/composer Use it: php /usr/local/bin/composer ``` Next, change the directory to the /var/www/html and create a new Symfony project with the following command: ``` cd /var/www/html composer create-project symfony/website-skeleton symfony5 ``` Next, give proper permissions to the symfony5 directory using the following command: ``` chown -R apache:apache /var/www/html/symfony5 chmod -R 755 /var/www/html/symfony5 ``` ## Step 4 – Start Symfony in Development Mode You can now start Symfony in development mode using the following command: ``` cd /var/www/html/symfony5 php -S 0.0.0.0:8000 -t public ``` You should see the following output: ``` PHP 7.2.11 Development Server started at Thu Feb  6 08:56:29 2020 Listening on http://0.0.0.0:8000 Document root is /var/www/html/symfony5/public Press Ctrl-C to quit. ``` Symfony web server is now started and listening on port 8000. You can access it using the URL http://your-server-ip:8000. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Symfony-Welcome.png) You can stop the Symfony web server by pressing **CTRL+C** on your terminal interface. ## Step 5 – Configure Apache for Symfony Next, you will need to create a new Apache virtual host configuration file for Symfony. You can create it with the following command: ``` nano /etc/httpd/conf.d/symfony.conf ``` Add the following lines: ```   ServerAdmin admin@example.com   DocumentRoot "/var/www/html/symfony5/public"   ServerName symfony.example.com            AllowOverride All        Order Allow,Deny        Allow from All       ErrorLog "/var/log/httpd/example.com-error_log"   CustomLog "/var/log/httpd/example.com-access_log" combined ``` Save and close the file when you are finished. Then, restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 6 – Configure Firewall If the firewalld service is enabled in your system, you will need to allow HTTP/HTTPS port through firewalld. First, check the firewalld service using the following command: ``` systemctl status firewalld ``` You should see that firewalld service is not running: ``` ● firewalld.service - firewalld - dynamic firewall daemon   Loaded: loaded (/usr/lib/systemd/system/firewalld.service; disabled; vendor preset: enabled)   Active: inactive (dead)     Docs: man:firewalld(1) ``` You can start the firewalld service and enable it to start after system reboot with the following command: ``` systemctl start firewalld systemctl enable firewalld ``` Next, allow HTTP and HTTPS port through firewalld with the following command: ``` firewall-cmd --permanent --add-service=http firewall-cmd --permanent --add-service=https ``` Next, reload the firewalld to apply the changes: ``` firewall-cmd --reload ``` ## Step 7 – Access Symfony Now, open your web browser and type the URL http://symfony.example.com. You will be redirected to the Symfony default dashboard as shown in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Symfony-Access.png) ## Conclusion Congratulations! you have successfully installed Symfony 5 on CentOS 8 server. You can now start building brilliant applications with Symfony. Get started on Symfony today on a [VPS Hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net! --- # How to Set Up a Fully Featured Mail Server with Postfix, Dovecot and Roundcube on Ubuntu 24.04 > URL: https://www.atlantic.net/vps-hosting/how-to-set-up-fully-featured-mail-server-with-postfix-dovecot-and-roundcube-on-ubuntu/ | Published: 2020-03-16 | Updated: 2025-05-30 | Author: Hitesh Jethva Setting up your own mail server on Linux VPS is an important task for any Linux system administrator. Postfix is one of the most widely used and easiest mail server solutions available. It is a free, open-source, and powerful Mail Transfer Agent (MTA) that can be used to send and receive email.  By default, Postfix is the default MTA software on all Linux distributions. Dovecot is an open-source IMAP and POP3 email server that can act as a mail storage server. It is used to deliver and retrieve emails to and from local mailboxes. Roundcube is a web-based IMAP email client that can read emails stored by Dovecot on virtual mailboxes. It provides all features you expect from an email client including MIME support, multiple sender identities, spell checking, folder manipulation, and many more. In this tutorial, we will show you how to set up a full-featured Mail server with Postfix, Dovecot and Roundcube on Ubuntu 20.04 VPS. ## Prerequisites - A fresh Ubuntu 24.04 VPS. - A valid domain name pointed to your VPS IP address. In this tutorial, we will use email.example.com. - A & MX records for your server. **Note**: You can refer to the Atlantic DNS Guide to manage the [DNS records](https://www.atlantic.net/dedicated-server-hosting/cloud-hosting-getting-started-with-dns-records/). ## Step 1 – Set Up the Hostname Next, you will need to set the hostname of your server. In this case, we will set the hostname to mail.example.com, as shown below: ``` hostnamectl set-hostname email.example.com ``` Next, open /etc/hosts file and bind your server IP address with the hostname: ``` nano /etc/hosts ``` Add the following line: ``` your-server-ip   email.example.com email ``` Save and close the file. Then, run the following command to apply the configuration changes: ``` hostname -f ``` ## Step 2 – Install Apache, MariaDB and PHP Roundcube requires Apache, MariaDB and PHP to be installed on your server. You can install them with the following command: ``` apt-get install apache2 mariadb-server php libapache2-mod-php php-mysql -y ``` After installing all the required packages, you will need to enable the Apache rewrite module for Roundcube to work. You can enable it with the following command: ``` a2enmod rewrite ``` Next, reload the Apache service to apply the changes: ``` systemctl restart apache2 ``` ## Step 3 – Install Let’s Encrypt SSL Certificate Next, you will need to install the Let’s Encrypt Free SSL certificate on your server to configure your mail server with TLS. First, install the Certbot client in your server with the following command: ``` add-apt-repository ppa:certbot/certbot apt-get update -y apt-get install python-certbot-apache -y ``` Next, download the Let’s Encrypt Free SSL certificate for your domain email.example.com with the following command: ``` certbot certonly --apache -d email.example.com ``` This command will download the certificate in the /etc/letsencrypt/live/email.example.com/ directory. ## Step 4 – Install and Configure Postfix Next, let’s start to install a Postfix mail server with the following command: ``` apt-get install postfix ``` You will be redirected to the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Postfix-Install.png) Select **Internet Site** and press **TAB** and **Enter** to continue. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Postfix-Internet-Site.png) Provide your domain name and hit **Tab** and **Enter** to finish the installation. The default Postfix configuration file is located at /etc/postfix/main.cf. Before configuring Postfix, it is recommended to back up this file: ``` mv /etc/postfix/main.cf /etc/postfix/main.cf.bak ``` Next, create a new Postfix configuration file as shown below: ``` nano /etc/postfix/main.cf ``` Add the following lines: ``` # GENERAL SETTINGS smtpd_banner = $myhostname ESMTP $mail_name biff = no append_dot_mydomain = no readme_directory = no # SMTP SETTINGS smtp_use_tls=yes smtp_tls_security_level = may smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache # SMTPD SETTINGS smtpd_use_tls=yes smtpd_tls_security_level = may smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache smtpd_tls_cert_file=/etc/letsencrypt/live/email.example.com/fullchain.pem smtpd_tls_key_file=/etc/letsencrypt/live/email.example.com/privkey.pem smtpd_relay_restrictions = permit_mynetworks, permit_sasl_authenticated,  reject_unauth_destination # SASL SETTINGS smtpd_sasl_auth_enable = yes smtpd_sasl_type = dovecot smtpd_sasl_path = private/auth # VIRTUAL MAIL BOX AND LMTP SETTINGS virtual_transport = lmtp:unix:private/dovecot-lmtp virtual_mailbox_domains = /etc/postfix/virtual_mailbox_domains # OTHER SETTINGS myhostname = email.example.com myorigin = /etc/mailname mydestination =  localhost.$mydomain, localhost relayhost = mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128 mailbox_size_limit = 0 recipient_delimiter = + inet_interfaces = all inet_protocols = all alias_maps = hash:/etc/aliases alias_database = hash:/etc/aliases ``` Save and close the file. Next, you will need to define your domain in the /etc/postfix/virtual_mailbox_domains file: ``` nano /etc/postfix/virtual_mailbox_domains ``` Add the following line: ``` example.com #domain ``` Save and close the file then create another file: ``` nano /etc/mailname ``` Add your FQDN. ``` email.example.com ``` Next, convert the file to a format that Postfix can understand with the following command: ``` postmap /etc/postfix/virtual_mailbox_domains ``` Next, edit the Postfix master configuration file: ``` nano /etc/postfix/master.cf ``` Uncomment the following line: ``` submission inet n       -       y       -       -       smtpd ``` Save and close the file when you are finished. ## Step 5 – Install and Configure Dovecot Next, you will need to install Dovecot with other required packages. You can install them using the following command: ``` apt-get install dovecot-core dovecot-imapd dovecot-pop3d dovecot-lmtpd -y ``` Next, you will need to define the Dovecot mail location to communicate with Postfix and virtual mailbox domains. You can define it by editing /etc/dovecot/conf.d/10-mail.conf file: ``` nano /etc/dovecot/conf.d/10-mail.conf ``` Find the following line: ``` mail_location = mbox:~/mail:INBOX=/var/mail/%u ``` And replace it with the following: ``` mail_location = maildir:/var/mail/vhosts/%d/%n ``` Save and close the file. Next, create the Dovecot vhosts directory and the sub-directory for your domain name. ``` mkdir /var/mail/vhosts mkdir /var/mail/vhosts/example.com ``` Next, create a vmail user and a group, and assign the ownership of the directories to the vmail user. ``` groupadd -g 5000 vmail useradd -r -g vmail -u 5000 vmail -d /var/mail/vhosts -c "virtual mail user" chown -R vmail:vmail /var/mail/vhosts/ ``` Next, edit the Dovecot master configuration file and enable IMAP and POP3 secure services: ``` nano /etc/dovecot/conf.d/10-master.conf ``` Find the following lines: ``` inet_listener imaps {    #port = 993    #ssl = yes } ``` And replace them with the following: ``` inet_listener imaps {    port = 993    ssl = yes } ``` On the same file, find the following lines: ``` inet_listener pop3s {    #port = 995    #ssl = yes } ``` And replace them with the following: ``` inet_listener pop3s {    port = 995    ssl = yes } ``` Next, find the following lines: ``` service lmtp { unix_listener lmtp { #mode = 0666 } ``` And replace them with the following: ``` service lmtp { unix_listener /var/spool/postfix/private/dovecot-lmtp { mode = 0600 user = postfix group = postfix } ``` Next, find the following lines: ``` service  auth { # Postfix smtp-auth #unix_listener /var/spool/postfix/private/auth { #  mode = 0666 #} } ``` And replace them with the following: ``` service auth { ... #Postfix smtp-auth unix_listener /var/spool/postfix/private/auth { mode = 0666 user=postfix group=postfix } ``` Save and close the file when you are finished. Next, set up the Dovecot authentication process by editing the file /etc/dovecot/conf.d/10-auth.conf: ``` nano /etc/dovecot/conf.d/10-auth.conf ``` Uncomment the following line: ``` disable_plaintext_auth = yes ``` On the same file, find the following line: ``` auth_mechanisms = plain ``` And replace it with the following: ``` auth_mechanisms = plain login ``` Next, comment out the following line to disable the default Dovecot behaviour for authenticating users. ``` #!include auth-system.conf.ext ``` Next, uncomment the following line to enable password file configuration. ``` !include auth-passwdfile.conf.ext ``` Save and close the file when you are finished. Next, edit the /etc/dovecot/conf.d/auth-passwdfile.conf.ext  file: ``` nano /etc/dovecot/conf.d/auth-passwdfile.conf.ext ``` Change the file as shown below: ``` passdb { driver = passwd-file args = scheme=PLAIN username_format=%u /etc/dovecot/dovecot-users } userdb { driver = static args = uid=vmail gid=vmail home=/var/mail/vhosts/%d/%n } ``` Save and close the file. Next, create a password file for the user you want to assign an email account: ``` nano /etc/dovecot/dovecot-users ``` Add the following lines: ``` admin@example.com:admin@123 ``` Save and close the file. ## Step 6 – Configure Dovecot to Use Let’s Encrypt SSL Next, you will need to configure Dovecot to work with SSL. You can do it by editing the file /etc/dovecot/conf.d/10-ssl.conf: ``` nano /etc/dovecot/conf.d/10-ssl.conf ``` Find the following line: ``` ssl = yes ``` Replace it with the following: ``` ssl = required ``` Next, find the following lines: ``` #ssl_cert =        Alias /mail /usr/share/roundcube        ServerAdmin webmaster@localhost        DocumentRoot /var/www/html        ErrorLog ${APACHE_LOG_DIR}/error.log        CustomLog ${APACHE_LOG_DIR}/access.log combined ``` Save and close the file, then restart the Apache web service to apply the changes: ``` systemctl restart apache2 ``` ## Step 8 – Access Roundcube Webmail Now, open your web browser and type the URL h**http://email.example.com/mail.**You will be redirected to the Roundcube login page: ![](https://www.atlantic.net/wp-content/uploads/2020/03/r1.png)   Provide your username and password which you have defined in the Dovecot password file and click on the **Login** button. You should see the Roundcube default dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/03/Roundcube-Dashboard.png) ## Conclusion Congratulations! You have successfully installed and configured a mail server with Postfix, Dovecot and Roundcube. You can now send and receive email from the Roundcube webmail dashboard. Ready to get started with Postfix, Dovecot and Roundcube? Try it out on a [VPS Hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net today! Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [Virtual private servers.](https://www.atlantic.net/vps-hosting/) --- # How to Choose the Right VPS Plan for Your Business > URL: https://www.atlantic.net/vps-hosting/how-to-choose-the-right-vps-plan-for-your-business/ | Published: 2020-03-27 | Updated: 2025-09-19 | Author: Richard Bailey Cloud Virtual Private Servers (VPS) are available in many different flavors, and the service providers offer an abundance of plans for customers to choose from when deploying a server. When requisitioning a VPS, you are in control of choosing the operating system, usually Windows or a Linux distribution, and you can also opt for a pre-imaged auto-deployed application server, such as WordPress, cPanel, Docker or NodeJS. Importantly, you also get to choose the performance of the Cloud VPS you are creating; this is done by selecting a VPS Plan that suits your needs. ## VPS Hosting Models & Plans A Cloud VPS offers the perfect blend between a traditional VPS and dedicated hosting, which has made it an extremely popular service offering for the service providers and hosting companies. With a Cloud VPS, not only do you benefit greatly from the cost savings associated with the legacy hosting platforms, but you also get the guaranteed CPU, disk, and memory resources from a dedicated cloud platform. This is why a growing number of organizations are migrating private, personal, and business workloads to Cloud VPS. Atlantic.Net’s sales and support teams are often asked, “What plan should I choose? Do I need all this CPU power? Do I need extra memory (RAM)?” IT Professionals and System administrators will be able to answer these questions, but not everyone is a computer expert. For this reason, we have put together this guide to offer you the background knowledge you need to make an informed decision on what plan best suits your requirements. ## What Is a Cloud VPS Plan? Most service providers offer Cloud VPS under a variety of available plans. These plans typically include a **General Purpose** collection of standardized servers which are designed and suitable for multiple roles. Plans are also available for I/O intensive applications; these are **Storage Optimized** servers whose main benefit is disk performance. Providers also offer plans for **Memory-Optimized** or **Compute-Optimized** workloads. Cloud VPS plans allow you to choose a server that will provide the specified resources detailed above, guaranteed. A VPS is a virtual machine that is hosted on a virtual hypervisor. Virtual hypervisor technology allows the VPS to be deployed automatically, using pre-defined build scripts. The VPS is then built and allocated to a physical host that has the resources specified in the plan. The selected plan will include the preferred number of vCPUs available on the VPS. One vCPU is a single-core, while 8 vCPUs are 8 cores. The host will allocate CPU reservations against the physical hosts CPU [sockets, cores and threads](https://stackoverflow.com/questions/40163095/what-is-socket-core-threads-cpu). The physical hosts will have huge allocations of superfast memory (RAM), and this physical memory is logically divided up between the VPS guests. If you select a plan with 4GB RAM, your VPS is reserved 4GB of physical RAM from the stack. Your VPS will have exclusive access to that 4GB of allocated memory. VPS plans also include a multitude of disk storage options. Not only do these options include the size of storage allocated to the VPS, but also the type and speed. Storage allocations can be super fast Solid State Disk (SSD) storage, advanced premium (High I/O) dedicated local SSD storage, or extensive, flexible, and robust Secure Block Storage (SBS). The VPS network bandwidth allocated by the cloud provider must be taken into consideration when setting up a VPS. All inbound (ingress) network traffic to a VPS is usually free, but outbound (egress) network traffic is chargeable. Your customers will use egress network allocations to access data on your server, for example, when accessing your website. Most VPS plans will include a set amount of “free” network bandwidth. This might be a small amount or a substantial allocation; the best option for you depends purely on your usage expectations. ## Plan Flexibility You can always upgrade your Cloud VPS plan at any time. This adds a lot of flexibility; as your business grows organically, so can your VPS. Essentially, you can re-provision the server with more CPU, disk, memory and network bandwidth. There are a few “gotchas” with this technology; commonly, the operating system will need to be re-imaged when upgrading your VPS. But if you have planned your VPS design, you can save your data on an SBS volume, or if you have a backup or snapshot, you can simply move the data volume onto the new server. Backup restoration is a much simpler way of restoring data to a newly reprovisioned server. Simply restore your system over the top of your new server from backup. This approach gets you back up and running in next to no time. A VPS can scale up by reprovisioning to a new plan with better performance, but the VPS can also scale out meaning that you can implement a cluster of virtual private servers to work together to provide additional compute resources. ## General Purpose VPS General-purpose VPS plans are the most commonly used and deployed. These types of VPS are for general, everyday workloads. The use case scenario for a general-purpose VPS varies massively; for example, you might provision this type of plan to host a website or a workstation. Just because these servers are labeled general purpose does not mean that they are slow or underperforming. Our SSD-backed servers are ultra-fast, no matter what resources you allocate. You can purchase a VPS for as little as $10 per month, and you might be surprised how powerful the smallest plan works out. If using Linux, the servers are more than powerful enough to run WordPress, cPanel, and basic MySQL applications. The general purpose plan goes up to 64GB RAM, 20vCPU and 650GB SSD. These kinds of resources are powerful enough for enterprise-grade Docker installations, backup servers, or even powerful SQL database servers. ## Storage Optimized VPS A VPS optimized for storage does exactly as the name suggests; you not only have access to dedicated, high-performance professional SSD hardware, but also can allocate up to 4TB of SSD storage to your VPS. For obvious reasons, we do not recommend running just Windows Server on a 4TB SSD; these storage optimized servers are recommended for I/O intensive applications such as Microsoft SQL Server and, in particular, SQL ETL data transformation jobs. The super-fast I/O gives the VPS the capability to crunch huge amounts of data in no time at all. Storage Optimized VPS use local SSD drives and are great for ultra-low latency, mission-critical tasks. Most commonly, our customers use these servers for distributed databases and data analytics. ## Memory-Optimized VPS Customers that need servers with a large amount of volatile memory (RAM) can opt for the Memory Optimized VPS, which offers not only the best prices for higher RAM amounts, but also large amounts of uninterrupted memory sizes ranging from 16GB to 128GB. These are designed for applications that require extremely high memory I/O or use applications that reside in memory for better performance. This type of VPS suits database applications and programs like Apache Spark. Each server uses SSDs which enhance the performance of memory-optimized servers, and the SSDs can be used to dump data in the event of an error. ## Compute-Optimized VPS An Optimized CPU VPS will provide your applications with a huge amount of compute power. With this type of VPS, you have access to the optimized Intel CPU hosting platform, allowing users to process vast amounts of information instantaneously. CPU optimized VPSes are perfect for data analytics, video processing, gaming servers, and Docker worker nodes. SSD storage and ultra-fast memory create a server package that can keep up with the biggest of workloads. ## What Next? Clearly the array of choices for a VPS is vast, and there are many use cases for each type of VPS. Usually, customers opt for plans with lower specifications, knowing that they can upgrade the plan if and when an upgrade is needed. Cloud VPS offers greater levels of control over your server. Our hosting environment is simple to use, but powerful and flexible. Most importantly, your resources are guaranteed without disruption. Share your vision with us and we will develop a hosting environment tailored to your needs! Contact an advisor at 866-618-DATA (3282) or get started on our [VPS Hosting](https://www.atlantic.net/vps-hosting/) page. --- # Overview of CCPA and GDPR > URL: https://www.atlantic.net/vps-hosting/overview-of-ccpa-and-gdpr/ | Published: 2020-03-30 | Updated: 2025-09-19 | Author: Richard Bailey The California Consumer Privacy Act (CCPA), and the General Data Protection Regulations (GDPR) are both privacy acts recently passed to update outdated laws regarding how personal information is handled, stored and processed in the digital age. Since the proliferation of internet services, mobile telecommunications, and social media, campaigners have been demanding changes to how businesses handle personal information. CCPA was passed in 2018 and came into force on January 1st, 2020. GDPR was passed into law in May 2018. Both legislations have similar recommendations and requirements. GDPR is focused on the personal information of European citizens, and CCPA relates to the personal information of California residents. Importantly, both legislations have a shared synergy that impacts businesses on both sides of the Atlantic. Any business in the United States that processes European personal information and any business in Europe that processes US personal information must adhere to each legislation’s guidelines to be compliant with the privacy rules. ## What is CCPA? CCPA protects the private information of California residents in the United States. This includes data about the person’s identity, any sensitive health information, biometric data, mobile geolocation data, and any financial or asset information. The aim of the privacy act is to limit sensitive information disclosures or unexpected leaks caused by data breaches. CCPA has been designed to give consumers control of their personal information and reinforce the penalties for any breaches of information, be this by negligence or as a result of a data hack. The legislation’s purpose is to enforce consumer rights and give the consumer new rights about their data. This includes the right to know exactly what information is held on a person by a business. This is why you can now go to sites like Google and Facebook and download detailed archives of what information they hold on you. California residents also have the right to access and view the data held on them, and importantly, the right to have the data deleted. Rights to opt-in or opt-out of data collection have been created. Other key elements include the right to equal service and price, and the right to seek damages if personal information is breached. The new rules put a number of new requirements upon businesses that process personal data. They must be able to provide access to personal information, delete personal information on request, and evidence its destruction. They must also introduce consent management practices. This is commonly seen on websites where companies share information with third parties. The organization has a duty to disclose what data is shared. CCPA gives the individual control over what information can or cannot be sold about them. Businesses are required to conduct data inventory exercises to learn in-scope personal data and instances of “selling” data. As a result, updating service-level agreements with third-party data processors is needed to be compliant. Remediation of information security gaps and system vulnerabilities must be resolved promptly by implementing data governance reinforcement and data identification programs. If there is data held that is out of scope, it must be deleted. ## What is GDPR? GDPR was designed for European citizens but affects every entity processing EU data. Its main purpose was to standardize data protection laws of all EU member states. There are seven key principles of GDPR legislation. These focus on the lawfulness of retaining personal information and ensuring it is stored in a fair and transparent manner. The data must be retained for a specific reason and serve a specific purpose. Personal data cannot be retained indefinitely and must be destroyed once it has served its purpose. Organizations must also commit to data minimization, retaining only recent and relevant information that is accurate. They must retain data integrity and ensure the confidentiality of private information is upheld. EU citizens have many new rights since the introduction of GDPR. These rights lay the foundation of what third parties can and cannot do with personal information. People have the right to be informed of what personal data is being held by the business, and the individual has the right to view and access this information. If necessary, they have the right to correct the data. EU citizens can request personal information is deleted and restrict how personal information is processed. They have the right to object as well as rights in relation to automated decision making and profiling, such as credit card acceptability criteria. ## CCPA vs GDPR It is obvious to see the striking similarities between CCPA and GDPR. CCPA could be considered the US counterpart of GDPR. There are however some significant differences. [GDPR affects data controllers and data processors](https://www.atlantic.net/vps-hosting/gdpr-compliance-for-global-managed-service-providers/) inside and outside of the European Union, however, CCPA only regulates companies “[doing business](https://www.financierworldwide.com/the-california-consumer-privacy-act-and-the-gdpr-two-of-a-kind#.XkxF9-j7SUk)” in California. Other rules exist such as CCPA only being applicable to companies with gross revenue above $25 million USD, and those that process the personal information of more than 50,000 California residents. The penalties given for breaching either legislation are also quite different. GDPR is up to 4% of turnover, or 20 million Euro (whichever is greater). CCPA is specifically $2500 per record for unintentional violations and $7500 for intentional violations. There are other subtle differences,  but importantly both legislation set out with the same objective,  which is to enhance and protect personal and private information. Both laws enforce the notion that businesses cannot harvest whatever data they choose. Data has significant value and many tech giants in Silicon Valley have made huge profits selling personal information. CCPA and GDPR have identified this and have acted to protect each of us. --- # How to Protect Apache and SSH With Fail2Ban on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-protect-apache-and-ssh-with-fail2ban-on-centos-8/ | Published: 2020-03-31 | Updated: 2023-11-27 | Author: Hitesh Jethva If you’re a system administrator, then protecting your server from different kinds of attacks is an essential part of your job; Fail2Ban firewall can help you achieve this. Fail2Ban is an intrusion prevention system written in the Python language used to block malicious IPs that are trying to breach your system security. It works by scanning various log files and blocking the IPs that are trying to make frequent login attempts for a specified bantime.  It also allows you to monitor the strength and frequency of attacks. Due to its simplicity, it is considered the preferred software to secure your server from DOS, DDOS, and brute-force attacks. In this tutorial, we will show you how to secure an SSH and Apache server with Fail2Ban on CentOS 8. ## Step 1 – Install Fail2Ban By default, Fail2Ban is not available in the CentOS 8 default repository, so you will need to install the EPEL repository in your system. You can install it with the following command: ``` dnf install epel-release -y ``` After installing the EPEL repository, you can install Fail2Ban with the following command: ``` dnf install fail2ban -y ``` Once installed, start the Fail2Ban service and enable it to start after system reboot: ``` systemctl start fail2ban systemctl enable fail2ban ``` ## Step 2 – Secure SSH with Fail2Ban In this section, we will learn how to secure the SSH server with Fail2Ban. **Configure Fail2Ban for SSH** By default, all pre-set jails are located inside /etc/fail2ban/jail.conf file. This is not an appropriate way to edit the default jail.conf file. You should create a separate jail.local file for each service that you want to configure. You can create a jail.local file for SSH with the following command: ``` nano /etc/fail2ban/jail.local ``` Add the following lines: ``` [DEFAULT] ignoreip = your-server-ip bantime = 300 findtime = 300 maxretry = 3 banaction = iptables-multiport backend = systemd [sshd] enabled = true ``` Save and close the file when you are finished. Then, restart the Fail2Ban service to apply the changes: ``` systemctl restart fail2ban ``` You can now check the status of SSH jail with the following command: ``` fail2ban-client status ``` You should see that an SSH jail is enabled: ``` Status |- Number of jail:        1 `- Jail list:        sshd ``` **A brief explanation of each parameter is shown below:** - **ignoreip**: Used to define the IP addresses that you want to be ignored. - **bantime**: Used to define a number of seconds the IP address will be banned for. - **findtime**: Used to define the amount of time between login attempts before the IP is banned. - **maxretry**: Used to define the number of attempts to be made before the IP address is banned. - **banaction**: Banning action. - **enabled**: This option enables the protection for SSH service. **Test SSH Against Password Attacks** At this point, Fail2Ban is installed and configured. It’s time to test whether it is working or not. To do so, go to the remote machine and try to SSH to the server IP address: ``` ssh root@server-ip ``` You will be asked to provide the root password. Type the wrong password again and again. Once you reach the login attempt limit, your IP address will be blocked. You can verify your blocked IP address with the following command: ``` fail2ban-client status sshd ``` You should see your blocked IP in the following output: ``` Status for the jail: sshd |- Filter |  |- Currently failed:   7 |  |- Total failed:          39 |  `- Journal matches:  _SYSTEMD_UNIT=sshd.service + _COMM=sshd `- Actions   |- Currently banned: 1   |- Total banned:        2   `- Banned IP list:     190.8.80.42 ``` You can also check the SSH log for failed logins: ``` tail -5 /var/log/secure | grep 'Failed password' ``` You should see the following output: ``` Mar  1 03:55:03 centos8 sshd[11196]: Failed password for invalid user bpadmin from 190.8.80.42 port 55738 ssh2 ``` You can also block and unblock a specific IP address manually. For example, to unblock the IP 190.8.80.42, run the following command: ``` fail2ban-client set sshd unbanip 190.8.80.42 ``` To block the IP 190.8.80.42, run the following command: ``` fail2ban-client set sshd banip 190.8.80.42 ``` ## Step 3 – Secure Apache with Fail2Ban You can also secure the Apache webserver from different kinds of attacks. You will need to configure jail.local file for Apache as shown below: ``` nano /etc/fail2ban/jail.local ``` Add the following lines at the end of the file: ``` [apache-auth] enabled = true port    = http,https logpath = %(apache_error_log)s [apache-badbots] enabled = true port    = http,https logpath = %(apache_access_log)s bantime = 48h maxretry = 1 [apache-noscript] enabled = true port    = http,https logpath = %(apache_error_log)s ``` Save and close the file when you are finished. Then, restart the Fail2Ban service to implement the changes: ``` systemctl restart fail2ban ``` You can now verify the status of all jails with the following command: ``` fail2ban-client status ``` You should see the following output: ``` Status |- Number of jail:        5 `- Jail list:        apache-auth, apache-badbots, apache-noscript, sshd ``` **A brief explanation of each jail is shown below:** - **apache-auth**: This jail is used to protect Apache from failed login attempts. - **apache-badbots**: This jail is used to ban hosts which agent identifies spammer robots crawling the web for email addresses. - **apache-noscript**: Used to block the IP which is trying to search for scripts on the website to execute. ## Conclusion In the above tutorial, we learned how to protect SSH and Apache server with Fail2Ban. It is a very useful intrusion prevention system that adds extra security to your Linux system. You are now able to configure Fail2Ban that will suit your specific security needs. Get started with Fail2Ban today with [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Ansible Server on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-ansible-server-on-ubuntu-18-04/ | Published: 2020-04-01 | Updated: 2023-11-22 | Author: Hitesh Jethva Ansible is an automation tool set that works extremely well with Linux-based servers, but is also compatible with other cloud servers, such as Windows and VMware (to name a few). Ansible is an agentless application that only requires Python to function, which is a default application in nearly all Linux distributions. Ansible its great at automating administrative tasks and creating a desired state infrastructure (ensuring all servers are the same). Ansible works using the SSH protocol, so you don’t need any software or agent on remote servers. It is a great alternative to other automation tools, including Chef and Puppet. In this article, we will show you how to install and configure Ansible on Ubuntu 18.04 server. ## Prerequisites - A fresh Ubuntu 18.04 [VPS](https://www.atlantic.net/vps-hosting/) - Preferably, you will have a few Linux test servers (Ubuntu or Debian) - A root password configured on your server ## Step 1 – Configure SSH Key-based Authentication Ansible uses SSH to retrieve information from the remote hosts. You will need to set up key-based authentication for the remote hosts so the Ansible server can communicate with remote hosts without entering SSH password. First, generate an SSH key on Ansible server with the following command: ``` ssh-keygen -t rsa ``` You should get the following output: ``` Generating public/private rsa key pair. Enter file in which to save the key (/root/.ssh/id_rsa): Created directory '/root/.ssh'. Enter passphrase (empty for no passphrase): Enter same passphrase again: Your identification has been saved in /root/.ssh/id_rsa. Your public key has been saved in /root/.ssh/id_rsa.pub. The key fingerprint is: SHA256:HzUXrR+ltn9w0mwz5+hKeFzEOPcJrLTKi9C72Y7elAE root@ubuntu1804 The key's randomart image is: +---[RSA 2048]----+ |              .. | |            .o .o| |       E   .=o=o.| |        . ..o*=o.| |        S..o ..*o| |      . ..++ .+oB| |     . . =o +  O+| |      . O .o  . +| |      .Bo=  .o. .| +----[SHA256]-----+ ``` Next, copy the generated key to the remote hosts with the following command: ``` ssh-copy-id -i ~/.ssh/id_rsa.pub root@your-remote-host-ip ``` Next, check the SSH password-less login with the following command: ``` ssh root@your-remote-host-ip ``` ## Step 2 – Install Ansible By default, Ansible is not available in the Ubuntu 18.04 default repository, so you will need to add Ansible PPA to your system. You can add Ansible PPA with the following command: ``` apt-add-repository ppa:ansible/ansible ``` After adding Ansible PPA, update the repository and install Ansible with the following command: ``` apt-get update -y apt-get install ansible -y ``` Once the installation has been completed, you can proceed to the next step. ## Step 3 – Configure Ansible Hosts Next, you will need to configure your Ansible hosts file to define the remote servers. You can edit the /etc/ansible/hosts with the following command: ``` nano /etc/ansible/hosts ``` You can add single hosts or group of hosts, as shown below: ``` [webservers] webserver1 ansible_ssh_host=192.168.1.2 ansible_ssh_port=22 ansible_ssh_user=root webserver2 ansible_ssh_host=192.168.1.3 ansible_ssh_port=22 ansible_ssh_user=root [databaseservers] dbserver1 ansible_ssh_host=192.168.1.4 ansible_ssh_port=22 ansible_ssh_user=root ``` Save and close the file when you are finished. In the above file, webserver1 and webserver2 are used to define a webserver IP address, SSH port and username, while dbserver1 is used to define a database server IP Address, SSH port and username. Next, disable the Python warning by editing the file /etc/ansible/ansible.cfg: ``` nano /etc/ansible/ansible.cfg ``` Add the following line below [defaults]: ``` deprecation_warnings=False ``` Save and close the file when you are finished. At this point, your Ansible server is ready to manage your web server and database server. ## Step 4 – Test Ansible After setting up the Ansible server, it’s time to test the connectivity of all Ansible hosts. On the Ansible server, run the following command to test the connectivity of all hosts: ``` ansible -m ping all ``` If everything is fine, you should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Ansible-Ping.png) To test the connectivity of specific hosts like dbserver1, run the following command: ``` ansible -m ping dbserver1 ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Ansible-Ping-2.png) To test the connectivity of a group of hosts like [webservers], run the following command: ``` ansible -m ping webservers ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Ansible-Ping-3.png) ## Step 5 – Ansible Advanced Commands You can execute any command on a remote server over SSH from the Ansible server. For example, to check disk usage of all Ansible hosts, run the following command: ``` ansible -m shell -a "df -h" all ``` This command will execute “df -h” command on all remote hosts and give the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Ansible-Disk-Usage.png) You can list all databases on dbserver1 hosts with the following command: ``` ansible -m shell -a "mysql -u root -padmin@123 -e 'show databases;'" dbserver1 ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Ansible-Databases.png) ## Conclusion In the above tutorial, we learned how to install Ansible on Ubuntu 18.04 server. We also learned how to manage multiple servers with Ansible. You can now easily manage your entire infrastructure with Ansible – try it out with [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Use Docker on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-docker-on-centos-8/ | Published: 2020-04-02 | Updated: 2023-11-17 | Author: Hitesh Jethva Sometimes when designing an application, it will work perfectly on your machine, but upon moving it into production, the application fails to work with the same performance or same optimization. This frustrating experience can be mitigated by using Docker. Docker is an open-source container management service that allows you to build, ship and run applications on a server, cloud, or laptop, or even ship it into a container that can be deployed anywhere. To summarize, Docker simplifies the process of managing application processes in containers. Docker has recently become very popular in recent times due to its ability to run applications anywhere, irrespective of the host operating system. In this tutorial, we will show you how to install and use Docker on CentOS 8. ## Install Docker By default, the latest version of Docker is not available in the CentOS 8 default repository. You can add and enable the official Docker CE repository with the following command: ``` dnf config-manager --add-repo=https://download.docker.com/linux/centos/docker-ce.repo ``` After adding the repository, you can verify the repository with the following command: ``` dnf repolist -v | grep docker ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Docker-Repository.png) Now, install the appropriate version of Docker using the –nobest option as shown below: ``` dnf install docker-ce --nobest -y ``` After installing Docker, start the Docker service and enable it to start after system reboot: ``` systemctl start docker systemctl enable docker ``` Next, verify the status of the Docker service using the following command: ``` systemctl status docker ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Docker-Service.png) ## Docker Basic Commands You can check the installed version of Docker using the following command: ``` docker --version ``` You should get the following output: ``` Docker version 19.03.6, build 369ce74a3c ``` To check the system-wide information on Docker, run the following command: ``` docker info ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Docker-Info.png) You can check all information about the container with the following command: ``` docker inspect "Container-ID" ``` You can display all options available with docker command using the following command: ``` docker --help ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Docker-Help.png) ## Start the Docker Container in Interactive Mode First, pull the Ubuntu image from the Docker hub repository with the following command: ``` docker pull ubuntu ``` You should see the following output: ``` Using default tag: latest latest: Pulling from library/ubuntu 423ae2b273f4: Pull complete de83a2304fa1: Pull complete f9a83bce3af0: Pull complete b6b53be908de: Pull complete Digest: sha256:04d48df82c938587820d7b6006f5071dbbffceb7ca01d2814f81857c631d44df Status: Downloaded newer image for ubuntu:latest docker.io/library/ubuntu:latest ``` ![](https://www.atlantic.net/wp-content/uploads/2020/04/Docker-Pull-Ubuntu.png) You can now verify the image with the following command: ``` docker images ``` You should see the following output: ``` REPOSITORY          TAG                 IMAGE ID            CREATED             SIZE ubuntu              latest              72300a873c2c        8 days ago          64.2MB ``` Now, start the Ubuntu container using the downloaded image in interactive mode with the following command: ``` docker run -it ubuntu ``` Once the container started, you should get the Ubuntu container shell. You can now run the update command inside the shell to update the system. ![](https://www.atlantic.net/wp-content/uploads/2020/04/Docker-Update-Ubuntu.png) You can exit from the container with the following command: ``` exit ``` You can list the active container by running the following command: ``` docker ps ``` Output: ``` CONTAINER ID        IMAGE               COMMAND             CREATED             STATUS              PORTS               NAMES ``` You can list both active and inactive containers by running the following command: ``` docker ps -a ``` Output: ``` CONTAINER ID        IMAGE               COMMAND             CREATED              STATUS                      PORTS               NAMES 96fdc35ac495        ubuntu              "/bin/bash"         About a minute ago   Exited (0) 24 seconds ago                       stupefied_keller ``` ![](https://www.atlantic.net/wp-content/uploads/2020/04/Docker-Containers.png) ## Start the Docker Container in Detached Mode Docker allows you to search for images available in the Docker Hub. For example, you can search for Nginx images using the following command: ``` docker search nginx ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Docker-Nginx-Search.png) Now, download and start Nginx container in detached mode with the following command: ``` docker run -itd nginx ``` This command will download the Nginx image from the Docker Hub repository and start the container in detached mode as shown below: ``` Unable to find image 'nginx:latest' locally latest: Pulling from library/nginx 68ced04f60ab: Pull complete c4039fd85dcc: Pull complete c16ce02d3d61: Pull complete Digest: sha256:380eb808e2a3b0dd954f92c1cae2f845e6558a15037efefcabc5b4e03d666d03 Status: Downloaded newer image for nginx:latest 4eeabeb599d079795c1acd4822420c8513f12d6264176ea0685f9028f8bfd014 ``` ![](https://www.atlantic.net/wp-content/uploads/2020/04/Docker-Nginx-Install.png) You can now verify the running container using the following command: ``` docker ps ``` You should see your Nginx container in the following output: ``` CONTAINER ID        IMAGE               COMMAND                  CREATED             STATUS              PORTS               NAMES 4eeabeb599d0        nginx               "nginx -g 'daemon of…"   30 seconds ago      Up 28 seconds       80/tcp              pensive_ptolemy ``` ## Manage the Docker Container In this section, we will show you some useful Docker commands that will help you to manage a Docker container easily. To start the Docker container, use the following syntax: ``` docker start "Container-ID" ``` First, find the container id with the following command: ``` docker ps -a ``` Output: ``` CONTAINER ID        IMAGE               COMMAND                  CREATED             STATUS                          PORTS               NAMES 4eeabeb599d0        nginx               "nginx -g 'daemon of…"   19 minutes ago      Exited (0) About a minute ago                       pensive_ptolemy 96fdc35ac495        ubuntu              "/bin/bash"              22 minutes ago      Exited (0) About a minute ago                       stupefied_keller ``` Next, start the container with id **4eeabeb599d0** as shown below: ``` docker start 4eeabeb599d0 ``` Now, check the running container with the following command: ``` docker ps ``` You should see the following output: ``` docker ps CONTAINER ID        IMAGE               COMMAND                  CREATED             STATUS              PORTS               NAMES 4eeabeb599d0        nginx               "nginx -g 'daemon of…"   20 minutes ago      Up 36 seconds       80/tcp              pensive_ptolemy ``` To pause the running container, run the following command: ``` docker pause "Container-ID" ``` To stop the running container, run the following command: ``` docker stop "Container-ID" ``` To stop all running containers, run the following command: ``` docker stop $(docker ps -a -q) ``` To delete the container, you will need to stop it first. Then, run the following command to delete it: ``` docker rm "Container-ID" ``` To remove all stopped containers, run the following command: ``` docker rm $(docker ps -a -q) ``` To remove the Docker image, run the following command: ``` docker rmi "Image-ID" ``` To remove all unused Docker images, run the following command: ``` docker rmi $(docker images -q -a) ``` To remove any stopped container and all unused images, run the following command: ``` docker system prune -a ``` You should see the following output: ``` WARNING! This will remove: - all stopped containers - all networks not used by at least one container - all images without at least one container associated to them - all build cache Are you sure you want to continue? [y/N] y Deleted Containers: 4eeabeb599d079795c1acd4822420c8513f12d6264176ea0685f9028f8bfd014 96fdc35ac49588aea490833a1ca66387ee9617217ee29715043291db1942b219 Deleted Images: untagged: ubuntu:latest untagged: ubuntu@sha256:04d48df82c938587820d7b6006f5071dbbffceb7ca01d2814f81857c631d44df deleted: sha256:72300a873c2ca11c70d0c8642177ce76ff69ae04d61a5813ef58d40ff66e3e7c deleted: sha256:d3991ad41f89923dac46b632e2b9869067e94fcdffa3ef56cd2d35b26dd9bce7 deleted: sha256:2e533c5c9cc8936671e2012d79fc6ec6a3c8ed432aa81164289056c71ed5f539 deleted: sha256:282c79e973cf51d330b99d2a90e6d25863388f66b1433ae5163ded929ea7e64b deleted: sha256:cc4590d6a7187ce8879dd8ea931ffaa18bc52a1c1df702c9d538b2f0c927709d untagged: nginx:latest untagged: nginx@sha256:380eb808e2a3b0dd954f92c1cae2f845e6558a15037efefcabc5b4e03d666d03 deleted: sha256:a1523e859360df9ffe2b31a8270f5e16422609fe138c1636383efdc34b9ea2d6 deleted: sha256:4d5d91d27654e1c0284efbe6617ab628d30f2be44301460f94ca811d0ea14f44 deleted: sha256:4245b7ef9b70e3b2975ed908c7d68ce5f03972d8be702b0ed491e32445b42b8f deleted: sha256:f2cb0ecef392f2a630fa1205b874ab2e2aedf96de04d0b8838e4e728e28142da Total reclaimed space: 218.9MB ``` ![](https://www.atlantic.net/wp-content/uploads/2020/04/Docker-Prune.png) ## Conclusion Congratulations! You have successfully installed Docker on CentOS 8 and you have enough knowledge to install and manage the Docker containers. You can now explore Docker and start developing your first project inside the Docker container on a [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Install and Use Git on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-git-on-ubuntu-18-04/ | Published: 2020-04-03 | Updated: 2024-06-11 | Author: Hitesh Jethva Git is the most popular version control system. Now used by developers around the world, it was originally developed by Linus Torvalds for Linux kernel development. A version control system is used to store and manage every revision of your code and files. Git is used by many companies to collaborate on source code, manage releases, and roll back to previous versions when bugs are discovered. Git keeps track of each change that you have made to a file or code and allows you to roll back those changes. For example, if you are editing code on your system and want to delete a section of code, you can use a version control system to restore that deleted code in the future. Git also allows multiple  users to work on the same files at the same time. In this tutorial, we will show you how to install and use the Git version control system on Ubuntu 18.04. ## Install Git By default, Git is available in the Ubuntu 18.04 default repository. You can install it by just running the following command: ``` apt-get install git -y ``` Once the installation has been completed, you can check the version of the Git using the following command: ``` git --version ``` You should see the following output: ``` git version 2.23.0 ``` ## Configure Git Before configuring Git, you will need to create an account on GitHub. You can create a new account using the URL [github.com](https://github.com/) as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/04/GitHub-Landing-Page.png) After creating an account on GitHub, open your terminal and run the following command that matches your GitHub username and email: ``` git config --global user.name "YOUR_USERNAME" git config --global user.email "YOUR@EMAIL” ``` Next, verify the configuration changes with the following command: ``` git config --list ``` You should see the following output: ``` user.name=YOUR_USERNAME user.email=YOUR@EMAIL ``` ## Create a New Repository on GitHub Next, log in to your GitHub account as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/04/GitHub-Account.png) Click on the **New** button to create a repository. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/04/GitHub-Create-Repository.png) Provide a *repository name*, description and click on the **Create** **repository** button. Once the repository is created, make a note of your **Git Repo Address** at the Quick Setup page. ## Use Git with Local and Remote Repositories Next, open your terminal and create a new directory that matches your project, as shown below: ``` mkdir atlanticapp ``` Next, change the directory to atlanticapp and initiate Git for this directory with the following command: ``` cd atlanticapp git init ``` You should see the following output: ``` Initialized empty Git repository in /home/vyom/atlanticapp/.git/ ``` Next, connect the remote GitHub repository to the local system with the following command: ``` git remote add origin https://github.com/YOUR_GIT_REPO.git ``` Next, create a new file named test.html as shown below: ``` nano test.html ``` Add the following contents: ``` My Atlantic App

This is my first atlantic App.

``` Save and close the file, then run the following command to adds changes in the working directory to the staging area: ``` git add test.html ``` Next, run the following command to save your changes to the local repository: ``` git commit -m "This my first version of test.html file" ``` You should see the following output: ``` [master (root-commit) 4d7a3de] This my first version of test.html file 1 file changed, 4 insertions(+) create mode 100644 test.html ``` ![](https://www.atlantic.net/wp-content/uploads/2020/04/Git-Test-File.png) Next, run the following command to upload local repository content to a remote repository. ``` git push origin master ``` You will be asked to provide your GitHub username and password, as shown below: ``` Username for 'https://github.com': YOUR_USERNAME Password for 'https://github.com’: YOUR_PASSWORD ``` After providing the correct details, your local repository content has been added to the remote repository: ``` Counting objects: 3, done. Delta compression using up to 4 threads. Compressing objects: 100% (2/2), done. Writing objects: 100% (3/3), 292 bytes | 0 bytes/s, done. Total 3 (delta 0), reused 0 (delta 0) To https://github.com/hitjethva/exampleapp.git * [new branch]      master -> master ``` ![](https://www.atlantic.net/wp-content/uploads/2020/04/Git-Remote-Repository.png) To verify it, go to the GitHub account page and refresh it. You should see the added file in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/04/GitHub-Repository-File.png) You can also view which remote servers are configured using the following command: ``` git remote -v ``` You should see the names of your remote repositories in the following output: ``` origin  https://github.com/hitjethva/exampleapp.git (fetch) origin  https://github.com/hitjethva/exampleapp.git (push) ``` ## Working with Git Revisions Next, edit the test.html file and add some more contents: ``` nano test.html ``` Make the following changes: ``` My Atlantic App

This is my first atlantic App.

I am adding some content to this file.

``` Save and close the file when you are finished. Then, add the updated file to the remote repository with the following commands: ``` git add test.html git commit -m "This my second version of test.html file" git push origin master ``` ![](https://www.atlantic.net/wp-content/uploads/2020/04/Git-Test-File-Updated.png) Now, go to the GitHub page and refresh it. You should see the updated file with different revision number in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/04/GitHub-Repository-File-Updated.png) Next, open your terminal and clone your repository to the local system with the following command: ``` git clone https://github.com/hitjethva/exampleapp.git ``` You should see the following output: ``` Cloning into 'exampleapp'... remote: Enumerating objects: 6, done. remote: Counting objects: 100% (6/6), done. remote: Compressing objects: 100% (4/4), done. remote: Total 6 (delta 1), reused 5 (delta 0), pack-reused 0 Unpacking objects: 100% (6/6), done. Checking connectivity... done. ``` Next, change the directory to the cloned directory. ``` cd exampleapp/ ``` Now, you can use the git checkout command to download the files in the working directory to match with your desired version stored in that branch. For example, to download the previous version file, go to the GitHub page and copy the previous version file’s revision number as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/04/GitHub-Repository-File-Revision.png) Next, run the git checkout command with revision number as shown below: ``` git checkout 4d7a3de02b19e6aaea3b7f2bd6a4c0a5c85ddbe6 ``` You should see the following output: ``` Note: checking out '4d7a3de02b19e6aaea3b7f2bd6a4c0a5c85ddbe6'. You are in 'detached HEAD' state. You can look around, make experimental changes and commit them, and you can discard any commits you make in this state without impacting any branches by performing another checkout. If you want to create a new branch to retain commits you create, you may do so (now or later) by using -b with the checkout command again. Example:   git checkout -b new_branch_name HEAD is now at 4d7a3de... This my first version of test.html file ``` ![](https://www.atlantic.net/wp-content/uploads/2020/04/Git-Checkout.png) Now, check the content of test.html file: ``` cat test.html ``` You should see the content of your previous version file: ``` My Atlantic App

This is my first atlantic App.

``` ## Conclusion In the above tutorial, we learned how to install Git on Ubuntu 18.04. We also learned how to add files and commit changes to the remote repository. You can now manage and track your project from a central location – start using Git today with a [VPS from Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # How to Install and Secure Redis on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-secure-redis-on-ubuntu-18-04/ | Published: 2020-04-04 | Updated: 2023-11-17 | Author: Hitesh Jethva Redis, which stands for “remote dictionary server,” is a key-value store that stores data as key-value pairs. Redis is a NoSQL database, meaning it does not have tables, rows and columns like in MySQL and Oracle databases. It does not use INSERT, SELECT, UPDATE and DELETE. Instead of this, Redis uses data structures to store data. It uses five primary data structures including Strings, Lists, Sets, Sorted Sets, and Hashes, as well as three extra data structures including bitmaps, hyperloglogs and geospatial indexes. One of the most important features of Redis is that it is an in-memory database, meaning it keeps the data in memory, making it super-fast. However, Redis also has options to write the data to the disk. In this tutorial, we will show you how to install and secure Redis on Ubuntu 18.04. ## Install Redis Server By default, the Redis package is available in the Ubuntu 18.04 server. You can install it with the following command: ``` apt-get install redis-server php-redis -y ``` After installing the Redis server, you will need to configure the Redis server to use the init system for managing Redis as a service. You can configure it by editing redis.conf file: ``` nano /etc/redis/redis.conf ``` Find the following line: ``` supervised no ``` Replace it with the following line: ``` supervised systemd ``` ![](https://www.atlantic.net/wp-content/uploads/2020/04/Supervised-Systemd.png) Save and close the file. Then, restart the Redis service to apply the changes: ``` systemctl restart redis ``` You can also check the status of the Redis service with the following command: ``` systemctl status redis ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Redis-Status.png) ## Verify Redis Server It is recommended to test whether the Redis server is functioning as expected or not. You can test it using the redis-cli command-line utility: ``` redis-cli 127.0.0.1:6379> ping ``` If everything is fine, you should get the following output: ``` PONG ``` ![](https://www.atlantic.net/wp-content/uploads/2020/04/Redis-Ping.png) You can now exit from the Redis shell with the following command: ``` exit ``` You can also check the version of the Redis with the following command: ``` redis-cli -v ``` Output: ``` redis-cli 4.0.9 ``` For more information about Redis, run the following command: ``` redis-cli info ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Redis-Info.png) You can also verify the Redis listening port with the following command: ``` netstat -lnp | grep redis ``` You should see that Redis server is listening on localhost on port 6379: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Redis-Listening-Port.png) ## Secure Redis with Password By default, Redis can be accessed without any password. It is recommended to secure Redis with a password for security reasons. First, generate a strong password with OpenSSL command as shown below: ``` openssl rand 60 | openssl base64 -A ``` You should see the following output (a password like this): ``` MGDCmmWh2Ot+aZDv7TBr54SY5PueoSAVhX41sApcOLWYBTlPrfe01OT/nqO0YWK/y0ROozsDi9Dw61jR ``` Now, paste your password in the Redis configuration file /etc/redis/redis.conf: ``` nano /etc/redis/redis.conf ``` Find the following line: ``` # requirepass foobared ``` Replace it with the following line: ``` requirepass MGDCmmWh2Ot+aZDv7TBr54SY5PueoSAVhX41sApcOLWYBTlPrfe01OT/nqO0YWK/y0ROozsDi9Dw61jR ``` Save and close the file. Then, restart the Redis service to apply the changes: ``` systemctl restart redis ``` Now, connect to the Redis command-line with the following command: ``` redis-cli 127.0.0.1:6379> ``` Now, run the following command to test whether the Redis password works: ``` 127.0.0.1:6379> set test "How Are You" ``` You will get the following error because didn’t authenticate: ``` (error) NOAUTH Authentication required. ``` Now, authenticate Redis with the password as shown below: ``` 127.0.0.1:6379> auth MGDCmmWh2Ot+aZDv7TBr54SY5PueoSAVhX41sApcOLWYBTlPrfe01OT/nqO0YWK/y0ROozsDi9Dw61jR ``` You should get the following output: ``` OK ``` Now, run the previous command again: ``` 127.0.0.1:6379> set test "How Are You" ``` Output: ``` OK ``` Now, get the value of the test: ``` 127.0.0.1:6379> get test ``` You should see the following output: ``` "How Are You" ``` After testing successfully, exit from the Redis command-line with the following command: ``` 127.0.0.1:6379> exit ``` ## Rename Dangerous Commands It is always a good idea to rename some dangerous commands including config, shutdown, flushdb, flushall and rename. These commands can destroy or wipe your data if run by mistake. You can rename these commands by editing /etc/redis/redis.conf file: ``` nano /etc/redis/redis.conf ``` Add the following lines at the end of the file: ``` rename-command CONFIG ATLANTICCONFIG rename-command FLUSHDB ATLANTICFLUSHDB rename-command SHUTDOWN ATLANTICSHUTDOWN rename-command FLUSHALL ATLANTICFLUSHALL ``` Save and close the file, then restart Redis service to implement the changes: ``` systemctl restart redis ``` To test the above commands, enter the Redis command line: ``` redis-cli ``` Now, authenticate Redis with the password as shown below: ``` 127.0.0.1:6379> auth MGDCmmWh2Ot+aZDv7TBr54SY5PueoSAVhX41sApcOLWYBTlPrfe01OT/nqO0YWK/y0ROozsDi9Dw61jR ``` You should get the following output: ``` OK ``` Now, try to run the original CONFIG command as shown below: ``` 127.0.0.1:6379> config get requirepass ``` You should get the following error: ``` (error) ERR unknown command 'config' ``` Now, try again with the renamed command: ``` 127.0.0.1:6379> atlanticconfig get requirepass ``` You should see the following output: ``` 1) "requirepass" 2) "MGDCmmWh2Ot+aZDv7TBr54SY5PueoSAVhX41sApcOLWYBTlPrfe01OT/nqO0YWK/y0ROozsDi9Dw61jR" ``` ## Conclusion Congratulations! Your Redis server is now installed and secured. This method is compatible with Atlantic.Net [VPS Hosting](https://www.atlantic.net/vps-hosting/). For more information, you can visit the Redis [documentation](https://redis.io/documentation) page. --- # How to Install and Secure phpMyAdmin on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-secure-phpmyadmin-on-centos-8/ | Published: 2020-04-05 | Updated: 2024-07-02 | Author: Hitesh Jethva phpMyAdmin is an open-source software tool used for managing MySQL/MariaDB databases. It provides an easy way to interact with MySQL through a web browser. phpMyAdmin is very useful for users who are not comfortable administering their data from the command line, so it is essential for any system administrator to secure phpMyAdmin from different kinds of attacks. In this tutorial, we will show you how to install and secure phpMyAdmin on CentOS 8. ## Step 1 – Install Apache, MariaDB and PHP Before starting, install Apache, MariaDB, PHP and other required PHP extensions with the following command: ``` dnf update -y dnf install httpd mariadb-server php php-cli php-json php-mbstring php-pdo php-pecl-zip php-mysqlnd -y ``` After installing all the packages, you can proceed to the next step. ## Step 2 – Set MariaDB Root Password First, start the MariaDB service and enable it to start on boot time with the following command: ``` systemctl start mariadb systemctl enable mariadb ``` Next, set the MySQL root password using the following script: ``` mysql_secure_installation ``` This script will set the MySQL root password, remove anonymous users, disallow root login remotely and remove the test database and access to it, as shown below: Enter current password for root (enter for none): ``` Set root password? [Y/n] Y New password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` ## Step 3 – Install phpMyAdmin First, download the latest version of phpMyAdmin to the Apache web root directory using the following command: ``` cd /var/www/html wget https://files.phpmyadmin.net/phpMyAdmin/4.9.4/phpMyAdmin-4.9.4-all-languages.zip ``` Once downloaded, unzip the downloaded file with the following command: ``` unzip phpMyAdmin-4.9.4-all-languages.zip ``` Next, rename the extracted directory to phpmyadmin as shown below: ``` mv phpMyAdmin-4.9.4-all-languages phpmyadmin ``` Next, change the ownership of the phpmyadmin directory to the apache user: ``` chown -R apache:apache /var/www/html/phpmyadmin ``` Next, rename the config.sample.inc.php file: ``` cd /var/www/html/phpmyadmin mv config.sample.inc.php config.inc.php ``` Next, edit the file and define your secure password: ``` nano config.inc.php ``` Find the line below and update with your secure password, as shown below: ``` $cfg['blowfish_secret'] = 'your-secure-password'; ``` Save and close the file. Then, import the tables for phpMyAdmin with the following command: ``` mysql < sql/create_tables.sql -u root -p ``` Once you are done, you can proceed to the next step. ## Step 4 – Configure Apache for phpMyAdmin Next, create an Apache virtual host configuration file for phpMyAdmin: ``` nano /etc/httpd/conf.d/phpmyadmin.conf ``` Add the following lines: ``` Alias /phpmyadmin /var/www/html/phpmyadmin   AddDefaultCharset UTF-8        # Apache 2.4          Require all granted             # Apache 2.2     Order Deny,Allow     Deny from All     Allow from 127.0.0.1     Allow from ::1         # Apache 2.4           Require all granted               # Apache 2.2     Order Deny,Allow     Deny from All     Allow from 127.0.0.1     Allow from ::1   ``` Save and close the file. Then, start the Apache service and enable it to start after system reboot with the following command: ``` systemctl start httpd systemctl enable httpd ``` Now, open your web browser and visit the URL your-server-ip/phpmyadmin. You should see the phpMyAdmin web interface in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/04/phpMyAdmin-Login.png) Log in with your MySQL credentials created earlier. ![](https://www.atlantic.net/wp-content/uploads/2020/04/phpMyAdmin-Dashboard.png) ## Step 5 – Secure phpMyAdmin In this section, we will show different ways to secure your phpMyAdmin web interface. ### Change phpMyAdmin Access Location It is a good idea to change the access URL of your phpMyAdmin interface. You can change it by editing the phpmyadmin.conf file: ``` nano /etc/httpd/conf.d/phpmyadmin.conf ``` Find the following line: ``` Alias /phpmyadmin /var/www/html/phpmyadmin ``` Replace it with the following line: ``` Alias /securelocation /var/www/html/phpmyadmin ``` Save and close the file, then restart the Apache service to implement the changes: ``` systemctl restart httpd ``` You can now access the phpMyAdmin interface using the URL: your-server-ip/securelocation. ### Allow phpMyAdmin from Specific IP It is always a good idea to allow phpMyAdmin only to be accessible from a specific IP address. To do so, open the phpmyadmin.conf file: ``` nano /etc/httpd/conf.d/phpmyadmin.conf ``` Find the following lines: ```            Require all granted     ``` Replace it with the following: ```    Require ip your-client-ip-address    Require ip ::1 ``` Save and close the file, then restart the Apache service to implement the changes: ``` systemctl restart httpd ``` Your phpMyAdmin interface is now only accessible from a specified IP address. ### Password Protect phpMyAdmin Interface You can also add an extra layer of password protection on phpMyAdmin by setting up basic authentication. First, create an authentication file using the following command: ``` htpasswd -c /etc/httpd/.htpasswd phpadmin ``` Provide a secure password as shown below: ``` New password: Re-type new password: Adding password for user phpadmin ``` Next, create the .htaccess file within the phpmyadmin directory: ``` nano /var/www/html/phpmyadmin/.htaccess ``` Add the following lines: ``` AuthType basic AuthName "Authentication Required" AuthUserFile /etc/httpd/.htpasswd Require valid-user ``` Save and close the file when you are finished. Next, edit the phpmyadmin.conf file and configure Apache to use the .htpasswd file. ``` nano /etc/httpd/conf.d/phpmyadmin.conf ``` Add the following lines below the line “AddDefaultCharset UTF-8”: ```     AllowOverride All ``` Save the file, then restart the Apache service to implement the changes: ``` systemctl restart httpd ``` ## Step 6 – Test phpMyAdmin At this point, the phpMyAdmin interface is secured with an extra layer of password protection. To test it, open your web browser and type the URL http://your-server-ip/securelocation. You will be asked to provide the login credentials that we created earlier: ![](https://www.atlantic.net/wp-content/uploads/2020/04/phpMyAdmin-Password.png) Type your username and password and click on the **OK** button. You will be redirected to the phpMyAdmin login page: ![](https://www.atlantic.net/wp-content/uploads/2020/04/phpMyAdmin-Login.png) Provide your MySQL username and password, then click on the **Go** button. You should see your phpMyAdmin web interface in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/04/phpMyAdmin-Dashboard.png) ## Conclusion In the above guide, we learned how to install and secure phpMyAdmin on CentOS 8. Your phpMyAdmin interface is now secured with additional password protection. You can use this method to secure a server under an Atlantic.Net VPS Hosting Plan. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [Virtual private servers.](https://www.atlantic.net/vps-hosting/) --- # How to Setup Password Authentication with Apache on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-setup-password-authentication-with-apache-on-ubuntu-18-04/ | Published: 2020-04-06 | Updated: 2024-07-02 | Author: Hitesh Jethva Apache webserver is free, open-source, and one of the most widely used web servers in the world. It allows you to serve the content on the web. Any user can access your application over the Internet when it is hosted on an Apache web server. In some cases, you may need to secure your application so that only authenticated users can access the application. You can protect your application at the server level using Apache htpasswd. This utility allows you to limit access to a specific website to the limited person who has the login details only. In this tutorial, we will show you how to setup password authentication with Apache on Ubuntu 18.04. ## Step 1 – Install Apache Webserver By default, the Apache webserver package is available in the Ubuntu 18.04 default repository. You can install it with the following command: ``` apt-get install apache2 apache2-utils -y ``` Once installed, start the Apache service and enable it to start after system reboot with the following command: ``` systemctl start apache2 systemctl enable apache2 ``` Now, open your web browser and navigate to the URL http://your-server-ip. You should see your default Apache web page in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Apache-Default-Page.png) ## Step 2 – Create Apache Password File First, you will need to create a password file that Apache can use to authenticate users. You can create a hidden .htpasswd file withing /etc/apache2 directory for a user named user1 using the htpasswd utility: ``` htpasswd -c /etc/apache2/.htpasswd user1 ``` Provide your desired password, as shown below: ``` New password: Re-type new password: Adding password for user user1 ``` The above command will create a .htpasswd file with user credentials. You will need to use these credentials to access your website. ## Step 3 – Create a Sample Website In this section, we will create a sample directory structure and index.html file for testing purposes. First, create a directory for your website with the following command: ``` mkdir /var/www/html/example.com ``` Next, create an index.html file inside your web directory with the following command: ``` nano /var/www/html/example.com/index.html ``` Add the following contents: ``` Password Protected Apache Website.

This website is password protected.

``` Save and close the file when you are finished. Then, change the ownership of your web directory to www-data: ``` chown -R www-data:www-data /var/www/html/example.com ``` ## Step 4 – Configure Apache Basic Authentication Next, you will need to create an Apache virtual host configuration file for your website and define basic authentication. ``` nano /etc/apache2/sites-available/example.conf ``` Add the following lines: ``` ServerAdmin webmaster@example.com ServerName  example.com DocumentRoot /var/www/html/example.com DirectoryIndex index.html ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined      AuthType Basic      AuthName "Restricted Content"      AuthUserFile /etc/apache2/.htpasswd      Require valid-user ``` Save and close the file when you are finished. A brief explanation of each directive is specified below: - **ServerAdmin**: Email address of the server admin. - **ServerName**: Domain name that the server uses to identify itself. - **DocumentRoot**: Specify the path of your application. - **DirectoryIndex**: Specify a default page to display when a directory is accessed. - **AuthType**: Type of authentication. - **AuthName**: Specify the message to appear on the password page. - **AuthUserFile**: Specify the location of the user credential file. - **Require**: Specify the users that can access this region of the server. Next, check the Apache for any syntax errors with the following command: ``` apachectl -t ``` You should get the following output: ``` Syntax OK ``` Next, enable the Apache virtual host file for your website with the following command: ``` a2ensite example.conf ``` Next, restart the Apache service to implement the changes: ``` systemctl restart apache2 ``` ## Step 5 – Verify Apache Password Authentication At this point, your website is secured with Apache basic authentication. To check it, open your web browser and type the URL http://example.com. You will be asked to provide a username and password to access your website, as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Apache-Username-Password.png) Provide your username and password and click on the **Sign in** button. You should see your website default page in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Apache-Website.png) ## Conclusion In the above guide, we learned how to create a password protected website with Apache on Ubuntu 18.04. You can now easily password protect your website with Apache – test it out today with a [VPS Hosting Plan](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! For more information, you can visit the Apache official documentation at [Apache Auth](https://httpd.apache.org/docs/2.4/howto/auth.html). --- # Install and Configure Varnish Cache with Nginx Web Server on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/install-and-configure-varnish-cache-with-nginx-web-server-on-ubuntu-18-04/ | Published: 2020-04-07 | Updated: 2023-11-27 | Author: Hitesh Jethva Varnish Cache is a free, open-source, and powerful web application accelerator designed for high-load dynamic websites. The Varnish Cache sits behind the web server and can speed up your website by a factor between about 300 and 1000 times. It can also be used as a load balancer if you are running multiple servers. Varnish Cache works by caching requested web pages in memory and serving a requested page without the delay of building content from scratch when the same information is asked for several times. In this tutorial, we will show you how to set up Varnish Cache as a proxy server for Nginx on Ubuntu 18.04 VPS. ## Step 1 – Install Varnish Cache By default, the Varnish package is available in the Ubuntu 18.04 default repository. You can install it by running the following command: ``` apt-get update -y apt-get install varnish -y ``` After successful installation, the Varnish cache service has been started automatically. You can check the status of Varnish service with the following command: ``` systemctl status varnish ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Varnish-Status.png) You can also verify the installed version of Varnish with the following command: ``` varnishd -V ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Varnish-Version.png) By default, Varnish cache is listening on port 6081 and 6082. You can verify it with the following command: ``` netstat -ant ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Varnish-Listening-Port.png) ## Step 2 – Install and Configure Nginx In this section, we will install and configure Nginx to sit behind the Varnish cache server. By default, Nginx runs on port 80, so you will need to configure the Nginx to listen on port 8088. First, install the Nginx web server with the following command: ``` apt-get install nginx -y ``` After installing the Nginx web server, edit the Nginx default virtual host configuration file: ``` nano /etc/nginx/sites-available/default ``` Change the default port from 80 to 8088, as shown below: ``` server {        listen 8088 default_server;        listen [::]:8088 default_server;        root /var/www/html;        index index.html index.htm index.nginx-debian.html;        server_name _;        location / {                try_files $uri $uri/ =404;        } } ``` Note : Ensure you have deleted or commented out all of the default entries in the files, make sure only the above content is saved. Failure to do this will result in the nginx service refusing to start Save and close the file when you are finished. Then, restart the Nginx service to apply the configuration: ``` systemctl restart nginx ``` ## Step 3 – Configure Varnish Cache Next, you will need to configure Varnish to use port 80 so it can route traffic to the Nginx web server via the Varnish cache server. You can do it by editing the file /lib/systemd/system/varnish.service: ``` nano /lib/systemd/system/varnish.service ``` Change the Varnish default port from 6081 to 80 as shown below: ``` [Unit] Description=Varnish HTTP accelerator Documentation=https://www.varnish-cache.org/docs/4.1/ man:varnishd [Service] Type=simple LimitNOFILE=131072 LimitMEMLOCK=82000 ExecStart=/usr/sbin/varnishd -j unix,user=vcache -F -a :80 -T localhost:6082 -f /etc/varnish/default.vcl -S /etc/varnish/secret -s malloc,256m ExecReload=/usr/share/varnish/varnishreload ProtectSystem=full ProtectHome=true PrivateTmp=true PrivateDevices=true [Install] WantedBy=multi-user.target ``` Save and close the file when you are finished. Then, reload systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, you will need to configure Nginx as a backend server for Varnish. You can do it by editing the file /etc/varnish/default.vcl: ``` nano /etc/varnish/default.vcl ``` Change the port from 8080 to 8088, as shown below: ``` backend default {    .host = "127.0.0.1";    .port = "8088"; } ``` Save and close the file when you are finished. **Note**: Replace 127.0.0.1 with your Nginx server IP address if your Nginx web server is installed on the other host. Finally, restart the Varnish cache server with the following command: ``` systemctl restart varnish ``` ## Step 4 – Verify Varnish Cache Server At this point, the Varnish cache is configured to work with the Nginx web server. It’s time to test it. You can check the Varnish cache with the curl command as shown below: ``` curl -I your-server-ip ``` You should get the following output: ``` HTTP/1.1 200 OK Server: nginx/1.14.0 (Ubuntu) Date: Sun, 01 Dec 2019 06:46:18 GMT Content-Type: text/html Last-Modified: Sun, 01 Dec 2019 06:41:28 GMT ETag: W/"5de36098-264" Vary: Accept-Encoding X-Varnish: 32770 3 Age: 17 Via: 1.1 varnish (Varnish/5.2) Accept-Ranges: bytes Connection: keep-alive ``` The above output clearly indicates that you are using Nginx server with Varnish Cache. You can also verify Varnish caching statistics with the following command: ``` varnishstat ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Varnish-Caching-Statistics.png) You can also see Varnish log entry ranking with the following command: ``` varnishtop ``` Output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Varnish-Log-Entry-Ranking.png) If you have any issues with the Varnish cache, you can check the Varnish log with the following commands: ``` tail -f varnishncsa.log ``` ## Conclusion Congratulations! You have successfully installed and configured the Varnish Cache server with Nginx on Ubuntu 18.04 [VPS](https://www.atlantic.net/vps-hosting/). You can refer to the [Varnish documentation](https://varnish-cache.org/docs/) to optimize your configuration per your needs. --- # How to Install Webmin on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-webmin-on-ubuntu-18-04/ | Published: 2020-04-08 | Updated: 2023-11-18 | Author: Hitesh Jethva Webmin is a free and open-source web-based control panel for the Linux operating system. It is specifically designed for those who are unable to manage Linux servers from the command-line interface. Webmin allows you to manage users and groups, share files and folders, configure a web server, DNS, SSH, and FTP, install and update packages, create and manage databases, and start and stop services, all using a web-based interface. Webmin is written in Perl language and runs as its own process and web server. It also allows you to control many Linux machines through a single interface. In this tutorial, we will describe how to install Webmin on Ubuntu 18.04 server. We will also configure Apache as a reverse proxy for Webmin. ## Step 1 – Install Webmin By default, Webmin is not available in the Ubuntu 18.04 default repository. You can install it by adding the Webmin repository in your system. First, install the required packages with the following command: ``` apt-get install software-properties-common apt-transport-https wget -y ``` Next, download and add the Webmin GPG key with the following command: ``` wget -q http://www.webmin.com/jcameron-key.asc -O- | apt-key add - ``` Next, add the Webmin repository with the following command: ``` add-apt-repository "deb [arch=amd64] http://download.webmin.com/download/repository sarge contrib" ``` Once the repository is added, run the following command to install Webmin in your system: ``` apt-get install webmin -y ``` Once Webmin has been installed successfully, you should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Webmin-Install.png) You cal also verify the status of the Webmin service with the following command: ``` systemctl status webmin ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Webmin-Status.png) At this point, Webmin is installed and listening on port 10000. ## Step 2 – Configure Apache as a Reverse Proxy For Webmin In this section, we will configure the Apache as a reverse proxy for Webmin so you can access Webmin without specifying the port (10000). To do so, first install the Apache webserver with the following command: ``` apt-get install apache2 apache2-utils -y ``` After installing the Apache server, you will need to configure Webmin to disable SSL. You can disable SSL by editing the file /etc/webmin/miniserv.conf: ``` nano /etc/webmin/miniserv.conf ``` Change the SSH value from 1 to 0, as shown below: ``` ssl=0 ``` Save and close the file. Next, you will need to add your domain name to the list of allowed domains. You can add your domain by editing the file /etc/webmin/config: ``` nano /etc/webmin/config ``` Add the following line at the end of the file: ``` referers=webmin.example.com ``` Save and close the file when you are finished. Then, restart the Webmin service to implement the changes: ``` systemctl restart webmin ``` Next, you will need to create an Apache virtual host configuration file to serve Webmin. You can create it using the following command: ``` nano /etc/apache2/sites-available/webmin.conf ``` Add the following lines: ```        ServerAdmin admin@example.com        ServerName webmin.example.com        ProxyPass / http://localhost:10000/        ProxyPassReverse / http://localhost:10000/ ``` Save and close the file, then enable the virtual host and proxy module with the following command: ``` a2ensite webmin a2enmod proxy_http ``` Finally, restart the Apache service to implement the changes: ``` systemctl restart apache2 ``` ## Step 3 – Access Webmin Interface Now, open your web browser and type the URL **http://webmin.example.com**. You will be redirected to the Webmin login page: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Webmin-Login.png) Provide your system root username and password and click on the **Sign** **in** button. You should see the Webmin dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Webmin-Dashboard.png) To access the file manager, click on the **Others => File Manager**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Webmin-File-Manager.png) From here, you can manage files and directory through a web-based interface. To access the password manager page, click on the **System => Change Passwords**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Webmin-Passwords.png) From here, you can change any user’s password easily. ## Conclusion Congratulations! You have successfully installed and configured Webmin on Ubuntu 18.04 server. You can now manage your Linux system easily through a web-based interface from the remote location. Test it today with a [VPS Hosting](https://www.atlantic.net/vps-hosting/) package from Atlantic.Net! --- # How to Install PostgreSQL Server on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-postgresql-server-on-centos-8/ | Published: 2020-04-14 | Updated: 2023-11-26 | Author: Hitesh Jethva PostgreSQL is a free and open-source object-relational database management system. PostgreSQL was developed by the PostgreSQL Global Development Group and is available for various platforms, including Linux, Microsoft Windows, and Mac OS X. PostgreSQL is known for its robustness, high availability, data integrity, reliability and ease of installation. PostgreSQL comes with many advanced features that allow you to build complex applications. PostgreSQL supports many programming languages including Java, Python, Ruby, Perl, PHP and pgSQL. It also offers several library interfaces including JDBC, ODBC, OCI, libpq, C/C+, PHP, .NET, Perl, Qt and many more. If you are looking for enterprise-class database solutions, then PostgreSQL is the best choice for you. In this tutorial, we will explain how to install the PostgreSQL server on CentOS 8. ## Step 1 – Install PostgreSQL 12 By default, the latest version of PostgreSQL is not available in CentOS 8 default repository, so you will need to add the PostgreSQL repository to your system. You can add it with the following command: ``` dnf update -y dnf install https://download.postgresql.org/pub/repos/yum/reporpms/EL-8-x86_64/pgdg-redhat-repo-latest.noarch.rpm -y ``` Next, disable the built-in PostgreSQL module by running the following command: ``` dnf -qy module disable postgresql ``` Next, install PostgreSQL 12 with the following command: ``` dnf install postgresql12 postgresql12-server -y ``` Once the PostgreSQL server has been installed, you can proceed to the next step. ## Step 2 – Manage PostgreSQL Service First, initialize the PostgreSQL database with the following command: ``` /usr/pgsql-12/bin/postgresql-12-setup initdb ``` You should get the following output: ``` Initializing database ... OK ``` Next, start the PostgreSQL service and enable it to start after system reboot with the following command: ``` systemctl start postgresql-12 systemctl enable postgresql-12 ``` You can check the status of the PostgreSQL service with the following command: ``` systemctl status postgresql-12 ``` You should see the following output: ``` ● postgresql-12.service - PostgreSQL 12 database server   Loaded: loaded (/usr/lib/systemd/system/postgresql-12.service; enabled; vendor preset: disabled)   Active: active (running) since Sun 2020-03-22 11:33:01 EDT; 26s ago     Docs: https://www.postgresql.org/docs/12/static/ Main PID: 27099 (postmaster)    Tasks: 8 (limit: 12537)   Memory: 17.4M   CGroup: /system.slice/postgresql-12.service           ├─27099 /usr/pgsql-12/bin/postmaster -D /var/lib/pgsql/12/data/           ├─27102 postgres: logger             ├─27104 postgres: checkpointer             ├─27105 postgres: background writer             ├─27106 postgres: walwriter             ├─27107 postgres: autovacuum launcher             ├─27108 postgres: stats collector             └─27109 postgres: logical replication launcher   Mar 22 11:33:01 centos8 systemd[1]: Starting PostgreSQL 12 database server... ``` You can also check the PostgreSQL service with the following command: ``` netstat -antup | grep 5432 ``` You should see the following output: ``` tcp        0      0 127.0.0.1:5432      0.0.0.0:*               LISTEN      30317/postmaster ``` ## Step 3 – Set PostgreSQL Admin Password During the PostgreSQL installation, a new user called postgres is created without a password. It is recommended to set a PostgreSQL password for security reasons. To set a password, log in to the postgres user with the following command: ``` su - postgres ``` Next, set a new password with the following command: ``` psql -c "alter user postgres with password 'password'" ``` Next, exit from the PostgreSQL shell with the following command: ``` exit ``` ## Step 4 – Configure PostgreSQL Server for Remote Access By default, PostgreSQL is configured to listen on the localhost so that only local applications can connect to the database server, restricting external applications from connecting to the database. You can configure PostgreSQL server for remote connection by editing postgresql.conf file: ``` nano /var/lib/pgsql/12/data/postgresql.conf ``` Find and change the listen_addresses value to * as shown below: ``` listen_addresses = '*' ``` Save and close the file. Then, you will also need to configure PostgreSQL to accept remote connections. You can do it by editing pg_hba.conf file: ``` nano /var/lib/pgsql/12/data/pg_hba.conf ``` Find the following line: ``` host all all 127.0.0.1/32 ident ``` Replace it with the following line: ``` host all all 0.0.0.0/0 md5 ``` Save and close the file when you are finished. Then, restart the PostgreSQL service to apply the changes: ``` systemctl restart postgresql-12 ``` Next, you can verify the PostgreSQL listening connection with the following command: ``` netstat -antup | grep 5432 ``` You should see the following output: ``` tcp        0      0 0.0.0.0:5432            0.0.0.0:*               LISTEN      21603/postmaster    tcp6       0      0 :::5432                 :::*                    LISTEN      21603/postmaster ``` Next, go to the remote machine and run the following command to verify the PostgreSQL connection: ``` psql -h your-server-ip -p 5432 -U postgres -W ``` You will be asked to provide your Postgres password: ``` Password for user postgres: ``` Provide your password and hit Enter. Once the connection has been established, you should see the following output: ``` psql (9.3.24, server 12.2) WARNING: psql major version 9.3, server major version 12.         Some psql features might not work. Type "help" for help. postgres=# ``` ## Conclusion Congratulations! You have successfully installed PostgreSQL 12 on CentOS 8. You can now host any application and use PostgreSQL as a database backend – try it out today on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! For more information, visit the PostgreSQL official documentation at [Postgres Doc](https://www.postgresql.org/docs/). --- # How to Install R on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-r-on-ubuntu-18-04/ | Published: 2020-04-15 | Updated: 2023-11-26 | Author: Hitesh Jethva R is an open-source programming language that can be used to develop statistical software and perform data analysis. R is a GNU project and very similar to the S language. It is mainly used by data analysts, researchers, statisticians and marketers to retrieve, analyze, visualize and present the data. R also offers many packages for specific areas of study, making it easy to find applications in different fields. R can be run on various operating systems including Linux, Windows and MacOS. In this tutorial, we will show you how to install and use R programming language on Ubuntu 18.04. ## Step 1 – Install R Programming Language By default, R is not available in the Ubuntu 18.04 default repository, so you will need to add CRAN repositories in order to install the latest version of R on your system. First, install the required packages by running the following command: ``` apt-get update -y apt-get install apt-transport-https software-properties-common -y ``` Next, download and add the GPG key with the following command: ``` apt-key adv --keyserver keyserver.ubuntu.com --recv-keys E298A3A825C0D65DFD57CBB651716619E084DAB9 ``` You should get the following output: ``` Executing: /tmp/apt-key-gpghome.mOaFpZLCLj/gpg.1.sh --keyserver keyserver.ubuntu.com --recv-keys E298A3A825C0D65DFD57CBB651716619E084DAB9 gpg: key 51716619E084DAB9: public key "Michael Rutter " imported gpg: Total number processed: 1 gpg:               imported: 1 ``` Next, add the CRAN repository with the following command: ``` add-apt-repository 'deb https://cloud.r-project.org/bin/linux/ubuntu bionic-cran35/' ``` Once the repository has been added, update the repository and install R with the following command: ``` apt-get update -y apt-get install r-base -y ``` After installing R, you can verify the R version with the following command: ``` R --version ``` You should see the following output: ``` R version 3.6.3 (2020-02-29) -- "Holding the Windsock" Copyright (C) 2020 The R Foundation for Statistical Computing Platform: x86_64-pc-linux-gnu (64-bit) R is free software and comes with ABSOLUTELY NO WARRANTY. You are welcome to redistribute it under the terms of the GNU General Public License versions 2 or 3. For more information about these matters see https://www.gnu.org/licenses/. ``` ## Step 2 – Use R Programming Language You can open the R console as root with the following command: ``` sudo -i R ``` You should get the following output: ``` R version 3.6.3 (2020-02-29) -- "Holding the Windsock" Copyright (C) 2020 The R Foundation for Statistical Computing Platform: x86_64-pc-linux-gnu (64-bit) R is free software and comes with ABSOLUTELY NO WARRANTY. You are welcome to redistribute it under certain conditions. Type 'license()' or 'licence()' for distribution details.   Natural language support but running in an English locale R is a collaborative project with many contributors. Type 'contributors()' for more information and 'citation()' on how to cite R or R packages in publications. Type 'demo()' for some demos, 'help()' for on-line help, or 'help.start()' for an HTML browser interface to help. Type 'q()' to quit R. > ``` Next, check the default packages installed with R using the following command: ``` > getOption("defaultPackages") ``` You should see the following output: ``` [1] "datasets"  "utils"     "grDevices" "graphics"  "stats"     "methods" ``` You can also list all available packages with the following command: ``` > (.packages(all.available=TRUE)) ``` You should get the following output: ```  [1] "backports"  "base64url"  "filelock"   "R6"         "txtq"      [6] "base"       "boot"       "class"      "cluster"    "codetools" [11] "compiler"   "datasets"   "foreign"    "graphics"   "grDevices" [16] "grid"       "KernSmooth" "lattice"    "MASS"       "Matrix"   [21] "methods"    "mgcv"       "nlme"       "nnet"       "parallel" [26] "rpart"      "spatial"    "splines"    "stats"      "stats4"   [31] "survival"   "tcltk"      "tools"      "utils"     > ``` You can also use the library() command to list all available packages with a short description: ``` > library() ``` Output: ``` Packages in library ‘/usr/lib/R/library’: base                    The R Base Package boot                    Bootstrap Functions (Originally by Angelo Canty                        for S) class                   Functions for Classification cluster                 "Finding Groups in Data": Cluster Analysis                        Extended Rousseeuw et al. codetools               Code Analysis Tools for R compiler                The R Compiler Package datasets                The R Datasets Package foreign                 Read Data Stored by 'Minitab', 'S', 'SAS',                       'SPSS', 'Stata', 'Systat', 'Weka', 'dBase', ... graphics                The R Graphics Package grDevices               The R Graphics Devices and Support for Colours                        and Fonts grid                    The Grid Graphics Package KernSmooth              Functions for Kernel Smoothing Supporting Wand                        & Jones (1995) lattice                 Trellis Graphics for R MASS                    Support Functions and Datasets for Venables and                        Ripley's MASS Matrix                  Sparse and Dense Matrix Classes and Methods methods                 Formal Methods and Classes mgcv                    Mixed GAM Computation Vehicle with Automatic                        Smoothness Estimation nlme                    Linear and Nonlinear Mixed Effects Models nnet                    Feed-Forward Neural Networks and Multinomial ``` You can exit from the R console with the following command: ``` > quit() ``` ## Step 3 – Install R Packages from the Console You can also install R packages within the R console.  First, log in to the R console as a root with the following command: ``` sudo -i R ``` Next, install the txtq package using the following command: ``` > install.packages("txtq") ``` You should get the following output: ``` Installing package into ‘/usr/local/lib/R/site-library’ (as ‘lib’ is unspecified) trying URL 'https://cloud.r-project.org/src/contrib/txtq_0.2.0.tar.gz' Content type 'application/x-gzip' length 10536 bytes (10 KB) ================================================== downloaded 10 KB * installing *source* package ‘txtq’ ... ** package ‘txtq’ successfully unpacked and MD5 sums checked ** using staged installation ** R ** inst ** byte-compile and prepare package for lazy loading ** help *** installing help indices ** building package indices ** testing if installed package can be loaded from temporary location ** testing if installed package can be loaded from final location ** testing if installed package keeps a record of temporary installation path * DONE (txtq) The downloaded source packages are in            ‘/tmp/RtmpHfzZs1/downloaded_packages’ > ``` You can also remove the installed package with the following command: ``` > remove.packages("txtq") ``` ## Step 4 – Install R Packages from Linux CLI You can also install the R packages using the command-line interface. **NOTE**: If you are still on the R CLI, press **CTRL D**and select **no**when prompted to save the workspace. First, download the txtq package from the CRAN website with the following command: ``` wget -q https://cran.r-project.org/src/contrib/txtq_0.2.0.tar.gz ``` Once downloaded, you can install it with the following command: ``` sudo R CMD INSTALL txtq_0.2.0.tar.gz ``` Once installed, you should see the following output: ``` * installing to library ‘/usr/local/lib/R/site-library’ * installing *source* package ‘txtq’ ... ** package ‘txtq’ successfully unpacked and MD5 sums checked ** using staged installation ** R ** inst ** byte-compile and prepare package for lazy loading ** help *** installing help indices ** building package indices ** testing if installed package can be loaded from temporary location ** testing if installed package can be loaded from final location ** testing if installed package keeps a record of temporary installation path * DONE (txtq) ``` ## Conclusion That’s it for now. I hope you now have enough understanding of how to install and use R on the Ubuntu 18.04 server. You can now use it to build a statistical software using R programming language on your [VPS from Atlantic.Net](https://www.atlantic.net/vps-hosting/). --- # Managing Dedicated Hosts > URL: https://www.atlantic.net/vps-hosting/managing-dedicated-hosts/ | Published: 2020-04-17 | Updated: 2026-03-04 | Author: Josh Simon ## Introduction [Dedicated Hosts](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) are private computing nodes that are fully dedicated to a single customer’s use with no shared resources or noisy neighbors. This service is ideal for any customer that has a growing need for powerful infrastructure, security, compliance, or is looking for the flexibility and cost-effectiveness that comes with having their own computing infrastructure. **Dedicated Host highlights** Fully dedicated and private environment for your use with no shared resources and no noisy neighbors. Self-service ability to add and remove Dedicated Hosts on-demand or opt for a discount with the selection of a 1 or 3-year term. View and manage RAM, CPU, and Disk space in use. Freedom and flexibility to provision any Cloud Server plan type. Complete control to create, manage and remove Cloud Server on your [Dedicated Host](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/). The environment is ready to help you meet your compliance and regulatory requirements.   ## **What you will learn in this guide** Adding a Dedicated Host Viewing an Overview of your Dedicated Hosts Viewing the Details of a Dedicated Host Enable or Disable the ability to host Windows Cloud Servers on your Dedicated Host Delete a Dedicated Host Creating a Cloud Server on a Dedicated Host Determining if a Cloud Server is on a Dedicated Host or the Public Cloud   ## Adding a Dedicated Host In the Atlantic.Net Control Panel, click on “Dedi Hosts” in the navigation menu on the left side of the page. ![](https://www.atlantic.net/wp-content/uploads/2020/04/dedi_menu_nav.png)   From the Dedicated Host page click the “Add Dedicated Hosts” button to go to the Add Dedicated Host page. On the Add Dedicated Host page, a customer will choose a display name for the Dedicated Host, location, term, plan, and whether they want the Dedicated Host to be able to host Windows Servers. ![](https://www.atlantic.net/wp-content/uploads/2020/04/add_dedi-1.png)   ## Viewing an Overview of your Dedicated Hosts In the Atlantic.Net Control Panel, click on “Dedi Hosts” in the navigation menu on the left side of the page. ![](https://www.atlantic.net/wp-content/uploads/2020/04/dedi_menu_nav.png)   You will now be presented with a list of your Dedicated Hosts and an overview of the host resources and server count on that host. ![](https://www.atlantic.net/wp-content/uploads/2020/04/Screenshot-from-2020-04-15-19-32-41.png)   ## Viewing the Details of a Dedicated Host On the Dedicated Hosts page, click on the “Description” field in the list of your Dedicated Hosts and you will be presented with an overview of the host resources, server count, and list of Cloud Servers that reside on the host. ![](https://www.atlantic.net/wp-content/uploads/2020/04/dedi_info.png) ## Enable or Disable the ability to host Windows Cloud Servers on your Dedicated Host   #### **Add Support for Windows Servers** Click the Manage button and then click “Add Windows Licensing” ![](https://www.atlantic.net/wp-content/uploads/2020/04/add_dedi_win.png)   #### Remove Support for Windows Servers Click the Manage button and then click “Remove Windows Licensing” Note: You must remove any Windows Servers deployed on your Dedicated Host before you can remove Windows Licensing from your Dedicated Host. ![](https://www.atlantic.net/wp-content/uploads/2020/04/remove_dedi_win.png)   ## Delete a Dedicated Host Click the Manage button and then click Delete Host Note: If a user attempts to delete a Dedicated Host that still has an active non-expired term commitment, they will receive an error message stating they can not remove the Dedicated Host until the term commitment ends. Note: If a user attempts to delete a Dedicated Host that still has Cloud Servers deployed they will receive an error message stating they can not remove the Dedicated Host until all Cloud Servers are removed from the Host. ![](https://www.atlantic.net/wp-content/uploads/2020/04/delete_dedi.png)   ## Creating a Cloud Server on a Dedicated Host You can create a new Cloud Server on a Dedicated Host from the Dedicated Host Details page or from the Add Server page.   #### From the Add Server Page In the Atlantic.Net Control Panel, click on “Servers”, then click the “Add Server” button. Next, select your desired [Dedicated Host](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) in the “Public or Dedicated Host” section of the page. You will then proceed to select the same remaining options as you normally would when building a Cloud Server.   **From the Dedicated Host Details Page** In the Atlantic.Net Control Panel, click on “Dedi Hosts”, then click on the “Description” of the Dedicated Host you want to create the Cloud Server on, and then click on the “Add Server” button. Next, select your desired Dedicated Host in the “Public or Dedicated Host” section of the page. You will then proceed to select the same remaining options as you normally would when building a Cloud Server. ![](https://www.atlantic.net/wp-content/uploads/2020/04/Screenshot-from-2020-04-15-19-34-29-804x1024-1.png) ## Determining if a Cloud Server is on a Dedicated Host or the Public Cloud From your list of Cloud Servers, click on the name of the desired Cloud Server. You will then view the value of the “Host Type” field. This field will either display the Dedicated Host where the Cloud Server resides or state it resides on the Public Cloud ![](https://www.atlantic.net/wp-content/uploads/2020/04/Screenshot-from-2020-04-15-20-45-11.png)   ## Want to learn more about Dedicated Hosts? Learn more about our [Dedicated Hosting](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) by visiting our [Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/) page or email us at sales@atlantic.net. --- # How to Install Yarn on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-yarn-on-centos-8/ | Published: 2020-04-20 | Updated: 2023-11-26 | Author: Hitesh Jethva Yarn is an advanced package management tool released by Facebook for JavaScript applications. Yarn is mostly used for Node.js applications and is compatible with npm, meaning it can install, remove, configure and update npm packages. It was specially designed to speed up package installation process. In this guide, we will explain different ways to install Yarn on CentOS 8. ## Step 1 – Install Yarn ### Install Yarn with NPM You can install Yarn with NPM “Node Package Manager.” First, install Node.js with the following command: ``` dnf update -y dnf install @nodejs -y ``` Once installed, you can install the Yarn package globally using the following command: ``` npm install yarn -g ``` Once installed, you should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Yarn-NPM.png) You can now verify the version of Yarn with the following command: ``` yarn -v ``` You should see the following output: ``` 1.22.4 ``` ### Install Yarn with Script The simplest and easiest way to install Yarn is to install it from the script available at the Yarn official website. You can install download and run the Yarn installation script with the following command: ``` curl -o- -L https://yarnpkg.com/install.sh | bash ``` Once the installation has been finished, you should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Yarn-Script.png) **Note**: This script will install Yarn only for the current user. Next, activate the PATH environment variable for Yarn with the following command: ``` source ~/.bashrc ``` Next, verify the Yarn version with the following command: ``` yarn -v ``` You should see the following output: ``` 1.22.4 ``` ### Install Yarn from Repository You can also install Yarn from the official repository. First, add the Yarn repository with the following command: ``` curl --silent --location https://dl.yarnpkg.com/rpm/yarn.repo | tee /etc/yum.repos.d/yarn.repo ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Yarn-Repository.png) Next, import the Yarn GPG key with the following command: ``` rpm --import https://dl.yarnpkg.com/rpm/pubkey.gpg ``` Finally, install Yarn by running the following command: ``` dnf install yarn -y ``` Next, verify the Yarn version with the following command: ``` yarn -v ``` You should see the following output: ``` 1.22.4 ``` ## Step 2 – Yarn Basic Command-line Usage In this section, we will show some basic commands to create and manage the Yarn project. To create a new Yarn project, run the following command: ``` yarn init projectname ``` This will create a package.json for your project. You can now initiate a Yarn project in your current working directory with the following command: ``` yarn init ``` To install all the dependencies for your project specified in the package.json, run the following command: ``` yarn install ``` To add any package as a dependency in your project, run the following command: ``` yarn add packagename ``` To update any package dependencies, run the following command: ``` yarn upgrade packagename ``` To remove any package from the dependencies, run the following command: ``` yarn remove packagename ``` ## Conclusion Congratulations! You have successfully installed Yarn on CentOS 8. You can now use your desired method to install Yarn in your system – try it today using your Atlantic.Net [VPS Hosting](https://www.atlantic.net/vps-hosting/). For more information, visit the Yarn official [documentation page](https://yarnpkg.com/lang/en/docs/). --- # How to Set Up GitLab on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-set-up-gitlab-on-centos-8/ | Published: 2020-04-30 | Updated: 2024-06-30 | Author: Hitesh Jethva GitLab is a free, open-source, web-based version control platform that allows you to manage all your Git repositories from the centralized server. GitLab is a great alternative to Github, offering very useful features including code review, issue management, repository branching, merging, time tracking, and continuous integration and deployment. GitLab is specially designed for developers to create, review, and deploy their projects. GitLab is available in three different editions: Community Edition (CE), Enterprise Edition (EE), and a GitLab-hosted version. You can install any of them depending on the requirements of your use case. In this tutorial, we will show you how to install GitLab CE on CentOS 8. Next, you will need to install some required dependencies on your system. You can install all of them with the following command: ``` dnf install curl policycoreutils python3-policycoreutils -y ``` ## Step 1 – Install GitLab CE By default, GitLab is not available in the CentOS 8 default repository, so you will need to add the GitLab repository in your system. You can install it with the following command: ``` curl -s https://packages.gitlab.com/install/repositories/gitlab/gitlab-ce/script.rpm.sh | bash ``` Once the repository is added, you should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Gitlab-Repository.png) Next, install GitLab CE by running the following command: ``` dnf install gitlab-ce -y ``` Once the installation has been completed successfully, you can proceed to the next step. ## Step 2 – Secure GitLab with Let’s Encrypt Next, you will need to set the GitLab URL and enable Let’s Encrypt integration. You can do it by editing the file /etc/gitlab/gitlab.rb: ``` nano /etc/gitlab/gitlab.rb ``` Change the following lines that match your domain name and enable Let’s Encrypt integration with your desired value: ``` external_url 'https://gitlab.example.com' letsencrypt['enable'] = true letsencrypt['contact_emails'] = ['admin@example.com']  letsencrypt['auto_renew'] = true letsencrypt['auto_renew_hour'] = 12 letsencrypt['auto_renew_minute'] = 15 letsencrypt['auto_renew_day_of_month'] = "*/4" ``` Save and close the file when you are finished. Then, reconfigure GitLab CE with the following command: ``` gitlab-ctl reconfigure ``` This command will reconfigure GitLab and secure it with Let’s Encrypt SSL. Once the GitLab setup has been completed successfully, you should get the following output: ```   * execute[reload prometheus] action run    - execute /opt/gitlab/bin/gitlab-ctl hup prometheus Recipe: monitoring::alertmanager * runit_service[alertmanager] action restart (up to date) Recipe: monitoring::postgres-exporter * runit_service[postgres-exporter] action restart (up to date) Recipe: monitoring::grafana * runit_service[grafana] action restart (up to date) Recipe: nginx::enable * execute[reload nginx] action run    - execute gitlab-ctl hup nginx Recipe: letsencrypt::enable * ruby_block[display_le_message] action run    - execute the ruby block display_le_message Recipe: crond::enable * runit_service[crond] action restart (up to date) Running handlers: Running handlers complete Chef Client finished, 609/1641 resources updated in 10 minutes 43 seconds Warnings: Environment variable LANG specifies a non-UTF-8 locale. GitLab requires UTF-8 encoding to function properly. Please check your locale settings. gitlab Reconfigured! ``` ## Step 3 – Access GitLab Web UI At this point, GitLab is installed and configured, and you can now access the GitLab UI by visiting the URL https://gitlab.example.com. You will be redirected to the password change screen as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Gitlab-Password-Change.png) Set the new password for the root user and click on the **Change** **your** **password** button. Once the password is changed successfully, you should see the GitLab login screen: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Gitlab-Login.png) Enter root as your username, your specified password, and click on the **Sign** **in** button. You should see the GitLab dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Gitlab-Dashboard.png) ## Step 4 – Disable User Sign Up By default, GitLab allows new users to sign up, which is very dangerous for security reasons. It is recommended to disable user registration on the GitLab welcome page. To disable User Sign Up, click on the **Admin** area as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Gitlab-Admin.png) Now, click on **Settings** in the left pane. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Gitlab-Settings.png) Next, **Expand** the Sign-up restrictions. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Gitlab-Signup-Restriction.png) Next, uncheck Sign-up enabled button to disable User registration on the GitLab welcome page and click on the **Save** **Changes** button. Next, log out of your GitLab dashboard. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/04/Gitlab-Login-No-Register.png) As you can see, the tab for user registration is missing. ## Step 5 – Automate GitLab Backup You can take a complete backup of GitLab data with the following command: ``` gitlab-rake gitlab:backup:create ``` This command will take a complete backup of GitLab data and save it in the /var/opt/gitlab/backups directory. Once the backup has been completed successfully, you should get the following output: ``` 2020-03-22 10:59:34 -0400 -- Dumping database ... Dumping PostgreSQL database gitlabhq_production ... [DONE] 2020-03-22 10:59:37 -0400 -- done 2020-03-22 10:59:37 -0400 -- Dumping repositories ... 2020-03-22 10:59:38 -0400 -- done 2020-03-22 10:59:38 -0400 -- Dumping uploads ... 2020-03-22 10:59:38 -0400 -- done 2020-03-22 10:59:38 -0400 -- Dumping builds ... 2020-03-22 10:59:38 -0400 -- done 2020-03-22 10:59:38 -0400 -- Dumping artifacts ... 2020-03-22 10:59:38 -0400 -- done 2020-03-22 10:59:38 -0400 -- Dumping pages ... 2020-03-22 10:59:38 -0400 -- done 2020-03-22 10:59:38 -0400 -- Dumping lfs objects ... 2020-03-22 10:59:38 -0400 -- done 2020-03-22 10:59:38 -0400 -- Dumping container registry images ... 2020-03-22 10:59:38 -0400 -- done Creating backup archive: 1584889178_2020_03_22_12.9.0_gitlab_backup.tar ... done Uploading backup archive to remote storage  ... skipped Deleting tmp directories ... done done done done done done done done done Deleting old backups ... skipping Backup task is done. ``` It is recommended to schedule backups with Cron so that you don’t need to run backups regularly. You can schedule backups by editing the following file: nano /etc/crontab Add the following line to back up GitLab data every day at 8:00 PM: ``` 0 20 * * * gitlab-rake gitlab:backup:create ``` Save and close the file when you are finished. ## Conclusion Congratulations! You have successfully installed and configured GitLab CE on CentOS 8 server. You can now host your own repository with GitLab and start collaborating with other developers today with GitLab on a [VPS with Atlantic.Net](https://www.atlantic.net/vps-hosting/)! --- # How to Install Syncthing Cloud Sync Service on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-syncthing-cloud-sync-service-on-ubuntu-18-04/ | Published: 2020-05-01 | Updated: 2024-07-02 | Author: Hitesh Jethva Syncthing is a free and open-source file synchronization tool used to synchronize files across multiple devices. Syncthing uses peer-to-peer architecture, meaning that each device attached to your Syncthing network retains copies of the files in your shared folders and pushes new content whenever any changes have been made. Syncthing can be run on most operating systems including Linux, Windows, MacOS, FreeBSD, Solaris and OpenBSD. **Syncthing offers many features and benefits, some of which are listed below:** - Easy-to-use - Secure against attacks - Powerful and portable - Safe from data loss - Fully automatic In this tutorial, we will show you how to install and configure the Syncthing Cloud Sync service on Ubuntu 18.04. ## Prerequisites - **Two**fresh Ubuntu servers - Root passwords configured on both servers. ## Step 1 – Install Syncthing on Both Servers By default, Syncthing is not available in the Ubuntu 18.04 default repository, so you will need to add Syncthing repository in your system. First, install the required packages with the following command: ``` apt-get install curl apt-transport-https -y ``` Once installed, download and import the GPG Key for the repository with the following command: ``` curl -s https://syncthing.net/release-key.txt | apt-key add - ``` Next, add the Syncthing repository with the following command: ``` echo "deb https://apt.syncthing.net/ syncthing release" > /etc/apt/sources.list.d/syncthing.list ``` Next, update the repository and install the Syncthing service with the following command: ``` apt-get update -y apt-get install syncthing -y ``` Once installed, you can verify the installed version of Syncthing with the following command: ``` syncthing --version ``` You should get the following output: ``` syncthing v1.3.4 "Fermium Flea" (go1.13.7 linux-amd64) deb@build.syncthing.net 2020-01-14 07:01:03 UTC ``` **Note: Now repeat the process on Server 2** ## Step 2 – Create a Systemd Service File for Syncthing Next, you will need to create a systemd service file to manage the Syncthing service on both servers. On **server1**, create a systemd service file with the following command: ``` nano /etc/systemd/system/syncthing@.service ``` Add the following lines: ``` [Unit] Description=Syncthing - Open Source Continuous File Synchronization for %I Documentation=man:syncthing(1) After=network.target [Service] User=%i ExecStart=/usr/bin/syncthing -no-browser -gui-address="server1-ip-address:8384" -no-restart -logflags=0 Restart=on-failure SuccessExitStatus=3 4 RestartForceExitStatus=3 4 [Install] WantedBy=multi-user.target ``` Save and close the file when you are finished. On **server2**, create a systemd service file with the following command: ``` nano /etc/systemd/system/syncthing@.service ``` Add the following lines: ``` [Unit] Description=Syncthing - Open Source Continuous File Synchronization for %I Documentation=man:syncthing(1) After=network.target [Service] User=%i ExecStart=/usr/bin/syncthing -no-browser -gui-address="server2-ip-address:8384" -no-restart -logflags=0 Restart=on-failure SuccessExitStatus=3 4 RestartForceExitStatus=3 4 [Install] WantedBy=multi-user.target ``` Save and close the file when you are finished. Next, reload the systemd daemon and start the Syncthing service as a root user **on both servers** with the following command: ``` systemctl daemon-reload systemctl start syncthing@root ``` Next, enable the Syncthing service to start after system reboot with the following command: ``` systemctl enable syncthing@root ``` Next, verify the status of the Syncthing service with the following command: ``` systemctl status syncthing@root ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Status.png) At this point, Syncthing service is started and listening on port 8384. ## Step 3 – Access Syncthing Web Interface Now, open your web browser and access the Syncthing web UI using the URL http://server1-ip-address:8384. You will be redirected to the Syncthing web interface as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Web-Interface.png) By default, the Syncthing web interface can be accessed without username and password, so it is a good idea to set an admin user and password for Syncthing. To do so, click on the **Actions => Advanced** in the top-right pane. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Actions-Advanced.png) ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Admin-Username-Password.png) Now, provide your admin username and password and click on the **Save** button to apply the changes. You should get an authentication prompt for the username and password as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Sign-In.png) Provide your admin username and password and click on the **Sign** **in** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Signed-In.png) Do the same procedure on the second server to set the admin password. ## Step 4 – Sync Data Between Two Servers In this section, we will create a shared directory on **server1** and sync it with **server2**. ### Create a Shared Directory First, you will need to add a folder that you want to share between two servers. On the server1 dashboard, click on **Add** **Folder**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Add-Folder-1.png) ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Add-Folder-2.png) Provide your folder name, folder ID, and the path of the folder and click on the **Save** button. Once the folder has been created, you should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Folder-Created.png) ### Sync Device ID In order to get your two servers to talk to each other, you will need to exchange device IDs with other servers. First, you will need to find the device ID of the second server. On the **server2**dashboard, click on the **Actions => Show ID** to obtain Device ID as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Device-ID-1.png) ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Device-ID-2.png) On the **server1**dashboard, click on **Add Remote Device** as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Add-Remote-Device.png) Provide **server2**device ID, Device Name and click on the **Sharing** tab. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Sharing.png) Select a directory that you created earlier and click on the **Save** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Saved-Device.png) On the **Server2**dashboard, refresh the page. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-New-Device.png) Click on the **Add** **Device** button to add the Server1 device ID to Server2. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Add-Device-1.png) Click on the **Save** button to add the Server1 device ID to Server2. You will be asked whether you want to add folder shared on Server1 as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Add-Folder-3.png) Click on the **Add** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Add-Folder-4.png) Provide Folder label, Folder ID, Folder path and click on the **Save** button. You should see that **server1** has been added to **server2** in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Server-Added-1.png) On the server1 dashboard, refresh the page and you should see that server2 has been added to server1 in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Syncthing-Server-Added-2.png) At this point, both servers are connected and syncing the directory /opt/MyApp. Now, any changes made in the /opt/MyApp directory will be replicated to the other server. ## Conclusion In the above guide, you learned how to install and configure the Syncthing service on Ubuntu 18.04 server. You also learned how to sync a directory between two servers. You can now add an additional directory or server to sync. Try it today on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install MySQL 8.0 on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-mysql-8-0-on-ubuntu-18-04/ | Published: 2020-05-04 | Updated: 2023-11-24 | Author: Hitesh Jethva MySQL is a free and open-source relational database management system for Linux-based operating systems. MySQL is the most widely used database system and is used for many open-source projects and high availability systems. If your server is running the older version of MySQL 5.7, then it is recommended to install MySQL 8 to use newly released features. In this tutorial, we will explain how to install MySQL 8 on Ubuntu 18.04. ## Step 1 – Install MySQL 8 Repository By default, MySQL 8 is not available in the Ubuntu 18.04 default repository, so you will need to add the MySQL 8 repository in your system. First, download the repository package with the following command: ``` apt-get update -y wget -c https://repo.mysql.com//mysql-apt-config_0.8.13-1_all.deb ``` Once downloaded, install the downloaded package with the following command: ``` dpkg -i mysql-apt-config_0.8.13-1_all.deb ``` During the installation process, you will be asked to choose the MySQL version as shown in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/05/MySQL-8-Choose-Version.png) Scroll down, select **Ok** and hit **Enter** to finish the installation. ## Step 2 – Install MySQL 8 Next, update the repository with the following command: ``` apt-get update -y ``` Once the repository is updated, run the following command to install MySQL 8 in your system. ``` apt-get install mysql-server -y ``` During the installation process, you will be asked to set the MySQL root password as shown below: Next, you will need to select the default authentication plugin for MySQL as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/05/MySQL-8-Root-Password-1.png) ![](https://www.atlantic.net/wp-content/uploads/2020/05/MySQL-8-Root-Password-2.png) Select “**Use Strong Password Encryption**” and hit **Enter** to finish the installation. ![](https://www.atlantic.net/wp-content/uploads/2020/05/MySQL-8-Strong-Password.png) Next, you can verify the installed version of the MySQL with the following command: ``` mysql -V ``` You should get the following output: ``` mysql  Ver 8.0.19 for Linux on x86_64 (MySQL Community Server - GPL) ``` ## Step 3 – Manage MySQL Service You can manage the MySQL service with the systemctl utility. To start the MySQL service, run the following command: ``` systemctl start mysql ``` To enable the MySQL service to start after a system reboot, run the following command: ``` systemctl enable mysql ``` To check the status of the MySQL service, run the following command: ``` systemctl status mysql ``` Output: ![](https://www.atlantic.net/wp-content/uploads/2020/05/MySQL-8-Status.png) ## Step 4 – Secure MySQL Installation It is also recommended to secure the MySQL installation and set the MySQL root password. You can do it using the mysql_secure_installation script: ``` mysql_secure_installation ``` You will be asked to provide your current root MySQL password as shown below: ``` Securing the MySQL server deployment. Enter password for user root: ``` Provide your root password and hit **Enter**. You will be asked to validate the password to improve security as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/05/MySQL-8-Validate-Password.png) Type **Y** and hit **Enter** to check the password strength as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/05/MySQL-8-Check-Password-Strength.png) Here, you can select your desired password strength and hit **Enter** to continue: ``` Estimated strength of the password: 100 Change the password for root ? ((Press y|Y for Yes, any other key for No) : Y ``` Type **Y** and hit **Enter** to change the password to one with the selected password strength: ``` New password: Re-enter new password: ``` Type your new password and hit **Enter** to continue. You should see the following output: ``` Estimated strength of the password: 100 Do you wish to continue with the password provided?(Press y|Y for Yes, any other key for No) : Y ``` Type **Y** and hit **Enter** to continue with your provided password as shown below: ``` By default, a MySQL installation has an anonymous user, allowing anyone to log into MySQL without having to have a user account created for them. This is intended only for testing, and to make the installation go a bit smoother. You should remove them before moving into a production environment. Remove anonymous users? (Press y|Y for Yes, any other key for No) : Y Success. ``` Next, type **Y** and hit **Enter** to remove the anonymous user. You should see the following output: ``` Normally, root should only be allowed to connect from 'localhost'. This ensures that someone cannot guess at the root password from the network. Disallow root login remotely? (Press y|Y for Yes, any other key for No) : Y ``` Next, type **Y** and hit **Enter** to disallow root login from the remote machine. You should see the following output: ``` By default, MySQL comes with a database named 'test' that anyone can access. This is also intended only for testing, and should be removed before moving into a production environment. Remove test database and access to it? (Press y|Y for Yes, any other key for No) : Y ``` Type **Y** and hit **Enter** to remove the test database. You should see the following output: ```  - Dropping test database... Success.  - Removing privileges on test database... Success. Reloading the privilege tables will ensure that all changes made so far will take effect immediately. Reload privilege tables now? (Press y|Y for Yes, any other key for No) : Y ``` Finally, type **Y** and hit **Enter** to reload the privileges tables. ## Conclusion Congratulations! You have successfully installed and secured MySQL 8 on Ubuntu 18.04. You can now connect to MySQL and create a database, user, or table and integrate it with many applications. Get started with MySQL today on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Java on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-java-on-centos-8/ | Published: 2020-05-06 | Updated: 2024-06-11 | Author: Hitesh Jethva Java JDK is a free and open-source software development kit used for building applications, applets, and components using the Java programming language. Java JDK comes with a set of tools for developing and testing applications written in the Java programming language; these tools include JRE, Java, Javac (Compiler) and Jar (Archiver). There are two different implementations of Java, OpenJDK and Oracle JDK: - **OpenJDK** is the free and open-source implementation of the Java Platform. - **Oracle JDK** is a paid and permits only non-commercial use of the software. In this tutorial, we will show you how to install OpenJDK 8, OpenJDK 11 and Oracle Java JDK 14 on CentOS 8. ## Step 1 – Install OpenJDK 11 By default, OpenJDK 11 is available in the CentOS 8 default repository. You can install it by running the following command: ``` dnf install java-11-openjdk -y ``` Once installed, verify the installed Java version with the following command: ``` java -version ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Java-OpenJDK11-CentOS8-Version.png) ## Step 2 – Install OpenJDK 8 By default, OpenJDK 8 is available in the CentOS 8 default repository. You can install it with the following command: ``` dnf install java-1.8.0-openjdk -y ``` Once installed, verify the installed Java version with the following command: ``` java -version ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Java-OpenJDK8-CentOS8-Version.png) ## Step 3 – Set Up the Default Java Version At this point, you have two different versions of Java installed on your system. You can switch between multiple Java versions using the following command: ``` alternatives --config java ``` In the following output, you should see that OpenJDK 8 is the default version on your system. ![](https://www.atlantic.net/wp-content/uploads/2020/05/Java-OpenJDK8-Default-Version.png) Type **1** and press **Enter** to switch the Java version from OpenJDK 8 to OpenJDK 11. Now, verify the default Java version with the following command: ``` java -version ``` You should see that OpenJDK 11 is the default Java version on your system. ![](https://www.atlantic.net/wp-content/uploads/2020/05/Java-OpenJDK11-Default-Version.png) ## Step 4 – Setup JAVA_HOME Environment Variable In some Java-based applications, you will need to define the installation location of Java to specify which Java version you want to use to run the application. You can use the JAVA_HOME environment variable to define the Java installation path. You can set the JAVA_HOME environment variable for OpenJDK 11 by editing the file /etc/profile: ``` nano /etc/profile ``` Add the following line at the end of the file: ``` JAVA_HOME="/usr/lib/jvm/java-11-openjdk-11.0.5.10-2.el8_1.x86_64/" ``` Save and close the file when you are finished. Then, activate the changes with the following command: ``` source /etc/profile ``` Next, verify the JAVA_HOME environment with the following command: ``` echo $JAVA_HOME ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Java-Home.png) ## Step 5 –  Install Oracle Java 14 First, you will need to download the Oracle Java 14 RPM package file from the [Oracle download page](https://www.oracle.com/java/technologies/javase-jdk14-downloads.html), as shown below. ![](https://www.atlantic.net/wp-content/uploads/2020/05/Java-14-Download.png) Here, you can see the different versions of Java 14. Click on [jdk-14_linux-x64_bin.rpm](https://www.oracle.com/java/technologies/javase-jdk14-downloads.html#license-lightbox)  to download it in your system. You *may* now need to upload the file to your Centos8 server from your local desktop. This can be done using WinSCP. Download WinSCP and install WinSCP using the following guide: [guide install](https://winscp.net/eng/docs/guide_install) Upload the file using your CentOS 8 server information: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Java-14-File-Upload.png) ![](https://www.atlantic.net/wp-content/uploads/2020/05/Java-14-File-Upload-2.png) ![](https://www.atlantic.net/wp-content/uploads/2020/05/Java-14-File-Upload-3.png) Once the upload has completed, you can install it with the following command: ``` dnf localinstall jdk-14_linux-x64_bin.rpm -y ``` Once installed successfully, change the default Java version to Oracle Java 8 with the following command: ``` alternatives --config java ``` You should see a list of different Java versions in the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Java-Versions-List.png) Type **3** and hit **Enter** to change the default Java version. Next, verify the Java default version with the following command: ``` java -version ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Java-14-Default-Version.png) ## Conclusion Congratulations! You have successfully installed Java on CentOS 8. I hope you have now enough knowledge to switch between different Java versions and start building your application on your [virtual private server](https://www.atlantic.net/vps-hosting/). --- # How to Install Laravel Framework on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-laravel-framework-on-ubuntu-18-04/ | Published: 2020-05-08 | Updated: 2023-11-25 | Author: Hitesh Jethva Laravel is a free and open-source PHP framework that can be used to build modern, fast, and scalable web applications. Laravel comes with expressive and elegant syntax that makes it a popular framework among PHP developers. Laravel uses a model view controller architecture pattern and comes with a lot of features including pagination, a complete authentication system, a powerful ORM, sessions, caching and many more. Laravel also provides a command-line interface called Artisan that can be used for building and managing Laravel-based apps. In this tutorial, we will show you how to install Laravel Framework on Ubuntu 18.04. ## Prerequisites - A fresh Ubuntu 18.04 [VPS](https://www.atlantic.net/vps-hosting/). - A valid domain name pointed to your server. In this tutorial, we will use example.com domain. - A root password configured on your server. ## Step 1 – Install LAMP Server Laravel is based in PHP, runs on the webserver, and uses MySQL/MariaDB as a database backend, so you will need to install Apache, MariaDB, PHP and other required PHP extensions in your system. You can install all of them by just running the following command: ``` apt-get install apache2 libapache2-mod-php7.2 mariadb-server php7.2 php7.2-common php7.2-cli php7.2-gd php7.2-mysql php7.2-curl php7.2-intl php7.2-mbstring php7.2-bcmath php7.2-imap php7.2-xml php7.2-zip unzip git curl -y ``` Once all the packages are installed, you can proceed to the next step. ## Step 2 – Configure Database Before configuring the database, it is recommended to set a MySQL/MariaDB root password and secure the MariaDB installation. You can do it by running the following script: ``` mysql_secure_installation ``` Answer each question as shown below to set a root password and secure the MariaDB installation: Enter current password for root (enter for none): Just Press Enter ``` Set root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` Next, log in to the MariaDB shell with root user: ``` mysql -u root -p ``` Provide your MariaDB root password, then create a database and user for Laravel with the following command: ``` CREATE DATABASE laraveldb; GRANT ALL ON laraveldb.* to 'laravel'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from MariaDB with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install Composer Next, you will need to install Composer in your system. Composer is a PHP dependency manager used for installing PHP dependencies. First, download the Composer setup file from Composer’s website with the following command: ``` curl -sS https://getcomposer.org/installer -o composer-setup.php ``` Next, check whether the installation script is corrupt with the following command: ``` HASH="$(wget -q -O - https://composer.github.io/installer.sig)" php -r "if (hash_file('SHA384', 'composer-setup.php') === '$HASH') { echo 'Installer verified'; } else { echo 'Installer corrupt'; unlink('composer-setup.php'); } echo PHP_EOL;" ``` You should get the following output if everything is fine: ``` Installer Verified ``` Finally, run the following command to install Composer: ``` php composer-setup.php --install-dir=/usr/local/bin --filename=composer ``` You should get the following output: ``` All settings correct for using Composer Downloading... Composer (version 1.10.0) successfully installed to: /usr/local/bin/composer Use it: php /usr/local/bin/composer ``` ## Step 4 – Install Laravel Next, change the directory to the Apache web root directory and create a Laravel project named mylaravel using Composer command as shown below: ``` cd /var/www/html composer create-project --prefer-dist laravel/laravel mylaravel ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Laravel-Create-Project.png) **NOTE: If you get errors in during the installation about not enough swap file space available –**[**follow this process**](https://askubuntu.com/questions/920595/fallocate-fallocate-failed-text-file-busy-in-ubuntu-17-04)**. Make sure you run*rm -fr /var/www/html/mylaravel* if you get this error only.** ![](https://www.atlantic.net/wp-content/uploads/2020/05/Laravel-Create-Project-Error.png) After successful installation, change the directory to mylaravel and start the Laravel application: ``` cd mylaravel php artisan serve --host=your-server-ip --port=8000 ``` You should see the following output: ``` Laravel development server started: http://your-server-ip:8000 ``` Laravel is now installed and listening on port 8000. You can check it by visiting the URL http://your-server-ip-8000 in your web browser. You should get the Laravel default dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Laravel-Dashboard.png) Next, press **Ctrl + C** to stop Laravel. ## Step 5 – Configure Laravel Next, you will need to configure Laravel to use MariaDB database. You can do it by editing the .env file: ``` nano /var/www/html/mylaravel/.env ``` Change the following lines that match with your database: ``` DB_CONNECTION=mysql DB_HOST=127.0.0.1 DB_PORT=3306 DB_DATABASE=laraveldb DB_USERNAME=laravel DB_PASSWORD=password ``` Save and close the file when you are finished. Then, give proper permissions to the Laravel project directory: ``` chown -R www-data:www-data /var/www/html/mylaravel/ chmod -R 775 /var/www/html/mylaravel/ ``` Once you are done, you can proceed to the next step. ## Step 6 – Configure Apache for Laravel Next, you will need to configure an Apache virtual host configuration file to serve the Laravel project. You can create it with the following command: ``` nano /etc/apache2/sites-available/laravel.conf ``` Add the following lines: ```         ServerAdmin webmaster@example.com        DocumentRoot /var/www/html/mylaravel/public        ServerName www.example.com                       Options FollowSymLinks                AllowOverride None                              AllowOverride All                ErrorLog ${APACHE_LOG_DIR}/error.log        CustomLog ${APACHE_LOG_DIR}/access.log combined ``` Save and close the file when you are finished. Then, enable the Apache virtual host file with the following command: ``` a2ensite laravel.conf ``` Next, restart the Apache service to apply the changes: ``` systemctl restart apache2 ``` ## Step 7 – Access Laravel Dashboard Now, open your web browser and type the URL [http://example.com](http://example.com/). You will be redirected to the Laravel default dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/05/Laravel-Dashboard.png) ## Conclusion That’s it for now. You can now start creating your fast and scalable application with the Laravel framework. For more information visit the Laravel official documentation at [Laravel Doc](https://laravel.com/docs). If you’re ready to try out Laravel, [get a VPS today](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Install TimescaleDB on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-timescaledb-on-ubuntu-18-04/ | Published: 2020-05-12 | Updated: 2023-11-26 | Author: Hitesh Jethva There are two types of database systems: relational databases and NoSQL databases. Relational databases are used to store data and cannot process a large amount of time series data. NoSQL databases are especially useful for working with large sets of distributed data. TimescaleDB is a free and open-source time-series database specially designed for scale, ease-of-use, and complex queries. TimescaleDB is an extension of PostgreSQL offering the best of both NoSQL and relational database systems. You can write millions of data points per second and store 100s of billions of rows and 10s of terabytes of data with TimescaleDB. In this tutorial, we will explain how to install TimescaleDB on Ubuntu 18.04. ## Step 1 – Install PostgreSQL TimescaleDB is powered by PostgreSQL and used to analyze time-series data with a PostgreSQL query language, so you will need to install the PostgreSQL server 9.6 or later in your server. You can install it by running the following command: ``` apt-get update -y apt-get install postgresql-10 -y ``` After installing the PostgreSQL server, start the PostgreSQL service and enable it to start after system reboot with the following command: ``` systemctl start postgresql systemctl enable postgresql ``` You can now verify the status of the PostgreSQL service with the following command: ``` systemctl status postgresql ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/05/TimescaleDB-PostgreSQL-Status.png) By default, PostgreSQL is configured to login without a password, so it is recommended to set a password for the Postgres user. To do so, log in with PostgreSQL user with the following command: ``` su - postgres ``` Next, set a password for the Postgres user with the following command: ``` psql -c "alter user postgres with password 'new-password'" ``` Next, exit from the PostgreSQL shell with the following command: ``` exit ``` Once you are done, you can proceed to the next step. ## Step 2 – Install and Configure TimescaleDB By default, TimescaleDB is not available in the Ubuntu 18.04 default repository, so you will need to add the repository for TimescaleDB. You can add it with the following command: ``` add-apt-repository ppa:timescale/timescaledb-ppa -y ``` Once the repository has been added, update the repository with the following command: ``` apt-get update -y ``` Finally, install TimescaleDB by running the following command: ``` apt-get install timescaledb-postgresql-10 -y ``` Once installed, you will need to edit your postgresql.conf file and include the TimescaleDB library. ``` nano /etc/postgresql/10/main/postgresql.conf ``` Add the following line at the end of the file: ``` shared_preload_libraries = 'timescaledb' ``` Save and close the file when you are finished. Then, restart the PostgreSQL service to apply the changes: ``` systemctl restart postgresql ``` ## Step 3 – Verify TimescaleDB Installation At this point, TimescaleDB is installed and configured. It’s time to test the TimescaleDB database. To do so, log in to PostgreSQL shell with the following command: ``` su - postgres postgres@ubuntu1804:~$ psql ``` ![](https://www.atlantic.net/wp-content/uploads/2020/05/TimescaleDB-PostgreSQL-Login.png) Next, create a new database named testdb with the following command: ``` postgres=# CREATE DATABASE timedb; ``` Next, connect to your database with the following command: ``` postgres=# \c timedb ``` Output: You are now connected to database “timedb” as user “postgres”. Finally, enable the TimescaleDB extension with the following command: ``` timedb=# CREATE EXTENSION IF NOT EXISTS timescaledb CASCADE; ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/05/TimescaleDB-Enabled.png) The above output clearly indicates that the TimescaleDB is enabled with PostgreSQL. Next, exit from the PostgreSQL shell with the following command: ``` \q exit ``` ## Conclusion Congratulations! You have successfully installed TimescaleDB on Ubuntu 18.04 server. You can now take advantage the key benefits TimescaleDB offers over traditional relational database systems. For more information, refer to the official documentation at [TimescaleDB Doc](https://docs.timescale.com/). Get started with TimescaleDB today on Atlantic.Net [VPS Hosting](https://www.atlantic.net/vps-hosting/)! --- # How to Find the Best Hosting Platform for HIPAA-Compliant Forms > URL: https://www.atlantic.net/hipaa-compliant-hosting/how-to-find-the-best-hosting-platform-for-hipaa-compliant-forms/ | Published: 2020-05-14 | Updated: 2025-09-19 | Author: Brandon Schroth Whether you are a pediatrician, an emergency room doctor, or a psychologist, collecting patient information through an online form is more efficient than using paper forms.  And amid the COVID-19 pandemic, it’s also a lot safer to have patients fill out forms through their phone or laptop instead of filling out paper forms using shared pens and clipboards that may have lingering germs.   However, online forms carry their own unique risks and challenges, mainly related to HIPAA compliance. Congress passed [The Health Insurance Portability and Accountability Act (HIPAA)](https://www.dhcs.ca.gov/formsandpubs/laws/hipaa/Pages/1.00WhatisHIPAA.aspx) in 1996 as a way to regulate and secure sensitive personal health information.  This means that both your online form as well as your hosting platform must be fully HIPAA compliant.  In this post, we’re sharing some tips to help you find the best hosting platform for your HIPAA-compliant forms.   ## What’s a HIPAA-Compliant Form? Before you dive into the key considerations for choosing the right hosting platform, it’s important to define what a HIPAA-compliant form is. You can create, collect, and store sensitive patient information through an online or mobile HIPAA-compliant form. These forms range from new patient registrations, health consent forms, medical history forms, and online bill payments to prescription refill requests, medical record releases, incident reports, and patient feedback surveys.   HIPAA-compliant platforms, such as [JotForm](https://www.jotform.com/hipaa/), make it easy to set up a new form (often in a matter of a few minutes) and collect this information.    For example, if you are a psychologist, you could use JotForm to create a contact form that allows new patients to book their first appointment right on your website. The confirmation screen could then take them to a new patient onboarding form that asks questions about their medical and mental health history.  This process is way more efficient for patients than having to call to schedule their first appointment and then spending 10–15 minutes of the appointment filling out countless forms.  ## What’s a HIPAA-Compliant Hosting Platform?  The other critical part of this process is your hosting provider. This is where your [HIPAA-compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) website and all electronic records are stored.   ### The key factors to consider when evaluating hosting platforms   You can never be too careful when choosing and vetting your hosting platform.  Here is a checklist of things to look for when evaluating providers. 1. Does it have a**secure private hosted environment?** In order to be HIPAA compliant, you need to be on secure and private server. You need to have control over the server and ensure it has dedicated resources available and reserved for your exclusive use. 2. Does the platform provide **encrypted VPNs and firewalls?** There are actually three types of firewalls: hardware, software, and web applications. Many companies have been fined for HIPAA violations because they have necessary firewalls in place for their software but forget about the one-off Chrome plug-in they built to handle a specific process six months ago.  Most importantly, is the firewall configured properly? Atlantic.Net engineers can help not only choose the right firewall and encryption, but also set it up properly. 3. Does the company have **multifactor authentication** (aka MFA) in place? This ultimately boils down to having at least two ways to verify someone’s identity, such as a code sent to a user’s phone or email address after they enter their username and password. 4. Does the provider have all of the **proper technical, physical, and administrative safeguards and protocols in place to prevent improper access to personal health records or sensitive data?** Make sure the data is fully encrypted and secure. This means having secure, thoroughly documented processes in place with data logs available. Making sure your provider is HIPAA and HITECH audited will go a long way. SOC certifications are also a helpful way to ensure you are hosting on the right infrastructure. 5. Does the company **limit and enforce who has access to their physical offices and facilities?** This relates to the point above. Does your hosting provider have processes in place to ensure that only authorized employees and personnel can enter their offices, including having to key in to get access? After all, what good are proper electronic protocols if anyone can enter the building and potentially access sensitive information? 6. Does the provider have **fast, friendly, and helpful customer support?** If you have a question, or in the event something breaks, you’ll need help immediately. Do you have confidence that they will respond quickly and work with you to resolve the issue efficiently? For example, is customer service always available via phone or email?   7. Does the company have **an extensive disaster recovery plan, including off-site backups?** There is the old adage “Hope for the best, but plan for the worst.” When dealing with sensitive patient information, you need to have mountains of contingency plans, including multiple, offsite backups. These contingency plans range from protecting any hackers to how to respond if a tornado levels one of your offices in Kansas. 8. Will the provider**sign a Business Associates Agreement (BAA)?** This agreement clearly outlines the specific roles and responsibilities of the hosting platform for maintaining HIPAA compliance. 9. How **long has the platform been HIPAA compliant, and has it ever run into issues?** A good starting point is to see if they’ve ever been fined for a HIPAA compliance violation.  There is one big caveat to all of this.  You can do your due diligence and thoroughly vet your [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) provider and still run into compliance issues down the line. Let’s look at an example.  HIPAA compliance is often compared to driving a car. If you have a valid driver’s license and insurance, the state says you are allowed to drive.  However, if you decide to have a few cocktails, get behind the wheel, and crash into a tree, you are no longer compliant and will likely end up with hefty medical and legal bills from your DUI and emergency room visit.  The same principles apply to your hosting provider. They could be fully compliant. However, if your dev-ops team makes a mistake and forgets to properly secure a Chrome plug-in (which is easy to do), you will no longer be compliant.  The consequences for a HIPAA compliance violation can be steep, ranging from a few thousand dollars to jail time for malicious or particularly egregious offenses.  *** There are a lot of factors to consider when it comes to proper HIPAA compliance. The consequences of getting it wrong can be dire. Make sure to do your due diligence upfront when choosing a hosting platform. It is always best practice to focus on your core business and let the experts take care of HIPAA compliance. If you’re in the market for fast compliance, consider trying Atlantic.Net with a [free HIPAA trial](https://www.atlantic.net/hipaa-compliant-hosting/) or call one of our engineers to get a custom solution built for you. Learn more about our [HIPAA compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. --- # How Can Cloud Technology Empower eLearning and Distance Learning? > URL: https://www.atlantic.net/vps-hosting/how-can-cloud-technology-empower-elearning-and-distance-learning/ | Published: 2020-05-19 | Updated: 2026-06-04 | Author: Alexander Wise Cloud technology is facilitating an educational revolution in delivering teaching services to students. The interoperability of the learning technology, in conjunction with the ability for almost anyone to consume education via a laptop and an internet connection, has helped online education to thrive globally. The eLearning industry has flourished since the inception of cloud technology. Established Ivy League universities, schools, and specialist training houses have long been offering online education programs. In addition, many organizations offer a variety of online-only education services, and there has been a significant increase in [free online learning](https://www.youtube.com/watch?v=cjGERWYvzqk) programs. ## What Are eLearning and Distance Learning? eLearning and distance learning are often thought of as interchangeable terms, but there are some meaningful differences between these two types of learning. - **eLearning** is when the technique of learning is the same; generally, a teacher is communicating directly to students. However, the medium is changed from the classroom to an online forum, typically video conferencing. eLearning is often used to complement classroom-based study, but as we have seen in recent weeks, eLearning has quickly become the new way to teach. - **Distance learning** is designed for foreign or rural students, commonly those attending University but are unable to travel to the University town to complete their studies. This might include a student based in the UK distance learning at an American University without ever having to move to the USA. ## Why Is Online Learning so Popular? Teaching faculties are often regarded as forward-thinking establishments, institutions that embrace new technology. As such, the revolution in information technology in the 20th and 21st centuries has been heavily intertwined with places of education. As such, students both young and old, from all professions and backgrounds, are embracing a new approach to online learning powered by the cloud. Programs like [Florida Virtual School](https://www.flvs.net/) are taking off. Prior to the Covid-19 pandemic, online education services were already growing with significant popularity; some [elearning statistics](https://www.learnworlds.com/elearning-statistics/) suggest that the sector could become a $319 billion industry by 2029. Since COVID-19, eLearning and distance learning have really shown their strengths, and cloud computing has powered the fallback option to in-person education. One of the few positive outcomes of the pandemic is the number of [free education services being offered to parents](https://www.khanacademy.org/donate). However, as many as [1.2 billion children](https://www.weforum.org/agenda/2020/04/coronavirus-education-global-covid19-online-digital-learning/) globally could be embarking on eLearning initiatives as of April 2020. While it is almost impossible to provide statistically accurate figures at present, there are a huge number of students who have been forced to adapt to online teaching in light of the Coronavirus crisis. ## How Does the Cloud Empower Online Learning? There are several ways in which the cloud has simplified and empowered education-as-a-service. eLearning and distance learning material are easy to access via the Web, they rarely require the installation of any client-side software, online learning services are easily consumed using low cost, pay by subscription tariffs, and [eLearning platforms](https://www.ispringsolutions.com/blog/elearning-platforms) for state schools typically offer free access for millions of students. Cloud computing technology provides a number of core beneficial features needed to bring learning to the student. Two key beneficial features are scalability and accessibility. It is relatively easy to create an online learning application that can be used by students, that incorporates video streams provided by teachers, that includes downloadable learning materials and whiteboards, etc. However, creation of such a solution becomes more complex when introducing scale. ### Scalability & Accessibility There are currently millions of American schools embarking on cloud teaching to their students, and [Cloud Service Providers](https://www.atlantic.net/cloud-platform/) are supplying the infrastructure to make it happen.  The influx of network traffic and server load created by the multiple simultaneous connections from students’ devices to the learning material can put massive strain on the eLearning infrastructure. Cloud technology handles this risk by introducing scalability, applications, and server workloads that can scale up and out as needed. Practically limitless cycles of CPU and memory can be made available, and the network layer, typically a cloud load balancer, can distribute heavy workloads to multiple endpoints. What this means in real terms is that ten of thousands of students can live stream classroom content, contribute in-class discussion, and submit work in a seamless manner. Accessibility is key because every student is accessing the learning platform from a different internet endpoint. The connection needs to be stable, secure, and in many cases encrypted during transit. Only the massive scale of cloud infrastructure can absorb this level of intense workload on-demand. ### Privacy & Security The cloud resolves many other technical challenges introduced by eLearning and distance learning. One such challenge is the maintenance of the security, privacy, and confidentiality of the enrolled students and participating staff. Many cloud service providers are extensively audited and certified for data protection safeguards. Cloud hosting introduces high availability, fault tolerance, and the option for automatic recovery in the event the infrastructure is overloaded. ### Distance Learning & School Choice For the students of distance learning, cloud technology allows almost anyone to learn at the institution of their choice. Overseas learning has thrived since education providers have leveraged cloud resources to distribute learning, with some sources estimating that as many as 15% of enrolled students in the United States are doing distance learning. ## Final Thoughts The COVID-19 pandemic has highlighted how important online learning services are for professionals, students, and parents. Few predicted the turmoil that would result from closing schools and universities around the world. Cloud technology has made a significant difference to many students’ lives, offering an education platform that can be accessed by everyone, on-demand. Atlantic.Net is already helping many learning partners who have reached out to see how we can help them with server usage spikes and how to create a more cost-effective solution. Our [VPS hosting](https://www.atlantic.net/vps-hosting/) technology is cutting edge, available 24x7x365 with a 100% uptime guarantee, we offer a user-friendly cloud platform that can spin up what you need in seconds. We believe that eLearning powered by the cloud is the future of education services. --- # How to Setup Passwordless Sudo for a Specific User > URL: https://www.atlantic.net/vps-hosting/how-to-setup-passwordless-sudo-for-a-specific-user/ | Published: 2020-06-11 | Updated: 2023-11-25 | Author: Hitesh Jethva In a Linux system, the root user is a superuser that has permission to access everything on the server. A standard user account only has limited privileges and can run only specific commands on the system. The sudo command elevates a standard user account, granting root access to the system. Every time you sudo a sudo command you will be prompted for the sudoer password, which can become repetitive. However, there is a great way to securely configure a passwordless sudo account In this tutorial, we will show you how to set up Passwordless Sudo in Linux. ## Step 1 – Configure Passwordless Sudo For a Specific User If you want to allow a user named vyom to execute sudo without a password, edit the /etc/sudoers file: ``` nano /etc/sudoers ``` Add the following line at the end of the file: ``` your_username ALL=(ALL:ALL) NOPASSWD:ALL ``` For example: ``` Atlantic-Admin ALL=(ALL:ALL) NOPASSWD:ALL ``` Save and close the file. Then, run any superuser command with sudo: ``` sudo fdisk -l ``` You don’t need to provide any password after running the above command. ## Step 2 – Configure Passwordless Sudo For a Specific Group If you want to allow a member of a specific group named www-data to execute sudo without a password, edit the /etc/sudoers file: ``` nano /etc/sudoers ``` Add the following line at the end of the file: ``` %www-data  ALL=(ALL:ALL) NOPASSWD:ALL ``` Save and close the file when you are finished. ## Step 3 – Configure Passwordless Sudo For All Users If you want to allow all users to execute sudo without a password **(note: this is only advisable in test systems and should never be used on production workloads)**, edit the /etc/sudoers file: ``` nano /etc/sudoers ``` Find the following line: ``` %sudo   ALL=(ALL:ALL) ALL ``` Replace it with the following line: ``` %sudo   ALL=(ALL:ALL) NOPASSWD:ALL ``` ## Step 4 – Configure Passwordless Sudo For Specific User to Execute Only Specific Command If you want to allow a specific user named vyom to execute only “fdisk -l” command  without password, edit the /etc/sudoers file: ``` nano /etc/sudoers ``` Add the following line at the end of the file: ``` your_username  ALL=(ALL:ALL) NOPASSWD: /sbin/fdisk -l ``` Save and close the file when you are finished. Now, only the user can only run the “fdisk -l” command without a password. ## Conclusion In the above guide, you have learned how to configure passwordless sudo for a specific group, specific user and all users. Ready to get started with Passwordless Sudo in Linux? Get [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [Virtual private servers.](https://www.atlantic.net/vps-hosting/) --- # New European and Californian data privacy regulations are creating a significant challenge to achieving the HIPAA disaster recovery safeguards > URL: https://www.atlantic.net/hipaa-compliant-hosting/new-european-and-californian-data-privacy-regulations-are-creating-a-significant-challenge-to-achieving-the-hipaa-disaster-recovery-safeguards/ | Published: 2020-06-12 | Updated: 2026-06-17 | Author: Richard Bailey While achieving HIPAA-compliant status has always been a significant accomplishment for cloud hosting providers, organizations that process electronic Protected Health Information (ePHI) for the purposes of business continuity and disaster recovery recently had two major constraints added on top of HIPAA compliance requirements. Healthcare organizations, business associates, and third parties already must adhere to a stringent set of data handling regulations enforced ever since the enactment of [Health Insurance Portability and Accountability Act](https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html) (HIPAA) in 1996. More recently, new data privacy requirements have been passed in the European Union (EU) and the state of California that have added further restrictions on data processing and data handling. ## Game-Changing New Regulations The California Consumer Privacy Act (CCPA) and the General Data Protection Regulations (GDPR) are both recently passed privacy acts that update antiquated laws in relation to how personal information (PI) is handled, stored, and processed. Since the proliferation of Internet services, mobile telecommunications, and social media, campaigners have been demanding changes to how businesses handle PI. ![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-Privacy-Violations.png) [Hipaa Violations by Type – Pie Chart](https://commons.wikimedia.org/wiki/File:Hipaa_Violations_by_Type_-_Pie_Chart.png) CCPA was passed in 2018 and came into force on January 1, 2020. GDPR was passed into law on May 25, 2018. Both legislations have similar recommendations and requirements, but GDPR is focused on European citizens’ personal information while CCPA relates to US citizens’ personal information. Importantly, both legislations have a shared synergy that impacts businesses on both sides of the Atlantic. Any business in the United States that is responsible for processing European personal information, and any business in Europe that processes US personal information, must adhere to each of the new legislation guidelines to be compliant with the updated privacy rules. To briefly summarise GDPR, some of the key protections introduced are: - GDPR requires that permission must be granted prior to collecting data. This is why you now see “Accept All Tracking Cookies” popups when you enter your favorite websites. - You must notify of a data breach within 72 hours. - Upon request, data collectors must be able to explain what information is being collected, how it is being used, and whether the data is being shared. - EU citizens have the right to have any and all data held on them deleted by the collector. The CCPA protections are largely the same as GDPR, and some of the key elements are: - US citizens have the right to know what personal information is being collected, sold, or disclosed. - US citizens have the right to view their collected data and demand their data is not sold. - CCPA applies if a company generates more than $25 million USD a year and half of that revenue is from selling personal data. For those trying to [balance HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) with the requirements of these two new pieces of legislation, pay attention – here is the important information you need to know. ## When Data Disaster Strikes HIPAA compliance requires that an organization must develop a contingency plan that allows an organization to both protect ePHI and quickly recover core business functions in the event of a disaster. Disaster recovery is an information technology safeguard designed to protect both the business operations and the access to ePHI. The ability of a healthcare facility to be able to resume day-to-day activities and process ePHI is an essential part of compliance. ![](https://www.atlantic.net/wp-content/uploads/2020/06/Fake-FBI-Warning.png) [Ransomware pic jpg](https://commons.wikimedia.org/wiki/File:Ransomware-pic.jpg) For a quick example, let’s consider a hypothetical hospital whose infrastructure has been [infected with ransomware](https://www.atlantic.net/vps-hosting/ransomware-in-the-wild/). Without normal access to patient medical records, one would expect the business operations of the hospital to grind to a halt quickly.  HIPAA regulations were created to combat such an “Armageddon” scenario, meaning that the hospital could fail over technical services to a secondary location, thus restoring access to core applications and ePHI. When the U.S. Department of Health and Human Services (HHS) created the HIPAA act, it is unlikely that they could have predicted what future local or international privacy rules might be introduced and their impact on US legislation. Likewise, GDPR and CCPA legislation was focused on protecting data privacy online, but was seemingly not tailored with the medical industry in mind. ## The Problem with Duplicate Data Centers Prior to the recent legislation, a favorite disaster recovery solution to protect data was to simply create redundant data center(s) in different geographic location(s) or to contract a colocation facility. The end result is that if the onsite database becomes unavailable due to a malfunction, it is often a simple matter to switch over production services to the secondary location. Complications arise due to the fact that both GDPR and CCPA require that all personally identifiable information related to any person in the database can be [removed upon request](https://www.csoonline.com/article/3292578/california-consumer-privacy-act-what-you-need-to-know-to-be-compliant.html). Handling these requests and securely wiping the requested data has to be done not only on the live database, but also any replica copies. Healthcare organizations and cloud service providers are having to create automated processes and routines that identify expired data and delete what is out of scope. The business associates must work together to identify data that is in scope, as well as understand how long the data can be retained to remain compliant. The end result of these additional requirements is more work and an increased chance of mistakes, and this might place the entire organization in violation of the new regulations if not done correctly. ## The Problem of Unstructured Data When it comes to protecting or deleting personal information, such as, in one example, a Social Security number from the Social Security Administration’s database, the task to achieve this is not overly complicated. This is because a Social Security number is structured data that is easily located within a database. Unstructured data, such as documents, emails, form submissions, excel files are much more complex. The reason is that these files might contain Protected Information, and it would be an administrative nightmare to audit every single file for sensitive information. This problem makes precise analysis and location of personal data a huge challenge. Advanced tools can be deployed that encrypt data at rest and in transit, or use AI to redact information buried in documents. In one popular example, if an administrator accidentally sent a manual payment receipt to a patient and the [PAN](https://en.wikipedia.org/wiki/PAN_truncation#:~:text=%22PAN%22%20is%20an%20acronym%20for,being%20replaced%20usually%20by%20asterisks.) was not hashed out, intelligent email software can identify this information in email attachments and reject sending of the email, automatically responding to the sender that their action would breach GDPR or CCPA regulations. However, the implementation of these toolsets is technically challenging and expensive to achieve. ## The Right to be Forgotten Prior to GDPR and CCPA legislation, some speculated that personal privacy may have already been dead – check out this [article about Amazon Alexa](https://www.gadgetguy.com.au/alexa-invades-your-privacy-and-how-to-stop-it/?display=all) if you don’t believe it – but the foundations of both the GDPR and CCPA rest on the idea that an individual has the right to be forgotten. In other words, any website or business that holds your information in a database is required to delete it upon request. This newly outlined right often clashes with practical business processes in reality. A good example is bank loans. Does it make sense that you can ask your banker to get rid of all your data he or she has on file immediately after you’ve taken out a $250,000 loan? Probably not. The right to be forgotten directly impacts disaster recovery services, creating an almost impossible situation for business associates. HIPAA legislation demands that the location of ePHI is known explicitly to all involved. However, the reality is that many medical professionals do not have a firm grasp on what ePHI data that they do have, which makes the process of reliably deleting requested records an exercise in futility. The added complication makes choosing the best HIPAA compliant hosting partner an essential due diligence exercise the healthcare organization must undertake. The right partner can help to guide healthcare professionals in achieving compliance and knowing exactly what ePHI data is in the scope of the legislation. ## Hackers Create a Huge Liability It’s one thing if an earthquake, hurricane, flood, or tornado were to take out a hospital’s frontline database. Such “acts of God” are unavoidable. But if you own one or more of the [1.24 billion websites active online](https://hostingcanada.org/internet-statistics/) now, you have to be even more worried about human intrusion, which presents a greater danger when measured against the standards set out by these new regulations. Cyberattacks that leave behind malware and steal personally identifiable information are often preventable. The responsibility lies with the organization and technology business partners, and failure to uphold this responsibility can bring a heavy financial penalty. ![](https://www.atlantic.net/wp-content/uploads/2020/06/GDPR-Image.png) [European 451 Error Code Example png](https://en.m.wikipedia.org/wiki/File:European_451_Error_Code_Example.png) For example, the first year GDPR was active yielded $344 million worth of fines that mostly fell in the category of “insufficient security measures.” GDPR penalties for a single incident can run [as high as $20 million euros](https://www.zdnet.com/article/gdpr-an-executive-guide-to-what-you-need-to-know/) or 4% of global income, whichever number is higher. That’s a hefty fine to be dropping on top of an organization that is already reeling from what might have been a costly security breach. ## Final Thoughts Disaster recovery remains a critical part of HIPAA compliance, and healthcare organizations and their technology partners must be able to create a disaster recovery solution that protects ePHI, as well as the core applications that process and maintain ePHI, at all times. In-scope ePHI must be identified, and its locations documented, within a Business Associate Agreement (BAA). The technology partner and the healthcare institution must work together to ensure ePHI is protected at all times. GDPR and CCPA require explicit consent to access ePHI, but HIPAA allows anonymized data to be made public. The rules are slightly different when reporting a data breach to the authorities. HIPAA demands that the Officer for Civil Rights (OCR) must be informed for breaches of 500 or more patients within 60 days, while for GDPR there is a 72-hour breach reporting window. From the preceding analysis, it’s easy to see why cyber insurance has become an increasingly popular solution. In theory, cyber insurance could protect an online company by paying off fines imposed by regulators. There are mixed opinions on this type of protection; for some, it adds peace of mind, while for others it provides protection when inadequate information technology is available. For now, any organization under the auspices of HIPAA would do well to find a security expert with some track record of success in navigating the current regulatory minefield. --- # File Permissions in Linux with Example > URL: https://www.atlantic.net/vps-hosting/file-permissions-in-linux-with-example/ | Published: 2020-06-13 | Updated: 2023-11-16 | Author: Hitesh Jethva Linux is a multi-user operating system with multiple users accessing the same system. System administrators are responsible for preventing a user from accessing another user’s confidential files. For these reasons, Linux divides authorization into two levels, Ownership and Permission. ## File Ownership Each file and directory has three kinds of owners. - **User:** A “user” is the owner of the file. If you create a new file, then you become the owner of the file. - **Group:** Every user is a part of the specific “group.” A group contains multiple users, all of whom will have the same access permissions to the file. - **Other:** All users and groups in the system are considered as “others.” Owners are denoted with the following symbols: - u = user owner - g = group owner - o = other - a = all (user + group + other) ## Change the Ownership with chown To display the ownership of the file *index.html* in */var/www/html*directory, run the following command: ``` ls -l /var/www/html/index.html ``` You should get the following output: ``` -rw-r--r-- 1 www-data www-data 11510 Feb  3 20:25 /var/www/html/index.html ``` As you can see, the group and user owner of the file is www-data. A basic syntax to change the ownership of the file is shown below: ``` chown owner:group filename ``` To change the owner of the file *index.html* to root  and group to root, run the following command: ``` chown root:root /var/www/html/index.html ``` You can use the -R option with the *chown*command to change the ownership of the directory recursively. For example, to change the ownership of the directory */var/www/html* to www-data**as the user** and www-data **as the group**, run the following command: ``` chown -R www-data:www-data /var/www/html/ ``` This will change the ownership of all files and directories located inside */var/www/html/.* ## File Permissions Each file and directory has three types of permission: - **Read:** You can view and read the content of the file, but can not edit or modify the file. You can list the content of the directory with “read” permission. - **Write:** You can read and edit the content of the file. You can also rename and remove the file. You can add, remove, and rename files in the directory with “read” permission. - **Execute:** You can execute the file. Permissions are defined using **octal permissions**. These are nine characters created in three sets of three characters: ``` ---    ---    --- rwx    rwx    rwx user   group  other ``` Each letter denotes a particular permission: - **r:** Read permission - **w:** Write permission - **x:** Execute permission - **–:** No permission set Permissions are also represented in numeric form as shown below: - **r**(read) = 4 - **w**(write) = 2 - **x**(execute) = 1 - **–**(no permission) = 0 - **rwx**= 4+2+1 = 7 - **rw**= 4+2 = 6 You can also use mathematical operators to add and remove permissions. - **+:** Add the permissions. - **-:** Remove the permissions. - **=:** Overriding existing permissions. ## Change the Permissions with chmod *Chmod*stands for **change mode**, and it is a basic syntax used to change the permissions of the file: ``` chmod permissions filename ``` To check the permissions of the file, run the following command: ``` ls -l /var/www/html/index.html ``` Output: ``` -rw-r--r-- 1 www-data www-data 11510 Feb  3 20:25 /var/www/html/index.html ``` As you can see, the owner of the file has *read/write* permissions, the group has *read*permission and the other has *read*permission. To add *execute*permissions to the user, run the following command: ``` chmod u+x /var/www/html/index.html ``` Now, verify the permissions with the following command: ``` ls -l /var/www/html/index.html ``` Output: ``` -rwxr--r-- 1 www-data www-data 11510 Feb  3 20:25 /var/www/html/index.html ``` To add write permissions to group and others, run the following command: ``` chmod g+w,o+w /var/www/html/index.html ``` Now, verify the permissions with the following command: ``` ls -l /var/www/html/index.html ``` Output: ``` -rwxrw-rw- 1 www-data www-data 11510 Feb  3 20:25 /var/www/html/index.html ``` To remove the write permissions from others, run the following command: ``` chmod o-w /var/www/html/index.html ``` Now, verify the permissions with the following command: ``` ls -l /var/www/html/index.html ``` Output: ``` -rwxrw-r-- 1 www-data www-data 11510 Feb  3 20:25 /var/www/html/index.html ``` You can also set the permissions using the **octal value**. You can use the following values for each permission: **777 =** rwxrwxrwx **765 =** rwxrw-r-x **654 =** rw-r-xr– For example, change the permissions of the file so that the user can *read/write and execute*, the group can *read*and *execute*and the others can only *read*the file. ``` chmod u=rwx,g=rx,o=r /var/www/html/index.html ``` Or ``` chmod 754 /var/www/html/index.html ``` ## Conclusion In the above guide, you learned how ownership and permissions work in Linux. You also learned how to set and change the ownership and permissions of the files and directories. I hope you have now enough understanding of file ownership and permissions – try it today on your [Linux VPS](https://www.atlantic.net/vps-hosting/). --- # Top 8 MySQL Command-line Tips and Tricks > URL: https://www.atlantic.net/vps-hosting/top-8-mysql-command-line-tips-and-tricks/ | Published: 2020-06-14 | Updated: 2025-09-19 | Author: Hitesh Jethva MySQL is an open-source relational database management system that is developed, distributed, and supported by Oracle Corporation. There are several web-based tools available for managing the MySQL server, but best practice is to use the native MySQL command-line client for performing day-to-day MySQL tasks. It does take some time to get familiar with a command-line interface, particularly if you don’t regularly work in a CLI environment. In this tutorial, we will show you some MySQL command-line tips and tricks that help you to perform day-to-day tasks. ## Prerequisites - A fresh Ubuntu 18.04 [VPS](https://www.atlantic.net/vps-hosting/) with MySQL installed on the Atlantic.Net Cloud Platform. - A root password configured on your server. ## Create Atlantic.Net Cloud Server First, log in to your [Atlantic.Net Cloud Server](https://cloud.atlantic.net/?page=userlogin).  Create a new [server](https://www.atlantic.net/vps-hosting/how-to-create-new-atlantic-net-cloud-server/), choosing Ubuntu 18.04 as the operating system with at least 1GB RAM. Connect to your Cloud Server via SSH and log in using the credentials highlighted at the top of the page. Once you are logged into your Ubuntu 18.04 server, run the following command to update your base system with the latest available packages. ``` apt-get update -y ``` ## 1 – Automate the MySQL Login In order to connect the MySQL server, you will be required to authenticate by specifying a username and password. If this is your routine process, then you can save your lots of time by specifying your MySQL username and password in ~/.my.cnf file to automate the login process. To do so, create a ~/.my.cnf file in your home directory: ``` nano ~/.my.cnf ``` Add the following information containing your MySQL host, username, and password: ``` [client] host     = localhost user     = root password = your-password ``` Save and close the file then change the ownership of the file to mysql: ``` chown mysql:mysql ~/.my.cnf ``` Now, you can connect your MySQL server without specifying a username and password as shown below: ``` mysql ``` You should get the following output: ``` Welcome to the MySQL monitor.  Commands end with ; or \g. Your MySQL connection id is 5 Server version: 5.7.29-0ubuntu0.18.04.1 (Ubuntu) Copyright (c) 2000, 2020, Oracle and/or its affiliates. All rights reserved. Oracle is a registered trademark of Oracle Corporation and/or its affiliates. Other names may be trademarks of their respective owners. Type 'help;' or '\h' for help. Type '\c' to clear the current input statement. mysql> ``` ## 2 – Check Running Processes To check all the running processes of the MySQL service, run the following command: ``` mysqladmin -u root -pnew-password processlist ``` You should see the following output: ``` mysqladmin: [Warning] Using a password on the command line interface can be insecure. +----+------+-----------+----+---------+------+----------+------------------+ | Id | User | Host      | db | Command | Time | State    | Info             | +----+------+-----------+----+---------+------+----------+------------------+ | 6  | root | localhost |    | Query   | 0    | starting | show processlist | +----+------+-----------+----+---------+------+----------+------------------+ ``` ## 3 – Shutdown MySQL Service To shut down the MySQL server, run the following command: ``` mysqladmin -u root -pnew-password shutdown ``` ## 4 – Create and Delete Database To create a new database, run the following command: ``` mysqladmin -u root -pnew-password create dbname ``` To remove a database, run the following command: ``` mysqladmin -u root -pnew-password drop dbname ``` ## 5 – Check the Status of MySQL To check whether the MySQL server is running or not, use the following command: ``` mysqladmin -u root -pnew-password ping ``` You should get the following output: ``` mysqld is alive ``` To verify the current status of the MySQL server, run the following command: ``` mysqladmin -u root -pnew-password status ``` You should see the status of uptime with running threads and queries in the following output: ``` Uptime: 2607  Threads: 1  Questions: 30  Slow queries: 0  Opens: 112  Flush tables: 2  Open tables: 0  Queries per second avg: 0.011 ``` If you want to check the status of remote MySQL server, run the following command: ``` mysqladmin -h remote-server-ip -u root -pnew-password status ``` ## 6 – Check MySQL Version To check the installed version of the MySQL server, run the following command: ``` mysqladmin -u root -pnew-password version ``` You should get the following output: ``` mysqladmin: [Warning] Using a password on the command line interface can be insecure. mysqladmin  Ver 8.42 Distrib 5.7.29, for Linux on x86_64 Copyright (c) 2000, 2020, Oracle and/or its affiliates. All rights reserved. Oracle is a registered trademark of Oracle Corporation and/or its affiliates. Other names may be trademarks of their respective owners. Server version             5.7.29-0ubuntu0.18.04.1 Protocol version          10 Connection                 Localhost via UNIX socket UNIX socket               /var/run/mysqld/mysqld.sock Uptime:                                   44 min 44 sec Threads: 1  Questions: 35  Slow queries: 0  Opens: 113  Flush tables: 2  Open tables: 1  Queries per second avg: 0.013 ``` ## 7 – Store MySQL Debug Information If you want to tell MySQL server to write debug information in MySQL log file, run the following command: ``` mysqldump -u root -pnew-password debug ``` ## 8 – Backup and Restore MySQL Database To back up a single database, run the following command: ``` mysqldump -u root -pnew-password databasename > database-backup.sql ``` To back up multiple databases in a single file, run the following command: ``` mysqldump -u root -pnew-password database1 database2 database3 > database-backup.sql ``` To back up all databases in a single file, run the following command: ``` mysqldump -u root -pnew-password --all-databases --single-transaction --quick --lock-tables=false > full-database.sql ``` To restore a database from the backup file, run the following command: ``` mysqldump -u root -pnew-password databasename < database-backup.sql ``` ## Conclusion In the above guide, you learned some useful MySQL commands with examples. We hope this will help you to save lots of time when using MySQL on your [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Set Up Apache as Frontend Proxy Server for Node.js CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-set-up-apache-as-frontend-proxy-server-for-node-js-centos-8/ | Published: 2020-06-15 | Updated: 2024-07-02 | Author: Hitesh Jethva Node.js is an open-source, cross-platform, JavaScript runtime environment that can be used to run JavaScript outside the web browser. It is most commonly used to build web applications with real-time, two-way connections, where both the client and server can initiate communication, allowing them to exchange data freely. Node.js uses an event-driven, non-blocking I/O model that makes it perfect for data-intensive applications that run across distributed devices. In this tutorial, we will install Node.js and configure it to run as a backend server; then, we will configure Apache as frontend proxy server for Node.js. ## Step 1 – Install Node.js By default, the latest version of the Node.js is not available in the CentOS 8, so you will need to add Node.js repository in your system. You can install the Node.js repository using the following command: ``` curl --silent --location https://rpm.nodesource.com/setup_18.x | bash - ``` Once the repository is installed, you can install Node.js by simply running the following command: ``` dnf install nodejs -y ``` Once the installation has been completed, you can verify the installed version of Node.js with the following command: ``` node -v ``` You should get the following output: ``` v18.19.0 ``` You can also check the NPM version with the following command: ``` npm -v ``` You should get the following output: ``` 10.2.3 ``` ## Step 2 – Create a Sample Node.js Application First, let’s create a directory to hold the Node.js application: ``` mkdir project ``` Next, change the directory to project and create a sample Node.js application with the following command: ``` cd project nano app.js ``` Add the following contents: ``` var http = require('http'); http.createServer(function (req, res) { res.writeHead(200, {'Content-Type': 'text/plain'}); res.end('Welcome to Node.js Server'); }).listen(8080, "127.0.0.1"); console.log('Server running at http://127.0.0.1:8080/'); ``` Save and close the file when you are finished. Your Node.js application is now ready to serve on port 8080. Next, start the application with the following command: ``` node app.js ``` You should get the following output: ``` Server running at http://127.0.0.1:8080/ ``` The above output indicates that your Node.js application is working properly. Next, press **CTRL + C** to stop the application. ## Step 3 – Install and Configure PM2 to Manage Node.js Application PM2 is a process manager for the Node.js application. It allows you to keep Node.js application alive forever, to manage Node.js, to reload Node.js without downtime, and to facilitate common system admin tasks. You can install it using the NPM as shown below: ``` npm i -g pm2 ``` After installing PM2, change the directory to the project and start the Node.js application with PM2 as shown below: ``` pm2 start app.js ``` Once the application has been started successfully, you should get the following output: ```                         ------------- __/\\\\\\\\\\\\\____/\\\\____________/\\\\____/\\\\\\\\\_____ _\/\\\/////////\\\_\/\\\\\\________/\\\\\\__/\\\///////\\\___ _\/\\\_______\/\\\_\/\\\//\\\____/\\\//\\\_\///______\//\\\__   _\/\\\\\\\\\\\\\/__\/\\\\///\\\/\\\/_\/\\\___________/\\\/___    _\/\\\/////////____\/\\\__\///\\\/___\/\\\________/\\\//_____     _\/\\\_____________\/\\\____\///_____\/\\\_____/\\\//________      _\/\\\_____________\/\\\_____________\/\\\___/\\\/___________       _\/\\\_____________\/\\\_____________\/\\\__/\\\\\\\\\\\\\\\_        _\///______________\///______________\///__\///////////////__                           Runtime Edition         PM2 is a Production Process Manager for Node.js applications                     with a built-in Load Balancer.                 Start and Daemonize any application:                $ pm2 start app.js                 Load Balance 4 instances of api.js:                $ pm2 start api.js -i 4                 Monitor in production:                $ pm2 monitor                 Make pm2 auto-boot at server restart:                $ pm2 startup                 To go further checkout:                http://pm2.io/                         ------------- [PM2] Spawning PM2 daemon with pm2_home=/root/.pm2 [PM2] PM2 Successfully daemonized [PM2] Starting /root/project/app.js in fork_mode (1 instance) [PM2] Done. ┌─────┬────────┬─────────────┬─────────┬─────────┬──────────┬────────┬──────┬───────────┬──────────┬──────────┬──────────┬──────────┐ │ id  │ name   │ namespace   │ version │ mode    │ pid      │ uptime │ ↺    │ status    │ cpu      │ mem      │ user     │ watching │ ├─────┼────────┼─────────────┼─────────┼─────────┼──────────┼────────┼──────┼───────────┼──────────┼──────────┼──────────┼──────────┤ │ 0   │ app    │ default     │ N/A     │ fork    │ 1437     │ 0s     │ 0    │ online    │ 0%       │ 31.1mb   │ root     │ disabled │ └─────┴────────┴─────────────┴─────────┴─────────┴──────────┴────────┴──────┴───────────┴──────────┴──────────┴──────────┴──────────┘ ``` Next, enable the Node.js application to start at boot time with the following command: ``` pm2 startup ``` This command will create a systemd service file for the Node.js application and enable it to start after system reboot as shown below: ``` [PM2] Init System found: systemd Platform systemd Template [Unit] Description=PM2 process manager Documentation=https://pm2.keymetrics.io/ After=network.target [Service] Type=forking User=root LimitNOFILE=infinity LimitNPROC=infinity LimitCORE=infinity Environment=PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/root/bin:/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin Environment=PM2_HOME=/root/.pm2 PIDFile=/root/.pm2/pm2.pid Restart=on-failure ExecStart=/usr/lib/node_modules/pm2/bin/pm2 resurrect ExecReload=/usr/lib/node_modules/pm2/bin/pm2 reload all ExecStop=/usr/lib/node_modules/pm2/bin/pm2 kill [Install] WantedBy=multi-user.target Target path /etc/systemd/system/pm2-root.service Command list [ 'systemctl enable pm2-root' ] [PM2] Writing init configuration in /etc/systemd/system/pm2-root.service [PM2] Making script booting at startup... [PM2] [-] Executing: systemctl enable pm2-root... Created symlink /etc/systemd/system/multi-user.target.wants/pm2-root.service → /etc/systemd/system/pm2-root.service. [PM2] [v] Command successfully executed. +---------------------------------------+ [PM2] Freeze a process list on reboot via: $ pm2 save [PM2] Remove init script via: $ pm2 unstartup systemd ``` You can also list your active application with the following command: ``` pm2 list ``` You should get the following output: ``` ┌─────┬────────┬─────────────┬─────────┬─────────┬──────────┬────────┬──────┬───────────┬──────────┬──────────┬──────────┬──────────┐ │ id  │ name   │ namespace   │ version │ mode    │ pid      │ uptime │ ↺    │ status    │ cpu      │ mem      │ user     │ watching │ ├─────┼────────┼─────────────┼─────────┼─────────┼──────────┼────────┼──────┼───────────┼──────────┼──────────┼──────────┼──────────┤ │ 0   │ app    │ default     │ N/A     │ fork    │ 1437     │ 104s   │ 0    │ online    │ 0.1%     │ 39.7mb   │ root     │ disabled │ └─────┴────────┴─────────────┴─────────┴─────────┴──────────┴────────┴──────┴───────────┴──────────┴──────────┴──────────┴──────────┘ ``` ## Step 4 – Configure Apache as a Frontend Proxy for Node.js Next, you will need to install and configure the Apache webserver as a frontend server to access the Node.js application. First, install the Apache webserver with the following command: ``` dnf install httpd -y ``` Next, create an Apache virtual host configuration file for Node.js application with the following command: ``` nano /etc/httpd/conf.d/example.conf ``` Add the following lines: ```        ServerAdmin admin@example.com        ServerName node.example.com        ErrorLog /var/log/httpd/error.log        CustomLog /var/log/httpd/access.log combined       ProxyRequests On        ProxyPass / http://localhost:8080        ProxyPassReverse / http://localhost:8080 ``` Save and close the file when you are finished. Then, start the Apache webserver and enable it to start at reboot with the following command: ``` systemctl start httpd systemctl enable httpd ``` ## Step 5 – Access Node.js Application At this point, the Apache webserver is configured to access the Node.js application. Next, open your web browser and type the URL http://node.example.com. You will be redirected to the Node.js application page as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/06/Nodejs-Application.png) ## Conclusion Congratulations! You have successfully deployed Node.js application with Apache as a frontend server. You can now start building your Node.js application for the production environment – try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Create a SFTP User without Shell Access on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-create-a-sftp-user-without-shell-access-on-centos-8/ | Published: 2020-06-16 | Updated: 2024-06-04 | Author: Hitesh Jethva SFTP stands for “SSH File Transfer Protocol.” SFTP is a file transfer protocol used to transfer files between two servers. By default, SFTP allows you to transfer files on all servers that have SSH access enabled. However, it will grant terminal access to all users and this is not recommended for security reasons. In this tutorial, we will learn how to create an SFTP user without shell access so that the user has only SFTP access and not SSH access. ## Step 1 – Create an SFTP User First, you will need to create a new user with only file transfer access. You can create a new user named sftp using the following command: ``` adduser sftp ``` Next, set the password for the above user: ``` passwd sftp ``` Provide your desired password and hit enter. ## Step 2 – Create a Directory Structure for File Transfers Next, you will need to create a directory structure for file transfer to restrict SFTP access to one directory. You can create a new directory with the following command: ``` mkdir -p /opt/sftp/public ``` Next, set the ownership of the /opt/sftp/ directory to root: ``` chown root:root /opt/sftp ``` Next, give proper permissions with the following command: ``` chmod 755 /opt/sftp ``` Next, set the ownership of the public directory to the sftp user: ``` chown sftp:sftp /opt/sftp/public ``` ## Step 3 – Configure SSH for SFTP Next, you will need to configure SSH to restrict access to one directory and disallow terminal access to the sftp user. You can do it by editing the file /etc/ssh/sshd_config: ``` nano /etc/ssh/sshd_config ``` Add the following lines at the end of the file: ``` Match User sftp ForceCommand internal-sftp PasswordAuthentication yes ChrootDirectory /opt/sftp PermitTunnel no AllowAgentForwarding no AllowTcpForwarding no X11Forwarding no ``` Save and close the file when you are finished. Then, restart the SSH service to implement the changes: ``` systemctl restart sshd ``` ## Step 4 – Verify SFTP Now, verify the SFTP access with the following command: ``` sftp sftp@your-server-ip ``` You will be asked to provide a password as shown below: ``` sftp@your-server-ip's password: ``` Provide your sftp user password and hit Enter. Once connected, you should see the following output: ``` Connected to your-server-ip. sftp> ``` Next, run the following command to list the directory: ``` sftp> ls ``` You should see the public directory in the following output: ``` public  sftp> ``` Next, verify whether you are able to make SSH connection or not: ``` ssh sftp@your-server-ip ``` You will be asked to provide a password as shown below: ``` sftp@your-server-ip's password: ``` Provide your sftp user password and hit Enter. You should see the following output: ``` This service allows sftp connections only. Connection to your-server-ip closed. ``` The above output indicates that sftp user can no longer access the server shell via SSH. ## Conclusion Congratulations! You have successfully configured SFTP without shell access on CentOS 8. You can also use this setup for multiple users and directory. Get started with SFTP today on a [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Why All Small Business Owners Need to Install SSL Certificates Immediately > URL: https://www.atlantic.net/hipaa-compliant-wordpress-hosting/why-all-small-business-owners-need-to-install-ssl-certificates-immediately/ | Published: 2020-06-17 | Updated: 2026-05-04 | Author: Brandon Schroth Consumer opinions about security are shifting as new technologies, such as the Internet of Things (IoT), enter the marketplace. Studies increasingly show the impact of security breaches on average people. As many as [25% of people](https://www.experian.com/blogs/ask-experian/identity-theft-statistics/) have experienced some kind of identity theft. When you start to build a website for your small business, you have to ensure that your customers’ data is protected and that your company is secured against cyber attacks and [data breaches](https://www.atlantic.net/hipaa-data-centers/data-breaches-caused-by-misconfigured-servers-within-a-healthcare-environment/). Adequate defense of your business from malicious code is extremely difficult to achieve, especially when that code has been designed to destroy your infrastructure and allow cybercriminals to access your data, steal it, and sell it to the highest bidder on the black market. With so many different forms of attack, it can be confusing to know where to begin, but one strategy every business should use is to protect their customers through a [Secure Sockets Layer certificate (SSL)](https://www.atlantic.net/vps-hosting/what-is-ssl-certificate/). ## What exactly is an SSL certificate? An SSL certificate ensures that content provided to users originates from the correct sender – thus making communications through computer networks far more secure. For example, if you are using an online service like Netflix, Amazon, or Google, an SSL certificate can ensure that you are confident you are using the right service, and not a fake one. Because of this, including an SSL in [your business plan](https://www.freshbooks.com/blog/5-simple-rules-for-writing-solid-business-plans) should be essential, as it helps to verify who you are to your customers. In order to obtain certain (and reputable) SSL certificates, companies have to be thoroughly vetted before they will be allowed to [display the certificate](https://smallbusiness.chron.com/can-sites-ssl-certificate-57315.html) on their webpages and provide a secure connection. ## Why use SSL certification? While you should also maintain other channels of communication with customers for convenience and security, protecting and [combining your business communications over the Internet](https://www.getweave.com/5-reasons-for-small-businesses-to-combine-communication-through-their-phone-system/) will always be key, especially as online communication becomes more frequent. Consumers have come to expect their sensitive information to be secure when they are shopping online. By displaying an SSL certification to your customers, you are telling them that your business takes security seriously and you are taking steps to protect them from identity theft. Not only does this help to protect you from a data breach, but it is also essential for building customer trust. While this may increase costs, most providers offer a verified SSL certificate typically at a low cost or free. Alongside this, consider that failing to use a certification can lead to being penalized by search engines. Google has specifically stated that they have been testing to see whether secure sites tend to rank higher in searches. When they did, they [started using HTTPS and SSL](https://searchengineland.com/google-starts-giving-ranking-boost-secure-httpsssl-sites-199446) as a ranking signal. While this won’t be a primary ranking factor, they have suggested it will become more important over time. ## How to get an SSL certification Every SSL company has a different approach for verifying a website, so your first step should always be getting background information about the company or Certification Authority (CA) that will be providing your SSL. You’ll want to see what their vetting process is and read reviews from other businesses so that you’re sure you’re being protected by a credible source. Once you have decided on using a reputable provider, you will request certification and pay for it. After the payment is completed, the CA will then begin the process of verifying your website. The amount of time this takes can vary, but approval usually takes around an hour.  The time taken depends on the complexity of your business and [the encryption required](https://www.thesslstore.com/blog/understanding-the-encryption-technology-behind-ssl/). Once the certificate is paid for and approved, you can install it and secure your website behind the new web protocol. ## How do you check to see if a website is SSL protected? When customer data is spread across emails, payments, data, and login information, users need to feel that their data is [safe with secure encryption methods](https://privacycanada.net/classical-encryption/). While there may be vulnerabilities on their side, such as using a poorly secured browser, it builds confidence if they know you’ve taken steps to protect your organization and their data. Users also want to be sure that any website that they visit and use to make purchases has been thoroughly vetted and confirmed to be legitimate. Here are some methods to check that your page, or another company’s, is SSL protected: 1. A padlock symbol will appear on the far left side of the browser bar. If this symbol is broken or absent, this indicates the page is not secured by an SSL. This symbol can be clicked and it will provide more information about the company that is connected to the website. 2. The URL will begin with “https”, which indicates that users are securely connected. HTTP (hypertext transfer protocol) was the old standard for websites, and the addition of S indicates the increased level of security. This is essential when websites are transmitting sensitive information such as credit card details, especially when your website is [built on vulnerable platforms](https://really-simple-ssl.com/hardening-your-websites-security/). 3. The address bar will sometimes have a green background color that indicates it has gone through additional layers of vetting. This is typically referred to as extended validation. ## Conclusion Small business owners have multiple reasons to install SSL certificates as part of their overall plan to [mitigate cybersecurity risks](https://www.atlantic.net/hipaa-compliant-hosting/how-to-best-mitigate-cybersecurity-risks-and-protect-your-data/). If they are taking payments online, they want to make sure they limit the risk of a data breach by making sure payments take place over a secure connection. Even if your business doesn’t handle payments online, securing your employee’s connections helps to ensure business-critical data isn’t at risk of being stolen in a data breach. By installing an SSL, you help to keep your business network and customers safe – a move that will improve trust in your company and keep your business secure from cybersecurity threats. To learn more about how Atlantic.Net can help you secure your [web hosting server](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/) with an SSL certificate, contact our sales team today at [sales@atlantic.net](mailto:sales@atlantic.net). --- # How to Copy Files and Directories in Linux > URL: https://www.atlantic.net/vps-hosting/how-to-copy-files-and-directories-in-linux/ | Published: 2020-06-18 | Updated: 2026-03-02 | Author: Hitesh Jethva If you are a system administrator, copying files and directories is one of the most common tasks in your day-to-day work. The cp command is a basic Linux command used for copying files and directories from one location to another. By default, the cp command is available in almost all Unix- and Linux-like operating systems. In this tutorial, we will show you how to use the cp command to copy files and directories in Linux. ## The cp Command Options The basic syntax of the cp command is shown below: ``` cp [OPTION] [SOURCE] [DESTINATION] ``` A brief explanation of each available option is shown below: - **-a :** Copy files and directories recursively and preserve links. - **-i :** You will be prompted before overwriting any existing file on the destination. - **-r :** Copy directory recursively. - **-f :** Remove an existing destination file if it can not be opened. - **-u :** Copy only when the SOURCE file is newer. ## Copy a File to Directory If you want to copy a single file named /etc/crontab to the /mnt directory, run the following command: ``` cp /etc/crontab /mnt ``` You can now verify it with the following command: ``` ls -l /mnt ``` You should see your file in the following output: ``` -rw-r--r-- 1 root root 1042 Jun 21 11:32 crontab ``` ## Copy Multiple Files to Directory If you want to copy multiple files named /etc/hosts and /etc/hostname at the same time to the /mnt directory, run the following command: ``` cp /etc/hosts /etc/hostname /mnt ``` If you want to display verbose output during the copying process, run the following command: ``` cp -v /etc/hosts /etc/hostname /mnt ``` You should see the following output: ``` '/etc/hosts' -> '/mnt/hosts' '/etc/hostname' -> '/mnt/hostname' ``` ## Copy a File Interactively If you want to copy a file interactively, use the option -i with cp command. This option will prompt you before copying the file to the destination directory if the same file already exists. ``` cp -i /etc/crontab /mnt ``` You should see the following output: ``` cp: overwrite '/mnt/crontab'? yes ``` If you don’t want to overwrite an existing file, you can use the option -n. ``` cp -vn /etc/crontab /mnt ``` This will not prompt for the overwrite and also will not overwrite the existing file. ## Copy a Directory Recursively You can use option -r with cp command to copy files and directory recursively. ``` cp -r /etc/apache2 /mnt ``` You can also use -a option to archive the files and directory during the copy. ``` cp -ar /etc/apache2 /mnt ``` ## Preserve mode, ownership, and timestamps If you want to preserve mode, ownership, and timestamps after copying files and directories, you can use -p option: ``` cp -arp /etc/apache2 /opt ``` ## Backup a Destination File By default, the cp command will overwrite the file on the destination directory if the same file exists. In this case, you can use –backup option to back up any existing destination file during the copying process. ``` cp --backup=simple -v /etc/hosts /mnt ``` You should see the following output: ``` '/etc/hosts' -> '/mnt/hosts' (backup: '/mnt/hosts~') ``` ## Copy Multiple Files from One Directory to Another You can also copy multiple files from one directory to another using the *. For example, if you want to copy all PHP files from the /var/www/wordpress directory to the /mnt directory, you can copy them with the following command: ``` cp -r /var/www/wordpress/*.php /mnt/ ``` This command will find all files with .php extension in the /var/www/wordpress/ directory and copy them into the /mnt directory. ## Conclusion In this guide, you learned how to use the cp command to copy files and directories. Get started with the cp command today on a [Linux VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Schedule Cron Jobs with Crontab > URL: https://www.atlantic.net/vps-hosting/how-to-schedule-cron-jobs-with-crontab/ | Published: 2020-06-19 | Updated: 2025-09-19 | Author: Hitesh Jethva Cron is a time-based job scheduling daemon in Linux-based operating systems. It is used to schedule specific tasks to run periodically at fixed times, dates, or intervals. It is very similar to the Windows task scheduling utility and is very useful for routine tasks including: - Daily backups - System scanning - Automated system maintenance The cron daemon runs in the background and continuously checks the /etc/crontab file, and /etc/cron.*/ directories. ## Crontab Syntax The basic syntax of crontab file is shown below: ``` M H DOM MON DOW USER COMMAND * * * * * root command(s) - - - - - | | | | | | | | | ----- Day of week (0 - 7) (Sunday=0 or 7) | | | ------- Month (1 - 12) | | --------- Day of month (1 - 31) | ----------- Hour (0 - 23) ------------- Minute (0 - 59) ``` - **Minutes (M)** specified as a number from 0 to 59. - **Hours (H)** specified as numbers from 0 to 23. - **Days of the month (DOM)** specified as numbers from 1 to 31. - **Months (MON)** specified as numbers from 1 to 12. - **Days of the week (DOW)** specified as numbers from 0 to 7, with Sunday represented as either/both 0 and 7. ## Crontab Commands Some commonly used crontab commands are shown below: - crontab -e : Used to edit or create a new crontab file. - crontab -l : Used to display the content of the crontab file. - crontab -i : Used to remove the current crontab file with a prompt before removal. - crontab -r : Used to remove the current crontab file without prompt. - crontab -u : Used to edit other user’s crontab file. ## 1. Schedule a cron to execute at 10 AM Daily task If you want to have a script named /opt/test.sh run every day at 10 AM, run the following command: ``` crontab -e ``` Add the following line: ``` 0 10 * * * /bin/sh /opt/test.sh ``` ## 2. Schedule a cron to execute on every 5 minutes To run a test.sh script every 5 minutes, redirect the standard output to /dev/null, and send errors to a specified email address, run the following command: ``` crontab -e ``` Add the following line: ``` MAILTO=admin@example.com */5 * * * * /bin/sh /opt/test.sh > /dev/null ``` ## 3. Schedule a cron to execute on every day, every hour, on the hour from 10 AM to 6 PM To run a test.sh script every day, every hour, on the hour from 10 AM to 6 PM, run the following command: ``` crontab -e ``` Add the following line: ``` 00 10-18 * * * /bin/sh /opt/test.sh ``` ## 4. Schedule a cron to execute at 10 AM on the first of every month To run a test.sh script at 10 AM on the first of every month, run the following command: ``` crontab -e ``` Add the following line: ``` 00 10 1 * * /bin/sh /opt/test.sh ``` ## 5. Schedule a cron to execute at 10 minutes after midnight and every three hours after that, every day To run a test.sh script at 10 minutes after midnight and every 3 hours after that, every day, run the following command: ``` crontab -e ``` Add the following line: ``` 10 0-23/3 * * * /bin/sh /opt/test.sh ``` ## 6. Schedule a cron to execute on specific days To run a test.sh script each Monday and Friday at 6 PM, run the following command: ``` crontab -e ``` Add the following line: ``` 0 18 * * mon,fri /bin/sh /opt/test.sh ``` ## 7. Schedule a cron to execute multiple scripts To run a test.sh and test1.sh script at a 2-hour interval, run the following command: ``` crontab -e ``` Add the following line: ``` 0 */2 * * * /bin/sh /opt/test.sh; /bin/sh /opt/test1.sh ``` ## 8. Schedule a cron to execute every week, month or year To run a test.sh every week, add the following line: ``` @weekly /bin/sh /opt/test.sh ``` To run a test.sh every month, add the following line: ``` @monthly /bin/sh /opt/test.sh ``` To run a test.sh every year, add the following line: ``` @yearly /bin/sh /opt/test.sh ``` ## Conclusion In the above guide, you learned what cron is and how to use it, with several examples. Start using cron jobs to automate daily tasks today with [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Backup and Restore a Database in PostgreSQL > URL: https://www.atlantic.net/vps-hosting/how-to-backup-and-restore-database-in-postgresql/ | Published: 2020-06-22 | Updated: 2023-11-21 | Author: Hitesh Jethva PostgreSQL is free, open-source, and one of the most popular relational database management systems, powering millions of applications. Suppose you are a database administrator using PostgreSQL in a production environment. In that case, it is essential to back up your database so you can quickly restore your system if your database is lost. PostgreSQL has built-in utilities to create or restore the database backup by default. There are several ways to backup and restore your PostgreSQL databases. With PostgreSQL, you can easily take a full, incremental, or continuous backup. You can use the pg_dump utility to back up the PostgreSQL database. This function allows you to back up a local database and restore it on a remote database simultaneously. In this tutorial, we will show you how to back up and restore the PostgreSQL database in Linux. ## Understand the Basic Syntax of pg_dump PostgreSQL comes with built-in utilities called pg_dump for quickly creating and restoring backups. The basic syntax of the pg_dump command is shown below: ``` pg_dump [OPTION]... [DBNAME] ``` A brief explanation of each option is shown below: **-d, –dbname=DATABASENAME :** Used to specify the database that you want to back up. **-h, –host=HOSTNAME :**  Used to specify the hostname of your database server. **-U, –username=USERNAME :** Used to specify the PostgreSQL username. **-w, –no-password :** Used to ignore the password prompt. **-p, –port=PORT :** Used to specify the PostgreSQL server port number. **-W, –password :** Used to force password prompt. **–role=ROLENAME :** SET ROLE before the dump. ## Backup and Restore a Single Database You can back up and restore a single database using the pg_dump utility. The basic syntax to back up a single database is shown below: ``` pg_dump -d [source-database] -f [database_backup.sql] ``` For example, to back up a single database named testdb and generate a backup file named testdb_backup.sql, run the following command: ``` su - postgres pg_dump -d testdb -f testdb_backup.sql ``` You can also restore a single database using psql command. The basic syntax to restore a single database is shown below: ``` psql -d [destination_database] -f [database_backup.sql] ``` For example, to restore a single database named testdb from a backup file named testdb_backup.sql, run the following command: ``` su - postgres psql -d testdb -f testdb_backup.sql ``` You should get the following output: ``` SET SET SET SET SET set_config ------------ (1 row) SET SET SET SET ``` If you want to stop the database restore process in case an error occurs, run the following command: ``` psql -d testdb --set ON_ERROR_STOP=on -f testdb_backup.sql ``` **Note :** Before restoring any database, it is recommended to terminate all connections to that database and prepare the backup file. ## Backup and Restore All Databases You can [back up all databases in PostgreSQL](https://airbyte.com/tutorials/postgres-replication) using pg_dumpall utility. The basic syntax to backup all databases as shown below: ``` pg_dumpall -f [alldatabase_backup.sql] ``` For example, to back up all databases in PostgreSQL and generate a backup file named alldb_backup.sql, run the following command: ``` pg_dumpall -f alldb_backup.sql ``` To restore all databases from a backup file named alldb_backup.sql, run the following command: ``` psql -f alldb_backup.sql ``` ## Backup and Restore Single Table PostgreSQL also allows you to back up a single table from the specific database. You can achieve this using the following syntax: ``` pg_dump -d [source-database] -t [table_name]-f [dbtable_backup.sql] ``` For example, to back up a table named mytab from the database named testdb and generate a backup file named testdb_mytab.sql, run the following command: ``` pg_dump -d testdb -t mytab  -f testdb_mytab_backup.sql ``` If you want to restore this table from the backup file, run the following command: ``` psql -d testdb -f testdb_mytab_backup.sql ``` ## Backup and Restore Compressed Database You can also back up the PostgreSQL database and compress it in .gz format to reduce the backup size. To take a back up of database named testdb and generate a compressed backup file named testdb_compressed.sql.gz, run the following command: ``` pg_dump -d testdb | gzip > testdb_compressed.sql.gz ``` You can also restore the backup from the compressed file using the following command: ``` gunzip -c testdb_compressed.sql.gz | psql  -d testdb ``` ## Conclusion In the above guide, you learned several ways to backup and restore a PostgreSQL database to help you perform day-to-day database backup operations. Get started today with a PostgreSQL database on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Secure MongoDB 4 in CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-secure-mongodb-4-in-centos-8/ | Published: 2020-06-23 | Updated: 2023-11-17 | Author: Hitesh Jethva MongoDB is a cross-platform NoSQL database system written in C++. MongoDB is different from traditional table-based SQL databases like MySQL and PostgreSQL and is specially designed for high-volume data storage. MongoDB uses JSON-like documents with dynamic schemas and does not require a predefined schema before you add data to a database. MongoDB is free, open-source, and comes with a rich set of features including, storage, data replication, Ad-hoc queries, load balancing, and many more. In this tutorial, we will explain how to install and secure MongoDB on CentOS 8. ## Step 1 – Add the MongoDB Repository By default, MongoDB is not available in the CentOS 8 default repository, so you will need to create a repo file for MongoDB. You can create it with the following command: ``` nano /etc/yum.repos.d/mongodb-org.repo ``` Add the following lines: ``` [mongodb-org-4.2] name=MongoDB Repository baseurl=https://repo.mongodb.org/yum/redhat/$releasever/mongodb-org/4.2/x86_64/ gpgcheck=1 enabled=1 gpgkey=https://www.mongodb.org/static/pgp/server-4.2.asc ``` Save and close the file when you are finished. Next, you can proceed to install MongoDB in your system. ## Step 2 – Install MongoDB Now, you can install the MongoDB by simply running the following command: ``` dnf install mongodb-org -y ``` Once the installation has been completed, start the MongoDB service and enable it to start after system reboot with the following command: ``` systemctl start mongod systemctl enable mongod ``` You can now check the status of the MongoDB service using the following command: ``` systemctl status mongod ``` You should see the following output: ``` ● mongod.service - MongoDB Database Server   Loaded: loaded (/usr/lib/systemd/system/mongod.service; enabled; vendor preset: disabled)   Active: active (running) since Fri 2020-04-10 10:58:18 EDT; 7s ago     Docs: https://docs.mongodb.org/manual Process: 2904 ExecStart=/usr/bin/mongod $OPTIONS (code=exited, status=0/SUCCESS) Process: 2902 ExecStartPre=/usr/bin/chmod 0755 /var/run/mongodb (code=exited, status=0/SUCCESS) Process: 2899 ExecStartPre=/usr/bin/chown mongod:mongod /var/run/mongodb (code=exited, status=0/SUCCESS) Process: 2897 ExecStartPre=/usr/bin/mkdir -p /var/run/mongodb (code=exited, status=0/SUCCESS) Main PID: 2906 (mongod)   Memory: 77.0M   CGroup: /system.slice/mongod.service           └─2906 /usr/bin/mongod -f /etc/mongod.conf Apr 10 10:58:17 centos8 systemd[1]: Starting MongoDB Database Server... Apr 10 10:58:17 centos8 mongod[2904]: about to fork child process, waiting until server is ready for connections. Apr 10 10:58:17 centos8 mongod[2904]: forked process: 2906 Apr 10 10:58:18 centos8 mongod[2904]: child process started successfully, parent exiting Apr 10 10:58:18 centos8 systemd[1]: Started MongoDB Database Server. ``` Now, MongoDB is running and listening on port 27017. You can verify it with the following command: ``` netstat -pnltu | grep 27017 ``` You should get the following output: ``` tcp        0      0 127.0.0.1:27017         0.0.0.0:*               LISTEN      2906/mongod ``` You can also access the MongoDB shell with the following command: ``` mongo ``` You should get the following output: ``` MongoDB shell version v4.2.5 connecting to: mongodb://127.0.0.1:27017/?compressors=disabled&gssapiServiceName=mongodb Implicit session: session { "id" : UUID("b0f7656f-f939-4f50-87d2-01cbeca0849a") } MongoDB server version: 4.2.5 Welcome to the MongoDB shell. For interactive help, type "help". For more comprehensive documentation, see            http://docs.mongodb.org/ Questions? Try the support group            http://groups.google.com/group/mongodb-user Server has startup warnings: 2020-04-10T10:58:18.521-0400 I  CONTROL  [initandlisten] 2020-04-10T10:58:18.521-0400 I  CONTROL  [initandlisten] ** WARNING: Access control is not enabled for the database. 2020-04-10T10:58:18.521-0400 I  CONTROL  [initandlisten] **          Read and write access to data and configuration is unrestricted. 2020-04-10T10:58:18.521-0400 I  CONTROL  [initandlisten] 2020-04-10T10:58:18.521-0400 I  CONTROL  [initandlisten] 2020-04-10T10:58:18.521-0400 I  CONTROL  [initandlisten] ** WARNING: /sys/kernel/mm/transparent_hugepage/enabled is 'always'. 2020-04-10T10:58:18.521-0400 I  CONTROL  [initandlisten] **        We suggest setting it to 'never' 2020-04-10T10:58:18.522-0400 I  CONTROL  [initandlisten] --- Enable MongoDB's free cloud-based monitoring service, which will then receive and display metrics about your deployment (disk utilization, CPU, operation statistics, etc). The monitoring data will be available on a MongoDB website with a unique URL accessible to you and anyone you share the URL with. MongoDB may use this information to make product improvements and to suggest MongoDB products and deployment options to you. To enable free monitoring, run the following command: db.enableFreeMonitoring() To permanently disable this reminder, run the following command: db.disableFreeMonitoring() --- ``` You can exit from the MongoDB shell with the following command: ``` >exit ``` ## Step 3 – Enable MongoDB Authentication By default, authentication is disabled in MongoDB. Any user can interact with the database, and create and destroy databases. It is a good idea to enable authentication in MongoDB. You can enable it by editing mongod.conf file: ``` nano /etc/mongod.conf ``` Add the following line at the end of the file: ``` security: authorization: enabled ``` Save and close the file when you are finished. Then, restart the MongoDB service to apply the changes: ``` systemctl restart mongod ``` ## Step 4 – Create a MongoDB Admin User Next, you will need to create an administrative user with all privileges to perform administrative tasks. First, access the MongoDB shell with the following command: ``` mongo ``` You should get the following output: ``` MongoDB shell version v4.2.5 connecting to: mongodb://127.0.0.1:27017/?compressors=disabled&gssapiServiceName=mongodb Implicit session: session { "id" : UUID("09e0e028-cd26-4f9d-9270-52b938925f99") } MongoDB server version: 4.2.5 ``` Next, change the database to admin with the following command: ``` > use admin ``` Next, create a MongoDB admin user called myadmin with the following command: ``` > db.createUser( { user: "myadmin", pwd: "password", roles: [ { role: "userAdminAnyDatabase", db: "admin" } ] } ) ``` Once the user has been created, you should get the following output: ``` Successfully added user: {            "user" : "myadmin",            "roles" : [                        {                                    "role" : "userAdminAnyDatabase",                                    "db" : "admin"                        }            ] } ``` Next, exit from the MongoDB shell with the following command: ``` >exit ``` ## Step 5 – Verify MongoDB Authentication At this point, MongoDB is configured with authentication. Now you will be required to provide a username and password before interacting with MongoDB. Next, connect the MongoDB without authentication: ``` mongo ``` You should get the following output: ``` MongoDB shell version v4.2.5 connecting to: mongodb://127.0.0.1:27017/?compressors=disabled&gssapiServiceName=mongodb Implicit session: session { "id" : UUID("fecf1846-13fd-4959-91da-5cf323781e13") } MongoDB server version: 4.2.5 ``` Now, run the following command to list MongoDB users: ``` > show users ``` You should get the following error: ``` 2020-04-10T11:08:04.598-0400 E  QUERY    [js] uncaught exception: Error: command usersInfo requires authentication : _getErrorWithCode@src/mongo/shell/utils.js:25:13 DB.prototype.getUsers@src/mongo/shell/db.js:1638:15 shellHelper.show@src/mongo/shell/utils.js:883:9 shellHelper@src/mongo/shell/utils.js:790:15 @(shellhelp2):1:1 ``` This demonstrates that you can not list the users without authenticating. Now, exit from MongoDB with the following command: ``` >exit ``` ## Step 6 – Access MongoDB with Administrative User Now, let’s connect to the MongoDB with the administrative user: ``` mongo -u myadmin -p --authenticationDatabase admin ``` You will be asked to provide your admin password as shown below: ``` MongoDB shell version v4.2.5 Enter password: ``` Provide your admin password and hit **Enter**. You should get the following output: ``` connecting to: mongodb://127.0.0.1:27017/?authSource=admin&compressors=disabled&gssapiServiceName=mongodb Implicit session: session { "id" : UUID("a39f723c-f1b5-4c93-9e67-ff82379dfb62") } MongoDB server version: 4.2.5 ``` Next, change the database to admin and list the users with the following command: ``` > use admin > show users ``` You should get the following output: ``` {            "_id" : "admin.myadmin",            "userId" : UUID("bcd920c1-63fd-4b82-a8a6-eb6515d51a34"),            "user" : "myadmin",            "db" : "admin",            "roles" : [                        {                                    "role" : "userAdminAnyDatabase",                                    "db" : "admin"                        }            ],            "mechanisms" : [                        "SCRAM-SHA-1",                        "SCRAM-SHA-256"            ] } ``` Now, exit from the MongoDB shell with the following output: ``` > exit ``` ## Conclusion In the above guide, we learned how to install MongoDB on CentOS 8. We have also shown how to enable MongoDB authentication and create an administrative user. Your MongoDB on your Atlantic.Net VPS is now secured with username and password – if you don’t have a VPS from Atlantic.Net, get started with [VPS hosting](https://www.atlantic.net/vps-hosting/) today to install MongoDB! --- # How To Secure PostgreSQL Server > URL: https://www.atlantic.net/vps-hosting/how-to-secure-postgresql-server/ | Published: 2020-06-24 | Updated: 2023-11-27 | Author: Hitesh Jethva PostgreSQL, also known as Postgres, is a general-purpose object-relational database management system. It is one of the most advanced open-source databases available. However, there are many security concerns and potential vulnerabilities if the application is not secured correctly. If you are a system or database administrator, you need to know how to protect Postgres prior to going into production. In this tutorial, we will show you how to secure the PostgreSQL server on Ubuntu18.04. ## Step 1 – Install PostgreSQL By default, the PostgreSQL server package is available in the Ubuntu 18.04 default repository. You can install it by running the following command: ``` apt-get update -y apt-get install postgresql postgresql-contrib -y ``` Once the installation has been completed, start the PostgreSQL server and enable it to start at reboot: ``` systemctl start postgresql systemctl enable postgresql ``` ## Step 2 – Create Database and User Next, you will need to create a database and user for testing purposes. First, log in to PostgreSQL shell with the following command: ``` sudo -i -u postgres psql ``` You should see the following output: ``` psql (10.12 (Ubuntu 10.12-0ubuntu0.18.04.1)) Type "help" for help. postgres=# ``` Next, create a user named testuser and set the password. ``` postgres=# CREATE USER testuser WITH PASSWORD 'password'; ``` Next, create a database named testdb and grant full access to the new user: ``` postgres=# CREATE DATABASE testdb OWNER testuser; ``` Next, exit from the PostgreSQL shell with the following command: ``` postgres=# \q ``` ## Step 3 – Configure Listening Address By default, the PostgreSQL server is listening on the localhost and can not be accessed from outside the network. For the production environment, you will need to configure PostgreSQL to listen on a public interface. You can change this setting by editing the file /postgresql.conf: ``` nano /etc/postgresql/10/main/postgresql.conf ``` Find the following line: ``` #listen_addresses = 'localhost' ``` Replace it with the following: ``` listen_addresses = 'localhost,your-server-ip' ``` Save and close the file when you are finished. Then, restart the PostgreSQL service to implement the changes: ``` systemctl restart postgresql ``` ## Step 4 – Configure the Allowed Hosts For better security, it is recommended to allow only specific IPs to access and modify the PostgreSQL database. You can do it by editing the file pg_hba.conf: ``` nano /etc/postgresql/10/main/pg_hba.conf ``` Find the following line: ``` # local      DATABASE  USER  METHOD  [OPTIONS] ``` Add the following line below the above line: ``` host  testdb  testuser   client-ip-address/32   md5 ``` Save and close the file when you are finished. Then, restart the PostgreSQL service to implement the changes: ``` systemctl restart postgresql ``` **Where:** **host** : host is a plain or SSL-encrypted TCP/IP socket. **database** : testdb is the name of the database the host can connect to. **user** : testuser is the name of the user that is allowed to make the connection. **address** : client-ip-address/32 specify the IP address of the client computer. **auth-method** : md5 is the name of the authentication method. ## Step 5 – Configure UFW Firewall By default, the UFW firewall comes pre-installed in all Debian based distributions. If not installed, you can install it with the following command: ``` apt-get install ufw -y ``` Next, it is recommended to configure the UFW firewall rule to grant access to the PostgreSQL default port 5432 to only the client’s IP. **IMPORTANT:** Before starting, you will need to allow incoming SSH connection through UFW, as that will make you lose shell access. You will be locked and unable to connect to your instance. You can allow SSH service using the following command: ``` ufw allow ssh ``` Next, enable the UFW firewall with the following command: ``` ufw enable ``` Next, allow PostgreSQL port 5432 to only client’s IP address using the following command: ``` ufw allow from client-ip-address to any port 5432 ``` Next, check the status of the UFW rule with the following command: ``` ufw status ``` You should get the following output: ``` Status: active To                         Action      From --                         ------      ---- 22/tcp                     ALLOW       Anywhere                 5432                       ALLOW       client-ip-address 22/tcp (v6)                ALLOW       Anywhere (v6) ``` ## Step 6 – Verify the Remote Connection At this point, the PostgreSQL server is secured and accessible only from the client’s IP. To verify it, connect your PostgreSQL database from the client’s system: ``` psql -U testuser -h postgres-server-ip -d testdb ``` You will be asked to provide the password for testuser, as shown below: ``` Password for user testuser: ``` Type your password and hit **Enter**. Once the connection has been established, you should get the following output: ``` psql (9.3.24, server 10.12 (Ubuntu 10.12-0ubuntu0.18.04.1)) WARNING: psql major version 9.3, server major version 10.         Some psql features might not work. SSL connection (cipher: ECDHE-RSA-AES256-GCM-SHA384, bits: 256) Type "help" for help. testdb=> ``` That’s it for now. ## Conclusion In the above guide, you learned how to secure the PostgreSQL by configuring PostgreSQL to grant access to only specific hosts. You have also learned how to configure UFW to allow connections only from specific hosts. You should now be able to protect your PostgreSQL server from certain kinds of attacks. Get started today with [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Protect Business Data When Employees Are Working from Home > URL: https://www.atlantic.net/hipaa-compliant-hosting/how-to-protect-business-data-when-employees-are-working-from-home/ | Published: 2020-06-29 | Updated: 2025-09-19 | Author: Richard Bailey Over the last decade, the number of employees working from home has steadily increased. Estimates suggest that [1 in 10 US citizens](https://www.gensler.com/uploads/document/695/file/Gensler-US-Work-From-Home-Survey-2020-Briefing-1.pdf) had regularly worked from home up to 2019. Understandably, since the outbreak of Covid-19 in the first half of 2020, this figure has grown exponentially, a trend that is likely to continue for the foreseeable future. Governments around the world have encouraged employees to work from home wherever possible. Key frontline workers are still required to continue their occupations, and millions have unfortunately lost their jobs, with tens of millions furloughed on government financial aid. Some [reporters](https://www.bloomberg.com/news/articles/2020-02-02/coronavirus-forces-world-s-largest-work-from-home-experiment) are referring to this shift in working behavior as the greatest ever working-from-home experiment. With this paradigm shift of working behavior, organizations must consider the additional risks and [security concerns](https://www.swiftlane.com/best-access-control-systems/) to protect themselves from data breaches, fraud, ransomware, and exploitation. Below are some of Atlantic.Net’s key recommendations to follow to help ensure that business data is protected when employees are [working from home](https://www.felixhomes.com/blog/tips-for-working-from-home). ## Protect User Devices The biggest threat to data integrity with home working is seemingly obvious; when an employee works from home, business data is necessarily accessed, processed, and updated from that employee’s home. Businesses must prepare for the change in working environments to help protect company assets. People’s homes do not have [physical security controls](https://www.pelco.com/blog/physical-security-guide) found in the workplace such as building access cards and 24×7 security guards. So what can be done to protect a user device? - Employees should only use devices provided by the business, such as laptops, desktops, and cell phones. Bring-your-own-device (BYOD) practices should be discouraged. If an employee uses a personal device, protecting business information becomes a significant challenge. - Employee laptops must be protected by automatic security updates, such as Windows Update and application updates. - Employees must not be allowed to download or install any software without the administrator’s permission. - Antivirus should be rolled out to all devices. Daily updates to Antivirus definitions must also be enforced and security controls should be put in place to prevent users from tampering with AV, such as uninstalling AV or stopping critical services. - User devices must be secured using group policies that enforce automatic screen locks. - Encrypt employee laptops; this ensures that if a device is stolen, the hard disk will be unreadable unless the user has the security key. - If employees use WIFI in their home network, ensure that security controls are set to WPA2 or higher. - Multi-Factor Authentication has become a must, as usernames and passwords are easily phished and stolen.  Atlantic.Net is uniquely positioned to help businesses tackle the distinct problems working from home can create. We currently provide an extensive number of Remote Desktop services that allow our clients to access our cloud platforms. This approach provides secure remote access to a centralized, easy-to-manage server or desktop. This procedure helps greatly with regulated industries; for example, those impacted by [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/), HITECH, or SOC compliance requirements. Atlantic.Net’s data centers are already compliant with these standards, and home workers can connect to our secure infrastructure over a VPN. You, the customer, do not have to invest huge amounts in infrastructure to provide a service to your employees; simply leverage the servers we offer ready-to-go! ## Define a Strong Password Policy Passwords are the first line of defense on a computer network; you might be surprised by how often [easy passwords](https://edition.cnn.com/2019/04/22/uk/most-common-passwords-scli-gbr-intl/index.html) are compromised by hackers. Businesses can protect against this by using technical measures that enforce password complexity. - A strict password policy should be defined that enforces complex passwords. - Password generators can be used, but as a rule of thumb, try to include at least 3 different words, a mixture of upper and lower case, and some special characters (*&^%%$£!”). - Use different passwords for each of your accounts and note the password in a secured database application. - Protect the secured database application with encryption keys and another strong password. Set the password to reset every few weeks. These user-friendly features are available when installing the password application. - Consider saving your password database to secure cloud storage, such as OneDrive for Business Personal Vault for added security. - Utilize Multi-Factor Authentication (MFA or 2FA) wherever possible to increase the security level of your user’s logins.  MFA makes phishing and brute force attacks extremely hard for hackers. All of Atlantic.Net’s infrastructure services provide best practice security for our clients, and our services not only are resilient, but also are built with security at the forefront of the design process. We offer compliant storage and databases that can be leveraged with guaranteed security hardening. ## Create a Work-from-Home Policy Businesses need to work together with HR and technology teams to create an enforceable work-from-home policy. Businesses must always trust employees, and a work-from-home policy should only create boundaries of acceptable use of computer systems. Businesses must ensure that they provide employees with the appropriate technology to work from home. This typically includes: - Laptops - Computer hardware - VPN network access - Access to email systems - Collaboration tools (Skype / Teams / JIRA) - Applications needed by the employee. Businesses can then secure these assets to protect data integrity. Employees should find a dedicated workspace at home with minimal distractions, away from people that might read or overhear sensitive business conversations. Any business compliance regulations are still enforceable for home working, such as data protection laws or healthcare legislation. Ensure children or relatives do not use company assets. If you’re looking for assistance with maintaining data security in a work-from-home environment, [contact Atlantic.Net](https://www.atlantic.net/about-us/corporate-contact/) for assistance with managed hosting services and IT support. --- # How to Securely Transfer Files Using SCP > URL: https://www.atlantic.net/vps-hosting/how-to-securely-transfer-files-using-scp/ | Published: 2020-06-30 | Updated: 2023-11-18 | Author: Hitesh Jethva SCP stands for secure copy. It is a Linux command-line utility used to securely copy files and directories between servers. SCP uses the SSH protocol, so it requires a password or password less authentication between servers. With SCP, you can copy files between two remote hosts from your local system, as well as copy files between local and remote hosts. In this tutorial, we will show you how to use the SCP command with examples. ## 1. SCP Syntax The basic syntax of the SCP command is shown below: ``` scp [option] user@source-ip:/file_or_directory user@dest-ip:/directory ``` **user:** Name of the user. **source-ip:** IP address of the system from where you want to copy files or directories. **dest-ip:** IP address of the system destination system. Some of the options used in scp command are listed below: **-P:** Specify the ssh port number of the destination host. **-r:** Used to copy files and directories recursively. **-v:** Used to display verbose output during file transfer. **-C:** Used to enable file compression. **-i:** Specify the SSH key. **-l:** Used to limit the bandwidth while copying. **-p:** Used to preserve permissions, modes, and access time of files while copying. ## 2. Copying a File from Local to Remote Host If you want to copy a file named /etc/rc.local from localhost to the remote host (172.20.10.3) in /mnt directory, run the following command: ``` scp /etc/rc.local root@172.20.10.3:/mnt/ ``` You should see the following output: ``` root@172.20.10.3's password: rc.local                                                                                      100%  306     0.3KB/s   00:00 ``` If you want to copy multiple files (in this example we will use */etc/fstab*and */etc/hosts,*and copy them to the remote host (172.20.10.3) into /mnt directory), run the following command: ``` scp /etc/fstab /etc/hosts root@172.20.10.3:/mnt/ ``` You should see the following output: ``` root@172.20.10.3's password: fstab                                                                                         100%  628     0.6KB/s   00:00   hosts                                                                                         100%  249     0.2KB/s   00:00 ``` ## 3. Copying Files and Directories Recursively You can use the recursive option -r with SCP to copy the entire directory from one system to another. For example, to copy the directory named */var/log/apache2* from localhost to the remote host (172.20.10.3) in /mnt directory recursively, run the following command: ``` scp -r /var/log/apache2 root@172.20.10.3:/mnt/ ``` You should see the following output: ``` root@172.20.10.3's password: error.log                                                                                      100%    0     0.0KB/s   00:00   access.log.3.gz                                                                      100%   61KB  61.3KB/s   00:00   other_vhosts_access.log                                                            100%    0     0.0KB/s   00:00   access.log.4.gz                                                                        100%  317     0.3KB/s   00:00   error.log.3.gz                                                                           100% 1622     1.6KB/s   00:00 error.log.1                                                                                100% 2352     2.3KB/s   00:00   access.log                                                                                  100%    0     0.0KB/s   00:00   access.log.1                                                                            100% 1287     1.3KB/s   00:00   access.log.2.gz                                                                        100%  239     0.2KB/s   00:00   error.log.2.gz                                                                            100%  246     0.2KB/s   00:00   error.log.5.gz                                                                           100% 1471     1.4KB/s   00:00   error.log.4.gz                                                                           100% 2296     2.2KB/s   00:00 ``` You can also use -v option with SCP to display verbose output during the copying process: ``` scp -vr /var/log/apache2 root@172.20.10.3:/mnt/ ``` ## 4. Copying File from Remote to Local Host If you want to copy a file named /etc/hostname from the remote host (172.20.10.3) to the localhost in /opt directory, run the following command: ``` scp root@172.20.10.3:/etc/hostname /opt/ ``` You should see the following output: ``` root@172.20.10.3's password: hostname                                                                                                     100%    6     0.0KB/s   00:00 ``` ## 5. Copying File from one Remote Host to other Remote Host To copy files and directories between two remote hosts, you will need to configure SSH key-based authentication between both remote hosts. After configuring key-based authentication, copy a directory named /var/log from one remote host (172.20.10.3) to the other remote host (172.20.10.4) in /mnt directory, run the following command: ``` scp -r root@172.20.10.3:/var/log root@172.20.10.4:/mnt/ ``` ## 6. Limiting Bandwidth Usage While Copying You can use -l option with SCP to limit the bandwidth during the copying process. For example, to copy a file named google-chrome-stable_current_amd64.deb from localhost to the remote host (172.20.10.3) in /opt directory and limit the bandwidth to 1000 KB/sec (1000×8), run the following command: ``` scp -l 8000 /home/vyom/Downloads/google-chrome-stable_current_amd64.deb  root@172.20.10.3:/opt/ ``` You should see the following output: ``` root@172.20.10.3's password: google-chrome-stable_current_amd64.deb                                                                       100%   60MB   1.0MB/s   01:01 ``` ## 7. Specify Specific Port with SCP In some cases, the SSH port is different on the destination host. In this case, you can use -P option to specify the SSH port. For example, to copy a file named /etc/hosts on the local system to the remote host (172.20.10.3) in /mnt directory using the port 8088, run the following command: ``` scp -P 8088 /etc/hosts root@172.20.10.3:/mnt/ ``` ## 8. Enabling Compression While Copying You can use -C option with SCP to enable compression at source and decompression at the destination host. This can increase the transfer speed on large files. For example, to copy a directory*/var/log/nginx*on the local host to the remote host (172.20.10.3) in /mnt directory with compression, run the following command: ``` scp -r -C /var/log/nginx root@172.20.10.3:/mnt/ ``` You should see the following output: ``` root@172.20.10.3's password: error.log                                                                                      100%    0     0.0KB/s   00:00   access.log.3.gz                                                                        100%  217     0.2KB/s   00:00   error.log.1                                                                                 100%  974     1.0KB/s   00:00   access.log                                                                                 100%    0     0.0KB/s   00:00   access.log.1                                                                              100%   90     0.1KB/s   00:00   access.log.2.gz                                                                        100%  239     0.2KB/s   00:00 ``` ## 9. Preserve Permissions, Modes, and Access Time of Files While Copying You can use -p option with SCP to preserve permissions, access time, and modes during the copying process. For example, to copy a file named *magento-ce-2.3.5-p1-2020-04-24-08-59-28.tar.bz2* on the local host to the remote host (172.20.10.3) in /mnt directory and preserve permissions, access time, and modes, run the following command: ``` scp -p /home/vyom/Downloads/magento-ce-2.3.5-p1-2020-04-24-08-59-28.tar.bz2 root@172.20.10.3:/mnt/ ``` You should see the following output: ``` root@172.20.10.3's password: magento-ce-2.3.5-p1-2020-04-24-08-59-28.tar.bz2                                                              100%  112MB  55.9MB/s   00:02 ``` ## Conclusion In the above guide, you learned how to use SCP to securely transfer files and directories from one server to another. Get started with SCP on a [VPS Hosting](https://www.atlantic.net/vps-hosting/) account with Atlantic.Net today! --- # How to Protect and Secure Website Infrastructure > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-protect-and-secure-website-infrastructure/ | Published: 2020-07-10 | Updated: 2024-09-11 | Author: Richard Bailey There are four primary Web Server applications used to host websites: Apache HTTP Server, Microsoft IIS, Nginx, and LiteSpeed. While there are others, these four are by far the most popular. You can deploy any of these web servers in the Atlantic.Net Cloud Platform. We have an extensive selection of detailed [step-by-step procedures](https://www.atlantic.net/blog/#gsc.tab=0&gsc.sort=)explaining how to deploy and secure these applications; [simply search the Atlantic.Net blog](https://www.atlantic.net/blog/#gsc.tab=0&gsc.sort=). ## Why Should You Secure Your Website? There are an estimated [2 billion websites](https://hostingtribunal.com/blog/how-many-websites/#gref) on the World Wide Web, ranging from sites as simple as single homepages to huge, popular social media and sprawling eCommerce platforms. However, for any type of website, web security should be at the top of the priority list. Web security is defined as “the protection of personal and organizational public-facing websites from cyberattacks.” There are various threats such as website vandalism, hacking backend services, and potentially stealing business data. Ransomware and malware attacks are another serious threat. Victims of these kinds of cyberattacks often must spend a significant amount of money to resolve them and are likely to lose a lot of customer confidence, especially if data is compromised. ## Create a Secured Infrastructure The keys to website security are to minimize the attack surface of the website infrastructure and place controls over how network traffic traverses the platform. A security-first architectural design is the only recommended way to protect web servers hosted on-premise or in the cloud. If you decide not to go with [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/), VPS hosting is a very popular platform choice when designing websites, but it is important to check that your cloud provider has already done the hard work of creating a security-defined infrastructure as part of the VPS service. Most web designers are happy to let someone else manage the infrastructure so they can focus on creating excellent web content, [designing a logo](https://www.brandcrowd.com/logo-maker), etc. There are many distinct layers to web server infrastructure, typically comprised of the front end, the mid-tier, and the backend. Multi-tier web applications are arguably the most common configuration, wherein the infrastructure is usually protected by a load-balancer with enhanced security configuration and a network firewall at the network edge perimeter. Only the front end web server(s) are externally-facing to the public internet within a DMZ, with the application and database servers logically positioned behind additional firewalls inside the core network. The frontend should be protected by proxying TLS traffic through a secured web gateway, preferably virtual appliances such as a software-defined HAProxy; a cloud secured service, such as a [Web Application Firewall (WAF)](https://www.atlantic.net/vps-hosting/waf-web-application-firewall/#gsc.tab=0), will also work well. ## Network Edge Protection Services Edge Services such as [DDoS](https://www.comptia.org/content/guides/what-is-a-ddos-attack-how-it-works) protection, Web Application Firewalls, Website Optimization, and Content Delivery Networks are cloud services that afford consumers great flexibility and added security. Downtime on revenue-generating websites must be avoided at all costs; if Walmart.com suffered downtime of only a few minutes, this would result in [several million dollars](https://www.gremlin.com/ecommerce-cost-of-downtime/)of lost revenue. DDoS, or distributed denial of service, is an attack launched by hackers to overload a web server with fake requests with the intention of bringing the system down or blocking legitimate traffic. The end result is that legitimate users will encounter a slow or offline website. Content Delivery Networks (CDN) reduce the attack surface of your website. User requests for content on your site are cached at the network edge CDN, the result is that your web server has to serve less web content, because the CDN delivers many of the duplicate requests. Atlantic.Net provides our own CDN using servers positioned across key global points. As information travels across the web, our Content Delivery Network caches data and routes traffic according to server proximity, enabling users to reach your content quickly, regardless of their location. The system is easy to set up and offers affordable and predictable pricing. ## Secure Web Gateway (SWG) A secure web gateway (SWG) is essentially the doorkeeper to your web server infrastructure. If you operate an on-premise infrastructure, an SWG is a great way to provide layer 7 termination and in-depth inspection of http/https web traffic to protect against web threats that target businesses. The main difference between an SWG and a network firewall is that the SWG receives the complete request from the client before making a decision on where to send the traffic. This decision is made using predefined security policies and intelligent session termination, whereas a firewall makes decisions on a packet-by-packet basis, with no session termination. It is highly recommended to create strict security policies to manage end-to-end traffic inside the perimeter network. Configure the secured gateway to disable and reject deprecated security cipher suites such as SSLv3, RC4, TLS1, TLS1.1, DES, 3DES, and so on. Such legacy ciphers have been discontinued because there are a huge number of vulnerabilities and exploits embedded in them. Instead, enable a modern cipher suite such as AES or RSA. ## Scan for vulnerabilities Website app servers are susceptible to hacks, exploits, and vulnerabilities. Because malware is a serious risk to websites, the ability to detect and remove malware is essential. Regular file scans and detailed reporting generate a holistic overview of the state of the network. The software that runs websites is constantly evolving and being upgraded to prevent vulnerabilities. Scanning for vulnerabilities, sometimes known as penetration testing or pen testing, is a technique of testing external and internal computer infrastructure against all known vulnerabilities. Vulnerability scans look for known vulnerabilities in your systems and report potential exposures. Penetration tests are intended to exploit weaknesses in the architecture of your IT network and determine the degree to which a malicious attacker can gain unauthorized access to your assets. Atlantic.Net offers vulnerability scans as part of our [managed services offering](https://www.atlantic.net/managed-services/server-management/). We can provide biweekly vulnerability scans and penetration testing for host servers or configured websites, as well as assist with evaluating and interpreting scan results while working with our customers to patch vulnerabilities. Additionally, social engineering can be conducted to test employee’s [susceptibility to ransomware](https://www.atlantic.net/vps-hosting/how-to-prepare-for-ransomware-malware-network-and-file-vulnerabilities/), phishing, or whaling attacks; these tasks are usually completed by an internal security team or outsourced to a managed service provider. ## Other best practices to consider So far, we have mainly referenced hierarchical design decisions for implementing security on your website. There is, of course, much that system administrators can do to increase security awareness. Network engineers are needed to monitor and update rules for Web Application Firewalls (WAF) and Secure Gateways (SWG). The network layer can prevent [SQL injections, cross-site scripting, vulnerability probing](https://www.tripwire.com/state-of-security/featured/web-hosting-security-best-practices/), etc. Atlantic.Net offers a robust Web Application Firewall as part of our Network Edge protection. The WAF examines web traffic looking for suspicious activity; it then automatically filters out illegitimate traffic based on rulesets that Atlantic.Net applies for you or custom rulesets applied at your request. The WAF looks at both GET and POST-based HTTP requests and applies a rule set, such as the ModSecurity core rule set covering the OWASP Top 10 vulnerabilities to determine what traffic to block, challenge or let pass. The operating system is the next entity to be secured. Regardless of whether they are Windows or Linux based, operating systems must be regularly updated, preferably monthly. Default usernames and passwords should be changed, and consider disabling root or administrator accounts in addition to limiting the number of privileged user accounts. In other words, *do not make everyone a domain admin!* The type of website application you host can also affect your security. In all cases, the latest versions of website code should be used; for example, expired and unsupported versions of Java are still surprisingly common. Middleware such as Apache Tomcat, IBM WebSphere, and IIS should be updated regularly and patched for known security issues. Backups are also important, as even the most reliable servers are susceptible to failure, and in the event of a problem, a backup to restore the website is essential. Atlantic.Net offers [one-click backups](https://www.atlantic.net/cloud-platform/backups/) as part of our cloud service, and if you operate a large, revenue-generating website, you should consider [offsite backups](https://www.atlantic.net/resources/documents/brochures/pdf/acp-cloud-backups-atlantic-net-brochure.pdf). Share your vision with us, and we will develop a hosting environment tailored to your needs! Contact an advisor at 866-618-DATA (3282) or fill out the form at the link below. --- # How to Enable User Quotas in cPanel/WHM > URL: https://www.atlantic.net/hipaa-compliant-hosting/how-to-enable-user-quotas-cpanel-whm/ | Published: 2020-07-12 | Updated: 2026-02-28 | Author: Alexander Wise This tutorial will explain how to enable user quotas on Atlantic.Net’s cPanel Cloud Servers. Before we get into the details, let’s do some housekeeping: *Verified on 7/12/20 for cPanel on CentOS 7.2 64-bit* ## Prerequisites - **Atlantic.Net Cloud Account** [Click here to sign up for your free account!](https://cloud.atlantic.net/?page=signup) - **SSH Program** *Don’t have one? Follow the guides below for how to SSH:* [From Windows](https://www.atlantic.net/vps-hosting/how-to-ssh-server-via-linux/) [From Linux/Mac](https://www.atlantic.net/vps-hosting/how-to-ssh-linux-server-windows/) - **Atlantic.Net cPanel Server** *Follow this simple guide for how to quickly create a cPanel server:* ![Create cpanel](https://www.atlantic.net/wp-content/uploads/2017/12/create-cpanel-gif.gif) --- ## Connecting to Your cPanel Server Now it’s time to connect to your server via SSH: ``` ssh root@[IP Address] ``` ## Check If Your System Has Quotas Enabled ``` mount ``` Find the line that says ``` /dev/sda1 ``` and if there is no quota enabled, it will say ``` noquota... /dev/sda1 on / type xfs (rw,relatime,attr2,inode64,noquota) ... ``` ## Edit the default Grub file By editing the default Grub file, we can specify that the file system should have quotas enabled when the system boots up. Edit the default Grub file with your favorite editor: ``` nano /etc/default/grub ``` Modify the following line from: ``` GRUB_CMDLINE_LINUX=”” ``` to: ``` GRUB_CMDLINE_LINUX="rd.lvm.lv=centos/root crashkernel=auto rhgb quiet rootflags=uquota,pquota" ``` *Note: By default, our cPanel Cloud Servers do not have **swap** enabled. If you have enabled it, you can prepend **rd.lvm.lv=centos/swap** before **rd.lvm.lv=centos/root**.* The resulting file should look like this: ``` GRUB_TIMEOUT=5 GRUB_DISTRIBUTOR="$(sed 's, release .*$,,g' /etc/system-release)" GRUB_DEFAULT=saved GRUB_DISABLE_SUBMENU=true GRUB_TERMINAL_OUTPUT="console" GRUB_CMDLINE_LINUX="rd.lvm.lv=centos/root crashkernel=auto rhgb quiet rootflags=uquota,pquota" GRUB_DISABLE_RECOVERY="true" ``` ## Generate the New Grub Configuration File Now that we have edited the default Grub file, we must use it to generate the Grub bootloader configuration file. First, let’s make a backup of our Grub configuration: ``` cp /boot/grub2/grub.cfg /boot/grub2/grub.cfg.bak grub2-mkconfig -o /boot/grub2/grub.cfg ``` If done correctly, the system will let you know you generated the file successfully. ``` Generating grub configuration file ... Found linux image: /boot/vmlinuz-3.10.0-327.10.1.el7.x86_64 Found initrd image: /boot/initramfs-3.10.0-327.10.1.el7.x86_64.img Found linux image: /boot/vmlinuz-0-rescue-17115f95ddd92d410be8cb803e2d845d Found initrd image: /boot/initramfs-0-rescue-17115f95ddd92d410be8cb803e2d845d.img done ``` ## Finishing Up In order for the new changes to take effect, let’s reboot the system: ``` reboot ``` Allow a minute or two for the cPanel server to reboot. Once it has rebooted, SSH back into the server. ``` ssh root@[IP Address] ``` Let’s check **mount** again to see if **quota** shows up now: ``` mount ... /dev/sda1 on / type xfs (rw,relatime,attr2,inode64,usrquota,prjquota) ... ``` As we can now see, user quotas and project quotas are now enabled. You have successfully completed enabling quotas on your Atlantic.Net cPanel Cloud Server! Your next step is to log in to your cPanel’s WHM to setup quotas: https://[your IP address]:2087. There should no longer be any notification about enabling quotas. *Note: If cPanel is telling you quotas are still not enabled for the filesystem, please run the following command in an SSH terminal:* ``` /scripts/fixquotas ``` --- Questions? Comments? Concerns? Let us know in the comments below or email us at cloudsupport@atlantic.net! Interested in a HIPAA-compliant hosting solution in the cloud? Atlantic.Net offers [HIPAA compliant cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) services for healthcare organizations. --- # What Is an Intrusion Detection System and Why Do I Need It? > URL: https://www.atlantic.net/dedicated-server-hosting/what-is-an-intrusion-detection-system-and-why-do-i-need-it/ | Published: 2020-07-14 | Updated: 2025-10-21 | Author: Richard Bailey A proven and reliable cybersecurity strategy is a major driving force behind business decision-making within the modern global organization. Having the ability to protect and secure information technology services enables tech-savvy organizations to prove that they can control and secure the network. Securing business assets is essential to help prevent information exposure or data breaches of confidential business data. ## Monitoring and Preventing Unwanted Traffic That Poses Threats to Your Organization Most industry professionals already know how to protect their infrastructure with network firewalls and a securely architected networking design. A more recent technology, known as an [intrusion detection system](https://www.atlantic.net/managed-services/intrusion-detection-service/), is a software image or hardware-based appliance for the security-conscious organization. It monitors the entire network and [hosting environment](https://www.atlantic.net/dedicated-server-hosting/) by analyzing traffic and network activity throughout a corporate network. An IDS application is sometimes referred to as a security information event management ([SIEM](https://www.esecurityplanet.com/products/siem-tools/)) system. A typical setup includes IDS appliances at various layers of the network, usually at choke points on the perimeter network. Each network packet is monitored and ranked according to a risk policy based upon information concatenated from a vast number of global threat prevention databases.  The global database is used to compare networking data packets with known exploits or vulnerability hashes. This approach enables businesses to be on the forefront of the latest global threat trends and risks within the cybersecurity industry. An IDS solution is designed to monitor and alert against scenarios such as an application or operating system exploit, buffer overflow attacks, unauthorized port scanning, cross-site scripting exploits, and many other vulnerabilities. ## How does an Intrusion Detection System (IDS) work? The first time an IDS is configured and deployed within a networking environment, the IDS will securely scan the network and create a baseline of the current usage scenario of the compute, storage and networking configuration. Over time, the IDS will analyze all network traffic and start to compare changes against the baseline configuration. This enables the IDS to generate an anomaly-based identification intelligence that can work out what traffic is considered a threat. TCP/IP network packets are multiple data objects that traverse the network at a single time. Each packet contains information such as a source and destination IP address, the data itself, information regarding QoS, and how the packet should be handled.  All this information is encapsulated within the packet prior to being transported over the network. The IDS screens each packet, which can help detect intrusions. This is done by comparing intercepted local data packets with information known about previous attacks via the global threat databases. This intelligence can be configured to trigger alerts and automatically raise incident reports which will allow a dedicated security team to identify and respond to suspicious traffic before any damage is done to the infrastructure. The IDS will look for a signature-based flow of traffic that perfectly matches the previously known attack signatures over the network, and it will result in an ALLOW or DENY to the network request. This intelligence is vital to help provide an organization with the opportunity to identify threats and risks. It can help with attack prevention, preparation, and response times by identifying behavior-based network changes. An IDS can also help with infrastructure visibility which enable engineers to manage a network more efficiently by monitoring and blocking unexpected network traffic, such as network traffic over higher port ranges or file transfers at unexpected times of day or night. ## The Atlantic.Net Comprehensive Intrusion Detection System (IDS) To protect our valued clients at both a networking and hosting level, Atlantic.Net provides a dual IDS solution that implements a NIDS (Network Intrusion Detection System) and HIDS (Host Intrusion Detection System) solution. The IDS is placed at strategic points within a network and works with your firewall by inspecting packets that the firewall has already accepted as legitimate. Another IDS resides directly on the network, protecting against local vulnerabilities on the network layer. The first part of our IDS solution is a custom-build NIDS platform created by our experts using industry-leading, open-source technology. As it is based on open-source technology, the Atlantic.Net proprietary NIDS appliance can utilize a community consensus rule database and then customize it to fit the specific needs of the computing environment it protects. Secondly, Atlantic.Net provides the host-based Trend Micro Deep Security HIDS to protect critical infrastructure against network vulnerabilities from the server-side, whether those servers are [dedicated](https://www.atlantic.net/dedicated-server-hosting/), virtual, or cloud. Trend Micro Deep Security includes protection against malware, including ransomware, targeted attacks, and advanced threats such as logging privileged user account access. Both technologies are managed within a unified dashboard interface, allowing Atlantic.Net the ability to review the incident logs that are generated and automatically alert when a threat is identified or suspected. These detailed information logs can be extensive and can add up significantly within a short space of time, so the ability to rank and classify each identified incident is a priceless feature when attempting to get an accurate overview of what is happening on the networking estate. ![](https://www.atlantic.net/wp-content/uploads/2020/07/IPS-Panel-Image.png) With this, we offer excellent reporting facilities built into the IDS solution; the reports can be as granular or as high-level as required. Users can choose to receive weekly or monthly reports summarizing the current infrastructure vulnerabilities.  These reports provide invaluable insight and are a perfect match for clients in regulated industries. The reports are offered in addition to any critical alerts which the Atlantic.Net IDS discovers. To keep your network safe from attackers, Atlantic.Net uses Cisco-developed packet analyzer software that scans your network traffic for malicious activity. As an open-source network intrusion detection system, this software can perform real-time traffic analysis, packet logging on IP networks, protocol analysis, and content searching/matching, and can also be used to detect a variety of attacks. ## Next Steps When you choose to work with Atlantic.Net, you can rest assured that your system will be protected with state-of-the-art IDS software. Our team can install and configure the software on your behalf and monitor your network for operating system fingerprinting attempts, common gateway interface, buffer overflows, server message block probes, and stealth port scans. You will not have to be concerned about updates and reporting. While business is free to innovate, Atlantic.Net will ensure your systems are running safely and smoothly. [Get started with an IDS](https://www.atlantic.net/managed-services/intrusion-detection-service/) from Atlantic.Net today. --- #### Read More About Intrusion Detection - [Intrusion Detection Service](https://www.atlantic.net/managed-services/intrusion-detection-service/) from Atlantic.Net - [Intrusion Detection Systems](https://www.atlantic.net/hipaa-compliant-hosting/intrusion-detection-systems/) from Atlantic.Net - [Penetration Testing Best Practices](https://www.atlantic.net/vps-hosting/best-penetration-testing-practices-you-need-to-know/) --- --- # COVID-19: Will the OCR Exercise Enforcement Discretion and Waive Penalties for HIPAA Violations? > URL: https://www.atlantic.net/hipaa-compliant-hosting/covid-19-will-the-ocr-exercise-enforcement-discretion-and-waive-penalties-for-hipaa-violations/ | Published: 2020-07-14 | Updated: 2024-10-22 | Author: Richard Bailey The global pandemic Covid-19 ([SARS-CoV-2](https://www.who.int/emergencies/diseases/novel-coronavirus-2019/technical-guidance/naming-the-coronavirus-disease-(covid-2019)-and-the-virus-that-causes-it#:~:text=ICTV%20announced%20%E2%80%9Csevere%20acute,on%2011%20February%202020.)) has wreaked havoc around the world for the first half of 2020. The virus’s huge impact on the US Healthcare industry has overloaded physicians, doctors, and other hospital staff who have been caring for the sick or helping keep the hospital lights on 24×7. Non-frontline healthcare workers have been forced to work from home, small clinics have closed, and non-critical patient operations have been canceled. ## Impact of the Pandemic on the Healthcare Industry and HIPAA Regulation Enforcement At the peak of the pandemic, [US hospital emergency room visits were down 42%,](https://www.cidrap.umn.edu/news-perspective/2020/06/emergency-visits-down-42-us-hospitals-reeling-covid-19) accompanied by a seismic shift toward visiting patients at home and conducting telephone or video conferencing appointments and consultation. On the 17th March 2020, the Office for Civil Rights (OCR) announced that [enforcement discretion and waiving penalties for HIPAA violations](https://www.hhs.gov/about/news/2020/03/17/ocr-announces-notification-of-enforcement-discretion-for-telehealth-remote-communications-during-the-covid-19.html) would be introduced. However, it has become evident that this headline-grabbing announcement may have been misinterpreted by some HIPAA covered entities. Atlantic.Net is one of the largest and most successful providers of HIPAA compliant hosting solutions for the US healthcare industry. We have been extremely alarmed by reports that some covered entities have interpreted this news thinking that they do not need to meet HIPAA guidelines during this period of uncertainty. **This interpretation is absolutely not true.** The OCR is *only waiving specific HIPAA enforcement rules to allow greater flexibility when providing healthcare services directly to patients* during these uncertain times. The OCR is not relaxing HIPAA regulation, and covered entities must at all times uphold the integrity of protected health information. ## CMS Blanket Waivers Some of the confusion may have arisen because a number of blanket waivers were introduced by the CMS. The CMS (Center for Medicare and Medicaid Services) [has relaxed a number of rules](https://www.cms.gov/Medicare/Provider-Enrollment-and-Certification/SurveyCertEmergPrep/1135-Waivers) (mostly relating to patient interactions) during the pandemic. Any healthcare facility that has declared an emergency due to Covid-19 is in the scope of the waivers. For example, doctors no longer have to seek patient approval to notify immediate family if they are affected by Covid-19. Also, patient health records can be shared with the CMS if patients are being seen at home or offsite (not at a hospital). It is possible that these CMS waivers created some confusion about the scope of the rule relaxation. ## The OCR Enforcement Waivers The OCR waivers only relate to the teleconferencing technical safeguards of HIPAA compliance. Video conferencing services have proven invaluable during the pandemic, enabling clinics to continue operating and follow safe distancing guidelines. The technology has also helped to bring families closer together during the lockdown. But, importantly, it has enabled GPs and medical teams to continue to offer front line services direct to patients. The discretion offered by the OCR relates directly to video conferencing technology – nothing more, nothing less! ## About Video Conferencing and HIPAA Video conferencing is an approved technology that is allowed when using HIPAA-compliant service; however, there are usually strict rules about the technology, patient consent, and the need for a Business Associate Agreement (BAA) to meet the security restrictions needed. Prior to Covid-19, such a video conferencing tool would commonly have been non-public facing remote communication device that patients could consume, often using bespoke software solutions. Since Covid-19, the rules have been relaxed significantly. [According to the HHS](https://www.hhs.gov/hipaa/for-professionals/special-topics/emergency-preparedness/notification-enforcement-discretion-telehealth/index.html): “Under this Notice, covered health care providers may use popular applications that allow for video chats, including Lets Talk, Apple FaceTime, Facebook Messenger video chat, Google Hangouts video, Zoom, or Skype, to provide telehealth without the risk that OCR might seek to impose a penalty for non-compliance with the HIPAA Rules related to the good faith provision of telehealth during the COVID-19 nationwide public health emergency.” ## What Types of Video Conferencing Are Covered by HIPAA? Some banned video services such as Facebook, Twitch, Snapchat, and TikTok are simply not allowed under HIPAA. A number of video conferencing organizations have created HIPAA-compliant products that are approved by the HHS and OCR. However, the business associate agreements (BAA) offered by them have not been individually reviewed by the HHS; therefore, it is recommended that healthcare organizations conduct thorough due diligence to ensure that the product is suitable. The type of video conferencing in-scope is usually the specific healthcare version, not the general public releases. The toolsets that have been whitelisted include Updox, VSee, Zoom for Healthcare, Doxy.me, Google G Suite Hangouts Meet, Cisco Webex Meetings / Webex Teams, GoToMeeting, and Spruce Health Care Messenger. These platforms offer a number of technical safeguards that protect the integrity of PHI, including HIPAA-compliant levels of encryption that shield the audio and video stream, detailed logging of connection and session activity, and enforcement of user authentication with unique IDs and passwords. Conference rooms are protected with meeting access codes that are not publicly listed, and the presenter can specifically share applications needed which can prevent accidental exposure of PHI. ## Conclusion To conclude, it is important to stress that the OCR has only relaxed some of the rules regarding video conferencing services implemented by HIPAA covered entities. This change in rules might be considered a sensible update to the rules as technology evolves. Video conferencing technology is everywhere, and relaxing these rules will greatly improve the patient experience. All other physical, administrative, and technical safeguards required for HIPAA compliance are still enforceable by the OCR. One might argue that covered entities should be even more vigilant in these uncertain times as cyber-attacks have risen exponentially during the pandemic. Even the World Health Organization (WHO) has experienced a fivefold increase in cyber attacks. ## HIPAA Compliant Hosting Are you in need of an infrastructure that can protect the health data of your organization? At Atlantic.Net, whatever your technical requirements, we can offer a top-grade [HIPAA-Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solution. Learn more about our [HIPAA compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. --- # Overview of Redundant Systems > URL: https://www.atlantic.net/dedicated-server-hosting/overview-of-redundant-systems/ | Published: 2020-07-26 | Updated: 2025-09-19 | Author: Richard Bailey The purpose of this article is to explain redundancy in terms of computing, networking, and hosting. We will provide real-world examples of redundant technology solutions to illustrate what redundancy is and how it works.  Atlantic.Net has created multiple hosting environments, including a [durable cloud platform](https://cloud.atlantic.net/?page=signup), high-speed [VPS hosting](https://www.atlantic.net/vps-hosting/), [HIPAA compliant infrastructure](https://cloud.atlantic.net/?page=signup&s=hp), and [managed private cloud hosting](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/). All of our systems are built with redundancy as a primary driving factor of the design process. In everyday English, redundancy may have a negative connotation; something redundant is usually not needed or considered superfluous. However, in a [cloud hosting environment](https://cloud.atlantic.net/?page=signup), redundancy can mean the difference between seamless system availability and unwanted or unexpected downtime. ## What Is a Redundant System? A redundant system will provide [failover](https://www.atlantic.net/hipaa-data-centers/increasing-uptime-of-your-web-assets-by-instituting-failover-services/) or [load balancing](https://www.atlantic.net/managed-services/load-balancing/) support to protect a live system in the event of an unexpected failure. In the case of [power, mechanical, or software failure](https://www.atlantic.net/blog/), a redundant system will have a duplicate component or platform to fall back to. In general, any component of a system with a single point of failure can be seen as a risk to production services. Power or mechanical systems have simpler fall back strategies requiring the mere presence of another of the same type of service; software failovers usually require extra configuration on the host system or a master or gateway. Redundancy capabilities are recommended for any business-critical system, but particularly for systems that have a significant impact during downtime. Some businesses may keep all of their critical customer information in a database; therefore, for business continuity purposes, protecting that database with redundancy will protect the data integrity in the event of a catastrophic failure. ## Types of Redundant Systems A redundant system consists of at least two systems that are interconnected and designed for the same purpose. There are many different types of redundant system configurations available, and different implementations of the system provide unique approaches to how to keep a system up at all times. Not all servers need to be configured with redundancy; rather, only the most critical should be considered. We highly recommended detailed risk assessment to understand what servers are in scope and the maximum amount of downtime your servers can handle. Use this assessment to determine an RTO (Recovery Time Objective) and RPO (Recovery Point Objective) strategy. RTO is the maximum amount of acceptable downtime. This can range from 5 seconds to 24 hours. The RPO is the point in time from which you require your data; for example, your business can function with a maximum loss of 24 hours worth of data. Here are a few popular examples[2]: - **Active-Inactive/Hot-Cold –** When one component of a system is the active system and another is inactive or shut down. The inactive component is activated only when the currently running component fails or undergoes maintenance - **Active-Active/Hot-Hot**– When both systems are live and making connections. This is most commonly known as clustering. Usually, the device in front of both machines will determine how to split incoming traffic - **Active-Standby/Hot-Warm** – When both systems are on, but only one is making connections. The second system is meant to periodically receive updates or backups from the primary system. In the event of a failure, the system on standby takes the primary role until the initial system can be recovered. Each type has its own pros and cons.  - **Active-Inactive/Hot-Cold** systems can provide a simple redundant platform, but any failover will result in users seeing an older version of the system. - **Active-Active/Hot-Hot**will require a constant update of both systems, either manually or through a separate service, to ensure that all users can use either system. This approach can heavily reduce the active load on a service you’re providing to customers. - **Active-Standby/Hot-Warm** will provide the failover capabilities of hot-cold with a more up-to-date copy of your active system on the failover, but it does not provide any load easing. Other forms of multiple node redundancy are available that allow for greater redundancy and robust load balancing solutions. At that point, you’ll have a high-availability cluster, also known as an HA cluster.  This can use any combination of the previously noted redundancy solutions with maximum flexibility in the approach or amount of redundancy needed. HA clusters can also be set up across multiple physical locations to allow for availability up to the internet backbone level.[3] ## Examples of Redundant Software Services Short of low resource availability, there is very little reason to not have proprietary replication or redundant services set up in a virtual environment; thus, many such services are available by default in most virtualization systems. All of our cloud services have replication available, a feature that allows us to replicate any server from one node to another, whether they are in the same data center or separate data center regions.  ### Hyper-V Replica [Hyper-V Replica is a form of hot-warm redundancy](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/). A primary virtual machine is created on one physical host and accepts incoming connections. When enabling replication, the virtual hard disks of the new machine are transferred to a separate physical Hyper-V host. This host then configures a VM on itself that replicates on a user-defined schedule to ensure that the most recent image of the active server is taken. Additional checkpoints points can be kept as well.[4] [Hyper-V private hosting with managed services](https://www.atlantic.net/dedicated-server-hosting/) is provided by Atlantic.Net with this feature baked in; [contact our team](https://www.atlantic.net/vps-hosting/what-is-private-cloud-hosting/) for further information. ### Hyper-V Clustering [Hyper-V is also capable of clustering](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/) through a connection to other Hyper-V hosts. VMs on any Hyper-V host can be clustered together on that singular host to provide redundancy on a local level through virtual networking.  Microsoft Network Load Balancing (NLB) can be used to create a single resource made up of multiple hosts that share the same information to provide a simple point of access for file sharing. Since this is only capped by the amount of resources you have available, you can theoretically set up multiple hosts with multiple VMs for maximum redundancy, which would also allow you to perform maintenance on individual VMs without sacrificing service or resource availability.[5]  [Hyper-V private hosting with managed services](https://www.atlantic.net/dedicated-server-hosting/) is provided by Atlantic.Net with this feature baked in; [contact our team](https://www.atlantic.net/vps-hosting/what-is-private-cloud-hosting/) for further information.  ### HAProxy Aside from Hyper-V, a gateway device such as a firewall can be used for failover or load balancing services. For example, Atlantic.Net can provide pfSense with High Availability Proxy, also known as HAProxy.  HAProxy will act as a load balancer, a proxy, or a simple hot-warm high availability solution for TCP and HTTP-based applications.[6] HAProxy is a very popular, Linux-based open-source solution used by some of the most visited sites in the world.[7] ### Heartbeat Heartbeat is a service available on most distributions of Linux that is used to determine whether nodes in a cluster are still up or responsive. It’s very simple to set up and provides failover capabilities to any system working over TCP.  The developers of Heartbeat also recommend other cluster resource managers which start or stop services based on whether a particular host is down. Heartbeat has this included, but other managers are available. Due to Heartbeat’s simplicity, it is highly customizable.[8] Cloud Hosting platforms provided by Atlantic.Net already have this feature baked in, and we can assist you with implementing Heartbeat on your own private Linux distribution, if needed. ## Examples of Redundant Hardware Services The best part about redundant hardware is its simplicity. While software services may require excessive configuration and are possibly quite sensitive, the hardware is *usually*very simple to set up and incredibly durable. The first example we will look at is the widely used RAID technology. ### RAID RAID stands for **R**edundant **A**rray of **I**ndependent **D**isks (or **R**edundant **A**rray of **I**nexpensive **D**isks depending on how long you’ve been using it) and has multiple levels used either for data protection or increased disk I/O. RAID can either be set up via a software or hardware controller. The controller has the software and configuration necessary to manage the RAID disks. The configuration can be exported to different systems with little to no additional configuration. RAID can be set up in a few different ways to provide a good balance of both of its qualities: - **RAID 0** – This is essentially no redundancy. No disks on the system share data through mirroring, but all data is striped across each disk providing increased read/write speed. Each drive can still use the storage provided to it at its fullest, meaning the more drives you add to a RAID 0 the more space you’ll have. ![](https://lh4.googleusercontent.com/kzJwXFl9FucgrVQGNK7c0hQRxyIPSfa6Ow8d6mhGiwp_9mAm8ET8Ch9-4f2edA308_IGpvsTVJFH5zCBjWJM7G5e_Uy2M_Hk5bm_tklWlUzADRMF8UePdQJendYRs1CtvD7dxAY) - **RAID 1** – A basic form of mirroring providing excellent redundancy at the cost of space. In a two-drive system, a complete copy of the data on one drive is written to the other. This redundancy is enhanced with each drive added. Since all data must be mirrored across all drives, total space on the system will be limited to just the space of the smallest drive in the system. ![](https://lh4.googleusercontent.com/WbhqoaNme69jehS-N_eVIor_SEdVist6EBrwAclpGWoKIPShwFyxcXuAzfo7Mh_12d30DCUc_Uc6UktEPhrrzAuZrs1D8QpPBlXuby6xVcIg9JB9frb_dsW3mHZWL5eLr2y23S0) - **RAID 5** – This form of RAID is usually used to increase read speed and reliability. In this case, stripes are placed about each drive in the system, with the minimum being 3 drives. At the same time, an extra block of error-correcting data is placed about each drive in a technique called parity. This checks whether data is changed when transferring from one drive to another.[10] This also provides a minimal form of redundancy since 1 of these drives can fail and the system can still run. The more drives added to this type of RAID setup, the more your read speed increases. With minimum redundancy and striping across all drives, the total amount of space in this setup is equal to the size of your logical RAID volume times the number of drives you use, minus one. For example, if you have 5 500 GB drives in a RAID 5, you would have 2000 GB usable, or 2 TB (500 *(5-1)=2000). ![](https://lh5.googleusercontent.com/lBJcyaV6RkTNNgblTR8obLS_VhywzdrAuHfxXDMCWmoFZLVL2aGPe6CbAzZfPuMPRZ0AAKfjjfDpq9oQ2q8tdO50vrTgb_BwULhHT_rV9SgLt6rUSgnE3kH4OZ4NfrIcuW0_xrI) - **RAID 10** – This is a combination of RAID 1 and RAID 0. In this case, all data is striped across each device with blocks of data also being mirrored across the entirety of the striped system. For example, in a 4 drive RAID 10 system 2 500 GB drives may have the same data, but not all the data needed for the system to work properly. 2 other drives’ data would be required. Think of each RAID 1 system as a single drive, and each of those systems placed into a RAID 0 array. In this setup, performance can be drastically increased as in RAID 0, with some redundancy still in place with the mirroring. Up to half of the drives in the system can fail before the system crashes, but as with any redundant array, it’s best to replace drives as soon as possible. [Atlantic.Net uses RAID 10 for all SSD Cloud VPS Storage](https://cloud.atlantic.net/?page=signup). ![](https://lh5.googleusercontent.com/LYNybv7Md-ApanD7c6N8dJRiy_v90U37Xaj2hdsT5ZLtRDlV7pG6z_o69WmvaOjKPvQefJr1dxb5P34hf7xNYReVNjsihI47q7wKIuiFbrqrez_mWcrjWmWsWUqRjH6BMtMjzTQ) For added protection, the RAID controllers are protected by battery backup units that power the ROM chips used to save the configuration in memory in case of power loss, etc. A BBU will provide power to a RAID array that’s part of a powered down system for a small amount of time, allowing the content of a RAID controller’s cache to stay intact. This can be a lifesaver if the information is constantly being fed into your [RAID array](https://www.atlantic.net/hipaa-data-centers/raid-10/) and any downtime could cause data corruption.[11] So, your physical system and the services within can be constructed redundantly rather adequately. But what about your connection to any part of your system? As in, your direct internet connection to your system as a whole? ## Networking Redundancy ### First Hop Redundancy Protocols (FHRP) In contrast to dynamic gateway discovery protocols, static gateways allow for straightforward hops between the client and their appropriate gateway, but this creates a single point of failure – namely the gateway itself.  To prevent or reduce the impact of gateway failure, FHRPs were created. They provide redundant gateways a fallback, or offer load-balancing for high traffic systems, along with redundancy. These protocols include VRRP, HSRP, and GLBP.[12] #### **Virtual Router Redundancy Protocol (VRRP)** VRRP is a form of redundancy used for routers that requires at least two physically separate routers connected via either Ethernet or optical fiber connections. In this situation, a ‘virtual router’ containing static routes is created and shared between each system.  One system is considered the ‘master’ and another the ‘backup’. When the master fails, the backup takes over as the next master. This can be set up with multiple backups for extra redundancy. The concept is very similar to Heartbeat in that the backup systems will check to see if the master is available. Once it does not receive a response, after a predetermined amount of time the backup will assume control of the virtual switch and accept connections for all requests coming in for the default IP configured for the master switch.[13][14] #### **Hot Standby Router Protocol (HSRP)** HSRP is like VRRP; however, in this scenario, the configured virtual switch isn’t a ‘switch’, but rather a logical group of multiple routers. The IP of the group is an IP not assigned to a physical host. Instead, the group is assigned an IP and one of the routers is determined to be the ‘active’ router.  A standby router is ready to take any connections should the active router go down. All routers besides the active and standby are all listening to determine its place in line. HSRP is a Cisco proprietary protocol and has very few, minor differences to VRRP such as their default timers determining when to failover. HSRP has been around a bit longer and is more well-known compared to VRRP.[12] #### **Gateway Load Balancing Protocol (GLBP)** GLBP’s main advantage over HSRP and VRRP is its ability to load balance on top of providing redundancy to a gateway with little to no extra configuration. Much like HSRP and VRRP, GLBP will create a group between physical routers and determine an Active Virtual Gateway, or AVG.  A virtual IP not currently used by any of the routers in the group is assigned to the AVG. The AVG then distributes virtual MAC addresses among the rest of the routers in the group. Each backup router is now considered an Active Virtual Forwarder, or AVF.  ARP requests sent to the AVG will provide a different virtual MAC address to the client sending the request. At that point, traffic from that client to the virtual IP of the group forwards to the router whose virtual MAC address they received, allowing each router to still be used instead of sitting idly by. In the event of a failure of the AVG, priority-based election takes place, just like in HSRP and VRRP, and the next backup takes its place, distributing virtual MAC addresses as normal. The other routers still retain the virtual MAC address provided by the original AVG and things continue as normal. In the event of a failure of one of the AVFs, the AVG will prevent routing traffic to its virtual MAC address. Just like HSRP, GLBP is a Cisco proprietary form of FHRP. ## Data Center Redundancy In addition to redundancy measures for your personal servers or routers, data centers are designed to be resilient to system failure. Data centers fall under *tiers*defined by the Uptime Institute to provide fault tolerance for failure of any mechanical or service failure, allowing for as much uptime as possible.  There are four tiers, each building upon one another to provide high availability to all clients within a data center: - **Tier I** ***– Basic Capacity***: This requires space for an IT group for data center operations, an uninterruptible power supply (UPS) that monitors and filters power usage and dedicated cooling equipment that is constantly running 24/7. This also includes a power generator in the case of electrical power failure. - **Tier II** – **Redundant Capacity Components**: Everything that Tier I provides, plus redundant power and cooling to the facility. This can include extra UPS units or extra generators.  - **Tier III** – **Concurrently Maintainable**: Everything Tier II provides, plus extra equipment in place to prevent any need for shutdowns for equipment replacement or maintenance. At this tier, redundant power and cooling are applied directly to all technical equipment, and the equipment itself is configured for redundancy or seamless failover. - **Tier IV** **– Fault Tolerance**: Everything Tier III provides, plus uninterrupted service at the provider level. While a data center may have electricity or water provided by a city or state provider, a secondary line of each service utilized by the data center is required. This includes the ISP as well. In the event of a failure at any section leading up to client equipment, there is a backup plan in place ready for a seamless transition. ## **Conclusion** Redundancy has become an everyday term in the IT industry due to necessity. The high availability of services provides an easy, reliable experience for our customers.  Whether on the service level or the data center level, providing redundancy to your system is an important and difficult issue to tackle. Hopefully, this paper has shed some light on the options available and will help in any decisions made regarding high availability going forward. Ready to take advantage of Atlantic.Net’s redundant systems? Contact us today to find out more about [Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/) with Atlantic.Net. ===Sources=== [1] Redundant System Basic Concepts: http://www.ni.com/white-paper/6874/en/ [2] Cold/Warm/Hot Server: http://searchwindowsserver.techtarget.com/definition/cold-warm-hot-server [3] High Availability Clustering: https://www.mulesoft.com/resources/esb/high-availability-cluster [4] Hyper-V Replica: https://technet.microsoft.com/en-us/library/jj134172(v=ws.11).aspx [5] Hyper-V and High Availability: https://technet.microsoft.com/en-us/library/hh127064.aspx [6][HAProxy Description](http://www.haproxy.org/#desc) [7][HAProxy – They use it!](http://www.haproxy.org/they-use-it.html) [8] Heartbeat: http://www.linux-ha.org/wiki/Main_Page [9] RAID Definition:[RAID techtarget](http://searchstorage.techtarget.com/definition/RAID) [10] Striping:[techtarget com](http://searchstorage.techtarget.com/definition/disk-striping) [11] [RAID Battery Backup Units](https://www.thomas-krenn.com/en/wiki/Battery_Backup_Unit_(BBU/BBM)_Maintenance_for_RAID_Controllers) [12] High-Availability – VRRP, HSRP, GLBP: http://www.freeccnastudyguide.com/study-guides/ccna/ch14/vrrp-hsrp-glbp/ [13] [Understanding VRRP](http://www.juniper.net/techpubs/en_US/junos/topics/concept/vrrp-overview-ha.html) [14] Configuring VRRP:[check cisco](http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipapp_fhrp/configuration/15-mt/fhp-15-mt-book/fhp-vrrp.html) [15] [Configuring GLBP](http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipapp_fhrp/configuration/xe-3s/fhp-xe-3s-book/fhp-glbp.html) [16] Explaining the Uptime Institute’s Tier Classification System: https://journal.uptimeinstitute.com/explaining-uptime-institutes-tier-classification-system/ --- # How to Set Up WireGuard VPN on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-set-up-wireguard-vpn-on-centos-8/ | Published: 2020-08-10 | Updated: 2024-09-25 | Author: Hitesh Jethva WireGuard is an open-source, fast, security-focused virtual private network application that can be used to create secure point-to-point connections in routed configurations. It is simple, faster than OpenVPN, and uses proven cryptography protocols and algorithms to protect data. It can be installed in many operating systems including Windows, macOS, BSD, iOS, Linux, and Android. WireGuard is a peer-to-peer VPN and does not use the client-server model. It assigns static IP addresses to VPN clients, and user authentication is done by exchanging public keys. In this tutorial, we will show you how to set up WireGuard VPN on CentOS 8. ## Step 1 – Enable IP Forwarding Before starting, you will need to enable IP forwarding in your system. You can enable it by creating a new /etc/sysctl.d/99-custom.conf file: ``` nano /etc/sysctl.d/99-custom.conf ``` Add the following line: ``` net.ipv4.ip_forward=1 ``` Save and close the file then run the following command to apply the changes: ``` sysctl -p /etc/sysctl.d/99-custom.conf ``` ## Step 2 – Install Wireguard First, you will need to install the Epel and Elrepo repositories in your system. You can install them with the following command: ``` dnf install epel-release elrepo-release -y ``` Once installed, install WireGuard by running the following command: ``` dnf install kmod-wireguard wireguard-tools -y ``` Once the installation is completed, restart your system to load the kernel module. ## Step 3 – Configure WireGuard First, you will need to generate the public and private keys inside /etc/wireguard directory. Run the following command to generate them: ``` wg genkey | tee /etc/wireguard/privatekey | wg pubkey | tee /etc/wireguard/publickey ``` You should see your generated key in the following output: ``` Nnid+rqJBnsZ+SN68dILbmxMreKyFTlSjBI8bh4sbzU= ``` You can also list them with the following command: ``` ls /etc/wireguard/ ``` You should see the following output: ``` privatekey  publickey ``` Next, you will need to configure the tunnel device that will route the VPN traffic. You can do that by creating a new configuration file named wp0.conf: ``` nano /etc/wireguard/wg0.conf ``` Add the following lines: ``` [Interface]Address = 10.0.0.1/24SaveConfig = trueListenPort = 51820PrivateKey = Nnid+rqJBnsZ+SN68dILbmxMreKyFTlSjBI8bh4sbzU=PostUp     = firewall-cmd --zone=public --add-port 51820/udp && firewall-cmd --zone=public --add-masqueradePostDown   = firewall-cmd --zone=public --remove-port 51820/udp && firewall-cmd --zone=public --remove-masquerade ``` Save and close the file when you are finished. Here are the relevant definitions for the lines above: - **Address**: Specify the private IP address of the VPN server. - **ListenPort**: Specify the WireGuard listening port. - **PrivateKey**: Specify private key of the VPN server, which can be found in the /etc/wireguard/privatekey. - **PostUp**: Specify any actions to execute at the time of bringing up the WireGuard interface. - **PostDown**: Specify any actions to execute at the time of bringing down the WireGuard interface. Next, bring up the WireGuard interface by using wg-quick command: ``` wg-quick up wg0 ``` You should get the following output: ``` [#] ip link add wg0 type wireguard[#] wg setconf wg0 /dev/fd/63[#] ip -4 address add 10.0.0.1/24 dev wg0[#] ip link set mtu 1420 up dev wg0[#] firewall-cmd --zone=public --add-port 51820/udp && firewall-cmd --zone=public --add-masqueradesuccess ``` You can now check the status of the wg0 interface with the following command: ``` wg show wg0 ``` You should see the following output: ``` interface: wg0   public key: 6hxSg1eZR9n4oPYckJbzXcNbVwcjF5vNsSzUREsoBEY=   private key: (hidden)   listening port: 51820 ip a show wg0 5: wg0: mtu 1420 qdisc noqueue state UNKNOWN group default qlen 1000     link/none     inet 10.0.0.1/24 scope global wg0        valid_lft forever preferred_lft forever ``` Next, enable the wg0 interface to start at system reboot with the following command: ``` systemctl enable wg-quick@wg0 ``` ## Step 4 – Install and Configure Wireguard VPN Client First, install the Epel and Elrepo repositories on the client machine with the following command: ``` dnf install epel-release elrepo-release -y ``` Once installed, install WireGuard by running the following command: ``` dnf install kmod-wireguard wireguard-tools ``` Once the installation is completed, restart your system to load the kernel module. Next, generate the public and private keys with the following command: ``` wg genkey | tee /etc/wireguard/privatekey | wg pubkey | tee /etc/wireguard/publickey ``` You should get the following output: ``` NvzqF7ilT01OD3uTAmNME1rHFnCcTdGSXo+f8tkRElQ= ``` Next, create a new wg0.conf configuration file with the following command: ``` nano /etc/wireguard/wg0.conf ``` Add the following lines: ``` [Interface] PrivateKey = NvzqF7ilT01OD3uTAmNME1rHFnCcTdGSXo+f8tkRElQ= Address = 10.0.0.2/24 [Peer] PublicKey = Nnid+rqJBnsZ+SN68dILbmxMreKyFTlSjBI8bh4sbzU= Endpoint = your-server-ip:51820 AllowedIPs = 0.0.0.0/0 ``` Save and close the file when you are finished. Here are the relevant definitions for the lines above: - **PrivateKey** : Specify the client’s private key. - **Address**: Specify the private IP address for wg0 interface. - **PublicKey** : Specify the server public key. - **Endpoint** : Specify the server IP address. - **AllowedIPs** : Specify the allowed IPs. ## Step 5 – Add the Client Peer to the Server Next, you will need to add your WireGuard client’s public key and IP Address in your WireGuard VPN Server. On the server machine, run the following command to add the client public key and IP address to the server: ``` wg set wg0 peer NvzqF7ilT01OD3uTAmNME1rHFnCcTdGSXo+f8tkRElQ= allowed-ips 10.0.0.2 ``` You can find the client-public key at /etc/wireguard/publickey on the client machine. On the client machine, bring up the wg0 interface with the following command: ``` wg-quick up wg0 ``` You should see the following output: ``` [#] ip link add wg0 type wireguard[#] wg setconf wg0 /dev/fd/63[#] ip -4 address add 10.0.0.2/24 dev wg0[#] ip link set mtu 1420 up dev wg0 ``` On the server machine, you can check the WireGuard server status with the following command: ``` wg ``` You should get the following output: ``` interface: wg0   public key: 6hxSg1eZR9n4oPYckJbzXcNbVwcjF5vNsSzUREsoBEY=   private key: (hidden)   listening port: 51820 peer: NvzqF7ilT01OD3uTAmNME1rHFnCcTdGSXo+f8tkRElQ=   allowed ips: 0.0.0.0/0   latest handshake: 22 seconds ago   transfer: 126.15 KiB received, 123.12 KiB sent ``` ## Conclusion Congratulations, you have successfully set up a WireGuard VPN server on CentOS 8 and created a VPN tunnel between two CentOS 8 machines. You can now surf the web anonymously and keep your traffic data private. Get started today with a [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Apache with Python Mod_wsgi on Debian > URL: https://www.atlantic.net/vps-hosting/how-to-install-apache-with-python-mod-wsgi-on-debian/ | Published: 2020-08-11 | Updated: 2025-09-02 | Author: Hitesh Jethva WSGI stands for “Web Server Gateway Interface,” which provides a standard and efficient method for dynamic web applications to communicate with web servers.  It is used for deploying applications written in Django, Web.py, Werkzug, and Flask. Mod_wsgi simplifies the WSGI application deployment on an Apache webserver. Mod_wsgi is an Apache webserver module that can be used to serve Python applications using the HTTP protocol. In this tutorial, we will show you how to install Apache with Python Mod_wsgi on Debian 12. ## Step 1 – Install Python First, you will need to install Python in your system. You can install it by just running the following command: ``` apt-get install python3 libexpat1  -y ``` Once Python is installed, you can proceed to the next step. ## Step 2 – Install Apache with mod_wsgi Module Next, you will need to install the Apache webserver package and mod_wsgi Python module in your system. Run the following command to install them: ``` apt-get install apache2 apache2-utils ssl-cert libapache2-mod-wsgi-py3 -y ``` Once all the packages are installed, restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` ## Step 3 – Configure Apache with mod_wsgi Module First, you will need to create a Python script in your Apache web root directory. You can create it with the following command: ``` nano /var/www/html/wsgi.py ``` Add the following lines: ``` def application(environ, start_response): status = '200 OK' html = b"\n" \ b"\n" \ b"
\n" \ b"Welcome to Apache with mod_wsgi\n" \ b"
\n" \ b"\n" \ b"\n" response_header = [('Content-type', 'text/html; charset=utf-8')] start_response(status, response_header) return [html] ``` Save and close the file when you are finished. Next, you will need to create an Apache virtual host configuration file to serve the Python script with HTTP protocol. You can create it with the following command: ``` nano /etc/apache2/conf-available/mod-wsgi.conf ``` Add the following line: ``` WSGIScriptAlias /wsgi /var/www/html/wsgi.py Require all granted ``` Save and close the file. Then, activate the virtual host configuration with the following command: ``` a2enconf mod-wsgi ``` Next, restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` ## Step 4 – Verify mod_wsgi Application Now, open your web server and visit the URL http://your-server-ip/wsgi. You will be redirected to the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Mod_wsgi-welcome-1024x319.png) ## Conclusion Congratulations! You have successfully deployed Python application with mod_wsgi and Apache on Debian 12. Easily deploy a Python application in the production environment on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net. --- # How to Install and Configure Memcached on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-configure-memcached-on-centos-8/ | Published: 2020-08-12 | Updated: 2024-09-25 | Author: Hitesh Jethva Memcached is an open-source and high-performance in-memory caching system. Generally, it is used to speed up web applications by caching session data, user authentication tokens, and API calls. Its aim is to accelerate dynamic web applications by alleviating database load.  Memcached reduces application load by storing data objects in dynamic memory. In this tutorial, we will explain how to install Memcached on CentOS 8. ## Step 1 – Install Memcached By default, Memcached is available in the CentOS 8 default repository. You can install it by just running the following command: ``` dnf update -ydnf install memcached libmemcached -y ``` After installing Memcached, start the Memcached service and enable it to start at boot with the following command: ``` systemctl start memcachedsystemctl enable memcached ``` You can also verify the status of the Memcached service with the following command: ``` systemctl status memcached ``` You should see the following output: ``` memcached.service - memcached daemon    Loaded: loaded (/usr/lib/systemd/system/memcached.service; disabled; vendor preset: disabled)    Active: active (running) since Fri 2020-08-07 06:30:57 EDT; 10s ago  Main PID: 9933 (Memcached)     Tasks: 10 (limit: 12537)    Memory: 3.6M    CGroup: /system.slice/memcached.service            └─9933 /usr/bin/memcached -p 11211 -u memcached -m 64 -c 1024 -l 127.0.0.1,::1 Aug 07 06:30:57 centos8 systemd[1]: Started memcached daemon. ``` ## Step 2 – Configure Memcached Memcached default configuration file is located at /etc/sysconfig/memcached. By default, Memcached is configured to listen on the localhost. If your application is hosted on the same server, then you don’t need to configure Memcached. If your application is hosted on the remote server, then you will need to configure Memcached to listen on that IP address and allow access to the Memcached port 11211 only from the client IP address. To see the Memcached default configuration, run the following command: ``` cat -n /etc/sysconfig/memcached ``` You should see the following output: ```      1     PORT="11211"     2     USER="memcached"     3     MAXCONN="1024"     4     CACHESIZE="64"     5     OPTIONS="-l 127.0.0.1,::1" ``` If you want to configure Memcached for a remote application, you need to replace the **127.0.0.1** with the IP address of the remote system. ## Step 3 – Integrate Memcached with PHP If you want to use Memcached as a caching database for your PHP application, then you will need to install the Memcached extension for PHP. First, you will need to install the EPEL and Remi repository in your system. You can install them by running the following command: ``` dnf install epel-release -ydnf install https://rpms.remirepo.net/enterprise/remi-release-8.rpm -y ``` Next, enable the PHP Remi repository with the following command: ``` dnf module enable php:remi-7.4 -y ``` Next, install the PHP Memcached extension with the following command: ``` dnf install php-pecl-memcache php-pecl-memcached -y ``` Once you are finished, you can proceed to the next step. ## Step 4 – Verify Memcached Next, install the Nginx web server and create a sample PHP page to test whether Memcached is enabled for PHP or not. First, install Nginx with PHP by running the following command: ``` dnf install nginx php php-cli -y ``` Once installed, create a sample info.php page: ``` nano /var/www/html/info.php ``` Add the following lines: ``` ``` Save and close the file, then create a symbolic link of info.php file to the Nginx default web root directory: ``` ln -s /var/www/html/info.php /usr/share/nginx/html/ ``` Next, start the Nginx server and enable it to start at boot with the following command: ``` systemctl start nginxsystemctl enable nginx ``` Now, open your web browser and type the URL http://your-server-ip/info.php. You should see the Memcached section in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Memcached-1024x568.png) ## Conclusion Congratulations! You have successfully installed and configured Memcached on CentOS 8. You can now integrate your web application with Memcached and use its features to speed up your website on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. For more information, visit the [Memcached](https://github.com/memcached/memcached/wiki) documentation. --- # How to Install Plesk Onyx on CentOS 7 > URL: https://www.atlantic.net/vps-hosting/how-to-install-plesk-onyx-on-centos-7/ | Published: 2020-08-13 | Updated: 2024-09-25 | Author: Hitesh Jethva Plesk Onyx is the newest and smoothest upgrade of the traditional Plesk control panel. It is one of the best control panels for Linux and Windows servers.  Plesk Onyx is very similar to cPanel and DirectAdmin and makes managing your website easy while providing a set of security improvements designed to help harden your server. It supports various databases, including Docker, Git, Ruby, Node.js, DNSSEC, and many more. In this tutorial, we will show you how to install Plesk Onyx control panel on CentOS 7. ## Step 1 – Download Plesk Onyx Installer Next, you will need to download the Plesk Onyx installation script from its official website. You can download it using the wget command: ``` wget http://autoinstall.plesk.com/plesk-installer ``` Once downloaded, give execution permissions with the following command: ``` chmod +x plesk-installer ``` Next, start the installation using the following command: ``` ./plesk-installer ``` You will be asked to choose the following options: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Plesk-Install-Options.png) ``` Select an action [F/q]: F ``` Type **F**and hit **Enter**to continue. You should see the following output: ``` Would you like to help Plesk make better products by sending information about issues occurred, including installation and upgrade issues? [Y/n]: Y ``` Type **Y**and hit **Enter**. You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Plesk-Install-Type.png) ``` Select an action or a number [F/b/q/1-3]: F ``` Type **F**and hit **Enter**. You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Plesk-Install-Prep.png) ``` Select an action [F/b/q/s]: F ``` Type **F**and hit **Enter**to start the installation. Once the installation has been completed, you should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Plesk-Install-Complete.png) ## Step 2 – Access Plesk Onyx Web Interface Now, open your web browser and type **the URL from the above.** You will be redirected to the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Plesk-Contact-Info-1024x561.png) ![](https://www.atlantic.net/wp-content/uploads/2020/08/Plesk-Password-License-1024x583.png) Provide your administrator email, password, License key and click on the **Enter** **Plesk** button. You should see the Plesk dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Plesk-Dashboard-1024x538.png) ## Conclusion Congratulations! You have successfully installed the Plesk Onyx control panel on CentOS 7. You can now manage your web hosting account, DNS, Domain, Mailbox, and Website easily with Plesk Onyx. For more information, visit the [Plesk Onyx](https://docs.plesk.com/en-US/onyx/) documentation. Try Plesk Onyx today with an Atlantic.Net [VPS Hosting](https://www.atlantic.net/vps-hosting/) account! --- # How to Install Hestia Control Panel on Debian 12 > URL: https://www.atlantic.net/vps-hosting/how-to-install-hestia-control-panel-on-debian-12/ | Published: 2020-08-14 | Updated: 2025-09-05 | Author: Hitesh Jethva Hestia Control Panel is a powerful, free, open-source web hosting control panel that can be used to host websites, mail servers, DNS, and other web hosting features from the central location. It is designed for speed, security, and stability, and capably runs on a low-resource server. Hestia Control Panel comes with a user-friendly web and command-line interface that enables deployment and management of web domains, mail accounts, and DNS zones without hassle. In this tutorial, we will show you how to install Hestia Control Panel on Debian 12. [jumpbox] ## Prerequisites - A fresh Debian 12 64-bit [VPS](https://www.atlantic.net/vps-hosting/) with 4GB RAM. - A valid domain name that your server IP points to. - A root password configured on your server. ## Step 1 – Download Hestia Installation Script Before starting, you will need to install the required dependencies on your server. You can install all of them with the following command: ``` apt-get install ca-certificates gnupg2 curl wget unzip systemd-timesyncd -y ``` Next, start and enable the timesyncd service. ``` systemctl enable --now systemd-timesyncd ``` After installing all the packages, you will need to download the Hestia installation script. You can download it with the following command: ``` wget https://raw.githubusercontent.com/hestiacp/hestiacp/release/install/hst-install.sh ``` Once downloaded, give proper permission to the downloaded script with the following command: ``` chmod 755 hst-install.sh ``` ## Step 2 – Install Hestia Now, run the downloaded installation script to start the installation with the following command: ``` bash hst-install.sh ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Hestia-Install.png) ``` Please use a valid username (ex. user).Please enter administrator username: hjethvaPlease enter administrator password: securepasswordPress Y to continue the installationPlease enter admin email address: example@atlantic.netPlease enter FQDN hostname [debian10]: hestia.example.com ``` Provide your admin username, password, email address and valid domain name, and hit **Enter**to start the installation. Once the installation has been completed successfully, you should see the following output: ``` Congratulations! You have successfully installed Hestia Control Panel on your server. Ready to get started? Log in using the following credentials: Admin URL: https://hestia.example.com:8083 Backup URL: https://69.87.218.182:8083 Username: hjethva Password: The password you chose during installation. Thank you for choosing Hestia Control Panel to power your full stack web server, we hope that you enjoy using it as much as we do! Please feel free to contact us at any time if you have any questions, or if you encounter any bugs or problems: Documentation: https://docs.hestiacp.com/ Forum: https://forum.hestiacp.com/ GitHub: https://www.github.com/hestiacp/hestiacp Note: Automatic updates are enabled by default. If you would like to disable them, please log in and navigate to Server > Updates to turn them off. Help support the Hestia Control Panel project by donating via PayPal: https://www.hestiacp.com/donate -- Sincerely yours, The Hestia Control Panel development team Made with love & pride by the open-source community around the world. [ ! ] IMPORTANT: The system will now reboot to complete the installation process. Press any key to continue ``` Press the **Enter** key to restart your server. **Note** : Please remember the Hestia login URL and credentials as shown in the above output. ## Step 3 – Manage Hestia Service You can manage the Hestia service easily with systemd utility. For example, you can start and stop the Hestia service with the following command: ``` systemctl start hestiasystemctl stop hestia ``` You can also verify the status of the Hestia service with the following command: ``` systemctl status hestia ``` You should see the following output: ``` ● hestia.service - LSB: starts the hestia control panel Loaded: loaded (/etc/init.d/hestia; generated) Active: active (running) since Fri 2025-09-05 12:11:06 UTC; 1min 55s ago Docs: man:systemd-sysv-generator(8) Process: 447 ExecStart=/etc/init.d/hestia start (code=exited, status=0/SUCCESS) Tasks: 3 (limit: 4637) Memory: 26.0M CPU: 80ms CGroup: /system.slice/hestia.service ├─471 "nginx: master process /usr/local/hestia/nginx/sbin/hestia-nginx" ├─474 "nginx: worker process" └─496 "php-fpm: master process (/usr/local/hestia/php/etc/php-fpm.conf)" ``` ## Step 4 – Secure Hestia with Let’s Encrypt SSL By default, Hestia is secured with a self-signed certificate, but it is not signed by a certificate authority (CA). Therefore, it is recommended to install an SSL certificate signed by a CA to place normal traffic in a protected, encrypted wrapper. Let’s Encrypt is a free and non-profit certificate authority run by Internet Security Research Group. Its aim is to create a more secure and privacy-respecting Web by promoting the widespread adoption of HTTPS. You can secure your Hestia with Let’s Encrypt free SSL by just running the following command: ``` v-add-letsencrypt-host ``` If successful, nothing will be displayed on the screen. ## Step 5 – Access Hestia Control Panel Now, open your web browser and type the URL **https://hestia.example.com:8083.** You will be redirected to the Hestia login screen: ![](https://www.atlantic.net/wp-content/uploads/2020/08/h1.png) ![](https://www.atlantic.net/wp-content/uploads/2020/08/h2.png) Provide your admin username, password, and click on the **login** button. You should see the Hestia Control Panel default dashboard. ![](https://www.atlantic.net/wp-content/uploads/2020/08/h3.png) ## Conclusion Congratulations! You have successfully installed Hestia Control Panel and secure it with Let’s Encrypt SSL on Debian 12. You can now start setting up your host environment and other settings after logging on to the back-end panel. Get started today on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net! --- # 10 Telehealth Best Practices When Running a Remote Practice During COVID-19 > URL: https://www.atlantic.net/hipaa-compliant-hosting/10-telehealth-best-practices-when-running-a-remote-practice-during-covid-19/ | Published: 2020-08-17 | Updated: 2025-09-19 | Author: Brandon Schroth As healthcare workers on the front lines put themselves at risk each day, more hospitals and healthcare systems are turning to telehealth services to keep workers safe.  In many cases, telehealth technology can keep patients out of hospitals, urgent care facilities, and doctors’ offices by providing timely diagnoses and access to medical care. This limits the spread of a contagious disease like COVID-19 by keeping patients safe at home. However, implementing telehealth services comes with challenges. Potential limitations include the inability to perform a proper physical exam and a lack of patient comfort with the technology. However, during a pandemic, offering telehealth services lets you provide necessary healthcare and keep everyone safe. It even enables quarantined staff to continue working in a remote capacity and reduce the risk of spreading the illness. In this post, we’ll share 10 telehealth best practices to help you make the most of the technology and efficiently care for your patients on a remote basis. ## 1. Set strategic goals Before you implement or expand telehealth services within your organization, take the time to set appropriate goals. Realistic and measurable goals will help when determining staffing needs, evaluating performance, estimating costs, and picking the right equipment. Start small to improve the chances of success. For example, say the ultimate goal of your telehealth program is to provide rural patients with access to care. A realistic goal might be to have at least 50 percent of your rural-based patients sign up for the telehealth service. If you know that the majority of rural patients in your practice are over the age of 60, it would make sense to make telehealth services available via a phone call instead of a smartphone-accessible patient portal.  Assessing your goals before implementing your plan will ensure you allocate resources correctly. ## 2. Create an implementation team An internal team dedicated to implementing telemedicine services can help you keep costs down and smoothly roll out the new service. Using a third-party team instead of an internal one can result in time-consuming meetings and miscommunication. Keep in mind that the entire organization should be involved to get everyone’s input and assistance. Don’t just use IT staff; include your physicians and clinical staff as well. For example, one of the first things you’ll need to set up is [telehealth video conferencing software](https://www.jotform.com/blog/telehealth-video-conferencing/). This software needs to be fully [HIPAA compliant](https://www.atlantic.net/hipaa-compliant-hosting/) and easy for your doctors, staff, and patients to use.  ## 3. Search and apply for grants It can be expensive to implement telemedicine services, and reimbursements often won’t fund the upgrades. However, there are technology grants that can help offset the cost. You can find tech grants designed to improve the quality of life for rural citizens through organizations like the U.S. Department of Agriculture or state rural health associations. Take the time to look for grants available in your area and apply for any that your practice qualifies for. If you don’t feel confident in your writing skills, it may be worth working with a writer who specializes in grant applications to improve your chances of being awarded the funds. ## 4. Follow the CDC framework When in doubt, stick to the guidelines set forth by the CDC in their Non-COVID-19 Care Framework. This framework gives healthcare systems key considerations and examples of how to triage and respond to both critical and noncritical care to keep everyone safe. For instance, you’ll need to provide different levels of care and support for someone who is complaining of chest pains vs someone who needs a routine vaccine vs someone who needs a prescription refill. There’s only so much care you can provide in a telehealth consultation to someone with heart attack symptoms, so you’ll need to prioritize care in a hospital or in-person clinic safely. It might be OK to defer a routine vaccine a month or two or hold the appointment in a safer location with less COVID-19 community spread. And, you could most likely handle a simple prescription refill remotely on a telehealth appointment.   ## 5. Train your team on new technology first  Before testing the new technology on patients, it’s important to train your doctors, nurses, and administrative staff first. If they spend 10 minutes fumbling around with how to get their webcam to work, they won’t inspire confidence with your patients.  *Pro tip: In addition to detailed training manuals, you might even want to provide mandatory training workshops and drills for anyone who will be using the technology. * ## 6. Share telehealth protocols with patients Your patients won’t know about the new telehealth service unless you tell them. Even if it’s on your website, you cannot realistically expect all of your patients to discover the information on their own.  Here are some communication tactics you can use to promote the service:  - Communicate your organization’s policies during the COVID-19 health crisis as soon as you implement them.  - Call patients with upcoming appointments and let them know how any new policies will affect their appointment.  - Change your messaging scripts to share information about telehealth services. Contact high-risk patients, such as the elderly, as soon as possible. ## 7. Communicate with remote team members and vendors  To keep your telehealth services running smoothly, ensure open communication with all stakeholders. This means communicating with schedulers, presenters, clinicians, nursing staff, and anyone else working remotely. Be open to feedback and regularly check to make sure that billing systems, IT support, administration, and other functions are running as they should be. It can help to bring onsite staff together on a regular basis, such as quarterly, to discuss any issues with the telehealth program or connecting with remote partners. Encouraging communication means the organization can gather feedback, make improvements, and move forward with patient care.  ## 8. Maintain accurate records Just as you would maintain detailed records for patients who walk through the door, you’ll also need to keep accurate electronic records for those using telemedicine services.  You’ll want to record as much as possible, including any assessments or treatment plans — in addition to collecting [signed HIPAA forms and waivers](https://www.jotform.com/hipaa/templates/) from all patients.   ## 9. Come up with a backup plan There will be times when you need to escalate care for a patient or consult with a specialist or other provider in person. And sometimes, your telehealth software might have an outage.  In these scenarios, you’ll need to have protocols in place so your staff can take the appropriate action. For instance, if your video chat software fails, how will your staff reach out to the patient? Have a plan in place before the need arises so everyone’s on the same page. ## 10. Ask for patient feedback While you can certainly anticipate some of the challenges patients will face when using telehealth technology — such as a learning curve on video chats for some elderly patients without smartphones — you can’t predict everything. There could be trouble areas that your IT department didn’t expect.  This is where asking for feedback from patients — whether it’s during their appointment or in a follow-up survey afterward — can be beneficial. You can use this valuable feedback to make continuous improvements as everyone adjusts to using the new service. ## ** In addition to the tips above, stay informed about COVID-19 cases in your community. Monitoring trends in local case counts will help you prepare for increased demand in telehealth services. Check with the CDC regularly for additional guidance on safely operating during the COVID-19 pandemic. Start implementing these best practices today with [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) from Atlantic.Net – the perfect hosting solution to support telehealth. Contact us today to start a free HIPAA hosting trial! --- # How to Install Pure-FTPd on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-install-pure-ftpd-on-ubuntu/ | Published: 2020-08-18 | Updated: 2025-09-19 | Author: Hitesh Jethva Pure FTPd is a free and open-source FTP server designed with a strong focus on software security. It can be run on several operating systems including Linux, OpenBSD, NetBSD, FreeBSD, DragonFly BSD, Solaris, and many more. It is a very lightweight and stable daemon that supports various authentication backends such as Linux system users, puredb, MySQL, and PostgeSQL. In this tutorial, we will explain how to install Pure FTPd with SSL/TLS on Ubuntu 24.04. ## Prerequisites - A fresh Ubuntu 24.04 [VPS](https://www.atlantic.net/vps-hosting/) on the Atlantic.Net Cloud Platform. - A root password configured on your server. ## Step 1 – Create Atlantic.Net Cloud Server First, log in to your [Atlantic.Net Cloud Server](https://cloud.atlantic.net/?page=userlogin).  Create a new [server](https://www.atlantic.net/vps-hosting/how-to-create-new-atlantic-net-cloud-server/), choosing Ubuntu 24.04 as the operating system with at least 1GB RAM. Connect to your Cloud Server via SSH and log in using the credentials highlighted at the top of the page. Once you are logged in to your Ubuntu 24.04 server, run the following command to update your base system with the latest available packages. ``` apt-get update -y ``` ## Step 2 – Install Pure FTPd By default, Pure FTPd is available in the Ubuntu 24.04 default repository. You can install it with the following command: ``` apt-get install pure-ftpd -y ``` After installing Pure FTPd, you can verify the status of Pure FTPd with the following command: ``` systemctl status pure-ftpd ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/08/f1.png) ## Step 3 – Create FTP User Next, you will need to create a FTP user in your system. You can create it with the following command: ``` adduser vyom ``` You will be asked to set a password as shown below: ``` Adding user `vyom' ... Adding new group `vyom' (1000) ... Adding new user `vyom' (1000) with group `vyom' ...Creating home directory `/home/vyom' ... Copying files from `/etc/skel' ... New password: Retype new password: passwd: password updated successfully Changing the user information for vyom Enter the new value, or press ENTER for the default             Full Name []:             Room Number []:             Work Phone []:             Home Phone []:             Other []: Is the information correct? [Y/n] Y ``` ## Step 4 – Create a Self-signed SSL/TLS certificate Next, you will need to generate a self-signed certificate for Pure FTPd. You can generate it with the following command: ``` openssl req -x509 -nodes -newkey rsa:2048 -keyout /etc/ssl/private/pure-ftpd.pem -out /etc/ssl/private/pure-ftpd.pem -days 365 ``` Answer all the questions with answers relevant to your installation, as shown below: ``` Generating a RSA private key.......................+++++....+++++writing new private key to '/etc/ssl/private/pure-ftpd.pem'-----You are about to be asked to enter information that will be incorporated into your certificate request.What you are about to enter is what is called a Distinguished Name or a DN.There are quite a few fields but you can leave some blankFor some fields there will be a default value,If you enter '.', the field will be left blank.-----Country Name (2 letter code) [AU]:INState or Province Name (full name) [Some-State]:GUJLocality Name (eg, city) []:JUNOrganization Name (eg, company) [Internet Widgits Pty Ltd]:AtlanticOrganizational Unit Name (eg, section) []:ITCommon Name (e.g. server FQDN or YOUR name) []:exampleEmail Address []:admin@example.com ``` ## Step 5 – Configure Pure FTPd to use SSL/TLS Next, you will need to configure Pure FTPd to use the certificate which we have generated above. You can configure it by editing the pure-ftpd.conf file: ``` nano /etc/pure-ftpd/pure-ftpd.conf ``` Change the following lines: ``` TLSCipherSuite               HIGHCertFile                     /etc/ssl/private/pure-ftpd.pem ``` Save and close the file when you are finished. Enable the TLS support. ``` echo "2" | tee /etc/pure-ftpd/conf/TLS ``` Then, restart the Pure FTPd service to apply the changes: ``` systemctl restart pure-ftpd ``` At this point, Pure FTPd is installed and configured to use SSL/TLS. ## Step 6 – Connect FTP Server from Client Next, you will need to connect to your Pure FTPd server from the client machine using the FileZilla FTP client. First, open the FileZilla client and click on the **Site Manager**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Pure-FTPd-Filezilla-Site-Manager-1024x583.png) Provide your Pure FTPd server IP, select FTP protocol, select “Require explicit FTP over TLS”, provide your FTP username and password, and click on the **Connect** button. You will be prompted to accept the certificate as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/08/f2.png) Accept the certificate and click on the **OK** button. Once you are connected, you should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Pure-FTPd-Filezilla-Connected-1024x590.png) ## Conclusion Congratulations! You have successfully installed Pure FTPd with SSL/TLS support on Ubuntu 24.04 server. You can now upload and download files and directories, to and from the FTP server. Try Pure FTPd today on Linux [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How To Install Calibre Web On Ubuntu 20.04 with Docker > URL: https://www.atlantic.net/vps-hosting/how-to-install-calibre-web-on-ubuntu-20-04-with-docker/ | Published: 2020-08-25 | Updated: 2023-11-17 | Author: Hitesh Jethva Calibre Web is a web-based application that allows you to browse, download, and read eBooks using an existing Calibre database. You can also integrate Google Drive or Dropbox, edit metadata, and update your Calibre library through the app itself. Calibre Web allows you to access your Calibre libraries and read books directly in a browser on your favorite mobile phone or tablet device. **Features** - Bootstrap 3 HTML5 interface - User management - Support for editing eBook metadata - Restrict eBook download to logged-in users - Support for reading eBooks directly in the browser - Fine-grained per-user permissions - Create a custom book collection In this tutorial, we will show you how to install Calibre Web with Docker on Ubuntu 20.04. ## Step 1 – Install Docker and Docker Compose By default, the latest version of Docker is not available in the Ubuntu 20.04 default repository, so it is recommended to add Docker’s official repository in your system. First, install some required packages with the following command: ``` apt-get install apt-transport-https ca-certificates curl software-properties-common -y ``` Once all the packages are installed, import the GPG key with the following command: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add - ``` Next, add the Docker repository with the following command: ``` add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu focal stable" ``` Next, install the latest version of Docker and Docker Compose with the following command: ``` apt-get install docker-ce docker-compose -y ``` Once installed, verify the version of Docker with the following command: ``` docker --version ``` You should see the following output: ``` Docker version 19.03.12, build 48a66213fe ``` You can also verify the Docker Compose version with the following command: ``` docker-compose --version ``` You should see the following output: ``` docker-compose version 1.25.0, build unknown ``` ## Step 2 – Install Calibre Web First, you will need to create a directory to store books and a database. You can create it with the following command: ``` mkdir -p /volume1/books/calibre ``` Next, give proper permission and ownership with the following command: ``` chown -R root:users /volume1/ chmod -R 770 /volume1 ``` Next, create a Docker container for Calibre Web with the following command: ``` docker create --name=calibre-web --restart=always -v /volume1/books/calibre:/books -e SET_CONTAINER_TIMEZONE=true -e CONTAINER_TIMEZONE=Europe/Amsterdam -e PGID=100 -e PUID=1000 -p 8082:8083 technosoft2000/calibre-web:v1.1.9 ``` You should get the following output: ``` Unable to find image 'technosoft2000/calibre-web:v1.1.9' locally latest: Pulling from linuxserver/calibre-web 1b6b131f80dd: Pull complete 0644a6c93828: Pull complete 5ce05b5dfdaa: Pull complete 9ffa5f0d8822: Pull complete 6bfcd0e10365: Pull complete b92a89a4f19d: Pull complete Digest: sha256:27f5979ffc9ba3e5c4b2ef4385cc30e2af42a6a7d453302f45ecdc75f47c4bf8 Status: Downloaded newer image for technosoft2000/calibre-web:v1.1.9 f9a32db589bdc00a34ee089d3da14d416f97f4376f2249dd9a0d955f43e9e2a7 ``` Next, start the container with the following command: ``` docker start calibre-web ``` At this point, Calibre Web is installed and listening on port 8082. You can check it with the following command: ``` ps -ef | grep 8082 ``` You should see the following output: ``` root        3248     425  0 10:46 ?        00:00:00 /usr/bin/docker-proxy -proto tcp -host-ip 0.0.0.0 -host-port 8082 -container-ip 172.17.0.2 -container-port 8083 root        3943     855  0 10:56 pts/0    00:00:00 grep --color=auto 8082 ``` ## Step 3 – Access Calibre Web Now, open your web browser and type the URL http://your-server-ip:8082. You will be redirected to the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Calibre-Configuration-1024x417.png) Now, provide the location of the eBook and click on the **Login** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Calibre-Login-1024x443.png) Now, provide default username as **admin** and password as **admin123**, and click on the **Login** button. You should see the Calibre Web dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Calibre-Dashboard-1024x489.png) ## Conclusion Congratulations! You have successfully installed Calibre Web with the Docker on Ubuntu 20.04. You can now easily upload, download, and read your book online through a web browser. Try Calibre Web today on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Install CodeIgniter PHP Framework on Debian > URL: https://www.atlantic.net/vps-hosting/how-to-install-codeigniter-php-framework-on-debian/ | Published: 2020-08-26 | Updated: 2025-09-02 | Author: Hitesh Jethva CodeIgniter is a free and open-source PHP MVC Framework used for building websites in PHP. It is a very powerful framework that allows you to easily create full-featured web applications. CodeIgniter provides a set of useful libraries used for performing various operations like sending emails, uploading files, managing sessions, and more. Lightweight but powerful, CodeIgniter enables developers to write their applications much more quickly. In this tutorial, we will explain how to install the CodeIgniter PHP Framework on Debian 12. ## Step 1 – Install LAMP Stack First, you will need to install the Apache web server, MariaDB server, PHP, and other required packages in your system. You can install all of them by running the following command: ``` apt-get install apache2 mariadb-server libapache2-mod-php php php-cli php-intl php-mysql php-zip php-gd php-mbstring php-curl php-xml php-pear php-bcmath unzip git wget nano -y ``` Once all the packages are installed, start the Apache and MariaDB services and enable them to start at system reboot with the following command: ``` systemctl start apache2 systemctl start mariadb systemctl enable apache2 systemctl enable mariadb ``` ## Step 2 – Configure the MariaDB Database Next, you will need to create a database and user for CodeIgniter. First, log in to MySQL shell with the following command: ``` mysql ``` Once logged in, create a user and database with the following command: ``` CREATE USER 'codeigniter'@'localhost' IDENTIFIED BY 'password'; CREATE DATABASE codeigniterdb; ``` Next, grant all the privileges to the codeigniter database with the following command: ``` GRANT ALL ON codeigniterdb.* to 'codeigniter'@'localhost'; ``` Next, flush the privileges and exit from the MariaDB console with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install and Configure CodeIgniter First, download the latest version of CodeIgniter from the Git repository with the following command: ``` wget https://github.com/codeigniter4/CodeIgniter4/archive/refs/heads/4.7.zip ``` Once downloaded, unzip the downloaded file to the Apache web root directory: ``` unzip 4.7.zip mv CodeIgniter4-4.7 /var/www/codeigniter ``` Set proper ownership and permission with the following command: ``` chown -R www-data:www-data /var/www/codeigniter chmod -R 755 /var/www/codeigniter ``` Once you are done, you can proceed to the next step. ## Step 4 – Configure Apache for CodeIgniter Next, you will need to create an Apache virtual host configuration file to serve the CodeIgniter application. You can create it with the following command: ``` nano /etc/apache2/sites-available/codeigniter.conf ``` Add the following lines: ``` ServerName codeigniter.example.comDocumentRoot /var/www/codeigniter/publicAllowOverride AllErrorLog ${APACHE_LOG_DIR}/error.logCustomLog ${APACHE_LOG_DIR}/access.log combined ``` Save and close the file, then enable the virtual host configuration file with the following command: ``` a2ensite codeigniter.conf ``` Next, restart the Apache service to apply the changes: ``` systemctl reload apache2 ``` ## Step 5 – Access CodeIgniter At this point, CodeIgniter is installed and configured with Apache. Now, open your web browser and access the URL **http://codeigniter.example.com.** You should see your CodeIgniter application in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/08/CodeIgniter-Application-1024x426.png) ## Conclusion Congratulations! You have successfully installed CodeIgniter Framework with Apache on Debian 12. For more information about how to use this PHP web application framework visit the CodeIgniter [documentation](https://www.codeigniter.com/user_guide/) page. Get started with CodeIgniter today on a Debian 12 VPS with [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Bitwarden Password Manager with Docker on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-bitwarden-password-manager-with-docker-on-ubuntu-20-04/ | Published: 2020-08-27 | Updated: 2024-06-04 | Author: Hitesh Jethva Bitwarden is a free and open-source password manager that can be used to store passwords for any device and browser. Bitwarden helps you to not only create and manage your passwords but also sync them across all devices. It offers several client applications including mobile apps, a CLI, a web interface, browser extensions, and desktop applications. In this tutorial, we will show you how to install the Bitwarden Password Manager on Ubuntu 20.04 server. ## Step 1 – Install Required Dependencies First, you will need to install some dependencies in your server. You can install all of them by running the following command: ``` apt-get install apt-transport-https ca-certificates curl gnupg-agent software-properties-common -y ``` Once all the packages are installed, you can proceed to the next step. ## Step 2 – Install Docker and Docker Compose By default, the latest version of Docker is not available in the Ubuntu 20.04 default repository, so it is a good idea to add the Docker official repository in your system. First, download and add the GPG key with the following command: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add - ``` Next, add the Docker repository with the following command: ``` add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" ``` Once the repository is added, you can install the Docker and Docker Compose using the following command: ``` apt-get install docker-ce docker-ce-cli containerd.io docker-compose -y ``` After installing both packages, check the installed version of Docker with the following command: ``` docker --version ``` You should get the following output: ``` Docker version 19.03.12, build 48a66213fe ``` You can also verify the Docker Compose version with the following command: ``` docker-compose --version ``` You should see the following output: ``` docker-compose version 1.25.0, build unknown ``` ## Step 3 – Install Bitwarden First, you will need to download the Bitwarden installation script from their official website. You can download it with the following command: ``` curl -Lso bitwarden.sh https://go.btwrdn.co/bw-sh ``` Next, give the execution permission to the downloaded script: ``` chmod +x bitwarden.sh ``` Before installing Bitwarden, you will need to generate the Bitwarden installation ID and Key. You can generate them from the Bitwarden website. ![](https://www.atlantic.net/wp-content/uploads/2020/08/Bitwarden-Installation-Generate-ID-Key-1024x308.png) Provide your email address and click on the **Submit** button. You should see your installation ID and Key in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Bitwarden-Installation-ID-Key-1024x519.png) Next, start the Bitwarden installation with the following command: ``` ./bitwarden.sh install ``` During the installation, you will be asked to provide your server IP, installation key and installation ID as shown below: ```  _     _ _                         _            | |__ (_) |___      ____ _ _ __ __| | ___ _ __  | '_ \| | __\ \ /\ / / _` | '__/ _` |/ _ \ '_ \ | |_) | | |_ \ V  V / (_| | | | (_| |  __/ | | | |_.__/|_|\__| \_/\_/ \__,_|_|  \__,_|\___|_| |_| Open source password management solutions Copyright 2015-2020, 8bit Solutions LLC https://bitwarden.com, https://github.com/bitwarden =================================================== Docker version 19.03.12, build 48a66213fe docker-compose version 1.25.0, build unknown (!) Enter the domain name for your Bitwarden instance (ex. bitwarden.example.com): 69.87.216.49 (!) Do you want to use Let's Encrypt to generate a free SSL certificate? (y/n): n 1.36.1: Pulling from bitwarden/setup 6ec8c9369e08: Pull complete fe8522826504: Pull complete 658bf4619169: Pull complete 0392978bbc2e: Pull complete 33dd02257803: Pull complete 2a69859c8164: Pull complete d68079cd71ee: Pull complete 7c08df4e94b0: Pull complete 653a8af878c4: Pull complete d252f877c4a2: Pull complete Digest: sha256:5b2c43b46c03da54aecc6d19098b0574b5fb205f0cd3046019725925cadfdf29 Status: Downloaded newer image for bitwarden/setup:1.36.1 docker.io/bitwarden/setup:1.36.1 (!) Enter your installation id (get at https://bitwarden.com/host): 97e9325e-f0e7-47cf-9667-ac0f008645b9 (!) Enter your installation key: tloMiUlAn4NTUCgWTSC5 (!) Do you have a SSL certificate to use? (y/n): n (!) Do you want to generate a self-signed SSL certificate? (y/n): y Generating self signed SSL certificate. Generating a RSA private key ........................++++ ..................++++ writing new private key to '/bitwarden/ssl/self/69.87.216.49/private.key' ----- Generating key for IdentityServer. Generating a RSA private key .........++++ .......................++++ writing new private key to 'identity.key' ----- !!!!!!!!!! WARNING !!!!!!!!!! You are using an untrusted SSL certificate. This certificate will not be trusted by Bitwarden client applications. You must add this certificate to the trusted store on each device or else you will receive errors when trying to connect to your installation. Building nginx config. Building docker environment files. Building docker environment override files. Building FIDO U2F app id. Building docker-compose.yml. Installation complete If you need to make additional configuration changes, you can modify the settings in `./bwdata/config.yml` and then run: `./bitwarden.sh rebuild` or `./bitwarden.sh update` Next steps, run: `./bitwarden.sh start` ``` Once the installation has been completed, start the Bitwarden service with the following command: ``` ./bitwarden.sh start ``` You can see all command line options with the following command: ``` ./bitwarden.sh help ``` Output: ```  _     _ _                         _            | |__ (_) |___      ____ _ _ __ __| | ___ _ __  | '_ \| | __\ \ /\ / / _` | '__/ _` |/ _ \ '_ \ | |_) | | |_ \ V  V / (_| | | | (_| |  __/ | | | |_.__/|_|\__| \_/\_/ \__,_|_|  \__,_|\___|_| |_| Open source password management solutions Copyright 2015-2020, 8bit Solutions LLC https://bitwarden.com, https://github.com/bitwarden =================================================== Docker version 19.03.12, build 48a66213fe docker-compose version 1.25.0, build unknown Available commands: install start restart stop update updatedb updaterun updateself updateconf renewcert rebuild help ``` ## Step 4 : Access Bitwarden Now, open your web browser and access the Bitwarden using the URL http://your-server-ip. You should see the Bitwarden login screen: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Bitwarden-Login-1024x534.png) Click on the **Create** **account** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Bitwarden-Create-Account-1024x586.png) Provide your email address, name, and master password, then click on the **Submit** button. You should see the Bitwarden login screen: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Bitwarden-Submit-Account-1024x566.png) Provide your email address and password and click on the **Log** **in** button. You should see the Bitwarden dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Bitwarden-Dashboard-1024x534.png) ## Conclusion Congratulations! You have successfully installed the Bitwarden password manager on Ubuntu 20.04 server. I hope this will helps you to store, manage, and sync your password across all devices. Try using Bitwarden with your [VPS Hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [Virtual private servers.](https://www.atlantic.net/vps-hosting/) --- # How to Install Cockpit on Debian > URL: https://www.atlantic.net/vps-hosting/how-to-install-cockpit-on-debian/ | Published: 2020-08-28 | Updated: 2025-09-03 | Author: Hitesh Jethva Cockpit is a free and open-source remote management software sponsored by Red Hat. It provides a web-based interface to manage and monitor a Linux-based server through a web browser. It runs on several operating systems, including Debian, Ubuntu, CentOS, Fedora, RHEL, and Arch Linux. With Cockpit, you can perform server management tasks remotely, such as manage services, create user accounts, monitor system, configure networks, inspect log, system update, manage firewall, domain management, setup OpenVPN, and many more. It also supports Kubernetes and Openshift cluster. Cockpit also provides graphs and easy-to-use forms to measure system performance and make changes to your systems. In this tutorial, we will explain how to install Cockpit on Debian 12. ## Step 1 – Install Cockpit By default, Cockpit is available in the Debian 12 default repository. You can install it by simply running the following command: ``` apt-get update -yapt-get install cockpit -y ``` Once Cockpit is installed, start the Cockpit service and enable it to start at system reboot with the following command: ``` systemctl start cockpit systemctl enable cockpit ``` You can also verify the status of Cockpit with the following command: ``` systemctl status cockpit ``` You should get the following output: ``` ● cockpit.service - Cockpit Web Service    Loaded: loaded (/lib/systemd/system/cockpit.service; static; vendor preset: enabled)    Active: active (running) since Tue 2025-08-28 05:57:44 UTC; 3s ago      Docs: man:cockpit-ws(8)   Process: 30466 ExecStartPre=/usr/sbin/remotectl certificate --ensure --user=root --group=cockpit-ws --selinux-type= (code=exited, status=0/SU  Main PID: 30469 (cockpit-ws)     Tasks: 2 (limit: 2359)    Memory: 2.2M    CGroup: /system.slice/cockpit.service            └─30469 /usr/lib/cockpit/cockpit-ws Aug 28 05:57:44 debian12 systemd[1]: Starting Cockpit Web Service... Aug 28 05:57:44 debian12 remotectl[30466]: Generating temporary certificate using: sscg --quiet --lifetime 3650 --key-strength 2048 --cert-key- Aug 28 05:57:44 debian12 remotectl[30466]: Error generating temporary dummy cert using sscg, falling back to openssl Aug 28 05:57:44 debian12 remotectl[30466]: Generating temporary certificate using: openssl req -x509 -days 36500 -newkey rsa:2048 -keyout /etc/ Aug 28 05:57:44 debian12 systemd[1]: Started Cockpit Web Service. Aug 28 05:57:44 debian12 cockpit-ws[30469]: Using certificate: /etc/cockpit/ws-certs.d/0-self-signed.cert ``` ## Step 2 – Access Cockpit Web Interface At this point, Cockpit is installed and listening on port 9090. You can verify the listening port with the following command: ``` apt install net-tools -y netstat -tunelp | grep  9090 ``` You should see the following output: ``` tcp6       0      0 :::9090                 :::*                    LISTEN      0          192987     1/init ``` Next, create a dedicated administrative user using the below command: ``` adduser adminuser ``` Set your password as shown below: ``` Adding user `adminuser' ... Adding new group `adminuser' (1000) ... Adding new user `adminuser' (1000) with group `adminuser (1000)' ... Creating home directory `/home/adminuser' ... Copying files from `/etc/skel' ... New password: Retype new password: passwd: password updated successfully ``` Add your user to sudo group. ``` usermod -aG sudo adminuser ``` Now, open your web browser and access the Cockpit web UI using the URL **https://your-server-ip:9090.** You will be redirected to the Cockpit web interface as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/08/cock.png) Provide your username and password, and click on the **Log** **in** button. You should see the Cockpit dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Cockpit-Dashboard-1024x534.png) In the above screen, you should see the summary of your system information and performance graphs for CPU, Memory, Disk I/O, and network traffic. ## Step 3 – How to Use Cockpit  In this section, we will show you how to use Cockpit web interface. In the left pane, you should see a lot of useful options. In the left pane, click on the **Logs** menu. You should see the logs page which allows for logs inspection. ![](https://www.atlantic.net/wp-content/uploads/2020/08/Cockpit-Logs-1024x527.png) The **Storage**menu provides a summary of the system disk, partition, and file system as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/08/Cockpit-Storage-Menu-1024x529.png) The **Networking**menu provides network interface, IP address, and traffic information. You can also add Bond, Bridge, and VLAN using this menu. ![](https://www.atlantic.net/wp-content/uploads/2020/08/Cockpit-Networking-Menu-1024x530.png) With the **Services**menu, you can see Targets, System Services, Sockets, Timers, and Paths pages. You can also manage system services using this menu. ![](https://www.atlantic.net/wp-content/uploads/2020/08/Cockpit-Services-Menu-1024x530.png) The **Terminal**menu provides a command-line interface to execute commands in your system. ![](https://www.atlantic.net/wp-content/uploads/2020/08/Cockpit-Terminal-Menu-1024x531.png) ## Conclusion In this guide, you learned how to install and use Cockpit on Debian 12. This tool is very useful for Linux beginners who don’t know the command-line and helps you to control a Linux server through a web interface. Get started with Cockpit on your Linux server on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Configure Parse Server on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-configure-parse-server-on-ubuntu-20-04/ | Published: 2020-09-01 | Updated: 2024-09-25 | Author: Hitesh Jethva Parse Server is a free and open-source Backend-as-a-Service platform developed by Facebook. It is written in Node.js and can be used for any application running Node.js. Parse Server comes with a simple and easy-to-use web interface that can be used for data manipulation, to view analytics, and to schedule and send push notifications. In this tutorial, we will show you how to install Parse Server on Ubuntu 20.04. ## Step 1 – Install MongoDB By default, MongoDB is available in the Ubuntu 20.04 default repository. You can install it by running the following command: ``` apt-get install mongodb-server -y ``` Once the MongoDB is installed, you can verify the status of MongoDB with the following command: ``` systemctl status mongodb ``` You should see the following output: ``` ● mongodb.service - An object/document-oriented database      Loaded: loaded (/lib/systemd/system/mongodb.service; enabled; vendor preset: enabled)      Active: active (running) since Thu 2020-08-06 07:32:44 UTC; 30s ago        Docs: man:mongod(1)    Main PID: 3222 (mongod)       Tasks: 23 (limit: 4691)      Memory: 42.0M      CGroup: /system.slice/mongodb.service              └─3222 /usr/bin/mongod --unixSocketPrefix=/run/mongodb --config /etc/mongodb.conf Aug 06 07:32:44 ubuntu2004 systemd[1]: Started An object/document-oriented database. ``` ## Step 2 – Install Node.js First, install the necessary dependencies using the following command. ``` apt-get install -y ca-certificates curl gnupg ``` Next, download the Node.js GPG key. ``` mkdir -p /etc/apt/keyrings curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg ``` Next, add the NodeSource repo to the APT source list. ``` echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_18.x nodistro main" | tee /etc/apt/sources.list.d/nodesource.list ``` Then, update the repository index and install the Ndoe.js with the following command. ``` apt update apt-get install -y nodejs ``` Next, verify the Node.js version using the following command. ``` node -v ``` Output. ``` v18.19.0 ``` ## Step 3 – Install Parse Server You can install the parse-server module using the Yarn package manager as shown below: ``` yarn global add parse-server ``` Once installed, you will need to create a parse server configuration file and define the attributes of the parse server. You can create it with the following command: ``` nano config.json ``` Add the following lines: ``` {   "appName": "My Parse Server",   "databaseURI": "mongodb://localhost:27017/parsedb",   "appId": "KSDJFKASJFI3S8DSJFDH",   "masterKey": "LASDK823JKHR87SDFJSDHF8DFHASFDF",   "serverURL": "https://localhost:1337/parse",   "publicServerURL": "https://0.0.0.0:1337/parse",   "port": 1337 } ``` Save and close the file then start the parse server using the following command: ``` nohup parse-server config.json & ``` At this point, the parse server is started and listening on port 1337. You can verify it with the following command: ``` ss -ant | grep 1337 ``` You should get the following output: ``` LISTEN     0       511            0.0.0.0:1337            0.0.0.0:*             TIME-WAIT  0       0            127.0.0.1:1337          127.0.0.1:40568      ``` ## Step 4 – Configure Parse Server Dashboard Parse server comes with a powerful dashboard that allows you to access the Parse server through a web browser. You can install the parse dashboard with the following command: ``` yarn global add parse-dashboard ``` After installing the Parse dashboard, create a configuration file for the Parse dashboard with the following command: ``` nano parse-darshboard-config.json ``` Add the following lines: ``` {   "apps": [     {       "serverURL": "http://your-server-ip:1337/parse",       "appId": "KSDJFKASJFI3S8DSJFDH",       "masterKey": "LASDK823JKHR87SDFJSDHF8DFHASFDF",       "allowInsecureHTTP": "true",       "appName": "MyApp1"     }   ],  "users": [     {       "user":"admin",       "pass":"yourpassword"     }   ],   "iconsFolder": "icons" } ``` Save and close the file, then start the Parse dashboard with the following command: ``` nohup parse-dashboard --dev --config parse-darshboard-config.json & ``` At this point, the Parse dashboard is started and listening on port 4040. You can verify it with the following command: ``` ss -ant | grep 4040 ``` You should get the following output: ``` LISTEN  0       511            0.0.0.0:4040             0.0.0.0:*      ``` ## Step 5 – Verify Parse Server At this point, the Parse server is installed and configured. Now, perform some tests to make sure it’s running. First, add some values to the Parse server with the following command: ``` curl -X POST -H "X-Parse-Application-Id: KSDJFKASJFI3S8DSJFDH" -H "Content-Type: application/json" -d '{"score":1337,"InventoryName":"Desktops","cheatMode":false}' http://localhost:1337/parse/classes/Inventory ``` You should get the following output: ``` {"objectId":"BCq9j8fPfM","createdAt":"2020-08-06T07:48:14.530Z"} ``` Now, fetch the value from the Parse server using the following command: ``` curl -X GET -H "X-Parse-Application-Id: KSDJFKASJFI3S8DSJFDH" http://localhost:1337/parse/classes/Inventory/BCq9j8fPfM ``` You should get the following output: ``` {"objectId":"BCq9j8fPfM","score":1337,"InventoryName":"Desktops","cheatMode":false,"createdAt":"2020-08-06T07:48:14.530Z","updatedAt":"2020-08-06T07:48:14.530Z"} ``` ## Step 6 – Access Parse Server Dashboard You can also access the parse server dashboard by visiting the URL http://your-server-ip:4040 in your web browser. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/09/Parse-Login-1024x518.png) Provide your admin username and password which you have defined in the Parse dashboard configuration file and click on the **Log** **in** button. You should see the Parse server dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/09/Parse-Dashboard-1024x529.png) ## Conclusion In this guide, you learned how to install Parse Server and Parse Dashboard in Ubuntu 20.04 server. You can now build your mobile application’s backend with Parse Server on a [VPS Hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net! --- # Hybrid Hosting – One Size Does Not Fit All > URL: https://www.atlantic.net/hipaa-compliant-hosting/hybrid-hosting-one-size-not-fit/ | Published: 2020-09-11 | Updated: 2025-09-19 | Author: Kent Roberts A hosting service provider may tend to focus more on standardized packages or on its ability to customize and provide highly specialized service on a case-by-case basis. When a provider is known for its central attention to customization and creating unique systems to meet the challenges of organizations one at a time, they will often have to find ways to problem-solve sophisticated technical issues of their clients. Again, customization of solutions should not be a standard expectation. Often a company will sell simplified one-size-fits-all plans or will simply offer external server management. On the other hand, a company with a broad array of customizable solutions will offer a range of services that could include dedicated servers and nodes, public cloud, private cloud, and colocation, along with managed services – all of which can be ingredients of a hybrid hosting setup. ## Examples of Hybrid Hosting Solutions In terms of different types of situations that benefit from a customized approach, here are a few: A company will often want to improve its cost savings, security, and efficiency by transitioning to a cloud environment from an internal data center, colocation setup, or hosted servers. These customers might need services that will handle migration and management of the system, along with the infrastructure services that will allow them the raw resources to run their workloads and support to maintain their systems. An organization might run an advertising demand-side platform (DSP) or other type of online ad network with very specific stipulations in terms of their IT space. They will have to find an environment that gives them incredible memory, processing, and network connectivity performance. At the same time, they need to be conscientious about cost since they do not have big margins with which to work. An organization of that type will generally want to use a public cloud plan along with some sort of private cloud. These two types of systems may or may not be fully integrated with one another by the provider. A hosting client might need to have the strongest possible security mechanisms and protocols in place. These elements might include **two-factor authentication** (2FA), **firewalls**, and **encrypted backup**. Often the companies that will need this degree of security are those concerned with compliance – as is typical of healthcare organizations. A fully compliant setting can be provided by a host that has a properly designed system within public cloud; note that there should be total isolation of data and compute to allow for the greatest possible organizational control and agility. One other type of company for which a hybrid setup is useful is an aviation business that specializes in flight controls. A firm of this type might want to use colocation services in order to maintain full control of the aspect of the system that they want to run through equipment they own. For the rest of their infrastructure, though, these companies will often choose to spin up servers on Public Cloud, allowing them to avoid a large initial expense and ongoing maintenance. ## Priority #1 – Security For many organizations, especially those in highly regulated industries such as healthcare, data security is the first priority. When security is a paramount concern, firms want to know the best practices in terms of storing something in a private cloud vs. a public one. However, a high-quality hosting provider will have a [data center](https://www.atlantic.net/hipaa-data-centers/) audited to meet the exacting parameters of the Service Organization Control Reports ([SOC 1 and SOC 2](https://www.aicpa.org/interestareas/frc/assuranceadvisoryservices/downloadabledocuments/faqs_service_orgs.pdf)), formulated within the Statement on Standards for Attestation Engagements No. 18 (SSAE 18), a standard developed by the American Institute of Certified Public Accountants (AICPA). Called “Reporting on Controls at a Service Organization,” SSAE 16 is a highly respected set of guidelines used for auditing purposes, to check for appropriate security safeguards and other best-practice accounting and monitoring controls. The effort and expense required to get this voluntary certification is an indicator that a host cares about data safety, and that it wants to prove it. Within an SSAE 16 compliant setting, backed by a hosting provider with years in the industry, anyone using the hybrid hosting provider should feel confident that they can get secure solutions in the full range of environments – dedicated servers and private cloud, [as well as public cloud](https://urldefense.proofpoint.com/v2/url?u=https-3A__www.atlantic.net_hipaa-2Dcompliant-2Dhosting_how-2Dsecure-2Dis-2Dthe-2Dcloud_&d=DQIGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=UChi3C1F2KzF3gDdKeDIWT0Y2FVnGxMftp5efqLBa9U&m=WeBwqR0vC2QPmHQe1L_HqvKB4WvOk9cwp4FMsQLtHmc&s=zl-KJ8gy3EUWCiMwkRiZ_wJ3JUyTnQtBDO7Ih_qycNQ&e=). Since many thought leaders have suggested recently that cloud might even outdo on-premise from a raw security perspective, more companies are transitioning their systems to cloud, including test environments. At many companies, very little of the infrastructure is now maintained internally. ## Choosing a Hybrid Host The challenge with setting up a customized solution is that it is, by its nature, unique. Setting up environments in this manner requires engineering skill and an environmental culture of flexibility. Specifically in terms of networking, you want an organization that commonly utilizes technologies such as virtual private networks (VPNs) and multi-protocol label switching (MPLS) so that communications can occur through standardized security protocols. Are you looking for a hybrid host? At Atlantic.Net, we have a lot of flexibility and go as far as the client requires, with customized solutions configured to individual specifications, including [HIPAA Managed Hosting](https://www.atlantic.net/hipaa-compliant-hosting/). We are audited to meet SOC 1 and SOC 2 for broad SSAE 18 compliance, and offer years of networking and connectivity experience, having originally formed as an internet service provider (ISP). ### Atlantic.Net Hybrid Hosting Services One size does not fit all and we understand that. Do you already have an extensive IT infrastructure in place? Are you simply looking to store a bit of data offsite? Atlantic.Net can help in both situations, with our custom Hybrid Hosting. ### Extend Your IT Infrastructure ![Extend Your IT Infrastructure](https://www.atlantic.net/wp-content/themes/anet/img/site/front-page/infrastructure.png) We put our vast experience in connectivity and advanced computing to use, to help provide our clients with unique, powerful and flexible hosting options. Below are some scenarios, where Atlantic.Net can assist but you’re also free to mix and match: - Dedicated Virtualization in combination with an existing Atlantic.Net Hosting Solution. - Dedicated Virtualization in tandem with server colocation at a data center of your choice. - Secondary dedicated hosting platform established in parallel to an existing cloud environment. - Virtualization Hosting in combination with existing computing solutions elsewhere. - On-site and off-site private virtualization, combined for a robust hybrid hosting infrastructure. - Cloud in combination with the Atlantic.Net Hosting Solution of your choice. - Cloud in tandem with server colocation at our data center or a data center of your choice. - Secondary cloud hosting platform established in parallel to an existing cloud. - Cloud Solutions in combination with existing computing solutions elsewhere. - On-site and off-site private and public clouds, combined for a robust hybrid hosting infrastructure. With Hybrid Hosting, you’ll have the best of both worlds – tremendous savings and the ability to enjoy the latest, dedicated, secure, and robust hosting platform. And with Atlantic.Net, you’ll have a host with all the expertise necessary to enable you to get the most out of hybrid hosting. Count on it. With our hybrid solutions for your team, Atlantic.Net outperforms the competition. Along with the highly redundant hosting solutions, Atlantic.Net also provides a wide array of managed services, including backup as a service, firewall as a service, security as a service, and more. If you have any questions about Atlantic.Net’s Hybrid Solutions, please call 866-618-DATA or email [sales@atlantic.net](mailto:sales@atlantic.net) for a free evaluation of your environment to see how Atlantic.Net can help you today! --- # Replace Your Physical Tape Backups with Atlantic.Net Cloud Backups and Save > URL: https://www.atlantic.net/dedicated-server-hosting/replace-your-physical-tape-backups-with-atlantic-net-cloud-backups-and-save/ | Published: 2020-09-14 | Updated: 2025-09-19 | Author: Richard Bailey Tape backup technology became popular in the early 1960s. IBM pioneered the technology,  creating the first tape libraries and introducing tape media for data backup into the public domain.   Today, many organizations, governments, and professional institutions still rely on tape backup for legacy systems; however, the use of tapes is rapidly declining. This decline has been hastened by the surge in cloud computing, with many tech firms adopting flexible cloud backup solutions. Atlantic.Net has various backup solutions available; all of our Cloud solutions are underpinned by a managed [cloud backup service](https://www.atlantic.net/cloud-platform/backups/). This is a flexible service that can be enabled with the click of a mouse. For our Managed Hosting and [Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/) customers, we can provide a fully managed [Veeam Backup solution](https://www.atlantic.net/managed-services/veeam-services/) and also a proprietary Atlantic.Net Cloud Platform (ACP) Backups. ## What is Cloud Backup? Atlantic.Net’s Cloud Backups are a fully automated, flexible service that is surprisingly easy to set up; for the Atlantic.Net Cloud Platform (ACP) Backups, you only have to press a checkbox when building a Virtual Machine or when adding a backup to an existing Atlantic.Net VM. Cloud Backups enables File-Level Recovery as well as Full System Restore capabilities. Optional ACP Offsite Backups are protected offsite using the latest offsite backup technology. Did you know that you can even take a separate snapshot of a server and export it to another Atlantic.Net location, or recover the snapshot onto a brand new VM? ACP Snapshots are great when upgrading your server, as they offer a working rollback option. ## What is a Managed Veeam Service? Veeam is a highly versatile agent-based backup solution that works incredibly well with both Virtual Machines and Physical Hosts. Veeam can back up entire environments and restore data into sandbox locations for testing. The service offers significant savings, as we onboard you to our licensing model, meaning significantly less financial outlay when compared with creating your own Veeam solution. The incremental forever backups are super-fast and very lightweight, and recovery is lightning-quick and bulletproof, as each backup is validated for integrity prior to being marked successful. Veeam can snapshot data and replicate critical datasets to an alternative Atlantic.Net location. ## Why Replace Your Tape Backups? Tape libraries are hugely expensive to buy, maintain, license, and replace if a fault occurs. Tape media is pricey, and its capacity may be considered too small for modern enterprise workloads. Tape libraries have limited scalability, as each library can only expand to a predefined number of tape drives. If you run out of drives, you need to purchase an entirely new library and pool resources. Tape read and write access speeds are also considered very slow, and tape backups are inefficient as they can often span multiple tapes, resulting in slow media inventories when attempting to restore a backup set from tape.  The tape media degrades over time and can easily become damaged, especially if dropped by mistake. There is a lot of manual effort needed to accurately track tape rotations, and tapes are prone to getting stuck in the tape drive mechanism, often requiring an on-site engineer to fix. ## What are the Advantages of a Managed Backup Service? Atlantic.Net Cloud Backup solutions don’t have the problems with efficiency, fragility, and cost that tape backups have. They are fully managed services, meaning that you do not need to worry about the backend systems; Atlantic.Net will look after all of that. Our solutions are disk-based, and our locations are interconnected using rapid network connectivity for seamless data transfer. Another major problem with tape backups is the day-to-day management of the tape media. Skilled media administrators are difficult to find, and tape rotations are very difficult to manage accurately unless sophisticated tape handling processes are defined or expensive tape management software is used.  These complexities can result in human error, potentially resulting in missed backups or incorrectly following the backup rotation policy. All of these limitations make it very easy to lose track of tapes or miss key backup schedules, such as month- or year-end backups, and mismanagement of tape backups can create issues such as the wrong backup tapes being sent to offsite storage.  Again, with a managed backup service from Atlantic.Net, these problems go away. Our highly trained backup specialists monitor, manage, and maintain all our backup platforms 24x7x365. ### Getting Started with Cloud Backups We are proud to welcome you to the Atlantic.Net [Cloud Backups service](https://www.atlantic.net/cloud-platform/backups/) and the [Veeam Managed Service](https://www.atlantic.net/managed-services/veeam-services/). Both are designed to protect your critical data in the cloud and eliminate the problems of inefficiency created by tape backups. There are significant advantages to embracing cloud backup and save technology. You can transfer your infrastructure to our cloud backup storage, ensuring you have the critical restore points needed for your organization’s disaster recovery and data retention requirements.  The technology provides multiple opportunities for cost savings, including an OPEX cost model that only charges our customers for what they use on a pay-as-you-go basis. Cost savings can be recovered by saving on the manpower needed to manage the backup solution, as this responsibility is managed by Atlantic.Net; you can rest assured that all your critical data is backed up as per the terms of our SLA agreement, leaving you the time to concentrate on your core business. The Cloud Backup solution utilizes an advanced agentless technology that uses none of the customer’s system resources, and industry-leading deduplication technology drastically cuts bandwidth utilization and reduces overall storage costs. Data is saved on the Atlantic.Net proprietary cloud storage solution; this custom-designed technology offers immense flexibility, usability, and accessibility. Best of all, we can ingest huge quantities of data into the cloud storage without restriction. The storage provides fault tolerance, redundancy, and data replication capabilities between your choice of 8 data center locations. ## Cloud Archiving Our existing customers enjoy an agile cloud solution that provides secure storage of business-critical data in their preferred location. Cloud archiving is a non-disruptive service where the only prerequisite is network connectivity.  Some of our clients choose to operate the service over their existing network circuits, while others decide to purchase additional dedicated backup circuits for more intense workloads. Our customers can utilize their existing trusted backup software as part of this service if required. Cloud Archiving streamlines the entire backup process, reduces costs, and provides our clients with class-leading service level agreements for data retrieval. The customer systems can remain on-premise, as the data is transferred to the Atlantic.Net storage solutions. Gone are the days of painstakingly slow restore requests, managing the process of recalling tapes, or waiting for the tapes to be located or couriered to site; instead, data is available near-instantly and on-demand, and there is no need to wait hours, days, weeks for data recovery. Ready to get started with Atlantic.Net [Cloud Backups](https://www.atlantic.net/cloud-platform/backups/) and [Veeam Managed Service](https://www.atlantic.net/managed-services/veeam-services/)? Contact Atlantic.Net today and we’ll help you take advantage of our easy-to-use backups, and can help you with a plan to transfer your data from your legacy tape backup system to our environment! --- # How to Install Ansible AWX on Debian 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-ansible-awx-on-debian-10/ | Published: 2020-09-17 | Updated: 2023-11-17 | Author: Hitesh Jethva Ansible is a free and open-source configuration management and automation tool used to manage hundreds and thousands of servers from a central location. Ansible AWX is an open-source project, sponsored by Red Hat, that helps you control Ansible in IT environments. It provides a web-based interface REST API and task engine for Ansible. You can manage playbooks, secrets, inventories, and cron jobs using the AWX web-based interface. In this tutorial, we will show you how to install Ansible AWX with Docker on Debian 10. ## Step 1 – Install Docker First, you will need to install the Docker and Docker compose in your system. By default, the latest version of Docker is not available in the Debian standard repository, so you will need to add the Docker repository to your system. Install the required dependencies with the following command: ``` apt-get install apt-transport-https ca-certificates curl gnupg2 software-properties-common -y ``` Next, download and add the Docker GPG key with the following command: ``` curl -fsSL https://download.docker.com/linux/debian/gpg | apt-key add - ``` Next, add the Docker repository with the following command: ``` add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/debian $(lsb_release -cs) stable" ``` Next, update the Docker repository and install Docker with Docker compose using the following command: ``` apt-get update -y apt-get install docker-ce docker-compose -y ``` Once both packages are installed, verify the installed version of Docker with the following command: ``` docker --version ``` You should get the following output: ``` Docker version 19.03.13, build 4484c46d9d ``` ## Step 2 – Install Ansible AWX is built on the top of the Ansible. so you will need to install Ansible in your system. First, add the Ansible repository with the following command: ``` apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 93C4A3FD7BB9C367 echo "deb http://ppa.launchpad.net/ansible/ansible/ubuntu bionic main" | tee /etc/apt/sources.list.d/ansible.list ``` Next, update the repository and install the Ansible with the following command: ``` apt-get update -y apt-get install ansible -y ``` Once the Ansible is installed, verify the installed version of Ansible using the following command: ``` ansible --version ``` You should get the following output: ``` ansible 2.9.13   config file = /etc/ansible/ansible.cfg   configured module search path = [u'/root/.ansible/plugins/modules', u'/usr/share/ansible/plugins/modules']   ansible python module location = /usr/lib/python2.7/dist-packages/ansible   executable location = /usr/bin/ansible   python version = 2.7.16 (default, Oct 10 2019, 22:02:15) [GCC 8.3.0] ``` ## Step 3 – Install Nodejs and Python Library First, install the Node.js, NPM and Git with the following command: ``` apt-get install nodejs npm git -y npm install npm --global ``` Next, install the Python module for Docker and other required dependencies with the following command: ``` apt-get install python3-pip pwgen python3-docker -y pip3 install requests==2.14.2 ``` Next, update the default Python version with the following command: ``` update-alternatives --install /usr/bin/python python /usr/bin/python2.7 1 update-alternatives --install /usr/bin/python python /usr/bin/python3 2 ``` Next, you will need to install Docker compose Python module in your system. First, check the installed version of Docker compose with the following command: ``` docker-compose version ``` You should get the following output: ``` docker-compose version 1.21.0, build unknown docker-py version: 3.4.1 CPython version: 3.7.3 OpenSSL version: OpenSSL 1.1.1d  10 Sep 2019 ``` Next, installed the matching version of Docker compose Python module with the following command: ``` pip3 install docker-compose==1.21.0 ``` ## Step 4 – Install Ansible AWX First, download the latest version of AWX source from the Git repository using the following command: ``` git clone --depth 50 https://github.com/ansible/awx.git ``` Once downloaded, change the directory to awx and generate the secrete key with the following command: ``` cd awx/installer/ pwgen -N 1 -s 30 ``` You should get the following output: ``` 4NaNkNcMBOj4Jxp4fWi91mymuW9TbR ``` Next, create a new inventory file with the following command: ``` nano inventory ``` Add the following lines including, admin user, password, secret key, port, and hostname as shown below: ``` dockerhub_base=ansible awx_task_hostname=awx awx_web_hostname=awxweb postgres_data_dir=/tmp/pgdocker host_port=80 host_port_ssl=443 docker_compose_dir=/tmp/awxcompose pg_username=awx pg_password=awxpass pg_database=awx pg_port=5432 admin_user=admin admin_password=adminpassword create_preload_data=True secret_key=2fCkx2K5GnIjBz4OterhOC3ey0WPdj ``` Save and close the file when you are finished. Next, run the playbook to install the Ansible AWX with the following command: ``` ansible-playbook -i inventory install.yml ``` Once the Ansible AWX has been installed, you should get the following output: ``` TASK [local_docker : Create Docker Compose Configuration] ************************************************************************************* changed: [localhost] => (item={u'mode': u'0600', u'file': u'environment.sh'}) changed: [localhost] => (item={u'mode': u'0600', u'file': u'credentials.py'}) changed: [localhost] => (item={u'mode': u'0600', u'file': u'docker-compose.yml'}) changed: [localhost] => (item={u'mode': u'0600', u'file': u'nginx.conf'}) changed: [localhost] => (item={u'mode': u'0664', u'file': u'redis.conf'}) TASK [local_docker : Render SECRET_KEY file] ************************************************************************************************** changed: [localhost] TASK [local_docker : Start the containers] **************************************************************************************************** changed: [localhost] TASK [local_docker : Update CA trust in awx_web container] ************************************************************************************ changed: [localhost] TASK [local_docker : Update CA trust in awx_task container] *********************************************************************************** changed: [localhost] PLAY RECAP ************************************************************************************************************************************ localhost                  : ok=15   changed=7    unreachable=0    failed=0    skipped=86   rescued=0    ignored=0   ``` Next, you can verify the list of running containers using the following command: ``` docker ps ``` You should get the following output: ``` CONTAINER ID        IMAGE                COMMAND                  CREATED              STATUS              PORTS                  NAMES 167d008ee26f        ansible/awx:14.1.0   "/usr/bin/tini -- /u…"   About a minute ago   Up About a minute   8052/tcp               awx_task 260c028bf07d        ansible/awx:14.1.0   "/usr/bin/tini -- /b…"   About a minute ago   Up About a minute   0.0.0.0:80->8052/tcp   awx_web e15d5ee1c940        postgres:10          "docker-entrypoint.s…"   About a minute ago   Up About a minute   5432/tcp               awx_postgres 6472ee690066        redis                "docker-entrypoint.s…"   About a minute ago   Up About a minute   6379/tcp               awx_redis ``` ## Step 5 – Access Ansible AWX Dashboard Now, open your web browser and access the Ansible AWX dashboard using the URL **http://your-server-ip**. You will be redirected to the AWX login page: ![](https://www.atlantic.net/wp-content/uploads/2020/09/AWX-Login.png) Provide your admin username and password that you have defined in the inventory file and click on the **SIGN** **IN** button. You should see the Ansible AWX dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/09/AWX-Dashboard.png) ## Conclusion Congratulations! You have successfully installed Ansible AWX with Docker on Debian 10. You can now easily control Ansible inventory, secrets, playbooks, and more from the AWX dashboard; try it now on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install ArangoDB on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-arangodb-on-ubuntu-20-04/ | Published: 2020-09-18 | Updated: 2024-09-25 | Author: Hitesh Jethva ArangoDB is a free, open-source NoSQL database with a flexible data model for documents, graphs, and key-values.  It is a multi-purpose and multi-model database developed by triAGENS GmbH. ArangoDB comes with a simple and easy-to-use web interface and CLI for managing and monitoring databases. It is used in small and large organizations that process large amounts of data. ArangoDB is designed for high-performance and scalable applications that use SQL-like query language. In this tutorial, we will explain how to install the ArangoDB database on Ubuntu 20.04. ## Step 1 – Install ArangoDB By default, ArangoDB is not available in the Ubuntu 20.04 default repository, so you will need to add the ArangoDB repository to your system. First, install some required dependencies using the following command- ``` apt-get install gnupg2 apt-transport-https -y ``` Once all the dependencies are installed, import the ArangoDB GPG key and add the repository with the following command: ``` wget -q https://download.arangodb.com/arangodb34/DEBIAN/Release.key -O- | apt-key add - echo 'deb https://download.arangodb.com/arangodb34/DEBIAN/ /' | tee /etc/apt/sources.list.d/arangodb.list ``` Next, update the repository and install the ArangoDB with the following command: ``` apt-get update -y apt-get install arangodb3 -y ``` During the installation, you will be asked to set the root password as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/09/ArangoDB-Root-Password.jpg) Provide your desired password and hit **OK** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/09/ArangoDB-Repeat.png) Re-enter the password and hit **OK**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/09/ArangoDB-Upgrade.png) Click on the **OK** button to automatically upgrade database files. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/09/ArangoDB-Database-Storage.png) Select the database storage engine and hit the **Ok** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/09/ArangoDB-Backup.png) Click on the **Yes** button to back up the database before upgrading. Once the installation has been completed, start the ArangoDB service and enable it to start at system reboot with the following command: ``` systemctl start arangodb3 systemctl enable arangodb3 ``` ## Step 2 – Connect ArangoDB Shell ArangoDB comes with a command-line utility to manage the databases. You can connect the ArangoDB shell with the following command: ``` arangosh ``` You will be asked to provide the password as shown below: ``` Please specify a password: ``` Provide the root password which you have set during the installation and hit enter. You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/09/ArangoDB-Start.png) Now, create a database named mydb with the following command: ``` 127.0.0.1:8529@_system> db._createDatabase("mydb"); ``` Next, create a database user with the following command: ``` 127.0.0.1:8529@_system> var users = require("@arangodb/users"); 127.0.0.1:8529@_system> users.save("myuser@localhost", "password"); ``` You should see the following output: ``` {   "user" : "myuser@localhost",   "active" : true,   "extra" : {   },   "code" : 201 } ``` Next, grant all the privileges to the mydb database with the following command: ``` 127.0.0.1:8529@_system> users.grantDatabase("myuser@localhost", "mydb"); ``` Now, you can list your databases using the following command: 127.0.0.1:8529@_system> db._databases() You should see the following output: ``` [   "_system",   "mydb" ] ``` Now, exit from the ArangoDB shell with the following command: ``` 127.0.0.1:8529@_system> exit ``` Now, verify the ArangoDB connection using the database and user which you have created earlier using the following command: ``` arangosh --server.username "myuser@localhost" --server.database mydb ``` You will be asked to provide password as shown below: ``` Please specify a password: ``` Provide the password of the myuser and hit Enter. You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/09/ArangoDB-User-Password.png) Now, exit from the ArangoDB shell with the following command: ``` 127.0.0.1:8529@_system> exit ``` ## Step 3 – Access ArangoDB Web Interface ArangoDB comes with a web-based interface for managing and monitoring ArangoDB. By default, it is configured to access only from the localhost. So you will need to configure ArangoDB for external access. You can configure it by editing the file /etc/arangodb3/arangod.conf: ``` nano /etc/arangodb3/arangod.conf ``` Find the following line: ``` endpoint = tcp://127.0.0.1:8529 ``` And replace it with the following line: ``` endpoint = tcp://your-server-ip:8529 ``` Save and close the file, then restart the ArangoDB service to apply the changes. ``` systemctl restart arangodb3 ``` Now, open your web browser and type the URL http://your-server-ip:8529. You should see the ArangoDB login page: ![](https://www.atlantic.net/wp-content/uploads/2020/09/ArangoDB-Login.jpg) Provide your ArangoDB root username and password and click on the Login button. You should see the ArangoDB dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/09/ArangoDB-Dashboard.png) ![](https://www.atlantic.net/wp-content/uploads/2020/09/ArangoDB-Dashboard-2.png) ## Conclusion In this tutorial, you learned how to install ArangoDB on Ubuntu 20.04. You also learned how to user ArangoDB shell to create a database and user. ArangoDB is a very good alternative to MongoDB and can be used in a mission-critical environment. Get started with ArangoDB on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Best Practice for Creating a HIPAA-Compliant LAMP Stack > URL: https://www.atlantic.net/hipaa-compliant-hosting/best-practice-for-creating-a-hipaa-compliant-lamp-stack/ | Published: 2020-09-21 | Updated: 2025-09-19 | Author: Richard Bailey A LAMP stack is a collection of applications that work seamlessly together to create a powerful open-source web server. The application stack is not only completely free, but also unbelievably powerful and highly customizable, both of which make it a popular choice for developers. **Why is it called LAMP?** - **L**inux is the base operating system used on the server. - **A**pache is the most popular web server used today, powering about 37% of all websites.  - **M**ySQL (or MariaDB) is a relational database application that is perfect for storing website data. - **P**HP is a highly adaptable scripting language that is especially suited to web development. One of the best things about a LAMP stack is its ease of deployment. The one-click application is our recommended deployment method, but if you want to give it a try yourself you can: > **Did you know?** > > Atlantic.Net has a one-click application that spins up an Ubuntu LAMP stack in under 30 seconds. ## How to secure a HIPAA-compliant LAMP stack Any LAMP stack that will host or process Protected Health Information (PHI) must adhere to the administrative, physical, and technical safeguards of HIPAA to ensure the confidentiality of data uploaded or made available through a website or application. ## Linux – Hardening the Operating System  If you are a relative newcomer to Linux, Atlantic.Net recommends you let our [one-click LAMP application](https://cloud.atlantic.net/?page=signup) handle the deployment for you. However, if you want to take the plunge and try it yourself, here is what you need to do: - Update the operating system monthly - Utilize the built-in hard drive encryption tools > **Did you know?** > > Two of the best filesystem encryption tools are [eCryptfs](https://launchpad.net/ecryptfs)and [EncFS](https://github.com/vgough/encfs). > > Two of the best block level (disk) encryption tools are [DMCrypt](https://gitlab.com/cryptsetup/cryptsetup) and [VeraCrypt](https://www.veracrypt.fr/en/Home.html). - Only use very strong passwords, and never reuse passwords throughout the LAMP stack - Only use sFTP encryption to transfer files to and from the webserver - Update file permissions so that no user can change or modify files - Ensure no system services or applications run as the root user > **Did you know?** > > You can set up a cron job to *chown*and *chmod*files every night as a scheduled task. This helps with preventing user error and correcting careless mistakes when updating web server files. ## Apache Security Tips - Keep Apache up-to-date - Configure Apache to increase DDOS (denial of service) protection level > **Did you know?** > > Editing the httpd.conf file and reducing the *RequestReadTimeout*, *Timeout*, *KeepAliveTimeout*, and *MaxRequestWorkers*thresholds will greatly improve DDOS protection. - Set strict *chown*, *chmod*, and *chggrp*permissions on *ServerRoot Directories*; this will reduce the ability of a hacker to run arbitrary code - Enforce TLS certificate encryption using *mod_ssl,*ensuring you use a strong cipher suite and OCSP stapling - Implement dynamic content security > **Did you know?** > > The Apache module [mod_security](https://www.modsecurity.org/) can be finely tuned as a HTTP firewall, perfect for dynamic content security. - Protect system settings with .htaccess restrictions - Protect access to service files > **Did you know?** > > To enable this protection, add this to your httpd.conf: > > <**Directory** “/”> **AllowOverride** None > > <**Directory** “/”> **Require** all denied ## MySQL Best Practice The database is where many users will save protected health information. There are strict regulatory compliance rules regarding the masking and de-identification of data, as well as encryption. - Invoke MySQL Enterprise Data Masking and De-identification routines > **Did you know?** > > A server-side plugin called *data_masking* can manage a SQL-Level API to perform masking and de-identification tasks on your data when it is used by an application. - Data must be encrypted at rest > **Did you know?** > > Atlantic.Net’s Cloud Platform is encrypted at rest with every server deployed by default, saving you time and effort from implementing encryption inside MySQL - Enable SELinux for mandatory access controls to protect the MySQL daemon - Implement MySQL plugins to authenticate users and restrict access by user, password, and approved IP address - Enable MySQL Enterprise Audit plugin to enable standard, policy-based monitoring and logging of connection and query activity executed on the 8MySQL servers ## PHP Best Practice PHP is a popular programming language used by websites to display enhanced content. PHP can either run as an Apache plugin or as a standalone CGI binary. No HIPAA legislation relates directly to PHP; instead, PHP must adhere to access and transmission security, and the browser connections must be secure. - Ensure PHP is kept up-to-date - Use PHP to hash and verify all passwords entered by users; BCrypt is included with PHP 7 onwards > **Did you know?** > > Passwords can be hashed using the *password_hash* PHP function. - Use PHP to enforce a user registration system and prevent access to unauthorized users - Use PHP to protect against Cross-site scripting (XSS) and Request Forgery XSFR > **Did you know?** > > You can protect against XSS and XSFR by sanitizing data input. The *htmlspecialchars()* and*htmlentities*functions prevent special characters that can hijack PHP code. Ready to get started with setting up a HIPAA-Compliant LAMP Stack? Choose Atlantic.Net for a one-click LAMP installation that will set you well on your way to a [HIPAA-Compliant LAMP Server](https://www.atlantic.net/hipaa-compliant-hosting/) – get started today! --- # Best Practice for Creating a HIPAA-Compliant LEMP Stack > URL: https://www.atlantic.net/hipaa-compliant-hosting/best-practice-for-creating-a-hipaa-compliant-lemp-stack/ | Published: 2020-09-22 | Updated: 2025-09-19 | Author: Richard Bailey A LEMP stack is a collection of applications that work seamlessly together to create a powerful open-source web server. Unlike a LAMP Stack, which uses Apache, a LEMP Stack is powered by Nginx (pronounced Engine-Ex, hence the E in LEMP).  Nginx is about 2.5x faster than Apache for high traffic websites with static content, so if you have a popular website that serves multiple concurrent connections, then Nginx is what you need. The stack is completely free, and Nginx has many additional modules built-in, including the popular reverse proxy. > **Did you know?** > > Atlantic.Net has a 1-click application that spins up an Ubuntu LEMP stack in under 30 seconds. ## Best Practice to Secure a HIPAA-Compliant LEMP Stack Any LEMP stack that will host or process Protected Health Information (PHI) must adhere to the administrative, physical, and technical safeguards of HIPAA to ensure the confidentiality of data uploaded or made available through a website or application. > **Did you know?** > > You can automatically deploy a LEMP stack on the Atlantic Cloud Platform in less than 30 seconds using our 1-Click Applications. Visit [https://cloud.atlantic.net](https://cloud.atlantic.net/?page=userlogin) for further information. ## Linux – Hardening the Operating System  If you are a relative newcomer to Linux, Atlantic.Net recommends you let our [one-click LEMP application](https://cloud.atlantic.net/?page=userlogin) handle the deployment for you. However, if you want to take the plunge and try it yourself, here is what you need to do: - Update the operating system monthly - Utilize the built-in hard drive encryption tools > **Did you know?** > > Two of the best filesystem encryption tools are [eCryptfs](https://launchpad.net/ecryptfs)and [EncFS](https://github.com/vgough/encfs). > > Two of the best block-level (disk) encryption tools are [DMCrypt](https://gitlab.com/cryptsetup/cryptsetup) and [VeraCrypt](https://www.veracrypt.fr/en/Home.html). - Only use very strong passwords, and never reuse passwords within the LEMP stack - Only use sFTP encryption to transfer files to and from the webserver - Update file permissions so that no user can change or modify files - Ensure no system services or applications run as the root user > **Did you know?** > > You can set up a cron job to chownand chmodfiles every night as a scheduled task. This helps with preventing user error and correcting careless mistakes when updating web server files. ## Nginx Best-Practice Tips - Ensure Nginx is updated regularly - Obfuscate Nginx server information from the public > **Did you know?** > > You can mask server information on Nginx by adding this to the Nginx.conf file: > > server_tokens off; - Enforce HTTP Strict Transport Security (HSTS on TLS) to add a layer of encryption in communications > **Did you know?** > > Enforcing HTTP Strict Transport Security means using HTTPS. You can enforce it by adding this to your ssl.conf: > > add_header Strict-Transport-Security “max-age=63072000; includeSubdomains; preload”; - Disable deprecated SSL standards and weak cipher suites - Disable unwanted modules to reduce the attack surface - Enforce cross-site scripting (XSS) protection > **Did you know?** > > XSS protection can be implemented by updating your ssl.conf file > > add_header X-XSS-Protection “1; mode=block”; ## MySQL Best Practice The database is where many users will save protected health information. There are strict regulatory compliance rules regarding the masking and de-identification of data, as well as encryption. - Invoke MySQL Enterprise Data Masking and De-identification routines > **Did you know?** > > A server-side plugin called data_masking can manage a SQL-Level API to perform masking and de-identification tasks on your data when it is used by an application. - Data must be encrypted at rest > **Did you know?** > > Purekit for MariaDB is perfect for encrypting data at rest; it uses record layer encryption of the database, per-user encryption, and a zero-trust KMS. - Enable SELinux for mandatory access controls to protect the MySQL daemon - Implement MySQL plugins to authenticate users and restrict access by user, password, and approved IP address - Enable MySQL Enterprise Audit plugin to enable standard, policy-based monitoring and logging of connection and query activity executed on the 8MySQL servers ## PHP Best Practice PHP is a popular programming language used by websites to display enhanced content. PHP can either run as an Apache plugin or as a standalone CGI binary. No HIPAA legislation relates directly to PHP; instead, PHP must adhere to access and transmission security, and the browser connections must be secure. - Ensure PHP is kept up-to-date - Use PHP to hash and verify all passwords entered by users; BCrypt is included with PHP 7 onwards > **Did you know?** > > Passwords can be hashed using the *password_hash* PHP function. - Use PHP to enforce a user registration system and prevent access to unauthorized users - Use PHP to protect against Cross-site scripting (XSS) and Request Forgery XSFR > **Did you know?** > > You can protect against XSS and XSFR by sanitizing data input. The *htmlspecialchars()* and*htmlentities*functions prevent special characters that can hijack PHP code. Ready to get started with setting up a HIPAA-Compliant LEMP Stack? Choose Atlantic.Net for a one-click LEMP installation that will set you well on your way to a [HIPAA-Compliant LEMP Server](https://www.atlantic.net/hipaa-compliant-hosting/) – get started today! --- # Install and Configure DRBD on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/install-and-configure-drbd-on-centos-8/ | Published: 2020-09-23 | Updated: 2024-03-02 | Author: Hitesh Jethva DRBD, also known as “Distributed Replicated Block Device,” is a distributed storage solution for Linux. It is used to mirror the data on block devices such as hard disks, partitions, and logical volumes from one server to another over a network connection. If one server crashed, then the data on the other could be used. DRBD also ensures high availability (HA) for Linux applications by networked mirroring. In this tutorial, we will show you how to install DRBD and use it to replicate the partition between two servers. ## Prerequisites - Two fresh CentOS 8 [VPS](https://www.atlantic.net/vps-hosting/) on the Atlantic.Net Cloud Platform with one block storage device attached to each VPS. The server must be created in USA-EAST1 (Orlando) - A root password configured on both servers ## Step 1 – Setup Hostname on Each Node First, you will need to set up a hostname on each node. On the first node, run the following command to setup hostname. ``` hostnamectl set-hostname node1.example.com ``` On the second node, run the following command to setup hostname. ``` hostnamectl set-hostname node2.example.com ``` Once you are finished, you can proceed to the next step. ## Step 2 – Prepare Storage Device on Each Node Next, you will need to set the same size storage device on each node for your DRBD resource. In this tutorial, we will use /dev/sdb block storage on each node. On both nodes, create a GPT partition table and partition with the following command: ``` parted -s -a optimal -- /dev/sdb mklabel gpt parted -s -a optimal -- /dev/sdb mkpart primary 0% 100% parted -s -- /dev/sdb align-check optimal 1 ``` Next, verify the partition with the following command: ``` fdisk -l ``` You should get the /dev/sdb1 partition in the following output: ``` Disk /dev/sda: 80 GiB, 85899345920 bytes, 167772160 sectors Units: sectors of 1 * 512 = 512 bytes Sector size (logical/physical): 512 bytes / 512 bytes I/O size (minimum/optimal): 512 bytes / 512 bytes Disklabel type: dos Disk identifier: 0x7e9dbe13 Device     Boot Start       End   Sectors Size Id Type /dev/sda1        2048 167770112 167768065  80G 83 Linux Disk /dev/sdb: 50 GiB, 53687091200 bytes, 104857600 sectors Units: sectors of 1 * 512 = 512 bytes Sector size (logical/physical): 512 bytes / 512 bytes I/O size (minimum/optimal): 512 bytes / 512 bytes Disklabel type: gpt Disk identifier: 4CBB1682-09B1-4785-B96C-2B9D2B3BEB53 Device     Start       End   Sectors Size Type /dev/sdb1   2048 104855551 104853504  50G Linux filesystem ``` ## Step 3 – Install DRBD **Important**: Repeat this process on both nodes. By default, DRBD is not available in the CentOS standard repository, so you will need to install the EPEL repository in your system. You can install it with the following command: ``` dnf -y install https://www.elrepo.org/elrepo-release-8.el8.elrepo.noarch.rpm rpm --import https://www.elrepo.org/RPM-GPG-KEY-elrepo.org ``` Once the repository is installed, install the DRBD package with the following command: ``` dnf install drbd90-utils kmod-drbd90 -y ``` Once the installation is completed, you can proceed to the next step. ## Step 4 – Configure DRBD Resource **Important**: Repeat this process on both nodes. The default DRBD configuration file is located at /etc/drbd.conf, and other files are located inside /etc/drbd.d/ directory. To replicate storage device between two servers, you will need to create a new configuration file inside /etc/drbd.d/ directory: ``` nano /etc/drbd.d/resource0.res ``` Add the following lines: ``` resource resource0 {   on node1.example.com {     device    /dev/drbd1;     disk      /dev/sdb1;     address   node1-ip-address:7789;     meta-disk internal;   }   on node2.example.com {     device    /dev/drbd1;     disk      /dev/sdb1;     address  node2-ip-address:7789;     meta-disk internal;   } } ``` **Note**: The resource0.res is the same on both nodes. Where: - **node1.example.com** and **node2.example.com** are the hostnames of each node. - **/dev/drbd1** is the name of the DRBD device. - **/dev/sdb1** is the name of the storage device on each node. - **Node1-ip-address** is the IP address of the first node. - **Node2-ip-address** is the IP address of the second node. - **7789** is the DRBD port. Save and close the file when you are finished. ## Step 5 – Initialize and Enable DRDB Resource Next, you will need to initialize DRBD’s metadata on both nodes. Run the following command on both nodes to initialize the DRBD resource: ``` drbdadm create-md resource0 ``` You should get the following output: ``` md_offset 53684989952 al_offset 53684957184 bm_offset 53683318784 Found ext3 filesystem      2097152 kB data area apparently used     52425116 kB left usable by current configuration Even though it looks like this would place the new meta data into unused space, you still need to confirm, as this is only a guess. Do you want to proceed? [need to type 'yes' to confirm] yes initializing activity log initializing bitmap (1600 KB) to all zero Writing meta data... New drbd meta data block successfully created. success ``` After initializing the DRBD resource on both nodes, you will need to enable the resource. Run the following command on both nodes to enable the resource. ``` drbdadm up resource0 ``` This will attach the resource with its backing device; then, it sets replication parameters and connects the resource to its peer. On the first node, check the status of the DRBD with the following command: ``` drbdadm status resource0 ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/09/DRBD-Status-1.png) ## Step 6 – Set Primary Resource of Initial Device Synchronization At this point, DRBD is ready for operation. Next, you will need to tell it which node should be used as the source of the initial device synchronization. On the first node, start the initial full synchronization with the following command: ``` drbdadm primary --force resource0 ``` Now, check the status on the first node with the following command: ``` drbdadm status resource0 ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/09/DRBD-Status-2.png) You can also get device mapping for a name with the following command: ``` lsblk ``` You should see the new DRBD device **drbd1** in the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/09/DRBD-Device.jpg) ## Step 7 – Create a Filesystem on DRBD Device Next, you will need to create a filesystem on the DRBD device, mount it, and check whether we can use it for replicated data storage. On the first node, create an ext4 filesystem on the DRBD device with the following command: ``` mkfs.ext4 /dev/drbd1 ``` **Note**: This Process can take a while depending on the size of your block storage. You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/09/DRBD-Filesystem.png) Next, mount the DRBD device on /opt directory using the following command: ``` mount /dev/drbd1 /opt/ ``` Next, create some test files inside /opt directory. ``` cd /opt touch file1 file2 file3 file4 file5 file6 file7 file8 file9 ``` Next, verify the mounted device with the following command: ``` df -hT /opt ``` You should see the following output: ``` Filesystem     Type  Size  Used Avail Use% Mounted on /dev/drbd1     ext4   49G   53M   47G   1% /opt ``` ## Step 8 – Mount the DRBD Device on Second Node In this section, we will mount the DRBD device on the second node and check whether the replication is working or not. On the **first node**, unmount the DRBD device and make it a secondary node with the following command: ``` cd umount /opt drbdadm secondary resource0 ``` On the **second node**, make the second node primary with the following command: ``` drbdadm primary resource0 ``` Next, mount the DRBD device on the /opt directory with the following command: ``` mount /dev/drbd1 /opt ``` Now, run the following command to print the list of files in the /opt directory: ``` ls /opt ``` If everything is fine, all the files stored in the DRBD device should be there: ![](https://www.atlantic.net/wp-content/uploads/2020/09/DRBD-Files.png) You can also check the mounted partition of the DRBD device with the following command: ``` df -hT /opt ``` You should get the following output: ``` Filesystem     Type  Size  Used Avail Use% Mounted on /dev/drbd1     ext4   49G   53M   47G   1% /opt ``` ## Conclusion Congratulations! You have successfully installed and setup replication with DRBD on CentOS 8. DRBD is a great tool if you are looking to increase the availability of your data. For more information, you can visit the DRBD [documentation](https://www.linbit.com/drbd/). Try DRBD today on your [VPS Hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net! --- # Best Practices for Creating a HIPAA-Compliant WordPress Site > URL: https://www.atlantic.net/hipaa-compliant-wordpress-hosting/best-practice-for-creating-a-hipaa-compliant-wordpress-site/ | Published: 2020-09-25 | Updated: 2025-09-19 | Author: Richard Bailey WordPress is a widely used website creation application powering about [38% of all websites](https://w3techs.com/technologies/details/cm-wordpress) on the Internet today. WordPress achieved mainstream popularity because of its ease of use, allowing almost anyone to create detailed and professional-looking websites with a few clicks. WordPress is particularly popular with small-to-medium size businesses, web developers, graphic designers, and personal blogs. However, it is also [used by big companies](https://wpclipboard.com/famous-brands-companies-using-wordpress/), [such as](https://www.isitwp.com/popular-big-name-brands-using-wordpress/) BBC America, Sony Music, and Microsoft News. > **Did you know?** > > On the Atlantic.Net Cloud Platform (cloud.atlantic.net), you can auto-deploy a WordPress client-server in seconds. Our secure, defined one-click WordPress application uses Ubuntu 20.04 with PHP, MySQL, Apache, WordPress, and Postfix included as standard. WordPress sites that include Protected Health Information (PHI), as with any website handling PHI, must adhere to the administrative, physical, and technical safeguards of HIPAA to ensure the confidentiality of data uploaded or made available through the website. ## HIPAA-Compliant Design Rules for WordPress The following three-step HIPAA-compliant framework facilitates the development of a WordPress site that can handle PHI: - HIPAA compliance built into the ***website design*** process - ***Server hardening*** to meet the technical requirements of HIPAA - [HIPAA-compliant WordPress ***hosting***](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/) > **Did you know?** > > HIPAA rules are applicable regardless of whether the WordPress site is being used in-house or connected to the public Internet. ## Website Design HIPAA compliance must drive the website design plan; the design must meet HIPAA’s minimum security and privacy standards to ensure the confidentiality, integrity, and availability of PHI. - Access controls to prevent unauthorized access to PHI - Access controls to the WordPress administration control panel > **Need help? ** > > Check out the “[*Advanced Access Manager*](https://en-gb.wordpress.org/plugins/advanced-access-manager/)” plugin by Vasyl Martyniuk. - Audit controls to log all access to the site  - Audit controls to log any activity on the site that involves ePHI > **Need help? ** > > Check out the “[*WP Activity Log*](https://en-gb.wordpress.org/plugins/wp-security-audit-log/)” plugin by WP White Security. - Integrity controls to prevent PHI from being altered by unauthorized users - Transmission security controls to protect PHI uploads (encrypted in transit)  - Encrypt the webserver data ## Server Hardening Here are some practical ways to protect your WordPress server from common vulnerabilities and threats: - Update WordPress and PHP regularly - Update the operating system monthly - Only use very strong passwords and never reuse passwords - Only use sFTP encryption to transfer files to and from the webserver - Update file permissions so that no user can change or modify files - Ensure no system services or applications run as the root user > **Did you know?** > > Only the*.htaccess* file should have root permissions. - Restrict database user privileges and set IP restrictions to access the DB - Secure WP-Admin with multi-factor authentication (MFA) > **Need Help?** > > Here are two great MFA plugins: “[*Duo Two-Factor Authentication*](https://wordpress.org/plugins/duo-wordpress/)” and “*[Google Authenticator](https://wordpress.org/plugins/google-authenticator/)*.” ## HIPAA-Compliant WordPress Hosting A hosting company that is HIPAA compliant will provide you with an infrastructure that is built around the fundamental safeguards needed for compliance. Make sure you choose a hosting provider that can: - Implement physical security controls to prevent unauthorized physical access to the webserver - Offer a Fully Managed Firewall or Web Application Firewall (WAF) - Provide an encrypted VPN - Provide an encrypted Data Backup plan to protect PHI securely - Provide a Disaster Recovery solution to ensure that PHI is continuously available - Provide forensic level logging of all activity of the host server (this is in addition to WordPress layer logging) - Monitoring and alerting logging - Monitoring file changes using an Intrusion Prevention Service > **Did you know?** > > Atlantic.Net offers [HIPAA Compliant WordPress Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA Compliant Cloud Storage](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-cloud-storage/) services to support IT Solutions for Healthcare.  Ready to get started with setting up a HIPAA-Compliant WordPress Site? Choose Atlantic.Net for a one-click WordPress installation that will set you well on your way to a [HIPAA-Compliant WordPress Website](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/) – get started today! --- #### Read More About HIPAA Compliant Hosting - [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) - How to Make a [HIPAA-Compliant Website](https://www.atlantic.net/hipaa-compliant-hosting/how-to-make-website-hipaa-compliant/) - [HIPAA Compliant Server](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-server-for-a-client-portal-solution/) Case Study - [HIPAA Compliant Data Center](https://www.atlantic.net/hipaa-data-centers/) - [Is WordPress HIPAA Compliant?](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/a-sample-hipaa-wordpress-setup/) - [HIPAA Compliant WordPress Hosting](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/) --- # How to Backup and Restore a WordPress Website > URL: https://www.atlantic.net/vps-hosting/how-to-backup-and-restore-a-wordpress-website/ | Published: 2020-10-07 | Updated: 2026-03-02 | Author: Hitesh Jethva Backing up your website regularly is a very important task for any webmaster. You should always have a recent backup of your website to prevent data loss in case something goes wrong, but backing up and restoring the WordPress website manually can be difficult for a beginner user. There are several ways to back up and restore a WordPress website. However, a simple and easy way is to use the UpdraftPlus backup plugin to backup and restore a WordPress website. UpdraftPlus can automate the backup and copy it to a cloud-based drive, such as Google Drive, Dropbox, and more. In this tutorial, we will show you how to back up and restore a WordPress website with the UpdraftPlus WordPress plugin. ## Prerequisites - A Linux [VPS](https://www.atlantic.net/vps-hosting/) with WordPress installed on the Atlantic.Net Cloud Platform ## Step 1 – Install UpdraftPlus Plugin UpdraftPlus is the world’s highest-ranking and most popular scheduled backup plugin; it allows you to back up your files and database backups into the local or cloud storage and restore with a single click!. This free plugin supports various remote cloud storage options including Dropbox, Google Drive, Amazon S3, UpdraftVault, Rackspace Cloud, FTP, DreamObjects, and Openstack Swift. Follow the below steps to install the UpdraftPlus plugin: **1 –**Go to the WordPress admin dashboard => **Plugins** => **Add New** and type **UpdraftPlus** in search bar. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/UpdraftPlus-Plugin.png) **2 –**Select the **UpdraftPlus** WordPress Backup Plugin and click on the **Install** Now button to install the plugin. Once the plugin has been installed, you should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/UpdraftPlus-Plugin-Install.png) **3 –**Click on the **Activate** button to activate the plugin. ## Step 2 – Create a WordPress Backup with UpdraftPlus At this point, the UpdraftPlus backup and restore plugin is installed. Next, you will need to configure UpdraftPlus plugin settings. On the WordPress admin dashboard, click on the UpdraftPlus Backups in the left pane. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/UpdraftPlus-Dashboard.png) Next, click on the **Settings**tab. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/UpdraftPlus-Settings.png) ![](https://www.atlantic.net/wp-content/uploads/2020/10/UpdraftPlus-Settings-2.png) ![](https://www.atlantic.net/wp-content/uploads/2020/10/UpdraftPlus-Settings-3.png) Here, select your database and file backup schedule, choose your remote storage, select include and exclude a directory, check the email checkbox and click on the **Save Changes** button to save the configuration. You should see the Dropbox storage authentication screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/UpdraftPlus-Dropbox.png) Click on the **link**. You will be redirected to the Dropbox authentication screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/UpdraftPlus-Dropbox-Authenticate.png) Provide your Dropbox username, password, and click on the **Sign-in** button. You should see the UpdraftPlus website where you need to click on the ‘Complete Setup’ button to finish the setup. ![](https://www.atlantic.net/wp-content/uploads/2020/10/UpdraftPlus-Complete-Setup.png) Click on the **Complete Setup** button to finish the setup. Now, click on the **Backup / Restore** tab to create a backup of your WordPress website. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/UpdraftPlus-Backup-Restore.png) Click on the **Backup Now** button to start the backup process. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/UpdraftPlus-Backup-Now.png) Check the required box and click on the **Backup Now** button. Once the backup is generated, you should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/UpdraftPlus-Existing-Backups.png) From here, you can also download your generated backup to your local system. ## Step 3 – Restore a WordPress Backup with UpdraftPlus Now that you have up your website, being able to restore it with UpdraftPlus is just as important. UpdraftPlus provides an easy way to restore your website from a backup. If your website or system has crashed, then you may need to install WordPress and the UpdraftPlus plugin again before proceeding. You can perform the restoration process using the following steps: **1 –**Go to the **WordPress** admin dashboard and click on the **UpdraftPlus** **Backups**in the left pane. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/UpdraftPlus-Restore-1.png) You should see your generated backup file in the above screen. If you don’t find it, you can also upload it from your local system or Dropbox. **2 –**Click on the **Restore** button to start the restoration process. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/UpdraftPlus-Restore-2.png) **3 –**Select the components that you want to restore from the backup and click on the **Next** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/UpdraftPlus-Restore-3.png) **4 –**Click on the **Restore** button to start the process. Once the restoration process has completed successfully, you should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/UpdraftPlus-Restore-4.png) ## Conclusion In the above guide, you learned how to backup and restore a WordPress website easily with the UpdraftPlus backup plugin. You can now schedule the backup process to save yourself time – test it out on your WordPress installation on your [VPS Hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net today! --- # How To Set Up Apache with MPM Event and PHP-FPM on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-set-up-apache-with-mpm-event-and-php-fpm-on-ubuntu/ | Published: 2020-10-08 | Updated: 2024-09-25 | Author: Hitesh Jethva Apache is free, open-source, and the most widely used web server, largely because it is capable of working in different environments. Apache has the ability to manage different processes to serve an HTTP protocol request including processing the request, opening a socket, and handling new events. These tasks are performed by the Apache Multi-Processing Module (MPM). ## What Is Apache MPM? Apache MPM (Multi-Processing Modules) are Apache modules used for creating child processes in Apache. They allow more requests to be served simultaneously by passing off some processing work to listener threads, freeing up worker threads to serve new requests. Using PHP-FPM with MPM Event in an Apache webserver decreases the website page loading time and allows the webserver to handle more concurrent connections. In this tutorial, we will learn how to configure Apache with MPM Event and PHP-FPM on Ubuntu 20.04. ## Step 1 – Install LAMP Server First, install the Apache web server, and MariaDB with the following command: ``` apt-get install apache2 mariadb-server -y ``` Next, add the PHP repository using the following command. ``` apt install software-properties-common add-apt-repository ppa:ondrej/php -y ``` Next, install PHP with other required dependencies using the following command. ``` apt install php7.4 libapache2-mod-php7.4 php7.4-mysql php7.4-gd php7.4-curl php7.4-xml ``` Once the LAMP server is installed, you can proceed to the next step. ## Step 2 – Change the Multi-Processing Module Before starting, you will need to switch the MPM from pre-fork to event and remove the php7.4 module connection between PHP and Apache. First, stop the Apache service and disable the php7.4 module with the following command: ``` systemctl stop apache2 a2dismod php7.4 ``` Next, disable the Pre-fork MPM module with the following command: ``` a2dismod mpm_prefork ``` Next, enable the Event MPM module with the following command: ``` a2enmod mpm_event ``` Once you are finished, you can proceed to the next step. ## Step 3 – Configure Apache to Use the FastCGI Process Manager In this section, we will install the PHP-FPM processor and proxy modules so Apache can communicate with PHP. First, install the PHP-FPM with the following command: ``` apt-get install php7.4-fpm -y ``` Once installed, you will need to install libapache2-mod-fcgid library in order to communicate Apache and PHP. You can install it with the following command: ``` apt-get install libapache2-mod-fcgid -y ``` Once installed, you will need to enable the PHP-FPM, Proxy and FastCGI Proxy module in Apache webserver. You can enable them with the following command: ``` a2enconf php7.4-fpm a2enmod proxy a2enmod proxy_fcgi ``` Next, restart the Apache service to apply the changes: ``` systemctl restart apache2 ``` Now, verify the MPM module with the following command: ``` apachectl -M | grep 'mpm' ``` You should get the following output: ``` mpm_event_module (shared) ``` ![](https://www.atlantic.net/wp-content/uploads/2020/10/Apache-MPM-Event.png) Next, verify the Proxy and FastCGI Proxy module with the following command: ``` apachectl -M | grep 'proxy' ``` You should get the following output: ```  proxy_module (shared)  proxy_fcgi_module (shared) ``` ![](https://www.atlantic.net/wp-content/uploads/2020/10/Apache-MPM-FCGI.jpg) ## Step 4 – Verify FastCGI Process Manager At this point, Apache web server is configured to use the FastCGI Process Manager. It’s time to verify if PHP is using the FastCGI Process Manager. First, create an info.php file inside the Apache document root directory: ``` nano /var/www/html/info.php ``` Add the following lines: ``` ``` Save and close the file when you are finished. Next, open your web browser and type the URL http://your-server-ip/info.php. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/Apache-MPM-PHP.png) In the above page, you should see that Apache web server is using FPM/FastCGI. ## Conclusion In the above guide, we learned how to configure Apache with MPM Event and PHP-FPM on Ubuntu 20.04. Now, PHP-FPM will handle the PHP code and improve overall resource utilization. Give it a shot on your [VPS Hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net! --- # How to Adopt a DevOps Development Model When You Don’t Know Where to Start > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-adopt-a-devops-development-model-when-you-dont-know-where-to-start/ | Published: 2020-10-09 | Updated: 2025-09-19 | Author: Brandon Schroth The ongoing pandemic has forced business owners to make significant shifts in their operating strategies, including swapping centralized databases with distributed databases and adopting remote work culture.  They have also figured out that the best way to stay ahead of their competition is by implementing DevOps practices that can significantly accelerate product launches and upgrades. But a problem sometimes arises when they are unsure about where to start with new DevOps processes. Leaping into DevOps can be intimidating due to the absence of any relevant cookie-cutter approach. You have to customize a model based on your organization’s needs to make your team more agile and competitive while [simultaneously improving business security](https://www.atlantic.net/hipaa-compliant-hosting/how-to-protect-business-data-when-employees-are-working-from-home/), cutting costs, and boosting revenue. If you are considering adopting a DevOps model, keep reading. We will discuss different approaches to help make the transformation successful. ## What Do You Mean by DevOps? Before discussing strategies, it‘s crucial to understand what the term “DevOps“ means. The concept of DevOps [refers to a change in IT culture](https://medium.com/@copyconstruct/what-is-devops-5b0181fdb953) that focuses on rapid IT service delivery through the adoption of agile practices. These practices are aimed at creating a system-oriented approach to IT services and development. The priority here is to improve the collaboration between software development (Dev) and IT operations (Ops). In essence, DevOps focuses on automating manual processes such as making payments, measuring performances, processing data, and so on. The idea here is to combine the efforts and functions of both the teams and make them share responsibilities. This can be done through automating infrastructure, automating code testing and workflows, and continuously measuring performance. You can think of implementing a DevOps model into your business as a means of digitally transforming your IT and development teams for the better. This is something you would be wise to do quickly if you are not already doing so, since [74% of all organizations](https://brainstation.io/research/digital-skills-survey-2020-results) are actively involved in digitally transforming their business processes.  In some models, quality assurance and security teams also merge with the developers and operations teams to make up for the lack of security practices around it. In such cases, the name gets modified to DevSecOps. ## The Best Practice is to Adopt a DevOps Model The following are a few approaches that can be critical for [ensuring a successful DevOps adoption](https://www.cigniti.com/blog/10-best-practices-for-successful-devops-implementation/) within an organization: #### Embracing the Integration Mindset Combining development and operations efforts can be a rather complicated task in the absence of open communication and transparency. The only way to overcome disunity is to share common goals among teams. Any DevOps strategy has two main components: continuous integration and continuous delivery. Before implementing a new DevOps strategy, you have to identify areas where the current delivery process is inefficient, along with an open mindset to experiment.  Try to understand that short-term failure is acceptable as long as your organization [Comparing Three Approaches to Multi-Cloud Security Management Sees](https://devops.com/comparing-three-approaches-to-multi-cloud-security-management/) it as an opportunity to learn and improve. At the same time, implementing DevOps [shouldn’t put confidential data at risk](https://devops.com/comparing-three-approaches-to-multi-cloud-security-management/), so make sure to take necessary measures to protect data integrity and ensure uniformity. #### Launching Pilot Projects that Use a DevOps Methodology Step-by-step implementation can be an excellent way to get on the DevOps bandwagon. You can start with a pilot project based on DevOps methodology. Doing this will help you understand vital elements, check the response and readiness of teams, and evaluate the overall effectiveness of the DevOps program. But make sure that it doesn’t affect the quality of other projects or jeopardize your business operations. #### Setting Up Metrics for Giving Feedback Selecting the right metrics to record and track progress [is the most overlooked aspect](https://techbeacon.com/devops/6-proven-metrics-devops-success) of DevOps adoption.  Consider this: how could you possibly give feedback at every stage if you cannot identify your weaknesses and the areas that need more improvement? Here are some of the most useful DevOps metrics for you to consider: - **Deployment speed:** how long does it take you to deploy an upgraded version of an application to a particular environment? - **Production failure rate:** how often does the software fail in the production stage during a fixed period of time? - **Average lead time:** how long does it take for a new requirement to be built, tested, delivered, and deployed? - **Mean time to production:** how long does it take for a new code to be committed into a code repository for it to be deployed into production? - **Deployment frequency:** how often do you deploy new release candidates to test, staging, pre-production, and production environments? You need a balanced approach in the implementation of DevOps, so giving feedback on every work process, from design and testing to release, is necessary. You can consider designing a quick feedback process to [boost the effectiveness of workflow automation](https://www.cloudwards.net/17-pro-tips-for-workflow-automation/) for this purpose as well. #### Focus Automation Efforts on the Part of the IT Process that Needs It Most Now that you have a pilot project and a feedback system in place, you should start by automating one process. We would recommend automating the most key processes in order to best evaluate the results. Also, be prepared for errors and setbacks that may occur in the process. Another way to approach this would be to start implementing DevOps with a process that runs parallel to the key. The benefit of this approach is you get an opportunity to learn and understand advances in the framework of the real process without disturbing the entire project. #### Lay Emphasis on Standardization While it‘s true that [automation has several business advantages](https://blog.clicky.com/4-ways-to-automate-business-operations/), you won’t be able to mitigate communication gaps, performance bottlenecks, and silos between teams if you don’t have standardized workflows, technologies, protocols, processes, and metrics in place. Hence, DevOps standardization is crucial in automation for ensuring developers, operations, QA, and everyone associated with these teams have a common frame of reference, along with a common language. #### Revising Your Agile and DevOps Culture Adopting DevOps [is a huge cultural shift](https://www.mckinsey.com/business-functions/mckinsey-digital/our-insights/digital-blog/five-cultural-changes-you-need-for-devops-to-work#) since it consists of intermingling workgroups and overcoming the traditional disunity of teams. It makes sense to make certain adjustments to boost the overall efficiency of an organization. DevOps isn’t only limited to using new tools and re-drawing processes. It’s equally important to change the corporate culture itself, which is heavily dependent on uninterrupted and secure data access and transparent communication between employees. ## Understanding the Benefits of DevOps Culture Now that we have spoken about the ways of [implementing a successful DevOps strategy](https://www.cio.com/article/3234105/6-steps-to-devops-success.html), you should also know the advantages that you can expect from this.  DevOps helps you foster transparency through the processes, especially for version control. You will be able to ensure continuous software delivery and improve the speed of resolution and turnaround time. Not only will this help you deliver value to customers, but you will also enjoy a better position in the market. A successful DevOps strategy can even pave the way for adopting DevSecOps in the future, a strategy that will protect sensitive data and maximize privacy on the web. By adopting DevSecOps into your business, security will ideally be implemented at the same speed and scale as the development of business operations.  The best DevSecOps strategy will be to automate as many things as possible to keep up with your operations. This can be best accomplished if you [use open source security tools](https://privacyaustralia.net/privacy-tools/) to mitigate common security threats such as SQL injections and cross-site scripting.  Concerning automation, DevOps can help stabilize operating environments and also give more time to teams for innovation through automated processes. Any manual implementation of tasks will, in turn, be limited. Another huge advantage is the introduction of a more production-oriented concept that will reduce time wastage. This will ultimately cut down software costs. Interestingly,63% of organizations have reported seeing improvements in software deployment quality, and frequency. This is made possible because teams can engage more through collaboration that helps them handle management challenges. To put things to a perspective, DevOps can be a challenge, yes. But it can also be very beneficial for the overall growth of an organization. ## Conclusion In addition to the efficiency benefits your organization could enjoy from implementing DevOps, successful implementation may even improve your organization‘s chances to [mitigate the adverse impact of coronavirus](https://www.atlantic.net/vps-hosting/how-can-remote-working-and-business-continuity-planning-mitigate-the-impact-of-the-covid-19-coronavirus/) by following standardized processes and protocols, sharing common interests, and having team unity. Learn how Atlantic.Net’s [Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/) could help you implement DevOps! If your organization is just beginning to embrace a DevOps culture, keep yourself and your team’s mindsets prepared for the challenges. After all, DevOps cannot be bought or declared, and it can only be attained through hard work and discipline. --- # How to Benchmark Web Server Performance with Apache Bench > URL: https://www.atlantic.net/vps-hosting/how-to-benchmark-web-server-performance-with-apache-bench/ | Published: 2020-10-12 | Updated: 2024-09-25 | Author: Hitesh Jethva If you are a webmaster, you may often be concerned with the performance of your web applications. You might ask questions like, “how do I perform load testing of my application?” or “will my application be able to handle a lot of users?” In these cases, Apache Bench can be a great help. Apache Bench is a free and open-source tool to measure the performance of a web server with a simple, easy-to-use command-line interface; it can help you understand how your current Apache installation performs. In this tutorial, we will show you how to install and use Apache Bench on Linux. ## Step 1 – Install Apache Bench Apache Bench is a part of the Apache webserver package, so you don’t need to install the Apache Bench if the Apache Web Server is installed on your system. For Ubuntu/Debian operating system, install the Apache Bench tool with the following command: ``` apt-get install apache2-utils -y ``` For RHEL/CentOS operating system, install the Apache Bench tool with the following command: ``` yum install httpd-tools -y ``` You can display all options available with Apache Bench tool using the following command: ``` ab ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/Apache-Bench-Options.png) A brief explanation of the most commonly used options is shown below: - **-n:** Specify the number of connection requests sent to the webserver. - **-c:** Specify the number of concurrent connection requests sent to the webserver. - **-t:** Specify the number of seconds the ab command should continue sending requests. **Note:** Sometimes you may get a “connection timed out” error. The reason for this is your connection request blocked by a firewall or the Apache webserver wasn’t able to handle further requests. ## Step 2 – Running a Stress Test At this point, the Apache Bench tool is installed. Now,you can perform a stress test against your webserver locally or using the domain name. Let’s perform a stress test against your Apache web server by sending 800 requests over 300 concurrent connections. ``` ab -n 800 -c 300 http://your-domain-name/ ``` This will perform for 800 requests with a concurrency of 300 as shown below: ``` This is ApacheBench, Version 2.3 <$Revision: 1807734 $> Copyright 1996 Adam Twiss, Zeus Technology Ltd, http://www.zeustech.net/ Licensed to The Apache Software Foundation, http://www.apache.org/ Benchmarking localhost (be patient) Completed 100 requests Completed 200 requests Completed 300 requests Completed 400 requests Completed 500 requests Completed 600 requests Completed 700 requests Completed 800 requests Finished 800 requests Server Software:        Apache/2.4.29 Server Hostname:        localhost Server Port:            80 Document Path:          / Document Length:        10918 bytes Concurrency Level:      300 Time taken for tests:   0.459 seconds Complete requests:      800 Failed requests:        0 Total transferred:      8953600 bytes HTML transferred:       8734400 bytes Requests per second:    1743.53 [#/sec] (mean) Time per request:       172.064 [ms] (mean) Time per request:       0.574 [ms] (mean, across all concurrent requests) Transfer rate:          19056.29 [Kbytes/sec] received Connection Times (ms)               min  mean[+/-sd] median   max Connect:        0    6   7.8      0      20 Processing:     8   92 124.3     44     437 Waiting:        4   92 124.4     43     437 Total:         22   98 128.9     44     453 Percentage of the requests served within a certain time (ms)   50%     44   66%     50   75%     53   80%     56   90%    435   95%    445   98%    450   99%    452  100%    453 (longest request) ``` In the above output, you can see Apache has handled 1743.53 requests per second, and it took a total 0.459 seconds to serve the total requests. Let’s perform another stress test against your Nginx web server and compare it with Apache result by sending 800 requests over 300 concurrent connections. ``` ab -n 800 -c 300 http://your-domain-name/ ``` You should see the following output: ``` This is ApacheBench, Version 2.3 <$Revision: 1807734 $> Copyright 1996 Adam Twiss, Zeus Technology Ltd, http://www.zeustech.net/ Licensed to The Apache Software Foundation, http://www.apache.org/ Benchmarking localhost (be patient) Completed 100 requests Completed 200 requests Completed 300 requests Completed 400 requests Completed 500 requests Completed 600 requests Completed 700 requests Completed 800 requests Finished 800 requests Server Software:        nginx/1.14.0 Server Hostname:        localhost Server Port:            80 Document Path:          / Document Length:        10918 bytes Concurrency Level:      300 Time taken for tests:   0.184 seconds Complete requests:      800 Failed requests:        0 Total transferred:      8930400 bytes HTML transferred:       8734400 bytes Requests per second:    4354.95 [#/sec] (mean) Time per request:       68.887 [ms] (mean) Time per request:       0.230 [ms] (mean, across all concurrent requests) Transfer rate:          47474.91 [Kbytes/sec] received Connection Times (ms)               min  mean[+/-sd] median   max Connect:        1   12   7.5      9      32 Processing:     5   33  12.8     30      56 Waiting:        4   26  12.9     22      49 Total:         15   46  13.6     46      70 Percentage of the requests served within a certain time (ms)   50%     46   66%     56   75%     58   80%     60   90%     64   95%     66   98%     70   99%     70  100%     70 (longest request) ``` In the above output, you can see Apache has handled 4354.95 requests per second, and it took a total 0.184 seconds to serve the total requests. You can see that Nginx can handle more requests than Apache. After comparing the result of both servers, you will get an idea of which one to choose for your web application. ## Conclusion In the above guide, we learned how to test web server performance with Apache Bench. You can now explore the Apache Bench tool and run it with different options to measure the performance of your webserver; try it today on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How To Install and Configure Elasticsearch on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-configure-elasticsearch-on-ubuntu-20-04/ | Published: 2020-10-17 | Updated: 2023-11-22 | Author: Hitesh Jethva Elasticsearch is a free and open-source NoSQL database used to store, search, and analyze big volumes of data in real-time. It is written in the Java language so it can run on different platforms. Elasticsearch is built on Lucene indexing technology and supports database queries through REST APIs. You can also integrate Elasticsearch with other tools, such as Kibana, Logstash, X-Pack, and other. Generally, it is used in applications that have complex search features and requirements. In this tutorial, we will learn how to install Elasticsearch on Ubuntu 20.04. ## Step 1 – Install Java Elasticsearch is written in the Java language, so Java must be installed in your system. If not installed, you can install it with the following command: ``` apt-get install default-jdk -y ``` Once the Java is installed, verify the installed version of Java using the following command: ``` java -version ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/elastic1.png) ## Step 2 – Install Elasticsearch By default, the Elasticsearch package is not available in the Ubuntu default repository, so you will need to add the repository in your system. First, you need to install an APT transport package to allow access to your repositories via HTTPS: ``` apt-get install apt-transport-https gnupg2 -y ``` Next, download and add the GPG key for the Elasticsearch repository with the following command: ``` wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | apt-key add - ``` Next, run the following command to add the repository to your system: ``` echo "deb https://artifacts.elastic.co/packages/7.x/apt stable main" | tee -a /etc/apt/sources.list.d/elastic-7.x.list ``` Next, update the repository and install the Elasticsearch with the following command: ``` apt-get update -y apt-get install elasticsearch -y ``` Once installed, start the Elasticsearch service and enable it to start at boot with the following command: ``` systemctl start elasticsearch systemctl enable elasticsearch ``` You can also verify the status of Elasticsearch service with the following command: ``` systemctl status elasticsearch ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/elastic2.png) ## Step 3 – Configure Elasticsearch for Remote Access The default Elasticsearch configuration is located at /etc/elasticsearch/elasticsearch.yml and it comes preconfigured for basic usage, so you don’t need to configure it if you use only one node in your setup. In some cases, you need to configure Elasticsearch to be accessed by other hosts. You can allow remote access by editing elasticsearch.yml file: ``` nano /etc/elasticsearch/elasticsearch.yml ``` Add the following lines below “Network” section: ``` transport.host: localhost transport.tcp.port: 9300 http.port: 9200 network.host: 0.0.0.0 ``` Save and close the file, then restart Elasticsearch service to apply the changes: ``` systemctl restart elasticsearch ``` ## Step 4 – Verify Elasticsearch At this point, Elasticsearch is installed, configured, and listening on port 9200. Now it’s time to test whether it is working or not. To test it, go to the remote system and run the following command: ``` curl http://your-server-ip:9200 ``` You should see the version, date, and hash information in the following output: ``` { "name" : "ubuntu2004", "cluster_name" : "elasticsearch", "cluster_uuid" : "CqfMwJSsRH-ucofVQxI9cA", "version" : { "number" : "7.7.1", "build_flavor" : "default", "build_type" : "deb", "build_hash" : "ad56dce891c901a492bb1ee393f12dfff473a423", "build_date" : "2020-05-28T16:30:01.040088Z", "build_snapshot" : false, "lucene_version" : "8.5.1", "minimum_wire_compatibility_version" : "6.8.0", "minimum_index_compatibility_version" : "6.0.0-beta1" }, "tagline" : "You Know, for Search" } ``` ## Conclusion Congratulations! You have successfully installed Elasticsearch in Ubuntu 20.04. You can now explore Elasticsearch for more functionality. For more information, visit the Elasticsearch [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/7.6/index.html). Install Elasticsearch on your [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # How to Install and Use WP-CLI to Manage WordPress > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-wp-cli-to-manage-wordpress/ | Published: 2020-10-18 | Updated: 2023-11-22 | Author: Hitesh Jethva WP-CLI is the official command-line tool used for managing WordPress. WP-CLI allows you to install and update themes, plugins and configure multisite installations without using a web browser. It can boost productivity and speed up the development process, since performing certain tasks using the command-line is much easier than using a graphical interface. WP-CLI allows you to perform commands that are not supported through the standard WordPress back-end. One of the most important benefits of WP-CLI is its efficiency; for a multi-site environment, you don’t need to log in to each account to take care of basic tasks. In this tutorial, we will show you how to install and use WP-CLI to manage WordPress. ## Install WP-CLI By default, WP-CLI is not available in the Ubuntu default repository, so you will need to download it from their website. You can download it with the following command: ``` wget https://raw.githubusercontent.com/wp-cli/builds/gh-pages/phar/wp-cli.phar ``` Once the download is completed, move the downloaded file to the /usr/bin directory: ``` mv wp-cli.phar /usr/bin/wpcli ``` Next, provide execution permission with the following command: ``` chmod +x /usr/bin/wpcli ``` Next, verify the WP-CLI installation using the following command: ``` wpcli --info ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/wpcli1.png) ## Manage Plugins with WP-CLI WP-CLI allows you to search, install, and activate the WordPress plugins as per your need. To list the installed WordPress plugins, run the wp-cli command as a www-data user inside the WordPress document root directory: ``` cd /var/www/html/ sudo -u www-data wpcli plugin list ``` You should get something similar to the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/wpcli2.png) If you want to install caching plugin, first search for the plugin with the following command: ``` sudo -u www-data wpcli plugin search w3-total-cache ``` You should see the following list: ![](https://www.atlantic.net/wp-content/uploads/2020/10/wpcli3.png) Now, install the w3-total-cache plugin from the above list using the following command: ``` sudo -u www-data wpcli plugin install w3-total-cache ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/wpcli4.png) Next, activate the installed plugin with the following command: ``` sudo -u www-data wpcli plugin activate w3-total-cache ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/wpcli5.png) Now, verify the installed plugins with the following command: ``` sudo -u www-data wpcli plugin list ``` You should get the following list: ![](https://www.atlantic.net/wp-content/uploads/2020/10/wpcli6.png) ## Manage Themes with WP-CLI You can also search for, install, and activate a WordPress theme using the WP-CLI. First, list the installed WordPress themes in your system using the following command: ``` sudo -u www-data wpcli theme list ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/wpcli7.png) Next, search your for desired theme with the following command: ``` sudo -u www-data wpcli theme search astra ``` You should get the following list: ![](https://www.atlantic.net/wp-content/uploads/2020/10/wpcli8.png) Now, install the theme from the above list using the following command: ``` sudo -u www-data wpcli theme install astra ``` Once installed, you should get the following output: ``` Installing Astra (2.4.5) Downloading installation package from https://downloads.wordpress.org/theme/astra.2.4.5.zip... Unpacking the package... Installing the theme... Theme installed successfully. Success: Installed 1 of 1 themes. ``` Now, activate the installed theme using the following command: ``` sudo -u www-data wpcli theme activate astra ``` You should see the following output: ``` Success: Switched to 'Astra' theme. ``` ## Manage Post With WP-CLI You can also create, edit and manage WordPress posts with WP-CLI. List all posts in your system using the following command: ``` sudo -u www-data wpcli post list ``` You should see the following list: ``` +----+--------------+-------------+---------------------+-------------+ | ID | post_title | post_name | post_date | post_status | +----+--------------+-------------+---------------------+-------------+ | 1 | Hello world! | hello-world | 2020-06-21 05:01:58 | publish | +----+--------------+-------------+---------------------+-------------+ ``` Next, create and publish a new post with title “Install Django Ubuntu 20.04” using the following command: ``` sudo -u www-data wpcli post create --post_status=publish --post_title="Install Django Ubuntu 20.04" --edit ``` This will open the vim editor. Add the following contents: ``` In this tutorial, we will learn how to install Django on an Ubuntu 20.04 server. ``` Save and close the vim editor when you are finished. You can now verify your newly created post using the following command: ``` sudo -u www-data wpcli post list ``` You should get the following output: ``` +----+-----------------------------+-----------------------------+---------------------+-------------+ | ID | post_title | post_name | post_date | post_status | +----+-----------------------------+-----------------------------+---------------------+-------------+ | 5 | Install Django Ubuntu 20.04 | install-django-ubuntu-20-04 | 2020-06-21 05:31:36 | publish | | 1 | Hello world! | hello-world | 2020-06-21 05:01:58 | publish | +----+-----------------------------+-----------------------------+---------------------+-------------+ ``` ## Manage Database with WP-CLI You can also manage the WordPress database with WP-CLI. You can connect to the WordPress database using the following command: ``` sudo -u www-data wpcli db cli ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/wpcli9.png) Now, exit from the database with the following command: ``` MariaDB [wordpress]> EXIT ``` You can also query about your users using the following command: ``` sudo -u www-data wpcli db query "SELECT user_login,ID FROM wp_users;" ``` You should get the following output: ``` +------------+----+ | user_login | ID | +------------+----+ | admin | 1 | +------------+----+ ``` ## Update WordPress with WP-CLI If you want to update your WordPress installation, run the following command: ``` sudo -u www-data wpcli core update ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/wpcli10.png) To update your WordPress database, run the following command: ``` sudo -u www-data wpcli core update-db ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/wpcli11.png) To update all plugins, run the following command: ``` sudo -u www-data wpcli plugin update --all ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/wpcli12.png) ## Conclusion In this guide, you learned how to manage WordPress with WP-CLI. WP-CLI is a very useful tool that makes WordPress administration much easier. See if it helps you to perform your day-to-day WordPress administration tasks on your [VPS Hosted](https://www.atlantic.net/vps-hosting/) WordPress installation from Atlantic.Net. --- # How to Install and Configure Akaunting Software on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-configure-akaunting-software-on-ubuntu-20-04/ | Published: 2020-10-20 | Updated: 2023-11-22 | Author: Hitesh Jethva Akaunting is free and open-source online accounting software that can be used to manage your invoices, quotes, and finances. It is built with modern technology frameworks, such as Laravel, VueJS, Bootstrap 4, and RESTful API, and was designed for small businesses and freelancers. Akaunting allows you to manage and track all your payments, invoices, expenses, and more from a central location. In this tutorial, we will show you how to install Akaunting Software on Ubuntu 20.04. ## Step 1 – Install Apache, MariaDB, and PHP Akaunting requires an Apache webserver, MariaDB database, and PHP to be installed on your server. You can install all of them by running the following command: ``` apt-get install apache2 mariadb-server php7.4 libapache2-mod-php7.4 php7.4-common php7.4- imap php7.4-mbstring php7.4-xmlrpc php7.4-soap php7.4-gd php7.4-xml php7.4-intl php7.4-mysql php7.4-cli php7.4-bcmath php7.4-ldap php7.4-zip php7.4-curl unzip curl -y ``` Once all the packages are installed, edit the php.ini file and change some desired settings. ``` nano /etc/php/7.4/apache2/php.ini ``` Change the following lines: ``` memory_limit = 256M upload_max_filesize = 20M post_max_size = 20M max_execution_time = 300 date.timezone = America/Chicago ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` ## Step 2 – Configure Database for Akaunting Next, you will need to create a database for Akaunting. First, log in to the MariaDB shell with the following command: ``` mysql ``` Once logged in, create a database and user for Akaunting with the following command: ``` CREATE DATABASE akaunting; CREATE USER 'akaunting'@'localhost' IDENTIFIED BY 'your-password'; ``` Next, grant all privileges to the Akaunting database with the following command: ``` GRANT ALL ON akaunting.* TO 'akaunting'@'localhost' IDENTIFIED BY 'your-password' WITH GRANT OPTION; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download Akaunting First, you will need to download the latest version of Akaunting from its official website. You can download it using the curl command as shown below: ``` curl -O -J -L https://akaunting.com/download.php?version=latest ``` Once the download is completed, create a directory for Akaunting inside the Apache web root directory: ``` mkdir -p /var/www/html/akaunting ``` Next, extract the downloaded file to the akaunting directory with the following command: ``` unzip Akaunting_*.zip -d /var/www/html/akaunting/ ``` Next, change the ownership of the akaunting directory and set proper permission with the following command: ``` chown -R www-data:www-data /var/www/html/akaunting/ chmod -R 755 /var/www/html/akaunting/ ``` ## Step 4 – Configure Apache for Akaunting Next, you will need to create an Apache virtual host configuration file for Akaunting. You can create it with the following command: ``` nano /etc/apache2/sites-available/akaunting.conf ``` Add the following lines: ``` ServerAdmin admin@example.com DocumentRoot /var/www/html/akaunting ServerName example.com DirectoryIndex index.html index.php Options +FollowSymlinks AllowOverride All Require all granted ErrorLog ${APACHE_LOG_DIR}/akaunting_error.log CustomLog ${APACHE_LOG_DIR}/akaunting_access.log combined ``` Save and close the file, then enable the Apache virtual host file and rewrite module with the following command: ``` a2ensite akaunting a2enmod rewrite ``` Next, restart the Apache service to apply the changes: ``` systemctl restart apache2 ``` ## Step 5 – Access Akaunting Web Interface Now, open your web browser and access the Akaunting web installation wizard using the URL **http://example.com**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/akaunting1.png) Select your desired language and click on the **Next** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/akaunting2.png) Provide your database details and click on the **Next** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/akaunting3.png) Provide your company name, email address, admin email address, and click on the **Next** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/akaunting4.png) Provide your admin email and password and click on the **Login** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/akaunting5.png) Click on the **Skip** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/akaunting6.png) Click on the **Next** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/akaunting7.png) Click on the **Next** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/akaunting8.png) Now, click on the **Go** **to** **dashboard** button. You should see the Akaunting dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/akaunting9.png) ## Conclusion In the above guide, you learned how to install Akaunting software on Ubuntu 20.04. You can now easily manage your finance, invoice, and account online from the central location. Try out Akaunting on your [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Configure Code-Server Cloud IDE Platform on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-configure-code-server-cloud-ide-platform-on-ubuntu-20-04/ | Published: 2020-10-20 | Updated: 2024-06-30 | Author: Hitesh Jethva Cloud IDE is a web-based integrated development platform (IDE). It is a programming environment designed for developers and comes with a code editor, a compiler, a debugger, and a graphical user interface. The main benefit of Cloud IDE is that you can access it from anywhere, from any compatible device, enabling easy installation and real-time collaboration between developer teams. code-server is an open-source project that allows you to run Visual Studio Code on a remote server accessible directly from your browser. Visual Studio Code provides a code editor with integrated Git support, a code debugger, and smart autocompletion. In this tutorial, we will learn how to install a code-server Cloud IDE platform on Ubuntu 20.04. ## Step 1 – Install code-server IDE First, you will need to download the latest version of the code-server from the Git Hub repository. At the time of writing this tutorial, the latest version of the code-server is v3.4.0. You can download it with the following command: ``` apt-get update -y ``` ``` wget https://github.com/cdr/code-server/releases/download/v3.4.0/code-server-3.4.0-linux -amd64.tar.gz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar -xvzf code-server-3.4.0-linux-amd64.tar.gz ``` Next, move the extracted directory to the /usr/lib directory: ``` cp -r code-server-3.4.0-linux-amd64 /usr/lib/code-server ``` Next, create a symbolic link of code-server binary to the /usr/bin/ directory: ``` ln -s /usr/lib/code-server/bin/code-server /usr/bin/code-server ``` Next, create a directory to store user’s data: ``` mkdir /var/lib/code-server ``` Once you are finished, you can proceed to the next step. ## Step 2 – Create a Systemd Unit File for code-server Next, you will need to create a systemd service file to manage the code-server service. You can create it with the following command: ``` nano /lib/systemd/system/code-server.service ``` Add the following lines: ``` [Unit] Description=code-server After=nginx.service [Service] Type=simple Environment=PASSWORD=secure-password ExecStart=/usr/bin/code-server --bind-addr 127.0.0.1:8080 --user-data-dir /var/lib/code-server -- auth password Restart=always [Install] WantedBy=multi-user.target ``` Save and close the file when you are finished. Then, reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the code-server service and enable it to start at boot with the following command: ``` systemctl start code-server systemctl enable code-server ``` You can now verify the status of the code-server service with the following command: ``` systemctl status code-server ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/ubuntu1.png) At this point, code-server is started and listening on port 8080. You can now proceed to the next step. ## Step 3 – Configure Nginx as a Reverse Proxy It is a good idea to configure Nginx as a reverse proxy to access the code-server without specifying the port 8080. First, install the Nginx server with the following command: ``` apt-get install nginx -y ``` Once Nginx has been installed, create a new virtual host configuration file for code-server: ``` nano /etc/nginx/sites-available/code-cloud.conf ``` Add the following lines: ``` server_names_hash_bucket_size 64; server { listen 80; server_name code.example.com; location / { proxy_pass http://localhost:8080/; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection upgrade; proxy_set_header Accept-Encoding gzip; } } ``` Save and close the file then, activate the Nginx virtual host with the following command: ``` ln -s /etc/nginx/sites-available/code-cloud.conf /etc/nginx/sites-enabled/ ``` Next, check Nginx for any syntax errors with the following command: ``` nginx -t ``` You should get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 4 – Access code-server IDE Now, open your web browser and type the URL http://code.example.com. You will be redirected to the code-server IDE login page: ![](https://www.atlantic.net/wp-content/uploads/2020/10/ubuntu2.png) Provide your password which you set in the previous steps and click on the **SUBMIT** button. You should see the code-server GUI interface in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/ubuntu3.png) ## Conclusion Congratulations! You have successfully installed and configured code-server IDE on Ubuntu 20.04. You can now start coding directly in Cloud IDE on your [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Install Ganglia Monitoring Server on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-ganglia-monitoring-server-on-ubuntu-18-04/ | Published: 2020-10-20 | Updated: 2023-11-17 | Author: Hitesh Jethva Ganglia is a free, open-source, scalable distributed monitoring tool designed for high-performance computing systems. It runs on all major operating systems and can handle clusters with 2000 nodes. Ganglia uses RRDtool for data storage and visualization, XML for data representation and XDR for compact, portable data transport. It comes with a simple and easy to use web interface that can be used to display live statistics and metrics, such as average CPU load and network utilization for multiple systems. In this tutorial, we will explain how to install Ganglia monitoring server and client on Ubuntu 18.04. ## Step 1 – Install Apache, MariaDB and PHP Before starting, LAMP server must be installed in your system. If not installed, you can install it with the following command: ``` apt-get install apache2 mariadb-server php libapache2-mod-php php-mbstring php-curl php-zip php-gd php-mysql php-curl unzip wget -y ``` Once installed, edit the php.ini file and tweak some settings: ``` nano /etc/php/7.2/apache2/php.ini ``` Change the following lines: ``` memory_limit = 256M upload_max_filesize = 100M max_execution_time = 360 max_input_vars = 1500 date.timezone = America/Chicago ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` ## Step 2 – Install Ganglia Server By default, Ganglia is available in the Ubuntu 18.04 default repository. You can install it with other required packages using the following command: ``` apt-get install ganglia-monitor rrdtool gmetad ganglia-webfrontend -y ``` Note: You will be asked to automatically restart apache2 – select YES. Once all the packages are installed, start the Ganglia service and enable it to start at boot with the following command: ``` systemctl start ganglia-monitor systemctl start gmetad systemctl enable ganglia-monitor systemctl enable gmetad ``` ## Step 3 – Configure Ganglia Server First, you will need to edit the /etc/ganglia/gmetad.conf file and define your master server. ``` nano /etc/ganglia/gmetad.conf ``` Find the following line: ``` data_source "my cluster" localhost ``` Replace it with the following line: ``` data_source "mycluster" 50 localhost your-server-ip:8649 ``` Save and close the file. Next, edit the /etc/ganglia/gmond.conf file as shown below: ``` nano /etc/ganglia/gmond.conf ``` Change the following section: ``` cluster { name = "mycluster" owner = "unspecified" latlong = "unspecified" url = "unspecified" } ``` ``` udp_send_channel { /* mcast_join = 239.2.11.71*/ host = your-server-ip port = 8649 ttl = 1 } ``` ``` udp_recv_channel { /* mcast_join = 239.2.11.71 */ port = 8649 /*bind = 239.2.11.71 */ } ``` Save and close the file when you are finished. Next, you will need to copy the Ganglia configuration file to the Apache virtual host directory. You can copy it with the following command: ``` cp /etc/ganglia-webfrontend/apache.conf /etc/apache2/sites-enabled/ganglia.conf ``` Next, restart the Ganglia and Apache services to apply the changes: ``` systemctl restart ganglia-monitor systemctl restart gmetad systemctl restart apache2 ``` ## Step 4 – Install and Configure Ganglia Client Next, you will need to install and configure the Ganglia client on the client system so that you can monitor it from the Ganglia server. On the Ganglia client system, install the Ganglia client package with the following command: ``` apt-get install ganglia-monitor -y ``` Once installed, edit the /etc/ganglia/gmond.conf file and define the Ganglia server details: ``` nano /etc/ganglia/gmond.conf ``` Change the following section by adding your server IP: ``` udp_send_channel { /* mcast_join = 239.2.11.71*/ host = your-server-ip port = 8649 ttl = 1 } ``` Save and close the file, then restart the Ganglia service to apply the changes: ``` systemctl restart ganglia-monitor ``` ## Step 5 – Access Ganglia Dashboard Now, open your web browser and access the Ganglia dashboard using the URL http://your-server-ip/ganglia You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/ganglia4.png) Now, click on the “**Choose a Node**” and select your server. You should see detailed information about your server in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/ganglia5.png) Next, click on the “**Choose a Node**” and select your client. You should see detailed information about your client in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/ganglia6.png) ![](https://www.atlantic.net/wp-content/uploads/2020/10/ganglia7.png) ## Conclusion Congratulations! You have successfully installed Ganglia monitoring server and client on Ubuntu 18.04. You can now add more clients and start monitoring from the Ganglia dashboard. This process can also be completed on a [VPS Hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net! --- # How to Install Foreman Configuration Management and Provisioning Tool on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-foreman-configuration-management-and-provisioning-tool-on-centos-8/ | Published: 2020-10-21 | Updated: 2023-11-17 | Author: Hitesh Jethva Foreman is a free and open-source tool used for provisioning, configuring, and monitoring servers. It uses configuration management tools including Salt, Chef and Puppet to automate repetitive tasks and deploy applications. Foreman comes with a CLI tool and web-based interface to manage servers in public and private clouds. It supports all major operating systems including, CentOS, Ubuntu, Fedora, CoreOS, Debian, RHEL and many more. In this tutorial, we will show you how to install Foreman on CentOS 8. ## Step 1 – Setup Hostname First, you will need to set up a hostname to resolve an IP address. You can set up it with the following command: ``` hostnamectl set-hostname foreman.example.com ``` Next, you will need to edit the file /etc/hosts and define your IP address. ``` nano /etc/hosts ``` Add the following lines: ``` your-server-ip foreman.example.com ``` Save and close the file when you are finished. ## Step 2 – Install Foreman Installer By default, Foreman installer is not available in the CentOS default repository, so you will need to add the Puppet and Foreman repositories to your system. You can install them with the following command: ``` dnf install https://yum.puppet.com/puppet6-release-el-8.noarch.rpm -y dnf install https://yum.theforeman.org/releases/2.1/el8/x86_64/foreman-release.rpm -y ``` Once both repositories are installed, install the Foreman installer with the following command: ``` dnf install foreman-installer -y ``` After installing the Foreman installer, you can proceed to the next step. ## Step 3 – Run Foreman Installer Foreman installer installs everything including Apache, Puppet, Smart Proxy and TFTP. You can run the Foreman installer using the following command: ``` foreman-installer ``` Once the installation has been completed successfully, you should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/foreman1.png) **Note:** Please note down the admin credentials as shown in the above output. You can also check the status of the Foreman service with the following command: ``` systemctl status foreman ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/foreman2.png) ## Step 4 – Configure Firewall If FirewallD is installed in your server, then you will also need to allow all required ports for external access. You can allow them with the following command: ``` firewall-cmd --add-port={22,53,80,443,3000,8140,3306,5432,8443,5910-5930}/tcp --permanent firewall-cmd --add-port=67-69/udp --permanent ``` Next, reload the FirewallD to apply the configuration changes. ``` firewall-cmd --reload ``` ## Step 5 – Access Foreman Web UI Now, open your web browser and access the Foreman web interface using the URL **https://foreman.example.com**. You should see the Foreman login page as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/10/foreman3.png) Provide your admin username and password and click on the **Log** **In** button. You should see the Foreman dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/10/foreman4.png)   ## Conclusion Congratulations! You have successfully installed and configured Foreman on CentOS 8. You can now add any remote hosts and start managing through the Foreman dashboard on your [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Install Flectra on Debian 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-flectra-on-debian-10/ | Published: 2020-10-22 | Updated: 2024-09-25 | Author: Hitesh Jethva Flectra is free and open-source ERP and CRM software ideal for small to large size companies. Flectra combines the capabilities of both CRM and ERP systems into a single and powerful package. It is a fork of Odoo Community Edition, and it aims replicate many of the features in Odoo Enterprise. This simple, feature-rich, and cost-effective ERP system will likely fulfill all your business needs. **Features** - CRM, HR and & Payroll - Accounting and Financial Management - Business Intelligence - eCommerce – Online Store - Inventory and Production Management - BoM and Vendor Management In this tutorial, we will explain how to install Flectra community edition on Debian 10. ## Step 1 – Install PostgreSQL Flectra uses PostgreSQL as a database backend, so you will need to install it in your server. You can install it with the following command: ``` apt-get install postgresql -y ``` After installing Flectra, you will need to create a new user for Flectra. You can create it with the following command: ``` su - postgres -c "createuser -s flectra" ``` ## Step 2 – Install Flectra Dependencies Next, you will need to install all dependencies required for Flectra. You can install them with the following command: ``` apt-get install node-less gcc python3-venv build-essential python3-pillow python3-wheel python3-lxml python3-dev python3-pip python3-setuptools npm nodejs git gdebi libldap2-dev libsasl2-dev libxml2-dev libxslt1-dev libjpeg-dev libpq-dev -y ``` Once all the dependencies are installed, you will need to install the wkhtmltopdf tool in your system. The wkhtmltopdf is a command line toolset to render HTML into PDFs and various image formats. You can install it with the following command: ``` wget https://github.com/wkhtmltopdf/packaging/releases/download/0.12.6-1/wkhtmltox_0.12.6-1.buster_amd64.deb dpkg -i wkhtmltox_0.12.6-1.buster_amd64.deb apt-get install -f ``` ## Step 3 – Install Flectra First, you will need to create a new system user to run Flectra. You can create it with the following command: ``` useradd -m -U -r -d /opt/flectra -s /bin/bash flectra ``` **Note**: The name of this user should be the same as your PostgreSQL user. After creating Flectra user, switch user to flectra and download the latest version of Flectra with the following command: ``` su - flectra git clone --depth=1 --branch=1.0 https://gitlab.com/flectra-hq/flectra.git flectra ``` Next, create a Python virtual environment for Flectra using the following command: ``` python3 -m venv flectra-venv ``` Next, run the following command to activate the virtual environment. ``` source flectra-venv/bin/activate ``` Next, you will need to edit the file requirements.txt and make some changes. ``` nano flectra/requirements.txt ``` Find the following lines: ``` psycopg2==2.7.3.1; sys_platform != 'win32' psycopg2==2.8.3; sys_platform == 'win32' ``` And replace them with the following lines: ``` psycopg2==2.8.5; sys_platform != 'win32' psycopg2==2.8.5; sys_platform == 'win32' ``` Save the file then install the required modules with the following command: ``` pip3 install -r flectra/requirements.txt ``` After installing all modules, deactivate from the virtual environment and exit from the flectra user with the following command: ``` deactivate exit ``` ## Step 4 – Configure Flectra First, you will need to create some directories to store Flectra files, logs and addons. You can create them with the following command: ``` mkdir -p /opt/flectra/flectra-custom-addons /var/log/flectra /etc/flectra touch /var/log/flectra/flectra.log ``` Next, provide proper ownership to the above directories with the following command: ``` chown -R flectra:flectra /opt/flectra/flectra-custom-addons /var/log/flectra /etc/flectra ``` Next, create a Flectra main configuration file using the following command: ``` nano /etc/flectra/flectra.conf ``` Add the following lines: ``` [options] admin_passwd = flectra-master-password db_host = False db_port = False db_user = flectra db_password = False logfile = /var/log/flectra/flectra.log logrotate = True proxy_mode = True addons_path = /opt/flectra/flectra/addons, /opt/flectra/flectra-custom-addons ``` Save and close the file. ## Step 5 – Create a Systemd Service File for Flectra Next, you will need to create a Flectra service file to manage the Flectra service. You can create it with the following command: ``` nano /etc/systemd/system/flectra.service ``` Add the following lines: ``` [Unit] Description=flectra [Service] Type=simple SyslogIdentifier=flectra PermissionsStartOnly=true User=flectra Group=flectra ExecStart=/opt/flectra/flectra-venv/bin/python3 /opt/flectra/flectra/flectra-bin -c /etc/flectra/flectra.conf StandardOutput=journal+console [Install] WantedBy=multi-user.target ``` Save the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the Flectra service and enable it to start at system reboot with the following command: ``` systemctl start flectra systemctl enable flectra ``` At this point, Flectra is started and listening on port 7073. ## Step 6 – Access the Flectra Dashboard Now, open your web browser and access the Flectra dashboard using the URL **http://your-server-ip:7073**. You should get the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/flectra1.png) Provide your Flectra master password that you previously defined in Flectra configuration file, database, email, password, and click on the **Create** **database** button. You should see the Flectra dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/flectra2.png) ## Conclusion In the above guide, you learned how to install Flectra in Python virtual environment on Debian 10. You can now use Flectra as an ERP or CRM system for your business needs; use Flectra on your [VPS Hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net! --- # How to Setup HAProxy on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-setup-haproxy-on-centos-8/ | Published: 2020-10-22 | Updated: 2024-07-02 | Author: Hitesh Jethva HAProxy stands for High Availability Proxy. Written in C, it is a free and open-source TCP/HTTP Load Balancer and proxying solution for TCP and HTTP-based applications. HAProxy is used to improve the performance of a server environment by distributing the workload across multiple servers. HAProxy allows an application to restart automatically or reroute work to another server in the event of a failure. This powerful, high performance, reliable, and secure load balancer is the most widely used and was specially designed for very high traffic web sites. In this tutorial, we will show you how to set up a high availability load balancer with HAProxy on CentOS 8. ## Prerequisites **For this tutorial, we will use the following setup:** **HAProxy Server:** – hostname : haproxy IP: 192.168.0.10 **Web Server 1:-** hostname : web1 IP: 192.168.0.11 **Web Server 2:-** hostname : web2 IP: 192.168.0.12 ## Step 1 – Create an Atlantic.Net Cloud Server First, log in to your [Atlantic.Net Cloud Server](https://cloud.atlantic.net/?page=userlogin). Create a new [server](https://www.atlantic.net/vps-hosting/how-to-create-new-atlantic-net-cloud-server/), choosing CentOS 8 as the operating system with at least 1GB RAM. Connect to your Cloud Server via SSH and log in using the credentials highlighted at the top of the page. Once you are logged in to your CentOS 8 server, run the following command to update your base system with the latest available packages. ``` dnf update -y ``` ## Step 2 – Install and Configure Nginx ***Note: Complete this step on WebServer 1 and WebServer2*** First, you will need to install the Nginx web server on web1 and web2 instances. You can install Nginx by running the following command: ``` dnf install nginx -y ``` Once Nginx has been installed, start the Nginx service and enable it to start at boot on both instances: ``` systemctl start nginx systemctl enable nginx ``` Next, modify the **index.html** file on each instance. Modify **index.html** file on **web1** instance with the following command: ``` echo "This is My First Nginx Web Server" > /usr/share/nginx/html/index.html ``` Modify **index.html** file on **web2** instance with the following command: ``` echo "This is My Second Nginx Web Server" > /usr/share/nginx/html/index.html ``` Save and close the file when you are finished. ## Step 3 – Install and Configure HAProxy ***Note: Complete this step on HAProxy Server*** First, install HAProxy on the haproxy server instance with the following command: ``` dnf install haproxy -y ``` Once the installation is completed, backup the haproxy default configuration file: ``` mv /etc/haproxy/haproxy.cfg /etc/haproxy/haproxy.cfg-bak ``` The configuration file is divided into four major sections. 1. **global settings:** Used to set process-wide parameters. 2. **defaults:** Used to set default parameters for all other sections. 3. **frontend:** Used to define how HAProxy is externally accessed to enable access to the backend. 4. **backend:** Used to define a set of servers to which the proxy will connect to forward incoming connections. Next, create a new haproxy configuration file using the following command: ``` nano /etc/haproxy/haproxy.cfg ``` Add the following lines that match with your infrastructure: #——————————————————————— ``` global log 127.0.0.1 local2 chroot /var/lib/haproxy pidfile /var/run/haproxy.pid maxconn 4000 user haproxy group haproxy daemon ``` # turn on stats unix socket ``` stats socket /var/lib/haproxy/stats ``` # utilize system-wide crypto-policies ``` ssl-default-bind-ciphers PROFILE=SYSTEM ssl-default-server-ciphers PROFILE=SYSTEM ``` #——————————————————————— ``` defaults mode http log global option httplog option dontlognull option http-server-close option forwardfor except 127.0.0.0/8 option redispatch retries 3 timeout http-request 10s timeout queue 1m timeout connect 10s timeout client 1m timeout server 1m timeout http-keep-alive 10s timeout check 10s maxconn 3000 ``` #——————————————————————— # main frontend which proxys to the backends #——————————————————————— ``` frontend haproxy_balancer # define the name of the frontend. bind 192.168.0.10:80 # IP address of HAProxy server option http-server-close option forwardfor stats uri /haproxy?stats # Specify the HAProxy status page. default_backend webservers ``` #——————————————————————— # round robin balancing between the various backends #——————————————————————— backend webservers # Specify a name for identifying an application ``` mode http balance roundrobin # defines the roundrobin load balancer scheduling algorithm option httpchk HEAD / HTTP/1.1\r\nHost:\ localhost server nginx-web1 192.168.0.11:80 check # IP address of the first backend server server nginx-web2 192.168.0.12:80 check # IP address of the second backend server ``` **Note: Ensure you amend the IP address above with the IP relevant to your server setup** Save and close the file when you are finished. Then, check the haproxy configuration file for any errors with the following command: ``` haproxy -c -f /etc/haproxy/haproxy.cfg ``` You should get the following output: ``` Configuration file is valid ``` Finally, start the haproxy service and enable it to start at boot with the following command: ``` systemctl start haproxy systemctl enable haproxy ``` You can also verify haproxy with the following command: ``` systemctl status haproxy ``` You should get the following output: - ``` haproxy.service - HAProxy Load Balancer ``` ``` Loaded: loaded (/usr/lib/systemd/system/haproxy.service; disabled; vendor preset: disabled) Active: active (running) since Fri 2020-04-24 02:14:55 EDT; 5min ago Process: 1371 ExecStartPre=/usr/sbin/haproxy -f $CONFIG -c -q (code=exited, status=0/SUCCESS) Main PID: 1373 (haproxy) Tasks: 2 (limit: 6087) Memory: 2.8M CGroup: /system.slice/haproxy.service ├─1373 /usr/sbin/haproxy -Ws -f /etc/haproxy/haproxy.cfg -p /run/haproxy.pid └─1374 /usr/sbin/haproxy -Ws -f /etc/haproxy/haproxy.cfg -p /run/haproxy.pid Apr 24 02:14:55 haproxy systemd[1]: Starting HAProxy Load Balancer... Apr 24 02:14:55 haproxy systemd[1]: Started HAProxy Load Balancer. ``` ## Step 4 – Configure HAProxy Logging HAProxy logging allows you to see statistics of each connection to your backend web servers. You can configure rsyslog by editing the file /etc/rsyslog.conf: ``` nano /etc/rsyslog.conf ``` Uncomment the following line: ``` module(load="imudp") input(type="imudp" port="514") ``` Save and close the file when you are finished. Next, you will need to configure a rsyslog server to receive and process HAProxy log messages. To do so, create a new haproxy.conf configuration file: ``` nano /etc/rsyslog.d/haproxy.conf ``` Add the following lines: ``` local2.=info /var/log/haproxy-access.log local2.notice /var/log/haproxy-info.log ``` Save and close the file when you are finished. Then, restart rsyslog service and enable it to start at boot with the following command: ``` systemctl restart rsyslog systemctl enable rsyslog ``` ## Step 5 – Test HAProxy Load Balancing At this point, HAProxy is installed and configured. It’s time to test whether the load balancing is working or not. Open your web browser and type your HAProxy IP http://192.168.0.10. You should see the content of your first Nginx web server in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/haproxy1.png) Next, refresh the webpage. You should see the content of your second Nginx web server in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/haproxy2.png) You can view the status of haproxy using the URL [http://192.168.0.10/haproxy?stats](http://192.18.0.10/haproxy?stats). You should see the health of your servers, current request rates, response times and other metrics in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/haproxy3.png) ## Conclusion In the above guide, we learned how to set up a high availability load balancer with HAProxy on CentOS 8. You can now easily design and configure load balancing to suit your IT infrastructure and application’s requirements; try it out on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How To Install Jitsi Meet Video Conferencing Application on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-jitsi-meet-video-conferencing-application-on-ubuntu-20-04/ | Published: 2020-10-23 | Updated: 2024-06-30 | Author: Hitesh Jethva Jitsi is a free, open-source, multiplatform video conferencing and instant messaging application for web & mobile. It works on Linux, macOS, Windows, iOS and Android, and you can use it as a standalone app or embed it in your web application. Jitsi Meet Audio/Video Chat is fully encrypted and supports several protocols including SIP, XMPP/Jabber, ICQ/AIM, Yahoo!, GTalk/Hangouts extensions, and ZRTP. With Jitsi Meet, you can share your desktop & presentations, invite users to a conference via a simple URL, edit documents with Etherpad, and pick fun meeting URLs for every meeting. In this tutorial, we will explain how to install Jitsi Meet Video Conferencing Server on Ubuntu 20.04. ## Step 1 – Install Jitsi Meet Before starting, you will need to install the required dependencies in your server. You can install them by running the following command: ``` apt-get update -y apt-get install apt-transport-https software-properties-common -y ``` Once installed, download and add the Jitsi GPG key with the following command: ``` wget -qO - https://download.jitsi.org/jitsi-key.gpg.key | apt-key add - ``` Next, add the Jitsi repository using the following command: ``` echo 'deb https://download.jitsi.org stable/' | tee /etc/apt/sources.list.d/jitsi-stable.list ``` Next, update the repository and install the Jitsi Meet with the following command: ``` apt-get update -y apt-get install jitsi-meet ``` During the installation, you will need to provide a valid domain name as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/10/jutsu1.png) Provide your domain name and click on the **Ok** button. You will be asked to generate a new self-signed TLS certificate so that later you can obtain and install a trusted Let’s Encrypt certificate, as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/10/jitsi2.png) Select the first option and hit **Enter** to start the installation. Once the installation has been completed successfully, you can verify the status of Jitsi service with the following command: ``` systemctl status jitsi-videobridge2 ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/jitsi3.png) ## Step 2 – Secure Jitsi Meet with a Let’s Encrypt Certificate Before starting, you will need to install the Certbot client in your server to install and manage the Let’s Encrypt Certificate. First, add the Certbot repository with the following command: ``` add-apt-repository ppa:ahasenack/certbot-tlssni01-1875471 sudo add-apt-repository ppa:certbot/certbot ``` Next, update the repository and install the Certbot client with the following command: ``` apt-get update -y apt-get install certbot python3-certbot-nginx -y ``` The Jitsi Let’s Encrypt installation script expects certbot in /usr/local/sbin directory while Ubuntu installs it in /usr/bin, so create a symbolic link of the script with the following command: ``` ln -s /usr/bin/certbot /usr/local/sbin/certbot ``` Next, update install-letsencrypt-cert.sh to use certbot instead of certbot-auto. ``` sed -i 's/\.\/certbot-auto/certbot/g' /usr/share/jitsi-meet/scripts/install-letsencrypt-cert.sh ``` Next, run the install-letsencrypt-cert.sh script to secure Jitsi Meet with Let’s Encrypt SSL: ``` /usr/share/jitsi-meet/scripts/install-letsencrypt-cert.sh ``` You will be asked to provide your email address and accept the terms of service as shown below: ————————————————————————- ``` This script will: - Need a working DNS record pointing to this machine(for domain jitsi.example.com) - Download certbot-auto from https://dl.eff.org to /usr/local/sbin - Install additional dependencies in order to request Let’s Encrypt certificate - If running with jetty serving web content, will stop Jitsi Videobridge - Configure and reload nginx or apache2, whichever is used - Configure the coturn server to use Let's Encrypt certificate and add required deploy hooks - Add command in weekly cron job to renew certificates regularly You need to agree to the ACME server's Subscriber Agreement (https://letsencrypt.org/documents/LE-SA-v1.1.1-August-1-2016.pdf) by providing an email address for important account notifications Enter your email and press [ENTER]: admin@example.com ``` Provide your valid email address and hit **Enter**. Once the installation is finished, you should see the following output: ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log Plugins selected: Authenticator webroot, Installer None Obtaining a new certificate Performing the following challenges: http-01 challenge for jitsi.example.com Using the webroot path /usr/share/jitsi-meet for all unmatched domains. Waiting for verification... Cleaning up challenges Running deploy-hook command: /etc/letsencrypt/renewal-hooks/deploy/0000-coturn-certbot-deploy.sh Output from deploy-hook command 0000-coturn-certbot-deploy.sh: Configuring turnserver ``` ``` IMPORTANT NOTES: - Congratulations! Your certificate and chain have been saved at: /etc/letsencrypt/live/jitsi.example.com/fullchain.pem Your key file has been saved at: /etc/letsencrypt/live/jitsi.example.com/privkey.pem Your cert will expire on 2020-08-31. To obtain a new or tweaked version of this certificate in the future, simply run certbot again. To non-interactively renew *all* of your certificates, run "certbot renew" - Your account credentials have been saved in your Certbot configuration directory at /etc/letsencrypt. You should make a secure backup of this folder now. This configuration directory will also contain certificates and private keys obtained by Certbot so making regular backups of this folder is ideal. - If you like Certbot, please consider supporting our work by: Donating to ISRG / Let's Encrypt: https://letsencrypt.org/donate Donating to EFF: https://eff.org/donate-le ``` ## Step 3 – Access Jitsi Meet Now, open your web browser and type the URL https://jitsi.example.com. You will be redirected to the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/10/jitsi4.png) Type your meeting a name and click the **Go** button. Once the meeting is started, you should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/jitsi5.png) ## Conclusion Congratulations! you have successfully deployed a Jitsi Meet Video Conferencing server on Ubuntu 20.04. You can now install the Jitsi client app in your mobile device and start exploring Jitsi. Try out Jitsi on VPS [Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net and visit the [Jitsi documentation](https://github.com/jitsi/jitsi-meet/wiki) for more information. --- # How to Set Up Firewall with Firewalld on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-set-up-firewall-with-firewalld-on-centos-8/ | Published: 2020-10-23 | Updated: 2023-11-27 | Author: Hitesh Jethva A firewall is a way to protect your system from unwanted traffic from outside networks. Free and commercial firewall tools are plentiful; some of them include Iptables, UFW, Juniper, pfSense, SonicWall, and more. Among them, FirewallD is a free firewall software tool for CentOS/RHEL/Fedora operating system. It is a frontend controller for iptables and provides a command-line interface to implement firewall rules. Compared to Iptables, FirewallD uses zones and services instead of chains and rules and manages rulesets dynamically. FirewallD provides the firewall-cmd command line tool to manage runtime and permanent configuration. ## Step 1: Install Firewalld By default, FirewallD comes pre-installed in the CentOS operating system. If not installed, you can install it by running the following command: ``` dnf install firewalld -y ``` Once installed, start the FirewallD service and enable it to start at system reboot with the following command: ``` systemctl start firewalld systemctl enable firewalld ``` You can also verify FirewallD’s status using the following command: ``` firewall-cmd --state ``` Output: ``` running ``` ## Step 2: Basic FirewallD Usage FirewallD manages a set of rules using zones. Each zone has its own configuration to accept or deny packets depending on the level of trust you have in the networks your computer is connected to. You can list all available zones using the following command: ``` firewall-cmd --get-zones ``` You should see the following list: ``` block dmz drop external home internal public trusted work ``` To get a list of all active zones, run the following command: ``` firewall-cmd --get-active-zones ``` You should see the following list: ``` public interfaces: eth0 eth1 ``` You can list the default zone set for network connections using the following command: ``` firewall-cmd --get-default-zone ``` Output: ``` public ``` To change the default zone from public to home using the following command: ``` firewall-cmd --set-default-zone=home --permanent ``` To display more information about any zone using the following command: ``` firewall-cmd --info-zone public ``` You should get the following output: ``` public (active) target: default icmp-block-inversion: no interfaces: eth0 eth1 sources: services: cockpit dhcpv6-client ssh ports: protocols: masquerade: no forward-ports: source-ports: icmp-blocks: rich rules: ``` You can also list all available services by running the following command: ``` firewall-cmd --get-services ``` You should get the following output: ``` RH-Satellite-6 amanda-client amanda-k5-client amqp amqps apcupsd audit bacula bacula-client bb bgp bitcoin bitcoin-rpc bitcoin-testnet bitcoin-testnet-rpc bittorrent-lsd ceph ceph-mon cfengine cockpit condor-collector ctdb dhcp dhcpv6 dhcpv6-client distcc dns dns-over-tls docker-registry docker-swarm dropbox-lansync elasticsearch etcd-client etcd-server finger freeipa-4 freeipa-ldap freeipa-ldaps freeipa-replication freeipa-trust ftp ganglia-client ganglia-master git grafana gre high-availability http https imap imaps ipp ipp-client ipsec irc ircs iscsi-target isns jenkins kadmin kdeconnect kerberos kibana klogin kpasswd kprop kshell kube-apiserver ldap ldaps libvirt libvirt-tls lightning-network llmnr managesieve matrix mdns memcache minidlna mongodb mosh mountd mqtt mqtt-tls ms-wbt mssql murmur mysql nfs nfs3 nmea-0183 nrpe ntp nut openvpn ovirt-imageio ovirt-storageconsole ovirt-vmconsole plex pmcd pmproxy pmwebapi pmwebapis pop3 pop3s postgresql privoxy prometheus proxy-dhcp ptp pulseaudio puppetmaster quassel radius rdp redis redis-sentinel rpc-bind rsh rsyncd rtsp salt-master samba samba-client samba-dc sane sip sips slp smtp smtp-submission smtps snmp snmptrap spideroak-lansync spotify-sync squid ssdp ssh steam-streaming svdrp svn syncthing syncthing-gui synergy syslog syslog-tls telnet tentacle tftp tftp-client tile38 tinc tor-socks transmission-client upnp-client vdsm vnc-server wbem-http wbem-https wsman wsmans xdmcp xmpp-bosh xmpp-client xmpp-local xmpp-server zabbix-agent zabbix-server ``` ## Step 3: Allow and Deny Ports with Firewalld Firewalld provides firewall-cmd command line tool to add and remove ports in your system. For example, to allow TCP port 80 and 22 in the public zone, run the following command: ``` firewall-cmd --zone=public --permanent --add-port=80/tcp --add-port=22/tcp ``` Next, reload the FirewallD daemon to save the configuration: ``` firewall-cmd --reload ``` Now, list the added port with the following command: ``` firewall-cmd --info-zone public ``` You should see the following output: ``` public (active) target: default icmp-block-inversion: no interfaces: eth0 eth1 sources: services: cockpit dhcpv6-client ssh ports: 80/tcp 22/tcp protocols: masquerade: no forward-ports: source-ports: icmp-blocks: rich rules: ``` You can also deny or remove the port from the zone easily using the option –remove-port. For example, to deny or remove the port 80 from the public zone, run the following command: ``` firewall-cmd --zone=public --permanent --remove-port=80/tcp ``` ## Step 4: Allow and Deny Services with FirewallD You can also allow and deny by service name instead of using a port with the FirewallD. For example, allow FTP service in the public zone by running the following command: ``` firewall-cmd --zone=public --permanent --add-service=ftp firewall-cmd --reload ``` You can deny or remove the FTP service from the public zone using the following command: : ``` firewall-cmd --zone=public --permanent --remove-service=ftp firewall-cmd --reload ``` ## Step 5: Setup IP Masquerading with FirewallD IP masquerading is a process or method that allows your computers in a network with private IP addresses to communicate with the Internet using your server’s address. It is very useful when you want another computer to communicate to the Internet without buying additional IPs from your ISP. Before setting up IP masquerading, check if masquerading is active or not with the following command: ``` firewall-cmd --zone=public --query-masquerade ``` You should see that IP masquerading is disabled in the public zone as shown below: ``` no ``` Now, set the IP masquerading using the following command: ``` firewall-cmd --zone=public --add-masquerade firewall-cmd --reload ``` You can also disable the IP masquerading using the option –remove-masquerade: ``` firewall-cmd --zone=public --remove-masquerade firewall-cmd --reload ``` ## Conclusion In the above guide, you learned how to use FirewallD to block unwanted traffic in your system. You should now be able to limit all unnecessary connections and protect your server from attackers. Try FirewallD on an Atlantic.Net [VPS](https://www.atlantic.net/vps-hosting/)! --- # Install Graylog Monitoring Server on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/install-graylog-monitoring-server-on-centos-8/ | Published: 2020-10-23 | Updated: 2023-11-18 | Author: Hitesh Jethva Graylog is a powerful platform for simplified log management of structured or unstructured data. Additionally, it is useful for debugging applications. Graylog is broadly based upon Scala, MongoDB, and Elasticsearch. It has a main server to receive data from the clients that may be installed over different servers. Similarly, Graylog features a web interface for the visualization of data. It facilitates work over the logs that the main server aggregates. Graylog is primarily used as a stash for logs for any web application in use. Alternately, Graylog is also effective when working with raw strings, such as Syslog. In this tutorial, we will show you how to install the Graylog Monitoring server on CentOS 8. ## Step 1 – Install Required Dependencies Before starting, you will need to install Java and other required dependencies on your server. First, install the EPEL repository with the following command: ``` dnf install epel-release -y ``` Next, install the Java using the following command: ``` dnf install -y java-1.8.0-openjdk-headless -y ``` Once Java is installed, you can verify it with the following command: ``` java -version ``` You should get the following output: ``` openjdk version "1.8.0_265" OpenJDK Runtime Environment (build 1.8.0_265-b01) OpenJDK 64-Bit Server VM (build 25.265-b01, mixed mode) ``` Next, install other required packages with the following command: ``` dnf install wget pwgen perl-Digest-SHA -y ``` ## Step 2 – Install Elasticsearch Graylog uses Elasticsearch to store log messages and its search function. By default, the latest version of Elasticsearch is not available in the CentOS 8 default repository, so you will need to add the Elasticsearch repo to your system. First, import the GPG key with the following command: ``` rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch ``` Next, create Elasticsearch repo with the following command: ``` nano /etc/yum.repos.d/elasticsearch.repo ``` Add the following lines: ``` [elasticsearch-6.x] name=Elasticsearch repository for 6.x packages baseurl=https://artifacts.elastic.co/packages/oss-6.x/yum gpgcheck=1 gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch enabled=1 autorefresh=1 type=rpm-md ``` Save and close the file then install the Elasticsearch with the following command: ``` dnf install elasticsearch-oss -y ``` Once the Elasticsearch is installed, edit the Elasticsearch main configuration file: ``` nano /etc/elasticsearch/elasticsearch.yml ``` Define your cluster name and add another line as shown below: ``` cluster.name: my-graylog action.auto_create_index: false ``` Save the file, then reload the systemd daemon and enable Elasticsearch to start at system reboot with the following command: ``` systemctl daemon-reload systemctl enable elasticsearch ``` Next, restart the Elasticsearch service with the following command: ``` systemctl restart elasticsearch ``` You can now check the Elasticsearch response using the following command: ``` curl -X GET http://localhost:9200 ``` If everything is correct, you should get the following output: ``` { "name" : "7FL0524", "cluster_name" : "my-graylog", "cluster_uuid" : "C4OvK0Y_TjCiVzBiHbz0pA", "version" : { "number" : "6.8.12", "build_flavor" : "oss", "build_type" : "rpm", "build_hash" : "7a15d2a", "build_date" : "2020-08-12T07:27:20.804867Z", "build_snapshot" : false, "lucene_version" : "7.7.3", "minimum_wire_compatibility_version" : "5.6.0", "minimum_index_compatibility_version" : "5.0.0" }, "tagline" : "You Know, for Search" } ``` ## Step 3 – Install MongoDB Server Graylog uses MongoDB to store configurations and meta information. By default, MongoDB is not available in the CentOS 8 standard repository, so you will need to create a repository for MongoDB. You can create it with the following command: ``` nano /etc/yum.repos.d/mongodb-org-4.0.repo ``` Add the following lines: ``` [mongodb-org-4] name=MongoDB Repository baseurl=https://repo.mongodb.org/yum/redhat/8/mongodb-org/4.2/x86_64/ gpgcheck=1 enabled=1 gpgkey=https://www.mongodb.org/static/pgp/server-4.2.asc ``` Save and close the file, then update the repository with the following command: ``` dnf update -y ``` Next, install the MongoDB server with the following command: ``` dnf install mongodb-org -y ``` Once MongoDB is installed, start the MongoDB service and enable it to start at system reboot: ``` systemctl start mongod systemctl enable mongod ``` ## Step 4 – Install and Configure Graylog Server By default, the Graylog server package is not available in the CentOS 8 standard repository, so you will need to create a repo for Graylog. You can install the Graylog repo using the following command: ``` dnf install https://packages.graylog2.org/repo/packages/graylog-3.2-repository_latest.rpm -y ``` Once the repository is created, you can install the Graylog server with the following command: ``` dnf install graylog-server -y ``` After installing Graylog server, you will need to generate a secret key for Graylog. You can generate it with the following command: ``` pwgen -N 1 -s 96 ``` Output: ``` un5R8H7vmoq1japNYvHD2pEkawKyBzZpWeFsfVEk4Ustl5sWPtcdMbgTV18mHyqBnBK0sk83fcEmceTtyNzxntWqWhNPYe9N ``` You will also need to generate a secure password for Graylog. You can generate it with the following command: ``` echo -n your-password | shasum -a 256 ``` You should get the following output: ``` 616384da8ed2fb86db3462ec827bc433256324e323a2438f48ae32930e707065 - ``` **Note**: You can use this password “your-password” to log in to the Graylog web interface. Next, edit the Graylog main configuration file and define your secret key, password, and other settings: ``` nano /etc/graylog/server/server.conf ``` Change the following lines: ``` password_secret = un5R8H7vmoq1japNYvHD2pEkawKyBzZpWeFsfVEk4Ustl5sWPtcdMbgTV18mHyqBnBK0sk83 fcEmceTtyNzxntWqWhNPYe9N root_username = admin root_password_sha2 = 616384da8ed2fb86db3462ec827bc433256324e323a2438f48ae32930e707065 root_timezone = UTC http_bind_address = your-server-ip:9000 ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the Graylog service and enable it to start at system reboot with the following command: ``` systemctl start graylog-server systemctl enable graylog-server ``` You can check the Graylog server log to verify whether the Graylog server is started or not: ``` tail -f /var/log/graylog-server/server.log ``` If the Graylog server is started successfully, you should get the following output: ``` 2020-10-02T11:46:15.649-04:00 INFO [InputSetupService] Triggering launching persisted inputs, node transitioned from Uninitialized [LB:DEAD] to Running [LB:ALIVE] 2020-10-02T11:46:15.654-04:00 INFO [ServerBootstrap] Graylog server up and running. ``` At this point, the Graylog server is started and listening on port 9000. ## Step 5 – Access Graylog Interface Now, you can access the Graylog web interface using the URL **http://your-server-ip:9000**. You should see the Graylog login page: ![](https://www.atlantic.net/wp-content/uploads/2020/10/graylog1.png) Provide your admin username and password and click on the **Sign**–**in** button. You should see the Graylog dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/10/graylog2.png) ## Conclusion Congratulations! You have successfully installed and configured the Graylog server on CentOS 8. You can now configure your Graylog server to receive Rsyslog logs from external servers. For more information, you can visit the Graylog [documentation](https://docs.graylog.org/). Get started with Graylog today on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Install Dgraph on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-dgraph-on-centos-8/ | Published: 2020-10-24 | Updated: 2026-05-04 | Author: Hitesh Jethva Dgraph is a free, open-source, distributed GraphQL database with a graph backend written in Go language. It is one of the most advanced graphing and multi-model NoSQL database systems available to small and large companies that process massive amounts of data. Dgraph aims to provide Google production-level scale and throughput and serve real-time user queries. It is capable of handling terabytes of structured data running on commodity hardware with low latency for real-time user queries. Dgraph is fast and highly available, offers flexible schema, distributed and transactional graphs, and much more. In this tutorial, we will show you how to install the Dgraph database system on CentOS 8. ## Step 1 – Install Dgraph A simple and easy way to install Dgraph is to run the Dgraph auto-installation script. You can run the Dgraph installation script using the following command: ``` curl https://get.dgraph.io -sSf | bash ``` You will need to accept the terms of service to install the Dgraph in your system, as shown below: ``` By downloading Dgraph you agree to the Dgraph Community License (DCL) terms shown above. An open-source (Apache 2.0) version of Dgraph without any DCL-licensed enterprise features is available by building from the Dgraph source code. See the source installation instructions for more info: https://github.com/dgraph-io/dgraph#install-from-source Do you agree to the terms of the Dgraph Community License? [Y/n] Y Latest release version is v20.07.0. Downloading checksum file for v20.07.0 build. ######################################################################## 100.0%##O#- # ######################################################################## 100.0% Download complete. Comparing checksums for dgraph binaries Downloading https://github.com/dgraph-io/dgraph/releases/download/v20.07.0/dgraph-linux-amd64.tar.gz ######################################################################## 100.0%#=#=# ######################################################################## 100.0% Download complete. Inflating binaries (password may be required). Dgraph binaries v20.07.0 have been installed successfully in /usr/local/bin. ``` Once Dgraph is installed, you can proceed to the next step. ## Step 2 – Create a User for Dgraph Next, you will need to create a separate user and group to run the Dgraph service. You can create them with the following command: ``` groupadd --system dgraph useradd --system -d /var/run/dgraph -s /bin/false -g dgraph dgraph ``` Next, you will need to create directories to store Dgraph log and state files. You can create them with the following command: ``` mkdir -p /var/log/dgraph mkdir -p /var/run/dgraph/{p,w,zw} ``` Next, change the ownership of the directory to dgraph as shown below: ``` chown -R dgraph:dgraph /var/{run,log}/dgraph ``` ## Step 3 – Create a Systemd Service File for Dgraph Next, you will need to create some systemd service files to manage Dgraph. First, create a dgraph.service file with the following command: ``` nano /etc/systemd/system/dgraph.service ``` Add the following lines: ``` [Unit] Description=dgraph.io data server Wants=network.target After=network.target dgraph-zero.service Requires=dgraph-zero.service [Service] Type=simple ExecStart=/usr/local/bin/dgraph alpha --lru_mb 2048 -p /var/run/dgraph/p -w /var/run/dgraph/w StandardOutput=journal StandardError=journal User=dgraph Group=dgraph [Install] WantedBy=multi-user.target ``` Save and close the file when you are finished. Next, create a dgraph-zero.service file with the following command: ``` nano /etc/systemd/system/dgraph-zero.service ``` Add the following lines: ``` [Unit] Description=dgraph.io zero server Wants=network.target After=network.target [Service] Type=simple ExecStart=/usr/local/bin/dgraph zero --wal /var/run/dgraph/zw StandardOutput=journal StandardError=journal User=dgraph Group=dgraph [Install] WantedBy=multi-user.target RequiredBy=dgraph.service ``` Save and close the file when you are finished. Next, create a graph-ui.service file with the following command: ``` nano /etc/systemd/system/dgraph-ui.service ``` Add the following lines: ``` [Unit] Description=dgraph.io UI server Wants=network.target After=network.target [Service] Type=simple ExecStart=/usr/local/bin/dgraph-ratel StandardOutput=journal StandardError=journal User=dgraph Group=dgraph [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start and enable all services to start at system reboot with the following command: ``` systemctl enable --now dgraph systemctl enable --now dgraph-ui systemctl enable --now dgraph-zero systemctl start dgraph systemctl start dgraph-ui systemctl start dgraph-zero ``` At this point, all Dgraph services are running and listening on port 8000 and 8080. You can check them with the following command: ``` ss -tunelp | grep 8000 ``` You should get the following output: ``` tcp6 0 0 :::8000 :::* LISTEN 990 24437 1066/dgraph-ratel ss -tunelp | grep 8080 ``` You should get the following output: ``` tcp6 0 0 :::8080 :::* LISTEN 990 24979 1083/dgraph ``` ## Step 4 – Access Dgraph Web Interface Now, open your web browser and access the Dgraph web interface using the URL http://your-server-ip:8000. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/10/dgraph1.png) Click on the **Launch** **Latest** button. You will be redirected to the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/10/dgraph2.png) Provide your Dgraph server URL and click on the **Continue** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/10/dgraph3.png) Click on the **Continue** button. You will be redirected to the Dgraph dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/10/dgraph4.png) ## Conclusion Congratulations! You have successfully installed Dgraph on CentOS 8. You can now start building your application with Dgraph and GraphQL on your Atlantic.Net [VPS](https://www.atlantic.net/vps-hosting/). For more information, visit the Dgraph official [documentation](https://docs.dgraph.io/). --- # How to Install Mautic Marketing Automation Tool on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-mautic-marketing-automation-tool-on-ubuntu-20-04/ | Published: 2020-10-24 | Updated: 2023-11-18 | Author: Hitesh Jethva Mautic is a very popular open-source email marketing and lead management software that helps you create customized email templates and email campaigns. It is an alternative to other [email service providers](https://www.omnisend.com/blog/email-marketing-software/), like MailChimp, and can be integrated with third-party SMTP relay services, like Gmail, Mandrill, Sendgrid, and others. Mautic offers a rich set of features, including customizable dripflow programs, marketing campaigns, social media monitoring, and many more. In this tutorial, we will show you how to install Mautic Marketing Automation Tool on Ubuntu 20.04. ## Step 1 – Install Apache, MariaDB, and PHP First, you will need to install Apache web server and MariaDB in your server. You can install them using the following command: ``` apt-get install apache2 mariadb-server -y ``` Once both packages are installed, you will also need to install PHP version 7.2 on your server. By default, Ubuntu 20.04 ships with PHP version 7.4, so you will need to add the Ondrej PHP repository in your system. You can add it with the following command: ``` apt-get install software-properties-common -y add-apt-repository ppa:ondrej/php apt-get update -y ``` Once the repository is added, install PHP with all required extensions by running the following command: ``` apt-get install php7.2 libapache2-mod-php7.2 php7.2-common php7.2-gmp php7.2-curl php7.2-intl php7.2-mbstring php7.2-xmlrpc php7.2-mysql php7.2-bcmath php7.2-gd php7.2-xml php7.2-cli php7.2-zip php7.2-imap curl git -y ``` After installing PHP, edit the php.ini file and change some desired settings: ``` nano /etc/php/7.2/apache2/php.ini ``` Change the following lines: ``` memory_limit = 512M upload_max_filesize = 100M max_execution_time = 360 date.timezone = America/Chicago ``` Save and close the file then restart Apache web service to apply the changes: ``` systemctl restart apache2 ``` ## Step 2 – Configure Database for Mautic First, log in to MariaDB shell with the following command: ``` mysql ``` Once logged in, create a database and user for Mautic with the following command: ``` CREATE DATABASE mauticdb; CREATE USER 'mauticuser'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the Mautic database with the following command: ``` GRANT ALL ON mauticdb.* TO 'mauticuser'@'localhost' IDENTIFIED BY 'password' WITH GRANT OPTION; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download Mautic First, change the directory to the Apache web root directory and download the latest version of the Mautic from the Git Hub using the following command: ``` cd /var/www/html git clone https://github.com/mautic/mautic.git ``` Once downloaded, install the Composer in your system with the following command: ``` curl -sS https://getcomposer.org/installer | php -- --install-dir=/usr/local/bin --filename=composer ``` Next, change the directory to mautic and install all PHP dependencies with the following command: ``` cd mautic composer install ``` Next, change the ownership of the mautic to www-data and set proper permissions with the following command: ``` chown -R www-data:www-data /var/www/html/mautic/ chmod -R 755 /var/www/html/mautic/ ``` ## Step 4 – Configure Apache for Mautic First, create an Apache virtual host configuration file to serve Mautic. ``` nano /etc/apache2/sites-available/mautic.conf ``` Add the following lines: ``` ServerAdmin admin@example.com DocumentRoot /var/www/html/mautic ServerName example.com ServerAlias www.example.com Options +FollowSymlinks AllowOverride All Require all granted ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined ``` Save and close the file, then enable the Mautic virtual host file and rewrite module with the following command: ``` a2ensite mautic.conf a2enmod rewrite ``` Next, restart the Apache web service to apply the changes: ``` systemctl restart apache2 ``` ## Step 5 – Access Mautic Web UI At this point, Mautic is installed. Now, open your web browser and access the Mautic web UI using the URL **http://example.com**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/amutic5.png) Click on the **Next** **Step** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/mautic6.png) Provide your Mautic database details and click on the **Next** **Step** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/mautic7.png) Provide your Mautic admin username, email, and password and click on the **Next** **Step** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/mautic8.png) Provide your desired SMTP settings and click on the **Next** **Step** button. You will be redirected to the Mautic login screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/mautic9.png) Provide your Mautic admin username and password and click on the **login** button. You should see the Mautic dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/mautic10.png) ## Conclusion Congratulations! You have successfully installed Mautic on Ubuntu 20.04. You can now install additional plugins to extend the functionality of Mautic and create your own email campaigns; try it out on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Install Chef Automation Server on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-chef-automation-server-on-ubuntu-20-04/ | Published: 2020-10-25 | Updated: 2023-11-23 | Author: Hitesh Jethva Chef is a powerful platform for automation, simplifying how infrastructure is managed, deployed, or configured across a network. Chef operates by transforming the infrastructure into code. The developer can then deploy or manage resources across multiple servers or nodes, but before the developer deploys the code over any other environment, they first create and test it over a workstation. Overall, Chef is one of the best tools for administering infrastructure from a workstation. For compliance, node visibility, and workflow, Chef Automate makes available a full suite of enterprise capabilities. The software integrates with Open source products such as Habitat, InSpec, and Chef. In this tutorial, we will show you how to install the Chef server and client on Ubuntu 20.04. **Note: **The procedure uses requires two Ubuntu instances: - One Client - One Server ## Step 1 – Setup Hostname Before starting, you will need to set up a fully qualified hostname and hostname resolution on your Chef server. First, set up the hostname with the following commands: ``` apt-get update -y ``` ``` hostnamectl set-hostname chef.example.com ``` Next, open /etc/hosts file and bind your server IP address with hostname: ``` nano /etc/hosts ``` Add the following line: ``` chef-server-ip chef.example.com ``` Save and close the file when you are finished. ## Step 3 – Install Chef Server By default, Chef package is not available in the Ubuntu 20.04 default repository, so you will need to download it from their official website. First, install the required dependencies by running the following command on the Chef server: ``` apt-get install curl wget gnupg2 -y ``` Next, download the Chef package with the following command: ``` wget https://packages.chef.io/files/stable/chef-server/13.1.13/ubuntu/18.04/chef-server-core_13.1.13-1_amd64.deb ``` Once the package is downloaded, install it by running the following command: ``` dpkg -i chef-server-core_13.1.13-1_amd64.deb ``` Once the package is installed, you will need to reconfigure the Chef server. You can reconfigure it with the following command: ``` chef-server-ctl reconfigure ``` You will be asked to accept the term of license as shown below: ``` +---------------------------------------------+ Chef License Acceptance Before you can continue, 3 product licenses must be accepted. View the license at https://www.chef.io/end-user-license-agreement/ Licenses that need accepting: * Chef Infra Server * Chef Infra Client * Chef InSpec Do you accept the 3 product licenses (yes/no)? > yes ``` Type yes to accept the license and hit enter to continue. Once the installation has been completed, you should get the following output: ``` Running handlers: Running handlers complete Chef Infra Client finished, 482/1032 resources updated in 04 minutes 34 seconds Chef Server Reconfigured! ``` **Note**: The installation will take over 5 minutes ## Step 4 – Create an Administrator Account and Organization First, create a directory to store all keys. ``` mkdir ~/.chef_key ``` Next, run the following command to create an administrator account: ``` chef-server-ctl user-create atlanticuser Atlantic User admin@example.com 'mypassword' --filename ~/.chef_key/atlantic.pem ``` The above command will create an admin account with the name atlanticuser, full name “Atlantic User,” password “mypassword,” and generate the keyfile at ~/.chef_key/atlantic.pem. Next, create an organization with the following command: ``` chef-server-ctl org-create atlantic "atlantic cloud" --association_user atlanticuser --filename ~/.chef_key/atlantic-org.pem ``` The above command will create an organization with name atlantic, full name “atlantic cloud,” associate user “atlanticuser,” and generate keyfile at ~/.chef_key/atlantic-org.pem. You can now verify the generated keys with the following command: ``` ls ~/.chef_key/ ``` You should see the following output: ``` atlantic.pem hitjethva.pem ``` ## Step 5 – Install Chef Web Management Console Next, you will need to install the Chef manage in your server. Chef manage is an add-on that can be used to manage Chef server from the web-based interface. You can install the Chef manage with the following command: ``` chef-server-ctl install chef-manage ``` Next, reconfigure the Chef server and Chef manage with the following command: ``` chef-server-ctl reconfigure chef-manage-ctl reconfigure ``` You will be asked to accept the license agreement as shown below: ``` Press any key to continue. Type 'yes' to accept the software license agreement or anything else to cancel. yes ``` Type **yes** and hit Enter to finish the installation. ## Step 6 – Install Chef Client Next, you will need to log into the Chef client machine and install the Chef client package. By default, the Chef client package is not available in the Ubuntu 20.04 default repository, so you will need to download it from their official website. Run the following command to download the Chef workstation package: ``` wget https://packages.chef.io/files/stable/chef-workstation/20.6.62/debian/10/chef-workstation_20.6.62-1_amd64.deb ``` Once the package is downloaded, install it with the following command: ``` dpkg -i chef-workstation_20.6.62-1_amd64.deb ``` After installing Chef client, you will need to create a Chef repo in your system. The chef-repo directory will store your Chef cookbooks and other related files. You can create it with the following command: ``` chef generate repo chef-repo ``` You will be asked to accept the license as shown below: ``` +---------------------------------------------+ Chef License Acceptance Before you can continue, 3 product licenses must be accepted. View the license at https://www.chef.io/end-user-license-agreement/ Licenses that need accepting: * Chef Workstation * Chef Infra Client * Chef InSpec Do you accept the 3 product licenses (yes/no)? > yes ``` Type **yes** and hit Enter to accept the License. You should get the following output: ``` Persisting 3 product licenses... ✔ 3 product licenses persisted. +---------------------------------------------+ Generating Chef Infra repo chef-repo - Ensuring correct Chef Infra repo file content Your new Chef Infra repo is ready! Type `cd chef-repo` to enter it. ``` You can list all generated files and directories inside the Chef repo with the following command: ``` ls chef-repo ``` You should get the following output: ``` chefignore cookbooks data_bags LICENSE policyfiles README.md ``` Next, you will need to create a .chef directory to store all Knife configuration file and the .pem files that are used for RSA key pair authentication with the Chef server. You can create it with the following command: ``` mkdir ~/chef-repo/.chef ``` Next, generate an SSH key pair with the following command: ``` ssh-keygen -b 4096 ``` Don’t provide any password, just press Enter to generate an SSH key pair as shown below: ``` Generating public/private rsa key pair. Enter file in which to save the key (/root/.ssh/id_rsa): Created directory '/root/.ssh'. Enter passphrase (empty for no passphrase): Enter same passphrase again: Your identification has been saved in /root/.ssh/id_rsa Your public key has been saved in /root/.ssh/id_rsa.pub The key fingerprint is: SHA256:OvOCW9vNnVfs8II8TKJnRxv9vwRu5R4JqRxWPVU1rTY root@clientnode The key's randomart image is: +---[RSA 4096]----+ | .B| | . +| | . + | | . E .| | S o * + | | . + B B +| | .= . O * @ | | ...*.oo.O.= =| | ....ooo.oo ++| +----[SHA256]-----+ ``` Next, copy the generated key to the Chef server machine with the following command: ``` ssh-copy-id root@chef-server-ip ``` Next, you will need to copy all .pem files from the Chef server to the client machine. You can copy them with the following command: ``` scp root@chef-server-ip:~/.chef_key/*.pem ~/chef-repo/.chef/ ``` You should get the following output: ``` atlantic.pem 100% 1674 2.2MB/s 00:00 hitjethva.pem 100% 1678 2.4MB/s 00:00 ``` ## Step 7 – Configure Knife and Generate Cookbook Next, you will need to configure Knife and generate cookbook on the client machine. First, change into the repository with the command: ``` cd ~/chef-repo ``` Next, generate yourfirst cookbook with the following command: ``` chef generate cookbook my_cookbook ``` Once the cookbook is generated, create a new Knife configuration file: nano ~/chef-repo/.chef/config.rb Add the following lines: ``` current_dir = File.dirname(__FILE__) log_level :info log_location STDOUT node_name 'hitjethva' client_key "hitjethva.pem" validation_client_name 'atlantic-validator' validation_key "atlantic-validator.pem" chef_server_url 'https://chef.example.com/organizations/atlantic' cache_type 'BasicFile' cache_options( :path => "#{ENV['HOME']}/.chef/checksums" ) cookbook_path ["#{current_dir}/../cookbooks"] ``` Save and close the file. Make sure all names match with your organization name and admin username. Next, edit the /etc/hosts file and add the fully qualified name of your Chef server. ``` nano /etc/hosts ``` Add the following line: ``` chef-server-ip chef.example.com ``` Save and close the file when you are finished. Next, fetch the SSL certificate from the Chef server with the following command: ``` cd ~/chef-repo knife ssl fetch ``` You should get the following output: ``` WARNING: Certificates from chef.example.com will be fetched and placed in your trusted_cert directory (/root/chef-repo/.chef/trusted_certs). Knife has no means to verify these are the correct certificates. You should verify the authenticity of these certificates after downloading. Adding certificate for chef_example_com in /root/chef-repo/.chef/trusted_certs/chef_example_com.crt ``` You can also verify the SSL with the following command: ``` knife ssl check ``` You should get the following output: ``` Connecting to host chef.example.com:443 Successfully verified certificates from `chef.example.com' ``` ## Step 8 – Bootstrap a Client Node Next, you will need to install the Chef client on the node and validate the node. This allows the node to read from the Chef server and pull down and apply any needed configuration updates detected by the chef-client from the workstation. On the Chef client machine, change the directory to .chef with the following command: ``` cd ~/chef-repo/.chef ``` Next, bootstrap the client with the following command: ``` knife bootstrap chef.example.com -x root -P rootpassword --node-name clientnode ``` Once the installation is completed, you should get the following output: ``` Patents: https://www.chef.io/patents [chef.example.com] resolving cookbooks for run list: [] [chef.example.com] Synchronizing Cookbooks: [chef.example.com] Installing Cookbook Gems: [chef.example.com] [chef.example.com] Compiling Cookbooks... [chef.example.com] [2020-10-02T07:56:21+00:00] WARN: Node clientnode has an empty run list. [chef.example.com] Converging 0 resources [chef.example.com] [chef.example.com] Running handlers: Running handlers complete Chef Infra Client finished, 0/0 resources updated in 02 seconds ``` You can now list all nodes with the following command: ``` knife client list ``` You should get the following output: ``` atlantic-validator clientnode ``` ## Step 9 – Access Chef Manage Console Now, open your web browser and access the Chef manage console using the URL http://chef.server-ip/login. You should see the Chef login page: ![](https://www.atlantic.net/wp-content/uploads/2020/10/chef1.png)   Provide your admin username and password and click on the **Sign** **in** button. You should see the Chef dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/10/chef2.png) ![](https://www.atlantic.net/wp-content/uploads/2020/10/chef3.png) ## Conclusion In the above guide, you learned how to install Chef server and client on Ubuntu 20.04 server. You also learned its components with installation and configuration settings. For more information, you can visit Chef [documentation](https://www.chef.io/). Try out Chef on your [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Install OpenMeetings on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/install-openmeetings-on-ubuntu-20-04/ | Published: 2020-10-25 | Updated: 2023-11-27 | Author: Hitesh Jethva OpenMeeting is open-source conferencing software used for web conferencing, online training, and desktop sharing. It is an Apache Foundation project and based on Red5 Media Server. OpenMeeting is written in Java and supports multiple database servers. It allows you to record sessions and includes features such as an advanced file explorer, chat, user management, and more. In this tutorial, we will show you how to install OpenMeetings on Ubuntu 20.04. ## Step 1 – Install Required Dependencies OpenMeeting is written in Java, so you will need to install Java JDK in your system. You can install it with the following command: ``` apt-get update -y apt-get install openjdk-11-jdk openjdk-11-jdk-headless -y ``` Once installed, verify the Java version using the following command: ``` java -version ``` You should see the following output: ``` openjdk version "11.0.7" 2020-04-14 OpenJDK Runtime Environment (build 11.0.7+10-post-Ubuntu-3ubuntu1) OpenJDK 64-Bit Server VM (build 11.0.7+10-post-Ubuntu-3ubuntu1, mixed mode, sharing) ``` Next, install icedtea, imagemagick, and other required packages in your system. You can install them with the following command: ``` apt-get install icedtea-netx imagemagick libjpeg62 zlib1g-dev flashplugin-installer ffmpeg vlc sox -y ``` Next, you will need to modify ImageMagick, so OpenMeetings can upload office files to a whiteboard. You can do it by editing the following file: ``` nano /etc/ImageMagick-6/policy.xml ``` Comment out the following lines: ``` ``` Save and close the file, then install LibreOffice with the following command: ``` apt-get install software-properties-common -y add-apt-repository ppa:libreoffice/ppa apt-get update -y apt-get install libreoffice -y ``` Once you are finished, you can proceed to the next step. ## Step 2 – Install and Configure a Database OpenMeeting uses MariaDB/MySQL as a database backend, so you will need to install the MariaDB server in your system. You can install it with the following command: ``` apt-get install mariadb-server -y ``` Once installed, login to the MariaDB shell with the following command: ``` mysql ``` Once login, create a database and user for OpenMeeting with the following command: ``` CREATE DATABASE openmeeting DEFAULT CHARACTER SET 'utf8'; GRANT ALL PRIVILEGES ON openmeeting.* TO 'open'@'localhost' IDENTIFIED BY 'password' WITH GRANT OPTION; ``` Next, flush the privileges and exit from the MariaDB shell using the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install OpenMeeting First, you will need to download the OpenMeeting from the Apache website: ``` wget http://archive.apache.org/dist/openmeetings/4.0.9/bin/apache-openmeetings-4.0.9.tar.gz ``` Once the download is completed, create a directory for OpenMeeting and extract the downloaded file inside it: ``` mkdir /opt/openmeetings tar -xvzf apache-openmeetings-4.0.9.tar.gz -C /opt/openmeetings ``` Next, you will need to download the MySQL connector and copy it to OpenMeeting. You can download it with the following command: ``` wget https://repo1.maven.org/maven2/mysql/mysql-connector-java/5.1.48/mysql-connector-java- 5.1.48.jar ``` Next, copy the downloaded file to the OpenMeeting directory with the following command: ``` cp mysql-connector-java-5.1.48.jar /opt/openmeetings/webapps/openmeetings/WEB-INF/lib/ ``` Next, change the directory to /opt/openmeetings and start the application with the following command: ``` cd /opt/openmeetings sh red5.sh openmeetings ``` At this point, OpenMeeting is started and listening on port 5080. ## Step 4 – Access OpenMeeting Web UI Now, open your web browser and access OpenMeeting using the URL **http://your-server-ip:5080/openmeetings**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/om1.png) Click on the **>** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/om2.png) Select your database type and provide the database name, then click on the > button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/om3.png) Provide your username, password, and email, then click on the **>** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/om4.png) Provide your SMTP details and click on the **>** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/om5.png) Provide your ImageMagick, sox, and FFmpeg path and click on the **>** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/om6.png) Click on the **>** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/om7.png) Click on the **Finish** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/om8.png) Click on the **Enter the Application** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/om9.png) Provide your admin username, password, and click on the **Sign** **In** button. You should see the OpenMeeting dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/om10.png) **Conclusion** Congratulations! You have successfully installed OpenMeeting on Ubuntu 20.04. Try setting up your own web conferencing and training system on your [VPS Hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net. --- # How To Setup Bareos Backup Solution On CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-setup-bareos-backup-solution-on-centos-8/ | Published: 2020-10-26 | Updated: 2023-11-18 | Author: Hitesh Jethva Bareos, also called “Backup Archiving Recovery Open Sourced,” is an open-source software used for backing up and protecting data. It is cross-platform and supports all major operating systems including Linux, Windows, MacOS and Unix. Bareos comes with a simple and user-friendly web interface that helps you to perform backup operations through a web browser. Bareos consists of several components, including the Backup Directory, Control Unit, Storage Daemons, and File Daemons. The Director is the controller for the other daemons, while the File Daemons are responsible for backing up the data from the client. In this tutorial, we will learn how to install the Bareos backup application on CentOS 8. ## Step 1 – Install LAMP Server Bareos uses MariaDB or MySQL as a database backend. You will need to install the MariaDB database server, Apache and PHP in your system. You can install them with the following command: ``` dnf install httpd mariadb-server php php-cli php-common -y ``` Once all the packages are installed, start the Apache and MariaDB services and enable them to start at system reboot with the following command: ``` systemctl start httpd systemctl enable httpd systemctl start mariadb systemctl enable mariadb ``` ## Step 2 – Install Bareos By default, the Bareos is not available in the CentOS 8 default repository. You will need to download the Bareos repo from their official website. You can download it with the following command: ``` wget -O /etc/yum.repos.d/bareos.repo http://download.bareos.org/bareos/release/latest/CentOS_8/bareos.repo ``` Next, install the Bareos server by running the following command: ``` dnf install bareos bareos-database-mysql -y ``` Once all the packages are installed, start all Bareos services and enable them to start at boot with the following command: ``` systemctl start bareos-dir systemctl start bareos-sd systemctl start bareos-fd systemctl enable bareos-dir systemctl enable bareos-sd systemctl enable bareos-fd ``` ## Step 3 – Prepare Bareos Database Next, you will need to create a database and table for Bareos. First, create a database with the following command: ``` /usr/lib/bareos/scripts/create_bareos_database ``` You should get the following output: ``` Creating mysql database Creating of bareos database succeeded. ``` Next, create a database table with the following command: ``` /usr/lib/bareos/scripts/make_bareos_tables ``` You should get the following output: ``` Making mysql tables Creation of Bareos MySQL tables succeeded. ``` Next, grant all the privileges to the Bareos with the following command: ``` /usr/lib/bareos/scripts/grant_bareos_privileges ``` You should get the following output: ``` Granting mysql tables Privileges for user bareos granted ON database bareos. ``` ## Step 4 – Install Bareos Web UI First, you will need to install EPEL repo in your system. You can install it with the following command: ``` dnf install epel-release -y ``` Once installed, you can run the following command to install the Bareos WebUI. ``` dnf install bareos-webui -y ``` Once the installation is completed, restart the httpd and Bareos services with the following command: ``` systemctl restart httpd systemctl restart bareos-dir bareos-sd bareos-fd ``` Next, you will need to create an admin user and password for Bareos WebUI. To do so, login to Bareos console with the following command: ``` bconsole ``` You should get the following output: ``` Connecting to Director localhost:9101  Encryption: TLS_CHACHA20_POLY1305_SHA256 1000 OK: bareos-dir Version: 19.2.7 (16 April 2020) bareos.org build binary bareos.org binaries are UNSUPPORTED by bareos.com. Get official binaries and vendor support on https://www.bareos.com You are connected using the default console ``` ``` Enter a period (.) to cancel a command. ``` Next, run the following command to create an admin user and password: ``` configure add console name=admin password=admin123 profile=webui-admin ``` You should get the following output: ``` Created resource config file "/etc/bareos/bareos-dir.d/console/admin.conf": Console {   Name = admin   Password = admin123   Profile = webui-admin } ``` Next, exit from the Bareos console and edit the Bareos admin configuration file: ``` nano /etc/bareos/bareos-dir.d/console/admin.conf ``` Add the “TLS Enable = No” line as shown below: ``` Console { Name = admin Password = admin123 Profile = webui-admin TLS Enable = No } ``` Save and close the file, then restart the Bareos service with the following command: ``` systemctl restart bareos-dir bareos-sd bareos-fd ``` ## Step 5 – Access Bareos WEB UI Now, open your web browser and access the Bareos Web UI using the URL **http://your-server-ip/bareos-webui**. You will be redirected to the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/10/bareos1-1.png) Provide your admin username, password and click on the **Login** button. You should see the Bareos dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/10/Bareos3-1.png) Congratulations! You have successfully installed and configured Bareos backup application on CentOS 8. Now, you can add your first Bareos client and create a job for it to run on a regular basis – get started with Bareos on Atlantic.Net [VPS Hosting](https://www.atlantic.net/vps-hosting/) today! --- # How to Install Bludit CMS with NGINX on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-bludit-cms-with-nginx-on-ubuntu-20-04/ | Published: 2020-10-27 | Updated: 2024-06-02 | Author: Hitesh Jethva Bludit is a free, open-source, file-based content management system that helps you to host a blogging website within a minute. It is written in PHP and uses flat-files to store posts and pages. You don’t need to install any database system on your system to use Bludit. It is very similar to other content management systems including Drupal, Joomla, and WordPress, and offers a rich set of features including SEO friendliness, WYSIWYG support, a flexible CSS framework, and many more. In this tutorial, we will explain how to install and configure Bludit CMS on Ubuntu 20.04 server. ## Step 1 – Install LAMP Server First, you will need to install Nginx, PHP, and other required packages in your system. You can install all of them with the following command: ``` apt-get update -y apt-get install nginx php php-cli php-fpm php-common php-mbstring php-zip php-pgsql php-sqlite3 php-curl php-gd php-mysql php-intl php-json php-opcache php-xml unzip git curl -y ``` The above command will also install the Apache package in your system, but it is recommended that you remove it from your system. You can remove it using the following command: ``` apt-get remove apache2 --purge ``` Next, edit the php.ini file and make some desired changes: ``` nano /etc/php/7.4/fpm/php.ini ``` Change the following values: ``` memory_limit = 512M upload_max_filesize = 32M date.timezone = Asia/Kolkata ``` Save and close the file, then restart the PHP-FPM service to apply the changes: ``` systemctl restart php7.4-fpm ``` ## Step 2 – Install Bludit CMS First, you will need to download the latest version of Bludit from its official website. You can download it with the following command: ``` wget https://www.bludit.com/releases/bludit-3-13-1.zip ``` Once downloaded, unzip the downloaded file with the following command: ``` unzip bludit-3-13-1.zip ``` Next, move the extracted directory to the Nginx root directory: ``` mv bludit-3-13-1 /var/www/html/bludit ``` Next, change the ownership and provide necessary permissions to the bludit directory: ``` chown -R www-data:www-data /var/www/html/bludit chmod -R 775 /var/www/html/bludit ``` ## Step 3 – Configure Nginx for Bludit First, you will need to create an Nginx virtual host configuration file for Bludit. You can create it with the following command: ``` nano /etc/nginx/sites-available/bludit.conf ``` Add the following lines: ``` server { listen 80; server_name your-domain.com; root /var/www/html/bludit; index index.php; location ~ \.php$ { fastcgi_pass unix:/var/run/php/php7.4-fpm.sock; fastcgi_index index.php; include fastcgi.conf; } location / { try_files $uri $uri/ /index.php?$args; } location ^~ /bl-content/tmp/ { deny all; } location ^~ /bl-content/pages/ { deny all; } location ^~ /bl-content/databases/ { deny all; } } ``` Save and close the file, then activate the Nginx virtual host with the following command: ``` ln -s /etc/nginx/sites-available/bludit.conf /etc/nginx/sites-enabled/ ``` Next, verify the Nginx for any syntax errors with the following command: ``` nginx -t ``` You should get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the configuration changes: ``` systemctl restart nginx ``` ## Step 4 – Access Bludit Web Interface Now, open your web browser and access the Bludit CMS using the URL **http://your-domain.com**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/bludit1.png) Select your desired language and click on the **Next** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/bludit2.png) Set your admin password and click on the **Install** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/bludit3.png) Click on the **admin panel** button. You should see the Bludit login screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/bludit4.png) Provide your admin username, password and click on the **Login** button. You should see the Bludit dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/bludit5.png) ## Conclusion In the above guide, you learned how to install Bludit CMS on Ubuntu 20.04 server. You can now build your blogging website easily with Bludit dashboard on your [VPS Hosting](https://www.atlantic.net/vps-hosting/) account with Atlantic.Net. --- # Install Splunk Log Analyzer Tool on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/install-splunk-log-analyzer-tool-on-ubuntu-20-04/ | Published: 2020-10-27 | Updated: 2024-06-05 | Author: Hitesh Jethva Splunk is a powerful log analysis tool used for searching, monitoring, and analyzing machine-generated big data from a web browser. It helps you simplify log data from servers and networking devices into a simple format that you can easily read and digest. Splunk supports all major operating systems including Windows, Linux, and Mac OS. It is easily scalable, fully integrated, and supports both local and remote data sources. In this tutorial, we will show you how to install Splunk Log Analyzer Tool on Ubuntu 20.04. ## Step 1 – Install Splunk First, you must download Splunk onto the Ubuntu server. - Log in to the [Splunk](https://www.splunk.com/en_us/download/splunk-enterprise.html) website to download the latest version of Splunk package. - Click on the “Free Splunk” logo on their website. - Complete the brief registration form to create an account. - Once the download is complete, use your favorite FTP client to transfer the file to the server.![](https://www.atlantic.net/wp-content/uploads/2020/10/splunk.png) Note – If you are not sure how to use FTP, please visit either of these guides: - [FileZilla](https://www.atlantic.net/vps-hosting/how-to-upload-files-filezilla/) - or [Monsta FTP](https://www.atlantic.net/vps-hosting/upload-files-with-monsta-ftp/) Once the download is completed, install the downloaded file with the following command: ``` dpkg -i splunk-8.0.5-a1a6394cc5ae-linux-2.6-amd64.deb ``` Once the installation is completed, enable the Splunk service at system boot with the following command: ``` /opt/splunk/bin/splunk enable boot-start ``` You will need to accept the license agreement as shown below: ``` "Personnel" means any employee, consultant, contractor, or subcontractor of Splunk. "Splunk Preexisting IP" means, with respect to any C&I Services Materials, all associated Splunk Technology and all Intellectual Property Rights created or acquired: (a) prior to the date of the Statement of Work that includes such C&I Services Materials, or (b) after the date of such Statement of Work but independently of the C&I Services provided under such Statement of Work. "Statement of Work" means the statements of work and/or any all applicable Orders that describe the specific services to be performed by Splunk, including any materials and deliverables to be delivered by Splunk. SPLUNK GENERAL TERMS (v1.2020) Do you agree with this license? [y/n]: y ``` Type **y** and hit **Enter** to continue. You will be asked to create an administrative account and set a password as shown below: ``` This appears to be your first time running this version of Splunk. Splunk software must create an administrator account during startup. Otherwise, you cannot log in. Create credentials for the administrator account. Characters do not appear on the screen when you type in credentials. Please enter an administrator username: admin Password must contain at least: * 8 total printable ASCII character(s). Please enter a new password: Please confirm new password: ``` Type your admin username and password and hit **Enter**. You should see the following output: ``` Copying '/opt/splunk/etc/openldap/ldap.conf.default' to '/opt/splunk/etc/openldap/ldap.conf'. Generating RSA private key, 2048 bit long modulus .........+++++ ..+++++ e is 65537 (0x10001) writing RSA key Generating RSA private key, 2048 bit long modulus .+++++ ..................................................................................................................................................+++++ e is 65537 (0x10001) writing RSA key Moving '/opt/splunk/share/splunk/search_mrsparkle/modules.new' to '/opt/splunk/share/splunk/search_mrsparkle/modules'. Init script installed at /etc/init.d/splunk. Init script is configured to run at boot. ``` ## Step 2 – Start Splunk Service At this point, Splunk is installed in your system. Now, start the Splunk service with the following command: ``` service splunk start ``` You can verify the status of the Splunk service with the following command: ``` service splunk status ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/splunk1.png) At this point, Splunk is started and listening on port 8000. ## Step 3 – Access Splunk Web Interface Now, open your web browser and access the Splunk interface using the URL **http://your-server-ip:8000**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/splunk2.png) Provide your admin username and password and click on the **Sign** **In** button. You should see the Splunk dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/splunk3.png) ## Conclusion Congratulations! You have successfully installed Splunk on Ubuntu 20.04. Splunk is a very useful solution for log processing, collection, and analysis. Monitor your Linux environment with Splunk on your [VPS Hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net. --- # Rsync Command in Linux with Examples > URL: https://www.atlantic.net/vps-hosting/rsync-command-in-linux-with-examples/ | Published: 2020-10-28 | Updated: 2023-11-27 | Author: Hitesh Jethva rsync is a command-line utility for Unix-based operating systems that can be used to transfer and synchronize files and directories between multiple computers. It is an extraordinarily fast file copying tool that uses an algorithm to transfer only the portions of files that have changed. rsync is written in C and is a replacement for scp, sftp, and cp commands. rsync uses compression and decompression of data blocks, which will save your bandwidth compared to other file transfer protocols, like FTP. It also encrypts the data during the file transfer using SSH protocol. In this tutorial, we will show you how to use rsync command to transfer files and directories in Linux. ## Install rsync rsync comes pre-installed in most Linux operating systems. If not installed, you can install it with the following command: ``` apt-get update -y apt-get install rsync -y ``` Once installed, you can verify the version of rsync using the following command: ``` rsync --version ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/rsync1.png) ## Rsync Syntax The basic syntax of rsync command is shown below: ``` rsync [OPTION] [SOURCE] [DESTINATION] ``` rsync comes with a lot of options. A brief explanation of each option is shown below: **-a:** Used to sync directories recursively and preserve symbolic links, modification times, group, ownership, and permissions. **-r:** Used to sync directories recursively but does not keep ownership for users and groups, permissions, timestamps, or symbolic links. **-z:** Used to compress the data during the transfer. **-e:** Used to specify SSH protocol for remote transfers. **-h:** Used to print the numbers in the output in a human-readable format. **-b:** Used to take a backup during synchronization. ## 1. Copy a File Locally To copy a single file from one directory to another on the local system, use the following command: ``` rsync -v /etc/rsyslog.conf /mnt/ ``` This will copy a file named rsyslog.conf located in /etc to the /mnt directory: ![](https://www.atlantic.net/wp-content/uploads/2020/10/rsync2.png) To copy multiple files from one directory to another on the local system, use the following command: ``` rsync -v /etc/fstab /etc/passwd /mnt ``` This will copy files fstab and passwd to the /mnt directory: ``` rsync -v /etc/fstab /etc/passwd /mnt ``` ## 2. Copy a Directory Locally To copy a directory with all its contents to the other directory on the local system, use the following command: ``` rsync -av /etc/init.d /mnt ``` This will copy directory named init.d and all its contents to the /mnt directory: ![](https://www.atlantic.net/wp-content/uploads/2020/10/rsync4.png) ## 3. Copy Files and Directories from the Local to the Remote System With rsync, you can also copy or sync files and directories from the local to the remote system. For example, to copy the directory /etc on the local system to the remote system (192.168.0.102) under the /mnt directory, run the following command: ``` rsync -zarvh /etc/init.d/ root@192.168.0.102:/mnt/ ``` You will be asked to provide the root password of remote system: ![](https://www.atlantic.net/wp-content/uploads/2020/10/rsync5.png) ## 4. Copy Files and Directories from the Remote to the Local System If you want to copy the directory /etc/rcS.d from the remote system (192.168.0.102) to the local system inside /opt directory, run the following command: ``` rsync -zarvh root@192.168.0.102:/etc/rcS.d /opt/ ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/10/rsync6.png) ## 5. Display Synchronization Progress During Transfer You can also display the file transfer progress using the option –progress. You can run the following command to display the progress bar: ``` rsync -avh --progress root@192.168.0.102:/etc/apache2 /opt/ ``` ## 6. Limit Bandwidth During Transfer You can also set the bandwidth limit for data transfer using the option –bwlimit. For example, set the bandwidth limit to 500 KB/s during file transfer using the following command: ``` rsync -avz --progress --bwlimit=500 /root/ubuntu-20.04-live-server-amd64.iso root@192.168.0.102:/mnt/ ``` ## 7. Include and Exclude Files During Transfer In some cases, you want to include or exclude only specific file types during the transfer. In this case, you can use –include and –exclude option. ``` rsync -avz --include '*.php' --exclude *.png /var/www/html/wordpress /opt/ ``` This will copy only PHP files and exclude PNG files from /var/www/html/wordpress to /opt directory. ## Conclusion In the above guide, you learned how to use rsync command to transfer files from one system to another. You also learned how to use different options with rsync command. You can now easily use the rsync command to perform backup tasks; try using rsync on your [VPS Hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net! --- # SaaS, Cloud, or Any Business – When Profitability Matters! > URL: https://www.atlantic.net/vps-hosting/saas-cloud-or-any-business-when-profitability-matters/ | Published: 2020-11-02 | Updated: 2024-11-14 | Author: Hitesh Jethva Atlantic.Net was founded in 1994 with no Venture Capital backing or Wall Street funding. 25 years ago, what mattered most to our founders was how to grow the business organically and simultaneously develop profitability, and always offer the latest technology to our wonderful customers. This approach still holds true today, now that Atlantic.Net has become a leading global cloud provider with clients in hundreds of countries, being served from eight global data centers, we will always remember our humble beginnings back in 1994 as an internet service provider. ## How Atlantic.Net Has Stayed Independent and Profitable Running a profitable business with little to no debt, staying ahead of the technology curve, and most importantly, being able to bill our customers accurately are some of the top reasons behind our continued success. Credit goes to Marty Puranik, our CEO, who has consistently shown real strength to make his vision become true. ### Atlantic.Net’s Beginnings Marty dropped out of the University of Florida to start his own internet company in neighboring Gainesville, Florida. The University was at that time proactively blocking student access to the internet from their halls of residence. It might seem inconceivable that today a University would have this kind of stance towards Internet access. However, this decision kickstarted Marty on his journey to becoming a successful dot-com entrepreneur, rapidly building an Internet Service Provider company with 2000 customers and eight employees in the first 12 months. ICC Computers, as it was known at the time, launched commercial internet services in 1995, and had expanded into Tampa and Orlando before the end of 1996. ### Growth of Atlantic.Net’s Services & the Dot-Com Bubble The business continued to grow at pace, introducing services into Mississippi, Louisiana, Georgia, and Alabama before going national in 2000 with dial-up and DSL services. At one point, Atlantic.Net was the largest independent internet service provider in the South East and most of the national brands were providing access to their clients by using the Atlantic.Net network. This all took place during the height of the Dot-Com bubble, global investors were lavishly keen to spend on technology companies. Between 1995 and 2000, the Nasdaq stock market index rose by 400%. Sadly, when the bubble started to burst between 2000-2001, many dotcom businesses went under. Investors became extremely cautious, trust in the industry was waning after Microsoft was found [guilty in a landmark antitrust case in 2001](https://www.justice.gov/atr/us-v-microsoft-courts-findings-fact), and the tragic events of 9/11 accelerated the rapid decline. Even Atlantic.Net, as a privately owned company, was not immune to the crisis. Consumer confidence was at an all-time low, but Marty never gave up and showed strength and persistence. ### Into the Modern Era Atlantic.Net survived the DotCom crash thanks to some tough decision making, Marty took a major pay cut and he made many other sacrifices. Today, COVID-19 is threatening an even bigger economic downturn, but this time it is different. Even though our economy is facing a difficult future, a bubble bigger than Dot-Com, Atlantic.Net is in a unique position to grow stronger, as we realize the digital transformation goals of our clients. This is all because of Marty’s leadership and vision. From its inception in 1994 until 2002, Atlantic.Net became one of Florida’s largest privately-owned Internet Service Providers, providing Internet access to consumers in cities and small towns throughout Florida and the southeastern United States.  Atlantic.Net acquired 16 Internet companies in those nine years, doubling and tripling revenues annually. As legislation made it more difficult for a small business like Atlantic.Net to exist as an ISP, from 2002 Atlantic.Net entered the Data Center Services business and we have never looked back. ## “Weathering the Storm” Atlantic.Net knows how to weather a storm.  For 25 years the company has remained profitable despite the dot.com bust, a strategic redirection, and the current economic downturn caused by COVID-19. How have we achieved this?  By helping local, regional and global businesses remain up and running through computer outages, failed Internet connections, and, well, bad weather. The core business principals that helped to build the business are still incredibly important today. Customer satisfaction, security, and technical mastery are some of the foundations that the business was built upon, and today these foundations keep the business driving forward and capable of absorbing the next misfortune to face the industry. ## Business Accomplishments In addition to growing organically, Atlantic.Net acquired 16 Internet companies from 1994-2002, doubling, and tripling revenues annually.  In 1998 Atlantic.Net was named in the *Florida Council of 100*, a non-profit organization of Florida business leaders that recognizes the state’s fastest-growing private companies. Between 1998 and 2002, Atlantic.Net made the *Inc 500* list for four consecutive years. This was an incredible achievement to be named in the top 500 US privately-held businesses. During the past 20 years, fewer than 6 percent of the winners have been named to the list three times. Atlantic.Net is one of only 31 Florida-based companies to make the Inc 500 and was the state’s only Internet service provider to be honored. ### How Ubersmith Has Helped The business continues to grow even during the current economic down-turn and biggest pandemic in a century, and this is thanks to our solid partnership with Ubersmith. One thing we have always understood since the business was founded is that you can only grow if you can bill your customers accurately and efficiently. Our confidence in Ubersmith has been unwavering in the 25 years we have been in business. They are champions at what they do, and we are delighted to have partnered up with them to help us grow, and most importantly handle our complex billing transactions between hundreds of countries with a growing diverse set of services and solutions. ### Recent Recognition More recently, Atlantic.Net won two awards at the 2020 Stevies, we were awarded the *Gold Stevie Winner* for Healthcare Technology and the *Silver Stevie Winner* for Cloud Platform.  Our world-class [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions and [VPS Cloud Hosting](https://www.atlantic.net/vps-hosting/) Platforms won us these awards. Ubersmith billings underpin these platforms, another example of our great partnership. Atlantic.Net was recognized as a leading cloud services provider in Gartner’s 2019 Market Guide for Cloud Service Providers to Healthcare Delivery Organizations, and this was for the second time! the first time was in 2017. Our inclusion inside a highly recognized, leading research and advisory company publication was down to an exceptional job done by our technical teams. Our other reward highlights include being in the [CRN MSP Top 500](http://assets.cdnma.com/8247/assets/2015_SP_Lists/2015%20MSP500%20PDF.pdf) of 2015 and then making it into the CRN Tech Elite Top 250 in 2019. The Medtech Breakthrough award wins in 2018 and 2019 are also treasured by the team as it validates our Medical IoT platforms. ## Why Choose Atlantic.Net? Today, Atlantic.Net is a leading managed services provider, with a strong presence in cloud compliance, and [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/). From meeting the strictest security, privacy, and compliance requirements to ensuring a robust and scalable hosting environment, our hosting solutions are designed to help bring focus to your core business and applications. Our Compliance Hosting solutions are a perfect fit for financial services and healthcare organizations that require the most robust security levels for their data. Certified and audited by third party independent auditors, Atlantic.Net Compliance Hosting Solutions fulfill HIPAA, HITECH, PCI, or SOC requirements. ## Why Choose Ubersmith? Accurate billing is a cornerstone of building a successful data center services business. It might sound simple to just bill your customer, but in reality, it is an extremely complex task to undertake, especially for a company like Atlantic.Net who manages ten of thousands of customers globally. What makes cloud computing so popular is the flexibility of costs, Ubersmith empowers Atlantic.Net to bill accurately for the compute, network, and storage usage of our customers. Ubersmith creates fast, accurate, and automated billing down at a finite level. It is easy to apply our pay-as-you-go model costings, or automatically assign one or three-year discount offerings. Our customers benefit because they can predict the recurring billing costs and can pay with a large number of payment options. We highly recommend Ubersmith and no matter what business you are running, make sure you are billing your customers! --- # Setup Personal Audio Streaming Server with Koel on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/setup-personal-audio-streaming-server-with-koel-on-ubuntu-20-04/ | Published: 2020-11-03 | Updated: 2024-06-05 | Author: Hitesh Jethva Koel is a simple, free, open-source, web-based personal audio streaming server written in PHP and JavaScript. It uses Laravel on the server-side and Vue on the client-side. Koel allows you to stream your music and access it from anywhere through the Internet. It supports many media formats, including AAC, OGG, WMA, FLAC and APE, and it can stream music over HTTP / HTTPS. In this tutorial, we will explain how to install Koel Audio Streaming server on Ubuntu 20.04. ## Step 1 – Install Required Dependencies First, you will need to install some dependencies required for Koel. You can install all of them with the following command: ``` apt-get update -y apt-get install git unzip curl build-essential libpng-dev gcc make ffmpeg -y ``` Once all the dependencies are installed, you can proceed to the next step. ## Step 2 – Install LEMP Server Next, you will need to install Nginx, MariaDB, PHP, and other PHP extensions in your system. You can install all of them with the following command: ``` apt-get install nginx mariadb-server php php-cli php-fpm php-json php-common php-mysql php-zip php-gd php-mbstring php-curl php-xml php-pear php-bcmath php-tokenizer openssl php-json -y ``` **Note**: If you get an error when Apache2 automatically starts – see this [procedure](https://askubuntu.com/questions/256013/apache-error-could-not-reliably-determine-the-servers-fully-qualified-domain-n). After installing the above packages, Apache package will be installed automatically with PHP. Here, we will use Nginx web server so remove the Apache package with the following command: ``` systemctl stop apache2 apt-get purge apache2 -y ``` Next, edit the php.ini file and tweak some desired settings: ``` nano /etc/php/7.4/fpm/php.ini ``` Change the following lines: ``` memory_limit = 512M date.timezone = Asia/Kolkata ``` Save and close the file when you are finished. ## Step 3 – Install Composer Composer is a dependency manager used for managing PHP dependencies. You can install it with the following command: ``` curl -sS https://getcomposer.org/installer -o composer-setup.php php composer-setup.php --install-dir=/usr/local/bin --filename=composer ``` You should get the following output: ``` All settings correct for using Composer Downloading... Composer (version 1.10.10) successfully installed to: /usr/local/bin/composer Use it: php /usr/local/bin/composer ``` Next, verify the installed version of Composer using the following command: ``` composer -V ``` You should get the following output: ``` Composer version 1.10.10 2020-08-03 11:35:19 ``` ## Step 4 – Create a Database for Koel Next, you will need to create a database and user for Koel. First, log in to MariaDB with the following command: ``` mysql ``` Once logged in, create a database and user with the following command: ``` CREATE DATABASE koeldb; CREATE USER 'koeluser'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the Koel database with the following command: ``` GRANT ALL PRIVILEGES ON koeldb.* TO 'koeluser'@'localhost'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 5 – Install Node.js First, install the necessary dependencies using the following command. ``` apt-get install -y ca-certificates curl gnupg ``` Next, download the Node.js GPG key. ``` mkdir -p /etc/apt/keyrings curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg ``` Next, add the NodeSource repo to the APT source list. ``` echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_18.x nodistro main" | tee /etc/apt/sources.list.d/nodesource.list ``` Then, update the repository index and install the Ndoe.js with the following command. ``` apt update apt-get install -y nodejs ``` Additionally, you will also need to import the Yarn repository with the following command: ``` curl -sS https://dl.yarnpkg.com/debian/pubkey.gpg | gpg --dearmor -o /usr/share/keyrings/yarn-archive-keyring.gpg ``` Next, create a new file in the /etc/apt/sources.list.d/ directory to store the Yarn repository information: ``` echo "deb [signed-by=/usr/share/keyrings/yarn-archive-keyring.gpg] https://dl.yarnpkg.com/debian/ stable main" | sudo tee /etc/apt/sources.list.d/yarn.list ``` Finally, update the repository and install Yarn using the following command. ``` apt update -y apt install yarn -y ``` ## Step 6 – Install Koel First, change the directory to the Nginx root directory and install Laravel dependencies using the following command: ``` cd /var/www/html composer global require laravel/installer ``` Next, download the latest version of Koel with the following command: ``` git clone https://github.com/koel/koel.git --recursive ``` Once downloaded, change the directory to Koel and install Node dependencies with the following command: ``` cd koel npm install npm audit fix npm audit fix --force ``` Finally, install PHP dependencies using the following command: ``` composer install ``` Next, edit the .env file and define your database and other settings: ``` nano .env ``` Change the following lines: ``` DB_CONNECTION=mysql DB_HOST=127.0.0.1 DB_PORT=3306 DB_DATABASE=koeldb DB_USERNAME=koeluser DB_PASSWORD=password ADMIN_NAME="admin" ADMIN_EMAIL=admin@example.com ADMIN_PASSWORD=adminpassword MEMORY_LIMIT=512 FFMPEG_PATH=/usr/bin/ffmpeg ``` Save and close the file, then initialize the database with the following command: ``` php artisan koel:init --no-interaction ``` You should get the following output: ``` Done in 156.20s. 🎆 Success! Koel can now be run from localhost with `php artisan serve`. Again, visit 📙 https://docs.koel.dev for the official documentation. Feeling generous and want to support Koel's development? Check out https://github.com/users/phanan/sponsorship 🤗 Thanks for using Koel. You rock! 🤘 ``` Next, initialize the database again with the following command: ``` php artisan koel:init ``` You should see the following output: ``` Attempting to install or upgrade Koel. Remember, you can always install/upgrade manually following the guide here: 📙 https://docs.koel.dev Generating app key JWT secret exists -- skipping Migrating database Data seeded -- skipping The absolute path to your media directory. If this is skipped (left blank) now, you can set it later via the web interface. Media path []: > Now to front-end stuff ├── Installing Node modules in resources/assets directory ``` Next, create a logs directory and provide necessary permissions and ownership with the following command: ``` mkdir /var/www/html/koel/storage/logs chown -R www-data:www-data /var/www/html/koel chmod -R 755 /var/www/html/koel ``` ## Step 7 – Configure Nginx for Koel Now, create a Nginx virtual host configuration file to serve Koel. ``` nano /etc/nginx/sites-available/koel.conf ``` Add the following lines: ``` server { listen 80 default_server; server_name koel.example.com; root /var/www/html/koel; index index.html index.htm index.php; location / { try_files $uri /index.php$is_args$args; } location ~ \.php$ { fastcgi_pass unix:/run/php/php7.4-fpm.sock; fastcgi_index index.php; fastcgi_read_timeout 240; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; fastcgi_split_path_info ^(.+.php)(/.+)$; } } ``` Save and close the file, then activate the Nginx virtual host file with the following command: ``` ln -s /etc/nginx/sites-available/koel.conf /etc/nginx/sites-enabled/ ``` Next, restart the Nginx and PHP-FPM services to apply the changes: ``` systemctl restart nginx systemctl restart php7.4-fpm ``` ## Step 8 – Access Koel Web UI Now, open your web browser and access the Koel UI using the URL http://koel.example.com. You will be redirected to the Koel login page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/koel1.png) Provide your admin email and password which you have set in .env file, then click on the **Log** **In** button. You should see the Koel default dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/koel2.png) ## Conclusion Congratulations! You have successfully installed and configured a Koel audio streaming server on Ubuntu 20.04. Now, you can host your own music streaming server and access it over the Internet. Try Koel on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net using the tutorial above! --- # Install and Set Up Grafana Monitoring Dashboards with Telegraf and InfluxDB Backend on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/install-and-set-up-grafana-monitoring-dashboards-with-telegraf-and-influxdb-backend-on-ubuntu-20-04/ | Published: 2020-11-04 | Updated: 2024-06-06 | Author: Hitesh Jethva A TIG stack is a collection of open-source tools including Telegraf, InfluxDB, and Grafana. It is one of the most popular tools for montoring a wide panel of data sources. Telegraf is a server agent used for collecting and aggregating data and reporting metrics. It is highly scalable and allows users to access metrics from the system. Grafana is an open-source data visualization tool that supports various time series datastores including Prometheus, Elasticsearch, and InfluxDB. InfluxDB is an open-source database used to store data and expose it to the Grafana dashboard. It can automate sensors and devices in real-time. In this tutorial, we will learn how to install the TIG stack on Ubuntu 20.04 server. ## Step 1 – Install Telegraf First, you will need to install Telegraf in your system. By default, Telegraf is not available in the Ubuntu 20.04 standard repository, so you will need to add the InfluxData repo to your system. First, install the required dependencies using the following command: ``` apt-get install gnupg2 software-properties-common -y ``` Next, import the GPG key with the following command: ``` wget -qO- https://repos.influxdata.com/influxdb.key | apt-key add - ``` Next, activate the lsb-release and add the InfluxData repository with the following command: ``` source /etc/lsb-release echo "deb https://repos.influxdata.com/${DISTRIB_ID,,} ${DISTRIB_CODENAME} stable" | tee /etc/apt/sources.list.d/influxdb.list ``` Next, update the repository and install Telegraf with the following command: ``` apt-get update -y apt-get install telegraf ``` Once the installation is completed, start and enable the Telegraf service with the following command: ``` systemctl enable --now telegraf systemctl start telegraf ``` Next, verify the status of Telegraf using the following command: ``` systemctl status telegraf ``` You should get the following output: - ``` telegraf.service - The plugin-driven server agent for reporting metrics into InfluxDB Loaded: loaded (/lib/systemd/system/telegraf.service; enabled; vendor preset: enabled) Active: active (running) since Sat 2020-10-10 09:46:53 UTC; 23s ago Docs: https://github.com/influxdata/telegraf Main PID: 105155 (telegraf) Tasks: 8 (limit: 4691) Memory: 17.4M CGroup: /system.slice/telegraf.service └─105155 /usr/bin/telegraf -config /etc/telegraf/telegraf.conf -config-directory /etc/telegraf/telegraf.d 105155]: 2020-10-10T09:46:53Z I! Loaded outputs: influxdb ``` ## Step 2 – Install InfluxDB We have added the InfluxData repo in the previous step, so you can install InfluxDB by just running the following command: ``` apt-get install influxdb -y ``` Once InfluxDB has been installed, start the InfluxDB service and enable it to start at system reboot with the following command: ``` systemctl enable --now influxdb systemctl start influxdb ``` Next, verify the status of the InfluxDB service using the following command: ``` systemctl status influxdb ``` You should get the following output: - ``` influxdb.service - InfluxDB is an open-source, distributed, time series database Loaded: loaded (/lib/systemd/system/influxdb.service; enabled; vendor preset: enabled) Active: active (running) since Sat 2020-10-10 09:48:22 UTC; 13s ago Docs: https://docs.influxdata.com/influxdb/ Main PID: 105724 (influxd) Tasks: 10 (limit: 4691) Memory: 10.3M CGroup: /system.slice/influxdb.service └─105724 /usr/bin/influxd -config /etc/influxdb/influxdb.conf ``` ## Step 3 – Install Grafana By default, the latest version of Grafana is not available in the Ubuntu 20.04 server, so you will need to add the Grafana repository to your system. First, import the Grafana key with the following command: ``` wget -q -O - https://packages.grafana.com/gpg.key | apt-key add - ``` Next, add the Grafana repository with the following command: ``` add-apt-repository "deb https://packages.grafana.com/oss/deb stable main" ``` Once the repository is added, update the repository and install the latest version of Grafana using the following command: ``` apt-get update -y apt-get install grafana -y ``` Once Grafana has been installed, reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the Grafana service and enable it to start at system reboot with the following command: ``` systemctl enable --now grafana-server systemctl start grafana-server ``` Next, verify the status of the Grafana service with the following command: ``` systemctl status grafana-server ``` You should get the following output: - ``` grafana-server.service - Grafana instance Loaded: loaded (/lib/systemd/system/grafana-server.service; enabled; vendor preset: enabled) Active: active (running) since Sat 2020-10-10 09:50:26 UTC; 44s ago Docs: http://docs.grafana.org Main PID: 106788 (grafana-server) Tasks: 8 (limit: 4691) Memory: 19.4M CGroup: /system.slice/grafana-server.service └─106788 /usr/sbin/grafana-server --config=/etc/grafana/grafana.ini -- pidfile=/var/run/grafana/grafana-server.pid --packaging=deb> ``` ## Step 4 – Configure InfluxDB Next, you will need to configure the InfluxDB database to store the metrics collected by Telegraf agent. First, connect the InfluxDB with the following command: ``` influx ``` You should get the following output: ``` Connected to http://localhost:8086 version 1.8.3 InfluxDB shell version: 1.8.3 ``` Next, create a database and user with the following command: ``` > create database telegrafdb > create user telegraf with password 'password' > grant all on telegrafdb to telegraf ``` Next, verify the database using the following command: ``` > show databases ``` You should get the following output: ``` name: databases name ---- telegraf _internal telegrafdb ``` Next, verify the users by using the following command: ``` > show users ``` You should get the following output: ``` user admin ---- ----- telegraf false ``` Next, exit from the InfluxDB console with the following command: ``` >exit ``` ## Step 5 – Configure Telegraf Agent to Collect System Metrics Next, you will need to configure the Telegraf agent to collect system metrics. Here, we will configure the Telegraf agent to collect system metrics including memory usage, system processes, disk usage, system load, system uptime, and logged in users. You can generate a custom Telegraf configuration file with the following command: ``` telegraf config -input-filter cpu:mem:swap:system:processes:disk -output-filter influxdb > /etc/telegraf/telegraf.conf ``` Once the configuration file is generated, edit the configuration file: ``` nano /etc/telegraf/telegraf.conf ``` Define your InfluxDB database details: ``` [[outputs.influxdb]] urls = ["http://127.0.0.1:8086"] database = "telegrafdb" username = "telegraf" password = "password" ``` Save and close the file, then restart the Telegraf service to apply the configuration changes: ``` systemctl restart telegraf ``` Next, you will need to verify whether the data appears or not. You can run the configuration test using the following command: ``` telegraf --config /etc/telegraf/telegraf.conf --test ``` If everything is correct, you should see the following output: ``` 2020-10-10T09:57:58Z I! Starting Telegraf 1.15.3 > mem,host=ubuntu2004 active=1144344576i,available=3518758912i,available_percent=85.25516847152974,buffered=164 536320i,cached=2911133696i,commit_limit=2559074304i,committed_as=1576108032i,dirty=6144 0i,free=731619328i,high_free=0i,high_total=0i,huge_page_size=2097152i,huge_pages_free=0i,hug e_pages_total=0i,inactive=1903452160i,low_free=0i,low_total=0i,mapped=218427392i,page_table s=3502080i,shared=651264i,slab=326660096i,sreclaimable=277262336i,sunreclaim=49397760i,sw ap_cached=24576i,swap_free=495136768i,swap_total=495411200i,total=4127326208i,used=3200 36864i,used_percent=7.754096668677951,vmalloc_chunk=0i,vmalloc_total=35184372087808i,vm alloc_used=6316032i,write_back=0i,write_back_tmp=0i 1602323878000000000 > system,host=ubuntu2004 load1=0,load15=0.05,load5=0.08,n_cpus=2i,n_users=4i 1602323878000000000 > disk,device=sda1,fstype=ext4,host=ubuntu2004,mode=rw,path=/ free=95962320896i,inodes_free=6365813i,inodes_total=6553600i,inodes_used=187787i,total=105 619841024i,used=5238685696i,used_percent=5.176515404753021 1602323878000000000 > diskio,host=ubuntu2004,name=sda1 io_time=351028i,iops_in_progress=0i,merged_reads=2995i,merged_writes=420522i,read_bytes=5 23574272i,read_time=3572i,reads=11978i,weighted_io_time=287724i,write_bytes=13355402240i, write_time=574952i,writes=587911i 1602323878000000000 > diskio,host=ubuntu2004,name=sda io_time=353848i,iops_in_progress=0i,merged_reads=2995i,merged_writes=420522i,read_bytes=5 25794304i,read_time=3581i,reads=12094i,weighted_io_time=288784i,write_bytes=13355402240i, write_time=593845i,writes=641651i 1602323878000000000 > kernel,host=ubuntu2004 boot_time=1602216148i,context_switches=13167299i,entropy_avail=2803i,interrupts=8104602i,pr ocesses_forked=107054i 1602323878000000000 > system,host=ubuntu2004 uptime=107730i 1602323878000000000 > system,host=ubuntu2004 uptime_format="1 day, 5:55" 1602323878000000000 ``` ## Step 6 – Setup Grafana Data Source Next, you will need to access the Grafana dashboard and add a data source to display the InfluxDB and Telegraf metrics. You can access the Grafana Dashboard using the URL **http://your-server-ip:3000**/. You should see the Grafana login page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/grafana1.png) Provide default username as admin and password as admin then click on the **login** button. You should see the password reset screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/grafana2.png) Note: Since Grafana version 7.2.2, many users have reported the default *admin* and *password* does not work. If this is the case, type the following on your server command prompt: ``` grafana-cli admin reset-admin-password mynewpassword ``` Provide your new password and click on the **Submit** button to change the default password. You should see the Grafana dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/grafana3.png) To add the data source, click on the **Add your first data source**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/grafana4.png) Search for **InfluxDB** and click on the **Select** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/grafana5.png) ![](https://www.atlantic.net/wp-content/uploads/2020/11/graphana7.png) Set the name of the **InfluxDB**, select **InfluxQL** in Query Language, define the URL of the InfluxDB data source, provide InfluxDB database details, and click on the **Save & Test** button. Once the test is successful, you should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/grafana9.png) ## Step 7 – Setup Grafana Dashboard At this point, we have added InfluxDB as a data source to the Grafana server. Next, you will need to import the Grafana dashboard. On the Grafana Dashboard, click on the **‘+’** menu on the left panel and click the ‘**Import**‘ button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/grafana10.png) ![](https://www.atlantic.net/wp-content/uploads/2020/11/grafana11.png) Type Grafana ID **5955** and click on the **Load** button to load the dashboard as shown below. ![](https://www.atlantic.net/wp-content/uploads/2020/11/grafana12.png) Select InfluxDB and click on the **Import** button. You should see the Grafana Dashboard showing the system metrics collected by the Telegraf agent: ![](https://www.atlantic.net/wp-content/uploads/2020/11/grafana13.png) ## Conclusion Congratulations! You have successfully installed and configured a TIG stack on Ubuntu 20.04 server. You can now explore the Dashboard and start monitoring your server using the TIG stack. Try it on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # Best Practices for Creating a HIPAA-Compliant cPanel Host > URL: https://www.atlantic.net/hipaa-compliant-hosting/best-practices-for-creating-a-hipaa-compliant-cpanel-host/ | Published: 2020-11-05 | Updated: 2025-07-26 | Author: Richard Bailey cPanel, one of the most popular Linux-based control panels, simplifies website and server management. This powerful application offers a user-friendly and intuitive platform to create multiple, detailed, and highly secure websites. cPanel is very popular with developers and web designers who are not completely comfortable using the Linux Shell command line. cPanel allows simplified management of files, databases, domains, email, metrics, security,  and software, and because there is so much available in cPanel, extra care must be taken to ensure the platform remains HIPAA-Compliant. ## cPanel Hosting Your choice of host for cPanel is the most important part of meeting the required administrative, technical, and physical safeguards of HIPAA compliance. The chosen infrastructure must meet and exceed the minimum required elements of HIPAA. Atlantic.Net has been supporting US healthcare organizations for decades, and we specialize in both [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and cPanel. ##### Did you know? ###### Atlantic.Net is HIPAA Audited for our hosting solutions and data centers. Our support, management and business processes are fully compliant to HIPAA standards and we are the best choice for your healthcare hosting needs To ensure HIPAA compliance  your hosting must have: - Fully Managed Firewall - Intrusion Prevention Service - Encrypted VPN, Backups, and Storage - Offsite Backups - Multi Factor Authentication - Business Associate Agreement - Vulnerability Scans - File Integrity Monitoring - Anti-Malware Protection - Log Management System - High Availability Networking ## Securing cPanel - Secure Apache – cPanel and WHM include the ModSecurity tool that prevents unauthorized Apache scripts from being executed - Secure PHP – The suPHP module forces PHP scripts to run as the script owner, denying unauthorized scripts from being executed - Secure SSH – changing the port used by SSH is a great way to harden your server. SSH is usually port 22, but you can modify it in /etc/ssh/sshd_config - Secure passwords – It may sound like common sense, but use long and complex passwords and make sure you use different passwords throughout cPanel ##### Did you know? ###### The /etc/login.defs file on a Linux server can be used to enforce a strict password policy. - Harden the tmp partition – cPanel advises separating the /tmp partition and mounting it with the nosuid option. This forces the OS to access /tmp with user-based permissions - Restrict the system compilers – C and C++ compilers can be used to execute malicious code, so it is best practice to limit these permissions only to users in the compilers group in /etc/group/ - Disable unused services and daemons - Restrict your filesystem permissions – locking down file and folder permissions is fundamental to securing the server ##### Did you know? ###### Atlantic.Net is fully SOC audited, we are compliant to AICPA SOC service organization control reporting. These standards ensure our information management and network technology assurance adheres to AICPA best practice and ethical standards. - Control access to service by IP address – Access can be controlled at the firewall, but also by WHM’s Host Access Control interface. Here you can create granular controls to most cPanel services - Stay up-to-date – updating cPanel, the operating system, and all the installed applications is necessary to limit the attack surface of your cPanel server. This process can be automated for simplicity - Enable cPanel logging – there is a hidden logging feature to cPanel which should be enabled; this will give you cPanel access and server access logs ##### Did you know? ###### You can monitor and alert on what users login to their cPanel account. To do so, type: ``` grep "login=1&post_login=" /usr/local/cpanel/logs/access_log | awk '{print $1" : "$3" : "$4}' ``` - Suspend email in cPanel – There are strict rules in HIPAA regarding encrypting and securing email communications. It is recommended to disable the email features of cPanel: cpanel>home>email>emailaccounts ## Securing Apache cPanel uses Apache as a web server by default. Users can change this or use another Web Server such as Nginx, but the principle of securing the webserver is still the same. - Keep Apache up-to-date - Configure Apache to increase DDOS (denial of service) protection level ##### Did you know? ###### Editing the httpd.conf file and reducing the RequestReadTimeout, Timeout, KeepAliveTimeout, and MaxRequestWorkers thresholds will greatly improve DDOS protection. - Set strict chown, chmod, and chggrp permissions on ServerRoot Directories; this will reduce the ability of a hacker to run arbitrary code - Enforce TLS certificate encryption using mod_ssl, ensuring you use a strong cipher suite and OCSP stapling - Implement dynamic content security ##### Did you know? ###### The Apache module mod_security can be finely tuned as an HTTP firewall, perfect for dynamic content security. - Protect system settings with .htaccess restrictions - Protect access to service files ##### Did you know? ###### To enable this protection, add this to your httpd.conf: ``` AllowOverride None Require all denied ``` ## Secure Your Database cPanel is heavily reliant on a MySQL database for cPanel configuration and for content delivery on websites. - Invoke MySQL Enterprise Data Masking and De-identification routines ##### Did you know? ###### A server-side plugin called data_masking can manage a SQL-Level API to perform masking and de-identification tasks on your data when it is used by an application. - Data must be encrypted at rest ##### Did you know? ###### Atlantic.Net’s Cloud Platform is encrypted at rest with every server deployed by default. - Enable SELinux for mandatory access controls to protect the MySQL daemon - Implement MySQL plugins to authenticate users and restrict access by user, password, and approved IP address - Enable MySQL Enterprise Audit plugin to enable standard, policy-based monitoring and logging of connections and query activity executed on the MySQL DB ##### Did you know? ###### Atlantic.Net always recommends customers encrypt their Operating Systems and Databases, even though we take the extra step of encrypting data at rest. ## Secure PHP In cPanel, PHP can either run as an Apache plugin or as a standalone CGI binary. No HIPAA legislation relates directly to PHP; instead, PHP must adhere to access and transmission security: - Ensure PHP is kept up-to-date - Use PHP to hash and verify all passwords entered by users; BCrypt is included with PHP 7 onwards ##### Did you know? ###### Passwords can be hashed using the password_hash PHP function. - Use PHP to protect against cross-site scripting (XSS) and Request Forgery XSFR ##### Did you know? ###### Atlantic.Net is audited and compliant to the HITECH standards for privacy and security of confidential Electronic Health Record (EHR) data. This certification ensures we are the best choice for your healthcare hosting and data confidentiality requirements. ## Ready to find out more? Atlantic.Net stands ready to help you attain fast compliance with a range of certifications, such as SOC 2 and SOC 3, HIPAA, and HITECH, all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, [contact us today](https://www.atlantic.net/about-us/corporate-contact/), call 866-618-DATA (3282), or email us at sales@atlantic.net. --- # BAA vs BASA: What Is the Difference Between a BAA and BASA? > URL: https://www.atlantic.net/hipaa-compliant-hosting/baa-vs-basa-what-is-the-difference-between-a-baa-and-basa/ | Published: 2020-11-06 | Updated: 2025-09-19 | Author: Richard Bailey You may be surprised to learn that there are two types of business associate agreements related to HIPAA compliance. Most healthcare professionals will already know what a BAA consists of, but did you know that there is also a Business Associate Subcontractor Agreement? ## BAA vs. BASA Comparison Both agreements are a vital part of HIPAA compliance, forming the basis of the contractual agreements between a covered entity and a business associate. Here is a breakdown of the two types of business associate relationships: - **BAA:** Business Associate Agreement between a Covered Entity and a Business Associate - **BASA:** Business Associate Subcontractor Agreement between a Business Associate and a subcontractor While each agreement synergizes with the other and they share much in common, the key factor is that the *Business Associate*that has the subcontractor relationship, not the covered entity. A BASA is needed if the Business Associate outsources part of a service to another company or service provider. ### Example BAA/BASA Scenario To demonstrate, consider system backups that contain Protected Health Information; on occasion, there might be a requirement to archive PHI insurance data to an external data warehouse, perhaps on tape or in the cloud. The business associate may choose to outsource this responsibility to a subcontractor. The Covered Entity must be made aware of the details of such an arrangement, but it is the Business Associate that maintains the relationship with the subcontractor. The BASA makes the subcontractor liable for the safeguarding of PHI as per the rules of HIPAA compliance, the BAA, and the BASA. Both agreements outline the shared responsibilities between the Covered Entity and the Business Associate or the Business Associate and the Subcontractor. ## [What Is a BAA?](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) To recap, the requirement to hold a [Business Associate Agreement](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) was introduced in 2003 as part of the HIPAA Privacy Rule amendments. A Covered Entity (CE) is considered to be any healthcare provider, health plan provider, or clearinghouse. A Business Associate is someone that handles or processes PHI on behalf of the covered entity. Atlantic.Net is a business associate, as we provide HIPAA Compliant hosting services to the healthcare industry. Covered Entities may use our service to process and transmit protected health information. We sign a BAA with each of our healthcare clients to document our responsibilities and the guarantees we adhere to when handling PHI. Atlantic.Net’s BAA offers assurances regarding our HIPAA and HITECH accreditations and details the guarantees we provide for each of the administrative, physical, and technical safeguards we uphold to secure Protected Health Information. ## What Is a BASA? The Business Associate Subcontractor Agreement is very similar to a BAA, but with subtle differences that govern the obligations and activities of the subcontractor. The BASA permits the subcontractor to process or disclose PHI under HIPAA regulations (typically redacted information). There are several additional obligations required of a subcontractor that creates, receives, maintains, or transmits on behalf of another business associate. The obligations vary depending on who the subcontractor is. ## Types of subcontractors There are numerous examples of subcontractors that need access to protected health information as part of their daily tasks. If any of this information is processed or transmitted by the Business Associate, then a Business Associate Subcontractor Agreement must be in place. All subcontractors have a relationship with the business associate. here are the most common types of subcontractors that will process PHI: - **Accountants** – medical accountants, or for example, those who work for insurance companies to process patient medical bills, will likely have access to sensitive protected health information. HIPAA compliant accounting software such as Clinko,  Lytec, or NueMD might use data collected on a Business Associate’s infrastructure - **Consultancy Firms**   – many healthcare organizations outsource some or all of the HIPAA compliance responsibility to a consultancy firm, a company that specializes in gaining compliance for its customers. A business associate may be required by terms within the BAA to share PHI with the subcontractor consultancy firms - **Lawyers** – any attorney who provides legal services to a health plan in reviewing a benefits claim would likely be a business associate subcontractor if the claim involves PHI - **Medical equipment engineering** –  field engineers or service companies may be handling equipment that holds PHI, in particular, if the equipment must be sent offsite for repair or servicing. Consider a medical imaging device that has failed mid-consultation; it’s possible PHI would still be on the device, and as a result, the company responsible would need to sign a BASA - **Translator services** – medical interpreters are bound by HIPAA regulations as well, similar to doctor-patient confidentiality; interpreters may need access to PHI to assess a client - **Shredding services** – you may think that shredding services are just responsible for paper records, but in reality, any Protected Health Information that is stored digitally is still bound by the same rule. If a tape hosted at Iron Mountain is damaged in transit, a certified record will be needed to prove its destruction - **Cloud Service Providers** – external cloud providers may be used by a business associate; a good example is Microsoft Office and OneDrive. Cloud vendors can be both under a BAA or BASA depending on if there is a middle vendor between the Cover Entity and the Cloud Vendor. ## Why choose Atlantic.Net as your next Business Associate Atlantic.Net has more than 25 years of experience exceeding the needs of health professionals and is one of the country’s leading healthcare technology companies. If you’re in this industry and you need help with IT, contact our sales team to find out how our managed services could help your organization. If you are in the market for managed IT healthcare services, make sure you choose an experienced HIPAA compliant provider that focuses on security, business continuity, and scalability: a provider that can grow with you, and one that focuses on collaboration and data interoperability. We know that the regulations of the industry are intense, but Atlantic.Net can take away the stress of managing your entire IT operation. We have an extensive list of healthcare clients who have trusted us for many years, and our managed service packages do allow you to forget about the complexities of IT and focus on your patients. We will protect your infrastructure from the very latest cybersecurity threats, as well as manage upgrades and maintenance behind the scenes. We will work with you to identify and secure PHI, protect you from ransomware attacks, and offer you the very best Healthcare Managed Services platform available.Atlantic.Net offers [HIPAA Cloud](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) services to support IT Solutions for Healthcare. --- # How to Install Kanboard on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-kanboard-on-ubuntu-20-04/ | Published: 2020-11-08 | Updated: 2023-11-24 | Author: Hitesh Jethva Kanboard is a free and open-source project management software that helps you visualize and limit your work in progress to focus on your goal. It follows the Kanban methodology and is specially designed for those people who want to manage their projects efficiently and simply. Kanboard also supports reports and analytics and can be integrated with external services. It allows you to create multiple projects and customize your boards according to your needs. In this tutorial, we will learn how to install the Kanboard software on Ubuntu 20.04. ## Step 1 – Install Apache, MariaDB, and PHP First, you must install your system’s Apache web server, MariaDB, PHP, and other necessary extensions. You can install all of them with the following command: ``` apt-get update -y apt-get install apache2 mariadb-server php libapache2-mod-php php-common php-curl php-intl php-mbstring php-xmlrpc php-mysql php-gd php-pgsql php-xml php-cli php-zip unzip wget curl git -y ``` After installing all the packages, edit the php.ini file and make some desired changes: ``` nano /etc/php/7.4/apache2/php.ini ``` Change the following lines: ``` file_uploads = On allow_url_fopen = On short_open_tag = On memory_limit = 512M upload_max_filesize = 150M max_execution_time = 360 date.timezone = America/Chicago ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart apache2 ``` ## Step 2 – Create a Database for Kanboard Next, you will need to create a database and user for Kanboard. First, log into MariaDB with the following command: ``` mysql ``` Once logged in, create a database and user with the following command: ``` CREATE DATABASE kanboard; CREATE USER 'kanboard'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the database with the following command: ``` GRANT ALL ON kanboard.* TO 'kanboard'@'localhost' WITH GRANT OPTION; ``` Next, flush the privileges and exit from the MariaDB with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` At this point, your database and user are created. You can now proceed to the next step. ## Step 3 – Download Kanboard First, download the latest version of Kanboard from the Git repository using the following command: ``` wget https://github.com/kanboard/kanboard/archive/v1.2.15.zip ``` Once downloaded, unzip the downloaded file with the following command: ``` unzip v1.2.15.zip ``` Next, move the extracted directory to the Apache root directory: ``` mv kanboard-1.2.15 /var/www/html/kanboard ``` Next, change the directory to kanboard and rename the default configuration file: ``` cd /var/www/html/kanboard cp config.default.php config.php ``` Next, edit the default configuration file with the following command: ``` nano config.php ``` Define your database setting as shown below, and ensure you overwrite the default entries already in confiig.php: ``` // Database driver: sqlite, mysql or postgres (sqlite by default) define('DB_DRIVER', 'mysql'); // Mysql/Postgres username define('DB_USERNAME', 'kanboard'); // Mysql/Postgres password define('DB_PASSWORD', 'password'); // Mysql/Postgres hostname define('DB_HOSTNAME', 'localhost'); // Mysql/Postgres database name define('DB_NAME', 'kanboard'); ``` Save and close the file, then give proper ownership and permissions to Kanboard: ``` chown -R www-data:www-data /var/www/html/kanboard chmod -R 755 /var/www/html/kanboard ``` ## Step 4 – Configure Apache for Kanboard First, create an Apache virtual host configuration file using the following command: ``` nano /etc/apache2/sites-available/kanboard.conf ``` Add the following lines: ``` ServerAdmin admin@example.com DocumentRoot /var/www/html/kanboard ServerName your-domain.com Options FollowSymlinks AllowOverride All Require all granted ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined ``` Save and close the file, then activate the virtual host and enable the Apache rewrite module with the following command: ``` a2ensite kanboard.conf a2enmod rewrite ``` Finally, restart the Apache service to apply the changes: ``` systemctl restart apache2 ``` ## Step 5 – Access Kanboard UI Now, open your web browser and access Kanboard using the URL http://your-domain.com. You will be redirected to the Kanboard login page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/kanboard11.png) Provide the default username and password as admin/admin and click the **Sign** **in** button. You should see the Kanboard dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/kanboard2.png) ## Conclusion Congratulations! You have successfully installed Kanboard on the Ubuntu 20.04 server. You can now create your project, create a board, and manage project workflow using the Kanban methodology. Try Kanboard on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net using the tutorial above! --- # How to Setup a GitHub Style Wiki Using Gollum on Debian > URL: https://www.atlantic.net/vps-hosting/how-to-setup-a-github-style-wiki-using-gollum-on-debian/ | Published: 2020-11-09 | Updated: 2025-09-03 | Author: Hitesh Jethva Gollum is wiki software based on Git using GitHub Wiki as a backend. This free, open-source software is written in Ruby and comes with a simple web interface to create and manage pages from the web browser. Gollum supports a variety of formats including Markdown, AsciiDoc, ReStructuredText, Creole, and MediaWiki markup. In this tutorial, we will show you how to install Gollum with Nginx as a reverse proxy on Debian 12. ## Step 1 – Install Required Dependencies Gollum is written in Ruby, so you will need to install Ruby and other dependencies in your system. You can install all of them using the following command: ``` apt-get update -y apt-get install ruby ruby-dev cmake libssl-dev pkg-config build-essential zlib1g-dev libicu-dev git - y ``` Once all the packages are installed, you can proceed to the next step. ## Step 2 – Install Gollum Next, run the following command to install Gollum with other required packages: ``` gem install gollum org-ruby omnigollum github-markup omniauth-github ``` Next, install the GitHub Flavored Markdown, Textile and MediaWiki type markups using the following command: ``` gem install wikicloth gem install RedCloth gem install github-markdown ``` After installing all packages, you can proceed to the next step. ## Step 3 – Setup Git Repository Next, you will need to setup a Git repository for Gollum. First, configure Git username and email address with the following command: ``` git config --global user.name "Gollum Admin" git config --global user.email "admin@example.com" ``` Next, create a directory name mywiki and initialize it with the following command: ``` mkdir mywiki cd mywiki git init . ``` Once you are finished, you can proceed to the next step. ## Step 4 – Configure Gollum Next, you will need to create a Gollum configuration directory in your system. You can create it with the following command: ``` mkdir /etc/gollum/ ``` Next, create a Gollum configuration file using the following command: ``` nano /etc/gollum/config.rb ``` Add the following lines: ``` =begin This file can be used to (e.g.): - alter certain inner parts of Gollum, - extend it with your stuff. It is especially useful for customizing supported formats/markups. For more information and examples: - https://github.com/gollum/gollum#config-file =end ``` Save and close the file when you are finished. ## Step 5 – Create a Systemd Service File for Gollum Next, you will need to create a Gollum systemd service file to manage the Gollum service. You can create it with the following command: ``` nano /etc/systemd/system/gollum.service ``` Add the following lines: ``` [Unit] Description=Gollum wiki server After=network.target After=syslog.target [Service] Type=simple User=root Group=root WorkingDirectory=/root/mywiki/ ExecStart=/usr/local/bin/gollum --config "/etc/gollum/config.rb" Restart=on-abort [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the Gollum service and enable it to start at system reboot with the following command: ``` systemctl start gollum systemctl enable gollum ``` You can verify the status of the Gollum service using the following command: ``` systemctl status gollum ``` You should get the following output: - ``` gollum.service - Gollum wiki server Loaded: loaded (/etc/systemd/system/gollum.service; enabled; vendor preset: enabled) Active: active (running) since Sat 2025-08-10 15:28:00 UTC; 3s ago Main PID: 23069 (gollum) Tasks: 2 (limit: 4701) Memory: 61.8M CGroup: /system.slice/gollum.service └─23069 /usr/bin/ruby2.5 /usr/local/bin/gollum --config /etc/gollum/config.rb Oct 10 15:28:00 debian10 systemd[1]: Started Gollum wiki server. ``` At this point, Gollum is started and listening on port 4567. You can check it with the following command: ``` ss -tunelp | grep 4567 ``` You should get the following output: ``` tcp LISTEN 0 128 0.0.0.0:4567 0.0.0.0:* users:(("gollum",pid=23069,fd=7)) ino:41646 sk:9 <-> ``` ## Step 6 – Configure Nginx for Gollum Next, you will need to install and configure Nginx as a reverse proxy to access Gollum using port 80. First, install the Nginx web server by running the following command: ``` apt-get install nginx -y ``` Once installed, create a new Nginx virtual host configuration file with the following command: ``` nano /etc/nginx/conf.d/gollum.conf ``` Add the following lines: ``` server { listen 80; server_name gollum.example.com; location / { proxy_pass http://127.0.0.1:4567; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_connect_timeout 150; proxy_send_timeout 100; proxy_read_timeout 100; proxy_buffers 4 32k; client_max_body_size 500m; client_body_buffer_size 128k; } access_log /var/log/nginx/gollum-access.log; error_log /var/log/nginx/gollum-error.log; } ``` Save and close the file when you are finished. Then, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` If you get any errors, then you will need to edit the Nginx default server configuration file and set server_names_hash_bucket_size: ``` nano /etc/nginx/nginx.conf ``` Add the following line below http {: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 7 – Access Gollum Web UI Now, open your web browser and type the URL http://gollum.example.com. You should see the Gollum dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/gollum1.png) Now, create your first page by adding some content and click on the **Save** button. You should see your Home page in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/gollum2.png) ## Conclusion In the above guide, you learned how to install Gollum wiki with Nginx as a reverse proxy on Debian 12. You can now easily deploy GitHub style wiki with Gollum. Try Gollum on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # How to install RainLoop Webmail on Debian > URL: https://www.atlantic.net/vps-hosting/how-to-install-rainloop-webmail-on-debian/ | Published: 2020-11-10 | Updated: 2025-09-03 | Author: Hitesh Jethva RainLoop is a free, open-source, web-based mail client written in PHP. It allows you to access your external mail server from a web browser. RainLoop is simple, fast, lightweight, and supports both SMTP and IMAP. It is an alternative to other web-based mail applications like RoundCube and SquirrelMail. It supports two-factor authentication and can be integrated with Facebook, Twitter, Google, and Dropbox. In this tutorial, we will learn how to install RainLoop Webmail on Debian 12. ## Step 1 – Install LEMP Server First, you will need to install the Nginx web server, MariaDB, PHP and other required PHP extensions to your server. You can install all of them with the following command: ``` apt-get install nginx mariadb-server php php-cli php-fpm php-curl php-json php-mbstring php- mysql php-common php-xml unzip -y ``` Once all the packages are installed, edit the php.ini file and make some changes: ``` nano /etc/php/7.3/fpm/php.ini ``` Change the following lines: ``` upload_max_filesize = 50M post_max_size = 50M date.timezone = Asia/Kolkata ``` Save and close the file,. then restart the PHP-FPM service to apply the changes: ``` systemctl restart php8.2-fpm ``` ## Step 2 – Create a Database for RainLoop Next, you will need to create a database and user for RainLoop. First, log in to MariaDB shell with the following command: ``` mysql ``` Once logged in, create a database and user with the following command: ``` CREATE DATABASE raindb; CREATE USER 'rainuser'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the raindb with the following command: ``` GRANT ALL ON raindb.* TO 'rainuser'@'localhost'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` At this point, MariaDB is configured for RainLoop. ## Step 3 – Install RainLoop First, create a directory for RainLoop inside the Nginx default root directory: ``` mkdir /var/www/rainloop ``` Next, download the latest version of RainLoop with the following command: ``` wget https://www.rainloop.net/repository/webmail/rainloop-latest.zip ``` Next, unzip the downloaded file to the /var/www/rainloop directory with the following command: ``` unzip rainloop-latest.zip -d /var/www/rainloop ``` Next, change the ownership and permission of the rainloop directory: ``` chown -R www-data:www-data /var/www/rainloop chmod -R 775 /var/www/rainloop ``` Once you are finished, you can proceed to configure Nginx. ## Step 4 – Configure Nginx for RainLoop Next, you will need to create an Nginx virtual host configuration file for RainLoop. You can create it with the following command: ``` nano /etc/nginx/sites-available/rainloop.conf ``` Add the following lines: ``` server { listen 80; server_name rainloop.example.com; root /var/www/rainloop; index index.php; location / { try_files $uri $uri/ /index.php?$query_string; } location ~ \.php$ { fastcgi_index index.php; fastcgi_split_path_info ^(.+\.php)(.*)$; fastcgi_keep_conn on; include fastcgi_params; fastcgi_pass unix:/var/run/php/php8.2-fpm.sock; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; } location ~ /\.ht { deny all; } location ^~ /data { deny all; } } ``` Save and close the file, then activate the Nginx virtual host with the following command: ``` ln -s /etc/nginx/sites-available/rainloop.conf /etc/nginx/sites-enabled/ ``` Next, verify the Nginx for any syntax errors with the following command: ``` nginx -t ``` You should get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Next, restart the Nginx service to apply the changes. ``` systemctl reload nginx ``` If you get any errors, then you will need to edit the Nginx default server configuration file and set server_names_hash_bucket_size: ``` nano /etc/nginx/nginx.conf ``` Add the following line below http {: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 5 – Access RainLoop Dashboard Now, open your web browser and access the RainLoop dashboard using the URL rainloop.example.com/?admin. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rainloop1.png) Provide the default username **admin** and password **12345** and click on the **>** button. You should see the RainLoop dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rainloop2.png) Next, click on the **change** **password** button to change the default admin password. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rainloop3.png) Provide your new password and click on the **Update** **Password** button to change the password. ## Conclusion Congratulations! You have successfully installed RainLoop mail client on Debian 12 server. You can now add your mail server from the RainLoop web interface and access your email through the web browser. For more information, visit the RainLoop [documentation](https://www.rainloop.net/docs/configuration) page. Get started with RainLoop on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # Top 13 Difficult Questions Your HIPAA Consultant Should Be Asking You > URL: https://www.atlantic.net/hipaa-compliant-hosting/top-13-difficult-questions-your-hipaa-consultant-should-be-asking-you/ | Published: 2020-11-10 | Updated: 2026-09-15 | Author: Richard Bailey Becoming HIPAA compliant is a challenging undertaking, as the Health Insurance Portability and Accountability Act of 1996 together with all of the subsequent amendments and updates form a very complex piece of legislation. There are countless mandatory and recommended safeguards concerning the physical, technical, and administrative securities over Protected Health Information (PHI). ### Questions Your HIPAA Consultant Should Be Asking The questions we have highlighted will often be difficult to answer, and once you have the answer, it might be difficult to implement and successfully maintain, but they reflect core elements of HIPAA that must be adhered to. This is where Atlantic.Net can help with our fully managed service offerings.  We take care of the hard and repetitive work to maintain your HIPAA environment. You can readily understand why so many covered entities hire a HIPAA compliance consultant to oversee the monumental task of becoming HIPAA compliant. If you are embarking on this journey, it is important to consider these top critical questions: 1. When was your last Risk Assessment completed? 2. Do you know where your PHI resides? 3. Who is managing your firewall(s) and network to ensure they are patched, up to date, and in compliance? 4. Who is managing your servers and operating systems to ensure they are patched, up to date, and in compliance? 5. Do you have a cloud strategy? 6. Do you have an Incident Response Plan in place? 7. What are your off-site backup and disaster recovery plans? 8. How do you encrypt PHI? 9. How do you control access to PHI? 10. How do you log access to PHI? 11. What is your workstation policy? 12. Have your employees recently had a security awareness training refresh? 13. Do you outsource to a HIPAA Compliant Hosting partner? ## When was your last Risk Assessment completed? A **Risk Assessment** is a mandatory administrative safeguard of HIPAA compliance, is usually the first task undertaken on the journey to becoming compliant, and should form part of a systematic risk management program. It is advisable to complete a risk assessment at least once a year. A consultant will advise that all covered entity IT systems are analyzed for security risks and security measures are implemented to mitigate against the risk. All measures must be documented and, if necessary, the covered entity must install and maintain reasonable, appropriate, and continuous protection. The scope of the risk assessment is enormous, and the aim is to make sure all systems adhere to the physical and technical requirements of HIPAA, such as PHI data being encrypted at rest and in transit or implementing a VPN solution to access a [HIPAA compliant hosting platform](https://www.atlantic.net/hipaa-compliant-hosting/) . When you partner with Atlantic.Net, we will work with you to complete a full risk assessment, helping to detect compliance weaknesses and document what future action is required by the availability standards of HIPAA. We will look for vulnerabilities, complete a threat analysis, and assess PHI data locations to help determine the likelihood of threat occurrence. Need help with your risk assessment? [Get in touch today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) ! ## Do you know where your PHI resides? The covered entity must know what PHI they manage and where it is located and processed on their IT systems. Understanding what databases, applications, and file servers contain PHI and where PHI is located underpins the entire process. Making a change to the security outlook of a covered entity is essential. Securing PHI is the cornerstone of HIPAA and one of the most important first steps to achieve compliance. Know where PHI is stored and how you process PHI! Knowing what PHI you have will help to create a baseline to work upon, and the baseline acts as a line in the sand, helping to define how to handle and process PHI and creating a  roadmap for the future desired state configuration. As part of the risk assessment, Atlantic.Net can complete a Data Collection assessment which will determine where PHI is stored, received, maintained, or transmitted. Need help with Data Collection? [Get in touch today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) ! ## Who is managing your firewall(s) and network to ensure they are patched, up to date, and in compliance? Network firewalls are difficult to update gracefully and require a high availability configuration to prevent downtime. Firewalls are the #1 network component we find not being patched or managed in HIPAA compliant environments. Passwords must be changed from defaults, the networking stacks must be updated to the latest run-time code levels, and SFP fiber connectors need their firmware updated, not to mention the software used to manage the firewalls. This is a tough assignment even for the professionals, and it is one of the principal reasons customers outsource to a HIPAA compliant hosting provider like Atlantic.Net. Our engineers have vast experience looking for vulnerabilities at the network layer. Need help with your managed firewall? [Get in touch today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) ! ## Who is managing your servers and operating systems to ensure they are patched, up to date, and in compliance? When we review customer infrastructure before onboarding them, one of the major concerns we find is the lack of operating system patching or the use of operating systems that are at end-of-life from the vendor. Server patching is often months and sometimes years out of date. This is a major security concern, and these systems potentially have countless vulnerabilities. Running an out-of-date operating system, basically any Windows Server platform up to and including Windows Server 2008 R2, puts your organization at risk. Atlantic.Net can provide a managed service offering wherein our highly skilled engineers will manage and maintain your server infrastructure. This can include a patch management program, anti-virus consolidation, and a best practice security implementation to defend against system vulnerabilities. Need help with Managed Services? [Get in touch today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) ! ## Do you have a cloud strategy? Digital transformation is a hot topic in 2020, with many organizations fast-tracking cloud migration strategies in the wake of Covid-19. How can the cloud help your healthcare organization grow on a HIPAA compliant platform? The cloud offers many benefits to healthcare, outsourcing the responsibility of server hardware patching, managing, replacement, monitoring, and more. Working alongside Atlantic.Net, a cloud-first strategy will help to ensure access and uptime within a fully redundant cloud stack from physical, hardware, and network, including multiple carriers with multiple high-speed connections. The cloud provider will also be responsible for vulnerability scanning and mitigation. Need help with your cloud strategy?  [Get in touch today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) ! ## Do you have an Incident Response Plan in place? An IRP is an administrative safeguard that forms part of the HIPAA Breach Notification Rule (2009). It is a mandatory requirement to have a plan in place that documents the steps undertaken in the event of a security breach affecting PHI. The IRP contains details about who is responsible and what roles employees undertake to react to a security incident. There are regulations about notifying patients and the media in a timely fashion. Investigate the nature and extent of PHI involved and understand if patients can be tracked from data leaked. If possible, work out who was involved and try to determine if PHI was accessed/taken. The investigation will determine if PHI was put at risk and if the theft needs to be reported to the [Office of Civil Rights](https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf) (OCR). Working with Atlantic.Net will dramatically reduce the risk of ever having to use an incident response plan, as our HIPAA compliant services have been finely tuned to provide the best-in-class security for your healthcare organization. However, if the worst should happen, we will stand by you, implementing an IRP that is created as part of the risk assessment. Need help with an IRP? [Get in touch today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) ! ## What are your off-site backup and disaster recovery plans? A business continuity plan is something every business must focus on, especially since the Covid-19 outbreak. Two key parts of a BCP are Off-Site Backups and Disaster Recovery Planning. They are a required safeguard that aims to document and test how a covered entity responds to a disaster recovery scenario such as a natural disaster, a global pandemic, or flooding of a data center. The availability of PHI is mandatory; authorized systems must be able to access PHI, and appropriate measures must be undertaken to protect PHI. A BCP usually consists of a predefined backup strategy that protects PHI systems, such as a data backup system that replicates to a secondary location. Likewise, critical IT systems, such as patient databases, must be capable of failing over service to a secondary data center location. This is a technical solution commonly provided by your HIPAA compliant hosting partner. Some providers achieve this using tape backup, but it has become increasingly popular to hold backup data on secure, redundant, geolocated storage systems. Data is replicated from the source location to at least one other offsite location, and regular test restores should be conducted to confirm the validity of the backup data. At all times, a backup is available should the worst happen, meaning that data can be restored in all scenarios. A BCP is an evolving administrative task that involves an annual disaster recovery test to ensure the failover process works, and lessons can be learned if issues are encountered. Atlantic.Net are specialists in backup and disaster recovery. Our cloud backup solution can be added by a simple checkbox enable, and our DR service provides best-in-class site failover to any of our 8 data centers located in the United States, Canada, Asia, and Europe. Need help with your Backup Strategy and DR? [Get in touch today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) ! ## How do you encrypt PHI? Data encryption is a method of translating data into a protected format that can only be read by the person or computer with the decryption key. Unencrypted data, sometimes called *plaintext,* is readable by humans and computers. Encrypted data, sometimes called *ciphertext* , is only readable by the holder of the secret (encryption) key. It is highly recommended to encrypt all PHI data, and the only way to achieve this standard is to use AES-256 encryption for PHI data stored at rest and in transit. By default, Atlantic.Net encrypts all data. Surprisingly, holding PHI data encrypted at rest is not mandatory, but you need to have a very good excuse when you are audited as to why you are not encrypting data at rest. Only encrypting PHI in transit is mandatory. HIPAA recommends using end-to-end encryption (E2EE); this standard means that only the sender and receiver can view or access the data (it is encrypted everywhere but at the endpoints). Data is not stored on an intermediate server, such as a content server, during the data transfer, making the entire data transaction incredibly secure. You should also consider making your email platform encrypted and encrypting user laptops, mobile phones, tablets, and strictly manage your employee’s BYOD habits. Backups must be encrypted, as well as any in-scope database. Need help with encryption? [Get in touch today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) ! ## How do you control access to PHI? Controlling who has access to PHI is another mandatory requirement of HIPAA compliance. It is important to know who should have access to PHI and what PHI they should have access to. It requires credential management, access control lists, and several administrative policies to remain compliant. Each user must have a unique username and password combination, credentials must never be shared and to enforce this, and accounts must be protected by Multifactor authentication. Servers or applications that contain PHI must use access control lists; this is usually managed by directory service security groups that can deny access to all but a chosen few. System administrators and service desks need to oversee the entire process, not only enforcing system-wide password policies and restricting access to sensitive systems, but also taking care of user management; for example, enforce a strict leavers policy, ensuring at minimum a user’s credentials are locked as soon as they leave the business. Atlantic.Net has vast experience in assessing current security measures, including making sure access controls are in place to manage inappropriate accesses or disclosure of PHI. Need help with your access controls? [Get in touch today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) ! ## How do you log access to PHI? HIPAA compliance also demands that in addition to maintaining access controls to PHI, detailed logging must also be enabled to log who has accessed PHI, what PHI has been accessed, and when the PHI was accessed. Verbose logging can be enabled inside applications, databases, and on server and cloud infrastructure. Logging creates huge volumes of data, making manual monitoring is all but impossible. An automated SIEM solution can be implemented to automatically audit the logs for specific trends, such as users logging in outside-of-hours, multiple failed login attempts, changes in user’s elevated permissions, and so on. These controls are required to introduce a technical layer of auditing on PHI. It ensures that the covered entity can determine when PHI is accessed, altered, or destroyed in an unapproved manner. Security Information Event Management (SIEM) platforms are configured to audit and alert on any changes made to PHI, and the alerts should be monitored and escalated as required. Need help with your access controls? [Get in touch today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) ! ## What is your workstation policy? Write a policy that limits which workstations can access protected health data; it should define how a screen should be guarded against snooping and specify appropriate workstation use. Automated lock screens should be enabled by system administrators. A clear screen states that whenever your staff members leave their desks for an extended time, they should log off their computers and that whenever they leave, even for a moment, they should lock their screens. A clean desk policy should be in place that mandates that employees empty their desks of any materials, including removable media, sticky notes, business cards, and documents, whenever they leave it unattended. Atlantic.Net can offer advice and guidance related to the physical protection of a workstation. This includes cable locks, screen filters, docking stations with locks, privacy screens, and technical protections such as password policies, automated lockouts, and so on. Need help with your workstation policy? [Get in touch today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) ! ## Have your employees recently had a security awareness training refresh? Finally, one of the most important questions you should be asked is about employee training about HIPAA compliance and security best practices. Training plays such as a large part in protecting the covered entity’s IT ecosystem, as employees form the front line of defense against breaches of PHI. Adequate training includes not only the latest security awareness training, such as the latest trends and threats in cybersecurity, but also training on how to correctly use computer systems and medical devices, and how to protect patient information. To wrap up, if you are in the market for Managed IT services for healthcare, make sure you choose an experienced HIPAA compliant provider that focuses on security, business continuity, and scalability. Choose a provider that can grow with you, one that focuses on collaboration and data interoperability. We know that the regulations of the industry are intense, but Atlanic.Net can take away the stress of managing your entire IT operation. We have an extensive list of healthcare clients who have trusted us for many years, and our managed service packages allow you to forget about the complexities of IT and focus on your patients. We will protect your infrastructure from the very latest cybersecurity threats, as well as manage upgrades and maintenance behind the scenes. We will work with you to identify and secure PHI, protect you from ransomware attacks, and offer you the very best Healthcare Managed Services platform available. The most effective way to manage training is to ensure all workforce members are given security training on regular occasions. Speak to our sales team to learn how Atlantic.Net can guide your organization through this critical learning journey. Need help with your learning journey? [Get in touch today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) ! ## Do you outsource to a HIPAA Compliant Hosting partner? Are you in need of an infrastructure that can protect the health data of your organization? At Atlantic.Net, whatever your technical requirements, we can offer a top-grade [HIPAA-Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solution. Get a [HIPAA-Compliant Server Cost](https://www.atlantic.net/hipaa-compliant-hosting/) from one of our experts. If you’re in need of a HIPAA compliance consultant, check out our [list of the top 10 HIPAA consulting companies](https://www.atlantic.net/hipaa-compliant-hosting/top-10-hipaa-consulting-companies-in-2020/). [Get a free consultation today!](https://www.atlantic.net/hipaa-compliant-hosting/) --- #### Read More About Consulting Services - [IT Consulting Services](https://www.atlantic.net/managed-services/consulting/) - Best [Cloud Computing Consulting Services](https://www.atlantic.net/vps-hosting/best-cloud-consultancy-or-msp/) --- --- # How to Install Jenkins on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-jenkins-on-centos-8/ | Published: 2020-11-11 | Updated: 2023-11-24 | Author: Hitesh Jethva Jenkins is an open-source, Java-based continuous integration and continuous delivery tool that makes the development process easier. It helps developers to effectively test and deploy code. Continuous integration is a development practice where every developer commits their code changes to the central repository. Continuous delivery is the second part of this development process where code changes are tested and deployed to production automatically. In this tutorial, we will learn how to install Jenkins on CentOS 8. ## Step 1 – Install Java Jenkins is a Java-based software and requires Java version 8, so Java must be installed on your server. If not installed, you can install it by running the following command: ``` yum update -y yum install java-1.8.0-openjdk-devel -y ``` After installing Java, verify the Java version with the following command: ``` java -version ``` You should get the following output: ``` openjdk version "1.8.0_265" OpenJDK Runtime Environment (build 1.8.0_265-b01) OpenJDK 64-Bit Server VM (build 25.265-b01, mixed mode) ``` ## Step 2 – Install Jenkins By default, Jenkins is not available in the CentOS standard repository, so you will need to add the Jenkins official repository to your system. First, add the Jenkins repository with the following command: ``` wget -O /etc/yum.repos.d/jenkins.repo https://pkg.jenkins.io/redhat-stable/jenkins.repo ``` Next, import the Jenkins key with the following command: ``` rpm --import https://pkg.jenkins.io/redhat-stable/jenkins.io.key ``` Next, install the Jenkins by running the following command: ``` yum install jenkins ``` Once the Jenkins is installed, start the Jenkins service and enable it to start at system reboot with the following command: ``` systemctl start jenkins systemctl enable jenkins ``` You can also verify the status of Jenkins with the following command: ``` systemctl status jenkins ``` You should get the following output: - ``` jenkins.service - LSB: Jenkins Automation Server Loaded: loaded (/etc/rc.d/init.d/jenkins; generated) Active: active (running) since Sat 2020-10-17 03:41:00 EDT; 19s ago Docs: man:systemd-sysv-generator(8) Process: 39242 ExecStart=/etc/rc.d/init.d/jenkins start (code=exited, status=0/SUCCESS) Tasks: 42 (limit: 25014) Memory: 429.2M CGroup: /system.slice/jenkins.service └─39265 /etc/alternatives/java -Dcom.sun.akuma.Daemon=daemonized - Djava.awt.headless=true -DJENKINS_HOME=/var/lib/jenkins -jar /usr> ``` ``` Oct 17 03:40:59 centos systemd[1]: Starting LSB: Jenkins Automation Server... Oct 17 03:40:59 centos runuser[39249]: pam_unix(runuser:session): session opened for user jenkins by (uid=0) Oct 17 03:41:00 centos runuser[39249]: pam_unix(runuser:session): session closed for user jenkins Oct 17 03:41:00 centos jenkins[39242]: Starting Jenkins [ OK ] Oct 17 03:41:00 centos systemd[1]: Started LSB: Jenkins Automation Server. ``` ## Step 3 – Access Jenkins At this point, Jenkins is started and listening on port 8080. Now, open your web browser and access the Jenkins web interface using the URL **http://your-server-ip:8080**. You will be redirected to the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/jenkins1.png) The Jenkins password will be automatically generated during the installation. You can print it with the following command: ``` cat /var/lib/jenkins/secrets/initialAdminPassword ``` You should see the Jenkins password in the following output: ``` 819d86d763024eacb9154f7697593eab ``` Type the password on the screen and click on the **Continue** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/jenkins2.png) Click on the **Install suggested plugins** panel to start the installation process. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/jenkins3.png) Once the installation has been completed, you should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/jenkins4.png) Provide your admin username, password, and email and click on the **Save** **and** **Continue** button. ![](https://www.atlantic.net/wp-content/uploads/2020/11/jenkins5.png) Provide your Jenkins URL and click on the **Save and Finish** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/jenkins6.png) Click on the **Start using Jenkins** button. You should see the Jenkins dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/jenkins7.png) ## Conclusion Congratulations! You have successfully installed Jenkins on CentOS 8. You can now explore Jenkins and start creating your first software project. Get started with Jenkins on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # How to Install Monit Monitoring Server on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-install-monit-monitoring-server-on-ubuntu/ | Published: 2020-11-12 | Updated: 2023-11-24 | Author: Hitesh Jethva Monit is a utility to designed to manage and monitor filesystems, directories, files, programs, and processes over a UNIX system for changes in size, checksum, and timestamp. Monit not only undertakes automatic repair and maintenance, but also executes meaningful casual actions when error situations arise. Just as an example, Monit can start a process if it ceases to run, restart a process if it fails to respond, and halt a process if it uses too many resources. An easy-to-configure control file, which is based on a token-oriented, free-format syntax, is used for controlling Monit. Monit also sends customizable alert messages as notifications regarding error conditions. In this tutorial, we will learn how to install the Monit monitoring tool on Ubuntu 20.04. ## Step 1 – Install Monit By default, Monit is available in the Ubuntu 20.04 default repository. You can install it with the following command: ``` apt-get update -y apt-get install monit -y ``` Once Monit is installed, the Monit service will be started automatically. You can check the status of Monit with the following command: ``` systemctl status monit ``` You should get the following output: ``` monit.service - LSB: service and resource monitoring daemon Loaded: loaded (/etc/init.d/monit; generated) Active: active (running) since Thu 2020-10-01 09:35:07 UTC; 17s ago Docs: man:systemd-sysv-generator(8) Tasks: 1 (limit: 2353) Memory: 1.6M CGroup: /system.slice/monit.service └─40909 /usr/bin/monit -c /etc/monit/monitrc Oct 01 09:35:07 ubuntu2004 systemd[1]: Starting LSB: service and resource monitoring daemon... Oct 01 09:35:07 ubuntu2004 monit[40893]: * Starting daemon monitor monit Oct 01 09:35:07 ubuntu2004 monit[40893]: ...done. Oct 01 09:35:07 ubuntu2004 systemd[1]: Started LSB: service and resource monitoring daemon. ``` ## Step 2 – Configure Monit The Monit default configuration file is located at /etc/monit/monitrc. Monit provides a web-based interface to monitor Monit through the web browser. By default, the Monit web interface is disabled, so you will need to enable it and set the admin password. You can do this by editing the file /etc/monit/monitrc. ``` nano /etc/monit/monitrc ``` Uncomment and set the Monit admin password as shown below: ``` set httpd port 2812 and allow admin:adminpassword ``` Save and close the file when you are finished, then check for syntax errors with the following command: ``` monit -t ``` You should get the following output: ``` Control file syntax OK ``` Next, restart the Monit service to apply the changes: ``` systemctl restart monit ``` At this point, Monit is started and listening on port 2812. You can check it with the following command: ``` ss -plunt | grep 2812 ``` You should see the following output: ``` tcp LISTEN 0 1024 0.0.0.0:2812 0.0.0.0:* users:(("monit",pid=41867,fd=6)) tcp LISTEN 0 1024 [::]:2812 [::]:* users:(("monit",pid=41867,fd=7)) ``` Now, open your web browser and access the Monit web interface using the URL **http://your-server-ip:2812**. You should see the Monit login page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/monit1.png) Provide your admin username and password, then click on the **Sign**–**in** button. You should see the Monit dashboard on the following page:   You can also verify the status of your system with the following command: ``` monit status ``` You should get the following output: ``` Monit 5.26.0 uptime: 2m System 'ubuntu2004' status OK monitoring status Monitored monitoring mode active on reboot start load average [0.17] [0.30] [0.30] cpu 7.8%us 5.1%sy 0.1%wa memory usage 794.3 MB [40.0%] swap usage 1.8 MB [0.4%] uptime 5h 21m boot time Thu, 01 Oct 2020 04:19:36 data collected Thu, 01 Oct 2020 09:40:29 ``` ## Step 3 – Monitor Apache and MariaDB with Monit Monit woks by continuously monitoring different services in your system. If any service goes down Monit, automatically start it. In this section, we will install Apache and MariaDB and monitor both services using Monit. First, install Apache and MariaDB with the following command: ``` apt-get install apache2 mariadb-server -y ``` Next, enable the Apache and MariaDB monitoring with the following command: ``` ln -s /etc/monit/conf-available/apache2 /etc/monit/conf-enabled/ ln -s /etc/monit/conf-available/mysql /etc/monit/conf-enabled/ ``` Now, restart the Monit service to apply the changes: ``` systemctl restart monit ``` You can now check the status of the Apache and MariaDB using the Monit command-line utility: ``` monit summary ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/11/monit3.png) Now, go to the Monit web interface and refresh the page. You should see the status of all services in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/monit4.png) Next, stop the Apache service and check whether the Monit starts it automatically or not. You can stop the Apache service with the following command: ``` systemctl stop apache2 ``` Now, check the Monit log file and see how Monit starts the Apache service: tail -f /var/log/monit.log You should get the following output: ``` [UTC Oct 1 09:58:06] error : 'apache' process is not running [UTC Oct 1 09:58:06] info : 'apache' trying to restart [UTC Oct 1 09:58:06] info : 'apache' start: '/etc/init.d/apache2 start' [UTC Oct 1 10:00:06] info : 'apache' process is running with pid 4404 ``` . Wait some time, then run the following command to check the status of the Apache service. ``` monit summary apache ``` You should see that Apache is started and in listening status: ``` Monit 5.26.0 uptime: 6m ┌─────────────────────────────────┬────────────────────────────┬───────────────┐ │ Service Name │ Status │ Type │ ├─────────────────────────────────┼────────────────────────────┼───────────────┤ │ apache │ OK │ Process │ └─────────────────────────────────┴────────────────────────────┴───────────────┘ ``` ## Conclusion In this guide, you learned how to install and configure Monit on Ubuntu 20.04. You also learned how to configure Monit to monitor different services. You can now use Monit in the production environment and monitor your desired services. Try Monit on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net using the tutorial above! --- # How to Install and Use MySQL Workbench on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-mysql-workbench-on-ubuntu/ | Published: 2020-11-14 | Updated: 2023-11-23 | Author: Hitesh Jethva MySQL Workbench is a graphical and visual database designing tool for MySQL servers and databases. It is specially designed to enable database administrators, developers and database architects to visually design, generate, model and manage databases. MySQL Workbench’s aim is to provide a simple and easy-to-use interface for working with databases. It has an ability to create multiple models in the same environment and supports all objects including tables, views, triggers, and stored procedures. In this tutorial, we will install MySQL server on one Ubuntu 18.04 server, install MySQL workbench on another Ubuntu 18.04 desktop and connect MySQL server with MySQL Workbench interface. ## Step 1 – Install and Configure MySQL Server MySQL Workbench supports MySQL server versions 5.6 and higher, so you will need to install a MySQL server version greater than 5.6 in your first server. On the Ubuntu 18.04 server, run the following command to install MySQL server: ``` apt-get update -y apt-get install mysql-server -y ``` After installing the MySQL server, you will need to set the MySQL root password, as MySQL is configured to login without a password by default. First, access the MySQL shell with the following command: ``` mysql ``` Once connected, change the database to mysql using the following command: ``` use mysql; ``` Next, set the MySQL root password with the following command: ``` ALTER USER 'root'@'localhost' IDENTIFIED WITH mysql_native_password BY 'password'; ``` Next, flush the privileges and exit from the MySQL shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` Next, log in to MySQL with root user: ``` mysql -u root -p ``` Provide your MySQL root password and hit Enter to connect the MySQL shell. Next, create a test database with the following command: ``` create database testdb; ``` Next, grant all privileges to all database and all remote IPs with the following command: ``` GRANT ALL PRIVILEGES ON *.* TO 'root'@'%' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MySQL shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` In order to connect MySQL Workbench via TCP/IP over SSH tunnel, you will need to add KexAlgorithms key exchange algorithms in your SSH config file. You can do it by editing the file /etc/ssh/sshd_config: ``` nano /etc/ssh/sshd_config ``` Add the following line at the end of the file: ``` KexAlgorithms curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2- nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group14-sha1,diffie-hellman- group1-sha1 ``` Save and close the file when you are finished, then restart the SSH service to implement the changes: ``` systemctl restart ssh ``` At this point, the MySQL server is installed and configured. ## Step 2 – Install MySQL Workbench Next, you will need to install MySQL Workbench in your **Ubuntu 18.04 desktop system.** By default, MySQL Workbench is available in the Ubuntu 18.04 default repository. You can install it by simply running the following command: ``` apt-get install mysql-workbench -y ``` Once the installation is completed, you can proceed to the next step. ## Step 3 – Connect MySQL Server with MySQL Workbench In this section, we will open the MySQL Workbench interface and connect the MySQL server via TCP/IP over SSH. On the Ubuntu 18.04 desktop system, open the MySQL Workbench interface as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/11/workbench1.png) Click on the **+** icon to create a new connection. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/workbench2.png) Provide connection name, select connection method, provide your MySQL Server IP address and username, and in SSH Password field, click on “**Store in keychain**“. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/workbench3.png) ![](https://www.atlantic.net/wp-content/uploads/2020/11/workbench4.png) Provide your MySQL server SSH root password and click on the OK button. Next, provide your MySQL server host, port, and username, then in the MySQL Password field, click on “**Store in Keychain**” and click on the **Test Connection** button. Once the connection is tested successfully, you should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/workbench5.png) Click on the **OK** button and again click on the **OK** button to save the connection. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/workbench6.png) Now, double click on your connection. Once the connection has been established successfully, you should see the MySQL Workbench start page. ![](https://www.atlantic.net/wp-content/uploads/2020/11/workbench7.png) Now, click on the **Server** **Status** in the left pane and you should see your MySQL Server status in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/workbench8.png) ## Conclusion Congratulations! You have successfully installed MySQL server on Ubuntu 18.04 server and connected with MySQL Workbench. You can now start managing your MySQL users, schemas, databases, and much more. For more information, visit the [MySQL Workbench](https://www.mysql.com/products/workbench/) documentation. Get started with MySQL Workbench on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # How to Install Metabase on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-metabase-on-centos-8/ | Published: 2020-11-15 | Updated: 2023-11-24 | Author: Hitesh Jethva Metabase is a free and open-source business intelligence tool that helps you to visualize large data sets without ever writing a single line of SQL. It is a powerful database lookup tool that comes with a web-based interface that makes it easier to search for data sets and display information. Metabase can be integrated with almost all types of databases and allows you to run queries on the database. In this tutorial, we will explain how to install Metabase on CentOS 8. ## Step 1 – Install Java Metabase is a Java-based application, so Java must be installed in your system. If not installed, you can install it by running the following command: ``` dnf update -y dnf install java-11-openjdk-devel -y ``` Once Java is installed, verify the installed version of Java with the following command: ``` java --version ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/11/metabase1.png) ## Step 2 – Install and Configure MariaDB Next, you will need to install the MariaDB server in your system. You can install it with the following command: ``` dnf install mariadb-server -y ``` Once installed, start the MariaDB service and enable it to start on system reboot with the following command: ``` systemctl start mariadb systemctl enable mariadb ``` Next, log in to MariaDB with the following command: ``` mysql ``` Once logged in, create a database and user for Metabase with the following command: ``` create database metabasedb; create user metabaseuser@'localhost' identified by 'password'; ``` Next, grant all privileges to the Metabase with the following command: ``` grant all on metabasedb.* to metabaseuser@'localhost' with grant option; ``` Next, flush the privileges and exit from the MariaDB with the following command: ``` flush privileges; exit ``` ## Step 3 – Download and Setup Metabase Installation Directory Before starting, create a user and group for Metabase with the following command: ``` groupadd --system metabase useradd --system -g metabase --no-create-home metabase ``` Next, create the necessary directories and files for Metabase: ``` mkdir -p /opt/metabase touch /var/log/metabase.log touch /etc/default/metabase ``` Next, change the ownership with the following command: ``` chown -R metabase:metabase /opt/metabase chown metabase:metabase /var/log/metabase.log chmod 640 /etc/default/metabase ``` Next, create a log file for Metabase with the following command: ``` nano /etc/rsyslog.d/metabase.conf ``` Add the following lines: ``` :msg,contains,"metabase" /var/log/metabase.log & stop ``` Save and close the file, then restart the rsyslog service with the following command: ``` systemctl restart rsyslog ``` Next, change the directory to metabase and download the latest version of Metabase with the following command: ``` cd /opt/metabase wget https://downloads.metabase.com/v0.36.2/metabase.jar ``` Next, change the ownership of the downloaded file to metabase with the following command: ``` chown -R metabase:metabase /opt/metabase ``` ## Step 4 – Create a System Service File for Metabase Next, create a systemd service file to manage the Metabase service. You can create it with the following command: ``` nano /etc/systemd/system/metabase.service ``` Add the following lines: ``` [Unit] Description=Metabase server After=syslog.target After=network.target [Service] WorkingDirectory=/opt/metabase/ ExecStart=/usr/bin/java -jar /opt/metabase/metabase.jar EnvironmentFile=/etc/default/metabase User=metabase Type=simple StandardOutput=syslog StandardError=syslog SyslogIdentifier=metabase SuccessExitStatus=143 TimeoutStopSec=120 Restart=always [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the Metabase service and enable it to start at system reboot with the following command: ``` systemctl start metabase systemctl enable metabase ``` You can now check the status of the Metabase service with the following command: ``` systemctl status metabase ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/11/metabase2.png) ## Step 5 – Access Metabase Web Interface At this point, Metabase is started and listening on port 3000. Now, open your web browser and access Metabase using the URL http://your-server-ip:3000. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/metabase3.png) Click on the “**Let’s get started**“. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/metabase4.png) Select your language and click on the **Next** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/metabase5.png) Provide your full name, email address, and password and click on the **Next** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/metabase6.png) ![](https://www.atlantic.net/wp-content/uploads/2020/11/metabase7.png) Provide your database details and click on the **Next** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/metabase8.png) Enable your “**Usage data preferences**” and click on the **Next** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/metabase9.png) Provide your admin email address and click on the **Take me to Metabase** button. You should see the Metabase default dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/metabase10.png) ## Conclusion In this guide, you learned how to install and configure Metabase on CentOS 8. You can now use the application for gleaning new insights from your dataset. You can visit the Metabase official [documentation](https://metabase.com/docs/latest/) for more information. Try Metabase on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net using the tutorial above! --- # Atlantic.Net Announces New Initiatives to Help America’s Small to Mid-Size Businesses During the COVID-19 Pandemic > URL: https://www.atlantic.net/press-releases/atlantic-net-announces-new-initiatives-to-help-americas-small-to-mid-size-businesses-during-the-covid-19-pandemic/ | Published: 2020-11-15 | Updated: 2024-06-11 | Author: Editorial Team *Company to Offer Double the Resources at No Cost Permanently and Free Cloud Virtual Servers for One Full Year* **ORLANDO, FLA. (November 15, 2020)** – [Atlantic.Net](https://www.atlantic.net/), a leading cloud services provider, today launched a plan that enables new cloud VPS customers double their server resources at no extra cost. This program aims to help businesses establish more permanent remote workforces in response to social distancing measures and work-from-home policies during COVID-19. Atlantic.Net will upgrade all cloud plans hosted at its Orlando data center to the capabilities of the next highest price bracket at no additional cost for new customers. Additionally, the company plans to offer this upgrade at all seven global data centers in the coming weeks. This program also includes Atlantic.Net’s Free-to-Use for One Year Server promotion, meaning that any new free tier users will be automatically upgraded from 1GB to 2GB Cloud Server usage for one full year. “COVID 19 has put an incredible strain on IT and cloud services systems, with remote work scaling to a larger and more permanent levels. In order to help businesses, we’re offering even more flexibility to organizations reevaluating their cloud provider,” said Marty Puranik, CEO and Founder of Atlantic.Net. “We truly hope that this will not only help America’s small to mid-size businesses get more for less, but also our healthcare providers, who can now get audit-ready and healthcare compliant solutions for half the price!” Initially, Atlantic.Net will offer the new program in its Orlando, Florida data center, with plans to make it available at all of its locations before the end of this year; the company provides scalable computing from seven international data centers including New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando.. The Atlantic.Net Cloud Platform, which is engineered to provide fault-tolerant, and ultra-fast performance, includes award-winning Cloud Servers, Secure Block Storage, one-click applications, DNS, dedicated private nodes, private networking, RESTful API, data backup, a full suite of managed services, 24/7/365 expert U.S.-based support, and more. This infrastructure is ideally suited to support businesses and organizations as they evolve toward a distributed, remote work environment to mitigate the health risks of COVID-19 to the global workforce. To view the latest cloud offerings and pricing structure, visit [https://www.atlantic.net/vps-hosting/](https://urldefense.proofpoint.com/v2/url?u=https-3A__www.atlantic.net_vps-2Dhosting_&d=DwMFAg&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=UChi3C1F2KzF3gDdKeDIWT0Y2FVnGxMftp5efqLBa9U&m=g04GC2HzMtXXVCRxt7u_STJ-x-16xkLdaBH77qqaSAM&s=Y-R78AI7NK1KhSzsD5fRocVtvoKvgdGMjTQ-ljhCweg&e=) . **About Atlantic.Net** Atlantic.Net is a global [cloud services](https://www.atlantic.net/hipaa-compliant-hosting/) provider with over 25 years of experience, serving thousands of developers and small, medium, and large clients in more than one hundred countries. Atlantic.Net specializes in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions and has served dynamic business clients including Lenovo, Newegg, NASA, and Hilton, among others. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions, backed by 24/7/365 support in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. For more information, please visit [Atlantic Net/](https://www.atlantic.net/). --- # How to Install ONLYOFFICE Docs on Debian > URL: https://www.atlantic.net/vps-hosting/how-to-install-onlyoffice-document-server-on-debian/ | Published: 2020-11-17 | Updated: 2025-09-03 | Author: Hitesh Jethva ONLYOFFICE Docs is a free and open-source document server for small and medium-sized organizations. This web-based collaboration suite can manage documents, projects, teams, and customer relations from a central location. ONLYOFFICE Docs support several Open XML formats, including .xlsx, .pptx, and .docx, enabling real-time collaborative editing. You can use the ONLYOFFICE Docs API to integrate the ONLYOFFICE Document Editor into your website to manage editors. This tutorial will show you how to install ONLYOFFICE Docs on Debian 12. ## Step 1- Install Nginx and Other Dependencies First, you must install the Nginx webserver to serve the ONLYOFFICE Dcos. You can install it with the following command: ``` apt-get update -y apt-get install nginx nginx-extras -y ``` After installing the Nginx web server, you must install RabbitMQ-server and Redis in your system. You can install both using the following command: ``` apt-get install redis-server rabbitmq-server gnupg2 curl -y ``` Once both packages are installed, start the RabbitMQ and Redis service with the following command: ``` systemctl start rabbitmq-server systemctl start redis-server ``` Once you are finished, you can proceed to the next step. ## Step 2 – Install and Configure PostgreSQL ONLYOFFICE uses PostgreSQL as a database backend, so you must install it on your server. You can install it using the following command: ``` apt-get install postgresql -y ``` Once installed, start the PostgreSQL service with the following command: ``` systemctl start postgresql ``` Next, log into the PostgreSQL shell with the following command: ``` su - postgres postgres@debian12:~$ psql ``` Once logged in, you should get the following output: ``` psql (12.9 (Debian 12.9-0+deb10u1)) Type "help" for help. ``` Next, create a database and user for the Document server with the following command: ``` postgres=# CREATE DATABASE onlyoffice; postgres=# CREATE USER onlyoffice WITH password 'onlyoffice'; postgres=# GRANT ALL privileges ON DATABASE onlyoffice TO onlyoffice; ``` Next, exit from the PostgreSQL shell with the following command: ``` postgres=# EXIT ``` Next, **rerun the exit command**to exit from the Postgres user: ``` exit ``` ## Step 3 – Install ONLYOFFICE Docs By default, the ONLYOFFICE Docs package is unavailable in the Debian 12 default repository, so you must add the ONLYOFFICE Docs repository to your system. First, download and add the GPG key with the following command: ``` mkdir -p -m 700 ~/.gnupg curl -fsSL https://download.onlyoffice.com/GPG-KEY-ONLYOFFICE | gpg --no-default-keyring --keyring gnupg-ring:/tmp/onlyoffice.gpg --import chmod 644 /tmp/onlyoffice.gpg chown root:root /tmp/onlyoffice.gpg mv /tmp/onlyoffice.gpg /usr/share/keyrings/onlyoffice.gpg ``` Next, add the ONLYOFFICE Docs repository with the following command: ``` echo "deb [signed-by=/usr/share/keyrings/onlyoffice.gpg] https://download.onlyoffice.com/repo/debian squeeze main" | tee /etc/apt/sources.list.d/onlyoffice.list ``` Once the storage is added, update the repository with the following command: ``` apt-get update -y ``` Next, download and install the ttf-mscorefonts-installer and other packages using the following command. ``` wget http://ftp.de.debian.org/debian/pool/contrib/m/msttcorefonts/ttf-mscorefonts-installer_3.8.1_all.deb dpkg -i ttf-mscorefonts-installer_3.8.1_all.deb apt install x11-common xfonts-encodings libfontenc1 fonts-dejavu-extra cabextract xfonts-utils libcurl4 libxml2 fonts-dejavu fonts-liberation ttf-mscorefonts-installer fonts-crosextra-carlito fonts-takao-gothic fonts-opensymbol -y ``` You will get some dependency errors after running the above commands. You can fix it with the following management. ``` apt install -f ``` Finally, install the ONLYOFFICE Docs with the following command. ``` apt-get install onlyoffice-documentserver -y ``` During the installation, you will be asked to provide the password as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/11/debian1.png) Provide your ONLYOFFICE database password that you created earlier, then hit Enter to finish the installation: ``` Setting up onlyoffice-documentserver (5.6.5-3) ... Generating AllFonts.js, please wait...Done Generating presentation themes, please wait...Done Congratulations, the ONLYOFFICE docs has been installed successfully! ``` ONLYOFFICE creates an Nginx configuration file automatically during the installation. You can check it with the following command: ``` cat /etc/nginx/conf.d/ds.conf ``` Output: ``` include /etc/nginx/includes/http-common.conf; server { listen 0.0.0.0:80; listen [::]:80 default_server; server_tokens off; include /etc/nginx/includes/ds-*.conf; } ``` Next, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 4 – Access ONLYOFFICE Docs Web UI Now, open your web browser and access the ONLYOFFICE Docs web interface using the URL **http://your-server-ip**. You should see the ONLYOFFICE dashboard on the following screen: ![onlyoffice welcome page](https://www.atlantic.net/wp-content/uploads/2020/11/onlyoffice-welcome-page.png) ![onlyoffice welcome page2](https://www.atlantic.net/wp-content/uploads/2020/11/onlyoffice-welcome-page2.png) Use the integrated test example, a simple doc management system, to check if the editors are running correctly. Run the following command in your terminal. ``` systemctl start ds-example ``` Now, click on the **GO TO TEST EXAMPLE.** You will see your example docs on the following screen. ![onlyoffice example doc](https://www.atlantic.net/wp-content/uploads/2020/11/onlyoffice-example-doc.png) ## Conclusion Congratulations! You have successfully installed the ONLYOFFICE Docs on Debian 12. You can now integrate ONLYOFFICE Docs API into your website and edit your documents. For more information, visit the ONLYOFFICE [documentation](https://api.onlyoffice.com/editors/basic) page. Start using ONLYOFFICE on your Alantic.Net [VPS Hosting](https://www.atlantic.net/vps-hosting/) account! --- # How to Install MyWebSQL on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-mywebsql-on-centos-8/ | Published: 2020-11-18 | Updated: 2023-11-25 | Author: Hitesh Jethva MyWebSQL is a free, open-source, web-based MySQL database client written in PHP. It supports MySQL, PostgreSQL, and SQLite databases, and can be used to perform all database-related operations and is compatible with all major web browsers. MyWebSQL is simple, fast, easy-to-use, and allows you to keep track of your databases from any location and to edit and delete multiple records at the same time. In this tutorial, we will show you how to install MyWebSQL on CentOS 8. ## Step 1 – Install LAMP Server First, you will need to install the Apache web server, MariaDB server, PHP, and other required modules in your system. You can install all of them by running the following command: ``` dnf install httpd mariadb-server php php-cli php-mysqlnd php-zip php-devel php-gd php-mbstring php-curl php-xml php-pear php-bcmath php-json unzip curl wget -y ``` Once all the packages are installed, start the Apache and MariaDB service and enable them to start at system reboot: ``` systemctl start httpd systemctl start mariadb systemctl enable httpd systemctl enable mariadb ``` ## Step 2 – Configure MariaDB Database First, you will need to secure the MariaDB and set a root password. You can do it with the following command: ``` mysql_secure_installation ``` Answer all the questions as shown below: ``` Enter current password for root (enter for none): OK, successfully used password, moving on... Set root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` Once your MariaDB is secured, you can proceed to the next step. ## Step 3 – Download MyWebSQL First, download the latest version of the MyWebSQL with the following command: ``` wget https://downloads.sourceforge.net/project/mywebsql/stable/mywebsql-3.7.zip ``` Once downloaded, unzip the downloaded file with the following command: ``` unzip mywebsql-3.7.zip ``` Next, copy the extracted directory to the Apache root directory: ``` mv mywebsql /var/www/html/ ``` Next, change the ownership of the mywebsql directory to apache: ``` chown -R apache:apache /var/www/html/mywebsql/ ``` Once you are finished, you can proceed to the next step. ## Step 4 – Access MyWebSQL Now, open your web browser and type the URL http://your-server-ip/mywebsql. You will be redirected to the MyWebSQL login page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/mywebsql1.png) Provide your MariaDB root username and password and click on the **Login** button. You should see the MyWebSQL dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/mywebsql2.png) ## Conclusion Congratulations! You have successfully installed MyWebSQL on CentOS 8. I hope you can now easily manage your databases from a central location. MyWebSQL is very useful for those who don’t know how to use the command line. Get started with MyWebSQL on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # How to Allow Remote Connection to MySQL Database Server > URL: https://www.atlantic.net/vps-hosting/how-to-allow-remote-connection-to-mysql-database-server/ | Published: 2020-11-19 | Updated: 2023-11-16 | Author: Hitesh Jethva Many websites and applications host their web server and database backend on the same machine. However, some organizations are moving to a distributed environment. A separate database server can improve hardware performance and security and allows you to scale resources quickly. By default, MySQL is configured to allow connections only from the localhost. You will need to allow remote access to the MySQL database server if your application and database are hosted on different servers. In this tutorial, we will show you how to enable remote connections to a MySQL database. ## Step 1 – Configure MySQL Before starting, verify the MySQL listening connection with the following command: ``` ss -tunlp | grep 3306 ``` You should get the following output: ``` tcp LISTEN 0 151 127.0.0.1:3306 0.0.0.0:* users:(("mysqld",pid=7753,fd=33)) ``` As you can see, the MySQL server is listening on the localhost on port 3306. That means the MySQL server is accessible only from the localhost. You will need to configure MySQL server to listen for an external IP address where the server can be reached. To enable this, edit the mysqld.cnf file: ``` nano /etc/mysql/mysql.conf.d/mysqld.cnf ``` Find the following line: ``` bind-address = 127.0.0.1 ``` And replace it with the following line: ``` bind-address = 0.0.0.0 ``` Save and close the file when you are finished, then, restart the MySQL service to implement the changes: ``` systemctl restart mysql ``` At this point, MySQL server is configured to listen on external IP. ## Step 2 – Grant Access to User from Remote System In this section, we will create a new database and database user and grant access to the remote system to connect to the database. First, log in to the MySQL shell with the following command: ``` mysql ``` Once logged in, create a database named testdb and a user named testuser for a remote system using the following command: ``` CREATE DATABASE testdb; CREATE USER 'testuser'@'remote-server-ip' IDENTIFIED BY 'password'; ``` Next, grant access to the remote system (remote-server-ip) to connect to a database named testdb as a testuser: ``` GRANT ALL PRIVILEGES ON testdb.* TO 'testuser'@'remote-server-ip'; ``` Next, flush the privileges and exit from the MySQL shell with the following command: ``` FLUSH PRIVILEGES ; EXIT; ``` **In the example above:** **testdb**: The name of the database. **testuser**: The name of the user. **remote-server-ip**: The IP address of the remote system. ## Step 3 – Verify Database Connection At this point, MySQL is configured to allow remote connections from the IP remote-server-ip. Now, log in to the remote system and connect to the MySQL server with the following command: ``` mysql -u testuser -h remote-server-ip -p ``` Provide the password for testuser and hit Enter. If everything is set up correctly, you will be able to log in to the remote MySQL server. Next, list the database with the following command: ``` show databases; ``` You should see the following output: ``` +--------------------+ | Database | +--------------------+ | information_schema | | testdb | +--------------------+ 2 rows in set (0.01 sec) ``` ## Conclusion In the above guide, we learned how to enable MySQL remote connection and grant access to the remote system to connect the database, and you can now host your application using a database hosted on the remote server. Get started with a MySQL remote connection on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! We can even help with your HIPAA [compliant database](https://www.atlantic.net/hipaa-compliant-hosting/). --- # How to Install Nginx with RTMP Module on Ubuntu 24.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-nginx-with-rtmp-module-on-ubuntu/ | Published: 2020-11-20 | Updated: 2025-12-21 | Author: Hitesh Jethva RTMP (Real-Time Messaging Protocol) is a streaming protocol originally developed by Macromedia to deliver audio, video, and data over the internet with low latency. It is still widely used today for live video streaming, especially when pushing streams from tools like OBS or FFmpeg to a media server. The Nginx RTMP module extends Nginx into a lightweight yet powerful streaming server. It supports live RTMP streaming, HLS (HTTP Live Streaming) generation, video-on-demand playback, and even on-the-fly transcoding when combined with FFmpeg. Because Nginx is fast, stable, and resource-efficient, it is a popular choice for self-hosted streaming setups. In this tutorial, you will compile Nginx 1.28.0 from source with the RTMP module enabled and set up a live RTMP + HLS streaming server on Ubuntu 24.04. This procedure has been tested on Ubuntu 20.04, 22.04, and 24.04. ## Step 1: Install Required Dependencies First, update your system. ``` apt update -y ``` To compile Nginx with the RTMP module, you need several build tools and libraries. These packages provide compiler support, compression, SSL, media processing, and additional Nginx features such as HTTP streaming and image handling. You can install all required tools using the below command. ``` apt install -y build-essential wget git ffmpeg unzip libpcre3 libpcre3-dev zlib1g zlib1g-dev libssl-dev libxml2 libxml2-dev libxslt1-dev libgd-dev geoip-database libgeoip-dev perl perl-modules ``` Next, create a dedicated system user for Nginx. Running Nginx as a non-login user improves security. ``` useradd -r -s /sbin/nologin nginx ``` ## Step 2: Download Required Components In this step, you will download the Nginx source code, OpenSSL source, and the Nginx RTMP module. These components are required to compile Nginx with RTMP support enabled. First, download the latest Nginx source. ``` wget http://nginx.org/download/nginx-1.28.0.tar.gz ``` After the download completes, extract the archive. ``` tar -xvzf nginx-1.28.0.tar.gz ``` This creates a new directory named nginx-1.28.0 containing the Nginx source files. Nginx will link against OpenSSL during compilation. Download the required OpenSSL version. ``` wget https://www.openssl.org/source/openssl-1.1.0h.tar.gz tar -xzvf openssl-1.1.0h.tar.gz ``` Next, clone the RTMP module repository from GitHub. ``` git clone https://github.com/sergey-dryabzhinsky/nginx-rtmp-module.git ``` This module adds RTMP, HLS, and VOD streaming capabilities to Nginx. ## Step 3: Compile and Install Nginx with RTMP Support Now that all required source components are available, you can compile Nginx with the RTMP module enabled. This step builds a custom Nginx binary with streaming, SSL, and HTTP features. Change into the extracted Nginx source directory. ``` cd nginx-1.28.0 ``` Run the following ./configure command to enable RTMP, SSL, HTTP streaming, and other commonly used modules. ``` ./configure \ --prefix=/etc/nginx \ --sbin-path=/usr/sbin/nginx \ --conf-path=/etc/nginx/nginx.conf \ --error-log-path=/var/log/nginx/error.log \ --http-log-path=/var/log/nginx/access.log \ --pid-path=/var/run/nginx.pid \ --lock-path=/var/run/nginx.lock \ --user=nginx \ --group=nginx \ --with-threads \ --with-file-aio \ --with-http_ssl_module \ --with-http_v2_module \ --with-http_realip_module \ --with-http_addition_module \ --with-http_xslt_module \ --with-http_image_filter_module \ --with-http_geoip_module \ --with-http_sub_module \ --with-http_flv_module \ --with-http_mp4_module \ --with-http_gunzip_module \ --with-http_gzip_static_module \ --with-http_stub_status_module \ --with-stream \ --with-stream_ssl_module \ --with-openssl=../openssl-1.1.0h \ --add-module=../nginx-rtmp-module ``` After the configuration completes successfully, compile and install Nginx. ``` make make install ``` The compilation process may take a few minutes depending on your server’s resources. Check the installed Nginx version and build options. ``` nginx -V ``` You should see output similar to the following, confirming RTMP and OpenSSL support: ``` nginx version: nginx/1.28.0 built by gcc 13.3.0 (Ubuntu 13.3.0-6ubuntu2~24.04) built with OpenSSL 1.1.0h 27 Mar 2018 TLS SNI support enabled configure arguments: --prefix=/etc/nginx --sbin-path=/usr/sbin/nginx --conf-path=/etc/nginx/nginx.conf --error-log-path=/var/log/nginx/error.log --http-log-path=/var/log/nginx/access.log --pid-path=/var/run/nginx.pid --lock-path=/var/run/nginx.lock --user=nginx --group=nginx --with-threads --with-file-aio --with-http_ssl_module --with-http_v2_module --with-http_realip_module --with-http_addition_module --with-http_xslt_module --with-http_image_filter_module --with-http_geoip_module --with-http_sub_module --with-http_flv_module --with-http_mp4_module --with-http_gunzip_module --with-http_gzip_static_module --with-http_stub_status_module --with-stream --with-stream_ssl_module --with-openssl=../openssl-1.1.0h --add-module=../nginx-rtmp-module ``` Once verified, Nginx is successfully installed with RTMP support. In the next step, you will create a systemd service to manage the Nginx service. ## Step 4: Create systemd Service for Nginx Since you compiled Nginx from source, it does not include a systemd service file by default. You need to create one so you can start, stop, and manage Nginx using systemctl. Create a service file. ``` nano /lib/systemd/system/nginx.service ``` Add the following content: ``` [Unit] Description=nginx - high performance web server After=network.target [Service] Type=forking PIDFile=/var/run/nginx.pid ExecStartPre=/usr/sbin/nginx -t ExecStart=/usr/sbin/nginx ExecReload=/bin/kill -s HUP $MAINPID ExecStop=/bin/kill -s TERM $MAINPID [Install] WantedBy=multi-user.target ``` Reload systemd to apply the new service file. ``` systemctl daemon-reload ``` Start the Nginx service. ``` systemctl start nginx ``` Enable Nginx to start automatically at boot. ``` systemctl enable nginx ``` ## Step 5: Configure Nginx RTMP and HLS Streaming With Nginx installed and running, the next step is to configure it for RTMP live streaming, HLS playback, and VOD support. First, backup the Nginx main configuration file. ``` mv /etc/nginx/nginx.conf /etc/nginx/nginx.conf.bak ``` Next, create a new configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the below configuration. ``` worker_processes auto; events { worker_connections 1024; } rtmp { server { listen 1935; chunk_size 4000; application show { live on; hls on; hls_path /mnt/hls; hls_fragment 3; hls_playlist_length 60; deny play all; } application stream { live on; } application vod { play /mnt/mp4s; } } } http { sendfile off; tcp_nopush on; server { listen 8080; location / { root /mnt; add_header Cache-Control no-cache; types { application/vnd.apple.mpegurl m3u8; video/mp2t ts; } } } } ``` Create directories for HLS and VOD content. ``` mkdir -p /mnt/hls /mnt/mp4s chown -R nginx:nginx /mnt ``` Apply the new configuration by restarting Nginx. ``` systemctl restart nginx ``` ## Step 6: Start RTMP Streaming Using FFmpeg Now that the RTMP and HLS server is configured, you can push a live stream to Nginx using FFmpeg. This step helps you verify that RTMP ingestion and playback are working correctly. First, download the sample video file from the URL https://file-examples.com/index.php/sample-video-files/sample-mp4-files/. ``` wget https://file-examples.com/storage/febe13078a694784e9dcb0b/2017/04/file_example_MP4_1280_10MG.mp4 -O myfile.mp4 ``` Use FFmpeg to send the video to the RTMP application configured earlier. ``` ffmpeg -re -i myfile.mp4 -vcodec libx264 -acodec aac -f flv rtmp://your-server-ip:1935/show/vod ``` ## Step 7: Test RTMP and HLS Playback After pushing the stream to the RTMP server, the final step is to confirm that playback works correctly using both RTMP and HLS clients. On the client system, open the VLS media player, go to VLC Media => Open Network Stream. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rtmp1.png) Provide your RTMP streaming server URL and click on the Play button. Once you are connected successfully, you should see your MP4 video in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rtmp2.png) ## Conclusion You have successfully installed Nginx 1.28.0 with the RTMP module on Ubuntu 24.04 and built a working live streaming server from source. This setup allows you to accept incoming RTMP streams, generate HLS segments in real time, and serve them over HTTP for broad device compatibility. --- # Top ps Command Examples to Monitor Your Linux Processes > URL: https://www.atlantic.net/dedicated-server-hosting/top-ps-command-examples-to-monitor-your-linux-processes/ | Published: 2020-11-22 | Updated: 2023-11-21 | Author: Hitesh Jethva The ps command, also called “processes status,” is a tool to view information about running processes on a Linux-based operating system. It is used to monitor all running processes along with USER, PID, %CPU, %MEM, VSZ, RSS, TTY, STAT, and many more. The ps command is very useful, allowing system administrators to find the PID of any process to troubleshoot issues. It is one of the most powerful and essential process management tools that every Linux user should know and learn. ## 1. List All Processes of the Current User You can use the ps command without any parameters to display a list of all running processes started by the user who ran the command. ``` ps ``` You should see the following output: ``` PID TTY TIME CMD 3871 pts/5 00:00:00 bash 5633 pts/5 00:00:00 ps ``` As you can see, there are four columns. A brief explanation of each column is shown below: **PID :** Specifies the process ID of the process. **TTY :** Specifies the name of the console the user logged in. **TIME :** Specifies the amount of CPU processing time. **CMS :** Specifies the command used to launch the process. ## 2. List Processes for All Users You can list all processes started by all users using the following command: ``` ps -ef | less ``` or ``` ps ax | less ``` You should see all the processes in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/ps1.png) ## 3. List Processes by User You can also filter the processes using the option -u followed by the username. For example, to list all processes owned by www-data user, use the following command: ``` ps -f -u www-data ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/ps2.png) You can also specify multiple usernames using a comma. For example, to list all processes owned by the www-data and root users, use the following command: ``` ps -f -u www-data,root ``` ## 4. List Processes by Name or PID To list the processes, by name use the -C option with search term. For example, to list the processes of MySQL, run the following command: ``` ps -C mysqld ``` Or ``` ps -ef | grep mysql ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/ps3.png) You can also list the processes by process id using the -p option. ``` ps -f -p 11560 ``` You should see the Apache process in the following output: ``` UID PID PPID C STIME TTY TIME CMD www-data 11560 11559 0 Jun12 ? 00:00:00 /usr/sbin/apache2 -k start ``` ## 5. Sort Processes by CPU and Memory Usage Sometimes you will need to find out processes that are consuming lots of CPU and Memory. In this case, you can sort the process list based on a specific field or parameter. Run the following command to list the top 10 processes consuming most of the CPU and Memory: ``` ps aux --sort=-pcpu,+pmem | head -10 ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/ps4.png) ## 6. Display Processes in Realtime You can also display the top CPU and Memory consuming processes using the watch command with ps: ``` watch -n 1 'ps -e -o pid,uname,cmd,pmem,pcpu --sort=-pmem,-pcpu | head -15' ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/ps5.png) ## 7. List the Process Tree Some processes are forked out of parent processes. This can help you to figure out an issue or identify a particular process. You can use -e option with –forest to show how processes are linked in a Linux. ``` ps -e --forest ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/ps6.png) ## 8. Display Elapsed Time of Running Processes You can find out how long the process has been running for using the -o option: ``` ps -e -o pid,comm,etime | less ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/ps111.png) ## Conclusion In the above guide, you learned how to use the ps command to monitor Linux processes. Try using the ps command today on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Seafile to Sync and Share Files on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-seafile-to-sync-and-share-files-on-centos-8/ | Published: 2020-11-23 | Updated: 2023-11-25 | Author: Hitesh Jethva Seafile is a free, open-source, self-hosted file-sharing solution for Linux. It is a cross-platform file-hosting software that can be used to store files on a central server and sync them with your personal computer or mobile device. Seafile is written with Python Django framework and is functionally very similar to Dropbox and Google Drive. It has a lot of features including file encryption, version control, two-factor authentication, online editing, file locking, and many more. In this tutorial, we will show you how to install Seafile with Nginx as a reverse proxy on CentOS 8. ## Prerequisites - A fresh CentOS 8 [VPS](https://www.atlantic.net/vps-hosting/) - A valid domain name pointed to your server IP - A root password is configured on your server ## Step 1 – Install Required Dependencies First, you will need to install the EPEL repository in your system. You can install it with the following command: ``` yum install epel-release -y ``` Once the EPEL repository is installed, install other dependencies with the following command: ``` yum install python3 python3-devel python3-setuptools gcc gcc-c++ freetype-devel python3-pip python3-ldap memcached java-1.8.0-openjdk libmemcached libreoffice-headless libreoffice-pyuno libffi-devel pwgen curl tar -y ``` Once all the dependencies are installed, use the pip command to install other dependencies: ``` pip3 install Pillow pylibmc captcha jinja2 sqlalchemy psd-tools django-pylibmc django-simple- captcha ``` Once all the packages are installed, enable the Memcached service to start at system reboot: ``` systemctl enable --now memcached ``` ## Step 2 – Install Nginx and MariaDB Next, you will need to install Nginx and MariaDB server on your system. You can install both packages with the following command: ``` yum install nginx mariadb-server -y ``` Once installed, start the Nginx and MariaDB services and enable them to start at system reboot: ``` systemctl start nginx systemctl start mariadb systemctl enable nginx systemctl enable mariadb ``` ## Step 3 – Create a Database for Seafile First, you will need to set the MariaDB root password and secure the MariaDB installation. You can do it using the following script: ``` mysql_secure_installation ``` Answer all the questions as shown below: ``` Enter current password for root (enter for none): Set root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` Next, log in to the MariaDB shell with the following command: ``` mysql -u root -p ``` Once logged in, create a database for Seafile with the following command: ``` create database `ccnetdb` character set = 'utf8'; create database `seafiledb` character set = 'utf8'; create database `seahubdb` character set = 'utf8'; ``` Next, create a user for Seafile with the following command: ``` create user 'seafile'@'localhost' identified by 'yourpassword'; ``` Next, grant all the privileges to the ccnetdb, seafiledb and seahubdb with the following command: ``` GRANT ALL PRIVILEGES ON `ccnetdb`.* to `seafile`@localhost; GRANT ALL PRIVILEGES ON `seafiledb`.* to `seafile`@localhost; GRANT ALL PRIVILEGES ON `seahubdb`.* to `seafile`@localhost; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 4 – Install Seafile First, download the latest version of Seafile with the following command: ``` wget https://s3.eu-central-1.amazonaws.com/download.seadrive.org/seafile-server_7.1.5_x86- 64.tar.gz ``` Once downloaded, extract the downloaded file with the following command: ``` tar -xvzf seafile-server_7.1.5_x86-64.tar.gz ``` Next, move the extracted directory to /opt with the following command: ``` mv seafile-server-* /opt/seafile cd /opt/seafile ``` Next, change the directory to /opt/seafile and set up the Seafile server by running the following script: ``` ./setup-seafile-mysql.sh ``` You will be asked to provide the server name, valid domain name, and database details as shown below. ``` Checking python on this machine ... ----------------------------------------------------------------- This script will guide you to setup your seafile server using MySQL. Make sure you have read seafile server manual at https://download.seafile.com/published/seafile-manual/home.md Press ENTER to continue ----------------------------------------------------------------- What is the name of the server? It will be displayed on the client. 3 - 15 letters or digits [ server name ] seafile What is the ip or domain of the server? For example: www.mycompany.com, 192.168.1.101 [ This server's ip or domain ] seafile.example.com Which port do you want to use for the seafile fileserver? [ default "8082" ] ------------------------------------------------------- Please choose a way to initialize seafile databases: ------------------------------------------------------- [1] Create new ccnet/seafile/seahub databases [2] Use existing ccnet/seafile/seahub databases [ 1 or 2 ] 2 What is the host of mysql server? [ default "localhost" ] What is the port of mysql server? [ default "3306" ] Which mysql user to use for seafile? [ mysql user for seafile ] seafile What is the password for mysql user "seafile"? [ password for seafile ] verifying password of user seafile ... done Enter the existing database name for ccnet: [ ccnet database ] ccnetdb verifying user "seafile" access to database ccnetdb ... done Enter the existing database name for seafile: [ seafile database ] seafiledb verifying user "seafile" access to database seafiledb ... done Enter the existing database name for seahub: [ seahub database ] seahubdb verifying user "seafile" access to database seahubdb ... done ``` Provide each detail carefully. Once the installation has been completed, you should see the following output: ``` --------------------------------- This is your configuration --------------------------------- server name: seafile server ip/domain: seafile.example.com seafile data dir: /opt/seafile-data fileserver port: 8082 database: use existing ccnet database: ccnetdb seafile database: seafiledb seahub database: seahubdb database user: seafile --------------------------------- Press ENTER to continue, or Ctrl-C to abort ----------------------------------------------------------------- Your seafile server configuration has been finished successfully. ----------------------------------------------------------------- run seafile server: ./seafile.sh { start | stop | restart } run seahub server: ./seahub.sh { start | stop | restart } ----------------------------------------------------------------- If you are behind a firewall, remember to allow input/output of these tcp ports: ----------------------------------------------------------------- port of seafile fileserver: 8082 port of seahub: 8000 When problems occur, Refer to https://download.seafile.com/published/seafile-manual/home.md for information. ``` ## Step 5 – Set Up Admin Account Next, you will need to set up an admin account to access Seafile. First, start the Seafile service with the following command: ``` /opt/seafile/seafile.sh start ``` Next, start the Seahub service to set an admin password: ``` /opt/seafile/seahub.sh start ``` You will be asked to set an admin username and password as shown below. ``` LC_ALL is not set in ENV, set to en_US.UTF-8 Starting seahub at port 8000 ... ---------------------------------------- It's the first time you start the seafile server. Now let's create the admin account ---------------------------------------- What is the email for the admin account? [ admin email ] admin@example.com What is the password for the admin account? [ admin password ] Enter the password again: [ admin password again ] ---------------------------------------- Successfully created seafile admin ---------------------------------------- ``` Next, stop the Seafile and Seahub services with the following command: ``` /opt/seafile/seafile.sh stop /opt/seafile/seahub.sh stop ``` ## Step 6 – Create a Systemd Service File for Seafile Next, you will need to create systemd service files for Seafile and Seahub to manage the services. First, create a service file for Seafile using the following command: ``` nano /etc/systemd/system/seafile.service ``` Add the following lines: ``` [Unit] Description=Seafile After= mysql.service After=network.target [Service] Type=forking ExecStart=/opt/seafile-server-latest/seafile.sh start ExecStop=/opt/seafile-server-latest/seafile.sh stop [Install] WantedBy=multi-user.target ``` Save and close the file, then create a service file for Seahub with the following command: ``` nano /etc/systemd/system/seahub.service ``` Add the following lines: ``` [Unit] Description=Seafile After= mysql.service After=network.target [Service] Type=forking ExecStart=/opt/seafile-server-latest/seahub.sh start ExecStop=/opt/seafile-server-latest/seahub.sh stop [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the Seafile and Seahub service and enable them to start at system reboot with the following command: ``` systemctl start seafile systemctl enable seafile systemctl start seahub systemctl enable seahub ``` At this point, Seafile server is started and listening on port 8000. You can verify it with the following command: ``` ss -tunelp | grep 8000 ``` You should get the following output: ``` tcp LISTEN 0 128 127.0.0.1:8000 0.0.0.0:* users:(("python3",pid=44925,fd=8),("python3",pid=44924,fd=8),("pyt hon3",pid=44923,fd=8),("python3",pid=44922,fd=8),("python3",pid=44921,fd=8),("python3",pid=44916,fd=8)) ino:77620 sk:9 <-> ``` ## Step 7 – Configure Nginx for Seafile Next, you will need to configure Nginx as a reverse proxy to access Seafile using port 80. You can configure it with the following command: ``` nano /etc/nginx/conf.d/seafile.conf ``` Add the following lines: ``` server { listen 80; listen [::]:80; server_name seafile.example.com; autoindex off; client_max_body_size 100M; access_log /var/log/nginx/seafile.com.access.log; error_log /var/log/nginx/seafile.com.error.log; location / { proxy_pass http://127.0.0.1:8000; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Host $server_name; proxy_read_timeout 1200s; } location /seafhttp { rewrite ^/seafhttp(.*)$ $1 break; proxy_pass http://127.0.0.1:8082; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_connect_timeout 36000s; proxy_read_timeout 36000s; proxy_send_timeout 36000s; send_timeout 36000s; } location /media { root /opt/seafile-server-latest/seahub; } } ``` Save and close the file, then restart the Nginx service with the following command: ``` systemctl restart nginx ``` If you got any errors, then edit the Nginx.conf file: ``` nano /etc/nginx/nginx.conf ``` Add the following line below http {: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then restart the Nginx service: ``` systemctl restart nginx ``` ## Step 8 – Access Seafile Web Interface At this point, Nginx is configured to serve Seafile. Now, open your web browser and access the Seafile web interface using the URL **http://seafile.example.com**. You will be redirected to the Seafile login page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/seafile1.png) Provide your admin username and password and click on the **Login** button. You should see the Seafile dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/seafile2.png) ## Conclusion In the above tutorial, you learned how to install the Seafile server with Nginx as a reverse proxy on CentOS 8. You can now upload your files and personal photos to the Seafile server, share them with your friends, and access them from your computer or mobile device. Try Seafile on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net using the tutorial above! --- # How to Install Mailtrain Newsletter Application on Ubuntu 20.04. > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-mailtrain-newsletter-application-on-ubuntu-20-04/ | Published: 2020-11-24 | Updated: 2023-11-14 | Author: Hitesh Jethva Mailtrain is a free, open-source, self-hosted newsletter application and email marketing tool. It is built on Node.js and uses MySQL/MariaDB as a database backend. Mailtrain is not only a newsletter app, but also provides other features including list management, a template editor, RSS campaigns, custom fields, and much more. You can integrate Mailtrain with an external SMTP server or use a local SMTP server to send emails, and you can use the RSS feed to generate a newsletter automatically and send emails to all subscribers. In this tutorial, we will learn how to install Mailtrain Newsletter Application on Ubuntu 20.04. ## Step 1 – Install and Configure MariaDB Server Mailtrain uses MySQL/MariaDB as a database backend, so a MariaDB server must be installed in your system. If not installed, you can install it using the following command: ``` apt-get install mariadb-server mariadb-client -y ``` After installing the MariaDB server, you will need to set up a MariaDB root password. You can set up it with the following command: mysql_secure_installation Answer all the questions as shown below to reset the root password and secure MariaDB: ``` Enter current password for root (enter for none): Set root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` Next, log in to MariaDB and create a database and user for Mailtrain. ``` mysql -u root -p ``` Provide your MariaDB root password, then create a database with the following command: ``` create database mailtrain; ``` Next, create a user and grant all the privileges to the Mailtrain database: ``` grant all privileges on mailtrain.* to mailtrain@localhost identified by 'password'; grant all privileges on mailtrain.* to mailtrain_readonly@localhost identified by 'password'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` flush privileges; exit; ``` ## Step 2 – Install Node.js Mailtrain is built on Node.js, so you will need to install it in your system. In this tutorial, we will install Node.js using Snapd, so you will need to install Snapd and other packages in your system. You can install them with the following command: ``` apt-get install snapd git build-essential -y ``` Once all the required packages are installed, run the following command to install Node.js: ``` snap install node --classic --channel=8/stable ``` Next, log out of the system and log in again to activate the snapd. Once logged in, verify the Node.js version using the following command: ``` node -v ``` You should see the following output: ``` v8.16.0 ``` ## Step 3 – Install and Configure Mailtrain First, create a separate user and group for Mailtrain. ``` adduser --system --group mailtrain ``` You should see the following output: ``` Adding system user `mailtrain' (UID 112) ... Adding new group `mailtrain' (GID 121) ... Adding new user `mailtrain' (UID 112) with group `mailtrain' ... Creating home directory `/home/mailtrain' ... ``` Next, create a directory for Mailtrain with the following command: ``` mkdir -p /var/www/html ``` Next, change the directory to /var/www/html and download the latest version of Mailtrain from the Git repository using the following command: ``` cd /var/www/html git clone https://github.com/Mailtrain-org/mailtrain.git ``` Next, import the Mailtrain database with the following command: ``` mariadb -u mailtrain -p mailtrain < /var/www/html/mailtrain/setup/sql/mailtrain.sql ``` Next, create a new Mailtrain configuration file: ``` nano /var/www/html/mailtrain/config/production.toml ``` Add the following lines: ``` user="mailtrain" group="mailtrain" [log] level="error" [www] port="3000" # HTTP interface to listen on host="0.0.0.0" [mysql] host="localhost" user="mailtrain" password="password" database="mailtrain" [queue] processes=5 ``` Save and close the file, then create a configuration file for the report worker. ``` nano /var/www/html/mailtrain/workers/reports/config/production.toml ``` Add the following lines: ``` [log] level="error" [mysql] user="mailtrain_readonly" password="password" ``` Next, change the ownership and permissions of the mailtrain directory: ``` chown -R mailtrain:mailtrain /var/www/html/mailtrain/ chmod -R 775 /var/www/html/mailtrain/ ``` Next, you will also need to install Python version 2.7 and create a symlink: ``` apt-get install python2.7 -y ln -s /usr/bin/python2.7 /usr/bin/python ``` Next, change the directory to mailtrain and install required node packages with the following command: ``` cd /var/www/html/mailtrain sudo -u mailtrain npm config set scripts-prepend-node-path true sudo -u mailtrain npm install --no-progress --production --unsafe-perm=true ``` ## Step 4 – Create a Systemd Service File for Mailtrain Next, you will need to create a systemd service file to manage the Mailtrain application. You can create it with the following command: ``` nano /etc/systemd/system/mailtrain.service ``` Add the following lines: ``` [Unit] Description=Mailtrain server #Requires=mysql.service After=syslog.target network.target [Service] Environment="NODE_ENV=production" WorkingDirectory=/var/www/html/mailtrain ExecStart=/snap/bin/node index.js Type=simple Restart=always RestartSec=10 [Install] WantedBy=multi-user.target # Alias=mailtrain.service ``` Save and close the file, then reload the systemd daemon to apply the changes: ``` systemctl daemon-reload ``` Next, start the Mailtrain service and enable it to start at system reboot with the following command: ``` systemctl start mailtrain systemctl enable mailtrain ``` Next, verify the status of Mailtrain with the following command: ``` systemctl status mailtrain ``` You should get the following output: - ``` mailtrain.service - Mailtrain server Loaded: loaded (/etc/systemd/system/mailtrain.service; disabled; vendor preset: enabled) Active: active (running) since Fri 2020-10-30 06:11:52 UTC; 18s ago Main PID: 31946 (mailtrain) Tasks: 20 (limit: 4691) Memory: 231.0M CGroup: /system.slice/mailtrain.service ├─31946 mailtrain └─31986 /snap/node/2310/bin/node /var/www/html/mailtrain/services/sender.js ``` ``` Oct 30 06:11:52 ubuntu2004 systemd[1]: Started Mailtrain server. ``` At this point, Mailtrain is started and listening on port 3000. You can verify it with the following command: ``` ss -tunelp | grep 3000 ``` You should get the following output: ``` tcp LISTEN 0 511 0.0.0.0:3000 0.0.0.0:* users:(("mailtrain",pid=32013,fd=10)) ino:79343 sk:11 <-> ``` ## Step 5 – Access Mailtrain Web Interface Now, open your web browser and access the Mailtrain using the URL **http://your-server-ip:3000**. You will be redirected to the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/mailtrain1.png) Now, click on the **Sign** **in** button. You should see the Mailtrain login page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/mailtrain2.png) Provide default username as **admin** and the password as **test** then click on the **Sign**–**in** button. You should see the Mailtrain default dashboard on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/mailtrain3.png) ## Conclusion Congratulations! You have successfully installed and configured the Mailtrain newsletter application on Ubuntu 20.04. Now, you can configure the SMTP server setting or use an external SMTP server and start managing your email subscription lists. Start using Mailtrain today on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure Nextcloud on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-configure-nextcloud-on-ubuntu-20-04/ | Published: 2020-11-25 | Updated: 2024-03-04 | Author: Hitesh Jethva Nextcloud is a free, open-source file share and collaboration platform – the most widely used one – that allows you to host your own file hosting services. It is a fork of ownCloud and very similar to other storage solutions including Dropbox, Google Drive, and others. Nextcloud allows you to store your personal contents, files, documents, and photos and share them with your friends and family. It comes with a lot of add-ons that help you to extend its functionality. In this tutorial, we will show you how to install Nextcloud server and client on Ubuntu 20.04. ## Prerequisites - A fresh Ubuntu 20.04 [VPS](https://www.atlantic.net/vps-hosting/) on the Atlantic.Net Cloud Platform - A desktop system running Ubuntu 20.04 - A valid domain name pointed to your server IP - A root password configured on your server ## Step 1 – Install LAMP Server Before starting, a LAMP stack must be installed on your server. If not installed, you can install them with the following command: ``` apt-get install apache2 mariadb-server libapache2-mod-php php php-gmp php-bcmath php-gd php- json php-mysql php-curl php-mbstring php-intl php-imagick php-xml php-zip bzip2 -y ``` Once all the packages are installed, edit the php.ini file and modify some of the values according to your requirements. ``` nano /etc/php/7.4/apache2/php.ini ``` Change the following lines: ``` memory_limit = 512M date.timezone = Asia/Kolkata ``` Save and close the file when you are finished, then restart the Apache service to apply the changes: ``` systemctl restart apache2 ``` ## Step 2 – Create a Nextcloud Database Next, you will need to create a database and user for Nextcloud. First, connect to MariaDB with the following command: ``` mysql ``` Once connected, create a database and user with the following command: ``` create database nextclouddb; grant all on nextclouddb.* to 'nextcloud'@'localhost' identified by 'yourpassword'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` flush privileges; exit; ``` ## Step 3 – Download Nextcloud First, download the latest version of Nextcloud from its official website with the following command: ``` wget https://download.nextcloud.com/server/releases/latest-20.tar.bz2 ``` Once the download is completed, extract the downloaded file with the following command: ``` tar -jxvf latest-20.tar.bz2 ``` Next, move the extracted directory to the Apache web root directory and give proper permissions with the following command: ``` mv nextcloud /var/www/html/ chown -R www-data:www-data /var/www/html/nextcloud chmod -R 775 /var/www/html/nextcloud ``` Once you are done, you can proceed to configure the Apache server. ## Step 4 – Configure Apache for Nextcloud Next, you will need to create an Apache virtual host configuration file to serve Nextcloud. You can create it with the following command: ``` nano /etc/apache2/sites-available/nextcloud.conf ``` Add the following lines: ``` DocumentRoot "/var/www/html/nextcloud" ServerName nextcloud.example.com ErrorLog ${APACHE_LOG_DIR}/nextcloud.error CustomLog ${APACHE_LOG_DIR}/nextcloud.access combined Require all granted Options FollowSymlinks MultiViews AllowOverride All Dav off SetEnv HOME /var/www/html/nextcloud SetEnv HTTP_HOME /var/www/html/nextcloud Satisfy Any ``` Save and close the file, then enable the Apache virtual host with the following command: ``` a2ensite nextcloud.conf ``` Next, enable the required Apache modules with the following command: ``` a2enmod rewrite headers env dir mime setenvif ssl ``` Next, restart the Apache service to apply the configuration changes: ``` systemctl restart apache2 ``` At this point, Apache web server is configured to serve Nextcloud. ## Step 5 – Access Nextcloud Now, open your web browser and access the Nextcloud using the URL **http://nextcloud.example.com**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/nextcloud1.png) ![](https://www.atlantic.net/wp-content/uploads/2020/11/nextcloud2.png) Set your admin username and password, define your database settings, and click on the **Finish** setup page. You should see the Nextcloud dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/nextcloud3.png) ![](https://www.atlantic.net/wp-content/uploads/2020/11/nextcloud4.png) ## Step 6 – Install and Configure Nextcloud Client Nextcloud provides a client application for Android, Windows, iOS that can be used to connect your Nextcloud server. It allows users to access and sync files on the go. On the client machine, install the Nextcloud application using the following command: ``` apt-get install software-properties-common gnupg2 -y add-apt-repository ppa:nextcloud-devs/client apt-get update -y apt-get install nextcloud-client -y ``` Once the application is installed, launch the Nextcloud application from your Ubuntu DASH. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/nextcloud5.png) Provide your Nextcloud server URL and click on the **Next** button. You will be asked to provide your Nextcloud username and password: ![](https://www.atlantic.net/wp-content/uploads/2020/11/nextcloud6.png) Provide your username and password and click on the **Next** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/nextcloud7.png) Select your desired settings and click on the **Connect** button. Once connected, you should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/nextcloud8.png) Select OpenLocal Folder and click on the **Finish** button. You should see your Nextcloud folder in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/nextcloud9.png) You can now easily put any files and folders inside this directory and synchronize them with Nextcloud. ## Conclusion In this guide, you learned how to install Nextcloud on Ubuntu 20.04 server. You also learned how to install the Nextcloud client on the Desktop machine and connect it with the Nextcloud server. You can now easily save and share your personal content with your friends and family. Try out Nextcloud on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # How to Setup Private Docker Registry on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-setup-private-docker-registry-on-ubuntu-20-04/ | Published: 2020-11-26 | Updated: 2023-11-21 | Author: Hitesh Jethva Docker Registry is a centralized application that can be used to store your images and share them with other users. The private registry gives you full control to protect your images. You can also use Docker Hub to store your images, but these images will be public and anyone can access them. In this tutorial, we will show you how to set up your own private Docker registry on Ubuntu 20.04. ## Step 1 – Setup Hostname Resolution First, you will need to set up the hostname resolution on **both** the **registry server** and the **client machine** so that they can communicate with each other using the hostname. You set up it by editing /etc/hosts file on both server and client machine: ``` nano /etc/hosts ``` Add the following lines: ``` your-server-ip registry-server your-client-ip registry-client ``` Save and close the file when you are finished. ## Step 2 – Install Docker Next, you will need to install Docker on **both the server and client** machines. By default, the latest version of Docker is not available in the Ubuntu 20.04 default repository, so you will need to add the Docker repository in your system. First, install the required dependencies with the following command: ``` apt-get install apt-transport-https ca-certificates curl software-properties-common curl -y ``` After installing all dependencies, import the Docker GPG key using the following command: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add - ``` Next, add the Docker CE official repository to the APT source file with the following command: ``` add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu $(lsb_release - cs) stable" ``` Once the repository has been added, you will need to update the repository cache. You can update it with the following command: ``` apt-get update -y ``` Once your repository is up-to-date, run the following command to install the latest version of Docker CE to your system. ``` apt-get install docker-ce -y ``` Once the installation is completed, you can verify the installed version of Docker CE by running the following command: ``` docker --version ``` You should get the following output: ``` Docker version 19.03.13, build 4484c46d9d ``` At this point, Docker CE is installed on both the registry server and the client machine. ## Step 3 – Install and Configure Registry Server Next, you will need to install and configure the registry server on the server machine. First, download the registry image from the Docker hub with the following command: ``` docker pull registry ``` You should get the following output: Using default tag: latest ``` latest: Pulling from library/registry cbdbe7a5bc2a: Pull complete 47112e65547d: Pull complete 46bcb632e506: Pull complete c1cc712bcecd: Pull complete 3db6272dcbfa: Pull complete Digest: sha256:8be26f81ffea54106bae012c6f349df70f4d5e7e2ec01b143c46e2c03b9e551d Status: Downloaded newer image for registry:latest docker.io/library/registry:latest ``` By default, Docker uses a secure connection over TLS to upload and download the images, so you will need to create a self-signed certificate for the registry server. First, create a directory to store the certificates: ``` mkdir /etc/certs ``` Next, change the directory to the /etc/certs and generate a self-signed certificate with the following command: ``` cd /etc/certs openssl req -newkey rsa:4096 -nodes -sha256 -keyout ca.key -x509 -days 365 -out ca.crt ``` Provide all details as shown below to generate the certificate: ``` Generating a RSA private key ....................................++++ ......++++ writing new private key to 'ca.key' ----- You are about to be asked to enter information that will be incorporated into your certificate request. What you are about to enter is what is called a Distinguished Name or a DN. There are quite a few fields but you can leave some blank For some fields, there will be a default value, If you enter '.', the field will be left blank. ----- Country Name (2 letter code) [AU]:IN State or Province Name (full name) [Some-State]:GUJ Locality Name (eg, city) []:JUNAGADH Organization Name (eg, company) [Internet Widgits Pty Ltd]:IT Organizational Unit Name (eg, section) []:IT Common Name (e.g. server FQDN or YOUR name) []:registry-server Email Address []:admin@example.com ``` Once the certificate is generated, start the registry container from the downloaded image using the self-signed certificate with the following command: ``` docker run -d -p 5000:5000 --restart=always --name registry -v /etc/certs:/etc/certs -e REGISTRY_HTTP_TLS_CERTIFICATE=/etc/certs/ca.crt -e REGISTRY_HTTP_TLS_KEY=/etc/certs/ca.key registry ``` Next, verify the running container by running the following command: ``` docker ps ``` You should get the following output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 90f4155f3926 registry "/entrypoint.sh /etc…" 4 seconds ago Up 2 seconds 0.0.0.0:5000->5000/tcp registry ``` At this point, your registry server is installed and running. ## Step 4 – Create a Custom Image on Registry Client For this tutorial, we will download Ubuntu 20.04 server image on the client machine, create a new container, install the Apache server inside the container, build the new image and upload this image to the registry server. First, download the Ubuntu 20.04 server image and create a container with the following command: ``` docker container run -it ubuntu:20.04 /bin/bash ``` This will download the Ubuntu 20.04 image from the Docker hub, create a new container, and attach it to the bash shell: ``` Unable to find image 'ubuntu:20.04' locally 20.04: Pulling from library/ubuntu 6a5697faee43: Already exists ba13d3bc422b: Already exists a254829d9e55: Already exists Digest: sha256:fff16eea1a8ae92867721d90c59a75652ea66d29c05294e6e2f898704bdb8cf1 Status: Downloaded newer image for ubuntu:20.04 root@ee2cc97397fb:/# ``` Next, run the following command to update the system and install the apache webserver: ``` root@ee2cc97397fb:/#apt-get update -y root@ee2cc97397fb:/#apt-get install apache2 -y ``` Next, exit from the running container with the following command: ``` root@ee2cc97397fb:/#exit ``` Next, you will need to rename or tag the Ubuntu 20.04 image in “**registryserver:portnumber/image name:tag**” format. You can tag it with the following command: ``` docker tag ubuntu:20.04 registry-server:5000/ubuntu:apachev1.0 ``` Next, verify your new image with the following command: ``` docker images ``` You should get the following output: ``` REPOSITORY TAG IMAGE ID CREATED SIZE ubuntu 20.04 d70eaf7277ea 13 days ago 72.9MB registry-server:5000/ubuntu apachev1.0 d70eaf7277ea 13 days ago 72.9MB ``` ## Step 5 – Upload New Image to Registry Server First, you will need to create a new certificate directory on the client machine and copy the ca.crt file from the registry server: First, create a cert directory with the following command: ``` mkdir -p /etc/docker/certs.d/registry-server:5000 ``` Next, copy the ca.crt file from the registry server to the client machine: ``` scp root@registry-server:/etc/certs/ca.crt /etc/docker/certs.d/registry-server:5000/ ``` Next, restart the Docker service to use this certificate: ``` systemctl restart docker ``` Next, upload your newly created image to the registry server with the following command: ``` docker push registry-server:5000/ubuntu:apachev1.0 ``` You should get the following output: The push refers to repository [registry-server:5000/ubuntu] ``` cc9d18e90faa: Pushed 0c2689e3f920: Pushed 47dde53750b4: Pushed apachev1.0: digest: sha256:1d7b639619bdca2d008eca2d5293e3c43ff84cbee597ff76de3b7a7de3e84956 size: 943 ``` ## Conclusion Congratulations! You have successfully set up the Docker registry server and client on Ubuntu 20.04. You can now download and upload your own customized images to and from the registry server. Give it a shot on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to install Brotli Module for Nginx on Ubuntu > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-brotli-module-for-nginx-on-ubuntu/ | Published: 2020-11-30 | Updated: 2025-05-23 | Author: Hitesh Jethva Nginx is a free, open-source, high-performance web server and proxy server used around the world. Brotli is a compression algorithm developed by Google. It can be used as an alternative to other compression methods such as Gzip, Zopfli, and Deflate. By default, Nginx does not support Brotli compression, so you will need to compile Nginx with Brotli support. Brotli works well for the compression of static resources like HTML, JS, CSS, and JSON. In this tutorial, we will show you how to install the Brotli module with Nginx on Ubuntu 24.04. ## Step 1 – Install Required Dependencies Before starting, you will need to install some dependencies required to compile Nginx in your system. You can install all of them with the following command: ``` apt-get install dpkg-dev build-essential gnupg2 git gcc cmake libpcre3 libpcre3-dev zlib1g zlib1g- dev openssl libssl-dev curl unzip libbrotli-dev -y ``` Once all the packages are installed, you can proceed to the next step. ## Step 2 – Add Nginx Repository Next, you will need to add the Nginx official repository to download the latest version of the Nginx source. First, import the Nginx GPG key with the following command: ``` curl -L https://nginx.org/keys/nginx_signing.key | apt-key add - ``` Next, add the Nginx repository with the following command: ``` nano /etc/apt/sources.list.d/nginx.list ``` Add the following lines: ``` deb http://nginx.org/packages/ubuntu/ noble nginx deb-src http://nginx.org/packages/ubuntu/ noble nginx ``` Save and close the file when you are finished. Next, update the repository with the following command: ``` apt-get update -y ``` Once your repository is updated, you can proceed to the next step. ## Step 3 – Install Nginx with Brotli Support First, download the latest version of the Nginx source with the following command: ``` cd /usr/local/src apt-get source nginx ``` Next, install the required dependencies to build Nginx: ``` apt-get build-dep nginx -y ``` Next, download the latest version of Brotli from the Git repository using the following command: ``` git clone --recursive https://github.com/google/ngx_brotli.git ``` Next, change the directory to the Nginx source and edit the rules file: ``` cd /usr/local/src/nginx-*/ nano debian/rules ``` Find the **‘config.env.nginx**‘ and **‘config.env.nginx_debug’** section and add the following line within **./configure** line: ``` --add-module=/usr/local/src/ngx_brotli ``` Save and close the file, then compile and build the nginx package with the following command: ``` dpkg-buildpackage -b -uc -us ``` The above command will generate Nginx .deb files inside /usr/local/src directory. You can list them with the following command: ``` ls /usr/local/src/*.deb ``` You should see both files in the following output: ``` /usr/local/src/nginx_1.28.0-1~noble_amd64.deb /usr/local/src/nginx-dbg_1.28.0-1~noble_amd64.deb ``` Next, install the Nginx by running the both *.deb file: ``` dpkg -i /usr/local/src/*.deb ``` ## Step 4 – Configure Nginx to Use Brotli Next, you will need to configure Nginx to use Brotli module. You can do it by editing the Nginx main configuration file: ``` nano /etc/nginx/nginx.conf ``` Add the following lines inside the http { section: ``` brotli on; brotli_comp_level 6; brotli_static on; brotli_types text/plain text/css application/javascript application/x-javascript text/xml application/xml application/xml+rss text/javascript image/x-icon image/vnd.microsoft.icon image/bmp image/svg+xml; ``` Save and close the file, then verify the Nginx for any syntax errors: ``` nginx -t ``` You should get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Next, start the Nginx service using the following command: ``` systemctl start nginx ``` You can verify the status of the Nginx service with the following command: ``` systemctl status nginx ``` You should get the following output: ``` ● nginx.service - nginx - high performance web server Loaded: loaded (/usr/lib/systemd/system/nginx.service; enabled; preset: enabled) Active: active (running) since Fri 2025-05-23 11:06:17 UTC; 3s ago Docs: https://nginx.org/en/docs/ Process: 56231 ExecStart=/usr/sbin/nginx -c ${CONFFILE} (code=exited, status=0/SUCCESS) Main PID: 56232 (nginx) Tasks: 5 (limit: 9440) Memory: 4.6M (peak: 4.8M) CPU: 16ms CGroup: /system.slice/nginx.service ├─56232 "nginx: master process /usr/sbin/nginx -c /etc/nginx/nginx.conf" ├─56233 "nginx: worker process" ├─56234 "nginx: worker process" ├─56235 "nginx: worker process" └─56236 "nginx: worker process" ``` ## Step 5 – Verify Brotli Module At this point, Nginx is installed and configured with Brotli support. Now, verify whether the Brotli module is enabled or not by running the following command: ``` curl -H 'Accept-Encoding: br' -I http://localhost ``` You should get the “Content-Encoding: br” in the following output: ``` HTTP/1.1 200 OK Server: nginx/1.28.0 Date: Fri, 23 May 2025 11:06:40 GMT Content-Type: text/html Last-Modified: Wed, 23 Apr 2025 11:48:54 GMT Connection: keep-alive ETag: W/"6808d3a6-267" Content-Encoding: br ``` ## Conclusion In the above guide, you learned how to compile Nginx with Brotli support on Ubuntu 24.04. Compared to other compression methods, Brotli compression ratios are up to 26% smaller than current methods, with less CPU usage. Start using Brotli today on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install OpenProject on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-openproject-on-ubuntu-20-04/ | Published: 2020-12-01 | Updated: 2023-11-17 | Author: Hitesh Jethva OpenProject is free, open-source project management software that helps you manage your entire project life cycle. It is written in Ruby on Rails and AngularJS. OpenProject provides a simple and easy-to-use web interface that allows you to collaborate on projects using features such as a WYSIWYG text editor, intelligent workflows, conditional formatting, team collaboration, Kanban, Agile & Scrum, project planning and scheduling, time tracking, product roadmaps, and release planning. In this tutorial, we will show you how to install OpenProject on Ubuntu 20.04. ## Step 1 – Install OpenProject By default, the OpenProject package is not available in the Ubuntu 20.04 default repository, so you will need to add the OpenProject repository to your system. First, install some required dependencies with the following command: ``` apt-get update -y apt-get install apt-transport-https gnupg2 -y ``` Next, import the GPG key and add the OpenProject repository with the following command: ``` wget -qO- https://dl.packager.io/srv/opf/openproject/key | apt-key add - wget -O /etc/apt/sources.list.d/openproject.list https://dl.packager.io/srv/opf/openproject/stable/10/installer/debian/10.repo ``` Once the repository is added, update the repository and install the OpenProject package with the following command: ``` apt-get update -y apt-get install openproject -y ``` Once OpenProject is installed, you should get the following output: ``` ============== The openproject package provides an installer. Please run the following command to finish the installation: sudo openproject configure ============== Processing triggers for libc-bin (2.31-0ubuntu9) ... Processing triggers for man-db (2.9.1-1) ... Processing triggers for mime-support (3.64ubuntu1) ... ```   ## Step 2 – Configure OpenProject After installing OpenProject, you will need to configure it. You can configure it with the following command: ``` openproject configure ``` You will be asked to install or use the database as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/11/openproject1.png) Select the second option and hit **Enter**. You will be asked to install the Webserver: ![](https://www.atlantic.net/wp-content/uploads/2020/11/openproject2.png) Select Apache webserver and hit **Enter**. You will be asked to set a fully qualified domain name: ![](https://www.atlantic.net/wp-content/uploads/2020/11/openproject3.png) Provide your fully qualified domain name and hit **Enter**. You will be asked to set the installation path:   Leave it blank and hit **Enter**. You will be asked to enable SSL: ![](https://www.atlantic.net/wp-content/uploads/2020/11/openproject6.png) ![](https://www.atlantic.net/wp-content/uploads/2020/11/openproject4.png) Select no and hit **Enter**. You will be asked to install SVN: ![](https://www.atlantic.net/wp-content/uploads/2020/11/openproject7.png) Select your desired option and hit **Enter**. You will be asked to specify the SVN repo path: ![](https://www.atlantic.net/wp-content/uploads/2020/11/openproject8.png) Provide your SVN repo path or leave it default and hit **Enter**. You will be asked to set up Git: ![](https://www.atlantic.net/wp-content/uploads/2020/11/openproject9.png) Select skip and hit **Enter**. You will be asked to set up sendmail: ![](https://www.atlantic.net/wp-content/uploads/2020/11/openproject10.png) Select skip and hit **Enter**. You will be asked to install a memcached server: ![](https://www.atlantic.net/wp-content/uploads/2020/11/openproject11.png) Select skip and hit **Enter** to finish the configuration. ## Step 3 – Manage OpenProject Service At this point, OpenProject is installed and running. You can verify the status of OpenProject with the following command: ``` systemctl status openproject ``` You should get the following output: - ``` openproject.service Loaded: loaded (/etc/systemd/system/openproject.service; enabled; vendor preset: enabled) Active: active (running) since Fri 2020-10-30 05:22:46 UTC; 1min 33s ago Main PID: 18299 (sleep) Tasks: 1 (limit: 4691) Memory: 148.0K CGroup: /system.slice/openproject.service └─18299 /bin/sleep infinity ``` ``` Oct 30 05:22:46 ubuntu2004 systemd[1]: Started openproject.service. ``` You can also start and stop OpenProject with the following command: ``` systemctl start openproject systemctl stop openproject ``` ## Step 4 – Access OpenProject Web UI Now, open your web browser and access the OpenProject admin interface using the URL **http://openproject.example.com/admin**. You will be redirected to the OpenProject login page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/openproject12.png) Provide the default admin username and password as admin / admin, then click on the **Sign** **in** button. You should see the default admin password reset screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/openproject13.png) Set your new password and click on the **Save** button. You should see the OpenProject dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/openproject14.png) ## Conclusion Congratulations! You have successfully installed and configured OpenProject on Ubuntu 20.04 server. You can now explore OpenProject and start creating your first project. Try OpenProject today on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Dockerizing Python Django Application on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/dockerizing-python-django-application-on-ubuntu-20-04/ | Published: 2020-12-02 | Updated: 2023-11-13 | Author: Hitesh Jethva Docker is a free and open-source platform that allows you to build, package, and run applications in a lightweight container. It helps you to separate your applications from your infrastructure so you can deliver software quickly. Django is an open-source web application framework that follows the Model-View-Controller architecture. Written in Python, it is used for rapidly developed, pragmatically designed, and secure websites. In this tutorial, we will explain how to deploy Python Django web application in the Docker environment. ## Step 1 – Install Docker and Docker Compose First, you will need to install Docker and Docker Compose in your system. By default, the latest version of Docker is not available in the Ubuntu 20.04 default repository, so you will need to add the repository for that. First, install all dependencies with the following command: ``` apt-get install apt-transport-https curl gnupg2 software-properties-common tree -y ``` Once all the dependencies are installed, import the GPG key with the following command: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add - ``` Next, add the Docker official repository with the following command: ``` add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu $(lsb_release - cs) stable" ``` Once the repository has been added, install the Docker and Docker Compose with the following command: ``` apt-get install docker-ce docker-compose -y ``` Once both packages are installed, verify the installed version of Docker with the following command: ``` docker -v ``` Output: ``` Docker version 19.03.13, build 4484c46d9d ``` You can also check the Docker Compose version using the following command: ``` docker-compose -v ``` Output: ``` docker-compose version 1.25.0, build unknown ``` ## Step 2 – Create a Dockerfile Next, you will need to create a Dockerfile to build a container image for your Django application. First, create a project directory named myapp with the following command: ``` mkdir ~/myapp ``` Next, change the directory to myapp and create a new Dockerfile with the following command: ``` cd ~/myapp nano Dockerfile ``` Add the following lines: ``` FROM python:3 ENV PYTHONUNBUFFERED=1 RUN mkdir /code WORKDIR /code COPY requirements.txt /code/ RUN pip install -r requirements.txt COPY . /code/ ``` Save and close the file when you are finished. The above file will pull the official Python image from Dockerhub, create a code directory inside the container, and install the requirements listed in the requirements.txt file. Next, create a requirements.txt file and add the required modules: ``` nano requirements.txt ``` Add the following lines: ``` Django==3.0.7 psycopg2-binary==2.8.5 ``` Save and close the file when you are finished. ## Step 3 – Create a Docker-compose.yml File Docker compose is a tool used for defining and running multi-container Docker applications. You can create a docker-compose.yml file with the following command: ``` nano ~/myapp/docker-compose.yml ``` Add the following lines: ``` version: "3.7" services: db: image: postgres environment: - POSTGRES_DB=postgres - POSTGRES_USER=postgres - POSTGRES_PASSWORD=postgres web: build: . command: python manage.py runserver 0.0.0.0:8000 volumes: - .:/code ports: - "8000:8000" depends_on: - db ``` Save and close the file when you are finished. The above file will create the database service named db using the PostgreSQL image and create our python Django container using the custom docker images generated from our Dockerfile. ## Step 4 – Create a Django Project Next, you will need to download the sample Django project named composeexample inside your project directory. First, change the directory to ~/myapp and run the following command: ``` cd ~/myapp docker-compose run web django-admin startproject composeexample ``` This will download the composeexample project in the current directory. Next, copy the required directory and files from the downloaded directory with the following command: ``` mv composeexample /opt/ mv /opt/composeexample/* . ``` Your project directory structure will look like the following: ``` tree ``` Output: ``` . ├── composeexample │ ├── asgi.py │ ├── __init__.py │ ├── __pycache__ │ │ ├── __init__.cpython-39.pyc │ │ ├── settings.cpython-39.pyc │ │ ├── urls.cpython-39.pyc │ │ └── wsgi.cpython-39.pyc │ ├── settings.py │ ├── urls.py │ └── wsgi.py ├── docker-compose.yml ├── Dockerfile ├── manage.py └── requirements.txt ``` Next, you will need to edit the settings.py file and define your database settings and allowed hosts: ``` nano composeexample/settings.py ``` Change the following lines: ``` ALLOWED_HOSTS = ['your-server-ip'] DATABASES = { 'default': { 'ENGINE': 'django.db.backends.postgresql', 'NAME': 'postgres', 'USER': 'postgres', 'PASSWORD': 'postgres', 'HOST': 'db', 'PORT': 5432, } } ``` Save and close the file when you are finished. ## Step 5 – Build and Run the Docker Image Next, change the directory to your project and build the image with the following command: ``` docker-compose build ``` This will download the required images to your system: ``` ---> ad21d53c5de1 Step 7/7 : COPY . /code/ ---> 0d912d4c215b Successfully built 0d912d4c215b Successfully tagged myapp_web:latest ``` Next, start the all containers by running the following command: ``` docker-compose up -d ``` You should get the following output: ``` Pulling db (postgres:)... latest: Pulling from library/postgres bb79b6b2107f: Pull complete e3dc51fa2b56: Pull complete f213b6f96d81: Pull complete 2780ac832fde: Pull complete ae5cee1a3f12: Pull complete 95db3c06319e: Pull complete 475ca72764d5: Pull complete 8d602872ecae: Pull complete c4fca31f2e3d: Pull complete a00c442835e0: Pull complete 2e2305af3390: Pull complete 6cff852bb872: Pull complete 25bb0be11543: Pull complete 4738c099c4ad: Pull complete Digest: sha256:8f7c3c9b61d82a4a021da5d9618faf056633e089302a726d619fa467c73609e4 Status: Downloaded newer image for postgres:latest Creating myapp_db_1 ... done Creating myapp_web_1 ... done ``` Now, you can verify the running containers with the following command: ``` docker-compose ps ``` You should get the following output: ``` Name Command State Ports ----------------------------------------------------------------------------- myapp_db_1 docker-entrypoint.sh postgres Up 5432/tcp myapp_web_1 python manage.py runserver ... Up 0.0.0.0:8000->8000/tcp ``` You can also list all downloaded images with the following command: ``` docker-compose images ``` You should get the following output: ``` Container Repository Tag Image Id Size ----------------------------------------------------------- myapp_db_1 postgres latest c96f8b6bc0d9 314.1 MB myapp_web_1 myapp_web latest 0d912d4c215b 928.6 MB ``` If you have any problem running the container, you can verify the container log with the following command: ``` docker-compose logs ``` ## Step 6 – Access Django Web UI At this point, the Django container is started and running on port 8000. You can access it using the URL **http://your-server-ip:8000**. You should see your Django application dashboard on the following screen:![](https://www.atlantic.net/wp-content/uploads/2020/11/django1.png)   ## Conclusion Congratulations! You have successfully deployed the Django application with Docker on Ubuntu 20.04. You should now be able to deploy your Python application easily with Docker. Try it today on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Manage Docker Containers with Rancher > URL: https://www.atlantic.net/dedicated-server-hosting/manage-docker-containers-with-rancher/ | Published: 2020-12-03 | Updated: 2023-11-18 | Author: Hitesh Jethva Rancher is a free and open-source platform that can be used to manage the Docker containers through a web-based interface. You can deploy and manage containers, manage clusters, manage centralized policy and workloads, and much more with Rancher. It includes different technologies from the Docker environment like orchestration and scheduling frameworks Swarm and Kubernetes in one application. Rancher can be deployed as a set of Docker containers with one container as the management server and another container on a node as an agent. In this tutorial, we will show you how to install Rancher on Ubuntu 20.04 VPS. ## Step 1: Install Docker First, you will need to install Docker dependencies on **both nodes**. You can install them using the following command: ``` apt-get install apt-transport-https ca-certificates curl gnupg-agent software-properties-common -y ``` Once all the dependencies are installed, download and add the GPT key with the following command: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add - ``` Next, add the Docker repository using the following command: ``` add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" ``` Now, run the following command to install the latest version of Docker: ``` apt-get install docker-ce docker-ce-cli containerd.io -y ``` Once the installation has been completed, start the Docker service and enable it to start at system reboot with the following command: ``` systemctl start docker systemctl enable docker ``` You can now verify the status of Docker with the following command: ``` systemctl status docker ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rancher1.png) **Note**: Run all commands on both nodes.   ## Step 2: Install the Rancher Container Next, you will need to install the Rancher container on the master node. You can deploy the Rancher container by running the following command: ``` docker run -d --restart=unless-stopped -p 8080:8080 rancher/server:stable ``` This will download the Rancher image and start the container on port 8080 as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rancher2.png) At this point, The Rancher is installed and listening on port 8080. ## Step 3: Configure Rancher Now, access the Rancher container using the URL http://rancher-server-ip:8080/. You will be redirected to the Rancher dashboard, as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rancher3.png) Next, you will need to configure Rancher’s Access Control to manage users. Rancher supports many access controls including Active Directory, Azure AD, Github, OpenLDAP, SAML, and Local Authentication. To configure the local authentication for Rancher, click on the **ADMIN => Access Control**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rancher4.png) Select Local Access Control, provide username and password, and click on the **Enable** **Local** **Auth** button. Once the LOCAL authentication is enabled, you should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rancher6.png) ## Step 4: Add Rancher Agent to Rancher Server In this section, we will add a Rancher agent to the Rancher server. On the Rancher server Dashboard, click on **INFRASTRUCTURE** => **HOSTS**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rancher7.png) Click on **Add** **Host**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rancher8.png) Now, click on the **Save** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rancher9.png) Select Custom host type, provide your Rancher agent IP, and copy the Docker command from the box. Now, login to the Rancher agent node (node 2) and paste the command which you have copied earlier: ``` docker run -e CATTLE_AGENT_IP="rancher-agent-ip" --rm --privileged -v /var/run/docker.sock:/var/run/docker.sock -v /var/lib/rancher:/var/lib/rancher rancher/agent:v1.2.11 http://rancher-server- ip:8080/v1/scripts/8744892631BE33B2E14D:1577750400000:ItvCtcS7fG3WeRIChGqxfhhM ``` This will deploy the new container on the Rancher client node. Once the container has been deployed, you should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rancher18.png) On the Rancher server dashboard, click on the Close button. You should see the newly added Rancher agent in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rancher20.png) ## Step 5: Deploy WordPress Container with Rancher Now, you can easily deploy any container through the Rancher server dashboard. In this section, we will deploy a WordPress container. On the Rancher Dashboard, click on the **INFRASTRUCTURE** => **Containers**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rancher13.png) Now, click on the **Add** **Container** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rancher14.png) ![](https://www.atlantic.net/wp-content/uploads/2020/11/rancher15.png) Provide your container name, port number, and image and click on the **Create** button. Once the container has been created successfully, you should see your WordPress container in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/rancher16.png) You can view your Docker WordPress image by entering your Rancher Client IP and the port you configured, e.g. 185.50.60.70:80 ![](https://www.atlantic.net/wp-content/uploads/2020/11/rancher17.png) ## Conclusion In the above guide, you learned how to install Rancher server and Rancher agent on Ubuntu 20.04 VPS. You have also deployed new WordPress container with Rancher. You can now easily manage and deploy containers using the Rancher web interface. Get started with Rancher on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Kubernetes with Minikube on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-kubernetes-with-minikube-on-centos-8/ | Published: 2020-12-04 | Updated: 2023-11-25 | Author: Hitesh Jethva Minikube is an open-source software written in Go and used for setting up a Kubernetes cluster on your local machine. Developers or administrators mainly use Minikube for testing purposes. This cross-platform software can be run on macOS, Linux, and Windows. In this tutorial, we will learn how to install Kubernetes with Minikube on CentOS 8. ## Step 1: Install Docker By default, the Docker package is not available in the CentOS 8 default repo, so you will need to add the Docker repo in your system. You can add it with the following command: ``` dnf config-manager --add-repo=https://download.docker.com/linux/centos/docker-ce.repo ``` After adding the Docker repo, install Docker by running the following command: ``` dnf install docker-ce --nobest -y ``` Once the installation is completed, start the Docker service and enable it to start at system reboot: ``` systemctl start docker systemctl enable docker ``` You can also verify the installed version of Docker using the following command: ``` docker -v ``` You should see the following output: ``` Docker version 19.03.12, build 48a66213fe ``` ## Step 2: Install Kubectl Before starting, you will need to install the required dependencies in your system. You can install them with the following command: ``` dnf install curl conntrack -y ``` Next, you will need to install Kubectl in your system. By default, kubectl is not included in CentOS 8, so you will need to install it using the curl command: ``` curl -LO https://storage.googleapis.com/kubernetes-release/release/`curl -s https://storage.googleapis.com/kubernetes-release/release/stable.txt`/bin/linux/amd64/kubectl ``` Next, give the execution permission to the downloaded binary and move it to the /usr/local/bin directory: ``` chmod +x ./kubectl mv ./kubectl /usr/local/bin/kubectl ``` You can now verify the Kubectl version with the following command: ``` kubectl version --client ``` You should see the following output: ``` Client Version: version.Info{Major:"1", Minor:"18", GitVersion:"v1.18.5", GitCommit:"e6503f8d8f769ace2f338794c914a96fc335df0f", GitTreeState:"clean", BuildDate:"2020-06-26T03:47:41Z", GoVersion:"go1.13.9", Compiler:"gc", Platform:"linux/amd64"} ``` ## Step 3: Install Minikube First, download the Minikube binary package using the curl command: ``` curl -Lo minikube https://storage.googleapis.com/minikube/releases/latest/minikube-linux-amd64 ``` Next, give the execution permission to the downloaded binary with the following command: ``` chmod +x minikube ``` Next, install Minikube by running the following command: ``` install minikube /usr/local/bin/ ``` You can now start Minikube using the following command: ``` minikube start --driver=none ``` Once Minikube is started successfully, you should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/11/minikube1.png) The above command will download and start the Docker containers for setting up a single node Kubernetes cluster. You can also verify the status of the Kubernetes cluster with the following command: ``` minikube status ``` You should see the following output: ``` minikube type: Control Plane host: Running kubelet: Running apiserver: Running kubeconfig: Configured ``` You can also view the cluster information using the following command: ``` kubectl cluster-info ``` You should see the following output: ``` Kubernetes master is running at https://your-server-ip:8443 KubeDNS is running at https://your-server-ip:8443/api/v1/namespaces/kube-system/services/kube- dns:dns/proxy To further debug and diagnose cluster problems, use 'kubectl cluster-info dump'. ``` You can also view the cluster nodes using the following command: ``` kubectl get nodes ``` You should get the following output: ``` NAME STATUS ROLES AGE VERSION minicube Ready master 2m v1.18.3 ``` ## Step 4: Verify Kubernetes Cluster Now, deploy a k8s using echoserver image to test the Kubernetes cluster. ``` kubectl create deployment test-minikube --image=k8s.gcr.io/echoserver:1.10 ``` You should see the following output: ``` deployment.apps/test-minikube created ``` Now, expose your deployment on port 8080 using the following command: ``` kubectl expose deployment test-minikube --type=NodePort --port=8080 ``` You should see the following output: ``` service/test-minikube exposed ``` Next, get the information about your exposed deployment using the following command: ``` kubectl get pod ``` You should see the following output: ``` NAME READY STATUS RESTARTS AGE test-minikube-f4df69575-7m2pl 1/1 Running 0 33s ``` Next, get the URL of your deployment using the following command: ``` minikube service test-minikube --url ``` You should see the following output: ``` http://your-server-ip:31186 ``` Now, open your web browser and access the above URL http://your-server-ip:31186. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/minicube2.png) ## Step 5: Enable Kubernetes Dashboard Kubernetes comes with a web dashboard that can be used to manage your cluster through a web browser. By default, the dashboard is disabled in Minikube. You can list all Minikube addons using the following command: ``` minikube addons list ``` You should see the following output: ``` |-----------------------------|----------|--------------| | ADDON NAME | PROFILE | STATUS | |-----------------------------|----------|--------------| | ambassador | minikube | disabled | | dashboard | minikube | disabled | | default-storageclass | minikube | enabled ✅ | | efk | minikube | disabled | | freshpod | minikube | disabled | | gvisor | minikube | disabled | | helm-tiller | minikube | disabled | | ingress | minikube | disabled | | ingress-dns | minikube | disabled | | istio | minikube | disabled | | istio-provisioner | minikube | disabled | | logviewer | minikube | disabled | | metallb | minikube | disabled | | metrics-server | minikube | disabled | | nvidia-driver-installer | minikube | disabled | | nvidia-gpu-device-plugin | minikube | disabled | | olm | minikube | disabled | | registry | minikube | disabled | | registry-aliases | minikube | disabled | | registry-creds | minikube | disabled | | storage-provisioner | minikube | enabled ✅ | | storage-provisioner-gluster | minikube | disabled | |-----------------------------|----------|--------------| ``` Now, enable the Minikube dashboard and get the URL of the dashboard with the following command: ``` minikube dashboard --url ``` This will enable the Minikube dashboard as shown below: ``` * Enabling dashboard ... * Verifying dashboard health ... * Launching proxy ... * Verifying proxy health ... http://127.0.0.1:42939/api/v1/namespaces/kubernetes-dashboard/services/http:kubernetes- dashboard:/proxy/ ``` Now, you can access the Minikube dashboard locally using the above URL. ## Conclusion Congratulations! You have successfully installed Kubernetes cluster with Minikube on CentOS 8. You can now start experimenting with Kubernetes locally. Get started with Kubernetes and Minikube on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # How to Install Matrix Synapse on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-matrix-synapse-on-ubuntu-20-04/ | Published: 2020-12-05 | Updated: 2023-11-25 | Author: Hitesh Jethva Matrix is an open-source Python project for decentralized real-time communication used for messaging and VoIP services. It allows one user to communicate with other users on a different service provider via voice-over-IP and chat. Matrix is an open standard and lightweight protocol and allows you to create your own home server, store all user personal info, and create a personal room. In this tutorial, we will show you how to install Matrix Synapse with Nginx as a reverse proxy on Ubuntu 20.04. ## Prerequisites - A fresh Ubuntu 20.04 [VPS](https://www.atlantic.net/vps-hosting/) - A valid domain name pointed to your server IP - A root password configured on your server ## Step 1 – Install Matrix Synapse By default, Matrix synapse package is not available in the Ubuntu 20.04 default repository, so you will need to add the Matrix repository to your system. First, install the required dependencies with the following command: ``` apt-get install curl wget gnupg2 apt-transport-https -y ``` Once all the dependencies are installed, download and add the GPG key with the following command: ``` wget -qO /usr/share/keyrings/matrix-org-archive-keyring.gpg https://packages.matrix.org/debian/matrix-org-archive-keyring.gpg ``` Next, add the Matrix repository to the APT with the following command: ``` echo "deb [signed-by=/usr/share/keyrings/matrix-org-archive-keyring.gpg] https://packages.matrix.org/debian/ $(lsb_release -cs) main" | tee /etc/apt/sources.list.d/matrix- org.list ``` Next, update the repository and install the latest version of Matrix with the following command: ``` apt-get update -y apt-get install matrix-synapse-py3 -y ``` During the installation, you will be asked to provide your domain name as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/11/matrix1.png) Provide your domain and click on the **Ok** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/matrix2.png) Select your desired option and hit Enter to start the installation. Once Matrix has been installed, start the Matrix service and enable it to start at system reboot with the following command: ``` systemctl start matrix-synapse systemctl enable matrix-synapse ``` By default, Matrix synapse listens on port 8008. You can check it with the following command: ``` ss -tunelp | grep 8008 ``` You should get the following output: ``` tcp LISTEN 0 50 127.0.0.1:8008 0.0.0.0:* users:(("python",pid=102359,fd=13)) uid:109 ino:594551 sk:a <-> tcp LISTEN 0 50 [::1]:8008 [::]:* users:(("python",pid=102359,fd=12)) uid:109 ino:594550 sk:d v6only:1 <-> ``` ## Step 2 – Configure Matrix Synapse The Matrix Synapse default configuration file is located at /etc/matrix-synapse/homeserver.yaml. Before editing it, create a secret password with the following command: ``` cat /dev/urandom | tr -dc 'a-zA-Z0-9' | fold -w 32 | head -n 1 ``` You should get the following output: ``` 2VHeHAwjGlMlqpEGBNMhfEbb5BOmp6qE ``` Next, edit the Matrix configuration file: ``` nano /etc/matrix-synapse/homeserver.yaml ``` Change the following lines: ``` listeners: - port: 8008 tls: false type: http x_forwarded: true bind_addresses: ['127.0.0.1'] resources: - names: [client, federation] compress: false enable_registration: false registration_shared_secret: "2VHeHAwjGlMlqpEGBNMhfEbb5BOmp6qE" ``` Save and close the file, then restart the Matrix synapse service to apply the changes. ``` systemctl restart matrix-synapse ``` At this point, Matrix Synapse is configured to listen on localhost. ## Step 3 – Create a New Matrix User Next, you will need to create a new user for Matrix Synapse. You can use this user on the Matrix client to connect to the Matrix server. Run the following command to create a new user: ``` register_new_matrix_user -c /etc/matrix-synapse/homeserver.yaml http://localhost:8008 ``` You will be asked to set a username and password as shown below: ``` New user localpart [root]: admin Password: Confirm password: Make admin [no]: yes Sending registration request... Success! ``` Once the user is created, you can proceed to the next step. ## Step 4 – Configure Nginx for Matrix Synapse Next, you will need to install and configure Nginx as a reverse proxy for Matrix Synapse so you can access the Matrix Synapse from the external network using port 80. First, install the Nginx server with the following command: ``` apt-get install nginx -y ``` Once installed, create an Nginx virtual host configuration file with the following command: ``` nano /etc/nginx/sites-available/matrix.conf ``` Add the following lines: ``` server { listen 80; server_name matrix.example.com; location / { proxy_pass http://localhost:8008; proxy_set_header X-Forwarded-For $remote_addr; } } ``` Save and close the file, then enable the Nginx virtual host with the following command: ``` ln -s /etc/nginx/sites-available/matrix.conf /etc/nginx/sites-enabled/ ``` Next, verify Nginx for any syntax errors with the following command: ``` nginx -t ``` You should get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Next, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` If you get any errors, then you will need to edit the Nginx default server configuration file and set server_names_hash_bucket_size: ``` nano /etc/nginx/nginx.conf ``` Add the following line below http {: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 5 – Access Matrix Synapse Now, open your web browser and access the Matrix Synapse web interface using the URL **http://matrix.example.com**/. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/matrix3.png) As you can see, Matrix Synapse is now running. ## Conclusion Congratulations! You have successfully installed Matrix Synapse with Nginx as a reverse proxy on Ubuntu 20.04. You can now install the Matrix client on your mobile device or desktop computer and communicate with other users. Get started with Matrix on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # How to Install WordPress with EasyEngine on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-wordpress-with-easyengine-on-ubuntu-20-04/ | Published: 2020-12-06 | Updated: 2024-06-30 | Author: Hitesh Jethva EasyEngine is a collection of Linux shell scripts that makes it easier to install and manage Nginx, MariaDB, PHP and WordPress using the command line. It can be installed on any Debian-based distributions and allows you to deploy single and multisite WordPress installations, including WP Super Cache, W3 Total Cache, Redis Cache, and ngx_fastcgi_cache. If you are a WordPress developer, then you may need to install it on several systems for testing purposes. There are several ways to install WordPress. Installing WordPress manually is a bit time-consuming process. EasyEngine is the easiest way to install WordPress automatically within a minute. In this tutorial, we will show you how to install WordPress with EasyEngine on Ubuntu 20.04. ## Step 1 – Install EasyEngine EasyEngine provides an installer script to install EasyEngine in your system automatically. You can download and run the EasyEngine installer script by running the following command: ``` apt-get update -y wget -qO ee https://rt.cx/ee4 && bash ee ``` This script will install Docker and all images required to host WordPress website as shown below: ``` Status: Downloaded newer image for easyengine/redis:v4.1.4 docker.io/easyengine/redis:v4.1.4 +-------------------+---------------------------------------------------------------------------+ | OS | Linux 5.4.0-29-generic #33-Ubuntu SMP Wed Apr 29 14:32:27 UTC 2020 x86_64 | | Shell | /bin/bash | | PHP binary | /usr/bin/php7.3 | | PHP version | 7.3.23-1+ubuntu20.04.1+deb.sury.org+1 | | php.ini used | /etc/php/7.3/cli/php.ini | | EE root dir | phar://ee.phar | | EE vendor dir | phar://ee.phar/vendor | | EE phar path | /root | | EE packages dir | | | EE global config | | | EE project config | | | EE version | 4.1.5 | +-------------------+---------------------------------------------------------------------------+ -----> Run "ee help site" for more information on how to create a site. ``` Next, verify the installed version of EasyEngine using the following command: ``` ee --version ``` You should get the following output: ``` EE 4.1.5 ``` Next, you can list all downloaded docker images with the following command: ``` docker images ``` You should get the following output: ``` REPOSITORY TAG IMAGE ID CREATED SIZE easyengine/php v4.1.6 d700893ee9a0 2 weeks ago 759MB easyengine/postfix v4.1.5 f5ac5c1276af 6 weeks ago 475MB easyengine/nginx v4.1.4 502705ab18a2 8 weeks ago 85.2MB easyengine/redis v4.1.4 8df6607d58ef 8 weeks ago 104MB easyengine/nginx-proxy v4.1.4 e62b5bc02d07 8 weeks ago 163MB easyengine/mariadb v4.1.3 580f7d75d8d5 3 months ago 407MB easyengine/cron v4.0.0 e86e4f2e4e9a 22 months ago 8.83MB easyengine/mailhog v4.0.0 789b9de98747 22 months ago 19.3MB ``` ## Step 2 – Install WordPress with EasyEngine At this point, EasyEngine is installed in your server. Now, you can use “ee site create” command followed by your domain name to install the WordPress in your system. ``` ee site create wordpress.example.com --wp --cache ``` This script will start Nginx, MariaDB, PHP, and Redis container, create a database, and configure WordPress as shown below: ``` Starting site creation. Configuring project. Creating WordPress site wordpress.example.com Copying configuration files. Starting site's services. Downloading and configuring WordPress. Moved /var/www/htdocs/wp-config.php to /var/www/wp-config.php successfully Success: Host entry successfully added. Checking and verifying site-up status. This may take some time. Installing WordPress site. Success: http://wordpress.example.com has been created successfully! Site entry created. Creating cron entry Success: Cron created successfully +--------------------+---------------------------------------------+ | Site | http://wordpress.example.com | +--------------------+---------------------------------------------+ | Site Root | /opt/easyengine/sites/wordpress.example.com | +--------------------+---------------------------------------------+ | Site Title | wordpress.example.com | +--------------------+---------------------------------------------+ | WordPress Username | epic-bose | +--------------------+---------------------------------------------+ | WordPress Password | LbWdvLk1cS7ng4iQkK | +--------------------+---------------------------------------------+ | Alias Domains | None | +--------------------+---------------------------------------------+ | DB Host | global-db | +--------------------+---------------------------------------------+ | DB Name | wordpress_example_com | +--------------------+---------------------------------------------+ | DB User | wordpress.example.com-YuhM29 | +--------------------+---------------------------------------------+ | DB Password | qO3oq8HM5E77 | +--------------------+---------------------------------------------+ | E-Mail | admin@wordpress.example.com | +--------------------+---------------------------------------------+ | SSL | Not Enabled | +--------------------+---------------------------------------------+ | Cache | Enabled | +--------------------+---------------------------------------------+ | Proxy Cache | Off | +--------------------+---------------------------------------------+ ``` In the above output, you can see all the information about your WordPress website including WordPress site URL, admin username, password, database name, username, password and email address. You can list all running containers using the following command: ``` docker ps ``` You should get the following output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES c418ec63de84 easyengine/cron:v4.0.0 "/usr/bin/ofelia dae…" 20 seconds ago Up 16 seconds ee-cron-scheduler 20b5374e5ad9 easyengine/nginx:v4.1.4 "/usr/bin/openresty …" About a minute ago Up About a minute 80/tcp wordpressexamplecom_nginx_1 5c73654233a4 easyengine/php:v4.1.6 "docker-entrypoint.s…" About a minute ago Up About a minute 9000/tcp wordpressexamplecom_php_1 c5cb0cb15a03 easyengine/postfix:v4.1.5 "postfix start-fg" About a minute ago Up About a minute 25/tcp wordpressexamplecom_postfix_1 f7856139ae4c easyengine/mariadb:v4.1.3 "docker-entrypoint.s…" About a minute ago Up About a minute 3306/tcp services_global-db_1 1f1f7c7f4f22 easyengine/redis:v4.1.4 "docker-entrypoint.s…" About a minute ago Up About a minute 6379/tcp services_global-redis_1 068ff0967f13 easyengine/nginx-proxy:v4.1.4 "/app/docker-entrypo…" 2 minutes ago Up About a minute 0.0.0.0:80->80/tcp, 0.0.0.0:443->443/tcp services_global-nginx-proxy_1 ``` If you forgot the WordPress login username and password, then you can run the following command to see all the information for your website: ``` ee site info wordpress.example.com ``` ## Step 3 – Access WordPress Website Now, open your web browser and access your WordPress admin page using the URL wordpress.example.com/wp-admin. You should see the WordPress login page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/easyengine1.png) Provide your WordPress admin username, password and click on the **Log in** button. You should see your WordPress dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/11/easyengine2.png) ## Step 4 – Working with EasyEngine In this section, we will show you some useful EasyEngine commands that will help you to manage the WordPress website. To list all websites created with Easyengine, run the following command: ``` ee site list ``` You should get the following output: ``` +-----------------------+---------+ | site | status | +-----------------------+---------+ | wordpress.example.com | enabled | +-----------------------+---------+ ``` To restart your website, run the following command: ``` ee site restart wordpress.example.com ``` You should get the following output: ``` nginx: the configuration file /usr/local/openresty/nginx/conf/nginx.conf syntax is ok nginx: configuration file /usr/local/openresty/nginx/conf/nginx.conf test is successful Restarting nginx Restarting wordpressexamplecom_nginx_1 ... done Restarting php Restarting wordpressexamplecom_php_1 ... done ``` To disable or enable the WordPress website, run the following command: ``` ee site disable wordpress.example.com ee site enable wordpress.example.com ``` If you want to delete your website, run the following command: ``` ee site delete wordpress.example.com ``` You should get the following output: ``` Are you sure you want to delete wordpress.example.com? [y/n] y [wordpress.example.com] Docker Containers removed. [wordpress.example.com] site root removed. Removed database entry. Success: Site wordpress.example.com deleted. ``` ## Conclusion As you can see, EasyEngine is a very handy tool for system administrators or developers to automate the website deployment process. You can also install phpMyAdmin, Let’s Encrypt and many other administration utilities using EasyEngine. For more information, you can visit the EasyEngine’s official [documentation](https://easyengine.io/docs/) page. Get started with EasyEngine on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # How to Install Tiki Wiki on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-tiki-wiki-on-ubuntu-20-04/ | Published: 2020-12-06 | Updated: 2023-11-18 | Author: Hitesh Jethva Tiki Wiki is a free and open-source wiki content management system that allows you to host your own Wiki within a minute. It is written in PHP and uses MariaDB/MySQL as a database backend. Tiki Wiki is made from four components including content creation and management tools, communication tools, content organization tools and navigation aids, and configuration and administration tools. It comes with very useful features including wiki pages, blogs, forums, and file and image galleries. In this tutorial, we will show you how to install Tiki Wiki on Ubuntu 20.04. ## Step 1 – Install LAMP Server First, install the Apache web server and MariaDB server with the following command: ``` apt-get install apache2 mariadb-server unzip git gnupg -y ``` After installing the above packages, you will need to install PHP and the required extensions to your system. Tiki Wiki supports only PHP version 7.0 to 7.2. By default, Ubuntu 20.04 ships with PHP 7.4 version, so you will need to add the Ondrej PHP repository in your server. You can add it with the following command: ``` apt-get install software-properties-common gnupg2 -y add-apt-repository ppa:ondrej/php ``` Once the repository is added, update the repository and install PHP with required extensions by running the following command: ``` apt-get install php7.2 php7.2-tidy php7.2-gd php7.2-xmlrpc php7.2-mbstring libapache2-mod -php7.2 php7.2-mysql php-apcu php7.2-curl php7.2-intl php7.2-sqlite3 php7.2-zip php-memcache php7.2-pspell php7.2-zip php7.2-memcached php-pear php7.2-common php7.2-opcache php7.2 -xml php7.2-zip -y ``` Once all packages are installed, edit the php.ini file and make some changes: ``` nano /etc/php/7.2/apache2/php.ini ``` Change the following lines: ``` memory_limit = 256M upload_max_filesize = 100M max_execution_time = 300 date.timezone = Asia/Kolkata ``` At this point, a LAMP stack is installed in your server. ## Step 2 – Create a Database for Tiki Wiki Next, you will need to create a database and user for Tiki WIki. First, log in to MariaDB shell with the following command: ``` mysql ``` Once logged in, create a database and user with the following command: ``` CREATE DATABASE tiki CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci; CREATE USER 'tiki'@'localhost' IDENTIFIED BY 'yourpassword'; ``` Next, grant all the privileges to tiki database with the following command: ``` GRANT ALL ON tiki.* TO 'tiki'@'localhost' WITH GRANT OPTION; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download Tiki Wiki Next, you will need to download the latest version of Tiki Wiki from the Sourceforge website. You can download it with the following command: ``` wget https://sourceforge.net/projects/tikiwiki/files/latest/download --no-check-certificate ``` Once the download is completed, extract the downloaded file with the following command: ``` unzip download ``` Next, move the extracted directory to the Apache root directory: ``` mv tiki-21.2 /var/www/html/tikiwiki ``` Next, change the ownership and permissions of the tikiwiki directory: ``` chown -R www-data:www-data /var/www/html/tikiwiki/ chmod -R 755 /var/www/html/tikiwiki/ ``` At this point, Tiki Wiki is downloaded and configured. ## Step 4 – Configure Apache for Tiki Wiki Next, create an Apache virtual host configuration file for Tiki Wiki with the following command: ``` nano /etc/apache2/sites-available/tikiwiki.conf ``` Add the following lines: ``` ServerAdmin admin@example.com DocumentRoot /var/www/html/tikiwiki ServerName tiki.example.com Options FollowSymlinks AllowOverride All Require all granted ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined ``` Save and close the file when you are finished, then activate the Apache virtual host with the following command: ``` a2ensite tikiwiki.conf ``` Next, enable the Apache rewrite module and restart the Apache service using the following command: ``` a2enmod rewrite systemctl restart apache2 ``` ## Step 5 – Access Tiki Wiki Now, open your web browser and access the Tiki Wiki web interface using the URL **http://tiki.example.com/tiki-install.php**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/tiki1.png) Select your language and click on the **Continue** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/tiki2.png) Click on the **Continue** to agree the license agreement. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/tiki3.png) Make sure all tests are green, then click on **Continue**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/tiki4.png) ![](https://www.atlantic.net/wp-content/uploads/2020/11/tiki5.png) Provide your database details and click on the **Continue** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/tiki6.png)   Choose your Database engine and click on the **Install** button. Once the installation has been completed, you should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/tiki7.png) Review the installation click on the **Continue** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/tiki8.png) ![](https://www.atlantic.net/wp-content/uploads/2020/11/tiki9.png) ![](https://www.atlantic.net/wp-content/uploads/2020/11/tiki10.png) Configure Tiki Wiki and click on the **Continue** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/tiki11.png)   Click on the **Continue** button. You should see the admin user creation page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/tiki12.png) Click on the “**Enter Tiki and Lock Installer**“. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/tiki13.png) Click on the **Log** **in** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/tiki14.png) Provide default username as “admin” and password as “admin” and click on the **Log In** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/tiki15.png) Set your admin password and click on the **Apply** button. You should see the Tiki Wiki dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/tiki16.png) ## Conclusion Congratulations! You have successfully installed Tiki Wiki on Ubuntu 20.04 server. You can now host your own Wiki using Tiki Wiki. For more information, you can visit the Tiki Wiki [documentation](https://doc.tiki.org/) page. Get started with Tiki Wiki on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # How to Install OpenNebula on Debian > URL: https://www.atlantic.net/vps-hosting/how-to-install-opennebula-on-debian/ | Published: 2020-12-07 | Updated: 2025-09-03 | Author: Hitesh Jethva OpenNebula is a free and open-source cloud computing platform that can be used to build and manage Enterprise Clouds. It is easy to install, update and operate by administrators. OpenNebula is specially designed for data center virtualization and cloud deployments based on the KVM hypervisor. It combines containers from Kubernetes or Docker Hub and integrates multiple virtualization technologies to meet your workload needs. In this tutorial, we will show you how to install and configure OpenNebula on Debian 12. ## Step 1 – Install MariaDB Server OpenNebula uses MariaDB as a database backend, so you will need to install it in your server. You can install it with the following command: ``` apt-get install mariadb-server curl gnupg2 -y ``` Once installed, login to MariaDB shell with the following command: ``` mysql ``` Once login, create a database and user with the following command: ``` CREATE DATABASE opennebula; GRANT ALL PRIVILEGES ON opennebula.* TO 'oneadmin' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 2 – Install OpenNebula By default, OpenNebula is not available in the Debian 12 default repository, so you will need to add the OpenNebula repository to your system. First, download and add the GPG key with the following command: ``` curl -fsSL https://downloads.opennebula.io/repo/repo2.key| gpg --dearmor -o /etc/apt/trusted.gpg.d/opennebula.gpg ``` Next, add the OpenNebula repository with the following command: ``` echo "deb https://downloads.opennebula.io/repo/6.10/Debian/12 stable opennebula" | tee /etc/apt/sources.list.d/opennebula.list ``` Next, update the repository and install OpenNebula with the following command: ``` apt-get update -y apt-get install opennebula opennebula-sunstone opennebula-gate opennebula-flow -y ``` Once OpenNebula has been installed, run the following command to install other required dependencies: ``` /usr/share/one/install_gems ``` You should get the following output: ``` Execution continues in 15 seconds ... Distribution "debian" detected. About to install these dependencies: * gcc * rake * libxml2-dev * libxslt1-dev * patch * g++ * libsqlite3-dev * libcurl4-openssl-dev * libssl-dev * default-libmysqlclient-dev * postgresql-server-dev-all * libzmq5 * libzmq3-dev * libaugeas-dev * ruby-dev * make Press enter to continue... ``` Press Enter to install the required dependencies. ## Step 3 – Configure OpenNebula Next, you will need to edit the file /etc/one/oned.conf and define your database settings. ``` nano /etc/one/oned.conf ``` Find the following lines: ``` DB = [ BACKEND = "sqlite", TIMEOUT = 2500 ] ``` And replace them with the following lines: ``` DB = [ BACKEND = "mysql", SERVER = "localhost", PORT = 0, USER = "oneadmin", PASSWD = "password", DB_NAME = "opennebula", CONNECTIONS = 25, COMPARE_BINARY = "no" ] ``` Save and close the file, then generate the oneadmin password with the following command: ``` cat /var/lib/one/.one/one_auth ``` You should see the following output: ``` oneadmin:cask7QuowHym ``` **Note**: Please remember the above password, as you will need this password to log in OpenNebula. ## Step 4 – Verify OpenNebula Installation Now, start the OpenNebula service and enable it to start at system reboot with the following command: ``` systemctl start opennebula opennebula-sunstone systemctl enable opennebula opennebula-sunstone ``` Next, connect the OpenNebula daemon and verify the installation with the following command: ``` su - oneadmin -c "oneuser show" ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/12/on1.png) ## Step 5 – Access OpenNebula Web UI Now, open your web browser and access the OpenNebula web interface using the URL **http://your-server-ip:9869**. You should see the OpenNebula login page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/on2.png) Provide your admin username and password and click on the **Login** button. You should see the OpenNebula dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/on3.png)   ## Conclusion Congratulations! You have successfully installed and configured OpenNebula on Debian 12 server. Now, you can install KVM on another system, add KVM node to the OpenNebula and start creating your first virtual machine from the OpenNebula dashboard. Try OpenNebula on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # Ubersmith Brings Together 50 Disparate Business Operations Systems at Atlantic.Net > URL: https://www.atlantic.net/press-releases/ubersmith-brings-together-50-disparate-business-operations-systems-at-atlantic-net/ | Published: 2020-12-08 | Updated: 2024-06-11 | Author: Editorial Team **Ubersmith Brings Together 50 Disparate Business Operations Systems at Atlantic.Net** *Greatly improves efficiency, more precise billing, better overall customer service* NEW YORK, December 8, 2020 – Atlantic.Net Inc., a global cloud services provider, replaced or integrated more than 50 different subscription billing, device management and customer support systems into one. Ubersmith business management software has improved business processes from seven to fourteen days to one day, quickened response to support issues by enabling resolution in half of the previous time and realized a 55% improvement in billing for customers’ overage usage. “By consolidating all our previous systems into Ubersmith, customer information related to billing, products and service is centralized in one place, making it readily accessible,” said Marty Puranik, Founder and CEO, Atlantic.Net. “Plus, we’ve eliminated the need for training our staff on different systems, which saves countless hours and streamline resources.” “We can automatically tie support tickets to information regarding to specific devices and customers, and as a result, our support ticket times have dropped in half,” said Puranik. “Also, we have better capabilities to monitor customer usage and bill accordingly, which is a net positive for revenue growth.” Atlantic.Net has achieved tremendous operational efficiencies and substantial cost savings by eliminating many redundant systems. Started in 1994 in Gainesville, Florida, Atlantic.Net quickly expanded to other cities with new office openings and acquisitions of service providers. Today, it operates out of five data centers in the U.S., one in Canada, and one in the U.K., with plans to expand services in Amsterdam and Singapore next year. Atlantic.Net is a global cloud services provider, providing more than 15,000 customers with business-class dedicated and cloud hosting solutions backed by 24/7/365 support. Ubersmith is an easily customizable, integrated and modular software suite for subscription billing, quoting, order management, infrastructure management and ticketing. A plug-in system provides flexibility for extending and integrating other software used as part of business operations. Ubersmith provides an application programming interface (API) and software development kit (SDK) to enable customers and partners to easily integrate other systems and programs with the Ubersmith suite. “We make extensive use of Ubersmith APIs to integrate with other systems that we use for payments, accounting, domain registration, security certificates and more,” said Puranik. Deep integrations with the Ubersmith software enable Atlantic.Net to achieve high levels of efficiency in operations, helping to improve [employee productivity](https://blog.hubstaff.com/employee-productivity/) and ultimately provide higher levels of customer service. Atlantic.Net is known for delivering outstanding products, service and high customer satisfaction with one of the lower customer churn rates in the VPS hosting industry. With Ubersmith’s plans to soon add support for Salesforce, Atlantic.Net will be able to tie in its sales and prospecting activities, along with customer quotes, in its systems. “Atlantic.Net has done an impressive job at leveraging the capabilities we provide in Ubersmith’s business management, infrastructure and operations software,” said Kurt Daniel, CEO of Ubersmith. “We’re pleased to be an important partner for their business as they continue to grow and expand in the cloud services and hosting arenas.” **About Atlantic.Net** Atlantic.Net is a global cloud services provider with over 25 years of experience, specializing in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions and HIPAA compliant hosting. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions, backed by 24/7/365 support through their global data centers located in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. For more information, please visit [Atlantic.Net](https://www.atlantic.net/). **About Ubersmith** Ubersmith is a leader in subscription management software for the cloud and beyond. Headquartered in New York, Ubersmith provides billing, infrastructure and ticketing solutions that are open, scalable and integrated. Organizations worldwide rely on Ubersmith to better serve their customers and better run their businesses. For more, please visit [Ubersmith.com](https://ubersmith.com). Media Contact: Glenn Rossman Acorn PR, for Ubersmith (914) 623-8354 [glenn@theacornpr.com](mailto:glenn@theacornpr.com) --- # How to Install Passbolt Password Manager on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-passbolt-password-manager-on-ubuntu-18-04/ | Published: 2020-12-09 | Updated: 2024-06-30 | Author: Hitesh Jethva Passbolt is an open-source, self-hosted password manager that can be used to store and share the login credentials for websites securely. If your business is organized into teams, then Passbolt will help you to store and share the password across those teams. Passbolt comes with a simple and user-friendly interface and uses GnuPG to authenticate users and verify secrets server side. In this tutorial, we will show you how to install the Passbolt password manager on Ubuntu 18.04. ## Step 1 – Download Passbolt Installation Script The simplest way to install Passbolt using the Passbolt installation script. To download the installation script, run the following command: ``` wget -O passbolt-ce-installer-ubuntu-18.04.tar.gz https://www.passbolt.com/ce/download/installers/ubuntu/latest ``` Next, check the installer checksum with the following command: ``` wget -O passbolt-installer-checksum https://www.passbolt.com/ce/download/installers/ubuntu/latest-checksum sha512sum -c passbolt-installer-checksum ``` You should see the following output: ``` passbolt-ce-installer-ubuntu-18.04.tar.gz: OK ``` Next, extract the downloaded installer with the following command: ``` tar -xzf passbolt-ce-installer-ubuntu-18.04.tar.gz ``` Once the installer is extracted, you can proceed with the installation. ## Step 2 – Install Passbolt Now, run the following command to install Passbolt in your system: ``` ./passbolt_ce_ubuntu_installer.sh ``` You will be asked to install MariaDB on your system as shown below: ``` ================================================================ ____ __ ____ / __ \____ _____ ____/ /_ ____ / / /_ / /_/ / __ `/ ___/ ___/ __ \/ __ \/ / __/ / ____/ /_/ (__ |__ ) /_/ / /_/ / / /_ /_/ \__,_/____/____/_,___/\____/_/\__/ The open source password manager for teams (c) 2020 Passbolt SA https://www.passbolt.com ================================================================ IMPORTANT NOTE: This installation scripts are for use only on FRESH installed debian >= 9.0 | ubuntu 18.04 | CentOS >= 7.0 ================================================================ ============================================================== Do you want to install a local mariadb server on this machine? ============================================================== 1) yes 2) no #? 1 ```   Type **1**and hit **Enter** to continue. You will be asked to set MariaDB root password as shown below: ``` ======================================================= Please enter a new password for the root database user: ======================================================= MariaDB Root Password: MariaDB Root Password (verify): ``` Next, you will be asked to provide a name for the Passbolt database, a database username, and a password as shown below: ``` ====================================================== Please enter a name for the passbolt database username ====================================================== Passbolt database user name:passbolt ======================================================= Please enter a new password for the mysql passbolt user ======================================================= MariaDB passbolt user password: MariaDB passbolt user password (verify): ============================================== Please enter a name for the passbolt database: ============================================== Passbolt database name:passboltdb ``` Next, you will be asked to create a GnuPG key as shown below: ``` ================================================================================ On virtualized environments GnuPG happen to find not enough entropy to generate a key. Therefore, Passbolt will not run properly. Do you want to install Haveged to speed up the entropy generation on your system? Please check https://help.passbolt.com/faq/hosting/why-haveged- virtual-env ================================================================== ============== 1) yes 2) no #? 1 ================================================================= =============== ``` Type **1** and hit **Enter** to continue. You will be asked to provide a domain name or the IP address of your server as shown below: ``` Setting hostname... Please enter the domain name under which passbolt will run. Note this hostname will be used as server_name for nginx and as the domain name to register a SSL certificate with let's encrypt. If you don't have a domain name and you do not plan to use let's encrypt please enter the ip address to access this machine =============================================================== ================= Hostname:your-server-ip =============================================================== ================= ``` Provide your server IP address or domain name and hit **Enter**. You will be asked to set up an SSL certificate as shown below: ``` Setting up SSL... Do you want to set up a SSL certificate and enable HTTPS now? - manual: Prompts for the path of user uploaded ssl certificates and set up nginx - auto: Will issue a free SSL certificate with https://www.letsencrypt.org and set up nginx - none: Do not setup HTTPS at all ================================================================================ 1) manual 2) auto 3) none #? 3 ``` Type **3** and hit **Enter** to start the installation. Once the installation has been completed successfully, you should see the following output: ``` Installation is almost complete. Please point your browser to http://your-server-ip to complete the process ============================================================== ================== ```   At this point, Passbolt is now installed on your server. ## Step 3 – Access Passbolt Configuration Wizard Next, you will need to configure Passbolt via a web browser. Open your web browser and type the URL http://your-server-ip. You will be redirected to the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/passbolt1.png) Click on the **Start the wizard** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/passbolt2.png) Click on the **Start configuration** to configure Passbolt as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/12/passbolt3.png) Under Database configuration, Set the host as **localhost.** Leave port as **3306** Provide your database details *created earlier* and click on the **Next** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/passbolt4.png) Give your server a **name**, **email**and click on the **Next** button to create a new server key. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/passbolt5.png) Provide your SMTP server settings and click on the **Next** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/passbolt6.png) Provide your server URL and click on the **Next** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/passbolt7.png) Provide your admin user details and click on the **Next** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/passbolt8.png) Click on the **“Download it here”** to download Passbolt chrome extension and click on the **retry** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/passbolt9.png) Provide your server IP and click on the **Next** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/passbolt10.png) Provide the owner name and owner email and click on the **Next** button to create a new key. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/passbolt11.png) Set your passphrase and click on the **Next** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/passbolt12.png) Click on the **Next** button. You will be redirected to the Passbolt login page as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/12/passbolt13.png) Provide your username, password and click on the **login** button. You should see the Passbolt dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/passbolt15.png) ## Conclusion Congratulations! You have successfully installed and configured Passbolt password manager on Ubuntu 18.04. You can now share your login credentials across your team using Passbolt. Set up Passbolt on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # Creating a Cloud Server from an ISO > URL: https://www.atlantic.net/vps-hosting/creating-a-cloud-server-from-an-iso/ | Published: 2020-12-09 | Updated: 2026-03-02 | Author: Josh Simon ## Introduction There are times when you may have a need for a Cloud Server with an operating system, virtual appliance, application, partition scheme, filesystems, packages, etc. that are not offered by one of the standard operating systems or One-click applications offered by Atlantic.Net.  To answer this need, Atlantic.Net offers the ability for you to create a Cloud Server using the ISO image of your choice in addition to our standard operating systems and one-click applications. **Some highlights offered when creating a Cloud Server from an ISO** - All non-Windows Operating Systems or Application ISOs are currently supported (Windows support coming soon). - Freedom and flexibility to choose any Cloud plan or Cloud location for your custom Cloud Server. - Complete control to choose your operating system, virtual application, partition scheme, filesystems, packages, etc. for your Cloud Server. - Great solution for customers that need customized solutions, specific compliance and regulatory requirements, and/or have specialized applications. ## **What you will learn in this guide** Creating a Cloud Server from an ISO Accessing the Cloud Server Console to perform the install of the Cloud Server Detaching an ISO from the Cloud Server   ## Creating a Cloud Server from an ISO **Menu Navigation** – click on *Server* in the https://cloud.atlantic.net control panel ![](https://www.atlantic.net/wp-content/uploads/2020/12/server.png) **Visit the Add Server Page** – click on the *Add Server* button ![](https://www.atlantic.net/wp-content/uploads/2020/12/add_server_button-e1634064558460.png) **Create your Cloud Sever using an ISO** - Click on the *ISOs* tab in the *Type* section - Enter the URL to your ISO (example: https://releases.ubuntu.com/20.04.1/ubuntu-20.04.1-live-server-amd64.iso) - Proceed with selecting the rest of your desired Cloud Server options and press the *Create Server* button ![](https://www.atlantic.net/wp-content/uploads/2020/12/iso_1.png)   ## Accessing the Cloud Server Console to perform the install of the Cloud Server On the *Server Details* page, you will see instructions to complete the install/configuration of your Cloud Server using the Cloud Server Console. You will also see information regarding the ISO that is attached to your Cloud Server. Click on the *Start Console* button to launch the *Cloud Server Console*. *Note: While an ISO is attached to your Cloud Server the actions you can take through the control panel and API on that server are restricted to certain allowed actions. Additionally, you will only be able to boot from the ISO. When you are done with the installation/configuration of your Cloud Server you will need to detach the ISO to boot into your configured Cloud Server.* ![](https://www.atlantic.net/wp-content/uploads/2020/12/vmdetails2-e1634064663867.png)   Once the page is done loading you should see the console of your Cloud Server and be able to begin install/setup of your operating system, virtual appliance, or application. *Note: It may take some time for your ISO to finish downloading and load for use. The time it takes will largely depend on the bandwidth of the site providing the ISO and the size of the ISO.*   ![](https://www.atlantic.net/wp-content/uploads/2020/12/ubuntu_installer.png)   ## Detaching an ISO from the Cloud Server Once you are done with the installation/setup of your operating system, virtual appliance, or application, you will need to detach the ISO from your Cloud Server to boot from your installed/configured Cloud Server. Click on the D*etach ISO and boot up Cloud Server* option to detach the ISO from your Cloud server. ![](https://www.atlantic.net/wp-content/uploads/2020/12/vmdetails2-1-e1634064734256.png)   Once the ISO is done detaching from your Cloud Server it will be booted automatically from storage instead of the ISO. You will also see that the ISO is not longer attached to your Cloud Server in the Control Panel and that you have additional actions available to you that were not available when the ISO was attached.   ![](https://www.atlantic.net/wp-content/uploads/2020/12/iso_detached-e1634064783673.png)   Your Cloud Server is now ready for normal use. Enjoy!   --- # How to Install PandoraFMS Server on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-pandorafms-server-on-centos-8/ | Published: 2020-12-10 | Updated: 2023-11-26 | Author: Hitesh Jethva Pandora FMS is free and open-source monitoring software that allows you to monitor thousands of systems and devices from a central location. It is highly scalable, suitable for complex and large environments. You can monitor the status and performance of web servers, databases, routers, firewalls, and many more types of devices using Pandora FMS. Pandora FMS uses TCP, UDP, ICMP, SNMP and HTTP protocol and agents to collect metrics from the client system. It is cross-platform and supports Windows and Linux operating systems. In this tutorial, we will show how to install and configure Pandora FMS server on CentOS 8. ## Step 1 – Install Apache and MariaDB Server Pandora FMS runs on a web server and uses MariaDB as a database backend. Therefore, you will need to install Apache and MariaDB server in your system. You can install them with the following command: ``` dnf update -y dnf install httpd mariadb-server -y ``` After installing both packages, start the Apache and MariaDB service and enable them to start at system reboot: ``` systemctl start httpd systemctl start mariadb systemctl enable httpd systemctl enable mariadb ``` ## Step 2 – Create a Database for Pandora FMS First, you will need to set the MariaDB root password. You can set it with the following command: ``` mysql_secure_installation ``` Answer all questions as shown below: ``` Enter current password for root (enter for none): Set root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` Next, log in to MariaDB with the following command: ``` mysql -u root -p ``` Provide your root password and create a database and user for Pandora FMS: ``` CREATE DATABASE pandora; GRANT ALL PRIVILEGES ON pandora.* to pandora@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from MariaDB with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install Pandora FMS By default, Pandora FMS is not available in the CentOS default repository, so you will need to add the Pandora repository to your system. You can create a Pandora repo with the following command: ``` nano /etc/yum.repos.d/pandorafms.repo ``` Add the following lines: ``` [artica_pandorafms] name=CentOS6 - PandoraFMS official repo baseurl=http://firefly.artica.es/centos7 gpgcheck=0 enabled=1 ``` Save and close the file, then install the Pandora FMS with the following command: ``` dnf install pandorafms_console -y ``` Once the installation has been completed, give proper permissions and ownership to the pandora directory: ``` chown -R apache:apache /var/www/html/pandora_console/ chmod -R 775 /var/www/html/pandora_console/ ``` Next, restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 4 – Access Pandora FMS Now, open your web browser and access the Pandora FMS web interface using the URL **http://your-server-ip/pandora_console**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/Pandora1.png) Click on the **Next** button. You should see the license agreement page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/pandora2.png) Accept the license agreement. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/pandora3.png) Make sure all the dependencies are installed, then click on the **Next** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/pandora4.png) Provide your root username, MariaDB root password, database name, and the path of the application and click on the **Next** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/pandora5.png) Click on the **Next** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/pandora6.png) Now, open your terminal and delete the install.php file: ``` rm -rf /var/www/html/pandora_console/install.php ``` Next, edit the config.php file and define your database details: ``` nano /var/www/html/pandora_console/include/config.php ``` Change the following lines as per your database settings: ``` // Begin of automatic config file $config["dbtype"] = "mysql"; //DB type (mysql, postgresql...in future others) $config["mysqli"] = true; $config["dbname"]="pandora"; // MySQL DataBase name $config["dbuser"]="pandora"; // DB User $config["dbpass"]="password"; // DB Password $config["dbhost"]="localhost"; // DB Host ``` Save and close the file, then go to the Pandora web installation screen and click on the **Click here to access to your Pandora FMS console**. You should see the Pandora login page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/pandora8.png) Provide the default user as admin and password as pandora and click on the **Login** button. You should see the Pandora FMS dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/pandora9.png) ## Conclusion Congratulations! You have successfully installed and configured Pandora FMS on CentOS 8. You can now install an agent package on the client system and start monitoring from the Pandora dashboard. Get started with Pandora FMS on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # What Is Malware? How It Works and How to Remove It > URL: https://www.atlantic.net/hipaa-compliant-hosting/what-is-malware-how-it-works-and-how-to-remove-it/ | Published: 2020-12-10 | Updated: 2026-03-01 | Author: Brandon Schroth The word malware is a short form of two words put together; malicious and software. It refers to a program designed to infiltrate a system without the victim’s knowledge and damage it. Once the cybercriminals have access to a computer network, the victim remains oblivious to the fact that his/her computer has been compromised. Malware is a huge cybersecurity threat, as it may result in loss of data and identity theft, among other unpleasant results. ![What is Malware?](https://www.atlantic.net/wp-content/uploads/2020/12/Malware.jpg) ## **How Does Malware Work?** Overall, malware is intended to bring profits for hackers. After infecting the computer, it steals the victim’s information, such as passwords and usernames, locations, contacts, and so much more. This information is usually sold to the dark web. With the help of certain types of [malware, i.e., ransomware](https://www.atlantic.net/vps-hosting/how-to-prepare-for-ransomware-malware-network-and-file-vulnerabilities/) , hackers access the victim’s computer and lock all the data stored on it. They then ask for a ransom to be paid in order for them to decrypt the data. ## **Different Types of Malware** Malware is a general term that refers to different types of threats. In this section, we’ll have a look at the different [types of malware and what they do](https://softwaretested.com/malware/) . ### **Viruses and worms** These two classes of malware are quite contagious. They’re both designed to replicate easily and move from one computer to another. Viruses mostly infect legitimate software and get into the computer when the victim uses the software. The viruses then perform malicious acts, such as destroying or corrupting data. On the other hand, worms spread from one computer to another without requiring any action from the user. They take advantage of any vulnerability they find in existing security tools or the operating system. ### **Trojans and rootkits** This second classification of malware involves a concealed attack on an unsuspecting user’s computer. Trojans disguise themselves by pretending to be harmless software. Most users download them unknowingly, thinking that they’re installing useful programs. Rootkits mask harmful viruses in such a way that they go unnoticed by antivirus programs. ### **Spyware and keyloggers** These two types of malware are used to monitor the victims’ actions, such as web browsing habits and the most frequently used applications. The data collected is used to commit [identity theft-related fraud](https://www.aura.com/learn/how-to-protect-yourself-from-identity-theft), such as stealing money from the victim’s bank account. ### **Ransomware** [Ransomware](https://www.tetradefense.com/incident-response/understanding-ransomware-how-it-works-and-how-to-avoid-it/) encrypts the victim’s data and sends a ransom note demanding that payment be made in Bitcoin, [Ethereum](https://paybis.com/ethereum-calculator/), or another cryptocurrency. The victim is threatened that if he/she doesn’t pay on time, either the ransom will increase or all their data will be permanently erased. This type of malware can be especially damaging for organizations who have a responsibility to maintain data security, such as those covered by the requirements of [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/). The perpetrators promise that a decryption key will be sent to them after the payment has been made. However, this does not necessarily happen – once the money has been paid, a cybercriminal might ignore the victim. ### **Adware** Adware is designed for the sole purpose of making money through advertising. It’s intended to get the user to watch as many ads as possible. Every time the user clicks on the ad, the cybercriminal gets some money. In most cases, these ads also steal the user’s information. ## **How Malware Spreads** Long ago, before the numerous technological advancements that we see today and before the pervasive spread of the Internet, malware was transferred from one computer to another manually. This happened through floppy discs or CD-ROMs. Today, malware may still be spread through physical means, but the vector is USB sticks or flash drives. However, this dubious software is more commonly delivered through other means. For example, infected attachments are distributed via email. When users click on the links, their personal information and other types of data are left vulnerable, especially if they don’t have any sort of [PC repair](https://softwaretested.com/pc-repair/) software tools installed. Some hackers deliver malware using complicated alerts in the hope of tricking unsuspecting victims into participating. For example, the victim may be made to believe that he/she has won a contest, missed a delivery or tax payment, or has received some money in their bank account. In this instance, the victim’s attention is fully drawn, and he/she is bound to follow that up with an action to try and get more information. Doing this activates the malware. Whenever the hackers have a specific target in mind, they can customize the false message to lure an individual or a particular organization. It’s worth knowing that malware may spread through means other than those described here. Some ways do not even require any action from the end-users. These techniques take advantage of software vulnerabilities in the system. ## **What Does Malware Do to Victims’ Devices?** How can one tell if their device has a malware infection considering that the damage is internal and not physical? It’s quite simple to figure this out, since malicious software usually performs repeated tasks that take up resources on your computer. Since malware is quite difficult to detect, some devices may be infected without the user ever noticing it. Here are some of the signs that are huge indicators showing that your device may have malware: - The computer becomes too slow. - Applications take too long to load. - The battery drains a lot faster than usual. - There are many annoying popup ads. - You start noticing apps that you didn’t download/install. - There’s a huge spike in data usage that you cannot explain. To further confirm your doubts, you should run an [anti-malware scan](https://www.atlantic.net/vps-hosting/). Make sure that you use the most comprehensive product in the market to keep your device safe. ## **How to Remove Malware** Malicious software sneaks into peoples’ computers when they least expect it. If your device has already been infected, you should remove the malware as soon as possible to prevent any further damage. The easiest way to remove malware from your computer is by using your antivirus program. If you’re having trouble removing the threats in a normal boot environment, try going into Safe Mode and tackle the infection from there. Keep your antivirus database updated at all times to prevent new malware from sneaking into your device. Although macOS and Windows both have their own malware scanners, some new viruses, like rootkit malware, are so complex that you need extra help.  This type of virus can’t be dealt with using your regular malware removal techniques, so don’t hesitate to ask for professional help. But the best way to deal with malware is to not get infected in the first place. Having a foolproof cybersecurity strategy in place ensures that your data and your devices are protected from all types of threats. ## **How to Protect Your Computer from Malware Infections** Even though all devices that connect to the Internet are prone to malware attacks, there are some actions that you can take to stay protected. These include: - Always making sure that your OS is up-to-date. - Keeping all your data backed up. - Scanning all executable files before you run them. - Avoiding opening unfamiliar emails and clicking on suspicious links. - Investing in reliable security software to protect your computer. **Conclusion** The threat of malware attacks keeps getting more serious with each passing day. Malware gets installed onto the victims’ computers without their consent and steals their personal information, usually for profit-making purposes. The attacks may happen on all types of devices, including PCs, tablets, and smartphones. Malware attacks also affect all types of operating systems ranging from Windows, Android, Linux, macOS, and iOS. --- # Install Ntopng to Monitor Network Traffic on Ubuntu > URL: https://www.atlantic.net/vps-hosting/install-ntopng-to-monitor-network-traffic-on-ubuntu/ | Published: 2020-12-11 | Updated: 2024-07-02 | Author: Hitesh Jethva Ntopng is software for monitoring network traffic. This free, open-source software provides a web interface for enabling real-time monitoring. Ntopng is essentially the next-generation version of the original ntop. It shows the network usage similar to the way popular UNIX commands do, but ntopng supports various operating systems, such as Windows, BSD, Mac OS, Linux, and UNIX. Ntopng is best described as a passive network monitoring tool. It is focused on statistics and flows that are obtained from the traffic that the server captures. While professional and enterprise editions of Ntopng have licensing requirements, the community edition has none. In this tutorial, we will show you how to install NtopNG on Ubuntu 20.04. ## Step 1 – Add ntopng Repository By default, the ntopng package is not available in the Ubuntu 20.04 default repository, so you will need to add the ntopng repository to your system. First, install the required dependencies to your server with the following command: ``` apt-get install wget gnupg -y ``` Next, download the ntopng repository package with the following command: ``` wget http://apt.ntop.org/18.04/all/apt-ntop.deb ``` Once the package is downloaded, install the downloaded package with the following command: ``` dpkg -i apt-ntop.deb ``` Once the repository is installed, update it with the following command: ``` apt-get update -y ``` ## Step 2 – Install and Configure ntopng Now, you can install the ntopng package with other packages using the following command: ``` apt-get install pfring-dkms nprobe ntopng n2disk cento -y ``` After installing ntopng, you will need to edit the ntopng configuration file and define your Network Interface, Port, and Location of the PID. ``` nano /etc/ntopng/ntopng.conf ``` Change the following lines per your requirements: ``` -G=/var/run/ntopng.pid -i=eth0 -w=3000 ``` Save and close the file when you are finished. Next, create a new configuration file and define your Network IP range: ``` nano /etc/ntopng/ntopng.start ``` Add the following lines as per your Network IP: ``` --local-networks "0.0.0.0/24" ## give your local IP Ranges here. --interface 1 ``` Save and close the file when you are finished. Then, start the ntopng service and enable it to start at system reboot with the following command: ``` systemctl start ntopng systemctl enable ntopng ``` You can also verify the status of the ntopng with the following command: ``` systemctl status ntopng ``` You should get the following output: - ``` ntopng.service - ntopng high-speed web-based traffic monitoring and analysis tool ``` ``` Loaded: loaded (/etc/systemd/system/ntopng.service; enabled; vendor preset: enabled) Active: active (running) since Thu 2020-10-01 09:10:02 UTC; 8min ago Main PID: 31314 (ntopng) Tasks: 52 (limit: 2353) Memory: 291.4M CGroup: /system.slice/ntopng.service └─31314 /usr/local/bin/ntopng /run/ntopng.conf Oct 01 09:10:06 ubuntu2004 ntopng[31314]: 01/Oct/2020 09:10:06 [startup.lua:226] Startup completed ``` ## Step 3 – Access ntopng Web Interface At this point, ntopng is started and listening on port 3000. You can check it with the following command: ``` ss -plunt | grep 3000 ``` You should get the following output: ``` tcp LISTEN 0 4096 0.0.0.0:3000 0.0.0.0:* users:(("ntopng",pid=31314,fd=33)) ``` Now, open your web browser and access the NtopNG dashboard using the URL **http://your-server-ip:3000**. ![](https://www.atlantic.net/wp-content/uploads/2020/12/ntop1.png) Provide the default username and password as **admin**/**admin** and click on the **Login** button. You will be redirected to the password reset screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/ntop2.png) Provide your new password and click on the **Change** **Password** button. You should see the ntopng dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/ntop3.png) Click on the **Hosts** button in the left pane. You should see your system information in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/ntop4.png) Click on the **Interface** button in the left pane. You should see your network information in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/ntop5.png) ## Conclusion Congratulations! You have successfully installed and configured ntopng on Ubuntu 20.04. You can now easily monitor your network usage in real-time. Get started with ntopng on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # How to Setup Nginx Cache on LEMP Server > URL: https://www.atlantic.net/vps-hosting/how-to-setup-nginx-cache-on-lemp-server/ | Published: 2020-12-12 | Updated: 2023-11-25 | Author: Hitesh Jethva Nginx is free, open-source web server, not to mention one of the most widely used web servers in the world. It can be used as a reverse proxy, mail proxy, load balancer and caching server. Nginx is highly scalable and specially designed for maximum performance and stability. It uses an event-driven architecture and handles every incoming request in a single thread. Nginx comes with a FastCGI module that can be used to cache dynamic content served from the PHP backend. You don’t need to set up other caching solutions such as Redis, Varnish, Memcache after setting up Nginx with FastCGI cache. In this tutorial, we will show you how to set up Nginx FastCGI cache with LEMP on Ubuntu 18.04. ``` ``` ## Step 1 – Install LEMP Server Let’s start with installing LEMP (Nginx, PHP, PHP-FPM) on your server. ``` apt-get install nginx php php-cli php-fpm -y ``` The above command will also install Apache web server in your system, so you will need to stop and disable the Apache service. ``` systemctl stop apache2 systemctl disable apache2 ``` Next, start the Nginx and PHP-FPM service with the following command: ``` systemctl start nginx systemctl start php7.2-fpm ``` Once you are finished, you can proceed to the next step. ## Step 2 – Create a Sample Website First, create a directory for your website with the following command: ``` mkdir /var/www/html/example.com ``` Next, create a sample info.php file inside your website directory: ``` nano /var/www/html/example.com/info.php ``` Add the following lines: ``` ``` Save and close the file. Then, change the ownership of your website to www-data user: ``` chown -R www-data:www-data /var/www/html/example.com chmod -R 755 /var/www/html/example.com ``` Once you are finished, you can proceed to the next step. ## Step 3 – Configure Nginx with FastCGI Cache Next, you will need to create a new Nginx virtual host configuration file to serve your website and enable the FastCGI cache. ``` nano /etc/nginx/sites-available/example.com.conf ``` Add the following lines: ``` # Enable FastCGI Support fastcgi_cache_path /etc/nginx/cache levels=1:2 keys_zone=nginxcache:150m max_size=1g inactive=60m use_temp_path=off; fastcgi_cache_key "$scheme$request_method$host$request_uri"; add_header X-Cache $upstream_cache_status; server { listen 80; root /var/www/html/example.com; client_max_body_size 256M; index info.php; server_name example.com; access_log /var/log/nginx/access.log; error_log /var/log/nginx/error.log; location = /favicon.ico { access_log off; log_not_found off; } #Disable caching for login session, user cookie, POST request, query string, site map and feeds set $skip_cache 0; if ($request_method = POST) { set $skip_cache 1; } if ($query_string != "") { set $skip_cache 1; } # Enable caching for your website. location ~ \.php$ { fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_pass unix:/var/run/php/php7.2-fpm.sock; fastcgi_index info.php; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_intercept_errors off; fastcgi_buffer_size 16k; fastcgi_buffers 4 16k; fastcgi_connect_timeout 600; fastcgi_send_timeout 600; fastcgi_read_timeout 600; fastcgi_cache nginxcache; fastcgi_cache_valid 200 301 302 60m; fastcgi_cache_use_stale error timeout updating invalid_header http_500 http_503; fastcgi_cache_min_uses 1; fastcgi_cache_lock on; } } ``` Save and close the file when you are finished, then check Nginx for any syntax errors with the following command: ``` nginx -t ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/12/lemp1.png) Next, enable the Nginx virtual host file with the following command: ``` ln -s /etc/nginx/sites-available/example.com.conf /etc/nginx/sites-enabled/ ``` Finally, reload the Nginx service to apply the changes: ``` systemctl restart nginx ``` A brief explanation of each directive in the above configuration file is shown below: - **fastcgi_cache_path** creates a FastCGI cache and specifies the cache location, memory zone name (nginxcache) with size (150M), max_size (1G), and defines the key for cache lookup. - **add_header** is used to validate whether the request has been served from the FastCGI cache or not. - **fastcgi** specifies the path of the php-fpm socket. - **fastcgi_cache** enables caching, which we have specified using the memory zone in fastcgi_cache_path directive. - **fastcgi_cache_valid** sets the cache time with status code 200, 301, 302 will be cached for 60 minutes. - **fastcgi_cache_lock** allows only first request through the upstream PHP-FPM server. ## Step 4 – Test Nginx FastCGI Cache At this point, Nginx is installed and configured with FastCGI Cache support. It’s time to verify whether the caching is working or not. Open your web browser, access your Nginx web server using the URL [http://example.com](http://example.com/), and reload the page a few times. Next, open your terminal and run the following command to fetch the http response header. ``` curl -I http://example.com ``` You should get the following output: ``` HTTP/1.1 200 OK Server: nginx/1.14.0 (Ubuntu) Date: Fri, 24 Apr 2020 16:07:24 GMT Content-Type: text/html; charset=UTF-8 Connection: keep-alive X-Cache: HIT ``` From the above output, X**-Cache: HIT**indicates that the response was served from the cache. ## Conclusion Congratulations! You have successfully configured Nginx with FastCGI Cache support. After enabling caching, you should notice a huge improvement in performance because pages are loaded without having to be rendered by PHP. Try out FastCGI Cache on Nginx today with Atlantic.Net’s [VPS hosting](https://www.atlantic.net/vps-hosting/) service. --- # How to Setup Nginx Cache on a LAMP Server > URL: https://www.atlantic.net/vps-hosting/how-to-setup-nginx-cache-on-a-lamp-server/ | Published: 2020-12-13 | Updated: 2023-11-27 | Author: Hitesh Jethva Apache is one of the most reliable and powerful web servers available. Apache is open-source, highly customizable, and comes with many modules that allow you to add additional functionality. It is known for its power and is specially designed for small-to-medium-sized websites. Using Apache in parallel with Nginx and FastCGI Cache allows you to get the best of both worlds. This setup will improve your web server performance using the strengths of both web server applications. Nginx FastCGI cache works by storing copies of files in a cache so that they can be accessed more quickly. In this tutorial, we will show you how to setup Nginx FastCGI cache with LAMP Server on Ubuntu 18.04. We will configure Apache as a backend server and Nginx as a frontend server with FastCGI Cache. ## Step 1 – Install LAMP Server First, install the Apache web server, PHP, PHP-FPM and other modules with the following command: ``` apt-get update -y apt-get install apache2 php php-fpm libapache2-mod-php7.2 libapache2-mod-fcgid -y ``` Once all the packages are installed, you will need to enable some required Apache modules so that Apache can work with PHP-FPM. You can enable them with the following command: ``` a2enmod actions fcgid alias proxy_fcgi ``` Next, restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` ## Step 2 – Create a Sample Website First, create a directory for your website with the following command: ``` mkdir /var/www/html/example.com ``` Next, create a sample info.php file inside your website directory: ``` nano /var/www/html/example.com/info.php ``` Add the following lines: ``` ``` Save and close the file, then change the ownership of your website to www-data user: ``` chown -R www-data:www-data /var/www/html/example.com chmod -R 755 /var/www/html/example.com ``` Once you are finished, you can proceed to the next step. ## Step 3 – Configure Apache Web Server By default, the Apache web server listens on port 80. Here, we will use Apache as a backend server, so *change the Apache default port from 80 to **8088***. ``` nano /etc/apache2/ports.conf ``` Change the line from “Listen 80” to “Listen 8088”: ``` Listen 8088 ``` Save and close the file when you are finished, then disable the Apache default virtual host file with the following command: ``` a2dissite 000-default.conf ``` Next, restart the Apache web server to implement the changes. ``` systemctl restart apache2 ``` Next, create a new virtual host configuration file to serve your website: ``` nano /etc/apache2/sites-available/example.com.conf ``` Add the following content: ``` ServerName 127.0.0.1 ServerAdmin webmaster@localhost DocumentRoot /var/www/html/example.com DirectoryIndex info.php # 2.4.10+ can proxy to unix socket SetHandler "proxy:unix:/run/php/php7.2-fpm.sock|fcgi://localhost" Options FollowSymLinks Includes ExecCGI AllowOverride All Require all granted CustomLog /var/log/apache2/access.log combined ErrorLog /var/log/apache2/error.log ``` Save and close the file when you are finished, then enable the Apache virtual host configuration file with the following command: ``` a2ensite example.com.conf ``` Next, restart the Apache service to apply the changes: ``` systemctl restart apache2 ``` At this point, the Apache web server is configured and listening on localhost on port 8088. ![](https://www.atlantic.net/wp-content/uploads/2020/12/nginx1.png) ## Step 4 – Configure Nginx as a Reverse Proxy with FastCGI Cache In this section, we will configure Nginx as a reverse proxy for Apache web server and enable FastCGI Cache. First, install the Nginx web server with the following command: ``` apt-get install nginx -y ``` Once installed, create a new Nginx virtual host configuration file: ``` nano /etc/nginx/sites-available/example.com.conf ``` Add the following content: ``` # Enable FastCGI Support proxy_cache_path /etc/nginx/cache levels=1:2 keys_zone=nginxcache:100m max_size=1g inactive=60m use_temp_path=off; fastcgi_cache_key "$scheme$request_method$host$request_uri"; add_header X-Cache $upstream_cache_status; server { listen 80; server_name example.com; access_log /var/log/nginx/access.log; error_log /var/log/nginx/error.log; location = /favicon.ico { access_log off; log_not_found off; } set $skip_cache 0; #Disable caching for login session, user cookie, POST request, query string, site map and feeds if ($request_method = POST) { set $skip_cache 1; } if ($query_string != "") { set $skip_cache 1; } # Enable caching for your website. location / { proxy_pass http://127.0.0.1:8088; proxy_set_header Host $host; proxy_buffering on; proxy_cache nginxcache; proxy_cache_use_stale error timeout invalid_header updating http_500 http_502 http_503 http_504; proxy_cache_valid 200 301 302 60m; proxy_cache_min_uses 1; proxy_cache_lock on; } } ``` Save and close the file when you are finished, then enable the Nginx virtual host file with the following command: ``` ln -s /etc/nginx/sites-available/example.com.conf /etc/nginx/sites-enabled/ ``` Next, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 5 – Test Nginx FastCGI Cache At this point, Nginx is installed and configured as a reverse proxy for Apache with FastCGI Cache support. It’s time to verify whether the caching is working or not. Open your web browser and access your Nginx web server using the URL [http://example.com](http://example.com/) and reload the page for a few times. Next, open your terminal and run the following command to fetch the http response header. ``` curl -I http://example.com ``` You should get the following output: ``` HTTP/1.1 200 OK Server: nginx/1.14.0 (Ubuntu) Date: Fri, 24 Apr 2020 17:01:42 GMT Content-Type: text/html; charset=UTF-8 Connection: keep-alive Vary: Accept-Encoding X-Cache: HIT ``` From the above output, **X-Cache: HIT** indicates that the response was served from the cache. ## Conclusion In the above guide, we have installed and configured the Apache web server as a backend server and Nginx as a frontend server with FastCGI caching. Hopefully, this setup will dramatically improve the performance of your webserver. Get started with FastCGI caching on your LAMP server with [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # Netstat Command Line Tips and Tricks > URL: https://www.atlantic.net/vps-hosting/netstat-command-line-tips-and-tricks/ | Published: 2020-12-14 | Updated: 2023-11-27 | Author: Hitesh Jethva Netstat, which stands for “network statistics,” is a network command-line utility that displays network connections, routing tables, network interface and network protocol statistics. It is very useful for checking your network configuration and activity. You can also get detailed information of which services are listening on which port and the details of any connections currently made to them. This tool is available in most versions of Windows, Linux, Unix, Solaris and BSD. Netstat helps a system administrator troubleshoot network-related problems and determine network traffic performance. In this tutorial, we will show you some useful netstat command-line tips and tricks. ## Install Netstat By default, the netstat utility comes pre-installed in most Linux operating systems. If not installed, you can install it by running the following command: ``` apt-get install net-tools -y ``` ## List All Connection You can list all TCP and UDP connections with listening and non-listening ports by using the option -a: ``` netstat -a ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/netstat.png) ## List Only TCP Connections To list only TCP connections, use the option -at as shown below: ``` netstat -at ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/netstat2.png) ## List Only UDP Connections To list only UDP connections, use the option -ut as shown below: ``` netstat -ut ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/netstat3.png) ## List All Listening Connections You can print only listening connections using the option -l as shown below: ``` netstat -l ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/netstat5.png) ## List Only TCP Listening Connections To list only active TCP connections, use the option -lt as shown below: ``` netstat -lt ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/netstat6.png) ## List Only UDP Listening Connections To list only active UDP connections, use the option -lu as shown below: ``` netstat -lu ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/netstat7.png) ## List Only Unix Listening Connection To list only listening UNIX Ports, use the option -lx as shown below: ``` netstat -lx ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/netstat8.png) ## List All Connections with PID and Process Name If you want to get a list of all connections with PID and process name, use the option -ap as shown below: ``` netstat -ap ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/netstat9.png) ## Display Service Name with PID and UID To display service name with PID and UID, use the option -tp as shown below: ``` netstat -nlpt ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/netstat10.png) ## Display Interface Statistics To display statistics about the network interface, use option -i as shown below: ``` netstat -i ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/netstat11.png) You can also print information about your network interface using the option -ie as shown below: ``` netstat -ie ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/netstat12.png) ## Display Routing Information To display information about network routing, use the option -r as shown below: ``` netstat -r ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/netstat13.png) ## Display IPv4 and IPv6 information To display multicast information for both IPv4 and IPv6 protocols, use the option -g as shown below: ``` netstat -g ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/netstat14.png) ## Disable Hostname Lookup When you run a netstat command, it will try to find the hostname of each connection. This will slow down your output. You can disable hostname lookup and display only IP address by running the following command: ``` netstat -ant ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/netstat15.png) ## Display Help Information You can display all options available with netstat utility using the following command: ``` netstat --help ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/netstat16.png) ## Conclusion In the above guide, you learned how to use netstat command to find active and inactive connections with TCP and UDP ports. This can help you to troubleshoot network related problems. Try netstat today on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net. --- # How to Install PowerDNS and PowerAdmin on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-powerdns-and-poweradmin-on-centos-8/ | Published: 2020-12-15 | Updated: 2023-11-25 | Author: Hitesh Jethva PowerDNS is a powerful and high-performance authoritative nameserver written in C++. It is an alternative to BIND DNS and uses MariaDB, MySQL, Oracle, and MariaDB to store records. PowerDNS runs on most UNIX-based operating systems and is used to host domains using DNSSEC. It uses a separate program called PowerDNS Recursor as the resolving DNS server. PowerDNS-Admin is an advanced web interface for PowerDNS used for managing zones and records through a web browser. In this tutorial, we will show you how to install PowerDNS and PowerAdmin with MariaDB backend on CentOS 8. ## Step 1 – Install LAMP Server First, install the Apache and MariaDB server with the following command: ``` dnf install httpd mariadb-server -y ``` Once installed, start the MariaDB and Apache services and enable them to start at system reboot with the following command: ``` systemctl start httpd systemctl start mariadb systemctl enable httpd systemctl enable mariadb ``` Next, you will need to install the latest version of PHP in your system. By default, the latest version of PHP is not available in CentOS 8, so you will need to add the Remi repository in your system. You can add it with the following command: ``` dnf install http://rpms.remirepo.net/enterprise/remi-release-8.rpm -y ``` Next, disable the default PHP module and enable the PHP Remi module with the following command: ``` dnf module reset php dnf module enable php:remi-7.4 ``` Next, install PHP and other required modules with the following command: ``` dnf install php php-devel php-gd php-imap php-ldap php-mysql php-odbc php-pear php-xml php- xmlrpc php-mbstring php-mcrypt php-mhash gettext php-pear -y ``` Once all the packages are installed, you can proceed to the next step. ``` systemctl start php-fpm systemctl enable php-fpm ``` ## Step 2 – Configure MariaDB Database Next, you will need to create a database and user for PowerDNS. First, log in to MariaDB with the following command: ``` mysql ``` Once logged in, create a database and user with the following command: ``` create database powerdnsdb; create user 'powerdns' identified by 'password'; ``` Next, grant all the privileges to the powerdnsdb with the following command: ``` grant all privileges on powerdnsdb.* to 'powerdns'@'localhost' identified by 'password'; ``` Next, flush the privileges with the following command: ``` flush privileges; ``` Next, change the database to powerdnsdb and create table structures with the following command: ``` use powerdnsdb; CREATE TABLE domains ( id INT AUTO_INCREMENT, name VARCHAR(255) NOT NULL, master VARCHAR(128) DEFAULT NULL, last_check INT DEFAULT NULL, type VARCHAR(6) NOT NULL, notified_serial INT DEFAULT NULL, account VARCHAR(40) DEFAULT NULL, PRIMARY KEY (id) ) Engine=InnoDB; CREATE UNIQUE INDEX name_index ON domains(name); CREATE TABLE records ( id BIGINT AUTO_INCREMENT, domain_id INT DEFAULT NULL, name VARCHAR(255) DEFAULT NULL, type VARCHAR(10) DEFAULT NULL, content VARCHAR(64000) DEFAULT NULL, ttl INT DEFAULT NULL, prio INT DEFAULT NULL, change_date INT DEFAULT NULL, disabled TINYINT(1) DEFAULT 0, ordername VARCHAR(255) BINARY DEFAULT NULL, auth TINYINT(1) DEFAULT 1, PRIMARY KEY (id) ) Engine=InnoDB; CREATE INDEX name_index ON domains(name); CREATE INDEX nametype_index ON records(name,type); CREATE INDEX domain_id ON records(domain_id); CREATE INDEX recordorder ON records (domain_id, ordername); CREATE TABLE supermasters ( ip VARCHAR(64) NOT NULL, nameserver VARCHAR(255) NOT NULL, account VARCHAR(40) NOT NULL, PRIMARY KEY (ip, nameserver) ) Engine=InnoDB; CREATE TABLE comments ( id INT AUTO_INCREMENT, domain_id INT NOT NULL, name VARCHAR(255) NOT NULL, type VARCHAR(10) NOT NULL, modified_at INT NOT NULL, account VARCHAR(40) NOT NULL, comment VARCHAR(64000) NOT NULL, PRIMARY KEY (id) ) Engine=InnoDB; CREATE INDEX comments_domain_id_idx ON comments (domain_id); CREATE INDEX comments_name_type_idx ON comments (name, type); CREATE INDEX comments_order_idx ON comments (domain_id, modified_at); CREATE TABLE domainmetadata ( id INT AUTO_INCREMENT, domain_id INT NOT NULL, kind VARCHAR(32), content TEXT, PRIMARY KEY (id) ) Engine=InnoDB; CREATE INDEX domainmetadata_idx ON domainmetadata (domain_id, kind); CREATE TABLE cryptokeys ( id INT AUTO_INCREMENT, domain_id INT NOT NULL, flags INT NOT NULL, active BOOL, content TEXT, PRIMARY KEY(id) ) Engine=InnoDB; CREATE INDEX domainidindex ON cryptokeys(domain_id); CREATE TABLE tsigkeys ( id INT AUTO_INCREMENT, name VARCHAR(255), algorithm VARCHAR(50), secret VARCHAR(255), PRIMARY KEY (id) ) Engine=InnoDB; CREATE UNIQUE INDEX namealgoindex ON tsigkeys(name, algorithm); ``` You can now list all tables with the following command: ``` show tables; ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/12/dns1.png) Next, exit from the MariaDB with the following command: ``` exit; ``` ## Step 3 – Install PowerDNS Before installing PowerDNS, you will need to disable systemd-resolve service. You can disable it with the following command: ``` systemctl disable systemd-resolved systemctl stop systemd-resolved ``` Next, add new name server entry with the following command: ``` ls -lh /etc/resolv.conf echo "nameserver 8.8.8.8" | tee /etc/resolv.conf ``` Finally, install PowerDNS with other required packages using the following command: ``` dnf install pdns pdns-backend-mysql bind-utils -y ``` After installing PowerDNS, you will need to configure PowerDNS to use MySQL as backend instead of BIND. You can do it by editing the file /etc/pdns/pdns.conf: ``` nano /etc/pdns/pdns.conf ``` Remove the launch=bind line and add the following lines: ``` launch=gmysql gmysql-host=localhost gmysql-user=powerdns gmysql-password=password gmysql-dbname=powerdnsdb ``` Save and close the file, then start PowerDNS service and enable it to start on boot. ``` systemctl start pdns systemctl enable pdns ``` ## Step 4 – Install PowerAdmin First, download the latest version of PowerAdmin with the following command: ``` wget http://downloads.sourceforge.net/project/poweradmin/poweradmin-2.1.7.tgz ``` Once downloaded, extract the downloaded file with the following command: ``` tar xvf poweradmin-2.1.7.tgz ``` Next, move the extracted directory to the Apache root directory: ``` mv poweradmin-2.1.7 /var/www/html/poweradmin/ ``` Next, change the ownership of the poweradmin directory to apache with the following command: ``` chown -R apache:apache /var/www/html/poweradmin ``` ## Step 5 – Access PowerAdmin Web Interface Now, open your web browser and access the PowerAdmin web interface using the URL http://your-server-ip/poweradmin/install. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/dns2.png) Select your desired language and click on “**Go to step 2.**” You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/dns3.png) Now, click on “**Go to step 3.**” You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/dns4.png) Provide your PowerDNS database details and administrator password and click on “**Go to step 4.**” You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/dns5.png) Provide the PowerDNS user, password, host, and nameserver and click on “**Go to step 5.**” You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/dns6.png) Now, open your terminal, log in to MySQL, and grant the new user all required permissions with the following command: ``` GRANT SELECT, INSERT, UPDATE, DELETE ON powerdnsdb.* TO 'user1'@'localhost' IDENTIFIED BY 'password'; ``` Next, click on “**Go to step 6.**” You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/dns7.png) Now, create a new file named config.inc.php as shown below: ``` nano /var/www/html/poweradmin/inc/config.inc.php ``` Paste the content from the web page: ``` URL: https://www.atlantic.net/vps-hosting/how-to-install-vestacp-control-panel-on-debian-9/ | Published: 2020-12-17 | Updated: 2025-12-12 | Author: Hitesh Jethva VestaCP is a powerful, free, open-source control panel that helps you to create and manage a website, email, database, and DNS from its web-based interface. You can manage a website, domain, FTP, SSL, and backups with the help of VestaCP. It has a built-in Softaculous auto-installer that allows you to install more than 439 apps with one click. If you are looking for a cost-effective alternative to cPanel, then VestaCP is the best solution for you. In this tutorial, we will show you how to install VestaCP on Debian 9. ## Step 1 – Install Required Dependencies Before starting, you will need to install some dependencies on your server. You can install all of them with the following command: ``` apt-get update -y apt-get install nano wget curl unzip gnupg -y ``` Once all the packages are installed, you can proceed to the next step. ## Step 2 – Install VestaCP VestaCP provides an auto-installer script to install the VestaCP in your server. You can download it with the following command: ``` curl -O http://vestacp.com/pub/vst-install.sh ``` Once the download is completed, give proper permissions with the following command: ``` chmod +x vst-install.sh ``` Next, start the VestaCP installation by running the script as shown below: ``` bash vst-install.sh --force ``` You will be asked to provide a valid email address and domain name as shown below: ``` _| _| _|_|_|_| _|_|_| _|_|_|_|_| _|_| _| _| _| _| _| _| _| _| _| _|_|_| _|_| _| _|_|_|_| _| _| _| _| _| _| _| _| _|_|_|_| _|_|_| _| _| _| Vesta Control Panel The following software will be installed on your system: - Nginx Web Server - Apache Web Server (as backend) - Bind DNS Server - Exim Mail Server - Dovecot POP3/IMAP Server - MariaDB Database Server - Vsftpd FTP Server - Softaculous Plugin - Iptables Firewall + Fail2Ban Would you like to continue [y/n]: y Please enter admin email address: hitjethva@gmail.com Please enter FQDN hostname [centos]: vesta.example.com ``` Provide your email, domain name and hit Enter to start the installation. Once the installation has been completed, you should see the following output: ``` Installation backup directory: /root/vst_install_backups/1602913863 ======================================================= _| _| _|_|_|_| _|_|_| _|_|_|_|_| _|_| _| _| _| _| _| _| _| _| _| _|_|_| _|_| _| _|_|_|_| _| _| _| _| _| _| _| _| _|_|_|_| _|_|_| _| _| _| Congratulations, you have just successfully installed Vesta Control Panel https://vesta.example.com:8083 username: admin password: OkF1MklD0p We hope that you enjoy your installation of Vesta. Please feel free to contact us anytime if you have any questions. Thank you. -- Sincerely yours vestacp.com team ``` At this point, VestaCP is installed and listening on port 8083. Please remember the admin username and password as shown above. ## Step 3 – Access VestaCP Web Interface Now, open your web browser and type the URL **https://vesta.example.com:8083**. You should see the VestaCP login page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/deb1.png) Provide your admin username, password and click on the **Log in** button. You should see the VestaCP dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/deb2.png) ## Step 4 – Add a New Website To create a new website, click on **WEB**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/deb3.png) Click on the **+**button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/deb6.png) Provide your website domain name and IP address and click on the **Add** button. Once the website is created, you should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/deb8.png) Now, open your web browser and access your new website using the URL **http://web1.example.com**. You should see your website default page in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/dev9.png) You can now FTP to your server and add your site to the public_html folder. Your public_html file should be located in the following directory: ``` /web/your-ip-domain-name/public_html ``` In our example, it is: ``` /web/web1.example.com/public_html ``` You can get a simple FTP client called [Filezilla here if you need one.](https://filezilla-project.org/) Congratulations! You have just created a website on the Vesta control panel. Thank you for following this guide! Be sure to check back here for updates. ## Conclusion Congratulations! You have successfully installed VestaCP on a Debian 9 server. You can now explore and VestaCP dashboard for more functionality and start managing your database, domain, email and DNS from a central location. Get started with VestaCP on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # How VPS is Giving a Competitive Edge to Forex Trading > URL: https://www.atlantic.net/vps-hosting/how-vps-is-giving-a-competitive-edge-to-forex-trading/ | Published: 2020-12-18 | Updated: 2026-03-03 | Author: Alexander Wise Improving your Forex trading speed while cutting costs is an important factor for all traders. Securing a competitive edge and preventing theft from cyber criminals has never been more vital than in today’s current landscape. In the wake of COVID-19, we have seen a real push towards internet-based trading in the majority of financial industries. Fintech has exploded in the last year, providing anyone with an internet connection the ability to complete a trade at their fingertips. However, in the world of Forex, we’ve seen a range of different developments favoring a more secure and faster approach. One of the most interesting developments is the [increasing use of Virtual Private Servers](https://www.atlantic.net/vps-hosting/how-to-choose-the-right-vps-plan-for-your-business/) , or VPS, to circumnavigate the need for a traditional internet connection when trading. The low latency provided by VPS as well as the increased security result in Forex traders experiencing less negative slippage and avoiding wasting time with requotes and off-quotes. This article will look into VPS and explore the benefits it provides for Forex traders as well as its impact on latency. We’ll also discuss how it can help your Forex trading reach new heights and secure you a competitive edge. ## VPS & Forex Forex, or foreign currency exchange, has been in a real state of flux since the beginning of the pandemic, and has presented traders with [several opportunities](https://www.reuters.com/article/us-health-coronavirus-fx/explosion-in-forex-volatility-cheers-some-bruises-others-as-virus-fears-drive-swings-idUSKBN20Y3B4) . However, these opportunities can also come with additional risks. Two currencies can produce great profits or bad losses if judged incorrectly. More importantly, working with a computer that lags behind in response time (referred to as high latency) can prove disastrous for a time sensitive deal. While speed is a concern for most Forex traders, another main concern is protection from hackers. A VPS, or Virtual Private Server, gives you an added layer of security. Running your trading through this type of server is much safer and faster than working from your own stationary server and can also [be more affordable](https://www.atlantic.net/vps-hosting/how-vps-saves-hosting-costs/) as well. ### What Is a VPS? A VPS is essentially the hosting equivalent of a subscription service such as Netflix. As opposed to owning, you are basically renting your space on the server. VPS servers can also be [partitioned for each individual trader](https://www.accuwebhosting.com/blog/speed-profits-understanding-vps-works-forex-trading/) , with specific IPs given to traders sustaining specific service. This provides protection from hackers similar to that offered by VPNs. Regardless of where you are, you can access your VPS and it’s available around the clock, even in the event of a power outage. Like all subscription services, once you quit your VPS service your partitioned space on the server is wiped, with a new subscriber being given a new IP. VPS gives you your own RAM, data limits, OS, etc, so it is different from other websites that make you share resources. In addition, virtual private servers are more flexible than dedicated servers. Forex markets hit a high of [$6.6 trillion per day](https://tokenist.com/investing/forex-trading-guide/) in 2019, so despite what cynics say, it’s a huge industry that has been growing year on year. Security and speed will continue to be a driving factor behind the success of many current and future traders. ## Latency & VPS The bane of many a trader’s existence, latency is the delay between your computer’s command being sent and the server (trading exchange in this case) receiving the command, known to the gaming community as a ‘lag’. In the Forex world, this [can be the difference](https://www.cnbc.com/2020/01/27/latency-arbitrage-trading-costs-investors-5-billion-a-year-study.html) between making a successful or failed trade. ### What Is Latency? Latency, in layman’s terms, is the amount of time a command takes to travel a computer network. It is generally quantified in milliseconds. A [latency level below 100 milliseconds](https://susedefines.suse.com/definition/lower-latency/) (ms) is considered decent, whereas a latency level below 50 ms is very good and ideal for Forex trading. Normal cable internet or DSL connections have latencies that hover below 100 ms, while satellite connections have latencies of 500 ms or even higher. What difference does a few milliseconds make? Depending on the volume of trading you are doing, this can add up to thousands of dollars lost over the course of a year, not to mention wasted time dealing with requotes. ### How a VPS Can Help Virtual private servers can alleviate these issues by providing traders with a secure, speedy, and reliable platform to conduct their trades. While more expensive than other hosting options such as shared hosts, VPS platforms still [offer greater power](https://hostingcanada.org/#top-hosting-types-for-canadians:~:text=costs%20a%20bit%20more%20but%20also%20has%20more%20power) and speed. This is why the importance of having a VPS shouldn’t be overlooked for any trader, be that a beginner or a seasoned veteran. ## Why Virtualization Matters From a technical standpoint, another way in which high latency is prevented is through [direct market access (DMA)](https://blackwellglobal.com/latency-forex-trading/) , an account type which directly connects the buying trader with the order book before an exchange. This reduces the amount of steps needed to complete a trade. Until recently, most retail traders did not have access to this technology, meaning this advantage was almost entirely with institutional traders. However, DMA is only as good as the latency levels within which they operate. Virtualization has brought positive changes to the majority of industries it has affected, but with the move to the digitalization of wealth, online traders can be at risk from cybercriminals. Therefore, protecting yourself when trading is more important than ever, especially when  even the top trading platforms [have significant vulnerabilities](https://www.networkcomputing.com/network-security/trading-online-steps-take-avoid-getting-phished) that can be easily exploited. ### How Does Virtualization Help with Forex Trading? In the context of Forex trading, virtualization creates compartmentalized virtual servers, which gives traders specific space at a price you can afford, and scalable to whatever you need. This helps avoid fees associated with the trading engines that are commonly used by Forex traders. Using a VPS, you can affect trades from wherever you want, because the software on the VPS doesn’t require a traditional internet connection to make trades. Cutting out infrastructural costs are a great way to improve your trading success and margins. Utilizing VPS is a viable place to start, and can help develop your competitive edge. ## Creating a Competitive Edge With minimal barriers to entry, there has been a real influx of traders in recent years, which in turn has an impact on the market. To be successful with all the competition, limiting your costs and improving your trading is key. As most people will tell you in the Forex game, there are seven major currency pairs, which each [have different extraneous variables](https://www.investopedia.com/terms/forex/m/majors.asp) affecting them. Finding ways to create a competitive edge for your trading portfolio is vital. With the use of VPS, traders can benefit from locational access and cutting overall costs. Furthermore, with VPS they have the ability to trade automatically any time of day or night, which can reduce stress and save a lot of valuable time. Unsurprisingly, Forex and VPS work incredibly well together, creating a 24/7 trading capability that is uninterrupted and available worldwide. With reduced latency and the availability of scalable options, it’s pretty easy to see how the benefits can affect traders in a number of ways. Having near 100% uptime for traders backed by Atlantic.Net’s SLA makes VPS options a great addition to their portfolio. The seamless remote execution of automated trading strategies opens up a plethora of new opportunities to make better trades. ## A Viable Direction for Forex Trading In short, VPS runs remotely and allows you to be completely independent of unforeseeable problems that can arise when working with your own server. For most traders, security and speed is one of the major factors in investment decisions, so having a VPS that can give you robust security is a must. This will not only keep your system safe by preventing data from being broadcasted across a larger internet network, but also [utilizes the cloud to transport data](https://www.atlantic.net/vps-hosting/what-can-you-do-with-a-vps-and-cloud-server/) , making it more secure. Ultimately, whether COVID-19 was a catalyst or just a coincidence for the rise in FX traders using VPS remains unclear. However, the simple fact remains that [VPS services](https://www.atlantic.net/vps-hosting/) have become very popular in recent months and years for more reasons than one. --- # How to Install Elgg Social Network on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-elgg-social-network-on-ubuntu-20-04/ | Published: 2020-12-21 | Updated: 2024-03-04 | Author: Hitesh Jethva Elgg is an open-source and highly customizable framework used for building an online social environment. It provides a simple and powerful user interface that helps to manage and build your content through a web browser. Elgg offers a rich set of features including messaging, microblogging, file-sharing, RSS support, access control, groups, and many more. In this tutorial, we will show you how to install and configure Elgg social networking platform on Ubuntu 20.04. ## Prerequisites • A fresh Ubuntu 20.04 on the Atlantic.Net Cloud Platform • A valid domain name pointed to your server IP • A root password configured on your server ## Step 1 – Install Apache, MariaDB and PHP Elgg runs on Apache web server, is written in PHP, and uses MySQL/MariaDB as a database backend, so you will need to install the Apache, MariaDB, PHP and other required PHP extensions to your server. You can install all of them with the following command: ``` apt-get install apache2 mariadb-server php libapache2-mod-php php-common php-sqlite3 php-curl php-intl php-mbstring php-xmlrpc php-mysql php-gd php-xml php-cli php-zip unzip wget -y ``` After installing all the packages, edit the php.ini file and change some recommended settings. ``` nano /etc/php/7.4/apache2/php.ini ``` Change the following values: ``` max_execution_time = 300 memory_limit = 512M upload_max_filesize = 100M date.timezone = Asia/Kolkata ``` Save and close the file, then restart the Apache service to apply the configuration changes. ``` systemctl restart apache2 ``` ## Step 2 – Create a Database for Elgg Next, you will need to create a database and user for Elgg. First, log in to MySQL shell with the following command: ``` mysql ``` Once logged in, create a database and user with the following command: ``` CREATE DATABASE elgg; CREATE USER 'elgg'@'localhost' IDENTIFIED BY 'secure-password'; ``` Next, grant all the privileges to the elgg database with the following command: ``` GRANT ALL ON elgg.* TO 'elgg'@'localhost' IDENTIFIED BY 'secure-password' WITH GRANT OPTION; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` At this point, the MariaDB database is created for Elgg. ## Step 3 – Install Elgg First, download the latest version of Elgg from its official website using the following command: ``` wget https://elgg.org/download/elgg-3.3.13.zip ``` Once the download is completed, unzip the downloaded file with the following command: ``` unzip elgg-3.3.13.zip ``` Next, move the extracted directory to the Apache root directory: ``` mv elgg-3.3.13 /var/www/html/elgg ``` Next, create a data directory and set proper ownership and permissions to the Elgg directory: ``` mkdir /var/www/html/data chown -R www-data:www-data /var/www/html/elgg chown -R www-data:www-data /var/www/html/data chmod -R 755 /var/www/html/elgg ``` Once you are finished, you can proceed to the next step. ## Step 4 – Configure Apache for Elgg Next, you will need to configure Apache to serve Elgg. You can configure it by creating a new Apache virtual host configuration file: ``` nano /etc/apache2/sites-available/elgg.conf ``` Add the following lines: ``` ServerAdmin admin@example.com DocumentRoot /var/www/html/elgg/ ServerName elgg.example.com Options FollowSymLinks AllowOverride All ErrorLog /var/log/apache2/elgg-error_log CustomLog /var/log/apache2/elgg-access_log common ``` Save and close the file, then enable the virtual host and Apache rewrite module with the following command: ``` a2ensite elgg.conf a2enmod rewrite ``` Finally, restart the Apache service to apply the changes: ``` systemctl restart apache2 ``` ## Step 5 – Access Elgg Web Interface Now, open your web browser and access the Elgg web interface using the URL http://elgg.example.com. You should see the Elgg welcome screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/elgg1.png) Click on the Next button. You should see the PHP requirement check page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/elgg2.png) Once all checks are passed, click on the Next button. You should see the database configuration page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/elgg3.png) Provide your database information, data directory, and site URL and click on the Next button. You should see the site configuration page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/elgg4.png) Provide your database table prefix, data directory, site URL, and timezone and click on the Next button. You should see the site creation page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/elgg5.png) Provide your site name and email and click on the Next button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/elgg6.png) Provide your admin username, password, email and click on the Next button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/elgg7.png) Click on Go to site. You should see the Elgg login page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/elgg8.png) Provide your admin username and password and click on the Log in button. You should see the Elgg dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/elgg9.png) ## Conclusion In the above guide, you learned how to install and configure the Elgg social networking platform on Ubuntu 20.04. You can now deploy your own social networking platform in your internal network or live environment. Get started with Elgg today on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to install Hugo Website Generator on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-install-hugo-website-generator-on-ubuntu/ | Published: 2020-12-22 | Updated: 2023-11-22 | Author: Hitesh Jethva Hugo is an open-source static website generator designed for small projects and informative sites. It is written in Go language, making it very secure and extremely fast. Hugo provides a great writing experience and is optimized for website viewing. You don’t need to install any dependencies such as PHP, Python, or databases to run Hugo sites. In this tutorial, we will show you how to install and use the Hugo site generator on Ubuntu 20.04. ## Step 1 – Install Hugo By default, Hugo is not available in the Ubuntu 20.04 default repository, so you will need to download the latest version of Hugo package from the Git repository. You can download it with the following command: ``` wget https://github.com/gohugoio/hugo/releases/download/v0.79.0/hugo_0.79.0_Linux-64bit.deb ``` Once the package is downloaded, you can install it with the following command: ``` dpkg -i hugo_0.79.0_Linux-64bit.deb ``` If you see any dependency errors, you can resolve them with the following command: ``` apt-get install -f ``` After installing Hugo, verify the installed version of Hugo with the following command: ``` hugo version ``` You should get the following output: ``` Hugo Static Site Generator v0.79.0-1415EFDC linux/amd64 BuildDate: 2020-11-27T09:09:02Z ``` ## Step 2 – Create a Website Using Hugo First, create a new website named web1.doamin.com using the hugo command, as shown below: ``` hugo new site web1.domain.com ``` You should get the following output: ``` Congratulations! Your new Hugo site is created in /root/web1.domain.com. Just a few more steps and you're ready to go: 1.Download a theme into the same-named folder. Choose a theme from https://themes.gohugo.io/ or create your own with the "hugo new theme " command. 2. Perhaps you want to add some content. You can add single files with "hugo new /.". 3. Start the built-in live server via "hugo server". ``` ``` Visit https://gohugo.io/ for quickstart guide and full documentation. ``` You can see the list of all files and directories generated by Hugo with the following command: ``` ls web1.domain.com ``` Output: ``` archetypes  config.toml  content  data  layouts  static  themes ``` ## Step 3 – Create Your First Page Now, change the directory to your website and create a new page named main.md with the following command: ``` cd web1.domain.com hugo new main.md ``` You should get the following output: ``` /root/web1.domain.com/content/main.md created ``` Next, edit the main.md page and add some content: ``` nano content/main.md ``` Add the following lines at the end of file: ``` # Test Page This is my first test page. ``` Save and close the file when you are finished. ## Step 4 – Download and Install a Theme First, change the directory to themes and download the Hugo theme with the following command: ``` cd web1.domain.com/themes wget https://github.com/digitalcraftsman/hugo-strata-theme/archive/master.zip ``` Once downloaded, unzip the downloaded file with the following command: ``` unzip master.zip ``` Next, rename the extracted directory with the following command: ``` mv hugo-strata-theme-master hugo-strata-theme ``` Next, copy the sample content from the config.toml file located inside themes directory to the default config.toml file: ``` cat hugo-strata-theme/exampleSite/config.toml > ../config.toml ``` Next, edit the config.toml file with the following command: ``` nano ../config.toml ``` Change the base URL and define your page name as shown below: ``` baseurl = "/" [[menu.main]] name = "main" url  = "main" weight = 5 ``` Save and close the file, then create a landing page layout file with the following command: ``` nano /root/web1.domain.com/layouts/index.html ``` Add the following lines: ``` {{ define "main" }} {{ if not .Site.Params.about.hide }} {{ partial "about" . }} {{ end }} {{ if not .Site.Params.portfolio.hide }} {{ partial "portfolio" . }} {{ end }} {{ if not .Site.Params.recentposts.hide }} {{ partial "recent-posts" . }} {{ end }} {{ if not .Site.Params.contact.hide }} {{ partial "contact" . }} {{ end }} {{ end }} ``` Save and close the file. ## Step 5 – Build Your Website Now, change the directory to your website and build your Hugo website using the following command: ``` cd /root/web1.domain.com hugo ``` You should get the following output: ``` Start building sites … WARN 2020/12/06 09:21:44 Page.Hugo is deprecated and will be removed in a future release. Use the global hugo function. WARN 2020/12/06 09:21:44 Page.RSSLink is deprecated and will be removed in a future release. Use the Output Format's link, e.g. something like: {{ with .OutputFormats.Get "RSS" }}{{ .RelPermalink }}{{ end }} | EN -------------------+----- Pages            |  7 Paginator pages  |  0 Non-page files   |  0 Static files     | 26 Processed images |  0 Aliases          |  2 Sitemaps         |  1 Cleaned          |  0 ``` Next, start the Hugo server by specifying your server IP as shown below: ``` hugo server --bind=0.0.0.0 --baseUrl=http://your-server-ip -D -F ``` You should get the following output: ``` Start building sites … WARN 2020/12/06 09:22:02 Page.Hugo is deprecated and will be removed in a future release. Use the global hugo function. WARN 2020/12/06 09:22:02 Page.RSSLink is deprecated and will be removed in a future release. Use the Output Format's link, e.g. something like: {{ with .OutputFormats.Get "RSS" }}{{ .RelPermalink }}{{ end }} | EN -------------------+----- Pages            | 11 Paginator pages  |  0 Non-page files   |  0 Static files     | 26 Processed images |  0 Aliases          |  3 Sitemaps         |  1 Cleaned          |  0 Built in 35 ms Watching for changes in /root/web1.domain.com/{archetypes,content,data,layouts,static,themes} Watching for config changes in /root/web1.domain.com/config.toml Environment: "development" Serving pages from memory Running in Fast Render Mode. For full rebuilds on change: hugo server --disableFastRender Web Server is available at http://69.87.216.179:1313/ (bind address 0.0.0.0) Press Ctrl+C to stop ``` ## Step 6 – Access Hugo Web UI Now, open your web browser and type the URL **http://your-server-ip:1313**. You should see the Hugo dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/hugo1.png) Click on **main** in the left pane. You should see your page in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/hugo2.png) ## Conclusion In the above guide, you learned how to install Hugo and generate a static website on Ubuntu 20.04. You should now have enough knowledge to build your own static website easily with Hugo; try it today on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Top 10 Healthcare Marketing Agencies > URL: https://www.atlantic.net/hipaa-compliant-hosting/top-10-healthcare-marketing-agencies/ | Published: 2020-12-22 | Updated: 2025-12-05 | Author: Dr. Rachael Bailey The marketing and advertising sector is highly competitive, so businesses must ensure that they stay ahead of their adversaries. Cloud computing can provide agencies with the competitive edge needed to thrive. ## Why are healthcare marketing agencies turning towards the cloud? Cloud-based services can offer significant benefits to many creative agencies, including marketing agencies, web developers, and advertising agencies. Cloud computing can: - Help businesses to increase their productivity and efficiency by providing 24/7 access to hosted applications, tools, and data from any location - Enhance a business’s reach and engagement with its audience, improving both communication and collaboration - Reduce costs by negating the need for expensive infrastructure, as many cloud providers offer a pay-as-you-go structure - Level the playing field so that smaller marketing companies can compete with their larger competitors - Improve analysis of real-time, actionable data to allow the success of marketing campaigns to be continuously monitored - Provide access to reliable insight that helps businesses to tailor their content to best suit the needs of their clients - Increase data security and provide access to automatic and constant backups - Provide clients with on-demand scalability and the ability to allocate and optimize resources to meet the needs of the business. - Ensure complete freedom for creativity in content, social media, and [SMS marketing](https://dexatel.com/sms-marketing/) strategies for better results. - Enable marketing agencies to shift towards inbound marketing techniques, such as blog posts, [online podcasts](https://podcastle.ai/blog/audio-chat-online-podcast-or-radio), video tutorials, and e-books, as opposed to traditional outbound approaches, such as cold calls, trade shows, and advertising - Ensure full HIPAA compliance for those healthcare marketing agencies dealing with sensitive patient information - Provide [marketing automation](https://www.engagebay.com/marketing/marketing-automation) to improve productivity and precision Here, we take a closer look at some of the leading marketing agencies, highlighting our top 10 choices: ## 1. Signify Digital With over 15 years of experience providing marketing solutions for the healthcare industry, Signify offers its clients a tailored, multi-platform marketing approach that maximizes public awareness and online presence and generates new business leads. Signify’s clients include health tech startups, private consultants, national hospitals, and healthcare charities. ## 2. Wisevu [Wisevu](https://www.wisevu.com/) is a trusted healthcare marketing agency with more than a decade of experience helping medical organizations grow online. The team understands the unique challenges of healthcare marketing, including compliance requirements, competitive markets, and local search complexities. Wisevu offers a full suite of healthcare-specific services, including **SEO, PPC management, website development, and online reputation solutions**. These strategies are designed to improve your online visibility, attract new patients, and deliver measurable growth. With a proven track record of success, Wisevu has helped specialty medical practices increase **organic traffic, lead volume, and appointment bookings** through data-driven strategies. If you’re looking for a reliable partner to enhance your digital presence and consistently drive revenue, Wisevu is an excellent choice. ## 3. LEVO Health Levo Health provides healthcare branding, patient engagement platforms, and direct to patient medical marketing solutions to physician groups, surgery centers, medical practices, and hospitals on a global scale. This full-service advertising and consulting agency is passionate about helping its clients to grow and strengthen their healthcare brand, accelerate business outcomes, and increase patient acquisition and engagement. ## 4. Distill Health Distill Health is a boutique healthcare and communications marketing agency that provides its clients with a full spectrum of services, including brand development, digital marketing, strategic storytelling, and brand activation. The team at Distill Health delivers a 3-step system that transforms their client’s healthcare technology innovations into relatable brands. This system combines a synthesis of key clinical data and market intelligence with the development of a strong strategy to deliver a compelling brand story to customers. ## 5. McCann Health McCann Health is a global leader in marketing, employing over 1,900 staff with offices in 20 countries and across 6 continents. The company specializes in strategic consulting, healthcare professional marketing, medical communications, global health, and HCP communication. McCann Health delivers a bespoke service to their clients, constructing high-performing teams that are perfectly matched to their specific goals. ## 6. Medico Digital [Medico Digital](https://www.medicodigital.co.uk/) is a forward-thinking, digital marketing agency, specializing in helping healthcare organizations to build their brand using data-driven marketing and tailored digital strategy. Clients have access to leading medical website designers and healthcare marketing experts who are focused on delivering results and supporting companies to reach their business objectives. ## 7. Intrepy Intrepy is an award-winning, patient-centric healthcare marketing agency that helps medical practices, healthcare businesses, and hospitals to attract, engage, and convert their ideal patients. Intrepy uses its industry-specific knowledge to implement strategies that drive significant growth, expanded reach, and accelerated revenue for their clients. The services offered by this healthcare marketing agency include healthcare digital advertising, medical SEO, medical website design, telemedicine marketing, and graphic design. ## 8. Audacity Health Audacity Health is a diverse brand strategy and activation agency that specializes in branding, communications, advertising, and marketing services for organizations within the health and science sectors. The industry-recognized company adopts a human approach to their work, creating content that triggers a customer’s emotions and provokes a meaningful response. ## 9. Razorfish Health As a member of Publicis Health, one of the world’s leading healthcare communications networks, Razorfish Health has helped some of the top healthcare brands to realize their business goals and maximize their audience engagement. Setting them apart from many of their rivals, Razorfish Health boasts one of the largest in-house clinical teams, including medical doctors and scientists. ## 10. Dobies Health Marketing Established in 1992, Dobies Health Marketing specializes in providing healthcare providers with a strategy-first approach to deliver top-level marketing, branding, and advertising. Dobies works with healthcare organizations of all sizes and types, including hospitals, medical device manufacturers and distributors, certifying boards and associations, physician practices, and health information technology firms. ## 11. Activate Health Activate Health is a boutique marketing and public relations agency that works with leading health insurers, pharmaceutical companies, hospitals, and health information technology firms. Activate Health’s team boasts decades of combined experience, providing them with unrivaled industry-specific knowledge that can be transformed into creative work that exceeds its clients’ expectations. The agency follows a standard approach when completing its projects, ensuring continuity and quality; this approach involves research, strategy, creativity, results, and refinement. ## How can Atlantic.Net help? Are you on the lookout for a leading managed service provider to handle your cloud networking needs? As a leading healthcare marketing agency, you need to find a managed service provider that can ensure any sensitive patient data is always fully protected, aligning with the relevant HIPAA regulations. With over 30 years of industry-leading experience, Atlantic.Net offers fully customizable hosting solutions. If you are seeking a reliable and dependable, secure [HIPAA compliant cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) service, then Atlantic.Net is a perfect choice. Contact our sales team to find out how our easy-to-use cloud infrastructure and services can help to launch and scale your agency. --- # How to install Let’s Chat on an Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-lets-chat-on-an-ubuntu-20-04/ | Published: 2020-12-23 | Updated: 2024-01-18 | Author: Hitesh Jethva Let’s Chat is a persistent messaging application designed for small teams. It is an open-source and self-hosted chat application that runs on Node.js and MongoDB. Let’s Chat supports private and password-protected rooms, multiple rooms, notifications. Giphy search, Kerberos and LDAP authentication, multi-user chat, and more. In this tutorial, we will show you how to install Let’s Chat with Nginx as a reverse proxy on Ubuntu 20.04. ## Step 1 – Install Nodejs First, install the necessary dependencies using the following command. ``` apt-get install -y ca-certificates curl gnupg ``` Next, download the Node.js GPG key. ``` mkdir -p /etc/apt/keyrings curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg ``` Next, add the NodeSource repo to the APT source list. ``` echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_18.x nodistro main" | tee /etc/apt/sources.list.d/nodesource.list ``` Then, update the repository index and install the Ndoe.js with the following command. ``` apt update apt-get install -y nodejs ``` Next, verify the Node.js version using the following command. ``` node -v ``` Output. ``` v18.19.0 ``` ## Step 2 – Install MongoDB Let’s Chat uses MongoDB as a database backend, so you will need to install it in your server. By default, the latest version of MongoDB is not available in the Ubuntu 20.04 default repository, so you will need to add the MongoDB repository to your system. First, download and add the GPG key with the following command: ``` curl -fsSL https://www.mongodb.org/static/pgp/server-4.4.asc | apt-key add - ``` Next, add the MongoDB repository with the following command: ``` echo "deb [ arch=amd64,arm64 ] https://repo.mongodb.org/apt/ubuntu focal/mongodb-org/4.4 multiverse" | tee /etc/apt/sources.list.d/mongodb-org-4.4.list ``` Next, update the repository and install MongoDB with the following command: ``` apt-get update -y apt-get install mongodb-org -y ``` After installing the MongoDB, start the MongoDB service and enable it to start at system reboot: ``` systemctl start mongod systemctl enable mongod ``` ## Step 3 – Install Let’s Chat First, download the latest version of Let’s Chat from the Git repository with the following command: ``` git clone https://github.com/sdelements/lets-chat.git ``` Next, change the directory to the downloaded directory and install all required dependencies with the following command: ``` cd lets-chat npm install ``` Next, copy the sample configuration file and start the Node server with the following command: ``` cp settings.yml.sample settings.yml npm start ``` Once the server is started successfully, you should get the following output:![](https://www.atlantic.net/wp-content/uploads/2020/12/chat1.png) Now, press **CTRL+C** to stop the server. ## Step 4 – Create a Systemd Service File for Let’s Chat Next, you will need to create a systemd service file for Let’s Chat. You can create it with the following command: ``` nano /etc/systemd/system/letschat.service ``` Add the following lines: ``` [Unit] Description=Let's Chat Server Wants=mongodb.service After=network.target mongod.service [Service] Type=simple WorkingDirectory=/root/lets-chat ExecStart=/usr/bin/npm start User=root Group=root Restart=always RestartSec=9 [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the Let’s Chat service and enable it to start at system reboot with the following command: ``` systemctl start letschat systemctl enable letschat ``` You can now check the status of the Let’s Chat with the following command: ``` systemctl status letschat ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2020/12/chat2.png) At this point, Let’s Chat service is started and listening on port 5000. You can check it with the following command: ``` ss -antpl | grep 5000 ``` You should get the following output: ``` LISTEN    0         511              127.0.0.1:5000           0.0.0.0:*        users:(("letschat",pid=31534,fd=20)) ``` ## Step 5 – Install and Configure Nginx for Let’s Chat Next, you will need to install and configure Nginx as a reverse proxy for Let’s Chat. First, install the Nginx server with the following command: ``` apt-get install nginx -y ``` Once installed, create a new Nginx virtual host configuration file with the following command: ``` nano /etc/nginx/sites-available/letschat.conf ``` Add the following lines: ``` server { server_name letschat.example.com; listen 80; access_log /var/log/nginx/lets_chat-access.log; error_log /var/log/nginx/lets_chat-error.log; location / { proxy_set_header   X-Real-IP $remote_addr; proxy_set_header   Host      $host; proxy_http_version 1.1; proxy_set_header   Upgrade $http_upgrade; proxy_set_header   Connection 'upgrade'; proxy_cache_bypass $http_upgrade; proxy_pass         http://127.0.0.1:5000; } } ``` Save and close the file, then activate the Nginx virtual host with the following command: ``` ln -s /etc/nginx/sites-available/letschat.conf /etc/nginx/sites-enabled/ ``` Next, you will need to set hash_bucket size in the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line below http {: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 6 – Access Let’s Chat Web Interface Now, open your web browser and access the Let’s Chat web interface using the URL **http://letschat.example.com**. You will be redirected to the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/letschat4.png) Click on “**I need an account**” button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/chat5.png) Provide your username, email, and password and click on the **Register** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/chat7.png) Click on the **OK** button. You should see the Let’s Chat login page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/chat8.png) Provide your username and password and click on the **Sign** **in** button. You should see the Let’s Chat dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/chat9.png) ## Conclusion Congratulations! You have successfully installed Let’s Chat with Nginx as a reverse proxy on Ubuntu 20.04. You can now create a new chat room and invite users to join this room. Get started with Let’s Chat on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net now! --- # How to Install Live Helper Chat on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-live-helper-chat-on-ubuntu-20-04/ | Published: 2020-12-28 | Updated: 2023-11-18 | Author: Hitesh Jethva Live Helper Chat is an open-source chat application that supports web and desktop clients, co-browsing, XMPP notifications, GTalk, Jabber, and more. It can be embedded easily in your website and provide live chat service with multiple departments, multiple locations, and more. Live Helper Chat is based on PHP and uses MySQL or MariaDB as a database backend. It provides many useful features including multiple chats, online tracking, file upload, archive chat, user screenshots, and more. In this tutorial, we will show you how to install Live Helper Chat on Ubuntu 20.04. ## Step 1 – Install LAMP Server Before starting, you will need to install the Apache webserver, MariaDB, PHP and other PHP libraries to your server. You can install all of them with the following command: ``` apt-get install apache2 mariadb-server php libapache2-mod-php php-common php-gmp php-curl php-intl php-mbstring php-xmlrpc php-mysql php-gd php-bcmath php-xml php-cli php-zip php- sqlite3 unzip git -y ``` After installing all the packages, edit the php.ini file and set some values as below: ``` nano /etc/php/7.4/apache2/php.ini ``` Change the following lines: ``` memory_limit = 256M upload_max_filesize = 100M max_execution_time = 360 max_input_vars = 1500 date.timezone = America/Chicago ``` Save and close the file when you are finished. ## Step 2 – Create a Database for Live Helper Chat Next, you will need to create a user and database for Live Helper Chat. First, log in to the MariaDB shell with the following command: ``` mysql ``` Once logged in, create a database and user with the following command: ``` CREATE DATABASE livehelperchat; CREATE USER 'livehelperchat'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the livehelperchat database with the following command: ``` GRANT ALL ON livehelperchat.* TO 'livehelperchat'@'localhost' WITH GRANT OPTION; ``` Next, flush the privileges and exit from the MariaDB with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download Live Helper Chat Next, download the latest version of the Live Helper Chat from the Git repository with the following command: ``` wget https://github.com/remdex/livehelperchat/archive/master.zip ``` Once the download is completed, unzip the downloaded file with the following command: ``` unzip master.zip ``` Next, copy the extracted directory to the Apache root directory: ``` mv livehelperchat-master /var/www/html/livehelperchat ``` Next, set proper ownership and permissions with the following command: ``` chown -R www-data:www-data /var/www/html/livehelperchat/ chmod -R 755 /var/www/html/livehelperchat/ ``` ## Step 4 – Configure Apache for Live Helper Chat Next, you will need to create an Apache virtual host configuration file to serve Live Helper Chat. You can create it with the following command: ``` nano /etc/apache2/sites-available/livehelperchat.conf ``` Add the following lines: ``` ServerAdmin admin@example.com DocumentRoot /var/www/html/livehelperchat/lhc_web ServerName livehelper.example.com Options +FollowSymlinks AllowOverride All Require all granted ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined ``` Save and close the file, then enable the Apache virtual host with the following command: ``` a2ensite livehelperchat.conf ``` Next, enable the Apache rewrite and headers module with the following command: ``` a2enmod rewrite a2enmod headers ``` Next, restart the Apache service to apply the changes: ``` systemctl restart apache2 ``` ## Step 5 – Access Live Helper Chat Web Interface Now, open your web browser and access the Live Helper Chat using the URL **http://livehelper.example.com**. You will be redirected to the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/livehelper.png) Make sure all the PHP extensions are installed, then click on the **Next** button. You should see the database configuration page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/livehelper2.png) Provide your database details and click on the **Next** button. You should see the application settings page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/livehelper3.png) Provide your admin username, password, and email and click on the **Finish** **installation** button. Once the installation has been completed, you should get the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/livehelper4.png) Click on **Login**. You will be redirected to the Live Helper Chat login page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/livehelper5.png) Provide your admin username, password and click on the **Login** button. You should see the Live Helper Chat dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/12/livehelper7.png) ## Conclusion Congratulations! You have successfully installed Live Helper Chat on Ubuntu 20.04. You can now explore the dashboard for more functionality and integrate it with your existing website. Get started with Live Helper Chat on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today. --- # How To Install & Configure MEAN Stack On Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-configure-mean-stack-on-ubuntu-20-04/ | Published: 2020-12-29 | Updated: 2024-01-18 | Author: Hitesh Jethva A MEAN Stack is a free, open-source, popular JavaScript software stack used for developing dynamic websites and web applications. It is made from four components: MongoDB, Express, Angular, and Node.js. Angular is used for frontend development, while Node.js, Express, and MongoDB are used for backend development. A MEAN stack is based on JavaScript language so it can handle all aspects of an application. In this tutorial, we will show you how to install a MEAN Stack on Ubuntu 20.04. ## Prerequisites - A fresh Ubuntu 20.04 [VPS](https://www.atlantic.net/vps-hosting/) on the Atlantic.Net Cloud Platform - A valid domain name pointed to your server IP - A root password configured on your server ## Step 1 – Install MongoDB First, you will need to install a MongoDB database in your server. By default, the latest version of MongoDB is available in the Ubuntu 20.04 default repository, so you can install it easily with the following command: ``` apt-get install mongodb -y ``` Once MongoDB is installed, start the MongoDB service and enable it to start at system reboot with the following command: ``` systemctl start mongodb systemctl enable mongodb ``` ## Step 2 – Install Node.js First, install the necessary dependencies using the following command. ``` apt-get install -y ca-certificates curl gnupg ``` Next, download the Node.js GPG key. ``` mkdir -p /etc/apt/keyrings curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg ``` Next, add the NodeSource repo to the APT source list. ``` echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_18.x nodistro main" | tee /etc/apt/sources.list.d/nodesource.list ``` Then, update the repository index and install the Ndoe.js with the following command. ``` apt update apt-get install -y nodejs ``` Next, verify the Node.js version using the following command. ``` node -v ``` Output. ``` v18.19.0 ``` Next, install other required packages including yarn, gulp, and pm2 with the following command: ``` npm install -g yarn npm install -g gulp npm install pm2 -g ``` Once all the packages are installed, you can proceed to the next step. ## Step 3 – Install and Configure MEAN Stack First, download the latest version of MEAN with the following command: ``` git clone https://github.com/meanjs/mean ``` Once the download is completed, change the directory to mean and install all required dependencies with the following command: ``` cd mean yarn install ``` Next, edit the server.js file with the following command: ``` nano server.js ``` Replace all the lines with the following: ``` const express = require('express'); const MongoClient = require('mongodb').MongoClient; const app = express(); app.use('/', (req, res) => { MongoClient.connect("mongodb://localhost:27017/test", function(err, db){ db.collection('Example', function(err, collection){ collection.insert({ pageHits: 'pageHits' }); db.collection('Example').count(function(err, count){ if(err) throw err; res.status(200).send('Page Hits: ' + Math.floor(count/2)); }); }); }); }); app.listen(3000); console.log('Server running at http://localhost:3000/'); module.exports = app; ``` Save and close the file when you are finished, then start the server with the following command: ``` pm2 start server.js ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2021/01/mean1.png) Next, enable server.js to start at system reboot with the following command: ``` pm2 startup ``` At this point, the MEAN Stack is installed and listening on port 3000. You can check it with the following command: ``` ss -antpl | grep 3000 ``` You should get the following output: ``` LISTEN 0 511 *:3000 *:* users:(("node",pid=26014,fd=20)) ``` ## Step 4 – Configure Nginx as a Reverse Proxy For MEAN Next, you will need to install and configure Nginx as a reverse proxy to access the MEAN application. First, install the Nginx web server with the following command: ``` apt-get install nginx -y ``` Once installed, create a new Nginx virtual host configuration file with the following command: ``` nano /etc/nginx/sites-available/mean ``` Add the following lines: ``` server { listen 80; server_name mean.example.com; access_log /var/log/nginx/mean-access.log; error_log /var/log/nginx/mean-error.log; location / { proxy_set_header X-Forwarded-Host $host; proxy_set_header X-Forwarded-Server $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_pass http://localhost:3000/; } } ``` Save and close the file when you are finished, then enable the virtual host with the following command: ``` ln -s /etc/nginx/sites-available/mean /etc/nginx/sites-enabled/ ``` Next, edit the Nginx main configuration file and set the hash_bucket_size: ``` nano /etc/nginx/nginx.conf ``` Add the following line below http { ``` server_names_hash_bucket_size 64; ``` Save and close the file, then verify the Nginx for syntax errors with the following command: ``` nginx -t ``` You should get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the configuration changes: ``` systemctl restart nginx ``` ## Step 5 – Access MEAN Application Now, open your web browser and access the MEAN application using the URL **http://mean.example.com**. You should see your MEAN application in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/01/mean2.png) In the above screen, the number will be increased automatically when you refresh the page. ## Conclusion Congratulations! You have successfully installed MEAN Stack with Nginx as a reverse proxy on Ubuntu 20.04 server. You can now easily deploy your own dynamic application with a MEAN Stack on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account with Atlantic.Net. --- # How to Setup Mantis Bug Tracker on Debian 12 > URL: https://www.atlantic.net/vps-hosting/how-to-setup-mantis-bug-tracker-on-debian-12/ | Published: 2021-01-04 | Updated: 2025-09-07 | Author: Hitesh Jethva Mantis is one of the most popular web-based bug tracking systems used to track software defects. It also supports release and issues tracking for managing various releases of a project. Mantis is written in PHP and supports several databases including MySQL, PostgreSQL, and MS SQL. It comes with a lot of built-in tools that help you to collaborate with teams to resolve bugs easily from a web-based interface. If you are looking for a self-hosted bug tracking system, then MantisBT is the best choice for you. In this tutorial, we will show you how to install and configure the Mantis bug tracking system on Debian 12. ## Step 1 – Install Nginx, MariaDB and PHP First, you will need to install the Nginx web server, MariaDB, PHP and other PHP extensions to your server. You can install all required packages with the following command: ``` apt-get update -y apt-get install nginx mariadb-server php php-fpm php-mysql php-cli php-ldap php-zip php-curl php php-cli php-mbstring php-xmlrpc php-soap php-gd php-xml php-intl php-pear php-bcmath unzip -y ``` After installing all the packages, tweak the PHP settings by editing the file php.ini: ``` nano /etc/php/8.2/fpm/php.ini ``` Change the following settings: ``` file_uploads = On allow_url_fopen = On short_open_tag = On cgi.fix_pathinfo = 0 memory_limit = 512M upload_max_filesize = 100M max_execution_time = 300 max_input_vars = 1600 date.timezone = America/Chicago ``` Save and close the file when you are finished. ## Step 2 – Configure MariaDB Database Mantis uses MariaDB as a database backend, so you will need to create a database and user for Mantis. First, log in to MariaDB with the following command: ``` mysql ``` Once logged in, create a database and user with the following command: ``` CREATE DATABASE mantisdb; GRANT ALL PRIVILEGES ON mantisdb.* TO 'mantisuser'@'localhost' IDENTIFIED BY 'secure- password'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download MantisBT First, visit the Sourceforge website and download the latest version of MantisBT with the following command: ``` wget https://sourceforge.net/projects/mantisbt/files/mantis-stable/2.27.1/mantisbt-2.27.1.zip ``` Once the download is completed, unzip the downloaded file with the following command: ``` unzip mantisbt-2.27.1.zip ``` Next, move the extracted directory to the Nginx root directory with the following command: ``` mv mantisbt-2.27.1 /var/www/html/mantisbt ``` Next, set proper permissions and ownership to the mantisbt directory: ``` chown -R www-data:www-data /var/www/html/mantisbt chmod -R 755 /var/www/html/mantisbt ``` ## Step 4 – Configure Nginx for MantisBT Next, you will need to create an Nginx virtual host configuration file to host Mantis. You can create it with the following command: ``` nano /etc/nginx/sites-available/mantisbt ``` Add the following lines: ``` server { listen 80; server_name mantisbt.example.com; root /var/www/html/mantisbt; index index.php; access_log /var/log/nginx/example.com.access.log; error_log /var/log/nginx/example.com.error.log; client_max_body_size 100M; autoindex off; location / { index index.html index.php; try_files $uri /index.php$is_args$args; } location ~ \.php$ { include snippets/fastcgi-php.conf; fastcgi_pass unix:/var/run/php/php8.2-fpm.sock; include fastcgi_params; fastcgi_intercept_errors on; } } ``` Save and close the file, then enable the Mantis virtual host with the following command: ``` ln -s /etc/nginx/sites-available/mantisbt /etc/nginx/sites-enabled/ ``` Next, verify Nginx for any syntax errors using the following command: ``` nginx -t ``` You should get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 5 – Access Mantis Web UI Now, open your web browser and access the Mantis web interface using the URL **http://mantisbt.example.com**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/mantis1.png) ![](https://www.atlantic.net/wp-content/uploads/2021/01/mantis2.png) Provide your database information and timezone and click on the **Install/Upgrade Database** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/mantis3.png) Now, click on the **Continue** button. You should see the Mantis login page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/mantis4.png) Provide default username as **administrator** and click on the **Login** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/mantis5.png) Provide default password as **root** and click on the **Login** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/mantis6.png) Change your current password and click on the **Update** **User** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/mantis7.png) ## Conclusion In the above guide, you learned how to install Mantis bug tracking system on Debian 12. You can now start implementing Mantis in the development environment and manage your project and code from the central location. Try out Mantis on your [VPS Hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net! --- # How to Install Memcached on Debian 12 > URL: https://www.atlantic.net/vps-hosting/how-to-install-memcached-on-debian-12/ | Published: 2021-01-05 | Updated: 2025-09-05 | Author: Hitesh Jethva Memcached is an open-source, high-performance, general-purpose distributed memory object caching system. It helps to speed up dynamic websites by caching data, user authentication tokens, and API calls in RAM. Memcached also provides a mechanism to share the data across multiple application instances. Generally, it is used to speed up php-based applications including Joomla, WordPress, Drupal, and Python. In this tutorial, we will show you how to install and configure Memcached on Debian 12. ## Step 1 – Install Memcached By default, Memcached is available in the Debian standard repository. You can install it by just running the following command: ``` apt-get update -y apt-get install memcached libmemcached-tools -y ``` Once the Memcached is installed, you can check the status of Memcached with the following command: ``` systemctl status memcached ``` You should get the following output: ``` ● memcached.service - memcached daemon Loaded: loaded (/lib/systemd/system/memcached.service; enabled; preset: enabled) Active: active (running) since Fri 2025-09-05 10:12:55 UTC; 8s ago Docs: man:memcached(1) Main PID: 24701 (memcached) Tasks: 10 (limit: 2304) Memory: 2.0M CPU: 38ms CGroup: /system.slice/memcached.service └─24701 /usr/bin/memcached -m 64 -p 11211 -u memcache -l 127.0.0.1 -P /var/run/memcached/memcached.pid Sep 05 10:12:55 debian systemd[1]: Started memcached.service - memcached daemon. ``` By default, Memcached listens on port 11211. You can verify it with the following command: ``` ss -antpl | grep 11211 ``` You should get the following output: ``` LISTEN 0 128 127.0.0.1:11211 0.0.0.0:* users:(("memcached",pid=15969,fd=26)) ``` ## Step 2 – Configure Memcached The default Memcached configuration file is located at /etc/memcached.conf. You can change the Memcached default port and configure it for external access using the file: ``` nano /etc/memcached.conf ``` Change the following lines if you want to configure Memcached for external access. ``` -l your-server-ip -p 11211 ``` Save and close the file, then restart the Memcached service to apply the changes: ``` systemctl restart memcached ``` ## Step 3 – Enable Memcached for PHP and Python You will need to install a PHP extension for Memcached if you want to enable Memcached for a php-based web application. You can install it with the following command: ``` apt-get install php php-memcached -y ``` If you want to enable Memcached for Python applications, you can install the Python Memcached extension with the following command: ``` apt install python3-memcache python3-pylibmc -y ``` ## Step 4 – Verify Memcached Installation At this point, Memcached is installed and running. Now it’s time to test whether it is enabled in PHP or not. First, install the Apache webserver with the following command: ``` apt-get install apache2 libapache2-mod-php -y ``` Next, create a new info.php file inside Apache web root directory: ``` nano /var/www/html/info.php ``` Add the following lines: ``` ``` Save and close the file, then restart the Apache to apply the changes. ``` systemctl restart apache2 ``` Now, open your web browser and access the info.php page using the URL **http://your-server-ip/info.php**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/m1.png) As you can see, Memcached is enabled in PHP. ## Conclusion In the above guide, you learned how to install Memcached on Debian 12. You also learned how to enable Memcached in PHP and Python. You can now easily integrate your website with Memcached and speed up page loading time; give it a try on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Install Piwigo Photo Gallery on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-install-piwigo-photo-gallery-on-ubuntu/ | Published: 2021-01-06 | Updated: 2023-11-26 | Author: Hitesh Jethva Piwigo is a free, open-source, web-based photo gallery application that allows you to upload your photos and videos via FTP, web uploads, and desktop applications. It is written in PHP and uses MySQL as a database backend. Piwigo is especially useful for a photographer who wants to upload their photographs to the web and show them to their client. Piwigo allows you to customize per your needs using built-in extensions. In this tutorial, we will show you how to install Piwigo Photo Gallery on Ubuntu 20.04. ## Step 1 – Install LAMP Server First, you will need to install the Apache web server, MariaDB, PHP and other PHP extensions to your server. You can install all of them with the following command: ``` apt-get install apache2 mariadb-server php libapache2-mod-php php-common php-mbstring php- xmlrpc php-gd php-xml php-intl php-mysql php-cli php php-ldap php-zip php-curl unzip git -y ``` Once all the packages are installed, edit the php.ini file and tweak some settings to recommended values: ``` nano /etc/php/7.4/apache2/php.ini ``` Change the following lines: ``` memory_limit = 256M upload_max_filesize = 100M date.timezone = America/Chicago ``` Save and close the file, then restart the Apache service to apply the configuration. ``` systemctl restart apache2 ``` ## Step 2 – Create a Database for Piwigo Piwigo uses MySQL or MariaDB as a database backend, so you will need to create a database and user for Piwigo. First, log in to MySQL with the following command: ``` mysql ``` Once logged in, create a database and user with the following command: ``` CREATE DATABASE piwigo; CREATE USER 'piwigo'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the piwigo database with the following command: ``` GRANT ALL ON piwigo.* TO 'piwigo'@'localhost' IDENTIFIED BY 'password' WITH GRANT OPTION; ``` Next, flush the privileges and exit from the MySQL shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install Piwigo First, download the latest version of Piwigo from their official website using the following command: ``` curl -o piwigo.zip http://piwigo.org/download/dlcounter.php?code=latest ``` Once the download is completed, unzip the downloaded file with the following command: ``` unzip piwigo.zip ``` Next, move the extracted directory to the Apache web root directory: ``` mv piwigo /var/www/html/piwigo ``` Next, set proper permissions and ownership with the following command: ``` chown -R www-data:www-data /var/www/html/piwigo/ chmod -R 777 /var/www/html/piwigo/ ``` ## Step 4 – Configure Apache for Piwigo Next, you will need to create an Apache virtual host configuration file for Piwigo. You can create it with the following command: ``` nano /etc/apache2/sites-available/piwigo.conf ``` Add the following lines: ``` ServerAdmin admin@example.com DocumentRoot /var/www/html/piwigo ServerName piwigo.example.com Options +FollowSymlinks AllowOverride All Require all granted ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined ``` Save and close the file, then enable the Piwigo virtual host and Apache rewrite module with the following command: ``` a2ensite piwigo.conf a2enmod rewrite ``` Finally, restart the Apache service using the following command: ``` systemctl restart apache2 ``` ## Step 5 – Access Piwigo Now, open your web browser and type the URL **http://piwigo.example.com**. You will be redirected to the Piwigo setup page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/piwigo.png) Provide your database details and admin user information and click on the **Start** **installation** button. Once the installation has been completed successfully, you should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/piwigo2.png) Now, click on the **Visit** **the** **gallery**. You should see the Piwigo dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/piwigo3.png) From here, you can add your photo easily or click on “**I will find my way by myself.**” You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/piwigo4.png) ## Conclusion Congratulations! You have successfully installed and configured Piwigo photo gallery on Ubuntu 20.04. You can now upload your photos and access them over the Internet easily – give it a try with [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # SolarWinds Orion Hack > URL: https://www.atlantic.net/vps-hosting/solarwinds-orion-hack/ | Published: 2021-01-06 | Updated: 2024-11-14 | Author: Richard Bailey *Atlantic.Net is providing this security advisory message as a news item; we want to reassure our customers that Atlantic.Net does not use any SolarWinds products internally or as part of any of our service offerings.* On the 13th December 2020, [news broke from the cybersecurity organization FireEye concerning a major security breach at SolarWinds Corporation](https://www.solarwinds.com/securityadvisory?mkt_tok=eyJpIjoiWkdOaU1qRmhOamt4WXpNMiIsInQiOiJXT1ltbWJJZFJraVpnMEg4MnIrdENLa1VcL0ZGUVNCVW9RbnQ3ZGkyN01SbVwvMUl5OWlvWndueUp1NjlIMHVqU244RU55enJLQ2J5TU1lYWRBYkl6VEZBNm9pNGFhQXBBemZNY1Q5UXJUSFQxN0d3V1AwMkZ3Sm1HN01ETDB6cFBqIn0%3D). SolarWinds is a Texas-based tech giant that has become a dominant player in server monitoring and network management with its Orion line of software products. It serves [300,000 customers](https://www.theregister.com/2020/12/15/solar_winds_update/#:~:text=It%20has%20a%20long%20history,of%20more%20than%20300%2C000%20customers.) globally and is trusted by several high-profile organizations and government institutions. ## How Did the Attack Happen and Who Was Impacted? Cybersecurity experts believe that a sophisticated, possibly Russian, state-sponsored cyberattack breached SolarWinds infrastructure and impacted many of the company’s customers. Experts believe SolarWinds was breached in the Spring of 2020, but the groundwork for the attack may have started much earlier. Global companies such as VMware, Intel, Microsoft, and Cisco are [reportedly](https://www.bloomberg.com/news/articles/2020-12-18/cisco-latest-victim-of-russian-cyber-attack-using-solarwinds) impacted by the attack, as well as [all five branches of the US military, the national nuclear security administration, the Pentagon, the State Department, and the Office of the President of the United States](https://www.independent.co.uk/life-style/gadgets-and-tech/solarwinds-hack-how-russia-us-government-b1776034.html). ### How the Hack Worked The hack was incredibly sophisticated. Hackers were able to gain access to SolarWinds internal systems and compromise their official Orion software updates with *“trojanized”* malware updates. This allowed the hackers to disguise compromised updates as legitimate, SolarWinds-approved Orion updates. It is believed that up to [18,000 SolarWinds customers](https://www.theregister.com/2020/12/15/solar_winds_update/) downloaded the malware.  This is, undeniably, a huge, incredible, and quite shocking lapse in security to happen at a company valued at about $5 billion. [FireEye](https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html), the cybersecurity company that first identified the breach, said the hack gave the intruders “the ability to transfer files, execute files, profile the system, reboot the machine, and disable system services. The malware masquerades its network traffic as the Orion Improvement Program (OIP) protocol and stores reconnaissance results within legitimate plugin configuration files, allowing it to blend in with legitimate SolarWinds activity.” Once installed by the victims, the hackers used part of the Orion software framework, specifically an [HTTP API vulnerability in a file called SolarWinds.Orion.Core.BusinessLayer.dll](https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html). The exploit allowed them to execute remote ‘jobs’ on any compromised server and traverse the victim’s network using “god mode” privileges to compromise any connected server and perform data theft. [Symantec](https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/sunburst-supply-chain-attack-solarwinds) and [Palo Alto Networks](https://unit42.paloaltonetworks.com/solarstorm-supernova/) reported that secondary payloads known as Teardrop and Supernova were deployed against “targets of interest.” Teardrop embeds the Cobalt Strike Beacon malware which attempts to steal credentials, hack Active Directory, and perform data theft. ### The Scale of the Attack As this news only broke recently, the scale of the impact is not yet fully known, but many businesses are bracing themselves as they investigate the impact of the data breach. As of yet, no one knows exactly what data has been stolen, though the government may have some idea. This might go down as the worst cyberattack in history when the true scope of this breach and its fallout are understood. What made this attack so insidious was the attack vector used: the SolarWinds supply chain. SolarWinds were not the end target, but they are heavily embedded in and trusted by government entities and high-profile organizations. This type of attack is known as an Advanced Persistent Threat (APT) and the method of attack is nothing more than a trojan horse; specifically, it is known as a Remote Access Trojan (RAT) because it targeted user data and company secrets. ## Recommended Actions ### Update Orion Platform SolarWinds has identified the infected Orion updates and [published information about them here](https://www.solarwinds.com/securityadvisory). Users need to check if updated Orion Platform versions 2019.4 HF5 were installed between March and June 2020. They recommend that all Orion users should update to Orion Platform version 2020.2.1 Hot Fix 2. ### Scan for Evidence of Compromise Users should check their networks for evidence of being compromised. Scan for two key identifiers: the use of the Teardrop in-memory malware to drop Cobalt Strike Beacon and for your organization’s hostnames. If breached, hostnames can uncover malicious IP addresses used by the attackers. ### Use a Password Manager Atlantic.Net also offers this further advice on cybersecurity best practices: make sure you use some form of a local password manager. If you do not already, use some form of multi-factor authentication, get it installed urgently across your network. There are various options available including paid licensed versions or open source. Never use the same password throughout your organization, enforce a strict password policy, and enforce a complex password strategy. One theory circulating concerning how the hackers managed the initial compromise posits that they achieved access by using internal usernames and passwords for SolarWinds that were found embedded into public GitHub code repositories.  The “Solarwinds123” password theory may have some merit and, if true, points the finger at entrenched bad security practices inside SolarWinds. ## What to Expect Next We can’t predict the fallout of this breach, but it is likely to have serious global ramifications. This incident will likely force US organizations to conduct a head-to-toe audit of their network environments. SolarWinds will doubtlessly lose many customers from this high-profile breach and can expect huge regulatory fines. It’s possible they may even be hit with fines for breaching GDPR, as many SolarWinds customers are located within the European Union. We expect the US administration to revamp cybersecurity protocol in the wake of this attack, especially if it turns out to be a state-sponsored attack by Russia. The US government already has a cybersecurity platform in place that is designed to thwart this kind of attack known as [EINSTEIN 3](https://www.cisa.gov/resources-tools/resources/privacy-impact-assessment-pia-einstein-3-accelerated). It would appear this system was completely unaware of this attack. If your business is concerned about cybersecurity, please feel welcome to reach out to Atlantic.Net. We are specialists in Managed Services, Cloud Hosting, and HIPAA Compliance. Security of our infrastructure is of paramount importance, and we work hard to ensure we have the best security processes in place. This cyberattack will go down in history as one of the worst ever, we feel concerned for our friends in the industry that might be affected by this. The clients of SolarWinds have done nothing wrong; they purchased an industry-leading server management suite from a reputable business, and now, due to unknown security incompetence, each customer has been put at risk through no fault of their own. [Get in touch today.](https://www.atlantic.net/about-us/corporate-contact/) --- # Atlantic.Net Expands the Free G3.2GB Promo in New York and Toronto Data Centers > URL: https://www.atlantic.net/press-releases/atlantic-net-expands-the-free-g3-2gb-promo-in-new-york-and-toronto-data-centers/ | Published: 2021-01-07 | Updated: 2024-06-11 | Author: Editorial Team **Free G3.2GB Cloud VPS Hosting is now available in two additional data centers for one full year** **ORLANDO, FLA. (January 7, 2021)** – [Atlantic.Net](https://www.atlantic.net/), a leading cloud services provider, expanded their offer that enables new cloud VPS customers to double their server resources at no extra cost. Atlantic.Net will upgrade all cloud plans to the capabilities of the next highest price bracket at no additional cost for new customers in their Orlando, New York, and Toronto data centers. This program also includes Atlantic.Net’s Free-to-Use for One Year Server promotion, meaning that any new free tier users will be automatically upgraded from 1GB to 2GB Cloud Server usage for one full year. “We are pleased to have continued to assist small business with our free server offer for one full year in additional markets. This is one more way of helping the small business affected by the COVID 19 pandemic,” said Marty Puranik, CEO and Founder of Atlantic.Net. “We truly hope that this will help not only America’s small to mid-size businesses get more for less, but also our healthcare providers, who can now get audit-ready and healthcare compliant solutions for half the price!” Initially, Atlantic.Net offered the new program in its Orlando, Florida data center, but has now expanded it to New York and Toronto, with plans to make it available at all its locations in coming weeks. The Atlantic.Net Cloud Platform, which is engineered to provide fault-tolerant, ultra-fast performance, includes award-winning Cloud Servers, Secure Block Storage, one-click applications, DNS, dedicated private nodes, private networking, RESTful API, data backup, a full suite of managed services, 24/7/365 expert U.S.-based support, and more. This infrastructure is ideally suited to support businesses and organizations as they evolve toward a distributed remote work environment to mitigate the health risks of COVID-19 to the global workforce. To view the latest cloud offerings and pricing structure, visit [VPS hosting](https://www.atlantic.net/vps-hosting/). **About Atlantic.Net** Atlantic.Net is a global [cloud services](https://www.atlantic.net/hipaa-compliant-hosting/) provider with over 25 years of experience, serving thousands of developers and small, medium, and large clients in more than one hundred countries. Atlantic.Net specializes in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions and has served dynamic business clients including Lenovo, Newegg, NASA, and Hilton, among others. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions, backed by 24/7/365 support in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. For more information, please visit [Atlantic Net/](https://www.atlantic.net/). --- # How to Install Apache Spark on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-apache-spark-on-centos-8/ | Published: 2021-01-07 | Updated: 2023-11-22 | Author: Hitesh Jethva Apache Spark is a data processing framework that performs processing tasks over large data sets quickly. Apache Spark can also distribute data processing tasks across several computers. It does so either on its own or in tandem with other distributed computing tools. These two qualities make it particularly useful in the world of machine learning and big data. Spark also features an easy-to-use API, reducing the programming burden associated with data crunching. It undertakes most of the work associated with big data processing and distributed computing. ## Step 1 – Install Java Spark is a Java-based application, so you will need to install Java in your system. You can install the Java using the following command: ``` dnf install java-11-openjdk-devel -y ``` Once Java is installed, you can verify the Java version with the following command: ``` java --version ``` You should get the Java version in the following output: ``` openjdk 11.0.8 2020-07-14 LTSOpenJDK Runtime Environment 18.9 (build 11.0.8+10-LTS) OpenJDK 64-Bit Server VM 18.9 (build 11.0.8+10-LTS, mixed mode, sharing) ``` ## Step 2 – Install Spark First, you will need to download the latest version of Spark from its official website. You can download it with the following command: ``` wget https://mirrors.estointernet.in/apache/spark/spark-3.0.1/spark-3.0.1-bin-hadoop2.7.tgz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar -xvf spark-3.0.1-bin-hadoop2.7.tgz ``` Next, move the extracted directory to /opt with the following command: ``` mv spark-3.0.1-bin-hadoop2.7 /opt/spark ``` Next, create a separate user to run Spark with the following command: ``` useradd spark ``` Next, change the ownership of the /opt/spark directory to the spark user with the following command: ``` chown -R spark:spark /opt/spark ``` ## Step 3 – Create a Systemd Service File for Spark Next, you will need to create a systemd service file for the Spark master and slave. First, create a master service file with the following command: ``` nano /etc/systemd/system/spark-master.service ``` Add the following lines: ``` [Unit] Description=Apache Spark Master After=network.target [Service] Type=forking User=spark Group=spark ExecStart=/opt/spark/sbin/start-master.sh ExecStop=/opt/spark/sbin/stop-master.sh [Install] WantedBy=multi-user.target ``` Save and close the file when you are finished, then create a Spark slave service with the following command: ``` nano /etc/systemd/system/spark-slave.service.service ``` Add the following lines: ``` [Unit] Description=Apache Spark Slave After=network.target [Service] Type=forking User=spark Group=spark ExecStart=/opt/spark/sbin/start-slave.sh spark://your-server-ip:7077 ExecStop=/opt/spark/sbin/stop-slave.sh [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` ## Step 4 – Start the Master Service Now, you can start the Spark master service and enable it to start at boot with the following command: ``` systemctl start spark-master systemctl enable spark-master ``` You can verify the status of the Master service with the following command: ``` systemctl status spark-master ``` You should get the following output: - ``` spark-master.service - Apache Spark Master ``` ``` Loaded: loaded (/etc/systemd/system/spark-master.service; disabled; vendor preset: disabled) Active: active (running) since Fri 2020-10-02 10:40:40 EDT; 18s ago Process: 2554 ExecStart=/opt/spark/sbin/start-master.sh (code=exited, status=0/SUCCESS) Main PID: 2572 (java) Tasks: 32 (limit: 12523) Memory: 174.5M CGroup: /system.slice/spark-master.service └─2572 /usr/lib/jvm/java-11-openjdk-11.0.8.10-0.el8_2.x86_64/bin/java -cp /opt/spark/conf/:/opt/spark/jars/* -Xmx1g org.apache.spar> Oct 02 10:40:37 centos8 systemd[1]: Starting Apache Spark Master... Oct 02 10:40:37 centos8 start-master.sh[2554]: starting org.apache.spark.deploy.master.Master, logging to /opt/spark/logs/spark-spark-org.apac> Oct 02 10:40:40 centos8 systemd[1]: Started Apache Spark Master. ``` You can also check the Spark log file to check the Master server. ``` tail -f /opt/spark/logs/spark-spark-org.apache.spark.deploy.master.Master-1-centos8.out ``` You should get the following output: ``` 20/10/02 10:40:40 INFO Utils: Successfully started service 'MasterUI' on port 8080. 20/10/02 10:40:40 INFO MasterWebUI: Bound MasterWebUI to 0.0.0.0, and started at http://centos8:8080 20/10/02 10:40:40 INFO Master: I have been elected leader! New state: ALIVE ``` At this point, the Spark master server is started and listening on port **8080**. ## Step 5 – Access Spark Dashboard Now, open your web browser and access the Spark dashboard using the URL **http://your-server-ip:8080**. You should see the Spark dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/spark1.png) In the above page, there are no workers attached to the master. ## Step 6 – Start Slave Service Now, start the Slave service and enable it to start at boot with the following command: ``` systemctl start spark-slave systemctl enable spark-slave ``` Next, check the status of the Slave with the following command: ``` systemctl status spark-slave ``` You should get the following output: - ``` spark-slave.service - Apache Spark Slave ``` ``` Loaded: loaded (/etc/systemd/system/spark-slave.service; disabled; vendor preset: disabled) Active: active (running) since Fri 2020-10-02 10:45:12 EDT; 10s ago Process: 2671 ExecStart=/opt/spark/sbin/start-slave.sh spark://45.58.32.165:7077 (code=exited, status=0/SUCCESS) Main PID: 2680 (java) Tasks: 35 (limit: 12523) Memory: 197.9M CGroup: /system.slice/spark-slave.service └─2680 /usr/lib/jvm/java-11-openjdk-11.0.8.10-0.el8_2.x86_64/bin/java -cp /opt/spark/conf/:/opt/spark/jars/* -Xmx1g org.apache.spar> Oct 02 10:45:09 centos8 systemd[1]: Starting Apache Spark Slave... Oct 02 10:45:09 centos8 start-slave.sh[2671]: starting org.apache.spark.deploy.worker.Worker, logging to /opt/spark/logs/spark-spark-org.apach> Oct 02 10:45:12 centos8 systemd[1]: Started Apache Spark Slave. ``` You can also check the Spark slave log file for confirmation: ``` tail -f /opt/spark/logs/spark-spark-org.apache.spark.deploy.worker.Worker-1-centos8.out ``` You should get the following output: 20/10/02 10:45:12 INFO Worker: Spark home: /opt/spark 20/10/02 10:45:12 INFO ResourceUtils: ============================================================== 20/10/02 10:45:12 INFO ResourceUtils: Resources for spark.worker: 20/10/02 10:45:12 INFO ResourceUtils: ============================================================== 20/10/02 10:45:12 INFO Utils: Successfully started service ‘WorkerUI’ on port 8081. 20/10/02 10:45:12 INFO WorkerWebUI: Bound WorkerWebUI to 0.0.0.0, and started at http://centos8:8081 20/10/02 10:45:12 INFO Worker: Connecting to master 45.58.32.165:7077… 20/10/02 10:45:12 INFO TransportClientFactory: Successfully created connection to /45.58.32.165:7077 after 66 ms (0 ms spent in bootstraps) 20/10/02 10:45:13 INFO Worker: Successfully registered with master spark://centos8:7077 Now, go to the Spark dashboard and reload the page. You should see the worker in the following page. ![](https://www.atlantic.net/wp-content/uploads/2021/01/spark2.png) You can also access the worker directly using the URL **http://your-server-ip:8081**. ## Conclusion In this guide, you learned how to set up a single-node Spark cluster on CentOS 8. You can now configure Spark multinode cluster easily and use it for big data and machine learning processing. Set up Apache Spark on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account with Atlantic.Net! --- # How to Create an HTTP Proxy Using Squid on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-create-an-http-proxy-using-squid-on-centos-8/ | Published: 2021-01-08 | Updated: 2024-06-11 | Author: Hitesh Jethva Squid is a free and open-source web proxy caching server that supports different protocols, such as HTTP, HTTPS, FTP, and SSL. It is mainly used as a caching proxy server and can greatly improve the server performance by caching repeated requests, filtering web traffic, and accessing geo-restricted content. Squid can act as an intermediary between the client and web server. After connecting the Squid proxy, you will be able to anonymously access Internet services and bypass local network restrictions. In this tutorial, we will learn how to install and configure Squid Proxy on CentOS 8. ## Step 1 – Install Squid Proxy Server The Squid package is available in the CentOS 8 default repository. You can install it by just running the following command: ``` dnf install squid -y ``` Once installed, start the Squid proxy service and enable it to start at reboot with the following command: ``` systemctl start squid systemctl enable squid ``` ## Step 2 – Configure IP Based Authentication There are several ways to configure Squid to accept connections and serve as an HTTP proxy. In this section, we will configure Squid to authenticate clients based on their IP addresses. Open the Squid default configuration file at /etc/squid/squid.conf: ``` nano /etc/squid/squid.conf ``` Add the following line at the beginning of the file: ``` acl user1 src 192.168.0.10 acl user2 src 192.168.0.11 http_access allow user1 user2 ``` Save and close the file when you are finished, then restart the Squid service to apply the changes: ``` systemctl restart squid ``` **In the above step, substitute your relevant information as below**: **user1** and **user2** is the name that identifies the client computers. **192.168.0.10** and **192.168.0.11** is the IP address of the client computer. ## Step 3 – Configure User Based Authentication In this section, we will configure Squid to authenticate a client with usernames and passwords. First, install the Apache utility package in your system: ``` dnf install httpd-tools -y ``` Next, create a file to store Squid users and passwords and change the ownership of the password file: ``` touch /etc/squid/squid_passwd chown squid /etc/squid/squid_passwd ``` Next, create a new squid user with name user1 using the following command:   ``` htpasswd /etc/squid/squid_passwd user1 ``` You will be asked to create a password for this user as shown below: ``` New password: Re-type new password: Adding password for user user1 ``` Next, create another user named user2 with the following command: ``` htpasswd /etc/squid/squid_passwd user2 ``` Provide a password for this user as shown below: ``` New password: Re-type new password: Adding password for user user2 ``` You can now verify both users with the following command: ``` cat /etc/squid/squid_passwd ``` You should get the following output: ``` user1:$apr1$szXO3OTj$37MuRy2V06mIAOiRpFjnr1 user2:$apr1$MCAckv0h$0VwDLLhAfMLaLm3Xvk3H/0 ``` Next, edit the Squid configuration file: ``` nano /etc/squid/squid.conf ``` Add the following lines at the beginning of the file: ``` auth_param basic program /usr/lib64/squid/basic_ncsa_auth /etc/squid/squid_passwd acl ncsa_users proxy_auth REQUIRED http_access allow ncsa_users ``` Save and close the file, then restart the Squid proxy service to apply the changes: ``` systemctl restart squid ``` ## Step 4 – Configure Combined Authentication In this section, we will configure Squid to authenticate a client based on the IP address and username/password. Edit the Squid default configuration file: ``` nano /etc/squid/squid.conf ``` Find the following lines which you added earlier: ``` auth_param basic program /usr/lib64/squid/basic_ncsa_auth /etc/squid/squid_passwd acl ncsa_users proxy_auth REQUIRED http_access allow ncsa_users acl user1 src 192.168.0.10 acl user2 src 192.168.0.11 http_access allow user1 user2 ``` And replace them with the following lines: ``` acl user1 src 192.168.0.10 acl user2 src 192.168.0.11 auth_param basic program /usr/lib64/squid/basic_ncsa_auth /etc/squid/squid_passwd acl ncsa_users proxy_auth REQUIRED http_access allow user1 user2 ncsa_users ``` Save and close the file, then restart the Squid proxy service to apply the changes: ``` systemctl restart squid ``` ## Step 5 – Configure Squid to Anonymize Traffic Next, you will need to add some rules to mask client IP addresses from the servers that receive traffic from your Squid HTTP proxy. You can do it by editing the Squid default configuration file: ``` nano /etc/squid/squid.conf ``` Add the following lines at the beginning of the file: ``` forwarded_for off request_header_access Allow allow all request_header_access Authorization allow all request_header_access WWW-Authenticate allow all request_header_access Proxy-Authorization allow all request_header_access Proxy-Authenticate allow all request_header_access Cache-Control allow all request_header_access Content-Encoding allow all request_header_access Content-Length allow all request_header_access Content-Type allow all request_header_access Date allow all request_header_access Expires allow all request_header_access Host allow all request_header_access If-Modified-Since allow all request_header_access Last-Modified allow all request_header_access Location allow all request_header_access Pragma allow all request_header_access Accept allow all request_header_access Accept-Charset allow all request_header_access Accept-Encoding allow all request_header_access Accept-Language allow all request_header_access Content-Language allow all request_header_access Mime-Version allow all request_header_access Retry-After allow all request_header_access Title allow all request_header_access Connection allow all request_header_access Proxy-Connection allow all request_header_access User-Agent allow all request_header_access Cookie allow all request_header_access All deny all ``` Save and close the file, then restart the Squid proxy service to apply the changes: ``` systemctl restart squid ``` ## Step 6 – Test Squid Proxy At this point, your Squid proxy server is configured to accept client connections based on the IP address and username/password and anonymously handle Internet traffic. Next, you will need to configure your Client computer’s browser settings to use your Squid server as an HTTP proxy. On the client computer, open Mozilla Firefox and click on Edit => Preferences as shown below: ![](https://www.atlantic.net/wp-content/uploads/2021/01/squid1.png) ![](https://www.atlantic.net/wp-content/uploads/2021/01/squid2.png) Scroll down to the Network Settings section and click on **Settings**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/squid3.png) Select the Manual proxy configuration radio button, enter your Squid server IP address in the HTTP Host field and 3128 in the Port field, select the “Use this proxy server for all protocols” check box, and click on the **OK** button to save the settings. Now your browser is configured to browse the Internet through the Squid proxy. To verify it, type the URL [What is my ip](https://www.whatismyip.com/). You will be asked to provide a username and password as shown below: ![](https://www.atlantic.net/wp-content/uploads/2021/01/squid4.png) Provide your Squid proxy server username and password which you have created earlier and click on the **OK** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/squid6.png) On the above page, you should see your Squid server’s IP address IP address instead of the IP address of your client computer. ## Conclusion In the above guide, you learned how to configure Squid as an HTTP proxy server on CentOS 8 and configure your browser to use it. You can now surf the web anonymously and keep Firefox from tracking you. Try out Squid on a [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net today! --- # How to Install Varnish Cache with Nginx on CentOS 8 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-varnish-cache-with-nginx-on-centos-8/ | Published: 2021-01-10 | Updated: 2023-11-15 | Author: Hitesh Jethva Varnish Cache is an HTTP accelerator and reverse proxy specially designed for heavily loaded dynamic web sites as well as APIs. It acts as a middleman between your client and server. Varnish works by handling requests before they make it to your backend. If Varnish doesn’t have a request cached, it will forward the request to your backend and then cache its output. This process dramatically increases the performance of your web server. Varnish is famously useful and is employed by many companies such as Wired, Urban Dictionary, Zappos, Technorati, DynDNS, OpenDNS, and many more. One of the key features of Varnish is the flexibility of its configuration language (VCL) which allows you to write policies on how incoming requests should be handled. In this tutorial, we will learn how to set up Varnish caching with Nginx on CentOS 8. We will set up Nginx to listen on port 8080 and work as a backend server, then configure Varnish to listen on default HTTP port 80. ## Step 1 – Install Varnish Cache   By default, the Varnish package is available in the CentOS 8 system. You can install it by just running the following command:   ``` dnf install varnish -y ``` After installing Varnish, start the Varnish service and enable it to start after system reboot with the following command: ``` systemctl start varnish systemctl enable varnish ``` Next, verify the status of Varnish with the following command: ``` systemctl status varnish ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2021/01/nginxvarnish1.png) By default, Varnish listens on port **6081**. You can verify it using the following command: ``` netstat -ltnp | grep 6081 ``` You should get the following output: ``` tcp        0      0 0.0.0.0:6081            0.0.0.0:*               LISTEN      1508/varnishd       tcp6       0      0 :::6081                 :::*                    LISTEN      1508/varnishd      ``` ## Step 2 – Install and Configure Nginx Next, you will need to install the Nginx web server and configure it to work with the Varnish cache. First, install the Nginx server with the following command: ``` dnf install nginx -y ``` After installing the Nginx web server, you will need to change the Nginx web server listening port from **80** to **8080**. You can do it by editing the file /etc/nginx/nginx.conf. ``` nano /etc/nginx/nginx.conf ``` Find the following line: ``` listen       80 default_server; listen       [::]:80 default_server; ``` And replace it with the following line: ``` listen       8080 default_server; listen       [::]:8080 default_server; ``` Save and close the file, then start the Nginx service and enable it to start after system reboot: ``` systemctl start nginx systemctl enable nginx ``` **Note:** If you are using virtual hosting, then configure the relevant configuration file. ## Step 3 – Configure Varnish to Work with Nginx By default, Varnish is configured to listen on port 6081, so you will need to configure it to listen on port 80. You can configure it by editing varnish.service configuration file: ``` nano /usr/lib/systemd/system/varnish.service ``` Find the following line: ``` ExecStart=/usr/sbin/varnishd -a :6081 -f /etc/varnish/default.vcl -s malloc,256m ``` And replace it with the following line: ``` ExecStart=/usr/sbin/varnishd -a :80 -f/etc/varnish/default.vcl -s malloc,256m ``` ![](https://www.atlantic.net/wp-content/uploads/2021/01/nginxvarnish2.png) Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, restart the Varnish service to apply the changes: ``` systemctl restart varnish ``` ## Step 4 – Configure Nginx as a Backend Server for Varnish Next, you will need to configure Nginx as a backend server for the Varnish proxy. You can configure it by editing the file /etc/varnish/default.vcl: ``` nano /etc/varnish/default.vcl ``` Check to ensure the following lines are uncommented: ``` backend default {    .host = "127.0.0.1";    .port = "8080"; } ``` ![](https://www.atlantic.net/wp-content/uploads/2021/01/nginzvarnish3.png) Save and close the file when you are finished. **Note:** Change the line 127.0.0.1 with your Nginx server IP address if your Nginx server resides on the other host. Change the port 8080 with the port number of your Nginx server. ## Step 5 – Verify Varnish Cache At this point, the Varnish cache is configured to work with the Nginx webserver. It’s time to test whether caching is working or not. You can test it using the curl command: ``` curl -I http://your-server-ip ``` You should get the HTTP header information in the following output: ![](https://www.atlantic.net/wp-content/uploads/2021/01/nginxvarnish4.png) Next, run this command again: ``` curl -I http://your-server-ip ``` You should get the Varnish cached response in Age header (X-Varnish): ![](https://www.atlantic.net/wp-content/uploads/2021/01/nginxvarnish5.png) You can also test the Varnish cache using varnishlog command with curl command to view Varnish activity as it happens: ``` varnishlog ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2021/01/nginxvarnish7.png) ## Conclusion Congratulations! You have successfully installed and configured Varnish Cache with an Nginx web server on CentOS 8. Now your Nginx web server has a Varnish Cache server in front of it. You will need to add additional configuration to get the full benefit from it. Get started with Varnish on your Atlantic.Net [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) today! --- # What Is a VPN? Everything You Need to Know About VPNs > URL: https://www.atlantic.net/vps-hosting/what-is-vpn/ | Published: 2021-01-11 | Updated: 2026-04-24 | Author: Richard Bailey Most computer users have probably heard the term VPN at one time or another. Perhaps you wondered what a VPN is and why you would want to use one. Maybe you have heard that a VPN can help combat internet censorship and keep your data more secure when you want to access the Internet. You might be using a VPN now but not fully understand how it works. In this article, we are going to tell you everything you need to know about VPNs. We’ll cover how they work, why you might want to use one, and the dangers that can present themselves if you don’t connect to the Internet via a VPN. This is especially important for those of you who make use of public Wi-Fi. This is part of an extensive series of guides about [information security](https://www.exabeam.com/explainers/information-security/information-security-goals-types-and-applications/). ## What Is a VPN? The acronym VPN stands for Virtual Private Network. A VPN has both a simple working explanation and a slightly more complex technical definition. From the perspective of a user, a VPN is a method of ensuring the security and privacy of their online activity. You can browse websites without worrying about being tracked by third parties. When you use a VPN, IP addresses are hidden from everyone by the VPN provider (or your server that you created as a VPN node). Your computer’s IP address is its public identifier. You are essentially anonymous from everyone but the aforementioned parties and can therefore maintain a high degree of privacy – however, note that you can still be tracked if the VPN provider keeps track of your records. When using a VPN, your data may also encrypted so it cannot be compromised by malicious users who may have access to the communication network, depending on the VPN you choose. Encrypting your Internet traffic makes it unusable to anyone without the encryption key. In this way, the VPN offers enhanced security when data is transferred over an Internet connection. The technology behind a VPN is fairly straightforward. A secure point-to-point connection is established between a remote client and a VPN server. The IP addresses of the client computers are masked and replaced with IP addresses provided by the VPN server. The data to be transferred and the original IP header is encapsulated and encrypted. A new IP header is added that allows access to the desired public network so the data can be transferred. Using the services of a VPN provider protects the identity of the client machine by hiding its IP address from the Internet and encrypting the information to safeguard it from unauthorized access. Let’s dig further into the details of how a VPN works. ## VPN Components Three components are required to establish a VPN. They work together to provide a virtual private network over which your data can flow safely and securely. ### VPN Client A VPN client is a computer or device that uses a VPN, or virtual private network, to obtain Internet access. In addition to desktop and laptop computers, devices such as smartphones and tablets that can access the Internet can benefit from a VPN connection. There are three basic types of VPN clients available. - **Standalone VPN clients** require software to be installed on both endpoints of the connection. Using a commercial VPN product involves downloading and installing the client code on the device that connects to the VPN provider. Most consumer VPN solutions involve standalone clients on each customer’s machine. - Most modern **operating systems have built-in VPN clients** that enable connectivity to be established with a remote VPN server if it uses the same VPN protocol. This type of VPN is commonly found in a corporate environment, as it is not easily configured by end-users. - **Open source VPNs** are also available for a wide variety of operating systems. The advantages of an open-source solution are that it is free and the code can be modified to meet specific requirements. ### VPN Server A VPN server accepts connections from VPN clients and is responsible for transforming the data packets sent from the clients into a form that can be distributed on the Internet or a local private network. Replies generated from the connected network are sent to the VPN server which in turn sends them back to the client or endpoint. VPN servers can be physical or virtual machines that run specialized software to accomplish their tasks. The software handles communication between the server and its clients. It also performs encryption and decryption of transferred data packets. An important component of a VPN server’s software is the VPN protocol used to construct a secure tunnel through which information is transferred. ### VPN Protocols VPN protocols are also referred to as tunneling protocols. The tunneling analogy comes from the way the VPN protects your data when you connect to the Internet. You can visualize the protection as a tunnel wrapped around your data that keeps it safe and away from prying eyes. The tunnel is formed by the masking of IP addresses and the encryption of transmitted data. The tunnel is only as strong as the VPN protocol that is used to construct it. There are [many different VPN protocols](https://www.techradar.com/vpn/vpn-tunnels-explained-how-to-keep-your-internet-data-secure) in use that offer different levels of functionality. Here is an overview of some of the most used tunneling protocols to set up a VPN. - **PPTP** – Point to Point Tunneling Protocol is one of the oldest protocols still in use by VPNs. It is an easy protocol to configure and only requires a username, password, and server address to establish a connection. PPTP furnishes fast connection speeds but provides a low level of encryption, making it unsuitable if you need reliable data security. Atlantic.Net does not recommend using PPTP as it is at end-of-life due to numerous security vulnerabilities. - **SSTP** – Secure Socket Tunneling Protocol is a Windows-based protocol that transports data using Secure Sockets Layer (SSL). It is more secure than PPTP, but is limited to use with Windows machines. The fact that it does not use fixed ports makes it harder to stop SSTP connections with firewalls. - **L2TP/IPSec** – Layer 2 Tunneling Protocol (L2TP) is used together with Internet Protocol Security (IPSec) to create a more secure connection than PPTP. The protocols provide two layers of encryption for additional protection. Strong AES-256 bit encryption is used, but fixed ports make it easier to block connections using this protocol. It is also slower than some other VPN protocols due to the double data encapsulation it performs. - **OpenVPN** – This open-source VPN protocol also uses strong AES-256 bit encryption to protect data transmission. It can be complicated to configure, but once in place, OpenVPN can keep data safe, establish fast connections, and avoid detection from firewalls. Due to the interest of the security community, the tool is always being reviewed for potential vulnerabilities. The choice of VPN protocol can have a substantial impact on your online activity. In some cases, you may have to balance connection speed with encryption strength. Protocols that use fixed ports can be detected by firewalls, which may limit the functionality of the VPN and affect your ability to reach sites that offer products such as streaming services. Your specific needs should be considered when selecting a VPN provider and it’s worth looking at which VPN protocol they use. ## Types of VPNs A virtual private network can be implemented in multiple ways. A key characteristic is that both endpoints in the connection need to use the same VPN protocol. - In a **remote client** implementation, a public network is used to connect to a private local network. The remote users have a VPN client installed that can connect to a VPN gateway on the local network. An example of this type of implementation is a business VPN that allows workers to access sensitive corporate information remotely. - A **site-to-site VPN** enables a private network connection to be established between two sites without the need for software to be installed on all clients. Each site is connected to a VPN server which handles all clients on its end and acts as the endpoint for communication from the second site. End-users need to be connected to the VPN gateway so local network traffic can be sent through an encrypted tunnel to the alternate site. - In a **client-to-provider**virtual private network implementation, the user needs VPN client software installed and configured to enable a connection to a VPN provider’s servers. The connection establishes a secure tunnel to the service provider. The provider receives data packets which it then encapsulates and forwards to the Internet. The VPN connection is only between the client and the server. It does not extend to the destination website. This type of VPN is very common for addressing privacy concerns and can create a secure connection when using public WiFi which is notoriously unsecured. Each kind of VPN implementation has its uses in certain scenarios. Most individuals who are using a VPN to protect their browsing activity will use the client-to-provider method. All it requires is the installation of client software which is used to create a secure VPN connection to the provider. Remote client and site-to-site VPNs require a greater level of configuration and administration. ## What Are the Benefits of a VPN? Many advantages come with using a VPN to connect to the Internet. Some of them straddle the line between legitimate and illegitimate forms of online activity. In some cases, the use of a VPN may be morally acceptable by society yet prohibited by a government or corporation. Here are some of the benefits of using a VPN service to provide a secure and private Internet connection. - Using a VPN conceals your private information from websites and applications that track your online movement. The encryption capabilities of the chosen VPN will enable you to conduct secure communications and transactions over the Internet even when connected to WiFi hotspots, say, at your local coffee shop. This can be a very important factor in nations with repressive regimes that limit the ability of their citizens to freely communicate among themselves without fear of reprisal. In such cases, a secure VPN may be the only way to safely discuss sensitive subjects. - Access to blocked websites is another common reason for connecting to a VPN. Geoblocking is the practice of restricting access to specific websites based on the location of the potential client computer. [Websites may be geoblocked based on the part of the world in which you live](https://www.geoawesomeness.com/this-map-shows-which-countries-censor-the-internet-today/). A computer’s location is determined by its IP address, and by using a VPN, the IP is modified, making it impossible to tell the origin of a request to access the Internet. This fact allows you to gain access to sites that are geoblocked in your area with the help of a VPN service. - Corporate VPNs are commonly used to provide workers access to sensitive data from their home office or any other remote location. This will usually be in the form of a remote client implementation where the user will not be able to access the requested resources if they are not connecting through the VPN. Using a corporate encryption standard ensures the safety of enterprise data assets and can be instrumental in preventing a data breach. ## Disadvantages of Using a VPN There are disadvantages that you should be aware of before using a VPN. In some cases, there can be serious consequences involved with using a VPN in the wrong places. Usually, the benefits or necessity of using a VPN will outweigh any disadvantages you may encounter. Here are some factors to consider when using a VPN to enable your Internet traffic. - The use of a VPN is illegal in some countries. You should understand the laws in the country or jurisdiction in which you will establish a VPN connection. This is where the concept of Internet freedom and the law clash with each other. Using a VPN may be the only way to obtain information in authoritarian regimes that tightly control Internet access, but it can be extremely dangerous to get caught. In this situation, using a VPN is a personal decision that should not be taken lightly. - Using a VPN may result in slower Internet speeds. This is due to the rerouting that is necessary to spoof IP addresses and the processing cycles required for the encryption and decryption of data packets. - Configuration of the VPN client may be required, and this may be beyond the level of computer expertise of the average user. - Tracking of online activity performed by the VPN provider may be a problem with some VPN services. Check out the privacy policies of your VPN provider before engaging in any activities that you wish to keep anonymous. Ensure that logs are not retained of user activity that may negate the benefits of masking IP addresses. Consider setting up [your own VPN](https://www.atlantic.net/vps-hosting/how-to-set-up-wireguard-vpn-on-centos-8/) to avoid this. ## When Should I Use a VPN? Many situations that require some degree of privacy when users connect to the Internet can benefit from using a VPN service. Here are some examples of usage scenarios where the secure connection of a VPN is necessary or privacy concerning the websites you visit is desired. In the business world, the use of a VPN is often mandatory for remote workers who need to access a corporate private network. This will most likely be in the form of a remote site VPN. Employees access their worksite by connecting to a VPN that is configured to enable the required level of access through an encrypted tunnel to protect enterprise data assets. Internet censorship is a problem that manifests itself in many ways. The use of a VPN service provider can get around many of the restrictions that are placed on your web activity. A virtual private network spoofs IP addresses so your location cannot be determined when you open an Internet connection. This will allow you to subvert geoblocking and censorship strategies that are implemented in your locale. Public WiFi is offered in many establishments as an enticement to customers. Unfortunately, the WiFi connection you are using in a hotel, airport, restaurant, or other facility is probably not secure. Hackers may have compromised the local network and have access to your unencrypted data. You should always use a VPN when accessing the internet from public WiFi, even if you are not transferring sensitive data. ## Conclusion The use of a VPN can address privacy and data security issues that accompany certain types of online activity. Maintaining an anonymous presence on the Internet will help reduce unwanted advertising and enable you to access sites that may be blocked by your ISP. Keeping your data encrypted is always a good idea to protect it from misuse by malicious individuals. In most cases, the advantages of a VPN make its use an easy decision. If you are in the market for a VPS, Atlantic.Net offers [VPS Hosting](https://www.atlantic.net/vps-hosting/) at eight international locations. ## See Additional Guides on Key Information Security Topics Together with our content partners, we have authored in-depth guides on several other topics that can also be useful as you explore the world of [information security](https://www.exabeam.com/explainers/information-security/information-security-goals-types-and-applications/). ### [API Security](https://checkmarx.com/learn/api-security/ultimate-guide-to-api-security/) *Authored by Checkmarx* - [[Guide] Ultimate guide to API Security 2024](https://checkmarx.com/learn/api-security/ultimate-guide-to-api-security/) - [[Guide] API Security Best Practices – How To Secure APIs In Your Environment](https://checkmarx.com/learn/api-security/api-security-best-practices/) ### [Application Security](https://checkmarx.com/glossary/application-security-appsec/) *Authored by Checkmarx* - [[Guide] What is Application Security – How Does It Work & Best Practices](https://checkmarx.com/glossary/application-security-appsec/) - [[Guide] What is SQL Injection + Examples](https://checkmarx.com/glossary/sql-injection/) - [[Guide] Malicious code and how to prevent it](https://checkmarx.com/learn/supply-chain-security/malicious-code-guide/) ### [SAST](https://checkmarx.com/glossary/static-application-security-testing-sast/) *Authored by Checkmarx* - [[Guide] What is SAST? Static Application Security Testing Meaning](https://checkmarx.com/glossary/static-application-security-testing-sast/) - [[Guide] CVS Static Code Analysis](https://checkmarx.com/learn/sast/effective-static-source-code-analysis/) - [[Guide] Open-Source Vs. Premium SAST Tools](https://checkmarx.com/learn/sast/open-source-vs-premium-sast-tools/) ##### **VPN Resources:** [Atlantic.Net – VPN Connection Guide](https://www.atlantic.net/vps-hosting/atlantic-net-vpn-connection-guide/) [How to Set Up WireGuard VPN on CentOS 8](https://www.atlantic.net/vps-hosting/how-to-set-up-wireguard-vpn-on-centos-8/) [How to Install and Configure strongSwan VPN on Ubuntu 18.04](https://www.atlantic.net/vps-hosting/how-to-install-and-configure-strongswan-vpn-on-ubuntu/) [Do I need a VPN?](https://www.atlantic.net/hipaa-compliant-hosting/do-i-need-a-vpn/) [Censorship Workarounds: VPN as a Service and Other VM Options](https://www.atlantic.net/vps-hosting/censorship-workarounds-vpn-as-a-service-and-other-vm-options/) [Censorship Workarounds: How to Set Up a VPN – Part 2](https://www.atlantic.net/vps-hosting/censorship-workarounds-part-2-how-to-set-up-a-vpn/) --- #### Read More About Remote Management and VPNs - [VPS vs VPN](https://www.atlantic.net/vps-hosting/vps-vs-vpn-similar-names-but-completely-different-functions/)? - Best [Remote Management Tools](https://www.atlantic.net/vps-hosting/top-10-remote-management-tools/) --- --- # Atlantic.Net Technology Wins 2021 BIG Innovation Award > URL: https://www.atlantic.net/press-releases/atlantic-net-technology-wins-2021-big-innovation-award/ | Published: 2021-01-12 | Updated: 2026-03-02 | Author: Editorial Team ORLANDO, FLA—January 12, 2021—Atlantic.Net has been named a winner in the [2021 BIG Innovation Awards](https://www.bintelligence.com/big-innovation-awards), presented by the Business Intelligence Group. Atlantic.Net was awarded the BIG Innovation Award for 2021 for its technological solutions in the cloud, especially for the healthcare vertical. “More than ever, the global society relies on innovation to help progress humanity and make our lives more productive, healthy, and comfortable,” said Maria Jimenez, chief operating officer of the Business Intelligence Group. “We are thrilled to be honoring Atlantic.Net as they are one of the organizations leading this charge and helping humanity progress.” Organizations from across the globe submitted their recent innovations for consideration in the BIG Innovation Awards. Nominations were then judged by a select group of business leaders and executives who volunteer their time and expertise to score submissions. **About Atlantic.Net** Atlantic.Net is a global [cloud services](https://www.atlantic.net/hipaa-compliant-hosting/) provider with over 25 years of experience, serving thousands of developers and small, medium, and large clients in more than one hundred countries. Atlantic.Net specializes in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions and has served dynamic business clients including Lenovo, Newegg, NASA, and Hilton, among others. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions, backed by 24/7/365 support in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. For more information, please visit [Atlantic.Net](https://www.atlantic.net/). About **Business Intelligence Group** The [Business Intelligence Group](http://www.bintelligence.com/what-we-do/) was founded with the mission of recognizing true talent and superior performance in the business world. Unlike other [industry award programs](http://www.bintelligence.com/awards-deadlines/), these programs are judged by business executives having experience and knowledge. The organization’s proprietary and unique scoring system selectively measures performance across multiple business domains and then rewards those companies whose achievements stand above those of their peers. **Contacts** Atlantic.Net [pr@atlantic.net](mailto:pr@atlantic.net) +1(321) 206-1371 Maria Jimenez Chief Operating Officer Business Intelligence Group [jmaria@bintelligence.com](mailto:jmaria@bintelligence.com) +1 (909) 529-2737 --- # The SolarWinds Hack’s Impact on the US Software Supply Chain > URL: https://www.atlantic.net/vps-hosting/solarwinds-orion-hack-part-2/ | Published: 2021-01-12 | Updated: 2025-02-07 | Author: Richard Bailey *Atlantic.Net is providing this security advisory as a news item; we want to reassure our customers that Atlantic.Net does not use any SolarWinds products internally or in any of our service offerings.* Businesses, organizations, and government institutions are reeling from the fallout of the SolarWinds hack. The story of this far-reaching security breach broke around the 14th of December 2020, and even now we do not know the full impact of the incident. Every day we learn more of the extent of this unprecedented supply chain cyberattack. ## About the SolarWinds Hack What we do know is that in March 2020, [hackers beached SolarWinds’ computer infrastructure](https://www.solarwinds.com/securityadvisory) and gained control of the SolarWinds content management servers. In April 2020, the bad actors embedded sophisticated malware inside ‘genuine’ digitally signed SolarWinds updates. The affected updates were the automated updates that client computers look up when downloading security patches and hotfixes for SolarWinds’ Orion applications. This widely trusted software update practice is used by countless tech companies around the globe. For the SolarWinds customers that downloaded and installed the poisoned update, the hackers used the compromised update to inject a malware payload called SUNBURST into compromised customer servers. The malware apparently stayed dormant for about 2 weeks, likely to evade detection, before being activated by a [command and control site](https://www.microsoft.com/security/blog/2020/12/18/analyzing-solorigate-the-compromised-dll-file-that-started-a-sophisticated-cyberattack-and-how-microsoft-defender-helps-protect/) (C2) using subdomains gathered by the malware. ### How Long Did the Attack Go Undetected? Security experts believe the [malware lay dormant from April until July 2020](https://www.theguardian.com/technology/2020/dec/16/solarwinds-orion-hack-scrutiny-technology) , hiding in plain sight, and many believe this period was used for target reconnaissance by the threat actors to identify the highest value targets.  While we don’t know what data was compromised, we do know Office 365 data is likely to have been breached, potentially from OneDrive, Word documents, Sharepoint sites, and so on. The list of high profile victims grows daily. Some of the biggest names in technology and government are known to have been breached. Many security experts speculate that the attack was orchestrated by Russia, a view supported by a joint statement released by the FBI, CISA, ODNI, and NSA claiming that [the bad actors were likely Russian](https://www.cisa.gov/news-events/news/joint-statement-federal-bureau-investigation-fbi-cybersecurity-and-infrastructure) . The CISA was so concerned by the breach that on the 14th of December, it ordered all nonmilitary government systems that were running the SolarWinds Orion software to be [shut down and disconnected](https://www.lawfareblog.com/solarwinds-breach-why-your-work-computers-are-down-today) from the network. ## What Is a Supply Chain Attack? A **Supply Chain Attack** is a security incident that occurs when a malicious actor infiltrates a target’s system by exploiting an outside partner or service provider to gain unauthorized access to the systems and data files of the target. Global businesses are more connected now than ever in history. Cloud computing and the Internet have provided the tools to allow businesses to share large amounts of confidential business data quickly. As a normal practice, businesses buy software and hardware from one another to improve their own offerings to their customers. In this supply chain attack, businesses, global organizations, and US government institutions purchased the SolarWinds Orion Network Management System to gain insights about their networks. The real victims of the hack are not SolarWinds, but the 18,000 customers who never expected to be victims of a sophisticated hack that they had no control over, a hack that may turn out to be potentially the biggest cyberattack in history, and an attack that may lead to dramatic changes in cybersecurity. A supply chain attack blows cybersecurity controls wide open. The victims were following cybersecurity best practices by ensuring that their platforms were updated to the latest release; they did not know that their technology provider, SolarWinds, had been infiltrated by suspected Russian hacking squads that had poisoned updates to infect the entire supply chain. ## Who Was Targeted in the Supply Chain Attack? Our picture of this hack is changing all the time as the story unfolds, and we may not know the full extent of the hack for many months to come. But we do know that the US government has been significantly impacted. There are reports that the [US Treasury,](https://www.bankinfosecurity.com/us-treasury-suffers-significant-solarwinds-breach-a-15641) the [US Department of State](https://www.bbc.co.uk/news/technology-55318815) , the [CISA](https://www.scmagazine.com/home/security-news/updated-cisa-directive-discovers-saml-token-abuse-around-solarwinds-hack-calls-for-full-rebuild-of-affected-networks/) , the [DOE](https://www.utilitydive.com/news/doe-confirms-its-systems-were-compromised-by-solarwinds-hack/592441/) were targeted. ### How It Happened While the exact details are not known, one theory is that each government office used Office 365 and Exchange for email and that the shared keys for Azure Active Directory were compromised, potentially allowing the attackers to masquerade as genuine users to access email systems and document libraries. This theory is supported by statements released by the [Department of Justice](https://www.justice.gov/opa/pr/department-justice-statement-solarwinds-update) that “this activity involved access to the Department’s Microsoft O365 email environment” and “the number of potentially accessed O365 mailboxes appears limited to around 3 percent and we have no indication that any classified systems were impacted.” ### Who Was Impacted Of the many tech giants targeted, we know that among the victims were networking powerhouse Cisco Systems, CPU manufacturer Intel, GPU makers NVIDIA Corp., and the tech heavyweights VMware, Microsoft and Belkin. Doubtless many more companies have been impacted, but it will be weeks or months until the full picture is known. ## Next Steps If your business is concerned about cybersecurity, please feel welcome to reach out to Atlantic.Net. We are specialists in Managed Services, Cloud Hosting, and HIPAA compliance. The security of our infrastructure is of paramount importance, and we work hard to ensure we have the best security processes in place. This cyberattack will go down in history as one of the worst, and we feel concerned for our friends in the industry that might be affected by this. The clients of SolarWinds have done nothing wrong; they purchased an industry-leading server management suite from a reputable business, and now, due to unknown security incompetence, each customer has been put at risk through no fault of their own. [Get in touch today. ](https://www.atlantic.net/about-us/corporate-contact/) --- # Announcement: Meet Our Customer Service Champion for 2020: Sam G. > URL: https://www.atlantic.net/announcements/meet-our-customer-service-champion-for-2020-sam-g/ | Published: 2021-01-12 | Updated: 2025-09-19 | Author: Alexander Wise Sam G. was awarded our Customer Service Champion for the year 2020! ![](https://www.atlantic.net/wp-content/uploads/2021/01/Sam-G.png)Sam G., our Senior Account Executive – Major Accounts, has been with the company since 2003, and his favorite part of working here is that every day is different and exciting. He also likes meeting the challenge of helping customers to join and trust Atlantic.Net; Sam feels that a long-term business relationship is very rewarding. He also enjoys creating personal relationships with fellow A-listers (the rest of the Atlantic.Net Team) where he is trusted to do his job and to impart that trust to the people he works with. Sam says he is grateful for the award and feels that caring for customers is what he does best. He also feels very lucky to have a great place to work and people he loves to work with! Congrats Sam and thank you for all you do. Being an outside sales representative during a pandemic isn’t easy, and we appreciate all your hard work since 2003! --- # How to Install React.js on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-react-js-on-ubuntu-20-04/ | Published: 2021-01-15 | Updated: 2024-01-18 | Author: Hitesh Jethva React is an open-source JavaScript library used for building interactive user interfaces for web and mobile applications. It uses a virtual browser to act as an agent between a developer and a real browser. React was created and is maintained by Facebook, but is now used by many companies around the world. React consists of compiled HTML, CSS, and JavaScript files and is often used as a frontend for more complex applications. In this tutorial, we will show you how to deploy React.js on Ubuntu 20.04. ## Step 1 – Install Nodejs React App is a JavaScript library, so Node.js must be installed in your server. By default, the latest version of Node.js is not available in the Ubuntu standard repository, so you will need to install it from NodeSource. First, install the necessary dependencies using the following command. ``` apt-get install -y ca-certificates curl gnupg ``` Next, download the Node.js GPG key. ``` mkdir -p /etc/apt/keyrings curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg ``` Next, add the NodeSource repo to the APT source list. ``` echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_18.x nodistro main" | tee /etc/apt/sources.list.d/nodesource.list ``` Then, update the repository index and install the Ndoe.js with the following command. ``` apt update apt-get install -y nodejs ``` Once Node.js is installed, update the NPM to the latest version using the following command: ``` npm install npm@latest -g ``` You can now verify the installed version of Node.js with the following command: ``` node -v ``` You should get the following output: ``` v18.19.0 ``` ## Step 2 – Create a New Reactjs App First, you will need to install the create-react-app tool to create a new project in React. You can install it using the following command: ``` npm install -g create-react-app ``` You should get the following output: ``` /usr/bin/create-react-app -> /usr/lib/node_modules/create-react-app/index.js + create-react-app@4.0.1 added 67 packages from 25 contributors in 3.605s ``` Next, create a new project with the following command: ``` create-react-app awesome-project ``` You should see the following output: ``` Success! Created awesome-project at /root/awesome-project Inside that directory, you can run several commands: npm start Starts the development server. npm run build Bundles the app into static files for production. npm test Starts the test runner. npm run eject Removes this tool and copies build dependencies, configuration files and scripts into the app directory. If you do this, you can’t go back! We suggest that you begin by typing: cd awesome-project npm start Happy hacking! ``` Once your project is created, change the directory to your project and start the application with the following command: ``` cd awesome-project npm start ``` You should get the following output: ``` Compiled successfully! You can now view awesome-project in the browser. http://localhost:3000 Note that the development build is not optimized. To create a production build, use npm run build. ``` Press **CTRL+C** to stop the application. ## Step 3 – Create a Systemd Service File for React App Next, you will need to create a systemd service file to manage the React service. You can create it with the following command: ``` nano /lib/systemd/system/react.service ``` Add the following lines: ``` [Service] Type=simple User=root Restart=on-failure WorkingDirectory=/root/awesome-project ExecStart=npm start -- --port=3000 ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the React service and enable it to start at system reboot: ``` systemctl start react systemctl enable react ``` You can verify the status of the React service with the following command: ``` systemctl status react ``` You should get the following output: - ``` react.service ``` ``` Loaded: loaded (/lib/systemd/system/react.service; static; vendor preset: enabled) Active: active (running) since Sun 2020-12-06 10:11:04 UTC; 5s ago Main PID: 18556 (node) Tasks: 30 (limit: 4691) Memory: 170.0M CGroup: /system.slice/react.service ├─18556 npm ├─18583 sh -c react-scripts start "--port=3000" ├─18584 node /root/awesome-project/node_modules/.bin/react-scripts start --port=3000 └─18591 /usr/bin/node /root/awesome-project/node_modules/react-scripts/scripts/start.js -- port=3000 Dec 06 10:11:04 ubuntu2004 systemd[1]: Started react.service. Dec 06 10:11:04 ubuntu2004 npm[18556]: > awesome-project@0.1.0 start /root/awesome-project Dec 06 10:11:04 ubuntu2004 npm[18556]: > react-scripts start "--port=3000" Dec 06 10:11:07 ubuntu2004 npm[18591]: ℹ 「wds」: Project is running at http://0.0.0.0:3000/ Dec 06 10:11:07 ubuntu2004 npm[18591]: ℹ 「wds」: webpack output is served from Dec 06 10:11:07 ubuntu2004 npm[18591]: ℹ 「wds」: Content not from webpack is served from /root/awesome-project/public Dec 06 10:11:07 ubuntu2004 npm[18591]: ℹ 「wds」: 404s will fallback to / Dec 06 10:11:07 ubuntu2004 npm[18591]: Starting the development server... ``` ## Step 4 – Configure Nginx as a Reverse Proxy At this point, your React App is started and listening on port 3000. Next, you will need to configure Nginx as a reverse proxy to access the React App through port 80. First, install the Nginx web server with the following command: ``` apt-get install nginx -y ``` Once installed, create a new Nginx virtual host configuration file: ``` nano /etc/nginx/conf.d/react.conf ``` Add the following lines: ``` upstream react_backend { server localhost:3000; } server { listen 80; server_name react.example.com; location / { proxy_pass http://react_backend/; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forward-For $proxy_add_x_forwarded_for; proxy_set_header X-Forward-Proto http; proxy_set_header X-Nginx-Proxy true; proxy_redirect off; } } ``` Save and close the file then restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 5 – Access Reactjs Web UI Now, open your web browser and access the React App using the URL **http://react.example.com**. You should see your React Application in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/01/react1.png) ## Conclusion Congratulations! You have successfully installed and deployed React App with Nginx as a reverse proxy on Ubuntu 20.04. You can now start exploring React App for more features. Try out React.js on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Rundeck on CentOS 8 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-rundeck-on-centos-8/ | Published: 2021-01-16 | Updated: 2023-11-15 | Author: Hitesh Jethva Rundeck is a free and open-source tool used for managing multiple servers from a single server. Written in Java programming language, Rundeck provides a web-based interface to perform all administrative tasks. It uses a MySQL/MariaDB database to store the job definitions and execution history. Rundeck comes with a lot of tools that make it easier for you to scale up your automation efforts. In this tutorial, we will show you how to install Rundeck on CentOS 8. ## Step 1 – Install Java Rundeck is written in Java, so Java must be installed in your system. If not installed, you can install it with the following command: ``` dnf install java -y ``` After installing Java, you can verify the installed version of Java using the following command: ``` java -version ``` You should see the following output: ``` openjdk version "1.8.0_262" OpenJDK Runtime Environment (build 1.8.0_262-b10) OpenJDK 64-Bit Server VM (build 25.262-b10, mixed mode) ``` ## Step 2 – Install and Configure MySQL Rundeck uses a MySQL database to store the job and other history, so you will need to install MySQL on your server. You can install it with the following command: ``` dnf install mysql-server -y ``` Once installed, start the MySQL service and enable it to start at system reboot with the following command: ``` systemctl start mysqld systemctl enable mysqld ``` Next, you will need to create a database and user for Rundeck. First, log into the MySQL shell with the following command: ``` mysql ``` Once logged in, create a database and user with the following command: ``` create database rundeck; create user 'rundeckuser'@'localhost' identified by 'rundeckpassword'; ``` Next, grant all the privileges to the Rundeck database with the following command: ``` grant ALL on rundeck.* to 'rundeckuser'@'localhost'; ``` Next, flush the privileges and exit from MySQL with the following command: ``` flush privileges; exit; ``` ## Step 3 – Install Rundeck By default, Rundeck is not available in the CentOS 8 default repository, so you will need to add Rundeck repository to your system. First, import the Rundeck GPG key with the following command: ``` rpm --import http://rundeck.org/keys/BUILD-GPG-KEY-Rundeck.org.key ``` Next, add the Rundeck repository with the following command: ``` dnf install -y http://repo.rundeck.org/latest.rpm ``` Next, install Rundeck by running the following command: ``` dnf install rundeck -y ``` Once Rundeck is installed, you can proceed to the next step. ## Step 4 – Configure Rundeck Next, you will need to define your server address and database details in the Rundeck configuration file. Edit the Rundeck default configuration file as shown below: ``` nano /etc/rundeck/rundeck-config.properties ``` Change the following lines: ``` grails.serverURL=http://your-server-ip:4440 dataSource.dbCreate = update dataSource.url = jdbc:mysql://localhost/rundeck?autoReconnect=true&useSSL=false&serverTimezone=UTC dataSource.username=rundeckuser dataSource.password=rundeckpassword dataSource.driverClassName=com.mysql.jdbc.Driver ``` Save and close the file when you are finished, then start the Rundeck server and enable it to start at system reboot with the following command: ``` systemctl enable rundeckd systemctl start rundeckd ``` You can now verify the status of the Rundeck service with the following command: ``` systemctl status rundeckd ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2021/01/rundeck2.png) ## Step 5 – Access Rundeck Web Interface At this point, Rundeck is started and listening on port 4440. Now, open your web browser and type the URL http://your-server-ip:4440. You will be redirected to the Rundeck login page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/rundeck3.png) Provide the default username as **admin** and password as **admin** and click on the **Log** **In** button. You should see the Rundeck dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/rundeck4.png) Next, click on the **New** **Project** button to create a new project. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/rundeck5.png) Provide your project name, label, and description and click on the **Create** button. You should see the following page:![](https://www.atlantic.net/wp-content/uploads/2021/01/rundeck6.png) Click on the **Commands** in the left pane. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/rundeck7.png) Type the command “free -m” and click on the “**Run on 1 Node**“. This will execute the command on the localhost and display the output of the command as shown in the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/rundeck8.png) ## Conclusion In this guide, we learned how to install Rundeck and integrate it with the MySQL database on CentOS 8. We have also created a new project and execute commands with Rundeck. For more information about Rundeck, visit the Rundeck [documentation](https://docs.rundeck.com/docs/). If you’re ready to try Rundeck, get started on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How To Install RethinkDB on CentOS 8 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-rethinkdb-on-centos-8/ | Published: 2021-01-17 | Updated: 2024-08-15 | Author: Hitesh Jethva RethinkDB is a free and open-source No-SQL database manager that can be used in applications that require continuous access to data. It has very minimal response times and updates and supports the most popular languages, including PHP, Java, Ruby, and Python. RethinkDB is designed with automatic failover and robust fault tolerance. It uses a new database access model instead of polling for changes. RethinkDB also offers a built-in web interface to manage the database. In this tutorial, we will show you how to install RethinkDB on CentOS 8. ## Step 1 – Install RethinkDB By default, RethinkDB is not available in the CentOS 8 default repository, so you will need to install it from the RPM package. You can run the following command to download and install the RethinkDB RPM package in your system. Once installed, you should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2021/01/rethinkdb1.png) ## Step 2 – Configure RethinkDB First, you will need to copy RethinkDB sample configuration file with the following command: ``` cp /etc/rethinkdb/default.conf.sample /etc/rethinkdb/instances.d/instance1.conf ``` Next, edit the configuration file using the following command: ``` nano /etc/rethinkdb/instances.d/instance1.conf ``` Change the following lines to enable the RethinkDB web console: ``` http-port=8080 server-name=server1 directory=/var/lib/rethinkdb/default log-file=/var/log/rethinkdb bind=0.0.0.0 ```   ![](https://www.atlantic.net/wp-content/uploads/2021/01/rethinkdb2.png) Save and close the file when you are finished. Next, create the necessary files and provide proper permissions with the following command: ``` touch /var/log/rethinkdb chown -R rethinkdb:rethinkdb  /var/log/rethinkdb /var/lib/rethinkdb chmod -R 775 /var/log/rethinkdb /var/lib/rethinkdb ``` Now, start the RethinkDB service and enable it to start at system reboot with the following command: ``` systemctl enable --now rethinkdb systemctl start rethinkdb ``` You can now verify the status of the RethinkDB service with the following command: ``` systemctl status rethinkdb ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2021/01/rethinkdb3.png) ## Step 3 – Access RethinkDB Web Interface Now, open your web browser and access RethinkDB using the URL http://your-server-ip:8080. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/rethinkdb4.png) Now, click on the **Tables** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/rethinkdb5.png) Click on the **Add** **Database** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/rethinkdb7.png) Provide your database name and click on the **Add** button. You should see your database in the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/rethinkdb8.png) ## Conclusion Congratulations! You have successfully installed RethinkDB on CentOS 8. You can now easily use RethinkDB to build your large-scale applications. For more information, visit the RethinkDB official [documentation](https://rethinkdb.com/docs). Install RethinkDB on your Atlantic.Net [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) today. --- # How to Install and Configure OpenVPN Server on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-configure-openvpn-server-on-ubuntu-20-04/ | Published: 2021-01-19 | Updated: 2023-11-22 | Author: Hitesh Jethva OpenVPN is an open-source VPN solution for businesses that use virtual private network techniques to create secure point-to-point connections with remote access facilities. OpenVPN is a trusted technology used by many VPNs to make sure any data sent over the internet is encrypted and private. In simple terms, OpenVPN allows you to connect to other devices within one secure network. It is cross-platform and can be Windows, Mac, Android, iOS, and Linux. OpenVPN offers a rich set of features including: - Unlimited Bandwidth - Unlimited Server Switches - Multi-Device Usage - No Log Storage - Protocol Choices - Multiple Concurrent Connections In this tutorial, we will learn how to install and configure the OpenVPN server and client on an Ubuntu 20.04 VPS. ## Step 1: Enable IP Forwarding First, you will need to enable IP forwarding in your system so that OpenVPN can correctly route traffic through the VPN. You can enable IP forwarding by editing the file /etc/sysctl.conf: ``` nano /etc/sysctl.conf ``` Uncomment the following line: ``` net.ipv4.ip_forward = 1 ``` Save the file when you are finished, then run the following command to apply the changes: ``` sysctl -p ``` ## Step 2: Install OpenVPN Server By default, the OpenVPN package is available in Ubuntu 20.04, so you can install it by just running the following command: ``` apt-get install openvpn -y ``` Once the installation has been completed, you can proceed to the next step. ## Step 3: Build the Certificate Authority To set up the certificate authority and PKI infrastructure, you will need to download EasyRSA in your system. You can download it with the following command: ``` wget https://github.com/OpenVPN/easy-rsa/releases/download/v3.0.6/EasyRSA-unix-v3.0.6.tgz ``` Once downloaded, extract the downloaded file with the following command: ``` tar -xvzf EasyRSA-unix-v3.0.6.tgz ``` Next, move the extracted directory to the /etc/openvpn/ with the following command: ``` mv EasyRSA-v3.0.6 /etc/openvpn/easy-rsa ``` Next, change the directory to /etc/openvpn/easy-rsa and create a EasyRSA configuration file: ``` cd /etc/openvpn/easy-rsa nano vars ``` Add the following lines including your country, city, and preferred email address: ``` set_var EASYRSA                 "$PWD" set_var EASYRSA_PKI             "$EASYRSA/pki" set_var EASYRSA_DN              "cn_only" set_var EASYRSA_REQ_COUNTRY     "INDIA" set_var EASYRSA_REQ_PROVINCE    "Gujarat" set_var EASYRSA_REQ_CITY        "Junagadh" set_var EASYRSA_REQ_ORG         "Atlantic CERTIFICATE AUTHORITY" set_var EASYRSA_REQ_EMAIL     "admin@atlantic.net" set_var EASYRSA_REQ_OU          "Atlantic EASY CA" set_var EASYRSA_KEY_SIZE        2048 set_var EASYRSA_ALGO            rsa set_var EASYRSA_CA_EXPIRE      7500 set_var EASYRSA_CERT_EXPIRE     365 set_var EASYRSA_NS_SUPPORT  "no" set_var EASYRSA_NS_COMMENT            "Atlantic CERTIFICATE AUTHORITY" set_var EASYRSA_EXT_DIR         "$EASYRSA/x509-types" set_var EASYRSA_SSL_CONF        "$EASYRSA/openssl-easyrsa.cnf" set_var EASYRSA_DIGEST          "sha256" ``` Save the file when you are finished. Next, initiate the PKI directory using the following command: ``` ./easyrsa init-pki ``` You should get the following output: ``` Note: using Easy-RSA configuration from: ./vars init-pki complete; you may now create a CA or requests. Your newly created PKI dir is: /etc/openvpn/easy-rsa/pki ``` Next, build the CA certificates with the following command: ``` ./easyrsa build-ca ``` You should get the following output: ``` Note: using Easy-RSA configuration from: ./vars Using SSL: openssl OpenSSL 1.1.1f  31 Mar 2020 Enter New CA Key Passphrase: Re-Enter New CA Key Passphrase: Generating RSA private key, 2048 bit long modulus (2 primes) .....................................................................................................+++++ ..................................................+++++ e is 65537 (0x010001) Can't load /etc/openvpn/easy-rsa/pki/.rnd into RNG 139636302492992:error:2406F079:random number generator:RAND_load_file:Cannot open file:../crypto/rand/randfile.c:98:Filename=/etc/openvpn/easy-rsa/pki/.rnd You are about to be asked to enter information that will be incorporated into your certificate request. What you are about to enter is what is called a Distinguished Name or a DN. There are quite a few fields but you can leave some blank For some fields, there will be a default value, If you enter '.', the field will be left blank. ----- Common Name (eg: your user, host, or server name) [Easy-RSA CA]: CA creation complete and you may now import and sign cert requests. Your new CA certificate file for publishing is at: /etc/openvpn/easy-rsa/pki/ca.crt ``` The above command will generate two files named ca.key and ca.crt. These certificates will be used to sign your server and clients’ certificates. ## Step 4: Create Server Certificate Files Next, you will need to generate a keypair and certificate request for your server. Run the following command to generate the server key named atlantic-server: ``` ./easyrsa gen-req atlantic-server nopass ``` You should see the following output: ``` Note: using Easy-RSA configuration from: ./vars Using SSL: openssl OpenSSL 1.1.1f  31 Mar 2020 Generating a RSA private key .............................+++++ ...+++++ writing new private key to '/etc/openvpn/easy-rsa/pki/private/atlantic-server.key.IMonKybM0y' ----- You are about to be asked to enter information that will be incorporated into your certificate request. What you are about to enter is what is called a Distinguished Name or a DN. There are quite a few fields but you can leave some blank For some fields there will be a default value, If you enter '.', the field will be left blank. ----- Common Name (eg: your user, host, or server name) [atlantic-server]: Keypair and certificate request completed. Your files are: req: /etc/openvpn/easy-rsa/pki/reqs/atlantic-server.req key: /etc/openvpn/easy-rsa/pki/private/atlantic-server.key ``` This will generate a private key and a certificate request file for the server. ## Step 5: Sign the Server Key Using CA Next, you will need to sign the atlantic-server key using your CA certificate: You can sign the server key using the following command: ``` ./easyrsa sign-req server atlantic-server ``` You should see the following output: ``` Note: using Easy-RSA configuration from: ./vars Using SSL: openssl OpenSSL 1.1.1f  31 Mar 2020 You are about to sign the following certi ficate. Please check over the details shown below for accuracy. Note that this request has not been cryptographically verified. Please be sure it came from a trusted source or that you have verified the request checksum with the sender. Request subject, to be signed as a server certificate for 365 days: subject= commonName                = atlantic-server Type the word 'yes' to continue, or any other input to abort. Confirm request details: yes Using configuration from /etc/openvpn/easy-rsa/pki/safessl-easyrsa.cnf Enter pass phrase for /etc/openvpn/easy-rsa/pki/private/ca.key: Check that the request matches the signature Signature ok The Subject's Distinguished Name is as follows commonName            :ASN.1 12:'atlantic-server' Certificate is to be certified until Jun 29 11:43:05 2021 GMT (365 days) Write out database with 1 new entries Data Base Updated Certificate created at: /etc/openvpn/easy-rsa/pki/issued/atlantic-server.crt ``` Next, verify the generated certificate file with the following command: ``` openssl verify -CAfile pki/ca.crt pki/issued/atlantic-server.crt ``` You should get the following output: ``` pki/issued/atlantic-server.crt: OK ``` Next, run the following command to generate a strong Diffie-Hellman key to use for the key exchange: ``` ./easyrsa gen-dh ``` You should get the following output: ``` Note: using Easy-RSA configuration from: ./vars Using SSL: openssl OpenSSL 1.1.1f  31 Mar 2020 Generating DH parameters, 2048 bit long safe prime, generator 2 This is going to take a long time ......................+...........................+............................................ DH parameters of size 2048 created at /etc/openvpn/easy-rsa/pki/dh.pem ``` After creating all certificate files, copy them to the /etc/openvpn/server/ directory: ``` cp pki/ca.crt /etc/openvpn/server/ cp pki/dh.pem /etc/openvpn/server/ cp pki/private/atlantic-server.key /etc/openvpn/server/ cp pki/issued/atlantic-server.crt /etc/openvpn/server/ ``` ## Step 6: Generate Client Certificate and Key File Next, you will need to create the key and certificate file for the client. First, run the following command to build the client key file: ``` ./easyrsa gen-req client nopass ``` You should get the following output: ``` Note: using Easy-RSA configuration from: ./vars Using SSL: openssl OpenSSL 1.1.1f  31 Mar 2020 Generating a RSA private key ...+++++ ........+++++ writing new private key to '/etc/openvpn/easy-rsa/pki/private/client.key.JmBal6cmr8' ----- You are about to be asked to enter information that will be incorporated into your certificate request. What you are about to enter is what is called a Distinguished Name or a DN. There are quite a few fields but you can leave some blank For some fields there will be a default value, If you enter '.', the field will be left blank. ----- Common Name (eg: your user, host, or server name) [client]: Keypair and certificate request completed. Your files are: req: /etc/openvpn/easy-rsa/pki/reqs/client.req key: /etc/openvpn/easy-rsa/pki/private/client.key ``` Next, sign the client key using your CA certificate: ``` ./easyrsa sign-req client client ``` You should get the following output: ``` Note: using Easy-RSA configuration from: ./vars Using SSL: openssl OpenSSL 1.1.1f  31 Mar 2020 You are about to sign the following certificate. Please check over the details shown below for accuracy. Note that this request has not been cryptographically verified. Please be sure it came from a trusted source or that you have verified the request checksum with the sender. Request subject, to be signed as a client certificate for 365 days: subject= commonName                = client Type the word 'yes' to continue, or any other input to abort. Confirm request details: yes Using configuration from /etc/openvpn/easy-rsa/pki/safessl-easyrsa.cnf Enter pass phrase for /etc/openvpn/easy-rsa/pki/private/ca.key: Check that the request matches the signature Signature ok The Subject's Distinguished Name is as follows commonName            :ASN.1 12:'client' Certificate is to be certified until Jun 29 11:46:58 2021 GMT (365 days) Write out database with 1 new entries Data Base Updated Certificate created at: /etc/openvpn/easy-rsa/pki/issued/client.crt ``` Next, copy all client certificates and key files to the /etc/openvpn/client/ directory: ``` cp pki/ca.crt /etc/openvpn/client/ cp pki/issued/client.crt /etc/openvpn/client/ cp pki/private/client.key /etc/openvpn/client/ ``` ## Step 7: Configure OpenVPN Server At this point, all certificates and key files are ready. Next, create a new OpenVPN configuration file inside /etc/openvpn/ directory: ``` nano /etc/openvpn/server.conf ``` Add the following lines per your certificate and key path: ``` port 1194 proto udp dev tun ca /etc/openvpn/server/ca.crt cert /etc/openvpn/server/atlantic-server.crt key /etc/openvpn/server/atlantic-server.key dh /etc/openvpn/server/dh.pem server 10.8.0.0 255.255.255.0 push "redirect-gateway def1" push "dhcp-option DNS 208.67.222.222" push "dhcp-option DNS 208.67.220.220" duplicate-cn cipher AES-256-CBC tls-version-min 1.2 tls-cipher TLS-DHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256- CBC-SHA256:TLS-DHE-RSA-WITH-AES-128-GCM-SHA256:TLS-DHE-RSA-WITH-AES-128- CBC-SHA256 auth SHA512 auth-nocache keepalive 20 60 persist-key persist-tun compress lz4 daemon user nobody group nogroup log-append /var/log/openvpn.log verb 3 ``` Save the file when you are finished, then start the OpenVPN service and enable it to start after the system reboot using the following command: ``` systemctl start openvpn@server systemctl enable openvpn@server ``` Run the following command to verify the status of OpenVPN service: ``` systemctl status openvpn@server ``` You should get the following output: - ``` openvpn@server.service - OpenVPN connection to server ``` ``` Loaded: loaded (/lib/systemd/system/openvpn@.service; disabled; vendor preset: enabled) Active: active (running) since Mon 2020-06-29 11:48:25 UTC; 7s ago Docs: man:openvpn(8) https://community.openvpn.net/openvpn/wiki/Openvpn24ManPage https://community.openvpn.net/openvpn/wiki/HOWTO Main PID: 2868 (openvpn) Status: "Initialization Sequence Completed" Tasks: 1 (limit: 2353) Memory: 2.0M CGroup: /system.slice/system-openvpn.slice/openvpn@server.service └─2868 /usr/sbin/openvpn --daemon ovpn-server --status /run/openvpn/server.status 10 --cd /etc/openvpn --script-security 2 --conf> Jun 29 11:48:25 vpnserver systemd[1]: Starting OpenVPN connection to server... Jun 29 11:48:25 vpnserver systemd[1]: Started OpenVPN connection to server. ``` Once the OpenVPN service has started successfully, it will create a new network interface named tun0. You can verify it with the following command: ``` ip a show tun0 ``` You should get the new interface tun0 in the following output: ``` 4: tun0: mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 100 link/none inet 10.8.0.1 peer 10.8.0.2/32 scope global tun0 valid_lft forever preferred_lft forever inet6 fe80::5f83:99a:30d:eb0/64 scope link stable-privacy valid_lft forever preferred_lft forever ``` ## Step 8: Create Client Configuration File Next, you will need to create an OpenVPN client configuration file named client.ovpn. You will need this file to connect your OpenVPN server from the client system. ``` nano /etc/openvpn/client/client.ovpn ``` Add the following lines: ``` client dev tun proto udp remote your-vpn-server-ip 1194 ca ca.crt cert client.crt key client.key cipher AES-256-CBC auth SHA512 auth-nocache tls-version-min 1.2 tls-cipher TLS-DHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256- CBC-SHA256:TLS-DHE-RSA-WITH-AES-128-GCM-SHA256:TLS-DHE-RSA-WITH-AES-128- CBC-SHA256 resolv-retry infinite compress lz4 nobind persist-key persist-tun mute-replay-warnings verb 3 ``` Save the file when you are finished. ## Step 9: Install and Configure OpenVPN Client Next, you will need to install OpenVPN on the client system and connect to the OpenVPN server. First, log in to the client machine and install the OpenVPN package with the following command: ``` apt-get install openvpn -y ``` Next, you will need to copy the OpenVPN client configuration files from the OpenVPN server to the client machine. On the client machine, run the following command to download all the client configuration files: ``` scp -r root@vpn-server-ip:/etc/openvpn/client . ``` Once all files are copied, change the directory to the client and run the following command to connect to the OpenVPN server: ``` cd client openvpn --config client.ovpn ``` Once you are connected to the OpenVPN server, you should see the following output: ``` Jun 29 11:48:27 2020 TCP/UDP: Preserving recently used remote address: [AF_INET]69.87.218.145:1194 Jun 29 11:48:27 2020 Socket Buffers: R=[212992->212992] S=[212992->212992] Jun 29 11:48:27 2020 UDP link local: (not bound) Jun 29 11:48:27 2020 UDP link remote: [AF_INET]69.87.218.145:1194 Jun 29 11:48:27 2020 TLS: Initial packet from [AF_INET]69.87.218.145:1194, sid=6d27e1cb 524bd8cd Jun 29 11:48:27 2020 VERIFY OK: depth=1, CN=Easy-RSA CA Jun 29 11:48:27 2020 VERIFY OK: depth=0, CN=atlantic-server Jun 29 11:48:27 2020 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, 2048 bit RSA Jun 29 11:48:27 2020 [atlantic-server] Peer Connection Initiated with [AF_INET]69.87.218.145:1194 Jun 29 11:48:27 2020 SENT CONTROL [atlantic-server]: 'PUSH_REQUEST' (status=1) Jun 29 11:48:27 2020 PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1,dhcp-option DNS 208.67.222.222,dhcp-option DNS 208.67.220.220,route 10.8.0.1,topology net30,ping 20,ping-restart 60,ifconfig 10.8.0.6 10.8.0.5,peer-id 0,cipher AES-256-GCM' Jun 29 11:48:27 2020 OPTIONS IMPORT: timers and/or timeouts modified Jun 29 11:48:27 2020 OPTIONS IMPORT: --ifconfig/up options modified Jun 29 11:48:27 2020 OPTIONS IMPORT: route options modified ``` After a successful connection, OpenVPN will assign an IP address to your system. You can check it with the following command: ``` ip a show tun0 ``` Output: ``` 4: tun0: mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 100 link/none inet 10.8.0.6 peer 10.8.0.5/32 scope global tun0 valid_lft forever preferred_lft forever inet6 fe80::7226:57b1:f101:313b/64 scope link stable-privacy valid_lft forever preferred_lft forever ``` You can also check the OpenVPN server log to verify the connection status using the following command: ``` tail -f /var/log/openvpn.log ``` ## Conclusion Congratulations! You have successfully set up a VPN server with OpenVPN on an Ubuntu 20.04 [VPS](https://www.atlantic.net/vps-hosting/). You can now access the internet securely and protect your identity, location, and traffic. Visit the [OpenVPN](https://openvpn.net/community-resources/reference-manual-for-openvpn-2-4/) official documentation for more information. --- # How to Find a Data Center for Edge Computing Colocation > URL: https://www.atlantic.net/orlando-colocation-hosting-data-center/how-to-find-a-data-center-for-edge-computing-colocation/ | Published: 2021-01-19 | Updated: 2024-09-24 | Author: Richard Bailey Organizations have begun to unlock [edge computing](https://www.ibm.com/cloud/what-is-edge-computing)’s potential to provide them with a competitive advantage over market rivals or improve the functionality of distributed Internet-of-Things (IoT) systems. ## What Is Edge Computing? Edge computing is akin to an extension of, or improvement to, the power inherent to cloud computing. By bringing computing power closer to data sources, edge computing can provide better system response time and more efficient bandwidth usage. The idea behind edge computing is to process and act on data as closely as physically possible to where the data is created. Edge computing is a strategy to address the constantly growing volume of data generated by connected devices; the huge volume of data is challenging to efficiently transmit and process in centralized cloud data centers. As businesses and consumers move to 5G networks and beyond, the amount of data will only continue to increase. ### How Edge Computing Empowers IoT Devices The prevalence of IoT implementations and smart devices drives the growth in data and introduces new information streams that need to be efficiently collected and processed. As enterprises struggle to effectively use available data resources, processing them via an edge computing solution becomes an attractive alternative to in-house or traditional cloud data centers. One of the factors that makes edge computing possible is the advancement of artificial intelligence technology in endpoint devices like security cameras, smartphones, and equipment used in industrial automation systems. These devices can perform preprocessing or sorting of data to minimize the amount of data that needs to be transmitted to more powerful computing environments. ## The Benefits of Edge Computing Organizations can expect to achieve [multiple advantages](https://www.forbes.com/sites/bernardmarr/2020/09/16/3-advantages-and-1-disadvantage-of-edge-computing/?sh=8f17a4afc71a) when implementing an edge computing approach. These benefits may make the difference between a viable distributed or IoT system and a system that is destined to fail. One of the primary reasons that organizations use colocated data centers is to speed up data transmission. - **Latency** is a big problem with transferring large amounts of data to cloud data centers. Slow data transfer and response is tolerable under certain circumstances, such as the short delays in the response of a smartphone’s virtual assistant. In more time-sensitive scenarios, latency must be reduced to achieve the system’s desired functionality. Sensors responsible for real-time traffic control systems or autonomous vehicles cannot tolerate the time spent sending waiting for results based on data sent to the cloud. - **Bandwidth** is like latency in this regard: for certain use cases, the network resources must be available to satisfy system requirements, and bandwidth can be a limiting factor. In edge computing, the critical and most important data can be preprocessed and handled more efficiently without putting excessive demands on bandwidth. The remaining data can be transmitted to the cloud later for further analysis. - **Security** is enhanced by reducing the volume of data traveling over a network, thereby limiting the possibility of access by unauthorized actors. Having data distributed on multiple devices also eliminates the risk of a single point of failure that can cripple a sy Minimizing the distance data travels also reduces the number of routers the transmission must traverse, each of which is a potential security risk. The power in edge computing comes from bringing compute capabilities closer to the data rather than insisting on data being processed in a centralized data center. Logically, this means having hardware and software resources situated near the endpoint devices. This means that every organization wishing to make use of computing capabilities effectively needs a data center located near its end-users or systems. Providers are addressing this need through edge colocation offerings that connect devices located at the edge of the network to more extensive computing resources. ## Essential Components of an Edge Computing Data Center Companies that wish to make productive use of edge computing need to find the right partner unless they plan to build a dedicated colocation infrastructure. In most cases, this is unnecessary, and organizations will be better served by identifying a partner in their location that can provide the required resources. Many edge data centers are in secondary markets that lack access to more extensive colocation facilities. Their offerings are designed to appeal to local enterprises that need a bridge between their edge devices and the power of larger cloud infrastructure. In some cases, all processing can be done at the edge data center without the need to access more substantial resources. Size is not a defining factor for edge data centers. They can vary in size from a single antenna and server to an extensive infrastructure rivaling traditional data centers to meet specific customer requirements. Before entering into an agreement with a provider of edge computing data center services, customers should investigate the following essential components of the prospective provider: - The location of an edge data center is one of its most defining characteristics. To address the requirements of real-time processing involved in autonomous factories and smart city implementations, the data center needs to be located near the endpoint devices whose data it will service. One of the primary [benefits of edge computing](https://xailient.com/blog/a-comprehensive-guide-to-edge-ai/#Edge_AI_Unlocks_Many_Benefits_for_End_Users) is reducing latency, which is facilitated by limiting the distance between devices and the data center. - The capability for customers to perform data filtering is necessary to limit the amount of information transferred to larger data centers or the cloud. This helps address the issues of high latency or insufficient bandwidth that plague edge computing implementations. Critical data should be processed rapidly, while less time-sensitive data can be transferred so it can be used for business analytics. - Cutting-edge technology is mandatory for an edge data center. At a minimum, it must have the infrastructure and space to support its’ customers 5G networking requirements. While 5G promises incredible data transfer speeds, its coverage area per antenna is greatly reduced. This implies that many antennas will be needed to adequately cover a given area. A reliable edge computing data center provider will need to be willing to provide the space, power, and cooling resources to enable customers to install 5G equipment. ## Atlantic Net’s Orlando Data Center If you are looking for an edge computing colocation partner in the Orlando area, you need to consider the capabilities offered by Atlantic.Net. We offer state-of-the-art edge computing capabilities to Orlando organizations at our [Orlando Colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/) Data Center. Our secure and reliable collocation platforms are designed to meet the needs of all types of bandwidth-intensive businesses. Some of the features that set Atlantic.Net apart from its competitors include: - Our carrier-neutral facility has multiple redundant connections to the Internet backbone to ensure your data is transported over the fastest route. In the event of a carrier outage, traffic is redirected using alternate carriers. - Infrastructure is immediately available for customers with no waiting period required as with some other providers. Atlantic offers Dedicated Internet Access (DIA) through a blended solution for customers who don’t want to use their own carrier so they can get up and running quickly. - We offer 100% uptime SLAs for network and infrastructure so customers can be confident that their systems will always be accessible. - The [Orlando data center](https://www.atlantic.net/orlando-colocation-hosting-data-center/)’s hosting infrastructure is fully audited and is certified to be AICPA SOC 2 and SOC 3 compliant. - The facility is protected by redundant temperature and humidity controls as well as a backup generator that can serve 100% of customer peak load. - Our fully customizable and secure colocation hosting lets your business obtain the exact resources it needs and can seamlessly scale as your business grows. - Dark fiber connections are available, as well as roof space for 5G or satellite antennas, and our partnerships with fiber providers allow customers to minimize the deployment time. Edge computing can provide businesses with competitive or operational advantages. As opportunities for computing at the edge of the network increase, it becomes more evident that robust implementations require collaborative partnerships that make the best use of all available technology. Atlantic.Net offers organizations a reliable partner with which to reap the benefits of edge computing. --- # How to Reset a MySQL Root Password > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-reset-a-mysql-root-password/ | Published: 2021-01-20 | Updated: 2024-09-25 | Author: Hitesh Jethva MySQL is a free, open-source, and widely used database management system. It is very popular for web application software. MySQL has a root password that allows a user to perform all database-related tasks. If you are a system administrator responsible for managing a MySQL server, then you may often need to set or reset the MySQL root password – for example, if you forgot the MySQL root password or want to change the password for security reasons. In this tutorial, we will show how to set, change, or reset the MySQL root password in Ubuntu 18.04. ## Step 1 – Set the MySQL Password for the First Time When you install the MySQL server for the first time, a MySQL root password is not set. You can connect to the MySQL shell without providing a password, but this is not recommended for security reasons. To set the MySQL root password, connect to the MySQL shell with the following command: ``` mysql ``` Once connected, change the database to mysql using the following command: ``` use mysql; ``` Next, set the MySQL root password with the following command: ``` ALTER USER 'root'@'localhost' IDENTIFIED WITH mysql_native_password BY 'secure- password'; ``` Next, flush the privileges and exit from the MySQL shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` Next, verify the MySQL by logging in with the root user: ``` mysql -u root -p ``` You will be prompted to enter the newly configured password to connect to the MySQL shell. ![](https://www.atlantic.net/wp-content/uploads/2021/01/mysql1.png) ## Step 2 – Change the MySQL Root Password The easiest way to change the MySQL root password is with mysql_secure_installation script. ``` mysql_secure_installation ``` You will be asked to provide your current MySQL root password as shown below: ``` Securing the MySQL server deployment. Enter password for user root: ``` Provide your MySQL root password and hit **Enter**. You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2021/01/mysql2.png) ``` Select “No” ``` You will then be prompted to change the **root**password. Select **YES.** ** ** ``` Estimated strength of the password: 100 Change the password for root ? ((Press y|Y for Yes, any other key for No) : Y ``` Type **Y** and hit **Enter** to proceed. You will be asked to provide new password as shown below: ``` New password: Re-enter new password: ``` Provide your new password, hit **Enter**, and complete the remaining steps as shown below: ``` Do you wish to continue with the password provided?(Press y|Y for Yes, any other key for No) : Y Remove anonymous users? (Press y|Y for Yes, any other key for No) : Y Disallow root login remotely? (Press y|Y for Yes, any other key for No) : Y Remove test database and access to it? (Press y|Y for Yes, any other key for No) : Y Reload privilege tables now? (Press y|Y for Yes, any other key for No) : Y ``` You can also change the MySQL root password with the following command: ``` mysqladmin -u root -p password your-new-password ``` You will be asked to provide your current root password to change the password. ## Step 3 – Recover Forgotten MySQL Root Password If you forgot the MySQL root password, then you will need to recover it. To recover the MySQL root password, first stop the MySQL service using the following command: ``` systemctl stop mysql ``` Next, create a mysqld directory and give proper permissions with the following command: ``` mkdir -p /var/run/mysqld chown mysql:mysql /var/run/mysqld ``` Next, start the MySQL service with the –skip-grant-tables: ``` mysqld_safe --skip-grant-tables & ``` This will allow you to connect the MySQL server without a password. Next, log in to MySQL with the root user as shown below: ``` mysql -u root ``` After login, change the database to mysql as shown below: ``` use mysql; ``` Next, reset your root password with the following command: ``` UPDATE mysql.user SET authentication_string = PASSWORD('new-password') WHERE User = 'root' AND Host = 'localhost'; ``` Next, reload the privileges and exit from the MySQL shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` Next, stop the MySQL service with the following command: ``` mysqladmin -u root -p shutdown ``` You will be asked to provide your new password to stop the MySQL service. ![](https://www.atlantic.net/wp-content/uploads/2021/01/mysql4.png) Next, start the MySQL service again with the following command: ``` systemctl start mysql ``` Next, log in to MySQL with your new password as shown below: ``` mysql -u root -pnew-password ``` Once logged in, you should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2021/01/mysql5.png) ## Conclusion In the above guide, you learned how to set, update, and recover the MySQL root password on an Ubuntu 18.04 server. This guide should work with Ubuntu 18.04, Debian 10 and CentOS 8. If you are ready to try resetting your MySQL password, get started on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # Top 10 HIPAA Web Conference Software Companies > URL: https://www.atlantic.net/hipaa-compliant-hosting/top-10-hipaa-web-conference-software-companies/ | Published: 2021-01-20 | Updated: 2025-08-03 | Author: Dr. Rachael Bailey Web conferencing software is nothing new and, in some industries, it has been a valuable tool for decades. However, as much of the world’s workforce has shifted to working from home in 2020, video conferencing has transformed from a helpful supporting technology for businesses into an essential tool across the workforce that is keeping the majority of businesses up and running. Within the healthcare industry, telemedicine enables healthcare providers to improve their patient reach, reduce costs, maximize time, improve emergency response, and improve overall health outcomes. Thanks to technological advances, video conferencing software has now become accessible for businesses of any size. ## What makes a Web Conference Software Company HIPAA-compliant? With the [recent massive increase in telehealth appointments](https://www.cdc.gov/mmwr/volumes/69/wr/mm6943a3.htm) as a result of the current global pandemic, healthcare providers must ensure that sensitive patient data is protected. Healthcare professionals should make certain that they are using a fully HIPAA and/or HITECH-compliant web conferencing service. To ensure HIPAA compliance when choosing a video conferencing tool, it is advisable that healthcare professionals: 1. Verify that the web conference software company offers a Business Associate Agreement (BAA) 2. Choose a provider that offers end-to-end encryption 3. Check that your provider has completed a relevant risk assessment to ensure compliance 4. Ensure that web conferencing software implements the necessary access controls, making sure that video calls are password protected 5. Make sure that the chosen software has detailed auditing trails in place 6. Confirm that the telemedicine software features user authentication 7. Ensure that all application executables are digitally signed to ensure data integrity ## Choosing a HIPAA-Compliant Web Conference Software Company While there are hundreds of web conferencing tools available, there are subtle differences between these solutions. Below we have highlighted some of the top HIPAA-compliant web conferencing services: 1. Let’s Talk Interactive 2. Doxy.me 3. Zoom for Healthcare 4. TheraNest 5. thera-LINK 6. GoToMeeting 7. Medici 8. Mend 9. SimplePractice 10. VSee ## 1. Let’s Talk Interactive [Let’s Talk Interactive](https://letstalkinteractive.com/) is a leading provider of HIPAA-compliant telehealth technology solutions, facilitating over three million minutes of remote telehealth sessions each month. They deliver a customizable and user-friendly web conferencing platform, ensuring high levels of security and full HIPAA compliance. Compatible with any operating system, browser, or mobile phone, this company’s cloud-based telehealth platform can be used by medical organizations, ranging from solo practitioners to hospital networks. ## 2. Doxy.me Doxy.me is a highly popular cloud-based web conferencing solution that is fully compliant with HIPAA, GDPR, PHIPA/PIPEDA, and HITECH standards. Doxy.me provides healthcare professionals with a free, simple, and easily accessible interface, requiring no download of software thanks to its browser-based platform. Users can benefit from a fully customizable virtual patient queue, a live chat function, and a BAA across all accounts. High-quality HD video and audio ensures that healthcare providers and their patients have a positive virtual experience. ## 3. Zoom for Healthcare The popularity of Zoom has risen rapidly during the global coronavirus pandemic. Despite being used primarily by businesses, Zoom also offers a plan aimed specifically at the healthcare industry. Zoom for Healthcare offers a HIPAA-compliant video conferencing solution for healthcare providers that includes a signed BAA. Zoom for Healthcare can successfully integrate with medical devices, such as medical cameras and digital stethoscopes, as well as a patient’s electronic health record (EHR). ## 4. TheraNest TheraNest is a HIPAA-compliant web-based practice management software tool for the mental health sector. This software is used by therapists, counselors, social workers, and psychologists in educational, non-profit, individual, and large health organizations. Patients can join a scheduled meeting simply by using a unique invite link with no need to download any additional software. This EHR solution offers clients storage for patient information, insurance billing tools, and calendar scheduling, with HIPAA-compliant telehealth video conferencing an additional useful feature available for an extra cost. ## 5. thera-LINK thera-LINK is a video conferencing solution that is targeted specifically at professionals working within the mental and behavioral health sector, providing them with an essential tool for both one-to-one and group therapy sessions. All video conferencing sessions are fully secured and encrypted to ensure the safety of PHI. thera-LINK incorporates important security features including end-to-end encryption and secure file sharing. ## 6. GoToMeeting GoToMeeting provides web-hosted face-to-face video conferencing to businesses and professionals. Powered by LogMeIn, GoToMeeting offers a specific, easy-to-use web conferencing platform for healthcare professionals. The software fully supports HIPAA compliance by offering clients a comprehensive BAA and providing robust security measures, such as meeting locks, access codes, and invite-only restrictions. GoToMeeting offers clients a choice of three plans – professional, business, and enterprise, and unlike many competitors, all of these plans are HIPAA compliant. ## 7. Medici Medici provides medical professionals with a HIPAA-compliant telehealth mobile app. A striking feature of this software is the ability to import patient contact information into the Medici app directly from a supported EHR. Medici’s platform implements robust security standards, with SOC2 Type 2, HIPAA, and VcPR compliance. Using this platform, patients can choose between three secure consultation options: text, voice, or HD video. ## 8. Mend Mend is a comprehensive integrated telehealth and patient engagement platform. Mend allows integration with EHR services and access to numerous patient communication tools. Mend enables healthcare professionals and patients to make a secure connection with just the click of a link, enabling the sharing of videos, files, photos, messages, and data. PredictiveIQ AI can be used to predict missed appointments and automated appointment reminders can also be set up. Mend meets all HIPAA requirements while providing patients and healthcare providers with a friendly and easy-to-use interface. ## 9. SimplePractice SimplePractice offers healthcare organizations bank-level encryption to ensure that sensitive patient data remains secure, anonymous, and private during telemedical appointments. Using SimplePractice, patients are able to access meetings from anywhere using just a link and can even share information with their healthcare professionals prior to their appointment. Incorporating many useful features, SimplePractice’s offer of insurance processing distinguishes it from many of its competitors. ## 10. VSee With over 10 years of experience within the healthcare sector, VSee offers an all-in-one platform that provides its users with easy-to-use HIPAA-compliant video conferencing and remote patient monitoring. VSee enables healthcare professionals to connect with their patients in between appointments, as well as offering the ability to integrate with popular medical devices. VSee securely encrypts all audio and video communication and provides users with a BAA. ## How Can Atlantic.Net Help? Atlantic.Net is a global cloud service provider with over 30 years of industry-leading experience. We have very many happy healthcare clients that leverage Atlantic.Net services for a robust and scalable HIPAA-compliant hosting solution that can integrate directly with your telehealth applications. We can provide turn-key hosting solutions that include encrypted VPN connectivity, perfect if your medical organization opts for a cloud-based SaaS web conferring solution. We encrypt peer-to-peer connections and implement access controls in line with HIPAA safeguard recommendations. Our world-class HIPAA hosting facilities can power your healthcare infrastructure, giving you the performance needed to build your own teleconferencing solution on our platform. We have detailed instructions on how to install [Let’s Chat](https://www.atlantic.net/vps-hosting/how-to-install-lets-chat-on-an-ubuntu-20-04/) or [Rocket.Chat](https://www.atlantic.net/vps-hosting/how-to-deploy-rocket-chat-with-nginx-on-ubuntu-18-04/) securely on our HIPAA infrastructure. If you are a healthcare provider in the market for a secure HIPAA compliant cloud hosting service, [contact our sales team](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) to find out how Atlantic.Net can help you. --- # Top 10 DSP Providers > URL: https://www.atlantic.net/vps-hosting/top-10-dsp-providers/ | Published: 2021-01-21 | Updated: 2024-08-16 | Author: Dr. Rachael Bailey A Demand-Side Platform (DSP) is a web-based platform that allows media buyers to purchase digital ad inventory from multiple sources through a single interface. As a part of the Programmatic Advertising ecosystem, the DSP acts as a central repository, integrating with ad exchanges and other sources, such as SSPs (Supply Side Platform). By acting as a middleman between publishers and media buyers, DSPs help to streamline the process of ad buying, making it significantly cheaper, quicker, and more efficient.  DSPs automate media buying activities by using intelligent software to analyze ad impressions and make informed bids in real-time. This allows advertisers, brands, and agencies to target adverts to their tailored audiences. Are you in the market for a DSP? With hundreds of DSPs on the market, we have compiled a list of our top 10 DSP providers. Our list considers their available inventory, targeting capabilities, reporting analytics, and anti-fraud measures. 1. The Trade Desk 2. MediaMath 3. Adobe Advertising Cloud DSP 4. Amazon DSP 5. StackAdapt 6. Adform 7. Brightroll 8. Google Display and Video 360 9. AppNexus 10. Adelphic ## 1. The Trade Desk The Trade Desk is an industry-leading independent DSP provider, helping media buyers to improve their reach across every channel and device all around the world. With access to a marketplace of over 225 partners, The Trade Desk provides its clients with the data management platform necessary to ensure that all media buying decisions are guided by real-time insights. The Trade Desk API can hook straight into client systems streamlining application integration. The Trade Desk has partnered with White Ops, an industry-leading cybersecurity firm, to scan and block fraudulent impressions before purchase. ## 2. MediaMath MediaMath’s TerminalOne is a responsive and fully customizable media buying platform designed to improve a [brand’s reach](https://brand24.com/blog/online-presence-score/) and influence. MediaMath provides its clients with access to hundreds of integrated data, media, and technology providers. Like The Trade Desk, TerminalOne also allows media buyers to control the features of the digital advertising platform using APIs. Committed to transparency and honesty, MediaMath’s TerminalOne has partnered with White Ops and use White Ops Human Verification Technology to block sophisticated invalid traffic (SIVT) and fraudulent impressions. ## 3. Adobe Advertising Cloud DSP Adobe’s DSP offering, Adobe Advertising Cloud DSP, delivers cross-screen and cross-channel integrations, allowing media buyers to purchase, measure, and optimize their ad campaigns. As Adobe Advertising Cloud is natively integrated with Adobe Analytics, brands and agencies can target their advertising more efficiently through analysis of DSP performance metrics. ## 4. Amazon DSP Amazon DSP, previously known as Amazon Advertising Platform (AAP), allows media buyers to target audiences on Amazon-owned sites and apps and through third-party exchanges and Amazon’s publishing partners. [Amazon DSP](https://www.sellerapp.com/blog/amazon-dsp/) provides its clients with audience insights and performance reporting, allowing them to track the success of their ad campaigns. Clients may opt for a self-service or a managed-service option and will benefit from industry-standard protection against SIVT. ## 5. StackAdapt Based out of Toronto, Canada, [StackAdapt](https://www.stackadapt.com/) is a leading self-serve programmatic advertising platform that allows digital marketers to plan, execute, and manage data-driven digital advertising campaigns. With the use of machine learning and AI, StackAdapt makes automating performance decisions quicker and easier so that business can scale their campaigns. ## 6. Adform Based in Denmark, Adform is a leading global independent advertising technology company. Adform’s omnichannel DSP platform provides advertisers with access to its extensive inventory, advanced buying algorithms, cross-device targeting, and built-in proprietary anti-fraud measures. ## 7. BrightRoll Owned by Yahoo, BrightRoll is a global DSP that provides access to inventory from both Yahoo-owned sites and other premium publishing partners. Exclusive access to Yahoo Audience Data ensures that clients are able to gain insights that help them to target the right audiences. With BrightRoll, media buyers have extensive data at their fingertips as Yahoo platforms register over 165 billion data points each day. BrightRoll has built strong strategic partnerships with companies, such as DoubleVerify, to effectively manage fraud across the platform. ## 8. Google Display and Video 360 Google Display and Video 360 represents the amalgamation of DoubleClick Bid Manager, Campaign Manager, Studio, and Audience Center. With a reach across over 80 non-Google 3rd-party ad exchanges and over 800 million websites, the inventory provided by Display and Video 360 is unparalleled. Clients can benefit from intelligent automation to allow bidding and optimization to be streamlined and native integration with other solutions, such as Google Analytics 360. ## 9. AppNexus AppNexus boasts the world’s largest independent programmatic marketplace and allows clients to harness the power of data and machine learning to inform advertising decisions, delivering intelligent campaigns. AppNexus DSP’s transparent platform can be integrated with internal programs to streamline the media buying process. ## 10. Adelphic Adelphic is a leading omnichannel DSP, designed to simplify the workflow of programmatic traders. Adelphic’s self-service intuitive software ensures that brands and agencies are able to establish and maintain meaningful campaigns across all programmatic formats and devices. Adelphic is the only DSP on the market that provides a subscription-based model, helping to significantly reduce buying fees. ## Bonus: Oxagile We also would like to highlight [Oxagile,](https://www.oxagile.com/adtech/?utm_source=atlanticnet&utm_medium=referral&utm_campaign=dsplisting) a full-fledged [adtech](https://hightouch.com/blog/adtech) development provider that focuses on building, re-architecturing, and enhancing demand-side platforms. Underpinned by programmatic advertising knowledge, the company revamps complex workflows, including inventory buying and optimization, cross-device campaign creation and management, ad performance reporting, and advanced audience targeting. By reinforcing existing DSPs with cutting-edge functionality or building custom ones, Oxagile helps clients get more control over their media-buying processes as well as optimize costs. ## Bonus: Basis Basis by Centro is an award-winning omnichannel DSP designed for speed and performance. Basis has an intuitive and user-friendly interface and possesses the toolkit necessary for the purchase and management of cross-channel and cross-format ad campaigns. With over 15 years of establishing publisher relationships, Basis brings its best-in-class private marketplace of over 2000 active private deals across hundreds of top sites. Basis has established partnerships with industry-leading brand safety providers, ensuring that fraudulent activity across the platform is constantly monitored and blocked. ## How Can Atlantic.Net Help? Atlantic.Net has been providing cutting-edge hosting services for over 30 years. Our platform uses the latest technology and is powered by the latest Intel Xeon CPUs architecture and networking. All our storage is redundant, tipping the reliability scale into overdrive. If you are looking for a scalable cloud platform to meet the demand of your next DSP marketing drive, look no further than Atlantic.Net. Our programmatic API allows you to provision a single server to thousands of machines in a matter of seconds and allows for programmatic integration. Our service is resilient and will stay up even with heavy traffic loads; we even offer a 100% service level agreement to back up this claim. Our Managed Services are specially designed to help our clients get more for less, and our engineering team will never leave you hanging. Our Managed Services and Security Services help bring focus to your core business so that you can continue to grow your business. [Contact the team today](https://www.packtpub.com/product/amazon-web-services-aws-technical-essentials-ultimate-training-program-video/9781801079716) to see how Atlantic.Net can drive you forward and help get your brand out there for the rest of the world to explore. --- # How to Set Environment Variables in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-set-environment-variables-in-linux/ | Published: 2021-01-23 | Updated: 2023-11-18 | Author: Hitesh Jethva A variable is a location for storing a value which could be a filename, text, number or any other data. A variable is usually referred to with its symbolic name. The value stored can be displayed, deleted, edited, and re-saved. Variables play an important role in computer programming because they enable programmers to write flexible programs. An environment variable alters the dynamic values which affect the processes or programs on a computer. They exist in every operating system and their types vary. Environment variables also give information about system behavior and can change the behavior of software and programs. In this tutorial, we will show you how to set environment variables in Linux. ## Step 1 – List Environment Variables You can list all environment variables in your system by running the following command: ``` printenv ``` Or: ``` env ``` You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/01/variable1.png) There are a lot of environment variables available in Linux, including HOME, USER, EDITOR, PATH, LANG, TERM, MAIL, SHELL, and many more. You can display the value of specific variable by passing the name of the variable to the printenv command. For example, to display the value of the LANG variable, use the following command: ``` printenv LANG ``` You should see the following output: ``` en_US.UTF-8 ``` ## Step 2 – Set up an Environment Variable There are two types of variables: Shell variables and the Environment variables. To create a new shell variable named COMPANY with value Atlantic, use the following command: ``` COMPANY="Atlantic" ``` Next, you can verify the variable using the echo command: ``` echo $COMPANY ``` You should see the value of your variable in the following output: ``` Atlantic ``` You can also verify whether the above variable is an environment variable or not using the printenv command: ``` printenv COMPANY ``` You should see the empty output which means the variable is not an environment variable. To create a new environment variable named ORGANIZATION, use the export command: ``` export ORGANIZATION=Atlantic ``` You can verify the environment variable with the following command: ``` printenv ORGANIZATION ``` You should get the following output: ``` Atlantic ``` The environment variables which you have created in this way are available only in the current session. If you log out of your system, all variables will be lost. You can also unset an environment variable you created earlier using the unset command followed by the variable name. For example, to unset an ORGANIZATION variable, use the following command: ``` unset ORGANIZATION ``` ## Step 3 – Set up Persisting Environment Variable When you set an environment variable using the export command, its existence ends when the user’s session ends, so it is recommended to set environment variables that are persist across sessions. To set persisting environment variables globally, you will need to define them in /etc/profile file. For example, you can set the persisting environment variable named COMPANY with value Atlantic by editing /etc/profile file as shown below: ``` nano /etc/profile ``` Add the following line at the end of the file: ``` export COMPANY=Atlantic ``` Save and close the file when you are finished, then activate the variable with the following command: source /etc/profile You can also set a persisting environment for a specific user by editing the user’s .bashrc file. For example, set a persisting environment named VAR with value “My Linux Box” by editing the user’s .bashrc file: ``` nano ~/.bashrc ``` Add the following line at the end of the file: ``` export VAR="My Linux Box" ``` Save and close the file when you are finished, then activate the environment variable with the following command: ``` source ~/.bashrc ``` ## Conclusion In the above guide, you learned how to set and unset an environment variable in Linux. Environment variables are very useful for developers who will need to read or alter the environment of your system. If you’re ready to try setting an environment variable in Linux, get started on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install the Rudder System Auditing tool on CentOS 8 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-the-rudder-system-auditing-tool-on-centos-8/ | Published: 2021-01-25 | Updated: 2023-11-15 | Author: Hitesh Jethva Rudder is a multi-platform, open-source, professional solution for continuous auditing, deployment, and remediation of configurations within critical systems. It can be likened to a control tower that offers real-time visibility over how compliant your systems are with security and reliability parameters. Rudder manages the following issues: - **Continuous growth:** The IT industry increasingly demands an ever greater number of machines to maintain business services. Ensuring that all of these machines are functioning properly can be a major challenge. - **Continuous availability:** When IT infrastructure is reliable and continuously reachable, it ensures high availability for IT services. - **Continuous threat:** Systems that are constantly exposed to threats require continuous audits. Audits help detect and correct the threats. In this tutorial, we will learn how to install the Rudder system auditing tool on CentOS 8. ## Step 1 – Install Rudder By default, Rudder is not available in the CentOS 8 standard repository, so you will need to create a repo for Rudder. First, import the Rudder key with the following command: ``` rpm --import https://repository.rudder.io/rpm/rudder_rpm_key.pub ``` Next, create a Rudder repo file using the following command: ``` nano /etc/yum.repos.d/rudder.repo ``` Add the following lines: ``` [Rudder_6.1] name=Rudder 6.1 baseurl=http://repository.rudder.io/rpm/6.1/RHEL_$releasever/ gpgcheck=1 gpgkey=https://repository.rudder.io/rpm/rudder_rpm_key.pub ``` Save and close the file when you are finished, then install the Rudder server with the following command: ``` dnf install rudder-server-root -y ``` Once the Rudder is installed, you can verify the status of the Rudder service with the following command: ``` systemctl status rudder-jetty ``` You should get the following output: - ``` rudder-jetty.service - Jetty Web Application Server ``` ``` Loaded: loaded (/usr/lib/systemd/system/rudder-jetty.service; enabled; vendor preset: disabled) Active: active (running) since Fri 2020-10-02 04:56:08 EDT; 3min 59s ago Main PID: 5155 (java) Tasks: 84 (limit: 12523) Memory: 630.7M CGroup: /system.slice/rudder-jetty.service └─5155 /bin/java -server -Xms1024m -Xmx1024m -XX:+UseConcMarkSweepGC - XX:+CMSClassUnloadingEnabled -Dfile.encoding=UTF-8 -Drudder.c> Oct 02 04:55:50 centos8 systemd[1]: Starting Jetty Web Application Server... Oct 02 04:55:50 centos8 rudder-jetty.sh[5081]: Setting umask to 0007 Oct 02 04:56:08 centos8 rudder-jetty.sh[5081]: Starting Jetty: . . . OK Fri Oct  2 04:56:08 EDT 2020 Oct 02 04:56:08 centos8 systemd[1]: Started Jetty Web Application Server. ``` ## Step 2 – Create an Admin User for Rudder Next, you will need to create a Rudder admin user and set the password. You can create it with the following command: ``` rudder server create-user -u admin ``` You will be asked to set admin password, as shown below: ``` New password: Re-type new password: User 'admin' added, restarting the Rudder server Next, restart the Rudder service to apply the changes: ``` ``` systemctl restart rudder-server ``` Next, you will need to allow the network that you want to monitor. You can allow it with the following command: ``` /opt/rudder/bin/rudder-init LDAPReset 0.0.0.0/0 ``` You should get the following output: ``` SUMMARY OF OPTIONS: Allowed networks: 0.0.0.0/0 Force LDAP reset: LDAPReset done. Updating Rudder password file with random passwords...  done. Cleaning up temporary directories... done. Restarting jetty... done. Reinitialization complete, Rudder is currently reloading. You can access it via https://centos8/rudder ``` ## Step 3 – Access Rudder Web Interface You can now access the Rudder web interface using the URL **https://your-server-ip/rudder**. You should see the Rudder login page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/rudder1.png) Provide your admin username and password and click on the **SIGN** **IN** button. You should see the Rudder dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/rudder2.png) ## Conclusion Congratulations! You have successfully installed and configured Rudder on CentOS 8. You can now install Rudder clients on the remote nodes, add them to the Rudder server, and start managing them from the Rudder dashboard. Install Rudder on your Atlantic.Net [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) today. --- # How to Install Varnish Cache with Apache on CentOS 8 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-varnish-cache-with-apache-on-centos-8/ | Published: 2021-01-27 | Updated: 2023-11-19 | Author: Hitesh Jethva Caching is the process of storing copies of files in a cache so that future requests for that file can be accessed more quickly. Varnish is a free, open-source, powerful HTTP engine and reverse HTTP proxy used by more than 3.4 million websites. It stores the incoming page requests in memory and serves the same page request directly from Varnish cache instead of going straight to the web server. This will speed up the performance of your website significantly. Varnish has its own configuration language (VCL) to write policies on incoming requests such as back-end servers, ACLs, responses, and more. In this tutorial, we will learn how to set up Varnish caching with Apache on CentOS 8. We will set up Apache to listen on port 8080 and work as a backend server, then configure Varnish to listen on default HTTP port 80. ## Step 1 – Install Varnish Cache By default, the Varnish package is available in the CentOS 8 system. You can install it by just running the following command: ``` dnf update -y dnf install varnish -y ``` After installing Varnish, start the Varnish service and enable it to start after system reboot with the following command: ``` systemctl start varnish systemctl enable varnish ``` Next, verify the status of Varnish with the following command: ``` systemctl status varnish ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2021/01/varnish1.png) By default, Varnish listens on port 6081. You can verify it using the following command: ``` netstat -ltnp | grep 6081 ``` You should get the following output: ``` tcp        0      0 0.0.0.0:6081            0.0.0.0:*               LISTEN      1508/varnishd tcp6       0      0 :::6081                 :::*                    LISTEN      1508/varnishd ``` ## Step 2 – Install and Configure Apache Next, you will need to install the Apache webserver and configure it to work with the Varnish cache. First, install the Apache server with the following command: ``` dnf install httpd -y ``` After installing the Apache webserver, you will need to change the Apache web server listening port from **80** to **8080**. You can do it by editing the file /etc/httpd/conf/httpd.conf. ``` nano /etc/httpd/conf/httpd.conf ``` Find the following line: ``` Listen 80 ``` And replace it with the following line: ``` Listen 8080 ``` Save and close the file, then start the Apache service and enable it to start after system reboot: ``` systemctl start httpd systemctl enable httpd ``` Next, copy the sample **index.html** page to the Apache default document root directory: ``` cp /usr/share/httpd/noindex/index.html.en-US /var/www/html/index.html ``` **Note:** If you are using Virtual hosting, then configure the relevant configuration file. ## Step 3 – Configure Varnish to Work with Apache By default, Varnish is configured to listen on port 6081, so you will need to configure it to listen on port 80. You can configure it by editing varnish.service configuration file: ``` nano /usr/lib/systemd/system/varnish.service ``` Find the following line: ``` ExecStart=/usr/sbin/varnishd -a :6081 -f /etc/varnish/default.vcl -s malloc,256m ``` And replace it with the following line: ``` ExecStart=/usr/sbin/varnishd -a :80 -f/etc/varnish/default.vcl -s malloc,256m ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, restart Varnish service to apply the changes: ``` systemctl restart varnish ``` ## Step 4 – Configure Apache as a Backend Server for Varnish Next, you will need to configure Apache as a backend server for the Varnish proxy. You can configure it by editing the file /etc/varnish/default.vcl: ``` nano /etc/varnish/default.vcl ``` Uncomment the following lines **if commented**: ``` backend default { .host = "127.0.0.1"; .port = "8080"; } ``` Save and close the file when you are finished. **Note:** Change the line 127.0.0.1 with your Apache server IP address if your Apache server resides on the other host. Change the port 8080 with a port number of your Apache server. ## Step 5 – Verify Varnish Cache At this point, the Varnish cache is configured to work with the Apache webserver. It’s time to test whether caching is working or not. You can test it using the curl command: ``` curl -I http://your-server-ip ``` You should get the HTTP header information in the following output: ![](https://www.atlantic.net/wp-content/uploads/2021/01/varnish3.png) Next, run the command again: ``` curl -I http://your-server-ip ``` You should get the Varnish cached response in the Age header: ![](https://www.atlantic.net/wp-content/uploads/2021/01/varnish4.png) You can also test the varnish cache using varnishlog command with curl command to view Varnish activity as it happens: ``` varnishlog ``` You should get an output similar to the following: ![](https://www.atlantic.net/wp-content/uploads/2021/01/varnish5.png) ## Conclusion Congratulations! You have successfully installed and configured Varnish cache with Apache web server on CentOS 8. Your website should now load faster because Varnish will retrieve the most frequently requested content from the cache memory. Try out Varnish on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install TimescaleDB on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-timescaledb-on-ubuntu-20-04/ | Published: 2021-01-28 | Updated: 2023-11-25 | Author: Hitesh Jethva TimescaleDB is a free, open-source, powerful database system powered by PostgreSQL. It is an extension of PostgreSQL and is specially designed to analyze time-series data with PostgreSQL. TimescaleDB is very similar to PostgreSQL, but it is optimized for speed and scale. Generally, relational databases are mainly used to store data, and they cannot handle the large volumes of time series data. This where TimescaleDB excels; it combines the speed of NoSQL databases and the ease-of-use of relational databases. In this tutorial, we will show you how to install and use TimescaleDB on Ubuntu 20.04. ## Step 1 – Install PostgreSQL Database First, you will need to install a PostgreSQL server in your server. By default, it is available in the Ubuntu standard repository. You can install it easily using the following command: ``` apt-get install postgresql postgresql-contrib -y ``` Once the installation is completed, log in to PostgreSQL and set the postgres password: ``` su - postgres psql -c "alter user postgres with password 'password'" ``` Next, exit from the PostgreSQL shell with the following command: ``` exit ``` ## Step 2 – Install TimescaleDB By default, TimescaleDB is not available in the Ubuntu 20.04 default repository, so you will need to add the repository for it. First, install all the required dependencies with the following command: ``` apt-get install gnupg2 software-properties-common curl git unzip -y ``` Once all the dependencies are installed, add the TimescaleDB repository with the following command: ``` add-apt-repository ppa:timescale/timescaledb-ppa -y ``` Next, install TimescaleDB by running the following command: ``` apt-get install timescaledb-postgresql-12 -y ``` Once the TimescaleDB is installed, it is recommended to tune some desired configurations. You can do it with the following command: ``` timescaledb-tune --quiet --yes ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2021/01/timescale1.png) Next, restart the PostgreSQL service to apply the configuration changes: ``` systemctl restart postgresql ``` ## Step 3 – Create a New Database and Enable TimescaleDB In this section, we will create a new database, enable TimescaleDB, and connect the database to it. First, log in to the PostgreSQL shell and create a new database named testdb with the following command: ``` su - postgres psql CREATE DATABASE testdb; ``` Next, change the database to testdb and connect it to the TimescaleDB with the following command: ``` \c testdb CREATE EXTENSION IF NOT EXISTS timescaledb CASCADE; ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2021/01/timescale2.png) The time-series data are hypertables which consist of many individual tables. We will create a regular SQL table and then convert it into a hypertable via the function create_hypertable. First, create a table to store temperature and humidity information. ``` CREATE TABLE conditions ( time        TIMESTAMP WITH TIME ZONE NOT NULL, device_id   TEXT, temperature  NUMERIC, humidity     NUMERIC ); ``` Next, transform your table into a hypertable with the following command: ``` SELECT create_hypertable('conditions', 'time'); ``` Next, insert some data into the hypertable with the following command: ``` INSERT INTO conditions(time, device_id, temperature, humidity) VALUES (NOW(), 'weather-pro-000000', 84.1, 84.1); ``` Next, insert multiple rows of data with the following command: ``` INSERT INTO conditions VALUES (NOW(), 'weather-pro-000002', 71.0, 51.0), (NOW(), 'weather-pro-000003', 70.5, 50.5), (NOW(), 'weather-pro-000004', 70.0, 50.2); ``` You can now verify your inserted data with the following command: ``` INSERT INTO conditions VALUES (NOW(), 'weather-pro-000002', 70.1, 50.1) RETURNING *; ``` You should get the following output: ``` time              |     device_id      | temperature | humidity -------------------------------+--------------------+-------------+---------- 2020-12-03 15:48:24.329461+00 | weather-pro-000002 |        70.1 |     50.1 (1 row) INSERT 0 1 ``` You can also delete data from the hypertable using the following command: ``` DELETE FROM conditions WHERE temperature > 80; ``` Once the data is deleted, you can run the VACUUM command to reclaim space still used by data that has been deleted. ``` VACUUM conditions; ``` ## Conclusion Congratulations! You have successfully installed and configured TimescaleDB on Ubuntu 20.04. You can now use TimescaleDB for storing time-series data and use those data to create graphs. Get started with TimescaleDB on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Upgrade Ubuntu 18.04 to Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-upgrade-ubuntu-18-04-to-ubuntu-20-04/ | Published: 2021-01-29 | Updated: 2023-11-18 | Author: Hitesh Jethva The stable version of Ubuntu 20.04 Focal Fossa was released on April 23, 2020. This version is the latest Long-Term Support (LTS) release with security patches and updates available until 2025. If you are using an older version of Ubuntu, you must upgrade it to the latest version as Ubuntu 20.04 introduced some important fea­­tures. Some of them are listed below: - Fast boot process - Linux Kernel version 5.4 - Ships with GNOME 3.36 - Modified login screen - Ships with PHP7.4, Ruby 2.7, Python 3.8 and OpenJDK 11 - Improved ZFS file system with native encryption In this tutorial, we will explain how to upgrade Ubuntu. ## Step 1 – Verify Current Ubuntu Version Before starting, we recommend that you create a backup of applications, databases, and other important files. Next, verify your existing Ubuntu Version by running the following command: ``` cat /etc/lsb-release ``` You should see the following output: ![](https://www.atlantic.net/wp-content/uploads/2021/01/ubuntu18.041.png) Next, update all installed packages in your system with the following command: ``` apt-get update -y apt-get upgrade -y apt-get dist-upgrade -y ``` The process will take several minutes to complete. Once your system is up to date, restart it to apply all the changes: ``` reboot ``` Once you are finished, you can proceed to the next step. ## Step 2 – Remove Unused Packages Next, it is a good idea to remove unnecessary packages in your system to free up the space. You can do it with the following command: ``` apt-get --purge autoremove ``` Next, you will need to install the Update Manager package in your system, as it is frequently not installed in server operating systems. You can install it with the following command: ``` apt-get install update-manager-core -y ``` Once the installation is completed, you can proceed to the next step. ## Step 3 – Upgrade Ubuntu 18.04 to Ubuntu 20.04 At this point, your system is ready for upgrade. Now, run the following command to display whether new 20.04 LTS version is available for your system: ``` do-release-upgrade ``` You should see that there is no development version of an LTS available: ``` Checking for a new Ubuntu release There is no development version of an LTS available. To upgrade to the latest non-LTS develoment release set Prompt=normal in /etc/update-manager/release-upgrades. ``` You can now use the -d option to get the latest supported release forcefully and start the upgrade process: ``` do-release-upgrade -d ``` During the upgrade process, you will be prompted to type **y** or hit **Enter** to confirm as shown below: ``` Reading cache Checking package manager Continue running under SSH? This session appears to be running under ssh. It is not recommended to perform an upgrade over ssh currently because in case of failure it is harder to recover. If you continue, an additional ssh daemon will be started at port '1022'. Do you want to continue? Continue [yN] y Starting additional sshd To make recovery in case of failure easier, an additional sshd will be started on port '1022'. If anything goes wrong with the running ssh you can still connect to the additional one. If you run a firewall, you may need to temporarily open this port. As this is potentially dangerous it's not done automatically. You can open the port with e.g.: 'iptables -I INPUT -p tcp --dport 1022 -j ACCEPT' To continue please press [ENTER] ``` Once the process has been completed successfully, you will be asked to select **y** to restart your system as shown below: ``` System upgrade is complete. Restart required To finish the upgrade, a restart is required. If you select 'y' the system will be restarted. Continue [yN] y ``` Type **y** and hit **Enter** to restart your system. ## Step 4 – Verify Upgrade After rebooting the system, run the following command to verify the Ubuntu version: ``` cat /etc/lsb-release ``` You should see Ubuntu 20.04 LTS in the following output: ``` DISTRIB_ID=Ubuntu DISTRIB_RELEASE=20.04 DISTRIB_CODENAME=focal DISTRIB_DESCRIPTION="Ubuntu 20.04 LTS" ``` ## Conclusion In the above guide, you learned how to upgrade Ubuntu 18.04 LTS to Ubuntu 20.04 LTS. Upgrade your Ubuntu 18.04 [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # How to Install XWiki on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-xwiki-on-ubuntu-20-04/ | Published: 2021-02-01 | Updated: 2023-11-25 | Author: Hitesh Jethva XWiki is a simple, lightweight, powerful wiki platform that allows you to customize the wiki to your specific needs. It is written in Java and runs on servlet containers like JBoss or Tomcat. XWiki provides a simple and user-friendly web interface that helps you create and manage your content from any device and browser. It comes with a rich set of features including WYSIWYG editing, OpenDocument-based document import/export, tagging, version control, powerful wiki syntax, advanced search functionality and many more. In this tutorial, we will show you how to install XWiki on Ubuntu 20.04. ## Step 1 – Install Java XWiki is written in Java, so you will need to install Java in your system. You can install Java using the following command: ``` apt-get install default-jdk gnupg2 -y ``` Once Java is installed, you can verify the Java version with the following command: ``` java --version ``` You should get the following output: ``` openjdk 11.0.9.1 2020-11-04 OpenJDK Runtime Environment (build 11.0.9.1+1-Ubuntu-0ubuntu1.20.04) OpenJDK 64-Bit Server VM (build 11.0.9.1+1-Ubuntu-0ubuntu1.20.04, mixed mode, sharing) ``` ## Step 2 – Install XWiki By default, XWiki is not available in the Ubuntu 20.04 default repository, so you will need to add the XWiki official repository to your system. First, add the GPG key with the following command: ``` wget -q "https://maven.xwiki.org/public.gpg" -O- | apt-key add - ``` Next, add the XWiki repository with the following command: ``` wget "https://maven.xwiki.org/stable/xwiki-stable.list" -P /etc/apt/sources.list.d/ ``` Next, update the repository with the following command: ``` apt-get update -y ``` Once the repository is updated, you can install XWiki by running the following command: ``` apt-get install xwiki-tomcat9-common xwiki-tomcat9-mariadb -y ``` During the installation, you will be asked to configure a database for XWiki as shown below: ![](https://www.atlantic.net/wp-content/uploads/2021/01/xwiki1.png) Select **yes** and hit **Enter**. You will need to set a password for the xwiki database as shown below: ![](https://www.atlantic.net/wp-content/uploads/2021/01/xwiki2.png) Provide your desired password and hit **Enter** to finish the installation. After installing XWiki, you can verify the Tomcat service using the following command: ``` systemctl status tomcat9.service ``` You should get the following output: - ``` tomcat9.service - Apache Tomcat 9 Web Application Server ``` ``` Loaded: loaded (/lib/systemd/system/tomcat9.service; enabled; vendor preset: enabled) Drop-In: /etc/systemd/system/tomcat9.service.d └─xwiki-tomcat9-systemd.conf Active: active (running) since Wed 2020-11-18 10:27:27 UTC; 1min 42s ago Docs: https://tomcat.apache.org/tomcat-9.0-doc/index.html Main PID: 39480 (java) Tasks: 52 (limit: 2353) Memory: 524.9M CGroup: /system.slice/tomcat9.service └─39480 /usr/lib/jvm/default-java/bin/java - Djava.util.logging.config.file=/var/lib/tomcat9/conf/logging.properties -Djava.util.l> Nov 18 10:27:44 server tomcat9[39480]: 2020-11-18 10:27:44,176 [main] WARN  o.e.j.u.s.S.config             - No Client EndPointIdentificationA> Nov 18 10:27:44 server tomcat9[39480]: 2020-11-18 10:27:44,202 [main] WARN  o.a.s.c.CoreContainer          - Not all security plugins configur> Nov 18 10:27:47 server tomcat9[39480]: 2020-11-18 10:27:47,618 [main] INFO  o.x.s.s.i.EmbeddedSolr         - Started embedded Solr server. Nov 18 10:27:52 server tomcat9[39480]: 2020-11-18 10:27:52,832 [main] INFO  o.x.s.f.i.FilesystemStoreTools - Using filesystem store directory > Nov 18 10:27:54 server tomcat9[39480]: Deployment of deployment descriptor [/etc/tomcat9/Catalina/localhost/xwiki.xml] has finished in [24,889> Nov 18 10:27:54 server tomcat9[39480]: Deploying web application directory [/var/lib/tomcat9/webapps/ROOT] Nov 18 10:27:55 server tomcat9[39480]: At least one JAR was scanned for TLDs yet contained no TLDs. Enable debug logging for this logger for a> Nov 18 10:27:55 server tomcat9[39480]: Deployment of web application directory [/var/lib/tomcat9/webapps/ROOT] has finished in [926] ms Nov 18 10:27:55 server tomcat9[39480]: Starting ProtocolHandler ["http-nio-8080"] Nov 18 10:27:55 server tomcat9[39480]: Server startup in [25,998] milliseconds ``` By default, Tomcat is listening on port 8080. You can check it with the following command: ``` ss -antpl | grep 8080 ``` You should get the following output: ``` LISTEN    0         100                      *:8080                   *:*        users:(("java",pid=39480,fd=39)) ``` ## Step 3 – Configure Nginx for XWiki Next, you will need to install and configure Nginx as a reverse proxy to access the XWiki. First, install the Nginx webserver with the following command: ``` apt-get install nginx -y ``` Once installed, create a new Nginx virtual host configuration file using the following command: ``` nano /etc/nginx/sites-available/xwiki.conf ``` Add the following lines: ``` server { listen 80; server_name xwiki.example.com; access_log /var/log/nginx/xwiki-access.log; error_log /var/log/nginx/xwiki-error.log; location / { proxy_set_header   X-Real-IP $remote_addr; proxy_set_header   Host      $host; proxy_http_version 1.1; proxy_set_header   Upgrade $http_upgrade; proxy_set_header   Connection 'upgrade'; proxy_cache_bypass $http_upgrade; proxy_pass         http://127.0.0.1:8080; } } ``` Save and close the file then activate the Nginx virtual host with the following command: ``` ln -s /etc/nginx/sites-available/xwiki.conf /etc/nginx/sites-enabled/ ``` Next, you will need to edit the Nginx main configuration file and increase the hash_bucket size: ``` nano /etc/nginx/nginx.conf ``` Add the following line below http {: ``` server_names_hash_bucket_size 64; ``` Save and close the file then restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 4 – Access XWiki Web UI Now, open your web browser and access the XWiki web interface using the URL **http://xwiki.example.com/xwiki**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/xwiki3.png) Click on the **Continue** button. You should see the admin user creation page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/xwiki4.png) Provide your username, password, and email and click on the **Register** **and** **Login** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/xwiki5.png) Click on the **Continue** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/xwiki7.png) Select your flavor and click on the **Install** button. Once the installation has been finished, you should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/xwiki8.png) Click on the **Continue** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/xwiki9.png) Click on the **Continue** button. You should see the XWiki default dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/xwiki10.png) ## Conclusion Congratulations! You have successfully installed and configured XWiki on Ubuntu 20.04. You can now easily deploy your own XWiki in the production environment. Try XWiki on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Install Zulip Chat Server on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/install-zulip-chat-server-on-ubuntu-20-04/ | Published: 2021-02-02 | Updated: 2023-11-25 | Author: Hitesh Jethva Zulip is a free and open-source chat application used for sharing private and public messages. It is very similar to Slack, written in Python, and uses the Django framework. Zulip is a cross-platform software tool able to handle thousands of concurrent chat sessions. It can be integrated with GitHub, Jira, Stripe, Sentry, and more using third-party plugins. Zulip offers a rich set of features including private messaging, group chats, drag-and-drop file uploads, Emoji, audible notifications, missed-message emails, and more. In this tutorial, we will show you how to install a Zulip chat server on Ubuntu 20.04. ## Prerequisites - A fresh Ubuntu 20.04 [VPS](https://www.atlantic.net/vps-hosting/) - A valid domain pointed to your server IP - A root password configured on your server ## Step 1 – Download Zulip First, you will need to download the latest version of Zulip from its official website. You can download it with the following command: ``` wget https://www.zulip.org/dist/releases/zulip-server-latest.tar.gz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar -xvzf zulip-server-latest.tar.gz ``` Once the downloaded file is extracted, you can proceed to the next step. ## Step 2 – Install Zulip Server You can start the Zulip installation by specifying your valid email address and an FQDN as shown below: ``` ./zulip-server-3.1/scripts/setup/install --certbot --email=admin@example.com -- hostname=zulip.example.com ``` Once the Zulip server is installed successfully, you should get the following output along with Zulip URL: ``` + '[' -e /var/run/supervisor.sock ']' + supervisorctl restart all zulip-django: started zulip-tornado: started process-fts-updates: started zulip-workers:zulip_events_deferred_work: started zulip-workers:zulip_events_digest_emails: started zulip-workers:zulip_events_email_mirror: started zulip-workers:zulip_events_embed_links: started zulip-workers:zulip_events_embedded_bots: started zulip-workers:zulip_events_error_reports: started zulip-workers:zulip_events_invites: started zulip-workers:zulip_events_email_senders: started zulip-workers:zulip_events_missedmessage_emails: started zulip-workers:zulip_events_missedmessage_mobile_notifications: started zulip-workers:zulip_events_outgoing_webhooks: started zulip-workers:zulip_events_signups: started zulip-workers:zulip_events_user_activity: started zulip-workers:zulip_events_user_activity_interval: started zulip-workers:zulip_events_user_presence: started zulip-workers:zulip_deliver_enqueued_emails: started zulip-workers:zulip_deliver_scheduled_messages: started + set +x + su zulip -c '/home/zulip/deployments/current/manage.py generate_realm_creation_link' Please visit the following secure single-use link to register your new Zulip organization: https://zulip.example.com/new/mmlbpkhig2hnl5kpkzz6hot1 ``` ## Step 3 – Access Zulip Web Interface Now, open your web browser and type the URL from the above output https://zulip.example.com/new/mmlbpkhig2hnl5kpkzz6hot1. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/zulip1.png) Provide your email address and click on the **Create** **organization** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/zulip2.png) ![](https://www.atlantic.net/wp-content/uploads/2021/01/zulip3.png) Provide your Organization name, URL, admin username, and password and click on the **Login** button. You will be redirected to the Zulip dashboard as shown below: ![](https://www.atlantic.net/wp-content/uploads/2021/01/zulip4.png) ## Conclusion Congratulations! You have successfully installed Zulip chat server with Let’s Encrypt SSL on Ubuntu 20.04. If you’re looking for a simple and cost-effective replacement for Slack or Microsoft Teams then the Zulip chat server is the right choice for you – get started with Zulip on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Why cPanel Is the Best Solution for Website Designers > URL: https://www.atlantic.net/vps-hosting/why-cpanel-is-the-best-solution-for-website-designers/ | Published: 2021-02-03 | Updated: 2026-03-04 | Author: Alexander Wise Linux-based website hosting is popular due to its nonexistent-to-low price and high degree of security. Linux supports multiple control panel software applications that facilitate customer website design. Let’s take a close look at the most popular solution available today, cPanel, and see why it’s the best choice for website designers. ## What Is cPanel/WHM? The most popular Linux-based control panel software is aptly named cPanel. You will often see it referenced in combination with WHM (Web Host Manager) as a website management solution. These two tools perform complementary functions related to the management of websites or cloud servers. cPanel is control panel software accessed by end-users to manage a Linux hosting service, such as for a website. It features a simple and intuitive GUI that provides a powerful platform for performing many website administrative and management tasks. We will get deeper into its details shortly, but for now, let’s just say it’s the front end of the cPanel/WHM tandem. WHM is used to create and manage cPanel accounts, and frequently resellers use WHM to manage their customers’ hosting accounts. Administrators using the WHM interface have root-level access to resources, whereas cPanel provides access to a customer’s hosting account. ## cPanel Features and Benefits cPanel has become a popular solution for managing virtual private server (VPS) hosted websites and servers due to several features that directly address the needs of the user community. The tool offers complete control over a website or server for both experienced professionals and non-technical users just beginning to explore the possibilities of the web. What follows are some of the main characteristics that make cPanel so popular for [VPS hosting](https://www.atlantic.net/vps-hosting/) and an explanation of why it should be the first choice of website designers. ### Simplicity No matter what level of technical expertise you enjoy, it’s always preferable to use a simple solution when one exists. cPanel’s user interface enables many website management activities to be accomplished by simply pointing and clicking. Both basic and complex tasks can be performed through the GUI with a few clicks. Documentation and built-in tutorials that help guide non-technical users through all cPanel operations are easily accessible. The cPanel interface enables users to fully manage their website without requiring them to possess any level of technical skills. Many website designers are not computer experts. They have decided to build an online presence to further business or personal interests and greatly benefit from using the simple and intuitive cPanel interface. By eliminating the technical impediments to website management, cPanel allows users to focus on designing interesting sites and managing them efficiently. Rather than getting bogged down investigating the syntax of some arcane command, designers can concentrate on the aspects of their website that appeal to users, drive traffic, and increase engagement. ### Scalability Another outstanding feature of cPanel is its ability to allow entities such as marketing agencies to manage multiple clients on a single VPS. With cPanel, it’s easy to manage multiple domains on the same VPS. Client email lists and files can be segregated and managed efficiently from cPanel’s intuitive interface. Once again, cPanel enables users to focus on what they want to do rather than on the technical details of how to get things done. ### Flexibility If the basic features of cPanel are not sufficient, [multiple extensions](https://cpanel.net/extensions/) allow users to easily augment their systems. Offerings like WordPress management tools, billing systems, customizable backup applications, and security solutions can quickly be added. Easy installation capabilities with Atlantic.Net’s One-Click Apps let you add software with just a few clicks. ### Compatibility cPanel is compatible with all web browsers including Google Chrome, Safari, Firefox, Microsoft Edge, Opera, and Internet Explorer. It is also compatible with many third-party add-ons and applications that extend website functionality. This adds to the degree of creativity that can be exercised by website designers using cPanel. ### Customization Through cPanel extensions and third-party compatibility, there is no limit to the degree of customization that can be achieved by website designers. CMS solutions like Joomla, Drupal, or WordPress can be added simply and easily. Resellers can take advantage of cPanel customization for enhanced branding and improving [logo design](https://blog.designcrowd.com/article/1898/7-tips-to-keep-in-mind-while-designing-a-brand-logo) and brand colors to promote their business. ### Database Management Databases are an essential component of most useful websites. They are a requirement for any site that intends to be more than a bulletin board. Database creation and management can be done with cPanel. Multiple database platforms are supported by cPanel, with the two most popular being MySQL and PostgreSQL. ### Email Management A primary objective of many website owners is retaining visitors once they have attracted them to their sites. Another is communicating with visitors who have expressed interest in the website’s offering. Email is perfect for both tasks and is easily managed with cPanel. Users can easily create or delete email accounts and customize emails to reflect their brand. ### Backup and Recovery cPanel provides flexible backup and recovery functionality that enables users to protect their information. You can back up full cPanel accounts and use the media to restore them on different servers. This includes all of the account files, databases, email accounts, and settings. ### Conclusion As this list demonstrates, cPanel offers website designers an intuitive platform from which to manage all aspects of their sites. It removes most of the technical impediments that stand in the way of an average user running a superb website. ## [Atlantic.Net](https://www.atlantic.net)‘s cPanel Offerings As a [VPS provider](https://www.atlantic.net/vps-hosting/), Atlantic.Net offers its customers flexible hosting options. Atlantic’s Cloud VPS offerings provide users with the choice to host on a VPS with or without cPanel. It is a fully integrated solution that enables users to only pay for what they need. You can easily add cPanel as one of Atlantic.Net’s One-Click Apps, rather than taking the hour or so normally spent on manual installation. Atlantic’s combination of cost-efficient Linux VPS solutions and a cPanel license gives website designers the perfect platform for building engaging sites. You can tailor the size of the hosting solution to meet your business requirements and avoid paying for unnecessary capacity. The addition of cPanel lets users of all levels of technical proficiency efficiently manage their websites. --- # What’s the Best VPS: Windows or Linux? > URL: https://www.atlantic.net/vps-hosting/whats-the-best-vps-windows-or-linux/ | Published: 2021-02-04 | Updated: 2025-09-19 | Author: Alexander Wise A [Virtual Private Server (VPS)](https://www.atlantic.net/vps-hosting/) is a popular choice for organizations in need of web hosting as it provides an economical and secure platform from which to run their applications, for example, a business or e-commerce website. In this article, we are going to look at why a VPS makes sense for businesses of any size and how to choose the operating system used by your virtual server. ## Why Choose a VPS? There are three basic choices when engaging hosting services for a website or web-based application. Depending on the security and performance requirements and the organization’s budget constraints, an enterprise might choose one of the following options: - **Dedicated Physical Server** – Dedicated server hosting provides the greatest control and customization. Customers self-manage or pay for the management of an entire server that is housed in a provider’s data center. The increased control over the hosting environment comes with a price. Using a dedicated physical server is the most expensive of the three options. It can provide a secure environment when configured correctly but relies on the customer to implement this security or pay a service provider for those services. - **Shared Hosting** – In a shared hosting environment, multiple customers have access to the same physical server. They share the server resources such as the storage space, memory, and CPU power. A shared hosting option is the least expensive alternative but provides limited customization. The possibility exists that performance may be impacted by other customers sharing the server. You may also be limited as to the software you can install making it difficult to achieve business goals or utilize certain software packages. - **Virtual Private Server** – A virtual private server, also known as a cloud server, gives users additional benefits to those provided by a dedicated physical server at a lower cost. It builds on the concept of shared hosting; however, hosting multiple virtual servers on a physical machine offers customers more fine-grained control and less interference from the other occupants. It is a secure, scalable, customizable, and economical alternative that can fit the needs of many customers. Using a VPS eliminates the resource limitations enforced in a shared hosting scenario. Selecting a VPS is a wise decision for organizations or individuals who desire the security and customization of a dedicated server at a reduced cost. In addition to providing a secure and customizable platform for their websites and applications, the virtual nature of a VPS makes it more flexible than a physical server. Resources can be scaled to allow customers to use exactly what they need and easily address variable usage patterns. At Atlantic.Net, if you are utilizing a VPS but your business’ growth requires a dedicated server for compliance or other business reasons, then you have the option to live-migrate your VPS to your own private Dedicated Host in the cloud.  This means no downtime for you or your business, providing an easy path to upgrade your VPS and scale your online presence as needed. A VPS combines the best features of the dedicated and shared hosting models. Once the choice has been made to go with a virtual private server, the next decision customers must make is whether to choose a VPS that uses the Windows or Linux operating system. ## Choosing the Operating System for Your VPS While other operating systems are available for virtual hosting, we will focus on Windows and Linux. Both operating systems can provide reliable functionality for websites and applications, but some significant differences may make one more attractive to some customers. Below, we compare the characteristics of the two platforms to differentiate the two choices and help you select the one that works best for your situation. ### Cost As an open-source solution, Linux can initially be a less expensive solution. Some Linux distributions have no licensing fees, unlike Microsoft Windows Server. This is a major difference between the two solutions and may be enough to sway customers who are primarily concerned with budgetary constraints. Other concerns may impact the final decision, but Linux is a less expensive alternative out of the box when only considering licensing. ### Performance If performance and extended uptime is a primary concern, Linux may be a better choice in an operating system. Linux provides more opportunities for server optimization and has less intensive hardware requirements. Windows servers require more frequent reboots, which impact system availability, and need to be restarted after patching. The Windows GUI can expend unnecessary resources if not correctly configured and optimized. Optionally, the Windows GUI can be disabled in favor of PowerShell to reduce resource usage, but this is not a common solution for most.  When it comes to utilizing server resources, Linux is still considered the performance king, but Microsoft is continually pursuing improvements. ### Compatibility The software tools and packages that you plan to use on the VPS can be the determining factor in making the selection. If you are working with Microsoft-centric products a Windows VPS will provide a better and, in some cases, the only solution. A Linux VPS will be better suited for users who are comfortable with Linux-specific software. You need to perform a thorough review of the products you will use and ensure they are compatible with the operating system you select.  Additionally, you will need to ensure that your OS is supported by your provider. For Windows and Linux, earlier versions may be “end of life” (EOL) operating systems, meaning they are no longer supported.  This means that patching, security fixes, bug fixes, etc. will no longer be provided from the manufacturer. ### Control Panel The control panel used to manage and customize your website differs based on the chosen OS platform. Linux systems use cPanel or Web Host Manager (WHM). On a Windows VPS, these will be replaced by Plesk. Familiarity with one of these control panel solutions may influence the choice of operating system to host your VPS.  While an administrator could install either software package on the other operating system, the issues and work involved are not considered worthwhile.  If you require a control panel, selecting your OS first is a great place to start. ### Security The security of web-based applications is a critically important consideration when choosing its hosting platform. Due to its incredible popularity, Windows is a prime target of hackers looking to compromise enterprise IT resources. Malicious actors also attempt to subvert Linux security but are generally less successful. Linux was designed with strong security in mind and the user community works to maintain it as a safe choice in operating systems. If security is your primary concern, and you are comfortable working with the OS, you may want to go with a Linux solution. It is important to remember that proper configuration and patch management are necessary to maintain security in any operating system platform, so if you do not understand how to properly secure your Linux server, purchasing managed services or instead opting for a Windows Server and additional software to cover your needs will be the best routes for you and your team. ### Ease of Use A Windows VPS provides a more user-friendly interface that features its well-known graphical user interface (GUI). Even with the addition of management tools such as cPanel, a Linux VPS requires a higher degree of technical knowledge than a Windows solution. Thus, the users who will interact with the system may be a deciding factor in the operating system choice. In general, a Windows VPS is easier to use than a Linux alternative. A GUI can be added to some Linux distributions to remove the need to work with a command-line interface; however, most server-based GUIs will use additional resources and can introduce additional security concerns which negate some of the advantages Linux offers over Windows. ### Technical Support One of the most apparent benefits of going with a Windows solution is the technical support available from Microsoft and Microsoft certified partners. Windows is the most widely used commercial operating system in the world, and the company offers extensive support options that can be used by its customers. Organizations that are more comfortable with a corporate-backed OS solution will favor running their VPS on the Windows platform. Over the past decade, however, operating systems like Red Hat Linux, Ubuntu, and others have begun to provide paid support, though engaging that paid support can bring you closer the costs of Windows Server. Technical support for many Linux distributions is provided by the large user community associated with the solution free of charge.  However, that old saying “you get what you pay for” holds true.  Volunteer-provided Linux support will not help you through your issues if the user base does not want to. There are no contracts, service level agreements, or anything to guarantee your issue will be resolved. This should be a key factor in your decision if you or your team do not possess the technical skills needed to overcome issues. ## Conclusion Specific aspects of implementing a Linux or Windows VPS can pose contradictions that customers must resolve when making their decision on which OS to employ. You might want to take the least expensive route, which generally means a Linux solution, but be skeptical of your ability to handle its technical challenges. While a Windows-based VPS may enable your team to work in a familiar setting, security concerns may cause you to opt for a hardened Linux installation. As with many decisions in life, you need to strike the proper balance to be successful. [Atlantic.Net](https://www.atlantic.net/managed-services/) also offers managed services to help enterprises reach their IT objectives. With over 20 years of experience, their technical team ensures you have the best support available. Offerings include managed server hosting as well as a fully Managed Firewall, Intrusion Prevention Service, patch management, vulnerability scans, multi-factor authentication, onsite and offsite backups, replication, and more.  Managed services are a perfect solution for customers who want to use a Linux platform but do not have the required technical expertise in-house as they can help cover the gaps you have in your IT knowledge base. You can choose from a variety of Windows Server variants and Linux distributions. Windows Server users can select to host their VPS using Windows Server 2008, Windows Server 2012, Windows Server 2016, or Windows Server 2019. A wide range of Linux flavors are available with users able to use Ubuntu, Debian, CentOS, Fedora, or Arch Linux. FreeBSD Unix VPS options are also available. Atlantic.Net also has One-Click Apps to help take some of the work out of a Linux deployment.  Our most popular One-Click Apps include cPanel, WordPress, LAMP stacks, and LEMP stacks. Atlantic.Net can meet your requirements for a VPS with either Linux or Windows solutions. We offer Windows or Linux VPS hosting in the cloud powered by enterprise-grade solid-state drives and backed by an experienced technical support team that is available 24x7x365. Virtual private servers built on multiple Linux distributions and a wide range of hosting options are available. Atlantic.Net can tailor a [VPS solution](https://www.atlantic.net/vps-hosting/) that gives you the features your application needs with straightforward and competitive pricing. Found out more by contacting Atlantic.Net today. --- # Applied Cloud Computing in Higher Education > URL: https://www.atlantic.net/life-sciences-pharma-biotech/applied-cloud-computing-in-higher-education/ | Published: 2021-02-05 | Updated: 2026-09-15 | Author: Dr. Rachael Bailey The current global pandemic has made it essential for educational institutions to fully embrace the power of the cloud. University professors and researchers are turning to cloud-based technologies to provide and maintain their online resources and, as the benefits of cloud computing align perfectly with the key priorities of the higher education sector, this transition is unsurprising. So, how can cloud computing deliver a vital academic solution? ## Benefits of Cloud Computing for Academic Research Scientific research demands fast and intense compute power, flexible turn-key solutions, and the resources to store vast data volumes. What are the key benefits of leveraging the power of the cloud in academic research? **Turn-key flexible terms** Academic research teams generally seek a one-stop-shop computing platform that enables them to get up and running immediately. Cloud providers can deliver a turn-key solution with flexible terms to ensure maximum performance while saving time and money. Implementing a managed service ensures that an institution deploys a highly effective and secure IT infrastructure that is routinely maintained and updated. **Set Pricing** When working within academic research, funds can be restrictive and must be spent wisely. When choosing a managed service provider, lead researchers may wish to consider cloud providers that offer their clients fixed pricing or subscription model. Under this type of model, the client is charged a set fee for a specific number of service units. This is much easier to understand than [dynamic pricing](https://dealhub.io/glossary/dynamic-pricing/) structures and can be seamlessly factored into a grant proposal. **Communication and Collaboration** The year 2020 has highlighted how essential collaboration is when we seek to drive scientific innovation and discovery. Global collaboration has led to the successful discovery and approval of several COVID-19 vaccines and therapies. Cloud-based technologies support a collaborative research environment, allowing data and resources to be securely shared, anywhere and at any time. **Scalability** By providing flexible scalability, cloud-based technologies allow researchers to meet the computing demands of working with large data sets. Whether your research involves highly complicated computations or complex run models, cloud computing delivers the flexibility and elasticity required to efficiently match computing power to demand. **Innovation and Agility** The cloud can improve both the quality and quantity of scientific research, helping to drive novel scientific discoveries. Scientists are now able to do what was once impossible, analyzing vast datasets to discover exciting patterns and correlations. By leveraging the power of cloud technology and AI/machine learning, scientists can even identify new and exciting areas of research. ## Benefits of Employing Cloud Technology in a Higher Education Setting **Accessibility** The cloud enables students and staff to access online lessons, coursework, digital textbooks, and journals remotely. This makes online content more accessible and helps to enhance productivity. Higher education often requires the use of specialized hardware and software that can be expensive to purchase. Cloud technology allows individual terminals to access shared resources remotely, from anywhere with internet access. This content and infrastructure can be accessed 24/7. **Security** When employing cloud-based services within a higher education setting, robust security is essential. Data safety and privacy and intellectual property are key concerns for university professors and researchers who must consider relevant federal regulations, such as FERPA, HIPAA, HITECH, and COPPA, and opt for a cloud provider that can ensure full compliance with these standards. **Scalability** Cloud computing enables a university professor or researcher’s infrastructure to be highly and dynamically scalable. On-demand scalability allows professors to quickly and efficiently expand their compute and storage capabilities in response to the traffic spikes and usage peaks that are inevitable given the vast amount of staff and students accessing services at any given time. It also enables academics who are engaged in research projects to offset intense workloads to the cloud, automating resource deployments using the power of cloud API’s, **Reduced infrastructure** Cloud technology significantly reduces physical hardware requirements, resulting in a significant cost saving. Just like utility companies, cloud providers enable university professors to only pay for the resources that they use, saving money and consolidating space. As space is often at a premium within universities, the elimination of on-premise servers allows valuable space to be utilized for more pressing needs. ## How Can Atlantic.Net Help? With over 30 years of experience, Atlantic.Net can deliver a turn-key solution that will fast-track [research and development](https://www.atlantic.net/life-sciences-pharma-biotech/) within your institution. If you are an educator or researcher looking for a managed service provider that can help to boost productivity, streamline your workload and accelerate time to science, then Atlantic.Net can help. By deploying our services, you can trust that your valuable data is safe and secure and that you remain fully compliant with the necessary regulations. Unlike Hyper-scale cloud providers, Atlantic.Net is willing and able to adjust our terms of service so that they can meet the requirements needed to be cleared by your legal team. [Contact the team today](https://www.atlantic.net/about-us/corporate-contact/) to see how Atlantic.Net can provide the powerful infrastructure needed to drive your education and research forwards. --- # Paying With PayPal > URL: https://www.atlantic.net/vps-hosting/paying-with-paypal/ | Published: 2021-02-16 | Updated: 2026-03-04 | Author: Richard Bailey ## Introduction Based on feedback we have received and to better serve our ever-growing customer base, we have introduced the ability for our customers to pay with PayPal. While paying online securely with credit/debit cards is commonplace, you can now enjoy paying with PayPal if you don’t want to pay with a credit/debit card, or simply prefer to pay in advance for your services. You can choose PayPal as a form of payment during or after signing up with Atlantic.Net. When you choose PayPal, you prepay an amount of your choosing which will be applied to your Atlantic.Net account as an ‘account credit’.  This account credit will then be applied to the invoices generated on your customer account. If the account credit is not sufficient to cover the total of your outstanding invoice, our systems will check if you also have a credit or debit card on file. If you do, the card will be charged for the remaining outstanding amount. You can view your remaining available credit on the Account page inside the Cloud Portal. Additionally, we will notify you if your account credit falls below 20% of what you deposited to give you an opportunity to add funds to your account before you have exhausted your remaining credit.   ## **What you will learn in this guide** How do I signup using PayPal as a method of payment? How do I use PayPal after signing up to add funds to my account? ## How do I signup using PayPal as a method of payment? You can choose PayPal as a form of payment during the second step of signup where you  are requested to provide ‘Billing information’. You can  choose the desired amount to preload ranging from $10 to $500 in the following set of choices: $10, $25, $50, $100, or $500. Additionally, you can choose to enter a custom amount.   ![](https://www.atlantic.net/wp-content/uploads/2021/02/paypal_signup_2.png)   Once you submit the information on ‘Billing Information’ page, you will be taken to the PayPal website to complete the payment. If you are not already logged into PayPal in your browser, you will be prompted to log into PayPal first. Note that you can use a PayPal account registered with a different email address than the one you are using to create your account with Atlantic.Net. ![](https://www.atlantic.net/wp-content/uploads/2021/02/paypal_signup_3-857x1024.png)   Once you log into PayPal, you will be requested to confirm the PayPal transaction.   ![](https://www.atlantic.net/wp-content/uploads/2021/02/paypal_signup_4-905x1024.png)   After you confirm the PayPal transaction, you will be brought back to the Atlantic.Net Cloud Signup page and you will see the confirmation that your account is currently undergoing verification.   ![](https://www.atlantic.net/wp-content/uploads/2021/02/paypal_signup_5-1024x528.png) ## How do I use PayPal after signing up to add funds to my account? Head over to your Atlantic.Net Control Panel at [cloud.atlantic.net](https://cloud.atlantic.net/?page=userlogin), login and then click on your email address in the top right and then click on ‘Account’. This  will bring you to the Account Info page. This page will help you use PayPal with your account as well as show you important information about your usage, the amount past due (if any), the amount of credit you have with us and how much of your credit has been used up based on your usage since the last statement. You can easily add a credit or debit card as a second form of payment even if you have chosen to use PayPal. ![](https://www.atlantic.net/wp-content/uploads/2021/02/paypal_account-1024x480.png)   You can click on the ‘Manage Cards / Make Payment’ button to bring up options that will allow you to update/view the credit/debit card you have on file with us or choose PayPal and the amount you wish to add to your account. If you choose PayPal, you can pick from the preset amounts to add or enter a custom amount you wish to add to your account, then click ‘Proceed to Pay with PayPal’. You will be taken to the PayPal website to complete the transaction. Once you complete the transaction, you will be sent back to the ‘Account Info’ page with the new credit correctly reflected. ![](https://www.atlantic.net/wp-content/uploads/2021/02/paypal_account-1.png)   You can view your PayPal history by clicking on the ‘PayPal Payment History’ button. ![](https://www.atlantic.net/wp-content/uploads/2021/02/paypal_history-1024x510.png)   Since PayPal is a prepaid type payment, a convenient feature called ‘Manage Billing Alerts’ is available to help you stay informed if your Atlantic.Net usage for the current billing cycle exceeds a chosen threshold. ![](https://www.atlantic.net/wp-content/uploads/2021/02/paypal_alerts-1024x371.png) ## FAQ **My PayPal account email address is different from my the email address I used to signup at Atlantic.Net. Can I still use that PayPal email address to pay for my services?** Yes. Your PayPal account email address that you use to pay for your services can be different from the email address you used to signup up with Atlantic.Net   **What is the minimum amount I can deposit into my account using PayPal?** $10.   **Can I use multiple PayPal accounts to pay for my services?** Yes. Feel free to use as many accounts as you like. However, only one account can be used per transaction.   --- # Atlantic.Net Expands the Free G3.2GB Promo in San Francisco Data Center > URL: https://www.atlantic.net/press-releases/atlantic-net-expands-the-free-g3-2gb-promo-in-san-francisco-data-center/ | Published: 2021-02-19 | Updated: 2024-06-11 | Author: Editorial Team **Free G3.2GB Cloud VPS Hosting is now available in California data center for one full year** **ORLANDO, FLA. (February 19, 2021)** – [Atlantic.Net](https://www.atlantic.net/), a leading cloud services provider, expanded their offer enabling new cloud VPS customers to double their server resources at no extra cost. Atlantic.Net will upgrade all cloud plans to the capabilities of the next highest price bracket at no additional cost for new customers at its San Francisco data center. This program also includes Atlantic.Net’s Free-to-Use for One Year Server promotion, meaning that any new free tier users will be automatically upgraded from 1GB to 2GB Cloud Server usage for one full year. “With this expansion, our Free-to-Use promotion is now available in five data centers for one full year,” said Marty Puranik, CEO and Founder of Atlantic.Net. “We are excited to continue to expand our services and happy to allow entrepreneurs a full year of free service with our G3.2GB Cloud VPS. This is one way we are helping small businesses and developers get their businesses off the ground.” Atlantic.Net initially offered the new program in Orlando, New York, Ashburn, and Toronto, but has now expanded it to San Francisco, with plans to make it available at all its locations in coming weeks. Customers will be able to take advantage of the G3 plans with double memory, 1TB more outbound data transfer than the G2 plans, some plans have better vCPU and disk space, and three new larger 48 GB, 96 GB, and 192 GB RAM plans are also available. The Atlantic.Net Cloud Platform, which is engineered to provide fault-tolerant, ultra-fast performance, includes award-winning Cloud Servers, Secure Block Storage, one-click applications, DNS, dedicated private nodes, private networking, RESTful API, data backup, a full suite of managed services, 24/7/365 expert U.S.-based support, and more. This infrastructure is ideally suited to support businesses and organizations as they evolve toward a distributed remote work environment to mitigate the health risks of COVID-19 to the global workforce. To view the latest cloud offerings and pricing structure, visit [https://www.atlantic.net/vps-hosting/](https://www.atlantic.net/vps-hosting/). **About Atlantic.Net** Atlantic.Net is a global [cloud services](https://www.atlantic.net/hipaa-compliant-hosting/) provider with over 25 years of experience, serving thousands of developers and small, medium, and large clients in more than one hundred countries. Atlantic.Net specializes in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions and has served dynamic business clients including Lenovo, Newegg, NASA, and Hilton, among others. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions, backed by 24/7/365 support in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. For more information, please visit [Atlantic Net/](https://www.atlantic.net/). --- # How to Choose a WordPress VPS Provider > URL: https://www.atlantic.net/vps-hosting/how-to-choose-a-wordpress-vps-provider/ | Published: 2021-02-19 | Updated: 2025-09-19 | Author: Brandon Schroth WordPress powers 455 million websites (around 35% of *all websites)*, and its broad support and user-friendliness make it an ideal choice for a content management system. But setting up a website is never as easy as just picking a website platform – you need a [web host](https://hostingdata.co.uk/), too. VPS hosting can be incredibly powerful, so much so that it can even give a competitive edge to industries as unforgiving as [Forex trading](https://www.atlantic.net/vps-hosting/how-vps-is-giving-a-competitive-edge-to-forex-trading/), Healthcare, Advertising, Life Sciences and more. Today, though, we’ll be covering the benefits that VPS hosting can provide in the context of [WordPress VPS hosting](https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/). ## What Is VPS Hosting? So what exactly is a VPS? Essentially, it’s a type of cloud hosting that doesn’t put you in a position where a bad neighbor can potentially cause you an issue. With traditional shared hosting, there may be dozens or hundreds of people on the same server, and the technology that oversees that server isn’t always very strict. That means that if a shared server has 32GB of RAM and there are a few hundred people on it, then that 32GB of ram gets torn back and forth between users in a virtual tug-of-war. For *most* personal use cases, that’s not necessarily a problem, but if you’re trying to host a website on an overutilized shared server, you might find the website crashing often. VPS is a nice alternative to such unrestricted shared hosting wherein the host limits the number of users per server and strictly cordones off each user’s environment (or VPS). To continue using our example above – a server that has 32GB of RAM – the number of users may be limited to 16, so each user can get 2GB of RAM. No matter what happens, you are guaranteed the 2GB RAM resources. Servers are not overprovisioned; instead, the load is balanced to another host. Of course, this equal split applies to all the hardware on the server, whether that’s RAM, the CPU, storage, or maybe even the connection the server runs on. ### The Cost Since the resources of virtual private servers are allocated to fewer people, that means that VPS hosting is generally more expensive than shared hosting. While you may find monthly prices in the $5-$10 ballpark at the lower end, you might expect a relatively good entry-tier [VPS hosting](https://www.atlantic.net/vps-hosting/pricing/) service starts from $10 monthly, although that can go up to hundreds or thousands of dollars depending on the server and your needs. There are also specific VPS hosting services that come with a slew of additional features such as server management, additional IP addresses, 100% Service Level Agreements, Onsite and Offsite backups, replication, and so forth. Going with such an option is perfect if you aren’t necessarily familiar with the website development and hosting or if you just don’t feel comfortable setting up and maintaining a WordPress website on your own. ## What to Look For ### Server Uptime One of the most important things you’ll want to focus on when choosing a host is the [uptime of the service](https://www.atlantic.net/disaster-recovery/what-exactly-does-uptime-mean-in-the-cloud-hosting-industry/). There’s no point putting so much effort into building a site if the host it’s on is constantly going down and your users can’t access it. As such, you’ll want to look for hosts that [guarantee 100% uptime if possible](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/). These types of providers have high-performing and highly available infrastructure services that should never go down unexpectedly. ### WordPress Management Suite Since we’re talking about WordPress hosting, it’s important to find a site that has WordPress management tools that you’re comfortable with. These considerations can range from how your WordPress site is installed (such as with a one-click installation) to the control panel that you’re going to be dealing with day-to-day (such as cPanel). More importantly, you need to gauge your own level of comfort when it comes to managing WordPress and knowing how much help you’re going to need. If you are a novice at administering a website, then choosing a VPS host that does most of the stuff for you is a good idea. On the other hand, if you have some experience, then a bit less hand-holding is OK. ### Customer Support Related to the point above, you’ll certainly want a host that has excellent customer support. Customer support can come in various forms, from email support to phone support. Ultimately the best choice here comes down to your preference and the way you’re most comfortable communicating. Either way, you’ll want a host that has [24/7 customer support](https://www.atlantic.net/press-releases/atlantic-net-begins-offering-247-customer-service/). We’ll even go so far as to say that if the host you’re looking at doesn’t offer 24/7 support, then you should just move on to the next one. We can’t stress how important it is to have timely access to help in a situation where your website has a problem. Similarly, check out reviews for the customer support of the host you want to join and make sure the customer service representatives are actually helpful. ## What to Avoid ### Unmanaged Servers While we’ve flagged this as a potential issue with a host, it may not be if you have experience in managing servers. On the other hand, if you’re reading this article, it’s likely you are entering the world of servers and hosting for the first time and therefore might possibly not be comfortable with server management. As such, we’d generally suggest getting a managed service, either as a plain VPS or managed WordPress VPS. Setting up a website can be frustrating if you don’t have experience with it, and knowing how to handle working and managed server can certainly help build experience with websites in the long run. Another option is to select a VPS hosting provider that also provides professional services so if you ever hit a tough spot, you can engage with the hosting parnter as a consultant to get you over that hurdle you are facing.  That said, if you feel comfortable with an unmanaged server, go for it! ### VPS vs Dedicated Hosting While most people will probably start out with relatively cheap VPS hosting, at some point they almost always need to scale up in both hardware *and* cost. As such, you may want to consider whether [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/9-essential-features-of-dedicated-server-hosting/) works better for you than VPS hosting. You can certainly find both at similar price points, even in the hundreds or thousands of dollars, and so it’s important to make sure you’re purchasing the right service. ### Cheap Hosting Far be it from us to tell you how you should spend your money, but the truth of the matter is that you get what you pay for. If you find a VPS hosting service in the free to $5 a month range, it’s likely not going to be great and you’re more than likely to run into problems. Not only that, but you’re probably giving up something important to get to that price point, such as 24/7 customer support. As such, we’d advise against any VPS service that costs less than $10 or so, since that’s really the lower bound of what we’d consider good entry-level VPS hosting. ## Conclusion While VPS hosting may seem complicated when you first start exploring hosting, don’t let it scare you off. It’s incredibly versatile, and when you add WordPress management into the mix, it can be an empowering tool for those who are just starting out with hosting their own website. More importantly, keep in mind that WordPress VPS hosting is a very flexible service and you can tier up and down in terms of cost depending on your budget and your needs. Hopefully, after reading this you have a better idea of what to look for when it comes to a good WordPress VPS host! --- # How to Install Chatwoot on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-chatwoot-on-ubuntu-20-04/ | Published: 2021-02-23 | Updated: 2023-11-15 | Author: Hitesh Jethva Chatwoot is an open-source customer support tool for real-time messaging channels. It is like other commercial customer support software like Intercorn & Zendesk. Chatwoot is designed to provide a great customer experience and to increase the productivity of your support team. Chatwoot allows you to integrate social media chat including WhatsApp, Twitter, Facebook and Email to a central place. In this tutorial, we will explain how to install **Chatwoot** on Ubuntu 20.04. ## Step 1 – Install Chatwoot You can install Chatwoot easily by downloading its automated installation script. You can download it with the following command: ``` apt install git -y git clone https://github.com/chatwoot/chatoot.git cd chatwoot/deployment/ bash setup_20.04.sh -O setup.sh ``` ``` ``` **Note: the install process will take several minutes.** Once the installation has been completed successfully, you should get the following output: ``` Woot! Woot!! Chatwoot server installation is complete The server will be accessible at http://:3000 To configure a domain and SSL certificate, follow the guide at https://www.chatwoot.com/docs/deployment/deploy-chatwoot-in-linux-vm ``` You can also verify the status of the Chatwoot service with the following command: ``` systemctl status chatwoot.target ``` You should get the following output: - ``` chatwoot.target Loaded: loaded (/etc/systemd/system/chatwoot.target; enabled; vendor preset: enabled) Active: active since Mon 2021-01-11 07:13:25 UTC; 2min 20s ago ``` ``` Jan 11 07:13:25 ubuntu2004 systemd[1]: Reached target chatwoot.target. ``` By default, Chatwoot listens on port 3000. You can verify it with the following command: ``` ss -antpl | grep 3000 ``` You should see the following output: ``` LISTEN 0 1024 0.0.0.0:3000 0.0.0.0:* users:(("ruby",pid=57666,fd=8)) ``` ## Step 2 – Configure Nginx as a Reverse Proxy Next, you will need to install and configure Nginx as a reverse proxy for Chatwoot. First, install the Nginx with the following command: ``` apt-get install nginx -y ``` Once the Nginx has been installed, create a new Nginx virtual host configuration file with the following command: ``` nano /etc/nginx/conf.d/chatwoot.conf ``` Add the following lines: ``` server { server_name chatwoot.example.com; # Point upstream to Chatwoot App Server set $upstream 127.0.0.1:3000; # Nginx strips out underscore in headers by default # Chatwoot relies on underscore in headers for API # Make sure that the config is turned on. underscores_in_headers on; location /.well-known { alias /var/www/ssl-proof/chatwoot/.well-known; } location / { proxy_pass_header Authorization; proxy_pass http://$upstream; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $host; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-Ssl on; # Optional proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_http_version 1.1; proxy_set_header Connection “”; proxy_buffering off; client_max_body_size 0; proxy_read_timeout 36000s; proxy_redirect off; } listen 80; ``` } Save and close the file, then verify Nginx for any syntax errors with the following command: ``` nginx -t ``` If you get this error: ``` nginx: [emerg] could not build server_names_hash, you should increase server_names_hash_bucket_size: 32 ``` Do the following: ``` nano /etc/nginx/nginx.conf ``` In the http block, add: ``` server_names_hash_bucket_size 64; ``` Next, restart the Nginx to apply the configuration changes: ``` systemctl reload nginx ``` ## Step 3 – Access Chatwoot Now, open your web browser and access the Chatwoot web interface using the URL **http://chatwoot.example.com**. You will be redirected to the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/02/chatwoot1.png) Click on the **Create new account** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/02/chatwoot2.png) Provide your username and email and click on the **Submit** button. You should see the Chatwoot dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/02/chatwoot3.png) ## Conclusion Congratulations! You have successfully installed Chatwoot on Ubuntu 20.04. You can now use Chatwoot to integrate all your social accounts and manage them from a central location. Try it using a [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Top Healthcare Technology and Compliance Trends in 2021 > URL: https://www.atlantic.net/hipaa-compliant-hosting/top-healthcare-technology-and-compliance-trends-in-2021/ | Published: 2021-02-23 | Updated: 2025-09-19 | Author: Dr. Rachael Bailey The year 2020 saw a rapid acceleration in the development and uptake of new healthcare technologies, largely due to the global COVID-19 pandemic. Nascent technologies, such as telehealth solutions and AI chatbots, quickly became essential as the world united in its fight against coronavirus. As the pandemic continues to unfold, will we see a surge in digital health technologies through 2021? Innovation in digital health will be key to resolving the pandemic and supporting economic recovery and growth. Here, we consider some of the trends in healthcare technology and compliance that can be expected in 2021. ## Accelerated Cloud Adoption Driven by the Need for Compliance and Telehealth Cloud adoption within the healthcare industry has traditionally remained notoriously slow, due to concerns regarding data security and regulatory requirements, such as HIPAA and HITECH. Today, it is regulatory compliance that is driving the growth curve. The COVID-19 pandemic has served to drive forward cloud adoption in order to address the changing needs of the healthcare sector. In 2021, we can expect more healthcare organizations to utilize the benefits of cloud-based infrastructure, to support remote consultations, improve collaboration, increase security and provide the scalability required for data storage. Telehealth has played an essential role in ensuring that patients remain able to access vital healthcare services during the pandemic. Indeed, [43.5% of Medicare primary care visits](https://www.hhs.gov/about/news/2020/07/28/hhs-issues-new-report-highlighting-dramatic-trends-in-medicare-beneficiary-telehealth-utilization-amid-covid-19.html) were delivered via telehealth services in April 2020. Telehealth solutions have allowed physicians to continue to offer primary care to patients while abiding with the necessary social distancing guidelines. Virtual consultations lessen the strain placed on healthcare services by limiting the use of valuable time and resources, including PPE, which has remained in short supply throughout the pandemic. With high patient adoption rates, this telehealth boom looks set to continue long after the pandemic has ended. ## 5G, Geonomics and 3D Printing These three technologies will surge in popularity in 2021, as 5G networks are already expanding across the globe at a rapid pace, and coverage will populate all cities and major towns quickly. The added network performance introduced with 5G will benefit telehealth significantly, improve teleconferencing capabilities, and give doctors greater flexibility with remote surgery, transferring medical files, and real-time monitoring of patients. Genomic medicine will thrive in 2021, and advances will include using genomics to personalize care for diagnosis or decision making. 3D printing (bioprinting) advances will push genomics further to creating human cells and tissue for use in regenerative medicine. ## Artificial Intelligence and Machine Learning Powered Healthcare The potential for AI/Machine Learning in healthcare is endless. AI has certainly proven valuable so far during the fight against coronavirus, powering scientific research, managing hospital bed capacities, triaging COVID-19 patients, and easing the burden of administrative duties via the use of AI-powered digital workers. AI solutions help to reduce costs, increase productivity, and, most importantly, improve patient outcomes. In 2021, we can expect to see many more AI-powered solutions being deployed within the healthcare sector. With technological advancements, we will see a move to a personalized medicine model, steering away from the traditional “one size fits all” approach. AI tools will enable physicians to select the appropriate treatment strategy for their patient, based on the analysis of unique information that may include biometrics, such as genetic data. As we move towards identifying many potential COVID-19 therapies and vaccines, AI tools can also help to speed up and cut the costs of the vital drug discovery process. ## Virtual and Augmented Reality Virtual Reality (VR) and Augmented Reality (AR) technologies are helping to transform healthcare services. When used alongside telehealth solutions, VR/AR can enhance patient-physician interaction, improving diagnosis and treatment planning. VR and AR technology also presents an invaluable tool for the education and surgical training of medical students. VR and AR tools show promise in improving visualization when gaining intravenous access or conducting spinal surgery and for helping patients with certain chronic conditions, for example, improving motor deficiencies in victims of stroke. As the technology advances throughout 2021, we can expect to see progress in the use of VR/AR for these applications. ## Blockchain Technology Increasing numbers of healthcare organizations are adopting blockchain technology to improve the security of data and enable secure interoperability and accessibility. The implementation of blockchain technologies is set to optimize the healthcare industry. Replacing the conventional pharma supply chain management system with blockchain technology would help to overcome the issues surrounding counterfeit products, improving drug traceability and authenticity. As we move towards building a more resilient healthcare system, the swift implementation of transformative technologies, such as blockchain, will become vital. ## Internet of Medical Things (IoTM) The Internet of Medical Things (IoMT) refers to a system of connected medical applications and devices that serves to collect individual patient health and fitness data. [By 2026, the IoMT market is predicted to be worth USD 254,233.6 million](https://www.alltheresearch.com/report/166/internet-of-medical-things-market#:~:text=The%20global%20Internet%20of%20Medical,period%20(2016%2D2026).) . While the adoption of wearable devices is soaring, IoMT will not be limited to such tools with the implementation of this technology for new applications set to occur throughout the coming year. Driven by advances in 5G technology, network coverage, and patient acceptance, we expect an upsurge in IoMT. As the precision of device sensors improve, an increasing number of chronic conditions will be able to be effectively managed using IoMT. IoMT will enable remote patient monitoring to improve the accuracy and effectiveness of telehealth solutions, as well as providing a welcome boost to patient engagement. ## Big Data and Predictive Analytics Leveraging the power of big data and predictive analytics to predict pandemics/epidemics, improve patient outcomes, and cure chronic disease has become more important than ever before. The scale and quality of data available is growing as fast as the deployment of new technologies, and we must keep pace to ensure that we are using the right tools to obtain calculative and meaningful insights from this information. Throughout 2021, all eyes will be watching keenly to see how advances in big data are used to gain real-time control of coronavirus and help in our fight against the current epidemiological crisis we find ourselves in. ## Post-Pandemic Focus on Cybersecurity Cybersecurity was already incredibly important before the Covid-19 pandemic, but with remote working becoming commonplace and telehealth appointments increasing, cybersecurity must become the backbone of any healthcare in technology. It has been essential for healthcare providers to carefully consider security and compliance requirements throughout 2020. While certain HIPAA compliance regulations were relaxed and waivers introduced during the pandemic, healthcare providers must still ensure that their services remain fully compliant wherever possible. Some telehealth solutions are not fully HIPAA compliant and, as telemedicine becomes the norm, this is an issue that needs to be addressed in 2021. ## Atlantic.Net Healthcare Hosting Solutions Atlantic.Net is an award-winning [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) provider, with over 30 years worth of experience. We provide effective hosting solutions to an extensive list of leading healthcare clients. [Contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) to find out how, heading through 2021, Atlantic.Net can help your organization to both meet and exceed HIPAA requirements, with a managed or unmanaged hosting solution that is customized to meet the needs of your business. Learn more about our [HIPAA compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions.   --- # How to Install FiveM Game Server on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-install-fivem-game-server-on-ubuntu/ | Published: 2021-02-24 | Updated: 2026-03-14 | Author: Hitesh Jethva FiveM is a multiplayer game server that allows you to play on customized dedicated servers. It was specifically designed for creativity. You can create your server and make your dreams come true. It provides a set of tools to personalize the gameplay experience of your server. With FiveM, you can make anything, including roleplay, drifting, racing, deathmatch, or something completely original. This tutorial will show you how to install FiveM on Ubuntu 20.04. ## Prerequisites - A fresh Ubuntu 20.04 Server (at least 2GB RAM) - A valid domain name pointed to your server IP - A root password configured on your server ## Step 1 – Install Required Dependencies Before starting, you will need to install some dependencies on your server. You can install all of them with the following commands: ``` apt-get update -y ``` ``` apt-get install screen wget git -y ``` Once all the packages are installed, you can proceed to the next step. ## Step 2 – Install and Configure FiveM First, create a directory for FiveM and download the latest version of FiveM inside the directory: ``` mkdir ~/fivem_server cd ~/fivem_server wget https://runtime.fivem.net/artifacts/fivem/build_proot_linux/master/6683- 0c5d71ad77873c159d7542a7e8314d9696c1b55b/fx.tar.xz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar -xvf fx.tar.xz ``` Next, you must download the CFX server data to your system. You can download it with the following command: ``` git clone https://github.com/citizenfx/cfx-server-data ~/fivem_resources ``` Next, you will need to create a FiveM configuration file. You can create it with the following command: ``` nano ~/fivem_resources/server.cfg ``` Add the following lines, including your FiveM Licence: ``` # Only change the IP if you’re using a server with multiple network interfaces, otherwise change the port only. endpoint_add_tcp "0.0.0.0:30120” endpoint_add_udp "0.0.0.0:30120” # These resources will start by default. ensure mapmanager ensure chat ensure spawnmanager ensure sessionmanager ensure fivem ensure hardcap ensure rconlog ensure scoreboard # This allows players to use scripthook-based plugins such as the legacy Lambda Menu. # Set this to 1 to allow scripthook. Do note that this does _not_ guarantee players won’t be able to use external plugins. sv_scriptHookAllowed 0 # Uncomment this and set a password to enable RCON. Make sure to change the password - it should look like rcon_password "YOURPASSWORD” #rcon_password "” # A comma-separated list of tags for your server. # For example: # - sets tags "drifting, cars, racing” # Or: # - sets tags "roleplay, military, tanks” sets tags "default” # Set an optional server info and connecting banner image url. # Size doesn’t matter, any banner sized image will be fine. #sets banner_detail "https://url.to/image.png” #sets banner_connecting "https://url.to/image.png” # Set your server’s hostname sv_hostname "FXServer, but unconfigured” # Nested configs! #exec server_internal.cfg # Loading a server icon (96×96 PNG file) #load_server_icon myLogo.png # convars which can be used in scripts set temp_convar "hey world!” # Uncomment this line if you do not want your server to be listed in the server browser. # Do not edit it if you *do* want your server listed. #sv_master1 "” # Add system admins add_ace group.admin command allow # allow all commands add_ace group.admin command.quit deny # but don’t allow quit add_principal identifier.steam:110000100000000 group.admin # add the admin to the group # Hide player endpoints in external log output. sv_endpointprivacy true # Server player slot limit (must be between 1 and 32, unless using OneSync) sv_maxclients 32 # License key for your server (https://keymaster.fivem.net) sv_licenseKey i1mqzvi2eukui85p8cb0uddanqsru2lk ``` Save and close the file when you are finished. Next, you can start the FiveM server with the following command: ``` cd ~/fivem_resources && bash ~/fivem_server/run.sh +exec server.cfg ``` Once the server has started successfully, you should get the following output: Note: This process will take several minutes to start ``` [------------------------------------------------------------------------------------------------------ --------------------------------] 0/315Server license key authentication succeeded. Welcome! Authenticating with Nucleus... [#####------------------------------------------------------------------------------------------------- -------------------------------] 11/315 fff cccc ff xx xx rr rr eee cc ffff xx rrr r ee e cc ff xx ... rr eeeee ccccc ff xx xx ... rr eeeee Authenticated with cfx.re Nucleus: https://hitj-e8q3pd.users.cfx.re/ [###############################----------------------------------------------------------------------------- -------------------------] 74/315-- [server notice: tebex_not_set] ================ Monetize your server using Tebex! Visit https://tebex.io/fivem for more info. ================ ``` Press **CTRL + C** to stop the server. ## Step 3 – Create a Systemd Service File for FiveM Creating a systemd service file to manage the FiveM service is a good idea. You can create it with the following command: ``` nano /lib/systemd/system/fivem.service ``` Add the following lines: ``` [Unit] Description=FiveM server [Service] Type=forking User=root ExecStart=/usr/bin/fivem_start.sh [Install] WantedBy=multi-user.target ``` Save and close the file, then create a FiveM start script: ``` nano /usr/bin/fivem_start.sh ``` ``` Add the following lines: #!/bin/bash screen -dm bash -c 'cd /root/fivem_resources && bash /root/fivem_server/run.sh +exec server.cfg' ``` Save and close the file, then set proper permission: ``` chmod +x /usr/bin/fivem_start.sh ``` Next, reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start FiveM and enable it to start at system reboot: ``` systemctl start fivem systemctl enable fivem ``` You can verify the status of FiveM with the following command: systemctl status five You should get the following output: - ``` fivem.service - FiveM server ``` ``` Loaded: loaded (/lib/systemd/system/fivem.service; disabled; vendor preset: enabled) Active: active (running) since Wed 2021-01-13 15:09:13 UTC; 6s ago Process: 24132 ExecStart=/usr/bin/fivem_start.sh (code=exited, status=0/SUCCESS) Main PID: 24136 (screen) Tasks: 67 (limit: 4691) Memory: 48.1M CGroup: /system.slice/fivem.service ├─24136 SCREEN -dm bash -c cd /root/fivem_resources && bash /root/fivem_server/run.sh +exec server.cfg ├─24148 /root/fivem_server/alpine/opt/cfx-server/ld-musl-x86_64.so.1 -- library-path /root/fivem_server/alpine/usr/lib/v8/:/root/f> └─24151 /root/fivem_server/alpine/opt/cfx-server/ld-musl-x86_64.so.1 -- library-path /root/fivem_server/alpine/usr/lib/v8/:/root/f> Jan 13 15:09:13 ubuntu2004 systemd[1]: Starting FiveM server... Jan 13 15:09:13 ubuntu2004 systemd[1]: Started FiveM server. ``` By default, FiveM listens on port 30120. You can check it with the following command: ``` ss -antpl | grep 30120 ``` You should get the following output: ``` LISTEN 0 128 0.0.0.0:30120 0.0.0.0:* users:(("ld-musl-x86_64.",pid=24148,fd=57)) ``` ## Step 4 – Manage Your FiveM Server with txAdmin Once your FiveM server is running, you can [set up txAdmin](https://gravelhost.com/index.php?rp=/knowledgebase/90/Setting-up-txAdmin-for-your-FiveM-server.html) to manage the server using a web-based dashboard. txAdmin comes built into the FXServer platform and provides a graphical interface that makes server administration much easier compared to managing everything from the terminal. Instead of stopping and restarting the server manually through SSH, you can log into the txAdmin panel from a browser and control most server operations from a single interface. This is especially helpful for community servers where administrators need to monitor activity, manage players, and maintain server stability. One of the most useful features of txAdmin is the real-time server monitoring dashboard. The panel displays server performance metrics such as CPU usage, memory consumption, player count, and resource activity. This information helps administrators identify performance issues quickly and maintain smooth gameplay for connected players. ## Conclusion Congratulations! You have successfully installed and configured a FiveM game server on Ubuntu 20.04. You can now download the FiveM client on your desktop system and play using FiveM on your [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [Virtual private servers.](https://www.atlantic.net/vps-hosting/) --- # How to Install Elasticsearch Ubuntu 20.04 and CentOS 8 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-elasticsearch-ubuntu-20-04-and-centos-8/ | Published: 2021-02-25 | Updated: 2023-11-16 | Author: Hitesh Jethva [jumpbox] ## Update your Server Once you are logged in to your Ubuntu 20.04 server, run the following command to update your base system with the latest available packages. ``` apt-get update -y ``` You can also update your CentOS 8 system with the following command: ``` dnf update -y ``` Elasticsearch is an open-source, distributed search engine that allows you to store and analyze a large amount of data. It is specially designed for complex search requirements. It uses a simple set of APIs that provide the ability for full-text search. Elasticsearch is the best choice for you if you are looking to search a large, complex dataset. In this tutorial, we will show you how to install Elasticsearch on Ubuntu 20.04 and CentOS 8. ## Install Elasticsearch on Ubuntu 20.04 In this section, we will show you how to install Elasticsearch on Ubuntu 20.04. First, you will need to install all the required dependencies to your server. You can install them with the following command: ``` apt-get install apt-transport-https ca-certificates gnupg2 curl -y ``` Once all the dependencies are installed, add the Elasticsearch GPG key with the following command: ``` wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | apt-key add - ``` Next, add the Elasticsearch repository to APT with the following command: ``` sh -c 'echo "deb https://artifacts.elastic.co/packages/7.x/apt stable main" > /etc/apt/sources.list.d/elastic-7.x.list' ``` Once the repository is added, update the repository and install Elasticsearch with the following command: ``` apt-get update -y apt-get install elasticsearch -y ``` Once the installation is completed, start Elasticsearch and enable it to start at system reboot: ``` systemctl start elasticsearch systemctl enable elasticsearch ``` You can now verify Elasticsearch with the following command: ``` curl -X GET "localhost:9200/" ``` You should get the following output: ``` { "name" : "ubuntu2004", "cluster_name" : "elasticsearch", "cluster_uuid" : "PKpCl7VJT6G8q8SxR7m6DQ", "version" : { "number" : "7.10.1", "build_flavor" : "default", "build_type" : "deb", "build_hash" : "1c34507e66d7db1211f66f3513706fdf548736aa", "build_date" : "2020-12-05T01:00:33.671820Z", "build_snapshot" : false, "lucene_version" : "8.7.0", "minimum_wire_compatibility_version" : "6.8.0", "minimum_index_compatibility_version" : "6.0.0-beta1" }, "tagline" : "You Know, for Search" } ``` ## Install Elasticsearch on CentOS 8 In this section, we will show you how to install Elasticsearch on CentOS 8. First, install Java and other required dependencies with the following command: ``` dnf install java-11-openjdk-devel curl ``` Once the installation is completed, verify the Java version with the following command: ``` java -version ``` You should get the following output: ``` openjdk version "11.0.9.1" 2020-11-04 LTS OpenJDK Runtime Environment 18.9 (build 11.0.9.1+1-LTS) OpenJDK 64-Bit Server VM 18.9 (build 11.0.9.1+1-LTS, mixed mode, sharing) ``` Next, import the Elasticsearch GPG key with the following command: ``` rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch ``` Next, create a repo file for Elasticsearch with the following command: ``` nano /etc/yum.repos.d/elasticsearch.repo ``` Add the following lines: ``` [elasticsearch-7.x] name=Elasticsearch repository for 7.x packages baseurl=https://artifacts.elastic.co/packages/7.x/yum gpgcheck=1 gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch enabled=1 autorefresh=1 type=rpm-md ``` Save and close the file, then install Elasticsearch with the following command: ``` dnf install elasticsearch -y ``` Once the installation is completed, start the Elasticsearch service and enable it to start at system reboot with the following command: ``` systemctl start elasticsearch systemctl enable elasticsearch ``` You can now verify the status of the Elasticsearch service with the following command: ``` systemctl status elasticsearch ``` You should get the following output: - ``` elasticsearch.service - Elasticsearch ``` ``` Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; disabled; vendor preset: disabled) Active: active (running) since Mon 2021-01-11 03:04:19 EST; 8s ago Docs: https://www.elastic.co Main PID: 1801 (java) Tasks: 65 (limit: 12523) Memory: 1.2G CGroup: /system.slice/elasticsearch.service ├─1801 /usr/share/elasticsearch/jdk/bin/java -Xshare:auto -Des.networkaddress.cache.ttl=60 -Des.networkaddress.cache.negative.ttl=1> └─1986 /usr/share/elasticsearch/modules/x-pack-ml/platform/linux-x86_64/bin/controller Jan 11 03:03:50 centos8 systemd[1]: Starting Elasticsearch... Jan 11 03:04:19 centos8 systemd[1]: Started Elasticsearch. ``` Next, run the following command to verify Elasticsearch: ``` curl -X GET "localhost:9200/" ``` You should see the following output: ``` { "name" : "centos8", "cluster_name" : "elasticsearch", "cluster_uuid" : "vFz_YYRvTAWC3AiaMP_ORA", "version" : { "number" : "7.10.1", "build_flavor" : "default", "build_type" : "rpm", "build_hash" : "1c34507e66d7db1211f66f3513706fdf548736aa", "build_date" : "2020-12-05T01:00:33.671820Z", "build_snapshot" : false, "lucene_version" : "8.7.0", "minimum_wire_compatibility_version" : "6.8.0", "minimum_index_compatibility_version" : "6.0.0-beta1" }, "tagline" : "You Know, for Search" } ``` ## Conclusion In the above guide, you learned how to install Elasticsearch on Ubuntu 20.04 and CentOS 8. You can now use Elasticsearch with your e-commerce store application on your [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) plan from Atlantic.Net! --- # How to Install and Use Checkmk Monitoring Server on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-checkmk-monitoring-server-on-ubuntu-20-04/ | Published: 2021-02-26 | Updated: 2023-11-15 | Author: Hitesh Jethva Checkmk is a monitoring software written in Python and C++. This self-contained tool combines with Nagios and its add-ons and can be used for monitoring your infrastructure and services. Checkmk works in client-server architecture, meaning you must install Checkmk agent on each computer that you want to monitor. With Checkmk, you can monitor web servers, database servers, and cloud infrastructure such as, Azure, AWS and more. In this tutorial, we will show you how to install and use the Checkmk monitoring server on Ubuntu 20.04. ## Step 1 – Install Checkmk By default, Checkmk is not included in the Ubuntu default repository, so you will need to download Checkmk package from its official website: First, download the Checkmk with the following command: ``` wget https://download.checkmk.com/checkmk/1.6.0p20/check-mk-raw- 1.6.0p20_0.focal_amd64.deb ``` Once the download is completed, install the downloaded package with the following command: ``` dpkg -i check-mk-raw-1.6.0p20_0.focal_amd64.deb ``` Next, run the following command to install the required dependencies for Checkmk. ``` apt-get install -f ``` Once the installation has been completed, run the following command to list all commands available with Checkmk: ``` omd ``` You should get the following output: ``` Usage (called as root): omd help Show general help omd setversion VERSION Sets the default version of OMD which will be used by new sites omd version [SITE] Show version of OMD omd versions List installed OMD versions omd sites Show list of sites omd create SITE Create a new site (-u UID, -g GID) omd init SITE Populate site directory with default files and enable the site omd rm SITE Remove a site (and its data) omd disable SITE Disable a site (stop it, unmount tmpfs, remove Apache hook) omd enable SITE Enable a site (reenable a formerly disabled site) omd mv SITE NEWNAME Rename a site omd cp SITE NEWNAME Make a copy of a site omd update SITE Update site to other version of OMD omd start [SITE] [SERVICE] Start services of one or all sites omd stop [SITE] [SERVICE] Stop services of site(s) omd restart [SITE] [SERVICE] Restart services of site(s) omd reload [SITE] [SERVICE] Reload services of site(s) omd status [SITE] [SERVICE] Show status of services of site(s) omd config SITE ... Show and set site configuration parameters omd diff SITE ([RELBASE]) Shows differences compared to the original version files omd su SITE Run a shell as a site-user omd umount [SITE] Umount ramdisk volumes of site(s) omd backup SITE [SITE] [-|ARCHIVE_PATH] Create a backup tarball of a site, writing it to a file or stdout omd restore [SITE] [-|ARCHIVE_PATH] Restores the backup of a site to an existing site or creates a new site omd cleanup Uninstall all Check_MK versions that are not used by any site. General Options: -V set specific version, useful in combination with update/create omd COMMAND -h, --help show available options of COMMAND ``` ## Step 2 – Create a Monitoring Instance Next, you will need to create a monitoring instance for testing purposes. You can create it using the omd tool: ``` omd create myserver ``` You will should see the following output: ``` Adding /opt/omd/sites/myserver/tmp to /etc/fstab. Creating temporary filesystem /omd/sites/myserver/tmp...OK Restarting Apache...OK Created new site myserver with version 1.6.0p20.cre. The site can be started with omd start myserver. The default web UI is available at http://ubuntu2004/myserver/ The admin user for the web applications is cmkadmin with password: RCDM5jQG (It can be changed with 'htpasswd -m ~/etc/htpasswd cmkadmin' as site user. ) Please do a su - myserver for administration of this site. ``` **Note:** Please remember the checkmk username and password from the above output. You will need it to access the Checkmk dashboard. Next, start the server with the following command: ``` omd start myserver ``` You should get the following output: ``` Starting mkeventd...OK Starting rrdcached...OK Starting npcd...OK Starting nagios...OK Starting apache...OK Initializing Crontab...OK ``` You can verify the status of the server with the following command: ``` omd status ``` You should get the following output: ``` Doing 'status' on site myserver: mkeventd: running rrdcached: running npcd: running nagios: running apache: running crontab: running ----------------------- Overall state: running ``` To check the omd version, run the following command: ``` omd version ``` Output: ``` OMD - Open Monitoring Distribution Version 1.6.0p20.cre ``` You can also see your all monitoring instances with the following command: ``` omd sites ``` Output: ``` SITE VERSION COMMENTS myserver 1.6.0p20.cre default version ``` ## Step 3 – Access Checkmk Web Interface Now, open your web browser and access the Checkmk web interface using the URL **http://your-server-ip/myserver**. You will be redirected to the Checkmk login page: ![](https://www.atlantic.net/wp-content/uploads/2021/02/checkmk1.png) Provide your Checkmk username, password and click on the **Login** button. You should see the Checkmk dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/02/checkmk2.png) It is a good idea to change the default Checkmk password. Click on the WATO – Configuration in the left side and you should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/02/checkmk3.png) Set your new password and click on the **Save** button to change the password. ## Step 4 – Create a Monitoring Host Before starting, you will need to download and install the Checkmk monitoring agent on the server. In the WATO – Configuration menu, click on the **Monitoring Agents**, you should see agent packages for all operating systems in the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/02/checkmk4.png) Pick the package for Ubuntu and download it with the following command: ``` wget http://45.58.38.223/myserver/check_mk/agents/check-mk-agent_1.6.0p20-1_all.deb ``` Once downloaded, install the agent package with the following command: ``` dpkg -i check-mk-agent_1.6.0p20-1_all.deb ``` Once the agent package is installed, you can verify it with the following command: ``` check_mk_agent | less ``` You should get the following output: ``` <<>> Version: 1.6.0p20 AgentOS: linux Hostname: ubuntu2004 AgentDirectory: /etc/check_mk DataDirectory: /var/lib/check_mk_agent SpoolDirectory: /var/lib/check_mk_agent/spool PluginsDirectory: /usr/lib/check_mk_agent/plugins LocalDirectory: /usr/lib/check_mk_agent/local <<>> ``` In the WATO – Configuration menu, click on the **Hosts** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/02/checkmk5.png) Click on the **Create new host** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/02/checkmk6.png) Provide all required information and click on the **Save and go to Services** button. You should see all services in the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/02/checkmk7.png) ## Conclusion Congratulations! You have successfully installed and configured a Checkmk monitoring server on Ubuntu 20.04. You can now install Checkmk agents on the remote machines and start monitoring from the Checkmk web interface. Try it today using a [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Use Cockpit on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-cockpit-on-ubuntu-20-04/ | Published: 2021-02-27 | Updated: 2023-11-15 | Author: Hitesh Jethva The Cockpit is a web-based tool that helps system administrators perform day-to-day administrative tasks from a web browser. You can monitor system resources, create and remove user accounts, start and stop services, restart and shut down the system, and create and manage virtual boxes using the Cockpit. Cockpit makes it easier to administer your Linux server via a web-based interface. ## Step 1 – Install Cockpit By default, the Cockpit package is included in the Ubuntu default repository. You can install it by just running the following command: ``` apt-get update -y apt-get install cockpit -y ``` Once the Cockpit is installed, start the Cockpit service and enable it to start at system reboot: ``` systemctl start cockpit systemctl enable cockpit ``` You can also verify the status of the Cockpit service with the following command: ``` systemctl status cockpit ``` You should get the following output: ``` cockpit.service - Cockpit Web Service Loaded: loaded (/lib/systemd/system/cockpit.service; static; vendor preset> Active: active (running) since Fri 2021-01-22 15:26:48 UTC; 4s ago TriggeredBy: ● cockpit.socket Docs: man:cockpit-ws(8) Process: 7544 ExecStartPre=/usr/sbin/remotectl certificate --ensure --user=> Main PID: 7552 (cockpit-tls) Tasks: 1 (limit: 2353) Memory: 2.0M CGroup: /system.slice/cockpit.service └─7552 /usr/lib/cockpit/cockpit-tls Jan 22 15:26:48 ubuntu2004 systemd[1]: Starting Cockpit Web Service... Jan 22 15:26:48 ubuntu2004 remotectl[7544]: Generating temporary certificate us> Jan 22 15:26:48 ubuntu2004 remotectl[7544]: Error generating temporary dummy ce> Jan 22 15:26:48 ubuntu2004 remotectl[7544]: Generating temporary certificate us> Jan 22 15:26:48 ubuntu2004 systemd[1]: Started Cockpit Web Service. ``` At this point, Cockpit is started and listening on port 9090. You can verify it with the following command: ``` ss -antpl | grep 9090 ``` You should see the following output: ``` LISTEN 0 4096 *:9090 *:* users:(("cockpit- tls",pid=7552,fd=3),("systemd",pid=1,fd=101)) ``` ## Step 2 – Access Cockpit Web Interface Now, open your web browser and access the Cockpit web interface using the URL **https://your-server-ip:9090**. You should see the Cockpit login page: ![](https://www.atlantic.net/wp-content/uploads/2021/02/cockpit1.png) Provide your root username and password and click on the **Log in** button. You should see the Cockpit dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/02/cockpit2.png) ## Step 3 – How to Use Cockpit You can also create and manage the virtual machine using Cockpit. First, you will need to enable the virtual machine option in Cockpit. You can enable it with the following command: ``` apt-get install cockpit-machines -y ``` Once installed, log out and log in again, you should see the Virtual machine option in the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/02/cockpit3.png) Click on the **Create VM** button to create a virtual machine. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/02/cockpit4.png) Provide your VM name, operating system, RAM, and Disk and click on the **Create** button. Once the VM is created, you should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/02/cockpit5.png) Next, click on the **Console** tab, you should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/02/cockpit6.png) Click on the **Run** button to start the Virtual Machine. Once the VM is started, you should see the Virtual Machine login screen in the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/02/cockpit7.png) You can now login to VM using your root username and password. ## Step 4 – Manage Services and Logs You can manage the system services and logs from the Cockpit web interface. In the Cockpit web interface, click on the **Services** button. You should see all system services in the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/02/cockpit8.png) From here, you can start, stop and disable the system services easily. Click on the **Logs** button in the left pane and you should see all system logs in the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/02/cockpit9.png) If you want to access your server via terminal, click on the **Terminal** button. You should see the terminal windows in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/02/cockpit10.png) ## Conclusion Congratulations! You have successfully installed Cockpit on Ubuntu 20.04. You can now easily manage your server from its web-based interface. You can also use Cockpit on a [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Update Docker Container with Zero Downtime > URL: https://www.atlantic.net/vps-hosting/how-to-update-docker-container-with-zero-downtime/ | Published: 2021-03-01 | Updated: 2023-11-27 | Author: Hitesh Jethva In a Dockerized environment, you are using multiple images and working with many containers. When you run a container from an image, it continues running that version because Docker images do not update automatically. You may need to update it manually. It is always recommended to run a container from the latest Docker image. In this guide, we will show you hands-on examples of how to update a running container with zero downtime. ## Step 1 – Install Docker CE and Docker Compose First, install all required dependencies with the following command: ``` apt-get update -y apt-get install git apt-transport-https ca-certificates curl software-properties-common -y ``` Next, add the Docker GPG key and repository with the following command: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add - add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu focal stable" ``` Once the repository has been added, install the Docker and Docker compose with the following command: ``` apt-get install docker-ce docker-compose -y ``` Once both packages are installed, you can proceed to the next step. ## Step 2 – Create a Docker Compose File For the purpose of this tutorial, we will create a docker network, volume, and a docker-compose.yml file to deploy a Ghost container. First, create a network named net and volume named ghost using the following command: ``` docker network create net docker volume create ghost ``` Next, create a directory for the Ghost project with the following command: ``` mkdir Ghost ``` Next, change the directory to Ghost and create a docker-compose.yml file: ``` cd Ghost nano docker-compose.yml ``` Add the following lines: ``` version: '3.5' services: ghost: image: ghost:3.36 volumes: - ghost:/var/lib/ghost/content environment: - VIRTUAL_HOST=ghost.example.com - url=http://ghost.example.com - NODE_ENV=production restart: always networks: - net volumes: ghost: external: true networks: net: external: true ``` Save and close the file when you are finished. The above file will download the Ghost image version 3.36 and create a Ghost container for domain ghost.example.com. ## Step 3 – Create a Ghost Container Now, change the directory to Ghost and launch the Ghost container using the following command: ``` docker-compose up -d ``` You should get the following output: ``` Pulling ghost (ghost:3.36)... 3.36: Pulling from library/ghost bb79b6b2107f: Pull complete 99ce436c3449: Pull complete f7bdc31da5f5: Pull complete 7a1300b9ff59: Pull complete a495c68fa838: Pull complete 6e362a39ec35: Pull complete b68b4f3c36f7: Pull complete 41f8b02d4a71: Pull complete 3ecc736ea4e5: Pull complete Digest: sha256:595c759980cd22e99037811397012908d89efb799776db222a4be6d4d892917c Status: Downloaded newer image for ghost:3.36 Creating ghost_ghost_1 ... done ``` You can check the Ghost image with the following command: ``` docker images ``` Output: ``` REPOSITORY TAG IMAGE ID CREATED SIZE ghost 3.36 455ce1645479 4 months ago 440MB ``` You can also check the Ghost container with the following command: ``` docker ps ``` Output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES d4b51b1aafc8 ghost:3.36 "docker-entrypoint.s…" 23 seconds ago Up 20 seconds 2368/tcp ghost_ghost_1 ``` ## Step 4 – Update the Docker Compose File In this section, we will update the Docker compose file and change the Ghost version from 3.36 to 3.37.1: ``` nano docker-compose.yml ``` Make the following changes: ``` version: '3.5' services: ghost: image: ghost:3.37.1 volumes: - ghost:/var/lib/ghost/content environment: - VIRTUAL_HOST=ghost.example.com - url=http://ghost.example.com - NODE_ENV=production restart: always networks: - net volumes: ghost: external: true networks: net: external: true ``` Save and close the file when you are finished. ## Step 5 – Launch a New Ghost Container Now, we will use the scaling method to create a new Ghost container without affecting the older Ghost container. You can do it with the following command: ``` cd Ghost docker-compose up -d --scale ghost=2 --no-recreate ``` You should get the following output: ``` Pulling ghost (ghost:3.37.1)... 3.37.1: Pulling from library/ghost bb79b6b2107f: Already exists 99ce436c3449: Already exists 7f4b5e228565: Pull complete de71eab7febf: Pull complete 29961d2eb573: Pull complete 923f84e249ab: Pull complete dfad6f73fc3d: Pull complete b16cf83b3022: Pull complete 387b2254843c: Pull complete Digest: sha256:fad0c2631cbba3d6c61da6fa5ef39da201780f2ae64ce51f3d5ebb412ca2564b Status: Downloaded newer image for ghost:3.37.1 Starting ghost_ghost_1 ... done Creating ghost_ghost_2 ... done ``` You can check the new Ghost image with the following command: ``` docker images ``` Output: ``` REPOSITORY TAG IMAGE ID CREATED SIZE ghost 3.37.1 c64d108acdfe 3 months ago 439MB ghost 3.36 455ce1645479 4 months ago 440MB ``` You can also check the new Ghost container with the following command: ``` docker ps ``` Output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES c21550f39440 ghost:3.37.1 "docker-entrypoint.s…" 33 seconds ago Up 31 seconds 2368/tcp ghost_ghost_2 d4b51b1aafc8 ghost:3.36 "docker-entrypoint.s…" 4 minutes ago Up 4 minutes 2368/tcp ghost_ghost_1 ``` ## Step 6 – Scale the New Ghost Container At this point, both Ghost containers are running using the same configuration. Now, we will stop and remove the old Ghost container. ``` docker container stop ghost_ghost_1 docker container rm ghost_ghost_1 ``` Now, run the following command to scale down the configuration to its original setting: ``` cd Ghost docker-compose up -d --scale ghost=1 --no-recreate ``` You can also check the new Ghost container log for more information. ``` docker logs ghost_ghost_2 ``` Output: ``` [2021-03-05 04:50:13] INFO Blog is in maintenance mode. [2021-03-05 04:50:13] INFO Ghost is running in production... [2021-03-05 04:50:13] INFO Your site is now available on http://ghost.example.com/ [2021-03-05 04:50:13] INFO Ctrl+C to shut down [2021-03-05 04:50:13] INFO Ghost boot 3.581s [2021-03-05 04:50:13] INFO Creating database backup [2021-03-05 04:50:13] INFO Database backup written to: /var/lib/ghost/content/data/ghost.ghost.2021-03-05-04-50-13.json [2021-03-05 04:50:13] INFO Updating portal button setting to false [2021-03-05 04:50:13] INFO Blog is out of maintenance mode. ``` Your Ghost container is now updated with a new Ghost image. ## Conclusion In the above guide, you learned how to update the Docker container without any downtime. Get started with updating your Docker container on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Dockerize Python Applications With Miniconda > URL: https://www.atlantic.net/vps-hosting/how-to-dockerize-python-applications-with-miniconda/ | Published: 2021-03-02 | Updated: 2023-11-18 | Author: Hitesh Jethva Python is a popular general-purpose programming language used for a wide variety of applications. It is used by software developers as a support language for build control and management, testing, and other purposes. Docker is an open-source containerized platform that allows you to run your application in a lightweight container. This way your application runs in exactly the same manner as it will in production using the same operating system. In this post, we will show you how to dockerize Python applications with Miniconda on CentOS 8. ## Step 1 – Install Docker CE By default, the latest version of Docker CE is not included in the CentOS 8 default repo, so you will need to add a repo from Docker’s official website. You can add it with the following command: ``` dnf config-manager --add-repo=https://download.docker.com/linux/centos/docker-ce.repo ``` Once the repo is created, run the following command to install the Docker CE on your system. ``` dnf install docker-ce --nobest ``` Once the installation is finished, start the Docker service and enable it to start at system reboot with the following command: ``` systemctl start docker systemctl enable docker ``` Next, verify the installed version of Docker with the following command: ``` docker --version ``` You should get the following output: ``` Docker version 20.10.5, build 55c4c88 ``` ## Step 2 – Create a Docker File to Deploy Python App In this section, we will create a directory for the Python project and create a Dockerfile with all required information to deploy the Python app. First, create a directory with the following command: ``` mkdir project ``` Next, change the directory to project and create a Dockerfile with the following command: ``` cd project nano Dockerfile ``` Add the following lines: ``` FROM python:slim RUN apt-get update && apt-get -y upgrade \ && apt-get install -y --no-install-recommends \ git \ wget \ g++ \ ca-certificates \ && rm -rf /var/lib/apt/lists/* ENV PATH="/root/miniconda3/bin:${PATH}" ARG PATH="/root/miniconda3/bin:${PATH}" RUN wget https://repo.anaconda.com/miniconda/Miniconda3-latest-Linux-x86_64.sh \ && mkdir /root/.conda \ && bash Miniconda3-latest-Linux-x86_64.sh -b \ && rm -f Miniconda3-latest-Linux-x86_64.sh \ && echo "Running $(conda --version)" && \ conda init bash && \ . /root/.bashrc && \ conda update conda && \ conda create -n python-app && \ conda activate python-app && \ conda install python=3.6 pip && \ echo 'print("Hello World!")' > python-app.py RUN echo 'conda activate python-app \n\ alias python-app="python python-app.py"' >> /root/.bashrc ENTRYPOINT [ "/bin/bash", "-l", "-c" ] CMD ["python python-app.py"] ``` Save and close the file when you are finished. The above file will download Python minimal image, install Miniconda, create a Python environment, and create a simple Hello World application. ## Step 3 – Build the Python Application Image Now, you will need to build the image using the Dockerfile that we have created in the previous step. First, change the directory to project with the following command: ``` cd project ``` Next, build the Python application by running the following command: ``` docker build -t python-app . ``` You should get the following output: ``` Downloading and Extracting Packages setuptools-52.0.0 | 724 KB | ########## | 100% certifi-2020.12.5 | 140 KB | ########## | 100% python-3.6.13 | 29.7 MB | ########## | 100% pip-21.0.1 | 1.8 MB | ########## | 100% Preparing transaction: ...working... done Verifying transaction: ...working... done Executing transaction: ...working... done Removing intermediate container 10f97804ad82 ---> 3662950574f9 Step 6/8 : RUN echo 'conda activate python-app \nalias python-app="python python-app.py"' >> /root/.bashrc ---> Running in faab9e188650 Removing intermediate container faab9e188650 ---> 8ee98d205c5c Step 7/8 : ENTRYPOINT [ "/bin/bash", "-l", "-c" ] ---> Running in 3e74eb8fd8b7 Removing intermediate container 3e74eb8fd8b7 ---> 6c6d83dfd01f Step 8/8 : CMD ["python python-app.py"] ---> Running in 4d8c066aeefc Removing intermediate container 4d8c066aeefc ---> 78e4f8e7e05e Successfully built 78e4f8e7e05e Successfully tagged python-app:latest ``` You can now check the downloaded images with the following command: ``` docker images ``` You should see all images in the following output: ``` REPOSITORY TAG IMAGE ID CREATED SIZE python-app latest 78e4f8e7e05e 24 seconds ago 907MB python slim ce689abb4f0d 10 days ago 118MB ``` ## Step 4 – Launch the Container At this, point the Python application image is ready. You can now launch the container from the python-app image with the following command: ``` docker run python-app ``` You should see the output of your python application in the following output: ``` Hello World! ``` You can also connect to your Python application container and run the application. To do so, run the container again with the following command: ``` docker run -it python-app /bin/bash ``` You will be connected to the python-app container as shown below: ``` (python-app) root@42e627b899fe:/# ``` Now, run your Python Hello World application using the following command: ``` (python-app) root@42e627b899fe:/# python-app ``` You should get the following output: ``` Hello World! ``` You can also verify your Python version using the following command: ``` (python-app) root@42e627b899fe:/# python --version ``` Output: ``` Python 3.6.13 :: Anaconda, Inc. ``` You can now exit from the container with the following command: ``` (python-app) root@42e627b899fe:/# exit ``` ## Conclusion In the above guide, you learned how to dockerize a Python application with Miniconda on CentOS 8. Now you can deploy your Python application in a lightweight and containerized environment on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net. --- # Atlantic.Net Named to CRN’s Managed Service Provider 500 List > URL: https://www.atlantic.net/press-releases/atlantic-net-named-to-crns-managed-service-provider-500-list/ | Published: 2021-03-02 | Updated: 2026-03-02 | Author: Editorial Team ORLANDO, FLA—March 2, 2021—Atlantic.Net has been named to CRN’s Managed Service Provider 500 list as an MSP Pioneer 250. Atlantic.Net was recognized amongst the **Pioneer 250 list** of top MSPs for 2021 for their continually growing suite of **technological solutions in the cloud** **and for** **providing exceptional services** to small and medium-sized businesses. CRN’s annual MSP500 list recognizes North American solution providers with innovative approaches to managed services. The list is divided into 3 categories, including The **MSP Pioneer 250,** *t*he **MSP Elite 150**, and the **Managed Security 100.**  Every year, The Channel Co. releases its list of top 500 Managed Service providers, which ranks the leading IT channel partner organizations across North America. The CRN Solution Provider 500 list serves as the industry’s leading identifier of top-performing technology integrators and service providers. The MSP 500 list was featured in the February 2021 issue of CRN and online at [www.CRN.com/msp500](https://www.crn.com/rankings-and-lists/msp2021.htm). “We are pleased to be recognized by CRN as a top Pioneer MSP, which further solidifies our standing as a profitable and successful business for over 25 years without any outside funding,” said Marty Puranik, Founder and CEO of Atlantic.Net. “I am proud to be recognized for our continued growth and for our very own cloud platform that we worked very hard to build from the ground-up.” **About The Channel Company** The Channel Company enables breakthrough IT channel performance with our dominant media, engaging events, expert consulting and education, and innovative marketing services and platforms. As the channel catalyst, we connect and empower technology suppliers, solution providers, and end-users. Backed by more than 30 years of unequaled channel experience, we draw from our deep knowledge to envision innovative new solutions for ever-evolving challenges in the technology marketplace. [www.thechannelcompany.com](http://www.thechannelcompany.com/). © 2021. CRN is a registered trademark of The Channel Company, LLC.  All rights reserved. **About Atlantic.Net** Atlantic.Net is a global [cloud services](https://www.atlantic.net/hipaa-compliant-hosting/) provider with over 25 years of experience, serving thousands of developers and small, medium, and large clients in more than one hundred countries. Atlantic.Net specializes in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions and has served dynamic business clients including Lenovo, Newegg, NASA, and Hilton, among others. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions, backed by 24/7/365 support in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. For more information, please visit [Atlantic Net](https://www.atlantic.net/). --- # Postfix Mail Server Setup on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/postfix-mail-server-setup-on-ubuntu-20-04/ | Published: 2021-03-03 | Updated: 2023-11-18 | Author: Hitesh Jethva ![Ubuntu Mail Server - by Walker Cahall](https://www.atlantic.net/wp-content/uploads/2021/03/Ubuntu_mail-server-01-e1635016079166-1024x394.png) Verified and tested 02/27/2021 ### Introduction In this how-to article, we will walk you through building a complete mail server on Ubuntu 20.04 with Postfix. Building a Linux mail server from ground up can be a painful process unless you do it day in and day out, but we are going to show you how to do it as painlessly as we can. A mail server usually consists of a range of different packages that handle SMTP, POP3/IMAP, storage of the mail, and spam-related tasks, and they must all talk together. Here is an outline of the packages and goals for this how-to article. ## 1 – Basic Server Preparation The base installation of Ubuntu comes with a limited set of packages, so the first thing we want to do is install the tools we’ll be using to complete all tasks. First, make sure that you are logged in as the root user account. ``` sudo su - ``` Now, let’s install the basic tools so that we can download files, and edit configuration files easily. ``` apt-get install wget nano ssl-cert ``` > - **wget**: package for retrieving files using HTTP, HTTPS and FTP, the most widely-used Internet protocols. > - **nano**: command line text editor with easy to use controls. > - **ssl-cert**: package that enables the ability to create SSL certificates. Next, we are going to update the hostname and domain name of the server so that when you send email it will match the reverse pointer DNS record that we set up with your hosting provider. We will also update the `/etc/hostname` file. Make sure to replace example with your real hostname and domain name. ``` hostnamectl set-hostname email.linuxbuz.com ``` Now we are going to manually edit the `/etc/hosts` configuration file so that it matches the name we just entered. ``` nano /etc/hosts ``` Edit the first line and add your FQDN (fully qualified domain name) just after the 127.0.0.1 IP address. ``` 127.0.0.1 email.linuxbuz.com localhost ``` We are now going to update the default SSL certificate on the server so that it matches our new hostname. If you purchased an SSL certificate for your mail server, you can skip this step. ``` make-ssl-cert generate-default-snakeoil --force-overwrite ``` This command tells the server to regenerate the default system SSL certificate and forces it to overwrite the original CRT and KEY files. We have now completed the Basic Server Preparation and can move on to installing our web server services. [Back to top] ## 2 – Build out the LAMP Web Server During this step, we are going to install the “LAMP” packages. LAMP stands for Linux, Apache, MySQL, and PHP. These packages combined will enable your server to provide dynamic web services with MySQL connectivity. First, let’s install the packages. This is called a task package installation. ``` apt-get install lamp-server^ ``` > To see a list of the packages that are included in this group install, you can execute the following: > > ``` > tasksel --task-packages lamp-server > ```   After all the packages are installed, we will be ready to install some additional PHP modules. These additional modules will enable your server to support APC User Cache for PHP 5, memcached, cURL, an XML parser, and GD image processing. ``` apt-get install php-apcu php-memcache php-curl php-mbstring php-gd php-xml php-imap php-xmlrpc libdbi-perl libdbd-mysql-perl -y ``` Next, you will need to set the MySQL root password and secure the MySQL installation. You can do it with the following command: ``` mysql_secure_installation ``` Answer all the questions as shown below: ``` New password: Re-enter new password: Do you wish to continue with the password provided?(Press y|Y for Yes, any other key for No) : Y Remove anonymous users? (Press y|Y for Yes, any other key for No) : Y Disallow root login remotely? (Press y|Y for Yes, any other key for No) : Y Reload privilege tables now? (Press y|Y for Yes, any other key for No) : Y ``` Next, log in to MySQL and change the password policy to low: ``` mysql -u root -p SET GLOBAL validate_password.policy = 0; FLUSH PRIVILEGES; EXIT; ``` [Back to top] ## 3 – Configure PHP We are now going to update the configuration of PHP. The default configuration is usually sufficient for most systems; however, we want to make sure that PHP does not expose information to potential attackers. We are going to edit the file `/etc/php/7.4/apache2/php.ini`. ``` nano /etc/php/7.4/apache2/php.ini ``` Locate the variable `expose_php` and update the value from `On` to `Off`. With nano, you can search by pressing `CTRL-W` and then enter your search word. ``` 367 ;;;;;;;;;;;;;;;;; 368 ; Miscellaneous ; 369 ;;;;;;;;;;;;;;;;; 370 371 ; Decides whether PHP may expose the fact that it is installed on the server 372 ; (e.g. by adding its signature to the Web server header). It is no security 373 ; threat in any way, but it makes it possible to determine whether you use PHP 374 ; on your server or not. 375 ; http://php.net/expose-php 376 expose_php = Off 377 ``` [Back to top] ## 4 – Configure Apache2 We are now ready to move on to customizing the configuration of the Apache web services. The end result for Apache is that it will serve a single website with a couple of running web applications: Webmail (RoundCube) and Postfix Admin. All traffic will be directed to HTTPS (secured) web services. First, we are going to minimize the information that Apache exposes to the public. Using nano, we are going to edit the configuration file `/etc/apache2/conf-available/security.conf`. ``` nano /etc/apache2/conf-available/security.conf ``` Search for the configuration variable `ServerTokens` and set the value from `OS` to `Prod`. ``` # ServerTokens # This directive configures what you return as the Server HTTP response # Header. The default is 'Full' which sends information about the OS-Type # and compiled in modules. # Set to one of: Full | OS | Minimal | Minor | Major | Prod # where Full conveys the most information, and Prod the least. #ServerTokens Minimal ServerTokens Prod #ServerTokens Full ``` Now search for the configuration variable `ServerSignature` and set the value from `On` to `Off`. ``` # Optionally add a line containing the server version and virtual host # name to server-generated pages (internal error documents, FTP directory # listings, mod_status and mod_info output etc., but not CGI generated # documents or custom error documents). # Set to "EMail" to also include a mailto: link to the ServerAdmin. # Set to one of: On | Off | EMail ServerSignature Off #ServerSignature On ``` You can now save and exit this configuration file. We are now going to enable the additional modules `rewrite` and `ssl` in Apache so that we can redirect default HTTP traffic to the HTTPS port as well as support SSL certificates within Apache. ``` a2enmod rewrite ssl a2ensite default-ssl ``` We are now moving on to customize the website configuration. These files are located in the directory `/etc/apache2/sites-available`. We are going to update the existing default configuration files to support SSL services. First, edit the configuration file `000-default.conf`. You can replace the existing configuration with the below, just replace the `ServerName` variable with your hostname. ``` nano /etc/apache2/sites-available/000-default.conf ``` ``` # The ServerName directive sets the request scheme, hostname and port that # the server uses to identify itself. This is used when creating # redirection URLs. In the context of virtual hosts, the ServerName # specifies what hostname must appear in the request's Host: header to # match this virtual host. For the default virtual host (this file) this # value is not decisive as it is used as a last resort host regardless. # However, you must set it for any further virtual host explicitly. ServerName email.linuxbuz.com DocumentRoot /var/www/html Options FollowSymLinks AllowOverride All # Available loglevels: trace8, ..., trace1, debug, info, notice, warn, # error, crit, alert, emerg. # It is also possible to configure the loglevel for particular # modules, e.g. LogLevel info ssl:warn ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined # For most configuration files from conf-available/, which are # enabled or disabled at a global level, it is possible to # include a line for only one particular virtual host. For example the # following line enables the CGI configuration for this host only # after it has been globally disabled with "a2disconf". #Include conf-available/serve-cgi-bin.conf ``` You can now save and exit this configuration file. If you have not purchased your own SSL certificate, the system default SSL configuration file `default-ssl.conf` will work for our needs. However, if you have purchased a custom SSL certificate, you will need to edit the configuration file and update the variables `SSLCertificateFile`, `SSLCertificateKeyFile` and `SSLCertificateChainFile` to point to the location where you have saved your certificate and key files (consult your certificate authority or vendor for additional configuration assistance). We are now going to create an `.htaccess` configuration file that will force visitors to your web server to use the HTTPS (SSL) protocol. ``` nano /var/www/html/.htaccess ``` Copy and paste the following variables into the `.htaccess` configuration. ``` RewriteEngine On RewriteCond %{SERVER_PORT} 80 RewriteRule ^(.*) https://%{HTTP_HOST}/$1 [L] ``` These configuration variables tell Apache to enable the mod_rewrite engine, and then to redirect visitors on HTTP (port 80) to the HTTPS (port 443) URL. [Back to top] ## 5 – Install and Configure Memcached Memcached is a high-performance, distributed memory object caching system. This package will help speed up dynamic web applications, such as RoundCube and Postfix Webadmin. First, let’s install the package using apt-get. ``` apt-get install memcached ``` For smaller systems, the default configuration is usually sufficient. It locks down access to the localhost and provides sufficient memory allocation values. However, if you are building a larger server that may get heavy usage, you will most likely want to change the memory allocation values to be higher than the default of 64M. The memcached configuration files is located at `/etc/memcached.conf`. [Back to top] ## 6 – Install the Mailserver Packages We are now ready to install the mail server packages. Again, these are located in a `tasksel` package group. ``` apt-get install mail-server^ ```   > To see a list of the packages that are included in this group install, you can execute the following: > > ``` > tasksel --task-packages mail-server > ``` During the package installation, Postfix will ask you a series of questions: 1. Installation configuration type — You will want to select “**Internet Site**” as the configuration type. 2. Hostname of the mail server — Make sure to enter the same hostname (FQDN) that you used in Step #1 3. Create a self-signed SSL Certificate — Select the ‘Yes’ option 4. Setup the SSL Certificate Common Name — Enter the same hostname (FQDN) that you used in Step #1 We are now going to install the remainder of the packages that are needed for the mail server to support MySQL-based users as well as the Spam and AntiVirus detection packages. (Note: these packages could be installed via a single `apt-get install` command, with each package name separated by a space, but they are presented here as separate commands for ease of reading.) ``` apt-get install postfix-mysql dovecot-mysql dovecot-imapd postgrey apt-get install amavis clamav clamav-daemon spamassassin apt-get install php-imap ``` This next set of optional packages extends the abilities of the anti-spam and antivirus detection packages by allowing greater inspection of attached files that come into your mail server. ``` apt-get install libnet-dns-perl pyzor razor apt-get install arj bzip2 cabextract cpio file gzip nomarch pax unzip zip ``` Now, let’s restart the Apache2 services so that it will see the new modules we have provided it. ``` systemctl restart apache2 ``` [Back to top] ## 7 – Creating a MySQL Database for the Email Server We are now ready to create the database for our user accounts and other mail server functions. To begin, we need to log into the MySQL database service as the root user. You will need that password that you first entered in Step #2. ``` mysql -u root -p ``` You will now see a different command line prompt (`mysql>`). This is the MySQL CLI console where you can manage your MySQL server databases and tables. First, we are going to create a new database named “mail”, and then we will create a system user account with full permissions to this new database. Make sure to replace the `` variable with another *new* secure password for this account. *Do not use the same password that you used for the root user account*. ``` CREATE DATABASE mail; CREATE USER 'mail'@'localhost' IDENTIFIED BY 'mypassword'; GRANT ALL PRIVILEGES ON mail.* TO 'mail'@'localhost' WITH GRANT OPTION; FLUSH PRIVILEGES; EXIT; ``` We have now setup the database that will be used by your mail server services. [Back to top] ## 8 – Installing Postfix Admin [Postfix Admin](http://postfixadmin.sourceforge.net/) is a web-based management tool created for Postfix. It is a PHP-based application that handles Postfix-style virtual domains and users that are stored in MySQL or PostgreSQL. First, we need to download the latest release of the application. This example will download version 2.92–*always check [the version on the provider’s website](http://postfixadmin.sourceforge.net/) to make sure you are getting the latest release*. ``` wget https://excellmedia.dl.sourceforge.net/project/postfixadmin/postfixadmin-3.3.1/PostfixAdmin%203.3.1.tar.gz ``` We are now going to extract the application and copy it to the HTML directory `/var/www/html/postfixadmin` on our server. ``` tar -xvf PostfixAdmin%203.3.1.tar.gz mv postfixadmin-postfixadmin-cc23eba /var/www/html/postfixadmin ``` Now we need to create a template directory and update the permissions of this new folder so that the `www-data` user account has access to it. ``` mkdir /var/www/html/postfixadmin/templates_c chown -R www-data:www-data /var/www/html/postfixadmin ``` [Back to top] ## 9 – Configuring Postfix Admin We now have some configurations to update in the Postfix Admin files. First, we will modify the `config.inc.php` file so that it knows how to communicate with the database that we just created in Step #7. ``` nano /var/www/html/postfixadmin/config.inc.php ``` Search for the variable `'configured'` and reset the value from `false` to `true`. ``` $CONF['configured'] = true; ``` Now search for the variable `'database_'` and replace the values for your MySQL server configuration. Make sure to replace the variable `mypassword` with the password for the database user “mail” that you entered in Step #7. ``` $CONF['database_type'] = 'mysqli'; $CONF['database_host'] = 'localhost'; $CONF['database_user'] = 'mail'; $CONF['database_password'] = 'mypassword'; $CONF['database_name'] = 'mail'; ``` Now search for the variable `'admin_email'` and replace the value with the email address you will setup for your administrator email account. ``` $CONF['admin_email'] = 'admin@linuxbuz.com'; ``` Now search for the variable `'domain_path'` and replace the value from ‘`YES`‘ to ‘`NO`‘. ``` $CONF['domain_path'] = 'NO'; ``` Now search for the variable `'domain_in_mailbox'` and replace the value from ‘`NO`‘ to ‘`YES`‘. ``` $CONF['domain_in_mailbox'] = 'YES'; ``` These last configuration variables do not define the path to where the actual user mailbox data will be stored on the server. These will be defined later during the Dovecot configuration steps. You are now ready to save the configuration file, **but do not exit yet!** We are now going to open a web browser enter the URL of your mail server, pointing directly to the `setup.php` configuration page. *Make sure to replace *mail.example.tld* with your real server hostname.* ``` https://email.linuxbuz.com/postfixadmin/public/setup.php ``` When you access the URL, the script will automatically check the server and confirm that all the prerequisite modules are installed and working. ![Postfix Admin setup checker output](https://www.atlantic.net/wp-content/uploads/2021/03/anet_howto-ubuntu-1404-mailserver-01.png) Postfix Admin setup checker output Once the checks are completed, you will be prompted to enter a setup password. This password is used to create master admin accounts for the Postfix Admin web interface. Enter a secure password and press the “Generate Password Hash” button. ![Postfix Admin generate password hash](https://www.atlantic.net/wp-content/uploads/2021/03/anet_howto-ubuntu-1404-mailserver-02-e1635015532908.png) Postfix Admin generate password hash   ![Postfix Admin example password hash](https://www.atlantic.net/wp-content/uploads/2021/03/anet_howto-ubuntu-1404-mailserver-03.png) Postfix Admin example password hash **Do NOT close the web browser yet! We are coming back here in a few minutes.** After generating the password hash, we will then need to update the `config.inc.php` file again with this password. Search for the variable `'setup_password'` and replace the value with the one generated from the script. ``` // In order to setup Postfixadmin, you MUST specify a hashed password here. // To create the hash, visit setup.php in a browser and type a password into the field, // on submission it will be echoed out to you as a hashed value. $CONF['setup_password'] = ''; ``` You can now save and exit the configuration file. We are now ready to return to the web browser and generate the “super admin” account for the Postfix Admin portal. When you clicked the ‘Generate Password Hash’ button, the form fields changed to look like the example below. You can now fill out the form to generate a super admin account. ![Creating a superadmin account with Postfix Admin](https://www.atlantic.net/wp-content/uploads/2021/03/anet_howto-ubuntu-1404-mailserver-04.png) Creating a superadmin account with Postfix Admin You can also create an admin user with the following command: ``` bash /var/www/html/postfixadmin/scripts/postfixadmin-cli admin add superadmin@linuxbuz.com --superadmin 1 --active 1 --password password@123 --password2 password@123 ``` You should get the following output: ``` Welcome to Postfixadmin-CLI v0.3 --------------------------------------------------------------- The admin superadmin@linuxbuz.com has been added! --------------------------------------------------------------- ``` [Back to top] ## 10 – Adding User Accounts (mailboxes) to Postfix Admin We are now ready to create a virtual user account on our mail server. To do this, we will return to the Postfix Admin URL in our web browser and enter the URL of your mail server. *Make sure to replace *mail.example.tld* with your real server hostname.* ``` https://email.linuxbuz.com/postfixadmin/public ``` You will now be able to log in to the Postfix Admin portal where you can manage virtual domains and virtual user accounts. Enter the super admin username and password that you created above during the Postfix Admin configuration, and then press the “Login” button. ![ Admin login for Postfix Admin](https://www.atlantic.net/wp-content/uploads/2021/03/anet_howto-ubuntu-1404-mailserver-05.png) Admin login for Postfix Admin Once you are logged in to the Postfix Admin portal, you will see a menu at the top of the page. The menu options provide the ability to manage your Postfix mail server virtual domains and users and to view log files. ![Postfix Admin menu](https://www.atlantic.net/wp-content/uploads/2021/03/anet_howto-ubuntu-1404-mailserver-06-e1635039891116.png) Postfix Admin menu ![Postfix Admin Add Mailbox option](https://www.atlantic.net/wp-content/uploads/2021/03/anet_howto-ubuntu-1404-mailserver-07-e1635039936112.png) Postfix Admin Add Mailbox option To create a user mailbox, click the quick link “Add Mailbox.” You will now be taken to the “Add Mailbox Wizard” screen. Fill out the details in the form and press the “Add Mailbox” button once completed. The wizard will create your first virtual user (mailbox) account. ![Creating a new mailbox in Postfix Admin](https://www.atlantic.net/wp-content/uploads/2021/03/anet_howto-ubuntu-1404-mailserver-08-e1635039984601.png) Creating a new mailbox in Postfix Admin [Back to top] ## 11 – Create a System User To Handle Virtual Mail Directories Virtual users are those that don’t technically exist on your Linux server, and they don’t use the standard Linux methods for authentication or mail delivery and storage. Your mail server virtual user accounts are defined within the database created by Postfix Admin rather than existing as system user accounts, so we have to create a single system user account that will handle services like mail storage and Dovecot authentication. First, let’s create a system user account called `vmail` and give it permissions to the required directories. This system account will be responsible for the backend operations for mailbox storage and services. ``` useradd -r -u 150 -g mail -d /var/vmail -s /sbin/nologin -c "Virtual MailDir Handler" vmail mkdir -p /var/vmail chown vmail:mail /var/vmail chmod 770 /var/vmail ``` An explanation of the above commands: 1. We created the system user account `vmail`, assigned the home directory as `/var/vmail`, and restricted the ability for this account to login via shell or console. 2. We then manually created the home directory `/var/vmail` for the new system user account. 3. We then set the owner and group for the `/var/vmail` directory. 4. We then gave full permissions to the system user `vmail` and the security group `mail` assigned to the directory `/var/vmail`. [Back to top] ## 12 – Configuring Dovecot Dovecot is an open-source IMAP and POP3 email server written with security in mind. Dovecot has many built-in features, which you can view at [their public website, http://www.dovecot.org](http://www.dovecot.org). Dovecot will be responsible for managing the IMAP and POP3 connections, managing local mail directories, and receiving the incoming mail handed off from the Postfix SMTP mail server process. Dovecot will also manage the authentication for SMTP connections. Many different files within the `/etc/dovecot` directory handle Dovecot configuration. First, let’s configure Dovecot to use the database set up by Postfix Admin. We will first edit the configuration file `/etc/dovecot/conf.d/auth-sql.conf.ext` ``` nano /etc/dovecot/conf.d/auth-sql.conf.ext ``` Edit or update the contents to have the following configuration. ``` # Look up user passwords from a SQL database as # defined in /etc/dovecot/dovecot-sql.conf.ext passdb { driver = sql args = /etc/dovecot/dovecot-sql.conf.ext } # Look up user information from a SQL database as # defined in /etc/dovecot/dovecot-sql.conf.ext userdb { driver = sql args = /etc/dovecot/dovecot-sql.conf.ext } ``` Once done, save and exit the configuration file. **SQL Configuration File** Now we are going to back up the original SQL configuration file `/etc/dovecot/dovecot-sql.conf.ext` and create a new configuration file for Dovecot to use. ``` mv /etc/dovecot/dovecot-sql.conf.ext /etc/dovecot/dovecot-sql.conf.ext.original nano /etc/dovecot/dovecot-sql.conf.ext ``` Now copy the below content into the configuration file and update the values for the mail database you set up in Step 7. ``` # Database driver: mysql, pgsql, sqlite driver = mysql # Database Connection: # connect = host=192.168.1.1 dbname=users # connect = host=sql.example.com dbname=virtual user=virtual password=blarg # connect = /etc/dovecot/authdb.sqlite # connect = host=localhost dbname=mail user=mail password=mypassword # Default password scheme. # # List of supported schemes is in # http://wiki2.dovecot.org/Authentication/PasswordSchemes # # Weak but common encryption scheme: default_pass_scheme = MD5-CRYPT # # Comment the above out and uncomment below # for stronger encryption: #default_pass_scheme - SHA256-CRYPT # Define the query to obtain a user password. password_query = \ SELECT username as user, password, '/var/vmail/%d/%n' as userdb_home, \ 'maildir:/var/vmail/%d/%n' as userdb_mail, 150 as userdb_uid, 8 as userdb_gid \ FROM mailbox WHERE username = '%u' AND active = '1' # Define the query to obtain user information. user_query = \ SELECT '/var/vmail/%d/%n' as home, 'maildir:/var/vmail/%d/%n' as mail, \ 150 AS uid, 8 AS gid, concat('dirsize:storage=', quota) AS quota \ FROM mailbox WHERE username = '%u' AND active = '1' ``` Once done, save and exit this configuration file. **Authentication Definition File** We are now going to back up the authentication definition file `/etc/dovecot/conf.d/10-auth.conf` and create a new one. ``` mv /etc/dovecot/conf.d/10-auth.conf /etc/dovecot/conf.d/10-auth.conf.original nano /etc/dovecot/conf.d/10-auth.conf ``` Now copy the below content into the definition file. ``` # Disable LOGIN command and all other plaintext authentications unless # SSL/TLS is used (LOGINDISABLED capability). Note that if the remote IP # matches the local IP (ie. you're connecting from the same computer), the # connection is considered secure and plaintext authentication is allowed. disable_plaintext_auth = yes # Space separated list of wanted authentication mechanisms: # plain login digest-md5 cram-md5 ntlm rpa apop anonymous gssapi otp skey # gss-spnego # NOTE: See also disable_plaintext_auth setting. auth_mechanisms = plain login ## ## Password and user databases ## # # Password database is used to verify user's password (and nothing more). # You can have multiple passdbs and userdbs. This is useful if you want to # allow both system users (/etc/passwd) and virtual users to login without # duplicating the system users into virtual database. # # # # User database specifies where mails are located and what user/group IDs # own them. For single-UID configuration use "static" userdb. # # # Use the SQL database configuration rather than any of the others. !include auth-sql.conf.ext ``` Once done, save and exit the file. **Mail Definition File** Next, we are going to tell Dovecot where to store the virtual users’ mail. We will be backing up the mail definition file `/etc/dovecot/conf.d/10-mail.conf` and creating a new one. ``` mv /etc/dovecot/conf.d/10-mail.conf /etc/dovecot/conf.d/10-mail.conf.original nano /etc/dovecot/conf.d/10-mail.conf ``` Now copy the below content into the definition file. ``` # Location for users' mailboxes. The default is empty, which means that Dovecot # tries to find the mailboxes automatically. This won't work if the user # doesn't yet have any mail, so you should explicitly tell Dovecot the full # location. # # If you're using mbox, giving a path to the INBOX file (eg. /var/mail/%u) # isn't enough. You'll also need to tell Dovecot where the other mailboxes are # kept. This is called the "root mail directory", and it must be the first # path given in the mail_location setting. # # There are a few special variables you can use, eg.: # # %u - username # %n - user part in user@domain, same as %u if there's no domain # %d - domain part in user@domain, empty if there's no domain # %h - home directory # # See doc/wiki/Variables.txt for full list. Some examples: # # mail_location = maildir:~/Maildir # mail_location = mbox:~/mail:INBOX=/var/mail/%u # mail_location = mbox:/var/mail/%d/%1n/%n:INDEX=/var/indexes/%d/%1n/%n # # # mail_location = maildir:/var/vmail/%d/%n # System user and group used to access mails. If you use multiple, userdb # can override these by returning uid or gid fields. You can use either numbers # or names. mail_uid = vmail mail_gid = mail # Valid UID range for users, defaults to 500 and above. This is mostly # to make sure that users can't log in as daemons or other system users. # Note that denying root logins is hardcoded to dovecot binary and can't # be done even if first_valid_uid is set to 0. # # Use the vmail user uid here. first_valid_uid = 150 last_valid_uid = 150 # If you need to set multiple mailbox locations or want to change default # namespace settings, you can do it by defining namespace sections. # # You can have private, shared and public namespaces. Private namespaces # are for user's personal mails. Shared namespaces are for accessing other # users' mailboxes that have been shared. Public namespaces are for shared # mailboxes that are managed by sysadmin. If you create any shared or public # namespaces you'll typically want to enable ACL plugin also, otherwise all # users can access all the shared mailboxes, assuming they have permissions # on filesystem level to do so. namespace inbox { # Namespace type: private, shared or public #type = private # Hierarchy separator to use. You should use the same separator for all # namespaces or some clients get confused. '/' is usually a good one. # The default however depends on the underlying mail storage format. #separator = # Prefix required to access this namespace. This needs to be different for # all namespaces. For example "Public/". #prefix = # Physical location of the mailbox. This is in same format as # mail_location, which is also the default for it. #location = # There can be only one INBOX, and this setting defines which namespace # has it. inbox = yes # If namespace is hidden, it's not advertised to clients via NAMESPACE # extension. You'll most likely also want to set list=no. This is mostly # useful when converting from another server with different namespaces which # you want to deprecate but still keep working. For example you can create # hidden namespaces with prefixes "~/mail/", "~%u/mail/" and "mail/". #hidden = no # Show the mailboxes under this namespace with LIST command. This makes the # namespace visible for clients that don't support NAMESPACE extension. # "children" value lists child mailboxes, but hides the namespace prefix. #list = yes # Namespace handles its own subscriptions. If set to "no", the parent # namespace handles them (empty prefix should always have this as "yes") #subscriptions = yes } ``` Once done, save and exit the file. **SSL Definition File** If you have an SSL certificate that you would like to install, you will need to modify the Dovecot SSL definition file `/etc/dovecot/conf.d/10-ssl.conf` with your valid certificate. Remember, you will have to also include your CA certificate bundle if one has been provided by the certificate issuer. **Dovecot Master Definition File** We are now going to update the Dovecot master definition file `/etc/dovecot/10-master.conf` to include the system user account and the postfix settings. ``` nano /etc/dovecot/conf.d/10-master.conf ``` Search for the config definition `service auth` and replace the definition block with the following. ``` service auth { # auth_socket_path points to this userdb socket by default. It's typically # used by dovecot-lda, doveadm, possibly imap process, etc. Users that have # full permissions to this socket are able to get a list of all usernames and # get the results of everyone's userdb lookups. # # The default 0666 mode allows anyone to connect to the socket, but the # userdb lookups will succeed only if the userdb returns an "uid" field that # matches the caller process's UID. Also if caller's uid or gid matches the # socket's uid or gid the lookup succeeds. Anything else causes a failure. # # To give the caller full permissions to lookup all users, set the mode to # something else than 0666 and Dovecot lets the kernel enforce the # permissions (e.g. 0777 allows everyone full permissions). unix_listener auth-userdb { mode = 0600 user = vmail group = mail } # Postfix smtp-auth unix_listener /var/spool/postfix/private/auth { mode = 0660 # Assuming the default Postfix userid and groupid user = postfix group = postfix } } ``` Once done, save and exit the file. **LDA Definition File** In some cases, you may have to explicitly define the postmaster email address for your server. To do this, you will need to edit the LDA definition file `/etc/dovecot/conf.d/15-lda.conf`. If you see error messages like `Invalid settings: postmaster_address setting not given` showing up in the mail server logs, then this configuration change is the likely fix for that error. ``` nano /etc/dovecot/conf.d/15-lda.conf ``` Search for the definition `postmaster_address` and update the value to include your domain’s postmaster account. ``` # Address to use when sending rejection mails. # Default is postmaster@. %d expands to recipient domain. #postmaster_address = postmaster_address = postmaster@linuxbuz.com ``` Once done, save and exit the file. We now need to update the Dovecot configuration directory to be accessible to the Dovecot service account as well as the vmail system account. ``` chown -R vmail:dovecot /etc/dovecot chmod -R o-rwx /etc/dovecot ``` You have now completed the configuration of the Dovecot service and we can now move on to the antivirus and anti-spam services. [Back to top] ## 13 – Configuring Amavis, ClamAV, and SpamAssassin What are these packages? – [Amavis](http://amavis.sourceforge.net/) is an interface between Postfix and content filtering packages such as SpamAssassin and ClamAV. – [ClamAV](http://www.clamav.net/) is a high-performance antivirus engine for detecting trojans, viruses, malware & other malicious threats. – [SpamAssassin](http://spamassassin.apache.org/) is a high-performance anti-spam platform famous for its Bayesian spam filtering capabilities. It gives system administrators a filter to classify messages and block unsolicited bulk email. We will now walk you through the process of installing some protection for your mail server. For the most part, the default configurations are sufficient for a good line of defense against spam and viruses getting through your mail server. If you have special requirements, you can, of course, spend a good amount of time crafting intricate processing rules. Let’s first create the two system user accounts, amavis and clamav, and allow them to collaborate together. ``` adduser clamav amavis adduser amavis clamav ``` We are now going to enable the Amavis daemon by editing the `/etc/amavis/conf.d/15-content_filter_mode` configuration file. ``` nano /etc/amavis/conf.d/15-content_filter_mode ``` By default, the Amavis software is disabled. To enable the Amavis software, all you need to do is remove the comment tags from the `bypass` configuration lines. ``` use strict; # You can modify this file to re-enable SPAM checking through spamassassin # and to re-enable antivirus checking. # # Default antivirus checking mode # Please note, that anti-virus checking is DISABLED by # default. # If You wish to enable it, please uncomment the following lines: @bypass_virus_checks_maps = ( %bypass_virus_checks, @bypass_virus_checks_acl, $bypass_virus_checks_re); # # Default SPAM checking mode # Please note, that anti-spam checking is DISABLED by # default. # If You wish to enable it, please uncomment the following lines: @bypass_spam_checks_maps = ( %bypass_spam_checks, @bypass_spam_checks_acl, $bypass_spam_checks_re); 1; # ensure a defined return ``` Once done, you can save and exit the file. We are now going to enable the SpamAssassin software by editing the `/etc/default/spamassassin` configuration file. ``` nano /etc/default/spamassassin ``` Now search for the variable `CRON=0` in the configuration file and change the value to 1. ``` # Cronjob # Set to anything but 0 to enable the cron job to automatically update # spamassassin's rules on a nightly basis CRON=1 ``` Next, enable the SpamAssassin software with the following command: ``` update-rc.d spamassassin enable ``` We are now going to set up Amavis to use the database from Postfix Admin to identify mail that is arriving for local delivery. By default, SpamAssassin and Amavis will only check mail that is determined to be arriving for local delivery. Because we are set up to use virtual user mailboxes, we have to tell the services where to locate the user accounts. To do this, we need to update the configuration file `/etc/amavis/conf.d/50-user`. ``` nano /etc/amavis/conf.d/50-user ``` Replace the contents of this configuration file with the below. Be sure to update the MySQL database password to use the password for the database user “mail” that you entered in Step #7. ``` use strict; # # Place your configuration directives here. They will override those in # earlier files. # # See /usr/share/doc/amavisd-new/ for documentation and examples of # the directives you can use in this file # # Three concurrent processes. This should fit into the RAM available on an # AWS micro instance. This has to match the number of processes specified # for Amavis in /etc/postfix/master.cf. $max_servers = 3; # Add spam info headers if at or above that level - this ensures they # are always added. $sa_tag_level_deflt = -9999; # Check the database to see if mail is for local delivery, and thus # should be spam checked. @lookup_sql_dsn = ( ['DBI:mysql:database=mail;host=127.0.0.1;port=3306', 'mail', 'mypassword']); $sql_select_policy = 'SELECT domain from domain WHERE CONCAT("@",domain) IN (%k)'; # Uncomment to bump up the log level when testing. # $log_level = 2; #------------ Do not modify anything below this line ------------- 1; # ensure a defined return ``` Once done, save and exit the configuration file. We will now need to restart the Amavis and SpamAssassin services so that they see the new configuration settings. ``` service amavis restart services spamassassin restart ``` [Back to top] ## 14 – Configuring Postfix We are now ready to configure the Postfix mail server. Postfix handles all of the incoming and outgoing mail via the SMTP protocol, and we are going to configure it to integrate will all of the other software packages that we have just configured. From a high level view, we are needing Postfix to hand off incoming mail to the SpamAssassin and ClamAV scanners for filtering, and then to pass unblocked mail messages on to the Dovecot services for final mailbox delivery. Postfix will also authenticate the virtual users who connect via SMTP in order to send email messages. We are going to create a definition file for Postfix to identify users and mailboxes. Please note that the “hosts” directive in these configuration files must be exactly the same as the “bind-address” in the `/etc/mysql/my.cnf` configuration files. First, let’s look up the value of the bind-address in the MySQL configuration files. ``` cat /etc/mysql/mysql.conf.d/mysqld.cnf | grep bind-address ``` ``` << output >> bind-address = 127.0.0.1 ``` Now that we have the configuration value, we are going to create the required Postfix definition files. Copy and paste the content for each file. Make sure to update the password value with the password for the database user “mail” that you entered in Step #7. #### /etc/postfix/mysql_virtual_ #### alias_domainaliases_maps.cf /etc/postfix/mysql_virtual_alias_maps.cf ``` user = mail password = mypassword hosts = 127.0.0.1 dbname = mail query = SELECT goto FROM alias,alias_domain WHERE alias_domain.alias_domain = '%d' AND alias.address=concat('%u', '@', alias_domain.target_domain) AND alias.active = 1 ``` Once done, save and exit the configuration file. #### /etc/postfix/ #### mysql_virtual_alias_maps.cf ``` nano /etc/postfix/mysql_virtual_alias_maps.cf ``` ``` user = mail password = mypassword hosts = 127.0.0.1 dbname = mail table = alias select_field = goto where_field = address additional_conditions = and active = '1' ``` Once done, save and exit the configuration file. #### /etc/postfix/ #### mysql_virtual_domains_maps.cf ``` user = mail password = mypassword hosts = 127.0.0.1 dbname = mail table = domain select_field = domain where_field = domain additional_conditions = and backupmx = '0' and active = '1' ``` Once done, save and exit the configuration file. #### /etc/postfix/mysql_virtual #### _mailbox_domainaliases_maps.cf ``` user = mail password = mypassword hosts = 127.0.0.1 dbname = mail query = SELECT maildir FROM mailbox, alias_domain WHERE alias_domain.alias_domain = '%d' AND mailbox.username=concat('%u', '@', alias_domain.target_domain ) AND mailbox.active = 1 ``` Once done, save and exit the configuration file. #### /etc/postfix/mysql_ #### virtual_mailbox_maps.cf ``` user = mail password = mypassword hosts = 127.0.0.1 dbname = mail table = mailbox select_field = CONCAT(domain, '/', local_part) where_field = username additional_conditions = and active = '1' ``` Once done, save and exit the configuration file. We are now going to create the Postfix header-checking directives. These directives remove certain headers when relaying mail through the system. This helps improve privacy for sending users by removing specific headers like origin IP Address and the mail software identifiers. Copy and paste the below content into the file. ``` nano /etc/postfix/header_checks ``` ``` /^Received:/ IGNORE /^User-Agent:/ IGNORE /^X-Mailer:/ IGNORE /^X-Originating-IP:/ IGNORE /^x-cr-[a-z]*:/ IGNORE /^Thread-Index:/ IGNORE ``` Once done, save and exit. We are now ready to make some changes to the system default Postfix `/etc/postfix/main.cf` configuration file. > This file contains a large amount of complex choices and options for a Postfix server installation. It is far beyond the scope of this article to explain every option or best practice available, so we strongly suggest that you read through the Postfix configuration options `/usr/share/postfix/main.cf.dist` or the [software vendor online manual](http://www.postfix.org/postconf.5.html). O’Reilly has also published a very good book named [*Postfix: The Definitive Guide*](http://shop.oreilly.com/product/9780596002121.do). First, we are going to create a backup of the original `main.cf` configuration file and then create a new copy of the file. ``` mv /etc/postfix/main.cf /etc/postfix/main.cf.original nano /etc/postfix/main.cf ``` Now, copy the below content into the `/etc/postfix/main.cf` configuration file. ``` # See /usr/share/postfix/main.cf.dist for a commented, more complete version # The first text sent to a connecting process. smtpd_banner = $myhostname ESMTP $mail_name biff = no # appending .domain is the MUA's job. append_dot_mydomain = no readme_directory = no # SASL parameters # --------------------------------- # Use Dovecot to authenticate. smtpd_sasl_type = dovecot # Referring to /var/spool/postfix/private/auth smtpd_sasl_path = private/auth smtpd_sasl_auth_enable = yes broken_sasl_auth_clients = yes smtpd_sasl_security_options = noanonymous smtpd_sasl_local_domain = smtpd_sasl_authenticated_header = yes # TLS parameters # --------------------------------- # Replace this with your SSL certificate path if you are using one. smtpd_tls_cert_file=/etc/ssl/certs/ssl-cert-snakeoil.pem smtpd_tls_key_file=/etc/ssl/private/ssl-cert-snakeoil.key # The snakeoil self-signed certificate has no need for a CA file. But # if you are using your own SSL certificate, then you probably have # a CA certificate bundle from your provider. The path to that goes # here. #smtpd_tls_CAfile=/path/to/ca/file smtp_tls_note_starttls_offer = yes smtpd_tls_loglevel = 1 smtpd_tls_received_header = yes smtpd_tls_session_cache_timeout = 3600s tls_random_source = dev:/dev/urandom #smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache #smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache # Note that forcing use of TLS is going to cause breakage - most mail servers # don't offer it and so delivery will fail, both incoming and outgoing. This is # unfortunate given what various governmental agencies are up to these days. # These are Postfix 2.2 only. # # Enable (but don't force) use of TLS on incoming smtp connections. smtpd_use_tls = yes smtpd_enforce_tls = no # Enable (but don't force) use of TLS on outgoing smtp connections. smtp_use_tls = yes smtp_enforce_tls = no # These are Postfix 2.3 and later. # # Enable (but don't force) all incoming smtp connections to use TLS. smtpd_tls_security_level = may # Enable (but don't force) all outgoing smtp connections to use TLS. smtp_tls_security_level = may # See /usr/share/doc/postfix/TLS_README.gz in the postfix-doc package for # information on enabling SSL in the smtp client. # SMTPD parameters # --------------------------------- # Uncomment the next line to generate "delayed mail" warnings #delay_warning_time = 4h # will it be a permanent error or temporary unknown_local_recipient_reject_code = 450 # how long to keep message on queue before return as failed. # some have 3 days, I have 16 days as I am backup server for some people # whom go on holiday with their server switched off. maximal_queue_lifetime = 7d # max and min time in seconds between retries if connection failed minimal_backoff_time = 1000s maximal_backoff_time = 8000s # how long to wait when servers connect before receiving rest of data smtp_helo_timeout = 60s # how many address can be used in one message. # effective stopper to mass spammers, accidental copy in whole address list # but may restrict intentional mail shots. smtpd_recipient_limit = 16 # how many error before back off. smtpd_soft_error_limit = 3 # how many max errors before blocking it. smtpd_hard_error_limit = 12 # This next set are important for determining who can send mail and relay mail # to other servers. It is very important to get this right - accidentally producing # an open relay that allows unauthenticated sending of mail is a Very Bad Thing. # # You are encouraged to read up on what exactly each of these options accomplish. # Requirements for the HELO statement smtpd_helo_restrictions = permit_mynetworks, warn_if_reject reject_non_fqdn_hostname, reject_invalid_hostname, permit # Requirements for the sender details smtpd_sender_restrictions = permit_sasl_authenticated, permit_mynetworks, warn_if_reject reject_non_fqdn_sender, reject_unknown_sender_domain, reject_unauth_pipelining, permit # Requirements for the connecting server # This is primarily the RBL (Realtime Blacklist) Filtering smtpd_client_restrictions = reject_rbl_client b.barracudacentral.org, reject_rbl_client zen.spamhaus.org, reject_rbl_client spam.dnsbl.sorbs.net # Requirement for the recipient address. Note that the entry for # "check_policy_service inet:127.0.0.1:10023" enables Postgrey. smtpd_recipient_restrictions = reject_unauth_pipelining, permit_mynetworks, permit_sasl_authenticated, reject_non_fqdn_recipient, reject_unknown_recipient_domain, reject_unauth_destination, check_policy_service inet:127.0.0.1:10023, permit smtpd_data_restrictions = reject_unauth_pipelining # This is a new option as of Postfix 2.10+, and is required in addition to # smtpd_recipient_restrictions for things to work properly in this setup. smtpd_relay_restrictions = reject_unauth_pipelining, permit_mynetworks, permit_sasl_authenticated, reject_non_fqdn_recipient, reject_unknown_recipient_domain, reject_unauth_destination, check_policy_service inet:127.0.0.1:10023, permit # require proper helo at connections smtpd_helo_required = yes # waste spammers time before rejecting them smtpd_delay_reject = yes disable_vrfy_command = yes # General host and delivery info # ---------------------------------- myhostname = email.linuxbuz.com myorigin = /etc/hostname # Some people see issues when setting mydestination explicitly to the server # subdomain, while leaving it empty generally doesn't hurt. So it is left empty here. # mydestination = mail.example.com, localhost mydestination = # If you have a separate web server that sends outgoing mail through this # mailserver, you may want to add its IP address to the space-delimited list in # mynetworks, e.g. as 111.222.333.444/32. mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128 mailbox_size_limit = 0 recipient_delimiter = + inet_interfaces = all mynetworks_style = host # This specifies where the virtual mailbox folders will be located. virtual_mailbox_base = /var/vmail # This is for the mailbox location for each user. The domainaliases # map allows us to make use of Postfix Admin's domain alias feature. virtual_mailbox_maps = mysql:/etc/postfix/mysql_virtual_mailbox_maps.cf, mysql:/etc/postfix/mysql_virtual_mailbox_domainaliases_maps.cf # and their user id virtual_uid_maps = static:150 # and group id virtual_gid_maps = static:8 # This is for aliases. The domainaliases map allows us to make # use of Postfix Admin's domain alias feature. virtual_alias_maps = mysql:/etc/postfix/mysql_virtual_alias_maps.cf, mysql:/etc/postfix/mysql_virtual_alias_domainaliases_maps.cf # This is for domain lookups. virtual_mailbox_domains = mysql:/etc/postfix/mysql_virtual_domains_maps.cf # Integration with other packages # --------------------------------------- # Tell postfix to hand off mail to the definition for dovecot in master.cf virtual_transport = dovecot dovecot_destination_recipient_limit = 1 # Use amavis for virus and spam scanning content_filter = amavis:[127.0.0.1]:10024 # Header manipulation # -------------------------------------- # Getting rid of unwanted headers. See: https://posluns.com/guides/header-removal/ header_checks = regexp:/etc/postfix/header_checks # getting rid of x-original-to enable_original_recipient = no ``` Once done, save and exit. We are now ready to move on to the Postfix `/etc/postfix/master.cf` configuration file. This configuration file also contains a large number of complex choices and options for a Postfix server installation that is far beyond the scope of this article to explain. We are going to create a backup of the original `master.cf` configuration file and then create a new file. ``` mv /etc/postfix/master.cf /etc/postfix/master.cf.original nano /etc/postfix/master.cf ``` Now, copy the below content into the `/etc/postfix/master.cf` configuration file. ``` # # Postfix master process configuration file. For details on the format # of the file, see the master(5) manual page (command: "man 5 master"). # # Do not forget to execute "postfix reload" after editing this file. # # ========================================================================== # service type private unpriv chroot wakeup maxproc command + args # (yes) (yes) (yes) (never) (100) # ========================================================================== # SMTP on port 25, unencrypted. smtp inet n - - - - smtpd #smtp inet n - - - 1 postscreen #smtpd pass - - - - - smtpd #dnsblog unix - - - - 0 dnsblog #tlsproxy unix - - - - 0 tlsproxy # SMTP with TLS on port 587. submission inet n - - - - smtpd -o syslog_name=postfix/submission -o smtpd_tls_security_level=encrypt -o smtpd_sasl_auth_enable=yes -o smtpd_enforce_tls=yes -o smtpd_client_restrictions=permit_sasl_authenticated,reject_unauth_destination,reject -o smtpd_sasl_tls_security_options=noanonymous # SMTP over SSL on port 465. smtps inet n - - - - smtpd -o syslog_name=postfix/smtps -o smtpd_tls_wrappermode=yes -o smtpd_sasl_auth_enable=yes -o smtpd_tls_auth_only=yes -o smtpd_client_restrictions=permit_sasl_authenticated,reject_unauth_destination,reject -o smtpd_sasl_security_options=noanonymous,noplaintext -o smtpd_sasl_tls_security_options=noanonymous #628 inet n - - - - qmqpd pickup fifo n - - 60 1 pickup -o content_filter= -o receive_override_options=no_header_body_checks cleanup unix n - - - 0 cleanup qmgr fifo n - n 300 1 qmgr #qmgr fifo n - n 300 1 oqmgr tlsmgr unix - - - 1000? 1 tlsmgr rewrite unix - - - - - trivial-rewrite bounce unix - - - - 0 bounce defer unix - - - - 0 bounce trace unix - - - - 0 bounce verify unix - - - - 1 verify flush unix n - - 1000? 0 flush proxymap unix - - n - - proxymap proxywrite unix - - n - 1 proxymap smtp unix - - - - - smtp relay unix - - - - - smtp # -o smtp_helo_timeout=5 -o smtp_connect_timeout=5 showq unix n - - - - showq error unix - - - - - error retry unix - - - - - error discard unix - - - - - discard local unix - n n - - local virtual unix - n n - - virtual lmtp unix - - - - - lmtp anvil unix - - - - 1 anvil scache unix - - - - 1 scache # # ==================================================================== # Interfaces to non-Postfix software. Be sure to examine the manual # pages of the non-Postfix software to find out what options it wants. # # Many of the following services use the Postfix pipe(8) delivery # agent. See the pipe(8) man page for information about ${recipient} # and other message envelope options. # ==================================================================== # # maildrop. See the Postfix MAILDROP_README file for details. # Also specify in main.cf: maildrop_destination_recipient_limit=1 # maildrop unix - n n - - pipe flags=DRhu user=vmail argv=/usr/bin/maildrop -d ${recipient} # # ==================================================================== # # Recent Cyrus versions can use the existing "lmtp" master.cf entry. # # Specify in cyrus.conf: # lmtp cmd="lmtpd -a" listen="localhost:lmtp" proto=tcp4 # # Specify in main.cf one or more of the following: # mailbox_transport = lmtp:inet:localhost # virtual_transport = lmtp:inet:localhost # # ==================================================================== # # Cyrus 2.1.5 (Amos Gouaux) # Also specify in main.cf: cyrus_destination_recipient_limit=1 # #cyrus unix - n n - - pipe # user=cyrus argv=/cyrus/bin/deliver -e -r ${sender} -m ${extension} ${user} # # ==================================================================== # Old example of delivery via Cyrus. # #old-cyrus unix - n n - - pipe # flags=R user=cyrus argv=/cyrus/bin/deliver -e -m ${extension} ${user} # # ==================================================================== # # See the Postfix UUCP_README file for configuration details. # uucp unix - n n - - pipe flags=Fqhu user=uucp argv=uux -r -n -z -a$sender - $nexthop!rmail ($recipient) # # Other external delivery methods. # ifmail unix - n n - - pipe flags=F user=ftn argv=/usr/lib/ifmail/ifmail -r $nexthop ($recipient) bsmtp unix - n n - - pipe flags=Fq. user=bsmtp argv=/usr/lib/bsmtp/bsmtp -t$nexthop -f$sender $recipient scalemail-backend unix - n n - 2 pipe flags=R user=scalemail argv=/usr/lib/scalemail/bin/scalemail-store ${nexthop} ${user} ${extension} mailman unix - n n - - pipe flags=FR user=list argv=/usr/lib/mailman/bin/postfix-to-mailman.py ${nexthop} ${user} # The next two entries integrate with Amavis for anti-virus/spam checks. amavis unix - - - - 3 smtp -o smtp_data_done_timeout=1200 -o smtp_send_xforward_command=yes -o disable_dns_lookups=yes -o max_use=20 127.0.0.1:10025 inet n - - - - smtpd -o content_filter= -o local_recipient_maps= -o relay_recipient_maps= -o smtpd_restriction_classes= -o smtpd_delay_reject=no -o smtpd_client_restrictions=permit_mynetworks,reject -o smtpd_helo_restrictions= -o smtpd_sender_restrictions= -o smtpd_recipient_restrictions=permit_mynetworks,reject -o smtpd_data_restrictions=reject_unauth_pipelining -o smtpd_end_of_data_restrictions= -o mynetworks=127.0.0.0/8 -o smtpd_error_sleep_time=0 -o smtpd_soft_error_limit=1001 -o smtpd_hard_error_limit=1000 -o smtpd_client_connection_count_limit=0 -o smtpd_client_connection_rate_limit=0 -o receive_override_options=no_header_body_checks,no_unknown_recipient_checks # Integration with Dovecot - hand mail over to it for local delivery, and # run the process under the vmail user and mail group. dovecot unix - n n - - pipe flags=DRhu user=vmail:mail argv=/usr/lib/dovecot/dovecot-lda -d $(recipient) ``` Once done, save and exit. We are now ready to restart all of the mail services and test the server. ``` service postfix restart service spamassassin restart service clamav-daemon restart service amavis restart service dovecot restart ``` While testing your new mail server, make sure to watch the log files closely for any errors or unusual responses. The mail server log files are located here: - General Logging: `/var/log/mail.log` - Error Logging: `/var/log/mail.err` [Back to top] ## 15 – Reverse DNS Lookup You will now need to set up reverse DNS lookup for your mail server. Reverse DNS is IP-address-to-domain-name mapping – the opposite of forward (normal) DNS which maps domain names to IP addresses. Reverse DNS is mostly used by people for such things as tracking where a website visitor came from or where an email message originated, for example. Reverse DNS is also important for mail server applications. Many email servers on the Internet are configured to reject incoming emails from any IP address which does not have reverse DNS record configured. Unless you also administer your own DNS server, you can update reverse DNS with your ISP (Internet Service Provider) or via the hosting provider of your server. [Back to top] ## 16 – Install RoundCube Webmail Now we are going to install the [RoundCube Webmail](https://roundcube.net/) application. This application will allow your remote users to connect to their mailbox through a web browser. ``` apt-get install roundcube roundcube-mysql roundcube-plugins roundcube-plugins-extra ``` During the installation process, the system will ask you the prerequisite install questions. Note: you will need the password for the MySQL *root* user you set up in Step 2. ``` Configure database for roundcube with dbconfig-common? >> Select 'YES' Database type to be used by roundcube: >> Select 'mysql' Password of the database's administrative user: >> Enter the 'root' MySQL password that you created. MySQL application password for roundcube: >> Enter a new secure password for the RoundCube application to use. ``` Once you are finished with the pre-installation questions, you should see the following output. Double check the output to make sure there are not errors posted during the installation process. ``` dbconfig-common: writing config to /etc/dbconfig-common/roundcube.conf Creating config file /etc/dbconfig-common/roundcube.conf with new version Creating config file /etc/roundcube/debian-db.php with new version granting access to database roundcube for roundcube@localhost: success. verifying access for roundcube@localhost: success. creating database roundcube: success. verifying database roundcube exists: success. populating database via sql... done. dbconfig-common: flushing administrative password Creating config file /etc/roundcube/config.inc.php with new version apache2_invoke: Enable configuration roundcube.conf * Reloading web server apache2 * * Reloading web server apache2 * Setting up roundcube (1.4.3) ... Setting up roundcube-plugins (1.4.3) ... Setting up roundcube-plugins-extra (0.9.2-20130819) ... Processing triggers for dictionaries-common (1.20.5) ... aspell-autobuildhash: processing: en [en-common] aspell-autobuildhash: processing: en [en-variant_0] aspell-autobuildhash: processing: en [en-variant_1] aspell-autobuildhash: processing: en [en-variant_2] aspell-autobuildhash: processing: en [en-w_accents-only] aspell-autobuildhash: processing: en [en-wo_accents-only] aspell-autobuildhash: processing: en [en_CA-variant_0] aspell-autobuildhash: processing: en [en_CA-variant_1] aspell-autobuildhash: processing: en [en_CA-w_accents-only] aspell-autobuildhash: processing: en [en_CA-wo_accents-only] aspell-autobuildhash: processing: en [en_GB-ise-w_accents-only] aspell-autobuildhash: processing: en [en_GB-ise-wo_accents-only] aspell-autobuildhash: processing: en [en_GB-ize-w_accents-only] aspell-autobuildhash: processing: en [en_GB-ize-wo_accents-only] aspell-autobuildhash: processing: en [en_GB-variant_0] aspell-autobuildhash: processing: en [en_GB-variant_1] aspell-autobuildhash: processing: en [en_US-w_accents-only] aspell-autobuildhash: processing: en [en_US-wo_accents-only] Setting up aspell (0.60.7~20110707-1ubuntu1) ... Processing triggers for dictionaries-common (1.20.5) ... Setting up aspell-en (7.1-0-1) ... Processing triggers for libc-bin (2.19-0ubuntu6.6) ... Processing triggers for dictionaries-common (1.20.5) ... root@host# ``` Next, we need to customize some of the RoundCube configuration files. First, we are going to add the RoundCube application into our current Apache configuration files using path alias directives. The default configuration file is installed at `/etc/apache2/conf-available/roundcube.conf` ``` nano /etc/apache2/conf-available/roundcube.conf ``` We now need to remove the two comment flags in front of the alias directives. If you would like to use a different alias name, you can change that here as well. The default alias will use the URL `http:///roundcube/` ``` Alias /roundcube/program/js/tiny_mce/ /usr/share/tinymce/www/ Alias /roundcube /var/lib/roundcube ``` Once done, save and exit the file. Now we are going to modify the `/etc/roundcube/config.inc.php` configuration file. This file is where you can customize the RoundCube advanced settings. ``` nano /etc/roundcube/config.inc.php ``` Locate the following directives and update the values to match the following. ``` $config['default_host'] = ''; $config['smtp_server'] = 'localhost'; $config['smtp_port'] = 25; $config['smtp_user'] = '%u'; $config['smtp_pass'] = '%p'; $config['support_url'] = ''; ``` Once done, save and exit the configuration file. Finally, restart the apache service to apply the changes: ``` systemctl restart apache2 ``` You should now be able to use your new RoundCube webmail application for sending and receiving message. [Back to top] ### Congratulations! You have now set up a fully functional and secure mail server on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net. Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [Virtual private servers.](https://www.atlantic.net/vps-hosting/) --- # Should Your VPS-Hosted Website Use WordPress, Joomla, or Drupal? > URL: https://www.atlantic.net/vps-hosting/should-your-vps-hosted-website-use-wordpress-joomla-or-drupal/ | Published: 2021-03-08 | Updated: 2025-09-19 | Author: Alexander Wise When you first began entertaining the idea of creating a website, you may not have realized how many choices you would have to make. Many decisions need to be made when designing a website. One of your first choices will be whether to use a dedicated physical server, a Virtual Private Server (VPS), or a shared hosting arrangement. Another option that meets some more advanced customers’ needs is a bare metal solution which can be addressed with physical resources in conjunction with virtual resources. While a shared hosting solution may initially be less expensive, it limits the degree of customization that can be performed on your website. In many cases, you will find that a VPS offering is the most attractive as it provides the best combination of security, scalability, and customization at a reasonable price point. It’s the most flexible, functional, and economical way to host your website. One of the most important decisions you will make regarding your website is the content management system (CMS) that will be used to organize and display the information on your site. We are going to look at three of the most popular CMS solutions and provide information that allows you to make an informed choice regarding which one best suits your needs and level of technical expertise. ## What is a CMS? A CMS is an application that is used to build and manage a website without the need to perform extensive coding. You can create, manage, and publish content easily through the solution’s user-friendly interface. Much of the customization you want to do can be accomplished through templates or extensions instead of digging into the code. Multiple users can be granted different levels of authority over the processes required to create, modify, and publish information on the website. A CMS is made up of two core components. The content management application (CMA) is the part you interact with when adding and managing the website’s content. When you add a new page to your site, you are using the CMA. A content delivery application (CDA) works in the background, storing the input to the CMA and displaying it to your visitors. There are substantial differences in the functionality and complexity of competing CMS solutions. Making the wrong initial choice in a content management system can make it extremely difficult to migrate your website to a different platform. It can also be frustrating either because it is too complex or does not support all of the features you would like to implement. The selection of your CMS must be made carefully. ## Three Popular Content Management System Solutions WordPress, Joomla, and Drupal are three popular, open-source CMS solutions for building VPS-hosted websites. The three platforms support MySQL as their database management system and are primarily written in PHP. Themes, plugins, and extensions are used extensively to add customization and functionality in each of these community-driven content management systems. Each solution has strengths and weaknesses that may make them a more attractive option for different types of users. Let’s take an objective look at how these three CMS platforms address the needs of VPS-hosted [website builders](https://www.shno.co/blog/free-website-builders-with-custom-domain). ### [WordPress](https://wordpress.org/) Let’s investigate WordPress first. [WordPress is currently the most popular CMS](https://trends.builtwith.com/cms) and dominates the market. It has reached this level of acceptance for many very good reasons, but it is not without its flaws. Let’s begin by identifying the strong points of using WordPress as your CMS. - **User-friendliness** – The WordPress dashboard is reasonably intuitive and makes it easy for users to create or edit posts, format web pages, and update WordPress itself. Changing themes is a straightforward operation and plugins can be added with a few clicks. - **Simplicity** – Very little technical proficiency is required to create and manage a website with WordPress. There is essentially no learning curve as most processes such as updating plugins and installing security patches can be done with a single click. Ease of use is one of the main reasons for the popularity of this CMS. - **Community support** – Due to the number of WordPress-based websites, there is a large and active community of users and developers. The result is an incredible amount of blogs and websites filled with tips that allow users to use WordPress more efficiently. Community members also regularly create new themes and plugins that customize websites and give them enhanced functionality. These factors have made WordPress the most popular CMS solution for website builders. Its simplicity and user-friendliness are what attract a large percentage of individuals new to website design. The amount of community support available is comforting when embarking on an unfamiliar endeavor like creating a website. Not everything about WordPress is perfect. Following are some characteristics of WordPress that may lead you to consider other CMS options. - **Security** – As the most popular CMS on the web, WordPress offers an inviting target for hackers. WordPress sites are regularly attacked by hackers and many sites contain spam. Users must make sure that they install security patches as soon as they become available. - **A low initial degree of functionality** – Without using plugins, the functionality of a WordPress site is limited. This should not pose a serious problem for designers, although they will have to browse a large set of plugins to find what they need. - **Flexibility** – The required use of plugins and themes can limit the degree of flexibility afforded to website designers. Atlantic.Net offers a One-Click [Word Press VPS Hosting](https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/) Application. ### [Joomla](https://www.joomla.org/) Joomla does not enjoy as large a user base as WordPress but has some features that may make it a better solution for your VPS-hosted website. - **More initial functionality** – Joomla provides a high degree of out-of-the-box functionality. A basic installation allows content to be optimized for search engines without the use of plugins. - **Enhanced customization** – You can extend the functionality of your Joomla website with components, plugins, modules, and extensions. With these items, you can easily add things like news feeds and buttons to your website. - **A potential app development platform** – Developers can use Joomla’s basic code as the foundation for web applications. Coding will be necessary to make use of this feature. The disadvantages of using Joomla include: - **A substantial learning curve** – Finding the correct options and using extensions effectively can be challenging for new users. It takes a little more time to be comfortable using all of Joomla’s powerful features. - **Basic coding knowledge is required** – Taking advantage of the [web app development](https://www.netsolutions.com/insights/how-to-build-a-web-app/) framework offered by Joomla requires CSS and PHP coding knowledge. ### [Drupal](https://www.drupal.org/) Drupal is the last CMS we will look at in this article. It also has a powerful feature set but is not as easy to use as WordPress. Its features include: - **Enhanced security** – Drupal is the choice of many government agencies due to its robust security capabilities. - **A large selection of modules** – An advantage of Drupal modules is that multiple modules can be combined to add additional custom functionality. - **Powerful content management features** – Content types and custom views enable the presentation of web pages to be fine-tuned. Its cache management system handles traffic spikes to keep your website running smoothly. Here are some of the potential issues associated with using Drupal: - **A very steep learning curve** – While Drupal is a very powerful and secure CMS solution, it takes a substantial time investment to get up to speed with the tool. - **Slower implementation time** – It can take a long time to correctly configure your website with the desired functionality using Drupal. ## Conclusion Simply choosing a CMS based on its popularity might not be the best way to go. Each solution we reviewed addresses the needs of a segment of the overall user community. Individuals with little technical experience who are interested in developing an online presence should look at WordPress first. More experienced users who want extended functionality at the cost of additional complexity may find that Joomla works better for them. Drupal offers enterprise-grade security and functionality that may be better suited for larger, more professional websites. Many CMS solutions are available for use on your website in addition to these three. [OctoberCMS](https://octobercms.com/) is another open-source content management system that is easy to learn and use. It’s a lightweight solution that isn’t packed with little-used features. OctoberCMS is one of the one-click additions available from [Atlantic.Net](https://www.atlantic.Net) to tailor your VPS-hosted website to your specific requirements. We suggest that you investigate these CMS solutions and make your selection before engaging a VPS-hosting provider. Make sure that the provider you pick offers an easy way to add the CMS to your site. **One Year of Free Cloud VPS Hosting:** Atlantic.Net stands ready to assist you with a world-class Cloud VPS platform, backed by always available USA-based support. Get started today and take advantage of our G3.2GB Cloud [VPS](https://www.atlantic.net/vps-hosting/) free offer for a year and be up and running in seconds. --- # How to Install Plausible on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-plausible-on-ubuntu-20-04/ | Published: 2021-03-09 | Updated: 2023-11-26 | Author: Hitesh Jethva Plausible is a free and open-source web analytics tool that helps you to track your website visitors. This lightweight solution is an alternative to Google Analytics. With Plausible, you can see all your site stats and metrics on a modern-looking, simple-to-use, and fast-loading dashboard. It is self-hosted, which means you can install it on any physical or [virtual private server](https://www.atlantic.net/vps-hosting/). In this post, we will show how to install Plausible Analytics with Docker on Ubuntu 20.04. ## Step 1 – Install Docker CE and Docker Compose Before starting, you will need to install Docker CE and Docker compose on your server. By default, the latest Docker CE package is not available in the Ubuntu 20.04 default repository, so you will need to add the Docker CE official repository to your server. First, install all required dependencies with the following command: ``` apt-get update -y apt-get install git apt-transport-https ca-certificates curl software-properties-common -y ``` Next, add the GPG key and repository with the following command: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add - add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu focal stable" ``` Once the repository has been added, install Docker and Docker Compose with the following command: ``` apt-get install docker-ce docker-compose -y ``` Once the installation is completed, verify the Docker version with the following command: ``` docker --version ``` You should see the following output: ``` Docker version 20.10.5, build 55c4c88 ``` ## Step 2 – Download Plausible Next, you will need to download Plausible from the Git repository. You can download it with the following command: ``` git clone https://github.com/plausible/hosting ``` Once the download is completed, change the directory to the downloaded directory and generate a secrete password with the following command: ``` cd hosting openssl rand -base64 64 ``` You should get the following output: ``` ZWOn9ulvt24T0nJUpZsyIyAL16AdyZWzY3bpw0sL/c5KuAUCNruX8JhQeMLJcJ8Y 51UtPG4/r8nXFxv0A67rWA== ``` Next, edit the Plausible environment configuration file and define your email, admin username, password, and secret key: ``` nano plausible-conf.env ``` Change the following lines: ``` ADMIN_USER_EMAIL=admin@example.com ADMIN_USER_NAME=admin ADMIN_USER_PWD=adminpassword BASE_URL=http://plausible.example.com SECRET_KEY_BASE=ZWOn9ulvt24T0nJUpZsyIyAL16AdyZWzY3bpw0sL/c5KuAUCNruX8JhQeMLJcJ8Y51UtPG4/r8nXFxv0A67rWA== ``` Save and close the file when you are finished. ## Step 3 – Launch the Plausible Container Next, you will need to run a docker-compose command inside the hosting directory to launch the Plausible container: ``` docker-compose up --detach ``` You should get the following output: ``` Digest: sha256:ab22a669cfe20cb54fa0d237f8ff7592793204d16ea5f588ceef4f63639cfc24 Status: Downloaded newer image for plausible/analytics:latest Creating hosting_mail_1 ... done Creating hosting_plausible_events_db_1 ... done Creating hosting_plausible_db_1 ... done Creating hosting_plausible_1 ... done ``` You can check all Docker images downloaded by the above command as shown below: ``` docker images ``` Output: ``` REPOSITORY TAG IMAGE ID CREATED SIZE yandex/clickhouse-server latest eeafa0a212bf 2 days ago 557MB postgres 12 85f1c84fe307 2 weeks ago 314MB plausible/analytics latest 213327b74c3b 5 weeks ago 149MB bytemark/smtp latest cd5c77c3bcd8 2 years ago 130MB ``` Now, check all the running containers with the following command: ``` docker ps ``` Output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 071b49800d01 plausible/analytics:latest "/entrypoint.sh sh -…" 7 seconds ago Up 5 seconds 0.0.0.0:8000->8000/tcp hosting_plausible_1 0cdae715308b postgres:12 "docker-entrypoint.s…" 18 minutes ago Up 6 seconds 5432/tcp hosting_plausible_db_1 90fb544b4425 yandex/clickhouse-server:latest "/entrypoint.sh" 18 minutes ago Up 6 seconds 8123/tcp, 9000/tcp, 9009/tcp hosting_plausible_events_db_1 750a908682be bytemark/smtp "docker-entrypoint.s…" 18 minutes ago Up 7 seconds 25/tcp hosting_mail_1 ``` ## Step 4 – Access Plausible Web Interface At this point, the Plausible container is started and listening on port 8000. You can access it using the URL http://plausible.example.com:8000. ![](https://www.atlantic.net/wp-content/uploads/2021/03/p3.png) Click on the Register button to register in Plausible and start working. ## Conclusion Congratulations! You have successfully installed Plausible analytics on Ubuntu 20.04. You can now add your website and track the website visitors from the central dashboard from your [Atlantic.Net VPS](https://www.atlantic.net/vps-hosting/). --- # How to Install TensorFlow with Docker on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-tensorflow-on-ubuntu-20-04/ | Published: 2021-03-13 | Updated: 2024-08-17 | Author: Hitesh Jethva Tensorflow is a free and end-to-end open-source machine learning platform created by the Google Brain team. It is a library used for numerical computation and large-scale machine learning. You can install it in a Python virtual environment or using Anaconda, as a docker container. It comes with a set of libraries and community resources that helps you to develop machine learning programs and applications. In this tutorial, we will show you how to install Tensorflow with Docker on Ubuntu 20.04. ## Step 1 – Install Docker CE First, install all required dependencies with the following command: ``` apt-get install git apt-transport-https ca-certificates curl software-properties-common -y ``` Next, add the Docker GPG key and repository with the following command: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add - add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu focal stable" ``` Once the repository has been added, install the Docker and Docker compose with the following command: ``` apt-get install docker-ce -y ``` Once the installation is completed, verify the Docker version with the following command: ``` docker --version ``` You should see the following output: ``` Docker version 20.10.5, build 55c4c88 ``` ## Step 2 – Launch Tensorflow Container Docker provides a Tensorflow container for building machine learning applications. First, download the Tensorflow container using the following command: ``` docker pull tensorflow/tensorflow:latest ``` You should get the following output: ``` latest: Pulling from tensorflow/tensorflow d519e2592276: Pull complete d22d2dfcfa9c: Pull complete b3afe92c540b: Pull complete c12ceea561ed: Pull complete 1f0ffb4d2509: Pull complete 961442e8e0e4: Pull complete 0b2b6f75fc95: Pull complete e266fced02fa: Pull complete c29b15b084af: Pull complete 5d43e8c7056a: Pull complete Digest: sha256:0118f3db64ddadf5d16f4b8d85ffb14228e194c0211c690562fb5dfd16fc86c0 Status: Downloaded newer image for tensorflow/tensorflow:latest docker.io/tensorflow/tensorflow:latest ``` Next, create a Tensorflow container from the downloaded image with the following command: ``` docker run -it -p 8888:8888 tensorflow/tensorflow:latest ``` You will be redirected inside the Tensorflow container: ``` ________ _______________ ___ __/__________________________________ ____/__ /________ __ __ / _ _ \_ __ \_ ___/ __ \_ ___/_ /_ __ /_ __ \_ | /| / / _ / / __/ / / /(__ )/ /_/ / / _ __/ _ / / /_/ /_ |/ |/ / /_/ \___//_/ /_//____/ \____//_/ /_/ /_/ \____/____/|__/ WARNING: You are running this container as root, which can cause new files in mounted volumes to be created as the root user on your host machine. To avoid this, run the container by specifying your user's userid: $ docker run -u $(id -u):$(id -g) args... root@f8968eb6e582:/# ``` You can now write and run any application inside the container. You can exit from the container anytime using the following command: ``` exit ``` ## Step 3 – Launch Tensorflow Jupyter Container Docker also provides a Tensorflow container with Jupyter notebook that allows you to write and run code through the Jupyter notebook dashboard. You can download and launch the Tensorflow Jupyter container with the following command: ``` docker run -it -p 8088:8088 tensorflow/tensorflow:latest-jupyter ``` You should get the following output: ``` latest-jupyter: Pulling from tensorflow/tensorflow d519e2592276: Already exists d22d2dfcfa9c: Already exists b3afe92c540b: Already exists c12ceea561ed: Already exists 1f0ffb4d2509: Already exists 961442e8e0e4: Already exists 0b2b6f75fc95: Already exists e266fced02fa: Already exists c29b15b084af: Already exists 5d43e8c7056a: Already exists c09e41c80475: Pull complete 4928d4fd53b4: Pull complete 4f8c501e8020: Pull complete 9a927eacde80: Pull complete cca85cdd242a: Pull complete c491a3ee7337: Pull complete 70252b385326: Pull complete c385e49aff55: Pull complete 32a1800a0df4: Pull complete 56ac089c301a: Pull complete 32b4fcc94634: Pull complete 62fbf7c8b492: Pull complete a184bae0471c: Pull complete 3138b3afe589: Pull complete 322ff03a149a: Pull complete Digest: sha256:15ca1ea5083f1f9fcc2b006df4f1d51c3d0b6f2616fa14c12ff6dc7c4bc83588 Status: Downloaded newer image for tensorflow/tensorflow:latest-jupyter [I 03:08:37.757 NotebookApp] Writing notebook server cookie secret to /root/.local/share/jupyter/runtime/notebook_cookie_secret jupyter_http_over_ws extension initialized. Listening on /http_over_websocket [I 03:08:38.106 NotebookApp] Serving notebooks from local directory: /tf [I 03:08:38.107 NotebookApp] Jupyter Notebook 6.2.0 is running at: [I 03:08:38.107 NotebookApp] http://40959756271a:8088/?token=2cbdd5bc2250270506f38954ed7f891a146cc71e50bc46fb [I 03:08:38.108 NotebookApp] or http://127.0.0.1:8088/?token=2cbdd5bc2250270506f38954ed7f891a146cc71e50bc46fb [I 03:08:38.108 NotebookApp] Use Control-C to stop this server and shut down all kernels (twice to skip confirmation). [C 03:08:38.114 NotebookApp] To access the notebook, open this file in a browser: file:///root/.local/share/jupyter/runtime/nbserver-1-open.html Or copy and paste one of these URLs: http://40959756271a:8088/?token=2cbdd5bc2250270506f38954ed7f891a146cc71e50bc46fb or http://127.0.0.1:8088/?token= ``` You can now access the Jupyter notebook using the URL http://your-server-ip:8088/?token=2cbdd5bc2250270506f38954ed7f891a146cc71e50bc46fb. You should see the following screen:   ![](https://www.atlantic.net/wp-content/uploads/2021/03/p1-1.png) ## Conclusion Congratulations! You have successfully installed Tensorflow with Docker on Ubuntu 20.04. You can now easily write and run a machine learning program with Tensorflow. Try it today on an Atlantic.Net [VPS](https://www.atlantic.net/vps-hosting/)! --- # How to Install Relic Server Monitoring on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-relic-server-monitoring-on-centos-8/ | Published: 2021-03-15 | Updated: 2023-11-26 | Author: Hitesh Jethva New Relic is one of the most popular web-based monitoring applications that monitors server performance in real-time. It is used by web hosting companies for resource and network monitoring including CPU, RAM, Disk Usage, and specific user-defined events. You just need to create an account on New Relic, get the installation code, run the code inside your server, and New Relic will do the rest of things for you. In this post, we will show you how to install New Relic on CentOS 8 and start monitoring your server. ## Step 1 – Create an Account on New Relic First, you will need to create an account on the [New Relic](https://newrelic.com/signup) as shown below: ![New Relic](https://www.atlantic.net/wp-content/uploads/2021/03/pp.png) After sign up, log in to the New Relic. You should see the following page: ![select operating system](https://www.atlantic.net/wp-content/uploads/2021/03/p1-3.png) Select your operating system and click on the **Continue** button. You should get an installation code as shown below: ![Installation](https://www.atlantic.net/wp-content/uploads/2021/03/p2-1.png) Copy the above code and proceed to the next step. ## Step 2 – Install New Relic Now, log in to your CentOS 8 server and run the code as shown below: ``` curl -Ls https://raw.githubusercontent.com/newrelic/newrelic-cli/master/scripts/install.sh | bash && NEW_RELIC_API_KEY=NRAK-KKNV6Z6A8EJ7AW8U21AQG72OKWC NEW_RELIC_ACCOUNT_ID=3086649 /usr/local/bin/newrelic install ``` Once the installation has been completed, you should get the following output: ``` Starting installation. Installing New Relic CLI v0.19.0 Installing to /usr/local/bin WARNING unknown region, using default: US INFO profile default added INFO setting default as default profile _ _ ____ _ _ | \ | | _____ __ | _ \ ___| (_) ___ | \| |/ _ \ \ /\ / / | |_) / _ | | |/ __| | |\ | __/\ V V / | _ | __| | | (__ |_| \_|\___| \_/\_/ |_| \_\___|_|_|\___| Welcome to New Relic. Let's install some instrumentation. Questions? Read more about our installation process at https://docs.newrelic.com/ The guided installation will begin by installing the New Relic Infrastructure agent, which is required for additional instrumentation. ? Please choose from the additional recommended instrumentation to be installed: Logs integration The following will be installed: Infrastructure Agent Logs integration ==> Installing infrastructure-agent-installer... Importing GPG key 0x8ECCE87C: Userid : "infrastructure-eng " Fingerprint: A758 B3FB CD43 BE8D 123A 3476 BB29 EE03 8ECC E87C From : https://download.newrelic.com/infrastructure_agent/gpg/newrelic-infra.gpg ==> Installing logs-integration...success. --- Instrumentation recommendations We discovered some additional instrumentation opportunities: - Node Agent Installer - Python Agent Installer Please refer to the "Detected observability gaps" section in the link to your data. --- New Relic installation complete! Your data is available at https://one.newrelic.com/redirect/entity/MzA4NjY0OXxJTkZSQXxOQXw4ODA3MjE5MDg0OTUzODQ4NTMz ``` Please remember the New Relic URL as shown in the above output. You will need it to access the New Relic web interface. ## Step 3 – Access the New Relic Web Interface Now, open your web browser and access the New Relic web interface using the URL [https://one.newrelic.com](https://one.newrelic.com/redirect/entity/MzA4NjY0OXxJTkZSQXxOQXw4ODA3MjE5MDg0OTUzODQ4NTMz.) You should see the New Relic dashboard on the following page: ![Dashboard](https://www.atlantic.net/wp-content/uploads/2021/03/p3-3.png) ## Conclusion Congratulations! You have successfully installed New Relic on CentOS 8. You can now monitor your [virtual server](https://www.atlantic.net/vps-hosting/) from the central location. --- # How to Set Up Remote Access to Docker Daemon > URL: https://www.atlantic.net/vps-hosting/how-to-set-up-remote-access-to-docker-daemon/ | Published: 2021-03-17 | Updated: 2023-11-18 | Author: Hitesh Jethva If you are a system administrator and manage multiple Docker hosts, then you will need to connect to each Docker host and run a command to manage Docker. This can be a time-consuming process. This is where Docker daemon comes into the picture. Docker daemon allows you to connect to a remote docker host over TCP. This way, you can manage multiple Docker hosts from your local system without having to log in to each Docker host individually. In this post, we will show you how to configure Docker daemon to manage the Docker host over TCP. ## Step 1 – Install Docker CE First, install all required dependencies with the following command: ``` apt-get install git apt-transport-https ca-certificates curl software-properties-common -y ``` Next, add the Docker GPG key with the following command: curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add – Next, add the Docker repository with the following command: ``` add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu focal stable" ``` Once the repository has been added, install Docker and Docker compose with the following command: ``` apt-get install docker-ce docker-compose -y ``` Once the installation is completed, verify the Docker version with the following command: ``` docker --version ``` You should see the following output: ``` Docker version 20.10.5, build 55c4c88 ``` ## Step 2 – Configure Docker Daemon First, you will need to create a directory to store the Docker daemon configuration file. You can create it with the following command: ``` mkdir -p /etc/systemd/system/docker.service.d ``` Next, create a new file to store the daemon options. ``` nano /etc/systemd/system/docker.service.d/options.conf ``` Add the following lines: ``` [Service] ExecStart= ExecStart=/usr/bin/dockerd -H unix:// -H tcp://0.0.0.0:2375 ``` Save and close the file, then reload the systemd daemon to apply the changes: ``` systemctl daemon-reload ``` Next, restart the Docker service to apply the changes: ``` systemctl restart docker ``` At this point, the Docker daemon is configured and listening on port 2375. You can check it with the following command: ``` ps aux | grep dockerd ``` You should get the following output: ``` root 48453 1.2 2.4 1005080 98520 ? Ssl 00:58 0:00 /usr/bin/dockerd -H unix:// -H tcp://0.0.0.0:2375 root 48775 0.0 0.0 12108 992 pts/0 S+ 00:58 0:00 grep --color=auto dockerd ``` ## Step 3 – Configure Local System to Connect to the Docker Daemon Before starting, make sure Docker and Docker compose are installed on your local system. Now, you will need to configure your local system to connect to the Docker daemon on the remote Docker host. You can use a single one-liner to direct connect to the Docker daemon and run command on the remote Docker host. You can use the DOCKER_HOST variable to define the Docker daemon address. For example, run the following command to run the docker info command on the remote Docker host: ``` DOCKER_HOST=tcp://remote-docker-host-ip:2375 docker info ``` Or ``` docker -H tcp://remote-docker-host-ip:2375 docker info ``` You should get the output of the docker info command as below: ``` Containers: 2 Images: 3 Storage Driver: overlay2 Backing Filesystem: xfs Supports d_type: true Native Overlay Diff: true Execution Driver: Kernel Version: 4.18.0-193.6.3.el8_2.x86_64 Operating System: CentOS Linux 8 (Core) CPUs: 2 Total Memory: 3.846 GiB Name: centos8 ID: S56P:VPIW:CMGZ:GAFN:YZNG:22CE:OBY3:SKEW:JAMT:DLD4:FG5K:QXYR Http Proxy: Https Proxy: No Proxy: Labels: ``` You can also run the docker-compose command on the remote host as shown below: ``` docker-compose -H tcp://remote-docker-host-ip:2375 --version ``` You can also set DOCKER_HOST variable in your .bashrc file. So you don’t need to specify every time when executing docker or docker-compose command. You can set it with the following command: ``` echo "export DOCKER_HOST=tcp://remote-docker-host-ip:2375" >> ~/.bashrc ``` Next, activate the configuration with the following command: ``` source ~/.bashrc ``` Now, you can manage remote Docker host by just running the docker and docker-compose command locally. For example, run the following command to check the Docker version on the remote host: ``` docker --version ``` ## Conclusion In the above guide, you learned how to configure Docker daemon to connect the remote Docker host over TCP and manage it from the local system. I hope this will make your day-to-day Docker tasks much easier. Start using Docker daemon today on a [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # VPS vs VPN – Similar Names, But Completely Different Functions > URL: https://www.atlantic.net/vps-hosting/vps-vs-vpn-similar-names-but-completely-different-functions/ | Published: 2021-03-19 | Updated: 2024-09-24 | Author: Gilad Maayan ## **Difference Between VPS and VPN** The technology industry is full of acronyms, and although VPS Hosting and VPN have similar names, they are different things altogether. Though the acronyms look and sound similar, in reality, they are individual technologies that have very little to do with one another. Naming convention similarities can indeed cause confusion, especially for individuals outside of the tech industry, but you can rest easy, as we will explain the difference and help you to understand which technology is best for your current needs. Let’s break these acronyms down. **VPS **stands for Virtual Private Server and **VPN **stands for Virtual Private Network. They are two completely different technologies, so it is important to understand what the difference is to ensure you are getting the correct service. ## What Is a VPS? A VPS is a server, typically a server that users can lease from a hosting provider. The VPS is an isolated virtual machine with finite local resources. Resources are allocated from a physical host, and the hosting provider will likely have many VPS hosts in a data center; they essentially split up the host into multiple Virtual Private Servers. A typical standard VPS configuration will usually not be interconnected with other services and does not share resources. You simply purchase some server space and get to work. However, there are alternative solutions available, and Cloud VPS can share resources and interconnect with other cloud services such as backups, edge services, and many other managed services. You can also get a Dedicated Host that you can place VPS on, an entirely private host for your personal use. ## What Are the Advantages of a VPS? VPS is popular for a reason, and there are several advantages of using a VPS. Primarily, they are typically less expensive than other cloud server offerings. Another advantage is that the user rarely knows that they are working on a shared tenancy as performance is usually very good, and all neighboring VPS are completely isolated from one another by the host. Your neighbors can reboot, upgrade operating systems, and pretty much do what they like, and it will not affect you. ## Cloud VPS Atlantic.Net also offers a Cloud VPS service that guarantees system resources without the need for a dedicated host (although we offer that too). Cloud VPS includes additional high availability configurations and access to other ACP Cloud Services such as onsite and offsite backups, snapshots, and Secure Block Storage. Our Cloud VPS servers are built to stringent security best practices, and all servers have root access (or Windows Administrator) privileges enabled and available upon launch. The Atlantic.Net Cloud VPS combines simplicity, security, and scalability with the reliability of the latest virtualization and cloud hosting platform technology. You can scale up when needed, you only have to pay for what you use, and you can cancel the Cloud VPS at any time with no commitments, saving you significant time and money. ## What Is a VPN? Now know what a VPS is, so let’s take a look at VPNs to understand why they are different from VPSes! A virtual private network (VPN) is a secure, private and encrypted network connection between two endpoints. A [secured VPN](https://vpnoverview.com/best-vpn/top-5-best-vpn/) tunnel is created peer-to-peer to encapsulate all network traffic, even if being used over the public internet. The technology is widely used by home workers to create a private network connection between you and a workplace computer network. This is done over a home internet connection. It enables the user to access workplace resources and use your computer as if you were sitting at your office desk. The VPN creates a secured network tunnel where the end-user can safely transmit sensitive data without the risk of any data being compromised. With today’s rapid internet speeds, there is no noticeable difference in the user experience on a VPN connection compared with accessing the infrastructure directly outside of latency depending on physical distance from the data center.  The miles between the end-user and the data center are why Atlantic.Net has so many different physical locations across the globe. ## Why Are VPNs So Popular? Virtual Private Networks are incredibly popular because the technology not only allows the secure and private transfer of data between many different authorized endpoints, but also is very simple to use. It’s relatively easy to set up, too; long gone are the days where you need to purchase expected hardware VPN devices. Now you can configure a VPN as a software device in a matter of minutes. Popular VPN applications used by Atlantic.Net customers include [StrongSwan](https://www.atlantic.net/vps-hosting/how-to-install-and-configure-strongswan-vpn-on-ubuntu/) and [Wireguard](https://www.atlantic.net/vps-hosting/how-to-set-up-wireguard-vpn-on-centos-8/). Most VPN clients are very user-friendly, and since almost all workplaces have a VPN in place, the usage of the technology is becoming commonplace. ## What Are the Key Features of a VPN? [Data encryption](https://cloudian.com/guides/secure-data-storage/data-encryption/) is one of the primary features of a VPN as encryption protected the transfer of sensitive information. A VPN enforces the confidentiality, integrity, and availability of business data. The encryption ciphers used are so advanced that it is almost impossible to break 2048 bit encryption with today’s technology. Access Controls can be applied to VPNs, and integration to business directory services (such as Active Directory) is very simple. One of the principal purposes of a VPN is to control access to digital resources. When a VPN is deployed, only authorized users can register a VPN account. Strict access controls can be created that include locking down access to specific users, specific laptops, or workstations. Once a user is on the VPN, access controls can be set to control what and where the user can or cannot access the network. All VPN traffic can be logged and access logs are easy to decipher to who has accessed the network at a particular time; this is very useful for auditing businesses. ## How Can Atlantic.Net Help? You will be glad to know that Atlantic.Net can help you if you need a Cloud VPS, or if you need a VPN by provisioning a cloud VPS. For more than 30 years, Atlantic.Net has helped thousands of businesses with industry-leading hosting solutions, and we can do the same for you too. Atlantic.Net Cloud VPS is a far superior alternative to standard VPS, providing full control of your server software backed by dedicated and premium hardware resources.  Get started today with a free-to-use [Cloud VPS Hosting](https://www.atlantic.net/vps-hosting/) for one full year today! --- #### Read More About Remote Management and VPNs - [What Is a VPN?](https://www.atlantic.net/vps-hosting/what-is-vpn/) - Best [Remote Management Tools](https://www.atlantic.net/vps-hosting/top-10-remote-management-tools/) --- --- # The Best One-Click Apps for VPS Hosting > URL: https://www.atlantic.net/vps-hosting/the-best-one-click-apps-for-vps-hosting/ | Published: 2021-03-22 | Updated: 2025-09-19 | Author: Alexander Wise Requisitioning a Virtual Private Server (VPS) is often one of the first steps individuals or organizations take when looking to develop a web presence. Other options, like hosting the website on a physical server or sharing a server with other customers, are either more expensive or less flexible. In most cases, a VPS is the best choice. It offers clients a secure and economical method of getting up and running on the web. One of the factors that can influence your choice of a VPS hosting provider is the availability of software tools and packages to run on your server. Even the most high-performing and technologically advanced virtual server makes a poor website without the addition of the right software. Once you have settled on a hosting solution, it’s time to make it functional by installing software that addresses your requirements. A perk that many top-notch web-hosting providers offer their customers is the availability of one-click software installation. Depending on your needs, some providers may have a more attractive portfolio of one-click apps than others. This article will look at the best one-click apps for clients hosting their websites on virtual private servers. ## Why Do You Want One-Click Apps? One-click apps are beneficial for all web-hosting customers for one main reason. The simplicity of a one-click methodology removes the complexity of manual installations of software on web servers. Hosting providers offer a streamlined installation path as a perk to their clients that allows them to more easily construct the type of website they want. Traditional software installation methods can be challenging for even the most experienced technophiles. Many new VPS customers are not technically proficient developers. A lot of prospective web-hosting clients have average computing skills at best but are looking to develop a web presence for business reasons or to present information to a worldwide audience. At a minimum, installing software on the web requires multiple steps. Many new hosting clients would find it very difficult to perform these procedures without engaging professional help or incurring undue stress. A common installation involves: **Determining system requirements** – Before initiating any software installation, it’s necessary to verify that a system meets the minimum requirements. This can be complicated and may require some serious research and a substantial time investment. **Ensuring code support** – Language support on the VPS is an essential ingredient in getting applications to run successfully. You need to make sure that the PHP version required by an app is compatible with your server and other software with which it will interact. **Setting permissions correctly** – Setting permissions is vitally important for website security. It can also be a very complex undertaking. A small permission error can enable unauthorized access to your server, making it imperative that the procedure is performed correctly. **Creating databases** -A database needs to be created to store and manage information on the website. This too can be complicated and beyond the technical skills of many potential VPS customers. **Installing third-party application extensions** – Third-party code libraries, applications, and extensions may be necessary to complete the installation of the original app. The complexity involved with getting an application to run smoothly on a VPS can make the process extremely challenging. That’s the reason hosting providers offer a one-click installation path. The complications we have just outlined are eliminated when installing one-click apps. With one-click apps, providers make it easy for their customers to make the most efficient use of their valuable time and virtual private servers. ## What Are Some of the Best One-Click Apps? Now that you have a sense of why VPS hosting providers offer one-click app installation, the next question to consider is which apps will be the most useful when developing, designing, and maintaining your website. Here are our choices for the most beneficial one-clicks apps to use with a virtual private server. ### WordPress [WordPress is an extremely popular content management system (CMS)](https://hostingtribunal.com/blog/wordpress-statistics/#gref) that powers millions of websites. Its popularity derives from its simplicity, ease-of-use, and large user support community. This has made it very attractive for setting up a website or blog by non-technical customers. A WordPress site is customizable using the many themes and plugins made available by the professional and user community. The application makes it easy to create impressive personal or business websites and gets them up and running fast.  There is a large range of technical users from beginners to advanced that utilize WordPress for their website needs. ### cPanel [cPanel](https://cpanel.net/)is the industry-leading hosting platform that makes it easy for users to automate the management tasks necessary when operating a website. It features a simple and intuitive interface that facilitates efficient website administration. cPanel is very customizable and can be used by resellers to promote their business through improved branding along with more advanced hosting options for that next level of a web presence. Some of the tasks simplified by cPanel include setting up and managing email accounts, database management, and handling backup and recovery processes. cPanel eliminates many of the technical hurdles faced by new website designers while providing a graphical user interface to make navigating and administrating your website easy. ### October CMS This app is a modern CMS that provides an alternative to WordPress. October CMS is primarily designed for use by developers and is not as easy to use as WordPress. It can also function as a flat-file CMS, eliminating the need for a database. October CMS is more lightweight than WordPress and enables more granular control and management of new features. ### NextCloud This app is a self-hosted productivity platform that helps users collaborate and share information. [NextCloud](https://nextcloud.com/) enables data to be protected, controlled, and monitored across the whole organization. The app allows secure emails and video chats without the risk of data leaks.  NextCloud is a must-have One-Click App that solves a lot of company-related needs especially in the new economy where some of your workers will now be remote. ### LAMP LAMP is an acronym for Linux, Apache, MySQL, and PHP. It’s a development stack used for developing and building dynamic websites. Linux provides the operating system, Apache is the web server software, MySQL is the database solution, and PHP is the programming language used to tie it all together. It’s the most popular development stack on the web.  This One-Click app is mostly for developers and to get the website project underway as quick as possible.  This is not a beginner-oriented One-Click app. ### LEMP LEMP is a similar development stack that replaces the Apache web server component with Nginx. It offers users the tools necessary to create and customize websites using the simpler and potentially faster Nginx web server software.  This One-Click app, just like a LAMP stack above, is mostly for developers and to get the website project underway as quickly as possible.  This is not a beginner-oriented One-Click app. ### MySQL MySQL is the leading open-source relational database management system (RDBMS) in the world. Its popularity is demonstrated by its inclusion in the LAMP and LEMP development stacks. MySQL has a large user community that can help provide online support and help keep the RDBMS solution secure. ### Docker [Docker](https://www.docker.com/why-docker) is a development framework that streamlines the process of creating innovative apps in software containers. Containers isolate an application from its environment, making it easier to create more robust and cloud-based solutions. It has become the de-facto industry standard for building containerized apps. ### Node.js Node.js is an open-source server environment that runs on multiple platforms including Windows, Linux, and macOS. It employs asynchronous programming, which is more memory-efficient and potentially much faster than routines written in PHP or ASP. ## Where Can I Get These One-Click Apps? Atlantic.Net is a full-service web hosting provider that offers customers a wide range of options enabling them to tailor a [VPS](https://www.atlantic.net/vps-hosting/) to their business requirements. All the one-click apps discussed above are available when you choose Atlantic.Net for your [VPS hosting provider](https://www.atlantic.net/vps-hosting/). They provide an excellent platform for getting your website implemented quickly with all the features it needs to succeed. --- # How to Install Invoice Ninja on Debian > URL: https://www.atlantic.net/vps-hosting/how-to-install-invoice-ninja-on-debian/ | Published: 2021-03-23 | Updated: 2025-09-03 | Author: Hitesh Jethva Invoice Ninja is a free, open-source, self-hosted application for invoicing and billing customers. It is written in PHP with a Laravel framework. Invoice Ninja is specially designed for freelancers & businesses for invoicing, accept payments, track expenses, create proposals, and time tasks. It allows you to create and send invoices to clients with your own domain name and brand. Invoice Ninja supports 40+ payment gateways including WePay, GoCardless, PayPal, Authorize.net, 2Checkout, and more. In this post, we will show you how to install Invoice Ninja with Nginx on Debian 12. ## Prerequisites - A fresh Debian 12 server - A valid domain name pointed to your [virtual private server](https://www.atlantic.net/vps-hosting/) - A root password configured on your server ## Step 1 – Install LEMP Server First, you will need to install Nginx, MariaDB, PHP, and other PHP extensions on your server. You can install all of them with the following command: ``` apt-get install nginx mariadb-server php php-zip php-bcmath php-fpm php-cli php-common php-curl php-gd php-mysql php-xml php-mbstring unzip -y ``` Once all the packages are installed, stop the Apache, start the Nginx and MariaDB service if not started. ``` systemctl stop apache2 systemctl start nginx systemctl start mariadb ``` ## Step 2 – Create a Database Next, you will need to create a database and user for Invoice Ninja. First, log in to MariaDB with the following command: ``` mysql ``` Once connected, create a database and user with the following command: ``` CREATE DATABASE ninja; GRANT ALL PRIVILEGES ON ninja.* TO 'ninja'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download Invoice Ninja Next, download the latest version of Invoice Ninja with the following command: ``` wget https://github.com/invoiceninja/invoiceninja/releases/download/v5.11.72/invoiceninja.tar.gz ``` Once the download is completed, extract the downloaded file to the Nginx root directory: ``` cd /var/www/html tar -xvzf invoiceninja.tar.gz ``` Next, copy the example environment file. ``` cp .env.example .env ``` Next, change the ownership of the invoiceninja directory to www-data: ``` chown -R www-data:www-data /var/www/html/ ``` Set proper permissions. ``` chmod -R 775 * ``` ## Step 4 – Configure Nginx for Invoice Ninja Next, you will need to create an Nginx virtual host configuration file for Invoice Ninja. You can create it with the following command: ``` nano /etc/nginx/conf.d/ninja.conf ``` Add the following lines: ``` server { listen 80; server_name ninja.example.com; root /var/www/html/public; index index.php index.html index.htm; client_max_body_size 20M; charset utf-8; access_log /var/log/nginx/ininja.access.log; error_log /var/log/nginx/ininja.error.log; gzip on; gzip_types application/javascript application/x-javascript text/javascript text/plain application/xml application/json; gzip_proxied no-cache no-store private expired auth; gzip_min_length 1000; location / { try_files $uri $uri/ /index.php?$query_string; } if (!-e $request_filename) { rewrite ^(.+)$ /index.php?q= last; } location ~ \.php$ { fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_pass unix:/run/php/php8.2-fpm.sock; fastcgi_index index.php; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_intercept_errors off; fastcgi_buffer_size 16k; fastcgi_buffers 4 16k; } } ``` Save and close the file, then verify the Nginx for any syntax errors with the following command: ``` nginx -t ``` Finally, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 5 – Access Invoice Ninja Now, open your web browser and access the Invoice Ninja web interface using the URL **http://ninja.example.com**. You will be redirected to the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p1-6-1024x557.png) ![](https://www.atlantic.net/wp-content/uploads/2021/03/p2-4-1024x401.png) ![](https://www.atlantic.net/wp-content/uploads/2021/03/p3-4-1024x537.png) ![](https://www.atlantic.net/wp-content/uploads/2021/03/p4-2-1024x451.png) Provide your Invoice Ninja URL, database details, and administrative user information, and click on the **Next** button. You will be redirected to the Invoice Ninja login page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p5-1-1024x536.png) Provide your admin username and password and click on the **Login** button. You should see the Invoice Ninja dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p6-1-1024x541.png) ## Conclusion Congratulations! You have successfully installed and configured Invoice Ninja on Debian 12. You can now implement Invoice Ninja in your organization and start invoicing and billing customers with your [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # Atlantic.Net now accepts PayPal payments > URL: https://www.atlantic.net/press-releases/atlantic-net-now-accepts-paypal-payments/ | Published: 2021-03-25 | Updated: 2024-06-11 | Author: Editorial Team **ORLANDO, FLA. (March 25, 2021)** – [Atlantic.Net](https://www.atlantic.net/), a leading cloud services provider, now accepts PayPal as a payment option for all its services and solutions. “Based on the feedback we have received and to better serve an ever-growing customer base, we are introducing the ability for all our customers to pay with PayPal. As we continue to expand our business and footprint internationally, PayPal payments will help further accelerate our growth in all markets,” said Marty Puranik, CEO and Founder of Atlantic.Net. “Having an additional payment option for our customers is particularly important as we plan to introduce additional international cloud locations to the market.” PayPal is an online payments system with 305 million active customers across most countries. It serves as an electronic alternative to traditional payment methods like checks, money orders, and credit/debit cards, allowing people to transfer funds electronically between individuals and businesses directly from their PayPal account. This presents a significant opportunity to increase overall revenues by opening services up to clients that do not wish to use a credit or debit card or prefer to pay in advance for their services. The Atlantic.Net Cloud Platform, which is engineered to provide fault-tolerant, ultra-fast performance, includes award-winning Cloud Servers, Secure Block Storage, one-click applications, DNS, Dedicated Hosts, private networking, RESTful API, data backup, a full suite of managed services, 24/7/365 expert U.S.-based support, and more. This infrastructure is ideally suited to support businesses and organizations as they evolve toward a distributed or hybrid remote work environment to help mitigate the health risks of COVID-19. **About Atlantic.Net** Atlantic.Net is a global cloud services provider with over 25 years of experience, serving thousands of developers and small, medium, and large clients in more than one hundred countries. Atlantic.Net specializes in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions and has served dynamic business clients including Lenovo, Newegg, NASA, and Hilton, among others. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions, backed by 24/7/365 support in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. For more information, please visit [Atlantic.Net](https://www.atlantic.net/). --- # Atlantic.Net Now Accepts PayPal Payments > URL: https://www.atlantic.net/announcements/atlantic-net-now-accepts-paypal-payments/ | Published: 2021-03-25 | Updated: 2025-09-19 | Author: Alexander Wise ## PayPal payments are now accepted for all Atlantic.Net services and solutions ![Paypal Payments](https://www.atlantic.net/wp-content/uploads/2021/03/paypal-banner-v-2-x2.jpg) Today we began accepting PayPal payments for all our services and solutions. PayPal is an online payments system with 305 million active customers across most countries. It serves as an electronic alternative to traditional payment methods like checks, money orders, and credit/debit cards by allowing people to transfer funds electronically between individuals and businesses directly from their PayPal account. This presents a significant opportunity to increase our revenues by opening our services up to clients that do not wish to use a credit or debit card or prefer to pay in advance for their services. “Based on feedback we have received and to better serve an ever-growing customer base, we are introducing the ability for our customers to pay with PayPal. As we continue to expand our business and footprint internationally, PayPal payments will help further accelerate our growth in all markets,” said Marty Puranik, CEO and Founder of Atlantic.Net. “Having an additional payment option for our customers is particularly important as we plan to introduce additional international cloud locations to the market.” To learn more about making payments for your Atlantic.Net Cloud services, please visit: [https://www.atlantic.net/community/howto/paying-with-paypal/](https://www.atlantic.net/vps-hosting/paying-with-paypal/)   --- # What Makes Dedicated Cloud Hosting a Perfect Choice for Resellers? > URL: https://www.atlantic.net/dedicated-server-hosting/what-makes-dedicated-cloud-hosting-a-perfect-choice-for-resellers/ | Published: 2021-03-27 | Updated: 2025-09-19 | Author: Richard Bailey Cloud Hosting is experiencing significant growth right now, and cloud reselling is also becoming hugely popular, as small businesses and entrepreneurs realize the affordability of offering Cloud Hosting. Dedicated cloud servers are driving this transformation initiative, allowing resellers to harness the power of new, high-performance server hardware at a fraction of the cost of setting up your own data center. The reseller performs the role of the hosting company, and they can charge their clients their own fee, making it easy to turn a profit. The reseller can create their own hosting plans that are personalized to their customers. The customer will not know that server space is being resold from a principal cloud hosting provider. ## What Is Reseller Hosting? You may be unsure exactly what reseller hosting is, so in the interests of clarity, reseller hosting is when an individual or small business leverages an existing hosting company’s infrastructure, rebrands it, and resells it to its own customer base. Website hosting is particularly popular for resellers, and frequently resellers offer servers for cryptocurrency mining. Typically a reseller will purchase one (or many) dedicated cloud hosts, then split up the resources and resell them. Hosting providers often offer incentives to resellers, such as discounts or performance perks depending on how much server space is purchased. The reseller only has to worry about reselling computer resources; they don’t have to worry about keeping the data center lights on, the cost of power and cooling, or maintaining a strong service level agreement, as all these responsibilities are owned by the principal hosting provider. ## What Is a Dedicated Cloud Host? A dedicated cloud host is a physical server that is sold or leased in its entirety to the customer. Techies might refer to it as a dedicated piece of tin. In a typical data center, [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) will be used by businesses for complex, data-intensive tasks or for reselling purposes. Depending on the provider, a dedicated cloud host will have a hypervisor installed and will be connected to a pre-existing cloud platform. Resellers usually have a personalized cloud portal for their customers, or they may offer a solution like cPanel to lease personalized server space. The principal cloud provider’s software then manages the server and opens up the substantial benefits of having cloud connectivity. This makes provisioning availability near-instant, as a customer can lease the server in minutes. Despite cloud connectivity, there is no direct sharing of server resources, and resources are exclusive for the reseller to manage. Some of the major benefits include the ability to add secure block storage on-demand and scale up the server on demand – great if your reseller business grows rapidly. Also, snapshots, onsite and offsite backup integration, replication, DNS integration, and so on are useful features. The resellers have complete control to create, manage and remove Cloud Servers on the Dedicated Cloud Host and the freedom and flexibility to provision any resources offered on a plan by the principal hosting company. ## A Perfect Match for Resellers? With evolving technology increasing our dependence on newer developments, it can be difficult for resellers and integrators to manage modern server infrastructure. This is why there is a greater need and desire for services to help make the reseller’s and integrators’ jobs easier. The reseller has complete control over the disk space, network bandwidth, and CPU allocations per client, enabling the creation of a white label hosting company. The reseller gets all the perks of working with the hosting provider, including 24/7 support options, uptime guarantees, and the option to leverage professional services. For many years, managed servers helped to fuel business growth for resellers, but a saturation point has been reached where system management overhead overtakes the ability to continue growing profitably. This is not the case with a dedicated cloud host, as most of the emphasis is on the reseller’s customers to manage their own VPS. Imagine being a reseller with the ability to turn up one-click applications, or the ability to resize a [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) with additional resources, not only providing greater power but also meeting regulatory compliance standards. Dedicated Cloud Nodes are now available that help resellers to become more efficient with their time and help them bring focus to the core business functions. Client cloud servers are available in minutes and come with all the benefits of highly available infrastructure and the option to purchase additional services from the principal hosting company. The reseller has complete control to create, manage and remove Cloud Servers on the Dedicated Cloud Host, including complete and detailed logging of each VMS, making it easier to charge your customers accurately and enabling the freedom and flexibility to provision any cloud hosting plan. ## What Should I Look for in a Hosting Provider? Hopefully, you can now understand the major benefits of using dedicated cloud hosts as a reseller, but what else should you look for? - Integration to a cloud control panel - (or) Integration with cPanel - High performance dedicated cloud hosts - Solid State Hard drives used throughout the infrastructure - Flexible bandwidth options - Bolt-on secure block storage capability - Scalability - Ability to manage DNS and Nameservers - Around the clock support - 100% uptime guarantee - Professional Service Agreements for consulting work - Ability to integrate with other cloud services and managed service offerings, such as a backup-as-a-service, firewall as a service, intrusion prevention as a service, and more If you are a growing business, require the advanced features for disaster recovery and business continuity, have unpredictable growth patterns, have a SAAS offering, have a high traffic website, or want the ability to become a cloud reseller (where you can lease/resell cloud resources to another client), a dedicated cloud host is a perfect match. Not only do you get a powerful server, but the dedicated cloud host also allows you to provision multiple servers in seconds with a fully orchestrated and built cloud mechanism. With [Dedicated Hosts](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/), the tools to accomplish a full DR plan while planning ahead for business growth are already waiting and ready to make your life easier. Atlantic.Net is a market-leading Dedicated Cloud Host, with a presence in eight international data center locations. With Atlantic.Net Dedicated Cloud Host, you can launch Cloud Servers within minutes, backed by highly available infrastructure. You get complete control to create, manage and remove Cloud Servers with a full log of your servers and VMS, making it easy for you to bill your customers. If you would like to learn more about our Dedicated Cloud Host solution for resellers, please visit our [Dedicated Host page](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/), email [sales@atlantic.net](mailto:sales@atlantic.net), or call +1 (321) 206- 3734. --- # Breaking News: Acer Hit with $50 million Ransomware Demand > URL: https://www.atlantic.net/vps-hosting/breaking-news-acer-hit-with-50-million-ransomware-demand/ | Published: 2021-03-29 | Updated: 2026-03-02 | Author: Richard Bailey *Atlantic.Net is providing this security advisory as a news item; we want to reassure our customers that Atlantic.Net does not use any of these products affected by this exploit internally or in any of our service offerings.* Over the last few days, reports have emerged of what could turn out to be the biggest ransomware demand in history. The reported victim is Acer Inc., the Taiwanese multinational tech giant that is famous for manufacturing business and personal computer hardware including laptops, computers, tablets, and visual displays. The news began breaking on the 19th March 2020 by tech and security website [Bleeping Computer](https://www.bleepingcomputer.com/news/security/computer-giant-acer-hit-by-50-million-ransomware-attack/). The hacking group REvil has demanded a $50 million ransom from Acer after what they claim to be a successful data breach and ransomware attack. REvil (previously known as Sodinokibi) is believed to be a Russian-based ransomware-as-a-service operation. They have previously successfully targeted the UK HQ of motoring giant [Honda](https://www.bbc.co.uk/news/technology-52982427), and U.S law firm [Grubman Shire Meiselas & Sack](https://www.infosecurity-magazine.com/news/revil-to-auction-stolen-madonna/). The Grubman breach made international news as they represented many famous people including Madonna, Lady Gaga, Donald Trump, and Lebron James. As part of the Grubman breach, legal documents were leaked as part of the extortion, but they sensibly never paid the ransom (unlike UK travel currency company Travelex who reportedly paid REvil over $2.3 million). ## What Do We Know About the Acer Breach? At the time of writing, there has been no official statement from Acer Inc. If reports are to be believed, only the back-office email system was targeted at Acer and no production environments were compromised. However, REvil has given Acer 9 days to pay a [$50 million bounty](https://www.bleepstatic.com/images/news/ransomware/attacks/a/acer/tor-payment-site.jpg); this is the largest ransom ever reported, and the group has published ‘evidence’ of the successful breach on their [hidden TOR website](https://www.bleepstatic.com/images/news/ransomware/attacks/a/acer/acert-leak-site.jpg). Despite the rise in Exchange Online and Microsoft 365 cloud services, a huge number of businesses still operate on-premise Microsoft Exchange server farms, and it is believed that the breach may have taken advantage of a recently uncovered Microsoft Exchange vulnerability.   Due to the very nature of the Exchange email delivery method, at least part of the network infrastructure has to be exposed to the public internet, usually in the form of a DMZ or perimeter proxy. As a result, any vulnerability can potentially expose a business to malicious actors. On the 2nd March 2021, Microsoft scrambled to patch a “Microsoft Exchange Server Remote Code Execution Vulnerability” documented in [CVE-2021-26855](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26855). The security bulletin states that Exchange 2013, 2016, or 2019 were vulnerable when running on Windows Server 2008 R2, Server 2012, Server 2012 R2, Server 2016, and Server 2019. Microsoft has subsequently released a patching [tool on GitHub](https://github.com/microsoft/CSS-Exchange/tree/main/Security) for system administrators. The tool scans the environment to see if the infrastructure is vulnerable. If the scan confirms the system is vulnerable, the security updates are installed. ## What Is the Next Move? Unless Acer Inc. goes public, we may never know the true extent of the breach, but to demand $50 million, many expect the hacking group to have some valuable data on the company. If not that, the hackers are just being bullish in an attempt to extort money. With Acer being tight-lipped, this is very much a case of “wait and see.” Have they paid the ransom? Have they even been hacked? Truthfully, no one knows yet, and while some suggested evidence has been released, there is no way to validate whether it’s genuine. If your business is concerned about cybersecurity, please feel welcome to reach out to Atlantic.Net. We are specialists in Managed Services, Cloud Hosting, and HIPAA compliance. Security of our infrastructure is of paramount importance, and we work hard to ensure we have the best security processes in place. There is no doubt that this cyberattack will go down in history, and we feel concerned for our friends in the industry that might be affected by this. Atlantic.Net has a full suite of [Managed Security Services](https://www.atlantic.net/pci-compliant-hosting/pci-security-services/), to help be proactive and prepare in advance for any security issues. [Get in touch today.](https://www.atlantic.net/about-us/corporate-contact/) --- # Announcement: Meet Our Customer Service Champion for Q1 2021: Alex C. > URL: https://www.atlantic.net/announcements/meet-our-customer-service-champion-for-q1-2021-alex-c/ | Published: 2021-03-30 | Updated: 2025-09-19 | Author: Alexander Wise We are pleased to announce that Alex C. is our Customer Service Champion for Q1 2021! ![](https://www.atlantic.net/wp-content/uploads/2021/03/Alex-C-150x150.png)Alex C. is one of our top Account Executives. He enjoys sports, and his biggest new year goal is to ride bikes and exercise more frequently with his family. He likes how close everyone is at Atlantic.Net, and he says that Atlantic.Net even feels like a family sometimes. For 2021, Alex says he is grateful he is part of a team that is willing to share knowledge with him to be able to continue to work during the pandemic. Great work, Alex! We thank you and we appreciate all your hard work! --- # VPS Hosting, Dedicated Hosts and Dedicated Servers – When Should I Upgrade? > URL: https://www.atlantic.net/dedicated-server-hosting/vps-hosting-dedicated-hosts-and-dedicated-servers-when-should-i-upgrade/ | Published: 2021-04-07 | Updated: 2025-09-19 | Author: Richard Bailey When a business begins to consider upgrading from [VPS hosting](https://www.atlantic.net/vps-hosting/) to a [dedicated host](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) or server, it is often because the total cost of ownership (TCO) is starting to become a concern. One of the greatest benefits of using a Cloud VPS is the flexibility the users have when customizing server specifications. However, there comes a point when a customer outgrows the VPS model, not only will VPS pricing become uneconomical, but the performance trade-off between a VPS and dedicated hardware becomes negligible. The saturation point will vary between customers, but at Atlantic.Net, our engineers witness customers switching to dedicated hardware when an organization’s VPS host starts to demand around 32GB to 48GB of RAM, usually when the base monthly cost of the VPS starts to become a burden on company finances. However, to understand the best upgrade to make, and lessen the burden of cost or mediocre performance, it is a clever idea to have a basic understanding of the differences between VPS hosting and dedicated servers. ## What Is A VPS (Virtual Private Server)? VPS is an acronym for a virtual private server. The term is, of course, self-explanatory: a VPS is a virtual machine that is allocated a set value of CPU, disk, and memory from a cloud hypervisor host. The VPS works just like any normal server, it is pretty much impossible to tell the difference. The VPS logically exists as numerous flat files located network-attached storage, and the cloud hypervisor mimics the functionality of a [dedicated server](https://www.atlantic.net/dedicated-server-hosting/), writing the server state to disk. With VPS hosting, the server’s operating system environment and all the necessary apps come pre-built, ready to go within seconds. We already know that each VPS is allocated CPU, disk, and memory, but these values are dependent on the type of cloud plan the user purchases. Each cloud plan varies; some concentrate on lots of processing power, others provide huge amounts of memory for advanced number crunching, and others focus on high-speed disk for breakneck I/O performance. A cloud hypervisor’s job is to reserve the specific number of CPU cores and RAM chosen for the individual user’s virtual machine plan. Once allocated, the resources are guaranteed, and this on-demand performance is why VPS hosting is recommended to businesses looking for on-demand web servers far more often than shared web hosting might be. Cloud plans make it extremely easy to upgrade individual VPS components as needed. If you need more memory but are okay with your number of CPU cores, look at the available hosting plans to see which matches your needs. ### The Pros and Cons of Using VPS Hosting VPS hosting has many advantages. The most noticeable advantage is that it is much cheaper to operate than a dedicated server is. Another powerful advantage is greater flexibility when integrating with additional cloud services, such as managed services, backups, and more. All of these advantages come without costing much more than a shared tenancy hosting platform. VPS hosting is also easy to upgrade and comes with simple, automated backups. Best of all, a VPS comes configured for remote access, can be cloned within minutes, and comes with built-in monitoring tools. You have full control over your VPS with Atlantic.Net, as we provide root access to the server. There is no shared kernel, and if your application requires a certain version of the software, no problem, you can install it!  On shared hosting, you have to request it from the hosting company, and occasionally the request may be rejected. This only usually happens with legacy software or applications with complicated licensing models such as Java; if it happens to you, you are dead in the water. With these assets in mind, it is easy to see why VPS hosting is popular with web app developers and system administrators. However, there are a few cons with using VPS hosting. The TCO for VPS hosting can be a lot more expensive than the cost of a dedicated server if a business needs a lot of computing power, data, or bandwidth. While web hosts do an excellent job with their server farms’ physical and logical security, they cannot anticipate each customer’s unique security needs. Companies that need custom security or compliance protocols in place may feel more at ease with a dedicated server. ## What Is A Dedicated Server? A dedicated server involves the leasing of an entire physical server. A dedicated server gives the user exclusive access to the entire physical computer. Dedicated servers may come pre-built and ready to go, or you can opt for a barebones configuration – the choice is yours! Atlantic.Net can provide consultancy services if you require a specific build of a server; our professional services teams will do the setup for the customer and assist with any additional changes required. The most significant danger with a business using a dedicated server is jumping into owning one prematurely. If a dedicated server is not required to handle the workload, then that business is spending significantly more than it needs to. You must weigh the benefits; while a dedicated host may effectively future-proof an investment, there may be a chance the server will sit relatively dormant. ### The Pros and Cons of Using a Dedicated Server The most apparent advantage of a dedicated server is that it focuses on the individual business instead of on a group of customer accounts. Dedicated server solutions offer custom-tailored hardware, software, and services. Atlantic.Net can provide customer Cloud Servers / VPSes to custom-fit the customer’s needs. Nothing can beat the long-term value of a dedicated server in high-demand business environments. Some cons go with dedicated servers, however. If the customer chooses to operate everything in-house, then expect large capex invoices for purchasing and licensing cloud server equipment. To avoid a high upfront cost, leasing a dedicated server from a cloud services provider will give you all the power needed without an immediate large investment. Instead, a predictable, monthly opex cost will be charged. Additionally, future upgrades can become complicated, messy, and expensive if not executed by a pragmatic IT team. Migrating to a dedicated server from shared or VPS hosting can also be a difficult transition to make. Because of this, businesses who want a dedicated server but lack their own IT departments can reach out to Atlantic.Net to migrate their existing network infrastructure and to plan/implement any future upgrades. ## Signs It Is Time to Upgrade to a Dedicated Server There are some clear-cut signs that a business is ready to upgrade to a dedicated server. These might include: - The existing server is unable to keep up with application demand - The existing server is suffering from high I/O disk latency - System monitoring tools consistently showing high system load - Customers/users are complaining about poor performance - Network bandwidth limits being reached or VPS plan being exceeded - Complex compliance needs of the business, such as managing a database containing HIPAA-Compliant data - The business is hosting a large online community or digital media for its customers - The business wants to work with data analytics or big data, and have the ability to spike usage then remove the compute VMs while still retaining the data in the cloud. At Atlantic.Net we provide options for On-Demand or Monthly term commits (as well as 1-year and 3-year) but the short term commits enable companies to burst their compute power to tackle projects without having to buy expensive hardware Determine what signs of strain need to show in daily operations before pursuing a dedicated server upgrade—knowing ahead of time what symptoms to look out for keeps the business prepared to make the switch as soon as possible. Additionally, determine which IT firm is best to hire for the VPS hosting migration ahead of time. That creates enough time to review different IT agencies to determine the best fit for industry needs, so the decision is not rushed later when the need for upgrading is imminent. A flexible, logical, and well-organized IT team meets the demands of both the individual business and changes in industry technologies. They make any VPS hosting migration to a dedicated server efficient and graceful. ## Ready to Upgrade to a Dedicated Host? Learn more about our [Dedicated Hosting](https://www.atlantic.net/dedicated-server-hosting/) and talk to a hosting expert today by emailing [sales@atlantic.net](mailto:sales@atlantic.net). We can help you decide whether it’s time to upgrade to a Dedicated Host. --- # How to Set Up a Mail Server with Modoboa on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-set-up-a-mail-server-with-modoboa-on-ubuntu-20-04/ | Published: 2021-04-08 | Updated: 2023-11-18 | Author: Hitesh Jethva Modoboa is a free, open-source, complete mail server solution that comes with Postfix and Dovecot. It is written in Python and allows you to set up a fully functional mail server within a minute. You can create an unlimited number of mailboxes and domains from a web-based interface. It has Let’s Encrypt integration and also includes Amavis frontend to block spam and detect viruses in email. If you are a beginner and don’t know how to set up a mail server, then Modoboa is the best option for you. In this post, we will learn how to set up a mail server with Modoboa on Ubuntu 20.04 server. ## Step 1 – Install Required Dependencies Before starting, you will need to install Python and other required dependencies to your server. You can install all of them with the following command: ``` apt-get install python3-virtualenv python3-pip git curl gnupg2 ``` Once all the packages are installed, set up an FQDN hostname with the following command: ``` hostnamectl set-hostname email.linuxbuz.com ``` ## Step 2 – Install and Configure Modoboa First, download the latest version of Modoboa with the following command: ``` git clone https://github.com/modoboa/modoboa-installer ``` Once the download is completed, change the directory to the downloaded directory and check the configuration file with the following command: ``` cd modoboa-installer python3 ./run.py --stop-after-configfile-check linuxbuz.com ``` You should see that the Modoboa configuration file is not found: ``` Welcome to Modoboa installer! Configuration file installer.cfg not found, creating new one. ``` Next, create a configuration file for Modoboa with the following command: ``` nano installer.cfg ``` Change the following lines that match your domain name and email address: ``` [general] hostname = email.%(domain)s [certificate] generate = true type = letsencrypt [letsencrypt] email = admin@gmail.com [database] engine = postgres host = 127.0.0.1 install = true ``` Save and close the file, then start the Modoboa installation with the following command: ``` python3 ./run.py --interactive linuxbuz.com ``` Once the installation has been finished, you should get the following output: ``` Welcome to Modoboa installer! Warning: Before you start the installation, please make sure the following DNS records exist for domain 'linuxbuz.com': email IN A IN MX email.linuxbuz.com. Your mail server will be installed with the following components: modoboa automx amavis clamav dovecot nginx razor postfix postwhite spamassassin uwsgi radicale opendkim Do you confirm? (Y/n) y The process can be long, feel free to take a coffee and come back later ;) Starting... Generating new certificate using letsencrypt Installing amavis Installing spamassassin Installing razor Installing clamav Installing modoboa Installing automx Installing radicale Installing uwsgi Installing nginx Installing opendkim Installing postfix Installing postwhite Installing dovecot Congratulations! You can enjoy Modoboa at https://email.linuxbuz.com (admin:password) ``` Next, you will need to edit the Nginx main configuration file and increase the hash_bucket size limit: ``` nano /etc/nginx/nginx.conf ``` Add the following line after http{ ``` server_names_hash_bucket_size 64; ``` Save and close the file, then restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 3 – Access Modoboa Web UI Now, open your web browser and access the Modoboa web UI using the URL **https://email.linuxbuz.com**. You will be redirected to the Modoboa login page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p1-8-1024x512.png) Provide default admin username and password as admin / password and click on the **Login** button. You should see the Modoboa dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p2-5-1024x505.png) ## Conclusion Congratulations! You have successfully installed the Modoboa mail server on Ubuntu 20.04. You can now add a mailbox from the Modaboa admin panel and start sending mail from the web UI using your [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net. --- # How to Install Talkyard Forum with Nginx on Ubuntu 18.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-talkyard-forum-with-nginx-on-ubuntu-18-04/ | Published: 2021-04-09 | Updated: 2023-11-18 | Author: Hitesh Jethva Talkyard is a free and open-source community discussion platform that helps you to share knowledge with your co-workers, customers, volunteers, users. It is an alternative to other discussion platforms including StackOverflow, Slack, Discourse, and Reddit. You can use it as a knowledge base, customer support, discussion forum, and much more. In this post, we will show you how to install Talkyard Forum with Nginx on Ubuntu 18.04. ## Step 1 – Install Required Dependencies First, you will need to install some required dependencies to your server. You can install all of them with the following command: ``` apt-get install git curl gnupg2 unzip -y ``` Once all the dependencies are installed, you can proceed to the next step. ## Step 2 – Download Talkyard First, you will need to download the Talkyard from the Git Hub repository. You can download it with the following command: ``` git clone -b w-km2 --single-branch https://github.com/debiki/talkyard-prod-one.git talkyard ``` Once the download is completed, change the directory to talkyard and install the required packages with the following command: ``` cd talkyard ./scripts/prepare-ubuntu.sh ``` ## Step 3 – Install Docker and Docker Compose Next, you will need to install the Docker and Docker compose to your system. You can install them by running the following script: ``` ./scripts/install-docker-compose.sh ``` Once both are installed, edit the play-framework.conf file and change some required values: ``` nano conf/play-framework.conf ``` Change the following lines: ``` talkyard.becomeOwnerEmailAddress="admin@example.com" talkyard.hostname="talkyard.example.com" play.http.secret.key="your-secure-key" ``` Save and close the file, then edit the .env file and define your database password: ``` nano .env ``` Change the following line: ``` POSTGRES_PASSWORD=your-database-password ``` Save and close the file when you are finished. ## Step 4 – Copy Docker Compose File Next, you will need to copy a desired Docker Compose file depending on how much RAM your server has. If your server has 2GB RAM, copy the following file: ``` cp mem/2g.yml docker-compose.override.yml ``` If your server has 4GB RAM, copy the following file: ``` cp mem/4g.yml docker-compose.override.yml ``` ## Step 5 – Install Talkyard Now, you will need to install the Talkyard with all the required app. You can start the installation by running the following script: ``` ./scripts/upgrade-if-needed.sh ``` You should get the following output: ``` 2021-03-13T07:23:03+00:00 upgrade-script: Installing: Starting version v0.2021.08-639ccf013... Creating network "talkyard_internal_net" with driver "bridge" Creating talkyard_cache_1 ... done Creating talkyard_rdb_1 ... done Creating talkyard_search_1 ... done Creating talkyard_app_1 ... done Creating talkyard_web_1 ... done 2021-03-13T07:23:09+00:00 upgrade-script: Installing: Setting current version number to v0.2021.08-639ccf013... 2021-03-13T07:23:09+00:00 upgrade-script: Done. Bye. ``` Once the installation is completed, you can check all running containers with the following command: ``` docker ps ``` You should see the following output: ``` CONTAINER ID I MAGE COMMAND CREATED STATUS PORTS NAMES 5793fefc561b debiki/talkyard-web:v0.2021.08-639ccf013 "/bin/sh -c '/etc/ng…" 31 seconds ago Up 28 seconds 0.0.0.0:80->80/tcp, 0.0.0.0:443->443/tcp talkyard_web_1 b3fee6dd28b8 debiki/talkyard-app:v0.2021.08-639ccf013 "/bin/sh -c 'rm -f /…" 32 seconds ago Up 3 seconds 3333/tcp, 9000/tcp, 9443/tcp, 9999/tcp talkyard_app_1 0898dbac769d debiki/talkyard-cache:v0.2021.08-639ccf013 "docker-entrypoint.s…" 36 seconds ago Up 32 seconds 6379/tcp talkyard_cache_1 e583d8a4d553 debiki/talkyard-rdb:v0.2021.08-639ccf013 "/chown-logs-then-ex…" 36 seconds ago Restarting (1) 5 seconds ago talkyard_rdb_1 878e757d274d debiki/talkyard-search:v0.2021.08-639ccf013 "/docker-entrypoint.…" 36 seconds ago Up 33 seconds 9200/tcp, 9300/tcp talkyard_search_1 ``` ## Step 6 – Setup Cron Job Next, you will need to set up a cron job to schedule auto backup and enable automatic upgrades. You can set up it by running the following scripts: ``` ./scripts/schedule-logrotate.sh ./scripts/schedule-daily-backups.sh ./scripts/schedule-automatic-upgrades.sh ``` You can also check the Talkyard container log with the following command: ``` docker-compose logs app docker-compose logs rdb ``` ## Step 7 – Access Talkyard At this point, Talkyard is installed and configured. Now, open your web browser and access the URL **http://talkyard.example.com**. You will be redirected to the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p1-4-1024x426.png) Click on the **Continue** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p2-2-1024x566.png) Provide your admin email, username, and password, and click on the **Create Account** button. You will be redirected to the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p4-1-1024x421.png) Provide your community name and click on the **Next** button. You should see the Talkyard dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p5-1024x545.png) ![](https://www.atlantic.net/wp-content/uploads/2021/03/p6-1024x536.png) ## Conclusion Congratulations! You have successfully installed and configured Talkyard on Ubuntu 18.04. You can now create your own discussion forum with Talkyard easily using your [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net. --- # How to Install EteSync Server on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-etesync-server-on-ubuntu-20-04/ | Published: 2021-04-12 | Updated: 2023-11-23 | Author: Hitesh Jethva EteSync is a free, open-source, and end-to-end tool used to sync your contacts, calendars, tasks, and notes. It can be easily integrated with your existing apps. You just need one password for login and encryption. EteSync has the ability to share data with other users and synchronization between multiple devices. It also provides an add-on for Mozilla Thunderbird and a client for Web, Desktop, Android, and iOS. In this post, we will show you how to install EteSync on Ubuntu 20.04 server.[jumpbox] ## Step 1 – Install and Configure MariaDB Database EteSync uses MariaDB as a database backend, so the latest version of MariaDB must be installed on your server. First, install the required dependencies with the following command: ``` apt-get update -y apt-get install software-properties-common curl git gnupg2 -y ``` Next, download and add the GPG key and repository with the following command: ``` apt-key adv --recv-keys --keyserver hkp://keyserver.ubuntu.com:80 0xF1656F24C74CD1D8 add-apt-repository 'deb [arch=amd64,arm64,ppc64el] http://mirror.lstn.net/mariadb/repo/10.5/ubuntu focal main' ``` Next, install the latest version of the MariaDB server with the following command: ``` apt-get install mariadb-server -y ``` Next, connect to the MariaDB and create a database and user: ``` mysql ``` Once connected, create a database and user with the following command: ``` create database etebase; create user etebase@localhost identified by 'password'; ``` Next, grant all the privileges to the etebase database with the following command: ``` grant all privileges on etebase.* to etebase@localhost; ``` Next, flush the privileges and exit from the MariaDB with the following command: ``` flush privileges; exit; ``` ## Step 2 – Install EteSync First, you will need to install all Python dependencies to your server. You can install all of them with the following command: ``` apt-get install python3-virtualenv python3-pip gcc build-essential libmysqlclient-dev -y ``` Once all the dependencies are installed, download the latest version of EteSync with the following command: ``` git clone https://github.com/etesync/server.git etebase ``` Next, change the directory to the downloaded directory and create a Python virtual environment with the following command: ``` cd etebase virtualenv -p python3 .venv ``` Next, activate the virtual environment with the following command: ``` source .venv/bin/activate ``` Next, install all required dependencies with the following command: ``` pip install -r requirements.txt ``` Next, rename the example configuration file: ``` cp etebase-server.ini.example etebase-server.ini ``` Next, edit the configuration file with the following command: ``` nano etebase-server.ini ``` Change the following lines: ``` media_root = /mnt allowed_host1 = etebase.example.com ;engine = django.db.backends.sqlite3 ;name = db.sqlite3 engine = django.db.backends.mysql name = etebase user = etebase password = password host = 127.0.0.1 port = 3306 ``` Save and close the file, then install the Django web socket server and MariaDB client with the following command: ``` pip3 install daphne mysqlclient aioredis ``` Next, create Django’s static files with the following command: ``` ./manage.py collectstatic ``` Next, initialize the application with the following command: ``` ./manage.py migrate ``` Next, start the EteSync server with the following command: ``` daphne -b 0.0.0.0 -p 8001 etebase_server.asgi:application ``` You should get the following output: ``` 2021-03-13 04:30:04,102 INFO Starting server at tcp:port=8001:interface=0.0.0.0 2021-03-13 04:30:04,103 INFO HTTP/2 support not enabled (install the http2 and tls Twisted extras) 2021-03-13 04:30:04,103 INFO Configuring endpoint tcp:port=8001:interface=0.0.0.0 2021-03-13 04:30:04,104 INFO Listening on TCP address 0.0.0.0:8001 ``` Press CTRL+C to stop the server. ## Step 3 – Create a Systemd Service File for EteSync Next, you will need to create a systemd service file for EteSync. You can create it with the following command: ``` nano /etc/systemd/system/etebase.service ``` Add the following lines: ``` [Unit] Description=EteSync: End-to-End Encryption to Sync Calendar, Contacts, Tasks and Notes. [Service] WorkingDirectory=/root/etebase/ ExecStart=/root/etebase/.venv/bin/daphne -b 127.0.0.1 -p 8001 -u /tmp/etebase_server.sock etebase_server.asgi:application User=root Group=root Restart=always RestartSec=5s [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the EteSync service and enable it to start at system reboot with the following command: ``` systemctl start etebase systemctl enable etebase ``` Next, verify the status of the EteSync service with the following command: ``` systemctl status etebase ``` You should get the following output: ``` ● etebase.service - EteSync: End-to-End Encryption to Sync Calender, Contacts, Tasks and Notes. Loaded: loaded (/etc/systemd/system/etebase.service; disabled; vendor preset: enabled) Active: active (running) since Sat 2021-03-13 04:30:57 UTC; 6s ago Main PID: 13641 (daphne) Tasks: 1 (limit: 2353) Memory: 48.5M CGroup: /system.slice/etebase.service └─13641 /root/etebase/.venv/bin/python /root/etebase/.venv/bin/daphne -b 127.0.0.1 -p 8001 -u /tmp/etebase_server.sock etebase_se> Mar 13 04:30:57 ubuntu2004 systemd[1]: Started EteSync: End-to-End Encryption to Sync Calender, Contacts, Tasks and Notes.. Mar 13 04:30:58 ubuntu2004 daphne[13641]: 2021-03-13 04:30:58,437 INFO Starting server at tcp:port=8001:interface=127.0.0.1, unix:/tmp/ete> Mar 13 04:30:58 ubuntu2004 daphne[13641]: 2021-03-13 04:30:58,438 INFO HTTP/2 support not enabled (install the http2 and tls Twisted extra> Mar 13 04:30:58 ubuntu2004 daphne[13641]: 2021-03-13 04:30:58,439 INFO Configuring endpoint tcp:port=8001:interface=127.0.0.1 Mar 13 04:30:58 ubuntu2004 daphne[13641]: 2021-03-13 04:30:58,441 INFO Listening on TCP address 127.0.0.1:8001 Mar 13 04:30:58 ubuntu2004 daphne[13641]: 2021-03-13 04:30:58,441 INFO Configuring endpoint unix:/tmp/etebase_server.sock ``` ## Step 4 – Configure Nginx for EteSync Next, install the Nginx with the following command: ``` apt-get install nginx -y ``` Once installed, create an Nginx virtual host configuration file with the following command: ``` nano /etc/nginx/conf.d/etebase.conf ``` Add the following lines: ``` upstream etebase { server unix:/tmp/etebase_server.sock; } server { listen 80; server_name etebase.example.com; charset utf-8; access_log /var/log/nginx/etebase.access; error_log /var/log/nginx/etebase.error; # max upload size client_max_body_size 75M; location /static/ { alias /root/etebase/static/; } location / { proxy_pass http://etebase; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_redirect of/f; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Host $server_name; } } ``` Save and close the file, then restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 5 – Create an Admin User Next, you will need to create an administrative user for EteSync. First, change the directory to etebase and activate the virtual environment if not activated: ``` cd etebase source .venv/bin/activate ``` Next, create a superuser with the following command: ``` ./manage.py createsuperuser ``` Provide all information as shown below: ``` Username: admin Email address: admin@example.com Password: Password (again): Superuser created successfully. ``` ## Step 6 – Access EteSync Now, open your web browser and access your EteSync web interface using the URL **http://etebase.example.com/admin**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p1-5.png) Provide your username, password and click on the **Login** button. You should see the EteSync dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p2-3.png) ## Conclusion Congratulations! You have successfully installed and configured EteSync on Ubuntu 20.04 server. You can now easily sync your contacts, calendars, tasks, and notes using [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Socioboard on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-socioboard-on-ubuntu-20-04/ | Published: 2021-04-13 | Updated: 2024-01-18 | Author: Hitesh Jethva Socioboard is a free, open-source social media management tool used for managing multiple social media channels from a central dashboard. It is used by small and medium-sized businesses for lead generation, marketing, customer support, and automated engagement. It comes with a rich set of features including advanced scheduling & publishing tools, social CRM tools, customizability, scalability, customer support, Helpdesk integration, and more. In this post, we will show you how to install Socioboard with Apache on Ubuntu 20.04. ## Step 1 – Install Apache, PHP and MariaDB First, Apache, PHP, MariaDB, and other required packages by running the following command: ``` apt-get update -y apt-get install apache2 mariadb-server php libapache2-mod-php7.4 php7.4-cli php7.4-mysql php7.4-common php7.4-json php7.4-opcache php7.4-readline php7.4-curl php7.4-gd php7.4-xml git curl gnupg2 -y ``` After installing all the packages, you can proceed to the next step. ## Step 2 – Create a MariaDB Database Next, you will need to create a database and user for Socioboard. First, connect to MariaDB with the following command: ``` mysql ``` Once connected, create a database and user with the following command: ``` create database socioboarddb; create user socioboarduser@localhost identified by 'password'; ``` Next, grant all the privileges with the following command: ``` grant all privileges on socioboarddb.* to socioboarduser@localhost; ``` Next, flush the privileges and exit from MariaDB with the following command: ``` flush privileges; exit; ``` ## Step 3 – Install and Configure MongoDB Next, you will need to install MongoDB and create a database for Socioboard. First, add the MongoDB repository with the following command: ``` wget -qO - https://www.mongodb.org/static/pgp/server-4.4.asc | apt-key add - echo "deb [ arch=amd64,arm64 ] https://repo.mongodb.org/apt/ubuntu focal/mongodb-org/4.4 multiverse" | tee /etc/apt/sources.list.d/mongodb-org-4.4.list ``` Next, update the repository and install MongoDB with the following command: ``` apt-get update -y apt-get install mongodb-org -y ``` Next, start the MongoDB service with the following command: ``` systemctl start mongod ``` Next, connect MongoDB and create a database and user with the following command: ``` mongo use socioboarddb db.new_collection.insert({ some_key: "some_value" }) db.createUser( { user: "socioboarduser", pwd: "password", roles: [ { role: "readWrite", db: "socioboarddb" } ] } ) ``` Next, exit from the Mongo shell with the following command: ``` exit ``` ## Step 4 – Install Node.js First, install the necessary dependencies using the following command. ``` apt-get install -y ca-certificates curl gnupg ``` Next, download the Node.js GPG key. ``` mkdir -p /etc/apt/keyrings curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg ``` Next, add the NodeSource repo to the APT source list. ``` echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_18.x nodistro main" | tee /etc/apt/sources.list.d/nodesource.list ``` Then, update the repository index and install the Ndoe.js with the following command. ``` apt update apt-get install -y nodejs ``` Next, verify the Node.js version using the following command. ``` node -v ``` Output. ``` v18.19.0 ``` ## Step 5 – Install Socioboard First, download the latest version of Socioboard and copy it to the Apache web root directory: ``` git clone https://github.com/socioboard/Socioboard-4.0.git mv Socioboard-4.0 /var/www/html/socioboard ``` Next, change the ownership of the socioboard directory to www-data: ``` chown -R www-data:www-data /var/www/html/socioboard ``` Next, edit the config.json file and define your MariaDB database settings: ``` nano /var/www/html/socioboard/socioboard-api/library/sequelize-cli/config/config.json ``` Change the following lines: ``` { "development": { "username": "socioboarduser", "password": "password", "database": "socioboarddb", "host": "127.0.0.1", "dialect": "mysql", "operatorsAliases": false, "pool": { "max": 100, "min": 0, "acquire": 1000000, "idle": 200000 }, ``` Save and close the file, then change the directory to feeds, library, notification, and publish directory and install all the dependencies for each: ``` cd /var/www/html/socioboard/socioboard-api/feeds npm install npm audit fix cd /var/www/html/socioboard/socioboard-api/library npm install cd /var/www/html/socioboard/socioboard-api/notification npm install cd /var/www/html/socioboard/socioboard-api/publish npm install cd /var/www/html/socioboard/socioboard-api/user npm install ``` Next, initialize the database with the following command: ``` cd /var/www/html/socioboard/socioboard-api/library/sequelize-cli/ NODE_ENV=development sequelize db:migrate ``` Next, list all files inside seeders directory: ``` ls /var/www/html/socioboard/socioboard-api/library/sequelize-cli/seeders/ ``` Output: ``` 20190213051930-initialize_application_info.js 20190507065043-initialize_dummy_users.js 20190507122417-initialize_socialaccounts.js 20190509121650-unauthorized_unittest_accounts.js ``` Next, pick the file that ends with initialize_application_info.js and run the following command: ``` NODE_ENV=development sequelize db:seed --seed 20190213051930-initialize_application_info.js ``` Next, edit the development.json and define your MongoDB database: ``` nano /var/www/html/socioboard/socioboard-api/user/config/development.json ``` Change the following lines: ``` "mongo": { "username": "socioboarduser", "password": "password", "host": "localhost", "db_name": "socioboarddb" }, ``` Save and close the file then edit each of the following files and define your MongoDB database settings: ``` nano /var/www/html/socioboard/socioboard-api/feeds/config/development.json nano /var/www/html/socioboard/socioboard-api/notification/config/development.json nano /var/www/html/socioboard/socioboard-api/publish/config/development.json ``` ## Step 6 – Create a Systemd Service File for Socioboard First, create a systemd service file for Socioboard user with the following command: ``` nano /etc/systemd/system/socioboard-user.service ``` Add the following lines: ``` [Unit] Description=SocioBoard User Microservice After=multi-user.target [Service] Type=simple User=www-data WorkingDirectory=/var/www/html/socioboard/socioboard-api/user/ Environment=NODE_ENV=development ExecStart=/usr/bin/nodemon app.js Restart=on-failure RestartSec=5 [Install] WantedBy=multi-user.target ``` Save and close the file, then create a systemd service file for Socioboard publish with the following command: ``` nano /etc/systemd/system/socioboard-publish.service ``` Add the following lines: ``` [Unit] Description=SocioBoard Publish Microservice After=multi-user.target [Service] Type=simple User=www-data WorkingDirectory=/var/www/html/socioboard/socioboard-api/publish/ Environment=NODE_ENV=development ExecStart=/usr/bin/nodemon app.js Restart=on-failure RestartSec=5 [Install] WantedBy=multi-user.target ``` Save and close the file, then create a systemd service file for Socioboard feeds with the following command: ``` nano /etc/systemd/system/socioboard-feeds.service ``` Add the following lines: ``` [Unit] Description=SocioBoard Feeds Microservice After=multi-user.target [Service] Type=simple User=www-data WorkingDirectory=/var/www/html/socioboard/socioboard-api/feeds/ Environment=NODE_ENV=development ExecStart=/usr/bin/nodemon app.js Restart=on-failure RestartSec=5 [Install] WantedBy=multi-user.target ``` Save and close the file, then create a systemd service file for Socioboard notification: ``` nano /etc/systemd/system/socioboard-notification.service ``` Add the following lines: ``` [Unit] Description=SocioBoard Notification Microservice After=multi-user.target [Service] Type=simple User=www-data WorkingDirectory=/var/www/html/socioboard/socioboard-api/notification/ Environment=NODE_ENV=development ExecStart=/usr/bin/nodemon app.js Restart=on-failure RestartSec=5 [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start all the services and enable them to start at system reboot: ``` systemctl start socioboard-user socioboard-publish socioboard-feeds socioboard-notification systemctl enable socioboard-user socioboard-publish socioboard-feeds socioboard-notification ``` Next, verify the status of all services with the following command: ``` systemctl status socioboard-user socioboard-publish socioboard-feeds socioboard-notification ``` ## Step 7 – Configure Socioboard-web-php Next, change the directory to socioboard-web-php with the following command: ``` cd /var/www/html/socioboard/socioboard-web-php/ ``` Note: If you encounter any issues with the following, retry after disabling IPV6 ``` sysctl -w net.ipv6.conf.all.disable_ipv6=1 ``` Next, install the Composer with the following command: ``` apt-get install composer -y ``` Next, install the Laravel components with the following command: ``` composer global require laravel/installer ``` Next, rename the environment variable file with the following command: ``` mv environmentfile.env .env ``` Next, edit the .env file: ``` nano .env ``` Change the following lines: ``` APP_URL=http://socioboard.linuxbuz.com/ API_URL=http://localhost:3000/ API_URL_PUBLISH=http://localhost:3001/ API_URL_FEEDs=http://localhost:3002/ API_URL_NOTIFY=http://localhost:3003/ ``` Save and close the file, then update the composer with the following command: ``` composer update ``` Next, generate the Laravel app key with the following command: ``` php artisan key:generate ``` ## Step 8 – Configure Apache for Socioboard Next, create an Apache virtual host configuration file for Socioboard: ``` nano /etc/apache2/sites-available/socioboard.conf ``` Add the following lines: ``` ServerName socioboard.linuxbuz.com DocumentRoot /var/www/html/socioboard/socioboard-web-php/public/ DirectoryIndex index.php Options +FollowSymLinks AllowOverride All Require all granted ErrorLog ${APACHE_LOG_DIR}/socioboard.error.log CustomLog ${APACHE_LOG_DIR}/socioboard.access.log combined ``` Save and close the file, then enable the Apache virtual host and rewrite module with the following command: ``` a2ensite socioboard.conf a2enmod rewrite ``` Next, restart the Apache and Socioboard services with the following command: ``` systemctl restart apache2 systemctl restart socioboard-user socioboard-publish socioboard-feeds socioboard-notification ``` ## Step 9 – Access Socioboard Now, open your web browser and access the Socioboar using the URL **http://socioboard.linuxbuz.com**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p1-7-1024x540.png) Click on the **Create** **New** button to create a new account. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/a1.png) Provide all the details and click on the **Create an account now** button. Socioboard tries to send a verification email, but it can not send an email. You will need to activate the account from the MariaDB console. Connect to the MariaDB with the following command: ``` mysql ``` Once connected, change the database to socioboarddb and activate the account with the following command: ``` use socioboarddb; update user_activations set activation_status = 1; ``` Next, change the account to Platinum plan with the following command: ``` update user_activations set user_plan = 7; ``` Next, exit from the MariaDB with the following command: ``` exit; ``` ![](https://www.atlantic.net/wp-content/uploads/2021/03/a2-1024x491.png) ![](https://www.atlantic.net/wp-content/uploads/2021/03/p3-5-1024x543.png) Now go back to your web interface, enter your email and password which you have provided during the registration process, and click on the Login button. You should see the Socioboard dashboard on the following page: ## Conclusion In the above guide, you learned how to install Socioboard on Ubuntu 20.04. You can implement it in your organizations and manage all social media channels from the central dashboard on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net! --- # Broward County Schools Ransomware Attack > URL: https://www.atlantic.net/dedicated-server-hosting/broward-county-schools-ransomware-attack/ | Published: 2021-04-14 | Updated: 2026-05-03 | Author: Richard Bailey *Atlantic.Net is providing this security advisory as a news item; we want to reassure our customers that Atlantic.Net does not use any of these products affected by this exploit internally or in any of our service offerings.* Local news reported that Florida-based Broward County Public Schools are in the midst of a serious cybersecurity incident. Experts believe a cybersecurity attack took place against Broward IT Systems in early [March](https://www.sun-sentinel.com/local/schools/fl-ne-broward-schools-computer-malware-20210309-6sjzaxdmyvcuhjmlxefpqrinfi-story.html). Broward County is home to approximately 240 public schools, ranging from elementary to high schools, and some 260,000 students attend schools in this Florida district. [Reports](https://www.wptv.com/news/state/broward/computer-hackers-demand-40-million-ransom-from-broward-county-public-schools) suggest that the schools’ computer systems have been targeted by a ransomware attack. Most shockingly, the cybercriminals are demanding a payment of $40 million or they will release “personal information” about students and staff. So far, Broward County Schools have remained tight-lipped, neither confirming nor denying the cybersecurity threat. ## What do we know about the Broward County Schools breach? The Hackers claim to have stolen 1.5TB of data from the Broward County Schools backend IT systems. In a [transcript of phone messages published online](https://www.scribd.com/document/501190779/Broward-County-Public-Schools-ransom-chat#fullscreen&from_embed), the hackers claim that “personal data, including financial, contracts, databases and other documents containing (Social Security numbers) addresses (dates of birth) and other information about students and teachers” had been stolen. Many students are still having to learn remotely due to the Covid-19 pandemic, and these students and parents reported issues with some of Broward County IT Systems on the 9th of March 2021. Students were unable to access the primary learning platform known as Canvas. Other applications were reported offline including Pinnacle (a grading and attendance tool), and access to some of the school databases was cut. The[South Florida Sun-Sentinel](https://www.sun-sentinel.com/local/schools/fl-ne-broward-schools-computer-malware-20210309-6sjzaxdmyvcuhjmlxefpqrinfi-story.html) started to receive information from parents and teachers that “Pinnacle was scheduled to be back online at noon Wednesday [10th March]. A program called Virtual Counselor would be back up at noon Saturday [13th March] and one called BASIS, which hosts a variety of student data, would be up at 10 a.m. Monday [15th March].” This information seems to add credibility that the ransomware attack was genuine. The hackers are believed to be the group known as Conti. Not much is known about Conti, but they are thought to be based in Russia, and there is online chatter that the group is a successor to Ryuk.  They do have a reputation; British retailer[FatFace paid Conti £2 million](https://www.cybernewsgroup.co.uk/fat-face-pays-2m-to-conti-ransomware-gang/) in March 2021, so there is a good chance that they are expecting Broward County Schools to pay the ransom. According to a leaked Scribd conversation allegedly between Conti and Broward County, an offer of $500,000 was made to the hackers. We don’t know if this was accepted or what has happened, there has been radio silence from the Conti dark web leak site that published the information. Maybe they have been paid? We simply do not know! ## What are the likely causes of the breach? We can only speculate at the moment because the schools have not released anything directly, but we expect this breach to be caused by a lack of training. Either a member of staff or a student with access to the internal systems clicked on a phishing email, a malicious URL link, or a TrickBot website, or they downloaded a compromised attachment embedded with malware. Broward Schools manage and support their own private IT network, and it is believed to be operated in-house and managed at their [head office](https://www.browardschools.com/domain/13490). It’s possible a system was secured with a weak, guessable password. It is also likely that they were targeted simply because they are a school,  as public schools have strict, limited budgets and cybersecurity may not always be the number one priority. Schools are data-rich environments; they hold sensitive data on students who are approaching adulthood and will soon be applying for bank accounts, credit cards, and student loans. The data is valuable as it could potentially be used for fraud. Broward Schools may have been targeted because of the enforced remote working for students and teachers, In December 2020, the [Cybersecurity and Infrastructure Security](https://www.cisa.gov/stopransomware/official-alerts-statements-cisa) Agency, a federal agency, said cybercriminals like Conti have been aiming their sights more on schools due to the transition to remote learning during the COVID-19 pandemic. ## What happens next? With Broward County Schools being tight-lipped, it is very much a case of “wait and see what happens.” Have they paid the ransom? Have they even been hacked? Truthfully no one knows yet, and while some suggestive evidence has been released, there is no way of validating if it’s genuine. If your business is concerned about cybersecurity. please feel welcome to reach out to Atlantic.Net. We are specialists in Managed Services, Cloud Hosting, and HIPAA compliance. Security of our infrastructure is of paramount importance, and we work hard to ensure we have the best security processes in place. There is no doubt that this cyberattack is a very sensitive incident. Targeting schools is very demoralizing, and we feel concerned for any of our friends in the state of Florida that might be affected by this. Atlantic.Net has a full suite of [Managed Security Services](https://www.atlantic.net/pci-compliant-hosting/pci-security-services/) to help be proactive and prepare in advance for any security issues. Get in touch today. --- # How to Upgrade Ubuntu 20.04 to Ubuntu 21.04 > URL: https://www.atlantic.net/vps-hosting/how-to-upgrade-ubuntu-20-04-to-ubuntu-21-04/ | Published: 2021-04-26 | Updated: 2023-11-27 | Author: Hitesh Jethva The new Ubuntu 21.04 (Hirsute Hippo) has been released on 22 April 2021. Ubuntu 20.04 is long-term support and will be supported for five years. Ubuntu 21.04 is not a long-term support release, meaning it will be kept until January 2022 (9 months). Before upgrading to Ubuntu 21.04 version, you should be aware of the following things: - The upgrade will download a couple of GBs of data so you will need a good internet connection. - Backing your essential files to an external hard disk is always recommended. - After upgrading to a newer version, you can revert to the older version. - Upgrading to a newer version will turn off the third-party repositories that you have added on your own. This post will show you how to upgrade from Ubuntu 20.04 to Ubuntu 21.04. ## Step 1 – Update the System Before starting, check the current version of Ubuntu with the following command: ``` lsb_release -a ``` You should see the following output: ``` Distributor ID: Ubuntu Description: Ubuntu 20.04 LTS Release: 20.04 Codename: focal ``` Next, update your system to the latest packages with the following command: ``` apt-get update -y apt-get upgrade -y apt-get dist-upgrade -y ``` Next, install the update-manager-core with the following command: ``` apt-get install update-manager-core -y ``` Next, remove all unwanted packages with the following command: ``` apt-get clean apt-get --purge autoremove ``` Next, restart your system to apply the changes: ``` reboot ``` ## Step 2 – Upgrade 20.04 to Ubuntu 21.04 Ubuntu 21.04 is a non-LTS version, so you will need to edit the file /etc/update-manager/release-upgrades and change the LTS version to normal: ``` nano /etc/update-manager/release-upgrades ``` Find the following line: ``` Prompt=lts ``` Replaced it with the next line: ``` Prompt=normal ``` Save and close the file when you are finished. Run the following command to upgrade to Ubuntu 20.10 first. After that, follow the same steps to upgrade to Ubuntu 21.04. ``` do-release-upgrade ``` Follow the on-screen installation instructions to finish the process. Once the upgrade process has been completed, your system will be restarted automatically. After restarting, log in to your system and verify the version of your Ubuntu with the following command: ``` lsb_release -a ``` ``` Distributor ID: Ubuntu Description: Ubuntu 20.10 Release: 20.10 Codename: groovy ``` Now, run the following command to upgrade from Ubuntu 20.10 to 21.04: ``` do-release-upgrade -d ``` After restarting, log in to your system and verify the version of your Ubuntu with the following command: ``` lsb_release -a ``` You should see that your system will be updated to Ubuntu 21.04: ``` Distributor ID: Ubuntu Description: Ubuntu 21.04 Release: 21.04 Codename: hirsute ``` ## Conclusion The above guide taught you how to upgrade from Ubuntu 20.04 to Ubuntu 21.04. Ubuntu 21.04 is a non-LTS version, so stick with the Ubuntu 20.04 version if you need a stable version. If you don’t, try it on your [virtual private server](https://www.atlantic.net/vps-hosting/) today! --- # How to Install ClickHouse on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-clickhouse-on-ubuntu-20-04/ | Published: 2021-04-27 | Updated: 2023-11-17 | Author: Hitesh Jethva ClickHouse is a free, open-source, fast OLAP database management system used to generate analytical reports using SQL queries in real-time. It is column-oriented and has other important characteristics like user-friendliness, scalability, and security. It stores records in blocks grouped by columns instead of rows. Compared to row-based systems, column-oriented databases spend less time reading and computing the data. In this post, we will show you how to install and ClickHouse on Ubuntu 20.04 server. ## Step 1 – Add ClickHouse Repository By default, ClickHouse is not included in the Ubuntu 20.04 default repository, so you will need to add the ClickHouse repository to your system. First, install the required dependencies using the following command: ``` apt-get install curl gnupg2 wget git apt-transport-https ca-certificates -y ``` Once all the dependencies are installed, add the GPG key with the following command: ``` apt-key adv --keyserver keyserver.ubuntu.com --recv E0C56BD4 ``` Output: ``` Executing: /tmp/apt-key-gpghome.kaYYOnkSVy/gpg.1.sh --keyserver keyserver.ubuntu.com --recv E0C56BD4 gpg: key C8F1E19FE0C56BD4: public key "ClickHouse Repository Key " imported gpg: Total number processed: 1 gpg: imported: 1 ``` Next, add the ClickHouse repository to APT with the following command: ``` echo "deb http://repo.yandex.ru/clickhouse/deb/stable/ main/" | tee /etc/apt/sources.list.d/clickhouse.list ``` Next, update the repository with the following command: ``` apt-get update -y ``` ## Step 2 – Install ClickHouse Now, install the ClickHouse server and client with the following command: ``` apt-get install clickhouse-server clickhouse-client -y ``` Once the ClickHouse is installed, start the ClickHouse service and enable it to start at system reboot: ``` systemctl start clickhouse-server systemctl enable clickhouse-server ``` You can now verify the status of the ClickHouse with the following command: ``` systemctl status clickhouse-server ``` Output: ``` ● clickhouse-server.service - ClickHouse Server (analytic DBMS for big data) Loaded: loaded (/etc/systemd/system/clickhouse-server.service; enabled; vendor preset: enabled) Active: active (running) since Wed 2021-05-05 03:17:41 UTC; 4s ago Main PID: 26649 (clckhouse-watch) Tasks: 46 (limit: 2353) Memory: 46.4M CGroup: /system.slice/clickhouse-server.service ├─26649 clickhouse-watchdog --config=/etc/clickhouse-server/config.xml --pid-file=/run/clickhouse-server/clickhouse-server> └─26650 /usr/bin/clickhouse-server --config=/etc/clickhouse-server/config.xml --pid-file=/run/clickhouse-server/clickhouse-server> May 05 03:17:41 ubuntu2004 systemd[1]: Started ClickHouse Server (analytic DBMS for big data). May 05 03:17:41 ubuntu2004 clickhouse-server[26649]: Processing configuration file '/etc/clickhouse-server/config.xml'. May 05 03:17:41 ubuntu2004 clickhouse-server[26649]: Logging trace to /var/log/clickhouse-server/clickhouse-server.log May 05 03:17:41 ubuntu2004 clickhouse-server[26649]: Logging errors to /var/log/clickhouse-server/clickhouse-server.err.log May 05 03:17:41 ubuntu2004 clickhouse-server[26650]: Processing configuration file '/etc/clickhouse-server/config.xml'. May 05 03:17:41 ubuntu2004 clickhouse-server[26650]: Saved preprocessed configuration to '/var/lib/clickhouse/preprocessed_configs/config.xml'. May 05 03:17:41 ubuntu2004 clickhouse-server[26650]: Processing configuration file '/etc/clickhouse-server/users.xml'. May 05 03:17:41 ubuntu2004 clickhouse-server[26650]: Saved preprocessed configuration to '/var/lib/clickhouse/preprocessed_configs/users.xml'. ``` ## Step 3 – Set ClickHouse Password By default, ClickHouse is configured without a password, so you will need to set the password for the default user. You can set it by editing the file users.xml: ``` nano /etc/clickhouse-server/users.xml ``` Find the following line: ``` ``` And, replaced it with the following command: ``` MyPassword ``` Save and close the file, then restart the ClickHouse service to apply the changes: ``` systemctl restart clickhouse-server ``` ## Step 4 – Working with ClickHouse In this section, we will show you how to interact with the ClickHouse database. First, connect ClickHouse using the following command: ``` clickhouse-client --password ``` You will be asked to provide a password for the default user as shown below: ``` ClickHouse client version 21.4.6.55 (official build). Password for user (default): ``` Provide your password and hit **ENTER**. Once you are connected, you will be redirected to the ClickHouse shell: ``` Connecting to localhost:9000 as user default. Connected to ClickHouse server version 21.4.6 revision 54447. ubuntu2004 :) ``` To create a database named mydb, run the following command: ``` ubuntu2004 :) CREATE DATABASE mydb; ``` Output: ``` CREATE DATABASE mydb Query id: 9f82c771-a072-495e-b2a7-cc9618d9b73f Ok. 0 rows in set. Elapsed: 0.008 sec. ``` Change the database to mydb, run the following command: ``` ubuntu2004 :) USE mydb; ``` Output: ``` USE mydb Query id: d94a4fb5-f3fd-41a9-a27f-0bb9efa9e020 Ok. 0 rows in set. Elapsed: 0.002 sec. ``` To create a table named data, run the following command: ``` ubuntu2004 :) CREATE TABLE data (  id UInt64,  name String,  url String,  created DateTime ) ENGINE = MergeTree() PRIMARY KEY id ORDER BY id; ``` Output: ``` CREATE TABLE data ( `id` UInt64, `name` String, `url` String, `created` DateTime ) ENGINE = MergeTree PRIMARY KEY id ORDER BY id Query id: 6039b4d9-c296-4115-b4bb-06a1bbe5499f Ok. 0 rows in set. Elapsed: 0.011 sec. ``` Insert some data into the table with the following command: ``` ubuntu2004 :) INSERT INTO data VALUES (1, 'hitesh', 'http://example.com', '2021-05-01 00:01:01'); ``` Output: ``` INSERT INTO data VALUES Query id: f7dfd959-688a-4481-8fb8-85e49c669b9e Ok. 1 rows in set. Elapsed: 0.022 sec. ``` To add a new column, run the following command: ``` ubuntu2004 :) ALTER TABLE data ADD COLUMN location String; ``` Output: ``` ALTER TABLE data ADD COLUMN `location` String Query id: 7d40bfee-0d0c-4113-bcd9-fd89ac42b82b Ok. 0 rows in set. Elapsed: 0.038 sec. ``` To retrieve the data from the table, run the following command: ``` ubuntu2004 :) SELECT url, name FROM data WHERE url = 'http://example.com' LIMIT 1; ``` Output: ``` SELECT url, name FROM data WHERE url = 'http://example.com' LIMIT 1 Query id: 60dd1e11-f2d9-4b33-8403-6e1859fa266a ┌─url────────────────┬─name───┐ │ http://example.com │ hitesh │ └────────────────────┴────────┘ 1 rows in set. Elapsed: 0.007 sec. ``` To delete a column from the data table, run the following command: ``` ubuntu2004 :) ALTER TABLE data DROP COLUMN location; ``` Output: ``` ALTER TABLE data DROP COLUMN location Query id: 6feffa20-7d33-490f-b8b5-a2d3c1ad93a1 Ok. 0 rows in set. Elapsed: 0.017 sec. ``` To delete a data table, run the following command: ``` ubuntu2004 :) DROP TABLE data; ``` Output: ``` DROP TABLE data Query id: bbac3bd1-8f1d-40b9-8f35-e5816de45855 Ok. 0 rows in set. Elapsed: 0.008 sec. ``` To delete a mydb database, run the following command: ``` ubuntu2004 :) DROP DATABASE mydb; ``` Output: ``` DROP DATABASE mydb Query id: 6fa79629-e2a9-4dcc-ba11-4a6684a085c3 Ok. 0 rows in set. Elapsed: 0.002 sec. ``` Next, exit from the ClickHouse shell with the following command: ``` ubuntu2004 :) exit; ``` ## Step 5 – Enable ClickHouse Web UI By default, ClickHouse web UI is disabled. You will need to enable it by editing the file config.xml: ``` nano /etc/clickhouse-server/config.xml ``` Uncomment and change the **listen_host** line and **http_server_default_response** as shown below: ``` 0.0.0.0
]]>
``` Save and close the file, then restart the ClickHouse server to apply the changes: ``` systemctl restart clickhouse-server ``` Now, open your web browser and type the URL **http://your-server-ip:8123**. You should see the ClickHouse login page: ![ClickHouse Login Page](https://www.atlantic.net/wp-content/uploads/2021/05/p2-1024x529.png) Provide your default username and password then click on the **Sign In** button. You should see the ClickHouse dashboard on the following page: ![ClickHouse Dashboard Page](https://www.atlantic.net/wp-content/uploads/2021/05/p3-1024x523.png) ## Conclusion Congratulations! You have successfully installed and configured ClickHouse on Ubuntu 20.04. I hope you have now enough knowledge of how to interact with a ClickHouse database on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account. For more information, you can visit the ClickHouse documentation page. https://clickhouse.yandex/docs/en/ --- # How to Install OpenMAINT on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-install-openmaint-on-ubuntu/ | Published: 2021-04-28 | Updated: 2024-06-01 | Author: Hitesh Jethva OpenMAINT is an open-source CMMS (Computerized Maintenance Management System) application for managing movable assets, including plants, technical devices, furniture, etc. It is designed to manage and streamline maintenance processes at all scales and across all industries. It is implemented on the open-source asset management framework CMDBuild. OpenMAINT has powerful tools, including dashboards, inventory control, reports, and tracking and history records. You can also customize it according to the needs of the organization. In this post, we will learn how to install OpenMAINT on Ubuntu 20.04. ## Step 1 – Update System and Install Java It is recommended to use a server with at least 8GB of RAM OpenMAINT is built on Java, so Java must be installed on your server. If not installed, you can install it with the following commands: ``` apt-get update -y ``` ``` apt-get install default-jdk -y ``` Once the Java is installed, you can verify the Java version with the following command: ``` java --version ``` You should get the Java version in the following output: ``` openjdk 11.0.7 2020-04-14 OpenJDK Runtime Environment (build 11.0.7+10-post-Ubuntu-3ubuntu1) OpenJDK 64-Bit Server VM (build 11.0.7+10-post-Ubuntu-3ubuntu1, mixed mode, sharing) ``` Next, you will need to install some required dependencies on your server. You can install all of them with the following command: ``` apt-get install gnupg2 wget unzip git curl -y ``` Once all the dependencies are installed, you can proceed to the next step. ## Step 2 – Install PostgreSQL OpenMAINT uses PostgreSQL as a database backend, so you must install PostgreSQL version 10 on your server. First, add the GPG key with the following command: ``` wget --quiet -O - https://www.postgresql.org/media/keys/ACCC4CF8.asc | apt-key add - ``` Next, add the PostgreSQL repository to APT with the following command: ``` echo "deb [arch=amd64] http://apt.postgresql.org/pub/repos/apt/ focal-pgdg main" | tee /etc/apt/sources.list.d/pgdg.list ``` Next, update the repository and install PostgreSQL with the following command: ``` apt-get update -y apt-get install postgresql-10 postgresql-contrib -y ``` Next, install other PostgreSQL packages with the following command: ``` apt-get install postgis postgresql-10-postgis-3 libpostgis-java -y ``` Once all the packages are installed, set the Postgres user password: ``` passwd postgres ``` Set the Postgres password as shown below: ``` New password: Retype new password: passwd: password updated successfully ``` Next, connect to Postgres and set a password for the Postgres database user. ``` su - postgres psql -d template1 -c "ALTER USER postgres WITH PASSWORD 'admin';" ``` Next, exit from the Postgres user with the following command: ``` exit ``` ## Step 3 – Install OpenMAINT First, create a new user for OpenMAINT with the following command: ``` adduser tomcat ``` Next, switch the user to Tomcat with the following command: ``` su - tomcat ``` Next, download the latest version of OpenMAIN with the following command: ``` wget https://downloads.sourceforge.net/project/openmaint/2.1/Core%20updates/openmaint-2.1-3.3.1/openmaint-2.1-3.3.1.war ``` Once the download is completed, start the OpenMAINT installation with the following command: ``` java -jar ./openmaint-2.1-3.3.1.war install ``` Now, follow and type the installation options as shown below: ``` loading jars .................................................................................................................. done CMDBuild interactive install wizard - welcome! this wizard will guide you in the process of installing and configuring a new instance of CMDBuild! tomcat install location : tomcat http port <8080>: tomcat shutdown port (offset already applied) <8005>: tomcat debug port (offset already applied) <8000>: postrgres db : ``` Next, type the PostgreSQL username and the password we have set earlier: ``` postrgres admin account : postgres/admin ``` Next, select the default option and hit **ENTER** to continue. Once the installation has been completed, you should see the following output: ``` WARNING: server version 10.0.16 is not supported, you may encounter problems cmdbuild posrgres database name : database dump to load : we're ready to begin, this is your configuration: tomcat: /home/tomcat/cmdbuild_30 http port: 8080 shutdown port: 8005 debug port: 8000 postgres database: localhost:5432/cmdbuild_18d9 database dump: demo.dump.xz if everything is ok, press ENTER to begin installation BEGIN installation install tomcat... OK create database... create database cmdbuild_18d9 demo.dump.xz cmdbuild successfully installed! you can find startup/shutdown scripts in dir /home/tomcat/cmdbuild_30/bin ``` ## Step 4 – Start OpenMAINT At this point, OpenMAINT is installed in **/home/tomcat/cmdbuild_30** directory. Next, change the directory to **cmdbuild_30** and start the server with the following command: ``` cd cmdbuild_30/bin/ ./startup.sh ``` You should see the following output: ``` Using CATALINA_BASE: /home/tomcat/cmdbuild_30 Using CATALINA_HOME: /home/tomcat/cmdbuild_30 Using CATALINA_TMPDIR: /home/tomcat/cmdbuild_30/temp Using JRE_HOME: /usr Using CLASSPATH: /home/tomcat/cmdbuild_30/bin/bootstrap.jar:/home/tomcat/cmdbuild_30/bin/tomcat-juli.jar Using CATALINA_PID: /home/tomcat/cmdbuild_30/bin/catalina.pid Tomcat started. ``` ## Step 5 – Access OpenMAINT Dashboard At this point, OpenMAINT is started and listening on port 8080. You can access it using the URL **http://your-server-ip:8080/cmdbuild**. You will be redirected to the OpenMAINT login page: ![OpenMAINT login page](https://www.atlantic.net/wp-content/uploads/2021/05/p1-1-1024x429.png) Provide username and password as admin/admin, then click the **Login** button. You will be redirected to the OpenMAINT dashboard as shown below: ![OpenMAINT Dashboard page](https://www.atlantic.net/wp-content/uploads/2021/05/p2-2-1024x526.png) ## Conclusion Congratulations! You have successfully installed and configured OpenMAINT on the Ubuntu 20.04 server. You can now use OpenMAINT to manage the inventory, maintenance, logistics, and economic information related to buildings, plants, and movable assets. Try it today on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net! --- # Babuk Ransomware Gang Threatens to Release Highly Sensitive DC Metropolitan Police Department Files > URL: https://www.atlantic.net/vps-hosting/babuk-ransomware-gang-threatens-to-release-highly-sensitive-dc-metropolitan-police-department-files/ | Published: 2021-04-29 | Updated: 2025-09-19 | Author: Richard Bailey *Atlantic.Net is providing this security advisory as a news item. We want to reassure our customers that Atlantic.Net does not use any of these products affected by this exploit internally or in any of our service offerings.* Concerning reports are circulating about an audacious cybercriminal ransomware attack exploiting the Washington DC police department’s internal servers. [Screenshots](https://therecord.media/ransomware-gang-threatens-to-expose-police-informants-if-ransom-is-not-paid/) of the department’s internal [file servers](https://twitter.com/vxunderground/status/1387395693615190017/photo/1) were uploaded to the Babuk Locker ransomware site and published to the darknet on the 26th of April 2021.  The Metropolitan Police Department (MPD) governs the city of Washington DC. They are a high-profile police force policing multiple government locations. They were recently called in to protect against the January 6th, 2021 storming of the United States Capitol Building. US broadcasters have speculated that the MPD was targeted for these reasons. ## What do we know about the data breach? The hackers gained unauthorized access to MPD computers and downloaded over 250GB of highly sensitive and unencrypted files. This was part of an advanced cyberattack where police servers were infiltrated on or around the[19th of April 2021](https://www.bleepingcomputer.com/news/security/dc-police-confirms-cyberattack-after-ransomware-gang-leaks-data/). The ransomware gang states on their website that the data downloaded includes information about police informants, DC street gangs, and sensitive information on serving police officers. An MPD confirmed the breach on the 27th of April, spokesperson [Sean Hickman](https://therecord.media/ransomware-gang-threatens-to-expose-police-informants-if-ransom-is-not-paid/) said,  “We are aware of unauthorized access on our server.” It has been subsequently reported that the MPD is [working with the FBI](https://www.nbcnews.com/news/us-news/washington-d-c-police-report-server-breach-fbi-called-investigate-n1265439) to counter this ongoing serious threat. The attack is believed to be financially motivated. In previous Babuk cyberattacks published ransoms on their website, but it is unknown what the ransom has been set at for the MPD. Babuk has given the MPD 3 days to respond to the ransom or they will start releasing sensitive information. The Babuk ransomware and the group themselves are relative newcomers to the scene, first coming to our attention in January 2021. They are known to have been involved in at least [5 big enterprise data breaches](https://www.mcafee.com/blogs/other-blogs/mcafee-labs/babuk-ransomware/), including the British company [Serco Group PLC](https://www.cyberscoop.com/babuk-ransomware-serco-attack/), a UK government services company. McAfee has completed a[deep-dive technical analysis](https://www.mcafee.com/enterprise/en-us/assets/reports/rp-babuk-ransomware.pdf) of the Babuk ransomware. To summarize, the malware deletes the shadow copies of a server, similar to local system backups. Files are encrypted with a key using the extremely strong ChaCha algorithm, making the key impossible to crack. ## What are the likely causes of the breach? We are still learning exactly how the MPD was targeted, as details are thin on the ground. When we take into consideration the previous Babuk ransomware attacks, it’s highly likely to be one of the following: - **Email Spear Phishing** – a phishing campaign is usually the number one cause of data breaches. The hackers engage with front-line personnel to gain their trust or trick them to download a malware attachment from an email. Once downloaded, a malware payload executes using various layers of sophistication to compromise the victim’s network. - **Exploitable Public-Facing Application** – this could be any application, website, or URL that is exposed to the public internet. Every application can potentially be exploited; this is why patching and security updates are so important. - **Remote Desktop Attack** – another proven attack vector is brute force RDP attacks on vulnerable endpoints. If a company has externally facing remote desktop connections, all that stands between the hacker and the server is a username and password. If the RDP connection is secured with weak credentials, these can be guessed relatively quickly by hacking tools. - **Data Mining/Keylogging/Infostealer** – another possibility, and although less likely, credentials may have been found in MPD online code repository, or a terminal may have been compromised to steal credentials to police computers. ## What happens next? So far the MPD has remained silent, only confirming the breach but making no comment on the content allegedly stolen from MPD servers. Currently, it seems we are awaiting the expiration of the 3-day deadline given to the MPD. It is unlikely the MPD will pay the ransom, and FBI advice is usually not to pay the ransom, but given the potentially extreme sensitivity of the compromised data, most notably a possible list of police informants, Atlantic.Net will be keeping an eye on how the situation plays out. If your business is concerned about [cybersecurity](https://www.atlantic.net/pci-compliant-hosting/pci-security-services/) please feel welcome to reach out to Atlantic.Net. We are specialists in Managed Services, [Dedicated Cloud Hosting](https://www.atlantic.net/dedicated-server-hosting/), and [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). Security of our infrastructure is of paramount importance, and we work hard to ensure we have the best security processes in place. --- # How to Install Tig Git Repository Browser on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-tig-git-repository-browser-on-ubuntu-20-04/ | Published: 2021-04-30 | Updated: 2026-03-03 | Author: Hitesh Jethva Tig is a Ncurses-based and command-line Git repository browser. It supports various operating systems including Linux, macOS, and Windows. Tig provides an easier way to interact with Git and staging Git commits. It provides a rich set of features. Some of them are listed below: - Displays the list of stashes - Displays the changes for a single file - Allows to browse the commits in the current branch - Compares two branches - Displays the commits for one or more specific branches In this post, we will show you how to install and use the Tig git repository browser on Ubuntu 20.04. ## Step 1 – Install Tig By default, Tig is included in the Ubuntu 20.04 default repository. You can install it using the following command: ``` apt-get install tig -y ``` Once the Tig is installed, verify the installed version of Tig with the following command: ``` tig --version ``` You should get the following output: ``` tig version 2.4.1 ncursesw version 6.2.20200212 readline version 8.0 ``` You can see all options available with Tig using the following command: ``` tig --help ``` You should see the following output: ``` tig 2.4.1 Usage: tig [options] [revs] [--] [paths] or: tig log [options] [revs] [--] [paths] or: tig show [options] [revs] [--] [paths] or: tig blame [options] [rev] [--] path or: tig grep [options] [pattern] or: tig refs or: tig stash or: tig status or: tig < [git command output] Options: + Select line in the first view -v, --version Show version and exit -h, --help Show help message and exit ``` ## Step 2 – How to Use Tig In order to work with Tig, you will need to clone any Git repository to your local system. You can clone it using the following command: ``` git clone https://github.com/hitjethva/linuxbuz ``` Output: ``` Cloning into 'linuxbuz'... remote: Enumerating objects: 3, done. remote: Counting objects: 100% (3/3), done. remote: Compressing objects: 100% (2/2), done. remote: Total 3 (delta 0), reused 0 (delta 0), pack-reused 0 Unpacking objects: 100% (3/3), done. Checking connectivity... done. ``` Once the repository is cloned, change the cloned repository using the following command: ``` cd linuxbuz ``` Next, run the Tig command without any argument and it will display the list of commits on the current branch: ``` tig ``` You should see the detailed information of your commits on the following screen: ![Detail Information of Commits](https://www.atlantic.net/wp-content/uploads/2021/05/p1-1024x558.png) To display all the references of your repository, run the following command: ``` tig refs ``` You should see the following screen: ![References of repository](https://www.atlantic.net/wp-content/uploads/2021/05/p2-1-1024x562.png) To display log activities of the above repository, run the following command: ``` tig log ``` You should see the following screen: ![Log activity of repository](https://www.atlantic.net/wp-content/uploads/2021/05/p3-1-1024x566.png) To display one or more objects such as commits and many more, run the following command: ``` tig show commits ``` You should see the following screen: ![Display one or more objects](https://www.atlantic.net/wp-content/uploads/2021/05/p4-1024x429.png) If you want to search for a particular pattern from your repository, run the following command: ``` tig grep linux ``` You should see the following screen: ![Search specific pattern from the repository](https://www.atlantic.net/wp-content/uploads/2021/05/p5-1024x565.png) To display the status of your git repository, run the following command: ``` tig status ``` You should see the following screen: ![To display the status of the repository](https://www.atlantic.net/wp-content/uploads/2021/05/p6-1024x336.png) To put Tig in Pager mode, run the following command: ``` git status | tig ``` You should see the following screen: ![Put Tig in pager mode](https://www.atlantic.net/wp-content/uploads/2021/05/p7-1024x568.png) To find out who made a change to a file, run the following command: ``` tig blame readme.md ``` You should see the following screen: ![Display who made a changes in the file](https://www.atlantic.net/wp-content/uploads/2021/05/p8-1024x567.png) ## Step 3 – Update Tig If you want to update the Tig to the latest version, run the following command: ``` apt-get update -y apt-get --only-upgrade install tig ``` ## Conclusion In the above guide, you learned how to install and use Tig git repository browser on Ubuntu 20.04. You can now easily check and manage your Git repository from the command-line interface – try it today on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account! --- # How to Install and Use Mosh Command Line Tool Linux > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-mosh-command-line-tool-linux/ | Published: 2021-05-01 | Updated: 2023-11-17 | Author: Hitesh Jethva Mosh, also known as “Mobile Shell,” is a command-line tool used for connecting remote Linux servers. Mosh is optimized for mobile working. It allows roaming, supports intermittent connectivity, and provides intelligent local echo and line editing of user keystrokes. Mosh is an alternative to SSH and provides more features than Secure Shell. It is available for all major operating systems including Linux, FreeBSD, Solaris, Mac OS X, and Android. In this post, we will show you how to install and use Mosh command-line tool on Linux. ## Install Mosh For Debian based Linux distributions, you can install the Mosh using the following command: ``` apt-get install mosh ``` For CentOS-based Linux distributions, you can install the Mosh using the following command: ``` yum install mosh ``` Once the Mosh is installed, you can verify the installed version of Mosh with the following command: ``` mosh --version ``` You should get the following output: ``` mosh 1.3.2 [build mosh 1.3.2] Copyright 2012 Keith Winstein License GPLv3+: GNU GPL version 3 or later . This is free software: you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law. ``` You can also see all options available with Mosh using the following command: ``` mosh --help ``` You should get the following output: ``` Usage: /usr/bin/mosh [options] [--] [user@]host [command...] --client=PATH mosh client on local machine (default: "mosh-client") --server=COMMAND mosh server on remote machine (default: "mosh-server") --predict=adaptive local echo for slower links [default] -a --predict=always use local echo even on fast links -n --predict=never never use local echo --predict=experimental aggressively echo even when incorrect -4 --family=inet use IPv4 only -6 --family=inet6 use IPv6 only --family=auto autodetect network type for single-family hosts only --family=all try all network types --family=prefer-inet use all network types, but try IPv4 first [default] --family=prefer-inet6 use all network types, but try IPv6 first -p PORT[:PORT2] --port=PORT[:PORT2] server-side UDP port or range (No effect on server-side SSH port) --bind-server={ssh|any|IP} ask the server to reply from an IP address (default: "ssh") --ssh=COMMAND ssh command to run when setting up session (example: "ssh -p 2222") (default: "ssh") --no-ssh-pty do not allocate a pseudo tty on ssh connection --no-init do not send terminal initialization string --local run mosh-server locally without using ssh --experimental-remote-ip=(local|remote|proxy) select the method for discovering the remote IP address to use for mosh (default: "proxy") --help this message --version version and copyright information ``` ## Working with Mosh Mosh uses the same SSH method to connect to the remote server. Run the following command to connect to the remote server: ``` mosh root@your-server-ip ``` You will be asked to provide your root password to connect to the remote server. If your remote SSH server is listening on port 2200, then you can specify it using the following command: ``` mosh --ssh="ssh -p 2200" root@your-server-ip ``` One of the best features of Mosh is that it will send you a notification if your network connection is lost. Once the network connection is restored, it will be synced to the server and you will be connected to the remote server automatically, so you don’t have to close the Mosh window. ## Conclusion In the above post, you learned how to install and use Mosh command-line tool on your [Linux VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. It is a great tool compared to SSH. Generally, Mosh is used in slow network connections. You can visit [Mosh documentation](https://mosh.org/) page for more information. --- # How to Control System Resource Usage with ulimit in Linux > URL: https://www.atlantic.net/vps-hosting/how-to-control-system-resource-usage-with-ulimit-in-linux/ | Published: 2021-05-02 | Updated: 2024-06-04 | Author: Hitesh Jethva Ulimit is a command-line utility in a Linux-based operating system used to allocate and limit resources. You can use it to control resources at the global, group, and user levels. Setting the right limits will make your system works optimally. You can use ulimit to set restrictions on the resources used by a process so that only important processes on your servers can keep running. In this post, we will show you how to control system resource usage with ulimit in Linux. ## Basic Syntax The basic syntax of the ulimit command is shown below: ``` ulimit [option] ``` A brief explanation of each option is shown below: - -a: Display the limits for all the users. - -d: Define the size of the data area. - -c: Define the size of the core dump. - -e: Used to define the priority. - -s: Define the maximum stack size. - -u: Define the maximum number of user processes. By default, all resource limit is saved in the file /etc/security/limits.conf. ## How to Use ulimit To display the resource limit of all user, run the following command: ``` ulimit -a ``` Output: ``` core file size (blocks, -c) 0 data seg size (kbytes, -d) unlimited scheduling priority (-e) 0 file size (blocks, -f) unlimited pending signals (-i) 15237 max locked memory (kbytes, -l) 64 max memory size (kbytes, -m) unlimited open files (-n) 1024 pipe size (512 bytes, -p) 8 POSIX message queues (bytes, -q) 819200 real-time priority (-r) 0 stack size (kbytes, -s) 8192 cpu time (seconds, -t) unlimited max user processes (-u) 15237 virtual memory (kbytes, -v) unlimited file locks (-x) unlimited ``` To display the resource limit for a specific user, run the following command: ``` ulimit -a root ``` Output: ``` core file size (blocks, -c) 0 data seg size (kbytes, -d) unlimited scheduling priority (-e) 0 file size (blocks, -f) unlimited pending signals (-i) 15237 max locked memory (kbytes, -l) 64 max memory size (kbytes, -m) unlimited open files (-n) 1024 pipe size (512 bytes, -p) 8 POSIX message queues (bytes, -q) 819200 real-time priority (-r) 0 stack size (kbytes, -s) 8192 cpu time (seconds, -t) unlimited max user processes (-u) 15237 virtual memory (kbytes, -v) unlimited file locks (-x) unlimited ``` To display the soft limit of a current user, run the following command: ``` ulimit -S ``` To display the hard limit of a current user, run the following command: ``` ulimit -H ``` To check the hard limit allocate on the maximum number of user processes, run the following command: ``` ulimit -Hu ``` Output: ``` 15237 ``` To change the default hard limit temporarily, run the following command: ``` ulimit -u 20000 ``` To change the hard limit permanently, edit the /etc/security/limits.conf file: ``` nano /etc/security/limits.conf ``` Add the following line: ``` root hard nproc 20000 ``` Save and close the file when you are finished. To check the open files limit, run the following command: ``` ulimit -n ``` To change the open files limit, run the following command: ``` ulimit -n 1000 ``` To check the max memory size limit, run the following command: ``` ulimit -m ``` To change the max memory size limit, run the following command: ``` ulimit -m 2000 ``` ## Conclusion In the above guide, you learned how to limit system resources with the ulimit command. ulimit will help you to make your system run with optimal performance. Try it today on your Atlantic.Net [VPS hosting](https://www.atlantic.net/vps-hosting/) account! --- # How to Install Discourse Forum on Debian with Nginx and Let’s Encrypt > URL: https://www.atlantic.net/vps-hosting/how-to-install-discourse-forum-on-debian-with-nginx-and-lets-encrypt/ | Published: 2021-05-02 | Updated: 2025-09-04 | Author: Hitesh Jethva Discourse is open-source forum software written in Ember.js and Ruby on Rails. You can build your own online discussion forums and chat rooms using Discourse. Discourse is mostly used by gamers to create content accessible by the community. It is used by many companies including New Relic, Cloudflare, and Docker to power their communities. Discourse offers a rich set of features including dynamic notifications, infinite scrolling, powerful moderation, spam blocking, two-factor authentication, a comprehensive API, and many more. In this post, we will explain how to install Discourse Forum with Docker on Debian 12. ## Step 1 – Install Docker By default, the latest version of Docker is not available in the Debian default repository, so you will need to add the Docker official repository to your system. First, install the required dependencies using the following command: ``` apt-get update -y apt-get install git apt-transport-https ca-certificates curl gnupg2 software-properties-common -y ``` Once all the dependencies are installed, add the Docker CE repository with the following command: ``` curl -fsSL https://download.docker.com/linux/$(. /etc/os-release; echo "$ID")/gpg | apt-key add - add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/$(. /etc/os-release; echo "$ID") $(lsb_release -cs) stable" ``` Once the repository is added, update the repository and install Docker CE with the following command: ``` apt-get update -y apt-get install docker-ce -y ``` Once Docker CE is installed, you can proceed to install Discourse. ## Step 2 – Install Discourse First, create a directory for Discourse and download the latest version of Discourse with the following command: ``` mkdir /var/discourse git clone https://github.com/discourse/discourse_docker.git /var/discourse ``` Next, change the directory to discourse and start the Discourse installation using the following command: ``` cd /var/discourse ./discourse-setup ``` During the installation, you will be asked to provide the Hostname, email, and SMTP details as shown below: ``` Hostname for your Discourse? [discourse.example.com]: discourse.linuxbuz.com Checking your domain name . . . Connection to discourse.linuxbuz.com succeeded. Email address for admin account(s)? [me@example.com,you@example.com]: hitjethva1982@gmail.com SMTP server address? [smtp.example.com]: smtp.gmail.com SMTP port? [587]: SMTP user name? [user@example.com]: hitjethva1982@gmail.com SMTP password? [pa$$word]: your-password notification email address? [noreply@discourse.linuxbuz.com]: hitjethva1982@gmail.com Optional email address for Let's Encrypt warnings? (ENTER to skip) [me@example.com]: hitjethva1982@gmail.com Optional Maxmind License key (ENTER to continue without MAXMIND GeoLite2 geolocation database) [1234567890123456]: ``` Provide all the details and hit Enter. You should see the following output: ``` Does this look right? Hostname : discourse.linuxbuz.com Email : hitjethva1982@gmail.com SMTP address : smtp.gmail.com SMTP port : 587 SMTP username : hitjethva1982@gmail.com SMTP password : your-password Notification email: hitjethva1982@gmail.com Let's Encrypt : hitjethva1982@gmail.com Maxmind license: (unset) ENTER to continue, 'n' to try again, Ctrl+C to exit: ``` Confirm all the information and hit Enter to start the installation. Once the installation has been finished, you should get the following output: ``` + /usr/bin/docker run --shm-size=512m -d --restart=always -e LANG=en_US.UTF-8 -e RAILS_ENV=production -e UNICORN_WORKERS=4 -e UNICORN_SIDEKIQS=1 -e RUBY_GLOBAL_METHOD_CACHE_SIZE=131072 -e RUBY_GC_HEAP_GROWTH_MAX_SLOTS=40000 -e RUBY_GC_HEAP_INIT_SLOTS=400000 -e RUBY_GC_HEAP_OLDOBJECT_LIMIT_FACTOR=1.5 -e DISCOURSE_DB_SOCKET=/var/run/postgresql -e DISCOURSE_DB_HOST= -e DISCOURSE_DB_PORT= -e LETSENCRYPT_DIR=/shared/letsencrypt -e LC_ALL=en_US.UTF-8 -e LANGUAGE=en_US.UTF-8 -e DISCOURSE_HOSTNAME=discourse.linuxbuz.com -e DISCOURSE_DEVELOPER_EMAILS=hitjethva1982@gmail.com -e DISCOURSE_SMTP_ADDRESS=smtp.gmail.com -e DISCOURSE_SMTP_PORT=587 -e DISCOURSE_SMTP_USER_NAME=hitjethva1982@gmail.com -e DISCOURSE_SMTP_PASSWORD=Jethva@1981 -e DISCOURSE_SMTP_DOMAIN=gmail.com -e DISCOURSE_NOTIFICATION_EMAIL=hitjethva1982@gmail.com -e LETSENCRYPT_ACCOUNT_EMAIL=hitjethva1982@gmail.com -h debian-app -e DOCKER_HOST_IP=172.17.0.1 --name app -t -p 80:80 -p 443:443 -v /var/discourse/shared/standalone:/shared -v /var/discourse/shared/standalone/log/var-log:/var/log --mac-address 02:95:89:04:2c:d3 local_discourse/app /sbin/boot adc3196fb49b6711135c30f88bf6b3f5132e1310e22060f6d907a16ce4e7d963 ``` ## Step 3 – Access Discourse Now, open your web browser and access the Discourse web interface using the URL **https://discourse.linuxbuz.com**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/04/discourse-registration-1024x590.png) Click on the **Register** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/04/discourse-registration2-1024x593.png) Provide your email address, username, and password, and click on the **Register** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/04/discourse-notification-1024x523.png) You will get an activation email in your mailbox. You can activate your Discourse account by clicking on the activation email. ## Conclusion In the above post, you learned how to install Discourse Forum with Docker on Debian 12. You can implement a Discourse Forum for your organization on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net. --- # How to Use journalctl to Analyze Logs in Linux > URL: https://www.atlantic.net/vps-hosting/how-to-use-journalctl-to-analyze-logs-in-linux/ | Published: 2021-05-03 | Updated: 2023-11-27 | Author: Hitesh Jethva Systemd is the default system manager in all major Linux-based operating systems. It provides a journald daemon that handles all messages produced by the kernel and system services. The journald daemon collects data from all available sources and stores them in a binary format for easy and dynamic manipulation. Systemd provides a command-line tool called journalctl that can be used to read and analyze journal logs. journalctl allows you to analyze and monitor the logs in real-time. In this guide, we will show you how to use journalctl to analyze logs in Linux. ## Configure Journal By default, journal logs are enabled and stores log data at /run/log/journal/. But, since logs are deleted automatically after a system reboot, you will need to configure Journal to store all logs permanently. First, create a directory to store the Journal log: ``` mkdir /var/log/journal ``` Next, set proper ownership with the following command: ``` chown -R root:systemd-journal /var/log/journal ``` Next, edit the journald default configuration file /etc/systemd/journald.conf and define your new directory: ``` nano /etc/systemd/journald.conf ``` Change the following line: ``` Storage=persistent ``` Save and close the file, then restart the systemd-journald service to apply the changes: ``` systemctl restart systemd-journald ``` You can now check the /var/log/journal directory: ``` ls -l /var/log/journal ``` You should see the following output: ``` drwxr-xr-x 2 root systemd-journal 4096 Apr 21 11:35 97bcb1f0d9aa4b339adefc87f1332d04 ``` ## Use journalctl to Analyze Log **To print all logs collected by journald daemon, run the journalctl command:** ``` journalctl ``` Output: ``` -- Logs begin at Wed 2021-04-21 07:00:15 UTC, end at Wed 2021-04-21 11:40:12 UTC. -- Apr 21 07:00:15 ubuntu2004 kernel: Linux version 4.19.0-9-amd64 (debian-kernel@lists.debian.org) (gcc version 8.3.0 (Debian 8.3.0-6)) #1 SMP Debian 4.19.118-2+deb10u1 (2020-06-07) Apr 21 07:00:15 ubuntu2004 kernel: Command line: BOOT_IMAGE=/boot/vmlinuz-4.19.0-9-amd64 root=UUID=d4f8c3a8-164f-4e15-a198-6124ce8719b5 ro Apr 21 07:00:15 ubuntu2004 kernel: x86/fpu: x87 FPU will use FXSAVE Apr 21 07:00:15 ubuntu2004 kernel: BIOS-provided physical RAM map: Apr 21 07:00:15 ubuntu2004 kernel: BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable Apr 21 07:00:15 ubuntu2004 kernel: BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved Apr 21 07:00:15 ubuntu2004 kernel: BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved Apr 21 07:00:15 ubuntu2004 kernel: BIOS-e820: [mem 0x0000000000100000-0x000000007ffdbfff] usable Apr 21 07:00:15 ubuntu2004 kernel: BIOS-e820: [mem 0x000000007ffdc000-0x000000007fffffff] reserved Apr 21 07:00:15 ubuntu2004 kernel: BIOS-e820: [mem 0x00000000feffc000-0x00000000feffffff] reserved Apr 21 07:00:15 ubuntu2004 kernel: BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved Apr 21 07:00:15 ubuntu2004 kernel: NX (Execute Disable) protection: active ``` **If you need more verbose output, run the following command:** ``` journalctl -o verbose ``` Output: ``` -- Logs begin at Wed 2021-04-21 07:00:15 UTC, end at Wed 2021-04-21 11:40:29 UTC. -- Wed 2021-04-21 07:00:15.461318 UTC [s=1baac74dce14445f9a6670f231104955;i=1;b=41c491f449fa44c288474cf9f14386c0;m=1ee776;t=5c0761d6627c6;x=4c88a9 _SOURCE_MONOTONIC_TIMESTAMP=0 _TRANSPORT=kernel PRIORITY=5 SYSLOG_FACILITY=0 SYSLOG_IDENTIFIER=kernel MESSAGE=Linux version 4.19.0-9-amd64 (debian-kernel@lists.debian.org) (gcc version 8.3.0 (Debian 8.3.0-6)) #1 SMP Debian 4.19.118-2+deb10u1 _BOOT_ID=41c491f449fa44c288474cf9f14386c0 _MACHINE_ID=97bcb1f0d9aa4b339adefc87f1332d04 _HOSTNAME=ubuntu2004 Wed 2021-04-21 07:00:15.461357 UTC [s=1baac74dce14445f9a6670f231104955;i=2;b=41c491f449fa44c288474cf9f14386c0;m=1ee79e;t=5c0761d6627ed;x=eaf7df _SOURCE_MONOTONIC_TIMESTAMP=0 _TRANSPORT=kernel SYSLOG_FACILITY=0 SYSLOG_IDENTIFIER=kernel _BOOT_ID=41c491f449fa44c288474cf9f14386c0 _MACHINE_ID=97bcb1f0d9aa4b339adefc87f1332d04 _HOSTNAME=ubuntu2004 PRIORITY=6 MESSAGE=Command line: BOOT_IMAGE=/boot/vmlinuz-4.19.0-9-amd64 root=UUID=d4f8c3a8-164f-4e15-a198-6124ce8719b5 ro ``` **To list all available boot logs, run the following command:** ``` journalctl --list-boots ``` Output: ``` 0 41c491f449fa44c288474cf9f14386c0 Wed 2021-04-21 07:00:15 UTC—Wed 2021-04-21 11:41:44 UTC ``` **To display all logs since the most recent reboot, run the following command:** ``` journalctl -b ``` **To display the most recent log entries, run the following command:** ``` journalctl --lines 5 ``` Output: ``` -- Logs begin at Wed 2021-04-21 07:00:15 UTC, end at Wed 2021-04-21 11:45:13 UTC. -- Apr 21 11:45:06 ubuntu2004 sshd[12088]: Failed password for invalid user telecomadmin from 103.42.205.111 port 64471 ssh2 Apr 21 11:45:08 ubuntu2004 sshd[12088]: Connection closed by invalid user telecomadmin 103.42.205.111 port 64471 [preauth] Apr 21 11:45:13 ubuntu2004 sshd[12092]: Invalid user admin from 81.70.161.162 port 60614 Apr 21 11:45:13 ubuntu2004 sshd[12092]: pam_unix(sshd:auth): check pass; user unknown Apr 21 11:45:13 ubuntu2004 sshd[12092]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=81.70.161.162 ``` **To print the log continuously, run the following command:** ``` journalctl --follow ``` Output: ``` -- Logs begin at Wed 2021-04-21 07:00:15 UTC. -- Apr 21 11:45:36 ubuntu2004 sshd[12106]: Disconnected from invalid user babi 104.131.102.169 port 54872 [preauth] Apr 21 11:45:40 ubuntu2004 sshd[12108]: Invalid user telecomadmin from 103.108.241.111 port 60842 Apr 21 11:45:40 ubuntu2004 sshd[12108]: pam_unix(sshd:auth): check pass; user unknown Apr 21 11:45:40 ubuntu2004 sshd[12108]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.108.241.111 Apr 21 11:45:41 ubuntu2004 sshd[12110]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=101.32.11.137 user=root Apr 21 11:45:42 ubuntu2004 sshd[12108]: Failed password for invalid user telecomadmin from 103.108.241.111 port 60842 ssh2 Apr 21 11:45:43 ubuntu2004 sshd[12108]: Connection closed by invalid user telecomadmin 103.108.241.111 port 60842 [preauth] Apr 21 11:45:43 ubuntu2004 sshd[12110]: Failed password for root from 101.32.11.137 port 43086 ssh2 Apr 21 11:45:45 ubuntu2004 sshd[12110]: Received disconnect from 101.32.11.137 port 43086:11: Bye Bye [preauth] Apr 21 11:45:45 ubuntu2004 sshd[12110]: Disconnected from authenticating user root 101.32.11.137 port 43086 [preauth] ``` **To display specific service-related logs like SSH and Nginx, run the following command:** ``` journalctl -u ssh.service journalctl -u nginx.service ``` **To display only kernel-related logs, run the following command;** ``` journalctl -k ``` **To display logs which contain error or critical, run the following command:** ``` journalctl -p err -b ``` Output: ``` -- Logs begin at Wed 2021-04-21 07:00:15 UTC, end at Wed 2021-04-21 11:49:21 UTC. -- Apr 21 07:00:16 ubuntu2004 ntpd[337]: leapsecond file ('/usr/share/zoneinfo/leap-seconds.list'): expired less than 115 days ago Apr 21 07:00:16 ubuntu2004 ntpd[337]: bind(21) AF_INET6 fe80::200:2dff:fe3a:264e%2#123 flags 0x11 failed: Cannot assign requested address Apr 21 07:00:16 ubuntu2004 ntpd[337]: unable to create socket on ens3 (5) for fe80::200:2dff:fe3a:264e%2#123 ``` **To display all logs from yesterday, run the following command:** ``` journalctl --since yesterday ``` **To display all logs starting from 6:00 AM and continuing until an hour ago, run the following command:** ``` journalctl --since 06:00 --until "1 hour ago" ``` **To display the amount of space used by the journal, run the following command:** ``` journalctl --disk-usage ``` Output: ``` Archived and active journals take up 16.0M in the file system. ``` **If you want to keep all logs’ data only from the last year, run the following command:** ``` journalctl --vacuum-time=1years ``` **To display only the last few logs, run the following command:** ``` journalctl -xe ``` ## Conclusion In the above guide, you learned how to use journalctl to read and analyze different system logs. You can now identify or troubleshoot system or application-related issues on your [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Install AWStats on CentOS 7 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-awstats-on-centos-7/ | Published: 2021-05-04 | Updated: 2024-06-10 | Author: Hitesh Jethva AWStats, also known as “Advanced Web Statistics,” is an open-source web analytics software written in Perl. It uses log files to analyze log files from Apache, Nginx, IIS, and other web servers. AWStats is a very useful tool that helps you to monitor your website traffic, the number of visits, unique visitors, visit duration, and other data. It also displays information about visitors OS, IP, Browser, Search engine, Screen size, and keywords used to find your website.7 In this post, we will show you how to install AWStats on CentOS 7. ## Step 1 – Install and Configure Apache For this article, you will need to install the Apache webserver and create a virtual host configuration file for domain test.example.com. First, install the Apache package with the following command: ``` yum install httpd -y ``` Once the installation is completed, start the Apache service and enable it to start at system reboot with the following command: ``` systemctl start httpd systemctl enable httpd ``` Next, create a new virtual host configuration file with the following command: ``` nano /etc/httpd/conf.d/test.conf ``` Add the following content: ``` ServerName test.example.com ServerAdmin webmaster@example.com DocumentRoot /usr/share/httpd/noindex DirectoryIndex index.html ErrorLog /var/log/httpd/test_error.log CustomLog /var/log/httpd/test_access.log combined ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 2 – Install AWStats By default, AWStats is not available in the CentOS 7 default repo, so you will need to add EPEL repo to your system. You can add it with the following command: ``` yum install epel-release -y ``` Next, install the AWStats with the following command: ``` yum install awstats -y ``` Once the installation is completed, you can proceed to the next step. ## Step 3 – Configure AWStats By default, AWStats all configuration files are located inside /etc/awstats/ directory. Here, you will need to create a separate configuration file for your domain test.example.com. To do so, create a copy of the main configuration file to the file that matches your domain name: ``` cp /etc/awstats/awstats.centos7.conf /etc/awstats/awstats.test.example.com.conf ``` Next, edit the configuration file: ``` nano /etc/awstats/awstats.test.example.com.conf ``` Change the following lines: ``` LogFile="/var/log/httpd/test_access.log" LogType=W LogFormat=1 SiteDomain="test.example.com" HostAliases="REGEX[test.example.com]" ``` Save and close the file when you are finished. ## Step 4 – Generate Web Statistics from Apache Logs Next, you will need to generate your initial statistics from the current Apache logs. You can generate it with the following command: ``` /usr/share/awstats/wwwroot/cgi-bin/awstats.pl -config=awstats.test.example.com.conf ``` You should get the following output: ``` Create/Update database for config "/etc/awstats/awstats.test.example.com.conf" by AWStats version 7.8 (build 20200416) From data in log file "/var/log/httpd/test_access.log"... Phase 1 : First bypass old records, searching new record... Searching new records from beginning of log file... Phase 2 : Now process new records (Flush history on disk after 20000 hosts)... Jumped lines in file: 0 Parsed lines in file: 13 Found 0 dropped records, Found 0 comments, Found 0 blank records, Found 0 corrupted records, Found 0 old records, Found 13 new qualified records. ``` ## Step 5 – Configure Apache to Access AWStats By default, the Apache webserver is configured to access AWStats only from the localhost, so you will need to edit awstats.conf file to grant access to your IP address. ``` nano /etc/httpd/conf.d/awstats.conf ``` Find the following line: ``` Require local ``` Replace it with the following line: ``` Require ip your-system-ip ``` Save and close the file when you are finished. **your-system-ip** is the IP address of your desktop system from where you want to access AWStats. You can find the IP address of your desktop system using [whatismyipaddress](https://whatismyipaddress.com/). Next, make sure CGI modules are enabled with the following command: ``` httpd -M | grep cgi ``` You should get the following output: ``` proxy_fcgi_module (shared) proxy_scgi_module (shared) cgi_module (shared) ``` Next, set proper ownership to the AWStats root directory with the following command: ``` chown -R apache: /usr/share/awstats/wwwroot/ ``` Next, restart the Apache service to apply the configuration changes: ``` systemctl restart httpd ``` ## Step 6 – Access AWStats You can now view the Apache log statistics of your website (test.example.com) using the URL **http://your-server-ip/awstats/awstats.pl**. You should see the AWStats dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p1-11-1024x522.png) ## Conclusion In the above post, you learned how to install and configure AWStats to analyze your website log. You can now host AWStats in the production environment to monitor your website – try it on your [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) account from Atlantic.Net. --- # How to Install SysPass Password Manager on CentOS 8 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-syspass-password-manager-on-centos-8/ | Published: 2021-05-05 | Updated: 2023-11-15 | Author: Hitesh Jethva sysPass is a free, open-source, web-based password management system. It is cross-platform and available through a web app, mobile app, and browser extension. sysPass provides a simple and user-friendly web interface to generate and manage all passwords. It is written in PHP, providing password management securely and collaboratively. In this tutorial, we will show you how to install the sysPass password manager on CentOS 8 operating system. ## Step 1 – Install Apache Web Server sysPass runs on a web server. So Apache or Nginx web server must be installed in your system. If not installed, you can install the Apache webserver using the command below: ``` dnf install httpd -y ``` After the successful installation, start the Apache web service and enable it to start at system reboot: ``` systemctl start httpd systemctl enable httpd ``` Now, open your web browser and type the URL **http://your-server-ip** to test the Apache webserver. If everything is fine, you should see the Apache webserver test page as shown below: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p1-14-1024x537.png) ## Step 2 – Install PHP sysPass is written in the PHP language, so you will need to install PHP and other required PHP extensions in your system. sysPass is compatible with PHP version 7.3 to 7.4. Both PHP versions are not available in the CentOS 8 default repository, so you will need to add EPEL and REMI repository to your system. First, add both repositories using the command below: ``` dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-8.noarch.rpm dnf install https://rpms.remirepo.net/enterprise/remi-release-8.rpm ``` Once installed, run the following command to list all available PHP versions: ``` dnf module list php ``` You can see all PHP versions in the following output: ``` CentOS Linux 8 - AppStream 1.7 MB/s | 6.3 MB 00:03 CentOS Linux 8 - BaseOS 8.5 MB/s | 2.3 MB 00:00 Remi's Modular repository for Enterprise Linux 8 - x86_64 455 kB/s | 732 kB 00:01 Safe Remi's RPM repository for Enterprise Linux 8 - x86_64 943 kB/s | 1.6 MB 00:01 CentOS Linux 8 - AppStream Name Stream Profiles Summary php 7.2 [d][e] common [d], devel, minimal PHP scripting language php 7.3 common [d], devel, minimal PHP scripting language php 7.4 common [d], devel, minimal PHP scripting language Remi's Modular repository for Enterprise Linux 8 - x86_64 Name Stream Profiles Summary php remi-7.2 common [d], devel, minimal PHP scripting language php remi-7.3 common [d], devel, minimal PHP scripting language php remi-7.4 common [d], devel, minimal PHP scripting language php remi-8.0 common [d], devel, minimal PHP scripting language ``` Next, run the following command to reset the PHP default repository and enable the PHP REMI repository for version 7.4. ``` dnf module reset php dnf module enable php:7.4 ``` Now, install PHP 7.4 along with all necessary modules using the command below: ``` dnf install php php-mysqli php-pdo php-pear php php-cgi php-cli php-common php-gd php-json php-readline php-curl php-intl php-ldap php-xml php-mbstring git -y ``` Once the installation is completed, edit the php.ini file make some changes: ``` nano /etc/php.ini ``` Change the following values: ``` post_max_size = 100M upload_max_filesize = 100M max_execution_time = 7200 memory_limit = 512M date.timezone = Etc/UTC ``` Save the file when you are finished. ## Step 3 – Install and Configure MariaDB Database sysPass uses a MariaDB/MySQL database to store all passwords, so a MariaDB server must be installed in your system. Run the following command to install the MariaDB server: ``` dnf install mariadb-server -y ``` Once installed, start the MariaDB service and enable it to start at system reboot: ``` systemctl start mariadb systemctl enable mariadb ``` Next, you will need to create a database and user for sysPass. First, connect the MariaDB using the command below: ``` mysql ``` Once connected, create a database and user using the command below: ``` create database syspass; grant all privileges on syspass.* to syspass@localhost identified by "securepassword"; ``` Next, flush the privileges and exit from the MariaDB with the following command: ``` flush privileges; exit; ``` ## Step 4 – Install sysPass Next, download the sysPass code from the Git Hub repository: ``` git clone https://github.com/nuxsmin/sysPass.git ``` Once the download is completed, move the downloaded directory to the Apache web root directory: ``` mv sysPass /var/www/html/syspass ``` Next, set proper permissions and ownership to the sysPass directory: ``` chown -R apache:apache /var/www/html/syspass chmod 750 /var/www/html/syspass/app/{config,backup} ``` Next, create a Composer installation script: ``` nano /var/www/html/syspass/install-composer.sh ``` Add the following code: ``` #!/bin/sh EXPECTED_SIGNATURE="$(wget -q -O - https://composer.github.io/installer.sig)" php -r "copy('https://getcomposer.org/installer', 'composer-setup.php');" ACTUAL_SIGNATURE="$(php -r "echo hash_file('sha384', 'composer-setup.php');")" if [ "$EXPECTED_SIGNATURE" != "$ACTUAL_SIGNATURE" ] then >&2 echo 'ERROR: Invalid installer signature' rm composer-setup.php exit 1 fi php composer-setup.php --quiet RESULT=$? rm composer-setup.php exit $RESULT ``` Save the file, then change the directory to sysPass and run the script as shown below: ``` cd /var/www/html/syspass/ sh install-composer.sh ``` Once the Composer is installed, run the following command to install all PHP dependencies required for sysPass: ``` php composer.phar install --no-dev ``` ## Step 5 – Configure Apache to Host sysPass Next, create an Apache virtual host configuration file to host the sysPass. ``` nano /etc/httpd/conf.d/syspass.conf ``` Add the following codes: ``` ServerAdmin admin@your-domain.com DocumentRoot "/var/www/html/syspass" ServerName syspass.your-domain.com Options MultiViews FollowSymlinks AllowOverride All Order allow,deny Allow from all TransferLog /var/log/httpd/syspass_access.log ErrorLog /var/log/httpd/syspass_error.log ``` Save and close the file when you are finished. **Note**: replace **syspass.your-domain.com** with your own fully qualified domain name. Finally, restart the Apache service to apply the configuration changes: ``` systemctl restart httpd ``` ## Step 6 – Access sysPass Web UI Now, open your web browser and type the URL **http://syspass.your-domain.com** to access the sysPass. You will be redirected to the sysPass web installation wizard: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p2-8-1024x451.png) ![](https://www.atlantic.net/wp-content/uploads/2021/03/p3-7-1024x503.png) Provide your admin username, password, master password, database name, database username, password, then select HOSTING MODE and click on the **INSTALL** button to start the installation. Once the sysPass has been installed, you will be redirected to the sysPass login page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p5-2-1024x492.png) Provide your sysPass admin username, password and hit **Enter**. You should see the sysPass dashboard on the following page. ![](https://www.atlantic.net/wp-content/uploads/2021/03/p6-2-1024x530.png) Congratulations! You have successfully installed sysPass password manager on CentOS 8 operating system. You can now add your all account passwords and manage them through the web browser. Try it on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net today! --- # How to Disable Apache Server Signature on CentOS 8 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-disable-apache-server-signature-on-centos-8/ | Published: 2021-05-08 | Updated: 2023-11-13 | Author: Hitesh Jethva If you are using an Apache webserver to host your application in the production environment, then it is recommended to disable the Apache server signature to hide the Apache version number. Attackers can use Nmap or another tool to find the Apache version number before performing an attack. After detecting the Apache version number, attackers find the vulnerability of a specific Apache version and perform the attack. In this post, we will show you how to disable the Apache server signature on CentOS 8. ## Step 1 – Install Apache Server Before starting, the Apache webserver must be installed on your server. If not installed, you can install it with the following command: ``` dnf install httpd -y ``` Once installed, start the Apache service and enable it to start at system reboot: ``` systemctl start httpd systemctl enable httpd ``` ## Step 2 – Verify Apache Server Signature Next, you will need to check whether the Apache signature is on or off. You can check it by running the following command: ``` curl --head http://localhost ``` You should see the following output: ``` HTTP/1.1 403 Forbidden Date: Wed, 24 Mar 2021 12:24:45 GMT Server: Apache/2.4.37 (centos) Content-Location: index.html.zh-CN Vary: negotiate,accept-language TCN: choice Last-Modified: Fri, 14 Jun 2019 03:37:43 GMT ETag: "fa6-58b405e7d6fc0;5be475f323d62" Accept-Ranges: bytes Content-Length: 4006 Content-Type: text/html; charset=UTF-8 Content-Language: zh-cn ``` The above output shows the Apache version number that means the Apache signature is enabled in your system. ## Step 3 – Disable Apache Signature You can disable the Apache signature by editing the Apache main configuration file: ``` nano /etc/httpd/conf/httpd.conf ``` Add the following line at the end of the file: ``` ServerTokens Prod ``` Save and close the file when you are finished. Then, restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 4 – Verify the Apache Signature At this point, the Apache signature is disabled on your system. Next, you will need to verify whether the Apache signature is disabled or not. To check it, run the following command: ``` curl --head http://localhost ``` You should see the following output: ``` HTTP/1.1 403 Forbidden Date: Wed, 24 Mar 2021 12:26:25 GMT Server: Apache Content-Location: index.html.zh-CN Vary: negotiate,accept-language TCN: choice Last-Modified: Fri, 14 Jun 2019 03:37:43 GMT ETag: "fa6-58b405e7d6fc0;5be475f323d62" Accept-Ranges: bytes Content-Length: 4006 Content-Type: text/html; charset=UTF-8 Content-Language: zh-cn ``` The above output does not show the Apache version, which means the Apache signature is disabled in your system. ## Conclusion In the above guide, you learned how to disabled the Apache signature on CentOS 8. Ideally, this will increase your Apache web server security; try it today on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install Sphinx-Doc on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-sphinx-doc-on-ubuntu-20-04/ | Published: 2021-05-09 | Updated: 2023-11-15 | Author: Hitesh Jethva Sphinx is a powerful documentation generator tool that allows you to create intelligent and beautiful documentation. It is written in python and based on the jinja template. Sphinx has many features that make it easier to generate web pages, printable PDFs, and ePub documents. In this post, we will show you how to install Sphinx-Doc on Ubuntu 20.04. ## Step 1 – Install Required Dependencies Sphinx-Doc is written in Python, so you will need to install Python modules and Apache server to your system. You can install all of them with the following command: ``` apt-get install python3-pip python3-dev python3-setuptools apache2 -y ``` Once all the packages are installed, update pip to the latest version with the following command: ``` pip3 install --upgrade pip ``` ## Step 2 – Install Sphinx-Doc Next, you can install the Sphinx-Doc using the pip command as shown below: ``` pip3 install sphinx ``` Once the installation has been finished, you should get the following output: Installing collected packages: MarkupSafe, Jinja2, sphinxcontrib-jsmath, Pygments, sphinxcontrib-devhelp, docutils, imagesize, snowballstemmer, alabaster, sphinxcontrib-serializinghtml, sphinxcontrib-htmlhelp, pytz, babel, sphinxcontrib-applehelp, pyparsing, packaging, sphinxcontrib-qthelp, sphinx Successfully installed Jinja2-2.11.3 MarkupSafe-1.1.1 Pygments-2.8.1 alabaster-0.7.12 babel-2.9.0 docutils-0.16 imagesize-1.2.0 packaging-20.9 pyparsing-2.4.7 pytz-2021.1 snowballstemmer-2.1.0 sphinx-3.5.3 sphinxcontrib-applehelp-1.0.2 sphinxcontrib-devhelp-1.0.2 sphinxcontrib-htmlhelp-1.0.3 sphinxcontrib-jsmath-1.0.1 sphinxcontrib-qthelp-1.0.3 sphinxcontrib-serializinghtml-1.1.4 ## Step 3 – Configure Sphinx-Doc Next, change the directory to Apache document root and run the Sphinx-Doc setup script. ``` cd /var/www/html/ sphinx-quickstart ``` You will be asked to provide your project name, author name, and project release as shown below: ``` Welcome to the Sphinx 3.5.3 quickstart utility. Please enter values for the following settings (just press Enter to accept a default value, if one is given in brackets). Selected root path: . You have two options for placing the build directory for Sphinx output. Either, you use a directory "_build" within the root path, or you separate "source" and "build" directories within the root path. > Separate source and build directories (y/n) [n]: n The project name will occur in several places in the built documentation. > Project name: myapp > Author name(s): admin > Project release []: 20.04 If the documents are to be written in a language other than English, you can select a language here by its language code. Sphinx will then translate text that it generates into that language. For a list of supported codes, see https://www.sphinx-doc.org/en/master/usage/configuration.html#confval-language. > Project language [en]: Creating file /var/www/html/conf.py. Creating file /var/www/html/index.rst. Creating file /var/www/html/Makefile. Creating file /var/www/html/make.bat. Finished: An initial directory structure has been created. You should now populate your master file /var/www/html/index.rst and create other documentation source files. Use the Makefile to build the docs, like so: make builder where "builder" is one of the supported builders, e.g. html, latex or linkcheck. ``` Next, run the following command to generate a static HTML file: ``` make html ``` You should get the following output: ``` Running Sphinx v3.5.3 making output directory... done building [mo]: targets for 0 po files that are out of date building [html]: targets for 1 source files that are out of date updating environment: [new config] 1 added, 0 changed, 0 removed reading sources... [100%] index looking for now-outdated files... none found pickling environment... done checking consistency... done preparing documents... done writing output... [100%] index generating indices... genindex done writing additional pages... search done copying static files... done copying extra files... done dumping search index in English (code: en)... done dumping object inventory... done build succeeded. The HTML pages are in _build/html. ``` The above command will generate an HTML file at /var/www/html/_build/html/index.html. ## Step 4 – Configure Apache for Sphinx-Doc Next, you will need to edit the Apache default virtual host configuration file and define the path of your HTML file. ``` nano /etc/apache2/sites-available/000-default.conf ``` Find the following lien: ``` DocumentRoot /var/www/html/ ``` And, replaced it with the following line: ``` DocumentRoot /var/www/html/_build/html/ ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` ## Step 5 – Access Sphinx-Doc Now, open your web browser and access the Sphinx-Doc using the URL **http://your-server-ip**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p1-10-1024x415.png) ## Conclusion Congratulations! You have successfully installed Sphinx-Doc on Ubuntu 20.04 server. You can now use Sphinx-Doc for any documentation project, including one on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install AskBot on Debian 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-askbot-on-debian-10/ | Published: 2021-05-10 | Updated: 2023-11-16 | Author: Hitesh Jethva Askbot is a free and open-source question and answers forum application written in Python and Django. It is simple, highly customizable, and very similar to other forum software including StackOverflow and YahooAnswers. It has some good features including a karma-based content system, voting, and content moderation. Currently, it is used by open-source projects like Fedora and LibreOffice. In this post, we will show you how to install Askbot forum software on Debian 10. ## Step 1 – Install Required Dependencies Before starting, you will need to install some Python dependencies in your server. You can install all of them by running the following command: ``` apt-get update -y ``` ``` apt-get install python-dev python-setuptools python-pip sudo python-psycopg2 libpq-dev -y ``` Once all the dependencies are installed, you can proceed to the next step. ## Step 2 – Install and Configure PostgreSQL Askbot uses PostgreSQL or MariaDB as a database backend, so you will need to install any database software in your system. You can install the PostgreSQL database with the following command: ``` apt-get install postgresql -y ``` Once installed, connect to the PostgreSQL shell with the following command: ``` su - postgres [postgres@centos8 ~]$ psql ``` Next, create a database and user for Askbot with the following command: ``` postgres=# create database askbot; postgres=# create user askbot with password 'password'; ``` Next, grant all the privileges to askbot with the following command: ``` postgres=# grant all privileges on database askbot to askbot; ``` Finally, exit from the PostgreSQL shell with the following command: ``` postgres=# \q exit ``` Next, you will need to edit the PostgreSQL main configuration file and enable the md5 authentication. ``` nano /etc/postgresql/11/main/pg_hba.conf ``` Change the following lines: ``` # "local" is for Unix domain socket connections only local all all md5 # IPv4 local connections: host all all 127.0.0.1/32 md5 # IPv6 local connections: host all all ::1/128 md5 ``` Save and close the file, then restart PostgreSQL to apply the changes: ``` systemctl restart postgresql ``` ## Step 3 – Install Askbot First, create a user for Askbot and set a password with the following command: ``` useradd -m -s /bin/bash askbot passwd askbot ``` Next, add askbot user to sudo with the following command: ``` usermod -a -G sudo askbot ``` Next, install python virtualenv package with the following command: ``` pip install virtualenv six ``` Once installed, change the user to askbot and create a new virtual environment for Askbot with the following command: ``` su - askbot virtualenv askbot ``` Next, change the directory to askbot and activate the virtual environment with the following command: ``` cd askbot source bin/activate ``` Next, upgrade pip to the latest version using the command below: ``` pip install --upgrade pip ``` Next, install Askbot, Six, and PostgreSQL module with the following command: ``` pip install six==1.10.0 pip install askbot==0.10.3 psycopg2 ``` Next, create a directory for your application: ``` mkdir myapp ``` Next, change the directory to myapp and setup the Askbot with the following command: ``` cd myapp askbot-setup ``` You will be asked to provide installation path: ``` Deploying Askbot - Django Q&A forum application Problems installing? -> please email admin@askbot.org To CANCEL - hit Ctr-C at any time Enter directory path (absolute or relative) to deploy askbot. To choose current directory - enter "." > . ``` Type . and hit Enter to continue. You should see the following output: ``` Please select database engine: 1 - for postgresql, 2 - for sqlite, 3 - for mysql, 4 - oracle type 1/2/3/4: 1 ``` Type 1 to select a postgresql database engine and hit Enter to continue. You should see the following output: ``` Please enter database name (required) > askbot Please enter database user (required) > askbot Please enter database password (required) > password Press Enter for all other values ``` Provide your Askbot database details and hit Enter to finish the setup. Next, generate the static file with the following command: ``` python manage.py collectstatic ``` Next, migrate the database with the following command: ``` python manage.py migrate ``` Next, start the Askbot server with the following command: ``` python manage.py runserver 0.0.0.0:8080 & ``` You should get the following output: ``` Performing system checks... System check identified no issues (0 silenced). March 24, 2021 - 03:07:43 Django version 1.8.19, using settings 'settings' Starting development server at http://0.0.0.0:8080/ Quit the server with CONTROL-C. ``` Press CTRL+C to stop the server. ## Step 4 – Install and Configure Uwsgi Make sure you have exited out of the virtualenv to the root shell – type *exit* Next, you will need to install Uwsgi to manage the Askbot service. You can install it with Nginx using the following command: ``` pip install uwsgi apt-get install nginx -y ``` Next, create a site directory for Uwsqi and create an askbok.ini file: ``` mkdir -p /etc/uwsgi/sites nano /etc/uwsgi/sites/askbot.ini ``` Add the following lines: ``` [uwsgi] chdir = /home/askbot/askbot/myapp home = /home/askbot/askbot static-map = /m=/home/askbot/askbot/myapp/static wsgi-file = /home/askbot/askbot/myapp/django.wsgi master = true processes = 5 # Askbot will running under the sock file socket = /run/uwsgi/askbot.sock chmod-socket = 664 uid = askbot gid = www-data vacuum = true # uWSGI Log file logto = /var/log/uwsgi.log ``` Save and close the file when you are finished. ## Step 5 – Create a Systemd Service File for Askbot Next, you will need to create a systemd service file to manage the Askbot service. ``` nano /etc/systemd/system/uwsgi.service ``` Add the following lines: ``` [Unit] Description=uWSGI service [Service] ExecStartPre=/bin/bash -c 'mkdir -p /run/uwsgi; chown askbot:www-data /run/uwsgi' ExecStart=/usr/local/bin/uwsgi --emperor /etc/uwsgi/sites Restart=always KillSignal=SIGQUIT Type=notify NotifyAccess=all [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the Askbot service and enable it to start at system reboot: ``` systemctl start uwsgi systemctl enable uwsgi ``` You can also verify the status of Askbot with the following command: ``` systemctl status uwsgi ``` You should get the following output: ``` ● uwsgi.service - uWSGI service Loaded: loaded (/etc/systemd/system/uwsgi.service; disabled; vendor preset: enabled) Active: active (running) since Wed 2021-03-24 09:12:55 UTC; 6s ago Process: 13609 ExecStartPre=/bin/bash -c mkdir -p /run/uwsgi; chown askbot:www-data /run/uwsgi (code=exited, status=0/SUCCESS) Main PID: 13612 (uwsgi) Status: "The Emperor is governing 1 vassals" Tasks: 7 (limit: 2359) Memory: 65.4M CGroup: /system.slice/uwsgi.service ├─13612 /usr/local/bin/uwsgi --emperor /etc/uwsgi/sites ├─13613 /usr/local/bin/uwsgi --ini askbot.ini ├─13617 /usr/local/bin/uwsgi --ini askbot.ini ├─13618 /usr/local/bin/uwsgi --ini askbot.ini ├─13619 /usr/local/bin/uwsgi --ini askbot.ini ├─13620 /usr/local/bin/uwsgi --ini askbot.ini └─13621 /usr/local/bin/uwsgi --ini askbot.ini Mar 24 09:12:55 debian10 uwsgi[13612]: your processes number limit is 7865 Mar 24 09:12:55 debian10 uwsgi[13612]: your memory page size is 4096 bytes Mar 24 09:12:55 debian10 uwsgi[13612]: detected max file descriptor number: 1024 Mar 24 09:12:55 debian10 systemd[1]: Started uWSGI service. Mar 24 09:12:55 debian10 uwsgi[13612]: *** starting uWSGI Emperor *** Mar 24 09:12:55 debian10 uwsgi[13612]: *** has_emperor mode detected (fd: 7) *** Mar 24 09:12:55 debian10 uwsgi[13612]: [uWSGI] getting INI configuration from askbot.ini Mar 24 09:12:55 debian10 uwsgi[13612]: [uwsgi-static] added mapping for /m => /home/askbot/askbot/myapp/static Mar 24 09:12:56 debian10 uwsgi[13612]: Wed Mar 24 09:12:56 2021 - [emperor] vassal askbot.ini has been spawned Mar 24 09:12:56 debian10 uwsgi[13612]: Wed Mar 24 09:12:56 2021 - [emperor] vassal askbot.ini is ready to accept requests ``` ## Step 6 – Configure Nginx for Askbot Next, you will need to configure Nginx to host the Askbot application. To do so, create an Nginx virtual host configuration file: ``` nano /etc/nginx/conf.d/askbot.conf ``` Add the following lines: ``` server { listen 80; server_name askbot.example.com; location / { include uwsgi_params; uwsgi_pass unix:/run/uwsgi/askbot.sock; } } ``` Save and close the file, then verify Nginx for any syntax error with the following command: ``` nginx -t ``` **If you get this error : nginx: [emerg] could not build server_names_hash, you should increase server_names_hash_bucket_size: 32** **nginx: configuration file /etc/nginx/nginx.conf test failed type:** **nano /etc/nginx/nginx.conf** **Make sure that server_names_hash_bucket_size 64; is uncommented** Next, restart Nginx to apply the configuration changes: ``` systemctl start nginx ``` ## Step 7 – Access Askbot Now, open your web browser and access the Askbot web UI using the URL**http://askbot.example.com**. You will be redirected to the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p1-9-1024x420.png) Click on the **Sign in** button. You should see the following page; ![](https://www.atlantic.net/wp-content/uploads/2021/03/p2-6-1024x483.png) Provide your login name, email, and password and click on the **Signup** button. You should see the Askbot dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p3-6-1024x460.png) ## Conclusion Congratulations! You have successfully installed Askbot with Nginx on Debian 10. You can now create your own Q&A forum with Askbot. Try it today on a [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Atlantic.Net, Inc. Named Winner of 2021 Bronze Stevie® Award in Healthcare Technology Solution > URL: https://www.atlantic.net/announcements/atlantic-net-inc-named-winner-of-2021-bronze-stevie-award-in-healthcare-technology-solution/ | Published: 2021-05-11 | Updated: 2025-09-19 | Author: Alexander Wise ![](https://www.atlantic.net/wp-content/uploads/2021/05/ABA21_Bronze_Winner-300x296.jpg) We are pleased to announce that the American Business Awards recognized Atlantic.Net for its [Healthcare HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) with a Stevie Award the for second year in a row. This is a testament to our top-notch and unparalleled service chosen by thousands of businesses in over 100 countries. Atlantic.Net, Inc. was named the winner of a Bronze Stevie® Award in the Healthcare Technology Solution category in the 19th Annual American Business Awards®. The American Business Awards are the U.S.A.’s premier business awards program. All organizations operating in the U.S.A. – public and private, for-profit and non-profit, large and small – are eligible to submit nominations. Nicknamed the Stevies for the Greek word meaning “crowned,” the awards will be virtually presented to winners during a live event on Wednesday, June 30. More than 3,800 nominations – a record number – from organizations of all sizes and in virtually every industry were submitted this year for consideration in a wide range of categories, including Startup of the Year, Executive of the Year, Best New Product or Service of the Year, Marketing Campaign of the Year, Virtual Event of the Year, and App of the Year, among others.  Atlantic.Net was nominated in the Healthcare Technology Solution category for [HIPAA-Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/). We are truly excited to be awarded the prestigious award! We look forward to continuing to provide top-notch HIPAA Compliant Hosting services to our clients, backed by our world-class infrastructure and always available expert support. --- # How to Create Soft and Hard Links in Linux > URL: https://www.atlantic.net/vps-hosting/how-to-create-soft-and-hard-links-in-linux/ | Published: 2021-05-12 | Updated: 2023-11-16 | Author: Hitesh Jethva A link in a Linux-based operating system points to a file or a directory. Links allow more than one file name to refer to the same file. There are two types of links, Soft Links and Hard Links. In simple terms, a soft link is an actual link to the original file, while a hard link is a mirror copy of the original file. If you delete the original file. you can not access its contents via its soft link. On the other hand, if you delete the original file you can still access its contents via its hard link. The hard link has the same inode number and file permissions while the soft link has the different inode number and file permissions. In this post, we will show you how to create a soft and hard link in Linux. ## Create a Soft Link First, create a directory named softlink with the following command: ``` mkdir softlink ``` Next, create a file named normal_link.txt: ``` cd softlink echo "This is a softlink" > normal_link.txt ``` Next, create a soft link of the file **normal_link.txt**: ``` ln -s normal_link.txt soft_link.txt ``` Now, check the content of both files: ``` cat normal_link.txt ``` Output: ``` This is a softlink ``` And ``` cat soft_link.txt ``` Output: ``` This is a softlink ``` As you can see, both files have the same content. Now, check the inode number and permissions of both files: ``` ls -lia ``` You should see that both files have different inode numbers and permission. ``` 15866192 drwxrwxr-x 2 vyom vyom 4096 Apr 19 15:10 . 15466497 drwxrwxrwt 13 root root 4096 Apr 19 15:10 .. 15866186 -rw-rw-r-- 1 vyom vyom 19 Apr 19 15:09 normal_link.txt 15866189 lrwxrwxrwx 1 vyom vyom 15 Apr 19 15:10 soft_link.txt -> normal_link.txt ``` Now, remove the original file with the following command: ``` rm -rf normal_link.txt ``` Now, check the content of the soft link file: ``` cat soft_link.txt ``` Output: ``` cat: soft_link.txt: No such file or directory ``` As you can see, there is no such file or directory. If you want to remove the soft link, run the following command: ``` unlink soft_link.txt ``` ## Create a Hard Link First, create a directory named hardlink with the following command: ``` mkdir hardlink ``` Next, create a file named normal_link.txt with the following command: ``` cd hardlink echo "This is a hard link" > normal_link.txt ``` Next, create a hard link of the file with the following command: ``` ln normal_link.txt hard_link.txt ``` Now, check the content of both files: ``` cat normal_link.txt ``` Output: ``` This is a hard link ``` And ``` cat hard_link.txt ``` Output: ``` This is a hard link ``` Next, check the inode and permission of both files: ``` ls -lia ``` You should see that both files have the same inode and permission: ``` 15866186 drwxrwxr-x 2 vyom vyom 4096 Apr 19 15:16 . 15466497 drwxrwxrwt 14 root root 4096 Apr 19 15:16 .. 15866190 -rw-rw-r-- 2 vyom vyom 20 Apr 19 15:16 hard_link.txt 15866190 -rw-rw-r-- 2 vyom vyom 20 Apr 19 15:16 normal_link.txt ``` Now, try to add some content to the original file: ``` echo "I am adding some content" >> normal_link.txt ``` Now, check the content of the hard link: ``` cat hard_link.txt ``` You should see that the changes we made on the original file are updated in both files. ``` This is a hard link I am adding some content ``` Now, remove the original file: ``` rm -rf normal_link.txt ``` Now, check the content of the hard link: ``` cat hard_link.txt ``` You should still see the content of the file: ``` This is a hard link I am adding some content ``` If you want to remove the hard link, run the following command: ``` unlink hard_link.txt ``` ## Conclusion In the above guide, you learned how to create a soft and hard link on Linux. Try creating soft and hard links on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account with Atlantic.Net! --- # Atlantic.net Honored As Bronze Stevie® Award Winner In 2021 American Business Awards® > URL: https://www.atlantic.net/press-releases/atlantic-net-honored-as-bronze-stevie-award-winner-in-2021-american-business-awards/ | Published: 2021-05-13 | Updated: 2024-07-02 | Author: Editorial Team *Stevie winners will be celebrated during the virtual awards ceremony on June 30* **ORLANDO, FLORIDA (May 13, 2021)** – Atlantic.Net, Inc. was named the winner of a Bronze Stevie® Award in the Healthcare Technology Solution category in the 19^th^ Annual American Business Awards® today. The American Business Awards are the U.S.A.’s premier business awards program. All organizations operating in the U.S.A. – public and private, for-profit and non-profit, large and small – are eligible to submit nominations. Nicknamed the Stevies for the Greek word meaning “crowned,” the awards will be virtually presented to winners during a live event on Wednesday, June 30. More than 3,800 nominations – a record number – from organizations of all sizes and in virtually every industry were submitted this year for consideration in a wide range of categories, including Startup of the Year, Executive of the Year, Best New Product or Service of the Year, Marketing Campaign of the Year, Virtual Event of the Year, and App of the Year, among others.  Atlantic.Net was nominated in the Healthcare Technology Solution category for HIPAA compliant Hosting. More than [250 professionals](https://stevieawards.com/aba/judges) worldwide participated in the judging process to select this year’s Stevie Award winners. “We are excited that the American Business Awards recognized our [Healthcare HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) with a Stevie Award for the second year in a row,” said Marty Puranik, CEO of Atlantic.Net. “This is a testament to our top-notch service and unparallel service chosen by thousands of businesses in over 100 counties.” “The American economy continues to show its resilience, and as we’re poised on the beginning of what should be a phenomenal period of growth, we celebrate the remarkable achievements of a wide range of organizations and people over the past 18 months,” said Stevie Awards president Maggie Gallagher.  “This year’s Stevie-winning nominations in The American Business Awards are testament to the ingenuity, the commitment, the passion, the adaptability, and the creativity of the American people.  We look forward to celebrating this year’s winners during our virtual ceremony on June 30.” Details about The American Business Awards and the list of 2021 Stevie winners are available at [www.StevieAwards.com/ABA](https://www.stevieawards.com/ABA). **About Atlantic.Net** Atlantic.Net is a global cloud services provider with over 25 years of experience, specializing in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions, backed by 24/7/365 support through their global data centers located in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. For more information, please visit [Atlantic Net](https://www.atlantic.net/). **About the Stevie Awards** Stevie Awards are conferred in eight programs: the Asia-Pacific Stevie Awards, the German Stevie Awards, the Middle East & North Africa Stevie Awards, The American Business Awards®, The International Business Awards®, the Stevie Awards for Women in Business, the Stevie Awards for Great Employers, and the Stevie Awards for Sales & Customer Service. The Stevies also produces the annual [Women|Future Conference|http://www.womenfutureconference.com/].  Stevie Awards competitions receive more than 12,000 entries each year from organizations in more than 70 nations. Honoring organizations of all types and sizes and the people behind them, the Stevies recognize outstanding performances in the workplace worldwide. Learn more about the Stevie Awards at [http://www.StevieAwards.com](https://www.stevieawards.com/). Sponsors of the 2021 American Business Awards include John Hancock Financial Services, Melissa Sones Consulting, and SoftPro. ** Contact: Email: pr@atlantic.net Ph: 321- 206-1371 --- # How to Use SSMTP to Send an Email from Linux Terminal > URL: https://www.atlantic.net/vps-hosting/how-to-use-ssmtp-to-send-an-email-from-linux-terminal/ | Published: 2021-05-13 | Updated: 2026-06-17 | Author: Hitesh Jethva SSMTP is a simple utility that can be used to send emails from Linux in a local system to the specified email address. It is just MTA; it does not receive mail, expand aliases, or manage a queue. It forwards automated emails to an external email address. Generally, it can be used to forward an automated email (like system alerts) from your system to an external email address. This post will show you how to install and use SSMTP to send an email from the command-line interface. ## Step 1 – Install SSMTP The SSMTP package is included in the Ubuntu 20.04 default repository by default. You can install it by just running the following command: ``` apt update -y ``` ``` apt-get install ssmtp -y ``` Once the SSMTP package is installed, you can proceed to the next step. ## Step 2 – Configure SSMTP Next, you will need to define your Gmail or other SMTP servers in SSMTP configuration file. You can define it in the /etc/ssmtp/ssmtp.conf file: ``` nano /etc/ssmtp/ssmtp.conf ``` Add the following lines: ``` FromLineOverride=YES root=postmaster mailhub=smtp.atlantic.net:587 hostname=ubuntu2004 AuthUser=hiteshjethva@atlantic.net AuthPass=your-password FromLineOverride=YES UseSTARTTLS=YES ``` Save and close the file when you are finished. SSMTP is now configured to send an email to your SMTP server address. ## Step 3 – Send an Email with SSMTP First, create a text file and write some content: ``` nano file.txt ``` Add the following lines: ``` Subject: This is Subject Line Email content line 1 Email content line 2 ``` Save and close the file, then send an email with an attachment file.txt to the external address user@atlantic.net: ``` ssmtp -v user@atlantic.net < file.txt ``` If everything is fine, you should see the following output: ``` [<-] 220 and/or bulk e-mail. [->] EHLO ubuntu2004 [<-] 250 HELP [->] STARTTLS [<-] 220 TLS go ahead [->] EHLO ubuntu2004 [<-] 250 HELP [->] AUTH LOGIN [<-] 334 VXNlcm5hbWU6 [->] aGl0ZXNoamV0aHZhQGxpbnV4YnV6LmNvbQ== [<-] 334 UGFzc3dvcmQ6 [<-] 235 Authentication succeeded [->] MAIL FROM: [<-] 250 OK [->] RCPT TO: [<-] 250 Accepted [->] DATA [<-] 354 Enter message, ending with "." on a line by itself [->] Received: by ubuntu2004 (sSMTP sendmail emulation); Sun, 18 Apr 2021 08:05:14 +0000 [->] From: "root" [->] Date: Sun, 18 Apr 2021 08:05:14 +0000 [->] Subject: This is Subject Line [->] [->] Email content line 1 [->] Email content line 2 [->] [->] . [<-] 250 OK id=1lY2Qe-003yGr-RV [->] QUIT [<-] 221 box2419.atlantic.net closing connection ``` You can now check your inbox to check your email. You can also send an email using the mail command. To do so, you will need to install the mailutils package to send an email using the command line. You can install it with the following command: ``` apt-get install mailutils -y ``` Once installed, run the following command to send an email with your desired body text and subject line, as shown below: ``` echo "Your Email Body" | mail -s "your subject" user@gmail.com ``` ## Conclusion In the above guide, you learned how to install and use SSMTP to send an email from the command line. You can now integrate SSMPT with your application to send an email – try it on your [Atlantic.Net VPS](https://www.atlantic.net/vps-hosting/) today! --- # How to Install and Use the Screen Command on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-the-screen-command-ubuntu/ | Published: 2021-05-14 | Updated: 2023-11-27 | Author: Hitesh Jethva Screen is a console application that allows users to open several separate terminal instances within a single terminal. It is very useful when you are performing a long-running task on a remote system and you lose your connection or SSH session. In this case, the Screen command utility will help you to resume the SSH session. The process running in the Screen will continue running even after closing the terminal windows. You can reconnect exactly from where the session was disconnected. In this post, we will show you how to install and use the Screen command on Ubuntu 20.04. ## Install Screen By default, the Screen package is included in the Ubuntu 20.04 default repository. You can install it with the following command: ``` apt-get update -y apt-get install screen -y ``` Once the Screen package is installed, verify the installed version of Screen using the following command: ``` screen --version ``` Output: ``` Screen version 4.08.00 (GNU) 05-Feb-20 ``` To print the list of all options, press CTRL+a followed by ?: ![](https://www.atlantic.net/wp-content/uploads/2021/04/p2-2-1024x576.png) ## How to Use the Screen Command To create a new name session, run the following command: ``` screen -S name1 ``` To exit from the screen session, run the following command: ``` exit ``` To create a new screen window, press **CTRL+a** followed by **c**: To list all open windows, press **CTRL+a** followed by **“**: ![](https://www.atlantic.net/wp-content/uploads/2021/04/list-screen-windows-1024x171.png) To change the current window to**0**, press **CTRL+a** followed by **0.** To rename the current windows, press **CTRL+a** followed by **A**. ![](https://www.atlantic.net/wp-content/uploads/2021/04/rename-windows.png) To split the screen horizontally, press **CTRL+a** followed by **S**. ![](https://www.atlantic.net/wp-content/uploads/2021/04/split1-1024x567.png) To toggle between the split windows, press **CTRL+a** followed by **tab**. To split the screen vertically, press **CTRL+a** followed by**|**. ![](https://www.atlantic.net/wp-content/uploads/2021/04/split2-1024x564.png) When you have finished and you want to quit the screen session, you can use the command **CTRL+a** followed by**k**. To detach from the screen session, press**CTRL+a** followed by **d**. To find the session id of all screen sessions, run the following command: ``` screen -ls ``` You should see the following output: ``` There are screens on: 23829.name1 (04/18/2021 09:19:50 AM) (Detached) 23751.name1 (04/18/2021 09:09:01 AM) (Attached) 23724.pts-0.ubuntu2004 (04/18/2021 09:04:05 AM) (Detached) 23670.pts-0.ubuntu2004 (04/18/2021 09:02:42 AM) (Detached) 4 Sockets in /run/screen/S-root. ``` To resume your screen session named 23829.name1, run the following command: ``` screen -r 23829.name1 ``` ## Conclusion In the above guide, you learned how to use Screen command-line utility to open multiple screens from a single session, switch between them, resume, detach and resume the screen session. You can use the command on your Atlantic.Net [VPS](https://www.atlantic.net/vps-hosting/) remote system. --- # How to Deploy a PHP Application with Nginx and MySQL Using Docker and Docker Compose > URL: https://www.atlantic.net/vps-hosting/how-to-deploy-a-php-application-with-nginx-and-mysql-using-docker-and-docker-compose/ | Published: 2021-05-15 | Updated: 2025-10-01 | Author: Hitesh Jethva Docker is an open-source containerization tool that allows you to create, deploy, and run applications using containers. Containers allow you to package an application with all required parts and deploy it as a single package. Containers are portable, and you can deploy them anywhere. A container brings developers a uniform and streamlined work environment that can be easily shared. This guide will show you how to deploy a PHP application with Nginx and MySQL using Docker and Docker Compose. ## Step 1 – Install Docker and Docker Compose By default, the latest version of Docker is not included in the Ubuntu default repository, so you will need to add the Docker repository to your system. First, install the required dependencies using the following commands: ``` apt-get update -y ``` ``` apt-get install apt-transport-https ca-certificates curl tree software-properties-common -y ``` Next, add the Docker repository using the following command: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add - add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu focal stable" ``` Next, install the Docker and Docker Compose with the following command: ``` apt-get install docker-ce docker-compose -y ``` Once you are finished, you can proceed to the next step. ## Step 2 – Directory Structure For this tutorial, we will use the following directory structure: ``` /root/docker-project/ ├── docker-compose.yml ├── nginx │   ├── default.conf │   └── Dockerfile ├── php │   └── Dockerfile └── www └── html └── index.php ``` ## Step 3 – Create an Nginx Container Before starting, you must create and launch an Nginx container to host the PHP application. First, create a directory for your project with the following command: ``` mkdir ~/docker-project ``` Next, change the directory to your project and create a docker-compose.yml file to launch the Nginx container. ``` cd ~/docker-project nano docker-compose.yml ``` Add the following lines: ``` nginx: image: nginx:latest container_name: nginx-container ports: - 80:80 ``` Save and close the file when you are finished. The above file will download the latest Nginx image, create an Nginx container, and expose it on port 80. Next, launch the Nginx container with the following command: ``` docker-compose up -d ``` You can check the running container with the following command: ``` docker ps ``` You should see the following output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES c6641e4d5bbf nginx:latest "/docker-entrypoint.…" 5 seconds ago Up 3 seconds 0.0.0.0:80->80/tcp, :::80->80/tcp nginx-container ``` Now, open your web browser and access your Nginx container using the URL **http://your-server-ip**. You should see the Nginx test page on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/04/p1-1.png) ## Step 4 – Create a PHP Container First, create a new directory inside your project with the following command: ``` mkdir -p ~/docker-project/www/html ``` Next, create an index.php file to verify your PHP version. ``` nano ~/docker-project/www/html/index.php ``` Add the following lines: ``` Hello World!

Hello World!

``` Save and close the file, then create a directory for Nginx inside your project directory: ``` mkdir ~/docker-project/nginx ``` Next, create an Nginx default configuration file to run your PHP application: ``` nano ~/docker-project/nginx/default.conf ``` Add the following lines: ``` server { listen 80 default_server; root /var/www/html; index index.html index.php; charset utf-8; location / { try_files $uri $uri/ /index.php?$query_string; } location = /favicon.ico { access_log off; log_not_found off; } location = /robots.txt { access_log off; log_not_found off; } access_log off; error_log /var/log/nginx/error.log error; sendfile off; client_max_body_size 100m; location ~ .php$ { fastcgi_split_path_info ^(.+.php)(/.+)$; fastcgi_pass php:9000; fastcgi_index index.php; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_intercept_errors off; fastcgi_buffer_size 16k; fastcgi_buffers 4 16k; } location ~ /.ht { deny all; } } ``` Save and close the file. Next, create a Dockerfile inside the nginx directory. This will copy the Nginx default config file to the Nginx container. ``` nano ~/docker-project/nginx/Dockerfile ``` Add the following lines: ``` FROM nginx:latest COPY ./default.conf /etc/nginx/conf.d/default.conf ``` Next, edit the docker-compose.yml file: ``` nano ~/docker-project/docker-compose.yml ``` Remove the old contents and add the following contents: ``` nginx build: ./nginx/ container_name: nginx-container ports: - '80:80' links: - php volumes_from: - app-data php: build: ./php/ container_name: php-container expose: - 9000 links: - mysql volumes_from: - app-data app-data: image: 'php:7.0-fpm' container_name: app-data-container volumes: - './www/html/:/var/www/html/' command: 'true' mysql: image: 'mysql:5.7' container_name: mysql-container volumes_from: - mysql-data environment: MYSQL_ROOT_PASSWORD: secret MYSQL_DATABASE: mydb MYSQL_USER: myuser MYSQL_PASSWORD: password mysql-data: image: 'mysql:5.7' container_name: mysql-data-container volumes: - /var/lib/mysql command: 'true' ' ``` Save and close the file when you are finished. The above file will create a new PHP-container, expose PHP-FPM on port 9000, link nginx-container to php-container, create a volume, and mount it on the container so that all content will be in sync with the container’s directory /var/www/html/. Now, launch the container with the following command: ``` cd ~/docker-project docker-compose up -d ``` You can verify the running containers with the following command: ``` docker ps ``` You should see the following output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 82c8baf15221 docker-project_nginx "/docker-entrypoint.…" 23 seconds ago Up 22 seconds 0.0.0.0:80->80/tcp, :::80->80/tcp nginx-container 10778c6686d8 php:7.0-fpm "docker-php-entrypoi…" 25 seconds ago Up 23 seconds 9000/tcp php-container ``` Now, open your web browser and access the URL **http://your-server-ip**. You should see your Hello World page: ![](https://www.atlantic.net/wp-content/uploads/2021/04/p2-1.png) Next, we will check whether our mounted volume works or not. To do so, edit the index.php file: ``` nano ~/docker-project/www/html/index.php ``` Change the line “Hello World! Changes are Applied”: ``` Hello World!

Hello World! Changes are Applied

``` Now, refresh your web page. You should see your modified page on the screen: ![](https://www.atlantic.net/wp-content/uploads/2021/04/p3-1024x440.png) ## Step 5 – Create a Data Container As you can see, we have mounted the directory www/html to our containers, nginx-container, and php-container. However, this is not a proper way. This section will create a separate data container to hold the data and link it to all other containers. To do so, edit the docker-compose.html file: ``` nano ~/docker-project/docker-compose.yml ``` Make the following changes: ``` nginx: build: ./nginx/ container_name: nginx-container ports: - '80:80' links: - php volumes_from: - app-data php: image: 'php:7.0-fpm' container_name: php-container expose: - 9000 volumes_from: - app-data app-data: image: 'php:7.0-fpm' container_name: app-data-container volumes: - './www/html/:/var/www/html/' command: 'true' ``` Now, recreate and launch all containers using the following command: ``` cd ~/docker-project docker-compose up -d ``` Now, verify all running containers with the following command: ``` docker ps -a ``` You should see the following output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 849315c7ffc0 docker-project_nginx "/docker-entrypoint.…" 27 seconds ago Up 25 seconds 0.0.0.0:80->80/tcp, :::80->80/tcp nginx-container 59a0d7040fd8 php:7.0-fpm "docker-php-entrypoi…" 28 seconds ago Up 27 seconds 9000/tcp php-container fbca95944234 php:7.0-fpm "docker-php-entrypoi…" 29 seconds ago Exited (0) 28 seconds ago app-data-container ``` ## Step 6 – Create a MySQL Container This section will create a MySQL database container and link it to all other containers. First, you must modify the PHP image and install the PHP extension for MySQL to connect to the MySQL database. First, create a directory for PHP with the following command: ``` mkdir ~/docker-project/php ``` Next, create a Dockerfile to install the PHP extension: ``` nano ~/docker-project/php/Dockerfile ``` Add the following lines: ``` FROM php:7.0-fpm RUN docker-php-ext-install pdo_mysql ``` Save and close the file. Then, edit the docker-compose.yml file to create a MySQL container and MySQL data container to hold the database and tables: ``` nano ~/docker-project/docker-compose.yml ``` Make the following changes: ``` nginx: build: ./nginx/ container_name: nginx-container ports: - '80:80' links: - php volumes_from: - app-data php: build: ./php/ container_name: php-container expose: - 9000 links: - mysql volumes_from: - app-data app-data: image: 'php:7.0-fpm' container_name: app-data-container volumes: - './www/html/:/var/www/html/' command: 'true' mysql: image: 'mysql:5.7' container_name: mysql-container volumes_from: - mysql-data environment: MYSQL_ROOT_PASSWORD: secret MYSQL_DATABASE: mydb MYSQL_USER: myuser MYSQL_PASSWORD: password mysql-data: image: 'mysql:5.7' container_name: mysql-data-container volumes: - /var/lib/mysql command: 'true' ``` Save and close the file. Next, edit the**index.php** file and make changes to test the database connection. ``` nano ~/docker-project/www/html/index.php ``` Make the following changes: ``` Hello World!

Hello World!

query("SELECT TABLE_NAME FROM information_schema.TABLES WHERE TABLE_TYPE='BASE TABLE'"); $tables = $query->fetchAll(PDO::FETCH_COLUMN); if (empty($tables)) { echo "

There are no tables in database \"{$database}\".

"; } else { echo "

Database \"{$database}\" has the following tables:

"; echo "
    "; foreach ($tables as $table) { echo "
  • {$table}
  • "; } echo "
"; } ?> ``` Save and close the file, then launch the container with the following command: ``` cd ~/docker-project docker-compose up -d ``` Verify all running containers with the following command: ``` docker ps -a ``` You should see the following output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES d3e82747fe0d mysql:5.7 "docker-entrypoint.s…" 39 seconds ago Up 38 seconds 3306/tcp, 33060/tcp mysql-container 606320e5a7f8 mysql:5.7 "docker-entrypoint.s…" 41 seconds ago Exited (0) 39 seconds ago mysql-data-container ca4f63797d11 docker-project_php "docker-php-entrypoi…" 2 hours ago Up 2 hours 9000/tcp php-container 849315c7ffc0 docker-project_nginx "/docker-entrypoint.…" 2 hours ago Up 2 hours 0.0.0.0:80->80/tcp, :::80->80/tcp nginx-container fbca95944234 php:7.0-fpm "docker-php-entrypoi…" 2 hours ago Exited (0) 39 seconds ago app-data-container ``` ## Step 7 – Verify Database Connection Now, open your web browser and access the web page at **http://your-server-ip**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/04/p4-1.png) As you can see, there are no tables in the mydb database. However, there are, in fact, some tables that are not visible to a regular user. If you want to see them, edit the index.php file and change**$user** to **“root”** and **$password** to **“secret.”** ``` nano ~/docker-project/www/html/index.php ``` Change the following line: ``` $user = "root"; $password = "secret"; ``` Save and close the file, then refresh the page. You should see the database with all tables on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/04/p5-1-1024x610.png) ## Conclusion In the above guide, you learned how to deploy a PHP application with Nginx and MySQL using Docker and Docker Compose. You should now be able to host the PHP application in the production environment with Docker; try it on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net. --- # How to Use the id Command in Linux > URL: https://www.atlantic.net/vps-hosting/how-to-use-the-id-command-in-linux/ | Published: 2021-05-16 | Updated: 2024-06-01 | Author: Hitesh Jethva The id command is a basic Linux command used to confirm the identity of a specified Linux user. It is also used to find user and group names, along with the UID and GID of any user in Linux. By default, the id command is available in all the Linux operating systems. In this post, we will show you how to use the id command in Linux. ## Basic Syntax The basic syntax to use the id command is shown below: ``` id [OPTIONS] [USERNAME] ``` You can print all options with the following command: ``` id --help ``` You should see the following output: ``` Usage: id [OPTION]... [USERNAME] Print user and group information for the specified USERNAME, or (when USERNAME omitted) for the current user. -a ignore, for compatibility with other versions -Z, --context print only the security context of the current user -g, --group print only the effective group ID -G, --groups print all group IDs -n, --name print a name instead of a number, for -ugG -r, --real print the real ID instead of the effective ID, with -ugG -u, --user print only the effective user ID --help display this help and exit --version output version information and exit ``` ## How to Use id Command Running the id command without any option will print the information about the current login user: ``` id ``` You should see the following output: ``` uid=1000(username) gid=1000(username) groups=1000(username),4(adm),24(cdrom),27(sudo),30(dip),46(plugdev),108(lpadmin),124(sambashare),125(vboxusers) ``` **To print only the UID of a specific user, run the following command:** ``` id -u username ``` Output: ``` 1000 ``` **To print only the GID of a specific user, run the following command:** ``` id -g username ``` Output: ``` 1000 ``` **To print the UID and GID of a specific user, run the following command:** ``` id username ``` Output: ``` uid=1000(username) gid=1000(username) groups=1000(username),4(adm),24(cdrom),27(sudo),30(dip),46(plugdev),108(lpadmin),124(sambashare),125(vboxusers) ``` **To print the IDs of all other groups the user belongs to, run the following command:** ``` id -G username ``` Output: ``` 1000 4 24 27 30 46 108 124 125 ``` **To print a name instead of the ID, run the following command:** ``` id -nG username ``` Output: ``` username adm cdrom sudo dip plugdev lpadmin sambashare vboxusers ``` **To display real id instead of effective id, use the -r option:** ``` id -r -u username ``` Output: ``` 1000 ``` Or ``` id -r -g username ``` Output: ``` 1000 ``` Or ``` id -r -G username ``` Output: ``` 1000 4 24 27 30 46 108 124 125 ``` ## Conclusion In the above guide, you learned how to use the id command to find user and group id in Linux. This command is useful when your application needs UID or GID to be run; give it a try on your Atlantic.Net [VPS](https://www.atlantic.net/vps-hosting/). --- # Guide to Choosing the Right HIPAA Platform for Your New App > URL: https://www.atlantic.net/hipaa-compliant-hosting/guide-to-choosing-the-right-hipaa-platform-for-your-new-app/ | Published: 2021-05-17 | Updated: 2025-10-21 | Author: Dr. Rachael Bailey Online communication in healthcare is rapidly expanding, largely due to the effects of the current global pandemic. Patients are increasingly reliant on web communication tools and healthcare apps to stay in contact with their physicians and manage their health and wellbeing. With demand growing, our attention must be directed to making sure that healthcare apps protect the integrity of sensitive patient data. In this article, we discuss what you should be considering when choosing a suitable HIPAA platform to ensure that your new healthcare app complies with HIPAA regulations. ## What Is HIPAA Compliance? The Health Insurance Portability and Accountability Act (HIPAA), a US federal law, was enacted in 1996 and documents standards for the safety and security of protected health information (PHI). Both Covered Entities and their Business Associates should adhere to the regulations laid out in HIPAA legislation. The two key sections of [HIPAA law are the Privacy Rule and the Security Rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/). The Privacy Rule establishes the guidelines for protecting all forms of patient information, while the Security Rule focuses on the protection of electronic PHI (ePHI). It is crucial that healthcare organizations understand and implement HIPAA guidelines, as failure to comply with the legislation can lead to costly penalties. ## Should Your App Be HIPAA-Compliant? When designing a new healthcare app, you must carefully consider whether it needs to comply with HIPAA regulations. In a nutshell, if your app manages, stores, or discloses PHI, or has the capacity to do so, it should be HIPAA-compliant. PHI includes any data that is personally identifiable, such as medical records and results, demographic information, and billing information. If your app will only be used for non-identifiable information, such as calories burnt or resting heartbeat then it would not fall under the scope of HIPAA compliance; however, if you tie that calories burnt data to a user, then it will become PHI. ## Choosing a HIPAA-Compliant Platform As an app developer, you should thoroughly vet any potential third parties before partnering with them. It is imperative that your chosen hosting provider can ensure that you remain fully compliant with HIPAA regulations and that your ePHI is adequately safeguarded, so take your time and choose wisely. Here, we have summed up some of the factors that you should consider as you search for a suitable HIPAA-compliant platform: ### 1. Check out the infrastructure interoperability Interoperability is of great importance within the health sector, as patients, physicians, and health insurance providers must have the capacity to share health information. An increasing number of healthcare organizations are adopting [HIPAA-compliant cloud infrastructure](https://www.atlantic.net/hipaa-compliant-hosting/) to optimize the interoperability between different systems and enhance data sharing. The COVID-19 pandemic has highlighted the importance of interoperability within the health system as remote data sharing holds more value than ever before. ### 2. Obtain a signed Business Associate Agreement (BAA) Any third-party service provider must offer you a signed BAA to ensure HIPAA compliance. When outsourcing your infrastructure to a hosting provider, you need to be confident that they will implement and maintain the necessary safeguards to ensure that your app is fully compliant. A signed BAA offers you the reassurance that your chosen service provider is dedicated to your compliance needs, detailing how they will ensure the safe handling of ePHI. ### 3. Ensure implementation of adequate access controls and encryption A good HIPAA-compliant platform will adopt a security-first approach, implementing the necessary safeguards to protect the integrity of patient data. Choose a platform that offers effective physical and technical safeguards, including 24×7 monitoring, data encryption, CCTV, access controls, and [Intrusion Detection Systems](https://www.atlantic.net/managed-services/intrusion-detection-service/). ### 4. Assess the efficacy of internal risk assessments Regular internal risk assessments are an important aspect of HIPAA compliance. These checks enable HIPAA hosting providers to identify any vulnerabilities within your cloud environment that may risk the integrity of ePHI. Given the rapid evolution of cybersecurity, risk assessments should be completed annually at a minimum. ### 5. Find out more about their compliance standards When choosing a suitable cloud hosting provider, be sure to choose one that has been fully certified and audited by an independent third party. External audits ensure that a hosting provider’s processes, policies, and facilities comply fully with HIPAA standards. HITECH certification ensures that service providers are complying with the policies and procedures documented in the HITECH act regarding the integrity of Electronic Health Record (EHR) information. You should also inquire about Service Organization Control (SOC) audits. This examines the use of internal controls and implementation of AICPA best practices, looking at physical security, availability, processing, integrity, confidentiality, and privacy. ### 6. Consider using a managed service As the health sector faces unprecedented strain, healthcare providers find themselves stretched and extremely busy. A Managed Service Provider can ease some of the strain on healthcare providers and maximize the time that they can spend with their patients. By outsourcing the management of your infrastructure, you can leave the stresses and complexities of data protection in the capable hands of the experts! ## How Can Atlantic.Net Help? Atlantic.Net hosts a multitude of web applications for our clients, and we have a number of services available to speed up your deployment. We have one-click apps available that launch in less than 30 seconds. Need cloud storage to host your app? Why not spin up your own private nextcloud host! And for a jump start to your app, we have offer one-click LEMP, LAMP, Docker, and even cPanel or WordPress, if needed, to round out the hosting environment around your new app, all of which can be protected by Atlantic.Net’s managed services such as Managed Firewall, Intrusion Detection Service, Multi-Factor Authentication, and more. As an award-winning web and cloud hosting provider, Atlantic.Net has over 30 years of industry-leading experience. We provide [HIPAA-compliant](https://www.atlantic.net/hipaa-compliant-hosting/), dedicated, managed, and cloud hosting solutions to an extensive list of leading healthcare clients. We are independently audited and certified by a third-party auditing firm, fulfilling HIPAA, HITECH,  SOC 2, and SOC 3 requirements while exceeding PCI-DSS, GDPR, and CCPA compliance. Atlantic.Net will sign a BAA detailing our contractual obligations regarding the safety and security of PHI. Our HIPAA-compliant cloud hosting solution offers an encrypted VPN, 100% uptime guarantee, fully managed firewall solutions, Certified Data Centers providing state-of-the-art redundant systems, power, and physical security, as well as our industry-leading experience in surpassing compliance and security standards. If you are looking for a suitable HIPAA platform for your new app, then look no further! [Contact our team today](https://www.atlantic.net/) to find out how we can help you to host and maintain your fully HIPAA-compliant app. --- # Atlantic.Net, Inc. Named Winner of the Coveted Global InfoSec Awards during RSA Conference 2021 > URL: https://www.atlantic.net/announcements/atlantic-net-inc-named-winner-of-the-coveted-global-infosec-awards-during-rsa-conference-2021/ | Published: 2021-05-18 | Updated: 2025-09-19 | Author: Alexander Wise We are pleased to be recognized for our Healthcare HIPAA Compliant Hosting at the coveted Global InfoSec Awards during this year’s RSA annual conference. We have won the “Cutting Edge in Compliance” award from Cyber Defense Magazine (CDM), the industry’s leading electronic information security magazine. ![](https://www.atlantic.net/wp-content/uploads/2021/05/Global-InfoSec-Awards-for-2021-Winner-300x242.png) “Atlantic.Net’s Healthcare HIPAA Compliant Hosting embodies major features we judges look for to become winners: Meeting the regulatory compliance requirements for healthcare, providing a comprehensive cybersecurity solution, and innovating in unexpected ways that can help offset cybersecurity threats,” said Gary S. Miliefsky, Publisher of Cyber Defense Magazine. Atlantic.Net is absolutely worthy of this award and consideration for the deployment of your data,” said Gary S. Miliefsky, Publisher of Cyber Defense Magazine. This is Cyber Defense Magazine’s ninth year of honoring global InfoSec innovators. The submission requirements allow for any startup, early-stage, later-stage, or public companies in the INFORMATION SECURITY (INFOSEC) space who believe they have a unique and compelling value proposition for their product or service. We are truly excited to be awarded the prestigious award and we look forward to continuing to provide top-notch HIPAA Compliant Hosting services to our clients, backed by our world-class infrastructure and always available expert support. We’re thrilled to be a member of this coveted group of winners, located here:   [http://www.cyberdefenseawards.com/](https://cyberdefenseawards.com/global-infosec-awards-for-2021-winners-by-company-a-z/) --- # Atlantic.Net, Inc. Named Winner of the Coveted Global InfoSec Awards during RSA Conference 2021 > URL: https://www.atlantic.net/press-releases/atlantic-net-inc-named-winner-of-the-coveted-global-infosec-awards-during-rsa-conference-2021/ | Published: 2021-05-18 | Updated: 2024-06-11 | Author: Editorial Team **Atlantic.Net, Inc. Wins Cutting Edge in Compliance in 9th Annual Global InfoSec Awards at #RSAC 2021** **ORLANDO, FLA. (May 18, 2021)**– Atlantic.Net is the proud winner of the Cutting Edge in Compliance award from Cyber Defense Magazine (CDM), the industry’s leading electronic information security magazine. “We’re thrilled to receive one of the most prestigious and coveted cybersecurity awards in the world from Cyber Defense Magazine. We knew the competition would be tough and with top judges who are leading infosec experts from around the globe, we couldn’t be more pleased,” said Marty Puranik of Atlantic.Net, Inc. “Atlantic.Net’s Healthcare HIPAA Compliant Hosting embodies major features we judges look for to become winners: Meeting the regulatory compliance requirements for healthcare, providing a comprehensive cybersecurity solution, and innovating in unexpected ways that can help offset cybersecurity threats,” said Gary S. Miliefsky, Publisher of Cyber Defense Magazine. Atlantic.Net is absolutely worthy of this award and consideration for the deployment of your data,” said Gary S. Miliefsky, Publisher of Cyber Defense Magazine. We’re thrilled to be a member on this coveted group of winners, located here: [http://www.cyberdefenseawards.com/](https://cyberdefenseawards.com/global-infosec-awards-for-2021-winners-by-company-a-z/) About Atlantic.Net Atlantic.Net is a global cloud services provider with over 25 years of experience, serving thousands of developers and small, medium, and large clients in more than one hundred countries. Atlantic.Net specializes in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions and has served dynamic business clients including Lenovo, Newegg, NASA, and Hilton, among others. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions, backed by 24/7/365 support in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. For more information, please visit [Atlantic Net](https://www.atlantic.net/). About CDM InfoSec Awards This is Cyber Defense Magazine’s ninth year of honoring global InfoSec innovators. Our submission requirements are for any startup, early stage, later stage, or public companies in the INFORMATION SECURITY (INFOSEC) space who believe they have a unique and compelling value proposition for their product or service. About the Judging The judges are CISSP, FMDHS, CEH, certified security professionals who voted based on their independent review of the company submitted materials on the website of each submission including but not limited to data sheets, white papers, product literature, and other market variables. CDM has a flexible philosophy to find more innovative players with new and unique technologies, than the one with the most customers or money in the bank. CDM is always asking “What’s Next?” so we are looking for Next Generation InfoSec Solutions. About Cyber Defense Magazine With over 5 Million monthly readers and growing, and thousands of pages of searchable online infosec content, Cyber Defense Magazine is the premier source of IT Security information for B2B and B2G with our sister magazine Cyber Security Magazine for B2C. We are managed and published by and for ethical, honest, passionate information security professionals. Our mission is to share cutting-edge knowledge, real-world stories and awards on the best ideas, products and services in the information technology industry. We deliver electronic magazines every month online for free, and special editions exclusively for the RSA Conferences. CDM is a proud member of the Cyber Defense Media Group. Learn more about us at [https://www.cyberdefensemagazine.com](https://www.cyberdefensemagazine.com/). ### Contact: Email: pr@atlantic.net Ph: 321- 206-1371 CDM Media Inquiries: Contact: April Palanca, Director of Marketing Email: marketing@cyberdefensemagazine.com Toll Free (USA): 1-833-844-9468 International: 1-646-586-9545 Website: www.cyberdefensemagazine.com --- # How to Manage a Swap Partition in Linux > URL: https://www.atlantic.net/vps-hosting/how-to-manage-a-swap-partition-in-linux/ | Published: 2021-05-19 | Updated: 2023-11-18 | Author: Hitesh Jethva Swap is a physical space on the disk that is used when the system RAM is full. When the memory usage in a system exceeds the available RAM, the kernel will move the idle page to the swap memory. Swap space can be created on a separate partition or a swap file. If your server is running on a VPS and a swap partition is not present, then you will need to create a swap file. In this post, we will show how to create and manage a swap space on Linux. ## Step 1 – Verify Swap Partition Before starting, you will need to check whether Swap is enabled or not in your system. You can check it with the following command: ``` swapon --show ``` If the output is empty that means there is not any swap space active in your system. ## Step 2 – Create a Swap File As you can see, there is not any swap space active in your system. So you will need to create a new swap file to your system. First, create a swap file with size 4GB using the following command: ``` dd if=/dev/zero of=/swapfile bs=4096 count=1048576 ``` You should see the following output: ``` 1048576+0 records in 1048576+0 records out 4294967296 bytes (4.3 GB, 4.0 GiB) copied, 9.47796 s, 453 MB/s ``` Next, set the correct permission on swapfile with the following command: ``` chmod 600 /swapfile ``` Next, create a swap area on the swapfile with the following command: ``` mkswap /swapfile ``` Output: ``` Setting up swapspace version 1, size = 4 GiB (4294963200 bytes) no label, UUID=035ada64-2c1a-407d-9f1a-c0dd02b8dcd4 ``` Next, activate the swap space using the following command: ``` swapon /swapfile ``` The above command will activate the swap space temporarily. To set up it permanently, edit the /etc/fstab file: ``` nano /etc/fstab ``` Add the following line: ``` /swapfile swap swap defaults 0 0 ``` ``` Save and close the file then verify the swap partition with the following command: ``` ``` swapon --show ``` You should see the following output: ``` NAME TYPE SIZE USED PRIO /swapfile file 4G 0B -2 ``` ## Step 3 – Check Swap Usage To check the Swap usage information, run the following command: ``` free -m ``` You should see the following output: ``` total used free shared buff/cache available Mem: 1987 74 69 0 1843 1745 Swap: 4095 0 4095 ``` You can also check it with the following command: ``` cat /proc/swaps ``` You should see the following output: ``` Filename Type Size Used Priority /swapfile file 4194300 0 -2 ``` You can also use the top command to check the swap usage in real-time: ``` top ``` You should see the following output: ``` Tasks: 84 total, 1 running, 83 sleeping, 0 stopped, 0 zombie %Cpu(s): 5.9 us, 5.9 sy, 0.0 ni, 88.2 id, 0.0 wa, 0.0 hi, 0.0 si, 0.0 st MiB Mem : 1987.7 total, 68.0 free, 74.8 used, 1844.9 buff/cache MiB Swap: 4096.0 total, 4096.0 free, 0.0 used. 1745.5 avail Mem ``` You can also use the vmstat command to check the swap usage: ``` vmstat 2 6 ``` You should see the following output: ``` procs -----------memory---------- ---swap-- -----io---- -system-- ------cpu----- r b swpd free buff cache si so bi bo in cs us sy id wa st 3 0 0 69356 12096 1877228 0 0 35 652 31 59 0 0 99 0 0 0 0 0 69420 12096 1877228 0 0 0 0 24 42 0 0 100 0 0 0 0 0 69388 12096 1877228 0 0 0 0 22 40 0 0 100 0 0 ``` ## Step 4 – Remove a Swap Space In order to remove the swap space, you will need to deactivate the swap space first. You can do it with the following command: ``` swapoff -v /swapfile ``` Next, edit the /etc/fstab file and remove the following line: ``` nano /etc/fstab ``` Remove the following line: ``` /swapfile swap swap defaults 0 0 ``` Next, remove the swap file using the following command: ``` rm -rf /swapfile ``` Next, verify whether the swap space is removed or not with the following command: ``` swapon --show ``` ## Conclusion In the above guide, you learned how to check and create a swap space on Linux. You also learned how to monitor the swap space with different commands. Get started today with your [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # Misconceptions About “Cloud” and What to Ask Your Cloud Providers > URL: https://www.atlantic.net/vps-hosting/misconceptions-about-cloud-and-what-to-ask-your-cloud-providers/ | Published: 2021-05-20 | Updated: 2025-09-19 | Author: Richard Bailey If you are starting your cloud journey, you may be unclear about what cloud computing is, what it does, what comes standard as part of cloud hosting, and what doesn’t! It’s quite likely that you have been bombarded with misinformation and technical terminology that you simply have no interest in. Yes, you want to assess your options before committing; yes, you will have researched potential cloud providers; however, it’s quite likely you will have misconceptions about cloud computing. Atlantic.Net is here to set the record straight, giving you the required information to make an informed decision about which cloud provider works best for you. Our team gets asked many questions about cloud technology, so we have produced this Q&A to answer some of the misconceptions we witness in the industry. ## Are All Cloud Providers the Same? This misconception may ring true for hyper-scale cloud providers, and it is fair to say that most providers offer a similar range of core services, such as virtual private servers, storage, and networking. But look closer and you will see the industry has many diverse providers; some providers focus on affordability, others focus on compliance, while still others focus on Machine Learning, Cryptocurrency, and Blockchain. Atlantic.Net is world-famous for our security and compliance in Cloud that covers PCI-DSS and HIPAA compliant healthcare hosting, but like all the other providers, we offer so much more. ## What Is the Redundancy Level of the Cloud? Another common misconception is that most people think that the cloud never goes down and that uptime is 24x7x365 when referenced as 100% uptime. While it is true that cloud computing is extremely reliable, inevitably downtime does happen. A lot depends on how well architected your solution is, applications need to be designed to be resilient to transient failure. All of the hyper-scale providers have experienced big outages in recent years, resulting in large swaths of the Internet going offline. Atlantic.Net offers a 100% uptime guarantee, but like all providers, there are times when we must complete mandatory maintenance tasks to keep the service running in a security-defined, high-performing platform. Atlantic.Net provides RAID for all cloud-based turnaround one-time systems including VPS, Cloud Servers, and Dedicated Hosts, while some other cloud providers do not provide RAID.  If a drive fails, you will lose the data on that host, but not on Atlantic.Net.  Atlantic.Net also provides redundant Internet uplinks, redundant data center power systems, redundant cooling systems, and redundant server uplinks and power.  We take the extra steps that others do not to help provide as close to 100% uptime as possible. ## Do I Need to Do Anything to Ensure I Hit My Uptime Goals? Similar to redundancy level misconceptions, some users may assume that the service will never go down and that nothing has to be done to achieve 100% uptime. This is incorrect. Cloud solutions need to be built to withstand failure. Instead of having everything running on one server, split your application up between many servers, preferably in multiple locations. Consider enabling backups and replication. Consider creating snapshots of your servers and copying them to alternative locations. Consider managed service add-ons such as disaster recovery, managed backups, business continuity, and monitoring capabilities for your servers. Atlantic.Net can help with having engineers review your cloud environment design, pairing them with your risk analysis to ensure that a properly designed environment will be able to meet and exceed your uptime requirements. ## Do I Need Disaster Recovery? Have you considered disaster recovery? DR is a technical and administrative service that ensures the continuity of technical services. Disasters are rare, but they do happen. Floods, terrorism, and tornadoes, to name just a few, can wipe out a data center, so what happens to all your servers? With a disaster recovery solution, your services can be brought up in a secondary location, typically in a controlled process. DR is a mandatory requirement for some heavily regulated industries, such as parts of the US healthcare system. ## What Is Included When I Get a Cloud Server? When you purchase a Cloud Server, you get the CPU, Disk, and Memory resources you are paying for. You get the licenses for the Operating System (if applicable), network access (both private and public). Some think backups are included as standard, but this is not true. Some think a managed firewall is included: also not true. And unfortunately, some think that the cloud provider will manage the day-to-day operations for you on that server. Again, this is not true – you will need to manage your server or purchase a managed service option.  We press newcomers to Cloud to ask questions and not assume that something they require is included. Chances are someone like Atlantic.Net does offer the service you are looking for, but it might need to be an add-on and not a standard to the cloud server. ## When I Put My Data in the Cloud, That Just Goes to All Your Locations Automatically, Right? No, this is incorrect. Your data is stored in the service you chose, which is contained in the region that your instance is created. Say you purchased a cloud server in San Francisco, California. Your data will remain in the same data center in the same location. It will also be subject to California and United States legislative restrictions, such as CCPA. To make your data available in multiple regions, you must enable storage replication. Replication creates a 1:1 copy of your data. This is a feature that practically every cloud provider has, and it will copy your data (automatically) from Region A to Region B. ## I Am Compliant If My Cloud Provider Is Compliant, Right? This misconception is a big one; just because your cloud provider is compliant with some legal standard doesn’t necessarily mean you are compliant immediately. Careful consideration must be given to your legal requirements. Take HIPAA Compliance, for example. Atlantic.Net is a HIPAA compliant and HIPAA audited business, and when we onboard new healthcare customers there are some extra steps needed to make sure they are HIPAA compliant too. It might be the signing of a business associate agreement, or a requirement to have Protected Health Information redacted for a public-facing website. Be mindful that your company usually has to take additional steps to ensure your company is meeting all compliance requirements around a cloud environment AND their company business practices. ## The Cloud Is Expensive. Can I Do It Cheaper Myself? Many users may think that cloud computing is too expensive and that they could do it cheaper themselves. In nearly every scenario possible, this is a misconception. The costs of building a data center, heating, cooling, and powering the data center are astronomical. Also consider the network provider uplink costs and all the costs associated with administering the platform, not to mention the cost of servers, storage and network equipment, building utilities, staff wages, audit costs, and so on. Oh, and then multiply this by at least two so you have some form of business continuity. ## Is Technical Support Included for Free? It is true that most providers have some layer of free technical support. Take Atlantic.Net for example; we have phone and email support available 24x7x365 to our cloud platform customers. However, there is a line drawn between free and premium support. Premium support is a technical service provided within a service level agreement. I’m sure if you have ever had to call on Microsoft Azure technical support, you know that the turnaround is very slow and their help can be underwhelming. With Atlantic.Net, you can utilize the standard support or opt for Server Management, which takes the scope of support to the next level. Atlantic.Net also offers Professional Service Agreements (PSAs) for one time projects or issues that fall outside of the scope of support and will be billed on an hourly basis. ## Do Azure, AWS, and Google Cloud Never Go Down? This is another misconception. All cloud providers have technical issues. It is the nature of the industry that if something breaks, there is a possibility for an outage. Only last November, a [huge outage hit AWS](https://www.theverge.com/2020/11/25/21719396/amazon-web-services-aws-outage-down-internet) that knocked out a large number of high-profile customer solutions. Google is not immune either. [Check out their outage history the last 365 days](https://status.cloud.google.com/summary)! What is important is that businesses plan and create solutions that are resistant to failure. ## I Don’t Need Backups Since My Servers Are in the Cloud, Right? Backups should still be a critical part of your IT strategy. Backups are the cornerstone of protecting files, folders, databases, and systems. If you upgrade your webservers version of WordPress or PHP, you can roll back to a backup or snapshot if it breaks your website. You can protect all your critical files, restore older versions of the same file, protect your databases, and so on. ## Does the Location of My Cloud Server Matter? It’s a small world in cloud computing. Regions are availability zones that are connected using superfast network connections, but in the real world, location is very important. Think of the end-user; if you have a user in Germany and your server is in Toronto, there will be a certain amount of latency between the two. If you moved your server to London, the latency would be much lower. If a user is on a cell device, latency matters even more! It’s important to consider local laws and legislation when selecting a location for your server; you should ask yourself whether your data is allowed in a foreign country where you intend to host it. ## How Can Atlantic.Net Help? As an award-winning web and [VPS hosting](https://www.atlantic.net/vps-hosting/) provider, Atlantic.Net has over 30 years of industry-leading experience. We provide HIPAA-compliant, dedicated, managed, and cloud hosting solutions to an extensive list of leading healthcare clients. We are independently audited and certified by a third-party auditing firm, fulfilling HIPAA, HITECH, and SOC requirements. Atlantic.Net also exceeds PCI-DSS, CCPA, and GDPR requirements. Atlantic.Net will sign a BAA detailing our contractual obligations regarding the safety and security of PHI. Our HIPAA-compliant cloud hosting solution offers an encrypted VPN, 100% uptime guarantee, fully managed firewall solutions, Certified Data Centers providing state-of-the-art redundant systems, power, and physical security, as well as our industry-leading experience in surpassing compliance and security standards. If you are looking for a suitable platform for your new cloud service, then look no further than Atlantic.Net! [Contact our team today](https://www.atlantic.net/), we can even help you to host and maintain a fully HIPAA-compliant solution. --- # What’s the Difference Between HDDs, SATA SSDs, and NVMe SSDs? – Beginner > URL: https://www.atlantic.net/dedicated-server-hosting/whats-the-difference-between-hdds-sata-ssds-and-nvme-ssds/ | Published: 2021-05-22 | Updated: 2025-09-19 | Author: Alexander Wise A very important but sometimes neglected aspect of a hosted website is the infrastructure on which it is built. No matter what degree of virtualization is used to construct your web server, it is supported with physical components such as CPUs, networking cables, and storage devices. Data needs to be stored on a storage medium such as a hard disk drive (HDD) or a solid-state drive (SSD). The equipment used to provide a website may not be evident to the customer or end-user; however, the hardware is meticulously selected for certain key reasons. In some cases, the server design may be just the way the client likes it or specially designed for a certain piece of software. With other scenarios like mainstream web hosting, it is irrelevant to these customers how the systems are implemented as long as they perform up to expectations. They may not be interested in what type of drives are used in the storage arrays that hold their data. This article is for readers interested in the differences between the various types of storage drives that may be used by your hosting provider. It’s also good for anyone wanting a little in-depth information about how data is stored on your website or even on your laptop. ## Comparing HDDs and SSDs Let’s look at the [differences between HDDs and SSDs](https://www.pcmag.com/news/ssd-vs-hdd-whats-the-difference). While both types of devices store and provide access to data resources, they do it in very different ways. ### ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_physical-construction-e1622485926432.png)Physical Construction HDDs are a legacy storage solution that makes use of spinning disks that store data magnetically. Mechanical arms, similar to those of a record-playing turntable, are used to position read and write heads over the disk to transfer data. SSDs do not have moving parts and store data in flash memory cells. The lack of moving parts is responsible for the majority of the other differences in the two types of storage devices. ### ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_speed.png)Speed SSDs offer better read/write speeds than HDDs for two main reasons. The first is the time spent moving the mechanical parts to access or write data on HDDs that is not necessary with the flash memory of SSDs. The second reason is the degraded speed caused by file fragmentation that affects HDDs but not SDDs. If you have ever forgotten to “defrag” your Windows XP or Windows 7 system, you will know what it is like when your file system is fragmented across your drive and loading times seem to get longer and longer.  With SSDs, TRIM is built-in along with garbage collection, which takes care of all these issues hand-in-hand with your operating system of choice. ### ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_capacity.png)Capacity HDDs for the consumer market are available with greater capacity than SSDs. Large HHDs designed for enterprise use can reach 18 TB in capacity or more. SSDs intended for the consumer market are usually 4 TB or less, though Nimbus does make a [100 TB SSD drive](https://hexus.net/tech/news/storage/144040-nimbus-data-shares-pricing-50tb-100tb-exadrive-ssds/) that will only set you back $40,000.  For consumers, enterprises, or hosting providers, the criteria of capacity and which drive to select remains the same.  If you require to just back up data, the slower spinning HDD will be an ideal choice.  For larger data sets in a database or possibly your PC gaming system then you would opt for the faster SSD to cut down on loading times. ### ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_durability-and-reliability.png)Durability and Reliability The lack of moving parts makes SSDs more durable and able to withstand a level of physical misuse that cannot be matched by HDDs. Dropping an HDD will probably damage it since the metal platter inside is spinning from 5400 RPMs to 10,000 RPMs and the drop will have the reading head hit the platter on occasion.  This will cause damage up to destroying the HDD. An SDD can handle a little rough treatment without any performance degradation. This characteristic, combined with their smaller form factor, is why SSDs are so popular for supplying storage space in laptops, cellphones, action cameras, etc. ### ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_energy-e1622486003570.png)Noise and Energy Use HDDs make more noise and consume more energy than SSDs. This again is due to the mechanical moving parts associated with hard disk drives. High-performing HDDS may make even more noise than slower models since they are spinning faster.  Think of your gas-powered car when it is idling vs when you are at a higher RPM; the engine will make even more noise the faster it goes. SSDs operate silently and use less energy, extending the battery life of laptops and mobile devices. For a fair comparison, an SSD can be likened to a Tesla electric car since there is no loud gas engine that makes noise as it spins.  It is much quieter and is more efficient overall. ### ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_lifespan-and-recoverability-e1622486025947.png)Lifespan and Recoverability Both SSDs and HDDs will wear out over time. The mechanical components of an HDD can fail, and each flash memory cell in an SSD can only be written to and erased a limited number of times. Some data recovery techniques are only possible using the remnants of files left on an HDD and while the same can be said for SSDs, it is much more difficult since the failures are not mechanical like an HDD but rather corruption in the data will start to occur.  There are different levels of both HDD and SSD for consumers, pros, and enterprises, so if you require a higher level of endurance and lifespan then the extra cost of a higher level drive will be worth it. ### ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_form-e1622486095791.png)Form Factor Due to the necessity of providing room for its moving parts, HDDs are limited in how small they can be designed. The most common form factors are 2.5-inch drives and 3.5-inch drives. SSDs are not constrained by this design limitation and can be made much smaller than HDDs. This fact makes SSDs the logical storage choice for mobile devices and any system that needs a custom-built storage requirement.  For SSDs, the common size for laptops are 2.5” or M.2 which is the smaller drive size about the same size as a large thumb. ### ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_cost-e1622486129907.png)Price HDDs are less expensive on a per GB basis than SSDs with the same storage capacity. This is one of the reasons laptops with SSDs cost more than a similarly performing desktop machine that can use HDDs.  This has been changing through the years, and while HDDs still hold the crown for the lowest price, SSD technology is gaining momentum toward price parity between HDDs and SSDs. ## What are the Differences Between SATA SSDs and NVMe SSDs Now we will look at the differences between SATA SSDs and NVMe SSDs. SATA and NVMe refer to the interfaces that connect hosts to SSD drives. The interface governs how data flows between hosts and storage. SATA, which stands for Serial Advanced Technology Attachment, was introduced in 2000 to provide connectivity to the mechanical HDD drives that existed at that time. SATA makes use of the Advanced Host Controller Interface (AHCI) to access data. AHCI features Native Command Queuing (NCQ) which speeds up mechanical drives and enables hot-swapping to be performed. NVMe stands for Non-Volatile Memory Express. It is a host controller interface designed explicitly for PCIe SSDs. NVMe addresses many of the issues associated with using the SATA interface with higher-speed SSD devices. Let’s take a look at the [differences between SATA and NVMe](https://www.enterprisestorageforum.com/hardware/nvme-vs-sata-comparing-storage-technologies/) and how those differences might impact the type of interface that best suits your specific situation. ### ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_compatibility.png)Compatibility A SATA interface can be used with both HDDs and SSDs and is supported by older computers and hosts. NVMe is only used with SSD drives and may not be supported by some older machines. ### ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_speed.png)Performance/Speed There are two distinct differences in how the two interfaces perform. As far as straight speed goes, SATA SSD read speeds top out at about 600 MB/s. The top speed of an NVMe SSD is around 3,500 MB/s. That means the NVMe SSD is almost six times as fast as one connected via SATA. The second aspect of the two interfaces that affects performance is their very different queue depth capacity. SATA uses a single command queue with a capacity to store 32 commands. Conversely, NVMe supports up to 64k queues each of which can contain 64k commands. This fact allows NVMe SSD drives to run multiple threads simultaneously, thereby increasing processing speed. The third which is more important for hosting and enterprises are IOPS.  Input/output operations per second (IOPS) is a key performance matrix for when you are trying to retrieve more than one file at a time.  This comes into play when loading the operating system, a program, or a PC game; in the enterprise world, it would affect the hundreds of users accessing a software program that ties to a large database.  SATA SSDs max out at around 75,000 read IOPS (depending on the drive) while NVMe drives are now pushing over 1,500,000 IOPS on both reads and writes (depending on the drive). ### ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_cost-e1622486129907.png)Price SATA SSD drives are generally less expensive than comparable NVMe devices. When deciding on a disk storage solution, the performance gains available with NVMe drives need to be reconciled with any budgetary concerns that may impact the purchasing decision.  Also, if you are looking to upgrade that old system, chances are your system will support a SATA SSD; you will have to verify whether it will support an NVMe SSD. ### ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_use-cases.png)Use Cases NVMe is preferable for environments that require high-performance data processing and store large amounts of information. Systems that can tolerate slower access slower speeds and perform mostly sequential reads will find SATA satisfactory for their needs. Examples of high-performance systems include the online commerce sites of busy retailers like Walmart. Financial institutions need the ability to execute transactions as quickly as possible and benefit from NVMe technology. Sites hosting purely informational applications can tolerate the slower speeds of SATA devices. Research libraries or data archiving services are examples of sites that can use SATA technology. ## What Disk Storage Solution is Right For My Business? Based on business requirements, either a SATA SSD or NVMe SSD implementation may make the most sense. When engaging with a hosting provider, it is essential that they understand your needs and can provide the necessary infrastructure to fulfill your company’s IT vision. Atlantic.Net offers RAID arrays featuring both of these types of storage devices. Their standard [dedicated host](https://www.atlantic.net/dedicated-server-hosting/) offerings include SATA SSD RAID 1 and RAID 10 storage options as well as an NVMe SSD RAID 10 option. You can also take advantage of Atlantic’s bare metal [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) which allows clients to fully customize their storage environment. Based on the kind of processing your business needs, one type of storage system may make better sense than the other. Understanding the processes that will access the storage system is a critical aspect of making the correct choice. We hope that the information we have provided here helps you decide which type of storage best serves your business. --- # How to Effectively Establish HIPAA and PCI-DSS Regulatory Compliance > URL: https://www.atlantic.net/hipaa-compliant-hosting/how-to-effectively-establish-hipaa-and-pci-dss-regulatory-compliance/ | Published: 2021-05-24 | Updated: 2026-06-17 | Author: Alexander Wise HIPAA and PCI-DSS are two sets of regulatory guidelines that govern the way an organization handles certain types of data. This includes how data is saved, used, and accessed by enterprise information technology (IT) systems. Failure to conform to the appropriate regulations puts data resources at risk and can lead to substantial financial penalties along with long-term negative repercussions to a business’s reputation. When contracting with a web hosting provider, you need to know if you are bound by either or both guidelines and if your vendor offers compliant systems and storage. Fortunately, Atlantic.Net is compliant and audited for HIPAA, HITECH, and PCI-DSS requirements and maintains SOC2 and SOC3 certifications that are performed by a third party to verify Atlantic.Net’s compliance. ## ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_hipaa-and-dss.png)What are HIPAA and PCI -DSS Compliance Standards? These sets of regulatory guidelines were developed to address the needs of two very different industries. The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is focused on protecting the personal data of individuals who interact with healthcare providers. The Payment Card Industry Data Security Standard (PCI-DSS) was designed to protect the information of credit cardholder data. Companies handling health-related data are bound to adhere to HIPAA guidelines. PCI-DSS regulations must be followed by companies processing credit card data. In many cases, both sets of standards may apply to the same company, for example with a healthcare provider that accepts credit card payments. [Compliance with HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) or PCI-DSS guidelines is mandatory for businesses in these industries. There is no opting out, and inadvertent non-compliance is no excuse nor a remedy for potential penalties. Let’s take a look at how these regulations were established. ### ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_hipaa.png)HIPAA The Health Insurance Portability and Accountability Act of 1996 set the original guidelines that organizations need to follow to guard protected health information (PHI) and electronic protected health information (ePHI). The Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 also plays a role in HIPAA IT compliance. [The HIPAA Security Rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/) contains the standards that must be applied to safeguard and protect electronically created, accessed, processed, or stored PHI (ePHI) when at rest and in transit. Some of the following safeguards are required while others are categorized as [addressable](https://www.hhs.gov/hipaa/for-professionals/faq/2020/what-is-the-difference-between-addressable-and-required-implementation-specifications/index.html) to provide for flexibility in implementing the controls. **Technical safeguards** are: - Encrypting data that travels beyond internal firewalls to NIST standards; - Implementing a means of access control for PHI and ePHI; - Introducing audit controls and activity logs to the environment. **Physical safeguards** apply to physical access to ePHI regardless of where it is stored.  Required physical safeguards are: - Implementing policies to protect workstations that access ePHI; - Implementing policies directed at the use of ePHI on mobile devices and its removal when an individual leaves the organization. - Implementing policies that secure where the ePHI is stored and also disposed of in accordance of best practices. **Administrative safeguards** are designed to ensure an organization is taking the proper steps to maintain the privacy and security of ePHI. Required administrative safeguards are: - Conducting risk assessments to determine how ePHI is used and how breaches could occur; - Developing a risk management policy and [HIPAA compliant policies and procedures](https://www.totalhipaa.com/hipaa-compliance-guide-all-your-questions-answered/) that includes sanctions for employees who fail to comply with HIPAA guidelines; - Developing a contingency plan to protect ePHI in case of an emergency; - Restricting third-party access to ePHI. ### ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_pci-dss-e1622487022610.png)PCI-DSS The development of the PCI-DSS standards began through the efforts of founding members American Express, Discover Financial Services, JCB International, MasterCard, and Visa. The group introduced PCI-DSS 1.0 in December of 2004 to address the risks of fraud in the credit card industry. In 2006 the PCI Security Standards Council (PCI SSC) was created and continues to oversee the evolution of the guidelines. There are [12 general steps](https://www.pcisecuritystandards.org/pdfs/pci_ssc_quick_guide.pdf) that may each be comprised of multiple activities required to conform to entry-level [PCI-DSS standards](https://www.atlantic.net/pci-compliant-hosting/). They are: - 1-Install and maintain a firewall to protect cardholder data; - 2-Change all vendor-supplied and default passwords; - 3-Protect stored cardholder data; - 4-Encrypt transmission of cardholder data over open networks; - 5-Deploy and update anti-virus software; - 6-Develop and maintain secure systems; - 7-Restrict access to cardholder data on a need-to-know basis; - 8-Assign a unique ID to all computer users; - 9-Restrict physical access to cardholder data; - 10-Track and monitor access to networks and data; - 11-Regularly test security systems and procedures; - 12-Maintain a policy that addresses data security for [employees and contractors](https://remote.com/blog/international-contractor-vs-employee). ## ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_comparison.png)A Comparison of HIPAA and PCI-DSS While the two sets of regulations are meant for different industries, they share the same core principles related to protecting sensitive data. Here’s an overview of how HIPAA and PCI-DSS compare.![HIPAA Compliance vs. PCI Compliance](https://www.atlantic.net/wp-content/uploads/2021/05/How-to-Effectively-Establish-HIPAA-and-PCI-DSS-Regulatory-Compliance-02-02-e1622652913913.jpg) ## ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_ensure-e1622487061542.png)How to Ensure HIPAA and PCI Compliance A growing number of organizations are required to meet PCI-DSS and HIPAA compliance standards, which means implementing more controls, preparing documentation, and assessment efforts. This can be easily achieved by hiring skilled external auditors that can implement framework mapping to combine PCI and HIPAA compliance efforts, limit assessments to a single scope, and cut out redundant work,” according to[ I.S. Partners](https://www.ispartnersllc.com/blog/pci-dss-compliance-vs-hipaa-compliance/). Organizations can obtain certification from licensed third parties to verify their compliance with HIPAA or PCI-DSS guidelines. This is commonly done via Service Organization Control (SOC) 2 and 3 certifications. ### What is SOC? [SOC reports](https://kirkpatrickprice.com/video/soc-1-vs-soc-2-vs-soc-3/) are internal control reports on the services provided by a service organization. The reports furnish important information to potential customers about the risks of using the outsourced services. - SOC 1 reports concentrate on an enterprise’s controls over financial reporting. Companies operating in the financial services industry rely on SOC 1 reporting. - SOC 2 reports evaluate an organization’s information systems relating to their security, availability, processing integrity, confidentiality, and privacy. These elements are collectively known as the Trust Services Criteria. A SOC 2 report has restricted access and is only used by an organization and the customers that use their systems. - SOC 3 reports also provide information based on the Trust Services Criteria but with a very important difference. SOC 3 reports can be freely distributed and used for marketing purposes to demonstrate the system compliance to prospective clients. ### ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_providers.png)Check with your provider Simply because your chosen web hosting provider offers HIPAA or PCI-DSS complaint system and storage solutions, customers are not automatically compliant with the standards. Most providers, including Atlantic.Net, offer customers multiple hosting options, some of which may not be concerned with the level of security and privacy demanded by HIPAA or PCI-DSS.  These less secure systems would be used for personal websites for example or development work. Make sure you fully understand the certification standing of the hosting package you select and verify that it meets your requirements. As a potential customer, you can have access to SOC 3 reports and certifications that demonstrate the provider’s ability to protect sensitive data. ### ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_audit.png)Third-party audits Providers should use third-party audits to verify to themselves and their customers that they are adhering to the audited standards.  Self-assessments are a good place for organizations to start determining if they are compliant or if changes need to be made to reach that goal. After addressing the issue found in a self-assessment, trained third-party auditors can ensure that standards are being met and supply HIPAA, HITECH, PCI-DSS, SOC 2, or SOC 3 certifications. Having a second set of eyes focused on compliance helps organizations avoid the pitfalls of non-compliance. ### ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_fines.png)Fines for noncompliance Substantial fines can be levied against entities not conforming to the appropriate data handling guidelines. In the case of PCI-DSS, fines can range from $5,000 to $100,000 per month until the noncompliance issue is resolved. HIPAA penalties are determined based on the scope and severity of the data breach. The most severe transgressions can cost an organization $1.5 million per year. There are also potential criminal penalties for using PHI maliciously that can lead to 10 years in prison. ## ![](https://www.atlantic.net/wp-content/uploads/2021/05/icon_why-atlantic.png)Why Choose Atlantic.Net? Contracting with Atlantic.Net for [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) or [PCI-DSS-compliant web hosting](https://www.atlantic.net/pci-compliant-hosting/) gives you peace of mind that your provider knows what they’re doing. Atlantic.Net is SOC 2, SOC 3, HIPAA audited, and [PCI ready](https://www.atlantic.net/pci-compliant-hosting/) and provides customers in the healthcare industry and those who process credit cards with the hardened, secure, and compliant infrastructure they need. They enable clients to effectively maintain HIPAA and PCI-DSS compliance. Learn more about our [HIPAA compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. --- # How to Install WordPress on a CentOS 8 Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-wordpress-centos-8-server/ | Published: 2021-05-25 | Updated: 2026-03-03 | Author: Alexander Wise ##### Verified and Tested 05/19/21 ## Introduction This how-to will show you how to install WordPress on CentOS 8. WordPress started as a blogging system, but now has become a full content management system (CMS). Since WordPress is a free open source program, it has become the most popular CMS on the Web. With thousands of plugins, your website is nearly limitless. ![WordPress Illustration by Walker Cahall](https://www.atlantic.net/wp-content/uploads/2018/01/wordpress1.png) *WordPress Illustration by Walker Cahall* ## Prerequisite – To install WordPress, a CentOS 8 server running LAMP or LEMP is required. ## Install WordPress on CentOS 8 To install WordPress, we are going to start off by setting up the database by running the following commands: ``` mysql -u root -p ``` When prompted, enter your MySQL root password that you set up when installing MySQL. In MySQL, enter the following commands: ``` create database wordpress character set utf8 collate utf8_bin; ``` Make sure you set your own secure password where it says [insert-password-here] ``` grant all privileges on wordpress.* to wordpressuser@localhost identified by '[insert-password-here]'; ``` ``` flush privileges; ``` ``` exit ``` Now that the database is created, we can download the latest version of WordPress with the following command: ``` wget http://wordpress.org/latest.tar.gz ``` Note: if wget is not installed, install it by running the command: ``` yum install wget ``` The latest package will download to the directory you are currently in, with the file name latest.tar.gz. We need to decompress the file by running: ``` tar -xzvf latest.tar.gz ``` Next, we need to copy wp-config-sample.php to wp-config.php which is where WordPress gets its base configuration. To do that run: ``` cp wordpress/wp-config-sample.php wordpress/wp-config.php ``` In your favorite text editor, edit wordpress/wp-config.php For a basic setup, we need to have the following. define(‘DB_NAME’, ‘wordpress’); define(‘DB_USER’, ‘wordpressuser’); define(‘DB_PASSWORD’, ‘[insert-password-here]’); It should look like this when completed: ![Enter DB_USER, DB_PASSWORD, DB_HOST values.](https://www.atlantic.net/wp-content/uploads/2018/01/wordpress2.png) *wp-config.php* Next, we need to move the WordPress folder to your web directory. ``` sudo cp -r ~/wordpress/* /var/www/html ``` We now can go to the WordPress web installation. In your browser go to http://yourhostname-or-ipaddress If you are unsure what you IP address is run the following: ``` ifconfig ``` ![Sample ifconfig](https://www.atlantic.net/wp-content/uploads/2018/01/wordpress3.png) *ifconfig* In our example, we would put http://192.68.0.2/ in the address bar and get the following page.   ![Fill in your sites infromation, username, password and email addressa accordingly.](https://www.atlantic.net/wp-content/uploads/2018/01/wordpress4.png) *Welcome Page* From here all that is needed to do is to follow along with the WordPress install and give the information required. For more information, you may want to check out the [WordPress Codex](https://codex.wordpress.org/). Atlantic.Net offers [VPS hosting](https://www.atlantic.net/vps-hosting/) as well as managed server hosting which include a layer of business-essential managed services to your hosting packages. Contact us today for more information. --- # How to Install MediaWiki on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-mediawiki-ubuntu-20-04/ | Published: 2021-05-26 | Updated: 2026-03-03 | Author: Arnaldo Arrieta MediaWiki is a wiki application written in PHP that the Wikimedia Foundation developed to run several of their projects. The encyclopedia Wikipedia is the most popular of these projects. A wiki is a type of website that allows its users to create and edit content in a collaborative manner. It can be used in several ways, including as a knowledge base, documentation library, community website, or company intranet. These kinds of websites are especially useful in contexts where several people need to create and modify pages in a quick and easy way. This guide will show you how to install and set up the application, giving you the basis to deploy your own wiki site. We will use the domain name “mediawiki.example.com” in this guide. Replace it with the domain name or IP address you have configured on your server. ## Step 1 – Install LAMP Server First, you will need to install the Apache, MariaDB, PHP and other PHP extensions to your server. You can install all of them using the following command: ``` apt-get install apache2 mariadb-server php libapache2-mod-php php-mbstring php-xml php-json php-mysql php-curl php-intl php-gd php-mbstring texlive imagemagick unzip -y ``` Once all the packages are installed, you can proceed to create a database. ## Step 2 – Create a Database Next, login to the MariaDB shell with the following command: ``` mysql ``` Once you are login, create a database and user for MediaWiki with the following command: ``` CREATE DATABASE mediawiki; GRANT ALL PRIVILEGES ON mediawiki.* TO 'wikiuser'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB with the following command: ``` flush privileges; exit; ``` At this point, your MariaDB database is created. ## Step 3 – Download MediaWiki Next, you will need to download the latest version of MediaWiki to the Apache web root directory. You can download it with the following command: ``` wget https://releases.wikimedia.org/mediawiki/1.35/mediawiki-1.35.2.zip ``` Once the download is completed, unzip the downloaded file with the following command: ``` unzip mediawiki-1.35.2.zip ``` Next, move the extracted directory to the Apache web root directory: ``` mv mediawiki-1.35.2 /var/www/html/mediawiki ``` Next, you will need to install Composer in your system. You can install it with the following command: ``` apt-get install composer -y ``` Once the Composer is installed, change the directory to the MediaWiki and install all PHP dependencies using the following command: ``` cd /var/www/html/mediawiki composer install --no-dev ``` Once all the dependencies are installed, set proper permission to the MediaWiki with the following command: ``` chown -R www-data:www-data /var/www/html/mediawiki ``` ## Step 4 – Configure Apache for MediaWiki Next, create an Apache virtual host configuration file for MediaWiki with the following command: ``` nano /etc/apache2/sites-available/mediawiki.conf ``` Add the following lines: ``` ServerAdmin admin@example.com DocumentRoot /var/www/html/mediawiki/ ServerName mediawiki.example.com Options FollowSymLinks AllowOverride All Order allow,deny allow from all ErrorLog /var/log/apache2/mediawiki_error CustomLog /var/log/apache2/mediawiki_access common ``` Save and close the file then enable the virtual host file and restart the Apache service with the following command: ``` a2ensite mediawiki.conf systemctl reload apache2 ``` ## Step 5 – Access MediaWiki Now, open your web browser and access the MediaWiki installation page using the URL **http://mediawiki.example.com**. ![MediaWiki Setup Page](https://www.atlantic.net/wp-content/uploads/2015/09/mediawiki-setup-page-1024x442.png) MediaWiki will now show its version. It will also say “LocalSettings.php not found”. We’ll be creating that file based on the next few steps. Get started by clicking on the link to “**set up the wiki**”. ![MediaWiki Language Selection Page](https://www.atlantic.net/wp-content/uploads/2015/09/mediawiki-language-page-1024x543.png) On this page, you can choose the language for your wiki. Select your preferred options and click “**Continue**”. You should see the following page: ![MediaWiki Terms Page](https://www.atlantic.net/wp-content/uploads/2015/09/mediawiki-terms-page-1024x580.png) At this point, MediaWiki performs several checks before proceeding with the configuration. If all is OK, the message “The environment has been checked. You can install MediaWiki” will appear. Press “**Continue**” to advance to the next step. ![MediaWiki Database Page](https://www.atlantic.net/wp-content/uploads/2015/09/mediawiki-database-page-1024x552.png) Provide your database details and click on the **Continue** button. You should see the following page: ![MediaWiki Database Account Page](https://www.atlantic.net/wp-content/uploads/2015/09/mediawiki-database-installation-1024x472.png) Uncheck “Use the same account as for installation” and click on the **Continue** button. You should see the following page: ![MediaWiki Site Information Page](https://www.atlantic.net/wp-content/uploads/2015/09/mediawiki-site-information.png) Provide your sitename, admin username, password and click on the **Continue** button. You should see the following page: ![MediaWiki Download LocalSettings Page](https://www.atlantic.net/wp-content/uploads/2015/09/mediawiki-download-localsetting-1024x494.png) Now, download the “LocalSettings.php” file to your system and copy it to the **/var/www/html/mediawiki** directory over the SSH. Then, set the correct ownership using the following command: ``` chown www-data:www-data /var/www/html/mediawiki/LocalSettings.php ``` Once you have completed this last step, back in your browser click the “enter your wiki” link. You will be redirected to the MediaWiki dashboard: ![MediaWiki Dashboard Page](https://www.atlantic.net/wp-content/uploads/2015/09/mediawiki-dashboard-1024x449.png) ## More Resources The default main page of your wiki includes several useful links where you can learn more about all the features included with MediaWiki and the ways to use it. An excellent starting point is the MediaWiki [User’s Guide](https://meta.wikimedia.org/wiki/Help:Contents). Thank you for following along this how-to, please check out our other related articles at the bottom of the page. --- # How to Install Matrix Synapse with Nginx and Let’s Encrypt SSL on Debian > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-matrix-synapse-with-nginx-and-lets-encrypt-ssl-on-debian/ | Published: 2021-05-27 | Updated: 2025-09-04 | Author: Hitesh Jethva Synapse is a home server implementation of Matrix written in Python. Matrix is an open standard for real-time communication over IP. IT allows people, services, and devices to easily communicate with each other. Matrix Synapse is a great alternative for applications like Slack, Discord, Rocket.chat, Skype and others. You can access the Matrix server through a web browser or other clients like Riot, bots, and bridges. In this post, we will show you how to deploy Matrix Synapse with Nginx on Debian 12. ## Step 1 – Add Matrix Synapse Repository By default, the Matrix Synapse package is not included in the Debian default repository, so you will need to install it from its official repository. First, download the Matrix Synapse GPG key. ``` wget -O /usr/share/keyrings/matrix-org-archive-keyring.gpg https://packages.matrix.org/debian/matrix-org-archive-keyring.gpg ``` Then, add the Matrix Synapse repository to the APT source file. ``` echo "deb [signed-by=/usr/share/keyrings/matrix-org-archive-keyring.gpg] https://packages.matrix.org/debian/ $(lsb_release -cs) main" | tee /etc/apt/sources.list.d/matrix-org.list ``` Next, update the package index using the following command. ``` apt update -y ``` ## Step 2 – Install Matrix Synapse Now, install the Matrix Synapse package using the following command. ``` apt install matrix-synapse-py3 ``` You will be asked to provide your domain name as shown below: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p1-9.png) Provide your domain name and click on OK. Once Matrix Synapse is installed, start the Matrix Synapse service using the following command. ``` systemctl start matrix-synapse ``` You can now verify the status of Matrix Synapse using the following command. ``` systemctl status matrix-synapse ``` Output. ``` ● matrix-synapse.service - Synapse Matrix homeserver Loaded: loaded (/usr/lib/systemd/system/matrix-synapse.service; enabled; preset: enabled) Active: active (running) since Fri 2025-09-04 06:08:58 UTC; 10s ago Process: 76117 ExecStartPre=/opt/venvs/matrix-synapse/bin/python -m synapse.app.homeserver --config-path=/etc/matrix-synapse/homeserver.yaml --config-path=/etc/mat> Main PID: 76154 (python) Tasks: 8 (limit: 629145) Memory: 97.1M (peak: 98.6M) CPU: 3.994s CGroup: /system.slice/matrix-synapse.service └─76154 /opt/venvs/matrix-synapse/bin/python -m synapse.app.homeserver --config-path=/etc/matrix-synapse/homeserver.yaml --config-path=/etc/matrix-synapse> Sept 04 06:08:55 debian matrix-synapse[76117]: Generating signing key file /etc/matrix-synapse/homeserver.signing.key Sept 04 06:08:57 debian matrix-synapse[76154]: This server is configured to use 'matrix.org' as its trusted key server via the Sept 04 06:08:57 debian matrix-synapse[76154]: 'trusted_key_servers' config option. 'matrix.org' is a good choice for a key Sept 04 06:08:57 debian matrix-synapse[76154]: server since it is long-lived, stable and trusted. However, some admins may Sept 04 06:08:57 debian matrix-synapse[76154]: wish to use another server for this purpose. Sept 04 06:08:57 debian matrix-synapse[76154]: To suppress this warning and continue using 'matrix.org', admins should set Sept 04 06:08:57 debian matrix-synapse[76154]: 'suppress_key_server_warning' to 'true' in homeserver.yaml. Sept 04 06:08:57 debian matrix-synapse[76154]: -------------------------------------------------------------------------------- Sept 04 06:08:57 debian matrix-synapse[76154]: Config is missing macaroon_secret_key Sept 04 06:08:58 debian systemd[1]: Started matrix-synapse.service - Synapse Matrix homeserver. ``` At this point, Matrix Synapse is started and listens on port 8008. You can verify it using the command given below: ``` ss -plnt | grep 8008 ``` Output. ``` LISTEN 0 50 127.0.0.1:8008 0.0.0.0:* users:(("python",pid=2170,fd=14)) LISTEN 0 50 [::1]:8008 [::]:* users:(("python",pid=2170,fd=13)) ``` ## Step 3 – Configure Matrix Synapse First, generate the secret key using the following command. ``` cat /dev/urandom | tr -dc 'a-zA-Z0-9' | fold -w 32 | head -n 1 ``` Output. ``` c4eEv6cZCc1jXeHGbzFyzGB0RFPp2HfP ``` Next, edit the Matrix Synapse main configuration file. ``` nano /etc/matrix-synapse/homeserver.yaml ``` Change the following lines: ``` listeners: - port: 8008 tls: false type: http x_forwarded: true bind_addresses: ['127.0.0.1'] resources: - names: [client, federation] compress: false enable_registration: false registration_shared_secret: "c4eEv6cZCc1jXeHGbzFyzGB0RFPp2HfP" ``` Save and close the file, then restart the Matrix Synapse service to reload the changes. ``` systemctl restart matrix-synapse ``` ## Step 4 – Create an Administrative User Next, you will need to create an admin user to authenticate Matrix Synapse. You can create it using the following command. ``` register_new_matrix_user -c /etc/matrix-synapse/homeserver.yaml http://localhost:8008 ``` Define your user and password as shown below: ``` New user localpart [root]: madmin Password: Confirm password: Make admin [no]: yes Sending registration request... Success! ``` ## Step 5 – Download Let’s Encrypt SSL We will use the Let’s Encrypt SSL to secure the Matrix Synapse server. First, install the Nginx web server. ``` apt install nginx snapd ``` Next, install the Certbot Let’s Encrypt client using the following commands. ``` snap install core ``` ``` snap refresh core ``` ``` snap install --classic certbot ``` ``` ln -s /snap/bin/certbot /usr/bin/certbot ``` Next, download the Let’s Encrypt SSL for your domain. ``` certbot certonly --nginx --agree-tos --no-eff-email --staple-ocsp --preferred-challenges http -m hitjethva@gmail.com -d matrix.linuxbuz.com ``` Next, generate the dhparam using the following command. ``` openssl dhparam -dsaparam -out /etc/ssl/certs/dhparam.pem 4096 ``` ## Step 6 – Configure Nginx for Matrix Synapse Next, you will need to configure Nginx as a reverse proxy for Matrix Synapse. First, edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http{: ``` server_names_hash_bucket_size 64; ``` Next, create an Nginx virtual host configuration file for Matrix Synapse. ``` nano /etc/nginx/conf.d/synapse.conf ``` Add the following configurations. ``` # enforce HTTPS server { # Client port listen 80; server_name matrix.linuxbuz.com; return 301 https://$host$request_uri; } server { server_name matrix.linuxbuz.com; # Client port listen 443 ssl http2; listen [::]:443 ssl http2; # Federation port listen 8448 ssl http2 default_server; listen [::]:8448 ssl http2 default_server; access_log /var/log/nginx/synapse.access.log; error_log /var/log/nginx/synapse.error.log; # TLS configuration ssl_certificate /etc/letsencrypt/live/matrix.linuxbuz.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/matrix.linuxbuz.com/privkey.pem; ssl_trusted_certificate /etc/letsencrypt/live/matrix.linuxbuz.com/chain.pem; ssl_protocols TLSv1.2 TLSv1.3; ssl_prefer_server_ciphers on; ssl_stapling on; ssl_stapling_verify on; ssl_dhparam /etc/ssl/certs/dhparam.pem; location /_matrix { proxy_pass http://localhost:8008; proxy_set_header X-Forwarded-For $remote_addr; # Nginx by default only allows file uploads up to 1M in size # Increase client_max_body_size to match max_upload_size defined in homeserver.yaml client_max_body_size 10M; } } # This is used for Matrix Federation # which is using default TCP port '8448' server { listen 8448 ssl; server_name matrix.linuxbuz.com; ssl_certificate /etc/letsencrypt/live/matrix.linuxbuz.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/matrix.linuxbuz.com/privkey.pem; location / { proxy_pass http://localhost:8008; proxy_set_header X-Forwarded-For $remote_addr; } } ``` Save and close the file, then reload Nginx to apply the changes. ``` systemctl restart nginx ``` ## Step 7 – Access Matrix Synapse You can now verify the Matrix Synapse installation using the URL **https://matrix.linuxbuz.com:8448/_matrix/static/** on your web browser. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p2-7.png) You can also verify your Matrix Synapse using the Riot web-based client **https://riot.im/app/#/login.** You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p3-4.png) Click on the **Edit** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p4-3.png) Provide your Matrix server URL and click on the **Continue** button. You should see the Matrix login page: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p5-3.png) Provide your admin username and password and click on the **Sign in** button. Once you are connected to the Matrix Synapse server. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p6-2.png) ## Conclusion In the above guide, you learned how to install Matrix Synapse server with Nginx and Let’s Encrypt SSL on Debian 12. You can now easily implement your own communication server in the production environment of your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/). --- # How To Setup Local OpenShift Origin (OKD) Cluster on CentOS 7 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-setup-local-openshift-origin-okd-cluster-on-centos-7/ | Published: 2021-05-28 | Updated: 2024-06-02 | Author: Hitesh Jethva OpenShift is an open-source PaaS platform that allows you to deploy an application on the cloud. It supports many programming languages including, Python, PHP, Perl, Node.js, Ruby, and Java. It is extensible so you can add support for other languages. It is specially designed for a high-availability and scalable application platform. It provides an easy way to scale your application as per your demand with zero downtime. It provides a powerful web UI that helps you to monitor container resources, container health, and the IP address of nodes. In this post, we will show you how to set up a local OpenShift Origin (OKD) cluster on CentOS 7. ## Step 1 – Install Docker First, you will need to install Docker on the host system to run the OpenShift container. By default, the latest version of Docker is not included in CentOS 7, so you will need to add the Docker repo to your system. First, install the required dependencies using the following command: ``` yum install yum-utils device-mapper-persistent-data lvm2 -y ``` Once all the dependencies are installed, add a Docker repo with the following command: ``` yum-config-manager --add-repo https://download.docker.com/linux/centos/docker-ce.repo ``` Once the Docker repo is added, you can install the Docker using the following command: ``` yum install docker-ce docker-ce-cli containerd.io -y ``` Once Docker is installed, verify the Docker version with the following command: ``` docker -v ``` Output: ``` Docker version 20.10.5, build 55c4c88 ``` ## Step 2 – Configure Docker Next, you will need to configure the Docker daemon with an insecure registry parameter. First, create required directories using the following command: ``` mkdir /etc/docker /etc/containers ``` Next, create a registry file with the following command: ``` nano /etc/containers/registries.conf ``` Add the following lines: ``` [registries.insecure] registries = ['172.30.0.0/16'] ``` Next, create a daemon file: ``` nano /etc/docker/daemon.json ``` Add the following lines: ``` { "insecure-registries": [ "172.30.0.0/16" ] } ``` Save and close the file, then reload the systemd daemon and start the Docker service with the following command: ``` systemctl daemon-reload systemctl start docker ``` Next, enable the IP forwarding with the following command: ``` echo "net.ipv4.ip_forward = 1" | tee -a /etc/sysctl.conf sysctl -p ``` ## Step 3 – Install OpenShift First, download the latest version of OpenShift with the following command: ``` wget https://github.com/openshift/origin/releases/download/v3.11.0/openshift-origin-client-tools-v3.11.0-0cbc58b-linux-64bit.tar.gz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar xvf openshift-origin-client-tools*.tar.gz ``` Next, change the directory to the extracted directory and copy the required binaries with the following command: ``` cd openshift-origin-client*/ mv oc kubectl /usr/local/bin/ ``` Next, verify the version of OpenShift client utility. ``` oc version ``` Output: ``` oc v3.11.0+0cbc58b kubernetes v1.11.0+d4cacc0 features: Basic-Auth GSSAPI Kerberos SPNEGO ``` ## Step 4 – Start OpenShift Origin Cluster Next, start the OpenShift cluster using the following command: ``` oc cluster up --public-hostname=your-server-ip --routing-suffix=your-server-ip.nip.io ``` Once the installation has been completed, you should get the following output: ``` OpenShift server started. The server is accessible via web console at: https://your-server-ip:8443 You are logged in as: User: developer Password: To login as administrator: oc login -u system:admin ``` ## Step 5 – Working with OpenShift Origin Cluster You can log in to the OpenShift cluster using the following command: ``` oc login -u system:admin ``` You should get the following output: ``` Logged into "https://your-server-ip:8443" as "system:admin" using existing credentials. You have access to the following projects and can switch between them with 'oc project ': default kube-dns kube-proxy kube-public kube-system * myproject openshift openshift-apiserver openshift-controller-manager openshift-core-operators openshift-infra openshift-node openshift-service-cert-signer openshift-web-console Using project "myproject". ``` You can now check the node status using the following command: ``` oc get nodes -o wide ``` You should get the following output: ``` NAME STATUS ROLES AGE VERSION INTERNAL-IP EXTERNAL-IP OS-IMAGE KERNEL-VERSION CONTAINER-RUNTIME localhost Ready 3m v1.11.0+d4cacc0 your-server-ip CentOS Linux 7 (Core) 3.10.0-1127.10.1.el7.x86_64 docker://20.10.5 ``` ## Step 6 – Create a New Project Next, you will need to create a new project on OpenShift cluster. First, log in to the cluster with the following command: ``` oc login ``` Provide your developer login credentials as shown below: ``` Authentication required for https://your-server-ip:8443 (openshift) Username: developer Password: Login successful. You have one project on this server: "myproject" Using project "myproject". ``` Next, create a new project with the following command: ``` oc new-project dev --display-name="MyProject - Dev" --description="My-Project" ``` You should see the following output: ``` Now using project "dev" on server "https://your-server-ip:8443". You can add applications to this project with the 'new-app' command. For example, try: oc new-app centos/ruby-25-centos7~https://github.com/sclorg/ruby-ex.git to build a new example application in Ruby. ``` ## Step 7 – Access OpenShift Cluster At this point, the OpenShift cluster is running and listening on port 8443. You can access it using the URL **https://your-server-ip:8443/console/**. You will be redirected to the login page: ![](https://www.atlantic.net/wp-content/uploads/2021/04/okd-login-1024x494.png) Provide the username as “developer” and the password as “developer,” then click on the **Login** button. You should see the OpenShift cluster dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/04/okd-dashboard-1024x533.png) ## Conclusion In the above guide, you learned how to set up an OpenShift Cluster on CentOS 7. You can now deploy and scale your application on the OpenShift cluster on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install Gulp.js on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-install-gulp-js-on-ubuntu/ | Published: 2021-05-29 | Updated: 2025-05-25 | Author: Hitesh Jethva Gulp is an open-source JavaScript software toolkit that helps you to automate painful or time-consuming tasks in your development workflow. It is cross-platform and can be integrated into all major IDEs. You can use Gulp with many programming languages including PHP, .NET, Node.js, Java, and more. In this post, we will explain how to install Gulp js on Ubuntu 24.04 [VPS](https://www.atlantic.net/vps-hosting/). ## Step 1 – Install Required Dependencies Before starting, you will need to install some dependencies on your server. You can install all of them with the following command: ``` apt-get install python3-software-properties gnupg2 curl wget -y ``` Once all the dependencies are installed, you can proceed to install Node.js. ## Step 2 – Install Node.js First, install the necessary dependencies using the following command. ``` apt-get install -y ca-certificates curl gnupg ``` Next, download the Node.js GPG key. ``` mkdir -p /etc/apt/keyrings curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg ``` Next, add the NodeSource repo to the APT source list. ``` echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_22.x nodistro main" | tee /etc/apt/sources.list.d/nodesource.list ``` Then, update the repository index and install Node.js with the following command. ``` apt update apt-get install -y nodejs ``` Next, verify the Node.js version using the following command. ``` node -v ``` Output. ``` v22.15.1 ``` ## Step 3 – Create a Sample Application with NPM First, create a new application directory with the following command: ``` mkdir project ``` Next, change the directory to the project directory and create an application with the following command: ``` cd project npm init ``` You will be asked some questions to create a package.json file: ``` This utility will walk you through creating a package.json file. It only covers the most common items, and tries to guess sensible defaults. See `npm help init` for definitive documentation on these fields and exactly what they do. Use `npm install ` afterwards to install a package and save it as a dependency in the package.json file. Press ^C at any time to quit. package name: (project) version: (1.0.0) description: My Gulp Project entry point: (index.js) test command: "echo "How Are You" && exit 1" git repository: keywords: author: Admin license: (ISC) About to write to /root/project/package.json: { "name": "project", "version": "1.0.0", "description": "My Gulp Project", "main": "index.js", "scripts": { "test": "\"echo \"How Are You\" && exit 1\"" }, "author": "Admin", "license": "ISC" } Is this OK? (yes) Yes ``` ## Step 4 – Install Gulpjs Next, you can install the Gulp CLI tool with the following command: ``` npm install -g gulp-cli ``` Output: ``` /usr/bin/gulp -> /usr/lib/node_modules/gulp-cli/bin/gulp.js + gulp-cli@2.3.0 added 252 packages from 165 contributors in 17.941s ``` Once Gulp is installed, change the directory to your project directory and install the gulp package with the following command: ``` cd /root/project npm install --save-dev gulp ``` You can now verify the Gulp version with the following command: ``` gulp --version ``` You should see the following output: ``` CLI version: 3.0.0 Local version: 5.0.0 ``` ## Step 5 – Create a Gulp Application Next, create a sample Gulp application with the following command: ``` nano /root/project/gulpfile.js ``` Add the following lines: ``` var gulp = require('gulp'); gulp.task('hello', function(done) { console.log('Hello World!!!'); done(); }); ``` Save and close the file, then run the gulp task with the following command: ``` gulp hello ``` If everything is fine, you should get the following output: ``` [09:11:28] Using gulpfile ~/project/gulpfile.js [09:11:28] Starting 'hello'... Hello World!!! [09:11:28] Finished 'hello' after 4.41 ms ``` ## Conclusion Congratulations! You have successfully installed Gulp on Ubuntu 24.04 [VPS](https://www.atlantic.net/vps-hosting/). You can now create your own application with Gulp. For more information, visit the Gulp [documentation](https://gulpjs.com/docs/en/getting-started/quick-start). --- # How to Install Landing CMS on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-landing-cms-on-centos-8/ | Published: 2021-05-30 | Updated: 2023-11-24 | Author: Hitesh Jethva Landing CMS is a free, open-source, cross-platform content management system used for managing landing pages. It is a flat file-based CMS, so it does not require any database. You only need a web server and PHP to host the Landing CMS. If you are looking for a simple but powerful CMS for landing pages, then Landing CMS is the best choice for you. In this post, we will show you how to install Landing CMS on CentOS 8 VPS. ## Step 1 – Install Apache and PHP Landing CMS is written in PHP and runs on a web server, so you will need to install Apache and PHP to your server. You can install both with the following command: ``` dnf update -y dnf install httpd php php-cli php-gd php-json php-curl unzip -y ``` Once all the packages are installed, start the Apache service and enable it to start at system reboot: ``` systemctl start httpd systemctl enable httpd ``` ## Step 2 – Download Landing CMS First, you will need to download the latest version of Landing CMS from the Github repository. You can download it with the following command: ``` wget https://github.com/Elias-Black/Landing-CMS/archive/master.zip ``` Once the download is completed, unzip the downloaded file with the following command: ``` unzip master.zip ``` Next, move the extracted directory to the Apache web root with the following command: ``` mv Landing-CMS-master /var/www/html/landing ``` Next, set proper permissions and ownership with the following command: ``` chown -R apache:apache /var/www/html/landing chmod -R 755 /var/www/html/landing ``` ## Step 3 – Configure Apache for Landing CMS Next, you will need to create an apache virtual host configuration file for Landing CMS. You can create it with the following command: ``` nano /etc/httpd/conf.d/landing.conf ``` Add the following lines: ``` ServerAdmin admin@example.com ServerName landing.example.com DocumentRoot /var/www/html/landing allowoverride all allow from all TransferLog /var/log/httpd/landing_access.log ErrorLog /var/log/httpd/landing_error.log ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` At this point, the Apache web server is configured to host Landing CMS. You can now proceed to access Landing CMS. ## Step 4 – Access Landing CMS Now, open your web browser and access the Landing CMS web UI using the URL **http://landing.example.com**. You will be redirected to the following page: ![Landing CMS Welcome Page](https://www.atlantic.net/wp-content/uploads/2021/05/p1-3-1024x482.png) Click on the **Go to CMS**. You should see the following page: ![Landing CMS Set password Page](https://www.atlantic.net/wp-content/uploads/2021/05/p2-4-1024x531.png) Now, set a password for Landing CMS and click on the **Save** button to apply the changes. You should see the Landing CMS dashboard on the following page: ![Landing CMS Dashboard Page](https://www.atlantic.net/wp-content/uploads/2021/05/p3-3-1024x529.png) ## Conclusion That’s it for now. You can now use Landing CMS to create and manage landing pages for your CMS. Give it a try on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Backdrop CMS on CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-backdrop-cms-on-centos-8/ | Published: 2021-05-31 | Updated: 2023-11-23 | Author: Hitesh Jethva Backdrop CMS is an open-source content management system written in PHP language. It is a fork of Drupal and suitable for small to medium-sized businesses and non-profits. Backdrop CMS allows you to build customized websites through collaboration and open-source software. It provides a beautiful and user-friendly web UI that helps non-technical users create and manage various content. Backdrop CMS offers powerful features, including advanced access control, a robust API, integrated add-on installation, and more. This post will show you how to install Backdrop CMS on CentOS 8 [VPS](https://www.atlantic.net/vps-hosting/).[jumpbox] ## Step 1 – Install LAMP Server First, you will need to install the LAMP stack on your server. You can install it with other required packages by running the following command: ``` dnf update -y dnf install httpd mariadb-server php php-cli php-gd php-mysqlnd php-json php-curl php-pdo php-mbstring php-dom php-xml unzip -y ``` Once all the packages are installed, start the Apache and MariaDB services and enable them to start at system reboot: ``` systemctl start httpd systemctl enable httpd systemctl start mariadb systemctl enable mariadb ``` ## Step 3 – Configure MariaDB Database Next, you must create a database and user for Backdrop CMS to store its content. First, log in to MySQL with the following command: ``` mysql ``` Once login, create a database and user with the following command: ``` create database backdrop; create user 'backdrop'@localhost identified by 'password'; ``` Next, grant all permissions to the backdrop database: ``` grant all privileges on backdrop.* to 'backdrop' @localhost; ``` Next, flush the privileges to apply the changes and exit from the MySQL with the following command: ``` flush privileges; exit; ``` At this point, the MariaDB database is ready for Backdrop CMS. ## Step 4 – Download Backdrop CMS First, visit the Backdrop CMS Git Hub page and download the latest version of Backdrop CMS with the following command: ``` wget https://github.com/backdrop/backdrop/archive/1.16.2.zip ``` Once the download is completed, unzip the downloaded file with the following command: ``` unzip 1.16.2.zip ``` Next, move the extracted directory to the Apache root directory: ``` mv backdrop-1.16.2 /var/www/html/backdrop ``` Next, set proper permissions and ownership to the backdrop directory: ``` chown -R apache:apache /var/www/html/backdrop chmod -R 755 /var/www/html/backdrop ``` ## Step 5 – Configure Apache for Backdrop CMS Next, you must configure the Apache virtual host file to host Backdrop CMS. You can create it with the following command: ``` nano /etc/httpd/conf.d/backdrop.conf ``` Add the following lines: ``` ServerAdmin admin@example.com ServerName backdrop.example.com DocumentRoot /var/www/html/backdrop allowoverride all allow from all TransferLog /var/log/httpd/backdrop_access.log ErrorLog /var/log/httpd/backdrop_error.log ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` Currently, the Apache web server is configured to serve backdrop CMS. ## Step 6 – Access Backdrop CMS Now, open your web browser and access the Backdrop CMS web UI using the URL http://backdrop.example.com. You will be redirected to the following page: ![BackDrop CMS Language Selection Page](https://www.atlantic.net/wp-content/uploads/2021/05/p1-4-1024x511.png) Select your language and click on the **SAVE AND CONTINUE** button. You should see the following page: ![BackDrop CMS Database Page](https://www.atlantic.net/wp-content/uploads/2021/05/p2-5-1024x613.png) Provide your database details and click on the **SAVE AND CONTINUE** button. You should see the following page: ![BackDrop CMS Site Info Page1](https://www.atlantic.net/wp-content/uploads/2021/05/p3-4-1024x638.png) ![BackDrop CMS Site Info Page2](https://www.atlantic.net/wp-content/uploads/2021/05/p4-1.png) Provide your site information and click on the **SAVE AND CONTINUE** button. You will be redirected to the Backdrop CMS dashboard: ![BackDrop CMS Dashboard](https://www.atlantic.net/wp-content/uploads/2021/05/p5-1-1024x308.png) ## Conclusion That’s it for now. You can now explore the Backdrop CMS and start creating your website through the Backdrop CMS dashboard on your [VPS](https://www.atlantic.net/vps-hosting/). For more information, visit the Backdrop CMS [documentation](https://backdropcms.org/) page. --- # How to Install and Configure Privoxy Server On CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-configure-privoxy-server-on-centos-8/ | Published: 2021-06-01 | Updated: 2023-11-21 | Author: Hitesh Jethva Privoxy is a free and non-caching web proxy server. A web browser uses this proxy server before connecting to the Internet directly. Privoxy is mainly used for security and to improve efficiency through its advanced caching features. Privoxy has advanced filtering capabilities including ad-blocking, web content filtering, modifying web page data and HTTP access, controlling access and blocking unwanted sites, and more. It is simple, easy to configure, and highly customizable. In this post, we will show you how to install and configure the Privoxy server on CentOS 8 [VPS](https://www.atlantic.net/vps-hosting/). ## Step 1 – Install Privoxy By default, the Privoxy package is not included in the CentOS default repo, so you will need to install the EPEL repo to your system. You can install it with the following command: ``` dnf update -y dnf install epel-release -y ``` Once EPEL is installed, you can install the Privoxy server with the following command: ``` dnf install privoxy -y ``` Privoxy server stores all their configuration files at /etc/privoxy/. You can check them with the following command: ``` ls -l /etc/privoxy/ ``` You should see the following output: ``` -rw-r--r-- 1 root root 84868 Mar 1 12:22 config -rw-r--r-- 1 root root 109864 Mar 1 12:22 default.action -rw-r--r-- 1 root root 43970 Feb 25 12:54 default.filter -rw-r--r-- 1 root root 600 Feb 25 12:54 match-all.action -rw-r--r-- 1 root root 42259 Feb 25 12:54 regression-tests.action drwxr-xr-x 2 root root 4096 May 26 02:29 templates -rw-r--r-- 1 root root 3565 Feb 25 12:54 trust -rw-r--r-- 1 root root 9012 Feb 25 12:54 user.action -rw-r--r-- 1 root root 0 Mar 1 12:22 user.filter ``` ## Step 2 – Configure Privoxy By default, the Privoxy server listens to the localhost, so you will need to configure it to listen to the IP address. You can do it by editing the Privoxy default config file: ``` nano /etc/privoxy/config ``` Find the following line: ``` listen-address 127.0.0.1:8118 ``` Change it with the following line: ``` listen-address your-server-ip:8118 ``` Next, uncomment the following lines: ``` logdir /var/log/privoxy logfile logfile debug 1 # Log the destination for each request. See also debug 1024. debug 2 # show each connection status debug 4 # show tagging-related messages debug 8 # show header parsing debug 16 # log all data written to the network debug 32 # debug force feature debug 64 # debug regular expression filters# debug 128 # debug redirects debug 256 # debug GIF de-animation debug 512 # Common Log Format debug 1024 # Log the destination for requests Privoxy didn't let through, and the reason why. debug 2048 # CGI user interface# debug 4096 # Startup banner and warnings. debug 8192 # Non-fatal errors debug 32768 # log all data read from the network debug 65536 # Log the applying actions ``` Save and close the file, then start the Privoxy service using the following command: ``` systemctl start privoxy ``` You can check the status of the Privoxy with the following command: ``` systemctl status privoxy ``` You should get the following output: ``` ● privoxy.service - Privoxy Web Proxy With Advanced Filtering Capabilities Loaded: loaded (/usr/lib/systemd/system/privoxy.service; disabled; vendor preset: disabled) Active: active (running) since Wed 2021-05-26 02:34:04 EDT; 5s ago Process: 41499 ExecStart=/usr/sbin/privoxy --pidfile /run/privoxy.pid --user privoxy /etc/privoxy/config (code=exited, status=0/SUCCESS) Main PID: 41500 (privoxy) Tasks: 1 (limit: 12524) Memory: 1.4M CGroup: /system.slice/privoxy.service └─41500 /usr/sbin/privoxy --pidfile /run/privoxy.pid --user privoxy /etc/privoxy/config May 26 02:34:03 centos8 systemd[1]: Starting Privoxy Web Proxy With Advanced Filtering Capabilities... May 26 02:34:04 centos8 systemd[1]: Started Privoxy Web Proxy With Advanced Filtering Capabilities. ``` At this point, the Privoxy server is started and listening on port 8118. You can check it with the following command: ``` ss -antpl | grep 8118 ``` You should see the following output: ``` LISTEN 0 128 104.245.32.188:8118 0.0.0.0:* users:(("privoxy",pid=41500,fd=7)) ``` ## Step 3 – Configure Web Browser to Use Privoxy Proxy Next, you will need to configure your web browser to the Privoxy server as a proxy server. First, go to the client system, open your **Firefox web browser** => and click on **Edit** => **Preferences**. You should see the following page: ![Firefox settings](https://www.atlantic.net/wp-content/uploads/2021/05/p1-1-1-1024x578.png) Now, click on **Network Settings** => **Settings**. You should see the following page: ![Firefox proxy settings](https://www.atlantic.net/wp-content/uploads/2021/05/p1-5.png) Now, provide your Privoxy server IP and port and click on the **Ok** button to save the changes. At this point, your web browser is configured to use the Privoxy server before connecting to the internet. Now, open your web browser and access the URL **https://www.whatismyip.com** to check your public IP address. If everything is fine, you should see your Privoxy server IP on the following page: ![Check Public IP](https://www.atlantic.net/wp-content/uploads/2021/05/p2-6-1024x541.png) By default, the Privoxy server is configured to block any advertising site. To check it, open a new tab in your web browser and access any advertising site **http://advertise.com/**. ![Website blocked](https://www.atlantic.net/wp-content/uploads/2021/05/p-1024x561.png) As you can see, your request for http://advertise.com/ was blocked. ## Conclusion Congratulations! You have successfully installed and configured the Privoxy server on your CentOS 8 [virtual private server](https://www.atlantic.net/vps-hosting/). You can now use some advanced filter in the Privoxy server and block your desired contents. --- # How to Install and Configure Sandstorm Server On CentOS 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-configure-sandstorm-server-on-centos-8/ | Published: 2021-06-02 | Updated: 2024-06-30 | Author: Hitesh Jethva Sandstorm is a free and open-source platform for web applications and servers. You can deploy many applications including WordPress, GitLab, MediaWiki, Apache Wave, and RoundCube webmail using Sandstorm. It comes with a simple and user-friendly web interface that helps you to install and manage apps on your server. Compared to other platforms, Sandstorm is designed from the ground up to be radically easier to use. In this post, we will show you how to install Sandstorm on CentOS 8 [VPS](https://www.atlantic.net/vps-hosting/). ## Step 1 – Set Up Hostname Before starting, you will need to set a fully qualified hostname of your server. You can set it using the following command: ``` hostnamectl set-hostname sandstorm.example.com ``` Once you are done, you can proceed to the next step. ## Step 2 – Install Sandstorm Sandstorm provides an auto-installation script that makes it easy to install Sandstorm on your server. You can download the Sandstorm installation script using the following command: ``` curl https://install.sandstorm.io >install.sh ``` Once the script is downloaded, run the downloaded script to start the installation: ``` bash install.sh ``` You will be asked to select the installation option as shown below: ``` Sandstorm makes it easy to run web apps on your own server. You can have: 1. A typical install, to use Sandstorm (press enter to accept this default) 2. A development server, for working on Sandstorm itself or localhost-based app development ``` Press **enter** to select the default option. You should see the following output: ``` How are you going to use this Sandstorm install? [1] We're going to: * Install Sandstorm in /opt/sandstorm * Automatically keep Sandstorm up-to-date * Create a service user (sandstorm) that owns Sandstorm's files * Configure Sandstorm to start on system boot (with systemd) * Listen for inbound email on port 25. Rest assured that Sandstorm itself won't run as root. OK to continue? [yes] ``` Press **enter** to continue. You should see the following output: ``` NOTE: It looks like your system already has some other web server installed (port 80 and/or 443 are taken), so Sandstorm cannot act as your main web server. This script can set up Sandstorm to run on port 6080 instead, without HTTPS. This makes sense if you're OK with typing the port number into your browser whenever you access Sandstorm and you don't need security. This also makes sense if you are going to set up a reverse proxy; if so, see https://docs.sandstorm.io/en/latest/administering/reverse-proxy/ If you want, you can quit this script with Ctrl-C now, and go uninstall your other web server, and then run this script again. It is also OK to proceed if you want. OK to skip automatic HTTPS setup & bind to port 6080 instead? [yes] ``` Press **enter** to bind Sandstorm port to **6080**. You should see the following output: ``` Note: Sandstorm's storage will only be accessible to the group 'sandstorm'. As a Sandstorm user, you are invited to use a free Internet hostname as a subdomain of sandcats.io, a service operated by the Sandstorm development team. ... Sandcats.io protects your privacy and is subject to terms of use. By using it, you agree to the terms of service & privacy policy available here: https://sandcats.io/terms https://sandcats.io/privacy Choose your desired Sandcats subdomain (alphanumeric, max 20 characters). Type the word none to skip this step, or help for help. What *.sandcats.io subdomain would you like? [] none ``` Type none and hit **enter**. Once the installation has been completed you should see the following output: ``` URL users will enter in browser: [http://sandstorm.example.com:6080] Sandstorm requires you to set up a wildcard DNS entry pointing at the server. This allows Sandstorm to allocate new hosts on-the-fly for sandboxing purposes. Please enter a DNS hostname containing a '*' which maps to your server. For example, if you have mapped *.foo.example.com to your server, you could enter "*.foo.example.com". You can also specify that hosts should have a special prefix, like "ss-*.foo.example.com". Note that if your server's main page is served over SSL, the wildcard address must support SSL as well, which implies that you must have a wildcard certificate. For local-machine servers, we have mapped *.local.sandstorm.io to 127.0.0.1 for your convenience, so you can use "*.local.sandstorm.io" here. If you are serving off a non-standard port, you must include it here as well. Wildcard host: [*.sandstorm.example.com:6080] Your server is now online! Visit this link to start using it: http://sandstorm.example.com:6080/setup/token/7f7f36c9e39f738a69564622123be64b373141a5 NOTE: This URL expires in 15 minutes. You can generate a new setup URL by running 'sudo sandstorm admin-token' from the command line. To learn how to control the server, run: sandstorm help ``` At this point, Sandstorm is installed and listening on port 6080. You can check it with the following command: ``` ss -antpl | grep 6080 ``` You should see the following page: ``` LISTEN 0 128 0.0.0.0:6080 0.0.0.0:* users:(("sandstorm/gtway",pid=28336,fd=7),("sandstorm/montr",pid=28265,fd=7),("sandstorm/top",pid=28262,fd=7)) ``` ## Step 3 – Access Sandstorm Web UI Now, open your web browser and access the Sandstorm You will be redirected to the following page: ![Sandstorm Installation begin](https://www.atlantic.net/wp-content/uploads/2021/05/p1-6-1024x566.png) Click on the **Begin Sandstorm Setup**. You should see the following page: ![Sandstorm Select Authentication](https://www.atlantic.net/wp-content/uploads/2021/05/p2-7-1024x607.png) Select E-Mail and click on the **Configure** button. You should see the following page: ![Sandstorm Enable Authentication](https://www.atlantic.net/wp-content/uploads/2021/05/p3-5-1024x623.png) Click on **Enable**. You should see the following page: ![Sandstorm Define Email domain](https://www.atlantic.net/wp-content/uploads/2021/05/p4-2.png) Provide your mail server domain and click on the **Save and continue** button. You should see the following page: ![Sandstorm Provide SMTP configuration](https://www.atlantic.net/wp-content/uploads/2021/05/p6-1.png) Provide your SMTP host, port, username and password and click on the **Save and continue** button. You should see the following page: ![Sandstorm App Setup](https://www.atlantic.net/wp-content/uploads/2021/05/p7-1-1024x478.png) Click on the **Skip for now**. You should see the following page: ![Sandstorm Send Login Email](https://www.atlantic.net/wp-content/uploads/2021/05/p8-1.png) Provide your email address and click on the SEND LOGIN EMAIL. You should receive an email with login credentials. You can use those credentials to log in to the Sandstorm server. ## Conclusion Congratulations! You have successfully installed Sandstorm on CentOS 8 [VPS](https://www.atlantic.net/vps-hosting/). Sandstorm is a very useful tool for developers. It helps them to deploy any app with just a single click. For more information and documentation about Sandstorm, visit their [documentation](https://docs.sandstorm.io/en/latest/). --- # How to Install CTparental on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-ctparental-on-ubuntu-20-04/ | Published: 2021-06-03 | Updated: 2023-11-23 | Author: Hitesh Jethva CTparental is an open-source parental control software for controlling computer usage and Internet browsing. This simple, powerful tool is one of the best at filtering website access. It is made from components like dnsmasq, iptables, and inguardian privoxy, making CTparental a fully-fledged parental control solution. It supports several web browsers, including Firefox, Midori, Chromium, and more. This post will explain how to install CTparental on Ubuntu 20.04 VPS. ## Step 1 – Install CTparental By default, the CTparental package is not included in the Ubuntu default repository, so you must download the CTparental .deb file from the Gitlab website. You can download it with the following command: ``` apt-get update -y wget -c https://gitlab.com/marsat/CTparental/uploads/bff8a619a7993256c4249ba8c881673f/ctparental_ubuntu20.04_lighttpd_4.44.18-1.0_all.deb ``` Once the file is downloaded, install the downloaded file with the following command: ``` dpkg -i ctparental_ubuntu20.04_lighttpd_4.44.18-1.0_all.deb ``` Next, run the following command to resolve the dependency error: ``` apt-get install -f ``` During the installation, you will be asked to provide a CTparental admin username as shown below: ![CTparental Set Admin User](https://www.atlantic.net/wp-content/uploads/2021/05/p1-7.png) Provide your admin username and hit Enter. You will be asked to provide the password as shown below: ![CTparental Set Password](https://www.atlantic.net/wp-content/uploads/2021/05/p2-8.png) Provide your secure password and hit Enter to finish the installation. CTparental all configuration files are located at /etc/CTparental directory. You can see them with the following command: ``` ls /etc/CTparental/ ``` You should see the following output: ``` blacklist-enabled CThourscompteur dip-blackliste.conf GCToff.conf ipv6filter-available nftables-timerweb blacklists.tar.gz.md5sum CThours.conf dip-rehabiliter.conf ip-blackliste.conf ipv6filter-enable resolv.conf.sav bl-categories-available CTparental.conf dist.conf ipv4filter-available ipv6-rehabiliter sshd categories-enabled.conf CTsafe.conf dnsfilter-available ipv4filter-enable nftables.conf whitelist-enabled categoriesmd5sum ctsync.conf domaine-rehabiliter ipv4-rehabiliter nftables-save.nft wl-categories-available ``` ## Step 2 – Configure CTparental By default, CTparental is configured to listen on 127.0.0.11. You will need to configure it to listen to your public IP so you can access the CT parental web UI from the remote machine. You can configure it with the following command: ``` sed -i 's/127.0.0.11/your-server-ip/g' /etc/lighttpd/conf-enabled/90-CTparental.conf ``` The above command will replace the IP 127.0.0.11 with your-server-ip. Now, restart the Lighttpd service to apply the changes: ``` systemctl restart lighttpd ``` ## Step 3 – Access CTparental web UI Before accessing the CTparental web interface, you must edit the /etc/hosts file of the Linux system from where you want to access the CTparental. ``` nano /etc/hosts ``` Add the following lines: ``` your-server-ip admin.ct.local ``` Save and close the file, then open your web browser and access the CTparental web UI using the URL **https://admin.ct.local**. You will be redirected to the CTparental login page: ![CTparental Login page](https://www.atlantic.net/wp-content/uploads/2021/05/p4-3.png) Provide your username and password, and click on the **Connection** button. You should see the CTparental dashboard on the following page: ![CTparental Dashboard page](https://www.atlantic.net/wp-content/uploads/2021/05/p5-2-1024x535.png) ## Conclusion The above guide taught you how to install and configure CTparental on an Ubuntu 20.04 VPS. You can now control computer usage and internet browsing from the CTparental dashboard on your [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Install PrestaShop on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-prestashop-on-ubuntu-20-04/ | Published: 2021-06-04 | Updated: 2026-03-03 | Author: Hitesh Jethva PrestaShop is an e-commerce solution that allows you to create your own online shop easily. It is written in PHP and uses MySQL/MariaDB to store its content. PrestaShop provides a simple and efficient platform to sell and manage your product online. It offers very useful features including inventory management, invoicing, shipping, product catalogs, multiple payment gateway support, and many more. In this post, we will show you how to install PrestaShop with Apache on Ubuntu 20.04 VPS. ## Step 1 – Install Apache, MariaDB, and PHP First, you will need to install the Apache webserver, MariaDB database, PHP, and other packages to your system. You can install all of them with the following command: ``` apt-get update -y apt-get install apache2 mariadb-server php7.4 libapache2-mod-php7.4 php7.4-gd php7.4-mbstring php7.4-mysql php7.4-curl php-xml php-cli php7.4-intl php7.4-zip unzip -y ``` After installing all the packages, edit the php.ini file: ``` nano /etc/php/7.4/apache2/php.ini ``` Change the following settings per your requirements: ``` memory_limit = 512M post_max_size = 32M upload_max_filesize = 32M date.timezone = Asia/Kolkata ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart apache2 ``` ## Step 2 – Create a PrestaShop Database Next, you will need to create a database for PrestaShop to store their content. First, connect to MySQL with the following command: ``` mysql ``` Once connected, create a database and user with the following command: ``` CREATE DATABASE prestadb; GRANT ALL PRIVILEGES ON prestadb.* TO 'prestauser'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges to apply the changes: ``` FLUSH PRIVILEGES; ``` Next, exit from the MySQL with the following command: ``` EXIT; ``` ## Step 3 – Download PrestaShop First, go to the PrestaShop Git Hub repository page and download the latest version of PrestaShop with the following command: ``` wget https://github.com/PrestaShop/PrestaShop/releases/download/1.7.7.4/prestashop_1.7.7.4.zip ``` Once the download is completed, unzip the downloaded file to the Apache root directory: ``` unzip prestashop_1.7.7.4.zip -d /var/www/html/prestashop ``` Next, set proper permissions to the PrestaShop directory: ``` chown -R www-data:www-data /var/www/html/prestashop/ chmod -R 755 /var/www/html/prestashop ``` Once you are done, you can proceed to the next step. ## Step 4 – Configure Apache for PrestaShop Next, you will need to create an Apache virtual host configuration file to host PrestaShop. You can create it with the following command: ``` nano /etc/apache2/sites-available/prestashop.conf ``` Add the following lines: ``` ServerAdmin admin@example.com DocumentRoot /var/www/html/prestashop ServerName presta.example.com Options FollowSymlinks AllowOverride All Require all granted ErrorLog ${APACHE_LOG_DIR}/example_error.log CustomLog ${APACHE_LOG_DIR}/example_access.log combined ``` Save and close the file, then enable the PrestaShop virtual host with the following command: ``` a2ensite prestashop ``` Next, enable the Apache rewrite module and restart the Apache service to apply the changes: ``` a2enmod rewrite systemctl restart apache2 ``` Now, your Apache web server is configured to serve PrestaShop. You can now proceed to access PrestaShop. ## Step 5 – Access PrestaShop Web UI Now, open your web browser and type the URL http://presta.example.com. You should see the following page: ![PrestaShop Select Language](https://www.atlantic.net/wp-content/uploads/2021/05/p2-9.png) Choose your language and click on **Next**. You should see the following page: ![PrestaShop Accept License](https://www.atlantic.net/wp-content/uploads/2021/05/p3-6.png) Accept the license and click on the **Next**. You should see the following page: ![PrestaShop Site Info Page1](https://www.atlantic.net/wp-content/uploads/2021/05/p4-4.png) ![PrestaShop Site Info Page2](https://www.atlantic.net/wp-content/uploads/2021/05/p5-3.png) Provide your site information and click on the **Next**. You should see the following page: ![PrestaShop Database Info](https://www.atlantic.net/wp-content/uploads/2021/05/p6-2.png) Provide your database information and click on the **Next**. You should see the following page: ![PrestaShop Manage Store](https://www.atlantic.net/wp-content/uploads/2021/05/p7-2.png) Click on the “**Manage your store**“. You will be redirected to the following page: ![PrestaShop Admin URL](https://www.atlantic.net/wp-content/uploads/2021/05/a1.png) Before connecting to the PrestaShop admin interface, delete the install folder with the following command: ``` rm -rf /var/www/html/prestashop/install ``` Next, click on the **PrestaShop admin URL**. You will be redirected to the PrestaShop admin login page: ![PrestaShop Login Page](https://www.atlantic.net/wp-content/uploads/2021/05/a2-1024x637.png) Provide your admin username and password and click on **LOG IN**. You will be redirected to the PrestaShop dashboard: ![PrestaShop Dashboard Page](https://www.atlantic.net/wp-content/uploads/2021/05/a3-1024x535.png) ## Conclusion That’s it for now. You can now explore the PrestaShop dashboard, add your products, and start selling them online – install PrestaShop on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net and get started with your online store! --- # How to Install and Use Neofetch on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-neofetch-on-ubuntu/ | Published: 2021-06-05 | Updated: 2025-05-11 | Author: Hitesh Jethva Neofetch is a simple and powerful command-line system information tool. It can be installed on all Linux operating systems and is used to display the system information in the terminal alongside the operating system’s logo. Neofetch displays the most useful system information including host and kernel details, IP address, memory, CPU, desktop environment, uptime, GPU, themes, and more. In this post, we will show you how to install and use Neofetch on Ubuntu 24.04. ## Step 1 – Install Neofetch By default, Neofetch is included in the Ubuntu default repository. You can install it using the following command: ``` apt-get install neofetch -y ``` Once Neofetch is installed, you can verify the installed version of Neofetch using the following command: ``` neofetch --version ``` Output: ``` Neofetch 7.1.0 ``` You can see the help information about Neofetch with the following command: ``` neofetch --help ``` ## Step 2 – How to Use Neofetch In order to use Neofetch, just open the terminal and run the following command: ``` neofetch ``` You should see the following output: ``` .-/+oossssoo+/-. root@ubuntu `:+ssssssssssssssssss+:` ----------- -+ssssssssssssssssssyyssss+- OS: Ubuntu 24.04.2 LTS x86_64 .ossssssssssssssssssdMMMNysssso. Host: KVM/QEMU (Standard PC (i440FX /ssssssssssshdmmNNmmyNMMMMhssssss/ Kernel: 6.8.0-54-generic +ssssssssshmydMMMMMMMNddddyssssssss+ Uptime: 4 mins /sssssssshNMMMyhhyyyyhmNMMMNhssssssss/ Packages: 827 (dpkg), 4 (snap) .ssssssssdMMMNhsssssssssshNMMMdssssssss. Shell: bash 5.2.21 +sssshhhyNMMNyssssssssssssyNMMMysssssss+ Resolution: 1024x768 ossyNMMMNyMMhsssssssssssssshmmmhssssssso Terminal: /dev/pts/0 ossyNMMMNyMMhsssssssssssssshmmmhssssssso CPU: QEMU Virtual version 2.5+ (2) @ +sssshhhyNMMNyssssssssssssyNMMMysssssss+ GPU: 00:02.0 Cirrus Logic GD 5446 .ssssssssdMMMNhsssssssssshNMMMdssssssss. Memory: 213MiB / 3916MiB /sssssssshNMMMyhhyyyyhdNMMMNhssssssss/ +sssssssssdmydMMMMMMMMddddyssssssss+ /ssssssssssshdmNNNNmyNMMMMhssssss/ .ossssssssssssssssssdMMMNysssso. -+sssssssssssssssssyyyssss+- `:+ssssssssssssssssss+:` .-/+oossssoo+/-. ``` In the above output, you can see your system information. If you want Neofetch to start automatically when you open a terminal window, edit the ~/.bashrc file: ``` nano ~/.bashrc ``` Add the following line at the end of the file: ``` neofetch ``` Save and close the file, then activate the changes using the following command: ``` source ~/.bashrc ``` You can also exclude specific information from the Neofetch output. To exclude CPU and Memory information, run the following command: ``` neofetch --disable cpu memory ``` To hide operating system architecture, run the following command: ``` neofetch --os_arch off ``` To print the CPU cores information, run the following command: ``` neofetch --cpu_cores logical ``` To display CPU temperature, run the following command: ``` neofetch --cpu_temp C ``` ## Step 3 – Customize Neofetch Neofetch create a config file at **$HOME/.config/neofetch/config.conf** after the first run. You can edit it and change it per your requirements. ``` nano .config/neofetch/config.conf ``` Enable or disable the information that you need to display. ``` print_info() { info title info underline info "OS" distro info "Host" model info "Kernel" kernel info "Uptime" uptime info "Packages" packages info "Shell" shell info "Resolution" resolution info "DE" de info "WM" wm info "WM Theme" wm_theme info "Theme" theme info "Icons" icons info "Terminal" term info "Terminal Font" term_font info "CPU" cpu info "GPU" gpu info "Memory" memory info "Disk" disk info "Battery" battery info "Local IP" local_ip # info "Public IP" public_ip # info "Users" users # info "Public IP" public_ip # info "Locale" locale # This only works on glibc systems. info cols ``` Save and close the file when you are finished. ## Conclusion In the above guide, you learned how to install and use Neofetch to display the system information. Neofetch can now help you find the system’s basic information in an easier way – try it on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account today! --- # How to Install and use Bpytop Resource Monitoring Tool on Ubuntu 20.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-bpytop-resource-monitoring-tool-on-ubuntu-20-04/ | Published: 2021-06-06 | Updated: 2024-06-04 | Author: Hitesh Jethva Bpytop is a free and open-source resource monitoring tool written in Python. It provides a command-line interface to monitor system resources including disk, network, process, and CPU in real-time. Bpytop can be installed on several operating systems including Linux, macOS, and FreeBSD. It provides many useful features including a responsive UI, keyboard and mouse support, support for multiple filters, and much more. In this post, we will show you how to install and use the Bpytop resource monitoring tool on Ubuntu 20.04. ## Step 1 – Install Required dependencies Before starting, you will need to install some dependencies in your system. You can install all of them with the following command: ``` apt-get install python3 python3-pip git make gcc build-essential -y ``` Once all the dependencies are installed, you can proceed to the next step. ## Step 2 – Install Bpytop Using PIP There are several ways to install Bpytop in your Ubuntu system. You can use PIP to install Bpytop to your system. First, install the required dependencies using the following command: ``` pip3 install psutil ``` Next, install the Bpytop with the following command: ``` pip3 install bpytop ``` ## Step 3 – Compile Bpytop from Source You can also install Bpytop by downloading it from the Git Hub, then compiling it to your system. First, download the latest version of Bpytop with the following command: ``` git clone https://github.com/aristocratos/bpytop.git ``` Once the download is completed, change the directory to bpytop and compile it with the following command: ``` cd bpytop make install ``` ## Step 4 – Install Bpytop Using SNAP You can also use SNAP package manager to install Bpytop to your system. First, install the SNAP package manager with the following command: ``` apt-get install snapd -y ``` Once installed, run the following command to install Bpytop: ``` snap install bpytop ``` ## Step 5 – Install Bpytop Using Ubuntu Repository You can also add the Bpytop repository to APT and install it from the Ubuntu repository. First, add the Bpytop repository with the following command: ``` echo "deb http://packages.azlux.fr/debian/ buster main" | tee /etc/apt/sources.list.d/bpytop.list ``` Next, add the GPG key with the following command: ``` wget -qO - https://azlux.fr/repo.gpg.key | apt-key add - ``` Next, update the repository and install Bpytop with the following command: ``` apt-get update -y apt-get install bpytop -y ``` Once the installation is complete, verify the installed version of Bpytop with the following command: ``` bpytop --version ``` Output: ``` bpytop version: 1.0.64 psutil version: 5.8.0 ``` ## Step 6 – Working with Bpytop You can launch the Bpytop command-line interface using the following command: ``` bpytop ``` You should see the following screen: ![Bpytop Interface](https://www.atlantic.net/wp-content/uploads/2021/05/p1-2-1024x566.png) To get the list of all commands and keyboard shortcuts, press the ESC key. You should see the following screen: ![Bpytop Options](https://www.atlantic.net/wp-content/uploads/2021/05/p2-3-1024x568.png) Now, scroll down and select the HELP option. You will get a list of keyboard shortcuts on the following screen: ![Bpytop Help Page](https://www.atlantic.net/wp-content/uploads/2021/05/p3-2-1024x568.png) If you want to exit from the Bpytop resource monitor, press q on the keyboard. ## Conclusion In the above guide, you learned how to install and use the Bpytop resource monitoring tool on Ubuntu. You can now play around with different options and check the results on your [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # SSL, VPN, and Compliance: Frequently Asked Questions > URL: https://www.atlantic.net/dedicated-server-hosting/ssl-vpn-and-compliance-frequently-asked-questions/ | Published: 2021-06-08 | Updated: 2025-09-19 | Author: Richard Bailey Our engineers are asked lots of questions about how to use SSL/TLS certificates, how should customers secure their VPN connections, and whether they support the types of compliance offered by Atlantic.Net. Below are some of the most common questions we are asked, giving you all the information you need in advance! ## What is an SSL Certificate? SSL stands for Secure Socket Layer (SSL) It is a security standard used to create an encrypted connection between a source and a destination. SSL is a cryptographic protocol commonly used on a web server that creates an encrypted channel between the web server and the client, usually a web browser. The first use of SSL 1.0 was way back in 1995 by Netscape, and SSL 2.0 and SSL 3.0 quickly followed. SSL is a name that has stuck to the security standard over the last 30 years, but SSL was deprecated around 2015. The security standard has been replaced by TLS (Transport Layer Security). SSL/TLS is used to transmit encrypted data such as credit card numbers, [bank account](https://www.sofi.com/banking/) details, healthcare data, or social security numbers. Cipher Suites are used to authenticate with the client, and an SSL certificate enables the handshake to allow this to happen. ## What is the difference between SSL and TLS? TLS is the successor to SSL, but the latest versions of TLS, versions TLS1.2 and TLS1.3, are significantly more secure than SSL. At the end of the day, both SSL and TLS do the same job; they encrypt traffic between a source and a destination. To get technical for a moment, in SSL, the message digest is used to create a master secret, providing the basic security services which are authentication and confidentiality. However, with TLS, a pseudo-random function is used to create a master secret. Essentially, they both do the same job, but they go about it a different way. ## What is a VPN? A virtual private network (VPN) is a secure, private and encrypted network connection between two endpoints. A secured VPN tunnel is created peer-to-peer to encapsulate all network traffic, even if used over the public internet. The technology is widely used by home workers to create a private network connection between you and a workplace computer network over a home internet connection. It enables the user to access workplace resources and use your computer as if you were sitting at your office desk. ## What is the correct way to connect to the VPN? There is no predefined way to connect to a VPN. Customers often ask the proper way to connect to a VPN. The answer will vary depending on your situation. There are two common VPN solutions used by our clients; these are site-to-site VPN (sometimes called peer-to-peer or point-to-point) and remote access (or user-based) VPNs. If you have worked from home during the Covid-19 pandemic, you are likely connected to your work network through a remote access VPN. A secured tunnel is created between your home and the endpoint, probably a server in your office building or on one of their [cloud nodes](https://www.atlantic.net/dedicated-server-hosting/). These VPNs can be software-based or hardware-based. Alternatively, site-to-site VPNs are used to connect geographically disparate networks; for example, they might be used to connect Office A in Florida to Office B in New York. Sometimes both VPN technologies are used, you may use remote access VPN to connect to a gateway server, perhaps an [OpenVPN Cloud server](https://www.atlantic.net/vps-hosting/how-to-install-and-configure-openvpn-server-on-ubuntu-20-04/) hosted in Atlantic.Net. Another site-to-site VPN connects Atlantic.Net to your Head Office. ## Why I can’t access my website when I am on the VPN? First, do not worry, this is perfectly normal if your VPN provider has denied access to the public internet. When you are connected to a VPN, your computer registers with the VPN network and authentication of network addresses takes place inside the VPN network. There are three ways to fix this issue: 1. Try connecting to your website’s Private IP Address, or ensure DNS is configured correctly to point at the Internal, Private IP 2. Disconnect from the VPN to access the website 3. Enable split VPN tunneling; this will allow your local machine to look to the public internet for websites and also look inside the VPN network for corporate resources ## What is the difference between WHM and cPanel? WHM and cPanel are part of the same product. WHM is the reseller’s control panel, which is the owner of the server. cPanel is the control panel used by customers/end users. | **WHM** | **cPanel** | | --- | --- | | WHM is the reseller control panel | cPanel is the control panel used by customers | | WHM provides root access to server resources | cPanel provides individual user access to their private resources | | WHM is isolated from the customers and access is via separate port numbers | cPanel users have complete control over their account | ## Do I need another VPN user for my SEO? The real benefit of having a VPN user for your SEO office is to create a private connection between you and your SEO provider. This is something that you may want to consider if you use an overseas SEO provider, or if the SEO team needs to research the local market. It may also be a requirement for compliance. If your website is behind a firewall and you have security concerns, you don’t want, for example, /wp-admin/ exposed to the world. ## How do I request doing updates? So you need a new SSL? No problem, Atlantic.Net can get this sorted for you. Here is the process to request a new SSL: - The customer must notify Atlantic.Net that they need a new SSL. A request can be made to our Sales team who will provide a brochure on what SSLs are available, including the benefits, perks, and the cost of each. - Once a selection has been made, the new order is set to billing to complete the purchase of the SSL. The customer can decide if they would like Atlantic.Net to perform the install for a small fee or if they would like to install the SSL themselves. - The SSL is then ordered from our SSL providers. - The Atlantic.Net support team generates a Certificate Signing Request (CSR) with identification info relating to the customer. If the certificate is a renewal, a CSR is not necessary. - The CSR is submitted to the Registrar with an admin contact email (typically webmaster@domain.com or admin@domain.com). - Depending on the level of SSL purchased, validation can take from a few hours to a few days. - Once approved, the Registrar will send the approval letter to the supplied email with links of how to download their SSL or provide the Certificate code in their email. - The customer can then provide this to Atlantic.Net if they have opted for Atlantic.Net to install the SSL for them. ## Do you have more questions about SSL, VPN, and compliance? Get in touch with Atlantic.Net today! If you’re an existing client, reach out to support@atlantic.net and we can assist you. If you need help setting up a new VPN or SSL certificate and are interested in [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) or VPS hosting, contact sales@atlantic.net for more information about how Atlantic.Net can help.   --- # Should You Hire a Chief Compliance Officer? > URL: https://www.atlantic.net/hipaa-compliant-hosting/should-you-hire-a-chief-compliance-officer/ | Published: 2021-06-09 | Updated: 2026-05-30 | Author: Alexander Wise Regulatory compliance is a major issue for the information technology (IT) departments of many organizations. Failure to meet the standards required to protect sensitive personal or financial data can lead to substantial monetary fines and an associated drop in customer confidence. Data breaches affecting critical industries such as healthcare [continue to occur at an alarming rate](https://www.govinfosecurity.com/health-data-breach-tallys-2021-surge-continues-a-16757), putting additional emphasis on the protection of sensitive data resources. ## Who Should Be Responsible for Compliance in an Organization? A company can be responsible for complying with multiple regulations based on their business or market sector. Companies processing credit card payments need to follow the guidelines defined in the Payment Card Industry Data Security Standard (PCI-DSS). Organizations working in the healthcare industry in the United States are required to comply with standards developed in response to the Health Insurance Portability and Accountability Act of 1996, otherwise known as HIPAA. While the question surrounding the hiring of a Chief Compliance Officer (CCO) can apply to an enterprise required to navigate any type of regulatory landscape, this article focuses on complying with [HIPAA data security](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-security/) and privacy regulations. We’ll look at the benefits of companies that have a CCO and try to determine if it is necessary for all enterprises that are subject to HIPAA regulations to fill that position. ## What Is a Chief Compliance Officer? A Chief Compliance Officer is responsible for ensuring that an organization is complying with laws, regulatory standards, and policies that pertain to its specific market sector. It’s possible that a CCO will need to address multiple sets of guidelines that affect a company, such as a healthcare provider that accepts credit card payments. The CCO holds a key position in an enterprise that ensures checks, balances, and proper controls are in place to avoid the risks of regulatory noncompliance. A CCO will typically report directly to a company’s Chief Executive Officer (CEO). The CCO is also expected to inform the Board of Directors regarding important issues surrounding compliance and any violations that may have occurred. A CCO has many diverse responsibilities that include: - Defining the level of regulatory knowledge required for an organization to address current and future compliance requirements; - Developing an annual compliance strategy specifically tailored to meet the needs of the business; - Acting as a guide to the company’s compliance team or teams and overseeing the implementation of the overall compliance program; - Staying abreast of regulatory changes that impact the business and modifying compliance plans appropriately; - Furnishing the management team with strategic insight into compliance issues; - Providing the company’s Board with reports that keep them apprised of the organization’s compliance standing; - Acting as the central point-of-contact for compliance regulators and auditors; - Encouraging employees and managers to freely report possible compliance failures; - Coordinating internal reviews, monitoring, and audit activities to strengthen the organization’s compliance position; - Investigating and taking action on all compliance-related issues impacting the company. Individuals in the role of CCO can face several challenges in successfully fulfilling their responsibilities. In many organizations, the role is not clearly defined and there may be internal conflicts of interest surrounding compliance issues. A CCO does not report directly to the Board and is dependent on the support of the company’s CEO. In some cases, there are not adequate policies and procedures available to the CCO to achieve compliance. It can also be difficult for the CCO to obtain the necessary resources to implement the steps to ensure the organization’s compliance with regulatory guidelines. With the required qualifications in hand, you can make the most out of a job aggregator platform to search for [a CCO job](https://jooble.org/jobs-chief-compliance-officer) and maximize your opportunities. ## Options for HIPAA Compliance The focus on HIPAA compliance has led to multiple solutions being developed that help organizations adhere to the regulations. These third-party HIPAA compliance solutions can in some cases minimize or negate the need for a company to hire a CCO. ### HIPAA Cloud solutions Healthcare organizations desiring to take advantage of the benefits of cloud-based IT infrastructure and applications need specialized and [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) services from their providers. Their data needs to be stored securely, and the cloud infrastructure and services need to provide the necessary security to safeguard ePHI and address all other HIPAA requirements. [Atlantic.Net](https://www.atlantic.net/hipaa-compliant-hosting/) offers customers high-performance websites, databases, and storage servers that are HIPAA-compliant and guarantee 100% uptime. Partnering with an experienced organization ensures that healthcare startups or companies migrating to the cloud can easily construct an environment that conforms to all HIPAA requirements. ### HIPAA Forms HIPAA release forms are an example of regulatory documents that can easily be obtained from third-party providers.  Electronic protected health information (ePHI) needs to adhere to HIPAA guidelines for securing the data and maintaining its privacy. Tools such as plugins for WordPress websites make it easy for any company to meet HIPAA regulations when transferring health-related data over the web. ### HIPAA Email HIPAA has strict guidelines for how email can be used for communication between healthcare providers and patients. Any ePHI must be protected with robust encryption whether in use, in transit, or at rest unless patient approval for unencrypted communication has been obtained. Many email systems can be made HIPAA-compliant but are not configured to be safe out of the box. Potential solutions should be investigated as to their HIPAA compliance capabilities before being implemented in healthcare-related industries. ## Does Your Organization Need a Chief Compliance Officer? The answer to this question is not as straightforward as one might wish. All businesses should evaluate the impact of regulatory requirements on their operation and take the necessary steps to ensure compliance. In some cases, the answer may be obvious, but in others, the business model may influence the decision whether or not to hire a CCO. Even if a company chooses not to hire a dedicated CCO there will need to be someone in the organization responsible for compliance. This responsibility often falls to the chief operating officer (COO) or another corporate executive of similar status. Every company needs an individual capable of interacting with auditors and who understands how regulatory standards affect the business. Failure to address this need is a recipe for disaster. Let’s look at some different scenarios to see if it makes sense to fill the role of a chief compliance officer, specifically to address concerns about HIPAA regulations. - Companies with no relation to the healthcare industry do not have to worry about hiring a CCO to address HIPAA guidelines. They may, however, have other regulatory concerns based on their business that would benefit from the insight and focus of a CCO. - Smaller companies operating in the healthcare sphere may be able to get by without the services of a CCO. Through the use of third-party solutions like HIPAA-compliant cloud infrastructure and email applications, a healthcare provider can take the necessary steps to secure ePHI without hiring a full-time CCO. Engaging a HIPAA-compliance consultant may offer a viable alternative path with which this type of company can strengthen its regulatory standing without committing to hiring a CCO. - Larger organizations that deal extensively in the healthcare market will generally obtain more value from hiring a dedicated chief compliance officer. As the scope of a business grows and diversifies, successfully maintaining regulatory compliance becomes increasingly difficult. Conflicts can arise in businesses that need to comply with multiple sets of regulations. Resolving these issues effectively demands the centralized authority of a CCO. Diverse organizations in any business may need a CCO to address the complexities of global regulatory standards. The decision of a company to hire a CCO can also be directly influenced by its financial exposure in the event of a noncompliance event or data breach. As the privacy of personal information continues to gain importance in society, the penalties for offending entities will also increase. This will ensure that the role of CCO also increases in importance in the modern business world. ### Do You Need Robust HIPAA-Compliant Hosting or PCI-Compliant Hosting? Contracting with Atlantic.Net for [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) or PCI-DSS-compliant web hosting gives you peace of mind that your provider knows what they’re doing. Atlantic.Net is SOC 2, SOC 3, HIPAA audited, and [PCI ready](https://www.atlantic.net/pci-compliant-hosting/) and provides customers in the healthcare industry and those who process credit cards with the hardened, secure, and compliant infrastructure they need. They enable clients to effectively maintain HIPAA and PCI-DSS compliance. Learn more about our [HIPAA compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. --- # PCI Compliance in the Cloud: Challenges and Key Requirements > URL: https://www.atlantic.net/pci-compliant-hosting/pci-compliance-in-the-cloud-challenges-and-key-requirements/ | Published: 2021-06-10 | Updated: 2026-03-01 | Author: Gilad Maayan ![](https://www.atlantic.net/wp-content/uploads/2021/06/icon_pci-compliance-e1641564803790.png) ## What is PCI Compliance in the Cloud? PCI-DSS (the Payment Card Industry Data Security Standard) is a set of security requirements designed and enforced by major credit card brands. The standards apply to anyone who stores or processes cardholder data. It is commonly believed that a PCI-DSS certification means the organization has already evaluated their environment for the relevant security measures and is not required to implement further security measures. However, a PCI-DSS certification alone is not enough to ensure the environment is secure. Certified service providers should inform their customers exactly how they comply with PCI-DSS, and clearly define the steps all parties must take to comply with PCI requirements. ![](https://www.atlantic.net/wp-content/uploads/2021/06/icon_challenges.png) ## Challenges in Cloud PCI Compliance The path to PCI-DSS compliance is complex, but any company that handles the storage, processing or transfer of cardholder data must address it. In addition, compliance with all 12 PCI-DSS requirements and over 100 security controls is a daunting responsibility for IT teams. In large organizations with a substantial volume of cardholder data, such as banks, retail chains, and e-commerce companies, it is very difficult to fully comply with PCI-DSS. This is because the PCI standard needs to be addressed at every level, from the underlying infrastructure to the operating system to the network. The distributed architecture of cloud environments makes this much more complex to achieve. The public cloud is designed to allow resources to be accessed from anywhere on the internet. Therefore, special control measures are required to compensate for the inherent risks and reduced visibility of these environments. This makes it difficult to operate public cloud services in a PCI-compliant manner. Cloud providers are responsible for providing a PCI-DSS compliance certificate, and customers should only accept that certificate after reviewing evidence that proper controls are in place. Cloud providers must provide their hosting customers with: - Documentation showing their PCI-DSS assessment and when it took place - What was or was not included in their assessment - Details of PCI-DSS security controls that are in place or not in place ## **Key PCI Compliance Requirements in the Cloud** PCI-DSS has 12 requirements. Here are the most important requirements that are relevant for a cloud environment, and what you should consider when using a cloud service for processing or storage of cardholder data. - - Requirement 1: Firewall - Requirement 2: Avoid Vendor-Supplied Defaults - Requirement 3: Protect Stored Cardholder Data - Requirement 4: Encrypting Cardholder Data in Transit - Requirement 5: Antivirus - Requirement 6: Secure Systems and Applications - (We have deliberately omitted requirements 7-9 because they are not directly relevant to cloud hosting services) - Requirement 10: Monitor Access to Network and Data - Requirement 11: Regular Security Testing and File Integrity Monitoring ## ![](https://www.atlantic.net/wp-content/uploads/2021/06/graphic_key-pci-compliance-requirements-e1641564853190.jpg) ![](https://www.atlantic.net/wp-content/uploads/2021/06/icon_firewall.png) ### Requirement 1: Firewall PCI requires a firewall to protect cardholder data. In a local environment, this can be achieved by deploying firewall devices for each network. In the cloud, you should use the cloud provider’s capabilities. Ensure security configuration is documented and can be demonstrated to auditors. ![](https://www.atlantic.net/wp-content/uploads/2021/06/icon_avoid-defaults.png) ### Requirement 2: Avoid Vendor-Supplied Defaults PCI requires changing default passwords and security settings for any IT system in the protected environment. In the cloud, you need to access all cloud resources and manually check if the defaults are still configured. A more practical approach is to use an automated tool to validate cloud misconfigurations and security vulnerabilities, like [cloud security posture management (CSPM)](https://www.aquasec.com/products/cspm/). ![](https://www.atlantic.net/wp-content/uploads/2021/06/icon_protect-cardholder-data-e1641564901756.png) ### Requirement 3: Protect Stored Cardholder Data PCI-compliant hosting providers help you protect cardholder data, and some providers offer fully managed security. Still, it is up to you to properly configure the security tools they provide. Assess your future and current providers to ensure they supply you with the necessary tooling. Key management is an important consideration. Managed hosting providers ensure that data encryption keys (DEK) and key-encryption keys (KEK) are managed securely according to PCI requirements. ![](https://www.atlantic.net/wp-content/uploads/2021/06/icon_encrypting-cardholder-data.png) ### Requirement 4: Encrypting Cardholder Data in Transit When you transmit cardholder data using public networks, you need to use secure communication channels. Preferably, with strong encryption protocols allowed by PCI-DSS such as TLS 1.2, SFTP, or IPSec. ![](https://www.atlantic.net/wp-content/uploads/2021/06/icon_antivirus.png) ### Requirement 5: Antivirus In a local environment, the common approach is to deploy an antivirus or endpoint protection agent on each computer. In the cloud, you have the same requirement—to deploy an antivirus agent on each cloud resource to prevent it from being infected by malware. Modern and endpoint protection tools support deployment on cloud resources. ### ![](https://www.atlantic.net/wp-content/uploads/2021/06/icon_secure-system-and-apps-e1641564957350.png)Requirement 6: Secure Systems and Applications This PCI requirement applies differently to different [types of cloud services](https://www.datamation.com/cloud-computing/top-managed-services-providers.html): - When using a managed service, the cloud user does not have any responsibilities in ensuring that the provider’s systems are secure. - When using cloud services in an IaaS or PaaS model, the organization using the services needs to test for vulnerabilities in its systems, apply security updates, perform change management, and adopt secure development practices. PCI-DSS requires manual or automatic verification of all code developed for public web applications. An alternative to code verification is to implement a web application firewall (WAF), which can be used as a cloud service or deployed as standalone software on cloud resources. **(We have deliberately omitted requirements 7-9 because they are not directly relevant to cloud hosting services)** ![](https://www.atlantic.net/wp-content/uploads/2021/06/icon_monitor-access.png) ### Requirement 10: Monitor Access to Network and Data On-premises, tracking, and monitoring access to cardholder data is achieved by “sniffing” network traffic and recording network logs. In the cloud, use the cloud provider’s monitoring platform or third party tools to check relevant event streams and resource logs. ![](https://www.atlantic.net/wp-content/uploads/2021/06/icon_testing-e1641564999139.png) ### Requirement 11: Regular Security Testing and File Integrity Monitoring (FIM) In a local environment, this requirement can be addressed by vulnerability scanning tools, which commonly include an FIM agent. In the cloud, check what security testing tools are offered by the cloud provider, and if they are insufficient, deploy a third-party tool that supports the relevant cloud services. ## PCI Compliance in the Cloud with Atlantic Contracting with Atlantic.Net for [PCI compliant hosting](https://www.atlantic.net/pci-compliant-hosting/) gives you peace of mind that your provider knows what they’re doing. Atlantic.Net is SOC 2, SOC 3, HIPAA audited, and [PCI hosting](https://www.atlantic.net/pci-compliant-hosting/)ready and provides customers in the eCommerce industry with the hardened, secure, and compliant infrastructure they need. ### We’ve taken the following security measures to make sure our cloud is as ironclad as possible: ![vpn](https://www.atlantic.net/wp-content/themes/anet/img/pci/solutions/icon_vpn.png) #### VPN’s ![Log Inspection](https://www.atlantic.net/wp-content/themes/anet/img/pci/solutions/icon_log-inspection.png) #### Log Inspection ![Cloud Server Management](https://www.atlantic.net/wp-content/themes/anet/img/pci/solutions/icon_cloud-server-management.png) #### Cloud Server Management ![Cloud Server Management](https://www.atlantic.net/wp-content/themes/anet/img/pci/solutions/icon_integrity-monitoring.png) #### Integrity Monitoring ![Intrusion Server Management](https://www.atlantic.net/wp-content/themes/anet/img/pci/solutions/icon_ips.png) #### Intrusion Server Management ![Managed Backup](https://www.atlantic.net/wp-content/themes/anet/img/pci/solutions/icon_backup.png) #### Managed Backup ![Anti-Malware](https://www.atlantic.net/wp-content/themes/anet/img/pci/solutions/icon_anti-malware.png) #### Anti-Malware ![Managed Firewall](https://www.atlantic.net/wp-content/themes/anet/img/pci/solutions/icon_firewall.png) #### Managed Firewall ![Network Security](https://www.atlantic.net/wp-content/themes/anet/img/pci/solutions/icon_network-security.png) #### Network Security ![Log Inspection](https://www.atlantic.net/wp-content/themes/anet/img/pci/solutions/icon_encryption.png) #### Encrypted Data At Rest --- #### Read More About PCI Compliant Hosting - [PCI Compliant Hosting](https://www.atlantic.net/pci-compliant-hosting/) - [What Is PCI Compliance?](https://www.atlantic.net/pci-compliant-hosting/what-is-pci-compliance/) - [PCI Compliance Requirements](https://www.atlantic.net/pci-compliant-hosting/pci-dss-cybersecurity-requirements-a-practical-guide/) for Cybersecurity - [PCI Compliance Checklist](https://www.atlantic.net/pci-compliant-hosting/small-business-pci-compliance-guide/) for Small Businesses --- --- # How to Install Sails.js Framework with Nginx as a Reverse Proxy on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-sails-js-framework-with-nginx-as-a-reverse-proxy-on-ubuntu-20-04/ | Published: 2021-06-11 | Updated: 2026-02-28 | Author: Hitesh Jethva Sails.js is the most popular MVC framework for Node.js. It allows you to build custom, enterprise-grade Node.js applications. Sails.js supports scalable, service-oriented architecture and provides basic security and role-based access control. It is used for developing chat, real-time dashboards, and multiplayer games. ## Step 1 – Install Node.js First, install the necessary dependencies using the following command. ``` apt-get install -y ca-certificates curl gnupg ``` Next, download the Node.js GPG key. ``` mkdir -p /etc/apt/keyrings curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg ``` Next, add the NodeSource repo to the APT source list. ``` echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_18.x nodistro main" | tee /etc/apt/sources.list.d/nodesource.list ``` Then, update the repository index and install the Ndoe.js with the following command. ``` apt update apt-get install -y nodejs ``` Next, verify the Node.js version using the following command. ``` node -v ``` Output. ``` v18.19.0 ``` ## Step 2 – Install Sails.js You can install Sails.js easily using the NPM command. ``` npm -g install sails ``` Once Sails.js is installed, create a new project named myapp with the following command: ``` sails new myapp ``` You will be asked to choose a template for your Sails application: ``` Choose a template for your new Sails app: 1. Web App · Extensible project with auth, login, & password recovery 2. Empty · An empty Sails app, yours to configure (type "?" for help, or to cancel) ? 2 ``` Type 2 and hit Enter to finish the installation: ``` info: Installing dependencies... Press CTRL+C to cancel. (to skip this step in the future, use --fast) info: Created a new Sails app `myapp`! ``` Next, change the directory to myapp and start the Sails app with the following command: ``` cd myapp sails lift ``` You should see the following output: ``` info: Starting app... info: info: .-..-. info: info: Sails <| .-..-. info: v1.4.3 |\ info: /|.\ info: / || \ info: ,' |' \ info: .-'.-==|/_--' info: `--'-------' info: __---___--___---___--___---___--___ info: ____---___--___---___--___---___--___-__ info: info: Server lifted in `/root/myapp` info: To shut down Sails, press + C at any time. info: Read more at https://sailsjs.com/support. debug: ------------------------------------------------------- debug: :: Sun Jun 13 2021 04:33:02 GMT+0000 (Coordinated Universal Time) debug: Environment : development debug: Port : 1337 debug: ------------------------------------------------------- ``` Press CTRL + C to stop the Sails application. ## Step 3 – Create a Systemd Service File for Sails.js App Next, you will need to create a systemd service file to manage the Sails.js application. You can create it with the following command: ``` nano /lib/systemd/system/sails.service ``` Add the following lines: ``` [Unit] After=network.target [Service] Type=simple User=root WorkingDirectory=/root/myapp ExecStart=/usr/bin/sails lift Restart=on-failure [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes: ``` systemctl daemon-reload ``` Next, start the Sails.js service and enable it to start at system reboot: ``` systemctl start sails systemctl enable sails ``` You can check the status of the Sails.js service with the following command: ``` systemctl status sails ``` You should see the following output: ``` ● sails.service Loaded: loaded (/lib/systemd/system/sails.service; disabled; vendor preset: enabled) Active: active (running) since Sun 2021-06-13 04:41:48 UTC; 6s ago Main PID: 3730 (node) Tasks: 22 (limit: 2353) Memory: 114.0M CGroup: /system.slice/sails.service ├─3730 node /usr/bin/sails lift └─3752 grunt Jun 13 04:41:49 ubuntu2004 sails[3730]: info: ____---___--___---___--___---___--___-__ Jun 13 04:41:49 ubuntu2004 sails[3730]: info: Jun 13 04:41:49 ubuntu2004 sails[3730]: info: Server lifted in `/root/myapp` Jun 13 04:41:49 ubuntu2004 sails[3730]: info: To shut down Sails, press + C at any time. Jun 13 04:41:49 ubuntu2004 sails[3730]: info: Read more at https://sailsjs.com/support. Jun 13 04:41:49 ubuntu2004 sails[3730]: debug: ------------------------------------------------------- Jun 13 04:41:49 ubuntu2004 sails[3730]: debug: :: Sun Jun 13 2021 04:41:49 GMT+0000 (Coordinated Universal Time) Jun 13 04:41:49 ubuntu2004 sails[3730]: debug: Environment : development Jun 13 04:41:49 ubuntu2004 sails[3730]: debug: Port : 1337 Jun 13 04:41:49 ubuntu2004 sails[3730]: debug: ------------------------------------------------------- ``` ## Step 4 – Configure Nginx as a Reverse Proxy for Sails.js It is recommended to configure Nginx as a reverse proxy to access the Sails application through port 80. First, install the Nginx web server with the following command: ``` apt-get install nginx -y ``` Once installed, create an Nginx virtual host configuration file: ``` nano /etc/nginx/conf.d/sails.conf ``` Add the following lines: ``` server { listen 80; server_name sails.example.com; location / { proxy_pass http://localhost:1337/; proxy_set_header Host $host; proxy_buffering off; } } ``` Save and close the file, then verify Nginx for any syntax error: ``` nginx -t ``` You should see the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Next, restart the Nginx service to apply the configuration changes: ``` systemctl restart nginx ``` ## Step 5 – Access Sails.js Web Interface Now, open your web browser and access the Sails.js application using the URL **http://sails.example.com**. You should see the Sails.js dashboard on the following screen: ![Sails.js Dashboard](https://www.atlantic.net/wp-content/uploads/2021/06/p1-4-1024x542.png) ## Conclusion Congratulations! You have successfully installed Sails.js with Nginx as a reverse proxy on Ubuntu 20.04 server. You can now build your own real-time application with Sails.js easily. Get started on your [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) account today! --- # How to Install Redmine 6 on Debian > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-redmine-6-on-debian/ | Published: 2021-06-13 | Updated: 2025-09-02 | Author: Hitesh Jethva Redmine is an open-source and cross-platform project management system. It is written in Ruby on Rails. Redmine allows you to manage multiple projects and sub-projects. It offers a web-based interface and other useful features including support for multiple languages, time tracking, role-based access control, and more. It supports various SCM integration including, SVN, CVS, Git, Mercurial, and more. In this tutorial, we will show you how to install Redmine 6 on a Debian 12 server. ## Prerequisites Before installing Redmine 6 on Debian 12, make sure your server meets the following requirements: - A Debian 12 server with sudo or root privileges. - A valid domain name (e.g., redmine.example.com) pointing to your server’s IP address. - At least 2 GB of RAM (4 GB recommended for smoother performance). ## Step 1: Install Required Packages Redmine requires a web server, database server, Ruby, and several development libraries to function properly. You can install all necessary dependencies with the following command: ```bash apt install apache2 mariadb-server ruby gnupg2 curl ruby-dev build-essential libssl-dev libreadline-dev zlib1g-dev libcurl4-openssl-dev libmariadb-dev libpq-dev libaprutil1-dev libapr1-dev apache2-dev ``` Once the installation is completed, start the Apache and MariaDB services. ```bash systemctl start apache2 systemctl start mariadb ``` ## Step 2: Configure the Database Redmine needs a database to store its data. We’ll use MariaDB, which is already installed. Run the following command to open the MariaDB shell. ```bash mariadb ``` Create a Redmine database and user. ```bash CREATE DATABASE redminedb CHARACTER SET utf8mb4 COLLATE utf8mb4_general_ci; CREATE USER redminedbuser@localhost IDENTIFIED BY 'password'; GRANT ALL ON redminedb.* TO redminedbuser@localhost WITH GRANT OPTION; FLUSH PRIVILEGES; ``` Once done, exit the MariaDB shell: ```bash EXIT; ``` Your Redmine database and user are now ready. ## Step 3: Install RVM and Ruby Redmine is a Ruby on Rails application, so we need Ruby installed. We’ll use RVM (Ruby Version Manager) to install and manage Ruby versions. 1. Run the following command to import the RVM keys. ```bash gpg2 --keyserver hkp://keyserver.ubuntu.com --recv-keys 409B6B1796C275462A1703113804BB82D39DC0E3 7D2BAF1CF37B13E2069D6956105BD0E739499BDB ``` If the above command fails, manually import the key with. ```bash curl -sSL https://rvm.io/pkuczynski.asc | gpg2 --import - ``` 2. Download and install RVM. ```bash curl -sSL https://get.rvm.io | bash -s stable source /etc/profile.d/rvm.sh ``` 3. Update RVM and install Ruby 3.3. ```bash rvm pkg install openssl rvm get head rvm install ruby 3.3 rvm use ruby 3.3 --default ``` This sets Ruby 3.3 as the default version on your server. ## Step 4: Download and Configure Redmine With Ruby installed, we can now download and set up Redmine 6.0.3. 1. Create a directory where Redmine will be stored. ```bash mkdir /var/lib/redmine ``` 2. Download the Redmine 6.0.3 tarball and extract it. ```bash wget https://www.redmine.org/releases/redmine-6.0.3.tar.gz tar -xvzf redmine-6.0.3.tar.gz ``` 3. Copy the extracted files into the Redmine directory. ```bash cp -r redmine-6.0.3/* /var/lib/redmine ``` 4. Copy the sample database configuration file. ```bash cp /var/lib/redmine/config/database.yml.example /var/lib/redmine/config/database.yml ``` 5. Make www-data (Apache user) the owner of the Redmine directory. ```bash chown -R www-data:www-data /var/lib/redmine ``` 6. Edit the file to match the database credentials you created earlier. ```bash nano /var/lib/redmine/config/database.yml ``` Update the production section: ```bash production: adapter: mysql2 database: redminedb host: localhost username: redminedbuser password: "password" # Use "utf8" instead of "utfmb4" for MySQL prior to 5.7.7 encoding: utf8mb4 variables: # Recommended `transaction_isolation` for MySQL to avoid concurrency issues is # `READ-COMMITTED`. # In case of MySQL lower than 8, the variable name is `tx_isolation`. # See https://www.redmine.org/projects/redmine/wiki/MySQL_configuration tx_isolation: "READ-COMMITTED" ``` At this point, Redmine is downloaded and linked to your database. Next, you’ll install required Ruby gems and initialize the application. ## Step 5: Install Ruby Gems and Initialize Redmine Now that Redmine is configured, we need to install the required Ruby gems and set up the application. 1. Bundler is a Ruby tool used to manage application dependencies. Install it with the below command. ```bash gem install bundler ``` 2. Move into the Redmine directory and install the required gems. ```bash cd /var/lib/redmine bundle config set --local without 'development test' bundle install ``` This will download and install all necessary Ruby gems for Redmine, excluding development and test dependencies. 3. Redmine requires a secret token for session management. Generate it with: ```bash bin/rake generate_secret_token ``` 4. Set up the database schema and load default data. ```bash bin/rake db:migrate RAILS_ENV="production" RAILS_ENV=production bundle exec rake redmine:load_default_data ``` During this step, you may be asked to choose a default language for Redmine’s interface. Once complete, your Redmine database is ready, and the application is fully initialized. ## Step 6: Install and Configure Passenger with Apache Redmine runs on Ruby, so we’ll use Passenger as the application server to integrate it with Apache. 1. Run the following command to install Passenger. ```bash gem install passenger ``` 2. Then, install the Passenger Apache module automatically. ```bash passenger-install-apache2-module --auto --languages ruby ``` 3. Run the below command to see a configuration snippet for Apache. ```bash passenger-install-apache2-module --snippet ``` Output. ```bash LoadModule passenger_module /usr/local/rvm/gems/ruby-3.3.9/gems/passenger-6.0.27/buildout/apache2/mod_passenger.so PassengerRoot /usr/local/rvm/gems/ruby-3.3.9/gems/passenger-6.0.27 PassengerDefaultRuby /usr/local/rvm/gems/ruby-3.3.9/wrappers/ruby ``` Copy this snippet because you’ll need to add it to your Apache configuration in the next step. ## Step 7: Configure Apache Virtual Host for Redmine Now that Passenger is installed, let’s configure Apache to serve Redmine. 1. Create a new Apache configuration file for Redmine. ```bash nano /etc/apache2/sites-available/redmine.conf ``` Paste the following configuration, replacing the Passenger paths with the ones you noted from the previous step. ```bash ServerName redmine.example.com ServerAdmin admin@example.com DocumentRoot /var/lib/redmine/public Require all granted # Basic configuration for Passenger. Use the info gathered from running #the passenger command and update the lines below. LoadModule passenger_module /usr/local/rvm/gems/ruby-3.3.9/gems/passenger-6.0.27/buildout/apache2/mod_passenger.so PassengerRoot /usr/local/rvm/gems/ruby-3.3.9/gems/passenger-6.0.27 PassengerDefaultRuby /usr/local/rvm/gems/ruby-3.3.9/wrappers/ruby # Allow access to Redmine's installation directory Allow from all Options -MultiViews Require all granted ``` 2. Enable the Apache virtual host and restart the Apache. ```bash a2ensite redmine.conf systemctl restart apache2 ``` ## Step 8: Access Redmine Web Interface With Apache and Passenger configured, you can now access Redmine through your browser. 1. Go to your server’s domain or IP address. If everything is configured correctly, you’ll see the Redmine page. ``` http://redmine.example.com ``` ![](https://www.atlantic.net/wp-content/uploads/2021/06/p1-12.png) 2. Click **Sign in,** and you will see the Redmine login page. ![](https://www.atlantic.net/wp-content/uploads/2021/06/p2-7.png) 3. Enter the default administrator username **admin,** the password as **admin** and click **Login.** On first login, Redmine will prompt you to change the password. ![](https://www.atlantic.net/wp-content/uploads/2021/06/p3-3.png) 4. Enter the current password (admin) and set a new secure password. After applying the changes, you’ll be redirected to the Redmine dashboard, ready to start creating projects, users, and issues. ![](https://www.atlantic.net/wp-content/uploads/2021/06/p4-4.png) ## Conclusion In this tutorial, you installed and configured Redmine 6 on Debian 12 with Apache, MariaDB, and Passenger. You created a database, set up Ruby using RVM, downloaded and configured Redmine, installed required gems, and integrated it with Apache to serve the application. At this point, your Redmine instance is up and running. You can log in from your browser, create projects, add users, assign roles, and start tracking tasks. --- # How to Install DokuWiki with Nginx on Debian > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-dokuwiki-with-nginx-on-debian/ | Published: 2021-06-14 | Updated: 2025-09-02 | Author: Hitesh Jethva DokuWiki is one of the most popular wiki applications written in PHP. It is a file-based wiki so you don’t need to install any database system to your system. DokuWiki allows you to create your own wiki site without any advanced knowledge. It offers very useful features such as multiple language support, SEO, authentication, spam blacklist, autosave, read-only pages, simple and lightweight architecture, and more. It is used by small companies to manage information and build knowledge bases. In this post, we will explain how to install DokuWiki with Nginx on Debian 12. ## Step 1 – Install Nginx and PHP First, you will need to install the Nginx web server, PHP, and other PHP extensions to your server. You can install all of them with the following command: ``` apt-get install nginx php php-fpm php-curl php-gd php-opcache php-json php-mbstring php-intl php-imagick php-xml -y ``` The above command will also install the Apache package and start the Apache service, so you will need to remove the Apache from your system. Run the following command to remove the Apache package and stop the service. ``` systemctl stop apahce2 apt-get remove apache2 --purge ``` Next, start the Nginx and PHP-FPM service with the following command: ``` systemctl start nginx systemctl start php8.2-fpm ``` ## Step 2 – Download DokuWiki Next, go to the DokuWiki download page, pick the latest version of DokuWiki, and download it with the following command: ``` cd /var/www/html wget https://download.dokuwiki.org/src/dokuwiki/dokuwiki-stable.tgz ``` After downloading, extract the downloaded file with the following command: ``` tar -xvzf dokuwiki-stable.tgz ``` Next, move the extracted directory to DokuWiki with the following command: ``` mv dokuwiki-2025-05-14a dokuwiki ``` Next, give proper permissions and ownership to the DokuWiki directory: ``` chown -R www-data:www-data /var/www/html/dokuwiki chmod -R 755 /var/www/html/dokuwiki ``` ## Step 3 – Configure Nginx for DokuWiki Next, create an Nginx virtual host configuration file for DokuWiki: ``` nano /etc/nginx/sites-available/dokuwiki.conf ``` Add the following lines: ``` server { listen 80; server_name doku.example.com; root /var/www/html/dokuwiki; index install.php index.html index.html; location / { try_files $uri $uri/ @dokuwiki; } location @dokuwiki { rewrite ^/_media/(.*) /lib/exe/fetch.php?media=$1 last; rewrite ^/_detail/(.*) /lib/exe/detail.php?media=$1 last; rewrite ^/_export/([^/]+)/(.*) /doku.php?do=export_$1&id=$2 last; rewrite ^/(.*) /doku.php?id=$1&$args last; } location ~ \.php$ { include snippets/fastcgi-php.conf; fastcgi_pass unix:/var/run/php/php8.2-fpm.sock; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } } ``` Save and close the file, then activate the Nginx virtual host and verify Nginx with the following command: ``` ln -s /etc/nginx/sites-available/dokuwiki.conf /etc/nginx/sites-enabled/ nginx -t ``` Output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` If you experience this issue: ``` nginx: [emerg] could not build server_names_hash ``` You should increase server_names_hash_bucket_size: 32 and edit the /etc/nginx.conf file to read: ``` server_names_hash_bucket_size 64; ``` Next, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 4 – Access DokuWiki Installation Now, open your web browser and access the DokuWiki installation using the URL **http://doku.example.com**. You should see the following screen: ![Dokuwiki welcome page](https://www.atlantic.net/wp-content/uploads/2021/06/p1-5-1024x559.png) Provide your Wiki name, admin username, password, and email and click on the Save button. You should see the following screen: ![Dokuwiki installation complete page](https://www.atlantic.net/wp-content/uploads/2021/06/p2-1-1024x510.png) Click on your new DokuWiki. You will be redirected to the DokuWiki welcome screen: ![Dokuwiki welcome screen](https://www.atlantic.net/wp-content/uploads/2021/06/p3-1024x579.png) Click on the Log In button. You should see the DokuWiki login screen: ![Dokuwiki Login screen](https://www.atlantic.net/wp-content/uploads/2021/06/p4-1024x571.png) Provide your admin username, password and click on the Log In button. You should see the DokuWiki dashboard on the following screen: ![Dokuwiki Dashboard](https://www.atlantic.net/wp-content/uploads/2021/06/p5-1024x614.png) ## Conclusion In the above guide, you learned how to install DokuWiki with Nginx on Debian 12 server. You can now use the DokuWiki to store your documentation and other information. Get started with DokuWiki on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Zimplit CMS on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-zimplit-cms-on-ubuntu-20-04/ | Published: 2021-06-16 | Updated: 2023-11-15 | Author: Hitesh Jethva Zimplit is a free, open-source, extremely lightweight content management system. It is simple, easy to install, customizable, and doesn’t need any database system. Zimplit consists of only one core engine file; you can edit your site by editing the HTML/CSS page. It has an on-site editor that enables you to do everything on the website directly without an admin area. In this post, we will show you how to install Zimplit CMS on Ubuntu 20.04. ## Step 1 – Install Apache and PHP First, you will need to install Apache web server, PHP, and other PHP extensions to your system. You can install all of them using the following command: ``` apt-get install apache2 libapache2-mod-php php php-mysql php-xml php-curl php-imap php-gd php-mbstring php-soap php-sqlite3 php-ldap php-zip -y ``` Once all the packages are installed, start the Apache service and enable it to start at system reboot: ``` systemctl start apache2 systemctl enable apache2 ``` ## Step 2 – Install Zimplit CMS First, download the latest version of Zimplit CMS from Github using the following command: ``` wget https://github.com/niutech/zimplitcms/archive/3.0.zip ``` Once the download is completed, unzip the downloaded file with the following command: ``` unzip 3.0.zip ``` Next, move the extracted directory to the Apache root directory: ``` mv zimplitcms-3.0 /var/www/html/zimplitcms ``` Next, set proper permissions and ownership with the following command: ``` chown -R www-data:www-data /var/www/html/zimplitcms chmod -R 775 /var/www/html/zimplitcms ``` At this point, Zimplit CMS is downloaded to the Apache root directory. ## Step 3 – Configure Apache for Zimplit CMS Next, you will need to create an Apache virtual host configuration file for Zimplit CMS. You can create it with the following command: ``` nano /etc/apache2/sites-available/zimplit.conf ``` Add the following lines: ``` ServerAdmin admin@domain.com DocumentRoot /var/www/html/zimplitcms ServerName zimplit.domain.com ErrorLog /var/log/apache2/zimplitcms-error_log CustomLog /var/log/apache2/zimplitcms-access_log common ``` Save and close the file, then activate the Zimplit virtual host with the following command: ``` a2ensite zimplit ``` Finally, restart the Apache service to apply the changes: ``` systemctl restart apache2 ``` ## Step 4 – Access Zimplit CMS Now, open your web browser and access the Zimplit CMS using the URL **http://zimplit.domain.com/zimplit.php**. You should see the following page: ![Zimplit Create Account](https://www.atlantic.net/wp-content/uploads/2021/05/p1-8.png) Provide your admin username, password, email, and click on the **Start** button. You should see the following page: ![Zimplit Accept License](https://www.atlantic.net/wp-content/uploads/2021/05/a1-1-1024x322.png) Now, accept the terms of use and type any word then click on the **OK**. Now, open a new browser window and type the URL **http://zimplit.domain.com/zimplit.php**. You should see your Zimplit CMS dashboard on the following page: ![Zimplit Dashboard](https://www.atlantic.net/wp-content/uploads/2021/05/p4-5-1024x478.png) ## Conclusion Congratulations! You have successfully installed Zimplit CMS on Ubuntu 20.04 server. You can now create a new website easily using the Zimplit CMS – try it today on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Deploy Kubernetes Cluster with Minikube on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-deploy-kubernetes-cluster-with-minikube-on-ubuntu-20-04/ | Published: 2021-06-17 | Updated: 2024-06-01 | Author: Hitesh Jethva Minikube is an open-source tool specially designed for developers to run a single-node Kubernetes cluster on their local system. Minikube starts a virtual machine and runs a Kubernetes cluster inside it. You can then test in a Kubernetes environment locally. With Minikube, you don’t need to set up multiple systems for the Kubernetes cluster. In this guide, we will show you how to set up a Kubernetes cluster with Minikube on Ubuntu 20.04. ## Step 1 – Install Required Dependencies First, you will need to install some required dependencies on your server. You can install all the dependencies using the following command: ``` apt-get install git apt-transport-https ca-certificates curl gnupg-agent software-properties-common virtualbox virtualbox-ext-pack -y ``` Once all the packages are installed, you can proceed to the next step. ## Step 2 – Install Docker CE Kubernetes requires Docker CE to be installed in your server. First, add the Docker CE repository with the following command: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add - add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" ``` Once the repository is added, install the Docker with the following command: ``` apt-get install docker-ce -y ``` Once installed, verify the Docker CE version with the following command: ``` docker --version ``` You should see the following output: ``` Docker version 20.10.7, build f0df350 ``` ## Step 3 – Install Minikube By default, the Minikube package is not included in Ubuntu, so you will need to download it from their website. Run the following command to download it: ``` wget https://storage.googleapis.com/minikube/releases/latest/minikube-linux-amd64 ``` Next, move the downloaded file to the system path: ``` mv minikube-linux-amd64 /usr/local/bin/minikube ``` Next, set execution permissions with the following command: ``` chmod +x /usr/local/bin/minikube ``` Now, verify the Minikube version with the following command: ``` minikube version ``` Output: ``` minikube version: v1.20.0 commit: c61663e942ec43b20e8e70839dcca52e44cd85ae ``` ## Step 4 – Install Kubernetes Utility Next, you will need to install Kubernetes utilities including kubectl, kubeadm, and kubectl to your server. First, add the Kubernetes repository with the following command: ``` curl -s https://packages.cloud.google.com/apt/doc/apt-key.gpg | apt-key add - echo "deb http://apt.kubernetes.io/ kubernetes-xenial main" | tee /etc/apt/sources.list.d/kubernetes.list ``` Next, update the repository and install all the utilities with the following command: ``` apt-get update -y apt-get install kubectl kubeadm kubectl -y ``` ## Step 5 – Launch Kubernetes Cluster with Minikube Now, you can start the Kubernetes cluster using the Minikube as shown below: ``` minikube start --driver=none ``` You should get the following output: ``` * minikube v1.20.0 on Ubuntu 20.04 (kvm/amd64) * Using the none driver based on user configuration * Starting control plane node minikube in cluster minikube * Running on localhost (CPUs=2, Memory=3936MB, Disk=80568MB) ... * OS release is Ubuntu 20.04 LTS * Preparing Kubernetes v1.20.2 on Docker 20.10.7 ... - kubelet.resolv-conf=/run/systemd/resolve/resolv.conf > kubectl.sha256: 64 B / 64 B [--------------------------] 100.00% ? p/s 0s > kubeadm.sha256: 64 B / 64 B [--------------------------] 100.00% ? p/s 0s > kubelet.sha256: 64 B / 64 B [--------------------------] 100.00% ? p/s 0s > kubectl: 38.37 MiB / 38.37 MiB [-------------] 100.00% 29.81 MiB p/s 1.5s > kubeadm: 37.40 MiB / 37.40 MiB [-------------] 100.00% 28.73 MiB p/s 1.5s > kubelet: 108.73 MiB / 108.73 MiB [-----------] 100.00% 42.93 MiB p/s 2.7s - Generating certificates and keys ... - Booting up control plane ... - Configuring RBAC rules ... * Configuring local host environment ... * ! The 'none' driver is designed for experts who need to integrate with an existing VM * Most users should use the newer 'docker' driver instead, which does not require root! * For more information, see: https://minikube.sigs.k8s.io/docs/reference/drivers/none/ * ! kubectl and minikube configuration will be stored in /root ! To use kubectl or minikube commands as your own user, you may need to relocate them. For example, to overwrite your own settings, run: * - sudo mv /root/.kube /root/.minikube $HOME - sudo chown -R $USER $HOME/.kube $HOME/.minikube * * This can also be done automatically by setting the env var CHANGE_MINIKUBE_NONE_USER=true * Verifying Kubernetes components... - Using image gcr.io/k8s-minikube/storage-provisioner:v5 * Enabled addons: storage-provisioner, default-storageclass * Done! kubectl is now configured to use "minikube" cluster and "default" namespace by default ``` You can check the cluster information with the following command: ``` kubectl cluster-info ``` Output: ``` Kubernetes control plane is running at https://45.58.43.101:8443 KubeDNS is running at https://45.58.43.101:8443/api/v1/namespaces/kube-system/services/kube-dns:dns/proxy To further debug and diagnose cluster problems, use 'kubectl cluster-info dump'. ``` Kubernetes stores all configuration information in the file ~/.minikube/machines/minikube/config.json. You can check it with the following command: ``` kubectl config view ``` Output: ``` apiVersion: v1 clusters: - cluster: certificate-authority: /root/.minikube/ca.crt extensions: - extension: last-update: Tue, 08 Jun 2021 11:51:58 UTC provider: minikube.sigs.k8s.io version: v1.20.0 name: cluster_info server: https://45.58.43.101:8443 name: minikube contexts: - context: cluster: minikube extensions: - extension: last-update: Tue, 08 Jun 2021 11:51:58 UTC provider: minikube.sigs.k8s.io version: v1.20.0 name: context_info namespace: default user: minikube name: minikube current-context: minikube kind: Config preferences: {} users: - name: minikube user: client-certificate: /root/.minikube/profiles/minikube/client.crt client-key: /root/.minikube/profiles/minikube/client.key ``` To check the Minikube node status, run the following command: ``` minikube status ``` Output: ``` minikube type: Control Plane host: Running kubelet: Running apiserver: Running kubeconfig: Configured ``` ## Step 6 – Enable Kubernetes Dashboard Next, you will need to enable the Kubernetes dashboard to access it from the web browser. To enable the dashboard, run the following command: ``` minikube dashboard & ``` This will start a Kubernetes dashboard on the localhost. Next, you will need to create a local proxy for access to the dashboard from the remote machine. Run the following command to create a local proxy: ``` kubectl proxy & ``` This will start a proxy on localhost on port 8001. ## Step 7 – Access Kubernetes Dashboard At this point, the Kubernetes dashboard is accessible on the localhost on port 8001. Next, you will need to set an SSH port forwarding on the client machine from where you want to access the Kubernetes cluster. On the client machine, run the following command to set an SSH port forwarding: ``` ssh -L 12345:localhost:8001 root@your-kubernetes-server-ip ``` Now, you can access your Kubernetes cluster using the URL **http://localhost:12345/api/v1/namespaces/kubernetes-dashboard/services/http:kubernetes-dashboard:/proxy/** from your web browser. ![Kubernetes Dashboard](https://www.atlantic.net/wp-content/uploads/2021/06/p1-1024x532.png) ## Conclusion Congratulations! You have successfully set up a Kubernetes cluster with Minikube on Ubuntu 20.04. You now have enough knowledge to set up a local Kubernetes cluster using Minikube. Get started with Minikube on a [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # Real-World Case Study for HIPAA Storage and Sharing: Nextcloud & HIPAA Compliance > URL: https://www.atlantic.net/hipaa-compliant-hosting/real-world-case-study-for-hipaa-storage-and-sharing-nextcloud-hipaa-compliance/ | Published: 2021-06-18 | Updated: 2025-09-19 | Author: Kent Roberts One major advantage of cloud computing is the ability to leverage huge amounts of cloud storage on demand. When you choose a HIPAA Compliant Hosting Provider like Atlantic.Net, you get Cloud Storage that meets and exceeds the complex requirements of HIPAA-Compliance. The HIPAA-Compliance Security Rule requires that any organization handling Protected Health Information (PHI) must implement appropriate cybersecurity measures to protect this information, and this includes Cloud Storage. In this case study, we take a deep dive into Nextcloud and discuss why it makes the perfect Cloud Storage solution for HIPAA-Compliance. There is no cookie-cutter solution for HIPAA; each organization is different, but Nextcloud’s appeal is its ability to offer something to all healthcare organizations. ## ![](https://www.atlantic.net/wp-content/uploads/2019/05/icon_hospital-system-needs.png) ## Hospital System Needs HIPAA-Compliant Document Collaboration and Communication While collaboration and communication are built into a huge number of tools available from Cloud Providers, the biggest problem is that the majority of them are not HIPAA-Compliant. As a result hospitals, doctors’ groups, and any company using PHI need to look elsewhere for cloud solutions. A hospital system contacted Atlantic.Net to help them set up a storage and sharing site that would meet [HIPAA compliance standards](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). The site would allow the developers to create various folders for each of the organization’s hospitals so that each could upload its patient reports. Access to this site would be limited to two users per hospital. The unique login credentials for those users would enable them to enter the site via VPN and multi-factor authentication (MFA) and download the folder and data related to their hospital while blocking them from seeing or accessing the folders of other hospitals. Atlantic.Net offered to configure and manage a server-side [HIPAA compliant storage solution](https://www.atlantic.net/hipaa-compliant-hosting/). While the infrastructure and security are from Atlantic.Net, the underlying software platform is from [Nextcloud](https://nextcloud.com/). ![](https://www.atlantic.net/wp-content/uploads/2019/05/icon_extcloud.png) ## How Does Nextcloud Help Deliver HIPAA Compliance? Nextcloud makes patient information available to healthcare professionals when they need it through an easy-to-use interface with the highest degree of reliability, security, and privacy. Nextcloud is designed for on-premise security, secure productivity, and ease of use.  You do not want the user’s experience to be complicated, especially not in the critical environment of healthcare, in which errors can have devastating consequences. Access is clear. Everything is visible to those who are authorized to see it. File Access Control (FAC) is a key capability of Nextcloud that allows organizations to maintain compliance. Through FAC, you can build policy and legal guidelines into your processes. You can create strict rules that prevent anyone who does not have proper authorization (based on various chosen characteristics) from viewing, uploading, or downloading files. Encryption is easy to implement within Nextcloud. ePHI should be encrypted (or protected via alternative means) whether it is in transit or at rest, as a best practice. Following that requirement, Nextcloud can be configured to use SSL/TLS encryption whenever data is transferred, and Atlantic.Net can provide the VPN connections to ensure all data transmitted is encrypted and safe from prying eyes. When data is at rest in storage, Atlantic.Net already takes care of encrypting your data based on the AES-256 standard – a military-grade cryptographic algorithm. Key management for this system is managed by Atlanitc.Net, so you and your team have one less issue to worry about. Nextcloud is simple to integrate with your current systems or to pair with leading [healthcare cloud offerings](https://www.atlantic.net/hipaa-compliant-hosting/). Nextcloud gives you the ability to closely monitor and log everything with or without the addition of tools such as OpenNMS, Splunk, or Nagios. Through features such as these – features to allow for a HIPAA-compliant environment – Nextcloud enhances your documents and communication security. When you partner with a HIPAA Compliant hosting company and use Nextcloud for storage, Nextcloud features all of the technical safeguards required for HIPAA Compliance. The administrative, physical, and technical safeguards built into the Atlantic.Net HIPAA-compliant hosting make the perfect platform for a Nextcloud solution. Here are some of the key features of Nextcloud: - Advanced Access Control capabilities - Automatic expiration of passwords - Account lockout upon multiple failed log-in attempts - Automatic virus scans - Secure data backups - Audit-ready logging of all user actions - Data-at-rest, in-transit, and full end-to-end encryption - Email verification and multi-factor authentication ![](https://www.atlantic.net/wp-content/uploads/2019/05/icon_ease-of-use-e1623951057437.png) ### User-Friendly HIPAA Compliant experience Nextcloud’s offering gives you integration for better overall productivity. The Nextcloud clients deliver a seamless experience regardless of the means of access throughout all your desktop and mobile devices. Your team can collaborate on files in real-time, perform secure video and audio calls, and perform secure chat. Nurses and doctors are able simply to locate files and revert files to earlier saved versions. Together, these capabilities improve productivity as they enhance security. ![](https://www.atlantic.net/wp-content/uploads/2019/05/icon_hipaa-security-rule.png) ## HIPAA Security Rule and the Cloud To understand this healthcare platform, it helps to review HIPAA itself. At the core of HIPAA, particularly for digital systems, is the Security Rule, which takes the patient privacy rights established in the Privacy Rule and protects them through a mandate for technical, administrative, and physical safeguards. These designations are a bit broader than they may first seem. For instance, technical protections refer to not only data-safeguarding tools (such as a virtual private network) but also policies and procedures applicable to those tools. HIPAA protections must be robust, whether they are in public, private, or hybrid cloud models; the Department of Health and Human Services stipulates that the business associate agreement (BAA) of a provider should reflect the nature of the environment, with risk evaluation revealing necessary points of focus for the BAA. ![](https://www.atlantic.net/wp-content/uploads/2019/05/icon_cloud-security.png) ## Strengthening Cloud Security Cloud Computing has built a firm reputation of being a highly secure environment, and the Atlantic.Net HIPAA Compliant cloud has been built from the group up to be a security-defined infrastructure. It starts with our data centers. These buildings are more like secure compounds; each is monitored 24×7 and has ever-present security personnel. CCTV, door access controls, and access to the premises are closely monitored and audited. The technical solution is architected to the highest security standards. Network segregation, encryption, and managed firewalls are just the start. Atlantic.Net’s approach to cloud security meets and exceeds all HIPAA security and privacy requirements. If you choose to self-host Nextcloud, consider these two critical concerns: ### ![](https://www.atlantic.net/wp-content/uploads/2019/05/icon_confront-e1623951120372.png) ### How Do You Handle the Insider Threat? Time and resources invested in security often go toward high-end security tools that use artificial intelligence, machine learning, and other cutting-edge technologies. You can only put so much trust in those systems, though. It is important to recognize that hacking efforts such as social engineering can specifically target your people as a way into your organization. Human error is a serious concern. This might be caused by inadequate training or by a genuine mistake. Employees may unintentionally not follow proper mitigation or authentication steps when handling PHI.  All of these problems go away when you choose to outsource to Atlantic.Net. ### ![](https://www.atlantic.net/wp-content/uploads/2019/05/icon_adapt-challenge.png)Adapt to the Ongoing and Evolving Challenge You may not reach perfection when it comes to cybersecurity or healthcare compliance – especially given the increasing complexity of IT systems that now typically include internally supported systems integrated with those of Cloud Hosts and other Managed Service Providers. You simply need to minimize risk in any way possible. ## ![](https://www.atlantic.net/wp-content/uploads/2019/05/icon_hipaa-compliant-cloud-storage.png)Your HIPAA-Compliant Cloud Storage Did you know you can easily use Nextcloud on Atlantic.Net? We have 1-click Nextcloud applications that install in under 30 seconds with no configuration to be done by you; simply spin up the Nextcloud server (it takes about 2 or 3 clicks) and then connected to your Nextcloud website. It’s that simple!  This allows you to test it out, and once you are ready, our specialized team of security engineers deploys your HIPAA-compliant environment for you.   At Atlantic.Net we help you reduce risk through access to our tested, trusted healthcare solutions. Our one-click Nextcloud app allows you to integrate server-side compliance seamlessly into your IT approach. See our [HIPAA-compliant cloud hosting & storage](https://www.atlantic.net/hipaa-compliant-hosting/). --- # How to Install the Helm Kubernetes Package Manager on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-the-helm-kubernetes-package-manager-on-ubuntu-20-04/ | Published: 2021-06-19 | Updated: 2024-06-02 | Author: Hitesh Jethva After deploying the Kubernetes cluster, configuring and deploying applications and services on the Kubernetes cluster are very complicated processes. Helm is a Kubernetes package manager that helps to streamline the installation and management of applications. It allows you to search and install software built for Kubernetes. It uses Helm charts to make your deploying process easier. In this post, we will show you how to install and use Helm Kubernetes package manager on Ubuntu 20.04. ## Step 1 – Install Helm By default, the Helm package is not included in the Ubuntu default repository, so you will need to install it from the installation script provided by Helm. First, download the Helm installation script with the following command: ``` curl -fsSL -o get_helm.sh https://raw.githubusercontent.com/helm/helm/master/scripts/get-helm-3 ``` Once the script is downloaded, set execution permissions with the following command: ``` chmod +x get_helm.sh ``` Next, install the Helm package with the following command: ``` ./get_helm.sh ``` You should get the following output: ``` Downloading https://get.helm.sh/helm-v3.6.0-linux-amd64.tar.gz Verifying checksum... Done. Preparing to install helm into /usr/local/bin helm installed into /usr/local/bin/helm ``` Once Helm is installed, verify the installed version of Helm with the following command: ``` helm version ``` You should get the following output: ``` version.BuildInfo{Version:"v3.6.0", GitCommit:"7f2df6467771a75f5646b7f12afb408590ed1755", GitTreeState:"clean", GoVersion:"go1.16.3"} ``` To list all command options available in Helm, run the following command: ``` helm ``` Output: ``` Usage: helm [command] Available Commands: completion generate autocompletion scripts for the specified shell create create a new chart with the given name dependency manage a chart's dependencies env helm client environment information get download extended information of a named release help Help about any command history fetch release history install install a chart lint examine a chart for possible issues list list releases package package a chart directory into a chart archive plugin install, list, or uninstall Helm plugins pull download a chart from a repository and (optionally) unpack it in local directory repo add, list, remove, update, and index chart repositories rollback roll back a release to a previous revision search search for a keyword in charts show show information of a chart status display the status of the named release template locally render templates test run tests for a release uninstall uninstall a release upgrade upgrade a release verify verify that a chart at the given path has been signed and is valid version print the client version information ``` ## Step 2 – How to Use Helm In this section, we will show you how to use the Helm command to manage packages. If you want to search for a specific chart, run the following command: ``` helm search hub apache ``` You should get the following output: ``` URL CHART VERSION APP VERSION DESCRIPTION https://artifacthub.io/packages/helm/bitnami/ap... 8.5.5 2.4.48 Chart for Apache HTTP Server https://artifacthub.io/packages/helm/cloudposse... 0.1.3 Apache Helm chart for Kubernetes https://artifacthub.io/packages/helm/apache-iot... 0.1.0 0.11.2 A Helm chart for Apache IoTDB https://artifacthub.io/packages/helm/pfisterer-... 0.1.9 1.5.0 Apache Knox https://artifacthub.io/packages/helm/gh-shessel... 1.0.22 5.7.2 Web publishing platform for building blogs and ... https://artifacthub.io/packages/helm/psu-swe/co... 0.9.0 1.0 A Helm chart for Kubernetes https://artifacthub.io/packages/helm/apache-sol... 0.3.0 v0.3.0 The Solr Operator enables easy management of So... https://artifacthub.io/packages/helm/apache-air... 1.0.0 2.0.2 Helm chart to deploy Apache Airflow, a platform... https://artifacthub.io/packages/helm/apache/pulsar 2.7.2 2.7.2 Apache Pulsar Helm chart for Kubernetes ``` To search a repo for Apache, run the following command: ``` helm search repo apache ``` You should get the following error: ``` Error: no repositories configured ``` Now, you can add a stable repository to your system using the following command: ``` helm repo add stable https://charts.helm.sh/stable ``` Output: ``` "stable" has been added to your repositories ``` Now, search the Apache repo again with the following command: ``` helm search repo apache ``` Output: ``` NAME CHART VERSION APP VERSION DESCRIPTION stable/hadoop 1.1.4 2.9.0 DEPRECATED - The Apache Hadoop software library... stable/ignite 1.2.2 2.7.6 DEPRECATED - Apache Ignite is an open-source di... stable/jenkins 2.5.4 lts DEPRECATED - Open source continuous integration... stable/kafka-manager 2.3.5 1.3.3.22 DEPRECATED - A tool for managing Apache Kafka. stable/spark 0.1.2 A Apache Spark Helm chart for Kubernetes. Apach... stable/superset 1.1.13 0.36.0 DEPRECATED - Apache Superset (incubating) is a ... ``` To list all repositories which you have added, run the following command: ``` helm repo list ``` Output: ``` NAME URL stable https://charts.helm.sh/stable ``` ## Step 3 – Deploy Jenkins with Helm In this section, we will show you how to install Jenkins on the Kubernetes cluster with Helm. First, you will need to add the Bitnami repository to your system. Run the following command to add the repository: ``` helm repo add bitnami https://charts.bitnami.com/bitnami ``` Output: ``` "bitnami" has been added to your repositories ``` Now, check the added repository with the following command: ``` helm repo list ``` Output: ``` NAME URL stable https://charts.helm.sh/stable bitnami https://charts.bitnami.com/bitnami ``` Next, install Jenkins on the Kubernetes cluster with the following command: ``` helm install my-jenkins bitnami/jenkins ``` You should get the following output: ``` NAME: my-jenkins LAST DEPLOYED: Mon Jun 7 06:48:32 2021 NAMESPACE: default STATUS: deployed REVISION: 1 TEST SUITE: None NOTES: ** Please be patient while the chart is being deployed ** 1. Get the Jenkins URL by running: ** Please ensure an external IP is associated to the my-jenkins service before proceeding ** ** Watch the status using: kubectl get svc --namespace default -w my-jenkins ** export SERVICE_IP=$(kubectl get svc --namespace default my-jenkins --template "{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}") echo "Jenkins URL: http://$SERVICE_IP/" 2. Login with the following credentials echo Username: user echo Password: $(kubectl get secret --namespace default my-jenkins -o jsonpath="{.data.jenkins-password}" | base64 --decode) ``` Note: Please remember the “Username: user” from the above output. Next, verify the Jenkins with the following command: ``` kubectl get svc --namespace default -w my-jenkins ``` Output: ``` NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE my-jenkins LoadBalancer 10.106.248.146 80:31006/TCP,443:30067/TCP 73s ``` Next, get the Jenkins admin user password with the following command: ``` kubectl get secret --namespace default my-jenkins -o jsonpath="{.data.jenkins-password}" | base64 --decode ``` Output: ``` EOzueJ3jqX ``` ## Step 4 – Access Jenkins Now, open your web browser and access Jenkins using the URL http://your-server-ip:31006. You should see the following page: ![Jenkins Login Page](https://www.atlantic.net/wp-content/uploads/2021/06/p1-1-1024x565.png) Provide your admin username, password and click on the **Sign In** button. You should see the Jenkins dashboard on the following page: ![Jenkins Dashboard Page](https://www.atlantic.net/wp-content/uploads/2021/06/p2-1024x531.png) To list your Jenkins namespace, run the following command: ``` helm ls ``` Output: ``` NAME NAMESPACE REVISION UPDATED STATUS CHART APP VERSION my-jenkins default 1 2021-06-07 06:48:32.145492504 +0000 UTC deployed jenkins-8.0.1 2.289.1 ``` To remove your Jenkins namespace, run the following command: ``` helm delete my-jenkins ``` Output: ``` release "my-jenkins" uninstalled ``` ## Conclusion In the above guide, you learned how to install and manage packages in the Kubernetes cluster with Helm in order to make your package management process easier. Try Helm Kubernetes Package Manager on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Deploy and Run Redis in Docker > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-deploy-and-run-redis-in-docker/ | Published: 2021-06-20 | Updated: 2023-11-15 | Author: Hitesh Jethva Redis is an open-source, fast, and in-memory key-value data store. It can be used as a database, cache, message broker, and queue. Redis is designed for distributed cluster environment and it can handle large datasets. Deploying Redis in a Docker container will help to scale Redis and fit it right into your development environment. In this post, we will show you how to deploy Redis with Docker on Ubuntu 20.04. ## Step 1 – Install Docker By default, the latest version of Docker is not included in the Ubuntu default repository, so you will need to add the Docker official repository to your system. First, install all required dependencies using the following command: ``` apt-get install apt-transport-https ca-certificates curl gnupg-agent software-properties-common -y ``` Next, add the Docker repository with the following command: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add - add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" ``` Once the repository is added, install Docker with the following command: ``` apt-get install docker-ce -y ``` Once Docker is installed, check the status of Docker with the following command: ``` systemctl status docker ``` Output: ``` ● docker.service - Docker Application Container Engine Loaded: loaded (/lib/systemd/system/docker.service; enabled; vendor preset: enabled) Active: active (running) since Mon 2021-06-07 07:14:36 UTC; 13s ago TriggeredBy: ● docker.socket Docs: https://docs.docker.com Main PID: 9081 (dockerd) Tasks: 10 Memory: 41.0M CGroup: /system.slice/docker.service └─9081 /usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock ``` ## Step 2 – Download Redis Image Next, you will need to download the latest version of the Redis image from the Docker registry. You can download it with the following command: ``` docker pull redis:latest ``` Output: ``` latest: Pulling from library/redis 69692152171a: Pull complete a4a46f2fd7e0: Pull complete bcdf6fddc3bd: Pull complete 2902e41faefa: Pull complete df3e1d63cdb1: Pull complete fa57f005a60d: Pull complete Digest: sha256:7e2c6181ad5c425443b56c7c73a9cd6df24a122345847d1ea9bb86a5afc76325 Status: Downloaded newer image for redis:latest docker.io/library/redis:latest ``` You can now verify the downloaded image with the following command: ``` docker images ``` Output: ``` REPOSITORY TAG IMAGE ID CREATED SIZE redis latest fad0ee7e917a 5 days ago 105MB ``` ## Step 3 – Launch Redis Container Next, you will need to launch a Redis container from the downloaded image. You can launch it with the following command: ``` docker run --name redis-instance -dit redis ``` Output: ``` 2e7b27647159791d589cbfd55ce3503b8e4cae56b79eaecedeff77cb1824904a ``` Once the container is started, you can check it with the following command: ``` docker ps ``` You should see the following output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 2e7b27647159 redis "docker-entrypoint.s…" 11 seconds ago Up 9 seconds 6379/tcp redis-instance ``` As you can see, the Redis container is started and listening on port 6379. ## Step 4 – Connect the Redis Container Next, you can connect to the Redis container with the following command: ``` docker exec -it redis-instance /bin/bash ``` Once you are connected, you should see the following shell: ``` root@2e7b27647159:/data# ``` Now, connect to the Redis interface with the following command: ``` root@2e7b27647159:/data# redis-cli ``` Output: ``` 127.0.0.1:6379> ``` Now, test the Redis with the ping command: ``` 127.0.0.1:6379> ping ``` If everything is fine, you should see the following output: ``` PONG ``` Run the quit command to exit from the Redis CLI. ``` 127.0.0.1:6379> quit ``` Next, exit from the Redis container with the following command: ``` root@2e7b27647159:/data# exit ``` ## Conclusion Congratulations! You have successfully deployed a Redis within a Docker container. You can now use this setup to deploy and scale a Redis within a Docker cluster on your [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) account from Atlantic.Net. --- # How to Deploy NGINX Reverse Proxy in Docker on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-deploy-nginx-reverse-proxy-in-docker-on-ubuntu-20-04/ | Published: 2021-06-21 | Updated: 2024-06-01 | Author: Hitesh Jethva Proxy is very useful in a development environment when you need to expose several ports to access different modules of the application. You can use Reverse Proxy to access different modules of the application through the same URL. It will also help you to access the backend, frontend, and other services using a single domain name. In this post, we will set up two websites inside two Docker containers, then set up an Nginx reverse proxy to access both websites. ## Prerequisites - A fresh Ubuntu 20.04 server on the Atlantic.Net Cloud Platform - A root password configured on your server **For the purposes of this tutorial, we will use the following directory structure:** ``` ├── proxy │   ├── backend-not-found.html │   ├── default.conf │   ├── docker-compose.yml │   ├── Dockerfile │   ├── includes │   │   ├── proxy.conf │   │   └── ssl.conf │   └── ssl │   ├── website1.crt │   ├── website1.key │   ├── website2.crt │   └── website2.key ├── website1 │   ├── docker-compose.yml │   └── index.html └── website2 ├── docker-compose.yml └── index.html ``` ## Step 1 – Set Up a Host File First, you will need to edit the /etc/hosts file and bind both website domains with the IP address: ``` nano /etc/hosts ``` Add the following lines: ``` your-server-ip website1.test your-server-ip website2.test ``` Save and close the file when you are finished. ## Step 2 – Install Docker and Docker Compose First, you will need to install some required dependencies on your server. You can install them with the following command: ``` apt-get install git apt-transport-https ca-certificates curl gnupg-agent software-properties-common -y ``` After installing all of them, add the Docker repository with the following command: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add - add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" ``` Once the repository is added, install Docker and Docker Compose with the following command: ``` apt-get install docker-ce docker-compose -y ``` After installing both packages, you can proceed to the next step. ## Step 3 – Create a First Website Container First, create a directory to host your first website container. ``` mkdir website1 ``` Next, change the directory to website1 and create a docker-compose.yml file: ``` cd website1 nano docker-compose.yml ``` Add the following lines: ``` version: '2' services: app: image: nginx volumes: - .:/usr/share/nginx/html ports: - "80" ``` Save and close the file when you are finished. Next, create an Index page for your website. ``` nano index.html ``` Add the following lines: ``` First Website

Hello! This is my first website.

``` Save and close the file then launch your website1 container with the following command: ``` docker-compose build docker-compose up -d ``` This will download an Nginx image, launch a container, and expose it on port 80. ``` Creating network "website1_default" with the default driver Pulling app (nginx:)... latest: Pulling from library/nginx 69692152171a: Already exists 30afc0b18f67: Pull complete 596b1d696923: Pull complete febe5bd23e98: Pull complete 8283eee92e2f: Pull complete 351ad75a6cfa: Pull complete Digest: sha256:6d75c99af15565a301e48297fa2d121e15d80ad526f8369c526324f0f7ccb750 Status: Downloaded newer image for nginx:latest Creating website1_app_1 ... done ``` ## Step 4 – Create a Second Website Container First, create a directory to host your second website container. ``` cd mkdir website2 ``` Next, change the directory to website2 and create a docker-compose.yml file: ``` cd website2 nano docker-compose.yml ``` Add the following lines: ``` version: '2' services: app: image: nginx volumes: - .:/usr/share/nginx/html ports: - "80" ``` Save and close the file, then create an Index page for the second website. ``` nano index.html ``` Add the following lines: ``` Second Website

Hello! This is my second website.

``` Save and close the file, then launch your website2 container with the following command: ``` docker-compose build docker-compose up -d ``` You should see the following output: ``` Creating network "website2_default" with the default driver Creating website2_app_1 ... done ``` You can now verify both website containers with the following command: ``` docker ps ``` You should get the following output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 01e83ba3a3dd nginx "/docker-entrypoint.…" About a minute ago Up About a minute 0.0.0.0:49154->80/tcp, :::49154->80/tcp website2_app_1 75207f53411c nginx "/docker-entrypoint.…" 2 minutes ago Up 2 minutes 0.0.0.0:49153->80/tcp, :::49153->80/tcp website1_app_1 ``` ## Step 5 – Set up Reverse Proxy Container First, create a new proxy directory with the following command: ``` cd mkdir proxy ``` Next, change the directory to proxy and create a Dockerfile for a new custom image: ``` cd proxy nano Dockerfile ``` Add the following lines: ``` FROM nginx COPY ./default.conf /etc/nginx/conf.d/default.conf COPY ./backend-not-found.html /var/www/html/backend-not-found.html COPY ./includes/ /etc/nginx/includes/ COPY ./ssl/ /etc/ssl/certs/nginx/ ``` Save and close the file, then create a backend index file for a not found response. ``` nano backend-not-found.html ``` Add the following lines: ``` Proxy Backend Not Found

Proxy Backend Not Found

``` Save and close the file, then create an Nginx default configuration file: ``` nano default.conf ``` Add the following lines: ``` server { listen 80; listen 443 ssl http2; server_name website1.test; # Path for SSL config/key/certificate ssl_certificate /etc/ssl/certs/nginx/website1.crt; ssl_certificate_key /etc/ssl/certs/nginx/website1.key; include /etc/nginx/includes/ssl.conf; location / { include /etc/nginx/includes/proxy.conf; proxy_pass http://website1_app_1; } access_log off; error_log /var/log/nginx/error.log error; } # web service2 config. server { listen 80; listen 443 ssl http2; server_name website2.test; # Path for SSL config/key/certificate ssl_certificate /etc/ssl/certs/nginx/website2.crt; ssl_certificate_key /etc/ssl/certs/nginx/website2.key; include /etc/nginx/includes/ssl.conf; location / { include /etc/nginx/includes/proxy.conf; proxy_pass http://website2_app_1; } access_log off; error_log /var/log/nginx/error.log error; } # Default server { listen 80 default_server; server_name _; root /var/www/html; charset UTF-8; error_page 404 /backend-not-found.html; location = /backend-not-found.html { allow all; } location / { return 404; } access_log off; log_not_found off; error_log /var/log/nginx/error.log error; } ``` Save and close the file when you are finished. Next, create a docker-compose.yml file to launch a proxy container: ``` nano docker-compose.yml ``` Add the following lines: ``` version: '2' services: proxy: build: ./ networks: - website1 - website2 ports: - 80:80 - 443:443 networks: website1: external: name: website1_default website2: external: name: website2_default ``` Save and close the file when you are finished. Next, you will need to generate an SSL certificate and key for both websites. First, create an SSL directory within your proxy directory: ``` mkdir ssl ``` Next, change the directory to ssl and generate ssl certificates and keys with the following command: ``` cd ssl openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout website1.key -out website1.crt openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout website2.key -out website2.crt ``` Next, go back to your proxy directory and create an includes directory: ``` cd .. mkdir includes ``` Next, change the directory to includes and create a proxy configuration file: ``` cd includes nano proxy.conf ``` Add the following lines: ``` proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_buffering off; proxy_request_buffering off; proxy_http_version 1.1; proxy_intercept_errors on; ``` Save and close the file, then create an ssl.conf file: ``` nano ssl.conf ``` Add the following lines: ``` ssl_session_timeout 1d; ssl_session_cache shared:SSL:50m; ssl_session_tickets off; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHAECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS'; ssl_prefer_server_ciphers on; ``` Save and close the file when you are finished. Next, go back to the proxy directory and build the proxy container with the following command: ``` cd .. docker-compose build ``` You should see the following output: ``` Building proxy Step 1/5 : FROM nginx ---> d1a364dc548d Step 2/5 : COPY ./default.conf /etc/nginx/conf.d/default.conf ---> d70a72d6011f Step 3/5 : COPY ./backend-not-found.html /var/www/html/backend-not-found.html ---> 1cb5af66233f Step 4/5 : COPY ./includes/ /etc/nginx/includes/ ---> 7c18f2753b1e Step 5/5 : COPY ./ssl/ /etc/ssl/certs/nginx/ ---> ebb0447a1317 Successfully built ebb0447a1317 Successfully tagged proxy_proxy:latest ``` Next, launch the proxy container with the following command: ``` docker-compose up -d ``` Output: ``` Creating proxy_proxy_1 ... done ``` You can now verify your all containers with the following command: ``` docker ps -a ``` You should get the following output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES c413da7e85ba proxy_proxy "/docker-entrypoint.…" 16 seconds ago Up 15 seconds 0.0.0.0:80->80/tcp, :::80->80/tcp, 0.0.0.0:443->443/tcp, :::443->443/tcp proxy_proxy_1 01e83ba3a3dd nginx "/docker-entrypoint.…" 52 minutes ago Up 52 minutes 0.0.0.0:49154->80/tcp, :::49154->80/tcp website2_app_1 75207f53411c nginx "/docker-entrypoint.…" 53 minutes ago Up 53 minutes 0.0.0.0:49153->80/tcp, :::49153->80/tcp website1_app_1 ``` ## Step 6 – Check the Nginx Reverse Proxy At this point, both the website and proxy container are started successfully. Now, it’s time to test it. First, your first website using the following command: ``` curl website1.test ``` If everything is fine, you should see your first website page: ``` First Website

Hello! This is my first website.

``` Now, test your second website with the following command: ``` curl website2.test ``` If everything is fine, you should see your second website page: ``` Second Website

Hello! This is my second website.

``` ## Conclusion In the above guide, you learned how to set up an Nginx reverse proxy container for two websites within a Docker container. This should help you to deploy an application in the development environment; try it on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # Why Is Atlantic.Net the Right Choice Over Other Cloud Providers? Part 1 of 3 > URL: https://www.atlantic.net/vps-hosting/why-is-atlantic-net-the-right-choice-over-other-cloud-providers-part-1-of-3/ | Published: 2021-06-22 | Updated: 2025-09-19 | Author: Richard Bailey ## Part 1: Performance and Technology In this blog series, we will be focusing on some of the many advantages that Atlantic.Net has over its competitors in the cloud computing sector. While Atlantic.Net is not the largest cloud provider, we are absolutely a major leader in our sector. Businesses of all sizes utilize Atlantic.Net, especially small and medium businesses who trust Atlantic.Net to power their business ventures. We serve countless startups and personal users looking to maximize their bang-for-buck. We also have a significant number of US healthcare organizations that trust Atlantic.Net to provide always-available HIPAA-compliant hosting services. Where would we be without our outstanding healthcare professionals over the last 14 months? As a business, we are extremely proud that they trust Atlantic.Net to get the job done. The Atlantic.Net Cloud Platform (ACP) has grown into a global cloud community supporting tens of thousands of businesses around the world on their cloud journey. Users choose Atlantic.Net for our global presence, cost savings, our technical support, and the unprecedented performance of our cloud platform. We may not be the biggest cloud provider, but our size gives us many advantages over hyper-scale cloud providers. ## The Atlantic.Net Difference ### Cloud Performance Atlantic.Net invests heavily in technology and cloud hardware. Our data centers are built and managed to exact standards. Security is paramount to us, as we provide hosting and support in heavily regulated industries, such as healthcare and payment services, which requires an infrastructure that is designed to be high performing, fault-tolerant, and inherently secure both internally and externally. The entire cloud environment runs on the latest generation of Intel and AMD hardware, all host storage systems run a minimum of SSD for superb data transfer rates, and the network layer operates on carrier-neutral data center facilities, consisting of multiple top tiered network providers. Our system is designed to automatically select the fastest route to transfer your data. ### Cloud Security Technology Cloud security is essential for every cloud provider. While many of the big players in cloud hosting give you the tools, you must then go and implement the security yourself. That might be fine if you are a Certified Cloud Engineer, but may not be so good if you don’t have a degree in computer science. Atlantic.Net’s managed services help take away this complexity. Not only is the cloud platform secured by specialist Atlantic.Net engineers, but our support teams will also make sure your MFA is configured correctly and help to manage the containment, flow, and security of data in your cloud environment. This will save you time, effort, and resources, enabling you to focus on their core business. Atlantic.Net’s Data Center infrastructure is routinely inspected and is fully audited and SOC 2 TYPE II and SOC 3 TYPE II certified. Rest assured, your systems are secure with Atlantic.Net Hosting Solutions. Utilizing our solutions eliminates regulation concerns, as we offer PCI, HIPAA, HITECH, and SOC 2 TYPE II and SOC 3 TYPE II compliance. We take care of regulatory compliance so that you can focus on growing your business. This approach greatly improves resource utilization and decreases overall operational costs. If you are a healthcare customer, you can opt for an Intrusion Protection System. This system requires high-performance networking equipment (provided by Atlantic.Net) to enable superfast throughput, with performance so fast it’s impossible to tell that each packet of data hitting the network goes through deep packet inspection! ### Cost Incentives Cost is hugely important to our customers, so we work hard to provide extremely competitive pricing on all of our cloud plans. We also understand that customers want the latest and greatest hardware as part of their cloud services. Each plan offers great value for money, especially when you consider the infrastructure that underpins the service. We used the [AWS price calculator](https://calculator.aws/#/addService) to compare our prices with AWS. | | **AWS** | **Atlantic.Net** | | --- | --- | --- | | **Location** | N. Virginia | N. Virginia | | **Uptime Guarantee** | 99.95% | 100% | | **Instance Type** | a1.2xlarge | G3.16GB | | **vCPU** | 8 | 6 | | **RAM** | 16GB | 16GB | | **Storage** | 320GB gp3 | 320GB SSD | | **Network** | up to 10GB | Up to 7,000GB | | **Cost per month** **(on-demand)** | $174 | $80 | *Note: Query ran on 16th May 2021. We decided to omit the AWS Miami data center which is geographically much closer to our Florida data center. However, AWS Miami was significantly more expensive.* While it’s true that you get 2 extra cores with AWS, the storage speed is comparable and the RAM is identical. But importantly, the price for AWS is significantly inflated. You can decide for yourself, but we believe this demonstrates significant value to our customers. ### Technical Support One factor often overlooked when choosing a cloud provider is the available support services. Some users may never have to call technical support, but it’s important to have a team of knowledgeable professionals available 24x7x365 just in case. Many of the bigger cloud providers hide their technical support behind a premium support paywall, and smaller consumers have to wait a lengthy period for a successful response. Having USA-based tech support also helps with HIPAA-Compliance and other regulations. When dealing with such requirements, it helps to ensure that your data doesn’t leave the country or is handled by someone outside the country. Our support team stands ready to assist you and is always a call or message away. We provide professional support 24/7/365 via phone and email. You have full access to a dedicated support team capable of solving any technical problem you throw their way. Atlantic.Net is different from many providers in that all our support personnel are based in the United States. We provide American jobs for American people and our teams are available around the clock. The Atlantic.Net team has earned national recognition for the company’s growth and superior customer service. We extend our gratitude to our business partners and loyal customers for helping us rise to the top! ## Atlantic.Net: The Right Size for Your Cloud Server Hosting Needs At Atlantic.Net, we partner with you to develop cloud hosting solutions tailored to your needs. We’re big enough to offer enterprise-level solutions and small enough to care about what you want by providing just the right amount of guidance. We bring you reliable, high-quality services and support at reasonable prices with well-located data centers like our Ashburn/Reston hosting data center. Contact us and learn more about why we’re the right size for your cloud server and [virtual private server hosting](https://www.atlantic.net/vps-hosting/) needs. --- # Why Is Atlantic.Net the Right Choice Over Other Cloud Providers? Part 2 of 3 > URL: https://www.atlantic.net/hipaa-compliant-hosting/why-is-atlantic-net-the-right-choice-over-other-cloud-providers-part-2-of-3/ | Published: 2021-06-23 | Updated: 2025-09-19 | Author: Richard Bailey ## Part 2: Compliance Hosting This is part 2 of our blog mini-series, “Why Is Atlantic.Net the Right Choice Over Other Cloud Providers?” This time, we’ll explore how Atlantic.Net is leagues ahead when it comes to compliance hosting. Throughout our 30 years in business, Atlantic.Net has helped countless businesses reach the required standards for different types of compliance hosting. Many of the goals required to achieve a compliant status are extremely difficult to achieve in-house for most IT teams, which means partnering with a Cloud Hosting Provider that specializes in this field is an important consideration. ## What Do We Mean by Compliance Hosting? Two main types of compliance impact our customers. The first is when government legislation imposes a legal requirement to reach a required level of standards for IT services to be authorized to operate in this sector. Healthcare and legal are two industries that are heavily regulated by the US Government. The second type of compliance is a recommended compliance to meet and exceed industry standards. While there are no legal government requirements to become compliant with these types of standards, more often than not, these standards must be achieved to provide or access a specific IT service. The financial sector is one such industry, as banks and merchants require certain levels of security and protection to use their services. ## What Compliance Hosting Does Atlantic.Net Provide? There are three key industries that Atlantic.Net serves with Compliance hosting and solutions. These are: - [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) for the US healthcare industry - [Pharma and biotech solutions](https://www.atlantic.net/life-sciences-pharma-biotech/) - [PCI-compliant hosting](https://www.atlantic.net/pci-compliant-hosting/) for anyone using payment cards We will go into detail about these three specializations a little later, but it’s important for us to demonstrate our capabilities in these industries. We take our certifications and partnerships seriously and take pride in our accreditations from some of the biggest names in the industry. ## What Accreditations Does Atlantic.Net Have? **HIPAA Audited** – We are HIPAA Audited for our hosting solutions and data centers. Our support, management, and business processes are fully compliant with HIPAA standards, making us the best choice for your healthcare hosting needs **HITECH Audited** – Atlantic.Net is audited and compliant with the Health Information Technology for Economic and Clinical Health Act (HITECH) standards for privacy and security of confidential Electronic Health Record (EHR) data. This certification ensures we are the best choice for your healthcare hosting and data confidentiality requirements. **PCI-DSS Ready** – Atlantic.Net’s hosting solutions are PCI ready to help you conduct all of your online business needs. We provide secure, robust, and proven network and compute architecture to help your company become PCI-compliant for the added security of your online transactions. These are the big three standards that Atlantic.Net are well known for, but we are also AICPA SOC 2 and SOC 3 audited. These accreditations ensure that Atlantic.Net provide information management and network technology assurance that adheres to AICPA best practice and ethical standards and that our internal controls, security policies, data processing, and client confidentiality among the highest standards available for a managed service provider ## HIPAA-Compliant Hosting One key factor that makes Atlantic.Net better than other providers is our world-class healthcare hosting. We are famous for HIPAA-compliant solutions and are proud to host an extensive number of US healthcare organizations in our US data centers. We offer fully managed HIPAA compliant hosting solutions for all of your HIPAA servers, and our high-performance website, database, and storage servers are available in both Dedicated and HIPAA Compliant Cloud environments backed by our 100% uptime guarantee. Head over to our [main HIPAA-Compliant hosting page](https://www.atlantic.net/hipaa-compliant-hosting/) to get extensive details about all of the HIPAA-Compliant services we provide. ## Pharma and Biotech Solutions Atlantic.Net has a growing relationship with universities, researchers, and the life science industry. This is for two reasons. First, our HIPAA-Compliant standards are a great match for Pharma and Biotech, and a great way to ensure privacy standards are achieved. Second, the sheer performance of the Atlantic.Net Cloud Platform (ACP) is perfect for on-demand research. More and more biotech businesses are offloading their workloads to our cloud computing to speed up their results. Partnering with a highly regulated managed hosting provider can help life science companies drive innovation, boost global collaboration, and deliver enhanced security and compliance. With a significant number of heavily regulated healthcare clients, Atlantic.Net provides a secure, reliable, and affordable HIPAA cloud hosting environment – perfect for life sciences organizations that work with healthcare big data. ## PCI Hosting Solutions The payment card industry is growing as more businesses focus online. If your business accepts credit card payments, we’ve got you covered with PCI-compliant cloud hosting. You can focus on running your business knowing your cloud VPS is securely and properly handling your customers’ sensitive credit card information when passing through credit card payments on your website or app. ## The Atlantic.Net Difference The biggest difference between Atlantic.Net and our competitors is that our services are personal, and we don’t offer a cookie-cutter, one-size-fits-all solution, unlike the hyper-scale cloud providers. Atlantic.Net knows that each customer is different. We don’t just give you the platform; we provide the entire wrap-around service to customize the solution for your needs. Atlantic.Net partners with you to develop cloud hosting solutions tailored to your needs. We’re big enough to offer enterprise-level solutions and agile enough to care about what you want by providing just the right amount of guidance, and if you need help, our US-based support teams are available 24x7x365 We bring you reliable, high-quality services and support at reasonable prices with well-located data centers like our Ashburn, San Francisco, New York, and more hosting data centers. Contact us and learn more about why we’re the right size for your [complaint server hosting](https://www.atlantic.net/compliance-hosting/) needs. --- # Atlantic.Net Expands the Free G3.2GB Promo in Dallas and London Data Center > URL: https://www.atlantic.net/press-releases/atlantic-net-expands-the-free-g3-2gb-promo-in-dallas-and-london-data-center/ | Published: 2021-06-24 | Author: Editorial Team **Free G3.2GB Cloud VPS Hosting is now available in Texas and UK data centers for one full year** **ORLANDO, FLA. (June 24, 2021)** – Atlantic.Net, a leading cloud services provider, expanded their offer enabling new cloud VPS customers to double their server resources at no extra cost. Atlantic.Net will upgrade all cloud plans to the capabilities of the next highest price bracket at no additional cost for new customers at all its data centers. This program also includes Atlantic.Net’s Free-to-Use for One Year Server promotion, meaning that any new free tier users will be automatically upgraded from 1GB to 2GB Cloud Server usage for one full year. “Our G3 plans offer more powerful and cost-effective Cloud Severs which should help attract growth customers and make it an easier choice for existing customers to expand their business with us.,” said Marty Puranik, CEO and Founder of Atlantic.Net. “We are excited to continue to offer entrepreneurs a full year of free service.” Atlantic.Net initially offered the new program in Orlando, New York, Ashburn, Toronto, and San Francisco, but has now expanded it to Dallas and London. Customers will be able to take advantage of the G3 plans with double the memory and 1TB more outbound data transfer than the G2 plans. Some plans have better vCPU and disk space, and three larger 48 GB, 96 GB, and 192 GB RAM plans are also newly available. The Atlantic.Net Cloud Platform, which is engineered to provide fault-tolerant, ultra-fast performance, includes award-winning Cloud Servers, Secure Block Storage, one-click applications, DNS, dedicated private nodes, private networking, RESTful API, data backup, a full suite of managed services, 24/7/365 expert U.S.-based support, and more. This infrastructure is ideally suited to support businesses and organizations as they evolve toward a distributed remote work environment to mitigate the health risks of COVID-19 to the global workforce. To view the latest cloud offerings and pricing structure, visit https://www.atlantic.net/vps-hosting/. About Atlantic.Net Atlantic.Net is a global cloud services provider with over 25 years of experience, serving thousands of developers and small, medium, and large clients in more than one hundred countries. Atlantic.Net specializes in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions and has served dynamic business clients including Lenovo, Newegg, NASA, and Hilton, among others. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions, backed by 24/7/365 support in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. For more information, please visit https://www.atlantic.net/. ### Contact: Email: pr@atlantic.net Ph: 321- 206-1371 --- # How to Deploy WordPress with Docker and Docker Compose > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-deploy-wordpress-with-docker-and-docker-compose/ | Published: 2021-06-24 | Updated: 2024-06-05 | Author: Hitesh Jethva WordPress is an open-source and popular content management system. However, installing and setting up WordPress on a new server is a very time-consuming process, especially if you need to do it again and again. In this case, you can use Docker and Docker compose to simplify your WordPress installation process using just a single command. In this post, we will show you how to deploy WordPress with Docker and Docker Compose.[jumpbox] ## Step 1 – Install Docker and Docker Compose First, you will need to install some required dependencies on your server. You can install them with the following commands: ``` apt-get update -y ``` ``` apt-get install apt-transport-https ca-certificates curl gnupg-agent software-properties-common -y ``` After installing all of them, add the Docker repository with the following command: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add - add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" ``` Once the repository is added, install Docker and Docker Compose with the following command: ``` apt-get install docker-ce docker-compose -y ``` After installing both packages, you can proceed to the next step. ## Step 2 – Create a Docker-Compose YML File Next, you will need to create a docker-compose.yml file to deploy the WordPress. First, create a new directory named wordpress with the following command: ``` mkdir wordpress ``` Next, change the directory to wordpress and create a new docker-compose.yml file: ``` cd wordpress nano docker-compose.yml ``` Add the following lines: ``` wordpress: image: wordpress links: - mariadb:mysql environment: - WORDPRESS_DB_PASSWORD=secure-password - WORDPRESS_DB_USER=root ports: - "your-server-ip:80:80" volumes: - ./html:/var/www/html mariadb: image: mariadb environment: - MYSQL_ROOT_PASSWORD=secure-password - MYSQL_DATABASE=wordpress volumes: - ./database:/var/lib/mysql ``` Save and close the file when you are finished. **Note:** Replaced **your-server-ip** with your public IP. The above file will download WordPress and MariaDB images from the Docker registry, create a database and set a password, link both containers, and expose the container on port 80. ## Step 3 – Deploy WordPress Now, change the directory to wordpress and launch the WordPress and MariaDB container with the following command: ``` docker-compose up -d ``` You should get the following output: ``` Pulling mariadb (mariadb:)... latest: Pulling from library/mariadb 345e3491a907: Pull complete 57671312ef6f: Pull complete 5e9250ddb7d0: Pull complete 2d512e2ff778: Pull complete 57c1a7dc2af9: Pull complete b846f4f4774a: Pull complete 66409f940bd2: Pull complete 82d8723e99d8: Pull complete 55edbf0f673e: Pull complete c34793730ad6: Pull complete 8f1925a0d734: Pull complete 72904fb5fd0b: Pull complete Digest: sha256:0c3c560359a6da112134a52122aa9b78fec5f9dd292a01ee7954de450f25f0c1 Status: Downloaded newer image for mariadb:latest Pulling wordpress (wordpress:)... latest: Pulling from library/wordpress 69692152171a: Pull complete 2040822db325: Pull complete 9b4ca5ae9dfa: Pull complete ac1fe7c6d966: Pull complete 5b26fc9ce030: Pull complete 3492f4769444: Pull complete 1dec05775a74: Pull complete 77107a42338e: Pull complete f58e4093c52a: Pull complete d32715f578d3: Pull complete 7a73fb2558ce: Pull complete 667b573fcff7: Pull complete 75e2da936ffe: Pull complete 759622df3a7b: Pull complete c2f98ef02756: Pull complete 50e11300b0a6: Pull complete de37513870b9: Pull complete f25501789abc: Pull complete 0cf8e3442952: Pull complete d45ce270a7e6: Pull complete 534cdc5a6ea6: Pull complete Digest: sha256:e9da0d6c867249f364cd2292ea0dd01d7281e8dfbcc3e4b39b823f9a790b237b Status: Downloaded newer image for wordpress:latest Creating wordpress_mariadb_1 ... done Creating wordpress_wordpress_1 ... done ``` You can verify the downloaded images with the following command: ``` docker images ``` Output: ``` REPOSITORY TAG IMAGE ID CREATED SIZE wordpress latest c2dd1984ad5b 3 days ago 551MB mariadb latest eff629089685 13 days ago 408MB ``` You can also verify the running container with the following command: ``` docker-compose ps ``` Output: ``` Name Command State Ports --------------------------------------------------------------------------------------- wordpress_mariadb_1 docker-entrypoint.sh mysqld Up 3306/tcp wordpress_wordpress_1 docker-entrypoint.sh apach ... Up 45.58.43.20:80->80/tcp ``` ## Step 4 – Access WordPress Installation Wizard At this point, WordPress has been deployed and listening on port 80. You can access it using the URL http://your-server-ip. You should see the following page: ![WordPress Installation Page](https://www.atlantic.net/wp-content/uploads/2021/06/p1-2-1024x641.png) You can now follow the steps to complete the WordPress installation. If you want to update both WordPress and MariaDB images, run the following command: ``` docker-compose pull ``` Now, push changes to your containers using the commands below. ``` docker-compose up -d ``` If you want to stop and remove all containers, run the following command: ``` docker-compose down ``` ## Conclusion In the above guide, you learned how to deploy a WordPress with Docker and Docker Compose. Try it out on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Deploy Jitsi Meet with Docker on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-deploy-jitsi-meet-with-docker-on-ubuntu-20-04/ | Published: 2021-06-25 | Updated: 2024-06-01 | Author: Hitesh Jethva Jitsi Meet is a free and open-source video-conferencing application that allows you to host your own video conferencing server without any subscription. It provides multi-person video conference rooms and allows you to access them from your web browser. It provides end-to-end TLS encryption so that no one can snoop on the call. Deploying Jitsi meet in the Docker container will save you a lot of time. In this post, we will show you how to Deploy Jitsi Meet with Docker and Docker Compose on Ubuntu 20.04. ## Step 1 – Install Docker and Docker Compose First, you will need to install some required dependencies on your server. You can install them with the following commands: ``` apt-get update -y ``` ``` apt-get install git apt-transport-https ca-certificates curl gnupg-agent software-properties-common -y ``` After installing all of them, add the Docker repository with the following command: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add - add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" ``` Once the repository is added, install Docker and Docker Compose with the following command: ``` apt-get install docker-ce docker-compose -y ``` After installing both packages, you can proceed to the next step. ## Step 2 – Download and Configure Jitsi Meet Next, you will need to download Jitsi Meet for Docker from the Git repository. You can download it with the following command: ``` git clone https://github.com/jitsi/docker-jitsi-meet.git ``` Once the download is completed, change the directory to the downloaded directory and copy the sample environment file. ``` cd docker-jitsi-meet cp env.example .env ``` Next, edit the .env file and define your server IP, ports, domain, and email address. ``` nano .env ``` Change the following lines: ``` HTTP_PORT=80 HTTPS_PORT=443 TZ=UTC PUBLIC_URL="https://jitsi.linuxbuz.com" DOCKER_HOST_ADDRESS=your-server-ip ENABLE_HTTP_REDIRECT=1 ENABLE_LETSENCRYPT=1 LETSENCRYPT_DOMAIN=jitsi.linuxbuz.com LETSENCRYPT_EMAIL=hitjethva@gmail.com ``` Save and close the file when you are finished. ## Step 3 – Launch the Jitsi Meet Container You can now launch the Jitsi Meet container with the following command: ``` docker-compose up -d ``` You should see the following output: ``` Status: Downloaded newer image for jitsi/jvb:latest Creating docker-jitsi-meet_web_1 ... done Creating docker-jitsi-meet_prosody_1 ... done Creating docker-jitsi-meet_jvb_1 ... done Creating docker-jitsi-meet_jicofo_1 ... done ``` You can now check the running container with the following command: ``` docker-compose ps ``` You should get the following output: ``` Name Command State Ports -------------------------------------------------------------------------------------------------------------------------------------- docker-jitsi-meet_jicofo_1 /init Up docker-jitsi-meet_jvb_1 /init Up 0.0.0.0:10000->10000/udp,:::10000->10000/udp, 0.0.0.0:4443->4443/tcp,:::4443->4443/tcp docker-jitsi-meet_prosody_1 /init Up 5222/tcp, 5280/tcp, 5347/tcp docker-jitsi-meet_web_1 /init Up 0.0.0.0:443->443/tcp,:::443->443/tcp, 0.0.0.0:80->80/tcp,:::80->80/tcp ``` As you can see, the Jitsi Meet container is started and listen on ports 80 and 443. ## Step 4 – Access Jitsi Meet Web UI Now, you can access the Jitsi Meet web interface using the URL https://your-domain-name. You should see the Jitsi Meed dashboard on the following page: ![Jitsi Meet Dashboard](https://www.atlantic.net/wp-content/uploads/2021/06/p1-3-1024x534.png) ## Conclusion Congratulations! You have successfully deployed Jitsi Meet with Docker on Ubuntu 20.04. Docker makes your job easier when it comes to deploying an application within a minute – get started on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Benchmark and Test Website Load with Siege > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-benchmark-and-test-website-load-with-siege/ | Published: 2021-06-26 | Updated: 2023-11-15 | Author: Hitesh Jethva Benchmarking is essential for any webmaster to measure and test the performance of a website or web application. It will give you an idea about the amount of data transferred, transaction rate, throughput, and concurrency. This information will help you to improve website speed and grow your website. There are a lot of benchmarking tools available in the market. Siege is a free, open-source, and cross-platform HTTP load testing and benchmarking tool that can be used to measure the speed of your website and provides a summary of the performance. In this post, we will explain how to install and use Siege to test the speed of your website. ## Step 1 – Install Siege In this section, we will show you how to install Siege on Debian and RPM-based distributions. For Debian and Ubuntu operating system, install Siege with the following command: ``` apt-get install siege -y ``` For RHEL, CentOS, and Fedora operating system, install Siege with the following command: ``` yum install epel-release -y yum install siege -y ``` Once Siege is installed, verify the installed version of Siege with the following command: ``` siege --version ``` You should get the following output: ``` SIEGE 4.0.4 Copyright (C) 2017 by Jeffrey Fulmer, et al. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. ``` ## Step 2 – Basic Syntax Basic syntax of the Siege command is shown below: ``` siege [option] website-name ``` A brief explanation of each option is shown below: - -v: Enable verbose mode. - -c: Specify the number of concurrent users. - -t: Specify a time limit for Siege run. - -d: Specify the delay for each Siege user. - -f: Specify the file containing the list of websites. - -i: Used to generate a log file. - -r: Define how many times to run the test. - -A: Define a user agent. ## Step 3 – Configure Siege The Siege configuration file is located at /etc/siege/siegerc. You will need to edit it and define the path of the log. ``` nano /etc/siege/siegerc ``` Find the following line: ``` logfile = $(HOME)/var/log/siege.log ``` Replaced it with the following line: ``` logfile = /var/log/siege.log ``` Save and close the file when you are done. ## Step 4 – Perform Load Test with Siege In this section, we will show you how to perform a load test for a single website and multiple websites. ### Test a Single Website Let’s test the website www.example.com by simulating 10 users with a delay of up to 10 seconds between requests. ``` siege -c10 -d10 -r1 -v www.example.com ``` You should see the following output: ``` ** SIEGE 3.0.5 ** Preparing 10 concurrent users for battle. The server is now under siege... HTTP/1.1 200 0.00 secs: 3256 bytes ==> GET / HTTP/1.1 200 0.01 secs: 3256 bytes ==> GET / HTTP/1.1 200 0.01 secs: 3256 bytes ==> GET / HTTP/1.1 200 0.00 secs: 3256 bytes ==> GET / HTTP/1.1 200 0.00 secs: 3256 bytes ==> GET / HTTP/1.1 200 0.01 secs: 3256 bytes ==> GET / HTTP/1.1 200 0.01 secs: 3256 bytes ==> GET / HTTP/1.1 200 0.01 secs: 3256 bytes ==> GET / HTTP/1.1 200 0.01 secs: 3256 bytes ==> GET / HTTP/1.1 200 0.01 secs: 3256 bytes ==> GET / done. Transactions: 10 hits Availability: 100.00 % Elapsed time: 8.01 secs Data transferred: 0.03 MB Response time: 0.01 secs Transaction rate: 1.25 trans/sec Throughput: 0.00 MB/sec Concurrency: 0.01 Successful transactions: 10 Failed transactions: 0 Longest transaction: 0.01 Shortest transaction: 0.00 ``` ### Test Multiple Websites Siege also allows you to test multiple websites at a time. In this case, you will need to define all your website name, URL or IPs in the /etc/siege/urls.txt file: ``` nano /etc/siege/urls.txt ``` Add the following line: ``` www.atlantic.net https://google.com 172.16.0.123 ``` Save and close the file. Next, test the load of all website defined in the urls.txt file run the following command: ``` siege -c10 -d10 -r1 -v -f /etc/siege/urls.txt ``` ## Conclusion In this guide, you learned how to install and use the Siege tool to benchmark and load test your website. I hope this will give you enough information to get an idea about your website performance – try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install MEAN.JS Stack on Debian 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-mean-js-stack-on-debian-10/ | Published: 2021-06-27 | Updated: 2024-01-18 | Author: Hitesh Jethva MEAN.JS is an open-source JavaScript framework used for developing web applications rapidly. It provides a set of tools including MongoDB, Express, Angular, and Node.js for simplifying the development process. It uses a single programming language and can handle all aspects of an application. In this guide, we will show you how to install MEAN.JS on Debian 10. ## Step 1 – Install MongoDB First, you will need to install the MongoDB database on your server. By default, MongoDB is not included in the Debian 10 default repository, so you will need to add the MongoDB repository to your server. First, install all the required dependencies with the following command: ``` apt-get install dirmngr gnupg apt-transport-https software-properties-common ca-certificates curl -y ``` Next, add the GPG key and MongoDB repository with the following command: ``` curl -fsSL https://www.mongodb.org/static/pgp/server-4.2.asc | apt-key add - add-apt-repository 'deb https://repo.mongodb.org/apt/debian buster/mongodb-org/4.2 main' ``` Next, update the repository and install MongoDB with the following command: ``` apt-get update -y apt-get install mongodb-org -y ``` After installing MongoDB, start the MongoDB service and enable it to start at system reboot: ``` systemctl start mongod.service systemctl enable mongod.service ``` ## Step 2 – Install Node.js Next, you will need to install Node.js on your server. First, install the necessary dependencies using the following command. ``` apt-get install -y ca-certificates curl gnupg ``` Next, download the Node.js GPG key. ``` mkdir -p /etc/apt/keyrings curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg ``` Next, add the NodeSource repo to the APT source list. ``` echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_18.x nodistro main" | tee /etc/apt/sources.list.d/nodesource.list ``` Then, update the repository index and install the Ndoe.js with the following command. ``` apt update apt-get install -y nodejs ``` Next, verify the Node.js version using the following command. ``` node -v ``` Output. ``` v18.19.0 ``` Next, install the Yarn and Gulp package with the following command: ``` npm install -g yarn npm install -g grunt-cli npm install -g gulp ``` Once all the packages are installed, you can proceed to the next step. ## Step 3 – Install MEAN.JS First, download the latest version of MEAN from the Git repository using the following command: ``` git clone https://github.com/meanjs/mean.git meanjs ``` Once the download is completed, change the directory to the downloaded directory and install all required dependencies with the following command: ``` cd meanjs/ yarn install ``` Once all the dependencies are installed, you can proceed to the next step. ## Step 4 – Launch MEAN.JS At this point, MEAN.JS is installed on your server. You can now start the MEAN.JS with the following command: ``` npm start ``` You should see the following output: ``` MEAN.JS - Development Environment Environment: development Server: http://0.0.0.0:3000 Database: mongodb://localhost/mean-dev App version: 0.6.0 MEAN.JS version: 0.6.0 ``` At this point, MEAN.JS is started and listen on port 3000. ## Step 5 – Access MEAN.JS Now, open your web browser and access the MEAN.JS web interface using the URL **http://your-server-ip:3000**. You should see the MEAN.JS web interface on the following screen: ![MEAN Dashboard Page](https://www.atlantic.net/wp-content/uploads/2021/06/p1-8-1024x544.png) ## Conclusion Congratulations! You have successfully installed MEAN.JS on Debian 10. You can now start developing dynamic web applications using MEAN.JS; get started on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install Ampache Music Streaming Server on Debian > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-ampache-music-streaming-server-on-debian/ | Published: 2021-06-28 | Updated: 2025-09-04 | Author: Hitesh Jethva Ampache is an open-source and web-based audio/video streaming application that allows you to access your music & videos from anywhere over the internet. Ampache provides a platform to host and manage your digital music collection on your own server. With Ampache, you can stream your music to your smartphone, tablet, and smart TV. In this post, we will show you how to install the Ampache Music Streaming server on Debian 12. ## Step 1 – Install LAMP Server Ampache requires an Apache web server, Database server, PHP. So you will need to install the LAMP server and other PHP dependencies in your server. You can install all of them with the following commands: ``` apt-get update -y ``` ``` apt-get install apache2 mariadb-server php libapache2-mod-php php-cli php-common php-json php-gd php-xmlrpc php-curl php-intl php-imagick php-mysql php-zip php-xml php-mbstring php-bcmath unzip ffmpeg -y ``` After installing all packages, edit the php.ini file and make some changes: ``` nano /etc/php/8.2/apache2/php.ini ``` Change the following lines: ``` short_open_tag = On memory_limit = 256M cgi.fix_pathinfo = 0 max_execution_time = 360 upload_max_filesize = 64M post_max_size = 64M ``` Save and close the file then restart the Apache service to apply the changes: ``` systemctl restart apache2 ``` ## Step 2 – Configure MariaDB Database Next, you will need to create a database and user for Ampache. First, connect to MariaDB with the following command: ``` mysql ``` Next, create a database and user with the following command: ``` CREATE DATABASE ampachedb; CREATE USER 'ampache'@'%' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to ampachedb with the following command: ``` GRANT ALL PRIVILEGES ON ampachedb.* TO 'ampache'@'%' WITH GRANT OPTION; ``` Next, flush the privileges and exit from MariaDB with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install Ampache Next, download the latest version of Ampache from the Git repository: ``` wget https://github.com/ampache/ampache/releases/download/7.7.2/ampache-7.7.2_all_php8.2.zip ``` Once the download is completed, unzip the downloaded file to the Apache web root directory: ``` unzip ampache-7.7.2_all_php8.2.zip -d /var/www/html/ampache ``` Next, change the directory to the extracted directory and rename some sample .htaccess files. ``` cd /var/www/html/ampache cp config/ampache.cfg.php.dist config/ampache.cfg.php ``` Next, edit the ampache.cfg.php file. ``` nano config/ampache.cfg.php ``` Define your database settings: ``` database_hostname = "localhost" database_name = "ampachedb" database_username = "ampache" database_password = "password" ``` Next, set proper ownership and permission to the Ampache directory: ``` chown -R www-data:www-data /var/www/html/ampache chmod -R 775 /var/www/html/ampache ``` Next, create a directory to store your music and set proper ownership: ``` mkdir -p /data/ chown -R www-data:www-data /data/ ``` Next, enable the Apache expires and rewrite module with the following command: ``` a2enmod expires rewrite ``` Finally, restart the Apache service to apply the changes: ``` systemctl restart apache2 ``` ## Step 4: Configure Apache Next, create an Apache configuration file for Ampache. ``` nano /etc/apache2/sites-available/ampache.conf ``` Add the following configuration: ``` ServerName ampache.example.com.com DocumentRoot /var/www/html/ampache/public Options Indexes FollowSymLinks AllowOverride All Require all granted ErrorLog ${APACHE_LOG_DIR}/ampache_error.log CustomLog ${APACHE_LOG_DIR}/ampache_access.log combined ``` Save and close the file then activate the Apache virtual host. ``` a2ensite ampache.conf ``` Finally, restart the Apache to apply the changes. ``` systemctl restart apache2 ``` ## Step 5 – Access Ampache Web Interface Now, open your web browser and access the Ampache web interface using the URL **http://ampache.example.com/install.php**. You should see the following page: ![Ampache Select Language](https://www.atlantic.net/wp-content/uploads/2021/06/p1-9-1024x386.png) Select your language and click on **Start** **Configuration**. You should see the following page: ![Ampache Verify Dependencies](https://www.atlantic.net/wp-content/uploads/2021/06/p2-4-1024x542.png) Make sure all the PHP dependencies are installed then click on the **Continue** button. You should see the following page: ![Ampache Database Configuration](https://www.atlantic.net/wp-content/uploads/2021/06/p3-2.png) Provide your database details, uncheck “**Create Database**” and click on the **Insert** **Database**. You should see the following page: ![Ampache Select Ffmpeg](https://www.atlantic.net/wp-content/uploads/2021/06/p4-3.png) Select the FFmpeg template and click on the **Create** **Config** button. You should see the following page: ![Ampache Set Admin Password](https://www.atlantic.net/wp-content/uploads/2021/06/p5-1.png) Set your admin password and click on the **Create** **Account** button. You should see the following page: ![Ampache Login Page](https://www.atlantic.net/wp-content/uploads/2021/06/p6.png) Provide your admin username, password and click on the **Login** button. You should see the Ampache dashboard on the following page: ![Ampache Dashboard Page](https://www.atlantic.net/wp-content/uploads/2021/06/p7-1024x526.png) ## Conclusion Congratulations! You have successfully installed the Ampache music streaming server on Debian 12. You can now store your music and audio on the Ampache server and stream them over the internet from any device. Try it on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install Nexus Repository Manager on Debian > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-nexus-repository-manager-on-debian/ | Published: 2021-06-29 | Updated: 2025-09-05 | Author: Hitesh Jethva Nexus is a repository manager that is used for managing all dependencies required in your entire software development lifecycle. It provides a single source for all components and makes it easier to distribute your software. It can be integrated with the existing user and LDAP authentication. Currently, it is used by more than 100,000 organizations globally. In this post, we will show you how to install the Nexus repository manager on Debian 12. ## Step 1 – Install Java Before starting, Java  must be installed on your server. First, update the repository index with the following command: ``` apt-get update -y ``` Next, install Java  with the following command: ``` apt-get install default-jdk -y ``` Once Java has been installed, verify the Java version using the following command: ``` java -version ``` You should see the following output: ``` java --version openjdk 17.0.16 2025-07-15 OpenJDK Runtime Environment (build 17.0.16+8-Debian-1deb12u1) OpenJDK 64-Bit Server VM (build 17.0.16+8-Debian-1deb12u1, mixed mode, sharing) ``` ## Step 2 – Install Nexus Repository First, add a user to run Nexus: ``` useradd -M -d /opt/nexus -s /bin/bash -r nexus ``` Next, install the Sudo package and allow nexus user to run all commands without providing Sudo password: ``` apt-get install sudo bash echo "nexus ALL=(ALL) NOPASSWD: ALL" > /etc/sudoers.d/nexus ``` Next, go to [Nexus](https://help.sonatype.com/en/download.html) website, get the download link and download the latest version of Nexus with the following command: ``` wget https://sonatype-download.global.ssl.fastly.net/repository/downloads-prod-group/3/nexus-3.83.0-08-linux-x86_64.tar.gz ``` Next, create a directory for Nexus and extract the downloaded file to /opt/nexus. ``` mkdir /opt/nexus tar xzf nexus-3.83.0-08-linux-x86_64.tar.gz -C /opt/nexus --strip-components=1 ``` Next, set proper ownership to the /opt/nexus directory with the following command: ``` chown -R nexus:nexus /opt/nexus ``` ## Step 3 – Configure Nexus Repository Next, you will need to edit **nexus.vmoptions** file: ``` nano /opt/nexus/bin/nexus.vmoptions ``` Find the following lines: ``` -Xms2703m -Xmx2703m ``` Replaced them with the following lines: ``` -Xms1024m -Xmx1024m ``` Next, find the following lines: ``` -Dkaraf.data=../sonatype-work/nexus3 -Dkaraf.log=../sonatype-work/nexus3/log -Djava.io.tmpdir=../sonatype-work/nexus3/tmp ``` Replaced them with the following lines: ``` -Dkaraf.data=./nexus3 -Dkaraf.log=./nexus3/log -Djava.io.tmpdir=./nexus3/tmp ``` Save and close the file then edit **/opt/nexus/bin/nexus** file: ``` nano /opt/nexus/bin/nexus ``` Change the following line: ``` #!/bin/bash run_as_user='nexus' ``` Save and close the file when you are finished. ## Step 4 – Create a Systemd Service File for Nexus Now, create a systemd service file for Nexus with the following command: ``` nano /etc/systemd/system/nexus.service ``` Add the following lines: ``` [Unit] Description=nexus service After=network.target [Service] Type=forking LimitNOFILE=65536 ExecStart=/opt/nexus/bin/nexus start ExecStop=/opt/nexus/bin/nexus stop User=nexus Restart=on-abort [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon: ``` systemctl daemon-reload ``` Next, start the Nexus service and enable it to start at system reboot: ``` systemctl enable --now nexus.service ``` You can now check the status of Nexus with the following command: ``` systemctl status nexus ``` Output: ``` ● nexus.service - nexus service Loaded: loaded (/etc/systemd/system/nexus.service; disabled; preset: enabled) Active: active (running) since Fri 2025-09-05 05:50:50 UTC; 2min 3s ago Process: 40363 ExecStart=/opt/nexus/bin/nexus start (code=exited, status=0/SUCCESS) Main PID: 40610 (java) Tasks: 73 (limit: 2304) Memory: 820.3M CPU: 1min 29.405s CGroup: /system.slice/nexus.service └─40610 /opt/nexus/jdk/temurin_17.0.13_11_linux_x86_64/jdk-17.0.13+11/bin/java -server -Dnexus.installer.type=linux-x86-64 -Xms1024m -Xmx1024m -XX:+Unlock> Sep 05 05:50:50 debian systemd[1]: Starting nexus.service - nexus service... Sep 05 05:50:50 debian nexus[40363]: Starting nexus Sep 05 05:50:50 debian systemd[1]: Started nexus.service - nexus service. ``` At this point, Nexus is started and listen on port 8081. You can check it with the following command: ``` ss -antpl | grep :8081 ``` You should see the following output: ``` LISTEN 0 50 0.0.0.0:8081 0.0.0.0:* users:(("java",pid=1547,fd=793)) ``` ## Step 5 – Access Nexus Web Interface Wait for some time to start the Nexus service, then print the Nexus admin password with the following command: ``` cat /opt/nexus/nexus3/admin.password ``` Output: ``` 538fd664-215b-45ac-8cf3-e2a24a256a23 ``` Now, open your web browser and access the Nexus web interface using the URL **http://your-server-ip:8081.** You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/06/n1.png) Click on the **Sign In** button. You should see the Nexus login page: ![](https://www.atlantic.net/wp-content/uploads/2021/06/n2.png) Provide your admin username and password then click on the **Sign in** button. You should see the Nexus setup page: ![](https://www.atlantic.net/wp-content/uploads/2021/06/n3.png)Click on **Next**. You will see the page below. ![](https://www.atlantic.net/wp-content/uploads/2021/06/unnamed-file.png) Set your new admin password and click **Next**. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2021/06/n5.png) Click on Next. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2021/06/n6.png) Accept the licence agreement. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2021/06/n7.png) Enable the anonymous access and click **Next**. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2021/06/n8.png) Click on **Finish** to finish the repository setup. ![](https://www.atlantic.net/wp-content/uploads/2021/06/n9.png) ## Conclusion Congratulations! You have successfully installed and configured the Nexus repository manager on Debian 12. You can now implement Nexus in your development environment and start managing your entire software development lifecycle. Try installing it on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # Announcement: Meet Our Customer Service Champion for Q2 2021: Brandon P. > URL: https://www.atlantic.net/announcements/meet-our-customer-service-champion-for-q2-2021-brandon-p/ | Published: 2021-06-30 | Updated: 2025-09-19 | Author: Alexander Wise ![](https://www.atlantic.net/wp-content/uploads/2021/06/Brandon-P-160x300-1.jpg)We are pleased to announce that Brandon P. is our Customer Service Champion for Q2 2021! Brandon was initially hired in 2019 as a SOC Tech TIER 2 and has since then moved up to become a Systems Engineer. He likes the friendships he has made at Atlantic.Net and the challenging work which requires learning new things and gives him something to look forward to every day. Brandon loves kayaking and finding interesting places to explore; lately, he’s been exploring springs around Florida. He continues to receive praise for his work ethic and his willingness to go the extra mile for his projects. Great work, Brandon! We thank you and we appreciate all your hard work! --- # How to Install Pleroma Social Network Platform on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-pleroma-social-network-platform-on-ubuntu-20-04/ | Published: 2021-07-02 | Updated: 2024-06-02 | Author: Hitesh Jethva Pleroma is a free, open-source and self-hosted social networking platform. It consists of two components, a backend which is called Pleroma and a frontend which is called Pleroma-FE. It is compatible with Mastodon and other ActivityPub implementations. In this post, we will show you how to install Pleroma with Nginx and Let’s Encrypt SSL on Ubuntu 20.04. ## Step 1 – Install Nginx and PostgreSQL First, install Nginx and PostgreSQL with the following command: ``` apt-get install postgresql nginx -y ``` Once both packages are installed, install other dependencies with the following command: ``` apt-get install wget curl gnupg2 ca-certificates lsb-release gnupg zip libncurses5 libmagic-dev unzip -y ``` After installing all the dependencies, you can proceed to the next step. ## Step 2 – Download Pleroma First, create a user for Pleroma with the following command: ``` adduser --system --shell /bin/bash --home /opt/pleroma pleroma ``` Next, switch the user to Pleroma and download the latest version of Pleroma with the following command: ``` su - pleroma curl "https://git.pleroma.social/api/v4/projects/2/jobs/artifacts/stable/download?job=amd64" -o pleroma_amd64.zip ``` Next, create a directory for Pleroma and extract the downloaded file to the pleroma directory: ``` mkdir pleroma unzip pleroma_amd64.zip -d pleroma ``` Next, move all the contents from pleroma to /opt/pleroma with the following command: ``` mv pleroma/release/* /opt/pleroma/ ``` Next, exit from the Pleroma user with the following command: ``` exit ``` Next, create other required directories with the following command: ``` mkdir -p /var/lib/pleroma/{uploads,static} mkdir -p /etc/pleroma ``` Next, set proper ownership to all created directories: ``` chown -R pleroma /var/lib/pleroma /etc/pleroma ``` ## Step 3 – Configure Pleroma Next, switch the user to Pleroma and install the Pleroma using the following command: ``` su - pleroma ./bin/pleroma_ctl instance gen --output /etc/pleroma/config.exs --output-psql /tmp/setup_db.psql ``` You will be asked several questions as shown below: ``` What domain will your instance use? (e.g pleroma.soykaf.com) [] pleroma.linuxbuz.com What is the name of your instance? (e.g. The Corndog Emporium) [pleroma.linuxbuz.com] What is your admin email address? [] hitjethva@gmail.com What email address do you want to use for sending email notifications? [hitjethva@gmail.com] Do you want search engines to index your site? (y/n) [y] y Do you want to store the configuration in the database (allows controlling it from admin-fe)? (y/n) [n] n What is the hostname of your database? [localhost] What is the name of your database? [pleroma] What is the user used to connect to your database? [pleroma] What is the password used to connect to your database? [autogenerated] password Would you like to use RUM indices? [n] n What port will the app listen to (leave it if you are using the default setup with nginx)? [4000] What ip will the app listen to (leave it if you are using the default setup with nginx)? [127.0.0.1] What directory should media uploads go in (when using the local uploader)? [/var/lib/pleroma/uploads] What directory should custom public files be read from (custom emojis, frontend bundle overrides, robots.txt, etc.)? [/var/lib/pleroma/static] Do you want to strip location (GPS) data from uploaded images? This requires exiftool, it was detected as not installed, please install it if you answer yes. (y/n) [n] n Do you want to anonymize the filenames of uploads? (y/n) [n] y Do you want to deduplicate uploaded files? (y/n) [n] y Writing config to /etc/pleroma/config.exs. Writing the postgres script to /tmp/setup_db.psql. Writing /var/lib/pleroma/static/robots.txt. All files successfully written! Refer to the installation instructions for your platform for next steps. ``` Once Pleroma is installed, exit from the Pleroma user with the following command: ``` exit ``` ## Step 4 – Migrate the Database Next, log in to PostgreSQL and import the Pleroma database to PostgreSQL: ``` su - postgres psql -f /tmp/setup_db.psql ``` Output: ``` CREATE ROLE CREATE DATABASE You are now connected to database "pleroma" as user "postgres". CREATE EXTENSION CREATE EXTENSION CREATE EXTENSION ``` Next, exit from the PostgreSQL with the following command: ``` exit ``` Next, log in to Pleroma user and migrate the database with the following command: ``` su - pleroma ./bin/pleroma_ctl migrate ``` Next, exit from the Pleroma user with the following command: ``` exit ``` ## Step 5 – Install And Configure Let’s Encrypt First, install the Certbot client with the following command: ``` apt-get install python3-certbot-nginx -y ``` Next, stop the Nginx service and download the Let’s Encrypt SSL for your domain with the following command: ``` systemctl stop nginx certbot certonly --standalone --preferred-challenges http -d pleroma.linuxbuz.com ``` Next, copy the sample Pleroma configuration file to the Nginx configuration location: ``` cp /opt/pleroma/installation/pleroma.nginx /etc/nginx/conf.d/pleroma.conf ``` Next, replace the word “example.tld” with your domain name in pleroma.conf file: ``` sed -i 's/example\.tld/pleroma.linuxbuz.com/g' /etc/nginx/conf.d/pleroma.conf ``` Next, verify the Nginx for any syntax errors: ``` nginx -t ``` Output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Note: If you get this error message, you need to edit the /etc/nginx/nginx.conf file and change the value server_names_hash_bucket_size to 64: ``` nginx: [emerg] could not build server_names_hash, you should increase server_names_hash_bucket_size: 32 nginx: configuration file /etc/nginx/nginx.conf test failed ``` Next, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 6 – Start Pleroma Service First, copy the Pleroma service file from the Pleroma directory to the system location: ``` cp /opt/pleroma/installation/pleroma.service /etc/systemd/system/pleroma.service ``` Next, start the Pleroma service and enable it to start at system reboot: ``` systemctl start pleroma systemctl enable pleroma ``` Next, check the status of the Pleroma service with the following command: ``` systemctl status pleroma ``` You should see the following output: ``` ● pleroma.service - Pleroma social network Loaded: loaded (/etc/systemd/system/pleroma.service; disabled; vendor preset: enabled) Active: active (running) since Sun 2021-06-20 08:15:21 UTC; 4s ago Main PID: 12086 (beam.smp) Tasks: 20 (limit: 2353) Memory: 129.0M CGroup: /system.slice/pleroma.service ├─12086 /opt/pleroma/erts-10.7.2.1/bin/beam.smp -- -root /opt/pleroma -progname erl -- -home /opt/pleroma -- -noshell -s elixir s> ├─12134 /opt/pleroma/erts-10.7.2.1/bin/epmd -daemon └─12137 erl_child_setup 1024 ``` ## Step 7 – Create an Admin User Next, you will need to create an admin user for the Pleroma web interface. First, log in to Pleroma user with the following command: ``` su - pleroma ``` Next, create an admin user with the following command: ``` ./bin/pleroma_ctl user new admin admin@pleroma.linuxbuz.com --password mypassword --admin ``` You should see the following output: ``` A user will be created with the following information: - nickname: admin - email: admin@pleroma.linuxbuz.com - password: mypassword - name: admin - bio: - moderator: false - admin: true Continue? [n] y User admin created ``` ## Step 8 – Access Pleroma Web Interface Now, open your web browser and access the Pleroma web interface using the URL **https://pleroma.linuxbuz.com**. You should see the following screen: ![Pleroma Login Page](https://www.atlantic.net/wp-content/uploads/2021/06/p1-11-1024x641.png) Provide your admin username, password and click on the **Log in** button. You should see the Pleroma dashboard on the following screen: ![Pleroma Dashboard Page](https://www.atlantic.net/wp-content/uploads/2021/06/p2-6.png) ## Conclusion Congratulations! You have successfully installed and configured Pleroma with Nginx and Let’s Encrypt SSL on Ubuntu 20.04. You can now host your own social networking platform with Pleroma on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Use the Linux sleep Command with Examples > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-use-the-linux-sleep-command-with-examples/ | Published: 2021-07-04 | Updated: 2025-04-20 | Author: Hitesh Jethva The sleep command is very useful in many shell scripts. It is used when you want to wait for some time to complete the specific operation before starting the next operation in the shell script. In simple terms, it is used to delay of execution of the next command. You can set a fixed amount of time by seconds, minutes, hours, and days. In this post, we will show you how to use sleep command with practical examples. ## Basic Syntax of Sleep Command The basic syntax of the sleep command is shown below: ``` sleep NUMBER[SUFFIX]... ``` Sleep supports multiple values to calculate the duration of sleep: - s – seconds - m – minutes - h – hours - d – days To check the version of the sleep command, use the following command: ``` sleep --version ``` You should see the following output: ``` sleep (GNU coreutils) 8.21 Copyright (C) 2013 Free Software Foundation, Inc. License GPLv3+: GNU GPL version 3 or later . This is free software: you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law. Written by Jim Meyering and Paul Eggert. ``` ## Sleep Command Examples By default, the sleep command will take time in seconds. For example, run the following command: ``` sleep 7 ``` This will pause the terminal for 7 seconds. You can use the **m** option to specify the time in a minute: ``` sleep 2m ``` This will pause the terminal for 2 minutes. Press CTRL + C to exit from the sleep mode. Let’s take another example, run the date and cal command with sleep command. The date command will print the current date and the cal command will print the calendar after waiting for 5 seconds. ``` date && sleep 1 && echo "One" && sleep 1 && echo "Two" && sleep 1 && echo "Three" && sleep 1 && echo "Four" && sleep 1 && echo "Five" && cal ``` You should see the following output: ``` Sun Jun 27 20:44:12 IST 2021 One Two Three Four Five June 2021 Su Mo Tu We Th Fr Sa 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 ``` Let’s take another example that pauses a shell script for 5 seconds. First, create a shell script with the following command: ``` nano bash.sh ``` Add the following lines: ``` #!/bin/bash SLEEP_TIME="5" echo "Current time: $(date +%T)" echo "Hi, Wait for ${SLEEP_TIME} seconds ..." sleep ${SLEEP_TIME} echo "All done and current time: $(date +%T)" ``` Save the file, then run it with the following command: ``` bash bash.sh ``` You should see the following output: ``` Current time: 20:52:04 Hi, Wait for 5 seconds ... All done and current time: 20:52:09 ``` ## Conclusion That’s it. You have now enough knowledge of how to use the sleep command in Linux. Try using it on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net, and for more information, visit the sleep command manual page. --- # kubectl Commands with Examples > URL: https://www.atlantic.net/dedicated-server-hosting/kubectl-commands-with-examples/ | Published: 2021-07-05 | Updated: 2023-11-21 | Author: Hitesh Jethva Kubernetes is a free, open-source, and popular container orchestration tool developed by Google. It is used to manage and scale containerized infrastructure. The kubectl is a command-line utility used to query and manage a Kubernetes cluster. It uses the API interface to make this process more comfortable. In this post, we will show you how to use the kubectl command to manage a Kubernetes cluster. ## Step 1 – Install Kebectl By default, kubectl automatically installed during the Kubernetes cluster setup. If you want to manage the Kubernetes cluster from the remote system, then you can install the kubectl using the following commands: ``` apt-get update -y wget https://dl.k8s.io/release/v1.21.2/bin/linux/amd64/kubectl -O /usr/bin/kubectl chmod +x /usr/bin/kubectl ``` Next, check your kubectl setup using the following command: ``` kubectl version --client ``` ## Step 2 – Create and List Resources To get a list of all namespaces, run the following command: ``` kubectl get namespaces ``` To generate a list of all daemon sets, run the following command: ``` kubectl get daemonset ``` To list all pods, run the following command: ``` kubectl get pods ``` To get a list of all pods with detailed information, run the following command: ``` kubectl get pods -o wide ``` To list a specific replication controller, run the following command: ``` kubectl get replicationcontroller "replication-controller-name" ``` To list all replication controllers and services, run the following command: ``` kubectl get replicationcontroller,services ``` You can use “kubectl create” command to create a resource such as a service, a deployment, a job, or a namespace. For example, to create a new namespace, run the following command: ``` kubectl create namespace namespace-name ``` To create a resource from a JSON or YAML file, run the following command: ``` kubectl create -f [filename] ``` ## Step 3 – Update a Resource with kubectl You can use the kubectl apply command to apply or update a resource. To create a new replication controller or a service with the definition contained in filename.yaml, run the following command: ``` kubectl apply -f filename.yaml ``` To create the object defined in the filename.yaml file located inside any directory, run the following command: ``` kubectl apply -f directory-name ``` You can use the kubectl edit command to edit any resource file. For example, to edit a service, run the following command: ``` kubectl edit service-name ``` ## Step 4 – Check the Status of Resources You can use the kubectl describe command to check the status of any resources. To check the status of any node, run the following command: ``` kubectl describe nodes nodename ``` To check the status of any pod, run the following command: ``` kubectl describe pods pod-name ``` To check the status of any pod listed in the pod.json file, run the following command: ``` Kubectl describe -f pod.json ``` To display detailed information of all pods, run the following command: ``` kubectl describe pods ``` ## Step 5 – Delete a Resource with kubectl You can use the kubectl delete command to delete any resources. To remove a pod listed in the pod.yaml file, run: ``` kubectl delete -f pod.yaml ``` To remove all pods, run: ``` kubectl delete pods --all ``` ## Step 6 – Modify kubeconfig Files To display kubectl’s current configuration, run: ``` kubectl config view ``` To list all available contexts, run: ``` kubectl config get-contexts ``` To get the current context for kubectl, run: ``` kubectl config current-context ``` To set a cluster entry in kubeconfig, run: ``` kubectl config set-cluster [cluster-name] --server=[server-name] ``` You can use the kubectl logs command to print logs from containers in a pod. ``` kubectl logs "pod-name" ``` ## Conclusion In the above guide, you learned how to use the kubectl command to manage the Kubernetes effectively, Refer to the [kubectl official documentation](https://kubernetes.io/docs/reference/generated/kubectl/kubectl-commands) for more information. Try it today on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How To Use Linux SS Command with Examples > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-use-linux-ss-command-with-examples/ | Published: 2021-07-06 | Updated: 2023-11-16 | Author: Hitesh Jethva The Socket Statistics (ss) command is a tool used to get statistics about your network connections. It is a modern replacement for the classic netstat command that display information similar to netstat. It helps system administrator with troubleshooting network issues. In this article, we will show you how to use the ss command with examples. ## Step 1 – How to Use ss Command The ss command is a part of the iproute2 package and comes pre-installed in all major Linux distributions. Run the ss command without any options: ``` ss ``` You should see a list of all open non-listening sockets with established connections: ``` Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port u_dgr ESTAB 0 0 @0002d 21279 * 21280 u_dgr ESTAB 0 0 @0002c 21277 * 21278 u_str ESTAB 0 0 * 24372 * 24371 u_str ESTAB 0 0 * 24121 * 24122 u_str ESTAB 0 0 /var/run/dbus/system_bus_socket 22039 * 22625 u_str ESTAB 0 0 * 28687 * 28688 u_str ESTAB 0 0 * 20684 * 20685 u_str ESTAB 0 0 /var/run/dbus/system_bus_socket 19468 * 18720 u_str ESTAB 0 0 * 19408 * 21950 ``` A brief explanation of each column is shown below: - Netid: Type of the socket like TCP, UDP, etc. - State: State of the socket like established, unconnected, listening, etc. - Recv-Q: Display the number of received packets. - Send-Q: Display the number of sent packets. - Local address:port: Display the address and port of the local machine. - Peer address:port: Display the address and port of the remote machine. ## Step 2 – List All Connections To list all listening and non-listening connections, run: ``` ss -a ``` Output: To list only listening connections, run: ``` ss -l ``` Output: ``` Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port nl UNCONN 0 0 rtnl:whoopsie/1343 * nl UNCONN 0 0 rtnl:chrome/3508 * nl UNCONN 0 0 rtnl:4195436 * nl UNCONN 0 0 rtnl:deja-dup-monito/4340 * ``` ## Step 3 – List All TCP Connections To list all TCP connections, run: ``` ss -t ``` Output: ``` State Recv-Q Send-Q Local Address:Port Peer Address:Port ESTAB 0 0 172.20.10.3:60338 103.43.89.4:https SYN-SENT 0 1 172.20.10.3:34652 13.127.247.216:https SYN-SENT 0 1 172.20.10.3:34474 13.127.247.216:https ESTAB 0 0 172.20.10.3:34310 103.43.90.179:https ESTAB 0 0 172.20.10.3:34362 34.95.69.49:https ``` To list all listening TCP connections, run: ``` ss -lt ``` Output: ``` State Recv-Q Send-Q Local Address:Port Peer Address:Port LISTEN 0 50 127.0.0.1:mysql *:* LISTEN 0 50 *:netbios-ssn *:* LISTEN 0 128 *:sunrpc *:* LISTEN 0 128 *:http *:* ``` ## Step 4 – List UDP Connections To list all UDP connections, run: ``` ss -u ``` Output: ``` State Recv-Q Send-Q Local Address:Port Peer Address:Port ESTAB 0 0 127.0.0.1:56315 127.0.0.1:56315 ESTAB 0 0 172.20.10.3:44691 142.250.67.130:https ``` To list all listening UDP connections, run: ``` ss -lu ``` Output: ``` State Recv-Q Send-Q Local Address:Port Peer Address:Port UNCONN 0 0 *:323 *:* UNCONN 0 0 *:ipsec-nat-t *:* UNCONN 0 0 *:isakmp *:* UNCONN 0 0 *:19002 *:* UNCONN 0 0 *:ipp *:* ``` ## Step 5 – Display IPv4 and IPv6 Connections To display only IPv4 connections, run: ``` ss -4 ``` Output: ``` Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port u_dgr ESTAB 0 0 @0002d 21279 * 21280 u_dgr ESTAB 0 0 @0002c 21277 * 21278 u_str ESTAB 0 0 * 24372 * 24371 u_str ESTAB 0 0 * 24121 * 24122 ``` To display only IPv6 connections, run: ``` ss -6 ``` Output: ``` Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port u_dgr ESTAB 0 0 @0002d 21279 * 21280 u_dgr ESTAB 0 0 @0002c 21277 * 21278 u_str ESTAB 0 0 * 24372 * 24371 u_str ESTAB 0 0 * 24121 * 24122 ``` ## Step 6 – List Connections to a Specific IP Address If you want to list all connections to a specific destination IP address, run the following command: ``` ss dst 172.20.10.3 ``` Output: ``` Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port u_dgr ESTAB 0 0 @0002d 21279 * 21280 u_dgr ESTAB 0 0 @0002c 21277 * 21278 u_str ESTAB 0 0 * 24372 * 24371 ``` To list all connections to a specific source address, run: ``` ss src 172.20.10.3 ``` Output: ``` Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port u_dgr ESTAB 0 0 @0002d 21279 * 21280 u_dgr ESTAB 0 0 @0002c 21277 * 21278 u_str ESTAB 0 0 * 24372 * 24371 u_str ESTAB 0 0 * 24121 * 24122 u_str ESTAB 0 0 /var/run/dbus/system_bus_socket 22039 * 22625 ``` ## Step 7 – Display Process IDs of Connections To display PIDs of all connections, run: ``` ss -p ``` Output: ``` Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port u_dgr ESTAB 0 0 @0002d 21279 * 21280 users:(("chrome",3508,10)) u_dgr ESTAB 0 0 @0002c 21277 * 21278 users:(("chrome",3508,9)) u_str ESTAB 0 0 * 24372 * 24371 users:(("chrome",4002,70)) u_str ESTAB 0 0 * 24121 * 24122 users:(("chrome",3714,42)) ``` ## Step 8 – Filter Connections You can use the ss command with advanced filtering to list all connections based on your requirements. For example, to list all TCP connections that are in the listening state, run: ``` ss -t state listening ``` Output: ``` Recv-Q Send-Q Local Address:Port Peer Address:Port 0 50 127.0.0.1:mysql *:* 0 50 *:netbios-ssn *:* 0 128 *:sunrpc *:* ``` To list all connections with destination port 22, run: ``` ss dst :22 ``` ## Conclusion That’s it for now. The ss command tool is very useful to get socket and network statistics with advanced filtering options on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. For more information check the [ss command man pages](https://man7.org/linux/man-pages/man8/ss.8.html). --- # How to Reduce Your PCI Scope When Accepting Payments > URL: https://www.atlantic.net/pci-compliant-hosting/reduce-pci-scope-accepting-payments/ | Published: 2021-07-07 | Updated: 2026-05-30 | Author: Alexander Wise Accepting credit card payments can greatly boost your business’s bottom line, but it comes with immense responsibility. Anyone paying attention to the news knows how ubiquitous credit card breaches and hacks have become. One of the biggest PCI breaches is still the 2013 Target attack that resulted in 40 million card details being stolen. Other significant recent attacks include the Magecart Attack on Warner Music Group, the Adobe breach where 3 million customer card details were stolen, and of course Equifax — a premier U.S. credit bureau — falling victim to data breaches that compromise precious cardholders and personal data. ## Why You Need a Secure Environment Maintaining a secure cardholder data environment (CDE) isn’t simply recommended, it’s required. Any business or organization that transmits, stores, or processes cardholder data falls within the scope of the Payment Card Industry Data Security Standard (PCI-DSS). You may be thinking to yourself, “Wait, that means my business is within PCI scope!” Yes, it likely is. By being within scope, your business is subject to: - Annual PCI audits to evaluate systems and check for security vulnerabilities. - Potential quarterly reviews of the systems that store cardholder data. - Losses of up to $90 per compromised card in the event of a data breach. ### The Consequences of Ignoring PCI The fact is, you simply can’t ignore your PCI obligations. Consider the fact that Target’s earnings reportedly fell 46 percent in the immediate aftermath of its infamous 2013 data breach. Can your business sustain a revenue drop of this magnitude? Even if it does, PCI non-compliance can result in merchant account termination rendering you unable to accept credit or debit card transactions moving forward. So, let’s discuss what PCI is, how your CDE is configured, and how you can best reduce your scope to minimize your business’s risk of a data breach. ## An Overview of PCI DSS PCI DSS was put into place by the major card brands (Visa, MasterCard, Discover, and Amex) to reduce fraud-related losses by establishing higher security standards and enforcing their adherence. These guidelines also allow for the ranking of businesses based on their compliance. [PCI compliance](https://www.atlantic.net/pci-compliant-hosting/) is the highest achievable level. You can verify whether your current merchant services provider is PCI compliant by searching for it among the [Visa Global Registry of Service Providers](https://www.visa.com/splisting/searchGrsp.do). Compliance is assessed annually through audits and system tests that probe for vulnerabilities and evaluate implemented best practices. To ensure that your business and customers are safe, PCI compliance should be a requirement for any provider you partner with. This includes the provider of your processing terminal, e-commerce, point-of-sale software (POS), and virtual terminal if you have a patchwork setup. Additionally, it’s important to use common sense and best practices when storing and accessing data. While writing a frequent customer’s card number down and filing it in a cabinet may seem convenient, it violates PCI standards. Spreadsheets aren’t safer, even if your computer is password protected. Likewise, even if there isn’t cash in your drawers, locking up at night is vital if your computer or network interacts with cardholder data. ## The Components of Your CDE Your computer and network could be vulnerable due to the following components of your CDE: - **Networks:** Physical connections like Ethernet, wireless connections like Bluetooth, or virtual connections like firewalls. - **Applications:** Retail and mobile POS, virtual terminals or payment gateways, e-commerce websites, and management software that interacts with cardholder data. - **Software:** Processing software that is either native or SaaS. Native software must be downloaded to your servers, which opens your business up to PCI scope. To reduce your liability, you can implement the following best practices when it comes to your network, applications, and software: - Leverage network segmentation to isolate where cardholder data is stored. - Elect to only use applications that are secured using point-to-point encryption (P2PE) or tokenization. - Middleware is an additional piece of software that’s often required to connect your POS to your card reader, but select EMV-certified processing terminals connect to your network via Ethernet instead of middleware. This means all cardholder data bypasses your computer and network for reduced PCI scope. ## Streamlining Your Providers for Simpler Compliance By partnering with a proven and tested all-in-one provider that is PCI-compliant, you can minimize your liability. Opting for Atlantic.Net hosting, using a processing terminal that lacks middleware, and committing to best practices for storing cardholder data can all contribute to a safer, more compliant business environment where no cardholder data is transmitted, processed, or stored on your computer or network. If a fraudster breaks into your business location, you can rest assured that cardholder data isn’t compromised. Furthermore, choosing a provider that [uses tokenization to protect cardholder data](https://blog.payjunction.com/point-to-point-encryption-cloud/) will ensure that your customers’ information isn’t compromised throughout the transaction process. ## Why Choose Atlantic.Net? Contracting with Atlantic.Net for [PCI-DSS-compliant web hosting](https://www.atlantic.net/pci-compliant-hosting/) gives you peace of mind that your provider knows what they’re doing. Atlantic.Net is SOC 2, SOC 3, HIPAA audited, and PCI ready and provides customers and those who process credit cards with the hardened, secure, and compliant infrastructure they need. --- # The Growing Threat of Ransomware in 2021 > URL: https://www.atlantic.net/hipaa-compliant-hosting/the-growing-threat-of-ransomware-in-2021/ | Published: 2021-07-09 | Updated: 2026-05-30 | Author: Richard Bailey *Atlantic.Net is providing this security advisory as a news item. We want to reassure our customers that Atlantic.Net does not use any of these exploited products internally or in any of our service offerings.* Barely a week goes past without a breaking news report about the latest high-profile business or government organization to be targeted by ransomware. Ransomware is everywhere, and cybercriminals are stealing business revenue in the form of cryptocurrency and hijacking sensitive data at an alarming rate. Ransomware is not a new phenomenon, but it has been growing into a serious threat over the last decade. Year after year, the threat is becoming more profound. Until recently, victims have been held to ransom after an attacker gained unauthorized access to critical IT systems. These systems were encrypted, locking legitimate users out and essentially paralyzing day-to-day business operations. Fortunately, many businesses were able to recover from backup relatively quickly, and the few that had invested in disaster recovery capabilities were up and running in no time. However, there were still far too many paying the ransom due to inadequate security safeguards. ## How Ransomware Is Changing Today the scope of the attacks is changing. Businesses are still targeted with ransomware that renders their systems unusable with encrypted files, but besides encrypting files and folders, the cybercriminals are stealing sensitive business data such as intellectual property or sensitive employee and customer data; sometimes entire company email systems are breached. While the attack vectors remain identical, successful phishing campaigns and RDP attacks are still the most popular ways of gaining unauthorized access. The type of victim is changing, too; more recent attacks have focused on the supply chain, targeting one big fish to get access to all of the other, smaller fish that use the big fish’s software or infrastructure. In this article, we will discuss some of the biggest ransomware attacks in 2021. Then, we’ll discuss what a managed services provider like Atlantic.Net can do to reduce your attack surface and how we can protect your IT investment. ## The Biggest Ransomware Attacks of 2021 ### Solarwinds 2021 started in turmoil after the [Solarwinds Hack](https://www.atlantic.net/vps-hosting/solarwinds-orion-hack/) of December 2020. Businesses and government agencies were still reeling from[the supply chain cyberattack](https://www.atlantic.net/vps-hosting/solarwinds-orion-hack-part-2/) that impacted a large percentage of SolarWinds customers. Even today we are still learning about the impact of this data breach, but the incident started a trend where cybercriminals began targeting US infrastructure as well as businesses. ### Colonial Pipeline The Colonial Pipeline breach was reported on May 7th, 2021; what makes this breach significant is the direct impact it had on ordinary citizens. The oil refinery is one of the biggest in the United States, serving gas to over half of the east coast. It caused an instantaneous spike in gas prices. [People were panic buying](https://www.reuters.com/world/us/far-colonial-pipeline-panic-buying-leaves-florida-cities-short-gas-2021-05-13/#:~:text=Even%20as%20Colonial%20has%20begun,regions%20far%20from%20the%20pipeline.&text=Yet%20some%20of%20the%20southern,than%20those%20in%20the%20north.), and long queues were observed at many gas stations. To make matters worse, the Colonial Pipeline Company paid the ransom of approximately $4.4 million.  Some of this money has been [recovered by the Department of Justice,](https://www.vox.com/recode/22428774/ransomeware-pipeline-colonial-darkside-gas-prices) but unfortunately it sends the wrong message to the hackers involved and arguably gives the attackers further reason to pursue victims with ransomware. ### JBS Meat Plants Another major recent supply chain attack was against JBS Meat Plants, a pork and poultry company that serves ⅕ of the US meat market. Again, JBS paid the ransom, [believed to be $11 million](https://thehackernews.com/2021/06/beef-supplier-jbs-paid-hackers-11.html)! The attack resulted in factories being closed and production being ceased, causing supermarkets and restaurants to run low on meat products. Just one day’s closure threatened the wholesale price of meat, with the average restaurant [adding $4 for beef](https://www.nytimes.com/2021/06/01/business/meat-plant-cyberattack-jbs.html)dishes. This can be a big threat in [restaurant management](https://www.7shifts.com/blog/restaurant-management-guide/). ### Kaseya These are just three examples that have jeopardized businesses and government organizations in the last 6 months. Only last week, a huge demand of $70 million has been made against US IT management company [Kaseya.](https://thehackernews.com/2021/07/revil-used-0-day-in-kaseya-ransomware.html) This attack is still unfolding, but it could be worse than the SolarWinds breach. ## What Can Companies Do to Protect Their Livelihood and Business? The US government now considers ransomware attacks to have the[same priority as terrorism](https://www.reuters.com/technology/exclusive-us-give-ransomware-hacks-similar-priority-terrorism-official-says-2021-06-03/), and in recent meetings with Vladamir Putin, [ransomware has been increasingly on the agenda](https://www.npr.org/2021/06/17/1007632156/biden-tells-putin-to-crackdown-on-ransomware-what-are-the-odds-he-will?t=1625514036922). This change in stance is important, and we hope that more resources will be given to fighting the threat and finding these attackers. Atlantic.Net has 30 years of experience in providing security-defined, hardened, and robust managed services for our customers. Many of our customers have additional security requirements necessitated by [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) or [PCI-compliant hosting](https://www.atlantic.net/pci-compliant-hosting/). Leveraging our Cloud services will protect you from ransomware infection and ensure that your infrastructure and network are in a healthy state to give the best possible protection. ### Managed Services for Security Our managed services teams and professional consultancy services create added protection. Let us manage your server infrastructure and we will take care of all your security patching requirements on top of the day-to-day upkeep we perform on our cloud platform. One of the best methods to protect against malware is to ensure that your infrastructure is patched to the very latest levels. This includes host server patching, operating systems updates, firmware updates, and microcode updates. ### Backups A tried and tested backup strategy should also be a priority. If the worst does happen and you are impacted by ransomware, often the quickest resolution is to restore from backup. Regular offsite backups should be completed on a daily, weekly, and monthly rotation to reduce the likelihood of the backups also being infected. Atlantic.Net Consultants can create and test a disaster recovery solution, including a scenario where a total outage is caused by ransomware.  This will typically be a disaster recovery setup at a secondary site. ### Vulnerability Scanning & Risk Analysis Vulnerability scanning is a technique of testing external and internal computer infrastructure against all known vulnerabilities. It’s a solution that is highly effective at preventing hacked systems since you are able to take preventative measures to patch any vulnerabilities. Atlantic.Net systems are tested for weakness often, and our team can recommend some of our trusted partners to test your systems directly with penetration testing. Atlantic.Net can also advise and offer key safeguards that can be implemented. One such safeguard is to create a system inventory of all your business assets; cataloging what assets you own will allow you to create a baseline to work from to create a risk analysis. A cybersecurity risk analysis is a process to identify security weaknesses and create a priority list of what to fix first. ### Training Finally, training! Probably the best protection against ransomware is to train all employees about the risks of ransomware. This should help them to understand what cybersecurity is and what to look out for in avoiding risks. Common examples include being on the lookout for phishing, scams, and fake websites; our experts are available to recommend training suitable for your teams. ## About Atlantic.Net If your business is concerned about cybersecurity, please feel welcome to reach out to Atlantic.Net. We are specialists in Managed Services, Cloud Hosting, and HIPAA Compliance. Security of our infrastructure is of paramount importance, and we work hard to ensure we have the best security processes in place. Atlantic.Net has a full suite of Managed Security Services to help be proactive and prepare in advance for any security issues. Get in touch today. Learn more about our [HIPAA compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. --- # Announcement: Our Free G3.2GB Server Promotion Now Available in Dallas and London Data Centers! > URL: https://www.atlantic.net/announcements/our-free-g3-2gb-server-promotion-now-available-in-dallas-and-london-data-centers/ | Published: 2021-07-10 | Updated: 2025-09-19 | Author: Alexander Wise We are pleased to expand our offer enabling new cloud VPS customers to double their server resources at no extra cost. Atlantic.Net will upgrade all cloud plans to the capabilities of the next highest price bracket at no additional cost for new customers at all its data centers. This program also includes Atlantic.Net’s Free-to-Use for One Year Server promotion, meaning that any new free tier users will be automatically upgraded from 1GB to 2GB Cloud Server usage for one full year. Our G3 plans offer more powerful and cost-effective Cloud Severs, which should help attract growth customers and make it an easier choice for existing customers to expand their business with us. We are excited to continue to offer entrepreneurs a full year of free service. Atlantic.Net initially offered the new program in Orlando, New York, Ashburn, Toronto, and San Francisco, but has now expanded it to Dallas and London. Customers will be able to take advantage of the G3 plans with double the memory and 1TB more outbound data transfer than the G2 plans. Some plans have better vCPU and disk space, and three larger 48 GB, 96 GB, and 192 GB RAM plans are also newly available. To view the latest cloud offerings and pricing structure, visit [VPS Hosting](https://www.atlantic.net/vps-hosting/). --- # Kaseya Ransomware Attack July 2021 > URL: https://www.atlantic.net/hipaa-compliant-hosting/kaseya-ransomware-attack-july-2021/ | Published: 2021-07-12 | Updated: 2024-10-31 | Author: Richard Bailey *Atlantic.Net is providing this security advisory as a news item. We want to reassure our customers that Atlantic.Net does not use any of these exploited products internally or in any of our service offerings.* On July 2nd, 2021, during the run-up to Independence Day, we started getting reports of a major ransomware attack affecting [Florida-based Kaseya](https://www.kaseya.com/potential-attack-on-kaseya-vsa/). Kaseya is a technology company that sells software designed to simplify the management of your computer infrastructure. Their target clientele is small businesses with minimal in-house tech teams or managed service providers (MSPs) that manage IT for businesses. ## Who Is Affected? The ransomware is reported to have affected the [Kaseya VSA](https://www.kaseya.com/products/vsa/) product only. Kaseya VSA is an all-in-one suite created to allow businesses the end-to-end management of not only their IT systems, point of sale systems, servers, laptops, patch management, monitoring, but also DR backups, antivirus, SaaS backups, and so on. ## Who Is Behind the Attack? The attack, called a supply chain attack, was undertaken by the REvil Ransomware Group, a Russian-based criminal group. In a supply chain attack, a provider is targeted and the victim’s customers become the target. This is a trend that appears to be on the rise, as we saw it in December 2020 with the notorious SolarWinds Orion supply chain attack. The attack vectors are strikingly similar to the SolarWinds breach. Experts originally suspected Kaseya VSA trusted distribution network or the mechanism used to deliver software updates to customers was breached, but we now know that the breach was a result of a zero-day exploit [CVE-2021-30116](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30116).  The exploit allowed the hackers to bypass authentication and execute remote commands down the supply chain. ## What Was the Impact of the Attack? On July 2nd, Kaseya requested that all customers with the [on-premise version of Kaseya are shut down](https://www.kaseya.com/potential-attack-on-kaseya-vsa/), later followed by the shutdown of the SaaS offering.  Dutch security team [DIVD CSIRT](https://csirt.divd.nl/2021/07/04/Kaseya-Case-Update-2/) reported that the number of active Kaseya VSA instances dropped from 2200 to less than 140 in the space of 24 hours. VSA has remained down for 8 days now and is still down at the time of writing (10th July). CEO Fred Voccola stating that services were expected to resume on Sunday 11th July at 4 pm EST. The impact of this breach is still being understood. Kaseya performs a mission-critical operation to its customers, and an estimated 1500 businesses have been directly or indirectly impacted by the breach. The ransom has been set at [$70](https://www.reuters.com/technology/hackers-demand-70-million-liberate-data-held-by-companies-hit-mass-cyberattack-2021-07-05/)million. The impact was felt in 17 countries according to [Futurum Research](https://futurumresearch.com/research-notes/full-impact-of-revil-ransomware-attack-on-kaseya-becomes-apparent/) and included a [Swedish Supermarket chain that had to close 800](https://www.bbc.co.uk/news/technology-57707530)stores. Over[100 kindergartens in New Zealand](https://www.rnz.co.nz/news/national/446225/kaseya-ransomware-attack-hits-new-zealand-kindergartens) were impacted, and it is thought that 70% of the impacted customers were Managed Service Providers, each in turn with a countless number of clients. So far, the only MSPs to acknowledge the impact are Dutch MSPs [VelzArt](https://velzart.nl/blog/ransomeware/)and Hoppenbrouwer Techniek. Kaseya has been refreshingly transparent about the attack and [published a lot of information on their website](https://www.kaseya.com/potential-attack-on-kaseya-vsa/). Their CTO and CEO have published video content online explaining to customers what has happened and the plans for the business to resolve the issue and get the service back online. ## What Can You Do to Protect Yourself? The US Government was quick to react to the Kaseya attack, and Kaseya’s CEO has reported working directly with Homeland Security and the FBI. This approach reinforces that the US Government is starting to give ransomware attacks the same priority as terrorist activities. The best line of defense is to team up with a Managed Service Provider like Atlantic.Net that has the manpower to overcome and patch these attacks. We do not use any Kaseya products in our solutions, instead opting for proprietary solutions that are built, maintained, and operated in-house and within the USA. ## How Can Atlantic.Net Help? Atlantic.Net has 30 years of experience in providing security-defined, hardened, and robust managed services for our customers. Leveraging our Cloud services will protect you from ransomware infection and ensure that your infrastructure and network are in a healthy state to give the best possible protection. Let us manage your server infrastructure; we will take care of all your security patching requirements on top of the day-to-day upkeep we perform on our cloud platform. When impacted by ransomware, the quickest resolution is nearly always to restore from backup. Regular offsite backups should be completed at least on a daily, weekly, and monthly rotation to reduce the likelihood of the backups also being infected. Hackers gain access to systems when they are inadequately protected, and the best way to find if you are vulnerable is by performing vulnerability scanning. This technique tests the external and internal computer infrastructure against all known vulnerabilities. Atlantic.Net systems are tested for weakness often, and our team can recommend some of our trusted partners to test your systems directly with penetration testing.  In a situation like this, it is best to ensure that you are taking advantage of all best-known security practices to minimize any exposure to zero-day exploits like this Kaseya incident. If your business is concerned about cybersecurity please feel welcome to reach out to Atlantic.Net. We are specialists in Managed Services, Cloud Hosting, and [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). Security of our infrastructure is of paramount importance, and we work hard to ensure we have the best security processes in place.  Atlantic.Net has a full suite of [Managed Security Services](https://www.atlantic.net/managed-services/) to help us and our customers be proactive and prepare in advance for any security issues. Get in touch today. ## HIPAA Compliant Hosting with Atlantic.Net Contracting with Atlantic.Net for [HIPAA-compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) gives you peace of mind that your provider knows what they’re doing. Atlantic.Net is SOC 2, SOC 3, HIPAA audited, and [PCI](https://www.atlantic.net/pci-compliant-hosting/) ready, providing clients with the hardened, secure, and compliant infrastructure they need. --- # What Do I Need to Do to Become HIPAA Compliant With Atlantic.Net? > URL: https://www.atlantic.net/hipaa-compliant-hosting/what-do-i-need-to-do-to-become-hipaa-compliant-with-atlantic-net/ | Published: 2021-07-22 | Updated: 2025-09-10 | Author: Richard Bailey Achieving a HIPAA-compliant status for your cloud environment is a much easier process when signing up with Atlantic.Net’s [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) services. With this service, the majority of the cloud hosting responsibilities are picked up by the teams at Atlantic.Net; however, due to the nature of HIPAA compliance certification, there are a few parts of HIPAA that each of our customers must either be fully or partially responsible for. HIPAA compliance is achieved when all of the mandated physical, technical, and administrative safeguards are met. This includes the Privacy and Security rule amendments of 2003 and the Final Omnibus Rule of 2013. We will go into detail about what all that means to you, the customer. Although some of the following may seem like a daunting task, you can rest easy, because Atlantic.Net can handle 90% of the requirements with managed services. In reality, our HIPAA compliant customers only need to worry about a small fraction of the overall process. As always, if ever you need to contact our teams to discuss your requirements, you are welcome to [get in touch today](https://www.atlantic.net/about-us/corporate-contact/). ## Customer Responsibilities Inevitably with HIPAA Compliance, some elements need to be completed by the client. These parts are focused on customer data and patient data and relate to information systems directly handled by the client. ## **![](https://www.atlantic.net/wp-content/uploads/2021/07/icon_database-management-e1640013378656.png)Database Management** Atlantic.Net hosting solutions will stand up a database instance for you on our cloud platform; however, the day-to-day administration is the responsibility of the customer. Atlantic.Net engineers do not have any user access to your system, making managing the DB an impossible task for our engineers. The customer is responsible for the structure of the data, how the tables are defined, and so forth, and they are also [responsible for user administration and security](https://hipaatimes.com/top-healthcare-cybersecurity-concerns-for-2025). The instance Atlantic.Net provides is hardened to industry best practices; however, each client will need to force adequate system controls to protect unauthorized access to data. Clients are responsible for the day-to-day maintenance of any database applications hosted on the platform, including database security, user credentials, and privileges. This also includes the data contained within the database. If the customer requires the database to be additionally encrypted, this must be managed by the customer; this is highly recommended according to industry best practices. ## **![](https://www.atlantic.net/wp-content/uploads/2021/07/icon_customer-data-e1640013399834.png)Customer Data** Each client is responsible for their customer data. This includes importing, managing, and updating all data. The customer is required by HIPAA legislation to have accurate data held on each patient and to respond promptly to information requests from the patient. Atlantic.Net has no access to customer data, and as a result, this must be managed in-house by the customer. ## **![](https://www.atlantic.net/wp-content/uploads/2021/07/icon_apps.png)Applications** – As a client of Atlantic.Net, you are responsible for the maintenance of your applications. This includes the installation, configuration, and upkeep, such as security patching, unless you opt for our Server Management which can cover these requirements depending on the applications. Every healthcare organization uses different HIPAA compliant applications, and many also use their own proprietary applications. As a result, supporting applications is very difficult for a managed service provider. You will receive a similar response at most MSPs; alternatively, the price will be reflective of the custom one-off work that is required to properly maintain these types of applications. It is the customer’s responsibility to manage and maintain any additional software licensing used in day-to-day operations, including off-the-shelf applications or in-house custom software. Please note that we do offer Managed Service options that offer support up to and including the operating system. ## **![](https://www.atlantic.net/wp-content/uploads/2021/07/icon_identity-e1640013440459.png)Identity & Access Management** Each customer is responsible for managing their directory services, such as Active Directory or any other LDAP solution. This includes permission-based access and access to the Atlantic.Net control panel. The client owns the entire user lifecycle process. This includes adding, modifying, and deleting users and handling all-access queries about permissions. Atlantic.Net will provide the tools to complete the job. ![](https://www.atlantic.net/wp-content/uploads/2021/07/icon_client-side-data-enryption-e1640013459848.png) ## **Client-Side Data Encryption and Data Integrity Authentication** Any protected health information stored locally on client internal IT Systems is the responsibility of the client. What this means is that employees must ensure that files are encrypted locally and that correct protocol is followed when transmitting PHI locally. This is typically any frontend client-side encryption technology, such as PGP, BitLocker, and any application-specific encryption. Once the data is in the Atlantic.Net cloud, our systems will ensure protective measures are followed; however, to be HIPAA compliant, patient data must be protected before sending to the cloud platform. ## **![](https://www.atlantic.net/wp-content/uploads/2021/07/icon_service-side-encryption-e1640013487783.png)Service-Side Encryption (File and Data)** Once the data is stored inside the Atlantic.Net cloud, the customer must ensure that files remain encrypted and that the data remains valid. Any backend service-side encryption technology, which is typically database and application-specific encryption, is the responsibility of the customer outside of the physical disks since they are encrypted at rest by default by Atlantic.Net. Employees shouldn’t decrypt files server-side or copy them to their devices. The entire process must be audited from end to end. If you have any queries about these customer requirements, then please talk to the team. We are more than happy to explain the exact requirements to you. HIPAA compliance is hard to achieve, and unfortunately, there are some elements that Atlantic.Net are unable to control until ingested into our systems. ## ![](https://www.atlantic.net/wp-content/uploads/2021/07/icon_difference.png)The Atlantic.Net Difference Atlantic.Net will do as much as possible to help our healthcare clients. We are always available for help and assistance, so do not hesitate to get in touch. Unfortunately, due to the complexity of HIPAA Compliance, there are just some tasks that Atlantic.Net is unable to do for our clients. If there is ever a time that your request is outside our scope of support, we can offer a one-time fee for a professional service agreement if our team is able to handle the request. These are hourly-based support requests for those times when you need a specialized helping hand that Atlantic.Net normally doesn’t provide. The good news is that we handle just about everything else, including managing the Cloud Servers, storage, networking, encryption-at-rest, physical security, and the day-to-day management of the Cloud Platform. Elsewhere several elements come with shared responsibility: auto-patching, log inspection, VPN management, DNS, and integrity monitoring. Please check [this article](https://www.atlantic.net/hipaa-compliant-hosting/what-makes-atlantic-net-hipaa-compliant/) if you want to learn more about the Atlantic.Net shared responsibility model. Atlantic.Net has over 30 years of experience providing customer-oriented IT Solutions. We are renowned for our HIPAA-compliant cloud services, supported by a security-defined platform architected to the highest standards. Our HIPAA-compliant cloud is available as a managed service or via a self-service offering – the perfect choice for your next healthcare project. ## ![](https://www.atlantic.net/wp-content/uploads/2021/07/icon_get-help.png)Get Help with HIPAA Compliance Atlantic.Net stands ready to help you attain fast compliance with a range of certifications, such as SOC 2 and SOC 3, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/), and HITECH, all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282), or visit [www.atlantic.net](https://www.atlantic.net). --- # Incident Response in PCI DSS > URL: https://www.atlantic.net/pci-compliant-hosting/incident-response-in-pci-dss/ | Published: 2021-08-03 | Updated: 2025-09-19 | Author: Gilad Maayan Incident response is a critical process in every organization. If you are processing or storing credit cardholder data, it becomes even more important and can impact your compliance with the PCI DSS standard. In this article, we’ll cover the basics of PCI DSS and explain how you should [adapt your incident response process](https://www.cynet.com/incident-response/) to comply with the standard and ensure the required level of protection for sensitive credit card information. ## What is PCI DSS? The [Payment Card Industry Data Security Standard](https://www.pcisecuritystandards.org/) (PCI DSS) is a collection of security standards regulating the use of credit card information. It was formed in 2004 by MasterCard, Visa, Discover Financial Services, JCB International, and American Express. The Payment Card Industry Security Standards Council (PCI SSC) is the entity that governs the PCI DSS. The purpose of the standard is to prevent fraud and data theft by securing debit and credit card transactions. The PCI council does not have the legal authority to enforce compliance. However, PCI DSS is a mandatory requirement for all organizations processing debit and credit card transactions; organizations who fail to comply may be fined by their payment processor, and in extreme cases, can be blocked from performing credit card transactions. Organizations can get a PCI certification if they meet certain requirements established by the PCI council. Some common security measures mandated by PCI DSS are the use of firewalls, antivirus software, and [data protection measures](https://cloudian.com/guides/data-protection/data-protection-and-privacy-7-ways-to-protect-user-data/) such as encryption, intrusion prevention systems, and [data loss prevention (DLP)](https://www.nightfall.ai/blog/data-loss-prevention-fundamentals-and-best-practices-nightfall). ## PCI DSS Incident Response Requirements When implementing an incident response procedure in an organization impacted by PCI DSS, you should take into account two main PCI DSS requirements: - **Requirement 10—Implement Logging and Log Management** - **Requirement 12—Documentation and Risk Assessments** Below we describe each of these in more depth and how they can affect your incident response operation. ### PCI DSS Requirement 10: Implement Logging and Log Management Requirement 10 stipulates that a merchant must “establish a process for linking all access to system components (especially access done with administrative privileges such as root) to each individual user.” Requirement 10 was created to ensure the reliable and safe transfer of credit and payment card data through the use of monitoring and analysis of system activity logs. To comply with this requirement, organizations need to protect customer data against many types of threats. #### Complying with Requirement 10 Requirement 10 security controls are a common contributing factor to data breaches. System event logs record small bits of information about actions performed on printers, office computers, firewalls, and other systems. Logs can help detect threats and weaknesses. However, to truly be useful, logs should be regularly reviewed. Requirement 10 stipulates that logs must be reviewed on a daily basis, at the very least. Logs should be searched for anomalies, errors, and any suspicious activities deviating from the norm. Additionally, to comply with Requirement 10, organizations are asked to set up a process for responding to the anomalies and exceptions detected in their logs. Log monitoring systems can help you gain visibility and control over logs, especially when this functionality comes built into your [security information and event monitoring (SIEM) solution](https://www.exabeam.com/siem-guide/). Log monitoring functionality can store user actions occurring within the ecosystem, monitor and inspect system events, and push alerts when suspicious activity is detected. #### How Requirement 10 Impacts Incident Response This requirement specifies how you should record and monitor logs to identify security incidents. Logs are one of the main ways to identify and triage security events in an incident response process. To ensure your incident response is PCI DSS compliant, implement compliant logging systems, and ensure log anomalies are reviewed by security staff at the required frequency. ### PCI DSS Requirement 12: Documentation and Risk Assessments PCI DSS requirement 12 stipulates that all policies, documentation, procedures, and any evidence related to the security practices of the organizations must be safely stored. During assessments, a Qualified Security Assessor (QSA) usually checks that company policies and procedures (P&P) document and define the relevant PCI requirements. Next, QSAs follow a predefined testing procedure designed to ensure that all relevant policy controls have been implemented in compliance with the PCI DSS. #### Complying with Requirement 12 To comply with Requirement 12, your organization must include certain information in its PCI documentation, including employee manuals, third-party vendor agreements, policies and procedures, and incident response plans. In addition to documentation, the organization must perform a formal risk assessment on an annual basis. This assessment must identify critical assets, vulnerabilities, and threats. It can help organizations in the identification, prioritization, and management of information security risks. #### How Requirement 12 Impacts Incident Response To be compliant, ensure your incident response process is comprehensively documented and that any change to the process is documented as well. In addition, it is not sufficient to perform ad-hoc improvements to incident response processes or post mortem after major incidents. PCI DSS requires you to conduct a full threat assessment, document your findings, and incorporate the results of the assessment into your incident response process. Specifically, you will need to develop and document incident response procedures for every major threat. ## How to Implement a Successful Incident Response Plan for PCI DSS Beyond specific adjustments you may have to make in light of PCI DSS Requirements 10 and 12, take the following steps to implement a PCI-compliant incident response process in your organization: 1. **Identify and prioritize critical assets**—identify where your sensitive data and mission-critical applications are located. Make a list of these critical assets, which will cause heavy damage to the organization if compromised. Classify assets into risk groups and define a protection plan and budget for each group. 2. **Establish procedures and policies**—create clear, well-documented procedures for personnel to follow when an incident occurs. The process should detail the role of operational and security staff, when and how to escalate the incident, internal and external communication protocols, and when to enlist help from third parties like consultants, legal, or PR. 3. **Establish an incident response team**—you must have a team of individuals, who may be dedicated full time to incident response or take on this responsibility alongside a related role in IT operations or security. Each member of the team should have clear roles and responsibilities in case of a cyber incident. 4. **Educate all stakeholders about the incident response plan**—a cyber incident can affect different parts of the organization, from IT to software development, legal, HR, and public relations, all the way to senior management. All relevant stakeholders must be aware of your incident response plan, and should also be encouraged to provide inputs from their perspective. This will ensure that when a cyber incident occurs, everyone is aligned on the steps that should be taken, and roles and responsibilities are clear. 5. **Get buy-in from senior management**—an incident response plan cannot succeed if senior management is not involved. This is especially true if incident response measures require a budget—for example, to procure security tools, leverage third-party security services, or perform training and certifications for staff. Present the incident response plan to management, explain the security and compliance implications, and the business benefits of incident response to the company. 6. **Security training for employees**—incident response will not be effective without security awareness and a culture of secure business practices. Conduct regular security training for all employees, and ensure everyone in the company knows how to recognize and avoid social engineering, and is aware of their responsibility to prevent and actively report security violations. 7. **Test your plan**—incident response plans cannot remain on paper until an incident occurs. Validate your plans using tabletop exercises involving all relevant staff. Conduct regular, realistic drills and exercises to ensure your team can work together effectively when an incident occurs. After every tabletop or simulation, review the incident response plan to identify gaps and update it to address them. ## Conclusion In this article I covered several ways PCI DSS compliance impacts incident response: Requirement 10 specifies how you should log events and review log data, as part of security event triage and detection of security incidents. Requirement 12 specifies that your incident response process must be formal and documented, and must be informed by an annual threat assessment. Beyond these specific requirements, you must implement an incident response process that prioritizes critical assets, establishes a clear process and a well-defined incident response team, is shared with stakeholders across the organization, and includes education for management and employees (even if they are not directly involved in incident response). I hope this will be of help as you move closer to a secure, PCI-compliant IT environment. ## PCI Hosting with Atlantic.Net Contracting with Atlantic.Net for [PCI web hosting](https://www.atlantic.net/pci-compliant-hosting/) gives you peace of mind that your provider knows what they’re doing. Atlantic.Net is SOC 2, SOC 3, HIPAA audited, and [PCI](https://www.atlantic.net/pci-compliant-hosting/) ready, providing clients with the hardened, secure, and compliant infrastructure they need. --- # How to Install PHP 8.5 on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-php-8-5-on-rocky-linux-10/ | Published: 2021-08-04 | Updated: 2025-10-24 | Author: Hitesh Jethva PHP is a server-side scripting language, also known as a “**Hypertext Preprocessor.**” It is used for developing static and dynamic web applications. PHP is used by many popular frameworks including Laravel, Symfony, and CodeIgniter. PHP 8.5 was officially released on November 26, 2020. At the time of writing this tutorial, the latest stable release is PHP 8.5. In this post, we will show you how to install PHP 8.5 on Rocky Linux 10. ## Step 1 – Install EPEL and Remi PHP Repository In order to install PHP 8.4, you will need to install the EPEL and Remi PHP repositories on your system. You can install them with the following command: ``` dnf install epel-release -y dnf install dnf-utils https://rpms.remirepo.net/enterprise/remi-release-10.rpm -y ``` Once both packages are installed, verify the available PHP versions with the following command: ``` dnf module list php ``` You should see the following output: ``` Remi's Modular repository for Enterprise Linux 10 - x86_64 Name Stream Profiles Summary php remi-7.4 common [d], devel, minimal PHP scripting language php remi-8.0 common [d], devel, minimal PHP scripting language php remi-8.1 common [d], devel, minimal PHP scripting language php remi-8.2 common [d], devel, minimal PHP scripting language php remi-8.3 common [d], devel, minimal PHP scripting language php remi-8.4 [e] common [d], devel, minimal PHP scripting language php remi-8.5 common [d], devel, minimal PHP scripting language Hint: [d]efault, [e]nabled, [x]disabled, [i]nstalled ``` ## Step 2 – Install PHP 8.5 on Rocky Linux 10 First, reset the default PHP module with the following command: ``` dnf module reset php ``` ``` Next, enable the Remi PHP 8.5 module with the following command: ``` ``` dnf module enable php:remi-8.5 ``` You should see the following output: ``` Last metadata expiration check: 0:01:43 ago on Sat 25 Oct 2025 12:16:41 AM EDT. Dependencies resolved. ======================================================================================================================================================================================== Package Architecture Version Repository Size ======================================================================================================================================================================================== Enabling module streams: php remi-8.5 Transaction Summary ======================================================================================================================================================================================== Is this ok [y/N]: y Complete! ``` Next, install PHP with other common extensions using the following command: ``` dnf install php php-cli php-mysqlnd php-gd php-curl -y ``` Once PHP has been installed, you can verify the PHP version with the following command: ``` php -v ``` You should see the following output: ``` PHP 8.5.0RC3 (cli) (built: Oct 21 2025 20:30:57) (NTS gcc x86_64) Copyright (c) The PHP Group Built by Remi's RPM repository #StandWithUkraine Zend Engine v4.5.0RC3, Copyright (c) Zend Technologies with Zend OPcache v8.5.0RC3, Copyright (c), by Zend Technologies ``` ## Conclusion Congratulations! You have successfully installed PHP 8.5 on Rocky Linux 10. PHP 8.5 comes with some major updates and new features including, error handling, match expression, null safe operator, JIT, and more. You can now upgrade your older PHP version to the latest PHP 8.5 and take its improved performance benefit. Give it a try on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Joomla 6 on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-joomla-6-on-rocky-linux-10/ | Published: 2021-08-05 | Updated: 2025-10-25 | Author: Hitesh Jethva Joomla is an open-source and PHP-based content management system used for creating different types of websites including blogs, eCommerce storefronts, and marketing sites. It is simple, user-friendly, and provides an easy way to build dynamic and powerful websites. You can use Joomla to host your website on the Internet easily without the need to learn how to read and write complicated codes and scripts. In this post, we will show you how to install Joomla with Nginx on Rocky Linux 10. ## Step 1 – Install Nginx and MariaDB First, install the Nginx and MariaDB database servers with the following command: ``` dnf install nginx mariadb-server -y ``` Once both packages are installed, start the Nginx and MariaDB services and enable them to start at system reboot: ``` systemctl start nginx mariadb systemctl enable nginx mariadb ``` ## Step 2 – Install PHP and PHP-FPM Next, you will need to install PHP, PHP-FPM, and other PHP extensions on your server. You can install PHP with other extensions using the following command: ``` dnf install php php-fpm php-curl php-xml php-zip php-mysqlnd php-intl php-gd php-json php-ldap php-mbstring php-opcache unzip -y ``` Once all the packages are installed, edit the php.ini file and tweak some settings: ``` nano /etc/php.ini ``` Change the following values: ``` memory_limit = 256M output_buffering = Off max_execution_time = 300 date.timezone = Europe/London ``` Save and close the file when you are done. Next, edit the PHP-FPM configuration file: ``` nano /etc/php-fpm.d/www.conf ``` Change the user and group from apache to nginx: ``` user = nginx group = nginx ``` Save and close the file, then set proper permissions to the PHP library directory: ``` chown -R nginx:nginx /var/lib/php/ ``` Next, start the PHP-FPM service and enable it to start at system reboot: ``` systemctl start php-fpm systemctl enable php-fpm ``` ## Step 3 – Create a Joomla Database Joomla uses MySQL/MariaDB as a database backend, so you will need to create a database and user for Joomla. First, log in to the MariaDB shell with the following command: ``` mysql ``` Once you are connected, create a database and user with the following command: ``` CREATE DATABASE joomladb; GRANT ALL PRIVILEGES ON joomladb.* TO 'joomla'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 4 – Download Joomla Next, go to the Joomla download and download the latest version of Joomla using the following command: ``` wget https://downloads.joomla.org/cms/joomla6/6-0-0/Joomla_6-0-0-Stable-Full_Package.zip ``` Next, create a directory for Joomla and extract the downloaded file inside the joomla directory: ``` mkdir -p /var/www/html/joomla unzip Joomla*.zip -d /var/www/html/joomla ``` Next, set proper permissions and ownership to the joomla directory: ``` chown -R nginx:nginx /var/www/html/joomla chmod -R 755 /var/www/html/joomla ``` ## Step 5 – Configure Nginx for Joomla Next, you will need to create an Nginx virtual host configuration file for Joomla. You can create it with the following command: ``` nano /etc/nginx/conf.d/joomla.conf ``` Add the following lines: ``` server { listen 80; root /var/www/html/joomla; index index.php index.html index.htm; server_name joomla.example.com; location / { try_files $uri $uri/ /index.php?$args; } location ~ [^/]\.php(/|$) { fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_index index.php; fastcgi_pass unix:/run/php-fpm/www.sock; include fastcgi_params; fastcgi_param PATH_INFO $fastcgi_path_info; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; } } ``` Save and close the file, then restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 6 – Access Joomla Website Now, Joomla is installed and configured on your server. You can now access the Joomla website using the URL **http://joomla.example.com**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/08/j1.png) Provide your site information and click on **Setup Login Data**. You should see the database configuration page: ![](https://www.atlantic.net/wp-content/uploads/2021/08/j2.png)Provide your admin username, password, email and click on **Setup Database Connection**. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2021/08/j3.png) Provide your database information and click on the **Install Joomla** button. Once the installation has been finished, you should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/08/j4.png)   Now, open a new tab in your web browser and access the Joomla administrator console using the URL http://joomla.example.com/administrator/. ![](https://www.atlantic.net/wp-content/uploads/2021/08/j6.png) Provide your admin username and password, then click on the **Login** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/08/j7.png) ## Conclusion In this guide, we explained how to install Joomla with Nginx on Rocky Linux 10. You can now use your [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) account to start creating your blog or website using Joomla. --- # How to Secure Rocky Linux > URL: https://www.atlantic.net/vps-hosting/how-to-secure-rocky-linux/ | Published: 2021-08-06 | Updated: 2025-10-24 | Author: Hitesh Jethva Security is an essential consideration for any server you launch into a production environment. The latest version of Rocky Linux 10 comes with robust security features. However, not all of them are active or properly configured by default, so a fresh installation is always vulnerable to hacks and intrusion attacks. In this guide, we will have a look at a few important tasks to perform on the server for the initial setup and basic server hardening. This guide is tested on Rocky Linux 8, 9and 10. ## Step 1 – Update Your Server First, install the latest security patches and updates to your server. Run the following command to update them. ``` dnf update -y ``` Next, install some basic software packages by running the following command: ``` dnf install wget git curl bind-utils tree net-tools -y ``` ## Step 2 – Change the Default Root Password When you launch a new server, your servers are automatically set with secure passwords. However, it is recommended to change your root password every 60-90 days thereafter in order to ensure it remains secure. You should create a root password with a minimum of 8 characters, including lowercase characters, uppercase characters, and numbers. You can change the root password using the following command: ``` passwd root ``` ## Step 3 – Create a New User with sudo Privileges By default, the root is the default admin user for many Linux operating systems, including Rocky Linux, so it’s recommended to create a new user with sudo/root permissions and use it for day-to-day administration tasks. Generally, hackers target the root user because they know it’s the default admin user. Creating a new user with root permissions will increase the security of your server access. First, create a new user with the following command: ``` adduser user1 ``` Next, set the password user1 using the following command: ``` passwd user1 ``` After creating a new user, you will need to add this user to the sudo wheel group. In Rocky Linux, once you add them to the sudo wheel group, they are automatically assigned sudo/root permissions. Run the following command to add the user to the sudo wheel group. ``` usermod -aG wheel user1 ``` Once you created the user with sudo/root permissions, log in to user1 with the following command: ``` su - user1 ``` Once you are logged in, run the following command using sudo: ``` sudo dnf update -y ``` You will be asked to provide the user1 password to update your system. This will confirm that your sudo user is working as expected. ## Step 4 – Disable Root Login Via SSH We already created an admin user with sudo/root permissions to perform all tasks. You don’t need to keep the root user available and vulnerable over SSH on your server, so you will need to disable the root login via SSH. Edit the SSH main configuration file with the following command: ``` sudo nano /etc/ssh/sshd_config ``` Find the following line: ``` PermitRootLogin yes ``` Change it to the following line: ``` PermitRootLogin no ``` Save and close the file, then restart the SSH service to apply the changes: ``` systemctl restart sshd ``` ## Step 5 – Change SSH Default Port By default, SSH listens on port 22. Generally, hackers and bots continuously target the default SSH port 22, so it is recommended to change the default SSH port to any other port. To change the SSH port, edit the SSH main configuration file: ``` sudo nano /etc/ssh/sshd_config ``` Find the following line: ``` #Port 22 ``` Change it to the following lines: ``` Port 2020 ``` Save and close the file, then restart the SSH service to apply the changes: ``` systemctl restart sshd ``` You can now log in to your Atlantic server remotely via SSH using the following command: ``` ssh user1@your-server-ip -p 2020 ``` ## Step 6 – Configure a Firewall By default, your Atlantic.Net’s Rocky Linux is loaded with a default firewall named firewalld, but it is not enabled. You can check the status of the firewall using the following command: ``` firewall-cmd --state ``` You should see that firewall is not running: ``` not running ``` It is recommended to enable the firewall and allow necessary ports for external access. First, enable the firewalld service with the following command: ``` systemctl start firewalld systemctl enable firewalld ``` Next, allow the SSH port 2020 through the firewall with the following command: ``` sudo firewall-cmd --permanent --add-port=2020/tcp ``` Next, reload the firewalld service to apply the changes: ``` sudo firewall-cmd --reload ``` You can now verify the added ports with the following command: ``` sudo firewall-cmd --list-ports ``` You should see the following output: ``` 2020/tcp ``` If you have any web server installed and running on your server, you may need to allow the HTTP and HTTPS service through the firewall in order to access it over the Internet. ``` sudo firewall-cmd --permanent --add-service=http sudo firewall-cmd --permanent --add-service=https ``` To allow POP3, IMAP, and SMTP services for external access, run the following command: ``` sudo firewall-cmd --permanent --add-service=pop3s sudo firewall-cmd --permanent --add-service=imaps sudo firewall-cmd --permanent --add-service=smtp ``` ## Step 7 – Install NTP for Time Synchronization It is also recommended to install an NTP server to synchronize the time and date of computers over the network in order to keep them accurate and up to date. First, install the NTP server using the following command: ``` sudo dnf install chrony -y ``` Once the NTP service is installed, start it and enable it to start at system reboot: ``` sudo systemctl start chronyd sudo systemctl enable chronyd ``` Now, your NTP server is installed and will constantly update the server’s time from the NTP server. ## Step 8 – Disable IPv6 If you are not using IPv6, then it is recommended to disable it for security reasons. First, check whether IPv6 is enabled on your Rocky Linux installation using the following command: ``` ip a | grep inet6 ``` You should see the following lines if IPv6 is enabled: ``` inet6 ::1/128 scope host inet6 fe80::200:d8ff:fe62:817/64 scope link inet6 fe80::200:aff:fe62:817/64 scope link ``` You will need to create a new configuration file to disable IPv6: ``` sudo nano /etc/sysctl.d/70-ipv6.conf ``` Add the following lines: ``` net.ipv6.conf.all.disable_ipv6 = 1 net.ipv6.conf.default.disable_ipv6 = 1 ``` Save and close the file, then reload the configuration file with the following command: ``` sudo sysctl --load /etc/sysctl.d/70-ipv6.conf ``` You should see the following output: ``` net.ipv6.conf.all.disable_ipv6 = 1 net.ipv6.conf.default.disable_ipv6 = 1 ``` To verify IPv6 is disabled, run the following command: ``` ip a | grep inet6 ``` If the command doesn’t return anything, you have confirmed that IPv6 has been disabled on all your network interfaces. ## Step 9 – Create a Swap Space A swap is a space on a disk that is used when the amount of physical RAM memory is full. When your server runs out of RAM, all inactive pages are moved from the RAM to the swap space. When you launch a new instance on Atlantic.Net, it does not create a swap partition. You will need to create a swap space manually after launching the new instance. Generally, swap space should be half of your existing RAM. If you have 1GB of actual Ram, then you will need to create a 512MB file. First, create a swap space (of 512MB) with the following command: ``` sudo dd if=/dev/zero of=/swapfile bs=1024 count=524288 ``` Output: ``` 524288+0 records in 524288+0 records out 536870912 bytes (537 MB, 512 MiB) copied, 10.3523 s, 51.9 MB/s ``` You can calculate the block size using the formula 1024 x 512MB = 524288. After creating the Swap space, format it with the following command: ``` sudo mkswap /swapfile ``` Output: ``` mkswap: /swapfile: insecure permissions 0644, 0600 suggested. Setting up swapspace version 1, size = 512 MiB (536866816 bytes) no label, UUID=8981408a-549d-47aa-a99a-72870b65212d ``` Next, set proper permissions on the /swapfile with the following command: ``` sudo chown root:root /swapfile sudo chmod 0600 /swapfile ``` Next, activate the Swap space using the following command: ``` sudo swapon /swapfile ``` Next, verify the Swap space using the following command: ``` swapon -s ``` Output: ``` Filename Type Size Used Priority /swapfile file 524284 0 -2 ``` Next, you will need to add the Swap file entry to the /etc/fstab in order to make it active even after a reboot. ``` nano /etc/fstab ``` Add the following line: ``` /swapfile swap swap defaults 0 0 ``` Save and close the file, then verify the Swap space using the following command: ``` free -m ``` You should see the following output: ``` total used free shared buff/cache available Mem: 1817 263 100 68 1452 1329 Swap: 511 0 511 ``` ## Conclusion In the above guide, we explained some basic steps to secure your Rocky Linux server. You can now proceed to host any application in the secured environment – try it on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net! --- # Install LAMP Stack on Rocky Linux 10 > URL: https://www.atlantic.net/vps-hosting/install-lamp-stack-on-rocky-linux-10/ | Published: 2021-08-07 | Updated: 2025-10-24 | Author: Hitesh Jethva LAMP is free, open-source, and one of the most popular development stacks used by developers and hosting companies to host web applications on the internet. LAMP stands for Linux, Apache, MariaDB, and PHP. A LAMP stack is a group of open-source Linux-based web development software that includes Apache web server, MariaDB (or MySQL database server), and PHP. In this post, we will explain how to install a LAMP stack on Rocky Linux 10. ## Step 1 – Install Apache Web Server on Rocky Linux 10 By default, the Apache webserver is included in the Rocky Linux 10 default repo. You can install it by running the following command: ``` dnf install httpd -y ``` After the installation, run the following command to start the Apache service and enable it to start at system reboot. ``` systemctl start httpd systemctl enable httpd ``` Next, verify the status of the Apache service using the following command: ``` systemctl status httpd ``` You should see the following output: ``` ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; preset: disabled) Drop-In: /etc/systemd/system/httpd.service.d └─php-fpm.conf Active: active (running) since Fri 2025-10-24 23:50:02 EDT; 6s ago Invocation: 102f6c502c0948c88e9a72eb5bab1efe Docs: man:httpd.service(8) Main PID: 150020 (httpd) Status: "Started, listening on: port 3000, port 80" Tasks: 197 (limit: 24809) Memory: 20.7M (peak: 25.4M) CPU: 275ms CGroup: /system.slice/httpd.service ├─150020 /usr/sbin/httpd -DFOREGROUND ├─150048 "Passenger watchdog" ├─150052 "Passenger core" ├─150070 /usr/sbin/httpd -DFOREGROUND ├─150071 /usr/sbin/httpd -DFOREGROUND ├─150072 /usr/sbin/httpd -DFOREGROUND └─150076 /usr/sbin/httpd -DFOREGROUND ``` Next, open your web browser and verify the Apache test page using the URL **http://your-server-ip**. You should see the Apache test page on the following screen: ![Apache Test Page](https://www.atlantic.net/wp-content/uploads/2021/08/p1-1024x596.png) ## Step 2 – Install MariaDB Database Server on Rocky Linux 10 Next, you will need to install the MariaDB or MySQL database server in your system. I would recommend installing the MariaDB server due to its numerous enhancements, like high-performance storage engines and backward compatibility with MySQL. Run the following command to install the MariaDB server: ``` dnf install mariadb-server -y ``` After installing MariaDB, start the MariaDB service and enable it to start at system reboot: ``` systemctl start mariadb systemctl enable mariadb ``` Run the following command to verify that the MariaDB daemon is running: ``` systemctl status mariadb ``` Next, I would recommend running the mysql_secure_installation script to secure the MariaDB installation. You can run it using the following command: ``` mysql_secure_installation ``` You will then be asked whether to set a MariaDB root password, remove anonymous users, disallow root login, and remove the test database, as shown below: ``` Enter current password for root (enter for none): Set root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` ## Step 3 – Install PHP on Rocky Linux 10 Next, you will need to install PHP (PHP Hypertext Preprocessor) in your system. By default, PHP is available in the Rocky Linux default repository. ``` ``` You can install PHP with other extensions using the following command: ``` dnf install php php-cli php-curl php-zip php-mysqli -y ``` Once PHP is installed, verify the installed version of PHP with the following command: ``` php -v ``` You should see the following command: ``` PHP 8.3.19 (cli) (built: Mar 12 2025 13:10:27) (NTS gcc x86_64) Copyright (c) The PHP Group Zend Engine v4.3.19, Copyright (c) Zend Technologies with Zend OPcache v8.3.19, Copyright (c), by Zend Technologies ``` You can also test the PHP version through the web browser. To do so, create an info.php file: ``` nano /var/www/html/info.php ``` Add the following lines: ``` ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` Now, open your web browser and access the info.php page using the URL **http://your-server-ip/info.php**. You should see the PHP version on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/08/lamp.png) ## Conclusion In the above guide, you learned how to install the LAMP stack on Rocky Linux 10. You should now have enough understanding of LAMP to install it for yourself and start hosting your website on the Internet using the LAMP stack; try it on your Atlantic.Net [virtual private server](https://www.atlantic.net/vps-hosting/)! --- # How to Install LEMP stack on Rocky Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-lemp-stack-on-rocky-linux-10/ | Published: 2021-08-08 | Updated: 2025-10-24 | Author: Hitesh Jethva LEMP is an open-source software stack and is and ideally suited to hosting web applications on the internet. LEMP is an acronym for Linux, Nginx, MariaDB/MySQL, and PHP. Generally, LEMP stacks are used to host high-traffic and highly scalable websites on the internet. A LEMP stack is a group of open-source Linux-based software including Nginx web server, MariaDB database server, and PHP. In this post, we will explain how to install a LEMP stack on Rocky Linux 10. ## Step 1 – Install Nginx Web Server on Rocky Linux 10 The first step you will need to do is to install the Nginx web server package on your system. You can install it using the following command: ``` dnf install nginx -y ``` This will install the Nginx package along with other required dependencies to your system. Next, start the Nginx service and enable it to start at system reboot: ``` systemctl start nginx systemctl enable nginx ``` You can now verify the status of the Nginx service using the following command: ``` systemctl status nginx ``` You should see the following output: ``` ● nginx.service - The nginx HTTP and reverse proxy server Loaded: loaded (/usr/lib/systemd/system/nginx.service; disabled; preset: disabled) Drop-In: /etc/systemd/system/nginx.service.d └─php-fpm.conf Active: active (running) since Fri 2025-10-24 23:35:31 EDT; 3s ago Invocation: b8d862fb254b4bbb93589f3cd4015a96 Process: 149273 ExecStartPre=/usr/bin/rm -f /run/nginx.pid (code=exited, status=0/SUCCESS) Process: 149275 ExecStartPre=/usr/sbin/nginx -t (code=exited, status=0/SUCCESS) Process: 149277 ExecStart=/usr/sbin/nginx (code=exited, status=0/SUCCESS) Main PID: 149278 (nginx) Tasks: 3 (limit: 24809) Memory: 3M (peak: 3.1M) CPU: 37ms CGroup: /system.slice/nginx.service ├─149278 "nginx: master process /usr/sbin/nginx" ├─149279 "nginx: worker process" └─149281 "nginx: worker process" ``` You can also verify the Nginx installation through the web browser. Open your web browser and type the URL http://your-server-ip. You should see the Nginx test page on the following screen: ![Nginx Test Page](https://www.atlantic.net/wp-content/uploads/2021/08/p1-1-1024x410.png) ## Step 2 – Install MariaDB Database Server on Rocky Linux 10 Next, you will need to install the MariaDB or MySQL database server on your system. I would recommend installing the MariaDB server due to its numerous enhancements, like high-performance storage engines and backward compatibility with MySQL. Run the following command to install the MariaDB server: ``` dnf install mariadb-server -y ``` After installing MariaDB, start the MariaDB service and enable it to start at system reboot: ``` systemctl start mariadb systemctl enable mariadb ``` Run the following command to verify that the MariaDB daemon is running: ``` systemctl status mariadb ``` Next, I would recommend running the mysql_secure_installation script to secure the MariaDB installation. You can run it using the following command: ``` mysql_secure_installation ``` You will then be asked whether to set a MariaDB root password, remove anonymous users, disallow root login, and remove the test database as shown below: ``` Enter current password for root (enter for none): Set root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` ## Step 3 – Install PHP on Rocky Linux 10 Next, you will need to install PHP on your system. By default, PHP is available in RockyLinux 10. You can install PHP with other extensions using the following command: ``` dnf install php php-fpm php-cli php-curl php-zip php-mysqli -y ``` Once PHP is installed, verify the installed version of PHP with the following command: ``` php -v ``` You should see the following command: ``` PHP 8.3.19 (cli) (built: Mar 12 2025 13:10:27) (NTS gcc x86_64) Copyright (c) The PHP Group Zend Engine v4.3.19, Copyright (c) Zend Technologies with Zend OPcache v8.3.19, Copyright (c), by Zend Technologies ``` By default, PHP-FPM runs as the apache user, so you will need to edit the PHP-FPM configuration file and set it to run as the nginx user. ``` nano /etc/php-fpm.d/www.conf ``` Change the following lines: ``` user = nginx Group = nginx ``` Save and close the file when you are finished. Then, change ownership of session directory. ``` chown -R nginx:nginx /var/lib/php/session ``` Another way to test the PHP version is to create an info.php file in the Nginx web root directory and access it through the web browser. First, create an info.php file: ``` nano /usr/share/nginx/html/info.php ``` Add the following lines: ``` ``` Save and close the file, then restart the Nginx and PHP-FPM service to apply the changes: ``` systemctl restart nginx php-fpm ``` Now, open your web browser and access the info.php page using the URL http://your-server-ip/info.php. You should see the PHP version on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/08/lemp.png) ## Conclusion In the above guide, we learned how to install the LEMP stack on Rocky Linux 10. You can now start installing the LEMP stack on Rocky Linux 10 and host your first website; get started on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install WordPress on Rocky Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-wordpress-on-rocky-linux-10/ | Published: 2021-08-09 | Updated: 2025-10-24 | Author: Hitesh Jethva WordPress is the most popular content management system used to host static and dynamic websites on the Internet. It is open-source, written in PHP and using MariaDB/MySQL as a database backend. It is designed for small businesses, personal blogs, and e-commerce. WordPress is being adopted by more users every day and is a great choice for getting a website up and running quickly. In this post, we will explain how to install WordPress using a LAMP stack on Rocky Linux 10. ## Step 1 – Install LAMP Stack Before starting, the LAMP stack must be installed in your system. First, install Apache and MariaDB using the following command: ``` dnf install httpd mariadb-server -y ``` After installing both packages, you will need to install PHP and other PHP extensions to your system. You can install PHP with other extensions using the following command: ``` dnf install php php-cli php-json php-gd php-mbstring php-pdo php-xml php-mysqlnd php-pecl-zip curl -y ``` Once all the packages are installed, you can proceed to set up the MariaDB database. ## Step 2 – Create a Database for WordPress WordPress uses a database to store the contents. You will need to make sure that MariaDB is started: ``` systemctl start mariadb systemctl enable mariadb ``` Next, you will need to create a database and user for WordPress: First, connect to the MariaDB with the following command: ``` mysql ``` Once you are connected, create a database and user with the following command: ``` CREATE DATABASE wordpressdb; CREATE USER `wordpressuser`@`localhost` IDENTIFIED BY 'securepassword'; ``` Next, grant all the privileges to the WordPress database using the following command: ``` GRANT ALL ON wordpressdb.* TO `wordpressuser`@`localhost`; ``` Next, flush the privileges and exit from MariaDB with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download WordPress Next, navigate to the Apache default root directory and download the latest version of WordPress with the following command: ``` cd /var/www/html curl https://wordpress.org/latest.tar.gz --output wordpress.tar.gz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar xf wordpress.tar.gz ``` Next, set proper ownership of the WordPress directory with the following command: ``` chown -R apache:apache /var/www/html/wordpress ``` ## Step 4 – Configure Apache to Host WordPress Next, you will need to create an Apache virtual host file to host the WordPress. You can create it with the following command: ``` nano /etc/httpd/conf.d/wordpress.conf ``` Add the following lines: ``` ServerAdmin root@localhost ServerName wordpress.example.com DocumentRoot /var/www/html/wordpress Options Indexes FollowSymLinks AllowOverride all Require all granted ErrorLog /var/log/httpd/wordpress_error.log CustomLog /var/log/httpd/wordpress_access.log common ``` Save and close the file, then restart the Apache service to apply the configuration changes: ``` systemctl restart httpd ``` ## Step 5 – Access WordPress Installer Now, open your web browser and access the WordPress installer using the URL http://wordpress.example.com. You should see the following screen: ![WordPress Select Language](https://www.atlantic.net/wp-content/uploads/2021/08/p1-2-1024x628.png) Select your language and click on the Next button. You will be redirected to the following screen: ![WordPress Required Configuration](https://www.atlantic.net/wp-content/uploads/2021/08/p2-2-1024x553.png) Click on the Let’s go! button. You should see the database configuration page: ![WordPress Database Configuration](https://www.atlantic.net/wp-content/uploads/2021/08/p3-1024x555.png) Provide your database credentials and click on the Submit button. You should see the following screen: ![WordPress Run Installation](https://www.atlantic.net/wp-content/uploads/2021/08/p4-1.png) Click on the Run the installation button. You should see the WordPress site configuration screen: ![WordPress Site Configuration](https://www.atlantic.net/wp-content/uploads/2021/08/p5.png) Provide your site information and click on the Install WordPress button. You should see the following screen: ![WordPress Installation Finished](https://www.atlantic.net/wp-content/uploads/2021/08/p6-1024x488.png) Click on the Log in button. You should see the following screen: ![WordPress Login Page](https://www.atlantic.net/wp-content/uploads/2021/08/p8.png) Provide your admin username and password and click on the Log In button. You should see the WordPress dashboard on the following screen: ![WordPress Dashboard Page](https://www.atlantic.net/wp-content/uploads/2021/08/p9-1024x528.png) ## Conclusion In the above guide, we explained how to install WordPress with LAMP on Rocky Linux 10. You can now install necessary plugins and themes and start creating your first website from the WordPress dashboard; install WordPress today on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net. --- # How to Migrate from CentOS 8 to Rocky Linux 8 > URL: https://www.atlantic.net/vps-hosting/how-to-migrate-from-centos-8-to-rocky-linux-8/ | Published: 2021-08-10 | Updated: 2023-11-18 | Author: Hitesh Jethva As you may be aware, CentOS has announced they will be discontinuing support for CentOS 8 on December 31, 2021 and discontinuing future development of new CentOS versions that track RedHat upstream releases. Luckily, a new community enterprise operating system called Rocky Linux from the founder of CentOS has been introduced. With the release of Rocky Linux 8.4, you can now easily migrate your CentOS 8 server to a fully compatible operating system that will continue to be free and fully supported for the long term. ## Step 1 – Update CentOS 8 Packages Before starting, you will need to update all CentOS 8 packages to the latest versions. You can update them with the following command: ``` dnf update -y ``` Once all the packages are updated, restart your system to apply the update. ``` reboot ``` Next, verify your current operating system version using the following command: ``` cat /etc/redhat-release ``` Output: ``` CentOS Linux release 8.4.2105 ``` You can also verify it using the following command: ``` cat /etc/os-release ``` Output: ``` NAME="CentOS Linux" VERSION="8" ID="centos" ID_LIKE="rhel fedora" VERSION_ID="8" PLATFORM_ID="platform:el8" PRETTY_NAME="CentOS Linux 8" ANSI_COLOR="0;31" CPE_NAME="cpe:/o:centos:centos:8" HOME_URL="https://centos.org/" BUG_REPORT_URL="https://bugs.centos.org/" CENTOS_MANTISBT_PROJECT="CentOS-8" CENTOS_MANTISBT_PROJECT_VERSION="8" ``` ## Step 2 – Upgrade CentOS 8 to Rocky Linux 8 Rocky Linux provides a migration script that helps you to convert an existing CentOS 8 system to Rocky Linux 8. You can download the **migrate2rocky** script from Rocky Linux’s Github repository using the following command: ``` wget https://raw.githubusercontent.com/rocky-linux/rocky-tools/main/migrate2rocky/migrate2rocky.sh ``` Once the script is downloaded, set the execution permission with the following command: ``` chmod +x migrate2rocky.sh ``` Next, start the migration process using the following command: ``` bash migrate2rocky.sh -r ``` Once the migration process has been completed, you should get the following output: ``` Complete! Done, please reboot your system. A log of this installation can be found at /var/log/migrate2rocky.log ``` Next, restart your system to apply the migration. ``` reboot ``` ## Step 3 – Verify Rocky Linux 8 Migration After restarting the system, you can verify whether CentOS 8 was migrated successfully to Rocky Linux 8. You can check it with the following command: ``` cat /etc/redhat-release ``` You should get the following output: ``` Rocky Linux release 8.4 (Green Obsidian) ``` You can also check it with the following command: ``` cat /etc/os-release ``` Output: ``` NAME="Rocky Linux" VERSION="8.4 (Green Obsidian)" ID="rocky" ID_LIKE="rhel fedora" VERSION_ID="8.4" PLATFORM_ID="platform:el8" PRETTY_NAME="Rocky Linux 8.4 (Green Obsidian)" ANSI_COLOR="0;32" CPE_NAME="cpe:/o:rocky:rocky:8.4:GA" HOME_URL="https://rockylinux.org/" BUG_REPORT_URL="https://bugs.rockylinux.org/" ROCKY_SUPPORT_PRODUCT="Rocky Linux" ROCKY_SUPPORT_PRODUCT_VERSION="8" ``` ## Conclusion In this post, you learned how to migrate CentOS 8 to Rocky Linux 8. You can now start using the Rocky Linux 8.4. Try it on your CentOS 8 Atlantic.Net [VPS](https://www.atlantic.net/vps-hosting/) today! --- # How to Install Apache Tomcat 11 on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-tomcat-11-on-rocky-linux-10/ | Published: 2021-08-11 | Updated: 2025-10-24 | Author: Hitesh Jethva Apache Tomcat is an open-source web server used for deploying Java-based web applications. It is platform-independent and allows you to runs the JavaServer (JSP), JavaServlet, and Java Expression languages. Apache Tomcat enables a webserver to handle dynamic Java-based web content using the HTTP protocol. In this post, we will explain how to install Apache Tomcat 11 on Rocky Linux 10. ## Step 1 – Install Java Apache Tomcat is a Java-based application, so Java must be installed on your server. If not installed, you can install it using the following command: ``` dnf install java-21-openjdk -y ``` After installing Java, verify the Java version with the following command: ``` java -version ``` Sample output: ``` openjdk version "21.0.8" 2025-07-15 LTS OpenJDK Runtime Environment (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS, mixed mode, sharing) ``` ## Step 2 – Download Apache Tomcat 11 Before starting, you will need to add a dedicated user for Tomcat. You can add it using the following command: ``` useradd -r -d /opt/tomcat/ -s /bin/false -c "Tomcat User" tomcat ``` Next, download the latest version of Apache Tomcat 11 using the following command: ``` wget https://dlcdn.apache.org/tomcat/tomcat-11/v11.0.13/bin/apache-tomcat-11.0.13.tar.gz ``` After downloading Apache Tomcat, create a directory for Tomcat and extract the downloaded file inside the /opt/tomcat directory: ``` mkdir /opt/tomcat tar xzf apache-tomcat-11.0.13.tar.gz -C /opt/tomcat --strip-components=1 ``` Next, change the ownership of /opt/tomcat directory to tomcat: ``` chown -R tomcat: /opt/tomcat/ ``` ## Step 3 – Configure Tomcat Admin User Next, you will need to create an admin user for managing Manager and Host Manager. You can do it by editing the /opt/tomcat/conf/tomcat-users.xml file: ``` nano /opt/tomcat/conf/tomcat-users.xml ``` Add the following lines just above the last line: ``` ``` Save and close the file when you are finished. ## Step 4 – Configure Tomcat for Remote Host By default, Tomcat can be accessed only from the localhost, so you will need to configure Tomcat to access it from the remote host. To access the Manager from the remote host, edit the **context.xml** file: ``` nano /opt/tomcat/webapps/manager/META-INF/context.xml ``` Remove the following lines: ``` ``` Save and close the file when you are finished. To access the Host Manager from the remote host, edit the **context.xml file**: ``` nano /opt/tomcat/webapps/host-manager/META-INF/context.xml ``` Remove the following lines: ``` ``` Save and close the file when you are finished. ## Step 5 – Create a Systemd Unit File for Apache Tomcat Next, it is recommended that you create a systemd unit file to manage the Tomcat service. You can create it with the following command: ``` nano /etc/systemd/system/tomcat.service ``` Add the following lines: ``` [Unit] Description=Apache Tomcat Server After=syslog.target network.target [Service] Type=forking User=tomcat Group=tomcat Environment=CATALINA_PID=/opt/tomcat/temp/tomcat.pid Environment=CATALINA_HOME=/opt/tomcat Environment=CATALINA_BASE=/opt/tomcat ExecStart=/opt/tomcat/bin/catalina.sh start ExecStop=/opt/tomcat/bin/catalina.sh stop RestartSec=10 Restart=always [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the Tomcat service and enable it to start at system reboot: ``` systemctl start tomcat systemctl enable tomcat ``` You can verify the status of the Tomcat service with the following command: ``` systemctl status tomcat ``` Sample output: ``` ● tomcat.service - Apache Tomcat Server Loaded: loaded (/etc/systemd/system/tomcat.service; disabled; preset: disabled) Active: active (running) since Fri 2025-10-24 23:04:23 EDT; 5s ago Invocation: 2012419a433b4b7a9f18842f4f0f5e85 Process: 147191 ExecStart=/opt/tomcat/bin/catalina.sh start (code=exited, status=0/SUCCESS) Main PID: 147204 (java) Tasks: 35 (limit: 24809) Memory: 157.5M (peak: 160M) CPU: 3.570s CGroup: /system.slice/tomcat.service └─147204 /usr/bin/java -Djava.util.logging.config.file=/opt/tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Djdk.tls.eph ``` ## Step 6 – Access Apache Tomcat Web UI At this point, Apache Tomcat is started and listening on port 8080. You can check it with the following command: ``` ss -antpl | grep 8080 ``` Sample output: ``` LISTEN 0 100 *:8080 *:* users:(("java",pid=16841,fd=43)) ``` You can now access Tomcat using the URL **http://your-server-ip:8080**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/08/t1.png) To access the Manager App, click on the **Manager App**button. You will be asked to provide an admin user and password as shown below: ![Tomcat Login Page](https://www.atlantic.net/wp-content/uploads/2021/08/p2-5.png) Provide your admin username and password and click on the **Sign in** button. You should see the following screen: ![Tomcat Manager Page](https://www.atlantic.net/wp-content/uploads/2021/08/p3-2-1024x536.png) To access the Host Manager App, click on the**Host Manager**link. You should see the following screen: ![Tomcat Host Manager Page](https://www.atlantic.net/wp-content/uploads/2021/08/p4-3-1024x535.png) ## Conclusion Congratulations! You have successfully installed Apache Tomcat 11 on Rocky Linux 10. You can now deploy your Java application easily with Apache Tomcat on your Atlantic.Net [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) account. --- # How to Install Magento 2.4 on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-magento-2-4-on-rocky-linux-10/ | Published: 2021-08-12 | Updated: 2025-10-24 | Author: Hitesh Jethva Magento is a free, open-source, PHP-based eCommerce platform and cloud solution to grow your online business rapidly. It is built on open-source technology, with a flexible shopping cart system and an admin control panel that helps you start your online store easily. Magento also offers many plugins and themes to enhance a customer’s experience. In this post, we will show you how to install the Magento eCommerce platform on Rocky Linux 10. ## Step 1 – Install Apache and MariaDB Server First, install the Apache and MariaDB server using the following command: ``` dnf install httpd httpd-tools mariadb-server -y ``` Once both packages are installed, start both services and enable them to start at system reboot: ``` systemctl start httpd mariadb systemctl enable httpd mariadb ``` ## Step 2 – Install PHP and Other Extensions Next, you will need to install PHP and other extensions to your server. You can install PHP with other extensions using the following command: ``` dnf install php php-cli php-mysqlnd php-sodium php-opcache php-xml php-gd php-soap php-pdo php-bcmath php-intl php-mbstring php-json php-iconv php-zip unzip git -y ``` Next, edit the php.ini file and change some values: ``` nano /etc/php.ini ``` Change the following values: ``` memory_limit = 1024M upload_max_filesize = 256M zlib.output_compression = on max_execution_time = 18000 date.timezone = Asia/Kolkata ``` Save and close the file when you are finished. Next, you will need to install the PHP **sodium** extension to your system. First, install the EPEL repository with the following command: ``` dnf install epel-release ``` Next, install the required dependencies with the following command: ``` dnf install php-cli libsodium php-pear php-devel libsodium-devel make ``` Next, verify the sodium extension using the following command: ``` php -i | grep sodium ``` Sample output: ``` /etc/php.d/30-sodium.ini, sodium sodium support => enabled libsodium headers version => 1.0.20 libsodium library version => 1.0.20 ``` ## Step 3 – Create a Magento Database Next, you will need to create a database and user for Magento. First, connect to the MariaDB with the following command: ``` mysql ``` Once you are connected, create a database and user: ``` CREATE DATABASE magento; CREATE USER 'magento'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the Magento database: ``` GRANT ALL ON magento.* TO 'magento'@'localhost' IDENTIFIED BY 'password' WITH GRANT OPTION; SET GLOBAL log_bin_trust_function_creators = 1; SET PERSIST log_bin_trust_function_creators = 1; ``` Next, flush the privileges and exit from the MariaDB shell: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 4 – Install Composer Next, you will need to install Composer on your system. You can install it using the following command: ``` curl -sS https://getcomposer.org/installer | php mv composer.phar /usr/local/bin/composer ``` Next, verify the Composer installation using the following command: ``` composer -V ``` Sample output: ``` Composer version 2.1.5 2021-07-23 10:35:47 ``` ## Step 5 – Download Magento At the time of writing this tutorial, the latest version of Magento is 2.4.2. You can download it with the following command: ``` wget https://github.com/magento/magento2/archive/refs/tags/2.4.8.zip ``` Once the Magento is downloaded, unzip the downloaded file with the following command: ``` unzip 2.4.8.zip ``` Next, move the extracted directory to Apache web root: ``` mv magento2-* /var/www/html/magento2 ``` Next, change the directory to magento2 and install all required PHP dependencies with the following command: ``` cd /var/www/html/magento2 composer install ``` Next, set proper ownership to the magento2 directory: ``` chown -R apache:apache /var/www/html/magento2 ``` Next, set required permissions with the following commands: ``` cd /var/www/html/magento2 find var generated vendor pub/static pub/media app/etc -type f -exec chmod g+w {} + find var generated vendor pub/static pub/media app/etc -type d -exec chmod g+ws {} + chown -R apache:apache . chmod u+x bin/magento chown -R apache:apache /var/lib/php/session ``` ## Step 6 – Configure Apache for Magento Next, create an Apache virtual host configuration file for Magento: ``` nano /etc/httpd/conf.d/magento.conf ``` Add the following lines: ``` ServerAdmin admin@example.com ServerName magento.example.com DocumentRoot /var/www/html/magento2/ DirectoryIndex index.php Options Indexes FollowSymLinks MultiViews AllowOverride All Order allow,deny allow from all ErrorLog /var/log/httpd/magento_error.log CustomLog /var/log/httpd/magento_access.log combined ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 7 – Install Magento Magento web installation has been removed from Magento version 2.2, so you will need to install the Magento from the command line. First, change the directory to magento2 and disable the Elasticsearch module using the following command: ``` cd /var/www/html/magento2/ sudo -u apache bin/magento module:disable Magento_OpenSearch Magento_Elasticsearch Magento_Elasticsearch8 ``` Next, install the Magento using the following command: ``` sudo -u apache bin/magento setup:install --admin-firstname="hitesh" --admin-lastname="jethva" --admin-email="admin@example.com" --admin-user="admin" --admin-password="secure@123" --db-name="magento" --db-host="localhost" --db-user="magento" --db-password="password" --language=en_US --currency=USD --timezone=Asia/Kolkata --cleanup-database --base-url=http://"magento.example.com" ``` Once the Magento has been installed, you should get the following output: ``` [Progress: 828 / 831] Disabling Maintenance Mode: [Progress: 829 / 831] Post installation file permissions check... For security, remove write permissions from these directories: '/var/www/html/magento2/app/etc' [Progress: 830 / 831] Write installation date... [Progress: 831 / 831] [SUCCESS]: Magento installation complete. [SUCCESS]: Magento Admin URI: /admin_lfsxqf Nothing to import. ``` ## Step 8 – Install Magento Cron Jobs Next, you will need to set up Magento cron jobs. First, navigate to the Magento root directory with the following command: ``` cd /var/www/html/magento2 ``` Next, install the Magento cron jobs with the following command: ``` sudo -u apache bin/magento cron:install ``` ## Step 9 – Access Magento Web UI Now, open your web browser and access the Magento web interface using the URL **http://magento.example.com/admin_lfsxqf**. You should see the Magento login page: ![](https://www.atlantic.net/wp-content/uploads/2021/08/m-1.png) Provide your admin username and password and click on the **Sign in** button. You should see the Magento dashboard on the following page: ![Magento Dashboard Page](https://www.atlantic.net/wp-content/uploads/2021/08/p2-4-1024x537.png) ## Conclusion You have successfully installed Magento 2.4 on Rocky Linux 10. You can now start building your online store using the Magento platform on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install Drupal 11 on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-drupal-11-on-rocky-linux-10/ | Published: 2021-08-13 | Updated: 2025-10-23 | Author: Hitesh Jethva Drupal is a free, flexible, open-source CMS software solution that allows you to build and deploy a website without any coding knowledge. It is written in PHP and uses MySQL/MariaDB as a database backend. Drupal provides a simple and powerful admin interface to manage your content, media, and other assets easier than ever before. It is very similar to other CMS platforms, such as WordPress and Joomla, and helps your organization connect with users, customers, and visitors wherever they are. In this tutorial, we will show you how to install Drupal 11 CMS with Apache on Rocky Linux 10. ## Step 1 – Install Apache and MariaDB Server First, install the Apache web server and MariaDB database server using the following command: ``` dnf install httpd mariadb-server curl unzip git -y ``` Once both packages are installed, start the Apache and MariaDB services and enable them to start at system reboot: ``` systemctl start httpd systemctl start mariadb systemctl enable httpd systemctl enable mariadb ``` ## Step 2 – Install PHP and Other Extensions Next, it is recommended to install the latest version of PHP and other extensions to your server. By default, the latest version of PHP is not included in the Rocky Linux default repository, so you will need to install it from the Remi repository. You can install the Remi repository with the following command: ``` dnf install epel-release -y ``` Next, install the PHP 8 and other extensions using the following command: ``` dnf install php php-curl php-mbstring php-gd php-xml php-pear php-fpm php-mysqlnd php-pdo php-opcache php-json php-zip php-soap -y ``` Once all the packages are installed, verify the PHP version with the following command: ``` php -v ``` Output: ``` PHP 8.3.19 (cli) (built: Mar 12 2025 13:10:27) (NTS gcc x86_64) Copyright (c) The PHP Group Zend Engine v4.3.19, Copyright (c) Zend Technologies with Zend OPcache v8.3.19, Copyright (c), by Zend Technologies ``` Next, edit the php.ini file and tweak some settings: ``` nano /etc/php.ini ``` Change the following lines: ``` memory_limit = 256M date.timezone = Asia/Kolkata ``` Save and close the file when you are finished. ## Step 3 – Create a Drupal Database Next, you will need to create a database and user for Drupal. First, connect to the MariaDB with the following command: ``` mysql ``` Once you are connected, create a database and user using the following command: ``` CREATE DATABASE drupaldb; GRANT ALL ON drupaldb.* TO 'drupaluser'@'localhost' IDENTIFIED BY 'securepassword'; ``` Next, flush the privileges and exit from the MariaDB shell: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 4 – Download Drupal First, download the latest version of Drupal from its official website using the following command: ``` wget https://www.drupal.org/download-latest/tar.gz -O drupal.tar.gz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar xvf drupal.tar.gz ``` Next, move the extracted directory to the Apache root directory: ``` mv drupal-*/ /var/www/html/drupal ``` Next, create a file directory required for Drupal and copy a sample settings.php file: ``` mkdir /var/www/html/drupal/sites/default/files cp /var/www/html/drupal/sites/default/default.settings.php /var/www/html/drupal/sites/default/settings.php ``` Next, set proper ownership and permissions on the drupal directory: ``` chown -R apache:apache /var/www/html/drupal chmod -R 777 /var/www/html/drupal ``` ## Step 5 – Configure Apache for Drupal Next, create an Apache virtual host configuration file for Drupal with the following command: ``` nano /etc/httpd/conf.d/drupal.conf ``` Add the following lines: ``` ServerName drupal.example.com ServerAdmin admin@example.com DocumentRoot /var/www/html/drupal/ CustomLog /var/log/httpd/access_log combined ErrorLog /var/log/httpd/error_log Options Indexes FollowSymLinks AllowOverride All Require all granted RewriteEngine on RewriteBase / RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule ^(.*)$ index.php?q=$1 [L,QSA] ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 6 – Access Drupal Website Now Drupal is installed and configured. You can now access it using the URL **http://drupal.example.com**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/08/d1.png) Select your Language and click on **Save and continue** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/08/d2.png) Select an installation type and click on the **Save and continue** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/08/d3-1.png) Provide your database information and click on the **Save and continue** button. You should see the Drupal site information on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/08/d4.png) ![](https://www.atlantic.net/wp-content/uploads/2021/08/d5.png) Provide your site information and click on the **Save and continue** button. Once the installation has been completed, you should see the Drupal dashboard on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/08/d6.png) ## Conclusion In the above guide, you learned how to install Drupal with Apache on Rocky Linux 10. You should now have enough knowledge to install Drupal on a live server easily – get started with Drupal on your Atlantic.Net [dedicated server](https://www.atlantic.net/dedicated-server-hosting/). --- # Characteristics of a Successful Data Protection Officer > URL: https://www.atlantic.net/hipaa-compliant-hosting/characteristics-of-a-successful-data-protection-officer/ | Published: 2021-08-25 | Updated: 2025-08-01 | Author: Alexander Wise The requirement to appoint a data protection officer stems from the passing of the [General Data Protection Regulation](https://gdpr.eu/what-is-gdpr/)(GDPR) in the UK on May 25th, 2018, which applies to any companies that collect, store, or process personal data from residents of any country in the United Kingdom. Within the GDPR itself, there are clear expectations set for someone before they can even become eligible to be a data protection officer. In this article, we will review the position’s primary functions and five characteristics that aid in success within the role. ## Common Misconceptions ### Misconception: Data Protection Officers Must Meet Specific Education Requirements In the early days of the GDPR, it was commonplace to find information online stating that an organization’s data protection officer needed to be a lawyer who lived in the United Kingdom with 7 to 10 years of experience in data security and relevant experience within Information Technology. This essentially limited the pool of qualified candidates to a very select group and created a false perception of a shortage of qualified individuals to take on this role. ### Truth: Data Protection Officers Must Have Specific Expertise Although GDPR does emphasize the importance of having a qualified individual take the role of data protection officer (DPO), the requirements are not as set in stone as these specific schooling requirements or hard and fast industry experience standard that was spread around. According to the GDPR, the officer needs to be appointed based on their professional qualifications, expertise, and knowledge of data protection law. Many have cited this as a requirement for lawyers to fill this function. While being a lawyer would yield a robust set of skills given the adequate knowledge and experience with privacy law, it does not mean that it is necessary by law. One distinction the GDPR makes for a qualified data protection officer is that their experience should be proportionate to the scope of data processing. For example, the requirements for the position in an online retail store would be much less than that of an officer in a company like Amazon. With thousands, if not millions, of user data processed each day, it would make sense that an online retail giant like Amazon would need to have a highly credentialed data protection officer with an expansive team supporting them. ### Misconception: The Data Protection Officer Role Can Be Shared Another misconception of the role is that this position can be shared amongst a team of individuals, as the GDPR suggests and encourages having a team responsible for data privacy and security measures. ### Truth: The Data Protection Officer Must Be a Singular Individual While the GDPR does suggest that having a team of people responsible can be helpful and ideal, it clearly states that the data protection officer needs to be a singular individual. Other supportive roles under the officer are intensely engaged, especially as organizations grow and the scope of data protection increases in size and complexity. Ultimately, the responsibility for these duties needs to fall on one individual. ## Responsibilities of the Data Protection Officer Most of the responsibilities of the data protection officer are as expected, although a few might be a surprise. The officer must report to the company’s executive officers, giving them full authority within their role. It is truly an officer’s role within the company and should not be treated as merely a task to assign someone with other company responsibilities. The officer can have different responsibilities within the company so long as they do not conflict with their primary role as the DPO. Any roles within information technology or revenue-driving goals that could potentially create a conflict of interest should be avoided at all costs. ### Legal Literacy Your data protection officer needs to be well versed in not only the GDPR but any other pertinent legislation related to data security within your industry. This ensures that your candidate meets the minimum requirements of the GDPR and serves as a resource to your company on all fronts of data security. It is important to note that while these functions are permissible, as the person responsible for data privacy, they cannot possess any duties that create a conflict of interest in performing their role under the GDPR compliance functions. ### Effective Communicator The chief function of the data protection officer is to be a direct point of contact for the Information Commissioner’s Office. Therefore, this person should be capable of clear, professional communication with their point of contact within the office. Because of this, good communication skills are a significant asset to anyone selected for the role. Having someone who can communicate effectively and professionally is crucial to maintaining a strong relationship with the ICO. ### Independence The data protection officer must have the ability to think for themselves. Not reporting to anyone other than the executive team creates a unique level of autonomy for the position that could leave some with a lack of sense of direction. On the other hand, a qualified candidate can think critically and solve pertinent issues as they arise and proactively avoid them. ### Industry Experience Literacy within your company’s specific industry is an integral part of being an effective data protection officer. This knowledge gives the individual the necessary insight to make data protection decisions to safeguard your data processes and save your organization thousands of dollars in fines. Industry experience will also give the officer an edge in knowing industry standards and best practices that might not be as clear from an outsider’s point of view. Industry experience does not necessarily have to mean direct expertise in data security but rather a holistic understanding of the essential functions of the industry to mitigate risk and ensure best practices are being followed. ### Teaching Skills Another beneficial skill for the individual to possess is the ability to teach. It will be the task of the DPO to lead in the implementation of proper employee training and be a resource to employees who have questions regarding continued compliance. Again, this person will serve as the expert in the room, and the emphasis on industry experience and a mastery of pertinent compliance law for your specific industry is essential. ## An Overview of the Ideal Data Protection Officer The role of the data protection officer is a vital role that not only fulfills the requirement of the GDPR but also possesses a plethora of skills to tackle the challenges that come with leading the data security and protection measures of your organization. An effective officer can work independently across multiple business channels and ensure pertinent tasks are completed effectively and efficiently. Another major asset is a robust understanding of industry-leading practices and a knack for fostering solid relationships with appropriate government agencies. All in all, the role of the data protection officer is one that, while only a few years old, has already proven to play a vital role in the success of businesses engaging in data processes that touch the United Kingdom. Ultimately, time will tell how this role will evolve. Still, we can only assume an even higher demand for highly qualified individuals to fill this requirement of the GDPR will continue to grow in the UK and worldwide. **Contributed by Accountable, LLC.** Accountable provides a comprehensive administrative framework to help organizations comply with data privacy regulations such as the GDPR, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/), and CPRA. Their goal is to make compliance simple. --- # How to Install OpenCart on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-opencart-on-ubuntu-20-04/ | Published: 2021-08-30 | Updated: 2023-11-17 | Author: Hitesh Jethva OpenCart is an open-source, PHP-based e-commerce platform used to host your online store on the Internet. It provides a user-friendly web interface that makes it easier to manage products, orders, and users in a seamless manner. OpenCart offers a lot of plugins that help you to extend the platform’s functionality and includes features like user management, multi-store functionality, affiliates, discounts, multiple payment gateways, product reviews, and more. In this post, we will explain how to install and configure the OpenCart e-commerce platform on Ubuntu 20.04. ## Step 1 – Install Nginx, PHP, and MariaDB First, install the Nginx web server and MariaDB database with the following command: ``` apt-get update -y apt-get install nginx mariadb-server -y ``` OpenCart only supports PHP version 8.0, so you will need to install PHP version 8.0 on your server. By default, PHP 8.0 is not included in the Ubuntu default repository, so you will need to add the PHP repository to the APT. First, install the required dependencies using the following command: ``` apt-get install software-properties-common git -y ``` Next, add the PHP repository with the following command: ``` add-apt-repository ppa:ondrej/php ``` Once the repository is added, install the PHP 8.0 with all required extensions using the following command: ``` apt-get install php8.0 php8.0-fpm php8.0-mysql php8.0-curl php8.0-gd php8.0-cli php8.0-zip -y ``` The above command will also install the Apache package to your server, so you will need to remove it and stop the service. ``` apt-get remove apache2 systemctl stop apache2 ``` Next, start the Nginx, MariaDB, and PHP-FPM services and enable them to start at system reboot: ``` systemctl start nginx mariadb php8.0-fpm systemctl enable nginx mariadb php8.0-fpm ``` ## Step 2 – Create a Database for OpenCart OpenCart uses the MariaDB as a database backend, so you will need to create a database and user for OpenCart. First, log in to MySQL using the following command: ``` mysql ``` Once logged in, create a database and user using the following command: ``` CREATE DATABASE opencart; CREATE USER 'opencart'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all privileges to the OpenCart database: ``` GRANT ALL PRIVILEGES ON opencart.* TO 'opencart'@'localhost'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install OpenCart Next, download the latest version of OpenCart to the Nginx web root directory: ``` cd /var/www/html git clone https://github.com/opencart/opencart.git ``` Once the download is completed, change the directory to upload and rename the config file: ``` cd opencart/upload mv config-dist.php config.php ``` Next, change the directory to admin and rename the config file: ``` cd admin mv config-dist.php config.php ``` Next, set proper ownership to the OpenCart directory: ``` chown -R www-data:www-data /var/www/html/opencart ``` ## Step 4 – Configure Nginx for OpenCart Next, create an Nginx virtual host configuration file to host OpenCart: ``` nano /etc/nginx/conf.d/opencart.conf ``` Add the following lines: ``` server { listen 80; server_name opencart.example.com; root /var/www/html/opencart/upload; index index.php index.htm index.html; location / { try_files $uri $uri/ /index.php?$args; } location ~ .php$ { fastcgi_pass unix:/run/php/php8.0-fpm.sock; fastcgi_index index.php; fastcgi_read_timeout 240; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; fastcgi_split_path_info ^(.+.php)(/.+)$; } } ``` Save and close the file, then verify the Nginx for any configuration errors: ``` nginx -t ``` Sample output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 5 – Access OpenCart Web Interface Now, open your web browser and access OpenCart using the URL **http://opencart.example.com**. You should see the following page: ![Opencart welcome Page](https://www.atlantic.net/wp-content/uploads/2021/07/p1-3-1024x555.png) Click on **CONTINUE** to accept the License. You should see the following page: ![Opencart Requirement Check Page](https://www.atlantic.net/wp-content/uploads/2021/07/p2-3-1024x592.png) Make sure all the PHP extensions are installed, then click on **CONTINUE**. You should see the following page: ![Opencart Database Setup Page](https://www.atlantic.net/wp-content/uploads/2021/07/p3-3-1024x612.png) Provide your database information and admin user details and click on **CONTINUE**. Once the installation has been completed, you should see the following page: ![Opencart Installation Finish Page](https://www.atlantic.net/wp-content/uploads/2021/07/p4-3.png) Now, remove the install directory using the following command: ``` rm -rf /var/www/html/opencart/upload/install ``` Next, click on the **LOGIN TO YOUR ADMINISTRATION**. You should see the following page: ![Opencart Login Page](https://www.atlantic.net/wp-content/uploads/2021/07/p5-1-1024x464.png) Provide your admin username and password and click on the **Login**. You should see the OpenCart dashboard on the following page: ![Opencart Dashboard Page](https://www.atlantic.net/wp-content/uploads/2021/07/p6-2-1024x534.png) ## Conclusion Congratulations! Your OpenCart platform is now ready to use. You can now deploy your own online store using OpenCart. Get started on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install Atlantis CMS with Apache on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-atlantis-cms-with-apache-on-ubuntu-20-04/ | Published: 2021-08-31 | Updated: 2023-11-16 | Author: Hitesh Jethva Atlantis is a free, open-source, Laravel-based content management system that helps you to build and maintain a website for your business. It offers a lot of modules that can be used to extend the functionality of your website. Atlantis provides a rich set of features including real-time on-page editing, CMS search, content discovery, image optimization, image upload and management, free-form URLs, SEO friendly, and more. In this post, we will show you how to install Atlantis CMS on Ubuntu 20.04. ## Step 1 – Install Apache, MariaDB, and PHP First, install the Apache server, MariaDB, and other packages with the following command: ``` apt-get update -y ``` ``` apt-get install apache2 mariadb-server curl git -y ``` By default, Atlantis CMS supports PHP version 7.0, so you will need to install PHP 7.0 to your server. By default, PHP 7.0 is not included in the Ubuntu default repository, so you will need to add it to the APT. First, install the required dependencies with the following command: ``` apt-get install software-properties-common -y ``` Next, add the PHP repository with the following command: ``` add-apt-repository ppa:ondrej/php ``` Next, install PHP 7.0 with all required extensions using the following command: ``` apt-get install php7.0 libapache2-mod-php7.0 php7.0-common php7.0-gmp php7.0-curl php7.0-intl php7.0-mbstring php7.0-xmlrpc php7.0-mysql php7.0-gd php7.0-xml php7.0-cli php7.0-zip ``` After installing PHP, edit the php.ini file and change some settings: ``` nano /etc/php/7.0/apache2/php.ini ``` Change the following lines: ``` short_open_tag = On memory_limit = 256M upload_max_filesize = 100M max_execution_time = 360 max_input_vars = 1500 date.timezone = America/Chicago ``` Save and close the file when you are done. ## Step 2 – Create a Database for Atlantis Next, log in to the MariaDB shell with the following command: ``` mysql ``` Once you are logged in, create a database and user for Atlantis: ``` CREATE DATABASE atlantis; CREATE USER 'atlantis'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all privileges to the Atlantis database: ``` GRANT ALL PRIVILEGES ON atlantis.* TO 'atlantis'@'localhost'; ``` Next, flush the privileges and exit from the MariaDB: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install Atlantis CMS First, you will need to install Composer on your server. Run the following command to install Composer: ``` curl -sS https://getcomposer.org/installer | php mv composer.phar /usr/local/bin/composer chmod +x /usr/local/bin/composer ``` Next, change the directory to the Apache web root and download Atlantis using Composer: ``` cd /var/www/html composer create-project atlantis-labs/atlantis3 --prefer-dist atlantis3 ``` Sample output: ``` > php artisan atlantis:key:generate Atlantis key [uip4KIUm9AuYrULlE5eXDkzHwG2ZaSPT] set successfully. > chmod -R 775 storage > chmod -R 775 resources > chmod -R 775 modules > chmod -R 775 bootstrap/cache > php install-instructions.php ************Please run*************** php artisan atlantis:set:db php artisan atlantis:install ``` Next, change the directory to atlantis3 and define the database using the following command: ``` cd atlantis3/ php artisan atlantis:set:db ``` Sample output: ``` Do you want to set database credential? (yes/no) [no]: > yes Host: > localhost Database name: > atlantis Username: > atlantis Password: > Database configuration is changed ``` Next, migrate the database with the following command: ``` php artisan atlantis:install ``` Sample output: ``` Do you want to run migrations? (yes/no) [no]: > yes Migrations complete. Do you want to run seeds? (yes/no) [no]: > yes Seeds complete. Installation complete. ``` Next, set proper ownership and permissions to atlantis3: ``` chown -R www-data:www-data /var/www/html/atlantis3/ chmod -R 755 /var/www/html/atlantis3/ ``` ## Step 4 – Configure Apache for Atlantis3 Next, create an Apache virtual host configuration file for Atlantis: ``` nano /etc/apache2/sites-available/atlantis.conf ``` Add the following lines: ``` ServerAdmin admin@example.com DocumentRoot /var/www/html/atlantis3/ ServerName atlantis.example.com Options +FollowSymlinks AllowOverride All Require all granted ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined ``` Save and close the file, then activate the virtual host and enable the rewrite module: ``` a2ensite atlantis.conf a2enmod rewrite ``` Next, restart the Apache service to apply the changes: ``` systemctl restart apache2 ``` ## Step 6 – Access Atlantis CMS Now, open your web browser and access the Atlantis admin interface using the URL **http://atlantis.example.com/admin**. You will be redirected to the Atlantis CMS login page: ![Atlantis Login Page](https://www.atlantic.net/wp-content/uploads/2021/07/p2-4-1024x550.png) Provide default username **admin** and password as **admin123** then click on the **Login** button. You should see the Atlantic CMS dashboard on the following page: ![Atlantis Dashboard Page](https://www.atlantic.net/wp-content/uploads/2021/07/p3-4-1024x536.png) ## Conclusion In the above guide, you learned how to install Atlantis CMS with Apache on Ubuntu 20.04. Feel free to ask me if you find any errors – get started on your [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) account with Atlantic.Net! --- # How to Install WordPress with Lighttpd Web Server on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-wordpress-with-lighttpd-web-server-on-ubuntu-20-04/ | Published: 2021-09-02 | Updated: 2024-06-02 | Author: Hitesh Jethva Lighttpd is a free, open-source, and lightweight web server known for its fast speed. It is simple and easy to install and it provides a web-based interface to control and manage the application. WordPress is a free and open-source content management system that allows you to create a blog and website from a web-based interface. Installing WordPress with Lighttpd will increase the speed and performance of your website. In this post, we will show you how to install WordPress with a Lighttpd web server on Ubuntu 20.04. ## Step 1 – Install Lighttpd, MariaDB, and PHP First, install the Lighttpd, MariaDB, PHP, and other PHP extensions using the following command: ``` apt-get install mysql-server lighttpd php php-fpm php-mysql php-cli php-curl php-xml php-json php-zip php-mbstring php-gd php-intl php-cgi -y ``` The above command will also install the Apache package to your server, so you will need to remove it and stop the Apache service. ``` apt-get remove apache2 -y systemctl stop apache2 ``` Next, start the Lighttpd service and enable it to start at system reboot: ``` systemctl start lighttpd systemctl enable lighttpd ``` ## Step 2 – Configure PHP-FPM to Work with Lighttpd Next, you will need to configure PHP-FPM to work with Lighttpd. To do so, edit the www.conf file: ``` nano /etc/php/7.4/fpm/pool.d/www.conf ``` Find the following line: ``` listen = /run/php/php7.4-fpm.sock ``` And, replace it with the following line: ``` listen = 127.0.0.1:9000 ``` Save and close the file, then edit the 15-fastcgi-php.conf file: ``` nano /etc/lighttpd/conf-available/15-fastcgi-php.conf ``` Find the following lines: ``` "bin-path" => "/usr/bin/php-cgi", "socket" => "/var/run/lighttpd/php.socket", ``` And, replaced them with the following lines: ``` "host" => "127.0.0.1", "port" => "9000", ``` Save and close the file, then enable the required modules with the following command: ``` lighty-enable-mod fastcgi lighty-enable-mod fastcgi-php ``` Next, restart the Lighttpd and PHP-FPM service to apply the changes: ``` systemctl restart lighttpd systemctl restart php7.4-fpm ``` ## Step 3 – Create a Database for WordPress Next, log in to the MariaDB with the following command: ``` mysql ``` Once you are log in, create a database and user with the following command: ``` CREATE DATABASE wpdb; GRANT ALL PRIVILEGES on wpdb.* TO 'wpuser'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 4 – Install WordPress Next, change the directory to the Lighttpd web root directory and download the latest version of WordPress using the following command: ``` cd /var/www/html wget https://wordpress.org/latest.tar.gz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar -xvzf latest.tar.gz ``` Next, change the directory to WordPress and rename the sample configuration file: ``` cd wordpress mv wp-config-sample.php wp-config.php ``` Next, edit the configuration file and define your database settings: ``` nano wp-config.php ``` Change the following lines: ``` /** The name of the database for WordPress */ define( 'DB_NAME', 'wpdb' ); /** MySQL database username */ define( 'DB_USER', 'wpuser' ); /** MySQL database password */ define( 'DB_PASSWORD', 'password' ); /** MySQL hostname */ define( 'DB_HOST', 'localhost' ); /** Database Charset to use in creating database tables. */ define( 'DB_CHARSET', 'utf8' ); ``` Save and close the file, then set proper permissions and ownership with the following command: ``` chown -R www-data:www-data /var/www/html/wordpress chmod -R 755 /var/www/html/wordpress ``` ## Step 5 – Configure Lighttpd for WordPress First, create a directory to store the virtual host configuration file: ``` mkdir -p /etc/lighttpd/vhosts.d/ ``` Next, edit the Lighttpd configuration file: ``` nano /etc/lighttpd/lighttpd.conf ``` Add mod_rewrite in the following block: ``` server.modules = ( "mod_access", "mod_alias", "mod_compress", "mod_redirect", "mod_rewrite", ) ``` And define the path of your virtual host configuration directory: ``` include_shell "cat /etc/lighttpd/vhosts.d/*.conf" ``` Save and close the file. Then, create a new virtual host configuration file for WordPress: ``` nano /etc/lighttpd/vhosts.d/wordpress.conf ``` Add the following lines: ``` $HTTP["host"] =~ "(^|.)wordpress.example.com$" { server.document-root = "/var/www/html/wordpress" server.errorlog = "/var/log/lighttpd/wordpress-error.log" } ``` Save and close the file, then restart the Lighttpd service to apply the changes: ``` systemctl restart lighttpd ``` ## Step 6 – Access WordPress Dashboard Now, open your web browser and access the WordPress installation wizard using the URL **http://wordpress.example.com**. You should see the following page: ![WordPress Welcome Page](https://www.atlantic.net/wp-content/uploads/2021/07/p2-2-1024x652.png) Select your language and click on the **Continue** button. You should see the following page: ![WordPress Site Information Page](https://www.atlantic.net/wp-content/uploads/2021/07/p3-2.png) Provide your site information and click on the **Start the installation** button. Once the installation is completed, you should see the following screen: ![WordPress Installation Finished Page](https://www.atlantic.net/wp-content/uploads/2021/07/p4-2.png) Click on the **Login** button. You should see the WordPress login page; ![WordPress Login Page](https://www.atlantic.net/wp-content/uploads/2021/07/p5.png) Provide your admin username and password and click on the **Login** button. You should see the WordPress admin dashboard on the following screen: ![WordPress Dashboard Page](https://www.atlantic.net/wp-content/uploads/2021/07/p6-1-1024x535.png) ## Conclusion Congratulations! You have successfully installed WordPress with Lighttpd on Ubuntu 20.04. You can now create a high-performance website or blog from the WordPress dashboard on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # Install OpenLiteSpeed, MariaDB, PHP8.0 on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/install-openlitespeed-mariadb-php8-0-on-ubuntu-20-04/ | Published: 2021-09-03 | Updated: 2023-11-21 | Author: Hitesh Jethva OpenLiteSpeed is a free, open-source, and lightweight HTTP web server that is quickly growing in popularity throughout the world. It supports all major operating systems including Linux, FreeBSD, and macOS. OpenLiteSpeed can handle thousands of concurrent connections with low resource usage. It provides a simple and user-friendly web interface that helps you to manage OpenLiteSpeed through a web browser. In this post, we will show you how to install OpenLiteSpeed, MariaDB, and PHP 8.0 on Ubuntu 20.04. ## Step 1 – Install Openlightspeed By default, OpenLiteSpeed is not included in the Ubuntu default repository, so you will need to add the OpenLiteSpeed repository to your server. You can add it using the following commands: ``` apt-get update -y wget -O - http://rpms.litespeedtech.com/debian/enable_lst_debian_repo.sh | bash ``` Once the repository is added, install OpenLiteSpeed with the following command: ``` apt-get install openlitespeed -y ``` After the installation, start the OpenLiteSpeed service and enable it to start at system reboot: ``` systemctl enable lshttpd systemctl start lshttpd ``` Next, verify the status of OpenLiteSpeed with the following command: ``` systemctl status lshttpd ``` Sample output: ``` ● lshttpd.service - OpenLiteSpeed HTTP Server Loaded: loaded (/etc/systemd/system/lshttpd.service; enabled; vendor preset: enabled) Active: active (running) since Mon 2021-07-12 08:35:13 UTC; 23s ago Main PID: 4556 (litespeed) CGroup: /system.slice/lshttpd.service ├─4556 openlitespeed (lshttpd - main) ├─4566 openlitespeed (lscgid) ├─4595 openlitespeed (lshttpd - #01) └─4596 lsphp Jul 12 08:35:11 ubuntu2004 systemd[1]: Starting OpenLiteSpeed HTTP Server... Jul 12 08:35:11 ubuntu2004 lswsctrl[4512]: [OK] litespeed: pid=4556. Jul 12 08:35:13 ubuntu2004 systemd[1]: Started OpenLiteSpeed HTTP Server. ``` You can also verify the OpenLiteSpeed version with the following command: ``` /usr/local/lsws/bin/openlitespeed -v ``` Sample output: ``` LiteSpeed/1.7.12 Open module versions: modgzip 1.1 cache 1.62 modinspector 1.1 uploadprogress 1.1 mod_security 1.4 (built: Wed Jul 7 02:28:18 UTC 2021) module versions: modgzip 1.1 cache 1.62 modinspector 1.1 uploadprogress 1.1 mod_security 1.4 ``` ## Step 2 – Change OpenLiteSpeed Port By default, OpenLiteSpeed listens on port 8088. You can check it using the following command: ``` ss -antpl | grep 8088 ``` Sample output: ``` LISTEN 0 4096 0.0.0.0:8088 0.0.0.0:* users:(("litespeed",pid=4595,fd=22),("litespeed",pid=4556,fd=22)) ``` It is recommended that you change the default port to 80. To do so, edit the OpenLiteSpeed default configuration file: ``` nano /usr/local/lsws/conf/httpd_config.conf ``` Find the following line: ``` address *:8088 ``` And, replaced it with the following line: ``` address *:80 ``` Save and close the file, then restart the OpenLiteSpeed service to apply the changes: ``` systemctl restart lshttpd ``` Now, open your web browser and type the URL http://your-server-ip. You should see the OpenLiteSpeed default page: ![OpenLightSpeed Default Page](https://www.atlantic.net/wp-content/uploads/2021/07/p1-2-1024x574.png) ## Step 3 – Install MariaDB Server You can install the MariaDB server and client package using the following command: ``` apt-get install mariadb-server mariadb-client -y ``` After the installation, start the MariaDB service and enable it to start at system reboot: ``` systemctl start mariadb systemctl enable mariadb ``` You can verify the installed version of MariaDB with the following command: ``` mariadb --version ``` Sample output: ``` mariadb Ver 15.1 Distrib 10.3.29-MariaDB, for debian-linux-gnu (x86_64) using readline 5.2 ``` ## Step 4 – Install PHP8.0 You can install PHP version 8.0 with other extensions using the following command: ``` apt-get install lsphp80 lsphp80-mysql lsphp80-common lsphp80-opcache lsphp80-curl -y ``` After the installation, verify the PHP version with the following command: ``` /usr/local/lsws/lsphp80/bin/php8.0 -v ``` Sample output: ``` PHP 8.0.8 (cli) (built: Jul 1 2021 08:13:46) ( NTS ) Copyright (c) The PHP Group Zend Engine v4.0.8, Copyright (c) Zend Technologies with Zend OPcache v8.0.8, Copyright (c), by Zend Technologies ``` By default, OpenLiteSpeed is configured to use PHP version 7.3. You can check the current PHP version using the URL **http://your-server-ip/phpinfo.php** ![PHP 7.3 Page](https://www.atlantic.net/wp-content/uploads/2021/07/p2-1-1024x616.png) Next, you will need to configure it to use PHP version 8.0. You can do it by editing the **httpd_config.conf** file: ``` nano /usr/local/lsws/conf/httpd_config.conf ``` Find the following line: ``` path lsphp73/bin/lsphp ``` Replaced it with the following line: ``` path lsphp80/bin/lsphp ``` Save and close the file, then restart the LiteSpeed service to apply the changes: ``` systemctl restart lsws ``` Now, open your web browser and verify the PHP version using the URL **http://your-serverip/phpinfo.php**. You should see the following page: ![PHP 8.0 Page](https://www.atlantic.net/wp-content/uploads/2021/07/a1.png) ## Step 5 – Create OpenLiteSpeed Admin User Next, you will need to create an admin user to access the OpenLiteSpeed admin interface. Run the following script to create an admin user: ``` /usr/local/lsws/admin/misc/admpass.sh ``` Set your admin username and password as shown below: ``` Please specify the user name of administrator. This is the user name required to login the administration Web interface. User name [admin]: admin Please specify the administrator's password. This is the password required to login the administration Web interface. Password: Retype password: Administrator's username/password is updated successfully! ``` You can now access the OpenLiteSpeed web interface using the URL **https://server-ip-address:7080/login.php**. You should see the following page: ![Openlitespeed login Page](https://www.atlantic.net/wp-content/uploads/2021/07/p3-1-1024x599.png) Provide your admin username and password and click on the **Login** button. You should see the OpenLiteSpeed dashboard on the following page: ![Openlitespeed Dashboard Page](https://www.atlantic.net/wp-content/uploads/2021/07/p4-1-1024x536.png) ## Conclusion Congratulations! OpenLiteSpeed web server is now installed with MariaDB and PHP 8.0 support. You can now host your website using the high-performance OpenLiteSpeed web server – try it on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net today! --- # How to Install and Setup Wazuh Server in CentOS 8 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-setup-wazuh-server-in-centos-8/ | Published: 2021-09-04 | Updated: 2023-11-14 | Author: Hitesh Jethva Wazuh is a free and open-source security monitoring tool that monitors security events at an application and OS level. It uses Elastic stack to visualize event data through a web-based interface. Wazuh allows users to search the security event data from the web browser. It offers a rich set of features including Intrusion Detection, File Integrity Monitoring, Log Data Analysis, Incident Response, Vulnerability Detection, and more. In this post, we will show you how to install a Wazuh server on CentOS 8. ## Step 1 – Install Java Wazuh is a Java-based application, so Java must be installed on your server. If not installed, you can install it using the following command: ``` dnf install java-11-openjdk-devel -y ``` Once Java has been installed, verify the Java version using the following command: ``` java -version ``` Sample output: ``` openjdk version "11.0.11" 2021-04-20 LTS OpenJDK Runtime Environment 18.9 (build 11.0.11+9-LTS) OpenJDK 64-Bit Server VM 18.9 (build 11.0.11+9-LTS, mixed mode, sharing) ``` ## Step 2 – Install Wazuh Server By default, the Wazuh server package is not included in the CentOS 8 default repository, so you will need to create a repo for Wazuh. First, import the GPG key with the following command: ``` rpm --import https://packages.wazuh.com/key/GPG-KEY-WAZUH ``` Next, create a Wazuh repo with the following command: ``` nano /etc/yum.repos.d/wazuh.repo ``` Add the following lines: ``` [wazuh] gpgcheck=1 gpgkey=https://packages.wazuh.com/key/GPG-KEY-WAZUH enabled=1 name=EL-Wazuh baseurl=https://packages.wazuh.com/4.x/yum/ protect=1 ``` Save and close the file, then install the Wazuh server with the following command: ``` dnf install wazuh-manager -y ``` Once the Wazuh server is installed, start the Wazuh service and enable it to start at system reboot: ``` systemctl enable --now wazuh-manager ``` ## Step 3 – Install Elasticsearch and Kibana First, import the Elasticsearch GPG key with the following command: ``` rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch ``` Next, create an Elasticsearch repo with the following command: ``` nano /etc/yum.repos.d/elasticsearch.repo ``` Add the following lines: ``` [elasticsearch-7.x] name=Elasticsearch repository for 7.x packages baseurl=https://artifacts.elastic.co/packages/7.x/yum gpgcheck=1 gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch enabled=1 autorefresh=1 type=rpm-md ``` Save and close the file, then install Elasticsearch and Kibana with the following command: ``` dnf install elasticsearch-7.11.2 kibana-7.11.2 -y ``` Once the installation is completed, start Elasticsearch and enable it to start at system reboot: ``` systemctl enable elasticsearch.service --now ``` Next, edit the Kibana configuration file and define the Elasticsearch host, server port, and server host: ``` nano /etc/kibana/kibana.yml ``` Change the following lines: ``` server.port: 5601 server.host: "45.58.42.91" elasticsearch.hosts: [http://localhost:9200] ``` Save and close the file, then start the Kibana service and enable it to start at system reboot: ``` systemctl enable --now kibana ``` ## Step 4 – Install and Configure Filebeat First, install Filebeat using the following command: ``` dnf install filebeat-7.11.2 -y ``` Once installed, you will need to configure Filebeat to work with Wazuh. First, back up the Filebeat configuration file: ``` mv /etc/filebeat/filebeat.yml{,.bak} ``` Next, download the pre-configured configuration file: ``` curl -so /etc/filebeat/filebeat.yml https://raw.githubusercontent.com/wazuh/wazuh/v4.0.3/extensions/filebeat/7.x/filebeat.yml ``` Next, edit the downloaded file: ``` nano /etc/filebeat/filebeat.yml ``` Add or modify the following lines: ``` #output.elasticsearch.hosts: ['http://YOUR_ELASTIC_SERVER_IP:9200'] output.elasticsearch.hosts: ['http://localhost:9200'] logging.level: info logging.to_files: true logging.files: path: /var/log/filebeat name: filebeat keepfiles: 7 permissions: 0644 ``` Save and close the file, then verify the Filebeat with the following command: ``` filebeat test output ``` Sample output: ``` elasticsearch: http://localhost:9200... parse url... OK connection... parse host... OK dns lookup... OK addresses: ::1, 127.0.0.1 dial up... OK TLS... WARN secure connection disabled talk to server... OK version: 7.13.3 ``` ## Step 5 – Install Filebeat Wazuh Module Next, you will need to download and install the Wazuh module for Filebeat. You can download it with the following command: ``` wget https://packages.wazuh.com/4.x/filebeat/wazuh-filebeat-0.1.tar.gz ``` Next, create a directory for Wazuh and extract the content of the downloaded file to the Wazuh directory: ``` mkdir /usr/share/filebeat/module/wazuh tar xzf wazuh-filebeat-0.1.tar.gz -C /usr/share/filebeat/module/wazuh/ --strip-components=1 ``` Next, download the Wazuh Elasticsearch alerts index template with the following command: ``` curl -so /etc/filebeat/wazuh-template.json https://raw.githubusercontent.com/wazuh/wazuh/4.1/extensions/elasticsearch/7.x/wazuh-template.json ``` Next, set up it using the following command: ``` filebeat setup --path.config /etc/filebeat --path.home /usr/share/filebeat --path.data /var/lib/filebeat --index-management -E setup.template.json.enabled=false ``` Next, restart the Filebeat service to apply the changes: ``` systemctl restart filebeat ``` ## Step 6 – Install Wazuh Plugin for Kibana First, create a data directory for Kibana and set proper ownership for the kibana directory: ``` mkdir /usr/share/kibana/data chown -R kibana: /usr/share/kibana/ ``` Next, change the directory to Kibana and install the Wazuh plugin: ``` cd /usr/share/kibana sudo -u kibana /usr/share/kibana/bin/kibana-plugin install https://packages.wazuh.com/4.x/ui/kibana/wazuh_kibana-4.1.5_7.11.2-1.zip ``` Once the plugin is installed, verify the installed plugin with the following command: ``` sudo -u kibana /usr/share/kibana/bin/kibana-plugin list ``` Sample output: ``` wazuh@4.1.5-4108 ``` Finally, restart all services to apply the changes: ``` systemctl restart kibana systemctl restart elasticsearch systemctl restart wazuh-manager ``` ## Step 7 – Access Kibana Dashboard You can now access the Kibana web interface using the URL http://server-IP:5601. You should see the Kibana dashboard on the following page: ![Kibana Welcome Page](https://www.atlantic.net/wp-content/uploads/2021/07/p1-1-1024x577.png) Click on **Explore on my own**. You should see the following screen: ![Kibana Dashboard Page](https://www.atlantic.net/wp-content/uploads/2021/07/p2-1024x538.png) Now, click on the **Menu** and select **Wazuh**. You should see the Wazuh dashboard on the following page: ![Access Wazuh Page](https://www.atlantic.net/wp-content/uploads/2021/07/p3-1024x529.png) ![Wazuh DashboardPage](https://www.atlantic.net/wp-content/uploads/2021/07/p6-1024x533.png) ## Conclusion Congratulations! You have successfully installed and configured a Wazuh server with an ELK stack on CentOS 8. You can now install and configure the Wazuh agent on the client machine and start monitoring it from the Wazuh dashboard – try it on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install and Use AIDE in Debian > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-aide-in-debian/ | Published: 2021-09-05 | Updated: 2025-09-05 | Author: Hitesh Jethva AIDE is an advanced intrusion detection system that protects a system against viruses, rootkits, malware, and unauthorized activities. It is a host-based file and directory integrity checker that compares the system files information and attributes with a database initially created by AIDE. Whenever someone makes any changes to your system, AIDE compares the database against the real status of the system and reports it to you. In this post, we will show you how to install and use AIDE on Debian 12. ## Step 1 – Install AIDE By default, AIDE is available in the Ubuntu 20.04 default repository. You can install it using the following commands: ``` apt-get update -y apt-get install aide -y ``` After the installation, you can verify the AIDE version with the following command: ``` aide -v ``` Sample output: ``` Aide 0.18.3 Compiled with the following options: WITH_MMAP WITH_PCRE WITH_POSIX_ACL WITH_SELINUX WITH_XATTR WITH_E2FSATTRS WITH_LSTAT64 WITH_READDIR64 WITH_ZLIB WITH_MHASH WITH_AUDIT CONFIG_FILE = "/dev/null" ``` ## Step 2 – Initialize AIDE Database Before starting, you will need to create a new AIDE database. You can create it with the following command: ``` aideinit ``` This will creates a new database at /var/lib/aide/aide.db.new: ``` Running aide --init... Start timestamp: 2025-09-05 08:53:19 +0000 (AIDE 0.18.3) AIDE initialized database at /var/lib/aide/aide.db.new Verbose level: 6 Number of entries: 37719 --------------------------------------------------- The attributes of the (uncompressed) database(s): --------------------------------------------------- /var/lib/aide/aide.db.new RMD160 : EKLJYOgQoxA1T1rDaDwSKPT+zS8= TIGER : ++cPjPggEXIiZPv7/6wxgVw50ddXpE3g SHA256 : pa9MXZXSt0Oq80rSeYry1IA6u48mAJ65 CxhD6wpU0SE= SHA512 : sgB/1IhSDZAjJ8kPEbANX0EVc1v/M4BA qJh7ab0KY1q+f8QxY3xxDBzpOuLKEl3I b1C5px59JEqTy8F8u7oWQQ== CRC32 : R/I+2g== HAVAL : 5shLpFN9owhYyjVC9F822TcVDOkXvhv+ Xt4HSJ28fJs= GOST : u/AioKKAQNB77sCvgUCzc2fJtYWzsM+W xG0U1LGPgHQ= End timestamp: 2025-09-5 08:54:54 +0000 (run time: 1m 35s) ``` In order to use the new AIDE database, you will need to copy and replaced it with name **aide.db:** ``` cp /var/lib/aide/aide.db{.new,} ``` ## Step 3 – Verify AIDE At this point, AIDE is installed and configured. Now, it’s time to check whether AIDE works or not. To do so, create some files inside /etc directory with the following command: ``` echo "How to Install AIDE" > /etc/test touch /etc/file1.txt ``` Next, run the AIDE check on /etc directory to detect new files: ``` aide -c /etc/aide/aide.conf --limit /etc --check ``` You should see the changes detected by AIDE in the following output: ``` End timestamp: 2025-09-5 08:57:42 +0000 (run time: 0m 11s) AIDE found differences between database and filesystem!! Limit: /etc | Verbose level: 6 Summary: Total number of entries: 37721 Added entries: 2 Removed entries: 0 Changed entries: 1 --------------------------------------------------- Added entries: --------------------------------------------------- f++++++++++++++++: /etc/file1.txt f++++++++++++++++: /etc/test --------------------------------------------------- Changed entries: --------------------------------------------------- f >b... mc..C.. .: /etc/aide/aide.conf --------------------------------------------------- ``` If you want to add a new file definition to the AIDE database, run the following command: ``` aide --update --config /etc/aide/aide.conf ``` In order to use the new database for future scans, rename the newly created database to /var/lib/aide/aide.db.gz: ``` mv /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz ``` ## Step 4 – Configure AIDE to Alert via Email You can also configure AIDE to send a daily report by email. You can do it by editing the file /etc/default/aide: ``` nano /etc/default/aide ``` Find the following line: ``` MAILTO=root ``` And, replace it with the following line: ``` MAILTO=user@email.com ``` Save and close the file, then edit the /etc/aliases file: ``` nano /etc/aliases ``` Add the following line: ``` root: user@email.com ``` Save and close the file, then update the aliases with the following command: ``` newaliases ``` ## Conclusion In the above guide, you learned how to install and use AIDE on Debian 12. You can now implement AIDE in the production server to protect it from viruses, rootkits, and malware – you can use AIDE on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install and Use Composer on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-composer-on-ubuntu-20-04/ | Published: 2021-09-06 | Updated: 2023-11-14 | Author: Hitesh Jethva Composer is a package management system and dependency manager for PHP. It checks your project requirements and installs all the required dependencies. Composer is a simple, reliable, and very useful tool that helps developers to manage and integrate packages and libraries into their PHP-based projects. In this tutorial, we will show you how to install and use Composer on Ubuntu 20.04 server. ## Step 1 – Install PHP and Other Dependencies Before installing Composer, you will need to install PHP and other required dependencies on your server. You can install all of them with the following command: ``` apt-get install php php-cli php-mbstring curl gnupg2 git unzip -y ``` After installing all the packages, you can proceed to the next step. ## Step 2 – Install Composer Composer provides a PHP-based installation script to install the Composer to your system. First, download the Composer installation script with the following command: ``` curl -sS https://getcomposer.org/installer -o composer-setup.php ``` Next, you will need to verify whether the downloaded script matches with the SHA-384 hash for the latest installer found on the [Composer](https://composer.github.io/pubkeys.html) signature page. ![Composer Hash Page](https://www.atlantic.net/wp-content/uploads/2021/07/p1-1024x567.png) To do so, copy the hash from that page and store it in the shell variable. ``` HASH=756890a4488ce9024fc62c56153228907f1545c228516cbf63f885e036d37e9a59d27d63f46af1d4d07ee0f76181c7d3 ``` Next, run the following command to verify the downloaded script: ``` php -r "if (hash_file('SHA384', 'composer-setup.php') === '$HASH') { echo 'Installer verified'; } else { echo 'Installer corrupt'; unlink('composer-setup.php'); } echo PHP_EOL;" ``` If everything is correct, you should get the following output: ``` Installer verified ``` Next, run the following script to install Composer globally: ``` php composer-setup.php --install-dir=/usr/local/bin --filename=composer ``` Once the installation has been completed, you should get the following output: ``` All settings correct for using Composer Downloading... Composer (version 2.1.3) successfully installed to: /usr/local/bin/composer Use it: php /usr/local/bin/composer ``` You can now check the Composer version using the following command: ``` composer --version ``` You should see the following output: ``` Composer version 2.1.3 2021-06-09 16:31:20 ``` ## Step 3 – How to Use Composer At this point, Composer is installed on your server. Now we will show you how to create a project with Composer. First, create a new directory for your project: ``` mkdir myproject ``` Next, change the directory to myproject: ``` cd myproject ``` Next, create a PHP-based application that prints the current time. ``` composer require nesbot/carbon ``` The above command will download and install carbon with all required dependencies and creates the composer.json file: ``` Installing dependencies from lock file (including require-dev) Package operations: 6 installs, 0 updates, 0 removals - Downloading symfony/translation-contracts (v2.4.0) - Downloading symfony/polyfill-mbstring (v1.23.0) - Downloading symfony/translation (v5.3.3) - Downloading nesbot/carbon (2.50.0) - Installing symfony/translation-contracts (v2.4.0): Extracting archive - Installing symfony/polyfill-php80 (v1.23.0): Extracting archive - Installing symfony/polyfill-mbstring (v1.23.0): Extracting archive - Installing symfony/deprecation-contracts (v2.4.0): Extracting archive - Installing symfony/translation (v5.3.3): Extracting archive - Installing nesbot/carbon (2.50.0): Extracting archive 3 package suggestions were added by new dependencies, use `composer suggest` to see details. Generating autoload files ``` Run the following command to verify all files created by Composer: ``` ls -l ``` You should see the following output: ``` -rw-r--r-- 1 root root 60 Jul 15 04:52 composer.json -rw-r--r-- 1 root root 18155 Jul 15 04:52 composer.lock drwxr-xr-x 6 root root 4096 Jul 15 04:52 vendor ``` Now, create a new file named app.php: ``` nano app.php ``` Add the following code: ``` ``` Save and close the file, then run the app.php with the following command: ``` php app.php ``` This will print the current time of your system: ``` Now: 2021-07-15 04:54:37 ``` If you want to update the project, run the following command: ``` composer update ``` This will check for newer versions of the installed packages and match them with all packages inside composer.json then update the package. ## Conclusion In the above guide, you learned how to install Composer on Ubuntu 20.04. You also learned how to create a PHP-based project with Composer. Get started with Composer on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net, and for more information, visit the [Composer](https://getcomposer.org/doc/) official documentation. --- # How to Secure SSH Server with Fail2Ban > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-secure-ssh-server-with-fail2ban/ | Published: 2021-09-07 | Updated: 2023-11-21 | Author: Hitesh Jethva Fail2Ban is open-source intrusion prevention software that protects your Linux system from different kinds of attacks. It is written in Python and monitors the services logs for malicious activity. It scans all services’ log files and counts the number of failed login attempts. Fail2ban will add extra IP table rules to block the source IPs whenever their number reaches a predefined threshold. This post will show you how to secure an SSH server with Fail2Ban on Linux. ## Step 1 – Update Linux Server Once logged in to your Linux server, run the following command to update your base system with the latest available packages. ``` apt-get update -y ``` Or ``` dnf update -y ``` ## Step 2 – Install Fail2Ban By default, Fail2Ban is available in all major Linux distributions. To install Fail2Ban on Ubuntu and Debian, run the following command: ``` apt-get install fail2ban -y ``` To install Fail2Ban on CentOS, RHEL, and Fedora, run the following command: ``` dnf install epel-release -y dnf install fail2ban -y ``` Once the Fail2Ban is installed, start the Fail2Ban service and enable it to start at system reboot: ``` systemctl start fail2ban systemctl enable fail2ban ``` ## Step 3 – Configure Fail2Ban By default, Fail2Ban’s main configuration file is located at /etc/fail2ban/jail.conf. Creating a new configuration file named jail. local in the /etc/fail2ban/ directory is always recommended. Next, create a new configuration file using your favorite editor: ``` nano /etc/fail2ban/jail.local ``` Add the following lines: ``` [sshd] enabled = true port = ssh filter = sshd logpath = /var/log/auth.log maxretry = 3 bantime = 300 ignoreip = 127.0.0.1, whitelist-ip ``` Save and close the file, then restart the Fail2Ban service to apply the changes: ``` systemctl restart fail2ban ``` Where: - **Port** is the SSH port number. - **logpath** is the path of the SSH log file. - **bantime** is the number of seconds to block the attacker’s IP. - **maxretry** is the number of failed login attempts allowed for remote hosts. - **ignoreip** is the white list IP addresses. ## Step 4 – Monitor Fail2Ban Status Fail2Ban comes with a command-line utility named fail2ban-client that is used to monitor the Fail2Ban status. To check the status of the sshd jail, run the following command: ``` fail2ban-client status sshd ``` You should see the list of all IPs blocked by Fail2Ban: ``` Status for the jail: ssh |- Filter | |- Currently failed: 1 | |- Total failed: 10 | `- File list: /var/log/auth.log `- Actions |- Currently banned: 1 |- Total banned: 1 `- Banned IP list: 45.58.44.186 ``` To check the status of the all active jail, run the following command: ``` fail2ban-client status ``` Sample output: ``` Status |- Number of jail: 3 `- Jail list: proftpd, sshd, apache2 ``` You can also check the Fail2Ban log for more information: ``` tail -f /var/log/fail2ban.log ``` Sample output: ``` 2021-07-15 10:02:13,084 fail2ban.filter [8012]: INFO [ssh] Found 45.58.44.186 - 2021-07-15 10:02:13 2021-07-15 10:02:33,085 fail2ban.filter [8012]: INFO [sshd] Found 45.58.44.186 - 2021-07-15 10:02:13 2021-07-15 10:02:33,117 fail2ban.actions [8013]: NOTICE [ssh] Ban 45.58.44.186 ``` ## Step 5 – Ban and Unban Remote IPs with Fail2Ban Fail2Ban also allows you to ban and unban remote IPs manually. To unban any blocked IP, run the following command: ``` fail2ban-client set sshd unbanip remote-ip ``` If you want to ban any untrusted IP, run the following command: ``` fail2ban-client set sshd banip remote-ip ``` ## Conclusion In the above guide, we explain how to secure an SSH server using Fail2Ban on Linux. You can now create more jails to protect other services like Apache, FTP, WordPress, and more – try it on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) today! --- # How to Set Up Unbound DNS Resolver on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-set-up-unbound-dns-resolver-on-ubuntu/ | Published: 2021-09-08 | Updated: 2025-05-23 | Author: Hitesh Jethva Unbound is a free, open-source, recursive, and validating DNS caching server. It uses DNS-over-TLS and DNS-over-HTTPS to encrypt connections between clients. Compared to Bind9, Unbound is lightweight and extremely fast. A caching server will help you reduce the loading time of the website by keeping the cache database on an Unbound server. It is also capable of DNSSEC validation and can serve as a trust anchor. In this post, we will show you how to set up an Unbound DNS Resolver on Ubuntu 24.04. ## Step 1 – Install and Configure Unbound DNS By default, the Unbound package is included in the Ubuntu default repository. You can install it using the following command: ``` apt-get install unbound -y ``` After installing Unbound DNS, you will need to configure it. By default, the Unbound main configuration file is located at /etc/unbound/unbound.conf. ``` nano /etc/unbound/unbound.conf ``` Add the following lines: ``` server: port: 53 verbosity: 0 num-threads: 2 outgoing-range: 512 num-queries-per-thread: 1024 msg-cache-size: 32m interface: 0.0.0.0 rrset-cache-size: 64m cache-max-ttl: 86400 infra-host-ttl: 60 infra-lame-ttl: 120 access-control: 127.0.0.0/8 allow access-control: 0.0.0.0/0 allow username: unbound directory: "/etc/unbound" logfile: "/var/log/unbound.log" use-syslog: no hide-version: yes so-rcvbuf: 4m so-sndbuf: 4m do-ip4: yes do-ip6: no do-udp: yes do-tcp: yes remote-control: control-enable: yes control-port: 953 control-interface: 0.0.0.0 ``` Save and close the file. ## Step 2 – Configure System DNS Settings Next, you will need to configure your system to use the local resolver. Disable systemd-resolved, ``` systemctl disable --now systemd-resolved ``` Remove existing resolv.conf, ``` rm /etc/resolv.conf ``` Create new resolv.conf. ``` echo "nameserver 127.0.0.1" | sudo tee /etc/resolv.conf echo "options edns0 trust-ad" | sudo tee -a /etc/resolv.conf ``` Prevent changes by network managers. ``` chattr +i /etc/resolv.conf ``` ## Step 3: Start and Enable Unbound Now, start and enable the unbound service. ``` systemctl enable unbound systemctl start unbound ``` Now, verify the status of unbound. ``` systemctl status unbound ``` Output. ``` ● unbound.service - Unbound DNS server Loaded: loaded (/usr/lib/systemd/system/unbound.service; enabled; preset: enabled) Active: active (running) since Fri 2025-05-23 07:35:05 UTC; 17min ago Docs: man:unbound(8) Main PID: 24982 (unbound) Tasks: 1 (limit: 9440) Memory: 12.1M (peak: 12.6M) CPU: 131ms CGroup: /system.slice/unbound.service └─24982 /usr/sbin/unbound -d -p ``` ## Step 4 – Test Unbound DNS Now, you must use the dig command and perform some DNS queries to test the Unbound DNS server. We will use ubuntu.com for testing. ``` dig ubuntu.com @localhost ``` Sample output: ``` ; <<>> DiG 9.18.30-0ubuntu0.24.04.2-Ubuntu <<>> ubuntu.com @localhost ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 54289 ;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1232 ;; QUESTION SECTION: ;ubuntu.com. IN A ;; ANSWER SECTION: ubuntu.com. 60 IN A 185.125.190.20 ubuntu.com. 60 IN A 185.125.190.29 ubuntu.com. 60 IN A 185.125.190.21 ;; Query time: 307 msec ;; SERVER: 127.0.0.1#53(localhost) (UDP) ;; WHEN: Fri May 23 07:53:08 UTC 2025 ;; MSG SIZE rcvd: 87 ``` As you can see, the query time is **307** msec in the first query. Your query is now cached. Next, let’s rerun the same query: ``` dig ubuntu.com @localhost ``` Sample output: ``` ; <<>> DiG 9.18.30-0ubuntu0.24.04.2-Ubuntu <<>> ubuntu.com @localhost ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 37386 ;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1232 ;; QUESTION SECTION: ;ubuntu.com. IN A ;; ANSWER SECTION: ubuntu.com. 10 IN A 185.125.190.29 ubuntu.com. 10 IN A 185.125.190.21 ubuntu.com. 10 IN A 185.125.190.20 ;; Query time: 0 msec ;; SERVER: 127.0.0.1#53(localhost) (UDP) ;; WHEN: Fri May 23 07:53:58 UTC 2025 ;; MSG SIZE rcvd: 87 ``` As you can see, the query time is **0** msec. You can also test the Unbound DNS server from the client machine. In this case, you will need to specify your Unbound DNS server IP with the query: ``` dig ubuntu.com @your-server-ip ``` Sample output: ``` ; <<>> DiG 9.18.30-0ubuntu0.24.04.2-Ubuntu <<>> ubuntu.com @104.245.34.161 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 35235 ;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1232 ;; QUESTION SECTION: ;ubuntu.com. IN A ;; ANSWER SECTION: ubuntu.com. 47 IN A 185.125.190.21 ubuntu.com. 47 IN A 185.125.190.29 ubuntu.com. 47 IN A 185.125.190.20 ;; Query time: 285 msec ;; SERVER: 104.245.34.161#53(104.245.34.161) (UDP) ;; WHEN: Fri May 23 13:36:02 IST 2025 ;; MSG SIZE rcvd: 87 ``` ## Step 5 – Troubleshooting Unbound If you want to check the status of the Unbound DNS, run the following command: ``` unbound-control status ``` Sample output: ``` version: 1.19.2 verbosity: 0 threads: 2 modules: 3 [ subnetcache validator iterator ] uptime: 83 seconds options: reuseport control(namedpipe) unbound (pid 27189) is running... ``` If you want to back up a DNS Cache to a text file, run the following command: ``` unbound-control dump_cache > cache.txt ``` You can verify the cache.txt file with the following command: ``` cat cache.txt ``` Sample output: ``` START_RRSET_CACHE END_RRSET_CACHE START_MSG_CACHE END_MSG_CACHE EOF ``` In some cases, your DNS server cannot reply to your query. In this case, you can flush the DNS cache using the following command: ``` unbound-control flush ubuntu.com ``` ## Conclusion In the above guide, we explained how to install and use an Unbound DNS caching server on Ubuntu 24.04. We also tested using the dig command to query Unbound DNS and get a response. Try it out on your [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # Top 10 Server Monitoring Software Solutions > URL: https://www.atlantic.net/hipaa-compliant-hosting/top-10-server-monitoring-software-solutions/ | Published: 2021-09-10 | Updated: 2025-04-11 | Author: Richard Bailey Businesses and organizations rely on large numbers of [servers](https://www.atlantic.net/vps-hosting/), both in the cloud and on-premise, to run smoothly to ensure that their services remain productive and reliable. Poor performance, or even worse, server downtime, can have huge repercussions, impacting company revenue, customer service, and reputation. This means that close monitoring of server performance is vital. ## What Do Server Monitoring Tools Do? Server monitoring software is used to continuously monitor, track, and analyze the performance of your [server infrastructure](https://www.atlantic.net/cloud-platform/). These tools monitor elements such as CPU usage, RAM utilization, memory allocation, network links, and disk space. Such monitoring helps to identify performance issues early, enabling their swift resolution. Tracking server performance in real-time enables you to generate capacity forecasts, helping to inform capacity planning decisions. Choosing the right server monitoring tool for your business or organization can prove difficult. In this article, we have compiled a list of the top 10 server monitoring tools on the market to help make this choice easier for you. ## What Are the Top 10 Server Monitoring Tools? ### 1. Paessler PRTG PRTG is an agentless monitoring tool and dashboard that is designed to probe servers, switches, routers, and more. It has been available since 2003. PRTG is a highly tuned application commonly used to monitor network appliances for throughput and uptime. One major advantage of PRTG is its discovery mode feature, which scans a pre-defined network range and automatically adds new devices as soon as they join the network, a perfect solution for remote monitoring at scale. ### 2. Nagios Nagios is an agentless monitoring solution that is available in both a free core version and a paid offering called Nagios XI. Nagios is a popular solution and has great compatibility with Linux, VMware, and networking appliances. It can monitor host resources such as CPU, Disk, and Memory and can also probe hardware such as temperature sensors, alarms, etc. Alerts can be received by push notification, email, and SMS, and it offers great customizable options that can be modified extensively using shell scripts, C++, Python, and more. ### 3. WhatsUp Gold WhatsUp Gold is another monitoring tool that has been around since the early 2000s. It has changed significantly since its first revisions that created HTTP dashboards displaying the status of nodes. Traditionally a data center-based application, newer revisions have full cloud integration, dashboards, and alerts. Automated device discovery, network mapping, and real-time alerting are popular features of WhatsUp Gold. ### 4. Zabbix Zabbix is an open-source monitoring tool for networks, servers, cloud, and virtual infrastructure. Zabbix is primarily an agent-based platform, but agentless monitoring using SNMP, TCP, and ICMP are available. However, it is the agent that shines for Zabbix. Zabbix is available as a virtual application and lightweight Docker container. Key features include auto-discovery and agents for pretty much any operating system (including out-of-support OSes like Windows 2000). The open-source community releases 3 feature updates per year, resulting in many new features and services. ### 5. OpenNMS OpenNMS is a comprehensive, 100% open-source server monitoring tool designed for flexibility and scalability. Despite being available for free, OpenNMS boasts numerous features that set it apart from its competitors, including event-driven architecture, network traffic analysis, performance metric management, and topology discovery and mapping. With its user-friendly interface and the availability of an iPhone mobile app, OpenNMS allows customers to monitor the status of their network wherever they are. ### 6. Spiceworks Network Monitor Another free server monitoring option, Spiceworks is a simplified tool that allows customers to access real-time information on the health of their servers. Customers can benefit from free support, easy deployment, real-time insights, a dynamic dashboard, flexibility and scalability, and the introduction of real-time email alerts in the near future. ### 7. Sematext Monitoring Sematext Monitoring offers performance monitoring for both on-premise and cloud environments. Hosted in the cloud, it provides real-time information on the health of your infrastructure. It is a feature-rich tool offering many out-of-the-box integrations, automatic discovery, quick deployment, log and event reporting, built-in troubleshooting tools, and network, inventory, processes, and database monitoring. It has a simple pricing plan and offers new customers a 14-day free trial. ### 8. Datadog Datadog was founded in 2010 and is a fantastic tool for cloud metrics, monitoring, and preparing in-house servers for cloud migration. The monitoring tool’s biggest asset is its compatibility with existing infrastructure. It is fair to say that Datadog can integrate with every operating system released, even the most obscure. ### 9. ManageEngine OpManager ManageEngine OpManager is a cost-effective and easy-to-use server monitoring software application that focuses on the performance and health of the network. The key features of this monitoring tool include end-to-end network monitoring, network traffic flow visualization, WAN link monitoring, multi-level thresholds, and customizable dashboards. A possible disadvantage of this tool is that it requires a good deal of manual configuration. Customers are able to opt for a price plan that meets their needs and may even take advantage of a free trial, allowing the monitoring of up to three devices. ### 10. Solarwinds Serving over 300,000 customers across 190 countries, Solarwinds is one of the leading players within the server monitoring and network management space. Offering end-to-end monitoring support, Solarwinds is user-friendly and easy to set up, automatically detecting connected network devices and allowing you to start monitoring promptly. Notable features include forecast and capacity planning, the creation of Wi-Fi heat maps, customizable dashboards, and alert and reporting systems. Solarwinds can be deployed in almost any environment. In December 2020, the Solarwinds Orion monitoring tool was infected with malware that was distributed to an unknown number of customers. This security breach opened up customer infrastructure to the hacking community, and the exploit allowed them to execute remote ‘jobs’ on any compromised server and traverse the victim’s network using “god mode” privileges to compromise any connected server and perform data theft.  Solarwinds has stated the issue has been patched. Solarwinds still makes the top 10 list due to the years of a track record they have along with the numerous Fortune 100 companies that utilize the software.  Please take these pros and cons into consideration when selecting your software. ## How Can Atlantic.Net Help? Are you looking for a leading [hosting provider](https://www.atlantic.net/hosting-services-provider/) to host your monitoring solution? Look no further than Atlantic.Net. With over 30 years of proven experience, our [full suite of managed services](https://www.atlantic.net/managed-services/) and always available professional support team is able to build the perfect solution for your business or organization. We also include a complimentary monitoring solution for our cloud customers. Atlantic.Net stands ready to help you attain fast compliance with a range of certifications, such as SOC 2 and SOC 3, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/), and HITECH, all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, visit us at www.atlantic.net, call 866-618-DATA (3282), or email us at [sales@atlantic.net](mailto:sales@atlantic.net). You can find out more information by [contacting our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # How to Install and Use Darkstat Web Based Linux Network Traffic Analyzer > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-darkstat-web-based-linux-network-traffic-analyzer/ | Published: 2021-09-11 | Updated: 2024-06-04 | Author: Hitesh Jethva If you are a system administrator managing a Linux server, you want a simple tool that helps to monitor your server. Darkstat is a network traffic monitoring tool that calculates and reports usage statistics sent over the HTTP server. It is a lightweight, simple, and real-time network statistics tool with an integrated webserver. Darkstat supports IPv6 protocol and asynchronous reverse DNS resolution. In this post, we will show you how to install and use Darkstat Network Traffic Analyzer in Linux. ## Step 1 – Install Darkstat By default, Darkstat is included in the default repository of all major Linux operating systems. For Ubuntu and Debian operating systems, install Darkstat with the following command: ``` apt-get install darkstat -y ``` For CentOS and RHEL operating systems, install Darkstat with the following command: ``` dnf install darkstat -y ``` Once the Darkstat package is installed, you can proceed to the next step. ## Step 2 – Configure Darkstat Next, you will need to edit the Darkstat main configuration file and define your network interface, port, and listening IP address: ``` nano /etc/darkstat/init.cfg ``` Change the following lines: ``` START_DARKSTAT=yes INTERFACE="-i eth0" DIR="/var/lib/darkstat" PORT="-p 666" BINDIP="-b 0.0.0.0" DAYLOG="--daylog darkstat.log" ``` Save and close the file when you are finished, then restart the Darkstat service to apply the changes: ``` systemctl restart darkstat ``` You can now check the status of the Darkstat with the following command: ``` systemctl status darkstat ``` You should see the following output: ``` ● darkstat.service - LSB: start darkstat monitoring system at boot time Loaded: loaded (/etc/init.d/darkstat; generated) Active: active (running) since Sun 2021-08-15 07:40:05 UTC; 6s ago Docs: man:systemd-sysv-generator(8) Process: 6092 ExecStart=/etc/init.d/darkstat start (code=exited, status=0/SUCCESS) Tasks: 2 (limit: 2353) Memory: 792.0K CGroup: /system.slice/darkstat.service ├─6100 /usr/sbin/darkstat -i eth0 -p 666 --chroot /var/lib/darkstat --pidfile /var/run/darkstat.pid -b 0.0.0.0 --daylog darkstat.> └─6101 /usr/sbin/darkstat -i eth0 -p 666 --chroot /var/lib/darkstat --pidfile /var/run/darkstat.pid -b 0.0.0.0 --daylog darkstat.> Aug 15 07:40:05 ubuntu2004 systemd[1]: Starting LSB: start darkstat monitoring system at boot time... Aug 15 07:40:05 ubuntu2004 darkstat[6092]: * Starting darkstat network daemon : darkstat Aug 15 07:40:05 ubuntu2004 darkstat[6092]: * done Aug 15 07:40:05 ubuntu2004 darkstat[6092]: ...done. Aug 15 07:40:05 ubuntu2004 systemd[1]: Started LSB: start darkstat monitoring system at boot time. ``` ## Step 3 – Access Darkstat Web UI At this point, Darkstat is running and listening on port 666. You can check it with the following command: ``` ss -antpl | grep 666 ``` You should see the following output: ``` LISTEN 0 128 0.0.0.0:666 0.0.0.0:* users:(("darkstat",pid=6100,fd=8)) ``` Now, open your web browser and access the Darkstat web interface using the URL http://your-server-ip:666. You should see the following screen: ![Darkstate Dashboard Page](https://www.atlantic.net/wp-content/uploads/2021/08/p1-8-1024x620.png) Now, click on the hosts tab. You’ll get a list of all hosts on the network that have attempted to reach the server: ![Darkstate Hosts Information Page](https://www.atlantic.net/wp-content/uploads/2021/08/p2-7.png) ## Conclusion In this guide, we explained how to install and use Darkstat in Linux to capture network traffic over the HTTP. Hopefully this tool will help you to make your Linux server admin job easier; try it out on your Atlantic.Net [VPS hosting](https://www.atlantic.net/vps-hosting/) account! --- # How to Monitor Linux Server Security with Osquery > URL: https://www.atlantic.net/vps-hosting/how-to-monitor-linux-server-security-with-osquery/ | Published: 2021-09-12 | Updated: 2023-11-25 | Author: Hitesh Jethva Osquery is an open-source security threat monitoring tool developed by Facebook. It is used for querying system information including system version, kernel information, running processes, memory information, listening ports, login users, and more. Osquery helps system administrators to write SQL queries to identify, probe, and eliminate various types of threats. It supports several operating systems including Windows, Linux, FreeBSD, and macOS. In this post, we will explain how to install and use Osquery on Ubuntu 20.04. ## Step 1 – Install Osquery By default, the Osquery package is not included in the Ubuntu default repository, so you will need to add the Osquery repository to your system. First, install required dependencies using the following command: ``` apt-get install gnupg2 software-properties-common wget unzip -y ``` Next, add the Osquery GPG key with the following command: ``` export OSQUERY_KEY=1484120AC4E9F8A1A577AEEE97A80C63C9D8B80B apt-key adv --keyserver keyserver.ubuntu.com --recv-keys $OSQUERY_KEY ``` Next, add the Osquery repository to APT using the following command: ``` add-apt-repository 'deb [arch=amd64] https://pkg.osquery.io/deb deb main' ``` Once the repository is added, update the repository and install Osquery with the following command: ``` apt-get update -y apt-get install osquery -y ``` ## Step 2 – Connect to Osquery Console Osquery provides an interactive shell to execute queries and explore the current state of your operating system. You can connect to the Osquery shell using the following command: ``` osqueryi ``` Once you are connected, you should get the following output: ``` Using a virtual database. Need help, type '.help' osquery> ``` Next, display the default settings of Osquery using the following command: ``` osquery> .show ``` You should see the following output: ``` osquery - being built, with love. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ osquery 4.9.0 using SQLite 3.35.5 General settings: Flagfile: Config: filesystem (/etc/osquery/osquery.conf) Logger: filesystem (/var/log/osquery/) Distributed: tls Database: ephemeral Extensions: core Socket: /root/.osquery/shell.em Shell settings: echo: off headers: on mode: pretty nullvalue: "" output: stdout separator: "|" width: Non-default flags/options: database_path: /root/.osquery/shell.db disable_database: true disable_events: true disable_logging: true disable_watchdog: true extensions_socket: /root/.osquery/shell.em hash_delay: 0 logtostderr: true stderrthreshold: 0 ``` Osquery has a lot of tables available for query. You can list them with the following command: ``` osquery> .tables ``` Sample output: ``` => acpi_tables => apparmor_events => apparmor_profiles => apt_sources => arp_cache => atom_packages => augeas => authorized_keys => azure_instance_metadata => azure_instance_tags => block_devices => bpf_process_events => bpf_socket_events => carbon_black_info => carves => chrome_extension_content_scripts => chrome_extensions => cpu_time => cpuid => crontab => curl => curl_certificate => deb_packages => device_file => device_hash => device_partitions => disk_encryption => dns_resolvers => docker_container_fs_changes => docker_container_labels => docker_container_mounts => docker_container_networks => docker_container_ports ``` Osquery has several modes to display the query output. Here, we will use line mode to display the output. To set line mode, run the following command: ``` osquery> .mode line ``` ## Step 3 – How to Use Osquery To get information about your running operating system, run: ``` osquery> SELECT * FROM system_info; ``` Sample output: ``` hostname = ubuntu2004 uuid = a83cffe2-50f4-4fea-9ef4-423853fdc122 cpu_type = x86_64 cpu_subtype = 6 cpu_brand = QEMU Virtual CPU version 2.5+ cpu_physical_cores = 1 cpu_logical_cores = 1 cpu_microcode = 0x1 physical_memory = 2084278272 hardware_vendor = QEMU hardware_model = Standard PC (i440FX + PIIX, 1996) hardware_version = pc-i440fx-bionic hardware_serial = board_vendor = board_model = board_version = board_serial = computer_name = ubuntu2004 local_hostname = ubuntu2004 ``` To filter the system information output, run: ``` osquery> SELECT hostname, cpu_type, physical_memory, hardware_vendor, hardware_model FROM system_info; ``` Sample output: ``` hostname = ubuntu2004 cpu_type = x86_64 physical_memory = 2084278272 hardware_vendor = QEMU hardware_model = Standard PC (i440FX + PIIX, 1996) ``` To display your operating system version, run: ``` osquery> SELECT * FROM os_version; ``` Sample output: ``` name = Ubuntu version = 20.04 LTS (Focal Fossa) major = 20 minor = 4 patch = 0 build = platform = ubuntu platform_like = debian codename = focal arch = x86_64 ``` To display your kernel information, run: ``` osquery> SELECT * FROM kernel_info; ``` Sample output: ``` version = 5.4.0-29-generic arguments = ro net.ifnames=0 biosdevname=0 console=ttyS0 console=tty0 path = /boot/vmlinuz-5.4.0-29-generic device = UUID=29a0b164-1ba1-45a7-b23a-cdb98f23edbc ``` To display all listening ports with the service name and PID, run: ``` osquery> SELECT DISTINCT processes.name, listening_ports.port, processes.pid FROM listening_ports JOIN processes USING (pid) WHERE listening_ports.address = '0.0.0.0'; ``` Sample output: ``` name = unbound port = 53 pid = 3407 name = sshd port = 22 pid = 649 name = unbound port = 953 pid = 3407 name = darkstat port = 666 pid = 6100 name = darkstat port = 667 pid = 6109 name = apt-cacher-ng port = 3142 pid = 4071 name = ntpd port = 123 pid = 483 ``` To display information for the Apache package, run: ``` osquery> SELECT name, version FROM deb_packages WHERE name="apache2"; ``` Sample output: ``` +---------+-------------------+ | name | version | +---------+-------------------+ | apache2 | 2.4.41-4ubuntu3.4 | +---------+-------------------+ ``` To display system memory information, run: ``` osquery> SELECT * FROM memory_info; ``` Sample output: ``` +--------------+-------------+----------+-----------+-------------+-----------+-----------+------------+-----------+ | memory_total | memory_free | buffers | cached | swap_cached | active | inactive | swap_total | swap_free | +--------------+-------------+----------+-----------+-------------+-----------+-----------+------------+-----------+ | 2084278272 | 1358233600 | 44519424 | 520896512 | 0 | 406622208 | 222449664 | 495411200 | 495411200 | +--------------+-------------+----------+-----------+-------------+-----------+-----------+------------+-----------+ ``` To display information of all network interfaces, run: ``` osquery> SELECT * FROM interface_addresses; ``` Sample output: ``` +-----------+-------------------------------+-----------------------------------------+---------------+----------------+---------+ | interface | address | mask | broadcast | point_to_point | type | +-----------+-------------------------------+-----------------------------------------+---------------+----------------+---------+ | lo | 127.0.0.1 | 255.0.0.0 | | 127.0.0.1 | unknown | | eth0 | 69.87.221.220 | 255.255.255.0 | 69.87.221.255 | | unknown | | lo | ::1 | ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff | | | unknown | | eth0 | fe80::200:45ff:fe57:dddc%eth0 | ffff:ffff:ffff:ffff:: | | | unknown | +-----------+-------------------------------+-----------------------------------------+---------------+----------------+---------+ ``` To check system uptime, run: ``` osquery> SELECT * FROM uptime; ``` Sample output: ``` +------+-------+---------+---------+---------------+ | days | hours | minutes | seconds | total_seconds | +------+-------+---------+---------+---------------+ | 0 | 1 | 55 | 5 | 6905 | +------+-------+---------+---------+---------------+ ``` To list all users whose UID is greater than 1000, run: ``` osquery> SELECT * FROM users WHERE uid>=1000; ``` Sample output: ``` +-------+-------+------------+------------+----------+-------------+--------------+-------------------+------+ | uid | gid | uid_signed | gid_signed | username | description | directory | shell | uuid | +-------+-------+------------+------------+----------+-------------+--------------+-------------------+------+ | 65534 | 65534 | 65534 | 65534 | nobody | nobody | /nonexistent | /usr/sbin/nologin | | | 65534 | 65534 | 65534 | 65534 | nobody | nobody | / | /usr/sbin/nologin | | +-------+-------+------------+------------+----------+-------------+--------------+-------------------+------+ ``` To check last logged in users, run: ``` osquery> SELECT * FROM last; ``` Sample output: ``` +----------+-------+------+------+------------+-----------------+ | username | tty | pid | type | time | host | +----------+-------+------+------+------------+-----------------+ | root | pts/0 | 1013 | 7 | 1629008887 | 106.213.193.155 | | root | pts/1 | 3372 | 7 | 1629010656 | 106.213.193.155 | | root | pts/2 | 4158 | 7 | 1629013021 | 106.213.193.155 | +----------+-------+------+------+------------+-----------------+ ``` To display all logged in users, run: ``` osquery> SELECT * FROM logged_in_users; ``` Sample output: ``` +-----------+----------+------------+------------------+------------+------+ | type | user | tty | host | time | pid | +-----------+----------+------------+------------------+------------+------+ | boot_time | reboot | ~ | 5.4.0-29-generic | 1629008369 | 0 | | init | | /dev/tty1 | | 1629008378 | 491 | | init | | /dev/ttyS0 | | 1629008378 | 484 | | login | LOGIN | ttyS0 | | 1629008378 | 484 | | login | LOGIN | tty1 | | 1629008378 | 491 | | runlevel | runlevel | ~ | 5.4.0-29-generic | 1629008383 | 53 | | user | root | pts/0 | 106.213.193.155 | 1629008887 | 1013 | | user | root | pts/1 | 106.213.193.155 | 1629010656 | 3372 | | user | root | pts/2 | 106.213.193.155 | 1629013021 | 4158 | +-----------+----------+------------+------------------+------------+------+ ``` ## Conclusion In the above guide, we explained how to install and use Osquery to get data from the operating system by running SQL-based queries. It is a very useful and easy-to-use tool to find backdoors, malware, zombie processes, and more. Get started with Osquery on your [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # How to Secure SSH Service with Port Knocking > URL: https://www.atlantic.net/vps-hosting/how-to-secure-ssh-service-with-port-knocking/ | Published: 2021-09-14 | Updated: 2023-11-18 | Author: Hitesh Jethva If you want to allow users to access specific services on your server without open a firewall, you can use port knocking. Port knocking is a method that allows you to secure your service from unauthorized users. Port knocking allows incoming connections when a correct sequence of connection attempts is received. In this post, we will secure open SSH port 22 with port knocking. This port will only be opened when someone requests the ports 7000, 8000, 9000 in sequence. ## Step 1 – Install and Configure Knockd By default, the knockd package is included in the Ubuntu 20.04 default repository. You can install it using the following command: ``` apt-get install knockd -y ``` Once the package is installed, edit the port knocking default configuration file: ``` nano /etc/knockd.conf ``` Find the default sequence shown below: ``` sequence = 7000,8000,9000 sequence = 9000,8000,7000 ``` And replace them with the following sequence: ``` sequence = 7777,8888,9999 sequence = 9999,8888,7777 ``` Also, find the following line: ``` command = /sbin/iptables -A INPUT -s %IP% -p tcp --dport 22 -j ACCEPT ``` And replace it with the following line: ``` command = /sbin/iptables -I INPUT -s %IP% -p tcp --dport 22 -j ACCEPT ``` Save and close the file when you are finished. In the above configuration file, the sequence 7777, 8888, 9999 is used to open port 22 for a client system, and the sequence 9999, 8888, 7777 is used to close port 22 for a client system. Next, edit the **/etc/default/knockd** configuration file: ``` nano /etc/default/knockd ``` Change the following lines: ``` # Start the Knockd service START_KNOCKD=1 # Name of your network interface KNOCKD_OPTS="-i eth0" ``` Save and close the file when you are finished, then restart the Knockd service and enable it to start at system reboot: ``` systemctl restart knockd systemctl enable knockd ``` Next, verify the status of Knockd service with the following command: ``` systemctl status knockd ``` Sample output: ``` ● knockd.service - Port-Knock Daemon Loaded: loaded (/lib/systemd/system/knockd.service; disabled; vendor preset: enabled) Active: active (running) since Sun 2021-08-15 13:26:31 UTC; 5s ago Docs: man:knockd(1) Main PID: 6555 (knockd) Tasks: 1 (limit: 2353) Memory: 296.0K CGroup: /system.slice/knockd.service └─6555 /usr/sbin/knockd -i eth0 Aug 15 13:26:31 ubuntu2004 systemd[1]: Started Port-Knock Daemon. Aug 15 13:26:31 ubuntu2004 knockd[6555]: starting up, listening on eth0 ``` ## Step 2 – Install and Configure Iptables Knockd uses the Iptables rule to open and close the SSH port, so you will need to install the Iptables package on your server. Run the following command to install the Iptables package: ``` apt-get install iptables iptables-persistent -y ``` Once the package is installed, create an Iptables rule to block SSH port 22 for all users: ``` iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT iptables -A INPUT -p tcp --dport 22 -j REJECT ``` Next, save the Iptables rule and reload it with the following command: ``` netfilter-persistent save netfilter-persistent reload ``` At this point, port knocking is configured for OpenSSH in your server. ## Step 3 – Check OpenSSH Connection from Client System Next, go to the client system and check whether the OpenSSH port 22 is blocked or not. You can check it using the NMAP command: ``` nmap your-server-ip ``` You should see that port 22 is filtered on the server. ``` Nmap scan report for your-server-ip Host is up (0.38s latency). Not shown: 998 closed ports PORT STATE SERVICE 21/tcp open ftp 22/tcp filtered ssh Nmap done: 1 IP address (1 host up) scanned in 277.58 seconds ``` Now, try to connect to your server using SSH from the client machine: ``` ssh root@your-server-ip ``` You should see the connection refused message: ``` ssh: connect to host your-server-ip port 22: Connection refused ``` ## Step 4 – Configure Knockd on Client to Connect SSH Server Now you will need to install Knock client on the client system to connect to the SSH server. First, run the following command to install the Knockd client package: ``` apt-get install knockd -y ``` Now use the following knock sequence to open the SSH port 22 on the server. ``` knock -v your-server-ip 7777 8888 9999 ``` When your server receives a correct sequence that you have defined in the Knockd configuration file, it will open the SSH port 22 for your client machine, and you will be able to connect to the SSH server. ``` ssh root@your-server-ip ``` After completing your task on the remote SSH server, you can use the following sequence from the client machine to close the SSH port again. ``` knock -v your-server-ip 9999 8888 7777 ``` ## Conclusion In the above guide, you learned how to secure an SSH server with port knocking. You can use the same method to secure other ports on a Linux server. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Change Nginx and Apache Port in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-change-nginx-and-apache-port-in-linux/ | Published: 2021-09-15 | Updated: 2024-06-01 | Author: Hitesh Jethva Apache is a free, open-source, widely used web server known for its stability, flexibility, and numerous features. Nginx is an open-source, stable, and most popular web server. It is used as a load-balancer, web reverse proxy, or POP and IMAP proxy server. In this post, we will show you how to change the Nginx and Apache default ports in Linux. ## Change Apache Default Port By default, the Apache webserver listens to all incoming connections on port 80. If you have installed an SSL certificate, it will listen to all secure connections on port 443. In this section, we will show you how to change the Apache default port on CentOS, RHEL, Debian, and Ubuntu operating systems. ## Change Apache Default Port on Debian/Ubuntu On the Debian and Ubuntu operating systems, Apache stores port-related information in the **/etc/apache2/ports.conf** and **/etc/apache2/sites-enabled/000-default.conf** files. First, edit **/etc/apache2/ports.conf** file: ``` nano /etc/apache2/ports.conf ``` Find the following line: ``` Listen 80 ``` And replace it with the following line: ``` Listen 8080 ``` Save and close the file when you are finished, then edit the Apache default virtual host configuration file **/etc/apache2/sites-enabled/000-default.conf**: ``` nano /etc/apache2/sites-enabled/000-default.conf ``` Find the following line: ``` ``` And replace it with the next line: ``` ``` Save and close the file, then restart the Apache service to apply the configuration changes: ``` systemctl restart apache2 ``` You can now verify the Apache listening port with the following command: ``` ss -antpl | grep 8080 ``` You should get the following output: ``` LISTEN 0 511 *:8080 *:* users:(("apache2",pid=2908,fd=4),("apache2",pid=2907,fd=4),("apache2",pid=2906,fd=4)) ``` ## Change Apache Default Port on CentOS/RHEL On the CentOS and RHEL operating systems, Apache stores port-related information in **/etc/httpd/conf/httpd.conf** file. You can edit it with the following command: ``` nano /etc/httpd/conf/httpd.conf ``` Find the following line: ``` Listen 80 ``` And replace it with the following line: ``` Listen 8080 ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` You can now verify the Apache listening port with the following command: ``` ss -antpl | grep 8080 ``` Output: ``` LISTEN 0 128 *:8080 *:* users:(("httpd",pid=5994,fd=4),("httpd",pid=5993,fd=4),("httpd",pid=5992,fd=4),("httpd",pid=5989,fd=4)) ``` ## Change Nginx Default Port By default, the Nginx web server listens to all incoming connections on port 80. If you have installed an SSL certificate, it will listen to all secure connections on port 443. In this section, we will show you how to change the Nginx default port on CentOS, RHEL, Debian, and Ubuntu operating systems. ## Change Nginx Default Port on Debian/Ubuntu On Ubuntu and Debian-based distributions, Nginx stores port-related configuration in the **/etc/nginx/sites-enabled/default** file. You can edit it with the following command: ``` nano /etc/nginx/sites-enabled/default ``` Find the following lines: ``` listen 80 default_server; listen [::]:80 default_server; ``` And replace them with the following lines: ``` listen 8080 default_server; listen [::]:8080 default_server; ``` Save and close the file, then restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` You can now verify the Nginx listening port with the following command: ``` ss -antpl | grep 8080 ``` You should get the following output: ``` LISTEN 0 511 0.0.0.0:8080 0.0.0.0:* users:(("nginx",pid=1596,fd=6),("nginx",pid=1595,fd=6)) LISTEN 0 511 [::]:8080 [::]:* users:(("nginx",pid=1596,fd=7),("nginx",pid=1595,fd=7)) ``` ## Change Nginx Default Port on CentOS/RHEL On CentOS and RHEL operating systems, Nginx stores port-related configuration in **/etc/nginx/nginx.conf** file. ``` nano /etc/nginx/nginx.conf ``` Find the following lines: ``` listen 80 default_server; listen [::]:80 default_server; ``` And replace them with the following lines: ``` listen 8080 default_server; listen [::]:8080 default_server; ``` Save and close the file, then restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` You can now verify the Nginx listening port with the following command: ``` ss -antpl | grep 8080 ``` You should see the following output: ``` LISTEN 0 128 0.0.0.0:8080 0.0.0.0:* users:(("nginx",pid=6589,fd=8),("nginx",pid=6588,fd=8)) LISTEN 0 128 [::]:8080 [::]:* users:(("nginx",pid=6589,fd=9),("nginx",pid=6588,fd=9)) ``` ## Conclusion In the above guide, you learned how to change the Apache and Nginx default ports on Debian, Ubuntu, CentOS, and RHEL operating systems. You can now set your desired port on Apache and Nginx web servers; try it on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Use pip Command on Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-pip-command-on-linux/ | Published: 2021-09-16 | Updated: 2023-11-14 | Author: Hitesh Jethva pip is a package management system for managing packages written in Python. It is also known as “pip Installs Packages” or “pip Installs Python.” pip uses Python Package Index (PyPI) for the packages and installs them on your system. In this post, we will show you how to install and use the pip command in Linux. ## Install pip On Debian/Ubuntu By default, pip is not installed in the Ubuntu and Debian-based operating systems. You will need to install it using the command line. To install pip for Python 2, run the following command: ``` apt-get install python-pip -y ``` To install pip for Python 3, run the following command: ``` apt-get install python3-pip -y ``` After the installation, verify the version of pip using the following command: ``` pip -V ``` Or ``` pip3 -V ``` You should get the following output: ``` pip 20.0.2 from /usr/lib/python3/dist-packages/pip (python 3.8) ``` ## Install pip On CentOS, Fedora and RHEL By default, pip is not included in the software repositories of CentOS/RHEL/Fedora, so you will need to install the EPEL repository to your system. Run the following command to install the EPEL repository. ``` yum install epel-release -y yum install python3-pip ``` To check the installed version, run the following command: ``` pip3 -V ``` You should get the following output: ``` pip 9.0.3 from /usr/lib/python3.6/site-packages (python 3.6) ``` ## How to Use pip To list all pip commands, run the following command : ``` pip --help ``` Sample output: ``` Usage: pip [options] Commands: install Install packages. download Download packages. uninstall Uninstall packages. freeze Output installed packages in requirements format. list List installed packages. show Show information about installed packages. check Verify installed packages have compatible dependencies. config Manage local and global configuration. search Search PyPI for packages. wheel Build wheels from your requirements. hash Compute hashes of package archives. completion A helper command used for command completion. debug Show information useful for debugging. help Show help for commands. ``` To install a package with pip, run: ``` pip install packagename ``` To remove a package, run: ``` pip uninstall packagename ``` To download a Python package without installing it in your system, run: ``` pip download packagename ``` To list all packages, run the following command: ``` pip list ``` You should see all installed packages in the following output: ``` Package Version ---------------------- ---------- certifi 2019.11.28 chardet 3.0.4 click 8.0.1 dbus-python 1.2.16 distro 1.4.0 Flask 2.0.1 idna 2.8 itsdangerous 2.0.1 Jinja2 3.0.1 MarkupSafe 2.0.1 netifaces 0.10.4 numpy 1.21.1 pip 20.0.2 PyGObject 3.36.0 pymacaroons 0.13.0 PyNaCl 1.3.0 PyYAML 5.3.1 requests 2.22.0 setuptools 45.2.0 six 1.14.0 ssh-import-id 5.10 ubuntu-advantage-tools 20.3 urllib3 1.25.8 Werkzeug 2.0.1 wheel 0.34.2 ``` To upgrade a specific package, run the following command: ``` pip install --upgrade packagename ``` To display detailed information of any package, run the following command: ``` pip show flask ``` You should get the following output: ``` Name: Flask Version: 2.0.1 Summary: A simple framework for building complex web applications. Home-page: https://palletsprojects.com/p/flask Author: Armin Ronacher Author-email: armin.ronacher@active-4.com License: BSD-3-Clause Location: /usr/local/lib/python3.8/dist-packages Requires: Jinja2, Werkzeug, itsdangerous, click Required-by: ``` ## Conclusion In the above guide, we explained how to install pip on Linux. pip is a very useful utility that simplifies the process of Python package installation. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Setup Apache Spark on Debian > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-setup-apache-spark-on-debian/ | Published: 2021-09-17 | Updated: 2025-09-05 | Author: Hitesh Jethva Apache Spark is a free, open-source, general-purpose framework for clustered computing. It is specially designed for speed and is used in machine learning to stream processing to complex SQL queries. It is capable of analyzing large datasets across multiple computers and processes the data in parallel. Apache Spark provides APIs for multiple programming languages including Python, R, and Scala. It also supports higher-level tools including GraphX, Spark SQL, MLlib, and more. In this post, we will show you how to install and configure Apache Spark on Debian 12. ## Step 1 – Install Java Before starting, you will need to install Java to run Apache Spark. You can install it using the following commands: ``` apt-get update -y ``` ``` apt-get install default-jdk -y ``` After installing Java, verify the Java installation using the following command: ``` java --version ``` You should see the following output: ``` openjdk 17.0.16 2025-07-15 OpenJDK Runtime Environment (build 17.0.16+8-Debian-1deb12u1) OpenJDK 64-Bit Server VM (build 17.0.16+8-Debian-1deb12u1, mixed mode, sharing) ``` ## Step 2 – Install Apache Spark First, you will need to download the latest version of Apache Spark from its official website. You can download it with the following command: ``` wget https://dlcdn.apache.org/spark/spark-4.0.0/spark-4.0.0-bin-hadoop3.tgz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar xvf spark-4.0.0-bin-hadoop3.tgz ``` Next, move the extracted directory to /opt: ``` mv spark-4.0.0-bin-hadoop3 /opt/spark ``` Next, you will need to define an environment variable to run Spark. You can define it inside the **~/.bashrc** file: ``` nano ~/.bashrc ``` Add the following line: ``` export SPARK_HOME=/opt/spark export PATH=$PATH:$SPARK_HOME/bin:$SPARK_HOME/sbin ``` Save and close the file, then activate the environment variable with the following command: ``` source ~/.bashrc ``` ## Step 3 – Start Apache Spark Cluster At this point, Apache spark is installed. You can now start the Apache Spark using the following command: ``` start-master.sh ``` You should get the following output: ``` starting org.apache.spark.deploy.master.Master, logging to /opt/spark/logs/spark-root-org.apache.spark.deploy.master.Master-1-debian10.out ``` By default, Apache Spark listens on port **8080**. You can check it with the following command: ``` ss -tunelp | grep 8080 ``` You should get the following output: ``` tcp LISTEN 0 1 *:8080 *:* users:(("java",pid=5931,fd=302)) ino:24026 sk:9 v6only:0 <-> ``` ## Step 4 – Start Apache Spark Worker Process Next, start the Apache Spark worker process with the following command: ``` start-worker.sh spark://debian:7077 ``` You should get the following output: ``` starting org.apache.spark.deploy.worker.Worker, logging to /opt/spark/logs/spark-root-org.apache.spark.deploy.worker.Worker-1-debian10.out ``` ## Step 5 – Access Apache Spark You can now access the Apache Spark web interface using the URL **http://your-server-ip:8080**. You should see the Apache Spark dashboard on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/09/s1.png) ## Step 6 – Access Apache Spark Shell Apache Spark also provides a command-line interface to manage Apache Spark. You can access it using the following command: ``` spark-shell ``` Once you are connected, you should get the following shell: ``` Using Spark's default log4j profile: org/apache/spark/log4j2-defaults.properties Setting default log level to "WARN". To adjust logging level use sc.setLogLevel(newLevel). For SparkR, use setLogLevel(newLevel). Welcome to ____ __ / __/__ ___ _____/ /__ _\ \/ _ \/ _ `/ __/ '_/ /___/ .__/\_,_/_/ /_/\_\ version 4.0.0 /_/ Using Scala version 2.13.16 (OpenJDK 64-Bit Server VM, Java 17.0.16) Type in expressions to have them evaluated. Type :help for more information. 25/09/05 07:06:33 WARN NativeCodeLoader: Unable to load native-hadoop library for your platform... using builtin-java classes where applicable Spark context Web UI available at http://debian:4040 Spark context available as 'sc' (master = local[*], app id = local-1757055995938). Spark session available as 'spark'. scala> ``` If you want to stop the Apache Spark cluster, run the following command: ``` stop-master.sh ``` To stop the Apache Spark worker, run the following command: ``` stop-worker.sh ``` ## Conclusion Congratulations! You have successfully installed and configured Apache Spark on Debian 12. This guide will help you to perform basic tests before you start configuring a Spark cluster and performing advanced actions. Try it on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) today! --- # How to Install Zeek Network Security Monitoring Tool in Ubuntu > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-zeek-network-security-monitoring-tool-in-ubuntu/ | Published: 2021-09-18 | Updated: 2024-06-02 | Author: Hitesh Jethva Zeek, formerly known as Bro, is a network security monitoring tool for Linux. It is a free, open-source, and flexible tool that sits on a “sensor,” or cloud platform, and observes network traffic. Zeek monitors and records connections, the volume of packets sent and received, attributes about TCP sessions, and other metadata that is useful for analyzing network behavior. It helps you trace complex events across multiple flows and protocols with ease. In this post, we will show you how to install the Zeek network security monitoring tool on Ubuntu 20.04. ## Step 1 – Install Zeek By default, Zeek is not included in the Ubuntu default repository, so you will first add the Zeek repository to your system. Install all required dependencies with the following command: ``` apt-get update -y apt-get install curl gnupg2 wget -y ``` Next, download and add the Zeek GPG key using the following command: ``` curl -fsSL https://download.opensuse.org/repositories/security:zeek/xUbuntu_20.04/Release.key | gpg --dearmor | tee /etc/apt/trusted.gpg.d/security_zeek.gpg ``` Next, add the Zeek repository to APT with the following command: ``` echo 'deb http://download.opensuse.org/repositories/security:/zeek/xUbuntu_20.04/ /' | tee /etc/apt/sources.list.d/security:zeek.list ``` Finally, update the repository cache and install the Zeek with the following command: ``` apt-get update -y apt-get install zeek -y ``` During the installation, you will be asked to provide some postfix settings as shown below: ![Select Internet or Local Mail server](https://www.atlantic.net/wp-content/uploads/2021/07/p1-4.png) ![Define mail name](https://www.atlantic.net/wp-content/uploads/2021/07/p2-5-1024x223.png) After installing Zeek, you will need to add Zeek to the system path. You can do it with the following command: ``` echo "export PATH=$PATH:/opt/zeek/bin" >> ~/.bashrc ``` Next, activate ~/.bashrc with the following command: ``` source ~/.bashrc ``` Now, verify the Zeek version with the following command: ``` zeek --version ``` You should get the following output: ``` zeek version 4.0.3 ``` ## Step 2 – Define Your Network Next, you will need to define the network that you want to monitor. You can define it by editing /opt/zeek/etc/networks.cfg file. ``` nano /opt/zeek/etc/networks.cfg ``` Here are the default values. You can add your own networks at the end of the file: ``` 10.0.0.0/8 Private IP space 172.16.0.0/12 Private IP space 192.168.0.0/16 Private IP space ``` Save and close the file when you are finished. ## Step 3 – Configure Zeek Cluster By default, Zeek is configured to run in standalone mode. In this section, we will configure Zeek in cluster mode. First, edit the Zeek main configuration file: ``` nano /opt/zeek/etc/node.cfg ``` Comment out the following lines: ``` #[zeek] #type=standalone #host=localhost #interface=eth0 ``` Add the following lines at the end of the file. ``` [zeek-logger] type=logger host=your-server-ip # [zeek-manager] type=manager host=your-server-ip # [zeek-proxy] type=proxy host=your-server-ip # [zeek-worker] type=worker host=your-server-ip interface=eth0 # [zeek-worker-lo] type=worker host=localhost interface=lo ``` Save and close the file when you are finished, then check the configuration file for any errors with the following command: ``` zeekctl check ``` If everything is fine, you should get the following output: ``` zeek-logger scripts are ok. zeek-manager scripts are ok. zeek-proxy scripts are ok. zeek-worker scripts are ok. zeek-worker-lo scripts are ok. ``` Next, deploy the Zeek configuration with the following command: ``` zeekctl deploy ``` You should get the following output: ``` starting logger ... starting manager ... starting proxy ... starting workers ... ``` ## Step 4 – Verify Status of Zeek You can now check the status of the Zeek instance using the following command: ``` zeekctl status ``` You should get the following output: ``` Name Type Host Status Pid Started zeek-logger logger your-server-ip running 10479 25 Jul 06:34:08 zeek-manager manager your-server-ip running 10529 25 Jul 06:34:10 zeek-proxy proxy your-server-ip running 10579 25 Jul 06:34:12 zeek-worker worker your-server-ip running 10648 25 Jul 06:34:14 zeek-worker-lo worker localhost running 10650 25 Jul 06:34:14 ``` At this point, Zeek will start to analyze traffic as per the configuration file and write logs to the /opt/zeek/logs/current directory. You can check all generated log files with the following command: ``` ls -l /opt/zeek/logs/current/ ``` You should see the following output: ``` -rw-r--r-- 1 root zeek 1780 Jul 25 06:36 broker.log -rw-r--r-- 1 root zeek 2346 Jul 25 06:36 cluster.log -rw-r--r-- 1 root zeek 578 Jul 25 06:36 conn.log -rw-r--r-- 1 root zeek 28733 Jul 25 06:36 loaded_scripts.log -rw-r--r-- 1 root zeek 596 Jul 25 06:36 ntp.log -rw-r--r-- 1 root zeek 187 Jul 25 06:36 packet_filter.log -rw-r--r-- 1 root zeek 601 Jul 25 06:36 stats.log -rw-r--r-- 1 root zeek 0 Jul 25 06:36 stderr.log -rw-r--r-- 1 root zeek 188 Jul 25 06:36 stdout.log -rw-r--r-- 1 root zeek 482 Jul 25 06:36 weird.log ``` Run the following command to check the connection logs. ``` tail /opt/zeek/logs/current/conn.log ``` Sample output: ``` 1627194994.735281 Cu51ph1SpnaI5e8VGe 184.188.36.2 56921 your-server-ip 445 tcp - 0.000036 0 0 REJ F F 0 Sr 1 52 1 40 - 1627194997.416217 CEMJC91xoEHySwvNdg your-server-ip 47762 your-server-ip 47466 tcp - - - - OTH FF 0 CcCc 0 0 0 0 - 1627194998.422707 C9lEWO2Cka3rN7kafa your-server-ip 46316 your-server-ip 47761 tcp - - - - OTH FF 0 CcCc 0 0 0 0 - 1627195000.441681 Cw8Uy5wH7AyZlUxg your-server-ip 46310 your-server-ip 47761 tcp - - - - OTH FF 0 CcCc 0 0 0 0 - ``` Run the following command to check the cluster logs: ``` tail /opt/zeek/logs/current/cluster.log ``` Sample output: ``` 1627194993.480149 zeek-proxy got hello from zeek-worker (37A494EB63B75E2A52F1EA47CA05933C608362F3#13744) 1627194993.506139 zeek-proxy got hello from zeek-worker-lo (78A849E99E95C3EB4A0E457797D42C13BAFF3E14#13742) 1627194993.506938 zeek-manager got hello from zeek-worker (37A494EB63B75E2A52F1EA47CA05933C608362F3#13744) ``` ## Step 5 – Check Zeek Node Processes You can also check the processes running on each node. To check the running processes of the zeek-manager node, run the following command: ``` zeekctl ps.zeek zeek-manager ``` You should get the following output: ``` USER PID PPID %CPU %MEM VSZ RSS TT S STARTED TIME COMMAND >>> your-server-ip (-) root 13574 13568 1.7 2.1 1263568 87912 ? S 06:36:26 00:00:01 zeek (+) root 13624 13618 1.5 2.2 642620 88836 ? S 06:36:27 00:00:01 zeek (-) root 13673 13667 1.3 2.1 640932 87224 ? S 06:36:29 00:00:01 zeek (-) root 13742 13732 2.1 5.4 771956 218288 ? S 06:36:31 00:00:01 zeek (-) root 13744 13731 2.2 5.4 772548 219764 ? S 06:36:31 00:00:02 zeek ``` ## Conclusion In this post, you learned how to install and configure the Zeek network security monitoring tool on Ubuntu 20.04. For more information on Zeek configuration, visit the [Zeek](https://docs.zeek.org/en/lts/quickstart.html) documentation. Get started with Zeek today on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # What Is an SSL Certificate? > URL: https://www.atlantic.net/vps-hosting/what-is-ssl-certificate/ | Published: 2021-09-19 | Updated: 2024-09-25 | Author: Chelsea Fieler SSL/TLS certificates are an essential security detail of any trusted website and a crucial business requirement for eCommerce websites that expect to generate revenue via a trusted website platform. ## What Are SSL Certificates For? The basic function of an SSL certificate is to provide secured communications between the web server and the website user. The SSL certificate gives you the padlock at the top of the browser. It guarantees that the data being served is the data intended by the provider. However, if you look closer, you will see that there is more to SSL certificates than their surface-level function. ### Paid SSL Certificates A paid SSL certificate requires the Certificate Authority (CA) to validate the website and company details prior to issuing the certificate. This gives the consumer the utmost confidence that the website is legitimate and safe to use. ### Free SSL Certificates There are many scenarios where a free SSL certificate is perfectly adequate for a website because it ensures your site will be encrypted! Free SSL certs are great for personal blogs such as WordPress sites or internal intranet pages. Free certificates are Domain Validated (DV) and can be created by anyone who has admin access to the domain name. This does create an element of trust; however, it’s easy to circumvent these protections, making it possible for unscrupulous entities to create a secure connection to an untrustworthy site. ## Site Validation A paid SSL certificate from a trusted certificate authority, such as [RapidSSL](https://www.clickssl.net/cheapest-rapidssl-certificates-provider), guarantees the users that they are visiting a secured, encrypted, and genuine website. It also guarantees that the website owner and website have been vetted and tested. This creates a level of trust between the consumer and the website that is vital for all revenue-generating websites or sites that exchange personal information to be validated. There are three types of validation available for paid certificates: - Organization Validation (OV) – an OV certificate verifies the identity of the organization. This might be a business, non-profit, NGO, or government organization. - Individual Validation (IV) – this validates an individual’s website or someone that is not registered as a business. - Extended Validation (EV) – an EV validates the identity of the organization at a deeper layer, representing a higher level of trust as more rigorous checks are required by the CA. ## Benefits of a PAID SSL While an OV or EV certificate validates the owner of a website, the sender of an email, the digital signatory of executable code, or that PDF documents are trustworthy, there are other important reasons why you should opt for a paid SSL. Paid certificates have a longer certificate lifetime. Free certs typically last from 90 days, but usually, no longer than 1 year before they must be renewed. Paid certificates typically last for a minimum of 3 years, however, they can last for much longer, and it depends on what policy the certificate authority follows. Your system admins will thank you for longer certificate lifetimes, as renewing an SSL is not the simplest of tasks to complete. Other perks of a paid SSL include a warranty that protects you financially in the event the certificate caused website errors resulting in the loss of revenue. Regardless of the implications of this warranty, you can rest easy, as SSL certificates are incredibly reliable and it’s almost never the certificate causing issues. ![SECURE AND TRUSTWORTHY FOR ABSOLUTE CUSTOMER CONFIDENCE](https://www.atlantic.net/wp-content/uploads/2021/09/SSL-Certificates4_secure-customer-confidence.png) ## Secure and Trustworthy for Absolute Customer Confidence SSL certificates are the number one security detail to promote trust in a website. A certificate encrypts website communications and guarantees site authenticity. The Chrome web browser confirms that a site has a valid security certificate by displaying a padlock, while Safari shows a security shield. Without a SSL certificate, some browsers will outright block your site. SSLs are a key component in web security. ## ![WHAT KIND OF SSL CERTIFICATE DO I NEED?](https://www.atlantic.net/wp-content/uploads/2021/09/SSL-Certificates4_certificate.png)What Kind of SSL Certificate Do I Need? - Each SSL has a different use case scenario. Some are free and some are subscription-based. Some can even be created by the user, but most need to be purchased from a Certificate Authority (CA). - An unregistered **Private Trust Certificate** is the most basic available. It’s a free self-signed cert created by the user. This is only recommended for internal company sites or personal blogs. - Basic trust is a domain-validated certificate that creates a private security session for the user. These are usually free of charge, and you can use applications like Let’s Encrypt to create rolling 90-day certificates. These are only recommended for sites not bound by regulations like PCI compliance or HIPAA compliance - Enhanced trust is available at an organizational or individual level using validated certificates that also create a private security session for the user. Business information is hard-coded into the enhanced certificate. Most business sites will start with this type and grow from here depending on compliance requirements. - Complete trust is an Extended Validation certificate that creates a private secure session with the user and typically displays the business details, usually in a green color next to the padlock. These types of certificates are usually used by companies that are under compliance requirements like HIPAA, PCI-DSS, HITECH, etc. - There are three types of Registered Certificates: **Domain Validated Certificate (DV)** - (Basic) **Organizational / Individual Certificate (OV)** - (Enhanced) **Extended Validation Certificate (EV)** - (Complete) ## SSL/TLS Options ##### A VISUAL GUIDE TO CHOOSING THE RIGHT SSL/TLS FOR YOUR ORGANIZATION ![SSL/TLS OPTIONS TO CHOOSE FROM](https://www.atlantic.net/wp-content/uploads/2021/09/SSL-Certificates4-09.png) ![SSL CERTIFICATE PRICING, SPECIFICATION, AND WARRANTY](https://www.atlantic.net/wp-content/uploads/2021/09/SSL-Certificates4_pricing-e1639251750344.png) ## SSL Certificate Pricing, Specification, and Warranty | Name | Geo Trust Quick SSL Premium | Geo Trust True Business ID | Geo Trust True Business ID EV | | --- | --- | --- | --- | | Validation Type | Domain Validated | Organization Validated | Extended Validation | | Wildcard | No | No | No | | SAN Support | Supports 1 SAN package that includes 4 sub-domains ($40/year). | SANs are $40/year each. Supports up to 100 domains. Minimum order is 4 SANs. | SANs are $50/year each. Supports up to 100 domains. Minimum order is 4 SANs. | | Price | **$149/year** | **$199/year** | **$299/year** | | Issuance | 1-2 days | 1-14 days | 1-4 weeks | | Re-issues | Unlimited | Unlimited | Unlimited | | Warranty by CA | $500,000 | $1,250,000 | $1,500,000 | | Business Validated | No | Yes | Yes | | Security and Encryption | 256-bit encryption signed with a 2048-bit root | 256-bit encryption signed with a 2048-bit root | 256-bit encryption signed with a 2048-bit root | | Available Periods | 1 Year | 1 Year | 1 Year | | Name | Geo Trust True Business ID Wildcard | RapidSSL Basic | RapidSSL Wildcard | | Validation Type | Organization Validated | Domain Validated | Domain Validated | | Wildcard | Yes | No | Yes | | SAN Support | No | No | No | | Price | **$599/year** | **$59/year** | **$249/year** | | Issuance | 1-7 days | 1-2 days | 1-2 days | | Re-issues | Unlimited | Unlimited | Unlimited | | Warranty by CA | $1,250,000 | $10,000 | $10,000 | | Business Validated | Yes | No | No | | Security and Encryption | 256-bit encryption signed with 256-bit encryption 256-bit encryption a 2048-bit root | 256-bit encryption | 256-bit encryption | | Available Periods | 1 Year | 1 Year | 1 Year | *SSL installation is $100 for each SSL certificate* You also get 24/7 support from the CA, especially useful if you have a certificate expiring in the next few hours. The CA support team will be available to generate you a new certificate in next to no time. To request an SSL with Atlantic.Net, please call 1-866-618-DATA (3282) or email [support@atlantic.net](mailto:support@atlantic.net). ## Atlantic.Net SSL Resources Atlantic.Net offers [VPS hosting](https://www.atlantic.net/vps-hosting/) as well as managed hosting services which include a layer of business-essential managed services to your hosting packages. Contact us today for more information. Learn more about SSL by visiting the following resources: [SSL, VPN, and Compliance: Frequently Asked Questions](https://www.atlantic.net/dedicated-server-hosting/ssl-vpn-and-compliance-frequently-asked-questions/) [Why All Small Business Owners Need to Install SSL Certificates Immediately](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/why-all-small-business-owners-need-to-install-ssl-certificates-immediately/) [Install LAMP Server with Let’s Encrypt Free SSL on Ubuntu 18.04](https://www.atlantic.net/vps-hosting/install-lamp-server-with-lets-encrypt-free-ssl-on-ubuntu-18-04/) [How to Generate a Certificate Signing Request (CSR) for an SSL](https://www.atlantic.net/vps-hosting/how-to-generate-certificate-signing-request/)   --- # What is Required for HIPAA Compliant Software? > URL: https://www.atlantic.net/hipaa-compliant-hosting/what-is-required-for-hipaa-compliant-software/ | Published: 2021-09-20 | Updated: 2025-08-03 | Author: Alexander Wise When choosing which software to use for their business, healthcare organizations must assess whether the software is HIPAA compliant. Many software providers meet HIPAA Security Rule requirements by implementing safeguards to keep patient data secure. However, there’s more to HIPAA-compliant software than security. There are certain requirements that must be met by software providers before they can be considered HIPAA compliant. ## When Does Software Need to be HIPAA Compliant? Before discussing what is required for HIPAA-compliant software, it is important to understand when software needs to be HIPAA compliant. When software is used to create, store, transmit, or receive electronic protected health information (ePHI), the software must be HIPAA compliant. In these instances, software providers are considered [business associates](https://compliancy-group.com/hipaa-business-associate/) and therefore must have security measures in place to secure ePHI and have signed business associate agreements with healthcare clients. ## What is Electronic Protected Health Information? Protected health information (PHI) is any individually identifiable health information related to the past, present, or future provision of healthcare by a covered entity. Electronic PHI (ePHI) is any protected health information that is created, stored, transmitted, or received in any electronic format or media. Some examples of PHI include patients’ names, email addresses, and Social Security numbers. ## HIPAA Security Requirements HIPAA compliant software ensures the confidentiality, integrity, and availability of ePHI through HIPAA safeguards. The HIPAA Security Rule provides [guidance](https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/administrative/securityrule/techsafeguards.pdf) on what security measures should be implemented to do so. - **User Authentication:** HIPAA compliant software enables administrators to provide unique login credentials for each of their employees. The HIPAA Security Rule requires entities to “implement procedures to verify that a person or entity seeking access to [electronic protected health information](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) is the one claimed.” - **Access Controls:** [HIPAA](https://compliancy-group.com/hipaa/) also requires ePHI access to be limited to the minimum necessary to perform a job function, so entities must “implement technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to those persons or software programs that have been granted access rights.” - **Audit Logs:** to ensure that ePHI access is in accordance with the minimum necessary standard, entities must “implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.” - **Encryption:** to prevent unauthorized access to ePHI, entities must “implement a mechanism to encrypt electronic protected health information whenever deemed appropriate.” - **Offsite Data Backup:** to prevent data loss, entities must “Establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information.” - Other HIPAA Requirements As a software provider servicing healthcare clients, not only does your software need to have security measures in place to protect ePHI, but also you must be HIPAA compliant. HIPAA requires business associates to implement an effective HIPAA compliance program as follows. **Business Associate Agreements** A key component of HIPAA compliance is the ability to sign a business associate agreement. Business associate agreements (BAAs) are legal contracts between healthcare organizations and business associates that require each signing party to be HIPAA compliant and be responsible for maintaining their compliance. Since BAAs require each party to be responsible for upholding HIPAA compliance standards, they also limit liability in the event of a breach. With an increase in healthcare organizations being [breached through their business associates](https://www.healthcareitnews.com/news/business-associates-were-largely-blame-2020-breaches), it’s more important than ever to secure BAAs with all healthcare clients. To be a HIPAA compliant software provider, you must also have signed BAAs with your vendors that have the potential to access the ePHI that your clients filter through your software. **Risk Assessments and Remediation** Each year, it is important to conduct risk assessments to identify risks and vulnerabilities to ePHI. There is a common misconception that conducting a security risk analysis is enough to meet HIPAA self-auditing requirements; however, business associates must also complete the HITECH Subtitle D Security Standards, Asset, and Device, and Physical Site audits. To be HIPAA compliant, organizations must implement remediation plans to address deficiencies found by conducting these self-audits. Remediation plans must include how the issue will be addressed, a timeline for when it will be remedied, and who is responsible for implementing the plan. **HIPAA Policies and Procedures** To ensure adherence to HIPAA, organizations must have written HIPAA Privacy, Security, and Breach Notification policies and procedures. These policies and procedures should dictate the proper uses and disclosures of ePHI, how the software provider protects ePHI, and what to do in the event of an ePHI breach. It is important that policies and procedures are customized for a specific organization. HIPAA requires business associates to implement “reasonably appropriate” measures to secure ePHI. However, what is considered a reasonably appropriate measure for a large organization would not necessarily be so for a small business. The policies and procedures must directly correlate with how that specific business operates. To be HIPAA compliant, the policies and procedures must be reviewed annually and amended when appropriate. **HIPAA Employee Training** A large portion of HIPAA breaches occur due to human error. The best way to avoid this type of breach is to train employees on HIPAA basics, your organization’s HIPAA policies and procedures, and cybersecurity best practices. Since each employee must be trained upon hire and HIPAA imposes annual training requirements, conducting one annual training session a year is not sufficient. As such, tracking employee training can be difficult and lead to a lapse in [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). To meet training requirements, it is best to use a HIPAA software solution in which employees can complete individual training that allows them to legally attest that they agree to adhere to the training material. Using software for training also allows administrators to easily track and manage employee training, ensuring that all employees are trained in a timely manner. **Breach Reporting and Incident Response** The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) requires business associates to report breaches affecting ePHI. Breaches affecting less than 500 patients must be reported within 60 days from the end of the calendar year (March 1st) in which they were discovered. These breaches must be reported to the HHS’ OCR and breach notification letters must be mailed to affected individuals. Breaches affecting 500 or more patients must be reported within 60 days of discovery. These breaches must be reported to the HHS’ OCR, affected patients, and local media outlets. Breaches affecting 500 or more patients are also listed on the [OCR online breach portal](https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf) for public scrutiny, colloquially known as the “HIPAA Wall of Shame.” Business associates that have been breached must contract third-party forensic investigators to determine what caused the breach, to understand how many patients were affected, and [remedy the security deficiencies](https://mobidev.biz/blog/best-practices-to-secure-web-applications-from-vulnerabilities) that led to the breach. They are also subject to investigation by the HHS’ OCR to determine whether or not the breach was due to negligence. When OCR investigations determine that a breach was caused by a failure to adequately protect ePHI, it is deemed a HIPAA violation subject to remediation, OCR monitoring, and fines. ## Contributed by Compliancy Group HIPAA should be simple. That’s why Compliancy Group is the only HIPAA software with expert Compliance Coaches® holding your hand to simplify compliance. Compliancy Group gives you confidence in your compliance plan, increasing customer loyalty, and profitability of your organization while reducing risk. Find out more about the HIPAA Seal of Compliance® and Compliancy Group. [Get HIPAA compliant today!](https://compliancy-group.com/) --- # Top 10 Remote Management Tools > URL: https://www.atlantic.net/vps-hosting/top-10-remote-management-tools/ | Published: 2021-09-21 | Updated: 2024-08-26 | Author: Dr. Rachael Bailey As the global coronavirus pandemic has caused a shift (perhaps permanent) towards remote working and learning, the remote management of IT systems is crucial. Our new work culture means that having remote access to our business or organization’s computers and network is not only desirable but essential. So, what are remote management tools, and how do they work? ## What Are Remote Management Tools? Remote management tools allow IT professionals and Managed Service Providers to remotely manage endpoints, allowing issues to be diagnosed and rectified and scheduled tasks to be automated. These tools are an essential utility for system administrators and technical support teams. A technology that was once found only in the data center has progressed to a more mainstream audience. Almost any device that has access to the internet can be managed by a remote management tool. The technical requirements of creating your own remote access connection are challenging, especially if you don’t have a static IP address. But remote management tools remove this complexity to create a seamless connection to a remote resource. All that is required is a username and password combination and a few prerequisites, such as authenticating the access request. Today, remote management tools are bundled with lots of user-friendly applications that make the entire process seamless. You can monitor, manage, and troubleshoot issues with ease, all within a secure ecosystem. Here is our list of the top 10 Remote Management tools: ## Top 10 Remote Management Software ## 1. TeamViewer Remote Management TeamViewer offers a centralized remote monitoring and management solution that users can try for free with a 14-day free trial. TeamViewer Remote Management provides cross-platform compatibility and is fully customizable and scalable, allowing it to be adapted to meet client’s needs. This comprehensive platform also offers patch management, asset management, endpoint protection, network monitoring, and remote backup. The only downside to TeamViewer Remote management is its price point. While personal users can benefit from a limited free version, businesses and organizations must sign up for a paid subscription, which is on the expensive side. ## 2. LogMeIn Central LogMeIn Central is a powerful cloud-hosted remote monitoring and management (RMM) software. A centralized dashboard allows users to remotely and reliably maintain their IT infrastructure. This software can be used to automate updates and other routine tasks and monitor the health of connected devices. LogMeIn Central is compatible with Windows, Mac OS X, Android, and iOS operating systems. Users can benefit from a 14-day free trial and the option to pay only for the services that they require due to the software being hosted in the cloud. ## 3. Webex Support Webex Support by Cisco is a dynamic platform, offering real-time remote support and customer service to businesses and organizations. Users are able to access support via remote desktop control, live chat, or video conferencing. Agents can assist up to five clients at a time and offer support across multiple platforms. As the software is delivered over the global Cisco Collaboration Cloud on an on-demand basis; there is no need for the installation of physical software or hardware, and services are fully secure and scalable. ## 4. AnyDesk Whether you are a large business or a [start-up](https://www.crowdspring.com/blog/starting-a-business/), AnyDesk can provide you with powerful remote assistance software to support your continued success. With seamless cross-compatibility across multiple operating systems, fast download, and automated rollout to multiple computers, AnyDesk is extremely user-friendly. Fast and lag-free connections ensure that your customers are never left waiting for your support. ## 5. Splashtop A leader in on-demand remote support software, Splashtop is good value for money and highly secure. This tool is a great alternative for some of the more expensive remote access tools on the market. It is trusted by over 200,000 businesses and 30 million end-users worldwide, this includes government agencies, law enforcement organizations, and large banks. Splashtop offers flexible monthly subscriptions to ensure that you are only paying for the services that you are using. ## 6. ConnectWise Control ConnectWise Control (previously ScreenConnect) offers a market-leading remote support solution. ConnectWise Control offers three different solutions: ConnectWise Control Access, ConnectWise Control Support, and ConnectWise Control Premium; these are tailored to the needs of clients ranging from individuals to Managed Service Providers (MSPs). This software delivers world-class security out-of-the-box, role-based security architecture, customization, and configurability, with hundreds of extensions and integrations. ## 7. Atera RMM Atera delivers a cloud-based all-in-one remote monitoring solution designed for IT Professionals and MSPs. With a 30-day free trial, you can try out all of their features before you invest. If you are happy with the software, Atera offers a transparent, technician-based price plan that includes unlimited servers and workstations. Features of Atera include RMM, Professional Services Automation (PSA), patch management, remote access and support, third party integrations, reporting, and analytics. ## 8. HelpDesk by RemotePC As a web-based, high-performance remote management tool, HelpDesk by RemotePC lets you connect securely to any device without the need for additional software. HelpDesk offers users plenty of features including industry-standard security measures (TLS v 1.2 and AES 256-bit encryption), video or text-based chat, the option to view multiple monitors, logs, and reporting, and cross-platform access. ## 9. BeyondTrust Remote Support BeyondTrust Remote Support (previously Bomgar Remote Support) is ideal for businesses and organizations that are looking for a remote support solution with additional security features. This remote support tool allows users to granularly manage users, roles, and session permission settings, ensuring that the right level of access is maintained. All session activity is logged to provide a comprehensive audit trail. It can integrate with CRM, ITSM, SIEM, and password tools and can be scaled to meet the changing needs of your business. ## 10. NinjaRMM NinjaRMM, a powerful RMM software, was founded by industry experts in 2013. This RMM tool is trusted by over 6000 customers worldwide and was rated number 1 across 8 categories by G2 Crowd; this rating included ease of setup, ease of use, and quality of support. NinjaRMM provides an intuitive and efficient platform with easily accessible features including multi-platform endpoint management, powerful patch management, IT automation, robust monitoring and alerting, fast and secure remote access, robust endpoint protection, and integrated cloud backup. ## How can Atlantic.Net help? As a provider of managed services and professional services, Atlantic.Net engineers use remote management tools almost every day. As we own the network our teams can remote desktop using RDP tools, we also use a proprietary management tool for our cloud systems. Each Atlantic.Net [cloud VPS](https://www.atlantic.net/vps-hosting/) has remote access built into the build, and you can gain console access using VNC Server that is built directly into [cloud.atlantic.net](https://cloud.atlantic.net/?page=userlogin). If you prefer to manage your server directly you can RDP or SSH directly to your server instance, or you can choose one of the applications mentioned in our Top 10. These are all compatible with Atlantic.Net customer servers, and to connect your instance you would typically just need to install the relevant agent, which can be downloaded and configured over the internet. To find out more about the solutions that we offer, [contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- #### Read More About Remote Management & VPNs - [What Is a VPN?](https://www.atlantic.net/vps-hosting/what-is-vpn/) - [VPS vs VPN](https://www.atlantic.net/vps-hosting/vps-vs-vpn-similar-names-but-completely-different-functions/)? --- --- # How To Create a New User and Grant Permissions in MySQL 8 on CentOS 8 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-create-a-new-user-and-grant-permissions-in-mysql8-on-centos8/ | Published: 2021-09-22 | Updated: 2024-06-05 | Author: Hitesh Jethva MySQL is one of the most popular database management systems around the world. This open-source database management system helps you to store, organize, and retrieve data. MySQL comes with a lot of options that allow you to grant specific permissions to databases based on user needs. This post will show you how to create a user and grant permissions in MySQL 8. ## Step 1 – Update Server Once you are logged in to your CentOS 8 server, run the following command to update your base system with the latest available packages. ``` dnf update -y ``` ## Step 2 – Install MySQL 8 First, you will need to install MySQL 8 on your server. You can install it with the following command: ``` dnf install mysql-server -y ``` Once the installation is completed, start the MySQL service and enable it to start at system reboot: ``` systemctl start mysqld systemctl enable mysqld ``` ## Step 3 – Create a Database and User in MySQL 8 In this section, we will create a database and user in MySQL. First, connect to the MySQL shell using the following command: ``` mysql ``` Once you are connected, create a database named testdb and testdb1 using the following command: ``` CREATE DATABASE testdb; CREATE DATABASE testdb1; ``` Next, display all the databases using the following command: ``` show databases; ``` You should get all databases in the following output: ``` +--------------------+ | Database | +--------------------+ | information_schema | | mysql | | performance_schema | | sys | | testdb | | testdb1 | +--------------------+ 6 rows in set (0.01 sec) ``` Next, create a user named testuser for localhost and set a password using the following command: ``` CREATE USER 'testuser'@'localhost' IDENTIFIED BY 'password'; ``` We have created a testuser for localhost, which means testuser will be able to connect to MySQL only from the localhost. If you want to create a MySQL user and grant access from the remote machine with IP **192.168.10.100**, run the following command: ``` CREATE USER 'testuser'@'192.168.10.100' IDENTIFIED BY 'password'; ``` If you want to create a MySQL user and grant access from all remote hosts, run the following command: ``` CREATE USER 'testuser'@'%' IDENTIFIED BY 'password'; ``` ## Step 4 – Grant Privileges to a MySQL User Account MySQL provides several types of user privileges that you can grant to a user. Some of them are listed below: - **ALL PRIVILEGES:** Used to grant all privileges to the user account. - **INSERT:** This allows the user to insert rows into a table. - **SELECT:** Allows users to read a database. - **UPDATE:** Allows users to update table rows. - **CREATE:** Allows users to create a database and table. - **DELETE:** This allows the user to delete rows from a table. - **DROP:** Allows users to delete a database and table. Let’s see some examples: To grant all the privileges to **testuser** on **testdb** database, run the following command: ``` GRANT ALL PRIVILEGES ON testdb.* TO 'testuser'@'localhost'; ``` To grant all the privileges to **testuser** on all **databases**, run the following command: ``` GRANT ALL PRIVILEGES ON *.* TO 'testuser'@'localhost'; ``` To grant only SELECT, INSERT and DELETE privileges to **testuser** on **testdb1** database, run the following command: ``` GRANT SELECT, INSERT, DELETE ON testdb1.* TO testuser@'localhost'; ``` ## Step 5 – Show Granted Privileges You can use the SHOW GRANTS command to display the privileges that you have granted to MySQL users. Run the following command to display all granted privileges to testuser: ``` SHOW GRANTS FOR 'testuser'@'localhost'; ``` You should get the following output: ``` +------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------a+ | Grants for testuser@localhost | +------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+ | GRANT SELECT, INSERT, UPDATE, DELETE, CREATE, DROP, RELOAD, SHUTDOWN, PROCESS, FILE, REFERENCES, INDEX, ALTER, SHOW DATABASES, SUPER, CREATE TEMPORARY TABLES, LOCK TABLES, EXECUTE, REPLICATION SLAVE, REPLICATION CLIENT, CREATE VIEW, SHOW VIEW, CREATE ROUTINE, ALTER ROUTINE, CREATE USER, EVENT, TRIGGER, CREATE TABLESPACE, CREATE ROLE, DROP ROLE ON *.* TO `testuser`@`localhost` | | GRANT APPLICATION_PASSWORD_ADMIN,AUDIT_ADMIN,BACKUP_ADMIN,BINLOG_ADMIN,BINLOG_ENCRYPTION_ADMIN,CLONE_ADMIN,CONNECTION_ADMIN,ENCRYPTION_KEY_ADMIN,GROUP_REPLICATION_ADMIN,INNODB_REDO_LOG_ARCHIVE,INNODB_REDO_LOG_ENABLE,PERSIST_RO_VARIABLES_ADMIN,REPLICATION_APPLIER,REPLICATION_SLAVE_ADMIN,RESOURCE_GROUP_ADMIN,RESOURCE_GROUP_USER,ROLE_ADMIN,SERVICE_CONNECTION_ADMIN,SESSION_VARIABLES_ADMIN,SET_USER_ID,SHOW_ROUTINE,SYSTEM_USER,SYSTEM_VARIABLES_ADMIN,TABLE_ENCRYPTION_ADMIN,XA_RECOVER_ADMIN ON *.* TO `testuser`@`localhost` | | GRANT ALL PRIVILEGES ON `testdb`.* TO `testuser`@`localhost` | | GRANT SELECT, INSERT, DELETE ON `testdb1`.* TO `testuser`@`localhost` | +------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+ 4 rows in set (0.00 sec) ``` ## Step 6 – Revoke Privileges from a MySQL User Account If you want to revoke or restore all privileges from a MySQL user over a database, use the revoke command as shown below: ``` REVOKE ALL PRIVILEGES ON testdb.* FROM 'testuser'@'localhost'; ``` ## Step 7 – Delete MySQL Database and User Account To delete a MySQL database, use the following command: ``` DROP DATABSE testdb; ``` To delete a MySQL user account, use the following command: ``` DROP USER 'testuser'@'localhost'; ``` ## Conclusion This guide explained how to create a MySQL database, user, and grant privileges in MySQL 8. You can now experiment with different permissions settings for your database and apply them in the development environment. Try it today on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Yarn NPM Package Manager on RockyLinux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-yarn-npm-package-manager-on-rocky-linux-10/ | Published: 2021-09-30 | Updated: 2025-10-22 | Author: Hitesh Jethva Yarn, also called “Yet Another Resource Navigator,” is a fast, secure and reliable JavaScript package manager that allows you to automate the installation, configuring, updating, and removing of npm packages. Yarn caches every package it has downloaded, so it never needs to download the same package again. In this post, we will explain the following: - Install Yarn using NPM - Install Yarn from repository NPM - Install Yarn with Script ## Step 1 – Install YARN using NPM In this section, we will show you how to install Yarn via Node Package Manager. First, you will need to add the NodeSource repository to your system. You can add it with the following command: ``` curl --silent --location https://rpm.nodesource.com/setup_22.x | bash - ``` Once the repository is added, install the Node.js and NPM package using the following command: ``` dnf install nodejs npm -y ``` Next, verify the Node.js version with the following command: ``` node --version ``` Sample output: ``` v22.21.0 ``` You can also check the NPM version using the following command: ``` npm -v ``` Sample output: ``` 10.9.4 ``` Now, install the Yarn package using the NPM as shown below: ``` npm install --global yarn ``` You should get the following output: ``` npm notice npm notice New major version of npm available! 10.9.4 -> 11.6.2 npm notice Changelog: https://github.com/npm/cli/releases/tag/v11.6.2 npm notice To update run: npm install -g npm@11.6.2 npm notice ``` Next, verify the Yarn version with the following command: ``` yarn -v ``` Sample output: ``` 1.22.11 ``` You can uninstall the Yarn package from your system using the following command: ``` npm uninstall -g yarn ``` ``` ``` ## Step 2 – Install YARN with Script In this section, we will show you how to install Yarn via the Yarn installation script. You can download and run the Yarn installation script using the following command: ``` curl -o- -L https://yarnpkg.com/install.sh | bash ``` Once the Yarn package has been installed, you should get the following output: ``` > Successfully installed Yarn 1.22.22! Please open another terminal where the `yarn` command will now be available. ``` Next, activate the system path with the following command: ``` source ~/.bashrc ``` Next, verify the Yarn version using the following command: ``` yarn -v ``` Sample output: ``` 1.22.22 ``` ## Conclusion In the above guide, we explained the two-way to install the Yarn package on RockyLinux 10. You can now use your preferred way to install the Yarn to your system. Get started with Yarn on a [dedicated host](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net today! --- # Top 10 Linux Distributions > URL: https://www.atlantic.net/vps-hosting/top-10-linux-distributions/ | Published: 2021-10-01 | Updated: 2025-09-19 | Author: Richard Bailey The Linux Operating System is one of the most popular OSes available today and is built into a huge number of products you may not have expected to find it in. The Android Smartphone software runs on the Linux Kernel, and macOS runs on a heavily modified version of Unix (which is also based on the Linux Kernel). Linux thrives in the business server market and is heavily utilized in Cloud Computing. It’s frequently used for virtual cloud instances, Kubernetes clusters, and Docker Containers due to being lightweight and super reliable. ## What is a Linux Distro? Linux is available in a wide variety of distributions, or distros as they’re commonly known, and each is based upon the Linux Kernel. This is the brain of the operating system that manages the underlying hardware. The distro is the software wrap-around that the user interacts with, commonly a command-line interface, but it is also available as a GUI (such as GNOME or KDE). Each Linux distro is streamlined for a particular use case. The overwhelming majority are open-source, meaning that the distro is built and maintained by the community and that they are all free (with the odd exception). Remember that many of these distros are available as 1-click applications on the [Atlantic.Net Cloud.](https://cloud.atlantic.net/?page=userlogin) Here is our top 10 list of Linux distros:![](https://www.atlantic.net/wp-content/uploads/2021/10/top-10-linux-distributions.png) ## Top 10 Linux Distributions ### ![](https://www.atlantic.net/wp-content/uploads/2021/10/ubuntu-e1638038274181.png)1. Ubuntu Ubuntu is probably the most popular Linux distribution available right now. It comes in two flavors: a [server](https://www.atlantic.net/vps-hosting/) core version, perfect for command-line ninjas, and a hugely popular Ubuntu Desktop edition. Ubuntu is arguably the biggest Linux competitor to Windows, but unlike the Microsoft product, it’s completely free. Paid support options are available for businesses with Canonical Advantage, a support package that provides extended security maintenance, Kernel Live patching (upgrades without reboots), and enhanced crypto security to name just a few of its offerings. Combine this with a huge catalog of free software, excellent reliability, and an exceptionally helpful community, and Ubuntu is right up there with the very best. You can deploy various versions of Ubuntu Linux on the Atlantic.Net Cloud right now. [Including 1-Click Apps that launch in under 30 seconds – click here to find out more.](https://cloud.atlantic.net/?page=signup) ### ![](https://www.atlantic.net/wp-content/uploads/2021/10/rocky-linux-e1638038347622.png)2. Rocky Linux Rocky Linux has quickly become a firm favorite in the Linux community, and its popularity with the enterprise is growing rapidly. Rocky only started development in December 2020 after Red Hat announced its discontinued support for CentOS downstream in favor of a more divisive upstream model. This might not sound like a big deal, but it essentially means that CentOS is going to be used as a pre-release testing platform for RHEL, absolutely not what is needed for an enterprise product. The result? Rocky Linux! The aim of Rocky Linux is to provide a business-grade operating system that has fully validated updates and applications available that are tested for compatibility and stability prior to release. The initial signs are very good, with the first general availability release being well-received, gaining sponsorship of AWS, Azure, and Google Cloud, to name just a few adopters. Want to try Rocky Linux? You can spin up Rocky Linux 8.4 directly from the [Atlantic.Net cloud console](https://cloud.atlantic.net/?page=userlogin). ### ![](https://www.atlantic.net/wp-content/uploads/2021/10/red-hat.png)3. Red Hat Enterprise Linux (RHEL) Red Hat is the most popular paid version of Linux. RHEL is part of a much larger Red Hat ecosystem created for business applications. Red Hat is the leader in open-source software development and has debuted some game-changing applications such as Ansible, OpenStack, OpenShift, and LibreOffice. Red Hat’s biggest appeal is the technical support provided for businesses. All Red Hat-provided software repositories are certified for Red Hat, meaning that any issues you encounter will be resolved as part of your support package. The good news is that the OS is bulletproof with exceptional reliability. ### ![](https://www.atlantic.net/wp-content/uploads/2021/10/debian.png)4. Debian Debian GNU Linux was started way back in 1993 and is a popular server Linux distribution. Debian is also what the Ubuntu OS is based upon and it is just as easy to use with either the command line or any of the desktop environments available. Debian’s biggest draw is its hardware compatibility; it will run on basically any architecture out there. Debian is extremely stable, and you can tweak just about every setting you can imagine. Want to try Debian now? You can spin up versions 8,9,10 and 11 directly from the [Atlantic.Net cloud console](https://cloud.atlantic.net/?page=userlogin). ### ![](https://www.atlantic.net/wp-content/uploads/2021/10/kali-e1638038419427.png)5. Kali Kali Linux is a specialist digital forensics edition of the Linux Kernel and a firm favorite of security professionals and ethical hackers. It’s all about penetration testing and security, with an extensive library of tools built in such as AircrackNG, Metasploit, John the Ripper, Nessus, Nmap, SQLMap, and Wireshark – each designed to spot vulnerabilities in a local attached networked server environment. ### ![](https://www.atlantic.net/wp-content/uploads/2021/10/suse-e1638038470246.png)6. SUSE Linux Founded in 1992, SUSE Linux is a paid Linux distro targeted at enterprise and cloud providers that want to run mission-critical applications with exemplary stability. SUSE is very popular for SAP data processing applications, HA Clustering, and Retail Point of Sale devices. Like Red Hat, SUSE has its own versions of OpenStack, Kubernetes, and containerization tools. ### ![](https://www.atlantic.net/wp-content/uploads/2021/10/arch-linux.png)7. Arch Linux The goal of Arch Linux is to create a fully functioning Linux Distribution with a lightweight footprint that is easy to use. Arch uses the Pac-Man software distribution tool that tracks and maintains its low-profile applications. The end result is a really quick, lightweight operating system that can be tailored to the exact workload needed – there is no excess baggage with Arch Linux. Want to try Arch now? You can spin up Arch Linux 64-bit directly from the [Atlantic.Net cloud console](https://cloud.atlantic.net/?page=userlogin). ### ![](https://www.atlantic.net/wp-content/uploads/2021/10/raspbian.png)8. Raspbian Raspbian (or Raspberry Pi OS as it’s officially known) is a Debian-based OS for the Raspberry Pi for single board ARM CPUs. It is a super lightweight OS design to fit on an 8 GB SD Card. If you own a Raspberry Pi, be sure to check out Raspbian to truly unlock the potential of the Pi. ### ![](https://www.atlantic.net/wp-content/uploads/2021/10/mx-linux-e1638038527961.png)9. MX Linux For those of you looking for a slick desktop experience that rivals the popular Windows 10 experience, check out MX Linux. It’s incredibly easy to use and looks clean and well presented. It comes preloaded with office suites, email clients, photo software, video software, even music players – everything you need, and it’s completely FREE! ### ![](https://www.atlantic.net/wp-content/uploads/2021/10/fedora.png)10. Fedora Fedora is owned by Red Hat, but is a completely free version but almost identical to RHEL in every way. Its GNOME revisions are targeted at users of Windows and macOS who want to break free of the restrictions of proprietary operating systems. It represents a perfect middle ground for the user who wants not only great performance but also access to the latest cross-compatible software. ### ![](https://www.atlantic.net/wp-content/uploads/2021/10/centos.png)What about CentOS? You may be wondering: why we haven’t included CentOS? This is because in 2020 it was announced CentOS Linux is being discontinued and replaced with CentOS Stream, a developer-focused distribution for Fedora and Red Hat Enterprise Linux. As a result, CentOS Linux 8 will go end-of-life on December 31st, 2021. ## ![](https://www.atlantic.net/wp-content/uploads/2021/10/how-can-we-help-e1638038595429.png)How Can Atlantic.Net Help? Are you looking for a leading [hosting provider](https://www.atlantic.net/hosting-services-provider/) to host your Linux Operating System? Look no further than the Atlantic.Net [VPS hosting service](https://www.atlantic.net/vps-hosting/). With over 25 years of proven experience, our [full suite of managed services](https://www.atlantic.net/managed-services/) and always available professional support team can host your mission-critical Linux workload. Our Cloud Platform has many of this Top 10 available as 1-Click applications, meaning you can spin up a fully configured server in about 30 seconds. You can also bring your own license if you want to use SUSE or Red Hat. Our platform is super flexible and built around your needs. For faster application deployment, free IT architecture design, and assessment, visit us at www.atlantic.net, call 866-618-DATA (3282), or email us at [sales@atlantic.net](mailto:sales@atlantic.net). You can find out more information by [contacting our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # How to Install Apache Cassandra on Rocky Linux 8 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-cassandra-on-rocky-linux-8/ | Published: 2021-10-02 | Updated: 2023-11-14 | Author: Hitesh Jethva Apache Cassandra is a free and open-source distributed NoSQL database management system. It is specially designed to handle large amounts of data across many commodity servers. Generally, it is used as a real-time data store for transactional applications and as a read-intensive database. It supports relational databases including MySQL, PostgreSQL, and Microsoft SQL. It is used by many companies that use large data sets including, Instagram, GitHub, Netflix, Reddit, and more. In this guide, we will show you how to install Apache Cassandra on Rocky Linux 8. ## Step 1 – Install Java 8 Apache Cassandra supports Java version 8, so you will need to install OpenJDK 8 to your system. You can install it with other required packages using the following command: ``` dnf install epel-release python2 python2-pip java-1.8.0-openjdk -y ``` Once Java is installed, verify the Java installation using the following command: ``` java -version ``` Sample output: ``` openjdk version "1.8.0_302" OpenJDK Runtime Environment (build 1.8.0_302-b08) OpenJDK 64-Bit Server VM (build 25.302-b08, mixed mode) ``` You will also need to install cqlsh utility to your system. You can install it using the following command: ``` pip2 install cqlsh ``` ## Step 2 – Install Apache Cassandra By default, the Apache Cassandra package is not included in the RockyLinux 8 default repository, so you will need to create a repository for Apache Cassandra. ``` nano /etc/yum.repos.d/cassandra.repo ``` Add the following lines: ``` [cassandra] name=Apache Cassandra baseurl=https://www.apache.org/dist/cassandra/redhat/40x/ gpgcheck=1 repo_gpgcheck=1 gpgkey=https://www.apache.org/dist/cassandra/KEYS ``` Save and close the file, then install the Apache Cassandra with the following command: ``` dnf install cassandra -y ``` ## Step 3 – Create a Service File for Cassandra Next, you will need to create a systemd service file to manage the Apache Cassandra service. You can create it with the following command: ``` nano /etc/systemd/system/cassandra.service ``` Add the following lines: ``` [Unit] Description=Apache Cassandra After=network.target [Service] PIDFile=/var/run/cassandra/cassandra.pid User=cassandra Group=cassandra ExecStart=/usr/sbin/cassandra -f -p /var/run/cassandra/cassandra.pid Restart=always [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes: ``` systemctl daemon-reload ``` Next, start and enable the Cassandra service with the following command: ``` systemctl start cassandra systemctl enable cassandra ``` Next, verify the status of Apache Cassandra with the following command: ``` systemctl status cassandra ``` You should see the following output: ``` ● cassandra.service - Apache Cassandra Loaded: loaded (/etc/systemd/system/cassandra.service; disabled; vendor preset: disabled) Active: active (running) since Wed 2021-09-22 08:07:05 UTC; 603ms ago Main PID: 11515 (cassandra) Tasks: 4 (limit: 11411) Memory: 156.1M CGroup: /system.slice/cassandra.service ├─11515 /bin/sh /usr/sbin/cassandra -f -p /var/run/cassandra/cassandra.pid ├─11584 /bin/sh /usr/sbin/cassandra -f -p /var/run/cassandra/cassandra.pid ├─11588 find /lib64 /lib /usr/lib64 /usr/lib /usr/lib64//bind9-export /lib /lib64 /lib/sse2 /lib64/sse2 /lib64/tls -regex .*/libjem> └─11589 head -n 1 Sep 22 08:07:05 RockyLinux8 systemd[1]: cassandra.service: Service RestartSec=100ms expired, scheduling restart. Sep 22 08:07:05 RockyLinux8 systemd[1]: cassandra.service: Scheduled restart job, restart counter is at 5. Sep 22 08:07:05 RockyLinux8 systemd[1]: Stopped Apache Cassandra. Sep 22 08:07:05 RockyLinux8 systemd[1]: Started Apache Cassandra. ``` ## Step 4 – Verify Apache Cassandra Wait for some time to bring up Apache Cassandra completely, then verify the Apache Cassandra using the following command: ``` nodetool status ``` You should get the following output: ``` Datacenter: datacenter1 ======================= Status=Up/Down |/ State=Normal/Leaving/Joining/Moving -- Address Load Tokens Owns (effective) Host ID Rack UN 127.0.0.1 69.08 KiB 16 100.0% d6672930-2b15-426b-8445-e6f6a2e923f2 rack1 ``` You can also connect to Cassandra with the following command: ``` cqlsh ``` Once you are connected, you should get the following output: ``` Python 2.7 support is deprecated. Install Python 3.6+ or set CQLSH_NO_WARN_PY2 to suppress this message. Connected to Test Cluster at 127.0.0.1:9042 [cqlsh 6.0.0 | Cassandra 4.0.1 | CQL spec 3.4.5 | Native protocol v5] Use HELP for help. cqlsh> ``` ## Step 5 – Change Cassandra Cluster Name In order to change the Cassandra cluster name, connect to the Cassandra with the following command: ``` cqlsh ``` Next, change the cluster name with the following command: ``` cqlsh> UPDATE system.local SET cluster_name = 'Atlantic Cluster' WHERE KEY = 'local'; ``` Next, exit from the Cassandra shell with the following command: ``` cqlsh> exit ``` Next, edit the Apache Cassandra main configuration file: ``` nano /etc/cassandra/default.conf/cassandra.yaml ``` Change the Cassandra cluster name as shown below: ``` cluster_name: 'Atlantic Cluster' ``` Save and close the file, then restart the Apache Cassandra to apply the changes: ``` systemctl restart cassandra ``` Now, verify the Cassandra cluster name with the following command: ``` cqlsh ``` You should get your new cluster name in the following output: ``` Connected to Atlantic Cluster at 127.0.0.1:9042 [cqlsh 6.0.0 | Cassandra 4.0.1 | CQL spec 3.4.5 | Native protocol v5] Use HELP for help. ``` ## Conclusion In the above guide, we explained how to install Apache Cassandra on RockyLinux 8. You can now use Apache Cassandra to handle and manage large data sets. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net today! --- # How to Install Apache Solr on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-solr-on-rocky-linux-10/ | Published: 2021-10-03 | Updated: 2025-10-21 | Author: Hitesh Jethva Apache Solr, also called “Searching On Lucene w/Replication,” is an open-source REST-API-based search platform built on Apache Lucene Framework. It is written in Java Language and designed for scalability and fault tolerance. Generally, it is used for enterprise search and analytics use cases. It has a lot of features including full-text search, hit highlighting, faceted search, real-time indexing, dynamic clustering, database integration, NoSQL features, and rich document handling. It also supports distributed, replication, sharing, clustering, and multi-node architecture. In this post, we will show you how to install Apache Solr on Rocky Linux 10. ## Step 1 – Install Java JDK Apache Solr is written in Java, so Java must be installed on your server. If not installed, you can install it with the following command: ``` dnf install java-21-openjdk -y ``` Once installed, verify the Java version using the following command: ``` java --version ``` You should get the following output: ``` openjdk 21.0.8 2025-07-15 LTS OpenJDK Runtime Environment (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS, mixed mode, sharing) ``` You will also need to install the EPEL repository on your server. You can install it with the following command: ``` dnf install epel-release -y ``` ## Step 2 – Download Apache Solr By default, Apache Solr is not included in the Rocky Linux default repository, so you will need to download it from their official website. You can download it with the following command: ``` wget https://dlcdn.apache.org/solr/solr/9.9.0/solr-9.9.0.tgz ``` **Note: Apache frequently updates SOLR, and you may get an error downloading the above version if it’s been updated since the time of writing. Please check [Apache org](https://downloads.apache.org/lucene/solr/) for the latest versions.** Once Apache Solr is downloaded, download the SHA512 checksum using the following command: ``` wget https://downloads.apache.org/solr/solr/9.9.0/solr-9.9.0.tgz.sha512 ``` Next, calculate the SHA512 checksum of the Apache Solr downloaded file: ``` gpg --print-md SHA512 solr-9.9.0.tgz.sha512 ``` Sample output: ``` solr-9.9.0.tgz.sha512: 15150B7F 191FD9E8 D2C1BD8B B619DD4B 3F27AF2E 0E94B760 9031F7E7 45A2E263 391C30F6 8865C208 AFB97CCA A9BDE6D1 6050200E 9BFCCEF6 5F762C2E D743C242 ``` Next, compare the hash value to the contents of the SHA512 file: ``` cat solr-9.9.0.tgz.sha512 ``` Sample output: ``` 15150b7f191fd9e8d2c1bd8bb619dd4b3f27af2e0e94b7609031f7e745a2e263391c30f68865c208afb97ccaa9bde6d16050200e9bfccef65f762c2ed743c242 *solr-8.9.0.tgz ``` After matching the SHA512 hashes, extract the downloaded file with the following command: ``` tar xzf solr-9.9.0.tgz ``` ## Step 3 – Install Apache Solr First, move the Solr extracted directory to /opt. ``` mv solr-9.9.0 /opt/solr ``` Next, create a dedicated user for Solr. ``` useradd --system --home /opt/solr --shell /bin/bash solr ``` Next, change the ownership of /opt/solr. ``` chown -R solr:solr /opt/solr ``` Next, edit the Solr service file. ``` nano /opt/solr/bin/solr.in.sh ``` Change the following line. ``` SOLR_JETTY_HOST="0.0.0.0" ``` Next, create a systemd service file for Solr. ``` nano /etc/systemd/system/solr.service ``` Add the following lines. ``` [Unit] Description=Apache Solr Service After=network.target [Service] Type=forking User=solr Group=solr ExecStart=/opt/solr/bin/solr start ExecStop=/opt/solr/bin/solr stop ExecReload=/opt/solr/bin/solr restart Restart=on-failure LimitNOFILE=65535 [Install] WantedBy=multi-user.target ``` Next, reload the systemd daemon. ``` systemctl daemon-reload ``` Next, start and enable the Solr service. ``` systemctl enable solr systemctl start solr ``` Next, check the status of Solr. ``` systemctl status solr ``` Output. ``` ● solr.service - Apache Solr Service Loaded: loaded (/etc/systemd/system/solr.service; disabled; preset: disabled) Active: active (running) since Tue 2025-10-21 22:38:51 EDT; 1min 10s ago Invocation: 407b04904cde4b1097a7e7a3945aac80 Process: 25232 ExecStart=/opt/solr/bin/solr start (code=exited, status=0/SUCCESS) Main PID: 25288 (java) Tasks: 44 (limit: 24809) Memory: 674M (peak: 694.4M) CPU: 9.568s CGroup: /system.slice/solr.service └─25288 java -server -Xms512m -Xmx512m -XX:+UseG1GC -XX:+PerfDisableSharedMem -XX:+ParallelRefProcEnabled -XX:MaxGCPauseMillis=250 -XX:+UseLargePages -XX:+AlwaysPreTouch > ``` At this point, Apache Solr is running and listens on port 8983. You can check it with the following command: ``` ss -altnp | grep 8983 ``` Sample output: ``` LISTEN 0 50 *:8983 *:* users:(("java",pid=9970,fd=153)) ``` ## Step 4 – Configure Firewall If a firewalld firewall is installed and running on your server, then you will need to allow port 8983 through firewalld. You can enable it with the following command: ``` firewall-cmd --add-port=8983/tcp --permanent ``` Next, reload the firewall using the following command: ``` firewall-cmd --reload ``` ## Step 5 – Access Apache Solr Before accessing Apache Solr, create a test collection using the following command: ``` su - solr -c "/opt/solr/bin/solr create -c testcollection -n data_driven_schema_configs" ``` Sample output: ``` Created new core 'testcollection' ``` Now, open your web browser and access the Apache Solr web interface using the URL **http://your-server-ip:8983**. You should see the Apache Solr dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/10/s1.png) ## Conclusion Congratulations! You have successfully installed Apache Solr on RockyLinux 10. You can now integrate Apache Solr with your application for search functionality. Get started on a [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net today! --- # How to Install Redmine with Apache and MariaDB on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-redmine-with-apache-and-mariadb-on-rocky-linux-10/ | Published: 2021-10-04 | Updated: 2025-10-23 | Author: Hitesh Jethva Redmine is a free and open-source project management software solution for Linux. It is a web-based issue tracking tool that allows you to manage multiple projects and associated subprojects. It can be integrated with various version control systems and also provides a repository browser. Redmine is written in the Ruby on Rails framework, is cross-platform, and supports 49 languages. It is very useful in daily work for handling tasks like tracking customer complaints, application failure, and project management. In this guide, we will explain how to install the Redmine project management system on Rocky Linux 10. ## Step 1 – Install Apache and MariaDB Database First, you will need to install the Apache webserver and MariaDB database server to your system. You can install them using the following command: ``` dnf update -y dnf install httpd mariadb-server -y ``` Once both packages are installed, start and enable both services with the following command: ``` systemctl start httpd mariadb systemctl enable httpd mariadb ``` ## Step 2 – Create a Database for Redmine Redmine uses MySQL/MariaDB as a database backend, so you will need to create a database and user for Redmine. First, log in to the MariaDB shell with the following command: ``` mysql ``` Once you are logged in, create a database and user with the following command: ``` create database redmine; grant all on redmine.* to redmine@localhost identified by 'securepassword'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` flush privileges; quit; ``` ## Step 3 – Install Redmine Dependencies Next, you will need to install the EPEL repository and other dependencies required for Redmine on your system. First, install the EPEL repo with the following command: ``` dnf install epel-release -y ``` Next, install other required dependencies using the following command: ``` dnf install ruby ruby-devel vim make openssl-devel automake rpm-build wget libxml2-devel libtool ImageMagick ImageMagick-devel mariadb-devel gcc httpd-devel libcurl-devel gcc-c++ -y ``` Once all the dependencies are installed, you can proceed to the next step. ## Step 4 – Install and Configure Redmine First, create a dedicated user for Redmine using the following command: ``` useradd -r -m -d /opt/redmine redmine ``` Next, add a Redmine user to the Apache group with the following command: ``` usermod -a -G redmine apache ``` Next, download the latest version of Redmine with the following command: ``` wget https://www.redmine.org/releases/redmine-5.0.14.tar.gz ``` Next, extract the downloaded file to the /opt with the following command: ``` tar xzf redmine-5.0.14.tar.gz -C /opt/redmine/ --strip-components=1 ``` Next, change the ownership of the /opt/redmine directory to redmine: ``` chown -R redmine:redmine /opt/redmine/ ``` Next, switch the user to redmine with the following command: ``` su - redmine ``` Next, copy all sample configuration files with the following command: ``` cp config/configuration.yml{.example,} cp public/dispatch.fcgi{.example,} cp config/database.yml{.example,} ``` Next, edit the database configuration file: ``` nano config/database.yml ``` Define your database credentials as shown below: ``` production: adapter: mysql2 database: redmine host: localhost username: redmine password: "securepassword" # Use "utf8" instead of "utfmb4" for MySQL prior to 5.7.7 encoding: utf8mb4 ``` Next, edit Gemfile and change Ruby version. ``` nano Gemfile ``` Change the following line: ``` ruby ">= 2.5.0", "< 3.4.0" ``` Next, install webrick. ``` bundle add webrick ``` Next, install required modules with the following command: ``` bundle install --without development test postgresql sqlite ``` Next, generate a secret token with the following command: ``` bundle exec rake generate_secret_token ``` Next, migrate the database with the following command: ``` RAILS_ENV=production bundle exec rake db:migrate ``` ``` RAILS_ENV=production REDMINE_LANG=en bundle exec rake redmine:load_default_data ``` Next, verify the Redmine installation with the following command: ``` bundle exec rails server -u webrick -e production ``` If everything is fine, you should get the following output: ``` => Booting WEBrick => Rails 6.1.7.10 application starting in production http://0.0.0.0:3000 => Run `bin/rails server --help` for more startup options [2025-10-23 07:30:54] INFO WEBrick 1.9.1 [2025-10-23 07:30:54] INFO ruby 3.3.8 (2025-04-09) [x86_64-linux] [2025-10-23 07:30:54] INFO WEBrick::HTTPServer#start: pid=56997 port=3000 ``` Next, press **CTRL+C** to stop the server. Next, install the passenger and apache module with the following command: ``` gem install passenger passenger-install-apache2-module ``` Next, exit from the Redmine user with the following command: ``` exit ``` ## Step 5 – Configure Apache for Redmine Next, you will need to configure Apache for Redmine. First, create a passenger configuration file: ``` nano /etc/httpd/conf.modules.d/00-passenger.conf ``` Add the following lines: ``` LoadModule passenger_module /opt/redmine/.local/share/gem/ruby/gems/passenger-6.1.0/buildout/apache2/mod_passenger.so PassengerRoot /opt/redmine/.local/share/gem/ruby/gems/passenger-6.1.0 PassengerDefaultRuby /usr/bin/ruby ``` Save and close the file, then create an Apache virtual host configuration file for Redmine: ``` nano /etc/httpd/conf.d/redmine.conf ``` Add the following lines: ``` Listen 3000 PassengerRoot /opt/redmine/.local/share/gem/ruby/gems/passenger-6.1.0 PassengerDefaultRuby /usr/bin/ruby ServerName redmine.example.com DocumentRoot "/opt/redmine/public" CustomLog logs/redmine_access.log combined ErrorLog logs/redmine_error_log LogLevel warn Options Indexes ExecCGI FollowSymLinks Require all granted AllowOverride all ``` Save and close the file and change ownership and permissions. ``` chown -R apache:redmine /opt/redmine/ chmod -R 775 /opt/redmine/ ``` Then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 6 – Access Redmine Web UI At this point, Redmine is started and listening on port **3000**. You can access it using the URL **http://redmine.example.com:3000**/. You will be redirected to the following page: ![Redmine welcome page](https://www.atlantic.net/wp-content/uploads/2021/09/p1-10-1024x407.png) Click on the **Sign in** button. You should see the following page: ![Redmine login page](https://www.atlantic.net/wp-content/uploads/2021/09/p2-7-1024x480.png) Provide default username and password as admin/admin and click on the **Login** button. You should see the Redmine password reset screen on the following page: ![Redmine password reset page](https://www.atlantic.net/wp-content/uploads/2021/09/p3-5-1024x490.png) Set your new password and click on the **Apply** button. You should see the Redmine dashboard on the following page: ![Redmine Dashboard](https://www.atlantic.net/wp-content/uploads/2021/09/p4-4-1024x536.png) ## Conclusion Congratulations! You have successfully installed Redmine on RockyLinux 10. You can now track and manage your project easily through the web browser. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Webmin on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-webmin-on-rocky-linux-10/ | Published: 2021-10-05 | Updated: 2025-10-21 | Author: Hitesh Jethva Webmin is a free, open-source, and web-based control panel that allows the system administrators to manage a Linux server from a web browser. It supports a wide range of Linux distributions including Linux, Solaris, FreeBSD, and more. With Webmin, you can do many things including package management, network configuration, and performance monitoring, user account creation, file management, firewall management, and more. It has become a good open-source alternative for cPanel. In this post, we will show you how to install Webmin on Rocky Linux 10. ## Step 1 – Install Webmin By default, Webmin is not included in the RockyLinux default repository, so you will need to install it from the RockyLinux installation script. First, install required packages with the following command: ``` dnf install wget tar perl -y ``` Next, download the latest version of Webmin with the following command: ``` wget https://www.webmin.com/download/webmin-current.tar.gz ``` After downloading Webmin, extract the downloaded file using the following command: ``` tar xvf webmin-current.tar.gz ``` Next, create an installation directory for Webmin. ``` mkdir -p /usr/local/webmin ``` Next, install the Webmin by running the following script: ``` ./webmin-2.520/setup.sh /usr/local/webmin/ ``` During the installation, you will be asked to provide a Webmin port, admin username, and password as shown below: ``` Config file directory [/etc/webmin]: Log file directory [/var/webmin]: *********************************************************************** Webmin is written entirely in Perl. Please enter the full path to the Perl 5 interpreter on your system. Full path to perl (default /usr/bin/perl): Testing Perl ... Perl seems to be installed ok *********************************************************************** Operating system name: Rocky Linux Operating system version: 8.4 *********************************************************************** Webmin uses its own password protected web server to provide access to the administration programs. The setup script needs to know : - What port to run the web server on. There must not be another web server already using this port. - The login name required to access the web server. - The password required to access the web server. - If the webserver should use SSL (if your system supports it). - Whether to start webmin at boot time. Web server port (default 10000): Login name (default admin): Login password: Password again: Use SSL (y/n): n Start Webmin at boot time (y/n): y *********************************************************************** Webmin has been installed and started successfully. Use your web browser to go to http://RockyLinux8:10000/ and login with the name and password you entered previously. ``` By default, Webmin listens on port 10000. You can check it with the following command: ``` ss -antpl | grep 10000 ``` You should see the following output: ``` LISTEN 0 128 0.0.0.0:10000 0.0.0.0:* users:(("miniserv.pl",pid=20906,fd=7)) ``` ## Step 2 – Configure Firewall If the firewalld firewall is installed and running in your server, then you will need to allow port 10000 through the firewalld. You can allow it with the following command: ``` firewall-cmd --add-port=10000/tcp --permanent ``` Next, reload firewalld to apply the changes: ``` firewall-cmd --reload ``` ## Step 3 – Access Webmin Web Interface Now, open your web browser and access the Webmin web interface using the URL **http://your-server-ip:10000**. You will be redirected to the Webmin login page: ![Webmin login page](https://www.atlantic.net/wp-content/uploads/2021/09/p1-9-1024x571.png) Provide your admin username and password and click on the **Sign in** button. You should see the Webmin dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/10/w1.png) Click on the **Tools => Command Shell**. You should see the following page: ![Webmin command shell page](https://www.atlantic.net/wp-content/uploads/2021/09/p3-4-1024x531.png) From here, you can execute any command on your Linux server. Click on the **Tools => File Manager**. You should see the following page: ![Webmin file manager page](https://www.atlantic.net/wp-content/uploads/2021/09/p4-3-1024x529.png) From here, you can create and manage files and directories on your server. Click on the **Tools => Text Login**. You should see the following page: ![Webmin text login page](https://www.atlantic.net/wp-content/uploads/2021/09/p6-2-1024x527.png) From here, you can log in to your server with any user. Click on the **Un-used Modules**. You should see the following page: ![Webmin package installation page](https://www.atlantic.net/wp-content/uploads/2021/09/p7-1-1024x530.png) From here, you can install any package on your server. If you want to uninstall Webmin from your server, run the following script: ``` bash /etc/webmin/uninstall.sh ``` ## Conclusion Congratulations! You have successfully installed Webmin to RockyLinux 10. You can now manage your Linux server easily from the web-based interface – try it on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Apache Maven on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-maven-on-rocky-linux-10/ | Published: 2021-10-06 | Updated: 2025-10-21 | Author: Hitesh Jethva Apache Maven is a free, open-source, and extremely popular build management tool for Java projects. It is based on the Project Object Model and contains XML files to define configuration details, project dependencies, and other data. It is designed to help Java developers build projects by proficiently documenting and reporting important project-related information. **Features** - All configuration is managed from a single XML file. - Easy to test and deploy. - Easy to manage upgrades. - Occupies less space than other project management tools. - Reduces multiple dependencies and eliminates duplicates. In this post, we will show you how to install Apache Maven on Rocky Linux 10. ## Step 1 – Install Maven via AppStream Repository By default, the Maven package is included in the Rocky Linux AppStream repository. You can check it using the following command: ``` dnf info maven ``` You should get the following output: ``` Available Packages Name : maven Epoch : 1 Version : 3.9.9 Release : 1.el10 Architecture : noarch Size : 18 k Source : maven-3.9.9-1.el10.src.rpm Repository : appstream Summary : Java project management and project comprehension tool URL : https://maven.apache.org/ License : Apache-2.0 AND MIT Description : Maven is a software project management and comprehension tool. : Based on the concept of a project object model (POM), Maven can : manage a project's build, reporting and documentation from a : central piece of information. ``` Now, install the Apache Maven using the following command: ``` dnf install maven -y ``` After the installation, verify the Maven version using the following command: ``` mvn --version ``` You should get the following output: ``` Apache Maven 3.9.9 (Red Hat 3.9.9-1) Maven home: /usr/share/maven Java version: 21.0.8, vendor: Red Hat, Inc., runtime: /usr/lib/jvm/java-21-openjdk Default locale: en_US, platform encoding: UTF-8 OS name: "linux", version: "6.12.0-55.21.1.el10_0.x86_64", arch: "amd64", family: "unix" ``` ## Step 2 – Install Maven From Source If you want to install the latest version of Maven then you can install it from the Maven source. First, install the Java package with the following command: ``` dnf install java-21-openjdk -y ``` Once Java is installed, verify the Java version using the following command: ``` java --version ``` Sample output: ``` openjdk 21.0.8 2025-07-15 LTS OpenJDK Runtime Environment (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS, mixed mode, sharing) ``` Next, download the latest version of Maven from their official website: ``` wget https://dlcdn.apache.org/maven/maven-3/3.9.11/binaries/apache-maven-3.9.11-bin.tar.gz ``` Next, create a directory for Apache Maven with the following command: ``` mkdir /usr/local/maven ``` Next, extract the downloaded file to the Maven directory with the following command: ``` tar xzf apache-maven-3.9.11-bin.tar.gz -C /usr/local/maven/ --strip-components=1 ``` Next, you will need to add the Maven binary location to the system path. You can add it with the following command: ``` echo export 'PATH=$PATH:/usr/local/maven/bin/' > /etc/profile.d/maven.sh echo 'export JAVA_HOME=/usr/lib/jvm/java-21-openjdk' >> /etc/profile.d/maven.sh ``` Next, set proper permissions to the maven.sh file with the following command: ``` chmod +x /etc/profile.d/maven.sh ``` Next, activate the Maven system path with the following command: ``` source /etc/profile.d/maven.sh ``` Next, verify the Maven version using the following command: ``` mvn --version ``` You should get the following output: ``` Apache Maven 3.9.9 (Red Hat 3.9.9-1) Maven home: /usr/share/maven Java version: 21.0.8, vendor: Red Hat, Inc., runtime: /usr/lib/jvm/java-21-openjdk Default locale: en_US, platform encoding: UTF-8 OS name: "linux", version: "6.12.0-55.21.1.el10_0.x86_64", arch: "amd64", family: "unix" ``` ## Conclusion In the above guide, we explained how to install Apache Maven on RockyLinux 10 using two methods. You can now use Apache Maven to manage your Java project – try it on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure Elasticsearch on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-elasticsearch-on-rocky-linux-10/ | Published: 2021-10-07 | Updated: 2025-10-26 | Author: Hitesh Jethva Elasticsearch is a free, open-source, distributed search and analytics engine capable of handling a large amounts of data. It is used for real-time full-text searches in applications where a large amount of data needs to be analyzed. It is very popular due to its usability, powerful features, and scalability. It supports RESTful with an HTTP URI to manipulate data. Elasticsearch is easy to use, offering features such as automatic node recovery, improved security, scalability and resiliency, automatic data balancing, and more. In this post, we will show you how to install and configure Elasticsearch on Rocky Linux 10. ## Step 1 – Install Java Elasticsearch is a Java-based application, so Java must be installed on your server. If not installed, you can install it by running the following command: ``` dnf install java-21-openjdk-devel -y ``` After the installation, verify the Java version using the following command: ``` java --version ``` Sample output: ``` openjdk 21.0.8 2025-07-15 LTS OpenJDK Runtime Environment (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS, mixed mode, sharing) ``` ## Step 2 – Create Elasticsearch Repository By default, Elasticsearch is not included in the Rocky Linux default repository, so you will need to create a repository for it. First, download and import the GPG key with the following command: ``` rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch ``` Next, create an Elasticsearch repo with the following command: ``` nano /etc/yum.repos.d/elasticsearch.repo ``` Add the following lines: ``` [elasticsearch] name=Elasticsearch repository for 8.x packages baseurl=https://artifacts.elastic.co/packages/8.x/yum gpgcheck=1 gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch enabled=1 autorefresh=1 type=rpm-md ``` Save and close the file when you are finished. ## Step 3 – Install and Configure Elasticsearch Now, install the Elasticsearch package with the following command: ``` dnf install elasticsearch -y ``` After installing Elasticsearch, edit the Elasticsearch main configuration file: ``` nano /etc/elasticsearch/elasticsearch.yml ``` Change the following lines: ``` cluster.name: my-cluster node.name: rocky # Data paths path.data: /var/lib/elasticsearch path.logs: /var/log/elasticsearch # Bind locally for testing network.host: 127.0.0.1 http.port: 9200 xpack.security.enabled: true xpack.security.http.ssl.enabled: false #cluster.initial_master_nodes: ["rocky"] ``` Save and close the file, then start the Elasticsearch service and enable it to start at system reboot: ``` systemctl start elasticsearch systemctl enable elasticsearch ``` Now, check the status of the Elasticsearch with the following command: ``` systemctl status elasticsearch ``` You should get the following output: ``` ● elasticsearch.service - Elasticsearch Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; disabled; preset: disabled) Active: active (running) since Tue 2025-10-21 04:49:30 EDT; 33s ago Invocation: 0be86d5fa6094c57afcd326ff343cd5a Docs: https://www.elastic.co Main PID: 9012 (java) Tasks: 80 (limit: 24809) Memory: 2.3G (peak: 2.3G) CPU: 46.807s CGroup: /system.slice/elasticsearch.service ├─9012 /usr/share/elasticsearch/jdk/bin/java -Xms4m -Xmx64m -XX:+UseSerialGC -Dcli.name=server -Dcli.script=/usr/share/elasticsearch/bin/elasticsearch -Dcli.libs=lib/tool> ├─9072 /usr/share/elasticsearch/jdk/bin/java -Des.networkaddress.cache.ttl=60 -Des.networkaddress.cache.negative.ttl=10 -XX:+AlwaysPreTouch -Xss1m -Djava.awt.headless=tru> ``` You can now verify Elasticsearch using the following command: ``` curl -X GET 'http://localhost:9200' ``` If everything is fine, you should get the following output: ``` { "name" : "node-1", "cluster_name" : "my-application", "cluster_uuid" : "_na_", "version" : { "number" : "8.19.5", "build_flavor" : "default", "build_type" : "rpm", "build_hash" : "d6dd0417f05cd69706f4f103c69bbb8b7688db9c", "build_date" : "2025-10-03T16:35:50.165700789Z", "build_snapshot" : false, "lucene_version" : "9.12.2", "minimum_wire_compatibility_version" : "7.17.0", "minimum_index_compatibility_version" : "7.0.0" }, "tagline" : "You Know, for Search" } ``` ## Step 4 – How to Use Elasticsearch After installing Elasticsearch, we will need to reset the Elasticsearch default password for the elastic user. Run the below command to reset the password: ``` /usr/share/elasticsearch/bin/elasticsearch-reset-password -u elastic --url http://localhost:9200 ``` You will see the output below. ``` This tool will reset the password of the [elastic] user to an autogenerated value. The password will be printed in the console. Please confirm that you would like to continue [y/N]y Password for the [elastic] user successfully reset. New value: pSzZn-lUl66pWYVALC2W ``` Now, run the following command to test the Elasticsearch API using the password: ``` curl -u elastic:pSzZn-lUl66pWYVALC2W -k http://127.0.0.1:9200 ``` Sample output: ``` { "name" : "rocky", "cluster_name" : "elasticsearch", "cluster_uuid" : "LyC76-Z8Tk6mSYQFQwPyKw", "version" : { "number" : "8.19.6", "build_flavor" : "default", "build_type" : "rpm", "build_hash" : "d2c42d91a1eb9e14b1a37c4d87eb2533ec859e2b", "build_date" : "2025-10-21T22:05:27.062491219Z", "build_snapshot" : false, "lucene_version" : "9.12.2", "minimum_wire_compatibility_version" : "7.17.0", "minimum_index_compatibility_version" : "7.0.0" }, "tagline" : "You Know, for Search" } ``` ## Conclusion In the above guide, you learned how to install and use Elasticsearch on Rocky Linux 10. You can now use Elasticsearch with other tools, such as Kibana and Logstash to search and display data via a graphical interface. Start using Elasticsearch on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install Craft CMS with Nginx on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-craft-cms-with-nginx-on-rocky-linux-10/ | Published: 2021-10-09 | Updated: 2025-10-21 | Author: Hitesh Jethva Craft CMS is a free and open-source content management system written in PHP and built on the Yii framework. It is designed for website owners who want more control and more powerful performance from their CMS. It is secure, scalable, and provides a lot of plugins that allow you to add more functionality to your website. Craft CMS offers an intuitive, user-friendly control panel for content creation and administrative tasks. In this step-by-step guide, we will show you how to install Craft CMS with Nginx on Rocky Linux 10. ## Step 1 – Install Nginx, PHP and MariaDB First, you will need to install the Nginx web server, MariaDB database, PHP, and other required extensions to your server. You can install all of them using the following command: ``` dnf install nginx mariadb-server php php-cli php-fpm php-common php-bcmath php-curl php-gd php-json php-mbstring php-mysqli php-pgsql php-zip php-intl php-xml php-pdo -y ``` After installing all the packages, edit the php.ini file and change some recommended settings: ``` nano /etc/php.ini ``` Change the following settings: ``` memory_limit = 256M date.timezone = Asia/Kolkata ``` Save and close the file, then edit the php-fpm configuration file and change user and group from apache to nginx: ``` nano /etc/php-fpm.d/www.conf ``` Change the following lines: ``` user = nginx group = nginx ``` Save and close the file, then start the Nginx, MariaDB and PHP-FPM services and enable them to start at system reboot: ``` systemctl start nginx mariadb php-fpm systemctl enable nginx mariadb php-fpm ``` ## Step 2 – Create a Database and User Next, you will need to create a database and user for Craft CMS. First, log in to MySQL with the following command: ``` mysql ``` Once you are logged in, create a database and user with the following command: ``` create database craftdb; grant all on craftdb.* to craftuser@localhost identified by 'securepassword'; ``` Next, flush the privileges and exit from MariaDB with the following command: ``` flush privileges; quit; ``` ## Step 3 – Install Composer Composer is a dependency manager for PHP used for resolving PHP dependencies for your project. First, download the Composer setup PHP file with the following command: ``` php -r "copy('https://getcomposer.org/installer', 'composer-setup.php');" ``` Next, fetch the Composer Hash value and match it with the downloaded file: ``` HASH="$(wget -q -O - https://composer.github.io/installer.sig)" php -r "if (hash_file('SHA384', 'composer-setup.php') === '$HASH') { echo 'Installer verified'; } else { echo 'Installer corrupt'; unlink('composer-setup.php'); } echo PHP_EOL;" ``` If everything is fine, you should get the following output: ``` Installer verified ``` Next, run the following command to install Composer to your system: ``` php composer-setup.php --install-dir=/usr/local/bin --filename=composer ``` Once Composer is installed, verify the Composer version using the following command: ``` composer -V ``` You should get the following output: ``` Composer version 2.1.8 2021-09-15 13:55:14 ``` ## Step 4 – Install Craft CMS First, navigate to the Nginx web root directory and download the latest version of Craft CMS using Composer: ``` cd /var/www/html/ composer create-project craftcms/craft craft ``` During the installation, you will be asked to provide database credentials, admin username, password, and Craft URL as shown below: ``` > @php craft setup/welcome ______ .______ ___ _______ .___________. / || _ \ / \ | ____|| | | ,----'| |_) | / ^ \ | |__ `---| |----` | | | / / /_\ \ | __| | | | `----.| |\ \----./ _____ \ | | | | \______|| _| `._____/__/ \__\ |__| |__| A N E W I N S T A L L ______ .___ ___. _______. / || \/ | / | | ,----'| \ / | | (----` | | | |\/| | \ \ | `----.| | | | .----) | \______||__| |__| |_______/ Generating an application ID ... done (CraftCMS--be1f09c9-cd35-4bfe-a01b-d611282eea19) Generating a security key ... done (HaBt-G01s1pwVPNXmb1iAQZDI0M1lpuh) Welcome to Craft CMS! Are you ready to begin the setup? (yes|no) [no]:yes Generating an application ID ... done (CraftCMS--f06f8153-f389-4603-97b7-c683b8cd422d) Which database driver are you using? [mysql,pgsql,?]: mysql Database server name or IP address: [127.0.0.1] Database port: [3306] Database username: [root] craftuser Database password: Database name: craftdb Database table prefix: Testing database credentials ... success! Saving database credentials to your .env file ... done Install Craft now? (yes|no) [yes]:yes Username: [admin] Email: admin@example.com Password: Confirm: Site name: mysite Site URL: http://craft.example.com Site language: [en-US] installed Craft successfully (time: 6.230s) Generating project config files from the loaded project config ... done ``` Next, change the ownership of Craft CMS directory and PHP session directory to Nginx: ``` chown -R nginx:nginx /var/www/html/craft chown -R nginx:nginx /var/lib/php/session ``` ## Step 5 – Configure Nginx for Craft CMS Next, you will need to create an Nginx virtual host configuration file for Craft CMS. You can create it with the following command: ``` nano /etc/nginx/conf.d/craft.conf ``` Add the following configuration: ``` server { listen 80; server_name craft.example.com; root /var/www/html/craft/web; index index.php; location / { try_files $uri/index.html $uri $uri/ /index.php?$query_string; } location ~ [^/]\.php(/|$) { try_files $uri $uri/ /index.php?$query_string; fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_pass unix:/run/php-fpm/www.sock; fastcgi_index index.php; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_param PATH_INFO $fastcgi_path_info; fastcgi_param HTTP_PROXY ""; } } ``` Save the file, then verify the Nginx configuration using the following command: ``` nginx -t ``` You should get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Please note if you get this warning message : ``` nginx: [emerg] could not build server_names_hash, you should increase server_names_hash_bucket_size: 32 nginx: configuration file /etc/nginx/nginx.conf test failed ``` You must edit the /etc/nginx.nginx.conf file and add this line before the server block: ``` server_names_hash_bucket_size 64; ``` Finally, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 6 – Access Craft CMS Now, open your web browser and access the Craft CMS website using the URL **http://craft.example.com**. You should see the following screen: ![Craft Welcome page](https://www.atlantic.net/wp-content/uploads/2021/09/p1-7-1024x562.png) Click on **Go to your control panel**. You will be redirected to the Craft CMS login page: ![Craft login page](https://www.atlantic.net/wp-content/uploads/2021/09/p2-5-1024x546.png) Provide your admin username and password and click on the **Login** button. You should see the Craft CMS dashboard on the following screen: ![Craft dashboard page](https://www.atlantic.net/wp-content/uploads/2021/09/p3-3-1024x533.png) ## Conclusion That’s it for now. You have successfully installed Craft CMS with Nginx on RockyLinux 10. You can start developing your website easily from the Craft CMS dashboard. Try it out on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install Jenkins on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-jenkins-on-rocky-linux-10/ | Published: 2021-10-10 | Updated: 2025-10-21 | Author: Hitesh Jethva Jenkins is an open-source, widely used automation software tool. It is used in the software development life cycle to build, test, and deploy code automatically. Jenkins is written in Java and allows you to automate a series of tasks in order to complete the continuous integration process. It provides a simple and user-friendly web interface that allows you to manage complicated tasks through a web-based dashboard. In this post, we will show you how to install Jenkins on Rocky Linux 10. ## Step 1 – Install Java Jenkins is a Java-based tool, so Java must be installed on your server. If not installed, you can install it using the following command: ``` dnf update -y dnf install java-21-openjdk -y ``` Once Java is installed, verify the Java version using the following command: ``` java --version ``` Sample output: ``` openjdk 21.0.8 2025-07-15 LTS OpenJDK Runtime Environment (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS, mixed mode, sharing) ``` ## Step 2 – Add Jenkins Repository By default, Jenkins is not included in the RockyLinux 8 default repository, so you will need to create a Jenkins repo to your system. You can create it using the following command: ``` wget -O /etc/yum.repos.d/jenkins.repo https://pkg.jenkins.io/redhat-stable/jenkins.repo ``` Next, download and import the Jenkins GPG key with the following command: ``` rpm --import https://pkg.jenkins.io/redhat-stable/jenkins.io-2023.key ``` Next, verify the Jenkins repo using the following command: ``` dnf repolist ``` Sample output: ``` repo id repo name appstream Rocky Linux 8 - AppStream baseos Rocky Linux 8 - BaseOS extras Rocky Linux 8 - Extras jenkins Jenkins-stable ``` ## Step 3 – Install Jenkins Now, you can install Jenkins using the following command: ``` dnf install jenkins --nobest ``` Once Jenkins is installed, start Jenkins and enable it to start at system reboot: ``` systemctl start jenkins systemctl enable jenkins ``` You can now check the status of Jenkins using the following command: ``` systemctl status jenkins ``` Sample output: ``` ● jenkins.service - Jenkins Continuous Integration Server Loaded: loaded (/usr/lib/systemd/system/jenkins.service; disabled; preset: disabled) Active: active (running) since Tue 2025-10-21 04:29:07 EDT; 1s ago Invocation: 0ba640a170924d408d8a1b55cf3483b1 Main PID: 8151 (java) Tasks: 45 (limit: 24809) Memory: 543.9M (peak: 547.8M) CPU: 14.293s CGroup: /system.slice/jenkins.service └─8151 /usr/bin/java -Djava.awt.headless=true -jar /usr/share/java/jenkins.war --webroot=/var/cache/jenkins/war --httpPort=8080 Oct 21 04:29:03 rocky jenkins[8151]: [LF]> 1ddc7300ded0478ebe5bb045b587fe12 Oct 21 04:29:03 rocky jenkins[8151]: [LF]> Oct 21 04:29:03 rocky jenkins[8151]: [LF]> This may also be found at: /var/lib/jenkins/secrets/initialAdminPassword Oct 21 04:29:03 rocky jenkins[8151]: [LF]> Oct 21 04:29:03 rocky jenkins[8151]: [LF]> ************************************************************* Oct 21 04:29:03 rocky jenkins[8151]: [LF]> ************************************************************* Oct 21 04:29:03 rocky jenkins[8151]: [LF]> ************************************************************* Oct 21 04:29:07 rocky jenkins[8151]: 2025-10-21 08:29:07.677+0000 [id=38] INFO jenkins.InitReactorRunner$1#onAttained: Completed initialization Oct 21 04:29:07 rocky jenkins[8151]: 2025-10-21 08:29:07.695+0000 [id=30] INFO hudson.lifecycle.Lifecycle#onReady: Jenkins is fully up and running Oct 21 04:29:07 rocky systemd[1]: Started jenkins.service - Jenkins Continuous Integration Server. ``` By default, Jenkins listens on port 8080. You can verify it with the following command: ``` ss -antpl | grep 8080 ``` Sample output: ``` LISTEN 0 50 *:8080 *:* users:(("java",pid=5129,fd=135)) ``` ## Step 4 – Configure Nginx as a Reverse Proxy for Jenkins It is recommended to install and configure Nginx as a reverse proxy for Jenkins. First, install the Nginx web server with the following command: ``` dnf install nginx -y ``` After installing Nginx, create an Nginx configuration file for Jenkins: ``` nano /etc/nginx/conf.d/jenkins.conf ``` Add the following lines: ``` upstream jenkins { server 127.0.0.1:8080 fail_timeout=0; } server { listen 80; server_name jenkins.example.com; location / { proxy_set_header Host $host:$server_port; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_pass http://jenkins; # Required for new HTTP-based CLI proxy_http_version 1.1; proxy_request_buffering off; proxy_buffering off; # Required for HTTP-based CLI to work over SSL } } ``` Save and close the file when you are finished. Next, verify Nginx for any syntax error: ``` nginx -t ``` Sample output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Please note if you get this warning message : ``` nginx: [emerg] could not build server_names_hash, you should increase server_names_hash_bucket_size: 32 nginx: configuration file /etc/nginx/nginx.conf test failed ``` You must edit the /etc/nginx.nginx.conf file and add this line before the server block: ``` server_names_hash_bucket_size 64; ``` Finally, start the Nginx service and enable it to start at system reboot: ``` systemctl start nginx systemctl enable nginx ``` ## Step 5 – Access Jenkins Dashboard Now, you can access the Jenkins web interface using the URL **http://jenkins.example.com** from the web browser. You should see the following screen: ![Jenkins initial password](https://www.atlantic.net/wp-content/uploads/2021/09/p1-6-1024x583.png) Now, open your terminal and retrieve the Jenkins setup password using the following command: ``` cat /var/lib/jenkins/secrets/initialAdminPassword ``` Sample output: ``` 24934e3f8d7e453a92f99c3439f21f8a ``` Now, paste the above password and click on the **Continue** button. You should see the following screen: ![Jenkins install plugins](https://www.atlantic.net/wp-content/uploads/2021/09/p2-4-1024x620.png) Now, select **‘Install using suggested plugins‘** or **‘Select plugins to install‘**. You should see the following screen: ![Jenkins create admin user](https://www.atlantic.net/wp-content/uploads/2021/09/p3-2-1024x616.png) Now, provide your admin user information and click on the **Save and Continue** button. You should see the following screen: ![Jenkins provide website URL](https://www.atlantic.net/wp-content/uploads/2021/09/p4-2-1024x600.png) Now, provide your Jenkins URL and click on the **Save and Finish** button. You should see the following screen: ![Jenkins installed](https://www.atlantic.net/wp-content/uploads/2021/09/p5-1024x630.png) Click on the **Start Using Jenkins**. You should see the Jenkins Dashboard on the following screen: ![Jenkins Dashboard](https://www.atlantic.net/wp-content/uploads/2021/09/p6-1-1024x539.png) ## Conclusion Congratulations! You have successfully installed Jenkins with Nginx as a reverse proxy on RockyLinux 10. You can now implement Jenkins in your development environment and automate the development process. Get started with Jenkins today on a [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # ​​Fight the Phish > URL: https://www.atlantic.net/hipaa-compliant-hosting/fight-the-phish/ | Published: 2021-10-11 | Updated: 2026-05-03 | Author: Richard Bailey Phishing is still the number one cause of data breaches and theft of personal information. If anything, the Covid-19 pandemic has reinforced this view, as there has been a huge rise in reported phishing incidents directly related to Covid. It’s difficult to put exact figures on the surge, but most sources quote around a [200% increase](https://www.f5.com/company/blog/phishing-attacks-soar-220--during-covid-19-peak-as-cybercriminal); one Canadian company, [CGI](https://www.cgi.com/uk/en-gb/blog/cyber-security/helping-defend-against-a-30000-increase-in-phishing-attacks-related-to-covid-19-scams), reported a massive 30,000% increase in Covid related malware, weaponized websites, and phishing emails. Phishing is not a new phenomenon. It has been used to steal personal information ever since the Internet went mainstream in the early 1990s. One of the earliest recorded phishing scams [targeted AOL users](https://enterprise.verizon.com/resources/articles/s/the-history-of-phishing/#:~:text=The%20first%20phish,passwords%20and%20hijack%20their%20accounts.). Cybercriminals reportedly impersonated AOL employees requesting their dial-up credentials. People’s perception of online security was completely different back then, and countless credentials were offered up and then sold on the black market. One of the most notorious phishing campaigns was called the LoveBug, sometimes known as ILOVEYOU. The malware was disguised inside a VBS script pretending to be a love letter email. Once opened, the malware encrypted local files and then emailed itself to all your Outlook contacts. It was very crude compared to today’s standards, but it caused millions of dollars of damage and forced businesses to rebuild infected computer systems. ## What Is Phishing? It’s highly likely that you have already heard of phishing and that you understand the basic principles of what phishing is. Awareness of phishing has grown rapidly in recent years because of the significant impact it is having on businesses and individuals. If you work in an office, it’s likely your company has rolled out a cybersecurity training program to help combat phishing. Despite this increased awareness, we still have a long way to go when it comes to preventing phishing. Cybercriminals are exploiting phishing techniques to trick people into disclosing sensitive personal information or into downloading malicious malware payloads from fake websites. The most common attack vector is a phishing campaign over email, but phishing can also happen over the phone, via text message, through social media, and so on. But what can you do to protect yourself in today’s interconnected world? ## Make Yourself a Hard Target Controlling the information that you share about yourself is a great start to controlling your privacy and limiting your digital footprint. Anyone who uses a computer online leaves a digital signature, history, and information about themselves. Often this is intentional, but other times others may inadvertently share information about you. Social media is known to harvest huge amounts of data about its users and leaves a detailed history of your personal habits, places you visit, and things that you like. Have you ever downloaded the information Facebook keeps on you? [Give it a try](http://www.facebook.com/help/212802592074644/?helpref=uf_share); you may be surprised. Your personal data is out there and available, so take time to review your privacy settings and delete social media accounts you no longer use. Check the privacy settings on your cell phone and always be on the lookout for suspicious emails, texts, and phone calls. Remember: never divulge sensitive information, and always think twice when answering an unrecognized phone number. ## Phishing Has Become Harder to Spot Phishing emails are getting more sophisticated as the rewards from the successes line the pockets of cybercriminals. Times have changed significantly since the ILOVEYOU malware was distributed; attacks are now coordinated, and hackers are using stolen personal information from data breaches to target individuals. The idea is that if the hacker has some correct information, you may be more likely to provide even more personal information. Bogus emails now look identical to the real thing, and there are some in circulation that look identical to legitimate emails. There are still several phishing attempts that are borderline amusing, littered with spelling mistakes, outrageous claims, or promises of lost riches and fortunes. However, there are still some tell-tale signs to be on the lookout for, so always think twice before clicking an embedded hyperlink or replying with personal data: - Is the email addressed directly to you? Or to a “valued customer,” “friend,” or “fellow citizen?” This is a tell-tale sign of a scam. - Spelling mistakes - Low-quality graphic design - Do the emails prompt for an “urgent response?” - Are you being asked for personal information, bank details, social security numbers, etc? If you are asked to provide information via email, alarm bells should sound, as no legitimate company will ask you to validate your data on email. Check the official website or phone the advertised number to make sure. ## Technical Solutions to Combat Phishing For businesses and organizations, the ability to combat phishing is rapidly becoming a mandatory business requirement. Customers expect [robust security frameworks](https://www.atlantic.net/hipaa-compliant-hosting/how-to-best-mitigate-cybersecurity-risks-and-protect-your-data/) and technical solutions to counteract phishing. Businesses are allocating much bigger budgets to target cybercriminal activity. One of the best ways to up your cybersecurity is to partner with a security-focused hosting provider. We expect outsourcing cloud security-as-a-service to increase in popularity throughout 2021. Outsourcing will help to reduce the impact of phishing, ransomware, and other malware attacks, but it will also tackle the problem many organizations face with having a lack of IT experts available to secure their cloud environment. Other benefits include a lesser chance of accidental information sharing by employees and fewer mistakes being made by system administrators thanks to additional managed services. Systems and controls can be introduced to limit the chance of data theft by employees (the insider threat), such as an added emphasis on endpoint device protection. Training employees is essential, and additional training should be offered to high-risk employees such as executives, finance, and IT professionals. Despite growing awareness of phishing, certain demographics are vulnerable, in particular the elderly and 18-to-29-year-olds. [Research](https://lorrie.cranor.org/pubs/pap1162-sheng.pdf) has shown that educating users about phishing is the most effective tool to combat it. What else can be done? - Create a strong and enforceable password policy - Use [multifactor authentication](https://www.atlantic.net/managed-services/multi-factor-authentication/) (MFA) - Patch your servers - Patch your applications - Never use deprecated Operating Systems such as Windows Server 2008 R2 - Monitor everything - Use an [Intrusion Detection System](https://www.atlantic.net/managed-services/intrusion-detection-service/)  (IDS)  to ensure that network traffic is closely monitored - Monitor TLS connections inbound and outbound - Block all ports apart from those absolutely necessary on the firewall ## How can Atlantic.Net help? Atlantic.Net has over 30 years of experience providing high-end hosting solutions that are built to exacting security standards. Our platform gives our customers the best chance to combat cybersecurity issues. Our network and platform are segregated, meaning that even if someone manages a successful phish, it would be impossible for the hacker to traverse our network as the design prevents that possibility. Any issue would be isolated at the source. [Cloud platforms](https://www.atlantic.net/cloud-platform/) are very secure and offer highly durable and robust services; the biggest problem is user misconfiguration or users clicking on phishing links. When leveraging cloud services, the shared responsibility model comes into play. Atlantic.Net is responsible for protecting data, applications, infrastructure, and physical protections, but the customer is responsible for managing users. If you are a healthcare provider, it is vital that you consider a fully audited [HIPAA-compliant server infrastructure](https://www.atlantic.net/hipaa-compliant-hosting/) for your organization. To find out more about the solutions that we offer, [contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! *A brief version of this article was also published on HealthITanswers.com.* --- # How to Install WordPress with SlickStack on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-wordpress-with-slickstack-on-ubuntu-20-04/ | Published: 2021-10-12 | Updated: 2024-06-30 | Author: Hitesh Jethva Many applications enable automation and configuration management, including Ansible, Puppet, and Chef. However, all those applications require in-depth knowledge and a lot of configuration to implement in a production environment. This is where SlickStack comes into the picture. SlickStack provides an easy-to-use shell script to deploy the modern web stack. SlickStack is a free and open-source LEMP stack automation script created by LittleBizzy. It simplifies the installation of WordPress and other PHP-based CMS software with a single command. You can use SlickStack to set up a lightning-fast WordPress site. SlickStack takes care of all modern SEO specs and optimizes scores in GTMetrix, SSL Labs, Security Headers, Google PageSpeed Insights, and more. SlickStack script will install the following modules: - WordPress - Nginx - OpenSSL or Let’s Encrypt SSL - MySQL - PHP-FPM - Redis - Adminer - Postfix - ClamAV - UFW Firewall In this post, we will show you how to install WordPress with SlickStack on Ubuntu 20.04. ## Install WordPress with SlickStack You can run the following command to install SlickStack with WordPress and Nginx FastCGI Cache. cd /tmp/ && wget -O ss slick.fyi && bash ss This command will run the SlickStack script and launch the setup wizard as shown below: ``` welcome to the magical world of ss where all your dreams come true _____________________________ < screw containers! excelsior > -----------------------------        \   ^__^         \  (oo)\_______            (__)\       )\/\                ||----w |                ||     || ################################################################################ SlickStack build   :  SEP2021MM Ubuntu version     :  20.04 LTS Hostname (FQDN)    :  ubuntu2004 IP Address (IPv4)  :  104.219.55.50 IP Address (IPv6)  :  fe80::200:68ff:fedb:3732 ################################################################################ Welcome to SlickStack! It appears that your ss-config file has not been setup yet. Please use the wizard to configure required options, or hit Ctrl+C to cancel wizard and configure ss-config manually:  1 #### SlickStack Interactive Setup Wizard (SS-Config) ###################### ########################################################################### Choose sudo username (for SSH): batman Choose sudo password (should be strong): 36977ae8d23eef73db21a4c2 Choose SSH port (use 22 for best compatibility): 22 Enable SSH keys (advanced users only): false Choose SFTP username (limited access): robin Choose SFTP password (should be strong): a44750d7958c44ca33e5f68d Choose app (only wordpress supported currently): wordpress Enable the WordPress plugin blacklist: true Link to your pilot file (leave blank if none): Are you using a remote database: false Choose database name (single database): production Choose database user (non-root user): robin Choose database user password (should be strong): aad9c63bec8ea492fef9002f Choose database host (IP address): 127.0.0.1 Choose database table prefix: wp_ Choose site TLD (subdomains not allowed): linuxbuz.com Choose site domain (subdirectories not allowed): wp.linuxbuz.com Enable site noindexing (block robots): false Choose SSL cert [openssl|certbot]: openssl Choose Cloudflare API key (account profile): your-cloudflare-api-key Choose Cloudflare API email (account profile): hitjethva@gmail.com Enable staging site (subdomain): false Password protect staging site: false Enable dev site (subdomain): false Password protect dev site: false Choose guest username (to view staging/dev): guest Choose guest password (easy is fine): a6fcba50cdb32c2ad9daf67e ``` Provide all configuration options and hit Enter. Once the installation has been completed, you should see the following output: ``` ########################################################################### #### Congrats! Here are your current SlickStack settings: ################# ########################################################################### SlickStack build: SEP2021MM IPv4: 104.219.55.50 IPv6: fe80::200:68ff:fedb:3732 Site TLD: linuxbuz.com Site domain: https://wp.linuxbuz.com Site noindex: false Staging site: false Dev site: false Sudo user: batman Sudo password: 36977ae8d23eef73db21a4c2 SFTP user: robin SFTP password: a44750d7958c44ca33e5f68d SSH/SFTP port: 22 SSH keys: false DB name: production DB user: robin DB user password: aad9c63bec8ea492fef9002f DB admin user: admin@127.0.0.1 DB admin user password: ec3d77980c6fa9d44d561327 DB host: 127.0.0.1 DB prefix: wp_ WP Multisite: false WP Multisite subdomains: true WP Multisite domain mapping: false CloudFlare API key: api-key CloudFlare API email: user@gmail.com ``` SlickStack will save all settings in the ss-config file located at /var/www. You can check it with the following command: ``` cat /var/www/ss-config ``` ## Access WordPress Installation Now, open your web browser and access the WordPress installation using the URL install wp admin. You should see the WordPress language selection screen: ![](https://www.atlantic.net/wp-content/uploads/2021/10/SlickStack-WP-1.png) Select your language and click on the Continue. You should see the WordPress site configuration screen: ![](https://www.atlantic.net/wp-content/uploads/2021/10/SlickStack-WP-2.png) Provide your site name, admin username, password, and email, and click on Install WordPress. Once the installation has been completed, you should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/10/SlickStack-WP-3.png) Click on the Log In button. You should see the WordPress login screen: ![](https://www.atlantic.net/wp-content/uploads/2021/10/SlickStack-WP-4.png) Provide your admin username and password and click on Log In. You should see the WordPress dashboard on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/10/SlickStack-WP-5.png) In the left pane, click on the SlickStack. You can see the SlickStack Settings on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/10/SlickStack-WP-6.png) Click on the SFTP tab. You should see the SFTP Settings on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/10/SlickStack-WP-7.png) Click on the Adminer tab. You should see the Adminer Settings on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/10/SlickStack-WP-8.png) Click on the Caching tab. You should see the Cache Settings on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/10/SlickStack-WP-9.png) You can also access the Adminer using the URL https://wp.linuxbuz.com/adminer?. You should see the Adminer login screen: ![](https://www.atlantic.net/wp-content/uploads/2021/10/SlickStack-Adminer-1.png) Provide your Adminer username, password and click on the Login button. You should see the Adminer dashboard on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/10/SlickStack-Adminer-2.png) To perform the SSL test for your website. Open the [Wormly SSL Test](https://www.wormly.com/test_ssl) and test your website as shown below: ![](https://www.atlantic.net/wp-content/uploads/2021/10/SlickStack-SSL-Test-1.png) ![](https://www.atlantic.net/wp-content/uploads/2021/10/SlickStack-SSL-Test-2.png) ## Conclusion In the above guide, we explained how to install WordPress CMS with SlickStack installation script. This script will help you to simplify the WordPress installation, provisioning, and security on your [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) account from Atlantic.Net. --- # Major SMS Company Hacked > URL: https://www.atlantic.net/hipaa-compliant-hosting/major-sms-company-hacked/ | Published: 2021-10-13 | Updated: 2024-10-31 | Author: Richard Bailey *Atlantic.Net is providing this security advisory as a news item. We want to reassure our customers that Atlantic.Net does not use any of these exploited products internally or in any of our service offerings.* On 27th September 2021, U.S. telecom giant Syniverse filed to the U.S. Security and Exchange Commission that they had been hacked. There is a good chance that you have never heard of Syniverse, but if you live in the United States and you have a cell phone, it’s extremely likely that your SMS data flows through Syniverse systems. ## About the Attack on Syniverse Syniverse provides backbone telecoms services between the major telecoms providers, their services allow each network to talk to one another. Their service links providers in the U.S., Europe, and Asia. Syniverse [revealed](https://www.vice.com/en/article/z3xpm8/company-that-routes-billions-of-text-messages-quietly-says-it-was-hacked) that “an individual or organization gained unauthorized access to databases within its network on several occasions, and that login information allowing access to or from its Electronic Data Transfer (EDT) environment was compromised for approximately 235 of its customers.” ## Who Was Affected and How? In the U.S. we know that Syniverse processes SMS data for AT&T, T-Mobile, and Verizon. In Europe, they are used by Vodafone, and in Asia, China Mobile. It’s likely they process data for many smaller carriers as well. Astoundingly, it appears that this hack went on for **five** years. We don’t know what data has been stolen in the breach, but the website [vice.com](https://www.vice.com/en/article/z3xpm8/company-that-routes-billions-of-text-messages-quietly-says-it-was-hacked) reported that former Syniverse employees advised that Syniverse processes metadata about the length and cost of calls, the sender and receiver numbers, their location, and the content of the SMS message. The biggest concern here is that this hack lasted for over five years; evidence found on the [SEC.gov website (page 69)](https://www.sec.gov/Archives/edgar/data/1839175/000119312521284329/d234831dprem14a.htm) states that the hack started way back in May 2016! Syniverse has notified the companies that they are contractually required to, but this approach has been criticized, as such a potentially large hack has been very quietly released to the public. As of yet, there has been no mention of the breach on the Syniverse website; the only evidence is the sec.gov official filing. Syniverse states that there is no evidence that data has been misappropriated, but the filing warns that future impact from the fallout of this hack is possible. It is clear that Syniverse is concerned about its public image, financial damage, and the adverse impact on “[Syniverse’s overall strategy to be a leading provider of technology solutions to the wireless ecosystem](https://www.sec.gov/Archives/edgar/data/1839175/000119312521284329/d234831dprem14a.htm).” ## Is the Problem Fixed? Syniverse stated on the filing that they have fixed and remediated the issue that allows hackers to gain access, but we don’t know what the attack vector was. It’s possible it was a server or application exploit, or an unsecured public asset, such as a cloud storage bucket. Syniverse has publicly stated that it must “strive to update its legacy IT infrastructure and existing operations,” suggesting that the existing infrastructure is old and not fit for purpose. Perhaps this is how access has been gained? ## Why Is This Hack Important? There are a lot of lessons that can be learned from the Syniverse hack. They have been universally criticized about their handling of the incident, only notifying the carriers and not the customer impacted. There has been no official announcement via the company website, and a general feeling like the company has been trying to keep things quiet and play down the impact of the hack. You may think that SMS is an outdated service, being rapidly replaced with services like WhatsApp and Messenger. The breach is reported to contain phone call metadata too, potentially huge news because it could contain the private information about billions of phone called made in the last 5 years. Next is the fact that they remained breached for 5 years, and using the dates in their report, that’s 1975 days! Now consider what SMS is used for; lots of multifactor authentication services use SMS such as Azure Active Directory. Some businesses even send account reset URLs direct to an SMS message, and clicking on the link gives you access to the site. ## What Can You Do to Protect Yourself? The first recommendation we offer is to review your multifactor solution. Most providers will offer an alternative to SMS, such as an app like Authy or phone call authentication. The next best line of defense is to team up with a Managed Service Provider like Atlantic.Net that has the manpower to overcome and patch these attacks. Atlantic.Net has 30 years of experience in providing security-defined, hardened, and robust managed services for our customers. Syniverse has already stated that their infrastructure is out-of-date and that they are in urgent need of digital transformation. Let us manage your server infrastructure. We will take care of all your security patching requirements on top of the day-to-day upkeep of the cloud platform. Hackers gain access to systems when they are inadequately protected, and the best way to find if you are vulnerable is by performing vulnerability scanning. This technique tests the external and internal computer infrastructure against all known vulnerabilities. Atlantic.Net systems are tested for weakness often, and our team can recommend some of our trusted partners to test your systems directly with penetration testing.  In a situation like this, it is best to ensure that you are taking advantage of all best-known security practices to minimize any exposure to zero-day exploits. If your business is concerned about cybersecurity, please feel welcome to reach out to Atlantic.Net. We are specialists in Managed Services, Cloud Hosting, and HIPAA compliance. Security of our infrastructure is of paramount importance, and we work hard to ensure we have the best security processes in place.  Atlantic.Net has a full suite of Managed Security Services to help be proactive and prepare in advance for any security issues. Get in touch today. ## HIPAA Compliant Hosting with Atlantic.Net Contracting with Atlantic.Net for [HIPAA-compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) gives you peace of mind that your provider knows what they’re doing. Atlantic.Net is SOC 2, SOC 3, HIPAA audited, and PCI ready and provides clients with the hardened, secure, and compliant infrastructure they need. --- # How to Install GitLab on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-gitlab-on-rocky-linux-10/ | Published: 2021-10-14 | Updated: 2025-10-21 | Author: Hitesh Jethva GitLab is a free, open-source, and web-based Git repository manager and DevOps tool. It comes with a lot of features including issue tracking, continuous integration, deployment pipeline, and more. It offers two editions, the Enterprise Edition and the Community Edition. It is an alternative to GitHub that supports integration with various services. With GitLab, you can host your own internal repository for a development team and allow users to host their projects. In this post, we will show you how to install the GitLab community edition on Rocky Linux 10. ## Step 1 – Install Postfix Before starting, you will need to install the Postfix package on your server. You can install it using the following command: ``` dnf install postfix ``` Once Postfix is installed, start the Postfix service and enable it to start at system reboot: ``` systemctl enable --now postfix ``` ## Step 2 – Add GitLab CE Repository By default, GitLab is not included in the Rocky Linux default repo, so you will need to add a repository from the GitLab installation script. First, download the script from the GitLab using the following command: ``` wget https://packages.gitlab.com/install/repositories/gitlab/gitlab-ce/script.rpm.sh ``` Once the download is completed, set execution permissions with the following command: ``` chmod +x script.rpm.sh ``` Next, run the script to add the GitLab CE repository. ``` os=el dist=9 ./script.rpm.sh ``` Once the repository has been created, you should get the following output: ``` Generating yum cache for gitlab_gitlab-ce... Importing GPG key 0x51312F3F: Userid : "GitLab B.V. (package repository signing key) " Fingerprint: F640 3F65 44A3 8863 DAA0 B6E0 3F01 618A 5131 2F3F From : https://packages.gitlab.com/gitlab/gitlab-ce/gpgkey Importing GPG key 0xF27EAB47: Userid : "GitLab, Inc. " Fingerprint: DBEF 8977 4DDB 9EB3 7D9F C3A0 3CFC F9BA F27E AB47 From : https://packages.gitlab.com/gitlab/gitlab-ce/gpgkey/gitlab-gitlab-ce-3D645A26AB9FBD22.pub.gpg Generating yum cache for gitlab_gitlab-ce-source... The repository is setup! You can now install packages. ``` You can check the repository using the following command: ``` dnf repolist ``` You should get the following output: ``` repo id repo name appstream Rocky Linux 8 - AppStream baseos Rocky Linux 8 - BaseOS epel Extra Packages for Enterprise Linux 8 - x86_64 epel-modular Extra Packages for Enterprise Linux Modular 8 - x86_64 extras Rocky Linux 8 - Extras gitlab_gitlab-ce gitlab_gitlab-ce gitlab_gitlab-ce-source gitlab_gitlab-ce-source remi-modular Remi's Modular repository for Enterprise Linux 8 - x86_64 remi-safe Safe Remi's RPM repository for Enterprise Linux 8 - x86_64 ``` ## Step 3 – Install GitLab CE Now, install GitLab CE using the following command: ``` dnf install gitlab-ce -y ``` Once GitLab has been installed, you should get the following output: ``` It looks like GitLab has not been configured yet; skipping the upgrade script. ``` ``` *. *. *** *** ***** ***** .****** ******* ******** ******** ,,,,,,,,,***********,,,,,,,,, ,,,,,,,,,,,*********,,,,,,,,,,, .,,,,,,,,,,,*******,,,,,,,,,,,, ,,,,,,,,,*****,,,,,,,,,. ,,,,,,,****,,,,,, .,,,***,,,, ,*,. _______ __ __ __ / ____(_) /_/ / ____ _/ /_ / / __/ / __/ / / __ `/ __ \ / /_/ / / /_/ /___/ /_/ / /_/ / \____/_/\__/_____/\__,_/_.___/ Thank you for installing GitLab! GitLab was unable to detect a valid hostname for your instance. Please configure a URL for your GitLab instance by setting `external_url` configuration in /etc/gitlab/gitlab.rb file. Then, you can start your GitLab instance by running the following command: sudo gitlab-ctl reconfigure ``` ## Step 4 – Configure GitLab CE At this point, GitLab is installed in your system but it is not configured yet. You can configure it by editing **/etc/gitlab/gitlab.rb** file: ``` nano /etc/gitlab/gitlab.rb ``` Define your external URL, email address and enable Let’s Encrypt as shown below: ``` external_url "https://gitlab.linuxbuz.com" # Enable the Let's encrypt SSL letsencrypt['enable'] = true # This is optional to get SSL related alerts letsencrypt['contact_emails'] = ['hitjethva@gmail.com'] # This example renews every 7th day at 12:30 letsencrypt['auto_renew_hour'] = "12" letsencrypt['auto_renew_minute'] = "30" letsencrypt['auto_renew_day_of_month'] = "*/7" ``` Save and close the file then run the following command to configure GitLab. ``` gitlab-ctl reconfigure ``` Once the configuration has been completed, you should get the following output: ``` Notes: Default admin account has been configured with following details: Username: root Password: You didn't opt-in to print initial root password to STDOUT. Password stored to /etc/gitlab/initial_root_password. This file will be cleaned up in first reconfigure run after 24 hours. ``` The above command will configure GitLab and store the access credential in**/etc/gitlab/initial_root_password** file. You can check the access password using the following command: ``` cat /etc/gitlab/initial_root_password ``` You should get the following output: ``` Password: M5wKH1kbSyHQgbr3GqpD4oH7rqv4l/A5f98g/FVq7xA= ``` ## Step 5 – Access GitLab CE You can now access the GitLab CE web UI using the URL https://gitlab.linuxbuz.com. You will be redirected to the GitLab login page: ![GitLab Login page](https://www.atlantic.net/wp-content/uploads/2021/09/p1-5-1024x508.png) Provide your root username, password and click on the **Sign-in** button. You should see the GitLab dashboard on the following page: ![GitLab Dashboard page](https://www.atlantic.net/wp-content/uploads/2021/09/p2-3-1024x478.png) ## Step 6 – Backup GitLab It is recommended to back up your GitLab instance per month. You can back up the GitLab instance using the following command: ``` gitlab-rake gitlab:backup:create ``` It is also a good idea to make your backups automatic. You can do it by creating a cron job. ``` nano /etc/crontab ``` Add the following line: ``` 0 22 * * * gitlab-rake gitlab:backup:create ``` Save and close the file when you are finished. ## Conclusion In this guide, we explained how to install GitLab CE on Rocky Linux 10. You can now implement GitLab in your local development to track your all projects. Get started on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install OpenCart on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-opencart-on-rocky-linux-10/ | Published: 2021-10-15 | Updated: 2025-10-21 | Author: Hitesh Jethva OpenCart is an open-source e-commerce platform written in PHP. It is simple, lightweight, user-friendly, and provides a web interface to manage it from the web browser. It allows you to easily manage product inventory, orders, affiliates, discounts, product reviews, payment gateways, and more. OpenCart comes with a lot of plugins and themes that help you to make your store more attractive and powerful. If you are looking to host your own online store, then OpenCart is a great choice for you. In this tutorial, we will show you how to install OpenCart on Rocky Linux 10. ## Step 1 – Install Apache, MariaDB, and PHP First, you will need to install Apache web server and MariaDB to your system. You can install them using the following command: ``` dnf install httpd mariadb-server -y ``` After installing both packages, you will also need to install PHP version 8.3 and all required extensions. First, install the EPEL with the following command: ``` dnf install epel-release -y ``` Finally, install PHP with all required extensions using the following command: ``` dnf install php php-gd php-ldap php-zip php-odbc php-pear php-xml php-mbstring php-mysqlnd php-snmp php-soap curl curl-devel unzip git -y ``` Once all the packages are installed, start the Apache and MariaDB service and enable them to start at system reboot: ``` systemctl start httpd systemctl enable httpd systemctl start mariadb systemctl enable mariadb ``` ## Step 2 – Create OpenCart Database OpenCart uses MariaDB as a database backend, so you will need to create a database and user for OpenCart. First, secure the MariaDB installation and set the MariaDB root password using the following command: ``` mysql_secure_installation ``` Answer all the questions as shown below: ``` Enter current password for root (enter for none): Set root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` Next, log in to MariaDB using the following command: ``` mysql -u root -p ``` Once you are logged in, create a user and database with the following command: ``` CREATE DATABASE opencart; CREATE USER 'opencart'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the OpenCart database with the following command: ``` GRANT ALL PRIVILEGES ON opencart.* TO 'opencart'@'localhost'; ``` Next, flush the privileges and exit from MariaDB with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download OpenCart You can download the latest version of the OpenCart from the GitHub repository using the following command: ``` git clone https://github.com/opencart/opencart.git ``` Once the download is completed, change the directory to the downloaded directory and copy the upload directory to Apache web root directory: ``` cd opencart mv upload /var/www/html/opencart ``` You will also need to copy the sample configuration file: ``` cp /var/www/html/opencart/config-dist.php /var/www/html/opencart/config.php cp /var/www/html/opencart/admin/config-dist.php /var/www/html/opencart/admin/config.php ``` Next, set proper permissions and ownership using the following command: ``` chown -R apache:apache /var/www/html/opencart chmod -R 777 /var/www/html/opencart ``` ## Step 4 – Configure Apache to Host OpenCart Next, you will need to create an Apache virtual host configuration file to host OpenCart on the internet: ``` nano /etc/httpd/conf.d/opencart.conf ``` Add the following lines: ``` ServerAdmin admin@yourdomain.com DocumentRoot /var/www/html/opencart/ ServerName opencart.yourdomain.com Options FollowSymLinks AllowOverride All Order allow,deny allow from all ErrorLog /var/log/httpd/yourdomain.com-error_log CustomLog /var/log/httpd/yourdomain.com-access_log common ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 5 – Configure Firewall If you are using firewalld then you will need to allow HTTP and HTTPS services through the firewall. You can allow them using the following command: ``` firewall-cmd --permanent --add-service=http firewall-cmd --permanent --add-service=https ``` Next, reload firewalld to apply the changes: ``` firewall-cmd --reload ``` ## Step 6 – Access OpenCart Web UI You can now access the OpenCart Web UI using the URL **http://opencart.yourdomain.com**. You should see the following page: ![OpenCart License page](https://www.atlantic.net/wp-content/uploads/2021/09/p1-4-1024x580.png) Accept the license agreement and click on the **Continue** button. You should see the following page: ![OpenCart Dependencies Check page](https://www.atlantic.net/wp-content/uploads/2021/09/p2-2-1024x571.png) Make sure all PHP extensions are installed then click on the **Continue** button. You should see the following page: ![OpenCart Database Configuration page](https://www.atlantic.net/wp-content/uploads/2021/09/p3-1-1024x559.png) Provide your database details, admin username, password, and click on the **Continue** button. You should see the following page: ![OpenCart Install finish page](https://www.atlantic.net/wp-content/uploads/2021/09/p4-1-1024x609.png) Now, open your terminal and remove the install directory using the following command: ``` rm -rf /var/www/html/opencart/install ``` Next, go back to the OpenCart web interface and click on **Login to your Administration**. You should see the OpenCart login page: ![OpenCart login page](https://www.atlantic.net/wp-content/uploads/2021/09/p6-1024x482.png) Provide your admin username, password and click on the **Login** button. You should see the OpenCart dashboard on the following page: ![OpenCart Dashboard page](https://www.atlantic.net/wp-content/uploads/2021/09/p7-1024x541.png) ## Conclusion Congratulations! Your OpenCart platform is now ready to use. You can now deploy your own online store using OpenCart. Get started on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install Nextcloud on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-nextcloud-on-rocky-linux-10/ | Published: 2021-10-16 | Updated: 2025-10-21 | Author: Hitesh Jethva Nextcloud is an enterprise-ready suite of client-server software built to help users create, host, and share files. Nextcloud is a free and open-source file hosting service, making it an excellent choice for home users, with scalability to enterprise-level deployments. In this post, we will show you how to install Nextcloud on Rocky Linux 10. ## Step 1 – Install LAMP Stack Before starting, a LAMP stack must be installed on your server. You can install it using the following command: ``` dnf update -y dnf install httpd mariadb-server php php-curl php-gd php-intl php-json php-ldap php-mbstring php-mysqlnd php-xml php-zip php-opcache unzip curl -y ``` After the successful installation, start the Apache and MariaDB services and enable them to start after system reboot: ``` systemctl start httpd systemctl enable httpd systemctl start mariadb systemctl enable mariadb ``` ## Step 2 – Create a Database and User for NextCloud First, secure the MariaDB installation and set the MariaDB root password using the following command: ``` mysql_secure_installation ``` Answer all the questions as shown below: ``` Enter current password for root (enter for none): Set root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` Next, log in to MariaDB using the following command: Nextcloud uses MariaDB or MySQL as a database backend. First, log in to MariaDB with the following command: ``` mysql -u root -p ``` Once you are logged in, create a database and user with the following command: ``` CREATE DATABASE nextcloud; CREATE USER 'nextcloud'@'%' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the Nextcloud database using the following command: ``` GRANT ALL PRIVILEGES ON nextcloud.* TO 'nextcloud'@'%'; ``` Next, flush the privileges and exit from the MariaDB shell using the command below: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install NextCloud At the time of writing this tutorial, the latest version of Nextcloud is 21. You can download it using the following command: ``` wget https://download.nextcloud.com/server/releases/latest-32.zip ``` Once the download is completed, extract it to the Apache web root directory with the following command: ``` unzip latest-32.zip -d /var/www/html/ ``` Next, create a data directory for Nextcloud with the following command: ``` mkdir -p /var/www/html/nextcloud/data ``` Next, change the ownership of the Nextcloud directory to Apache: ``` chown -R apache:apache /var/www/html/nextcloud/ chmod -R 777 /var/www/html/nextcloud/ ``` ## Step 4 – Create an Apache Virtual Host Configuration File Next, you will need to create an Apache virtual host configuration file to host Nextcloud using the Apache webserver. ``` nano /etc/httpd/conf.d/nextcloud.conf ``` Add the following code: ``` ServerName nextcloud.yourdomain.com DocumentRoot /var/www/html/nextcloud ErrorLog /var/log/httpd/nextcloud_error.log CustomLog /var/log/httpd/nextcloud_requests.log combined ``` Save the file when you are finished, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` You can check the status of Apache using the following command; ``` systemctl status httpd ``` You should get the following output: ``` ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; preset: disabled) Drop-In: /etc/systemd/system/httpd.service.d └─php-fpm.conf Active: active (running) since Tue 2025-10-21 03:46:02 EDT; 3s ago Invocation: 1673147d438a40d3b6a478bd72db848b Docs: man:httpd.service(8) Main PID: 5020 (httpd) Status: "Started, listening on: port 80" Tasks: 177 (limit: 24809) Memory: 17.9M (peak: 18.3M) CPU: 92ms CGroup: /system.slice/httpd.service ├─5020 /usr/sbin/httpd -DFOREGROUND ├─5021 /usr/sbin/httpd -DFOREGROUND ├─5022 /usr/sbin/httpd -DFOREGROUND ├─5023 /usr/sbin/httpd -DFOREGROUND └─5024 /usr/sbin/httpd -DFOREGROUND ``` ## Step 5 – Configure Firewall If firewalld is installed and running in your server, then you will need to allow port 80 through the firewall. You can allow it using the following command: ``` firewall-cmd --add-port=80/tcp --zone=public --permanent ``` Next, reload the firewall to apply the changes: ``` firewall-cmd --reload ``` ## Step 6 – Access NextCloud To access Nextcloud, open your web browser and visit the URL**http://nextcloud.yourdomain.com**. You should see the following screen: ![NextCloud Welcome page](https://www.atlantic.net/wp-content/uploads/2021/09/p1-3.png) ![NextCloud Welcome page2](https://www.atlantic.net/wp-content/uploads/2021/09/p2-1.png) Provide your administrator account name, password, define your data directory, database credentials and click on the **Finish** **setup** button. You will be redirected to the Nextcloud login page: ![NextCloud Login page](https://www.atlantic.net/wp-content/uploads/2021/09/p3.png) Provide your admin account username, password and click on the **Log in** button. You should see the Nextcloud dashboard: ![NextCloud Dashboard page](https://www.atlantic.net/wp-content/uploads/2021/09/p4-1024x535.png) ## Conclusion Now that you have installed Nextcloud on Rocky Linux 10, you can easily create and share documents, calendars, and more with your friends and family. Get started on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install Laravel PHP Framework on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-laravel-php-framework-on-rocky-linux-10/ | Published: 2021-10-17 | Updated: 2025-10-21 | Author: Hitesh Jethva Laravel is an open-source PHP framework designed for web application development. It is built on various components of the Symfony framework and makes it easier to program PHP web applications. It provides a meaningful and creative syntax for simplifying common tasks such as authentication, routing, sessions, working with databases, and more. It makes development process simple for developers without compromising program capabilities. In this post, we will show you how to install Laravel PHP Framework on Rocky Linux 10. ## Step 1 – Install Nginx, MariaDB and PHP First, you will need to install the Nginx web server, MariaDB database server, PHP, and other PHP extensions to your server. You can install all of them using the following command: ``` dnf install nginx mariadb-server php php-fpm php-common php-xml php-mbstring php-json php-zip php-mysqlnd curl unzip -y ``` Once all the packages are installed, start and enable the Nginx, MariaDB and PHP-FPM services using the following command: ``` systemctl start php-fpm nginx mariadb systemctl enable php-fpm nginx mariadb ``` Next, you will need to edit the PHP-FPM configuration file and change the user and group from apache to nginx. ``` nano /etc/php-fpm.d/www.conf ``` Change the following lines: ``` listen.owner = nginx listen.group = nginx ``` Save and close the file, then edit the php.ini file: ``` nano /etc/php.ini ``` Change the following lines: ``` date.timezone = UTC cgi.fix_pathinfo=1 ``` Save and close the file, then restart the PHP-FPM service to apply the changes. ``` systemctl restart php-fpm ``` ## Step 2 – Install Composer Composer is a dependency manager for PHP. It is used to install various PHP dependencies required for your project. You can install it using the following command: ``` curl -sS https://getcomposer.org/installer | php ``` You should get the following output: ``` All settings correct for using Composer Downloading... Composer (version 2.8.12) successfully installed to: /root/composer.phar Use it: php composer.phar ``` Next, move the downloaded binary to the system path and set proper permission: ``` mv composer.phar /usr/local/bin/composer chmod +x /usr/local/bin/composer ``` Now, verify the Composer version with the following command: ``` composer --version ``` You should get the following output: ``` Composer version 2.8.12 2025-09-19 13:41:59 ``` ## Step 3 – Install Laravel First, navigate to Nginx web root directory and download the latest version of Laravel using the following command: ``` cd /var/www/html/ composer create-project --prefer-dist laravel/laravel laravelsite ``` You should get the following output: ``` Generating optimized autoload files > Illuminate\Foundation\ComposerScripts::postAutoloadDump > @php artisan package:discover --ansi Discovered Package: facade/ignition Discovered Package: fruitcake/laravel-cors Discovered Package: laravel/sail Discovered Package: laravel/sanctum Discovered Package: laravel/tinker Discovered Package: nesbot/carbon Discovered Package: nunomaduro/collision Package manifest generated successfully. 76 packages you are using are looking for funding. Use the `composer fund` command to find out more! > @php artisan vendor:publish --tag=laravel-assets --ansi No publishable resources for tag [laravel-assets]. Publishing complete. > @php artisan key:generate --ansi Application key set successfully. ``` Next, set proper permissions and ownership to laravel directories: ``` chown -R nginx:nginx /var/www/html/laravelsite/storage/ chown -R nginx:nginx /var/www/html/laravelsite chown -R nginx:nginx /var/www/html/laravelsite/bootstrap/cache/ chmod -R 0777 /var/www/html/laravelsite/storage/ chmod -R 0775 /var/www/html/laravelsite/bootstrap/cache/ ``` ## Step 4 – Configure Nginx for Laravel Now, you will need to create an Nginx virtual host configuration file to host Laravel on the Internet. You can create it using the following command: ``` nano /etc/nginx/conf.d/laravel.conf ``` Add the following lines: ``` server { listen 80; server_name laravel.yourdomain.com; root /var/www/html/laravelsite/public; index index.php; charset utf-8; gzip on; gzip_types text/css application/javascript text/javascript application/x-javascript image/svg+xml text/plain text/xsd text/xsl text/xml image/x-icon; location / { try_files $uri $uri/ /index.php?$query_string; } location ~ \.php { include fastcgi.conf; fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_pass unix:/run/php-fpm/www.sock; } location ~ /\.ht { deny all; } } ``` Save and close the file then verify Nginx for any syntax error susing the following command: ``` nginx -t ``` You should get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart both the Nginx and PHP-FPM services to apply the changes: ``` systemctl restart php-fpm systemctl restart nginx ``` You can also verify the Nginx status using the following command: ``` systemctl status nginx ``` You should see the following output: ``` ● nginx.service - The nginx HTTP and reverse proxy server Loaded: loaded (/usr/lib/systemd/system/nginx.service; disabled; preset: disabled) Drop-In: /etc/systemd/system/nginx.service.d └─php-fpm.conf Active: active (running) since Tue 2025-10-21 03:18:56 EDT; 3s ago Invocation: c0359fc7652c4ccab4f023393a764f6f Process: 4546 ExecStartPre=/usr/bin/rm -f /run/nginx.pid (code=exited, status=0/SUCCESS) Process: 4548 ExecStartPre=/usr/sbin/nginx -t (code=exited, status=0/SUCCESS) Process: 4550 ExecStart=/usr/sbin/nginx (code=exited, status=0/SUCCESS) Main PID: 4551 (nginx) Tasks: 3 (limit: 24809) Memory: 2.9M (peak: 3.1M) CPU: 34ms CGroup: /system.slice/nginx.service ├─4551 "nginx: master process /usr/sbin/nginx" ├─4552 "nginx: worker process" └─4553 "nginx: worker process" ``` ## Step 5 – Configure Firewall If firewalld is installed and running in your server then you will need to allow HTTP and HTTPS service through the firewall. You can allow both services using the following command: ``` firewall-cmd --zone=public --permanent --add-service=http firewall-cmd --zone=public --permanent --add-service=https ``` Next, reload the firewalld to apply the changes: ``` firewall-cmd --reload ``` ## Step 6 – Access Laravel Dashboard You can now access the Laravel dashboard using the URL **http://laravel.yourdomain.com**. You will be redirected to the Laravel default screen: ![](https://www.atlantic.net/wp-content/uploads/2021/10/l.png) ## Conclusion Congratulations! You have successfully installed Laravel with Nginx on Rocky Linux 10. You can now start working smoothly to create PHP web applications on this framework. Get started on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install Odoo 18 ERP on RockyLinux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-odoo-18-erp-on-rocky-linux-10/ | Published: 2021-10-18 | Updated: 2025-10-21 | Author: Hitesh Jethva Odoo is a group of business management software tools that include features for billing, accounting, eCommerce, CRM, warehouse, project management, and inventory management. It is designed for small and medium businesses and is available in the cloud or on-premise. It is user-friendly, scalable, customizable, flexible, and helps you manage businesses and organizations with a CMS. In this post, we will show you how to install Odoo 18 in Rocky Linux 10. ## Step 1 – Install Python packages and Odoo Dependencies Before starting, install the EPEL repository using the following command: ``` dnf install epel-release -y ``` Once EPEL is installed, run the following command to install Python and Odoo dependencies: ``` dnf install python3 python3-devel git gcc git redhat-rpm-config libxslt-devel bzip2-devel openldap-devel libjpeg-devel freetype-devel -y ``` Next, install the **wkhtmltox** to render HTML into a PDF using the following command: ``` dnf install https://github.com/wkhtmltopdf/wkhtmltopdf/releases/download/0.12.5/wkhtmltox-0.12.5-1.centos8.x86_64.rpm ``` Next, enable CRB repo. ``` dnf config-manager --set-enabled crb ``` Next, install required Perl extension. ``` dnf install -y perl-IPC-Run ``` ## Step 2 – Install PostgreSQL Odoo uses PostgreSQL as a database backend. First, add PostgreSQL repo. ``` dnf install https://download.postgresql.org/pub/repos/yum/reporpms/EL-8-x86_64/pgdg-redhat-repo-latest.noarch.rpm ``` Next, install PostgreSQL with the following command. ``` dnf install postgresql18 postgresql18-server postgresql18-devel -y ``` After installing PostgreSQL, initialize the PostgreSQL database with the following command: ``` /usr/pgsql-18/bin/postgresql-18-setup initdb ``` Sample output: ``` WARNING: using obsoleted argument syntax, try --help WARNING: arguments transformed to: postgresql-setup --initdb --unit postgresql * Initializing database in '/var/lib/pgsql/data' * Initialized, logs are in /var/lib/pgsql/initdb_postgresql.log ``` Next, start the PostgreSQL service and enable it to start at system reboot: ``` systemctl enable --now postgresql-18 ``` Next, create a user for Odoo with the following command: ``` su - postgres -c "createuser -s odoo18" ``` ## Step 3 – Install Odoo 18 First, add an odoo user to run the Odoo service: ``` useradd -m -U -r -d /opt/odoo18 -s /bin/bash odoo18 ``` Next, log in with the odoo user and download Odoo version 18 using the following command: ``` su - odoo18 git clone https://www.github.com/odoo/odoo --depth 1 --branch 18.0 /opt/odoo18/odoo ``` Next, change the directory to /opt/odoo18 and create a Python virtual environment: ``` cd /opt/odoo18 python3 -m venv odooenv ``` Next, activate the virtual environment: ``` source odooenv/bin/activate ``` Next, install the required dependencies using the following command: ``` pip3 install -r odoo/requirements.txt ``` Next, deactivate the virtual environment with the following command: ``` deactivate ``` Next, create an addons directory and exit from the odoo user with the following command: ``` mkdir /opt/odoo18/odoo-custom-addons exit ``` Next, create an Odoo configuration file using the following command: ``` nano /etc/odoo18.conf ``` Add the following lines: ``` [options] admin_passwd = secure-password db_host = False db_port = False db_user = odoo18 db_password = False addons_path = /opt/odoo18/odoo/addons, /opt/odoo18/odoo-custom-addons ``` Save and close the file. ## Step 4 – Create an Odoo Service File Next, you will need to create a service file to manage the Odoo service. You can create it using the following command: ``` nano /etc/systemd/system/odoo.service ``` Add the following lines: ``` [Unit] Description=Odoo18 Requires=postgresql-18.service After=network.target postgresql-18.service [Service] Type=simple SyslogIdentifier=odoo18 PermissionsStartOnly=true User=odoo18 Group=odoo18 ExecStart=/opt/odoo18/odooenv/bin/python3 /opt/odoo18/odoo/odoo-bin -c /etc/odoo18.conf StandardOutput=journal+console [Install] WantedBy=multi-user.target ``` Save the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the enable the Odoo service using the following command: ``` systemctl enable --now odoo ``` You can check the status of the Odoo service using the following command: ``` systemctl status odoo ``` Sample output: ``` ● odoo.service - Odoo18 Loaded: loaded (/etc/systemd/system/odoo.service; disabled; preset: disabled) Active: active (running) since Tue 2025-10-21 02:43:04 EDT; 4s ago Invocation: a2fd6721e8bd483eaf7b9806f5de2a54 Main PID: 3127 (python3) Tasks: 4 (limit: 24809) Memory: 89.3M (peak: 91.3M) CPU: 1.507s CGroup: /system.slice/odoo.service └─3127 /opt/odoo18/odooenv/bin/python3 /opt/odoo18/odoo/odoo-bin -c /etc/odoo18.conf ``` ## Step 5 – Configure Firewall If you are using firewalls, then you will need to allow Odoo port 8069 through the firewall. You can allow it using the following command: ``` firewall-cmd --permanent --add-port=8069 ``` Next, reload the firewalld to apply the changes: ``` firewall-cmd --reload ``` ## Step 6 – Access Odoo 18 Web UI At this point, Odoo 18 is started and listening on port 8069. You can check it using the following command: ``` ss -antpl | grep 8069 ``` Sample output: ``` LISTEN 0 128 0.0.0.0:8069 0.0.0.0:* users:(("python3",pid=37537,fd=3)) ``` You can now access it using the URL **http://your-server-ip:8069**. You should see the following page: ![Odoo 14 login page](https://www.atlantic.net/wp-content/uploads/2021/09/p1-1.png) Provide your master admin password, email, password, and click on the “**Create database**” button. You will be redirected to the Odoo18 dashboard as shown below: ![Odoo 14 dashboard page](https://www.atlantic.net/wp-content/uploads/2021/09/p2-1024x530.png) ## Conclusion That’s it for now. You have successfully installed Odoo 18 on Rocky Linux 10. You can now start managing your business using the Odoo ERP. Get started on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Setup Password-less SSH on Linux > URL: https://www.atlantic.net/vps-hosting/how-to-setup-password-less-ssh-on-linux/ | Published: 2021-10-19 | Updated: 2024-06-04 | Author: Hitesh Jethva SSH, also known as “Secure Shell,” is an open-source protocol used to log in to a remote Linux server. It is used by the system and network administrators to manage Linux servers from a remote location. It is also used to transfer files between multiple Linux systems. There are two ways to log in to a remote Linux system: using password authentication and key-based authentication. Key-based authentication is more secure than passwords because only a user with valid keys can log in to Linux. In this post, we will show you how to set up password-less SSH on Linux. ## Step 1 – Generate an SSH Key First, you will need to generate an SSH key pair on the machine where you are working. You can generate it using the following command: ``` ssh-keygen -t rsa ``` You will be asked to specify the location to store the key as shown below: ``` Enter file in which to save the key (/home/vyom/.ssh/id_rsa): ``` Just press Enter and accept the default path. You will be asked to set a passphrase as shown below: ``` Enter passphrase (empty for no passphrase): Enter same passphrase again: ``` Just press Enter without providing any passphrase. You should see the following output: ``` Your identification has been saved in /home/vyom/.ssh/id_rsa. Your public key has been saved in /home/vyom/.ssh/id_rsa.pub. The key fingerprint is: ec:50:43:d9:39:64:f8:19:63:18:ab:1c:e4:ea:f5:e7 vyom@newpc The key's randomart image is: +--[ RSA 2048]----+ | . oBo. | | o .+oB | | o +o = | | o = .o | | . = S | | . . + | | . o . | | o | | E | +-----------------+ ``` Now, verify your SSH key using the following command: ``` ls -la ~/.ssh/id_*.pub ``` You should see the following output: ``` -rw-r--r-- 1 vyom vyom 392 Sep 8 14:34 /home/vyom/.ssh/id_rsa.pub ``` ## Step 2 – Copy SSH Public Key to Remote Server Now, you will need to copy your public key to the remote server. You can do it using the ssh-copy-id command: ``` ssh-copy-id root@69.87.217.12 ``` You will be asked to provide a root password of a remote server to copy a public key: ``` root@69.87.217.12's password: Number of key(s) added: 1 Now try logging into the machine, with: "ssh 'root@69.87.217.12'" and check to make sure that only the key(s) you wanted were added. ``` ## Step 3 – Connect Remote Server without Password At this point, the SSH key is generated and copied to the remote server. You can now connect to the remote server without providing a password: ``` ssh root@69.87.217.12 ``` Once you are connected, you should see the following output: ``` Welcome to Ubuntu 20.04 LTS (GNU/Linux 5.4.0-29-generic x86_64) * Documentation: https://help.ubuntu.com * Management: https://landscape.canonical.com * Support: https://ubuntu.com/advantage Last login: Wed Sep 8 07:50:27 2021 from 106.222.86.57 root@ubuntu:~# ``` ## Step 4 – Remove Password-based Authentication At this point, SSH key-based authentication is configured successfully. Now, it is recommended that you disable the use of password authentication so that everyone only uses keys to access the server. On the remote Linux server, edit the SSH main configuration file: ``` nano /etc/ssh/sshd_config ``` Uncomment and change the following line: ``` PasswordAuthentication no ``` Save and close the file, then restart the SSH service to apply the changes: ``` systemctl restart ssh ``` ## Conclusion In the above guide, you learned how to set up SSH password-less authentication on Linux. You can now implement SSH key-based authentication for each server that you want to manage remotely. Try it today on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Check Size of Files and Directory on Linux > URL: https://www.atlantic.net/vps-hosting/how-to-check-size-of-files-and-directory-on-linux/ | Published: 2021-10-20 | Updated: 2023-11-16 | Author: Hitesh Jethva If you are a system administrator, then you need to be aware of the total disk space occupied by the file system so you can identify unwanted files and directories, remove them and free the disk space. The du command stands for “Disk Usage” and can be used to check the information of disk usage of files and directories in your system. In this guide, we will show you how to check the size of files and directories in Linux. ## Step 1 – Basic Syntax The basic syntax of the du command is shown below: ``` du [OPTION]... [FILE]... ``` To display all options available with the du command, run: ``` du --help ``` You should see the following screen: ![du help page](https://www.atlantic.net/wp-content/uploads/2021/09/du-command-help.png) ## Step 2 – Display Disk Usage Summary of a Directory Running the du command without any options will display the disk usage summary of a directory. For example, to check the disk usage of the directory /opt, run the following command: ``` du /opt/ ``` This will print the disk usage summary in kilobytes in the first column: ``` 440 /opt/google/earth/pro/shaders 8804 /opt/google/earth/pro/resources/gdal 16 /opt/google/earth/pro/resources/flightsim/aircraft 12 /opt/google/earth/pro/resources/flightsim/hud 56 /opt/google/earth/pro/resources/flightsim/controller 12 /opt/google/earth/pro/resources/flightsim/keyboard 8 /opt/google/earth/pro/resources/flightsim/planet 112 /opt/google/earth/pro/resources/flightsim 12660 /opt/google/earth/pro/resources 15220 /opt/google/earth/pro/lang 1180 /opt/google/earth/pro/plugins/imageformats 468 /opt/google/earth/pro/plugins/bearer 396 /opt/google/earth/pro/plugins/platforms 80 /opt/google/earth/pro/plugins/printsupport 72 /opt/google/earth/pro/plugins/audio 18892 /opt/google/earth/pro/plugins 244252 /opt/google/earth/pro 244256 /opt/google/earth 2828 /opt/google/chrome/swiftshader 10140 /opt/google/chrome/WidevineCdm/_platform_specific/linux_x64 10144 /opt/google/chrome/WidevineCdm/_platform_specific 10156 /opt/google/chrome/WidevineCdm 20 /opt/google/chrome/cron ``` ## Step 3 – Display Total Size of a Directory You can use the du command with the -c option to display the disk usage summary of each file with total size. ``` du -c /opt ``` You should see the following output: ``` 440 /opt/google/earth/pro/shaders 8804 /opt/google/earth/pro/resources/gdal 16 /opt/google/earth/pro/resources/flightsim/aircraft 12 /opt/google/earth/pro/resources/flightsim/hud 56 /opt/google/earth/pro/resources/flightsim/controller 12 /opt/google/earth/pro/resources/flightsim/keyboard 8 /opt/google/earth/pro/resources/flightsim/planet 112 /opt/google/earth/pro/resources/flightsim 12660 /opt/google/earth/pro/resources 15220 /opt/google/earth/pro/lang 1180 /opt/google/earth/pro/plugins/imageformats 468 /opt/google/earth/pro/plugins/bearer 396 /opt/google/earth/pro/plugins/platforms 80 /opt/google/earth/pro/plugins/printsupport 72 /opt/google/earth/pro/plugins/audio 18892 /opt/google/earth/pro/plugins 244252 /opt/google/earth/pro 244256 /opt/google/earth 2828 /opt/google/chrome/swiftshader 10140 /opt/google/chrome/WidevineCdm/_platform_specific/linux_x64 10144 /opt/google/chrome/WidevineCdm/_platform_specific 10156 /opt/google/chrome/WidevineCdm 20 /opt/google/chrome/cron 599088 /opt 599088 total ``` ## Step 4 – Display Disk Usage in Human Readable Format By default, the du command shows the size of all files and directories in kilobytes. You can use the -h option to display the size of all files and directories in human-readable format: ``` du -h /opt ``` You should see the following output: ``` 440K /opt/google/earth/pro/shaders 8.6M /opt/google/earth/pro/resources/gdal 16K /opt/google/earth/pro/resources/flightsim/aircraft 12K /opt/google/earth/pro/resources/flightsim/hud 56K /opt/google/earth/pro/resources/flightsim/controller 12K /opt/google/earth/pro/resources/flightsim/keyboard 8.0K /opt/google/earth/pro/resources/flightsim/planet 112K /opt/google/earth/pro/resources/flightsim 13M /opt/google/earth/pro/resources 15M /opt/google/earth/pro/lang 1.2M /opt/google/earth/pro/plugins/imageformats 468K /opt/google/earth/pro/plugins/bearer 396K /opt/google/earth/pro/plugins/platforms 80K /opt/google/earth/pro/plugins/printsupport 72K /opt/google/earth/pro/plugins/audio 19M /opt/google/earth/pro/plugins 239M /opt/google/earth/pro 239M /opt/google/earth 2.8M /opt/google/chrome/swiftshader 10M /opt/google/chrome/WidevineCdm/_platform_specific/linux_x64 10M /opt/google/chrome/WidevineCdm/_platform_specific 10M /opt/google/chrome/WidevineCdm 20K /opt/google/chrome/cron 16K /opt/google/chrome/MEIPreload 21M /opt/google/chrome/locales 92K /opt/google/chrome/default_apps 255M /opt/google/chrome 493M /opt/google ``` ## Step 5 – Display Total File Size of a Directory You can use the -s option to display the only total size of the directory. ``` du -hs /opt ``` You should see the following output: ``` 586M /opt ``` ## Step 6 – Sort File and Directory by Size You can use the du command with sort to display and sort all files and directories by their size. ``` du /opt | sort -n -r ``` You should see the following output: ``` 599088 /opt 504580 /opt/google 260320 /opt/google/chrome 244256 /opt/google/earth 244252 /opt/google/earth/pro 94268 /opt/ffmpeg 58604 /opt/ffmpeg/bin 28400 /opt/ffmpeg/lib 21360 /opt/google/chrome/locales 18892 /opt/google/earth/pro/plugins 15220 /opt/google/earth/pro/lang 12660 /opt/google/earth/pro/resources 10156 /opt/google/chrome/WidevineCdm 10144 /opt/google/chrome/WidevineCdm/_platform_specific 10140 /opt/google/chrome/WidevineCdm/_platform_specific/linux_x64 8804 /opt/google/earth/pro/resources/gdal 5972 /opt/ffmpeg/share 5668 /opt/ffmpeg/share/doc 5664 /opt/ffmpeg/share/doc/ffmpeg 2828 /opt/google/chrome/swiftshader 1288 /opt/ffmpeg/include ``` ## Step 7 – Find the Largest File or Directory You use the du command with sort to find the largest file or directory in your system. Run the du command with -a option to find and display the largest file and directory: ``` du -a / | sort -n -r | head -n 10 ``` You should see the following output: ``` 1653740 / 931232 /usr 483812 /swapfile 425916 /usr/lib 268820 /usr/src 164476 /usr/share 156912 /var 151216 /usr/lib/x86_64-linux-gnu 142644 /var/lib 137388 /usr/lib/modules ``` ## Conclusion In this guide, we explained how to check the size of files and directories with different options. This will help you to track the file system usage on Linux. Get started on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Use Netcat to Transfer Files on Linux > URL: https://www.atlantic.net/vps-hosting/how-to-use-netcat-to-transfer-files-on-linux/ | Published: 2021-10-21 | Updated: 2023-11-25 | Author: Hitesh Jethva Lots of software can help to transfer files between multiple computers including FTP, NFS, Samba, and more. However, configuring those services incorrectly might make your server vulnerable to attacks. If this is a concern, you can use Netcat to transfer files between multiple devices securely. Netcat, also known as a “TCP/IP swiss army knife,” is a command-line network tool that allows you to transfer files through local networks or the Internet. It provides an easier way to transfer data without the need for additional services. In this guide, we will show you how to use Netcat to transfer files on Linux. ## Prerequisites - A Linux server - A root password configured on your server For the purposes of this tutorial, we will use the following setup: - **Sender Host IP**: 69.87.221.67 - **Receiver Host IP**: 45.58.46.205 ## Step 1 – Install Netcat By default, Netcat is not available in Linux, so you will need to install it first. For Ubuntu and Debian based distributions, install Netcat using the following command: ``` apt-get install netcat-openbsd pv -y ``` For CentOS and RHEL based distributions, install Netcat using the following command: ``` dnf install nmap-ncat pv -y ``` ## Step 2 – Transfer Files Between Two Linux Machine First, create a sample file.txt on the sender host. ``` echo "Transferring file using Netcat" > file.txt ``` Next, you will need to run the nc command on the receiver host from where you want to receive the file. ``` nc -l -p 8585 > file.txt ``` This command will instruct nc to listen for incoming requests on port **8585** until it receives a request. Once the request is received it will receive the **file.txt** file. Next, go to the sender host, run the following command to send the **file.txt** file to the receiver host: ``` nc -N 45.58.46.205 8585 < /root/file.txt ``` ## Step 3 – Transfer and Compress Files Between Two Linux Machine In this section, we will show you how to transfer and compress the larger file using Netcat. In this example, we will transfer the **ubuntu.iso** file from one machine to another. On the sender machine from where you want to transfer the **ubuntu.iso** file, run the following command: ``` tar -zcf - ubuntu.iso | pv | nc -l -p 8585 -q 25 ``` In the above command, tar is used to compress the file, and the pv command is used to monitor the progress of the file. Next, go to the receiver machine and run the following command to receive the ubuntu.iso file: ``` nc 69.87.221.67 8585 | pv | tar -zxf - ``` ## Conclusion Congratulations! You have successfully transferred files between two computers using the Netcat command. You can now use Netcat to transfer files over a secure network. Try it out on your [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Change Ownership of a File or Directory with chown Command > URL: https://www.atlantic.net/vps-hosting/how-to-change-ownership-of-files-and-directory-with-chown-command/ | Published: 2021-10-22 | Updated: 2024-06-04 | Author: Hitesh Jethva Only root or superusers access all files and directories in Linux. If you are a regular user, you can not access files and directories created by other users. In this case, you can use the chmod and chown commands to change the permissions or ownership of those files and directories. In this post, we will show you how to use the chown command to change the ownership of files and directories. ## Step 1 – Update the OS Once logged in to your server, run the following command to update your base system with the latest available packages. ``` apt-get update -y ``` Or ``` dnf update -y ``` ## Step 2 – Basic Syntax of the chown Command The basic syntax of the **chown** command is shown below: ``` chown [OPTIONS] USER:GROUP FILE ``` Where: - **USER** – Define the new owner of the file. - **GROUP** – Define the new group owner of the file. - **FILE** – Define the file name you want to change the ownership. To check the version of **the chown** command, run: ``` chown --version ``` Sample output: ``` chown (GNU coreutils) 8.21 Copyright (C) 2013 Free Software Foundation, Inc. License GPLv3+: GNU GPL version 3 or later . This is free software: you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law. Written by David MacKenzie and Jim Meyering. ``` ## Step 3 – Check the Ownership of a File and Directory Before changing any file or directory ownership, you will need to know the original file owner or group. To check the ownership of files and directories in**/opt** directory, run the following command: ``` ls -l /opt ``` You should see the user and group owner of all files in the second and third columns: ``` -rw-r--r-- 1 root root 0 Dec 4 2020 admin.html -rw-r--r-- 1 root root 0 Dec 4 2020 ajax.html drwxr-xr-x 2 root root 4096 Aug 26 14:30 backup -rw-r--r-- 1 root root 0 Dec 4 2020 composer.html drwxr-xr-x 6 root root 4096 Oct 17 2020 ffmpeg -rw-r--r-- 1 root root 891 Nov 3 2020 file2.txt -rw-rw-r-- 1 root root 0 Jan 29 2021 file3.txt -rw-r--r-- 1 root root 16 Oct 23 2020 -filename drwxr-xr-x 4 root root 4096 Jun 28 2020 google -rw-r--r-- 1 root root 0 Dec 4 2020 index.html -rw-r--r-- 1 root root 0 Dec 4 2020 login.html drwxr-xr-x 2 root root 4096 Jul 4 2020 mount -rw-r--r-- 1 root root 0 Oct 22 2020 myfile.txt drwxr-xr-x 3 root root 4096 Jul 2 2020 nginx-static-etags ``` ## Step 4 – Change the Owner of a Single File As you can see, all files and directories are owned by the root user. Now, pick a file named index.html and change the owner from **root** to **vyom**: ``` chown vyom /opt/index.html ``` Now, verify the ownership of index.html using the following command: ``` ls -l /opt/index.html ``` You should see the following output: ``` -rw-r--r-- 1 vyom root 0 Dec 4 2020 /opt/index.html ``` ## Step 5 – Change the Owner of Multiple Files You can also change the ownership of multiple files and directories by using a single space between multiple files. For example, run the following command to change the ownership of **the login.html** and **admin.html** files: ``` chown vyom /opt/login.html /opt/admin.html ``` If you want to change the ownership of all files and directories recursively, run the following command: ``` chown -R vyom /opt/* ``` ## Step 6 – Change the Owner and Group of a File To change the group of a specific file, use the following syntax: ``` chown :NewGroupname Filename ``` For example, to change the group of a file **index.html** to **www-data**, run the following command: ``` chown :www-data /opt/index.html ``` If you want to change the user and group ownership of any file, run the following command: ``` chown vyom:www-data /opt/index.html ``` **Where**: **vyom** is the user owner, and **www-data** is the group owner. ## Step 7 – Transfer User and Group Ownership from One File to Another You can copy ownership settings from one file to another using the **–reference** option. For example, to transfer user and group ownership settings from **index.html** file to **admin.html**, run the following command: ``` chown --reference=/opt/index.html /opt/admin.html ``` ## Conclusion This guide explained how to change the file and directory ownership using the chown command. The chown command is a powerful tool that helps you manage file and directory ownership. Get started on your [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # Find a File with Find and Locate Commands in Linux > URL: https://www.atlantic.net/vps-hosting/find-a-file-with-find-and-locate-commands-in-linux/ | Published: 2021-10-23 | Updated: 2023-11-21 | Author: Hitesh Jethva Finding a file and directory in Linux is easier than in Windows. The Linux find command provides many options to help you find any file type in the file system. The find command allows you to find files and directories and take action based on the results, for example, copying, moving, deleting, or changing permissions. The locate command can also be used to find files by their filename. The locate command is lightning-fast because a background process continuously finds new files and stores them in a database. This post will show you how to find files and directories using the find and locate command. ## Step 1 – The Basic Syntax The basic syntax of the find command is shown below: ``` find directory-path option search-term ``` **Where**: - **directorypath** – Where you want to find the file. - **option** – It could be file name, type, date of creation, etc. - **search-term** – Where you can specify keywords to search. ## Step 2 – Find File by Name To find a file by name, use the following syntax: ``` find . -name filename ``` For example, to find a file named file1.txt in your current working directory, run: ``` find . -name file1.txt ``` If you want to perform a case-insensitive search, run: ``` find . -iname file1.txt ``` ## Step 3 – Find a File by Type You can find the type of file using the **-type** parameter as shown below: ``` find -type query ``` Some example file types are shown below: - **f** – Regular file - **d** – Directory - **l** – Symbolic link - **c** – Character devices - **b** – Block devices For example, to find a regular file, run the following command: ``` find . -type f -name "file1" ``` To find a directory, run: ``` find . -type d -name "Downloads" ``` ## Step 4 – Find a File by Time You can also find the file based on access time, modified time, and change time. For example, to find all files modified more than two days ago, run the following: ``` find /opt -ctime +2 ``` This will find all files inside **/opt** directory, which was changed two days ago. To find all files modified less than **one** day ago, run the following: ``` find /opt -ctime -1 ``` To find all files modified more than **10** minutes ago, run the following: ``` find /opt -mmin +10 ``` ## Step 5 – Find a File by Size The find command will allow you to find files and filter the results by size. You can use the –**size** parameter to filter the result. Some of the most commonly used options with –**size** is shown below: - **c** – Bytes - **k** – Kilobytes - **M** – Megabytes - **G** – Gigabytes - **b** – 512-byte blocks For example, to find a file that is exactly **10MB** in size, run: ``` find / -size 10M ``` To find a file that is greater than **10MB**, run: ``` find / -size +10M ``` To find a file that is less than 10MB, run the following: ``` find / -size -10M ``` ## Step 6 – Find a File by User and Group You can use the option –**user** and –**group** to find a file owned by user and group. For example, to find all files owned by user **tom**, run: ``` find / -user tom ``` To find all files owned by group **sales**, run: ``` find / -group sales ``` ## Step 7 – How to Use Locate Command to Find File The locate command is an alternative to the find command. It builds a database of files on the system, so searches will be faster. To install the locate command in CentOS and RHEL, run the following: ``` yum install mlocate -y ``` To install the locate command in Debian and Ubuntu, run: ``` apt-get install mlocate -y ``` After installing the locate command, update the database using the following command: ``` updatedb ``` Now, to use the locate command to find a file named **file.txt**, run: ``` locate file.txt ``` You can also find a file by extension. For example, to find all files ending in .**txt**, run: ``` locate *.txt ``` ## Conclusion In the above guide, we explained how to find a file and directory using the find and locate command. You can now quickly find any file using the find and locate command. Try it today on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Use Dig Command in Linux with Examples > URL: https://www.atlantic.net/vps-hosting/how-to-use-dig-command-in-linux-with-examples/ | Published: 2021-10-24 | Updated: 2023-11-27 | Author: Hitesh Jethva Dig stands for “Domain Information Groper” used to gather DNS information. Generally, it is used by the system or network administrators for verifying DNS lookup and troubleshoot DNS-related problems. By default, the dig command sends a query to the DNS server listed in the /etc/resolv.com. It also allows you to query the specific DNS server. In this tutorial, we will show you how to use the dig command through practical examples. ## Step 1 – Install dig By default, the dig command is not available in Linux. For Debian and Ubuntu operating systems, install the dig command using the following command: ``` apt-get install dnsutils -y ``` For CentOS and RHEL operating systems, install the dig command using the following command: ``` yum install bind9-utils -y ``` After installing the dig command, verify the dig version using the following command: ``` dig -v ``` Sample output: ``` DiG 9.9.5-3ubuntu0.19-Ubuntu ``` ## Step 2 – Basic Dig Command Running a dig command without any options will display the A record of the target domain. For example, perform a DNS lookup for a domain ubuntu.org run the following command: ``` dig ubuntu.com ``` Sample output: ``` ; <<>> DiG 9.9.5-3ubuntu0.19-Ubuntu <<>> ubuntu.com ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 9230 ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ;; QUESTION SECTION: ;ubuntu.com. IN A ;; ANSWER SECTION: ubuntu.com. 77 IN A 91.189.88.181 ubuntu.com. 77 IN A 91.189.88.180 ;; Query time: 263 msec ;; SERVER: 127.0.1.1#53(127.0.1.1) ;; WHEN: Tue Aug 24 08:55:56 IST 2021 ;; MSG SIZE rcvd: 71 ``` In the above output, you can find the main information in the ANSWER SECTION. ## Step 3 – Query With Specific DNS Server Running the dig command without any options will use the DNS server specified in the /etc/resolv.conf. You can also query the domain using the specific DNS server. Run the following command to query the ubuntu.com domain using the DNS 4.4.4.4: ``` dig @8.8.4.4 ubuntu.com ``` Sample output: ``` ; <<>> DiG 9.9.5-3ubuntu0.19-Ubuntu <<>> @8.8.4.4 ubuntu.com ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 25217 ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 512 ;; QUESTION SECTION: ;ubuntu.com. IN A ;; ANSWER SECTION: ubuntu.com. 40 IN A 91.189.88.181 ubuntu.com. 40 IN A 91.189.88.180 ;; Query time: 130 msec ;; SERVER: 8.8.4.4#53(8.8.4.4) ;; WHEN: Tue Aug 24 09:00:48 IST 2021 ;; MSG SIZE rcvd: 71 ``` ## Step 4 – Querying ALL DNS Records Types If you want to get the information of all DNS records, run the following command: ``` dig @8.8.4.4 ubuntu.com ANY +noall +answer ``` Sample output: ``` ; <<>> DiG 9.9.5-3ubuntu0.19-Ubuntu <<>> @8.8.4.4 ubuntu.com ANY +noall +answer ; (1 server found) ;; global options: +cmd ubuntu.com. 3599 IN SOA ns1.canonical.com. hostmaster.canonical.com. 2018054375 10800 3600 604800 3600 ubuntu.com. 3599 IN MX 10 mx.canonical.com. ubuntu.com. 599 IN NS ns1.canonical.com. ubuntu.com. 599 IN NS ns2.canonical.com. ubuntu.com. 599 IN NS ns3.canonical.com. ubuntu.com. 59 IN AAAA 2001:67c:1360:8001::2b ubuntu.com. 59 IN AAAA 2001:67c:1360:8001::2c ubuntu.com. 59 IN A 91.189.88.180 ubuntu.com. 59 IN A 91.189.88.181 ``` ## Step 5 – Querying Only Answer Section You can use the options **+noall** and **+answer** to display only the answer section. ``` dig @8.8.4.4 ubuntu.com +noall +answer ``` Sample output: ``` ; <<>> DiG 9.9.5-3ubuntu0.19-Ubuntu <<>> @8.8.4.4 ubuntu.com +noall +answer ; (1 server found) ;; global options: +cmd ubuntu.com. 12 IN A 91.189.88.181 ubuntu.com. 12 IN A 91.189.88.180 ``` ## Step 6 – Querying A Record The “a record” in DNS is used to bind a domain name with an IP address. You can use the **+short** option to query the a record of a specified domain. ``` dig ubuntu.com A +short ``` Sample output: ``` 91.189.88.180 91.189.88.181 ``` ## Step 7 – Querying NS Record The NS record contains the information of a list of authoritative DNS servers for a domain name. You can use the NS option to query NS records: ``` dig +nocmd ubuntu.com NS +noall +answer ``` Sample output: ``` ubuntu.com. 714 IN NS ns2.canonical.com. ubuntu.com. 714 IN NS ns3.canonical.com. ubuntu.com. 714 IN NS ns1.canonical.com. ``` ## Step 8 – Querying MX Record An MX record is a mail exchange record used to specify the mail server. You can use the MX option to query the MX record: ``` dig +nocmd ubuntu.com MX +noall +answer ``` Sample output: ``` ubuntu.com. 4502 IN MX 10 mx.canonical.com. ``` ## Step 9 – Querying TTL Record You can use the TTL option to query the TTL record: ``` dig +nocmd ubuntu.com TTL +noall +answer ``` Sample output: ``` ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 50516 ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ;; QUESTION SECTION: ;ubuntu.com. IN A ;; ANSWER SECTION: ubuntu.com. 59 IN A 91.189.88.180 ubuntu.com. 59 IN A 91.189.88.181 ;; Query time: 4 msec ;; SERVER: 127.0.1.1#53(127.0.1.1) ;; WHEN: Tue Aug 24 09:24:32 IST 2021 ;; MSG SIZE rcvd: 71 ``` ## Step 10 – Perform Reverse Lookup A reverse DNS lookup will display the information about the domain and hostname associated with an IP address. You can use the -x option followed by the IP address to perform a reverse DNS lookup: ``` dig +answer -x 8.8.8.8 ``` Sample output: ``` ; <<>> DiG 9.9.5-3ubuntu0.19-Ubuntu <<>> +answer -x 8.8.8.8 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 58576 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ;; QUESTION SECTION: ;8.8.8.8.in-addr.arpa. IN PTR ;; ANSWER SECTION: 8.8.8.8.in-addr.arpa. 7200 IN PTR dns.google. ;; Query time: 580 msec ;; SERVER: 127.0.1.1#53(127.0.1.1) ;; WHEN: Tue Aug 24 09:27:00 IST 2021 ;; MSG SIZE rcvd: 73 ``` ## Conclusion In the above guide, we explained how to use the dig command to query the DNS server through various examples. Now you can perform DNS lookups for domains using various options. Give it a try today on your [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # Sort Command in Linux with Examples > URL: https://www.atlantic.net/vps-hosting/sort-command-in-linux-with-examples/ | Published: 2021-10-25 | Updated: 2023-11-25 | Author: Hitesh Jethva Sort is a command-line utility in Linux that helps you to sort the data in a file line by line. It has a lot of options that allow you to arrange the record in a specific order. It supports sorting, in reverse order, by month, by number, alphabetically, and more. The sort command only prints the sorted output; it doesn’t actually sort the files. In this post, we will show you how to use the sort command with examples in Linux. ## 1. Sort a File Alphabetically By default, the sort command will sort lines alphabetically. For the purpose of this tutorial, create a new file named file.txt: ``` nano file.txt ``` Add the following lines: ``` baroda ahmedabad Baroda rajkot jamnager junagadh Surat Gandhinagar ``` Save the file, then use the sort command to sort the file alphabetically: ``` sort file.txt ``` Sample output: ``` ahmedabad baroda Baroda Gandhinagar jamnager junagadh rajkot Surat ``` The sort command only sorts the output of the file. If you want to save the sorted file, then run the following command: ``` sort file.txt > sortedfile.txt ``` ## 2. Sort a File in Reverse Order You can use the -r flag with the sort command to sort the file in reverse order: ``` sort -r file.txt ``` Sample output: ``` Surat rajkot junagadh jamnager Gandhinagar Baroda baroda ahmedabad ``` ## 3. Sort a File by Number You can use the **-n** flag to sort the file from lowest number to highest number. First, let’s create a sample file: ``` nano file.txt ``` Add the following lines: ``` 1. Hitesh 4. Jayesh 2. Vyom 7. Disha 3. Ramesh 9. Vrat ``` Save and close the file, then use the sort command to sort a file by number: ``` sort -n file.txt ``` Sample output: ``` 1. Hitesh 2. Vyom 3. Ramesh 4. Jayesh 7. Disha 9. Vrat ``` ## 4. Sort a Mixed-case File If a file contains lowercase and uppercase content, then the sort command will sort uppercase first. In this case, you can use the **-f** option to ignore the case. Let’s create a sample file: ``` nano file.txt ``` Add the following content: ``` Haresh hamir Hari heta himani ``` Now, use the sort command with -f option: ``` sort -f file.txt ``` Sample output: ``` hamir Haresh Hari heta himani ``` ## 5. Check If a File is Sorted You can use the **-c** option to check if a file is sorted or not. ``` sort -c file.txt ``` Sample output: ``` sort: file.txt:2: disorder: hamir ``` If there is no output, then the file is sorted. ## 6. Sort a File and Remove Duplicates You can also use the **-u** option to find and remove the duplicate lines from the sorted output. Let’s create a sample file: ``` nano file.txt ``` Add the following contents: ``` Hitesh Jayesh Jayesh Hitesh Samir Ram ``` Now, use the sort command to remove the duplicate lines from the sorted output: ``` sort -u file.txt ``` Sample output: ``` Hitesh Jayesh Ram Samir ``` ## 7. Sort a File by Month You can pass the **-M** option with the sort command to sort a file by month name. Let’s create a sample file: ``` nano file.txt ``` Add the following lines: ``` january march june february september december ``` Save and close the file then sort a file by month using the following command: ``` sort -M file.txt ``` Sample output: ``` january february march june september december ``` ## 8. Sort a File by Column If you have a file with multiple columns and want to sort any specific column, then you can use the **-k** option. Let’s create a sample file to test. ``` nano file.txt ``` Add the following lines: ``` 2. anand 4. ear 3. bharat 1. janak 5. canal ``` Save and close the file, then sort the second column using the following command: ``` sort -k2 file.txt ``` Sample output: ``` 2. anand 3. bharat 5. canal 4. ear 1. janak ``` To sort the first column, run: ``` sort -k1 file.txt ``` Sample output: ``` 1. janak 2. anand 3. bharat 4. ear 5. canal ``` ## Conclusion In this guide, we explained how to sort a file with the sort command in Linux. You can now experiment with the sort command with other options and check the result. You can start using the command now on your [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # Penalties for Non-Compliance of HIPAA: What Is the Fine? Can You Get Jail Time? > URL: https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-penalty-for-a-hipaa-violation/ | Published: 2021-10-26 | Updated: 2026-06-17 | Author: Richard Bailey ### **What Is a HIPAA Violation?** A HIPAA violation is the unauthorized disclosure of protected health information or the failure to provide timely access to patient data to authorized individuals against the mandates of the Health Insurance Portability and Accountability Act, or HIPAA. Those who follow Healthcare IT news will often see stories about large HIPAA settlements enforced by the US Department of Health & Human Services (HHS). The biggest violation so far in 2021 is [Lifetime Healthcare Companies](https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/excellus/index.html)‘ violation, where 9.3 million people were affected and a $5.1 million fine was enforced. In 2020, [Premera Blue Cross](https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/premera/index.html) was the biggest violation; 10.4 million people were impacted and a $6.9 million fine was handed down. No HIPAA violation situation is ever the same as another, and not all penalties will be as severe as the examples above. If your organization is found to be in violation of HIPAA, you won’t necessarily have to pay millions of dollars. Such massive penalties are only for the very worst offenders, but what are the general parameters for violations? ## Summary of OCR HIPAA Settlements 2021 At the time of writing, October 2021, there have been eight settlements with the OCR so far this year. The majority of settlements are for healthcare organizations failing to give timely access to medical records, which is a mandatory requirement of HIPAA. | **Covered Entity** | **Reason** | **Individuals Impacted** | **Amount** | | --- | --- | --- | --- | | Diabetes, Endocrinology & Lipidology Center, Inc. (“DELC”) | Failed to give timely access to Patient Data | 1 | $5,000 | | AEON Clinical Laboratories (Peachstate) | Unsecured PHI in Telehealth App | 3 | $25,000 | | Banner Health ACE | Failed to give timely access to Patient Data | 1 | $200,000 | | Lifetime Healthcare Companies | Data Breach | 93,000,000 | $5,100,000 | | Renown Health, P.C | Failed to give timely access to Patient Data | 1 | $75,000 | | Sharp Rees-Stealy Medical Centers | Failed to give timely access to Patient Data | Unknown | $70,000 | | Arbour Hospital | Failed to give timely access to Patient Data | 1 | $65,000 | | Village Plastic Surgery | Failed to give timely access to Patient Data | 1 | $30,000 | ## Historical OCR Settlements (2016-2020) Following on from our 2021 figures, the HIPAA Journal has published data from 2016 to 2020. We have compiled this data to show the biggest penalties of each year. | **Covered Entity** | **Reason** | **Individuals Impacted** | **Amount** | **Year** | | --- | --- | --- | --- | --- | | University of Rochester Medical Center | Loss of flash drive/laptop; no encryption | 43 | $3,000,000 | 2019 | | Sentara Hospitals | Breach notification failure; business associate agreement failure | 577 | $2,175,000 | 2019 | | Touchstone Medical Imaging | No BAAs; insufficient access rights; risk analysis failure; failure to respond to a security incident; breach notification failure; media notification failure | 307,839 | $3,000,000 | 2019 | | Texas Department of Aging and Disability Services | Risk analysis failure; access control failure; information system activity monitoring failure; impermissible disclosure of 6,617 patients ePHI | 6,617 | $1,600,000 | 2019 | | Jackson Health System | Multiple Privacy Rule, Security Rule, and Breach Notification Rule violations | 25,661 | $2,154,000 | 2019 | | Cottage Health | Risk analysis and risk management failures; No BAA | 62,500 | 3,000,000 | 2018 | | Anthem Inc | Risk analysis failure; Insufficient reviews of system activity; Failure to respond to a detected breach; Insufficient technical controls to prevent unauthorized ePHI access | 78,800,000 | $16,000,000 | 2018 | | Fresenius Medical Care North America | Risk analysis failures; Impermissible disclosure of ePHI; Lack of policies covering electronic devices; Lack of encryption; Insufficient security policies; Insufficient physical safeguards | 521 | $3,500,000 | 2018 | | University of Texas MD Anderson Cancer Center | 3 breaches resulting in an impermissible disclosure of ePHI; No Encryption | 34,883 | $4,348,000 | 2018 | | Memorial Healthcare System | Impermissible access of PHI by employees; Impermissible disclosure of PHI to affiliated physicians’ offices | 115,143 | $5,500,000 | 2017 | | Cardionet | Theft of an unencrypted laptop computer | 1,391 | $2,500,000 | 2017 | | Memorial Hermann Health System | Disclosure of patient’s PHI to the media | 1 | $2,400,000 | 2017 | | 21st Century Oncology | Multiple HIPAA violations | 2,213,597 | $2,300,000 | 2017 | | MAPFRE Life Insurance Company of Puerto Rico | Theft of an unencrypted USB storage device | 2,209 | $2,200,000 | 2017 | | Children’s Medical Center of Dallas | Theft of unencrypted devices | 6,262 | $3,200,000 | 2017 | ### **Legislative Basis** The OCR and Centers for Medicare & Medicaid (CMS) are authorized to enforce HIPAA. The amount of some penalties can be frighteningly high, including civil and criminal judgments. The stimulus package that was adopted in 2009, called the American Recovery and Reinvestment Act (ARRA), detailed the specific minimum and maximum limits for healthcare privacy and security violations. “The Secretary of the Department of Health and Human Services (HHS) still has discretion in determining the amount of the penalty,” [according to the American Medical Association](http://www.ama-assn.org/ama/pub/physician-resources/solutions-managing-your-practice/coding-billing-insurance/hipaahealth-insurance-portability-accountability-act/hipaa-violations-enforcement.page), “based on the nature and extent of the violation and the nature and extent of the harm resulting from the violation.” However, there is an exception: if the agency determines that you were not purposely neglectful, you will have one full month to rectify the situation. **Consequences of HIPAA Violations – Civil Penalties for HIPAA Non-Compliance** | ** ** | **HIPAA Violation** | **Minimum Penalty** | **Maximum Penalty** | | --- | --- | --- | --- | | **Scenario #1** | The organization or employee  was unaware that they were in violation of the law, despite operating soundly | $100 for each instance of noncompliance, up to $25,000 total (the highest amount that can be assessed by an attorney general at the state level) | $50,000 for each instance, totaling up to $1.5 million | | **Scenario #2** | The company was noncompliant not because of purposeful neglect but because of unexpected causes | $1000 for each instance, up to $100,000 total | $50,000 for each instance, totaling up to $1.5 million | | **Scenario #3** | Purposeful neglect occurred, but the company took corrective action within an acceptable time window | $10,000 for each instance, up to $250,000 total | $50,000 for each instance, totaling up to $1.5 million | | **Scenario #4** | Purposeful neglect occurred, and the company did not implement the steps of a corrective plan | $50,000 for each instance, up to $1.5 million total | $50,000 for each instance, totaling up to $1.5 million | ## HIPAA Non-Compliance Criminal Penalties – Can You Be Imprisoned? According to data published by the HHS, up to 31st August 2021, the OCR has received nearly 273,000 compliance-related complaints, with over 1101 being investigated. However, in only 100 cases the OCR has settled or imposed a civil money penalty (since 2008), totaling $130,980,482.00 so far. Jail terms are rare, but not unheard of. In February 2017, Jeffery Luke was jailed for stealing PHI from his employer’s secured Google Drive accounts. In January 2020, Stacey Lavette Hendricks was imprisoned for 48 months for PHI identity theft. “Covered entities and specified individuals … who ‘knowingly’ obtain or disclose individually identifiable health information in violation of the Administrative Simplification Regulations face a fine of up to $50,000,” explained the AMA report, “as well as imprisonment up to one year.” Sentencing can be more severe, though. Anything that violates the law and involves deception carries a maximum sentence of $100,000 and/or five years imprisonment. Violations that occur because individual plans to use the data for their own gain or for malevolent reasons are penalized with judgments up to $250,000, accompanied by prison sentences as high as ten years. ## Covered Entities & Individual People The Department of Justice decided that if it is determined that a crime has been committed, covered entities (healthcare plans, data clearinghouses, and providers) can be held directly liable. Leadership at a covered entity can also be subject to criminal investigation and sentencing by piercing the corporate veil. Even if someone in an executive position at a company where misuse takes place didn’t do anything that was specifically non-compliant, they still may be guilty as a co-conspirator or accomplice. ## “Knowingly” The Department of Justice specifically targeted a word within the HIPAA crime provisions that are a source of confusion: what does knowingly mean? Knowingly refers to the highest criminal penalty situation listed above, the “for their own gain” scenario (bolded above). According to Law360, “Under the statute, covered entities and individuals who ‘knowingly’ obtain or disclose individually identifiable health information with the intent to” profit from it or hurt someone face the stiffest penalties. The Department of Justice clarified in 2005 that the word referred to knowledge of HIPAA law rather than knowledge of a particular instance of noncompliance. ## Exclusion & Upholding the Law The federal government can remove any healthcare plan, provider, or clearinghouse from the Medicare system if they have not adopted a universal, standardized medical code. In terms of enforcement, the OCR identifies and punishes HIPAA privacy violations. The Centers for Medicare & Medicaid (CMS) oversees security and uniform code. ## Choosing a Compliance Partner As you see above, the consequences of violating HIPAA can be extreme. Even if you don’t get fined millions, it’s not a productive way to spend money, and it’s not fun to end up on the HIPAA Wall of Shame. That’s why it’s extraordinarily important to choose a technological partner that specializes in healthcare [HIPAA Compliance Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) like Atlantic.Net. Our Virtual Private Servers offer a 100% uptime guarantee and can launch in under 30 seconds. Atlantic.Net stands ready to help you attain fast compliance with a range of certifications, such as SOC 2 and SOC 3, HIPAA, and HITECH, all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, visit us at [www.atlantic.net](https://www.atlantic.net), call 866-618-DATA (3282), or email us at [sales@atlantic.net](mailto:sales@atlantic.net). --- # Monitor Linux Network Bandwidth Usage in Real Time with nload > URL: https://www.atlantic.net/vps-hosting/monitor-linux-network-bandwidth-usage-in-real-time-with-nload/ | Published: 2021-10-27 | Updated: 2024-06-04 | Author: Hitesh Jethva nload is a command-line tool used for monitoring network traffic and bandwidth usage in real-time. It will display the incoming and outgoing traffic using two graphs. This console-based application also displays info like the total amount of transferred data and min/max network. In this post, we will show you how to install and use nload to monitor network bandwidth usage in real-time. ## Step 1 – Install Nload By default, nload is not installed on Linux operating system. For Debian or Ubuntu operating system, install nload using the following command: ``` apt-get install nload -y ``` For CentOS or RHEL operating system, install nload using the following command: ``` yum install epel-release -y yum install nload -y ``` ## Step 2 – Use Nload to Monitor Network Usage You can run the nload command by specifying a network interface. Otherwise, it will auto-detect the network interface and start monitoring. ``` nload wlan0 ``` You should see the bandwidth usage on the wlan0 network interface on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/08/p1-11-1024x567.png) Press**F2** to display the options windows: ![Display option window](https://www.atlantic.net/wp-content/uploads/2021/08/p2-11-1024x566.png) Press **F5** to save the current settings to the user’s configuration file. ![Save current settings](https://www.atlantic.net/wp-content/uploads/2021/08/p3-5-1024x449.png) Press**F6** to reload settings from the user’s configuration file. Press **CTRL + C** to close the nload window. You can use the **-m** flag with nload command to display network usage of all network interfaces. ``` nload -m ``` You can use the -t flag to sets the refresh interval of the display in milliseconds. ``` nload -t 700 -m ``` To display all options available with nload, run: ``` nload --help ``` You should see the Nload help page on the following screen: ![Nload help page](https://www.atlantic.net/wp-content/uploads/2021/08/p5-4.png) ## Conclusion In the above guide, you learned how to use the nload tool to monitor network usage in Linux. This tool will help you to monitor the network traffic and bandwidth usage in Linux. Get started today on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net. --- # Top 10 Network Monitoring Software Solutions > URL: https://www.atlantic.net/hipaa-compliant-hosting/top-10-network-monitoring-software-solutions/ | Published: 2021-10-29 | Updated: 2025-09-19 | Author: Richard Bailey Network monitoring systems allow businesses and organizations to oversee the performance of their networked components. These tools can alert network administrators to any issues, allowing them to be solved quickly and avoiding unnecessary downtime. By deploying a top network monitoring solution, businesses can save both time and money. With much of the population working from home over the last 18 months, these monitoring tools have become more essential than ever. There are many network monitoring options to choose from, ranging from free and open-source tools all the way up to costly high-end enterprise-grade solutions. The right network monitoring software for your business or organization will depend upon your individual needs. We have compiled and ranked a list of some of the leading network monitoring solutions to help with your decision. ## Top 10 Network Monitoring Solutions ## 1. Paessler PRTG Network Monitor PRTG Network Monitor is a powerful agentless all-in-one network monitoring solution for businesses of all sizes. It enables administrators to monitor all the systems, devices, applications, and traffic within their network. PRTG uses technologies such as SNMP, WMI, SSH, flow protocols or packet sniffing, HTTP requests, and SQL. This software would be a great option for businesses and organizations with little experience in network monitoring thanks to its easy-to-use and customizable dashboard. Users have access to useful real-time network maps with live status information and can adapt the notification system to create flexible alerts. PRTG Network Monitor is a cost-effective solution, offering a range of paid plans, and users can benefit from a free 30-day trial. ## 2. Site 24×7 Network Monitoring Site 24X7 Network Monitoring is a cloud-based complete network monitoring solution that can automatically detect all network-connected devices and create a network topology map. Some of the key features of Site 24×7 include network mapping, VoIP monitoring, SNMP trap processing, sensor monitoring, device templates, and multivendor support.  Site 27/4 allows users to track key performance metrics, such as memory and CPU usage, undersize and oversize packets, buffer failures, and VPN latency. A limited version of Site 24×7 is available for free; otherwise, there are four paid versions of the software tailored to different needs. ## 3. LogicMonitor Trusted by more than 2000 global enterprises, LogicMonitor is a fully-automated and cloud-based infrastructure monitoring platform designed for enterprise IT teams and Managed Service Providers. LogicMonitor can be used to monitor your entire infrastructure using one platform and has over 2000 pre-configured integrations. Its Anomaly Detection software is great at spotting trend deviations in network traffic, and its lightweight collector agents make logic monitor unintrusive. ## 4. ManageEngine OpManager The ManageEngine Network Performance Monitor allows you to immediately pinpoint issues on your internet network by monitoring network device availability, CPU and memory, network traffic, errors and discards, and WAN performance. Notifications are sent via email, text message, or push notification to a cell phone, and each alert can be tuned to the thresholds of your choosing. OpManager’s NetFlow module provides in-depth visibility on network traffic patterns and bandwidth utilization with support for NetFlow, sFlow, jFlow, IPFIX, and more. ## 5. Progress WhatsUp Gold WhatsUp Gold has always been famous for its network monitoring capabilities, and its distinguishing “party trick” is its dynamic network discovery capabilities and network mapping that result in significantly less administrative overhead. You can configure real-time alerts for networks, traffic, and even server infrastructure. Logging is another great feature, verbose device data logging allows you to monitor, filter, search and alert from networking syslogs, then intelligently archive the logs to any location using a predefined retention period – perfect for compliance requirements. ## 6. Spiceworks Network Monitor Spiceworks is a hugely popular network monitoring tool largely because it is 100% free for personal and business use. Best of all, it’s actually very good considering it is a free solution. It contains all the standard network tools for uptime, CPU, memory, and more, but it also lets you compare network states, like a before and after snapshot. This makes spotting network changes very easy and helps pinpoint issues quickly. Other helpful features include the ability to track when licenses are set to expire (perfect for SSL/TLS certs), built-in checks for whether antivirus is available and up to date, and basic vulnerability scanning to detect when system updates are required. ## 7. Idera Uptime Infrastructure Monitor Idera is an all-in-one agent-based tool that monitors network deixes, servers, VMs, and applications via a clean, user-friendly interface. The network tool offers the usual standard features for gaining visibility of your network. Other great features include the capability to quickly view the status of core networks and alert you when the network starts slowing down. Additionally, Idera can integrate with a huge library of APIs. ## 8. Zabbix While Zabbix is a well-known monitoring solution, did you know they have a network monitor tool available too? Zabbix focuses on 3 core networking metrics: network performance, network health, and configuration changes. This includes monitoring features such as network bandwidth usage, packet loss rate, interface error rate, high CPU or memory utilization, link status, device temperature, power supply state. If the network state changes, you will be alerted; some examples include a new device being added or removed, firmware releases, or serial number changes, to name just a few. ## 9. New Relic New Relic is an entire suite of monitoring tools with a focus on the entire network stack of an application. New Relic is available as a managed service (New Relic One), or you can install and manage it locally. The Network Monitor (NPM) analyzes your network performance data to understand the root cause of issues fast, allowing you to find network glitches using AI routines. ## 10. ConnectWise Automate ConnectWise is a feature-rich RMM popular with cloud MSPs. It can discover assets automatically, enabling endpoint management of devices making compliance simple. You can patch network devices from the console and remotely monitor the entire environment, making it easy to spot network bottlenecks, performance issues, and security threats. ## Partnering with Atlantic.Net Atlantic.Net Engineers have first-hand experience with the complexities of monitoring networked systems. Because there are so many products out there, it might seem impossible to choose the right one. Network monitoring is so important, especially in today’s security-conscious world. Having the ability to intelligently monitor your entire stack is essential, but some tools run the risk of becoming an administrative nightmare as the network grows with your business. The Atlantic.Net Cloud Platform will support all of these network monitoring tools discussed here, and we are available to discuss your monitoring needs. Are you looking for a leading [hosting provider](https://www.atlantic.net/hosting-services-provider/) to host your monitoring solution? Look no further than Atlantic.Net. With over 30 years of proven experience, our [full suite of managed services](https://www.atlantic.net/managed-services/) and always available professional support team can build the perfect solution for your business or organization. We also include a complimentary monitoring solution for our cloud customers. Atlantic.Net stands ready to help you attain fast compliance with a range of certifications, such as SOC 2 and SOC 3, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/), and HITECH, all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, visit us at www.atlantic.net, call 866-618-DATA (3282), or email us at [sales@atlantic.net](mailto:sales@atlantic.net). To find out more about the solutions that we offer, [contact our sales team today!](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) --- # How to Set Linux Process Priority Using nice and renice Commands > URL: https://www.atlantic.net/vps-hosting/how-to-set-linux-process-priority-using-nice-and-renice-commands/ | Published: 2021-10-29 | Updated: 2024-09-25 | Author: Hitesh Jethva This post will show you how to set Linux Process Priority with Nice and renice commands. ## What Is the Nice Command Used For? Put simply, Nice is a command-line utility in Linux that allows you to set processes’ “niceness” value. Nice is used to start a process with a defined priority. When you start any program or process without any defined priority, nice set a default priority of 10. A niceness of 19 is the lowest priority, while -20 is the highest priority. The nice command is very useful when several processes demand more resources than the CPU. ## What Is the Renice Command Used For? Renice is very similar to nice and is used to change the priority of an already running process. If your system is running very slow due to a lengthy process, you can reduce or increase the priority of that process with the help of renice command. Priority is a value that you can assign to each process, and the kernel uses this value to schedule the execution of the process. - **0-99** is the priority value used for real-time priority assignments. - **100-139** is the priority value that the users assign. ## Step 1 – Display Nice Value of a Process In Linux, when you start any process or program, it gets the default priority of 0. You can use the ps or top command to display the priority of a running process. To check the Nice value of the Nginx process, run the following command: ``` ps -fl -C nginx ``` You should see the priority of the Nginx process in the NI column as shown below: ``` F S UID PID PPID C PRI NI ADDR SZ WCHAN STIME TTY TIME CMD 5 S www-data 3156 3155 0 80 0 - 21700 - 10:33 ? 00:00:00 nginx: worker process ``` To display the nice value of all running processes, use the top command: ``` top ``` You should see the nice value of all processes in the NI column. ## Step 2 – Change the Priority of Process with Nice Command The nice command can not change the priority of the running process. However, you can use the nice command to start any program with pre-defined priority. For example, start a top program with a nice value 5: ``` nice -5 top ``` This will assign a priority value of 5 to the top. Now, open another terminal and verify the priority for the top as shown below: ``` ps -fl -C top ``` You should see the priority of the top command in the NI column: ``` F S UID PID PPID C PRI NI ADDR SZ WCHAN STIME TTY TIME CMD 4 S vyom 7966 7277 0 85 5 - 7323 poll_s 11:41 pts/14 00:00:00 top ``` You don’t need root privileges when you set a priority value higher than 0. You will need root privileges if you want to increase the priority of any process by assigning a negative value. For example, to increase the priority of the top command to -20, use the following command: ``` sudo nice --20 top ``` ## Step 3 – Change the Priority of Running Process with renice Command As you know, the nice command cannot change the priority of any running process. In this case, you will need to use the renice command to change the priority of a running process. Here, we will use the top process, which is already running. First, verify the current priority of the top process using the following command: ``` ps -fl -C top ``` Sample output: ``` F S UID PID PPID C PRI NI ADDR SZ WCHAN STIME TTY TIME CMD 4 S vyom 7966 7277 0 85 5 - 7323 poll_s 11:41 pts/14 00:00:03 top ``` As you can see, the priority of the top process is 5. Now, we will change the priority of the top process to -15. First, find the PID of the top process with the following command: ``` pidof top ``` Sample output: ``` 7966 ``` Now, run the following command by specifying the priority value and PID of the top: ``` sudo renice -n -15 -p 7966 ``` Sample output: ``` 7966 (process ID) old priority 5, new priority -15 ``` You can also change the priority of all processes a specific user owns. For example, change the priority of all processes owned by the root user, run: ``` sudo renice -n 10 -u root ``` ## Conclusion In this guide, you learned how to set and change the priority of any process using the nice and renice command. You can now easily increase and decrease the process priority per your needs. Start using nice and renice on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net. --- # Post-Pandemic: Top Cybersecurity Threats to Healthcare Security > URL: https://www.atlantic.net/hipaa-compliant-hosting/post-pandemic-top-cybersecurity-threats-to-healthcare-security/ | Published: 2021-10-31 | Updated: 2026-05-04 | Author: Alexander Wise How have cybersecurity threats changed during the pandemic? Last year started slowly in terms of cyberattacks, with fewer incidents reported in January than in previous years. Then, that all changed suddenly in February and March 2020 at the height of pandemic lockdowns. There was an unprecedented rise in hacking and malicious activity online during this time. Reports from businesses and cybersecurity experts continued to climb, reaching a three-fold spike in April compared to previous years. Unfortunately, this is not a new trend. The number of data breaches has been steadily rising since 2010, setting a new record in 2019, explains the HIPAA Journal. In addition, in 2020, the number of cyberattacks on healthcare [more than doubled](https://healthitsecurity.com/news/healthcare-cyberattacks-doubled-in-2020-with-28-tied-to-ransomware)! And now, in 2021, cyberattackers are expected to set another unwelcome record for [patient data breaches](https://www.forbes.com/sites/forbestechcouncil/2021/03/17/why-healthcare-could-face-unprecedented-cyber-threats-in-2021/?sh=11d83e7e5206). ## Top Cybersecurity Concerns for Health Care in the Post-Pandemic Period The majority of attacks at the onset of the COVID-19 pandemic fell into two broad categories: distributed denial of service ([DDoS](https://www.netscout.com/what-is-ddos/volumetric-attacks)) attacks, mostly volumetric, and password login attempts in the form of brute force and [credential stuffing](https://owasp.org/www-community/attacks/Credential_stuffing) attacks. In addition, there were also a larger number of reported malware attacks and web attacks than usual. ## 1. Attacks Targeting Telehealth When a national emergency was declared last year, the HHS loosened the application of fines for HIPAA privacy violations to facilitate wider adoption of [telemedicine](https://www.usnews.com/news/health-news/articles/2021-01-05/health-care-after-covid-the-rise-of-telemedicine) for patients and data sharing as more healthcare professionals began working from home. In addition, as HIPAA relaxed regulations, many providers started conducting e-visits with unsecured internet connections at home. The exact role of telehealth in data security breaches during the pandemic is unclear, but it’s certainly considered a runaway problem at this point. This is mainly because of the lack of comprehensive assessment and oversight of telemedicine’s data security landscape. Plus, reporting is hard to track, as often a period of time passes before victims understand that they were involved in an attack. Some forms of attack have targeted internet-facing remote desktop environments, patient-facing mobile apps,  or vulnerabilities in data transmission, encryption, and authentication by telemedicine providers. Additionally, hackers have exploited vulnerabilities in endpoint security and security patches, FTP, and RDP protocols regularly used for remote connections. Experts warn healthcare organizations to be aware that [HIPAA relaxation isn’t absolute](https://www.medpagetoday.com/practicemanagement/telehealth/88469). Most [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/what-do-i-need-to-do-to-become-hipaa-compliant-with-atlantic-net/) provisions for privacy and confidentiality are still in effect, including the need for providers to secure network connections. ## 2. DDoS Attacks Distributed denial of service attacks are dominating the pandemic cybersecurity challenges currently facing healthcare organizations. “Between January 2020 and March 2021, DDoS attacks increased by 55% and are becoming more complex, with 54% of incidents using multiple attack vectors,” [according to F5 Application Threat Intelligence](https://www.f5.com/labs/articles/threat-intelligence/ddos-attack-trends-for-2020). Volumetric DDoS attacks work by overwhelming network capacity with high volumes of malicious traffic. By using up the bandwidth of the targeted network or between the targeted network and the external internet, these attacks can cause real damage and cause an infrastructure to collapse. Professional hackers often combine volumetric DDoS attacks with application-layer attacks and changing techniques. They do this to evade static mitigation tools and draw security teams’ attention away from the real goal, which is Trojan Horse network penetration. At that point, the malicious actors can install malware and steal valuable patient data or try to extort money. DDoS attacks frequently target financial institutions and [cloud service providers](https://www.atlantic.net/vps-hosting/what-is-cloud-hosting/), but more hospitals and life science laboratories were the intended targets in this period than ever. During the pandemic, cybercriminals increasingly attempted to take advantage of vulnerabilities in healthcare organizations as they pivoted to remote work. Their attention was focused more on the emergency situation than on cybersecurity. Successful DDoS attacks have disrupted remote workers employed by a group of hospitals, interrupted internet services used to treat patients, and inhibited research activities. Of course, [these incidents](https://healthtechmagazine.net/article/2021/09/5-things-know-about-ddos-attacks-healthcare) were also costly to the healthcare organizations that had to restore service and mitigate the damages. These examples demonstrate the importance of proper security measures to prevent PHI breaches. ## 3. Ransomware Hospitals and healthcare networks are under siege by ransomware—including several government agencies like the FBI, CISA, and the Department of Health. Since the beginning of the pandemic, they have warned of “an increased and imminent cybercrime threat to U.S. hospitals and healthcare providers,” according to the [National Cyber Awareness System](https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-302a). While the healthcare industry was busy implementing the [pandemic protocol](https://www.ispartnersllc.com/cybersecurity-assessment-and-advisory-services/pandemic-planning/) and caring for critical patients, hackers were looking for ways to steal data and disrupt medical services. By October 2020, just six months into the pandemic, more than 24 hospital systems reported ransomware attacks. In the same period, researchers spotted more than [50,000 fake login pages](https://ironscales.com/blog/fake-login-pages-spoof-prominent-brands-phishing-attacks/) for 200 well-known organizations. Attackers are trying to distribute TrickBot and BazarLoader malware through sophisticated [phishing campaigns](https://healthitsecurity.com/news/4-sophisticated-phishing-campaigns-impacting-the-healthcare-sector). Healthcare is currently the biggest target for credential theft through [email phishing](https://easydmarc.com/blog/phishing-attacks-recognize-and-avoid-email-phishing/), social engineering, and phony login pages. These fraudulent activities are highly successful in luring employees of healthcare entities or their third-party service providers to insert their username and password into a false login page embedded in an email or a phishing website. By checking a [DMARC report](https://powerdmarc.com/how-to-read-dmarc-reports/), you can track and avoid these threats. Healthcare organizations need to be vigilant against [ransomware attacks](https://www.atlantic.net/hipaa-compliant-hosting/the-growing-threat-of-ransomware-in-2021/) and phishing because they are increasing even as the pandemic wanes. Plus, hackers are continuing to improve their techniques, making attempts even more challenging to detect. Some [cyberattacks](https://www.aura.com/learn/digital-security) have even used zero font to bypass automated inbox security controls or posed as emails from entities like the CDC or a hospital’s technical support staff. Learn about [Atlantic.Net’s Fully Managed Malware Protection & HIPAA Compliant Cloud Services](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-security/). ## HIPAA Compliance & Cybersecurity Go Hand-in-Hand Healthcare organizations shouldn’t have to face today’s threat landscape alone. However, partnering with cybersecurity professionals is the surest way to block attacks in the present and prepare for the threats on the horizon. [I.S. Partners, LLC](https://www.ispartnersllc.com/) specializes in testing, certifying, and improving risk mitigation measures. Read more about [Rising IT Challenges in Healthcare as a Result of the Pandemic](https://www.ispartnersllc.com/blog/healthcare-it-security-coronavirus-pandemic/). --- # Should You Choose an AMD or Intel-Based Dedicated Server? > URL: https://www.atlantic.net/dedicated-server-hosting/should-you-choose-an-amd-or-intel-based-dedicated-server/ | Published: 2021-11-01 | Updated: 2026-02-28 | Author: Alexander Wise Many choices need to be considered when selecting a dedicated server hosting solution. One of the most basic questions to consider is what type of CPU best fits your needs and business objectives. The CPUs powering the servers you select can have an impact on your ability to address your expected workload. This article is intended to help you decide between processors from Intel and those from AMD (Advanced Micro Devices). We will provide a comparison of the offerings available from the two chipmakers and attempt to identify key differences that may influence your decision when selecting [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/). Before attempting to choose a [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) platform, you need to understand your business requirements and the applications you intend to run. These factors may influence your selection to take advantage of the features provided by a specific chip manufacturer. Both Intel and AMD have many different processor models on the market. The following discussion will highlight some of these chips but is not meant to be an exhaustive inventory of the products available from these manufacturers. ## Preliminary Data Gathering When starting the process of selecting a CPU for a new server, different CPU choices might make the most sense based on how you will be using the server. Factors to consider when choosing a CPU include the following. - Obtaining hardware recommendations for the applications you intend to run on the server is a good place to start. Certain developers will suggest a specific CPU or clock speed as a minimum requirement for running their software. Take into account whether multiple core applications will be run from the same server. In the absence of specifications from the developer, try to see what type of hardware other customers are deploying to support the application. - The number of concurrent users accessing the server will have a substantial effect on CPU load. As the number of users increases, so do CPU requirements. In some cases, it is more efficient to deploy multiple servers rather than attempting to service them all with a single, high-powered machine. - Plan for future growth when selecting all aspects of a dedicated server, including its CPU. Estimating the number of concurrent users the server needs to handle in six months to a year can help determine the proper CPU. Failure to plan for growth may necessitate a CPU upgrade or deploying additional servers to address user requirements. ## Overview of Intel and AMD CPUs Let’s take a look at some of the most powerful CPUs currently offered by these two chip producers. We will concentrate on CPUs recommended by the manufacturers for use in data centers or servers as opposed to chips for desktop or gaming machines. ### [Intel](https://www.intel.com/content/www/us/en/products/details/processors.html) Intel produces multiple families of processors that are designed to power everything from personal laptops to mission-critical, cloud-based dedicated servers. Specifically, Intel’s Xeon and Xeon Scalable processors are the company’s most powerful server-focused CPUs. They are available in a large variety of configurations to meet the diverse business needs of their customers. Intel Xeon Scalable processors are available in many models to address the unique needs of a computing environment. They offer varying power, functionality, and price points to handle virtually any type of dedicated server. Features common to all varieties of Xeon Scalable processors include: - Built-in AI (artificial intelligence) acceleration supported by [data science tools and multiple smart solutions](https://www.intel.com/content/www/us/en/artificial-intelligence/xeon-scalable.html); - Intel SGX security solution which protects data and application code in real-time; - Intel Optane Persistent Memory that provides up to 6TB of system-level memory capacity when combined with traditional DRAM. Following are some examples of the processor classes available. As you move through the classes, the available feature set is expanded, allowing for the CPUs to be used in different usage scenarios. **Intel Xeon Bronze Processors**: - 8 cores; - 9GHz speed; - 11MB cache. **Intel Xeon Silver****Processors**: - 8-16 cores; - 11MB-20MB cache; - 3GHz to 3.2GHz base speed with 3.2GHz to 4.0GHz max turbo speed. **Intel Xeon Gold****Processors**: - 8-32 cores; - 12MB-48MB cache; - 0GHz to 3.6GHz base speed with 3.1GHz to 4.03GHz max turbo speed. **Intel Xeon Platinum****Processors**: - 8-40 cores; - 24MB-60MB cache; - 1GHz to 3.9GHz base speed with 3.0GHz to 4.4GHz max turbo speed. ### AMD AMD’s 3rd Generation EPYC processors are the company’s current top-of-the-line offering for use in servers. These CPUs are widely supported by cloud vendors and have been used for many processor-intensive high-performance computing solutions. AMD supports all features across the board for all of its processors. **AMD EPYC 7002 Series Processors** offer powerful performance powered by these base specifications: - Up to 64 cores and 128 threads; - Speeds up to 2.6GHz base, 3.4GHz boost, and 256MB cache; - 4TB of DDR4 memory capacity across 8 memory channels; - 128 PCIe 4.0 lanes; - AMD Infinity Guard proprietary security solution. **AMD EPYC 7003 Series Processors** are similarly powered with: - Up to 64 cores and 128 threads; - Speeds up to 2.45GHz base, 3.675GHz boost, and 256MB cache; - 4TB of DDR4 memory capacity across 8 memory channels; - 128 PCIe 4.0 lanes; - AMD Infinity Guard proprietary security solution. ## Processor Type of Specific Applications Intel processors commonly provide enhanced performance for applications that only make use of a single core due to the TPC per core with Intel being faster over AMD with a single core versus a single core. Threaded applications that use multiple cores simultaneously can take advantage of the greater core density available in AMD CPUs. This fact highlights the need to understand the applications that will be using your dedicated server and to keep in mind hardware recommendations made by the developer. Chip producers offer many models to allow systems to be configured to meet customers’ specifications. There is no need to overspend for unnecessary computing power or underspend and live with degraded performance when putting together a [Dedicated Host](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) solution. ## Chip Supply, Demand, and Innovation Executives at both Intel and AMD are concerned with the current chip shortage that is affecting many companies across numerous market sectors. The effects of the COVID-19 pandemic and supply-chain disruption have severely impacted the chip manufacturers and are not expected to be resolved until late 2022 or 2023. CPU producers may be forced to concentrate on their most profitable lines while waiting for the shortage to pass. Dealing with this issue can also hinder innovation and delay the introduction of new products. Intel and AMD are industry leaders in large part because of their ability to innovate and develop products that integrate with emerging standards. Both manufacturers are slated to support DDR5 and PCIe 5.0. It appears that Intel’s 12th generation CPUs will beat AMD to market and offer this support in late 2021. AMD’s offerings should start appearing in early 2022. ## Making the Choice in CPU for Dedicated Hosts The choice of CPU is important but is not the only factor that determines whether your chosen dedicated hosting solution provides the performance to meet your business objectives. In the end, a serviceable solution can be obtained using processors from either Intel or AMD. While the processor can make a difference, the real value comes from working with a cloud vendor that understands your needs and will tailor a solution to address them. Locate a partner that offers the networking, memory, and storage capabilities to complement your server’s CPU to extract the most performance for your money. Your vendor may concentrate on a specific chip manufacturer when designing your system. Depending on the amount of processing power your business requires, the cost of the dedicated server’s CPU will vary. A collaboration with a cloud provider like [Atlantic.Net](https://www.atlantic.net) can help you select the right Intel processor to handle your current workload and position you for future growth. --- #### Read More About Bare Metal Servers - [Bare Metal Server](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) Hosting - [Infrastructure as a Service vs. Platform as a Service](https://www.atlantic.net/dedicated-server-hosting/what-is-iaas/) --- --- # How to Install phpBB with LEMP on Rocky Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-phpbb-with-lemp-on-rocky-linux-10/ | Published: 2021-11-02 | Updated: 2025-10-25 | Author: Hitesh Jethva phpBB is a free, open-source, web-based flat-forum bulletin board software solution used by many popular discussion forums on the Internet. phpBB stands for “**PHP Bulletin Board**.” It supports all major database engines including MySQL, PostgreSQL, Oracle, and SQLite. It offers hundreds of style and image packages, allowing you to create and customize a very unique forum in minutes. In this post, we will show you how to install phpBB with LEMP on Rocky Linux 10. ## Step 1 – Install LEMP Stack First, you will need to install the EPEL repository on your server. You can install it using the following command: ``` dnf install epel-release -y ``` Next, install the Nginx server with the following command: ``` dnf install nginx -y ``` After installing Nginx, start and enable the Nginx service with the following command: ``` systemctl start nginx systemctl enable nginx ``` Next, it is recommended to install the latest version of MariaDB on your server. To do so, first reset the MariaDB default repository and enable the latest repository: ``` dnf module reset mariadb dnf module enable mariadb:10.5 ``` Next, install the MariaDB server with the following command: ``` dnf install mariadb-server -y ``` Once MariaDB is installed, start and enable the MariaDB service with the following command: ``` systemctl start mariadb systemctl enable mariadb ``` Next, install the PHP, PHP-FPM, and other packages with the following command: ``` dnf php php-fpm php-curl php-xml php-zip php-mysqlnd php-intl php-gd php-json php-ldap php-mbstring php-opcache unzip -y ``` Once all the packages are installed, edit the php.ini file and make some changes: ``` nano /etc/php.ini ``` Change the following values: ``` max_execution_time = 180 max_input_time = 90 memory_limit = 256M upload_max_filesize = 64M ``` Save and close the file, then edit the PHP-FPM configuration file: ``` nano /etc/php-fpm.d/www.conf ``` Change the user and group from apache to Nginx: ``` user = nginx group = nginx ``` Save and close the file then start the PHP-FPM service and enable it to start at system reboot: ``` systemctl start php-fpm systemctl enable php-fpm ``` ## Step 2 – Create a Database for phpBB Next, you will need to create a database and user for phpBB. First, log in to the MariaDB shell with the following command: ``` mysql ``` Once you are logged in, create a database and user with the following command: ``` CREATE DATABASE phpbb; CREATE USER 'phpbbuser'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the phpbb database with the following command: ``` GRANT ALL ON phpbb.* TO 'phpbbuser'@'localhost' IDENTIFIED BY 'password' WITH GRANT OPTION; ``` Next, flush the privileges to apply the changes: ``` FLUSH PRIVILEGES; ``` Next, exit from the MariaDB shell with the following command: ``` EXIT; ``` ## Step 3 – Install phpBB First, download the latest version of phpBB with the following command: ``` wget https://download.phpbb.com/pub/release/3.3/3.3.15/phpBB-3.3.15.zip ``` Once the download is completed, unzip the downloaded file with the following command: ``` unzip phpBB-3.3.15.zip ``` Next, move the extracted directory to the Nginx web root directory: ``` mv phpBB3 /var/www/html/phpbb ``` Next, set proper permissions and ownership with the following command: ``` chown -R nginx:nginx /var/www/html/phpbb chmod -R 775 /var/www/html/phpbb chown -R nginx:nginx /var/lib/php/session ``` ## Step 4 – Configure Nginx for phpBB Next, you will need to create an Nginx virtual host configuration file to host phpBB on the Internet. ``` nano /etc/nginx/conf.d/phpbb.conf ``` Add the following lines: ``` server { listen 80; server_name phpbb.example.com; root /var/www/html/phpbb; index index.php index.html index.htm; access_log /var/log/nginx/phpbb-access.log; error_log /var/log/nginx/phpbb-error.log; location / { try_files $uri $uri/ @rewriteapp; # Pass the php scripts to FastCGI server specified in upstream declaration. location ~ \.php(/|$) { include fastcgi.conf; fastcgi_pass unix:/run/php-fpm/www.sock; fastcgi_split_path_info ^(.+\.php)(/.*)$; fastcgi_param PATH_INFO $fastcgi_path_info; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; fastcgi_param DOCUMENT_ROOT $realpath_root; try_files $uri $uri/ /app.php$is_args$args; fastcgi_intercept_errors on; } # Deny access to internal phpbb files. location ~ /(config\.php|common\.php|cache|files|images/avatars/upload|includes|(? URL: https://www.atlantic.net/vps-hosting/how-to-install-memcached-on-rocky-linux-10/ | Published: 2021-11-03 | Updated: 2025-10-21 | Author: Hitesh Jethva Memcached is an open-source, high-performance, superfast in-memory key-value store and caching service. It is used to speed up web applications by caching session data, user authentication tokens, and API calls. It also helps when sharing a large amount of data across multiple application instances. It is used by some major companies including Facebook, Youtube, and Twitter. Memcached is multithreaded and scales vertically. In this post, we will show you how to install Memcached on Rocky Linux 10. ## Step 1 – Install Memcached on Rocky Linux 10 By default, the Memcached package is included in the Rocky Linux 8 default repo. You can install it by just running the following command: ``` dnf install memcached libmemcached -y ``` Once the Memcached is installed, you can see the detailed information of Memcached with the following command: ``` rpm -qi memcached ``` Sample output: ``` Name : memcached Epoch : 0 Version : 1.6.23 Release : 7.el10 Architecture: x86_64 Install Date: Tue 21 Oct 2025 01:18:32 AM EDT Group : Unspecified Size : 477599 License : BSD-3-clause AND Zlib AND BSD-2-Clause AND LicenseRef-Fedora-Public-Domain Signature : RSA/SHA256, Thu 22 May 2025 05:07:12 PM EDT, Key ID 5b106c736fedfc85 Source RPM : memcached-1.6.23-7.el10.src.rpm Build Date : Fri 01 Nov 2024 11:25:14 AM EDT Build Host : pb-6720739d-5195-43e0-967e-8c214d0af718-b-x86-64 Packager : Rocky Linux Build System (Peridot) Vendor : Rocky Enterprise Software Foundation URL : https://www.memcached.org/ Summary : High Performance, Distributed Memory Object Cache Description : memcached is a high-performance, distributed memory object caching system, generic in nature, but intended for use in speeding up dynamic web applications by alleviating database load. ``` ## Step 2 – Manage Memcached Service You can manage the Memcached service easily via systemd. To start the Memcached service, run the following command: ``` systemctl start memcached ``` To enable the Memcached service to start after the reboot, run the following command: ``` systemctl enable memcached ``` To check the status of the Memcached service, run the following command: ``` systemctl status memcached ``` Sample output: ``` ● memcached.service - memcached daemon Loaded: loaded (/usr/lib/systemd/system/memcached.service; disabled; preset: disabled) Active: active (running) since Tue 2025-10-21 01:18:53 EDT; 3s ago Invocation: e75fe0213cd443cd949c1c2c00b5154c Main PID: 132666 (memcached) Tasks: 10 (limit: 24809) Memory: 1.7M (peak: 1.9M) CPU: 16ms CGroup: /system.slice/memcached.service └─132666 /usr/bin/memcached -p 11211 -u memcached -m 64 -c 1024 -l 127.0.0.1,::1 Oct 21 01:18:53 rocky systemd[1]: Started memcached.service - memcached daemon. ``` ## Step 3 – Configure Memcached The Memcached default configuration file is located at /etc/sysconfig/memcached. You can edit it with the following command: ``` nano /etc/sysconfig/memcached ``` The default configuration is shown below. You can change it per your requirements: ``` PORT="11211" USER="memcached" MAXCONN="1024" CACHESIZE="64" OPTIONS="-l 127.0.0.1,::1" ``` Save and close the file then restart the Memcached service to apply the changes: ``` systemctl restart memcached ``` ## Step 4 – Integrate Memcached with PHP-Based Applications You can use Memcached as a caching service for all PHP based applications. You can do it by installing the Memcached extension for PHP. Install the Memcached PHP extensions using the following command: ``` dnf install php php-cli php-pecl-memcache php-pecl-memcached -y ``` ## Step 5 – Verify Memcached for PHP To verify the Memcached integration with PHP, you will need to install the Nginx web server package to your server. ``` dnf install nginx -y ``` Next, create a info.php file with the following command: ``` nano /var/www/html/info.php ``` Add the following code: ``` ``` Save and close the file, then create a symbolic link to the info.php file in the Nginx default web root directory: ``` ln -s /var/www/html/info.php /usr/share/nginx/html/ ``` Next, restart the Nginx service to apply the changes: ``` systemctl start nginx ``` Now, run the following command to verify the Memcahced: ``` php /var/www/html/info.php | grep memcache ``` You will see the below output. ``` memcache.session_redundancy => 2 => 2 memcache.session_save_path => no value => no value memcached memcached support => enabled libmemcached-awesome version => 1.1.4 memcached.compression_factor => 1.3 => 1.3 memcached.compression_level => 3 => 3 memcached.compression_threshold => 2000 => 2000 memcached.compression_type => fastlz => fastlz As you can see, both Memcache and Memcached PHP extensions are enabled. ``` ## Conclusion In the above post, you learned how to install the Memcached service on Rocky Linux 10. You also learned how to integrate Memcached with PHP applications. You should now be able to use Memcached to speed up your web applications – give it a try on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Rust Programming Language on Rocky Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-rust-programming-language-on-rocky-linux-10/ | Published: 2021-11-04 | Updated: 2025-10-21 | Author: Hitesh Jethva Rust is a free and open-source server-side programming language developed by Mozilla. It mainly focused on speed, memory safety, and replacing low-level coding languages like C/C++. It is used to create a wide range of applications including game engines, operating systems, file systems, browser components, and more. It can run on embedded devices and easily integrate with other languages. In this post, we will show you how to install the Rust programming language on Rocky Linux 10. ## Step 1 – Install Required Dependencies First, you will need to install some required dependencies on your server. You can install all of them by running the following commands: ``` dnf install epel-release -y dnf install cmake gcc make curl clang -y ``` Once all the dependencies are installed, you can proceed to the next step. ## Step 2 – Install Rust on Rocky Linux 10 Now, run the following command to download and run the Rust installation script: ``` curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh ``` You will be asked to select the installation option as shown below: ``` home directory, located at: /root/.rustup This can be modified with the RUSTUP_HOME environment variable. The Cargo home directory located at: /root/.cargo This can be modified with the CARGO_HOME environment variable. The cargo, rustc, rustup and other commands will be added to Cargo's bin directory, located at: /root/.cargo/bin This path will then be added to your PATH environment variable by modifying the profile files located at: /root/.profile /root/.bash_profile /root/.bashrc You can uninstall at any time with rustup self uninstall and these changes will be reverted. Current installation options: default host triple: x86_64-unknown-linux-gnu default toolchain: stable (default) profile: default modify PATH variable: yes 1) Proceed with installation (default) 2) Customize installation 3) Cancel installation >1 ``` Type 1 and hit Enter to start the installation. Once the installation is complete, you will get the following output: ``` stable-x86_64-unknown-linux-gnu installed - rustc 1.56.0 (09c42c458 2021-10-18) Rust is installed now. Great! To get started you may need to restart your current shell. This would reload your PATH environment variable to include Cargo's bin directory ($HOME/.cargo/bin). To configure your current shell, run: source $HOME/.cargo/env ``` Now, activate the Rust system path variable using the following command: ``` source ~/.profile source ~/.cargo/env ``` Now, verify the Rust version with the following command: ``` rustc -V ``` You should see the Rust version in the following output: ``` rustc 1.90.0 (1159e78c4 2025-09-14) ``` ## Step 3 – Create a Rust Application At this point, Rust is installed. Now, let’s create a sample application to test Rust. First, create a directory named project with the following command: ``` mkdir project ``` Next, change the directory to the project and create a sample Rust application with the following command: ``` cd project nano helloworld.rs ``` Add the following code: ``` fn main() { println!("This is my first project created using rust!"); } ``` Save and close the file, then compile the program using the following command: ``` rustc helloworld.rs ``` This command will create an executable file in your current directory. Now, run the program with the following command: ``` ./helloworld ``` You should see the following output: ``` This is my first project created using rust! ``` ## Step 4 – Update Rust to the Latest Version It is always a good idea to use the latest version of Rust. You can update it with the following command: ``` rustup update ``` ## Step 5 – How to Uninstall Rust If you want to remove Rust from your system, run the following command: ``` rustup self uninstall ``` After the successful uninstall, you will get the following output: ``` Thanks for hacking in Rust! This will uninstall all Rust toolchains and data, and remove $HOME/.cargo/bin from your PATH environment variable. Continue? (y/N) y info: removing rustup home info: removing cargo home info: removing rustup binaries info: rustup is uninstalled ``` ## Conclusion In the above post, we explained how to install the Rust programming language on your Rocky Linux 10. We also create a sample application using Rust. You can now start creating your application using the Rust language. Try using Rust on your [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Top 10 Database Offerings > URL: https://www.atlantic.net/hipaa-compliant-hosting/top-10-database-offerings/ | Published: 2021-11-05 | Updated: 2025-09-19 | Author: Dr. Rachael Bailey Are you in the market for a top [database](https://www.atlantic.net/dedicated-server-hosting/what-is-database-hosting/) offering to safely and securely store your data, either on-premise or in the cloud? No matter the size of your business or organization, today’s digital culture leaves us with vast amounts of data to store, such as customer contact details, inventory tracking, or account information. A top database solution will enable you to efficiently organize your data and ensure that it remains secure while enhancing accessibility to the information. Database offerings are part of a highly competitive market, making it difficult to find the right solution to leverage for your business. While all databases accomplish the same key task, they each offer distinct benefits and advantages. When choosing a suitable database software, you should consider how it will integrate with your existing infrastructure, whether it is user-friendly and scalable, the level of support offered, and the overall cost of the software. We have compiled a list of the leading database solutions on the market, including both free and paid offerings. ## List of the Top 10 Database Software ## 1. MySQL MySQL is one of the most widely adopted open-source relational database solutions on the market. Its popularity is due to its enterprise-grade features and its compatibility with most applications and popular platforms including Windows, macOS, and Linux. And of course, that it is free to use for non-production environments and individuals! Commercial businesses and organizations require a commercial license. Developed in 1995 by Swedish Software Engineers Michael Widenius and David Axmark, MySQL has since been acquired by Oracle. MySQL is deployed by some of the world’s leading organizations, including Facebook, Booking.com, and Twitter. [MySQL](https://www.atlantic.net/dedicated-server-hosting/what-is-mysql/) is reliable, easy to install, and user-friendly, using an easy-to-understand query language. Enterprise-grade features include subqueries, InnoDB Support, Berkeley DB (BDB) transactional storage engine, and prepared statements. Did you know you can spin up a MySQL instance on the Atlantic.Net cloud? [Try out our one-click application now](https://cloud.atlantic.net/?page=signup). ## 2. Oracle RDMS Created in 1979, Oracle was the first commercially available [relational database](https://www.atlantic.net/vps-hosting/what-is-relational-database/) management system (RDMS) in the world. It remains at the forefront of database offerings, with many improvements to functionality over the years. Its latest version allows integration with cloud-based systems, providing businesses with scalability and flexibility. As well as RDMS solutions, Oracle provides SQL and NoSQL database solutions. Users benefit from the latest in database technology, as well as an extensive suite of solutions and tools. As Oracle is a high-cost database solution and may require hardware upgrades prior to implementation, it is most suitable for large enterprise-grade organizations that are looking for an effective database to manage large volumes of data. ## 3. Microsoft SQL Server The first version of Microsoft SQL Server was released in 1989. This offering is fully compatible with both cloud-based and on-premise servers. As you might expect, Microsoft SQL Server integrates easily with Microsoft products, and one of its key benefits is a user-friendly yet powerful interface. MS SQL Server comes with numerous application services focusing on Machine Learning, Service Broker, Replication, Analysis, and Reporting. [MS SQL](https://www.atlantic.net/vps-hosting/what-is-mssql/) is hugely popular for data transformation, with ETL processes available out of the box. MS SQL Server is expensive to purchase, but it is a great solution for medium and large businesses. ## 4. IBM DB2 DB2 was first released way back in 1983 and is still a very popular database service today. It started life as a database for IBM server hardware, but it will run on any hardware today and is available as a managed service with most cloud service providers. DB2 is all about high-performance data management allowing access, sharing, and analysis of all types of data – structured, semi-structured or unstructured – wherever it’s stored or deployed. ## 5. PostgreSQL [PostgreSQL](https://www.atlantic.net/vps-hosting/how-to-secure-postgresql-server/) is a relational database management system that has grown in popularity in recent years due to its exemplary security and scalability options. Plus, it’s open-source and freely available to anyone. Unlike MySQL, there are no license costs for business and enterprise clients. Postgres is popular with cloud providers because of the way it scales and for its built-in enterprise-grade features for Data Warehousing, Machine Learning, and IoT. ## 6. MariaDB [MariaDB](https://www.atlantic.net/vps-hosting/how-to-manage-databases-in-mariadb-on-ubuntu-18-04/) is a fork of the MySQL server project. A number of developers were concerned when Oracle bought MySQL back in 2009, and as a result, the MariaDB project was launched. MariaDB is all but identical to MySQL on the surface, but dig deeper and you will see that MariaDB has more storage engines, can handle a larger connection pool, and offers faster replication. It is also 100% free, unlike MySQL, but its biggest disadvantage is the support provided; MariaDB is community-driven, whereas MySQL has enterprise-level support packages available. ## 7. MongoDB Released in 2009, [MongoDB](https://www.atlantic.net/hipaa-compliant-hosting/can-mongodb-be-hipaa-compliant/) is a relative newcomer but is still a popular document-orientated NoSQL database. MongoDB is popular with modern website applications due to its code-native data access and works extremely well with the Windows Server operating system and sites hosted on IIS. MongoDB resides in system memory, making it very fast, and has unique features such as sharding, a clever way to load balance the database to keep it highly efficient. ## 8. SAP HANA SAP HANA is an enterprise-grade in-memory database management system with a big focus on data analytics. It’s another relatively new database platform, originally released in 2010. Its biggest advantages are the decision-making capabilities and real-time analytics, and it’s capable of processing enormous data sets in parallel. SAP HANA is an in-memory DB and is usually sold with dedicated server hardware capable of running it at a breakneck pace. ## 9. Redis [Redis](https://www.atlantic.net/ashburn-virginia-hosting/why-redis-has-become-so-popular-fast-open-source/) (the Remote Dictionary Server) is an in-memory key-value data store. It supports various data structures such as strings, lists, maps streams, and spatial indices. It is commonly used in message queue applications and for streaming large datasets, typically for caching data, chat applications, and gaming leaderboards. Redis is open-source and easily scalable and works really well on a cloud platform. ## 10. Firebird Firebird is a cross-platform, open-source SQL relational database management system built on the Borland database structure. Firebird’s biggest draw is the support for stored procedures, making data manipulation a very simple process. It is highly redundant and uses careful writes, meaning no transaction logs. This makes data management much easier and database restores a simple process. The cross-platform capabilities mean that no matter what operating system you are running, it will work with Firebird (AIX, FreeBSD, HP-UX, Linux, OS X, server-less, Solaris, Unix, and Windows. ## How can Atlantic.Net help with your DBMS? While most hosting companies can run a web server, databases take a special combination of physical components and technical savvy to implement. The database host must configure the hosting environment to make the data quickly accessible, allow room for growth, and make the database secure enough to resist attacks or corruption. A company can host its own database, but the advantages offered by database hosting companies can simplify matters. Hosting companies stake their reputations and future sales on your data’s protection. Database hosting companies use active monitoring of all traffic to your database servers, looking for any suspicious activity, When traffic ramps up on your website, load balancers can distribute it so that your infrastructure continues to run optimally, and if you’re purchasing hardware to fit your specific needs, the costs can add up quickly. As your business grows, you may need to upgrade your hardware sooner rather than later. Thanks to economies of scale, a database hosting company can meet your hardware needs at a fraction of the cost. Atlantic.Net is uniquely positioned to offer database hosting services for customers in every vertical. For healthcare, The necessity of having a [HIPAA-compliant database](https://www.atlantic.net/hipaa-compliant-hosting/) requires specialized support from a [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) service. Atlantic.Net has the experience to meet your needs with a database Cloud Server so that your patients’ [PHI](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) data remains secure and private at all times. --- # How to Install Gulp.js on Rocky Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-gulp-js-on-rocky-linux-10/ | Published: 2021-11-06 | Updated: 2025-10-21 | Author: Hitesh Jethva Gulp is a free, open-source, cross-platform JavaScript tool that helps you automate time-consuming tasks in your development workflow. It is built on Node.js and NPM used to reduce the amount of development time and attention required for tasks such as modification and optimization. It helps developers to run front-end tasks and large-scale web applications. In this post, we will show you how to install Gulp.js on Rocky Linux 10. ## Step 1 – Install Node.js on Rocky Linux 10 Gulp is based on Node.js and NPM, so you will need to install both packages to your system. First, install the curl package with the following command: ``` dnf install curl -y ``` Next, add the Node source repository using the following command: ``` curl --silent --location https://rpm.nodesource.com/setup_22.x | bash - ``` Next, install the Node.js package with the following command: ``` dnf install nodejs -y ``` Once Node.js is installed, verify the Node.js version with the following command: ``` node -v ``` Sample output: ``` v22.20.0 ``` You can also verify the NPM version using the following command: ``` npm -v ``` Sample output: ``` 10.9.3 ``` ## Step 2 – Install Gulp.js First, you will need to install the Gulp CLI tool in your system. It is used to install and manage the Gulp application. You can install the Gulp CLI tool using the following command: ``` npm install -g gulp-cli ``` After the installation, create a directory for the Gulp application: ``` mkdir gulp ``` Next, change the directory to gulp and create a gulp application with the following command: ``` cd gulp npm init ``` You will be asked to provide several questions for your new application: ``` package name: (gulp) version: (1.0.0) description: entry point: (index.js) test command: git repository: keywords: author: license: (ISC) About to write to /root/gulp/package.json: { "name": "gulp", "version": "1.0.0", "description": "", "main": "index.js", "scripts": { "test": "echo \"Error: no test specified\" && exit 1" }, "author": "", "license": "ISC" } Is this OK? (yes) yes ``` Next, run the following command to install the Gulp module: ``` npm install --save-dev gulp ``` Next, verify the Gulp installation using the following command: ``` gulp --version ``` You should see the following output: ``` CLI version: 3.1.0 Local version: 5.0.1 ``` ## Step 3 – Create a Gulp Application At this point, Gulp is installed. Now, let’s create a sample Gulp application. First, create a project directory using the following command: ``` mkdir project ``` Next, change the directory to project and create a Gulp application with the following command: ``` cd project nano gulpfile.js ``` Add the following code: ``` var gulp = require('gulp'); gulp.task('hello', function(done) { console.log('Hello World Application!!!'); done(); }); ``` Save and close the file, then run the Gulp application using the following command: ``` gulp hello ``` You will get the following output: ``` [13:55:46] Using gulpfile ~/gulp/project/gulpfile.js [13:55:46] Starting 'hello'... Hello World Application!!! [13:55:46] Finished 'hello' after 3.69 ms ``` ## Conclusion Congratulations! You have successfully installed Gulp.js on Rocky Linux 10. You can now use Gulp to automate repetitive tasks on your [virtual private server](https://www.atlantic.net/vps-hosting/) with ease. For more information, visit the [Gulp.js](https://gulpjs.com/) official documentation page. --- # How to Install Latest Nginx Mainline on Rocky Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-latest-nginx-mainline-on-rocky-linux-10/ | Published: 2021-11-07 | Updated: 2025-10-20 | Author: Hitesh Jethva Nginx is a free, open-source software solution for web serving, reverse proxying, caching, load balancing, media streaming, and more. Compared to Apache, Nginx is a high‑performance, highly scalable, and highly available web server. Thanks to its ability to handle massive numbers of connections, it is the preferred web server of many websites that deal with high traffic. By default, the latest Nginx mainline version is not included in the Rocky Linux Appresteam repository. For a production environment, it is always recommended to install the latest version. In this post, we will show you how to install the latest Nginx Mainline on Rocky Linux 10. ## Step 1 – Add an Nginx Repository First, install the dnf-utils package using the following command: ``` dnf install dnf-utils -y ``` Next, create an Nginx repo with the following command: ``` nano /etc/yum.repos.d/nginx.repo ``` Add the following lines: ``` [nginx-stable] name=nginx stable repo baseurl=http://nginx.org/packages/centos/$releasever/$basearch/ gpgcheck=1 enabled=1 gpgkey=https://nginx.org/keys/nginx_signing.key module_hotfixes=true [nginx-mainline] name=nginx mainline repo baseurl=http://nginx.org/packages/mainline/centos/$releasever/$basearch/ gpgcheck=1 enabled=0 gpgkey=https://nginx.org/keys/nginx_signing.key module_hotfixes=true ``` Save and close the file, then enable the Nginx Mainline repo using the following command: ``` yum-config-manager --enable nginx-mainline ``` ## Step 2 – Install Nginx Mainline on Rocky Linux 10 Now, run the following command to install the latest Nginx Mainline package to your server. ``` dnf install nginx ``` You should see the following output: ``` nginx stable repo 48 kB/s | 32 kB 00:00 nginx mainline repo 111 kB/s | 86 kB 00:00 Dependencies resolved. =============================================================================================================================================== Package Architecture Version Repository Size =============================================================================================================================================== Installing: nginx x86_64 1:1.29.3-1.el8.ngx nginx-mainline 823 k Transaction Summary =============================================================================================================================================== Install 1 Package Total download size: 823 k Installed size: 2.8 M Is this ok [y/N]: y ``` Once Nginx is installed, start the Nginx service and enable it to start at system reboot: ``` systemctl start nginx systemctl enable nginx ``` Next, verify the status of Nginx with the following command: ``` systemctl status nginx ``` You should get the following output: ``` ● nginx.service - The nginx HTTP and reverse proxy server Loaded: loaded (/etc/systemd/system/nginx.service; disabled; preset: disabled) Drop-In: /etc/systemd/system/nginx.service.d └─php-fpm.conf Active: active (running) since Tue 2025-10-21 00:50:23 EDT; 4s ago Invocation: eb29a7cc471746ec823b615fb2431507 Process: 129170 ExecStartPre=/usr/bin/rm -f /run/nginx.pid (code=exited, status=0/SUCCESS) Process: 129172 ExecStartPre=/usr/sbin/nginx -t (code=exited, status=0/SUCCESS) Process: 129174 ExecStart=/usr/sbin/nginx (code=exited, status=0/SUCCESS) Main PID: 129176 (nginx) Tasks: 3 (limit: 24809) Memory: 2.9M (peak: 2.9M) CPU: 34ms CGroup: /system.slice/nginx.service ├─129176 "nginx: master process /usr/sbin/nginx" ├─129177 "nginx: worker process" └─129178 "nginx: worker process" Oct 21 00:50:23 rocky systemd[1]: Starting nginx.service - The nginx HTTP and reverse proxy server... Oct 21 00:50:23 rocky nginx[129172]: nginx: the configuration file /etc/nginx/nginx.conf syntax is ok Oct 21 00:50:23 rocky nginx[129172]: nginx: configuration file /etc/nginx/nginx.conf test is successful Oct 21 00:50:23 rocky systemd[1]: nginx.service: Failed to create reference to PID from file '/run/nginx.pid': Invalid argument Oct 21 00:50:23 rocky systemd[1]: Started nginx.service - The nginx HTTP and reverse proxy server. ``` Now, verify the Nginx version using the following command: ``` nginx -v ``` You should see the Nginx version in the following output: ``` nginx version: nginx/1.29.2 ``` ## Step 3 – Configure Firewall By default, Nginx listens on ports 80 and 443. If any firewall is installed and configured on your server, then you will need to allow both ports via firewalld. You can allow them with the following command: ``` firewall-cmd --permanent --zone=public --add-service=http firewall-cmd --permanent --zone=public --add-service=https ``` Next, reload firewalld to apply the changes: ``` firewall-cmd --reload ``` ## Step 4 – Access Nginx Default Page Now, open your web browser and access the Nginx default page using the URL **http://your-server-ip**. You should see the Nginx default page on the following screen: ![Nginx test page](https://www.atlantic.net/wp-content/uploads/2021/10/p1-3-1024x436.png) ## Conclusion In the above post, we explained how to install the latest Nginx mainline version to Rocky Linux 10. You can now easily update your current Nginx version to the latest version; try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install FTP Server with ProFTPD on RockyLinux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-ftp-server-with-proftpd-on-rockylinux-10/ | Published: 2021-11-08 | Updated: 2025-10-20 | Author: Hitesh Jethva ProFTPd is a free and open-source FTP application used to transfer files over the network. It is simple, easy to install, and highly configurable. ProFTPd is used by many users due to its security policies that make it perfect for web hosting environments. Compared to other FTP applications, ProFTPd focuses on speed, security, and simplicity. In this post, we will show you how to install a ProFTPD FTP server on Rocky Linux 10. ## Step 1 – Install ProFTPD By default, ProFTPD is not included in the Rocky Linux default repo, so you will need to install the EPEL repo on your system. You can install it using the following command: ``` dnf install epel-release -y ``` Once the EPEL repository is installed, run the following command to install the ProFTPD package: ``` dnf install proftpd -y ``` After the installation, start the ProFTPD service and enable it to start at system reboot: ``` systemctl start proftpd systemctl enable proftpd ``` You can verify the status of ProFTPD using the following command: ``` systemctl status proftpd ``` You will get the following output: ``` ● proftpd.service - ProFTPD FTP Server Loaded: loaded (/usr/lib/systemd/system/proftpd.service; disabled; preset: disabled) Active: active (running) since Tue 2025-10-21 00:34:52 EDT; 4s ago Invocation: bcfa8669a623456e97a054175c5ad7c6 Process: 127970 ExecStartPre=/usr/sbin/proftpd --configtest (code=exited, status=0/SUCCESS) Process: 127972 ExecStart=/usr/sbin/proftpd $PROFTPD_OPTIONS (code=exited, status=0/SUCCESS) Main PID: 127974 (proftpd) Tasks: 1 (limit: 24809) Memory: 4.6M (peak: 5.2M) CPU: 49ms CGroup: /system.slice/proftpd.service └─127974 "proftpd: (accepting connections)" ``` You can verify the ProFTPD version using the following command: ``` proftpd -v ``` You will get the following output: ``` ProFTPD Version 1.3.9 ``` ## Step 2 – Create an FTP User Next, you will need to create a user for FTP. You can create a new user named user1 with the following command: ``` useradd user1 ``` Next, set a password for user1 using the command below: ``` passwd user1 ``` Set the password as shown below: ``` Changing password for user user1. New password: Retype new password: passwd: all authentication tokens updated successfully. ``` Next, log in to user1 with the following command: ``` su - user1 ``` Next, create some files and directories using the following command: ``` touch cat dog mkdir jan feb march ``` Next, exit from user1 with the following command: ``` exit ``` ## Step 3 – Access ProFTPD Server There are two ways to access the FTP server: using the command-line, or via the FTP client. ### Access FTP Via Command Line On the remote machine, open the command-line interface and run the following command to connect to the ProFTPD server. ``` ftp proftpd-ip ``` You will be asked to provide your FTP username and password: ``` Connected to proftpd-ip. 220 FTP Server ready. Name (proftpd-ip:vyom): user1 331 Password required for user1 Password: ``` Once you are connected, you should get the following output: ``` 230 User user1 logged in Remote system type is UNIX. Using binary mode to transfer files. ``` Now, run the following command to list all files and directories on the FTP server: ``` ftp> ls ``` You will get the following output: ``` 200 PORT command successful 150 Opening ASCII mode data connection for file list -rw-rw-r-- 1 user1 user1 0 Nov 8 10:31 cat -rw-rw-r-- 1 user1 user1 0 Nov 8 10:31 dog drwxrwxr-x 2 user1 user1 6 Nov 8 10:31 feb drwxrwxr-x 2 user1 user1 6 Nov 8 10:31 jan drwxrwxr-x 2 user1 user1 6 Nov 8 10:31 march 226 Transfer complete ``` ### Access FTP via FTP Client Open the FileZilla FTP client as shown below: ![Filezilla interface](https://www.atlantic.net/wp-content/uploads/2021/11/p1-2-1024x560.png) Click on the **Site manager** to create a new FTP connection: ![Filezilla Site Manager](https://www.atlantic.net/wp-content/uploads/2021/11/p2-1.png) Provide your FTP server IP, username, and password, and click on the **connect** button. Once you are connected, you should see the following screen: ![Filezilla Connection Established](https://www.atlantic.net/wp-content/uploads/2021/11/p3-1024x566.png) ## Conclusion In the above guide, we explained how to install the ProFTPD FTP server on Rocky Linux 10. We also explained how to access FTP via command-line and FTP client. You can now set up an FTP server on your website to download and upload website pages – try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Rocky Linux Cloud VPS Hosting Is Now Available at All Seven Data Center Locations! > URL: https://www.atlantic.net/announcements/rocky-linux-cloud-vps-hosting-is-now-available-at-all-seven-data-center-locations/ | Published: 2021-11-10 | Updated: 2025-09-19 | Author: Alexander Wise The Rocky Linux operating system, seen by the developer community as the successor to CentOS, is now available for use in the Atlantic.Net Cloud.  Rocky Linux is an important release for many of our customers as CentOS has announced they will be cutting support for CentOS 8 much earlier than the original date of December 31, 2029, instead of planning end-of-life for a new date of December 31, 2021. CentOS will also be discontinuing future development of new CentOS versions that track RedHat upstream releases. ![](https://www.atlantic.net/wp-content/uploads/2021/11/Rock-Linux-banner-x2-01-03.jpg) We are a strong believer in open-source solutions, and we always strive to support the community with free open-source software. Offering Rocky Linux in our Cloud will allow our customers to migrate their workloads from CentOS to a fully compatible operating system that will continue to be free and fully supported for the long term. Rocky Linux 8.4 64-bit is available at all our data center locations in Orlando, New York, Ashburn, Toronto, San Francisco, Dallas, and London. To view the latest cloud offerings and pricing, visit [VPS hosting](https://www.atlantic.net/vps-hosting/). To view tutorials on Rocky Linux, visit [our tutorials](https://www.atlantic.net/tutorials/?prod_anet_tuts%5Bquery%5D=rocky%20linux). --- # Atlantic.Net Introduces Rocky Linux as a New Cloud VPS Operating System > URL: https://www.atlantic.net/press-releases/atlantic-net-introduces-rocky-linux-as-a-new-cloud-vps-operating-system/ | Published: 2021-11-10 | Updated: 2023-07-20 | Author: Editorial Team Rocky Linux Cloud VPS Hosting is now available at all seven data center locations! ORLANDO, FLA. (November 10, 2021) – Atlantic.Net, a leading cloud services provider, today introduced Rocky Linux as a new Cloud Server operating system for all cloud VPS customers. Rocky Linux is an important release for the majority of customers that rely on CentOS, as CentOS has announced they are moving up the timeline for ending CentOS 8 support from the original date of December 31, 2029, to a new date of December 31, 2021. “We are a strong believer in open-source solutions, and we always strive to support the community with free, open-source software,” said Marty Puranik, CEO and Founder of Atlantic.Net. “Offering Rocky Linux in our Cloud will allow our customers to migrate their workloads from CentOS to a fully compatible operating system that will continue to be free and fully supported for the long term.” Rocky Linux 8.4 64-bit is available at all our data center locations in Orlando, New York, Ashburn, Toronto, San Francisco, Dallas, and London. The Atlantic.Net [Cloud Platform](https://www.atlantic.net/cloud-platform/) provides fault-tolerant, ultra-fast performance, and includes award-winning Cloud Servers, Secure Block Storage, one-click applications, DNS, Dedicated Hosts, private networking, RESTful API, data backup, a full suite of managed services, 24/7/365 expert U.S.-based support, and more. To view the latest cloud offerings and pricing, visit [https://www.atlantic.net/vps-hosting/](https://www.atlantic.net/vps-hosting/). About Atlantic.Net Atlantic.Net is a global cloud services provider with over 25 years of experience, serving thousands of developers and small, medium, and large clients in more than one hundred countries. Atlantic.Net specializes in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions and has served dynamic business clients including Lenovo, Newegg, NASA, and Hilton, among others. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions backed by 24/7/365 support in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. For more information, please visit [https://www.atlantic.net/](https://www.atlantic.net/). ### Contact: Email: [pr@atlantic.net](mailto:pr@atlantic.net) Ph: 321- 206-1371 --- # How to Install ModSecurity with Nginx on Rocky Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-modsecurity-with-nginx-on-rocky-linux-10/ | Published: 2021-11-11 | Updated: 2025-10-20 | Author: Hitesh Jethva ModSecurity is a popular, free, open-source web application firewall used to protect web applications against several types of attacks including SQL injection, cross-site scripting, and local file inclusion. It is frequently employed to protect websites, cPanel, and other hosting control panels. While ModSecurity was primarily designed for the Apache webserver, it can also work with the Nginx web server. In this post, we will show you how to install ModSecurity with Nginx on Rocky Linux 10. ## Step 1 – Install Required Dependencies First, you will need to install all required dependencies on your server. You can install all of them with the following command: ``` dnf install gcc-c++ flex bison curl-devel curl zlib-devel autoconf automake git curl make libxml2-devel pkgconfig libtool httpd-devel redhat-rpm-config git wget openssl openssl-devel vim pcre2 pcre2-devel ``` Next, install the EPEL repository using the following command: ``` dnf install epel-release -y ``` ``` ``` ## Step 2 – Install ModSecurity First, download the latest version of ModSecurity using the following command: ``` git clone --depth 1 -b v3/master --single-branch https://github.com/SpiderLabs/ModSecurity ``` Next, change the directory to ModSecurity and install the other modules with the following command: ``` cd ModSecurity git submodule init git submodule update ``` Next, compile and install ModSecurity with the following command: ``` ./build.sh ./configure make make install ``` ## Step 3 – Install Nginx with LibModsecurity Support In order to enable LibModsecurity support in Nginx, you will need to compile Nginx with support for LibModsecurity. First, download the ModSecurity-nginx connector using the following command: ``` cd ../ git clone https://github.com/SpiderLabs/ModSecurity-nginx.git ``` Next, download the latest stable version of Nginx with the following command: ``` wget http://nginx.org/download/nginx-1.26.3.tar.gz ``` Next, extract the downloaded file using the following command: ``` tar xzf nginx-1.26.3.tar.gz ``` Next, create a user for Nginx with the following command: ``` useradd -r -M -s /sbin/nologin -d /usr/local/nginx nginx ``` Next, change the directory to the Nginx source and compile it using the following command: ``` cd nginx-1.26.3 ./configure --user=nginx --group=nginx --with-pcre-jit --with-debug --with-http_ssl_module --with-http_realip_module --add-module=/root/ModSecurity-nginx ``` Next, install it using the following command: ``` make make install ``` Next, copy the sample ModSecurity configuration file and Unicode mapping file with the following command: ``` cp /root/ModSecurity/modsecurity.conf-recommended /usr/local/nginx/conf/modsecurity.conf cp /root/ModSecurity/unicode.mapping /usr/local/nginx/conf/ ``` Next, back up the Nginx configuration file: ``` cp /usr/local/nginx/conf/nginx.conf{,.bak} ``` Next, edit the Nginx configuration file with the following command: ``` nano /usr/local/nginx/conf/nginx.conf ``` Remove all lines and add the following lines: ``` user nginx; worker_processes 1; pid /run/nginx.pid; events { worker_connections 1024; } http { include mime.types; default_type application/octet-stream; sendfile on; keepalive_timeout 65; server { listen 80; server_name nginx.example.com; modsecurity on; modsecurity_rules_file /usr/local/nginx/conf/modsecurity.conf; access_log /var/log/nginx/access_unix-demo.log; error_log /var/log/nginx/error_unix-demo.log; location / { root html; index index.html index.htm; } error_page 500 502 503 504 /50x.html; location = /50x.html { root html; } } } ``` Save and close the file, then create an Nginx log directory: ``` mkdir /var/log/nginx ``` ## Step 4 – Create a Systemd Service File for Nginx Next, you will need to create a systemd service file to manage the Nginx service. You can create it using the following command: ``` nano /etc/systemd/system/nginx.service ``` Add the following lines: ``` [Unit] Description=The nginx HTTP and reverse proxy server After=network.target remote-fs.target nss-lookup.target [Service] Type=forking PIDFile=/run/nginx.pid ExecStartPre=/usr/bin/rm -f /run/nginx.pid ExecStartPre=/usr/sbin/nginx -t ExecStart=/usr/sbin/nginx ExecReload=/bin/kill -s HUP $MAINPID KillSignal=SIGQUIT TimeoutStopSec=5 KillMode=mixed PrivateTmp=true [Install] WantedBy=multi-user.target ``` Save and close the file, then create a symlink of Nginx binary using the following command: ``` ln -s /usr/local/nginx/sbin/nginx /usr/sbin/ ``` Next, reload the systemd daemon to apply the changes: ``` systemctl daemon-reload ``` Next, start the Nginx service and enable it to start at system reboot: ``` systemctl enable --now nginx ``` You can check the status of Nginx with the following command: ``` systemctl status nginx ``` You will get the following output: ``` ● nginx.service - The nginx HTTP and reverse proxy server Loaded: loaded (/etc/systemd/system/nginx.service; enabled; preset: disabled) Drop-In: /etc/systemd/system/nginx.service.d └─php-fpm.conf Active: active (running) since Tue 2025-10-21 00:15:48 EDT; 4s ago Invocation: 95d84f55682946baa83fefd9e8df41d6 Process: 127241 ExecStartPre=/usr/bin/rm -f /run/nginx.pid (code=exited, status=0/SUCCESS) Process: 127243 ExecStartPre=/usr/sbin/nginx -t (code=exited, status=0/SUCCESS) Process: 127246 ExecStart=/usr/sbin/nginx (code=exited, status=0/SUCCESS) Main PID: 127248 (nginx) Tasks: 2 (limit: 24809) Memory: 3M (peak: 3.1M) CPU: 56ms CGroup: /system.slice/nginx.service ├─127248 "nginx: master process /usr/sbin/nginx" └─127249 "nginx: worker process" ``` ## Step 5 – Enable ModSecurity Rule By default, ModSecurity has been configured for detection-only mode, so you will need to enable the ModSecurity rule in the modsecurity.conf file. You can enable it with the following command: ``` sed -i 's/SecRuleEngine DetectionOnly/SecRuleEngine On/' /usr/local/nginx/conf/modsecurity.conf ``` Also, enable the audit log with the following command: ``` sed -i 's#/var/log/modsec_audit.log#/var/log/nginx/modsec_audit.log#' /usr/local/nginx/conf/modsecurity.conf ``` ## Step 6 – Install OWASP ModSecurity Core Rule Set OWASP provides generic attack detection rules for ModSecurity. You can download it with the following command: ``` git clone https://github.com/SpiderLabs/owasp-modsecurity-crs.git /usr/local/nginx/conf/owasp-crs ``` Next, rename the OWASP rule configuration file using the following command: ``` cp /usr/local/nginx/conf/owasp-crs/crs-setup.conf{.example,} ``` Next, define the OWASP rule in the ModSecurity configuration file: ``` echo -e "Include owasp-crs/crs-setup.conf\nInclude owasp-crs/rules/*.conf" >> /usr/local/nginx/conf/modsecurity.conf ``` Next, edit the reputation config file. ``` nano /usr/local/nginx/conf/owasp-crs/rules/REQUEST-910-IP-REPUTATION.conf ``` Remove the following liens: ``` SecRule TX:HIGH_RISK_COUNTRY_CODES "!@rx ^$" \ "id:910100,\ phase:2,\ block,\ t:none,\ msg:'Client IP is from a HIGH Risk Country Location',\ logdata:'%{MATCHED_VAR}',\ tag:'application-multi',\ tag:'language-multi',\ tag:'platform-multi',\ tag:'attack-reputation-ip',\ tag:'paranoia-level/1',\ ver:'OWASP_CRS/3.2.0',\ severity:'CRITICAL',\ chain" SecRule TX:REAL_IP "@geoLookup" \ "chain" SecRule GEO:COUNTRY_CODE "@within %{tx.high_risk_country_codes}" \ "setvar:'tx.anomaly_score_pl1=+%{tx.critical_anomaly_score}',\ setvar:'ip.reput_block_flag=1',\ setvar:'ip.reput_block_reason=%{rule.msg}',\ expirevar:'ip.reput_block_flag=%{tx.reput_block_duration}'" ``` Next, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 7 – Verify ModSecurity At this point, Nginx is installed and configured with ModSecurity support. Now it’s time to test it. Run the following command injection using the curl command: ``` curl localhost/index.html?exec=/bin/bash ``` If everything is fine, you should get the “403 Forbidden” error as shown below: ``` 403 Forbidden

403 Forbidden


nginx/1.26.3
``` You can also verify the ModSecurity log for more information: ``` tail -100 /var/log/nginx/modsec_audit.log ``` You should see the following output: ``` ---imefFQJy---D-- ---imefFQJy---E-- \x0d\x0a403 Forbidden\x0d\x0a\x0d\x0a

403 Forbidden

\x0d\x0a
nginx/1.19.10
\x0d\x0a\x0d\x0a\x0d\x0a ---imefFQJy---F-- HTTP/1.1 403 Server: nginx/1.26.3 Date: Mon, 08 Oct 2025 10:00:55 GMT Content-Length: 154 Content-Type: text/html Connection: keep-alive ---imefFQJy---H-- ModSecurity: Warning. Matched "Operator `PmFromFile' with parameter `unix-shell.data' against variable `ARGS:exec' (Value: `/bin/bash' ) [file "/usr/local/nginx/conf/owasp-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "496"] [id "932160"] [rev ""] [msg "Remote Command Execution: Unix Shell Code Found"] [data "Matched Data: bin/bash found within ARGS:exec: /bin/bash"] [severity "2"] [ver "OWASP_CRS/3.2.0"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "127.0.0.1"] [uri "/index.html"] [unique_id "1636365655"] [ref "o1,8v21,9t:urlDecodeUni,t:cmdLine,t:normalizePath,t:lowercase"] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/nginx/conf/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "80"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "2"] [ver "OWASP_CRS/3.2.0"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "127.0.0.1"] [uri "/index.html"] [unique_id "1636365655"] [ref ""] ``` ## Conclusion In the above guide, we explained how to install ModSecurity with Nginx on Rocky Linux 10. Your Nginx web server is now secured with ModSecurity WAF. ModSecurity can protect your server from a wide range of attacks. Get started on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # How to Install Sails.js Framework with Nginx on Rocky Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-sails-js-framework-with-nginx-on-rocky-linux-10/ | Published: 2021-11-12 | Updated: 2025-10-20 | Author: Hitesh Jethva Sails.js is a free, open-source, real-time MVC Framework developed on top of the Node.js environment. It makes it easy to build custom and enterprise-grade Node.js applications. Sails.js uses code generators to build an application with less manual writing of code. You can develop chat applications, real-time dashboards, and multiplayer games using the Salis.js framework. In this post, we will show you how to install the Salis.js framework with Nginx on Rocky Linux 10. ## Step 1 – Install Node.js Before starting, you will need to install Node.js to your system. First, install all required dependencies using the following command: ``` dnf update -y dnf install curl gcc-c++ make -y ``` Next, add the Node source repo using the following command: ``` curl --silent --location https://rpm.nodesource.com/setup_22.x | bash - ``` Next, install Node.js by running the following command: ``` dnf install nodejs -y ``` Once Node.js is installed, you can verify the Node.js version using the following command: ``` node --version ``` You will get the following output: ``` v22.20.0 ``` ## Step 2 – Install Sails.js Now, you can use NPM to install Sails.js: ``` npm -g install sails ``` After installing Sails.js, you will need to create a directory for the Sails.js application. ``` mkdir sails ``` Next, change the directory to sails and create a new application using the following command: ``` cd sails sails new myapp ``` You will be asked to select the template for your application: ``` Choose a template for your new Sails app: 1. Web App · Extensible project with auth, login, & password recovery 2. Empty · An empty Sails app, yours to configure (type "?" for help, or to cancel) ? 1 ``` Type 1 and press the Enter key to create your application: ``` info: Installing dependencies... Press CTRL+C to cancel. (to skip this step in the future, use --fast) info: Created a new Sails app `myapp`! ``` ## Step 3 – Start Sails.js Application After creating the Sails.js application, change the directory to your application and start the application using the command below: ``` cd myapp sails lift ``` You will get the following output: ``` info: Starting app... info: Initializing project hook... (`api/hooks/custom/`) info: Initializing `apianalytics` hook... (requests to monitored routes will be logged!) info: ·• Auto-migrating... (alter) info: Hold tight, this could take a moment. info: ✓ Auto-migration complete. debug: Running v0 bootstrap script... (looks like this is the first time the bootstrap has run on this computer) info: info: .-..-. info: info: Sails <| .-..-. info: v1.5.0 |\ info: /|.\ info: / || \ info: ,' |' \ info: .-'.-==|/_--' info: `--'-------' info: __---___--___---___--___---___--___ info: ____---___--___---___--___---___--___-__ info: info: Server lifted in `/root/sails/myapp` info: To shut down Sails, press + C at any time. info: Read more at https://sailsjs.com/support. debug: ------------------------------------------------------- debug: :: Mon Oct 08 2025 09:20:32 GMT+0000 (Coordinated Universal Time) debug: Environment : development debug: Port : 1337 debug: ------------------------------------------------------- ``` Press CTRL+C to stop the application. Find the location of sails binary. ``` which sails ``` Output. ``` /root/.nvm/versions/node/v22.20.0/bin/sails ``` Create a symbolic link of Sails. ``` ln -s /root/.nvm/versions/node/v22.20.0/bin/sails /usr/bin/sails ``` ## Step 4 – Create a Systemd Service File for Salis.js It is a good idea to create a systemd service file to manage the Sails.js application. You can create it using the following command: ``` nano /lib/systemd/system/sails.service ``` Add the following lines: ``` [Unit] After=network.target [Service] Type=simple User=root WorkingDirectory=/root/sails/myapp ExecStart=/usr/bin/sails lift Restart=on-failure [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes: ``` systemctl daemon-reload ``` Now, start the Sails.js service and enable it to start at system reboot: ``` systemctl start sails systemctl enable sails ``` You can also verify the status of the Sails.js service using the following command: ``` systemctl status sails ``` You will get the following output: ``` ● sails.service Loaded: loaded (/usr/lib/systemd/system/sails.service; disabled; preset: disabled) Active: active (running) since Mon 2025-10-20 03:27:56 EDT; 2s ago Invocation: 773624460fa744c18bc7898014dcfeb5 Main PID: 97828 (node) Tasks: 22 (limit: 24809) Memory: 163.4M (peak: 163.6M) CPU: 2.660s CGroup: /system.slice/sails.service ├─97828 node /usr/bin/sails lift └─97835 grunt Oct 20 03:27:58 rocky sails[97828]: info: Oct 20 03:27:58 rocky sails[97828]: info: Server lifted in `/root/sails/myapp` Oct 20 03:27:58 rocky sails[97828]: info: To shut down Sails, press + C at any time. Oct 20 03:27:58 rocky sails[97828]: info: Read more at https://sailsjs.com/support. Oct 20 03:27:58 rocky sails[97828]: debug: ------------------------------------------------------- Oct 20 03:27:58 rocky sails[97828]: debug: :: Mon Oct 20 2025 03:27:58 GMT-0400 (Eastern Daylight Time) Oct 20 03:27:58 rocky sails[97828]: debug: Environment : development Oct 20 03:27:58 rocky sails[97828]: debug: Port : 1337 Oct 20 03:27:58 rocky sails[97828]: debug: Local : http://localhost:1337 Oct 20 03:27:58 rocky sails[97828]: debug: ------------------------------------------------------- ``` At this point, the Sails.js application is started and listens on port **1337**. You can check it using the following command: ``` ss -antpl | grep 1337 ``` You will get the following output: ``` LISTEN 0 128 *:1337 *:* users:(("node",pid=48672,fd=19)) ``` ## Step 5 – Configure Nginx as a Reverse Proxy for Sails.js First, install Nginx with the following command: ``` dnf install nginx ``` Next, create an Nginx virtual host configuration file using the following command: ``` nano /etc/nginx/conf.d/sails.conf ``` Add the following lines: ``` server { listen 80; server_name sails.example.com; location / { proxy_pass http://localhost:1337/; proxy_set_header Host $host; proxy_buffering off; } } ``` Save and close the file, then verify Nginx for any syntax error: ``` nginx -t ``` You will get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart Nginx to apply the changes: ``` systemctl restart nginx ``` ## Step 6 – Access Sails.js Now, open your web browser and access the Sails.js web interface using the URL **http://sails.example.com**. You should see the Sails.js application on the following screen: ![Sails.js dashboard page](https://www.atlantic.net/wp-content/uploads/2021/11/p1-1024x601.png) ## Conclusion Congratulations! You have successfully installed Sails.js with Nginx on Rocky Linux 10. You can now start developing your first real-time application using the Sails.js framework. Try it out on your [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # What Digital Transformations Are Coming to Healthcare? > URL: https://www.atlantic.net/hipaa-compliant-hosting/healthcare-digital-transformations/ | Published: 2021-11-13 | Updated: 2025-09-19 | Author: Alexander Wise It’s no surprise that 2020 was a year of rapid digital transformation in healthcare. Faced with a worldwide pandemic, many healthcare organizations were forced to rethink their digitization strategies and priorities. In 2021, organizations were able to shift from survival mode into more proactive planning. This year set the stage for reimagining how processes, systems, and technology work, from creating better patient experiences to improving data practices. So what digital transformations are coming to healthcare in 2022? Below we dig into three ways healthcare will continue to evolve through digital transformation. ## Virtual Care Will Continue to Boom Although virtual healthcare exploded due to the COVID-19 pandemic, it’s not going away anytime soon. In fact, research shows that a [majority of patients will continue to prefer virtual](https://www.hmpgloballearningnetwork.com/site/ihe/videos/patient-telehealth-preferences-during-and-after-covid-19-pandemic) and at-home healthcare options. From telehealth visits to in-home testing options, patient preferences are changing and evolving due to the recent boom in virtual healthcare. According to research by [PwC’s Health Research Institute](https://www.pwc.com/us/en/industries/health-industries/library/assets/hri-2021-consumer-survey-Insight-chartpack.pdf), 85% of consumers said they’d be willing to have a DIY strep test, flu test, or remote monitoring. In 2022, it’s important for healthcare organizations to broaden virtual and in-home testing to keep up with patient preferences and expectations. For busy parents, working professionals, and college students, access to virtual healthcare is a game-changer. Many patients now expect virtual options when looking for services. In 2022, healthcare providers should prioritize developing excellent virtual experiences and securing technology that expands virtual care options. ## Paper Will Diminish as Data Processes Evolve As the healthcare industry continues to evolve digitally, paper will become a thing of the past. Electronic health records and digital workflows will become must-haves as the healthcare industry finally begins to phase out the usage of paper forms and documentation. Collecting patient data electronically is shown to reduce costs, minimize data errors, and improve patient satisfaction. Digitizing all data collection and workflows across patients, doctors and back-office staff often produces: - More efficient processes - Stronger data security - Higher patient satisfaction - Better patient retention - Improved data accuracy Experts believe 2022 will be the year healthcare facilities finally begin to shift to completely digitized data collection. According to the [Accenture Digital Health Technology Vision 2021 report](https://www.accenture.com/us-en/insights/health/accenture-digital-health-technology-vision-2021), 66% of healthcare executives say they will be in the cloud within the next year and 96% say this will happen within three years. With paper processes becoming a thing of the past, it’s important to invest in secure, [HIPAA-compliant technology](https://www.formstack.com/industry/healthcare) that can support a paperless approach. There are many [IT solutions](https://www.atlantic.net/hipaa-compliant-hosting/it-solutions-for-healthcare-how-to-choose/) that can help your organization improve data processing, from [HIPAA compliant server hosting](https://www.atlantic.net/hipaa-compliant-hosting/) to [authentication services](https://www.atlantic.net/managed-services/multi-factor-authentication/). Facilities must focus on identifying and implementing the right technology and processes in 2022 to facilitate a paperless experience. ## Transparency Becomes Key to Retaining Patients Patients are demanding more transparency from their healthcare providers, which will push organizations into different realms of digital transformation. The new regulations released on price transparency across the healthcare industry have created a domino effect. Patients now expect transparency across every touchpoint. This includes communications, pricing, data policies, information sharing, and more. In the digital age, patients have become highly educated healthcare consumers and expect the organizations that serve them to be transparent throughout all interactions. How does technology play into this? Investing in the right technology can help your organization ensure transparency across departments, locations, and employees. With the right workflows, processes, and tech in place, patients can do things like book appointments, easily access test results, find accurate pricing, and quickly communicate with providers. ## The Digitization of Healthcare Continues The changes happening within the healthcare landscape are exciting. The rapid digitization of the industry is improving patient care, accelerating growth, and expanding access to care. When healthcare organizations truly embrace digital transformation, great goals can be achieved. If you’re looking for more information on how to execute a successful digital transformation at your organization, check out Formstack’s Digital-First Healthcare Delivery: A Digital Transformation Checklist. About the Author: Lindsay McGuire is the Content Marketing Manager at [Formstack](https://www.formstack.com/), where she oversees the creation of blog content, guides, and Formstack’s Ripple Effect podcast. Learn more about our [HIPAA compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. --- # How to Install OTRS on Rocky Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-otrs-on-rocky-linux-10/ | Published: 2021-11-14 | Updated: 2025-10-20 | Author: Hitesh Jethva OTRS, also known as “Open Ticket Request System,” is a free, open-source, web-based ticket system written in Perl. It is used by many companies to improve operations related to their customer support, help desk, call center, and other such functions. It allows customers to register and create a ticket via the customer portal. OTRS is a powerful alternative to other popular ticketing systems. In this post, we will show you how to install OTRS on Rocky Linux 10. ## Step 1 – Install Required Packages First, you will need to install the EPEL repository and other dependencies to your system. You can install them by running the following command: ``` dnf update -y dnf install epel-release -y dnf install gcc expat-devel procmail mod_perl perl perl-core -y ``` Next, install all required perl modules. ``` dnf install -y perl perl-core perl-DBI perl-DBD-MySQL perl-YAML-LibYAML perl-CGI perl-LWP-Protocol-https perl-JSON perl-Net-DNS perl-MIME-Base64 perl-Encode perl-XML-Parser perl-TimeDate perl-libwww-perl perl-IO-Socket-SSL perl-MIME-tools perl-Crypt-Eksblowfish perl-Digest-MD5 perl-Digest-SHA perl-Text-CSV_XS mod_perl mod_perl-devel ``` Next, install the Apache and MariaDB server using the following command: ``` dnf install httpd mariadb-server -y ``` Once both packages are installed, start the Apache and MariaDB service and enable them to start at system reboot: ``` systemctl start httpd mariadb systemctl enable httpd mariadb ``` Next, edit the MariaDB configuration file: ``` nano /etc/my.cnf.d/mariadb-server.cnf ``` Add the following lines inside the [mysqld] section: ``` max_allowed_packet=256M character-set-server=utf8 collation-server=utf8_general_ci innodb_buffer_pool_size=4G innodb_log_file_size=1G ``` Save and close the file, then restart the MariaDB service to apply the changes: ``` systemctl restart mariadb ``` ## Step 2 – Install OTRS First, create a dedicated user to run OTRS using the following command: ``` useradd otrs ``` Next, add the OTRS user to the Apache group using the following command: ``` usermod -G apache otrs ``` Next, download the latest version of OTRS using the following command: ``` wget https://otrscommunityedition.com/download/otrs-community-edition-6.0.41.zip ``` Once OTRS is downloaded, unzip the downloaded file with the following command: ``` unzip otrs-community-edition-6.0.41.zip ``` Next, move the extracted directory to /opt with the following command: ``` mv otrs-community-edition-6.0.41 /opt/otrs ``` Next, set proper ownership to the OTRS directory: ``` chown -R otrs:otrs /opt/otrs ``` ## Step 3 – Install Required Perl Modules for OTRS Next, you will need to install several Perl modules to extend the OTRS functionality. You can check all necessary modules by running the following script: ``` perl /opt/otrs/bin/otrs.CheckModules.pl ``` This will list all necessary and optional modules. Now, run the following commands one by one to install all modules: ``` cpan Crypt::Eksblowfish::Bcrypt cpan Date::Format cpan DateTime cpan DBD::ODBC cpan DBD::Oracle cpan DBD::Pg cpan Encode::HanExtra cpan JSON::XS cpan Mail::IMAPClient cpan Authen::SASL cpan Authen::NTLM cpan Moo cpan Net::DNS cpan Net::LDAP cpan Template cpan Template::Stash::XS cpan Text::CSV_XS cpan XML::LibXML cpan XML::LibXSLT cpan XML::Parser cpan YAML::XS ``` Note: You may wish to wrap the above commands into a bash shell script to speed up the process. To do this, type: ``` nano installer.sh ``` Then copy the commands above. Make sure you **save and quit**. Now, type: ``` chmod 660 installer.sh ``` To run the script, type: ``` sh installer.sh ``` Next, rename the OTRS default configuration file using the following command: ``` cp /opt/otrs/Kernel/Config.pm.dist /opt/otrs/Kernel/Config.pm ``` Next, check all the required OTRS modules using the following command: ``` perl -cw /opt/otrs/bin/cgi-bin/index.pl perl -cw /opt/otrs/bin/cgi-bin/customer.pl perl -cw /opt/otrs/bin/otrs.Console.pl ``` Next, set appropriate permissions using the following command: ``` perl /opt/otrs/bin/otrs.SetPermissions.pl ``` ## Step 4 – Create an Apache Configuration File OTRS provides a pre-configured Apache virtual host configuration file. You can link it to the Apache configuration directory using the following command: ``` ln -s /opt/otrs/scripts/apache2-httpd.include.conf /etc/httpd/conf.d/otrs_apache.conf ``` Next, restart the Apache and MariaDB services to apply the changes: ``` systemctl restart httpd systemctl restart mariadb ``` ## Step 5 – Create a Systemd Service File for OTRS Next, you will need to create a systemd service file for OTRS. You can create it using the following command: ``` nano /etc/systemd/system/otrs.service ``` Add the following lines: ``` [Unit] Description=OTRS: Open-source Ticket Request System, Copyright (C) 2001-2016 OTRS AG Documentation=https://otrs.github.io/doc/manual/admin/stable/en/html/ Requires=crond.service httpd.service mariadb.service [Service] Type=oneshot RemainAfterExit=yes ExecStart=/opt/otrs/bin/otrs.Daemon.pl start ExecStart=/opt/otrs/bin/Cron.sh start ExecStop=/opt/otrs/bin/Cron.sh stop ExecStop=/opt/otrs/bin/otrs.Daemon.pl stop User=otrs Group=apache [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes: ``` systemctl daemon-reload ``` Next, start and enable the OTRS service using the following command: ``` systemctl start otrs systemctl enable otrs ``` ## Step 6 – Access OTRS Web Interface Now, open your web browser and access OTRS using the URL **http://your-server-ip/otrs/installer.pl**. You should see the following screen: ![OTRS welcome page](https://www.atlantic.net/wp-content/uploads/2021/11/p1-1-1024x488.png) Click on the **Next** button. You should see the License agreement screen: ![OTRS License page](https://www.atlantic.net/wp-content/uploads/2021/11/p2-1024x642.png) Click on the **Accept license and continue** button. You should see the database setting screen. Provide root as the username, leave the password field blank, and click on the **Check database settings**. You should see the following screen: ![OTRS Database setup page](https://www.atlantic.net/wp-content/uploads/2021/11/p4-1024x562.png) Click on the **Next** button to create a database and user. You should see the following screen: ![Database creation page](https://www.atlantic.net/wp-content/uploads/2021/11/p5-1024x485.png) Click on the **Next** button. You should see the general configuration screen: ![General configuration page](https://www.atlantic.net/wp-content/uploads/2021/11/p6-1024x559.png) Provide all necessary configurations and click on the **Next** button. You should see the following screen: ![SMTP configuration page](https://www.atlantic.net/wp-content/uploads/2021/11/p7-1024x577.png) Provide your SMTP configuration or click on the “**Skip this Step**” button. You should see the following screen: ![OTRS installation complete page](https://www.atlantic.net/wp-content/uploads/2021/11/p8-1024x481.png) Click on the Startup page link. You will be redirected to the OTRS login: ![OTRS login page](https://www.atlantic.net/wp-content/uploads/2021/11/p9.png) Provide your admin username and password and click on the **Login** button. You should see the OTRS dashboard: ![OTRS dashboard page](https://www.atlantic.net/wp-content/uploads/2021/11/p10-1024x535.png) ## Conclusion Congratulations! You have successfully installed the OTRS ticketing system on Rocky Linux 10. You can now create your own online ticketing system using OTRS. Give it a try on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Manage Java Versions on Rocky Linux > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-manage-java-versions-on-rocky-linux/ | Published: 2021-11-28 | Updated: 2025-10-19 | Author: Hitesh Jethva Java is the most popular programming language used to build applications and systems. Additionally, you can use Java to create games, chatbots, enterprise applications, and more. Java can be run on all operating systems. In order to develop Java applications, you will need to install an IDE on your system. It can be provided by OpenJDK or Oracle JDK. Java JDK is a free, open-source, and powerful software development environment used for developing Java Applications. JDK is a collection of programming tools including Javac, JRE, Jar, and Java. In this post, we will show you how to install and manage different Java versions on Rocky Linux. This procedure is compatible with Rocky Linux 9 and Rocky Linux 10. ## Install Java OpenJDK In this section, we will show you how to install OpenJDK version 21, and 25 on Rocky Linux 10. ### Install OpenJDK 21 At the time of writing this article, the latest version of Java OpenJDK is version 21. By default, the latest version is available in the Rocky Linux 10 default repository. You can install it using the below command. ``` dnf install java-21-openjdk-devel -y ``` You can verify the Java version using the following command: ``` java --version ``` You will get the following output: ``` java 21.0.8 2023-10-17 LTS Java(TM) SE Runtime Environment (build 21.0.1+12-LTS-29) Java HotSpot(TM) 64-Bit Server VM (build 21.0.1+12-LTS-29, mixed mode, sharing) ``` ## Install Oracle JDK 25 At the time of writing this article, the latest version of Oracle JDK is 25. First, you will need to download it from its official website: ``` wget https://download.oracle.com/java/25/latest/jdk-25_linux-x64_bin.rpm ``` Once the download is completed, you can install it using the following command: ``` rpm -ivh jdk-25_linux-x64_bin.rpm ``` You will get the following output: ``` warning: jdk-25_linux-x64_bin.rpm: Header V3 RSA/SHA256 Signature, key ID 8d8b756f: NOKEY Verifying... ################################# [100%] Preparing... ################################# [100%] Updating / installing... 1:jdk-25-2000:25-37 ################################# [100%] ``` Next, verify the Java version using the following command: ``` java --version ``` Sample output: ``` java 25 2025-09-16 LTS Java(TM) SE Runtime Environment (build 25+37-LTS-3491) Java HotSpot(TM) 64-Bit Server VM (build 25+37-LTS-3491, mixed mode, sharing) ``` ## Manage Java Versions If you are using multiple Java versions in your project, then you can easily switch between them using the following command: ``` alternatives --config java ``` You will be asked to set the default Java versions as shown below: ``` There are 2 programs which provide 'java'. Selection Command ----------------------------------------------- 1 /usr/lib/jvm/java-21-openjdk/bin/java *+ 2 /usr/lib/jvm/jdk-25-oracle-x64/bin/java Enter to keep the current selection[+], or type selection number: 1 ``` Select your preferred option and hit Enter to set the default Java version. Next, verify your current Java version using the following command: ``` java -version ``` Sample output: ``` openjdk version "21.0.8" 2025-07-15 LTS OpenJDK Runtime Environment (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS, mixed mode, sharing) ``` ## Conclusion In the above guide, you learned how to install OpenJDK 21, and Oracle JDK 25 on Rocky Linux 10. You also learned how to manage and switch between different Java versions. You can now easily install and manage your preferred Java version on your system. Get started on your [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Install WonderCMS on Rocky Linux 10 > URL: https://www.atlantic.net/vps-hosting/install-wondercms-on-rocky-linux-10/ | Published: 2021-12-01 | Updated: 2025-10-19 | Author: Hitesh Jethva WonderCMS is a simple, lightweight CMS written in PHP, jQuery, and HTML/CSS. It is a flat-file CMS, meaning it does not require a database like MySQL or MariaDB. WonderCMS allows you to create a website with ease without any programming knowledge. It offers a wide range of features including SEO-friendliness, friendly URLs, themes, custom login URLs, and more. In this post, we will explain how to install WonderCMS on Rocky Linux 10. ## Step 1 – Install Apache and PHP First, you will need to install Apache, PHP, and other necessary PHP extensions to your server. You can install all of them using the following command: ``` dnf install httpd php php-mysqlnd php-curl php-opcache php-xml php-gd php-mbstring php-zip php-json wget unzip git -y ``` Once all the packages are installed, edit the php.ini file and change some desired settings: ``` nano /etc/php.ini ``` Change the following settings: ``` file_uploads = On allow_url_fopen = On memory_limit = 256M post_max_size 32M upload_max_filesize = 64M max_execution_time = 300 date.timezone = "America/Chicago" ``` Save and close the file, then start the Apache service and enable it to start at system reboot: ``` systemctl start httpd systemctl enable httpd ``` ## Step 2 – Install WonderCMS Next, you will need to download the latest version of WonderCMS from the GitHub repository. You can download it using the following command: ``` git clone https://github.com/robiso/wondercms.git /var/www/html/wondercms ``` Once the download is completed, set proper permissions and ownership on the WonderCMS directory: ``` chown -R apache:apache /var/www/html/wondercms chmod -R 777 /var/www/html/wondercms ``` Once you are done, you can proceed to the next step. ## Step 3 – Create an Apache Virtual Host for WonderCMS Next, you will need to create an Apache virtual host configuration file for WonderCMS. You can create it using the following command: ``` nano /etc/httpd/conf.d/wondercms.conf ``` Add the following settings: ``` ServerName wonder.example.com DirectoryIndex index.php DocumentRoot /var/www/html/wondercms Redirect /wondercms/loginURL /loginURL ErrorLog /var/log/httpd/error.log CustomLog /var/log/httpd/access.log combined Options FollowSymLinks AllowOverride All Require all granted ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` You can check the status of Apache using the following command: ``` systemctl status httpd ``` You will get the following output: ``` ● ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; enabled; preset: disabled) Drop-In: /etc/systemd/system/httpd.service.d └─php-fpm.conf Active: active (running) since Mon 2025-10-20 00:21:51 EDT; 1s ago Invocation: 5afc27fa181f43dc939bc380d0123177 Docs: man:httpd.service(8) Main PID: 46420 (httpd) Status: "Started, listening on: port 80" Tasks: 177 (limit: 24809) Memory: 13.4M (peak: 13.8M) CPU: 103ms CGroup: /system.slice/httpd.service ├─46420 /usr/sbin/httpd -DFOREGROUND ├─46422 /usr/sbin/httpd -DFOREGROUND ├─46423 /usr/sbin/httpd -DFOREGROUND ├─46424 /usr/sbin/httpd -DFOREGROUND └─46445 /usr/sbin/httpd -DFOREGROUND . ``` ## Step 4 – Access WonderCMS Now, open your web browser and access the WonderCMS using the URL **http://wonder.example.com**. You should see the following screen containing your login password: ![](https://www.atlantic.net/wp-content/uploads/2021/12/w1.png) Click on the **“Click to login”**link. You should see the WonderCMS login screen: ![](https://www.atlantic.net/wp-content/uploads/2021/12/w2.png) Provide the WonderCMS password and click on the **Login** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/12/w3.png) Click on the**Open security settings** to change the default password and login URL as shown below: ![WonderCMS change login URL page](https://www.atlantic.net/wp-content/uploads/2021/11/p4-1-1024x536.png) Define your new login URL and password and click on the **CHANGE PASSWORD** button to update the password. ![WonderCMS update default password](https://www.atlantic.net/wp-content/uploads/2021/11/p4-2-1024x536.png) ## Conclusion Congratulations! You have successfully installed WonderCMS with Apache on Rocky Linux 10. You can now install themes and plugins and start creating your first website. Give it a try on your [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Config Server Firewall (CSF) on Rocky Linux 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-config-server-firewall-csf-on-rocky-linux-8/ | Published: 2021-12-02 | Updated: 2023-11-22 | Author: Hitesh Jethva CSF, also called **“Config Server Firewall,”** is a Stateful Packet Inspection (SPI) firewall for Linux operating systems. It provides basic firewall functionality as well as other security features, including login, intrusion, and flood detection. You can also integrate CSF with DirectAdmin, cPanel, and Webmin. Using CSF, you can detect many types of attacks like port scans, SYN floods, and login brute force attacks on many services. In this post, we will show you how to install and configure the CSF firewall on Rocky Linux 8. ## Step 1 – Install CSF on Rocky Linux 8 CSF is written in Perl, so you will need to install all required Perl modules to your system. You can install all of them with the following command: ``` dnf install @perl perl-libwww-perl.noarch perl-LWP-Protocol-https.noarch -y ``` After installing all required modules, download the latest version of CSF using the following command: ``` wget https://download.configserver.com/csf.tgz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar xzf csf.tgz ``` Next, navigate to the extracted directory and install CSF with the following command: ``` cd csf sh install.sh ``` Once CSF is installed, you will get the following output: ``` Don't forget to: 1. Configure the following options in the csf configuration to suite your server: TCP_*, UDP_* 2. Restart csf and lfd 3. Set TESTING to 0 once you're happy with the firewall, lfd will not run until you do so Adding current SSH session IP address to the csf whitelist in csf.allow: Adding 27.61.171.115 to csf.allow only while in TESTING mode (not iptables ACCEPT) *WARNING* TESTING mode is enabled - do not forget to disable it in the configuration 'lfd.service' -> '/usr/lib/systemd/system/lfd.service' 'csf.service' -> '/usr/lib/systemd/system/csf.service' Created symlink /etc/systemd/system/multi-user.target.wants/csf.service → /usr/lib/systemd/system/csf.service. Created symlink /etc/systemd/system/multi-user.target.wants/lfd.service → /usr/lib/systemd/system/lfd.service. Created symlink /etc/systemd/system/firewalld.service → /dev/null. '/etc/csf/csfwebmin.tgz' -> '/usr/local/csf/csfwebmin.tgz' Installation Completed ``` Next, verify that all the required iptables modules are available. ``` perl /usr/local/csf/bin/csftest.pl ``` If everything is set up correctly, you will get the following output: ``` Testing ip_tables/iptable_filter...OK Testing ipt_LOG...OK Testing ipt_multiport/xt_multiport...OK Testing ipt_REJECT...OK Testing ipt_state/xt_state...OK Testing ipt_limit/xt_limit...OK Testing ipt_recent...OK Testing xt_connlimit...OK Testing ipt_owner/xt_owner...OK Testing iptable_nat/ipt_REDIRECT...OK Testing iptable_nat/ipt_DNAT...OK RESULT: csf should function on this server ``` You can now check the CSF version using the following command: ``` csf -v ``` You will get the following output: ``` csf: v14.12 (generic) *WARNING* TESTING mode is enabled - do not forget to disable it in the configuration ``` ## Step 2 – Configure CSF By default, CSF main configuration file is located at **/etc/csf/csf.conf**. You will need to edit and change all settings as per your requirements: ``` nano /etc/csf/csf.conf ``` Change TESTING = “1” to TESTING = “0” and add allowed incoming and outgoing ports per your requirements: ``` # lfd will not start while this is enabled TESTING = "0" # Allow incoming TCP ports TCP_IN = "20,21,22,25,53,80,110,143,443,465,587,993,995" # Allow outgoing TCP ports TCP_OUT = "20,21,22,25,53,80,110,113,443,587,993,995" ``` Save and close the file when you are finished, then start and enable the CSF and LFD services: ``` systemctl start csf lfd systemctl enable csf lfd ``` You can check the status of CSF with the following command: ``` systemctl status csf ``` You should see the following output: ``` ● csf.service - ConfigServer Firewall & Security - csf Loaded: loaded (/usr/lib/systemd/system/csf.service; enabled; vendor preset: disabled) Active: active (exited) since Wed 2021-11-17 08:41:05 UTC; 3s ago Process: 13236 ExecStart=/usr/sbin/csf --initup (code=exited, status=0/SUCCESS) Main PID: 13236 (code=exited, status=0/SUCCESS) Tasks: 0 (limit: 11411) Memory: 0B CGroup: /system.slice/csf.service Nov 17 08:41:05 rockylinux csf[13236]: ACCEPT all opt in * out lo ::/0 -> ::/0 Nov 17 08:41:05 rockylinux csf[13236]: LOGDROPOUT all opt in * out !lo ::/0 -> ::/0 Nov 17 08:41:05 rockylinux csf[13236]: LOGDROPIN all opt in !lo out * ::/0 -> ::/0 Nov 17 08:41:05 rockylinux csf[13236]: csf: FASTSTART loading DNS (IPv4) Nov 17 08:41:05 rockylinux csf[13236]: csf: FASTSTART loading DNS (IPv6) Nov 17 08:41:05 rockylinux csf[13236]: LOCALOUTPUT all opt -- in * out !lo 0.0.0.0/0 -> 0.0.0.0/0 Nov 17 08:41:05 rockylinux csf[13236]: LOCALINPUT all opt -- in !lo out * 0.0.0.0/0 -> 0.0.0.0/0 Nov 17 08:41:05 rockylinux csf[13236]: LOCALOUTPUT all opt in * out !lo ::/0 -> ::/0 Nov 17 08:41:05 rockylinux csf[13236]: LOCALINPUT all opt in !lo out * ::/0 -> ::/0 Nov 17 08:41:05 rockylinux systemd[1]: Started ConfigServer Firewall & Security - csf. ``` You can also check the ports that are open when CSF is running using the following command: ``` csf -p ``` Sample output: ``` Ports listening for external connections and the executables running behind them: Port/Proto Open Conn PID/User Command Line Executable 22/tcp 4/6 1 (709/root) /usr/sbin/sshd -D -oCiphers=aes256-g... /usr/sbin/sshd 80/tcp 4/6 - (8954/root) /usr/sbin/httpd -DFOREGROUND /usr/sbin/httpd 80/tcp 4/6 - (8957/apache) /usr/sbin/httpd -DFOREGROUND /usr/sbin/httpd 80/tcp 4/6 - (8958/apache) /usr/sbin/httpd -DFOREGROUND /usr/sbin/httpd 80/tcp 4/6 - (8959/apache) /usr/sbin/httpd -DFOREGROUND /usr/sbin/httpd 80/tcp 4/6 - (9172/apache) /usr/sbin/httpd -DFOREGROUND /usr/sbin/httpd 323/udp -/- - (552/chrony) /usr/sbin/chronyd /usr/sbin/chronyd ``` ## Step 3 – How to Use CSF To flush all CSF rules, run the following command: ``` csf -f ``` To reload the CSF firewall, run the following command: ``` csf -r ``` To allow incoming connections from the specific IP, run the following command: ``` csf -a remote-ip-address ``` To deny connections from the specific IP, run the following command: ``` csf -d remote-ip-address ``` You can also edit the **csf.deny** and **csf.allow** file to define the list of allowed and denied IPs on the firewall. ## Step 4 – Enable CSF UI CSF also provides a web-based interface to manage the firewall. It is disabled by default. Before enabling CSF UI, install the required modules with the following command: ``` dnf install perl-IO-Socket-SSL perl-Net-SSLeay perl-IO-Socket-INET6 perl-Socket -y ``` Next, edit the CSF configuration file: ``` nano /etc/csf/csf.conf ``` Enable the UI, define the listening port, and set the admin username and password as shown below: ``` # 1 to enable, 0 to disable web ui UI = "1" # Set port for web UI. The default port is 6666, but # I change this to 1025 to easy access. Default port create some issue # with popular chrome and firefox browser (in my case) UI_PORT = "8080" # Leave blank to bind to all IP addresses on the server UI_IP = "" # Set username for authetnication UI_USER = "admin" # Set a strong password for authetnication UI_PASS = "securepassword" UI_ALLOW = "0" ``` Save and close the file then restart the CSF and LFD service to apply the changes: ``` systemctl restart lfd systemctl restart csf ``` ## Step 5 – Access CSF UI Now, open your web browser and access the CSF UI using the URL **https://your-server-ip:8080**. You should see the CSF login page: ![CSF login page](https://www.atlantic.net/wp-content/uploads/2021/11/p1-4-1024x481.png) Provide your admin username and password and click on the **Login** button. You should see the CSF web interface on the following screen: ![CSF dashboard page](https://www.atlantic.net/wp-content/uploads/2021/11/p2-3-1024x532.png) ## Step 6 – Remove CSF Firewall If you want to remove the CSF firewall completely from your server, just run the following script: ``` bash /etc/csf/uninstall.sh ``` This will remove the CSF firewall with all files, directories, and rules created by CSF. ## Conclusion In the above guide, we explained how to install CSF and CSF UI on Rocky Linux 8. We also explained how to ban and unban specific IP addresses with CSF. You can now implement CSF on your server and secure it from various type of attacks. Try it on your [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Getting started with Teams > URL: https://www.atlantic.net/vps-hosting/getting-started-with-teams/ | Published: 2021-12-03 | Updated: 2026-03-02 | Author: Josh Simon ## **Introduction** Atlantic.Net Teams (also known as Teams and the abbreviation ANT) allows users to collaborate and manage shared resources like Cloud Servers, IP Addresses, DNS, Block Storage, and more without having to share sensitive information like login credentials or billing information. Customers can control what resources users have access to create, view, and manage along with granting permission for users to contact support/billing for assistance. Teams is a feature included with an Atlantic.Net Cloud account at no additional charge. ****   **Teams highlights:** - Ability to create a Team - Invite others to join a Team - Assign Group permissions to Team Users like Administrator, Technical, Billing, Observer, or custom Groups - Track actions Users take via searchable user and service audit logs - Set security permissions for Users (require 2FA logins, password policies, etc) - Share important information through Notes on account resources - Included for free with your Cloud Account ## **What you will learn in this guide** Creating a Team Inviting a User to join your Team Managing Team Users (modifying user settings, password resets, and removing users) Team Audit Logs (viewing, searching, and sorting) Team Notes (creating, viewing, and pinning) Managing Team Groups (creating, editing, and deleting groups) Managing Team Settings Switching Between Teams ## **Creating a Team** **In the Atlantic.Net Control Panel, click on *Teams* in the navigation bar, fill out the fields based on your preference, then click the *Create* button to create your Team.** **Field Descriptions:** - *Team Name*: The name you want to give your Team. It will be displayed in the control panel and in emails to users you invite. - *Minimum Password Length*: The minimum number of characters you want to require your users to provide when creating or updating their passwords. - *Prevent Reuse of Last Number of Passwords*: This allows you to specify how many previous passwords you do not want your users to be to use again. Enter a value of “0” to allow the reuse of passwords. - *Expire Password in Number of Days*: Enter a value of “0” to never expire passwords. - Do not send owner emails when server actions are taken: Check this box if you do not want to receive an email update for actions taken on Cloud Servers through the API or Control Panel like server creation, reprovision, etc. - *Require Two-Factor Authentication for Team Users*: (Must be enabled on owner account to activate for team): Check this box to prompt your users to setup and provide a second factor (SMS or Auth App code) when logging into your Team. - *Admin required to reset team user passwords*: Check this box to require a Team user with Administrative permissions to reset user passwords. ![](https://www.atlantic.net/wp-content/uploads/2021/12/teamcreate.png)   **After Creating your Team you’ll be take to the Team *Users* page where you can invite and manage Team *Users*.** ![](https://www.atlantic.net/wp-content/uploads/2021/12/teammade.png) ## **Inviting a User to join your Team** Once your Team is created you can invite others to join your Team. When inviting a *User*, you will be able to assign specific permissions to your users that will control what resources they have access to create, view, and manage. Additionally, you’ll also be able to authorize users to contact support for assistance with your account and services. **To begin inviting a user to join your Team, click the *Invite Users* button on the Team *Users* page.** ![](https://www.atlantic.net/wp-content/uploads/2021/11/Screenshot_2020-09-18-Cloud-by-Atlantic-Net-e1638296013882.png) **You will now be viewing the *Invite Users* page where you can invite users and assign them *Group* permissions. Simply provide the name, email address, and phone number of the user you want to invite to your Team, select the permissions you want to assign to the *User* by picking the appropriate *Group*, and press the *Invite Users* button to invite the user. Your invited users will receive an email with instructions on how to join your Team.** Don’t worry, you can update a *User’s Group* permissions anytime from the *Users* page and if you want more granular permissions for a *User* than what the *Default Groups* provide, you can create a *Custom Group* with specific permissions from the *Groups* page. **Default Group Descriptions:** - *Administrator*: Can manage all features, billing, and contact support for all needs. - *Technical*: Can manage technical features and contact support for technical needs. - Billing: Can manage account billing, view servers, and contact support for billing needs. - *Observer*: Can only view features and has no contact permissions. This is great for users that are in training or you don’t want to be able to take actions on your account. ![](https://www.atlantic.net/wp-content/uploads/2021/12/invite_single_row.png) ## **Managing Team Users** Once you have invited a *User* to join your Team you can modify that user’s settings, reset their password, or remove them from your Team. **To modify a Team *User’s* settings, click the *Manage* drop-down menu next to the user you want to modify on the *User’s* page and select *Modify*.** ![](https://www.atlantic.net/wp-content/uploads/2021/11/Screenshot-from-2020-09-18-22-13-48-e1638296846805.png) **Once on the *Modify User* page, you can change the *User’s* permission *Group*. Simply select the new *Group* for the user and press the *Modify User* button to save the change.** ![](https://www.atlantic.net/wp-content/uploads/2021/11/Screenshot-from-2020-09-18-22-18-10-e1638296918760.png) **To reset a Team *User’s* password, click the *Manage* drop-down menu next to the *User* you want to modify on the *Users* page and select *Reset Password*.** ![](https://www.atlantic.net/wp-content/uploads/2021/11/Screenshot-from-2020-09-18-22-32-02-1-e1638297212405.png) **Once on the *Reset User Password* page, press the *Reset User Password* button to send a reset password link to the *User’s* email address.** ![](https://www.atlantic.net/wp-content/uploads/2021/11/Screenshot-from-2020-09-18-22-25-47.png) **To remove a *User* from your Team, click the *Manage* drop-down menu next to the user you want to modify on the *User’s* page and select *Remove*.** ![](https://www.atlantic.net/wp-content/uploads/2021/11/Screenshot-from-2020-09-18-22-36-59-e1638297342790.png)**Once on the *Remove User* page, press the *Remove User* button to remove the *User* from your Team. Once you proceed, the *User* will no longer have access to your Team and will be removed from your list of authorized contacts.** ![](https://www.atlantic.net/wp-content/uploads/2021/11/Screenshot-from-2020-09-18-22-41-04.png)Viewing Team Audit Logs Actions like inviting *Users* to your Team, updating user permissions, rebooting a server, creating a block storage volume, and more are all recorded in audit logs. These audit logs allow Team *Users* you authorize to view the action taken, who took the action, and when the action occurred. These Audit Logs can help you meet compliance requirements for your organization or simply figure out who took a specific action of interest to you. The audit logs are split into two categories: - User Audit Log: Logs of actions taken on Team *User* accounts (inviting *Users*, assigning *Groups*, resetting passwords, etc) - User Action Log: Logs of actions taken by *Users* on your Team (creating a server, rebooting a server, creating a block storage volume, etc) **To view the *User Audit Log* and the *User Action Log*, click on the *Audit Log* tab at the top of the Teams page.** **Once on the *Audit Log* page you can:** - View the logged entries in order from most recent to oldest. - Conduct a live search on by entering a search string in the *Filter* search query box to help narrow down what you are looking for. - Sort the results by a column by clicking on the sorting arrows next to the column heading in the results table.![](https://www.atlantic.net/wp-content/uploads/2021/11/Screenshot-from-2020-09-18-23-17-46.png) **In addition to the centralized logs available to you on the *Audit Log*page, you can also view all actions taken by your*Team* on an individual*Cloud Server*page.** **Click on *Servers* in the left hand navigation menu, then click on the server you want to view logs for.** Once on the page, you will see details on the last logged action taken on the server since you created your Team. ![](https://www.atlantic.net/wp-content/uploads/2021/11/Screenshot-from-2020-09-21-19-29-47-e1638297614204.png)   To view all logged actions taken on the server since you created your Team, scroll to the bottom of the *Server* page **Once you see the Logs, you can:** - View the logged entries in order from most recent to oldest. - Conduct a live search on by entering a search string in the *Search* query box to help narrow down what you are looking for. - Sort the results by a column by clicking on the sorting arrows next to the column heading in the results table.![](https://www.atlantic.net/wp-content/uploads/2021/11/Screenshot-from-2020-09-21-19-51-26-e1638297679788.png) ## **Team Notes** *Notes* allow you to share important information about your services with your *Team* members. For more important *Notes*, you can *Pin* them as important notes to make sure your Team doesn’t overlook them. *Notes* are only visible to your authorized *Team* members and are encrypted for your privacy. Examples of some *Notes* use cases: - Post a *Note* instructing Team members to contact a specific User before performing a reboot on a Server - Post a *Note* and *Pin* it as important to let your Team know about an upcoming maintenance window where you are planning to conduct software upgrades which may affect availability of the system. **To create a *Note* for a server, click on *Servers* in the left hand navigation menu, click on the server you want to post the Note to, then press the *Create Note* button on the *Server* details page.** ![](https://www.atlantic.net/wp-content/uploads/2021/11/Screenshot-from-2020-09-21-19-14-58.png)     You will now see the text field entry where you can enter the text for your *Note*. Your note will be prepended with the date, time, and user who is posting the *Note*, so you don’t have to type that information into the text field. If you want to mark the *Note* as more important than others, you can check the box to *Pin* the *Note* which will display the *Note* in bold text separated from non pinned notes. **Once you have entered your desired *Note* text and selected if you want your *Note* *Pinned* or not, press the *Add Note* button to post your *Note*.** ![](https://www.atlantic.net/wp-content/uploads/2021/11/Screenshot-from-2020-09-21-19-16-24-e1638297821878.png)   Your *Note* will now be displayed on the *Server* details page. Now, lets create a *Pinned Note*. **Press the *Create Note* button to create a new *Note*.** ![](https://www.atlantic.net/wp-content/uploads/2021/11/Screenshot-from-2020-09-21-19-22-19.png)   **Enter the details of your new Note, click the checkbox to *Pin* the *Note*, and press the *Add Note* button to post the *Note*.** ![](https://www.atlantic.net/wp-content/uploads/2021/11/Screenshot-from-2020-09-21-19-25-28.png)   You will now see your new *Note* has posted and is *Pinned* to the top of the *Notes* section on the *Server* details page. ![](https://www.atlantic.net/wp-content/uploads/2021/11/Screenshot-from-2020-09-21-19-27-14.png)   **If you want to *Pin* or *Un-Pin* an existing *Note*, simply click the + character to *Pin* the *Note*, and the – character to *Un-Pin* the *Note*.**   ## **Managing Team Groups** In the *Inviting Users to Join your Team* section of this document you learned that by assigning a user to a *Group* you control what resources they have access to create, view, and manage along with authorizing them to contact support for assistance with your account and services. While you may only want to use the *Default Groups* already available (*Administrator*, *Technical*, *Billing*, or *Observer*), you can also choose to create customized *Groups* with granular permissions to meet your organization’s or *User’s* specific needs. **To create a new *Group* for your Team, click on the *Groups* tab at the top of the *Teams* page and press the *Create Group* button.** ![](https://www.atlantic.net/wp-content/uploads/2021/12/groups_landing.png)   **You can now create a Group by specifying the following:** - *Group Name*: This is the display name of the Group you are creating and will be used to identify the Group when assigning to a User - *Group Description*: This field should be used to provide a short description of the permissions you have assigned to the Group - *Contact Permissions*: This section is used to authorize members of the Group to contact support for assistance with your account and services - *Administrator:* allows the Users in the *Group* access to technical, billing, and overall account related support - *Technical:* allows the *Users* in the *Group* access to technical support - *Billing:* allows the *Users* in the *Group* access to billing support - *Group Permissions*: This section is used to authorize members of the *Group* to access Atlantic.Net features and services on a granular basis. For example if you want a *Group* to have full access to all features and services, you can check the box for *Global – Allow All* or if you simply want a *Group* to only be able to reboot servers, you can check the box *Servers – Reboot Server*.   **Once you have selected the permissions you wish to grant to the *Group*, press the *Create Group* button at the bottom of the page to create your *Group*.** ![](https://www.atlantic.net/wp-content/uploads/2021/11/Screenshot-from-2020-09-19-00-18-41-e1638298048201.png) Once your *Group* has been created you can then, assign *Users* to your *Group* (see the *Inviting Team Users* and *Managing Team Users* section for details), edit *Group* settings, or delete your *Group*. **To edit an existing *Group* for your Team, click on the *Groups* tab at the top of the Teams page and press the *Edit* button for the desired *Group*.** ![](https://www.atlantic.net/wp-content/uploads/2021/12/cust_group_view.png)   Once on the *Group* page, you can update the permissions for the *Group* and press the *Update Group* button to save the changes.![](https://www.atlantic.net/wp-content/uploads/2021/11/Screenshot-from-2020-09-20-21-30-05.png)   **To delete an existing *Group* for your Team, click on the *Groups* tab at the top of the Teams page and press the *Delete* button for the desired *Group*.** ![](https://www.atlantic.net/wp-content/uploads/2021/12/cust_group_view.png) ## **Managing Team Settings** **In the Atlantic.Net Control Panel, click on *Teams* in the navigation bar, update the fields based on your preference, then click the *Update* button to update your Team settings.**   **Field Descriptions:** - *Team Name*: The name you want to give your Team. It will be displayed in the control panel and in emails to *Users* you invite. - *Minimum Password Length*: The minimum number of characters you want to require your *Users* to provide when creating or updating their passwords. - *Prevent Reuse of Last Number of Passwords*: This allows you to specify how many previous passwords you do not want your users to be to use again. Enter a value of “0” to allow the reuse of passwords. - *Expire Password in Number of Days*: Enter a value of “0” to never expire passwords. - *Do not send owner emails when server actions are taken*: Check this box if you do not want to receive an email update for actions taken on Cloud Servers through the API or Control Panel like server creation, reprovision, etc. - *Require Two-Factor Authentication for Team Users*(Must be enabled on owner account to activate for team): Check this box to prompt your *Users* to setup and provide a second factor (SMS or Auth App code) when logging into your Team. - *Admin required to reset team user passwords*: Check this box to require a *Team User* with Administrative permissions to reset user passwords. ![](https://www.atlantic.net/wp-content/uploads/2021/12/team_settings_page.png) ## Switching Between Teams If you are a member of multiple Teams or if you have a direct account with Atlantic.Net and are a member of another Team, you can will be prompted to choose the Team or Account you want to manage when you login. Additionally, once you are logged in, you can choose to switch to manage another Team you are a member of or your own Account if you have one. To choose a Team or Account to manage during the login process, simply enter  your username and password on the login screen and then click the Team or Account you want to manage. ![](https://www.atlantic.net/wp-content/uploads/2021/12/logint.png)   To choose a Team or Account to switch to once you are already logged in, please click the Teams menu in the upper left or the “Switch Teams” option from the Account Menu in the upper right of the control panel. ![](https://www.atlantic.net/wp-content/uploads/2021/12/switcht.png) --- # How to Install Icinga 2 Monitoring Tool on Rocky Linux 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-icinga-2-monitoring-tool-on-rocky-linux-8/ | Published: 2021-12-04 | Updated: 2023-11-23 | Author: Hitesh Jethva Icinga is a free and open-source system and network monitoring application for Linux operating systems. It is scalable and extensible and can monitor large and complex environments across multiple locations. It checks for network resources like CPU, Memory, Uptime, Processes, Disk space, and other services like HTTP, SMTP, SSH, and more. It can be configured to notify users and generates performance data for reporting. In this post, we will show you how to install Icinga 2 monitoring tool on Rocky Linux 8. ## Step 1 – Add Icinga 2 Repository By default, Icinga 2 is not included in the Rocky Linux 8 default repo, so you will need to add the Icinga 2 repository to your system. First, install the EPEL repository using the following command: ``` dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-8.noarch.rpm ``` Next, create an Icinga 2 repo with the following command: ``` nano /etc/yum.repos.d/icinga2.repo ``` Add the following lines: ``` [icinga2] name=Icinga 2 Repository for EPEL 8 baseurl=https://packages.icinga.com/epel/8/release enabled=1 ``` Save and close the file, then import the Icinga 2 key: ``` rpm --import https://packages.icinga.com/icinga.key ``` Next, clean the package cache with the following command: ``` dnf clean all dnf makecache ``` ## Step 2 – Install and Configure MariaDB Database Icinga 2 uses MariaDB as a database backend, so you will need to install the MariaDB server to your system. You can install it using the following command: ``` dnf install mariadb-server -y ``` Once MariaDB is installed, start and enable the MariaDB service using the following command: ``` systemctl start mariadb systemctl enable mariadb ``` Next, secure the MariaDB installation and set the root password with the following command: ``` mysql_secure_installation ``` Answer all the questions as shown below: ``` Enter current password for root (enter for none): OK, successfully used password, moving on... Set root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` Next, log in to MariaDB with the following command: ``` mysql -u root -p ``` Once you are logged in, create a database and user for Icinga 2: ``` CREATE DATABASE icinga; GRANT ALL PRIVILEGES ON icinga.* TO 'icinga'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from MariaDB with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install and Configure Icinga 2 Next, run the following command to install Icinga 2 and other required tools: ``` dnf install icinga2 icinga2-selinux icinga2-ido-mysql vim-icinga2 -y ``` Once Icinga 2 is installed, run the following command to enable the required features: ``` icinga2 feature enable command ido-mysql syslog ``` Next, import the Icinga 2 database schema to the Icinga database with the following command: ``` mysql -u root -p icinga < /usr/share/icinga2-ido-mysql/schema/mysql.sql ``` Next, edit the Icinga 2 MySQL configuration file: ``` nano /etc/icinga2/features-available/ido-mysql.conf ``` Define your database settings as shown below: ``` * The IdoMysqlConnection type implements MySQL support * for DB IDO. */ object IdoMysqlConnection "ido-mysql" { user = "icinga" password = "password" host = "localhost" database = "icinga" } ``` Save and close the file, then start and enable the Icinga 2 service: ``` systemctl start icinga2 systemctl enable icinga2 ``` To check the Icinga 2 service, run the following command: ``` systemctl status icinga2 ``` You will get the following output: ``` ● icinga2.service - Icinga host/service/network monitoring system Loaded: loaded (/usr/lib/systemd/system/icinga2.service; disabled; vendor preset: disabled) Active: active (running) since Wed 2021-11-17 09:22:54 UTC; 4s ago Process: 18616 ExecStartPre=/usr/lib/icinga2/prepare-dirs /etc/sysconfig/icinga2 (code=exited, status=0/SUCCESS) Main PID: 18624 (icinga2) Status: "Startup finished." Tasks: 11 (limit: 11411) Memory: 14.2M CGroup: /system.slice/icinga2.service ├─18624 /usr/lib64/icinga2/sbin/icinga2 --no-stack-rlimit daemon --close-stdio -e /var/log/icinga2/error.log ├─18639 /usr/lib64/icinga2/sbin/icinga2 --no-stack-rlimit daemon --close-stdio -e /var/log/icinga2/error.log └─18642 /usr/lib64/icinga2/sbin/icinga2 --no-stack-rlimit daemon --close-stdio -e /var/log/icinga2/error.log ``` ## Step 4 – Install Icinga Web 2 Icinga Web 2 is a web-based application used to manage Icinga 2 from a web-based interface. By default, it is not available in the Rocky Linux default repo, so you will need to enable the Powertools repo in your system. Run the following command to enable the Powertools repo: ``` dnf install 'dnf-command(config-manager)' dnf config-manager --set-enabled powertools ``` Next, run the following command to install Icinga Web 2 with Apache and other packages: ``` dnf install httpd icingacli icingaweb2 php-json php-ldap ``` Once all the packages are installed, start and enable the Apache and PHP-FPM service: ``` systemctl enable --now httpd systemctl enable --now php-fpm.service ``` ## Step 5 – Access Icinga Web 2 Setup Wizard Before starting, you will need to configure the Apache webserver for Icinga Web 2. You can configure it using the following command: ``` icingacli setup config webserver apache ``` Next, generate an authentication token with the following command: ``` icingacli setup token create ``` You will get the following output: ``` The newly generated setup token is: a84a833dd624e6a0 ``` Now, open your web browser and access the Icinga Web 2 setup wizard using the URL **http://your-server-ip/icingaweb2/setup**. You should see the Icinga Web 2 welcome screen: ![Icinga 2 setup page](https://www.atlantic.net/wp-content/uploads/2021/11/p1-6-1024x537.png) Provide your generated token and click on the **Next** button. You should see the following screen: ![Icinga 2 select module page](https://www.atlantic.net/wp-content/uploads/2021/11/p2-5-1024x469.png) Select the module that you want to enable and click on the **Next** button. You should see the following screen: ![Icinga 2 verify PHP extensions page](https://www.atlantic.net/wp-content/uploads/2021/11/p3-3-1024x539.png) Make sure all the PHP extensions are installed, then click on the **Next** button. You should see the following screen: ![Icinga 2 select authentication page](https://www.atlantic.net/wp-content/uploads/2021/11/p4-3-1024x425.png) Select your authentication type and click on the **Next** button. You should see the following screen: ![Icinga web 2 database details](https://www.atlantic.net/wp-content/uploads/2021/11/p5-1-1024x541.png) Provide your Icinga Web 2 database name, root username, password, and click on the **Next** button. You should see the following screen: ![Icinga web 2 provide backend details](https://www.atlantic.net/wp-content/uploads/2021/11/p6-1-1024x440.png) Provide your backend name and click on the **Next** button. You should see the following screen: ![Icinga web 2 provide admin username](https://www.atlantic.net/wp-content/uploads/2021/11/p7-1-1024x462.png) Provide your admin username and password and click on the **Next** button. You should see the following screen: ![Icinga web 2 provide logging details](https://www.atlantic.net/wp-content/uploads/2021/11/p8-1-1024x487.png) Provide your logging details and click on the **Next** button. You should see the following screen: ![Icinga web 2 verify all details](https://www.atlantic.net/wp-content/uploads/2021/11/p9-1-1024x540.png) Verify all details and click on the **Next** button. You should see the following screen: ![Icinga web 2 welcome page](https://www.atlantic.net/wp-content/uploads/2021/11/p10-1-1024x392.png) Click on the **Next** button. You should see the following screen: ![Provide Icinga 2 database name](https://www.atlantic.net/wp-content/uploads/2021/11/p11-1024x540.png) Provide your Icinga 2 database name, root username, password, and click on the **Next** button. You should see the following screen: ![configure command transport](https://www.atlantic.net/wp-content/uploads/2021/11/p12-1024x394.png) Configure the command transport and click on the **Next** button. You should see the following screen: ![configure monitoring security](https://www.atlantic.net/wp-content/uploads/2021/11/p14-1024x318.png) Configure monitoring security and click on the **Next** button. You should see the following screen: ![Verify all configuration](https://www.atlantic.net/wp-content/uploads/2021/11/p15-1024x539.png) Verify all settings and click on the **Finish** button. You should see the following screen: ![Icinga 2 setup completed](https://www.atlantic.net/wp-content/uploads/2021/11/p16-1024x489.png) Click on the **Login to Icinga Web 2** button. You should see the following screen: ![Icinga 2 login page](https://www.atlantic.net/wp-content/uploads/2021/11/p17-1024x548.png) Provide your admin username and password and click on the **Login** button. You should see the Icinga Web 2 dashboard on the following screen: ![Icinga 2 dashboard page](https://www.atlantic.net/wp-content/uploads/2021/11/p18-1024x530.png) ## Conclusion Congratulations! You have successfully installed Icinga 2 and Icinga Web 2 on Rocky Linux 8. You can now install Icinga 2 agents on the client system and start monitoring them from the Icinga Web 2 dashboard. Try it on your [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net --- # How to Install Fail2ban with Firewalld on Rocky Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-fail2ban-with-firewalld-on-rocky-linux-10/ | Published: 2021-12-05 | Updated: 2025-10-19 | Author: Hitesh Jethva Fail2ban is a free and open-source intrusion prevention software solution that protects servers from brute-force login attacks. It monitors various log files of SSH and other web applications, and whenever any failed authentication is detected and reaches the max numbers, Fail2Ban will automatically block the IP address using the iptables of Firewalld. Fail2Ban is simple, handy, easy to configure, and flexible. In this guide, we will show you how to install Fail2Ban with firewalld on Rocky Linux 10. ## Step 1 – Configure Firewalld By default, Firewalld comes pre-installed in Rocky Linux 10. You can check whether it is installed by using the following command: ``` dnf update -y dnf info firewalld ``` If the is installed, you will get the following output: ``` Last metadata expiration check: 0:04:44 ago on Sun 19 Oct 2025 11:44:30 PM EDT. Installed Packages Name : firewalld Version : 2.3.0 Release : 2.el10 Architecture : noarch Size : 2.0 M Source : firewalld-2.3.0-2.el10.src.rpm Repository : @System From repo : baseos Summary : A firewall daemon with D-Bus interface providing a dynamic firewall URL : http://www.firewalld.org License : GPL-2.0-or-later Description : firewalld is a firewall service daemon that provides a dynamic customizable : firewall with a D-Bus interface. Available Packages Name : firewalld Version : 2.3.1 Release : 1.el10_0 Architecture : noarch Size : 548 k Source : firewalld-2.3.1-1.el10_0.src.rpm Repository : baseos Summary : A firewall daemon with D-Bus interface providing a dynamic firewall URL : http://www.firewalld.org License : GPL-2.0-or-later Description : firewalld is a firewall service daemon that provides a dynamic customizable : firewall with a D-Bus interface. ``` Next, verify whether the Firewalld is running or not. ``` systemctl status firewalld ``` You should see that the Firewalld service is inactive: ``` ○ firewalld.service - firewalld - dynamic firewall daemon Loaded: loaded (/usr/lib/systemd/system/firewalld.service; disabled; preset: enabled) Active: inactive (dead) since Sun 2025-10-19 23:50:12 EDT; 1s ago Duration: 6min 9.710s ``` So you will need to activate the Firewalld service. You can start it using the following command: ``` systemctl start firewalld systemctl enable firewalld ``` At this point, Firewalld is installed and running in your system. You can now proceed to the next step. ## Step 2 – Install Fail2Ban By default, the Fail2Ban package is not included in the Rocky Linux 10 default repo, so you will need to add EPEL repo to your system. Run the following command to install the EPEL repo: ``` dnf install epel-release -y ``` Next, install the Fail2Ban package with the following command: ``` dnf install fail2ban fail2ban-firewalld -y ``` Once Fail2Ban is installed, start and enable the Fail2Ban service using the following command: ``` systemctl start fail2ban systemctl enable fail2ban ``` You can verify the Fail2Ban version using the following command: ``` fail2ban-client --version ``` Sample output: ``` Fail2Ban v1.1.0 ``` ## Step 3 – Configure Fail2Ban By default, Fail2Ban is configured to use the iptables firewall, so you will need to configure Fail2Ban to work with Firewalld. First, rename the Firewalld configuration file for Fail2Ban using the following command: ``` mv /etc/fail2ban/jail.d/00-firewalld.conf /etc/fail2ban/jail.d/00-firewalld.local ``` Next, copy the Fail2Ban default configuration file: ``` cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local ``` Next, edit the jail.local file: ``` nano /etc/fail2ban/jail.local ``` Find the following lines: ``` banaction = iptables-multiport banaction_allports = iptables-allports ``` And replace them with the following lines: ``` banaction = firewallcmd-rich-rules[actiontype=] banaction_allports = firewallcmd-rich-rules[actiontype=] ``` Save and close the file, then restart the Fail2Ban to apply the changes: ``` systemctl restart fail2ban ``` At this point, Fail2Ban is configured to work with Firewalld. ## Step 4 – Secure SSH Service with Fail2Ban By default, Fail2Ban is not configured to block any IP addresses. You will need to enable the specific jail for each service you want to protect. To protect the SSHD service, edit the jail.local file: ``` nano /etc/fail2ban/jail.local ``` Find the [sshd] section and enable it by adding the following lines: ``` [sshd] enabled = true port = ssh logpath = %(sshd_log)s backend = %(sshd_backend)s bantime = 10m findtime = 10m maxretry = 5 ``` Save and close the file, then restart Fail2Ban to apply the changes: ``` systemctl restart fail2ban ``` You can now verify the status of Fail2Ban using the following command: ``` systemctl status fail2ban ``` You will get the following output: ``` fail2ban.service - Fail2Ban Service Loaded: loaded (/usr/lib/systemd/system/fail2ban.service; disabled; preset: disabled) Active: active (running) since Sun 2025-10-19 23:47:48 EDT; 2s ago Invocation: bf7b50d6f60346e68c05b090c2c4d1d6 Docs: man:fail2ban(1) Process: 44741 ExecStartPre=/bin/mkdir -p /run/fail2ban (code=exited, status=0/SUCCESS) Main PID: 44743 (fail2ban-server) Tasks: 5 (limit: 24809) Memory: 13.3M (peak: 36M) CPU: 807ms CGroup: /system.slice/fail2ban.service └─44743 /usr/bin/python3 -sP /usr/bin/fail2ban-server -xf start 2025-10-19 23:47:48,488 fail2ban.filter [44743]: INFO [sshd] Found 69.164.245.208 - 2025-10-19 23:47:36 2025-10-19 23:47:48,488 fail2ban.filtersystemd [44743]: INFO [sshd] Jail is in operation now (process new journal entries) 2025-10-19 23:47:48,575 fail2ban.actions [44743]: NOTICE [sshd] Ban 69.164.245.208 2025-10-19 23:47:48,825 fail2ban.actions [44743]: NOTICE [sshd] Ban 193.46.255.103 2025-10-19 23:47:49,077 fail2ban.actions [44743]: WARNING [sshd] 69.164.245.208 already banne ``` ## Step 5 – Verify Fail2Ban Firewall At this point, Fail2Ban is configured to protect the SSH service. Now, it’s time to check whether Fail2Ban is working. First, verify the jail configuration using the following command: ``` fail2ban-client status ``` You should see the following output: ``` Status |- Number of jail: 1 `- Jail list: sshd ``` Now, go to the remote machine and try to connect to the SSH server with an incorrect password. After reaching the max number of retries (5 times), your IP address will be blocked by Fail2Ban. Now, check the IP address blocked by Fail2Ban using the following command: ``` fail2ban-client status sshd ``` You should get the following output: ``` Status for the jail: sshd |- Filter | |- Currently failed: 1 | |- Total failed: 6 | `- Journal matches: _SYSTEMD_UNIT=sshd.service + _COMM=sshd `- Actions |- Currently banned: 1 |- Total banned: 1 `- Banned IP list: 27.61.171.115 ``` You can check the rules added by Firewalld with the following command: ``` firewall-cmd --list-rich-rules ``` You will get the following output: ``` rule family="ipv4" source address="27.61.171.115" port port="ssh" protocol="tcp" reject type="icmp-port-unreachable" ``` You can also check the Fail2Ban logs for more information: ``` tail -f /var/log/fail2ban.log ``` Sample output: ``` 2025-10-19 23:47:48,488 fail2ban.filter [44743]: INFO [sshd] Found 69.164.245.208 - 2025-10-19 23:47:36 2025-10-19 23:47:48,488 fail2ban.filtersystemd [44743]: INFO [sshd] Jail is in operation now (process new journal entries) 2025-10-19 23:47:48,575 fail2ban.actions [44743]: NOTICE [sshd] Ban 69.164.245.208 2025-10-19 23:47:48,825 fail2ban.actions [44743]: NOTICE [sshd] Ban 193.46.255.103 2025-10-19 23:47:49,077 fail2ban.actions [44743]: WARNING [sshd] 69.164.245.208 already banned ``` ## Conclusion Congratulations! You have successfully installed Fail2Ban with Firewalld. You can now implement Fail2Ban on your server to protect it against brute-force login attacks. Try it out on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net! --- # Top SEO Tools > URL: https://www.atlantic.net/vps-hosting/top-seo-tools/ | Published: 2021-12-07 | Updated: 2026-05-04 | Author: Alexander Wise With no shortage of SEO tools on the market, choosing the right one can be a bit of a headache. A powerful SEO tool can help you to optimize and simplify your SEO efforts, driving traffic to your site and increasing your revenue. However, with each tool geared towards a specific type of SEO use case, it is important that you choose the right one for your needs. Some tools can really help an SEO novice to delve into the complex and daunting world of SEO, while others are designed to be used by SEO experts. Here, we will highlight a selection of some of the top SEO tools currently available on the market and highlight whether these are suitable for beginners or experts. If your budget is limited, we have also included some tools that are free to use. ## Top 10 SEO Tools on the Market: ### 1. SEMrush SEMrush offers businesses a comprehensive SEO platform, offering over 50 tools to help build online visibility. It is trusted by over 7 million marketing professionals and has gained 14 international awards as the best SEO software suite. SEMrush provides you with detailed keyword analysis tools and the opportunity to analyze and compare the performance of direct competitors. With customizable toolkits, SEMrush can help users who have little or no SEO knowledge with their campaigns. Some businesses may prefer to use a complete software package such as this rather than investing money in outsourcing to an SEO company. The downside is that learning about SEO will take time and patience and is no match for the experience and knowledge of a dedicated SEO professional. ### 2. Ahrefs Released in 2011, Ahrefs is a popular professional-grade SEMrush alternative. It provides an all-in-one SEO suite alongside free learning materials and access to a private online support community. The user interface is designed to be used by experienced digital marketers and is feature-rich. Trusted by some of the world’s leading companies, Ahrefs boasts one of the world’s best backlink analysis tools, an extensive web list index, advanced filtering tools, and comprehensive user support and documentation. While the price plans offered by Ahrefs are fairly high, they do offer you enough powerful features and continued community support to justify this investment. ### 3. Advanced Web Ranking Founded in 2002, Advanced Web Ranking (AWR) is an advanced and reliable rank tracking solution, trusted by over 24,000 leading agencies and brands worldwide. A free 30-day trial lets clients determine whether it is the best solution for their business before spending any money. The tool supports unlimited websites and unlimited users at no extra cost and is accessible from any device. Key features include hyper-specific local SEO results, monitoring across over 4,000 search engines in more than 170 countries, customizable reporting, and white-label reporting. ### 4. Yoast SEO Yoast SEO is a beginner-friendly and comprehensive WordPress plugin that provides some great features, helping you to improve the standard of SEO and readability across your site. Yoast SEO features include page optimization, “SEO Workouts” to get your site into shape, powerful internal linking tools, and a redirection plugin. A premium subscription to Yoast SEO gives users access to a complete catalog of SEO courses. ### 5. Moz Pro With over 50,000 users, Moz Pro is a leader in the SEO tools space, offering a complete and powerful toolset. While Moz does provide limited free SEO tools, Moz Pro is their paid web version suitable for small and larger businesses. This tool provides a wealth of features including a keyword explorer, link explorer, ranking tracker, content optimizer, SEO audit tools, and a backlink checker. Users are able to try before they buy with a 30-day free trial. ### 6. SpyFu SpyFu is one of the most popular competitor keyword analysis tools on the market. With competitive price plans that all include unlimited searches and downloads, it is ideal for businesses on a tight budget who want to make the biggest possible impact. SpyFu enables you to identify new keywords to increase both your paid and organic traffic. Competitor analysis lets you learn from the successes and failures of your direct competitors. The reason why SpyFu appears further down the list of our top SEO tools is that the information provided through its keyword research is not as extensive as that achieved using more expensive tools, such as SEMrush. ### 7. Screaming Frog Founded in 2010, Screaming Frog is a UK-based digital marketing agency that has created the industry-leading Screaming Frog SEO Spider, a website crawler and log file analysis tool. Screaming Frog SEO Spider is trusted by thousands of businesses and SEO agencies across the world. It allows users to crawl through websites, analyze key on-site data, audit redirects, identify broken links, analyze H1s and meta descriptions, discover duplicate content, and generate XML sitemaps. A free version is available with limited features. As it is an advanced tool, Screaming Frog is a good choice for digital marketing experts and larger companies. ### 8. KWFinder KWFinder by Mangools is a keyword finder tool that allows you to find long-tail keywords with low SEO difficulty. As well as KWFinder, Mangools offers a comprehensive suite of tools including SERP analysis, rank tracking, backlink analysis, and SEO metrics and insights. Despite not being as feature-rich as many of its competitors, KWFinder is a go-to tool for many SEO experts. ### 9. Surfer SEO Surfer SEO helps users to write and optimize their content quickly and easily. Trusted by over 8,000 clients, Surfer SEO’s algorithms help you to generate content that is specific for your domain, niche, and audience. A one-click audit of your website provides information on how to increase rankings and improve the quality of your content. Surfer SEO analyzes and compares over 500 ranking factors on your site with data from the top 50 ranking competitors. Its ease of use means that Surfer SEO can be a particularly helpful tool for those with less SEO experience. ### 10. Answer The Public Answer The Public is a great tool for generating new topic ideas for your blog based on specific keywords. Using a specified keyword, Answer The Public uses Google’s autocomplete predictions to determine the questions and phrases that people are searching for. These questions can be particularly useful for populating headers or FAQ articles. This consumer insight is invaluable for tailoring your content to the needs of your audience. Answer The Public allows users to perform some free searches, however, these are limited based on their traffic. They offer a number of different price plans to cater to businesses of different sizes. ## Bonus: Sitechecker Sitechecker is a Ukrainian all-in-one SEO platform created in 2016. The tools of this platform will help you conduct high-quality SEO audits, technical analyses and monitoring of your site. Sitechecker has many free and paid features. You can check your site for technical errors, analyze traffic, its safety, as well as its download speed and position in search engines. In addition, this platform will perform ongoing SEO monitoring of your site and track changes occurring on it. For example, the [SEO Page Checker](https://sitechecker.pro/on-page-seo-checker/) will help you perform an on-page SEO audit to find errors in meta tags, structured markup, page speed, indexing status, and hreflang tags. Sitechecker has a free trial and the pricing plans are very flexible. ## Bonus: Netpeak Checker Netpeak Checker is a multifunctional tool that allows you to aggregate data from top SEO services. With its help, you can analyze the link profile, compare sites, parse search results, and [check seo](https://netpeaksoftware.com/checker) using various parameters. Thanks to its reliability, high speed, and efficiency, it can handle the most complex and large tasks and automate your research in various fields. After all, everyone understands that a poorly functioning website entails negative consequences for the entire business. Moreover, in today’s highly competitive business environment, to acquire a decent client base, it is vital to organize the processes so that all communication channels work clearly.   ## How Can Atlantic.Net Drive Your SEO Results? Choosing good [SEO tools](https://theventurer.co/seo-software/) and a good [digital marketing agency](https://peertopeermarketing.co/marketing-strategy-agencies/) is vital to help you navigate your way around the complexities of SEO optimization. But did you know that partnering with a leading [VPS hosting provider](https://www.atlantic.net/vps-hosting/) can also boost your SEO efforts? Factors such as uptime, page load time, hosting location, and reliability can have an impact on your SEO rankings. Choosing to partner with the [best cloud hosting provider](https://www.atlantic.net/vps-hosting/what-is-cloud-hosting/) for your site can help to optimize these factors and boost your organic traffic. As a market-leading cloud computing and hosting solutions provider, Atlantic.Net is uniquely placed to help you to improve your SEO ranking. We have over 30 years of experience in the industry and are passionate about providing a customized solution to meet the needs of your business or organization. To find out more about the solutions that we offer, [contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # How to Install and Configure Velociraptor on Ubuntu > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-velociraptor-on-ubuntu/ | Published: 2021-12-09 | Updated: 2025-05-16 | Author: Hitesh Jethva Velociraptor is an open-source tool that can be used for collecting host-based state information using Velocidex Query Language. It is based on GRR, OSQuery, and Google’s Rekall tool. It can scale thousands of hosts using the Velociraptor Query Language. VQL is an expressive query language that allows you to gather information without deploying any software. Velociraptor is made from six components including Frontend, Gui, Client, VQL Engine, Data Store, and File Store. In this guide, we will explain how to install Velociraptor on an Ubuntu server. This procedure is compatible with Ubuntu 20.04 and Ubuntu 24.04. ## Step 1 – Install and Configure Velociraptor By default, Velociraptor is not included in the Ubuntu default repository, so you will need to download it from the Git repository. You can download it with the following command: ``` wget https://github.com/Velocidex/velociraptor/releases/download/v0.74/velociraptor-v0.74.1-linux-amd64 ``` Once the download is completed, copy the downloaded binary to the system location with the following command: ``` cp velociraptor-v0.74.1-linux-amd64 /usr/local/bin/velociraptor ``` Next, set proper permission with the following command: ``` chmod +x /usr/local/bin/velociraptor ``` Next, run the following command to configure Velociraptor: ``` velociraptor config generate -i ``` Answer all questions as shown below: ``` ? Welcome to the Velociraptor configuration generator --------------------------------------------------- I will be creating a new deployment configuration for you. I will begin by identifying what type of deployment you need. What OS will the server be deployed on? linux ? Path to the datastore directory. /opt/velociraptor ? Self Signed SSL ? What is the public DNS name of the Master Frontend (e.g. www.example.com): 45.58.43.227 ? Enter the frontend port to listen on. 8000 ? Enter the port for the GUI to listen on. 8889 ? Are you using Google Domains DynDNS? No ? GUI Username or email address to authorize (empty to end): admin ? GUI Username or email address to authorize (empty to end): [INFO] 2021-06-20T07:09:48Z _ __ __ _ __ [INFO] 2021-06-20T07:09:48Z | | / /__ / /___ _____(_)________ _____ / /_____ _____ [INFO] 2021-06-20T07:09:48Z | | / / _ \/ / __ \/ ___/ / ___/ __ `/ __ \/ __/ __ \/ ___/ [INFO] 2021-06-20T07:09:48Z | |/ / __/ / /_/ / /__/ / / / /_/ / /_/ / /_/ /_/ / / [INFO] 2021-06-20T07:09:48Z |___/\___/_/\____/\___/_/_/ \__,_/ .___/\__/\____/_/ [INFO] 2021-06-20T07:09:48Z /_/ [INFO] 2021-06-20T07:09:48Z Digging deeper! https://www.velocidex.com [INFO] 2021-06-20T07:09:48Z This is Velociraptor 0.5.9 built on 2021-05-10T19:48:17+10:00 (fbe594c5) [INFO] 2021-06-20T07:09:48Z Generating keys please wait.... ? Path to the logs directory. /opt/velociraptor/logs ? Where should i write the server config file? /root/server.config.yaml ``` Next, edit the Velociraptor configuration file with the following command: ``` nano /root/server.config.yaml ``` **Find all instances** of the following line: ``` bind_address: 127.0.0.1 ``` Replace them with the following line: ``` bind_address: your-server-ip ``` Save and close the file when you are finished. ## Step 2 – Create a Systemd Service File for Velociraptor Next, you will need to create a systemd service file for Velociraptor. You can create it with the following command: ``` nano /lib/systemd/system/velociraptor.service ``` Add the following lines: ``` [Unit] Description=Velociraptor linux amd64 After=syslog.target network.target [Service] Type=simple Restart=always RestartSec=120 LimitNOFILE=20000 Environment=LANG=en_US.UTF-8 ExecStart=/usr/local/bin/velociraptor --config /root/server.config.yaml frontend -v [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon: ``` systemctl daemon-reload ``` Next, start the Velociraptor service and enable it to start at system reboot: ``` systemctl enable --now velociraptor ``` You can now check the status of Velociraptor with the following command: ``` systemctl status velociraptor ``` Output: ``` ● velociraptor.service - Velociraptor linux amd64 Loaded: loaded (/usr/lib/systemd/system/velociraptor.service; disabled; preset: enabled) Active: active (running) since Fri 2025-05-16 06:30:40 UTC; 3s ago Main PID: 76819 (velociraptor) Tasks: 17 (limit: 629145) Memory: 85.9M (peak: 86.4M) CPU: 4.274s CGroup: /system.slice/velociraptor.service ├─76819 /usr/local/bin/velociraptor --config /root/server.config.yaml frontend -v └─76827 /usr/local/bin/velociraptor --config /root/server.config.yaml frontend -v May 16 06:30:42 ubuntu24 velociraptor[76819]: [INFO] 2025-05-16T06:30:42Z Upgrading tool OSQueryWindows {"Tool":{"name":"OSQueryWindows","github_project":"Velocidex/OS> May 16 06:30:42 ubuntu24 velociraptor[76819]: [INFO] 2025-05-16T06:30:42Z Upgrading tool Autorun_386 {"Tool":{"name":"Autorun_386","url":"https://live.sysinternals.com> May 16 06:30:43 ubuntu24 velociraptor[76819]: [INFO] 2025-05-16T06:30:43Z Compiled all artifacts. May 16 06:30:43 ubuntu24 velociraptor[76819]: [INFO] 2025-05-16T06:30:43Z CryptoServerManager: Watching for events from Server.Internal.ClientDelete May 16 06:30:43 ubuntu24 velociraptor[76819]: [INFO] 2025-05-16T06:30:43Z Throttling connections to 100 QPS May 16 06:30:43 ubuntu24 velociraptor[76819]: [INFO] 2025-05-16T06:30:43Z Starting gRPC API server on 69.28.91.23:8001 May 16 06:30:43 ubuntu24 velociraptor[76819]: [INFO] 2025-05-16T06:30:43Z Launched Prometheus monitoring server on 69.28.91.23:8003 May 16 06:30:43 ubuntu24 velociraptor[76819]: [INFO] 2025-05-16T06:30:43Z GUI will use the Basic authenticator May 16 06:30:43 ubuntu24 velociraptor[76819]: [INFO] 2025-05-16T06:30:43Z GUI is ready to handle TLS requests on https://69.28.91.23:8889/ May 16 06:30:43 ubuntu24 velociraptor[76819]: [INFO] 2025-05-16T06:30:43Z Frontend is ready to handle client TLS requests at https://69.28.91.23:8000/ ``` ## Step 3 – Access Velociraptor Web UI At this point, Velociraptor is installed and listen on port 8889. You can check the listening port with the following command: ``` ss -antpl | grep 8889 ``` Output: ``` LISTEN 0 4096 your-server-ip:8889 0.0.0.0:* users:(("velociraptor",pid=1074,fd=27)) ``` You can now access it using the URL **https://your-server-ip:8889**. You should see the Velociraptor dashboard on the following screen: ![Velociraptor Login Page](https://www.atlantic.net/wp-content/uploads/2021/06/p1-10-1024x392.png) Provide your admin username, password and click on the **Sign in**. You should see the Velociraptor dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/12/v1.png) ## Conclusion Congratulations! You have successfully installed and configured Velociraptor on Ubuntu. You can now configure Velociraptor clients and monitor them from the Velociraptor dashboard. Get started on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install Uptime-Kuma Self-Hosted Uptime Robot Alternative on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-uptime-kuma-self-hosted-uptime-robot-alternative-on-ubuntu-20-04/ | Published: 2021-12-10 | Updated: 2024-01-18 | Author: Hitesh Jethva Uptime-Kuma is a free, open-source, self-hosted monitoring tool written in Nodejs. It provides a web-based interface and supports multiple notification methods including Webhooks, Telegram, Discord, Gotify, Slack, Pushover, Email (SMTP), and more. Uptime-Kumacan monitor the uptime of remote hosts or servers via TCP, Ping, and HTTPS. If you are looking for a tool to monitor the uptime of remote servers, then Uptime-Kuma is the best tool for you. In this post, we will show you how to install the Uptime-Kuma uptime monitoring tool on Ubuntu 20.04. ## Step 1 – Install Nodejs Uptime-Kuma is written in Node.js, so you will need to install Node.js to your server. First, install the necessary dependencies using the following command. ``` apt-get install -y ca-certificates curl gnupg ``` Next, download the Node.js GPG key. ``` mkdir -p /etc/apt/keyrings curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg ``` Next, add the NodeSource repo to the APT source list. ``` echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_18.x nodistro main" | tee /etc/apt/sources.list.d/nodesource.list ``` Then, update the repository index and install the Ndoe.js with the following command. ``` apt update apt-get install -y nodejs ``` Next, verify the Node.js version using the following command. ``` node -v ``` Output. ``` v18.19.0 ``` ## Step 2 – Install Uptime-Kuma You can download the latest version of Uptime-Kuma from the GitHub repository using the following command: ``` git clone https://github.com/louislam/uptime-kuma.git ``` Once the download is completed, change the directory to uptime-kuma and set up it with the following command: ``` cd uptime-kuma/ npm run setup ``` ## Step 3 – Run Uptime-Kuma with pm2 pm2 is a process manager for Node.js. It allows you to run Node.js applications and keep them alive. You can install pm2 using the NPM as shown below: ``` npm install pm2@latest -g ``` Once the pm2 is installed, change the directory to uptime-kuma and run it using the following command: ``` pm2 start npm --name uptime-kuma -- run start-server -- --port=3001 --hostname=127.0.0.1 ``` You will get the following output: ``` [PM2] Spawning PM2 daemon with pm2_home=/root/.pm2 [PM2] PM2 Successfully daemonized [PM2] Starting /usr/bin/npm in fork_mode (1 instance) [PM2] Done. ┌─────┬────────────────┬─────────────┬─────────┬─────────┬──────────┬────────┬──────┬───────────┬──────────┬──────────┬──────────┬──────────┐ │ id │ name │ namespace │ version │ mode │ pid │ uptime │ ↺ │ status │ cpu │ mem │ user │ watching │ ├─────┼────────────────┼─────────────┼─────────┼─────────┼──────────┼────────┼──────┼───────────┼──────────┼──────────┼──────────┼──────────┤ │ 0 │ uptime-kuma │ default │ N/A │ fork │ 14381 │ 0s │ 0 │ online │ 0% │ 20.2mb │ root │ disabled │ └─────┴────────────────┴─────────────┴─────────┴─────────┴──────────┴────────┴──────┴───────────┴──────────┴──────────┴──────────┴──────────┘ ``` You can check the application logs using the following command: ``` pm2 logs ``` You will get the following output: ``` 0|uptime-k | Database Patched Successfully 0|uptime-k | JWT secret is not found, generate one. 0|uptime-k | Stored JWT secret into database 0|uptime-k | No user, need setup 0|uptime-k | Adding route 0|uptime-k | Adding socket handler 0|uptime-k | Init the server 0|uptime-k | Listening on 3001 ``` Next, enable the Node.js application to start after the system reboot: ``` pm2 startup ``` Output: ``` /etc/systemd/system/pm2-root.service Command list [ 'systemctl enable pm2-root' ] [PM2] Writing init configuration in /etc/systemd/system/pm2-root.service [PM2] Making script booting at startup... [PM2] [-] Executing: systemctl enable pm2-root... Created symlink /etc/systemd/system/multi-user.target.wants/pm2-root.service → /etc/systemd/system/pm2-root.service. [PM2] [v] Command successfully executed. +---------------------------------------+ [PM2] Freeze a process list on reboot via: $ pm2 save [PM2] Remove init script via: $ pm2 unstartup systemd ``` Next, save your application state using the following command: ``` pm2 save ``` ## Step 4 – Configure Apache as a Reverse Proxy for Uptime-Kuma Next, you will need to install and configure the Apache as a reverse proxy for Uptime-Kuma. First, install the Apache package with the following command: ``` apt-get install apache2 -y ``` Once the Apache web server is installed, enable the required modules with the following command: ``` a2enmod ssl proxy proxy_ajp proxy_wstunnel proxy_http rewrite deflate headers proxy_balancer proxy_connect proxy_html ``` Next, create a virtual host configuration file for Uptime-Kuma: ``` nano /etc/apache2/sites-available/uptime-kuma.conf ``` Add the following lines: ``` ServerName kuma.example.com ProxyPass / http://localhost:3001/ RewriteEngine on RewriteCond %{HTTP:Upgrade} websocket [NC] RewriteCond %{HTTP:Connection} upgrade [NC] RewriteRule ^/?(.*) "ws://localhost:3001/$1" [P,L] ``` Save and close the file, then activate the Apache virtual host configuration file with the following command: ``` a2ensite uptime-kuma ``` Finally, restart the Apache service to apply the changes: ``` systemctl restart apache2 ``` ## Step 5 – Access Uptime-Kuma Web Interface Now, open your web browser and access the Uptime-Kuma web interface using the URL **http://kuma.example.com**. You should see the following screen: ![Kuma setting up admin password](https://www.atlantic.net/wp-content/uploads/2021/11/p1-8.png) Here, create your administrative user, set your password, and click on the Create button. You will be redirected to the Kuma dashboard screen: ![Kuma dashboard](https://www.atlantic.net/wp-content/uploads/2021/11/p2-7-1024x489.png) Now, click on the Add New Monitor to add a remote host that you want to monitor. You should see the following screen: ![Kuma add monitoring host page1](https://www.atlantic.net/wp-content/uploads/2021/11/p3-5-1024x496.png) ![Kuma add monitoring host page2](https://www.atlantic.net/wp-content/uploads/2021/11/p4-4-1024x544.png) Provide all necessary information and click on the Save button. You should see the Uptime of your remote host on the following screen: ![Kuma monitoring host dashboard](https://www.atlantic.net/wp-content/uploads/2021/11/p5-2-1024x532.png) ## Conclusion Congratulations! You have successfully installed Uptime-Kuma uptime monitoring tool on Ubuntu 20.04. You can now add more remote hosts and monitor them from a single location. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Radicale Calendar (CalDAV and CardDAV) on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-radicale-calendar-caldav-and-carddav-on-ubuntu-20-04/ | Published: 2021-12-11 | Updated: 2024-06-02 | Author: Hitesh Jethva Radicale is a free, open-source, simple, powerful CalDAV and CardDAV server. It’s written in Python and is a complete solution to store calendars and contacts on the web. Radicale can be installed on operating systems like Linux, BSD, macOS, and Windows. It works out-of-the-box without any complicated configuration. Radicale allows you to share calendars and contact lists through CalDAV, CardDAV, and HTTP. In this post, we will show you how to install Radicale Calendar Server on Ubuntu 20.04. ## Step 1 – Install Required Dependencies First, you will need to install some Python dependencies on your server. You can install them by running the following command: ``` apt-get install python3-pip python3-passlib -y pip3 install bcrypt -y ``` Once all the dependencies are installed, you can proceed to install the Radicale server. ## Step 2 – Install and Configure Radicale Server The Radicale package comes in the Ubuntu 20.04 main repository. You can install it by just running the following command: ``` apt-get install radicale -y ``` Once the installation is completed, edit the Radicale main configuration file: ``` nano /etc/radicale/config ``` In the [server] section, uncomment the following lines: ``` [server] hosts = 127.0.0.1:5232 max_connections = 20 max_content_length = 100000000 timeout = 30 # SSL flag, enable HTTPS protocol #ssl = False # SSL certificate path #certificate = /etc/ssl/certs/ssl-cert-snakeoil.pem # SSL private key #key = /etc/ssl/private/ssl-cert-snakeoil.key ``` In the [auth] and [storage] sections, uncomment and change the following lines: ``` [auth] type = htpasswd htpasswd_filename = /etc/radicale/passwd htpasswd_encryption = bcrypt [storage] type = multifilesystem filesystem_folder = /var/lib/radicale/collections filesystem_locking = True ``` Save and close the file when you are finished. Next, install the Apache Utils package using the following command: ``` apt-get install apache2-utils -y ``` Next, create an admin user to secure the Radicale server. ``` htpasswd -B -c /etc/radicale/passwd admin ``` Set your password as shown below: ``` New password: Re-type new password: Adding password for user admin ``` Next, start and enable the Radicale service using the following command: ``` systemctl start radicale systemctl enable radicale ``` You can check the status of Radicale using the following command: ``` systemctl status radicale ``` You will get the following output: ``` ● radicale.service - LSB: Radicale CalDAV and CardDAV server Loaded: loaded (/etc/init.d/radicale; generated) Active: active (exited) since Fri 2021-11-26 03:48:39 UTC; 4s ago Docs: man:systemd-sysv-generator(8) Process: 9833 ExecStart=/etc/init.d/radicale start (code=exited, status=0/SUCCESS) Nov 26 03:48:38 ubuntu2004 systemd[1]: Starting LSB: Radicale CalDAV and CardDAV server... Nov 26 03:48:38 ubuntu2004 radicale[9833]: * Starting Radicale CalDAV server radicale Nov 26 03:48:39 ubuntu2004 radicale[9833]: ...fail! Nov 26 03:48:39 ubuntu2004 systemd[1]: Started LSB: Radicale CalDAV and CardDAV server. ``` ## Step 3 – Configure Apache for Radicale Next, you will need to install and configure Apache as a reverse proxy for the Radicale server. First, install the Apache package using the following command: ``` apt-get install apache2 -y ``` Next, enable the required modules using the following command: ``` a2enmod proxy proxy_ajp proxy_http rewrite deflate headers proxy_balancer proxy_connect proxy_html ssl ``` Next, create an Apache virtual host configuration file: ``` nano /etc/apache2/sites-available/radicale.conf ``` Add the following lines: ``` ServerName radicale.example.com ServerAdmin webmaster@example.com ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined ProxyRequests Off Order deny,allow Allow from all RewriteEngine On RewriteRule ^/radicale$ /radicale/ [R,L] AuthType Basic AuthName "Radicale - Password Required" AuthUserFile "/etc/radicale/passwd" Require valid-user ProxyPass http://localhost:5232/ retry=0 ProxyPassReverse http://localhost:5232/ RequestHeader set X-Script-Name /radicale RequestHeader set X-Remote-User expr=%{REMOTE_USER} Order allow,deny Allow from all ``` Save and close the file, then activate the Radicale virtual host with the following command: ``` a2ensite radicale.conf ``` Finally, restart Apache to apply the changes: ``` systemctl restart apache2 ``` ## Step 4 – Access Radicale Web Interface Now, open your web browser and access the Radicale web interface using the URL **http://radicale.example.com/radicale**. You should see the following screen: ![Radicale first login page](https://www.atlantic.net/wp-content/uploads/2021/11/p1-7-1024x315.png) Provide your admin username and password and click on the **Sign In** button. You should see the Radicale login page: ![Radicale second login page](https://www.atlantic.net/wp-content/uploads/2021/11/p2-6-1024x566.png) Provide the same admin username and password again and click on the **Next** button. You should see the Radicale dashboard on the following screen: ![Radicale dashboard](https://www.atlantic.net/wp-content/uploads/2021/11/p3-4-1024x502.png) ## Conclusion Congratulations! You have successfully installed the Radicale Calendar server with Apache as a reverse proxy on Ubuntu 20.04. You can now add contacts and share them with other users. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Prometheus System Monitoring Tool on Ubuntu 20.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-prometheus-system-monitoring-tool-on-ubuntu-20-04/ | Published: 2021-12-13 | Updated: 2024-06-05 | Author: Hitesh Jethva Prometheus is an open-source monitoring and alerting tool that records real-time metrics in a time-series database. It is written in Go and uses a powerful query language (PromQL) to collect the matrics. Prometheus has its own storage system to store and manage collected real-time metrics. It allows you to keep track of CPU usage, memory utilization, network IO wait time, and more. Prometheus was originally developed by SoundCloud and adopted by various companies later. In this post, we will show you how to install the Prometheus system monitoring tool on Ubuntu 20.04. ## Step 1 – Create Prometheus System Users and Directory It is recommended to create a dedicated user to run Prometheus. You can create users for both Prometheus and Node exporter using the command below: ``` useradd --no-create-home --shell /bin/false prome useradd --no-create-home --shell /bin/false node_exporter ``` Next, create a directory to store the Prometheus configuration file: ``` mkdir /etc/prometheus mkdir /var/lib/prometheus ``` Next, change the ownership of the created directories using the following command: ``` chown -R prome:prome /var/lib/prometheus/ chown -R prome:prome /etc/prometheus ``` ## Step 2 – Install Prometheus and Configure First, download the latest version of Prometheus from the GitHub repository. ``` wget https://github.com/prometheus/prometheus/releases/download/v2.31.1/prometheus-2.31.1.linux-amd64.tar.gz ``` Once the download is completed, extract the downloaded file using the command below: ``` tar -xvzf prometheus-2.31.1.linux-amd64.tar.gz ``` Next, copy the Prometheus binary file, configuration file, and other necessary directories: ``` cp prometheus-2.31.1.linux-amd64/prometheus /usr/local/bin/ cp prometheus-2.31.1.linux-amd64/promtool /usr/local/bin/ cp -r prometheus-2.31.1.linux-amd64/consoles /etc/prometheus cp -r prometheus-2.31.1.linux-amd64/console_libraries /etc/prometheus cp prometheus-2.31.1.linux-amd64/prometheus.yml /etc/prometheus/ ``` Next, change the ownership of all directories and files: ``` chown prome:prome /usr/local/bin/prometheus chown prome:prome /usr/local/bin/promtool chown -R prome:prome /etc/prometheus/consoles chown -R prome:prome /etc/prometheus/console_libraries ``` You can now verify the Prometheus installation using the following command: ``` prometheus --version ``` You should get the Prometheus version in the following output: ``` prometheus, version 2.31.1 (branch: HEAD, revision: 411021ada9ab41095923b8d2df9365b632fd40c3) build user: root@9419c9c2d4e0 build date: 20211105-20:35:02 go version: go1.17.3 platform: linux/amd64 ``` ## Step 3 – Create a Prometheus Systemd Service File Next, create a Prometheus systemd service file to manage Prometheus. ``` nano /etc/systemd/system/prometheus.service ``` Add the following lines: ``` [Unit] Description=Prometheus Wants=network-online.target After=network-online.target [Service] Type=simple User=prome Group=prome ExecReload=/bin/kill -HUP \$MAINPID ExecStart=/usr/local/bin/prometheus \ --config.file=/etc/prometheus/prometheus.yml \ --storage.tsdb.path=/var/lib/prometheus \ --web.console.templates=/etc/prometheus/consoles \ --web.console.libraries=/etc/prometheus/console_libraries \ --web.listen-address=0.0.0.0:9090 \ --web.external-url= SyslogIdentifier=prometheus Restart=always [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start and enable the Prometheus service using the following command: ``` systemctl start prometheus systemctl enable prometheus ``` You can check the status of the Prometheus service using the following command: ``` systemctl status prometheus ``` You will get the following output: ``` ● prometheus.service - Prometheus Loaded: loaded (/etc/systemd/system/prometheus.service; disabled; vendor preset: enabled) Active: active (running) since Fri 2021-11-26 04:39:35 UTC; 3s ago Docs: https://prometheus.io/docs/introduction/overview/ Main PID: 14903 (prometheus) Tasks: 6 (limit: 2353) Memory: 17.3M CGroup: /system.slice/prometheus.service └─14903 /usr/local/bin/prometheus --config.file=/etc/prometheus/prometheus.yml --storage.tsdb.path=/var/lib/prometheus --web.con> Nov 26 04:39:35 ubuntu2004 prometheus[14903]: ts=2021-11-26T04:39:35.124Z caller=head.go:479 level=info component=tsdb msg="Replaying on-disk> Nov 26 04:39:35 ubuntu2004 prometheus[14903]: ts=2021-11-26T04:39:35.124Z caller=head.go:513 level=info component=tsdb msg="On-disk memory ma> Nov 26 04:39:35 ubuntu2004 prometheus[14903]: ts=2021-11-26T04:39:35.124Z caller=head.go:519 level=info component=tsdb msg="Replaying WAL, th> Nov 26 04:39:35 ubuntu2004 prometheus[14903]: ts=2021-11-26T04:39:35.124Z caller=head.go:590 level=info component=tsdb msg="WAL segment loade> Nov 26 04:39:35 ubuntu2004 prometheus[14903]: ts=2021-11-26T04:39:35.125Z caller=head.go:596 level=info component=tsdb msg="WAL replay comple> Nov 26 04:39:35 ubuntu2004 prometheus[14903]: ts=2021-11-26T04:39:35.127Z caller=main.go:866 level=info fs_type=EXT4_SUPER_MAGIC Nov 26 04:39:35 ubuntu2004 prometheus[14903]: ts=2021-11-26T04:39:35.127Z caller=main.go:869 level=info msg="TSDB started" Nov 26 04:39:35 ubuntu2004 prometheus[14903]: ts=2021-11-26T04:39:35.127Z caller=main.go:996 level=info msg="Loading configuration file" file> Nov 26 04:39:35 ubuntu2004 prometheus[14903]: ts=2021-11-26T04:39:35.128Z caller=main.go:1033 level=info msg="Completed loading of configurat> Nov 26 04:39:35 ubuntu2004 prometheus[14903]: ts=2021-11-26T04:39:35.128Z caller=main.go:811 level=info msg="Server is ready to receive web r> ``` At this point, Prometheus is started and listens on port 9090. You can check it using the following command: ``` ss -antpl | grep 9090 ``` You will get the following output: ``` LISTEN 0 4096 *:9090 *:* users:(("prometheus",pid=14903,fd=7)) ``` ## Step 4 – Access Prometheus Web Interface Now, open your web browser and access the Prometheus web interface using the URL **http://your-server-ip:9090**. You should see the Prometheus dashboard on the following screen: ![Prometheus dashboard](https://www.atlantic.net/wp-content/uploads/2021/11/p1-9-1024x452.png) ## Conclusion Congratulations! You have successfully installed the Prometheus system monitoring tool on Ubuntu 20.04. You can now add your application or services and start monitoring them from the Prometheus dashboard. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Secure MongoDB on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-secure-mongodb-on-rocky-linux-10/ | Published: 2021-12-15 | Updated: 2025-10-19 | Author: Hitesh Jethva MongoDB is a high-performance, document-oriented NoSQL database used to handle high traffic and large volumes of data. It is written in the C ++ programming language and is available for the Windows, Mac OS X, and Linux operating systems. Instead of using NoSQL, MongoDB stores the data in JSON format. This means you can store your records without worrying about the data structure such as the number of fields or types of fields to store values. It is a highly scalable, flexible, and distributed NoSQL database. In this post, we will show you how to install MongoDB on Rocky Linux 10. ## Prerequisites - A server running Rocky Linux 10 on the Atlantic.Net Cloud Platform - A root password configured on your server ## Step 1 – Create Atlantic.Net Cloud Server First, log in to your [Atlantic.Net Cloud Server](https://cloud.atlantic.net/?page=userlogin). Create a new [server](https://www.atlantic.net/vps-hosting/how-to-create-new-atlantic-net-cloud-server/), choosing Rocky Linux 10 as the operating system with at least 2GB RAM. Connect to your Cloud Server via SSH and log in using the credentials highlighted at the top of the page. Once you are logged in to your server, run the following command to update your base system with the latest available packages. ``` dnf update -y ``` ## Step 2 – Install MongoDB By default, the MongoDB package is not included in the Rocky Linux 10 default repo, so you will need to create a MongoDB repo in your system. You can create it using the following command: ``` nano /etc/yum.repos.d/mongodb.repo ``` Add the following lines: ``` [mongodb-org-7.0] name=MongoDB Repository baseurl=https://repo.mongodb.org/yum/redhat/9/mongodb-org/7.0/x86_64/ enabled=1 gpgcheck=0 repo_gpgcheck=0 ``` Save and close the file, then install the MongoDB package using the following command: ``` dnf install mongodb-org ``` After the installation, start and enable the MongoDB service with the following command: ``` systemctl start mongod systemctl enable mongod ``` You can check the status of MongoDB using the following command: ``` systemctl status mongod ``` Sample output: ``` ● mongod.service - MongoDB Database Server Loaded: loaded (/usr/lib/systemd/system/mongod.service; enabled; preset: disabled) Active: active (running) since Sun 2025-10-19 23:39:25 EDT; 1min 29s ago Invocation: 691134383ce344259fdf55e2885fd2f0 Docs: https://docs.mongodb.org/manual Main PID: 44002 (mongod) Memory: 174.8M (peak: 263.2M) CPU: 1.493s CGroup: /system.slice/mongod.service └─44002 /usr/bin/mongod -f /etc/mongod.conf ``` Now, verify the MongoDB version using the following command: ``` mongod --version ``` Sample output: ``` db version v7.0.25 Build Info: { "version": "7.0.25", "gitVersion": "96dce3da49b8d2e9e0d328048cb56930eb1bdb2b", "openSSLVersion": "OpenSSL 3.2.2 4 Jun 2024", "modules": [], "allocator": "tcmalloc", "environment": { "distmod": "rhel90", "distarch": "x86_64", "target_arch": "x86_64" } } ``` ## Step 3 – How to Use MongoDB You can connect to the MongoDB shell using the following command: ``` mongosh ``` After connected, run the following command to list all databases: ``` > db ``` Sample output: ``` test ``` Next, create a new database named admin using the following command: ``` > use admin ``` To create a collection and insert some data, run the following command: ``` > db.linux.insertOne( { "RockyLinux" : "10", "centos" : "9", "debian" : "12" } ) ``` To verify the collection, run: ``` > show collections ``` Sample output: ``` linux ``` To display your data, run: ``` > db.linux.find() ``` Sample output: ``` { "_id" : ObjectId("6165aa323a2df0ac96aa216a"), "RockyLinux" : "10", "centos" : "9", "debian" : "12" } ``` ## Step 4 – Enable MongoDB Authentication By default, MongoDB is connected without login, so it is a good idea to enable authentication in MongoDB. First, log in to MongoDB with the following command: ``` mongosh ``` Next, create a MongoDB admin user and set a password: ``` > use admin > db.createUser( { user: "mongoadmin", pwd: "password", roles: [ { role: "userAdminAnyDatabase", db: "admin" } ] } ) ``` Sample output: ``` Successfully added user: { "user" : "mongoadmin ", "roles" : [ { "role" : "readWrite", "db" : "admin" } ] } ``` To verify your users, run: ``` > db.getUsers() ``` Sample output: ``` [ { "_id" : "admin.mongoadmin ", "userId" : UUID("ba2efd4e-84eb-4000-9d27-c0c337b4d7d8"), "user" : "mongoadmin ", "db" : "admin", "roles" : [ { "role" : "readWrite", "db" : "admin" } ], "mechanisms" : [ "SCRAM-SHA-1", "SCRAM-SHA-256" ] } ] ``` Next, edit the MongoDB configuration file and enable authentication: ``` nano /etc/mongod.conf ``` Add the following line: ``` security: authorization: enabled ``` Save and close the file, then restart the MongoDB service to apply the changes: ``` systemctl restart mongod ``` You can now connect to the MongoDB by specifying a user and password as shown below: ``` mongosh -u mongoadmin -p ``` ## Step 5 – Uninstall MongoDB If you want to remove the MongoDB from your system, first stop the MongoDB service: ``` systemctl stop mongod ``` Next, remove the MongoDB package by running the following command: ``` dnf remove mongodb-org ``` Next, remove the MongoDB logs and data directories by running the following command: ``` rm -rf /var/lib/mongodb ``` ## Conclusion In the above guide, we explained how to install MongoDB on RockyLinux 10. We also explained how to use MongoDB and enable authentication in MongoDB. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Docker and Docker Compose on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-docker-and-docker-compose-on-rocky-linux-10/ | Published: 2021-12-16 | Updated: 2025-10-19 | Author: Hitesh Jethva Docker is a free and open-source tool that allows you to build and run containers on your Linux system. It allows you to create lightweight and portable application images that run on any platform. Docker Compose is a free and open-source tool that allows you to define, visualize, and run multiple applications in a containerized environment. It uses a YAML file to define different applications and services. After defining the services in the YAML file, you can start all of them using a single command. In this post, we will show you how to install Docker and Docker Compose in Rocky Linux 10. ## Step 1 – Install Docker CE By default, the Docker package is not included in the RockyLinux default repository, so you will need to create a Docker CE repo. You can create it using the following commands: ``` dnf update -y dnf config-manager --add-repo https://download.docker.com/linux/centos/docker-ce.repo ``` Next, install Docker CE by running the following command: ``` dnf install docker-ce -y ``` Once Docker is installed, start the Docker service and enable it to start at system reboot. ``` systemctl start docker systemctl enable docker ``` You can verify the status of the Docker service using the following command: ``` systemctl status docker ``` Sample output: ``` ● docker.service - Docker Application Container Engine Loaded: loaded (/usr/lib/systemd/system/docker.service; disabled; preset: disabled) Active: active (running) since Sun 2025-10-19 23:18:53 EDT; 14s ago Invocation: a8e3c991e424460bb982889cd8905567 TriggeredBy: ● docker.socket Docs: https://docs.docker.com Main PID: 42672 (dockerd) Tasks: 9 Memory: 22.4M (peak: 26.3M) CPU: 307ms CGroup: /system.slice/docker.service └─42672 /usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock ``` To verify the Docker version with additional information, run the following command: ``` docker info ``` You will get the following output: ``` Client: Docker Engine - Community Version: 28.5.1 Context: default Debug Mode: false Plugins: buildx: Docker Buildx (Docker Inc.) Version: v0.29.1 Path: /usr/libexec/docker/cli-plugins/docker-buildx compose: Docker Compose (Docker Inc.) Version: v2.40.1 Path: /usr/libexec/docker/cli-plugins/docker-compose Server: Containers: 0 Running: 0 Paused: 0 Stopped: 0 Images: 0 Server Version: 28.5.1 Storage Driver: overlay2 Backing Filesystem: extfs ``` ## Step 2 – Verify Docker Installation After installing Docker, you will need to test whether it’s working. You can use Docker’s hello-world container to test Docker. ``` docker run hello-world ``` This will download the hello-world docker image to your system: ``` Unable to find image 'hello-world:latest' locally latest: Pulling from library/hello-world 2db29710123e: Pull complete Digest: sha256:9ade9cc2e26189a19c2e8854b9c8f1e14829b51c55a630ee675a5a9540ef6ccf Status: Downloaded newer image for hello-world:latest Hello from Docker! This message shows that your installation appears to be working correctly. To generate this message, Docker took the following steps: 1. The Docker client contacted the Docker daemon. 2. The Docker daemon pulled the "hello-world" image from the Docker Hub. (amd64) 3. The Docker daemon created a new container from that image which runs the executable that produces the output you are currently reading. 4. The Docker daemon streamed that output to the Docker client, which sent it to your terminal. To try something more ambitious, you can run an Ubuntu container with: $ docker run -it ubuntu bash Share images, automate workflows, and more with a free Docker ID: https://hub.docker.com/ For more examples and ideas, visit: https://docs.docker.com/get-started/ ``` You can verify the downloaded image using the following command: ``` docker images ``` You will get the following output: ``` REPOSITORY TAG IMAGE ID CREATED SIZE hello-world latest feb5d9fea6a5 2 weeks ago 13.3kB ``` ## Step 3 – Install Docker Compose Docker Compose is already installed with the Docker CE installation. You can verify the Docker Compose version using the following command: ``` docker compose version ``` You will get the following output: ``` Docker Compose version v2.40.1 ``` ## Step 4 – Remove Docker and Docker Compose If you want to remove the Docker package from your system, first stop the Docker service using the following command: ``` systemctl stop docker ``` Next, remove Docker and Docker Compose using the following command: ``` dnf remove docker-ce -y ``` ## Conclusion In the above guide, we explained how to install Docker and Docker Compose on RockyLinux 10. You can now start creating a YAML for your application and deploy it in the containerized environment. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Apache Spark on RockyLinux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-spark-on-rockylinux-10/ | Published: 2021-12-17 | Updated: 2026-02-28 | Author: Hitesh Jethva Apache Spark is an open-source framework used for analyzing big data in cluster computing environments. Generally, it is used in Hadoop to improve the data processing speeds. It supports a wide array of programming languages including Java, Scala, Python, and R. Apache Spark can easily process and distribute work on large datasets across multiple computers. It is used by data scientists and engineers to perform actions on large amounts of data. In this post, we will show you how to install Apache Spark on Rocky Linux 10. ## Step 1 – Install Java Apache Spark is a Java-based application, so you will need to install Jave to your server. You can install it by running the following commands: ``` dnf update -y ``` ``` dnf install java-21-openjdk-devel -y ``` Once Java is installed, verify the Java version using the following command: ``` java --version ``` You will get the following output: ``` openjdk 21.0.8 2025-07-15 LTS OpenJDK Runtime Environment (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS, mixed mode, sharing) ``` ## Step 2 – Install Spark First, download the latest version of Apache Spark for Apache’s website using the following command: ``` wget https://archive.apache.org/dist/spark/spark-3.3.2/spark-3.3.2-bin-hadoop3.tgz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar -xvf spark-3.3.2-bin-hadoop3.tgz ``` Next, move the extracted directory to the /opt with the following command: ``` mv spark-3.3.2-bin-hadoop3 /opt/spark ``` Next, create a dedicated user for Apache Spark and set proper ownership to the /opt directory: ``` useradd spark chown -R spark:spark /opt/spark ``` ## Step 3 – Create a Systemd Service File for Apache Spack Next, you will need to create a systemd service file for Apache Spark Master and Slave. First, create a systemd service file for Master using the following command: ``` nano /etc/systemd/system/spark-master.service ``` Add the following lines: ``` [Unit] Description=Apache Spark Master After=network.target [Service] Type=forking User=spark Group=spark ExecStart=/opt/spark/sbin/start-master.sh ExecStop=/opt/spark/sbin/stop-master.sh [Install] WantedBy=multi-user.target ``` Save and close the file then create a systemd service file for Slave: ``` nano /etc/systemd/system/spark-slave.service ``` Add the following lines: ``` [Unit] Description=Apache Spark Slave After=network.target [Service] Type=forking User=spark Group=spark ExecStart=/opt/spark/sbin/start-slave.sh spark://your-server-ip:7077 ExecStop=/opt/spark/sbin/stop-slave.sh [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start the Spark Master service and enable it to start at system reboot: ``` systemctl start spark-master systemctl enable spark-master ``` To verify the status of the Master service, run the following command: ``` systemctl status spark-master ``` You will get the following output: ``` ● spark-master.service - Apache Spark Master Loaded: loaded (/etc/systemd/system/spark-master.service; disabled; preset: disabled) Active: active (running) since Sun 2025-10-19 04:54:54 EDT; 4s ago Invocation: 7815bfe7e49849ca9a1c90a1d32851fd Process: 27424 ExecStart=/opt/spark/sbin/start-master.sh (code=exited, status=0/SUCCESS) Main PID: 27436 (java) Tasks: 33 (limit: 24809) Memory: 174.6M (peak: 174.9M) CPU: 4.757s CGroup: /system.slice/spark-master.service └─27436 /usr/lib/jvm/java-21-openjdk/bin/java -cp "/opt/spark/conf/:/opt/spark/jars/*" -Xmx1g org.apache.spark.deploy.master.Master --host roc. ``` ## Step 4 – Access Apache Spark At this point, Apache Spark is started and listening on port 8080. You can access it using the URL **http://your-server-ip:8080**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/12/s1-1.png) Now, start the Spark Slave service and enable it to start at system reboot: ``` systemctl start spark-slave systemctl enable spark-slave ``` You can check the status of the Slave service using the following command: ``` systemctl status spark-slave ``` Sample output: ``` ● spark-slave.service - Apache Spark Slave Loaded: loaded (/etc/systemd/system/spark-slave.service; disabled; preset: disabled) Active: active (running) since Sun 2025-10-19 04:56:13 EDT; 4s ago Invocation: bf24f0229f4e4677a0f26e1398d641af Process: 27508 ExecStart=/opt/spark/sbin/start-slave.sh spark://104.245.34.210:7077 (code=exited, status=0/SUCCESS) Main PID: 27521 (java) Tasks: 36 (limit: 24809) Memory: 210.1M (peak: 210.4M) CPU: 4.942s CGroup: /system.slice/spark-slave.service └─27521 /usr/lib/jvm/java-21-openjdk/bin/java -cp "/opt/spark/conf/:/opt/spark/jars/*" -Xmx1g org.apache.spark.deploy.worker.Worker --webui-port 8081 spark://104.245.34.2> ``` Now, reload your Apache Spark dashboard. You should see your worker on the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/12/s2-1.png) Now, click on the **Worker**. You should see the detailed information for the Worker on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/12/s3-1.png) ## Conclusion Congratulations! You have successfully installed Apache Spark on RockyLinux 10. You can now use Apache Spark in Hadoop to improve the data processing speeds. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Gitea Code Hosting Service on RockyLinux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-gitea-code-hosting-service-on-rockylinux-10/ | Published: 2021-12-18 | Updated: 2025-10-19 | Author: Hitesh Jethva Gitea is a free and open-source Git repository hosting platform written in the Go language. It allows you to work with version control software with other features including issue tracking, pull requests, user management, notifications, and more. It is very similar to GitHub, Bitbucket, and Gitlab, and can run on Linux, macOS, Windows, and ARM. If you are looking for an open-source, lightweight, and self-hosted code hosting platform, then Gitea is the best choice for you. In this post, we will show you how to install Gitea on Rocky Linux 10. ## Step 1 – Install and Configure MariaDB Database Gitea uses a MariaDB, MySQL, or PostgreSQL as a database backend, so one of the database software solutions must be installed on your server. First, install all the required dependencies using the following command: ``` dnf install git unzip gnupg2 nano wget -y ``` Once all the dependencies are installed, run the following command to install MariaDB: ``` dnf install mariadb-server -y ``` Next, start and enable the MariaDB service using the following command: ``` systemctl start mariadb systemctl enable mariadb ``` Next, you will need to create a database and user for Gitea. First, log in to the MariaDB shell with the following command: ``` mysql ``` Once you are logged in, create a database and user with the following command: ``` CREATE DATABASE gitea CHARACTER SET 'utf8mb4' COLLATE 'utf8mb4_unicode_ci'; GRANT ALL ON gitea.* TO 'gitea'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` Next, edit the MariaDB configuration file: ``` nano /etc/my.cnf.d/mariadb-server.cnf ``` Add the following lines below the line [mysqld]: ``` innodb_file_format = Barracuda innodb_large_prefix = 1 innodb_default_row_format = dynamic ``` Save and close the file then restart the MariaDB service to apply the changes: ``` systemctl restart mariadb ``` ## Step 2 – Install and Configure Gitea First, create a dedicated user to run Gitea using the following command: ``` useradd --system --shell /bin/bash --comment 'Git Version Control' --create-home --home /home/git git ``` Next, download the latest version of the Gitea binary with the following command: ``` wget -O gitea https://dl.gitea.io/gitea/1.18.5/gitea-1.18.5-linux-amd64 ``` Next, move the downloaded binary to the system path and set proper permissions: ``` mv gitea /usr/bin/gitea chmod 755 /usr/bin/gitea ``` Next, verify the Gitea version using the following command: ``` gitea --version ``` You should get the following output: ``` Gitea version 1.18.5 built with GNU Make 4.1, go1.19.6 : bindata, sqlite, sqlite_unlock_notify ``` Next, you will need to create a directory structure for Gitea. You can create it with the following commands: ``` mkdir -p /var/lib/gitea/{custom,data,indexers,public,log} chown git: /var/lib/gitea/{data,indexers,log} chmod 750 /var/lib/gitea/{data,indexers,log} mkdir /etc/gitea chown root:git /etc/gitea chmod 770 /etc/gitea ``` ## Step 3 – Create a Systemd Service File for Gitea Next, you will need to create a systemd service file to manage the Gitea service: ``` nano /etc/systemd/system/gitea.service ``` Add the following lines: ``` [Unit] Description=Gitea After=syslog.target After=network.target After=mysql.service [Service] RestartSec=2s Type=simple User=git Group=git WorkingDirectory=/var/lib/gitea/ ExecStart=/usr/bin/gitea web -c /etc/gitea/app.ini Restart=always Environment=USER=git HOME=/home/git GITEA_WORK_DIR=/var/lib/gitea [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the Gitea service and enable it to start at system reboot: ``` systemctl start gitea systemctl enable gitea ``` You can now check the status of Gitea using the following command: ``` systemctl status gitea ``` You should see the following output: ``` ● gitea.service - Gitea Loaded: loaded (/etc/systemd/system/gitea.service; disabled; preset: disabled) Active: active (running) since Sun 2025-10-19 04:43:49 EDT; 6s ago Invocation: 737040845e884c489e74e7a169ff9d35 Main PID: 27262 (gitea) Tasks: 8 (limit: 24809) Memory: 110.4M (peak: 110.6M) CPU: 700ms CGroup: /system.slice/gitea.service └─27262 /usr/bin/gitea web -c /etc/gitea/app.ini ``` By default, Gitea listens on port 3000. You can verify it using the following command: ``` ss -antpl | grep 3000 ``` You should get the following output: ``` LISTEN 0 128 *:3000 *:* users:(("gitea",pid=8998,fd=6)) ``` ## Step 4 – Access Gitea Web Interface Now, open your web browser and type the URL **http://your-server-ip:3000** to access the Gitea web interface. You will get the following screen: ![Gitea Database Settings](https://www.atlantic.net/wp-content/uploads/2021/10/p1-1024x603.png) ![Gitea General Settings](https://www.atlantic.net/wp-content/uploads/2021/10/p2.png) ![Gitea Port Settings](https://www.atlantic.net/wp-content/uploads/2021/10/p3.png) ![Gitea Admin Settings](https://www.atlantic.net/wp-content/uploads/2021/10/p4.png) Provide your Gitea repository name, run as username, listen port, base URL, admin username, and password and click on the **Install Gitea** button. Once the installation has been completed, you will be redirected to the Gitea dashboard: ![Gitea Dashboard Settings](https://www.atlantic.net/wp-content/uploads/2021/10/p5-1024x456.png) ## Conclusion In this guide, you learned how to install the Gitea code hosting platform on RockyLinux 10. You can now start implementing Gitea in your development environment to manage and track your code. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Node.js and NPM on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-node-js-and-npm-on-rocky-linux-10/ | Published: 2021-12-19 | Updated: 2025-10-19 | Author: Hitesh Jethva Node.js is a free, and open-source JavaScript runtime built on Chrome’s V8 JavaScript engine used to build scalable network applications. Generally, it is used on the back-end, but you can also use it as a full-stack and front-end solution. It is cross-platform, lightweight, and supports a non-blocking I/O model and event-driven architecture. Node.js allows you to develop complex and very scalable web applications easily. In this post, we will show you how to install Node.js and NPM on RockyLinux 10. ## Step 1 – Install Nodejs Using NodeSource Repository By default, the latest version of Node.js is not available in the RockyLinux 10 default repo, so you can use the NodeSource repository to install the latest version of Node.js. First, install the curl command utility using the following command: ``` dnf install curl -y ``` Next, add the NodeSource repository with the following command: ``` curl --silent --location https://rpm.nodesource.com/setup_22.x | bash - ``` Next, install the latest Node.js version with the following command: ``` dnf install nodejs ``` After the installation, verify the Node.js version with the following command: ``` node -v ``` You should see the following output: ``` v22.20.0 ``` To verify the NPM version, run the following command: ``` npm -v ``` You should see the following output: ``` 11.6.2 ``` ## Step 2 – Install Nodejs Using NVM You can also install Node.js using the Node Version Manager (NVM). NVM provides an easy way to install and manage multiple Node.js versions in the same system. First, install NVM using the following command: ``` curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/master/install.sh | bash ``` This will install NVM on your system and add the NVM path to the .bashrc file. Next, activate the NVM system path using the following command: ``` source ~/.bashrc ``` To verify the NVM version, run: ``` nvm --version ``` You should see the following output: ``` 0.40.3 ``` To install the latest Node.js version, run: ``` nvm install node ``` You should see the following output: ``` Downloading and installing node v25.0.0... Downloading https://nodejs.org/dist/v25.0.0/node-v25.0.0-linux-x64.tar.xz... ################################################################################################################################################################################# 100.0% Computing checksum with sha256sum Checksums matched! Now using node v25.0.0 (npm v11.6.2) Creating default alias: default -> node (-> v25.0.0) ``` To install the latest stable Node.js version, run: ``` nvm install --lts ``` You should see the following output: ``` Installing latest LTS version. Downloading and installing node v22.20.0... Downloading https://nodejs.org/dist/v22.20.0/node-v22.20.0-linux-x64.tar.xz... ################################################################################################################################################################################# 100.0% Computing checksum with sha256sum Checksums matched! Now using node v22.20.0 (npm v10.9.3) ``` To list all Node.js versions installed in your system, run: ``` nvm ls ``` You should see the following output: ``` v22.20.0 -> v25.0.0 v21.6.0 system default -> 20.2.0 (-> v20.2.0) iojs -> N/A (default) unstable -> N/A (default) node -> stable (-> v21.6.0) (default) stable -> 21.6 (-> v21.6.0) (default) lts/* -> lts/iron (-> v20.11.0) lts/argon -> v4.9.1 (-> N/A) lts/boron -> v6.17.1 (-> N/A) lts/carbon -> v8.17.0 (-> N/A) lts/dubnium -> v10.24.1 (-> N/A) lts/erbium -> v12.22.12 (-> N/A) lts/fermium -> v14.21.3 (-> N/A) lts/gallium -> v16.20.2 (-> N/A) lts/hydrogen -> v18.19.0 (-> N/A) lts/iron -> v20.11.0 To set the default Node.js version, run: ``` ``` nvm use 25.0.0 ``` You should see the following output: ``` Now using node v25.0.0 (npm v11.6.2) ``` ## Conclusion In the above guide, we explained three different ways to install Node.js and NPM on Rocky Linux 10. You can now install your required Node.js version using any of the above methods. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Apache Kafka on Rocky Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-apache-kafka-on-rocky-linux-10/ | Published: 2021-12-21 | Updated: 2025-12-30 | Author: Hitesh Jethva Apache Kafka is an open-source stream processing and message broker software application that allows you to process data streams via a distributed streaming platform. It acts as a messaging system between the sender and the recipient. Apache Kafka is based on a distributed architecture, so it provides high fault tolerance and scalability capabilities. It was originally developed by LinkedIn, but now it is a project of Apache Software Foundation. Apache Kafka provides an interface to read and write data to Kafka clusters or to import and export data to and from third-party systems. In this post, we will explain how to install Apache Kafka on Rocky Linux 10. ## Step 1- Install Java Apache Kafka is a Java-based application, so Java must be installed on your server. If not installed, you can install it using the following command: ``` dnf update -y dnf install java-21-openjdk-devel -y ``` Once Java is installed, verify the Java installation using the following command: ``` java --version ``` You will get the Java version in the following output: ``` openjdk 21.0.8 2025-07-15 LTS OpenJDK Runtime Environment (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS, mixed mode, sharing) ``` ## Step 2 – Install Apache Kafka on Rocky Linux 10 First, go to the Apache official website and download the latest version of Apache Kafka using the wget command: ``` wget https://dlcdn.apache.org/kafka/4.1.0/kafka_2.13-4.1.0.tgz ``` Once the download is completed, extract the downloaded file using the following command: ``` tar -xvzf kafka_2.13-4.1.0.tgz ``` Once the downloaded file is extracted, move the extracted directory to /usr/local directory: ``` mv kafka_2.13-4.1.0 /usr/local/kafka ``` Once you are finished, you can proceed to the next step. ## Step 3 – Configure Kafka First, edit the Kafka server.properties file. ``` nano /usr/local/kafka/config/server.properties ``` Modify the following lines: ``` process.roles=broker,controller node.id=1 controller.listener.names=CONTROLLER listeners=PLAINTEXT://0.0.0.0:9092,CONTROLLER://0.0.0.0:9093 listener.security.protocol.map=CONTROLLER:PLAINTEXT,PLAINTEXT:PLAINTEXT inter.broker.listener.name=PLAINTEXT controller.quorum.voters=1@localhost:9093 log.dirs=/usr/local/kafka/data ``` Next, build the random uuid. ``` /usr/local/kafka/bin/kafka-storage.sh random-uuid ``` Output. ``` SSoviLO8RtmlnOyHEPOcMQ ``` Initialize the storage directory with that UUID. ``` /usr/local/kafka/bin/kafka-storage.sh format -t SSoviLO8RtmlnOyHEPOcMQ -c /usr/local/kafka/config/server.properties ``` ## Step 4 – Create Systemd Service File for Kafka For the production environment, it is recommended to create a systemd service file to run both Zookeeper and Kafka in the background. First, create a systemd service file for Kafka using the following command: ``` nano /etc/systemd/system/kafka.service ``` Add the following lines: ``` [Unit] Description=Apache Kafka Server Documentation=http://kafka.apache.org/documentation.html [Service] Type=simple Environment="JAVA_HOME=/usr/lib/jvm/jre-21-openjdk" ExecStart=/usr/bin/bash /usr/local/kafka/bin/kafka-server-start.sh /usr/local/kafka/config/server.properties ExecStop=/usr/bin/bash /usr/local/kafka/bin/kafka-server-stop.sh [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start Kafka service and enable it to start at system reboot: ``` systemctl start kafka systemctl enable kafka ``` You can also check Kafka using the following command: ``` systemctl status kafka ``` You will get the following output: ``` ● kafka.service - Apache Kafka Server Loaded: loaded (/etc/systemd/system/kafka.service; disabled; preset: disabled) Active: active (running) since Sun 2025-10-19 01:56:50 EDT; 3s ago Invocation: 0fcfe3b308ce4be3b9a8ae56328e5e9a Docs: http://kafka.apache.org/documentation.html Main PID: 15974 (java) Tasks: 48 (limit: 24809) Memory: 218.5M (peak: 218.9M) CPU: 4.866s CGroup: /system.slice/kafka.service └─15974 /usr/lib/jvm/jre-21-openjdk/bin/java -Xmx1G -Xms1G -server -XX:+UseG1GC -XX:MaxGCPauseMillis=20 -XX:InitiatingHeapOccupancyPercent=35 -XX:+ExplicitGCInvokesConcur> ``` ## Step 5 – Create a Topic on Kafka To test Apache Kafka, you will need to create at least one topic on the server. Change the directory to Apache Kafka and create a test topic named topic1 with the following command: ``` cd /usr/local/kafka/ bin/kafka-topics.sh --create --bootstrap-server localhost:9092 --replication-factor 1 --partitions 1 --topic topic1 ``` You can now verify your created topic using the following command: ``` bin/kafka-topics.sh --list --bootstrap-server localhost:9092 ``` You will get the following output: ``` topic1 ``` Kafka provides two APIs: Producer and Consumer. The Producer is responsible for creating events and the Consumer displays them on the screen: First, run the following command to create an event named event1 using the following command: ``` bin/kafka-console-producer.sh --broker-list localhost:9092 --topic event1 ``` Type some text that you want to stream and display on the Consumer. ``` >Hi, this is my first event ``` Sample output: ``` [2025-10-22 07:58:05,318] WARN [Producer clientId=console-producer] Error while fetching metadata with correlation id 3 : {event1=LEADER_NOT_AVAILABLE} (org.apache.kafka.clients.NetworkClient) ``` Open another terminal and run the following command to display the generated event data in real-time: ``` bin/kafka-console-consumer.sh --bootstrap-server localhost:9092 --topic event1 --from-beginning ``` You will get the following output: ``` Hi, this is my first event ``` ## Conclusion In the above guide, you learned how to install Apache Kafka on Rocky Linux 10. For more information, you can visit the Apache Kafka [documentation page](https://kafka.apache.org/). Get started with Apache Kafka on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Secure PostgreSQL Server on RockyLinux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-secure-postgresql-server-on-rockylinux-10/ | Published: 2021-12-23 | Updated: 2025-10-19 | Author: Hitesh Jethva PostgreSQL is a popular open-source relational database management system. Known for its reliability, it is gaining popularity due to its robustness, flexibility, and performance. PostgreSQL is used for managing databases and numerous web and analytical applications. At the time of writing this article, PostgreSQL 18 is the latest version. This version comes with significant improvements to the indexing and lookup system that benefit large databases. In this post, we will show you how to install and secure PostgreSQL on Rocky Linux 10. ## Step 1 – Add PostgreSQL 18 Repository By default, the latest version of PostgreSQL is not included in the Rocky Linux default repository. You can check the default available version in the AppStream repository using the following command: ``` dnf install https://download.postgresql.org/pub/repos/yum/reporpms/EL-8-x86_64/pgdg-redhat-repo-latest.noarch.rpm ``` Once the repo is created, you can proceed to the next step. ## Step 2 – Install PostgreSQL 18 on Rocky Linux 10 Now, update your repository using the following command: ``` dnf update -y ``` Next, install the latest version of PostgreSQL by running the following command: ``` dnf install postgresql18 postgresql18-server ``` Once PostgreSQL 18 is installed, you will get the following output: ``` Last metadata expiration check: 0:38:45 ago on Sun 19 Oct 2025 12:53:52 AM EDT. Dependencies resolved. ======================================================================================================================================================================================== Package Architecture Version Repository Size ======================================================================================================================================================================================== Installing: postgresql18 x86_64 18.0-1PGDG.rhel10 pgdg18 2.0 M postgresql18-server x86_64 18.0-1PGDG.rhel10 pgdg18 7.3 M Installing dependencies: postgresql18-libs x86_64 18.0-1PGDG.rhel10 pgdg18 296 k Transaction Summary ======================================================================================================================================================================================== Install 3 Packages Total download size: 7.4 M Installed size: 31 M Is this ok [y/N]: y ``` Next, initialize the PostgreSQL database with the following command: ``` /usr/pgsql-18/bin/postgresql-18-setup initdb ``` Sample output: ``` Initializing database ... OK ``` Next, start the PostgreSQL service and enable it to start at system reboot with the following command: ``` systemctl start postgresql-18 systemctl enable postgresql-18 ``` You can check the status of PostgreSQL with the following command: ``` systemctl status postgresql-18 ``` You should get the following output: ``` ● postgresql-18.service - PostgreSQL 18 database server Loaded: loaded (/usr/lib/systemd/system/postgresql-18.service; disabled; preset: disabled) Active: active (running) since Sun 2025-10-19 01:33:48 EDT; 1s ago Invocation: ef82fd9873da4303b7454ffcf40b2226 Docs: https://www.postgresql.org/docs/18/static/ Process: 12263 ExecStartPre=/usr/pgsql-18/bin/postgresql-18-check-db-dir ${PGDATA} (code=exited, status=0/SUCCESS) Main PID: 12270 (postgres) Tasks: 10 (limit: 24809) Memory: 21.9M (peak: 22.1M) CPU: 62ms CGroup: /system.slice/postgresql-18.service ├─12270 /usr/pgsql-18/bin/postgres -D /var/lib/pgsql/18/data/ ├─12271 "postgres: logger " ├─12272 "postgres: io worker 0" ├─12273 "postgres: io worker 2" ├─12274 "postgres: io worker 1" ├─12275 "postgres: checkpointer " ├─12276 "postgres: background writer " ├─12278 "postgres: walwriter " ├─12279 "postgres: autovacuum launcher " └─12280 "postgres: logical replication launcher " ``` By default, PostgreSQL listens on port 5432. You can check it with the following command: ``` ss -antpl | grep 5432 ``` You will get the following output: ``` LISTEN 0 128 127.0.0.1:5432 0.0.0.0:* users:(("postmaster",pid=36417,fd=7)) LISTEN 0 128 [::1]:5432 [::]:* users:(("postmaster",pid=36417,fd=6)) ``` ## Step 3 – Set a Password for Postgres User By default, the password of the Postgres user is not set, so it is recommended to set a password for security reasons. To set a password, log in to PostgreSQL with the following command: ``` su - postgres ``` Next, set a secure password with the following command: ``` psql -c "alter user postgres with password 'securepassword'" ``` Next, exit from the PostgreSQL shell using the following command: ``` exit ``` ## Step 4 – Change PostgreSQL Authentication Method By default, PostgreSQL is configured to use the peer method to connect to PostgreSQL locally. but this method is not recommended for the production environment. It is recommended to change the authentication method from **peer** to **scram-sha-256**. You can change it by editing the PostgreSQL main configuration file: ``` nano /var/lib/pgsql/18/data/pg_hba.conf ``` Find the following line: ``` local all all peer ``` And, replace it with the following line: ``` local all all scram-sha-256 ``` Save and close the file, then restart the PostgreSQL service to apply the changes. ``` systemctl restart postgresql-18 ``` ## Step 5 – Create a Database and User in PostgreSQL First, log in to the PostgreSQL shell with the following command: ``` sudo -u postgres psql ``` You will get the following output: ``` could not change directory to "/root": Permission denied psql (18.4) Type "help" for help. postgres=# ``` Next, create a new PostgreSQL user named user1 using the following command: ``` CREATE USER user1 WITH CREATEDB CREATEROLE PASSWORD 'passoword'; ``` To verify the PostgreSQL users, run: ``` \du ``` You will get the following output: ``` List of roles Role name | Attributes | Member of -----------+------------------------------------------------------------+----------- postgres | Superuser, Create role, Create DB, Replication, Bypass RLS | {} user1 | Create role, Create DB | {} ``` To create a new PostgreSQL database named user1db, run: ``` CREATE DATABASE user1db OWNER user1; ``` To verify the PostgreSQL databases, run: ``` \l ``` You will get the following output: ``` List of databases Name | Owner | Encoding | Collate | Ctype | Access privileges -----------+----------+----------+-------------+-------------+----------------------- postgres | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | template0 | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | =c/postgres + | | | | | postgres=CTc/postgres template1 | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | =c/postgres + | | | | | postgres=CTc/postgres user1db | user1 | UTF8 | en_US.UTF-8 | en_US.UTF-8 | ``` ## Conclusion Congratulations! You have successfully installed and secured PostgreSQL on Rocky Linux 10. For security reasons, it is always recommended to install the latest version of PostgreSQL in the production environment. Give it a try on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Use MariaDB on Debian 12 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-mariadb-on-debian-12/ | Published: 2021-12-24 | Updated: 2025-09-05 | Author: Hitesh Jethva MariaDB is an open-source and extremely popular relational database management systems developed by MySQL developers. MariaDB is an alternative to MySQL and allows you to perform any operation that MySQL performs. It is designed for high availability, scalability, and performance in data-intensive, business-critical applications. MariaDB can be installed on many operating systems including Linux, FreeBSD, Solaris, Mac OS X, Windows, and more. At the time of writing this tutorial, the latest available version of MariaDB is 12.1. It comes with the following new features: - Atomic DDL - SQL Syntax - Oracle Compatibility - InnoDB - Replication, Galera and Binlog In this post, we will explain how to install and use MariaDB 12.1 on Debian 12. ## Step 1- Add MariaDB Repository By default, the latest version of MariaDB is not included in the Debian 12 default repository, so you will need to add the MariaDB official repository to your system. First, install the required dependencies using the following commands: ``` apt-get update -y ``` ``` apt-get install curl software-properties-common dirmngr gnupg2 -y ``` Once all the dependencies are installed, download and add the GPG key with the following command: ``` curl -fsSL https://mariadb.org/mariadb_release_signing_key.asc | gpg --dearmor -o /usr/share/keyrings/mariadb-keyring.gpg echo "deb [signed-by=/usr/share/keyrings/mariadb-keyring.gpg] https://mirror.mariadb.org/repo/12.1.1/debian bookworm main" | tee /etc/apt/sources.list.d/mariadb.list ``` Once the repository is added, you can update the package cache with the following command: ``` apt-get update -y ``` ## Step 2 – Install MariaDB 12 on Debian 12 Now, run the following command to install MariaDB 12.1 on Debian 12. ``` apt-get install mariadb-server mariadb-client -y ``` Once the installation is completed, start and enable the MariaDB service using the following command: ``` systemctl start mariadb systemctl enable mariadb ``` You can now check the status of MariaDB with the following command: ``` systemctl status mariadb ``` You should see the following output: ``` ● mariadb.service - MariaDB 12.1.1 database server Loaded: loaded (/lib/systemd/system/mariadb.service; enabled; preset: enabled) Drop-In: /etc/systemd/system/mariadb.service.d └─migrated-from-my.cnf-settings.conf Active: active (running) since Fri 2025-09-05 09:50:13 UTC; 3s ago Docs: man:mariadbd(8) https://mariadb.com/kb/en/library/systemd/ Process: 3145 ExecStartPre=/usr/bin/install -m 755 -o mysql -g root -d /var/run/mysqld (code=exited, status=0/SUCCESS) Process: 3146 ExecStartPre=/bin/sh -c [ ! -e /usr/bin/galera_recovery ] && VAR= || VAR=`/usr/bin/galera_recovery`; [ $? -eq 0 ] && echo _WSREP_START_POSITION=$> Process: 3182 ExecStartPost=/bin/rm -f /run/mysqld/wsrep-start-position (code=exited, status=0/SUCCESS) Process: 3183 ExecStartPost=/etc/mysql/debian-start (code=exited, status=0/SUCCESS) Main PID: 3171 (mariadbd) Status: "Taking your SQL requests now..." Tasks: 12 (limit: 15209) Memory: 129.2M CPU: 4.693s CGroup: /system.slice/mariadb.service └─3171 /usr/sbin/mariadbd ``` ## Step 3 – Secure MariaDB Installation By default, the MariaDB installation is not secured and its root password is not set. You can do both by running the following script: ``` mysql_secure_installation ``` You will be asked several questions to secure the MariaDB installation and set the root password, as shown below: ``` Enter current password for root (enter for none): Switch to unix_socket authentication [Y/n] Y Change the root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` Once you are done, log in to the MariaDB shell with the following command: ``` mysql -u root -p ``` Once you are logged in, run the following command to check the MariaDB version: ``` SELECT VERSION(); ``` You will get the following output: ``` +----------------------+ | VERSION() | +----------------------+ | 12.1.1-MariaDB-deb12 | +----------------------+ 1 row in set (0.000 sec) ``` ## Step 4 – Create Database and User in MariaDB In this section, we will show you how to create a database and user in MariaDB. To create a database called newdb, run the following command: ``` CREATE DATABASE newdb; ``` Next, check the created database using the following command: ``` SHOW DATABASES; ``` You should see the following output: ``` +--------------------+ | Database | +--------------------+ | information_schema | | mysql | | newdb | | performance_schema | | sys | +--------------------+ ``` To create a user called newuser, run the following command: ``` CREATE USER 'newuser'@'localhost' IDENTIFIED BY 'password'; ``` To grant all the privileges to newdb database, run the following command: ``` GRANT ALL PRIVILEGES ON newdb.* TO 'newuser'@'localhost' IDENTIFIED BY 'password'; ``` Next, reload the privileges using the following command: ``` FLUSH privileges; ``` ## Step 6 – Create a Table in MariaDB In this section, we will show you how to create a table and insert data into the table in MariaDB. First, change the database to newdb using the following command: ``` USE newdb; ``` Next, create a table called students using the following command: ``` CREATE TABLE students (id INT, name VARCHAR(20), email VARCHAR(20)); ``` Next, verify the created tables using the following command: ``` SHOW TABLES; ``` You should see the following output: ``` +-----------------+ | Tables_in_newdb | +-----------------+ | students | +-----------------+ ``` To insert the data in the first, second, and third rows of the table, run the following command: ``` INSERT INTO students (id,name,email) VALUES(01,"hitesh","hitesh@gmail.com"); INSERT INTO students (id,name,email) VALUES(02,"raj","raj@gmail.com"); INSERT INTO students (id,name,email) VALUES(03,"jay","jay@gmail.com"); ``` To verify your inserted data, run the following command: ``` SELECT * FROM students; ``` You should see the following output: ``` +------+--------+------------------+ | id | name | email | +------+--------+------------------+ | 1 | hitesh | hitesh@gmail.com | | 2 | raj | raj@gmail.com | | 3 | jay | jay@gmail.com | +------+--------+------------------+ ``` ## Step 7 – How to Uninstall MariaDB If you want to remove MariaDB from your system, run the following command: ``` apt-get remove mariadb-server --purge ``` After removing the MariaDB package, run the following command to uninstall all unwanted dependencies: ``` apt-get autoremove apt-get clean ``` Next, remove the MariaDB database files using the following command: ``` rm -rf /var/lib/mysql/ ``` ## Conclusion In the above guide, we explained how to install MariaDB 10.6 on Debian 11. We also explained how to create a database, user, and table in MariaDB. Try using a MariaDB database on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install PHP Composer on Debian > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-php-composer-on-debian/ | Published: 2021-12-25 | Updated: 2025-09-05 | Author: Hitesh Jethva Some PHP-based applications require extra libraries or components that you need to manage. Manual management is a very time-consuming and tedious process, but Composer can help. Composer is a dependency manager for PHP that helps developers to manage dependencies used in a PHP project. It provides an easier way to specify the set of all required libraries and dependencies of your project and install them. It is used by Symfony and Laravel to bootstrap new projects. In this post, we will explain how to install PHP Composer on Debian 12. ## Step 1 – Install PHP Composer on Debian 12 Before installing Composer, PHP and some other extensions must be installed to your system. You can install all of them by running the following command: ``` apt-get install php php-common php-cli php-curl php-intl php-zip git curl unzip -y ``` Once all the packages are installed, run the following command to install Composer: ``` php -r "copy('https://getcomposer.org/installer', 'composer-setup.php');" php composer-setup.php --install-dir=/usr/local/bin --filename=composer ``` You will get the following output: ``` All settings correct for using Composer Downloading... Composer (version 2.8.11) successfully installed to: /usr/local/bin/composer Use it: php /usr/local/bin/composer ``` Next, set the executable permission to the Composer binary using the command below: ``` chmod +x /usr/local/bin/composer ``` Next, verify the Composer version using the following command: ``` composer --version ``` You will get the following output: ``` Composer version 2.8.11 2025-08-21 11:29:39 ``` ## Step 2 – How to Use PHP Composer In this section, we will show you how to use Composer. To list all options available with Composer, run the following command: ``` composer ``` You will get the following output: ``` Continue as root/super user [yes]? yes ______ / ____/___ ____ ___ ____ ____ ________ _____ / / / __ \/ __ `__ \/ __ \/ __ \/ ___/ _ \/ ___/ / /___/ /_/ / / / / / / /_/ / /_/ (__ ) __/ / \____/\____/_/ /_/ /_/ .___/\____/____/\___/_/ /_/ Composer version 2.8.11 2025-09-05 10:51:43 Usage: command [options] [arguments] Options: -h, --help Display this help message -q, --quiet Do not output any message -V, --version Display this application version --ansi Force ANSI output --no-ansi Disable ANSI output -n, --no-interaction Do not ask any interactive question --profile Display timing and memory usage information --no-plugins Whether to disable plugins. ``` Now, let’s create a project directory and install some packages. First, create a directory named app using the following command: ``` mkdir app ``` Next, navigate to the app directory and install the carbon package using the following command: ``` cd app composer require nesbot/carbon ``` After the installation, list all files and directories created by the package using the following command: ``` ls -l ``` You will get the following output: ``` -rw-r--r-- 1 root root 60 Sep 5 09:33 composer.json -rw-r--r-- 1 root root 25640 Sep 5 09:32 composer.lock drwxr-xr-x 8 root root 4096 Sep 5 09:33 vendor ``` Now, create a sample application using the following command: ``` nano sample.php ``` Add the following lines: ``` URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-gradle-on-debian/ | Published: 2021-12-26 | Updated: 2025-09-05 | Author: Hitesh Jethva Gradle is a free and open-source build automation tool used for developing different applications. It uses Groovy to define project configurations. Gradle is compatible with Java, Javascript, and C/C++. It helps you to manage required libraries, deployment, testing, and notifications of the application in different platforms. Gradle is very popular due to its simplicity, ease of use, and prebuilt functionality. In this post, we will show you how to install Gradle on Debian 12. ## Step 1 – Install Java JDK Gradle is a Java-based application, so Java JDK must be installed on your server. If not installed you can install it by running the following command: ``` apt-get update -y apt-get install default-jdk -y ``` Once Java JDK is installed, verify the Java installation using the command given below: ``` java --version ``` You will get the following output: ``` openjdk 17.0.16 2025-07-15 OpenJDK Runtime Environment (build 17.0.16+8-Debian-1deb12u1) OpenJDK 64-Bit Server VM (build 17.0.16+8-Debian-1deb12u1, mixed mode, sharing) ``` ## Step 2 – Install Gradle on Debian 12 First, install the required dependencies using the following command: ``` apt-get install curl unzip -y ``` Next, download the latest version of Gradle using the following command: ``` wget https://services.gradle.org/distributions/gradle-9.0.0-all.zip ``` Once the download is completed, unzip the downloaded file with the following command: ``` unzip gradle-9.0.0-all.zip ``` Next, move the extracted directory to /opt with the following command: ``` mv gradle-9.0.0 /opt/gradle ``` Now, run the following command to list all files and directories inside /opt/gradle directory: ``` ls /opt/gradle/ ``` You should see the following output: ``` bin init.d lib LICENSE NOTICE README ``` ## Step 3 – Set up Environment Variable Next, you will need to create an environment variable for Gradle. You can create it by running the following command: ``` echo "export PATH=/opt/gradle/bin:${PATH}" | tee /etc/profile.d/gradle.sh ``` Next, set executable permissions to the **gradle.sh** file: ``` chmod +x /etc/profile.d/gradle.sh ``` Next, activate the environment variable using the following command: ``` source /etc/profile.d/gradle.sh ``` ## Step 4 – Verify the Gradle Installation At this point, Gradle is installed in your system. You can now verify the Gradle installation using the following command: ``` gradle -v ``` You should see the following output: ``` Welcome to Gradle 9.0.0! Here are the highlights of this release: - Configuration Cache is the recommended execution mode - Gradle requires JVM 17 or higher to run - Build scripts use Kotlin 2.2 and Groovy 4.0 - Improved Kotlin DSL script compilation avoidance For more details see https://docs.gradle.org/9.0.0/release-notes.html ------------------------------------------------------------ Gradle 9.0.0 ------------------------------------------------------------ Build time: 2025-07-31 16:35:12 UTC Revision: 328772c6bae126949610a8beb59cb227ee580241 Kotlin: 2.2.0 Groovy: 4.0.27 Ant: Apache Ant(TM) version 1.10.15 compiled on August 25 2024 Launcher JVM: 17.0.16 (Debian 17.0.16+8-Debian-1deb12u1) Daemon JVM: /usr/lib/jvm/java-17-openjdk-amd64 (no JDK specified, using current Java home) OS: Linux 6.1.0-32-amd64 amd64 ``` ## Step 5 – Create a Project with Gradle In this section, we will show you how to create a sample project with Gradle. First, create a directory for your project: ``` mkdir project ``` Next, navigate to the project directory and initialize the project with the following command: ``` cd project gradle init ``` You will be asked to select the type of project to generate: ``` Starting a Gradle Daemon (subsequent builds will be faster) Select type of build to generate: 1: Application 2: Library 3: Gradle plugin 4: Basic (build structure only) Enter selection (default: Application) [1..4] 4 ``` Type **4** and press the **Enter** key. You will be asked to select the build script: ``` Select build script DSL: 1: Groovy 2: Kotlin Enter selection (default: Groovy) [1..2] 1 ``` Type **1** and press **Enter** key. Once the project has been built successfully, you will get the following output: ``` Generate build using new APIs and behavior (some features may change in the next minor release)? (default: no) [yes, no] Project name (default: project): > Task :init Learn more about Gradle by exploring our Samples at https://docs.gradle.org/9.0.0/samples BUILD SUCCESSFUL in 1m 7s 1 actionable task: 1 executed Consider enabling configuration cache to speed up this build: https://docs.gradle.org/9.0.0/userguide/configuration_cache_enabling.html ``` You can list your project files using the following command: ``` ls ``` You should see the following output: ``` build.gradle.kts gradle gradle.properties gradlew gradlew.bat settings.gradle.kts ``` ## Conclusion Congratulations! You have successfully installed Gradle on Debian 12. You can now start deploying your application using Gradle. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install osTicket on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-osticket-on-rocky-linux-10/ | Published: 2021-12-27 | Updated: 2025-10-19 | Author: Hitesh Jethva osTicket is an open-source and web-based customer support ticketing system used to scale and streamline customer service operations. It is written in PHP programming and developed by Enhancesoft. osTicket is simple and lightweight and allows you to organize, manage and archive support requests. It helps to define routing rules for tickets to send the tickets to the correct department. **Features** - Ticket Filters - Customer Support Portal - Ticket Filters - Custom Fields, Columns, and Queues - Agent Collision Avoidance - Assign, Transfer, & Referral In this post, we will show you how to install osTicket on Rocky Linux 10. ## Step 1 – Install Apache, PHP, and MariaDB First, install the Apache and MariaDB server package using the following command: ``` dnf install httpd mariadb mariadb-server -y ``` Next, install PHP with other required extensions using the following command: ``` dnf install php php-fpm php-pear php-cgi php-common php-curl php-gettext php-zip php-opcache php-apcu php-intl php-gd php-mysqli wget unzip -y ``` Once all the packages are installed, start and enable the Apache and MariaDB services: ``` systemctl enable --now httpd systemctl enable --now mariadb ``` ## Step 2 – Configure MariaDB Database First, secure the MariaDB installation and set the MariaDB root password using the following command: ``` mysql_secure_installation ``` Answer all the questions as shown below: ``` Enter current password for root (enter for none): Set root password? [Y/n] y New password: Re-enter new password: Remove anonymous users? [Y/n] y Disallow root login remotely? [Y/n] y Remove test database and access to it? [Y/n] y Reload privilege tables now? [Y/n] y ``` Next, log in to the MariaDB server with the following command: ``` mysql -u root -p ``` Once you are logged in, create a database and user for osTicket: ``` CREATE DATABASE osticketdb; GRANT ALL PRIVILEGES ON osticketdb.* TO osticketuser@localhost IDENTIFIED BY "securepassword"; ``` Next, flush the privileges and exit from the MariaDB shell: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install osTicket First, download the latest version of osTicket using the following command: ``` wget https://github.com/osTicket/osTicket/releases/download/v1.18.2/osTicket-v1.18.2.zip ``` Once the download is completed, unzip the downloaded file to the Apache web root directory: ``` unzip osTicket-v1.18.2.zip -d /var/www/html/osTicket ``` Next, copy the osTicket sample configuration file: ``` cp /var/www/html/osTicket/upload/include/ost-sampleconfig.php /var/www/html/osTicket/upload/include/ost-config.php ``` Next, change the ownership of the osTicket directory to apache: ``` chown -R apache:apache /var/www/html/osTicket chmod 777 /var/www/html/osTicket/upload/include/ost-config.php ``` ## Step 4 – Configure Apache for osTicket Next, you will need to create an Apache virtual host configuration file for osTicket. You can create it using the following command: ``` nano /etc/httpd/conf.d/osticket.conf ``` Add the following lines: ``` ServerAdmin admin@example.com DocumentRoot /var/www/html/osTicket/upload ServerName osticket.example.com Options FollowSymlinks AllowOverride All Require all granted ErrorLog /var/log/httpd/osticket_error.log CustomLog /var/log/httpd/osticket_access.log combined ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` You can now check the status of Apache using the command below: ``` systemctl status httpd ``` You should see the following output: ``` ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; enabled; preset: disabled) Drop-In: /etc/systemd/system/httpd.service.d └─php-fpm.conf Active: active (running) since Sun 2025-10-19 01:17:12 EDT; 2s ago Invocation: 57272ab5ecf1496496887b8827f234d3 Docs: man:httpd.service(8) Main PID: 11618 (httpd) Status: "Started, listening on: port 80" Tasks: 177 (limit: 24809) Memory: 13.2M (peak: 13.4M) CPU: 89ms CGroup: /system.slice/httpd.service ├─11618 /usr/sbin/httpd -DFOREGROUND ├─11619 /usr/sbin/httpd -DFOREGROUND ├─11620 /usr/sbin/httpd -DFOREGROUND ├─11621 /usr/sbin/httpd -DFOREGROUND └─11633 /usr/sbin/httpd -DFOREGROUND ``` ## Step 5 – Access osTicket Web Installation Wizard Now, open your web browser and access the osTicket web installation wizard using the URL **http://osticket.example.com**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/12/o1.png) Make sure all the PHP extensions are installed, then click on the **Continue** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/12/o3.png) ![osticket admin user details](https://www.atlantic.net/wp-content/uploads/2021/12/a2-1.png) Provide your system settings, admin username, password, and database credentials, then click on the **Install** button. Once the installation is completed, you should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/12/o4.png) Now, open your terminal, change the permissions of the osTicket configuration file, and remove the setup directory: ``` chmod 0644 /var/www/html/osTicket/upload/include/ost-config.php rm -rf /var/www/html/osTicket/upload/setup/ ``` Next, go back to your web browser and click on the **Your Staff Control Panel**. You should see the following page: ![osticket login](https://www.atlantic.net/wp-content/uploads/2021/12/a7-1.png) Provide your admin username and password and click on the **Login** button. You should see the osTicket dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/12/o5.png) ## Conclusion Congratulations! You have successfully installed osTicket with Apache on Rocky Linux 10. You can now use osTicket in your organization to provide customer support. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install SonarQube Code Quality Analyzer on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-sonarqube-code-quality-analyzer-on-rocky-linux-10/ | Published: 2021-12-28 | Updated: 2025-10-19 | Author: Hitesh Jethva SonarQube is an open-source code quality checking platform developed by SonarSource. It detects bugs and vulnerabilities in your code automatically and provides reports for the code quality of your project. It can analyze code in 27 different programming languages including C, C++, Java, Javascript, PHP, Go, Python, and many more. SonarQube helps developers to reduce the code size, complexity, and maintenance time and make it easier to read and understand. In this post, we will show you how to install SonarQube on Rocky Linux10 ## Step 1 – Getting Started First, you will need to tweak the kernel settings per SonarQube requirements. You can do it editing /etc/sysctl.conf file. ``` nano /etc/sysctl.conf ``` Add the following lines: ``` vm.max_map_count=262144 fs.file-max=65536 ``` Save and close the file, then run the following command to apply the changes: ``` sysctl -f ``` Next, install Java JDK using the following command: ``` dnf install java-21-openjdk-devel unzip -y ``` After the installation, verify the Java version using the command given below: ``` java --version ``` You should see the following output: ``` openjdk 21.0.8 2025-07-15 LTS OpenJDK Runtime Environment (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS, mixed mode, sharing) ``` ## Step 2 – Install and Configure PostgreSQL SonarQube uses PostgreSQL as a database backend, so you will need to install a PostgreSQL database on your server. First, install the PostgreSQL repo using the following command: ``` dnf install https://download.postgresql.org/pub/repos/yum/reporpms/EL-8-x86_64/pgdg-redhat-repo-latest.noarch.rpm ``` Next, install the latest version of PostgreSQL with the following command: ``` dnf install postgresql18 postgresql18-server -y ``` Once the installation is completed, initialize the PostgreSQL database using the following command: ``` /usr/pgsql-18/bin/postgresql-18-setup initdb ``` Next, start and enable the PostgreSQL service with the following command: ``` systemctl enable --now postgresql-18 ``` Next, log in to PostgreSQL with the following command: ``` su - postgres psql ``` Next, create a database and user for SonarQube using the following command: ``` create user sonar; create database sonardb owner sonar; ``` Next, grant all the privileges to the SonarQube database and set the user password: ``` grant all privileges on database sonardb to sonar; ALTER USER sonar WITH ENCRYPTED password 'securepassword'; ``` Next, exit from PostgreSQL using the following command: ``` \q exit ``` ## Step 3 – Install and Configure SonarQube First, create a dedicated user for SonarQube using the following command: ``` useradd sonar ``` Next, download the latest version of SonarQube with the following command: ``` wget https://binaries.sonarsource.com/Distribution/sonarqube/sonarqube-25.10.0.114319.zip ``` After the successful download, unzip the downloaded file using the following command: ``` unzip sonarqube-25.10.0.114319.zip ``` Next, move the extracted directory to /opt with the following command: ``` mv sonarqube-25.10.0.114319 /opt/sonarqube ``` Next, edit the SonarQube configuration file: ``` nano /opt/sonarqube/conf/sonar.properties ``` Define your SonarQube database, web host, JVM option, and data directory: ``` sonar.jdbc.username=sonar sonar.jdbc.password=securepassword sonar.jdbc.url=jdbc:postgresql://localhost/sonardb sonar.web.host=0.0.0.0 sonar.web.port=9000 sonar.web.javaOpts=-Xmx512m -Xms128m -XX:+HeapDumpOnOutOfMemoryError sonar.search.javaOpts=-Xmx512m -Xms512m -XX:MaxDirectMemorySize=256m -XX:+HeapDumpOnOutOfMemoryError sonar.path.data=data sonar.path.temp=temp ``` Save and close the file, then change the ownership of the /opt/sonarqube: ``` chown -R sonar:sonar /opt/sonarqube ``` ## Step 4 – Create a Systemd Service File for SonarQube Next, you will need to create a systemd service to manage the SonarQube service. You can create it using the following command: ``` nano /etc/systemd/system/sonarqube.service ``` Add the following lines: ``` [Unit] Description=SonarQube service After=syslog.target network.target [Service] Type=forking ExecStart=/opt/sonarqube/bin/linux-x86-64/sonar.sh start ExecStop=/opt/sonarqube/bin/linux-x86-64/sonar.sh stop LimitNOFILE=65536 LimitNPROC=4096 User=sonar Group=sonar Restart=on-failure [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes: ``` systemctl daemon-reload ``` Next, start and enable the SonarQube service: ``` systemctl start sonarqube systemctl enable sonarqube ``` Next, verify the SonarQube service status using the command given below: ``` systemctl status sonarqube ``` You should see the following output: ``` ● sonarqube.service - SonarQube service Loaded: loaded (/etc/systemd/system/sonarqube.service; disabled; preset: disabled) Active: active (running) since Sun 2025-10-19 01:04:14 EDT; 4s ago Invocation: a173ea340b99480faca86052ddcc7f45 Process: 10735 ExecStart=/opt/sonarqube/bin/linux-x86-64/sonar.sh start (code=exited, status=0/SUCCESS) Main PID: 10759 (java) Tasks: 48 (limit: 24809) Memory: 457.4M (peak: 743.2M) CPU: 7.584s CGroup: /system.slice/sonarqube.service ├─10759 java -Xms8m -Xmx32m --add-exports=java.base/jdk.internal.ref=ALL-UNNAMED --add-opens=java.base/java.lang=ALL-UNNAMED --add-opens=java.base/java.nio=ALL-UNNAMED --> ├─10784 /usr/lib/jvm/java-21-openjdk/bin/java -Xms4m -Xmx64m -XX:+UseSerialGC -Dcli.name=server -Dcli.script=./bin/elasticsearch -Dcli.libs=lib/tools/server-cli -Des.path> └─10843 /usr/lib/jvm/java-21-openjdk/bin/java -Des.networkaddress.cache.ttl=60 -Des.networkaddress.cache.negative.ttl=10 -Djava.security.manager=allow -XX:+AlwaysPreTouch> Oct 19 01:04:14 rocky systemd[1]: Starting sonarqube.service - SonarQube service... Oct 19 01:04:14 rocky sonar.sh[10735]: /usr/bin/java Oct 19 01:04:14 rocky sonar.sh[10735]: Starting SonarQube... Oct 19 01:04:14 rocky sonar.sh[10735]: Started SonarQube. Oct 19 01:04:14 rocky systemd[1]: Started sonarqube.service - SonarQube service. ``` At this point, SonarQube is started and listens on port 9000. You can check it using the following command: ``` ss -antpl | grep 9000 ``` You should see the following output: ``` LISTEN 0 25 *:9000 *:* users:(("java",pid=6541,fd=13)) ``` ## Step 5 – Access SonarQube Web Interface Now, open your web browser and access the SonarQube web interface using the URL **http://your-server-ip:9000**. You should see the SonarQube login page: ![](https://www.atlantic.net/wp-content/uploads/2021/12/s1.png) Provide default admin username and password as admin/admin and click on the **Log in** button. Once you are logged in, you should see the password update page: ![](https://www.atlantic.net/wp-content/uploads/2021/12/s2.png) Change the default admin password and click on the **Update** button. You should see the SonarQube dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/12/s3.png) ## Conclusion Congratulations! You have successfully installed SonarQube on Rocky Linux 10. You can now create your project manually or import from GitHub, GitLab, or Azure and start analyzing your code from the web browser. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install AngularJS on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-angularjs-on-rocky-linux-10/ | Published: 2021-12-30 | Updated: 2025-10-18 | Author: Hitesh Jethva AngularJS is a free and open-source front-end web framework for developing single-page applications. It is based on JavaScript and maintained by Google and a community of individuals and corporations. It is fully extensible and can be used to keep track of all components and check regularly for their updates. It comes with a set of developer tools for developing, updating, and testing code. **Features** - Data-binding - Routing - Forms management - Deep linking - Dependency injection - Large community In this post, we will explain how to install AngularJS on Rocky Linux 10. ## Step 1 – Install Node.js Before installing AngularJS, you will need to install Node.js on your server. First, install the curl utility with the following command: ``` dnf install curl -y ``` Next, add the Node.js repository with the following command: ``` curl --silent --location https://rpm.nodesource.com/setup_22.x | bash - ``` Next, install Node.js using the following command: ``` dnf install nodejs -y ``` After the installation, verify the Node.js version using the command below: ``` node -v ``` You will get the following output: ``` v22.20.0 ``` Next, update NPM to the latest version using the command below: ``` npm install npm@latest -g ``` Next, verify the NPM version using the command below: ``` npm --version ``` You should see the following output: ``` 11.6.2 ``` ## Step 2 – Install Angular CLI By default, Angular CLI is included in the Rocky Linux default repo. You can install it by running the following command: ``` npm install -g @angular/cli ``` Once the Angular CLI is installed, you can verify the installation using the following command: ``` ng version ``` You will get the following output: ``` _ _ ____ _ ___ Angular CLI: 20.3.6 Node: 22.20.0 Package Manager: npm 11.6.2 OS: linux x64 Angular: Package Version ------------------------------------ @angular-devkit/architect 0.2003.6 (cli-only) @angular-devkit/core 20.3.6 (cli-only) @angular-devkit/schematics 20.3.6 (cli-only) @schematics/angular 20.3.6 (cli-only) ``` ## Step 3 – Create a Sample Application with Angular Next, use the Angular CLI tool to create a new application named newapp: ``` ng new newapp ``` Once the application has been installed, you will get the following output: ``` ✔ Packages installed successfully. *** Please tell me who you are. Run git config --global user.email "you@example.com" git config --global user.name "Your Name" to set your account's default identity. Omit --global to set the identity only in this repository. ``` Next, navigate to the newapp directory and start your application on port 8080: ``` cd newapp ng serve --host 0.0.0.0 --port 8080 ``` You will get the following output: ``` ✔ Browser application bundle generation complete. Initial Chunk Files | Names | Size vendor.js | vendor | 1.94 MB polyfills.js | polyfills | 339.07 kB styles.css, styles.js | styles | 212.39 kB main.js | main | 53.19 kB runtime.js | runtime | 6.85 kB | Initial Total | 2.54 MB Build at: 2021-12-06T13:57:31.158Z - Hash: be63da5bbfd6b41d - Time: 43952ms ** Angular Live Development Server is listening on 0.0.0.0:8080, open your browser on http://localhost:8080/ ** ✔ Compiled successfully. ``` Now, open your favorite web browser and access your Angular application using the URL **http://your-server-ip:8080**. You should see the Angular Dashboard on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/12/a1-2.png) Now, go back to your terminal and press **CTRL+C** to stop the application. ## Step 4 – Manage Angular Application with PM2 PM2 is a process manager used to manage the Nodejs-based application. In this section, we will install PM2 and use it to manage the AngularJS application. First, install PM2 using the NPM as shown below: ``` npm install -g pm2 ``` Once PM2 is installed, start your Angular Application using PM2: ``` pm2 start "ng serve --host 0.0.0.0 --port 8080" --name "myapp" ``` You will get the following output: ``` [PM2] Spawning PM2 daemon with pm2_home=/root/.pm2 [PM2] PM2 Successfully daemonized [PM2] Starting /usr/bin/bash in fork_mode (1 instance) [PM2] Done. ┌─────┬──────────┬─────────────┬─────────┬─────────┬──────────┬────────┬──────┬───────────┬──────────┬──────────┬──────────┬──────────┐ │ id │ name │ namespace │ version │ mode │ pid │ uptime │ ↺ │ status │ cpu │ mem │ user │ watching │ ├─────┼──────────┼─────────────┼─────────┼─────────┼──────────┼────────┼──────┼───────────┼──────────┼──────────┼──────────┼──────────┤ │ 0 │ myapp │ default │ N/A │ fork │ 14200 │ 0s │ 0 │ online │ 0% │ 34.3mb │ root │ disabled │ └─────┴──────────┴─────────────┴─────────┴─────────┴──────────┴────────┴──────┴───────────┴──────────┴──────────┴──────────┴──────────┘ ``` To check the status of your application, run: ``` pm2 status ``` You should see the following output: ``` ┌─────┬──────────┬─────────────┬─────────┬─────────┬──────────┬────────┬──────┬───────────┬──────────┬──────────┬──────────┬──────────┐ │ id │ name │ namespace │ version │ mode │ pid │ uptime │ ↺ │ status │ cpu │ mem │ user │ watching │ ├─────┼──────────┼─────────────┼─────────┼─────────┼──────────┼────────┼──────┼───────────┼──────────┼──────────┼──────────┼──────────┤ │ 0 │ myapp │ default │ N/A │ fork │ 14200 │ 20s │ 0 │ online │ 0% │ 336.1mb │ root │ disabled │ └─────┴──────────┴─────────────┴─────────┴─────────┴──────────┴────────┴──────┴───────────┴──────────┴──────────┴──────────┴──────────┘ ``` To list all running applications, run: ``` pm2 ls ``` To stop the running application, run: ``` pm2 stop myapp ``` To restart the application, run: ``` pm2 restart myapp ``` ## Conclusion In the above guide, you learned how to install AngularJS on Rocky Linux 10. You also learned how to manage the Angular App with PM2. You can now start developing Mobile, Web, and Desktop applications using the Angular framework. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How To Install SuiteCRM on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-suitecrm-on-rocky-linux-10/ | Published: 2021-12-31 | Updated: 2025-10-18 | Author: Hitesh Jethva SuiteCRM is a free and open-source Customer Relationship Management application written in PHP. It is an alternative to the popular CRM solution SugarCRM. SuiteCRM comes with all the functionalities required by a business with a need for a CRM solution. SuiteCRM offers many features that help you run your business and collaborate with your customers and employees. **Features** - Email marketing - Social media integration - Customer support, social CRM, and reporting - Supports multiple user accounts - Can be integrated Gmail, Facebook, Twitter, and more - Task management In this post, we will show you how to install SuiteCRM with Nginx on Rocky Linux 10. ## Step 1 – Install Nginx, MariaDB, and PHP First, install Nginx and MariaDB server using the following command: ``` dnf install nginx mariadb-server -y ``` Once both packages are installed, start and enable the Nginx and MariaDB services: ``` systemctl start nginx mariadb systemctl enable nginx mariadb ``` Next, install PHP with all required extensions using the following command: ``` dnf install php php-pear php-cgi php-common php-curl php-mbstring php-gd php-mysqlnd php-gettext php-bcmath php-json php-xml php-fpm php-intl php-zip php-gmp unzip curl git -y ``` Once all the packages are installed, edit the php.ini file and change some default settings: ``` nano /etc/php.ini ``` Change the following lines: ``` upload_max_filesize = 120M max_execution_time = 300 date.timezone = UTC ``` Save and close the file, then edit the PHP-FPM configuration file: ``` nano /etc/php-fpm.d/www.conf ``` Change the user and group from www-data to nginx: ``` user = nginx group = nginx ``` Save and close the file, then start the PHP-FPM service and enable it to start at system reboot: ``` systemctl start php-fpm systemctl enable php-fpm ``` ## Step 2 – Create a Database for SuiteCRM Next, you will need to create a database and user for SuiteCRM. First, log in to MariaDB with the following command: ``` mysql ``` Once you are logged in, create a database and user with the following command: ``` CREATE DATABASE suitecrm; GRANT ALL ON suitecrm.* TO suitecrm@localhost IDENTIFIED by "yourpassword"; ``` Next, flush the privileges and exit from the MariaDB shell: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install SuiteCRM First, you will need to install Composer to your system. You can install it using the following command: ``` wget https://getcomposer.org/installer -O composer-installer.php php composer-installer.php --filename=composer --install-dir=/usr/local/bin ``` Next, download the latest version of SuiteCRM with the following command: ``` wget https://suitecrm.com/download/166/suite89/565428/suitecrm-8-9-0.zip ``` Next, unzip the downloaded file with the following command: ``` unzip suitecrm-8-9-0.zip -d /var/www/html/suitecrm ``` Next, change the directory to the downloaded directory and install all the required PHP dependencies: ``` cd /var/www/html/suitecrm composer install --ignore-platform-req=ext-sodium --ignore-platform-req=ext-ldap ``` Next, set proper ownership and permissions for the SuiteCRM directory: ``` chown -R nginx:nginx /var/www/html/suitecrm chmod -R 755 /var/www/html/suitecrm ``` You will also need to change the ownership of the session directory as shown below: ``` chown -R nginx:nginx /var/lib/php/session/ ``` Once you are done, you can proceed to the next step. ## Step 4 – Configure Nginx for SuiteCRM Next, you will need to create an Nginx virtual host configuration file for SuiteCRM. You can create it using the command below: ``` nano /etc/nginx/conf.d/suitecrm.conf ``` Add the following lines: ``` server { server_name suitecrm.example.com; client_max_body_size 20M; root /var/www/html/suitecrm/public; location ~ \.php$ { fastcgi_pass unix:/var/run/php-fpm/www.sock; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } error_log /var/log/nginx/suitecrm_error.log; access_log /var/log/nginx/suitecrm_access.log; } ``` Save and close the file, then edit the **nginx.conf** file and set the hach_bucket size: ``` nano /etc/nginx/nginx.conf ``` Add the following line below the line http {: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then restart the Nginx service to apply the configuration changes: ``` systemctl restart nginx ``` ## Step 5 – Access SuiteCRM Now, open your web browser and access SuiteCRM using the URL **http://suitecrm.example.com/install.php**. You should see the License agreement screen: ![SuiteCRM license agreement](https://www.atlantic.net/wp-content/uploads/2021/12/p1-4-1024x527.png) Accept the License Agreement, then click on the **CONFIGURATION** tab. You should see the database setup screen: ![SuiteCRM database setup](https://www.atlantic.net/wp-content/uploads/2021/12/p2-3-1024x531.png) Provide your server URL, database configuration, admin username, and password, then click on the **PROCEED** button. You should see the SuiteCRM login screen: ![SuiteCRM login](https://www.atlantic.net/wp-content/uploads/2021/12/p3-1024x533.png) Provide your admin username and password and click on the **Log In** button. You should see the SuiteCRM dashboard on the following screen: ![SuiteCRM dashboard](https://www.atlantic.net/wp-content/uploads/2021/12/p4-1024x530.png) ## Conclusion Congratulations! You have successfully installed SuiteCRM on Rocky Linux 10. You can now explore SuiteCRM and implement it in your organization to help you run your business and collaborate with your customers. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How To Install Jira on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-jira-on-rocky-linux-10/ | Published: 2022-01-01 | Updated: 2025-10-18 | Author: Hitesh Jethva Jira is an issue tracking and project management application developed by the Australian software company Atlassian. It is used by agile development teams to track bugs, stories, epics, and other tasks. It comes with an intuitive and user-friendly web interface to track issues from a web browser. If you are looking for a self-hosted platform to build and manage your content then Jira is the right choice for you. In this post, we will show you how to install Jira on Rocky Linux 10. ## Step 1 – Install Java JDK Jira is a Java-based application, so you will need to install Java JDK to your system. You can install it by running the following command: ``` dnf install java-21-openjdk java-21-openjdk-devel -y ``` Once Java is installed, verify the Java installation using the following command: ``` java -version ``` You should see the Java version in the following output: ``` openjdk 21.0.8 2025-07-15 LTS OpenJDK Runtime Environment (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS, mixed mode, sharing) ``` ## Step 2 – Install and Configure MySQL Jira uses MySQL as a database backend, so you will need to install MySQL server on your server. You can install it by running the following command: ``` dnf install https://dev.mysql.com/get/mysql84-community-release-el9-1.noarch.rpm dnf install mysql-community-server -y ``` After the installation, start and enable the MySQL service with the following command: ``` systemctl start mysqld systemctl enable mysqld ``` Next, edit the MySQL configuration file and tweak some settings: ``` nano /etc/my.cnf ``` Add the following lines inside the [mysqld] section: ``` default-storage-engine=INNODB character_set_server=utf8mb4 innodb_default_row_format=DYNAMIC innodb_log_file_size=2G sql_mode = NO_AUTO_VALUE_ON_ZERO ``` Save and close the file, then restart the MySQL service to apply the changes: ``` systemctl restart mysqld ``` Next, retrieve the MySQL root password. ``` grep 'temporary password' /var/log/mysqld.log ``` Output. ``` 2025-10-18T06:36:47.362707Z 6 [Note] [MY-010454] [Server] A temporary password is generated for root@localhost: Oh(6kH,j!_%8 ``` Change MySQL default root password. ``` mysql -u root -p ALTER USER 'root'@'localhost' IDENTIFIED BY 'Secure@Pass_wordJethva1981'; FLUSH PRIVILEGES; EXIT; ``` Next, log in to MySQL with the following command: ``` mysql -u root -p ``` Once you are logged in, create a database and user for Jira: ``` CREATE DATABASE jira CHARACTER SET utf8mb4 COLLATE utf8mb4_bin; CREATE USER 'jira'@'localhost' IDENTIFIED BY 'yourpassword'; ``` Next, grant all required privileges to the Jira database with the following command: ``` GRANT SELECT,INSERT,UPDATE,DELETE,CREATE,DROP,REFERENCES,ALTER,INDEX on jira.* TO 'jira'@'localhost'; ``` Next, flush the privileges and exit from MySQL using the command below: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install Jira First, go to the Jira official download page and use the wget command to download the latest version of Jira: ``` wget https://product-downloads.atlassian.com/software/jira/downloads/atlassian-jira-core-11.1.1.zip ``` Once the Jira is downloaded, make it executable with the following command: ``` chmod +x atlassian-jira-software-11.1.1-x64.bin ``` Next, run the downloaded binary file to start the installation: ``` ./atlassian-jira-software-11.1.1-x64.bin ``` You will be asked to start the installation: ``` This will install Jira Software on your computer. OK [o, Enter], Cancel [c] ``` Press **Enter** key to start the installation. You will be asked to choose the installation option: ``` Click Next to continue, or Cancel to exit Setup. Choose the appropriate installation or upgrade option. Please choose one of the following: Express Install (use default settings) [1], Custom Install (recommended for advanced users) [2, Enter], Upgrade an existing Jira installation [3] 1 ``` Type **1** and press the **Enter** key to start with express installation. You will be asked to install Jira as a service: ``` Details on where Jira Software will be installed and the settings that will be used. Installation Directory: /opt/atlassian/jira Home Directory: /var/atlassian/application-data/jira HTTP Port: 8080 RMI Port: 8005 Install as service: Yes Install [i, Enter], Exit [e] ``` Just press the **Enter** key to continue. Once Jira is installed, you should see the following output: ``` Extracting files ... Please wait a few moments while Jira Software is configured. Installation of Jira Software is complete Start Jira Software now? Yes [y, Enter], No [n] y ``` Type **y** and press the **Enter** key to start Jira. You should see the following output: ``` Please wait a few moments while Jira Software starts up. Launching Jira Software ... Installation of Jira Software is complete Your installation of Jira Software is now ready and can be accessed via your browser. Jira Software 8.20.2 can be accessed at http://localhost:8080 Finishing installation ... ``` Next, download the Java MySQL connector using the command below: ``` wget https://dev.mysql.com/get/Downloads/Connector-J/mysql-connector-java-8.0.26.zip ``` Next, unzip the downloaded file using the following command: ``` dnf install unzip unzip mysql-connector-java-8.0.26.zip ``` Next, copy the MySQL connector file to the appropriate directory: ``` cp mysql-connector-java-8.0.26/mysql-connector-java-8.0.26.jar /opt/atlassian/jira/lib ``` ## Step 4 – Create a Systemd Service File for Jira Next, you will need to create a systemd service file to manage the Jira service: ``` nano /etc/systemd/system/jira.service ``` Add the following lines: ``` [Unit] Description=Atlassian JIRA Software Server After=network.target mysqld.service [Service] Type=forking User=jira ExecStart=/opt/atlassian/jira/bin/start-jira.sh ExecStop=/opt/atlassian/jira/bin/stop-jira.sh ExecReload=/opt/atlassian/jira/bin/start-jira.sh | sleep 60 | /opt/atlassian/jira/bin/stop-jira.sh [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, stop the Jira script using the following command: ``` /opt/atlassian/jira/bin/stop-jira.sh ``` Next, start and enable the Jira service using systemd: ``` systemctl start jira systemctl enable jira ``` Next, edit the Jira configuration file with the following command: ``` nano /opt/atlassian/jira/conf/server.xml ``` Modify the following section and include ProxyName and ProxyPort: ``` " maxThreads="150" minSpareThreads="25" connectionTimeout="20000" enableLookups="false" maxHttpHeaderSize="8192" protocol="HTTP/1.1" useBodyEncodingForURI="true" redirectPort="8443" acceptCount="100" disableUploadTimeout="true" bindOnInit="false" scheme="http" proxyName="jira.linuxbuz.com" proxyPort="80" /> ``` Save and close the file, then restart the Jira service to apply the changes: ``` systemctl restart jira ``` ## Step 5 – Configure Nginx as a Reverse Proxy Next, you will need to install and configure the Nginx as a reverse proxy for Jira. First, install the Nginx package with the following command: ``` dnf install nginx -y ``` Next, start and enable the Nginx service using the following command: ``` systemctl start nginx systemctl enable nginx ``` Next, create an Nginx virtual host configuration file: ``` nano /etc/nginx/conf.d/jira.conf ``` Add the following lines: ``` server { listen 80; server_name jira.linuxbuz.com; location / { proxy_set_header X-Forwarded-Host $host; proxy_set_header X-Forwarded-Server $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_pass http://jira.linuxbuz.com:8080; client_max_body_size 10M; } } ``` Save and close the file, then edit the **nginx.conf** file and set the hash_bucket size: ``` nano /etc/nginx/nginx.conf ``` Add the following line below htttp {: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 6 – Access Jira Web Installation Wizard Now, open your web browser and access the Jira web installation wizard using the URL **http://jira.linuxbuz.com**. You should see the Jira setup page: ![Jira Select Installation](https://www.atlantic.net/wp-content/uploads/2021/12/p1-3.png) Select “**I’ll set it up myself**” and click on **Next**. You should see the database setup page: ![Jira Database setup](https://www.atlantic.net/wp-content/uploads/2021/12/p2-2.png) Provide your database information and click on **Next**. You should see an application properties page: ![Jira application setup](https://www.atlantic.net/wp-content/uploads/2021/12/a1.png) Provide your application name and base URL and click on the **Next** button. You should see the Jira license page: ![Jira License](https://www.atlantic.net/wp-content/uploads/2021/12/a2.png) Provide your Jira software license and click on the **Next** button. You should see the administrator account setup page: ![Jira account setup page](https://www.atlantic.net/wp-content/uploads/2021/12/a3-1024x557.png) Provide your admin username, password, and email, and click on **Next**. You should see the Setup email notification page: ![Jira email notification page](https://www.atlantic.net/wp-content/uploads/2021/12/a4.png) Click on the **Finish** button to complete the setup. You should see the Jira language selection page: ![Jira language selection page](https://www.atlantic.net/wp-content/uploads/2021/12/a5.png) Select your language and click on **Continue**. You should see Choose an avatar page: ![Jira avatar page](https://www.atlantic.net/wp-content/uploads/2021/12/a6.png) Click on **Next**. You should see the Project creation page: ![Jira project creation](https://www.atlantic.net/wp-content/uploads/2021/12/a7-1024x403.png) Click on **Create** **new** **project**. You should see the following page: ![Jira project selection page](https://www.atlantic.net/wp-content/uploads/2021/12/a8.png) Select **Scrum** **software** **development** and click on **Next**. You should see the following page: ![Jira provide project name](https://www.atlantic.net/wp-content/uploads/2021/12/a9.png) Provide your project name, key and click on **Submit**. You should see the Jira dashboard on the following page: ![Jira dashboard](https://www.atlantic.net/wp-content/uploads/2021/12/a10-1024x493.png) ## Conclusion Congratulations! You have successfully installed Jira with Nginx on Rocky Linux 10. You can now implement Jira in your organization and start managing and tracking your projects from a central location. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Top 10 SEO Agencies > URL: https://www.atlantic.net/vps-hosting/top-10-seo-agencies/ | Published: 2022-01-02 | Updated: 2025-09-19 | Author: Dr. Rachael Bailey With over a quarter of users relying on their first organic search result, optimized SEO content has never been more important. In our fast-paced digital world, our reliance on digital marketing is set to grow. This means that businesses and organizations must continue to produce high-ranking content to ensure that they stay ahead of their competitors. SEO companies possess the specialized experience and knowledge necessary to boost organic traffic to your site. Partnering with a leading SEO company will help your business or organization to boost its visibility and traffic, ultimately generating new leads, increasing your revenue, and driving your business forward. When searching for SEO companies you have probably been inundated with options. But how do you know which one will partner best with your business? Here, we summarize some of the leading SEO companies on the market to make things a bit easier for you. ## Top 10 Best SEO Agencies ## [Nomad SEO](https://nomadseo.com/) Nomad SEO has a significant impact across this space, offering tremendous performance, growth, and transparency for their clients. Always at the forefront of the rapidly evolving SEO industry, Nomad SEO’s highly experienced expert analysts are passionate about delivering [goal-focused SEO solutions](https://nomadseo.com/). This sets them ahead of many of their competitors who often focus on keyword rankings that have little or no effect on a business’s impact. As an agile agency, the team at Nomad SEO is highly responsive to the needs of their clients. ## [DIGITECH SEO](https://www.digitechwebdesignaustin.com/austin-seo-agency/) DIGITECH SEO, based in Austin, Texas, is a leader in innovative web design and SEO services. Since 2011, their award-winning team has specialized in crafting user-centric websites, deeply integrated with advanced SEO technologies. They focus on creating digital experiences that convert visitors into customers, leveraging their expertise in branding, digital marketing, and website design. Recognized for excellence, DIGITECH is dedicated to pushing the boundaries of web design and SEO, helping brands of all sizes grow and succeed online. ## Solvid Solvid is an [SEO agency](https://solvid.co.uk/) that has been built to excel across a vast array of sectors with the help of several specialisms. The agency’s services can help provide next-level optimization for business throughout almost every industry, including retail, finance, legal, SaaS, eCommerce, fintech, marketing, entertainment, fashion, and technology. It’s this supreme level of adaptability that’s seen Solvid build relationships with leading brands in the world of investing, design, education, fintech, and finance. Solvid’s commitment to industry-leading keyword research, competitor analysis, sentiment insight, and industry innovation has paved the way for countless brands to supercharge their organic traffic, gain prestigious backlinks, and climb Google’s SERPs to new heights as a means of unlocking new opportunities in their respective markets. In addition to this, Solvid’s approach to SEO is equally comprehensive. Alongside meticulous keyword research, on-page SEO, local SEO, content creation, off-page SEO, and link-building, Solvid will undertake comprehensive technical search engine optimization to help optimize site performance, audit backlinks, accommodate crawlers, and fix page errors on site. ## Ignite Visibility Ignite Visibility is one of the leading players within the digital marketing industry. Based in San Diego, it has been named as the number one Search Engine Marketing company in the USA, UK, and Canada by Clutch.co. Serving some massive global brands, Ignite Visibility is a four-time Inc. 5000 company (2017, 2018, 2019, and 2020). Ignite Visibility offers its clients a selection of services including marketing, design, and analytics, but its main focus remains on goal-driven SEO strategies. Clients also benefit from Ignite Visibility’s proprietary performance-based forecasting technology. ## HigherVisibility Higher Visibility is an award-winning digital marketing agency that is happy to partner with companies of any size, ranging from small businesses to Fortune 1000s. They were recently named “SEO Agency of the Year 2020” by Search Engine Land and “Best Large SEO Agency” in the US Search Awards 2020. While improving ranking and increasing traffic remains important to them, HigherVisibility focuses heavily on achieving more conversions. This is what sets them ahead of many of their competitors. ## Straight North Founded in 1997, Straight North is a results-driven digital marketing agency that offers SEO, PPC, and Web Design services. Employing over 100 full-time experts, Straight North offers notable features including proprietary lead tracking technology, a free instant SEO audit tool, full penalty removal services, and an SEO consulting service that allows Straight North to advise your in-house SEO team. Straight North appreciates that each client will have their own individual needs, so they do not offer any set-priced packages. Instead, they tailor the cost to meet their client’s needs. ## Social SEO Headquartered in Colorado Springs, Social SEO is one of the top-rated digital marketing agencies in the US. It was ranked as the number 1 “Digital Marketing Firm in America” by UpCity in 2021. With over 20 years of experience, Social SEO offers an extensive range of services including local and national SEO, social media, [email marketing](https://www.founderjar.com/email-marketing/), content strategy, and graphic design. ## WebFX WebFX is a leader in tech-enabled digital marketing solutions, employing a diverse team of over 200 award-winning marketers, developers, and designers. WebFX focuses on performance and driving results, with proprietary software backed by Watson IBM and billions of collated data points. Having generated over 2.4 billion in client revenue and 6.3 million leads, WebFX customizes its strategies to get the most for its clients. Their range of services includes SEO, PPC, social media, web design, and email marketing. ## SmartSites Based in New Jersey, SmartSites is an award-winning digital marketing and web design agency. With a proven track record across many verticals, their SEO services are focused on the long-term success of their clients, helping to boost rankings and organic traffic. Unlike many of its competitors, SmartSites offers a comprehensive range of services, going beyond SEO. Their experts can help your business or organization with web content, outreach, and web development and design. ## SEO Valley Founded in 2000, SEO Valley is a top-rated and award-winning SEO agency located in India. A fast-growing company, SEO Valley is currently partnered with over 6,000 happy clients. Clients can benefit from a comprehensive list of services including SEO, PPC, link acquisition, social media marketing, analytics, and programming. SEO Valley has built a global presence, with development centers based in India and marketing offices across the USA, UK, Australia, New Zealand, and Spain. ## Bonus: PageTraffic PageTraffic is a leading search engine marketing agency with its headquarters based in New Delhi, India, and offices in Mumbai and Chicago. With a simplified approach to business, PageTraffic delivers customized solutions to their clients. They offer a comprehensive list of services including SEO, web design, social media, and [content marketing](https://www.activenoon.com/content-marketing-strategies/). The marketing experts at PageTraffic understand the need to customize your approach to SEO based on the size of your business. With this in mind, they employ separate strategies for small businesses and enterprise/large businesses. ## Bonus: Sure Oak Founded in 2013, Sure Oak is a full-service SEO agency based in New York. Services offered by Sure Oak include SEO, web design and development, social media marketing, content development, competitor analysis, and link building. Their proprietary ‘SEO Game Plan’ provides a strong foundation for the start of your SEO project, setting out a year-long plan focused on achieving sustainable growth and a return on your investment. Sure Oak offers a free SEO strategy review to get a clearer insight into the performance of your site and learn how to effectively grow your organic traffic. ## Cloud Hosting and SEO Go Hand in Hand Hosting your infrastructure in the cloud can benefit your SEO efforts greatly. Search rankings are affected by factors such as hosting location, uptime, speed of page loading, and reliability. Cloud hosting offers solutions and tools to optimize each of these factors, helping to boost organic traffic to your site and increase its visibility. To enhance your SEO campaign, you should seriously consider partnering with a [VPS hosting provider](https://www.atlantic.net/vps-hosting/). Atlantic.Net is a market-leading cloud computing and hosting solutions provider. With over 30 years of experience, our team of certified and expert engineers is here to provide a customized solution to meet the individual needs of your business or organization. To find out more about the solutions that we offer, [contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # Top 10 Payment Processors > URL: https://www.atlantic.net/pci-compliant-hosting/top-10-payment-processors/ | Published: 2022-01-03 | Updated: 2025-09-19 | Author: Dr. Rachael Bailey With plenty of services to choose from, how do you decide which payment processing company best meets the needs of your business or organization? ## What Does a Payment Processing Company Do? A payment processor is a company that manages transactions between a merchant and a customer. The service communicates payment information from the customer to the merchant’s dedicated bank account. As long as the appropriate funds are available, the payment is completed. Processed transactions may include payment methods such as debit cards, credit cards, and e-wallets. A good payment processor will ensure that this process is quick, efficient, and seamless for both the customers and the merchants. When choosing a suitable payment processor, businesses and organizations must consider the user experience of their clients as well as the compatibility with their current infrastructure, types of accepted payments, chargeable fees, appropriate security standards, and [PCI compliance](https://www.atlantic.net/pci-compliant-hosting/). With hundreds of available options, we have compiled a list of the top 10 payment processing solutions to help you out. ## Our Top 10 Payment Processing Solutions ### 1. PayPal Since its debut in 1998, PayPal has become one of the most widely used and recognizable payment processors. It allows payments to be processed from all over the world, operating in over 300 countries and processing money in 26 currencies. While PayPal used to be synonymous with the online marketplace eBay, this relationship ended in 2020. eBay now uses the payment processing services of Adyen (next on our list), in an attempt to offer their users access to more competitive prices. PayPal is PCI-compliant and can be integrated directly into a merchant’s website. Payments can be processed via a browser, mobile app, or mobile card reader. PayPal sits at the top of our list due to its popularity and accessibility, being accepted by most major retailers. ### 2. Adyen Adyen, Surinamese for “start over again”, was founded in 2006 to create a modern infrastructure capable of streamlining the payment process for customers across the world. They are trusted to handle the transactions of world-leading companies, including eBay, Uber, LinkedIn, Etsy, and Microsoft. Adyen accepts over 250 payment methods and 150 currencies through a single platform. It is fully certified for standards including PSD2 SCA and PCI compliance and offers advanced fraud protection methods with AI and a rule-based risk ecosystem. ### 3. Stripe With headquarters based in San Francisco and Dublin, Stripe is used by millions of businesses of all sizes to manage their payment transactions online. Stripe differs from many of its competitors as it offers a customizable payment processing solution. With powerful and easy-to-use APIs, Stripe was created with developers in mind, allowing the platform to be adapted to meet the needs of each business. Stripe supports over 100 different currencies and payment methods and enables one-click payments, flexible invoicing, subscription billing, and mobile payments. Stripe Radar scans payments and uses machine learning to protect transactions from fraud. ### 4. Skrill A popular Payment Processing tool, Skrill offers similar rates and fees to PayPal. One thing that Skrill does very well is its easy-to-use interface and quick account setup. With Skrill, users benefit from advanced fraud protection, multiple integrations, a fast and secure app allowing you to move money on the go, zero transfer fee when sending money abroad, and chargeback protection. Opening a Skrill account is free to all users. A free account allows you to use your e-wallet online, unload funds, make email transactions, use a Skrill prepaid card, and receive money from friends. Users must make at least one transaction every 12 months for this account to remain free of charge, otherwise, Skrill will charge a $5 fee. ### 5. WorldPay (FisGlobal) WorldPay is the UK’s biggest Payment Processor, helping over 250,000 small and medium businesses to manage their transactions. As with PayPal, WorldPay boasts an extensive global reach, operating across the globe and supporting more than 120 currencies. WorldPay is serious about security, operating a Risk Management Mechanism to detect fraudulent activity, and allowing users to set their own advanced security standards, such as using CVC and AVS to verify payments. One sticking point with WorldPay is that users must commit to lengthy contracts and be subject to early termination fees if these are not honored. ### 6. Authorize.Net Founded in 1996, Authorize.Net has plenty of experience in providing payment processing services across the world. Over 445,000 merchants trust Authorize.Net to handle their transactions, and they process around $149 billion in payments each year. Authorize.Net’s vast experience within this space means that the platform has formed strong partnerships with most major merchant account providers, meaning most payment types are accepted. A popular choice with online retailers, Authorize.Net provides a highly reliable and secure service. The free 24/7 support offered by Authorize.Net is award-winning and rated highly by their clients. ### 7. Square Square was founded in 2009 by the co-founder of Twitter, Jack Dorsey. Square allows merchants to accept online payments wherever they are by converting their mobile devices into a portable payment processor. Clients get access to Square’s custom hardware, including a contactless chip reader, magnetic stripe reader, and point of sale solutions. Customers can pay using all major credit cards, debit cards, Google Pay and Apple Pay. If you are looking to use PayPal though you will be out of luck, not surprising as it is one of Square’s biggest competitors. ### 8. Braintree Owned by PayPal, Braintree may be a smart option for start-up businesses with its simplistic interface and pricing structure. Braintree also claims to simplify the process of PCI compliance for its clients and provides advanced fraud protection solutions, backed by PayPal, one of the largest fintech companies. It serves over 45 different countries and can accept payments in over 130 currencies. ### 9. Wepay Wepay, a JP Morgan Chase company, is an online payment processing company that delivers integrated payment solutions to Integrated Software Vendors and SaaS providers. Wepay is most suited to merchants who sell their goods or services across multiple online channels, as it is easy to implement and integrates seamlessly. Key features of Wepay include instant onboarding, risk and compliance solutions, integrated merchant account with Chase Merchant Services, a flexible API, and no monthly charges. Key shortfalls of Wepay include its inability to accept PayPal and in-store card payments. ### 10. 2Checkout (now Verifone) 2Checkout, acquired by Verifone in August 2020, is a PCI-compliant all-in-one platform that allows payments to be processed across more than 200 countries and territories and in 87 currencies. For this reason, it may be the best payment processing solution for businesses or organizations that process a lot of international transactions. With 2Checkout, clients can host a fully secure checkout service, set up recurring transactions, benefit from advanced fraud protection, accept multiple payment options, and integrate with over 100 online systems and carts. ## Hosting Your Payment Gateway in the Cloud Atlantic.Net has been providing security-defined services for over 30 years, take advantage of our PCI-ready Atlantic.Net cloud platform. Our systems are built from the ground up, ready for your chosen payment processor. We will work with you to achieve PCI compliance, allowing your business to expand and deliver secured card services to your clients. We work directly with several Payment Processors, and we have recently introduced PayPal as a preferred payment method for our cloud platform. Payment gateways make your customer’s journey much easier, and our secured cloud platform is the ideal solution to host it for you. To find out more about the solutions that we offer, [contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # How to Install the Etherpad Collaborative Web Editor on Rocky Linux 8 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-the-etherpad-collaborative-web-editor-on-rocky-linux-8/ | Published: 2022-01-04 | Updated: 2024-06-02 | Author: Hitesh Jethva Etherpad is a free, open-source, web-based file editing application that allows you to collaborate on a file in actual time. It is written in Nodejs and supports thousands of simultaneous real-time users. It has data export capabilities and runs on your server, under your control. It allows authors and editors to see all of the participants’ edits in real-time. In this post, we will show you how to install Etherpad on Rocky Linux 8. ## Step 1 – Install and Configure Database First, enable the MariaDB version 10.04 repository using the following command: ``` dnf update -y dnf module enable mariadb:10.5 ``` Next, install MariaDB 10.5 with the following command: ``` dnf install mariadb-server -y ``` After the installation, start and enable the MariaDB service using the command below: ``` systemctl start mariadb systemctl enable mariadb ``` Next, log in to the MariaDB shell with the following command: ``` mysql ``` Once you are connected, create a database and user for Etherpad: ``` create database `etherpaddb`; create user 'etherpaduser'@'localhost' identified by 'yourpassword'; ``` Next, grant all the privileges to the etherpad database: ``` grant CREATE,ALTER,SELECT,INSERT,UPDATE,DELETE on `etherpaddb`.* to 'etherpaduser'@'localhost'; ``` Next, flush the privileges and exit from MariaDB with the following command: ``` flush privileges; exit; ``` ## Step 2 – Install Node.js Etherpad is written in Node.js, so it must be installed on your server. First, enable the Node.js repository using the following command: ``` curl --silent --location https://rpm.nodesource.com/setup_18.x | bash - ``` Next, install the Node.js with the following command: ``` dnf install nodejs git -y ``` Once Node.js is installed, verify the Node.js version using the following command: ``` node --version ``` You will get the following output: ``` v18.19.0 ``` ## Step 3 – Install Etherpad on Rocky Linux 8 First, create a dedicated user to run Etherpad: ``` adduser --system --home /opt/etherpad --create-home --user-group etherpad ``` Next, switch the user to etherpad and download the latest version of Etherpad with the following command: ``` su - etherpad cd /opt/etherpad git clone --branch master git://github.com/ether/etherpad-lite.git ``` Next, change the directory to the downloaded directory and run Etherpad with the following command: ``` cd etherpad-lite ./src/bin/run.sh ``` If everything is fine, you will get the following output: ``` [2021-12-05 11:19:21.804] [INFO] server - Installed plugins: [2021-12-05 11:19:21.805] [INFO] console - Report bugs at https://github.com/ether/etherpad-lite/issues [2021-12-05 11:19:21.806] [INFO] console - Your Etherpad version is 1.8.16 (142a47c) [2021-12-05 11:19:23.514] [INFO] http - HTTP server listening for connections [2021-12-05 11:19:23.514] [INFO] console - You can access your Etherpad instance at http://0.0.0.0:9001/ [2021-12-05 11:19:23.514] [WARN] console - Admin username and password not set in settings.json. To access admin please uncomment and edit "users" in settings.json [2021-12-05 11:19:23.514] [WARN] console - Etherpad is running in Development mode. This mode is slower for users and less secure than production mode. You should set the NODE_ENV environment variable to production by using: export NODE_ENV=production [2021-12-05 11:19:23.514] [INFO] server - Etherpad is running ``` Press **CTRL+C** to stop the Etherpad. Next, edit the settings.json file and define your database settings: ``` nano settings.json ``` Comment out the following lines: ``` // "dbType": "dirty", // "dbSettings": { // "filename": "var/dirty.db" // }, ``` Change the following lines: ``` "dbType" : "mysql", "dbSettings" : { "user": "etherpaduser", "host": "localhost", "port": 3306, "password": "yourpassword", "database": "etherpaddb", "charset": "utf8mb4" }, "trustProxy": true, ``` Save and close the file, then exit from the Etherpad user: ``` exit ``` ## Step 4 – Create a Systemd Service File for Etherpad Next, create a systemd service file to manage the Etherpad service: ``` nano /etc/systemd/system/etherpad.service ``` Add the following lines: ``` [Unit] Description=Etherpad, a collaborative web editor. After=syslog.target network.target [Service] Type=simple User=etherpad Group=etherpad WorkingDirectory=/opt/etherpad Environment=NODE_ENV=production ExecStart=/usr/bin/node --experimental-worker /opt/etherpad/etherpad-lite/node_modules/ep_etherpad-lite/node/server.js Restart=always [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon using the command below: ``` systemctl daemon-reload ``` Next, start and enable the Etherpad service using the following command: ``` systemctl start etherpad systemctl enable etherpad ``` You can check the status of Etherpad using the following command: ``` systemctl status etherpad ``` You should see the following output: ``` ● etherpad.service - Etherpad, a collaborative web editor. Loaded: loaded (/etc/systemd/system/etherpad.service; disabled; vendor preset: disabled) Active: active (running) since Sun 2021-12-05 11:22:04 UTC; 5s ago Main PID: 13518 (node) Tasks: 13 (limit: 11411) Memory: 104.9M CGroup: /system.slice/etherpad.service └─13518 /usr/bin/node --experimental-worker /opt/etherpad/etherpad-lite/node_modules/ep_etherpad-lite/node/server.js Dec 05 11:22:04 rockylinux node[13518]: DEFAULT_CHARACTER_SET_NAME: 'latin1', Dec 05 11:22:04 rockylinux node[13518]: DEFAULT_COLLATION_NAME: 'latin1_swedish_ci' Dec 05 11:22:04 rockylinux node[13518]: } utf8mb4 latin1_swedish_ci Dec 05 11:22:04 rockylinux node[13518]: [2021-12-05 11:22:04.915] [INFO] plugins - Running npm to get a list of installed plugins... Dec 05 11:22:08 rockylinux node[13518]: [2021-12-05 11:22:08.268] [INFO] plugins - Loading plugin ep_etherpad-lite... Dec 05 11:22:08 rockylinux node[13518]: [2021-12-05 11:22:08.270] [INFO] plugins - Loaded 1 plugins Dec 05 11:22:08 rockylinux node[13518]: [2021-12-05 11:22:08.932] [INFO] APIHandler - Api key file read from: "/opt/etherpad/etherpad-lite/AP> Dec 05 11:22:09 rockylinux node[13518]: [2021-12-05 11:22:09.000] [INFO] server - Installed plugins: Dec 05 11:22:09 rockylinux node[13518]: [2021-12-05 11:22:09.001] [INFO] console - Report bugs at https://github.com/ether/etherpad-lite/issu> Dec 05 11:22:09 rockylinux node[13518]: [2021-12-05 11:22:09.002] [INFO] console - Your Etherpad version is 1.8.16 (142a47c) ``` ## Step 5 – Configure Nginx as a Reverse Proxy for Etherpad Next, you will need to install and configure Nginx as a reverse proxy for Etherpad. First, install Nginx with the following command: ``` dnf install nginx -y ``` Once Nginx is installed, start and enable the Nginx service using the command below: ``` systemctl start nginx systemctl enable nginx ``` Next, create an Nginx virtual host configuration file: ``` nano /etc/nginx/conf.d/etherpad.conf ``` Add the following configuration: ``` server { listen 80; server_name etherpad.example.com; access_log /var/log/nginx/etherpad.access.log; error_log /var/log/nginx/etherpad.error.log; location / { rewrite ^/$ / break; rewrite ^/locales/(.*) /locales/$1 break; rewrite ^/locales.json /locales.json break; rewrite ^/admin(.*) /admin/$1 break; rewrite ^/p/(.*) /p/$1 break; rewrite ^/static/(.*) /static/$1 break; rewrite ^/pluginfw/(.*) /pluginfw/$1 break; rewrite ^/javascripts/(.*) /javascripts/$1 break; rewrite ^/socket.io/(.*) /socket.io/$1 break; rewrite ^/ep/(.*) /ep/$1 break; rewrite ^/minified/(.*) /minified/$1 break; rewrite ^/api/(.*) /api/$1 break; rewrite ^/ro/(.*) /ro/$1 break; rewrite ^/error/(.*) /error/$1 break; rewrite ^/jserror(.*) /jserror$1 break; rewrite ^/redirect(.*) /redirect$1 break; rewrite /favicon.ico /favicon.ico break; rewrite /robots.txt /robots.txt break; rewrite /(.*) /p/$1; proxy_pass http://127.0.0.1:9001; proxy_buffering off; proxy_set_header Host $host; proxy_pass_header Server; # proxy headers proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $remote_addr; proxy_set_header X-Forwarded-Proto $scheme; proxy_http_version 1.1; } } ``` Save and close the file, then edit the **nginx.conf** file and define hash_bucket size: ``` nano /etc/nginx/nginx.conf ``` Add the following line below the line **http {**: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then verify Nginx for any syntax errors: ``` nginx -t ``` ``` You should see the following output: ``` ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart Nginx to apply the configuration changes: ``` systemctl restart nginx ``` ## Step 6 – Access Etherpad Web Interface Now, open your favorite web browser and access the Etherpad web interface using the URL **http://etherpad.example.com**. You should see the following page: ![Etherpad Login](https://www.atlantic.net/wp-content/uploads/2021/12/p1-2-1024x539.png) Provide your pad name and click on the **OK** button. You should see the following page: ![Etherpad Dashboard](https://www.atlantic.net/wp-content/uploads/2021/12/p2-1-1024x530.png) ## Conclusion Congratulations! You have successfully installed Etherpad with Nginx as a reverse proxy on Rocky Linux 8. You can now use Etherpad to manage your content easily from the central location. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Apache Maven on Debian > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-maven-on-debian/ | Published: 2022-01-05 | Updated: 2025-09-05 | Author: Hitesh Jethva Apache Maven is an open-source automation tool that allows you to automate and simplify software development processes. It is also known as a build management system and is used to create and manage projects written in C#, Ruby, Scala, and other programming languages. It is used by many developers to manage all stages of the software development lifecycle. In this post, we will show you how to install Apache Maven on Debian 12.[jumpbox] ## Step 1 – Install Java Apache Maven is a Java-based application, so Java must be installed on your server. If not installed, you can install it by running the following command: ``` apt-get install default-jdk -y ``` After the successful installation, verify the Java installation using the command below: ``` java -version ``` You should see the Java version in the following output: ``` openjdk 17.0.16 2025-07-15 OpenJDK Runtime Environment (build 17.0.16+8-Debian-1deb12u1) OpenJDK 64-Bit Server VM (build 17.0.16+8-Debian-1deb12u1, mixed mode, sharing) ``` ## Step 2 – Install Apache Maven First, run the wget command to download the latest version of Apache Maven: ``` wget https://dlcdn.apache.org/maven/maven-3/3.9.11/binaries/apache-maven-3.9.11-bin.tar.gz ``` You will get the following output: ``` HTTP request sent, awaiting response... 200 OK Length: 9046177 (8.6M) [application/x-gzip] Saving to: ‘apache-maven-3.8.4-bin.tar.gz’ apache-maven-3.9.11-bin.tar.gz 100%[=================================================================>] 8.63M --.-KB/s in 0.1s ``` Once the download is completed, extract the downloaded file using the command below: ``` tar -xvzf apache-maven-3.9.11-bin.tar.gz ``` Next, move the extracted directory to /opt with the following command: ``` mv apache-maven-3.9.11 /opt/maven ``` ## Step 3 – Setup Environment Variables for Maven Next, you will need to set Java environment variables for Maven. You can set them by creating a file in the /etc/profile.d/ directory: ``` nano /etc/profile.d/maven.sh ``` Add the following lines based on your Java installation path: ``` export JAVA_HOME=/usr/lib/jvm/java-1.17.0-openjdk-amd64 export M2_HOME=/opt/maven export PATH=${M2_HOME}/bin:${PATH} ``` Save and close the file, then load the environment variable using the following command: ``` source /etc/profile.d/maven.sh ``` ## Step 4 – Verify Apache Maven Installation At this point, Apache Maven is installed on your system. You can now verify the Apache Maven installation using the command below: ``` mvn -version ``` You should see the following output: ``` Apache Maven 3.9.11 (3e54c93a704957b63ee3494413a2b544fd3d825b) Maven home: /opt/maven Java version: 17.0.16, vendor: Debian, runtime: /usr/lib/jvm/java-17-openjdk-amd64 Default locale: en_US, platform encoding: UTF-8 OS name: "linux", version: "6.1.0-32-amd64", arch: "amd64", family: "unix" ``` ## Step 5 – Create a Project with Maven Now, open your command-line terminal interface and run the following command to create your first Maven project: ``` mvn archetype:generate -DgroupId=com.example.app -DartifactId=testapp -DarchetypeArtifactId=maven-archetype-quickstart -DarchetypeVersion=1.4 -DinteractiveMode=false ``` You will get the following output: ``` [INFO] ---------------------------------------------------------------------------- [INFO] Using following parameters for creating project from Archetype: maven-archetype-quickstart:1.4 [INFO] ---------------------------------------------------------------------------- [INFO] Parameter: groupId, Value: com.example.app [INFO] Parameter: artifactId, Value: testapp [INFO] Parameter: version, Value: 1.0-SNAPSHOT [INFO] Parameter: package, Value: com.example.app [INFO] Parameter: packageInPathFormat, Value: com/example/app [INFO] Parameter: package, Value: com.example.app [INFO] Parameter: groupId, Value: com.example.app [INFO] Parameter: artifactId, Value: testapp [INFO] Parameter: version, Value: 1.0-SNAPSHOT [INFO] Project created from Archetype in dir: /root/testapp [INFO] ------------------------------------------------------------------------ [INFO] BUILD SUCCESS [INFO] ------------------------------------------------------------------------ [INFO] Total time: 21.503 s [INFO] Finished at: 2025-09-05T04:01:38Z [INFO] ------------------------------------------------------------------------ ``` Next, navigate to your project directory and compile the application using the command below: ``` cd testapp mvn package ``` You will get the following output: ``` [INFO] Building jar: /root/testapp/target/testapp-1.0-SNAPSHOT.jar [INFO] ------------------------------------------------------------------------ [INFO] BUILD SUCCESS [INFO] ------------------------------------------------------------------------ [INFO] Total time: 19.623 s [INFO] Finished at: 2025-09-05T04:02:22Z [INFO] ------------------------------------------------------------------------ ``` Now, run the following command to test your Jar file: ``` java -cp target/testapp-1.0-SNAPSHOT.jar com.example.app.App ``` You should see the following output: ``` Hello World! ``` ## Conclusion Congratulations! You have successfully installed Apache Maven on Debian 12. You can now use Apache Maven in your development environment to speed up your application development process. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install a Multi-Node Kubernetes Cluster on Ubuntu > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-set-up-three-node-kubernetes-cluster-on-ubuntu/ | Published: 2022-01-06 | Updated: 2025-01-07 | Author: Hitesh Jethva Kubernetes is an open-source system originally designed by Google for deploying, managing, scaling, and automating containerized applications. The open-source platform works with various containers and creates a framework to run these containers in clusters with images built via Docker. Also known as K8s, the system handles application failovers, stores and manages sensitive information, supports load balancing, and more. Nowadays, many businesses are turning to Kubernetes to solve container orchestration needs. At present, many services are delivered over the network using exposed APIs and distribution systems daily. Thus, the systems must be highly reliable, scalable, and must not face downtime. Kubernetes provides relevant services covering all these features to help deploy cloud-native applications anywhere. Kubernetes has become one of the best and fast-growing solutions for development. Let‘s discuss some of the essential benefits of using container orchestration platforms like Kubernetes for deployment, management, and scaling. ## Benefits of Kubernetes ### Highly Portable and Flexible No matter how complex your needs, whether you require local testing or running a global enterprise, Kubernetes’ flexible features help consistently deliver your applications. Also, Kubernetes can work virtually with any infrastructure, including the public cloud, a private cloud, hybrid, or an on-premises server. You can create portable deployments with Kubernetes and can run them consistently on different environments (development, staging, and production). Other orchestrators lack this feature. Kubernetes is a trusted open-source that helps effortlessly move workloads to your destined location. ### Using Kubernetes Can Improve Developer Productivity Proper implementation of Kubernetes into engineering workflows can be highly advantageous and lead to enhanced productivity. Kubernetes, with its huge ecosystem and ops friendly approach, allows developers to rely on tools and use them to reduce the negative impact and eliminate general complexity, as well as scale further and deploy faster (and at multiple times during a day). As a result, developers gain access to various solutions that cannot build themselves. Also, developers can now run distributed databases on Kubernetes and scale stateful applications with its advanced versions. ### Affordable Solution When compared with other orchestrators, Kubernetes can at times be a more affordable solution. It automatically helps scale resources up or down based on the requirement of a specific application, traffic, and load. As a result, when there is less demand for an application, the company or organization pays less. ### Self-Healing Service Enterprise-grade clusters are complex and require best-practice configuration to enable self-service Kubernetes features. Self-service Kubernetes clusters can restart if a container fails and can replace containers or reschedule on noticing the dead nodes. Also, they help kill containers not responding to a user-defined health check. ### Multi-Cloud Capability Nowadays, many businesses are switching to multi-cloud strategies, and there are various orchestrators available in the market that work with multi-cloud infrastructures. Kubernetes has the capability to host workloads running on both single and multiple clouds and is very flexible. Also, Kubernetes users can easily scale their environment. Apart from the above-listed benefits, Kubernetes also supports frequent container image build and deployment, high efficiency, and more. In this post, we will be going to explain how to install and deploy a three-node node Kubernetes Cluster on Ubuntu 20.04. ## Prerequisites - Three servers running an Ubuntu 20.04 operating system - Minimum 2 GB RAM and 2 Core CPUs on each node - A root password configured on each server We will use the following setup to demonstrate a three-node Kubernetes cluster: | **Kubernetes Node** | **IP Address** | **Operating System** | | --- | --- | --- | | Master-Node | 69.28.88.236 | Ubuntu 20.04 | | Worker1 | 104.219.55.103 | Ubuntu 20.04 | | Worker2 | 104.245.34.163 | Ubuntu 20.04 | ``` ``` ## Step 1 – Disable Swap and Enable IP Forwarding Memory swapping causes performance and stability issues within Kubernetes, so it is recommended to disable Swap and enable IP forwarding on all nodes. First, verify whether Swap is enabled or not using the following command: ``` swapon --show ``` If Swap is enabled, you will get the following output: ``` NAME TYPE SIZE USED PRIO /swapfile file 472.5M 0B -2 ``` Next, run the following command to disable Swap: ``` swapoff -a ``` To disable Swap permanently, edit the**/etc/fstab** file and comment the line containing swapfile: ``` nano /etc/fstab ``` Comment or remove the following line: ``` #/swapfile none swap sw 0 0 ``` Next, edit the **/etc/sysctl.conf** file to enable the IP forwarding: ``` nano /etc/sysctl.conf ``` Un-comment the following line: ``` net.ipv4.ip_forward = 1 ``` Save and close the file, then run the following command to apply the configuration changes: ``` sysctl -p ``` #### Also Read [How to Install Docker on Ubuntu 20.04 LTS](https://www.atlantic.net/vps-hosting/how-to-install-docker-ubuntu-20-04-lts/) ## Step 2 – Install Docker CE Kubernetes relies on a Docker container, so you will need to install the Docker CE on all nodes. The latest version of the Docker CE is not included in the Ubuntu default repository, so you will need to add Docker’s official repository to APT. First, install the required dependencies to access Docker repositories over HTTPS: ``` apt-get install apt-transport-https ca-certificates curl software-properties-common -y ``` Next, run the **curl** command to download and add Docker’s GPG key: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add - ``` Next, add Docker’s official repository to the APT: ``` add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" ``` Once the repository is added, run the following command to install Docker CE: ``` apt-get install docker-ce -y ``` After the installation, verify the Docker installation using the following command: ``` docker --version ``` Sample output: ``` Docker version 20.10.10, build b485636 ``` ## Step 3 – Add Kubernetes Repository By default, the Kubernetes package is not included in the Ubuntu 20.04 default repository, so you will need to add the Kubernetes repository to all nodes. First, add the Kubernetes GPG key: ``` curl -s https://packages.cloud.google.com/apt/doc/apt-key.gpg | apt-key add ``` Next, add the Kubernetes repository to APT: ``` apt-add-repository "deb http://apt.kubernetes.io/ kubernetes-xenial main" ``` Once the repository is added, update the APT cache using the command below: ``` apt-get update -y ``` ## Step 4 – Install Kubernetes Components (Kubectl, kubelet and kubeadm) Kubernetes depends on three major components (Kubectl, kubelet and kubeadm) that make up a Kubernetes run time environment. All three components must be installed on each node. Let’s run the following command on all nodes to install all Kubernetes components: ``` apt-get install kubelet kubeadm kubectl -y ``` Next, you will need to update the cgroupdriver on all nodes. You can do it by creating the following file: ``` nano /etc/docker/daemon.json ``` Add the following lines: ``` { "exec-opts": ["native.cgroupdriver=systemd"], "log-driver": "json-file", "log-opts": { "max-size": "100m" }, "storage-driver": "overlay2" } ``` Save and close the file, then reload the systemd daemon and restart the Docker service with the following command: ``` systemctl daemon-reload systemctl restart docker systemctl enable docker ``` At this point, all Kubernetes components are installed. Now, you can proceed to the next step. ## Step 5 – Initialize Kubernetes Master Node The Kubernetes Master node is responsible for managing the state of the Kubernetes cluster. In this section, we will show you how to initialize the Kubernetes Master node. Run the kubeadm command-line tool to initialize the Kubernetes cluster. ``` kubeadm init --pod-network-cidr=10.244.0.0/16 ``` Once the Kubernetes cluster has been initialized successfully, you will get the following output: ``` Your Kubernetes control-plane has initialized successfully! To start using your cluster, you need to run the following as a regular user: mkdir -p $HOME/.kube sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config sudo chown $(id -u):$(id -g) $HOME/.kube/config Alternatively, if you are the root user, you can run: export KUBECONFIG=/etc/kubernetes/admin.conf You should now deploy a pod network to the cluster. Run "kubectl apply -f [podnetwork].yaml" with one of the options listed at: https://kubernetes.io/docs/concepts/cluster-administration/addons/ Then you can join any number of worker nodes by running the following on each as root: kubeadm join 69.28.84.197:6443 --token tx7by6.nae8saexoj2y3gqb \ --discovery-token-ca-cert-hash sha256:a506a51aa88791b456275b289bedc5d3316534ff67475fdbc7c2c64ace82652f ``` From the above output, copy or note down the kubeadm join full command. You will need to run this command on all worker nodes to join the Kubernetes cluster. If you are logged in as a regular user then run the following command to start using your cluster: ``` mkdir -p $HOME/.kube sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config sudo chown $(id -u):$(id -g) $HOME/.kube/config ``` If you are the root user, you can run the following command: ``` export KUBECONFIG=/etc/kubernetes/admin.conf ``` At this point, the Kubernetes cluster is initialized. You can now proceed to add a pod network. #### Also Read [How to Use chmod (Change Mode) Command in Linux](https://www.atlantic.net/vps-hosting/how-to-use-chmod-change-mode-command-in-linux/) ## Step 6 – Deploy a Pod Network The pod network is used for communication between all nodes within the Kubernetes cluster and is necessary for the Kubernetes cluster to function properly. In this section, we will add a Flannel pod network on the Kubernetes cluster. Flannel is a virtual network that attaches IP addresses to containers. Run the following command on the Master node to deploy a Flannel pod network. ``` kubectl apply -f https://raw.githubusercontent.com/coreos/flannel/master/Documentation/kube-flannel.yml kubectl apply -f https://raw.githubusercontent.com/coreos/flannel/master/Documentation/k8s-manifests/kube-flannel-rbac.yml ``` Next, wait for some time for the pods to be in running state. Then, run the following command to see the status of all pods: ``` kubectl get pods --all-namespaces ``` If everything is fine, you will get the following output: ``` NAMESPACE NAME READY STATUS RESTARTS AGE kube-system calico-kube-controllers-5d995d45d6-tfdk9 1/1 Running 0 66m kube-system calico-node-5v5ll 1/1 Running 0 66m kube-system calico-node-rws9b 1/1 Running 0 66m kube-system calico-node-tkc8p 1/1 Running 0 66m kube-system coredns-78fcd69978-7ggpg 1/1 Running 0 127m kube-system coredns-78fcd69978-wm7wq 1/1 Running 0 127m kube-system etcd-master 1/1 Running 0 127m kube-system kube-apiserver-master 1/1 Running 0 127m kube-system kube-controller-manager-master 1/1 Running 0 127m ``` ## Step 7 – Join Worker Nodes to the Kubernetes Cluster After the successful pod network initialization, the Kubernetes cluster is ready to join the worker nodes. In this section, we will show you how to add both worker nodes to the Kubernetes cluster. You can use the kubeadm join command on each worker node to join them to the Kubernetes cluster. ``` kubeadm join 69.28.88.236:6443 --token alfisa.guuc5t2f66cpqz8e --discovery-token-ca-cert-hash sha256:1db0bb5317ae1007c1f7774d5281d22b2189b239ffabecaedcd605613a9b10cd ``` Once the worker node is joined to the cluster, you will get the following output: ``` This node has joined the cluster: * Certificate signing request was sent to apiserver and a response was received. * The Kubelet was informed of the new secure connection details. Run kubectl get nodes on the control-plane to see this node join the cluster. ``` If you forget the Kubernetes Cluster joining command, you can retrieve it any time using the following command on the master node: ``` kubeadm token create --print-join-command ``` You will get the Kubernetes Cluster joining command in the following output: ``` kubeadm join 69.28.88.236:6443 --token alfisa.guuc5t2f66cpqz8e --discovery-token-ca-cert-hash sha256:1db0bb5317ae1007c1f7774d5281d22b2189b239ffabecaedcd605613a9b10cd ``` Next, go to the master node and run the following command to verify that both worker nodes have joined the cluster: ``` kubectl get nodes ``` If everything is set up correctly, you will get the following output: ``` NAME STATUS ROLES AGE VERSION master Ready control-plane,master 18m v1.22.3 worker1 Ready 101s v1.22.3 worker2 Ready 2m1s v1.22.3 ``` You can also get the cluster information using the following command: ``` kubectl cluster-info ``` You will get the following output: ``` Kubernetes control plane is running at https://69.28.88.236:6443 CoreDNS is running at https://69.28.88.236:6443/api/v1/namespaces/kube-system/services/kube-dns:dns/proxy To further debug and diagnose cluster problems, use 'kubectl cluster-info dump'. At this point, the Kubernetes cluster is deployed and running fine. You can now proceed to the next step. ``` ## Step 8 – Verify the Kubernetes Cluster After setting up the Kubernetes cluster, you can deploy any containerized application to your cluster. In this section, we will deploy an Nginx service on the cluster and see how it works. To test the Kubernetes cluster, we will use the Nginx image and create a deployment called nginx-web: ``` kubectl create deployment nginx-web --image=nginx ``` Wait for some time, then run the following command to verify the status of deployment: ``` kubectl get deployments.apps ``` If the deployment is in a ready state, you will get the following output: ``` NAME READY UP-TO-DATE AVAILABLE AGE nginx-web 1/1 1 1 6s ``` Next, scale the Nginx deployment with 4 replicas using the following command: ``` kubectl scale --replicas=4 deployment nginx-web ``` Wait for some time, then run the following command to verify the status of Nginx replicas: ``` kubectl get deployments.apps nginx-web ``` You will get the following output: ``` NAME READY UP-TO-DATE AVAILABLE AGE nginx-web 4/4 4 4 40m ``` To see the detailed information of your deployment, run: ``` kubectl describe deployments.apps nginx-web ``` Sample output: ``` Name: nginx-web Namespace: default CreationTimestamp: Thu, 06 Jan 2022 05:49:41 +0000 Labels: app=nginx-web Annotations: deployment.kubernetes.io/revision: 1 Selector: app=nginx-web Replicas: 4 desired | 4 updated | 4 total | 4 available | 0 unavailable StrategyType: RollingUpdate MinReadySeconds: 0 RollingUpdateStrategy: 25% max unavailable, 25% max surge Pod Template: Labels: app=nginx-web Containers: nginx: Image: nginx Port: Host Port: Environment: Mounts: Volumes: Conditions: Type Status Reason ---- ------ ------ Progressing True NewReplicaSetAvailable Available True MinimumReplicasAvailable OldReplicaSets: NewReplicaSet: nginx-web-5855c9859f (4/4 replicas created) Events: Type Reason Age From Message ---- ------ ---- ---- ------- Normal ScalingReplicaSet 52s deployment-controller Scaled up replica set nginx-web-5855c9859f to 1 Normal ScalingReplicaSet 30s deployment-controller Scaled up replica set nginx-web-5855c9859f to 4 ``` As you can see, the Nginx deployment has been scaled up successfully. Now, let’s create another pod named http-web and expose it via http-service with port 80 and NodePort as a type. First, create a pod using the command below: ``` kubectl run http-web --image=httpd --port=80 ``` Next, run the following command to expose the above pod on port 80: ``` kubectl expose pod http-web --name=http-service --port=80 --type=NodePort ``` Wait for some time to bring up the pod then run the following command to check the status of the http-service: ``` kubectl get service http-service ``` You will get the following output: ``` NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE http-service NodePort 10.109.210.63 80:31415/TCP 8s ``` To get the detailed information of the service, run: ``` kubectl describe service http-service ``` You will get the following output: ``` Name: http-service Namespace: default Labels: run=http-web Annotations: Selector: run=http-web Type: NodePort IP Family Policy: SingleStack IP Families: IPv4 IP: 10.109.210.63 IPs: 10.109.210.63 Port: 80/TCP TargetPort: 80/TCP NodePort: 31415/TCP Endpoints: 10.244.1.4:80 Session Affinity: None External Traffic Policy: Cluster Events: Next, run the following command to retrieve the IP address and the node on which the http-web pod is deployed: ``` ``` kubectl get pods http-web -o wide ``` You will get all information in the following output: ``` NAME READY STATUS RESTARTS AGE IP NODE NOMINATED NODE READINESS GATES http-web 1/1 Running 0 62s 10.244.1.4 worker1 ``` As you can see, the http-web is deployed on the worker2 node and their IP address is **10.244.1.4**. You can now use the curl command to verify the webserver using port 80: ``` curl http://10.244.1.4:80 ``` If everything is set up correctly, you will get the following output: ```

It works!

``` ## Conclusion In this guide, we explained how to install and deploy a three-node Kubernetes cluster on Ubuntu 20.04 server. You can now add more worker nodes to scale the cluster if necessary. For more information, read the [Kubernetes](https://kubernetes.io/docs/tutorials/kubernetes-basics) documentation. Try to deploy Kubernetes cluster today on your [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install GoAccess Web Log Analyzer on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-goaccess-web-log-analyzer-on-rocky-linux-10/ | Published: 2022-01-07 | Updated: 2025-10-17 | Author: Hitesh Jethva GoAccess is a free, open-source, lightweight log analyzer written in C language. It can read and analyze log files of Apache, Nginx, CloudFront, Caddy, and more. It uses the ncurses library for its CLI interface. It is an interactive and real-time web server log analyzer that helps you to analyze and view web server logs quickly. **Features** - Display general Statistics, and bandwidth - Support for HTTP/2 and IPv6 - Display metrics per virtual host - Support for large datasets + data persistence - Display top visitors, referring sites, and URLs In this post, we will show you how to install GoAccess Web Log Analyzer on Rocky Linux 10. ## Step 1 – Install Required Packages First, you will need to install the required tools on your server. You can install all of them with the following command: ``` dnf update -y dnf install httpd ncurses-devel libmaxminddb-devel openssl-devel dnf groupinstall 'Development Tools' ``` Once all the packages are installed, start and enable the Apache service using the following command: ``` systemctl start httpd systemctl enable httpd ``` Also Read [How to Install Apache on Ubuntu 20.04](https://www.atlantic.net/vps-hosting/how-to-install-apache-ubuntu-20-04/) ## Step 2 – Install GoAccess on Rocky Linux 10 By default, GoAccess is not included in the Rocky Linux default repo, so you will need to compile it from the source. First, download the latest version of GoAccess with the [wget](https://www.atlantic.net/dedicated-server-hosting/how-to-download-file-using-wget-in-linux/) command: ``` wget https://tar.goaccess.io/goaccess-1.9.4.tar.gz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar -xvzf goaccess-1.9.4.tar.gz ``` Next, change the directory to the extracted directory and compile it using the following command: ``` cd goaccess-1.9.4 autoreconf -fi ./configure --enable-utf8 --with-openssl make make install ``` Once the installation is complete, verify the GoAccess version with the following command: ``` goaccess --version ``` You will get the following output: ``` GoAccess - 1.9.4. For more details visit: https://goaccess.io/ Copyright (C) 2009-2024 by Gerardo Orellana Build configure arguments: --enable-utf8 --with-openssl ``` ## Step 3 – Configure GoAccess The GoAccess main configuration file is located at **/usr/local/etc/goaccess/goaccess.conf**. Most of the options are commented out, so you will need to edit the file and enable the required options. ``` nano /usr/local/etc/goaccess/goaccess.conf ``` Change the following lines to enable and disable some recommended options: ``` time-format %H:%M:%S date-format %d/%b/%Y #ignore-panel REFERRERS log-format COMBINED ``` Save and close the file when you are finished. ## Step 4 – Run GoAccess First, we will run the GoAccess by specifying the Apache log file. The Apache log files keep a record of all incoming HTTP traffic. You can analyze and monitor the Apache logs using the following command: ``` goaccess /var/log/httpd/access_log ``` You should see the following interface: ![GoAccess interface](https://www.atlantic.net/wp-content/uploads/2022/01/p1-2-1024x526.png) In the above interface, you should see the Apache logs including the following: - Unique visitors per day - Requested Files (URLs) - Static Requests - Not Found URLs (404s) - Visitor Hostnames and IPs - Operating Systems - Browsers - Time Distribution - Virtual Hosts ## Step 5 – Generate HTML Reports GoAccess also allows you to generate HTML reports which you can access online through the web browser. Run the following command to generate an HTML report: ``` goaccess /var/log/httpd/access_log -o /var/www/html/stats.html ``` Now, open your web browser and access the generated reports using the URL **http://your-server-ip/stats.html**. You should see the following dashboard: ![GoAccess report](https://www.atlantic.net/wp-content/uploads/2022/01/p2-2-1024x535.png) Now, go back to your terminal and press the CTRL+C to close the GoAccess. GoAccess also allows you to generate a real-time HTML report. Run the following command to generate a real-time report and run GoAccess in the background: ``` goaccess /var/log/nginx/access.log -o /var/www/html/livereport.html --real-time-html --daemonize ``` You can now access the GoAccess real-time report using the URL **http://your-server-ip/livereport.html**. You should see the following screen: ![GoAccess real-time report](https://www.atlantic.net/wp-content/uploads/2022/01/p3-1-1024x533.png) Now, go back to your terminal and kill the GoAccess process using the following command: ``` kill -9 `pidof goaccess` ``` ## Conclusion In this guide, we explained how to install and configure GoAccess Log Analyzer on Rocky Linux 10. We also explained how to monitor Apache web server logs in real-time through the web browser. Try GoAccess on [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure RabbitMQ Server on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-rabbitmq-server-on-rocky-linux-10/ | Published: 2022-01-08 | Updated: 2025-10-17 | Author: Hitesh Jethva RabbitMQ is a free and open-source message broker software solution designed for applications that need to support legacy protocols, such as STOMP and MQTT. It is written in Erlang and can be used in implementing AMQP on modern operating systems. RabbitMQ receives messages from publishers and routes them to consumers. It provides your application with a common platform to send and receive messages. Currently, RabbitMQ is used worldwide by both small startups and large organizations. In this post, we will show you how to install the RabbitMQ server on Rocky Linux 10. ## Step 1 – Install Required Repositories Before starting, you will need to install EPLE, Erlang, and RabbitMQ repositories to your server. First, install the EPEL repository using the commands given below: ``` dnf update -y dnf install epel-release curl -y ``` Next, import the RabbitMQ GPG keys. ``` rpm --import https://github.com/rabbitmq/signing-keys/releases/download/3.0/rabbitmq-release-signing-key.asc rpm --import https://github.com/rabbitmq/signing-keys/releases/download/3.0/cloudsmith.rabbitmq-erlang.E495BB49CC4BBE5B.key rpm --import https://github.com/rabbitmq/signing-keys/releases/download/3.0/cloudsmith.rabbitmq-server.9F4587F226208342.key ``` Next, create a repo for RabbitMQ. ``` nano /etc/yum.repos.d/rabbitmq.repo ``` Add the following lines. ``` [rabbitmq_server] name=RabbitMQ Repository baseurl=https://packagecloud.io/rabbitmq/rabbitmq-server/el/9/\$basearch enabled=1 gpgcheck=1 gpgkey=https://packagecloud.io/rabbitmq/rabbitmq-server/gpgkey [rabbitmq_erlang] name=RabbitMQ Erlang Repository baseurl=https://packagecloud.io/rabbitmq/erlang/el/9/\$basearch enabled=1 gpgcheck=1 gpgkey=https://packagecloud.io/rabbitmq/erlang/gpgkey ``` Also Read [How to Install Anaconda Python on Rocky Linux 8](https://www.atlantic.net/vps-hosting/how-to-install-anaconda-python-on-rocky-linux-8/) ## Step 2 – Install Erlang and RabbitMQ Now, install both Erlang and RabbitMQ. ``` dnf install erlang rabbitmq-server -y ``` Once the RabbitMQ server is installed, start and enable the RabbitMQ service with the following command: ``` systemctl start rabbitmq-server systemctl enable rabbitmq-server ``` Now, check the status of RabbitMQ. ``` systemctl status rabbitmq-server ``` Output. ``` ● rabbitmq-server.service - RabbitMQ broker Loaded: loaded (/usr/lib/systemd/system/rabbitmq-server.service; disabled; preset: disabled) Active: active (running) since Fri 2025-10-17 03:33:15 EDT; 6s ago Invocation: b6ffb30996df42d08ebbf11fdbac52cd Main PID: 18149 (beam.smp) Tasks: 28 (limit: 24809) Memory: 110.5M (peak: 117.5M) CPU: 3.479s CGroup: /system.slice/rabbitmq-server.service ├─18149 /usr/lib64/erlang/erts-14.2.5.4/bin/beam.smp -W w -MBas ageffcbf -MHas ageffcbf -MBlmbcs 512 -MHlmbcs 512 -MMmcs 30 -pc unicode -P 1048576 -t 5000000 -stbt db -zd> ├─18162 erl_child_setup 32768 ├─18185 sh -s disksup ├─18187 /usr/lib64/erlang/lib/os_mon-2.9.1/priv/bin/memsup ├─18188 /usr/lib64/erlang/lib/os_mon-2.9.1/priv/bin/cpu_sup ├─18189 /usr/lib64/erlang/erts-14.2.5.4/bin/inet_gethost 4 ├─18190 /usr/lib64/erlang/erts-14.2.5.4/bin/inet_gethost 4 ├─18199 /usr/lib64/erlang/erts-14.2.5.4/bin/epmd -daemon └─18224 /bin/sh -s rabbit_disk_monitor ``` Also Read [How to Install PostgreSQL 14 in Rocky Linux 8](https://www.atlantic.net/dedicated-server-hosting/how-to-install-postgresql-14-in-rocky-linux/) ## Step 3 – Configure RabbitMQ By default, RabbitMQ uses a guest user to connect from localhost. It is recommended to create an admin user and set a password to secure RabbitMQ. To create an admin user, run the following command: ``` rabbitmqctl add_user admin ``` Sample output: ``` Adding user "admin" ... Password: ``` Next, assign administrator permissions to the admin user with the following command: ``` rabbitmqctl set_user_tags admin administrator ``` You can now verify the created user using the following command: ``` rabbitmqctl list_users ``` You will get the following output: ``` Listing users ... user tags admin [administrator] guest [administrator] ``` To add a new vhost, run the following command: ``` rabbitmqctl add_vhost /new_vhost ``` To list all vhosts, run the following command: ``` rabbitmqctl list_vhosts ``` You will get the following output: ``` Listing vhosts ... name / /new_vhost ``` Next, provide admin user permissions on vhosts using the following command: ``` rabbitmqctl set_permissions -p /new_vhost admin ".*" ".*" ".*" ``` ## Step 4 – Enable RabbitMQ Web UI RabbitMQ provides a web interface to manage the RabbitMQ. However, it is disabled by default. To enable the RabbitMQ web UI, run the following command: ``` rabbitmq-plugins enable rabbitmq_management ``` You will get the following output: ``` Enabling plugins on node rabbit@rockylinux: rabbitmq_management The following plugins have been configured: rabbitmq_management rabbitmq_management_agent rabbitmq_web_dispatch Applying plugin configuration to rabbit@rockylinux... The following plugins have been enabled: rabbitmq_management rabbitmq_management_agent rabbitmq_web_dispatch started 3 plugins. ``` Next, restart the RabbitMQ service to apply the changes. ``` systemctl restart rabbitmq-server ``` You can check the status of RabbitMQ using the following command: ``` rabbitmqctl status ``` You will get the following output: ``` Status of node rabbit@rockylinux ... Runtime OS PID: 19057 OS: Linux Uptime (seconds): 12 Is under maintenance?: false RabbitMQ version: 3.9.11 Node name: rabbit@rockylinux Erlang configuration: Erlang/OTP 24 [erts-12.2] [source] [64-bit] [smp:1:1] [ds:1:1:10] [async-threads:1] [jit] Erlang processes: 363 used, 1048576 limit Scheduler run queue: 1 Cluster heartbeat timeout (net_ticktime): 60 Plugins Enabled plugin file: /etc/rabbitmq/enabled_plugins Enabled plugins: ``` ## Step 5 – Access RabbitMQ Web UI At this point, the RabbitMQ web UI is started and listens on port **15672**. You can check it using the following command: ``` ss -antpl | grep 15672 ``` You will get the following output: ``` LISTEN 0 128 0.0.0.0:15672 0.0.0.0:* users:(("beam.smp",pid=19057,fd=35)) ``` Now, open your web browser and access the RabbitMQ web UI using the URL **http://your-server-ip:15672**. You should see the RabbitMQ login page: ![RabbitMQ login page](https://www.atlantic.net/wp-content/uploads/2022/01/p1-1024x368.png) Provide your admin username, password and click on the **Login** button. You should see the RabbitMQ dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2022/01/r1.png) ## Conclusion In this post, we explained how to install and configure the RabbitMQ server on Rocky Linux 10. We also explained how to enable the RabbitMQ web UI and set an admin password. Hopefully, this guide will help you to install the RabbitMQ server in the production environment. Try it on [dedicated hosts](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) from Atlantic.Net! --- # How to Install Teampass Password Manager on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-teampass-password-manager-on-rocky-linux-10/ | Published: 2022-01-09 | Updated: 2025-10-17 | Author: Hitesh Jethva Teampass is a free, open-source, self-hosted password manager used for managing passwords in a collaborative way. It offers a large set of features that allow you to manage all your passwords in an organized way. You can define access rights on users to allow them to access only a given set of data. Teampass uses MariaDB/MySQL as a database backend to store the password securely. In this post, we will explain how to install the Teampass password manager on Rocky Linux 10. ## Step 1 – Install Apache, MariaDB, and PHP First, you will need to install the Apache web server, MariaDB database server, PHP, and other PHP extensions to your server. You can run the following command to install all of them. ``` dnf install httpd mariadb-server php php-cli php-mysqli php-pear php-json php-devel php-curl php-mbstring php-bcmath php-common php-gd php-xml git wget -y ``` Once all the packages are installed, edit the php.ini file and change some recommended settings: ``` nano /etc/php.ini ``` Change the following values: ``` memory_limit = 256M upload_max_filesize = 100M max_execution_time = 360 date.timezone = Asia/Kolkata ``` Save and close the file, then start and enable the Apache and MariaDB services using the following command: ``` systemctl start httpd mariadb systemctl enable httpd mariadb ``` **Also Read** [Install a LAMP Stack on Rocky Linux 8](https://www.atlantic.net/vps-hosting/install-lamp-stack-on-rocky-linux-8/) ## Step 2 – Create a Database for Teampass Next, you will need to create a database and user for Teampass. To do so, first log in to the MariaDB shell with the following command: ``` mysql ``` Once you are logged in, create a database and user with the following command: ``` create database teampassdb; grant all privileges on teampassdb.* to teampassuser@localhost identified by "securepassword"; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` flush privileges; exit; ``` **Also Read** [How to Install SysPass Password Manager on Oracle Linux 8](https://www.atlantic.net/vps-hosting/how-to-install-syspass-password-manager-on-oracle-linux-8/) ## Step 3 – Install Teampass First, change the directory to Apache default root directory and download the latest version of Teampass from the Git repository: ``` cd /var/www/html git clone https://github.com/nilsteampassnet/TeamPass.git ``` Next, set proper permissions and ownership to the Teampass directory: ``` chmod -R 775 /var/www/html/TeamPass chown -R apache:apache /var/www/html/TeamPass ``` ## Step 4 – Create an Apache Virtual Host for Teampass Next, you will need to create an Apache virtual host configuration file to host Teampass on the internet. ``` nano /etc/httpd/conf.d/teampass.conf ``` Add the following lines: ``` ServerAdmin admin@example.com DocumentRoot /var/www/html/TeamPass ServerName teampass.example.com Options FollowSymlinks AllowOverride All Require all granted ErrorLog /var/log/httpd/teampass_error.log CustomLog /var/log/httpd/teampass_access.log combined ``` Save and close the file, then restart the Apache service to apply the configuration changes: ``` systemctl restart httpd ``` At this point, the Apache web server is configured to serve Teampass. You can now proceed to the Teampass web interface. ## Step 5 – Access Teampass Web Interface Now, open your web browser and access the Teampass web interface using the URL **http://teampass.example.com**. You should see the Teampass welcome page: ![](https://www.atlantic.net/wp-content/uploads/2022/01/t1.png) Click on the **Continue**. You should see the server check page: ![](https://www.atlantic.net/wp-content/uploads/2022/01/t2.png) Click on the **Start** then **Continue** button. You should see the Database information page: ![](https://www.atlantic.net/wp-content/uploads/2022/01/t3.png) Click on the **Start** then **Continue** button. You should see the admin creation page: ![](https://www.atlantic.net/wp-content/uploads/2022/01/t4.png) Click on the **Start** then **Continue** button. You should see the database population page: ![](https://www.atlantic.net/wp-content/uploads/2022/01/t5.png) Click on the **Start** then **Continue** button. You should see the Finalization page: ![](https://www.atlantic.net/wp-content/uploads/2022/01/t6.png) Click on the **Start** then **Continue** button. Once the installation is complete, you should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2022/01/t7.png) Click on the **Move to home page**. You should see the Teampass login page: ![](https://www.atlantic.net/wp-content/uploads/2022/01/t8.png) Provide your admin username, password and click on the **Log In** button. You should see the Teampass dashboard. ![](https://www.atlantic.net/wp-content/uploads/2022/01/t9.png) ## Conclusion In the above guide, we explained how to install the Teampass password manager on Rocky Linux 10. You can now implement Teampass in your organization to store all credentials and share them among the team members. Try installing Teampass password manager on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Set Up Pritunl VPN Server on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-set-up-pritunl-vpn-server-on-rocky-linux-10/ | Published: 2022-01-10 | Updated: 2025-10-17 | Author: Hitesh Jethva Pritunl is a free, open-source, web-based VPN server that virtualizes your private networks across datacenters and provides simple remote access in minutes. It supports all OpenVPN clients and has official clients for several devices and platforms. Pritunl allows you to choose between connecting with OpenVPN and WireGuard. All networking features are available with the WireGuard protocol. Pritunl provides a customizable plugin system that allows you to extend your VPN’s functionality. In this post, we will show you how to install Pritunl VPN Server on Rocky Linux 10. ## Step 1 – Increase Open File Limit Before starting, you will need to increase the open file limit on the server to prevent any connection issues in case of a high load. You can do it by editing limits.conf file: ``` nano /etc/security/limits.conf ``` Add the following lines: ``` * hard nofile 64000 * soft nofile 64000 root hard nofile 64000 root soft nofile 64000 ``` Save and close the file when you are finished. Also Read [How to Install and Configure OpenVPN Server on Ubuntu 20.04](https://www.atlantic.net/vps-hosting/how-to-install-and-configure-openvpn-server-on-ubuntu-20-04/) ## Step 2 – Install MongoDB Server Pritunl uses MongoDB as a database backend, so you will need to install MongoDB on your server. First, create a MongoDB repo using the following command: ``` nano /etc/yum.repos.d/mongodb-org-7.0.repo ``` Add the following lines: ``` [mongodb-org-7.0] name=MongoDB Repository baseurl=https://repo.mongodb.org/yum/redhat/9/mongodb-org/7.0/x86_64/ enabled=1 gpgcheck=0 repo_gpgcheck=0 ``` Save and close the file, then install MongoDB using the following command: ``` dnf install mongodb-org -y ``` Once MongoDB is installed, start and enable the MongoDB service using the command given below: ``` systemctl enable mongod --now ``` Also Read [How to Install and Secure MongoDB on Oracle Linux 8](https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-secure-mongodb-on-oracle-linux-8/) ## Step 3 – Install Pritunl Server on Rocky Linux 10 By default, the Pritunl server package is not included in the Rocky Linux 10, so you will need to create a Pritunl repo to your system. ``` nano /etc/yum.repos.d/pritunl.repo ``` Add the following lines: ``` [pritunl] name=Pritunl Repository baseurl=https://repo.pritunl.com/stable/yum/oraclelinux/9/ gpgcheck=0 enabled=1 ``` Save and close the file, then install the EPEL repo with the following command: ``` dnf install epel-release ``` Finally, install the Pritunl server using the following command: ``` dnf install pritunl -y ``` Once the Pritunl server is installed, verify the Pritunl version using the following command: ``` pritunl version ``` You will get the following output: ``` pritunl v1.32.4400.99 ``` ## Step 4 – Manage Pritunl Service You can now start and enable the Pritunl service by running the following command: ``` systemctl enable pritunl --now ``` You can also check the status of the Pritunl service using the following command: ``` systemctl status pritunl ``` You will get the following output: ``` ● pritunl.service - Pritunl Daemon Loaded: loaded (/etc/systemd/system/pritunl.service; enabled; preset: disabled) Active: active (running) since Fri 2025-10-17 02:57:34 EDT; 1min 5s ago Invocation: a5c4d641608e464f8fab9d8dadfff512 Main PID: 15159 (pritunl) Tasks: 19 (limit: 24809) Memory: 121M (peak: 123M) CPU: 4.022s CGroup: /system.slice/pritunl.service ├─15159 /usr/lib/pritunl/usr/bin/python3 /usr/lib/pritunl/usr/bin/pritunl start └─15181 pritunl-web ``` ## Step 5 – Access Pritunl Web Interface At this point, Pritunl is started and running. You can now access it using the URL **https://your-server-ip**. You will get the Pritunl database setup page: ![Pritunl setup page](https://www.atlantic.net/wp-content/uploads/2022/01/p1-3-1024x610.png) Now, go back to the terminal and generate the database setup key using the following command: ``` pritunl setup-key ``` Sample output: ``` 2d9c4f65ebba4479a5147d1a18feccf4 ``` Go back to the Pritunl web interface, paste the setup key, and click on the **Save** button. You should see the Pritunl login page: ![Pritunl login page](https://www.atlantic.net/wp-content/uploads/2022/01/p3-2.png) Go back to the terminal and generate login credentials with the following command: ``` pritunl default-password ``` You will get the following output: ``` [undefined][2021-12-29 11:55:53,139][INFO] Getting default administrator password Administrator default password: username: "pritunl" password: "UUgJaZt3ice6" ``` Go back to the Pritunl web interface, paste the username and password, and click on the **Sign in** button. You should see the Pritunl initial setup page: ![Pritunl initial setup page](https://www.atlantic.net/wp-content/uploads/2022/01/p5-1-1024x480.png) Provide your user name, password, IP address, and port, and click on the **Save** button. You should see the Pritunl dashboard on the following page: ![Pritunl dashboard page](https://www.atlantic.net/wp-content/uploads/2022/01/p6-1-1024x327.png) ## Step 6 – Add Users in Pritunl Next, you will need to add a user to the Pritunl server. First, click on the **Add** **Organization** button to add the organization. You should see the following page: ![Pritunl add organization page](https://www.atlantic.net/wp-content/uploads/2022/01/p8-1-1024x299.png) Provide your organization name and click on the **Add** button. You should see the following page: ![Pritunl organization added page](https://www.atlantic.net/wp-content/uploads/2022/01/p10-1-1024x312.png) Now, click on the **Add User** button to add a user. You should see the following page: ![Pritunl add user page](https://www.atlantic.net/wp-content/uploads/2022/01/p11.png) Provide your username, organization, and pin, and click on the **Add** button. Next, click on the **Add Server** in the server tab. You should see the following page: ![Pritunl add server page](https://www.atlantic.net/wp-content/uploads/2022/01/p12-1024x469.png) Provide your server name, port, protocol, DNS server, and Virtual Network, then click on the **Add** button. You should see the following page: ![Pritunl attach organization page](https://www.atlantic.net/wp-content/uploads/2022/01/p13-1024x542.png) Click on **Attach Organization**. You should see the following page: ![Pritunl attach organization](https://www.atlantic.net/wp-content/uploads/2022/01/p14.png) Select your organization and server and click on the **Attach** button. You should see the following page: ![Pritunl organization attached](https://www.atlantic.net/wp-content/uploads/2022/01/p15-1024x528.png) Finally, click on the **Start Server** button to start the server. Once the server is started successfully, you should see the following screen: ![Pritunl start server](https://www.atlantic.net/wp-content/uploads/2022/01/p16-1024x523.png) ## Conclusion Congratulations! You have successfully installed and configured the Pritunl VPN server on Rocky Linux 10. You can now install the Pritunl client on the remote client machine and connect to the Pritunl VPN server. Try it on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install TaskBoard on Rocky Linux 8 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-taskboard-on-rocky-linux-8/ | Published: 2022-01-11 | Updated: 2023-11-17 | Author: Hitesh Jethva TaskBoard is an open-source application for managing and tracking tasks from a web-based interface. It allows you to create unlimited projects and boards to keep track of tasks to be done. TaskBoard is customizable and can be installed on any Linux distribution. It is a PHP-based and self-hosted application used by many organizations and teams around the world. **Features** - Free, open-source, and self-hosted - Simple and easy to install - Supports unlimited board and projects - Customizable - Provides a full history of all boards In this post, we will show you how to install TaskBoard on Rocky Linux 8. ## Step 1 – Install Apache and PHP First, install the Apache webserver package using the command below: ``` dnf update -y dnf install httpd -y ``` Once installed, start and enable the Apache service using the following command: ``` systemctl start httpd systemctl enable httpd ``` Next, install the PHP Remi repo package using the command below: ``` dnf install http://rpms.remirepo.net/enterprise/remi-release-8.rpm -y ``` Next, disable the default PHP repo and install the PHP Remi repo: ``` dnf module reset php dnf module install php:remi-7.4 -y ``` Finally, install PHP with all required extensions using the following command: ``` dnf install php php-cli php-common php-fpm php-curl php-gd php-mbstring php-process php-snmp php-xml php-zip php-memcached php-mysqlnd php-json php-mbstring php-pdo php-pdo-dblib php-xml curl unzip git -y ``` TaskBoard uses SQLite as a database backend, so you can install it using the following command: ``` dnf install sqlite -y ``` ## Step 2 – Install TaskBoard First, download the latest version of TaskBoard using the following command: ``` curl -s https://api.github.com/repos/kiswa/TaskBoard/releases/latest |grep browser_download_url | cut -d '"' -f 4 | wget -i - ``` Once the download is completed, unzip the downloaded file with the following command: ``` unzip TaskBoard_v*.zip -d /var/www/html/taskboard ``` Next, change the ownership and permissions of TaskBoard with the following command: ``` chown -R apache:apache /var/www/html/taskboard chmod -R 775 /var/www/html/taskboard ``` Next, edit the .htaccess file: ``` nano /var/www/html/taskboard/api/.htaccess ``` Comment out the following lines: ``` #php_value upload_max_filesize 80M #php_value post_max_size 100M #php_value file_uploads On #php_value memory_limit 256M ``` Save and close the file when you are finished. ## Step 3 – Create An Apache Virtual Host Configuration File Next, you will need to create a virtual host configuration file for TaskBoard. You can create it with the following command: ``` nano /etc/httpd/conf.d/taskboard.conf ``` Add the following lines: ``` ServerAdmin admin@example.com DocumentRoot "/var/www/html/taskboard" ServerName taskboard.example.com Options Indexes FollowSymLinks AllowOverride All Require all granted ErrorLog "/var/log/httpd/taskboard-error_log" CustomLog "/var/log/httpd/taskboard-access_log" combined ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 4 – Access TaskBoard Now, open your web browser and access the TaskBoard using the URL **http://taskboard.example.com**. You should see the TaskBoard login page: ![TaskBoard Login](https://www.atlantic.net/wp-content/uploads/2021/12/p1-1.png) Provide the admin username and password as admin/admin and click on the **Login** button. You should see the TaskBoard dashboard on the following screen: ![TaskBoard Dashboard](https://www.atlantic.net/wp-content/uploads/2021/12/p2-1024x407.png) ## Conclusion Congratulations! You have successfully installed TaskBoard on Rocky Linux 8. You can now start creating your Tasks and manage them from the web-based interface. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Adding an Additional Public IP on Ubuntu, Debian, CentOS, or Rocky Linux > URL: https://www.atlantic.net/vps-hosting/adding-an-additional-public-ip-on-ubuntu-debian-centos-or-rocky-linux/ | Published: 2022-01-28 | Updated: 2026-03-02 | Author: Richard Bailey ##### Verified and Tested 01/28/2022 ## Introduction This how-to will walk you through the process of adding an additional IP to your Ubuntu, Debian, CentOS, or Rocky Linux server. In order for an additional IP to work properly, it must be added to both the cloud interface and your server. ## Prerequisites – Root privileges – A reserved additional IP. You can find out how to [reserve an additional IP here](https://www.atlantic.net/tutorials/). ## Adding your Additional Public IP in the Cloud Control Panel We’ll start by logging in to the [Atlantic.Net Cloud control panel](https://cloud.atlantic.net/?page=userlogin). ![](https://www.atlantic.net/wp-content/uploads/2017/03/Cloud-Login-1.png)   Navigate to your ‘*Public IPs*‘ section. ![](https://www.atlantic.net/wp-content/uploads/2017/03/Public-IP-Assigned-2.png) We begin by clicking on “**Reserve IP**“.  A popup box will appear asking for the *IP Location* and *Count* of public IPs to add. For *IP Location*, select the same location as your Atlantic.Net CentOS server. We only want to add one IP address, so we will enter “**1**” for *Count.*  Now click “**Reserve Public IP**.” ![](https://www.atlantic.net/wp-content/uploads/2017/03/Reserving-a-Public-IP-1.png) We can now see a new IP address displayed under “*Public IPs*.” ![](https://www.atlantic.net/wp-content/uploads/2017/03/Public-IP-Reserved-2-1.png) **Click on the checkbox** next to the newly reserved public IP address, and choose to “**Assign IP**“.  *(Note: You can assign the IP to any of the servers in the same location that IP was reserved. For this tutorial, we will assume you want to assign this IP to a CentOS server.)* ![](https://www.atlantic.net/wp-content/uploads/2017/03/Assigning-a-Public-IP-3.png)   ![](https://www.atlantic.net/wp-content/uploads/2017/03/Assigning-a-Public-IP-2-2-3.png) Once the IP is assigned, it should look something like this: ![](https://www.atlantic.net/wp-content/uploads/2017/03/Public-IP-Assigned-2-1.png) Now we can move on to adding the IP to the actual server’s network interface. ## Add an Additional IP to Your Ubuntu Server To add this IP to your server’s network interface, you will need to edit your /etc/netplan/01-netcfg.yaml file, but first we should back it up in case of any mistakes. To do this, make sure you are one the root account on your server and use the following command: ``` cp /etc/netplan/01-netcfg.yaml /etc/netplan/01-netcfg.yaml.backup ``` Once copied, we can view and edit the file with nano: ``` nano /etc/netplan/01-netcfg.yaml ``` Once there, you should see something like this: ``` network: version: 2 renderer: networkd ethernets: eth0: addresses: - 208.117.86.35/24 gateway4: 208.117.86.1 nameservers: addresses: - 209.208.127.65 - 209.208.25.18 ``` We want to add our IP below the eth0 and name it eth1. It should look something like this: ``` network: version: 2 renderer: networkd ethernets: eth0: addresses: - 208.117.86.35/24 gateway4: 208.117.86.1 eth1: addresses: - 208.117.87.9/24 gateway4: 208.117.87.1 nameservers: addresses: - 209.208.127.65 - 209.208.25.18 ``` Save and close the file then run the following command to apply the changes: ``` netplan apply ``` You can now verify the newly assigned IP address with the following command: ``` ip addr ``` You should get the following output: ``` 1: lo: mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever inet6 ::1/128 scope host valid_lft forever preferred_lft forever 2: eth0: mtu 1500 qdisc fq_codel state UP group default qlen 1000 link/ether 00:00:d0:75:56:23 brd ff:ff:ff:ff:ff:ff inet 208.117.86.35/24 brd 208.117.86.255 scope global eth0 valid_lft forever preferred_lft forever inet6 fe80::200:d0ff:fe75:5623/64 scope link valid_lft forever preferred_lft forever 3: eth1: mtu 1500 qdisc fq_codel state UP group default qlen 1000 link/ether 00:00:0a:75:56:23 brd ff:ff:ff:ff:ff:ff inet 208.117.87.9/24 brd 208.117.87.255 scope global eth1 valid_lft forever preferred_lft forever inet6 fe80::200:aff:fe75:5623/64 scope link valid_lft forever preferred_lft forever ``` ## Add an Additional IP to Your Debian Server To add this IP to your server’s network interface, you will need to edit your /root/etc/network/interfaces file, but first we should back it up in case of any mistakes. To do this, make sure you are one the root account on your server and use the following command: ``` cp /etc/network/interfaces /etc/network/interfaces.backup ``` Once copied, we can view and edit the file with nano: ``` nano /etc/network/interfaces ``` Once there, you should see something like this: ``` auto lo iface lo inet loopback ``` ``` auto eth0 iface eth0 inet static hwaddress ether 00:00:45:1c:5e:d6 address 192.168.0.1 netmask 255.255.252.0 gateway 192.168.0.1 ``` ``` ``` ``` dns-nameservers 209.208.127.65 209.208.25.18 ``` We want to add our IP below the eth0 and name it eth1. It should look something like this: ``` auto eth0 iface eth0 inet static hwaddress ether 00:00:45:1c:5e:d6 address 192.168.0.25 netmask 255.255.252.0 gateway 192.168.0.1 ``` ``` ``` ``` auto eth1 iface eth1 inet static address 192.168.0.26 netmask 255.255.252.0 ``` Once you have this set, save and restart the network service to apply the changes: ``` systemctl restart networking ``` Once the service is restarted, your new IP will be set! ## Add an Additional IP to Your CentOS / Rocky Server To add this IP to your CentOS or Rocky Servers network interface, you will need to edit the network configuration using **nmtui**. From the command line, type **nmtui** to access the NetworkManager interface and select **edit a connection**. ![Connection](https://www.atlantic.net/wp-content/uploads/2017/03/Edit-a-Connection.png) Select the **ethernet** connection you wish to add an alias to. In nearly all circumstances, this will be **eth0**. ![Ethernet Alias](https://www.atlantic.net/wp-content/uploads/2017/03/Ethernet-Alias.png) On the **edit connection** tab, under IPv4 configuration Address, **navigate to the button**. ![Add Connection](https://www.atlantic.net/wp-content/uploads/2017/03/Add-Connection.png) Enter the **IP Address** you reserved in the previous section and select **OK**at the bottom of the display. ![Enter IP Address](https://www.atlantic.net/wp-content/uploads/2017/03/Enter-IP-Address.png) This will drop you back to the edit Ethernet page, navigate to the **** button. ![Navigate Back Button](https://www.atlantic.net/wp-content/uploads/2017/03/Navigate-Back-Button.png) This will create a network config file in /etc/sysconfig/network-scripts/ Type the following to see your config files: ``` ls -l /etc/sysconfig/network-scripts/ ``` ![Config File](https://www.atlantic.net/wp-content/uploads/2017/03/Config-File.png) If you view the config file, you will see multiple IP addresses. Type the following: ``` cat /etc/sysconfig/network-scripts/ifcfg-eth0 ``` ![View Config FIle](https://www.atlantic.net/wp-content/uploads/2017/03/View-Config-FIle.png) You can now test your connection by using putty to SSH to the new IP Address. --- # Windows Server 2022 Is Now Available on the Atlantic.Net Cloud > URL: https://www.atlantic.net/vps-hosting/windows-server-2022-is-now-available-on-the-atlantic-net-cloud/ | Published: 2022-01-28 | Updated: 2025-09-19 | Author: Alexander Wise The Atlantic.Net Cloud Platform (ACP) now supports Windows Server 2022. You can spin up a Windows Server 2022 instance right now at [https://cloud.atlantic.net](https://cloud.atlantic.net/?page=userlogin). The Atlantic.Net Cloud Platform is one of the very first cloud providers to make Windows Server 2022 generally available. With Atlantic.Net’s Cloud Servers, a customer can launch a Windows Server 2022 instance in under 30 seconds. Windows Server 2022 has undergone some major transformations compared with previous releases. Microsoft has focused on security and performance with this release. Windows Server 2022 has a clean, crisp, and familiar interface, but it’s what’s going on under the hood that excites the techies here at Atlantic.Net. ## A Security Defined Operating System Microsoft has reworked many of the security features in this latest version, making Windows Server 2022 the perfect choice for cloud workloads.  are several key security features: - Hypervisor-Based Code Integrity (HVCI) –  The HVCI service determines whether code executing in kernel mode is securely designed and trustworthy. - Kernel DMA Protection – This boot policy allows or disallows devices to perform Direct Memory Access operations. - System Guard – The System Guard hardens the instance against malware, focusing on preventing malicious code from running. - Virtualization-Based Security (VBS) –  VBS technology creates an abstract layer between computer processes and the underlying operating system. This new and enhanced technology is all about providing hardware-layer protection to help prevent illegal code from being executed. These updates create protection for shared resources that use CPU and memory directly. ## Key Windows Server 2022 Features Microsoft has introduced an enhanced and upgraded version of Windows Admin Center in Windows Server 2022. This new version will eventually replace the traditional server manager utility. The updated version offers a cloud-style control panel, giving the user granular control over every server setting. Big changes were made to Failover Cluster Manager, and lots of cloud-style tweaks, metrics, and system values are now available on a clean user interface. With the new Failover Cluster Manager, you can manage storage, devices, services, and scheduled tasks, as well as manage and configure users and groups. Network settings received an overhaul, too, making it much easier to find everything you need. Windows Server 2022 supports up to 48TB of physical server memory, and the defined vCPU max for VMs on Windows Server 2022 is 240 vCPUs for Gen2 VMs in Hyper-V. This makes Server 2022 the perfect choice for a [dedicated](https://www.atlantic.net/dedicated-server-hosting/) Hyper-V host. [Speak to the team](https://www.atlantic.net/about-us/corporate-contact/) today to enquire about this option. TLS 1.3 is natively supported in Windows Server 2022, and the popular Microsoft Storage Spaces has returned. Storage Spaces is very similar to RAID technology but allows software-defined storage solutions to be presented directly to Windows Server in a similar fashion to VMWare vSan. ## Windows Server 2022 on the Atlantic.Net Cloud Windows Server 2022, the latest Windows Server offering from Microsoft, along with Windows 2019, Windows Server 2016, and Windows 2012, are all available with Cloud Servers from Atlantic.Net. Atlantic.Net’s Windows Cloud Server Hosting plans start at only $0.0230647 per hour (or $15.50 per month), with usage calculated on a per hour basis. For a limited time, Atlantic.Net is offering all new clients a free-to-use Windows Server 2022 Cloud Server for one full year on the G3.2GB Cloud Server plan, which includes 3 TB of outbound data transfer. The Atlantic.Net Cloud Platform provides fault-tolerant, ultra-fast performance, and includes award-winning Cloud Servers, Secure Block Storage, one-click applications, DNS, [Dedicated Hosts](https://www.atlantic.net/dedicated-server-hosting/), private networking, RESTful API, data backup, a full suite of managed services, 24x7x365 expert U.S.-based support, and more. To view the latest cloud offerings and pricing, please visit: [VPS hosting](https://www.atlantic.net/vps-hosting/) --- # Top 10 Server Patching Software Solutions > URL: https://www.atlantic.net/vps-hosting/top-10-server-patching-software-solutions/ | Published: 2022-01-31 | Updated: 2025-09-19 | Author: Dr. Rachael Bailey Server patching software enables administrators to use a single platform to ensure that the devices within their infrastructure are kept up to date. Making sure that all devices remain up to date is a fundamental part of maintaining a secure network. With server patching software, the responsibility of updating software and firmware is removed from individual employees, helping to strengthen cybersecurity standards. When choosing server patching software for your business or organization, you must ensure that it meets your requirements. A good solution should be user-friendly, robust, scalable, support your current infrastructure, and integrate with other system management software. Here, we have compiled a list of some of the best server patching software and tools that are currently available on the market. We have considered the features that they offer, their overall performance, and their cost. ## Best Server Patching Software ## 1. Automox [Atlantic.Net](https://www.atlantic.net/) is a market-leading hosting provider, and we have been proud partners with [Automox](https://www.automox.com/) since 2015. Automox offered a solution for the ever-increasingly complex task of keeping all Atlantic.Net platforms patched, hardened, and production-ready. Despite being largely automated, regular patching, system updates, application updates, and other management tasks still took up a significant amount of administration and many unsociable hours by the team. These issues are eliminated with Automox. ## 2. Atera Atera is a comprehensive all-in-one remote monitoring and management tool (RMM) designed for Managed Service Providers (MSPs). Atera includes tools for remote control, discovery, asset inventory, patch management, built-in Professional Services Automation (PSA), monitoring, backup, and security. As a cloud-based platform, Atera enables users to update patches remotely from a single centralized location. With Atera, patch management can also be automated, eliminating the need for repetitive manual tasks and improving workflow and efficiency. Robust reporting allows users to keep on top of their patch management at all times. With a 30-day free trial and a flexible pricing model, Atera is an ideal solution for all businesses and organizations, including smaller organizations with a restricted budget. ## 3. Syxsense Manage Syxsense provides another cloud-based IT management solution with a patch management offering that can be used to automatically update desktops, laptops, and remote users. Syxsense patch management provides cross-platform support for Windows, Linux, and Mac and can also support IoT devices. This server patching tool offers automated deployment, support of third-party software applications, security risk assessments, and comprehensive reporting that meets HIPAA, SOX, and PCI DSS standards. ## 4. NinjaRMM Patch Management NinjaRMM is a comprehensive RMM platform that provides a single tool for the effective centralized management of IT services. As part of their platform, they offer a cross-platform patch management tool that is suitable for remote and hybrid workforces. NinjaRMM can patch endpoints no matter where they are located and can patch over 135 common applications. NinjaRMM allows patch management to be automated and any additional automated tasks to be easily scheduled. Generating ready-to-share patch management reports is as easy as a simple click. ## 5. ManageEngine Patch Manager Plus Ranked as a Leader for G2’s Summer 2021, ManageEngine Patch Manager Plus offers automated patch deployment for Windows, Mac, and Linux endpoints. This server patching solution also supports patching for over 900 third-party updates across over 500 third-party applications. Users can deploy ManageEngine Patch Manager Plus either on-premise or in the cloud. A standout feature of this software is the ability to “test and approve” patches. This allows a particular patch to be tested on a small group of endpoints prior to being implemented across the entire network. ManageEngine Patch Manager Plus is available in three different versions: a free version that provides support for up to 25 computers and 5 servers, a professional version suitable for computers in LAN, and an Enterprise version suitable for computers in WAN. ## 6. Acronis Cyber Protec Cloud Acronis Cyber Protec Cloud provides a single platform that unifies the management of endpoint protection, data protection, and cybersecurity. With Acronis, users can take advantage of integrated vulnerability assessments to identify where updates are needed. Patches can then be rolled out either manually on-demand or via an automated schedule. Acronis also creates a full-system backup before a patch is rolled out to ensure all data is protected and that endpoints can easily be rolled back to a working state if needed. ## 7. PDQ Deploy PDQ Deploy is a patch management tool designed to help you automate the patching of Windows endpoints. It also provides additional capabilities including the remote execution of custom scripts and the ability to copy over files, to send notifications to logged-in users, and to force a reboot for reluctant users. PDQ Deploy has a package library of over 250 popular, ready-to-deploy third-party applications. PDQ Deploy supports collaboration between administrators with a shared database and multi-admin access. Users can take advantage of a free 14-day trial to test out the software. ## 8. Pulseway Pulseway has recently launched a standalone industry-leading patch management software that can be accessed independently of Pulseway RMM. Users can integrate Pulseway Patch with their existing RMM solution or use it as a standalone tool. It currently supports over 160 of the most popular out-of-the-box patching titles as well as custom third-party titles. With the Pulseway mobile app, the platform can be remotely managed from anywhere, ## 9. N-able RMM N-able RMM provides a comprehensive cloud-based patch management solution that is trusted by industry leaders. This tool allows the patch management process to be streamlined by providing granular control over patch management policies. Users can choose what is auto-approved and manually approved and can schedule patching windows outside of high productivity timeframes. N-able RMM supports updates for operating systems, Microsoft products including Exchange and Microsoft 365, and multiple third-party software applications, such as Adobe and Java. N-able RMM’s pricing structure means that you only pay for what you need, but before parting with any money, you can try out the platform using their 30-day free trial. ## 10. SecPod SanerNow SecPod SanerNow is a CyberHygiene platform that incorporates vulnerability management, patch management, compliance management, asset management, endpoint management, and detection and response. It is delivered via the cloud and provides automated patch management for all major OSs and over 250 third-party applications. Key features of the software include automated patching, continuous and customizable patch scans, a vulnerability manager, and auto-generated reports and audit logs. ## How Can Atlantic.Net Help? Atlantic.Net’s engineers have first-hand experience with the complexities of patching customer systems. Patching is especially important in today’s security-conscious world. Patching is the number one way to prevent cybersecurity breaches, ransomware, and all other types of malware. Software and hardware vendors invest millions of dollars in updating the security of their products. In particular, operating system giants like Microsoft and Apple see great benefit in patching their systems. Most successful cyberattacks could have been thwarted if the customer had updated their patching policy. The easiest way to achieve this is using a Server Patching Software tool like Automox. Atlantic.Net has been partnered with Automox for many years, and the Automox platform helps our engineers secure thousands of endpoints on Atlantic.Net’s [virtual private servers](https://www.atlantic.net/vps-hosting/) and managed hosting much more easily. Server patching is critical for your business and for maintaining cybersecurity best practices. Atlantic.Net Managed Services customers already benefit from our own in-house patch management solution, powered by Automox. If you prefer to host your own server patching software, our cloud platform can power the automated administration of your local area network. To find out more about the solutions that we offer, [contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # Windows Server 2022 Is Now Available on the Atlantic.Net Cloud Platform (ACP) > URL: https://www.atlantic.net/press-releases/windows-server-2022-is-now-available-on-the-atlantic-net-cloud-platform-acp/ | Published: 2022-02-01 | Author: Editorial Team ORLANDO, FLA. (February 1, 2022) – Atlantic.Net now supports Windows Server 2022 Datacenter Edition with Desktop Experience installed on its Cloud Platform. Atlantic.Net customers can now deploy and scale their Windows Server 2022 instances across the Atlantic.Net Cloud Platform, making Atlantic.Net one of the first highly redundant cloud hosting providers to do so. Some of the exciting new features introduced in Windows Server 2022 are: - Under the hood, its security-defined operating system is capable of operating securely in a cloud environment for mission-critical cloud workloads. Windows Server now supports AES-256-GCM and AES-256-CCM cryptographic encryption. - DNS-over-HTTPS (DoH) encrypts DNS queries using the HTTPS protocol. This helps keep your traffic as private as possible and your DNS data from being manipulated. A new virtual video device provides better graphics performance for Cloud Servers running remote desktops. - Networking performance enhancements have been enabled by default for the TCP and UDP transport stacks, providing a smoother network data flow with better performance at high speeds. Windows Server 2022, the latest Windows Server offering from Microsoft, and its predecessors, Windows 2019, Windows Server 2016, and Windows 2012, are all available with Cloud Servers from Atlantic.Net. “Windows Server 2022 is a solid solution for customers needing power and speed to run applications remotely,” said Marty Puranik, CEO of Atlantic.Net. “Atlantic.Net Cloud Server clients can test the new tools offered by the Windows Server 2022 operating system and pay via a usage model on a per-hour basis without having to incur additional licensing costs”. Atlantic.Net’s Windows Cloud Hosting plans start at only $0.0230647 per hour (or $15.50 per month), with usage calculated on a per-hour basis. For a limited time, Atlantic.Net is offering all new clients a free-to-use Windows Server 2022 Cloud Server for one full year on the G3.2GB Cloud Server plan, which includes 3TB of outbound data transfer. The Atlantic.Net Cloud Platform provides fault-tolerant, ultra-fast performance and includes award-winning Cloud Servers, Secure Block Storage, one-click applications, DNS, Dedicated Hosts, private networking, RESTful API, data backup, a full suite of managed services, 24/7/365 expert U.S.-based support, and more. To view the latest cloud offerings and pricing, please visit: https://www.atlantic.net/vps-hosting/ About Atlantic.Net Atlantic.Net is a global cloud services provider with over 25 years of experience serving thousands of developers and small, medium, and large clients in more than one hundred countries. Atlantic.Net specializes in managed and unmanaged Windows, Linux, and FreeBSD server hosting solutions and has served dynamic business clients including Lenovo, Newegg, NASA, and Hilton, among others. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions backed by 24/7/365 support in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. For more information, please visit https://www.atlantic.net/. ### Contact: Email: pr@atlantic.net Ph: 321- 206-1371 --- # How to Install Jellyfin Media Server in Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-jellyfin-media-server-in-rocky-linux-10/ | Published: 2022-02-14 | Updated: 2025-10-16 | Author: Hitesh Jethva Jellyfin is a free and open-source media streaming software used to organize media content and stream it to any device. It is similar to other media streaming applications like Plex and Netflix. Jellyfin is cross-platform, and it can be accessed from a range of devices such as mobile phones, tablets, TVs, PCs and popular media devices like Roku or NVIDIA Shield. Jellyfin manages all your movies, songs, photos, and podcasts from a central location and streams them to other devices. In this post, we will show you how to install the Jellyfin media server on Rocky Linux 10. ## Step 1 – Install Required Repository By default, the Jellyfin media package is not included in the Rocky Linux 10 default repo, so you will need to add the EPEL, RPM Fusion, and Power Tools repo to your system. You can install all of these using the following commands: ``` dnf update -y ``` ``` dnf install epel-release -y dnf install --nogpgcheck https://mirrors.rpmfusion.org/free/el/rpmfusion-free-release-9.noarch.rpm https://mirrors.rpmfusion.org/nonfree/el/rpmfusion-nonfree-release-9.noarch.rpm -y ``` Next, install the SDL2 and FFmpeg packages with the following command: ``` dnf install -y SDL2 ffmpeg ffmpeg-devel ``` Once all the required packages are installed, you can move to the next step. Also Read [How to Compare Two Files in Linux Terminal](https://www.atlantic.net/vps-hosting/how-to-compare-two-files-in-linux-terminal/) ## Step 2 – Install Jellyfin Media Server First, change the directory to /opt and download the latest version of Jellyfin. ``` cd /opt wget https://repo.jellyfin.org/files/server/linux/latest-stable/amd64/jellyfin_10.10.7-amd64.tar.gz ``` Next, extract the downloaded file. ``` tar xvzf jellyfin_10.10.7-amd64.tar.gz ``` Next, navigate to the jellyfin directory and create required directories. ``` cd jellyfin mkdir data cache config log ``` Next, create a jellyfin start up script. ``` nano jellyfin.sh ``` Add the following content. ``` #!/bin/bash JELLYFINDIR="/opt/jellyfin" FFMPEGDIR="/usr/bin" $JELLYFINDIR/jellyfin \ -d $JELLYFINDIR/data \ -C $JELLYFINDIR/cache \ -c $JELLYFINDIR/config \ -l $JELLYFINDIR/log \ --ffmpeg $FFMPEGDIR/ffmpeg ``` Give the executable permission. ``` chmod 755 jellyfin.sh ``` Also Read [How to Remove Files and Directories in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-remove-files-and-directories-in-linux/) ## Step 3 – Create Systemd Service File First, create a systemd service file to manage the Jellyfin service. ``` nano /etc/systemd/system/jellyfin.service ``` Add the following lines. ``` [Unit] Description=Jellyfin After=network.target [Service] Type=simple User=root Restart=always ExecStart=/opt/jellyfin/jellyfin.sh [Install] WantedBy=multi-user.target ``` Reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Start and enable the Jellyfin service. ``` systemctl enable jellyfin.service systemctl start jellyfin.service ``` Verify the Jellyfin service status. ``` systemctl status jellyfin.service ``` Output. ``` ● jellyfin.service - Jellyfin Loaded: loaded (/etc/systemd/system/jellyfin.service; disabled; preset: disabled) Active: active (running) since Thu 2025-10-16 23:34:06 EDT; 15s ago Invocation: d9a9d40f8ee24beebf982aaac5fde52e Main PID: 9922 (jellyfin.sh) Tasks: 19 (limit: 24809) Memory: 113.8M (peak: 128.6M) CPU: 10.560s CGroup: /system.slice/jellyfin.service ├─9922 /bin/bash /opt/jellyfin/jellyfin.sh └─9923 /opt/jellyfin/jellyfin -d /opt/jellyfin/data -C /opt/jellyfin/cache -c /opt/jellyfin/config -l /opt/jellyfin/log --ffmpeg /usr/bin/ffmpeg ``` ## Step 4 – Access Jellyfin Web Installation Wizard At this point, Jellyfin is installed and listens on port 8096. You can now check the listening port with the following command: ``` ss -antpl | grep 8096 ``` You will get the following output: ``` LISTEN 0 128 0.0.0.0:8096 0.0.0.0:* users:(("jellyfin",pid=2469,fd=289)) ``` Now, open your web browser and access the Jellyfin web interface using the URL **http://your-server-ip:8096**. You will be redirected to the following screen: ![Jellyfin select language](https://www.atlantic.net/wp-content/uploads/2022/02/p1-4-1024x543.png) Select your language and click on the **Next** button. You should see the following screen: ![Jellyfin set admin user](https://www.atlantic.net/wp-content/uploads/2022/02/p2-3-1024x549.png) Provide your Jellyfin admin username and password and click on the **Next** button. You should see the following screen: ![Jellyfin add media](https://www.atlantic.net/wp-content/uploads/2022/02/p3-2-1024x514.png) Click on the **Next** button. You should see the following screen: ![Jellyfin select metadata language](https://www.atlantic.net/wp-content/uploads/2022/02/p4-1-1024x532.png) Select your metadata language and click on the **Next** button. You should see the following screen: ![Jellyfin configure remote access](https://www.atlantic.net/wp-content/uploads/2022/02/p5-1-1024x530.png) Configure remote access and click on the **Next** button. Once the installation is finished, you should see the following screen: ![Jellyfin installed](https://www.atlantic.net/wp-content/uploads/2022/02/p6-1024x503.png) Click on the **Finish** button. You should see the Jellyfin login screen: ![Jellyfin login screen](https://www.atlantic.net/wp-content/uploads/2022/02/p7-1024x519.png) Provide your admin username, password, and click on the **Sign In** button. You should see the Jellyfin dashboard on the following screen: ![Jellyfin dashboard screen](https://www.atlantic.net/wp-content/uploads/2022/02/p8-1024x513.png) ## Conclusion In this guide, we explained how to install the Jellyfin media streaming server on Rocky Linux 10. Now, add your movies and other media to the Jellyfin media library and start streaming them from remote devices. Try installing a media server on a [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Anaconda Python on Rocky Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-miniconda-python-on-rocky-linux-10/ | Published: 2022-02-16 | Updated: 2025-10-16 | Author: Hitesh Jethva Miniconda is a free and open-source package manager for Python. It provides a large variety of packages and is designed for machine learning and data science projects. It can install on all popular operating systems including Windows, Linux, and macOS. Miniconda is used for scientific computing, predictive analytics, and data processing. It provides a conda command-line utility and Miniconda Navigator graphical interface to manage Python packages. In this post, we will show you how to install Miniconda Python on Rocky Linux 10. ## Step 1 – Install Required Dependencies First, you will need to install some packages required to install Miniconda. You can install all those packages by running the following command: ``` dnf install libXi libXtst libXrandr libXcursor alsa-lib mesa-libEGL libXcomposite libXScrnSaver libXdamage mesa-libGL -y ``` Once all the packages are installed, you can move to the next step. ## Step 2 – Download Miniconda Installer Script Next, go to the [Anaconda official download page](https://www.anaconda.com/products/individual#linux) and download the latest version of the Miniconda installer script using the [wget](https://www.atlantic.net/dedicated-server-hosting/how-to-download-file-using-wget-in-linux/) command. ![Anaconda Download Page](https://www.atlantic.net/wp-content/uploads/2022/02/p1-2-1024x564.png) ``` wget https://repo.anaconda.com/miniconda/Miniconda3-latest-Linux-x86_64.sh ```   ## Step 3 – Install Miniconda Now, run the downloaded script to install Miniconda on your system. ``` bash Miniconda3-latest-Linux-x86_64.sh ``` You will be asked to accept the license terms: ``` Welcome to Miniconda3 2021.11 In order to continue the installation process, please review the license agreement. Please, press ENTER to continue >>> Do you accept the license terms? [yes|no] [no] >>> yes ``` Type **yes** and press the **Enter** key to start the installation. You should see the following output: ``` Miniconda3 will now be installed into this location: /root/miniconda3 - Press ENTER to confirm the location - Press CTRL-C to abort the installation - Or specify a different location below [/root/miniconda3] >>> PREFIX=/root/miniconda3 Preparing transaction: done Executing transaction: \ Installed package of scikit-learn can be accelerated using scikit-learn-intelex. More details are available here: https://intel.github.io/scikit-learn-intelex For example: $ conda install scikit-learn-intelex $ python -m sklearnex my_application.py done installation finished. Do you wish the installer to initialize Miniconda3 by running conda init? [yes|no] [no] >>> yes ``` Type **yes** and press the **Enter** key to initialize Miniconda. You will get the following output: ``` ==> For changes to take effect, close and re-open your current shell. <== If you'd prefer that conda's base environment not be activated on startup, set the auto_activate_base parameter to false: conda config --set auto_activate_base false Thank you for installing Miniconda3! ``` Now, run the following command to activate the Miniconda: ``` source .bashrc ``` #### Also Read [How to Install Python 3.10 on Oracle Linux 8](https://www.atlantic.net/dedicated-server-hosting/how-to-install-python-3-10-on-oracle-linux/) ## Step 4 – Verify the Miniconda Installation At this point, Miniconda is installed on your system. You can now verify the Miniconda installation using the following command: ``` conda info ``` You should see the following output: ``` active environment : base active env location : /root/miniconda3 shell level : 1 user config file : /root/.condarc populated config files : /root/miniconda3/.condarc conda version : 25.7.0 conda-build version : not installed python version : 3.13.5.final.0 solver : libmamba (default) virtual packages : __archspec=1=haswell __conda=25.7.0=0 __glibc=2.39=0 __linux=6.12.0=0 __unix=0=0 base environment : /root/miniconda3 (writable) conda av data dir : /root/miniconda3/etc/conda conda av metadata url : None channel URLs : https://repo.anaconda.com/pkgs/main/linux-64 https://repo.anaconda.com/pkgs/main/noarch https://repo.anaconda.com/pkgs/r/linux-64 https://repo.anaconda.com/pkgs/r/noarch package cache : /root/miniconda3/pkgs /root/.conda/pkgs envs directories : /root/miniconda3/envs /root/.conda/envs platform : linux-64 user-agent : conda/25.7.0 requests/2.32.4 CPython/3.13.5 Linux/6.12.0-55.21.1.el10_0.x86_64 rocky/10.0 glibc/2.39 solver/libmamba conda-libmamba-solver/25.4.0 libmambapy/2.0.5 aau/0.7.2 c/. s/. e/. UID:GID : 0:0 netrc file : None offline mode : False ``` You can also list all packages included in the Miniconda repository using the following command: ``` conda list ``` You will get a full list of packages in the following output: ``` # packages in environment at /root/miniconda3: # # Name Version Build Channel _ipyw_jlab_nb_ext_conf 0.1.0 py39h06a4308_0 _libgcc_mutex 0.1 main _openmp_mutex 4.5 1_gnu alabaster 0.7.12 pyhd3eb1b0_0 anaconda 2021.11 py39_0 anaconda-client 1.9.0 py39h06a4308_0 anaconda-navigator 2.1.1 py39_0 anaconda-project 0.10.1 pyhd3eb1b0_0 anyio 2.2.0 py39h06a4308_1 appdirs 1.4.4 pyhd3eb1b0_0 argh 0.26.2 py39h06a4308_0 argon2-cffi 20.1.0 py39h27cfd23_1 arrow 0.13.1 py39h06a4308_0 ``` ## Step 5 – Update Miniconda Package To update the Miniconda package, you will need to update conda first. You can update it with the following command: ``` conda update conda ``` You will get the following output: ``` The following packages will be downloaded: package | build ---------------------------|----------------- ca-certificates-2025.9.9 | h06a4308_0 127 KB certifi-2025.10.5 | py313h06a4308_0 158 KB conda-25.9.1 | py313h06a4308_0 1.2 MB openssl-3.0.18 | hd6dcaed_0 4.5 MB ------------------------------------------------------------ Total: 5.9 MB The following packages will be UPDATED: ca-certificates 2025.7.15-h06a4308_0 --> 2025.9.9-h06a4308_0 certifi 2025.8.3-py313h06a4308_0 --> 2025.10.5-py313h06a4308_0 conda 25.7.0-py313h06a4308_0 --> 25.9.1-py313h06a4308_0 openssl 3.0.17-h5eee18b_0 --> 3.0.18-hd6dcaed_0 ``` Next, install Miniconda using the following command: ``` conda update miniconda ``` ## Step 6 – Uninstall Miniconda If you want to remove the Miniconda package from your system, you will need to install the Miniconda removal package in your system. You can install it with the following command: ``` conda install anaconda-clean ``` You will get the following output: ``` The following packages will be downloaded: package | build ---------------------------|----------------- anaconda-clean-1.1.0 | py39h06a4308_1 7 KB ------------------------------------------------------------ Total: 7 KB The following NEW packages will be INSTALLED: anaconda-clean pkgs/main/linux-64::anaconda-clean-1.1.0-py39h06a4308_1 Proceed ([y]/n)? y ``` Next, run the following command to remove the Anaconda package. ``` anaconda-clean ``` You will get the following output: ``` Delete .conda? (y/n): y Backup directory: /root/.miniconda_backup/2025-10-16T170117 ``` Next, you will also need to remove the Miniconda directory from the Home directory: ``` rm -rf ~/miniconda3 ``` ## Conclusion In this guide, we explained how to install Miniconda on Rocky Linux 10. We also explained how to update and uninstall Miniconda using the command line. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install PostgreSQL 18 on Rocky Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-postgresql-18-in-rocky-linux/ | Published: 2022-02-18 | Updated: 2025-10-16 | Author: Hitesh Jethva PostgreSQL is a free, open-source, object-relational database system designed to scale the most complicated data workloads. Generally, it is used as the primary data store for many web, mobile, geospatial, and analytics applications. PostgreSQL can store structured and unstructured data in a single product. PostgreSQL 18 comes with a variety of features that help users to deploy their data-backed applications. In this post, we will show you how to install PostgreSQL 18 in Rocky Linux 8. ## Step 1 – Add PostgreSQL 18 Repository By default, the latest version of PostgreSQL is not included in the Rocky Linux 8 default repo. First, update the repository index. ``` dnf update -y ``` Next, install the PostgreSQL 18 repository using the following command: ``` dnf install https://download.postgresql.org/pub/repos/yum/reporpms/EL-8-x86_64/pgdg-redhat-repo-latest.noarch.rpm ``` Once the PostgreSQL 18 repository is added, you can move to the next step. Also Read [How To Secure PostgreSQL Server](https://www.atlantic.net/vps-hosting/how-to-secure-postgresql-server/) ## Step 2 – Install PostgreSQL 18 on Rocky Linux 8 Run the following command to install the PostgreSQL 18: ``` dnf install postgresql18 postgresql18-server -y ``` Once the installation is finished, initialized the PostgreSQL database with the following command: ``` /usr/pgsql-18/bin/postgresql-18-setup initdb ``` Next, start and enable the PostgreSQL service using the following command: ``` systemctl start postgresql-18 systemctl enable postgresql-18 ``` To check the status of PostgreSQL, run the following command: ``` systemctl status postgresql-18 ``` You will get the following output: ``` ● postgresql-18.service - PostgreSQL 18 database server Loaded: loaded (/usr/lib/systemd/system/postgresql-18.service; disabled; preset: disabled) Active: active (running) since Thu 2025-10-16 09:13:35 EDT; 8s ago Invocation: 2abe7ccca34444f9a0c08ce7fcbe1c8f Docs: https://www.postgresql.org/docs/18/static/ Process: 3871 ExecStartPre=/usr/pgsql-18/bin/postgresql-18-check-db-dir ${PGDATA} (code=exited, status=0/SUCCESS) Main PID: 3877 (postgres) Tasks: 10 (limit: 24809) Memory: 21.6M (peak: 22M) CPU: 65ms CGroup: /system.slice/postgresql-18.service ├─3877 /usr/pgsql-18/bin/postgres -D /var/lib/pgsql/18/data/ ├─3878 "postgres: logger " ├─3879 "postgres: io worker 0" ├─3880 "postgres: io worker 1" ├─3881 "postgres: io worker 2" ├─3882 "postgres: checkpointer " ├─3883 "postgres: background writer " ├─3885 "postgres: walwriter " ├─3886 "postgres: autovacuum launcher " └─3887 "postgres: logical replication launcher " Oct 16 09:13:35 rocky systemd[1]: Starting postgresql-18.service - PostgreSQL 18 database server... Oct 16 09:13:35 rocky postgres[3877]: 2025-10-16 09:13:35.663 EDT [3877] LOG: redirecting log output to logging collector process Oct 16 09:13:35 rocky postgres[3877]: 2025-10-16 09:13:35.663 EDT [3877] HINT: Future log output will appear in directory "log". Oct 16 09:13:35 rocky systemd[1]: Started postgresql-18.service - PostgreSQL 18 database server. ``` By default, PostgreSQL listens on port 5432. You can check it with the following command: ``` ss -antpl | grep 5432 ``` You will get the following output: ``` LISTEN 0 128 127.0.0.1:5432 0.0.0.0:* users:(("postmaster",pid=8428,fd=7)) LISTEN 0 128 [::1]:5432 [::]:* users:(("postmaster",pid=8428,fd=6)) ``` ## Step 3 – Connect to PostgreSQL There are two ways to connect to the local PostgreSQL instance: Use the following command to connect to the local PostgreSQL instance directly: ``` sudo -u postgres psql ``` You will get the PostgreSQL shell in the following output: ``` psql (18.0) Type "help" for help. postgres=# ``` You can also use the following method to connect to the local PostgreSQL instance: First, switch the user to the PostgreSQL user: ``` su - postgres ``` Next, run the **psql** command to connect to the PostgreSQL shell: ``` psql ``` You will get the following output: ``` psql (18.0) Type "help" for help. postgres=# ``` Now, run the **exit** command two times to exit from the PostgreSQL. Also Read [How to Install and Use pgAdmin on Ubuntu 18.04](https://www.atlantic.net/vps-hosting/how-to-install-and-use-pgadmin-on-ubuntu/) ## Step 4 – Working with PostgreSQL By default, the Postgres user is configured without any password. For security reasons, it is recommended to set a strong password for the Postgres user. Run the following command to set a password for the Postgres user: ``` psql -c "alter user postgres with password 'password'" ``` To create a database named wpdb, run the following command: ``` psql CREATE DATABASE wpdb; ``` To list all PostgreSQL databases, run the following command: ``` \l ``` You will get a list of all PostgreSQL databases in the following output: ``` List of databases Name | Owner | Encoding | Collate | Ctype | Access privileges -----------+----------+----------+-------------+-------------+----------------------- postgres | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | template0 | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | =c/postgres + | | | | | postgres=CTc/postgres template1 | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | =c/postgres + | | | | | postgres=CTc/postgres wpdb | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | ``` ## Step 5 – Configure PostgreSQL for Remote Access By default, PostgreSQL is configured to listen on localhost, so only local users can connect to the PostgreSQL database. If your application is hosted on a different server then you will need to configure PostgreSQL for remote access. You can configure it by editing the following file: ``` nano /var/lib/pgsql/18/data/postgresql.conf ``` Change the following line with your server IP address: ``` listen_addresses = 'your-server-ip' ``` Save and close the file, then edit another file: ``` nano /var/lib/pgsql/18/data/pg_hba.conf ``` Add the following line: ``` # Accept from anywhere host all all 0.0.0.0/0 md5 ``` Save and close the file, then restart the PostgreSQL service to apply the changes: ``` systemctl restart postgresql-18 ``` You can now connect to the PostgreSQL server from the remote machine using the following command: ``` psql -U username -h your-server-ip -p 5432 dbname ``` ## Conclusion In this post, we learned how to install PostgreSQL 18 on Rocky Linux 8. We also learned how to connect and interact with PostgreSQL. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) from Atlantic.Net! --- # How to Install Focalboard on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-focalboard-on-rocky-linux-10/ | Published: 2022-02-21 | Updated: 2025-10-16 | Author: Hitesh Jethva Focalboard is a free, open-source, self-hosted project management system used to track and manage projects across systems such as Windows, Mac, or Linux. It is an alternate solution for Asana, Trello, and Notion and is designed for both personal and development use. Focalboard helps the software development team to complete tasks, reach milestones, and achieve goals. It supports multiple boards and multiple languages and comes with import and export options for boards and tasks, making it easy to migrate to and from Focalboard. In this post, we will explain how to install Focalboard on Rocky Linux 10. ## Step 1 – Install and Configure PostgreSQL Focalboard uses PostgreSQL as a database backend, so you will need to install the PostgreSQL server on your system. Install the PostgreSQL server using the following command: ``` dnf install postgresql-server postgresql -y ``` Next, initialize the PostgreSQL database using the following command: ``` postgresql-setup --initdb ``` Next, edit the PostgreSQL configuration file: ``` nano /var/lib/pgsql/data/pg_hba.conf ``` Find the following lines: ``` host all all 127.0.0.1/32 ident host all all ::1/128 ident ``` And replace them with the following lines: ``` host all all 127.0.0.1/32 trust host all all ::1/128 trust ``` Save and close the file, then start and enable the PostgreSQL service with the following command: ``` systemctl start postgresql systemctl enable postgresql ``` Next, log in to PostgreSQL with the following command: ``` su - postgres psql ``` Next, create a database and user for PostgreSQL with the following command: ``` CREATE DATABASE focaldb; CREATE USER focaluser WITH PASSWORD 'password'; ``` Grant privileges to the focalboard user. ``` \c focaldb; GRANT USAGE ON SCHEMA public TO focaluser; GRANT CREATE ON SCHEMA public TO focaluser; GRANT ALL PRIVILEGES ON ALL TABLES IN SCHEMA public TO focaluser; GRANT ALL PRIVILEGES ON ALL SEQUENCES IN SCHEMA public TO focaluser; ``` Make sure focaluser owns the database. ``` ALTER DATABASE focaldb OWNER TO focaluser; ``` Next, exit from PostgreSQL using the following command: ``` \q exit ``` **Also Read** [How to Install and Configure Postgres 14 on Ubuntu 20.04](https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-postgres-14-on-ubuntu/) ## Step 2 – Install and Configure Focalboard First, download the latest version of Focalboard with the [wget command](https://www.atlantic.net/dedicated-server-hosting/how-to-download-file-using-wget-in-linux/): ``` wget https://github.com/mattermost/focalboard/releases/download/v0.15.0/focalboard-server-linux-amd64.tar.gz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar -xvzf focalboard-server-linux-amd64.tar.gz ``` Next, move the extracted directory to /opt with the following command: ``` mv focalboard /opt ``` Next, edit the Focalboard configuration file: ``` nano /opt/focalboard/config.json ``` Find the following lines: ``` "dbtype": "sqlite3", "dbconfig": "./focalboard.db", "postgres_dbconfig": "dbname=focalboard sslmode=disable", ``` And replace them with the following lines: ``` "dbtype": "postgres", "dbconfig": "postgres://focal:password@localhost/focaldb?sslmode=disable&connect_timeout=10", "postgres_dbconfig": "dbname=focaldb sslmode=disable", ``` Save and close the file when you are finished. ## Step 3 – Create a Systemd Service File Next, you will need to create a systemd service file to manage the Focalboard service: ``` nano /lib/systemd/system/focalboard.service ``` Add the following lines: ``` [Unit] Description=Focalboard server [Service] Type=simple Restart=always RestartSec=5s ExecStart=/opt/focalboard/bin/focalboard-server WorkingDirectory=/opt/focalboard [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes: ``` systemctl daemon-reload ``` Next, start and enable the Focalboard service with the following command: ``` systemctl start focalboard systemctl enable focalboard ``` At this point, Focalboard is started and listening on port 8000. You can check it with the following command: ``` ss -antpl | grep 8000 ``` You will get the following output: ``` LISTEN 0 128 *:8000 *:* users:(("focalboard-serv",pid=6547,fd=9)) ``` ## Step 4 – Configure Nginx as a Reverse Proxy for Focalboard Next, you will need to install and configure Nginx as a reverse proxy for Focalboard. First, install Nginx with the following command: ``` dnf install nginx -y ``` Next, create an Nginx virtual host configuration file: ``` nano /etc/nginx/conf.d/focalboard.conf ``` Add the following lines: ``` upstream focalboard { server localhost:8000; keepalive 32; } server { listen 80; server_name focalboard.example.com; location ~ /ws/* { proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; client_max_body_size 50M; proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Frame-Options SAMEORIGIN; proxy_buffers 256 16k; proxy_buffer_size 16k; client_body_timeout 60; send_timeout 300; lingering_timeout 5; proxy_connect_timeout 1d; proxy_send_timeout 1d; proxy_read_timeout 1d; proxy_pass http://focalboard; } location / { client_max_body_size 50M; proxy_set_header Connection ""; proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Frame-Options SAMEORIGIN; proxy_buffers 256 16k; proxy_buffer_size 16k; proxy_read_timeout 600s; proxy_cache_revalidate on; proxy_cache_min_uses 2; proxy_cache_use_stale timeout; proxy_cache_lock on; proxy_http_version 1.1; proxy_pass http://focalboard; } } ``` Save and close the file, then edit the Nginx configuration file: ``` nano /etc/nginx/nginx.conf ``` Add the following line below http {: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then verify Nginx for any syntax configuration errors: ``` nginx -t ``` You will get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Next, start and enable the Nginx service: ``` systemctl start nginx systemctl enable nginx ``` ## Step 5 – Access Focalboard Now, open your web browser and access the Focalboard web interface using the URL **http://focalboard.example.com**. You will be redirected to the Focalboard login page: ![Focalboard login page](https://www.atlantic.net/wp-content/uploads/2022/03/p1-2.png) Click on **create an account if you don’t have one**. You should see the account creation page: ![Focalboard registration page](https://www.atlantic.net/wp-content/uploads/2022/03/p2-2.png) Set up your admin email address, username, and password, and click on the **Register** button. You should see the following page: ![Focalboard select template page](https://www.atlantic.net/wp-content/uploads/2022/03/p3-2-1024x534.png) Click on the **Use this template** button. You should see the Focalboard dashboard on the following page: ![Focalboard dashboard page](https://www.atlantic.net/wp-content/uploads/2022/03/p4-2-1024x527.png) ## Conclusion In this guide, you learned how to install Focalboard with Nginx as a reverse proxy on Rocky Linux 10. You can now manage your projects easily through a web browser. Try it on [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Best Practices for Creating a HIPAA-Compliant Docker Host > URL: https://www.atlantic.net/hipaa-compliant-hosting/best-practices-for-creating-a-hipaa-compliant-docker-host/ | Published: 2022-02-23 | Updated: 2025-09-19 | Author: Richard Bailey Docker is a popular container platform for running containerized applications and microservices. Docker provides a software-defined abstraction layer for developing, shipping, and running applications. Docker has a vast library of [official](https://hub.docker.com/search?image_filter=official&type=image) docker images that enables users to download and run containerized and lightweight versions of their favorite applications and operating systems. Out of the box, Docker is not HIPAA-compliant. However, with the correct [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) infrastructure solution in place and by using well-constructed and security-defined Dockerfiles, it is possible to run a HIPAA-compliant Docker host. ## What Are the Best Practices for Utilizing Docker Generally? Docker Inc. is keen to make Docker a highly secure environment for production workloads, and this approach greatly benefits healthcare organizations. When using Official Docker Images, you can be sure that each image has passed Docker’s stringent security onboarding. [Check here to discover the exacting requirements.](https://github.com/docker-library/official-images) Docker Images are updated frequently, but it’s not always best practice to use the latest version. Instead, use specific Docker Image versions. This is important because the latest versions may break your setup or cause unpredictable behavior. Always download lightweight Docker Images, the applications that have the absolute minimum installed to make the app work. This greatly reduces the attack surface of your application, improving security straight out of the box. Another essential best practice is to use a specific user to start your Docker container. By default, the system will use root, but the root is never really necessary – instead, create a user account with the minimum permissions to perform Docker tasks. Make sure you scan your Docker Images for vulnerabilities; this is a critical process if you build your own custom Docker images. ## How Is Docker Different From Virtualization Hypervisors like VMware ESXi and Hyper-V? This question can confuse those who are less familiar with Docker. Docker is a container-based technology that contains just the required files to complete the required processes of the task. Containers are run by sharing the host OS Kernel. Virtual Machines running on ESXi or Hyper-V are made up of the complete operating system and any user files. VM images are much larger than containers, and the server hardware is virtualized, sharing resources from the host. ## Best Practices for HIPAA Security Any application that processes protected health information (PHI) is subject to HIPAA compliance requirements, and if the application runs on Docker then the application, Docker and the host infrastructure must all comply with a HIPAA compliance framework. Several key design requirements must be at the forefront of the design process. These include: ### Best Practices for Your Employees When Using Docker User accounts, access, and authorization controls are critical for a Docker host. Docker containers must run on individual UserIDs and comply with the administrative requirements of HIPAA, such as complex passwords that are changed frequently and having Dockerfiles set to security roles to control unauthorized access to the application. Containers should only be accessible by authorized personnel who have pre-approved to access ePHI. Only allow web access to PHI applications on a need-to-know basis (typically doctors, nurses, physicians, and other such personnel). ### Backup and Restore Requirements To be HIPAA compliant, Docker volumes must be encrypted and adhere to a stringent daily backup schedule. Regardless of compliance, backups are very important for Docker; regular snapshots preserve the runtime environment from immediate failure, but individual backup policies need to be defined for each Docker volume and each Docker host. The backups must be completed at least daily and replicated offsite to an alternative location. The restore process must be tested regularly. ### Software-Defined Disaster Recovery Docker Swarm can be used for disaster recovery if configured correctly with multiple hosts in multiple regions, but be cautious of major network interruptions. Docker Swarm does not cope well with a transient network state. It is recommended to choose a hosting provider that can provide a disaster recovery solution at the host level, a service where a replica host is automatically powered up at an alternative location. ### Automatic Logout Another key design decision is to include an automatic logout function for Docker applications and a timeout for SSH connections. This may seem like common sense, but setting a timeout is required for compliance. Hospitals do not want strangers accessing PHI simply because a user forgot to log out of a web application. A timeout of between 30 seconds and 3 minutes of inactivity is recommended, with the user needing to re-authenticate using Multi-Factor Authentication upon return. ## What Common Mistakes Are Made with Docker? Here are some classic mistakes made by inexperienced Docker users: - **Do not create a Docker Image that contains PHI** – instead, mount an encrypted Docker volume from a protected source. - **Do not install unnecessary services to a Docker Image** – Docker images should be lightweight, not only for performance but also for minimizing the attack surface of the container. - **Do not write Docker Secrets in plaintext Dockerfiles** – it’s all too easy to pass a plaintext password to a Docker container; instead, use variables and consider creating a secrets vault. - **Do not run containers as the root user** – this is a very simple mistake to make. Instead, use a dedicated user account and group following the principle of least privilege. ## Atlantic.Net Containerization Capabilities Docker support is currently available on Atlantic.Net as a one-click application that runs on Ubuntu 20.04 or through Windows 2016 Datacenter (with Containers/Docker as a server based-deployment). Both can be deployed in any of our eight data center locations in less than 30 seconds! To ensure that your Docker implementation is HIPAA compliant, the environment must adhere to numerous administrative, physical, and technical safeguards. Thus the Docker host must meet these criteria; here are some of the key points to consider: - **Network encryption** – Encrypt any ePHI to meet NIST cryptographic standards any time it is transmitted over an external network. This includes Docker virtual networks. - **Authenticate ePHI** – Identify and authenticate ePHI, protecting it from corruption, unauthorized changes, and accidental destruction. - **Encrypt devices** –  All end-point devices that interact with your Docker application should be able to encrypt and decrypt data; this is particularly important for mobile and laptop devices. - **Control activity audits** – Detailed Container logging is needed to track all ePHI access attempts and to monitor how ePHI data is manipulated. - **Control facility access** – Consider the location of your Docker host. You want to be capable of tracking access to the data center. - **Manage workstations** – Write a policy that limits which workstations can access Docker containers processing health data. - **Risk assessment** – the Docker environment requires a full risk assessment to identify, analyze, and put measures in place to resolve concerns raised. - **Train your staff** – You need to train employees on all ePHI access protocols and how to recognize potential cybersecurity risks such as phishing, hacking, and deception. A record of these sessions must be kept. These are just a few of the considerations when implementing a HIPAA-Compliant Docker Host. [You can find additional information in the Atlantic.Net HIPAA-Compliance checklist – click here](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). Atlantic.Net is an industry-leading global cloud services provider with over 30 years of computing and networking experience. Our [HIPAA Compliant Cloud Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) is one of our most successful cloud-based services, offering the necessary tools and features to secure your infrastructure and streamline the workflow of your healthcare business. Share your vision with us, and we will develop a hosting environment tailored to your needs! Contact an advisor at 866-618-DATA (3282) or email [sales@atlantic.net](mailto:sales@atlantic.net) today. --- # How to Install Crater Invoicing Solution on Debian > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-crater-invoicing-solution-on-debian/ | Published: 2022-02-25 | Updated: 2025-09-02 | Author: Hitesh Jethva Crater is a free and open-source invoicing application based on the Laravel PHP framework. It is designed for individual users or small and medium-sized businesses to help track payments and expenses as well as create professional invoices. It comes with a suite of tools that are used to manage invoices. Crater allows users to create and send professional invoices to their clients. In this post, we will show you how to install Crater Invoicing Solution on Debian 12. ## Step 1 – Install Apache, MariaDB, and PHP Before starting, you will need to install the Apache web server, and the MariaDB database server: ``` apt-get update -y apt-get install apache2 mariadb-server -y ``` After installing all the packages, start and enable both the Apache and MariaDB services: ``` systemctl start apache2 mariadb systemctl enable apache2 mariadb ``` Add the PHP repository. ``` apt install apt-transport-https lsb-release ca-certificates curl -y curl -sSL https://packages.sury.org/php/apt.gpg | tee /etc/apt/trusted.gpg.d/sury.gpg > /dev/null echo "deb https://packages.sury.org/php/ $(lsb_release -sc) main" | tee /etc/apt/sources.list.d/sury-php.list ``` Update the repository index. ``` apt update -y ``` Install PHP 8.1 with other required extensions. ``` apt install php8.1 php8.1-cli php8.1-common php8.1-mysql php8.1-zip php8.1-gd php8.1-mbstring php8.1-curl php8.1-xml php8.1-bcmath php8.1-intl libapache2-mod-php8.1 -y ``` ## Step 2 – Create a Database for Crater Crater uses a MariaDB as a database backend, so you will need to create a database and user for Crater. First, log in to MySQL with the following command: ``` mysql ``` Next, create a database and user using the following command: ``` create database crater; create user 'crater'@'localhost' identified by 'password'; ``` Next, grant all the privileges to the Crater database with the following command: ``` grant all privileges on crater.* to 'crater'@'localhost'; ``` Next, flush the privileges and exit from the MariaDB shell using the following command: ``` flush privileges; exit; ``` ## Step 3 – Download Crater Next, you will need to download the latest version of Crater from their official website. You can download it using the [wget command](https://www.atlantic.net/dedicated-server-hosting/how-to-download-file-using-wget-in-linux/): ``` wget https://github.com/crater-invoice-inc/crater/archive/refs/heads/master.zip ``` Once Crater is downloaded, extract the downloaded file using the following command: ``` unzip master.zip ``` Next, move the extracted directory to the Apache web root directory: ``` mv crater-master /var/www/html/crater ``` Next, set proper ownership and permissions to the Crater directory: ``` chown -R www-data:www-data /var/www/html/crater chmod -R 775 /var/www/html/crater/storage/framework chmod -R 775 /var/www/html/crater/storage/logs chmod -R 775 /var/www/html/crater/bootstrap/cache ``` ## Step 4 – Configure Crater Next, you will need to install Composer and configure Crater. First, change the directory to the crater and install Composer with the following command: ``` cd /var/www/html/crater ``` ``` curl -sS https://getcomposer.org/installer | php mv composer.phar /usr/local/bin/composer ``` Next, install all required PHP dependencies. ``` composer install ``` Next, copy the sample .env file. ``` cp .env.example .env ``` Next, edit the .env file. ``` nano .env ``` Define your App URL and database settings: ``` APP_ENV=production APP_KEY=base64:kgk/4DW1vEVy7aEvet5FPp5un6PIGe/so8H0mvoUtW0= APP_DEBUG=true APP_LOG_LEVEL=debug APP_URL=http://crater.example.com DB_CONNECTION=mysql DB_HOST=db DB_PORT=3306 DB_DATABASE=crater DB_USERNAME=crater DB_PASSWORD="password" ``` Next, set proper permissions and ownership. ``` chown -R www-data:www-data /var/www/html/crater chmod -R 755 /var/www/html/crater ``` ## Step 5 – Create an Apache Virtual Host for Crater Next, you will need to create an Apache virtual host configuration file to host Crater on the internet. You can create it with the following command: ``` nano /etc/apache2/sites-available/crater.conf ``` Add the following lines: ``` ServerName crater.example.com DocumentRoot /var/www/html/crater/public AllowOverride All Require all granted ErrorLog /var/log/apache2/crater_error.log CustomLog /var/log/apache2/crater_access.log combined ``` Save and close the file, then activate the Crater virtual host and Apache rewrite module using the following command: ``` a2enmod rewrite a2ensite crater.conf ``` Next, restart the Apache service to apply the configuration changes: ``` systemctl restart apache2 ``` To check the status of the Apache service, use the following command: ``` systemctl status apache2 ``` You should see the following output: ``` ● apache2.service - The Apache HTTP Server Loaded: loaded (/lib/systemd/system/apache2.service; enabled; vendor preset: enabled) Active: active (running) since Tue 2022-03-01 08:03:05 UTC; 4s ago Docs: https://httpd.apache.org/docs/2.4/ Process: 14762 ExecStart=/usr/sbin/apachectl start (code=exited, status=0/SUCCESS) Main PID: 14767 (apache2) Tasks: 6 (limit: 2341) Memory: 13.6M CPU: 72ms CGroup: /system.slice/apache2.service ├─14767 /usr/sbin/apache2 -k start ├─14768 /usr/sbin/apache2 -k start ├─14769 /usr/sbin/apache2 -k start ├─14770 /usr/sbin/apache2 -k start ├─14771 /usr/sbin/apache2 -k start └─14772 /usr/sbin/apache2 -k start ``` ## Step 6 – Access Crater Web UI At this point, Crater is installed and configured. You can now access the Crater web UI using the URL **http://crater.example.com**. You should see the following page: ![Crater requirement check page](https://www.atlantic.net/wp-content/uploads/2022/03/p1-1-1024x417.png) Click on **Check Requirements**. You should see the following page: ![Crater PHP extensions check page](https://www.atlantic.net/wp-content/uploads/2022/03/p2-1-1024x519.png) If all required PHP extensions are installed then click on the **Continue** button. You should see the following page: ![Crater permissions check page](https://www.atlantic.net/wp-content/uploads/2022/03/p3-1-1024x506.png) Make sure all permissions are correct then click on the **Continue** button. You should see the following page: ![Crater database configuration page](https://www.atlantic.net/wp-content/uploads/2022/03/p4-1-1024x536.png) Provide the website URL and database configuration details and click on the **Save & Continue** button. You should see the following page: ![Crater domain varification page](https://www.atlantic.net/wp-content/uploads/2022/03/p5-1024x524.png) Provide your website Domain and click on the **Verify** **Now** button. You should see the following page: ![Crater mail configuration page](https://www.atlantic.net/wp-content/uploads/2022/03/p6-1024x502.png) Provide your Mail configuration and click on the **Save** button. You should see the following page: ![Crater account configuration page](https://www.atlantic.net/wp-content/uploads/2022/03/p7-1024x567.png) Provide your account information and click on the **Save & Continue** button. You should see the following page: ![Crater company information page](https://www.atlantic.net/wp-content/uploads/2022/03/p8-1024x543.png) Provide your company information and click on the **Save & Continue** button. You should see the following page: ![Crater company preferences page](https://www.atlantic.net/wp-content/uploads/2022/03/p9-1024x544.png) Select your company preferences and click on the **Save & Continue** button. You should see the Crater dashboard on the following page: ![Crater dashboard page](https://www.atlantic.net/wp-content/uploads/2022/03/p10-1024x532.png) ## Conclusion In this guide, we explained how to install Crater Invoicing Solution on Debian 12. You can now implement Crater in your organization and start managing taxes, invoices, and payments from the central location. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) from Atlantic.Net! --- # How to Check the MySQL Version in Linux > URL: https://www.atlantic.net/vps-hosting/how-to-check-the-mysql-version-in-linux/ | Published: 2022-02-28 | Updated: 2023-11-21 | Author: Hitesh Jethva MySQL is one of the most popular open-source database management systems and is used by many websites and organizations. There are a lot of MySQL versions available on the Internet. If you want to host an application that requires a specific MySQL version, you will need to know the version of MySQL installed on your server. In this post, we will show you how to check the MySQL version in Linux. ## Check the MySQL Version via Command Line The simple and easiest way to check the MySQL version on your system is from the command line. If you have root access to your Linux server, you can use the following command to check the MySQL version: ``` mysql -V ``` You will get the MySQL version in the following output: ``` mysql Ver 8.0.26 for Linux on x86_64 (Source distribution) ``` MySQL also provides a MySQLAdmin command-line utility to perform several administrative tasks. You can also use this utility to check the MySQL version: ``` mysqladmin -V ``` You will get the following output: ``` mysqladmin Ver 8.0.26 for Linux on x86_64 (Source distribution) ``` Also Read [How to Check and Repair MySQL](https://www.atlantic.net/dedicated-server-hosting/how-to-check-and-repair-mysql-databases-and-tables/) ## Check MySQL Version Using SHOW VARIABLES You can also use the MySQL command-line utility to check the MySQL version. First, connect to the MySQL server with the following command: ``` mysql -u root -p ``` Once you are connected, use the following command to check the MySQL version: ``` mysql> SHOW VARIABLES LIKE '%version%'; ``` You will get the MySQL version in the following output: ``` +--------------------------+-------------------------------+ | Variable_name | Value | +--------------------------+-------------------------------+ | admin_tls_version | TLSv1,TLSv1.1,TLSv1.2,TLSv1.3 | | immediate_server_version | 999999 | | innodb_version | 8.0.26 | | original_server_version | 999999 | | protocol_version | 10 | | replica_type_conversions | | | slave_type_conversions | | | tls_version | TLSv1,TLSv1.1,TLSv1.2,TLSv1.3 | | version | 8.0.26 | | version_comment | Source distribution | | version_compile_machine | x86_64 | | version_compile_os | Linux | | version_compile_zlib | 1.2.11 | +--------------------------+-------------------------------+ ``` Also Read [How to Create and Delete User in MySQL](https://www.atlantic.net/dedicated-server-hosting/how-to-create-and-delete-a-user-in-mysql/) ## Check MySQL Version Using SELECT VERSION After connecting to the MySQL server, you can also use the **SELECT VERSION** command to check the MySQL version. ``` mysql> SELECT VERSION(); ``` You will get the following output: ``` +-----------+ | VERSION() | +-----------+ | 8.0.26 | +-----------+ 1 row in set (0.00 sec) ``` ## Check MySQL Version Using STATUS You can also run the **STATUS** query inside the MySQL shell to check the MySQL version: ``` mysql> STATUS; ``` You will get the following output: ``` -------------- mysql Ver 8.0.26 for Linux on x86_64 (Source distribution) Connection id: 11 Current database: Current user: root@localhost SSL: Not in use Current pager: stdout Using outfile: '' Using delimiter: ; Server version: 8.0.26 Source distribution Protocol version: 10 Connection: Localhost via UNIX socket Server characterset: utf8mb4 Db characterset: utf8mb4 Client characterset: utf8mb4 Conn. characterset: utf8mb4 UNIX socket: /var/lib/mysql/mysql.sock Binary data as: Hexadecimal Uptime: 2 min 12 sec Threads: 2 Questions: 17 Slow queries: 0 Opens: 150 Flush tables: 3 Open tables: 66 Queries per second avg: 0.128 -------------- ``` ## Check MySQL Version Using PHP If your application is hosted on the shared hosting and doesn’t have access to the command line, you can upload the PHP file to your website directory and check the MySQL version. To check the MySQL version using PHP, create a file named info.php with the following content and upload it to your website directory: ``` URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-the-ack-command-in-linux/ | Published: 2022-03-01 | Updated: 2023-11-17 | Author: Hitesh Jethva Linux operating systems offer support for searching both files and directories for specific text strings. One of the most common tools to search for a text string is grep. Grep allows users to search for any pattern with regular expressions within files and directories. However, grep has some limitations. It is a general-purpose tool without any optimization. This is where the Ack tool can help. The Ack tool is specifically designed for developers for searching the source code of programs. The Ack tool is faster than grep and allows us to exclude certain outputs from search results. In this post, we will show you how to install and use the Ack command in Linux. ## Install Ack in Linux By default, the Ack tool is included in the default repository of all major operating systems. For Debian and Ubuntu-based distributions, install the Ack tool using the following command: ``` apt-get install ack-grep -y ``` For RHEL, Fedora, and CentOS-based distributions, install the Ack tool using the following command: ``` dnf install ack-grep -y ``` After the installation, verify the Ack version using the following command: ``` ack --version ``` You will get the following output: ``` ack 2.22 Running under Perl 5.26.1 at /usr/bin/perl Copyright 2005-2017 Andy Lester. This program is free software. You may modify or distribute it under the terms of the Artistic License v2.0. ``` Also Read [How to Install LFTP to Download and Upload Files in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-install-lftp-to-download-and-upload-files-in-linux/) ## Download Neovim Source Code To demonstrate how to use the Ack command, we will download neovim source code from the Git repository. Run the following command to download the neovim source: ``` git clone https://github.com/neovim/neovim.git ``` Once the download is completed, change the directory to the downloaded source and list all files: ``` cd neovim ls neovim ``` You should see all files in the following output: ``` BACKERS.md CMakeLists.txt CONTRIBUTING.md man scripts third-party BSDmakefile codecov.yml LICENSE.txt packaging snap unicode ci config MAINTAIN.md README.md src cmake contrib Makefile runtime test ``` ## Search for the Total Number of Files in the Directory You can use the Ack command to find out how many files are inside the repository. ``` ack -f | wc -l ``` You will get the following result: ``` 2899 ``` ## Search for a String Pattern Using Ack Command The Ack command can search for a specific pattern and find data that has either partial or full matches. For example, to search for the string “**restrict**” in the repository, run the following command: ``` ack restrict ``` You will get the following result: ![Ack search for a string](https://www.atlantic.net/wp-content/uploads/2022/03/p1.png) **Also Read** [How to Compare Two Files in Linux Terminal](https://www.atlantic.net/vps-hosting/how-to-compare-two-files-in-linux-terminal/) ## Search for a String Pattern Word Using Ack Command If you want to see the exact match in the result, use the **-w** option: ``` ack -w restrict ``` You will get the following output: ![Ack search for exact string](https://www.atlantic.net/wp-content/uploads/2022/03/p2-1024x588.png) As you can see, the Ack command searches for **restrict** as a complete word. ## Search for a String Pattern from a Specific File Type If you want to search for a specific string in a specific file type, including Python, C, or Vim, you can use the –python, –c, or –vim option. For example, to search for a string “**restrict**” only within Python files, run the following command: ``` ack -w --python restrict ``` You will get the following output: ![Ack search for a string in specific file](https://www.atlantic.net/wp-content/uploads/2022/03/p3.png) ## Count the Total Occurrences of a String Search If you want to count the total number of occurrences of a specified string, use the **-c** option with Ack command. ``` ack -c restrict ``` You will get the following output: ![Ack search for total occurrence](https://www.atlantic.net/wp-content/uploads/2022/03/p4.png) If you want to show the total number of occurrences of a string “**restrict**” in the output, run the following command: ``` ack -ch restrict ``` You will get the following output: ``` 232 ``` If you want to check the speed of the searches, run the following command: ``` time ack -ch restrict ``` You will get the following output: ``` 232 real 0m0.631s user 0m0.551s sys 0m0.076s ``` ## Search for a Specific File Type The Ack command can also find the specific file types from the specified directory. For example, to find all Python files in your current directory, run the following command: ``` ack -f --python ``` You will get all Python files in the following output: ``` src/clint.py src/nvim/testdir/pyxfile/py2_magic.py src/nvim/testdir/pyxfile/py3_magic.py src/nvim/testdir/pyxfile/py3_shebang.py src/nvim/testdir/pyxfile/pyx.py src/nvim/testdir/pyxfile/py2_shebang.py src/nvim/testdir/test_makeencoding.py contrib/gdb/nvim-gdb-pretty-printers.py contrib/YouCompleteMe/ycm_extra_conf.py scripts/stripdecls.py scripts/gen_help_html.py scripts/check-includes.py scripts/shadacat.py scripts/gen_vimdoc.py ``` ## Conclusion In this post, we explained how to install and use the Ack command in Linux. Ack is a very useful and flexible search tool for developers when handling multiple projects. Get started now on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Use Telnet on Debian > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-telnet-on-debian/ | Published: 2022-03-10 | Updated: 2025-09-02 | Author: Hitesh Jethva Telnet is a free and open-source remote management protocol for Linux and Windows systems. It is used to check the remote server port connectivity from the client system. Telnet is also used to troubleshoot and test the system services that define the remote computing environment. Telnet is a client-server protocol that runs on port 23. Telnet can perform several helpful tasks for Linux and Windows administrators. In this post, we will show you how to install and use Telnet in Debian 12. ## Install Telnet Server in Debian 12 By default, Telnet is included in the default repository of all major Linux distributions. You can use the **apt** or **dnf** command to install Telnet in Linux. For Ubuntu and Debian-based distributions, install the Telnet server using the following command: ``` apt-get install telnetd -y ``` Edit the inetd configuration file. ``` nano /etc/inetd.conf ``` Add the following line at the end of the file. ``` telnet stream tcp nowait root /usr/sbin/tcpd /usr/sbin/telnetd ``` Restart the inetd service. ``` systemctl restart inetd ``` Check the status of the Telnet server with the following command: ``` systemctl status inetutils-syslogd ``` You should see the following output: ``` ● xinetd.service - LSB: Starts or stops the xinetd daemon. Loaded: loaded (/etc/init.d/xinetd; generated) Active: active (running) since Tue 2025-09-02 11:03:53 UTC; 1min 23s ago Docs: man:systemd-sysv-generator(8) Process: 71217 ExecStart=/etc/init.d/xinetd start (code=exited, status=0/SUCCESS) Tasks: 3 (limit: 2304) Memory: 1.5M CPU: 627ms CGroup: /system.slice/xinetd.service ├─71227 /usr/sbin/xinetd -pidfile /run/xinetd.pid -stayalive -inetd_compat -inetd_ipv6 ├─71229 telnetd └─71233 /bin/login -p -h 49.36.71.22 Sep 02 11:03:53 debian systemd[1]: Starting xinetd.service - LSB: Starts or stops the xinetd daemon.... Sep 02 11:03:53 debian xinetd[71217]: Starting internet superserver: xinetd. Sep 02 11:03:53 debian systemd[1]: Started xinetd.service - LSB: Starts or stops the xinetd daemon.. ``` ## Log in to the Telnet Server from a Remote System Generally, Telnet is used to log in to the remote server and perform administrative tasks. Go to the remote system and run the following command to log in to the Telnet server: ``` telnet telnet-server-ip ``` You will be asked to provide your username and password to authenticate the Telnet server as shown below: ``` Trying 192.168.0.100... Connected to 192.168.0.100. Escape character is '^]'. Debian 12 LTS vyompc login: vyom Password: ``` Once you are logged in, you will get the following output: ``` Linux debian12 6.1.0-32-amd64 #1 SMP Debian 6.1.0-32 (2025-01-18) x86_64 The programs included with the Debian GNU/Linux system are free software; the exact distribution terms for each program are described in the individual files in /usr/share/doc/*/copyright. Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. Last login: Thu Sept 2 02:31:37 UTC 2025 from 103.1.103.89 on pts/0 vyom@vyompc:~$ ``` You can now manage your server remotely via a command-line interface. #### **Also Read** [How to Use Zip and Unzip Command in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-use-zip-and-unzip-commands-in-linux/) ## Check Open Ports on Remote System Telnet is also useful to check open ports on the remote system. For example, to test whether port 22 is open or not on the remote system, run the following command: ``` telnet remote-server-ip 22 ``` If port 22 is open, you will get the following output: ``` Trying 192.168.1.2... Connected to 192.168.1.2. Escape character is '^]'. SSH-2.0-OpenSSH_7.4 ``` If port 22 is not open or the service is not running, you will get the following output: ``` Trying 192.168.1.2... telnet: Unable to connect to remote host: Connection refused ``` To check whether the website **test.example.com** is open on port **80**, run the following command: ``` telnet test.example.com 80 ``` If port 80 is open, you will get the following output: ``` Trying test.example.com... Connected to test.example.com. Escape character is '^]'. ``` Now, run the following command to retrieve the **index.html** page from the website: ``` GET /index.html HTTP/1.0 ``` Output: ``` HTTP/1.1 200 OK Date: Wed, 02 Sept 2025 10:22:16 GMT Server: Apache/2.4.29 (Debian) Last-Modified: Mon, 31 Jan 2025 07:25:23 GMT ETag: "2aa6-5d6dbb015179f" Accept-Ranges: bytes Content-Length: 10918 Vary: Accept-Encoding Connection: close Content-Type: text/html ``` #### **Also Read** [Netstat Command Line Tips and Tricks](https://www.atlantic.net/vps-hosting/netstat-command-line-tips-and-tricks/) ## Check a Remote Email Server One of the best uses of the Telnet command is to check an email server. For example, to check a remote email server, run the following command: ``` telnet mail-server-ip 25 ``` Once the connection is successful, you will get the following shell: ``` Trying mail.example.com... Connected to mail.example.com. Escape character is '^]'. 220 vyompc ESMTP Postfix (Debian) ``` Now, run the **ehlo** followed by the email domain name to respond to the server: ``` ehlo example.com ``` You should see all methods supported by the email server: ``` 250-vyompc 250-PIPELINING 250-SIZE 10240000 250-VRFY 250-ETRN 250-STARTTLS 250-ENHANCEDSTATUSCODES 250-8BITMIME 250-DSN 250 SMTPUTF8 ``` Now, run the following command to exit from the Telnet connection: ``` quit ``` ## Conclusion In this post, we explained how to install and use Telnet on Debian 12. You can now use the Telnet command to check the remote port and email server status. Get started now on [virtual private servers](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Oracle Linux Is Now Available on the Atlantic.Net Cloud Platform (ACP) > URL: https://www.atlantic.net/press-releases/oracle-linux-is-now-available-on-the-atlantic-net-cloud-platform-acp/ | Published: 2022-03-11 | Updated: 2024-06-11 | Author: Editorial Team ORLANDO, FLA. (March 11, 2022) – Atlantic.Net now supports Oracle Linux on its Cloud Platform. Atlantic.Net customers can now deploy and scale their Oracle Linux instances across the Atlantic.Net Cloud Platform. This newly available distribution is designed for extremely high performance on a security-defined Linux platform. Oracle Linux is 100% RHEL-compatible and a genuine alternative to CentOS, which reached end-of-life (EOL) in December 2021. For power users who are already familiar with Red Hat, CentOS, and Rocky Linux, the transition to Oracle Linux will be a seamless experience, without incurring any operating system licensing cost. Oracle Linux offers the choice of two Linux Kernels: • RHCK (Red Hat Compatible Kernel) • UEK (Unbreakable Enterprise Kernel) Both are free and 100% compatible with Red Hat Enterprise Linux. “Oracle Linux is a very exciting distribution, and we are delighted to offer 64-bit editions of Oracle Linux 7.9 and Oracle Linux 8.5. Both are available right now on the ACP as one of our many Cloud Server operating systems that launches in less than 30 seconds,” said Josh Simon, Vice President – Cloud Services and Research & Development at Atlantic.Net. If you are currently using CentOS and are looking for a simple way to switch to Oracle Linux, Oracle offers a user-friendly script that will automatically handle the switch for you. Atlantic.Net’s Windows Cloud Server Hosting plans start at only $0.00595238 per hour (or $4 per month), with usage calculated on a per-hour basis. For a limited time, Atlantic.Net is offering all new clients a free-to-use Oracle Linux Cloud Server for one full year on the G3.2GB Cloud Server plan, which includes 3TB of outbound data transfer. The Atlantic.Net Cloud Platform provides fault-tolerant, ultra-fast performance and includes award-winning Cloud Servers, Secure Block Storage, one-click applications, DNS, Dedicated Hosts, private networking, RESTful API, data backup, a full suite of managed services, 24/7/365 expert U.S.-based support, and more. To view the latest cloud offerings and pricing, please visit: [Cloud platform](https://www.atlantic.net/cloud-platform/) About Atlantic.Net Atlantic.Net is a global cloud services provider with over 25 years of experience serving thousands of developers and small, medium, and large clients in more than one hundred countries. Atlantic.Net specializes in managed and unmanaged Windows, Linux, and FreeBSD server hosting solutions and has served dynamic business clients including Lenovo, Newegg, NASA, and Hilton, among others. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions backed by 24/7/365 support in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. For more information, please visit [Atlantic.Net](https://www.atlantic.net/). Contact: Email: pr@atlantic.net Ph: 321- 206-1371 --- # Oracle Linux Is Now Available on ACP > URL: https://www.atlantic.net/announcements/oracle-linux-is-now-available-on-acp/ | Published: 2022-03-11 | Updated: 2025-09-15 | Author: Alexander Wise Oracle Linux is now available on the Atlantic.Net Cloud Platform. This newly available distribution is designed for extremely high performance on a security-defined Linux platform. Oracle Linux is 100% RHEL-compatible and a genuine alternative to CentOS, which reached [end-of-life](https://www.centos.org/centos-linux-eol/) (EOL) in December 2021. CentOS is no longer officially supported by its creators, meaning no further releases are forthcoming. For power users who are already familiar with Red Hat, CentOS, and Rocky Linux, the transition to Oracle Linux will be a seamless experience. Oracle Linux has been available since 2006, and Oracle has used it directly to power their own cloud solutions. ## Why Should I Choose Oracle Linux on ACP? Oracle Linux is a completely free Linux distribution. There are no licensing requirements for Oracle Linux, a rarity for Oracle products. All Oracle Linux source code, binaries, updates, patches, and errata are free to the community. With Oracle Linux, you get a rock-solid production-ready environment with improved security, reduced downtime, and a simplified operations platform. ## The Choice of Two Kernels Oracle Linux offers the choice of two Linux Kernels: - RHCK (Red Hat Compatible Kernel) - UEK (Unbreakable Enterprise Kernel) Both are free and 100% compatible with Red Hat Enterprise Linux. ## Rock-Solid Stability The Unbreakable Enterprise Kernel (UEK) variant is enterprise-focused, offering superior stability, scalability, and performance with native support for Oracle Database.  Since Oracle launched its distribution in 2006 there has [not been one recorded bug](https://www.oracle.com/a/ocom/docs/dsc-ol-centos-replacement.pdf) relating to RHEL compatibility. ## Patch with No Downtime The Linux Kernel has always been great at on-the-fly patching. However, as the only operating system environment that offers kernel, hypervisor, and user-space live patching with no downtime required, Oracle Linux takes this a step further. It does this by applying patches using [Oracle Ksplice](https://ksplice.oracle.com/). ## The Perfect Solution for Oracle Databases IT industry professionals generally associate the word “Oracle” with the Oracle database, a solution that is synonymous with the organization’s brand name. Oracle Linux provides a native platform for your business database. Remember, Oracle owns MySQL, so nonproprietary databases work amazingly well too. ## Containerization Support Containers have become an everyday staple requirement for DevOps-focused businesses. Docker and Kubernetes are natively supported in Oracle Linux. When you combine this with support for the optional Ksplice tool, downtime of your Docker and K8s farms is a thing of the past. Oracle Linux is a very exciting product, and we are delighted to offer 64-bit editions of Oracle Linux 7.9 and Oracle Linux 8.5. It is available right now on the [ACP Cloud](https://cloud.atlantic.net/?page=userlogin) as one of our many Cloud Server operating systems that launches in less than 30 seconds. You can also enjoy all the benefits of Oracle Linux if you are currently using CentOS – Oracle offers a simple and user-friendly [migration application](https://docs.oracle.com/en/solutions/migrate-centos-ora-linux/index.html#GUID-551A6E5F-E614-4EC5-B4A5-FFFE65511625). --- Are you looking for a leading[hosting provider](https://www.atlantic.net/hosting-services-provider/) to host your Linux Operating System? Look no further than the Atlantic.Net[VPS hosting service](https://www.atlantic.net/vps-hosting/). Our[full suite of managed services](https://www.atlantic.net/managed-services/) and always-available professional support team can host your mission-critical Linux workload. Our Cloud Platform has many common operating systems and software solutions available as 1-Click applications, meaning you can spin up a fully configured server in about 30 seconds. Our platform is easy to use, flexible, and built around your needs. For faster application deployment, free IT architecture design, and assessment, visit us at[www.atlantic.net](https://www.atlantic.net), call 866-618-DATA (3282), or email us at sales@atlantic.net. You can find out more information by[contacting our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # How to Install Redis Server Using Docker Container > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-redis-server-using-docker-container/ | Published: 2022-03-12 | Updated: 2024-06-01 | Author: Hitesh Jethva Redis is a free, open-source, and in-memory key-value store that allows data to be stored and accessed at lightning-fast speeds. It can handle large datasets and maintain high availability. Generally, it is used for database, messaging, and caching functions. Running Redis in a Docker container can significantly shorten and simplify the deployment process. In this post, we will show you how to install Redis using a Docker container. ## Step 1 – Install Docker CE Before starting, Docker CE must be installed on your server. If not installed, you can install it by following the below steps. First, update your OS, then add the Docker CE repo with the following commands: ``` dnf update -y ``` ``` dnf config-manager --add-repo=https://download.docker.com/linux/centos/docker-ce.repo ``` Once the Docker CE repo is created, run the following command to start the installation: ``` dnf install docker-ce -y ``` Once the Docker CE is installed, start the Docker service and enable it to start at system reboot: ``` systemctl start docker systemctl enable docker ``` #### Also Read [How to Install and Use Docker on CentOS 8](https://www.atlantic.net/vps-hosting/how-to-install-and-use-docker-on-centos-8/) ## Step 2 – Download Redis Image First, you will need to download the Redis image from the Docker Hub registry. You can download it with the following command: ``` docker pull redis ``` You will get the following output: ``` Using default tag: latest latest: Pulling from library/redis 5eb5b503b376: Pull complete 6530a7ea3479: Pull complete 91f5202c6d9b: Pull complete 9f1ac212e389: Pull complete 82c311187b72: Pull complete da84aa65ce64: Pull complete Digest: sha256:0d9c9aed1eb385336db0bc9b976b6b49774aee3d2b9c2788a0d0d9e239986cb3 Status: Downloaded newer image for redis:latest docker.io/library/redis:latest ``` Once the Redis image is downloaded, verify the downloaded image using the following command: ``` docker images ``` You will get the following output: ``` REPOSITORY TAG IMAGE ID CREATED SIZE redis latest f1b6973564e9 5 days ago 113MB ``` ## Step 3 – Create a Redis Container At this point, the Redis image is downloaded to your local system. You can now start a Redis container using the following command: ``` docker run -it --name redis-container -d redis ``` Once the Redis container is created, you can check it with the following command: ``` docker ps ``` You will get the following output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 64163c8ed78d redis "docker-entrypoint.s…" 3 seconds ago Up 2 seconds 6379/tcp redis-container ``` You can also see the Redis container log using the following command: ``` docker logs redis-container ``` You will get the following output: ``` _._ _.-``__ ''-._ _.-`` `. `_. ''-._ Redis 6.2.6 (00000000/0) 64 bit .-`` .-```. ```\/ _.,_ ''-._ ( ' , .-` | `, ) Running in standalone mode |`-._`-...-` __...-.``-._|'` _.-'| Port: 6379 | `-._ `._ / _.-' | PID: 1 `-._ `-._ `-./ _.-' _.-' |`-._`-._ `-.__.-' _.-'_.-'| | `-._`-._ _.-'_.-' | https://redis.io `-._ `-._`-.__.-'_.-' _.-' |`-._`-._ `-.__.-' _.-'_.-'| | `-._`-._ _.-'_.-' | `-._ `-._`-.__.-'_.-' _.-' `-._ `-.__.-' _.-' `-._ _.-' `-.__.-' 1:M 01 Feb 2022 07:08:44.564 # WARNING: The TCP backlog setting of 511 cannot be enforced because /proc/sys/net/core/somaxconn is set to the lower value of 128. 1:M 01 Feb 2022 07:08:44.564 # Server initialized 1:M 01 Feb 2022 07:08:44.564 # WARNING overcommit_memory is set to 0! Background save may fail under low memory condition. To fix this issue add 'vm.overcommit_memory = 1' to /etc/sysctl.conf and then reboot or run the command 'sysctl vm.overcommit_memory=1' for this to take effect. 1:M 01 Feb 2022 07:08:44.564 * Ready to accept connections ``` ## Step 4 – Connect to Redis Container If you want to connect to the Redis container, run the following command: ``` docker exec -it redis-container bash ``` Once you are connected, you will get the following shell: ``` root@64163c8ed78d:/data# ``` Next, run the following command to connect to the Redis command-line interface: ``` root@64163c8ed78d:/data# redis-cli ``` Now, run the following command to check Redis: ``` 127.0.0.1:6379> ping ``` If everything is fine, you will get the following output: ``` PONG ``` Now, exit from the Redis container using the following command: ``` 127.0.0.1:6379> exit root@64163c8ed78d:/data# exit ``` ## Conclusion In the above guide, we explained how to install Redis on the Docker container. We also explained how to manage and interact with Redis containers. Try Redis on [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Enable Cloud Backups > URL: https://www.atlantic.net/vps-hosting/how-to-enable-cloud-backups/ | Published: 2022-03-14 | Updated: 2025-03-06 | Author: Alexander Wise The precious data saved on your Atlantic.Net cloud VPS needs a reliable and resilient backup solution. Backups are a critical part of data retention, and we highly recommend that our customers invest in backups to ensure that in the event of server corruption or malware you are able to restore with minimal downtime and data loss. At Atlantic.Net, we are advocates of the 3-2-1 backup strategy. To enable this approach, the Atlantic.Net Cloud Platform (ACP) is built to highly redundant architecture. Not only is the backup storage protected by RAID at a disk-level, but the entire environment is protected at the hardware layer. We are so confident in the safety of your data that we offer an industry-leading 100% SLA Agreement. Want to know more about the 3-2-1 backup strategy? [Check out this article on our blog.](https://www.atlantic.net/disaster-recovery/what-is-a-3-2-1-backup-strategy/) ## How to Enable Backups While backups are not enabled by default, enabling them is super simple. Backups can be enabled when provisioning and deploying a server or can be added to any existing Cloud Server that might already be running. *NOTE: Daily backups cost 20% of your server’s monthly price.  For example, if you have a G.34GB general-purpose cloud server that costs $20 per month, the backups will cost $2 per month.* ### Enable Cloud Backups on New Servers 1. Log in to the Atlantic.Net Cloud Console – [https://cloud.atlantic.net/](https://cloud.atlantic.net/?page=userlogin). 2. Navigate to **Servers > Add Server**. ![](https://www.atlantic.net/wp-content/uploads/2022/03/Add-Server.png) 3. Fill out the **Server Name** > choose the **Operating System** type. ![](https://www.atlantic.net/wp-content/uploads/2022/03/Server-Name.png) 4. Choose a **Location** > Select a **Term** > Choose a server **Plan**. ![](https://www.atlantic.net/wp-content/uploads/2022/03/Server-Location-Plan.png) 5. **Important:** At the bottom of the page, **tick the check box** for enabling backups and click **Create Server**. ![](https://www.atlantic.net/wp-content/uploads/2022/03/Enable-Backups.png) 6. After the server has finished provisioning, check the backup status and you will see it enabled. ![](https://www.atlantic.net/wp-content/uploads/2022/03/Backup-Status-Enabled.png) ### Enable Cloud Backups on Existing Servers If you already have an existing server, the process is simple. 1. Log into the Atlantic.Net Cloud Console – [https://cloud.atlantic.net/](https://cloud.atlantic.net/?page=userlogin) 2. Select the server you want to add a Cloud Backup to. ![](https://www.atlantic.net/wp-content/uploads/2022/03/Select-Server.png) 3. From the Server Information page, locate and press the **backups** button. ![](https://www.atlantic.net/wp-content/uploads/2022/03/Press-Backups-Button.png) 4. A prompt will appear. Select **Enable Backups**. ![](https://www.atlantic.net/wp-content/uploads/2022/03/Enable-Backups-Prompt.png) 5. Another prompt will appear that confirms the 20% charge for backups. Click **OK** if you agree to the charges. ![](https://www.atlantic.net/wp-content/uploads/2022/03/Backups-Price.png) 6. That’s it! Your backups are now enabled. The server will back up at the next backup run. A backup occurs every 24 hours on each Atlantic.Net Cloud VPS. ## Need Help with a Restore? ACP cloud backups have 2 restore options. 1. File Level Recovery 2. Full System Store ![](https://www.atlantic.net/wp-content/uploads/2022/03/Recovery-Options.png) ### How to Complete a File-Level Recovery For information on how to complete a file-level restore, please check this procedure that gives you a detailed end-to-end process to follow. [file-level recovery](https://www.atlantic.net/vps-hosting/work-with-file-level-recovery/) ### How to Complete a Full System Restore 1. Log in to the Atlantic.Net Cloud Console – [https://cloud.atlantic.net/](https://cloud.atlantic.net/?page=userlogin). 2. Select the server you want to restore. ![](https://www.atlantic.net/wp-content/uploads/2022/03/Select-Server.png) 3. From the Server Information page, locate and press the **Backups** button. ![](https://www.atlantic.net/wp-content/uploads/2022/03/Press-Backups-Button.png) 4. Select Full System Restore and choose the date you want to restore to, then click **Submit**. ![](https://www.atlantic.net/wp-content/uploads/2022/03/Full-System-Restore.png) 5. You will be greeted by the following prompt. Click **OK** to proceed. ![](https://www.atlantic.net/wp-content/uploads/2022/03/Restore-Prompt.png) 6. It will typically only take a few moments to recover the server. It depends on how big the backups are and the rate of change on the server. ![](https://www.atlantic.net/wp-content/uploads/2022/03/Request-Received.png) --- # How to Install OpenResty on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-openresty-on-rocky-linux-10/ | Published: 2022-03-16 | Updated: 2025-10-16 | Author: Hitesh Jethva OpenResty is an Nginx-based web platform that can run Lua scripts using its LuaJIT engine. It has many built-in Nginx modules that can make it a powerful web app server. OpenResty allows you to use Lua scripts inside the Nginx conf files and write a high-performance web application in Lua without installing any package. In this post, we will show you how to install OpenResty on Rocky Linux 10. ## Step 1 – Install OpenResty on Rocky Linux 10 By default, the OpenResty package is not included in the Rocky Linux 10 default repo, so you will need to add the OpenResty repo to your system. You can add it with the following command: ``` nano /etc/yum.repos.d/openresty.repo ``` Add the following lines: ``` [openresty] name=Official OpenResty Repository for RHEL/CentOS baseurl=https://openresty.org/package/rocky/9/$basearch gpgcheck=0 enabled=1 ``` Once the repo is added, run the following command to install OpenResty on Rocky Linux 10. ``` dnf install openresty -y ``` After the installation, verify the OpenResty version using the following command: ``` openresty -v ``` You will get the following output: ``` nginx version: openresty/1.27.1.2 ``` You can also install the OpenResty CLI utility using the following command: ``` dnf install openresty-resty -y ``` Next, start and enable the OpenResty service using the following command: ``` systemctl start openresty systemctl enable openresty ``` You can also check the status of OpenResty with the following command: ``` systemctl status openresty ``` You will get the following output: ``` ● openresty.service - The OpenResty Application Platform Loaded: loaded (/usr/lib/systemd/system/openresty.service; disabled; preset: disabled) Active: active (running) since Thu 2025-10-16 08:16:24 EDT; 3s ago Invocation: f8cbaf01bad3409cb6b3e91190e07b06 Process: 2208 ExecStartPre=/usr/local/openresty/nginx/sbin/nginx -t (code=exited, status=0/SUCCESS) Process: 2211 ExecStart=/usr/local/openresty/nginx/sbin/nginx (code=exited, status=0/SUCCESS) Process: 2216 ExecStartPost=/bin/sleep 1 (code=exited, status=0/SUCCESS) Main PID: 2213 (nginx) Tasks: 2 (limit: 24809) Memory: 3M (peak: 4.4M) CPU: 47ms CGroup: /system.slice/openresty.service ├─2213 "nginx: master process /usr/local/openresty/nginx/sbin/nginx" └─2214 "nginx: worker process" ``` **Also Read** [How to Install and Configure Nginx Webserver on Oracle Linux 8](https://www.atlantic.net/vps-hosting/how-to-install-and-configure-nginx-webserver-on-oracle-linux/) ## Step 2 – Create a Project with OpenResty In this section, we will create a sample hello world project using OpenResty. First, create a directory with the following command: ``` mkdir resty ``` Next, change the directory to resty and create the other required directories using the following command: ``` cd resty mkdir logs conf ``` Next, create an Nginx configuration file: ``` nano conf/nginx.conf ``` Add the following code: ``` worker_processes 1; error_log logs/error.log; events { worker_connections 1024; } http { server { listen 8080; location / { default_type text/html; content_by_lua_block { ngx.say("

hello, world

") } } } } ``` Save and close the file, then export the Nginx path with the following command: ``` PATH=/usr/local/openresty/nginx/sbin:$PATH export PATH ``` Next, start the Nginx server with the following command: ``` nginx -p `pwd`/ -c conf/nginx.conf ``` This will start an Nginx server on port **8080**. You can check it with the [ss command](https://www.atlantic.net/dedicated-server-hosting/how-to-use-linux-ss-command-with-examples/): ``` ss -antpl | grep 8080 ``` You will get the following output: ``` LISTEN 0 128 0.0.0.0:8080 0.0.0.0:* users:(("nginx",pid=8806,fd=8),("nginx",pid=8805,fd=8)) ``` ## Step 3 – Verify OpenResty Project You can now verify your OpenResty hello world project using the URL **http://your-server-ip:8080**. You should see the following page: ![Open Restry Dashboard](https://www.atlantic.net/wp-content/uploads/2022/02/p1.png) You can also use the curl command to test your project: ``` curl http://localhost:8080/ ``` You will get the following output: hello, world ## Conclusion In the above guide, we explained how to install OpenResty on Rocky Linux 10. We also created a sample hello world project and host it using OpenResty. Start working on the OpenResty platform today on [dedicated hosts](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) from Atlantic.Net! --- # Best Practices for Creating a HIPAA-Compliant NodeJS Host > URL: https://www.atlantic.net/hipaa-compliant-hosting/best-practices-for-creating-a-hipaa-compliant-nodejs-host/ | Published: 2022-03-17 | Updated: 2025-09-15 | Author: Richard Bailey ## What is NodeJS? NodeJS is an open-source, cross-platform JavaScript run-time environment for virtualizing Java applications outside of a web browser. Put simply, NodeJS is capable of providing the user with a clean environment to run JavaScript natively. NodeJS is so popular because of its performance and customization options. You can install modules on top of NodeJS that expand the functionality of the suite, such as creating virtualized application stacks running on a HTTP server. With NodeJS, creating backend services for Web Applications and Mobile Apps is easy. You can create cross-platform Application Programming Interfaces (API) in a single backend service. ## Is NodeJS Fit for Healthcare? NodeJS is a highly scalable runtime perfect for data-intensive and real-time applications. A lot of big businesses use NodeJS; two of the biggest include PayPal and [Netflix](https://openjsf.org/blog/2020/09/24/from-streaming-to-studio-the-evolution-of-node-js-at-netflix/). PayPal in particular has been vocal in its support for NodeJS. NodeJS has huge potential for rejuvenating legacy healthcare applications, as it makes porting them to mobile interfaces such as a cell phone or iPad is relatively straightforward. It can create significant advantages in the performance of older applications by handling multiple requests, rapid processing of NoSQL data, and near-instant response to queries. All of this makes NodeJS the perfect choice for hospital management applications, online forms, and electronic PHI systems. ## What Are the Requirements of a NodeJS Healthcare Application? For a NodeJS application to be HIPAA compliant, the entire software stack must meet the requirements of HIPAA legislation. This includes the software application and the underlying hardware that powers the application. The NodeJS application must comply with specific details from HIPAA’s Security Rule and Privacy Rule. Bespoke applications must follow a HIPAA compliance framework. HIPAA governance has to be at the forefront of the development process, and the application must meet the minimum security and privacy standards to ensure the confidentiality, integrity, and availability of ePHI. ## Best Practice for HIPAA-Compliant NodeJS applications? There is no predefined checklist that your developers must adhere to; instead, the application must meet the foundational principles of HIPAA’s protection of patient data. Here are our recommendations: ### Protect Your Data at All Costs Data protection is a fundamental requirement of HIPAA compliance. Not only does the application have to be capable of being backed up, but the infrastructure used to back up the program must meet legislation standards. Backups must be encrypted to AES-256 bit encryption, and backup applications (and data) should be protected with multi-factor authentication. Backup transfers need to be encrypted, and data redundancy requires at least 3 copies of the data: typically, the live data, a backup copy of the live data, and a replicated copy at an alternative location. ### Disaster Recovery [Disaster Recovery](https://www.atlantic.net/disaster-recovery/) goes hand in hand with Data Backup. DR is a key technical safeguard in HIPAA legislation, [referenced directly](https://www.hhs.gov/sites/default/files/hipaa-simplification-201303.pdf) here: “Assess the relative criticality of specific applications and data in support of other contingency plan components.” The NodeJS community has created modules that enable high availability, such as Nodemon and Supervisor. The modules can protect against network, server, and client outages. If a disaster strikes and you are required to invoke DR, choose a provider like Atlantic.Net that can failover live services from one data center to another with our Disaster Recovery managed service for HIPAA-compliant hosting customers. ### Monitoring and Logging Monitoring, logging, and auditing are becoming increasingly important for HIPAA compliance. Detailed verbose logging should monitor VPN activity, access controls, and file integrity to prevent unauthorized amendments of PHI. NodeJS applications should monitor usage, and intelligent SIEM applications are recommended to make sense of the extensive amount of data created. A permission-based authority can ensure view and edit controls are granted to the correct teams. An unauthorized user accessing or changing ePHI is a HIPAA violation; therefore, strict API controls must be implemented (GET/POST/PATCH, etc). A good example is a patient website where users can access and view medical test results or request repeat prescriptions; application developers want to ensure that the patient is only able to access the data relevant to them. ### Strict Authentication Controls Control methods must be built in to protect unauthorized access to the application. Data should only be accessible by authorized personnel who have pre-approved access to ePHI. This includes any in-scope member of the covered entity (typically doctors, nurses, and physicians). Integration with Active Directory or any other LDAP service is a great way to achieve this requirement. Access and authorization controls are written to restrict access to flagged confidential information. Code must be implemented that prevents the export of data, such as data export to an Excel file, printing a document, or the simple use of copy & paste. Link sensitive data to a UID instead of a username or, at the very least, architect your system so data is not traceable back to a single user on a first-name-last-name basis. The data should be encrypted and need a key to decrypt as it is created. In the event the database is exploited, this will prevent hackers from being able to see the data listed in plaintext. ### Partner with a HIPAA-Compliant Hosting Provider One of the best ways to meet many of the requirements of HIPAA is to outsource NodeJS application hosting to a [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) provider like Atlantic.Net. A hosting company that is HIPAA compliant will provide you with an infrastructure that is built to serve the fundamental safeguards of compliance. Make sure you choose a hosting provider that can: - Implement physical security controls to prevent unauthorized physical access to the webserver - Offer a Fully Managed Firewall or Web Application Firewall (WAF) - Provide an encrypted VPN - Provide an encrypted Data Backup plan to protect PHI - Provide a Disaster Recovery solution to ensure that PHI is continuously available - Provide forensic level logging of all activity of the host server (this is in addition to WordPress layer logging) - Monitoring and alert logging - Monitoring file changes using an Intrusion Prevention Service ## How Can Atlantic.Net Help? Are you looking for a leading [HIPAA hosting provider](https://www.atlantic.net/hipaa-compliant-hosting/) to host your NodeJS application? Look no further than Atlantic.Net. With over 30 years of proven experience, our [full suite of managed services](https://www.atlantic.net/managed-services/) and always available professional support team can build the perfect solution for your business or organization. Atlantic.Net stands ready to help you attain fast compliance with a range of certifications, such as SOC 2 and SOC 3, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/), and HITECH, all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, visit us at [www.atlantic.net](https://www.atlantic.net), call 866-618-DATA (3282), or email us at [sales@atlantic.net](mailto:sales@atlantic.net). You can find out more information by [contacting our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # How to Install OpenLiteSpeed Web Server on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-openlitespeed-web-server-on-rocky-linux-10/ | Published: 2022-03-20 | Updated: 2025-10-16 | Author: Hitesh Jethva OpenLiteSpeed is a free, open-source, lightweight web server developed by LiteSpeed ​​Technologies. Compared to Apache and Nginx, OpenLiteSpeed is known for its speed and performance. Furthermore, it also provides a web-based interface to easily manage virtual hosts, modules, and websites. **Features** - Event-driven architecture - Handles hundreds of thousands of concurrent connections - Web-based admin panel - Ability to bind certain processes to particular workers - Support of third-party modules through API - Compatibility with third-party PHP accelerators In this post, we will show you how to install an OpenLiteSpeed web server on Rocky Linux 10. ## Step 1 – Install OpenLiteSpeed Repo By default, the OpenLiteSpeed package is not included in the Rocky Linux 10 default repo, so you will need to add the OpenLiteSpeed repo to your system. You can install it using the following command: ``` wget -O - https://repo.litespeed.sh | bash ``` Once the installation is complete, you can proceed to install OpenLiteSpeed. **Also Read** [How to Install Lighttpd Web Server on Oracle Linux 8](https://www.atlantic.net/vps-hosting/how-to-install-lighttpd-web-server-on-oracle-linux-8/) ## Step 2 – Install OpenLiteSpeed Now, you can install the OpenLiteSpeed web server by running the following command: ``` dnf install openlitespeed -y ``` After the installation, start and enable the OpenLiteSpeed service with the following command: ``` systemctl start lsws systemctl enable lsws ``` You can check the status of OpenLiteSpeed with the following command: ``` systemctl status lsws ``` You will get the following output: ``` ● lshttpd.service - OpenLiteSpeed HTTP Server Loaded: loaded (/usr/lib/systemd/system/lshttpd.service; enabled; preset: disabled) Active: active (running) since Thu 2025-10-16 07:43:45 EDT; 42s ago Invocation: 91aca7015ba346019fff7bdca60082b1 Main PID: 1516 (litespeed) CGroup: /system.slice/lshttpd.service ├─1516 "openlitespeed (lshttpd - main)" ├─1523 "openlitespeed (lscgid)" ├─1536 "openlitespeed (lshttpd - #01)" ├─1537 "openlitespeed (lshttpd - #02)" └─1538 lsphp ``` By default, OpenLiteSpeed listens on port 8088. You can access it using the URL **http://your-server-ip:8088**. You should see the OpenLiteSpeed test page on the following screen: ![OpenLiteSpeed Test Page](https://www.atlantic.net/wp-content/uploads/2022/02/p1-1-1024x536.png) ## Step 3 – Setup OpenLiteSpeed Admin Password In order to access the OpenLiteSpeed admin interface, you will need to set the admin password. You can set it using the following command: ``` /usr/local/lsws/admin/misc/admpass.sh ``` You will be asked to define the admin username and password as shown below: ``` Please specify the user name of administrator. This is the user name required to login the administration Web interface. User name [admin]: admin Please specify the administrator's password. This is the password required to login the administration Web interface. Password: Retype password: Administrator's username/password is updated successfully! ``` You can now access the OpenLiteSpeed admin interface using the URL **https://your-server-ip-address:7080**. You should see the OpenLiteSpeed login screen: ![OpenLiteSpeed Login Page](https://www.atlantic.net/wp-content/uploads/2022/02/p4-1024x554.png) Provide your admin username and password and click on the **Login** button. You should see the OpenLiteSpeed dashboard on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2022/03/openlightspeed-dashboard.png) ## Step 4 – Install PHP 8.4 on OpenLiteSpeed By default, OpenLiteSpeed comes with PHP version 8.3. You can check it using the URL **http://your-server-ip-address:8088/phpinfo.php**. You should see the PHP version on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2022/03/php83.png) If you want to install PHP version 8.4, run the following command: ``` dnf install lsphp84 lsphp84-mysqlnd lsphp84-common lsphp84-xml lsphp84-mbstring lsphp84-process lsphp84-bcmath lsphp84-pdo lsphp84-soap lsphp84-gd lsphp84-opcache ``` After installing PHP 8.4, you will need to edit the httpd_config.conf configuration file and change the default PHP version to PHP 8.4: ``` nano /usr/local/lsws/conf/httpd_config.conf ``` Find the following line: ``` path $SERVER_ROOT/lsphp83/bin/lsphp ``` And replace it with the following line: ``` path $SERVER_ROOT/lsphp84/bin/lsphp ``` Save and close the file, then stop all PHP processes with the following command: ``` kill -9 `pidof lsphp` ``` Next, restart the OpenLiteSpeed service to apply the changes: ``` systemctl restart lsws ``` Now, open your web browser and verify the PHP version using the URL **http://your-server-ip-address:8088/phpinfo.php**. You should see the PHP 7.4 on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2022/03/php84.png) **Also Read** [How to Install Linux, Apache, MySQL, PHP on Ubuntu 20.04](https://www.atlantic.net/vps-hosting/how-to-install-linux-apache-mysql-php-lamp-ubuntu-20-04/) ## Conclusion In the above guide, we explained how to install the OpenLiteSpeed web server on Rocky Linux 10. We also explained how to install and change the default PHP version. You can now start creating your website using the OpenLiteSpeed web interface. Try it on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Healthcare Cloud Service Adoption: How Cloud Providers are Mitigating Risk with Patient Health Records > URL: https://www.atlantic.net/life-sciences-pharma-biotech/healthcare-cloud-service-adoption-2022-how-cloud-providers-are-mitigating-risk-with-patient-health-records/ | Published: 2022-03-21 | Updated: 2026-09-15 | Author: Richard Bailey With the exponential growth of uptake of [healthcare cloud services](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/), the healthcare cloud computing business sector is growing significantly in kind. Some conservative estimates suggest that the industry could be worth [over $40 billion by 2026](https://www.prnewswire.com/news-releases/healthcare-cloud-computing-market-to-cross-us-40-bn-by-2026-301007540.html), and back in 2014, Forbes suggested that [82% of healthcare companies had a cloud presence](https://www.forbes.com/sites/louiscolumbus/2014/07/17/83-of-healthcare-organizations-are-using-cloud-based-apps-today/#47df63863b72), a figure that has no doubt increased since.  As one of the United States’ leading healthcare cloud providers with 30 years of experience in the complex world of healthcare compliance, Atlantic.Net’s technical experts have created the world-class HIPAA-compliant hosting platform you need. But what are the major security and privacy challenges of cloud computing solutions in healthcare? ### Data Privacy & Healthcare Data privacy is seen as one of the most critical risks to cloud computing in a healthcare organization, and the protection of patient health records and all forms of protected health information (PHI) are the number one concern for our security engineers. To protect our clients, we have adopted a number of risk-mitigating activities that are designed to protect patient data. Atlantic.Net is HIPAA-compliant, HITECH audited, and SOC2 assessed. Our data centers and procedures adhere to the highest industry standards, which demonstrates to our customers that data integrity and the protection of electronic health records are our top priorities. If you are looking for a new cloud computing partner, make sure you perform detailed due diligence to ensure that their services exceed the latest HIPAA legislation rules and that the cloud computing service is the right fit for your business. ## How Is Cloud Computing Used in Healthcare? A key subject in cloud computing is the digital transformation and cloud migration projects that many organizations are undertaking as they move their critical operations into the cloud. The healthcare industry is going through a radical program of change wherein monolithic, on-premise computing services are being replaced by dynamic and intelligent cloud service offerings. ### Benefits of the Cloud for Healthcare How is cloud technology transforming the healthcare industry? Some benefits that are driving healthcare organizations to the cloud include: - **Data Storage and Scalability** – The healthcare industry is a complex machine saturated in digital patient data. Cloud data storage offers practically limitless amounts of data capacity to securely retain data in a resilient state. It is significantly easier to scale up resources in the cloud, making cloud computing the perfect prescription for growing healthcare needs. - **Collaboration and Increased Data Interoperability –**Cloud technology unlocks huge potential for collaboration and information sharing. Medical applications can share information and medical records to speed up the diagnosis process, while medical professionals can remotely collaborate on cases providing specialist care in an agile working environment. This flexibility has proven to be a game-changer during the Covid-19 pandemic, enabling [remote working collaboration](https://ruttl.com/blog/collaboration-across-borders-design-teams-in-the-age-of-remote-work/) capabilities and providing deeper patient insights. - **Artificial Intelligence** –  The massive amount of data collected by healthcare practices enables the use of big data to improve patient services. Clinical research can benefit from AI; huge data sets can be processed to predict the early detection of diseases such as cancer. AI models can recognize different data patterns, and through [annotation tools](https://www.superannotate.com/annotation-tool), they can train models to work more effectively in health systems.  - **Machine Learning** – ML is heavily utilized in diagnosis services; big data products such as [IBM Watson](https://www.ibm.com/watson) can reference an extensive collection of medical journals and case studies to predict a patient’s diagnosis. Also, Google is developing a tool called [Deepmind](https://deepmind.com/) aiming to [mimic the human brain neural networks](https://deepmind.com/about#our_story), which may also have applications in the medical industry. ## How Security and Reliability in the Cloud Help the Healthcare Industry The security and reliability of cloud solutions are two of its largest benefits to a healthcare provider. Atlantic.Net has taken significant steps to provide hardened and robust cloud services to healthcare providers. Our HIPAA cloud service is built with security as the main driver of the design process, and our customer’s data is stored in a securely architected cloud service located in geographically compliant regions.  Identity and access controls, as well as authentication and logging controls, are inherent to the design. ePHI data is encrypted at rest and in transit, a process that is managed by our encryption key management system. Cloud-based solutions over time will reduce the capital expenditure (CAPEX) of healthcare providers and institutions; there is no longer the need to buy expensive servers, networks, and storage equipment, or have extensively trained teams to support the infrastructure. Local data centers can be consolidated or potentially closed after migrating to the cloud, offering even more savings. The change to operational expenditure (OPEX) will introduce a pay-as-you-go subscription model where you only pay for the cloud solutions that you consume; heavy discounts are also offered for a 2 or 3-year commitment plan, an arrangement that will satisfy your finance team. ## What Are the Risks of Cloud Computing for a Healthcare Organization?  Ransomware, malware, and viruses are the most serious threats facing global organizations that rely on information technology, and unfortunately, healthcare providers are a prime target for malicious hacking communities. Hackers and malefactors view electronic health records as a valuable commodity. Medical providers operating in the industry have the immensely difficult task of protecting huge amounts of personal data and medical records while also satisfying the requirements of healthcare workers who need secure, rapid, efficient access to data. ### Preventing Ransomware and Viruses While maintaining HIPAA compliance may not prevent a ransomware outbreak, it creates a protective environment that makes ransomware infection highly unlikely. In the unlikely scenario that your organization is breached, HIPAA safeguards can protect the integrity of ePHI, rendering the data useless in the event it is stolen.  HIPAA compliant protections are put in place to enable the failover of technical services to a secondary location in the event of a disaster (such as a damaging ransomware event). These protections enable business-as-usual to continue in next to no time.  ### Who Must Protect Data? The risks are a joint responsibility between the covered entity (such as healthcare providers) and the cloud provider. The cloud solutions provider is duly obliged to protect ePHI and medical records at all costs, but the covered entity must also do the utmost to reduce risk. With Atlantic.Net’s HIPAA-compliant hosting and cloud computing services, we have implemented procedures that both detect and guard against malicious software, including hardware-layer protection against DDOS attacks, intrusion prevention systems that intelligently log and monitor every system, and a managed antivirus and anti-malware platform that is the operating system’s first line of defense. ## What are the Risks and Rewards for Healthcare Organizations That Use Cloud Computing? As in any industry, the adoption of new cloud computing technology will always be associated with risks. One such risk is that implementing a cloud computing strategy will create difficulties for employees in getting up to speed with new processes and tools. Staff might make mistakes, and data might be handled incorrectly. Cloud availability is another risk; our competitors have experienced major outages over the years, but only Atlantic.Net offers a [100% uptime SLA.](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/) However, the biggest risk is that of security, which is already a major concern for healthcare organizations. The good news is that cybersecurity has evolved so much in the last decade that it is now viable for the cloud provider to be one step ahead of the hackers.  Hackers will always choose the path of least resistance, so we have architected our platforms to make it as difficult as possible for hackers to gain access. Security is the number one priority of our HIPAA-compliant hosting, security that does not interrupt the user experience, but one that meets and exceeds the administrative, physical, and technical requirements of HIPAA compliance.  Our clients who are healthcare providers are reaping the rewards of committing to cloud-first technology, with huge benefits afforded to them in the form of data storage capacity and impressive reprovisioning capabilities on a secure cloud computing platform. HIPAA compliant hosting protects patient data, provides a robust and resilient service, and creates a collaborative environment perfect for healthcare professionals to interact and share ideas. ### **HIPAA Compliant Hosting** Are you in need of cloud computing solutions that can protect the patient data of your organization? At Atlantic.Net, whatever your technical requirements, we can offer a top-grade [HIPAA-Compliant Cloud Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solution. Get a [HIPAA-Cloud Cost](https://www.atlantic.net/hipaa-compliant-hosting/) from one of our experts. [Get a free consultation today!](https://www.atlantic.net/hipaa-compliant-hosting/) #### **Written by Richard Bailey** Linux, Cloud, and Lead IT Consultant with 20 years of experience.  Graduate of the University of Bradford, England. Enthusiastic about Technology, Automation, and Infrastructure as Code. Passionate writer, keen to understand and disseminate as much technical knowledge as possible. --- # IT Solutions for Healthcare: How to Choose > URL: https://www.atlantic.net/hipaa-compliant-hosting/it-solutions-for-healthcare-how-to-choose/ | Published: 2022-03-22 | Updated: 2025-08-03 | Author: Gilad Maayan Outsourcing IT for healthcare empowers an organization to meet and exceed the complex requirements of HIPAA regulations. These include all of the physical, administrative, and technical safeguards introduced by the [HHS](https://www.hhs.gov/) in 2003. ## **What Are IT Solutions for Healthcare?** Healthcare information technology (healthcare IT) is a segment of IT that includes the development, implementation, and maintenance of IT in healthcare. It is used to automate and integrate healthcare workflows to enable better patient care, [reduce operational costs](https://www.fylehq.com/expense-management-software/) due to efficiency gains, and improve collaboration.  Solutions often used in healthcare IT include: - Electronic medical records or health records (EMR/EHR) - On-call or shift planning  - Financial management and billing systems - Telehealth or remote healthcare - HIPAA-compliant devices, networks, and servers - Point-of-care devices - Registration kiosks and self-service equipment Atlantic.Net has a popular [HIPAA compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) platform where customers can create dedicated hosts or dedicated instances in next to no time. Managed services are available to wrap around all of the IT solutions on offer from Atlantic.Net. ## **How Healthcare Organizations Can Benefit From Managed IT Services** Healthcare IT solutions can be more complex than in many other industries. Infrastructures and workloads must meet strict compliance requirements, hardware and software are often specialized, and people’s lives may be at stake. Managed services can help ease this IT burden by offering several benefits to organizations.  ### What are IT Managed Services? IT managed services or managed IT services are third-party services that you can use to contract or outsource IT tasks. When you use these services, you pay a monthly fee in exchange for remote management or monitoring of your IT infrastructure. For example, there are managed services that can take over security and compliance monitoring, maintain your resources’ performance and versioning, or serve as your [incident response team](https://www.exabeam.com/incident-response/incident-response-team/). By outsourcing IT tasks, you can ensure that your IT responsibilities are covered even if you do not have the staffing or expertise to manage on your own. Service vendors can provide a guarantee of coverage or availability that can be difficult to enforce with in-house teams. They can also supplement your own teams, for example, by providing coverage during off-hours.  As cloud services become more popular, many managed service vendors have also begun managing cloud resources. Since access is already remote with these systems, managed services are easy to arrange and can often be integrated easily.  For example, some providers focus specifically on managing public cloud services. Others focus on specific cloud infrastructures, such as Kubernetes deployments, Salesforce, or private clouds.  If you engage managed services for IT with Atlantic.Net, one of the first tasks to complete is the signing of a Business Associate Agreement (BAA). The BAA is signed between a healthcare customer and Atlantic.Net, and it creates a baseline of the service guarantees on offer.  Because all our services are managed in-house, we have full control over the hosting environment; this also makes the process go much faster with no other third parties involved. The BAA can include a combination of agreements, response times, and other guarantees of the HIPAA disaster recovery solution. You can find extensive information on [what a BAA is here](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/#:~:text=The%20HIPAA%20Privacy%20Rule%20amendment,Protected%20Health%20Information%20(PHI).). ### **Overcome Compliance Challenges** Understanding how and when compliance regulations apply to data, auditing systems for compliance, training employees, and managing encryption all take a lot of work and expertise. Managed providers with healthcare experience can help provide guidance and support for in-house teams, perform certified audits, or offer higher-grade [IT security](https://www.exabeam.com/information-security/it-security/) solutions than what you can implement on your own.  ### **Improve Patient Care** Service level agreements (SLAs) with providers can help you ensure that your services remain functional and available, making patient visits and records management smoother. These providers can also help you upgrade your systems, enabling you to move to new technologies smoothly: for example, putting thin clients in patients’ rooms or implementing telehealth support. ### **Enable Workforce Mobility** A major concern for healthcare providers using technology is the distribution of protected health information (PHI). Providers need to access information from wherever they are working securely, whether that’s a hospital, an ambulance, a private office, or while on-call. Managed services, particularly those that provide cloud support, can help you ensure that data is available from wherever providers need it without sacrificing privacy. These services can help you implement encryption uniformly and continuously monitor data access and sharing to ensure security is maintained.  With managed IT services, all you need to do is choose either a dedicated or shared hosting tenancy. Atlantic.Net will do the rest to onboard you into our award-winning, HIPAA-compliant hosting service.  ### **Enhanced Cyber-Security** Looking after the welfare of patients is a healthcare organization’s top priority, and rightly so, but most healthcare practices are now fully realizing that [cybersecurity](https://www.sailpoint.com/identity-library/five-types-of-cybersecurity/) is a critical function of healthcare in the digital age.  The protections we offer and the security layers of the infrastructure are sufficient to protect data in most circumstances ### **Network Firewalls** Our network architects have designed an intrinsically secure network infrastructure that isolates and protects your service, resulting in a fully private managed environment that only you have access to. Hardware and software firewalls are utilized strategically around the perimeter and internal networks.  We offer an optional [Web Application Firewall](https://www.atlantic.net/hipaa-compliant-hosting/why-waf-configuration-matters-for-the-healthcare-industry/) (WAF), which is a policy-defined device that protects web applications by monitoring and filtering traffic via Network Edge Protection. ### **Encrypted as Standard** Amazingly, encryption is not outlined as a mandatory part of HIPAA compliance, but covered entities must have a roadmap to achieving encryption to enhance data management. At Atlantic.Net, our service is fully encrypted by default, and managed by an advanced Key Management System (KMS). All in-scope PHI data is [encrypted at rest](https://www.atlantic.net/hipaa-compliant-hosting/why-is-encryption-so-key-to-hipaa-compliance/), and in the unlikely event the data is intercepted, it will be completely unreadable or recoverable without the key. ### **Fully Encrypted Virtual Private Network** An encrypted VPN is a mandatory step to achieving HIPAA compliance. The VPN is a secure, encrypted network connection between the end-user and a corporate network. The technology allows you to connect to the hosted infrastructure over any whitelisted internet connection with a valid username and password, with additional protection offered with Multi-Factor Authentication. The VPN creates a [secured network tunnel](https://www.atlantic.net/hipaa-data-centers/hipaa-compliant-it-infrastructure-guide/) to safely transmit sensitive data without the risk of data being compromised. ### **Backups and Disaster Recovery ** Another strict requirement of HIPAA compliant hosting is the demand for healthcare IT solutions to back up and restore protected health information whenever required. A managed backup service can answer all of your backup needs. A backup schedule is created per your organizational requirements, and we recommend our customers test the restore process regularly.  File-level and VM-level backups and snapshots are available, as well as[offsite replication services](https://www.atlantic.net/disaster-recovery/). In the event of a disaster scenario, our optional service will manage the hosting platform failover to infrastructure into a secondary location. ### **Robust Log Management** For compliance purposes, all infrastructure services must have detailed logging available that can be monitored by our internal support groups or other experts. This includes system alerts, system errors, user activity, and VPN activity to name but a few. ### **Intrusion Prevention Service ** An IPS is placed at strategic points within the cloud network and work with the firewall by inspecting packets that the firewall has already accepted as legitimate. The IPS resides directly on the network, protecting against local vulnerabilities at the network layer. ### **24x7x365 Support** Since the health needs of patients never stop, why would your support for your IT needs stop?  Atlantic.Net’s support teams are available 24x7x365, and we always have someone available at the end of a phone line. The IT support teams are encouraged to develop and grow their expertise with advanced training, helping to ensure our customers get the support they need the first time they call. ## **Choosing a Managed IT Service for Your Healthcare Organization** When considering managed IT services, there are several aspects to consider before you plan to [rent a developer](https://www.esparkinfo.com/hire-dedicated-developer.html). You want to ensure that the provider of services understands your specific needs and can provide you with the greatest ROI.  Healthcare professionals have invested heavily in IT within the industry, and the rate of digital transformation to either cloud hosting or managed hosting is significant. The Covid-19 pandemic has highlighted the importance of managed services, as hospitals, clinics, and millions of home workers have been able to rely on HIPAA hosting to get the job done. ### **Breadth of Services** Ideally, you should be able to get one managed service provider for all of your IT needs. This includes on-premises resources, cloud resources, and any specialized software or hardware you may have. Every vendor you contract with requires access to your systems and a business associate agreement to ensure [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/), so the fewer providers you have, the better.  This doesn’t mean you need to transfer your IT responsibilities all at once, however. Instead, look for a vendor that supports the bulk of your needs and start small to ensure that they are reliable. For example, you may have them manage your cloud storage for archived data or medical records.  ### **Total Cost of Ownership (TCO)** Over time the TCO will reduce capital expenditure (CAPEX) and become very cost-effective; there is no longer the need to buy expensive servers, networks, and storage equipment, or have extensively trained teams to support the infrastructure. System Administrators and IT support personnel are expensive to hire and train, but access to our cloud company experts is included in the service.  Customer-owned data centers can be consolidated or potentially closed. The change to operational expenditure (OPEX) will introduce a predictable pay-as-you-go subscription model where you only pay for the services that you consume; heavy discounts are offered for a 2- or 3-year commitment plan, an arrangement that will satisfy your finance team. ### **Improved Performance and Reliability ** You are guaranteed system resources 24/7. Host nodes are scaled and load balanced to ensure no customer suffers from the noisy neighbor syndrome, meaning you always have the resources you need, on-demand.  Atlantic.Net invests heavily in computing hardware, with SSD exclusive storage layers, the very latest Intel CPU architecture, and a network layer that operates at breakneck speed. Performance that simply cannot be matched with a DIY model. ### **Less to Worry About** Outsourcing your healthcare hosting requirements to a managed hosting provider like Atlantic.Net will shift much of the responsibility of securing PHI. The Final Omnibus rule of HIPAA compliance places the responsibility firmly in the hands of the Managed Service Provider.  This responsibility is something Atlantic.Net has handled for well over 15 years, so we look forward to welcoming you aboard! Let us handle the complexity of compliance and managed hosting, while you focus on the well-being of patients. ### **Scalability and Flexibility** The ability to adapt configurations, resources, and availability to changing workload needs is one of the tougher parts of IT management. When contracting out services, you should verify that the provider you choose is capable of these tasks.  You want a provider who can continue to support you when you get new software or when you choose to migrate legacy applications to the cloud. If providers cannot help you adapt your system to meet changing needs, they cannot provide long-term value.  ### **Compliance Awareness** Ensure that any provider you choose is aware of exactly what compliance regulations apply to you and how they apply. This is critical if you are using cloud services since the location your data is stored can play an important role. For example, the GDPR standards apply to EU citizens’ data regardless of where a provider is operating or managing data.  ## **IT Solutions for Healthcare with Atlantic.Net** Atlantic.Net has more than 30 years of experience exceeding the needs of health professionals and is one of the country’s leading healthcare technology companies. If you’re in this industry and you need help with IT, contact our sales team to find out how our managed services could help your organization. If you are in the market for managed IT services for healthcare, make sure you choose an experienced HIPAA compliant provider that focuses on security, business continuity, and scalability: a provider that can grow with you, and one that focuses on collaboration and data interoperability. We know that the regulations of the industry are intense, but Atlantic.Net can take away the stress of managing your entire IT operation. We have an extensive list of healthcare clients who have trusted us for many years, and our managed service packages really do allow you to forget about the complexities of IT and focus on your patients. We will protect your infrastructure from the very latest cybersecurity threats, as well as manage upgrades and maintenance behind the scenes. We will work with you to identify and secure PHI, protect you from ransomware attacks, and offer you the very best Healthcare Managed Services platform available. Atlantic.Net offers[HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and[HIPAA Compliant Cloud Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) services to support IT Solutions for Healthcare. --- # Penetration Testing Guide Best Penetration Testing Practices You Need To Know > URL: https://www.atlantic.net/vps-hosting/best-penetration-testing-practices-you-need-to-know/ | Published: 2022-03-23 | Updated: 2025-10-21 | Author: Alexander Wise ## **What is Penetration Testing?** If your organization relies on the Internet to conduct business, you need to perform penetration tests regularly. [Penetration testing](https://www.getastra.com/blog/security-audit/penetration-testing/) is the practice of launching a simulated cyberattack on your system to identify flaws that hackers may attack. By identifying and fixing these vulnerabilities, you can improve the security of your systems and protect your data from being stolen or compromised. This blog post will discuss the best practices for penetration testing and how to choose a good penetration testing service provider. ## Features Of A Good Penetration Testing Tool When looking for a [penetration testing tool](https://www.atlantic.net/vps-hosting/most-popular-penetration-testing-tools-in-2021/), there are particular features you should look for. The tool should be able to simulate a wide range of attacks, including: - Brute force attacks - Denial of service attacks - SQL injection attacks - Cross-site scripting attacks It should also include modules for reconnaissance, information gathering, and [vulnerability scanning](https://www.atlantic.net/dedicated-server-hosting/how-to-protect-and-secure-website-infrastructure/). The tool should be easy to use and have a user-friendly interface. It should also be updated regularly with the latest security patches and vulnerabilities so that you can stay ahead of the latest threats. ## Why Is Penetration Testing Important? Penetration testing has become an integral part of every security program. It is the best way to identify potential vulnerabilities before a cyber attacker can exploit them. Penetration tests can be performed internally by your own penetration testers or externally using third-party service providers who have experience with conducting these types of assessments on behalf of other organizations such as banks, hospitals, and government agencies. The goal is always the same: find weaknesses in your system so that you may fix them before someone else does. If you don’t do this, there’s no point in having any kind of cybersecurity because hackers will keep finding new ways around whatever defenses might exist today (and tomorrow). ## How To Choose A Good Penetration Testing Service? It would help if you considered several factors when choosing a penetration testing service provider. - **Experience:** Ensure the company has extensive experience in performing these types of assessments. - **Keep Up-to-Date:** Make sure the company follows up on all the current, latest vulnerabilities and exploits that could be used against your organization. - **Reputation:** Check the company’s reputation for delivering outstanding services through acquaintances and verified reviews. - **Comprehensiveness:** Ensure the company’s ability to provide a holistic assessment covering all areas of your systems and networks. ## **Penetration Testing Considerations** In brief, here are the points to keep in mind when looking for a good penetration testing service: - Look for providers who have experience in your industry. - Ask for references and case studies. - Make sure the provider has a good understanding of your requirements. - Check that they have the necessary tools and resources to carry out the assessment effectively. - Get a quote before making a decision! “Is this something I need?” Is a commonly asked question, however, seeing the rising trends in cyberattacks across various industries like banking or healthcare, the answer becomes an obvious yes. Choosing to do penetration testing and choosing the right penetration testing tool for your needs helps you achieve your goal of a cyber-safe user-friendly platform like no other! Regular [software penetration testing](https://www.getastra.com/blog/security-audit/software-penetration-testing/) is the most effective technique for protecting your company against cyber assaults. By identifying and fixing vulnerabilities before they are exploited, you can improve the security of your systems and protect your data from being stolen or compromised. ## What Are The Best Penetration Testing Practices? Penetration testing should be performed regularly by a team of skilled professionals who have experience identifying and fixing vulnerabilities in various types of systems and networks. These tests are typically scheduled once per year, but some organizations may choose to do them twice each time as part of their security program. The assessment usually begins with an external vulnerability scan that looks for common problems such as open ports on [firewalls](https://www.atlantic.net/managed-services/firewall/) or weak passwords used by employees within the company’s network environment. After this initial step has been completed successfully, internal scans will follow suit so that any internal flaws can also be uncovered. Finally, after all steps are complete (external and internal scans, plus vulnerability assessment), the team will provide a detailed report of their findings to management with specific recommendations on how to fix the vulnerabilities that have been identified. Hopefully, this post has given you a better understanding of [why penetration testing is important](https://www.atlantic.net/pci-compliant-hosting/security-penetration-testing-need/) for organizations and some tips on how to choose a good service provider. Stay safe out there. ## How To Perform A Penetration Test Performing a penetration test is not as difficult as you might think. Here are the steps involved: - **Step One:** Plan your attack scenario. - **Step Two:** Gather information about the target network, including what operating system it runs on and any other vulnerable applications or services which might be running on its servers (such as web servers). You may also want to know what type of encryption they use for their data transfer protocol so that you can plan your attack accordingly. - **Step Three:** Once you have gathered all this information, it is time to start planning how you will [carry out your penetration test](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-penetration-testing-checklist/) – i.e., get access into the network via a backdoor exploit or brute force login attempts? It’s worth noting here that there are many different ways in which hackers gain unauthorized access these days, so don’t limit yourself. Also, take note of anything unusual happening within their network infrastructure that might indicate an active attack (e.g., unusual traffic patterns). - **Step Four:** Decide which tools you will need for the job – this could include anything from [advanced malware detection software](https://www.atlantic.net/hipaa-compliant-hosting/what-is-malware-how-it-works-and-how-to-remove-it/) to basic web browser extensions such as [Firebug](https://en.wikipedia.org/wiki/Firebug_(software)) or [Burp Suite Pro](https://nl.wikipedia.org/wiki/Burp_Suite). It may also involve some manual work like installing backdoors into vulnerable applications and services running on target machines (or even just brute-forcing logins). - **Step Five:** Now it’s time to execute your plan! This step involves using all those different tools at once so make sure they are compatible with each other before starting; otherwise, things could get messy very quickly indeed! For example, suppose you’re trying to use [Wireshark](https://en.wikipedia.org/wiki/Wireshark) while running an [antivirus program](https://www.atlantic.net/vps-hosting/antivirus-vs-anti-malware-whats-difference/) like Avast. In that case, this might not work so well because they will both be scanning every packet coming into your computer looking for signs of malware which could cause problems when analyzing network traffic. - **Step Six:** Finally, once everything has been executed successfully you should now have gained access as a legitimate user within the target system whereupon further actions can take place (e.g., installing backdoors or remotely controlling machines). This step also includes reporting back on what was found during the execution phase (such as whether any vulnerabilities were exploited successfully), followed by recommendations for how these could be mitigated in future tests. ## Good Tools For Penetration Testing Here is a list of some good tools that can help you get started with penetration testing: - **Astra’s Pentest Suite:**   A commercial pen-testing tool designed to carry out professional penetration tests, containing over 3000 tests. Astra’s Pentest Suite offers users an automated and continuous vulnerability scanner, vulnerability management dashboard, and manual pen-testing. This tool is used by large companies like Ford, Cosmopolitan, HotStar, Gillette, Dream11, Meta, and more. - **Kali Linux:** A Debian-based Linux distribution designed specifically for security professionals, hackers, and system administrators. It’s one of the most popular hacking tools today because it provides everything needed to perform basic reconnaissance tasks, such as scanning networks or sniffing traffic; advanced attacks like installing backdoors in vulnerable applications running on target machines (or even just brute-forcing logins). - **Nmap:** A port scanner that can find open services running on remote hosts/networks. It also has an interactive shell that allows users to type commands directly into their terminal window without having access to any other programs on their computer at all! - **GFI LANGuard Network Security Scanner:** A free tool that’s great for beginners. It scans through all ports on your network and checks for any vulnerabilities present in applications running locally or remotely connected devices such as printers and routers. - **Burp Suite Pro:** This is a paid-for professional suite of tools that can be used to perform different types of attacks such as SQL injection and cross-site scripting (XSS). This program also includes many other advanced features like intercepting requests/responses between web browsers (which makes it easier when debugging websites), scanning files within archives before downloading them from remote hosts. - **Wireshark:** An open-source packet analyzer with support for multiple protocols, including IPv* protocols like TCP/IP, UDP, and SCTP. This tool can be used to capture packets as they travel across a network and then save them into a file for further analysis. These are just some of the many different tools that can be used for penetration testing – so it’s important to do your own research before starting out in order to find the ones that best suit your needs. ## Levels Of Penetration Testing - **Level 1-** This is a more cost-effective process of scanning for vulnerabilities in order to establish a list of external threats to your network or system. This level of penetration testing is perfect for companies just looking to ensure that their security systems are well placed. - **Level 2-** This level of penetration testing is more cost-intensive and is well suited for companies within industries that are at higher targeted risk for security breaches, hacking, and data theft. It is more painstaking in the sense that each vulnerability, security failure has to be identified, exploited, reported, and then managed thus mimicking a real-life security threat. ## How Much Does Penetration Testing Cost? This depends on several factors, such as the size and complexity of the target network and the tools required. In general, though, you may expect to pay anything from $500 to $5,000 for a basic penetration test. ## Conclusion Penetration testing is an essential component of network security. It can help detect vulnerabilities that hackers and other cybercriminals could exploit and uncover weaknesses in your systems that might otherwise go unnoticed until it’s too late. ### How can Atlantic.Net Help? Atlantic.Net provides a world-class infrastructure for organizations to secure their most valuable asset – their data. Our Managed Services provide a full suite of services, designed to make your cloud strategy a success. With powerful services like Intrusion Detection Service, Managed Firewall, Network Edge protection, Trend Micro Services services; we stand ready to assist you with all your security and compliance needs! Share your vision with us, and we will develop a hosting environment tailored to your needs! Contact an advisor at 866-618-DATA (3282) or email [sales@atlantic.net](mailto:sales@atlantic.net) today. --- #### Read More About Intrusion Detection - [Intrusion Detection Service](https://www.atlantic.net/managed-services/intrusion-detection-service/) from Atlantic.Net - [Intrusion Detection Systems](https://www.atlantic.net/hipaa-compliant-hosting/intrusion-detection-systems/) from Atlantic.Net - [What Is an Intrusion Detection System?](https://www.atlantic.net/dedicated-server-hosting/what-is-an-intrusion-detection-system-and-why-do-i-need-it/) --- --- # How to Install and Configure NFS Server on Debian > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-nfs-server-on-debian/ | Published: 2022-03-24 | Updated: 2025-09-02 | Author: Hitesh Jethva NFS, also called “Network File System,” is a network file-sharing protocol that allows us to share and mount a remote file system over the network. It works in a client-server architecture and allows multiple systems or users to access the same shared folder or file. With NFS, you can share a common application among multiple users, eliminating the need for local disk space and reducing storage costs. This post will show you how to install and configure an NFS server on Debian 12. ## Step 1 – Update Server Once logged in to your server, run the following command to update your base system with the latest available packages. ``` apt-get update -y ``` ## Step 2 – Install NFS Server The NFS package is included in the Debian 12 default repository by default. You can install it by just running the following command: ``` apt-get install nfs-kernel-server -y ``` Once the NFS server has been installed, you can proceed to the next step. #### Also Read [How to Install FTP Server with ProFTPD on Oracle Linux 8](https://www.atlantic.net/vps-hosting/how-to-install-ftp-server-with-proftpd-on-oracle-linux-8/) ## Step 3 – Create the Export Directory Next, you must create a directory you want to share with the client machine. You can create it with the following command: ``` mkdir /nfsshare ``` Next, create some files inside the shared directory: ``` touch /nfsshare/file1.txt touch /nfsshare/file2.txt ``` Next, set proper permissions on the created directory: ``` chown nobody:nogroup /nfsshare chmod 755 /nfsshare ``` #### Also Read [How to Use chown (Change Ownership) Command in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-use-chown-change-ownership-command-in-linux/) ## Step 4 – Configure the Export Directory Next, you must edit the NFS server’s main configuration file and define the directory path you want to share. You can do it with the following command: ``` nano /etc/exports ``` Add the next line: ``` /nfsshare nfs-client-ip(rw,sync,no_subtree_check) ``` **Where**: - **RW** – Provide read and write access to the shared directory. - **sync** – Reply to requests only after the changes have been committed to stable storage. - **no_subtree_check** – Disables subtree checking. Save and close the file when you are finished. Finally, restart the NFS service to apply the changes: ``` systemctl restart nfs-server ``` You can check the status of NFS using the following command: ``` systemctl status nfs-server ``` You will get the following output: ``` ● nfs-server.service - NFS server and services Loaded: loaded (/lib/systemd/system/nfs-server.service; enabled; vendor preset: enabled) Active: active (exited) since Tue Sep 2 01:01:36 PM UTC 2025; 6s ago Process: 2117 ExecStartPre=/usr/sbin/exportfs -r (code=exited, status=0/SUCCESS) Process: 2118 ExecStart=/usr/sbin/rpc.nfsd $RPCNFSDARGS (code=exited, status=0/SUCCESS) Main PID: 2118 (code=exited, status=0/SUCCESS) CPU: 7ms Tue Sep 2 01:01:36 PM UTC 2025 nfsserver systemd[1]: Starting NFS server and services... Tue Sep 2 01:01:36 PM UTC 2025 nfsserver systemd[1]: Finished NFS server and services. ``` ## Step 5 – Install and Configure NFS Client Next, you must install the NFS client package on the remote system and access the NFS share. Run the following command to install the NFS client package: ``` apt-get install nfs-common -y ``` Now, mount the remote shared directory on the /mnt directory using the following command: ``` mount nfs-server-ip:/nfsshare /mnt ``` Next, verify the NFS mount using the following command: ``` df -h ``` You should see the NFS mount in the following output: ``` Filesystem Size Used Avail Use% Mounted on udev 976M 0 976M 0% /dev tmpfs 199M 388K 198M 1% /run /dev/sda1 50G 1.5G 46G 4% / tmpfs 992M 0 992M 0% /dev/shm tmpfs 5.0M 0 5.0M 0% /run/lock tmpfs 199M 0 199M 0% /run/user/0 69.28.91.99:/nfsshare 50G 1.5G 46G 4% /mnt ``` You can also list all files inside the shared directory using the following command: ``` ls -l /mnt ``` You will get the following result: ``` -rw-r--r-- 1 root root 0 Jan 29 05:49 file1.txt -rw-r--r-- 1 root root 0 Jan 29 05:50 file2.txt ``` ## Conclusion In the above guide, we explained how to set up an NFS server on Debian 12. We also explained how to access the NFS share from the client machine. Create a file server for your organization on [dedicated hosts](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) from Atlantic.Net! --- # Announcing Windows Server 2022 Datacenter Desktop Experience > URL: https://www.atlantic.net/announcements/announcing-windows-server-2022-datacenter-desktop-experience/ | Published: 2022-03-25 | Updated: 2025-09-15 | Author: Alexander Wise The Atlantic.Net Cloud Platform (ACP) announced support for Windows Server 2022 in November 2021. We were one of the very first cloud providers to offer the very latest version of Microsoft’s award-winning Operating System. Today we are proud to support the Windows Server 2022 Datacenter Desktop Experience, a finely tuned desktop-focused edition customized for the Atlantic.Net cloud platform. You can spin up a Windows Server 2022 Datacenter Desktop Experience instance right now! Simply log on to the [ACP Cloud Console](https://cloud.atlantic.net/?page=userlogin) and then: 1. Select Add Server 2. Give it a name 3. Choose a location 4. Choose a plan 5. Select additional options 6. Click create. Windows will be built and configured automatically and you will be able to log in after about 90 seconds. ## What Makes the Atlantic.Net Desktop Experience Unique? If you have ever built a vanilla installation of Windows Server, you will understand that the installation and initial configuration stage is often time-consuming, with Microsoft seemingly putting obstacles in your path to get the configuration you want and need. Our Professional Services team has created the Desktop Experience edition to remedy this problem. Not only will the server launch in under 30 seconds and be fully operational in under 90 seconds, but the Desktop Experience edition is tweaked to give you the best possible experience. Some highlights of our Desktop Experience edition:h - We disabled IE Enhanced Security protection by default. Don’t be alarmed, as many consider this “feature” unnecessary and annoying since it seemingly blocks almost everything you try to browse on the Internet. We turn off this feature and instead offer security built into Microsoft Edge, Firefox, and Chrome browsers. - We fine-tuned the HD video and audio experience (we recommend at least 2GB RAM or more for the best [HD video](http://renderforest.com/) experience). - We have improved the base performance of Windows Server 2022 to take advantage of the Atlantic.Net Cloud Platform. Running applications now take preference over background services, resulting in a smoother experience with less resource usage. - We have bundled in Google Chrome and Mozilla Firefox browsers. - Dot Net Framework 4.8 is installed by default to make your application experience a much smoother proposition. ## Windows Server 2022 on the Atlantic.Net Cloud Windows Server 2022, the latest Windows Server product from Microsoft, along with Windows 2019, Windows Server 2016, and Windows 2012, are all available as Virtual Private Cloud Servers (VPS) from Atlantic.Net. Atlantic.Net’s Windows Server Hosting plans start at only $0.0238095 per hour (or $16.00 per month), with usage calculated on a per hour basis. For a limited time, Atlantic.Net is offering all new clients a free-to-use Windows Server 2022 Cloud Server for one full year on the G3.2GB Cloud Server plan, which includes 3 TB of outbound data transfer. The Atlantic.Net Cloud Platform provides fault-tolerant, ultra-fast performance, and includes award-winning Cloud Servers, Secure Block Storage, one-click applications, DNS, Dedicated Hosts, private networking, RESTful API, data backup, a full suite of managed services, 24x7x365 expert U.S.-based support, and more. To view the latest cloud offerings and pricing, please visit: [Our Cloud Platform page](https://www.atlantic.net/cloud-platform/) --- # Cloud Backup vs. Local Backup: The Safest Way to Store Data > URL: https://www.atlantic.net/vps-hosting/cloud-backup-vs-local-backup-the-safest-way-to-store-data/ | Published: 2022-03-29 | Updated: 2026-03-02 | Author: Alexander Wise The decision about whether cloud backup or local backup is the safest way to store your data often comes down to your specific backup needs. Inexpensive and a cinch to set up, cloud backup was once mainly associated with small businesses that lacked the resources for elaborate hardware systems. Today, cloud storage adoption is a popular solution for many organizations. Imagine a SaaS company that has established itself as an expert in its niche through its robust off-page SEO techniques and [guest blogging](https://accelerateagency.ai/how-to-guest-blog) efforts. Such a growing business will typically be adding more and more cloud capabilities for users. Fortunately, new cloud storage and backup vendors are following on their heels to provide simple, scalable cloud backup solutions for organizations that need to protect valuable SaaS data. Local backup options are also still evolving, albeit more modestly. Which is the safest way to store data? This article evaluates the pros and cons of each backup option. ## The 3-2-1 Rule [The 3-2-1 rule](https://www.atlantic.net/disaster-recovery/what-is-a-3-2-1-backup-strategy/) is the industry best practice backup strategy where you keep multiple copies of your data in different places, across two different types of storage, with at least one copy stored offsite, such as in the cloud. Keeping multiple copies of critical data is a demonstrable no-brainer. And the cloud allows IT administrators to perform multiple backups more cost-effectively by [replacing your physical tape backups](https://www.atlantic.net/dedicated-server-hosting/replace-your-physical-tape-backups-with-atlantic-net-cloud-backups-and-save/). Typically, businesses already need to back up a dizzying array of devices. What’s more, they could also be going as far as looking to invent an app to grow their startup. That means choosing a cloud provider that can protect data stored on mobile devices and support other operating system requirements. Businesses can implement the 3-2-1 rule using a single vendor with a handful of advanced providers. ## What Is Cloud Backup? [Cloud backup](https://www.atlantic.net/cloud-platform/backups/) is when an organization backs up its system, devices, and data to another location, usually on a cloud-based server. A cloud backup service enables organizations to comply with industry regulations, improve their data protection, and restore information in the event of a disaster. The data gets copied over a network to a cloud-based server that can be either private or public. Some organizations have the resources to back up their cloud data on-premise on existing storage infrastructure. Alternatively, cloud options allow organizations to back up their data to an offsite server hosted by a public cloud service provider, like Atlantic.Net. Today, cloud-to-cloud backup is another option. The success of software as a service depends on having a firm grasp of [essential SaaS metrics](https://accelerateagency.ai/essential-saas-metrics) to learn how their customers tick. And businesses are eager to purchase from a slew of products on-demand from each new SaaS business. Such data that originates in the cloud can be backed up at another geographically diverse data center cloud. A hybrid backup uses traditional backup for some data while storing other data in the cloud. A [Managed Veeam Service](https://www.atlantic.net/managed-services/veeam-services/), for example, offers on-site storage for local backups and offsite storage in data center locations. ## What Is Local Backup? Local backup is the traditional strategy of backing up data on local servers at offices or premises using disk-based hardware. Sometimes, smaller businesses may also use an external hard drive for a basic form of local backup. Interestingly, some businesses have started to back up their SaaS data to a local device. For example, you might be familiar with how AI is revolutionizing content marketing with digital asset management solutions. This allows companies to streamline tedious tasks such as hunting for digital assets in the wilderness of their cloud storage. In a new twist to the cloud backup and local backup story, such data originating in the cloud is sometimes backed up on local storage. ## Cloud Backup Advantages Cloud backup is less expensive than purchasing and maintaining the hardware required for an on-premises backup system. Organizations can avoid an upfront capital purchase. Cloud backup can be a cheap way of setting up data protection for those that can’t afford a separate disaster recovery location. ### Disaster Recovery If a disaster occurs, cloud backup means that data remains safely stored in the cloud. Offices and systems, including local backups, can be destroyed in an on-site catastrophe, but a remote cloud storage solution that offers [data backup for your cloud server](https://www.atlantic.net/disaster-recovery/how-to-data-backup-cloud-server/) ensures your information is safe. ### Recovery Speed Disaster recovery can be swifter after a data failure or loss at an on-site location since there’s no physical equipment to contend with in recovering files. ### Security As cloud service providers have developed from new technology to a highly competitive industry, cloud backup safety worries have receded. Backup products now come with an array of security features such as end-to-end encryption that keep data safe. An experienced cloud provider can offer better security for small-to-medium-sized businesses that may not have dedicated cybersecurity experts to maintain and manage local backup. ### Protection Another safety consideration is the ever-looming threat of cybercriminal attacks. Bad actors can target your on-premises systems, compromising and destroying both your production data and local backups. Keeping an offsite backup protects data in the cloud. That said, no data that gets copied across networks is wholly safe from hackers. So be under no illusions about the security trade-offs even cloud backup entails. ## Cloud Backup Disadvantages ### Recovery Speed With a cloud backup, speed limits and thresholds can stall your efforts to download a full backup if you manage large amounts of data, and depending on the volume of data and your internet bandwidth, there can also be significant costs involved. This can easily be mitigated with a service called [Snapshots](https://www.atlantic.net/vps-hosting/creating-and-managing-snapshots/#restore_snap). ### Data Loss at Contract End Pay attention to your cloud provider’s policy if you decide to cancel your contract. Be sure to check how long the cloud provider will keep your data upon the contract end, so you have enough time to download your backup to avoid any data loss. ## Advantages of Local Backup The benefits of having a local backup include: ### On-site Accessibility Local backup with data stored in external hard drives, for example, delivers onsite accessibility. And because disk-based backups are usually continuous, they allow users to go back to specific points in time. ### Security Local backup can bring peace of mind that an organization’s infrastructure is protected. Sometimes, organizations backup data to tape for offline protection against ransomware attacks. Once the data is stored and the drive is disconnected, it’s safe from malicious attacks that affect your network. ### Fast Recovery Local backup doesn’t depend on an Internet connection, so it’s much faster to backup and recover large volumes of data compared to a cloud backup. ### Control Cloud providers can store your backups in different locations across states and even countries. But with a local backup, you always know where potentially sensitive data is. ## Disadvantages of Local Storage ### Disaster Recovery Since local backups are only accessible from the physical storage medium, a disaster affecting your premises could destroy your local backup system. While bringing offsite backups in for updating any data changes takes more work, having an additional copy of your backup is a recommended extra layer of protection. ### Security Cyberattacks such as ransomware that hit your primary systems often target your local backups to prevent you from restoring your data, so you’re more likely to cough up the ransom. In the event of such an attack, having an offsite backup – be it on tape or in the cloud – is essential for a clean restore. ## Cloud Backup Versus Local Backup: Which Is Safest? When comparing each option, what counts as an advantage in one situation can be disadvantageous in another. So businesses need to tailor their solutions to their specific data protection needs. What can we conclude, then, given the relative, sometimes conflicting merits of each type of backup? Certainly, a hybrid backup strategy, where you use a mix of cloud and local backups, provides additional security against possible data loss and cover for your organization. Because no matter which strategy you adopt and the security measures your IT team and cloud provider put in place, a cyberattack can always has the potential to compromise either local or cloud backup. If your local backup is deleted during an attack, you’ll still be able to recover using your cloud backup and restore your systems to a pre-attack condition. Conversely, in the rare event when a public cloud backup faces a data breach or data gets lost due to a disaster that affects the cloud provider’s infrastructure, you’ll still have your local copy to fall back on. Consider a final concrete example. Think about organizations that use SaaS applications that, for example, enable companies to stay ahead of the curve by personalizing websites. Backing up SaaS data here is essential. Sure, SaaS providers will ensure their infrastructure complies with Service Level Agreements. However, service backup and recovery are your responsibility as a business. So a local backup of essential data is recommended, along with cloud-to-cloud backups, ensuring all irreplaceable business data and personal customer data remain obtained throughout the [full sales cycle process](https://www.dialpad.com/blog/sales-cycle/) remain protected. ## Over to You While organizations are increasingly choosing cloud storage, cloud backup isn’t an adequate solution for all data types. An on-premises backup strategy relying on private data centers continues to make sense for some businesses. The surge in popularity of cloud backup testifies to its considerable advantages. But the key takeaway is that every backup strategy is unique. Yet more and more enterprises are settling on hybrid backup solutions that adhere to the 3-2-1 rule. A mix of automated cloud backup solutions and local backup for critical data can ensure businesses against most data loss events – a cloud with a silver lining if you will. ### How can Atlantic.Net Help? Atlantic.Net provides world-class infrastructure for organizations to secure their most valuable asset – their data. Atlantic.Net Cloud Platform provides a perfect solution for organizations to not only secure their data on a stable and secure platform but also enables them to choose from eight global locations to diversify their cloud backup strategy. In addition, our Managed Services provide a full suite of services, designed to make your cloud strategy a success. With powerful services like Veeam Backup, Server Management, Migration Services, and a full suite of security services; we stand ready to assist you with all your cloud services needs! Share your vision with us, and we will develop a hosting environment tailored to your needs! Contact an advisor at 866-618-DATA (3282) or email [sales@atlantic.net](mailto:sales@atlantic.net) today. *This article was contributed by Nick Brown founder & CEO of Accelerate Agency, a digital marketing agency.* --- #### Read More About Backup Server Solutions - Get a [Backup Server](https://www.atlantic.net/cloud-platform/backups/) from Atlantic.Net - [What Is a 3-2-1 Backup Strategy?](https://www.atlantic.net/disaster-recovery/what-is-a-3-2-1-backup-strategy/) --- --- # How to Install and Use Pigz to Compress a File in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-pigz-to-compress-file-in-linux/ | Published: 2022-03-31 | Updated: 2023-11-16 | Author: Hitesh Jethva Pigz stands for “Parallel Implementation of GZip,” which is a compression tool used to compress and uncompress files in Linux. It is written using the most commonly used zipping library functions. Pigz is the improved version of the older gzip utility that leverages multiple cores and processors to compress data. It can be able to archive larger files much faster than with gzip. In this post, we will show you how to compress and decompress files in parallel using Pigz in Linux. ## Install Pigz By default, the Pigz package is included in the default repository of all major Linux distributions. For Debian and Ubuntu distributions, install the Pigz utility using the following command: ``` apt-get install pigz -y ``` For CentOS, Rocky Linux, RHEL, and Fedora distributions, install the Pigz utility using the following command: ``` dnf install pigz -y ``` After the installation, verify the Pigz version using the following command: ``` pigz --version ``` You will get the following output: ``` pigz 2.6.1 ``` ## Compress a File with Pigz To compress a single file with the default options, use the following syntax: ``` pigz filename ``` For example, to compress a file named linux.iso, run the following command: ``` pigz linux.iso ``` This will compress the linux.iso file and save it as linux.iso.gz in your current working directory. The above command will also delete the original file after compression. If you don’t want to delete the original file, use the -k option: ``` pigz -k linux.iso ``` Also Read [How to Install LFTP to Download and Upload Files in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-pigz-to-compress-file-in-linux/) ## Compress a Directory with Pigz Pigz does not provide an option to compress the directory directly. You will need to use the tar command with the Pigz command to compress the directory. ``` tar cf - /etc/ | pigz > etc.tar.gz ``` The above command will compress the **/etc** directory and saves it as **etc.tar.gz**. ## List the Content of the Compress File You can use the -l option with the Pigz command to list the content of the compressed file: ``` pigz -l linux.iso.gz ``` You will get the following output: ``` compressed original reduced name 228799 209715200 99.9% linux.iso ``` ## Define Compression Method Pigz supports different compression methods during the compression process. You can use any method depending on your needs. Here is the list of different compression methods: - **-9** Slowest and best compression - **-1** Fastest and less compression - **-0** No compression - **-6** Default compression For example, to compress the file named **linux.iso** with the “less compression” method, run the following command: ``` pigz -1 linux.iso ``` Also Read [How to Use Zip and Unzip Command in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-use-zip-and-unzip-commands-in-linux/) ## Change the Compression Format By default, the Pigz command saves the file in gzip format. You can also use the different options to change the default format. To compress the file in **zlib** format, run the following command: ``` pigz -k -z linux.iso ``` To compress the file in **zip** format, run the following command: ``` pigz -k -K linux.iso ``` ## Define Processors During Compression Pigz allows you to define the number of processors and cores during the file compression. You can use the -p option to define the processor. ``` pigz -9 -k -p2 linux.iso ``` This command will compress the file using the best compression method and 2 processors while keeping the original file: ## Decompress a File with Pigz After compressing the file, you can use the **pigz -d** or**unpigz** commands to uncompress the file. For example, to uncompress the file **linux.iso.gz**, run the following command: ``` pigz -d linux.iso.gz ``` Or ``` unpigz linux.iso.gz ``` ## Conclusion In this post, we explained how to use the Pigz command-line utility to compress and uncompress files and directories. If you are using a modern multi-processor, multi-core system and want to compress a large file with the best results, then the Pigz is the best option for you. Try it on [dedicated hosts](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) from Atlantic.Net! --- # How to Download File Using Wget in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-download-file-using-wget-in-linux/ | Published: 2022-04-04 | Updated: 2024-06-01 | Author: Hitesh Jethva Wget is a Linux command-line utility that downloads files and web pages from the internet. It supports several internet protocols, including HTTP, HTTPS, and FTP, to access and retrieve the files. You can use different options with the wget command to perform various tasks. The wget utility is handy on slower and unstable internet connections. The wget command keeps trying until the entire file has been retrieved in case of a download failure. **Features** - Downloads multiple files at once. - Define download speed and bandwidth limit. - Allows resuming a failed download. - Download complete web and FTP sites. - Support for SSL/TLS for encrypted downloads. - Download files through proxies. In this post, we will show you how to use the wget command to download files in Linux. ## Install wget in Linux By default, the wget package comes pre-installed on all major Linux operating systems. If not installed, you can follow the below steps to install it. For Debian and Ubuntu operating systems, install wget using the following command: ``` apt-get install wget -y ``` For RHEL, CentOS, Rocky Linux, and Fedora operating systems, install wget using the following command: ``` dnf install wget -y ``` #### Also Read [How to Install LFTP to Download and Upload Files in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-install-lftp-to-download-and-upload-files-in-linux/) ## Download a File with wget Command The basic syntax to download a file using the wget command is shown below: ``` wget [option] [URL] ``` To download a single file, run the following command: ``` wget https://repo.skype.com/latest/skypeforlinux-64.deb ``` This will download a file named **skypeforlinux-64.deb** to your current working directory: ``` Connecting to get.skype.com (get.skype.com)|52.174.193.75|:443... connected. HTTP request sent, awaiting response... 302 Found Location: https://repo.skype.com/latest/skypeforlinux-64.deb [following] --2022-03-16 08:45:16-- https://repo.skype.com/latest/skypeforlinux-64.deb Resolving repo.skype.com (repo.skype.com)... 23.50.252.171, 2405:200:1630:18af::1263, 2405:200:1630:189c::1263 Connecting to repo.skype.com (repo.skype.com)|23.50.252.171|:443... connected. HTTP request sent, awaiting response... 200 OK Length: 140790360 (134M) [application/x-debian-package] Saving to: ‘skypeforlinux-64.deb’ skypeforlinux-64.deb 100%[=================================================================>] 134.27M 2.10MB/s in 64s 2022-03-16 08:46:20 (2.09 MB/s) - ‘skypeforlinux-64.deb’ saved [140790360/140790360] ``` ## Download Multiple Files Using wget Command You can also download multiple files by specifying various URLs with the wget command. ``` wget http://ftp.gnu.org/gnu/wget/wget-1.11.4.tar.gz https://curl.se/download/curl-7.82.0.tar.gz ``` This will download multiple files in your current working directory: ``` HTTP request sent, awaiting response... 200 OK Length: 1475149 (1.4M) [application/x-gzip] Saving to: ‘wget-1.11.4.tar.gz’ wget-1.11.4.tar.gz 100%[=================================================================>] 1.41M 293KB/s in 4.9s 2022-03-16 08:51:01 (293 KB/s) - ‘wget-1.11.4.tar.gz’ saved [1475149/1475149] --2022-03-16 08:51:01-- https://curl.se/download/curl-7.82.0.tar.gz Resolving curl.se (curl.se)... 151.101.2.49, 151.101.66.49, 151.101.130.49, ... Connecting to curl.se (curl.se)|151.101.2.49|:443... connected. HTTP request sent, awaiting response... 200 OK Length: 4106857 (3.9M) [application/x-gzip] Saving to: ‘curl-7.82.0.tar.gz’ curl-7.82.0.tar.gz 100%[=================================================================>] 3.92M 3.26MB/s in 1.2s 2022-03-16 08:51:04 (3.26 MB/s) - ‘curl-7.82.0.tar.gz’ saved [4106857/4106857] FINISHED --2022-03-16 08:51:04-- Total wall clock time: 15s Downloaded: 2 files, 5.3M in 6.1s (891 KB/s) ``` ## Download the File with a Different Name Generally, the wget command will download and save a file with its original name. You can use the -O option with the wget command to save a file with a different name. ``` wget -O wget.tar.gz http://ftp.gnu.org/gnu/wget/wget-1.11.4.tar.gz ``` This will download the file and save it with a different name: ``` Resolving ftp.gnu.org (ftp.gnu.org)... 209.51.188.20, 2001:470:142:3::b Connecting to ftp.gnu.org (ftp.gnu.org)|209.51.188.20|:80... connected. HTTP request sent, awaiting response... 200 OK Length: 1475149 (1.4M) [application/x-gzip] Saving to: ‘wget.tar.gz’ wget.tar.gz 100%[=================================================================>] 1.41M 231KB/s in 6.2s 2022-03-16 08:55:27 (231 KB/s) - ‘wget.tar.gz’ saved [1475149/1475149] ``` #### Also Read [How to Install and Use Pigz to Compress Files in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-pigz-to-compress-file-in-linux/) ## Download the File in a Specified Location The wget command downloads the file in your current working directory by default. You can use the **-P** option to download the file in a specified directory: ``` wget -P /tmp/ http://ftp.gnu.org/gnu/wget/wget-1.11.4.tar.gz ``` Output: ``` Connecting to ftp.gnu.org (ftp.gnu.org)|209.51.188.20|:80... connected. HTTP request sent, awaiting response... 200 OK Length: 1475149 (1.4M) [application/x-gzip] Saving to: ‘/tmp/wget-1.11.4.tar.gz.1’ wget-1.11.4.tar.gz.1 100%[=================================================================>] 1.41M 227KB/s in 6.3s 2022-03-16 08:58:07 (227 KB/s) - ‘/tmp/wget-1.11.4.tar.gz.1’ saved [1475149/1475149] ``` ## Download Multiple Files From a File You can use the **-i** option to specify a file containing a list of URLs to be downloaded. First, create a file named download-list.txt: ``` nano download-list.txt ``` Add all URLs from where you want to download files: ``` http://ftp.gnu.org/gnu/wget/wget-1.11.4.tar.gz http://www.openssl.org/source/openssl-0.9.8h.tar.gz https://curl.se/download/curl-7.82.0.tar.gz ``` Save and close the file, then run the wget command by specifying the download-list.txt file as shown below: ``` wget -i download-list.txt ``` This will download all files one by one, as shown below: ``` Length: 1475149 (1.4M) [application/x-gzip] Saving to: ‘wget-1.11.4.tar.gz’ wget-1.11.4.tar.gz 100%[=================================================================>] 1.41M 142KB/s in 10s 2022-03-16 09:06:19 (143 KB/s) - ‘wget-1.11.4.tar.gz’ saved [1475149/1475149] Length: 3439981 (3.3M) [application/x-gzip] Saving to: ‘openssl-0.9.8h.tar.gz’ openssl-0.9.8h.tar.gz 100%[=================================================================>] 3.28M 4.44MB/s in 0.7s 2022-03-16 09:06:21 (4.44 MB/s) - ‘openssl-0.9.8h.tar.gz’ saved [3439981/3439981] Length: 4106857 (3.9M) [application/x-gzip] Saving to: ‘curl-7.82.0.tar.gz’ curl-7.82.0.tar.gz 100%[=================================================================>] 3.92M 4.50MB/s in 0.9s 2022-03-16 09:06:22 (4.50 MB/s) - ‘curl-7.82.0.tar.gz’ saved [4106857/4106857] FINISHED --2022-03-16 09:06:22-- Total wall clock time: 13s Downloaded: 3 files, 8.6M in 12s (755 KB/s) ``` ## Resume Uncompleted Download Using wget Command If you are trying to download a large file and it stops due to a slow or unstable internet connection, you can use the**-c** option to resume downloading the same file where it left off. ``` wget -c https://curl.se/download/curl-7.82.0.tar.gz ``` Output: ``` --2022-03-16 09:11:11-- https://curl.se/download/curl-7.82.0.tar.gz Resolving curl.se (curl.se)... 151.101.2.49, 151.101.66.49, 151.101.130.49, ... Connecting to curl.se (curl.se)|151.101.2.49|:443... connected. HTTP request sent, awaiting response... 206 Partial Content Length: 4106857 (3.9M), 753031 (735K) remaining [application/x-gzip] Saving to: ‘curl-7.82.0.tar.gz’ curl-7.82.0.tar.gz 100%[+++++++++++++++++++++++++++++++++++++++++++++++++++++============>] 3.92M 4.23MB/s in 0.2s 2022-03-16 09:11:11 (4.23 MB/s) - ‘curl-7.82.0.tar.gz’ saved [4106857/4106857] ``` ## Ignore SSL Certificate Check While Downloading You can use the **–no-check-certificate** option to ignore SSL certificate checks while downloading files over HTTPS. ``` wget --no-check-certificate https://curl.se/download/curl-7.82.0.tar.gz ``` Output: ``` --2022-03-16 09:14:07-- https://curl.se/download/curl-7.82.0.tar.gz Resolving curl.se (curl.se)... 151.101.2.49, 151.101.66.49, 151.101.130.49, ... Connecting to curl.se (curl.se)|151.101.2.49|:443... connected. HTTP request sent, awaiting response... 200 OK Length: 4106857 (3.9M) [application/x-gzip] Saving to: ‘curl-7.82.0.tar.gz’ curl-7.82.0.tar.gz 100%[=================================================================>] 3.92M 4.40MB/s in 0.9s 2022-03-16 09:14:08 (4.40 MB/s) - ‘curl-7.82.0.tar.gz’ saved [4106857/4106857] ``` ## Set Download Speed Limit The wget command will also allow you to set a speed limit on a slower internet connection. You can use the **–limit-rate** option to set the speed limit. For example, to set the speed limit to 10k, run the following command: ``` wget -c --limit-rate=10k https://curl.se/download/curl-7.82.0.tar.gz ``` You should see the following output: ``` --2022-03-16 09:17:36-- https://curl.se/download/curl-7.82.0.tar.gz Resolving curl.se (curl.se)... 151.101.2.49, 151.101.66.49, 151.101.130.49, ... Connecting to curl.se (curl.se)|151.101.2.49|:443... connected. HTTP request sent, awaiting response... 200 OK Length: 4106857 (3.9M) [application/x-gzip] Saving to: ‘curl-7.82.0.tar.gz’ curl-7.82.0.tar.gz 3%[=> ] 159.22K 10.0KB/s eta 6m 26s ``` ## Download a File From Password Protected FTP Server The wget command lets you specify a username and password to download a file from the password-protected FTP server. You can use the following syntax to download a file from the password-protected FTP server: ``` wget --ftp-user=username --ftp-password=password ftp://ftp.server.com/filename.tar.gz ``` ## Create a Mirror of Entire Website You can use the **-m** option to create a complete local copy of the website by downloading all website files, including CSS, JavaScript, and images. ``` wget -m https://linuxbuz.com ``` If you want to use the downloaded website for local browsing, you can use some extra options with the wget command: ``` wget -m -k -p https://linuxbuz.com ``` ## Conclusion In this post, we explained using the wget command with different options to download files from the remote URLs. You can now use the wget command according to your needs. Try it on [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Change or Set User Passwords in Linux > URL: https://www.atlantic.net/vps-hosting/how-to-change-or-set-user-passwords-in-linux/ | Published: 2022-04-06 | Updated: 2023-11-18 | Author: Hitesh Jethva When working in a Linux operating system, a password is the first line of defense to secure the system. It is recommended to change the user password in Linux to reinforce security and make the system harder to breach. passwd is a command-line utility in Linux used to update a user’s authentication password stored in /etc/shadow file. A root or superuser can change the password of any user account while a normal user can only change the password for his/her own account. When changing a user password in Linux, you should follow the below guidelines: - A password must be strong, at least eight characters or more. - Use both upper and lowercase letters to make to the password strong. - Avoid any dictionary word, your name, surname, or your birth date in a password. In this post, we will show you how to change or set user passwords in Linux. ## Change Your User Password If you want to change your own password, use the passwd command-line utility as shown below: ``` passwd ``` You will be asked to provide your existing password in order to set the new password. Once the password is correct, you will be asked to provide a new password as shown below: ``` Changing password for vyom. (current) UNIX password: Enter new UNIX password: Retype new UNIX password: passwd: password updated successfully ``` After setting up a new password, you can use it on the next login. **Also Read** [How to Install and Use Ping Command in Linux](https://www.atlantic.net/vps-hosting/how-to-install-and-use-the-ping-command-in-linux/) ## Change Another User’s Password Only a root user or a user with sudo privileges can change the password of another user. Use the following syntax to change the password of the other user: ``` sudo passwd username ``` For example, to change the password of the user named **vyom**, run the following command: ``` sudo passwd vyom ``` You will be asked to provide and confirm the new password: ``` Enter new UNIX password: Retype new UNIX password: passwd: password updated successfully ``` ## Force User to Change a Password at Login If you are working in a multi-user environment, then it is recommended to force a user to change their password the next time they log in. Use the following command to force the user named **hitesh** to change a password at the next login: ``` sudo passwd --expire hitesh ``` This command will expire the user password. When the user tries to log in with the old password, they will see a message asking them to change their password: ``` ssh hitesh@server-ip ``` You should see the following message: ``` hitesh@192.168.0.10's password: You are required to change your password immediately (root enforced) WARNING: Your password has expired. You must change your password now and login again! Changing password for hitesh. (current) UNIX password: Enter new UNIX password: Retype new UNIX password: passwd: password updated successfully ``` **Also Read** [How to Find the Total Size of a Directory in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-find-the-total-size-of-a-directory-in-linux/) ## Conclusion In this guide, we explained how to set or change a user password in Linux. This procedure will work on any Linux operating system including Ubuntu, Debian, RHEL, Fedora, CentOS, Rocky Linux, Oracle Linux, Alpine, Arch, and more. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install LFTP to Download and Upload Files in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-lftp-to-download-and-upload-files-in-linux/ | Published: 2022-04-08 | Updated: 2024-06-01 | Author: Hitesh Jethva LFTP is a Linux command-line utility that downloads and uploads files from one server to another. It can transfer files via FTP, FTPS, HTTP, HTTPS, FISH, SFTP, BitTorrent, and FTP over HTTP proxy. It also supports the FXP protocol that allows data transfers between two FTP servers bypassing the client machine. It offers some valuable features. Some of them are listed below: - File directories recursive copying - Segmented file transfer - Recursive copying of file directories - Resuming partial downloads - Transfer queues This post will show you how to install and use LFTP to download and upload files in Linux. ## Install LFTP By default, the LFTP package is included in the official repository of all major Linux operating systems. For Ubuntu and Debian operating systems, use the following command to install the LFTP package: ``` apt-get install lftp -y ``` For CentOS, RHEL, and Fedora operating systems, use the following command to install the LFTP package: ``` dnf install lftp -y ``` Once LFTP is installed, verify the LFTP version using the following command: ``` lftp --version ``` You will get the following output: ``` LFTP | Version 4.9.2 | Copyright (c) 1996-2020 Alexander V. Lukyanov LFTP is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. ``` #### Also Read [How to Download Files Using Wget in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-download-file-using-wget-in-linux/) ## Configure LFTP Passwordless Access LFTP supports SSH protocol, so it is a good idea to configure passwordless authentication between two servers. To do so, generate an SSH key with the following command: ``` ssh-keygen -t rsa ``` You should see the following output: ``` Generating public/private rsa key pair. Enter file in which to save the key (/root/.ssh/id_rsa): Enter passphrase (empty for no passphrase): Enter same passphrase again: Your identification has been saved in /root/.ssh/id_rsa. Your public key has been saved in /root/.ssh/id_rsa.pub. The key fingerprint is: SHA256:gBnx9dwo3RXNgdaaDjpVBIPjNY507+HQtquTjxiwFXs root@vyompc The key's randomart image is: +---[RSA 2048]----+ | o. . .oo.==.| | = . B B.= .o| | o o +.@ O o | | . +o= B | | .SooEB o | | +o. = | | . .. . . | | oo.. | | . o+. | +----[SHA256]-----+ ``` Next, copy the newly generated SSH key to the remote Linux server using the following command: ``` ssh-copy-id root@remote-server-ip ``` You will get the following output: ``` /usr/bin/ssh-copy-id: INFO: Source of key(s) to be installed: "/root/.ssh/id_rsa.pub" The authenticity of host '216.98.10.172 (216.98.10.172)' can't be established. ECDSA key fingerprint is SHA256:Bj/4/r1XP0LQ0Vl2LMsfywLX5vu5Zaqr723K7wGUvkY. Are you sure you want to continue connecting (yes/no)? yes /usr/bin/ssh-copy-id: INFO: attempting to log in with the new key(s), to filter out any that are already installed /usr/bin/ssh-copy-id: INFO: 1 key(s) remain to be installed -- if you are prompted now it is to install the new keys Password: Number of key(s) added: 1 Now try logging into the machine, with: "ssh 'root@216.98.10.172'" and check to make sure that only the key(s) you wanted were added. ``` Next, verify the SSH passwordless authentication using the following command: ``` ssh root@remote-server-ip ``` If everything is fine, you will get the remote server shell in the following output: ``` Linux linux 5.10.0-11-amd64 #1 SMP Debian 5.10.92-1 (2022-01-18) x86_64 The programs included with the Debian GNU/Linux system are free software; the exact distribution terms for each program are described in the individual files in /usr/share/doc/*/copyright. Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. root@linux:~# ``` #### Also Read [How To Set Up SSH Public and Private Key in Linux](https://www.atlantic.net/vps-hosting/how-to-set-up-ssh-public-and-private-key-in-linux/) ## How to Use LFTP in Linux Before using the LFTP, you must connect to the FTP or SFTP server via a command-line interface. The basic syntax to login into FTP or SFTP server is shown below: ``` lftp sftp://user@sftp-server-ip ``` Or ``` lftp ftp://user@ftp-server-ip ``` Let’s connect to the SFTP server with the following command: ``` lftp sftp://root@216.98.10.172 ``` Once you are connected to the SFTP server, you will get the LFTP shell in the following output: ``` lftp root@216.98.10.172:~> ``` You can now use the ls command to list all files and directories: ``` lftp root@216.98.10.172:~> ls ``` You will get the following output: ``` drwx------ 4 root root 4096 Mar 16 02:46 . drwxr-xr-x 18 root root 4096 Mar 16 02:44 .. -rw-r--r-- 1 root root 570 Jan 31 2010 .bashrc drwxr-xr-x 3 root root 4096 Nov 22 2019 .local -rw-r--r-- 1 root root 161 Jul 9 2019 .profile drwx------ 2 root root 4096 Mar 16 02:46 .ssh ``` ## Upload and Download Files Using LFTP You can use the **pget** command to download files from the SFTP server. For example, to download a file named file1.txt from the SFTP server to your local machine, run the following command inside the LFTP shell: ``` lftp root@216.98.10.172:~> pget file1.txt ``` You will get the following output: ``` 104857600 bytes transferred in 58 seconds (1.73 MiB/s) ``` You can use the **put** command to upload files to the SFTP server. For example, to upload a file named file2.txt to the SFTP server from the local machine, run the following command: ``` put file2.txt ``` You will get the following output: ``` 10485760 bytes transferred in 21 seconds (499.1 KiB/s) ``` You can use the mirror command to download the whole directory from the SFTP server. ``` mirror /etc /opt/ ``` This command will download the **/etc** directory from the SFTP server to the local machine inside **/opt** directory. If you want to upload a directory to the SFTP server from the local machine, use the**mirros -R** command: ``` mirror -R /var/www/html /mnt/ ``` This will upload a directory named **/var/www/html** from the local machine to the SFTP server inside the **/mnt** directory. Finally, run the **exit** command to exit from the LFTP shell. ``` exit ``` ## Conclusion In this post, we explained how to use the LFTP command to download and upload a file and directory to and from the SFTP server. You can now try to use the LFTP command to transfer files and directories to the FTP server. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Suricata IDS on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-suricata-ids-on-rocky-linux-10/ | Published: 2022-04-10 | Updated: 2025-10-15 | Author: Hitesh Jethva Suricata is a free, open-source, independent threat detection engine developed by the Open Information Security Foundation. It is a flexible, high-performance intrusion detection system (IDS), intrusion prevention system (IPS), and network security monitoring (NSM) tool that can detect and block attacks against your network. The IDS analyses network traffic and detects known attacks by matching signatures, while the IPS has the ability to stop a packet from being delivered depending on the attack detected. In this post, we will show you how to install Suricata IDS on Rocky Linux 10. ## Step 1- Install Suricata on Rocky Linux 10 By default, Suricata is not included in the Rocky Linux default repo, so you will need to install it from the EPEL repo. Enable EPEL and the necessary DNF plugins. ``` dnf install -y epel-release dnf-plugins-core ``` The Open Information Security Foundation (OISF) maintains Suricata packages for Enterprise Linux families. You can enable a COPR repository using the following command. ``` dnf copr enable @oisf/suricata-7.0 ``` Now, install Suricata. ``` dnf install -y suricata ``` Once Suricata is installed, you can proceed to the next step. Also Read [How to Install Config Server Firewall (CSF) on Oracle Linux 8](https://www.atlantic.net/vps-hosting/how-to-install-config-server-firewall-csf-on-oracle-linux-8/) ## Step 2 – Configure Suricata Suricata uses several rules to alert to matching threats. All rules are located inside the**/etc/suricata/rules/** directory. You can see them with the following command: ``` ls /usr/share/suricata/rules// ``` You will get the following output: ``` app-layer-events.rules dnp3-events.rules ftp-events.rules ipsec-events.rules mqtt-events.rules quic-events.rules smtp-events.rules tls-events.rules decoder-events.rules dns-events.rules http2-events.rules kerberos-events.rules nfs-events.rules rfb-events.rules ssh-events.rules dhcp-events.rules files.rules http-events.rules modbus-events.rules ntp-events.rules smb-events.rules stream-events.rules ``` You can update all rules using the following command: ``` suricata-update ``` You will get the following output: ``` 15/10/2025 -- 06:00:50 - -- Using data-directory /var/lib/suricata. 15/10/2025 -- 06:00:50 - -- Using Suricata configuration /etc/suricata/suricata.yaml 15/10/2025 -- 06:00:50 - -- Using /usr/share/suricata/rules for Suricata provided rules. 15/10/2025 -- 06:00:50 - -- Found Suricata version 7.0.12 at /usr/sbin/suricata. 15/10/2025 -- 06:00:50 - -- Loading /etc/suricata/suricata.yaml 15/10/2025 -- 06:00:50 - -- Disabling rules for protocol pgsql 15/10/2025 -- 06:00:50 - -- Disabling rules for protocol modbus 15/10/2025 -- 06:00:50 - -- Disabling rules for protocol dnp3 15/10/2025 -- 06:00:50 - -- Disabling rules for protocol enip 15/10/2025 -- 06:00:50 - -- No sources configured, will use Emerging Threats Open 15/10/2025 -- 06:00:54 - -- Testing with suricata -T. 15/10/2025 -- 06:01:02 - -- Done. ``` Next, you will need to configure Suricata to define the network interface and IP address for the network interface. First, find the network interface and IP address of your server with the following command: ``` ip --brief add ``` You can see that the interface is eth0 and IP address is 209.23.8.4. ``` lo UNKNOWN 127.0.0.1/8 ::1/128 ens3 UP 69.28.84.193/23 ens4 UP ``` Now, edit the Suricata configuration file: ``` nano /etc/suricata/suricata.yaml ``` Define your IP address and network interface as shown below: ``` HOME_NET: "[209.23.8.4]" EXTERNAL_NET: "!$HOME_NET" af-packet: - interface: ens3 default-rule-path: /var/lib/suricata/rules rule-files: - suricata.rules ``` Save and close the file, then disable the packet offloading in Suricata using the following command: ``` ethtool -K ens3 gro off lro off ``` Next, you will need to edit the **/etc/sysconfig/suricata** file and define the network interface on which Suricata is listening. ``` nano /etc/sysconfig/suricata ``` Change the following line: ``` OPTIONS="-i ens3 --user suricata " ``` Save and close the file when you are finished. Then, start and enable the Suricata service with the following command: ``` systemctl enable --now suricata ``` Next, check the status of Suricata using the following command: ``` systemctl status suricata ``` You will get the following output: ``` ● suricata.service - Suricata Intrusion Detection Service Loaded: loaded (/usr/lib/systemd/system/suricata.service; enabled; preset: disabled) Active: active (running) since Wed 2025-10-15 06:05:38 EDT; 9s ago Invocation: eecc8ccb1c894d79a608c651b54f34dd Docs: man:suricata(1) Process: 56169 ExecStartPre=/bin/rm -f /var/run/suricata.pid (code=exited, status=0/SUCCESS) Main PID: 56170 (Suricata-Main) Tasks: 7 (limit: 12342) Memory: 985.2M (peak: 1G) CPU: 6.570s CGroup: /system.slice/suricata.service └─56170 /sbin/suricata -c /etc/suricata/suricata.yaml --pidfile /var/run/suricata.pid -i ens3 --user suricata ``` ## Step 3 – Check Suricata Logs Suricata provides various log files to check the Suricata process, alerts, and stats. To check the Suricata process log, run the following command: ``` tail /var/log/suricata/suricata.log ``` You should see the following output: ``` [56170 - Suricata-Main] 2025-10-15 06:05:45 Warning: af-packet: ens3: AF_PACKET tpacket-v3 is recommended for non-inline operation [56170 - Suricata-Main] 2025-10-15 06:05:45 Info: runmodes: ens3: creating 1 thread [56170 - Suricata-Main] 2025-10-15 06:05:45 Info: unix-manager: unix socket '/var/run/suricata/suricata-command.socket' [56172 - W#01-ens3] 2025-10-15 06:05:45 Info: ioctl: ens3: MTU 1500 [56170 - Suricata-Main] 2025-10-15 06:05:45 Notice: threads: Threads created -> W: 1 FM: 1 FR: 1 Engine started. ``` To check the Suricata alert log, run the following command: ``` tail -f /var/log/suricata/fast.log ``` You should see the following output: ``` 10/15/2025-06:07:10.843166 [**] [1:2403317:103810] ET CINS Active Threat Intelligence Poor Reputation IP group 18 [**] [Classification: Misc Attack] [Priority: 2] {TCP} 20.163.15.43:41370 -> 69.28.84.193:8443 10/15/2025-06:07:22.116273 [**] [1:2402000:7527] ET DROP Dshield Block Listed Source group 1 [**] [Classification: Misc Attack] [Priority: 2] {TCP} 204.76.203.231:43697 -> 69.28.84.193:654 10/15/2025-06:07:27.654114 [**] [1:2402000:7527] ET DROP Dshield Block Listed Source group 1 [**] [Classification: Misc Attack] [Priority: 2] {TCP} 87.120.191.13:54246 -> 69.28.84.193:8728 ``` To check the Suricata stats log, run the following command: ``` tail -f /var/log/suricata/stats.log ``` You should see the following output: ``` ------------------------------------------------------------------------------------ Counter | TM Name | Value ------------------------------------------------------------------------------------ capture.kernel_packets | Total | 651 decoder.pkts | Total | 651 decoder.bytes | Total | 51754 decoder.ipv4 | Total | 398 decoder.ipv6 | Total | 251 decoder.ethernet | Total | 651 ``` ## Step 4 – Test Suricata IDS At this point, Suricata IDS is installed and configured. Now, it’s time to test whether the Suricata IDS is working or not. To test it, log in to another system and install the Nmap utility to perform a DDoS attack. ``` dnf install nmap ``` After installing Nmap, perform a DDoS attack with the following command: ``` nping --tcp -p 22 --flags SYN --rate 1000 --count 10000 69.28.84.193 ``` Now, go to the Suricata system and check the alert log using the following command: ``` tail -f /var/log/suricata/fast.log ``` You should see the following output: ``` 10/15/2025-06:12:51.924577 [**] [1:2500016:7410] ET COMPROMISED Known Compromised or Hostile Host Traffic group 9 [**] [Classification: Misc Attack] [Priority: 2] {TCP} 36.140.33.10:36929 -> 69.28.84.193:22 10/15/2025-06:13:24.491969 [**] [1:2402000:7527] ET DROP Dshield Block Listed Source group 1 [**] [Classification: Misc Attack] [Priority: 2] {TCP} 147.185.132.10:55831 -> 69.28.84.193:22 10/15/2025-06:13:24.860635 [**] [1:2400031:4495] ET DROP Spamhaus DROP Listed Traffic Inbound group 32 [**] [Classification: Misc Attack] [Priority: 2] {TCP} 178.22.24.60:52601 -> 69.28.84.193:44329 10/15/2025-06:13:25.798491 [**] [1:2402000:7527] ET DROP Dshield Block Listed Source group 1 [**] [Classification: Misc Attack] [Priority: 2] {TCP} 64.62.156.61:36426 -> 69.28.84.193:3000 10/15/2025-06:13:31.067000 [**] [1:2402000:7527] ET DROP Dshield Block Listed Source group 1 [**] [Classification: Misc Attack] [Priority: 2] {TCP} 167.94.146.43:25436 -> 69.28.84.193:5426 ``` The above output confirms that Suricata is working well. ## Conclusion In this guide, we explained how to install Suricata IDS on Rocky Linux 10. We also configured Suricata IDS and tested it with a DDoS attack. You can now implement the Suricata IDS on the production server to secure it from the DDoS attack. Try it on [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Business Intelligence Group Announces the Winners of the 2022 Excellence in Customer Service Awards > URL: https://www.atlantic.net/press-releases/business-intelligence-group-announces-the-winners-of-the-2022-excellence-in-customer-service-awards/ | Published: 2022-04-12 | Updated: 2024-06-11 | Author: Editorial Team PHILADELPHIA, PA—April 12, 2022—Today, the Business Intelligence Group named 78 companies, executives, and products as winners of the 2022 Excellence in Customer Service Awards. This annual business awards program recognizes those who are helping companies better communicate with their customers to provide a differentiated level of customer service. “The role of customer service is changing every day and the winners of this year’s program highlight the people, organizations, and products that are really improving how consumers connect with companies,” said Maria Jimenez, chief nominations officer of the Business Intelligence Group. This year’s judges also recognized Atlantic.Net, Inc. as a finalist in the Business Intelligence Group Excellence in Customer Service Awards category. For more information about the Excellence in Customer Service Awards, visit [Excellence in customer service awards](https://www.bintelligence.com/excellence-in-customer-service-awards). About Business Intelligence Group The Business Intelligence Group was founded with the mission of recognizing true talent and superior performance in the business world. Unlike other industry award programs, these programs are judged by business executives having experience and knowledge. The organization’s proprietary and unique scoring system selectively measures performance across multiple business domains and then rewards those companies whose achievements stand above those of their peers. Contact Maria Jimenez Chief Nominations Officer +1 909-529-2737 jmaria@bintelligence.com About Atlantic.Net Atlantic.Net is a global cloud services provider with over 25 years of experience serving thousands of developers and small, medium, and large clients in more than one hundred countries. Atlantic.Net specializes in managed and unmanaged Windows, Linux, and FreeBSD server hosting solutions and has served dynamic business clients including Lenovo, Newegg, NASA, and Hilton, among others. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions backed by 24/7/365 support in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. For more information, please visit [Atlantic.Net](https://www.atlantic.net/). Contact: Email: pr@atlantic.net Ph: 321- 206-1371 --- # How to Generate Self-Signed SSL Certificates Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-generate-self-signed-ssl-certificates-rocky-linux-10/ | Published: 2022-04-13 | Updated: 2025-10-15 | Author: Hitesh Jethva SSL (Secure Sockets Layer) and TLS (Transport Layer Security) are security protocols used to secure web traffic between the web server and the client’s web browser. Generally, they are used to protect confidential data such as credit card data, login credentials, and other private information. Unlike other types of SSL certificates, a self-signed SSL certificate is a certificate signed by an individual who owns it. Typically, self-signed SSL certificates are totally free and are used for testing purposes on the locally hosted web server. In this post, we will show you how to generate a self-signed SSL certificate in Rocky Linux 10. ## Install OpenSSL Before starting, the OpenSSL toolkit must be installed on your server or desktop to generate a self-signed certificate. If not installed, you can install it by running the following command: ``` dnf install openssl -y ``` Once installed, verify the OpenSSL version with the following command. ``` rpm -qa openssl ``` You will get the following output: ``` openssl-3.2.2-16.el10_0.4.x86_64 ``` ## Generate a Private Key First, you will need to create a private key to enable encryption. Let’s create a password protected 2048-bit RSA private key using the following command: ``` openssl genrsa -out private.key 2048 ``` ``` You can see the content of the private key using the following command: ``` ``` cat private.key ``` You should see the following output: ``` -----BEGIN RSA PRIVATE KEY----- Proc-Type: 4,ENCRYPTED DEK-Info: DES-EDE3-CBC,E0C0E24222815CE0 ZWzirTOp+UGRSc44dbm0iW5R0gCXxd3C2LwwGbTKaSRxB5sQUurFvFP5ilCuywoR lNvz3Bd9vCPFnR8pVw355FLpc9qxLsxjweXXUaDjDg+W3s21hQqaWXOQLXjKvA2c W3cC9eMApgo8l1mG+a3fFIj/UAFElhmMLSnqdK2tH/gjpDbZUtaZcywqB7UW20tU uCyJN0T/rSHPCQ1w/7LvnK1e0cAn0ZEOHzdsdcbjYeBuRfv/oSHQAsSkmFxTZQCq p02gAiexddciXiTlDTp24Tr7Fp4BMkBktE2BX95ZjXY8dbidBSrnZki8RbxZwNeq Lr/cracFZ4h+sxac3/Pn25DcZEVyJKTmybypuNea63tsJrU0eHs7rfYqXcnyfhRg PrlPSWUPFwx3yuRkgZfo1OXcR1vuhKpvIOOm3awa3WyXb5t9PNwv/FeT2Ta1guTj NksxFEVCP8ven2VxLWD1ESf/oUE9jYmWDXxIU+xrgrVW5Bklv6A/EewR8T/oZsYB ap/SgHbW2/KzXYWEoB4fcVdzonTwZNutDFw2p1dzNVz792IwPCFsrE6BnNkoyyXE DQJAVE99fKgXY9f4L9qZru3yYNd3lP1g+2PzkX1u/QN2Ggr0YiPEJdixWh7QxwC8 ANALCCKUSJTm02YewhJHE+eU/UIfa1GQGaEJ+Pwxx6CjJCzfU571SuZBDpmz07Cu FBlx1Qzzmn2SWbFiIlLCS84pEOsByw26p+NhHzKZAhKHHq4DKrNCnDEWOU95GbSn I0QIIdTuY+X2sKj9a26nkjs8kWb3GfDAf/3pNXynRapxepRtceSfKTWOsEDIGGLA pgnuBIT6NaZ7zIe7KeZpnzbK6dJsltji9uI9+zebNjoq6CND+TTprpPqATVSj+E9 8xS2BQSX5se6t47ierbP3Rx1LP95tayoYI9bPUHPaTSzrx2R43SZSa0r9JVq9gLl MRdXhd+qUh2eNbDSWk0F3DiKbhbi/B3WwQA9l7eq/OYgDPo2TxXoyDWJlmJ+LllF iVA9sUI21+aJE4I+5BXQDz/dyLatuis+vAIpYCRSRcnsK7Y8ALe27NyViKO7ir7F gu+BGkcfAvZg2d/9G0IV+syRblW7OGvwphk+oy2Us0ggAh8BvoIp3ra9t62eOHCg rl784OEAW8w94WFzmCvmCLPzmXDUkwLIo06WmYzWhrEHhivzOc9W3WiJ9jlzBmR2 V9mWsNErytPUiEBhRm9c9i9ggrehN9PsYjEuOM3KYCbqneMXe4yH7wYlxJ70r3A0 0/cBxMyG/tlzgDqyhHV8tYEMFL9B3lqTsTWP/bfc2baTd4sstLrVESE+0f0BpeoI t6zKCOUe9tq4RBI+9selgPECwPhttJw4IKMuH9s7XAjaOiqP7TE8M79/VsgttGoJ /mxXWA8uVwEqonFx6CrAe1oOnuDObP5uC5ikPf3GnBDk2wf8pt0VteIJVCd6Pamy 6Hlb/eg9VtzQHpJBXOthjKGE1CGBw3rv/Q9eNaS8QhDUFQ09EkW6TBJVCI86QPX9 4tWhsj7DLHXN1Mt55unMjcb+tez+QXI7EgBySxBfycV2zbQ7odV6WZHEUCuZbJzV -----END RSA PRIVATE KEY----- ``` ## Generate a Certificate Signing Request Next, you will need a certificate signing request (CSR) if you want your certificate signed. CSR includes information about the public key, country, and organization. You can create a CSR named **server.csr** using your private key as shown below: ``` openssl req -key private.key -new -out server.csr ``` You will be asked to provide your private key password and some CSR information to complete the process as shown below: ``` Enter pass phrase for private.key: You are about to be asked to enter information that will be incorporated into your certificate request. What you are about to enter is what is called a Distinguished Name or a DN. There are quite a few fields but you can leave some blank For some fields there will be a default value, If you enter '.', the field will be left blank. ----- Country Name (2 letter code) [XX]:IN State or Province Name (full name) []:GUJ Locality Name (eg, city) [Default City]:AHMEDABAD Organization Name (eg, company) [Default Company Ltd]:Atlantic Organizational Unit Name (eg, section) []:IT Common Name (eg, your name or your server's hostname) []:server Email Address []:hitjethva@gmail.com Please enter the following 'extra' attributes to be sent with your certificate request A challenge password []: An optional company name []: ``` Also Read [How to Change or Set User Password in Linux](https://www.atlantic.net/vps-hosting/how-to-change-or-set-user-passwords-in-linux/) ## Generate a Self-Signed Certificate A self-signed certificate is a certificate that is signed by its own private key. It is used to encrypt data. You can create a self-signed certificate named **server.crt** using the private key and CSR, as shown below: ``` openssl x509 -signkey private.key -in server.csr -req -days 365 -out server.crt ``` You should see the following output: ``` Signature ok subject=C = IN, ST = GUJ, L = AHMEDABAD, O = Atlantic, OU = IT, CN = server, emailAddress = hitjethva@gmail.com Getting Private key Enter pass phrase for private.key: ``` **Note**: The **-days** option specifies the number of days that the certificate will be valid. You can now use the OpenSSL command to view the contents of your certificate in plain text: ``` openssl x509 -text -noout -in server.crt ``` You should see the certificate information in the following output: ``` Certificate: Data: Version: 1 (0x0) Serial Number: 6f:bd:1d:8d:be:52:8e:9b:ba:74:29:0c:e7:15:2b:01:42:5c:66:8d Signature Algorithm: sha256WithRSAEncryption Issuer: C = IN, ST = GUJ, L = AHMEDABAD, O = Atlantic, OU = IT, CN = server, emailAddress = hitjethva@gmail.com Validity Not Before: Mar 15 11:42:36 2022 GMT Not After : Mar 15 11:42:36 2023 GMT Subject: C = IN, ST = GUJ, L = AHMEDABAD, O = Atlantic, OU = IT, CN = server, emailAddress = hitjethva@gmail.com Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: 00:b1:d0:e3:36:46:64:4c:70:b6:24:bf:f7:5f:9a: 8a:5c:bd:89:b8:f0:b8:56:51:e5:f6:e5:ed:d1:6c: cc:89:7a:97:c3:15:89:98:9a:df:74:e1:a1:2e:da: 12:7c:a2:64:d6:62:1b:55:85:94:dc:5c:10:89:63: de:bd:f7:e2:56:68:7a:3c:48:88:7a:fd:d5:df:12: 8e:28:28:d6:77:5b:2d:51:53:84:f9:c3:d2:a7:db: 6f:2d:88:00:e0:b1:93:f8:a4:66:df:03:17:c4:5a: 9c:49:37:86:bf:34:c0:83:94:1f:aa:1b:a4:55:09: b3:75:b1:68:de:5c:1a:75:12:fb:65:4a:31:c9:f3: 34:93:b5:eb:1b:93:01:77:e2:ba:27:7c:62:9c:65: e7:49:37:1d:97:40:44:c0:f8:38:54:52:8c:69:3d: b5:d6:d5:90:16:45:83:a4:16:49:5e:cc:8d:da:dd: 1a:22:0d:26:f6:ef:b0:b4:8c:5b:8c:b4:bf:7d:cc: 48:98:a6:db:7d:78:cc:3d:5e:66:69:ca:c5:74:95: e3:21:84:6c:e1:87:b1:08:b4:26:24:84:3f:75:7b: fb:ee:36:4d:90:91:82:8d:35:ea:15:8e:95:6f:7c: e8:7b:71:ff:aa:d0:bb:46:b2:35:30:14:03:ba:ac: 05:8b Exponent: 65537 (0x10001) Signature Algorithm: sha256WithRSAEncryption 64:d1:11:03:64:89:12:29:e8:e8:a5:7c:03:5b:c3:f8:61:56: e2:d3:f5:4c:79:4b:e6:19:84:c8:5a:69:57:50:a0:78:0c:57: aa:5a:17:88:54:8c:3d:61:1c:f0:30:e6:41:31:e6:52:5c:d2: 84:f2:dd:da:a2:f4:42:7b:a0:c3:c7:80:3a:32:ab:10:15:c7: f5:e1:7d:7f:68:1a:89:35:c8:71:10:c0:03:5b:d7:ce:60:d9: 55:e7:44:15:e2:e4:7e:db:65:5b:34:1b:fe:2b:1f:c7:b1:e5: 2a:e7:28:05:1b:02:81:92:8b:b7:3e:28:78:20:68:e4:68:ac: e5:a2:21:e8:31:de:59:64:9b:c8:6a:16:9a:43:9c:52:0a:cf: 2d:c2:91:bf:9b:49:64:37:a7:00:60:28:e9:38:ae:35:d3:c6: b6:6e:fc:f3:81:cc:a2:f4:2e:50:80:d8:27:cf:f1:3d:4d:19: e9:a1:c8:61:8f:b6:28:c5:93:93:75:94:c3:f3:6b:d2:48:8f: 8b:3e:53:56:76:ab:fc:a9:9c:be:17:59:b4:db:c5:9c:96:6d: 49:3e:98:5a:d3:c8:03:2e:03:47:2c:1b:84:ee:b0:2f:ae:43: e9:49:42:4f:79:01:04:99:4a:8a:78:27:f8:f9:61:8d:73:47: 49:75:58:d3 ``` ## Conclusion In this post, we explained how to generate a self-signed SSL certificate using the OpenSSL utility. You can now configure Apache or Nginx webserver to use it and secure the communication between the web server and client. Try it on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Use chgrp (Change Group Ownership) Command to Change the Group of a File or Directory in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-use-chgrp-change-group-ownership-command-in-linux/ | Published: 2022-04-16 | Updated: 2024-06-01 | Author: Hitesh Jethva In Linux, each file and directory is associated with a user and group owner to decide which user and group can read, write and execute the file and directory. The chgrp command is used to change the group ownership of files and directories on Linux. Unlike the chown command, the chgrp command just requires you to specify a group name. In this post, we will show you how to use the chgrp command in Linux for various system administration situations. ## Basic Syntax of chgrp Command The basic syntax of the chgrp command is shown below: ``` chgrp [option] groupname file/directory ``` A brief explanation of each option is shown below: - **-c** Display verbose output only after the change is made. - **-f** Suppress most error messages - **-v** Show diagnostic for every processed file. - **-R** Apply ownership on files and directories recursively. - **–help** Used to display help information. ## Display Group Ownership Of a File Before changing the group ownership of any file and directory, it is important to know how to show the existing group ownership of any file and directory. You can use the **ls -l** command to display the exiting group ownership of any file and directory: ``` ls -l hitesh.txt ``` This will display the group ownership of the file hitesh.txt, as shown below: ``` -rw-rw-r-- 1 root vyom 0 Mar 15 09:48 hitesh.txt ``` As you can see, **vyom** is the group owner of the file **hitesh.txt**. #### Also Read [How to Use chown (Change Ownership) Command in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-use-chown-change-ownership-command-in-linux/) ## Change Group Ownership Of a Directory You can use the following syntax to change the group ownership of the directory: ``` chgrp groupname directory-name ``` For example, to change the group ownership of the directory /var/www to www-data group, run the following command: ``` chgrp www-data /var/www ``` You can use the -R flag with the chgrp command to change the group ownership of the specified directory including all sub-directories: ``` chgrp -R www-data /var/www ``` ## Change Group Ownership Of a File Use the following syntax to change the group ownership of a file: ``` chgrp groupname file-name ``` For example, to change the group ownership of the file hitesh.txt to sudo group, run the following command: ``` chgrp sudo hitesh.txt ``` If you want to change the group ownership of multiple files, run the following command: ``` chgrp sudo file1 file2 file3 ``` ## Copy Group Ownership From a Reference File The chgrp command also allows you to copy the group ownership information from a reference file. The basic syntax to copy the group ownership is shown below: ``` chgrp [OPTION] --reference=[RFILE_NAME] [FILE_NAME] ``` For example, to copy the group ownership from the file named**hitesh.txt** to **vyom.txt**, run the following command: ``` chgrp --reference=hitesh.txt vyom.txt ``` #### Also Read [How to Change Open File Limit in Linux](https://www.atlantic.net/vps-hosting/how-to-change-open-file-limit-in-linux/) ## Display chgrp Execution Information You can use the chgrp command with the **-c** option to display a list of changes chgrp has made to each file specified. For example, to see the changes that happened in the **/var/www/html** directory, run the following command: ``` chgrp -c -R sudo /var/www/html ``` You should see all changes made by **chgrp** command in the following output: ``` changed group of '/var/www/html/index.html' from root to sudo changed group of '/var/www/html/index.nginx-debian.html' from root to sudo changed group of '/var/www/html/example.com/index.html' from root to sudo changed group of '/var/www/html/example.com' from www-data to sudo changed group of '/var/www/html' from root to sudo ``` ## Conclusion In this post, we explained how to use the **chgrp** command to change the group ownership of a file or directory. We also used some options with the **chgrp** command to customize the process. Hopefully, this post will help you in a multi-user environment. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Use chown (Change Ownership) Command in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-use-chown-change-ownership-command-in-linux/ | Published: 2022-04-18 | Updated: 2024-06-01 | Author: Hitesh Jethva The chown command, change owner, is a Linux command-line tool used to change the file and directory ownership. Only root and admin users can access all files and directories in the file system in Linux. Each file and directory is associated with an owner and group owner. You can’t access any files that are owned by other users. In such a case, you will need to change the owner of the file to grant file access. The chown command allows you to grant read, write, and execute level permission on files and directories. In this post, we will show you how to use the chown command in Linux. ## Basic Syntax of chown Command The basic syntax of using the chown command is shown below: ``` chown [option] [owner][group] [file]/[directory] ``` A brief explanation of each option is shown below: - **-c** Display verbose output only after the change is made. - **-f** Suppress most error messages - **-v** Show diagnostic for every processed file. - **-R** Apply ownership on files and directories recursively. - **–help** Used to display help information. ## Display User and Group Ownership Of a File Before changing the ownership of any file, it is important to know the existing owner of that file. You can use the ls -l command to display the user and group owner of a file. For example, to display the user and group ownership of a file **file.txt**, run the following command: ``` ls -l file.txt ``` You will get the following output: ``` -rw-rw-r-- 1 vyom vyom 0 Mar 15 08:21 file.txt ``` As you can see, **vyom** is a user and group owner of a file. #### Also Read [How to Use chgrp (Change Group Ownership) Command in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-use-chgrp-change-group-ownership-command-in-linux/) ## Change the User Owner Of a File To change the user owner of the file, use the below syntax: ``` chown username filename ``` For example, to change the user owner of the file named **file.txt** to **www-data**, run the following command: ``` chown www-data file.txt ``` You can now verify the ownership of**file.txt** using the following command: ``` ls -l file.txt ``` You should see that the owner of **file.txt** has changed. ``` -rw-rw-r-- 1 www-data vyom 0 Mar 15 08:21 file.txt ``` #### Also Read [How to Download File Using Wget in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-download-file-using-wget-in-linux/) ## Change the Group Owner Of a File To change the group owner of a file, use the chown command and specify the group name. The basic syntax to change the group owner is shown below: ``` chown :groupname filename ``` For example, to change the group owner of the file named**file.txt** to **sudo**, run the following command: ``` chown :sudo file.txt ``` You can now verify the changes using the following command: ``` ls -l file.txt ``` You should see that the group owner is changed. ``` -rw-rw-r-- 1 www-data sudo 0 Mar 15 08:21 file.txt ``` ## Change the User and Group Owner Of a File If you want to change the user and group owner together, use the following syntax: ``` chown username:groupname file ``` For example, to change the user owner to root and group owner to root, run the following command: ``` chown root:root file.txt ``` If you want to change the user and group owner of a specified directory and all of their sub-directories recursively, use the following command: ``` chown -R www-data:www-data /var/www/html ``` This command will change the user and group owner of the **/var/www/html** directory and all of its sub-directories recursively. ## Copy Ownership Settings From One File to Another The chown command also allows you to copy the ownership settings from one file to another file. The basic syntax to copy the ownership settings is shown below: ``` chown --reference=filename new-filename ``` For example, to copy the ownership settings from file1.txt to file2.txt, run the following command: ``` chown --reference=file1.txt file2.txt ``` ## Conclusion In this post, we explained how to change the ownership of files using the chown command. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Top 10 Helpdesk Support Ticket Software > URL: https://www.atlantic.net/vps-hosting/top-10-helpdesk-support-ticket-software/ | Published: 2022-04-22 | Updated: 2025-09-15 | Author: Richard Bailey Helpdesk support software plays a vital role in the day-to-day business operations of countless businesses around the globe. Most medium or large businesses have some sort of support desk, service desk, or operations team that looks after the customer requests, IT problems, change management, and asset management. Helpdesk software categorizes issues and problems into a searchable log, helping users to manage the incident until completion. There are hundreds of Helpdesk Support Tickets applications available, and most require a business license to unlock every feature. However, there are several fully-featured open source apps that can help your business save cash. The majority are available as SaaS offerings that are managed directly by the supplier; the customer simply consumes the product as needed. Others require a local application server, database, or the corresponding Docker containers to work. Choosing the right helpdesk support ticket software for your business or organization can prove difficult. In this article, we have compiled a list of the top 10 helpdesk and support tools on the market to help make this choice easier for you. ## What are the Top 10 Helpdesk Support Software Solutions? ## 1. Ubersmith Ubersmith is a favorite here at Atlantic.Net because it provides an entire suite of products that help our teams work smarter and more inclusively. A key tool used by our support staff is the Ubersmith Ticketing System. This email-based ticketing system integrates directly with monitoring solutions, billing platforms, and asset databases to create a complete solution to manage customer issues end-to-end. It’s the best solution when working with multiple customers, as the toolset allows our teams to seamlessly manage clients 24×7, aiding our delivery of industry-leading customer support with automated ticket escalation and resolution for repetitive tasks. Department and workflow management tools allow our teams to keep on top of a large number of tickets. ## 2. Zendesk ZenDesk is a premium helpdesk platform that focuses on developers by providing a large number of API-driven tools that integrate with cloud platforms and existing collaboration tools such as Teams or Slack. Social integration plays an important role; integration with WhatsApp, Facebook, Instagram, etc is available out of the box. ZenDesk is popular with customer-facing businesses wanting to deliver an omnichannel presence. While ZenDesk is expensive, it allows you to build out personalized help centers and community forums, and you can even integrate smart [AI customer support](https://www.livechat.com/features/ai/) into your website if required. ## 3. HappyFox HappyFox is a relatively new helpdesk solution that has many social networking services built into the platform, including integration with Facebook and Twitter, as well as email, voice, and text. It is a web-based application that focuses on ticket organization to help teams to manage their queues, status, and priority of tickets with minimal fuss. Assets can be imported from tools like Salesforce to enable detailed customer information to be readily available directly from the ticket. For support teams that handle regular queries, canned responses can be created to give user instructions at the click of a button instead of typing personalized responses for every customer – clever stuff. ## 4. Jira Service Management (JSM) JSM is an Atlassian helpdesk and change management product that aims to offer a simple interface with a powerful backend. Tickets can be logged and automatically closed, escalated, or communicated to the correct team using automation, and it can even dial-out to on-call teams with the relevant 3rd party plugins. Best of all is that it integrates directly with the rest of the Atlassian suite: JIRA for Scrum project management, BitBucket for coding, and Confluence for documentation. Each product can reference the others, making for a highly intuitive environment. ## 5. Freshdesk Freshdesk is a SaaS Helpdesk Support tool that is customer-centric and perfect for customer service installations. It provides an omnichannel interface where customers can log tickets and chat with representatives. Much of its automation focuses on cutting down manual and repetitive work, including automating responses to commonly asked questions using the power of AI. There is a self-service option that includes self-help and chatbots that interact directly with the customer before offloading to an agent if needed. In-house collaboration is great, too, with features such as agent collision detection, shared ownership, and in-app collaboration. ## 6. Spiceworks Cloud Helpdesk Spiceworks is the first free helpdesk solution to make it onto our top 10. It is available as cloud-based SaaS helpdesk software and as a locally installable product. Limited tech support is also free, which is excellent. Some manual configuration is needed to get the platform working with other alerting software and to set up monitors, alerts, custom ticket attributes, and ticket rules. Spiceworks works on mobile and integrates well with existing email products such as Exchange. User access works with LDAP or Active Directory, and it’s straightforward to build out a knowledge base for customers and employees. ## 7. Richmond Systems (RichDesk) RichDesk is a helpdesk and asset management tool that strictly observes the ITIL framework for helpdesk ticket management, making it a great choice for Service Desks. The toolset can be hosted locally or in the cloud; customers have access to a web portal, and users have access to a bespoke application. It requires a SQL backend to build out a CMDB that grows as the product is used. Richmond features change management, ticket automation, and helpful in-ticket SLA timings to ensure the Service Desk is hitting contracted targets. ## 8. Service Now Service Now is one of the biggest players in helpdesk support ticket software and now offers multiple spin-off products for IT service management. It is a primarily SaaS-based platform. AI plays a key role in Service Now as IT incidents get auto-assigned to the correct resolution team and DevOps change approvals are automated to speed up implementation timings. Service Now includes automated support for common requests with virtual agents that understand simple human language. You can gain full visibility with built-in dashboards and real-time analytics. It has great compatibility, too, integrating seamlessly with Oracle, Jira, SAP, Azure, and many other services. ## 9. OsTicket OsTicket is another open source and free helpdesk ticket management system. It relies on users being able to install and host it locally, but the implementation is very simple, and it’s even available as a 1-click Docker image. Considering that it’s free, the feature list is very impressive and includes dashboards, filters, a customer support portal, SLAs, and self-help support. Customization is key with OsTicket. They know that every company has different needs, so it includes powerful customization options to allow the user to create an environment that perfectly suits their business. Some of the customization options include custom queues, fields, help topics, agent collision avoidance, and more. ## 10. Front Front is a new [help desk tool](https://www.helpscout.com/helpu/choosing-help-desk-software/) that aims to interact with customers as people instead of a ticket number. To do this, it heavily relies on social networking interaction, email, SMS, and chat tools to collaborate with the client. Each support channel such as FaceBook, WhatsApp, CRM, live chat, etc is ingested into a single pane of glass, making the management of all these systems super simple. ## How Can Atlantic.Net Help? Are you looking for a leading [hosting provider](https://www.atlantic.net/hosting-services-provider/) to host your helpdesk support ticket solution? Look no further than Atlantic.Net. With over 30 years of proven experience, our [full suite of managed services](https://www.atlantic.net/managed-services/) and always available professional support team will build the perfect solution for your business or organization. Atlantic.Net stands ready to help you attain fast compliance with a range of certifications, such as SOC 2 and SOC 3, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/), and HITECH, all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, visit us at [www.atlantic.net](https://www.atlantic.net), call 866-618-DATA (3282), or email us at [sales@atlantic.net](mailto:sales@atlantic.net). You can find out more information by [contacting our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # How to Install and Use MongoDB on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-mongodb-on-rocky-linux-10/ | Published: 2022-04-24 | Updated: 2025-10-15 | Author: Hitesh Jethva MongoDB is a free, open-source, and cross-platform document-oriented database system that uses JSON-like documents with optional schemas. It is written in C++ and used for developing modern dynamic apps. In MongoDB, data objects are stored as separate documents in a collection, unlike in traditional relational databases where rows and columns are used. It provides an aggregation framework and offers easy querying and indexing functionality that helps developers to query complex document-based data sets easily. In this post, we will explain how to install and use MongoDB on Rocky Linux 10. ## Add MongoDB Repository By default, the MongoDB package is not included in the Rocky Linux 10 default repo, so you will need to add the MongoDB official repo to your system. You can create it using the following command: ``` nano /etc/yum.repos.d/mongodb-org-7.0.repo ``` Add the following lines: ``` [mongodb-org-7.0] name=MongoDB Repository baseurl=https://repo.mongodb.org/yum/redhat/9/mongodb-org/7.0/x86_64/ enabled=1 gpgcheck=0 repo_gpgcheck=0 ``` Save and close the file when you are finished. ## Install MongoDB on Rocky Linux 10 You can now install the MongoDB package by just running the following command: ``` dnf install mongodb-org -y ``` Once MongoDB is installed, start and enable the MongoDB service using the following command: ``` systemctl start mongod systemctl enable mongod ``` You can also verify the MongoDB version using the following command: ``` mongod --version ``` You will get the following output: ``` db version v7.0.25 Build Info: { "version": "7.0.25", "gitVersion": "96dce3da49b8d2e9e0d328048cb56930eb1bdb2b", "openSSLVersion": "OpenSSL 3.2.2 4 Jun 2024", "modules": [], "allocator": "tcmalloc", "environment": { "distmod": "rhel90", "distarch": "x86_64", "target_arch": "x86_64" } } ``` ## Configure MongoDB By default, MongoDB is configured to connect without any authentication. For security purposes, it is a good idea to secure MongoDB with a password. First, edit the MongoDB configuration file and enable authentication: ``` nano /etc/mongod.conf ``` Add the following lines: ``` security: authorization: enabled ``` Save and close the file when you are finished. ## Create an Admin User for MongoDB Next, you will need to create an admin user to manage the MongoDB databases. First, connect to the MongoDB instance with the following command: ``` mongosh ``` Once you are connected, create a database named admin using the following command: ``` use admin ``` Next, create an admin user and set a password with the following command: ``` db.createUser( { user: "mongoadmin", pwd: passwordPrompt(), roles: [ { role: "userAdminAnyDatabase", db: "admin" }, "readWriteAnyDatabase" ] } ) ``` You will be asked to set a password as shown below: ``` Enter password: ******{ ok: 1 } ``` Next, exit from the MongoDB shell with the following command: ``` exit ``` Finally, restart the MongoDB service to apply the changes: ``` systemctl restart mongod ``` You can now connect to the MongoDB instance using the administrator credentials: ``` mongosh --port 27017 --authenticationDatabase "admin" -u "mongoadmin" -p ``` If you get any error, then remove the socket file and restart MongoD service. ``` rm -f /tmp/mongodb-*.sock systemctl restart mongod ``` ## Create a Database in MongoDB To create a database named testdb, run the following command: ``` use testdb ``` Next, add some data to the testdb database using the following command: ``` db.linux.insertOne( { "Debian" : "11", "Rocky Linux" : "10", "Alma Linux" : "9" } ) ``` You can now list available databases using the following command: ``` db ``` You will get the following output: ``` testdb ``` To show documents in your database, run the following command: ``` show collections ``` You will get the following output: ``` linux ``` To show the contents of your database collection, run the following command: ``` db.linux.find() ``` You will get the following output: ``` { "_id" : ObjectId("6245b6be2dff2ecebfbe59e0"), "Debian" : "11", "Rocky Linux" : "10", "Alma Linux" : "9" } ``` To switch the database to admin, use the following command: ``` use admin ``` To list all users, run the following command: ``` db.getUsers() ``` You will get a list of all users in the following output: ``` [ { "_id" : "admin.mongoadmin", "userId" : UUID("2b632052-c1ca-4a26-bc1c-e883f24fc7f0"), "user" : "mongoadmin", "db" : "admin", "roles" : [ { "role" : "userAdminAnyDatabase", "db" : "admin" }, { "role" : "readWriteAnyDatabase", "db" : "admin" } ], "mechanisms" : [ "SCRAM-SHA-1", "SCRAM-SHA-256" ] } ] ``` **Also Read** [How to Delete or Remove Databases in MySQL](https://www.atlantic.net/dedicated-server-hosting/how-to-delete-or-remove-databases-in-mysql/) ## Conclusion In this post, we explained how to install the MongoDB database on Rocky Linux 10. We also explained how to secure the MongoDB instance and interact with a MongoDB database. Try managing MongoDB databases on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Set $Path Variable in Linux > URL: https://www.atlantic.net/vps-hosting/how-to-set-path-variable-in-linux/ | Published: 2022-04-25 | Updated: 2023-11-25 | Author: Hitesh Jethva The $PATH variable plays an important role in Linux and Unix-based operating systems. It contains a list of directories that hold various executables on the system. The $PATH variable allows you to run any programs in Linux seamlessly. Generally, the **$PATH** variable contains the /bin, /usr/bin, /usr/local/bin, /sbin and /usr/sbin directories. However, you can also add your own directories to the $PATH variable to execute any script from anywhere on the system without specifying the script’s absolute path. In this post, we will show you how to set a $PATH variable in Linux. ## Check Current $PATH Variables The $PATH variable is a colon-delimited list of directories that tell the Linux shell to determine where to search for an executable file. To check the list of directories that currently exists in your $PATH, run the following command: ``` echo $PATH ``` You should see the following output: ``` /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin ``` You can also use the **printenv** command to list all variables: ``` printenv ``` Output: ``` LOGNAME=root DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/0/bus XDG_RUNTIME_DIR=/run/user/0 XAUTHORITY=/run/user/1000/gdm/Xauthority PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin LESSOPEN=| /usr/bin/lesspipe %s _=/usr/bin/printenv ``` **Also Read** [How to Remove Files and Directories in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-remove-files-and-directories-in-linux/) ## Setting $PATH Variable Temporarily If you just want to run any script in your current active session, then it is recommended to set a temporary $PATH variable. After setting up a $PATH variable, you can able to run your script with a command from anywhere on your system without specifying the full path of the script. Use the following syntax to set a $PATH variable temporarily: ``` export PATH=$PATH:/directory-path ``` For example, if your script is located inside the **/home/vyom/app** directory, run the following command to add **/home/vyom/app** directory to a **$PATH** variable. ``` export PATH=$PATH:/home/vyom/app ``` This command will set a **$PATH** variable only for your active session. It will reset back to the default after the system restart. ## Setting $PATH Variable Permanently If you want to use any program or script regularly, it would be recommended to set a $PATH variable permanently. You can add a $PATH variable to **~/.bashrc** and **/etc/profile** file. - If you want to set a $PATH for a specific user then you will need to add the $PATH variable inside the user’s **~/.bashrc** file. - If you want to set a $PATH for all users then you will need to add the $PATH variable inside **/etc/profile** file. For example, to add a $PATH variable for a specific user, edit the ~/.bashrc file: ``` nano /home/vyom/.bashrc ``` Add the following line: ``` export PATH=$PATH:/home/vyom/app ``` Save and close the file, then update the current shell variable using the following command: ``` source /home/vyom/.bashrc ``` To add a $PATH variable for all users, edit the /etc/profile file: ``` nano /etc/profile ``` Add the following line: ``` export PATH=$PATH:/home/vyom/app ``` Save and close the file, then update the current shell variable using the following command: ``` source /etc/profile ``` You can now check the added variable using the following command: ``` echo $PATH ``` **Also Read** [How to Compare Two Files in Linux Terminal](https://www.atlantic.net/vps-hosting/how-to-compare-two-files-in-linux-terminal/) ## Conclusion In this post, we explained how to set a $PATH variable in Linux. You can now add your desired directory to your user or global $PATH variable. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Remove Files and Directories in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-remove-files-and-directories-in-linux/ | Published: 2022-04-26 | Updated: 2023-11-15 | Author: Hitesh Jethva If you are working on Linux, then you may need to remove certain files and directories based on a set of predetermined requirements. Linux provides several tools to remove files and directories. Among them, the **rm** and **rmdir** are the most widely used commands to remove files and directories on Linux, macOS, and Unix-based operating systems. In this post, we will show you how to remove files and directories in Linux. ## Remove a Single File The rm command allows you to remove one or more files in a one-liner command. To remove a single file, run the following command: ``` rm file1.txt ``` The above command will delete a file without prompting you to confirm file deletion. If you want to make the **rm** command always prompt before deleting a file, use the **-i** flag: ``` rm -i file1.txt ``` You can use the -v flag to display what the **rm** command is actually doing: ``` rm -v file1.txt ``` If you want to remove a write-protected file without prompting for confirmation, use the **-f** flag: ``` rm -f file1.txt ``` Also Read [How to Install LFTP to Download and Upload Files in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-install-lftp-to-download-and-upload-files-in-linux/) ## Remove Multiple Files The rm command also allows you to remove a set of files by specifying all file names in a single command. To remove multiple files, run the following command: ``` rm file1.txt file2.txt file3.txt ``` You can also remove multiple files using regular expressions. For example, to remove all files whose names start with a word **notebook**, run the following command: ``` rm notebook* ``` If you want to remove all files with a **png** extension, run the following command: ``` rm *.png ``` Also Read [How to Install and Use Pigz to Compress File in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-pigz-to-compress-file-in-linux/) ## Remove Directory in Linux You can use the **rm** and **rmdir** commands to remove a directory in Linux. If you want to remove an empty directory, use the **rm -d** or **rmdir** command: ``` rm -d dir1 ``` Or ``` rmdir dir1 ``` If you want to remove a non-empty directory including all sub-directories and all the files within them, run the following command: ``` rm -r dir1 ``` If you want to remove a write-protected directory including all files within them, run the following command: ``` rm -rf dir1 ``` To remove multiple directories at once, run the following command: ``` rm -r dir1 dir2 dir3 ``` ## Find and Remove Directory You can also use the find command with different options to remove files and directories based on the matching patterns. To find and remove all empty directories within a given path, run the following command: ``` find /mnt -type d -empty -delete ``` This will find and remove all **empty** directories located inside the /mnt directory. To find and remove all **empty** files within a given path, run the following command: ``` find /mnt -type f -empty -delete ``` If you want to find and delete all **pdf** files located inside the /etc directory, run the following command: ``` find /etc -type f -name "*.pdf" -exec rm -f {} \; ``` If you want to find and delete all files **owned** by a specific user, run the following command: ``` find /opt -mindepth 1 -user user1 -delete ``` This command will find and remove all files owned by **user1** located inside /opt directory. If you want to find and remove all files older than **x** days, run the following command: ``` find /mnt -type f -mtime +30 -delete ``` This will find and remove all files inside /mnt directory that is older than **30** days. ## Conclusion In this post, we explained how to remove files and directories using the **rm** and **rmdir** commands. We also explained how to use the find command to perform some advanced file deletion tasks. You can now easily remove files and directories from the Linux system. Try it on [bare metal servers](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) from Atlantic.Net! --- # How to Compare Two Files in Linux Terminal > URL: https://www.atlantic.net/vps-hosting/how-to-compare-two-files-in-linux-terminal/ | Published: 2022-04-27 | Updated: 2023-11-21 | Author: Hitesh Jethva File comparison plays an important role in Linux, especially for programmers and Linux system administrators. For example, if you want to find the difference between two source code files to develop patches, then you need a file comparison tool to make this process easier. There are several command-line tools available in Linux to compare two files. Among them, diff is a very popular command-line utility that provides various options to get the difference between two files. In this post, we will show you how to compare two files in a Linux terminal. ## Basic Syntax The basic syntax of the diff command is shown below: ``` diff [OPTION] FILES ``` A brief explanation of each option is shown below: - **-s** Report when two files are the same - **-c** Display output in context mode - **-q** Report only when files differ - **-y** Shows difference output in two columns - **-r** Recursively compare any subdirectories - **-i** Ignore case differences in file contents - **-w** Ignores all white space - **–ignore-file-name-case** Ignore case when comparing file names - **–no-ignore-file-name-case** Consider a case when comparing file names Also Read [How to Download File Using Wget in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-download-file-using-wget-in-linux/) ## Create Files in Linux To perform file comparison in Linux, you will need to create some files in your system. Let’s create a first file named file1.txt: ``` nano file1.txt ``` Add the following contents: ``` 11 12 13 14 15 16 17 18 19 eveven twelve thirteen fourteen fifteen sixteen seventeen eighteen ninteen In this file, we added some numbers in text and numerix form Atlantic Cloud ``` Let’s create a second file named file2.txt: ``` nano file2.txt ``` Add the following contents: ``` 10 12 3 14 8 16 7 18 19 five twelve eight fourteen fifteen nine seventeen one ninteen In this file, we added some numbers in text and numerix form Atlantic Cloud ``` Let’s create a third file named file3.txt with content similar to file1.txt: ``` nano file3.txt ``` Add the following contents: ``` 11 12 13 14 15 16 17 18 19 eveven twelve thirteen fourteen fifteen sixteen seventeen eighteen ninteen In this file, we added some numbers in text and numerix form Atlantic Cloud ``` Also Read [How to Install and Use Ack Command in Linux](https://www.atlantic.net/vps-hosting/how-to-install-and-use-the-ack-command-in-linux/) ## Print Differences Between Two Files At this point, three files are ready for practical use with the diff command. Now, to print the differences between two files named **file1.txt** and **file2.txt**, run: ``` diff file1.txt file2.txt ``` You will get the following output: ``` 1,2c1,2 < 11 12 13 14 15 16 17 18 19 < eveven twelve thirteen fourteen fifteen sixteen seventeen eighteen ninteen --- > 10 12 3 14 8 16 7 18 19 > five twelve eight fourteen fifteen nine seventeen one ninteen ``` As you can see, the diff command has omitted all the similarities between the two files and only displayed their differences. If you want to display output in context mode, use the **-c** option: ``` diff -c file1.txt file2.txt ``` You will get the following output: ``` *** file1.txt 2022-03-30 16:00:02.639907838 +0530 --- file2.txt 2022-03-30 16:00:23.588174892 +0530 *************** *** 1,4 **** ! 11 12 13 14 15 16 17 18 19 ! eveven twelve thirteen fourteen fifteen sixteen seventeen eighteen ninteen In this file, we added some numbers in text and numerix form Atlantic Cloud --- 1,4 ---- ! 10 12 3 14 8 16 7 18 19 ! five twelve eight fourteen fifteen nine seventeen one ninteen In this file, we added some numbers in text and numerix form Atlantic Cloud ``` ## Find Similar Files Using Diff Command You can use the **-s** flag with the diff command to check whether two files are similar. Run the following command to compare the file1.txt and file3.txt: ``` diff -s file1.txt file3.txt ``` You should see the following output: ``` Files file1.txt and file3.txt are identical ``` ## Find Differ Files Using Diff Command You can use the **-q** flag with the diff command to check whether two files differ. Run the following command to compare the **file1.txt** and **file2.txt**: ``` diff -q file1.txt file2.txt ``` You should see the following output: ``` Files file1.txt and file2.txt differ ``` ## Display Output in side-by-side View If you compare two files and want to display file differences in a side-by-side view, use the **-y** option. ``` diff -y file1.txt file2.txt ``` You should see the following output: ``` 11 12 13 14 15 16 17 18 19 | 10 12 3 14 8 16 7 18 19 eveven twelve thirteen fourteen fifteen sixteen seventeen eig | five twelve eight fourteen fifteen nine seventeen one ninteen In this file, we added some numbers in text and numerix form In this file, we added some numbers in text and numerix form Atlantic Cloud Atlantic Cloud ``` If you want to ignore the similarities between the two files from the above output, run the following command: ``` diff -y --suppress-common-lines file1.txt file2.txt ``` You should see the following output: ``` 11 12 13 14 15 16 17 18 19 | 10 12 3 14 8 16 7 18 19 eveven twelve thirteen fourteen fifteen sixteen seventeen eig | five twelve eight fourteen fifteen nine seventeen one ninteen ``` ## Conclusion In this post, we explained how to compare two files in Linux using the diff command. We also demonstrated several use cases to explain how to use the diff command in different conditions. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Pass Passwords to the SCP Command in Linux (Use SCP with Password) > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-pass-password-to-scp-command-in-linux/ | Published: 2022-04-28 | Updated: 2024-06-02 | Author: Hitesh Jethva Copying files and directories from one system to another system is a common task for any system administrator. SCP, also called secure copy, is a Linux command-line utility used to securely copy or transfer files from one server to another server. The SCP command allows you to copy a file or directory from a local system to a remote system, from a remote system to a local system, or between two remote systems from your local system. When you use the SCP command, you will need to provide a remote user’s password before transferring a file. In this post, we will explain how to pass passwords to the SCP command in Linux. ## Copying Files Using SCP Command The basic syntax to copy a file from the local system to the remote system is shown below: ``` scp filename user@remotehost:/directory/path ``` For example, to copy a file named **file1.txt** from your local system to the remote system with IP address **192.168.1.100** inside the **/mnt** directory, run the following command: ``` scp file1.txt root@192.168.1.100:/mnt/ ``` The basic syntax to copy a file from the remote system to the local system is shown below: ``` scp user@remotehost:/file/path local/path ``` For example, to copy a file named file1.txt from the remote system with IP address **192.168.1.100** to the local system inside **/opt** directory, run the following command: ``` scp root@192.168.1.100:/mnt/file1.txt /opt/ ``` You will be prompted to provide a remote user’s password as shown below: ``` root@192.168.1.100 password: ``` #### **Also Read** [How to Install and Use Ack Command in Linux](https://www.atlantic.net/vps-hosting/how-to-install-and-use-the-ack-command-in-linux/) ## Install sshpass in Linux sshpass is a simple and lightweight command-line tool that allows you to provide passwords to the command prompt itself. It is very useful in a shell script when taking a backup via a cron job. By default, sshpass is not included in any Linux operating system, so you will need to install the sshpass utility in your Linux system to pass the password with the SCP command. For Ubuntu and Debian-based operating systems, install sshpass using the following command: ``` apt-get install sshpass -y ``` For RHEL, Fedora, CentOS, and Rocky Linux operating systems, install sshpass using the following command: ``` dnf install sshpass -y ``` After installing the sshpass utility, you can proceed to the next step. ## How to Pass Password with SCP Command The basic syntax to pass the password with the SCP command is shown below: ``` sshpass -p "remote-user-password" scp filename user@remotehost:/dir/path/ ``` For example, if you want to copy a file named **file1.txt** to the remote server with IP **192.168.1.100**, use the following command: ``` sshpass -p "password" scp file1.txt root@192.168.1.100:/mnt/ ``` As you see, the sshpass + SCP command will help you copy files and directories from one system to another system using a one-line command. #### Also Read [How to Change or Set User Password in Linux](https://www.atlantic.net/vps-hosting/how-to-change-or-set-user-passwords-in-linux/) ## Conclusion In this post, we explained how to use the SCP command with sshpass to pass a password in Linux. sshpass will help you speed up your file-copying process. You can also use it to automate backup from one server to another server. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Atlantic.net, Inc. Honored as gold and silver Stevie® award winner in 2022 American business awards® > URL: https://www.atlantic.net/press-releases/atlantic-net-inc-honored-as-gold-and-silver-stevie-award-winner-in-2022-american-business-awards/ | Published: 2022-04-29 | Updated: 2024-06-11 | Author: Editorial Team **Stevie winners will be presented their awards on June 11 in New York** ORLANDO, FLORIDA – April 28, 2022 – ATLANTIC.NET.INC. was named the winner of a Gold Stevie® Award in the CLOUD STORAGE AND BACKUP category, and a Silver Stevie® Award in the HEALTHCARE TECHNOLOGY SOLUTION category in The 20th Annual American Business Awards® today. More than 3,700 nominations from organizations of all sizes and in virtually every industry were submitted this year for consideration in a wide range of categories, including Startup of the Year, Executive of the Year, Best New Product or Service of the Year, Marketing Campaign of the Year, Thought Leader of the Year, and App of the Year, among others. More than 230 professionals worldwide participated in the judging process to select this year’s Stevie Award winners. “We are so pleased that we will be able to stage our first ABA awards banquet since 2019 and to celebrate, in person, the achievements of such a diverse group of organizations and individuals,” said Maggie Miller, president of the Stevie Awards. Details about The American Business Awards and the list of 2022 Stevie winners are available at [Product management new product awards](https://stevieawards.com/aba/product-management-new-product-awards). “For the third year in a row, the American Business Awards recognized our Cloud Storage and Backup Solution with a Gold Stevie Award and our [Healthcare HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) Solution with a Silver Stevie Award. To win three years in a row is a special accomplishment that shows the consistent quality of our offering,” said Marty Puranik, CEO of Atlantic.Net. “The awards are a testament to our top-notch, unparalleled service trusted by thousands of businesses in over 100 counties.” **About Atlantic.Net** Atlantic.Net is a global cloud services provider with over 25 years of experience, specializing in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions, backed by 24/7/365 support through their global data centers located in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. For more information, please visit [Atlantic Net](https://www.atlantic.net/). **About the Stevie Awards** Stevie Awards are conferred in eight programs: the Asia-Pacific Stevie Awards, the German Stevie Awards, the Middle East & North Africa Stevie Awards, The American Business Awards®, The International Business Awards®, the Stevie Awards for Women in Business, the Stevie Awards for Great Employers, and the Stevie Awards for Sales & Customer Service. Stevie Awards competitions receive more than 12,000 entries each year from organizations in more than 70 nations. Honoring organizations of all types and sizes and the people behind them, the Stevies recognize outstanding performances in the workplace worldwide. Learn more about the Stevie Awards at [Stevie Awards](https://www.stevieawards.com). ### Contact: Email: pr@atlantic.net Ph: 321- 206-1371 --- # How to Use chmod (Change Mode) Command in Linux > URL: https://www.atlantic.net/vps-hosting/how-to-use-chmod-change-mode-command-in-linux/ | Published: 2022-04-29 | Updated: 2023-11-18 | Author: Hitesh Jethva chmod is a Linux command-line utility used to change the access permissions of files and directories. It is very useful in a multi-user environment where you want to restrict files and directories so that only authorized users and processes can access them. The chmod command stands for “change mode” and is used to restrict the way a file can be accessed. In this post, we will show you how to use the chmod command in Linux. ## Basic Syntax The basic syntax of the chmod command in symbolic format is shown below: ``` chmod u=rwx,g=rwx,o=rwx file_name/dir_name ``` Where: - u – user - g – group - o – other - r – read - w – write - x – execute The basic syntax of the chmod command in numerical format is shown below: ``` chmod 777 file_name/dir_name ``` Where: - The First 7 represent user permissions - Second 7 represents group permissions - Third 7 represents other permissions Each of the digits is a combined sum of the numbers 4, 2, 1, and 0. Where: - 4 – read - 2 – write - 1 – execute - 0 – no permissions Also Read [How to Use chown (Change Ownership) Command in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-use-chown-change-ownership-command-in-linux/) ## Viewing File Permissions Before changing the file and directory permissions, it is important to view the existing permissions of the file and directory. Run the following command to check the existing permissions of all files located inside the current directory: ``` ls -l ``` You will get the following output: ``` -rw-rw-r-- 1 vyom vyom 1961 Feb 13 18:28 system-back.tar.gz -rw-rw-r-- 1 vyom vyom 1961 Feb 13 18:23 system-back.tar.gzip drwxr-xr-x 2 vyom vyom 4096 Oct 25 00:27 Templates -rwxrwxrwx 1 vyom vyom 119707966 Dec 7 00:31 Udeler-1.8.2-linux-x86_x64.AppImage -rw-rw-r-- 1 vyom vyom 93 Mar 29 21:57 'Untitled Document 1' drwxr-xr-x 7 vyom vyom 4096 Mar 28 10:19 Videos drwxrwxr-x 3 vyom vyom 4096 Nov 5 09:00 'VirtualBox VMs' ``` On each line, the first character identifies the type of entry that is being listed. If it is a dash **(-)**, it is a file. If it is the letter **d**, it is a directory. The next nine characters represent the settings for the three sets of permissions. - The first of the three sets of characters **rw-** shows the permissions for the user who owns the file. - The second of the three sets of characters **rw-** shows the permissions for members of the file’s group. - The third of the three sets of characters **r–** shows the permissions for others. Also Read [How to Use chgrp (Change Group Ownership) Command in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-use-chgrp-change-group-ownership-command-in-linux/) ## How to Use Chmod Command Now that we understand different types of permissions, let’s change the permissions of the file using some examples. To change the permissions of the file named file1.txt so that everyone can read and write it, run the following command: ``` chmod u=rw,g=rw,o=rw file1.txt ``` Or ``` chmod 666 file1.txt ``` To change the permissions of the file named **file1.txt** so that the file owner can read, write, and execute while a group and others can read and execute: ``` chmod u=rwx,g=r-x,o=r-x ``` Or ``` chmod 755 file1.txt ``` To grant read, write, & execute permissions to the owner and read permissions to the group and others to a directory named dir1 including all sub-directories and files, use the -R flag: ``` chmod -R u=rwx,g=r,o=r dir1 ``` Or ``` Chmod -R 744 dir1 ``` To grant execute permissions to everyone on a file named **file1.txt**, run: ``` chmod +x file1.txt ``` To remove write permissions for other users, run the following command: ``` chmod o-w file1.txt ``` To recursively remove the read permissions for other users on a given directory, run: ``` chmod -R o-r dirname ``` To remove the read, write, and execute permissions for all users except the file’s owner, run: ``` chmod og-rwx file1.txt ``` To copy the permissions of **file1.txt** and apply it to **file2.txt**, run: ``` chmod --reference=file1.txt file2.txt ``` ## Conclusion In this post, you learned how to use the chmod command to change the file and directory permissions in Linux. Try it on [virtual private servers](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Check Your Server Load in Linux > URL: https://www.atlantic.net/vps-hosting/how-to-check-your-server-load-in-linux/ | Published: 2022-05-01 | Updated: 2023-11-18 | Author: Hitesh Jethva If you are a Linux system administrator, then monitoring the server load is necessary to maintain stable performance. The server load is an average of the amount of computational work that a computer system performs. It can be defined as an average load over a specific interval of time. If your server load is higher, it will become very slow, sometimes resulting in a shutdown. In simple terms, the server load refers to the incoming traffic, login requests, hits, and whether the server is available for all users. There are many tools available in Linux for monitoring server load. Monitoring the server load through the command line can save your time and gives you an accurate value of the server load. In this post, we will show you how to check server load in Linux. ## Using Uptime Command uptime is a very useful command in Linux that shows how long the system has been running. It also shows you a number of users together with load averages. You can run the uptime command as shown below: ``` uptime ``` You will get the following output: ``` 17:23:38 up 24 min, 1 user, load average: 0.81, 0.74, 0.78 ``` A brief explanation of the above output is shown below: - Your server is up from 24 minutes. - Load average over the last 1 minute is 0.81 - Load average over the last 5 minutes is 0.74 - Load average over the last 15 minutes is 0.78 **Also Read** [How to Check Linux CPU Usage or Utilization](https://www.atlantic.net/vps-hosting/how-to-check-linux-cpu-usage-or-utilization/) ## Using Vmstat Command The vmstat command is a built-in monitoring utility in Linux. It shows you information about memory, system processes, paging, interrupts, block I/O, disk, and CPU scheduling. For Ubuntu and Debian-based operating systems, install the Vmstat tool using the following command: ``` apt-get install sysstat -y ``` For CentOS, RHEL, Fedora, and Rocky Linux operating systems, install the Vmstat tool using the following command: ``` dnf install epel-release -y dnf install sysstat -y ``` You can simply run it as shown below: ``` vmstat ``` You should get the following output: ``` procs -----------memory---------- ---swap-- -----io---- -system-- ------cpu----- r b swpd free buff cache si so bi bo in cs us sy id wa st 2 0 0 2392476 253040 1871552 0 0 548 92 1860 1569 15 4 76 5 0 ``` In the above output, under the CPU column, “us” means resources used by the user, “sy” means resources used by the system, and “id” means the percentage of idle resources. You can also run vmstat in a specific interval of time to see the loads in real-time. ``` vmstat 2 5 ``` This command will call vmstat 5 times with an interval of 2 seconds between each call. ``` procs -----------memory---------- ---swap-- -----io---- -system-- ------cpu----- r b swpd free buff cache si so bi bo in cs us sy id wa st 3 0 0 2442280 253900 1833564 0 0 467 85 1847 1480 14 4 78 5 0 0 0 0 2441988 253900 1833564 0 0 0 0 8250 2927 8 3 89 0 0 1 0 0 2441804 253908 1833564 0 0 0 26 10561 2438 4 3 92 1 0 1 0 0 2441404 253916 1833588 0 0 12 20 352 425 1 0 97 2 0 1 0 0 2449468 253916 1825388 0 0 0 0 324 380 1 1 98 0 0 ``` ## Using Top Command The top command is a built-in Linux command that shows a real-time view of running processes, load average, CPU, and memory usage. Run the top command as shown below: ``` top ``` You should see the following output: ``` top - 17:37:26 up 38 min, 1 user, load average: 0.90, 0.92, 0.84 Tasks: 331 total, 1 running, 283 sleeping, 0 stopped, 0 zombie %Cpu(s): 11.6 us, 2.7 sy, 0.0 ni, 85.5 id, 0.2 wa, 0.0 hi, 0.0 si, 0.0 st KiB Mem : 7580260 total, 2385556 free, 3105780 used, 2088924 buff/cache KiB Swap: 2097148 total, 2097148 free, 0 used. 3930244 avail Mem PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND 2314 vyom 20 0 3470536 215568 97432 S 10.9 2.8 1:28.77 gnome-shell 2161 vyom 20 0 979252 81892 52560 S 6.3 1.1 0:51.52 Xorg 3334 vyom 20 0 750476 52016 30808 S 3.6 0.7 0:20.63 gedit 3272 vyom 20 0 795964 37960 28272 S 1.7 0.5 0:01.73 gnome-terminal- ``` **Also Read** [Install Ntopng to Monitor Network Traffic on Ubuntu 20.04](https://www.atlantic.net/vps-hosting/install-ntopng-to-monitor-network-traffic-on-ubuntu/) ## Using Glances Tool Glances is a cross-platform and command-line system monitoring tool written in Python. It can monitor CPU, Load Average, Memory, Network Interfaces, Disk I/O, Processes, and File System space utilization. For Ubuntu and Debian-based operating system, install the Glances tool using the following command: ``` apt-get install glances -y ``` For CentOS, RHEL, Fedora, and Rocky Linux operating systems, install the Glances tool using the following command: ``` dnf install epel-release -y dnf install glances -y ``` Now, run the Glances tool as shown below ``` glances ``` You will get the following screen: ![Glances command-line dashboard](https://www.atlantic.net/wp-content/uploads/2022/04/glances-1024x527.png) You can also monitor Glances via a web browser. To do so, run the Glances tool with –**w** option: ``` glances -w ``` This will start Glances on port **61208**: ``` Glances web server started on http://0.0.0.0:61208/ ``` You can now access Glances via a web browser using the URL **http://your-server-ip:61208**. You should see the following screen: ![Glances web dashboard](https://www.atlantic.net/wp-content/uploads/2022/04/glances-web-1024x495.png) ## Conclusion In the above guide, we explained how to check server load using different tools. You can now choose any tools as per your requirement. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- #### Read More About Load Balancing - [Load Balanced Servers](https://www.atlantic.net/managed-services/load-balancing/) from Atlantic.Net - How [Load Balancing Servers](https://www.atlantic.net/hipaa-data-centers/server-load-balancing/) Works --- --- # Top 11 Best HIPAA Compliant VOIP Providers > URL: https://www.atlantic.net/hipaa-compliant-hosting/top-10-best-hipaa-compliant-voip-providers/ | Published: 2022-05-02 | Updated: 2025-11-11 | Author: Richard Bailey ## **What is a HIPAA Compliant VOIP Provider?** Securing digital communications is an essential requirement of the Privacy and Security Rule amendments of HIPAA legislation. All communications must uphold data integrity and safeguard patient confidentiality. Voice Over Internet Protocol (VoIP) is a digital data phone system that commonly integrates with email and text-based services, and for healthcare organizations and covered entities, VoIP likely must be HIPAA-compliant. The protection required on VoIP systems is varied, typically ranging from protecting CallerID information, voicemail and call recordings, transcription services, SMS (text), email conversions, and all forms of unified communications. VoIP systems are available as SaaS services or on private cloud servers. It’s imperative that both offerings are protected in line with HIPAA compliance. ## What Makes VoIP Communications HIPAA Compliant? Healthcare professionals should make certain that their chosen solution is a fully compliant HIPAA (and preferably HITECH) VoIP service. To ensure HIPAA compliance, it is advisable that healthcare professionals: - Verify that the VoIP provider offers a Business Associate Agreement (BAA). - Choose a service that offers end-to-end encryption. - Check that your VoIP provider has completed all relevant risk assessments to uphold compliance. - Ensure that the VoIP platform implements the necessary access controls, for example, making sure that access to the phone system is password protected. - Make sure that the chosen VoIP platform has detailed audit logging available. - Confirm that the VoIP service has user authentication built-in. - Ensure that all application executables are digitally signed (SSL/TLS) to ensure data integrity. ## What Are the Best HIPAA-Compliant VoIP Providers? While there are hundreds of [VoIP](https://getvoip.com/library/what-is-voip/) providers currently available, there are only a few that are fully HIPAA compliant. However, many VoIP services can be made compliant with some technical adjustments if hosted on HIPAA compliant hosting. There are subtle differences between these solutions and below we have highlighted some of the top HIPAA Compliant VoIP Providers: ## 1. VoIPX International VoIPX International is a 100% U.S.-based company established in 2009 and headquartered in New York. VoIPX is a leading provider of Cloud-Based Business Phone services in the United States and around the globe. They are dedicated to businesses that are focused on cost savings and time management and are one of the few VoIP providers that hold a HIPAA compliant accreditation. ## 2. iPlum [iPlum](https://iplum.com) provides a HIPAA-compliant VoIP tool for healthcare teams, where each user gets a separate business number for calls and texts on their own device. It supports encryption, call recording, secure voicemail, and text archiving to help organizations meet HIPAA communication requirements. It is well-suited to clinics and group practices that want to modernize patient communication and stay aligned with HIPAA safeguards. ## 3. Dialpad Dialpad is another HIPAA compliant service that features unlimited calls, call recording, and custom routing out of the box. But like others, it requires action from the user to achieve full compliance. The Dialpad service undergoes rigorous security audits to ensure it is in-line with HIPAA safeguards, and they are happy to sign a Business Associate Agreement. Identity and access controls are built-in, but the customer is required to make the configuration changes. ## 4. Freshdesk Contact Center (Freshcaller) Freshcaller is part of the Freshworks contact center solution, a cloud-based private exchange digital phone system that is suitable for healthcare organizations. Freshcaller can be made HIPAA compliant and the company is happy to sign a BAA. Freshdesk provides a secure operating environment (SOE) to keep healthcare data isolated and safe. It offers great levels of encryption and flexible recording options. ## 5. TalkRoute TalkRoute is a popular VoIP phone system for offices, home workers, and mobile users. Importantly, the service can be made HIPAA compliant with some minor changes and HIPAA compliant hosting. The company is willing to sign a BAA, but this does require the healthcare provider to use the Enterprise plan. TalkRoute configuration needs to be changed to match HIPAA safeguards, such as disabling the sending of voicemails to email and disabling text messaging features. ## 6. Nextiva Nextiva is part of NextOS services and their VoIP platform is HIPAA compliant. This includes voice calls, call recording, Nextiva Analytics, fax, and more. To maintain HIPAA compliance, some of the Nextiva features have been limited or are disabled altogether. For example, visual voicemail is only supported on the Nextiva app, but emailing voicemails and faxes is disabled. ## 7. RingCentral RingCentral is a feature-packed VoIP service that is HIPAA-ready, meaning that the service can be compliant but the customer must ensure the supporting infrastructure is in scope. RingCentral will sign a Business Associate Agreement (BAA) and the platform can be configured to automatically delete data to remain compliant. This includes RingCentral MVP data, RingCentral fax data, RingCentral professional account data, voice recordings, voicemail, and so on. ## 8. Zoom Healthcare Zoom made a name for itself during the Covid-19 global pandemic, and they now offer a Zoom healthcare license package that comes with a signed BAA. Zoom Healthcare keeps protected health information (PHI) secure and private with AES encryption as standard. Users can control meeting privacy and manage the security of Waiting Rooms. VoIP features require passcodes and locked room functionality is great for private consultations. ## 9. Vonage Vonage is a HIPAA and HITRUST certified VoIP provider with a focus on SMS and Video messaging for e-visits and medical consultations. Vonage must run on a HIPAA compliant hosting platform to remain compliant. It features video consultations, group discussion sessions, care and drug reminders, status notifications, critical alerts, and more. The Vonage Video API and SMS API allow these communications to be embedded with popular healthcare applications. ## 10. Ozonetel Ozenetel is a software-based VoIP provider that specializes in HIPAA-compliant call center software. Ozonetel is built to improve the patient experience by reducing wait times, enabling automating callbacks, and multichannel communications. Some of the services require written authorization from the patient to become HIPAA compliant, but the VoIP service is ISO 270001 & 200001 certified and HIPAA, PCI, and GDPR compliant. ## 11. 8×8 8×8 is a HIPAA compliant VoIP service popular with healthcare providers looking for business phone networks. It features unlimited calling, SMS and fax, call recordings, and visual voicemail. It specializes in HIPAA-compliant fax, video conferencing, and text messaging services. All comms are encrypted by default and use secure peer-to-peer connections. Importantly, the vendor has no access to any transmitted information. ## How Can Atlantic.Net Help? Atlantic.Net is a global cloud service provider with over 30 years of industry-leading experience. We have very many happy healthcare clients that leverage Atlantic.Net services for a robust and scalable [HIPAA Compliant hosting solution](https://www.atlantic.net/hipaa-compliant-hosting/) that can integrate directly with your telehealth services. We provide turn-key hosting solutions that include encrypted VPN connectivity, perfect if your medical organization opts for a cloud-based SaaS VoIP service. We encrypt peer-to-peer connections and implement access controls in line with HIPAA safeguard recommendations. Our world-class [HIPAA hosting](https://www.atlantic.net/hipaa-compliant-hosting/) facilities can power your healthcare infrastructure, giving you the performance needed to build your own VoIP platform. Why not speak to the team about using our service for your very own HIPAA-Complaint VoIP provider? If you are a healthcare provider in the market for a secure HIPAA Compliant cloud hosting service, [contact our sales team](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) to find out how Atlantic.Net can help you. --- #### Read More About HIPAA IT Compliance - [HIPAA IT Compliance](https://www.atlantic.net/hipaa-data-centers/hipaa-compliant-it-infrastructure-guide/) Guide - Best [HIPAA Compliant Fax](https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-fax-services-in-2021/) Service - Best [HIPAA Compliant Email Service](https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-email-service-in-2021/) - Top Considerations for a [HIPAA-Compliant Database](https://www.atlantic.net/hipaa-compliant-hosting/top-10-considerations-for-a-hipaa-compliant-database/) - [What Is a BAA?](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) - [SSAE16, SAAE18, SOC1, SOC2](https://www.atlantic.net/hipaa-compliant-hosting/ssae-16-soc-1-soc2-care/) – Why You Should Care - Best [Healthcare Software Development](https://www.atlantic.net/hipaa-compliant-hosting/top-10-healthcare-software-development-companies/) Companies - Best [HIPAA Consulting](https://www.atlantic.net/hipaa-compliant-hosting/top-10-hipaa-consulting-companies-in-2020/) Companies - Is It [HIPPA or HIPAA?](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-vs-hippa/) --- --- # How to Check if a Port Is Open on a Remote Linux System or Server > URL: https://www.atlantic.net/vps-hosting/how-to-check-open-port-on-a-remote-linux-system/ | Published: 2022-05-03 | Updated: 2024-06-01 | Author: Hitesh Jethva A Port is a logical number assigned to a process running on Linux. The port can be defined as an integer number between **0** to **65535**. Ports with numbers **0–1023** are called system or well-known ports, while ports with numbers **49152-65535** are called dynamic, private, or ephemeral ports. If you are a Linux system administrator, you should know which ports are open and running on a remote system. There are several ways to find an open port on Linux. This post will show the most reliable ways to find an open port on a remote Linux system. ## Find Open Port Using Netcat Command Netcat is a Linux command-line utility that reads and writes data across network connections using TCP or UDP protocol. It also allows us to find open ports on a remote Linux system. By default, the Netcat utility is not included in the Linux system. You will need to install it manually using the package manager. For Ubuntu and Debian-based operating systems, install the Netcat utility using the following command: ``` apt-get install netcat -y ``` For RHEL, CentOS, Fedora, and Rocky Linux operating systems, install the Netcat utility using the following command: ``` dnf install nc -y ``` The basic syntax to use the Netcat command is shown below: ``` nc [-options] [host_name or ip] [port_number] ``` For example, to check if port **80** is open on the remote host **172.20.10.2**, run the following command: ``` nc -zv 172.20.10.2 80 ``` If port 80 is open on a remote host, you will get the following output: ``` Connection to 172.20.10.2 80 port [tcp/http] succeeded! ``` **Where**: - **-z** : Sets nc to scan for listening daemons. - **-v** : Show output in verbose mode. You can also specify a range of ports to be scanned: ``` nc -zv 172.20.10.2 40-80 ``` The above command will scan for all ports between 40 and 80. #### **Also Read** [Netstat Command Line Tips and Tricks](https://www.atlantic.net/vps-hosting/netstat-command-line-tips-and-tricks/) ## Find Open Port Using Nmap Command Nmap is a powerful and very popular command-line utility used to perform network-related tasks. By default, the Nmap utility is not included in the Linux system. You will need to install it manually using the package manager. For Ubuntu and Debian-based operating systems, install the Nmap utility using the following command: ``` apt-get install namp -y ``` For RHEL, CentOS, Fedora, and Rocky Linux operating systems, install the Nmap utility using the following command: ``` dnf install nmap -y ``` The basic syntax to use the Nmap command is shown below: ``` nmap [-options] [HostName or IP] [-p] [PortNumber] ``` For example, to get a list of all open ports on a remote host **172.20.10.2**, run the following command: ``` nmap 172.20.10.2 ``` You should see all open ports in the following output: ``` Starting Nmap 7.60 ( https://nmap.org ) at 2022-04-05 14:05 IST Nmap scan report for vyompc (172.20.10.2) Host is up (0.000078s latency). Not shown: 996 closed ports PORT STATE SERVICE 22/tcp open ssh 23/tcp open telnet 80/tcp open http 7070/tcp open realserver Nmap done: 1 IP address (1 host up) scanned in 0.88 seconds ``` If you want to check if a particular port is open on the remote host, use the **-p** option: ``` nmap -Pn -p 80 172.20.10.2 ``` You will get the following output: ``` Starting Nmap 7.60 ( https://nmap.org ) at 2022-04-05 14:08 IST Nmap scan report for vyompc (172.20.10.2) Host is up (0.00011s latency). PORT STATE SERVICE 80/tcp open http Nmap done: 1 IP address (1 host up) scanned in 0.04 seconds ``` ## Find Open Port Using Telnet Command [Telnet](https://www.atlantic.net/vps-hosting/how-to-install-and-use-telnet-on-debian/) is another network protocol used to virtually access a remote computer. It also allows you to find open ports on remote systems. You can install it manually using the package manager. For Ubuntu and Debian-based operating systems, install the Telnet utility using the following command: ``` apt-get install telnet -y ``` For RHEL, CentOS, Fedora, and Rocky Linux operating systems, install the Telnet utility using the following command: ``` dnf install telnet -y ``` The basic syntax to use the Telnet command is shown below: ``` telnet [HostName or IP] [PortNumber] ``` For example, to check if port **22** is open on a remote host **172.20.10.2**, run the following command: ``` telnet 172.20.10.2 22 ``` If port **22** is open, you will get the following output: ``` Trying 172.20.10.2... Connected to 172.20.10.2. Escape character is '^]'. SSH-2.0-OpenSSH_7.6p1 Ubuntu-4ubuntu0.6 ``` If port **22** is not open, you will get the following output: ``` Trying 172.20.10.2... telnet: Unable to connect to remote host: Connection refused ``` ## Conclusion This guide shows how to find an open port on a remote machine using different commands. You can now choose your preferred tool to scan the remote system and find an open port. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install MySQL 8.4 on Rocky Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-mysql-8-4-on-rocky-linux-10/ | Published: 2022-05-04 | Updated: 2025-10-15 | Author: Hitesh Jethva MySQL is a free, open-source, and extremely popular relational database management system. It is a simple, fast, and scalable SQL-based database system that can be installed as part of a LAMP or LEMP stack. Due to its speed and efficiency, it is the best choice for e-commerce and data warehousing applications. MySQL is readily available for all Linux distributions as well as other operating systems. In this post, we will explain how to install MySQL 8.4 on Rocky Linux 10. ## Install MySQL 8.4 on Rocky Linux 8 By default, MySQL 8.4 is not included in the Rocky Linux AppStream repository. You will need to install it from MySQL repo maintained by Oracle. First, install the MySQL repo using the command below. ``` dnf install https://dev.mysql.com/get/mysql84-community-release-el9-1.noarch.rpm ``` Now, install MySQL 8.0 by running the following command: ``` dnf install mysql-community-server -y ``` Once MySQL is installed, you can verify the installed version of MySQL using the following command: ``` mysql --version ``` You will get the following output: ``` mysql Ver 8.4.6 for Linux on x86_64 (MySQL Community Server - GPL) ``` **Also Read** [How to Delete or Remove Databases in MySQL](https://www.atlantic.net/dedicated-server-hosting/how-to-delete-or-remove-databases-in-mysql/) ## Manage MySQL 8.4 Service By default, the MySQL service is managed by systemd. You can use the **systemctl** command to manage it from the command line. To start the MySQL service, run the following command: ``` systemctl start mysqld ``` Enable the MySQL service to start at system reboot with the following command: ``` systemctl enable mysqld ``` To check the status of the MySQL service, run the following command: ``` systemctl status mysqld ``` You will get the following output: ``` ● mysqld.service - MySQL Server Loaded: loaded (/usr/lib/systemd/system/mysqld.service; enabled; preset: disabled) Active: active (running) since Wed 2025-10-15 04:51:26 EDT; 2min 41s ago Invocation: 2f1493d9116a4fddbefcc49d5edccad5 Docs: man:mysqld(8) http://dev.mysql.com/doc/refman/en/using-systemd.html Process: 41393 ExecStartPre=/usr/bin/mysqld_pre_systemd (code=exited, status=0/SUCCESS) Main PID: 41494 (mysqld) Status: "Server is operational" Tasks: 34 (limit: 12342) Memory: 450.3M (peak: 468.8M) CPU: 4.552s CGroup: /system.slice/mysqld.service └─41494 /usr/sbin/mysqld ``` ## Secure MySQL Installation By default, MySQL is not secured and the root password is not set. First, retrieve the MySQL root password: ``` grep 'temporary password' /var/log/mysqld.log ``` Output. ``` 2025-10-15T08:51:19.966898Z 6 [Note] [MY-010454] [Server] A temporary password is generated for root@localhost: RE8fgtoYKA;F ``` Now, secure MySQL by running the following command: ``` mysql_secure_installation ``` You will be asked to set up the VALIDATE PASSWORD component: ``` Securing the MySQL server deployment. Enter password for user root: The existing password for the user account root has expired. Please set a new password. New password: Re-enter new password: The 'validate_password' component is installed on the server. The subsequent steps will run with the existing configuration of the component. Using existing password for root. Estimated strength of the password: 100 Change the password for root ? ((Press y|Y for Yes, any other key for No) : N ... skipping. By default, a MySQL installation has an anonymous user, allowing anyone to log into MySQL without having to have a user account created for them. This is intended only for testing, and to make the installation go a bit smoother. You should remove them before moving into a production environment. Remove anonymous users? (Press y|Y for Yes, any other key for No) : Y Success. Normally, root should only be allowed to connect from 'localhost'. This ensures that someone cannot guess at the root password from the network. Disallow root login remotely? (Press y|Y for Yes, any other key for No) : Y Success. By default, MySQL comes with a database named 'test' that anyone can access. This is also intended only for testing, and should be removed before moving into a production environment. Remove test database and access to it? (Press y|Y for Yes, any other key for No) : Y - Dropping test database... Success. - Removing privileges on test database... Success. Reloading the privilege tables will ensure that all changes made so far will take effect immediately. Reload privilege tables now? (Press y|Y for Yes, any other key for No) : Y Success. All done! ``` **Also Read** [How to Allow Remote Connection to MySQL Database Server](https://www.atlantic.net/vps-hosting/how-to-allow-remote-connection-to-mysql-database-server/) ## Connect to the MySQL Server After securing the MySQL, you can connect to the MySQL shell using the following command: ``` mysql -u root -p ``` You will be asked to provide your root password: ``` Enter password: ``` Provide your root password and press the Enter key. Once you are logged in, you should see the MySQL shell in the following output: ``` Welcome to the MySQL monitor. Commands end with ; or \g. Your MySQL connection id is 13 Server version: 8.4.6 MySQL Community Server - GPL Copyright (c) 2000, 2025, Oracle and/or its affiliates. Oracle is a registered trademark of Oracle Corporation and/or its affiliates. Other names may be trademarks of their respective owners. Type 'help;' or '\h' for help. Type '\c' to clear the current input statement. mysql> ``` You can check the MySQL version with the following command: ``` mysql> SELECT VERSION (); ``` You will get the following output: ``` +------------+ | VERSION () | +------------+ | 8.4.6 | +------------+ ``` ## Create a Database and User in MySQL To create a database named **testdb**, run the following command: ``` mysql> CREATE DATABASE testdb; ``` To create a user named **testuser**, run the following command: ``` mysql> CREATE USER 'testuser'@'localhost' IDENTIFIED BY 'securepassword'; ``` To grant all the privileges to the **testdb** database, run the following command: ``` mysql> GRANT ALL ON testdb.* TO 'testuser'@'localhost'; ``` Now, flush the privileges to apply the changes: ``` mysql> FLUSH PRIVILEGES; ``` To list all MySQL users, run the following command: ``` mysql> select user from mysql.user; ``` You will get the following output: ``` +------------------+ | user | +------------------+ | mysql.infoschema | | mysql.session | | mysql.sys | | root | | testuser | +------------------+ ``` To list all databases, run the following command: ``` mysql> SHOW DATABASES; ``` You should see the following output: ``` +--------------------+ | Database | +--------------------+ | information_schema | | mysql | | performance_schema | | sys | | testdb | +--------------------+ ``` Now, exit from MySQL using the following command: ``` mysql> EXIT; ``` ## Remove or Uninstall MySQL 8 If you don’t need to use MySQL and want to remove it from your system, run the following command: ``` dnf remove @mysql ``` After removing MySQL, remove the MySQL data directory with the following command: ``` rm -rf /var/lib/mysql* ``` ## Conclusion In the above post, we showed you how to install MySQL 8.4 on Rocky Linux 10. We also explained how to create a database and user in MySQL. Try it on a [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Change Open File Limit in Linux > URL: https://www.atlantic.net/vps-hosting/how-to-change-open-file-limit-in-linux/ | Published: 2022-05-05 | Updated: 2023-11-21 | Author: Hitesh Jethva If you are a Linux user and work with many files at a time, then you may often face the error **“Too many open files”** on Linux. This is because you have reached the maximum open file limit set by Linux operating system. In this case, you can use the **ulimit** command to change the default limit set by the operating system. The max open file limit is very useful to prevent your system from sudden crashes. There are two types of open file limits in Linux. - **Hard Limit:** This limit can only be modified by the root user. - **Soft Limit:** This limit can be modified by any normal user. It indicates the current value of the session or user. In this post, we will show you how to change the open file limit on Linux. ## Check Open File Limits in Linux To check the number of files that a user can have opened per login session, run the following command: ``` cat /proc/sys/fs/file-max ``` You will get the following output: ``` 752300 ``` The above result may be different based on the operating system. To check the hard limit, run the following command: ``` ulimit -Hn ``` You will get the following output: ``` 4096 ``` To check the soft limit, run the following command: ``` ulimit -Sn ``` You will get the following output: ``` 1024 ``` To check all limits set by the operating system, run the following command: ``` ulimit -a ``` You will get the following output: ``` core file size (blocks, -c) 0 data seg size (kbytes, -d) unlimited scheduling priority (-e) 0 file size (blocks, -f) unlimited pending signals (-i) 29405 max locked memory (kbytes, -l) 65536 max memory size (kbytes, -m) unlimited open files (-n) 1024 pipe size (512 bytes, -p) 8 POSIX message queues (bytes, -q) 819200 real-time priority (-r) 0 stack size (kbytes, -s) 8192 cpu time (seconds, -t) unlimited max user processes (-u) 29405 virtual memory (kbytes, -v) unlimited file locks (-x) unlimited ``` **Also Read** [How to Check Linux CPU Usage or Utilization](https://www.atlantic.net/vps-hosting/how-to-check-linux-cpu-usage-or-utilization/) ## Change Open File Limits in Linux Temporarily In this section, we will show you how to change the open file limits temporarily. To set the hard limit to **10000** temporarily, run the following command: ``` ulimit -Hn 10000 ``` To set the soft limit to **10000** temporary, run the following command: ``` ulimit -Sn 10000 ``` The above limits remain modified temporarily till the current session. ## Change Open File Limits in Linux Permanently You can edit the **/etc/security/limits.conf** file to set the open file limits permanently. Edit the /etc/security/limits.conf file as shown below: ``` nano /etc/security/limits.conf ``` Change the hard limits to **10000** for all users, add the following line: ``` * hard nofile 10000 ``` Change the soft limits to **10000** for all users, add the following line: ``` * soft nofile 10000 ``` If you want to set the limit only for a specific user, add the following line: ``` user1 hard nofile 8000 ``` Save and close the fil,e then log out and log back again to apply the changes. You can now check the new limits using the following command: ``` ulimit ``` **Also Read** [How to Set Up an Rsync Daemon on Your Linux Server](https://www.atlantic.net/vps-hosting/how-to-setup-rsync-daemon-linux-server/) ## Conclusion In this guide, we explained how to see and set the open file limits on Linux. If you are running the Apache webserver or Oracle database server then you may require a higher open file limit. In this case, you can increase the open file limit to prevent your application from crashing. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Delete or Remove Databases in MySQL > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-delete-or-remove-databases-in-mysql/ | Published: 2022-05-06 | Updated: 2024-04-19 | Author: Hitesh Jethva If you are a database or Linux system administrator, then you may often need to delete unwanted databases from your system. There are several ways to delete a MySQL database in Linux. You can either use the MySQL command-line or phpMyAdmin to delete a MySQL database. You must have a MySQL user account with delete privileges to delete a MySQL database from your system. In this tutorial, we will show you how to delete (or drop) a MySQL or MariaDB database in Linux. ## Delete MySQL Database with mysqladmin mysqladmin is a MySQL built-in command-line utility that allows you to create and delete MySQL databases, check MySQL processes, and set a MySQL root password via a command-line interface. First, use the following command to list all available databases in your system: ``` mysqlshow -u root -p ``` You will get a list of all databases in the following output: ``` +--------------------+ | Databases | +--------------------+ | drupaldb | | information_schema | | magentodb | | mysql | | performance_schema | | sys | | wpdb | +--------------------+ ``` Now, pick the **drupaldb** database from the above list and delete it by running the following command: ``` mysqladmin -u root -p drop drupaldb ``` You should see the following output: ``` Dropping the database is potentially a very bad thing to do. Any data stored in the database will be destroyed. Do you really want to drop the 'drupaldb' database [y/N] y Database "drupaldb" dropped ``` **Also Read** [How to Install and Use MySQL Workbench on Ubuntu 18.04](https://www.atlantic.net/vps-hosting/how-to-install-and-use-mysql-workbench-on-ubuntu/) ## Delete MySQL Database within MySQL Console MySQL databases can also be deleted after logging into the MySQL shell. To do so, log into the MySQL console with the root user using the following command: ``` mysql -u root -p ``` Once you are logged in, you should see the following output: Next, list all available databases with the following command: ``` mysql> show databases; ``` You should see all databases in the following output: ``` +--------------------+ | Database | +--------------------+ | drupaldb | | information_schema | | magentodb | | mysql | | performance_schema | | sys | | wpdb | +--------------------+ ``` Next, delete the MySQL database named **magentodb** from the above list with the following command: ``` mysql> drop database magentodb; ``` Next, exit from the MySQL console with the following command: ``` mysql> exit; ``` You can also delete the MySQL database named **wpdb** without logging into the MySQL console as shown below: ``` mysql -u root -p -e "drop database wpdb"; ``` ## Delete MySQL Database with PhpMyAdmin Before starting, make sure [phpMyAdmin](https://www.atlantic.net/vps-hosting/how-to-install-and-secure-phpmyadmin-on-centos-8/) is installed on your server. Next, open your web browser and access the PhpMyAdmin web UI using the URL **http://your-server-ip/phpmyadmin**. You should see the following page: ![phpMyAdmin login page](https://www.atlantic.net/wp-content/uploads/2022/04/a1-1024x554.png) Provide your MySQL root username and password and click on the **Go** button. You will be redirected to the PhpMyAdmin dashboard on the following page: ![phpMyAdmin dashboard page](https://www.atlantic.net/wp-content/uploads/2022/04/a2-1024x508.png) Now, click on **Databases**. You should see all the databases on the following page: ![phpMyAdmin drop database page](https://www.atlantic.net/wp-content/uploads/2022/04/a4-1024x510.png) Now, select the database you want to delete and click on the **Drop** button to delete the selected database. ## Conclusion In the above post, we explained how to delete a MySQL database via command-line and PhpMyAdmin. Try it on a [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Latest Linux Kernel on Ubuntu > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-latest-linux-kernel-on-ubuntu/ | Published: 2022-05-07 | Updated: 2025-05-19 | Author: Hitesh Jethva The kernel is the core and most essential component of Linux operating systems. It provides an interface between software applications and computer hardware. It manages I/O disks, filesystems, CPU, and processes. The kernel is responsible for managing resources as efficiently as possible. The community of kernel Developers builds and deploys patches and updates to the Linux kernel to roll out security updates, bug fixes, and new functionality. If you are using a Linux operating system, updating the kernel to the latest version is a good idea. This post will show you how to install the latest Linux kernel on Ubuntu 24.04. ## Step 1 – Update and Upgrade the System First, check your current operating system using the following command: ``` lsb_release -a ``` You will get your operating system version in the following output: ``` No LSB modules are available. Distributor ID: Ubuntu Description: Ubuntu 24.04.2 LTS Release: 24.04 Codename: noble ``` Next, install the required dependencies with the following command: ``` apt-get install gnupg2 wget -y ``` Next, update and upgrade all system packages to the latest version. ``` apt-get update -y apt-get upgrade -y ``` Once all the packages are upgraded, restart your system to apply the changes: ``` reboot ``` ## Step 2 – Check the Current Kernel Version Next, check the currently installed kernel version with the following command: ``` uname -r ``` You will get the current kernel version in the following output: ``` 6.8.0-54-generic ``` ## Step 3 – Download the Linux Kernel Installation Script Next, download the Linux kernel installation script on your system. This script will allow us to install the latest kernel on Linux. You can download it using the [wget command](https://www.atlantic.net/dedicated-server-hosting/how-to-download-file-using-wget-in-linux/): ``` wget https://raw.githubusercontent.com/pimlie/ubuntu-mainline-kernel.sh/master/ubuntu-mainline-kernel.sh ``` Once the download is complete, you will get the following output: ``` --2025-05-13 15:35:52-- https://raw.githubusercontent.com/pimlie/ubuntu-mainline-kernel.sh/master/ubuntu-mainline-kernel.sh Resolving raw.githubusercontent.com (raw.githubusercontent.com)... 185.199.109.133, 185.199.111.133, 185.199.110.133, ... Connecting to raw.githubusercontent.com (raw.githubusercontent.com)|185.199.109.133|:443... connected. HTTP request sent, awaiting response... 200 OK Length: 26474 (26K) [text/plain] Saving to: ‘ubuntu-mainline-kernel.sh’ ubuntu-mainline-kernel.sh 100%[=================================================================>] 25.85K --.-KB/s in 0.001s 2025-05-13 15:35:52 (26.9 MB/s) - ‘ubuntu-mainline-kernel.sh’ saved [26474/26474] ``` Next, set the execution permissions to the downloaded script with the following command: ``` chmod +x ubuntu-mainline-kernel.sh ``` ## Step 4 – Install the Latest Kernel Version First, list all available kernel versions using the following command: ``` ./ubuntu-mainline-kernel.sh -r ``` You will see all kernel versions in the following output: ``` v6.12.16 v6.12.17 v6.12.18 v6.12.19 v6.12.20 v6.12.21 v6.12.22 v6.12.23 v6.12.24 v6.12.25 v6.12.28 v6.12.29 v6.13.0 v6.13.1 v6.13.2 v6.13.4 v6.13.5 v6.13.6 v6.13.7 v6.13.8 v6.13.9 v6.13.10 v6.13.11 v6.13.12 v6.14.0 v6.14.1 v6.14.2 v6.14.3 v6.14.4 v6.14.6 v6.14.7 ``` Next, run the Linux kernel installation script followed by your kernel version to install the specified kernel on your system. ``` ./ubuntu-mainline-kernel.sh -i v6.14.7 ``` You will see the following output: ``` Downloading amd64/CHECKSUMS: 100% Downloading amd64/CHECKSUMS.gpg: 100% Importing kernel-ppa gpg key ok Signature of checksum file has been successfully verified Checksums of deb files have been successfully verified with sha256sum Installing 4 packages Cleaning up work folder ``` ## Step 5 – Restart the System After the latest kernel installation, you must restart your system to boot the system from the newly installed kernel. ``` reboot ``` #### **Also Read** [How to Use Rsync to Copy/Sync Files Between Servers](https://www.atlantic.net/vps-hosting/how-to-use-rsync-copy-sync-files-servers/) ## Step 6 – Verify the Latest Kernel Version After the successful restart, run the following command to check the newly installed kernel version: ``` uname -r ``` You should see the following output: ``` 6.14.7-061407-generic ``` ## Conclusion In this post, we explained how to install the latest Kernel version on Ubuntu 24.04. You can now easily upgrade or install the latest Kernel version to your server. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Find the Total Size of a Directory in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-find-the-total-size-of-a-directory-in-linux/ | Published: 2022-05-08 | Updated: 2025-12-12 | Author: Hitesh Jethva Finding the size of files and directories from the Linux command line can feel confusing if you are new to Linux. Fortunately, Linux provides a powerful utility called **`du`** (Disk Usage) that helps you analyze disk space usage easily. The `du` command shows how much disk space files and directories consume. With different options, you can view sizes in human-readable format, calculate totals, sort directories by size, and even find the largest files on your system. In this guide, you will learn how to check directory and file sizes in Linux using the**du**command, with clear examples. ## Basic Syntax of the du Command The basic syntax of the du command is shown below: ``` du [OPTION]... [FILE]... ``` A brief explanation of commonly used option is shown below: - -c – Produce a grand total - -h – Print sizes in a human-readable format - -S – For directories do not include the size of subdirectories - -a – Display the disk usage of all items including files and directories - -k – Display the disk usage size in kilobytes - -m – Display the disk usage size in megabytes - -X – Exclude certain file type **Also Read** [How to Check Size of Files and Directory on Linux](https://www.atlantic.net/vps-hosting/how-to-check-size-of-files-and-directory-on-linux/) ## Find Current Directory Size Running `du` without any options shows the disk usage of the current directory and all its subdirectories. ``` du ``` You will get the following output: ``` 8 ./html/example.com 20 ./html 3424 ./log/installer 84 ./log/apache2 236 ./log/apt du: cannot read directory './log/gdm3': Permission denied 4 ./log/gdm3 483588 ./log/journal/cfefe3a7c8694e51879fb521a2021b2e 483592 ./log/journal 64 ./log/cups 500192 ./log 509272 . ``` ## Find the Size of the Specific Directory To check the size of the specific directory, run the **du** command by specifying a directory: ``` du /var/www/html ``` This command will display the size of the **html** directory, including all of its sub-directories: ``` 8 /var/www/html/example.com 20 /var/www/html ``` If you want to find the size of the multiple directories, run the following command: ``` du /home/vyom/Music/ /home/vyom/Downloads ``` You will get the following output: ``` 4996 /home/vyom/Music/ 8 /home/vyom/Downloads/html/example.com 20 /home/vyom/Downloads/html 3424 /home/vyom/Downloads/log/installer 84 /home/vyom/Downloads/log/apache2 236 /home/vyom/Downloads/log/apt 4 /home/vyom/Downloads/log/gdm3 483588 /home/vyom/Downloads/log/journal/cfefe3a7c8694e51879fb521a2021b2e 483592 /home/vyom/Downloads/log/journal 64 /home/vyom/Downloads/log/cups 500192 /home/vyom/Downloads/log 509272 /home/vyom/Downloads ``` ## Display the Directory Size in Human Readable Format By default, the **du** command will display size in bytes. You can use the –**h** option with the **du** command to display the size of the directory in a human-readable format. ``` du -h Downloads/ ``` You will get the following output: ``` 8.0K Downloads/html/example.com 20K Downloads/html 3.4M Downloads/log/installer 84K Downloads/log/apache2 236K Downloads/log/apt 4.0K Downloads/log/gdm3 473M Downloads/log/journal/cfefe3a7c8694e51879fb521a2021b2e 473M Downloads/log/journal 64K Downloads/log/cups 489M Downloads/log 498M Downloads/ ``` ## Display the Directory Size in a Specific Format You can also display the directory size in KB, MB, or GB format. For example, to display the directory size in megabytes, use the **-m** option: ``` du -m Downloads/ ``` You will get the following output: ``` 1 Downloads/html/example.com 1 Downloads/html 4 Downloads/log/installer 1 Downloads/log/apache2 1 Downloads/log/apt 1 Downloads/log/gdm3 473 Downloads/log/journal/cfefe3a7c8694e51879fb521a2021b2e 473 Downloads/log/journal 1 Downloads/log/cups 489 Downloads/log 498 Downloads/ ``` To display the directory size in kilobytes, use the **-k** option: ``` du -k Downloads/ ``` You will get the following output: ``` 8 Downloads/html/example.com 20 Downloads/html 3424 Downloads/log/installer 84 Downloads/log/apache2 236 Downloads/log/apt 4 Downloads/log/gdm3 483588 Downloads/log/journal/cfefe3a7c8694e51879fb521a2021b2e 483592 Downloads/log/journal 64 Downloads/log/cups 500192 Downloads/log 509272 Downloads/ ``` ## Find the Total Size Of The Directory You can use the du command with the **-hs** option to display the total size of the specified directory in a human-readable format. ``` du -sh /etc/ ``` You will get the total size of the /etc directory in the following output: ``` 16M /etc/ ``` If you want to display the grand total of the combined directories in human-readable format, use the **-c** option: ``` du -csh Downloads/ Music/ Pictures/ ``` You will get the following output: ``` 498M Downloads/ 4.9M Music/ 2.6M Pictures/ 505M total ``` ## Find the Size of Both Files and Directories You can use the **du** command with the **-a** option to display the size of both files and directories: ``` du -ah Downloads/ ``` You will get the following output: ``` 8.0K Downloads/LocalSettings.php 4.0K Downloads/html/index.html 4.0K Downloads/html/index.nginx-debian.html 4.0K Downloads/html/example.com/index.html 8.0K Downloads/html/example.com 20K Downloads/html 8.9M Downloads/apache-zookeeper-3.5.6-bin.tar.gz 4.0K Downloads/image.png 8.9M Downloads/ ``` **Also Read** [How to Use Rsync to Copy/Sync Files Between Servers](https://www.atlantic.net/vps-hosting/how-to-use-rsync-copy-sync-files-servers/) ## Sort Directories By Their Size If your system is running out of disk space and you want to find out which directories consume the most disk size, use the following command to sort all directories by their size: ``` du -h --max-depth=1 /var/log | sort -hr ``` You will get the following output: ``` 1.9G /var/log/journal 1.9G /var/log 3.4M /var/log/installer 476K /var/log/teamviewer15 240K /var/log/apt 100K /var/log/unattended-upgrades 84K /var/log/apache2 68K /var/log/nginx 64K /var/log/postgresql 64K /var/log/cups 40K /var/log/mysql 8.0K /var/log/hp 4.0K /var/log/sysstat 4.0K /var/log/speech-dispatcher 4.0K /var/log/gdm3 4.0K /var/log/dist-upgrade ``` ## Find the Largest File or Directory You use the **du** command with sort to find the largest file or directory in your system. Run the **du** command with **-a** option to find and display the largest file and directory: ``` du -a / | sort -n -r | head -n 10 ``` You should see the following output: ``` 1653740 / 931232 /usr 483812 /swapfile 425916 /usr/lib 268820 /usr/src 164476 /usr/share 156912 /var 151216 /usr/lib/x86_64-linux-gnu 142644 /var/lib 137388 /usr/lib/modules ``` ## Scan up to a Chosen Subdirectory Level By default, the `du` command scans **all subdirectories recursively**, which can produce a very long output. When you only want a **summary view** of disk usage, you can limit how deep `du` scans using the `--max-depth` option. For example, to scan **only the selected directory itself** and ignore all subdirectories, set `--max-depth=0`. ``` du -h --max-depth=0 ./Downloads/ ``` Output. ``` 2.7G ./Downloads/ ``` This shows only the total size of the Downloads directory, without listing any subfolders. To view the size of **direct child directories** (one level deep), use: ``` du -h --max-depth=1 ./Downloads/ ``` Output. ``` 6.6M ./Downloads/June 604K ./Downloads/olx 46M ./Downloads/Linuxbuz 4.8M ./Downloads/DeepSeek-R1 13M ./Downloads/linuxbuz 3.2M ./Downloads/11zon_compressed 2.8M ./Downloads/roadmap ``` This helps you quickly identify **which subdirectory consumes the most space**. ## Conclusion The `du` command is one of the most useful Linux tools for analyzing disk usage. Whether you want to check the size of a directory, find large files, sort directories by size, or monitor disk usage on a server, `du` gives you full control from the command line. By using options like `-h`, `-s`, `-a`, and `sort`, you can quickly identify disk space issues and free up storage when needed. Try these commands on your Linux system or on a **VPS or dedicated server** to keep your file system clean and optimized. --- # How to Kill Running Processes in Linux > URL: https://www.atlantic.net/vps-hosting/how-to-kill-running-processes-in-linux/ | Published: 2022-05-09 | Updated: 2023-11-26 | Author: Hitesh Jethva In Linux, an instance of a running service, application, or script is called a process. When you run any command, program, or application, a process is created for it. Each process has its own process id that is associated with a specific user and group. If any processes consume too many resources or become unresponsive, then you may need to kill them. In this case, you can use the kill command to stop the process without restarting your server. In this post, we will show you how to kill running processes in Linux. ## View Running Processes in Linux The simplest and easiest way to get a list of all running processes is to use the top command. You can run the top command as shown below to list all running processes: ``` top ``` You will get all running processes in the following output: ``` Tasks: 344 total, 1 running, 297 sleeping, 0 stopped, 0 zombie %Cpu(s): 22.6 us, 6.0 sy, 0.1 ni, 67.1 id, 3.9 wa, 0.0 hi, 0.4 si, 0.0 st KiB Mem : 7580260 total, 2103076 free, 3174408 used, 2302776 buff/cache KiB Swap: 2097148 total, 2097148 free, 0 used. 3901388 avail Mem PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND 5994 vyom 20 0 44344 4160 3444 R 11.8 0.1 0:00.03 top 2206 vyom 20 0 1046476 89792 60368 S 5.9 1.2 1:15.26 Xorg 2359 vyom 20 0 3471324 216412 97596 S 5.9 2.9 1:58.27 gnome-shell 2745 vyom 20 0 1776552 136144 99424 S 5.9 1.8 1:09.93 skypeforlinux 2775 vyom 20 0 37.371g 169524 117660 S 5.9 2.2 1:05.09 skypeforlinux 5655 root 20 0 0 0 0 I 5.9 0.0 0:00.30 kworker/u8:3-ev 1 root 20 0 160356 9464 6632 S 0.0 0.1 0:03.50 systemd 2 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kthreadd 3 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 rcu_gp 4 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 rcu_par_gp 6 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kworker/0:0H-kb 9 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 mm_percpu_wq 10 root 20 0 0 0 0 S 0.0 0.0 0:00.40 ksoftirqd/0 11 root 20 0 0 0 0 I 0.0 0.0 0:03.58 rcu_sched 12 root rt 0 0 0 0 S 0.0 0.0 0:00.01 migration/0 13 root -51 0 0 0 0 S 0.0 0.0 0:00.00 idle_inject/0 14 root 20 0 0 0 0 S 0.0 0.0 0:00.00 cpuhp/0 15 root 20 0 0 0 0 S 0.0 0.0 0:00.00 cpuhp/1 16 root -51 0 0 0 0 S 0.0 0.0 0:00.00 idle_inject/1 ``` You can press k and enter the process ID to kill the process directly from the top interface. #### **Also Read** [Find Top 10 Running Processes by Memory and CPU Usage](https://www.atlantic.net/vps-hosting/find-top-10-running-processes-by-memory-and-cpu-usage/) ## Find the Process Using the ps Command ps is a command-line utility that will display a complete listing of running processes in the specified format. The basic syntax of the ps command is shown below: ``` ps [OPTION] ``` A brief explanation of each option is shown below: - -a – Display running processes of all users. - -u – Display detailed information about each of the processes. - -x – Display processes that are controlled by the daemon. For example, run the following command to get a detailed process list of all processes. ``` ps aux ``` You will get the following output: ``` USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND root 1 0.1 0.1 160356 9464 ? Ss 15:51 0:03 /sbin/init splash root 2 0.0 0.0 0 0 ? S 15:51 0:00 [kthreadd] root 3 0.0 0.0 0 0 ? I< 15:51 0:00 [rcu_gp] root 4 0.0 0.0 0 0 ? I< 15:51 0:00 [rcu_par_gp] root 6 0.0 0.0 0 0 ? I< 15:51 0:00 [kworker/0:0H-kb] root 9 0.0 0.0 0 0 ? I< 15:51 0:00 [mm_percpu_wq] root 10 0.0 0.0 0 0 ? S 15:51 0:00 [ksoftirqd/0] root 11 0.1 0.0 0 0 ? I 15:51 0:03 [rcu_sched] root 12 0.0 0.0 0 0 ? S 15:51 0:00 [migration/0] root 13 0.0 0.0 0 0 ? S 15:51 0:00 [idle_inject/0] root 14 0.0 0.0 0 0 ? S 15:51 0:00 [cpuhp/0] root 15 0.0 0.0 0 0 ? S 15:51 0:00 [cpuhp/1] root 16 0.0 0.0 0 0 ? S 15:51 0:00 [idle_inject/1] root 17 0.0 0.0 0 0 ? S 15:51 0:00 [migration/1] root 18 0.0 0.0 0 0 ? S 15:51 0:00 [ksoftirqd/1] root 20 0.0 0.0 0 0 ? I< 15:51 0:00 [kworker/1:0H-kb] root 21 0.0 0.0 0 0 ? S 15:51 0:00 [kdevtmpfs] root 22 0.0 0.0 0 0 ? I< 15:51 0:00 [netns] ``` The above command will show you all the running processes. You can use the grep command with the ps command to get a PID of a specific process. For example, to get a PID of an Apache process, run the following command: ``` ps aux | grep apache ``` You will get the following output: ``` root 1309 0.0 0.0 73992 4748 ? Ss 15:52 0:00 /usr/sbin/apache2 -k start www-data 1310 0.0 0.0 1285068 4620 ? Sl 15:52 0:00 /usr/sbin/apache2 -k start www-data 1311 0.0 0.0 1285068 4644 ? Sl 15:52 0:00 /usr/sbin/apache2 -k start ``` You can also use the **pidof** command to get a PID of a specific process. ``` pidof apache2 ``` You will get the following output: ``` 1311 1310 1309 ``` ## Kill a Process in Linux At this point, you know how to get the PID of any process. Now, you can use the kill command to kill a running process. To kill a single process, run the following command: ``` kill PID ``` Or ``` kill -9 PID ``` To kill multiple processes, run the following command: ``` kill -9 PID1 PID2 PID3 ``` You can also kill the processes by their names. You can use the **pkill** command to kill a process by its name. To kill the Apache process, run the following command: ``` pkill apache2 ``` You can also use the **killall** command to kill a process by its name: ``` killall mysqld ``` #### **Also Read** [Install Ntopng to Monitor Network Traffic on Ubuntu 20.04](https://www.atlantic.net/vps-hosting/install-ntopng-to-monitor-network-traffic-on-ubuntu/) ## Conclusion In this post, we explained how to find and kill a process in Linux. You can now kill any unresponsive processes by yourself without restarting your server. Try it on your [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How To Set Up SSH Public and Private Key in Linux > URL: https://www.atlantic.net/vps-hosting/how-to-set-up-ssh-public-and-private-key-in-linux/ | Published: 2022-05-10 | Updated: 2023-11-27 | Author: Hitesh Jethva SSH, also known as a “Secure Shell Protocol,” is a protocol used to access a remote Linux system securely over an unsecured network via the command-line interface. SSH allows users to run commands on remote Linux servers, install and remove software packages, and manage everything via command line from a single place. If you are a Linux system administrator and managing multiple servers via SSH, then you may need to provide a root password each time when you connect to the remote server. Remembering passwords for thousands of servers is very difficult for an administrator. In this case, you can use an SSH public and private key pair to connect remote servers without entering a password. In this post, we will show you how to create a public and private key and set up a Linux server for passwordless login. ## Create a Public and Private SSH Key Pair First, you will need to create a public and private key in your local Linux machine. You can use the ssh-keygen command to generate an RSA key pair. ``` ssh-keygen -t rsa ``` You will be asked to define the path to save the key files: ``` Generating public/private rsa key pair. Enter file in which to save the key (/home/vyom/.ssh/id_rsa): ``` Just press the **Enter** key to save the key files in the default location. You will be asked to set a passphrase: ``` Enter passphrase (empty for no passphrase): ``` Just press the **Enter** key to leave it empty. Once the key files are generated, you will get the following output: ``` Your identification has been saved in /home/vyom/.ssh/id_rsa. Your public key has been saved in /home/vyom/.ssh/id_rsa.pub. The key fingerprint is: SHA256:Osc1pEf3PGhYBuDiofx7GG6qbjo1+6Z4rxdcTxdeYsg vyom@vyompc The key's randomart image is: +---[RSA 2048]----+ | ..o. | | .E +.. | | o .oo++ | | . o.o.+o= + | | .o..oS.= o + | | o o..o.o o . | | . o o+oo | |..+ o ++. | |o*=O+o.. | +----[SHA256]-----+ ``` You can now list both public and private key files using the following command: ``` ls -l .ssh/ ``` You will get both files in the following output: ``` -rw------- 1 vyom vyom 1679 Apr 13 10:16 id_rsa -rw-r--r-- 1 vyom vyom 393 Apr 13 10:16 id_rsa.pub -rw-r--r-- 1 vyom vyom 8212 Apr 13 09:36 known_hosts ``` **Also Read** [How to Setup Password-less SSH on Linux](https://www.atlantic.net/vps-hosting/how-to-setup-password-less-ssh-on-linux/) ## Copy SSH Public Key to the Remote Server Next, you will need to copy the public key (id_rsa.pub) file to the remote server that you want to manage from your local machine. You can run the ssh-copy-id command to copy the public key to the remote server: ``` ssh-copy-id root@remote-server-ip ``` You will be asked to provide the password of the remote server to copy the public key to the remote server: ``` /usr/bin/ssh-copy-id: INFO: attempting to log in with the new key(s), to filter out any that are already installed /usr/bin/ssh-copy-id: INFO: 1 key(s) remain to be installed -- if you are prompted now it is to install the new keys root@209.23.8.35's password: Number of key(s) added: 1 Now try logging into the machine, with: "ssh 'root@209.23.8.35'" and check to make sure that only the key(s) you wanted were added. ``` **Also Read** [How to Secure SSH Service with Port Knocking](https://www.atlantic.net/vps-hosting/how-to-secure-ssh-service-with-port-knocking/) ## Connect to Remote Server Without Password At this point, the public key is copied to the remote server. You are now able to connect to the remote server without providing a password. ``` ssh root@your-server-ip ``` Once you are logged in to the remote server, you will get the following output: ``` Activate the web console with: systemctl enable --now cockpit.socket Last failed login: Wed Apr 13 04:39:07 UTC 2022 from 92.255.85.135 on ssh:notty There were 2 failed login attempts since the last successful login. Last login: Wed Apr 13 04:06:28 2022 from 27.61.243.122 [root@linux ~]# ``` ## Conclusion In this post, we explained how to create the public and private keys, copied the public key to a remote server, and accessed the remote Linux server without a password. Hopefully, this will save you a lot of time while managing multiple remote servers. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Find Files with fd Command in Linux > URL: https://www.atlantic.net/vps-hosting/how-to-find-files-with-fd-command-in-linux/ | Published: 2022-05-12 | Updated: 2023-11-21 | Author: Hitesh Jethva Finding files and directories in Linux is an essential skill for any system administrator. The fd command is a command-line tool used to find files and directories in Linux. It is a simple and fast alternative to the find command. Compared to the find command, the fd command has more intuitive syntax, colorized output, and faster search speed. It also supports the use of regular expressions and can ignore hidden files and directories by default. In this post, you will learn how to find files with fd command in Linux. ## Install the fd Command By default, the fd command is included in the default repository of all major operating systems. For Debian and Ubuntu operating systems, install the fd command using the following command: ``` apt-get install fd-find -y ``` For RHEL, Rocky Linux, and Fedora operating systems, install the fd command using the following command: ``` dnf install fd-find -y ``` After installing the fd command, you can check the version of the fd command with the following command: ``` fd --version ``` You will get the following output: ``` fd 7.3.0 ``` **Also Read** [Find a File with Find and Locate Commands in Linux](https://www.atlantic.net/vps-hosting/find-a-file-with-find-and-locate-commands-in-linux/) ## Basic Syntax of fd Command The basic syntax of the fd command is shown below: ``` fd [OPTION] [PATTERN] [PATH] ``` A brief explanation of each option is shown below: - **-H** – Include hidden files and directories in search results. - **-I** – Show the search results that would be ignored by .gitignore, .ignore, or .fdignore files. - **-s** – Perform a case-sensitive search. - **-i** – Perform a case-insensitive search. - **-a** – Show absolute instead of relative paths. - **-L** – Follow symlinks. - **-j** – Used to define the number of threads used for searching. ## The fd Command Basic Usage Using the fd command without any options will search all files and directories in your current working directory: ``` fd ``` You will get the following output: ``` directory1 directory1/my-File1.txt directory1/my-file.txt directory2 directory2/my-File2.txt directory2/my-file2.txt directory3 directory3/File4.txt directory3/file2.png directory3/man directory3/women ``` By default, the fd command will not show the hidden files in the output. You can use the -H option to list all files, including the hidden files. ``` fd -H ``` Output: ``` .allow .git directory1 directory1/my-File1.txt directory1/my-file.txt directory2 directory2/my-File2.txt directory2/my-file2.txt directory3 directory3/File4.txt directory3/file2.png directory3/man directory3/women ``` Use the -p option to search all files in the specified directory: ``` fd -p directory1 ``` Output: ``` directory1 directory1/my-File1.txt directory1/my-file.txt ``` ## Find File with String Match You can use the -F option to find a file that matches a string containing regular expressions. ``` fd -F my-file ``` Output: ``` directory1/my-File1.txt directory1/my-file.txt directory2/my-File2.txt directory2/my-file2.txt ``` ## Find Case Sensitive File You can use the **-s** option to enable case sensitivity and show only case-sensitive files in the result. ``` fd -s file ``` Output: ``` directory1/my-file.txt directory2/my-file2.txt directory3/file2.png ``` ## Find File By Type You can use the **-t** option to find a file by its type. For example, to find all directories and sub-directories in your current working directory, run the following command: ``` fd -t d ``` Output: ``` directory1 directory2 directory3 directory3/man directory3/women ``` To find only regular files use the **-t** option with the **f** indicator: ``` fd -t f ``` Output: ``` directory1/my-File1.txt directory1/my-file.txt directory2/my-File2.txt directory2/my-file2.txt directory3/File4.txt directory3/file2.png ``` To find only executable files, use the **-t** option with the **x** indicator: ``` fd -t x ``` To find only empty files and directories, use the -t option with the **e** indicator: ``` fd -t e ``` **Also Read** [How to Use Rsync to Copy/Sync Files Between Servers](https://www.atlantic.net/vps-hosting/how-to-use-rsync-copy-sync-files-servers/) ## Find File By Extension You can use the **-e** option to find a file by their extensions. To find all .png files, run the following command: ``` fd -e png ``` Output: ``` directory3/file2.png ``` To find both text and png files, run the following command: ``` fd -e png -e txt ``` Output: ``` directory1/my-File1.txt directory1/my-file.txt directory2/my-File2.txt directory2/my-file2.txt directory3/File4.txt directory3/file2.png ``` ## Find File By Location You can use the **-p** option to find a file from a specified location. ``` fd file.txt -p directory1 ``` Output: ``` directory1/my-file.txt ``` You can also find all files from multiple locations. For example, to find all regular files from directory1 and directory2, run the following command: ``` fd . ./directory1 ./directory2 -t f ``` Output: ``` directory1/my-File1.txt directory1/my-file.txt directory2/my-File2.txt directory2/my-file2.txt ``` ## Find File By Size You can use the -S option to find the file by their size. For example, to find all files with a size 1 MB or larger, run the following command: ``` fd -S +1m ``` Run the following command if you want to find all files with size 1 MB or smaller: ``` fd -S -1m ``` ## Find File By Data The fd command will also allow you to find files on the basis of the creation date. You can specify the duration of the week, day, time, or date. For example, find all files that are changed before “2022-02-02 10:00:00,” run the following command: ``` fd -t x --changed-before "2022-02-02 10:00:00" ``` To find all files that are changed within two weeks, run the following command: ``` fd -t x --changed-within 2week ``` To find all files that are changed within five days, run the following command: ``` fd -t x --changed-within 5day ``` ## Conclusion In this post, we explained the fd command with different examples to show you how to find files using your custom parameters. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Connect to MySQL Using PHP > URL: https://www.atlantic.net/vps-hosting/how-to-connect-to-mysql-using-php/ | Published: 2022-05-13 | Updated: 2023-11-18 | Author: Hitesh Jethva Free and open-source MySQL is one of the most popular relational database management systems. It is used to store the content of websites and web applications. If you want to integrate a PHP-based web application with MySQL, you will need to test whether PHP is able to connect to MySQL and execute database queries. To retrieve data from MySQL, you must establish a connection between the database and a PHP script. There are two ways to establish a connection between the database and a PHP script. In this post, we will explain: - How to Connect to MySQL Using PHP MySQLi Extension - How to Connect to MySQL Using PHP Data Objects (PDO) ## Install LAMP Stack Before starting, a LAMP stack must be installed on your server, If not installed, you can install it with the following command: ``` apt-get install apache2 mysql-server php libapache2-mod-php php-mysqli php-pdo -y ``` Once the LAMP stack is installed, start and enable the Apache and MySQL service: ``` systemctl start apache2 mysql systemctl enable apache2 mysql ``` **Also Read** [How to Install Linux, Apache, MySQL, PHP on Ubuntu 20.04](https://www.atlantic.net/vps-hosting/how-to-install-linux-apache-mysql-php-lamp-ubuntu-20-04/) ## Configure MySQL Database Next, you will need to create a test database, a table with some data to query for its contents using a PHP script. First, connect to the MySQL shell with the following command: ``` mysql ``` Once you are connected, create a database and user with the following command: ``` CREATE DATABASE testdb; CREATE USER 'testuser'@'%' IDENTIFIED WITH mysql_native_password BY 'password'; ``` Next, grant all the privileges to the database with the following command: ``` GRANT ALL ON testdb.* TO 'testuser'@'%'; ``` Next, switch the database to testdb and create a table named people: ``` USE testdb; CREATE TABLE people ( item_id INT AUTO_INCREMENT, content VARCHAR(255), PRIMARY KEY(item_id) ); ``` Next, insert some data into the table: ``` INSERT INTO people (content) VALUES ("Hitesh Jethva"); INSERT INTO people (content) VALUES ("Jayesh Jethva"); INSERT INTO people (content) VALUES ("Vyom Jethva"); INSERT INTO people (content) VALUES ("Ninav Jethva"); ``` Next, verify all inserted data with the following command: ``` SELECT * FROM people; ``` You will get the following output: ``` +---------+---------------+ | item_id | content | +---------+---------------+ | 1 | Hitesh Jethva | | 2 | Jayesh Jethva | | 3 | Vyom Jethva | | 4 | Ninav Jethva | +---------+---------------+ ``` Next, flush the privileges and exit from the MySQL with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` **Also Read** [How to Delete or Remove Databases in MySQL](https://www.atlantic.net/dedicated-server-hosting/how-to-delete-or-remove-databases-in-mysql/) ## Connect to MySQL Using PHP MySQLi MySQLi is a MySQL extension that supports MySQL databases and allows users to connect to MySQL and access its content. First, create a PHP script inside the Apache web root directory for connecting to a MySQL database using MySQLi: ``` nano /var/www/html/php-mysqli-connection.php ``` Add the following code: ``` connect_error) { die("Connection failed: " . $conn->connect_error); } echo "Connected to MySQL Using Mysqli Successfully"; echo "

List Table Content

    "; foreach($conn->query("SELECT content FROM $table") as $row) { echo "
  1. " . $row['content'] . "
  2. "; } echo "
"; mysqli_close($conn); ?> ``` Save and close the file when you are done. Now, open your web browser and access the PHP script using the URL **http://your-server-ip/php-mysqli-connection.php**. If PHP is connected to the MySQL server, you will get the table contents on the following screen: ![Connect PHP to MySQL with MySQLi](https://www.atlantic.net/wp-content/uploads/2022/04/p2.png) ## Connect to MySQL Using PHP PDO PDO, also called “PHP Data Objects,” is a PHP extension used for connecting to MySQL databases. First, create a PHP script inside the Apache web root directory for connecting to a MySQL database using PDO: ``` nano /var/www/html/php-pdo-connection.php ``` Add the following code: ``` setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); echo "Connected to MySQL Using PDO Successfully"; echo "

List Table Content

    "; foreach($pdo->query("SELECT content FROM $table") as $row) { echo "
  1. " . $row['content'] . "
  2. "; } echo "
"; } catch (PDOException $e) { print "Error!: " . $e->getMessage() . "
"; die(); } ?> ``` Save and close the file when you are done. Now, open your web browser and access the PHP script using the URL **http://your-server-ip/php-pdo-connection.php**. If PHP is connected to the MySQL server, you will get the table contents on the following screen: ![Connect PHP to MySQL with PDO](https://www.atlantic.net/wp-content/uploads/2022/04/p1.png) ## Conclusion In this post, we explained two ways to connect to a MySQL database using PHP. Both PDO and MySQLi are very useful PHP extensions. However, the MySQLi extension is only used for MySQL databases, while the PDO extension works with 12 different databases. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Use Zip and Unzip Commands in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-use-zip-and-unzip-commands-in-linux/ | Published: 2022-05-14 | Updated: 2024-06-01 | Author: Hitesh Jethva Compressing and uncompressing files and directories is a common task for any system administrator. It is an essential skill when you are working on a headless remote server. Many tools are available to compress and uncompress files and directories. Zip is a popular and cross-platform command-line tool used to compress and archive data in Linux. It allows you to combine multiple files and directories into a single archive file. The Unzip command is used to decompress or extract the content from the compressed archive. This post will show you how to use the Zip and Unzip commands in Linux. ## Install Zip and Unzip By default, the Zip and Unzip tool is available in the default repository of all major Linux distributions. For Debian and Ubuntu operating systems, install Zip and Unzip with the following command: ``` apt-get install zip unzip -y ``` For RHEL, Rocky Linux, and Fedora operating systems, install Zip and Unzip with the following command: ``` dnf install zip unzip -y ``` #### **Also Read** [What Is File Compression?](https://www.atlantic.net/dedicated-server-hosting/what-is-file-compression/) ## Zip a File with zip Command The basic syntax to zip a file is shown below: ``` zip [OPTION] file.zip file ``` For example, to zip a single file run the following command: ``` zip file1.zip file1.txt ``` To zip multiple files, run the following command: ``` zip files.zip file1.txt file2.txt file3.txt ``` Output: ``` adding: file1.txt (deflated 58%) adding: file2.txt (deflated 58%) adding: file3.txt (deflated 58%) ``` ## Add a File to an existing Zip Archive You can use the zip command with **-u** option to add an additional file to an existing zip archive. ``` zip -u files.zip file4.txt ``` Output: ``` adding: file4.txt (deflated 58%) ``` ## View the Content of the Zip File You can use the **zipinfo** command to view the content of the zip file. For example, to view the content of the **files.zip** file, run the following command: ``` zipinfo files.zip ``` Output: ``` Archive: files.zip Zip file size: 12634 bytes, number of entries: 4 -rw-r--r-- 3.0 unx 7224 tx defN 22-Apr-19 17:16 file1.txt -rw-r--r-- 3.0 unx 7224 tx defN 22-Apr-19 17:16 file2.txt -rw-r--r-- 3.0 unx 7224 tx defN 22-Apr-19 17:16 file3.txt -rw-r--r-- 3.0 unx 7224 tx defN 22-Apr-19 17:20 file4.txt 4 files, 28896 bytes uncompressed, 12028 bytes compressed: 58.4% ``` ## Remove a File From an Existing Zip Archive You can use the zip command with **-d** option to remove a file from the zip archive. For example, to remove a **file2.txt** from the **files.zip** archive, run the following command: ``` zip -d files.zip file2.txt ``` Output: ``` deleting: file2.txt ``` ## Delete Original Files After Zipping When you compress single or multiple files using the zip command, zip keeps the original and compressed files. After creating the zipped archive, you can use the -m option to delete the original files. ``` zip -m newfiles.zip file1.txt file2.txt file3.txt file4.txt ``` Output: ``` adding: file1.txt (deflated 58%) adding: file2.txt (deflated 58%) adding: file3.txt (deflated 58%) adding: file4.txt (deflated 58%) ``` ## Zip a Directory with zip Command Zip also allows us to compress the directory using the zip command. You will need to use the **-r** option to zip the directory recursively. The basic syntax to zip a directory is shown below: ``` zip -r directory.zip directory ``` For example, to zip a directory named **students**, run the following command: ``` zip -r students.zip students ``` Output: ``` adding: students/ (stored 0%) adding: students/gujarati.txt (deflated 58%) adding: students/maths.txt (deflated 58%) adding: students/english.txt (deflated 58%) ``` To zip multiple directories, run the following command: ``` zip -r directory.zip directory1 directory2 directory3 ``` #### **Also Read** [How to Check Size of Files and Directory on Linux](https://www.atlantic.net/vps-hosting/how-to-check-size-of-files-and-directory-on-linux/) ## Create a Password Protected Zip File Zip also allows us to create a password-protected zip archive. You can create a password-protected zip file using the **-e option** with the zip command. ``` zip -r -e teachers.zip teachers ``` Output: ``` Enter password: Verify password: adding: teachers/ (stored 0%) adding: teachers/gujarati.txt (deflated 58%) adding: teachers/maths.txt (deflated 58%) adding: teachers/english.txt (deflated 58%) ``` ## Unzip a Zipped File The basic syntax to unzip a file is shown below: ``` unzip file.zip ``` For example, to unzip a zipped file named **files.zip**, run the following command: ``` unzip files.zip ``` Output: ``` Archive: files.zip inflating: file1.txt inflating: file3.txt inflating: file4.txt ``` If you want to unzip a file to a different directory, use the **-d** option with the unzip command. For example, to unzip a file named **students.zip** to a **students** directory, run the following command: ``` unzip students.zip -d students ``` Output: ``` Archive: students.zip creating: students/students/ inflating: students/students/gujarati.txt inflating: students/students/maths.txt inflating: students/students/english.txt ``` To extract a single file named**file1.txt** from the **files.zip** file, run the following command: ``` unzip files.zip file1.txt ``` Output: ``` Archive: files.zip inflating: file1.txt ``` If you want to overwrite the existing files without being prompted, use the -o option as shown: ``` unzip -o files.zip ``` ## View the Content of the Zipped File You can use the -l option with the unzip command to view the content of a zipped file. For example, to list the content of a zipped file named students.zip, run the following command: ``` unzip -l students.zip ``` Output: ``` Archive: students.zip Length Date Time Name --------- ---------- ----- ---- 0 2022-04-19 17:17 students/ 7224 2022-04-19 17:17 students/gujarati.txt 7224 2022-04-19 17:17 students/maths.txt 7224 2022-04-19 17:17 students/english.txt --------- ------- 21672 4 files ``` To list the content of a zipped file with detailed information about the file, use the **-Z** option: ``` unzip -Z students.zip ``` Output: ``` Archive: students.zip Zip file size: 9691 bytes, number of entries: 4 drwxrwxr-x 3.0 unx 0 bx stor 22-Apr-19 17:17 students/ -rw-r--r-- 3.0 unx 7224 tx defN 22-Apr-19 17:17 students/gujarati.txt -rw-r--r-- 3.0 unx 7224 tx defN 22-Apr-19 17:17 students/maths.txt -rw-r--r-- 3.0 unx 7224 tx defN 22-Apr-19 17:17 students/english.txt 4 files, 21672 bytes uncompressed, 9021 bytes compressed: 58.4% ``` ## Split a Zip Archives into Multiple Files Sometimes, the size of a zipped file is very large, and you can not send it as an attachment via email. In this case, you can use the zip command to break up a zipped archive into multiple smaller files. For example, to create a zipped archive of the directory named directory into a 3MB file, run the following command: ``` zip -r -s 3m file.zip directory ``` You can now verify all created zipped files using the following command: ``` ls ``` Output: ``` directory file.z01 file.z02 file.z03 file.z04 file.z05 file.z06 file.z07 file.z08 file.z09 file.z10 file.zip ``` You can also check the size of each file with the following command: ``` du -hs * ``` You should see the following output: ``` 3.0M file.z01 3.0M file.z02 3.0M file.z03 3.0M file.z04 3.0M file.z05 3.0M file.z06 3.0M file.z07 3.0M file.z08 3.0M file.z09 3.0M file.z10 1.7M file.zip ``` ## Conclusion In this guide, we explained how to use the Zip and Unzip commands to compress and uncompress files and directories in Linux. I have demonstrated both commands’ usage with real-life examples for better understanding. Hopefully, you can now easily use the Zip and Unzip commands in your day-to-day operations. Try it on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Check and Repair MySQL Databases and Tables > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-check-and-repair-mysql-databases-and-tables/ | Published: 2022-05-17 | Updated: 2023-11-15 | Author: Hitesh Jethva You may need to check or repair a database or table in MySQL when your website is corrupt or not accessible due to a database error. In this case, you can use the mysqlcheck tool to check and fix the corrupted table or database. mysqlcheck is a maintenance tool that allows you to check, repair, analyze and optimize MySQL tables via a command-line interface. One of the best features of using mysqlcheck is that you can perform database maintenance on a live website without stopping the MySQL service. In this post, we will explain how to check/repair MySQL databases and tables. ## Basic Syntax of mysqlcheck The basic syntax of the mysqlcheck command-line tool is shown below: ``` mysqlcheck [OPTION] DATABASENAME TABLENAME -u root -p ``` A brief explanation of each option that you can use with mysqlcheck is shown below: - **-c** – Check a table for errors - **-C** – Check the tables that are changed after last week. - **-a** – Analyze tables. - **-A** – Check all databases. - **-g** – Check tables for version-dependent changes. - **-B**, **–databases** – Specify multiple databases. - **-F** – Check tables that are not closed properly. - **–fix-db-names** – Fix the database name. - **–fix-table-names** – Fix the table name. - **-e** – Perform an extended check. - **-r** – Repair a corrupted table. #### **Also Read** [How to Connect to MySQL Using PHP](https://www.atlantic.net/vps-hosting/how-to-connect-to-mysql-using-php/) ## Check a Table in MySQL Sometimes, you may need to check a specific table in a specific database. In that case, you can use the following syntax: ``` mysqlcheck -c db-name table-name -u root -p ``` For example, to check the **students** table in the **class** database, run the following command: ``` mysqlcheck -c class students -u root -p ``` You will get the following output: ``` class.students OK ``` ## Check All Tables in MySQL If you want to check all the tables in a specific database, use the following syntax: ``` mysqlcheck -c db-name -u root -p ``` For example, to check all tables in the **class** database, run the following command: ``` mysqlcheck -c class -u root -p ``` You should get the following output: ``` Enter password: class.teacher OK class.students OK class.peon OK ``` ## Check and Optimize All Tables and All MySQL Databases You can use the following command to check all tables and all databases: ``` mysqlcheck -c -u root -p --all-databases ``` Output: ``` Enter password: class.teacher OK class.students OK class.peon OK guest.MyGuests OK movies.hotstar OK mysql.columns_priv OK mysql.component OK mysql.db OK mysql.default_roles OK mysql.engine_cost OK mysql.func OK mysql.general_log OK mysql.global_grants OK mysql.gtid_executed OK mysql.help_category OK mysql.help_keyword OK mysql.help_relation OK mysql.help_topic OK mysql.innodb_index_stats OK mysql.innodb_table_stats OK mysql.password_history OK mysql.plugin OK mysql.procs_priv OK mysql.proxies_priv OK mysql.role_edges OK mysql.server_cost OK mysql.servers OK mysql.slave_master_info OK mysql.slave_relay_log_info OK mysql.slave_worker_info OK ``` You can also optimize all tables and all databases with the following command: ``` mysqlcheck -o root -p --all-databases ``` Output: ``` Enter password: class.teacher note : Table does not support optimize, doing recreate + analyze instead status : OK class.students note : Table does not support optimize, doing recreate + analyze instead status : OK class.peon note : Table does not support optimize, doing recreate + analyze instead status : OK guest.MyGuests note : Table does not support optimize, doing recreate + analyze instead status : OK movies.hotstar note : Table does not support optimize, doing recreate + analyze instead status : OK mysql.columns_priv ``` In the above output, you should see “**Table does not support optimize**” which means the InnoDB table that doesn’t support this option. #### **Also Read** [How to Delete or Remove Databases in MySQL](https://www.atlantic.net/dedicated-server-hosting/how-to-delete-or-remove-databases-in-mysql/) ## Repair/Fix MySQL Databases To repair teacher tables in the **class** database, run the following command: ``` mysqlcheck -r class teacher -u root -p ``` Output: ``` mysqlcheck -r class teacher -u root -p Enter password: class.teacher OK ``` To repair all tables in both **class** and **movies** database, run the following command: ``` mysqlcheck -r --databases class movies -u root -p ``` Output: ``` Enter password: class.teacher OK class.students OK class.peon OK movies.hotstar OK ``` If you want to check and repair all tables in all databases, run the following command: ``` mysqlcheck --auto-repair --all-databases -u root -p ``` Output: ``` Enter password: class.teacher OK class.students OK class.peon OK guest.MyGuests OK movies.hotstar OK mysql.columns_priv OK mysql.component OK mysql.db OK mysql.default_roles OK mysql.engine_cost OK mysql.func OK mysql.general_log OK mysql.global_grants OK mysql.gtid_executed OK mysql.help_category OK mysql.help_keyword OK mysql.help_relation OK mysql.help_topic OK mysql.innodb_index_stats OK mysql.innodb_table_stats OK mysql.password_history OK mysql.plugin OK mysql.procs_priv OK mysql.proxies_priv OK mysql.role_edges OK mysql.server_cost OK mysql.servers OK mysql.slave_master_info OK mysql.slave_relay_log_info OK mysql.slave_worker_info OK mysql.slow_log OK mysql.tables_priv OK mysql.time_zone OK mysql.time_zone_leap_second OK mysql.time_zone_name OK mysql.time_zone_transition OK mysql.time_zone_transition_type OK ``` Note: By default, the InnoDB storage engine does not support repair. In this case, you will need to change the MySQL storage engine from InnoDB to MyISAM. ## Conclusion In this post, we explained how to check and repair a table in MySQL using the mysqlcheck command-line tool. Hopefully, this will help you to fix your corrupted tables. Try it on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Create and Delete a User in MySQL > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-create-and-delete-a-user-in-mysql/ | Published: 2022-05-18 | Updated: 2023-11-15 | Author: Hitesh Jethva Databases are used to store and manage large amounts of information on computers and servers. They are an essential component to running web-based applications, content management systems, and online eCommerce shops. When working with a MySQL database, you may often need to create and delete users. Creating and removing users in MySQL is an essential skill for any database administrator. In this post, you will learn how to create and delete a user in MySQL. ## Create User in MySQL The basic syntax to create a user in MySQL is very simple. You can use the CREATE USER command by specifying the user and host for a new user account as shown below: ``` CREATE USER 'user'@'host' IDENTIFED BY 'password'; ``` To create a new user named **user1** and **user2** for MySQL locally, use the following command: ``` CREATE USER 'user1'@'localhost' IDENTIFIED WITH mysql_native_password BY 'password'; CREATE USER 'user2'@'localhost' IDENTIFIED WITH mysql_native_password BY 'password'; ``` If you are connecting to MySQL remotely, then you can replace the localhost with remote_ip_address as shown below: ``` CREATE USER 'user1'@'remote_ip_address' IDENTIFIED WITH mysql_native_password BY 'password'; ``` If you want to create a user that can connect from any machine, run the following command: ``` CREATE USER 'user1'@'%' IDENTIFIED WITH mysql_native_password BY 'password'; ``` #### **Also Read** [How to Check and Repair MySQL](https://www.atlantic.net/dedicated-server-hosting/how-to-check-and-repair-mysql-databases-and-tables/) ## Delete a User in MySQL Before deleting a user in MySQL, you will need to find the exact name of the user you want to remove. You can list all users with the following command: ``` SELECT User, Host FROM mysql.user; ``` You will get a list of all MySQL users in the following output: ``` +------------------+-----------+ | User | Host | +------------------+-----------+ | testuser | % | | debian-sys-maint | localhost | | mysql.infoschema | localhost | | mysql.session | localhost | | mysql.sys | localhost | | root | localhost | | user1 | localhost | | user2 | localhost | +------------------+-----------+ ``` Next, run the following command to delete a user named **user1**: ``` DROP USER 'user1'@'localhost'; ``` To delete multiple MySQL users, run the following command: ``` DROP USER 'user1'@'localhost', 'user2'@'localhost', 'user3'@'localhost'; ``` ## Delete an Active MySQL User Sometimes, the MySQL user that you try to delete is active. In this case, you will need to kill the user session and then remove the user account. First, get a list of all active MySQL users using the following command: ``` SHOW PROCESSLIST; ``` You will get the active user list with session ID: ``` +----+-----------------+-----------+------+---------+------+------------------------+------------------+ | Id | User | Host | db | Command | Time | State | Info | +----+-----------------+-----------+------+---------+------+------------------------+------------------+ | 5 | event_scheduler | localhost | NULL | Daemon | 5129 | Waiting on empty queue | NULL | | 20 | user2 | localhost | NULL | Sleep | 54 | | NULL | | 21 | root | localhost | NULL | Query | 0 | init | SHOW PROCESSLIST | +----+-----------------+-----------+------+---------+------+------------------------+------------------+ ``` Now, kill the **user2** session with the following command: ``` KILL 20; ``` Once the user is inactive, you can delete it with the following command: ``` DROP USER 'user2'@'localhost'; ``` #### **Also Read** [How to Connect to MySQL Using PHP](https://www.atlantic.net/vps-hosting/how-to-connect-to-mysql-using-php/) ## Conclusion In this post, we explained how to create and delete users in MySQL. We also explained how to delete multiple and active user accounts in MySQL. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Gitea Code Hosting Service on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-gitea-code-hosting-service-on-oracle-linux-10/ | Published: 2022-05-19 | Updated: 2026-01-02 | Author: Hitesh Jethva Gitea is an open-source, self-hosted code hosting platform written in Go. It is very similar to other version control software solutions like GitHub and GitLab with features including issue tracking, pull requests, user management, notifications, and more. It can be installed on all major operating systems including Linux, macOS, Windows, and ARM. With Gitea, you can create a central repository where developers merge and track their code changes in the repository. If you are looking for an open-source, lightweight, and self-hosted code hosting platform, then Gitea is the best choice for you. In this post, we will show you how to install Gitea on Oracle Linux 10. ## Step 1 – Install and Configure MariaDB Database Gitea uses a MariaDB, MySQL, or PostgreSQL database to store its data. In this tutorial, we will use a MariaDB server as a database backend. Note: You don’t need to install and configure the MariaDB database if you are using [database hosting](https://www.atlantic.net/dedicated-server-hosting/what-is-database-hosting/) from Atlantic.Net. First, install all the required dependencies using the following command: ``` dnf install git unzip gnupg2 nano wget -y ``` Once all the dependencies are installed, run the following command to install the MariaDB server: ``` dnf install mariadb-server -y ``` Next, start and enable the MariaDB service using the following command: ``` systemctl start mariadb systemctl enable mariadb ``` You can check the MariaDB version using the following command: ``` mysql --version ``` Sample output: ``` mysql Ver 15.1 Distrib 10.3.32-MariaDB, for Linux (x86_64) using readline 5.1 ``` Next, log in to the MariaDB shell with the following command: ``` mysql ``` Once you are logged in, create a database and user for Gitea using the following command: ``` CREATE DATABASE gitea CHARACTER SET 'utf8mb4' COLLATE 'utf8mb4_unicode_ci'; GRANT ALL ON gitea.* TO 'gitea'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` Next, edit the MariaDB configuration file and tweak some settings: ``` nano /etc/my.cnf.d/server.cnf ``` Add the following lines below the line [mysqld]: ``` innodb_file_format = Barracuda innodb_large_prefix = 1 innodb_default_row_format = dynamic ``` Save and close, the file then restart the MariaDB service to apply the changes: ``` systemctl restart mariadb ``` ## Step 2 – Install and Configure Gitea It is a good idea to create a dedicated user to run Gitea. You can create it using the following command: ``` useradd --system --shell /bin/bash --comment 'Git Version Control' --create-home --home /home/git git ``` Next, download the latest version of the Gitea binary using the [wget command](https://www.atlantic.net/dedicated-server-hosting/how-to-download-file-using-wget-in-linux/): ``` wget -O gitea https://dl.gitea.io/gitea/1.18.5/gitea-1.18.5-linux-amd64 ``` Next, move the downloaded binary to the system path and set proper permissions on it: ``` mv gitea /usr/bin/gitea chmod 755 /usr/bin/gitea ``` Next, run the following command to verify the Gitea version: ``` gitea --version ``` You should get the following output: ``` Gitea version 1.18.5 built with GNU Make 4.1, go1.19.6 : bindata, sqlite, sqlite_unlock_notify ``` Next, you will need to create a directory structure to store Gitea configuration, data, and log files. You can create it with the following commands: ``` mkdir -p /var/lib/gitea/{custom,data,indexers,public,log} chown git: /var/lib/gitea/{data,indexers,log} chmod 750 /var/lib/gitea/{data,indexers,log} mkdir /etc/gitea chown root:git /etc/gitea chmod 770 /etc/gitea ``` ## Step 3 – Create a Systemd Service File for Gitea Next, you will need to create a service file to manage the Gitea service via systemd. You can create it with the following command: ``` nano /etc/systemd/system/gitea.service ``` Add the following lines: ``` [Unit] Description=Gitea After=syslog.target After=network.target After=mysql.service [Service] RestartSec=2s Type=simple User=git Group=git WorkingDirectory=/var/lib/gitea/ ExecStart=/usr/bin/gitea web -c /etc/gitea/app.ini Restart=always Environment=USER=git HOME=/home/git GITEA_WORK_DIR=/var/lib/gitea [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the Gitea service and enable it to start at system reboot: ``` systemctl start gitea systemctl enable gitea ``` You can now check the status of Gitea using the following command: ``` systemctl status gitea ``` You should see the following output: ``` ● gitea.service - Gitea Loaded: loaded (/etc/systemd/system/gitea.service; disabled; preset: disabled) Active: active (running) since Thu 2026-01-01 23:54:08 EST; 3s ago Invocation: 1efa98afe57648b8ad64c0ac378b181b Main PID: 85737 (gitea) Tasks: 8 (limit: 24812) Memory: 108.2M (peak: 108.5M) CPU: 763ms CGroup: /system.slice/gitea.service └─85737 /usr/bin/gitea web -c /etc/gitea/app.ini Jan 01 23:54:08 oracle gitea[85737]: 2026/01/01 23:54:08 ...s/install/setting.go:21:PreloadSettings() [I] AppPath: /usr/bin/gitea Jan 01 23:54:08 oracle gitea[85737]: 2026/01/01 23:54:08 ...s/install/setting.go:22:PreloadSettings() [I] AppWorkPath: /var/lib/gitea Jan 01 23:54:08 oracle gitea[85737]: 2026/01/01 23:54:08 ...s/install/setting.go:23:PreloadSettings() [I] Custom path: /var/lib/gitea/custom Jan 01 23:54:08 oracle gitea[85737]: 2026/01/01 23:54:08 ...s/install/setting.go:24:PreloadSettings() [I] Log path: /var/lib/gitea/log Jan 01 23:54:08 oracle gitea[85737]: 2026/01/01 23:54:08 ...s/install/setting.go:25:PreloadSettings() [I] Configuration file: /etc/gitea/app.ini Jan 01 23:54:08 oracle gitea[85737]: 2026/01/01 23:54:08 ...s/install/setting.go:26:PreloadSettings() [I] Prepare to run install page Jan 01 23:54:08 oracle gitea[85737]: 2026/01/01 23:54:08 ...s/install/setting.go:29:PreloadSettings() [I] SQLite3 is supported Jan 01 23:54:08 oracle gitea[85737]: 2026/01/01 23:54:08 cmd/web.go:220:listen() [I] [69574f70-6] Listen: http://0.0.0.0:3000 Jan 01 23:54:08 oracle gitea[85737]: 2026/01/01 23:54:08 cmd/web.go:224:listen() [I] [69574f70-6] AppURL(ROOT_URL): http://localhost:3000/ Jan 01 23:54:08 oracle gitea[85737]: 2026/01/01 23:54:08 ...s/graceful/server.go:62:NewServer() [I] [69574f70-6] Starting new Web server: tcp:0.0.0.0:3000 on PID: 85737 ``` By default, Gitea listens on port **3000**. You can verify it using the following command: ``` ss -antpl | grep 3000 ``` You should get the following output: ``` LISTEN 0 128 *:3000 *:* users:(("gitea",pid=12643,fd=6)) ``` ## Step 4 – Access Gitea Web Interface You can now open your web browser and type the URL **http://your-server-ip:3000** to access the Gitea web interface. You should get the following screen: ![Gitea database settings](https://www.atlantic.net/wp-content/uploads/2022/05/p1-1.png) ![Gitea General Seetins](https://www.atlantic.net/wp-content/uploads/2022/05/p2.png) ![Gitea URL settings](https://www.atlantic.net/wp-content/uploads/2022/05/p3.png) ![Gitea admin user settings](https://www.atlantic.net/wp-content/uploads/2022/05/p4.png) Provide your Gitea repository name, run as username, listen port, base URL, admin username, and password and click on the **Install** **Gitea** button. Once the installation has been completed, you will be redirected to the Gitea dashboard: ![Gitea dashboard](https://www.atlantic.net/wp-content/uploads/2022/05/p5-1024x501.png) ## Conclusion In this guide, we explained how to install the Gitea code hosting platform on Oracle Linux 10. You can now start implementing Gitea in your development environment to manage and track your code from a central location. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Docker and Docker Compose on Oracle Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-docker-and-docker-compose-on-oracle-linux/ | Published: 2022-05-20 | Updated: 2026-01-01 | Author: Hitesh Jethva Docker is a free and open-source containerization platform that allows developers to package applications into containers. Docker uses OS-level virtualization to deliver software in packages called containers. It allows you to create, build, and run lightweight, portable application images for any platform. Docker Compose is a free and open-source tool that helps you define and share multi-container applications in a single YAML file. With Docker Compose, you can run and connect multiple containers as a single service. This post will show you how to install Docker and Docker Compose in Oracle Linux 10. ## Step 1 – Update Oracle Linux Server **Note**: It is recommended that your Oracle Linux 8 server has at least 4GB RAM. Connect to your Cloud Server via SSH and log in using the credentials highlighted at the top of the page. Once you are logged in to your server, run the following command to update your base system with the latest available packages. ``` dnf update -y ``` ## Step 2 – Install Docker CE (Community Edition) By default, the latest version of the Docker package is not included in the Oracle Linux default repository, so you will need to create a Docker CE repo. You can create it using the following command: ``` dnf config-manager --add-repo=https://download.docker.com/linux/centos/docker-ce.repo ``` Next, run the following command to install Docker CE on your server. ``` dnf install docker-ce -y ``` After the installation, start the Docker service and enable it to start at system reboot. ``` systemctl start docker systemctl enable docker ``` Next, verify the running status of the Docker service using the following command: ``` systemctl status docker ``` Sample output: ``` ● docker.service - Docker Application Container Engine Loaded: loaded (/usr/lib/systemd/system/docker.service; disabled; vendor preset: disabled) Active: active (running) since Sat 2025-12-31 08:35:46 EDT; 6s ago Docs: https://docs.docker.com Main PID: 8554 (dockerd) Tasks: 8 Memory: 31.7M CGroup: /system.slice/docker.service └─8554 /usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock ``` You can also verify the Docker version with additional information using the following command: ``` docker info ``` You will get the following output: ``` Client: Docker Engine - Community Version: 29.1.3 Context: default Debug Mode: false Plugins: buildx: Docker Buildx (Docker Inc.) Version: v0.30.1 Path: /usr/libexec/docker/cli-plugins/docker-buildx compose: Docker Compose (Docker Inc.) Version: v5.0.0 Path: /usr/libexec/docker/cli-plugins/docker-compose Server: Containers: 0 Running: 0 Paused: 0 Stopped: 0 Images: 0 Server Version: 29.1.3 Storage Driver: overlayfs driver-type: io.containerd.snapshotter.v1 Logging Driver: json-file Cgroup Driver: systemd Cgroup Version: 2 Plugins: ``` ## Step 3 – Verify Docker Installation At this point, Docker is installed and running. Now it’s time to test whether it’s working or not. You can download and run Docker’s hello-world container to test Docker. ``` docker run hello-world ``` This will download and run the hello-world Docker container on your system: ``` latest: Pulling from library/hello-world 2db29710123e: Pull complete Digest: sha256:10d7d58d5ebd2a652f4d93fdd86da8f265f5318c6a73cc5b6a9798ff6d2b2e67 Status: Downloaded newer image for hello-world:latest Hello from Docker! This message shows that your installation appears to be working correctly. To generate this message, Docker took the following steps: 1. The Docker client contacted the Docker daemon. 2. The Docker daemon pulled the "hello-world" image from the Docker Hub. (amd64) 3. The Docker daemon created a new container from that image which runs the executable that produces the output you are currently reading. 4. The Docker daemon streamed that output to the Docker client, which sent it to your terminal. To try something more ambitious, you can run an Ubuntu container with: $ docker run -it ubuntu bash Share images, automate workflows, and more with a free Docker ID: https://hub.docker.com/ For more examples and ideas, visit: https://docs.docker.com/get-started/ ``` You can use the “docker images” command to verify the downloaded image: ``` docker images ``` You will get the following output: ``` REPOSITORY TAG IMAGE ID CREATED SIZE hello-world latest feb5d9fea6a5 7 months ago 13.3kB ``` ## Step 4 – Install Docker Compose By default, Docker Compose installed with Docker. So you don’t need to install it You can verify the Docker Compose version using the following command: ``` docker compose version ``` You will get the following output: ``` Docker Compose version v5.0.0 ``` #### Also Read [How to Manage Docker Container with Rancher](https://www.atlantic.net/dedicated-server-hosting/manage-docker-containers-with-rancher/) ## Step 5 – Remove Docker and Docker Compose If you want to remove the Docker package from your system, you will need to stop the Docker service first: ``` systemctl stop docker ``` Next, remove the Docker package using the following command: ``` dnf remove docker-ce -y ``` To remove Docker Compose, delete the Docker Compose binary using the following command: ``` rm -rf /usr/local/bin/docker-compose ``` ## Conclusion You learned how to install Docker and Docker Compose on Oracle Linux 10 in this guide. You can now install both on your development environment and deploy an application in the Docker environment. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Apache Spark on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-spark-on-oracle-linux-10/ | Published: 2022-05-23 | Updated: 2026-01-01 | Author: Hitesh Jethva Apache Spark is open-source distributed processing system used to handle big data workloads in cluster computing environments. It is designed for speed, ease of use, and sophisticated analytics, with APIs available in Java, Scala, Python, R, and SQL. It supports several programming languages including Java, Scala, Python, and R. It can run programs up to 100x faster than Hadoop MapReduce in memory, or 10x faster on disk. It is used by data scientists and engineers for executing data engineering, data science, and machine learning on single-node machines or clusters. In this post, we will show you how to install Apache Spark on Oracle Linux 10. ## Step 1 – Install Java Apache Spark is a Java-based application, so Java must be installed on your server. If not installed, you can install it by running the following command: ``` dnf install java-21-openjdk-devel -y ``` Once Java is installed, you can verify it using the following command: ``` java --version ``` You will get the following output: ``` openjdk 21.0.9 2025-10-21 LTS OpenJDK Runtime Environment (Red_Hat-21.0.9.0.10-1.0.1) (build 21.0.9+10-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.9.0.10-1.0.1) (build 21.0.9+10-LTS, mixed mode, sharing) ``` Also Read [How to Install and Manage Multiple Java Versions](https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-manage-java-versions-on-oracle-linux/) ## Step 2 – Install Spark At the time of writing this tutorial, the latest version of Apache Spark is 4.1. You can download the latest version of Apache Spark from Apache’s official website using the [wget command](https://www.atlantic.net/dedicated-server-hosting/how-to-download-file-using-wget-in-linux/): ``` wget https://archive.apache.org/dist/spark/spark-4.1.0/spark-4.1.0-bin-hadoop3.tgz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar -xvf spark-4.1.0-bin-hadoop3.tgz ``` Next, move the extracted directory to /opt with the following command: ``` mv spark-4.1.0-bin-hadoop3 /opt/spark ``` Next, create a dedicated user for Apache Spark and set proper ownership to the /opt directory: ``` useradd spark chown -R spark:spark /opt/spark ``` ## Step 3 – Create a Systemd Service File for Apache Spack Next, you will need to create a service file for managing Apache Spark Master and Slave via systemd. First, create a systemd service file for Master using the following command: ``` nano /etc/systemd/system/spark-master.service ``` Add the following lines: ``` [Unit] Description=Apache Spark Master After=network.target [Service] Type=forking User=spark Group=spark ExecStart=/opt/spark/sbin/start-master.sh ExecStop=/opt/spark/sbin/stop-master.sh [Install] WantedBy=multi-user.target ``` Save and close the file, then create a systemd service file for Slave: ``` nano /etc/systemd/system/spark-slave.service ``` Add the following lines: ``` [Unit] Description=Apache Spark Slave After=network.target [Service] Type=forking User=spark Group=spark ExecStart=/opt/spark/sbin/start-worker.sh spark://your-server-ip:7077 ExecStop=/opt/spark/sbin/stop-slave.sh [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start the Spark Master service and enable it to start at system reboot: ``` systemctl start spark-master systemctl enable spark-master ``` To verify the status of the Master service, run the following command: ``` systemctl status spark-master ``` You will get the following output: ``` ● spark-master.service - Apache Spark Master Loaded: loaded (/etc/systemd/system/spark-master.service; disabled; vendor preset: disabled) Active: active (running) since Sat 2025-12-31 08:15:45 EDT; 6s ago Process: 5253 ExecStart=/opt/spark/sbin/start-master.sh (code=exited, status=0/SUCCESS) Main PID: 5264 (java) Tasks: 32 (limit: 23694) Memory: 177.7M CGroup: /system.slice/spark-master.service ``` ## Step 4 – Access Apache Spark At this point, Apache Spark is started and listening on port 8080. You can access it using the URL **http://your-server-ip:8080**. You should see the following page: ![Apache Spark dashboard](https://www.atlantic.net/wp-content/uploads/2022/05/p1-2-1024x465.png) Now, start the Spark Slave service and enable it to start at system reboot: ``` systemctl start spark-slave systemctl enable spark-slave ``` You can check the status of the Slave service using the following command: ``` systemctl status spark-slave ``` Sample output: ``` ● spark-slave.service - Apache Spark Slave Loaded: loaded (/etc/systemd/system/spark-slave.service; disabled; vendor preset: disabled) Active: active (running) since Sat 2025-12-31 08:23:11 EDT; 4s ago Process: 5534 ExecStop=/opt/spark/sbin/stop-worker.sh (code=exited, status=0/SUCCESS) Process: 5557 ExecStart=/opt/spark/sbin/start-worker.sh spark://oraclelinux:7077 (code=exited, status=0/SUCCESS) Main PID: 5575 (java) Tasks: 35 (limit: 23694) Memory: 207.4M CGroup: /system.slice/spark-slave.service ``` Now, reload your Apache Spark dashboard. You should see your worker on the following page: ![Apache Spark Worker Added](https://www.atlantic.net/wp-content/uploads/2022/05/p2-1-1024x505.png) ## Conclusion Congratulations! You have successfully installed Apache Spark on Oracle Linux 10. You can now use Apache Spark in Hadoop or cluster computing environments to improve the data processing speeds. Give it a try on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Yarn NPM Package Manager on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-yarn-npm-package-manager-on-oracle-linux-10/ | Published: 2022-05-24 | Updated: 2026-01-01 | Author: Hitesh Jethva Yarn is a JavaScript package manager used to automate the installation, configuration, update, and removal of npm packages. Yarn stands for “Yet Another Resource Navigator.” It was developed by Facebook and is very similar to the npm package manager, with a focus on speed, security, and consistency. Yarn replaces the existing workflow of the npm client or other package managers while remaining compatible with the npm registry. In this post, we will explain the following: ## Step 1 – Install YARN using npm First, you will need to install Node.js and npm on your server. You can install Node.js version using the following command: ``` dnf install nodejs npm -y ``` Once Node.js is installed, verify the Node.js version with the following command: ``` node --version ``` Sample output: ``` v22.19.0 ``` You can also check the npmversion using the following command: ``` npm -v ``` Sample output: ``` 10.9.3 ``` Now, use npm to install the Yarn package as shown below: ``` npm install --global yarn ``` You can verify the Yarn version with the following command: ``` yarn -v ``` Sample output: ``` 1.22.22 ``` If you want to uninstall the Yarn package from your system, run the following command: ``` npm uninstall -g yarn ``` Also Read [How to Install Node.js and NPM on Oracle Linux 8](https://www.atlantic.net/dedicated-server-hosting/how-to-install-node-js-and-npm-on-oracle-linux/) ## Step 2 – Install YARN from Yum Repository By default, the Yarn package is not included in the Oracle Linux default repository, so you will need to add the Yarn repo to your system. First, create a Yarn repo with the following command: ``` curl -sL https://dl.yarnpkg.com/rpm/yarn.repo | tee /etc/yum.repos.d/yarn.repo ``` Once the Yarn repo is created, install the Yarn package with the following command: ``` dnf install yarn -y ``` Once the Yarn has been installed, activate the Yarn environment variable using the following command: ``` source /etc/profile ``` Next, verify the Yarn version with the following command: ``` yarn -v ``` Sample output: ``` 1.22.22 ``` If you want to remove the Yarn package from your system, run the following command: ``` dnf remove yarn -y ``` ## Step 3 – Install YARN with Script Yarn also provides a bash script that allows you to install Yarn on any Linux operating system. You can download and run the Yarn installation script using the following command: ``` curl -o- -L https://yarnpkg.com/install.sh | bash ``` Once the Yarn package has been installed, you should get the following output: ``` > GPG signature looks good > Extracting to ~/.yarn... > Adding to $PATH... > We've added the following to your /root/.bashrc > If this isn't the profile of your current shell then please add the following to your correct profile: export PATH="$HOME/.yarn/bin:$HOME/.config/yarn/global/node_modules/.bin:$PATH" > Successfully installed Yarn 1.22.22! Please open another terminal where the `yarn` command will now be available. ``` Next, activate the system path with the following command: ``` source ~/.bashrc ``` Next, verify the Yarn version using the following command: ``` yarn -v ``` Sample output: ``` 1.22.22 ``` ## Conclusion In the above guide, we explained three-way to install the Yarn package on Oracle Linux 10. You can now use your preferred way to install the Yarn on your system. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Apache Cassandra on Oracle Linux 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-apache-cassandra-on-oracle-linux-8/ | Published: 2022-05-25 | Updated: 2023-11-23 | Author: Hitesh Jethva Apache Cassandra is an open-source, wide-column store NoSQL database management system designed to handle large amounts of data. Cassandra can be distributed across many servers to achieve high availability with no single point of failure. Generally, it is used to serve as a real-time operational data store for online transactional applications and as a read-intensive database for large-scale systems. Currently, it is used by many organizations including Netflix, Digg, Adobe, Twitter, HP, IBM, Rackspace, Cisco, and Reddit. In this guide, we will explain how to install Apache Cassandra on Oracle Linux 8. ## Step 1 – Install Java 8 By default, Apache Cassandra supports only Java version 8, so Java 8 must be installed on your server. If it is not installed, you can install it with other dependencies using the following command: ``` dnf update -y dnf install epel-release python2 python2-pip java-1.8.0-openjdk -y ``` After installation, verify the Java installation with the following command: ``` java -version ``` You will get the Java version in the following output: ``` openjdk version "1.8.0_332" OpenJDK Runtime Environment (build 1.8.0_332-b09) OpenJDK 64-Bit Server VM (build 25.332-b09, mixed mode) ``` Next, install the cqlsh command-line utility to connect to Cassandra via command-line. ``` pip2 install cqlsh ``` ## Step 2 – Install Apache Cassandra By default, the Apache Cassandra package is not included in the Oracle Linux 8 default repository, so you will need to create a repo for Apache Cassandra. You can create an Apache Cassandra repo using the following command: ``` nano /etc/yum.repos.d/cassandra.repo ``` Add the following lines: ``` [cassandra] name=Apache Cassandra baseurl=https://www.apache.org/dist/cassandra/redhat/40x/ gpgcheck=1 repo_gpgcheck=1 gpgkey=https://www.apache.org/dist/cassandra/KEYS ``` Save and close the file when you are done, then install Apache Cassandra with the following command: ``` dnf install cassandra -y ``` ## Step 3 – Create a Service File for Cassandra It is recommended to create a service file to manage the Apache Cassandra service via systemd. You can create it with the following command: ``` nano /etc/systemd/system/cassandra.service ``` Add the following lines: ``` [Unit] Description=Apache Cassandra After=network.target [Service] PIDFile=/var/run/cassandra/cassandra.pid User=cassandra Group=cassandra ExecStart=/usr/sbin/cassandra -f -p /var/run/cassandra/cassandra.pid Restart=always [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes: ``` systemctl daemon-reload ``` Next, start and enable the Cassandra service with the following command: ``` systemctl start cassandra systemctl enable cassandra ``` To verify the status of Apache Cassandra, run the following command: ``` systemctl status cassandra ``` You should see the following output: ``` ● cassandra.service - Apache Cassandra Loaded: loaded (/etc/systemd/system/cassandra.service; disabled; vendor preset: disabled) Active: active (running) since Sat 2022-04-30 07:54:46 EDT; 15s ago Main PID: 2170 (java) Tasks: 23 (limit: 23694) Memory: 1.1G CGroup: /system.slice/cassandra.service └─2170 /usr/bin/java -ea -da:net.openhft... -XX:+UseThreadPriorities -XX:+HeapDumpOnOutOfMemoryError -Xss256k -XX:+AlwaysPreTouch > Apr 30 07:55:00 oraclelinux cassandra[2170]: INFO [main] 2022-04-30 07:55:00,318 CassandraDaemon.java:640 - Classpath: /etc/cassandra/conf:/> Apr 30 07:55:00 oraclelinux cassandra[2170]: INFO [main] 2022-04-30 07:55:00,319 CassandraDaemon.java:642 - JVM Arguments: [-ea, -da:net.ope> Apr 30 07:55:00 oraclelinux cassandra[2170]: WARN [main] 2022-04-30 07:55:00,405 NativeLibrary.java:201 - Unable to lock JVM memory (ENOMEM)> Apr 30 07:55:00 oraclelinux cassandra[2170]: INFO [main] 2022-04-30 07:55:00,569 MonotonicClock.java:202 - Scheduling approximate time conve> Apr 30 07:55:00 oraclelinux cassandra[2170]: INFO [main] 2022-04-30 07:55:00,577 MonotonicClock.java:338 - Scheduling approximate time-check> Apr 30 07:55:00 oraclelinux cassandra[2170]: WARN [main] 2022-04-30 07:55:00,585 StartupChecks.java:143 - jemalloc shared library could not > Apr 30 07:55:00 oraclelinux cassandra[2170]: WARN [main] 2022-04-30 07:55:00,585 StartupChecks.java:187 - JMX is not enabled to receive remo> Apr 30 07:55:00 oraclelinux cassandra[2170]: INFO [main] 2022-04-30 07:55:00,590 SigarLibrary.java:44 - Initializing SIGAR library Apr 30 07:55:00 oraclelinux cassandra[2170]: WARN [main] 2022-04-30 07:55:00,603 SigarLibrary.java:174 - Cassandra server running in degrade> Apr 30 07:55:00 oraclelinux cassandra[2170]: WARN [main] 2022-04-30 07:55:00,604 StartupChecks.java:329 - Maximum number of memory map areas> ``` ## Step 4 – Verify Apache Cassandra Wait for some time to bring up Apache Cassandra completely, then verify Apache Cassandra using the following command: ``` nodetool status ``` You will get the following error: ``` nodetool: Failed to connect to '127.0.0.1:7199' - URISyntaxException: 'Malformed IPv6 address at index 7: rmi://[127.0.0.1]:7199'. ``` To resolve this error, add the “legacy” parsing flag when running nodetool: ``` nodetool -Dcom.sun.jndi.rmiURLParsing=legacy status ``` You should get the following output: ``` Datacenter: datacenter1 ======================= Status=Up/Down |/ State=Normal/Leaving/Joining/Moving -- Address Load Tokens Owns (effective) Host ID Rack UN 127.0.0.1 69.06 KiB 16 100.0% 91f2092e-f428-40f8-8093-efe820abe917 rack1 ``` Next, connect to the Cassandra shell using the cqlsh utility: ``` cqlsh ``` Once you are connected, you should get the following output: ``` Connected to Test Cluster at 127.0.0.1:9042 [cqlsh 6.0.0 | Cassandra 4.0.3 | CQL spec 3.4.5 | Native protocol v5] Use HELP for help. cqlsh> ``` ## Step 5 – Change Cassandra Cluster Name By default, Cassandra’s cluster name is set as  “Test Cluster.” To change the default cluster name, connect to Cassandra with the following command: ``` cqlsh ``` Next, change the cluster name with the following command: ``` cqlsh> UPDATE system.local SET cluster_name = 'Atlantic Cluster' WHERE KEY = 'local'; ``` Next, exit from the Cassandra shell with the following command: ``` cqlsh> exit ``` Next, edit the Apache Cassandra main configuration file and define your new cluster name: ``` nano /etc/cassandra/default.conf/cassandra.yaml ``` Change the Cassandra cluster name as shown below: ``` cluster_name: 'Atlantic Cluster' ``` Save and close the file, then restart Apache Cassandra to apply the changes: ``` systemctl restart cassandra ``` Now, verify the Cassandra cluster name with the following command: ``` cqlsh ``` You should get your new cluster name in the following output: ``` Connected to Atlantic Cluster at 127.0.0.1:9042 [cqlsh 6.0.0 | Cassandra 4.0.3 | CQL spec 3.4.5 | Native protocol v5] Use HELP for help. ``` ## Conclusion In the above guide, we explained how to install Apache Cassandra on Oracle Linux 8. You can now use Apache Cassandra to handle and manage large data sets. Give it a try on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Apache Solr on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-apache-solr-on-oracle-linux-10/ | Published: 2022-05-26 | Updated: 2026-01-01 | Author: Hitesh Jethva Apache Solr is an open-source, REST API-based search platform built on Apache Lucene Framework. It is also called “Searching On Lucene w/Replication.” Written in Java Language, Apache Solr is designed for scalability and fault tolerance. Solr is enterprise-ready, fast, and highly scalable, making it ideal for use in search-based and big data analytics applications. In simple terms, Solr is a ready-to-deploy search engine that is optimized to search large volumes of text-centric data. In this post, we will show you how to install Apache Solr on Oracle Linux 10. ## Step 1 – Install Java JDK Apache Solr is written in Java, so Java must be installed on your server. If not installed, you can install it with the following command: ``` dnf update -y dnf install java-21-openjdk -y ``` Once installed, you can verify the Java version using the following command: ``` java --version ``` You should get the following output: ``` openjdk 21.0.9 2025-10-21 LTS OpenJDK Runtime Environment (Red_Hat-21.0.9.0.10-1.0.1) (build 21.0.9+10-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.9.0.10-1.0.1) (build 21.0.9+10-LTS, mixed mode, sharing) ``` You will also need to install the EPEL repository on your server. You can install it with the following command: ``` dnf install -y https://dl.fedoraproject.org/pub/epel/epel-release-latest-10.noarch.rpm ``` **Also Read** [How to Install and Manage Java Versions on Oracle Linux 8](https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-manage-java-versions-on-oracle-linux/) ## Step 2 – Download Apache Solr By default, Apache Solr is not included in the Oracle Linux default repository, so you will need to download it from their official website. You can download it with the following command: ``` wget https://dlcdn.apache.org/solr/solr/9.10.0/solr-9.10.0.tgz ``` Once Apache Solr is downloaded, download the SHA512 checksum using the following command: ``` wget https://downloads.apache.org/solr/solr/9.10.0/solr-9.10.0.tgz.sha512 ``` Next, calculate the SHA512 checksum of the Apache Solr downloaded file: ``` gpg --print-md SHA512 solr-9.10.0.tgz ``` Sample output: ``` solr-9.10.0.tgz: F97153CE 12A1B881 34B54C4A 5A74F6EE DD67E060 92B6CAA3 CC9DDAFF 7B65FA3D 4816E770 2FB07A54 CC0E8372 4EB9CEAB 78AF7710 0B688CD6 8323B5A9 88E031BE ``` Next, compare the hash value to the contents of the SHA512 file: ``` cat solr-9.10.0.tgz.sha512 ``` Sample output: ``` f97153ce12a1b88134b54c4a5a74f6eedd67e06092b6caa3cc9ddaff7b65fa3d4816e7702fb07a54cc0e83724eb9ceab78af77100b688cd68323b5a988e031be *solr-9.10.0.tgz ``` After matching the SHA512 hashes, extract the downloaded file with the following command: ``` tar xzf solr-9.10.0.tgz ``` ## Step 3 – Install Apache Solr At this point, Apache Solr is downloaded and ready for installation. You can install it using the following command: ``` ./solr-9.10.0/bin/install_solr_service.sh solr-9.10.0.tgz ``` Once the installation is complete, you should get the following output: ``` { "solr_home":"/var/solr/data", "version":"9.10.0 6fe796b4300e3fceffd8a2e450c4a3ba0fe85f81 - janhoy - 2025-11-02 17:26:05", "startTime":"Thu Jan 01 22:28:56 EST 2026", "uptime":"0 days, 0 hours, 0 minutes, 11 seconds", "memory":"119.2 MB (%23.3) of 512 MB"} ``` By default, Solr listens on localhost. So you will need to configure it to listen on all interface. ``` nano /etc/default/solr.in.sh ``` Change the following lines: ``` SOLR_HOST="0.0.0.0" SOLR_JETTY_HOST="0.0.0.0" SOLR_ZK_EMBEDDED_HOST="0.0.0.0" ``` Next, restart the Solr service. ``` systemctl restart solr ``` At this point, Apache Solr is started and listens on port 8983. You can check it with the following command: ``` ss -altnp | grep 8983 ``` Sample output: ``` LISTEN 0 50 *:8983 *:* users:(("java",pid=4739,fd=157)) ``` ## Step 4 – Configure Firewall If the firewalld firewall is installed and running in your server, then you will need to allow port 8983 through firewalld. You can allow it with the following command: ``` firewall-cmd --add-port=8983/tcp --permanent ``` Next, reload the firewall using the following command: ``` firewall-cmd --reload ``` Also Read [How to Setup Firewall with Firewalld](https://www.atlantic.net/vps-hosting/how-to-set-up-firewall-with-firewalld-on-centos-8/) ## Step 5 – Access Apache Solr You can now open your web browser and access the Apache Solr web interface using the URL **http://your-server-ip:8983/solr**. You should see the Apache Solr dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2022/05/solr.png)   ## Conclusion Congratulations! You have successfully installed Apache Solr on Oracle Linux 10. You can now start building a search-based big analytics application using the Apache Solr. Give it a try on your [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Choosing Cloud or Dedicated Hosting for PCI Compliance > URL: https://www.atlantic.net/pci-compliant-hosting/choosing-cloud-or-dedicated-hosting-for-pci-compliance/ | Published: 2022-05-27 | Updated: 2025-07-26 | Author: Richard Bailey Businesses involved with handling credit cards for payment need to maintain compliance with the PCI-DSS guidelines designed to ensure transaction security. Failure to adhere to the standards exposes a company to substantial financial fines. Companies that accept credit card payments need to exercise caution when engaging a public cloud provider. This article will discuss the regulatory guidelines organizations must follow and take a look at the differences between a cloud and a [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) solution to establish PCI compliance. ## What Is PCI-DSS? The[Payment Card Industry Data Security Standard (PCI DSS)](https://www.fisglobal.com/en/insights/merchant-solutions-worldpay/article/pci-dss-history-everything-you-need-to-know) defines the security measures that need to be implemented by any company that accepts, processes, transmits, or stores credit card data. The guidelines were first introduced as PCI DSS 1.0 in December 2004 by the PCI’s founding members, which included American Express, Discover Financial Services, JCB International, Mastercard, and Visa. PCI-DSS 2.0, introduced in 2010, was designed to streamline the assessment process. In January 2015, version 3.0 went into effect with a focus on specific aspects of increasing credit card security. These included emphasizing employee education and awareness in companies accepting credit cards, implementing flexible and secure authentication methods, and treating security as a shared responsibility when third parties are involved. The current version of PCI-DSS is v4, which went live on March 31st, 2022. The core elements of PCI-DSS are largely unchanged; however, there is a greater focus on security and promoting security as a continuous process. ## What Is Required for PCI Compliance? All organizations handling credit cards are bound by the PCI-DSS requirements. In today’s business world, this encompasses virtually every company from small startups to multi-national conglomerates. E-commerce depends on payments being made via credit cards, and any business with an online presence needs to comply with PCI-DSS. Organizations need to follow [twelve requirements](https://www.pcisecuritystandards.org/pci_security/maintaining_payment_security) to be PCI-DSS compliant. The focus of all the requirements is to protect cardholder data. The requirements apply to any merchant processing credit cards and their service providers, including public cloud vendors. 1. A firewall must be installed and maintained to protect cardholder data. A firewall provides the first line of network defense, and its access rules should be reviewed regularly to identify and close security vulnerabilities. 2. Vendor-supplied default passwords and security settings should not be used. PCI-DSS mandates that these passwords be changed to harden security and make it more difficult for unauthorized actors to access systems containing cardholder data. 3. Stored cardholder data must be protected. Satisfying this requirement involves knowing where all related data is stored and its retention period. All data needs to be encrypted, truncated, tokenized, or hashed using methods accepted by the PCI industry. Rules regarding how primary account numbers can be displayed are also part of this requirement. 4. Cardholder data must be encrypted when transmitted across open, public networks like the Internet. The destination of transmitted data needs to be known before initiating the data transfer. 5. Anti-virus software must be used to protect all systems in the environment and be regularly updated with the latest malicious code signatures. Any laptop, desktop, or mobile device used to access systems containing cardholder information needs to be protected in this way. 6. Secure systems and applications must be developed and maintained. Security vulnerabilities need to be identified and mitigated. All systems in the payment card environment should be patched regularly, including operating systems, firewalls, databases, and application software. 7. Access to cardholder data should be granted only on a need-to-know basis. Restricting access to data in this way is a fundamental component of the PCI-DSS standards. 8. Unique IDs need to be assigned to everyone with computer access so access can be tracked to specific individuals for accountability. Two-factor authentication is required when accessing systems with cardholder data. 9. Physical access to cardholder data has to be restricted. Controls must be implemented to exclude unauthorized personnel from physically accessing the systems that hold cardholder data. 10. All-access to network resources and cardholder data needs to be tracked and monitored. Logs must be kept and reviewed for suspicious activity, and audit records need to contain specific information. 11. Security systems and processes are required to be tested regularly. This includes vulnerability scans and network penetration tests. All external IPs and domains are required to be scanned by a PCI-approved scanning vendor at least quarterly. 12. An information security policy must be maintained for all employees and contractors. The policy needs to undergo an annual review and be read by all employees and contractors. Many organizations do not have the internal IT resources necessary to effectively meet these requirements. This can pose a problem for businesses subject to PCI guidelines. They still need to protect cardholder data or face substantial fines. The most effective way for companies in this position to comply with the standards is with a third-party cloud vendor that offers [PCI-compliant hosting](https://www.atlantic.net/pci-compliant-hosting/). ## PCI-Compliant Solutions The two primary options when hosting servers with a public cloud provider involve using [shared cloud resources](https://www.atlantic.net/cloud-platform/) or [dedicated hosts](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/). The best choice depends on factors unique to each business situation. The following factors need to be considered when selecting your hosting solution. ### The size of the hosted environment An understanding of the size of your hosted environment is crucial when deciding how to host it. Very small environments may not need the benefits of a dedicated host. In cases where the required infrastructure’s size is unknown or is anticipated to grow substantially, the elasticity of a cloud-based solution may be best. When the infrastructure size is well-known, dedicated hosting provides customers with more control and privacy over the environment. ### The availability of in-house technical resources Dedicated solutions require more knowledge and involvement from the customer’s technical staff. Cloud servers generally place more responsibility for maintaining the environment on the provider, though there are vendors that offer extended support for dedicated hosting solutions. Organizations need to be realistic when evaluating their technical resources. ### Latency concerns Based on how much latency a business can tolerate, dedicated hosts may be the logical choice. Enhanced performance can be achieved with a dedicated solution by eliminating the need to traverse shared networks when transmitting data. ### Software requirements Some software vendors like Microsoft restrict some of their licenses from being used in public cloud settings. Companies deploying these products need to use dedicated hosts for PCI compliance. ### Budgetary limitations A cloud server solution will usually be less expensive to initially implement than one using dedicated hosts. As infrastructure grows, the resources available in a dedicated host can become more economical and provide the best fit. Larger implementations can benefit from engaging dedicated hosts at the outset of the move to the cloud. ## Making the Choice In most cases where the environment is understood and expected to be fairly stable going forward, a dedicated hosting solution is the best way to ensure PCI compliance. The self-contained nature of dedicated hosts provides enhanced security and reduced latency by eliminating shared tenants with fluctuating workloads. Software licensing may come into play and steer a customer toward a dedicated hosting solution. Businesses attempting to maintain PCI compliance don’t need to go it alone. [Atlantic.Net’s PCI hosting services](https://www.atlantic.net/pci-compliant-hosting/) include dedicated hosting and cloud server solutions for businesses required to comply with PCI-DSS guidelines. They can tailor their offerings to fit the needs of any size business that needs to protect the cardholder data they process. --- # How to Install Joomla on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-joomla-on-oracle-linux-10/ | Published: 2022-05-28 | Updated: 2026-01-01 | Author: Hitesh Jethva Joomla is a free, open-source CMS software solution written in PHP. It is used for creating different types of websites including blogs, eCommerce sites, and marketing sites. Joomla provides a user-friendly and powerful control panel that helps you to build and host your website on the Internet easily without the need to learn how to read and write complicated codes and scripts. In this post, we will explain to you how to install Joomla with Nginx on Oracle Linux 10. ## Step 1 – Install Nginx and MariaDB First, install the Nginx and MariaDB database servers with the following command: ``` dnf install nginx mariadb-server -y ``` Once both packages are installed, start the Nginx and MariaDB services and enable them to start at system reboot: ``` systemctl start nginx mariadb systemctl enable nginx mariadb ``` ## Step 2 – Install PHP and PHP-FPM Next, you will need to install PHP, PHP-FPM, and other PHP extensions on your server. You can install PHP with other extensions using the following command: ``` dnf install php php-fpm php-curl php-xml php-zip php-mysqlnd php-intl php-gd php-json php-ldap php-mbstring php-opcache unzip -y ``` Once all the packages are installed, edit the php.ini file and tweak some settings: ``` nano /etc/php.ini ``` Change the following values: ``` memory_limit = 256M output_buffering = Off max_execution_time = 300 date.timezone = Europe/London ``` Save and close the file when you are done. Next, edit the PHP-FPM configuration file: ``` nano /etc/php-fpm.d/www.conf ``` Change the user and group from apache to nginx: ``` user = nginx group = nginx ``` Save and close the file, then set proper permissions to the PHP library directory: ``` chown -R nginx:nginx /var/lib/php/ ``` Next, start the PHP-FPM service and enable it to start at system reboot: ``` systemctl start php-fpm systemctl enable php-fpm ``` ## Step 3 – Create a Joomla Database Joomla uses MySQL/MariaDB as a database backend, so you will need to create a database and user for Joomla. First, log in to the MariaDB shell with the following command: ``` mysql ``` Once you are connected, create a database and user with the following command: ``` CREATE DATABASE joomladb; GRANT ALL PRIVILEGES ON joomladb.* TO 'joomla'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 4 – Download Joomla Next, go to the Joomla download and download the latest version of Joomla using the following command: ``` wget https://downloads.joomla.org/cms/joomla6/6-0-0/Joomla_6-0-0-Stable-Full_Package.zip ``` Next, create a directory for Joomla and extract the downloaded file inside the joomla directory: ``` mkdir -p /var/www/html/joomla unzip Joomla*.zip -d /var/www/html/joomla ``` Next, set proper permissions and ownership to the joomla directory: ``` chown -R nginx:nginx /var/www/html/joomla chmod -R 777 /var/www/html/joomla ``` ## Step 5 – Configure Nginx for Joomla Next, you will need to create an Nginx virtual host configuration file for Joomla. You can create it with the following command: ``` nano /etc/nginx/conf.d/joomla.conf ``` Add the following lines: ``` server { listen 80; root /var/www/html/joomla; index index.php index.html index.htm; server_name joomla.example.com; location / { try_files $uri $uri/ /index.php?$args; } location ~ [^/]\.php(/|$) { fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_index index.php; fastcgi_pass unix:/run/php-fpm/www.sock; include fastcgi_params; fastcgi_param PATH_INFO $fastcgi_path_info; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; } } ``` Save and close the file, then restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 6 – Access Joomla Website Now, Joomla is installed and configured on your server. You can now access the Joomla website using the URL **http://joomla.example.com**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/08/j1.png) Provide your site information and click on **Setup Login Data**. You should see the database configuration page: ![](https://www.atlantic.net/wp-content/uploads/2021/08/j2.png)Provide your admin username, password, email and click on **Setup Database Connection**. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2021/08/j3.png) Provide your database information and click on the **Install Joomla** button. Once the installation has been finished, you should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/08/j4.png)   Now, open a new tab in your web browser and access the Joomla administrator console using the URL http://joomla.example.com/administrator/. ![](https://www.atlantic.net/wp-content/uploads/2021/08/j6.png) Provide your admin username and password, then click on the **Login** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/08/j7.png) ## Conclusion In this post, you learned how to install Joomla with Nginx on Oracle Linux 10. You can now start creating your blog or website from the Joomla web interface. Give it a try on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Drupal on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-drupal-on-oracle-linux-10/ | Published: 2022-05-29 | Updated: 2026-01-01 | Author: Hitesh Jethva Drupal is a powerful open-source content management system written in PHP. It is a simple and flexible CMS that helps beginner users to build and host a website without any coding knowledge. Drupal comes with a user-friendly web UI that helps you to manage your content, media, and other assets from a central location. It has a large, supportive community and is used by millions of people and organizations around the world. In this tutorial, we will show you how to install Drupal CMS with Apache on Oracle Linux 10. **Also Read** [Can Drupal Websites Be HIPAA-Compliant?](https://www.atlantic.net/hipaa-compliant-hosting/can-drupal-websites-be-hipaa-compliant/) ## Step 1 – Install Apache and MariaDB Server First, install the Apache web server and MariaDB database server using the following command: ``` dnf install httpd mariadb-server curl unzip git -y ``` Once both packages are installed, start the Apache and MariaDB services and enable them to start at system reboot: ``` systemctl start httpd systemctl start mariadb systemctl enable httpd systemctl enable mariadb ``` ## Step 2 – Install PHP and Other Extensions Next, it is recommended to install the latest version of PHP and other extensions to your server. By default, the latest version of PHP is not included in the Rocky Linux default repository, so you will need to install it from the Remi repository. You can install the Remi repository with the following command: ``` dnf install -y https://dl.fedoraproject.org/pub/epel/epel-release-latest-10.noarch.rpm ``` Next, install PHP 8 and other extensions using the following command: ``` dnf install php php-curl php-mbstring php-gd php-xml php-pear php-fpm php-mysqlnd php-pdo php-opcache php-json php-zip php-soap -y ``` Once all the packages are installed, verify the PHP version with the following command: ``` php -v ``` Output: ``` PHP 8.3.19 (cli) (built: Mar 12 2025 13:10:27) (NTS gcc x86_64) Copyright (c) The PHP Group Zend Engine v4.3.19, Copyright (c) Zend Technologies with Zend OPcache v8.3.19, Copyright (c), by Zend Technologies ``` Next, edit the php.ini file and tweak some settings: ``` nano /etc/php.ini ``` Change the following lines: ``` memory_limit = 256M date.timezone = Asia/Kolkata ``` Save and close the file when you are finished. ## Step 3 – Create a Drupal Database Next, you will need to create a database and user for Drupal. First, connect to the MariaDB with the following command: ``` mysql ``` Once you are connected, create a database and user using the following command: ``` CREATE DATABASE drupaldb; GRANT ALL ON drupaldb.* TO 'drupaluser'@'localhost' IDENTIFIED BY 'securepassword'; ``` Next, flush the privileges and exit from the MariaDB shell: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 4 – Download Drupal First, download the latest version of Drupal from its official website using the following command: ``` wget https://www.drupal.org/download-latest/tar.gz -O drupal.tar.gz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar xvf drupal.tar.gz ``` Next, move the extracted directory to the Apache root directory: ``` mv drupal-*/ /var/www/html/drupal ``` Next, create a file directory required for Drupal and copy a sample settings.php file: ``` mkdir /var/www/html/drupal/sites/default/files cp /var/www/html/drupal/sites/default/default.settings.php /var/www/html/drupal/sites/default/settings.php ``` Next, set proper ownership and permissions on the drupal directory: ``` chown -R apache:apache /var/www/html/drupal chmod -R 777 /var/www/html/drupal ``` ## Step 5 – Configure Apache for Drupal Next, create an Apache virtual host configuration file for Drupal with the following command: ``` nano /etc/httpd/conf.d/drupal.conf ``` Add the following lines: ``` ServerName drupal.example.com ServerAdmin admin@example.com DocumentRoot /var/www/html/drupal/ CustomLog /var/log/httpd/access_log combined ErrorLog /var/log/httpd/error_log Options Indexes FollowSymLinks AllowOverride All Require all granted RewriteEngine on RewriteBase / RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule ^(.*)$ index.php?q=$1 [L,QSA] ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 6 – Access Drupal Website Now Drupal is installed and configured. You can now access it using the URL **http://drupal.example.com**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/08/d1.png) Select your Language and click on **Save and continue** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/08/d2.png) Select an installation type and click on the **Save and continue** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/08/d3-1.png) Provide your database information and click on the **Save and continue** button. You should see the Drupal site information on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/08/d4.png) ![](https://www.atlantic.net/wp-content/uploads/2021/08/d5.png) Provide your site information and click on the **Save and continue** button. Once the installation has been completed, you should see the Drupal dashboard on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/08/d6.png) ## Conclusion In this post, we explained how to install Drupal with Apache on Oracle Linux 10. You can now install Drupal on a live server and start creating your first website. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Tomcat on Oracle Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-tomcat-on-oracle-linux/ | Published: 2022-05-30 | Updated: 2026-01-01 | Author: Hitesh Jethva Apache Tomcat is a free, open-source, and extremely popular Servlet container used for deploying Java-based applications on the web. You can run JavaServer (JSP), JavaServlet, and Java Expression languages on the Apache Tomcat platform. It is the first choice of web developers for building and deploying dynamic websites and applications based on Java. In this post, we will explain how to install Apache Tomcat 11 on Oracle Linux 10. ## Step 1 – Install Java Apache Tomcat is a Java-based application, so Java must be installed on your server. If not installed, you can install it using the following command: ``` dnf install java-21-openjdk -y ``` After installing Java, verify the Java version with the following command: ``` java -version ``` Sample output: ``` openjdk version "21.0.8" 2025-07-15 LTS OpenJDK Runtime Environment (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS, mixed mode, sharing) ``` ## Step 2 – Download Apache Tomcat 11 Before starting, you will need to add a dedicated user for Tomcat. You can add it using the following command: ``` useradd -r -d /opt/tomcat/ -s /bin/false -c "Tomcat User" tomcat ``` Next, download the latest version of Apache Tomcat 11 using the following command: ``` wget https://dlcdn.apache.org/tomcat/tomcat-11/v11.0.15/bin/apache-tomcat-11.0.15.tar.gz ``` After downloading Apache Tomcat, create a directory for Tomcat and extract the downloaded file inside the /opt/tomcat directory: ``` mkdir /opt/tomcat tar xzf apache-tomcat-11.0.15.tar.gz -C /opt/tomcat --strip-components=1 ``` Next, change the ownership of /opt/tomcat directory to tomcat: ``` chown -R tomcat: /opt/tomcat/ ``` ## Step 3 – Configure Tomcat Admin User Next, you will need to create an admin user for managing Manager and Host Manager. You can do it by editing the /opt/tomcat/conf/tomcat-users.xml file: ``` nano /opt/tomcat/conf/tomcat-users.xml ``` Add the following lines just above the last line: ``` ``` Save and close the file when you are finished. ## Step 4 – Configure Tomcat for Remote Host By default, Tomcat can be accessed only from the localhost, so you will need to configure Tomcat to access it from the remote host. To access the Manager from the remote host, edit the **context.xml** file: ``` nano /opt/tomcat/webapps/manager/META-INF/context.xml ``` Remove the following lines: ``` ``` Save and close the file when you are finished. To access the Host Manager from the remote host, edit the **context.xml file**: ``` nano /opt/tomcat/webapps/host-manager/META-INF/context.xml ``` Remove the following lines: ``` ``` Save and close the file when you are finished. ## Step 5 – Create a Systemd Unit File for Apache Tomcat Next, it is recommended that you create a systemd unit file to manage the Tomcat service. You can create it with the following command: ``` nano /etc/systemd/system/tomcat.service ``` Add the following lines: ``` [Unit] Description=Apache Tomcat Server After=syslog.target network.target [Service] Type=forking User=tomcat Group=tomcat Environment=CATALINA_PID=/opt/tomcat/temp/tomcat.pid Environment=CATALINA_HOME=/opt/tomcat Environment=CATALINA_BASE=/opt/tomcat ExecStart=/opt/tomcat/bin/catalina.sh start ExecStop=/opt/tomcat/bin/catalina.sh stop RestartSec=10 Restart=always [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the Tomcat service and enable it to start at system reboot: ``` systemctl start tomcat systemctl enable tomcat ``` You can verify the status of the Tomcat service with the following command: ``` systemctl status tomcat ``` Sample output: ``` ● tomcat.service - Apache Tomcat Server Loaded: loaded (/etc/systemd/system/tomcat.service; disabled; preset: disabled) Active: active (running) since Fri 2025-12-31 23:04:23 EDT; 5s ago Invocation: 2012419a433b4b7a9f18842f4f0f5e85 Process: 147191 ExecStart=/opt/tomcat/bin/catalina.sh start (code=exited, status=0/SUCCESS) Main PID: 147204 (java) Tasks: 35 (limit: 24809) Memory: 157.5M (peak: 160M) CPU: 3.570s CGroup: /system.slice/tomcat.service └─147204 /usr/bin/java -Djava.util.logging.config.file=/opt/tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Djdk.tls.eph ``` ## Step 6 – Access Apache Tomcat Web UI At this point, Apache Tomcat is started and listening on port 8080. You can check it with the following command: ``` ss -antpl | grep 8080 ``` Sample output: ``` LISTEN 0 100 *:8080 *:* users:(("java",pid=13821,fd=43)) ``` You can now access Tomcat using the URL **http://your-server-ip:8080**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2021/08/t1.png) To access the Manager App, click on the **Manager App**button. You will be asked to provide an admin user and password as shown below: ![Tomcat Login Page](https://www.atlantic.net/wp-content/uploads/2021/08/p2-5.png) Provide your admin username and password and click on the **Sign in** button. You should see the following screen: ![Tomcat Manager Page](https://www.atlantic.net/wp-content/uploads/2021/08/p3-2-1024x536.png) To access the Host Manager App, click on the**Host Manager**link. You should see the following screen: ![Tomcat Host Manager Page](https://www.atlantic.net/wp-content/uploads/2021/08/p4-3-1024x535.png) ## Conclusion In this post, we explained how to install the Apache Tomcat 11 on Oracle Linux 10. You can now start building a Java-based application and deploy it using the Apache Tomcat platform. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Magento on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-magento-on-oracle-linux-10/ | Published: 2022-05-31 | Updated: 2026-01-01 | Author: Hitesh Jethva Magento is an open-source, web-based eCommerce platform that helps with the rapid setup of an online shop. It is written in PHP and uses MariaDB to store its contents. Magento comes with an admin control panel that allows beginner users to start an online shopping cart easily. It comes with a variety of plugins and themes to enhance website functionality and customer experience. In this post, we will show you how to install the Magento eCommerce platform on Oracle Linux 10. ## Step 1 – Install Apache and MariaDB Server First, install Apache using the following command: ``` dnf install httpd httpd-tools -y ``` Once both packages are installed, start Apache service and enable it to start at system reboot: ``` systemctl start httpd systemctl enable httpd ``` Next, create a repo for MariaDB. ``` nano /etc/yum.repos.d/MariaDB.repo ``` Add the following line: ``` [mariadb] name=MariaDB 11.4 baseurl=https://archive.mariadb.org/mariadb-11.4/yum/rhel/\$releasever/\$basearch gpgkey=https://archive.mariadb.org/PublicKey gpgcheck=0 ``` Now, install MariaDB server using the command below. ``` dnf install mariadb-server ``` Next, start and enable the MariaDB service: ``` systemctl start mariadb systemctl enable mariadb ``` ## Step 2 – Install PHP and Other Extensions Next, you will need to install PHP and other extensions on your server. You can install PHP with other extensions using the following command: ``` dnf install php php-cli php-mysqlnd php-sodium php-opcache php-xml php-gd php-soap php-pdo php-bcmath php-intl php-mbstring php-json php-iconv php-zip unzip git -y ``` Next, edit the php.ini file and change some values: ``` nano /etc/php.ini ``` Change the following values: ``` memory_limit = 1024M upload_max_filesize = 256M zlib.output_compression = on max_execution_time = 18000 date.timezone = Asia/Kolkata ``` Save and close the file when you are finished. Next, you will need to install the PHP **sodium** extension on your system. First, install the EPEL repository with the following command: ``` dnf install -y https://dl.fedoraproject.org/pub/epel/epel-release-latest-10.noarch.rpm ``` Next, install the required dependencies with the following command: ``` dnf install php-cli libsodium php-pear php-devel libsodium-devel make ``` Next, verify the sodium extension using the following command: ``` php -i | grep sodium ``` Sample output: ``` /etc/php.d/30-sodium.ini, sodium sodium support => enabled libsodium headers version => 1.0.20 libsodium library version => 1.0.20 ``` ## Step 3 – Create a Magento Database Next, you will need to create a database and a user for Magento. First, connect to MariaDB with the following command: ``` mysql ``` Once you are connected, create a database and user: ``` CREATE DATABASE magento; CREATE USER 'magento'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the Magento database: ``` GRANT ALL ON magento.* TO 'magento'@'localhost' IDENTIFIED BY 'password' WITH GRANT OPTION; SET GLOBAL log_bin_trust_function_creators = 1; ``` Next, flush the privileges and exit from the MariaDB shell: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 4 – Install Composer Next, you will need to install Composer on your system. You can install it using the following command: ``` curl -sS https://getcomposer.org/installer | php mv composer.phar /usr/local/bin/composer ``` Next, verify the Composer installation using the following command: ``` composer -V ``` Sample output: ``` Composer version 2.9.3 2025-12-25 10:35:47 ``` ## Step 5 – Download Magento At the time of writing this tutorial, the latest version of Magento is 2.4.2. You can download it with the following command: ``` wget https://github.com/magento/magento2/archive/refs/tags/2.4.8.zip ``` Once Magento is downloaded, unzip the downloaded file with the following command: ``` unzip 2.4.8.zip ``` Next, move the extracted directory to the Apache web root: ``` mv magento2-* /var/www/html/magento2 ``` Next, change the directory to magento2 and install all required PHP dependencies with the following command: ``` cd /var/www/html/magento2 composer install ``` Next, set proper ownership to the Magento directory: ``` chown -R apache:apache /var/www/html/magento2 ``` Next, set permissions needed with the following commands: ``` cd /var/www/html/magento2 find var generated vendor pub/static pub/media app/etc -type f -exec chmod g+w {} + find var generated vendor pub/static pub/media app/etc -type d -exec chmod g+ws {} + chown -R apache:apache . chmod u+x bin/magento chown -R apache:apache /var/lib/php/session ``` ## Step 6 – Configure Apache for Magento Next, create an Apache virtual host configuration file for Magento: ``` nano /etc/httpd/conf.d/magento.conf ``` Add the following lines: ``` ServerAdmin admin@example.com ServerName magento.example.com DocumentRoot /var/www/html/magento2/ DirectoryIndex index.php Options Indexes FollowSymLinks MultiViews AllowOverride All Order allow,deny allow from all ErrorLog /var/log/httpd/magento_error.log CustomLog /var/log/httpd/magento_access.log combined ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 7 – Install Magento Magento web installation has been removed from Magento version 2.2, so you will need to install the Magento from the command line. First, change the directory to magento2 and disable the Elasticsearch module using the following command: ``` cd /var/www/html/magento2/ sudo -u apache bin/magento module:disable Magento_OpenSearch Magento_Elasticsearch Magento_Elasticsearch8 ``` Next, install Magento using the following command: ``` sudo -u apache bin/magento setup:install --admin-firstname="hitesh" --admin-lastname="jethva" --admin-email="admin@example.com" --admin-user="admin" --admin-password="secure@123" --db-name="magento" --db-host="localhost" --db-user="magento" --db-password="password" --language=en_US --currency=USD --timezone=Asia/Kolkata --cleanup-database --base-url=http://"magento.example.com" ``` Once Magento has been installed, you should get the following output: ``` [Progress: 828 / 831] Disabling Maintenance Mode: [Progress: 829 / 831] Post installation file permissions check... For security, remove write permissions from these directories: '/var/www/html/magento2/app/etc' [Progress: 830 / 831] Write installation date... [Progress: 831 / 831] [SUCCESS]: Magento installation complete. [SUCCESS]: Magento Admin URI: /admin_lfsxqf Nothing to import. ``` ## Step 8 – Install Magento Cron Jobs Next, you will need to set up Magento cron jobs. First, navigate to the Magento root directory with the following command: ``` cd /var/www/html/magento2 ``` Next, install the Magento cron jobs with the following command: ``` sudo -u apache bin/magento cron:install ``` ## Step 9 – Access Magento Web UI Now, open your web browser and access the Magento web interface using the URL **http://magento.example.com/admin_lfsxqf**. You should see the Magento login page: ![](https://www.atlantic.net/wp-content/uploads/2021/08/m-1.png) Provide your admin username and password and click on the **Sign in** button. You should see the Magento dashboard on the following page: ![Magento Dashboard Page](https://www.atlantic.net/wp-content/uploads/2021/08/p2-4-1024x537.png) ## Conclusion You have successfully installed Magento on Oracle Linux 10. You can now start building your online store using the Magento platform. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Top 10 Best HIPAA Compliant Practice Management Software > URL: https://www.atlantic.net/hipaa-compliant-hosting/top-10-best-hipaa-compliant-practice-management-software/ | Published: 2022-06-01 | Updated: 2025-08-03 | Author: Richard Bailey Healthcare practices across the United States rely on numerous kinds of software to assist day-to-day operations and help everything run smoothly. These applications vary from administration software, chat tools, billing, forms, and data analysis tools. Any Healthcare application that processes or saves protected health information (PHI) must be protected by the physical, technical, and administrative safeguards of HIPAA compliance. One of the easiest ways to meet the standards expected is to outsource IT services to a [HIPAA-compliant hosting provider](https://www.atlantic.net/hipaa-compliant-hosting/). This will open the door to a much greater choice of practice management software that is designed to take advantage of the built-in security features HIPAA-compliant cloud services provide. Here is a collection of the top 10 HIPAA compliant practice management software: ## 1. Let’s Talk Interactive Let’s Talk Interactive is a leading provider of HIPAA-compliant telehealth technology solutions, facilitating over three million minutes of remote telehealth sessions each month. Let’s Talk enables healthcare practices to provide remote telehealth in a secure and HIPAA-compliant environment. Let’s Talk delivers a customizable and user-friendly web conferencing platform that is compatible with almost any operating system, web browser, or mobile phone. The company’s cloud-based telehealth platform is used by medical organizations ranging from solo practitioners to large-scale hospital networks, and we are delighted to partner with them as part of our HIPAA compliant hosting services. ## 2. Naologic Inc Naologic Inc offers a completely visual, no-code HIPAA compliant application platform that helps small and medium-sized businesses build and customize their marketing, sales, operations, HR, training, and purchasing applications. Healthcare practices often require bespoke applications that are specific to the practice. Naologic empowers non-technical healthcare professionals to build their very own applications in an easy-to-use package. No code really means no coding, you simply drag and drop how you want the data to flow, or you can make use of a large number of pre-designed modules. ## 3. Simple Practice Simple Practice is an all-in-one provider of HIPAA-compliant software solutions for healthcare practices. You can purchase one or many healthcare applications, including scheduling software for keeping timely appointments and documentation portals for a secure and paperless practice. Popular billing tools provide a user-friendly client-facing interface for simple payments, customer interactions, and everyday requests like prescriptions and receiving medical results.  There are several bundled client communication tools such as text, email, and instant chat services that have proven popular. ## 4. Salesforce Health Cloud Salesforce is a major provider of enterprise software solutions. The Salesforce Health Cloud is an important client relationship manager (CRM) for healthcare and life sciences. It is a suite of HIPAA-compliant services that personalize patient engagement on a unified platform of clinical and non-clinical data. Health Cloud aims to make sharing data a secure but simple process. Larger, often multi-practice healthcare organizations are more likely to benefit from Health Clouds collaboration features. Expand access to healthcare using digital self-service tools and enable healthcare professionals to collaborate deeply on a secure platform. ## 5. QGenda QGenda is a suite of HIPAA-compliant tools that focus on managing the workforce and keeping the healthcare practice running smoothly. Scheduling tools keep the workforce running efficiently around the clock, while capacity tools help the practice by ensuring beds, operating rooms and examination rooms are always available. QGenda integrates with Human Resources tools for easier team management. With QGenda, employees can access and securely update electronic health records and leverage billing systems that benefit patient interaction. As a result, healthcare organizations can streamline processes, improve access to data, and ensure providers are available to deliver care when and where it is needed. ## 6. Kalix Kalix is a HIPAA-compliant EMR, practice management & telehealth solution for healthcare professionals. The platform is user-friendly and accessible 24×7. It integrates client care, scheduling, documentation, messaging & billing into a user-friendly platform. Kalix works for large and small healthcare organizations and the service can be tailored to suit any practice workflow. It features all the tools necessary in a simple, cost-effective package. ## 7. Pabau Pabau is a client relationship manager (CRM) for healthcare practices that works on all operating systems, mobile, and tablets. Pabau contains numerous tools such as appointment scheduling, paperless health records, online bookings, and payments. There are many features for healthcare professionals to improve staff productivity, enhance collaboration, and provide accurate consultancy. Clinical trials,  medical research, and healthcare training are achievable via Kalix. Need help hiring the best talent or handling the efficient ordering of stock? Kalix has you covered. ## 8. CipherHealth: CipherConnect [CipherConnect](https://cipherhealth.com/cipherconnect/) is all about patient engagement and well-being and delivering care on a consistent level during every touchpoint at the practice; pre-care, point of care, and post-care. There is a heavy focus on mobile communications for booking appointments, informing patients of appointments, registrations, and check-in. The app collects data for consent, forms, and payment information. This approach boosts patient satisfaction and helps with the smooth running of the practice, as well as helping to keep the revenue flowing with user-friendly payment options. ## 9. 10 x 8 10 x 8 is patient management software used by healthcare organizations to create and organize online bookings, forecast demand, and plan for busy times in the practice. Healthcare professionals benefit from accurate scheduling, reduced admin, and detailed reports about their patients. To reduce no-shows, the scheduling platform sends automated SMS, email, and voicemails to the patients. Patients can even book slots on the practice website and sync appointments with their phone calendars. ## 10. TheraNest TheraNest is a HIPAA compliant service that provides a platform for core practice services that saves healthcare professionals significant amounts of time and helps with accurate patient interactions. Therapy notes provide a templated form that carries patient data over between visits. The payment platform performs quick and easy insurance claims, and all data can be conveniently saved in secure document storage, helping practices to go paperless. The suite features HIPAA compliant video conferencing, mobile app integration, and a patient support portal to reach out directly to patients. ## How Can Atlantic.Net Help? Are you looking for a leading [hosting provider](https://www.atlantic.net/hosting-services-provider/) to host your Practice Management Software application? Look no further than Atlantic.Net. With over 30 years of proven experience, our [full suite of managed services](https://www.atlantic.net/managed-services/) and always available professional support team can build the perfect solution for your business or organization. Atlantic.Net stands ready to help you attain fast compliance with a range of certifications, such as SOC 2 and SOC 3, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/), and HITECH, all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, visit us at [www.atlantic.net](https://www.atlantic.net), call 866-618-DATA (3282), or email us at [sales@atlantic.net](mailto:sales@atlantic.net). You can find out more information by [contacting our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # How to Install LAMP Stack on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-lamp-stack-on-oracle-linux-10/ | Published: 2022-06-02 | Updated: 2025-12-31 | Author: Hitesh Jethva LAMP stands for “Linux, Apache, MariaDB, and PHP,” a free, open-source, widely used software stack to host web applications. LAMP is a collection of free software solutions that are used together to enable a server to host dynamic websites and web applications. Each component of the LAMP stack contributes essential capabilities. Linux is a free and open-source operating system, Apache is an open-source web server that processes requests and serves web pages, MySQL is an open-source relational database management system for storing application data, and PHP is an open-source scripting language that works with Apache to help you create dynamic web pages. In this post, we will explain how to install the LAMP stack on Oracle Linux 10. ## Step 1 – Install Apache Web Server on Oracle Linux 10 By default, the Apache webserver is available in the Oracle Linux 10 default repo. You can install it by running the following command: ``` dnf install httpd -y ``` Once the Apache web server is installed, start the Apache service and enable it to start at system reboot. ``` systemctl start httpd systemctl enable httpd ``` Next, check the running status of the Apache service using the following command: ``` systemctl status httpd ``` You should see the following output: ``` ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; vendor preset: disabled) Active: active (running) since Tue 2025-12-31 06:01:07 EDT; 7s ago Docs: man:httpd.service(8) Main PID: 1689 (httpd) Status: "Started, listening on: port 80" Tasks: 213 (limit: 23694) Memory: 25.1M CGroup: /system.slice/httpd.service ├─1689 /usr/sbin/httpd -DFOREGROUND ├─1690 /usr/sbin/httpd -DFOREGROUND ├─1691 /usr/sbin/httpd -DFOREGROUND ├─1692 /usr/sbin/httpd -DFOREGROUND └─1693 /usr/sbin/httpd -DFOREGROUND ``` Next, open your web browser and verify the Apache test page using the URL **http://your-server-ip**. You should see the Apache test page on the following screen: ![LAMP server Apache test page](https://www.atlantic.net/wp-content/uploads/2022/05/p1-3-1024x409.png) **Also Read** [How to Install and Configure Apache Web Server on Oracle Linux 8](https://www.atlantic.net/vps-hosting/how-to-install-and-configure-apache-webserver-on-oracle-linux/) ## Step 2 – Install MariaDB Database Server on Oracle Linux 10 By default, the MariaDB or MySQL package is included on the Oracle Linux default repo. I would recommend installing a MariaDB server due to its numerous enhancements like high-performance storage engines and backward compatibility with MySQL. You can install the MariaDB server with the following command: ``` dnf install mariadb-server -y ``` Once the MariaDB package is installed, start the MariaDB service and enable it to start at system reboot: ``` systemctl start mariadb systemctl enable mariadb ``` Next, verify the MariaDB service status using the following command: ``` systemctl status mariadb ``` Next, you will need to run the mysql_secure_installation script to secure the MariaDB installation. You can run it using the following command: ``` mysql_secure_installation ``` You will then be prompted to set a MariaDB root password, remove anonymous users, disallow root login, and remove the test database as shown below: ``` Enter current password for root (enter for none): Set root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` ## Step 3 – Install PHP on Oracle Linux 10 Next, you will need to install PHP (PHP Hypertext Preprocessor) in your system. You can install PHP 8 with other extensions using the following command: ``` dnf install php php-fpm php-cli php-curl php-zip php-mysqli -y ``` Once PHP is installed, verify the installed version of PHP with the following command: ``` php -v ``` You should see the following command: ``` PHP 8.3.26 (cli) (built: Sep 23 2025 17:57:26) (NTS gcc x86_64) Copyright (c) The PHP Group Zend Engine v4.3.26, Copyright (c) Zend Technologies with Zend OPcache v8.3.26, Copyright (c), by Zend Technologies ``` You can also test the PHP version through the web browser. To do so, create an info.php file: ``` nano /usr/share/httpd/noindex/info.php ``` Add the following code: ``` ``` Save and close the file, then create a symlink of info.php. ``` ln -s /usr/share/httpd/noindex/info.php /var/www/html/info.php ``` Next, edit the Apache default configuration file: ``` nano /etc/httpd/conf.d/welcome.conf ``` Find the following line: ``` AllowOverride None ``` And replace it with the following line: ``` AllowOverride All ``` Next, restart the Apache and PHP-FPM service to apply the changes: ``` systemctl restart php-fpm httpd ``` Now, open your web browser and access the info.php page using the URL **http://your-server-ip/info.php**. You should see the PHP information on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2022/06/p1-11.png) **Also Read** [Best Practice for Creating a HIPAA-Compliant LAMP Stack](https://www.atlantic.net/hipaa-compliant-hosting/best-practice-for-creating-a-hipaa-compliant-lamp-stack/) ## Conclusion In the above guide, we learned how to install the LAMP stack on Oracle Linux 10. You can now start developing a PHP-based web application and host it using the LAMP stack. Give it a try on your [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Odoo 14 ERP on Oracle Linux 8 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-odoo-14-erp-on-oracle-linux-8/ | Published: 2022-06-03 | Updated: 2023-11-17 | Author: Hitesh Jethva Odoo is an open-source ERP (Enterprise Resource Planning) system used for managing business processes. It comes with a suite of software tools including billing, accounting, eCommerce, CRM, warehouse, project management, and inventory management. Odoo is designed for small and medium businesses and is available in the cloud or on-premise. There are different apps available that can be installed and used to fit your business requirements. Odoo provides a user-friendly, scalable, customizable, and flexible dashboard that helps you manage businesses and organizations via a web browser. In this post, we will show you how to install Odoo 14 in Oracle Linux 8. ## Step 1 – Install Dependencies Before starting, you will need to install some dependencies required to install Odoo. First, install the EPEL repository using the following command: ``` dnf update -y dnf install epel-release -y ``` Once the EPEL is installed, run the following command to install Python and Odoo dependencies: ``` dnf install python3 python3-devel git gcc git redhat-rpm-config libxslt-devel bzip2-devel openldap-devel libjpeg-devel freetype-devel -y ``` Next, install wkhtmltox to render HTML into PDF using the following command: ``` dnf install https://github.com/wkhtmltopdf/wkhtmltopdf/releases/download/0.12.5/wkhtmltox-0.12.5-1.centos8.x86_64.rpm ``` ## Step 2 – Install PostgreSQL Server Odoo uses PostgreSQL as a database backend, so you will need to install it on your server. First, add the PostgreSQL repo using the following command: ``` dnf install https://download.postgresql.org/pub/repos/yum/reporpms/EL-8-x86_64/pgdg-redhat-repo-latest.noarch.rpm ``` Next, disable the default PostgreSQL module and install PostgreSQL 14 using the following command: ``` dnf -qy module disable postgresql dnf install postgresql14 postgresql14-server -y ``` Once the installation is finished, initialized the PostgreSQL database with the following command: ``` /usr/pgsql-14/bin/postgresql-14-setup initdb ``` Next, start the PostgreSQL service and enable it to start at system reboot: ``` systemctl start postgresql-14 systemctl enable postgresql-14 ``` Next, create a user for Odoo with the following command: ``` su - postgres -c "createuser -s odoo14" ``` Also Read [How to Install and Secure PostgreSQL Server on Oracle Linux 8](https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-secure-postgresql-server-on-oracle-linux/) ## Step 3 – Install Odoo 14 It is recommended to add a dedicated odoo user to run the Odoo service. You can add it using the following command: ``` useradd -m -U -r -d /opt/odoo14 -s /bin/bash odoo14 ``` Next, log in with the odoo user and download the Odoo version 14 using the following command: ``` su - odoo14 git clone https://www.github.com/odoo/odoo --depth 1 --branch 14.0 /opt/odoo14/odoo ``` Next, change the directory to /opt/odoo14 and create a Python virtual environment: ``` cd /opt/odoo14 python3 -m venv odooenv ``` Next, activate the virtual environment: ``` source odooenv/bin/activate ``` Next, install the required dependencies using the following command: ``` pip3 install --upgrade pip export PATH=/usr/pgsql-14/bin/:$PATH pip3 install -r odoo/requirements.txt ``` Next, deactivate the virtual environment with the following command: ``` deactivate ``` Next, create an addons directory and exit from the odoo user with the following command: ``` mkdir /opt/odoo14/odoo-custom-addons exit ``` Next, create an Odoo configuration file using the following command: ``` nano /etc/odoo14.conf ``` Add the following lines: ``` [options] admin_passwd = odoomasterpassword db_host = False db_port = False db_user = odoo14 db_password = False addons_path = /opt/odoo14/odoo/addons, /opt/odoo14/odoo-custom-addons ``` Save and close the file. ## Step 4 – Create an Odoo Systemd Service File Next, you will need to create a systemd service file to manage the Odoo service. You can create it using the following command: ``` nano /etc/systemd/system/odoo.service ``` Add the following lines: ``` [Unit] Description=Odoo14 Requires=postgresql-14.service After=network.target postgresql-14.service [Service] Type=simple SyslogIdentifier=odoo14 PermissionsStartOnly=true User=odoo14 Group=odoo14 ExecStart=/opt/odoo14/odooenv/bin/python3 /opt/odoo14/odoo/odoo-bin -c /etc/odoo14.conf StandardOutput=journal+console [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the enable the Odoo service using the following command: ``` systemctl enable --now odoo ``` You can check the status of the Odoo service using the following command: ``` systemctl status odoo ``` Sample output: ``` ● odoo.service Loaded: loaded (/etc/systemd/system/odoo.service; enabled; vendor preset: disabled) Active: active (running) since Thu 2022-05-19 01:14:24 EDT; 7s ago Main PID: 23674 (python3) Tasks: 4 (limit: 23694) Memory: 61.6M CGroup: /system.slice/odoo.service └─23674 /opt/odoo14/odooenv/bin/python3 /opt/odoo14/odoo/odoo-bin -c /etc/odoo14.conf May 19 01:14:24 oraclelinux systemd[1]: Started odoo.service. May 19 01:14:25 oraclelinux odoo14[23674]: /opt/odoo14/odooenv/lib64/python3.6/site-packages/psycopg2/__init__.py:144: UserWarning: The psyco> May 19 01:14:25 oraclelinux odoo14[23674]: """) May 19 01:14:25 oraclelinux odoo14[23674]: 2022-05-19 05:14:25,570 23674 INFO ? odoo: Odoo version 14.0 May 19 01:14:25 oraclelinux odoo14[23674]: 2022-05-19 05:14:25,571 23674 INFO ? odoo: Using configuration file at /etc/odoo14.conf May 19 01:14:25 oraclelinux odoo14[23674]: 2022-05-19 05:14:25,571 23674 INFO ? odoo: addons paths: ['/opt/odoo14/odoo/odoo/addons', '/opt/od> May 19 01:14:25 oraclelinux odoo14[23674]: 2022-05-19 05:14:25,571 23674 INFO ? odoo: database: odoo14@default:default May 19 01:14:25 oraclelinux odoo14[23674]: 2022-05-19 05:14:25,856 23674 INFO ? odoo.addons.base.models.ir_actions_report: Will use the Wkhtm> May 19 01:14:26 oraclelinux odoo14[23674]: 2022-05-19 05:14:26,253 23674 INFO ? odoo.service.server: HTTP service (werkzeug) running on oracl> ``` Also Read [How to Backup and Restore PostgreSQL in Linux](https://www.atlantic.net/vps-hosting/how-to-backup-and-restore-database-in-postgresql/) ## Step 5 – Configure Firewall If you are using firewalld, then you will need to allow Odoo port 8069 through the firewall. You can allow this using the following command: ``` firewall-cmd --permanent --add-port=8069 ``` Next, reload firewalld to apply the changes: ``` firewall-cmd --reload ``` ## Step 6 – Access Odoo 14 Web UI At this point, Odoo 14 is started and listening on port 8069. You can check the Odoo listening port using the following command: ``` ss -antpl | grep 8069 ``` Sample output: ``` LISTEN 0 128 0.0.0.0:8069 0.0.0.0:* users:(("python3",pid=23674,fd=3)) ``` You can now access the Odoo 14 web interface using the URL **http://your-server-ip:8069**. You should see the following page: ![Odoo 14 database page](https://www.atlantic.net/wp-content/uploads/2022/05/p1-8-1024x614.png) Provide your master admin password, email, and password, and click on the “**Create database**” button. You will be redirected to the Odoo15 dashboard as shown below: ![Odoo 14 dashboard page](https://www.atlantic.net/wp-content/uploads/2022/05/p2-7-1024x501.png) ## Conclusion In this post, we explained how to install Odoo 14 on Oracle Linux 8. You can now host Odoo in your organization and start managing your business using the Odoo ERP. Get started on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install Laravel PHP Framework on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-laravel-php-framework-on-oracle-linux-10/ | Published: 2022-06-04 | Updated: 2025-12-31 | Author: Hitesh Jethva Laravel is a free and open-source PHP framework designed for easy website development. It uses various Symfony components to make PHP web development easier. Laravel is a web application framework with expressive, elegant syntax to take the pain out of web development by simplifying some common tasks including authentication, routing, sessions, and caching. Laravel is robust, easy to understand, and provides a set of tools and resources to build modern PHP applications. In this post, we will show you how to install Laravel PHP Framework on Oracle Linux 10. ## Step 1 – Install LEMP Stack Before starting, you will need to install the LAMP server on your server. First, install Nginx and MariaDB server with the following command: ``` dnf update -y ``` ``` dnf install nginx mariadb-server -y ``` Next, install PHP 8 with all required extensions using the following command: ``` dnf install php php-fpm php-common php-xml php-mbstring php-json php-zip php-mysqlnd curl unzip -y ``` Once all the packages are installed, start and enable the Nginx, MariaDB, and PHP-FPM services using the following command: ``` systemctl start php-fpm nginx mariadb systemctl enable php-fpm nginx mariadb ``` Next, you will need to edit the PHP-FPM configuration file and change the user and group from apache to Nginx. ``` nano /etc/php-fpm.d/www.conf ``` Change the following lines: ``` listen.owner = nginx listen.group = nginx ``` Save and close the file, then edit the php.ini file: ``` nano /etc/php.ini ``` Change the following lines: ``` date.timezone = UTC cgi.fix_pathinfo=1 ``` Save and close the file, then restart the PHP-FPM service to apply the changes. ``` systemctl restart php-fpm ``` Also Read [How to Install LEMP Server on Oracle Linux 8](https://www.atlantic.net/vps-hosting/how-to-install-lemp-server-on-oracle-linux-8/) ## Step 2 – Install PHP Composer Composer is a dependency manager for PHP used to install various PHP dependencies required for your project. You can install it using the following command: ``` curl -sS https://getcomposer.org/installer | php ``` You should get the following output: ``` All settings correct for using Composer Downloading... Composer (version 2.9.5) successfully installed to: /root/opencart/composer.phar Use it: php composer.phar ``` Next, move the downloaded binary to the system path and set proper permissions: ``` mv composer.phar /usr/local/bin/composer chmod +x /usr/local/bin/composer ``` Now, verify the Composer version with the following command: ``` composer --version ``` You should get the following output: ``` Composer version 2.9.5 2022-04-13 16:43:00 ``` Also Read [How to Install and Use Composer in Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-composer-on-ubuntu-20-04/) ## Step 3 – Install Laravel Framework on Oracle Linux 10 First, navigate to the Nginx web root directory and download the latest version of Laravel using the following command: ``` cd /var/www/html/ composer create-project --prefer-dist laravel/laravel laravelsite ``` You should get the following output: ``` > @php artisan package:discover --ansi Discovered Package: laravel/sail Discovered Package: laravel/sanctum Discovered Package: laravel/tinker Discovered Package: nesbot/carbon Discovered Package: nunomaduro/collision Discovered Package: spatie/laravel-ignition Package manifest generated successfully. 78 packages you are using are looking for funding. Use the `composer fund` command to find out more! > @php artisan vendor:publish --tag=laravel-assets --ansi --force No publishable resources for tag [laravel-assets]. Publishing complete. > @php artisan key:generate --ansi Application key set successfully. ``` Next, set proper permissions and ownership to laravel directories: ``` chown -R nginx:nginx /var/www/html/laravelsite chown -R nginx:nginx /var/www/html/laravelsite/storage/ chown -R nginx:nginx /var/www/html/laravelsite/bootstrap/cache/ chmod -R 0777 /var/www/html/laravelsite chmod -R 0777 /var/www/html/laravelsite/storage/ chmod -R 0775 /var/www/html/laravelsite/bootstrap/cache/ ``` ## Step 4 – Create an Nginx Virtual Host for Laravel Now, you will need to create an Nginx virtual host configuration file to host Laravel on the internet. You can create it using the following command: ``` nano /etc/nginx/conf.d/laravel.conf ``` Add the following lines: ``` server { listen 80; server_name laravel.example.com; root /var/www/html/laravelsite/public; index index.php index.html; charset utf-8; # ========================= # DEBUG LOGGING # ========================= error_log /var/log/nginx/laravel_debug.log debug; access_log /var/log/nginx/laravel_access.log; # ========================= # GZIP # ========================= gzip on; gzip_types text/plain text/css application/json application/javascript text/javascript application/x-javascript image/svg+xml application/xml text/xml; # ========================= # LARAVEL ROUTING # ========================= location / { try_files $uri $uri/ /index.php?$query_string; } # ========================= # PHP-FPM # ========================= location ~ \.php$ { include fastcgi_params; fastcgi_pass unix:/run/php-fpm/www.sock; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; fastcgi_param DOCUMENT_ROOT $realpath_root; fastcgi_buffers 16 16k; fastcgi_buffer_size 32k; } # ========================= # SECURITY # ========================= location ~ /\.(?!well-known).* { deny all; } } ``` Save and close the file, then edit the Nginx configuration file: ``` nano /etc/nginx/nginx.conf ``` Add the following line below http{: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then verify Nginx for any syntax errors using the following command: ``` nginx -t ``` You should get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart both Nginx and PHP-FPM services to apply the changes: ``` systemctl restart php-fpm systemctl restart nginx ``` You can also verify the Nginx status using the following command: ``` systemctl status nginx ``` You should see the following output: ``` ● nginx.service - The nginx HTTP and reverse proxy server Loaded: loaded (/usr/lib/systemd/system/nginx.service; disabled; vendor preset: disabled) Drop-In: /usr/lib/systemd/system/nginx.service.d └─php-fpm.conf Active: active (running) since Wed 2025-12-31 23:07:14 EDT; 6s ago Process: 8451 ExecStart=/usr/sbin/nginx (code=exited, status=0/SUCCESS) Process: 8449 ExecStartPre=/usr/sbin/nginx -t (code=exited, status=0/SUCCESS) Process: 8445 ExecStartPre=/usr/bin/rm -f /run/nginx.pid (code=exited, status=0/SUCCESS) Main PID: 8458 (nginx) Tasks: 3 (limit: 23694) Memory: 5.0M CGroup: /system.slice/nginx.service ├─8458 nginx: master process /usr/sbin/nginx ├─8459 nginx: worker process └─8460 nginx: worker process ``` ## Step 5 – Configure Firewall If firewalld is installed and running on your server, then you will need to allow HTTP and HTTPS service through the firewall. You can allow both services using the following command: ``` firewall-cmd --zone=public --permanent --add-service=http firewall-cmd --zone=public --permanent --add-service=https ``` Next, reload the firewalld to apply the changes: ``` firewall-cmd --reload ``` ## Step 6 – Access Laravel Web Interface You can now access the Laravel dashboard using the URL **http://laravel.example.com**. You will be redirected to the Laravel default screen: ![Laravel dashboard page](https://www.atlantic.net/wp-content/uploads/2022/05/p1-9-1024x588.png) ## Conclusion In this post, we explained how to install Laravel with Nginx on Oracle Linux 10. You can now use the [Laravel](https://www.cloudways.com/blog/laravel-vs-wordpress/) framework to create high-performance and modern PHP web applications. Get started on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install NextCloud on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-nextcloud-on-oracle-linux-10/ | Published: 2022-06-05 | Updated: 2025-12-31 | Author: Hitesh Jethva NextCloud is an open-source, self-hosted cloud storage solution used for creating and using file hosting services. It offers on-premise access and sync service that allows you to sync and share files in a secure way. NextCloud is very similar to other cloud storage solutions such as Dropbox, Google Drive, and One Drive. It provides a client for all major operating systems including Linux, macOS, Windows, iOS, and Android. If you are looking for a free cloud storage solution, then NextCloud is the best option for you. In this post, we will show you how to install NextCloud on Oracle Linux 10. Also Read [Real-World Case Study for HIPAA Storage and Sharing: Nextcloud & HIPAA Compliance](https://www.atlantic.net/hipaa-compliant-hosting/real-world-case-study-for-hipaa-storage-and-sharing-nextcloud-hipaa-compliance/) ## Step 1 – Install LAMP Stack Before starting, you will need to install Apache, MariaDB, and PHP on your server. First, install the Apache and MariaDB server using the following command: ``` dnf install httpd mariadb-server -y ``` Next, install PHP 8 with other extensions using the following command: ``` dnf install php php-fpm php-curl php-gd php-intl php-json php-ldap php-mbstring php-mysqlnd php-xml php-zip php-opcache unzip curl -y ``` After the successful installation, start the Apache, php-fpm, and MariaDB services and enable them to start after the system reboot: ``` systemctl start httpd systemctl enable httpd systemctl start mariadb systemctl enable mariadb systemctl start php-fpm systemctl enable php-fpm ``` Also Read [How to Install LAMP Server on Oracle Linux 8](https://www.atlantic.net/vps-hosting/how-to-install-lamp-stack-on-oracle-linux-8/) ## Step 2 – Configure MariaDB Database for NextCloud NextCloud uses MariaDB or MySQL to store its data, so you will need to create a database and user for NextCloud. First, log in to MariaDB with the following command: ``` mysql -u root -p ``` Once you are logged in, create a database and user with the following command: ``` CREATE DATABASE nextclouddb; CREATE USER 'nextclouduser'@'localhost' IDENTIFIED BY 'securepassword'; ``` Next, grant all the privileges to the NextCloud database using the following command: ``` GRANT ALL PRIVILEGES ON nextclouddb.* TO 'nextclouduser'@'localhost'; ``` Next, flush the privileges and exit from the MariaDB shell using the command below: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install NextCloud At the time of writing this tutorial, the latest version of NextCloud is 24. You can download it from their official download page using the following command: ``` wget https://download.nextcloud.com/server/releases/nextcloud-32.0.3.zip ``` Once the download is completed, extract the downloaded file to the Apache web root directory with the following command: ``` unzip nextcloud-32.0.3.zip -d /var/www/html/ ``` Next, create a data directory for NextCloud with the following command: ``` mkdir -p /var/www/html/nextcloud/data ``` Next, change the ownership of NextCloud directory to Apache: ``` chown -R apache:apache /var/www/html/nextcloud/ ``` ## Step 4 – Configure Apache for NextCloud Next, you will need to create an Apache virtual host configuration file to host NextCloud using the Apache webserver. ``` nano /etc/httpd/conf.d/nextcloud.conf ``` Add the following code: ``` ServerName nextcloud.example.com DocumentRoot /var/www/html/nextcloud ErrorLog /var/log/httpd/nextcloud_error.log CustomLog /var/log/httpd/nextcloud_access.log combined ``` Save the file when you are finished, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` You can check the status of Apache using the following command; ``` systemctl status httpd ``` You should get the following output: ``` ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; vendor preset: disabled) Active: active (running) since Wed 2025-31-18 12:23:29 EDT; 6s ago Docs: man:httpd.service(8) Main PID: 4189 (httpd) Status: "Started, listening on: port 80" Tasks: 213 (limit: 23694) Memory: 26.4M CGroup: /system.slice/httpd.service ├─4189 /usr/sbin/httpd -DFOREGROUND ├─4190 /usr/sbin/httpd -DFOREGROUND ├─4191 /usr/sbin/httpd -DFOREGROUND ├─4192 /usr/sbin/httpd -DFOREGROUND └─4193 /usr/sbin/httpd -DFOREGROUND ``` ## Step 5 – Configure Firewall If firewalld is installed and running on your server, then you will need to allow port 80 through firewall. You can allow it using the following command: ``` firewall-cmd --add-port=80/tcp --zone=public --permanent ``` Next, reload the firewall to apply the changes: ``` firewall-cmd --reload ``` ## Step 6 – Access NextCloud Dashboard To access NextCloud, open your web browser and type the URL **http://nextcloud.example.com**. You should see the following screen: ![NextCloud setup page](https://www.atlantic.net/wp-content/uploads/2022/05/p1-10.png) Provide your administrator account name and password, define your data directory and database credentials, and click on the **Install** button. You will be redirected to the Recommended apps installation login page: ![](https://www.atlantic.net/wp-content/uploads/2022/05/p2-8.png) Click on the **Install recommended apps**. You should see the NextCloud dashboard: ![NextCloud dashboard page](https://www.atlantic.net/wp-content/uploads/2022/05/p3-4-1024x507.png) ## Conclusion In this post, you learned how to install NextCloud on Oracle Linux 10. You can now easily create and share documents, calendars, etc with your friends and family. Get started on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # ATLANTIC.NET Named Winner of the Coveted Global InfoSec Awards during RSA Conference 2022 > URL: https://www.atlantic.net/press-releases/atlantic-net-named-winner-of-the-coveted-global-infosec-awards-during-rsa-conference-2022/ | Published: 2022-06-06 | Author: Editorial Team *Atlantic.Net Wins***Publisher’s Choice Compliance***in 10**th**Annual Global InfoSec Awards at #RSAC 2022*   SAN FRANCISCO (BUSINESSWIRE) JUNE 6, 2022 – Atlantic.Net is proud to have won the Publisher’s Choice Compliance award from Cyber Defense Magazine (CDM), the industry’s leading electronic information security magazine.   “We’re thrilled to receive one of the most prestigious and coveted cybersecurity awards in the world from Cyber Defense Magazine, during their 10th anniversary as an independent cybersecurity news and information provider.  We knew the competition would be tough and with top judges who are leading infosec experts from around the globe, we couldn’t be more pleased,” said Marty Puranik of Atlantic.Net.   “Atlantic.Net embodies three major features we judges look for to become winners: understanding tomorrow’s threats, today, providing a cost-effective solution, and innovating in unexpected ways that can help mitigate cyber risk and get one step ahead of the next breach,” said Gary S. Miliefsky, Publisher of Cyber Defense Magazine.   We’re thrilled to be a member on this coveted group of winners, located here:   [http://www.cyberdefenseawards.com/](http://www.cyberdefenseawards.com/)   Please join us virtually at the #RSAC RSA Conference 2022, [https://www.rsaconference.com/usa](https://www.rsaconference.com/usa) today, as we share our red-carpet experience and proudly display our trophy online at our website, our blog, and our social media channels.   About Atlantic.Net Atlantic.Net is a global cloud services provider with over 25 years of experience serving thousands of developers and small, medium, and large clients in more than one hundred countries. Atlantic.Net specializes in managed and unmanaged Windows, Linux, and FreeBSD server hosting solutions and has served dynamic business clients including Lenovo, Newegg, NASA, and Hilton, among others. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions backed by 24/7/365 support in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. For more information, please visit [https://www.atlantic.net/](https://www.atlantic.net/).   **About the Judging** The judges are CISSP, FMDHS, CEH, certified security professionals who voted based on their independent review of the company submitted materials on the website of each submission including but not limited to data sheets, white papers, product literature and other market variables. CDM has a flexible philosophy to find more innovative players with new and unique technologies, than the one with the most customers or money in the bank. CDM is always asking “What’s Next?” so we are looking for best of breed, next generation InfoSec solutions.   **About Cyber Defense Magazine** Cyber Defense Magazine is the premier source of cyber security news and information for InfoSec professions in business and government. We are managed and published by and for ethical, honest, passionate information security professionals. Our mission is to share cutting-edge knowledge, real-world stories and awards on the best ideas, products and services in the information technology industry.  We deliver electronic magazines every month online for free, and special editions exclusively for the RSA Conferences. CDM is a proud member of the Cyber Defense Media Group. Learn more about us at [https://www.cyberdefensemagazine.com](https://www.cyberdefensemagazine.com) and visit [https://www.cyberdefensetv.com](https://www.cyberdefensetv.com) and [https://www.cyberdefenseradio.com](https://www.cyberdefenseradio.com) to see and hear some of the most informative interviews of many of these winning company executives.  Join a webinar at [https://www.cyberdefensewebinars.com](https://www.cyberdefensewebinars.com) and realize that infosec knowledge is power.    ### Contact: Email: pr@atlantic.net Ph: 321- 206-1371   ***CDM Media Inquiries:***   Contact:                 Irene Noser, Marketing Executive Email:                     [marketing@cyberdefensemagazine.com](mailto:marketing@cyberdefensemagazine.com)  Toll Free (USA):    1-833-844-9468 International:       1-646-586-9545 Website:               [www.cyberdefensemagazine.com](http://www.cyberdefensemagazine.com) --- # How to Install OpenCart on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-opencart-on-oracle-linux-10/ | Published: 2022-06-06 | Updated: 2025-12-31 | Author: Hitesh Jethva OpenCart is a free, open-source, web-based shopping cart e-commerce platform written in PHP. It allows you to [start your own online shop](https://www.hostinger.com/tutorials/how-to-start-an-online-store) to add, manage and sell products online. OpenCart provides an open-source code and enables you to customize it per your requirements. It is a simple, lightweight, user-friendly, and powerful store management program that allows you to manage multiple stores via a web browser. You can easily manage product inventory, orders, affiliates, discounts, product reviews, payment gateways, and more from the central location. If you are looking to host your own online store, then OpenCart is the best choice for you. In this tutorial, we will show you how to install OpenCart on Oracle Linux 10. ## Step 1 – Install LAMP Stack Before starting, a LAMP Stack must be installed on your server. If not installed, you can install it using the following command: ``` dnf install httpd mariadb-server -y ``` After the installation, you will also need to install PHP version 8 and all required extensions. Run the following command to install PHP 8.0 with all required extensions: ``` dnf install php php-fpm php-gd php-ldap php-zip php-odbc php-pear php-xml php-xmlrpc php-mbstring php-mysqlnd php-snmp php-soap curl curl-devel unzip git -y ``` Once PHP is installed with all the required packages, start the Apache and MariaDB services and enable them to start at system reboot: ``` systemctl start httpd php-fpm systemctl enable httpd php-fpm systemctl start mariadb systemctl enable mariadb ``` **Also Read** [How to Install LAMP Server on Oracle Linux 8](https://www.atlantic.net/vps-hosting/how-to-install-lamp-stack-on-oracle-linux-8/) ## Step 2 – Configure a Database for OpenCart OpenCart uses MariaDB as a database backend, so you will need to create a database and user for OpenCart. First, secure the MariaDB installation and set the MariaDB root password using the following command: ``` mysql_secure_installation ``` Answer all the questions as shown below: ``` Enter current password for root (enter for none): Set root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` Next, log in to MariaDB using the following command: ``` mysql -u root -p ``` Once you are connected to MariaDB, create a user and database with the following command: ``` CREATE DATABASE opencart; CREATE USER 'opencart'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the OpenCart database with the following command: ``` GRANT ALL PRIVILEGES ON opencart.* TO 'opencart'@'localhost'; ``` Next, flush the privileges and exit from MariaDB with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download OpenCart Source First, download the latest version of the OpenCart from the GitHub repository using the wget command: ``` wget https://github.com/opencart/opencart/archive/refs/tags/4.1.0.0.zip ``` Once the download is completed, unzip the downloaded file, navigate to the extracted directory and copy the upload directory to the Apache web root directory: ``` unzip 4.1.0.0.zip cd opencart-4.1.0.0 mv upload /var/www/html/opencart ``` Next, copy some sample configuration files using the following command: ``` cp /var/www/html/opencart/config-dist.php /var/www/html/opencart/config.php cp /var/www/html/opencart/admin/config-dist.php /var/www/html/opencart/admin/config.php ``` Next, set proper permissions and ownership using the following command: ``` chown -R apache:apache /var/www/html/opencart chmod -R 777 /var/www/html/opencart ``` ## Step 4 – Create an Apache Virtual Host for OpenCart Next, you will need to create an Apache virtual host configuration file to host OpenCart on the Internet: ``` nano /etc/httpd/conf.d/opencart.conf ``` Add the following lines: ``` ServerAdmin admin@example.com DocumentRoot /var/www/html/opencart/ ServerName opencart.example.com Options FollowSymLinks AllowOverride All Order allow,deny allow from all ErrorLog /var/log/httpd/yourdomain.com-error_log CustomLog /var/log/httpd/yourdomain.com-access_log common ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 5 – Configure Firewall If you are using firewalld, then you will need to allow HTTP and HTTPS services through the firewall. You can allow them using the following command: ``` firewall-cmd --permanent --add-service=http firewall-cmd --permanent --add-service=https ``` Next, reload firewalld to apply the changes: ``` firewall-cmd --reload ``` ## Step 6 – Access OpenCart Dashboard You can now access the OpenCart Web UI using the URL **http://opencart.example.com/install**. You should see the following page: ![OpenCart License page](https://www.atlantic.net/wp-content/uploads/2022/05/p1-11-1024x471.png) Accept the license agreement and click on the **Continue** button. You should see the following page: ![OpenCart Pre-requisites page](https://www.atlantic.net/wp-content/uploads/2022/05/p2-9-1024x543.png) Make sure all PHP extensions are installed then click on the **Continue** button. You should see the following page: ![OpenCart database configuration page](https://www.atlantic.net/wp-content/uploads/2022/05/p3-5-1024x444.png) ![OpenCart admin configuration page](https://www.atlantic.net/wp-content/uploads/2022/05/p4-4-1024x360.png) Provide your database details, admin username, and password, and click on the **Continue** button. You should see the following page: ![OpenCart installed page](https://www.atlantic.net/wp-content/uploads/2022/05/p5-3-1024x570.png) Now, open your terminal and remove the install directory using the following command: ``` rm -rf /var/www/html/opencart/install ``` Next, go back to the OpenCart web interface and click on **Login to your Administration**. You should see the OpenCart login page: ![OpenCart login page](https://www.atlantic.net/wp-content/uploads/2022/05/p6-2-1024x510.png) Provide your admin username and password and click on the **Login** button. You should see the OpenCart dashboard on the following page: ![OpenCart dashboard page](https://www.atlantic.net/wp-content/uploads/2022/05/p7-1024x509.png) ## Conclusion In this post, we explained how to install the OpenCart shopping cart platform on Oracle Linux 10. Your OpenCart platform is now ready to use. You can now start your own online store using OpenCart. Get started on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # ATLANTIC.NET Wins 2022 Fortress Cyber Security Award > URL: https://www.atlantic.net/press-releases/atlantic-net-wins-2022-fortress-cyber-security-award/ | Published: 2022-06-07 | Updated: 2024-06-11 | Author: Editorial Team ORLANDO, FLORIDA—June 7, 2022—The Business Intelligence Group awarded Atlantic.Net with a 2022 Fortress Cyber Security Award in the compliance category for its HIPAA Compliant Hosting product offering. The industry awards program identifies and rewards the world’s leading companies and products that are working to keep our data and electronic assets safe among a growing threat from hackers. Atlantic.Net’s HIPAA Compliant Hosting is SOC 2 and SOC 3 certified, HIPAA and HITECH audited and designed to secure and protect critical health data, electronic protected health information (ePHI), and records. “Atlantic.Net continues to offer an exceptional product as we maintain our leadership in the HIPAA compliance cloud services,” said Marty Puranik, Founder, and CEO of Atlantic.Net. “We are pleased to be recognized by this prestigious award and look forward to continued growth for many years to come!” “We are so proud to name Atlantic.Net as a winner in the 2021 Fortress Cyber Security Awards program,” said Maria Jimenez, Chief Nominations Officer, Business Intelligence Group. “As our society continues to evolve and become more reliant on networks and data, companies like Atlantic.Net are critical at providing the protection and trust consumers demand.” For information about Atlantic.Net HIPAA hosting solutions, please visit [https://www.atlantic.net/hipaa-compliant-hosting/](https://www.atlantic.net/hipaa-compliant-hosting/). For information about the annual Fortress Cyber Security Awards, please visit [https://www.bintelligence.com/fortress-cyber-security-awards](https://www.bintelligence.com/fortress-cyber-security-awards). About Atlantic.Net [Atlantic.Net](https://www.atlantic.net/) Atlantic.Net is a global cloud services provider with over 25 years of experience, specializing in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions, backed by 24/7/365 support through their global data centers located in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. About Business Intelligence Group [www.bintelligence.com](http://www.bintelligence.com/) The Business Intelligence Group was founded with the mission of recognizing true talent and superior performance in the business world. Unlike other industry award programs, these programs are judged by business executives having experience and knowledge. The organization’s proprietary and unique scoring system selectively measures performance across multiple business domains and rewards those companies whose achievements stand above those of their peers. Contact Maria Jimenez Chief Nominations Officer Business Intelligence Group [contact@fortresswards.com](mailto:contact@fortresswards.com) +1 909.529,2737 Contact Public Relations [pr@atlantic.net](mailto:pr@atlantic.net) +1 321.206.1371 --- # How to Install GitLab CE on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-gitlab-ce-on-oracle-linux-10/ | Published: 2022-06-07 | Updated: 2025-12-31 | Author: Hitesh Jethva GitLab is a free, open-source, web-based DevOps software solution that combines the ability to develop, secure, and operate software in a single application. It is written in Ruby and used by thousands of organizations worldwide. GitLab is a Git repository manager that offers a lot of features including issue tracking, continuous integration, deployment pipeline, and more. It comes in two editions, the Enterprise Edition and the Community Edition. It is very similar to GitHub and allows you to integrate it with various services. You can host your own repository using GitLab in a development environment that allows developers to host their projects. In this post, we will show you how to install the GitLab community edition on Oracle Linux 10. ## Step 1 – Install Postfix Server Before starting, you will need to install the Postfix package to include mail functionality. You can install it using the following command: ``` dnf install postfix ``` After the installation, start the Postfix service and enable it to start at system reboot: ``` systemctl enable --now postfix ``` Also Read [How to Install and Secure PostgreSQL Server](https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-secure-postgresql-server-on-oracle-linux/) ## Step 2 – Add GitLab CE Repository By default, the GitLab package is not included in the Oracle Linux default repo, so you will need to add a repository from the GitLab installation script. First, download the script from the GitLab using the [wget command](https://www.atlantic.net/dedicated-server-hosting/how-to-download-file-using-wget-in-linux/): ``` wget https://packages.gitlab.com/install/repositories/gitlab/gitlab-ce/script.rpm.sh ``` Once the script is downloaded, set execution permissions using the following command: ``` chmod +x script.rpm.sh ``` Next, run the script to add the GitLab CE repository. ``` os=el dist=9 ./script.rpm.sh ``` Once the repository has been created, you should get the following output: ``` Complete! Generating yum cache for gitlab_gitlab-ce... Importing GPG key 0x51312F3F: Userid : "GitLab B.V. (package repository signing key) " Fingerprint: F640 3F65 44A3 8863 DAA0 B6E0 3F01 618A 5131 2F3F From : https://packages.gitlab.com/gitlab/gitlab-ce/gpgkey Importing GPG key 0xF27EAB47: Userid : "GitLab, Inc. " Fingerprint: DBEF 8977 4DDB 9EB3 7D9F C3A0 3CFC F9BA F27E AB47 From : https://packages.gitlab.com/gitlab/gitlab-ce/gpgkey/gitlab-gitlab-ce-3D645A26AB9FBD22.pub.gpg Generating yum cache for gitlab_gitlab-ce-source... The repository is setup! You can now install packages. ``` You can now check the repository using the following command: ``` dnf repolist ``` You should see the GitLab repository in the following output: ``` repo id repo name gitlab_gitlab-ce gitlab_gitlab-ce gitlab_gitlab-ce-source gitlab_gitlab-ce-source pgdg-common PostgreSQL common RPMs for RHEL / Oracle 10 - x86_64 ``` ## Step 3 – Install GitLab CE on Oracle Linux 10 At this point, the GitLab CE repo is added to the server. You can now install GitLab CE using the following command: ``` dnf install gitlab-ce -y ``` Once GitLab has been installed, you should get the following output: ``` It looks like GitLab has not been configured yet; skipping the upgrade script. *. *. *** *** ***** ***** .****** ******* ******** ******** ,,,,,,,,,***********,,,,,,,,, ,,,,,,,,,,,*********,,,,,,,,,,, .,,,,,,,,,,,*******,,,,,,,,,,,, ,,,,,,,,,*****,,,,,,,,,. ,,,,,,,****,,,,,, .,,,***,,,, ,*,. _______ __ __ __ / ____(_) /_/ / ____ _/ /_ / / __/ / __/ / / __ `/ __ \ / /_/ / / /_/ /___/ /_/ / /_/ / \____/_/\__/_____/\__,_/_.___/ Thank you for installing GitLab! GitLab was unable to detect a valid hostname for your instance. Please configure a URL for your GitLab instance by setting `external_url` configuration in /etc/gitlab/gitlab.rb file. Then, you can start your GitLab instance by running the following command: sudo gitlab-ctl reconfigure For a comprehensive list of configuration options please see the Omnibus GitLab readme https://gitlab.com/gitlab-org/omnibus-gitlab/blob/master/README.md ``` ## Step 4 – Configure GitLab CE GitLab is now installed on your system, but it is not configured yet. You can configure it by editing **/etc/gitlab/gitlab.rb** file: ``` nano /etc/gitlab/gitlab.rb ``` Define your external UR and email address and enable Let’s Encrypt as shown below: ``` external_url "https://gitlab.linuxbuz.com" # Enable the Let's encrypt SSL letsencrypt['enable'] = true # This is optional to get SSL related alerts letsencrypt['contact_emails'] = ['hitjethva@gmail.com'] # This example renews every 7th day at 12:30 letsencrypt['auto_renew_hour'] = "12" letsencrypt['auto_renew_minute'] = "30" letsencrypt['auto_renew_day_of_month'] = "*/7" ``` Save and close the file, then run the following command to configure GitLab. ``` gitlab-ctl reconfigure ``` Once the configuration has been completed, you should get the following output: ``` Default admin account has been configured with following details: Username: root Password: You didn't opt-in to print initial root password to STDOUT. Password stored to /etc/gitlab/initial_root_password. This file will be cleaned up in first reconfigure run after 24 hours. NOTE: Because these credentials might be present in your log files in plain text, it is highly recommended to reset the password following https://docs.gitlab.com/ee/security/reset_user_password.html#reset-your-root-password. gitlab Reconfigured! ``` The above command will configure GitLab and store the access credentials in the **/etc/gitlab/initial_root_password** file. You can check the access password using the following command: ``` cat /etc/gitlab/initial_root_password ``` You should get the following output: ``` Password: Uzpeo6P8eYZQE5D0hMtCAC2xH9rCjTsx1E9iYvGQMuw= ``` ## Step 5 – Access GitLab CE Dashboard Now, open your web browser and access the GitLab CE web UI using the URL **https://gitlab.linuxbuz.com**. You will be redirected to the GitLab login page: ![GitLab login page](https://www.atlantic.net/wp-content/uploads/2022/05/p1-12-1024x510.png) Provide your root username and password and click on the **Sign in** button. You should see the GitLab dashboard on the following page: ![GitLab dashboard page](https://www.atlantic.net/wp-content/uploads/2022/05/p2-10-1024x376.png) ## Step 6 – Backup GitLab It is a good idea to back up your GitLab instance regularly. To back up the GitLab instance, run the following command: ``` gitlab-rake gitlab:backup:create ``` It is also a good idea to make your backups automatic. You can do it by creating a cron job. ``` nano /etc/crontab ``` Add the following line: ``` 0 22 * * * gitlab-rake gitlab:backup:create ``` Save and close the file when you are finished. ## Conclusion In this guide, we learned how to install GitLab CE on Oracle Linux 10. We also learned how to edit the GitLab CE and enable the Let’s Encrypt SSL. Your GitLab instance is now installed and secured. You can now start using GitLab in a local development environment to track all projects. Get started on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Install Apache Maven on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-apache-maven-on-oracle-linux-10/ | Published: 2022-06-08 | Updated: 2025-12-30 | Author: Hitesh Jethva Apache Maven is a free, open-source, POM-based Java project management tool. It is written in Java and used to build projects written in C#, Scala, Ruby, etc. Apache Maven is designed for Java developers to help them to develop reports, check, build and test automation setups. The tool was developed by the Apache Group to build, publish, and deploy multiple Java projects at once for better performance. Apache Maven uses XML files to define configuration details, project dependencies, and other data. **Features** - Dependency management - Large repository - Extensible via plug-ins - Model-based builds - Release management and distribution publication - Backward compatibility - Easy to test, deploy and manage upgrades In this post, we will show you how to install Apache Maven on OracleLinux 10. ## Step 1 – Install Maven via AppStream Repository By default, the Apache Maven package is included in the OracleLinux AppStream repository. You can check it using the following command: ``` dnf info maven ``` You should get the following output: ``` Last metadata expiration check: 0:25:44 ago on Tue 30 Dec 2025 11:22:04 PM EST. Available Packages Name : maven Epoch : 1 Version : 3.9.9 Release : 3.el10_1 Architecture : noarch Size : 47 k Source : maven-3.9.9-3.el10_1.src.rpm Repository : ol10_appstream Summary : Java project management and project comprehension tool URL : https://maven.apache.org/ License : Apache-2.0 AND MIT Description : Maven is a software project management and comprehension tool. Based on the : concept of a project object model (POM), Maven can manage a project's build, : reporting and documentation from a central piece of information. ``` Now, install Apache Maven using the following command: ``` dnf install maven -y ``` After the installation, verify the Maven version using the following command: ``` mvn --version ``` You should get the following output: ``` Apache Maven 3.9.9 (Red Hat 3.9.9-3) Maven home: /usr/share/maven Java version: 25.0.1, vendor: Oracle Corporation, runtime: /opt/jdk-25.0.1 Default locale: en_US, platform encoding: UTF-8 OS name: "linux", version: "6.12.0-101.33.4.3.el10uek.x86_64", arch: "amd64", family: "unix" ``` ## Step 2 – Install Maven From Source It is a good idea to install Apache Maven from the source if you want to install the latest version of Maven. Apache Maven is Java-based software. so you will need to install OpenJDK on your system. Run the following command to [install Java](https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-manage-java-versions-on-oracle-linux/) on your server. ``` dnf install java-21-openjdk -y ``` After the successful installation, verify the Java version using the following command: ``` java --version ``` Sample output: ``` openjdk 21.0.9 2025-10-21 LTS OpenJDK Runtime Environment (Red_Hat-21.0.9.0.10-1.0.1) (build 21.0.9+10-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.9.0.10-1.0.1) (build 21.0.9+10-LTS, mixed mode, sharing) ``` Next, go to the Apache Maven download page and download the latest version of Maven using the [wget command](https://www.atlantic.net/dedicated-server-hosting/how-to-download-file-using-wget-in-linux/): ``` wget https://dlcdn.apache.org/maven/maven-3/3.9.12/binaries/apache-maven-3.9.12-bin.tar.gz ``` Next, create a directory for Apache Maven with the following command: ``` mkdir /usr/local/maven ``` Next, extract the downloaded file to the Maven directory with the following command: ``` tar xzf apache-maven-3.9.12-bin.tar.gz -C /usr/local/maven/ --strip-components=1 ``` Next, you will need to add the Maven binary location to the system path. You can add it with the following command: ``` echo export 'PATH=$PATH:/usr/local/maven/bin/' > /etc/profile.d/maven.sh echo 'export JAVA_HOME=/usr/lib/jvm/java-21-openjdk' >> /etc/profile.d/maven.sh ``` Next, set proper permissions to the maven.sh file with the following command: ``` chmod +x /etc/profile.d/maven.sh ``` Next, activate the Maven system path with the following command: ``` source /etc/profile.d/maven.sh ``` Next, verify the Maven version using the following command: ``` mvn --version ``` You should get the following output: ``` Apache Maven 3.9.12 (848fbb4bf2d427b72bdb2471c22fced7ebd9a7a1) Maven home: /usr/local/maven Java version: 21.0.9, vendor: Red Hat, Inc., runtime: /usr/lib/jvm/java-21-openjdk Default locale: en_US, platform encoding: UTF-8 OS name: "linux", version: "6.12.0-101.33.4.3.el10uek.x86_64", arch: "amd64", family: "unix" ``` ## Conclusion In the above guide, we explained two methods to install Apache Maven on OracleLinux 10. You can now start using Apache Maven to manage your Java project. Get started on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Install Node.js and NPM on Oracle Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-node-js-and-npm-on-oracle-linux/ | Published: 2022-06-15 | Updated: 2025-12-30 | Author: Hitesh Jethva Node.js is a free and open-source JavaScript library that is used to build scalable network applications. It is built on Chrome’s V8 JavaScript engine and allows you to develop complex and very scalable web applications easily. Node.js is designed for the back-end application. However, you can also use it as a full-stack and front-end solution. It is cross-platform and runs on different platforms including Windows, Linux, Unix, and Mac OS X. It is simple, lightweight, and supports a non-blocking I/O model and event-driven architecture. In this post, we will show you how to install Node.js and NPM on Oracle Linux 10. ## Step 1 – Install Node.js Using Oracle Linux Repository By default, Node.js is included in the Oracle Linux default repository. You can install the Node.js by running the following command: ``` dnf install nodejs -y ``` Once Node.js is installed, you can verify the Node.js version using the following command: ``` node --version ``` You will get the following output: ``` v22.19.0 ``` To verify the NPM version, run the following command: ``` npm -v ``` Sample output: ``` 10.9.3 ``` ## Step 2 – Install Node.js From NodeSource Repository By default, the latest version of Node.js is not available in the Oracle Linux 10 default repo, so you can use the NodeSource repository to install the latest version of Node.js. First, install the curl command utility with the following command: ``` dnf install curl -y ``` Next, add the NodeSource repository for version 24 using the following command: ``` curl -sL https://rpm.nodesource.com/setup_24.x | bash - ``` To install the latest Node.js version, run the following command: ``` dnf install nodejs ``` After the installation, verify the Node.js version with the following command: ``` node -v ``` You should see the following output: ``` v24.12.0 ``` To verify the NPM version, run the following command: ``` npm -v ``` You should see the following output: ``` 11.6.2 ``` ## Step 3 – Install Node.js Using NVM NVM stands for Node Version Manager, which provides an easy way to install and manage multiple Node.js versions in the same system. To install NVM, run the following command: ``` curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/master/install.sh | bash ``` This command will install NVM to your system and add the NVM path to the .bashrc file. Next, activate the NVM system path using the following command: ``` source ~/.bashrc ``` You can now verify the NVM version using the following command: ``` nvm --version ``` You should see the following output: ``` 0.40.3 ``` To install the latest Node.js version, run the following command: ``` nvm install node ``` You should see the following output: ``` Downloading and installing node v25.2.1... Downloading https://nodejs.org/dist/v25.2.1/node-v25.2.1-linux-x64.tar.xz... ################################################################################################################################################################################# 100.0% Computing checksum with sha256sum Checksums matched! Now using node v25.2.1 (npm v11.6.2) Creating default alias: default -> node (-> v25.2.1) ``` To install the latest stable Node.js version, run the following command: ``` nvm install --lts ``` You should see the following output: ``` Installing latest LTS version. Downloading and installing node v24.12.0... Downloading https://nodejs.org/dist/v24.12.0/node-v24.12.0-linux-x64.tar.xz... ################################################################################################################################################################################# 100.0% Computing checksum with sha256sum Checksums matched! Now using node v24.12.0 (npm v11.6.2) ``` To list all Node.js versions installed in your system, run the following command: ``` nvm ls ``` You should see the following output: ``` -> v24.12.0 v25.2.1 default -> node (-> v25.2.1) ``` To set the default Node.js version, run the following command: ``` nvm use v24.12.0 ``` You should see the following output: ``` Now using node v24.12.0 (npm v11.6.2) ``` ## Conclusion This guide taught us how to install Node.js using three different ways on Oracle Linux 10. You can now choose your preferred method to install the Node.js on Oracle Linux 10. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Secure MongoDB on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-secure-mongodb-on-oracle-linux-10/ | Published: 2022-06-16 | Updated: 2025-12-30 | Author: Hitesh Jethva Open-source MongoDB is the most popular document-oriented database management system. It is cross-platform and uses JSON-like documents with optional schemas. MongoDB is written in C++ and is used for developing mission-critical and modern dynamic applications. The data objects are stored as separate documents in a collection in the MongoDB database versus in a traditional relational database system, where rows and columns are used. It also offers an easy querying and indexing functionality that allows developers to query complex document-based data sets easily. In this post, we will explain how to install and use MongoDB on Oracle Linux 10. ## Step 1 – Create Atlantic.Net Cloud Server First, log in to your [Atlantic.Net Cloud Server](https://cloud.atlantic.net/?page=userlogin). Create a new [server](https://www.atlantic.net/vps-hosting/how-to-create-new-atlantic-net-cloud-server/), choosing Oracle Linux 10 as the operating system with at least 2GB RAM. Connect to your Cloud Server via SSH and log in using the credentials highlighted at the top of the page. Once you are logged in to your server, run the following command to update your base system with the latest available packages. ``` dnf update -y ``` ## Step 2 – Install MongoDB By default, the MongoDB package is not included in the Oracle Linux 10 default repo, so you will need to create a MongoDB repo in your system. You can create it using the following command: ``` nano /etc/yum.repos.d/mongodb.repo ``` Add the following lines: ``` [mongodb-org-7.0] name=MongoDB Repository baseurl=https://repo.mongodb.org/yum/redhat/9/mongodb-org/7.0/x86_64/ enabled=1 gpgcheck=0 repo_gpgcheck=0 ``` Save and close the file, then install the MongoDB package using the following command: ``` dnf install mongodb-org ``` After the installation, start and enable the MongoDB service with the following command: ``` systemctl start mongod systemctl enable mongod ``` You can check the status of MongoDB using the following command: ``` systemctl status mongod ``` Sample output: ``` ● mongod.service - MongoDB Database Server Loaded: loaded (/usr/lib/systemd/system/mongod.service; enabled; preset: disabled) Active: active (running) since Tue 2025-12-30 22:50:17 EST; 3s ago Invocation: afbc54a6545d4bfba19fcc7fe0d44c26 Docs: https://docs.mongodb.org/manual Main PID: 182814 (mongod) Memory: 133.9M (peak: 134M) CPU: 796ms CGroup: /system.slice/mongod.service └─182814 /usr/bin/mongod -f /etc/mongod.conf Dec 30 22:50:17 oracle systemd[1]: Started mongod.service - MongoDB Database Server. Dec 30 22:50:17 oracle mongod[182814]: {"t":{"$date":"2025-12-31T03:50:17.749Z"},"s":"I", "c":"CONTROL", "id":7484500, "ctx":"main","msg":"Environment variable MONGODB_CONFIG_OVERRI> ``` Now, verify the MongoDB version using the following command: ``` mongod --version ``` Sample output: ``` db version v7.0.28 Build Info: { "version": "7.0.28", "gitVersion": "cfc346c59d2cc3dbc903507fc642e22e3097f362", "openSSLVersion": "OpenSSL 3.5.1 1 Jul 2025", "modules": [], "allocator": "tcmalloc", "environment": { "distmod": "rhel90", "distarch": "x86_64", "target_arch": "x86_64" } } ``` ## Step 3 – How to Use MongoDB You can connect to the MongoDB shell using the following command: ``` mongosh ``` After connected, run the following command to list all databases: ``` > db ``` Sample output: ``` test ``` Next, create a new database named admin using the following command: ``` > use admin ``` To create a collection and insert some data, run the following command: ``` > db.linux.insertOne( { "RockyLinux" : "10", "centos" : "9", "debian" : "12" } ) ``` To verify the collection, run: ``` > show collections ``` Sample output: ``` linux ``` To display your data, run: ``` > db.linux.find() ``` Sample output: ``` { "_id" : ObjectId("6165aa323a2df0ac96aa216a"), "RockyLinux" : "10", "centos" : "9", "debian" : "12" } ``` ## Step 4 – Enable MongoDB Authentication By default, MongoDB is connected without login, so it is a good idea to enable authentication in MongoDB. First, log in to MongoDB with the following command: ``` mongosh ``` Next, create a MongoDB admin user and set a password: ``` > use admin > db.createUser( { user: "mongoadmin", pwd: "password", roles: [ { role: "userAdminAnyDatabase", db: "admin" } ] } ) ``` Sample output: ``` Successfully added user: { "user" : "mongoadmin ", "roles" : [ { "role" : "readWrite", "db" : "admin" } ] } ``` To verify your users, run: ``` > db.getUsers() ``` Sample output: ``` [ { "_id" : "admin.mongoadmin ", "userId" : UUID("ba2efd4e-84eb-4000-9d27-c0c337b4d7d8"), "user" : "mongoadmin ", "db" : "admin", "roles" : [ { "role" : "readWrite", "db" : "admin" } ], "mechanisms" : [ "SCRAM-SHA-1", "SCRAM-SHA-256" ] } ] ``` Next, edit the MongoDB configuration file and enable authentication: ``` nano /etc/mongod.conf ``` Add the following line: ``` security: authorization: enabled ``` Save and close the file, then restart the MongoDB service to apply the changes: ``` systemctl restart mongod ``` You can now connect to the MongoDB by specifying a user and password as shown below: ``` mongosh -u mongoadmin -p ``` ## Step 5 – Uninstall MongoDB If you want to remove the MongoDB from your system, first stop the MongoDB service: ``` systemctl stop mongod ``` Next, remove the MongoDB package by running the following command: ``` dnf remove mongodb-org ``` Next, remove the MongoDB logs and data directories by running the following command: ``` rm -rf /var/lib/mongodb ``` ## Conclusion In this guide, we learned how to install and use the MongoDB database on Oracle Linux 10. We also learned how to enable MongoDB authentication and interact with a MongoDB database. You can now easily install and manage the MongoDB databases. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Apache Kafka on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-kafka-on-oracle-linux-10/ | Published: 2022-06-17 | Updated: 2025-12-30 | Author: Hitesh Jethva Apache Kafka is a free, open-source, distributed event streaming platform that is used by thousands of companies for high-performance data pipelines. It is a message broker software application primarily used to build real-time streaming data pipelines and applications. Apache Kafka allows you to process data streams via a distributed streaming platform. It is based on a distributed architecture, so it provides high fault tolerance and scalability capabilities. In this post, we will explain how to install Apache Kafka on Oracle Linux 10. ## Step 1- Install Java Apache Kafka is a Java-based application, so Java must be installed on your server. If not installed, you can install it using the following command: ``` dnf update -y dnf install java-21-openjdk-devel -y ``` Once Java is installed, verify the Java installation using the following command: ``` java --version ``` You will get the Java version in the following output: ``` openjdk 21.0.8 2025-07-15 LTS OpenJDK Runtime Environment (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.8.0.9-1) (build 21.0.8+9-LTS, mixed mode, sharing) ``` ## Step 2 – Install Apache Kafka on Oracle Linux 10 First, go to the Apache official website and download the latest version of Apache Kafka using the wget command: ``` wget https://dlcdn.apache.org/kafka/4.1.1/kafka_2.13-4.1.1.tgz ``` Once the download is completed, extract the downloaded file using the following command: ``` tar -xvzf kafka_2.13-4.1.1.tgz ``` Once the downloaded file is extracted, move the extracted directory to /usr/local directory: ``` mv kafka_2.13-4.1.1 /usr/local/kafka ``` Once you are finished, you can proceed to the next step. ## Step 3 – Configure Kafka First, edit the Kafka server.properties file. ``` nano /usr/local/kafka/config/server.properties ``` Modify the following lines: ``` process.roles=broker,controller node.id=1 controller.listener.names=CONTROLLER listeners=PLAINTEXT://0.0.0.0:9092,CONTROLLER://0.0.0.0:9093 listener.security.protocol.map=CONTROLLER:PLAINTEXT,PLAINTEXT:PLAINTEXT inter.broker.listener.name=PLAINTEXT controller.quorum.voters=1@localhost:9093 log.dirs=/usr/local/kafka/data ``` Next, build the random uuid. ``` /usr/local/kafka/bin/kafka-storage.sh random-uuid ``` Output. ``` SSoviLO8RtmlnOyHEPOcMQ ``` Initialize the storage directory with that UUID. ``` /usr/local/kafka/bin/kafka-storage.sh format -t SSoviLO8RtmlnOyHEPOcMQ -c /usr/local/kafka/config/server.properties ``` ## Step 4 – Create Systemd Service File for Kafka For the production environment, it is recommended to create a systemd service file to run both Zookeeper and Kafka in the background. First, create a systemd service file for Kafka using the following command: ``` nano /etc/systemd/system/kafka.service ``` Add the following lines: ``` [Unit] Description=Apache Kafka Server Documentation=http://kafka.apache.org/documentation.html [Service] Type=simple Environment="JAVA_HOME=/usr/lib/jvm/jre-21-openjdk" ExecStart=/usr/bin/bash /usr/local/kafka/bin/kafka-server-start.sh /usr/local/kafka/config/server.properties ExecStop=/usr/bin/bash /usr/local/kafka/bin/kafka-server-stop.sh [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the Kafka service and enable it to start at system reboot: ``` systemctl start kafka systemctl enable kafka ``` You can also check Kafka using the following command: ``` systemctl status kafka ``` You will get the following output: ``` ● kafka.service - Apache Kafka Server Loaded: loaded (/etc/systemd/system/kafka.service; disabled; preset: disabled) Active: active (running) since Tue 2025-12-30 22:31:17 EST; 4s ago Invocation: 69b9ca646b9d4a7da680eb793647a8e2 Docs: http://kafka.apache.org/documentation.html Main PID: 178425 (java) Tasks: 104 (limit: 24812) Memory: 366.4M (peak: 366.7M) CPU: 6.684s CGroup: /system.slice/kafka.service └─178425 /usr/lib/jvm/jre-21-openjdk/bin/java -Xmx1G -Xms1G -server -XX:+UseG1GC -XX:MaxGCPauseMillis=20 -XX:InitiatingHeapOccupancyPercent=35 -XX:+ExplicitGCInvokesConcu> Dec 30 22:31:22 oracle bash[178425]: [2025-12-30 22:31:22,219] INFO Awaiting socket connections on 0.0.0.0:9092. (kafka.network.DataPlaneAcceptor) Dec 30 22:31:22 oracle bash[178425]: [2025-12-30 22:31:22,239] INFO [BrokerServer id=1] Waiting for all of the authorizer futures to be completed (kafka.server.BrokerServer) Dec 30 22:31:22 oracle bash[178425]: [2025-12-30 22:31:22,239] INFO [BrokerServer id=1] Finished waiting for all of the authorizer futures to be completed (kafka.server.BrokerServer) Dec 30 22:31:22 oracle bash[178425]: [2025-12-30 22:31:22,240] INFO [BrokerServer id=1] Waiting for all of the SocketServer Acceptors to be started (kafka.server.BrokerServer) Dec 30 22:31:22 oracle bash[178425]: [2025-12-30 22:31:22,240] INFO [BrokerServer id=1] Finished waiting for all of the SocketServer Acceptors to be started (kafka.server.BrokerServer) Dec 30 22:31:22 oracle bash[178425]: [2025-12-30 22:31:22,240] INFO [BrokerServer id=1] Transition from STARTING to STARTED (kafka.server.BrokerServer) Dec 30 22:31:22 oracle bash[178425]: [2025-12-30 22:31:22,241] INFO Kafka version: 4.1.1 (org.apache.kafka.common.utils.AppInfoParser) Dec 30 22:31:22 oracle bash[178425]: [2025-12-30 22:31:22,241] INFO Kafka commitId: be816b82d25370ce (org.apache.kafka.common.utils.AppInfoParser) Dec 30 22:31:22 oracle bash[178425]: [2025-12-30 22:31:22,244] INFO Kafka startTimeMs: 1767151882240 (org.apache.kafka.common.utils.AppInfoParser) Dec 30 22:31:22 oracle bash[178425]: [2025-12-30 22:31:22,249] INFO [KafkaRaftServer nodeId=1] Kafka Server started (kafka.server.KafkaRaftServer) ``` ## Step 5 – Create a Topic on Kafka To test Apache Kafka, you will need to create at least one topic on the server. Change the directory to Apache Kafka and create a test topic named topic1 with the following command: ``` cd /usr/local/kafka/ bin/kafka-topics.sh --create --bootstrap-server localhost:9092 --replication-factor 1 --partitions 1 --topic topic1 ``` You can now verify your created topic using the following command: ``` bin/kafka-topics.sh --list --bootstrap-server localhost:9092 ``` You will get the following output: ``` topic1 ``` Kafka provides two APIs: Producer and Consumer. The Producer is responsible for creating events and the Consumer displays them on the screen: First, run the following command to create an event named event1 using the following command: ``` bin/kafka-console-producer.sh --bootstrap-server localhost:9092 --topic event1 ``` Type some text that you want to stream and display on the Consumer. ``` >Hi, this is my first event ``` Sample output: ``` [2025-10-22 07:58:05,318] WARN [Producer clientId=console-producer] Error while fetching metadata with correlation id 3 : {event1=LEADER_NOT_AVAILABLE} (org.apache.kafka.clients.NetworkClient) ``` Open another terminal and run the following command to display the generated event data in real-time: ``` bin/kafka-console-consumer.sh --bootstrap-server localhost:9092 --topic event1 --from-beginning ``` You will get the following output: ``` Hi, this is my first event ``` ## Conclusion In the above guide, we explained how to install Apache Kafka on Oracle Linux 10. You can now integrate Apache Kafka with your application to collect and analyze a large amount of data. For more information, you can visit the Apache Kafka [documentation](https://kafka.apache.org/) page. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Webmin on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-webmin-on-oracle-linux-10/ | Published: 2022-06-18 | Updated: 2025-12-30 | Author: Hitesh Jethva Open-source Webmin is one of the most widely used server control panels for Linux. It allows users to manage a Linux server from a web browser. Any user with basic knowledge can install and configure different services on Linux using Webmin. It can be installed on all major Linux operating systems including Linux, Solaris, FreeBSD, and more. It allows the system admin to perform several tasks using Webmin such as package management, network configuration, and performance monitoring, user account creation, file management, firewall management, and more. In this post, we will show you how to install Webmin on Oracle Linux 10. ## Step 1 – Install Webmin By default, the Webmin package is not available in the Oracle Linux default repository. You will need to install it from the Webmin installation script. First, install the required dependencies using the following command: ``` dnf install wget tar python3 perl -y ``` Once all the dependencies are installed, download the latest version of Webmin with the following command: ``` wget https://www.webmin.com/download/webmin-current.tar.gz ``` Once Webmin is downloaded, extract the downloaded file using the following command: ``` tar xvf webmin-current.tar.gz ``` Next, create an installation directory for Webmin. ``` mkdir -p /usr/local/webmin ``` Next, start the Webmin installation by running the following script: ``` ./webmin-2.610/setup.sh /usr/local/webmin/ ``` During the installation, you will be asked to provide a Webmin port, admin username, and password as shown below: ``` Config file directory [/etc/webmin]: Log file directory [/var/webmin]: *********************************************************************** Webmin is written entirely in Perl. Please enter the full path to the Perl 5 interpreter on your system. Full path to perl (default /usr/bin/perl): Testing Perl ... Perl seems to be installed ok *********************************************************************** Operating system name: Oracle Linux Operating system version: 10 *********************************************************************** Webmin uses its own password protected web server to provide access to the administration programs. The setup script needs to know : - What port to run the web server on. There must not be another web server already using this port. - The login name required to access the web server. - The password required to access the web server. - If the webserver should use SSL (if your system supports it). - Whether to start webmin at boot time. Web server port (default 10000): Login name (default admin): Login password: Password again: Use SSL (y/n): n Start Webmin at boot time (y/n): y *********************************************************************** Webmin has been installed and started successfully. Use your web browser to go to http://oraclelinux:10000/ and login with the name and password you entered previously. ``` At this point, Webmin is installed and listens on port 10000. You can check it with the following command: ``` ss -antpl | grep 10000 ``` You should see the following output: ``` LISTEN 0 128 0.0.0.0:10000 0.0.0.0:* users:(("miniserv.pl",pid=21220,fd=7)) ``` ## Step 2 – Configure Firewall You will also need to allow port 10000 through firewalld. You can allow it using the following command: ``` firewall-cmd --add-port=10000/tcp --permanent ``` Next, reload firewalld to apply the changes: ``` firewall-cmd --reload ``` ## Step 3 – Access Webmin Web Interface Now, open your web browser and access the Webmin web interface using the URL **http://your-server-ip:10000**. You will be redirected to the Webmin login page: ![Webmin login page](https://www.atlantic.net/wp-content/uploads/2022/06/p1-2-1024x547.png) Provide your admin username and password and click on the **Sign in** button. You should see the Webmin dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2022/06/w.png) Click on **Tools** => **Command** **Shell**. You should see the web-based Linux command-line shell: ![Webmin command line interface](https://www.atlantic.net/wp-content/uploads/2022/06/p3-1-1024x502.png) Here, you can execute any command on your Linux server. Click on **Tools** => **File** **Manager**. You should see the Linux file system on the following page: ![Webmin file manager](https://www.atlantic.net/wp-content/uploads/2022/06/p4-1024x505.png) Here, you can create and manage files and directories on your server. Click on **Tools** => **Upload** **and** **Download**. You should see the following page: ![Webmin upload download manager](https://www.atlantic.net/wp-content/uploads/2022/06/p5-1024x501.png) Here, you can upload and download any file to and from the server. Click on **Un-used Modules**. You should see the following page: ![Webmin software manager](https://www.atlantic.net/wp-content/uploads/2022/06/p6-1024x499.png) Here, you can install and remove different packages on your server. If you want to uninstall Webmin from your server, run the following script: ``` bash /etc/webmin/uninstall.sh ``` ## Conclusion Congratulations! You have successfully installed Webmin on Oracle Linux 10. You can now easily manage your Linux server without any command-line knowledge. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure Nginx Webserver on Oracle Linux > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-configure-nginx-webserver-on-oracle-linux/ | Published: 2022-06-19 | Updated: 2025-12-31 | Author: Hitesh Jethva Nginx, pronounced “engine-ex,” is a free and open-source web server used to host websites on the Internet. It is lightweight and high-performance and can be used for reverse proxy, caching, load balancing, media streaming, and more. It is a fast, highly scalable, and highly available web server compared to the Apache web server. It is one of the best web servers in the world. Nginx is the first choice for many websites due to its ability to handle massive connections. In this post, we will show you how to install the latest Nginx Mainline on Oracle Linux 10. ## Step 1 – Add an Nginx Repository By default, the latest Nginx mainline version is not included in the Oracle Linux Appresteam repository. For a production environment, it is always recommended to install the latest version. First, install the dnf-utils package using the following command: ``` dnf update -y dnf install dnf-utils -y ``` Next, create an Nginx repo with the following command: ``` nano /etc/yum.repos.d/nginx.repo ``` Add the following lines: ``` [nginx-stable] name=nginx stable repo baseurl=http://nginx.org/packages/centos/$releasever/$basearch/ gpgcheck=1 enabled=1 gpgkey=https://nginx.org/keys/nginx_signing.key module_hotfixes=true [nginx-mainline] name=nginx mainline repo baseurl=http://nginx.org/packages/mainline/centos/$releasever/$basearch/ gpgcheck=1 enabled=0 gpgkey=https://nginx.org/keys/nginx_signing.key module_hotfixes=true ``` Save and close the file, then enable the Nginx Mainline repo using the following command: ``` yum-config-manager --enable nginx-mainline ``` ## Step 2 – Install Nginx Mainline on Oracle Linux10 Now, install the latest Nginx Mainline package by running the following command: ``` dnf install nginx ``` After Nginx is successfully installed, start the Nginx service and enable it to start at system reboot: ``` systemctl start nginx systemctl enable nginx ``` Next, verify the status of Nginx with the following command: ``` systemctl status nginx ``` You should get the following output: ``` ● nginx.service - nginx - high performance web server Loaded: loaded (/usr/lib/systemd/system/nginx.service; disabled; preset: disabled) Drop-In: /etc/systemd/system/nginx.service.d └─php-fpm.conf Active: active (running) since Tue 2025-12-30 22:10:18 EST; 10s ago Invocation: 73b5a705724d47e5889a694f0d61d697 Docs: http://nginx.org/en/docs/ Process: 174344 ExecStart=/usr/sbin/nginx -c ${conffile} (code=exited, status=0/SUCCESS) Main PID: 174345 (nginx) Tasks: 3 (limit: 24812) Memory: 3.2M (peak: 3.3M) CPU: 16ms CGroup: /system.slice/nginx.service ├─174345 "nginx: master process /usr/sbin/nginx -c /etc/nginx/nginx.conf" ├─174346 "nginx: worker process" └─174347 "nginx: worker process" Dec 30 22:10:18 oracle systemd[1]: Starting nginx.service - nginx - high performance web server... Dec 30 22:10:18 oracle systemd[1]: Started nginx.service - nginx - high performance web server. ``` You can now verify the Nginx version using the following command: ``` nginx -v ``` You should see the Nginx version in the following output: ``` nginx version: nginx/1.29.4 ``` ## Step 3 – Configure Firewall By default, Nginx listens on ports 80 and 443. If any firewall is installed and configured to your server, then you will need to allow both ports via firewalld. You can allow them with the following command: ``` firewall-cmd --permanent --zone=public --add-service=http firewall-cmd --permanent --zone=public --add-service=https ``` Next, reload firewalld to apply the changes: ``` firewall-cmd --reload ``` ## Step 4 – Access Nginx Default Page Now, open your web browser and access the Nginx default page using the URL **http://your-server-ip**. You should see the Nginx default page on the following screen: ![Nginx test page](https://www.atlantic.net/wp-content/uploads/2022/06/p2-2.png) ## Step 5 – Host a Simple Website with Nginx First, create a directory to hold the website data with the following command: ``` mkdir /var/www/html/test.example.com ``` Next, create a simple HTML file inside the website directory: ``` nano /var/www/html/test.example.com/index.html ``` Add the following HTML code: ```

Welcome to the Example Website!

``` Save and close the file, then change the ownership and permissions of the website directory: ``` chown -R www-data:www-data /var/www/html/test.example.com/ chmod -R 775 /var/www/html/test.example.com/ ``` Next, create an Nginx virtual host configuration file to define the website path. ``` nano /etc/nginx/conf.d/test.example.com.conf ``` Add the following configuration: ``` server { listen 80; server_name test.example.com; root /var/www/html/test.example.com; index index.html; } ``` Save and close the file, then edit the Nginx main configuration file: ``` nano /etc/nginx/nginx.conf ``` Add the following line below http {: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then verify Nginx for any syntax configuration errors: ``` nginx -t ``` You should get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Next, restart the Nginx service to apply the configuration changes: ``` systemctl restart nginx ``` Now, open your web browser and verify your website using the URL **http://test.example.com**. You should see your website page on the following screen: ![Verify Nginx](https://www.atlantic.net/wp-content/uploads/2022/06/p3.png) ## Conclusion In the above post, we explained how to install the latest Nginx mainline version on Oracle Linux 10. We also explained how to create a new website and host it using the Nginx virtual host. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Configure Apache Webserver on Oracle Linux > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-configure-apache-webserver-on-oracle-linux/ | Published: 2022-06-20 | Updated: 2025-12-30 | Author: Hitesh Jethva Free, open-source Apache is one of the most popular web servers on the internet. It was developed and maintained by the Apache Software Foundation. Apache is reliable, secure, and fast and can be customized using extensions and modules. Due to its stability, efficiency, and popularity, it is used by many web hosting companies worldwide. It supports all major operating systems, including Linux, Windows, macOS, Solaris, etc. In this post, we will explain how to install an Apache web server on Oracle Linux 10. ## Step 1 – Install Apache on Oracle Linux 10 By default, the latest version of Apache is available in the Oracle Linux default repository. You can install it by running the following commands: ``` dnf update -y ``` ``` dnf install httpd -y ``` Once the Apache package is installed, verify the package information using the following command: ``` apachectl -V ``` You will get the following output: ``` Server version: Apache/2.4.63 (Oracle Linux Server) Server built: Dec 22 2025 00:00:00 Server's Module Magic Number: 20120211:139 Server loaded: APR 1.7.5, APR-UTIL 1.6.3, PCRE 10.44 2024-06-07 Compiled using: APR 1.7.5, APR-UTIL 1.6.3, PCRE 10.44 2024-06-07 Architecture: 64-bit Server MPM: event threaded: yes (fixed thread count) forked: yes (variable process count) Server compiled with.... -D APR_HAS_SENDFILE -D APR_HAS_MMAP -D APR_HAVE_IPV6 (IPv4-mapped addresses enabled) -D APR_USE_PROC_PTHREAD_SERIALIZE -D APR_USE_PTHREAD_SERIALIZE -D SINGLE_LISTEN_UNSERIALIZED_ACCEPT -D APR_HAS_OTHER_CHILD -D AP_HAVE_RELIABLE_PIPED_LOGS -D DYNAMIC_MODULE_LIMIT=256 -D HTTPD_ROOT="/etc/httpd" -D SUEXEC_BIN="/usr/sbin/suexec" -D DEFAULT_PIDLOG="run/httpd.pid" -D DEFAULT_SCOREBOARD="logs/apache_runtime_status" -D DEFAULT_ERRORLOG="logs/error_log" -D AP_TYPES_CONFIG_FILE="conf/mime.types" -D SERVER_CONFIG_FILE="conf/httpd.conf" ``` #### Also Read [Host Multiple Websites on a Single Server Using Apache Web Server](https://www.atlantic.net/vps-hosting/host-multiple-websites-on-a-single-server-with-apache-on-ubuntu/) ## Step 2 – Manage Apache Service By default, the Apache webserver service is managed by systemd. You can control it easily using the systemctl command-line utility. To start the Apache service, run the following command: ``` systemctl start httpd ``` To restart the Apache service, run the following command: ``` systemctl restart httpd ``` To enable the Apache service, run the following command: ``` systemctl enable httpd ``` To check the status of the Apache service, run the following command: ``` systemctl status httpd ``` You will get the following output: ``` ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; vendor preset: disabled) Active: active (running) since Wed 2022-06-08 11:41:51 EDT; 25min ago Docs: man:httpd.service(8) Main PID: 3745 (httpd) Status: "Running, listening on: port 80" Tasks: 213 (limit: 23694) Memory: 25.2M CGroup: /system.slice/httpd.service ├─3745 /usr/sbin/httpd -DFOREGROUND ├─3760 /usr/sbin/httpd -DFOREGROUND ├─3765 /usr/sbin/httpd -DFOREGROUND ├─3766 /usr/sbin/httpd -DFOREGROUND └─3767 /usr/sbin/httpd -DFOREGROUND Jun 08 11:41:51 oraclelinux8 systemd[1]: Starting The Apache HTTP Server... ``` ## Step 3 – Configure Firewall By default, Apache listens on ports **80** and **443**. If a firewall is installed and configured to your server, then you will need to allow both ports via firewalld. You can allow them with the following command: ``` firewall-cmd --permanent --zone=public --add-service=http firewall-cmd --permanent --zone=public --add-service=https ``` Next, reload the firewalld to apply the changes: ``` firewall-cmd --reload ``` ## Step 4 – Access Apache Default Web Page At this point, the Apache web server is installed and listens on port 80. You can now open your web browser and access the Apache test page using the URL **http://your-server-ip**. You should see the Apache default page on the following screen: ![Apache test page](https://www.atlantic.net/wp-content/uploads/2022/06/p1-1-1024x429.png) ## Step 5 – Host a Simple Website with Apache First, create a directory to hold the website data with the following command: ``` mkdir /var/www/html/web.example.com ``` Next, create a simple HTML file inside the website directory: ``` nano /var/www/html/web.example.com/index.html ``` Add the following HTML code: ```

Welcome to the Apache Webserver!

``` Save and close the file, then change the ownership and permissions of the website directory: ``` chown -R apache:apache /var/www/html/web.example.com/ chmod -R 775 /var/www/html/web.example.com/ ``` Next, create an Apache virtual host configuration file to define your website directory: ``` nano /etc/httpd/conf/example.conf ``` Add the following configuration: ``` ServerAdmin web.example.com DocumentRoot /var/www/html/web.example.com DirectoryIndex index.html ErrorLog /var/log/httpd/error.log CustomLog /var/log/httpd/access.log combined ``` Save and close the file, then restart the Apache service to apply the configuration changes: ``` systemctl restart httpd ``` Now, open your web browser and verify your website using the URL **http://web.example.com**. You should see your website page on the following screen: ![Apache test page](https://www.atlantic.net/wp-content/uploads/2022/06/p2-1.png) #### Also Read [How to Set Up Apache Virtual Hosting](https://www.atlantic.net/vps-hosting/how-to-set-apache-virtual-hosts-ubuntu-20-04/) ## Conclusion In the above post, we explained how to install an Apache web server on Oracle Linux 10. We also explained how to create a new website and host it using the Apache virtual host. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install LEMP Server on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-lemp-server-on-oracle-linux-10/ | Published: 2022-06-21 | Updated: 2025-12-30 | Author: Hitesh Jethva LEMP is a collection of four open-source software components that are used together to host a website on the Internet. In the LEMP stack, L represents the Linux operating system, E represents the Nginx web server, M represents the MariaDB/MySQL database server, and P represents the PHP programming language. As all the components are open-source in the LEMP stack, it is used in highly-scaled applications across the web. In this post, we will show you how to install a LEMP stack on Oracle Linux 10. ## Step 1 – Install Nginx Web Server on Oracle Linux 10 Nginx is the first component of the LEMP stack. By default, the Nginx package is included in the Oracle Linux 10 default repository. You can install it using the following command: ``` dnf install nginx -y ``` Once Nginx is installed, start the Nginx service and enable it to start at system reboot. ``` systemctl start nginx systemctl enable nginx ``` You can also verify the status of Nginx with the following command: ``` systemctl status nginx ``` To verify the Nginx version, run the following command: ``` nginx -v ``` You should see the following output: ``` nginx version: nginx/1.26.3 ``` Now, open your web browser and type the URL **http://your-server-ip**. You should see the Nginx default page on the following screen: ![Nginx test page](https://www.atlantic.net/wp-content/uploads/2022/06/p1-1024x430.png) **Also Read** [How to Install and Configure Nginx Web Server on Oracle Linux 8](https://www.atlantic.net/vps-hosting/how-to-install-and-configure-nginx-webserver-on-oracle-linux/) ## Step 2 – Install MariaDB Database Server on Oracle Linux 10 MariaDB is an open-source database server used to store website content. By default, MariaDB is included in the Oracle Linux 10 default repository. You can install it using the following command: ``` dnf install mariadb-server mariadb -y ``` Once MariaDB is installed, start the MariaDB service and enable it to start at system reboot: ``` systemctl start mariadb systemctl enable mariadb ``` You can check the status of MariaDB using the following command: ``` systemctl status mariadb ``` You will get the following command: ``` ● mariadb.service - MariaDB 10.11 database server Loaded: loaded (/usr/lib/systemd/system/mariadb.service; disabled; preset: disabled) Active: active (running) since Sun 2025-12-28 01:30:07 EST; 2 days ago Invocation: bd2ec2682b7d423bbeb559f48272cc49 Docs: man:mariadbd(8) https://mariadb.com/kb/en/library/systemd/ Main PID: 40092 (mariadbd) Status: "Taking your SQL requests now..." Tasks: 8 (limit: 24812) Memory: 350.9M (peak: 351.8M) CPU: 26.513s CGroup: /system.slice/mariadb.service └─40092 /usr/libexec/mariadbd --basedir=/usr ``` You can also verify the MariaDB version with the following command: ``` mysqladmin -V ``` You should see the following output: ``` mysqladmin Ver 10.0 Distrib 10.11.11-MariaDB, for Linux on x86_64 ``` Now, you will need to secure the MariaDB installation. You can secure it with the following command: ``` mysql_secure_installation ``` You will be asked to set a root password as shown below: ``` Enter current password for root (enter for none): OK, successfully used password, moving on... Setting the root password ensures that nobody can log into the MariaDB root user without the proper authorisation. Set root password? [Y/n] Y New password: Re-enter new password: Password updated successfully! Reloading privilege tables.. ... Success! ``` Next, you will be asked to remove anonymous users as shown below: ``` By default, a MariaDB installation has an anonymous user, allowing anyone to log into MariaDB without having to have a user account created for them. This is intended only for testing, and to make the installation go a bit smoother. You should remove them before moving into a production environment. Remove anonymous users? [Y/n] Y ``` Type Y and press Enter. You will be asked to disallow root login remotely: ``` ... Success! Normally, root should only be allowed to connect from 'localhost'. This ensures that someone cannot guess at the root password from the network. Disallow root login remotely? [Y/n] Y ``` Type Y and press the Enter key. You will be asked to remove the test database: ``` ... Success! By default, MariaDB comes with a database named 'test' that anyone can access. This is also intended only for testing, and should be removed before moving into a production environment. Remove test database and access to it? [Y/n] Y ``` Press Y and press the Enter key. You will be asked to reload the privileges table: ``` - Dropping test database... ... Success! - Removing privileges on test database... ... Success! Reloading the privilege tables will ensure that all changes made so far will take effect immediately. Reload privilege tables now? [Y/n] Y ``` Type Y and press the Enter key to secure MariaDB. ``` ... Success! Cleaning up... All done! If you've completed all of the above steps, your MariaDB installation should now be secure. Thanks for using MariaDB! ``` **Also Read** [How to Install and Use MySQL Workbench](https://www.atlantic.net/vps-hosting/how-to-install-and-use-mysql-workbench-on-ubuntu/) ## Step 3 – Install PHP on Oracle Linux 10 By default, the latest version of PHP is available in the Oracle Linux 10 main repository. ``` ``` You can install PHP with other required extensions using the following command: ``` dnf install php php-fpm php-gd php-mysqlnd php-cli php-opcache -y ``` Next, edit the PHP-FPM default configuration file and change the user from apache to nginx: ``` nano /etc/php-fpm.d/www.conf ``` Change the following lines: ``` user = nginx Group = nginx ``` Save and close the file, then start the PHP-FPM service and enable it to start at system reboot: ``` systemctl start php-fpm systemctl enable php-fpm ``` ## Step 4 – Create a Sample Website with Nginx In this section, we will show you how to host a simple website using an Nginx virtual host. First, create a directory to store website content: ``` mkdir -p /var/www/html/website ``` Next, change the ownership and permissions of the website using the following command: ``` chown -R nginx:nginx /var/www/html/website chmod -R 755 /var/www/html/website ``` Next, create a simple PHP page using the following command: ``` nano /var/www/html/website/info.php ``` Add the following PHP code: ``` ``` Save and close the file, then create an Nginx virtual host configuration file: ``` nano /etc/nginx/conf.d/website.conf ``` Add the following lines: ``` server { listen 80; server_name website.example.com; location / { root /var/www/html/website/; index info.php; try_files $uri $uri/ =404; } error_page 500 502 503 504 /50x.html; location = /50x.html { root /usr/share/nginx/html; } location ~ \.php$ { fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_pass unix:/run/php-fpm/www.sock; fastcgi_index info.php; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } } ``` Save and close the file, then edit the Nginx main configuration file: ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http {: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then verify the Nginx configuration using the following command: ``` nginx -t ``` You should see the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Next, restart the Nginx service to apply the configuration: ``` systemctl restart nginx ``` ## Step 5 – Verify Nginx Website Now, open your web browser and type the URL **http://website.example.com**. You should see the PHP page on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2022/06/nginx.png) ## Conclusion In this post, we learned how to install the LEMP server on Oracle Linux 10. You can now use Nginx virtual hosting feature to host multiple websites on a single machine. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Ansible on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-ansible-on-oracle-linux-10/ | Published: 2022-06-22 | Updated: 2025-12-30 | Author: Hitesh Jethva Ansible is a free and open-source automation platform administrators use to install, configure, and provision multiple systems simultaneously. Nowadays, IT environments are very complex and often need to scale extremely quickly. Automation makes system administrators’ and developers’ jobs more accessible, allowing them to focus on other tasks that add value to an organization. Ansible is very simple to set up and use; you don’t need any coding skills to use Ansible. This post will show you how to install Ansible on Oracle Linux 10. **Note**: This procedure will use 2 servers for demonstration purposes ## Step 1 – Set up an SSH Key-based Authentication Before starting, you must set up an SSH password-less login between the Ansible control node and the manager node. You can do it by setting up an SSH key-based authentication. First, generate a private and public key using the following command: ``` ssh-keygen -t rsa ``` You should see the following output: ``` Generating public/private rsa key pair. Enter file in which to save the key (/root/.ssh/id_rsa): Created directory '/root/.ssh'. Enter passphrase (empty for no passphrase): Enter same passphrase again: Your identification has been saved in /root/.ssh/id_rsa. Your public key has been saved in /root/.ssh/id_rsa.pub. The key fingerprint is: SHA256:0qOchzAC0Asm8WPlduL7ZxN6C5NUelScBo2nYVuqPMs root@oraclelinux8 The key's randomart image is: +---[RSA 3072]----+ |oo . .=.. | |+o.o +.B | |+.+.+ ..oO | | o.+ o =+ | | . +.+.S | | . *+B.. | | ..O+.. | | .E+= | | .+.o | +----[SHA256]-----+ ``` Next, copy the generated public key to the Ansible-managed nodes using the following command: ``` ssh-copy-id -i ~/.ssh/id_rsa.pub root@your-remote-host-ip ``` You should see the following output: ``` /usr/bin/ssh-copy-id: INFO: Source of key(s) to be installed: "/root/.ssh/id_rsa.pub" The authenticity of host '192.168.1.10 (192.168.1.10)' can't be established. ECDSA key fingerprint is SHA256:4K4sZbu1hLHzDGlwmWAJng6nDbxDqp6hnv65KDaOAn0. Are you sure you want to continue connecting (yes/no/[fingerprint])? yes /usr/bin/ssh-copy-id: INFO: attempting to log in with the new key(s), to filter out any that are already installed /usr/bin/ssh-copy-id: INFO: 1 key(s) remain to be installed -- if you are prompted now it is to install the new keys root@192.168.1.10's password: Number of key(s) added: 1 Now try logging into the machine, with: "ssh 'root@'" and check to make sure that only the key(s) you wanted were added. ``` Now, run the following command to test the SSH password-less login: ``` ssh root@your-remote-host-ip ``` Also Read [How to Setup SSH Public and Private Key in Linux](https://www.atlantic.net/vps-hosting/how-to-set-up-ssh-public-and-private-key-in-linux/) ## Step 2 – Install Ansible on Oracle Linux 10 Now, you must install the Ansible package on the Ansible control node. By default, the Ansible package is available in the Oracle Linux 10 default repo, so you can install it using the command below. ``` dnf install ansible-core -y ``` Once Ansible is installed, verify the Ansible version with the following command: ``` ansible --version ``` You should see the following output: ``` ansible [core 2.16.14] config file = /etc/ansible/ansible.cfg configured module search path = ['/root/.ansible/plugins/modules', '/usr/share/ansible/plugins/modules'] ansible python module location = /usr/lib/python3.12/site-packages/ansible ansible collection location = /root/.ansible/collections:/usr/share/ansible/collections executable location = /usr/bin/ansible python version = 3.12.12 (main, Dec 22 2025, 00:00:00) [GCC 14.3.1 20250617 (Red Hat 14.3.1-2)] (/usr/bin/python3) jinja version = 3.1.6 libyaml = True ``` ## Step 3 – Configure Ansible Hosts Next, you must edit the Ansible hosts configuration file and define the remote Linux server you want to manage. You can edit it with the following command: ``` nano /etc/ansible/hosts ``` Add the following lines: ``` [web] server1 ansible_ssh_host= ansible_ssh_port=22 ansible_ssh_user=root [database] dbserver1 ansible_ssh_host= ansible_ssh_port=22 ansible_ssh_user=root ``` Save and close the file when you are finished. Next, edit the Ansible configuration file and turn off the deprecation warnings and host key checking: ``` nano /etc/ansible/ansible.cfg ``` Add the following line below [defaults]: ``` deprecation_warnings=False host_key_checking = False ``` Save and close the file when you are finished. ## Step 4 – How to Use Ansible At this point, Ansible is installed and configured. Now, you will need to check Ansible’s functionality using the Ansible ad-hoc commands: First, check the connectivity of all managed nodes using the following command: ``` ansible -m ping all ``` If everything is fine, you should see the following output: ``` dbserver1 | SUCCESS => { "ansible_facts": { "discovered_interpreter_python": "/usr/bin/python" }, "changed": false, "ping": "pong" } server1 | SUCCESS => { "ansible_facts": { "discovered_interpreter_python": "/usr/bin/python" }, "changed": false, "ping": "pong" } ``` If you only want to check the database server connectivity, run the following command: ``` ansible -m ping database ``` You will get the following output: ``` dbserver1 | SUCCESS => { "ansible_facts": { "discovered_interpreter_python": "/usr/bin/python" }, "changed": false, "ping": "pong" } ``` To check the free memory on the web server node, run the following command: ``` ansible -m shell -a "free -m" web ``` You will get the following output: ``` server1 | CHANGED | rc=0 >> total used free shared buff/cache available Mem: 1817 621 210 21 985 1006 Swap: 0 0 0 ``` To check the MySQL version on the database server node, run the following command: ``` ansible -m shell -a "mysqladmin --version" database ``` You should see the following output: ``` dbserver1 | CHANGED | rc=0 >> mysqladmin Ver 8.0.26 for Linux on x86_64 (Source distribution) ``` Also Read [How to Check CPU Usage and Utilization in Linux](https://www.atlantic.net/vps-hosting/how-to-check-linux-cpu-usage-or-utilization/) ## Step 5 – Create Ansible Playbook to Install Packages on Managed Nodes Ansible allows us to create a playbook to define all tasks that we want to perform on the managed nodes. First, create a directory to store your playbook. ``` mkdir project ``` Next, navigate to the created directory and create a YAML file using the following command: ``` cd project nano app.yaml ``` Add the following configuration: ``` - name: Install Packages hosts: - web - database tasks: - name: Install php and nginx package: name: - php - httpd state: present ``` Save and close the file, then run the playbook using the following command: ``` ansible-playbook app.yaml ``` Once the Ansible playbook runs successfully, you will get the following output: ``` PLAY [Install Packages] ********************************************************************************************************************** TASK [Gathering Facts] *********************************************************************************************************************** ok: [server1] ok: [dbserver1] TASK [Install php and apache] **************************************************************************************************************** ok: [server1] changed: [dbserver1] PLAY RECAP *********************************************************************************************************************************** dbserver1 : ok=2 changed=1 unreachable=0 failed=0 skipped=0 rescued=0 ignored=0 server1 : ok=2 changed=0 unreachable=0 failed=0 skipped=0 rescued=0 ignored=0 ``` You can now verify the PHP version on the webserver node using the following command: ``` ansible -m shell -a "php -v" web ``` You will get the following output: ``` server1 | CHANGED | rc=0 >> PHP 7.2.24 (cli) (built: Oct 22 2019 08:28:36) ( NTS ) Copyright (c) 1997-2018 The PHP Group Zend Engine v3.2.0, Copyright (c) 1998-2018 Zend Technologies ``` ## Conclusion This guide explained how to install Ansible on Oracle Linux 10. We also explained using Ansible ad-hoc commands and playbook to provision managed nodes. You can now use Ansible to efficiently provide and manage your entire IT infrastructure. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Top 10 Best Cybersecurity Training Services > URL: https://www.atlantic.net/hipaa-compliant-hosting/top-10-best-cybersecurity-training-services/ | Published: 2022-07-01 | Updated: 2025-09-15 | Author: Richard Bailey Cybersecurity awareness training services are designed as education programs to teach business employees how to understand the fundamentals of what cybersecurity is all about and how to combat the threat of malware, ransomware, phishing, and hacking. Cybersecurity education is critical in today’s digital world and it’s considered an essential requirement by the U.S Department of Cybersecurity and Infrastructure Security Agency (CISA). Although cybersecurity applications are getting better by the day, it is still extremely difficult to eliminate all threats to businesses. This is why it’s so important to offer training to your employees, as they are the gatekeepers to the business. Front line workers are considered an easy target for hacking groups because they just need to catch someone not paying attention or acting in good faith to breach business security protections. Education is essential for any business with an IT presence, and cybersecurity courses range from introductory classes for non-technical employees to intensive deep-dives for security experts. There is so much cybersecurity advice available online that it’s often hard to know where to start looking, so we have compiled our top 10 cybersecurity training services to help narrow your shortlist to what we believe are the best training services available. ## 1. American Cyber Security Management American Cyber Security Management (ACSM) is a leader in data privacy and security and a proud partner of Atlantic.Net. They provide on-demand cybersecurity training services that cover the assessment, implementation, and sustainability of compliance services, teach how to reduce security risk, and enable the reliability, integrity, and security of applications. ACSM provides the full package of solutions that will help put your businesses on the front foot. ## 2. KnowBe4 KnowBe4 is a major player in IT training that aims to empower employees to make smarter security decisions. The training services aim to drastically reduce human error in the “human firewall.” KnowBe4 teaches users how to prevent sophisticated phishing and ransomware attacks by creating a baseline test of user security awareness from social engineering data. They then train the employee and later reassess with further social engineering. The training program is adjusted as the results come in to focus on areas of weakness throughout the business. ## 3. Infosec IQ Infosec is another big player aiming to build awareness and transform business culture to focus on the challenge of cybersecurity. Various security awareness programs create an engaging platform to capture employee awareness to promote cybersecurity best practices. Infosec IQ offers courses to prevent data leaks and cybercriminal activities and features phishing simulators to target employee emails and social engineering tests that help to ensure the training is proving successful. ## 4. Proofpoint Security Awareness Proofpoint’s training services aim to enhance employee cybersecurity knowledge to protect against ransomware and email fraud. The program teaches the foundation of what ransomware is and how it has changed in recent years. Students learn the very latest cybersecurity threat landscape and how to intercept attempts to compromise an email, SMS, or fax data, and how threat actors persuade staff to click on infected links. The goal is to change employee behavior and reduce the business’s exposure to cybersecurity threats. ## 5. Cofense Cofense is a training services business that focuses specifically on preventing phishing attacks. Phishing is arguably the number one reason behind successful hacks on business systems. Cofense PDR (Phishing Detection and Response) combines technology and unique human insight to catch and stop phishing attacks. Cofense PhishMe teaches employees to identify potential phishing with simulations that demonstrate known phishing tactics, employees can later be tested and offered training using intelligence from reporting. ## 6. Terranova Security Awareness Platform Terranova Security from HelpSystems empowers employees to become cyber heroes.  Students learn how to protect data with encryption and spot suspicious webpage forms. These exercises ensure users can recognize threats and tactics related to phishing, spear phishing, ransomware, malware, social engineering, and more. The training comes in various formats, including online, video, or classroom-based learning to create a diverse, inclusive, and engaging training program. ## 7. SANS Security Awareness The SANS Institute was founded 30 years ago to create cooperative research and education services for security professionals. This is achieved through EndUser training with culturally relevant material to ensure the employees needing assistance are targeted. Social engineering and analysis of user habits help to identify where high-risk data practices exist, helping the program to target training in areas where the business will benefit the most. ## 8. Barracuda Barracuda teaches employees how to identify and respond to potential security risks with their cybersecurity training service. An archive of phishing simulation email threats can be used to target different teams around the business. Management can analyze the results of user behavior to help identify any additional training that might be required. ## 9. CybSafe Cybsafe is a UK company that is popular in the United States. CybSafe targets changing user behavior to be more security-focused. A suite of tools is provided to help employees stay safe online, and training is automatically suggested as the platform learns employee behavior. ## 10. Mimecast Mimecast targets reducing human error with their cybersecurity training service by providing continuous, engaging, video-based micro-learning that can increase your employees’ cyber hygiene. They aim to improve employees’ cybersecurity knowledge using engaging content and training to boost confidence and teach users where to focus their training to stay on top of the latest trends. ## How can Atlantic.Net Help? Cyberattacks are becoming a daily threat that organizations have to face, and the urgent need to have all front-line employees well versed in cybersecurity is a major concern. Cybersecurity Training Services are arguably one of the best ways to combat this risk. Atlantic.Net has over 30 years of experience providing high-end hosting solutions that are built to exact security standards. Our platform gives our customers the best chance to combat cybersecurity issues. Our network and platform are segregated, meaning that even if someone manages a successful phish, it would be impossible for the hacker to traverse our network, the design prevents that possibility. Any issue would be isolated at the source. Are you a healthcare provider searching for a fully audited [HIPAA-compliant server infrastructure](https://www.atlantic.net/hipaa-compliant-hosting/) for your organization? To find out more about the solutions that we offer, [contact the sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # How RAID Arrays Keep Your Data Safe and Accessible > URL: https://www.atlantic.net/vps-hosting/how-raid-arrays-improve-performance-and-data-protection/ | Published: 2022-07-08 | Updated: 2025-09-10 | Author: Robert Agar Mission-critical enterprise data resources need to be readily available to allow organizations to meet their business objectives. The storage devices employed to furnish users and applications with access to this valuable data must exhibit elevated levels of performance and resiliency. One way to keep data flowing is to protect it by storing it in RAID arrays. RAID stands for redundant array of independent disks. It is a storage methodology that uses multiple hardware devices and techniques to ensure data remains available if one or several array components fail. This article looks at how the variety of RAID implementations offer businesses various levels of data protection and performance. We also discuss issues that can arise with RAID arrays and present reasons that effective monitoring should be in place. ## How RAID Arrays Are Constructed RAID arrays are built using a combination of up to three fundamental data storage concepts. As we will see shortly, different RAID levels are constructed using these concepts to provide varying levels of performance and data protection. ### Disk Mirroring In disk mirroring, data is written simultaneously to multiple disks. Mirroring offers protection against hardware failure by making the same data available on several physical devices. If a mirrored disk fails, performance is maintained by immediately switching to an alternate device. Mirroring eliminates the time required to restore a disk and reconstruct a file system if a non-mirrored storage device fails. Resiliency and redundancy are provided by mirrored disks which make them an appropriate choice for storing business-critical data. ### Disk Striping Disk striping is a technique that also uses multiple physical devices to augment the functionality of a single unit. When disk striping is implemented, multiple physical disks are treated as a single logical device. Blocks of data are segmented and stored across logically connected storage devices. Disk striping provides both advantages and disadvantages regarding data availability and performance. The benefits of disk striping include: - Simplified resource management as multiple physical disks are seen as a unified logical entity. - Multithreading read and write requests across multiple disks improves performance. A disadvantage that can affect storage systems employing disk striping is its fragility. When a disk fails, it can be impossible to get to the data stored on other disks where data was written. The potential exists for data to be lost if there is no hot-swapping ability built into the environment. ### Parity The use of parity checks is the third possible component of a RAID implementation. When parity checking is in play, a parity block is added to each byte of data. Parity bits are checked to ensure data accuracy and can be used to reconstruct data from failed drives. Parity error checking involves comparing data from different locations and can adversely affect I/O performance. ## What Do Different RAID Levels Provide? Various combinations of mirroring, striping, and parity checking are used in the implementation of different RAID levels. Understanding the differences between the levels is key to making the best choice for your business from the options available from your cloud service provider. The following table summarizes the features and requirements of the most commonly implemented RAID levels. ![RAID Chart](https://www.atlantic.net/wp-content/uploads/2021/05/RAID-Chart.png) ## Problems Affecting RAID Arrays A RAID array can partially or completely fail due to a variety of reasons. A failed array should not be used until the problems are resolved to prevent further damage or data loss. The following are the most common reasons for the failure of a RAID array. - **Multiple disk failures** – An array will fail if too many disks fail concurrently. While arrays can be run in degraded mode when experiencing a failed disk, this practice is not recommended as it can result in a total failure of the array. - **Failed RAID controller** – All array operations are directed by the RAID controller. Power surges or other types of problems can cause the controller to fail. The array can experience multiple performance problems and may become inaccessible. - **Infrastructure issues** – If the server hosting the RAID array crashes, the storage system can become inaccessible. - **Faulty volume rebuilds** – An incorrectly rebuilt RAID volume can lead to degraded data access or a complete failure of the array. Drive failures should be addressed and resolved as soon as possible. Letting an array continue to function at a degraded capacity opens the door for further problems and will increase the time necessary to repair the system. A large and complex RAID array that has experienced a failure can take an extended amount of time to rebuild. ## Monitoring RAID Arrays Unmonitored RAID arrays can be afflicted by degraded performance and potential data loss. Monitoring can be done using proprietary software supplied by the array’s hardware manufacturers. It can also be accomplished with general infrastructure monitoring tools that provide the necessary visibility into the array’s components of physical and logical disks. When RAID arrays are implemented in-house, an organization’s storage team is usually responsible for monitoring the system. Based on the type of server you obtain from a cloud provider, the vendor may handle monitoring the array and making sure your data is safe and accessible. ## Atlantic.Net’s RAID Offerings Atlantic.Net has several [different RAID implementations](https://www.atlantic.net/dedicated-server-hosting/) available for customers using their dedicated or VPS hosting offerings. Customers who select a VPS solution have a highly redundant RAID 10 storage architecture protecting their data and ensuring high performance. The system keeps a business running by tolerating the failure of individual components while maintaining performance and data availability. Choosing to deploy a dedicated server enables customers to choose from these storage options: - SATA SSD RAID1; - SATA SSD RAID10; - NVMe SSD RAID10; - A fully customizable implementation that provides any RAID level the customer desires. Whichever hosting option your company chooses, its data will be well-protected and always available when needed with the RAID options available from Atlantic.Net. --- # Protecting Patient Data: the Right Way and the Wrong Way! > URL: https://www.atlantic.net/hipaa-compliant-hosting/protecting-patient-data-the-right-way-and-the-wrong-way/ | Published: 2022-07-14 | Updated: 2025-09-15 | Author: Richard Bailey Medical institutions are under intense pressure to ensure that electronic health records and protected health information remain safeguarded to the highest data integrity standards on behalf of their patients. However, when it comes to protecting a patient’s health record, there is a “right way” and a “wrong way.” Join us as we untangle the fundamental requirements for securing health data that patients expect and legislative protections demand. All healthcare providers that operate in the United States have an obligation to protect patient records, including all electronic medical records (EMRs), electronic health records (EHRs), and any other sensitive healthcare data. Healthcare practices are also required by law to take steps to ensure the organization is in compliance with the rules and regulations of HIPAA. This will defend against the hefty fines and help prevent the violation of patient trust in your organization. We will draw a comparison between two different strategies that can have different outcomes, either beneficial or detrimental, to healthcare. ## The Wrong Way HIPAA compliance is a difficult status to achieve, especially if your healthcare organization is just starting out on this journey. HIPAA has been around since 1996, and healthcare professionals understand the need for compliance. Practices that are doing things the “wrong way” will rarely willfully neglect patient data; instead, genuine mistakes are made because they lack the knowledge of the required HIPAA safeguards or they fail to research the best HIPAA compliant partners, such as their [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) company. It is not unheard of for healthcare practices to cut corners to save money, but as you can see from the [HIPAA Wall of Shame,](https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf) the OCR is quite willing to hand out fines for neglectful practices. Here are some telltale signs that your practice may be protecting patient data the wrong way: - **Paper Patient Records:** Maintaining paper records on patients does not automatically breach HIPAA; however, it introduces a wide scope of unnecessary risk. Physical copies are harder to shield, papers are easily lost, results can be conveniently changed, and there are sometimes questions about their accuracy. - **Limited IT Security:** In-house IT systems are more likely to have weak or nonexistent security, especially if managed by an inexperienced team. Our engineers frequently hear the excuse “That’s how we have always done it.” - **Choosing Low-Budget Hosting:** Some healthcare practices want to save dollars by outsourcing to cheap hosting with basic or limited security. The basic safeguards of [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/), such as encryption, are ignored in favor of a cheaper expenditure. - **Partnering with Organizations that Falsely Claim HIPAA Compliance:** This is surprisingly more common than you may think. Some of the red flags here are providers that refuse to sign a business associate agreement, have no reliable backup strategy, and disaster recovery either doesn’t work or is nonexistent. ## Doing It the Right Way Doing HIPAA-Compliance the right way is hard, but it’s critical that all forms of electronic protected health information (ePHI) meet the standards of the five HIPAA rules: - Transactions and Code Sets Rules - Unique Identifiers Rule - The Security Rule - The Privacy Rule - Enforcement Rule (Final Omnibus Rule) Each rule has various physical, technical, and administrative safeguards that are required to meet compliance. You can read more about these rules on our detailed [HIPAA checklist](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). To follow HIPAA the right way, there are several required standards that your hosting provider must meet. Does your provider meet and exceed all of these standards? Or is it time to switch to a provider that can? Ask yourself these questions: - **Encryption to NIST Standards:** Are all external network traffic interfaces encrypted? Is traffic routed over a secure VPN tunnel between sites? Are all endpoints encrypted, servers, laptops, and cell phones? Is there a HIPAA-Compliant Firewall installed? Does you provider feature an Intrusion Prevention System (IPS)? - **Identify ePHI:** Do you know where all in-scope ePHI is located? Is it protected from unauthorized changes or accidental deletion? - **Access Controls:** Does every user have a unique username and passworded account protected by MFA? Does the business follow the principle of least privilege? - **Audit:** Can your logs identify user access facts or if ePHI data is changed? - **Automatic Logoff:** Are users automatically logged out of IT systems? - **Data Center Access:** Can your host provider give details of all access made to the data center? Is the data center monitored 24x7x365? Does it have CCTV and manned security? - **Workstation Policies:** Can your hosting provider restrict workstation access to PHI? - **Cell Phones:** If a business mobile is stolen, are you able to delete the data remotely? - **Tracking Equipment:** Do you have an inventory of all HIPAA infrastructure? - **Risk Assessment:** Can your provider assist with a risk assessment for all of your data? - **Risk Management:** How does your hosting provider manage security incidents related to HIPAA? - **Training:** Can your provider help train the workforce? Can employees identify phishing, hacking, and deception techniques? - **Disaster Recovery:** Does the hosting provider offer DR as a service? Is DR tested regularly? - **Business Continuity:** What is your provider’s contingency plan in the event of a disaster? Now that you have seen both options, the choice is yours. If you choose the cheap route, be prepared for the increased possibility of a hefty fine in the event of a breach or an unexpected audit. Or choose to outsource to a HIPAA-audited hosting company like Atlantic.Net – we stand ready to assist you with [HIPAA WordPress hosting](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/), HIPAA database hosting, HIPAA compliant applications, and more! --- # HIPAA Violations Guide 2022 > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-violations-guide-2022/ | Published: 2022-07-20 | Updated: 2024-09-10 | Author: Richard Bailey Achieving and maintaining HIPAA compliance is a fundamental challenge to covered entities and business associates that are responsible for protecting patient health information. This responsibility is imposed on them by the stringent requirements of the Security and Privacy Rules of the Health Insurance Portability and Accountability Act. ### Who Is Responsible for HIPAA Violations? All healthcare entities and their associated businesses, such as managed service providers (MSPs), are jointly responsible for complying with HIPAA regulations. The agreement is enforceable by the U.S. Department of Health & Human Services (HHS) and can result in significant fines to all involved parties. ### Q1 and Q2 2022 HIPAA Violations Take a moment to browse the [HHS hall of shame](https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf) and you will see that violations are commonplace and can involve significant financial and reputational impact. Using data obtained from HHS for the first 6 months of 2022 (1st January 2022 – 30th June 2022), there have been 335 reported incidents to the HHS; these are incidents that have either been investigated or are under investigation by the HHS. Over 20 million patients have been affected by reported breaches of HIPAA standards. Here are the Top 5 biggest breaches by the number of individuals affected. ![HIPAA Breaches2022](https://www.atlantic.net/wp-content/uploads/2022/07/HIPAA-Breaches-2022.png) *Source: HHS OCR Portal – [Breach report](https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf) * Violations are rarely the same, and not all incidents are as severe as the examples above. Nevertheless, in some cases, ePHI has actually been posted to the public internet, with patient files accessible directly via search engines. Understand that the severity of the fine will depend on the severity of the incident. If your organization is found to be in violation of HIPAA, you might not necessarily have to pay millions of dollars because the penalty depends on the severity of the violation and the size of the organization. ## How Are the Fines Calculated? The OCR and the Centers for Medicare & Medicaid (CMS) are authorized to enforce penalties on HIPAA violations. The extent of settlements can be quite frightening, including civil and criminal judgments. Minimum and maximum limits were introduced in 2009, but according to the American Medical Association, the HHS “still has discretion in determining the amount of the penalty.” There is one important exception: if the HHS determines that the covered entity was not purposely neglectful, one full month is given for the problem to be rectified. ## HIPAA Violation Penalties In 2022 the [penalties and fines](https://www.federalregister.gov/documents/2022/03/17/2022-05648/annual-civil-monetary-penalties-inflation-adjustment) for HIPAA violations were amended by the HHS. The penalties are tiered around severity: ![HIPAA Breach Tiers](https://www.atlantic.net/wp-content/uploads/2022/07/HIPAA-Breach-Tiers.png) ## HIPAA Non-Compliance Criminal Penalties – Can You Be Imprisoned? Sentencing can be more severe, though. Anything that violates the law and involves deception carries a maximum sentence of $100,000 and/or five years imprisonment. Violations that occur because an individual plans to use the data for their own gain or for malevolent reasons are penalized with judgments up to $250,000, accompanied by prison sentences as high as ten years. ### Covered Entities & Individual People The Department of Justice decided that if it is determined that a crime has been committed, covered entities (healthcare plans, data clearinghouses, and providers) can be held directly liable. Leadership in a covered entity can also be subject to criminal investigation and sentencing. Even if someone in an executive position at a company where misuse takes place did not do anything that was specifically non-compliant, they still may be guilty as a co-conspirator or accomplice. ### “Knowingly” The Department of Justice specifically targeted a word within HIPAA crime provisions that is a source of confusion: what does knowingly mean? Knowingly refers to the highest criminal penalty situation listed above, the “for their own gain” scenario (bolded above). According to Law360, “Under the statute, covered entities and individuals who ‘knowingly’ obtain or disclose individually identifiable health information with the intent to” profit from it or hurt someone face the stiffest penalties. The Department of Justice has clarified that the word refers to knowledge of HIPAA law rather than knowledge of a particular instance of non-compliance. ### Exclusion & Upholding the Law The federal government can remove any healthcare plan, provider, or clearinghouse from the Medicare system if they have not adopted a universal, standardized medical code. In terms of enforcement, OCR identifies and punishes HIPAA privacy violations. The Centers for Medicare & Medicaid (CMS) oversees the security and uniform code. ## Choosing a Compliance Partner The consequences of violating HIPAA can be extreme. Even if you are not fined millions, it is not a great way to spend money, [and it’s not fun to end up on the HIPAA Wall of Shame](https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf). For these reasons, it is extraordinarily important to choose a technological partner that specializes in healthcare [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) like Atlantic.Net. Our [SSD Cloud Servers ](https://www.atlantic.net/vps-hosting/pricing/)offer a 100% uptime guarantee and can launch in under 30 seconds. ### What Happens If You Violate HIPAA? Avoiding HIPAA violations is not as easy as it first may appear. If any employee violates certain stipulations, even unintentionally, the employer can be fined up to $1.5 million, the yearly cap per business. The rules of compliance are complex, and a substantial number of technical, administrative, and physical safeguards must be adhered to, too. ### Privacy and Security Violations As you might expect, there are some trends in the type of violations of HIPAA compliance. ### #1: Incorrectly Handling Data Here are some of the most common breaches: - Emailing an unintended person or party containing ePHI - Sending an incorrect patient chart - Choosing an incorrect dictator when sending transcriptions - Select incorrect patient healthcare numbers, such as medical records, account numbers, or identification numbers - Inputting an incorrect doctor - Disclosing healthcare information to third parties without consent - Waiting or generally neglecting to notify compliance officials or other appropriate personnel of any possible data breaches - Throwing away confidential healthcare documents in an unauthorized way (making them susceptible to theft) Regardless of whether or not an individual or facility has the right to review the record, there must still be a justifiable reason associated with each instance of access. ### #2: Contractual Errors Here are some of the most common breaches: - Accepted patient authorization forms that have missing data: - missing the full name of the patient - no entity defined to which health records are to be released - elements of PHI/EMR (electronic medical records) that have not been cleared release - end date through which permission is granted - Omitting a clause related to revocation (a right that needs to be clearly stated on a HIPAA authorization form for it to be legitimate) - Neglect to sign updated business association agreements (BAAs) with all applicable third parties - Disclosing patient data beyond the dates established in the relevant HIPAA contract, which typically involves an employee failing to double-check the authorization prior to release - Using laptop or PCs to store PHI without any appropriate security solutions installed (this is the most common violation and can be solved by HIPAA-compliant cloud hosting) ### How to Avoid HIPAA Violations You now know the most common violations, so what can be done to protect your business interests? #### #1: Secure PHI and EMR Establish one password to get access to the data, and designate a compliance officer on your staff (if you have not already) to safeguard the password. Adjust the password frequently, ideally with random password generation software, and use two-factor authentication for access. #### #2: Creation/Development Of Protective Policies Create management policies to make it less likely that patient health information gets into the wrong hands. Notify all personnel that any instances of entry into the EMR database are logged and monitored, and supply appropriate training as needed. #### #3: Simple And Timely Patient Access HIPAA requires that patients be able to review their EMR whenever they desire. Usernames and temporary passwords can be supplied to all patients immediately, both for compliance and efficiency. #### #4: Noncompliant disposal of hard copy PHI HIPAA places a significant focus on digital communications, but controlling paper copies of EMR is critical as well. You want to either have all paper documents under lock and key, accessible only to the appropriate staff members, or to keep all the paperwork at a fully secured external location. Shredding of any paperwork for disposal should either be conducted in-house (with extreme care) or through an expert third party. ## HIPAA Violations 2022: Atlantic CEO Q&A The [Becker’s Healthcare Review](https://www.beckersasc.com/asc-quality-infection-control/how-hipaa-has-evolved-what-ascs-can-do-to-keep-up-5-qs-with-atlantic-net-ceo-marty-puranik.html) interviewed our very own Marty Puranik, the president and CEO Atlantic.Net. The Q&A was about the evolution of HIPAA legislation and how healthcare organizations can prevent data breaches. ### How Can Healthcare Organizations Prevent Data Breaches? “It is a good idea to identify someone within your organization who will be responsible for training that will cover common internal and external breach risks, along with HIPAA-compliant policies and procedures to mitigate the threats to ePHI. Your staff needs to understand that health data can never be disclosed on social media or via text message and that it’s not all right to access ePHI simply out of curiosity. Patient files and mobile devices should be protected carefully at all times and, as your risk assessment reveals, target the high-priority risks immediately.” ### Can you explain how you have seen HIPAA evolve over the years? “One of the main things is that the fines were raised significantly. The maximum annual amount that could be charged per provision has increased from $25,000 to $1.5 million. Another core aspect of compliance introduced in HITECH was the Breach Notification Rule, which made it necessary to contact patients impacted by breaches directly and, in some cases, through the media. Another key change is that HIPAA rules became directly applicable to business associates. The main concept for staying well-versed in compliance is to get help as needed. While in-house training is great, you may also benefit from working with HIPAA-compliant service providers or consultants.” ### What Is Considered A Data Breach? “Unauthorized use or disclosure of electronic protected health information is a breach. There are three exceptions: - If the ePHI was accessed “in good faith” by a person who was acting on behalf of a HIPAA-compliant organization - If it was disclosed by an authorized individual to an unauthorized individual at the same organization - If the organization from which the information was accessed has a reasonable belief that the unauthorized party would not be able to collect and keep the data The ePHI also must be unsecured in order for it to be a breach. Determining quickly if a breach has occurred allows you to send mandated notifications and take other first steps.” ### How Can Healthcare Organizations Use Technology to Protect Their Patients’ Health Data? “Technology is integral to HIPAA compliance since it is directly related to the security rule, which essentially applies the Privacy Rule to IT. There should be encryption for both in-transit and at-rest data, for instance,  SSL certificates should be installed. Backups are used to maintain availability requirements under the law.” “The backups you use should be offsite CDP backups that allow you to completely restore your information using an up-to-date, easily accessible remote copy. Firewall and multifactor authentication are also critical to maintaining security, and we recommend those as managed services.” ### How Do See The Healthcare Landscape Changing In The Coming Years? “The Office of the National Coordinator’s contest for blockchain advances shows how it is being embraced at the federal level, in part because it helps address interoperability. Blockchain becomes even more important with the growing interoperability challenges of wearables and the IoT.” “A study from earlier this year showed the average breach sector-wide costs just over $700,000, so it is an unexpected expense for which you get billed the better part of a million dollars. Clearly, that will restrict the growth of a company; the combined effect of these breaches has an impact on all aspects of healthcare, and the ASC space is no exception. The ASC sector is projected for 6 percent growth for the next few years despite the threat landscape.” “The insider threat is the most common reason for a breach, per a study released earlier this year. Since that’s the case, there should be increased awareness that strong healthcare security preparation – setting aside compliance for a minute – is about looking within as much as it is about looking without. Now, most of these incidents are human error, so we are not generally talking about malice. Nonetheless, the results are the same.” ## Take Advantage Of HIPAA-Compliant Business Associates HIPAA violations are costly, and staying compliant represents a time-consuming hassle for many healthcare organizations. Using fully [HIPAA-Compliant Hosting solutions](https://www.atlantic.net/hipaa-compliant-hosting/) can remove the stress by allowing a company with three decades of data center expertise to stand guard over your PHI.  We offer a full line-up of 100 percent [HIPAA-Compliant Cloud Server](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. --- # How to Install Gulp.js on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-gulp-js-on-oracle-linux-10/ | Published: 2022-07-24 | Updated: 2025-12-30 | Author: Hitesh Jethva Gulp is a free, open-source, and cross-platform task runner tool that uses Node.js as a platform. It helps developers to automate painful tasks such as CSS and HTML minification, concatenating library files, and compiling the SASS files in the development workflow. Generally, it is used to run front-end tasks such as spinning up a web server or reloading the browser automatically whenever a file is saved. In this post, we will show you how to install Gulp.js on Oracle Linux 10. ## Step 1 – Install Node.js on Oracle Linux 10 Gulp uses Node.js and NPM framework, so you will need to install both packages to your system. First, install the curl package using the following command: ``` dnf update -y dnf install curl -y ``` Next, install the Node.js by running the following command: ``` dnf install nodejs npm -y ``` Once Node.js is installed, you can verify the Node.js version using the following command: ``` node --version ``` You will get the following output: ``` v22.19.0 ``` You can also verify the NPM version using the following command: ``` npm -v ``` Sample output: ``` 10.9.3 ``` ## Step 2 – Install Gulp.js Before starting, you will need to install the Gulp CLI tool to install and manage the Gulp application. You can install the Gulp CLI tool using the following command: ``` npm install -g gulp-cli ``` After the installation, create a directory for the Gulp application: ``` mkdir gulp ``` Next, change the directory to gulp and create a gulp application with the following command: ``` cd gulp npm init ``` You will be asked to provide answers to several questions for your new application: ``` package name: (gulp) version: (1.0.0) description: entry point: (index.js) test command: git repository: keywords: author: license: (ISC) About to write to /root/gulp/package.json: { "name": "gulp", "version": "1.0.0", "description": "", "main": "index.js", "scripts": { "test": "echo \"Error: no test specified\" && exit 1" }, "author": "", "license": "ISC" } Is this OK? (yes) yes ``` Next, run the following command to install the Gulp module: ``` npm install --save-dev gulp ``` Next, verify the Gulp installation using the following command: ``` gulp --version ``` You should see the following output: ``` CLI version: 3.1.0 Local version: 5.0.1 ``` ## Step 3 – Create a Gulp Application After installing Gulp, you will need to create a sample Gulp application to test it. First, create a project directory using the following command: ``` mkdir project ``` Next, change the directory to project and create a Gulp application with the following command: ``` cd project nano gulpfile.js ``` Add the following code: ``` var gulp = require('gulp'); gulp.task('hello', function(done) { console.log('Hello World Application!!!'); done(); }); ``` Save and close the file, then run the Gulp application using the following command: ``` gulp hello ``` You will get the following output: ``` [12:30:52] Using gulpfile ~/gulp/project/gulpfile.js [12:30:52] Starting 'hello'... Hello World Application!!! [12:30:52] Finished 'hello' after 2.11 ms ``` ## Conclusion In this post, we explained how to install Gulp.js on Oracle Linux 10. We also created a sample application using Gulp.js. You can now use Gulp in your environment to automate repetitive tasks with ease. For more information, visit the Gulp.js official [documentation](https://gulpjs.com/) page. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Top Healthcare Technology and Compliance Trends for 2022 > URL: https://www.atlantic.net/hipaa-compliant-hosting/top-healthcare-technology-and-compliance-trends-for-2022/ | Published: 2022-07-25 | Updated: 2025-09-15 | Author: Dr. Rachael Bailey The COVID-19 pandemic has had and continues to have a vast impact on the healthcare sector. New technology has always been adopted steadily within healthcare, but the pandemic forced the industry to adapt and innovate quickly to meet demand. Our overwhelmed healthcare systems became heavily dependent on technological advancements to improve efficiency and patient access. This expedited change will continue as we deal with the ongoing knock-on effects of the pandemic. Join us as we analyze the key healthcare technology and compliance trends in 2022. ## Cybersecurity and Data Protection With digital transformation comes the need to secure and protect sensitive digital data. Healthcare infrastructure was left vulnerable during the pandemic, and hackers took advantage of this. Notably, we saw a significant increase in cyber threats, ransomware attacks, and data theft during this time. Highly valuable vaccine data was a particular target, with the [European Medicines Agency (EMA) reporting a cyberattack](https://www.healthcareitnews.com/news/emea/pfizer-covid-19-vaccine-data-leaked-hackers) that resulted in unlawful access to regulatory submission documents for the Pfizer-BioNTech COVID-19 vaccine. According to the IBM Cost of a Data Breach Report 2021, the healthcare industry draws the costliest data breach with a staggering average cost of $9.23 million in 2021. Outdated technology and on-premise servers are a leading reason for data breaches. In 2022, healthcare providers will need to identify and address any underlying flaws in their digital solutions to minimize the risk of any future cyberattack. Many healthcare providers have chosen to migrate their services to the cloud, with cloud-based ERHs offering on-hand expertise and enhanced security features. Many more healthcare organizations will follow suit over the coming year. ## Internet of Medical Things (IoMT) Many of the hurdles that we faced during the previous two years could be addressed through the adoption and use of Internet of Medical Things (IoMT) devices. IoMT devices can help to reduce costs within the healthcare industry, improve patient access and enhance the efficiency and diversity of services offered. IoMT adoption has increased significantly over the pandemic, with over [10 billion active IoMT devices in 2021](https://dataprot.net/statistics/iot-statistics/#:~:text=Healthcare%20IoT%20statistics%208.%2087%25%20of%20healthcare%20organizations,greatly%20improve%20the%20quality%20and%20speed%20of%20healthcare.), and the number looking set to exceed [25.4 billion by 2030](https://dataprot.net/statistics/iot-statistics/#:~:text=Healthcare%20IoT%20statistics%208.%2087%25%20of%20healthcare%20organizations,greatly%20improve%20the%20quality%20and%20speed%20of%20healthcare.). Indeed, the IoMT global market value is predicted to reach [254.2 million by 2026](https://www.alltheresearch.com/report/166/internet-of-medical-things-market#:~:text=The%20global%20Internet%20of%20Medical,period%20(2016%2D2026).). IoMT devices and remote patient monitoring services will certainly be a trend to follow through 2022 as remote healthcare options become ever more popular. ## Data Interoperability Problems with data interoperability were highlighted during the pandemic. Interoperability enables multiple healthcare providers to securely access shared electronic health information. This allows patients to benefit from collaborative healthcare without the need for comprehensive diagnostics and history review each time they consult with a new healthcare professional. Inadequate data sharing slows down access to healthcare and impacts the standard of care provided. The influx of apps collecting valuable patient data has driven the need for enhanced data interoperability, so it is likely to be a top priority for the healthcare industry in 2022. ## Robotic Process Automation (RPA) Chronic medical staff shortages are proving problematic, particularly as the pandemic rumbles on and increases the number of staff sick days being taken. To highlight the scale of the problem, the [World Health Organization (WHO)](https://www.who.int/health-topics/health-workforce#tab=tab_1) has predicted a projected shortfall of 18 million healthcare workers by 2030. Arguably the most promising advancement in healthcare technology is the introduction of Robotic Process Automation (RPA)-powered bots. RPA is widely used in the modern healthcare industry for tasks including appointment scheduling, claims management, and general hospital management. RPA technology is set to transform the healthcare system, helping to combat inefficiencies within the industry. RPA-powered bots can help to streamline the referral process, using AI algorithms to accurately scan patients’ symptoms and refer them to the most appropriate healthcare professional. ## Mental Health Focus The COVID-19 pandemic has exacerbated the already growing mental health crisis in the US. From August 2020 to February 2021, the [CDC](https://www.cdc.gov/mmwr/volumes/70/wr/mm7013e2.htm) reported an increase in adults with recent symptoms of anxiety or a depressive disorder from 36.4% to 41.5%. This worrying increase in mental health conditions brings this issue to the forefront in 2022. Telemedicine and remote patient monitoring offers a breakthrough in this area, widening patient access to mental health services. According to [Rock Health](https://rockhealth.com/insights/2021-year-end-digital-health-funding-seismic-shifts-beneath-the-surface/), digital health startups offering mental health services raised $5.1 billion in 2021, which was $3.3 billion more than any other clinical indication. ## Fintech Integration With healthcare spending set to reach nearly [$6 trillion by 2027](https://www.cms.gov/Research-Statistics-Data-and-Systems/Statistics-Trends-and-Reports/NationalHealthExpendData/Downloads/ForecastSummary.pdf), healthcare organizations are seeking ways to streamline and automate financial processes. Financial technology is seeing rapid evolution, with heavy investment in FinTech startup companies. FinTech solutions simplify processes including insurance claims, finance management, settlement services, and digital payments. Additionally, FinTech offerings can level the playing field when it comes to income inequality, affordability, and access to healthcare. The FinTech space is one to watch in 2022. ## The “No Surprises Act” and The 21st Century Cures Act Two new pieces of federal legislation will be implemented in 2022, both aiming to improve and simplify the patient experience. These acts are likely to set the scene for the healthcare regulatory climate in 2022. The 21st Century Cures Act, which came into effect in 2020, aims to allow “all electronically accessible health information” to be accessed, exchanged, and used “without special effort on the part of the user.” Moving forwards, this must be carefully balanced with the protection of sensitive patient data, ensuring that the 21st Century Cures Act requirements are adhered to in a HIPAA-compliant manner. Effective from January 1st, 2022, the “No Surprises Act” was implemented to protect patients from unexpected medical bills. Surprise bills can often lead to unwanted disputes between healthcare providers and patients. This act covers healthcare accessed through out-of-network doctors and hospitals for both an emergency and non-emergency, as well as air ambulance services from out-of-network providers. ## Atlantic.Net Healthcare Hosting Solutions Atlantic.Net is an award-winning [HIPAA-compliant hosting provider](https://www.atlantic.net/hipaa-compliant-hosting/), with over 30 years worth of experience. We provide effective hosting solutions to an extensive list of leading healthcare clients. [Contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) to find out how, heading through 2022, Atlantic.Net can help your organization to both meet and exceed HIPAA requirements, with a managed or unmanaged hosting solution that is customized to meet the needs of your business. Learn more about our [HIPAA-compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. --- # How to Install Rust Programming Language on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-rust-programming-language-on-oracle-linux-10/ | Published: 2022-07-26 | Updated: 2025-12-28 | Author: Hitesh Jethva Rust is a free and open-source, multi-paradigm, general-purpose programming language developed by Mozilla. It is a server-side programming language designed for performance and safety, especially safe concurrency and memory management. It has direct access to hardware and memory, so it is an ideal language for embedded and bare-metal development. It is used to create a wide range of applications including game engines, operating systems, file systems, browser components, and more. In this post, we will show you how to install Rust programming language on Oracle Linux 10. ## Step 1 – Install Required Dependencies First, you will need to install some required dependencies on your server. You can install all of them by running the following commands: ``` dnf update -y dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-10.noarch.rpm dnf install cmake gcc make curl clang -y ``` Once all the dependencies are installed, you can proceed to the next step. ## Step 2 – Install Rust on Oracle Linux 10 Rust provides an installation script to make the installation process easier. You can run the following command to download and run the Rust installation script: ``` curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh ``` You will be asked to select the installation option as shown below: ``` home directory, located at: /root/.rustup This can be modified with the RUSTUP_HOME environment variable. The Cargo home directory located at: /root/.cargo This can be modified with the CARGO_HOME environment variable. The cargo, rustc, rustup and other commands will be added to Cargo's bin directory, located at: /root/.cargo/bin This path will then be added to your PATH environment variable by modifying the profile files located at: /root/.profile /root/.bash_profile /root/.bashrc You can uninstall at any time with rustup self uninstall and these changes will be reverted. Current installation options: default host triple: x86_64-unknown-linux-gnu default toolchain: stable (default) profile: default modify PATH variable: yes 1) Proceed with installation (default) 2) Customize installation 3) Cancel installation >1 ``` Type 1 and hit Enter to start the installation. Once the installation is complete, you will get the following output: ``` stable-x86_64-unknown-linux-gnu installed - rustc 1.61.0 (fe5b13d68 2022-05-18) Rust is installed now. Great! To get started you may need to restart your current shell. This would reload your PATH environment variable to include Cargo's bin directory ($HOME/.cargo/bin). To configure your current shell, run: source $HOME/.cargo/env ``` After the installation, activate the Rust system path variable using the following command: ``` source ~/.profile source ~/.cargo/env ``` Next, verify the Rust version with the following command: ``` rustc -V ``` You should see the Rust version in the following output: ``` rustc 1.92.0 (ded5c06cf 2025-12-08) ``` ## Step 3 – Create Your First Rust Application At this point, Rust is installed. Now, let’s create a sample application to test the Rust. First, create a directory named project with the following command: ``` mkdir project ``` Next, change the directory to the project and create a sample Rust application with the following command: ``` cd project nano helloworld.rs ``` Add the following code: ``` fn main() { println!("Welcome to Rust!"); } ``` Save and close the file, then compile the program using the following command: ``` rustc helloworld.rs ``` This command will create an executable file in your current directory. Now, run the program with the following command: ``` ./helloworld ``` You should see the following output: ``` Welcome to Rust! ``` ## Step 4 – How to Update Rust Version It is always a good idea to use the latest version of Rust. You can update it using the rustup command: ``` rustup update ``` ## Step 5 – How to Uninstall Rust If you want to remove the Rust from your system, run the following command: ``` rustup self uninstall ``` After the successful uninstall, you will get the following output: ``` Thanks for hacking in Rust! This will uninstall all Rust toolchains and data, and remove $HOME/.cargo/bin from your PATH environment variable. Continue? (y/N) y info: removing rustup home info: removing cargo home info: removing rustup binaries info: rustup is uninstalled ``` ## Conclusion In this post, you learned how to install Rust programming language on Oracle Linux 10. You also learned how to create a sample application using Rust. You can now install Rust in your development environment and start creating your application using the Rust language. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install phpBB with LEMP on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-phpbb-with-lemp-on-oracle-linux-10/ | Published: 2022-07-27 | Updated: 2025-12-28 | Author: Hitesh Jethva phpBB is a free, open-source, easy-to-use, simple, customizable, and powerful flat-forum bulletin board software. It is written in PHP and used by many popular discussion forums online. It supports all major database systems, including MySQL, PostgreSQL, Oracle, and SQLite. It includes a range of style and image packages to customize your board and lets you create a unique forum in minutes. With phpBB, you can make a discussion forum where users can post topics and others can reply to them. In this post, we will show you how to install phpBB with LEMP on Oracle Linux 10. ## Step 1 – Install LEMP Stack First, install the Nginx server with the following command: ``` dnf install nginx -y ``` Once the Nginx package is installed, start and enable the Nginx service with the following command: ``` systemctl start nginx systemctl enable nginx ``` Next, install the latest version of MariaDB server with the following command: ``` dnf install mariadb-server -y ``` Once MariaDB is installed, start and enable the MariaDB service with the following command: ``` systemctl start mariadb systemctl enable mariadb ``` Next, install the PHP, PHP-FPM, and other packages with the following command: ``` dnf install php php-mysqli php-fpm -y ``` Once all the packages are installed, edit the php.ini file and change the default settings: ``` nano /etc/php.ini ``` Change the following values: ``` max_execution_time = 180 max_input_time = 90 memory_limit = 256M upload_max_filesize = 64M ``` Save and close the file, then edit the PHP-FPM configuration file: ``` nano /etc/php-fpm.d/www.conf ``` Change the user and group from apache to nginx: ``` user = nginx group = nginx ``` Save and close the file, then start the PHP-FPM service and enable it to start at system reboot: ``` systemctl start php-fpm systemctl enable php-fpm ``` ## Step 2 – Create a Database for phpBB phpBB uses MariaDB as a database backend, so you will need to create a database and a user for phpBB. First, log in to the MariaDB shell with the following command: ``` mysql ``` Once you are logged in, create a database and user with the following command: ``` CREATE DATABASE phpbb; CREATE USER 'phpbbuser'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the phpbb database with the following command: ``` GRANT ALL ON phpbb.* TO 'phpbbuser'@'localhost' IDENTIFIED BY 'password' WITH GRANT OPTION; ``` Next, flush the privileges to apply the changes: ``` FLUSH PRIVILEGES; ``` Next, exit from the MariaDB shell with the following command: ``` EXIT; ``` ## Step 3 – Install phpBB Next, visit the phpBB official download page and download the latest version of phpBB with the following command: ``` wget https://download.phpbb.com/pub/release/3.3/3.3.15/phpBB-3.3.15.zip ``` Once the download is completed, unzip the downloaded file with the following command: ``` unzip phpBB-3.3.15.zip ``` Next, move the extracted directory to the Nginx web root directory: ``` mv phpBB3 /var/www/html/phpbb ``` Next, set proper permissions and ownership with the following command: ``` chown -R nginx:nginx /var/www/html/phpbb chmod -R 755 /var/www/html/phpbb ``` ## Step 4 – Configure Nginx for phpBB Next, you will need to create an Nginx virtual host configuration file to host phpBB on the Internet. ``` nano /etc/nginx/conf.d/phpbb.conf ``` Add the following lines: ``` server { listen 80; server_name phpbb.example.com; root /var/www/html/phpbb; index index.php index.html index.htm; access_log /var/log/nginx/phpbb-access.log; error_log /var/log/nginx/phpbb-error.log; location / { try_files $uri $uri/ @rewriteapp; # Pass the php scripts to FastCGI server specified in upstream declaration. location ~ \.php(/|$) { include fastcgi.conf; fastcgi_pass unix:/run/php-fpm/www.sock; fastcgi_split_path_info ^(.+\.php)(/.*)$; fastcgi_param PATH_INFO $fastcgi_path_info; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; fastcgi_param DOCUMENT_ROOT $realpath_root; try_files $uri $uri/ /app.php$is_args$args; fastcgi_intercept_errors on; } # Deny access to internal phpbb files. location ~ /(config\.php|common\.php|cache|files|images/avatars/upload|includes|(? URL: https://www.atlantic.net/vps-hosting/how-to-install-memcached-on-oracle-linux-10/ | Published: 2022-07-28 | Updated: 2025-12-28 | Author: Hitesh Jethva Memcached is a free and open-source in-memory caching service. You can use it with your web application to improve performance by caching session data, user authentication tokens, and API responses in memory. It is multithreaded, scales vertically, and enables sharing large amounts of data across multiple application instances. Some major companies, including Facebook, YouTube, and Twitter, use Memcached for caching. In this post, we will show you how to install Memcached on Oracle Linux 10. ## Step 1 – Install Memcached on Oracle Linux 10 The memcached package is included in the Oracle Linux 10 default repo, so you can install it easily by running the following command: ``` dnf install memcached libmemcached -y ``` Once Memcached is installed, you can see the detailed information of Memcached with the following command: ``` rpm -qi memcached ``` Sample output: ``` Name : memcached Epoch : 0 Version : 1.6.23 Release : 7.el10 Architecture: x86_64 Install Date: Sun 28 Dec 2025 11:28:01 PM EST Group : Unspecified Size : 481103 License : BSD-3-clause AND Zlib AND BSD-2-Clause AND LicenseRef-Fedora-Public-Domain Signature : RSA/SHA256, Sat 15 Mar 2025 07:03:10 PM EDT, Key ID bc4d06a08d8b756f Source RPM : memcached-1.6.23-7.el10.src.rpm Build Date : Mon 27 Jan 2025 09:11:08 AM EST Build Host : build-ol10-x86_64.oracle.com Vendor : Oracle America URL : https://www.memcached.org/ Summary : High Performance, Distributed Memory Object Cache Description : memcached is a high-performance, distributed memory object caching system, generic in nature, but intended for use in speeding up dynamic web applications by alleviating database load. ``` ## Step 2 – Manage Memcached Service By default, the Memcached service is managed by systemd. You can use the systemctl command to manage the Memcached service. To start the Memcached service, run the following command: ``` systemctl start memcached ``` To enable the Memcached service to start after the reboot, run the following command: ``` systemctl enable memcached ``` To check the status of the Memcached service, run the following command: ``` systemctl status memcached ``` Sample output: ``` ● memcached.service - memcached daemon Loaded: loaded (/usr/lib/systemd/system/memcached.service; disabled; preset: disabled) Active: active (running) since Sun 2025-12-28 23:28:37 EST; 4s ago Invocation: 19315c2eb96b4d5eb25e50ddbdde155e Main PID: 142733 (memcached) Tasks: 10 (limit: 24812) Memory: 1.8M (peak: 2.1M) CPU: 19ms CGroup: /system.slice/memcached.service └─142733 /usr/bin/memcached -p 11211 -u memcached -m 64 -c 1024 -l 127.0.0.1,::1 Dec 28 23:28:37 oracle systemd[1]: Started memcached.service - memcached daemon. ``` ## Step 3 – Configure Memcached The Memcached default configuration file is located at **/etc/sysconfig/memcached**. You can edit it with the following command: ``` nano /etc/sysconfig/memcached ``` The default configuration is shown below. You can change it per your requirements: ``` PORT="11211" USER="memcached" MAXCONN="1024" CACHESIZE="64" OPTIONS="-l 127.0.0.1,::1" ``` Save and close the file, then restart the Memcached service to apply the changes: ``` systemctl restart memcached ``` ## Step 4 – Install Memcached PHP Extension You can use Memcached as a caching service for all PHP-based applications. To do so, you will need to install the Memcached extension for PHP. You can install the Memcached PHP extensions using the following command: ``` dnf install php-pecl-memcache php-pecl-memcached -y ``` ## Step 5 – Verify Memcached for PHP To verify the Memcached integration with PHP, you will need to install the Nginx web server and PHP package to your server. ``` dnf install nginx php php-cli -y ``` Next, create an**info.php** file with the following command: ``` nano /var/www/html/info.php ``` Add the following code: ``` ``` Save and close the file, then create a symbolic link of info.php file to the Nginx default web root directory: ``` ln -s /var/www/html/info.php /usr/share/nginx/html/ ``` Next, restart the Nginx service to apply the changes: ``` systemctl start nginx ``` Now, open your web browser and type the URL **http://your-server-ip/info.php**. You should see the following page: ![Memcached test page](https://www.atlantic.net/wp-content/uploads/2022/06/p1-3-1024x625.png) As you can see, both Memcache and Memcached PHP extensions are enabled. ## Conclusion In this post, we explained how to install Memcached on Oracle Linux 10. We also explained how to integrate Memcached with PHP applications. You can now use Memcached to speed up your web application. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Python 3.14 on Oracle Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-python-3-14-on-oracle-linux/ | Published: 2022-07-29 | Updated: 2025-12-28 | Author: Hitesh Jethva Python is a free, open-source, powerful, and widely used programming language. It is an object-oriented application used in automation, scripting, data analysis, machine learning, back-end development, handling big data, and performing complex mathematics. It is the first choice for both beginners and experienced developers due to its versatile features. At the time of writing this article, Python 3.14.4 is the latest version of Python. In this post, we will show you how to install Python 3.14 on Oracle Linux 10. ## Step 1 – Install Required Dependencies The latest version of Python is not included in the Oracle Linux 8 default repo, so you will need to compile it from the source. To compile Python from the source, you will need to install some dependencies on your system. You can install all of them by running the following command: ``` dnf install curl gcc openssl-devel bzip2-devel libffi-devel zlib-devel wget make -y ``` Once all the dependencies are installed, you can proceed to the next step. ## Step 2 – Install Python 3.14.4 on Oracle Linux 8 Next, visit the Python official download page and download the latest version of Python using the following command: ``` wger https://www.python.org/ftp/python/3.14.2/Python-3.14.2.tgz ``` Once the download is completed, extract the downloaded file using the following command: ``` tar -xvzf Python-3.14.2.tgz ``` Next, change the directory to the extracted directory and configure Python using the following command: ``` cd Python-3.14.2 ./configure --enable-optimizations ``` Next, start the build process using the following command: ``` make -j 2 nproc ``` Finally, install Python 3.14 by running the following command: ``` make altinstall ``` After the successful installation, verify the Python installation using the following command: ``` python3.14 --version ``` You will get the following output: ``` Python 3.14.2 ``` ## Step 3 – Create a Virtual Environment in Python Python provides a venv module that helps developers to create a virtual environment and deploy applications easily in an isolated environment. To create a virtual environment named python-env, run the following command: ``` python3.14 -m venv python-env ``` Next, activate the virtual environment using the following command: ``` source python-env/bin/activate ``` You will get the following shell: ``` (python-env) [root@oraclelinux10 ~]# ``` Now, you can use the PIP package manager to install any package and dependencies inside your virtual environment. For example, run the following command to install apache-airflow: ``` pip3.14 install apache-airflow ``` If you want to remove this package, run the command below: ``` pip3.14 uninstall apache-airflow ``` To exit from the Python virtual environment, run the following command: ``` deactivate ``` ## Conclusion In this guide, we explained how to install Python 3.14.2 on Oracle Linux 10. You can now install Python in the development environment and start developing your first application using the Python programming language. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Secure PostgreSQL Server on Oracle Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-secure-postgresql-server-on-oracle-linux/ | Published: 2022-07-30 | Updated: 2025-12-28 | Author: Hitesh Jethva PostgreSQL is an open-source, powerful, and high-performance relational database management system. It is gaining popularity due to its robustness, flexibility, and performance. It is used as a database backend for several web, mobile, geospatial, and analytics applications. At the time of writing this article, PostgreSQL 14 is the latest version. This version comes with significant improvements to the indexing and lookup system that benefit large databases. In this post, we will show you how to install and secure PostgreSQL on Oracle Linux 10. ## Step 1 – Add PostgreSQL 18 Repository By default, the latest version of PostgreSQL is not included in the Oracle Linux default repository. So, add the PostgreSQL repo using the command below. ``` dnf install https://download.postgresql.org/pub/repos/yum/reporpms/EL-8-x86_64/pgdg-redhat-repo-latest.noarch.rpm ``` Once the repo is created, you can proceed to the next step. ## Step 2 – Install PostgreSQL 18 on Oracle Linux 10 Now, update your repository using the following command: ``` dnf update -y ``` Next, install the latest version of PostgreSQL by running the following command: ``` dnf install postgresql18 postgresql18-server ``` Once PostgreSQL 18 is installed, you will get the following output: ``` Last metadata expiration check: 0:38:45 ago on Sun 19 Oct 2025 12:53:52 AM EDT. Dependencies resolved. ======================================================================================================================================================================================== Package Architecture Version Repository Size ======================================================================================================================================================================================== Installing: postgresql18 x86_64 18.0-1PGDG.rhel10 pgdg18 2.0 M postgresql18-server x86_64 18.0-1PGDG.rhel10 pgdg18 7.3 M Installing dependencies: postgresql18-libs x86_64 18.0-1PGDG.rhel10 pgdg18 296 k Transaction Summary ======================================================================================================================================================================================== Install 3 Packages Total download size: 7.4 M Installed size: 31 M Is this ok [y/N]: y ``` Next, initialize the PostgreSQL database with the following command: ``` /usr/pgsql-18/bin/postgresql-18-setup initdb ``` Sample output: ``` Initializing database ... OK ``` Next, start the PostgreSQL service and enable it to start at system reboot with the following command: ``` systemctl start postgresql-18 systemctl enable postgresql-18 ``` You can check the status of PostgreSQL with the following command: ``` systemctl status postgresql-18 ``` You should get the following output: ``` ● postgresql-18.service - PostgreSQL 18 database server Loaded: loaded (/usr/lib/systemd/system/postgresql-18.service; disabled; preset: disabled) Active: active (running) since Sun 2025-12-19 01:33:48 EDT; 1s ago Invocation: ef82fd9873da4303b7454ffcf40b2226 Docs: https://www.postgresql.org/docs/18/static/ Process: 12263 ExecStartPre=/usr/pgsql-18/bin/postgresql-18-check-db-dir ${PGDATA} (code=exited, status=0/SUCCESS) Main PID: 12270 (postgres) Tasks: 10 (limit: 24809) Memory: 21.9M (peak: 22.1M) CPU: 62ms CGroup: /system.slice/postgresql-18.service ├─12270 /usr/pgsql-18/bin/postgres -D /var/lib/pgsql/18/data/ ├─12271 "postgres: logger " ├─12272 "postgres: io worker 0" ├─12273 "postgres: io worker 2" ├─12274 "postgres: io worker 1" ├─12275 "postgres: checkpointer " ├─12276 "postgres: background writer " ├─12278 "postgres: walwriter " ├─12279 "postgres: autovacuum launcher " └─12280 "postgres: logical replication launcher " ``` By default, PostgreSQL listens on port 5432. You can check it with the following command: ``` ss -antpl | grep 5432 ``` You will get the following output: ``` LISTEN 0 128 127.0.0.1:5432 0.0.0.0:* users:(("postmaster",pid=36417,fd=7)) LISTEN 0 128 [::1]:5432 [::]:* users:(("postmaster",pid=36417,fd=6)) ``` ## Step 3 – Set a Password for Postgres User By default, the password of the Postgres user is not set, so it is recommended to set a password for security reasons. To set a password, log in to PostgreSQL with the following command: ``` su - postgres ``` Next, set a secure password with the following command: ``` psql -c "alter user postgres with password 'securepassword'" ``` Next, exit from the PostgreSQL shell using the following command: ``` exit ``` ## Step 4 – Change PostgreSQL Authentication Method By default, PostgreSQL is configured to use the peer method for local connections. However, this method is not recommended for production environments. It is recommended to change the authentication method from **peer** to **scram-sha-256**. You can change it by editing the PostgreSQL main configuration file: ``` nano /var/lib/pgsql/18/data/pg_hba.conf ``` Find the following line: ``` local all all peer ``` And, replace it with the following line: ``` local all all scram-sha-256 ``` Save and close the file, then restart the PostgreSQL service to apply the changes. ``` systemctl restart postgresql-18 ``` ## Step 5 – Create a Database and User in PostgreSQL First, log in to the PostgreSQL shell with the following command: ``` sudo -u postgres psql ``` You will get the following output: ``` could not change directory to "/root": Permission denied psql (18.4) Type "help" for help. postgres=# ``` Next, create a new PostgreSQL user named user1 using the following command: ``` CREATE USER user1 WITH CREATEDB CREATEROLE PASSWORD 'passoword'; ``` To verify the PostgreSQL users, run: ``` \du ``` You will get the following output: ``` List of roles Role name | Attributes | Member of -----------+------------------------------------------------------------+----------- postgres | Superuser, Create role, Create DB, Replication, Bypass RLS | {} user1 | Create role, Create DB | {} ``` To create a new PostgreSQL database named user1db, run: ``` CREATE DATABASE user1db OWNER user1; ``` To verify the PostgreSQL databases, run: ``` \l ``` You will get the following output: ``` List of databases Name | Owner | Encoding | Collate | Ctype | Access privileges -----------+----------+----------+-------------+-------------+----------------------- postgres | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | template0 | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | =c/postgres + | | | | | postgres=CTc/postgres template1 | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | =c/postgres + | | | | | postgres=CTc/postgres user1db | user1 | UTF8 | en_US.UTF-8 | en_US.UTF-8 | ``` ## Conclusion In this post, we explained how to install and use PostgreSQL on Oracle Linux 10. You can now use PostgreSQL as the primary data store for your web application. For security reasons, it is always recommended to install the latest version of PostgreSQL in the production environment. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Manage Java Versions on Oracle Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-manage-java-versions-on-oracle-linux/ | Published: 2022-07-31 | Updated: 2025-12-28 | Author: Hitesh Jethva Java is an open-source, powerful, and widely used programming language. It is used to build web-based applications, games, chatbots, enterprise applications, and more. It is cross-platform and can be run on all operating systems. You will require an IDE on your system to develop Java applications. OpenJDK or Oracle JDK offers the Java package. Java JDK is a free, open-source, and powerful software development environment for developing Java Applications. JDK is a collection of programming tools, including Javac, JRE, Jar, and Java. This post will show you how to install and manage different Java versions on Oracle Linux 10. ## Install OpenJDK 25 When writing this article, the latest version of Java OpenJDK is version 18. The newest version is unavailable in the Oracle Linux 8 default repository, so you must install it from the source. First, update your Operating System, and then download the latest version of OpenJDK from the Java official website: ``` dnf update -y ``` ``` wget https://download.java.net/java/GA/jdk25.0.1/2fbf10d8c78e40bd87641c434705079d/8/GPL/openjdk-25.0.1_linux-x64_bin.tar.gz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar -xvf openjdk-25.0.1_linux-x64_bin.tar.gz ``` Next, move the extracted directory to the /opt directory: ``` mv jdk-25.0.1 /opt/ ``` Next, you must add the Java source path to the system environment. You can do it by creating the file java.sh: ``` nano /etc/profile.d/java.sh ``` Add the following lines: ``` export JAVA_HOME=/opt/jdk-25.0.1 export PATH=$PATH:$JAVA_HOME/bin ``` Save and close the file, then activate the Java path using the following command: ``` source /etc/profile.d/java.sh ``` Next, verify the Java path using the following command: ``` echo $JAVA_HOME ``` Sample output: ``` /opt/jdk-25.0.1 ``` You can also verify the Java version using the following command: ``` java --version ``` You will get the following result: ``` openjdk 25.0.1 2025-10-21 OpenJDK Runtime Environment (build 25.0.1+8-27) OpenJDK 64-Bit Server VM (build 25.0.1+8-27, mixed mode, sharing) ``` ## Install OpenJDK 21 By default, OpenJDK 11 is available in the Oracle Linux default repository. You can install it using the following command: ``` dnf install java-21-openjdk-devel -y ``` ## Install Oracle JDK 25 When writing this article, the latest version of Oracle JDK is 18. First, you will need to download it from its official website: ``` wget https://download.oracle.com/java/25/latest/jdk-25_linux-x64_bin.rpm ``` Once the download is completed, you can install it using the following command: ``` rpm -ivh jdk-25_linux-x64_bin.rpm ``` You will get the following output: ``` Verifying... ################################# [100%] Preparing... ################################# [100%] Updating / installing... 1:jdk-25-2000:25.0.1-8 ################################# [100%] ``` Next, verify the Java version using the following command: ``` java --version ``` ## Manage Java Versions Java also allows you to install and manage multiple Java versions in the same system. You can use the “alternatives –config java” command to switch between various Java versions easily: ``` alternatives --config java ``` You will be asked to set the default Java versions as shown below: ``` There are 2 programs which provide 'java'. Selection Command ----------------------------------------------- 1 /usr/lib/jvm/java-21-openjdk/bin/java *+ 2 /usr/lib/jvm/jdk-25.0.1-oracle-x64/bin/java Enter to keep the current selection[+], or type selection number: 1 ``` Select your preferred option and hit Enter to set the default Java version. ## Conclusion This post explained how to install OpenJDK 25, 21, and Oracle JDK 25 on Oracle Linux 10. You also learned how to manage and switch between different Java versions. You can now start developing a Java application using your preferred Java version. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Top 10 Best PCI Compliance Training Services > URL: https://www.atlantic.net/pci-compliant-hosting/top-10-best-pci-compliance-training-services/ | Published: 2022-08-01 | Updated: 2025-09-15 | Author: Richard Bailey Getting your business prepared for PCI Compliance is a significant challenge because the Payment Card Industry is one of the most heavily regulated across the globe. Without PCI-DSS (Payment Card Industry Data Security Standard) compliance, growing businesses will not be authorized to process payments from the major players in finance. The rules are strict, and the penalties for those who violate its rules are firm, which is why many turn to PCI Compliance Training Services to get their employees certified and ready before embarking on the PCI-DSS journey. ## What Makes a Business PCI-Compliant? There are loads of different types of standards that must be met, but the security of IT systems is arguably the most important. To quickly recap, there are twelve requirements that businesses must achieve to become PCI-DSS Compliant: - The implementation of strict firewall controls to control network traffic. - Ensure all vendor-supplied system passwords are changed from the default. - Protect all digitally held cardholder data (such as encryption). - Protect the transmission of cardholder data across open or public networks. - Protect all systems against malware, ransomware, and viruses. - Develop and maintain secure systems and applications (patching & vulnerabilities) - Restrict access to cardholder data on a need-to-know basis. - Identify and authenticate access to system components. - Restrict physical access to cardholder data. - Monitor and log access to network resources and cardholder data. - Regularly test security systems and processes (pen tests and social engineering). - Maintain a policy that addresses information security for all personnel (training). PCI Compliance is important to modern digital businesses wanting to digitally process payments for goods and services. Do you need additional training on PCI Compliance to understand the wide range of requirements? Atlantic.Net has created this **Top 10 PCI Compliance Training Services** to help you navigate through the complex world of the Payment Card Industry’s necessary compliance. ## Top 10 PCI Compliance Training Services ### 1. PCI Security Standards Council Training The PCI Council is the official office for PCI compliance, so what better way to learn the complexities of compliance than from the council that defined the rules? The PCI Council provides an eLearning platform to help businesses control costs and gain tangible, real-world insights into the best practices of PCI standards. The four-hour course costs about $500 per seat, and it was created to help users understand PCI compliance before going through an assessment. The completion of the course helps to satisfy PCI DSS Requirement 12.6 for general security awareness education for employees. ### 2. VISTA InfoSec VISTA is a global assured compliance business that features industry-leading PCI compliance services that include the very latest PCI-DSS revision version 4.0. PCI-DSS was only released at the end of March 2022, and the training on offer is designed to help existing PCI-DSS 3.2.1 holders transition to PCI-DSS 4.0 or train newcomers directly on the requirements of 4.0. The training offers a program for all personnel and covers only what is in the scope of their specific responsibilities. This tailor-made program teaches relevant employees what is needed to fulfill their role, helping the training to remain focused on individual development. ### 3. SecurityMetrics SecurityMetrics offers independent PCI Compliance training to help business employees understand all PCI-DSS requirements. The course provides detailed training on PCI-DSS Compliance, including PCI basics, how to write policies and procedures, PANscan (Card Data Discovery), PCI Secure for merchants, and more. The diverse number of courses on offer cover all aspects of compliance and can be used as a foundation for achieving official PCI Compliance certification. ### 4. Discover Global Network Discover Global is part of the wider organization Discover Financial Services, a business responsible for processing millions of cardholder transactions every day. What better way than to learn from a provider who secures transactions day-in-day-out? They work directly with the PCI Council to provide eLearning and instructor-led courses. The courses are designed to get individuals certified as PCI specialists in PCI Internal Security Assessor (ISA), Payment Card Industry Professional (PCIP), and Qualified Integrator and Reseller (QIR). These official qualifications will help employees deepen their understanding of PCI-DSS. ### 5. Inspired eLearning Inspired eLearning offers 2 core training programs that concentrate on ensuring employees are well equipped when working in a PCI-compliant industry. They provide engaging and high-quality content that aims to help change business culture so it is PCI-Ready. The two courses are PCI Essentials for Account Data Handlers and Supervisors and PCI Requirements Overview for IT Professionals. Each course educates the user to understand what PCI is, how to comply with PCI and enforce security such as fraud prevention, understanding POS devices, and the most command attack vectors used by cybercriminals. ### 6. Ready Training Online (RTO) RTO focuses on providing PCI Compliance training to retailers and merchants directly. The training focuses on how retailers can defend against card cloning and compromise credit card accounts. It teaches employees how to protect and secure chip and pin devices and protect against IT data breaches. ### 7. Academia Compliance Academia Compliance is part of the VISTA infosec security community, and they offer specific courses related to PCI Compliance. Training is available via online self-learning or via the classroom at the businesses’ expense, perfect for anyone looking to become certified as a Certified PCI Compliance Specialist (CPCS). ### 8. CFISA The Center for Information Security Awareness (CFISA) features numerous security training programs, including courses for PCI compliance. CFISA’s Employee PCI Level I and Level II training courses are designed to empower your employees to protect organization and customer data. ### 9. Udemy PCI DSS Courses Online training is growing in popularity, and platforms like Udemy offer a large number of PCI-DSS training programs. All training is online video delivered in bite-sized modules. It does require the individual to dedicate the time required to complete the course, but affords a lot of flexibility on when the training is completed. The user is then responsible to book the relevant certification exam to be taken separately. ### 10. Navex Navex provides engaging video content eLearning for business employees. The training covers the fundamental basics, and the audience is generally users who may perhaps process card payments (such as shop workers). NAVEX’s Payment Card Industry data security standards basics course give learners an overview of their obligations under the PCI DSS. The course also outlines measures employees can take to protect sensitive cardholder data and prevent data security breaches. ## How Can Atlantic.Net Help? Reliable partners and service providers play a crucial role in ensuring PCI compliance is maintained. Atlantic.Net is SOC 2 and SOC 3 certified, HIPAA and HITECH audited, PCI-DSS compliant, and regularly audited for security. Atlantic.Net’s team has extensive experience helping businesses with PCI-compliant hosting environments. [Contact our team today](https://www.atlantic.net/about-us/corporate-contact/) to get started on a custom [PCI-Compliant Hosting Solution](https://www.atlantic.net/pci-compliant-hosting/) for your business! --- # How to Install Anaconda Python Distribution on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-anaconda-python-distribution-on-oracle-linux-10/ | Published: 2022-08-02 | Updated: 2025-12-28 | Author: Hitesh Jethva Anaconda is a free and open-source package manager of the Python and R programming languages. Anaconda is used to develop software for data science, machine learning, big data processing, scientific computing, and predictive analytics. It is cross-platform and can be installed on several operating systems including Windows, Linux, and macOS. It is very popular among data science professionals as it allows them to install and manage Python dependencies in a single installation easily. It comes with a fantastic collection of scientific Python packages, tools, resources, and IDEs. In this post, we will show you how to install Anaconda Python Distribution on Oracle Linux 10. ## Step 1 – Download Anaconda Installer Script First, visit the Anaconda official download page and download the latest version of the Anaconda Python installation script using the following command: https://www.anaconda.com/products/individual ``` wget https://repo.anaconda.com/archive/Anaconda3-2025.12-1-Linux-x86_64.sh ``` Once the Anaconda installer is downloaded, create the sha256 cryptographic hash of the installer file using the command below: ``` sha256sum Anaconda3-2025.12-1-Linux-x86_64.sh ``` You will get the following output: ``` 132f1f312d05e391906b959ad83aa411b97ece55966bb34df011ef41ba60a35c Anaconda3-2025.12-1-Linux-x86_64.sh ``` Next, compare the above result to the hashes available on the [Anaconda](https://docs.anaconda.com/anaconda/install/hashes/) website. If the result matches, you can proceed to the next step. ## Step 2 – Install Anaconda on Oracle Linux 8 Next, run the Anaconda installer script to install Anaconda on your system. ``` bash Anaconda3-2025.12-1-Linux-x86_64.sh ``` You will be asked to accept the License terms as shown below: ``` Welcome to Anaconda3 2025.12-1 In order to continue the installation process, please review the license agreement. Please, press ENTER to continue Do you accept the license terms? [yes|no] [no] >>> yes ``` Type yes and hit Enter. You will be asked to proceed with initialization: ``` Downloading and Extracting Packages: Preparing transaction: done Executing transaction: done installation finished. Do you wish to update your shell profile to automatically initialize conda? This will activate conda on startup and change the command prompt when activated. If you'd prefer that conda's base environment not be activated on startup, run the following command when conda is activated: conda config --set auto_activate_base false Note: You can undo this later by running `conda init --reverse $SHELL` Proceed with initialization? [yes|no] [no] >>> yes no change /root/anaconda3/condabin/conda no change /root/anaconda3/bin/conda no change /root/anaconda3/bin/conda-env no change /root/anaconda3/bin/activate no change /root/anaconda3/bin/deactivate no change /root/anaconda3/etc/profile.d/conda.sh no change /root/anaconda3/etc/fish/conf.d/conda.fish no change /root/anaconda3/shell/condabin/Conda.psm1 no change /root/anaconda3/shell/condabin/conda-hook.ps1 no change /root/anaconda3/lib/python3.13/site-packages/xontrib/conda.xsh no change /root/anaconda3/etc/profile.d/conda.csh modified /root/.bashrc ==> For changes to take effect, close and re-open your current shell. <== Thank you for installing Anaconda3! ``` Now, activate the Anaconda installation using the following command: ``` source ~/.bashrc ``` You will get the Anaconda shell in the following output: ``` (base) [root@oraclelinux10 ~]# ``` ## Step 3 – Verify Anaconda Installation After the successful installation, you can verify the Anaconda installation using the following command: ``` conda info ``` You will get the following output: ``` active environment : base active env location : /root/anaconda3 shell level : 1 user config file : /root/.condarc populated config files : /root/anaconda3/.condarc conda version : 25.11.0 conda-build version : 25.11.1 python version : 3.13.9.final.0 solver : libmamba (default) virtual packages : __archspec=1=haswell __conda=25.11.0=0 __cuda=0=0 __glibc=2.39=0 __linux=6.12.0=0 __unix=0=0 base environment : /root/anaconda3 (writable) conda av data dir : /root/anaconda3/etc/conda conda av metadata url : None channel URLs : https://repo.anaconda.com/pkgs/main/linux-64 https://repo.anaconda.com/pkgs/main/noarch https://repo.anaconda.com/pkgs/r/linux-64 https://repo.anaconda.com/pkgs/r/noarch package cache : /root/anaconda3/pkgs /root/.conda/pkgs envs directories : /root/anaconda3/envs /root/.conda/envs platform : linux-64 user-agent : conda/25.11.0 requests/2.32.5 CPython/3.13.9 Linux/6.12.0-101.33.4.3.el10uek.x86_64 oracle/10.0 glibc/2.39 solver/libmamba conda-libmamba-solver/25.11.0 libmambapy/2.3.2 aau/0.7.5 c/. s/. e/. UID:GID : 0:0 netrc file : None offline mode : False ``` You can see a list of all packages available in Anaconda using the following command: ``` conda list ``` You should see all packages in the following output: ``` # packages in environment at /root/anaconda3: # # Name Version Build Channel _ipyw_jlab_nb_ext_conf 0.1.0 py39h06a4308_1 _libgcc_mutex 0.1 main _openmp_mutex 4.5 1_gnu aiohttp 3.8.1 py39h7f8727e_1 aiosignal 1.2.0 pyhd3eb1b0_0 alabaster 0.7.12 pyhd3eb1b0_0 anaconda 2022.05 py39_0 anaconda-client 1.9.0 py39h06a4308_0 anaconda-navigator 2.1.4 py39h06a4308_0 ``` ## Step 4 – Update Anaconda Anaconda provides a conda utility to update the Anaconda package. First, run the following command to update the conda utility to the latest version. ``` conda update conda ``` You will get the following output: ``` The following packages will be downloaded: package | build ---------------------------|----------------- ca-certificates-2025.12.2 | h06a4308_0 125 KB conda-25.11.1 | py313h06a4308_0 1.2 MB ------------------------------------------------------------ Total: 1.3 MB The following packages will be UPDATED: ca-certificates 2025.11.4-h06a4308_0 --> 2025.12.2-h06a4308_0 conda 25.11.0-py313h06a4308_0 --> 25.11.1-py313h06a4308_0 Proceed ([y]/n)? y ``` Next, update Anaconda with the following command: ``` conda update anaconda ``` ## Step 5 – Create an Environment Using Anaconda Anaconda provides an easier way to create an environment to organize projects based on Python versions. To create a new environment named conda_env, run the following command: ``` conda create --name conda_env python=3 ``` After creating an environment, activate the environment using the following command: ``` conda activate conda_env ``` You will get the following shell: ``` (conda_env) [root@oraclelinux10 ~]# ``` Next, verify the Python version using the following command: ``` python --version ``` You will get the following output: ``` Python 3.14.2 ``` To list all your environments, run the following command: ``` conda info --envs ``` You should see the following output: ``` # conda environments: # base /root/anaconda3 conda_env * /root/anaconda3/envs/conda_env ``` To deactivate from the Anaconda environment, run the following command: ``` conda deactivate ``` To remove the conda_env, run the following command: ``` conda env remove -n conda_env ``` Sample output: ``` Remove all packages in environment /root/anaconda3/envs/conda_env: ``` ## Step 6 – Uninstall Anaconda To uninstall Anaconda from your system, you will need to install the anaconda-clean utility on your system. You can install it using the following command: ``` conda install anaconda-clean ``` Once installed, you will get the following output: ``` ## Package Plan ## environment location: /root/anaconda3 added / updated specs: - anaconda-clean The following packages will be downloaded: package | build ---------------------------|----------------- anaconda-clean-1.1.1 | py39h06a4308_0 8 KB ------------------------------------------------------------ Total: 8 KB The following NEW packages will be INSTALLED: anaconda-clean pkgs/main/linux-64::anaconda-clean-1.1.1-py39h06a4308_0 Proceed ([y]/n)? y ``` Next, run the following command to uninstall Anaconda from your system. ``` anaconda-clean ``` You will get the following output: ``` Delete .conda? (y/n): y Backup directory: /root/.anaconda_backup/2022-06-22T114720 ``` Next, remove all files and directories created by Anaconda using the following command: ``` rm -rf ~/.condarc ~/.conda ~/.continuum ``` Next, edit the .bashrc file and remove all lines added by Anaconda: ``` nano ~/.bashrc ``` Remove the following lines: ``` # >>> conda initialize >>> # !! Contents within this block are managed by 'conda init' !! __conda_setup="$('/root/anaconda3/bin/conda' 'shell.bash' 'hook' 2> /dev/null)" if [ $? -eq 0 ]; then eval "$__conda_setup" else if [ -f "/root/anaconda3/etc/profile.d/conda.sh" ]; then . "/root/anaconda3/etc/profile.d/conda.sh" else export PATH="/root/anaconda3/bin:$PATH" fi fi unset __conda_setup # <<< conda initialize <<< ``` Save and close the file when you are finished. ## Conclusion In this post, we learned how to install Anaconda on Oracle Linux 10. You also learned how to manage Python using the Anaconda For more information, visit the Anaconda [documentation](https://docs.anaconda.com/anaconda/index.html) page. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # The Importance of Disaster Recovery During Rising Global Tensions and War > URL: https://www.atlantic.net/disaster-recovery/the-importance-of-disaster-recovery-during-rising-global-tensions-and-war/ | Published: 2022-08-03 | Updated: 2025-09-15 | Author: Richard Bailey Disaster recovery and business continuity are key business strategies designed to protect critical data and ensure vital IT operations are kept running in a disaster scenario. The recent conflict in Ukraine has brought war to Europe’s borders for the first time since 1945. The conflict has reminded everyone that disaster can strike when you least expect it. Nobody thought Russia would start a war, but the last five months have been a stark reminder that unexpected events can happen at any time. Rising global tensions and the outbreak of war have forced businesses and governments around the globe to refocus and rethink their disaster recovery strategy, with many questioning what would happen if their organization were in this situation. ## What Is Happening in Ukraine? On Thursday 24th February 2022, the Russian Federation led by Vladimir Putin defied international law and invaded Ukraine. Overnight the geopolitical landscape changed forever, and despite global outrage and crippling sanctions, the war is still raging today. An estimated 12 million people have been displaced, seeking refuge in neighboring EU states, with around 100,000 making it to the United States. The latest estimates suggest that at least 11,000 Ukrainian soldiers and 8000 civilians have been killed. The country’s infrastructure has been bombarded by Russian artillery and sustained over [$100 billion of damage](https://news.un.org/en/story/2022/03/1114022). Key IT and Telecom services have been targeted in Kyiv, Kharkiv, and Odesa. ## What Has Happened to Ukrainian Data? There are [34 colocation](https://www.datacentermap.com/ukraine/)data centers located in Ukraine. Most are hosted in and around Kyiv and are primarily used by public/private sector businesses and the Ukrainian government. Like most developed countries, Ukraine’s infrastructure is embedded in data. When Russia attacked, they launched large-scale cyberattacks against Ukrainian utilities, and some of the very first cruise missile attacks targeted government data centers. Ukraine’s government acted quickly to sustain civil and military operations by migrating digital infrastructure into the cloud, where it has been hosted in data centers across Europe including Poland, Estonia, and France. ## What was Ukraine’s Disaster Recovery Strategy? The threat to Ukrainian data was identified before the war started. They knew that having disaster recovery capabilities would strengthen their hand. Ukraine amended key data privacy laws to allow data to be moved away from sovereign data centers and into friendly neighboring countries. This was highlighted by Victor Zhora, a Ukrainian government data protection officer, who told the Wall Street Journal, “In case of emergency, we need to make sure our IT systems continue operating.” Ukraine has worked directly with global-scale cloud providers to move critical data into the cloud. As the conflict continues in its fourth month, [AWS has reportedly transferred](https://www.aboutamazon.com/news/aws/safeguarding-ukraines-data-to-preserve-its-present-and-build-its-future) 10 petabytes of data from 27 Ukrainian ministries, 18 Ukrainian universities, and dozens of other private sector companies. Microsoft Azure had been working directly with Ukrainian ministries, [spending $100 million](https://www.itpro.co.uk/security/cyber-attacks/367752/microsoft-provides-over-100-million-in-support-to-ukraine-government) in tech support to help the Ukrainian government move data from on-premise and into the cloud. ## The Importance of Establishing Multiple Sites because of Global Tensions and Wars The situation in Ukraine has demonstrated the immense unpredictability of global tensions, as 12 months ago no one thought Ukraine would be in this situation. Ukraine fights for its survival on the battlefield and in the digital world, illustrating the importance of having disaster recovery capabilities and a plan B for critical data infrastructure. It is essential to have a multi-site strategy so that your data will survive the next war or any other natural catastrophe. While the United States is a long way from being directly involved in the war in Ukraine, other disasters are much more likely, such as hurricanes, floods, earthquakes, and tornadoes, not to mention the risk of another major terrorist attack. ## Is Your Data The Lifeline of Your Business? Data is a valuable commodity in today’s digital world, and protecting data from being destroyed is not only essential but also required by legislation in many cases. Businesses combat this threat by leveraging disaster recovery technology and business continuity processes and procedures. Every business is different, but the requirement is the same: to preserve data – the lifeline of your business. Data backup is key to preserving data. A robust backup strategy ensures that all critical systems are backed up frequently with data being replicated offsite, perhaps overseas if legislation permits it. Technical disaster recovery solutions are available that will automatically recover critical services in an alternative location. This could be between two data centers or two countries. Local storage and compute infrastructure are synchronized between two or more locations, businesses have a primary data center where everyday business operations take place, and cloud technology replicates all data and all changes across to a secondary site. When disaster strikes, the failover of infrastructure to the secondary site takes place, and within a few minutes, normal service is restored. Needless to say, it’s more complicated in reality than it sounds, but the principle is the same. Testing disaster recovery is essential (preferably bi-annually) to ensure the entire process is as smooth as possible. ## Will Your Business Survive? DR aims to keep your business functioning, and the glue that helps keep all this together is the disaster recovery plan (DRP). A DRP is a pre-designed and rehearsed plan of precisely what needs to happen in the event a disaster is declared. The Disaster Recovery Plan aims to define: - What is a Disaster Recovery scenario? - When to Declare a Disaster - How to invoke Disaster Recovery - Who to contact and how communication flows during a DR Scenario - Description of key roles and responsibilities of anyone assigned to the recovery team - Instructions on how to keep the business running in the event of a disaster - Recovery Time Objectives – how long can the business operate? - Recovery Point Objectives – from what point can data be recovered? - Define a recovery process and flowchart of activities - Post DR activities (such as route cause analysis) - Continuously test and evolve the DR plan If you want to know more about what a DRP is and how each one of these steps should be defined, you can find all the information you need on our [Disaster Recovery Whitepaper](https://www.atlantic.net/resources/documents/whitepapers/pdf/hipaa-disaster-recovery-atlantic-net-whitepaper.pdf) for Healthcare. ## What Steps Can Be Taken? Atlantic.Net has been providing disaster recovery services to our clients for decades. We have a fantastic selection of healthcare clients bound by legislation demanding disaster recovery capabilities. The data must be available at all times, and we achieve this by leveraging state-of-the-art hardware and following industry-accredited policies, processes, and procedures. We have a wide range of [data center locations](https://www.atlantic.net/hipaa-data-centers/) to choose from, and our experts are available to discuss the best options of where to store your data. [Data backup](https://www.atlantic.net/vps-hosting/how-to-enable-cloud-backups/) and [Snapshot](https://www.atlantic.net/vps-hosting/creating-and-managing-snapshots/) managed services are available to ensure the highest levels of data protection. As commerce moves more and more online, business data is becoming a gold standard. Take advantage of a full suite of [managed services](https://www.atlantic.net/managed-services/) today to protect your business from the unexpected. --- # Scalable Hosting > URL: https://www.atlantic.net/vps-hosting/scalable-hosting/ | Published: 2022-08-05 | Updated: 2025-09-15 | Author: Alexander Wise One of the key benefits of cloud computing is having the ability to scale your infrastructure on-demand. Cloud scalability gives the user the ability to provide more and less computing resources when needed. A managed service provider hosting platform will typically scale-up, scale out, and scale in; this is sometimes referred to as vertical and horizontal scaling. Choosing a [hosting provider](https://www.atlantic.net/hosting-services-provider/) that offers such solutions will help your organization grow seamlessly, whether your business model expects to grow rapidly or steadily over time. Scaling introduces more affordable options for the desired web solutions. Scalability gives companies countless options when it comes to meeting the demand for computing resources. ## What Is Scalable Cloud Hosting? When computing resources can be scaled, they add a unique layer of flexibility to businesses that experience unexpected growth. Scalability also gives the ability to decrease on-demand services too, with many businesses scaling back resources out of hours and over weekends to introduce cost savings. Here are some examples of scalable hosting solutions: - **Scale Up:** Scaling up adds additional resources to cloud applications. This typically involves adding extra virtual private servers (VPS) to a virtual cluster. The cluster of multiple servers usually sits behind an application load balancer that operates on a round-robin to send user requests to different servers in the cluster. This greatly improves the application’s bandwidth and offers a seamless experience to the user. - **Scale-Out:** Scaling out keeps the same server, but adds resources to the existing configuration. This is usually the first step businesses will take to improve performance. Additional CPU, Disk Space, and Memory are added to improve performance. - **Scale In:** Scaling in is the opposite of scaling out; resources on the same server are reduced when not needed. Scaling in usually results in downtime and the VPS will always need to be rebuilt. In most circumstances, it is more beneficial to destroy the existing server and rebuild it from a snapshot or backup. ## How Does Scalable Cloud Hosting Work? Vertical and horizontal scalable hosting service plans are designed to either distribute server load between additional servers or by upgrading the existing virtual server. As a result, if the website is experiencing more visitors and traffic than normal, additional resources can be deployed to endure the increased traffic. Scalability ensures your website will always be up and running. Scaling introduces significant cost savings, making it much more affordable than other types of hosting. Scalable hosting plans are ideal for growing businesses, and there is no need to speed big on more expensive hosting plans or purchase additional hardware. Scaled hosting services can be adapted as you grow, and you can even make the transition to a cloud-hosted dedicated physical server when the time is right. The services that can be scaled vary from provider to provider. Choosing a cloud provider that offers scalable hosting will allow you to add more SSD storage/block storage disk space, RAM, CPU, and bandwidth at any time. Additional resources are added by creating new cloud instances or by using the provider’s hosting plans. Hosting plans are available for general-purpose instances, storage-optimized, memory-optimized, and compute-optimized plans. Extra resources are available via the provider’s cloud control panel. Configuring software-defined auto-scaling offers additional protection and immediate access to pre-provisioned virtual machine resources. Auto-scaling load balancing will handle any unexpected traffic spikes or loads on the server. Software-defined auto-scaling is an automatic process. It works by defining specific parameters, for example, a CPU metric that alerts if the server load is sustained at over 95% for 15 minutes; once this parameter is met, auto-scaling will kick in. The software will allocate pre-defined additional resources to meet the increase in traffic and usage on your website. ## What Is Cloud Web Hosting? [Cloud Hosting](https://www.atlantic.net/vps-hosting/what-is-cloud-hosting/) is typically the provisioning of a Virtual Private Server (VPS) upon a cloud provider’s infrastructure. It is a viable alternative to dedicated server hosting and empowers the user to take advantage of the latest cloud technology backed by redundant systems. [Many clients prefer VPS for hosting](https://www.atlantic.net/vps-hosting/what-can-you-do-with-a-vps-and-cloud-server/) to a physical machine because they get the same full root access and administrative server control as they would with a dedicated machine without incurring the additional costs associated with running a dedicated environment. What sets cloud hosting apart from old-fashioned VPSes is the speed, agility, reliability, and affordability of a cloud VPS. Cloud hosting services interconnect with existing cloud computing infrastructure, providing managed services such as managed backups and managed KMS, not to mention the availability of around-the-clock technical support. Cloud hosting works through customized virtualization technology that splits the vendor’s physical servers into multiple virtual machines. Virtual machines are called cloud [VPS](https://www.atlantic.net/vps-hosting/) servers and have access to the provider’s cloud network, making it super simple to host a website. ## Key Features Cloud Hosting is extremely popular and the industry is growing rapidly. This is because of the key features on offer that include: **Guaranteed Resources:** The best Cloud VPS providers guarantee system resources without the need for a dedicated host. If you purchase a plan with 4 vCPU and 8GB of Memory, that is exactly what you get. The hosting provider carves up host resources and locks them to your VPS. **Additional Managed Services:** Cloud VPS platforms include high availability configurations and access to other Cloud Services such as onsite and offsite daily backups, snapshots, and secure block storage. **Additional Managed Security:** Take advantage of a comprehensive suite of managed security features including DDoS protection, a secure content delivery network, encrypted SSH access, and more. **Managed Security:** Cloud VPS servers are built into stringent security best practices. All servers have root access (or Windows Administrator) privileges enabled and available upon launch. Choose a Cloud Hosting provider that combines simplicity, security, and scalability with the reliability of the latest virtualization and cloud hosting platform technology. **Scalability:** Scale-up resources when needed, and only pay for what is used. The pay-as-you-go model used in cloud hosting gives users the flexibility to cancel at any time with no commitments, saving you significant time and money. **One-Click Applications:** Choose your Operating System, Application, and disk space configuration using automation. Simply select what you want and the system resources needed, then hit deploy. If you need to scale up, simply snapshot your server, upgrade your hosting plan and recover the snapshot. The entire process takes no time at all. ## Cloud Hosting Benefits The hosting provider manages the entire cloud stack, relinquishing the need for an on-site IT department or experienced developers to manage and maintain it, empowering the customer to focus on using the platform. The provider is responsible for software provisioning, security patching, and any issues encountered while also achieving a 100% service level agreement and high performance throughout the host infrastructure. **High availability:** The provider’s core infrastructure is created in a highly redundant and high availability setup. The provider’s data center facilities will feature a minimum of N+1 availability, this includes at least dual power feeds, generator backup, and redundant bandwidth from multiple comms providers. Block Storage service is fail-safe, providing RAID10 protection in the disk layer, but also RAID protection in the infrastructure management layer. **Scalable solutions:** Add resources to business services at a moment’s notice, giving your users more power and more control over cloud resources. Add resources to scale on-demand directly from the provider’s management website. **Traffic load balancing:** Ensure your website and network resources are consistently available regardless of demand. **Faster performance:** Even basic VPS servers offer fantastic performance for your company. Only the latest hardware is used, and host policies ensure that each host is never overloaded, altogether making for happy customers and a great user experience. **Affordable prices:** Cost is a major focus for business finances, so it’s important to choose not only an affordable cloud company but also one that provides great service and support to its customers. **24x7x365 Support:** Choose a hosting business that will provide advice and support around the clock. ## Conclusion In this post, we explained what scalable hosting is and how you can achieve business growth with it. If you want to get scalable web hosting for your website, you can try out [Atlantic.Net](https://www.Atlantic.Net)‘s cloud platform. [Atlantic.Net](https://www.Atlantic.Net) has more than 30 years of experience in the web hosting industry and currently serves customers in over 100 countries from eight global data center regions in London, New York, Ashburn, Orlando, Dallas, San Francisco, Singapore, and Toronto. Over the last 30 years, we have consistently grown our digital footprint, allowing us to evolve as a technology leader trusted by thousands of businesses. We pride ourselves on the dedication and commitment of our workforce who have traveled with us on this incredible journey. We have weathered three recessions and are currently in a strong position to face the latest expected financial depression, thanks to our sound business principles and focus on growing a profitable company, with little to no debt. We have been developing world-class facilities and adapting and changing our business processes throughout our history. As a result, our customer base has continued to grow rapidly, year on year. We help businesses around the world master their technology requirements and realize their digital transformation vision for today and the future. Our technology and dynamic support teams are what make [Atlantic.Net](https://www.Atlantic.Net) stand out from the competition. The credit goes to our engineers, who have designed, created, and now support the cloud infrastructure 24x7x365. Their dedicated work keeps our servers, secure blob storage, network interconnects, and managed service offerings running to the highest of standards. We partner with global leaders in the cloud infrastructure procurement industry, allowing us to create an infrastructure that not only outperforms the competition in real-world testing but offers 100% uptime guarantees, great value, and a satisfying ROI. [Atlantic.Net](https://www.Atlantic.Net) is a trusted hosting provider that delivers excellent uptime, robust security features, and reliable customer support. In addition, all its hosting plans are scalable and can help your website grow. ## **Need help with Scalable Cloud Hosting?** **Atlantic.Net can help with all your cloud hosting needs!** Whether you need a scalable cloud hosting platform or a customized dedicated solution; Atlantic.Net stands ready to help you craft a scalable and affordable solution for you. When it comes to security and compliance, Atlantic.Net has got you covered too with [HIPAA hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [PCI-ready hosting](https://www.atlantic.net/pci-compliant-hosting/). For more information, please email sales@atlantic.net ## About HostAdvice [HostAdvice](https://hostadvice.com/) is a hosting solutions comparison engine that offers expert comparisons on web hosting providers based on unbiased user reviews. Since 2014, they have received over 65,000 user reviews and have written more than 4,000 expert reviews, and those numbers are growing every day. They also help businesses and individuals find a hosting solutions provider that best suits their needs and offers the best prices and reliability. Their experts also provide all kinds of how-to articles and guides on numerous tech-related topics that you can read on their website whenever you want. --- # How to Install Fail2ban with Firewalld on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-fail2ban-with-firewalld-on-oracle-linux-10/ | Published: 2022-08-08 | Updated: 2025-12-28 | Author: Hitesh Jethva Fail2ban is a free and open-source firewall software solution that protects your server from brute-force login attacks. It is an intrusion prevention framework that continuously monitors log files of different services, detects failed authentication, and blocks attacks using firewalld or iptables. Fail2ban blocks the attacker’s IP permanently or temporarily via the configuration file. It also sends you an email notification whenever an attack is occurring. It is primarily used for SSH attacks, however, it can be configured to work for any service that uses log files. In this guide, we will show you how to install Fail2ban with firewalld on Oracle Linux 10. ## Step 1 – Configure Firewalld By default, Firewalld comes pre-installed in the Oracle Linux 10. You can check whether it is installed or not using the following command: ``` dnf info firewalld ``` If the Firewalld is installed, you will get the following output: ``` License : GPL-2.0-or-later Description : firewalld is a firewall service daemon that provides a dynamic customizable : firewall with a D-Bus interface. Available Packages Name : firewalld Version : 2.3.1 Release : 1.0.1.el10_0 Architecture : noarch Size : 884 k Source : firewalld-2.3.1-1.0.1.el10_0.src.rpm Repository : ol10_baseos_latest Summary : A firewall daemon with D-Bus interface providing a dynamic firewall URL : http://www.firewalld.org License : GPL-2.0-or-later Description : firewalld is a firewall service daemon that provides a dynamic customizable : firewall with a D-Bus interface. ``` Next, verify whether Firewalld is running or not. ``` systemctl status firewalld ``` You should see that the Firewalld service is masked: ``` ● firewalld.service - firewalld - dynamic firewall daemon Loaded: loaded (/usr/lib/systemd/system/firewalld.service; disabled; vendor preset: enabled) Active: inactive (dead) Docs: man:firewalld(1) ``` You will need to unmask the Firewalld service. You can unmask it using the following command: ``` systemctl unmask firewalld ``` Next, start the Firewalld service and enable it to start at system reboot: ``` systemctl start firewalld systemctl enable firewalld ``` ## Step 2 – Install Fail2Ban By default, the Fail2ban package is not included in the Oracle Linux 10 default repo, so you will need to install the EPEL repo to your system. Run the following command to install the EPEL repo: ``` dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-10.noarch.rpm ``` Next, run the following command to install the Fail2ban package on your server: ``` dnf install fail2ban fail2ban-firewalld -y ``` Once Fail2ban is installed, start and enable the Fail2ban service using the following command: ``` systemctl start fail2ban systemctl enable fail2ban ``` You can also verify the Fail2ban version using the following command: ``` fail2ban-client --version ``` Sample output: ``` Fail2Ban v1.1.0 ``` ## Step 3 – Configure Fail2Ban By default, Fail2ban is configured to use Iptables firewall, so you will need to configure Fail2ban to work with Firewalld. First, rename the Firewalld configuration file for Fail2ban using the following command: ``` mv /etc/fail2ban/jail.d/00-firewalld.conf /etc/fail2ban/jail.d/00-firewalld.local ``` Next, copy the Fail2ban default configuration file: ``` cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local ``` Next, edit the jail.local file: ``` nano /etc/fail2ban/jail.local ``` Find the following lines: ``` banaction = iptables-multiport banaction_allports = iptables-allports ``` And replace them with the following lines: ``` banaction = firewallcmd-rich-rules[actiontype=] banaction_allports = firewallcmd-rich-rules[actiontype=] ``` Save and close the file, then restart Fail2ban to apply the changes: ``` systemctl restart fail2ban ``` At this point, Fail2ban is configured to work with Firewalld. ## Step 4 – Secure SSH Service with Fail2Ban By default, Fail2ban is not configured to block any IP addresses. You will need to enable the specific jail for each service you want to protect. To protect the SSHD service, edit the jail.local file: ``` nano /etc/fail2ban/jail.local ``` Find the [sshd] section and enable it by adding the following lines: ``` [sshd] enabled = true port = ssh logpath = %(sshd_log)s backend = %(sshd_backend)s bantime = 10m findtime = 10m maxretry = 5 ``` Save and close the file, then restart Fail2ban to apply the changes: ``` systemctl restart fail2ban ``` You can now verify the Fail2ban status using the following command: ``` systemctl status fail2ban ``` You will get the following output: ``` ● fail2ban.service - Fail2Ban Service Loaded: loaded (/usr/lib/systemd/system/fail2ban.service; disabled; vendor preset: disabled) Active: active (running) since Tue 2025-12-28 07:32:46 EDT; 3s ago Docs: man:fail2ban(1) Process: 3887 ExecStop=/usr/bin/fail2ban-client stop (code=exited, status=0/SUCCESS) Process: 3924 ExecStartPre=/bin/mkdir -p /run/fail2ban (code=exited, status=0/SUCCESS) Main PID: 3925 (fail2ban-server) Tasks: 5 (limit: 11409) Memory: 17.1M CGroup: /system.slice/fail2ban.service └─3925 /usr/bin/python3.6 -s /usr/bin/fail2ban-server -xf start ``` ## Step 5 – Verify Fail2ban Firewall At this point, Fail2ban is configured to protect the SSH service. Now, it’s time to check whether Fail2ban works. First, verify the jail configuration using the following command: ``` fail2ban-client status ``` You should see the following output: ``` Status |- Number of jail: 1 `- Jail list: sshd ``` Now, go to the remote machine and try to connect to the SSH server with an incorrect password. After reaching the maxretry “5” times, your IP address will be blocked by Fail2Ban. Now, check the IP address blocked by Fail2ban using the following command: ``` fail2ban-client status sshd ``` You should get the following output: ``` Status for the jail: sshd |- Filter | |- Currently failed: 1 | |- Total failed: 6 | `- Journal matches: _SYSTEMD_UNIT=sshd.service + _COMM=sshd `- Actions |- Currently banned: 1 |- Total banned: 1 `- Banned IP list: 10.61.187.115 ``` You can check the rules added by Firewalld with the following command: ``` firewall-cmd --list-rich-rules ``` You will get the following output: ``` rule family="ipv4" source address="10.61.187.115" port port="ssh" protocol="tcp" reject type="icmp-port-unreachable" ``` You can also check the Fail2ban logs for more information: ``` tail -f /var/log/fail2ban.log ``` Sample output: ``` 2025-12-28 03:31:28,152 fail2ban.actions [46482]: WARNING [sshd] 167.71.68.39 already banned 2025-12-28 03:31:28,152 fail2ban.actions [46482]: WARNING [sshd] 206.189.96.43 already banned 2025-12-28 03:31:28,152 fail2ban.actions [46482]: NOTICE [sshd] Ban 144.31.253.70 2025-12-28 03:31:28,425 fail2ban.actions [46482]: WARNING [sshd] 167.71.68.39 already banned 2025-12-28 03:31:28,425 fail2ban.actions [46482]: WARNING [sshd] 206.189.96.43 already banned ``` ## Conclusion In this post, we explained how to install Fail2ban with Firewalld on Oracle Linux 10. We also explained how to protect SSH service using Fail2Ban. You can now implement Fail2ban on your server to protect it against brute-force login attacks. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Config Server Firewall (CSF) on Oracle Linux 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-config-server-firewall-csf-on-oracle-linux-8/ | Published: 2022-08-09 | Updated: 2024-09-25 | Author: Hitesh Jethva CSF or “Config Server Firewall” is a web-based and command-line firewall tool for Linux and Unix operating systems. It offers a simple, easy-to-use, advanced web-based interface to configure and manage firewall settings. CSF comes with Login Failure Daemon (LFD) to view user activity due to excessive login failures. If a large number of login failures are seen coming from the same IP address, that IP will immediately be temporarily blocked from all services on your server. CSF can defend your server against many types of attacks like port scans, SYN floods, and login brute force attacks on many services. In this post, we will show you how to install and configure the CSF firewall on Oracle Linux 8. ## Step 1 – Install CSF on Oracle Linux 8 CSF is written in Perl, so you will need to install all the required Perl modules on your system. You can install all of them with the following command: ``` dnf update -y dnf install @perl perl-libwww-perl.noarch perl-LWP-Protocol-https.noarch bind-utils net-tools -y ``` After installing all the required modules, download the latest version of CSF using the following command: ``` wget https://download.configserver.com/csf.tgz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar xzf csf.tgz ``` Next, navigate to the extracted directory and install the CSF with the following command: ``` cd csf sh install.sh ``` Once CSF is installed, you will get the following output: ``` Don't forget to: 1. Configure the following options in the csf configuration to suite your server: TCP_*, UDP_* 2. Restart csf and lfd 3. Set TESTING to 0 once you're happy with the firewall, lfd will not run until you do so Adding current SSH session IP address to the csf whitelist in csf.allow: Adding 27.61.171.115 to csf.allow only while in TESTING mode (not iptables ACCEPT) *WARNING* TESTING mode is enabled - do not forget to disable it in the configuration 'lfd.service' -> '/usr/lib/systemd/system/lfd.service' 'csf.service' -> '/usr/lib/systemd/system/csf.service' Created symlink /etc/systemd/system/multi-user.target.wants/csf.service → /usr/lib/systemd/system/csf.service. Created symlink /etc/systemd/system/multi-user.target.wants/lfd.service → /usr/lib/systemd/system/lfd.service. Created symlink /etc/systemd/system/firewalld.service → /dev/null. '/etc/csf/csfwebmin.tgz' -> '/usr/local/csf/csfwebmin.tgz' Installation Completed ``` Next, verify if all the required iptables modules are available. ``` dnf install perl -y perl /usr/local/csf/bin/csftest.pl ``` If everything is fine, you will get the following output: ``` Testing ip_tables/iptable_filter...OK Testing ipt_LOG...OK Testing ipt_multiport/xt_multiport...OK Testing ipt_REJECT...OK Testing ipt_state/xt_state...OK Testing ipt_limit/xt_limit...OK Testing ipt_recent...OK Testing xt_connlimit...OK Testing ipt_owner/xt_owner...OK Testing iptable_nat/ipt_REDIRECT...OK Testing iptable_nat/ipt_DNAT...OK RESULT: csf should function on this server ``` You can now check the CSF version using the following command: ``` csf -v ``` You will get the following output: ``` *WARNING* URLGET set to use LWP but perl module is not installed, fallback to using CURL/WGET csf: v14.16 (generic) *WARNING* TESTING mode is enabled - do not forget to disable it in the configuration ``` ## Step 2 – Configure CSF By default, CSF’s main configuration file is located at /etc/csf/csf.conf. You will need to edit and change all settings per your requirements: ``` nano /etc/csf/csf.conf ``` Change TESTING = “1” to TESTING = “0” and add allowed incoming and outgoing ports per your requirements: ``` # lfd will not start while this is enabled TESTING = "0" # Allow incoming TCP ports TCP_IN = "20,21,22,25,53,80,110,143,443,465,587,993,995" # Allow outgoing TCP ports TCP_OUT = "20,21,22,25,53,80,110,113,443,587,993,995" ``` Save and close the file when you are finished. Then, start and enable the CSF and LFD services: ``` systemctl start csf lfd systemctl enable csf lfd ``` You can check the status of CSF with the following command: ``` systemctl status csf ``` You should see the following output: ``` ● csf.service - ConfigServer Firewall & Security - csf Loaded: loaded (/usr/lib/systemd/system/csf.service; enabled; vendor preset: disabled) Active: active (exited) since Tue 2022-06-28 10:52:28 EDT; 6s ago Process: 8973 ExecStart=/usr/sbin/csf --initup (code=exited, status=0/SUCCESS) Main PID: 8973 (code=exited, status=0/SUCCESS) Tasks: 0 (limit: 11409) Memory: 0B CGroup: /system.slice/csf.service Jun 28 10:52:27 oraclelinux8 csf[8973]: csf: FASTSTART loading UDP_IN (IPv4) Jun 28 10:52:27 oraclelinux8 csf[8973]: csf: FASTSTART loading UDP_OUT (IPv4) Jun 28 10:52:27 oraclelinux8 csf[8973]: ACCEPT all opt -- in lo out * 0.0.0.0/0 -> 0.0.0.0/0 Jun 28 10:52:28 oraclelinux8 csf[8973]: ACCEPT all opt -- in * out lo 0.0.0.0/0 -> 0.0.0.0/0 Jun 28 10:52:28 oraclelinux8 csf[8973]: LOGDROPOUT all opt -- in * out !lo 0.0.0.0/0 -> 0.0.0.0/0 Jun 28 10:52:28 oraclelinux8 csf[8973]: LOGDROPIN all opt -- in !lo out * 0.0.0.0/0 -> 0.0.0.0/0 Jun 28 10:52:28 oraclelinux8 csf[8973]: csf: FASTSTART loading DNS (IPv4) Jun 28 10:52:28 oraclelinux8 csf[8973]: LOCALOUTPUT all opt -- in * out !lo 0.0.0.0/0 -> 0.0.0.0/0 Jun 28 10:52:28 oraclelinux8 csf[8973]: LOCALINPUT all opt -- in !lo out * 0.0.0.0/0 -> 0.0.0.0/0 Jun 28 10:52:28 oraclelinux8 systemd[1]: Started ConfigServer Firewall & Security - csf. ``` You can also check the ports that are open when CSF is running using the following command: ``` csf -p ``` Sample output: ``` Ports listening for external connections and the executables running behind them: Port/Proto Open Conn PID/User Command Line Executable 22/tcp 4/- 1 (916/root) /usr/sbin/sshd -D -oCiphers=aes256-g... /usr/sbin/sshd 80/tcp 4/- - (2799/caddy) /usr/bin/caddy run --environ --confi... /usr/bin/caddy 323/udp -/- - (559/chrony) /usr/sbin/chronyd /usr/sbin/chronyd ``` ## Step 3 – How to Use CSF To flush all CSF rules, run the following command: ``` csf -f ``` To reload the CSF firewall, run the following command: ``` csf -r ``` To allow incoming connections from a specific IP, run the following command: ``` csf -a remote-ip-address ``` To deny connections from a specific IP, run the following command: ``` csf -d remote-ip-address ``` You can also edit the csf.deny and csf.allow file to define the list of allowed and denied IPs on the firewall. ## Step 4 – Enable CSF UI CSF also provides a web-based interface to manage the firewall. It is disabled by default. Before enabling CSF UI, install the required modules with the following command: ``` dnf install perl-IO-Socket-SSL perl-Net-SSLeay perl-IO-Socket-INET6 perl-Socket -y ``` Next, edit the CSF configuration file: ``` nano /etc/csf/csf.conf ``` Enable the UI, define the listening port, set the admin username and password as shown below: ``` # 1 to enable, 0 to disable web ui UI = "1" # Set port for web UI. The default port is 6666, but # I change this to 1025 to easy access. Default port create some issue # with popular chrome and firefox browser (in my case) UI_PORT = "8080" # Leave blank to bind to all IP addresses on the server UI_IP = "" # Set username for authetnication UI_USER = "admin" # Set a strong password for authetnication UI_PASS = "securepassword" UI_ALLOW = "0" ``` Save and close the file, then restart the CSF and LFD service to apply the changes: ``` systemctl restart lfd systemctl restart csf ``` ## Step 5 – Access CSF UI Now, open your web browser and access the CSF UI using the URL https://your-server-ip:8080. You should see the CSF login page: ![CSF login page](https://www.atlantic.net/wp-content/uploads/2022/06/p1-5-1024x369.png) Provide your admin username and password and click on the **Login** button. You should see the CSF web interface on the following screen: ![CSF dashboard page](https://www.atlantic.net/wp-content/uploads/2022/06/p2-5-1024x508.png) ## Step 6 – Remove CSF Firewall If you want to remove the CSF firewall completely from your server, just run the following script: ``` bash /etc/csf/uninstall.sh ``` This will remove the CSF firewall with all files, directories, and rules created by CSF. ## Conclusion In the above guide, we explained how to install CSF and CSF UI on Oracle Linux 8. We also explained how to ban and unban specific IP addresses with CSF. You can now implement CSF to your server and secured it from the various type of attacks. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install FTP Server with ProFTPD on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-ftp-server-with-proftpd-on-oracle-linux-10/ | Published: 2022-08-10 | Updated: 2025-12-28 | Author: Hitesh Jethva ProFTPd is a free, open-source, popular FTP server for the Linux operating system. It is used to transfer files from one server to another over the network. ProFTPd is simple, easy to install, highly configurable, secured, and specially designed for web hosting environments. It is famous for its flexibility and security. ProFTPD also supports FTP over TLS, so the connection is encrypted using TLS/SSL. **Features** - Supports IPv4 and IPv6. - Supports per-directory “.ftpaccess” configuration. - Allows configuring multiple virtual FTP servers and anonymous FTP services. - Configured to run as a stand-alone server or from inetd/xinetd. - Supports shadow password suite. In this post, we will show you how to install the ProFTPD FTP server on Oracle Linux 10. ## Step 1 – Install ProFTPD By default, ProFTPD is not included in the Oracle Linux default repo, so you will need to install the EPEL repo to your system. You can install it using the following command: ``` dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-10.noarch.rpm ``` Once the EPEL repository is installed, run the following command to install the ProFTPD package: ``` dnf install proftpd -y ``` After the installation, start the ProFTPD service and enable it to start at system reboot: ``` systemctl start proftpd systemctl enable proftpd ``` You can verify the status of ProFTPD using the following command: ``` systemctl status proftpd ``` You will get the following output: ``` ● proftpd.service - ProFTPD FTP Server Loaded: loaded (/usr/lib/systemd/system/proftpd.service; disabled; vendor preset: disabled) Active: active (running) since Tue 2025-12-28 11:36:39 EDT; 7s ago Process: 17085 ExecStartPre=/usr/sbin/proftpd --configtest (code=exited, status=0/SUCCESS) Main PID: 17086 (proftpd) Tasks: 1 (limit: 11409) Memory: 28.1M CGroup: /system.slice/proftpd.service └─17086 proftpd: (accepting connections) ``` You can verify the ProFTPD version using the following command: ``` proftpd -v ``` You will get the following output: ``` ProFTPD Version 1.3.9 ``` ## Step 2 – Create an FTP User Next, you will need to create a user for FTP. You can create a new user named **ftpuser** with the following command: ``` useradd ftpuser ``` Next, set a password for **ftpuser** using the command below: ``` passwd ftpuser ``` Set the password as shown below: ``` Changing password for user ftpuser. New password: Retype new password: passwd: all authentication tokens updated successfully. ``` Next, log in to ftpuser with the following command: ``` su - ftpuser ``` Next, create some files and directories using the following command: ``` touch file1 file2 mkdir sun mon tue ``` Next, exit from ftpuser with the following command: ``` exit ``` ## Step 3 – Access ProFTPD Server There are two ways to access the FTP server: using a command-line and or an FTP client. ### Access FTP Via Command Line On the remote machine, open the command-line interface and run the following command to connect to the ProFTPD server. ``` ftp proftpd-ip ``` You will be asked to provide your FTP username and password: ``` Connected to proftpd-ip. 220 FTP Server ready. Name (proftpd-ip:vyom): ftpuser 331 Password required for ftpuser Password: ``` Once you are connected, you should get the following output: ``` 230 User ftpuser logged in Remote system type is UNIX. Using binary mode to transfer files. ``` Now, run the following command to list all files and directories on the FTP server: ``` ftp> ls ``` You will get the following output: ``` 229 Entering Extended Passive Mode (|||17093|) 150 Opening ASCII mode data connection for file list -rw-rw-r-- 1 ftpuser ftpuser 0 Dec 28 15:38 file1 -rw-rw-r-- 1 ftpuser ftpuser 0 Dec 28 15:38 file2 drwxrwxr-x 2 ftpuser ftpuser 6 Dec 28 15:39 mon drwxrwxr-x 2 ftpuser ftpuser 6 Dec 28 15:39 sun drwxrwxr-x 2 ftpuser ftpuser 6 Dec 28 15:39 tue 226 Transfer complete ``` ### Access FTP Via FTP Client Open the FileZilla FTP client and click on the **Site manager** to create a new FTP connection: ![Open filezilla connection manager](https://www.atlantic.net/wp-content/uploads/2022/06/p1-6.png) Provide your FTP server IP, username, and password and click on the **connect** button. Once you are connected, you should see the following screen: ![FTP connection established](https://www.atlantic.net/wp-content/uploads/2022/06/p2-6-1024x563.png) ## Conclusion In this post, you learned how to install the ProFTPD FTP server on Oracle Linux 10. You also learned how to access FTP via command-line and FTP client. You can now set up an FTP server on your production server to download and upload website pages. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Use PIP Python Package Manager on Oracle Linux > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-pip-python-package-manager-on-oracle-linux/ | Published: 2022-08-11 | Updated: 2025-12-28 | Author: Hitesh Jethva Python is a free, open-source, high-level programming language used by thousands of developers worldwide. PIP is a Preferred Installer Program for installing and managing additional Python packages via the command line. PIP makes it easier to manage complete lists of packages and corresponding version numbers. PIP is a standard package manager that connects to an online repository of public packages called the Python Package Index, and allows users to install user-defined projects locally with the use of a setup.py file. In this post, we will explain how to install and use PIP on Oracle Linux 10. ## Step 1 – Install PIP on Oracle Linux 10 Before installing PIP, Python must be installed on your server. If not installed, you can install it by running the following commands: ``` dnf update -y ``` ``` dnf install python3 -y ``` After the installation, you can verify the Python version using the following command: ``` python3 --version ``` You should get the following output: ``` Python 3.12.9 ``` Next, install PIP using the following command: ``` dnf install python3-pip -y ``` Once PIP is installed, you can verify the installed version of PIP using the following command: ``` pip3 --version ``` You should see the following output: ``` pip 23.3.2 from /usr/lib/python3.12/site-packages/pip (python 3.12) ``` ## Step 2 – How to Update PIP It is a good idea to update PIP to the latest version. You can update it using the following command: ``` pip3 install --upgrade pip ``` You should see the following output: ```  Downloading pip-25.3-py3-none-any.whl.metadata (4.7 kB) Downloading pip-25.3-py3-none-any.whl (1.8 MB) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 1.8/1.8 MB 38.7 MB/s eta 0:00:00 Installing collected packages: pip Successfully installed pip-25.3 ``` You can now verify the PIP version again using the following command: ``` pip3 --version ``` You should see the following output: ``` pip 25.3 from /usr/local/lib/python3.12/site-packages/pip (python 3.12) ``` ## Step 3 – How to Use PIP To see a list of all important options available with PIP, use the following command: ``` pip3 --help ``` You should see the following output: ``` Usage: pip3 [options] Commands: install Install packages. download Download packages. uninstall Uninstall packages. freeze Output installed packages in requirements format. list List installed packages. show Show information about installed packages. check Verify installed packages have compatible dependencies. config Manage local and global configuration. search Search PyPI for packages. cache Inspect and manage pip's wheel cache. wheel Build wheels from your requirements. hash Compute hashes of package archives. completion A helper command used for command completion. debug Show information useful for debugging. help Show help for commands. ``` To install a specific package, run the following command: ``` pip3 install wheel ``` To get detailed information about the installed package, run the following command: ``` pip3 show wheel ``` You will get the following output: ``` Please see https://github.com/pypa/pip/issues/5599 for advice on fixing the underlying issue. To avoid this problem you can invoke Python with '-m pip' instead of running pip directly. Name: wheel Version: 0.45.1 Summary: A built-package format for Python Home-page: https://github.com/pypa/wheel Author: Daniel Holth Author-email: dholth@fastmail.fm License: MIT Location: /usr/local/lib/python3.12/site-packages Requires: Required-by: ``` To get a list of all installed packages, run the following command: ``` pip3 list ``` You should see the following output: ``` Package Version ------------------- ------- configobj 5.0.6 configshell-fb 1.1.28 dbus-python 1.2.4 decorator 4.2.1 fail2ban 0.11.2 gpg 1.13.1 isc 2.0 kmod 0.1 libcomps 0.1.16 ``` To get a list of all outdated packages, run the following command: ``` pip3 list --outdated ``` You should see the following output: ``` Package Version Latest Type ------------------------- --------- ------------ ----- attrs 23.2.0 25.4.0 wheel cffi 1.16.0 2.0.0 wheel charset-normalizer 3.3.2 3.4.4 wheel configobj 5.0.8 5.0.9 wheel configshell-fb 1.1.30 2.0.2 wheel cryptography 43.0.0 46.0.3 wheel dbus-python 1.3.2 1.4.0 sdist file-magic 0.4.0 0.4.1 wheel idna 3.7 3.11 wheel jsonpointer 2.3 3.0.0 wheel jsonschema 4.19.1 4.25.1 wheel jsonschema-specifications 2023.11.2 2025.9.1 whee ``` To uninstall a specific package from your system, run the following command: ``` pip3 uninstall wheel ``` ## Conclusion In the above article, we explained how to install and use PIP on Oracle Linux 10. We also showed you how to manage Python packages with PIP. You can now easily use PIP to manage the Python dependencies. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Configure Caddy Web Server with PHP on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-caddy-web-server-with-php-on-oracle-linux-10/ | Published: 2022-08-12 | Updated: 2025-12-28 | Author: Hitesh Jethva Caddy is a free, open-source web server used to host websites and applications on the internet. It is a simple, lightweight, modern web server written in the Go language. Caddy can be used as a file server, dynamic server, and scalable reverse proxy. It offers a lot of plugins that help you to extend the server functionality. Caddy offers a rich set of features including HTTP/2 support, virtual hosting support, Let’s Encrypt SSL support, a dependency-free codebase, and more. In this post, we will show you how to install the Caddy web server with PHP support on Oracle Linux 10. ## Step 1 – Install Caddy Web Server on Oracle Linux 10 By default, the Caddy package is not included in the Oracle Linux 10 default repo, so you will need to enable the special repository on your system. ``` dnf install 'dnf-command(copr)' dnf copr enable @caddy/caddy ``` Once the repository is enabled, you can install the Caddy web server with the following command: ``` dnf install caddy -y ``` Once Caddy is installed, verify the Caddy version using the following command: ``` caddy version ``` Sample output: ``` v2.10.2 ``` Next, start the Caddy service and enable it to start at system reboot: ``` systemctl start caddy systemctl enable caddy ``` You can also check the status of the Caddy service using the following command: ``` systemctl status caddy ``` You should see the following output: ``` ● caddy.service - Caddy Loaded: loaded (/usr/lib/systemd/system/caddy.service; disabled; vendor preset: disabled) Active: active (running) since Tue 2025-12-28 07:07:28 EDT; 7s ago Docs: https://caddyserver.com/docs/ Main PID: 1784 (caddy) Tasks: 5 (limit: 11409) Memory: 14.5M CGroup: /system.slice/caddy.service └─1784 /usr/bin/caddy run --environ --config /etc/caddy/Caddyfile ``` Now, open your web browser and access the Caddy web server using the URL **http://your-server-ip**. You should see the Caddy test page on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2022/08/o1.png) ## Step 2 – Create a Simple Website Using Caddy First, create a directory structure for the new website using the following command: ``` mkdir -p /var/www/example.com mkdir /var/log/caddy ``` Next, set proper ownership to the new website: ``` chown -R caddy:caddy /var/www/example.com chown -R caddy:caddy /var/log/caddy ``` Next, create an index.html page for a new website: ``` nano /var/www/example.com/index.html ``` Add the following HTML codes: ``` Caddy Web Server

Congratulations! Caddy Web Server Works on Oracle Linux 10

``` Save and close the file when you are finished. ## Step 3 – Create a Virtual Host Configuration File Next, you will need to edit the Caddy default configuration file to host the new website. You can edit it with the following command: ``` nano /etc/caddy/Caddyfile ``` Remove all lines and add the following lines: ``` test.example.com:80 { root * /var/www/example.com file_server encode gzip log { output file /var/log/caddy/example.access.log } @static { file path *.ico *.css *.js *.gif *.jpg *.jpeg *.png *.svg *.woff *.pdf *.webp } header @static Cache-Control max-age=5184000 } ``` Save and close the file when you are finished. Next, validate the Caddy configuration file: ``` caddy validate --adapter caddyfile --config /etc/caddy/Caddyfile ``` You should see the following output: ``` 2025/12/28 07:40:17.733 INFO using config from file {"file": "/etc/caddy/Caddyfile"} 2025/12/28 07:40:17.734 INFO adapted config to JSON {"adapter": "caddyfile"} 2025/12/28 07:40:17.734 WARN Caddyfile input is not formatted; run 'caddy fmt --overwrite' to fix inconsistencies {"adapter": "caddyfile", "file": "/etc/caddy/Caddyfile", "line": 2} 2025/12/28 07:40:17.735 WARN http.auto_https server is listening only on the HTTP port, so no automatic HTTPS will be applied to this server {"server_name": "srv0", "http_port": 80} 2025/12/28 07:40:17.735 INFO tls.cache.maintenance started background certificate maintenance {"cache": "0xc000608500"} 2025/12/28 07:40:17.735 INFO http servers shutting down with eternal grace period 2025/12/28 07:40:17.735 INFO tls.cache.maintenance stopped background certificate maintenance {"cache": "0xc000608500"} Valid configuration ``` Next, restart the Caddy service to apply the changes: ``` systemctl restart caddy ``` You can also check the Caddy service using the following command: ``` systemctl status caddy ``` You will get the following output: ``` ● caddy.service - Caddy Loaded: loaded (/usr/lib/systemd/system/caddy.service; disabled; vendor preset: disabled) Active: active (running) since Tue 2025-12-28 07:12:22 EDT; 8s ago Docs: https://caddyserver.com/docs/ Main PID: 1812 (caddy) Tasks: 5 (limit: 11409) Memory: 12.6M CGroup: /system.slice/caddy.service └─1812 /usr/bin/caddy run --environ --config /etc/caddy/Caddyfile ``` Now, open your web browser and access the Caddy website using the URL **http://test.example.com**. You should see your website on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2022/08/o2.png) ## Step 4 – Enable PHP Support on Caddy Web Server To enable PHP support on Caddy, PHP must be installed on your server. You can install PHP and other required extensions using the following command: ``` dnf install php-fpm php-cli php-gd -y ``` Once all the packages are installed, edit the Caddy configuration file: ``` nano /etc/caddy/Caddyfile ``` Define the php_fastcgi location as shown below: ``` test.example.com:80 { root * /var/www/example.com php_fastcgi unix//run/php-fpm/www.sock file_server encode gzip log { output file /var/log/caddy/example.access.log } @static { file path *.ico *.css *.js *.gif *.jpg *.jpeg *.png *.svg *.woff *.pdf *.webp } header @static Cache-Control max-age=5184000 } ``` Save and close the file, then restart the Caddy service: ``` systemctl restart caddy ``` Next, edit the PHP-FPM file: ``` nano /etc/php-fpm.d/www.conf ``` Change the following lines: ``` user = caddy group = caddy listen.acl_users = apache,nginx,caddy ``` Save and close the file, then start the PHP-FPM service and enable it to start at system reboot: ``` systemctl start php-fpm systemctl enable php-fpm ``` Next, create a sample info.php page: ``` nano /var/www/example.com/info.php ``` Add the following line: ``` ``` Save and close the file, then open your web browser and access the info.php page using the URL **http://test.example.com/info.php**. You will get the following page: ![](https://www.atlantic.net/wp-content/uploads/2022/08/o3.png) ## Conclusion In the above post, you learned how to install Caddy with PHP on Oracle Linux 10. You can now use Caddy on your production environment to deploy a website and test its performance. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install OTRS on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-otrs-on-oracle-linux-10/ | Published: 2022-08-15 | Updated: 2025-12-28 | Author: Hitesh Jethva OTRS, which stands for “Open Ticket Request System,” is a free, open-source, web-based ticketing system used by many companies to improve operations related to customer support, help desk, call center, etc. Written in Perl, OTRS offers a beautiful dashboard that helps customers to register and create a ticket via a web browser. If you are looking for an open-source ticketing system, then OTRS is the best choice for you. In this post, we will show you how to install OTRS on Oracle Linux 10. ## Step 1 – Install Required Packages Before we start, you will need to install the EPEL repository and other dependencies on your system. You can install all those packages by running the following command: ``` dnf update -y dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-10.noarch.rpm dnf install gcc expat-devel procmail mod_perl perl perl-core -y ``` ## Step 2 – Install Apache and MariaDB Next, you will need to install the Apache and MariaDB servers on your system. You can install both using the following command: ``` dnf install httpd mariadb-server mysql-devel -y ``` Once both packages are installed, start the Apache and MariaDB services and enable them to start during the system reboot: ``` systemctl start httpd mariadb systemctl enable httpd mariadb ``` Next, edit the MariaDB configuration file: ``` nano /etc/my.cnf.d/mariadb-server.cnf ``` Add the following lines inside the [mysqld] section: ``` max_allowed_packet=256M character-set-server=utf8 collation-server=utf8_general_ci innodb_buffer_pool_size=4G innodb_log_file_size=1G ``` Save and close the file, then restart the MariaDB service to apply the changes: ``` systemctl restart mariadb ``` ## Step 3 – Create a Database and User First, log in to MySQL. ``` mysql ``` Then, create a database and user for OTRS. ``` CREATE DATABASE otrs CHARACTER SET utf8 COLLATE utf8_unicode_ci; CREATE USER 'otrs'@'localhost' IDENTIFIED BY 'SecurePassword'; ``` Next, grant privilege to OTRS and apply the changes: ``` GRANT ALL PRIVILEGES ON otrs.* TO 'otrs'@'localhost'; FLUSH PRIVILEGES; ``` Next, exit from the MySQL. ``` EXIT; ``` ## Step 4 – Download and Install OTRS First, create a dedicated user to run OTRS using the following command: ``` useradd otrs ``` Next, add the OTRS user to the Apache group using the following command: ``` usermod -G apache otrs ``` Next, download the latest version of OTRS using the following command: ``` wget https://otrscommunityedition.com/download/otrs-community-edition-6.0.41.zip ``` Once OTRS is downloaded, unzip the downloaded file with the following command: ``` unzip otrs-community-edition-6.0.41.zip ``` Next, move the extracted directory to the /opt with the following command: ``` mv otrs-community-edition-6.0.41 /opt/otrs ``` Next, set proper ownership to the OTRS directory: ``` chown -R apache:otrs /opt/otrs chmod -R 775 /opt/otrs ``` ## Step 5 – Install Required Perl Modules for OTRS Next, you will need to install several Perl modules to extend the OTRS functionality. You can check all necessary modules by running the following script: ``` perl /opt/otrs/bin/otrs.CheckModules.pl ``` This will list out all necessary and optional modules. Now, run the following commands one by one to install all modules. Please note that this process will take a long time. ``` yum install "perl(DBD::mysql)" -y yum install "perl(XML::LibXSLT)" -y cpan Crypt::Eksblowfish::Bcrypt cpan Date::Format cpan DateTime cpan DBD::ODBC cpan DBD::Oracle cpan DBD::Pg cpan Encode::HanExtra cpan JSON::XS cpan Mail::IMAPClient cpan Authen::SASL cpan Authen::NTLM cpan Moo cpan Net::DNS cpan Net::LDAP cpan Template cpan Template::Stash::XS cpan Text::CSV_XS cpan XML::LibXML cpan XML::LibXSLT cpan XML::Parser cpan YAML::XS cpan DBD::mysql ``` Next, rename the OTRS default configuration file using the following command: ``` cp /opt/otrs/Kernel/Config.pm.dist /opt/otrs/Kernel/Config.pm ``` Next, check all the required OTRS modules using the following command: ``` perl -cw /opt/otrs/bin/cgi-bin/index.pl perl -cw /opt/otrs/bin/cgi-bin/customer.pl perl -cw /opt/otrs/bin/otrs.Console.pl ``` Next, set appropriate permissions using the following command: ``` perl /opt/otrs/bin/otrs.SetPermissions.pl ``` Next, edit the configuration file. ``` nano /opt/otrs/Kernel/Config.pm ``` Define your OTRS database user password. ``` $Self->{DatabasePw} = 'SecurePassword'; ``` Next, change ownership to the OTRS directory: ``` chown -R apache:otrs /opt/otrs chmod -R 775 /opt/otrs ``` ## Step 6 – Configure Apache for OTRS OTRS provides a pre-configured Apache virtual host configuration file. You can link it to the Apache configuration directory using the following command: ``` ln -s /opt/otrs/scripts/apache2-httpd.include.conf /etc/httpd/conf.d/otrs_apache.conf ``` Next, restart the Apache and MariaDB services to apply the changes: ``` systemctl restart httpd systemctl restart mariadb ``` ## Step 7 – Create a Systemd Service File for OTRS Next, you will need to create a systemd service file for OTRS. You can create it using the following command: ``` nano /etc/systemd/system/otrs.service ``` Add the following lines: ``` [Unit] Description=OTRS: Open-source Ticket Request System, Copyright (C) 2001-2016 OTRS AG Documentation=https://otrs.github.io/doc/manual/admin/stable/en/html/ Requires=crond.service httpd.service mariadb.service [Service] Type=oneshot RemainAfterExit=yes ExecStart=/opt/otrs/bin/otrs.Daemon.pl start ExecStart=/opt/otrs/bin/Cron.sh start ExecStop=/opt/otrs/bin/Cron.sh stop ExecStop=/opt/otrs/bin/otrs.Daemon.pl stop User=otrs Group=apache [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes: ``` systemctl daemon-reload ``` Next, start and enable the OTRS service using the following command: ``` systemctl start otrs systemctl enable otrs ``` ## Step 8 – Access OTRS Web Interface Now, open your web browser and access OTRS using the URL **http://your-server-ip/otrs/installer.pl**. You should see the following screen: ![OTRS welcome page](https://www.atlantic.net/wp-content/uploads/2022/06/p1-10-1024x500.png) Click on the **Next** button. You should see the License agreement screen: ![OTRS license page](https://www.atlantic.net/wp-content/uploads/2022/06/p2-9.png) Click on the Accept license and **continue** button. You should see the database selection screen. ![OTRS check database page](https://www.atlantic.net/wp-content/uploads/2022/06/p3-5-1024x520.png) Select MySQL database and click on the **Next** button. You should see the database setting page: ![OTRS database page](https://www.atlantic.net/wp-content/uploads/2022/06/p4-2-1024x557.png) Provide the root username, leave the password field blank, and click on the **Check database settings**. You should see the following screen: ![OTRS database checked](https://www.atlantic.net/wp-content/uploads/2022/06/p5-2-1024x565.png) Click on the **Next** button to create a database and user. You should see the following screen: ![OTRS database created](https://www.atlantic.net/wp-content/uploads/2022/06/p6-2-1024x469.png) Click on the **Next** button. You should see the general configuration screen: ![OTRS general configuration page](https://www.atlantic.net/wp-content/uploads/2022/06/p7-2-1024x607.png) Provide all necessary configurations and click on the **Next** button. You should see the following screen: ![OTRS smtp configuration page](https://www.atlantic.net/wp-content/uploads/2022/06/p8-1-1024x584.png) Provide your SMTP configuration or click on the **“Skip this Step”** button. You should see the following screen: ![OTRS installed page](https://www.atlantic.net/wp-content/uploads/2022/06/p9-2-1024x388.png) Click on the **Startup** **page** link. You will be redirected to the OTRS login: ![](https://www.atlantic.net/wp-content/uploads/2022/06/p10.png) Provide your login credentials and click on the **Login** button. You should see the following page: ![OTRS dashboard page](https://www.atlantic.net/wp-content/uploads/2022/06/p11-1024x508.png) Now, open your command-line interface to restart the OTRS service. ``` systemctl restart otrs ``` Now, refresh the OTRS dashboard. You should see that the “OTRS daemon not running” error is gone. ![OTRS dashboard page2](https://www.atlantic.net/wp-content/uploads/2022/06/p12-1024x509.png) ## Conclusion In this post, we explained how to install the OTRS ticketing system on Oracle Linux 10. You can now create your own online ticketing system using via the OTRS dashboard. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Sails.js Framework with Nginx on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-sails-js-framework-with-nginx-on-oracle-linux-10/ | Published: 2022-08-16 | Updated: 2025-12-28 | Author: Hitesh Jethva Sails.js is a popular, free, open-source MVC framework for Node.js. It is simple and easy to use and was developed on top of the Node.js environment. It provides developers an easier way to build custom and enterprise-grade Node.js applications. Sails.js offers a code generator that helps developers to build an application with less writing of code. With Sails.js, you can develop chat, real-time dashboards, and multiplayer games. In this post, we will show you how to install the Salis.js framework with Nginx on Oracle Linux 10. ## Step 1- Install Node.js on Oracle Linux 10 First, you will need to install Node.js on your system. To do so, first install all required dependencies using the following command: ``` dnf update -y dnf install curl gcc-c++ make -y ``` ``` Next, install the Node.js and npm by running the following command: ``` ``` dnf install nodejs npm -y ``` Once Node.js is installed, you can verify the Node.js version using the following command: ``` node --version ``` You will get the following output: ``` v22.19.0 ``` ## Step 2 – Install Sails.js on Oracle Linux 10 You can use the NPM to install Sails.js easily on your system. Let’s run the following command to install Sail.js using the NPM command: ``` npm -g install sails ``` After the Sails.js installation, create a directory for the Sails.js application. ``` mkdir sails ``` Next, change the directory to the sails and create a new application using the following command: ``` cd sails sails new newapp ``` You will be asked to select the template for your application: ``` Choose a template for your new Sails app: 1. Web App · Extensible project with auth, login, & password recovery 2. Empty · An empty Sails app, yours to configure (type "?" for help, or to cancel) ? 1 ``` Type 1 and press the Enter key to create your application: ``` info: Installing dependencies... Press CTRL+C to cancel. (to skip this step in the future, use --fast) info: Created a new Sails app `newapp`! ``` ## Step 3 – Start Sails.js Application After creating a Sails.js application, change the directory to your application and start the application using the command below: ``` cd newapp sails lift ``` You will get the following output: ``` info: Starting app... info: Initializing project hook... (`api/hooks/custom/`) info: Initializing `apianalytics` hook... (requests to monitored routes will be logged!) info: ·• Auto-migrating... (alter) info: Hold tight, this could take a moment. info: ✓ Auto-migration complete. debug: Running v0 bootstrap script... (looks like this is the first time the bootstrap has run on this computer) info: info: .-..-. info: info: Sails <| .-..-. info: v1.5.2 |\ info: /|.\ info: / || \ info: ,' |' \ info: .-'.-==|/_--' info: `--'-------' info: __---___--___---___--___---___--___ info: ____---___--___---___--___---___--___-__ info: info: Server lifted in `/root/sails/newapp` info: To shut down Sails, press + C at any time. info: Read more at https://sailsjs.com/support. debug: ------------------------------------------------------- debug: :: Tue Dec 28 2025 11:52:10 GMT-0400 (Eastern Daylight Time) debug: Environment : development debug: Port : 1337 debug: ------------------------------------------------------- ``` Press CTRL+C to stop the application. ## Step 4 – Create a Systemd Service File for Salis.js It is a good idea to create a systemd service file to manage the Sails.js application. You can create it using the following command: ``` nano /lib/systemd/system/sails.service ``` Add the following lines: ``` [Unit] After=network.target [Service] Type=simple User=root WorkingDirectory=/root/sails/newapp ExecStart=/usr/local/bin/sails lift Restart=on-failure [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes: ``` systemctl daemon-reload ``` Now, start the Sails.js service and enable it to start at system reboot: ``` systemctl start sails systemctl enable sails ``` You can also verify the status of the Sails.js service using the following command: ``` systemctl status sails ``` You will get the following output: ``` ● sails.service Loaded: loaded (/usr/lib/systemd/system/sails.service; disabled; preset: disabled) Active: active (running) since Sun 2025-12-28 00:50:02 EST; 2s ago Invocation: b6a7a48d293545fc90140b2fee44d36f Main PID: 19694 (node) Tasks: 18 (limit: 24812) Memory: 110.7M (peak: 110.7M) CPU: 2.757s CGroup: /system.slice/sails.service ├─19694 node /usr/local/bin/sails lift └─19703 grunt Dec 28 00:50:04 oracle sails[19694]: info: Dec 28 00:50:04 oracle sails[19694]: info: Server lifted in `/root/sails/newapp` Dec 28 00:50:04 oracle sails[19694]: info: To shut down Sails, press + C at any time. Dec 28 00:50:04 oracle sails[19694]: info: Read more at https://sailsjs.com/support. Dec 28 00:50:04 oracle sails[19694]: debug: ------------------------------------------------------- Dec 28 00:50:04 oracle sails[19694]: debug: :: Sun Dec 28 2025 00:50:04 GMT-0500 (Eastern Standard Time) Dec 28 00:50:04 oracle sails[19694]: debug: Environment : development Dec 28 00:50:04 oracle sails[19694]: debug: Port : 1337 Dec 28 00:50:04 oracle sails[19694]: debug: Local : http://localhost:1337 Dec 28 00:50:04 oracle sails[19694]: debug: ------------------------------------------------------- ``` At this point, the Sails.js application is started and listens on port 1337. You can check it using the following command: ``` ss -antpl | grep 1337 ``` You will get the following output: ``` LISTEN 0 128 *:1337 *:* users:(("node",pid=18809,fd=19)) ``` ## Step 5 – Configure Nginx as a Reverse Proxy for Sails.js First, install Nginx with the following command: ``` dnf install nginx ``` Next, create an Nginx virtual host configuration file using the following command: ``` nano /etc/nginx/conf.d/sails.conf ``` Add the following lines: ``` server { listen 80; server_name sails.example.com; location / { proxy_pass http://localhost:1337/; proxy_set_header Host $host; proxy_buffering off; } } ``` Save and close the file, then edit the Nginx main configuration file: ``` nano /etc/nginx/nginx.conf ``` Define the max hash bucket size: ``` server_names_hash_bucket_size 64; ``` Next, verify Nginx for syntax errors: ``` nginx -t ``` You will get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart Nginx to apply the changes: ``` systemctl restart nginx ``` ## Step 6 – Access Sails.js Now, open your web browser and access the Sails.js web interface using the URL **http://sails.example.com**. You should see the Sails.js application on the following screen: ![Sail.js dashboard](https://www.atlantic.net/wp-content/uploads/2022/06/p1-9-1024x510.png) ## Conclusion In this post, we explained how to install Sails.js with Nginx on Oracle Linux 10. You can now start developing your first real-time application using the Sails.js framework. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Install WonderCMS on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/install-wondercms-on-oracle-linux-10/ | Published: 2022-08-17 | Updated: 2025-12-28 | Author: Hitesh Jethva WonderCMS is a free, open-source, lightweight content management system. It is written in PHP, jQuery, and HTML/CSS. WonderCMS is an extremely small flat-file CMS, so you don’t need to install any databases on your system. It provides an easier way to build a website without any programming knowledge. WonderCMS is fast, responsive, and doesn’t require any configuration. It offers a rich set of features, including SEO-friendliness, friendly URLs, themes, custom login URLs, and more. In this post, we will explain how to install WonderCMS on Oracle Linux 10. ## Step 1 – Install Apache and PHP Before starting, you will need to install Apache, PHP, and other necessary PHP extensions on your server. You can install all of them using the following command: ``` dnf install httpd php php-mysqlnd php-curl php-opcache php-xml php-gd php-mbstring php-zip php-json wget unzip git -y ``` Once all the packages are installed, edit the php.ini file and change some default settings: ``` nano /etc/php.ini ``` Change the following settings per your requirements: ``` file_uploads = On allow_url_fopen = On memory_limit = 256M post_max_size 32M upload_max_filesize = 64M max_execution_time = 300 date.timezone = "America/Chicago" ``` Save and close the file, then start the Apache service and enable it to start at system reboot: ``` systemctl start httpd systemctl enable httpd ``` ## Step 2 – Download and Install WonderCMS Next, you will need to download the latest version of WonderCMS from the GitHub repository. You can download it using the following command: ``` git clone https://github.com/robiso/wondercms.git /var/www/html/wondercms ``` Once the download is completed, set proper permissions and ownership to the WonderCMS directory: ``` chown -R apache:apache /var/www/html/wondercms chmod -R 777 /var/www/html/wondercms/ ``` Once you are done, you can proceed to the next step. ## Step 3 – Configure for WonderCMS Next, you will need to create an Apache virtual host configuration file for WonderCMS. You can create it using the following command: ``` nano /etc/httpd/conf.d/wondercms.conf ``` Add the following configurations: ``` ServerName wonder.example.com DirectoryIndex index.php DocumentRoot /var/www/html/wondercms ErrorLog /var/log/httpd/error.log CustomLog /var/log/httpd/access.log combined Options FollowSymLinks AllowOverride All Require all granted ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` You can check the Apache status using the following command: ``` systemctl status httpd ``` You will get the following output: ``` ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; vendor preset: disabled) Drop-In: /usr/lib/systemd/system/httpd.service.d └─php-fpm.conf Active: active (running) since Tue 2025-12-28 13:29:03 EDT; 6s ago Docs: man:httpd.service(8) Main PID: 77315 (/usr/sbin/httpd) Status: "Started, listening on: port 80" Tasks: 213 (limit: 11409) Memory: 178.2M CGroup: /system.slice/httpd.service ├─77315 /usr/sbin/httpd -DFOREGROUND ├─77320 /usr/sbin/httpd -DFOREGROUND ├─77321 /usr/sbin/httpd -DFOREGROUND ├─77322 /usr/sbin/httpd -DFOREGROUND └─77323 /usr/sbin/httpd -DFOREGROUND ``` ## Step 4 – Access WonderCMS Web Interface Now, open your web browser and access WonderCMS using the URL **http://wonder.example.com**. You should see the following page containing your login password: ![WonderCMS welcome page](https://www.atlantic.net/wp-content/uploads/2022/06/p1-8-1024x520.png) Click on the **“Click to login.” button**. You should see the WonderCMS login screen: ![WonderCMS login page](https://www.atlantic.net/wp-content/uploads/2022/06/p2-8-1024x538.png) Provide the WonderCMS password and click on the **Login** button. You should see the following screen: ![WonderCMS dashboard page](https://www.atlantic.net/wp-content/uploads/2022/06/p3-4-1024x514.png) Click on **Open security settings** to change the default password and login URL as shown below: ![WonderCMS change password and url page](https://www.atlantic.net/wp-content/uploads/2022/06/p7-1.png) Define your new login URL and password and click on the **CHANGE PASSWORD** button to update the password. ## Conclusion in this guide, we explained how to install WonderCMS with Apache on Oracle Linux 10. You can now install themes and plugins and start creating your first website. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # HIPAA vs. PCI DSS for Healthcare Organizations > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-vs-pci-dss-for-healthcare-organizations/ | Published: 2022-08-22 | Updated: 2025-09-15 | Author: Gilad Maayan ## Why Is HIPAA Important for Healthcare Organizations? HIPAA facilitated the secure transition of the healthcare industry from paper to electronic records of health information. Healthcare institutions use HIPAA to streamline healthcare administration functions, ensure protected healthcare information is securely shared, and improve security and compliance. HIPAA provides standards for maintaining healthcare and electronic transaction records, ensuring all parties apply the same practices. All entities covered by HIPAA must use nationally-recognized identifiers and code sets. As a result, it standardizes the transfer of electronic health data between various entities, including healthcare and health plan providers. HIPAA not only helps transform the practices of healthcare institutions. It also helps secure patients’ data. It requires health plan providers, healthcare providers, medical clearinghouses, and all business associates of entities subject to HIPAA to implement several safeguards that protect health and other personal information. These practices are regulated, and violating entities face repercussions. HIPAA regulations require organizations in the healthcare industry to control access to sensitive health data and restrict actions like viewing and sharing health information with specific parties. It helps ensure the information disclosed to health plan and healthcare providers and the information created, stored, or transmitted by these entities is subject to stringent security regulations. It also gives patients control over with whom the entity can share their information. ## Why Is PCI DSS Compliance Important in Healthcare? The Payment Card Industry Data Security Standard (PCI DSS) helps secure credit and payment card data. While the healthcare industry has been hard at work implementing HIPAA standards, it is lagging when it comes to PCI DSS. [PCI DSS compliance](https://www.exabeam.com/explainers/pci-compliance/pci-compliance-a-quick-guide/) is mandated by the Payment Card Industry Security Council, formed by major credit card brands, such as Visa and American Express. PCI DSS compliance applies to all healthcare providers that accept payment cards, including small office practitioners and large third-party administrators of medical claims. HIPAA compliance relates to a different set of confidential data—it does not secure credit card information. Achieving compliance with one does not mean you are covered by both. You must achieve compliance separately with each regulation. ## HIPAA vs. PCI Compliance in Healthcare: Differences and Similarities Both HIPAA and PCI DSS are essential for the industry. However, each standard has a different focus. The key differences between these two compliance standards are: - **Covered entities**—HIPAA applies to healthcare organizations or practitioners and their business partners in the US only. PCI DSS applies to all businesses that process credit card transactions worldwide. - **Structure**—HIPAA has a broader structure that provides fewer details on how to implement security measures. PCI DSS provides detailed implementation instructions, which make it clearer how to comply, but can also present a larger organizational effort. - **Focus**—HIPAA focuses on a wide range of issues affecting an entire organization, such as patient safety, eliminating fraud, protecting privacy, and reducing waste and abuse. PCI DSS has a more narrow focus on the protection of cardholder data and related systems. - **Meaningful Use program**—HIPAA’s Omnibus Rule relates to requirements set by the Medicare and Medicaid EHR Incentive Programs (known as Meaningful Use). These are programs that give health providers incentive payments for integrating EHR. HIPAA compliance may be required to be eligible for the Meaningful Use incentives. PCI DSS compliance is not required as part of Meaningful Use. There are also several similarities between HIPAA and PCI DSS for healthcare organizations: - **Controls**—many of the controls required by HIPAA and PCI DSS overlap. - **Infrastructure**—many infrastructure components recommended by HIPAA, such as Active Directory, antivirus, and log monitoring, are also needed in PCI DSS. - **Maintenance**—both HIPAA and PCI DSS requires periodic vulnerability scanning and remediation, risk analysis, [incident response](https://www.cynet.com/incident-response/), self-auditing according to security protocols, and overall maintenance of security controls. ## Bottom Line: What Healthcare Organizations Need to Do to Comply with HIPAA, PCI DSS, or Both In short, here are the key requirements for each compliance standard: [**HIPAA compliance**](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) requires conducting regular security risk analyses and employee training and implementing technical safeguards that prevent unauthorized access to PHI. Additionally, HIPAA requires organizations to create an incident response plan, enter into business associate agreements (BAAs) with third-party vendors, and conduct third-party risk assessments. [**PCI compliance**](https://www.atlantic.net/pci-compliant-hosting/what-is-pci-compliance/) requires recording and tracking all card data across the organization’s network. It often involves implementing zero trust to mitigate data breach risks. Zero trust incorporates many PCI DSS standards, including access management, encryption, segmentation, and isolation. However, zero trust extends to all sensitive information instead of covering only payment card data. While each compliance standard presents unique challenges, there is also significant overlap between them. If your organization is required to comply with both PCI and HIPAA, it is possible to create one organizational framework that can address both standards. This can save a great deal of time and effort. HIPAA/PCI framework mappings are available which can help you plan the effort and understand how to prepare for both standards with a single initiative. --- # Top 10 Vulnerability Scanners > URL: https://www.atlantic.net/vps-hosting/top-10-vulnerability-scanners/ | Published: 2022-08-29 | Updated: 2026-03-04 | Author: Richard Bailey Cybersecurity is one of the highest priorities for organizations operating in the digital space. The threat to businesses from hacking, ransomware, malware, and data exfiltration has never been more serious. The best way to protect your business from the very latest cybersecurity threats is to invest in regular vulnerability scanning. ## What is Vulnerability Scanning? Vulnerability scanning is when a 3rd party application scanner is run against your computing environment to find security holes and exploits. A vulnerability scanner scans the entire platform, including the operating system, files and folders, permissions, and user accounts, as well as the cloud or data center configuration, networking, databases, and more. The vulnerability scanner compares the results against its database and creates a report of any vulnerabilities affecting the stack. These reports typically categorize vulnerabilities into urgent, high, medium, and low priorities. It is critical for the business to examine the report and assign remediation activities to various teams across the business. In some circumstances, a security waiver will be required to accept the issue as a known risk, but in most other circumstances action will be needed such as making configuration changes, patching, and updating software. ## What Are The Top Vulnerability Scanners? There are hundreds of vulnerability scanners available. Most incur licensing costs, but some are available as free open-source tools. A significant amount of expertise is required to operate these programs effectively, and this task is typically undertaken by security professionals or outsourced to a 3rd party. ### 1. Greenbone Vulnerability Management (GVM) Our number one choice is the open-source powerhouse Greenbone. It’s the world’s most used open-source vulnerability tool and features lightweight enterprise-grade utilities for risk assessment and remediation of vulnerabilities. GVM has a huge database of approximately 50,000 network vulnerability tests supporting 26,000 CVE and runs as a WebGUI or via the command line. Its compatibility with existing digital assets is stellar; it will detect and analyze any device on your network, making compliance and risk management a breeze to attain. ### 2. Wazuh Wazuh is a top vulnerability scanner that provides an entire security suite. The vulnerability detection engine runs an inventory against all of your digital assets, creating a baseline and continuously crosschecking CVE databases to ensure your systems a protected against the very latest threats. Other great features of Wazuh include File Integrity Monitoring, Log Data Analysis, Intrusion Detection, and Security Analysis. You also get tools for configuration assessment, regulatory compliance, and security of cloud assets including containers; Wazuh is truly a feature-packed product. ### 3. OpenVAS The Open Vulnerability Assessment Scanner (OpenVAS) is a user-friendly vulnerability tool that scans public-facing and internal IT systems for weaknesses. It is available as an SaaS cloud product or as a local server installation. The scanning service uses vulnerability tests (VTs) to detect existing vulnerabilities on the desired network. It features several premium services including issue tracking, compliance testing, perimeter scanning, and configuration management. ### 4. Qualys The Qualys Vulnerability Scanner is popular with enterprise clients. It is an SaaS service that requires a Qualys management server deployed to your network and the Qualys service installed on every device in your environment. Once installed and configured, Qualys works independently with minimal user interaction. The scan results are uploaded directly to the Qualys SaaS platform. The detailed audits identify risks in the chosen environment and provide key features including continuous monitoring, vulnerability management, policy compliance, PCI compliance, security assessment questionnaire, web application scanning, web application firewall, and more. ### 5. Nessus Tenable Nessus is another very popular vulnerability scanner that works similarly to Qualys. It’s available as a SaaS platform or as a locally installed server instance. It provides high-speed and in-depth assessments of the chosen environment by referencing over 69000 CVEs for known exploitations and misconfigurations. Nessus features detailed reporting and monitoring of the environment by scanning IPV4, IPV6, and hybrid networks. It actively scans network devices, virtualized platforms, operating systems, databases, web apps, and more, looking for threats, bots, compliance deviation, configuration drift, and sensitive content such as PII. ### 5. Burp Burp from PortSwigger is a relative newcomer to the cybersecurity scene, but it’s making waves and growing in popularity. It’s an SaaS offering that focuses on website and web application vulnerabilities. Users can perform recurring dynamic scans across thousands of applications; all you need is a URL. The clever thing about Burp is the wealth of information you are given when issues are identified; you get details of exactly what is erroring plus links to official documentation that details the vulnerability and the recommended actions. This saves a mountain of admin work as the information you need is right in front of you. ### 6. Tripwire Tripwire products are available as physical appliances for the data center or as a virtualized stack for cloud or on-premise. Tripwire is a popular choice for organizations that are bound by compliance and regulations such as PCI. Tripwire is great at detecting anomalies in transactions, file changes, unexpected network behavior, and so on. Upon activation, Tripwire creates a baseline of the exiting environment and monitors with real-time detection looking for changes in the configuration. Ideally, not only will Tripwire detect vulnerabilities, but will stop a breach from occurring! ### 7. WireShark Wireshark is another open-source vulnerability scanner that makes our top 10, and it’s highly likely you either use it already or have heard glowing reviews about it. Wireshark specializes in network layer analysis, inspecting packets of data as they traverse the network. It is superb at spotting vulnerabilities at the network layer, however, it requires a security expert that is well versed in WireShark to get the most out of it – it’s easy to use, but very hard to master. Some of the key features include live capture of network traffic for offline analysis and extremely detailed filters to narrow down searches to exactly what you are looking for. ### 8. OWASP ZAP OWASP Zed Attack Proxy (ZAP) is a hugely popular free security tool that is maintained by a large number of volunteers. It can help you automatically find security vulnerabilities in your web applications during the development process. It’s also a great tool for experienced pen-testers to use for manual security testing. For a free product, it is teeming with great features, including an intercepting proxy server, traditional and AJAX web crawlers, automated scanner, passive scanner, forced browsing, fuzzer, WebSocket support, scripting languages, and plug-n-hack support. ### 9. Acunetix Acunetix from Invicti is a suite of security tools designed to make security professional’s life much simpler to manage. Not only does it detect the latest types of vulnerabilities, but it also automatically creates tickets for the relevant support team and provides a detailed guide on how to remediate the issue.  It can continuously scan the existing environment and update the dashboard against what has been fixed and what new issues have been found. ### 10. Nikto2 Nikto2 is another free open-source vulnerability scanner that focuses on detecting issues with web servers. It performs comprehensive tests against web servers for multiple items (including over 6700 potentially dangerous files/programs), checks for outdated versions of over 1250 servers, and scans for version-specific problems on over 270 servers. It also checks for server configuration items such as the presence of multiple index files and HTTP server options and will attempt to identify installed web servers and software. ## How can Atlantic.Net help? Atlantic.Net has been providing cutting-edge hosting services for over 30 years. Are you looking for a leading [hosting provider](https://www.atlantic.net/hosting-services-provider/) to host your next project? Look no further than Atlantic.Net. Our infrastructure is audited frequently and we regularly conduct vulnerability remediation on our infrastructure services. With over 30 years of proven experience, our [full suite of managed services](https://www.atlantic.net/managed-services/) and always-available professional support team will build the perfect solution for your business or organization. Atlantic.Net stands ready to help you attain fast compliance with a range of certifications, such as SOC 2 and SOC 3, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/), and HITECH, all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, visit us at [www.atlantic.net](https://www.atlantic.net), call 866-618-DATA (3282), or email us at [sales@atlantic.net](mailto:sales@atlantic.net). You can find out more information by [contacting our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # How to Install Landing CMS on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-landing-cms-on-oracle-linux-10/ | Published: 2022-09-02 | Updated: 2025-12-28 | Author: Hitesh Jethva Landing CMS is a free and open-source CMS tool used for managing landing pages. Instead of using a database, it stores all data in a plain text file. The installation process is simple and straightforward. You will only need to install a web server and PHP to start with Landing CMS. This post will show you how to install Landing CMS on Oracle Linux 10. ## Step 1 – Install Apache and PHP First, install the Apache web server by running the following command: ``` dnf install httpd -y ``` Next, enable the PHP 7.4 module with the following command: ``` dnf module enable php:7.4 -y ``` Next, install PHP with other required extensions using the following command: ``` dnf install -y php php-zip php-intl php-mysqlnd php-dom php-simplexml php-xml php-xmlreader php-curl php-exif php-ftp php-gd php-iconv php-json php-mbstring php-posix php-sockets php-tokenizer php-fpm -y ``` Next, start and enable the Apache and PHP-FPM services with the following command: ``` systemctl start httpd php-fpm systemctl enable httpd php-fpm ``` ## Step 2 – Download Landing CMS First, navigate to the Apache web root directory and download the latest version of Landing CMS with the following command: ``` cd /var/www/html/ wget https://github.com/Elias-Black/Landing-CMS/archive/refs/heads/master.zip ``` Once the download is complete, unzip the downloaded file with the following command: ``` unzip master.zip ``` Next, rename the extracted directory: ``` mv Landing-CMS-master landing ``` Next, set proper permissions and ownership to the landing CMS directory: ``` chmod -R 755 /var/www/html/landing/ chown -R apache:apache /var/www/html/landing/ ``` ## Step 3 – Configure Apache for Landing CMS Next, create an Apache virtual host configuration file for Landing CMS with the following command: ``` nano /etc/httpd/conf.d/landing.conf ``` Add the following configurations: ``` ServerName landing.example.com DocumentRoot /var/www/html/landing Options -Indexes +FollowSymLinks AllowOverride All ErrorLog /var/log/httpd/landing-error.log CustomLog /var/log/httpd/landing-access.log combined ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` You can also check the Apache status using the following command: ``` systemctl status httpd ``` You should see the following output: ``` ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; vendor preset: disabled) Drop-In: /usr/lib/systemd/system/httpd.service.d └─php-fpm.conf Active: active (running) since Tue 2025-12-19 05:25:12 EDT; 3s ago Docs: man:httpd.service(8) Main PID: 32712 (httpd) Status: "Started, listening on: port 80" Tasks: 213 (limit: 11409) Memory: 32.6M CGroup: /system.slice/httpd.service ├─32712 /usr/sbin/httpd -DFOREGROUND ├─32714 /usr/sbin/httpd -DFOREGROUND ├─32715 /usr/sbin/httpd -DFOREGROUND ├─32716 /usr/sbin/httpd -DFOREGROUND └─32717 /usr/sbin/httpd -DFOREGROUND ``` ## Step 4 – Access Landing CMS Now, open your web browser and access the Landing CMS web interface using the URL **http://landing.example.com**. You should see the following screen: ![Landing CMS welcome page](https://www.atlantic.net/wp-content/uploads/2022/07/p1-6-1024x487.png) Click on **Go to CMS**. You should see the set password screen: ![Landing CMS set password page](https://www.atlantic.net/wp-content/uploads/2022/07/p2-5-1024x502.png) Set your new password and click on the **Save** button. You should see the Landing CMS dashboard: ![Landing CMS dashboard page](https://www.atlantic.net/wp-content/uploads/2022/07/p3-3-1024x354.png) ## Conclusion In this post, we explained how to install Landing CMS on Oracle Linux 10. You can now use Landing CMS to manage all your Landing pages. For more information, visit the Landing CMS [documentation](https://github.com/Elias-Black/Landing-CMS). Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Backdrop CMS on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-backdrop-cms-on-oracle-linux-10/ | Published: 2022-09-06 | Updated: 2025-12-28 | Author: Hitesh Jethva Backdrop CMS is a simple, user-friendly, and lightweight content management system used for building attractive and professional websites. It was forked from Drupal CMS and designed for small and medium organizations. Backdrop CMS is a full-featured CMS that helps non-technical users to manage a wide variety of content. Backdrop CMS offers more than 750 modules, themes, and layouts that help you to extend the functionality of your website. In this post, we will show you how to install Backdrop CMS on Oracle Linux 10.[jumpbox] ## Step 1 – Install the LAMP Server Before starting, you will need to install a LAMP stack on your server. First, install the Apache and MariaDB with the following commands: ``` dnf update -y dnf install httpd mariadb-server -y ``` Next, run the following command to install PHP with other required extensions: ``` dnf install php php-cli php-fpm php-gd php-mysqlnd php-json php-curl php-pdo php-mbstring php-dom php-xml unzip -y ``` Next, start and enable the Apache, MariaDB, and PHP-FPM services: ``` systemctl start httpd mariadb php-fpm systemctl enable httpd mariadb php-fpm ``` ## Step 2 – Create a Database for Backdrop CMS Next, you will need to create a database and user for Backdrop CMS. First, connect to MariaDB with the following command: ``` mysql ``` Once you are connected to MariaDB, create a database and user with the following command: ``` create database backdrop; create user 'backdrop'@localhost identified by 'password'; ``` Next, grant all permissions to the backdrop database: ``` grant all privileges on backdrop.* to 'backdrop'@localhost; ``` Next, flush the privileges to apply the changes and exit from MySQL with the following command: ``` flush privileges; exit; ``` ## Step 3 – Download Backdrop CMS Next, visit the Backdrop CMS GitHub page, pick the URL of the latest Backdrop CMS, and download it with the following command: ``` wget https://github.com/backdrop/backdrop/releases/download/1.32.1/backdrop.zip ``` Once the download is completed, unzip the downloaded file using the following command: ``` unzip backdrop.zip ``` Next, move the extracted directory to the Apache web root: ``` mv backdrop /var/www/html/ ``` Next, change the ownership and permissions of the backdrop directory: ``` chown -R apache:apache /var/www/html/backdrop chmod -R 775 /var/www/html/backdrop ``` ## Step 4 – Create an Apache Virtual Host for Backdrop CMS Next, you will need to create an Apache virtual host configuration file for Backdrop CMS. You can create it with the following command: ``` nano /etc/httpd/conf.d/backdrop.conf ``` Add the following configurations: ``` ServerAdmin admin@example.com ServerName backdrop.example.com DocumentRoot /var/www/html/backdrop allowoverride all allow from all TransferLog /var/log/httpd/backdrop_access.log ErrorLog /var/log/httpd/backdrop_error.log ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` To check the Apache status, run the following command: ``` systemctl status httpd ``` You should see the Apache status in the following output: ``` ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; vendor preset: disabled) Drop-In: /usr/lib/systemd/system/httpd.service.d └─php-fpm.conf Active: active (running) since Tue 2025-12-19 05:20:56 EDT; 7s ago Docs: man:httpd.service(8) Main PID: 32357 (httpd) Status: "Started, listening on: port 80" Tasks: 213 (limit: 11409) Memory: 24.4M CGroup: /system.slice/httpd.service ├─32357 /usr/sbin/httpd -DFOREGROUND ├─32359 /usr/sbin/httpd -DFOREGROUND ├─32360 /usr/sbin/httpd -DFOREGROUND ├─32361 /usr/sbin/httpd -DFOREGROUND └─32362 /usr/sbin/httpd -DFOREGROUND ``` ## Step 5 – Access Backdrop CMS Web UI Now, open your web browser and access the Backdrop CMS web interface using the URL **http://backdrop.example.com**. You should see the following screen: ![Backdrop cms select language page](https://www.atlantic.net/wp-content/uploads/2022/07/p1-4-1024x514.png) Select your language and click on the **SAVE AND CONTINUE** button. You should see the database configuration screen: ![Backdrop cms database configuration page](https://www.atlantic.net/wp-content/uploads/2022/07/p2-4-1024x600.png) Provide your database settings and click on the **SAVE AND CONTINUE** button. You should see the site configuration screen: ![Backdrop cms site configuration page](https://www.atlantic.net/wp-content/uploads/2022/07/p4-1-1024x623.png) ![Backdrop cms site configuration page 2](https://www.atlantic.net/wp-content/uploads/2022/07/p5-1.png) Provide your site information, admin username, password, email, time zone and click on the **SAVE AND CONTINUE** button. You should see the Backdrop CMS dashboard: ![Backdrop cms dashboard page](https://www.atlantic.net/wp-content/uploads/2022/07/p6-1-1024x510.png) ## Conclusion In this post, we explained how to install Backdrop CMS on Oracle Linux 10. You can now start building modern and comprehensive websites using the Backdrop CMS platform. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install PrestaShop on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-prestashop-on-oracle-linux-10/ | Published: 2022-09-07 | Updated: 2025-12-28 | Author: Hitesh Jethva PrestaShop is a free and open-source shopping cart system that allows you to quickly host your own online shop. It is written in the PHP programming language with support for the MySQL database management system. PrestaShop has over 300 functionalities, such as unlimited products with attributes, categories, multistore, many currencies, languages, payment, delivery methods, CMS, filtering, statistics, e-marketing, transactional e-mailing, and many more. In this post, we will show you how to install PrestaShop on Oracle Linux 10. ## Step 1 – Install the LAMP Server First, install the Apache and MariaDB server package with the following command: ``` dnf update -y dnf install httpd mariadb-server ``` ``` Next, install PHP with other required extensions using the following command: ``` ``` dnf install php php-zip php-xml php-gd php-curl php-fpm php-intl php-sodium php-mbstring php-mysqli php-bcmath php-dom php-posix php-cli php-pdo php-posix php-fileinfo php-json php-iconv -y ``` Next, edit the PHP configuration file and change some default settings: ``` nano /etc/php.ini ``` Change the following lines: ``` memory_limit = 256M post_max_size = 64M upload_max_filesize = 64M ``` Save and close the file, then start and enable the Apache, MariaDB, and PHP-FPM services: ``` systemctl start httpd mariadb php-fpm systemctl enable httpd mariadb php-fpm ``` ## Step 2 – Create a Database for PrestaShop Next, you will need to create a database and user for PrestaShop. First, log in to the MariaDB shell with the following command: ``` mysql ``` Once logged in, create a database and user with the following command: ``` CREATE DATABASE prestadb; CREATE USER 'prestauser'@'localhost' IDENTIFIED BY 'yourpassword'; ``` Next, grant all the privileges to the prestadb database: ``` GRANT ALL PRIVILEGES ON prestadb.* TO 'prestauser'@'localhost'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download PrestaShop Next, visit the PrestaShop Git Hub download page, pick the latest version and download it with the following command: ``` wget https://assets.prestashop3.com/dst/edition/corporate/9.0.2-2.1/prestashop_edition_basic_version_9.0.2-2.1.zip ``` Once the download is completed, unzip the downloaded file to the PrestaShop directory: ``` unzip prestashop_edition_basic_version_9.0.2-2.1.zip -d /var/www/html/prestashop/ ``` Next, change the permissions and ownership of the PrestaShop using the following command: ``` chown -R apache:apache /var/www/html/prestashop chmod -R 775 /var/www/html/prestashop ``` ## Step 4 – Configure Apache for PrestaShop Next, create an Apache virtual host configuration file using the following command: ``` nano /etc/httpd/conf.d/prestashop.conf ``` Add the following configuration: ``` ServerName prestashop.example.com DocumentRoot /var/www/html/prestashop Options -Indexes +FollowSymLinks AllowOverride All ErrorLog /var/log/httpd/prestashop-error.log CustomLog /var/log/httpd/prestashop-access.log combined ``` Save and close the file, then restart the Apache service to apply the configuration: ``` systemctl restart httpd ``` To check the Apache status, run the following command: ``` systemctl status httpd ``` You will get the following output: ``` ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; vendor preset: disabled) Drop-In: /usr/lib/systemd/system/httpd.service.d └─php-fpm.conf Active: active (running) since Tue 2025-12-19 05:44:24 EDT; 4s ago Docs: man:httpd.service(8) Main PID: 33190 (httpd) Status: "Started, listening on: port 80" Tasks: 213 (limit: 11409) Memory: 24.5M CGroup: /system.slice/httpd.service ├─33190 /usr/sbin/httpd -DFOREGROUND ├─33193 /usr/sbin/httpd -DFOREGROUND ├─33194 /usr/sbin/httpd -DFOREGROUND ├─33195 /usr/sbin/httpd -DFOREGROUND └─33196 /usr/sbin/httpd -DFOREGROUND ``` ## Step 5 – Access PrestaShop Web Interface At this point, PrestaShop is installed and configured. Now, open your web browser and access the PrestaShop web UI using the URL **http://prestashop.example.com**. You should see the store information screen: ![](https://www.atlantic.net/wp-content/uploads/2022/09/s1-1.png) Provide your store information, email, password, then click on the **Next** button. You should see the theme installation screen: ![](https://www.atlantic.net/wp-content/uploads/2022/09/s2-1.png) Select your theme and click on **Next**. You will see the database configuration screen. ![](https://www.atlantic.net/wp-content/uploads/2022/09/s3.png) Define your database and click on the **“Test your database connection now”** then click on the **Next** button. Once the installation is finished, you should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2022/09/s4.png) Next, remove the installation directory using the following command: ``` rm -rf /var/www/html/prestashop/install ``` Click on the **Manage Your Store** button. You should see the PrestaShop login screen: ![](https://www.atlantic.net/wp-content/uploads/2022/09/s5.png) Provide your admin username and password and click on the **LOG IN** button. You should see the PrestaShop dashboard on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2022/09/s6.png) ## Conclusion In this post, we explained how to install PrestaShop on Oracle Linux 10. You can now host your own e-commerce CMS and start selling your products online. For more information, visit PrestaShop’s [documentation](https://devdocs.prestashop.com/). Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Atlantis CMS with Apache on Oracle Linux 8 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-atlantis-cms-with-apache-on-oracle-linux-8/ | Published: 2022-09-10 | Updated: 2023-11-15 | Author: Hitesh Jethva Atlantis CMS is a free and open-source content management system that allows you to easily create a website. It is designed for agencies and marketers to simplify the process of building and maintaining a website. It features on-page editing, a visual form builder, and simple module integrations. Atlantis CMSis built on top of an MVC framework that enables any beginner to create a website, blog, community, or network. This post will explain how to install Atlantis CMS on Oracle Linux 8. ## Step 1 – Install Apache, MariaDB, and PHP Before starting, you will need to install an Apache web server, MariaDB database server, and PHP on your system. Let’s start with installing the Apache and MariaDB server using the following command: ``` dnf install httpd mariadb-server -y ``` Once both packages are installed, run the following command to install PHP with other required extensions: ``` dnf install php php-fpm php-common php-gmp php-curl php-json php-intl php-mbstring php-xmlrpc php-mysqli php-gd php-xml php-cli php-zip -y ``` Next, start the Apache, MariaDB, and PHP-FPM services and enable them to start at system reboot: ``` systemctl start httpd mariadb php-fpm systemctl enable httpd mariadb php-fpm ``` Next, edit the PHP configuration file and change the default settings: ``` nano /etc/php.ini ``` Change the following lines: ``` short_open_tag = On memory_limit = 256M upload_max_filesize = 100M max_execution_time = 360 max_input_vars = 1500 date.timezone = UTC ``` Save and close the file when you are done. ## Step 2 – Create a Database for Atlantis Next, you will need to create a database and user for Atlantis. First, log in to the MariaDB shell with the following command: ``` mysql ``` Once you are logged in, create a database and user for Atlantis: ``` CREATE DATABASE atlantis; CREATE USER 'atlantis'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all privileges to the Atlantis database: ``` GRANT ALL PRIVILEGES ON atlantis.* TO 'atlantis'@'localhost'; ``` Next, flush the privileges and exit from the MariaDB: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install Atlantis CMS First, you will need to install PHP Composer on your system. You can install it with the following command: ``` curl -sS https://getcomposer.org/installer | php mv composer.phar /usr/local/bin/composer chmod +x /usr/local/bin/composer ``` Next, change the directory to the Apache web root and download the latest version of Atlantis CMS using the Composer command: ``` cd /var/www/html composer create-project atlantis-labs/atlantis3 --prefer-dist atlantis3 ``` Next, navigate to the Atlantis directory and migrate the database with the following command: ``` cd atlantis3/ php artisan atlantis:set:db ``` You will be asked to define your database as shown below: ``` Do you want to set database credential? (yes/no) [no]: > yes Host: > localhost Database name: > atlantis Username: > atlantis Password: > Database configuration is changed ``` Next, run the following command to run the migration: ``` php artisan atlantis:install ``` You should see the following output: ``` Do you want to run migrations? (yes/no) [no]: > yes Migrations complete. Do you want to run seeds? (yes/no) [no]: > yes Seeds complete. Installation complete. ``` Next, set proper permissions and ownership on the Atlantis directory: ``` chown -R apache:apache /var/www/html/atlantis3/ chmod -R 755 /var/www/html/atlantis3/ ``` ## Step 4 – Configure Apache for Atlantis Next, you must create an Apache virtual host configuration file to host Atlantis. You can create it with the following command: ``` nano /etc/httpd/conf.d/atlantis.conf ``` Add the following lines: ``` ServerName atlantis.example.com DocumentRoot /var/www/html/atlantis3 Options -Indexes +FollowSymLinks AllowOverride All ErrorLog /var/log/httpd/atlantis-error.log CustomLog /var/log/httpd/atlantis-access.log combined ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` You can check the status of Apache with the following command: ``` systemctl status httpd ``` You will get the following output: ``` ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; vendor preset: disabled) Drop-In: /usr/lib/systemd/system/httpd.service.d └─php-fpm.conf Active: active (running) since Tue 2022-07-19 06:13:58 EDT; 8s ago Docs: man:httpd.service(8) Main PID: 34936 (httpd) Status: "Started, listening on: port 80" Tasks: 213 (limit: 11409) Memory: 24.6M CGroup: /system.slice/httpd.service ├─34936 /usr/sbin/httpd -DFOREGROUND ├─34938 /usr/sbin/httpd -DFOREGROUND ├─34939 /usr/sbin/httpd -DFOREGROUND ├─34940 /usr/sbin/httpd -DFOREGROUND └─34941 /usr/sbin/httpd -DFOREGROUND Jul 19 06:13:58 oraclelinux8 systemd[1]: httpd.service: Succeeded. Jul 19 06:13:58 oraclelinux8 systemd[1]: Stopped The Apache HTTP Server. Jul 19 06:13:58 oraclelinux8 systemd[1]: Starting The Apache HTTP Server... ``` ## Step 5 – Access Atlantis CMS Now, open your web browser and access the Atlantis web interface using the URL **http://atlantis.example.com/admin**. You will be redirected to the Atlantis login page: ![Atlantis login page](https://www.atlantic.net/wp-content/uploads/2022/07/p1-3-1024x544.png) Provide the default username admin and password as admin123, then click on the **Login** button. You should see the Atlantic CMS dashboard on the following page: ![Atlantis dashboard page](https://www.atlantic.net/wp-content/uploads/2022/07/p2-3-1024x503.png) ## Conclusion In this post, we explained how to install Atlantis CMS on Oracle Linux 8. You can now easily create and deploy your website or blog on the web. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Gatsby on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-gatsby-on-oracle-linux-10/ | Published: 2022-09-12 | Updated: 2025-12-27 | Author: Hitesh Jethva Gatsby is a free and open-source framework based on the frontend development framework React. Gatsby allows developers to build fast, secure, and powerful websites using a React-based framework. With Gatsby, you can build a portfolio site or blog, or a high-traffic e-commerce store or company homepage. It follows the latest web standards and is optimized for speed and security. Gatsby brings the speed of a statically generated site as well as the functionality of a framework. This post will show you how to install Gatsby on Oracle Linux 10. ## Step 1 – Install Node.js and NPM Before starting, you will need to install Node.js and NPM on your server. You can Install Node.js and NPM using the following command: ``` dnf install -y nodejs npm ``` Next, install Git and the Yarn package with the following command: ``` dnf install git npm install -i yarn ``` Next, verify the Node.js version using the following command: ``` node -v ``` Output: ``` v22.19.0 ``` To verify the NPM version, run the following command: ``` npm -v ``` Output: ``` 10.9.3 ``` ## Step 2 – Install Gatsby CLI Gatsby provides a CLI tool that allows you to create and manage projects via the command line. You can install it using the NPM command as shown below: ``` npm install -g gatsby-cli ``` Once Gatsby is installed, you can verify it using the following command: ``` gatsby --version ``` You will get the following output: ``` Gatsby CLI version: 5.15.0 ``` ## Step 3 – Create a New Site Using Gatsby After installing Gatsby, run the following command to create a new site: ``` gatsby new ``` You will be asked to create a site name and other options during the site creation process. Once the site is created, you should see the following output: ``` Welcome to Gatsby! This command will generate a new Gatsby site for you in /root with the setup you select. Let's answer some questions: What would you like to call your site? ✔ · My Gatsby Site What would you like to name the folder where your site will be created? ✔ root/ my-gatsby-site ✔ Will you be using JavaScript or TypeScript? · JavaScript ✔ Will you be using a CMS? · No (or I'll add it later) ✔ Would you like to install a styling system? · No (or I'll add it later) Thanks! Here's what we'll now do: 🛠 Create a new Gatsby site in the folder my-gatsby-site ✔ Created site from template ▸ Installing Gatsby... ✔ Created site from template ✔ Installed Gatsby ✔ Installed plugins ✔ Created site in my-gatsby-site Author identity unknown *** Please tell me who you are. Run git config --global user.email "you@example.com" git config --global user.name "Your Name" to set your account's default identity. Omit --global to set the identity only in this repository. Initial git commit failed - removing git support 🎉 Your new Gatsby site new has been successfully created at /root/my-gatsby-site. Start by going to the directory with cd my-gatsby-site Start the local development server with npm run develop See all commands at https://www.gatsbyjs.com/docs/gatsby-cli/ ``` Now, change the directory to your site and run the following command to start the development server: ``` cd my-gatsby-site gatsby develop -H 0.0.0.0 ``` Once the server is started, you will get the following output: ``` You can now view my-gatsby-site in the browser. ⠀ http://localhost:8000/ ⠀ View GraphiQL, an in-browser IDE, to explore your site's data and schema ⠀ http://localhost:8000/___graphql ⠀ Note that the development build is not optimized. To create a production build, use gatsby build ``` You can also use the following options to start the development server: - **-H,** –host Set host. Defaults to localhost - **-p,** –port Set port. Defaults to env.PORT or 8000 - **-o,** –open Open the site in your (default) browser for you - **-S,** –https Use HTTPS ## Step 4 – Access Gatsby Web Interface At this point, Gatsby is installed, started, and listens on port **8000.** You can now access it using the URL **http://your-server-ip:8000**. You should see the Gatsby default page on the following screen: ![Gatsby dashboard page](https://www.atlantic.net/wp-content/uploads/2022/07/p1-5-1024x596.png) ## Conclusion In this post, you learned how to install Gatsby on Oracle Linux 10. Gatsby is very useful for e-commerce developers to make blazing-fast stores in minimal time. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure Privoxy Server On Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-configure-privoxy-server-on-oracle-linux-10/ | Published: 2022-09-13 | Updated: 2025-12-27 | Author: Hitesh Jethva Privoxy is a web proxy service that acts as a non-caching web proxy. It works as a mediator between a user and the Internet. When the user accesses the Internet, the web browser sends a request to Privoxy to get the objects or pages, then Privoxy filters the user request per the proxy configuration and gives the result to the end user. Generally, a Privoxy server is used for privacy and security and to improve efficiency through its advanced caching features. In this post, we will show you how to install a Privoxy proxy server on Oracle Linux 10. ## Step 1 – Install Privoxy Server By default, the Privoxy package is not included in the Oracle Linux default repo, so you will need to compile it from the source. First, install the required packages using the following command: ``` dnf install -y gcc make autoconf automake pcre2-devel zlib-devel openssl-devel wget ``` Next, download the latest version of Privoxy. ``` wget https://sourceforge.net/projects/ijbswa/files/Sources/4.0.0%20%28stable%29/privoxy-4.0.0-stable-src.tar.gz ``` Next, extract the downloaded file. ``` tar -xvf privoxy-4.0.0-stable-src.tar.gz ``` Next, navigate to the extracted directory: ``` cd privoxy-4.0.0-stable ``` Next, compile the Privoxy with the following command: ``` autoheader autoconf ./configure make make install ``` ## Step 2 – Configure Privoxy Proxy By default, the Privoxy server listens on port **8118** on the localhost, so you will need to configure it to listen to your server’s IP address. To do so, edit the Privoxy configuration file: ``` nano /usr/local/etc/privoxy/config ``` Find the following line: ``` listen-address 127.0.0.1:8118 ``` Change it with the following line: ``` listen-address your-server-ip:8118 ``` Next, create a user for Privoxy. ``` useradd --system --no-create-home --shell /sbin/nologin privoxy ``` Next, give necessary permissions: ``` chown -R privoxy:privoxy /usr/local/etc/privoxy chown -R privoxy:privoxy /usr/local/var/log/privoxy chown -R privoxy:privoxy /var/log/privoxy ``` Save and close the file, then start the Privoxy service with the following command: ``` /etc/init.d/privoxy start ``` You can also verify the Privoxy listening port using the following command: ``` ss -antpl | grep 8118 ``` You will get the following output: ``` LISTEN 0 128 208.117.86.131:8118 0.0.0.0:* users:(("privoxy",pid=30046,fd=7)) ``` ## Step 3 – Configure Web Browser to Use Privoxy Proxy After installing the Privoxy server, you will need to test it. To test it, you must configure your web browser to use the Privoxy server. First, go to the client system, open your **Firefox web browser** => and click on **Edit** => **Preferences**. You should see the following page: ![Firefox preferences page](https://www.atlantic.net/wp-content/uploads/2022/07/p1-10-1024x558.png) Now, click on **Network Settings** => **Settings.** You should see the following page: ![Firefox proxy page](https://www.atlantic.net/wp-content/uploads/2022/07/p2-8.png) Now, provide your Privoxy server IP and port and click on the **Ok** button to save the changes. Now, open your web browser and access the URL **https://www.whatismyip.com** to check your public IP address. If everything is fine, you should see your Privoxy server IP on the following page: ![verify proxy page](https://www.atlantic.net/wp-content/uploads/2022/07/p3-6-1024x551.png) ## Conclusion Congratulations! You have successfully installed and configured the Privoxy server on your Oracle Linux 10 virtual private server. You can now use some advanced filters on the Privoxy server and block your desired content. Get started with Privoxy on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Configure Sandstorm Server On Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-configure-sandstorm-server-on-oracle-linux-10/ | Published: 2022-09-14 | Updated: 2025-12-27 | Author: Hitesh Jethva Sandstorm is a free and open-source platform that allows you to install different applications on a server with an easy-to-use interface. It has a library of self-hosted apps, including WordPress, GitLab, MediaWiki, Apache Wave, and RoundCube webmail. You can install any of these applications using the Sandstrom web interface. Sandstorm minimizes the time wasted on setup, configuration, and managing of apps. It is a handy application that can run on all enterprise and community-powered Linux distributions. In this post, we will show you how to install Sandstorm on Oracle Linux 10. ## Step 1 – Install Sandstorm on Oracle Linux 10 Sandstorm offers an auto-installation script that allows you to easily install Sandstorm on your server. You can download it with the following command: ``` curl https://install.sandstorm.io >install.sh ``` Output: ``` % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 76862 100 76862 0 0 247k 0 --:--:-- --:--:-- --:--:-- 247k ``` Once the Sandstorm script is downloaded, you can run it to start the installation: ``` bash install.sh ``` You will be asked to select the installation option as shown below: ``` Sandstorm makes it easy to run web apps on your own server. You can have: 1. A typical install, to use Sandstorm (press enter to accept this default) 2. A development server, for working on Sandstorm itself or localhost-based app development ``` Press enter to select the default option. You should see the following output: ``` How are you going to use this Sandstorm install? [1] We're going to: * Install Sandstorm in /opt/sandstorm * Automatically keep Sandstorm up-to-date * Configure auto-renewing HTTPS if you use a subdomain of sandcats.io * Create a service user (sandstorm) that owns Sandstorm's files * Configure Sandstorm to start on system boot (with systemd) * Listen for inbound email on port 25. Rest assured that Sandstorm itself won't run as root. OK to continue? [yes] ``` Type yes and press the Enter key to continue: ``` Note: Sandstorm's storage will only be accessible to the group 'sandstorm'. As a Sandstorm user, you are invited to use a free Internet hostname as a subdomain of sandcats.io, a service operated by the Sandstorm development team. ... Sandcats.io protects your privacy and is subject to terms of use. By using it, you agree to the terms of service & privacy policy available here: https://sandcats.io/terms https://sandcats.io/privacy Choose your desired Sandcats subdomain (alphanumeric, max 20 characters). Type the word none to skip this step, or help for help. What *.sandcats.io subdomain would you like? [] none URL users will enter in browser: [http://oraclelinux8:6080] http://sandstorm.example.com:6080 ``` Type your domain name and press the Enter key to continue: ``` Sandstorm requires you to set up a wildcard DNS entry pointing at the server. This allows Sandstorm to allocate new hosts on-the-fly for sandboxing purposes. Please enter a DNS hostname containing a '*' which maps to your server. For example, if you have mapped *.foo.example.com to your server, you could enter "*.foo.example.com". You can also specify that hosts should have a special prefix, like "ss-*.foo.example.com". Note that if your server's main page is served over SSL, the wildcard address must support SSL as well, which implies that you must have a wildcard certificate. For local-machine servers, we have mapped *.local.sandstorm.io to 127.0.0.1 for your convenience, so you can use "*.local.sandstorm.io" here. If you are serving off a non-standard port, you must include it here as well. Wildcard host: [*.sandstorm.example.com:6080] Your server is now online! Visit this link to start using it: http://sandstorm.example.com:6080/setup/token/e6921a5c674623f584aa63540f8e0811fcb367e9 NOTE: This URL expires in 15 minutes. You can generate a new setup URL by running 'sudo sandstorm admin-token' from the command line. To learn how to control the server, run: sandstorm help ``` At this point, Sandstorm is installed and listens on port 6080. You can check it with the following command: ``` ss -antpl | grep 6080 ``` You will get the following output: ``` LISTEN 0 128 0.0.0.0:6080 0.0.0.0:* users:(("sandstorm/gtway",pid=29378,fd=7),("sandstorm/montr",pid=29306,fd=7),("sandstorm/top",pid=29303,fd=7)) ``` ## Step 2 – Access Sandstorm Web Interface Now, open your web browser and type the URL: http://sandstorm.example.com:6080/setup/token/e6921a5c674623f584aa63540f8e0811fcb367e9 You should see the following screen: ![Sandstorm welcome screen](https://www.atlantic.net/wp-content/uploads/2022/07/p1-9-1024x531.png) Click on **Begin** **Sandstorm** **Setup**. You should see the following page: ![Sandstorm define login method](https://www.atlantic.net/wp-content/uploads/2022/07/p2-7-1024x524.png) Select E-Mail and click on the **Configure** button. You should see the following page: ![Sandstorm enable email](https://www.atlantic.net/wp-content/uploads/2022/07/p3-5-1024x609.png) Click on **Enable.** You should see the following page: ![Sandstorm define smtp](https://www.atlantic.net/wp-content/uploads/2022/07/p4-3.png) Provide your mail server domain and click on the **Save and continue** button. You should see the following page: ![Sandstorm define mail](https://www.atlantic.net/wp-content/uploads/2022/07/p5-3.png) Provide your SMTP host, port, username, and password and click on the **Save and continue** button. You should see the following page: ![Sandstorm skip settings](https://www.atlantic.net/wp-content/uploads/2022/07/p6-2-1024x563.png) Click on **Skip for now**. You should see the following page: ![Sandstorm login page](https://www.atlantic.net/wp-content/uploads/2022/07/p7-2-1024x610.png) Provide your email address and click on the **SEND LOGIN EMAIL**. You should receive an email with login credentials. You can use those credentials to log in to the Sandstorm server. ## Conclusion In this post, we explained how to install Sandstorm on Oracle Linux 10 VPS. You can now easily deploy any application on your server with just a single click. If you would like to learn more about Sandstorm, visit their documentation. Try Sandstorm on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlanitc.Net! --- # How to Install Vue.js on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-vue-js-on-oracle-linux-10/ | Published: 2022-09-15 | Updated: 2025-12-27 | Author: Hitesh Jethva Vue.js is a progressive JavaScript framework that allows you to build user interfaces and single-page applications. It is a famous framework used to simplify the web development process. Vue.js provides useful functionalities for progressive enhancement, allowing you to use it as a drop-in replacement for a library like jQuery. It is simple, reactive, and easy to learn for someone with knowledge of HTML, CSS, and JavaScript. In this post, we will show you how to install Vue.js on Oracle Linux 10. ## Step 1 – Install Node.js Before starting, you will need to install Node.js on your server. You can install it using the following command: ``` dnf install -y nodejs npm ``` Once Node.js is installed, you can verify the Node.js version with the following command: ``` node -v ``` Output: ``` v22.19.0 ``` You can also see the NPM version using the following command: ``` npm -v ``` Output: ``` 10.9.3 ``` ## Step 2 – Install Vue CLI Vue CLI is a complete package used for developing and managing Vue.js applications. You can install it using NPM as shown below: ``` npm install -g @vue/cli ``` Once Vue CLI is installed, verify its version with the following command: ``` vue --version ``` You should see the Vue CLI version in the following output: ``` @vue/cli 5.0.9 ``` ## Step 3 – Create an Application with Vue.js To use Vue.js, let’s create a sample application with the following command: ``` vue create web-application ``` You should see the following output: ``` Vue CLI v5.0.9 ? Please pick a preset: (Use arrow keys) ❯ Default ([Vue 3] babel, eslint) Default ([Vue 2] babel, eslint) Manually select features ⚓ Running completion hooks... 📄 Generating README.md... 🎉 Successfully created project web-application. 👉 Get started with the following commands: $ cd web-application $ npm run serve WARN Skipped git commit due to missing username and email in git config, or failed to sign commit. You will need to perform the initial commit yourself. ``` Next, change the directory to your application directory and run your application using the following command: ``` cd web-application npm run serve ``` You should see the following output: ``` > web-application@0.1.0 serve > vue-cli-service serve INFO Starting development server... DONE Compiled successfully in 7390ms 4:30:40 AM App running at: - Local: http://localhost:8080/ - Network: unavailable Note that the development build is not optimized. To create a production build, run npm run build. ``` ## Step 4 – Access Vue.js Application At this point, the Vue.js application is started and listens on port 8080. You can now access it using the URL **http://your-server-ip:8080**. You should see the Vue.js application default page on the following screen: ![Vue.js dashboard page](https://www.atlantic.net/wp-content/uploads/2022/07/p1-8-1024x535.png) ## Conclusion In this post, we explained how to install Vue.js on Oracle Linux 10. We also created a sample application using Vue.js. You can now start using the Vue.js framework to develop a modern web application – give it a try on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account today! --- # What is a BASA Compliance Agreement? > URL: https://www.atlantic.net/hipaa-compliant-hosting/what-is-a-basa-compliance-agreement/ | Published: 2022-09-15 | Updated: 2026-06-17 | Author: Richard Bailey Companies operating in the U.S. healthcare industry are required to comply with the data security and privacy standards defined in the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The HIPAA regulations are in part designed to protect the privacy and security of an individual’s sensitive and personal healthcare information. This article will discuss when an organization needs to enter into a Business Associate Subcontractor Agreement (BASA). We will look at how a BASA differs from a Business Associate Agreement (BAA) and how it protects the organization tasked with HIPAA compliance. ## Important Terminology Let us define some important terms before delving into the details of the business agreements necessary to ensure HIPAA compliance. ## Protected Health Information and Electronic Protected Health Information Protected Health Information (PHI) and Electronic Protected Health Information (ePHI) are the patient data that HIPAA legislation was designed to safeguard. PHI is defined as individually identifiable health information collected from a person which is recorded and received by a covered entity. This includes demographic and genetic information that may be used to identify an individual. HIPAA lists 18 identifiers that need to be protected including: - A patient’s name - Dates except for the year - Telephone numbers - Social security numbers - Email addresses - Biometric identifiers such as retinal scans PHI that is transmitted electronically or stored in computer systems is considered ePHI. Some aspects of HIPAA regulations only pertain to ePHI, as we will see shortly. Covered Entity (CE) When discussing HIPAA compliance, the following types of individuals and organizations are considered covered entities: - Healthcare providers, regardless of the size of the practice, that electronically transmit health information regarding claims, benefit eligibility, and referral authorizations - Health plans, except for group plans with less than 50 members that are administered and maintained by the employer who established them - Healthcare clearinghouses that process nonstandard information into a standard format All covered entities need to comply with the HIPAA Privacy and Security Rules. Business Associate (BA) A business associate is any person or organization working on behalf of a CE to perform functions related to the use or disclosure of PHI. BAs can be involved in many aspects of a CE’s operations. BAs may also provide services to a CE. Some examples of BAs are: - Medical billing companies - Accountants - Lawyers and attorneys - Backup storage providers - IT support vendors - Third-party administrators assisting with claims processing BAs can be held liable for incurring HIPAA violations. ## Business Associate Subcontractor (BAS) A business associate subcontractor is an entity that creates, transmits, or maintains PHI or ePHI for a BA. Companies can simultaneously be a BA for one CE and a BAS for another BA. The examples listed above of potential BAs also cover the range of work a BAS can perform. A limited set of exceptions exists for entities that are conduits for PHI but do not have any direct relationship with the information. Internet service providers, the U.S. Postal Service, and other couriers and delivery services are not considered to be business associate subcontractors. ## What Is HIPAA Compliance? Two main rules form the foundation of the HIPAA guidelines. CEs, BAs, and BASs are required to follow these rules to maintain HIPAA compliance. ## HIPAA Privacy Rule The HIPAA Privacy Rule addresses the use and disclosure of PHI by organizations subject to HIPAA guidelines. The rule includes standards that help patients understand their health information and how it is being used. A primary objective of the HIPAA Privacy Rule is to protect individuals’ health information while enabling it to be used effectively to provide high-quality healthcare. CEs can use and disclose PHI without an individual’s authorization in certain cases such as to facilitate treatment, payment, or to be used in the interest of public health. The Privacy Rule applies equally to PHI and ePHI. ## HIPAA Security Rule The HIPAA Security Rule is specifically designed to protect ePHI. It does not apply to PHI transmitted in writing or orally. The Security Rule requires all CEs and BAs to: - Ensure the confidentiality, integrity, and availability of ePHI - Implement the necessary measures to detect and safeguard ePHI from threats to its security - Protect against the possibility of the impermissible use or disclosure of ePHI - Certify compliance with the Security Rule by their workforce The Security Rule deals with electronically transmitted and stored ePHI and was found to be necessary to address the rise of computerized systems used in the healthcare landscape. ## Business Agreements Mandated by HIPAA Failure to comply with HIPAA regulations can result in serious financial penalties levied against the offending entity. Data breaches involving ePHI can also tarnish an organization’s reputation and lead to a loss of customers and consumer confidence. Covered entities need to protect themselves when partnering with BAs to assist in processing PHI and ePHI. This protection is built into the HIPAA guidelines in the form of two types of agreements between CEs and their partners. ## Business Associate Agreement (BAA) CEs that partner with BAs to assist in processing PHI and ePHI are required to enter into business agreements called “business associate agreements” (BAAs) that define their role and responsibilities. The BAA needs to be signed by everyone in both organizations who have access to PHI. A BAA is a written contract that defines the responsibilities of each party in protecting sensitive healthcare data. A BAA should establish the following guidelines: - The reason the BA is storing or processing ePHI for a CE - How the BA can use, store, and process ePHI - Assurances that the BA will not use the ePHI in ways not explicitly defined in the agreement. - Details on how the BA will safeguard ePHI to prevent data breaches. Additional factors need to be incorporated into BAAs when working with[cloud service providers (CSPs) beginning in 2016](https://healthitsecurity.com). BAAs need to include service level agreements (SLAs) that focus on the role of the CSP. The SLAs should address issues related to using cloud infrastructure to process ePHI. These issues include: - System reliability and availability - How ePHI will be backed up and recovered - How ePHI will be destroyed when services are terminated - Responsibility for the security of the cloud infrastructure - Limitations on the use, disclosure, and retention of ePHI A BAA needs to be in place even when the BA only has access to encrypted ePHI. ## Business Associate Subcontractor Agreement (BASA) BAs may decide to engage subcontractors to perform some of the duties required by a covered entity. It is the responsibility of the BA to enter into a Business Associate Subcontractor Agreement with its subcontractors that defines their roles in processing and protecting a CE’s ePHI resources. The details of a BASA are like those of a BAA. Both documents outline the responsibilities of the signee regarding the protection of ePHI. The main difference is that a BAA is between a CE and a BA whereas a BASA is between a BA and its subcontractors. In many cases, a BA may have multiple BASAs that cover various aspects of processing an individual’s sensitive healthcare data. ## Conclusion When contracting with a third party or CSP, a covered entity should insist on a partner willing to enter a BAA. Similarly, a company acting as a business associate needs to have a BASA in place when subcontracting work to another company. [Atlantic.Net](https://www.atlantic.net/) offers covered entities the peace of mind of a BAA that guarantees the security and privacy of their ePHI resources. They can address cloud data processing needs while ensuring HIPAA guidelines are followed so a covered entity can achieve and maintain compliance. Contact us today for more information about [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/). --- # How to Install Awstats on Oracle Linux 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-awstats-on-oracle-linux-8/ | Published: 2022-09-16 | Updated: 2023-11-17 | Author: Hitesh Jethva AWStats, also called **“Advanced Web Statistics,”** is a powerful, free tool that generates advanced web server graphical statistics. It captures your Apache web server logs and can measure visits, unique visitors, authenticated users, pages, domains/countries, and more, displaying them in a graphical format. AWStats is capable of analyzing lots of web servers including IIS, Weblogic, Webstar, Squid, and mail or FTP servers. It is written in Perl. In this post, we will show you how to install AWStats on Oracle Linux 8. ## Step 1 – Install Apache Web Server Before starting, an Apache web server must be installed on your server. If not installed, you can install it with the following command: ``` dnf install httpd -y ``` Once the Apache web server is installed, start and enable the Apache service: ``` systemctl start httpd systemctl enable httpd ``` ## Step 2 – Create a Sample Website to Monitor via AWStats Next, you will need to create a website that you want to monitor using AWStats. To do so, create an Apache virtual host configuration file: ``` nano /etc/httpd/conf.d/website.conf ``` Add the following lines: ``` ServerName web.example.com ServerAdmin webmaster@example.com DocumentRoot /usr/share/httpd/noindex DirectoryIndex index.html ErrorLog /var/log/httpd/example_error.log CustomLog /var/log/httpd/example_access.log combined ``` ## Step 3 – Install AWStats By default, the AWStatspackage is not included in the Oracle Linux default repo, so you will need to install the EPEL repo and enable the ol8_codeready_builder repo. ``` dnf config-manager --set-enabled ol8_codeready_builder dnf install epel-release -y ``` Next, install the required Perl modules with the following command: ``` dnf install perl perl-libwww-perl.noarch ``` Next, install the AWStats package using the following command: ``` dnf install awstats ``` ## Step 4 – Configure Awstats By default, AWStats generates the Apache configuration file and save it at **/etc/httpd/conf.d/awstats.conf**, so, you will need to create a separate configuration file for your website web.example.com. To do so, create a copy of the main configuration file to the file that matches your domain name: ``` cp /etc/awstats/awstats.oraclelinux8.conf /etc/awstats/awstats.web.example.com.conf ``` Next, edit the configuration file: ``` nano /etc/awstats/awstats.web.example.com.conf ``` Define your Apache server log file and domain name as shown below: ``` LogFile="/var/log/httpd/example_access.log" SiteDomain="web.example.com" HostAliases="REGEX[web.example.com]" ``` Save and close the file, then generate your initial statistics from the current Apache logs with the following command: ``` /usr/share/awstats/wwwroot/cgi-bin/awstats.pl -config=awstats.web.example.com.conf ``` You should see the following output: ``` Create/Update database for config "/etc/awstats/awstats.web.example.com.conf" by AWStats version 7.8 (build 20200416) From data in log file "/var/log/httpd/example_access.log"... Phase 1 : First bypass old records, searching new record... Searching new records from beginning of log file... Phase 2 : Now process new records (Flush history on disk after 20000 hosts)... Jumped lines in file: 0 Parsed lines in file: 4 Found 0 dropped records, Found 0 comments, Found 0 blank records, Found 0 corrupted records, Found 0 old records, Found 4 new qualified records ``` ## Step 5 – Allow AWStats from Remote Machine By default, the Apache webserver is configured to access AWStats only from the localhost, so you will need to edit **awstats.conf** file to grant access to your IP address. ``` nano /etc/httpd/conf.d/awstats.conf ``` Find the following line: ``` Require local ``` Replace it with the following line: ``` Require ip your-system-ip ``` Save and close the file when you are finished. **Note: your-system-ip** is the IP address of your desktop system from where you want to access AWStats. You can find the IP address of your desktop system using **https://whatismyipaddress.com/.** Next, set proper ownership to the AWStats root directory with the following command: ``` chown -R apache: /usr/share/awstats/wwwroot/ ``` Next, restart the Apache service to apply the configuration changes: ``` systemctl restart httpd ``` ## Step 6 – Access Awstats Now, open your web browser and access your Apache website log statistics using the URL **http://your-server-ip/awstats/awstats.pl?config=web.example.com**. You should see the AWStats dashboard on the following screen: ![awstats dashboard page](https://www.atlantic.net/wp-content/uploads/2022/07/p1-11-1024x508.png) ## Conclusion In the above post, we explained how to install and configure AWStats to analyze your website log on Oracle Linux 8. You can now host AWStats in your organization to monitor your website. Try it on your [VPS hosting](https://www.atlantic.net/vps-hosting/) account from Atlantic.Net. --- # Why Is FedEx Closing All Its Data Centers? Why It Makes Sense To Move To The Cloud > URL: https://www.atlantic.net/vps-hosting/why-is-fedex-closing-all-its-data-centers-why-it-makes-sense-to-move-to-the-cloud/ | Published: 2022-09-17 | Updated: 2025-10-21 | Author: Dr. Rachael Bailey Hot on the heels of many other large companies, the delivery giant FedEx has announced its plans to close down its remaining data centers and migrate fully to the cloud within the next two years. According to the data center information site, Baxtel, FedEx currently has only one remaining data center in Colorado Springs. Dubbed a “zero data center, zero mainframe” strategy, their move to the cloud looks set to save the company an estimated [$400 million a year](https://www.theregister.com/2022/07/05/fedex_to_close_all_datacenters/). ## A Long Time Coming Throughout its history, FedEx has established itself as a leader in technological innovation. Keen not to fall behind, FedEx has made a move to fully embrace cloud-native structures by 2024. While, along with other companies, FedEx began its transition into the cloud long ago, the COVID-19 pandemic has served to hasten the adoption process. With the shipping and logistics market being more saturated than ever, companies must do all that they can to cut down on costs moving forwards. ## How Will a Move to the Cloud Benefit FedEx? Moving from private and leased data centers to the public cloud makes excellent sense. After all, the public cloud offers distinct advantages to large companies, including scalability, cost reduction, resource optimization, simplified disaster recovery, and the ability to build applications faster. Cloud computing gives companies the edge, encouraging them to stay ahead of the competition and driving innovation. The cloud’s security advantages are unparalleled when compared to other hosting solutions. Cloud hosting companies offer a plethora of security options to protect client data, including VPNs, firewalls, and [intrusion detection systems](https://www.atlantic.net/managed-services/intrusion-detection-service/). Regular updates mean that cloud solutions can always stay one step ahead of the latest cybersecurity threats. Clients need not worry about the security of their data, as all data stored in the cloud is fully encrypted. Should the worst happen, cloud security provides enhanced disaster recovery and business continuity. Cloud-based services allow you to scale up or slim down as your company grows and evolves. The flexibility that this offers a large company such as FedEx is invaluable. Additionally, FedEx will benefit from massive cost and space savings. With larger companies, it takes a lot of effort to keep on top of data insights and analytics. Cloud technology helps to streamline this process and makes it easier to share and collaborate on these findings. In fact, a move to the cloud will make collaboration so much more accessible right across the company. Shared documents and automatic syncing mean that employees can collaborate on projects even when geographically disparate. Given the increase in remote working post-pandemic, these capabilities are essential. As we all work towards making more environmentally friendly choices for ourselves and our businesses, a move to the cloud supports a more sustainable work life. Energy savings will be made with the closure of data centers and the on-demand options offered by cloud services. ## Are There Any Risks? Given the scale and success of the company, it is likely that FedEx has a clear strategy in place when it comes to migrating to the cloud. However, nothing is without risk, and a transition to the cloud is no different. So, what risks will FedEx face as they migrate to the cloud? One of the major concerns, when companies migrate to the cloud, is whether existing architecture will be compatible. Therefore, all existing architecture should be audited to mitigate this risk and to ensure that any potential incompatibilities are dealt with early on. Inevitably, security risks, such as compliance violations and unsecured APIs, are involved with a move to cloud computing; these risks should be addressed from the start. Once security risks have been identified, preventative steps can be taken to deal with them. As data is moved, there is always the potential for it to be lost or corrupted. Creating multiple backups of your data will ensure this is not a problem. While some risks are associated with cloud migration, the advantages are unquestionable. Careful planning and preparation can help to overcome these risks, allowing companies to realize the full potential of cloud computing. Companies of all sizes, not just those as large as FedEx, can benefit from moving to the cloud. ## Atlantic.Net Can Make This Move Easy Atlantic.Net is a trusted [VPS hosting services](https://www.atlantic.net/vps-hosting/) provider with over 25 years of experience. We offer a range of customized hosting solutions designed to provide companies with the potential to grow and prosper. Atlantic.Net is SOC 2 and SOC 3 certified, HIPAA and HITECH audited, PCI-DSS compliant, and regularly audited for security. Some of the many reasons to choose Atlantic.Net to meet your business needs include a 100% uptime service level agreement, world-class data center infrastructure, and industry-leading certifications and partnerships. [Contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) and discover how your company can benefit from a move to the cloud, just like FedEx. --- # How to Install Sonatype Nexus Repository Manager on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-sonatype-nexus-repository-manager-on-oracle-linux-10/ | Published: 2022-09-18 | Updated: 2025-12-27 | Author: Hitesh Jethva Sonatype Nexus is a free, open-source artifact management tool that helps you to manage artifacts effectively across your software supply chain. It provides a single source of truth for every component with native package manager compatibility. It can be integrated with your existing user and authentication systems like LDAP and Atlassian Crowd. Sonatype Nexus is compatible with popular IDEs and CI like Eclipse, IntelliJ, Visual Studio, Jenkins, and more. In this post, we will show you how to install Sonatype Nexus on Oracle Linux 10. ## Step 1 – Install Java JDK Sonatype Nexus is a Java-based application, so Java must be installed on your system. If not installed, you can install it with the following command: ``` dnf update -y dnf install java-21-openjdk -y ``` Once Java is installed, you can verify the Java version using the following command: ``` java -version ``` You should see the following output: ``` openjdk version "21.0.9" 2025-10-21 LTS OpenJDK Runtime Environment (Red_Hat-21.0.9.0.10-1.0.1) (build 21.0.9+10-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.9.0.10-1.0.1) (build 21.0.9+10-LTS, mixed mode, sharing) ``` ## Step 2 – Install Sonatype Nexus on Oracle Linux 8 First, create a dedicated user to run Nexus with the following command: ``` adduser nexus ``` Next, create the required directory to store Nexus files: ``` mkdir /app ``` Next, change the directory to /app and download the latest version of Nexus with the following command: ``` cd /app wget -O nexus.tar.gz https://download.sonatype.com/nexus/3/nexus-3.87.1-01-linux-x86_64.tar.gz ``` Next, extract the downloaded file with the following command: ``` tar -xvf nexus.tar.gz ``` Next, rename the extracted directory with the following command: ``` mv nexus-3* nexus ``` Next, change the ownership and permissions of the Nexus directory with the following command: ``` chown -R nexus:nexus /app/nexus chown -R nexus:nexus /app/sonatype-work ``` ## Step 3 – Create a Systemd Service File for Nexus Next, you will need to create a systemd service file to manage the Nexus via systemd. You can create it with the following command: ``` nano /etc/systemd/system/nexus.service ``` Add the following configurations: ``` [Unit] Description=nexus service After=network.target [Service] Type=forking LimitNOFILE=65536 User=nexus Group=nexus ExecStart=/app/nexus/bin/nexus start ExecStop=/app/nexus/bin/nexus stop User=nexus Restart=on-abort [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start and enable the Nexus service with the following command: ``` systemctl start nexus systemctl enable nexus ``` You can check the status of the Nexus service using the following command: ``` systemctl status nexus ``` You will get the following output: ``` ● nexus.service - nexus service Loaded: loaded (/etc/systemd/system/nexus.service; disabled; preset: disabled) Active: active (running) since Sat 2025-12-27 03:08:20 EST; 4s ago Invocation: a0a502f0d6b642928067f00b8f945727 Process: 3227 ExecStart=/app/nexus/bin/nexus start (code=exited, status=0/SUCCESS) Main PID: 3474 (java) Tasks: 20 (limit: 24812) Memory: 321.7M (peak: 322.2M) CPU: 9.280s CGroup: /system.slice/nexus.service └─3474 /app/nexus/jdk/temurin_21.0.9_10_linux_x86_64/jdk-21.0.9+10/bin/java -server -Dnexus.installer.type=linux-x86-64 -Xms2703m -Xmx2703m -XX:+UnlockDiagnosticVMOptions> ``` ## Step 4 – Access Nexus Web Interface At this point, Nexus is started and listens on port **8081.** You can check it with the following command: ``` ss -antpl ``` You will get the following output: ``` State Recv-Q Send-Q Local Address:Port Peer Address:Port Process LISTEN 0 1 127.0.0.1:42221 0.0.0.0:* users:(("java",pid=13939,fd=118)) LISTEN 0 50 0.0.0.0:8081 0.0.0.0:* users:(("java",pid=13939,fd=971)) ``` Nexus’s default username is admin and the default password is stored in the **/app/sonatype-work/nexus3/admin.password** file. You can see the Nexus admin password with the following command: ``` cat /app/sonatype-work/nexus3/admin.password ``` You should see the Nexus admin password in the following output: ``` 9691dbd2-6d32-41a5-b4d4-e6ada1643869 ``` Now, open your web browser and access the Nexus web interface using the URL **http://your-server-ip:8081**. You should see the Nexus login page: ![](https://www.atlantic.net/wp-content/uploads/2022/09/n1.png) Enter your admin username, password and click **Login**. You will see the Nexus home page. ![](https://www.atlantic.net/wp-content/uploads/2022/09/n2.png) ## Conclusion In this tutorial, we explained how to install Nexus on Oracle Linux 10. You can now start managing your packages across your software supply chain. For more information, visit the Nexus [documentation](https://help.sonatype.com/repomanager3). Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install SysPass Password Manager on Oracle Linux 8 > URL: https://www.atlantic.net/vps-hosting/how-to-install-syspass-password-manager-on-oracle-linux-8/ | Published: 2022-09-19 | Updated: 2023-11-25 | Author: Hitesh Jethva sysPass is a free, open-source, multiuser password manager written in PHP. It is designed for business and personal use, allowing you to save your passwords securely. sysPass comes with a simple and easy-to-use web interface where you can save and share passwords with other users and groups. It offers a rich set of features, including centralized password management, encryption, security, permissions, access control, language configuration, and more. In this post, we will show you how to install sysPass password manager on Oracle Linux 8. ## Step 1 – Install the LAMP Server Before starting, you will need to install a LAMP server on your system. First, install the Apache and MariaDB server package using the following command: ``` dnf install httpd mariadb-server -y ``` Next, enable the PHP 7.4 module with the following command: ``` dnf module enable php:7.4 ``` Next, install PHP with other required extensions using the following command: ``` dnf install php php-fpm php-mysqli php-pdo php-pear php-cgi php-cli php-common php-gd php-json php-readline php-curl php-intl php-ldap php-xml php-mbstring git -y ``` Once all the PHP packages are installed, edit the PHP configuration file and change the recommended settings: ``` nano /etc/php.ini ``` Change the following settings: ``` post_max_size = 100M upload_max_filesize = 100M max_execution_time = 7200 memory_limit = 512M date.timezone = UTC ``` Save the file, then start and enable the Apache service with the following command: ``` systemctl start mariadb httpd php-fpm systemctl enable mariadb httpd php-fpm ``` ## Step 2 – Create a Database for sysPass Next, you will need to create a database and user for sysPass. First, connect to MariaDB with the following command: ``` mysql ``` Once you are connected, create a database and user with the following command: ``` create database syspass; grant all privileges on syspass.* to syspass@localhost identified by "securepassword"; ``` Next, flush the privileges and exit from MariaDB with the following command: ``` flush privileges; exit; ``` ## Step 3 – Install sysPass First, download the latest version of sysPass from the Git repository using the following command: ``` git clone https://github.com/nuxsmin/sysPass.git ``` Once the download is completed, move the downloaded directory to the Apache web root: ``` mv sysPass /var/www/html/syspass ``` Next, change the ownership and permissions of the sysPass directory: ``` chown -R apache:apache /var/www/html/syspass chmod 750 /var/www/html/syspass/app/{config,backup} ``` Next, you will also need to install Composer to install PHP dependencies. To do so, create a Composer installation file: ``` nano /var/www/html/syspass/install-composer.sh ``` Add the following codes: ``` #!/bin/sh EXPECTED_SIGNATURE="$(wget -q -O - https://composer.github.io/installer.sig)" php -r "copy('https://getcomposer.org/installer', 'composer-setup.php');" ACTUAL_SIGNATURE="$(php -r "echo hash_file('sha384', 'composer-setup.php');")" if [ "$EXPECTED_SIGNATURE" != "$ACTUAL_SIGNATURE" ] then >&2 echo 'ERROR: Invalid installer signature' rm composer-setup.php exit 1 fi php composer-setup.php --quiet RESULT=$? rm composer-setup.php exit $RESUL ``` Save and close the file, then navigate to the sysPass directory and install Composer with the following command: ``` cd /var/www/html/syspass/ sh install-composer.sh ``` Next, install all required PHP dependencies with the following command: ``` php composer.phar install --no-dev ``` ## Step 4 – Configure Apache for sysPass Next, create an Apache virtual host configuration file for sysPass: ``` nano /etc/httpd/conf.d/syspass.conf ``` Add the following codes: ``` ServerAdmin admin@your-domain.com DocumentRoot "/var/www/html/syspass" ServerName syspass.example.com Options MultiViews FollowSymlinks AllowOverride All Order allow,deny Allow from all TransferLog /var/log/httpd/syspass_access.log ErrorLog /var/log/httpd/syspass_error.log ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` To check the Apache status, run the following command: ``` systemctl status httpd ``` You should see the following output: ``` ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; vendor preset: disabled) Drop-In: /usr/lib/systemd/system/httpd.service.d └─php-fpm.conf Active: active (running) since Tue 2022-07-19 07:23:26 EDT; 11s ago Docs: man:httpd.service(8) Main PID: 36714 (httpd) Status: "Running, listening on: port 80" Tasks: 213 (limit: 11409) Memory: 25.2M CGroup: /system.slice/httpd.service ├─36714 /usr/sbin/httpd -DFOREGROUND ├─36715 /usr/sbin/httpd -DFOREGROUND ├─36716 /usr/sbin/httpd -DFOREGROUND ├─36717 /usr/sbin/httpd -DFOREGROUND └─36718 /usr/sbin/httpd -DFOREGROUND Jul 19 07:23:25 oraclelinux8 systemd[1]: httpd.service: Succeeded. Jul 19 07:23:25 oraclelinux8 systemd[1]: Stopped The Apache HTTP Server. Jul 19 07:23:25 oraclelinux8 systemd[1]: Starting The Apache HTTP Server... ``` ## Step 5 – Access sysPass Web UI Now, open your web browser and type the URL **http://syspass.example.com** to access the sysPass web interface. You should see the following screen: ![define syspass admin](https://www.atlantic.net/wp-content/uploads/2022/07/p1-12-1024x408.png) ![define syspass database](https://www.atlantic.net/wp-content/uploads/2022/07/p2-9-1024x484.png) Define your admin username, password, database, and language, and click on the **INSTALL** button. Once sysPass has been installed, you will be redirected to the sysPass login screen: ![syspass login page](https://www.atlantic.net/wp-content/uploads/2022/07/p3-7-1024x494.png) Type your admin username and password and click on the **>** button. You should see the sysPass dashboard. ![syspass dashboard page](https://www.atlantic.net/wp-content/uploads/2022/07/p4-4-1024x402.png) ## Conclusion In this tutorial, you learned how to install sysPass password manager on Oracle Linux 8. You can now explore the sysPass features and start implementing sysPass in your organization. Give it a try using [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # OrBit Malware and Linux > URL: https://www.atlantic.net/dedicated-server-hosting/orbit-malware-and-linux/ | Published: 2022-09-20 | Updated: 2025-09-15 | Author: Richard Bailey Malware is a collective term for any software created to cause disruption in a computer or network. Linux has an enviable reputation when it comes to protecting against malware and viruses. However, hacking communities strive to create malware to extort data, steal private information, or gain unauthorized access to Linux systems. In recent months hackers have been making headway in compromising the Linux operating system when specific conditions are met. OrBit is the fourth variant of offensive malware discovered in the last 12 months, the others being BPFDoor, Symbiote, and Syslogk. As hackers have increased their activity targeting Linux, OrBit appears to be the next step in compromising a popular operating system used extensively in the data center and the cloud. A compromised Linux server can provide remote SSH access to the server and even harvest credentials via a key logger. In addition, all TTY commands typed into the console are logged. ## How Does OrBit Infect? OrBit is serious malware posing a significant risk to anyone who operates a Linux workload. The good news is that OrBit’s infecting a server requires root credentials to activate the malware. This makes it much harder to deliver the payload, especially for security-conscious businesses with SELinux enabled. The attack vectors involve brute force root password attacks against the target [Linux server](https://www.atlantic.net/vps-hosting/linux-vps-hosting/). This is achieved via social engineering, phishing, or perhaps rogue employees. Root access is essential to get the elevated permissions required to deliver the malware payload. OrBit malware uses two different methods to load a malicious library into memory: 1. By adding a shared object to the configuration file used by the loader. 2. By patching the binary of the loader, so it loads a malicious shared object. This unique approach essentially makes the malware impossible to detect. It uses symlinks to fundamental processes and hides in plain sight. According to [Intezer](https://www.intezer.com/blog/incident-response/orbit-new-undetected-linux-threat/), the organization that discovered OrBit, the malware is impossible to see using standard monitoring, and 0 out of 60 antivirus products tested could recognize the malware payload. ## Hiding in Plain Sight The OrBit malware functions in a way that hides the payload in plain sight. It’s almost invisible to the operating system. Data is saved in small hidden files and sent out masked as DNS A records to a command and control server located somewhere on the Internet. The malware logs all keystrokes on the server and duplicates this data to the C&C, essentially publishing root access to the hacker. The malware is clever. Nearly all output related to the malware is redacted. Any malicious output is masked and will never get outputted to log files, so the Linux Kernel doesn’t know it exists. ## How to Protect Against OrBit Preparation is the best defense against OrBit malware, and introducing security controls for important cloud assets is essential in today’s security-conscious workplace. Unfortunately, not all employees are seasoned security professionals, and the basic security principles and concepts must be taught and practiced throughout the business. The Threat Actors are cybercriminals, hackers, hacktivists, insiders, and occasionally state-sponsored actors who target businesses and government institutions for personal gain. Most actions are financially motivated, while some want to vandalize or disrupt the industry. State-sponsored threat actors want to steal intellectual property and secrets or disrupt major enterprise businesses for political gain. Industry best practice is to disable the root account and only have sudo root access to specific power users. Additionally, it is best practice to have very complex root passwords if you have to use root. A secure password must be a non-dictionary word that uses letters, numbers, symbols, and special characters. Consider splitting their permissions for different tasks and specific use cases for cloud administrators or privileged users. For example, perhaps assign read-only roles for everyday tasks such as reviewing logs and inspecting infrastructure, reserving power user or administrator privileges for significant changes such as building infrastructure as code. Additionally, implementing a defense-in-depth strategy when it comes to cybersecurity – that is, a strategy that recognizes that security control can fail. With a defense-in-depth strategy, you create multiple layers of security to ‘catch all’ threats. This layered approach helps to minimize the risk of a security breach and create boundaries of trust that protect the environment even if other components are compromised. ## Choose a Security Conscious Hosting Provider If your business is concerned about cybersecurity, please contact Atlantic.Net. We are specialists in Managed Services, [Dedicated Hosting](https://www.atlantic.net/dedicated-server-hosting/), Cloud Hosting, and [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/). Security of our infrastructure is paramount, and we work hard to ensure we have the best security processes in place. [Get in touch today.](https://www.atlantic.net/about-us/corporate-contact/) --- # How to Install and Configure Velociraptor on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-velociraptor-on-oracle-linux-10/ | Published: 2022-09-21 | Updated: 2025-12-11 | Author: Hitesh Jethva Velociraptor is a free and open-source digital forensic and incident response tool that enhances your visibility into your endpoints. It is based on GRR, OSQuery, and Google’s Rekall tool and uses Velociraptor Query Language to collect host-based state information. It is a very powerful tool that is capable of collecting artifacts from thousands of endpoints in a matter of seconds. Velociraptor is made from six components such as GUI, Frontend, Client, VQL Engine, Datastore, and File store. In this post, we will explain how to install Velociraptor on Oracle Linux 10. ## Step 1 – Install Velociraptor on Oracle Linux 10 First, download the latest version of the Velociraptor binary from the GitHub repository using the following commands: ``` dnf update -y ``` ``` wget https://github.com/Velocidex/velociraptor/releases/download/v0.75/velociraptor-v0.75.1-linux-amd64 -O /usr/local/bin/velociraptor ``` Once the download is completed, set execution permissions to the downloaded binary: ``` chmod +x /usr/local/bin/velociraptor ``` You can now verify the Velociraptor version with the following command: ``` velociraptor version ``` ## Step 2 – Configure Velociraptor First, create a configuration directory for Velociraptor with the following command: ``` mkdir /etc/velociraptor ``` Next, generate the Velociraptor configuration file with the following command: ``` velociraptor config generate -i ``` Answer all the questions as shown below: ``` Welcome to the Velociraptor configuration generator --------------------------------------------------- I will be creating a new deployment configuration for you. I will begin by identifying what type of deployment you need. What OS will the server be deployed on? [Use arrows to move, type to filter] > linux windows darwin ? Path to the datastore directory. (/opt/velociraptor) > Self Signed SSL Automatically provision certificates with Lets Encrypt Authenticate users with SSO ? What is the public DNS name of the Master Frontend (e.g. www.example.com): vraptor.example.com ? Enter the frontend port to listen on. 8000 ? Enter the port for the GUI to listen on. 8889 ? Are you using Google Domains DynDNS? (y/N) N ? GUI Username or email address to authorize (empty to end): hitjethva@gmail.com ? Password ********** ? GUI Username or email address to authorize (empty to end): [INFO] 2022-09-01T08:16:10-04:00 _ __ __ _ __ [INFO] 2022-09-01T08:16:10-04:00 | | / /__ / /___ _____(_)________ _____ / /_____ _____ [INFO] 2022-09-01T08:16:10-04:00 | | / / _ \/ / __ \/ ___/ / ___/ __ `/ __ \/ __/ __ \/ ___/ [INFO] 2022-09-01T08:16:10-04:00 | |/ / __/ / /_/ / /__/ / / / /_/ / /_/ / /_/ /_/ / / [INFO] 2022-09-01T08:16:10-04:00 |___/\___/_/\____/\___/_/_/ \__,_/ .___/\__/\____/_/ [INFO] 2022-09-01T08:16:10-04:00 /_/ [INFO] 2022-09-01T08:16:10-04:00 Digging deeper! https://www.velocidex.com [INFO] 2022-09-01T08:16:10-04:00 Generating keys please wait.... ? Path to the logs directory. /opt/velociraptor/logs ? Where should i write the server config file? /etc/velociraptor/server.config.yaml ? Where should i write the client config file? /etc/velociraptor/client.config.yaml ``` Next, edit the Velociraptor configuration file and define your bind address: ``` cp server.config.yaml /etc/velociraptor/server.config.yaml nano /etc/velociraptor/server.config.yaml ``` Replace 127.0.0.1 with your-server-ip: ``` API: bind_address: 209.23.13.108 GUI: bind_address: 209.23.13.108 Monitoring: bind_address: 209.23.13.108 ``` Save and close the file, then create an administrative user with the following command: ``` velociraptor --config /etc/velociraptor/server.config.yaml user add admin --role administrator ``` Set your admin password as shown below: ``` Enter user's password: ``` ## Step 3 – Start Velociraptor Frontend You can now start the Velociraptor Frontend with the following command: ``` velociraptor -c /etc/velociraptor/server.config.yaml frontend -v ``` If everything is fine, you will get the following output: ``` [INFO] 2025-12-11T05:33:02Z _ __ __ _ __ [INFO] 2025-12-11T05:33:02Z | | / /__ / /___ _____(_)________ _____ / /_____ _____ [INFO] 2025-12-11T05:33:02Z | | / / _ \/ / __ \/ ___/ / ___/ __ `/ __ \/ __/ __ \/ ___/ [INFO] 2025-12-11T05:33:02Z | |/ / __/ / /_/ / /__/ / / / /_/ / /_/ / /_/ /_/ / / [INFO] 2025-12-11T05:33:02Z |___/\___/_/\____/\___/_/_/ \__,_/ .___/\__/\____/_/ [INFO] 2025-12-11T05:33:02Z /_/ [INFO] 2025-12-11T05:33:02Z Digging deeper! https://www.velocidex.com [INFO] 2025-12-11T05:33:02Z This is Velociraptor 0.75.1 built on 2025-09-03T16:01:20Z (46ff090b9) ``` Press the CTRL+C to stop Velociraptor. We will configure the systemd service for Velociraptor in the next step. ## Step 4 – Create a Systemd Unit File for Velociraptor It is a good idea to create a systemd service file to manage the Velociraptor service. You can create it with the following command: ``` nano /etc/systemd/system/velociraptor.service ``` Add the following lines: ``` [Unit] Description=Velociraptor linux amd64 After=syslog.target network.target [Service] Type=simple Restart=always RestartSec=120 LimitNOFILE=20000 Environment=LANG=en_US.UTF-8 ExecStart=/usr/local/bin/velociraptor -c /etc/velociraptor/server.config.yaml frontend -v [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes: ``` systemctl daemon-reload ``` Next, start and enable the Velociraptor service with the following command: ``` systemctl enable --now velociraptor ``` You can check the status of Velociraptor with the following command: ``` systemctl status velociraptor ``` You will get the following output: ``` ● velociraptor.service - Velociraptor linux amd64 Loaded: loaded (/etc/systemd/system/velociraptor.service; enabled; preset: disabled) Active: active (running) since Thu 2025-12-11 00:26:40 EST; 2s ago Invocation: 8e1d25af7f9e4ce8896d52207cceb982 Main PID: 265041 (velociraptor) Tasks: 15 (limit: 24812) Memory: 74M (peak: 74.7M) CPU: 2.046s CGroup: /system.slice/velociraptor.service ├─265041 /usr/local/bin/velociraptor -c /etc/velociraptor/server.config.yaml frontend -v └─265048 /usr/local/bin/velociraptor -c /etc/velociraptor/server.config.yaml frontend -v Dec 11 00:26:41 oracle velociraptor[265041]: [INFO] 2025-12-11T05:26:41Z server_monitoring_service: Watching for events from Server.Internal.MetadataModifications Dec 11 00:26:41 oracle velociraptor[265041]: [INFO] 2025-12-11T05:26:41Z Converting legacy client index to new format Dec 11 00:26:41 oracle velociraptor[265041]: [INFO] 2025-12-11T05:26:41Z CryptoServerManager: Watching for events from Server.Internal.ClientDelete Dec 11 00:26:41 oracle velociraptor[265041]: [INFO] 2025-12-11T05:26:41Z Throttling connections to 100 QPS Dec 11 00:26:41 oracle velociraptor[265041]: [INFO] 2025-12-11T05:26:41Z Starting gRPC API server on 209.23.13.108:8001 Dec 11 00:26:41 oracle velociraptor[265041]: [INFO] 2025-12-11T05:26:41Z Launched Prometheus monitoring server on 209.23.13.108:8003 Dec 11 00:26:41 oracle velociraptor[265041]: [INFO] 2025-12-11T05:26:41Z GUI will use the Basic authenticator Dec 11 00:26:41 oracle velociraptor[265041]: [INFO] 2025-12-11T05:26:41Z GUI is ready to handle TLS requests on https://209.23.13.108:8889/ Dec 11 00:26:41 oracle velociraptor[265041]: [INFO] 2025-12-11T05:26:41Z Frontend is ready to handle client TLS requests at https://localhost:8000/ Dec 11 00:26:42 oracle velociraptor[265041]: [INFO] 2025-12-11T05:26:42Z Compiled all artifacts. ``` ## Step 5 – Access the Velociraptor Web Interface At this point, Velociraptor is installed, started, and listening on port **8889.** You can now access it using the URL **https://your-server-ip:8889**. You should see the Velociraptor login page: ![](https://www.atlantic.net/wp-content/uploads/2022/09/v1.png)Provide your admin username, password and click Sign in. You will see the Velociraptor dashboard. ![](https://www.atlantic.net/wp-content/uploads/2022/09/v2.png) ## Conclusion Congratulations! You have successfully installed Velociraptor on Oracle Linux 10. You can now use Velociraptor for endpoint monitoring, digital forensic investigations, and threat hunting. For more information, Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How To Install Kamailio SIP Server on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-kamailio-sip-server-on-oracle-linux-10/ | Published: 2022-09-22 | Updated: 2025-12-10 | Author: Hitesh Jethva Kamailio is a free and open-source SIP server written in C. It can handle over 5000 call setups per second and serve up to 300,000 active subscribers with just 4GB RAM. You can use Kamailio as a registrar server, location server, proxy server, SIP application server, and redirect server. It supports both IPv4 and IPv6 IP addresses and can be installed on all major Linux-based operating systems. In this post, we will show you how to install a Kamailio SIP server on Oracle Linux 10. ## Step 1 – Install and Configure MariaDB Server Kamailio uses MariaDB as a database backend, so you will need to install a MariaDB server on your system. You can install it by running the following command: ``` dnf update -y dnf install mariadb-server -y ``` Once the MariaDB server is installed, start and enable the MariaDB service using the following command: ``` systemctl start mariadb systemctl enable mariadb ``` Next, you will need to secure the MariaDB installation and set the MariaDB root password: ``` mysql_secure_installation ``` Answer all questions as shown below: ``` Enter current password for root (enter for none): OK, successfully used password, moving on... Setting the root password ensures that nobody can log into the MariaDB root user without the proper authorisation. Set root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` ## Step 2 – Add Kamailio Repo By default, the Kamailio package is not included in the Oracle Linux 8 default repo, so you will need to add it to your system. You can add it with the following command: ``` yum install dnf-plugins-core -y yum config-manager --add-repo https://rpm.kamailio.org/centos/kamailio.repo ``` Once the Kamailio repo is added, you can verify it using the following command: ``` dnf repolist ``` You should get the following output: ``` repo id repo name kamailio Kamailio - latest - Packages for the Kamailio latest release ``` ## Step 3 – Install Kamailio Server Now, run the following command to install the Kamailio server with other required packages: ``` dnf install vim kamailio kamailio-mysql kamailio-presence kamailio-ldap kamailio-debuginfo kamailio-xmpp kamailio-unixodbc kamailio-utils kamailio-gzcompress kamailio-tls kamailio-outbound -y ``` After successful installation, you can verify the Kamailio version with the following command: ``` kamailio -version ``` You should get the following output: ``` version: kamailio 6.0.4 (x86_64/linux) flags: USE_TCP, USE_TLS, USE_SCTP, TLS_HOOKS, USE_RAW_SOCKS, DISABLE_NAGLE, USE_MCAST, DNS_IP_HACK, SHM_MMAP, PKG_MALLOC, MEM_JOIN_FREE, Q_MALLOC, F_MALLOC, TLSF_MALLOC, DBG_SR_MEMORY, USE_FUTEX, FAST_LOCK-ADAPTIVE_WAIT, USE_DNS_CACHE, USE_DNS_FAILOVER, USE_NAPTR, USE_DST_BLOCKLIST, HAVE_RESOLV_RES, TLS_PTHREAD_MUTEX_SHARED ADAPTIVE_WAIT_LOOPS 1024, MAX_RECV_BUFFER_SIZE 262144, MAX_SEND_BUFFER_SIZE 262144, MAX_URI_SIZE 1024, BUF_SIZE 65535, DEFAULT PKG_SIZE 8MB poll method support: poll, epoll_lt, epoll_et, sigio_rt, select. id: compiled on 00:00:00 Sep 13 2022 with gcc 14.3.1 ``` ## Step 4 – Configure Kamailio Server The Kamailio default configuration file is located at **/etc/kamailio/kamctlrc**. You will need to edit it and define your database and host. ``` nano /etc/kamailio/kamctlrc ``` Change the following lines: ``` DBENGINE=MYSQL DBHOST=localhost ``` Save and close the file. Next, open the **/etc/kamailio/kamailio.cfg** file and enable some features: ``` nano /etc/kamailio/kamailio.cfg ``` Add the following lines below #!KAMAILIO. ``` #!define WITH_MYSQL #!define WITH_AUTH #!define WITH_USRLOCDB #!define WITH_NAT #!define WITH_PRESENCE #!define WITH_ACCDB ``` Save and close the file, then restart the Kamailio service to apply the changes: ``` systemctl restart kamailio ``` You can now check the status of Kamailio with the following command: ``` systemctl status kamailio ``` You will get the following output: ``` ● kamailio.service - Kamailio - the Open Source SIP Server Loaded: loaded (/usr/lib/systemd/system/kamailio.service; enabled; preset: disabled) Active: active (running) since Wed 2025-12-10 23:18:54 EST; 4s ago Invocation: f4f12f6986c14338bf12a36dae246e81 Docs: man:kamailio(8) Main PID: 247531 (kamailio) Tasks: 34 (limit: 24812) Memory: 26.7M (peak: 27M) CPU: 85ms CGroup: /system.slice/kamailio.service ├─247531 /usr/sbin/kamailio --atexit=no -DD -P /run/kamailio/kamailio.pid -f /etc/kamailio/kamailio.cfg -m 64 -M 8 ``` ## Step 5 – Install Siremis Web UI Siremis provides a web-based interface to manage the Kamailio SIP server. First, install go package with the following command: ``` dnf install go -y ``` Next, navigate to the Apache web root directory and download the latest version of Siremis: ``` cd /var/www git clone https://github.com/asipto/siremis ``` Next, change the directory to the downloaded directory and edit the Siremis configuration files: ``` cd siremis nano main.go ``` Change the below line: ``` httpsrv: "your-server-ip:8284", ``` Next, copy all sample configuration files. ``` cp etc/config-sample.json etc/config.json cp etc/siremis-menu-sample.json etc/siremis-menu.json cp etc/siremis-charts-sample.json etc/siremis-charts.json ``` Next, edit the Siremis config file. ``` nano etc/siremis-config.json ``` Define your admin username and password: ``` "Username": "admin", "Password": "text123", ``` Next, create a database and tables: ``` kamdbctl create ``` Output. ``` MySQL password for : INFO: test server charset INFO: creating database kamailio ... INFO: granting privileges to database kamailio ... INFO: creating standard tables into kamailio ... INFO: Core Kamailio tables successfully created. Create the presence related tables? (y/n): y INFO: creating presence tables into kamailio ... INFO: Presence tables successfully created. Create the tables for imc cpl siptrace domainpolicy carrierroute drouting userblocklist htable purple uac pipelimit mtree sca mohqueue rtpproxy rtpengine secfilter ims_icscf? (y/n): y INFO: creating extra tables into kamailio ... INFO: Extra tables successfully created. Create the tables for uid_auth_db uid_avp_db uid_domain uid_gflags uid_uri_db? (y/n): y INFO: creating uid tables into kamailio ... INFO: UID tables successfully created. ``` Finally, build the Siremis with the following command. ``` go build . ``` Now, run the Siremis using the below command. ``` ./siremis ``` Output: ``` 2025/12/10 23:55:14 main.go:52: staring HTTP service on: http://209.23.13.108:8284/siremis ... ``` ## Step 6 – Access Siremis Web UI Now, open your web browser and access the Siremis web interface using the URL **http://your-server-ip:8284/siremis**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2022/09/s1.png) Provide your admin username, password and click on **Login**. You will see the Siremis dashboard. ![](https://www.atlantic.net/wp-content/uploads/2022/09/s2.png) ## Conclusion In this post, we explained how to install the Kamailio SIP server on Oracle Linux 10. We also explained how to install the Siremis web interface to manage the Kamailio SIP server. You can now start managing your SIP server via a web browser. Get started with Kamailio on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Kanban Kanboard on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-kanban-kanboard-on-oracle-linux-10/ | Published: 2022-09-23 | Updated: 2025-12-10 | Author: Hitesh Jethva Kanboard is a free and open-source project management system that visualizes the work and manages project goals. It provides a simple and user-friendly web interface that allows you to create and manage projects and tasks via a web browser. It helps beginner users to build and manage content from every device. It supports multiple authentication methods, including LDAP, Active Directory, and other OAuth2 providers. In this post, we will show you how to install Kanboard project management software on Oracle Linux 10. ## Step 1 – Install LEMP Server First, install the Nginx and MariaDB servers by running the following command: ``` dnf install nginx mariadb-server -y ``` Next, install PHP and other required PHP extensions using the following command: ``` dnf install php php-fpm php-mbstring php-cli php-json php-opcache php-zip php-xml php-gd php-ldap php-mysqli php-sqlite3 php-json php-dom -y ``` Once all the packages are installed, verify the PHP version with the following command: ``` php --version ``` You should see the following output: ``` PHP 8.3.19 (cli) (built: Mar 12 2025 13:10:27) (NTS gcc x86_64) Copyright (c) The PHP Group Zend Engine v4.3.19, Copyright (c) Zend Technologies with Zend OPcache v8.3.19, Copyright (c), by Zend Technologies ``` Next, edit the PHP-FPM configuration file and change the user from apache to nginx: ``` nano /etc/php-fpm.d/www.conf ``` Change the following lines: ``` user=nginx group=nginx ``` Save and close the file, then start and enable Nginx, MariaDB and PHP-FPM services: ``` systemctl start nginx php-fpm mariadb systemctl enable nginx php-fpm mariadb ``` ## Step 2 – Create a Database for Kanboard Next, you will need to create a database and user for Kanboard. First, log in to your MariaDB console with the following command: ``` mysql ``` Next, create a database and user with the following command: ``` CREATE DATABASE kanboard CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci; GRANT ALL PRIVILEGES ON kanboard.* TO 'kanboard'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB console with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download Kanboard Next, download the latest version of Kanboard from the GitHub repository. ``` wget https://github.com/kanboard/kanboard/archive/v1.2.48.tar.gz ``` After the successful download, extract the downloaded file: ``` tar -xvzf v1.2.48.tar.gz ``` Next, move the extracted directory to the Nginx web root: ``` mv kanboard-1.2.48 /var/www/html/kanboard ``` Next, navigate to the Kanboard directory and copy the default configuration file: ``` cd /var/www/html/kanboard cp config.default.php config.php ``` Next, edit the config.php file and define your database settings: ``` nano config.php ``` Change the following lines: ``` // Database driver: sqlite, mysql or postgres (sqlite by default) define('DB_DRIVER', 'mysql'); // Mysql/Postgres username define('DB_USERNAME', 'kanboard'); // Mysql/Postgres password define('DB_PASSWORD', 'password'); // Mysql/Postgres hostname define('DB_HOSTNAME', 'localhost'); // Mysql/Postgres database name define('DB_NAME', 'kanboard'); ``` Save and close the file, then change the ownership and permissions of the Kanboard directory: ``` chown -R nginx:nginx /var/www/html/kanboard chmod -R 775 /var/www/html/kanboard ``` ## Step 4 – Create an Nginx Virtual Host for Kanboard Next, create an Nginx virtual host configuration file for Kanboard: ``` nano /etc/nginx/conf.d/kanboard.conf ``` Add the following configurations: ``` server { listen 80; server_name kanban.example.com; index index.php; root /var/www/html/kanboard; client_max_body_size 32M; location / { try_files $uri $uri/ /index.php$is_args$args; } location ~ \.php$ { try_files $uri =404; fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_pass unix:/run/php-fpm/www.sock; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_index index.php; include fastcgi_params; } location ~* ^.+\.(log|sqlite)$ { return 404; } location ~ /\.ht { return 404; } location ~* ^.+\.(ico|jpg|gif|png|css|js|svg|eot|ttf|woff|woff2|otf)$ { log_not_found off; expires 7d; etag on; } gzip on; gzip_comp_level 3; gzip_disable "msie6"; gzip_vary on; gzip_types text/javascript application/javascript application/json text/xml application/xml application/rss+xml text/css text/plain; } ``` Save and close the file, then edit the Nginx configuration file: ``` nano /etc/nginx/nginx.conf ``` Add the following line below http {: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then verify the Nginx configuration using the following command: ``` nginx -t ``` You should see the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` You can also check the Nginx status with the following command: ``` systemctl status nginx ``` ## Step 5 – Access Kanboard Web Interface At this point, Kanboard is installed and configured on your server. You can now access it using the URL **http://kanboard.example.com**. You will be redirected to the Kanboard login page: ![Kanban login page](https://www.atlantic.net/wp-content/uploads/2022/08/p1-3.png) Provide default admin username and password as admin / admin then click on the **Sign in** button. You should see the Kanboard dashboard on the following page: ![Kanban dashboard page](https://www.atlantic.net/wp-content/uploads/2022/08/p2-2-1024x426.png) ## Conclusion In this post, we explained how to install and configure Kanboard project management software on Oracle Linux 10. You can now implement Kanboard in your organization and start managing projects and tasks from the central location. Get started with Kanban on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to setup HTTP Strict Transport Security (HSTS) for Apache on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-setup-http-strict-transport-security-hsts-for-apache-on-oracle-linux-10/ | Published: 2022-09-26 | Updated: 2025-12-10 | Author: Hitesh Jethva HSTS, which stands for “HTTP Strict Transport Security,” is a web security policy mechanism that can be used to secure HTTPS websites against downgrade attacks. HSTS prevents your web browser from accessing the website over non-HTTPS connections. Some websites contain pages that serve requests over HTTP. To avoid the usage of HTTP protocol in such cases, the HSTS header was introduced. It forces your website to redirect URLs from HTTP to HTTPS. In this post, we will explain how to enable HTTP Strict Transport Security (HSTS) for Apache on Oracle Linux 10. ## Prerequisites - A fresh Oracle Linux 10 server - A valid domain name pointed with your server - A root password configured on your server ## Step 1 – Install and Configure Apache Before starting, you will need to install the Apache web server and create a virtual host configuration file to host a website. First, install the Apache web server with the following command: ``` dnf install httpd -y ``` Once the installation is completed, start and enable the Apache service: ``` systemctl start httpd systemctl enable httpd ``` Next, create a new apache virtual host configuration file for domain test.linuxbuz.com. ``` nano /etc/httpd/conf.d/test.conf ``` Add the following configurations: ``` ServerName test.linuxbuz.com ServerAdmin webmaster@linuxbuz.com DocumentRoot /var/www/html/ DirectoryIndex index.html ``` Save and close the file, then restart Apache to apply the changes: ``` systemctl restart httpd ``` ## Step 2 – Secure Apache with Let’s Encrypt SSL Next, you will need to install the Certbot client to secure your website with SSL. First, install the EPEL repository. ``` dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-9.noarch.rpm ``` Next, install SNAP package manager. ``` dnf install snapd -y ``` Next, start the SNAP daemon. ``` systemctl enable --now snapd.socket ``` Next, create a symbolic link for SNAP. ``` ln -s /var/lib/snapd/snap /snap ``` Next, install the Certbot package. ``` snap install --classic certbot ``` Next, create a symbolic link for Certbot. ``` ln -s /snap/bin/certbot /usr/bin/certbot ``` Next, run the following command to install Let’s Encrypt SSL for your website test.linuxbuz.com. ``` certbot --apache -d test.linuxbuz.com ``` You will be asked to provide your email and accept the terms of service: ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log Enter email address (used for urgent renewal and security notices) (Enter 'c' to cancel): hitjethva@gmail.com - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Please read the Terms of Service at https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017-w-v1.3-notice.pdf. You must agree in order to register with the ACME server. Do you agree? - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - (Y)es/(N)o: Y - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Would you be willing, once your first certificate is successfully issued, to share your email address with the Electronic Frontier Foundation, a founding partner of the Let's Encrypt project and the non-profit organization that develops Certbot? We'd like to send you email about our work encrypting the web, EFF news, campaigns, and ways to support digital freedom. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - (Y)es/(N)o: Y Account registered. Requesting a certificate for test.linuxbuz.com Successfully received certificate. Certificate is saved at: /etc/letsencrypt/live/test.linuxbuz.com/fullchain.pem Key is saved at: /etc/letsencrypt/live/test.linuxbuz.com/privkey.pem This certificate expires on 2025-11-21. These files will be updated when the certificate renews. Certbot has set up a scheduled task to automatically renew this certificate in the background. Deploying certificate Successfully deployed certificate for test.linuxbuz.com to /etc/httpd/conf.d/test-le-ssl.conf Congratulations! You have successfully enabled HTTPS on https://test.linuxbuz.com - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - If you like Certbot, please consider supporting our work by: * Donating to ISRG / Let's Encrypt: https://letsencrypt.org/donate * Donating to EFF: https://eff.org/donate-le - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ``` Your website test.linuxbuz.com is now secured with Let’s Encrypt SSL. ## Step 3 – Enable HSTS Header Next, you will need to activate the HSTS header within your website virtual host configuration file. To do so, open your website virtual host configuration file: ``` nano /etc/httpd/conf.d/test-le-ssl.conf ``` Add the following line below the first line: ``` Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains" ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart httpd ``` ## Step 4 – Verify HSTS Header Your website is now configured with HSTS header. Next, you will need to verify whether the HSTS header is activated or not. You can verify it with the following command: ``` curl -s -D- https://test.linuxbuz.com/ | grep -i Strict ``` If everything is fine, you should get the following output: ``` Strict-Transport-Security: max-age=31536000; includeSubDomains ``` You can also verify it using the URL **https://www.ssllabs.com/ssltest/index.html**. ## Conclusion In the above tutorial, we explained how to enable the HSTS header for Apache on Oracle Linux 10. Your website is now secured with HSTS, and it can be accessed only through HTTPS protocol. Give HSTS a try on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Are Data Breaches In The Cloud Getting Better Or Worse? > URL: https://www.atlantic.net/vps-hosting/are-data-breaches-in-the-cloud-getting-better-or-worse/ | Published: 2022-09-27 | Updated: 2025-09-15 | Author: Richard Bailey News of the latest data breach frequently makes the headlines, and it appears the digital world will continue to have to reckon with hacking and data theft on a regular and increasing basis. Data breaches have been happening under many different guises since personal records became commonplace. Whereas in the past, criminals would walk off with briefcases full of stolen files, today, it’s the hacking community stealing countless amounts of data from big business. Data breaches are a severe, globally relevant problem affecting businesses and government institutions. As a result, cybersecurity professionals have greater scrutiny over the security posture of modern businesses and organizations. Moreover, as almost all companies rely heavily on IT systems to power innovation, the likelihood of a data breach grows daily. However, it’s not all doom and gloom, and businesses are fighting back with robust and stringent cybersecurity initiatives to minimize the risk of a data breach. Cybersecurity is taken seriously across the entire industry. Leaders are becoming wise to the intense threat cybersecurity represents to business operations and company reputation, not to mention the financial losses brought about by a successful data breach. ## A Brief History of Data Breaches The severity and impact of data breaches are becoming more significant in recent years. The number of data breaches appears to be on the increase. We curated our top 5 high-profile data breaches that impacted people’s lives, disrupted everyday businesses, and affected their business reputation. 1. **Yahoo! Data Breach (2013-2016) – 3 Billion Users Affected** – This is still the largest ever recorded data breach in history and was triggered by the spear-phishing of an employee. It cost Yahoo! nearly [$120 million in compensation](https://www.cbsnews.com/news/yahoo-data-breach-117-5-million-settlement-reached/). 2. **Target Stores (2013) – 110 Million Payment Cards Or Contact Info** – This major breach of a [U.S retailer](https://www.huffpost.com/entry/target-hacked-customer-credit-card-data-accessed_n_4471672) involved the theft of 40 million debit and credit card numbers. 3. **First American Financial Corp (2019) – 885 Million records** – This real estate [insurance broker’s website](https://gizmodo.com/885-million-sensitive-records-leaked-online-bank-trans-1835016235) leaked bank account numbers and statements, mortgage and tax documents, wire transaction receipts, Social Security numbers, and driver’s license images dating back to 2003. 4. **Equifax Data Breach (2017) – 605 Million Records** – This breach resulted in [hugely sensitive data](https://www.cnet.com/news/privacy/equifax-data-leak-hits-nearly-half-of-the-us-population/) being leaked, including names, dates of birth, Social Security numbers, addresses, genders, phone numbers, driver’s license numbers, email addresses, taxpayer IDs, driver’s licenses, and passport photos. 5. **Facebook (2019) – 540 Million Records** – Facebook exposed [millions of user records](https://www.cbsnews.com/news/millions-facebook-user-records-exposed-amazon-cloud-server/) (about 146GB) because of an unsecured AWS S3 Bucket. These five data breaches are arguably the most severe kind of data breaches. Again, check out this compilation list on Wikipedia, which goes into[great detail about known data breaches](https://en.wikipedia.org/wiki/List_of_data_breaches#cite_note-324). There is a staggering amount of data available. ## Reasons for Data Breaches Data Breaches are estimated to cost the world around [$10.5 Trillion annually](https://cybersecurityventures.com/cybercrime-damages-6-trillion-by-2021/) by 2025. Although the massive breaches experienced by Yahoo! Facebook and Equifax are less likely, attacks are becoming more targeted, with hackers hunting for specific data or specific victims. But why do companies get hacked? Here are some of the reasons why they fall afoul of data breaches. - **Poor Security** – The main reasons businesses get hacked are poor security and the weak implementation of security practices. Using weak passwords on publicly accessible resources such as a cloud server allows hackers to compromise your system in no time. Other reasons include no security training, out-of-date antivirus software, and having a business culture that does not promote security best practices. - **Ransomware** – This type of malware is reaching epidemic status. It’s the number one go-to for hackers because of the relatively high success rate in extorting money from the victim. Hackers access compromised systems via a successful phishing campaign or social engineering. Once inside the network, files are encrypted and a ransom demand is made. - **Zero-Day Vulnerabilities** – Applications are inherently vulnerable, and zero-day exploits are always a concern. This type of exploit occurs when the hacker identifies the vulnerability before anyone else. Unfortunately, no immediate patches or workarounds give the hacker the upper hand. One of the most high-profile 0-day attacks was the recent [Microsoft Exchange Server data breach](https://www.nbcnews.com/tech/security/u-s-issues-warning-after-microsoft-says-china-hacked-its-n1259522). - **Accidental Disclosure and Human Error** – This type of breach happens surprisingly often, but it’s essential to differentiate between unintentional human error and malicious foul play. Incidents include employees disclosing sensitive data and data being publicly shared to the cloud. - **Lost / Stolen Devices** – Another common incident is confidential data being lost, misplaced, or stolen. It most frequently involves missing laptops and USB storage devices. - **Misconfiguration** – Misconfiguration is frequently cited as a cause of a data breach. It is most commonly seen in the cloud by businesses that do not know the concept of cloud security. Examples include unprotected application APIs, unsecured websites, and cloud storage buckets. - **Rogue Contractor / Inside Job** – An insider threat may be a current or former employee or perhaps a malicious third party that acts maliciously to steal sensitive business data. Their motives usually surround financial gains or the opportunity to cause significant disruption to the business. ## How To Defend Against Data Breaches Defending against data breaches involves stakeholder buy-in and a concerted effort from the entire business to improve security standards. Outsourcing IT infrastructure to colocation or cloud service providers is a great way to enhance the business’s security stance overnight. An external provider will reduce the burden and security concerns to an expert team who can evaluate your organization objectively and design a solution that is unique to your organization. We have identified several other key ways to defend against a data breach. These include: - Understand Threat Actors –  Threat Actors are cybercriminals, hackers, hacktivists, insiders, or state-sponsored actors. Businesses and government institutions are targeted for personal gain and are typically financially motivated. State-sponsored threat actors target intellectual property and secrets or disrupt major enterprise businesses for political gain. - Follow The Principle Of Least Privilege: This security concept grants users or service accounts the minimum required permissions to do their jobs. A policy of denying by default minimizes the risk of having users and administrators, automation tools, and service accounts over-specced, such as granting a database account write permissions when only read is needed. - Implement Defense In-Depth: It’s important to remember that security control can fail. Create multiple layers of security to ‘catch all’ threats surrounding the data center’s physical security (including administrative processes) and remote access controls such as VPN, IAM, and Zero Trust networking. Invest in network security such as a DMZ, Firewall, or WAF, ensure server security by patching, and always encrypt your storage. Furthermore, a robust approach to [data governance security](https://www.databricks.com/discover/data-governance) is paramount, ensuring that data access, usage, and storage adhere to strict policies and guidelines, reducing the risk of unauthorized access or exposure. - Understand the Shared Responsibility Model: The general rule is that the cloud provider is responsible for the data center and the infrastructure that makes up the cloud platform, including the servers, storage, and networking layers. The customer is responsible for data integrity, usually application, middleware, and operating system security. Make sure you check the fine details with your chosen provider. ## Cloud Security Atlantic.Net Unfortunately, it does seem that data breaches in the cloud are getting worse; however, it’s important to remember that awareness is improving and that many businesses are taking appropriate action to secure their infrastructure to industry best practices. Cybersecurity is always on the agenda when we speak to our customers. You will be pleased to know that Atlantic.Net cloud services feature some of the best security standards for any cloud provider. Our cloud infrastructure and business processes are aligned to create a security-defined service. Atlantic.Net has been providing cutting-edge hosting services for over 30 years. We offer a full suite of managed services, including managed networking, managed security, Intrusion Protection Systems, Web Application Firewalls, and so on. In addition, our always-available professional support team will build the perfect solution for your business or organization. Atlantic.Net is ready to help you attain fast compliance with various certifications, such as SOC 2 and SOC 3, HIPAA, and HITECH, with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, visit us at [www.atlantic.net,](about:blank) call 866-618-DATA (3282), or email us at [sales@atlantic.net](mailto:sales@atlantic.net). You can find out more information by[contacting our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- #### Read More About Firewalls - [Managed Firewall](https://www.atlantic.net/managed-services/firewall/) Service from Atlantic.Net - [What Is a WAF?](https://www.atlantic.net/vps-hosting/waf-web-application-firewall/) - [Top 10 Firewalls](https://www.atlantic.net/hipaa-compliant-hosting/top-10-firewalls/) --- --- # How to Install Sails.js Framework with Nginx as a Reverse Proxy on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-sails-js-framework-with-nginx-as-a-reverse-proxy-on-oracle-linux-10/ | Published: 2022-09-28 | Updated: 2025-12-10 | Author: Hitesh Jethva Sails is the most popular MVC framework for Node.js. It is used for building production-ready enterprise Node.js applications. Sails is a lightweight server-side technology that uses Express for handling HTTP requests and wraps socket.io for managing WebSockets. It is used to develop chat applications, real-time dashboards, and multiplayer games. Sails provide a simple data access layer that works with any database, including MySQL, MongoDB, PostgreSQL, Redis, and local disk. In this post, we will show you how to install the Salis.js framework with Nginx as a reverse proxy on Oracle Linux 10. ## Step 1 – Install Nodejs Before starting, you will need to install some required dependencies on your server. You can install all of them by running the following command: ``` dnf install curl gcc-c++ make -y ``` Next, install the Node.js by running the following command: ``` dnf install nodejs -y ``` Once Node.js is installed, you can verify the Node.js version using the following command: ``` node --version ``` You will get the following output: ``` v22.19.0 ``` ## Step 2 – Install Sailsjs You can use the Node Package Manager (NPM) to install Sails.js easily on your server. ``` npm -g install sails ``` Once installed, create a directory for the Sails.js application. ``` mkdir sails ``` Next, change the directory to the sails and create a new application using the following command: ``` cd sails sails new project ``` You will be asked to select the template for your application: ``` Choose a template for your new Sails app: 1. Web App · Extensible project with auth, login, & password recovery 2. Empty · An empty Sails app, yours to configure (type "?" for help, or to cancel) ? 1 ``` Type 1 and press the Enter key to create your application: ``` info: Installing dependencies... Press CTRL+C to cancel. (to skip this step in the future, use --fast) info: Created a new Sails app `project`! ``` ## Step 3 – Start Sailsjs Application After creating the Sails.js application, change the directory to your application and start the application using the command below: ``` cd project sails lift ``` You will get the following output: ``` info: Starting app... info: Initializing project hook... (`api/hooks/custom/`) info: Initializing `apianalytics` hook... (requests to monitored routes will be logged!) info: ·• Auto-migrating... (alter) info: Hold tight, this could take a moment. info: ✓ Auto-migration complete. debug: Running v0 bootstrap script... (looks like this is the first time the bootstrap has run on this computer) info: info: .-..-. info: info: Sails <| .-..-. info: v1.5.3 |\ info: /|.\ info: / || \ info: ,' |' \ info: .-'.-==|/_--' info: `--'-------' info: __---___--___---___--___---___--___ info: ____---___--___---___--___---___--___-__ info: info: Server lifted in `/root/sails/project` info: To shut down Sails, press + C at any time. info: Read more at https://sailsjs.com/support. debug: ------------------------------------------------------- debug: :: Tue Dec 12 2025 03:54:53 GMT-0400 (Eastern Daylight Time) debug: Environment : development debug: Port : 1337 debug: ------------------------------------------------------- ``` Press CTRL+C to stop the application. ## Step 4 – Create a Systemd Service File for Salisjs It is recommended to create a systemd service file to manage the Sails.js application. You can create it using the following command: ``` nano /lib/systemd/system/sails.service ``` Add the following lines: ``` [Unit] After=network.target [Service] Type=simple User=root WorkingDirectory=/root/sails/project ExecStart=/usr/local/bin/sails lift Restart=on-failure [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes: ``` systemctl daemon-reload ``` Now, start the Sails.js service and enable it to start at system reboot: ``` systemctl start sails systemctl enable sails ``` You can also verify the status of the Sails.js service using the following command: ``` systemctl status sails ``` You will get the following output: ``` sails.service Loaded: loaded (/usr/lib/systemd/system/sails.service; disabled; preset: disabled) Active: active (running) since Wed 2025-12-10 22:33:23 EST; 5s ago Invocation: 0be9415c6dd14c2f90af2fae48541939 Main PID: 236625 (node) Tasks: 22 (limit: 24812) Memory: 165.4M (peak: 165.6M) CPU: 3.230s CGroup: /system.slice/sails.service ├─236625 node /usr/local/bin/sails lift └─236638 grunt Dec 10 22:33:25 oracle sails[236625]: info: Dec 10 22:33:25 oracle sails[236625]: info: Server lifted in `/root/sails/project` Dec 10 22:33:25 oracle sails[236625]: info: To shut down Sails, press + C at any time. Dec 10 22:33:25 oracle sails[236625]: info: Read more at https://sailsjs.com/support. Dec 10 22:33:25 oracle sails[236625]: debug: ------------------------------------------------------- Dec 10 22:33:25 oracle sails[236625]: debug: :: Wed Dec 10 2025 22:33:25 GMT-0500 (Eastern Standard Time) Dec 10 22:33:25 oracle sails[236625]: debug: Environment : development Dec 10 22:33:25 oracle sails[236625]: debug: Port : 1337 Dec 10 22:33:25 oracle sails[236625]: debug: Local : http://localhost:1337 Dec 10 22:33:25 oracle sails[236625]: debug: ----------------------------------------------------- ``` At this point, the Sails.js application is started and listens on port 1337. You can check it using the following command: ``` ss -antpl | grep 1337 ``` You will get the following output: ``` LISTEN 0 128 *:1337 *:* users:(("node",pid=12432,fd=19)) ``` ## Step 5 – Configure Nginx as a Reverse Proxy for Sailsjs Nginx reverse proxy allows you to access the Sails application via port 80. First, install the Nginx with the following command: ``` dnf install nginx ``` Next, create an Nginx virtual host configuration file using the following command: ``` nano /etc/nginx/conf.d/sails.conf ``` Add the following lines: ``` server { listen 80; server_name sails.example.com; location / { proxy_pass http://localhost:1337/; proxy_set_header Host $host; proxy_buffering off; } } ``` Save and close the file, then edit the Nginx main configuration file: ``` nano /etc/nginx/nginx.conf ``` Add the following line below http {: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then verify the Nginx configuration: ``` nginx -t ``` You will get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart Nginx to apply the changes: ``` systemctl restart nginx ``` ## Step 6 – Access Sailsjs Now, open your web browser and access the Sails.js web interface using the URL **http://salis.example.com**. You should see the Sails.js application on the following screen: ![Sails.js dashboard page](https://www.atlantic.net/wp-content/uploads/2022/08/p1-5-1024x511.png) ## Conclusion In this post, you learned how to install Sails.js with Nginx on Oracle Linux 10. You can now start developing your first real-time application using the Sails.js framework. Get started with Sails.js on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Use Composer on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-composer-on-oracle-linux-10/ | Published: 2022-09-29 | Updated: 2025-12-10 | Author: Hitesh Jethva Composer is a dependency manager for PHP. It was created by Nils Adermann and Jordi Boggiano and was initially published on 1 March 2012. It allows you to download, install, and loads dependencies that you have specified in the composer.json file. It helps developers to develop a project inside a specific framework. It is a very useful tool for installing third-party libraries and integrating them into their PHP-based projects. In this tutorial, we will show you how to install and use Composer on Oracle Linux 10 server. ## Step 1 – Install PHP and Other Dependencies Before installing Composer, you will need to install PHP and other required dependencies on your server. You can install PHP with other required dependencies with the following command: ``` dnf install php php-cli php-mbstring curl gnupg2 git unzip -y ``` After installing all the packages, you can proceed to install the Composer. ## Step 2 – Install Composer Composer provides a php-based installation script to install it on your system. First, download the Composer installation script with the following command: ``` curl -sS https://getcomposer.org/installer -o composer-setup.php ``` Next, you will need to verify whether the downloaded script matches the SHA-384 hash for the latest installer found on the [Composer signature page](https://composer.github.io/pubkeys.html). To do so, copy the hash from that page and store it in the shell variable. ``` HASH=c8b085408188070d5f52bcfe4ecfbee5f727afa458b2573b8eaaf77b3419b0bf2768dc67c86944da1544f06fa544fd47 ``` Next, run the following command to verify the downloaded script: ``` php -r "if (hash_file('SHA384', 'composer-setup.php') === '$HASH') { echo 'Installer verified'; } else { echo 'Installer corrupt'; unlink('composer-setup.php'); } echo PHP_EOL;" ``` If everything is fine, you should get the following output: ``` Installer verified ``` Next, run the following script to install Composer globally: ``` php composer-setup.php --install-dir=/usr/local/bin --filename=composer ``` Once the installation has been completed, you should get the following output: ``` All settings correct for using Composer Downloading... Composer (version 2.9.2) successfully installed to: /usr/local/bin/composer Use it: php /usr/local/bin/composer ``` You can now check the Composer version using the following command: ``` composer --version ``` You should see the following output: ``` Composer version 2.9.2 2025-11-19 21:57:25 ``` ## Step 3 – Working with Composer Composer is now installed on your server. You can now create a project with Composer. First, create a new directory for your project: ``` mkdir composerapp ``` Next, change the directory to composerapp: ``` cd composerapp ``` Next, create a PHP-based application that prints the current time. ``` composer require nesbot/carbon ``` The above command will download and install carbon with all required dependencies and creates the composer.json file: ``` - Installing symfony/polyfill-php80 (v1.26.0): Extracting archive - Installing symfony/polyfill-mbstring (v1.26.0): Extracting archive - Installing symfony/deprecation-contracts (v2.5.2): Extracting archive - Installing symfony/translation (v5.4.11): Extracting archive - Installing nesbot/carbon (2.61.0): Extracting archive 3 package suggestions were added by new dependencies, use `composer suggest` to see details. Generating autoload files 6 packages you are using are looking for funding. Use the `composer fund` command to find out more! No security vulnerability advisories found ``` Run the following command to verify all files created by Composer: ``` ls -l ``` You should see the following output: ``` -rw-r--r-- 1 root root 60 Dec 25 06:31 composer.json -rw-r--r-- 1 root root 18911 Dec 25 06:31 composer.lock drwxr-xr-x 6 root root 82 Dec 25 06:31 vendor ``` Now, create a new file named app.php: ``` nano app.php ``` Add the following code: ``` ``` Save and close the file, then run the app.php with the following command: ``` php app.php ``` This will print the current time of your system: ``` Now: 2025-12-11 03:26:42 ``` If you want to update the project, run the following command: ``` composer update ``` This will check for newer versions of the installed packages, match them with all packages inside composer.json, then update the package. ## Conclusion In the above post, you learned how to install Composer on Oracle Linux 10. You also learned how to create a PHP-based project with Composer. For more information, visit the Composer official documentation. Try it today on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install MEAN Stack on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-mean-stack-on-oracle-linux-10/ | Published: 2022-09-30 | Updated: 2025-12-10 | Author: Hitesh Jethva A MEAN stack is one of the most popular JavaScript technology stacks. It is a free and open-source framework that helps you build fast, robust, and maintainable production-ready web applications using MongoDB, Express, Angular, and Node.js. A MEAN stack supports the same language for both the front-end and back-end, which will increase efficiency and reduces the confusion of developers. In this guide, we will show you how to install MEAN.JS on Oracle Linux 10. ## Step 1 – Install MongoDB MongoDB is the first component of the MEAN stack. By default, MongoDB is not included in the Oracle Linux 8 default repository, so you will need to add the MongoDB repository to your server. ``` nano /etc/yum.repos.d/mongodb-org-7.0.repo ``` Add the following lines: ``` [mongodb-org-7.0] name=MongoDB Repository baseurl=https://repo.mongodb.org/yum/redhat/9/mongodb-org/7.0/x86_64/ enabled=1 gpgcheck=0 repo_gpgcheck=0 ``` Next, install the MongoDB server with the following command: ``` dnf install mongodb-org ``` After installing MongoDB, start the MongoDB service and enable it to start at system reboot: ``` systemctl start mongod.service systemctl enable mongod.service ``` You can now verify the MongoDB version using the following command: ``` mongod --version ``` You should see the following output: ``` db version v7.0.26 Build Info: { "version": "7.0.26", "gitVersion": "715b3bbc6c34cecc42ffc77ef77d24f71e240e94", "openSSLVersion": "OpenSSL 3.5.1 1 Jul 2025", "modules": [], "allocator": "tcmalloc", "environment": { "distmod": "rhel90", "distarch": "x86_64", "target_arch": "x86_64" } } ``` ## Step 2 – Install Node.js Next, you will need to install Node.js on your system. First, install all required dependencies using the following command: ``` dnf install curl git gcc-c++ make -y ``` Next, install the Node.js by running the following command: ``` dnf install nodejs -y ``` Once Node.js is installed, you can verify the Node.js version using the following command: ``` node --version ``` You will get the following output: ``` v22.19.0 ``` ## Step 3 – Install Express Express is a Node.js framework that supports MVC and helps to build more scalable, structured, and dynamic websites. You can install the Express using the NPM command: ``` npm install -g express-generator ``` Once Express is installed, create a directory for the Express project with the following command: ``` mkdir app ``` Next, navigate to the app directory and create an Express project with the following command: ``` cd app express ``` You will get the following output: ``` create : public/ create : public/javascripts/ create : public/images/ create : public/stylesheets/ create : public/stylesheets/style.css create : routes/ create : routes/index.js create : routes/users.js create : views/ create : views/error.jade create : views/index.jade create : views/layout.jade create : app.js create : package.json create : bin/ create : bin/www install dependencies: $ npm install run the app: $ DEBUG=app:* npm start ``` Next, run the following command to install additional dependencies: ``` npm install ``` Next, run the Express app using the following command: ``` DEBUG=app:* npm start ``` You will get the following output: ``` > app@0.0.0 start > node ./bin/www app:server Listening on port 3000 +0ms ``` Now, open your web browser and access the Express app using the URL **http://your-server-ip:3000**. You should see the following screen: ![Express dashboard page](https://www.atlantic.net/wp-content/uploads/2022/08/p1-6.png) Press the CTRL+C on your command line interface to stop the Express app. ## Step 4 – Install Angular Angular is an MVC framework used for both the client end and the front end. It allows you to create an interactive web or mobile application. You can install the Angular CLI by running the following command: ``` npm install -g @angular/cli ``` Once installed, create a new Angular app using the following command: ``` ng new angular-app ``` You should see the following output: ``` ? Would you like to add Angular routing? No ? Which stylesheet format would you like to use? CSS ``` Next, navigate to the angular-app directory and run your application using the following command: ``` cd angular-app ng serve --host your-server-ip --port 8088 ``` You should get the following output: ``` ✔ Browser application bundle generation complete. Initial Chunk Files | Names | Raw Size vendor.js | vendor | 1.73 MB | polyfills.js | polyfills | 315.30 kB | styles.css, styles.js | styles | 207.37 kB | main.js | main | 47.74 kB | runtime.js | runtime | 6.52 kB | | Initial Total | 2.29 MB Build at: 2025-12-23T10:25:26.405Z - Hash: 50e206289757a698 - Time: 23713ms ** Angular Live Development Server is listening on 208.117.81.16:8088, open your browser on http://208.117.81.16:8088/ ** ✔ Compiled successfully. ``` You can now access the Angular app using the URL **http://your-server-ip:8088**. You should see your Angular app on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2022/09/an.png) ## Conclusion Congratulations! You have successfully installed the MEAN stack on Oracle Linux 10. You can now use the MEAN stack in your production environment to develop fast, secure, and scalable dynamic web applications. Get started with a MEAN stack on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Top 10 Offshore Development Companies to Consider > URL: https://www.atlantic.net/vps-hosting/top-10-offshore-development-companies-consider/ | Published: 2022-10-02 | Updated: 2025-09-15 | Author: Richard Bailey Software development is a highly skilled vocation, and the demand for experienced developers is sky-high. As a result, companies are turning to offshore development businesses to outsource parts of the development cycle. This approach can help ensure that release dates are met and that you get the skill sets needed for the task. ## Why Choose Offshore? There are three key reasons why offshore development is hugely popular: - **Scalability:** Offshore development companies can quickly bring new resources from the talent pool on their books. Most offer ‘follow the clock’ service for outstanding 24/7 support, and developers will typically work remotely, but it’s possible to get them on-site if needed. - **Affordability:** Often it’s much cheaper to outsource resources overseas; there are minimum operating costs for any business, and costs are usually more affordable for a larger talent group. - **Experts on demand:** Software development requires workers with various skill sets. Outsourcing gives access to experts in a particular specialization. For example, perhaps your business excels in Android development, but now you want to build an app for iPhone. Outsourcing could help. ## Top 10 Offshore Development Companies There are thousands of software houses across the globe, both near shore and offshore. For example, software houses in eastern Europe, India, and the Philippines have built good relationships with U.S. businesses. Join us as we give you our Top 10 Offshore Development Companies: ### 1. Sigma Software Sigma Software LLC is a global company providing turn-key software solutions for over 20 years. They have offices in 40 countries and are available on four continents, allowing them to offer on-site developers in just a few weeks after contracts have been signed. They have a talent pool of over 2000 developers in multi-disciplined roles. They provide the entire development suite, including bespoke product development, application development, R&D research, and MVP Implementation, and can cater to SMBs and large-scale enterprise projects. Yes, they are expensive, but there is a reason why they are in the Top 100 global outsourcing businesses. ### 2. Netguru Netgeuru is a famous software house based in Poland, Europe, with access to over 900 highly skilled software developers. They have been in the industry for over 14 years and started as a specialist in ruby-on-rails web development with some of Europe’s most prominent businesses on their books, including Volkswagen and Ikea. Today they can develop multiple frontend and backend web and mobile applications, SaaS platforms, machine learning toolsets, trading systems, and social networking. ### 3. N-iX N-iX has been providing software services for over 20 years and has access to over 2000 software development professionals. They are based in eastern Europe with delivery centers in Poland, Bulgaria, and Ukraine, but they also have a representative office in the U.S. N-iX offers expert solutions in software engineering, cloud-native services, data analytics, embedded software, IoT, machine learning, and other tech domains covering a wide variety of sectors, including finance, manufacturing, telecom, and supply chain. ### 4. Admios Admios is one of the smallest software houses in our top 10, with only 50 developers on staff. However, what they lack in numbers they make up for in skills, and their employees are all nearshore based in the U.S., making it super convenient for U.S. time zones. They are exclusively a web development software company, with experts in Javascript, React, Ruby, Python, and Go, to name just a few. They are also specialists in infrastructure-as-code development of Kubernetes and Chef/Puppet workloads. The advantage of being small is that Admios can get resources to you in less than 14 days, and each developer is highly skilled across multiple industries and technologies. ### 5. Qubit Labs [Qubit Labs,](https://qubit-labs.com/) an offshore development company with over a decade of experience, specializes in delivering top-notch tech talent to its clients. The company excels in meeting client requirements by assembling remote dedicated teams from rapidly expanding IT hubs such as Ukraine, Poland, Moldova, Georgia, Romania, Kazakhstan, and Azerbaijan. Distinguished by their commitment to providing high-quality expertise and a personalized approach to each project, Qubit Labs effortlessly handles the recruitment of both technical and non-technical professionals possessing specific skills and experience. The company extends its assistance to businesses across various industries, offering services such as the establishment of dedicated development teams, the creation of R&D centers, IT staff augmentation, and more. Moreover, Qubit Labs offers a talent mapping service for those in need of thorough market research before making decisions about hiring their remote teams. ### 6. Eleks Elek’s software is headquartered in Tallinn, Estonia, and is an established software development company with over 2,000 devs on the roster. They specialize in Finance, Media & Entertainment, Healthcare, Retail, Agriculture, and logistics. In addition, they offer virtual reality, drones, mobile, and wearable IoT services. Along with custom software development, They have even [worked with the Ukrainian army](https://www.theguardian.com/technology/2015/apr/24/crowdfunding-war-ukraines-diy-drone-makers) to develop software for their UAV drones. In addition, they have some significant businesses on their books, including ESET, AutoDesk, and AVG. ### 7. Innowise Group Innowise is another primary software development business based in Poland specializing in Web, Mobile, and bespoke software. What differentiates Innowise is that UI/UX design choices guide the entire development process. They build applications for Content Management Systems (CMS), cloud-based web apps, backend, and frontend dev, and bundle in web optimization, testing, and support. ### 8. Radix Radixweb is a large-scale outsourcing partner based in India, part of their operation is offshore software development. They work with the biggest names in the industry, including Xerox, The New York Times, and Verizon. With over 650 highly skilled software engineers available, Radix has been providing software development services for over 22 years. They specialize in software consultancy and custom application design. ### 9. IBA Group Software Development is one of the most popular divisions within the IBA Group. They are based in Prague, Czech Republic, and are well known for their Mobile App development services. They specialize in Android and IOS development, including mobile application writing and testing and UX/UI design. Although the IBA team focuses on developing application architecture, data structures, software modules, and technical and user documents, they also offer Level 2 and Level 3 support, including analysis and problem-solving, implementation of extra functionality, and performance improvement of software applications if required. ### 10. CMC Global CMC Global is a Vietnam-based software development business with over 27 years of experience in the market. They have over 1500 skilled engineers available and ready to go in about 1-3 weeks. They specialize in Web, Mobile, and general software development and help you throughout the software development lifecycle, from product conceptualization, design, development, testing, implementation, and ongoing support. ### Bonus: Kaleida This software house is located in Manchester, North England. They have been around since 1997 and create bespoke middleware applications to integrate existing software. They are prominent in the retail and education sectors, and many engineers focus on developing Web Apps for Windows, document management, bespoke software integration services, and support. ## Partner With a Leading Cloud Provider There are thousands to choose from among the top offshore development companies, but these are the ten that stand out for us. Whichever you choose to help you, remember that Atlantic.Net stands ready to host your application in a security-defined cloud hosting platform. You must partner with a leading VPS hosting provider to leverage the power of cloud-based web applications. Atlantic.Net brings 30 years of experience, offering top-level services at cost-effective prices. In addition, we will work closely with your business to provide a tailored cloud hosting solution to meet your specific needs. The Atlantic.Net cloud platform is the perfect solution for all your testing needs. The high-performance infrastructure can run large-scale web and containerized applications. In addition, cloud storage availability will host large-scale application images to use in your environment without skipping a beat; great if you need to test mobile SDK, but great for general usage. Contact our sales team today to find out how [Atlantic.Net](https://www.atlantic.net/) can help you on your mission to streamline your hosting application needs. --- # How to Install Lighttpd Web Server on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-lighttpd-web-server-on-oracle-linux-10/ | Published: 2022-10-03 | Updated: 2025-12-10 | Author: Hitesh Jethva Lighttpd is a fast, lightweight, secure, and flexible web server specially designed for mission-critical environments. Compared to other web servers like Apache and Nginx, Lighttpd offers lower memory and CPU usage. It supports several technologies, including PHP, FastCGI, Auth, SSL, URL rewriting, reverse proxy, load balancing, and much more. It has a small memory footprint and is capable of handling many concurrent connections. It is cross-platform and can be installed on Unix, Linux, and Windows systems. In this post, we will show you how to install a Lighttpd web server on Oracle Linux 10. ## Step 1 – Install Lighttpd By default, Lighttpd is not included in the Oracle Linux 10 default repo, so you will need to install the EPEL repository on your server. You can install it with the following command: ``` dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-9.noarch.rpm ``` Once the EPEL repo is installed, install the Lighttpd package using the following command: ``` dnf install lighttpd ``` After the successful installation, edit the Lighttpd configuration file. ``` nano /etc/lighttpd/lighttpd.conf ``` Change the following lines: ``` server.use-ipv6 = "disable" server.bind = "your-server-ip" ``` Next, start and enable the Lighttpd service with the following command: ``` systemctl start lighttpd systemctl enable lighttpd ``` You can check the status of Lighttpd using the following command: ``` systemctl status lighttpd ``` You should get the following output: ``` ● lighttpd.service - Lightning Fast Webserver With Light System Requirements Loaded: loaded (/usr/lib/systemd/system/lighttpd.service; disabled; preset: disabled) Active: active (running) since Wed 2025-12-10 07:35:17 EST; 5s ago Invocation: ec4cf7c3f8df4214a2d07d28463a8243 Process: 72812 ExecStartPre=/usr/sbin/lighttpd -tt -f /etc/lighttpd/lighttpd.conf (code=exited, status=0/SUCCESS) Main PID: 72813 (lighttpd) Tasks: 1 (limit: 24812) Memory: 880K (peak: 1.2M) CPU: 16ms CGroup: /system.slice/lighttpd.service └─72813 /usr/sbin/lighttpd -D -f /etc/lighttpd/lighttpd.conf ``` You can also verify the Lighttpd version with the following command: ``` lighttpd -v ``` You should get the following output: ``` lighttpd/1.4.67 (ssl) - a light and fast webserver ``` Now, open your web browser and access the Lighttpd test page using the URL **http://your-server-ip**. You should see the following page: ![Lighttpd test page](https://www.atlantic.net/wp-content/uploads/2022/08/p1-7-1024x503.png) ## Step 2 – Install MariaDB Database Server By default, the MariaDB server package is included in the Oracle Linux 10 default repo. You can install it with the following command: ``` dnf install mariadb mariadb-server ``` Once MariaDB is installed, start and enable the MariaDB service using the following command: ``` systemctl start mariadb.service systemctl enable mariadb.service ``` To check the MariaDB status, run the following command: ``` systemctl status mariadb.service ``` You will get the following output: ``` ● mariadb.service - MariaDB 10.11 database server Loaded: loaded (/usr/lib/systemd/system/mariadb.service; disabled; preset: disabled) Active: active (running) since Tue 2025-12-09 23:43:40 EST; 7h ago Invocation: 16b9c064f8934f268eb717ae0e8136dd Docs: man:mariadbd(8) https://mariadb.com/kb/en/library/systemd/ Main PID: 7314 (mariadbd) Status: "Taking your SQL requests now..." Tasks: 9 (limit: 24812) Memory: 223.8M (peak: 231.7M) CPU: 43.380s CGroup: /system.slice/mariadb.service └─7314 /usr/libexec/mariadbd --basedir=/usr ``` ## Step 3 – Install PHP and PHP-FPM with FastCGI To install PHP with PHP-FPM and FastCGI support, you need to install PHP with some required extensions. You can install all of them by running the following command: ``` dnf install php php-mysqlnd php-pdo php-gd php-mbstring php-fpm lighttpd-fastcgi ``` Next, edit the PHP-FPM configuration file and change the user and group to lighttpd: ``` nano /etc/php-fpm.d/www.conf ``` Change the following lines: ``` user = lighttpd group = lighttpd ``` Next, find the following line: ``` ;listen = /run/php-fpm/www.sock ``` And replace it with the following line: ``` listen = 127.0.0.1:9000 ``` Save and close the file, then start the PHP-FPM service and enable it to start at system reboot: ``` systemctl start php-fpm systemctl enable php-fpm ``` ## Step 4 – Enable PHP and PHP-FPM Support in Lighttpd To enable FastCGI support in PHP, edit the php.ini configuration file: ``` nano /etc/php.ini ``` Change the following line: ``` cgi.fix_pathinfo=1 ``` Next, edit the /etc/lighttpd/modules.conf file: ``` nano /etc/lighttpd/modules.conf ``` Uncomment the following line: ``` include conf_dir + "/conf.d/fastcgi.conf" ``` Next, edit the /etc/lighttpd/conf.d/fastcgi.conf file. ``` nano /etc/lighttpd/conf.d/fastcgi.conf ``` Add the following lines at the end of the file: ``` fastcgi.server += ( ".php" => (( "host" => "127.0.0.1", "port" => "9000", "broken-scriptfilename" => "enable" )) ) ``` Save and close the file, then restart the PHP-FPM and Lighttpd service to apply the changes: ``` systemctl restart lighttpd systemctl restart php-fpm ``` ## Step 5 – Verify the Lighttpd Server Next, you will need to create a phpinfo.php configuration file to test the FastCGI support in PHP. ``` nano /var/www/lighttpd/phpinfo.php ``` Add the following code: ``` ``` Save and close the file. Then, open your web browser and access your PHP test page using the URL **http://your-server-ip/phpinfo.php**. You should see your PHP test page on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2022/10/l1.png) ## Conclusion Congratulations! You have successfully installed the Lighttpd server with PHP and FastCGI support on Oracle Linux 10. You can now start deploying your web application on your secure and fast Lighttpd server. Get started with Lighttpd on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Use Neofetch on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-neofetch-on-oracle-linux-10/ | Published: 2022-10-04 | Updated: 2025-12-10 | Author: Hitesh Jethva Neofetch is a free, open-source, command-line system information monitoring tool written in bash. It provides an easier way to fetch system information without installing additional software. With Neofetch, you can display various system information, including system model and manufacturer, operating system, kernel version, uptime, memory resources, disk usage, and more. In this post, we will show you how to install Neofetch on Oracle Linux 10. ## Step 1 – Install Neofetch Oracle Linux 10 By default, the Neofetch package is not included in the Oracle Linux default repository, so you will need to install it from the EPEL repository. First, install the EPEL repo with the following command: ``` dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-9.noarch.rpm ``` Next, install the Neofetch package with the following command: ``` dnf install neofetch -y ``` After the successful installation, you can verify the Neofetch version using the following command: ``` neofetch --version ``` You should get the following output: ``` Neofetch 7.1.0 ``` ## Step 2 – Launch Neofetch You can run Neofetch without any option to get all the system-related information: ``` neofetch ``` You will get the following output: ``` root@oracle `-/+++++++++++++++++/-.` ----------- `/syyyyyyyyyyyyyyyyyyyyyyys/. OS: Oracle Linux Server 10.0 x86_64 :yyyyo/-...............-/oyyyy/ Host: KVM/QEMU (Standard PC (i440FX + PIIX, 1996) pc-i440fx-jammy) /yyys- .oyyy+ Kernel: 6.12.0-101.33.4.3.el10uek.x86_64 .yyyy` `syyy- Uptime: 9 hours, 3 mins :yyyo /yyy/ Packages: 1031 (rpm) .yyyy` `syyy- Shell: bash 5.2.26 /yyys. .oyyyo Resolution: 1024x768 /yyyyo:-...............-:oyyyy/` Terminal: /dev/pts/0 `/syyyyyyyyyyyyyyyyyyyyyyys+. CPU: Intel (Haswell, no TSX) (2) @ 2.099GHz `.:/+ooooooooooooooo+/:.` GPU: 00:02.0 Cirrus Logic GD 5446 Memory: 1569MiB / 3910MiB ``` To get a list of all options available with Neofetch, run the following command: ``` neofetch --help ``` ## Step 3 – How to Use Neofetch The basic syntax to use Neofetch is shown below: ``` neofetch func_name --option "value" --option "value" ``` For example, to see system uptime run the following command: ``` neofetch uptime --uptime_shorthand tiny ``` You will get the system uptime in the following output: ``` uptime: 2h 2m ``` To get information about uptime, disk, and memory, run the following command: ``` neofetch uptime disk wm memory ``` You should see the following output: ``` uptime: 2 hours, 2 mins disk (/): 6.6G / 160G (5%) memory: 2270MiB / 7768MiB ``` To disable the CPU and Memory related information in the output, run the following command: ``` neofetch --disable cpu memory ``` To hide operating system architecture, run the following command: ``` neofetch --os_arch off ``` To print the CPU cores information, run the following command: ``` neofetch --cpu_cores logical ``` To display CPU temperature, run the following command: ``` neofetch --cpu_temp C ``` ## Step 4 – Customize Neofetch Neofetch creates a config file at **$HOME/.config/neofetch/config.conf** after the first run. You can edit it and change it as per your requirement. ``` nano .config/neofetch/config.conf ``` Enable or disable the information that you need to display. ``` print_info() { info title info underline info "OS" distro info "Host" model info "Kernel" kernel info "Uptime" uptime info "Packages" packages info "Shell" shell info "Resolution" resolution info "DE" de info "WM" wm info "WM Theme" wm_theme info "Theme" theme info "Icons" icons info "Terminal" term info "Terminal Font" term_font info "CPU" cpu info "GPU" gpu info "Memory" memory info "Disk" disk info "Battery" battery info "Local IP" local_ip # info "Public IP" public_ip # info "Users" users # info "Public IP" public_ip # info "Locale" locale # This only works on glibc systems. info cols ``` Save and close the file when you are finished. ## Conclusion In the above guide, we explained how to install and use Neofetch to display the system information. Now you can find your system’s basic information in an easier way. Try Neofetch on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Monitor Oracle Linux Server Security with Osquery > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-monitor-oracle-linux-server-security-with-osquery/ | Published: 2022-10-05 | Updated: 2025-12-10 | Author: Hitesh Jethva Osquery is a free and open-source tool that allows you to fetch operating system information for performance, security, and compliance audit analysis. It can be installed on all major operating systems such as Linux, FreeBSD, macOS, Windows systems, etc. With Osquery, you can fetch all important system information, including running processes, loaded kernel modules, active user accounts, network connections, and more. It is used by the system administrators to troubleshoot performance and operational issues. In this post, we will show you how to install Osquery on Oracle Linux 10. ## Step 1 – Install Osquery on Oracle Linux 10 By default, the Osquery package is not included in the Oracle Linux default repo, so you will need to add the Osquery repo to your system. You can add it with the following command: ``` curl -L https://pkg.osquery.io/rpm/GPG | tee /etc/pki/rpm-gpg/RPM-GPG-KEY-osquery dnf config-manager --add-repo https://pkg.osquery.io/rpm/osquery-s3-rpm.repo ``` Next, verify the added repo with the following command: ``` dnf repolist | grep osquery ``` You will get the following output: ``` osquery-s3-rpm-repo name=osquery RPM repository - x86_64 ``` Next, install the Osquery package using the following command: ``` dnf --enablerepo osquery-s3-rpm-repo install osquery -y ``` You can start the Osquery service using the following command: ``` osqueryctl start ``` To stop the Osquery service, run the following command: ``` osqueryctl stop ``` ## Step 2 – Run Osquery in Standalone Mode You can run Osquery in a standalone mode with the following command: ``` osqueryi ``` To get a list of all commands, run the following command: ``` .help ``` You will get the following output: ``` Welcome to the osquery shell. Please explore your OS! You are connected to a transient 'in-memory' virtual database. .all [TABLE] Select all from a table .bail ON|OFF Stop after hitting an error .connect PATH Connect to an osquery extension socket .disconnect Disconnect from a connected extension socket .echo ON|OFF Turn command echo on or off .exit Exit this program .features List osquery's features and their statuses .headers ON|OFF Turn display of headers on or off .help Show this message .mode MODE Set output mode where MODE is one of: csv Comma-separated values column Left-aligned columns see .width line One value per line list Values delimited by .separator string pretty Pretty printed SQL results (default) .nullvalue STR Use STRING in place of NULL values .print STR... Print literal STRING .quit Exit this program .schema [TABLE] Show the CREATE statements .separator STR Change separator used by output mode .socket Show the local osquery extensions socket path .show Show the current values for various settings .summary Alias for the show meta command .tables [TABLE] List names of tables .types [SQL] Show result of getQueryColumns for the given query .width [NUM1]+ Set column widths for "column" mode .timer ON|OFF Turn the CPU timer measurement on or off ``` ## Step 3 – How to Use Osquery Osquery uses a table to store all system-related information. You can list all tables with the following command: ``` .tables ``` You should see the list of all tables in the following output: ``` => acpi_tables => apparmor_events => apparmor_profiles => apt_sources => arp_cache => atom_packages => augeas => authorized_keys => azure_instance_metadata => azure_instance_tags => block_devices => bpf_process_events => bpf_socket_events => carbon_black_info => carves => certificates => chrome_extension_content_scripts => chrome_extensions => cpu_info => cpu_time => cpuid ``` To check the operating system version, run the following command: ``` select * from os_version; ``` You will get the following output: ``` +--------------------------+----------------------------------------------+-------+-------+-------+-------+----------+---------------+----------+--------+ | name | version | major | minor | patch | build | platform | platform_like | codename | arch | +--------------------------+----------------------------------------------+-------+-------+-------+-------+----------+---------------+----------+--------+ | Red Hat Enterprise Linux | Red Hat Enterprise Linux release (CentOS Stream) | 10 | 5 | 0 | | rhel | rhel | | x86_64 | +--------------------------+----------------------------------------------+-------+-------+-------+-------+----------+---------------+----------+--------+ ``` To list all users whose UID are greater than **1000,** run the following command: ``` select * from users where uid >=1000; ``` You will get the following output: ``` +-------+-------+------------+------------+----------+----------------------+-----------+---------------+------+ | uid | gid | uid_signed | gid_signed | username | description | directory | shell | uuid | +-------+-------+------------+------------+----------+----------------------+-----------+---------------+------+ | 65534 | 65534 | 65534 | 65534 | nobody | Kernel Overflow User | / | /sbin/nologin | | +-------+-------+------------+------------+----------+----------------------+-----------+---------------+------+ ``` To list all active logged-in users, run the following command: ``` select user,tty,host,time from logged_in_users where tty not like '~'; ``` You will get the following output: ``` +-------+-------+--------------+------------+ | user | tty | host | time | +-------+-------+--------------+------------+ | LOGIN | tty1 | | 1662011298 | | root | pts/0 | 117.99.59.26 | 1662011331 | +-------+-------+--------------+------------+ ``` To check the system uptime, run the following command: ``` select * from uptime; ``` You will get the following output: ``` +------+-------+---------+---------+---------------+ | days | hours | minutes | seconds | total_seconds | +------+-------+---------+---------+---------------+ | 0 | 0 | 5 | 57 | 357 | +------+-------+---------+---------+---------------+ ``` To list all network interfaces, run the following command: ``` select interface,address,mask from interface_addresses where interface NOT LIKE '%lo%'; ``` You will get the following output: ``` +-----------+-------------------------------+-----------------------+ | interface | address | mask | +-----------+-------------------------------+-----------------------+ | eth0 | 208.117.81.163 | 255.255.255.0 | | eth0 | fe80::200:d0ff:fe75:51a3%eth0 | ffff:ffff:ffff:ffff:: | | eth1 | fe80::200:aff:fe75:51a3%eth1 | ffff:ffff:ffff:ffff:: | +-----------+-------------------------------+-----------------------+ ``` To enable the line mode, run the following command: ``` .mode line ``` To check the system information and print the output line by line, run the following command: ``` SELECT * FROM system_info; ``` You will get the following output: ``` hostname = oraclelinux10 uuid = 537b369a-6701-4b31-bb3d-5a34d663eb1f cpu_type = x86_64 cpu_subtype = 6 cpu_brand = QEMU Virtual CPU version 2.5+ cpu_physical_cores = 1 cpu_logical_cores = 1 cpu_microcode = 0x1 physical_memory = 1905364992 hardware_vendor = QEMU hardware_model = Standard PC (i440FX + PIIX, 1996) hardware_version = pc-i440fx-bionic hardware_serial = board_vendor = board_model = board_version = board_serial = computer_name = oraclelinux10 local_hostname = oraclelinux10 ``` You can exit from the Osquery shell with the following command: ``` .exit ``` ## Step 4 – Run Osquery via Systemd To run Osquery via systemd, you will need to copy the Osquery configuration file: ``` cp /opt/osquery/share/osquery/osquery.example.conf /etc/osquery/osquery.conf ``` Next, stop the Osquery daemon with the following command: ``` osqueryctl stop ``` Next, start and enable the Osquery service via systemd with the following command: ``` systemctl start osqueryd systemctl enable osqueryd ``` To check the active status of Osquery, run the following command: ``` systemctl status osqueryd ``` You will get the following output: ``` ● osqueryd.service - The osquery Daemon Loaded: loaded (/usr/lib/systemd/system/osqueryd.service; disabled; preset: disabled) Active: active (running) since Wed 2025-12-10 07:24:41 EST; 4s ago Invocation: 155df4c095bc4de3931b9465eb670dc6 Process: 71265 ExecStartPre=/bin/sh -c if [ ! -f $FLAG_FILE ]; then touch $FLAG_FILE; fi (code=exited, status=0/SUCCESS) Process: 71267 ExecStartPre=/bin/sh -c if [ -f $LOCAL_PIDFILE ]; then mv $LOCAL_PIDFILE $PIDFILE; fi (code=exited, status=0/SUCCESS) Main PID: 71270 (osqueryd) Tasks: 14 (limit: 24812) Memory: 14.2M (peak: 14.5M) CPU: 77ms CGroup: /system.slice/osqueryd.service ├─71270 /opt/osquery/bin/osqueryd --flagfile /etc/osquery/osquery.flags --config_path /etc/osquery/osquery.conf └─71273 /opt/osquery/bin/osqueryd Dec 10 07:24:41 oracle systemd[1]: Starting osqueryd.service - The osquery Daemon... Dec 10 07:24:41 oracle systemd[1]: Started osqueryd.service - The osquery Daemon. Dec 10 07:24:41 oracle osqueryd[71270]: osqueryd started [version=5.20.0] ``` ## Conclusion In this post, we showed you how to install Osquery on Oracle Linux 10. We also explained how to use Osquery to fetch the system information. You can now use Osquery easily to fetch the system-related information. Try Osquery on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Configure Reverse Proxy for Node.js Application Using Apache on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-configure-reverse-proxy-for-node-js-application-using-apache-on-oracle-linux-10/ | Published: 2022-10-06 | Updated: 2025-12-10 | Author: Hitesh Jethva Node.js is a very powerful tool used to host JavaScript-based applications on the web. However, Node.js has some vulnerabilities that can cause performance-related issues. It does not work well with IO-bound operations or rapid traffic growth. In this case, you can use Apache as a reverse proxy to manage port contention and improve the Node.js performance. In this post, we will explain how to configure Apache as a Reverse Proxy for Node.js applications on Oracle Linux 10. ## Step 1 – Install Node.js By default, the latest version of Node.js is available in the Oracle Linux 10 default repo. You can install the Node.js by running the following command: ``` dnf install nodejs -y ``` Once Node.js is installed, you can verify the Node.js version using the following command: ``` node --version ``` You will get the following output: ``` v22.19.0 ``` ## Step 2 – Create a Node.js Application First, create a directory to store your Node.js application with the following command: ``` mkdir nodeapp ``` Next, navigate to the create directory with the following command: ``` cd nodeapp ``` Next, create an app.js file: ``` nano app.js ``` Add the following code: ``` var http = require('http'); http.createServer(function (req, res) { res.writeHead(200, {'Content-Type': 'text/plain'}); res.end('Welcome to Node.js Server'); }).listen(8000, "127.0.0.1"); console.log('Server running at http://127.0.0.1:8000/'); ``` Save and close the file, then run your Node.js application with the following command: ``` node app.js ``` You will get the following output: ``` Server running at http://127.0.0.1:8000/ ``` Press CTRL+C to stop the Node.js application. ## Step 3 – Install PM2 to Manage Node.js Service Next, you will need to install PM2 to manage the Node.js service. You can install it with the following command: ``` npm i -g pm2 ``` Once PM2 is installed, start the Node.js application with the following command: ``` pm2 start app.js ``` Next, enable your application to start at system reboot: ``` pm2 startup ``` You can list all your application services with the following command: ``` pm2 list ``` ## Step 4 – Configure Apache as a Reverse Proxy for Node.js It is a good idea to install and configure Apache as a reverse proxy for the Node.js applications. First, install the Apache package using the following command: ``` dnf install httpd -y ``` Next, create an Apache virtual host configuration file for the Node.js application: ``` nano /etc/httpd/conf.d/node.exampledomain.conf ``` Add the following configurations: ``` ServerAdmin admin@exampledomain.com ServerName node.exampledomain.com ErrorLog /var/log/httpd/error.log CustomLog /var/log/httpd/access.log combined ProxyRequests On ProxyPass / http://localhost:8000 ProxyPassReverse / http://localhost:8000 ``` Save and close the file, then start and enable the Apache service with the following command: ``` systemctl start httpd systemctl enable httpd ``` ## Step 5 – Access Node.js Application At this point, Apache is configured as a reverse proxy for the Node.js application. You can now access the Node.js application using the URL **http://node.exampledomain.com**. You should see your Node.js application page: ![Node.js application page](https://www.atlantic.net/wp-content/uploads/2022/09/p1-4.png) ## Conclusion Congratulations! You have successfully installed and configured Apache as a reverse proxy for the Node.js application. This will help you to increase your Node.js application performance. You can now host the Node.js applications on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Sphinx-Doc on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-sphinx-doc-on-oracle-linux-10/ | Published: 2022-10-07 | Updated: 2025-12-10 | Author: Hitesh Jethva Sphinx is a powerful documentation generator that makes it easy to create intelligent and beautiful documentation. It is written in Python and supports several Output formats such as PDF, plain text, EPUB, TeX, manual pages, and more. Sphinx uses the reStructuredText markup language by default and can read MyST markdown via third-party extensions. It supports many languages, including Python, C, C++, JavaScript, mathematics, and many more. In this post, we will show you how to install Sphinx-Doc on Oracle Linux 10. ## Step 1 – Install Python First, you will need to install Python and other required dependencies on your server. You can install all of them by running the following command: ``` dnf install python3 httpd make gcc -y ``` Once all the packages are installed, verify the Python version with the following command: ``` python3 --version ``` You will get the following output: ``` Python 3.12.11 ``` Next, install the PIP package with the following command: ``` dnf install python3-pip -y ``` Next, verify the PIP version using the following command: ``` pip3 --version ``` You will get the following output: ``` pip 23.3.2 from /usr/lib/python3.12/site-packages/pip (python 3.12) ``` ## Step 2 – Install Sphinx-Doc on Oracle Linux 10 You can now use the PIP command line utility to install Sphinx-Doc: ``` pip3 install sphinx ``` Once the installation has been completed, navigate to the Apache web root directory and configure Sphinx with the following command: ``` cd /var/www/html/ sphinx-quickstart ``` Answer all the questions as shown below to configure Sphinx-Doc: ``` Welcome to the Sphinx 9.0.4 quickstart utility. Please enter values for the following settings (just press Enter to accept a default value, if one is given in brackets). Selected root path: . You have two options for placing the build directory for Sphinx output. Either, you use a directory "_build" within the root path, or you separate "source" and "build" directories within the root path. > Separate source and build directories (y/n) [n]: The project name will occur in several places in the built documentation. > Project name: myapp > Author name(s): Hitesh Jethva > Project release []: 10.0 If the documents are to be written in a language other than English, you can select a language here by its language code. Sphinx will then translate text that it generates into that language. For a list of supported codes, see https://www.sphinx-doc.org/en/master/usage/configuration.html#confval-language. > Project language [en]: Creating file /var/www/html/conf.py. Creating file /var/www/html/index.rst. Creating file /var/www/html/Makefile. Creating file /var/www/html/make.bat. Finished: An initial directory structure has been created. You should now populate your master file /var/www/html/index.rst and create other documentation source files. Use the Makefile to build the docs, like so: make builder where "builder" is one of the supported builders, e.g. html, latex or linkcheck. ``` Next, build all configuration files using the following command: ``` make html ``` You will get the following output: ``` Running Sphinx v5.1.1 making output directory... done building [mo]: targets for 0 po files that are out of date building [html]: targets for 1 source files that are out of date updating environment: [new config] 1 added, 0 changed, 0 removed reading sources... [100%] index looking for now-outdated files... none found pickling environment... done checking consistency... done preparing documents... done writing output... [100%] index generating indices... genindex done writing additional pages... search done copying static files... done copying extra files... done dumping search index in English (code: en)... done dumping object inventory... done build succeeded. The HTML pages are in _build/html. ``` ## Step 3 – Create an Apache Virtual Host for Sphinx-Doc Next, you will need to create an Apache virtual host configuration file to host Sphinx-Doc on the web. ``` nano /etc/httpd/conf.d/sphinx.conf ``` Add the following configurations: ``` ServerAdmin admin@exampledomain.com ServerName sphinx.exampledomain.com DocumentRoot /var/www/html/_build/html/ ErrorLog /var/log/httpd/error.log CustomLog /var/log/httpd/access.log combined ``` Save and close the file, then change the ownership of the Apache web root directory: ``` chown -R apache:apache /var/www/html/ chmod -R 777 /var/www/html ``` Next, start and enable the Apache service with the following command: ``` systemctl start httpd systemctl enable httpd ``` Next, verify the status of Apache with the following command: ``` systemctl status httpd ``` You will get the following output: ``` ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; preset: disabled) Drop-In: /etc/systemd/system/httpd.service.d └─php-fpm.conf Active: active (running) since Wed 2025-12-10 00:15:03 EST; 3h 42min ago Invocation: 3a939838485e43549ca64fac9c7508f6 Docs: man:httpd.service(8) Main PID: 30617 (httpd) Status: "Total requests: 31; Idle/Busy workers 100/0;Requests/sec: 0.00232; Bytes served/sec: 322 B/sec" Tasks: 230 (limit: 24812) Memory: 22.5M (peak: 23.2M) CPU: 42.676s CGroup: /system.slice/httpd.service ├─30617 /usr/sbin/httpd -DFOREGROUND ├─30618 /usr/sbin/httpd -DFOREGROUND ├─30619 /usr/sbin/httpd -DFOREGROUND ├─30684 /usr/sbin/httpd -DFOREGROUND ├─30690 /usr/sbin/httpd -DFOREGROUND └─30802 /usr/sbin/httpd -DFOREGROUND ``` ## Step 4 – Access Sphinx-Doc Web Interface You can now access the Sphinx-Doc web interface using the URL **http://sphinx.exampledomain.com**. You should see Sphinx-Doc on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2022/10/s1.png) ## Conclusion Congratulations! You have successfully installed Sphinx-Doc on Oracle Linux 10 server. You can now use Sphinx-Doc for any documentation project, including one on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install Metabase on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-metabase-on-oracle-linux-10/ | Published: 2022-10-10 | Updated: 2025-12-10 | Author: Hitesh Jethva Metabase is a free, open-source, web-based database lookup tool. It can be integrated with any database and provides a graphical interface to run queries on the database. Metabase supports several databases such as MySQL/MariaDB, Postgres, Mongo, SQL Server, Druid, H2, SQLite, and Oracle business. It is a powerful analytics tool that allows you to learn and make decisions from your company’s data without any technical knowledge required. In this tutorial, we will explain how to install Metabase on Oracle Linux 10. ## Step 1 – Install Java JDK Metabase is written in Java, so you will need to install Java JDK on your server. You can install it by running the following command: ``` dnf update -y dnf install java-21-openjdk-devel -y ``` Once Java is installed, verify the installed version of Java with the following command: ``` java --version ``` You should get the following output: ``` openjdk 21.0.9 2025-10-21 LTS OpenJDK Runtime Environment (Red_Hat-21.0.9.0.10-1.0.1) (build 21.0.9+10-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.9.0.10-1.0.1) (build 21.0.9+10-LTS, mixed mode, sharing) ``` ## Step 2 – Install and Configure MariaDB Next, you will need to install the MariaDB and Rsyslog servers in your system. You can install them with the following command: ``` dnf install mariadb-server -y dnf install rsyslog -y ``` Once installed, start the MariaDB and Rsyslog services and enable them to start on system reboot with the following command: ``` systemctl start mariadb rsyslog systemctl enable mariadb rsyslog ``` Next, log in to MariaDB with the following command: ``` mysql ``` Once logged in, create a database and user for Metabase with the following command: ``` create database metabasedb; create user metabaseuser@'localhost' identified by 'password'; ``` Next, grant all the privileges to the Metabase with the following command: ``` grant all on metabasedb.* to metabaseuser@'localhost' with grant option; ``` Next, flush the privileges and exit from the MariaDB with the following command: ``` flush privileges; exit; ``` ## Step 3 – Install Metabase on Oracle Linux 10 First, create a dedicated user and group for Metabase with the following command: ``` groupadd --system metabase useradd --system -g metabase --no-create-home metabase ``` Next, create the necessary directories and files for Metabase: ``` mkdir -p /opt/metabase touch /var/log/metabase.log touch /etc/default/metabase ``` Next, change the ownership of the Metabase directories and files with the following command: ``` chown -R metabase:metabase /opt/metabase chown metabase:metabase /var/log/metabase.log chmod 640 /etc/default/metabase ``` Next, create a log file for Metabase with the following command: ``` nano /etc/rsyslog.d/metabase.conf ``` Add the following lines: ``` :msg,contains,"metabase" /var/log/metabase.log & stop ``` Save and close the file, then restart the rsyslog service with the following command: ``` systemctl restart rsyslog ``` Next, change the directory to metabase and download the latest version of Metabase with the following command: ``` cd /opt/metabase wget https://downloads.metabase.com/v0.44.2/metabase.jar ``` Next, change the ownership of the downloaded file to Metabase with the following command: ``` chown -R metabase:metabase /opt/metabase ``` ## Step 4 – Create a System Service File for Metabase Next, it is recommended to create a systemd service file to manage the Metabase service. You can create it with the following command: ``` nano /etc/systemd/system/metabase.service ``` Add the following lines: ``` [Unit] Description=Metabase server After=syslog.target After=network.target [Service] WorkingDirectory=/opt/metabase/ ExecStart=/usr/bin/java -jar /opt/metabase/metabase.jar EnvironmentFile=/etc/default/metabase User=metabase Type=simple StandardOutput=syslog StandardError=syslog SyslogIdentifier=metabase SuccessExitStatus=143 TimeoutStopSec=120 Restart=always [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the Metabase service and enable it to start at system reboot with the following command: ``` systemctl start metabase systemctl enable metabase ``` You can now check the status of the Metabase service with the following command: ``` systemctl status metabase ``` You should get the following output: ``` ● metabase.service - Metabase server Loaded: loaded (/etc/systemd/system/metabase.service; disabled; preset: disabled) Active: active (running) since Wed 2025-12-10 03:46:23 EST; 3s ago Invocation: 2dedbf013b8d4c65bb9c903b87af4446 Main PID: 52786 (java) Tasks: 19 (limit: 24812) Memory: 236.9M (peak: 237.3M) CPU: 6.472s CGroup: /system.slice/metabase.service └─52786 /usr/bin/java -jar /opt/metabase/metabase.jar ``` At this point, Metabase is started and listening on port 3000. You can check it with the following command: ``` ss -antpl | grep 3000 ``` You should see the following output: ``` LISTEN 0 50 *:3000 *:* users:(("java",pid=20045,fd=13)) ``` ## Step 5 – Access Metabase Web Interface Now, open your web browser and access Metabase using the URL **http://your-server-ip:3000**. You should see the following page: ![Metabase language selection page](https://www.atlantic.net/wp-content/uploads/2022/09/p1-1024x555.png) Click on **“Let’s get started”**. You should see the following page: ![Metabase language selection page](https://www.atlantic.net/wp-content/uploads/2022/09/p2-1024x616.png) Select your language and click on the **Next** button. You should see the following page: ![Metabase admin user creation page](https://www.atlantic.net/wp-content/uploads/2022/09/p3.png) Provide your full name, email address, and password and click on the **Next** button. You should see the following page: ![Metabase database creation page](https://www.atlantic.net/wp-content/uploads/2022/09/p5.png) Provide your database details and click on the **Connect Database** button. You should see the following page: ![select data usage page](https://www.atlantic.net/wp-content/uploads/2022/09/p6.png) Enable your “Usage data preferences” and click on the **Finish** button. You should see the following page: ![Define email address page](https://www.atlantic.net/wp-content/uploads/2022/09/p7.png) Provide your admin email address and click on the **Take me to Metabase** button. You should see the Metabase default dashboard on the following page: ![Metabase dashboard page](https://www.atlantic.net/wp-content/uploads/2022/09/p8-1024x506.png) ## Conclusion In this post, we learned how to install and configure Metabase on Oracle Linux 10. You can now connect your Metabase to an external database to query your own data. You can visit the Metabase official [documentation](https://metabase.com/docs/latest/) for more information. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Use AIDE in Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-aide-in-oracle-linux-10/ | Published: 2022-10-11 | Updated: 2025-12-10 | Author: Hitesh Jethva AIDE, also called “Advanced Intrusion Detection Environment,” is a free and open-source file integrity monitoring tool for Linux-based systems. It monitors changes in your Linux system and notifies you of them via email. It uses several algorithms, including md5, sha1, rmd160, and tiger, to check file integrity. Generally, AIDE checks file permissions, inodes, modification time, file contents, user, group, file size, and more. In this post, we will explain how to install and use AIDE on Oracle Linux 10. ## Step 1 – Install AIDE By default, the AIDE package is included in the Oracle Linux 10 default repository. You can install it by just running the following command: ``` dnf install aide -y ``` After the successful installation, you can see the AIDE package information using the following command: ``` rpm -qi aide ``` You should see the AIDE package information in the following output: ``` Name : aide Version : 0.18.6 Release : 8.el10_1.2 Architecture: x86_64 Install Date: Wed 10 Dec 2025 03:34:47 AM EST Group : Unspecified Size : 360759 License : GPL-2.0-or-later Signature : RSA/SHA256, Tue 25 Nov 2025 06:28:52 AM EST, Key ID bc4d06a08d8b756f Source RPM : aide-0.18.6-8.el10_1.2.src.rpm Build Date : Tue 25 Nov 2025 06:26:26 AM EST Build Host : build-ol10-x86_64.oracle.com Vendor : Oracle America URL : http://sourceforge.net/projects/aide Summary : Intrusion detection environment Description : AIDE (Advanced Intrusion Detection Environment) is a file integrity ``` ## Step 2 – Initialize the AIDE Database After installing AIDE, you will need to create a database for your current system state. You can create it with the following command: ``` aide --init ``` Once the AIDE database is created, you will get the following output: ``` Start timestamp: 2025-12-01 08:41:55 -0400 (AIDE 0.16) AIDE initialized database at /var/lib/aide/aide.db.new.gz Number of entries: 120136 --------------------------------------------------- The attributes of the (uncompressed) database(s): --------------------------------------------------- /var/lib/aide/aide.db.new.gz MD5 : HrRHisua7lg4j9+Age/DDA== SHA1 : E96LC//yREmtEYUbjhI3Q5I//r8= RMD160 : bxdClGATptUZyMcmMOk/yiOWAbY= TIGER : YPZ5DlnYs1b1rlAfL9XXou7d4VwxsNyJ SHA256 : Ys9VwAjaNQweueE8q8K276T16o/y9GY/ jUhvHS68IOg= SHA512 : Ra6uKNRCCvXc3NRQvPcARkaGaEvF6qr9 1qOZtJUsw24ksp416FX1FYVgN3r6Yo+3 52IebFgabo6s7pDuJvv2Fg== End timestamp: 2025-12-01 08:42:25 -0400 (run time: 0m 30s) ``` Next, copy your newly created database to the master database with the following command: ``` cp -p /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz ``` Next, verify the AIDE configuration using the following command: ``` aide -D ``` Next, check the database against your system baseline with the following command: ``` aide --check ``` You will get the following output: ``` Start timestamp: 2025-12-01 08:44:04 -0400 (AIDE 0.16) AIDE found NO differences between database and filesystem. Looks okay!! Number of entries: 120136 --------------------------------------------------- The attributes of the (uncompressed) database(s): --------------------------------------------------- /var/lib/aide/aide.db.gz MD5 : HrRHisua7lg4j9+Age/DDA== SHA1 : E96LC//yREmtEYUbjhI3Q5I//r8= RMD160 : bxdClGATptUZyMcmMOk/yiOWAbY= TIGER : YPZ5DlnYs1b1rlAfL9XXou7d4VwxsNyJ SHA256 : Ys9VwAjaNQweueE8q8K276T16o/y9GY/ jUhvHS68IOg= SHA512 : Ra6uKNRCCvXc3NRQvPcARkaGaEvF6qr9 1qOZtJUsw24ksp416FX1FYVgN3r6Yo+3 52IebFgabo6s7pDuJvv2Fg== End timestamp: 2025-12-01 08:44:27 -0400 (run time: 0m 23s) ``` ## Step 3 – Verify AIDE At this point, AIDE is installed and initialized. Next, create some files and directories for your system, then check whether AIDE detects your changes or not. First, create some files and a directory: ``` touch file1.txt file2.txt mkdir test ``` ``` aide --check ``` You should get detailed information about changes in the following output: ``` --------------------------------------------------- Directory: /root Linkcount: 3 | 4 --------------------------------------------------- Added entries: --------------------------------------------------- f++++++++++++++++: /etc/file1.txt f++++++++++++++++: /etc/fil2.txt f++++++++++++++++: /etc/test --------------------------------------------------- The attributes of the (uncompressed) database(s): --------------------------------------------------- /var/lib/aide/aide.db.gz MD5 : HrRHisua7lg4j9+Age/DDA== SHA1 : E96LC//yREmtEYUbjhI3Q5I//r8= RMD160 : bxdClGATptUZyMcmMOk/yiOWAbY= TIGER : YPZ5DlnYs1b1rlAfL9XXou7d4VwxsNyJ SHA256 : Ys9VwAjaNQweueE8q8K276T16o/y9GY/ jUhvHS68IOg= SHA512 : Ra6uKNRCCvXc3NRQvPcARkaGaEvF6qr9 1qOZtJUsw24ksp416FX1FYVgN3r6Yo+3 52IebFgabo6s7pDuJvv2Fg== /var/lib/aide/aide.db.new.gz MD5 : 5wuA8hCUYqQCrMwlx6/nYg== SHA1 : JTt9qJDtIG6/qHa3eVuB1nXz6Kw= RMD160 : 4GFuJ9U31dq5dXX9v4L6AhhrJMk= TIGER : mZY55DEZQ5QnIhf7g8U4CimJ+uv/CmOT SHA256 : VNySUFAutZ1+PADn7gWjdogwo2vsAbb2 Xw5Q/9lvU2A= SHA512 : u2KrVpQjk0YNg1uUcnzvqyhpX30UwyOH Vq6oIFAaLfs6trdwSp/ZymoVIsw4U+d7 VLnngfdYUcihoDMLPsj5qA== End timestamp: 2025-12-01 08:45:56 -0400 (run time: 0m 26s) ``` You can then update your AIDE database using the following command: ``` aide --update ``` ## Step 4 – Setup AIDE Cron and Email Notification AIDE also provides a pre-configured script that notifies you via email whenever any changes occur in your system. You can download the AIDE script with the following command: ``` wget https://rfxn.com/downloads/cron.aide -O aide_cron.sh ``` Next, set execution permissions on the downloaded script with the following command: ``` chmod +x aide_cron.sh ``` Next, edit the downloaded script file and define your email address to receive the email notification: ``` nano aide_cron.sh ``` Change the following line: ``` email="root@localhost,hitjethva@example.com" ``` Save and close the file, then edit the Cron file: ``` crontab -e ``` Define your script path to create a new Cron job: ``` 00 01 * * * /root/aide_cron.sh ``` Save and close the file when you finish. ## Conclusion In this post, we explained how to install AIDE on Oracle Linux 10. We also showed you how to use AIDE to monitor system changes and receive an email notification. You can now try AIDE on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Setup Wazuh Server in Oracle Linux 8 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-setup-wazuh-server-in-oracle-linux-8/ | Published: 2022-10-12 | Updated: 2023-11-15 | Author: Hitesh Jethva Wazuh is a free, open-source, powerful threat detection and integrity monitoring tool that helps organizations to detect intrusions, threats, and behavioral anomalies. It collects and analyzes the data gathered by the agent and visualizes event data through a web-based interface. It can be integrated with Kibana for visualization, Elasticsearch for data storage, and Filebeat for collecting Wazuh manager event data. It allows you to monitor hosts at the operating system and application levels to gain security visibility. In this post, we will show you how to install a Wazuh server on Oracle Linux 8 server. ## Step 1 – Install Java Wazuh is a Java-based application, so Java must be installed on your server. If not installed, you can install it using the following command: ``` dnf install java-11-openjdk-devel -y ``` Once Java has been installed, verify the Java version using the following command: ``` java -version ``` Sample output: ``` openjdk version "11.0.16" 2022-07-19 LTS OpenJDK Runtime Environment (Red_Hat-11.0.16.0.8-1.el8_6) (build 11.0.16+8-LTS) OpenJDK 64-Bit Server VM (Red_Hat-11.0.16.0.8-1.el8_6) (build 11.0.16+8-LTS, mixed mode, sharing) ``` ## Step 2 – Install Wazuh Server By default, the Wazuh server package is not included in the Oracle Linux 8 default repository, so you will need to create a repo for Wazuh. First, import the GPG key with the following command: ``` rpm --import https://packages.wazuh.com/key/GPG-KEY-WAZUH ``` Next, create a Wazuh repo with the following command: ``` nano /etc/yum.repos.d/wazuh.repo ``` Add the following lines: ``` [wazuh] gpgcheck=1 gpgkey=https://packages.wazuh.com/key/GPG-KEY-WAZUH enabled=1 name=EL-Wazuh baseurl=https://packages.wazuh.com/4.x/yum/ protect=1 ``` Save and close the file, then install the Wazuh server with the following command: ``` dnf install wazuh-manager -y ``` Once the Wazuh server is installed, start the Wazuh service and enable it to start at system reboot: ``` systemctl enable --now wazuh-manager ``` You can also check the status of Wazuh with the following command: ``` systemctl status wazuh-manager ``` You will get the following output: ``` ● wazuh-manager.service - Wazuh manager Loaded: loaded (/usr/lib/systemd/system/wazuh-manager.service; enabled; vendor preset: disabled) Active: active (running) since Thu 2022-09-01 06:34:14 EDT; 11s ago Process: 11484 ExecStart=/usr/bin/env /var/ossec/bin/wazuh-control start (code=exited, status=0/SUCCESS) Tasks: 102 (limit: 11409) Memory: 579.5M CGroup: /system.slice/wazuh-manager.service ├─11540 /var/ossec/framework/python/bin/python3 /var/ossec/api/scripts/wazuh-apid.py ├─11582 /var/ossec/bin/wazuh-authd ├─11599 /var/ossec/bin/wazuh-db ├─11611 /var/ossec/framework/python/bin/python3 /var/ossec/api/scripts/wazuh-apid.py ├─11614 /var/ossec/framework/python/bin/python3 /var/ossec/api/scripts/wazuh-apid.py ├─11629 /var/ossec/bin/wazuh-execd ├─11644 /var/ossec/bin/wazuh-analysisd ├─11658 /var/ossec/bin/wazuh-syscheckd ├─11695 /var/ossec/bin/wazuh-remoted ├─11728 /var/ossec/bin/wazuh-logcollector ├─11752 /var/ossec/bin/wazuh-monitord ├─11773 /var/ossec/bin/wazuh-modulesd └─12421 sysctl net.ipv4.icmp_echo_ignore_broadcasts Sep 01 06:34:04 oraclelinux8 env[11484]: Started wazuh-db... Sep 01 06:34:05 oraclelinux8 env[11484]: Started wazuh-execd... Sep 01 06:34:06 oraclelinux8 env[11484]: Started wazuh-analysisd... Sep 01 06:34:07 oraclelinux8 env[11484]: Started wazuh-syscheckd... Sep 01 06:34:09 oraclelinux8 env[11484]: Started wazuh-remoted... Sep 01 06:34:10 oraclelinux8 env[11484]: Started wazuh-logcollector... Sep 01 06:34:11 oraclelinux8 env[11484]: Started wazuh-monitord... Sep 01 06:34:12 oraclelinux8 env[11484]: Started wazuh-modulesd... Sep 01 06:34:14 oraclelinux8 env[11484]: Completed. Sep 01 06:34:14 oraclelinux8 systemd[1]: Started Wazuh manager. ``` ## Step 3 – Install Elasticsearch and Kibana First, import the Elasticsearch GPG key with the following command: ``` rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch ``` Next, create an Elasticsearch repo with the following command: ``` nano /etc/yum.repos.d/elasticsearch.repo ``` Add the following lines: ``` [elasticsearch-7.x] name=Elasticsearch repository for 7.x packages baseurl=https://artifacts.elastic.co/packages/7.x/yum gpgcheck=1 gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch enabled=1 autorefresh=1 type=rpm-md ``` Save and close the file, then install Elasticsearch and Kibana with the following command: ``` dnf install elasticsearch-7.16.3 kibana-7.16.3 -y ``` Once the installation is completed, start Elasticsearch and enable it to start at system reboot: ``` systemctl start elasticsearch ``` Next, edit the Kibana configuration file and define the Elasticsearch host, server port, and server host: ``` nano /etc/kibana/kibana.yml ``` Change the following lines: ``` server.port: 5601 server.host: "your-server-ip" elasticsearch.hosts: [http://localhost:9200] ``` Save and close the file, then start the Kibana service and enable it to start at system reboot: ``` systemctl start kibana ``` To check the statuses of Kibana and Elasticsearch, run the following command: ``` systemctl status kibana elasticsearch ``` You will get the following output: ``` ● kibana.service - Kibana Loaded: loaded (/etc/systemd/system/kibana.service; disabled; vendor preset: disabled) Active: active (running) since Thu 2022-09-01 07:01:03 EDT; 22s ago Docs: https://www.elastic.co Main PID: 5283 (node) Tasks: 11 (limit: 49496) Memory: 312.1M CGroup: /system.slice/kibana.service └─5283 /usr/share/kibana/bin/../node/bin/node /usr/share/kibana/bin/../src/cli/dist --logging.dest=/var/log/kibana/kibana.log --pi> Sep 01 07:01:03 oraclelinux8 systemd[1]: Started Kibana. ● elasticsearch.service - Elasticsearch Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; enabled; vendor preset: disabled) Active: active (running) since Thu 2022-09-01 06:59:54 EDT; 1min 31s ago Docs: https://www.elastic.co Main PID: 5025 (java) Tasks: 77 (limit: 49496) Memory: 4.2G CGroup: /system.slice/elasticsearch.service ├─5025 /usr/share/elasticsearch/jdk/bin/java -Xshare:auto -Des.networkaddress.cache.ttl=60 -Des.networkaddress.cache.negative.ttl=> └─5215 /usr/share/elasticsearch/modules/x-pack-ml/platform/linux-x86_64/bin/controller ``` ## Step 4 – Install and Configure Filebeat First, install Filebeat using the following command: ``` dnf install filebeat-7.16.3 -y ``` Once installed, you will need to configure Filebeat to work with Wazuh. First, backup the Filebeat configuration file: ``` mv /etc/filebeat/filebeat.yml{,.bak} ``` Next, download the pre-configured configuration file: ``` curl -so /etc/filebeat/filebeat.yml https://raw.githubusercontent.com/wazuh/wazuh/v4.0.3/extensions/filebeat/7.x/filebeat.yml ``` Next, edit the downloaded file: ``` nano /etc/filebeat/filebeat.yml ``` Add or modify the following lines: ``` output.elasticsearch.hosts: ['http://localhost:9200'] logging.level: info logging.to_files: true logging.files: path: /var/log/filebeat name: filebeat keepfiles: 7 permissions: 0644 ``` Save and close the file, then verify Filebeat with the following command: ``` filebeat test output ``` Sample output: ``` elasticsearch: http://localhost:9200... parse url... OK connection... parse host... OK dns lookup... OK addresses: ::1, 127.0.0.1 dial up... OK TLS... WARN secure connection disabled talk to server... OK version: 7.16.3 ``` ## Step 5 – Install Filebeat Wazuh Module Next, you will need to download and install the Wazuh module for Filebeat. You can download it with the following command: ``` wget https://packages.wazuh.com/4.x/filebeat/wazuh-filebeat-0.1.tar.gz ``` Next, create a directory for Wazuh and extract the content of the downloaded file to the Wazuh directory: ``` mkdir /usr/share/filebeat/module/wazuh tar xzf wazuh-filebeat-0.1.tar.gz -C /usr/share/filebeat/module/wazuh/ --strip-components=1 ``` Next, download the Wazuh Elasticsearch alerts index template with the following command: ``` curl -so /etc/filebeat/wazuh-template.json https://raw.githubusercontent.com/wazuh/wazuh/4.1/extensions/elasticsearch/7.x/wazuh-template.json ``` Next, set up it using the following command: ``` filebeat setup --path.config /etc/filebeat --path.home /usr/share/filebeat --path.data /var/lib/filebeat --index-management -E setup.template.json.enabled=false ``` Next, restart the Filebeat service to apply the changes: ``` systemctl restart filebeat ``` You can check the status of Filebeat with the following command: ``` systemctl status filebeat ``` You will get the following output: ``` ● filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch. Loaded: loaded (/usr/lib/systemd/system/filebeat.service; disabled; vendor preset: disabled) Active: active (running) since Thu 2022-09-01 07:03:55 EDT; 6s ago Docs: https://www.elastic.co/products/beats/filebeat Main PID: 5384 (filebeat) Tasks: 9 (limit: 49496) Memory: 26.8M CGroup: /system.slice/filebeat.service └─5384 /usr/share/filebeat/bin/filebeat --environment systemd -c /etc/filebeat/filebeat.yml --path.home /usr/share/filebeat --path> Sep 01 07:03:55 oraclelinux8 systemd[1]: Started Filebeat sends log files to Logstash or directly to Elasticsearch.. ``` ## Step 6 – Install Wazuh Plugin for Kibana First, create a data directory for Kibana and set proper ownership to the kibana directory: ``` mkdir /usr/share/kibana/data chown -R kibana: /usr/share/kibana/ ``` Next, change the directory to Kibana and install the Wazuh plugin: ``` cd /usr/share/kibana sudo -u kibana /usr/share/kibana/bin/kibana-plugin install https://packages.wazuh.com/4.x/ui/kibana/wazuh_kibana-4.3.3_7.16.3-1.zip ``` Once the plugin is installed, verify the installed plugin with the following command: ``` sudo -u kibana /usr/share/kibana/bin/kibana-plugin list ``` Sample output: ``` wazuh@4.1.5-4108 ``` Finally, restart all services to apply the changes: ``` systemctl restart kibana systemctl restart elasticsearch systemctl restart wazuh-manager ``` ## Step 7 – Access Kibana Dashboard You can now access the Kibana web interface using the URL **http://server-IP:5601**. You should see the following page: ![Kibana dashboard page](https://www.atlantic.net/wp-content/uploads/2022/09/p1-3-1024x506.png) Click on **Explore on my own.** You should see the following screen: ![Kibana dashboard page](https://www.atlantic.net/wp-content/uploads/2022/09/p2-1-1024x508.png) Now, click on the **Menu** and select **Wazuh**. You should see the Wazuh dashboard on the following page: ![Wazuh dashboard page](https://www.atlantic.net/wp-content/uploads/2022/09/p3-1-1024x508.png) ## Conclusion Congratulations! You have successfully installed and configured the Wazuh server with ELK stack on Oracle Linux 8. You can now install and configure the Wazuh agent on the client machine and start monitoring it from the Wazuh dashboard. Try out a Wazuh server on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install ArangoDB on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-arangodb-on-oracle-linux-10/ | Published: 2022-10-13 | Updated: 2025-12-10 | Author: Hitesh Jethva ArangoDB is a free, open-source, and native graph database system developed by ArangoDB Inc. It is a multi-model database system that natively supports graphs, documents, and searches. Compared to other NoSQL databases, ArangoDB stores data as documents, key/value pairs, or graphs. It uses a declarative query language called AQL (ArangoDB Query Language). ArangoDB provides both a command line interface and a web-based interface. In this post, we will show you how to install and use ArangoDB on Oracle Linux 10. ## Step 1 – Install ArangoDB By default, the ArangoDB package is not included in the Oracle Linux default repo, so you will need to create a repo for it. ``` nano /etc/yum.repos.d/arangodb.repo ``` Add the following lines: ``` [arangodb] name=ArangoDB Project type=rpm-md baseurl=https://download.arangodb.com/arangodb35/RPM gpgcheck=0 gpgkey=https://download.arangodb.com/arangodb35/RPM/repodata/repomd.xml.key enabled=1 ``` Next, install the ArangoDB with the following commands: ``` dnf install arangodb3 -y ``` After the successful installation, you can verify the ArangoDB version using the following command: ``` arangodb --version ``` You should see the following output: ``` Version 0.14.15-1, build fe064e0, Go go1.13.6 ``` ## Step 2 – Secure ArangoDB Installation Next, you will need to run the arango-secure-installation script to set the root password for ArangoDB. You can run it with the following command: ``` arango-secure-installation ``` You should see the following output: ``` Please enter password for root user: Repeat password: 2022-08-23T07:25:09Z [10283] INFO [a1c60] {syscall} file-descriptors (nofiles) hard limit is 262144, soft limit is 262144 2022-08-23T07:25:10Z [10283] INFO [95cab] Password changed. 2022-08-23T07:25:10Z [10283] INFO [7da27] {startup} server will now shut down due to upgrade, database initialization or admin restoration. ``` ## Step 3 – Manage ArangoDB Service By default, the ArangoDB service is managed by systemd. You can manage it easily using the systemctl command. To start the ArangoDB service, run the following command: ``` systemctl start arangodb3 ``` To enable the ArangoDB service to start at system reboot, run the following command: ``` systemctl enable arangodb3 ``` You can verify the status of the ArangoDB using the following command: ``` systemctl status arangodb3 ``` You should get the following output: ``` ● arangodb3.service - ArangoDB database server Loaded: loaded (/etc/systemd/system/arangodb3.service; disabled; preset: disabled) Active: active (running) since Wed 2025-12-10 02:44:41 EST; 4s ago Invocation: 74bf635c65d14256b2c4d1f14ee0b84f Process: 43418 ExecStartPre=/usr/bin/install -g arangodb -o arangodb -d /var/tmp/arangodb3 (code=exited, status=0/SUCCESS) Process: 43420 ExecStartPre=/usr/bin/install -g arangodb -o arangodb -d /var/run/arangodb3 (code=exited, status=0/SUCCESS) Process: 43422 ExecStartPre=/bin/chown -R arangodb:arangodb /var/log/arangodb3 (code=exited, status=0/SUCCESS) Process: 43424 ExecStartPre=/bin/chmod 700 /var/log/arangodb3 (code=exited, status=0/SUCCESS) Process: 43426 ExecStartPre=/bin/chown -R arangodb:arangodb /var/lib/arangodb3 (code=exited, status=0/SUCCESS) Process: 43428 ExecStartPre=/bin/chmod 700 /var/lib/arangodb3 (code=exited, status=0/SUCCESS) Process: 43430 ExecStartPre=/bin/chown -R arangodb:arangodb /var/lib/arangodb3-apps (code=exited, status=0/SUCCESS) Process: 43432 ExecStartPre=/bin/chmod 700 /var/lib/arangodb3-apps (code=exited, status=0/SUCCESS) Main PID: 43434 (arangod) Tasks: 27 (limit: 131072) Memory: 226M (peak: 226.4M) CPU: 640ms CGroup: /system.slice/arangodb3.service └─43434 /usr/sbin/arangod --pid-file /var/run/arangodb3/arangod.pid --temp.path /var/tmp/arangodb3 --log.foreground-tty true ``` ## Step 4 – How to Use ArangoDB ArangoDB provides a command line utility called **arangosh** to manage the ArangoDB via the command line. To connect to the ArangoDB shell, run the following command: ``` arangosh ``` You will be asked to provide your root password to connect to the ArangoDB shell as shown below: ``` Please specify a password: _ __ _ _ __ __ _ _ __ __ _ ___ ___| |__ / _` | '__/ _` | '_ \ / _` |/ _ \/ __| '_ \ | (_| | | | (_| | | | | (_| | (_) \__ \ | | | \__,_|_| \__,_|_| |_|\__, |\___/|___/_| |_| |___/ arangosh (ArangoDB 3.5.7 [linux] 64bit, using jemalloc, build tags/v3.5.7-0-ga94761e8c6, VPack 0.1.33, RocksDB 6.2.0, ICU 58.1, V8 7.1.302.28, OpenSSL 1.1.1h 22 Sep 2020) Copyright (c) ArangoDB GmbH Command-line history will be persisted when the shell is exited. You can use `--console.history false` to turn this off Connected to ArangoDB 'http+tcp://127.0.0.1:8529, version: 3.5.7 [SINGLE, server], database: '_system', username: 'root' Type 'tutorial' for a tutorial or 'help' to see common examples 127.0.0.1:8529@_system> ``` Next, create a database named **testdb** using the following command: ``` db._createDatabase("testdb"); ``` To create a user called **testuser** and set a password, run the following command: ``` var users = require("@arangodb/users"); users.save("testuser@localhost", "password"); ``` You should see the following output: ``` { "user" : "testuser@localhost", "active" : true, "extra" : { }, "code" : 201 } ``` To grant privileges to the database and user, run the following command: ``` users.grantDatabase("testuser@localhost", "testdb"); ``` To verify all databases, run the following command: ``` db._databases(); ``` You should see the following output: ``` [ "_system", "testdb" ] ``` To exit from the ArangoDB shell, run the following command: ``` exit ``` Run the following command to connect to the ArangoDB using the user and database which we have created above: ``` arangosh --server.username "testuser@localhost" --server.database testdb ``` You should get the ArangoDB shell in the following output: ``` Please specify a password: _ __ _ _ __ __ _ _ __ __ _ ___ ___| |__ / _` | '__/ _` | '_ \ / _` |/ _ \/ __| '_ \ | (_| | | | (_| | | | | (_| | (_) \__ \ | | | \__,_|_| \__,_|_| |_|\__, |\___/|___/_| |_| |___/ arangosh (ArangoDB 3.5.7 [linux] 64bit, using jemalloc, build tags/v3.5.7-0-ga94761e8c6, VPack 0.1.33, RocksDB 6.2.0, ICU 58.1, V8 7.1.302.28, OpenSSL 1.1.1h 22 Sep 2020) Copyright (c) ArangoDB GmbH Command-line history will be persisted when the shell is exited. You can use `--console.history false` to turn this off Connected to ArangoDB 'http+tcp://127.0.0.1:8529, version: 3.5.7 [SINGLE, server], database: 'testdb', username: 'testuser@localhost' Type 'tutorial' for a tutorial or 'help' to see common examples 127.0.0.1:8529@testdb> ``` ## Step 5 – Access ArangoDB Web Interface By default, the ArangoDB web interface is accessible only from the localhost. You will need to edit the ArangoDB configuration file for remote access. ``` nano /etc/arangodb3/arangod.conf ``` Find the following line: ``` endpoint = tcp://127.0.0.1:8529 ``` And replace it with the following line: ``` endpoint = tcp://your-server-ip:8529 ``` Save and close the file, then restart the ArangoDB service to apply the changes: ``` systemctl restart arangodb3 ``` Now, open your web browser and type the URL **http://your-server-ip:8529**. You should see the ArangoDB login page: ![ArangoDB login page](https://www.atlantic.net/wp-content/uploads/2022/08/p1-4-1024x559.png) Provide your ArangoDB root username and password and click on the **Login** button. You should see the ArangoDB dashboard on the following page: ![ArangoDB select database page](https://www.atlantic.net/wp-content/uploads/2022/08/p2-3-1024x586.png) ![ArangoDB dashboard page](https://www.atlantic.net/wp-content/uploads/2022/08/p3-2-1024x501.png) ## Conclusion In this guide, we explained how to install ArangoDB on Oracle Linux 10. We also explained how to use the ArangoDB shell to create a database and user. ArangoDB is a very good alternative to MongoDB and can be used in a mission-critical environment. Get started with ArangoDB on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install InvoiceNinja on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-invoiceninja-on-oracle-linux-10/ | Published: 2022-10-14 | Updated: 2025-12-10 | Author: Hitesh Jethva InvoiceNinja is free, open-source, low-cost invoicing software that allows you to create and send invoices to your client with your own branding. It is written in PHP and JavaScript and designed for invoicing and billing customers. InvoiceNinja offers a lot of useful features such as recurring invoices, creating tasks, proposals, and projects, invoice designs, multiple payment options and more. In this post, we will show you how to install InvoiceNinja on Oracle Linux 10. ## Step 1 – Install Apache, MariaDB, and PHP First, you will need to install the Apache and MariaDB service on your system. You can install both packages using the following command: ``` dnf install httpd mariadb-server -y ``` Next, you will need to install the latest version of PHP on your server. First, reset the default PHP module with the following command: ``` dnf module reset php ``` Next, install PHP with other required extensions using the following command: ``` dnf install php php-{cli,fpm,gd,mbstring,curl,zip,xml,pdo,mysqlnd,pear,bcmath,gmp,json} --nogpgcheck ``` Next, start and enable the Apache, MariaDB, and PHP-FPM services with the following command: ``` systemctl start httpd mariadb php-fpm systemctl enable httpd mariadb php-fpm ``` ## Step 2 – Create a Database for InvoiceNinja InvoiceNinja uses MariaDB/MySQL as a database backend, so you will need to create a database and user for InvoiceNinja. First, log in to the MariaDB shell with the following command: ``` mysql ``` Next, create a database and user with the following command: ``` CREATE DATABASE invoiceninja; GRANT ALL ON invoiceninja.* TO invoiceninja@localhost IDENTIFIED BY "password"; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install InvoiceNinja First, you will need to install Composer on your server. You can install it with the following command: ``` curl -sS https://getcomposer.org/installer -o composer-setup.php php composer-setup.php --install-dir=/usr/local/bin --filename=composer ``` Once Composer is installed, verify the Composer version using the following command: ``` composer -V ``` You will get the following output: ``` Composer version 2.9.2 2025-11-19 21:57:25 ``` Next, download the latest version of InvoiceNinja with the following command: ``` git clone -b v5-stable --single-branch https://github.com/invoiceninja/invoiceninja.git ``` Once the download is completed, move the downloaded file to the Apache web root: ``` mv invoiceninja /var/www/html/ninja ``` Next, change the directory to the InvoiceNinja and install all required dependencies: ``` cd /var/www/html/ninja composer create-project --no-dev --ignore-platform-req=ext-sodium ``` Next, edit the .env file and define your database settings: ``` nano .env ``` Change the following lines: ``` DB_HOST=localhost DB_DATABASE=invoiceninja DB_USERNAME=invoiceninja DB_PASSWORD=password DB_PORT=3306 ``` Save and close the file, then set proper permissions and ownership to the InvoiceNinja directory: ``` chown -R apache:apache /var/www/html/ninja chmod -R 755 /var/www/html/ninja/storage/ ``` ## Step 4 – Configure Apache for InvoiceNinja Next, you will need to create an Apache virtual host configuration file for InvoiceNinja. You can create it with the following command: ``` nano /etc/httpd/conf.d/invoice-ninja.conf ``` Add the following lines: ``` ServerName ninja.example.com DocumentRoot /var/www/html/ninja/public DirectoryIndex index.php Options +FollowSymLinks AllowOverride All Require all granted CustomLog /var/log/httpd/invoice_ninja_access.log combined ErrorLog /var/log/httpd/invoice_ninja_error.log ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 5 – Access InvoiceNinja Web UI Now, open your web browser and access the InvoiceNinja web interface using the URL **http://ninja.example.com/setup.** You should see the following page: ![InvoiceNinja setup page](https://www.atlantic.net/wp-content/uploads/2022/09/p1-10-1024x502.png) Provide your website URL and click on **Test PDF.** You should see the following page: ![InvoiceNinja database setup page](https://www.atlantic.net/wp-content/uploads/2022/09/p2-6-1024x463.png) Define your database settings and click on **Test connection.** You should see the following page: ![InvoiceNinja email setup page](https://www.atlantic.net/wp-content/uploads/2022/09/p3-6-1024x268.png) Define your email settings and click on **Send test email.** You should see the following page: ![InvoiceNinja admin setup page](https://www.atlantic.net/wp-content/uploads/2022/09/p4-2-1024x499.png) Provide your admin username, email, and password, and click the **Submit** button. You should see the following page: ![InvoiceNinja login page](https://www.atlantic.net/wp-content/uploads/2022/09/p7-2-1024x532.png) Provide your email and password and click on the **Login with email** button. You should see the InvoiceNinja welcome page: ![InvoiceNinja welcome page](https://www.atlantic.net/wp-content/uploads/2022/09/p8-2-1024x506.png) Provide your company name and click on the **SAVE** button. You should see the InvoiceNinja dashboard on the following page: ![InvoiceNinja dashboard page](https://www.atlantic.net/wp-content/uploads/2022/09/p9-1024x503.png) ## Conclusion In this post, we explained how to install InvoiceNinja on Oracle Linux 10. You can now implement InvoiceNinja in your organization and start managing all invoicing from the central location. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install MyWebSQL on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-mywebsql-on-oracle-linux-10/ | Published: 2022-10-17 | Updated: 2025-12-10 | Author: Hitesh Jethva MyWebSQL is a modern web-based application for database administration over the web. It is a free and open-source MySQL database client written in PHP. MyWebSQL supports several databases, including MySQL, PostgreSQL, and SQLite. It is simple, fast, easy to use, and can be used to perform all database-related operations. MyWebSQL is compatible with all major web browsers and allows you to edit and delete multiple records at the same time. In this tutorial, we will show you how to install MyWebSQL on Oracle Linux 10. ## Step 1 – Install Apache, MariaDB, and PHP First, you will need to install the Apache web server, MariaDB server, PHP, and other required modules in your system. You can install all of them by running the following command: ``` dnf update -y dnf install httpd mariadb-server php php-cli php-mysqlnd php-fpm php-zip php-devel php-gd php-mbstring php-curl php-xml php-pear php-bcmath php-json unzip curl wget -y ``` After installing all the packages, start the Apache and MariaDB services and enable them to start at system reboot: ``` systemctl start httpd php-fpm systemctl start mariadb systemctl enable httpd php-fpm systemctl enable mariadb ``` ## Step 2 – Secure MariaDB Installation First, you will need to secure MariaDB and set a root password. You can do it with the following command: ``` mysql_secure_installation ``` Answer all the questions as shown below: ``` Enter current password for root (enter for none): OK, successfully used password, moving on... Set root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` Once MariaDB is secured, you can proceed to the next step. ## Step 3 – Install MyWebSQL First, you will need to download the latest version of MyWebSQL from the Sourceforge website. ``` wget https://sourceforge.net/projects/mywebsql/files/v3.9/Version%203.9.zip ``` Once the download is completed, unzip the downloaded file with the following command: ``` unzip Version\ 3.9.zip ``` Next, move the extracted directory to the Apache root directory: ``` mv Samnan-MyWebSQL-36564f5 /var/www/html/mywebsql ``` Next, change the ownership of the mywebsql directory to apache: ``` chown -R apache:apache /var/www/html/mywebsql/ ``` Once you are finished, you can proceed to the next step. ## Step 4 – Access MyWebSQL Web Interface Now, open your web browser and type the URL **http://your-server-ip/mywebsql.** You will be redirected to the MyWebSQL login page: ![MyWebSQL login page](https://www.atlantic.net/wp-content/uploads/2022/09/p1-11-1024x553.png) Provide your MariaDB root username and password and click on the **Login** button. You should see the MyWebSQL dashboard on the following page: ![MyWebSQL dashboard page](https://www.atlantic.net/wp-content/uploads/2022/09/p2-7-1024x504.png) ## Conclusion In this post, you learned how to install MyWebSQL on Oracle Linux 10. You can now install and use MyWebSQL to perform all database-related operations via a web browser. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Setup Personal Audio Streaming Server with Koel on Oracle Linux 8 > URL: https://www.atlantic.net/dedicated-server-hosting/setup-personal-audio-streaming-server-with-koel-on-oracle-linux-8/ | Published: 2022-10-18 | Updated: 2024-01-18 | Author: Hitesh Jethva Koel is a free, open-source, web-based personal audio streaming server written in Laravel. Koel client is written in Vue.js. Koel Player is the official mobile app for Koel, which supports both iOS and Android without the limitations of the mobile web version. Koel allows you to stream your music and access it from anywhere through the Internet. In this post, we will show you how to install a Koel streaming server on Oracle Linux 8. ## Step 1 – Install Nginx, MariaDB and PHP First, install Nginx and MariaDB with the following command: ``` dnf install nginx mariadb-server -y ``` Next, reset the default PHP modules and enable the PHP 8.0 module with the following command: ``` dnf module reset php dnf module enable php:8.0 ``` Next, install PHP 8.0 and other required dependencies with the following command: ``` dnf install php php-cli php-fpm php-json php-common php-mysqlnd php-zip php-gd php-mbstring php-curl php-xml php-pear php-bcmath php-tokenizer openssl php-json -y ``` Once all the packages are installed, edit the PHP-FPM file: ``` nano /etc/php-fpm.d/www.conf ``` Change the user from Apache to Nginx: ``` user = nginx group = nginx ``` Next, find the following line: ``` ;listen = /run/php-fpm/www.sock ``` And replace it with the following line: ``` listen = 9000 ``` Save and close the file, then start and enable the Nginx, MariaDB, and PHP-FPM services: ``` systemctl start nginx mariadb php-fpm systemctl enable nginx mariadb php-fpm ``` ## Step 2 – Install Required Dependencies Before starting, you will need to install some required dependencies on your server. First, install the development tools group package and Composer with the following command: ``` dnf group install "Development Tools" -y curl -sS https://getcomposer.org/installer -o composer-setup.php php composer-setup.php --install-dir=/usr/local/bin --filename=composer ``` Next, enable the EPEL and RPM fusion repo with the following command: ``` dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-8.noarch.rpm dnf install https://download1.rpmfusion.org/free/el/rpmfusion-free-release-8.noarch.rpm https://download1.rpmfusion.org/nonfree/el/rpmfusion-nonfree-release-8.noarch.rpm ``` Next, install the SDL2 and FFMPEG package with the following command: ``` dnf install http://rpmfind.net/linux/centos/8-stream/PowerTools/x86_64/os/Packages/SDL2-2.0.10-2.el8.x86_64.rpm -y dnf install ffmpeg ffmpeg-devel -y ``` ## Step 3 – Create a Database and User for Koel Next, you will need to create a database and user for Koel. First, connect to MariaDB with the following command: ``` mysql ``` Once you are connected, create a database and user with the following command: ``` CREATE DATABASE koeldb; CREATE USER 'koeluser'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the Koel database with the following command: ``` GRANT ALL PRIVILEGES ON koeldb . * TO 'koeluser'@'localhost'; ``` Next, flush the privileges and exit from MariaDB with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 4 – Install Node.js and Yarn Next, you will also need to install Node.js and Yarn on your server. First, list all available Node.js versions using the following command. ``` dnf module list --all nodejs ``` You will see the following output. ``` Name Stream Profiles Summary nodejs 10 [d] common [d], development, minimal, s2i Javascript runtime nodejs 12 common [d], development, minimal, s2i Javascript runtime nodejs 14 common [d], development, minimal, s2i Javascript runtime nodejs 16 common [d], development, minimal, s2i Javascript runtime nodejs 18 common [d], development, minimal, s2i Javascript runtime nodejs 20 common, development, minimal, s2i Javascript runtime ``` Next, enable the Node.js version 20 repo using the following command. ``` dnf module enable nodejs:20 ``` Next, install the Node.js by running the following command: ``` dnf install nodejs -y ``` Once Node.js is installed, you can verify the Node.js version using the following command: ``` node --version ``` You will get the following output: ``` v20.0.0 ``` Next, import the Yarn repository with the following command: ``` curl -sS https://dl.yarnpkg.com/debian/pubkey.gpg | gpg --dearmor -o /usr/share/keyrings/yarn-archive-keyring.gpg ``` Next, create a new file in the /etc/apt/sources.list.d/ directory to store the Yarn repository information: ``` echo "deb [signed-by=/usr/share/keyrings/yarn-archive-keyring.gpg] https://dl.yarnpkg.com/debian/ stable main" | sudo tee /etc/apt/sources.list.d/yarn.list ``` Finally, update the repository and install Yarn using the following command. ``` apt update -y apt install yarn -y ``` ## Step 5- Install and Configure Koel First, download the Laravel installer with the following command: ``` composer global require laravel/installer ``` Next, download the latest version of Koel using the following command: ``` git clone https://github.com/koel/koel.git --recursive ``` Next, change the directory to Koel and install all required dependencies with the following commands: ``` cd koel npm install npm audit fix npm audit fix --force composer install ``` Next, rename the example environment file: ``` mv .env.example .env ``` Next, edit the .env file: ``` nano .env ``` Define your database and other settings as shown below: ``` DB_CONNECTION=mysql DB_HOST=127.0.0.1 DB_PORT=3306 DB_DATABASE=koeldb DB_USERNAME=koeluser DB_PASSWORD=password MEMORY_LIMIT=512 FFMPEG_PATH=/usr/bin/ffmpeg ``` Save and close the file, then migrate the database with the following command: ``` php artisan koel:init --no-interaction ``` Next, set the admin password with the following command: ``` php artisan koel:admin:change-password ``` Define your new admin password as shown below: ``` Changing the user's password (ID: 1, email: admin@koel.dev) Your desired password: > Again, just to be sure: > Alrighty, the new password has been saved. Enjoy! 👌 ``` Next, create a directory for Koel inside the Nginx web root: ``` mkdir /var/www/html/streaming/ ``` Next, move the Koel directory to the streaming directory: ``` cd mv ~/koel /var/www/html/streaming/ ``` ## Step 6 – Configure Nginx for Koel Next, create an Nginx virtual host configuration file for Koel: ``` nano /etc/nginx/conf.d/koel.conf ``` Add the following lines: ``` server { listen 80; server_name koel.example.com; root /var/www/html/streaming/koel/public; index index.html index.htm index.php; location / { try_files $uri /index.php$is_args$args; } location ~ \.php$ { try_files $uri $uri/ /index.php?$args; fastcgi_param PATH_INFO $fastcgi_path_info; fastcgi_param PATH_TRANSLATED $document_root$fastcgi_path_info; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_pass 127.0.0.1:9000; fastcgi_index index.php; fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_intercept_errors on; include fastcgi_params; } } ``` Save and close the file, then edit the Nginx main configuration file: ``` nano /etc/nginx/nginx.conf ``` Define the hash bucket size below the line http {: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then set proper permissions and ownership: ``` chown -R nginx:nginx /var/www/html/streaming/ chmod -R 755 /var/www/html/streaming/ ``` Finally, restart the Nginx and PHP-FPM services to apply the changes: ``` systemctl restart nginx php-fpm ``` ## Step 7 – Access Koel Web UI Now, open your web browser and access the Koel web interface using the URL **http://koel.example.com.** You should see the Koel login page: ![Koel login page](https://www.atlantic.net/wp-content/uploads/2022/09/p1-14.png) Provide the Koel default username as admin@koel.dev and the password which you set earlier, then click on the **Log In** button. You should see the Koel dashboard on the following page: ![Koel dashboard page](https://www.atlantic.net/wp-content/uploads/2022/09/p2-9-1024x506.png) ## Conclusion Congratulations! You have successfully installed and configured the Koel music streaming server on Oracle Linux 8. You can now upload media on your server, install the Koel client app on your smartphone and start listening to your music on your smartphone. Try Koel on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Relic Server Monitoring on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-relic-server-monitoring-on-oracle-linux-10/ | Published: 2022-10-19 | Updated: 2025-12-09 | Author: Hitesh Jethva New Relic is a web-based application monitoring solution that allows you to monitor server performance in real time. Using New Relic, you can monitor CPU, RAM, Disk Usage, and specific user-defined events. New Relic uses an application performance index score to set and rate application performance across the environment in a unified manner. It is used by developers and DevOps teams to monitor the performance of their applications and infrastructure. This post will show you how to install New Relic on Oracle Linux 10 and monitor your server. ## Step 1 – Install New Relic Infrastructure Agent Before starting, you will need to install New Relic Infrastructure Agent on your server. First, create a yum repository for Relic Agent. ``` nano /etc/yum.repos.d/newrelic-infra.repo ``` Add the below code. ``` [newrelic-infra] name=New Relic Infrastructure baseurl=https://download.newrelic.com/infrastructure_agent/linux/yum/el/8/x86_64/ gpgkey=https://download.newrelic.com/infrastructure_agent/keys/newrelic_rpm_key_current.gpg gpgcheck=0 repo_gpgcheck=1 ``` Then, install the Relic agent using the below command: ``` yum install newrelic-infra -y ``` ## Step 2 – Create an Account on New Relic First, you will need to [create an account](https://newrelic.com/signup) on New Relic as shown below: ![Relic sign up page](https://www.atlantic.net/wp-content/uploads/2022/09/pp-1024x540.png) After signing up, click on **Integrations & Agents**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2022/10/r1.png) Now, click on **Guided Install**. You will see the page below: ![](https://www.atlantic.net/wp-content/uploads/2022/10/r2.png) Select a Linux operating system. You should see the following page. ![](https://www.atlantic.net/wp-content/uploads/2022/10/r3.png)Click on **Create a new key**. You should see the page below. ![](https://www.atlantic.net/wp-content/uploads/2022/10/r4.png) Click on **Continue. **You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2022/10/r5.png)Copy the above code and proceed to the next step. ## Step 3 – Install New Relic Now, log in to your Oracle Linux 10 server and run the code as shown below: ``` curl -Ls https://download.newrelic.com/install/newrelic-cli/scripts/install.sh | bash && sudo NEW_RELIC_API_KEY=NRAK-EKQIT4WVIIA81GP2FMIVHD70K7F NEW_RELIC_ACCOUNT_ID=7459528 /usr/local/bin/newrelic install -y ``` Once the installation has been completed, you should get the following output: ``` ==> Installing PostgreSQL Integration [OK] All checks passed. Installing Postgres Integration... Installing nri-postgresql... No match for argument: nri-postgresql Error: Unable to find a match: nri-postgresql ! Installing postgres-open-source-integration Failed New Relic installation complete -------------------- Installation Summary ✔ Golden Signal Alerts (installed) ✔ Infrastructure Agent (installed) ! PostgreSQL Integration (incomplete) Installation was successful overall, however, one or more installations could not be completed. Follow the instructions at the URL below to complete the installation process. ⮕ https://onenr.io/0Vwg33WmpwJ ``` Please remember the New Relic URL as shown in the above output. You will need it to access the New Relic web interface. ## Step 4 – Access New Relic Web Interface Now, open your web browser and access the New Relic web interface using the URL **https://onenr.io/0Vwg33WmpwJ.** You should see the New Relic dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2022/10/r6.png) Click on **See** **your** **data**. You will see all the information on the following page. ![](https://www.atlantic.net/wp-content/uploads/2022/10/r7.png) ## Conclusion This post taught us how to install New Relic on Oracle Linux 10. You can now implement New Relic in your organization and start monitoring your infrastructure from the central location. Try New Relic on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How To Install RethinkDB on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-rethinkdb-on-oracle-linux-10/ | Published: 2022-10-20 | Updated: 2025-12-09 | Author: Hitesh Jethva RethinkDB is a powerful NoSQL database management system designed for applications that require continuous data access. It supports many popular languages, including PHP, Java, Ruby, and Python. You can use it for automatic failover and robust fault tolerance. RethinkDB has very low response times and update latency. In addition, it has a beautiful, user-friendly web interface that lets you manage databases online. This tutorial will show you how to install RethinkDB on Oracle Linux 10. ## Step 1 – Install RethinkDB By default, RethinkDB is not available in the Oracle Linux 8 default repository, so you will need to create a repo for RethinkDB. You can make it with the following command: ``` nano /etc/yum.repos.d/rethinkdb.repo ``` Add the following lines: ``` [rethinkdb] name=RethinkDB enabled=1 baseurl=https://download.rethinkdb.com/repository/rocky/9/x86_64/ gpgkey=https://download.rethinkdb.com/repository/raw/pubkey.gpg gpgcheck=1 ``` ``` dnf install rethinkdb -y ``` Once RethinkDB is installed, you can verify the RethinkDB version with the following command: ``` rethinkdb --version ``` You should get the following output: ``` rethinkdb 2.4.4 (x86_64-redhat-linux) (GCC 11.4.1) ``` ## Step 2 – Configure RethinkDB First, you will need to copy the RethinkDB sample configuration file with the following command: ``` cp /etc/rethinkdb/default.conf.sample /etc/rethinkdb/instances.d/instance1.conf ``` Next, edit the configuration file using the following command: ``` nano /etc/rethinkdb/instances.d/instance1.conf ``` Then, change the following lines to enable the RethinkDB web console: ``` http-port=8080 server-name=server1 directory=/var/lib/rethinkdb/default log-file=/var/log/rethinkdb bind=0.0.0.0 ``` Save and close the file when you are finished. Next, create the necessary files and provide proper permissions with the following command: ``` touch /var/log/rethinkdb chown -R rethinkdb:rethinkdb /var/log/rethinkdb /var/lib/rethinkdb chmod -R 775 /var/log/rethinkdb /var/lib/rethinkdb ``` Now, start the RethinkDB service and enable it to start at system reboot with the following command: ``` systemctl enable --now rethinkdb systemctl start rethinkdb ``` Finally, you can directly verify the status of the RethinkDB service with the following command: ``` systemctl status rethinkdb ``` You should get the following output: ``` ● rethinkdb.service - LSB: This starts a set of rethinkdb server instances. Loaded: loaded (/etc/rc.d/init.d/rethinkdb; generated) Active: active (running) since Tue 2025-12-09 22:56:38 EST; 4s ago Invocation: f821b4161e83491a8de47645f508a5c4 Docs: man:systemd-sysv-generator(8) Process: 3288 ExecStart=/etc/rc.d/init.d/rethinkdb start (code=exited, status=0/SUCCESS) Tasks: 71 (limit: 24812) Memory: 53.9M (peak: 54.3M) CPU: 99ms CGroup: /system.slice/rethinkdb.service ├─3399 /usr/bin/rethinkdb --daemon --config-file /etc/rethinkdb/instances.d/instance1.conf --runuser rethinkdb --rungroup rethinkdb --pid-file /var/run/rethinkdb/instance> └─3400 /usr/bin/rethinkdb --daemon --config-file /etc/rethinkdb/instances.d/instance1.conf --runuser rethinkdb --rungroup rethinkdb --pid-file /var/run/rethinkdb/instance> ``` At this point, RethinkDB is started and listening on port 8080. You can check it with the following command: ``` ss -antpl | grep 8080 ``` You should get the following output: ``` LISTEN 0 128 *:8080 *:* users:(("rethinkdb",pid=173906,fd=25)) ``` ## Step 3 – Access RethinkDB Web Interface Now, open your web browser and access the RethinkDB using the URL **http://your-server-ip:8080.** You should see the following page: ![Rethinkdb dashboard page](https://www.atlantic.net/wp-content/uploads/2022/09/p1-9-1024x516.png) Now, click on the **Tables** button. You should see the following page: ![Rethinkdb create database page](https://www.atlantic.net/wp-content/uploads/2022/09/p2-5-1024x511.png) Click on the **Add** **Database** button. You should see the following page: ![Rethinkdb define database page](https://www.atlantic.net/wp-content/uploads/2022/09/p3-5.png) Provide your database name and click on the **Add**button. You should see your database on the next page: ![Rethinkdb show database page](https://www.atlantic.net/wp-content/uploads/2022/09/p4-1-1024x472.png) ## Conclusion This post explained how to install RethinkDB on Oracle Linux 10. You can now use RethinkDB with your application and manage it over the web. For more information, visit the RethinkDB official [documentation](https://rethinkdb.com/docs). Give it a try today on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How Is Blockchain-Based Development Shaping the Future of Financial Services? > URL: https://www.atlantic.net/pci-compliant-hosting/how-is-blockchain-based-development-shaping-the-future-of-financial-services/ | Published: 2022-10-21 | Updated: 2025-09-15 | Author: Richard Bailey Fourteen years have passed since Satoshi Nakamoto published a whitepaper on using cryptographically secured chains. This technology became known as the blockchain, a digitally distributed, decentralized system that records all the transactions made of any asset across the blockchain network. The assets can be tangible, such as cash, cars, and houses, or intangible such as intellectual property, copyrights, and patients. Blockchain tracks orders, digital money, and accounts across its network. This is why it is popular with digital cryptocurrencies like bitcoin. However, it’s important to remember that bitcoin is not a blockchain; blockchain is the technology that enables bitcoin to function; think of it as the engine that drives the bitcoin network. Join us as we delve into the complicated world of blockchain and discover that blockchain has many applications, including shaping the future of the financial services industry. ## How Does Blockchain work? Thousands of books, journals, and whitepapers go into the details of blockchain. Blockchain technology is ingenious, and above all else, it is trusted. Every transaction that is processed is recorded in a block. The block can contain any [information you want,](https://www.ibm.com/uk-en/topics/what-is-blockchain) who, what, when, where, how much, and even the condition. Each block is connected to the ones before and after, forming a chain. It is impossible to amend the chain, and each new block joins the end of the chain. The created blockchain grows and grows into a single chronologically organized record of transactions. Blockchain data projects precisely what happened in the past, allowing assets to be tracked and verified, creating greater trust, security, and an accountable, transparent, highly efficient platform. ## Blockchain and Finance Blockchain can be used for any credible information. It is already being used for [healthcare medical records](https://www.atlantic.net/hipaa-compliant-hosting/it-solutions-for-healthcare-how-to-choose/), logistics tracking, and tracing ingredients in the food distribution network—however, it’s money transfer and financial services that most people associate with blockchain. Recently we have seen a surge in FinTech businesses disrupting the financial sector, many of whom use blockchain as the backbone of their financial offering. The offered services may include decentralized financial transactions, payments, remittances, share trading, and proving financial identity. Here are the key reasons financial services are backing blockchain: **#1: No Intermediaries:** An intermediary is an engine between two parties in a financial transaction. The intermediary facilitates that transaction when moving money from point A to point B. Companies like [SWIFT](https://www.swift.com/) oversee transactions between countries that are not directly linked to the banking layer. Elsewhere, intermediaries connect lenders to borrowers and process monthly paychecks. The biggest problem with intermediaries is the cost associated with the transaction, a penalty that ultimately is passed onto the customer. Blockchain completely cuts out the middleman, with only a small transaction fee to pay for the computing power needed to validate the transaction within the chain. In addition, the blockchain doesn’t need to use third parties to authenticate data because it authenticates itself; the level of trust is so great that the blockchain is accepted as the source of truth. **#2: Highly Secure:** The financial services sector is drawn to blockchain because of its inherently secure framework based on cryptography, decentralization, and consensus. The blockchain network creates this trust by creating immutable transactions. In addition, it’s nearly impossible to change the blockchain structure, making all data traceable. To alter a blockchain, a hacker would need control of more than half of all the computers in the same distributed ledger, which is impossible. The more users on the blockchain, the more secure the data becomes. Blockchains are either permissioned (private) or permissionless (public); ironically, it can be argued that private blockchains are less safe because the number of nodes needed to change the blockchain could be less. All users should always keep their access keys to the chain secure in an encrypted repository. **#3: Borderless:** Blockchain is an international technology without borders. It doesn’t matter where you are; you only need access to the blockchain network to use it. This promotes having a currency free from government influence in a technology that’s far-reaching and not just for finance. The technology has raised concerns because it’s a service that’s difficult to regulate. **#4: Fast Transactions:** Traditional banking transactions are historically slow to process; how many times have you sent (or been sent) a payment, and it’s taken days to hit your account? Many think this is the bank reserving the cash to earn interest, but while that is partly true, the most delay comes from intermediaries ensuring the transaction is genuine. Blockchain is much quicker at processing transactions; although not instant, the trades are typically processed within the first 2 hours. Factors impacting this are the load on the blockchain network and the number of ledgers (and miners) available to process and validate the data block. All nodes have to agree that the transaction is valid to reach a state of consensus. Once achieved, the transaction block is validated and added to the blockchain. ## Conclusion We have just scratched the surface of blockchain development. Blockchain has a proven track record with cryptocurrencies. Upstart businesses have already launched innovative blockchain-based banking solutions, [such as ripple](https://ripple.com/), transforming how users send and receive financial products. Only now monolithic banking corporations are trying to catch up. The future of cryptocurrency may be volatile; no one knows, but the technology that powers it has many uses for the financial sector. Security is paramount in today’s online world, and all organizations want to use the most advanced technologies for a proactive stance toward the threat landscape. Ensure that your hosting service meets your needs adequately by using security best practices – as indicated by [compliance with PCI DSS](https://www.atlantic.net/pci-compliant-hosting/), HIPAA, HITECH, and SSAE 18 SOC 2 & SOC 3. Visit [Atlantic.Net](https://www.atlantic.net) to learn more. --- # How to Install Focalboard on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-focalboard-on-oracle-linux-10/ | Published: 2022-10-22 | Updated: 2025-12-09 | Author: Hitesh Jethva Focalboard is an open-source and self-hosted project management system that allows you to manage projects via a web browser. It is very similar to other project management systems like Asana, Trello, and Notion. Focalboard is simple, easy to use, and designed for both personal and development use. It offers a rich set of features, including multiple languages, support for multiple boards, import and export options for boards, and much more. If you are looking for an open-source project management solution, then Focalboard is the right choice for you. In this post, we will explain how to install Focalboard on Oracle Linux 10. ## Step 1 – Install and Configure PostgreSQL Focalboard uses PostgreSQL as a database backend, so you will need to install PostgreSQL on your system. First, add the PostgreSQL repository with the following commands: ``` dnf update -y ``` ``` dnf install https://download.postgresql.org/pub/repos/yum/reporpms/EL-8-x86_64/pgdg-redhat-repo-latest.noarch.rpm ``` Next, install PostgreSQL using the following command: ``` dnf install postgresql18 postgresql18-server ``` Next, initialize the PostgreSQL database using the following command: ``` /usr/pgsql-18/bin/postgresql-18-setup initdb ``` Then start and enable the PostgreSQL service with the following command: ``` systemctl start postgresql-18 systemctl enable postgresql-18 ``` Next, log in to PostgreSQL with the following command: ``` su - postgres psql ``` Next, create a database and user for PostgreSQL with the following command: ``` CREATE DATABASE focaldb; CREATE USER focaluser WITH PASSWORD 'password'; ``` Next, grant the necessary permission to the focal database and the user: ``` ALTER DATABASE focaldb OWNER TO focaluser; GRANT ALL PRIVILEGES ON DATABASE focaldb TO focaluser; GRANT ALL ON SCHEMA public TO focaluser; GRANT ALL PRIVILEGES ON ALL TABLES IN SCHEMA public TO focaluser; GRANT ALL PRIVILEGES ON ALL SEQUENCES IN SCHEMA public TO focaluser; ALTER SCHEMA public OWNER TO focaluser; ``` Next, exit from PostgreSQL using the following command: ``` \q exit ``` ## Step 2 – Install and Configure Focalboard First, download the latest version of Focalboard with the following command: ``` wget https://github.com/mattermost/focalboard/releases/download/v0.15.0/focalboard-server-linux-amd64.tar.gz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar -xvzf focalboard-server-linux-amd64.tar.gz ``` Next, move the extracted directory to the /opt with the following command: ``` mv focalboard /opt ``` Next, edit the Focalboard configuration file: ``` nano /opt/focalboard/config.json ``` Find the following lines: ``` "dbtype": "sqlite3", "dbconfig": "./focalboard.db", "postgres_dbconfig": "dbname=focalboard sslmode=disable", ``` And replace them with the following lines: ``` "dbtype": "postgres", "dbconfig": "postgres://focaluser:password@localhost/focaldb?sslmode=disable&connect_timeout=10", "postgres_dbconfig": "dbname=focaldb sslmode=disable", ``` Save and close the file when you are finished. ## Step 3 – Create a Systemd Service File for Focalboard Next, you will need to create a systemd service file to manage the Focalboard service: ``` nano /lib/systemd/system/focalboard.service ``` Add the following lines: ``` [Unit] Description=Focalboard server [Service] Type=simple Restart=always RestartSec=5s ExecStart=/opt/focalboard/bin/focalboard-server WorkingDirectory=/opt/focalboard [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes: ``` systemctl daemon-reload ``` Next, start and enable the Focalboard service with the following command: ``` systemctl start focalboard systemctl enable focalboard ``` At this point, Focalboard is started and listening on port 8000. You can check it with the following command: ``` ss -antpl | grep 8000 ``` You will get the following output: ``` LISTEN 0 128 *:8000 *:* users:(("focalboard-serv",pid=65302,fd=8)) ``` ## Step 4 – Configure Nginx as a Reverse Proxy for Focalboard Next, you will need to install and configure Nginx as a reverse proxy for Focalboard. First, install Nginx with the following command: ``` dnf install nginx -y ``` Next, create an Nginx virtual host configuration file: ``` nano /etc/nginx/conf.d/focalboard.conf ``` Add the following lines: ``` upstream focalboard { server localhost:8000; keepalive 32; } server { listen 80; server_name focalboard.example.com; location ~ /ws/* { proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; client_max_body_size 50M; proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Frame-Options SAMEORIGIN; proxy_buffers 256 16k; proxy_buffer_size 16k; client_body_timeout 60; send_timeout 300; lingering_timeout 5; proxy_connect_timeout 1d; proxy_send_timeout 1d; proxy_read_timeout 1d; proxy_pass http://focalboard; } location / { client_max_body_size 50M; proxy_set_header Connection ""; proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Frame-Options SAMEORIGIN; proxy_buffers 256 16k; proxy_buffer_size 16k; proxy_read_timeout 600s; proxy_cache_revalidate on; proxy_cache_min_uses 2; proxy_cache_use_stale timeout; proxy_cache_lock on; proxy_http_version 1.1; proxy_pass http://focalboard; } } ``` Save and close the file, then edit the Nginx configuration file: ``` nano /etc/nginx/nginx.conf ``` Add the following line below http {: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then verify Nginx for any syntax configuration errors: ``` nginx -t ``` You will get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Next, start and enable the Nginx service: ``` systemctl start nginx systemctl enable nginx ``` ## Step 5 – Access Focalboard Now, open your web browser and access the Focalboard web interface using the URL **http://focalboard.example.com/login**. You will be redirected to the Focalboard login page: ![Focalboard welcome page](https://www.atlantic.net/wp-content/uploads/2022/09/p1-8-1024x527.png) Click on **create an account if you don’t have one**. You should see the account creation page: ![Focalboard registration page](https://www.atlantic.net/wp-content/uploads/2022/09/p2-4.png) Set up your admin email address, username, and password and click on the **Register** button. You should see the following page: ![Focalboard login page](https://www.atlantic.net/wp-content/uploads/2022/09/p3-4.png) Provide your admin username and password and click on the **Login** button. You should see the Focalboard dashboard on the following page: ![Focalboard dashboard page](https://www.atlantic.net/wp-content/uploads/2022/09/p4.png) ## Conclusion In this guide, you learned how to install Focalboard with Nginx as a reverse proxy on Oracle Linux 10. You can now manage your projects easily through the web browser. Try Focalboard on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Best Prepare Your IT Infrastructure Early for a Successful Ecommerce Season > URL: https://www.atlantic.net/pci-compliant-hosting/how-to-best-prepare-your-it-infrastructure-early-for-a-successful-ecommerce-season/ | Published: 2022-10-23 | Updated: 2025-09-15 | Author: Richard Bailey IT infrastructure is under immense pressure during the holiday season as customers flock to eCommerce and non-store retailers. In addition, most major online retailers have an international presence, putting even greater pressure on IT systems. This article will advise preparing your eCommerce platform for the peak season. Planning and load testing should be underway well before the holidays; in this article, you will learn how to plan and support all business areas during this critical time for retailers. ## Failing to Prepare Is Preparing to Fail Retailers make most of their annual sales and profits during the holiday season, and preparation is critical to avoid downtime during the peak season. Downtime equals no sales and a bad customer experience, potentially forcing loyal customers to shop with your immediate competitors. This [site](https://www.gremlin.com/ecommerce-cost-of-downtime/) gives you an exciting insight into how much money some of the major US retailers lose in the event of downtime. Downtime is the enemy of the retailer. Here are some of our top tips to prevent downtime. ## **1: Scalability:** The ability to scale your IT resources is essential during peak trade. Online retailers achieve sustained high traffic throughout the holiday period, with peak traffic surges at various points during the season. For example, traffic peaks at go-live and peaks when new items are discounted, so it is essential to scale the computing resources horizontally and vertically to meet demand. It isn’t easy to achieve this on-premise, but scalability is standard with most cloud service providers. ## **2: Load Testing:** Schedule out-of-hours load testing on your application in the weeks running up to the peak season. If you have auto-scaling, you can fire traffic at your servers to simulate the traffic volumes expected at peak. If you have manual scaling, testing will give you an idea of the resources and number of servers you would need to scale to meet demand. ## **3: Stay Flexible with Bandwidth:** The network that connects your customers to your infrastructure must be able to cope with the surge in traffic expected during the peak season. Site performance is critical for sales, and any issues with slow websites or connection timeouts will turn off the customer, who may look elsewhere. Reach out to your service provider asking for guaranteed uncontended bandwidth assurances. ## **4: Stay Focused on Cybersecurity:** On Black Friday and Cyber Monday (in particular), hackers come out in force to disrupt online retailers. Denial of Service (DDoS) attacks are common, where hackers attempt to bring down your site or flood the site with network traffic, so the site appears offline to your genuine customers. DDoS prevention is an everyday requirement for businesses and is typically a third-party solution that detects and blocks hacking attempts instantly. Retailers must also be extra vigilant to phishing, javascript sniffing, form jacking, and Magecart skimming. If you are using digital platforms and WhatsApp business platforms, pay close attention to security to keep customers’ personal information safe. ## **5: Know Exactly Your RTO:** The Recovery Time Objective is part of a disaster recovery scenario regarding how long your business can remain offline until service is restored. Managed Service Providers offer [RTO with specific guarantees](https://www.atlantic.net/disaster-recovery/rto-vs-rpo/) covering the time it takes to become operational again. Companies may opt for disaster recovery services that can be invoked if the primary infrastructure fails during a peak. DR capabilities enable production services to be switched to an alternative location allowing business as usual to commence within minutes. ## **6: Choose a Resilient Hosting Provider:** Outsourcing IT services to a provider is common practice, but choosing a reliable provider is essential. A good indicator of their performance is the guaranteed service level agreements (SLAs). The very best hosting providers will offer [100% uptime SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/). In addition, these providers have the best infrastructure and the most highly redundant configurations possible to meet this target. ## Cloud Computing For Retailers Every year during peak retailer season, you read stories or witness firsthand websites that cannot handle the stresses of key retailer events like black Friday. The businesses that falter and go down lose customers. The companies that power through with no issues gain customers and sales and cement a reputation for reliability. Atlantic.Net provide virtual private servers, dedicated hosting, and an award-winning cloud platform to businesses worldwide. Retailers and eCommerce champions trust us to keep their infrastructure serving customers throughout peak trading. Retailers can experience a 600% surge in traffic at crucial moments during peak, and our engineers stand ready to help your business prepare and thrive in this environment. Atlantic.Net has been providing cutting-edge hosting services for over 30 years. Are you looking for a leading [PCI compliant hosting provider](https://www.atlantic.net/pci-compliant-hosting/) to host your next project? Our [full suite of managed services](https://www.atlantic.net/managed-services/) and always-available professional support team will build a reliable and durable solution for your business or organization. Atlantic.Net data centers are accredited by SOC 2 and SOC 3, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/), and HITECH standards, and our 24x7x365 support, monitoring, and world-class data center infrastructure are available now. For faster application deployment, free IT architecture design, and assessment, visit us at [www.atlantic.net](https://www.atlantic.net), call 866-618-DATA (3282), or email us at sales@atlantic.net. You can find out more information by [contacting our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # Things to Look for When Identifying the Best Colocation Facility > URL: https://www.atlantic.net/orlando-colocation-hosting-data-center/things-to-look-for-when-identifying-the-best-site-for-colocation/ | Published: 2022-10-24 | Updated: 2024-09-24 | Author: Richard Bailey Hosting services in colocation data centers are still popular with small, medium, and enterprise businesses; some companies may not be ready to adopt the cloud and may see colocation as an ideal entry point. Businesses benefit from outsourcing their IT services to colocation sites, finding significant cost savings, around-the-clock support, and high-end secure facilities. ## What Is Colocation? Colocation involves a third-party data center hosting privately owned servers, storage, and networking. An everyday example is a private company lifting and shifting physical server racks from their onsite premises to an alternative location. For the customer, the configuration of their kit does not change. But someone else now ‘feeds and waters’ their server platform. Minor networking changes are needed, but the host handles this before moving in. Are you in the market for [colocation services](https://www.atlantic.net/orlando-colocation-hosting-data-center/what-is-colocation-hosting/)? Atlantic.Net has access to premium data centers across the United States, Europe, and Asia. Join us as we discover the top reasons why businesses choose colocation data centers. ## Geographic Planning One of the top reasons businesses choose colocation ahead of public cloud providers is that they want their servers close to their physical location. These businesses may need to visit onsite for maintenance regularly, perhaps to reboot equipment or to troubleshoot server and hardware issues. Perhaps the business is based in the same town or state as the chosen colocation facility. However, it’s also possible that the company may select a facility geographically disparate from their other locations, maybe for disaster recovery purposes or as off-site data storage. Either way, geography is critical. ## Reliability and Performance Colocation facilities are usually high-end, featuring fail-safe, reliable, and highly redundant power and cooling services. As a result, uptime statistics are some of the best available, with some hosting providers offering 100% uptime SLA. Standard facilities feature dual power feeds and redundant network connectivity from a wide selection of network providers. Ultra-fast uplinks are expected, usually ranging from 1GB to 200GB circuits. In addition, colo typically provides direct access to the cloud using ultra-fast and very low latency point of presence connectivity. Colocation provides a clean, temperature-controlled, dust-free environment that improves the longevity of server hardware. ## Physical Data Center Security Colocation facilities are highly secure environments in discrete, safe compounds, protected by perimeter fencing and 24×7 onsite security. In addition, customers are given private suites in highly secure data centers to store their server hardware. CCTV and onsite access controls and procedures are usually standard, but the level of security depends on the data center tiering classification. Colocation sites adhere to the five pillars of security: - **Defending Outside the Perimeter:** This is achieved by employing monitored CCTV, perimeter audio alerts that trigger when someone gets too close to the perimeter wall, strict pre-approved access control for visitors, gates, fences, and security lighting. - **Defending Within the Perimeter:** This is achieved using CCTV and audio alarms, radar surveillance, security lighting, and often security patrols – sometimes with guard dogs. - **Protect the Data Center Structure:** This is achieved with fire and intruder alarm systems, CCTV, and control key access controls. - **Protect the Server Room:** Every data center suite needs multi-direction CCTV and key card access controls. In addition, server racks should be locked and discrete labeling should be in place. - **Protect the Data:** have an alerting system when data center doors are opened, and when engineers are on site, guests should be escorted into shared areas. ## Skilled Onsite Staff A significant advantage of choosing a colocation data center is having access to a highly trained team of technical support professionals. Colocation typically comes with three types of support: do-it-yourself, smart hands, and full technical support. Smart hands, sometimes called “Hands and Eyes,” is when you get access to data center engineers to perform everyday tasks on your servers. This might be rebooting a server, escorting an engineer, or hooking up a terminal to the server for high-level investigations. Most colo sites offer a managed service that offers full technical support. This includes technical support, smart hands, access to professional services, project managers, and service delivery managers. In addition, a fully managed service usually includes around-the-clock server monitoring and access to 24×7 operations teams. ## Future Growth Colocation is used by businesses that want to grow in the coming years. Hosting providers offer expansion options in their colocation packages. This will consist of additional rack space. If the business demands faster network connectivity to meet future bandwidth demands, these services can be bolted on. There is also the option to consume additional managed services from the hosting provider to help with future growth. For example, some businesses may leverage shared storage platforms or private cloud hosting. Other companies may migrate servers to a managed platform such as a public cloud or shared hosting facility. ## Award Winning Atlantic.Net Hosting Solutions Atlantic.Net is an [award-winning hosting provider](https://www.atlantic.net/hosting-services-provider/award-winning-service/) with over 30 years worth of experience. We provide effective hosting solutions to an extensive list of leading businesses throughout the United States, Europe, and beyond. Contact our sales team today to find out how heading through 2022, Atlantic.Net can help your organization meet and exceed your requirements with managed or unmanaged hosting solutions customized to meet your business’s needs. Learn more about our [colocation facilities](https://www.atlantic.net/orlando-colocation-hosting-data-center/) by speaking to the team today. --- #### Read More About Colocation Hosting - What Is [Colocation Hosting](https://www.atlantic.net/orlando-colocation-hosting-data-center/what-is-colocation-hosting/)? - [Orlando Colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/) Hosting --- --- # How to Install and Use Bpytop Resource Monitoring Tool on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-bpytop-resource-monitoring-tool-on-oracle-linux-10/ | Published: 2022-10-26 | Updated: 2025-12-06 | Author: Hitesh Jethva Bpytop is a free and open-source resource monitoring tool written in Python. It is very similar to other monitoring tools such as top, htop, and bashtop and allows system resources monitoring in real-time, including disk, network, process, and CPU. Bpytop is cross-platform and can be installed on several operating systems, including, Linux, macOS, and FreeBSD. In addition, it offers a simple and user-friendly web UI, keyboard and mouse support, supports multiple filters, and many more. This post will show you how to install and use the Bpytop resource monitoring tool on Oracle Linux 10. ## Step 1 – Install Required Dependencies Before starting, you will need to install some dependencies in your system. You can install all of them with the following command: ``` dnf group install "Development Tools" -y dnf install python3 gcc python3-devel -y ``` Once all the dependencies are installed, you can proceed to the next step. ## Step 2 – Install bpytop from Source You can also install bpytop by downloading it from GitHub and compiling it into your system. First, download the latest version of bpytop with the following command: ``` git clone https://github.com/aristocratos/bpytop.git ``` Once the download is completed, change the directory to bpytop and compile it with the following command: ``` cd bpytop make install ``` ## Step 3 – Install bpytop Using SNAP Package Manager You can also use the SNAP package manager to install bpytop on your system. First, install the SNAP package manager with the following command: ``` dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-8.noarch.rpm dnf install snapd --nogpgcheck ``` Once installed, start the Snap service with the following command: ``` systemctl start snapd ``` Next, run the following command to install bpytop: ``` snap install bpytop ``` ## Step 4 – Install bpytop Using Oracle Linux Repository You can also install bpytop from the EPEL repository. First, install the EPEL repo with the following command: ``` dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-8.noarch.rpm ``` Next, install bpytop with the following command: ``` dnf install bpytop --nogpgcheck ``` Once the installation is complete, verify the installed version of bpytop with the following command: ``` bpytop --version ``` Output: ``` bpytop version: 1.0.68 psutil version: 5.9.8 ``` ## Step 5 – Working with bpytop This section will show you how to use the bpytop utility to monitor system resources. First, launch the bpytop command-line interface using the following command: ``` bpytop ``` You should see the following screen: ![Bpytop dashboard page](https://www.atlantic.net/wp-content/uploads/2022/09/p1-6-1024x526.png) Press the ESC key to get the list of all commands and keyboard shortcuts. You should see the following screen: ![Bpytop option page](https://www.atlantic.net/wp-content/uploads/2022/09/p2-2-1024x519.png) Now, scroll down and select the **HELP** option. You will get a list of keyboard shortcuts on the following screen: ![Bpytop keyboard shortcut page](https://www.atlantic.net/wp-content/uploads/2022/09/p3-2-1024x524.png) If you want to exit the bpytop resource monitor, press **q** on the keyboard. ## Conclusion The above guide taught you how to install and use the bpytop resource monitoring tool on Oracle Linux 10. You can now play around with different options and check the result. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Create a Samba Share on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-create-a-samba-share-on-oracle-linux-10/ | Published: 2022-10-27 | Updated: 2025-12-06 | Author: Hitesh Jethva Samba is a free and open-source Server Message Block protocol that provides file and print services between clients across various operating systems. Samba allows you to share files and directories between Linux and Windows operating systems. It can also integrate with a Microsoft Windows Server domain, either as a Domain Controller (DC) or as a domain member. In this post, we will show you how to install the Samba server and create a private and public share on Oracle Linux 10. ## Step 1 – Install Samba Server By default, the Samba server package is included in the Oracle Linux default repo. You can install it easily using the following command: ``` dnf update -y dnf install samba samba-common samba-client -y ``` Once the Samba packages are installed, start and enable the smb and nmb services with the following command: ``` systemctl start smb systemctl enable smb systemctl start nmb systemctl enable nmb ``` ## Step 2 – Create a Public Share In this section, we will show you how to create a public share on Samba so that everyone can access it without authentication. First, create a directory for the public share and provide the necessary permissions: ``` mkdir -p /data/public touch /data/public/public.txt chmod -R 755 /data/public chown -R nobody:nobody /data/public ``` Next, backup the default Samba configuration file and create a new one with the following command: ``` mv /etc/samba/smb.conf /etc/samba/smb.conf.bak nano /etc/samba/smb.conf ``` Add the following configuration: ``` [global] workgroup = WORKGROUP server string = Samba Server %v netbios name = Oracle Linux 8 security = user map to guest = bad user dns proxy = no [Public] path = /data/public writable = yes guest ok = yes read only = no ``` Save and close the file, then restart the smb and nmb services to apply the changes: ``` systemctl restart smb systemctl restart nmb ``` ## Step 3 – Create a Private Share In this section, we will show you how to create a private share on Samba so that the user needs to authenticate to Samba to access the share. First, create a user and group with the following command ``` groupadd private useradd -g private private ``` Next, create a directory for the private share and provides the necessary permissions: ``` mkdir -p /data/private touch /data/private/private.txt chmod -R 755 /data/private chown -R root:private /data/private ``` Next, set the password for the private user with the following command: ``` smbpasswd -a private ``` Set your password as shown below: ``` New SMB password: Retype new SMB password: Added user private. ``` Next, edit the Samba configuration file with the following command: ``` nano /etc/samba/smb.conf ``` Add the following configurations at the end of the file: ``` [Private] path = /data/private valid users = @private guest ok = no writable = yes browsable = yes ``` Save and close the file, then restart the smb and nmb service to apply the changes: ``` systemctl restart smb systemctl restart nmb ``` ## Step 4 – Install Samba Client and Access the Samba Share Next, go to the remote machine and install the Samba client with the following command: ``` dnf install samba-client cifs-utils -y ``` Next, run the following command to access the private share: ``` smbclient //server-IP/private -U private ``` You will be asked to provide your password to access the private share: ``` Password for [WORKGROUP\private]: ``` Once you are authenticated, you will get the following output: ``` Try "help" to get a list of possible commands. smb: \> ``` Next, run the following command to list all files inside the private share: ``` smb: \> ls ``` You will get the following output: ``` . D 0 Fri Sep 16 03:06:25 2025 .. D 0 Fri Sep 16 03:06:19 2025 private.txt N 0 Fri Sep 16 03:06:25 2025 83873792 blocks of size 1024. 75576444 blocks available ``` Next, exit from the Samba shell with the following command: ``` smb: \> exit ``` To access the public share, run the following command: ``` smbclient //server-IP/public ``` You should see the password prompt: ``` Password for [WORKGROUP\root]: ``` Just press the Enter key to connect to the Samba shell: ``` Try "help" to get a list of possible commands. smb: \> ``` Next, list all files inside the public share with the following command: ``` smb: \> ls ``` You should see the following output: ``` . D 0 Fri Sep 16 03:04:35 2025 .. D 0 Fri Sep 16 03:06:19 2025 public.txt N 0 Fri Sep 16 03:04:35 2025 83873792 blocks of size 1024. 75576424 blocks available ``` Next, exit from the Samba shell with the following command: ``` smb: \> exit ``` ## Conclusion In this post, we explained how to install the Samba server and create a private and public share on Oracle Linux 10. You can now easily share files and directories between multiple machines easily. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Helm Kubernetes Package Manager on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-helm-kubernetes-package-manager-on-oracle-linux-10/ | Published: 2022-10-28 | Updated: 2025-12-06 | Author: Hitesh Jethva Helm is a free and open-source tool used for managing Kubernetes applications. In simple words, Helm is a package manager for Kubernetes. It allows you to improve productivity, reduces the complexity of [microservices](https://taikun.cloud/microservices-monolithic-architectures-whats-the-difference/) deployments, and enables the adaptation of cloud-native applications. Helm is a client/server application that provides a convenient way for developers to package and ship an application to their end users to install. This post will show you how to install and use Helm package manager on Oracle Linux 10. **Note:** This procedure requires a Kubernetes Cluster to be available. If you need to set this up, [check out this procedure](https://www.atlantic.net/dedicated-server-hosting/how-to-set-up-three-node-kubernetes-cluster-on-ubuntu/). ## Step 1 – Install Helm Using Script The simplest and easiest way to install the Helm is using the script. First, download the Helm installation script using the Curl command: ``` dnf update -y curl -fsSL -o get_helm.sh https://raw.githubusercontent.com/helm/helm/master/scripts/get-helm-4 ``` Once the script is downloaded, set executable permissions with the following command: ``` chmod +x get_helm.sh ``` Next, run the script to install Helm: ``` ./get_helm.sh ``` After the installation, verify the Helm version using the following command: ``` helm version ``` You will get the following output: ``` version.BuildInfo{Version:"v4.0.1", GitCommit:"12500dd401faa7629f30ba5d5bff36287f3e94d3", GitTreeState:"clean", GoVersion:"go1.25.4", KubeClientVersion:"v1.34"} ``` ## Step 2 – Install Helm from Binary You can also install Helm by downloading it from their official website. First, download the latest version of Helm with the following command: ``` wget -O helm.tar.gz https://get.helm.sh/helm-v4.0.1-linux-amd64.tar.gz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar -zxvf helm.tar.gz ``` Next, move the Helm binary to the system location with the following command: ``` mv linux-amd64/helm /usr/local/bin/helm ``` Next, verify the Helm version using the following command: ``` helm version ``` You should get the following output: ``` version.BuildInfo{Version:"v4.0.1", GitCommit:"12500dd401faa7629f30ba5d5bff36287f3e94d3", GitTreeState:"clean", GoVersion:"go1.25.4", KubeClientVersion:"v1.34"} ``` ## Step 3 – How to Use Helm First, add the Helm chart repository with the following command: ``` helm repo add stable https://charts.helm.sh/stable ``` Next, verify the added repository with the following command: ``` helm repo list ``` You will get the following output: ``` NAME URL stable https://charts.helm.sh/stable ``` This is because Helm provides a search facility to search for a specific package. To search for a Jenkins package, run the following command: ``` helm search repo jenkins ``` You will get the following output: ``` NAME CHART VERSION APP VERSION DESCRIPTION stable/jenkins 2.5.4 lts DEPRECATED - Open source continuous integration... ``` You can now install the Jenkins package using the following command: ``` helm install jenkins stable/jenkins ``` To search for an Apache package, run the following command: ``` helm search repo apache ``` You will get the following output: ``` NAME CHART VERSION APP VERSION DESCRIPTION stable/hadoop 1.1.4 2.9.0 DEPRECATED - The Apache Hadoop software library... stable/ignite 1.2.2 2.7.6 DEPRECATED - Apache Ignite is an open-source di... stable/jenkins 2.5.4 lts DEPRECATED - Open source continuous integration... stable/kafka-manager 2.3.5 1.3.3.22 DEPRECATED - A tool for managing Apache Kafka. stable/spark 0.1.2 A Apache Spark Helm chart for Kubernetes. Apach... stable/superset 1.1.13 0.36.0 DEPRECATED - Apache Superset (incubating) is a ... ``` To learn more about the Helm environment, execute the following command, which will give you details regarding the Helm environment. ``` helm env ``` You should see the following output: ``` HELM_BIN="helm" HELM_BURST_LIMIT="100" HELM_CACHE_HOME="/root/.cache/helm" HELM_CONFIG_HOME="/root/.config/helm" HELM_DATA_HOME="/root/.local/share/helm" HELM_DEBUG="false" HELM_KUBEAPISERVER="" HELM_KUBEASGROUPS="" HELM_KUBEASUSER="" HELM_KUBECAFILE="" HELM_KUBECONTEXT="" HELM_KUBEINSECURE_SKIP_TLS_VERIFY="false" HELM_KUBETLS_SERVER_NAME="" HELM_KUBETOKEN="" HELM_MAX_HISTORY="10" HELM_NAMESPACE="default" HELM_PLUGINS="/root/.local/share/helm/plugins" HELM_REGISTRY_CONFIG="/root/.config/helm/registry/config.json" HELM_REPOSITORY_CACHE="/root/.cache/helm/repository" HELM_REPOSITORY_CONFIG="/root/.config/helm/repositories.yaml" ``` ## Conclusion In this post, we explained how to install Helm using two ways. We also explained how to use Helm package manager to install and manage packages. You can now easily install Helm on the Kubernetes cluster to manage and deploy applications using Helm. Try Helm on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Lessons Learned in 2022 About Cybersecurity for 2023 and Beyond > URL: https://www.atlantic.net/dedicated-server-hosting/lessons-learned-in-2022-about-cybersecurity-for-2023-and-beyond/ | Published: 2022-10-29 | Updated: 2026-05-30 | Author: Alexander Wise With cybersecurity awareness month upon us and 2023 just around the corner, it’s time to take stock and revisit how the cybersecurity landscape has changed and developed throughout 2022. For example, as we enter a post-covid world, only now are we seeing the true impact of the pandemic on the cybersecurity industry. In addition, data breaches and ransomware are as destructive as ever. Still, we have also seen an emergence of state-sponsored cyberterrorism and hacking communities targeting big businesses, supply chains, and government infrastructure. 2022 has seen more large-scale data breaches, including $18 million in bitcoin and $15 million in Ethereum [stolen from Crypto.com](https://crypto.com/product-news/crypto-com-security-report-next-steps). Additionally, Microsoft suffered a significant data breach, with hackers claiming they stole the source code of Cortana, Bing, and several other Microsoft products. 2022 has also seen Samsung and NVIDIA targeted in some high-profile cases. In this article, we will explore the security landscape of 2022 and discover how things are shaping up for 2023 and beyond. ## Lessons Learned in 2022 The past year represents one of the cybersecurity industry’s most challenging and disruptive periods on record. Governments and businesses worldwide continue to navigate the uncharted waters of a global pandemic. Companies strive to achieve a “new normal,” and digital transformation efforts are sharply accelerated as businesses embrace hybrid and remote work arrangements. However, businesses are still experiencing many of the cyber security threats that plagued many of them in 2021. Cyberattacks, on average, are up 50% more throughout 2022, and the education and research sectors are feeling the biggest squeeze, with an average of 1,605 attacks targeting these industries every week throughout 2021 and 2022. The employed attack vectors are changing, too: from a new generation of sophisticated pay-per-click exploits to the war in Ukraine, the cyber security landscape has changed significantly. What are the most common attack vectors witnessed in 2022? How are hackers gaining access to such high-profile victims? The answers might surprise you because we still see many old-fashioned techniques employed. **#1: Social Engineering:** This is when a hacker manipulates people into carrying out specific actions or divulging valuable information to an attacker. Thousands of person-hours go into creating complex social engineering campaigns. An attacker identifies a victim and builds trust using a variety of techniques. For example, a skilled hacker will willingly attempt to convince someone by phone or private messaging to hand over their details. Hackers often target persons of interest or senior employees; unfortunately, social engineering works. There are countless examples; over [$100 million was stolen from Google and Facebook CEOs](https://www.justice.gov/usao-sdny/pr/lithuanian-man-pleads-guilty-wire-fraud-theft-over-100-million-fraudulent-business). In addition, cybercriminals have used DeepFake AI technology to target a significant British energy supplier using a social engineering technique that mimicked the CEO’s voice. **#2: Business Email Compromise:** Business email compromise (BEC) is a growing problem for businesses of all sizes. In a recent survey, [78% of companies](https://www.helpnetsecurity.com/2022/02/28/email-based-ransomware-attacks/)reported experiencing at least one BEC attack in the past year. BEC can be used to phish for user credentials and sensitive business data and to deliver malware payloads used in ransomware attacks. Many scammers use real email addresses to target actual employees within the same business or attempt to intercept conversations and hijack communications between companies and customers. **#3: Cloud Misconfiguration:** One of the most common types of misconfiguration is when systems are not correctly configured for the cloud. Cloud misconfiguration can lead to the leakage of sensitive data and open up businesses to cyberattacks. It is caused by incorrect access management controls, often due to overly complex infrastructure. When an organization needs to configure its cloud-based applications or services properly, cloud misconfiguration can occur. Unfortunately, this can leave their data and systems open to attack. For example, a poorly configured storage bucket can allow hackers to access sensitive data, and attackers can easily guess weak passwords. **#4: Risk of Malware:** Malware describes malicious software, including computer viruses, trojan horses, and rootkits. It can also include ransomware, keyloggers, and trojans. In addition, attackers use many techniques to inject malware into a system, such as phishing attempts to trick an end user into installing malicious software. The malware requires multiple responses to be defended against. First, technology is needed to intercept malware, such as email scanning or end-user protection software. Second, servers must be patched and updated regularly, which significantly helps to have a workforce trained to spot phishing and malware attempts. **#5: Ransomware:** One of the most common malware payloads is ransomware. It’s a malicious application that typically locks computer files with an encryption key; the hacker then attempts to extort money from the victim. Ransomware is a severe threat because victims often pay the ransom to get their files back or pay them to prevent leaks of sensitive or controversial information. **#6: Increase in Supply Chain Attacks:** Today’s supply chain is highly digital, with most companies relying on digital services in some capacity. This reliance on another company’s services means your system becomes interconnected with theirs. As a result, an attack on one side could eventually compromise the other side. For this reason, a supply chain compromise could be catastrophic for anyone in the supply chain. ## Cybersecurity for 2023 and Beyond It is evident from 2022 that many of the threats face between 2020-2021 are still relevant today. The ever presence of social engineering, phishing, and ransomware makes familiar reading, but its sophistication and the number of high-profile victims make the cybersecurity lessons learned from 2022 crucial. It is the bigger fish that are falling afoul of sophisticated scams and hacks. As we approach 2023, cybersecurity will continue to be a top priority for organizations of all sizes. Unfortunately, the rapid development of digital technologies has created new opportunities for cybercriminals while presenting new threats to organizations and individuals. We expect to see more of the same as hackers continue to pick off the easy targets. These businesses do not adequately secure their cloud endpoints or set weak passwords and inadequate password policies. Cyberterrorism will continue to be a concern in 2023 as groups and individuals seek to cause damage and chaos through cyberattacks. Organizations need to understand cyber threats and how to protect themselves to stay ahead of these threats. ## Choose a Cybersecurity Conscious Hosting Provider One of the best ways to increase your business’s cybersecurity protection state is to outsource critical IT services to a hosting provider that offers managed security services, and a security-defined infrastructure, that adheres to the zero trust framework and the principle of least privilege. Atlantic.Net provide virtual private servers, [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/), and an award-winning cloud platform to businesses worldwide. Businesses around the globe trust us to keep their infrastructure serving customers throughout the year. Atlantic.Net provides a full suite of [managed security services](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-security/) including security firewall, intrusion prevention, multifactor authentication, server management, network edge protection, backup, Trend Micro Deep Security, and much more! Our engineers stand ready to help your business prepare and thrive in this environment. Atlantic.Net has been providing cutting-edge hosting services for over 30 years. Are you looking for a leading [hosting provider](https://www.atlantic.net/hosting-services-provider/) to host your next project? Our [full suite of managed services](https://www.atlantic.net/managed-services/what-are-managed-services/) and always-available professional support team will build a reliable and durable solution for your business or organization. Atlantic.Net data centers are accredited by SOC 2 and SOC 3, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/), and HITECH standards, and our 24x7x365 support, monitoring, and world-class data center infrastructure are available now. For faster application deployment, free IT architecture design, and assessment, visit us at [www.atlantic.net](https://www.atlantic.net), call 866-618-DATA (3282), or email us at sales@atlantic.net. You can find out more information by [contacting our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # How to Install Tig Git Repository Browser on Oracle Linux 10 > URL: https://www.atlantic.net/vps-hosting/how-to-install-tig-git-repository-browser-on-oracle-linux-10/ | Published: 2022-10-31 | Updated: 2026-05-26 | Author: Hitesh Jethva Tig is an ncurses-based text-mode interface and repository browser for Git. It is cross-platform and can be installed on various operating systems, including Linux, macOS, and Windows. Tig is a straightforward interface to Git and is used for staging Git commits. It provides a rich set of features. Some of them are listed below: - View stashes list - View single file changes - Browse the commits in the current branch - Allows to compare two branches - View the commits for one or more specific branches This post will show you how to install and use the Tig git repository browser on Oracle Linux 10. ## Step 1 – Install Tig By default, Tig is not included in the Oracle Linux 8 default repository, so you will need to compile it from the source. First, install the required dependencies using the following command: ``` dnf update -y dnf group install "Development Tools" -y dnf install ncurses-devel ncurses -y ``` Next, download the latest version of Tig with the following command: ``` git clone https://github.com/jonas/tig.git ``` Next, change the directory to the downloaded manual and compile it with the following command: ``` cd tig make make install ``` Once Tig is installed, verify the installed version of Tig with the following command: ``` tig --version ``` You should get the following output: ``` tig version 2.6.0-5-g19a25b95 ncursesw version 6.4.20240127 ``` You can see all options available with Tig using the following command: ``` tig --help ``` You should see the following output: ``` tig 2.6.0 Usage: tig [options] [revs] [--] [paths] or: tig log [options] [revs] [--] [paths] or: tig show [options] [revs] [--] [paths] or: tig reflog [options] [revs] or: tig blame [options] [rev] [--] path or: tig grep [options] [pattern] or: tig refs [options] or: tig stash [options] or: tig status or: tig < [git command output] Options: + Select line in the first view -v, --version Show version and exit -h, --help Show help message and exit -C Start in ``` ## Step 2 – Working with Tig You must clone any Git repository to your local system to use Tig. Let’s clone the repository using the following command: ``` git clone https://github.com/hitjethva/linuxbuz ``` Once the repository is cloned, change the cloned repository using the following command: ``` cd linuxbuz ``` Next, run the Tig command without any argument to display the list of commits on the current branch: ``` tig ``` You should see the detailed information on your commits on the following screen: ![Tig commit information](https://www.atlantic.net/wp-content/uploads/2022/09/p1-7-1024x526.png) To display all the references of your repository, run the following command: ``` tig refs ``` You should see the following screen: To display a log of activities of the above repository, run the following command: ``` tig log ``` You should see the following screen: If you want to search for a particular pattern from your repository, run the following command: ``` tig grep linux ``` You should see the following screen: ![Tig search for pattern](https://www.atlantic.net/wp-content/uploads/2022/09/p5-1.png) To display the status of your git repository, run the following command: ``` tig status ``` You should see the next screen: ![Tig git repository status](https://www.atlantic.net/wp-content/uploads/2022/09/p6-1.png) To put Tig in Pager mode, run the following command: ``` git status | tig ``` You should see the next screen: ![Tig git pagger mode](https://www.atlantic.net/wp-content/uploads/2022/09/p7-1.png) To find out who made a change to a file, run the following command: ``` tig blame readme.md ``` You should see the next screen: ![Tig find who made changes](https://www.atlantic.net/wp-content/uploads/2022/09/p8-1-1024x180.png) ## Conclusion The above guide taught you how to install and use the Tig git repository browser on Oracle Linux 10. You can easily track and manage your Git repository from the command-line interface. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Does Climate Change Make Disaster Recovery More Important? > URL: https://www.atlantic.net/disaster-recovery/does-climate-change-make-disaster-recovery-more-important/ | Published: 2022-11-01 | Updated: 2025-04-11 | Author: Richard Bailey The impact of climate change is being felt globally. Our summers appear to be getting hotter, our winters are volatile, and all the weather in between is getting more extreme. The [United States Geological Survey](https://www.usgs.gov/faqs/how-can-climate-change-affect-natural-disasters) (USGS) predicts that as global temperatures continue to rise, the likelihood of increased drought and intense storms will continue to grow. Warmer oceans fuel higher wind speeds, increasing the likelihood of tropical storms and hurricanes. In addition, rising sea levels increase the danger of storm surges and extreme weather, threatening to damage the infrastructure that impacts our daily lives. With this increased risk to IT infrastructure, join us as we look at how climate change influences business decision-making surrounding the importance of [disaster recovery and business continuity](https://www.atlantic.net/disaster-recovery/). ## How Does Climate Change Affect IT Services? One of the biggest threats to business continuity is an unexpected event that wipes out core IT infrastructure. Any structural impact to data centers or the destruction of provider services such as electricity, cooling, gas, water, or even O2 can result in widespread system outages. Such unexpected events are called ‘an act of God,’ which means an event out of your control. This includes events like lightning strikes, hurricanes, tornadoes, flooding, sandstorms, sinkholes, and even the outbreak of war like we are seeing in Ukraine. The likelihood of these events happening is slim, but it is not impossible. Therefore to protect business continuity, it’s prudent to prepare for every eventuality. The unique problem of climate change is that the likelihood of a natural disaster occurring is increasing, thus creating a particular concern for business strategists. ## Why Is Disaster Recovery Important During These Uncertain Times? The unpredictability of climate change makes it challenging to decide when to invest in DR. Disaster Recovery services are provided by cloud hosting businesses like Atlantic.Net; DR provides businesses with the technical capabilities to fail over critical business applications and core infrastructure services to an alternative location. The service will consist of a tried and tested backup strategy that protects critical servers with a regular backup. In addition, the backup provides a guaranteed restore point. Databases should be replicated synchronous or asynchronously to an alternative location, and the same should be done with domain controllers. All critical storage should be replicated at the hardware layer to the alternative site. There are multiple ways to fail over servers; each method varies between the cloud providers. One of the most popular ways is to have a DR application that integrates with the cloud platform hypervisor. It will migrate the virtual instances between sites A and B. Storage snapshots at site B can be used to start the instance almost immediately. Storage is so fast these days that data loss is infrequent, with the worst-case scenario typically still meeting your required RPO objectives. When a professional service provider implements DR, the impact on the end user is minimal. Most users will not realize services have failed, and problems are usually short-lived. However, if the customer doesn’t invest in DR, the enterprise is at risk of an extended outage period. ## Can a Disaster Impact My Business? Some readers may wonder how likely it is that a disaster may occur. Some may assume that a disaster won’t impact them. However, each company has individual business continuity requirements. Where would your employees work if the offices were destroyed? The biggest disaster I have witnessed in the last 20 years was the complete outage of one of the [biggest data centers in London](https://www.datacenterdynamics.com/en/news/details-emerge-of-global-switch-outage-in-london/). First, we were told it was a lightning strike, and later the truth came out it was a facilities problem in the breaker room. As a result, the massive global online fashion retailer I was working for at the time went offline for two days, but they had no DR strategy! The outage cost the company tens of millions in lost revenue and angered a lot of loyal customers. More recently, Google lost an entire availability zone in London, Europe-west2-a. On the 2nd of August 2022, Google [apologized](https://www.datacenterdynamics.com/en/news/googles-london-data-center-outage-during-heatwave-caused-by-simultaneous-failure-of-multiple-redundant-cooling-systems/) for the extended downtime and unexpected impact on cloud services in Europe-west2-a. Any customer who did not have disaster recovery services configured across the entire availability zone experienced extensive downtime. In June 2022, Microsoft Azure and Microsoft 365 (Office) experienced a 12-hour outage for all customers hosted via Microsoft’s Virginia Datacenter. Any customer that did not have  ‘always-available’ enabled or have zone-redundant services were impacted. Virginia hosts US-EAST1 and US-EAST2 availability zones and is a prevalent region with Azure customers. ## Disaster Recovery and Regulatory Compliance In many businesses, it is critical to ensure that Disaster Recovery services are available to protect businesses bound by legislation. For example, HIPAA compliance demands that healthcare organizations can restore PHI data in the event of complete failure. Therefore, a disaster recovery solution is recommended, and a robust and reliable data backup plan is essential. Additionally, restoring PHI from a disk or tape in an unaltered state must be possible if all else fails. ## What Disaster Recovery Service Can Atlantic.Net Provide? How do you look after your backups? Does your hosting partner offer disaster recovery-as-a-service? Have you developed your disaster recovery plan? If the answer to these questions is “no,” Atlantic.Net is here to help. We are a leading cloud services provider and have been providing cutting-edge hosting services for over 30 years. Our proven experience, full [suite of managed services](https://www.atlantic.net/managed-services/), and always-available professional support team deliver confidence in our DR solutions. Our [100% uptime guarantee](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/) protects all Atlantic.Net services. We will build the perfect solution for your business or organization, embedded with disaster recovery capabilities such as high availability, managed backup, and disaster-recovery-as-a-service. Ensuring business continuity and [disaster recovery capabilities](https://www.atlantic.net/disaster-recovery/) is essential to modern business. However, with the growing risk from global warming and climate change, now is the time to rethink your business continuity strategy to ensure it fits your business. Atlantic.Net data centers and hosting services are certified with SOC 2 and SOC 3, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/), and HITECH accreditation, with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, visit us at [www.atlantic.net](https://www.atlantic.net), call 866-618-DATA (3282), or email us at [sales@atlantic.net](mailto:sales@atlantic.net). You can find out more information by [contacting our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # How Is the Cloud Enabling Scientific Discoveries and Research? > URL: https://www.atlantic.net/life-sciences-pharma-biotech/how-is-the-cloud-enabling-scientific-discoveries-and-research/ | Published: 2022-11-11 | Updated: 2025-09-15 | Author: Dr. Rachael Bailey Cloud computing has dramatically changed how scientists and researchers conduct their work. It has allowed them to manage and process large amounts of data more efficiently and effectively than ever before. With the cloud, researchers can now access the necessary tools and resources to pursue their work with greater speed and agility. Imagine you are a scientist wanting to sequence the human genome. To do so, you need a tremendous amount of computing power. You could try to purchase or build your supercomputer, but that would be very expensive and require a lot of space. Alternatively, you could rent time on a supercomputer at a commercial data center. But even that would be prohibitively expensive and might not be available when you need it. Cloud computing solves this problem by enabling scientists to access massive amounts of computing power over the Internet. Researchers can use this computing power for sequencing the human genome, simulating climate change, designing new drugs, or any task requiring large amounts of processing power. This article will examine how the cloud drives scientific discoveries and research. ## Improving Access to Information Information is essential to finding the right product on the Internet, tracking a shipment, or simply keeping up with friends and family online. In the pharmaceutical and biosciences sector, researchers and medical professionals must have access to accurate information securely and quickly. Healthcare and Pharma organizations are turning to the cloud to organize, manage and analyze their data sets. For example, cloud-based Laboratory Information Management Systems (LIMS) provides clinical, research, and testing organizations with many advantages, including a faster implementation time, flexibility, scalability, high security, and cost reduction. In addition to managing and tracking laboratory samples, a cloud-based LIMS can automate processes, reduce the likelihood of human error, support compliance, and foster collaboration and accessibility. ## Revolutionizing Scientific Discovery Cloud-based platforms allow scientists and researchers to solve complex research challenges that would otherwise be impossible. In addition, the cloud helps researchers to collaborate effectively with each other. By sharing resources and data in a secure and accessible way, collaborators can work in sync on important research projects. Cloud computing also allows researchers to access public datasets for comparison and analysis. ## Processing Genomic Data in the Cloud Genomics is one of the fastest-growing and most data-intensive fields in biology. It is predicted that genomics research will generate somewhere between 2 and 40 exabytes of data over the next decade. In addition, estimates suggest that [over 60 million patients](https://www.biorxiv.org/content/10.1101/203554v1) will have sequenced genomes by 2025. As our understanding of genomics expands, we need new ways to process data. [Cloud computing is the answer.](https://www.atlantic.net/life-sciences-pharma-biotech/) A genomics research organization can analyze and visualize large genomic datasets. ## Discovering Novel Drugs in the Cloud Scientists are taking advantage of the power of big data to speed up the drug discovery process. [Cloud computing offers several benefits](https://www.atlantic.net/life-sciences-pharma-biotech/) for scientists working on drug discovery. First, it allows them to access large amounts of data quickly and easily, making it possible to test hypotheses and find new cures faster. In addition, the cloud can help scientists save money by sharing computing resources. This makes it possible for them to run complex simulations that would be too expensive or time-consuming on individual computers. ## Partnering with Atlantic.Net These are just some ways that researchers and scientists can harness the power of the cloud to benefit their research. In fact, the possibilities are endless and advancing every day as cloud computing evolves. With your next exciting research project in mind, consider partnering with Atlantic.Net, a leading cloud hosting services provider, to ensure it is a success. We already provide an effective cloud platform to many leading businesses and organizations, including several Ivy League universities. With over 30 years of experience, Atlantic.Net can help you leverage the power of the cloud to support your data-intensive research computations and big data analysis. Flexible, scalable, and fast computing power helps to drive innovation and discovery, and Atlantic.Net can help you to achieve this. As experts in providing fully compliant hosting services, Atlantic.Net can also help you to achieve all your regulatory and compliance requirements with minimal effort on your part. You can find out more information by [contacting our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # How to Install Gatsby.js Node Framework on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-gatsby-js-node-framework-on-arch-linux/ | Published: 2022-11-13 | Updated: 2024-06-02 | Author: Hitesh Jethva Gatsby is a free, open-source, React-based site generator built on top of Node.js using GraphQL. Gatsby offers 2500+ plugins and some great features that differentiate it from other static site generators. It has great components that simplify things like routing, linking, and handling images, which are not included in the core React library. In this post, we will show you how to install Getsby.js on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Node.js and NPM Gatsby is based on Node.js, so you will need to install Node.js and NPM on your server. Run the following command to install both Node.js and NPM: ``` pacman -Sy nodejs npm ``` Once Node.js is installed, you can verify the Node.js version with the following command: ``` node --version ``` You will get the following output: ``` v19.0.0 ``` To check the NPM version, run the following command: ``` npm --version ``` You should see the following output: ``` 8.19.2 ``` ## Step 3 – Install Gatsby.js Gatsby offers a command-line tool that helps you create a site using the command-line interface. You can install the Gatsby-cli using the following command: ``` npm -g install gatsby-cli ``` Once the installation is finished, you can verify the Gatsby version with the following command: ``` gatsby --version ``` You should see the following output: ``` ╔════════════════════════════════════════════════════════════════════════╗ ║ ║ ║ Gatsby collects anonymous usage analytics ║ ║ to help improve Gatsby for all users. ║ ║ ║ ║ If you'd like to opt-out, you can use `gatsby telemetry --disable` ║ ║ To learn more, checkout https://gatsby.dev/telemetry ║ ║ ║ ╚════════════════════════════════════════════════════════════════════════╝ Gatsby CLI version: 4.24.0 ``` ## Step 4 – Create a Site with Gatsby.js Next, run the following command to create a new site: ``` gatsby new ``` You will be asked several questions to create a site as shown below: ``` create-gatsby version 2.24.0 Welcome to Gatsby! This command will generate a new Gatsby site for you in /root with the setup you select. Let's answer some questions: What would you like to call your site? What would you like to call your site? ✔ · My Gatsby Site What would you like to name the folder where your site will be created? ✔ root/ my-gatsby-site ✔ Will you be using JavaScript or TypeScript? · JavaScript ✔ Will you be using a CMS? · No (or I'll add it later) ✔ Would you like to install a styling system? · No (or I'll add it later) Thanks! Here's what we'll now do: 🛠 Create a new Gatsby site in the folder my-gatsby-site cd my-gatsby-site Start the local development server with npm run develop See all commands at https://www.gatsbyjs.com/docs/gatsby-cli/ ``` Next, change the directory to your newly created site and run the development server using the following command: ``` cd my-gatsby-site gatsby develop -H your-server-ip ``` You should see the following output: ``` You can now view my-gatsby-site in the browser. ⠀ http://your-server-ip:8000/ ⠀ View GraphiQL, an in-browser IDE, to explore your site's data and schema ⠀ http://your-server-ip:8000/___graphql ⠀ Note that the development build is not optimized. To create a production build, use gatsby build ⠀ success Building development bundle - 33.679s success Writing page-data.json files to public directory - 0.222s - 3/4 18.01/s ``` ## Step 5 – Access Gatsby.js Web Interface At this point, Gatsby is started and listens on port 8000. You can now access it using the URL **http://your-server-ip:8000/.** You should see the Gatsby site on the following screen: ![Getsby dashboard page](https://www.atlantic.net/wp-content/uploads/2022/11/p1-1024x523.png) ## Conclusion In this post, we explained how to install the Gatsby.js framework on Arch Linux. We also explained how to create a static site using Gatsby.js. You can now start developing using the Gatsby.js framework. You can try Gatsby.js on [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Make the Most Innovative Use of Data in the Cloud > URL: https://www.atlantic.net/vps-hosting/how-to-make-the-most-innovative-use-of-data-in-the-cloud/ | Published: 2022-11-15 | Updated: 2025-09-15 | Author: Richard Bailey Data analytics, also known as data insights, is a booming industry and a sector of IT that is increasing. In the world of cloud computing, data is king, and with it comes endless possibilities to harness the information to drive business decisions and plan future strategies. To be a leader in big data, it is essential to collect, process, and transform data collection. Businesses use AI routines to create intelligent workflows, and data scientists crunch results using complex modeling programs. None of this would be possible without [cloud computing](https://www.atlantic.net/vps-hosting/). So join us as we discover the most innovative ways to harness data in the cloud. ## Data Data analytics applies to almost any industry, but marketing and retail are two industries that thrive on accurate data. Companies need to [use customer data](https://www.getcensus.com/blog/what-is-reverse-etl) to ensure they offer the right product or service to the right customer at the right time and place. Collecting data is relatively straightforward; however, creating accurate information based on the collected data is a huge challenge that takes teams of skilled data scientists and well-trained learning models. As consumers, we create data for our favorite brands in shops and online. Our behaviors shift in response to local and national events. Take COVID-19; customer buying habits fundamentally changed during the pandemic, driving customers online. The consumer has weathered the pandemic but is now facing the challenges of a cost of living crisis. Today, businesses must make critical decisions quickly, and data can give insights into customer attitudes and behavior. This knowledge gives your business the upper hand when retaining and attracting new customers. You may be wondering how it is possible to get access to big data. There are several avenues to explore here. - **Purchase Data Sets:** Did you know that you can simply buy this data from a global scale data business? There are several data collection agencies across the globe, such as [CACI International Inc](https://www.caci.co.uk). Datasets that are available to purchase that include any credible information, such as customer habits and behaviors, geodemographic segmentation tools, financial services, and digital, lifestyle, and attitudinal characteristics. - **Create Your Own Data Sets:** Nearly all businesses have at least one database containing information about their customers, sales, etc. Those that invest significantly in data analytics will gather all sorts of data, perhaps from their website using clickstream data or from surveys, sales orders, refunds, and returns. This is where we are seeing significant growth with data in the cloud as businesses offload these CPU-intense workloads to the cloud providers. ## Insights What kind of insights can you get from trained datasets? The possibilities are endless, but here are some of the standard data insights businesses may look for: - **Buying Habits**: Learning how and why your customer buys is a critical business need. It enables you to create effective advertising campaigns and tailor customized marketing strategies. In addition, an accurate dataset will allow you to discover where your customers shop, what they buy, and why they buy certain products and services. - **Customer Engagement:** Trained datasets can discover how customers engage with your brand in a physical and digital environment by learning customer interactions and preferences and predicting future behaviors. - **Demographics Insights:** This type of data is critical to understand the people you serve; shared insights include gender, location, profession, and age. This data allows you to target high-value customers and learn who interacts with your business. - **Customer Acquisition Costs:** This is the process of understanding the costs of getting customers to buy your products. Consider the marketing costs, advertising spends, salaries, running fees, and commissions. - **Marketing Insights:** Businesses rely on marketing to get the word about products and services. Advertising can be costly, so understanding the campaign’s outreach is critical. Learn how much new business the campaign has generated, what demographics interacted with the campaign, and what campaign platforms were a success. - **Monte Carlo Simulation:** Countless factors impact a customer journey. This simulator calculates the possibilities and options that may affect the customer’s purchase and determines the probability of an event happening. It can help predict failure. - **Factor Analysis:** This data reduction technique takes enormous datasets and shrinks them to a small, more accurate dataset with actionable insights, making data lineage much more straightforward to visualize [data analytics trends](https://www.rapidops.com/blog/top-data-analytics-trends-infographic/) and habits. We have just scratched the surface of data insights; quite literally, the possibilities are endless. Other common examples include using data to predict fraud, credit defaulting risk, and customer profiling. In addition, the number of simulations available is growing daily; other joint analysis tools are regression analysis, cohort analysis, cluster, time series, and sentiment analysis. ## Action Cloud computing opens the door to data analytics and insights. Cloud storage offers limitless space for your databases, datasets, and trained data, and cloud computing is available on demand to crunch numbers and process data cubes. Although performing this type of data modeling is challenging on-premises because you are always going to be restricted by the size of the infrastructure, you can leverage as much or as little as you need in the cloud. Data organizations have the added headache of regulatory compliance, with regulations such as HIPAA and HITRUST to consider. Cloud-service providers work closely with their customers to ensure that they comply with the necessary compliance and regulatory guidelines. As a result, they are setting a precedent for data companies. Atlantic.Net has been providing [cloud hosting](https://www.atlantic.net/vps-hosting/) and managed services for over 30 years. Our cloud platform is available with service plans that can scale to any demanding workload. In addition, you can provision multiple configurations up to 32 vCPU and 192GB of memory, all backed onto ultra-fast SSD storage – perfect for crunching large data sets. You can start your data journey right now by emailing [sales@atlantic.net.](mailto:sales@atlantic.net) If you have any questions, please get in touch! Contact an advisor at 866-618-DATA (3282) --- # How to Install and Use Node.js and NVM on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-node-js-on-arch-linux/ | Published: 2022-11-16 | Updated: 2024-06-01 | Author: Hitesh Jethva Node.js is a cross-platform JavaScript runtime environment for building back-end and front-end applications. It is built on Chrome’s JavaScript, allowing you to run JavaScript code on the server side. Node.js provides Node Package Manager to install and manage multiple node packages and dependencies. It is primarily deployed for non-blocking, event-driven servers like traditional websites and back-end API services. This post will show you how to install Node.js on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Node.js for Arch Linux Repository The Node.js package is included in the Arch Linux default repository by default. You can install it by just running the following command: ``` pacman -S nodejs npm ``` Once Node.js is installed, you can verify the Node.js version with the following command: ``` node --version ``` You will get the following output: ``` v19.0.0 ``` To check the NPM version, run the following command: ``` npm --version ``` You should see the following output: ``` 8.19.2 ``` ## Step 3 – Install NVM NVM, also called “Node Version Manager,” is a tool used for installing and managing multiple Node.js versions on the system. First, install the latest version of NVM with the following command: ``` curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.2/install.sh | bash ``` You should see the following command: ``` => Close and reopen your terminal to start using nvm or run the following to use it now: export NVM_DIR="$HOME/.nvm" [ -s "$NVM_DIR/nvm.sh" ] && \. "$NVM_DIR/nvm.sh" # This loads nvm ``` Next, run the following command to start using the NVM: ``` export NVM_DIR="$HOME/.nvm" [ -s "$NVM_DIR/nvm.sh" ] && \. "$NVM_DIR/nvm.sh" ``` Next, verify the NVM version using the following command: ``` nvm --version ``` You should see the following output: ``` 0.39.2 ``` ## Step 4 – Install Node.js with NVM To list all available Node.js versions, run the following command: ``` nvm list-remote ``` You will get a list of all versions in the following output: ``` v17.8.0 v17.9.0 v17.9.1 v18.0.0 v18.1.0 v18.2.0 v18.3.0 v18.4.0 v18.5.0 v18.6.0 v18.7.0 v18.8.0 v18.9.0 v18.9.1 v18.10.0 v18.11.0 v18.12.0 (Latest LTS: Hydrogen) v19.0.0 ``` To install the latest version of Node.js, run the following command: ``` nvm install node ``` You will get the following output: ``` Downloading and installing node v19.0.0... Downloading https://nodejs.org/dist/v19.0.0/node-v19.0.0-linux-x64.tar.xz... ####################################################################################################################################### 100.0% Computing checksum with sha256sum Checksums matched! Now using node v19.0.0 (npm v8.19.2) Creating default alias: default -> node (-> v19.0.0) ``` To install the latest stable version of Node.js, run the following command: ``` nvm install --lts ``` You will get the following output: ``` Installing latest LTS version. Downloading and installing node v18.12.0... Downloading https://nodejs.org/dist/v18.12.0/node-v18.12.0-linux-x64.tar.xz... ####################################################################################################################################### 100.0% Computing checksum with sha256sum Checksums matched! Now using node v18.12.0 (npm v8.19.2) ``` To install a specific Node.js version, run the following command: ``` nvm install 18.10.0 ``` You should see the following output: ``` Downloading and installing node v18.10.0... Downloading https://nodejs.org/dist/v18.10.0/node-v18.10.0-linux-x64.tar.xz... ####################################################################################################################################### 100.0% Computing checksum with sha256sum Checksums matched! Now using node v18.10.0 (npm v8.19.2) ``` To list all installed Node.js versions, run the following command: ``` nvm ls ``` You should see the following output: ``` -> v18.10.0 v18.12.0 v19.0.0 system default -> node (-> v19.0.0) ``` To change the default Node.js version to 19.0.0, run the following command: ``` nvm use 19.0.0 ``` You will get the following output: ``` Now using node v19.0.0 (npm v8.19.2) ``` ## Conclusion This post explained different ways to install Node.js on Arch Linux. You can now choose your preferred method depending on your requirements. We recommend using the NVM method as it gives you more flexibility for adding and removing different Node.js versions on a per-user basis. Try Node.js on [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Htop on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-htop-on-arch-linux/ | Published: 2022-11-17 | Updated: 2024-04-19 | Author: Hitesh Jethva Htop is a free, open-source, interactive system monitor, process viewer, and process manager designed for Linux-based operating systems. It is very similar to Task Manager in the Windows OS used to troubleshoot and kill a process that is utilizing excessive server resources. It helps the system administrator to monitor system load, CPU, memory usage, processes, and more via a command-line interface. In this post, we will show you how to install and use Htop on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Htop on Arch Linux By default, the Htop package is included in the Arch Linux default repository. You can see the detailed information on Htop using the following command: ``` pacman -Si htop ``` You should see the following output: ``` Repository : extra Name : htop Version : 3.2.1-1 Description : Interactive process viewer Architecture : x86_64 URL : https://htop.dev/ Licenses : GPL Groups : None Provides : None Depends On : libcap libcap.so=2-64 libnl ncurses libncursesw.so=6-64 Optional Deps : lm_sensors: show cpu temperatures lsof: show files opened by a process strace: attach to a running process Conflicts With : None Replaces : None Download Size : 144.56 KiB Installed Size : 362.45 KiB Packager : Christian Hesse Build Date : Fri 03 Jun 2022 06:35:51 AM UTC Validated By : MD5 Sum SHA-256 Sum Signature ``` Next, install Htop using the following command: ``` pacman -Sy htop ``` ## Step 3 – How to Use Htop To Monitor Linux System To use the Htop tool, open your command-line interface and run the Htop command: ``` htop ``` You should see all processes and system resources on the following screen: ![Htop list all processes](https://www.atlantic.net/wp-content/uploads/2022/11/p1-1-1024x526.png) Htop provides some common keyboard shortcuts that allow you to manage Htop. To see the help information for Htop, press the **F1** key. You should see the following screen: ![Htop help information](https://www.atlantic.net/wp-content/uploads/2022/11/p2.png) To see the setup information, press the **F2** key. You should see the following screen: ![Htop setup information](https://www.atlantic.net/wp-content/uploads/2022/11/f2-1024x434.png) To search htop for user names and process names, press the **F3** key. You should see the following screen: ![Htop search by username](https://www.atlantic.net/wp-content/uploads/2022/11/f3-1024x524.png) To see the process tree instead of a single line per process, press the **F5.** You should see the following screen: ![Htop process tree](https://www.atlantic.net/wp-content/uploads/2022/11/p5-1024x526.png) To see the individual process and sort it, press the **F6.** You should see the following screen: ![Htop see individual process](https://www.atlantic.net/wp-content/uploads/2022/11/p6-1024x526.png) To see a list of signals that can be sent to the process, press the **F9** key. You should see the following screen: ![Htop see list of signals](https://www.atlantic.net/wp-content/uploads/2022/11/p8-1024x525.png) ## Conclusion In this post, we explained how to install Htop on Arch Linux. We also explained how to use it to monitor the system resources. You can now install Htop on [dedicated hosts](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! and monitor server processes. --- # How to Make the Best Use of Artificial Intelligence in Cloud Computing > URL: https://www.atlantic.net/vps-hosting/how-to-make-the-best-use-of-artificial-intelligence-in-cloud-computing/ | Published: 2022-11-18 | Updated: 2026-05-30 | Author: Richard Bailey Artificial intelligence enables businesses to save time and money by achieving better data-driven outcomes. ## How Cloud AI Helps Businesses Manage Data Analytics Ever-evolving AI capabilities in the cloud can support digital transformation initiatives among enterprises. Incorporating AI, automation, and data analytics in the cloud can improve processes and organizational performance. Artificial Intelligence capabilities in a centralized cloud can help enterprises make the most of their business intelligence, as well as make more analytics-driven decisions that will help keep their businesses competitive. We are seeing a convergence of two digital enablers—Artificial Intelligence and [Cloud Computing](https://www.atlantic.net/vps-hosting/)—enabling users to experience more “intuitive” interactions and experiences to enrich their digital knowledge. This helps them bring their data and analytical processes to where they are. ## Use AI to Power Your Self-Managing Cloud Cloud computing is a method of storing and retrieving data on computers and servers hosted at an external location and providing remote access for users. According to a recent report, AI is applied in various ways, from automation to enterprise data analytics. In addition, AI is used for running routine operations that can improve the security and efficiency of businesses. For the past decade, cloud providers have been trying to develop a crown jewel platform to enable businesses to test and create their own sales models in a codeless manner, driving unprecedented efficiency and dynamic and engaging sales performance. ## Using Artificial Intelligence Techniques to Improve Data Management Of course, today’s organizations generate and collect large amounts of data. Cloud AI tools improve and help data management, including, for instance, the recognition of data, ingestion, classification, and managing the data over time. AI solutions are more trustworthy than human solutions in simple, repetitive tasks. This can mean that AI solutions can use data management to spot fraud and other functions. IT teams can also [learn artificial intelligence](https://www.mygreatlearning.com/artificial-intelligence/courses) to optimize their critical workflows. While AI handles tedious activities, the IT team can focus on strategic operations that generate meaningful business results. ## Seamless Data Management Data has become an essential resource for most businesses, especially for implementing artificial intelligence. More reliable data sources are needed to ensure that AI tools can provide more efficient ways of acquiring, modifying, and managing information. The future of AI technology will allow the use of tools that support more intelligent methods of developing, managing, and handling business information in every industry. For example, new technology is aiding large companies in gathering big data to expedite complex processes that may help speed up the delivery of products and services. ## AI Integration Into Our Daily Lives With the help of artificial intelligence, modern life has become ribbons of functionality that can be texted, spoken, written, or communicated through voice assistants. For example, an everyday user might ask a smart device: “Alexa, how do I cool off at the beach?” Artificial intelligence capabilities enable firms to enhance the expressiveness of service, increase their capacity, fine-tune activities, and profit with fee-based services because they host data and apps in the cloud. This lets you improve your analytics, expand your dashboards, and boost your mobile apps to monitor your outputs and generate profit. Rapid advancements in artificial intelligence and cloud computing allow companies to augment themselves with intelligent software, enabling them to derive and interpret insights in data, expedite workflows, and improve business processes and experience. ## How Can Atlantic.Net Help? Atlantic.Net has been working with various clients to deliver affordable and effective AI solutions to maximize their Return on Value (ROV). Atlantic.Net was founded in 1994 by Marty Puranik and a team of business and IT professionals with one vision: to help companies prepare for a new digital age. Atlantic.Net was born in the cloud, and our team empowers AI pioneers in recognizing the role of Big Data and Machine Learning in business. The Atlantic.Net cloud platform is an excellent fit for AI workloads, particularly offsetting data processing to our compute engine. Contact our sales team today to learn more about how [Atlantic.Net](https://www.atlantic.net) can deliver the robust [VPS hosting](https://www.atlantic.net/vps-hosting/) infrastructure required to place your company at the forefront of an AI-intensive industry. --- # List Installed Packages with Pacman on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/list-installed-packages-with-pacman-on-arch-linux/ | Published: 2022-11-19 | Updated: 2024-06-01 | Author: Hitesh Jethva If you are a Linux system administrator, you need a package manager to make your job easier. Pacman is a simple and handy tool that allows you to manage software packages in Arch Linux. With Pacman, you can install, update, remove, and list packages using the command-line interface. This post will show you how to list installed packages with Pacman on Arch Linux. ## Step 1 – Configure the Pacman Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – List Installed Packages Using Pacman You can use the Pacman command with the **-Q** option to list all installed packages on your system. ``` pacman -Q ``` You should see the list of all installed packages in the following output: ``` acl 2.3.1-2 acpid 2.0.34-1 archlinux-keyring 20220927-1 argon2 20190702-4 attr 2.5.1-2 audit 3.0.8-1 autoconf 2.71-1 automake 1.16.5-1 bash 5.1.016-1 binutils 2.39-3 bison 3.8.2-4 brotli 1.0.9-8 bzip2 1.0.8-4 ca-certificates 20220905-1 ca-certificates-mozilla 3.84-1 ca-certificates-utils 20220905-1 chrpath 0.16-3 coreutils 9.1-1 ``` In the above command, you should see two columns. The first column is the name of the installed packages and the second column is the version of the installed packages. If you want to export the list to a file, run the following command: ``` pacman -Q > packages.txt ``` This will create a new file named packages.txt in your current working directory. ## Step 3 – List Only the Later Installed Packages You can also list all packages that are installed later using the Pacman command. To list later installed packages, use the -Qe option: ``` pacman -Qe ``` You should see a list of later installed packages in the following output: ``` acpid 2.0.34-1 autoconf 2.71-1 automake 1.16.5-1 bash 5.1.016-1 binutils 2.39-3 bison 3.8.2-4 bzip2 1.0.8-4 coreutils 9.1-1 cryptsetup 2.5.0-1 debugedit 5.0-4 device-mapper 2.03.16-2 dhcpcd 9.4.1-1 diffutils 3.8-1 e2fsprogs 1.46.5-4 expac 10-5 fakeroot 1.29-1 ``` To list more system packages, run the following command: ``` pacman -Qet ``` You should see the following output: ``` acpid 2.0.34-1 autoconf 2.71-1 automake 1.16.5-1 bison 3.8.2-4 debugedit 5.0-4 expac 10-5 fakeroot 1.29-1 flex 2.6.4-3 gcc 12.2.0-1 grub 2:2.06.r334.g340377470-1 haveged 1.9.18-1 inetutils 2.3-1 iputils 20211215-1 jfsutils 1.1.15-8 licenses 20220125-1 linux 6.0.2.arch1-1 make 4.3-3 man-db 2.11.0-1 man-pages 6.01-1 ``` ## Step 4 – List Only the Installed Package Names By default, the Pacman command generates all installed package lists in two columns. If you want to show only the first column, run the following command: ``` pacman -Q | awk '{print $1}' ``` You will get the following output: ``` acl acpid archlinux-keyring argon2 attr audit autoconf automake bash binutils bison brotli bzip2 ca-certificates ca-certificates-mozilla ca-certificates-utils chrpath coreutils cracklib ``` To export the above list to a file, run the following command: ``` pacman -Q | awk '{print $1}' > package_list.txt ``` ## Conclusion In this post, we explained how to list packages in Arch Linux using the Pacman command. You can now use the Pacman command on [dedicated hosts](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) from Atlantic.Net! --- # How to Install and Configure UFW Firewall on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-ufw-firewall-on-arch-linux/ | Published: 2022-11-20 | Updated: 2024-06-01 | Author: Hitesh Jethva UFW, also called “Uncomplicated Firewall,” is a tool for managing a Netfilter firewall designed to be easy to use. It provides a user-friendly interface compared to other firewall management utilities. With UFW, you can block incoming and outgoing connections to and from the server. You can also block ports, IPs, or even entire subnets using UFW. In this post, we will show you how to install and configure UFW firewall on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install UFW on Arch Linux First, you will need to install the latest kernel to your system. You can install it using the following command: ``` pacman -Sy linux ``` Once installed, you can install the UFW tool with the following command: ``` pacman -Sy ufw ``` ## Step 3 – Enable UFW Firewall Before enabling the UFW firewall, you will need to allow incoming SSH connections to your server. Otherwise, you will lose SSH access to your server. To allow the SSH connection, run the following command: ``` ufw allow ssh/tcp ``` Next, enable the UFW firewall using the following command: ``` systemctl status ufw ufw enable ``` You can now check the status of UFW with the following command: ``` systemctl status ufw ``` You should get the following output: ``` ● ufw.service - CLI Netfilter Manager Loaded: loaded (/usr/lib/systemd/system/ufw.service; enabled; preset: disabled) Active: active (exited) since Fri 2022-10-28 07:50:40 UTC; 4s ago Process: 84145 ExecStart=/usr/lib/ufw/ufw-init start (code=exited, status=0/SUCCESS) Main PID: 84145 (code=exited, status=0/SUCCESS) Oct 28 07:50:40 archlinux systemd[1]: Starting CLI Netfilter Manager... Oct 28 07:50:40 archlinux ufw-init[84149]: Skip starting firewall: ufw (not enabled) Oct 28 07:50:40 archlinux systemd[1]: Finished CLI Netfilter Manager. ``` ## Step 4 – View UFW Application Profile UFW has a built-in application profile that helps you to manage UFW rules easily. You can list all of them using the following command: ``` ufw app list ``` You will get the following output: ``` AIM Bonjour CIFS DNS Deluge IMAP IMAPS IPP KTorrent Kerberos Admin Kerberos Full Kerberos KDC Kerberos Password LDAP LDAPS LPD MSN MSN SSL Mail submission NFS POP3 POP3S PeopleNearby SMTP SSH Socks Telnet Transmission Transparent Proxy VNC WWW WWW Cache WWW Full WWW Secure ``` To see detailed information on specific application profiles, run the following command: ``` ufw app info 'SSH' ``` You should get the following output: ``` Profile: SSH Title: SSH server Description: SSH server Port: 22/tcp ``` ## Step 5 – Allow HTTP and HTTPS Connections Using UFW To allow HTTP connection by application profile, run the following command: ``` ufw allow 'WWW Full' ``` To allow HTTP connection by service, run the following command: ``` ufw allow http ``` To allow HTTP connection by port, run the following command: ``` ufw allow 80/tcp ``` To allow HTTPS connection by application profile, run the following command: ``` ufw allow 'WWW Secure' ``` To allow HTTPS connection by service, run the following command: ``` ufw allow https ``` To allow HTTPS connection by port, run the following command: ``` ufw allow 443/tcp ``` ## Step 6 – Allow Port Range and IP Address Using UFW You can also allow specific port ranges using the UFW firewall. To allow a specific TCP port range, run the following command: ``` ufw allow 6500:6800/tcp ``` To allow a specific UDP port range, run the following command: ``` ufw allow 6500:6800/udp ``` To allow specific IP address, run the following command: ``` ufw allow from 192.168.0.10 ``` To allow a specific IP address on a specific port, run the following command: ``` ufw allow from 192.168.0.10 to any port 8800 ``` To allow a specific subnet, run the following command: ``` ufw deny from 192.168.10.0/24 ``` ## Step 7 – How to Remove UFW Rules To remove the UFW rules, you will need to list the rule numbers first. You can do it with the following command: ``` ufw status numbered ``` Output: ``` Status: active To Action From -- ------ ---- [ 1] 22/tcp ALLOW IN Anywhere [ 2] 22 ALLOW IN Anywhere [ 3] WWW Full ALLOW IN Anywhere [ 4] 80 ALLOW IN Anywhere [ 5] 80/tcp ALLOW IN Anywhere [ 6] WWW Secure ALLOW IN Anywhere [ 7] 443 ALLOW IN Anywhere [ 8] 6500:6800/tcp ALLOW IN Anywhere [ 9] 6500:6800/udp ALLOW IN Anywhere [10] 22/tcp (v6) ALLOW IN Anywhere (v6) [11] 22 (v6) ALLOW IN Anywhere (v6) [12] WWW Full (v6) ALLOW IN Anywhere (v6) [13] 80 (v6) ALLOW IN Anywhere (v6) [14] 80/tcp (v6) ALLOW IN Anywhere (v6) [15] WWW Secure (v6) ALLOW IN Anywhere (v6) [16] 443 (v6) ALLOW IN Anywhere (v6) [17] 6500:6800/tcp (v6) ALLOW IN Anywhere (v6) [18] 6500:6800/udp (v6) ALLOW IN Anywhere (v6) ``` Now, remove the third rule using the following command: ``` ufw delete 3 ``` You will get the following output: ``` Deleting: allow 'WWW Full' Proceed with operation (y|n)? y Rule deleted ``` ## Step 8 – Enable and Disable UFW Logs You can also enable the UFW logging to see the UFW logs. To set the UFW logging to low, run the following command: ``` ufw logging low ``` To set the UFW logging to medium, run the following command: ``` ufw logging medium ``` To set the UFW logging to high, run the following command: ``` ufw logging high ``` To disable the UFW logging, run the following command: ``` ufw logging off ``` ## Step 9 – How to Remove and Disable UFW Firewall To reset all UFW rules, run the following command: ``` ufw reset ``` You will get the following output: ``` Resetting all rules to installed defaults. This may disrupt existing ssh connections. Proceed with operation (y|n)? y ``` To disable the UFW firewall, run the following command: ``` ufw disable ``` To remove the UFW firewall, run the following command: ``` pacman -R ufw ``` ## Conclusion In this post, we explained how to install the UFW firewall on Arch Linux. We also explained how to allow specific ports and services with UFW. You can now easily use the UFW firewall to allow and deny specific ports based on your requirements. Try UFW on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure Wireguard VPN Server on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-wireguard-vpn-server-on-arch-linux/ | Published: 2022-11-21 | Updated: 2024-06-05 | Author: Hitesh Jethva Wireguard is a modern and fast VPN software that supports IPv4 and IPv6 connections. It is faster and simpler compared to other VPN software like IPSec and OpenVPN. It is cross-platform and can be installed on all major operating systems including Linux, macOS, Windows, BSD, and Android. It is a point-to-point VPN server and you can easily deploy it on small devices to high-end servers. In this post, we will show you how to install Wireguard VPN server on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Wireguard VPN Wireguard provides a script that allows you to install it on your system easily. First, download the Wireguard installation script using the following command: ``` pacman -S curl curl -O https://raw.githubusercontent.com/angristan/wireguard-install/master/wireguard-install.sh ``` Next, set executable permissions on the downloaded script: ``` chmod +x wireguard-install.sh ``` Next, run the installation script using the following command: ``` ./wireguard-install.sh ``` Answer all the questions as shown below: ``` Welcome to the WireGuard installer! The git repository is available at: https://github.com/angristan/wireguard-install I need to ask you a few questions before starting the setup. You can leave the default options and just press enter if you are ok with them. IPv4 or IPv6 public address: server-ip Public interface: ens3 WireGuard interface name: wg0 Server's WireGuard IPv4: 10.66.66.1 Server's WireGuard IPv6: fd42:42:42::1 Server's WireGuard port [1-65535]: 54781 First DNS resolver to use for the clients: 94.140.14.14 Second DNS resolver to use for the clients (optional): 94.140.15.15 Okay, that was all I needed. We are ready to setup your WireGuard server now. You will be able to generate a client at the end of the installation. Tell me a name for the client. The name must consist of alphanumeric character. It may also include an underscore or a dash and can't exceed 15 chars. Client name: vpn_client Client's WireGuard IPv4: 10.66.66.2 Client's WireGuard IPv6: fd42:42:42::2 Unable to retrieve current interface configuration: Protocol not supported Here is your client config file as a QR Code: It is also available in /root/wg0-client-vpn_client.conf If you want to add more clients, you simply need to run this script another time! WARNING: WireGuard does not seem to be running. You can check if WireGuard is running with: systemctl status wg-quick@wg0 If you get something like "Cannot find device wg0", please reboot! ``` Once the installation is complete, restart your system to apply the changes: ``` reboot ``` ## Step 3 – Verify Wireguard VPN Next, check the status of Wireguard using the following command: ``` systemctl status wg-quick@wg0 ``` You will get the following output: ``` ● wg-quick@wg0.service - WireGuard via wg-quick(8) for wg0 Loaded: loaded (/usr/lib/systemd/system/wg-quick@.service; enabled; preset: disabled) Active: active (exited) since Fri 2022-10-28 11:04:25 UTC; 3min 13s ago Docs: man:wg-quick(8) man:wg(8) https://www.wireguard.com/ https://www.wireguard.com/quickstart/ https://git.zx2c4.com/wireguard-tools/about/src/man/wg-quick.8 https://git.zx2c4.com/wireguard-tools/about/src/man/wg.8 Process: 249 ExecStart=/usr/bin/wg-quick up wg0 (code=exited, status=0/SUCCESS) Main PID: 249 (code=exited, status=0/SUCCESS) CPU: 73ms Oct 28 11:04:24 archlinux systemd[1]: Starting WireGuard via wg-quick(8) for wg0... Oct 28 11:04:24 archlinux wg-quick[249]: [#] ip link add wg0 type wireguard Oct 28 11:04:25 archlinux wg-quick[249]: [#] wg setconf wg0 /dev/fd/63 Oct 28 11:04:25 archlinux wg-quick[249]: [#] ip -4 address add 10.66.66.1/24 dev wg0 Oct 28 11:04:25 archlinux wg-quick[249]: [#] ip -6 address add fd42:42:42::1/64 dev wg0 Oct 28 11:04:25 archlinux wg-quick[249]: [#] ip link set mtu 1420 up dev wg0 Oct 28 11:04:25 archlinux wg-quick[249]: [#] iptables -A FORWARD -i ens3 -o wg0 -j ACCEPT; iptables -A FORWARD -i wg0 -j ACCEPT; iptables -t > Oct 28 11:04:25 archlinux systemd[1]: Finished WireGuard via wg-quick(8) for wg0. ``` Wireguard VPN creates a new network interface named wg0 on your system. You can check it with the following command: ``` ip a ``` You will get the following output: ``` 4: wg0: mtu 1420 qdisc noqueue state UNKNOWN group default qlen 1000 link/none inet 10.66.66.1/24 scope global wg0 valid_lft forever preferred_lft forever inet6 fd42:42:42::1/64 scope global valid_lft forever preferred_lft forever ``` Wireguard also generates a client configuration file at /root/wg0-client-vpn_client.conf. ## Step 4 – Configure Wireguard Client Next, you will need to install the Wireguard client package on the client machine. You can install it using the following command: ``` pacman -S wireguard-tools ``` After the installation, copy the client configuration file from the Wireguard server machine to the client machine: ``` scp root@server-ip:/root/wg0-client-vpn_client.conf /etc/wireguard/wg0.conf ``` Next, start the Wireguard client with the following command: ``` systemctl start wg-quick@wg0 ``` ## Step 5 – Verify Wireguard VPN Connection Next, go back to your server machine and run the following command to check the client-server connection: ``` wg ``` You should see the following output: ``` interface: wg0 public key: v2N2x3+NE2ZhyMmrJToNchobiFQzrRmDN7xbjt06Ziw= private key: (hidden) listening port: 54781 peer: OydUu+4sdDV2R+H7Ng1l5J7PTIq/cD/GbMdZ3kwNjig= preshared key: (hidden) endpoint: 209.23.10.169:35718 allowed ips: 10.66.66.2/32, fd42:42:42::2/128 latest handshake: 1 minute, 53 seconds ago transfer: 148 B received, 380 B sent ``` ## Conclusion In this post, we explained how to install the Wireguard VPN server on Arch Linux. We also installed and configured the Wireguard client to connect to the server machine. You can now use the Wireguard VPN server to hide your identity. Try Wireguard VPN on [dedicated hosts](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) from Atlantic.Net! --- # How to Make the Best Use of the Cloud in the Internet of Things (IoT) > URL: https://www.atlantic.net/hipaa-compliant-hosting/how-to-make-the-best-use-of-the-cloud-in-the-internet-of-things-iot/ | Published: 2022-11-22 | Updated: 2026-05-30 | Author: Richard Bailey The Internet of Things (IoT) is a giant network of interconnected devices (or things) that collects data and shares the information back to some control center or central location. A ‘thing’ could be anything; most commonly, it is a device embedded with sensors and software to connect and share data over and secure network or the Internet. ## IoT Device Examples and Use Cases IoT devices are everywhere, including consumer devices like home appliances, smart meters, and intelligent devices such as TVs, Amazon Echo, Google Home, and Google Nest. In addition, commercial IoT devices are prevalent as businesses invest in sensors and devices that manage and monitor healthcare devices, transport devices, connected vehicles, and asset tracking. IoT is also widely used within the military, manufacturing, and energy industrial sectors. We are seeing an emergence of Infrastructure IoT as our cities get more intelligent with infrastructure such as smart motorways, traffic light management, and even smart waste management solutions that alert when public trash cans are full. IoT is everywhere, and the devices impact our everyday lives. But the IoT network would not exist without cloud computing, which is a central location to collect and manage the vast amount of data generated by IoT devices. Join us as we discover the best use of the cloud in the Internet of Things (IoT). ## IoT Applications Now that we know what the IoT is, we look at some of the most popular use cases for the IoT in business. IoT can be described as connecting physical devices so they can communicate with each other and be controlled from a remote location. Cloud providers are the perfect hosting environment for intelligent IoT applications that capture and analyze IoT data and helpfully present the data, such as dashboards and reports. IoT applications commonly trigger automated routines when an event criterion is met. For example, when traffic builds up on a smart motorway, a routine will start to slow traffic down further back on the highway. Cloud providers have proprietary event drive serverless tools that execute functions automatically; however, you can also do it using applications like Apache OpenWhisk. Functions unlock the power of IoT by creating automated routines upon data received from the IoT device. In addition, IoT data works well with artificial intelligence and machine learning. ## Popular Use-Cases For IoT IoT has made a real difference worldwide and helped to change our world. **#1: Healthcare:** One such industry to benefit is healthcare and wearable technology. Healthcare has widely welcomed IoT technology, often known as the Internet of Medical Things (IoMT). The technology has several everyday uses; monitoring patients is already common practice, and modern medical equipment transmits test results autonomously around a hospital network. Medical devices such as CT Scanners, X-ray machines, and MRI scanners can be remotely monitored by IoMT, and results are shared between medical practices, patients, and insurance companies using [HIPAA-compliant cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/). The ability to track medical equipment within a hospital empowers the administration to know the exact location of their portable medical equipment on the hospital grounds. Any hardware issues are automatically reported and “dialed home” to an engineer, allowing key workers to visit the site safely and make repairs. **#2: Asset Tracking and Management:** Many businesses have a fleet of vehicles that move products and employees. Asset tracking and asset management allow them to keep track of their vehicles and equipment. For example, Volkswagen released a recall for over 59,000 of the 2017 Beetle to address airbag deployment in the event of a frontal collision. They found that 10,500 airbags failed during testing. This meant that the people driving the Beetles were suddenly at risk of losing control of an expensive piece of equipment, and it was the business that owned the vehicle, or the company, to bear the costs. However, thanks to the IoT, businesses can track the status of their vehicles and equipment online if anyone with internet access wants to. **#3: Remote Monitoring and Maintenance:** This is a substitute for remote video monitoring. Video conferences and remote monitoring were frequently used for this type of monitoring a few years ago, and IoT has replaced them. The Internet of Things (IoT) is the next big thing in business, and it’s already begun to change how we do things. **#4: The Connected Supply Chain:** Businesses can also use the IoT-connected factory solutions to the cloud and manage industrial IoT devices. The cloud software can be populated with different pre-built resources that allow control, such as alerting services and fleet dispatching to machines. An intelligent factory solution reports primary metrics on equipment, including efficiency and telemetry data. With a simple data stream, this generic solution can gather data from multiple devices at different geographical locations. ## Partnering with Atlantic.Net Atlantic.Net engineers have first-hand experience with the complexities of the Internet of Things. Our Managed Services allow you to monitor your entire stack without giving up control. For example, our Atlantic.Net cloud platform will support ultra-fast networking, and our infrastructure is future-proofed as more advanced and faster services are added to our data center regions. If you want a leading managed network hosting provider, look no further than Atlantic.Net. The company has been in the business for over 30 years and can provide multiple networking options to suit companies of all sizes. Furthermore, we also include a complimentary Network Monitoring Solution for our cloud customers. Atlantic.Net is ready to assist you with fast compliance with all certifications, including SOC 2 and SOC 3, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/), and HITECH, with 24x7x365 professional support, system monitoring, and world-class data center infrastructure. To receive your cost-free Architectural Design and Assessment, cost-free Software Technical Design and Assessment, or hourly consulting, call us at 866-618-3282. Contact us today to learn more about our solutions; visit us today! --- # How to Install and Use SQLite on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-sqlite-on-arch-linux/ | Published: 2022-11-23 | Updated: 2023-11-16 | Author: Hitesh Jethva SQLite is a lightweight and cross-platform database engine that is written in C. It is one of the most widely used database systems as it is bundled in mobile and desktop software. It can be installed on multiple operating systems, including Linux, macOS, Android, iOS, and Windows. It offers several useful features, including stable, cross-platform, backward compatibility, small size, precompiled binaries, and more. In this post, we will show you how to install and use SQLite on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install SQLite on Arch Linux By default, the SQLite package is included in the Arch Linux default repository. You can install it using the following command: ``` pacman -S sqlite ``` Once SQLite is installed, you can verify the SQLite version with the following command: ``` sqlite3 --version ``` You should see the following output: ``` 3.39.4 2022-09-29 15:55:41 a29f9949895322123f7c38fbe94c649a9d6e6c9cd0c3b41c96d694552f26alt1 ``` ## Step 3 – Create a Database in SQLite The basic syntax to create a database in SQLite is shown below: ``` sqlite3 database-name ``` For example, to create a database named company.db, run the following command: ``` sqlite3 company.db ``` You will get the following output: ``` SQLite version 3.39.4 2022-09-29 15:55:41 Enter ".help" for usage hints. sqlite> ``` ## Step 4 – Create a Table in SQLite To create a table named employee with some columns, run the following command: ``` CREATE TABLE employee(id integer NOT NULL, name text NOT NULL, employee text NOT NULL, length integer NOT NULL); ``` Next, run the following command to insert some data into the table: ``` INSERT INTO employee VALUES (1, "Hitesh", "Junagadh", 100); INSERT INTO employee VALUES (2, "Jayesh", "Hydrabad", 200); INSERT INTO employee VALUES (3, "Vyom", "Veraval", 300); ``` ## Step 5 – List Data from a Table in SQLite To list the inserted data, run the following command: ``` SELECT * FROM employee; ``` You will get the following output: ``` 1|Hitesh|Junagadh|100 2|Jayesh|Hydrabad|200 3|Vyom|Veraval|300 ``` To list the data based on its id, run the following command: ``` SELECT * FROM employee WHERE id IS 2; ``` You will get the following output: ``` 2|Jayesh|Hydrabad|200 ``` To add a new column named age, run the following command: ``` ALTER TABLE employee ADD COLUMN age integer; ``` Next, to add values to the age column, run the following command: ``` UPDATE employee SET age = 42 WHERE id=1; UPDATE employee SET age = 20 WHERE id=2; UPDATE employee SET age = 40 WHERE id=3; ``` Next, verify all data again using the following command: ``` SELECT * FROM employee; ``` You will get the following command: ``` 1|Hitesh|Junagadh|100|42 2|Jayesh|Hydrabad|200|20 3|Vyom|Veraval|300|40 ``` You can also delete entries in your table based on specific arguments. For example, to delete all entries in a table whose age is less than 40, run the following command: ``` DELETE FROM employee WHERE age <= 40; ``` ## Conclusion In this guide, we explained how to install SQLite on Arch Linux. We also explained how to create a database and a table and insert data in SQLite. You can try SQLite on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) from Atlantic.Net! --- # How to Install and Use PostgreSQL on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-postgresql-on-arch-linux/ | Published: 2022-11-24 | Updated: 2024-04-19 | Author: Hitesh Jethva PostgreSQL is a free, open-source, object-relational database management system used to build fault-tolerant and complex applications. It is very popular among developers due to its reliability, robustness of its features, and performance. PostgreSQL is one of the most popular database systems and is available for most operating systems, including Arch Linux. In this post, we will show you how to install and use PostgreSQL on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install PostgreSQL on Arch Linux By default, the PostgreSQL package is included in the Arch Linux main repository. You can install it using the following command: ``` pacman -S postgresql ``` Once the PostgreSQL is installed, you can verify the PostgreSQL version using the following command: ``` postgres --version ``` You will get the following output: ``` postgres (PostgreSQL) 14.5 ``` Next, initialize the PostgreSQL database with the following command: ``` sudo -u postgres initdb --locale en_US.UTF-8 -D /var/lib/postgres/data ``` ## Step 3 – Manage PostgreSQL Service By default, the PostgreSQL service is managed by systemd. You can start the PostgreSQL service with the following command: ``` systemctl start postgresql ``` To enable the PostgreSQL service to start after the system reboots, run the following command: ``` systemctl enable postgresql ``` To check the status of the PostgreSQL service, run the following command: ``` systemctl status postgresql ``` You should see the following output: ``` ● postgresql.service - PostgreSQL database server Loaded: loaded (/usr/lib/systemd/system/postgresql.service; disabled; preset: disabled) Active: active (running) since Fri 2022-10-28 07:35:27 UTC; 5s ago Process: 83878 ExecStartPre=/usr/bin/postgresql-check-db-dir ${PGROOT}/data (code=exited, status=0/SUCCESS) Main PID: 83880 (postgres) Tasks: 7 (limit: 2362) Memory: 15.7M CGroup: /system.slice/postgresql.service ├─83880 /usr/bin/postgres -D /var/lib/postgres/data ├─83883 "postgres: checkpointer " ├─83884 "postgres: background writer " ├─83885 "postgres: walwriter " ├─83886 "postgres: autovacuum launcher " ├─83887 "postgres: stats collector " └─83888 "postgres: logical replication launcher " ``` ## Step 4 – How to Use PostgreSQL By default, there is not any password for the Postgres user. To set it, log in with the Postgres user and set the password using the following command: ``` su - postgres psql -c "alter user postgres with password 'password'" ``` To create a new database, run the following command: psql CREATE DATABASE mydb; To list all databases, run the following command: ``` \l ``` You should see the following list: ``` List of databases Name | Owner | Encoding | Collate | Ctype | Access privileges -----------+----------+----------+-------------+-------------+----------------------- mydb | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | postgres | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | template0 | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | =c/postgres + | | | | | postgres=CTc/postgres template1 | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | =c/postgres + | | | | | postgres=CTc/postgres (4 rows) ``` To create a new user and set a password, run the following command: ``` CREATE USER user1 WITH ENCRYPTED PASSWORD 'password'; ``` Next, grant all the privileges to the mydb database using the following command: ``` GRANT ALL PRIVILEGES ON DATABASE mydb to user1; ``` To switch the database to mydb, run the following command: ``` \c mydb ``` To exit from the PostgreSQL shell, run the following command: ``` \q exit ``` ## Step 5 – Configure PostgreSQL for Remote Access By default, PostgreSQL is configured for local access only. If your application server and database servers are hosted on a different server, then you will need to configure PostgreSQL for remote access. First, edit the PostgreSQL main configuration file: ``` nano /var/lib/postgres/data/postgresql.conf ``` Change the following line with your server IP address: ``` listen_addresses = 'your-server-ip' ``` Save and close the file, then edit the pg_hba.conf file: ``` nano /var/lib/postgres/data/pg_hba.conf ``` Find the following line: ``` host all all 127.0.0.1/32 trust ``` And replace it with the following line: ``` host all all all trust ``` Save and close the file, then restart the PostgreSQL service to apply the changes: ``` systemctl restart postgresql ``` Next, try to connect your PostgreSQL database using the IP address: ``` psql -U user1 -h server-ip -p 5432 mydb ``` If everything is configured properly, you will get into the following shell: ``` psql (14.5) Type "help" for help. mydb=> ``` ## Conclusion In this post, we explained how to install and use PostgreSQL on Arch Linux. You can now install PostgreSQL in your development environment and use it as a database backend. You can try to install and use PostgreSQL on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Big Changes Planned at VMware As Recent Buyout Plans Threaten to Invalidate Existing Licensed Products > URL: https://www.atlantic.net/dedicated-server-hosting/big-changes-planned-at-vmware-as-recent-buyout-plans-threaten-to-invalidate-existing-licensed-products/ | Published: 2022-11-25 | Updated: 2025-09-15 | Author: Richard Bailey In May 2022, Broadcom semiconductors announced that they were planning to buy VMware in a mega cash and stock deal worth $61 billion. Existing shareholders will receive about $142.50 per share. The agreement was in the final stages of closing and experts expect the deal to fall over the line in Q4 2022. Analysts are concerned that the deal and the plan to revamp the existing license model will drive customers away from a business that has already had to adapt significantly to stay relevant in today’s market conditions. In addition, there are fears that the move to a subscription model will alienate loyal customers embedded in the virtualization ecosystem. ## What Is VMware? VMware Inc, founded in 1998, was the leading pioneer in bringing virtualization technology to the mainstream. VMware has set industry benchmarks for virtualization standards for over 30 years, and its various products are embedded in most data centers across the globe. VMware has created numerous hallmark software products over the years; notable mentions include vSphere, vCenter, vRealize, SRM, NSX, vSAN, Horizon, VMware Cloud, and VMware Workstation. They are still regarded as a global leader despite the mass adoption of cloud computing. They have remained relevant in recent years by embedding VMware with cloud service providers as a dedicated managed platform. Products like vSphere and ESXi still dominate private clouds and on-premise virtualization stacks, but there has been a decline in their usage in the last ten years. Apart from VMware Cloud, most VMware products use perpetual software licenses which remain valid for the product’s lifetime or a fixed number of years as agreed in a reseller’s contract. Users are free to use the VMware product indefinitely. ## VMware Licencing VMware licensing has traditionally been simple, not necessarily cheap, but indeed easy to use. However, there are caveats to the current licensing model, such as that the number of processor sockets installed in the host server(s) and the feature set you received varies on the license type purchased. Dell currently owns VMware, and financial observers have suggested that Dell kept the VMWare operating model in place to keep the company ticking along. On the other hand, Broadcom has a proven track record of running a lean and highly profitable business with a [gross margin of about 70%](https://siliconangle.com/2022/05/27/broadcom-will-tame-vmware-beast/). There is no doubt that Broadcom wants to monetize VMware; it plans to do this by investing heavily in its core products, such as vCenter and vSphere, and will likely look at VMware Cloud on AWS as that service is growing at 40%. In addition, they will focus R&D spending on developing products, so niche products like Horizon and SRM could potentially divest and be dropped. There is no doubt that Broadcom is an efficient, highly profitable business. However, the news of changing the licensing model has spooked customers. Broadcom CEO Hock Tan has even said they expect to lose customers in the short term, and customers are worried the takeover will stall innovation and increase costs across the board. ## What Is the Expected Impact on Customers? The impact will depend on several factors, such as how many years remain on your existing VMware contract and how embedded the business is in the VMware ecosystem. Gartner, a consultancy business with a solid reputation for advising business decisions, has much to say about the acquisition. Gartner recommends that VMware users “Identify exit ramps for deployed products, including alternative solutions and migration activities.” This should include immediate negotiations on contract extensions to lock into a predictable fixed-term contract. Also, consider your business’s exit strategy from VMware; this could be by accelerating your cloud migration strategy or outsourcing your server hardware to a managed service provider. Either way now is the time to draw up a contingency plan before making new or additional financial commitments to VMware products. Gartner recommends the following strategy: - **Create a baseline:** Inventory all existing VMware products, contracts, and licenses. This step will determine the effects of license model changes on your business and the impact of expected product roadmap changes. - **Roadmap commitments:** During negotiations, ensure that VMware commits to a technical roadmap of your products. This is particularly important for products outside of vSphere, NSX and vSAN. - **Price negotiation:** Negotiate exit clauses in new multiyear contracts. Negotiate price caps on subscription VMware license fees. Price caps should be within 1% to 2% of a standard metric such as the consumer price index. - **Contingency planning:** Identify exit ramps for deployed products, including alternative solutions and migration activities, should the situation become untenable. ## Is It Time to Ditch VMWare? Customers are in a real predicament with VMware, and the Broadcom acquisition has forced the hand of many users to consider seriously if now is the time to double down on VMware or look for alternatives in the market. The good news is that migrating away from VMware is relatively straightforward. Managed services providers like Atlantic.Net can quickly lift and shift entire environments into the cloud. Established in 1994, Atlantic.Net is a market-leading cloud infrastructure service provider founded in Orlando, Florida. We have grown rapidly over the last 30 years and today offer various cloud services at our eight state-of-the-art data centers based in New York, London, Toronto, San Francisco, Dallas, Ashburn, and Orlando. Atlantic.Net’s [experienced migration specialists](https://www.atlantic.net/resources/documents/brochures/pdf/migration-services-atlantic-net-brochure.pdf) have helped countless customers with their vision. As a result, our cloud platform has grown exponentially over the last decade, and we have received many accolades. We offer a variety of [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) and VPS hosting products and have designed a class-leading service wraparound that simplifies migration. We will be involved as much as you need. --- # How to Use Pacman in Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-use-pacman-in-arch-linux/ | Published: 2022-11-26 | Updated: 2024-04-19 | Author: Hitesh Jethva The package manager is a key part of any Linux-based operating system. It is used to install and manage software packages on your system. Pacman is the default package manager for Arch-based Linux distributions. It provides an easier way to install, remove and update software packages to your system. Pacman uses simple compressed files as a package format and maintains a text-based package database. In this post, we will show you how to use Pacman to manage packages on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install a Package with Pacman The basic syntax to install any package on Arch Linux is shown below: ``` pacman -S package-name ``` For example, to install the Nginx pack ``` age, run the following command: ``` ``` pacman -S nginx ``` You can also install multiple packages using the single Pacman command. For example, to install multiple packages unzip. curl and wget, run the following command: ``` pacman -S unzip curl wget ``` ## Step 3 – Remove a Package with Pacman The basic syntax to remove a package in Arch Linux is shown below: ``` pacman -R package-name ``` For example, to remove a package named unzip, run the following command: ``` pacman -R unzip ``` If you want to remove the dependencies along with the package, use the -s option with the Pacman command: ``` pacman -Rs package-name ``` If your specified package acts as a dependency of another package, you can use the -c option to remove both packages: ``` pacman -Rsc package-name ``` If you remove a package using the Pacman command, it will create a backup of all configuration files associated with that package. You can remove packages without backing up config files, use the -n option: ``` pacman -Rns package-name ``` ## Step 4 – Download a Package Using Pacman You can use the -Sw option to download any package without installing it on your system. ``` pacman -Sw package-name ``` For example, to download the Nginx package, run the following command: ``` pacman -Sw nginx ``` You should get the following output: ``` resolving dependencies... Packages (4) geoip-1.6.12-2 geoip-database-20220823-1 mailcap-2.1.53-1 nginx-1.22.0-2 Total Download Size: 2.75 MiB :: Proceed with download? [Y/n] y :: Retrieving packages... geoip-database-20220823-1-any 2.1 MiB 5.17 MiB/s 00:00 [#################################################] 100% nginx-1.22.0-2-x86_64 585.8 KiB 7.15 MiB/s 00:00 [#################################################] 100% geoip-1.6.12-2-x86_64 86.9 KiB 1609 KiB/s 00:00 [#################################################] 100% mailcap-2.1.53-1-any 29.5 KiB 590 KiB/s 00:00 [#################################################] 100% Total (4/4) 2.8 MiB 3.29 MiB/s 00:01 [#################################################] 100% (4/4) checking keys in keyring [#################################################] 100% (4/4) checking package integrity [#################################################] 100% ``` ## Step 5 – Search for a Package Using Pacman Pacman provides a search capability that allows you to search for packages in the local database. The basic syntax to search for any available package is shown below: ``` pacman -Ss query ``` For example, to search for a package named Docker, run the following command: ``` pacman -Ss docker ``` You should get the following list: ``` community/bashbrew 0.1.1-2 Canonical build tool for Docker official images community/container-diff 0.17.0-2 Diff your Docker containers community/docker 1:20.10.18-1 community/docker-buildx 0.9.1-1 Pack, ship and run any application as a lightweight container Docker CLI plugin for extended build capabilities with BuildKit community/docker-compose 2.11.2-1 Fast, isolated development environments using Docker community/docker-machine 0.16.2-5 Machine management for a container-centric world community/docker-scan 0.20.0-1 Docker Scan is a Command Line Interface to run vulnerability detection on your Dockerfiles and Docker images community/drone-runner-docker 1.8.2-1 Drone pipeline runner that executes builds inside Docker containers community/kompose 1.26.0-2 Docker compose to Kubernetes transformation tool community/molecule-docker 2.1.0-1 Molecule Docker Driver ``` To search for a package already installed on your system, use the -Qs option: ``` pacman -Qs wget ``` You should see the following output: ``` local/wget 1.21.3-1 Network utility to retrieve files from the Web ``` To list orphaned packages, run the following command: ``` pacman -Qdt ``` To find more information about any package, run the following command: ``` pacman -Si nginx ``` You will get the following output: ``` Repository : extra Name : nginx Version : 1.22.0-2 Description : Lightweight HTTP server and IMAP/POP3 proxy server Architecture : x86_64 URL : https://nginx.org Licenses : custom Groups : None Provides : None Depends On : pcre2 zlib openssl geoip mailcap libxcrypt Optional Deps : None Conflicts With : None Replaces : None Download Size : 585.77 KiB Installed Size : 1693.74 KiB Packager : Giancarlo Razzolini Build Date : Fri 10 Jun 2022 01:45:12 PM UTC Validated By : MD5 Sum SHA-256 Sum Signature ``` ## Step 6 – Clean Package Cache When you install a package using the Pacman command, it doesn’t remove the downloaded files. In this case, you can keep the cache files of currently installed packages and remove the rest using the following command: ``` pacman -Sc ``` You will get the following output: ``` Packages to keep: All locally installed packages Cache directory: /var/cache/pacman/pkg/ :: Do you want to remove all other packages from cache? [Y/n] Y ``` To remove unwanted dependencies, run the following command: ``` pacman -Rns $(pacman -Qdt) ``` ## Conclusion In this post, we explained how to manage packages with Pacman package manager on Arch Linux. This will help you to manage packages easily on Arch Linux. You can choose one of our [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! to use the Pacman. --- # HIPAA Compliance for Remote Workers: How to Maintain HIPAA Compliance with a Remote Team > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-for-remote-workers-how-to-maintain-hipaa-compliance-with-a-remote-team/ | Published: 2022-11-28 | Updated: 2025-09-15 | Author: Richard Bailey Remote working has become the new normal since the COVID-19 pandemic changed everyone’s lives in March 2020. Are you a healthcare business based in the United States with employees who work remotely? If so, you must be aware of remote employees’ HIPAA compliance requirements. HIPAA, or the Health Insurance Portability and Accountability Act, is a set of federal regulations that protect the privacy of patients’ healthcare information. Businesses dealing with protected health information (PHI) [must comply with HIPAA regulations at all times](https://www.atlantic.net/vps-hosting/how-can-remote-working-and-business-continuity-planning-mitigate-the-impact-of-the-covid-19-coronavirus/), and HIPAA also applies to remote workers. If your remote employees access PHI, you must ensure that they are HIPAA compliant. This includes implementing security measures to protect PHI, training employees to safeguard PHI, and establishing policies and procedures for handling PHI. In this article, we’ll explain the HIPAA compliance requirements for remote employees and provide tips for ensuring that your remote employees are HIPAA compliant. ## How Delivering Healthcare Services Has Changed The delivery of front-line healthcare services has changed dramatically in the past two years. However, many of these services have remained ‘remotely delivered’ as we slowly embrace the post-COVID dynamic. The [great remote working experiment](https://www.forbes.com/sites/forbestechcouncil/2020/12/11/why-has-the-great-work-from-home-experiment-been-so-successful/) has proved successful, and many patients are happy with the rapid delivery of remote services. As your employees work remotely, you may rely more on them to access PHI more frequently. Therefore, healthcare leaders must ensure that each employee understands how to handle PHI in a compliant manner and that your company has the technical ability to abide by the complex HIPAA regulations. Employees who collaborate electronically will require specialist equipment, data clearance, and training. In addition, four groups of individuals must comply with HIPAA regulations: remote employees, support personnel who access PHI, physicians, and other “covered entities” that handle or process Protected Health Information, such as [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) companies that support your operations. ## Steps to Protect PHI With a Remote Team Protected health information is any data held in electronic form that identifies the patient. Typical examples include the patient’s names, addresses, former names, social security numbers, dates of birth, and driver’s license information. PHI also includes information regarding treatment plans, test results, and insurance details. The first and most crucial requirement is to complete a risk assessment, a formal process that identifies all PHI touchpoints within the business. The evaluation is a complex review of all IT systems that handle PHI. The aim is to understand and document how PHI is processed, accessed, and processed. The risk assessment creates a baseline the healthcare organization uses to achieve and maintain compliance. The healthcare organization must identify who the remote workers will be, and to facilitate remote working, must provide secure laptops and remote network access (typically a secure and encrypted VPN). Endpoint protection applies to any remote device, including cell phones, tablets, or medical equipment. The minimum standards needed are AES256 encryption of all hard drives and encrypted network access. All endpoints require managed user access controls with multi-factor authentication. Additional security measures may include automatic screen locks and a remotely managed kill switch to wipe the data remotely if a laptop is stolen. The same rules apply to external media, such as flash or hard drives. When not in use, the media must be locked away, and the data must be professionally destroyed following task completion. ## Improve Your Security Posture by Outsourcing Critical IT Services to a HIPAA-Compliant Hosting Provider Outsourcing critical IT services to a dedicated [HIPAA-certified provider](https://www.atlantic.net/hipaa-compliant-hosting/) is a great way to solve most of the headaches of achieving HIPAA compliance standards. Choose a provider that will sign a business associate agreement (BAA), a contract that guarantees data integrity and minimum service levels. Choose a provider that will securely host IT equipment. HIPAA demands a secured, monitored environment with strict access controls to servers. An environmentally controlled and secure data center is a much better location for IT systems than an unsecured room within hospital grounds. A hosting provider can offer multiple choices of VPN and can advise how to harden the network further. Any remote worker network equipment should have the default passwords changed. When using WIFI, use a minimum security standard of WPA2-AES to prevent network sniffing. ## How Workers Can Help Remain Compliant Remote workers should adhere to a paperless office environment and only print ePHI if necessary. Any printouts must be destroyed, and medical files must be locked in secured storage. Although employees can bring their own devices (BYOD), it is not recommended. All laptops require antivirus enabled and an enforced patching policy the user cannot override. If a remote device is lost or stolen, the user must report the theft immediately, and it may be possible to recover the device using remote tracking. Ensure that your employees only use HIPAA-approved applications. We have compiled our[top 10 HIPAA-Compliant applications](https://www.atlantic.net/hipaa-compliant-hosting/top-10-best-hipaa-compliant-practice-management-software/), including some of the leading [VOIP solutions](https://www.atlantic.net/hipaa-compliant-hosting/top-10-best-hipaa-compliant-voip-providers/), HIPAA [Chat Software](https://www.atlantic.net/hipaa-compliant-hosting/top-hipaa-compliant-chat-applications-in-2021/),  [CRM](https://www.atlantic.net/hipaa-compliant-hosting/top-5-hipaa-compliant-crm-software-tools/) platforms, and [Web Conference](https://www.atlantic.net/hipaa-compliant-hosting/top-10-hipaa-web-conference-software-companies/) software companies. Another essential factor to consider is restricting access to PHI. Deny access to PHI by default except for authorized employees. In-house applications require access controls and detailed auditing that monitors PHI and creates logging when PHI is accessed, changed, or deleted. ## Choose Atlantic.Net for all your HIPAA hosting requirements. Eliminating risk is vital to HIPAA compliance, especially when implementing remote working conditions. Choose a cloud hosting provider audited to the exacting standards of HIPAA compliance. This ensures a compliant hosting environment and a physical data center that complies with the necessary privacy and security safeguards. Only consider a provider that ensures a highly redundant (fail-safe) platform with features such as enhanced cooling and redundancy generators. Certifications are the best way to determine the provider’s HIPAA credentials. Look for the HIPAA Audited certification. [Certification validates](https://www.atlantic.net/compliance-hosting/) the provider hosting solutions, support teams, and business processes are fully compliant with HIPAA standards. In addition, HITECH takes compliance to the next level with standards for the privacy and security of confidential Electronic Health Record (EHR) data. Other measures like SOC 2 and SOC 3 certifications can further boost the provider’s credentials. --- # BAA Red Flags: What Should Your HIPAA-Compliant Hosting Company Be Willing to Accommodate? > URL: https://www.atlantic.net/hipaa-compliant-hosting/baa-red-flags-what-should-your-hipaa-compliant-hosting-company-be-willing-to-accommodate/ | Published: 2022-11-29 | Updated: 2025-09-15 | Author: Richard Bailey The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a complex set of privacy and security regulations created to protect all types of electronic health information. HIPAA clarifies what information should be protected and who should be allowed to see that information. The U.S. Department of Health and Human Services enforces the regulations. The rules of HIPAA compliance bind all healthcare entities and business associates in the United States, and all are subject to enforceable privacy laws. Protecting the privacy and security of patient data is a critical part of HIPAA compliance. But even organizations that take all the necessary precautions can sometimes run into trouble. Some of the most common red flags can indicate a potential future HIPAA violation. This article will help you to identify specific areas of concern, and we will learn what your HIPAA-compliant hosting company must do to remain compliant. ## HIPAA Compliance: Does It Appear That Something Is Off with Your Hosting Provider? It is now standard for any healthcare organization to use electronic files to store, transmit, and securely unify healthcare data. For example, prescription data, diagnostic tests, test results, and other clinical data are stored, processed, and incorporated into electronic files. Failing to implement HIPAA compliance measures can cause an organization to be at risk of violating HIPAA. As a result, healthcare providers choose to outsource core IT services to [HIPAA hosting](https://www.atlantic.net/hipaa-compliant-hosting/) companies to solve the many complexities of adhering to the physical, administrative, and technical safeguards of HIPAA compliance. Choosing the best HIPAA hosting company is essential to avoid breaching regulations and to reduce the risk of exposing protected health information. However, not all hosting providers are the same. Here are some of the common mistakes made. - **Lack of Employee Training:** The hosting providers must have a team of highly trained experts that understand the rules and complexities of HIPAA compliance. Engineers must be security cleared and understand the rules of working in environments that process Protected Health Information. In addition, employees must understand basic concepts of the Security and Privacy rules and what constitutes a compliance breach. - **Poor Security Measures:** The hosting provider must follow security best practices and ensure HIPAA compliance. The physical security of the hosting provider must be robust and follow administrative controls. Choosing a hosting provider with proven accreditations will guarantee PHI security. Look for a business partner who is HIPAA compliance audited and has HITECH accreditation, SOC2, and SOC3 certification. - **Failure to Sign a Business Associate Agreement:** Failing to enter a BAA with a hosting provider correctly is a common HIPAA violation. The BAA is a joint responsibility of the Business Associate and the Covered Entity. A BAA is often tedious, dense, and technical, but it’s essential from a legal and business perspective. It documents the requirements to uphold the integrity of PHI and includes details regarding service agreements. - **Improper Disposal of PHI:** There are strict rules governing the destruction of PHI. There are times when PHI must be deleted, for example, when data retention periods expire, and the data must be removed. From the business associate’s perspective, they are responsible for the secure shredding of electronic equipment such as failed hard drives, broken servers, and various forms of digital media. In addition, HIPAA requires the certified destruction of protected health information. - **No Additional BAA with Subcontractors (BASA):** Many suppliers are not directly given PHI to perform duties on behalf of the covered entity, but ePHI still passes through their systems and databases. The process is known as the chain of custody, and all business associates must sign a Business Associate Subcontractor Agreement wherever there are PHI touchpoints. This is a tricky process to get right because many subcontractors do not require a BAA, and a scatter-gunning BAA is equally frowned upon. ## What You Should Expect from Your Hosting Provider Outsourcing healthcare IT systems to a HIPAA hosting provider solves many of the headaches in achieving HIPAA compliance. Atlantic.Net has over 30 years of experience providing first-class IT solutions. As a result, we excel in HIPAA compliance hosting, and many small, medium, and large healthcare organizations trust us daily to uphold the integrity of PHI and provide class-leading cloud services. Here are some of the ways Atlantic.Net can help protect your Healthcare IT systems: - **Data and Network Encryption:** Encrypt any ePHI to meet NIST cryptographic standards at rest and any time it is transmitted over an external network. - **Web Application Firewall:** Protect against 0-day exploits with a robust WAF. - **Upgrades and Patching Hardware:** As a hosting provider, Atlantic.Net manage all the underlying hardware, patching and upgrading regularly. - **Control Access:** Each user is assigned a centrally-controlled unique username, password, and multi-factor authentication to access the systems. - **Manage Risk:** Undertake a risk assessment at regular intervals and implement measures to reduce risks. - **Backups:** We provide a robust and tested backup system - **Disaster Recovery**: We provide the technical solution to ensure that systems containing PHI are available 100% of the time. - **Business Associate Agreement:** Atlantic.Net can sign the BAA. ## Want to Know More? Do you need an infrastructure that can protect your organization’s health data? At Atlantic.Net, whatever your technical requirements, we can offer a top-grade [HIPAA-Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solution. Get a [HIPAA-Compliant Server Cost](https://www.atlantic.net/hipaa-compliant-hosting/) from one of our experts. **[Get a free consultation today!](https://www.atlantic.net/hipaa-compliant-hosting/#GetStarted)** --- # How to Setup SSH Key-based Authentication on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-setup-ssh-key-based-authentication-on-arch-linux/ | Published: 2022-11-30 | Updated: 2024-06-02 | Author: Hitesh Jethva SSH is an open-source and Secure Shell protocol used to connect to a remote Linux server and manage it via the command line. It helps a system and network administrator to manage Linux servers from a remote location. You can also use it to transfer files between multiple Linux servers. You can connect to the removed SSH server using two methods, using password authentication and key-based authentication. Key-based authentication is more secure than a password because only a user with a valid key can log in to Linux. In this post, we will show you how to install SSH and set up SSH key-based authentication on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list if you have not done so already. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Generate an SSH Key First, you will need to generate an SSH key pair on the Linux system where you are working. You can generate it using the following command: ``` ssh-keygen -t rsa ``` You will be asked to specify the location to store the key as shown below: ``` Enter file in which to save the key (/home/user/.ssh/id_rsa): ``` Just press Enter and accept the default path. You will be asked to set a passphrase as shown below: ``` Enter passphrase (empty for no passphrase): Enter same passphrase again: ``` Just press Enter without providing any passphrase. You should see the following output: ``` Your identification has been saved in /home/user/.ssh/id_rsa. Your public key has been saved in /home/user/.ssh/id_rsa.pub. The key fingerprint is: ec:50:43:d9:39:64:f8:19:63:18:ab:1c:e4:ea:f5:e7 user@newpc The key's randomart image is: +--[ RSA 2048]----+ | . oBo. | | o .+oB | | o +o = | | o = .o | | . = S | | . . + | | . o . | | o | | E | +-----------------+ ``` Now, verify your SSH key using the following command: ``` ls -la ~/.ssh/id_*.pub ``` You should see the following output: ``` -rw-r--r-- 1 user user 392 Sep 8 14:34 /home/user/.ssh/id_rsa.pub ``` ## Step 3 – Copy SSH Public Key to Remote Server Now, you will need to copy your public key to the remote Linux server. You can do it using the ssh-copy-id command: ``` ssh-copy-id root@remote-server-ip ``` You will be asked to provide a root password of a remote server to copy a public key: ``` root@remote-server-ip's password: Number of key(s) added: 1 Now try logging into the machine, with: "ssh 'root@remote-server-ip'" and check to make sure that only the key(s) you wanted were added. ``` ## Step 4 – Connect Remote Server without Password At this point, the SSH key is generated and copied to the remote server. You can now connect to the remote server without providing a password: ``` ssh root@remote-server-ip ``` Once you are connected, you should see the following output: ``` Welcome to archlinux (GNU/Linux 5.4.0-29-generic x86_64) * Documentation: https://help.archlinux.com * Management: https://landscape.canonical.com * Support: https://archlinux.com/advantage Last login: Wed Sep 8 07:50:27 2022 from 10.10.20.203 root@archlinux:~# ``` ## Step 5 – Remove Password-based Authentication At this, SSH key-based authentication is configured successfully. Now, it is recommended to disable the use of password authentication so that everyone uses only keys to access the server. On the remote Linux server, edit the SSH main configuration file: ``` nano /etc/ssh/sshd_config ``` Uncomment and change the following line: ``` PasswordAuthentication no ``` Save and close the file, then restart the SSH service to apply the changes: ``` systemctl restart ssh ``` ## Conclusion In the above post, we explained how to set up SSH key-based authentication on Arch Linux. You can now implement SSH key-based authentication for each server that you want to manage remotely. You can choose one of our [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! to test the SSH. --- # How to Install and Use PIP Package Manager on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-pip-package-manager-on-arch-linux/ | Published: 2022-12-02 | Updated: 2024-06-05 | Author: Hitesh Jethva Python is a free, open-source, powerful programming language widely used by developers. PIP, a “Preferred Installer Program,” is a package manager for installing and managing additional Python packages via the command line. PIP makes your job easier by managing complete lists of packages and corresponding version numbers. PIP is a package manager that connects to the Python Package Index and allows users to install user-defined projects locally using a setup.py file. This post will explain how to install and use PIP on Arch Linux. ## Step 1 – Configure Pacman Repo By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install PIP on Arch Linux Before installing PIP, Python must be installed on your server. If not installed, you can install it by running the following command: ``` pacman -S python ``` After the installation, you can verify the Python version using the following command: ``` python --version ``` You should get output similar to: ``` Python 3.10.8 ``` Next, install PIP using the following command: ``` pacman -S python-pip ``` Once PIP is installed, you can verify the installed version of PIP using the following command: ``` pip3 --version ``` You should get output similar to: ``` pip 22.2.2 from /usr/lib/python3.10/site-packages/pip (python 3.10) ``` ## Step 3 – How to Update PIP It is a good idea to update PIP to the latest version. You can update it using the following command: ``` pip3 install --upgrade pip ``` You should see the following output: ``` Requirement already satisfied: pip in /usr/lib/python3.10/site-packages (22.2.2) ``` You can now verify the PIP version again using the following command: ``` pip3 --version ``` You should get output similar to: ``` pip 22.2.2 from /usr/lib/python3.10/site-packages/pip (python 3.10) ``` ## Step 4 – How to Use PIP You can use the –help option to see a list of all essential options available with PIP: ``` pip3 --help ``` You should see the following output: ``` Usage: pip3 [options] Commands: install Install packages. download Download packages. uninstall Uninstall packages. freeze Output installed packages in requirements format. list List installed packages. show Show information about installed packages. check Verify installed packages have compatible dependencies. config Manage local and global configuration. search Search PyPI for packages. cache Inspect and manage pip's wheel cache. wheel Build wheels from your requirements. hash Compute hashes of package archives. completion A helper command used for command completion. debug Show information useful for debugging. help Show help for commands. ``` To install a specific package, run the following command: ``` pip3 install wheel ``` To get detailed information about the installed package, run the following command: ``` pip3 show wheel ``` You will get the following output: ``` Name: wheel Version: 0.37.1 Summary: A built-package format for Python Home-page: https://github.com/pypa/wheel Author: Daniel Holth Author-email: dholth@fastmail.fm License: MIT Location: /usr/lib/python3.10/site-packages Requires: Required-by: ``` To get a list of all installed packages, run the following command: ``` pip3 list ``` You should get output similar to: ``` Package Version ------- ------- pip 22.2.2 wheel 0.37.1 ``` To get a list of all outdated packages, run the following command: ``` pip3 list --outdated ``` To uninstall a specific package from your system, run the following command: ``` pip3 uninstall wheel ``` You will get the following output: ``` Found existing installation: wheel 0.37.1 Uninstalling wheel-0.37.1: Would remove: /usr/bin/wheel /usr/lib/python3.10/site-packages/wheel-0.37.1.dist-info/* /usr/lib/python3.10/site-packages/wheel/* Proceed (Y/n)? y Successfully uninstalled wheel-0.37.1 ``` ## Conclusion In the above post, you learned how to install and use the PIP package manager on Arch Linux. You also learned how to manage Python packages with PIP. You can now use  PIP to execute the Python dependencies. Try it on a [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install PHP on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-php-on-arch-linux/ | Published: 2022-12-04 | Updated: 2024-04-19 | Author: Hitesh Jethva PHP is an acronym for “PHP: Hypertext Preprocessor”. It is a widely-used, open-source scripting language used to develop Static websites or Dynamic websites or Web applications. With PHP, you can manage dynamic content, databases, session tracking, and more. It is an interpreted language means you don’t need compilation. In this post, we will show you how to install PHP on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Add PHP Repository By default, Arch Linux provides PHP version 8.0 in the default repository, so if you want to install multiple PHP versions then you will need to add the PHP repository to your server. To add the PHP repository, edit the Pacman configuration file: ``` nano /etc/pacman.conf ``` Add the following lines: ``` [home_el_archphp_Arch] Server = https://download.opensuse.org/repositories/home:/el:/archphp/Arch/$arch ``` Save and close the file, then run the following command to store the PHP key and fingerprint variables: ``` key=$(curl -fsSL https://download.opensuse.org/repositories/home:el:archphp/Arch/$(uname -m)/home_el_archphp_Arch.key) fingerprint=$(gpg --quiet --with-colons --import-options show-only --import --fingerprint <<< "${key}" | awk -F: '$1 == "fpr" { print $10 }') ``` Next, initialize the key with the following command: ``` pacman-key --init ``` Next, add the key and fingerprint with the following command: ``` pacman-key --add - <<< "${key}" pacman-key --lsign-key "${fingerprint}" ``` Finally, update the repository with the following command: ``` pacman -Syy ``` You will get the following output: ``` :: Synchronizing package databases... core 156.8 KiB 2.89 MiB/s 00:00 [#################################################] 100% extra 1719.6 KiB 56.0 MiB/s 00:00 [#################################################] 100% community 7.0 MiB 62.1 MiB/s 00:00 [#################################################] 100% home_el_archphp_Arch 367.3 KiB 311 KiB/s 00:01 [#################################################] 100% ``` ## Step 3 – Install PHP 7.3 To install PHP version 7.3, run the following command: ``` pacman -Ss php73 ``` After the installation, verify the PHP version using the following command: ``` php73 --version ``` You will get the following output: ``` PHP 7.3.33 (cli) (built: Oct 7 2022 16:41:34) ( NTS ) Copyright (c) 1997-2018 The PHP Group Zend Engine v3.3.33, Copyright (c) 1998-2018 Zend Technologies with Zend OPcache v7.3.33, Copyright (c) 1999-2018, by Zend Technologies ``` ## Step 4 – Install PHP 7.4 If you want to install PHP version 7.4, run the following command: ``` pacman -S php7 ``` After the installation, verify the PHP version using the following command: ``` php7 --version ``` You will get the following output: ``` PHP 7.4.30 (cli) (built: Jul 9 2022 06:35:35) ( NTS ) Copyright (c) The PHP Group Zend Engine v3.4.0, Copyright (c) Zend Technologies ``` ## Step 5 – Install PHP 8.0 You can also install PHP version 8.0 by running the following command: ``` pacman -S php ``` After the successful installation, verify the PHP installation using the following command: ``` php --version ``` You should see the following output: ``` PHP 8.1.11 (cli) (built: Sep 29 2022 16:31:09) (NTS) Copyright (c) The PHP Group Zend Engine v4.1.11, Copyright (c) Zend Technologies ``` ## Conclusion In this post, we explained how to install different PHP versions on Arch Linux. You can now easily install your preferred PHP version as per your requirement. You can choose one of our [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! to test the PHP installation. --- # Maui Ransomware And Healthcare Organizations – How Can You Protect Yourself? > URL: https://www.atlantic.net/hipaa-compliant-hosting/maui-ransomware-and-healthcare-organizations-how-can-you-protect-yourself/ | Published: 2022-12-05 | Updated: 2026-06-04 | Author: Richard Bailey Maui ransomware has targeted healthcare and public health organizations since May 2021. Both the Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) have warned that [state-sponsored cybercriminals](https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-187a) have been using Maui to target U.S. healthcare organizations with increased frequency. The CISA encourages victims to report any suspected incidents of Maui ransomware and never to pay the ransom under any circumstances. According to the FBI, hackers are targeting healthcare organizations because they’re soft targets that are more likely to pay the ransom. After all, these organizations provide services critical to human life and health, and it’s in their best interest to quickly get essential IT systems back up and running. Join us as we discover what Maui ransomware is, and learn what you can do to defend yourself from Maui. Atlantic.Net provides world-class [HIPAA-compliant hosting services](https://www.atlantic.net/hipaa-compliant-hosting/) to healthcare businesses. We know the everyday risks U.S. healthcare companies face from hackers, and our HIPAA hosting services will protect your environment to the highest standards. ## What Is Maui Ransomware? Maui may not have been grabbing the headlines in recent months. However, it is still a severe threat to U.S. healthcare. Although the primary attack vector is unknown, it is understood that Maui is manually executed, and even the targeted files appear to be manually chosen. As with all ransomware, the purpose of Maui is to encrypt sensitive files using unbreakable encryption, then demand a ransom payment (usually in bitcoin) from the victim before the “unlock’ key is given. Strangely, there is no ransomware note left by the hackers on a compromised server. Maui uses a three-layer encryption technique; Advanced Encryption Standard (AES), Rivest–Shamir–Adleman (RSA), and XOR encryption are used to encrypt target files; each file has a different encryption key. RSA encryption is used to encrypt the AES Key, and XOR encryption is used to encrypt the RSA public key. Each XOR is unique because its generated from hard drive information (\\.\PhysicalDrive0). As a result, breaking the encryption is impossible. ## Who Is Behind Maui Ransomware? Several reports have surfaced that suggest the hacking group behind Maui is [Andariel](https://www.bleepingcomputer.com/news/security/maui-ransomware-operation-linked-to-north-korean-andariel-hackers/), a well-known group that usually targets South Korean companies in media, construction, manufacturing, and network services. In addition, it is believed they perform espionage, data theft, data wiping, and operations to raise revenues for state actors. The U.S. State Department sees Andariel as a severe threat to national security. They have even included the hacking group on a [$10 million reward program](https://rewardsforjustice.net/rewards/foreign-malicious-cyber-activity-against-u-s-critical-infrastructure/) for information leading to the arrest of the hackers. ## Why Is Healthcare Being Targeted? U.S. healthcare is a financially lucrative industry that’s often perceived to have limited security capabilities. Healthcare organizations hold detailed sensitive information on patients, which is highly prized by cybercriminals. In addition, Healthcare is a fast-paced industry, and hackers believe they are more likely to pay the ransom to get systems back up and running. Maui has targeted electronic healthcare records (EHR), diagnostics services, imaging services, and intranet platforms. As a result, victims have reported prolonged outages due to Maul. ## What Is the Impact of Maui Ransomware? Due to Maui’s manual execution, the hackers target the most critical assets on the victim’s network. The number of healthcare institutions targeted by Maui is unknown, but at least $500,000 was recovered by the [U.S. Department of Justice](https://www.justice.gov/opa/pr/justice-department-seizes-and-forfeits-approximately-500000-north-korean-ransomware-actors) in one major incident. One known victim is the District of Kansas Medical Center, who paid approximately $100,000 in Bitcoin to regain access to file servers offline for over a week due to Maui. ## How Can You Protect Yourself? The FBI, CISA, and the U.S. Treasury have urged healthcare organizations to take immediate action to reduce the risk of Maui ransomware. One of the best ways to meet this expectation is to make sure best security practices are adopted, and a compliant hosting platform like Atlantic.Net is utilized. This can significantly help to reduce the impact of ransomware and other malware attacks. How to reduce the risk of ransomware: - **Encrypt Network Traffic** – Limit access to IT systems by using multifactor PKI authentication and digital certificates to protect data transfer from healthcare networks, IoT medical devices, and electronic medical records. - **Enforce Strict Access Controls** – Segregate all user access and follow the principle of least privilege. For example, disable pure admin accounts and deploy read-only access as standard. - **Disabled Unnecessary OS Features** – Operating Systems should be built to be lean and only include the required applications to function. Containers make this process super simple, but if you are still using traditional servers – disable services like Telnet, SSH, and HTTP by default. - **Secure Protected Health Information** – Encrypt PHI at rest and in transit using TLS or TPS. Protect the PHI platform with firewalls, web application firewalls, and detailed SIEM logging platforms. - **Enforce Obfuscation** – Encrypt and obfuscate sensitive data such as social security numbers, addresses, phone numbers, or financial records. - **Follow HIPAA Compliance** – Ensure that all IT systems that manage or process Protected Health Information meet and exceed the physical, technical and administrative requirements of HIPAA-Compliance. - **Monitor Everything** – Detailed logging and automated alerting protect the network perimeter from unexpected access or state changes. Any variation from normal should trigger an alert for manual intervention. - **Patch Management** – It is essential to patch all servers and applications regularly. Patching is one of the best ways to reduce the risk of ransomware effectively. - **Protect Remote Access** – Remote access via SSH or RDP over the public internet is not recommended. Instead, route traffic via a VPN or private internet gateway to access PHI systems. If remote access has to be done over the internet, secure it with super solid passwords and MFA. How to reduce the impact of ransomware: - **Test Your Backup Strategy** – Ensure that all critical PHI servers are backed up regularly with an encrypted backup schedule. In addition, data should be located at a secondary location to uphold data integrity. - **Create a Cyber Incident Response Plan** – Organizations should ensure an incident response and communications plan is created that includes the response and notification procedures for ransomware or data breach incidents. - **Test Your Disaster Recovery Capability** – Healthcare organizations must have Disaster capabilities to ensure that access to PHI is uninterrupted. The best way to achieve this is through a tried and tested DR strategy. - **Training** – Training employees is essential, and additional training should be offered to high-risk employees such as executives, finance workers, and IT professionals. ## How Can Atlantic.Net Help? Atlantic.Net has over 30 years of experience providing high-end business solutions built to provide secure and compliant solutions. As a result, our platform gives our customers the necessary tools to help combat cybersecurity issues. As a healthcare provider, you must consider a fully audited [HIPAA-compliant server infrastructure](https://www.atlantic.net/hipaa-compliant-hosting/) for your organization. Contact our sales team today to learn more about our solutions. [Get In Touch Today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # How to Install NextCloud on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-nextcloud-on-arch-linux/ | Published: 2022-12-06 | Updated: 2024-04-19 | Author: Hitesh Jethva Nextcloud is an open-source file hosting software with comprehensive support options. It allows users to create their own cloud storage to store and share files online. It is an alternate solution to Dropbox and Google Drive and offers a modern, on-premises content collaboration platform with real-time document editing, video chat & groupware on mobile, desktop, and web. There are clients for Linux, macOS, and Microsoft Windows to synchronize files from Nextcloud Server. In this post, we will show you how to install Nextcloud on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Apache and PHP First, install the Apache web server with the following command: ``` pacman -Sy apache ``` After the successful installation, start and enable the Apache service with the following command: ``` systemctl start httpd systemctl enable httpd ``` Next, install the PHP and other required extensions using the following command: ``` pacman -Sy php php-gd php-cgi php-intl php-apache php-sqlite unzip ``` Next, edit the PHP configuration file and enable the required extensions: ``` nano /etc/php/php.ini ``` Add the following lines: ``` extension=pdo_mysql extension=gd extension=pdo_sqlite extension=mysqli extension=intl ``` Save and close the file when you are finished. ## Step 3 – Install and Configure MariaDB Database First, install the MariaDB server with the following command: ``` pacman -S libmariadbclient mariadb mariadb-clients ``` Next, initialize the MariaDB database with the following command: ``` mysql_install_db --user=mysql --basedir=/usr --datadir=/var/lib/mysql ``` Next, start and enable the MariaDB service with the following command: ``` systemctl start mysqld systemctl enable mysqld ``` Next, connect to the MariaDB console using the following command: ``` mysql ``` Once you are connected, create a database and user for drupal: ``` CREATE DATABASE nextcloud; GRANT ALL ON nextcloud.* TO nextcloud@localhost IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 4 – Install NextCloud At the time of writing this tutorial, the latest version of NextCloud is 23. You can download it using the following command: ``` wget https://download.nextcloud.com/server/releases/latest.zip ``` Once the Download is completed, extract it to the Apache web root directory with the following command: ``` unzip latest.zip -d /srv/http/ ``` Next, create a data directory for NextCloud with the following command: ``` mkdir -p /srv/http/nextcloud/data ``` Next, change the ownership of the NextCloud directory to http: ``` chown -R http:http /srv/http/nextcloud/ chmod -R 775 /srv/http/nextcloud/ ``` ## Step 5 – Create an Apache Virtual Host Configuration File Next, you will need to create an Apache virtual host configuration file to host NextCloud on the web. ``` nano /etc/httpd/conf/extra/nextcloud.conf ``` Add the following code: ``` ServerName nextcloud.example.com DocumentRoot /srv/http/nextcloud ErrorLog /var/log/httpd/nextcloud_error.log CustomLog /var/log/httpd/nextcloud_requests.log combined ``` Save and close the file, then edit the Apache main configuration file. ``` nano /etc/httpd/conf/httpd.conf ``` Uncomment the following line: ``` Include conf/extra/httpd-vhosts.conf LoadModule mpm_prefork_module modules/mod_mpm_prefork.so ``` Comment out the following line: ``` #LoadModule mpm_event_module modules/mod_mpm_event.so ``` Add the following lines: ``` LoadModule php_module modules/libphp.so AddHandler php-script .php Include conf/extra/php_module.conf Include conf/extra/nextcloud.conf ``` Save and close the file. Next, restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 6 – Access Nextcloud Now, open your web browser and access Nextcloud using the URL **http://nextcloud.example.com.** You should see the Nextcloud admin user creation screen: ![Nextcloud welcome page](https://www.atlantic.net/wp-content/uploads/2022/10/p1-2.png) Define your admin username and password and click on the **Install** button. You should see the following screen: ![Nextcloud install plugins page](https://www.atlantic.net/wp-content/uploads/2022/10/p2-2.png) Click on the **Install recommended apps**. Once all the recommended apps are installed, you should see the Nextcloud dashboard on the following screen: ![Nextcloud dashboard page](https://www.atlantic.net/wp-content/uploads/2022/10/p3-2-1024x508.png) ## Conclusion In this guide, we explained how to install Nextcloud with Apache on Arch Linux. You can now upload your files, docs, and music on the Nextcloud server and start sharing them with your friend and family. You can try Nextcloud on one of our [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # 10 Reasons Why WordPress Is the Best CMS for SEO > URL: https://www.atlantic.net/hipaa-compliant-wordpress-hosting/10-reasons-why-wordpress-is-the-best-cms-for-seo/ | Published: 2022-12-07 | Updated: 2026-03-01 | Author: Richard Bailey WordPress was first released in 2003 and is one of the Internet’s most popular content management systems. A CMS is an easy and efficient way to create and manage website content using one convenient application. The popularity of WordPress is staggering. It’s estimated that 810 million websites use WordPress (about [43.1% of all websites](https://www.hostingadvice.com/how-to/how-many-websites-use-wordpress/)) and it’s not just used for blogging; some major entities use it, including Bloomberg, Sony Music, and BBC America. WordPress is popular because it is super simple to produce engaging and creative content, and it’s constantly being updated to meet the ever-changing demands of security standards. One of WordPress’ best features is its SEO readiness. Search engines can index WordPress sites easily, and the unlimited configuration possibilities of WordPress mean that you can customize your site to work seamlessly with [SEO tools](https://pwd.com.au/seo/). This article will explain the top 10 reasons WordPress is the best CMS for SEO. ## **1: Easy Content Optimization**: WordPress provides a user-friendly platform that makes editing and updating content incredibly easy. To rank high on a search engine such as Google and Bing, your site’s content must be high quality and unique. The content must contain all the required keywords (without keyword stuffing) and as many relevant alternative keywords as possible. Knowing what keywords to use is the hard part; you can gain an advantage by employing a specialist SEO agency or investing in one of the many excellent online [SEO platform tools](https://www.onsaas.me/blog/semrush-alternatives). ## **2: Meta Description:** A meta description describes the content of a page and sometimes appears as those few lines of text that follow the URL in search engine results. Meta descriptions are essential because they distinguish between a user clicking on your site and skipping past a competitor. WordPress features several metadata plugins that allow you to edit the description directly. The metadata should contain keywords and be written to grab the user’s attention. ## **3: Website Crawling**: Underneath the website’s hood is a robots.txt file instructing search engine web crawlers how to archive and categorize the website. The robots file can also tell search engines not to index your site or how to index a site with multiple subdomains. WordPress features multiple plugins that let you directly edit your Robots.txt. In addition, some plugins will automatically generate the file, ensuring that Google bots index the site effectively. ## **4: Smart Permalinks**: WordPress enables users to create permalinks easily. Permalinks are essential for SEO because search engines examine the URL and the first four words to learn keywords and content. In addition, the ability to edit permalinks gives you the upper hand because you can embed keywords and make the permalink unique to your content. ## **5: Responsive WordPress Themes**: The speed at which a website loads is critical for SEO. Fast, responsive websites will rank higher in search listings. Choosing a lightweight WordPress theme will reduce the code footprint of the site, making it load more quickly. In 2018, Google introduced a search engine algorithm update that significantly changed how sites ranked based on site performance. As a result, responsiveness is now a significant factor in ranking; make sure you use a responsive WordPress theme. Not only does it create a better user experience, but it boosts conversion rates. ## **6: Spam Protection**: WordPress has some great plugins that protect against the spamming of the comment sections of websites. Bots target WordPress sites, so most messages are utterly unrelated to the website content. Spam significantly impacts a website’s ranking and is detrimental to search engine optimization. Comments typically have nothing to do with the site it is being posted on; for example, if a WordPress site about IT has bogus messages about Medical Supplies, Google will rank the site lower and penalize it for having unrelated spam. ## **7: Image Optimization**: Did you know that a website’s pictures, diagrams, and photographs are essential for SEO rankings? Photos can be tagged with keywords that describe the content, which helps with SEO ranking. Images with meaningful naming conventions, relevant alt tags, and title tags increase the visibility of your diagrams in Google searches. Ensure pictures are efficient and do not impact the site loading times significantly. ## **8: Fix Broken Site Links**: Search engine web crawlers follow each URL link on your site when indexing the content. If the link is broken, the web crawler will not like it, thus affecting your site ranking. The errors that hurt your ranking are 400-499 codes, such as bad request, forbidden, and page not found. The good news is that WordPress has plugins that will scan for broken links on the site. Plugins can also automatically redirect all traffic when a site error is found. This is very helpful for SEO rankings and helps your site score. ## **9: Installable SEO Plugins:** Several third-party SEO plugins are available for download for WordPress. These tools include automatic utilities for the recommendations we have discussed so far. Remember that they are not a substitute for an SEO expert, but they help. The most popular plugin is the Yoast plugin for WordPress; it has over 5 million active users. Other notable plugins include Moz, SEMRush, AHREFs, and Google Analytics. ## **10: Verify Your Site With Google:** Google is the number one search engine by a very long way. Verifying your WordPress site with the Google Search Console allows you to track and monitor the impressions on your website. You need to embed some HTML code into the website to get it working, but WordPress provides some easy ways to do that. Knowing what popular pages can help shape your content requirements to get more page views. You learn what content is popular and what content is overlooked. ## Atlantic.Net Hosting Service Those are the ten reasons why WordPress is the best CMS for SEO. However, there is one last critical reason behind SEO ranking; choosing a high-performing web hosting service. Atlantic.Net Cloud Hosting Services is an ultra-fast, highly durable provider of Virtual Private Servers that works well with WordPress, even [HIPAA-compliant WordPress](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/) sites. You can even deploy a 1-click WordPress application on Linux. All Atlantic.Net VPS operates on the latest Intel server hardware, backed by super-fast SSD exclusive storage. So why not sign up and check out our [award-winning service](https://www.atlantic.net/hosting-services-provider/award-winning-service/)? Reach out to the team at[Atlantic.Net](https://www.atlantic.net). Contact Atlantic.Net at 866-618-DATA (3282) (toll-free) or +1-321-206-3734 (international) or by writing to us via the[contact page](https://www.atlantic.net/about-us/corporate-contact/). --- # How to Install Tomcat on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-tomcat-on-arch-linux/ | Published: 2022-12-08 | Updated: 2024-04-19 | Author: Hitesh Jethva Apache Tomcat is an open-source Java servlet container used to host Java-based web applications. It is a popular choice for web developers to build and maintain dynamic websites and applications based on the Java software platform. Apache Tomcat is fast and lightweight, and it is much better than the alternative options. In this post, we will explain how to install Apache Tomcat 10 on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Java JDK Apache Tomcat is a Java-based application, so Java must be installed on your server. If not installed, you can install it using the following command: ``` pacman -S jre-openjdk-headless jre-openjdk jdk-openjdk openjdk-doc openjdk-src ``` After installing Java, verify the Java version with the following command: ``` java -version ``` Sample output: ``` openjdk version "18.0.2" 2022-07-19 OpenJDK Runtime Environment (build 18.0.2+0) OpenJDK 64-Bit Server VM (build 18.0.2+0, mixed mode) ``` ## Step 3 – Download Apache Tomcat 10 Before downloading Apache Tomcat, you will need to add a dedicated user for Tomcat. You can add it using the following command: ``` useradd -r -d /opt/tomcat/ -s /bin/false -c "Tomcat User" tomcat ``` Next, download the latest version of Apache Tomcat 10 using the following command: ``` wget https://dlcdn.apache.org/tomcat/tomcat-10/v10.0.27/bin/apache-tomcat-10.0.27.tar.gz After downloading Apache Tomcat, create a directory for Tomcat and extract the downloaded file inside the /opt/tomcat directory: ``` ``` mkdir /opt/tomcat tar xzf apache-tomcat-10.0.27.tar.gz -C /opt/tomcat --strip-components=1 ``` Next, change the ownership of /opt/tomcat directory to tomcat: ``` chown -R tomcat: /opt/tomcat/ ``` ## Step 4 – Configure Tomcat Admin User Next, you will need to create an admin user for managing Tomcat Manager and the Host Manager app. You can do it by editing the /opt/tomcat/conf/tomcat-users.xml file: ``` nano /opt/tomcat/conf/tomcat-users.xml ``` Add the following lines just above the last line: ``` ``` Save and close the file when you are finished. ## Step 5 – Configure Tomcat for Remote Host By default, Tomcat can be accessed only from the localhost, so you will need to configure Tomcat to access it from the remote host. To access the Manager from the remote host, edit the context.xml file: ``` nano /opt/tomcat/webapps/manager/META-INF/context.xml ``` Remove the following lines: ``` ``` Save and close the file when you are finished. To access the Host Manager from the remote host, edit the context.xml file: ``` nano /opt/tomcat/webapps/host-manager/META-INF/context.xml ``` Remove the following lines: ``` ``` Save and close the file when you are finished. ## Step 6 – Create a Systemd Unit File for Apache Tomcat Next, it is recommended to create a systemd unit file to manage the Tomcat service. You can create it with the following command: ``` nano /etc/systemd/system/tomcat.service ``` Add the following lines: ``` [Unit] Description=Apache Tomcat Server After=syslog.target network.target [Service] Type=forking User=tomcat Group=tomcat Environment=CATALINA_PID=/opt/tomcat/temp/tomcat.pid Environment=CATALINA_HOME=/opt/tomcat Environment=CATALINA_BASE=/opt/tomcat ExecStart=/opt/tomcat/bin/catalina.sh start ExecStop=/opt/tomcat/bin/catalina.sh stop RestartSec=10 Restart=always [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` Next, start the Tomcat service and enable it to start at system reboot: ``` systemctl start tomcat systemctl enable tomcat ``` You can verify the status of the Tomcat service with the following command: ``` systemctl status tomcat ``` Sample output: ``` ● tomcat.service - Apache Tomcat Server Loaded: loaded (/etc/systemd/system/tomcat.service; disabled; preset: disabled) Active: active (running) since Sat 2022-10-08 03:13:21 UTC; 6s ago Process: 50206 ExecStart=/opt/tomcat/bin/catalina.sh start (code=exited, status=0/SUCCESS) Main PID: 50218 (java) Tasks: 30 (limit: 2362) Memory: 77.6M CGroup: /system.slice/tomcat.service └─50218 /usr/bin/java -Djava.util.logging.config.file=/opt/tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache> Oct 08 03:13:21 archlinux systemd[1]: Starting Apache Tomcat Server... Oct 08 03:13:21 archlinux catalina.sh[50206]: Tomcat started. Oct 08 03:13:21 archlinux systemd[1]: Started Apache Tomcat Server. ``` ## Step 7 – Access Apache Tomcat Web UI At this point, Apache Tomcat is started and listening on port 8080. You can check it with the following command: ``` ss -antpl | grep 8080 ``` Sample output: ``` LISTEN 0 0 *:8080 *:* users:(("java",pid=50218,fd=41)) ``` You can now access the Tomcat using the URL **http://your-server-ip:8080**. You should see the following screen: ![Tomcat dashboard page](https://www.atlantic.net/wp-content/uploads/2022/10/p1-1-1024x620.png) To access the Manager App, click on the **Manager.** You will be asked to provide an admin user and password as shown below: ![Tomcat login page](https://www.atlantic.net/wp-content/uploads/2022/10/p2-1.png) Provide your admin username and password and click on the **Sign in** button. You should see the following screen: ![Tomcat manager app dashboard](https://www.atlantic.net/wp-content/uploads/2022/10/p3-1-1024x508.png) To access the Host Manager App, click on the **Host Manager,** you should see the following screen: ![Tomcat host manager dashboard](https://www.atlantic.net/wp-content/uploads/2022/10/p4-1-1024x507.png) ## Conclusion Congratulations! You have successfully installed Apache Tomcat 10 on Arch Linux. You can now deploy your Java application easily with Apache Tomcat. You can try Tomcat one of our [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Top 5 Places You Need to Be Using Encryption in Your IT Architecture > URL: https://www.atlantic.net/hipaa-compliant-hosting/top-5-places-you-need-to-be-using-encryption-in-your-it-architecture/ | Published: 2022-12-09 | Updated: 2025-09-15 | Author: Richard Bailey Encryption is a proven and highly effective protection standard for all data types. To provide the best level of protection, deploy encryption across your IT infrastructure, including servers, storage, and networking. Encryption standards vary in complexity, and the sweet spot for excellent protection and firm performance is the AES-256bit cipher. This article will discuss the top ways to use encryption throughout your IT architecture and discover how Atlantic.Net keeps our customer data safe and encrypted, even in highly regulated industries such as finance and healthcare. ## Data Encryption Types When implementing data encryption throughout your IT infrastructure, three data encryption types must be considered. Each type supports various encryption techniques that can implement in your IT environment. These include: **Encryption at Rest:** Data at rest is any static data housed physically on computer storage in any digital form. The data resides directly on the infrastructure, most commonly saved to disk file systems in files, folders, USB sticks, and network shares. **Encryption in Transit:** When active data traverses the network, it is in transit. Data moves from one application to another or when sending and receiving data over the Internet. Examples include encrypted corporate VPN traffic, SSL/TLS/DTLS certificates, and isolated encrypted networks. **Encryption When Live:** Active data, such as production data processing in real-time, is considered live data. A synchronous database is an excellent example because vast amounts of live data are cached in memory and pagefiles. Unfortunately, in-memory data is threatened by complex vulnerabilities that target the hardware layer of your systems. ## What Data Should I Encrypt? Now we know the type of encryption techniques available, let’s consider the Top 5 places you can use data encryption within your IT architecture to offer the best levels of protection possible. **#1: Encrypt User Data:** User data consists of any personal or business files used by your employees. All modern operating systems consolidate user data into a home directory saved locally, such as on a PC, server, or laptop hard drive. Depending on the employee’s location, user data is usually synced to a file server at the head office. What would happen if the user’s laptop was stolen? Removing and installing the disk elsewhere would allow simple access to your private data if the hard drive is unencrypted. In addition, this approach can bypass operating systems access controls such as user login and file system permissions. Changing file permissions is simple; however, the data would have been useless if you had encrypted the disk. Unfortunately, there are [countless examples](https://attack.mitre.org/techniques/T1083/) of how specific exploits and vulnerabilities can steal user data at rest. Therefore, make encryption of disks, files, and folders mandatory in your working environment. **#2: Encrypt VPN Traffic:** Home and hybrid working have become the new normal for millions of workers across the United States. To do this safely, many use a secure transport mechanism and application layer protection to encrypt all traffic routed via a VPN. Encryption provides confidentiality, integrity, and authenticity to protect data over an IPsec VPN connection. The VPN tunnel captures all traffic sent from point A to point B. The data is encrypted using TLS or DTLS protocols, forcing all VPN traffic to authenticate at both sides of the VPN Tunnel. This approach [defends against](https://attack.mitre.org/techniques/T1565/002/) replay, man-in-the-middle attacks, arp poisoning, and MIB dumps over wired and wireless networks. **#3: Encrypt Cloud Data Using KMS:** Data stored in the cloud is well protected because of the enforced use of secret cryptographic keys. KMS products safeguard data at rest and in transit. Keys encrypt and decrypt files, folders, databases, servers, cloud storage, etc. Have individual KMS keys for each cloud service to avoid using the same key for multiple systems. Ensure a solid security enclave by creating your own keys instead of using the default keys provided by the cloud hosting partner. To further enhance security, enforce a mandatory key rotation policy by setting a predefined number of days to rotate (change) the key. This process ensures the entire cloud platform is secure and that cryptographic keys will not age extensively over their lifetime. To further secure cryptographic keys, harden the ecosystem by generating keys on a TPM 2.0 crypto processor. TPM is additional  hardware that installs directly into modern server hardware and is used to create complex encryption keys greater than 4096 bits **#4: Compartmentalize Data with Detailed Access Controls:** Please classify data to avoid a severe risk to data integrity. For example, if your systems are compromised, a hacker can access all of your data if it’s in a single location. In addition, moving data around the infrastructure introduces a layer of complexity that provides additional security. Combining this approach with tiered access controls and encrypting data with cryptographic keys introduces further security measures, ensuring that only authorized users and authorized server accounts access approved data. Creating this configuration is complex, but it dramatically reduces the risk to data integrity. **#5: Encrypting Cloud Storage and Data Destruction:** Choose a Cloud Service Provider that encrypts data at rest, in transit, and live. Reputable providers will be audited and accredited to ensure these requirements are active. Encryption of shared storage and a policy on handling data destruction is essential. Hard disks fail, but it’s vital they are destroyed ethically and within a security framework. Servers, laptops, and PCs all have a limited shelf life. Take a moment to consider what happens when you discard the hardware. Is the data encrypted, Is the unique key saved directly to the hardware? Do adequate access controls protect the discarded device? The only way to guarantee this is to invest in certificated destruction services; mobile contractors will shred hard drives and equipment on-site and provide certificates of the secured destruction. ## What Encryption Is Offered by Atlantic.Net? Atlantic.Net is your security-focused hosting partner. In addition to offering enterprise-grade end-to-end encryption in the Cloud, we provide encryption standards that meet and exceed PCI and [HIPAA compliance requirements](https://www.atlantic.net/hipaa-compliant-hosting/). Atlantic.Net believes encryption of customer data when at rest should not be an optional feature and is now a requirement of all computing. That’s why our world-class encryption is implemented transparently with no further need for configuration by the user. Atlantic.Net provides enterprise-grade managed solutions, including our fully-managed Atlantic.Net Firewall and Intrusion Prevention Security services. These are cost-effective options for any hosting environment looking to improve its security and reliability. Contact our Sales team today for pricing and availability of our Managed Security solutions! [sales@atlantic.net](mailto:sales@atlantic.net) or 866-618-DATA (3282) --- # How to Install Drupal on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-drupal-on-arch-linux/ | Published: 2022-12-10 | Updated: 2025-10-01 | Author: Hitesh Jethva Drupal is an open-source content management software used by millions of people and organizations around the world. Drupal has a large and supportive community and can be used to host simple websites or complex web applications. It gives you the tools to structure and manage your content via a web browser. Drupal is written in PHP and allows non-technical users to add and edit content without any coding knowledge. In this post, we will show you how to install Drupal CMS on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Apache and PHP First, install the Apache web server with the following command: ``` pacman -Sy apache ``` After successful installation, start and enable the Apache service with the following command: ``` systemctl start httpd systemctl enable httpd ``` Next, install PHP and other required extensions using the following command: ``` pacman -Sy php php-gd php-cgi php-apache php-sqlite ``` Next, edit the PHP configuration file and enable the required extensions: ``` nano /etc/php/php.ini ``` Add the following lines: ``` extension=pdo_mysql extension=gd extension=pdo_sqlite extension=mysqli zend_extension=opcache ``` Save and close the file when you are finished. ## Step 3 – Install and Configure MariaDB Database First, install the MariaDB server with the following command: ``` pacman -S libmariadbclient mariadb mariadb-clients ``` Next, initialize the MariaDB database with the following command: ``` mysql_install_db --user=mysql --basedir=/usr --datadir=/var/lib/mysql ``` Next, start and enable the MariaDB service with the following command: ``` systemctl start mysqld systemctl enable mysqld ``` Next, connect to the MariaDB console using the following command: ``` mysql ``` Once you are connected, create a database and user for drupal: ``` CREATE DATABASE drupal; GRANT ALL ON drupal.* TO drupal@localhost IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 4 – Install Drupal CMS First, download the latest version of Drupal with the following command: ``` wget https://www.drupal.org/download-latest/tar.gz -O drupal.tar.gz ``` Once Drupal is downloaded, extract the downloaded file with the following command: ``` tar xvf drupal.tar.gz ``` Next, move the Drupal content to the Apache default root directory: ``` mv drupal-*/ /srv/http/drupal ``` Next, set proper permissions and ownership with the following command: ``` chown -R http:http /srv/http/drupal chmod -R 775 /srv/http/drupal ``` ## Step 5 – Configure Apache for Drupal Next, you will need to create an Apache virtual host configuration file for Drupal. You can create it with the following command: ``` nano /etc/httpd/conf/extra/drupal.conf ``` Add the following lines: ``` ServerAdmin webmaster@example.com DocumentRoot "/srv/http/drupal" ServerName drupal.example.com ErrorLog "/var/log/httpd/drupal-error_log" CustomLog "/var/log/httpd/drupal-access_log" common # Alias /drupal "/usr/share/webapps/drupal" AllowOverride All Options FollowSymlinks Require all granted php_admin_value open_basedir "/srv/:/tmp/:/usr/share/webapps/:/etc/webapps:/usr/share/pear/:/var/lib/drupal" ``` Save and close the file, then edit the Apache main configuration file: ``` nano /etc/httpd/conf/httpd.conf ``` Uncomment the following line: ``` Include conf/extra/httpd-vhosts.conf LoadModule rewrite_module modules/mod_rewrite.so LoadModule mpm_prefork_module modules/mod_mpm_prefork.so ``` Comment out the following line: ``` #LoadModule mpm_event_module modules/mod_mpm_event.so ``` Add the following lines: ``` LoadModule php_module modules/libphp.so AddHandler php-script .php Include conf/extra/php_module.conf Include conf/extra/drupal.conf ``` Save and close the file. Next, restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 6 – Access Drupal Website Now, open your web browser and access the Drupal web interface using the URL **http://drupal.example.com**. You should see the following screen: ![Drupal choose language page](https://www.atlantic.net/wp-content/uploads/2022/10/p1-1024x497.png) Select your language and click on the **Save and continue** button. You should see the following screen: ![Drupal select installation profile page](https://www.atlantic.net/wp-content/uploads/2022/10/p2-1024x546.png) Select your installation profile and click on the **Save and continue** button. You should see the following screen: ![Drupal check PHP requirements page](https://www.atlantic.net/wp-content/uploads/2022/10/p3.png) Make sure all the PHP extensions are installed then click on **continue anyway**. You should see the following screen: ![Drupal select database page](https://www.atlantic.net/wp-content/uploads/2022/10/p4.png) Define your database settings and click on the **Save and continue** button. You should see the following screen: ![Drupal define site information page](https://www.atlantic.net/wp-content/uploads/2022/10/p6.png) ![Drupal admin information page](https://www.atlantic.net/wp-content/uploads/2022/10/p7.png) Define your site information, admin username, and password, and click on the **Save and continue** button. You should see the Drupal dashboard on the following screen: ![Drupal dashboard page](https://www.atlantic.net/wp-content/uploads/2022/10/p8-1024x509.png) ## Conclusion In this tutorial, you learned how to install Drupal CMS on Arch Linux. You can now start creating your blog and website using the Drupal platform. You can choose one of our [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! to test the Drupal installation. --- # How to Install Java on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-java-on-arch-linux/ | Published: 2022-12-11 | Updated: 2024-06-01 | Author: Hitesh Jethva Java is one of the most popular programming languages for developing mobile and desktop applications. It provides a run-time environment to run several Java applications, including Tomcat, Jetty, Cassandra, Glassfish, and Jenkins. It is cross-platform and can run on Windows, Linux, and macOS. In this post, we will show you how to install Java on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Java JRE and JDK By default, Java JRE and JDK are available in the Arch Linux default repository. First, search for all available Java JRE versions using the following command: ``` pacman -sS java | grep jre ``` You will get the following versions: ``` extra/jre-openjdk 18.0.2.1.u0-1 [installed] extra/jre-openjdk-headless 18.0.2.1.u0-1 [installed] extra/jre11-openjdk 11.0.16.1.u1-2 extra/jre11-openjdk-headless 11.0.16.1.u1-2 extra/jre17-openjdk 17.0.4.1.u1-2 extra/jre17-openjdk-headless 17.0.4.1.u1-2 extra/jre8-openjdk 8.345.u01-1 extra/jre8-openjdk-headless 8.345.u01-1 ``` From the above list, install Java JRE 11 with the following command: ``` pacman -S jre11-openjdk ``` You can now verify the Java version using the following command: ``` java --version ``` You should see the following output: ``` openjdk 11.0.16.1 2022-08-12 OpenJDK Runtime Environment (build 11.0.16.1+1) OpenJDK 64-Bit Server VM (build 11.0.16.1+1, mixed mode) ``` Next, search for all available Java JDK versions using the following command: ``` pacman -sS java | grep jdk ``` You will get the following list of versions: ``` extra/jdk-openjdk 18.0.2.1.u0-1 extra/jdk11-openjdk 11.0.16.1.u1-2 extra/jdk17-openjdk 17.0.4.1.u1-2 extra/jdk8-openjdk 8.345.u01-1 extra/jre-openjdk 18.0.2.1.u0-1 extra/jre-openjdk-headless 18.0.2.1.u0-1 [installed] extra/jre11-openjdk 11.0.16.1.u1-2 [installed] extra/jre11-openjdk-headless 11.0.16.1.u1-2 [installed] extra/jre17-openjdk 17.0.4.1.u1-2 extra/jre17-openjdk-headless 17.0.4.1.u1-2 extra/jre8-openjdk 8.345.u01-1 extra/jre8-openjdk-headless 8.345.u01-1 extra/openjdk-doc 18.0.2.1.u0-1 extra/openjdk-src 18.0.2.1.u0-1 extra/openjdk11-doc 11.0.16.1.u1-2 extra/openjdk11-src 11.0.16.1.u1-2 extra/openjdk17-doc 17.0.4.1.u1-2 extra/openjdk17-src 17.0.4.1.u1-2 extra/openjdk8-doc 8.345.u01-1 extra/openjdk8-src 8.345.u01-1 ``` Now, run the following command to install Java JDK 17: ``` pacman -S jdk17-openjdk ``` ## Step 3 – Set Default Java Versions At this point, both Java versions are installed on your system. You can list all installed Java versions using the following command: ``` archlinux-java status ``` You will get the following output: ``` Available Java environments: java-11-openjdk (default) java-17-openjdk ``` Next, set Java JDK 17 as the default Java version using the following command: ``` archlinux-java set java-17-openjdk ``` Now, verify the Java versions using the following command: ``` java --version ``` You will get the following output: ``` openjdk 17.0.4.1 2022-08-12 OpenJDK Runtime Environment (build 17.0.4.1+1) OpenJDK 64-Bit Server VM (build 17.0.4.1+1, mixed mode) ``` ## Step 4 – Install Oracle Java When writing this article, the latest available Java version is Oracle Java 19. You can download it with the following command: ``` wget https://download.oracle.com/java/19/latest/jdk-19_linux-x64_bin.tar.gz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar xzf jdk-19_linux-x64_bin.tar.gz -C /opt ``` Next, create an environment variable for Java: ``` nano /etc/profile.d/jdk19.sh ``` Add the following lines: ``` export JAVA_HOME="/opt/jdk-19/" export PATH="$PATH:${JAVA_HOME}/bin" ``` Save and close the file, then load the environment variable with the following command: ``` source /etc/profile.d/jdk19.sh ``` Next, verify the Java home variable with the following command: ``` echo $JAVA_HOME ``` You will get the following output: ``` /opt/jdk-19/ ``` You can now confirm the Oracle Java version using the following command: ``` /opt/jdk-19/bin/java --version ``` You should get the following output: ``` java 19 2022-09-20 Java(TM) SE Runtime Environment (build 19+36-2238) Java HotSpot(TM) 64-Bit Server VM (build 19+36-2238, mixed mode, sharing) ``` ## Conclusion In this post, we explained how to install Java JRE, Java JDK, and Oracle Java on Arch Linux. We also explained how to switch between the Java versions. You can now start developing your Java application using your preferred Java versions. Try Java on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Set Up a PCI-DSS Compliant VPN > URL: https://www.atlantic.net/pci-compliant-hosting/how-to-set-up-a-pci-dss-compliant-vpn/ | Published: 2022-12-12 | Updated: 2025-09-15 | Author: Richard Bailey A Virtual Private Network (VPN) is a network implemented between two or more endpoint devices, typically using public networks such as the internet, to provide security and privacy for the transmissions between the devices. In addition, the VPN offers secure access to authorized resources from remote locations to inside the organization’s private network. In PCI compliance, businesses use a VPN to secure communications between two or more financial institutions. However, there are strict rules about sending and receiving financial transaction data across the internet. A [PCI-compliant](https://www.atlantic.net/pci-compliant-hosting/) VPN will ensure the safety of customer data. ## What Is A PCI-Compliant VPN? Virtual Private Networks (VPNs), commonly referred to as tunneling or IPsec VPNs, are set up to deliver client access to IP services at an organization’s remote access site. There are three commonly used VPN designs: - **Site-to-Site:** Site-to-site VPN allows you to connect two separate sites into one private network. This is helpful when businesses share assets such as files and databases. - **Remote Access:** This architecture allows you to connect your local VPN clients to peripheral devices through remote access VPN. Make use of this architecture to extend your private network to authorized users in other geographical locations. - **Host-to-Host:** Unlike VPNs that utilize a proxy gateway, host-to-host VPNs make connections directly between clients and destination hosts. This is similar to remote access, but instead of stepping through a VPN gateway, a host-to-host VPN user is connected directly to the remote destination. A PCI-compliant VPN is a security system that conforms to the Payment Card Industry Data Security Standard (PCI DSS), a set of comprehensive and technical security standards enabling data confidentiality, integrity, and availability. Companies that offer end-to-end products and services, such as financial institutions, need a VPN to serve internal websites based on controlled user access. When connected to a VPN, financial websites and transaction services use a private access virtual IP to connect and authenticate to the target. In addition, the secured connection allows you to send sensitive information, such as credit card numbers, over the internet, thus significantly reducing the risk of exposure to electronic threats. However, only some VPN products are PCI-Compliant due to the number of safeguards that PCI standards require. ## PCI-DSS Compliance Primary Objectives PCI compliance aims to protect the payment card industry and ensure that transactions are secure. Using a VPN is aligned with the six primary objectives of PCI compliance: - Build and maintain a secure network and systems. - Protect cardholder data. - Maintain a vulnerability management program. - Implement strong access control measures. - Regularly monitor and test networks. - Maintain an information security policy. ## PCI-DSS Requirements for a VPN PCI Risk Assessments and IT Governance have become firm requirements for businesses of all sizes, regardless of whether they are a retailer, a hospital, a bank, or a merchant. PCI-DSS accreditation aims to reduce the risk associated with electronic payments, and network security plays an essential role in securing transactions. According to PCI-DSS, there are three types of networks: - Internal (Isolated Cardholder Data Environment). - DMZ (Internet Facing Endpoints). - Insecure (Public Internet). A PCI-compliant VPN is only allowed to traverse a DMZ or insecure network. Direct connections are allowed between the DMZ and the isolated internal network. However, strict rules and requirements exist to stop insecure VPNs from accessing the internal network. A firewall should be configured to deny direct communication between the Insecure and Internal networks. All VPN traffic must be secured using Internet Protocol Security (IPSec) standards. Tunnel mode must be used except where communication is host-to-host, and Aggressive mode must not be used for tunnel establishment. The device authentication method must use certificates obtained from a trusted Certificate Authority. SSL and TLS 1.0 security ciphers and certificates are prohibited when configuring a VPN, and all ingress and egress traffic requires encryption using Advanced Encryption Standard (AES-256 minimum). In addition, control protections are needed to detect unauthorized changes to VPN configuration or user access settings. Monitoring for changes to digital signatures and file checksums is excellent for ensuring the configuration is secure and difficult to tamper with. All VPN users are required to authenticate to connect. Additional measures, such as MAC address filtering, can only authorize authentic endpoint devices. It is expected that multi-factor authentication will be enabled at all touchpoints for VPN user connectivity and that access must be denied after three consecutive unsuccessful login attempts. Such measures will lock the user account, and only an authorized individual can unlock it. Furthermore, if the VPN connection is idle, it should automatically disconnect within five minutes. Logging is a principal prerequisite for PCI compliance. All VPN remote access requests and user activity requires logging. PCI-DSS also recommends that logs are reviewed weekly for any suspicious activity. A SIEM platform can be configured to alert against suspicious activity and behavior automatically, and employees can triage these alerts to ensure compliance. ## I Need a PCI-Compliant VPN. What Are My Options? Modern VPNs are highly flexible; you no longer rely on expensive physical appliances. Instead, software VPNs are increasingly popular and meet the needs of an on-demand VPN. There are several open-source solutions available for Windows and Linux servers, and there are several open-source solutions available for Windows and Linux servers. The three most popular open-source VPN solutions are software-based; software like Softether VPN, Openswan, and Openconnect are often used to create a private network tunnel and, when configured correctly, can be made [PCI compliant](https://www.atlantic.net/pci-compliant-hosting/). A VPN solution routes traffic to the organizational network, giving an external user the appearance of connecting to the business network from outside. The key to a successful VPN is to ensure you create the connection using VPN software designed explicitly for cloud-based operating systems. ## How Can Atlantic.Net help? Atlantic.Net is a trusted cloud hosting services provider with over 30 years of experience. We offer a range of customized hosting solutions designed to provide companies with the potential to grow and prosper. Our [Cloud Platform](https://www.atlantic.net/cloud-platform/) has several Linux 1-click applications that create a VPS you can configure as your private VPN. We also feature [extensive documentation](https://www.atlantic.net/vps-hosting/how-to-install-and-configure-openvpn-server-on-ubuntu-20-04/) about how to make your VPN tools. Atlantic.Net is SOC 2, SOC 3 certified, HIPAA and HITECH audited, PCI-DSS compliant, and regularly audited for security. The many reasons to choose Atlantic.Net to meet your business needs include the following: - A 100% uptime service level agreement. - World-class data center infrastructure. - Industry-leading certifications and partnerships. [Contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) and discover how your company can benefit from a VPN. --- # How to Install MySQL on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-mysql-on-arch-linux/ | Published: 2022-12-13 | Updated: 2024-06-01 | Author: Hitesh Jethva MySQL is a free, open-source, Relational Database Management System used to develop web-based software applications. MySQL is a scalable, intuitive, high-performance, and feature-rich database management system compared to other databases. It is known for its stability and reliability and is considered simple and easy to use. This post will show you how to install MySQL on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install MySQL Server The MySQL package is included in the Arch Linux default repository by default. You can install it by running the following command: ``` pacman -S mysql ``` Once MySQL is installed, you can verify the MySQL version with the following command: ``` mysqld --version ``` You should see the following output: ``` mysqld Ver 10.9.3-MariaDB for Linux on x86_64 (Arch Linux) ``` Next, initialize the MySQL database with the following command: ``` mysql_install_db --user=mysql --basedir=/usr --datadir=/var/lib/mysql ``` ## Step 3 – Manage MySQL Service By default, the MySQL service is managed by systemd. You can control it easily using the **systemctl** command line utility. To start the MySQL service, run the following command: ``` systemctl start mysqld ``` To enable the MySQL service so it starts at system reboot with the following command: ``` systemctl enable mysqld ``` You can verify the active status of MySQL using the following command: ``` systemctl status mysqld ``` You will get the following output: ``` ● mariadb.service - MariaDB 10.9.3 database server Loaded: loaded (/usr/lib/systemd/system/mariadb.service; disabled; preset: disabled) Active: active (running) since Tue 2022-09-27 04:52:59 UTC; 6h ago Docs: man:mariadbd(8) https://mariadb.com/kb/en/library/systemd/ Main PID: 54978 (mariadbd) Status: "Taking your SQL requests now..." Tasks: 8 (limit: 2362) Memory: 0B CGroup: /system.slice/mariadb.service └─54978 /usr/bin/mariadbd Sep 27 04:52:59 archlinux systemd[1]: Started MariaDB 10.9.3 database server. ``` ## Step 4 – Secure the MySQL Installation By default, the MySQL installation is not secured. You can run the mysql_secure_installation script to secure the MySQL: ``` mysql_secure_installation ``` You will be asked to provide the current MySQL root password: ``` NOTE: RUNNING ALL PARTS OF THIS SCRIPT IS RECOMMENDED FOR ALL MariaDB SERVERS IN PRODUCTION USE! PLEASE READ EACH STEP CAREFULLY! In order to log into MariaDB to secure it, we'll need the current password for the root user. If you've just installed MariaDB, and haven't set the root password yet, you should just press enter here. Enter current password for root (enter for none): ``` Just press the Enter key. You will be asked to switch the Unix socket authentication: ``` OK, successfully used password, moving on... Setting the root password or using the unix_socket ensures that nobody can log into the MariaDB root user without the proper authorisation. You already have your root account protected, so you can safely answer 'n'. Switch to unix_socket authentication [Y/n] Y ``` Type Y and press the Enter key. You will be asked to set the root password: ``` Enabled successfully! Reloading privilege tables.. ... Success! You already have your root account protected, so you can safely answer 'n'. Change the root password? [Y/n] Y New password: Re-enter new password: Password updated successfully! Reloading privilege tables.. ... Success! By default, a MariaDB installation has an anonymous user, allowing anyone to log into MariaDB without having to have a user account created for them. This is intended only for testing, and to make the installation go a bit smoother. You should remove them before moving into a production environment. ``` Once the root password is set, you will be asked to remove the anonymous user: ``` Remove anonymous users? [Y/n] Y ``` Type Y and press the Enter key. You will be asked to disallow remote root login: ``` ... Success! Normally, root should only be allowed to connect from 'localhost'. This ensures that someone cannot guess at the root password from the network. Disallow root login remotely? [Y/n] Y ``` Type Y and press the Enter key. You will be asked to remove the test database: ``` ... Success! By default, MariaDB comes with a database named 'test' that anyone can access. This is also intended only for testing, and should be removed before moving into a production environment. Remove test database and access to it? [Y/n] Y ``` Type Y and press the Enter key. You will be asked to reload the privilege tables: ``` - Dropping test database... ... Success! - Removing privileges on test database... ... Success! Reloading the privilege tables will ensure that all changes made so far will take effect immediately. Reload privilege tables now? [Y/n] Y ... Success! Cleaning up... All done! If you've completed all of the above steps, your MariaDB installation should now be secure. Thanks for using MariaDB! ``` ## Step 5 – Create a User in MySQL First, log into the MySQL shell with the following command: ``` mysql -u root -p ``` Once you log in to MySQL, create a user and set a password: ``` CREATE USER 'testuser'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all privileges on all databases with the following command: ``` GRANT ALL PRIVILEGES ON *.* TO 'testuser'@'localhost' WITH GRANT OPTION; ``` Next, flush the privileges and exit from the MySQL shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Conclusion In this post, we learned how to install the MySQL server on Arch Linux. We also learned how to secure MySQL and create a user. You can now use MySQL as a database backend with your application. Try to deploy and use MySQL on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # The Impact of the Strengthening American Cybersecurity Act Of 2022 > URL: https://www.atlantic.net/hipaa-compliant-hosting/the-impact-of-the-strengthening-american-cybersecurity-act/ | Published: 2022-12-14 | Updated: 2025-09-15 | Author: Richard Bailey The Strengthening American Cybersecurity Act is described as a landmark piece of legislation that intends to augment the response to the growing threat of cybercrime and state-sponsored cyber warfare against the United States. Although Congress unanimously passed the act in March 2022, it is currently awaiting sign-off from the House of Representatives before President Biden finalizes the act into law. Commentators are stating the radical changes are long overdue and will introduce a much-needed security framework for government institutions to follow that provides a solid foundation of cybersecurity best practices, improving the cybersecurity posture of the United States government. The act comprises three bills; Title I, the Federal Information Security Modernization Act; Title II, the Cyber Incident Reporting Act; and Title III, the Federal Secure Cloud Improvement and Jobs Act. Join us as we discuss the impact expected from this act and why it is crucial in defending against an ever-increasing threat to national security. ## Why Is the Strengthening American Cybersecurity Act of 2022 Act needed? Cybercrime is a growing problem that poses a significant risk to government institutions and critical homeland infrastructure. Russia has been suspected of state-sponsored hacking and criminal cyber activity for many years. However, the risk has significantly amplified since Russia invaded Ukraine, and there is a growing threat of Russia retaliating in response to increasing U.S. support for the Ukrainian war effort. The federal agency in charge of responding to cybercrime, called CISA (Cybersecurity and Infrastructure Security Agency), wants greater authoritative capabilities to instruct critical government services on how to defend and coordinate a response to cybersecurity incidents. For example, a major oil pipeline (the colonial pipeline) was shut down last year because of a severe ransomware attack. The attack immediately caused a price rise at gas stations across the east coast. The legislation aims to stop such events from directly impacting the everyday life of the American people. It seeks to ensure that banks, utility services, electric grids, water networks, oil pipelines, and mass transit systems can quickly recover from a damaging cyberattack. ## What Does The Act Involve? At the moment, the primary focus of the act surrounds reporting cybersecurity incidents. It introduces some minimum reporting requirements: critical infrastructure entities and federal civilian agencies must report any “substantial cyber incident.” Attacks are to be reported to the Cybersecurity and Infrastructure Agency (CISA) regardless of compromised systems or breached data. They have 72 hours to report a hack and only 24 hours to report whether a ransomware payment has been made. If these guidelines are breached, the CISA has the power to summon the entity to court where they will likely have to pay some fine. As these enforcement details are still being worked out, the severity of the penalties is yet to be defined. The strict time restraints on reporting an incident may cause significant headaches. Due to the nature of a cyber attack, hackers can lay dormant for weeks or months before any evidence of compromise is discovered. The proposed legislation will likely force entities to emphasize their cybersecurity posture by enforcing policies that promote security awareness. These checks will ensure that basic standards are being met: systems are patched; vulnerabilities are being resolved, and detailed risk assessments are happening with a roadmap for fixing problems. Let’s dig deeper and discover more about each act in the legislation. ## The Federal Information Security Modernization Act FISMA was signed into law by President Barack Obama in 2014 and introduced processes and controls to ensure the confidentiality, integrity, and availability of system-related information. It applies to every federal agency, and its purpose is to standardize multiple information security practices. The purpose of the act was to: - Amend existing regulations to improve federal cybersecurity - Enhance federal incident transparency and notification expectations - Add to FISMA guidance - Enhance mobile security - Implement zero-trust architecture - Codify vulnerability disclosure programs - Automate reports - Establish inventory - Gather quantitative metrics - Secure physical operations centers Source: [strengthening american cybersecurity act/](https://www.onetrust.com/blog/strengthening-american-cybersecurity-act/) ## The Cyber Incident Reporting for Critical Infrastructure Act CIRCIA was signed into law in March 2022 by President Joe Biden; this is the specific part of the act that refers to the mandatory reporting of cybersecurity incidents. The purpose is to empower the CISA to send help and resources to the federal agency to assist in any cybersecurity incident. The purpose of the act was to address these concerns: - Cyber incident reporting - Federal incident report sharing - Ransomware vulnerability warning programs - Ransomware threat mitigation activities - Congressional reporting Source: [strengthening american cybersecurity act/](https://www.onetrust.com/blog/strengthening-american-cybersecurity-act/) ## The Federal Secure Cloud Improvement and Jobs Act While the act may not feature the catchiest of titles, it is nonetheless important. This part of the act focuses specifically on federal agencies receiving approval for using cloud technology providers to provide core services. It outlines the requirements and standards to use the public cloud by promoting cybersecurity modernization and next-generation security principles like a risk-based paradigm, zero trust principles, endpoint detection and response, cloud migration, automation, penetration testing, and vulnerability disclosure programs. ## How To Reduce the Risk of a Data Breach? One of the best ways to reduce the risk of a breach is to outsource critical IT systems to security-conscious hosting providers like Atlantic.Net. Our architecture is built to exacting standards, able to meet compliance requirements for special circumstances such as [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/). MFA is implemented across the business, and our engineers follow the principle of least privilege, ensuring that every user has only the required permissions to do the task. When outsourcing services to third parties, ensure that extra due diligence is performed on each vendor to understand the risk of a supply chain attack. Identifying all aspects of risk and writing down an actionable plan will create a baseline for the company’s required and desired security aspirations. If you would like to learn more, please reach out to the team. Contact Atlantic.Net at 866-618-DATA (3282) (toll-free) or +1-321-206-3734 (international) or by writing to us via the [contact page](https://www.atlantic.net/support/), and we will be happy to assist you. --- # How To Install Apache Maven On Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-maven-on-arch-linux/ | Published: 2022-12-15 | Updated: 2023-11-15 | Author: Hitesh Jethva Apache Maven is one of the most popular build management tools used for Java projects. It is based on a POM (project object model) and used for project build, dependency, and documentation. It is very useful for Java developers to manage an entire project’s build process, including storing documents, reporting, and more. Apache Maven uses an XML file to store information about projects, configurations, and dependencies. In this post, we will show you how to install Apache Maven on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Java OpenJDK Apache Maven is a Java-based application, so you will need to install Java on your system. You can install Java with the following command: ``` pacman -S jre-openjdk ``` Once Java is installed, verify the Java version using the following command: ``` java --version ``` You should see the following output: ``` openjdk 18.0.2 2022-07-19 OpenJDK Runtime Environment (build 18.0.2+0) OpenJDK 64-Bit Server VM (build 18.0.2+0, mixed mode) ``` ## Step 3 – Install Apache Maven from Source If you want to install the latest version of Apache Maven, then you will need to install it from the source. First, go to the Apache Maven download page and download the latest version using the following command: ``` wget https://dlcdn.apache.org/maven/maven-3/3.8.6/binaries/apache-maven-3.8.6-bin.tar.gz ``` Once the download is completed, create a directory for Apache Maven and extract the downloaded file inside the Apache Maven directory: ``` mkdir /usr/local/maven tar xzf apache-maven-3.8.6-bin.tar.gz -C /usr/local/maven/ --strip-components=1 ``` Next, create an environment variable for Apache Maven using the following command: ``` echo export 'PATH=$PATH:/usr/local/maven/bin/' > /etc/profile.d/maven.sh echo 'export JAVA_HOME=/usr/lib/jvm/java-18-openjdk/' >> /etc/profile.d/maven.sh ``` Next, set execution permissions on the created file with the following line: ``` chmod +x /etc/profile.d/maven.sh ``` Next, activate the Apache Maven environment variable with the following command: ``` source /etc/profile.d/maven.sh ``` Next, verify the Apache Maven version using the following command: ``` mvn --version ``` You will get the following output: ``` Apache Maven 3.8.6 (84538c9988a25aec085021c365c560670ad80f63) Maven home: /usr/local/maven Java version: 18.0.2, vendor: N/A, runtime: /usr/lib/jvm/java-18-openjdk Default locale: en_US, platform encoding: UTF-8 OS name: "linux", version: "5.8.14-arch1-1", arch: "amd64", family: "unix" ``` ## Step 4 – Install Apache Maven from the Repository The simple and easiest way to install Apache Maven is to install it from the Arch Linux default repository. Run the following command to install Apache Maven: ``` pacman -S maven ``` Once the Apache Maven is installed, you can verify the Apache Maven version using the following command: ``` mvn --version ``` You should get the following output: ``` Apache Maven 3.8.6 (84538c9988a25aec085021c365c560670ad80f63) Maven home: /opt/maven Java version: 18.0.2, vendor: N/A, runtime: /usr/lib/jvm/java-18-openjdk Default locale: en_US, platform encoding: UTF-8 OS name: "linux", version: "5.8.14-arch1-1", arch: "amd64", family: "unix" ``` ## Conclusion In this post, we explained two methods to install Apache Maven on Arch Linux. You can now use Apache Maven in your development environment and start managing Java-based projects. Try to install Apache Maven on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install WordPress on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-wordpress-on-arch-linux/ | Published: 2022-12-16 | Updated: 2025-10-01 | Author: Hitesh Jethva WordPress is a content management system that allows you to build and host a website on the web. It offers a plugin architecture and a template system that allows users to customize any website to fit their business, blog, portfolio, or online store. It is written in PHP and uses MariaDB and MySQL as database backends. In this post, we will show you how to install WordPress with Apache on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Apache and PHP First, install the Apache web server with the following command: ``` pacman -Sy apache ``` After successful installation, start and enable the Apache service with the following command: ``` systemctl start httpd systemctl enable httpd ``` Next, install PHP and other required extensions using the following command: ``` pacman -Sy php php-gd php-cgi php-apache ``` Next, edit the PHP configuration file and enable the required extensions: ``` nano /etc/php/php.ini ``` Add the following lines: ``` extension=pdo_mysql extension=mysqli ``` Save and close the file when you are finished. ## Step 3 – Install and Configure MariaDB Database First, install the MariaDB server with the following command: ``` pacman -S mariadb ``` ``` ``` Next, start and enable the MariaDB service with the following command: ``` systemctl start mysqld systemctl enable mysqld ``` Now, run the security script that is included with MariaDB. This is a critical step to secure your database installation by setting a root password, removing anonymous users, and restricting root user access. ``` mariadb-secure-installation ``` Follow the on-screen prompts. It is highly recommended to answer “Y” (yes) to all questions for a secure environment: - Enter current password for root (enter for none): **Press Enter** - Set root password? [Y/n]: **Y** - Remove anonymous users? [Y/n]: **Y** - Disallow root login remotely? [Y/n]: **Y** - Remove test database and access to it? [Y/n]: **Y** - Reload privilege tables now? [Y/n]: **Y** With the database server secured, log in to the MariaDB console as the root user: ``` mariadb -u root -p ``` Once you are connected, create a database and user for WordPress: ``` CREATE DATABASE wordpress CHARACTER SET utf8mb4 COLLATE utf8mb4_general_ci; CREATE USER 'wordpress'@'localhost' IDENTIFIED BY 'your_strong_password'; GRANT ALL PRIVILEGES ON wordpress.* TO 'wordpress'@'localhost'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 4 – Install WordPress CMS First, navigate to the Apache default root directory and download the latest version of WordPress with the following command: ``` cd /srv/http wget https://wordpress.org/latest.tar.gz ``` Once the download is completed, extract the downloaded file using the following command: ``` tar xvf latest.tar.gz ``` Next, rename the WordPress configuration file: ``` mv /srv/http/wordpress/wp-config-sample.php /srv/http/wordpress/wp-config.php ``` Next, edit the WordPress configuration file and define your database: ``` nano /srv/http/wordpress/wp-config.php ``` Change the following lines: ``` define( 'DB_NAME', 'wordpress' ); /** MySQL database username */ define( 'DB_USER', 'wordpress' ); /** MySQL database password */ define( 'DB_PASSWORD', 'password' ); ``` Save and close the file, then change the ownership of the WordPress directory: ``` chown -R root:http /srv/http/wordpress ``` Next, grant ownership of the `wp-content` directory to the Apache user (`http`). This allows WordPress to install themes/plugins and upload media. ``` chown -R http:http /srv/http/wordpress/wp-content ``` Finally, set secure file and directory permissions. Directories should be `755` and files should be `644`. ``` find /srv/http/wordpress/ -type d -exec chmod 755 {} \; ``` ``` find /srv/http/wordpress/ -type f -exec chmod 644 {} \; ``` These permissions ensure that only the file owner can write to files, while the web server can still manage themes, plugins, and uploads in the designated `wp-content` directory. ## Step 5 – Configure Apache for WordPress Next, edit the Apache default virtual host configuration file: ``` nano /etc/httpd/conf/extra/httpd-vhosts.conf ``` Remove all lines and add the following code: ``` ServerAdmin webmaster@example.com DocumentRoot "/srv/http/wordpress" ServerName wordpress.example.com ErrorLog "/var/log/httpd/wordpress-error_log" CustomLog "/var/log/httpd/wordpress-access_log" common ``` Save and close the file, then edit the Apache configuration file: ``` nano /etc/httpd/conf/httpd.conf ``` Uncomment the following line: ``` Include conf/extra/httpd-vhosts.conf LoadModule mpm_prefork_module modules/mod_mpm_prefork.so ``` Comment out the following line: ``` #LoadModule mpm_event_module modules/mod_mpm_event.so ``` Add the following lines: ``` LoadModule php_module modules/libphp.so AddHandler php-script .php Include conf/extra/php_module.conf ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 6 – Access WordPress Web Installation Wizard With all the server-side components configured, there are two final steps: telling your local machine how to find your new site and running the WordPress web installer. **Update Your Local Hosts File** To access the site using the custom domain `wordpress.example.com`, you must map this hostname to your local machine’s IP address. Add the entry to your `/etc/hosts` file with the following command. This ensures your web browser knows to look for the site on your local machine. ``` echo "127.0.0.1 wordpress.example.com" | sudo tee -a /etc/hosts ``` **Access the WordPress Web Installation Wizard** Now, open your web browser and access the WordPress installation using the URL **http://wordpress.example.com.** You will be redirected to the WordPress site configuration page: ![WordPress site configuration page](https://www.atlantic.net/wp-content/uploads/2022/09/p1-19.png) Provide your website name and admin credentials and click on the **Install WordPress** button. Once WordPress is installed, you should see the following page: ![WordPress installed](https://www.atlantic.net/wp-content/uploads/2022/09/p2-15.png) Click on the **Login** button. You should see the WordPress login page: ![WordPress login page](https://www.atlantic.net/wp-content/uploads/2022/09/p3-7.png) Provide your admin username and password and click on the **Login** button. You should see the WordPress admin dashboard on the following page: ![WordPress dashboard page](https://www.atlantic.net/wp-content/uploads/2022/09/p4-3-1024x509.png) ## Conclusion In this post, we explained how to install WordPress with Apache on Arch Linux. You can now create and deploy your website or blog from the WordPress admin dashboard. Try WordPress on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Endpoint Protection Requirements in Common Compliance Standards > URL: https://www.atlantic.net/hipaa-compliant-hosting/endpoint-protection-requirements-in-common-compliance-standards/ | Published: 2022-12-17 | Updated: 2025-09-15 | Author: Gilad Maayan Endpoint protection solutions are deployed on endpoints, such as employee workstations, mobile devices, servers, and cloud virtual machines (VMs), to protect them against cyber threats. These solutions cover the security gaps left by traditional antivirus technologies. [Endpoint protection provides multiple layers of protection](https://www.cynet.com/endpoint-security/top-6-endpoint-protection-platforms-and-how-to-choose/) that can address advanced threats such as data leaks, sophisticated malware, advanced persistent threats (APTs), and zero-day exploits. Most compliance standards have specific requirements regarding cybersecurity. Endpoints are a weak link in the security posture of many organizations. So endpoint protection is an important part of achieving and demonstrating an adequate level of security for a corporate network. In this article, I’ll cover several important compliance standards and how endpoint security can help your organization achieve compliance. ## GDPR and Endpoint Protection The General Data Protection Regulation (GDPR) is a personal data protection law by the European Union (EU). It imposes certain rules on all entities processing personal data to help protect the privacy of EU citizens. The GDPR applies to EU and non-EU entities processing EU personal data. The GDPR enforces strict penalties for noncompliance, and administrative fines for violations can reach up to €20 million or 4% of annual worldwide revenue (whichever is greater). ### Endpoints can help comply with GDPR. Endpoint security includes various technologies, such as secure web gateways (SWGs), anti-malware solutions, and endpoint management systems. These solutions help ensure desktops, mobile devices, and laptops are not compromised. Endpoint devices can contain personally identifiable information (PII) belonging to an organization’s customers or employees, covered by the GDPR. Thus, implementing endpoint security can play an important role in complying with Article 32 of the GDPR, which specifies that organizations should: - Ensure ongoing confidentiality and integrity of data processing systems and services; - Be able to restore access to personal data promptly in the event of a cybersecurity incident - Be able to test, assess and evaluate the effectiveness of security controls ### The importance of software composition analysis (SCA) Many organizations deploy their proprietary software on endpoints. This could be business software developed in-house by the organization or third-party solutions heavily customized by in-house development or IT teams. These proprietary systems are often included in the allowlist of an endpoint security solution and trusted implicitly by security teams. However, even though the organization developed in-house, this does not guarantee they are free of vulnerable, insecurely configured, or even malicious components. To ensure full protection, organizations must implement [software composition analysis (SCA) technology](https://www.mend.io/resources/blog/software-composition-analysis/), which can create a software bill of materials (SBOM) detailing all the components and sub-components included in proprietary software. This can guarantee and provide evidence for auditors that a software system does not contain vulnerable or malicious components. Thus, SCA is an important complement to endpoint security. ###  Deploying endpoint protection while respecting employee privacy Endpoint security solutions can be a double-edged sword while enhancing security. They can be used to monitor private data and Internet activity, and thus might have an impact on the privacy of employees using those endpoints. For example, smartphones and tablets are often used for personal as well as business purposes, which means they include private and sensitive information belonging to a company’s employees. Organizations must reconcile the requirement to protect company and customer data with the privacy rights of employees mandated by the GDPR. The GDPR allows monitoring employees if organizations follow certain rules regarding the extent of the monitoring and the handling of data collected as part of this activity. Organizations can monitor data for security purposes if they demonstrate that the benefits of security significantly outweigh the reduction in employee and customer privacy. If the organization cannot demonstrate a substantial increase in security, it cannot legally implement data collection and subsequent security protocols. This requirement applies to monitoring device usage on laptops, mobile devices, and desktops. The GDPR stipulates requirements governing how organizations secure employees’ corporate-owned mobile devices. Organizations using mobile security products like enterprise mobility management (EMM) systems must adapt their solution to comply with GDPR requirements such as: - Keep a record of how and when employees consent to store and use their personal data. - Record where the data came from and the parties it was shared with. - Conduct an information audit to ensure transparency and accountability in the event of unauthorized access to employee data. ## HIPAA and Endpoint Protection Enacted in 1996, the US Health Insurance Portability and Accountability Act (HIPAA) requires that healthcare providers protect patient data against unauthorized access and improper usage. Failure to comply with its guidelines can result in fines and other severe consequences for health providers and their partners. The [HIPAA Security Rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/) requires organizations to maintain reasonable administrative, technical, and physical security controls to safeguard protected health information (PHI). This includes: - Ensuring that any PHI the organization creates, receives, maintains, or transmits, is protected to ensure confidentiality, integrity, and availability. - Protecting PHI and related systems against threats to its security or integrity, unauthorized use, or disclosure. One way to meet these requirements is implementing multi-factor authentication (MFA) for systems that store or have access to PHI. Restricting access to sensitive systems across healthcare organizations not only safeguards data against outside attackers but ensures that staff is accessing data based on their level of privileges. Another important aspect is proactive prevention. Endpoint security solutions can safeguard the data and workflows associated with the individual devices that connect to your network, and examine files as they enter the network. Deploying endpoint protection on all devices that have access to PHI can help prevent various threats, including malware and ransomware. ## PCI DSS and Endpoint Protection The Payment Card Industry Data Security Standard (PCI DSS) is a set of policies and procedures intended to ensure the security of credit, debit, and cash card transactions, and protect cardholders against misuse of their personal information. There are three key PCI DSS requirements that can be met with the help of endpoint security technologies. ### Installing firewall software One of the PCI DSS requirements is to install firewall software or equivalent functionality on any computing device that connects to the Internet and is also used to access the cardholder data environment (CDE). Endpoint protection solutions typically include a device firewall and can block or detect malicious activity on the endpoint. They provide real-time visibility into inbound/outbound network connections across the organization. The contextual analysis allows security teams to inspect every file on endpoints and determine if an unknown or malicious file is responsible for an unauthorized network connection. ### Configuration standards to address security vulnerabilities Another PCI DSS requirement is to develop configuration standards for all system components, addressing all known security vulnerabilities in line with system hardening standards. Endpoint protection solutions can support this by defining organization-wide policies, which provide complete control over the security configuration on each endpoint. ### Deployment of anti-malware Additional PCI DSS requirements that can be met with the aid of endpoint security are the deployment of anti-malware solutions on endpoints, verifying that anti-malware is up to date, and generating an audit log of anti-malware software. Endpoint security deploys anti-malware functionality consistently across all endpoints and can provide an audit trail that meets [PCI requirements](https://www.atlantic.net/pci-compliant-hosting/what-is-pci-compliance/). ## Conclusion In this article, I explained the basics of endpoint protection, and showed how endpoint protection can help fulfill important requirements of three compliance standards: - **GDPR** – endpoint protection can help ensure the confidentiality and integrity of data processing systems and services, and make it easier to restore access to personal data in a timely manner. - **HIPAA** – endpoint protection can ensure that PHI is protected to ensure confidentiality, integrity, and availability, and that related systems are properly defended against reasonably expected threats. - **PCI DSS** – endpoint protection can help with three PCI DSS cybersecurity requirements: deploying firewalls, implementing configuration standards, and deploying anti-malware. I hope this will be useful as you leverage modern security technology to ease your organization’s compliance efforts. Atlantic.Net stands ready to help you attain fast compliance with a range of certifications, such as SOC 2 and SOC 3, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/), and HITECH, all with 24x7x365 support, monitoring, managed security services, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, visit us at www.atlantic.net, call 866-618-DATA (3282), or email us at sales@atlantic.net. --- # How to Install phpMyAdmin on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-phpmyadmin-on-arch-linux/ | Published: 2022-12-18 | Updated: 2023-11-18 | Author: Hitesh Jethva phpMyAdmin is a management console for MySQL and MariaDB database. It allows users to interact with MySQL and MariaDB via a web browser. It is designed for users who are not familiar with MySQL command line. You can use phpMyAdmin to browse, create, edit and delete tables, as well as modify columns and data from the central place. In this post, we will show you how to install phpMyAdmin on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list if you have not done so already. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Apache Web Server First, you will need to install the Apache web server package on your server. You can install it using the following command: ``` pacman -S apache ``` Once Apache is installed, start and enable the Apache service with the following command: ``` systemctl start httpd systemctl enable httpd ``` You can verify the Apache status using the following command: ``` systemctl status httpd ``` ## Step 3 – Install MySQL Server Next, you will need to install the MySQL database server on your server. You can install it with the following command: ``` pacman -S mysql ``` Once MySQL is installed, initialize the MySQL database with the following command: ``` mysql_install_db --user=mysql --basedir=/usr --datadir=/var/lib/mysql ``` Next, start and enable the MySQL service using the following command: ``` systemctl enable mysqld systemctl start mysqld ``` Next, run the following command to secure the MySQL installation and set the root password: ``` mysql_secure_installation ``` Answer all the questions as shown below: ``` Switch to unix_socket authentication [Y/n] Y Change the root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` ## Step 4 – Install PHP Next, you will also need to install PHP on your server. You can install it with the following command: ``` pacman -S php php-apache ``` Once PHP is installed, edit the PHP configuration file: ``` nano /etc/php/php.ini ``` Add the following lines to enable the required extensions: ``` extension=bz2.so extension=mcrypt.so extension=mysqli.so ``` Save and close the file when you are finished. ## Step 5 – Install phpMyAdmin By default, the phpMyAdmin package is included in the Arch Linux default repository. You can install it with the following command: ``` pacman -S phpmyadmin ``` Next, edit the phpMyAdmin configuration file and define the blowfish secret. ``` nano /etc/webapps/phpmyadmin/config.inc.php ``` Change the following line: ``` $cfg['blowfish_secret'] = 'My_Secret'; ``` Save and close the file when you are done. ## Step 6 – Configure Apache for phpMyAdmin Next, edit the Apache default configuration file: ``` nano /etc/httpd/conf/httpd.conf ``` Comment out the following line: ``` #LoadModule mpm_event_module modules/mod_mpm_event.so ``` Uncomment the following line: ``` LoadModule mpm_prefork_module modules/mod_mpm_prefork.so ``` Add the following lines: ``` LoadModule php_module modules/libphp.so AddHandler php7-script php Include conf/extra/php_module.conf Include conf/extra/phpmyadmin.conf ``` Save and close the file, then create an Apache virtual host configuration file: ``` nano /etc/httpd/conf/extra/phpmyadmin.conf ``` Add the following lines: ``` Alias /phpmyadmin "/usr/share/webapps/phpMyAdmin" DirectoryIndex index.php AllowOverride All Options FollowSymlinks Require all granted ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 7 – Access phpMyAdmin Web Interface Now, open your web browser and access the phpMyAdmin web interface using the URL **http://your-server-ip/phpmyadmin.** You should see the phpMyAdmin login page: ![phpMyAdmin Login page](https://www.atlantic.net/wp-content/uploads/2022/09/p1-18-1024x615.png) Provide your MySQL root user and password and click on the **Login** button. You should see the phpMyAdmin dashboard on the following screen: ![phpMyAdmin dashboard page](https://www.atlantic.net/wp-content/uploads/2022/09/p2-14-1024x508.png) ## Conclusion In this post, we explained how to install phpMyAdmin on Arch Linux. You can now use phpMyAdmin to interact with MySQL and perform several tasks via a web browser. You can now try to deploy phpMyAdmin on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Critical OpenSSL Security Vulnerability > URL: https://www.atlantic.net/vps-hosting/critical-openssl-security-vulnerability/ | Published: 2022-12-19 | Updated: 2025-09-15 | Author: Richard Bailey *Atlantic.Net is providing this security advisory as a news item. We want to reassure our customers that Atlantic.Net is not affected internally or in our service offerings by the exploited products.* On the 1st of November 2022, a Common Vulnerabilities and Exposures (CVE) statement was released about an exploit found in the widely used OpenSSL protocol. OpenSSL is an essential piece of software used by millions of people around the world, though many users are unaware their server is using it. In this article, we will learn what OpenSSL is, discover the details of this vulnerability and how it affects Linux, Windows, and macOS users differently, and assess its likely impact. ## What Is OpenSSL? OpenSSL is a general-purpose, open-source cryptographic library. OpenSSL supports secure communications between applications and servers. It is used for various purposes, including email encryption, authentication, and [digital signatures](https://contractbook.com/blog/what-is-a-digital-signature), and unfortunately, it’s not the first time OpenSSL has become vulnerable. It was initially developed over 20 years ago by ‘The OpenSSL Project.’ It has remained free to use and distribute in commercial or non-commercial projects. This approach has led to widespread use within most Linux distributions and is frequently embedded within cloud applications. The main features of this cryptography library are: - **Hashing:** an algorithm that takes an arbitrary amount of data and produces a fixed-size output. This output is also known as a hash, and in cryptography, it is often used as a type of encryption/decryption tool. - **Symmetric Encryption:** an encryption type where only one key is used to encrypt or decrypt, sometimes called Secret Key Cryptography. - **Public Key Cryptography:** an encryption scheme that uses two mathematically related, but not identical, [keys](https://www.globalsign.com/en/ssl-information-center/what-is-public-key-cryptography) – a public key and a private key. - **Key Agreement:** a simple way to let two or more parties exchange information without allowing them to communicate openly is by using a shared encryption key that protects both parties. - **Certificate Handing:** a cryptographic certificate allows users to access public keys. It will enable others to trust the public key. - **Pseudo-Random Number Generator (PRNG):** an algorithm that uses mathematical formulas to produce sequences of random numbers. - **Message Authentication Code (MAC):** a block of a few bytes used to authenticate a message. - **Hash Message Authentication Code (HMAC):** a message authentication code with an authentication key with a hash function. - **Key Derivation Function (KDF):** an algorithm that uses a secret key, such as a master key, to derive one or more secret keys from a string of data, such as a fingerprint. OpenSSH also uses it as part of the secure shell protocol, explicitly the OpenSSL libcrypto and zlib libraries. Thankfully, it does not use SSL/TLS to make a secure connection. ## Details of the OpenSSL Security Vulnerability In late October 2022, OpenSSL developers announced they would release OpenSSL 3.7 to fix a critical flaw in the OpenSSL 3 protocol. [OpenSSL](https://www.openssl.org/news/vulnerabilities.html) advised that the vulnerability allowed an attacker to trigger a buffer overrun in X.509 certificate verification. It allowed a skilled hacker to exploit certificate verification despite failure to construct a path to the trusted issue. This means the vulnerability could result in a stack overflow causing the affected system to crash, inducing a denial of service, and potentially allowing remote code execution on the endpoint. The only version affected by the exploit is OpenSSL 3; the first stable version of OpenSSL 3.0 was released in September 2021. Any older operating systems or appliances that use Linux will likely be using OpenSSL 1.1.1, which is not affected. However, the only way to be sure is to check manually. ## Known Linux Operating Systems that Use OpenSSL 3 OpenSSL is installed by default on most Linux distributions; however, only a handful use the exploitable version OpenSSL 3. These tend to be much newer Linux distributions. The known Linux distributions potentially impacted are: - CentOS Stream 9 (OpenSSL Version 3.0.1) - Fedora 36 (OpenSSL Version 3.0.5) - Fedora Rawhide (OpenSSL Version 3.0.5) - Kali 2022.3 (OpenSSL Version 3.0.5) - Linux Mint 21 Vanessa (OpenSSL Version 3.0.2) - Mageia Cauldron (OpenSSL Version 3.0.5) - OpenMandriva 4.3 (OpenSSL Version 3.0.3) - OpenMandriva Cooker (OpenSSL Version 3.0.6) - Redhat EL 9 (OpenSSL Version 3.0.0) - Rocky Linux 9.0 Blue Onyx (OpenSSL Version 3.0.1) - Ubuntu 22.04 (OpenSSL Version 3.0.2) ## What About Mac and Windows Users? For Mac users, by default, the macOS uses LibreSSL and not OpenSSL. However, other software may install OpenSSL later, particularly applications installed using homebrew tools like brew.sh. OpenSSL is not installed by default on Windows Desktop or Windows Server operating system; likewise, other applications may install OpenSSL. ## How Do I Check What Version of OpenSSL I Am Using? Checking the version of OpenSSL is simple; you type on the command line OpenSSL version. It’s the same command on Linux, Mac, and Windows. The server will respond with either the OpenSSL version being used or the command will give an error. If you get an error, OpenSSL is not installed on your system. ## What Can You Do to Protect Yourself? The first recommendation we offer is to review your OpenSSL version, and if the issue impacts you, download and install [OpenSSL version 3.0.7](https://www.openssl.org/source/), which includes a fix for the problem. If you own a business that needs to focus on cybersecurity for whom parts of your business reside on the internet, we encourage you to reach out to us. Working with someone with extensive cyber security experience will help your business remain independent from these issues. We specialize in managed services, business cloud [VPS hosting](https://www.atlantic.net/vps-hosting/), and [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/). We are security specialists who help you reduce the threats to your business and plan for them before they happen. Our managed services can reduce your daily cyber security attention. In addition, we provide cloud-based solutions and technology for your business to move beyond essential safeguards in cybersecurity that require daily maintenance. [Get in touch with us today](https://www.atlantic.net/about-us/corporate-contact/) to receive a detailed proposal. --- # Is There Such a Thing as a Green Data Center? Sustainability and the Data Center > URL: https://www.atlantic.net/dedicated-server-hosting/is-there-such-a-thing-as-a-green-data-center-sustainability-and-the-data-center/ | Published: 2022-12-20 | Updated: 2023-11-16 | Author: Richard Bailey Climate change awareness is growing. With every passing day, the world’s population is understanding more about their carbon footprint and how it affects the climate. This growing awareness has led to increased interest in a more significant concerted effort to create a sustainable lifestyle for future humans. The IT industry relies on large amounts of electricity, and data centers consume large amounts of power and emit vast quantities of heat and noise. In addition to the energy needs to run the hardware, data centers need even more electricity to cool IT systems. Most rely on generators that burn fossil fuel as an alternative power source in the event of power issues. The industry is aware of these issues, and there is a greater emphasis on sustainability in the cloud. Innovative technologies are being introduced to lower carbon footprint and increase efficiency. Cloud providers have invested vast amounts of money in green technology. As a result, customers expect providers to minimize their environmental footprint. Join us as we discover how green the data center is and learn some innovative steps to make the IT industry as green as possible. ## How Much Is Power Needed to Run the Cloud? If you ever step inside a data center, you will enter a noisy, power-hungry environment. You will be shrouded by hot aisles, cold aisles, and a clean, dry atmosphere. Servers, storage, and networking appliances draw power from the grid with an insatiable thirst. As a result, data center power consumption levels continue to grow yearly. Traditional on-premise data centers are using much less energy these days. This is simply because everyone is moving to the cloud, so the number of on-premise data centers has dropped significantly in recent years. So, unsurprisingly, cloud data centers are consuming an ever-increasing amount of electricity. It is estimated that the total electricity usage of all global data centers is about [105 TWh (terawatt hours)](https://www.statista.com/statistics/186992/global-derived-electricity-consumption-in-data-centers-and-telecoms/), about [6% of all the electricity consumed](https://www.statista.com/statistics/280704/world-power-consumption/#:~:text=Global%20electricity%20consumption%201980%2D2019&text=The%20world's%20electricity%20consumption%20has,increased%20by%20roughly%2075%20percent.) on Earth, which is estimated at around 24,000 TWh. This data is from May 2021, so these numbers are likely even higher now, but Cloud providers total approximately [72 twH](https://www.statista.com/statistics/186992/global-derived-electricity-consumption-in-data-centers-and-telecoms/), roughly 70% of data center power consumption. ## What Is Being Done to Combat This Threat? These figures may seem depressing, but much work is being done to make the data center green. As technology evolves, servers and data center appliances are getting more energy efficient, components are using less power for equal or greater performance, and cloud providers are managing server capacity to reduce wastage. Changes to the manufacturing process of computing components are taking shape by using fewer natural resources, reducing pollution, and increasing the use of recycled and reused materials. It may seem surprising, but the manufacturing of computing components has the most significant impact on the environment. For example, silicone mining is dirty, inefficient work that pollutes the atmosphere. As a result, manufacturers are switching away from cheaper Chinese factories which may have a more significant environmental impact. Cloud providers are switching to greener data centers that use environmental cooling solutions. Modern data centers pump cold water from rivers into their cooling systems and either continue to reuse or purify it and return it to the water source. In some regions, [water is pumped to farmers](https://www.datacenterdynamics.com/en/opinions/an-industry-in-transition-1-data-center-water-use/) to irrigate their crops! In the cooler months, water stewardship conservation switches off water usage, instead cooling the data center using the air. More data centers are being powered by wind and solar power farms, and Microsoft has even [trialed an underwater](https://news.microsoft.com/innovation-stories/project-natick-underwater-datacenter/) availability zone. The R&D project was hugely successful and involved sinking several self-contained capsules underwater. The reliability of the components was a surprise to all, with no severe hardware issues during the trial. ## Use Technology to Make the Data Center Greener We have already mentioned hot and cold aisles in the data center. This conserves energy by using the server to manage airflow. The front of a server sucks air in, and the rear acts as an exhaust. Server racks are positioned opposite each other, with cold air pumped up the middle aisle (feeding two rows of servers), and hot air is pumped into the rear of each row. Air conditioning units suck the hot air out, creating a highly efficient airflow environment. Cloud providers are using AI to assist in data center cooling, and the data center is full of sensors for temperature and humidity. The data is fed into an AI algorithm that controls cooling and power consumption, increasing energy efficiency even more. It has been suggested that AI can save up to 40% on cooling costs. Modern data centers are switching away from fossil fuels for generators. These are used as backup power sources. Despite being irregularly used, they are dirty and burn thousands of gallons of diesel to keep running. Generators are only ever used for testing load or running data centers if there is a power cut, but when used, they can run for days or weeks. A [Dutch data center](https://www.smart-energy.com/industry-sectors/distributed-generation/dutch-data-centre-saves-on-diesel-with-new-hydrogen-fuel-cells/) recently installed hydrogen-powered fuel cells. This saved a staggering 78,000 tons of carbon in a single year! ## What Can You Do To Make The Cloud Greener? If possible, switch off your non-essential servers when not in use. This could be in the evenings or weekends, even when one of your employees is on annual leave. Shutdown and StartUp scripts can be created using Infrastructure as Code tools such as Terraform. Combine this approach by right-sizing your instances. Only use an instance plan that you need. Overprovisioning is wasteful and costs you money. Cut down on e-waste by responsibly destroying legacy and redundant computer hardware. Recycling locations for computer hardware are readily available. Avoid placing in the trash – computer components contain toxic materials like lead, cadmium, mercury, and chromium, so be mindful when equipment reaches its end of life. Data centers inherently consume a great deal of power, and companies that rely heavily on cloud services are facing difficulties when considering their commitment to green initiatives. While data centers are generally designed to be as environmentally friendly as possible with current tech, new technologies will probably make more energy-efficient data centers possible in the future. As new data centers are built due to overwhelming popularity over the coming years, the decisions made in the building process will prove critical for future generations. In addition, because the information technology industry must reinvent its systems every two or three years, data center operators need to remind themselves of corporate responsibility in continuously supporting sustainable development. We offer cold aisle, hot aisle cooling, and shared hosting services that can reduce carbon footprint. In addition, we are always looking for ways to enhance our cooling systems to continue to try to reduce our carbon footprint. Give us a call today to discuss various shared and [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) options [sales@atlantic.net](mailto:sales@atlantic.net) or 866-618-DATA (3282) --- # How to Install a LEMP Stack on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-a-lemp-stack-on-arch-linux/ | Published: 2022-12-21 | Updated: 2023-11-13 | Author: Hitesh Jethva LEMP is a group of open-source software stacks used for developing and deploying highly-scaled applications across the web. In a LEMP stack, L stands for Linux, E is for Nginx, M is for MariaDB or MySQL, and P stands for PHP, Perl, or Python. With the LEMP stack, you can host websites and web applications, especially small to medium-sized sites on the web. In this post, we will show you how to install a LEMP stack on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Nginx Web Server First, install the latest version of Nginx using the following command: ``` pacman -S nginx-mainline ``` Once Nginx is installed, start and enable the Nginx service using the following command: ``` systemctl start nginx systemctl enable nginx ``` Next, check the status of Nginx with the following command: ``` systemctl status nginx ``` You should get the following output: ``` ● nginx.service - A high performance web server and a reverse proxy server Loaded: loaded (/usr/lib/systemd/system/nginx.service; disabled; preset: disabled) Active: active (running) since Tue 2022-09-27 04:50:37 UTC; 45s ago Process: 54810 ExecStart=/usr/bin/nginx -g pid /run/nginx.pid; error_log stderr; (code=exited, status=0/SUCCESS) Main PID: 54813 (nginx) Tasks: 2 (limit: 2362) Memory: 2.1M CGroup: /system.slice/nginx.service ├─54813 "nginx: master process /usr/bin/nginx -g pid /run/nginx.pid; error_log stderr;" └─54814 "nginx: worker process" Sep 27 04:50:36 archlinux systemd[1]: Starting A high performance web server and a reverse proxy server... ``` ## Step 3 – Install MariaDB Database Server You can install the MariaDB database server using the following command: ``` pacman -S mariadb ``` Once MariaDB is installed, initialize the database with the following command: ``` mysql_install_db --user=mysql --basedir=/usr --datadir=/var/lib/mysql ``` Next, start the MariaDB service and enable it to start at system reboot with the following command: ``` systemctl start mysqld systemctl enable mysqld ``` You can check the MariaDB service status using the following command: ``` systemctl status mysqld ``` You should see the following output: ``` ● mariadb.service - MariaDB 10.9.3 database server Loaded: loaded (/usr/lib/systemd/system/mariadb.service; disabled; preset: disabled) Active: active (running) since Tue 2022-09-27 04:52:59 UTC; 5s ago Docs: man:mariadbd(8) https://mariadb.com/kb/en/library/systemd/ Process: 54951 ExecStartPre=/bin/sh -c systemctl unset-environment _WSREP_START_POSITION (code=exited, status=0/SUCCESS) Process: 54952 ExecStartPre=/bin/sh -c [ ! -e /usr/bin/galera_recovery ] && VAR= || VAR=`cd /usr/bin/..; /usr/bin/galera_recovery`; [ $> Process: 54989 ExecStartPost=/bin/sh -c systemctl unset-environment _WSREP_START_POSITION (code=exited, status=0/SUCCESS) Main PID: 54978 (mariadbd) Status: "Taking your SQL requests now..." Tasks: 11 (limit: 2362) Memory: 77.1M CGroup: /system.slice/mariadb.service └─54978 /usr/bin/mariadbd ``` Next, secure the MariaDB installation using the following command: ``` mysql_secure_installation ``` Answer all the questions as shown below: ``` Switch to unix_socket authentication [Y/n] Y Change the root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` ## Step 4 – Install PHP and PHP-FPM You can install PHP and PHP-FPM using the following command: ``` pacman -S php php-fpm ``` Next, start and enable the PHP-FPM service: ``` systemctl start php-fpm systemctl enable php-fpm ``` Next, edit the Nginx main configuration file: ``` nano /etc/nginx/nginx.conf ``` Add the following line below http{: ``` server_names_hash_bucket_size 64; include sites-enabled/*; ``` Save and close the file when you are done. ## Step 5 – Verify PHP First, create a directory for Nginx virtual host with the following command: ``` mkdir /etc/nginx/sites-enabled ``` Next, create an Nginx virtual host file: ``` nano /etc/nginx/sites-enabled/example.com ``` Add the following code: ``` server { listen 80; server_name test.example.com; error_log /var/log/nginx/error.log warn; location / { root /usr/share/nginx/html/; index index.php index.html index.htm; } location ~ \.php$ { fastcgi_pass unix:/var/run/php-fpm/php-fpm.sock; fastcgi_index index.php; root /usr/share/nginx/html; include fastcgi.conf; } } ``` Save and close the file, then create an **index.php** file: ``` nano /usr/share/nginx/html/index.php ``` Add the following code: ``` ``` Finally, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` Now, open your web browser and verify PHP using the URL **http://test.example.com.** You should see the PHP information page on the following screen: ![PHP test page](https://www.atlantic.net/wp-content/uploads/2022/09/p2-13-1024x547.png) ## Conclusion In this post, we explained how to install a LEMP server on Arch Linux. You can now use the LEMP stack in the production environment and start developing and deploying high-performance web applications on the internet. Try to install LEMP on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install a LAMP Stack on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-a-lamp-stack-on-arch-linux/ | Published: 2022-12-22 | Updated: 2023-11-15 | Author: Hitesh Jethva LAMP is an open-source Web development platform used for hosting highly-scalable websites on the web. It uses Linux as the operating system, Apache as a web server, MariaDB or MySQL as a database server, and PHP, Python, or Perl as a programming language. A LAMP stack is an efficient and flexible method that enables competition with commercial software developers. As per global research, up to 80% of the Internet uses open-source programming and software. In this post, we will show you how to install a LAMP stack on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Apache Web Server First, install the Apache web server with the following command: ``` pacman -Sy apache ``` Next, start the Apache service and enable it to start on system reboot: ``` systemctl start httpd systemctl enable httpd ``` You can now check the status of Apache with the following command: ``` systemctl status httpd ``` You should see the following output: ``` ● httpd.service - Apache Web Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; preset: disabled) Active: active (running) since Tue 2022-09-27 05:56:18 UTC; 2s ago Main PID: 55616 (httpd) Tasks: 82 (limit: 2362) Memory: 6.8M CGroup: /system.slice/httpd.service ├─55616 /usr/bin/httpd -k start -DFOREGROUND ├─55617 /usr/bin/httpd -k start -DFOREGROUND ├─55618 /usr/bin/httpd -k start -DFOREGROUND └─55619 /usr/bin/httpd -k start -DFOREGROUND Sep 27 05:56:18 archlinux systemd[1]: Started Apache Web Server. ``` Next, create a simple index.html file to test the Apache web server. ``` nano /srv/http/index.html ``` Add the following codes: ``` LAMP

Welcome to LAMP Server

``` Save and close the file, then open your web browser and access the Apache web page using the URL **http://your-server-ip.** You should see the following screen: ![Apache test page](https://www.atlantic.net/wp-content/uploads/2022/09/p1-17-1024x366.png) ## Step 3 – Install MySQL Database Server By default, the MySQL server package is included in the Arch Linux default repository. You can install it with the following command: ``` pacman -S mariadb ``` Next, initialize the MySQL database with the following command: ``` mysql_install_db --user=mysql --basedir=/usr --datadir=/var/lib/mysql ``` Next, start and enable the MySQL service with the following command: ``` systemctl enable mysqld systemctl start mysqld ``` ## Step 4 – Install PHP Next, install PHP and other required extensions using the following command: ``` pacman -S php php-apache ``` Once PHP is installed, edit the Apache configuration file and add PHP modules: ``` nano /etc/httpd/conf/httpd.conf ``` Comment out the following line: ``` #LoadModule mpm_event_module modules/mod_mpm_event.so ``` Uncomment the following line: ``` LoadModule mpm_prefork_module modules/mod_mpm_prefork.so ``` Add the following lines at the end of the file: ``` LoadModule php_module modules/libphp.so AddHandler php7-script php Include conf/extra/php_module.conf ``` Save and close the file when you are finished. ## Step 5 – Verify PHP Installation Next, create a simple PHP file inside the Apache web root directory: ``` nano /srv/http/info.php ``` Add the following code: ``` ``` Save and close the file, then restart the Apache server to apply the changes: ``` systemctl restart httpd ``` Now, open your web browser and verify the PHP using the URL **http://your-server-ip/info.php.** You should see the PHP page on the following screen: ![PHP test page](https://www.atlantic.net/wp-content/uploads/2022/09/p2-12-1024x514.png) ## Conclusion In this post, we explained how to install the LAMP server on Arch Linux. You can now use the LAMP stack on the production environment and start developing and deploying a PHP-based application on the web. Try to install LAMP on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Nginx Web Server on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-nginx-web-server-on-arch-linux/ | Published: 2022-12-24 | Updated: 2023-11-15 | Author: Hitesh Jethva Nginx also known as engine-X, is a free and open-source web server used to host a website on the web. Simple and lightweight, it is often used as a reverse proxy, an HTTP cache, for load balancing, and for media streaming. Nginx uses an asynchronous, event-driven approach instead of creating new processes for each web request. Nginx is known for its high performance, security, stability, rich feature set, simple configuration, and low resource consumption. In this post, we will show you how to install the Nginx web server on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Nginx Web Server By default, the Nginx web server package is included in the Arch Linux default repository. You can install it using the following command: ``` pacman -S nginx-mainline ``` Once Nginx is installed, start and enable the Nginx service using the following command: ``` systemctl start nginx systemctl enable nginx ``` You can check the status of Nginx with the following command: ``` systemctl status nginx ``` You should see the following output: ``` ● nginx.service - A high performance web server and a reverse proxy server Loaded: loaded (/usr/lib/systemd/system/nginx.service; disabled; preset: disabled) Active: active (running) since Tue 2022-09-27 04:46:29 UTC; 4s ago Process: 54784 ExecStart=/usr/bin/nginx -g pid /run/nginx.pid; error_log stderr; (code=exited, status=0/SUCCESS) Main PID: 54785 (nginx) Tasks: 2 (limit: 2362) Memory: 2.1M CGroup: /system.slice/nginx.service ├─54785 "nginx: master process /usr/bin/nginx -g pid /run/nginx.pid; error_log stderr;" └─54786 "nginx: worker process" Sep 27 04:46:29 archlinux systemd[1]: Starting A high performance web server and a reverse proxy server... ``` Now, open your web browser and access the Nginx test page using the URL **http://your-server-ip.** You should see the following page: ![Nginx test page](https://www.atlantic.net/wp-content/uploads/2022/09/p1-16-1024x445.png) ## Step 3 – Create an Nginx Virtual Host With Nginx virtual hosting feature, you can host multiple websites on a single server. First, create your website directory using the following command: ``` mkdir /usr/share/nginx/example.com ``` Next, create an index.html file for your website using the following command: ``` nano /usr/share/nginx/example.com/index.html ``` Add the following codes: ``` Nginx Web Server

Welcome to Nginx Web Server

``` Next, create a directory to store your website content: ``` mkdir /etc/nginx/sites-enabled ``` Next, create an Nginx virtual host configuration file with the following command: ``` nano /etc/nginx/sites-enabled/example.com ``` Add the following configurations: ``` server { listen 80; server_name test.example.com; location / { root /usr/share/nginx/example.com; index index.html index.htm; } } ``` Save and close the file, then edit the Nginx main configuration file: ``` nano /etc/nginx/nginx.conf ``` Add the following lines below the line http{: ``` include sites-enabled/*; server_names_hash_bucket_size 64; ``` Save and close the file then verify Nginx for any syntax configuration error: ``` nginx -t ``` You will get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 4 – Verify Nginx Virtual Host Now, open your web browser and access your Nginx website using the URL **http://test.example.com.** You should see the Nginx website page on the following screen: ![Nginx virtual host test page](https://www.atlantic.net/wp-content/uploads/2022/09/p2-11.png) ## Conclusion In this post, we explained how to install the Nginx web server on Arch Linux. We also explained how to create a website using the Nginx virtual hosting feature. You can now host multiple websites on a single server using Nginx. Now, try the Nginx web server on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Apache Web Server on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-web-server-on-arch-linux/ | Published: 2022-12-25 | Updated: 2023-11-15 | Author: Hitesh Jethva Free and open-source Apache is one of the most popular web servers around the globe. It is based on process-driven architecture and supports all major operating systems, including Linux, Windows, macOS, and Solaris. Apache is customizable and can be integrated with other modules. It offers many features, including load balancing, URL tracking, auto-indexing, robust media support, and more. This post will explain how to install the Apache web server on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Apache Web Server By default, the Apache web server package is included in the Arch Linux default repository. You can install it using the following command: ``` pacman -S apache ``` Once the Apache package is installed, start and enable the Apache service with the following command: ``` systemctl start httpd systemctl enable httpd ``` You can also check the Apache status using the following command: ``` systemctl status httpd ``` You will get the following output: ``` ● httpd.service - Apache Web Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; preset: disabled) Active: active (running) since Tue 2022-09-27 04:41:54 UTC; 6s ago Main PID: 54484 (httpd) Tasks: 82 (limit: 2362) Memory: 6.8M CGroup: /system.slice/httpd.service ├─54484 /usr/bin/httpd -k start -DFOREGROUND ├─54485 /usr/bin/httpd -k start -DFOREGROUND ├─54486 /usr/bin/httpd -k start -DFOREGROUND └─54487 /usr/bin/httpd -k start -DFOREGROUND Sep 27 04:41:54 archlinux systemd[1]: Started Apache Web Server. Sep 27 04:41:54 archlinux httpd[54484]: AH00558: httpd: Could not reliably determine the server's fully qualified domain name, using fe80::20> ``` By default, the Apache package does not provide any default **index.html** file to test the Apache. You can create it in the Apache default root directory using the following command: ``` nano /srv/http/index.html ``` Add the following code: ``` Welcome

Welcome to Atlantic Cloud test page

``` Save and close the file, then open your web browser and verify the Apache test page using the URL **http://your-server-ip.** You should see the Apache page on the following screen: ![Apache test page](https://www.atlantic.net/wp-content/uploads/2022/09/p1-15.png) ## Step 3 – Create an Apache Virtual Host Virtual hosting allows users to host multiple websites on a single server. First, create a directory for virtual hosts using the following command: ``` mkdir /etc/httpd/conf/vhosts ``` Next, create an Apache virtual host configuration file: ``` nano /etc/httpd/conf/vhosts/example.com ``` Add the following code: ``` ServerAdmin webmaster@example.com DocumentRoot "/srv/example.com" ServerName test.example.com ErrorLog "/var/log/httpd/example.com-error_log" CustomLog "/var/log/httpd/example.com-access_log" common Require all granted ``` Save and close the file, then create a website directory with the following command: ``` mkdir /srv/example.com ``` Next, create an index.html page for your website: ``` nano /srv/example.com/index.html ``` Add the following code: ``` Example.COM

Welcome to example.com

``` Save and close the file, then change the ownership of your website: ``` chown -R root:http /srv/example.com ``` Next, edit the Apache main configuration file: ``` nano /etc/httpd/conf/httpd.conf ``` Add the following line to define your virtual host: ``` Include conf/vhosts/example.com ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 4 – Verify Apache Virtual Host Now, open your web browser and verify your website using the URL **http://test.example.com.** You should see your website on the following screen: ![Apache virtual host test page](https://www.atlantic.net/wp-content/uploads/2022/09/p2-10.png) ## Conclusion In this post, we explained how to install the Apache web server on Arch Linux. We also explained how to create a virtual host in Apache. You can now host multiple websites on a single website using Apache’s virtual hosting feature. You can now try to use the Apache web server on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Host Secure IT Infrastructure for Public Schools > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-host-secure-it-infrastructure-for-public-schools/ | Published: 2022-12-26 | Updated: 2026-05-04 | Author: Richard Bailey School IT Departments have had to adapt quickly as computing and cloud technology has changed education significantly over the last 20 years. As a result, the cybersecurity posture of public schools is complex, with several challenges to overcome. Schools have a wide and varied attack surface that is constantly changing, and a [school’s security response](https://www.pelco.com/solutions/industries/education/) has had to evolve as security threats have changed. In this article, we will learn how to secure IT infrastructure in public schools. We will discuss the various threats and discover the challenges and rewards of incredibly tech-savvy students. ## A Complex Security Posture Schools require various layers of cybersecurity protection because there are many moving parts inside a school. School staff, governors, trustees, and volunteers are responsible for improving the school’s understanding of the latest cybersecurity threats. Schools have a duty of care to protect students, including their cybersecurity. Therefore, measures must be in place to protect sensitive student information from internal and external threats while meeting the challenges of funding shortages, understaffing, and lack of physical resources. ### Are Schools a Target? According to [Real Clear Education](https://www.realcleareducation.com/articles/2022/05/04/collective_defense_americas_best_chance_to_safeguard_schools_from_cyberattacks_110729.html), 5.8 million malware attacks in 2021 targeted educational organizations. This evidence suggests that schools need to prepare for the eventuality of frequent cyberattacks. ## What are the Cybersecurity Challenges Public Schools face? The FBI and US Government are increasingly concerned about schools’ cybersecurity risks. Some of the common threats to schools are: - Data Breach: The risk of a data breach in schools is a significant concern. Schools collect personally identifiable information (PII) on students, including social security numbers and safeguarding measures. This data is susceptible and must be protected on computer systems, cloud storage, portable media, and during network transmission. - DDoS: Schools are frequently targeted in distributed denial of service attacks that overload servers to prevent access to critical school websites. - Phishing: Similar to the business world, schools are targeted via phishing campaigns. Students, teachers, and governors are targeted. Spear phishing targeting students (from “teachers”) is a terrible problem. - Malware / Ransomware: Another primary concern to public schools is malware and ransomware. Education can be halted if computer services are compromised and unprepared schools are perceived to have weak security. It just takes one student or teacher to open the door to hackers. - Vulnerable IT Systems: Due to budget constraints or possible lack of IT understanding, unpatched servers or using computers with legacy operating systems or applications increase the risk of systems being compromised. ## How Can Schools Protect IT infrastructure? Students are always keen to learn new ways to interact with IT systems, so educating students on security best practices should be relatively straightforward. **#1: Promote a Security First Agenda:** Teachers need to lead by example and promote responsible usage of IT systems. Rules should be introduced surrounding local laws, policies, and regulations. In addition, students should sign a Responsible Usage Policy that promotes appropriate content, websites, applications, and etiquette for using computer equipment. **#2: Principal of Least Privilege:** Abiding by this rule creates a secure ecosystem for students and teachers. Their access and user permissions should be heavily restricted to prevent users from accessing networked resources, accessing inappropriate content, installing games, etc. **#3: Enhanced Data Protection:** Introduce enhanced data-security measures to protect confidential student records, which are high-value targets for ransomware actors. Data encryption is a minimum requirement, as are strict access controls to the data. Any data stored offsite, perhaps with a cloud services provider, should only be locked down to authorized user access. **#4: Backups:** Also part of data protection, public schools need to back up data regularly every few hours to ensure data integrity. It is helpful to follow the 3-2-1 approach to backups is highly advisable. This strategy keeps three copies of your data; the first is live data, the second is a backup copy, and the third is another copy (preferably at an offsite location). **#4: Protect the Network:** Use a VPN to protect access to offsite services with multifactor authentication. Network firewalls should be strategically placed around the network to protect data flow internally and externally. Technical solutions such as network blocklisting can restrict network access to external sources, and having detailed logging in place will provide an audit trail where computer usage can be investigated. **#5: Know Your IT:** School leaders need to know who manages and coordinates the school’s IT infrastructure. Contact details for managed service providers or website contractors. The public school leadership teams must understand what IT systems are critical parts of the school’s digital estate and where PII is located. **#6: Be Prepared:** Schools need to know what to do in the event of a cybersecurity attack. Reports can be made to local law enforcement, the FBI, the [Internet Crime Commission](https://www.ic3.gov/), the National Cyber Investigative Joint Task Force (cywatch@ic.fbi.gov), and the US [Computer Emergency Readiness Team](https://www.cisa.gov/). ## Security Defined Cloud Services Atlantic.Net is a cloud services provider with over 30 years of experience providing security-defined hosting services. We offer business-class [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) and cloud hosting solutions focusing on security, compliance, and simplifying the user experience. Atlantic.Net offers fully-managed environments, security, and compliance-focused solutions across all its hosting facilities in San Francisco, New York, London, Toronto, Dallas, Ashburn, and Orlando. With a range of certifications, along with SSAE 18, SOC 2, SOC 3, HIPAA, and HITECH-audited data center infrastructure, Atlantic.Net is a security-first provider. For more information, please visit [www.atlantic.net](https://www.atlantic.net). --- # How to Hide Apache and Nginx Version on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-hide-apache-and-nginx-version-on-oracle-linux-10/ | Published: 2022-12-27 | Updated: 2025-12-06 | Author: Hitesh Jethva By default, Nginx and Apache versions are displayed when you query HTTP headers. Website security is very important for any system or website administrator. For security reasons, it is recommended to hide the Nginx and Apache versions to make it harder for attackers to know what vulnerabilities can be exploited on your server. In this post, we will show you how to hide Apache and Nginx versions on Oracle Linux 10. ## Step 1 – Verify Apache and Nginx Header Details By default, Apache and Nginx will show the version on error pages and in the response header. You can check it using the CURL command: ``` curl --head http://localhost ``` You should see the Apache version information in the following output: ``` Date: Sat, 06 Dec 2025 08:49:45 GMT Server: Apache/2.4.63 (Oracle Linux Server) Last-Modified: Tue, 02 Sep 2025 00:00:00 GMT ETag: "dd3-63dc62b53e000" Accept-Ranges: bytes Content-Length: 3539 Content-Type: text/html; charset=UTF-8 ``` To check the Nginx version information, run the following command: ``` curl --head http://localhost ``` You should see the Nginx version details in the following output: ``` Server: nginx/1.26.3 Date: Sat, 06 Dec 2025 08:49:14 GMT Content-Type: text/html Content-Length: 153 Connection: keep-alive ``` ## Step 2 – Hide Apache Version To hide the Apache version, you will need to edit the Apache configuration file and add the line “ServerTokens Prod”: ``` nano /etc/httpd/conf/httpd.conf ``` Add the following line at the end of the file: ``` ServerTokens Prod ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` Next, check the Apache header using the following command: ``` curl --head http://localhost ``` You should see that there is no version shown: ``` Date: Sat, 06 Dec 2025 08:50:55 GMT Server: Apache Last-Modified: Tue, 02 Sep 2025 00:00:00 GMT ETag: "dd3-63dc62b53e000" Accept-Ranges: bytes Content-Length: 3539 Content-Type: text/html; charset=UTF-8 ``` ## Step 3 – Hide Nginx Version To hide the Nginx version, you will need to edit the Nginx configuration file and add the line “server_tokens off”: ``` nano /etc/nginx/nginx.conf ``` Add the following line after http {: ``` server_tokens off; ``` Save and close the file, then restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` Next, check the Nginx header using the following command: ``` curl --head http://localhost ``` You should see that there is no version shown: ``` Server: nginx Date: Sat, 06 Dec 2025 08:51:57 GMT Content-Type: text/html Content-Length: 146 Connection: keep-alive ``` ## Conclusion In this tutorial, we explained how to hide the Apache and Nginx version on Oracle Linux 10. Hiding the Apache and Nginx version is one of the methods to protect your web server. You can now easily hide your Apache and Nginx versions in the production environment. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Top Considerations While Designing A HIPAA Compliant Website > URL: https://www.atlantic.net/hipaa-compliant-hosting/top-considerations-while-designing-a-hipaa-compliant-website/ | Published: 2022-12-28 | Updated: 2026-03-01 | Author: Richard Bailey U.S. healthcare providers rely on their websites to provide essential patient services. If you are starting with your first website or adding new functionality, it’s vital to keep the legislative requirements of HIPAA compliance at the forefront of the design process. Healthcare practices typically offer a wide range of services online, including telemedicine, live chat, patient portals, and tools for booking and reviewing appointments. Naturally, patient data is needed to make the service meaningful. As a result, Protected Health Information (PHI) is collected, stored, and transmitted via the website. There are strict rules about managing electronic PHI (ePHI), with the covered entity and business associates being responsible for correctly implementing the required physical, technical and administrative safeguards of HIPAA. This article will introduce the fundamental design requirements to keep your website HIPAA compliant. This includes the top considerations for application design and the mandatory requirements of the hosting environment. ## High-Level Overview The necessary safeguards of HIPAA apply to the entire website design process. This includes the appropriate rules for the software application code and hardware restrictions for the web server configuration, the network stack, and all other components that make up the hosting environment. A HIPAA-compliant website requires adherence to hundreds of rules, so outsourcing to a [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) provider is popular. Outsourcing reduces the compliance burden, as the healthcare client plugs into the HIPAA-compliant platform. In addition, this frees up resources, allowing you to focus on website design. ## What Design Rules are Mandatory to be HIPAA-Compliant If you want your website to be HIPAA-compliant, you must oversee every detail of the design process, including how the underlying infrastructure is protected. ### Administrative Preparation: - **Risk Assessment** – Before designing the site, you must perform a risk assessment. The audit looks at any existing environment. If you outsource the website design to an agency, they should cover their products and design principles and identify how PHI data flows through the application. - **Create an Action Plan** – The risk assessment will identify gaps in the healthcare practice’s HIPAA-compliant status, for example, whether the infrastructure meets HIPAA standards. You can engage a [HIPAA-compliant hosting partner](https://www.atlantic.net/hipaa-compliant-hosting/) like Atlantic.Net. The action plan is a roadmap for achieving a HIPAA-compliant website. - **Hire a HIPAA Specialist** – Compliance is complicated, and hiring a seasoned professional can streamline the entire project lifecycle. - **Sign a Business Associate Agreement** – After all the groundwork has been completed it is essential to get a BAA signed by all business associates. This will typically be the website design agency, the hosting provider, and all subcontractors that ‘touch’ PHI. ### Website Design Requirements: - **User Authentication** – Each user has a private account that adheres to the principle of least privilege, where access is only granted to the required PHI. Therefore, only the patient can view their own PHI records. Likewise, website administrators should have no access to any sensitive data. - **Access Controls** – Each website user is assigned a centrally-controlled unique username, password, and multi-factor authentication to access the website. A strong password policy that enforces complex passwords and regular password changes is recommended. Procedures must also be in place to govern when access requests are made to release or disclose ePHI during an emergency. - **Data Backup** – The website configuration should be backed up regularly and copied to a secured offsite location. Infrastructure backups are also routinely required, and all backups must be encrypted and secured with access controls. - **Disaster Recovery Capabilities** – One of the most challenging aspects of HIPAA is that the patients have the right to access their files at all times. As a result, data must be redundant, and website applications should incorporate high availability and failover capabilities. In addition, the site must be able to tolerate failure without crashing or freezing. - **Automated Logout** – Website users must be logged out after a set time frame, usually up to 3 minutes, depending on the application or system. - **Encryption** – The website needs to support encryption throughout the application. Encrypt PHI to a minimum of AES256 cipher protection; when data traverses the stack, it must be encrypted at all layers. ### Infrastructure Design Requirements: - **Network Encryption** – Encrypt access to ePHI using [NIST cryptographic standards](https://csrc.nist.gov/Projects/cryptographic-standards-and-guidelines) to encrypt network traffic. Secure the site with TLS certificates to ensure all traffic is encapsulated with a proven security cipher. - **Defend the Network** – The network stack requires a Web Application Firewall. The WAF is a simple web application firewall service that controls how traffic reaches and traverses your application stack. In addition, the WAF protects against common exploits and threats like SQL injection and cross-site scripting. - **Control Access** – Restrict server access to a few trusted employees or necessary third-party subcontractors. Log all user access and require employees to undergo security background checks before using the platform. - **Authenticate ePHI** – You must identify and authenticate ePHI and protect it from corruption, unauthorized changes, and accidental destruction. This requirement works hand in hand with the website. - **Control Activity Audits** – Detailed server logging is recommended to track all ePHI access attempts and to monitor how ePHI data is manipulated across the hosting platform. Detailed logging creates vast volumes of data. Use a SEIM application to make sense of the data and identify genuine issues. - **Control Facility Access** – The hosting provider must carefully track individuals with physical access to the data center. Protections include CCTV, security patrols, and audited access. ## HIPAA-Compliant Hosting Atlantic.Net is a global cloud service provider with over 30 years of industry-leading experience. We have many happy healthcare clients leveraging Atlantic.Net services for a robust and scalable HIPAA-compliant website. We can provide turn-key hosting solutions that include encrypted VPN connectivity, perfect if your medical organization opts for a cloud-based SaaS web conferring solution. In addition, we encrypt peer-to-peer connections and implement access controls in line with HIPAA safeguard recommendations. Our world-class [HIPAA hosting](https://www.atlantic.net/hipaa-compliant-hosting/) facilities can power your healthcare infrastructure, giving you the performance needed to build your website on our platform.  If you are a healthcare provider in the market for a secure HIPAA-compliant cloud hosting service, [contact our sales team](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) to find out how Atlantic.Net can help you. Make our award-winning platform the host of your [HIPAA-compliant website](https://www.atlantic.net/hipaa-compliant-hosting/how-to-make-website-hipaa-compliant/). --- # How to Install ClickHouse on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-clickhouse-on-oracle-linux-10/ | Published: 2022-12-29 | Updated: 2025-12-06 | Author: Hitesh Jethva ClickHouse is a free, open-source, and fast column-oriented database management system. It is used for generating analytical data reports in real-time using SQL queries. ClickHouse stands for “Clickstream Data Warehouse” which was initially built for web analytics in Yandex Metrica. It is capable of processing billions of rows and tens of gigabytes of data per server per second. It has built-in async replication features and can be deployed across multiple data centers. In this post, we will show you how to install ClickHouse on Oracle Linux 10. ## Step 1 – Install ClickHouse By default, the ClickHouse package is not included in the Oracle Linux default repo, so you will need to create a ClickHouse repo. You can create it with the following commands: ``` dnf update -y ``` ``` nano /etc/yum.repos.d/clickhouse.repo ``` Add the following lines: ``` [altinity_clickhouse] name=altinity_clickhouse baseurl=https://packagecloud.io/altinity/clickhouse/el/7/$basearch repo_gpgcheck=1 gpgcheck=0 enabled=1 gpgkey=https://packagecloud.io/altinity/clickhouse/gpgkey sslverify=1 sslcacert=/etc/pki/tls/certs/ca-bundle.crt metadata_expire=300 [altinity_clickhouse-source] name=altinity_clickhouse-source baseurl=https://packagecloud.io/altinity/clickhouse/el/7/SRPMS repo_gpgcheck=1 gpgcheck=0 enabled=1 gpgkey=https://packagecloud.io/altinity/clickhouse/gpgkey sslverify=1 sslcacert=/etc/pki/tls/certs/ca-bundle.crt metadata_expire=300 ``` Save and close the file, then enable the created repo using the following command: ``` dnf -q makecache -y --disablerepo='*' --enablerepo='altinity_clickhouse' ``` Next, run the following command to install the ClickHouse server and client packages: ``` dnf install -y clickhouse-server clickhouse-client ``` Once both packages are installed, you can proceed to start the ClickHouse service. ## Step 2 – Manage ClickHouse Service By default, the ClickHouse service is managed by systemd. You can start it with the following command: ``` systemctl start clickhouse-server ``` To enable the ClickHouse service, run the following command: ``` systemctl enable clickhouse-server ``` To check the ClickHouse service status, run the following command: ``` systemctl status clickhouse-server ``` You should see the following output: ``` clickhouse-server.service - LSB: Yandex clickhouse-server daemon Loaded: loaded (/etc/rc.d/init.d/clickhouse-server; generated) Active: active (exited) since Sat 2025-12-06 03:44:40 EST; 5s ago Invocation: 6cd92ad0e6214c239e7221cb2f9317cf Docs: man:systemd-sysv-generator(8) Process: 120467 ExecStart=/etc/rc.d/init.d/clickhouse-server start (code=exited, status=0/SUCCESS) Mem peak: 2.9M CPU: 85ms Dec 06 03:44:39 oracle su[120499]: pam_unix(su:session): session opened for user clickhouse(uid=981) by (uid=0) Dec 06 03:44:39 oracle su[120499]: pam_unix(su:session): session closed for user clickhouse Dec 06 03:44:39 oracle su[120502]: (to clickhouse) root on none Dec 06 03:44:39 oracle su[120502]: pam_unix(su:session): session opened for user clickhouse(uid=981) by (uid=0) Dec 06 03:44:39 oracle su[120502]: pam_unix(su:session): session closed for user clickhouse Dec 06 03:44:39 oracle su[120510]: (to clickhouse) root on none Dec 06 03:44:39 oracle su[120510]: pam_unix(su:session): session opened for user clickhouse(uid=981) by (uid=0) Dec 06 03:44:39 oracle su[120510]: pam_unix(su:session): session closed for user clickhouse Dec 06 03:44:40 oracle clickhouse-server[120471]: DONE Dec 06 03:44:40 oracle systemd[1]: Started clickhouse-server.service - LSB: Yandex clickhouse-server daemo ``` ## Step 3 – Create a Database in ClickHouse At this point, ClickHouse is started and running. To connect to ClickHouse, run the following command: ``` clickhouse-client --multiline ``` Once you are connected to ClickHouse, you will get the following shell: ``` ClickHouse client version 20.8.3.18. Connecting to localhost:9000 as user default. Connected to ClickHouse server version 20.8.3 revision 54438. oraclelinux8 :) ``` To create a database named db1, run the following command: ``` CREATE DATABASE db1; ``` You should see the following output: ``` CREATE DATABASE db1 Ok. ``` To verify the created database, run the following command: ``` show databases; ``` You should see the following output: ``` SHOW DATABASES ┌─name───────────────────────────┐ │ _temporary_and_external_tables │ │ db1 │ │ default │ │ system │ └────────────────────────────────┘ ``` ## Step 4 – Create a Table in ClickHouse To create a table, first switch the database to db1 using the following command: ``` USE db1; ``` You will get the following output: ``` USE db1 Ok. ``` Next, create a table named visits and run the following command: ``` CREATE TABLE visits ( id UInt64, duration Float64, url String, created DateTime ) ENGINE = MergeTree() PRIMARY KEY id ORDER BY id; ``` You should see the following output: ``` CREATE TABLE visits ( `id` UInt64, `duration` Float64, `url` String, `created` DateTime ) ENGINE = MergeTree() PRIMARY KEY id ORDER BY id Ok. 0 rows in set. Elapsed: 0.007 sec. ``` Next, to insert some value into the first, second, and third rows, run the following commands: ``` INSERT INTO visits VALUES (1, 12.5, 'http://linuxbuz.com', '2025-05-01 00:01:01'); INSERT INTO visits VALUES (2, 25.2, 'http://atlantic.net', '2025-06-06 10:01:01'); INSERT INTO visits VALUES (3, 20, 'http://example.com', '2025-07-04 02:01:01'); ``` To retrieve the specific value from the table, run the following command: ``` SELECT url, duration FROM visits WHERE url = 'http://atlantic.net.com' LIMIT 2; ``` You should see the following output: ``` SELECT url, duration FROM visits WHERE url = 'http://atlantic.net.com' LIMIT 2 Ok. ``` To retrieve the total duration of visits, run the following command: ``` SELECT SUM(duration) FROM visits; ``` You should see the following output: ``` SELECT SUM(duration) FROM visits ┌─SUM(duration)─┐ │ 57.7 │ └───────────────┘ 1 rows in set. Elapsed: 0.009 sec. ``` To get information about the top two URLs, run the following command: ``` SELECT topK(2)(url) FROM visits; ``` You will get the following output: ``` SELECT topK(2)(url) FROM visits ┌─topK(2)(url)──────────────────────────────────┐ │ ['http://linuxbuz.com','http://atlantic.net'] │ └───────────────────────────────────────────────┘ ``` ## Step 5 – Delete a Database and Table in ClickHouse If you want to delete a table, run the following command: ``` DROP TABLE visits; ``` To delete a database, run the following command: ``` DROP DATABASE db1; ``` ## Conclusion In this post, we explained how to install ClickHouse on Oracle Linux 10. We also explained how to create a database and table and retrieve information in ClickHouse. You can now use ClickHouse as a database in your application. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How Can You Future-Proof Your IT Infrastructure > URL: https://www.atlantic.net/vps-hosting/how-can-you-future-proof-your-it-infrastructure/ | Published: 2022-12-30 | Updated: 2025-09-15 | Author: Richard Bailey Because the IT industry evolves rapidly with new technology consistently being developed and released, IT systems only have a limited shelf life as top-of-the-line solutions until the “next big thing” is out. Even considering, servers are highly reliable, especially when looked after in an appropriate data center environment, and can last for decades. However, consider what’s changed in server hardware over the last ten years. Servers are getting faster, storage is expanding, and technology is getting greener. Therefore, careful consideration is needed when buying expensive computer equipment to ensure that your investment is well-timed and beneficial to the business. Join us to discover if there is another way you can keep your IT systems relevant and future-proofed. ## What Are Your Options? Hardware and software can be costly, often involving a significant outlay of cash to procure the equipment, running costs, hosting expenses, licensing, and annual subscriptions. Therefore, investing in technology that becomes redundant within a few years is not cost-effective. One possible option is to lease server hardware; all global server manufacturers lease equipment on short or long-term leases. A managed hosting provider also leases servers, racks, or the space you need inside a data center. But another option introduces significant cost savings and will future-proof your investment overnight – outsourcing to a [cloud services provider](https://www.atlantic.net/cloud-platform/). A typical, enterprise-ready server will likely cost more than $10,000 for basic hardware. On top of this, you may be looking at high licensing costs if you opt for Microsoft Windows, Red Hat Linux, or any consumer-licensed application such as Microsoft SQL Server or cPanel. With the Cloud, you pay as you go, with costs starting from a few dollars per month. ## How Does The Cloud Protect Your Investment? Future-proofing is not all about reducing costs and protecting your investment; businesses benefit from many advantages when moving to the cloud. Here are some of them: **Security:** The security world is a fast-paced, ever-changing environment where threats evolve daily, and new challenges are faced with every strain of ransomware, malware, and viruses. Cybersecurity is hugely vital to modern business, and there is barely a week that goes past when a big named brand becomes the next hacked victim. When you invest in Cloud technology, you get the primary benefit of security-as-a-service, especially when choosing a provider that architects security and defines service as part of their cloud offerings. Users will no longer need to worry about network security, data encryption, or physical data center security because this is all managed for you.  The user is responsible for maintaining the local security of your servers, such as passwords and patching. **Managed Services:** One critical advantage of choosing a cloud service provider like Atlantic.Net is that you can tailor the service to fit your requirements. These options are great for future-proofing your IT infrastructure because you can add these services whenever you need them. - **Managed Networking** – Our network architects have designed an intrinsically secure network infrastructure that isolates and protects your service, resulting in an entirely privately managed environment that only you can access. Hardware and Software Firewalls are installed strategically around the perimeter and internal networks. In addition, we offer an optional Web Application Firewall (WAF), a policy-defined device that protects web applications by monitoring and filtering traffic via Network Edge Protection. - **Managed Encryption** – With Atlantic.Net, our service is fully encrypted by default and managed by an advanced Key Management System (KMS). All data is encrypted at rest, and in the unlikely event the information is intercepted, it will be wholly unreadable or recoverable without the key. - **Managed Backups and Disaster Recovery** – The Atlantic.Net managed backup services are created per your requirements. File Level, VM-level backups, snapshots, and offsite replication services are available. In the event of a disaster scenario, our optional service will manage the hosting platform to failover infrastructure to a secondary location. - **24x7x365 Support** – Our front-line support teams are available 24x7x365 via email and phone, and we always have someone available at the end of a phone line. The support teams are encouraged to develop and grow with advanced training, helping to ensure our customers get the support they want the first time of calling. If you want to know more about the wide range of managed services available at Atlantic.Net, [please visit our website](https://www.atlantic.net/managed-services/). **Scalability:** By providing flexible scalability, cloud-based technologies allow businesses to meet the computing demands of working with large data sets. Whether your workloads involve highly complicated computations or complex run models, or if you simply need a WordPress server, cloud computing delivers the flexibility and elasticity required to match computing power to demand efficiently. Scalability should be considered early in the design process to negate the need for a complete rebuild further down the line. The easiest way to achieve scalability is to have an application that can live on multiple servers, commonly broken down into the frontend (a web server such as Apache/Nginx), the mid-tier (this is the programming layer), and the backend (typically a database such as MySQL). Then, providing the application is architected similarly, you can scale up your environment as much as you like. **Reliability:** Cloud computing is very reliable, especially when compared to the DIY approach, making the Cloud the ideal place for mission-critical applications without having to compromise speed, security, and reliability. It’s ideal for storing large datasets, file transfers, file storage, and online storage. Choose a Cloud Provider with 100% uptime guarantees. Atlantic.Net offers industry-leading service levels backed by a 100% Uptime SLA. All critical infrastructure components will be available 100% of the time in a month, excluding scheduled maintenance. Our 100% SLA differentiates Atlantic.Net from competitors, and each of our data centers has been designed from the ground up to be fail-safe and highly redundant. ## Performance with Guaranteed Resources Whether you choose a shared or dedicated cloud tenancy, ensure that your cloud provider guarantees system resources 24/7. Host nodes are scaled and load balanced to ensure that no customer suffers from the noisy neighbor syndrome, meaning you always have the resources you need on demand when you want them. VPS hosting providers invest heavily in computing hardware when building data centers and find a provider with SSD-exclusive storage layers that implement the latest intel CPU architecture, complemented with a network layer that operates at breakneck speed. This performance simply cannot be matched with a DIY model. ## How Can You Future-Proof Your It Infrastructure? These are some of the best ways to choose a cloud service provider to future-proof your IT investment. The cloud offers too many benefits to ignore. Your finance teams will enjoy the change from CAPEX to OPEX expenditure as your costs change to a pay-as-you-go model. The cloud brings many other advantages regarding performance, security, scalability, and adding managed services to your service. Best of all, your cloud services provider is responsible for the server upkeep cost, including maintenance and technical support, and they also have to bear the cost of hardware upgrades. Atlantic.Net has been providing cutting-edge hosting services for over 30 years. Are you looking for a leading [hosting provider](https://www.atlantic.net/hosting-services-provider/) to host your next project? Our infrastructure is audited, and we regularly conduct remediation on our infrastructure services. In addition, our [full suite of managed services](https://www.atlantic.net/managed-services/) and always-available professional support team will build the perfect solution for your business or organization. Atlantic.Net is ready to help you attain fast compliance with various certifications, such as SOC 2 and SOC 3, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/), and HITECH, with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, visit us at [www.atlantic.net](https://www.atlantic.net), call 866-618-DATA (3282), or email us at [sales@atlantic.net](mailto:sales@atlantic.net). You can find out more information by [contacting our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # Install and Configure October CMS on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/install-and-configure-october-cms-on-oracle-linux-10/ | Published: 2023-01-01 | Updated: 2026-05-26 | Author: Hitesh Jethva October is a free, open-source, and self-hosted content management system (CMS) written in PHP. It is based on the Laravel web application framework and supports MySQL, MariaDB, and PostgreSQL database backends. It is designed for beginner users and allows developers to build advanced web applications with convenience and ease. It offers innovative web features and has a large community of users around the world. In this tutorial, we will show you how to install October CMS with Nginx on Oracle Linux 10. ## Step 1 – Install Nginx, MariaDB and PHP First, you will need to install the Nginx web server, MariaDB database, PHP, and other required extensions on your server. Run the following command to install all of them: ``` dnf install nginx mariadb-server php php-cli php-fpm php-pdo php-common php-mysqlnd php-curl php-json php-zip php-gd php-xml php-mbstring git unzip -y ``` After installing all the components, edit the PHP-FPM configuration file and change the user and group from apache to nginx: ``` nano /etc/php-fpm.d/www.conf ``` Change the following lines: ``` user = nginx group = nginx ``` Save and close the file, then start and enable the Nginx, MariaDB, and PHP-FPM services: ``` systemctl start nginx php-fpm mariadb systemctl enable nginx php-fpm mariadb ``` ## Step 2 – Create a Database for October CMS Next, you will need to create a database and user to store content. First, log in to the MariaDB shell using the following command: ``` mysql ``` Once you are connected to MariaDB, create a database and user with the following command: ``` CREATE DATABASE october; GRANT ALL ON october.* TO 'october' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install October CMS First, download the latest version of October CMS from their official website using the wget command: ``` wget http://octobercms.com/download -O october.zip ``` Once the download is completed, unzip the downloaded file with the following command: ``` unzip october.zip ``` Next, move the extracted directory to the Apache web root: ``` mv install-master /var/www/html/october ``` Next, change the ownership and permissions of the October CMS directory: ``` chown -R nginx:nginx /var/www/html/october chmod -R 775 /var/www/html/october ``` ## Step 4 – Create an Nginx Virtual Host for October CMS First, create an Nginx virtual host configuration file for October CMS using the following command: ``` nano /etc/nginx/conf.d/october.conf ``` Add the following lines: ``` server { listen 80; server_name october.example.com; root /var/www/html/october; index index.php index.html; location / { try_files $uri /index.php$is_args$args; } location ~ \.php$ { fastcgi_pass unix:/run/php-fpm/www.sock; fastcgi_index index.php; fastcgi_read_timeout 240; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; fastcgi_split_path_info ^(.+.php)(/.+)$; } rewrite ^themes/.*/(layouts|pages|partials)/.*.htm /index.php break; rewrite ^bootstrap/.* /index.php break; rewrite ^config/.* /index.php break; rewrite ^vendor/.* /index.php break; rewrite ^storage/cms/.* /index.php break; rewrite ^storage/logs/.* /index.php break; rewrite ^storage/framework/.* /index.php break; rewrite ^storage/temp/protected/.* /index.php break; rewrite ^storage/app/uploads/protected/.* /index.php break; } ``` Save and close the file, then edit the Nginx configuration file and define the hash bucket size: ``` nano /etc/nginx/nginx.conf ``` Add the following line below the line http{: ``` server_names_hash_bucket_size 64; ``` Save and close the file then verify the Nginx for any syntax error: ``` nginx -t ``` You should get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx and PHP-FPM services to apply the changes: ``` systemctl restart nginx php-fpm ``` ## Step 5 – Access October CMS Now, open your web browser and access the October CMS web UI using the URL **http://october.example.com/install.php**. You should see the language selection page: Select your language, and you will see the system check page. Click on the **Agree &** **Continue** button. You should see the database configuration page: ![October database configuration page](https://www.atlantic.net/wp-content/uploads/2022/08/p2-1024x621.png) Provide your database configuration and click on the **Administrator** button. You should see the following page: ![October admin configuration page](https://www.atlantic.net/wp-content/uploads/2022/08/p3-1-1024x599.png) Provide your administrative user details and click on the **Continue** button. Once the October CMS is installed, you should see the following page: ![October installation finished page](https://www.atlantic.net/wp-content/uploads/2022/08/p4-1-1024x558.png) Click on the link below the **Administration Area.** You should see the October CMS login page: ![October login page](https://www.atlantic.net/wp-content/uploads/2022/08/p5-1024x465.png) Provide your admin username and password and click on the **Login** button. You should see the October CMS dashboard on the following page: ![October dashboard page](https://www.atlantic.net/wp-content/uploads/2022/08/p6-1024x494.png) ## Conclusion In this tutorial, we showed you how to install and configure October CMS with Nginx on Oracle Linux 10. You can now host your own website easily using the October CMS. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Zimplit CMS on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-zimplit-cms-on-oracle-linux-10/ | Published: 2023-01-02 | Updated: 2025-12-06 | Author: Hitesh Jethva Zimplit is an extremely lightweight, simple, and customizable content management system. It consists of only one file and does not require a database. It allows you to create a fast, secure, and powerful website or blog in seconds. It has a built-in site editor that helps you create and edit a website without logging in to the admin panel. In this post, we will show you how to install Zimplit CMS on Oracle Linux 10. ## Step 1 – Install Apache and PHP First, you will need to install the Apache web server, PHP, and other PHP dependencies to your server. You can install all of them by running the following command: ``` dnf install httpd php php-zip php-fpm php-soap php-cli php-common php-gd php-mbstring php-mysqlnd php-xml unzip -y ``` Once all the packages are installed, start and enable the Apache and PHP-FPM service with the following command: ``` systemctl start httpd systemctl start php-fpm systemctl enable httpd systemctl enable php-fpm ``` ## Step 2 – Download Zimplit CMS First, download the latest version of Zimplit CMS from the Git repository using the wget command: ``` wget https://codeload.github.com/niutech/zimplitcms/zip/master ``` Once the download is completed, unzip the downloaded file with the following command: ``` unzip master ``` Next, move the extracted directory to the Apache web directory using the following command: ``` mv zimplitcms-master /var/www/html/zimplit ``` ``` chown -R apache:apache /var/www/html/zimplit chmod -R 777 /var/www/html/zimplit ``` ## Step 3 – Configure Apache for Zimplit Next, you will need to create an Apache virtual host to host Zimplit on the Internet. You can create it with the following command: ``` nano /etc/httpd/conf.d/zimplit.conf ``` Add the following lines: ``` Servername zimplit.example.com Documentroot /var/www/html/zimplit Allowoverride all Allow from all ``` Save and close the file, then restart the Apache service to apply the changes: ``` systemctl restart httpd ``` To check the Apache status, run the following command: ``` systemctl status httpd ``` You should see the Apache status in the following output: ``` ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; vendor preset: disabled) Drop-In: /usr/lib/systemd/system/httpd.service.d └─php-fpm.conf Active: active (running) since Thu 2025-12-05 04:57:06 EDT; 3s ago Docs: man:httpd.service(8) Main PID: 2028 (httpd) Status: "Started, listening on: port 80" Tasks: 213 (limit: 11409) Memory: 24.3M CGroup: /system.slice/httpd.service ├─2028 /usr/sbin/httpd -DFOREGROUND ├─2030 /usr/sbin/httpd -DFOREGROUND ├─2031 /usr/sbin/httpd -DFOREGROUND ├─2032 /usr/sbin/httpd -DFOREGROUND └─2033 /usr/sbin/httpd -DFOREGROUND ``` ## Step 4 – Access Zimplit CMS You can now access the Zimplit CMS using the URL **http://zimplit.example.com/zimplit.php** in your web browser. You should see the account creation screen: ![Zimplit user creation page](https://www.atlantic.net/wp-content/uploads/2022/08/p1.png) Provide your admin username, password, and email, and click on the **Start** button. You should see the following screen: ![Zimplit change website style page](https://www.atlantic.net/wp-content/uploads/2022/08/p3-1024x346.png) Agree to the terms of service and type any website URL to copy their design and click on the **OK** button. You should see the Zimplit CMS dashboard on the following screen: ![Zimplit dashboard](https://www.atlantic.net/wp-content/uploads/2022/08/p4-1024x365.png) ## Conclusion Congratulations! You have successfully installed Zimplit CMS with Apache on Oracle Linux 10. You can now easily create a new website in a minimal time. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Ampache Music Streaming Server on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-ampache-music-streaming-server-on-oracle-linux-10/ | Published: 2023-01-04 | Updated: 2025-12-05 | Author: Hitesh Jethva Ampache is a free, open-source, web-based audio and video streaming server and file manager that allows you to access your music from a remote location over the Internet. It offers a beautiful and user-friendly web interface to browse and manage your music collection through a simple web interface. If you are looking for an open-source media server, then Ampache is the best option for you. This post will show you how to install Ampache media server on Oracle Linux 10. ## Step 1 – Install Apache, MariaDB, and PHP First, install the Apache web server and MariaDB database server packages using the following command: ``` dnf install httpd mariadb-server -y ``` Next, run the following command to install PHP with other required extensions: ``` dnf install php php-cli php-fpm php-gd php-mysqlnd php-json php-curl php-intl php-pdo php-mbstring php-dom php-xml unzip -y ``` Next, start and enable the Apache, MariaDB, and PHP-FPM services: ``` systemctl start httpd mariadb systemctl enable httpd mariadb ``` Next, edit the PHP configuration file and change the default settings: ``` nano /etc/php.ini ``` Change the following values: ``` post_max_size = 110M upload_max_filesize = 100M ``` Save and close the file when you are done. ## Step 2 – Download Ampache Next, you will need to download the latest version of Ampache from the Git repository. You can download it with the following command: ``` wget https://github.com/ampache/ampache/releases/download/7.7.1/ampache-7.7.1_all_php8.2.zip ``` Once the download is completed, unzip the downloaded file to the Apache web directory: ``` unzip ampache-7.7.1_all_php8.2.zip -d /var/www/html/ampache/ ``` Next, change the ownership and permissions of the Ampache directory: ``` chown --recursive apache:apache /var/www/html/ampache/ chmod -R 777 /var/www/html/ampache/ ``` ## Step 3 – Configure Apache for Ampache Next, you must create an Apache virtual host configuration file to host the Ampache media server. You can create it with the following command: ``` nano /etc/httpd/conf.d/ampache.conf ``` Add the following lines: ``` ServerName ampache.example.com DocumentRoot /var/www/html/ampache/public AllowOverride All Require all granted RewriteEngine on CustomLog /var/log/httpd/ampache.access.log common ErrorLog /var/log/httpd/ampache.error.log ``` Save and close the file, then restart the Apache service to apply the configuration changes: ``` systemctl restart httpd ``` ## Step 4 – Access Ampache Web Interface Now, open your web browser and access the Ampache web interface using the URL **http://ampache.example.com**. You should see the following page: ![Ampache select language](https://www.atlantic.net/wp-content/uploads/2022/08/s1-1024x309.png) Select your language and click on the **Start Configuration** button. You should see the following page: ![Ampache dependency check](https://www.atlantic.net/wp-content/uploads/2022/08/s2-1024x528.png) Ensure all PHP dependencies are installed, then click on the **Continue** button. You should see the database configuration page: ![Ampache database configuration](https://www.atlantic.net/wp-content/uploads/2022/08/s3-1024x469.png) Provide your new database information and click on the **Insert Database** button. You should see the following page: ![Ampache generate configuration](https://www.atlantic.net/wp-content/uploads/2022/08/s4-1024x504.png) ![Ampache generate configuration2](https://www.atlantic.net/wp-content/uploads/2022/08/s5-1024x433.png) Provide your database details, installation type, template configuration, and players, and click on the **Create Config** button. You should see the following page: ![Ampache administrator configuration](https://www.atlantic.net/wp-content/uploads/2022/08/s6-1024x544.png) Define your admin username and password and click on the **Create Account** button. You should see the Ampache login screen: ![Ampache login page](https://www.atlantic.net/wp-content/uploads/2022/08/s7-1024x430.png) Provide your admin username and password and click on the **Login** button. You should see the Ampache dashboard as shown below: ![Ampache dashboard page](https://www.atlantic.net/wp-content/uploads/2022/08/s8-1024x502.png) ## Conclusion This tutorial explained how to install and set up an Ampache media server on Oracle Linux 10. You can now explore the Ampache features, upload your music files, and access them from anywhere on the internet. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How Does The Dobbs Ruling Impact HIPAA-Covered Entities? > URL: https://www.atlantic.net/hipaa-compliant-hosting/how-does-the-dobbs-ruling-impact-hipaa-covered-entities/ | Published: 2023-01-05 | Updated: 2025-09-15 | Author: Richard Bailey The Dobbs ruling sent shockwaves across the United States and the rest of the world, sparking widespread protests and high-profile condemnation of what many people see as a fundamental breach of a women’s right to have an abortion. Instead, the decision gave individual states the full power to [regulate abortion laws](https://www.supremecourt.gov/opinions/21pdf/19-1392_6j37.pdf). Unfortunately, many states have enacted and revived statutes restricting women’s access to abortion services. The New York Times [recently confirmed](https://www.nytimes.com/interactive/2022/us/abortion-laws-roe-v-wade.html) that ten states, primarily located in the deep south and mid-United States, have enacted a complete ban. Other states have introduced limited restrictions on the baby’s gestational period; thankfully, many larger states like California continue to declare abortion legal. HIPAA compliance adds a significant twist to the complexity and legal challenges of the Dobbs ruling. The Dobbs ruling requires state officials to obtain information about abortion-related health services. The Privacy Act, part of HIPAA compliance, explicitly protects the patient in this circumstance as this data can only be shared when expressly permitted by the individual. Join us as we discover this controversial ruling’s unique complexity and learn how HIPAA legislation is trying to protect women’s rights. It doesn’t matter what side of the fence you sit on; this judgment is vitally important to the fundamental rights of all U.S. citizens. ## What Is the Dobbs Ruling? To comprehend the significance of this ruling, we need to go back to 1973, when a landmark decision was passed in the Roe V. Wade case. It enacted and ruled that the Constitution of the United States conferred the right of women to have an abortion. Fast forward to [March 2018](https://reproductiverights.org/case/scotus-mississippi-abortion-ban/), when this ruling was challenged by the Dobbs v. Jackson Women’s Health Organization. It took four years for the Supreme Court to deliberate, but on 24th June 2022, the Supreme Court overturned Roe v. Wade and revoked the constitutional right to abortion. This dramatic U-turn overturned nearly 50 years of precedent. Some have suggested it is the only time in history when the Supreme Court removed a fundamental human right. Condemnation has been led by President Biden, with European leaders calling it a “huge backward step” for women’s rights. ## What Are the Official HIPAA Guidelines for the Dobbs Ruling? There are a lot of unknowns about understanding how HIPAA compliance will affect the Dobbs ruling. Patients cannot hide behind HIPAA anonymity, but HIPAA can provide limited protections. We will be in a better position after the summer when local states confirm their position on abortion. The U.S. Department of Health and Human Services (HHS) reacted quickly to the ruling. The HHS, which governs the rules and enforcement of HIPAA compliance, promptly reminded everyone that “The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule supports such access by giving individuals confidence that their protected health information (PHI) including information relating to abortion and other sexual and reproductive health care, will be kept private.” Unfortunately, some caveats relate to disclosure to law enforcement or state officials. HIPAA requires that any data released to the public is anonymized. Therefore, nothing identifiable should exist, not even in the state county the abortion took place. However, supposing a warrant or subpoena is granted, the covered entity has a legal obligation to release PHI because HIPAA applies to the covered entity and business associate –  it does not apply directly to individuals. In the days after the Dobbs ruling, the HHS reiterated many existing provisions to protect women’s right to choose. This included: - Increased access to abortion medication and emergency contraceptives. - Ensure patient privacy and nondiscrimination for patients and healthcare providers. - Ensure that clinical judgment is supported in treating pregnant patients - Ensure that all providers have training and resources to handle family planning needs. - Take every legally available step to protect family planning care. These distinctions draw a clear line when emphasizing when the disclosure of PHI is mandated versus permitted. ## Implications of the Dobbs Ruling on the HIPAA Privacy Rule? Over the coming months and years, there will be significant scrutiny of the disclosure, and consequences of privacy breaches, particularly for reproductive health information. As a result, federal guidance is expected to change, and covered entities must act now to understand how the changes will impact processing PHI. - Covered entities should review their disclosure practices, ensuring that there is no breach of the HIPAA privacy rule when responding to the new requirements of the changes to state laws. - Ensure transparency when collecting sensitive data, such as the number of abortions performed per state, so that federal privacy requirements are upheld. - Published anonymized data should be scrutinized to ensure total anonymization is adhered to. ## Conclusion It’s evident that troubling times are ahead for women’s rights to an abortion in the United States, and there is a real chance that a post-code lottery will decide your rights. If you are in a deeply conservative state, your rights to an abortion may be blocked; likewise, if you reside in a liberal state, your rights will not be affected. This creates an unfair playing field; unfortunately, [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) is limited in protecting women’s rights. On the one hand, the privacy rule will block access to confidential, protected health information. On the other, if a court requests a warrant, the privacy rule becomes invalid as protected health information can be legally disclosed. We haven’t heard the end of the Dobbs ruling, and there likely is much more to come in the following weeks and months that will clarify the position of the HHS, HIPAA, and State Law officials. --- # How to Install Prometheus System Monitoring Tool on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-prometheus-system-monitoring-tool-on-oracle-linux-10/ | Published: 2023-01-06 | Updated: 2025-12-05 | Author: Hitesh Jethva Prometheus is a free and open-source monitoring application used for event monitoring and alerting. It gathers, organizes, and stores metrics in a time-series database. It has gained in popularity and has been adopted by many organizations to monitor their infrastructure metrics. It is written in the Go language and uses HTTP pulls to gather metrics from remote hosts and applications. It uses Grafana to visualize data for monitoring and analysis. In this post, we will show you how to install Prometheus on Oracle Linux 10. ## Step 1 – Download Prometheus Before starting, you will need to create a dedicated user for Prometheus. You can create it using the following command: ``` adduser -M -r -s /sbin/nologin prometheus ``` Next, create the required directories for Prometheus. ``` mkdir /var/lib/prometheus for i in rules rules.d files_sd; do mkdir -p /etc/prometheus/${i}; done ``` Next, download the latest version of Prometheus from the Git repo. ``` curl -s https://api.github.com/repos/prometheus/prometheus/releases/latest|grep browser_download_url|grep linux-amd64|cut -d '"' -f 4|wget -qi - ``` Once the download is completed, extract the downloaded file. ``` tar xvf prometheus*.tar.gz ``` Next, change the directory to Prometheus and copy all required files to the desired locations. ``` cd prometheus*/ mv prometheus promtool /usr/local/bin/ mv prometheus.yml /etc/prometheus/ ``` Set necessary permissions on the Prometheus directory. ``` for i in rules rules.d files_sd; do chown -R prometheus:prometheus /etc/prometheus/${i}; done for i in rules rules.d files_sd; do chmod -R 775 /etc/prometheus/${i}; done chown -R prometheus:prometheus /var/lib/prometheus/ ``` Next, install the Apache package. ``` dnf install httpd -y ``` Next, add a user for Prometheus. ``` htpasswd -nB hitesh ``` Set your password as shown below: ``` New password: Re-type new password: hitesh:$2y$05$X/QVUxWLF3JOpkpj62e2uO1p4fBd6bOeozcbYmT6GuR44ZWu053k. ``` Next, create the Prometheus main configuration file. ``` nano /etc/prometheus/web.yml ``` Define your username and password. ``` basic_auth_users: hitesh: $2y$05$X/QVUxWLF3JOpkpj62e2uO1p4fBd6bOeozcbYmT6GuR44ZWu053k. ``` Next, change ownership of the Prometheus configuration file. ``` chown prometheus: /etc/prometheus/web.yml ``` Next, edit the Prometheus configuration file. ``` nano /etc/prometheus/prometheus.yml ``` Change the following lines: ``` scrape_configs: # The job name is added as a label `job=` to any timeseries scraped from this config. - job_name: "prometheus" # metrics_path defaults to '/metrics' # scheme defaults to 'http'. basic_auth: username: 'admin' password: 'uniquepass' static_configs: - targets: ["127.0.0.1:9090"] ``` Save and close the file when you are done. ## Step 2 – Create a Systemd Service File for Prometheus Next, create a systemd file to manage the Prometheus service. ``` nano /etc/systemd/system/prometheus.service ``` Add the following configuration. ``` [Unit] Description=Prometheus Documentation=https://prometheus.io/docs/introduction/overview/ Wants=network-online.target After=network-online.target [Service] Type=simple User=prometheus Group=prometheus ExecReload=/bin/kill -HUP $MAINPID ExecStart=/usr/local/bin/prometheus \ --config.file=/etc/prometheus/prometheus.yml \ --storage.tsdb.path=/var/lib/prometheus \ --web.listen-address=0.0.0.0:9090 \ --web.config.file=/etc/prometheus/web.yml \ SyslogIdentifier=prometheus Restart=always [Install] WantedBy=multi-user.target ``` Save the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the Prometheus service. ``` systemctl start prometheus systemctl enable prometheus ``` You can now check the status of the Prometheus service using the following command. ``` systemctl status prometheus ``` Output. ``` ● prometheus.service - Prometheus Loaded: loaded (/etc/systemd/system/prometheus.service; enabled; preset: disabled) Active: active (running) since Fri 2025-12-05 23:26:18 EST; 2s ago Invocation: 87a225e1122a46dabfe803c1a3f8cc83 Docs: https://prometheus.io/docs/introduction/overview/ Main PID: 114921 (prometheus) Tasks: 7 (limit: 24812) Memory: 14M (peak: 14.2M) CPU: 54ms CGroup: /system.slice/prometheus.service └─114921 /usr/local/bin/prometheus --config.file=/etc/prometheus/prometheus.yml --storage.tsdb.path=/var/lib/prometheus --web.listen-address=0.0.0.0:9091 --web.config.fil> ``` ## Step 3 – Install node_exporter **Node exporter** is used to gather system metrics and expose an HTTP API on the default TCP port ‘9100’. First, download the latest version of node_exporter. ``` curl -s https://api.github.com/repos/prometheus/node_exporter/releases/latest| grep browser_download_url|grep linux-amd64|cut -d '"' -f 4|wget -qi - ``` Once the download is complete, extract the downloaded file. ``` tar -xvf node_exporter*.tar.gz ``` Next, navigate to the extracted directory and copy the node_exporter binary file to the system location. ``` cd node_exporter*/ cp node_exporter /usr/local/bin ``` Now, verify the node_exporter version. ``` node_exporter --version ``` Output. ``` node_exporter, version 1.10.2 (branch: HEAD, revision: 654f19dee6a0c41de78a8d6d870e8c742cdb43b9) build user: root@b29b4019149a build date: 20251025-20:05:32 go version: go1.25.3 platform: linux/amd64 tags: unknown ``` Next, create a system file to manage the node_exporter service. ``` nano /etc/systemd/system/node_exporter.service ``` Add the following configurations. ``` [Unit] Description=Node Exporter Wants=network-online.target After=network-online.target [Service] User=prometheus ExecStart=/usr/local/bin/node_exporter [Install] WantedBy=default.target ``` Save the file, then reload the system daemon using the following command. ``` systemctl daemon-reload ``` Next, start the node_exporter service using the following command. ``` systemctl start node_exporter ``` You can verify the status of the node_exporter using the following command. ``` systemctl status node_exporter ``` Output. ``` ● node_exporter.service - Node Exporter Loaded: loaded (/etc/systemd/system/node_exporter.service; disabled; preset: disabled) Active: active (running) since Fri 2025-12-05 23:28:03 EST; 3s ago Invocation: 3c1c6e3e56934935995ef50ce2fe08b7 Main PID: 115022 (node_exporter) Tasks: 4 (limit: 24812) Memory: 5.1M (peak: 5.3M) CPU: 14ms CGroup: /system.slice/node_exporter.service └─115022 /usr/local/bin/node_exporter ``` ## Step 4 – Add node_exporter to Prometheus First, open the Prometheus configuration file. ``` nano /etc/prometheus/prometheus.yml ``` Add the following configuration under the scrape_configs section. ``` scrape_configs: .... .... - job_name: "node_exporter" static_configs: - targets: ["your-server-ip:9100"] ``` Save and close the file, then restart the Prometheus service to apply the changes. ``` systemctl restart prometheus ``` ## Step 5 – Access Prometheus Dashboard Now, open your web browser and access Prometheus using the URL **http://your-server-ip:9090.** You will see the Prometheus login page. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p4-2.png) Provide your admin username and password and click on the **Sign in.** You will see the Prometheus dashboard. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p6-1.png) To verify whether the **node_exporter** is active or not, type the Prometheus query such as **‘node_memory_Active_bytes’** and click **‘Execute’.** Then, you’ll receive the simple graph generated by Prometheus. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p7-1.png) Now click on the **‘Status’** menu at the top and select **‘Targets’.** You should see two different target scraps that are active and running. ‘Prometheus’ for gathering Prometheus server metrics, and the **‘node_exporter’** for gathering system metrics. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p8.png) ## Conclusion In this post, we explained how to install Prometheus on Oracle Linux 10. We also explained how to add Node Exporter to Prometheus and run the query. I hope this guide will help you to implement your own monitoring system in your organization. Give it a try on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Icinga 2 Monitoring Tool on Oracle Linux 8 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-icinga-2-monitoring-tool-on-oracle-linux-8/ | Published: 2023-01-07 | Updated: 2024-06-02 | Author: Hitesh Jethva Icinga is an open-source system and network monitoring solution which can monitor small to large network environments via a web browser. It is scalable and extensible. Icinga checks the availability of your network resources, notifies users of outages, and generates performance data for reporting. It is used by system and network administrators to check CPU, Memory, Uptime, Processes, Disk space, and other services like HTTP, SMTP, SSH, and more. In this post, we will show you how to install Icinga 2 monitoring tool on Oracle Linux 8. ## Step 1 – Configure MariaDB Database Icinga 2 uses MariaDB to store its data, so you will need to install MariaDB server on your system. You can install it using the following command: ``` dnf update -y dnf install mariadb-server -y ``` Once MariaDB is installed, start and enable the MariaDB service using the following command: ``` systemctl start mariadb systemctl enable mariadb ``` Next, secure the MariaDB installation and set the root password with the following command: ``` mysql_secure_installation ``` Answer all the questions as shown below: ``` Enter current password for root (enter for none): OK, successfully used password, moving on... Set root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` Next, log in to MariaDB with the following command: ``` mysql -u root -p ``` Once you are logged in, create a database and user for Icinga 2: ``` CREATE DATABASE icinga; GRANT ALL PRIVILEGES ON icinga.* TO 'icinga'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from MariaDB with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 2 – Add Icinga 2 Repository By default, Icinga 2 is not included in the Oracle Linux 8 default repo, so you will need to add the Icinga 2 repository to your system. First, add the EPEL repository using the following command: ``` dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-8.noarch.rpm ``` Next, create an Icinga 2 repo with the following command: ``` nano /etc/yum.repos.d/icinga2.repo ``` Add the following lines: ``` [icinga2] name=Icinga 2 Repository for EPEL 8 baseurl=https://packages.icinga.com/epel/8/release enabled=1 ``` Save and close the file, then import the Icinga 2 key: ``` rpm --import https://packages.icinga.com/icinga.key ``` Next, clean the package cache with the following command: ``` dnf clean all dnf makecache ``` ## Step 3 – Install and Configure Icinga 2 Next, install the Icinga 2 package by running the following command: ``` dnf install icinga2 icinga2-selinux icinga2-ido-mysql vim-icinga2 -y ``` After the installation, enable some required features using the following command: ``` icinga2 feature enable command ido-mysql syslog ``` Next, import the Icinga 2 database schema to the Icinga database with the following command: ``` mysql -u root -p icinga < /usr/share/icinga2-ido-mysql/schema/mysql.sql ``` Next, edit the Icinga 2 MySQL configuration file: ``` nano /etc/icinga2/features-available/ido-mysql.conf ``` Define your database settings as shown below: ``` * The IdoMysqlConnection type implements MySQL support * for DB IDO. */ object IdoMysqlConnection "ido-mysql" { user = "icinga" password = "password" host = "localhost" database = "icinga" } ``` Save and close the file, then start and enable the Icinga 2 service: ``` systemctl start icinga2 systemctl enable icinga2 ``` You can also check the Icinga 2 service using the following command: ``` systemctl status icinga2 ``` You will get the following output: ``` ● icinga2.service - Icinga host/service/network monitoring system Loaded: loaded (/usr/lib/systemd/system/icinga2.service; disabled; vendor preset: disabled) Active: active (running) since Wed 2022-07-04 09:22:54 UTC; 4s ago Process: 18616 ExecStartPre=/usr/lib/icinga2/prepare-dirs /etc/sysconfig/icinga2 (code=exited, status=0/SUCCESS) Main PID: 18624 (icinga2) Status: "Startup finished." Tasks: 11 (limit: 11411) Memory: 14.2M CGroup: /system.slice/icinga2.service ├─18624 /usr/lib64/icinga2/sbin/icinga2 --no-stack-rlimit daemon --close-stdio -e /var/log/icinga2/error.log ├─18639 /usr/lib64/icinga2/sbin/icinga2 --no-stack-rlimit daemon --close-stdio -e /var/log/icinga2/error.log └─18642 /usr/lib64/icinga2/sbin/icinga2 --no-stack-rlimit daemon --close-stdio -e /var/log/icinga2/error.log ``` ## Step 4 – Install Icinga Web 2 Dashboard Icinga Web 2 is a web-based application used for managing Icinga 2 from the web-based interface. By default, it is available in the Oracle Linux default repo. You can run the following command to install Icinga Web 2 with Apache and other packages: ``` dnf install httpd icingacli icingaweb2 php-json php-ldap ``` Once all the packages are installed, start and enable the Apache and PHP-FPM service: ``` systemctl enable --now httpd systemctl enable --now php-fpm.service ``` ## Step 5 – Access Icinga Web 2 Setup Wizard Before starting, you will need to configure the Apache web server for Icinga Web 2. You can configure it using the following command: ``` icingacli setup config webserver apache ``` Next, generate an authentication token with the following command: ``` icingacli setup token create ``` You will get the following output: ``` The newly generated setup token is: a84a833dd624e6a0 ``` Next, open your web browser and type the URL **http://your-server-ip/icingaweb2/setup** to access the Icinga 2 web. You should see the Icinga Web 2 welcome screen: ![Icinga 2 welcome page](https://www.atlantic.net/wp-content/uploads/2022/07/p1-2-1024x510.png) Type your generated token and click on the **Next** button. You should see the following screen: ![Icinga 2 select module page](https://www.atlantic.net/wp-content/uploads/2022/07/p2-2-1024x472.png) Select the desired module that you want to enable and click on the **Next** button. You should see the following screen: ![Icinga 2 check prerequisites page](https://www.atlantic.net/wp-content/uploads/2022/07/p3-2-1024x513.png) Check all the PHP extensions then click on the **Next** button. You should see the following screen: ![Icinga 2 select authentication page](https://www.atlantic.net/wp-content/uploads/2022/07/p4-1024x400.png) Choose your authentication type and click on the **Next** button. You should see the following screen: ![Icinga 2 web database page](https://www.atlantic.net/wp-content/uploads/2022/07/p5-1024x517.png) Provide your Icinga Web 2 database name, root username, and password, and click on the **Next** button. You should see the following screen: ![Icinga 2 select backend page](https://www.atlantic.net/wp-content/uploads/2022/07/p6-1024x345.png) Provide your backend name and click on the **Next** button. You should see the following screen: ![Icinga 2 set admin password page](https://www.atlantic.net/wp-content/uploads/2022/07/p7-1024x381.png) Provide your admin username and password and click on the **Next** button. You should see the following screen: ![Icinga 2 define logging page](https://www.atlantic.net/wp-content/uploads/2022/07/p8-1024x421.png) Provide your log details and click on the **Next** button. You should see the following screen: ![Icinga 2 verify all details page](https://www.atlantic.net/wp-content/uploads/2022/07/p9-1024x511.png) Verify all details and click on the **Next** button. You should see the following screen: ![Icinga 2 module configuration page](https://www.atlantic.net/wp-content/uploads/2022/07/p10-1024x316.png) Click on the **Next** button. You should see the following screen: ![Icinga 2 define Icinga 2 database page](https://www.atlantic.net/wp-content/uploads/2022/07/p13-1024x512.png) Provide your Icinga 2 database name, root username, and password, and click on the **Next** button. You should see the following screen: ![Icinga 2 configure command transport page](https://www.atlantic.net/wp-content/uploads/2022/07/p14-1024x408.png) Configure the command transport and click on the **Next** button. You should see the following screen: ![Icinga 2 configure monitoring security page](https://www.atlantic.net/wp-content/uploads/2022/07/p15-1024x308.png) Configure monitoring security and click on the **Next** button. You should see the following screen: ![Icinga 2 verify all settings page](https://www.atlantic.net/wp-content/uploads/2022/07/p16-1024x453.png) Verify all settings and click on the **Next** button. You should see the following screen: ![Icinga 2 installation finished page](https://www.atlantic.net/wp-content/uploads/2022/07/p17-1024x393.png) Click on the **Login to Icinga Web 2** button. You should see the following screen: ![Icinga 2 login page](https://www.atlantic.net/wp-content/uploads/2022/07/p18-1024x502.png) Provide your admin username and password and click on the **Login** button. You should see the Icinga Web 2 dashboard on the following screen: ![Icinga 2 dashboard page](https://www.atlantic.net/wp-content/uploads/2022/07/p19-1024x500.png) ## Conclusion In this post, we showed you how to install Icinga 2 and Icinga Web 2 on Oracle Linux 8. Now install the Icinga 2 agent on the monitoring server and desktop system and start monitoring them from the Icinga Web 2 dashboard. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install ModSecurity with Nginx on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-modsecurity-with-nginx-on-oracle-linux-10/ | Published: 2023-01-08 | Updated: 2025-12-05 | Author: Hitesh Jethva Nginx is a free, open-source, and widely used web server. It is essential to secure the Nginx web server to defend it from DDoS and other attacks, and ModSecurity can help. ModSecurity is a free and open-source web application firewall used to protect web servers from external threats. It is used by many websites, cPanel, and other hosting control panels to protect their web applications and servers from SQL injection, cross-site scripting, and local file inclusion attack. Originally it was designed to secure only the Apache web servers. Now it can also work with the Nginx web server. In this post, we will show you how to install ModSecurity with Nginx on Oracle Linux 10. ## Step 1 – Install Required Dependencies First, you will need to install the required dependencies needed to compile Nginx with ModSecurity. You can install all of them with the following command: ``` dnf install gcc-c++ flex bison curl-devel curl zlib-devel autoconf automake git curl make libxml2-devel pkgconfig libtool httpd-devel redhat-rpm-config git wget openssl openssl-devel vim pcre2 pcre2-devel ``` ## Step 2 – Install ModSecurity On Oracle Linux 10 First, download the latest version of ModSecurity from the Git Hub repository using the following command: ``` git clone --depth 1 -b v3/master --single-branch https://github.com/SpiderLabs/ModSecurity ``` Once the download is completed, navigate to the ModSecurity directory and install other modules with the following command: ``` cd ModSecurity git submodule init git submodule update ``` Next, compile and install ModSecurity with the following command: ``` ./build.sh ./configure make make install ``` ## Step 3 – Compile Nginx with LibModsecurity Support In order to enable LibModsecurity support in Nginx, you will need to compile Nginx with support for LibModsecurity. First, download the ModSecurity-nginx connector using the following command: ``` cd /root git clone https://github.com/SpiderLabs/ModSecurity-nginx.git ``` Next, download the latest stable version of Nginx with the following command: ``` wget http://nginx.org/download/nginx-1.26.3.tar.gz ``` Next, extract the downloaded file using the following command: ``` tar xzf nginx-1.26.3.tar.gz ``` Next, create an Nginx user with the following command: ``` useradd -r -M -s /sbin/nologin -d /usr/local/nginx nginx ``` Next, change the directory to the Nginx source and compile it using the following command: ``` cd nginx-1.26.3 ./configure --user=nginx --group=nginx --with-pcre-jit --with-debug --with-http_ssl_module --with-http_realip_module --add-module=/root/ModSecurity-nginx ``` Next, install it using the following command: ``` make make install ``` Next, copy a sample ModSecurity configuration file and Unicode mapping file with the following command: ``` cp /root/ModSecurity/modsecurity.conf-recommended /usr/local/nginx/conf/modsecurity.conf cp /root/ModSecurity/unicode.mapping /usr/local/nginx/conf/ ``` Next, back up the Nginx configuration file: ``` cp /usr/local/nginx/conf/nginx.conf{,.bak} ``` Next, edit the Nginx configuration file with the following command: ``` nano /usr/local/nginx/conf/nginx.conf ``` Remove all lines and add the following lines: ``` user nginx; worker_processes 1; pid /run/nginx.pid; events { worker_connections 1024; } http { include mime.types; default_type application/octet-stream; sendfile on; keepalive_timeout 65; server { listen 80; server_name nginx.example.com; modsecurity on; modsecurity_rules_file /usr/local/nginx/conf/modsecurity.conf; access_log /var/log/nginx/access_unix-demo.log; error_log /var/log/nginx/error_unix-demo.log; location / { root html; index index.html index.htm; } error_page 500 502 503 504 /50x.html; location = /50x.html { root html; } } } ``` Save and close the file, then create an Nginx log directory: ``` mkdir /var/log/nginx ``` ## Step 4 – Create a Systemd Service File for Nginx Next, you will need to create a systemd service file to manage the Nginx service. You can create it using the following command: ``` nano /etc/systemd/system/nginx.service ``` Add the following lines: ``` [Unit] Description=The nginx HTTP and reverse proxy server After=network.target remote-fs.target nss-lookup.target [Service] Type=forking PIDFile=/run/nginx.pid ExecStartPre=/usr/bin/rm -f /run/nginx.pid ExecStartPre=/usr/sbin/nginx -t ExecStart=/usr/sbin/nginx ExecReload=/bin/kill -s HUP $MAINPID KillSignal=SIGQUIT TimeoutStopSec=5 KillMode=mixed PrivateTmp=true [Install] WantedBy=multi-user.target ``` Save and close the file, then create a symlink of Nginx binary using the following command: ``` ln -s /usr/local/nginx/sbin/nginx /usr/sbin/ ``` Next, reload the systemd daemon to apply the changes: ``` systemctl daemon-reload ``` Next, start the Nginx service and enable it to start at system reboot: ``` systemctl enable --now nginx ``` You can check the status of Nginx with the following command: ``` systemctl status nginx ``` You will get the following output: ``` ●nginx.service - The nginx HTTP and reverse proxy server Loaded: loaded (/etc/systemd/system/nginx.service; enabled; preset: disabled) Drop-In: /etc/systemd/system/nginx.service.d └─php-fpm.conf Active: active (running) since Fri 2025-12-05 07:16:52 EST; 3s ago Invocation: c15f63e1b9144b2282e75a1f396cc611 Process: 83457 ExecStartPre=/usr/bin/rm -f /run/nginx.pid (code=exited, status=0/SUCCESS) Process: 83458 ExecStartPre=/usr/sbin/nginx -t (code=exited, status=0/SUCCESS) Process: 83461 ExecStart=/usr/sbin/nginx (code=exited, status=0/SUCCESS) Main PID: 83462 (nginx) Tasks: 2 (limit: 24812) Memory: 4.5M (peak: 4.6M) CPU: 52ms CGroup: /system.slice/nginx.service ├─83462 "nginx: master process /usr/sbin/nginx" └─83463 "nginx: worker process" ``` ## Step 5 – Enable ModSecurity Rule By default, ModSecurity has been configured for detection-only mode, so you must enable the ModSecurity rule in the **modsecurity.conf** file. To enable it, run the following command: ``` sed -i 's/SecRuleEngine DetectionOnly/SecRuleEngine On/' /usr/local/nginx/conf/modsecurity.conf ``` Also enable the audit log with the following command: ``` sed -i 's#/var/log/modsec_audit.log#/var/log/nginx/modsec_audit.log#' /usr/local/nginx/conf/modsecurity.conf ``` ## Step 6 – Install OWASP ModSecurity Core Rule Set OWASP provides generic attack detection rules for ModSecurity, so it is recommended to download and integrate with ModSecurity for better security. ``` git clone https://github.com/SpiderLabs/owasp-modsecurity-crs.git /usr/local/nginx/conf/owasp-crs ``` Next, rename the OWASP rule configuration file using the following command: ``` cp /usr/local/nginx/conf/owasp-crs/crs-setup.conf{.example,} ``` Next, define the OWASP rule in the ModSecurity configuration file: ``` echo -e "Include owasp-crs/crs-setup.conf\nInclude owasp-crs/rules/*.conf" >> /usr/local/nginx/conf/modsecurity.conf ``` Next, edit the reputation config file. ``` nano /usr/local/nginx/conf/owasp-crs/rules/REQUEST-910-IP-REPUTATION.conf ``` Remove the following lines: ``` SecRule TX:HIGH_RISK_COUNTRY_CODES "!@rx ^$" \ "id:910100,\ phase:2,\ block,\ t:none,\ msg:'Client IP is from a HIGH Risk Country Location',\ logdata:'%{MATCHED_VAR}',\ tag:'application-multi',\ tag:'language-multi',\ tag:'platform-multi',\ tag:'attack-reputation-ip',\ tag:'paranoia-level/1',\ ver:'OWASP_CRS/3.2.0',\ severity:'CRITICAL',\ chain" SecRule TX:REAL_IP "@geoLookup" \ "chain" SecRule GEO:COUNTRY_CODE "@within %{tx.high_risk_country_codes}" \ "setvar:'tx.anomaly_score_pl1=+%{tx.critical_anomaly_score}',\ setvar:'ip.reput_block_flag=1',\ setvar:'ip.reput_block_reason=%{rule.msg}',\ expirevar:'ip.reput_block_flag=%{tx.reput_block_duration}'" ``` Next, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 7 – Verify ModSecurity At this point, Nginx is installed and configured with ModSecurity support. Now, it’s time to test it. Execute the code injection using the curl command: ``` curl localhost/index.html?exec=/bin/bash ``` If ModSecurity is working fine, you should get the “403 Forbidden” error as shown below: ``` 403 Forbidden

403 Forbidden


nginx/1.19.10
``` You can also verify the ModSecurity log for more information: ``` tail -100 /var/log/nginx/modsec_audit.log ``` You should see the following output: ``` ModSecurity: Warning. Matched "Operator `PmFromFile' with parameter `unix-shell.data' against variable `ARGS:exec' (Value: `/bin/bash' ) [file "/usr/local/nginx/conf/owasp-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "496"] [id "932160"] [rev ""] [msg "Remote Command Execution: Unix Shell Code Found"] [data "Matched Data: bin/bash found within ARGS:exec: /bin/bash"] [severity "2"] [ver "OWASP_CRS/3.2.0"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION"] [tag "WASCTC/WASC-31"] [tag "OWASP_TOP_10/A1"] [tag "PCI/6.5.2"] [hostname "127.0.0.1"] [uri "/index.html"] [unique_id "165651983136.006138"] [ref "o1,8v21,9t:urlDecodeUni,t:cmdLine,t:normalizePath,t:lowercase"] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/nginx/conf/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "80"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "2"] [ver "OWASP_CRS/3.2.0"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "127.0.0.1"] [uri "/index.html"] [unique_id "165651983136.006138"] [ref ""] ``` ## Conclusion In this guide, we learned how to install ModSecurity with Nginx on Oracle Linux 8. Your server is not fully protected with ModSecurity and it can able to protect from a wide range of attacks. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # HIPAA Cybersecurity Requirements: A Practical Guide > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-cybersecurity-requirements-a-practical-guide/ | Published: 2023-01-09 | Updated: 2024-09-24 | Author: Gilad Maayan ## What is HIPAA Compliance? HIPAA stands for Health Insurance Portability and Accountability Act of 1996. It was created to modernize the flow of medical information and to specify how organizations should protect personal health information (also known as PHI). These rules apply to anyone processing sensitive patient data. In 2013, HIPAA rules were expanded to include business associates, including those who may process PHI on behalf of healthcare entities, such as software vendors and [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) companies. HIPAA is designed to protect personally identifiable information (PII) in any form or medium. Many people think this means data such as social security numbers, names, and driver’s licenses, but it is much broader and includes identifying information such as fingerprints, photographs (a face or anything that can identify an individual), and voice prints. ## A Brief Overview of HIPAA Requirements HIPAA has a special focus on protecting and securing sensitive health information. HIPAA compliance requires hospitals and healthcare organizations to follow a number of different rules to protect confidential patient information: - **Privacy** – patients have the right to keep their Protected Health Information (PHI) confidential. PHI can contain a variety of information on sensitive topics such as diagnoses, appointments, and procedures. - **Security** – organizations must protect PHI from unauthorized use and distribution. A common example is a patient’s insurance information. - **Enforcement** – agencies protecting PHI should always implement security protocols and initiate investigations when data breaches occur. The best way to achieve this is to create and adhere to data protection protocols and to keep a complete audit in case an attack occurs. - **Breach notification** – in the event of a violation, businesses must notify the appropriate local and national authorities. A data breach report should include who contacted whom and what information was shared. - **Omnibus** – the Omnibus Rule added cybersecurity requirements to HIPAA (thanks to the HITECH Act). This rule defines an organization’s legal liabilities with regard to HIPAA. ## HIPAA Cybersecurity Requirements An important part of HIPAA requirements is a set of rules designed to prevent accidental or malicious access to HIPAA-protected health information. For example, healthcare providers and organizations must develop security policies that define how to conduct risk and vulnerability assessments to find vulnerabilities, create risk coordination plans, and respond to cyber incidents. ### HIPAA technical requirements and information security HIPAA technical requirements aim to ensure the confidentiality, integrity, and availability of protected electronic health information (ePHI). Healthcare providers and organizations must implement the standards necessary to maintain the privacy of HIPAA-protected healthcare information, using reasonable and appropriate healthcare cybersecurity measures. The exact implementation will depend on individual organizations and the cybersecurity personnel they employ. ### HIPAA requirements for access control Strong access control is one of the key safeguards for protecting HIPAA-protected health information. Access control grants rights or privileges to specific users of an information system, application, program, or file to perform task-related functions. The access control method must include: - **Unique user identification** using multiple factors, including biometric factors like fingerprint reading or eye scans. - **Documenting emergency access procedures**, including emergency ePHI access guidelines and procedures. - **Automatic logout** of end-user sessions after a period of inactivity. - **Encrypting data** to convert it to an unreadable format. With these measures, different people in different roles have different levels of access to data. For example, doctors may have access to everything, nurses may have access to a majority of the information, and billing and insurance may have very limited access. ### HIPAA Security Rule The HIPAA Security Rule stipulates that healthcare providers (covered entities) must protect PHI with policies and technical measures that prevent the inappropriate use of this confidential information. This includes the use of HIPAA-compliant firewalls, which [secure networks](https://www.catonetworks.com/network-security/) and prevent unauthorized access to your PHI. [Penetration testing](https://www.hackerone.com/product/pentest) is not explicitly required by HIPAA regulations. However, regulations require that entities perform a periodic security risk analysis. As part of the mandatory HIPAA security rule risk analysis, the organization must assess the risks and vulnerabilities in the environment and implement security controls to address those risks and vulnerabilities. Healthcare organizations must implement a variety of controls, including access controls, audit controls, integrity controls, authentication controls, and data transmission security controls. ## A Holistic Approach to Health Cybersecurity HIPAA rules are not enough to combat cybercrime. Legal requirements are not always consistent with cybersecurity best practices. Additionally, healthcare organizations should not consider cybersecurity and [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) as separate components, but as two concepts working in parallel with each other. In fact, a strong cybersecurity program supports compliance. To ensure cybersecurity in the healthcare sector and prevent sophisticated attacks, healthcare organizations can implement the following practices: - Review your current security risk analysis and identify areas and areas for improvement. Support regulatory compliance by documenting risk analysis. - Evaluate your risk management plan to ensure you have sufficient countermeasures to mitigate vulnerabilities. Adopt best practices used in healthcare such as unique identification, strong passwords, role-based permissions, automatic timeout, and screen lock. - Compare HIPAA and other cybersecurity standards and procedures, including your organization’s other legal and regulatory obligations, and ensure they are updated with the latest risk analysis findings. - Develop a security [incident response plan](https://www.cynet.com/incident-response/) that is compliant with HIPAA and other applicable legal requirements, to help your business respond to potential data breaches. Plan for the unexpected – anything from cyberattacks to natural disasters that threaten health records and other critical assets. - Make a backup and create a recovery plan. Ensure that the media used to store the backup data is secure and cannot be erased or encrypted by attacks such as ransomware. - Invest in people, processes, and management. Cybersecurity cannot be done by IT or security departments alone. It must be integrated with organizational practices, development plans, and business plans. We hope this will be useful as you align your cybersecurity strategy with HIPAA compliance requirements. --- # RTLS and Healthcare – Can Real Time Location System Security Improve Your Healthcare Operations? > URL: https://www.atlantic.net/hipaa-compliant-hosting/rtls-and-healthcare-can-real-time-location-system-security-improve-your-healthcare-operations/ | Published: 2023-01-10 | Updated: 2026-05-30 | Author: Richard Bailey Real-Time Location Systems are making a big difference in front-line US Healthcare services. RTLS is helping to create a highly efficient healthcare system that benefits patient welfare in many ways. Healthcare professionals from all sectors feel safer at work, and hospitals see significant benefits to their day-to-day business operations. RTLS is growing in popularity. Year after year, RTLS implementations have increased, yielding countless successful use cases. RLTS is found in hospitals, medical surgeries, and even nursing homes. The technology provides a significant volume of business intelligence that has some direct benefits for healthcare. This article will discover why many healthcare providers have gone all in on RTLS. ## What Is RTLS? RTLS is a technology solution that identifies and tracks the location of people or objects in real-time or near real-time. RFID tags are used throughout the healthcare environment, and wireless sensors determine their location throughout a chosen perimeter. The RFID tags are essentially portable IoT devices that gather specific data, typically location, temperature, humidity, and airflow. The sensors are located throughout the hospital, perhaps attached to medical equipment, given to staff to wear, or allocated to patients on arrival. They are often found in the maternity ward, and if you have had children recently, they likely had an RTLS sensor around their feet. RTLS allows healthcare managers to know exactly where equipment and critical employees are if needed in an emergency. As a result, the system helps to manage patient flow and improves hospital efficiency, saving time for patients and employees. ## RTLS and Patient Services Patients see a significant improvement in the delivery of front-line services when using RTLS sensors. Hospitals are full of beacons that track the flow of patients in and out of the hospital. Hospital management can track footfall throughout the healthcare location, including data such as movement at the hospital entrance, the number of patients in each department, and the capacity and waiting times for each department. RTLS can be used to document room usage, bed tracking, ward capacity, and treatment room usage levels. It enables managers to reallocate resources to where they are needed and quickly identify free beds and the likelihood that a bed will be available soon. In addition, cleaners can be notified automatically, and managers will know when a room is available for use again. Each use case improves the patient experience and assists healthcare professionals in providing efficient healthcare. ## RTLS and Equipment Management One of the most popular implementations of RTLS is to deliver improved hospital equipment management. Hospitals are vast, and machines are located throughout the ward and surgery rooms. Because equipment positioning is vital in a medical emergency, it’s essential to know where medical equipment is in emergency rooms. RTLS improves asset management because the sensors can report the device’s location anywhere in the hospital. RTLS helps healthcare managers answer vital questions like how often the medical devices are used. For example, are they relocated to patient rooms frequently, or are they never moving, instead sitting in a corner for months? In addition, management can buy and sell devices based on usage analytics or improve room facilities if a machine is frequently wheeled into patient rooms. Each sensor is portable and can be attached when vital life-saving equipment is being transferred around the hospital or practice. For example, consider blood transportation; an RTLS sensor can be added to the package. It will monitor the location of the parcel but also the temperature inside the box and alarm if there is any unauthorized tampering, all ensuring 6safe transportation. RTLS is used for temperature management extensively in fridges, autoclaves, medication storage, theatres, and hospital kitchens. Sensors monitor sanitization stations’ fill and usage levels and improve shrinkage control (loss of product). Monitoring prevents wastage and saves practices much cash. ## RTLS and Staff Management One massive widespread use case for RTLS is staff protection. For example, consider healthcare professionals working in correctional facilities or delivering front-line mental health services. Around [41% of these workers suffer physical violence](https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5948676/) in the workplace. RTLS is used to track staff at their place of work to improve safety, and each device can act as a panic button that alerts security and management in the event of an incident. Other use cases are iris biometrics, which introduces non-intrusive positive id access control for secure areas such as medicine cabinets or attached to automated security doors and locks. RTLS enables specialists to be located quickly, for example, if an emergency doctor is needed or an anesthetist is required in maternity for an epidural. Having comprehensive hospital visibility and protection to employees is game-changing when delivering critical healthcare. ## Benefits of RTLS There are many benefits to using RTLS in the US healthcare industry. Naturally, there will be some privacy concerns, but assurances should be given that the mandatory legislative requirements of HIPAA compliance cover RTLS. The majority of data used by RTLS is anonymous; however, it can hold protected health information in certain use cases, for example, on room information boards. RTLS introduces flexibility to healthcare management, saves time and money, and has no internal influence on decision-making. The analytics benefit healthcare even more, allowing hospitals to plan expansions, purchase orders, and improve equipment maintenance. This approach enhances the quality of care and helps to reduce waste. ## RTLS and HIPAA compliance RTLS can be made HIPAA compliant; not only must the local RTLS sensors, beacons, and infrastructure need to be compliant, but also the mission-critical cloud servers that power the intelligence behind the technology. All data must be anonymized or meet HIPAA compliance’s mandatory physical, technical and administrative safeguards. Atlantic.Net has been providing world-class, mission-critical [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) services for decades, and we are proud to host some of the biggest names in healthcare. Here are just some of the ways Atlantic.Net will secure your HIPAA-compliant services: - Industry Leading Certifications and Partnerships - Specialists at HIPAA-Compliant Hosting - 24/7 Technical Support via Phone or Email - Fully Managed Firewall Appliance - Trend Micro Deep Security Suite - Multi-Factor Authentication - Load Balancing - Encrypted Backup, Storage & VPN - Fully Managed Daily Backups - Log Inspection System - HIPAA and Hitech Audited - GDPR Ready - PCI/DSS ready - NIST Certified Data Centers - EU/US Privacy Shield Compliant Data Centers - Industry Awards and Accomplishments If you are a healthcare provider in the market for a secure [HIPAA-compliant cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) service, [contact our sales team](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) to find out how Atlantic.Net can help you. --- # What Is a DNS? Complete Domain Name System Guide > URL: https://www.atlantic.net/vps-hosting/what-is-dns-and-how-does-it-work/ | Published: 2023-01-11 | Updated: 2024-08-24 | Author: Richard Bailey ## **What Is the Domain Name System (DNS)?** The Domain Name System is a complex system to understand, but without DNS, hostnames, or domain names, each Internet user would have to remember every raw Internet Protocol (IP) address of their favorite websites. For example, instead of visiting [www.google.com](https://www.google.com/), you would visit [216.58.212.196](https://216.58.212.196/). You’ll likely agree that it’s a lot easier to remember “Google” than a string of IP addresses. It doesn’t matter if you use the DNS resource record (hostnames) or an IP address, the result is the same. It is the Domain Name System (DNS) that turns [www.google.com](https://www.google.com/) into [216.58.212.196](https://216.58.212.196/)! Now consider that for every single website in the world, each one has a different IP address and often multiple IP addresses per website. It’s difficult to imagine the sheer scale of the Internet, not to mention the size of the hypothetical phone book needed to store all of the domain name system data. There are three primary purposes of the Domain Name System: 1. To route traffic over the Internet to the domain name associated with the desired IP address. 2. Increasingly, to publish metadata. 3. To publish additional information often regarding authentication, encryption processes (such as X.509 certs), and website reputation. You can even deliver credentials over DNS using DNSSEC. It is clear to see that DNS is evolving as the Internet matures and the world becomes more security-conscious. ## **When Was the DNS System Created?** Long before DNS was created, the Internet didn’t exist as we know it today. It was a research project known as the Advanced Research Products Agency Network (ARPAnet). A handful of servers would communicate to one another by looking up the server host-names recorded in a HOSTS file. Yes, this is the same HOSTS file that you would find on modern releases of Windows Server, Mac, and the Linux Operating System. To see your HOST file, simply browse to: - Mac – cat /etc/hosts - Linux – cat /etc/hosts - Windows – c:\Windows\System32\Drivers\etc\hosts As you can see from the example, most HOST files don’t contain a lot of information these days, but you can still add local servers and computers to your HOST files. When your computer looks up a server name, it will always check the HOSTS file first before looking up DNS records. Before the Domain Name System (DNS), the HOSTS file was shared between every networked computer. Each computer would have to download the master HOSTS file. The HOSTS file was centrally managed and kept up to date by Stanford University. However, the system was flawed because it did not work at scale and soon Stanford University servers were overloaded with requests for its host-names – a better system was needed. In 1983, the idea of a domain name database was published in [RFC882](https://datatracker.ietf.org/doc/html/rfc882) and [RFC883](https://datatracker.ietf.org/doc/html/rfc883) by Paul Mockapetris, but it was not until 1986 that the DNS System was chosen as one of the very first Internet Standards. It was then that the very first top-level domains were created, most of which are still in use today. ## **How Does DNS Work?** The Domain Names System (DNS) is a technology that enables connectivity on the World Wide Web. Much like a phone book for the Internet age, DNS contains all the addresses of everything connected to the Internet and provides the framework for web browsing. DNS provides a distributed database of website addresses and their corresponding IP addresses. Likely DNS is something you have already heard about simply because the Domain Name System makes the Internet tick. One commonplace example of DNS popping up in everyday Internet use is the DNS error message that displays when you type a website incorrectly in your web browser. In this article, we will demystify nameservers, DNS, and domain names and help piece together how DNS makes the Internet, WAN, and LAN networking services work. ## What Is DNS Propagation? Think back to the phone book analogy. The phone book is a static list of names and addresses, and once it’s published, there is no option to update it. DNS is completely different, as websites dynamically update their IP addresses all the time. So, what happens if the IP address of your favorite website changes? If the domain name in the DNS is pointed to an old IP address, that’s where DNS Propagation comes in. DNS Propagation occurs when any changes to a DNS record are updated and published around the world’s DNS Name Servers. There are thousands of DNS Name Servers located around the world, and as you can imagine, it may take some time to update the entire system when a domain name entry is updated. While officially the process can take up to 72 hours, DNS Propagation is normally completed in just a few hours. When you consider the near-real-time impact the Internet has on our lives, it’s hard to imagine that these changes take so long for DNS servers to handle. According to [NS1](https://ns1.com/resources/dns-propagation), one of the world’s biggest DNS providers, traditional DNS takes so long to propagate for three reasons: - **Time to Live (TTL) Settings** – Time to Live (TTL) is a DNS setting that declares how long the DNS cache remains on your computer. Every time your computer requests a website address, the DNS records are cached locally, and the TTL setting defines how long your computer will use the cached local copy before reaching out to the Internet to update its DNS records. In most systems, TTL is set to 1500 seconds (25 minutes). There are hundreds of DNS providers on the Internet and updates can take 25 minutes at each DNS provider – hence the time can add up. - **Internet Service Provider (ISP)**– Your Internet provider also uses a DNS cache for DNS entries to speed up a user’s access to the Internet. The user pulls the DNS record direct from the provider, which is usually the first step when hopping on the Internet. ISPs ignore TTL configurations and set their own timeout on DNS cache refreshes. - **Domain Name Registry** – Changing the authoritative server creates long delays in DNS propagation. The authoritative server is the official DNS records holder, and if you move from one IP address to another, the change needs to be reflected in the entire DNS hierarchy. These changes can take over 48 hours to complete. There are things you can do to speed up DNS servers’ propagation, and we will go into detail about this later. ## What Is DNS Hierarchy? The DNS Database has to be structured in a specific hierarchy to work properly due to the sheer scale of the domain namespace. The DNS hierarchy is a tree hierarchy. It starts with the top-level domains and then extends to subdomains. TLD examples include .com, .net, .org, .edu, .mil, .gov, .us, .ca, .info, .biz, and [.tv](https://www.hostinger.com/tld/tv-domain). Consider the following for our domain name: **https://www.atlantic.net** - *HTTPS*:// – is the **protocol** - *www –*is the **subdomain** - *Atlantic –*is the **domain name** - *.net* – is the **top-level domain (TLD)** - *Atlantic.Net*– The root domain includes the domain name and top-level domain (TLD) Did you know that the *dot* *net* top-level domain was originally reserved for an Internet Service Provider (ISP) or for Internet administrative servers? In the early days of Atlantic.Net, we provided telecommunication services throughout Florida, hence we chose “Atlantic.Net.” The *dot com* domain is reserved for companies (however this has not been strictly observed) and of course, you get country domains such as *au*—Australia, *uk*—the United Kingdom, *us*—the United States, or *ca*—Canada. ## What Is a DNS Name Server? The Name Server stores DNS Records such as IP address records (A – AAAA Record), Aliases, Name Server (NS) records, and information about email exchange (MX record). There are many other DNS Record types stored on a Name Server (far too many to go into detail about here), but these four are the most common records you will discover. DNS Service provider Cloudflare has produced[this useful list of all the DNS record](https://www.cloudflare.com/en-gb/learning/dns/dns-records/) types that are available. There are multiple layers in the DNS Name Server hierarchy, and each layer has a Name Server. The Domain Name System consists of multiple servers located around the world that perform the translation of DNS names into IP Addresses. The Top-Level Root name servers, managed and maintained by the [Internet Corporation for Assigned Names and Numbers](https://en.wikipedia.org/wiki/Internet_Corporation_for_Assigned_Names_and_Numbers) (ICANN), are used to maintain the domain name hierarchy and the IP Address system. The next layer consists of Name Servers that manage Internet resources at the registrar level. A registrar is a company that sells domain names such as 123reg. They also maintain a hierarchy of master name servers that propagate to other registrars globally. Next are the DNS Name Servers that are managed and maintained by Internet Service Providers and telecoms providers; these provide DNS caching. Finally, you have individual domain controllers at a local layer (such as a business) that manage local DNS requests and route up the hierarchy for any unknown addresses. No matter which layer the name server is at, they all perform similar functions. There are four types of DNS servers for the DNS lookup process: - **Recursive DNS Resolver** – The DNS recursive resolver (sometimes called a Local DNS nameserver) is a server that acts as the first stop in a recursive query from a client machine. The DNS resolvers are the middlemen between the client and the nameserver by making additional requests to resolve a client query. The DNS resolver recursively chains a query for DNS resolution. - **DNS Root NameServer** – The root servers are the name servers responsible for the top-level domain within the hostname. For example, the root name server would refer the request to the Atlantic.Net DNS server. - **TLD Name Server** – Top-Level NameServers provide DNS services and DNS resolution for each domain extension. The TLD servers are managed by the Internet Assigned Numbers Authority (IANA) which is a division of ICANN. Each TLD is divided into the *generic top-level domains*including .com, .org, .net, .edu, and .gov, and the*country code top-level domains* that include .uk, .us, .ru, and .jp and so on. - **Authoritative DNS Server**s – An authoritative DNS server is a name server that has the authority to respond to DNS queries for a subdomain. It is usually the last step before resolving an IP address from a DNS A Record or CNAME record alias. ## What Is an Authoritative Name Server? An authoritative name server is a DNS name server that has the authority to respond to DNS queries by checking DNS records that are stored locally on the authoritative name server. There are three types of authoritative name servers: #### Primary master authoritative name server The primary master contains the master copy of the DNS records and it acts as the primary authoritative name server; all clients look to the server as the source of truth for DNS services. #### Secondary server authoritative name server The secondary server has an exact duplicate of the specific zones hosted on the primary authoritative name server. There can be many secondary authoritative name systems on the network, and they can even process master zones. #### Stealth authoritative name server Stealth servers, sometimes called DMZ or hidden authoritative name servers, are non-public authoritative DNS resolvers. These are often implemented in security-conscious environments; any DNS request for public resources goes straight out to the ISP Name server. ## What Is a Local DNS Server? Most home networks and nearly all business networks have at least one local DNS server. A local DNS server is usually the very first hop when resolving a DNS recursive query. If the resource you are connecting to is located on the local network, there is no requirement for DNS to query your ISP authoritative DNS server, and the ISP domain name servers would never even keep a record of your local resources anyway. For such a query, Local DNS is used. This can be a DNS server running on your network equipment or a fully configured corporate DNS Server farm configured as a local authoritative DNS server. Local DNS Servers run on Windows Servers and Linux Operating Systems, and they are typically managed by system administrators using a DNS manager tool. One of the most common uses of DNS is by Microsoft Active Directory Domain Servers (AD DS). Active Directory Domain Controllers use DNS to manage local resources. Networked Computers and Servers use DNS to locate the Domain Controller, and the Domain Controllers use DNS to locate all other Domain Controllers and local domain names. If you operate a Windows network of Computers and Servers, the DNS service is enabled by default. This allows automatic discovery of DNS servers, networked resources, and other servers on the local network. ## How Do I Fix a DNS Server Problem? DNS is used everywhere, including on your home network, in your workplace, and on all the infrastructure you are using to read this post. Most end-users interact with DNS in a work environment, and DNS is a key component of the entire business network. A DNS not only points your internal DNS queries from your web browsers to internal corporate websites, but also ensures that a business directory server has a route to every server connected to the network. ## DNS at Atlantic.Net Atlantic.Net’s [Cloud Portal](https://cloud.atlantic.net/?page=userlogin) includes a DNS management module that enables you to manage DNS records for your domains. DNS records tell people where your domain is hosted so they can reach it by name instead of just by server IP. - From the ACP Cloud Portal, navigate to the**“DNS”** button and click “**Add Domain.”** - After adding your domain, you will get a popup that says “Domain created successfully!” - After hitting “OK” on the popup, you will go back to the DNS page with a list of your domains. There are buttons next to each labeled “Manage” and “Delete.” - “Delete” will delete the domain and all associated DNS records from the system, and “Manage” will take you to the management page for that domain. - The next step is to add a DNS record; this information is available from your domain registrar. - Click the “Add DNS Record” button and fill in the information: - In the *Type* column, choose “**A/AAAA**.” - Leave the *Host *field **empty.** - In the *Content *column, enter **your server IP address.** - Click “**Add.”** The records may take a few minutes to make their way to the rest of the world or “propagate.” While our side knows the records were added, those records then have to propagate to all other name servers that any other computer is using for others to be able to access it correctly. This process can take up to 72 hours to complete globally but is usually done locally within 5-15 minutes. We can test our newly created record by either going to the site or checking a DNS propagation tool such as [WhatsMyDNS](https://www.whatsmydns.net/). ## DNS Q&A ### What Is My DNS Server Address? If you are on a home network, the DNS server is usually the IP address of your home network router. This is because in most home scenarios the router is responsible for resolving DNS lookups. The IP address will be either *192.168.1.1*or *192.168.1.254*in most setups; if you browse to this address you will be prompted to log into the home router. For internal networking, the router will redirect traffic locally, and for a DNS query on the Internet, the router will query the DNS server provided by your ISP. Corporate types of DNS systems are usually different; in a corporate situation, a dedicated DNS server will serve DNS requests. These types of DNS systems are typically managed by system administrators; a standard user would never normally interact with them. If you are using Windows type *ipconfig /all* to view information about your DNS configuration. If you are using a MacOS or Linux type *scutil –dns | grep ‘nameserver\[[0-9]*\]’* ### What Is “DNS Server Not Responding?” If after a DNS query you are getting the error message that reads something like “DNS server is not responding” it’s likely your Internet access is down or you are unable to browse to an internal website. In most circumstances, this error is a Local issue with your computer rather than with the DNS resolver; check network connectivity, reboot your router, or reboot your pc. this will fix the problem in most scenarios, if you are using a business system contact the IT department. ### What Does DNS Stand For? DNS stands for Domain Name System. ### How Do I Change DNS on Windows 10? On a Windows client system, you can check the DNS settings using *ipconfig*; however, to configure DNS settings perform the following process (this is the same process for IPV4 and IPV6). - Right-click the network icon in the system tray and then click Open Network And Sharing Center. - Click Change Adapter Settings. - Right-click the appropriate network adapter and then click Properties. - Double-click either IPv4 or IPv6)faith. - Click Use The Following DNS Server Addresses and then enter a valid IPv4 or IPv6 address for a DNS server that is accessible to the client. You can also configure DNS settings by using Netsh.exe from the Command Line **netsh interface ip set DNS name=”Ethernet” static <*DNS Server IP*>** If you prefer to use Windows PowerShell to manage DNS, type : **Set-DNSClientServerAddress -interfaceIndex <*your ethernet-id*> -ServerAddresses (‘<*DNS Server IP*>’)** ### How Do I Configure DNS Advanced Settings? Advanced DNS Settings are available from the properties box on your IPV4 or IPv6 adapter. Click *Advanced* and then click the *DNS* tab. If you want to take a deep dive into the configuration I highly recommend this book from Microsoft – [Exam Ref 70-698 Installing and Configuring Windows 10, 2nd Edition](https://www.microsoftpressstore.com/store/exam-ref-70-698-installing-and-configuring-windows-9781509307876) The advanced DNS settings are: #### Append Primary And Connection Specific DNS Suffixes This option controls how the DNS resolver on the local client appends the DNS suffixes during queries. It lists the nameservers your computer will use for DNS resolution and the order in which they will be queried. #### Append Parent Suffixes Of The Primary DNS Suffix Appending suffixes speeds up the process of name resolution during a DNS query; performance is marginal on small systems, but on enterprise-scale systems, this is an essential service. #### Append These DNS Suffixes This option enables you to define suffixes and order them for a DNS query. Consider the DNS suffix [cloud.atlantic.net](https://cloud.atlantic.net/?page=userlogin), it will append *atlantic.net*and *.net* to the query. Again, this is a service designed to speed up DNS queries in large environments. #### DNS suffix For This Connection You can define a DNS suffix for each network interface card installed in your device. This is automatically set when running Active Directory. #### Register This Connection’s Address When selected, this option enables your server to dynamically create DNS records. #### Use This Connection’s DNS Suffix This option determines whether the IP addresses and the connection-specific domain name of this connection are registered with DNS. ### What Is DNS Spoofing? DNS Spoofing is a technique used by Hackers to redirect unexpected users to fake websites at IP addresses they choose rather than the IP addresses in a legitimate DNS record. It is similar to ARP poisoning, except the attack attempts to hijack the DNS cache. This can result in the victim being redirected to bogus Internet sites after making a DNS query. The risk of DNS spoofing can be mitigated by using these techniques: - Resolve all DNS queries locally. - Implement DNSSEC. - Block DNS requests from going to external DNS servers. It is important to remember that spoofing attacks trick victims into thinking that something legitimate is occurring. #### What is Google Public DNS? Google Public DNS is not an authoritative nameserver; instead, it is a public DNS record resolver that anyone can use, and it’s a great developers tool for testing. Just a word of caution: make sure you read the [privacy policy](https://developers.google.com/speed/public-dns/privacy) for Google DNS solutions because ISP and geolocation information is stored permanently on their servers. Via IPv4 the addresses are **8.8.8.8** and **8.8.4.4** Via IPv6 the addresses are **2001:4860:4860::8888** and **2001:4860:4860::8844** ### How Do I Troubleshoot DNS? There are many online resources that can help determine whether a DNS record is set up correctly, most notably [WhatsMyDNS](https://www.whatsmydns.net/)which was referenced earlier. With WhatsMyDNS you can check each DNS record type you’re using. The only thing to note would be that WhatsMyDNS does not differentiate the TXT records (SPF, DKIM, and DMARC), and it will only provide the output for those records, not whether or not they are working as needed. [MXToolbox](https://mxtoolbox.com/) is another resource that can help with checking DNS records, specifically MX records. They also provide other services, including blacklist checks against a long list of blacklists, SMTP Diagnostics (some email providers require strict SMTP settings, including some DNS settings), and a Domain Health Report, which can determine what can be done to improve DNS configuration. Another convenient toolset is the default DNS tools that come with most operating systems. Windows comes with the ‘**nslookup**’ command, which can perform DNS queries directly from your system, and Linux systems also have the ‘**dig**’ command, which allows for similar requests. [You can find a guide on using ‘**nslookup**’ here](https://docs.microsoft.com/en-us/previous-versions/tn-archive/aa997324(v=exchg.65)?redirectedfrom=MSDN) [and one for ‘**dig**’ here](https://www.cyberciti.biz/faq/linux-unix-dig-command-examples-usage-syntax/). ### What Is DNS Caching? DNS caching is when DNS servers or root servers store DNS records locally. DNS caching reduces the wait time from your web browser request, quite often resource record needed in available almost instantly. The DNS lookup process is quick, and a recursive DNS query is much faster. One issue experienced with DNS caching is that the DNS lookup request might be out of date, which can cause delays on the resource record being updated. You can flush the DNS caching by issuing the command *ipconfig /flushdns*. This forces the DNS resolver to make a new DNS query every time a web browser requests a page – thus forcing the DNS caching to update. ### What’s a DNS Zone? A DNS zone is an administrative unit that hosts a collection of computers in the DNS namespace. The Zone is considered a sub-tree of the DNS database. The DNS configuration for a zone is stored in a zone file and the DNS servers refer to the information within the zone file. ### What Is the “in-addr.arpa” Zone Used for? This zone is used by a reverse lookup of a hostname. ### What Port does DNS use? DNS uses TCP/UDP port 53 ### **What Are the Requirements from DNS to Support Active Directory? ** When you install Active Directory on a domain server, the process promotes a server to a domain controller. Active Directory uses DNS as the location mechanism for domain controllers, enabling computers on the network to obtain the IP addresses of domain resources. During installation, the service (SRV) and address (A) records are dynamically registered by DNS, enabling the DC to find domain resources and vice versa. To find domain controllers in a domain or forest, a client queries DNS for the SRV and A record of the domain controller which is granted the IP addresses of the DC. When adding a domain controller to a domain forest, the DNS zone is updated with the Locator DNS resource records identifying the resource. For this to work, the DNS zone must allow dynamic updates (RFC 2136), and the DNS server hosting that zone must support the SRV resource records (RFC 2782) to advertise the Active Directory directory service. If the server does not support the required standards or the authoritative DNS zone cannot be configured to allow dynamic updates, the process will not work correctly. ## Where Can I Learn More About DNS? Atlantic.Net’s engineers have first-hand experience with the complexities of DNS server management. Our private and public VPS Cloud solutions have innovative, easy-to-use DNS resolver features built-in all available with a few clicks in your web browsers, taking the complexity out of DNS. All you need is a top-level domain (TLD Name) from your DNS provider; our system handles everything else. Should you have any trouble with the cloud DNS Manager, you can contact our technical support at any time via email at [cloudsupport@atlantic.net](mailto:cloudsupport@atlantic.net), phone at 1-866-618-3282 option 2, or LiveChat anywhere on the site. An industry-leading cloud hosting services provider, Atlantic.Net brings over 30 years of experience, hosting the infrastructure of top organizations. All personnel is trained to high-security standards, and Atlantic.Net is audited to ensure our [VPS hosting](https://www.atlantic.net/vps-hosting/) platforms are built and managed to the highest of standards. We can help you to achieve a fully secure and protected environment. [Contact our sales team](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) today to find out more about how Atlantic.Net can benefit your organization. --- --- # How to Install Grafana on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-grafana-on-oracle-linux-10/ | Published: 2023-01-12 | Updated: 2025-12-05 | Author: Hitesh Jethva Grafana is a free and open-source data visualization and monitoring tool used for monitoring and visualizing metrics from remote machines. It can be used with Prometheus, InfluxDB, Graphite, and ElasticSearch to gather metrics and display them on the user-friendly dashboard. Grafana allows you to share the generated graphs as snapshots with other users. You can also write your own plugins from scratch to integrate several different data sources. In this post, we will show you how to install Grafana on Oracle Linux 10. ## Step 1 – Add a Grafana Repo By default, the Grafana package is not included in the Oracle Linux default repo, so you will need to create a new one for Grafana. You can create it with the following command: ``` nano /etc/yum.repos.d/grafana.repo ``` Add the following lines: ``` [grafana] name=grafana baseurl=https://packages.grafana.com/oss/rpm repo_gpgcheck=1 enabled=1 gpgcheck=1 gpgkey=https://packages.grafana.com/gpg.key sslverify=1 sslcacert=/etc/pki/tls/certs/ca-bundle.crt ``` Save and close the file, then verify the added repo using the following command: ``` dnf repolist ``` You should see the following output: ``` repo id repo name grafana grafana ol8_UEKR6 Latest Unbreakable Enterprise Kernel Release 6 for Oracle Linux 10 (x86_64) ol8_appstream Oracle Linux 10 Application Stream (x86_64) ol8_baseos_latest Oracle Linux 10 BaseOS Latest (x86_64) ``` Next, verify the Grafana package information using the following command: ``` dnf info grafana -y ``` You should see the following output: ``` Name : grafana Version : 12.3.0 Release : 1 Architecture : x86_64 Size : 184 M Source : grafana-12.3.0-1.src.rpm Repository : grafana Summary : Grafana URL : https://grafana.com License : AGPLv3 Description : Grafana ``` ## Step 2 – Install Grafana Now, run the following command to install the Grafana package on your server. ``` dnf install grafana -y ``` Once the Grafana is installed, start the Grafana service and enable it to start at system reboot: ``` systemctl start grafana-server systemctl enable grafana-server ``` You can also check the status of the Grafana service with the following command: ``` systemctl status grafana-server ``` You should see the following output: ``` ● grafana-server.service - Grafana instance Loaded: loaded (/usr/lib/systemd/system/grafana-server.service; disabled; preset: disabled) Active: active (running) since Fri 2025-12-05 06:54:19 EST; 30s ago Invocation: 90666f347af44677a6ad85cf0ab8e476 Docs: http://docs.grafana.org Main PID: 64657 (grafana) Tasks: 8 (limit: 24812) Memory: 443M (peak: 445.2M) CPU: 3.097s CGroup: /system.slice/grafana-server.service └─64657 /usr/share/grafana/bin/grafana server --config=/etc/grafana/grafana.ini --pidfile=/var/run/grafana/grafana-server.pid --packaging=rpm cfg:default.paths.logs=/var/>1-04:00 level=info msgy default, Grafana listens on port 3000. You can check it with the following command: ``` ``` ss -antpl | grep 3000 ``` You should see the following output: ``` LISTEN 0 128 *:3000 *:* users:(("grafana-server",pid=7063,fd=9)) ``` ## Step 3 – Configure Nginx as a Reverse Proxy for Grafana It is recommended to configure Nginx as a reverse proxy so you can access the Grafana without specifying port 3000. First, install the Nginx server with the following command: ``` dnf install nginx -y ``` Once the Nginx package is installed, create an Nginx virtual host configuration file for Grafana: ``` nano /etc/nginx/conf.d/grafana.conf ``` Add the following lines: ``` server { server_name grafana.example.com; listen 80 ; access_log /var/log/nginx/grafana.log; location / { proxy_pass http://localhost:3000; proxy_set_header Host $http_host; proxy_set_header X-Forwarded-Host $host:$server_port; proxy_set_header X-Forwarded-Server $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; } } ``` Save and close the file, then edit the Nginx main configuration file: ``` nano /etc/nginx/nginx.conf ``` Add the following line below http {: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then verify the Nginx configuration file: ``` nginx -t ``` If your configuration is correct, you will see the message output ‘syntax is ok’ as below. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, start and enable the Nginx service: ``` systemctl start nginx systemctl enable nginx ``` You can also check the Nginx status using the following command: ``` systemctl status nginx ``` You will get the following output: ``` ● nginx.service - The nginx HTTP and reverse proxy server Loaded: loaded (/usr/lib/systemd/system/nginx.service; disabled; preset: disabled) Drop-In: /etc/systemd/system/nginx.service.d └─php-fpm.conf Active: active (running) since Fri 2025-12-05 06:56:07 EST; 4min 15s ago Invocation: 97efc99d02ca43948d6e6662d71e6d63 Process: 64808 ExecStartPre=/usr/bin/rm -f /run/nginx.pid (code=exited, status=0/SUCCESS) Process: 64810 ExecStartPre=/usr/sbin/nginx -t (code=exited, status=0/SUCCESS) Process: 64812 ExecStart=/usr/sbin/nginx (code=exited, status=0/SUCCESS) Main PID: 64814 (nginx) Tasks: 3 (limit: 24812) Memory: 5.5M (peak: 18.2M) CPU: 71ms CGroup: /system.slice/nginx.service ├─64814 "nginx: master process /usr/sbin/nginx" ├─64815 "nginx: worker process" └─64816 "nginx: worker process" ``` ## Step 4 – Access Grafana Dashboard At this point, Grafana is installed and running. You can now access the Grafana dashboard using the URL **http://grafana.example.com**. You should see the Grafana login page: ![Grafana login page](https://www.atlantic.net/wp-content/uploads/2022/07/p1-1-1024x564.png) Provide the default username and password as admin then click on the **Log** **in** button. You should see the change password screen: ![Grafana change default password page](https://www.atlantic.net/wp-content/uploads/2022/07/p2-1.png) Change your default admin password and click on the **Change** **Password** button. You should see the Grafana dashboard on the following page: ![Grafana dashboard page](https://www.atlantic.net/wp-content/uploads/2022/07/p3-1-1024x503.png) ## Conclusion In this post, we explained how to install Grafana with Nginx as a reverse proxy on Oracle Linux 10. You can now add external data sources to Grafana and start monitoring them from the web-based interface. For more information, visit the Grafana [documentation](http://docs.grafana.org/) page. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Add A Private IP to an Ubuntu Server > URL: https://www.atlantic.net/vps-hosting/how-to-add-a-private-ip-to-an-ubuntu-server/ | Published: 2023-01-13 | Updated: 2026-03-02 | Author: Richard Bailey ##### Verified and Tested 01/13/2023 ## Introduction In this How-to, we will learn how to configure a private IP address on an Ubuntu Server. Private networking is a great way to keep the traffic between your servers internal and not accessible publicly. It allows you to communicate between your servers without using your Cloud bandwidth as well. It is also faster than public traversal as it will not require leaving the network to reach the destination server. At this time, private networking within our Cloud will only be able to communicate with same-region servers. ## Prerequisites - A server with Ubuntu. If you do not have a server already, you can spin up any of our affordable [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions in under 30 seconds. ## Verifying your Private IP range with our Cloud Control Panel First, we will need to determine what you are allocated for your private IP range. If you have a Cloud server with us, I will go through how to find the Private IP address range you are allocated. If you do not know your private IP range or address, please consult your network administrator. ## Step 1 – Log Into Cloud.Atlantic.Net Sign in to your [Cloud Control Panel](https://cloud.atlantic.net/?page=userlogin): ![Cloud by Atlantic.Net Login](https://www.atlantic.net/wp-content/uploads/2021/03/2015-06-30-21_53_26-Cloud-by-Atlantic.Net-Login-1.png) Signing into Cloud Control Panel ## Step 2 – Find your Private IP Range. Once logged in, you will see “Private IPs” listed on the left side. ![](https://www.atlantic.net/wp-content/uploads/2021/03/2015_06_30_21_58_02_Cloud_by_Atlantic.Net_-1-118x300.png) You will see the IP range allocated to your account on the Private IP page. Under “IP” are the Private IPs available to use. For example: ![](https://www.atlantic.net/wp-content/uploads/2021/03/2015_06_30_22_04_07_Cloud_by_Atlantic.Net_.png) Once you have the private IP range to use, we will add it to our Ubuntu server. ## Adding the Private IP address to your Ubuntu Server ## Step 3 – Install Net-Tools Ensure you have Ubuntu Net-Tools installed on the Server ``` sudo apt install net-tools ``` ## Step 4 – Check Present Status of Eth1 You can check the current status of your network interfaces by using ``` ip addr show ``` From the output below, you can see that my eth1 interface is currently DOWN. ``` eth0: mtu 1500 qdisc fq_codel state UP group default qlen 1000 link/ether 00:00:45:1c:5e:59 brd ff:ff:ff:ff:ff:ff inet 69.28.94.89/22 brd 69.28.95.255 scope global eth0   valid_lft forever preferred_lft forever inet6 fe80::200:45ff:fe1c:5e59/64 scope link   valid_lft forever preferred_lft forever eth1: mtu 1500 qdisc fq_codel state DOWN group default qlen 1000 link/ether 00:00:0a:1c:5e:59 brd ff:ff:ff:ff:ff:ff ``` The interface state can be changed to **up** or **down** by using the command: ``` ifconfig eth1 up ifconfig eth1 down ``` ## Step 5 – Update Netplan Config Log on to your server and use your text editor to open /etc/netplan/01-netcfg.yaml .In this tutorial, we will be using nano. ``` nano /etc/netplan/01-netcfg.yaml ``` We will need to add the private IP address as an additional IP. You can add your private IP address below the existing public IP address as shown below: **Note**: Netplan uses YAML so you must adhere to the writing standards of YAML ``` network: version: 2 renderer: networkd ethernets:   eth0:     addresses:       - 69.28.94.89/22     gateway4: 69.28.92.1     nameservers:       addresses:         - 209.208.127.65         - 209.208.25.18   eth1:      dhcp4: yes      addresses:        - 10.126.130.10/24 ``` ## Step 6 – Debug the Netplan config Save and close the file, then verify the configuration with the following command: ``` netplan --debug generate ``` If everything is fine, you should get the following output: ``` root@turbogeek:/etc/systemd/network# netplan --debug generate DEBUG:command generate: running ['/lib/netplan/generate'] ** (generate:3802655): DEBUG: 21:59:17.127: starting new processing pass ** (generate:3802655): DEBUG: 21:59:17.128: We have some netdefs, pass them through a final round of validation ** (generate:3802655): DEBUG: 21:59:17.129: eth1: setting default backend to 1 ** (generate:3802655): DEBUG: 21:59:17.129: Configuration is valid ** (generate:3802655): DEBUG: 21:59:17.129: eth0: setting default backend to 1 ** (generate:3802655): DEBUG: 21:59:17.129: Configuration is valid ** (generate:3802655): DEBUG: 21:59:17.130: Generating output files.. ** (generate:3802655): DEBUG: 21:59:17.130: openvswitch: definition eth0 is not for us (backend 1) ** (generate:3802655): DEBUG: 21:59:17.130: NetworkManager: definition eth0 is not for us (backend 1) ** (generate:3802655): DEBUG: 21:59:17.130: openvswitch: definition eth1 is not for us (backend 1) ** (generate:3802655): DEBUG: 21:59:17.130: NetworkManager: definition eth1 is not for us (backend 1) (generate:3802655): GLib-DEBUG: 21:59:17.131: posix_spawn avoided (fd close requested) (generate:3802655): GLib-DEBUG: 21:59:17.143: posix_spawn avoided (fd close requested) ``` ## Step 7 – Apply Netplan Next, restart NetPlan to apply the changes: ``` netplan apply ``` You can now verify your new IP address using the following command: ``` ip addr ``` You should get the following output: ``` 2: eth0: mtu 1500 qdisc fq_codel state UP group default qlen 1000   link/ether 00:00:45:1c:5e:59 brd ff:ff:ff:ff:ff:ff   inet 69.28.94.89/22 brd 69.28.95.255 scope global eth0      valid_lft forever preferred_lft forever   inet6 fe80::200:45ff:fe1c:5e59/64 scope link      valid_lft forever preferred_lft forever 3: eth1: mtu 1500 qdisc fq_codel state UP group default qlen 1000   link/ether 00:00:0a:1c:5e:59 brd ff:ff:ff:ff:ff:ff   inet 10.126.130.10/24 brd 10.126.130.255 scope global eth1      valid_lft forever preferred_lft forever   inet6 fe80::200:aff:fe1c:5e59/64 scope link      valid_lft forever preferred_lft forever ``` You have successfully added a Private IP to your Ubuntu Server! Don’t forget to check out our many other articles and keep checking back for more.  Atlantic.Net has a selection of [industry-leading cloud servers](https://www.atlantic.net/vps-hosting/) for a wide variety of business needs. --- # PCI Compliance for Kubernetes > URL: https://www.atlantic.net/pci-compliant-hosting/pci-compliance-for-kubernetes/ | Published: 2023-01-14 | Updated: 2024-09-23 | Author: Gilad Maayan ## What is PCI Compliance? Payment Card Industry (PCI) compliance is a standard enforced by credit card companies to ensure the security of credit card transactions in the payment industry. It is a set of technical and operational standards companies follow to secure credit card data, whether provided by cardholders or transmitted through card processing transactions. The PCI Security Standards Council (SSC) develops and maintains PCI compliance standards. The Federal Trade Commission (FTC) oversees credit card processing due to consumer protection and oversight needs. PCI compliance is not necessarily a regulatory requirement but might be taken into account by regulators through legal precedent. [PCI compliance](https://www.atlantic.net/pci-compliant-hosting/what-is-pci-compliance/) is typically a key component of credit card company security protocols. It is usually required by the credit card company and is a part of credit card provider agreements. The PCI Standards Committee is responsible for developing standards that comply with PCI standards. These standards apply to merchant processing and outline requirements such as methods for encrypting Internet transactions. Other important organizations involved in developing standards for the credit card industry include the Network of Card Associations and the National Automated Clearing House (NACHA). ## Why is PCI Compliance Different in Containers and Kubernetes? [As applications move to the cloud](https://bluexp.netapp.com/blog/cloud-migration-strategy-challenges-and-steps), several key characteristics of containerized environments make PCI container compliance difficult: - In the past, virtual machine (VM) sprawl was considered a challenge in PCI compliance. Today’s containerized environments worsen things, with thousands or even millions of containers in large-scale environments. - Containers are ephemeral, with IP addresses constantly changing, making them difficult to track and monitor. - Developers extract open-source base images and leverage third-party libraries to build and extend containerized applications. These third-party components create a range of security risks. - Containers raise software quality concerns because of the difficulty of managing software development pipelines in a containerized environment. - PCI requires addressing known and newly discovered vulnerabilities, which can be challenging in a containerized environment, given the sheer number of components and moving parts. ## PCI DSS Compliance in Kubernetes-Based Platforms: 7 Best Practices ### Firewall Configuration You can add a firewall to applications deployed on Kubernetes by using container network interface (CNI) providers that support Kubernetes network policies. Combined with a formal process for who can update rules and how they provide adequate protection. Payment card data must be on the internal network. Enterprises can connect their internal networks with public networks, but a demilitarized zone (DMZ) must be established between them, with strict traffic flow rules. Network policies can help as they can selectively expose services based on IP ranges. ### Restrict Cardholder Data Access on a Need-To-Know Basis Within your organization, access to cardholder data should be limited to those who need it to do their job. PCI DSS compliance requires access control systems in place to enforce these restrictions. Organizations should use the following: - Secure application protocols such as LDAP and Active Directory (AD). - Security systems integrated with role-based access control [(RBAC) provided by Kubernetes](https://komodor.com/learn/kubernetes-rbac/), OpenShift, and others. - Avoid exposing real cardholder data to security and DevOps teams monitoring the environment. ### Avoiding Default Passwords and Security Parameters Kubernetes is completely unaware of which applications are being deployed. Therefore, it does not protect against configuration errors such as using default passwords or other security parameters. However, the Open Policy Agent (OPA) allows you to set a policy in a configuration file that can, for example, not allow the use of a default password. If an administrator makes a mistake, OPA catches it before the resource is created in the Kubernetes platform. The bug does not find its way to production, and the reason is documented. This requirement also states that services with different security levels must not coexist on the same server. To ensure this, you need to annotate your Kubernetes worker nodes with security levels. All pod specifications must reference required security levels. This should be specified automatically via OPAs to prevent human error. ### Protect All Systems Against Malware and Regularly Update Antivirus Solutions PCI requires that antivirus solutions are deployed on all systems commonly affected by malware, such as PCs and servers. These solutions must be properly maintained and kept active and not be disabled or modified without administrative authority (and if so, only on a specific and limited basis). Organizations can use orchestration tools to ensure secure containers are always running antivirus software. This can also be achieved by running a container firewall, which keeps systems virtually patched and up-to-date while still detecting suspicious file systems or network activity. ### Develop/Maintain Secure Systems and Applications PCI DSS requires organizations to pay close attention to systems and applications from development to production. This means proactively addressing security updates and newly discovered vulnerabilities, and following established rules for change control processes and procedures. If you have a container environment, this means adopting a container security strategy that secures your application throughout its build, ship, and run cycle. Integrating container security into your [CI/CD environment](https://codefresh.io/learn/ci-cd/) is ideal for meeting these requirements. ### Track and Monitor All Access to Network Resources and Cardholder Data PCI DSS requires managing individual user access to all system components (without shared accounts), and the implementation of an audit trail to reconstruct accurate details of each event. These audit trails must be protected from modification, and all logs and security events must be reviewed to identify unusual or suspicious activity. Organizations that use containers must implement a security system that maintains event logs of all user activity and actions, tracks all communication between containers for event reconstruction, and is compatible with SIEM systems. ### Regularly Test Security Systems and Processes PCI DSS compliance requires network vulnerability scans, at least on a quarterly basis, and after major network changes. Network intrusion detection and/or prevention technologies should be used in conjunction with traffic monitoring at CDE perimeters and critical points. You also need a change detection mechanism to alert you if sensitive files have been tampered with. From a container environment perspective, it is important to have a firewall that actively scans running containers for vulnerabilities and threats inside and outside the environment, and automatically detects and mitigates suspicious behavior. ## Conclusion In this article, I explained the basics of PCI DSS and how to comply with it in Kubernetes: - **Firewall configuration**—You can add a firewall to applications deployed on Kubernetes by using CNI providers that support Kubernetes network policies. - **Restrict cardholder data access on a need-to-know basis**—Organizations should use the following LDAP and RBAC to enforce access control. - **Avoiding default passwords and security parameters**—The OPA allows you to set a policy in a configuration file that can, for example, not allow the use of a default password. - **Protect all systems against malware and regularly update antivirus solutions**—Organizations can use orchestration tools to ensure secure containers are always running antivirus software. - **Develop/Maintain secure systems and applications**—Adopt a container security strategy that secures your application throughout its build, ship, and run cycle. - **Track and monitor all access to network resources and cardholder data**—Implement a security system that maintains event logs of all user activity and actions, tracks all communication between containers for event reconstruction, and is compatible with SIEM systems. - **Regularly test security systems and processes**—Network intrusion detection and/or prevention technologies should be used in conjunction with traffic monitoring at CDE perimeters and critical points. I hope this will be useful as you make Kubernetes comply with the PCI DSS. To learn more about [PCI-compliant hosting](https://www.atlantic.net/pci-compliant-hosting/) with Atlantic.Net, contact the sales team at [sales@atlantic.net](mailto:sales@atlantic.net) today.   --- # How to Install and Use PostgreSQL on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-postgresql-on-oracle-linux-10/ | Published: 2023-01-15 | Updated: 2025-12-05 | Author: Hitesh Jethva PostgreSQL is a free, open-source, secure, and robust relational database management system. It is specifically designed for high-performance, mission-critical applications. PostgreSQL supports SQL and JSON querying and is mainly used for many web and mobile and analytics applications. It is compatible with various platforms using all major languages and middleware. When writing this article, PostgreSQL 14 is the latest version. This version significantly improves the indexing and lookup system that benefits large databases. This post will show you how to install and secure PostgreSQL on Oracle Linux 10. ## Step 1 – Add PostgreSQL 18 Repository By default, the latest version of PostgreSQL is not included in the Oracle Linux default repository. So you will need to add the third-party repository for PostgreSQL. Install the PostgreSQL repository with the following command. ``` dnf update -y ``` ``` dnf install https://download.postgresql.org/pub/repos/yum/reporpms/EL-8-x86_64/pgdg-redhat-repo-latest.noarch.rpm ``` ``` ``` Once the repo is created, you can proceed to the next step. ## Step 2 – Install PostgreSQL 18 on Oracle Linux 10 Now, update your repository using the following command: ``` dnf update -y ``` Next, install the latest version of PostgreSQL by running the following command: ``` dnf install postgresql18 postgresql18-server ``` Next, initialize the PostgreSQL database with the following command: ``` /usr/pgsql-18/bin/postgresql-18-setup initdb ``` Sample output: ``` Initializing database ... OK ``` Next, start the PostgreSQL service and enable it to start at system reboot with the following command: ``` systemctl start postgresql-18 systemctl enable postgresql-18 ``` You can check the status of PostgreSQL with the following command: ``` systemctl status postgresql-18 ``` You should get the following output: ``` ● postgresql-18.service - PostgreSQL 18 database server Loaded: loaded (/usr/lib/systemd/system/postgresql-18.service; disabled; preset: disabled) Active: active (running) since Fri 2025-12-05 06:40:31 EST; 28s ago Invocation: c30e51f4a3784766bb0e0acb92d05d16 Docs: https://www.postgresql.org/docs/18/static/ Process: 64277 ExecStartPre=/usr/pgsql-18/bin/postgresql-18-check-db-dir ${PGDATA} (code=exited, status=0/SUCCESS) Main PID: 64283 (postgres) Tasks: 10 (limit: 24812) Memory: 22M (peak: 22.5M) CPU: 55ms CGroup: /system.slice/postgresql-18.service ├─64283 /usr/pgsql-18/bin/postgres -D /var/lib/pgsql/18/data/ ├─64284 "postgres: logger " ├─64285 "postgres: io worker 0" ├─64286 "postgres: io worker 2" ├─64287 "postgres: io worker 1" ├─64288 "postgres: checkpointer " ├─64289 "postgres: background writer " ├─64291 "postgres: walwriter " ├─64292 "postgres: autovacuum launcher " └─64293 "postgres: logical replication launcher " ``` By default, PostgreSQL listens on port 5432. You can check it with the following command: ``` ss -antpl | grep 5432 ``` You will get the following output: ``` LISTEN 0 128 127.0.0.1:5432 0.0.0.0:* users:(("postmaster",pid=2090,fd=7)) LISTEN 0 128 [::1]:5432 [::]:* users:(("postmaster",pid=2090,fd=6)) ``` Also Read [How to Secure PostgreSQL Server in Linux](https://www.atlantic.net/vps-hosting/how-to-secure-postgresql-server/) ## Step 3 – Set a Password for the Postgres User By default, the Postgres user’s password is not set, so it is recommended to set a password for security reasons. To set a password, log in to PostgreSQL with the following command: ``` su - postgres ``` Next, set a secure password with the following command: ``` psql -c "alter user postgres with password 'securepassword'" ``` Next, exit from the PostgreSQL shell using the following command: ``` exit ``` ## Step 4 – Change PostgreSQL Authentication Method By default, PostgreSQL is configured to use the peer method to connect to PostgreSQL locally, but this method is not recommended for the production environment. It is recommended to change the authentication method from peer to scram-sha-256. You can change it by editing the PostgreSQL main configuration file: ``` nano /var/lib/pgsql/18/data/pg_hba.conf ``` Find the following line: ``` local all all peer ``` And replace it with the next line: ``` local all all scram-sha-256 ``` Save and close the file, then restart the PostgreSQL service to apply the changes. ``` systemctl restart postgresql-18 ``` ## Step 5 – Create a Database and User in PostgreSQL First, log in to the PostgreSQL shell with the following command: ``` sudo -u postgres psql ``` You will get the following output: ``` psql (18.3) Type "help" for help. postgres=# ``` Next, create a new PostgreSQL user named testuser using the following command: ``` CREATE USER testuser WITH CREATEDB CREATEROLE PASSWORD 'passoword'; ``` To verify the PostgreSQL users, run: ``` \du ``` You will get the following output: ``` List of roles Role name | Attributes | Member of -----------+------------------------------------------------------------+----------- postgres | Superuser, Create role, Create DB, Replication, Bypass RLS | {} testuser | Create role, Create DB | {} ``` To create a new PostgreSQL database named testdb, run: ``` CREATE DATABASE testdb OWNER testuser; ``` To verify the PostgreSQL databases, run: ``` \l ``` You will get the following result: ``` List of databases Name | Owner | Encoding | Collate | Ctype | Access privileges -----------+----------+----------+-------------+-------------+----------------------- postgres | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | template0 | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | =c/postgres + | | | | | postgres=CTc/postgres template1 | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | =c/postgres + | | | | | postgres=CTc/postgres testdb | testuser | UTF8 | en_US.UTF-8 | en_US.UTF-8 | (4 rows) postgres=# ``` Also Read [How to Backup and Restore a Database in PostgreSQL](https://www.atlantic.net/vps-hosting/how-to-backup-and-restore-database-in-postgresql/) ## Conclusion This post explained how to install PostgreSQL on Oracle Linux 10. You can now start working with PostgreSQL to familiarize yourself with its features. For security reasons, installing the latest version of PostgreSQL in the production environment is always recommended. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Does Using SaaS Make My IT Environment More Secure or Less Secure? > URL: https://www.atlantic.net/vps-hosting/does-using-saas-make-my-it-environment-more-secure-or-less-secure/ | Published: 2023-01-16 | Updated: 2026-07-07 | Author: Richard Bailey As modern businesses turn to cutting-edge SaaS applications to improve business capabilities and save costs, the security of cloud-based workloads is a primary requirement. [SaaS platforms](https://www.atlantic.net/vps-hosting/what-is-saas-hosting/) introduce significant benefits to digital business, but one big question remains; does using SaaS make my IT environment more or less secure? It’s a difficult question because security is an outstanding experience for most SaaS subscribers. Unfortunately, several high-profile security breaches against SaaS platforms have raised concerns around the SaaS ecosystem and asked questions about the threat to the downstream supply chain. In this article, we will learn about the security outlook of SaaS, investigate the significant data breaches, and discover how you can defend against SaaS security threats. ## What is SaaS? There are countless SaaS applications on the market, and you will likely use at least one of these products professionally or personally. Google Docs (G Suite), Microsoft Office 365, Salesforce, Slack, Teams, and Zoom are just a few. Over [11,000 SaaS companies](https://virayo.com/saas/statistics/) are operating worldwide, and 85% of businesses will be utilizing SaaS platforms by 2025. Software as a Service typically involves the digital delivery of an online software product, usually from a cloud provider. Users access the software over the internet after subscribing to the service. Upon purchase, you are given an account; you log in and start consuming the service. SaaS products are usually business applications paid for via a monthly subscription. This opens the door for businesses to consume expensive enterprise-grade applications on an affordable pay-as-you-go model. In addition, SaaS deployments use cloud servers to power the application, and the user only requires a moderately powered laptop or PC to use it. SaaS platforms are prevalent. For example, there are [345 million active subscriptions](https://office365itpros.com/2022/04/28/office-365-number-of-users/) to the popular Office 365 Suite. This figure includes business and personal accounts. Microsoft has 75% of the biggest global companies on their account books for Office. Popular SaaS platforms must be at the forefront of security best practices to defend against sophisticated cyber attacks. Unfortunately, SaaS platforms are a popular target for hackers due to their popularity. ## SaaS Data Breaches In July 2021, [Kaseya](https://www.atlantic.net/hipaa-compliant-hosting/kaseya-ransomware-attack-july-2021/), a tech company that sells SaaS solutions, was targeted by ransomware. Their customers are typically small businesses or managed service resellers. The ransomware affected Kaseya VSA, an all-in-one suite for end-to-end IT infrastructure management, point-of-sale systems, servers, laptops, patching, and monitoring. This cyberattack was a watershed moment because although Kaseya was targeted, the customers were the real victims. After all, their systems were breached, many experiencing days of agonizing downtime, all because of weak security within Kaseya. Another significant [SaaS data breach happened to Zoom](https://www.tomsguide.com/news/zoom-security-privacy-woes). The video conferencing software saw astronomical growth during the pandemic, but the company that quickly became the target of hackers. Vulnerabilities were discovered in April 2020, and over 500,000 account credentials were stolen and auctioned on the dark web soon after. Other significant breaches include [Office 365 accounts being compromised](https://www.rubrik.com/blog/technology/22/5/why-hackers-are-targeting-microsoft365) by deception and social engineering tactics. Although an isolated incident, the business that owned the account was evicted entirely from it as the hackers took control. ## SaaS Cybersecurity Challenges What is the cause of these successful attacks? There are several ways in which hackers compromise SaaS services. Here are some of the most common: - Cloud Misconfiguration: The number one cause of a data breach is a result of incorrectly configuring the application, typically by sharing confidential information publicly. Pushing a database to public cloud storage or incorrectly configuring user permissions are common examples. - Third-party risk: When outsourcing to a SaaS provider, there is an element of risk that their employees may inadvertently give access to hackers. That’s what happened in the recent Office 365 attack. - Supply chain attack: The Kaseya attack highlights how vulnerable the supply chain becomes if a critical service provider is breached. Potentially all downstream users could be a victim. We saw this in the Solarwinds breach when big business and government institutions were targeted. - Zero-Day Vulnerabilities: 0-Day exploits are a genuine concern for SaaS providers because they typically offer proprietary applications as their primary service. Rushed code can equal weak security, but it’s something SaaS providers invest a lot of time and money into. - Unclear responsibilities: All SaaS platforms come with shared responsibility requirements that define what is managed by the provider, what is managed by the customer, and what responsibilities are shared. The confusion here can result in misconfiguration further down the line. ## Does Using SaaS Make My IT Environment More Secure Or Less Secure? In most cases, yes, using a SaaS platform does improve your security posture. However, it’s essential to realize that security requirements are ever-changing, so your cybersecurity policies must be kept relevant. In addition, remember that SaaS platforms typically offer an excellent all-around experience for the customer. The application delivery is streamlined to provide a superb experience for the subscriber, but be mindful that no service is 100% secure, and a zero-day exploit is a real possibility. Adopting fundamental cybersecurity initiatives now will ensure your business is in the best position in the event of a SaaS security event affecting you. Observe the best practices discussed in the article that promote enhanced authentication, data encryption, data integrity vetting, and security awareness training. Then, reevaluate your security posture by ensuring the SaaS service is configured as per the provider’s security best practice. With the right technology and best practices in place, SaaS can be far more secure than any other on-premise application. Businesses can retain control over the security infrastructure, such as encrypting customer data, and ensuring they meet necessary compliance standards. ## How to Reduce the Risk of a Data Breach One of the best ways to reduce the risk of a breach is to outsource critical IT systems to security-conscious [VPS hosting](https://www.atlantic.net/vps-hosting/) providers like Atlantic.Net. Our architecture is built to exacting standards. MFA is implemented across the business, and our engineers follow the principle of least privilege, ensuring that every user has only the required permissions to do the task. When outsourcing services to third parties, ensure that extra due diligence is performed on each vendor to understand the risk of a supply chain attack. Identifying all aspects of risk and writing down an actionable plan will create a baseline for the company’s required and desired security aspirations. If you would like to learn more, please reach out to the team. Contact Atlantic.Net at 866-618-DATA (3282) (toll-free) or +1-321-206-3734 (international) or by writing to us via the [Contact Page](https://www.atlantic.net/support/), and we will be happy to assist you. --- # What is a Cyber Attack? Common Attack Techniques and Targets > URL: https://www.atlantic.net/dedicated-server-hosting/what-is-a-cyber-attack-common-attack-techniques-and-targets/ | Published: 2023-01-17 | Updated: 2025-10-21 | Author: Richard Bailey A Cyber Attack is a common form of hacking. It is a term that describes malicious digital attacks launched by cybercriminals and targeted against small, medium, and large businesses, government institutions, and infrastructure assets such as utility services. All cyber attacks are launched digitally, but the attack vectors vary significantly. Hackers have hundreds of methods to target their victims. Sometimes hacks are opportunistic, but often the target is chosen for specific reasons. Hackers are usually after two things: data and financial reward. Data is a valuable commodity. For example, R&D secrets have significant value on the black market. However, data can also be used for extortion, bribery, and deformation. This article will discover what a cyber attack is and what attack vectors hackers use to compromise their victim’s servers. Join us as we find out who the victims are and learn if there is a trend in who is being targeted. This is part of a series of articles about [DDOS protection](https://www.atlantic.net/managed-services/network-edge-protection/). ## Cyber Attacks Are on the Increase Cyber Attacks are a huge global problem, and the escalation of cyber warfare, cyber terrorism, and state-sponsored hacking groups has exacerbated the pain significantly. Seemingly every week, the latest hacking scandal is all over the news with reports of personally identifiable information being breached. Some estimates suggest that cyber attacks are [increasing by 50%](https://blog.checkpoint.com/2022/01/10/check-point-research-cyber-attacks-increased-50-year-over-year/) yearly, and specific industries are increasingly targeted. Education, Government, Military, Communications, Managed Service Providers, and Healthcare are the industries to most commonly have victims of cyber attacks. We are seeing a significant rise in cyber attacks targeting the supply chain. Many high-profile breaches have occurred when a supplier gets hacked, but the customer falls prey to cyber-attacks. Perhaps the victim buys a service from the hacked service provider. We saw this trend starting to emerge in 2020, and it’s becoming a popular way to target victims. ## Common Attack Techniques Unauthorized network access is required for hackers to be able to launch a cyber attack. Attack vectors describe how hackers acquire access, and the methods vary among the hacking community. However, each technique will typically involve either social engineering, a brute force attack, or hackers taking advantage of system vulnerabilities. **#1: Social Engineering:** This is any hack that involves exploiting a person to gain access to a computer environment. Social engineering is the most common form of hacking. It typically requires successful Phishing campaigns where the chosen target is contacted via email, phone, or text message by a hacker impersonating a legitimate contact, perhaps a customer, 3rd party, or service provider. The aim is to trick the victim into disclosing sensitive information, such as user credentials, or getting them to click on a fake website that downloads malware payloads to the victim’s computer. The payload can do numerous actions, such as key logging and creating a network tunnel to the hacker’s command and control center. Malware can do anything; the only restriction is the capability of the hacking group. If the hacker compromises credentials, they could have unfettered access to your computer network. Fortunately, tools that scan network activity and random user access are available. In addition, technical solutions are available to prevent this, such as investing in multi-factor authentication. With MFA, the user authenticates with a code from an authentication app, blocking the hacker from gaining access. **#2: Brute Force:** A brute force attack is when hackers try to gain access to a computer network, typically over the Internet, using harvested credentials or simply guessing the password. Any server that is publicly accessible to the Internet is a potential target. Most server use either the Remote Desktop Protocol (port 3389) or Secure Shell (SSH port 22); if a user can access a server via the Internet using the credentials, so can the hacker. All the hacker has to do is crack the username and password. Suppose the end-user follows security best practices such as having a complex password, disabling default users, and restricting access to specific IP ranges. In that case, it’s improbable that these accounts would be cracked. However, the hacker could be inside your network in seconds if you use a default username and a simple password. Right now, there are botnets on the Internet searching for servers that are open to the Internet. Once discovered, hackers launch dictionary attacks where a program will attempt to force a connection to a server using a password database of common and known passwords. You would be surprised by the number of guessable passwords. If you are concerned about weak credentials, enforce secure complex passwords, invest in a password manager tool, or configure a single sign-on device such as Azure AD. **#3: Vulnerabilities:** Applications such as Operating Systems and business programs are constantly tested for vulnerabilities. Security experts rank the threat when a flaw is discovered and publish a Common Vulnerability and Exponotification ([CVE](https://cve.mitre.org/)). Patches and updates are released to fix these problems. If you are not regularly patching your servers, you may still be vulnerable to CVE. Having a regular patching schedule is an essential best practice to adhere to. Software houses are very good at keeping on top of any threats discovered, and patches are typically released months before the exploits are known in the wild. One of the biggest threats is a hacker discovering an O-day exploit; this term describes a vulnerability that no one is aware of (apart from the hacker). As a result, the hacker could be inside your system, and no one would ever know. Thankfully this type of attack is scarce, and only a[few companies have admitted this type](https://www.imperva.com/learn/application-security/zero-day-exploit/) of breach, including Sony Motion Pictures, security company RSA, Google, Adobe Systems, Yahoo, and Dow Chemical. **#4: Misconfiguration and Denial of Service:** Hackers use many different attack vectors. The misconfiguration of cloud resources is another considerable risk. There have been countless examples of users incorrectly configuring cloud storage buckets, giving the public access to confidential files in error. Hackers also use [DDoS attacks](https://www.indusface.com/blog/best-practices-to-prevent-ddos-attacks/) to disrupt access to networked resources, and this attack vector is used to bring websites down and cause a financial impact on the target. For example, one of the most significant recent DDoS attacks attempted to bring down parts of the AWS global network; thankfully, the provider could absorb the attack, which saw[incoming traffic surge to 2.3 terabits per second](https://www.cloudflare.com/en-gb/learning/ddos/famous-ddos-attacks/). ## Improve Your Cyber Security Capabilities Maintaining a secure environment to repel the latest and greatest cyber security threats is immensely challenging. Outsourcing critical IT services to a security-conscious hosting provider like Atlantic.Net is one of the best ways to meet this need. Atlantic.Net offers a wide range of managed services built from the ground up to exceed NIST security standards. Additionally, our [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) data centers are frequently audited to adhere to PCI, HITECH, SOC2, SOC3, and HIPAA-Compliance standards. Each Atlantic.Net platform is built to exacting standards. MFA is implemented across the business, and our engineers follow the principle of least privilege, ensuring that every user has only the required permissions to do the task. If you would like to learn more, please reach out to the team. Contact Atlantic.Net at 866-618-DATA (3282) (toll-free) or +1-321-206-3734 (international) or by writing to us via the [Contact Page](https://www.atlantic.net/support/), and we will be happy to assist you. --- #### Read More About DDoS Protection - [Network Edge Protection](https://www.atlantic.net/managed-services/network-edge-protection/) from Atlantic.Net - [Biggest DDoS Attack Incidents](https://www.atlantic.net/dedicated-server-hosting/top-5-biggest-ddos-attacks-and-what-hosting-companies-learned/) --- --- # How to Install and Use Docker on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-docker-on-arch-linux/ | Published: 2023-01-18 | Updated: 2023-11-15 | Author: Hitesh Jethva Docker is an open-source software platform used to build, test, and deploy applications quickly. It is a lightweight containerization platform that packages up an application and all its dependencies and delivers them into the virtual container. You can then run this container in any Linux operating system. Docker uses resource isolation that allows you to run multiple containers on the same operating system. Docker was originally designed to run on the Linux platform. Now, it also runs on Microsoft Windows and Apple OS X. This post will show you how to install and use Docker on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Docker By default, the Docker package is available in the Arch Linux default repository. You can install it easily using the following command. ``` pacman -S docker ``` Once the Docker is installed, enable the Docker service to start at system reboot. ``` systemctl enable docker ``` Next, restart your system to apply the system. ``` reboot ``` After the successful restart, you can verify the status of Docker using the following command. ``` systemctl status docker ``` You will get the following output. ``` ● docker.service - Docker Application Container Engine Loaded: loaded (/usr/lib/systemd/system/docker.service; enabled; preset: disabled) Active: active (running) since Thu 2023-01-05 00:00:42 EST; 56s ago TriggeredBy: ● docker.socket Docs: https://docs.docker.com Main PID: 265 (dockerd) Tasks: 15 (limit: 2349) Memory: 138.7M CPU: 486ms CGroup: /system.slice/docker.service ├─265 /usr/bin/dockerd -H fd:// └─356 containerd --config /var/run/docker/containerd/containerd.toml --log-level info ``` You can check Docker information using the following command. ``` docker info ``` You should see the following output. ``` Client: Context: default Debug Mode: false Server: Containers: 0 Running: 0 Paused: 0 Stopped: 0 Images: 0 Server Version: 20.10.22 Storage Driver: overlay2 ``` ## Step 3 – Verify Docker Installation Next, download and run a simple hello-world container to test whether the Docker works or not. ``` docker run hello-world ``` This will download the hello-world docker image and run it as shown below. ``` Unable to find image 'hello-world:latest' locally latest: Pulling from library/hello-world 2db29710123e: Pull complete Digest: sha256:94ebc7edf3401f299cd3376a1669bc0a49aef92d6d2669005f9bc5ef028dc333 Status: Downloaded newer image for hello-world:latest Hello from Docker! This message shows that your installation appears to be working correctly. To generate this message, Docker took the following steps: 1. The Docker client contacted the Docker daemon. 2. The Docker daemon pulled the "hello-world" image from the Docker Hub. (amd64) 3. The Docker daemon created a new container from that image which runs the executable that produces the output you are currently reading. 4. The Docker daemon streamed that output to the Docker client, which sent it to your terminal. To try something more ambitious, you can run an Ubuntu container with: $ docker run -it ubuntu bash Share images, automate workflows, and more with a free Docker ID: https://hub.docker.com/ For more examples and ideas, visit: https://docs.docker.com/get-started/ ``` You can verify the downloaded image using the following command. ``` docker images ``` You should see the following output. ``` REPOSITORY TAG IMAGE ID CREATED SIZE hello-world latest feb5d9fea6a5 15 months ago 13.3kB ``` You can also check the status of the hello-world container using the following command. ``` docker ps -a ``` You will get the following output. ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 0afb4631a34b hello-world "/hello" 18 seconds ago Exited (0) 17 seconds ago epic_kalam ``` ## Step 4 – How to Use Docker With Docker, you can download any image and run it inside the container. Let’s download the Ubuntu image and run it inside the container. ``` docker run -dit ubuntu:latest ``` You will get the following output. ``` Unable to find image 'ubuntu:latest' locally latest: Pulling from library/ubuntu 6e3729cf69e0: Pull complete Digest: sha256:27cb6e6ccef575a4698b66f5de06c7ecd61589132d5a91d098f7f3f9285415a9 Status: Downloaded newer image for ubuntu:latest 40c92b4107f8d7ff37d41d61a5c9b13b87ace2f8e14a32be8c5c52cc35daa6c9 ``` You can verify the status of the Ubuntu container using the following command. ``` docker ps ``` You should see the following output. ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 40c92b4107f8 ubuntu:latest "bash" 10 seconds ago Up 10 seconds tender_wozniak ``` Next, connect to the Ubuntu container using the following command. ``` docker exec -it 40c92b4107f8 /bin/bash ``` You will get into the following shell. ``` root@40c92b4107f8:/# ``` Now, verify your container operating system version using the following command. ``` cat /etc/lsb-release ``` You should see the following output. ``` DISTRIB_ID=Ubuntu DISTRIB_RELEASE=22.04 DISTRIB_CODENAME=jammy DISTRIB_DESCRIPTION="Ubuntu 22.04.1 LTS" ``` Finally, exit from the container using the following command. ``` root@40c92b4107f8:/# exit ``` ## Conclusion In this post, we explained how to install Docker on Arch Linux. We also showed you how to download and run a container using Docker. You can now try to deploy Docker on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure Samba Server on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-samba-server-on-arch-linux/ | Published: 2023-01-19 | Updated: 2024-06-05 | Author: Hitesh Jethva Samba, also known as “Server Message Block,” is a protocol that provides file and print services between clients across various operating systems. Samba allows us to access and use files, printers, and other commonly shared resources on a local intranet. It can be run on Unix/Linux-based platforms and communicate with Windows clients. This tutorial will show you how to install and configure the Samba server on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Samba Server The Samba server package is included in the Arch Linux default repository by default. You can install it easily with the following command. ``` pacman -S samba smbclient ``` After installing the Samba server, you can verify the Samba version using the following command. ``` smbd --version ``` You should see the following output. ``` Version 4.17.4 ``` ## Step 3 – Create a Public Share in Samba This section will show you how to create a public share in Samba. Anyone can access the public share without providing a username and password. First, create files and directories for the public share with the following command. ``` mkdir -p /samba/public touch /samba/public/public1 touch /samba/public/public2 ``` Next, set proper ownership to the public share directory. ``` chown -R nobody:nobody /samba ``` Next, create a Samba configuration file and define your public share: ``` nano /etc/samba/smb.conf ``` Add the following configuration: ``` [Public] comment = public share path = /samba/public browseable = yes writable = yes guest ok = yes ``` Save and close the file, then restart smb and NMB services to apply the changes. ``` systemctl start smb nmb ``` You can also verify the Samba configuration file using the following command. ``` testparm ``` You will get the following output. ``` # Global parameters [global] idmap config * : backend = tdb [Public] comment = public share guest ok = Yes path = /samba/public read only = No ``` ## Step 4 – Create a Private Share in Samba This section will show you how to create a private share in Samba. A private share is password protected, so the user must provide a username and password to access the private share. First, create a directory and files for the private share. ``` mkdir -p /samba/private touch /samba/private/private1 touch /samba/private/private2 ``` Next, create a user for the private share with the following command: ``` useradd smbuser smbpasswd -a smbuser ``` Set a password as shown below: ``` New SMB password: Retype new SMB password: Added user smbuser. ``` Next, edit the Samba configuration file and define your private share. ``` nano /etc/samba/smb.conf ``` Add the following configuration: ``` [Private] comment = private share path = /samba/private browseable = yes guest ok = no writable = yes valid users = smbuser ``` Save and close the file, then restart SMB and nmb services to apply the changes. ``` systemctl restart smb nmb ``` ## Step 5 – Verify Public and Private Share You must install the Samba client package on the remote system to verify the Samba share. You can install it with the following command. ``` pacman -S smbclient ``` Next, verify all Samba shares using the following command. ``` smbclient -L samba-server-ip ``` You will be asked to provide the password: ``` Password for [WORKGROUP\root]: ``` Just press the Enter key. You should see both public and private shares in the following output. ``` Anonymous login successful Sharename Type Comment --------- ---- ------- Public Disk public share Private Disk private share IPC$ IPC IPC Service (Samba 4.17.4) SMB1 disabled -- no workgroup available ``` To access the private share, run the following command. ``` smbclient //samba-ip-address/private -U smbuser ``` You will be asked to provide a password for smbuser: ``` Password for [WORKGROUP\smbuser]: ``` Provide your password, then press the Enter key. You will get into the Samba shell: ``` Try "help" to get a list of possible commands. smb: \> ``` List your files and directories inside the private share with the following command. ``` smb: \> ls ``` Output. ``` . D 0 Wed Jan 4 10:47:34 2023 .. D 0 Wed Jan 4 10:47:24 2023 private2 N 0 Wed Jan 4 10:47:34 2023 private1 N 0 Wed Jan 4 10:47:29 2023 51473020 blocks of size 1024. 46301492 blocks available ``` Now, exit from the Samba shell with the following command. ``` smb: \> exit ``` You can access the public share with the following command. ``` smbclient //samba-ip-address/public ``` You will be asked to provide a password. ``` Password for [WORKGROUP\root]: ``` Just press the Enter key to connect to Samba. ``` Anonymous login successful Try "help" to get a list of possible commands. ``` Now, verify all files and directories inside the public share. ``` smb: \> ls ``` You will get the following output. ``` . D 0 Wed Jan 4 10:45:29 2023 .. D 0 Wed Jan 4 10:47:24 2023 public2 N 0 Wed Jan 4 10:45:29 2023 public1 N 0 Wed Jan 4 10:45:24 2023 51473020 blocks of size 1024. 46301492 blocks available smb: \> ``` ## Conclusion This tutorial explained how to install the Samba server on Arch Linux. We also explained how to create a public and private share in Samba. You can now deploy the Samba server in your organization to share files and printers. You can try out a Samba server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # What Is 800G, and What Kind Of Impact Will It Have on Your Organization’s IT Infrastructure? > URL: https://www.atlantic.net/vps-hosting/what-is-800g-and-what-kind-of-impact-will-it-have-on-your-organizations-it-infrastructure/ | Published: 2023-01-20 | Updated: 2025-09-15 | Author: Richard Bailey 800G is the name given to an incoming network technology designed to improve the bandwidth capacity for network providers dramatically. The technology is already being rolled out in a series of small phased trials around the globe. 800G technology will be used to upgrade all global backbone Internet pipes, such as international subsea networks. Eventually, the technology will make it onshore and into the local data center and boost the network provider’s capacity by [up to 45](https://www.capacitymedia.com/article/29otdn0ylukn01p05fif5/news/telstra-rolls-out-infineras-800g-solution-across-its-subsea-network)%. Still, at the moment, the focus is on submarine and terrestrial interconnects. In this article, we will discover what 800G is, how it works, and what impact it will have on your organization’s IT infrastructure. ## What Is 800G? 800G is an ultra-high-speed network communications technology that uses high-capacity fiber optic cabling to interlink various locations. Everyday bandwidth demands continue to grow, fueled by the world population’s hunger for streaming services, cloud computing, and digital content delivery. Existing subsea and terrestrial backbone connections are starting to strain under the current bandwidth demands, and many are quickly reaching their operation life maximum. As a result, the plan is for global network providers to replace existing subsea cables with next-generation 800G optics. 800G technology has had a great start. In the last 18 months, 800G [modems and optics](https://www.ciena.com/insights/articles/2022/whirlwind-tour-how-800g-is-already-benefiting-network-providers-around-the-world)have been installed in 35 countries by 140 different network providers. Again, the United States leads the way in terrestrial installations, closely followed by Europe and East Asia. Likewise, submarine connectivity between the U.S. and Europe, and East Asia has been a priority. In the United States, work started on the 800G network in Q3 2020 and has progressed rapidly to incorporate most of the country. In addition, various network providers are building the [National Converged Optical Network](https://www.lightreading.com/opticalip/windstream-picks-ciena-for-new-nationwide-optical-network/d/d-id/763031) (NCON). NCON will first interconnect cities over the national network to Tier 1, 2, and 3 locations such as cloud service providers’ data centers, and build cable landing stations and cross-border gateways. ## What impact will 800G have? 800G will help satisfy the world’s need for increased bandwidth and higher line-rate connections. In addition, over time, the technology will introduce cost savings because of the [data center’s reduced space and power footprint requirements](https://www.zayo.com/resources/the-journey-to-800g-and-beyond/). Scientists and researchers are not just stopping at 800G; the technology is being used to [push speeds up to 1.6T](https://www.keysight.com/us/en/solutions/emerging-technologies/800g.html) soon. Modern lifestyles are data-hungry; the Internet delivers countless content-heavy services users rely upon. The amount of data generated by businesses like Netflix, Disney+, YouTube, Spotify, Facebook, Google, AWS, and Microsoft is mindboggling. In addition, other industries are churning through data at a significant rate. For example, consider the retail sector (in particular online shopping), healthcare, and manufacturing industries; they process incredible amounts of data behind the scenes. Since the Covid-19 pandemic started in March 2020, numerous face-to-face services have shifted online. Healthcare has seen one of the most significant changes as data-hungry front-line services became (and still largely remain) online. Home working is still primarily the norm for office workers, with most businesses introducing hybrid working to help employees balance their work-life commitments. These are just two examples of industries demanding more network bandwidth with lower latency, thus putting more significant strain on the existing infrastructure. Despite many benefits, 800G networking is not a perfect technology, and there is a trade-off between bandwidth capacity and network reach. To get the maximum spectral efficiency of 800G, the [network reach is limited to 2500km](https://www.lightwaveonline.com/network-design/high-speed-networks/article/14207812/800g-generation-coherent-and-the-new-normal) (approx. 1500 miles). This range is acceptable for terrestrial implementations but causes headaches for submarine crossings and cross-border configurations. ## The Race to Deliver 800G As with any new networking technology, it takes years for higher speed to become standardized across all global data centers. Even 200G and 400G services are not too common outside the largest [VPS hosting](https://www.atlantic.net/vps-hosting/) providers. Supply issues have also thwarted 800G as the world slowly recovers from the impact of Covid-19. 800G brings considerable increases in speed, power consumption needs, and heat extraction challenges. Data centers need to plan these implementations with these overhead environmental considerations. ## Partnering With Atlantic.Net Atlantic.Net engineers have first-hand experience with the complexities of high-speed networking. Our data centers provide cutting-edge network connectivity using several premium network providers at various speeds and levels of resiliency. Our managed services offer the ability to monitor your entire stack intelligently. In addition, the Atlantic.Net cloud platform will support ultra-fast networking, and the infrastructure is future-proofed as new and faster services become available in our data center regions. Are you looking for a leading [hosting provider](https://www.atlantic.net/hosting-services-provider/) with multiple networking options? Look no further than Atlantic.Net. With over 30 years of proven experience, our [full suite of managed services](https://www.atlantic.net/managed-services/) and always-available professional support team can build the perfect solution for your business or organization. We also include a complimentary monitoring solution for our cloud customers. Atlantic.Net is ready to help you attain fast compliance with various certifications, such as SOC 2 and SOC 3, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/), and HITECH, with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, visit us at www.atlantic.net, call 866-618-DATA (3282), or email us at sales@atlantic.net. Contact our sales team today to find out more about the solutions we offer, [contact our sales team today!](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) --- # What Is GitOps and How Can It Help Your Compliance Efforts? > URL: https://www.atlantic.net/hipaa-compliant-hosting/what-is-gitops-and-how-can-it-help-your-compliance-efforts/ | Published: 2023-01-21 | Updated: 2026-03-01 | Author: Gilad Maayan ## What is GitOps? GitOps is an architectural design pattern that can be applied to many infrastructure and cloud-native applications. It uses Git as the primary source of truth for coding infrastructure and continuous delivery systems. GitOps is now one of the primary ways software development teams manage and deliver code and software products. Having a single source of information about your code provides many opportunities for improving the software development process and the process for provisioning development environments. Before GitOps, it was challenging for developers to configure, configure, and manage environments and servers according to their needs. Previously, it was possible to do this only by writing many shell scripts, but there was a limit on the amount of infrastructure that could be configured on demand. ## How Does GitOps Work? A typical [workflow for a GitOps environment](https://codefresh.io/learn/gitops/) is 1. A developer submits a pull request to the Git repository. 2. Code is reviewed and approved by stakeholders. 3. Developers merge the code into a Git repository. 4. The CI build pipeline is triggered when changes are detected. The CI tool runs the tests automatically. If the code passes all tests, it builds the image and pushes it to the image container. 5. A deployment Automator component detects changes in the image repository and updates the YAML file in the configuration repository by pulling from the registry. 6. A deployment synchronizer component detects changes in the cluster. It pulls changes from the configuration repository and updates the cluster with new features. In this way, any deviation from the system configuration state, such as the appearance of bugs, is caught early in the development process. So, when implemented properly, GitOps is an effective way to move quality and security further to the left and detect vulnerabilities, bugs, and a variety of other common code quality issues early in the process. So GitOps is a tool for managing your infrastructure and another opportunity to transform your security. Finally, GitOps also speeds up pipeline changes. So, when the worst happens, and your developer pipeline is compromised, GitOps quickly responds to your security issues by rolling back to a safe version of the pipeline. ## Common Challenges in Software Compliance Here are key issues organizations need to consider when ensuring compliance in software environments: - **Observability:** Is someone breaking into the system and changing records and infrastructure? Answering this question is often a complex process. When providing information to auditors or meeting internally defined standards, it is usually not enough to rely on records or audit trails created manually using spreadsheets. - **Change management:** Do you store data about changes in one place? Because there are so many moving parts for a development team, it can be difficult to know who is making changes to the infrastructure or connecting to servers and containers via SSH. It’s hard to see what’s going on and log this data in one place. - **Secure ownership:** As the shift-left mindset becomes more prevalent, businesses must focus on preventing problems rather than finding them, reducing the burden on their security teams. Developers must share security responsibilities when building software. ## Using GitOps for Compliance Policies as code are references to rules encoded in the software delivery pipeline. These rules encapsulate and enforce organizational policies related to security, compliance, and basic coding or configuration standards. It only works if the entire pipeline is automated. Fortunately, thanks to the open-source nature of [Kubernetes and GitOps components](https://komodor.com/learn/kubernetes/), all the tools you need are available at a minimal cost. GitOps leverages the declarative capabilities of Kubernetes to provide the same level of versioning that developers traditionally enjoyed for the codebase, across their entire application architecture, including the cluster’s configuration itself. This means putting all configuration information and application code into a Git repository. This makes Git more than just a source of code. It becomes a single source of information for the entire organization. ### The compliance role of GitOps agents At the heart of GitOps is a software agent that acts as an intermediary between Kubernetes and Git. An agent sits between these two components and continuously monitors the live application, comparing the actual state to the ideal state of the Git code and configuration. An alert is displayed to the platform team if drift is detected. These agents are, therefore essential to GitOps, and represent a new and highly efficient method for automating CI/CD pipelines. But an important secondary goal is to remain secure and compliant—from when an application enters development to when it is launched. Monitoring and alerting is not enough—teams need the ability to set security guardrails, so everyone maintains security practices against [cybersecurity threats](https://www.bluevoyant.com/knowledge-center/7-types-of-cyber-threats-how-to-prevent-them-2022-guide). ### How GitOps automates compliance checks Automating security and compliance checks enables fully automated, reliable, secure deployments. Policy-as-code automatically detects misconfigurations, notifies the platform team, and pauses deployments if necessary. You also need to be flexible in applying your policies. This goes beyond RBAC—administrators should be free to choose where and how each policy is applied across workloads, environments, and geographic regions. Policy violations must be alerted to the right person at the right time. This means that checks should be triggered automatically at all key points in the pipeline, including commit, build, deployment, and production. ### Speeding up the pipeline with no compliance worries The ultimate goal is to speed up the pipeline without causing security or compliance problems. Of course, another goal is to make everything functional, safe, and compliant. These two goals are often contradictory—because the higher the speed, the more frequently software is deployed, and the fewer opportunities there are to fix security holes, compliance failures, and outdated misconfigurations. The only answer is automation. However, automation is not possible without intelligence built into the system to prevent these problems when they occur. This intelligence is delivered by policy as code. ## Conclusion In conclusion, GitOps is a way of managing infrastructure and applications using Git as a source of truth. By storing the system’s desired state in a Git repository and automating the deployment of changes, GitOps can help organizations improve their software compliance efforts. GitOps agents can automate compliance checks and ensure that the system is aligned with all relevant compliance requirements by enforcing policies as code. GitOps can automate many of the processes related to software management, helping organizations to improve and simplify compliance efforts, such as [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/), and improve visibility and auditability. Learn more about [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) with Atlantic.Net. --- # Install and Configure Network Time Protocol (NTP) on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/install-and-configure-network-time-protocol-ntp-on-arch-linux/ | Published: 2023-01-22 | Updated: 2024-06-04 | Author: Hitesh Jethva NTP, also known as a “Network Time Protocol,” is an Internet time protocol used to sync computer time with network time. NTP is built on UDP and uses port 123 for communication, while NTP clients use port 1023. NTP can be installed on any operating system and uses time from an external source to maintain time within its local internal clock. Generally, NTP is required for many distributed applications where time synchronization is a must between all nodes. In this post, we will show you how to install NTP on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Basic Time Commands You can use the date command to view the data and time on your server. ``` date ``` You will get the following output. ``` Wed Jan 4 11:05:42 AM UTC 2023 ``` As you can see, the timezone is set to UTC. To list all time zones, run the following command. ``` timedatectl list-timezones ``` You can set the timezone to America/New_York using the following command. ``` timedatectl set-timezone America/New_York ``` You can also verify time synchronization on your server using the following command. ``` timedatectl ``` You should see that time synchronization is active on your server. ``` Local time: Wed 2023-01-04 06:07:10 EST Universal time: Wed 2023-01-04 11:07:10 UTC RTC time: Wed 2023-01-04 11:07:11 Time zone: America/New_York (EST, -0500) System clock synchronized: yes NTP service: active RTC in local TZ: no ``` Before installing NTP, you will need to disable time synchronization. You can disable it with the following command. ``` timedatectl set-ntp no ``` You can verify it with the following command. ``` timedatectl ``` Output. ``` Local time: Wed 2023-01-04 06:07:52 EST Universal time: Wed 2023-01-04 11:07:52 UTC RTC time: Wed 2023-01-04 11:07:53 Time zone: America/New_York (EST, -0500) System clock synchronized: yes NTP service: inactive RTC in local TZ: no ``` ## Step 3 – Install and Configure NTP By default, the NTP package is available in the Arch Linux default repository. You can install it with the following command. ``` pacman -S ntp ``` Once NTP is installed, edit the NTP default configuration file: ``` nano /etc/ntp.conf ``` Change the default NTP server pool with your nearest server. ``` server 0.asia.pool.ntp.org server 1.asia.pool.ntp.org server 2.asia.pool.ntp.org server 3.asia.pool.ntp.org ``` Save and close the file, then restart NTP to apply the changes. ``` systemctl restart ntpd ``` Now, verify time synchronization with the following command. ``` ntpq -p ``` If everything is fine, you will get the following output. ``` remote refid st t when poll reach delay offset jitter ============================================================================== 103.177.8.228 ( .INIT. 16 u - 64 0 0.000 +0.000 0.000 time.firstlink. 202.12.97.45 2 u 3 64 1 268.468 -4.858 0.000 time.cloudflare 10.15.13.248 3 u 6 64 1 2.406 -0.133 0.000 ns.tu.ac.th 110.170.126.105 2 u 6 64 1 264.671 +7.973 0.000 ``` ## Conclusion In this post, we explained how to install an NTP server on Arch Linux. You can now install NTP in your local network to synchronize system time with internet time. You can test your NTP server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to install Monit Monitoring Tool on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-monit-monitoring-tool-on-arch-linux/ | Published: 2023-01-24 | Updated: 2023-11-15 | Author: Hitesh Jethva Monit is a free, open-source, lightweight monitoring tool used to manage and monitor services on Linux operating systems. Monit allows you to check the status of processes, files, directories, checksums, permissions, and filesystems via the command line interface. If something is wrong, Monit can notify you instantly via email. It has the ability to automatically start a process if it’s not running, restart one if it’s not responding, and stop a process if it’s consuming too many resources. In this post, we will show you how to install and use the Monit monitoring tool on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Monit Monitoring Tool By default, the Monit package is included in the Arch Linux default repository. You can install it easily using the following command. ``` pacman -S monit ``` Once Monit is installed, start the Monit service and enable it to start at system reboot. ``` systemctl start monit systemctl enable monit ``` To check the status of Monit, run the following command. ``` systemctl status monit ``` You should see the following output. ``` ● monit.service - Pro-active monitoring utility for unix systems Loaded: loaded (/usr/lib/systemd/system/monit.service; disabled; preset: disabled) Active: active (running) since Wed 2023-01-04 22:14:35 EST; 4s ago Docs: man:monit(1) https://mmonit.com/wiki/Monit/HowTo Main PID: 72648 (monit) Tasks: 2 (limit: 2362) Memory: 2.2M CGroup: /system.slice/monit.service └─72648 /usr/bin/monit -I Jan 04 22:14:35 archlinux systemd[1]: Started Pro-active monitoring utility for unix systems. Jan 04 22:14:35 archlinux monit[72648]: New Monit id: c0a3ed9c326d12711c321547eeb05f41 Stored in '/root/.monit.id' Jan 04 22:14:35 archlinux monit[72648]: Starting Monit 5.32.0 daemon with http interface at [localhost]:2812 Jan 04 22:14:35 archlinux monit[72648]: 'archlinux' Monit 5.32.0 started ``` ## Step 3 – Configure Monit Monit also provides a web interface to monitor your system and services. However, it is disabled by default. You can enable it by editing the Monit default configuration file. ``` nano /etc/monitrc ``` Change the following lines to enable the web interface and define the Monit admin username and password. ``` set httpd port 2812 and use address your-server-ip # allow localhost allow admin:monit ``` Save and close the file, then verify the Monit configuration file with the following command. ``` monit -t ``` You will get the following output. ``` Control file syntax OK ``` Next, restart the Monit service to apply the changes. ``` systemctl restart monit ``` At this point, the Monit web interface is enabled and listens on port 2812. You can check it with the following command. ``` ss -plunt | grep 2812 ``` You should see the following output. ``` tcp LISTEN 0 0 127.0.0.1:2812 0.0.0.0:* users:(("monit",pid=72668,fd=5)) tcp LISTEN 0 0 [::1]:2812 *:* users:(("monit",pid=72668,fd=6)) ``` ## Step 4 – Monitor Linux System Via Command Line Monit provides a command line tool to monitor your Linux system via cli. To check your system information, run the following command. ``` monit status ``` You should get the following information. ``` Monit 5.32.0 uptime: 0m System 'archlinux' status OK monitoring status Monitored monitoring mode active on reboot start load average [0.01] [0.01] [0.00] cpu 0.0%usr 0.0%sys 0.0%nice 0.0%iowait 0.0%hardirq 0.0%softirq 0.0%steal 0.0%guest 0.0%guestnice memory usage 270.5 MB [13.6%] swap usage 0 B [0.0%] uptime 18h 38m boot time Wed, 04 Jan 2023 03:38:23 filedescriptors 1024 [0.0% of 9223372036854775807 limit] data collected Wed, 04 Jan 2023 22:16:42 ``` ## Step 5 – Monitor Apache Service with Monit First, the Apache package must be installed on your server. If not installed, you can install it with the following command. ``` pacman -S apache ``` Once the Apache package is installed, start and enable the Apache service with the following command: ``` systemctl start httpd systemctl enable httpd ``` Next, edit the Monit configuration file. ``` nano /etc/monitrc ``` Add/modify the following lines to define your Apache server. ``` #set log syslog set log /var/log/monit.log check process apache with pidfile /var/run/httpd/httpd.pid start program = "/usr/bin/systemctl start httpd" with timeout 60 seconds stop program = "/usr/bin/systemctl stop httpd" if cpu > 60% for 2 cycles then alert if cpu > 80% for 5 cycles then restart if totalmem > 200.0 MB for 5 cycles then restart if children > 250 then restart if disk read > 500 kb/s for 10 cycles then alert if disk write > 500 kb/s for 10 cycles then alert ``` Save and close the file, then restart the Monit service to apply the changes. ``` systemctl restart monit ``` You can now verify your Apache service status using the following command. ``` monit summary ``` You will get the following output. ``` Monit 5.32.0 uptime: 0m ┌─────────────────────────────────┬────────────────────────────┬───────────────┐ │ Service Name │ Status │ Type │ ├─────────────────────────────────┼────────────────────────────┼───────────────┤ │ archlinux │ OK │ System │ ├─────────────────────────────────┼────────────────────────────┼───────────────┤ │ apache │ OK │ Process │ └─────────────────────────────────┴────────────────────────────┴───────────────┘ ``` You can also monitor your Apache via web interface using the URL **http://your-server-ip:2812.** You should see the Monit login page. ![monit login](https://www.atlantic.net/wp-content/uploads/2023/01/p1-7.png) Provide your Monit admin username and password and click on the **Sign In** button. You should see the Monit dashboard on the following screen. ![monit dashboard](https://www.atlantic.net/wp-content/uploads/2023/01/p2-4.png) Now, stop the Apache service and check how Monit can start the Apache service automatically. ``` systemctl stop httpd ``` You can now check the Monit logs using the following command. ``` tail -f /var/log/monit.log ``` You should see that Monit starts the Apache service automatically. ``` [2023-01-04T22:46:15-0500] info : Starting Monit 5.32.0 daemon with http interface at [localhost]:2812 [2023-01-04T22:46:15-0500] info : 'archlinux' Monit 5.32.0 started [2023-01-04T22:46:45-0500] error : 'apache' process is not running [2023-01-04T22:46:45-0500] info : 'apache' trying to restart [2023-01-04T22:46:45-0500] info : 'apache' start: '/usr/bin/systemctl start httpd' ``` ## Conclusion In this post, we showed you how to install Monit on Arch Linux. We also showed you how to monitor Apache service using Monit. You can now add more services to the Monit configuration and monitor them via the Monit dashboard. You can also deploy the Monit monitoring tool on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Vue.js on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-vue-js-on-arch-linux/ | Published: 2023-01-25 | Updated: 2023-11-19 | Author: Hitesh Jethva Vue.js is a free and open-source JavaScript framework used to build user interfaces. It is one of the most popular frameworks used to simplify the web development process. Vue.js has a built-in transition component that helps create custom elements, which can be reused in HTML. It has also built-in directives such as v-if, v-else, v-show, v-on, v-bind, and v-model that are used to perform various actions on the front end. In this post, we will show you how to install Vue.js on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Node.js Before starting, Node.js must be installed on your server. You can install it by running the following command. ``` pacman -S nodejs ``` After installing Node.js, verify the Node.js version with the following command. ``` node -v ``` Output. ``` v19.3.0 ``` Next, install NPM with the following command. ``` pacman -S npm ``` ## Step 3 – Install Vue.js First, update NPM to the latest version using the following command. ``` npm install -g npm@9.2.0 ``` Next, install the Vue CLI with the following command. ``` npm install -g @vue/cli ``` You can now verify the Vue.js version with the following command. ``` vue --version ``` Output. ``` @vue/cli 5.0.8 ``` ## Step 4 – Create a Simple Application with Vue.js Let’s create a simple application named my-app with the following command. ``` vue create my-app ``` You should see the following output. ``` Vue CLI v5.0.8 ? Please pick a preset: (Use arrow keys) ❯ Default ([Vue 3] babel, eslint) Default ([Vue 2] babel, eslint) Manually select features Vue CLI v5.0.8 ✨ Creating project in /root/my-app. 🗃 Initializing git repository... ⚙️ Installing CLI plugins. This might take a while... added 102 packages, and audited 959 packages in 7s 102 packages are looking for funding run `npm fund` for details found 0 vulnerabilities ⚓ Running completion hooks... 📄 Generating README.md... 🎉 Successfully created project my-app. 👉 Get started with the following commands: $ cd my-app $ npm run serve ``` Next, navigate to the application directory and start the Vue server with the following command. ``` cd my-app npm run serve ``` You will get the following output. ``` DONE Compiled successfully in 8790ms 11:16:38 PM App running at: - Local: http://localhost:8080/ - Network: unavailable Note that the development build is not optimized. To create a production build, run npm run build. ``` ## Step 5 – Access Vue.js Application At this point, Vue.js is installed on your server. You can now access the Vue.js application using the URL **http://your-server-ip:8080.** You should see the Vue.js application page on the following screen. ![vue.js dashboard](https://www.atlantic.net/wp-content/uploads/2023/01/p1-6.png) ## Conclusion In this tutorial, we explained how to install Vue.js on Arch Linux. We also showed you how to create a simple application using Vue.js. You can now start building interactive web applications using the Vue.js framework. You can try to install Vue.js on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Install Netdata Monitoring Tool on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/install-netdata-monitoring-tool-on-arch-linux/ | Published: 2023-01-26 | Updated: 2023-11-16 | Author: Hitesh Jethva Netdata is an open-source monitoring tool that collects all possible metrics from systems and applications and displays them via a web-based interface. With Netdata, you can collect real-time metrics such as CPU usage, disk activity, bandwidth usage, website visits, etc. It helps a system administrator to diagnose anomalies and slowdowns in your system with insightful analysis. Netdata runs its collectors every second to collect rich data and store them in a database. In this tutorial, we will show you how to install the Netdata monitoring tool on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Netdata Monitoring Tool By default, the Netdata package is included in the Arch Linux default repository. You can install it easily with the following command. ``` pacman -S netdata ``` Once installed, start and enable the Netdata service using the following command. ``` systemctl start netdata systemctl enable netdata ``` You can verify the Netdata service status with the following command. ``` systemctl status netdata ``` You will get the following output. ``` ● netdata.service - Real time performance monitoring Loaded: loaded (/usr/lib/systemd/system/netdata.service; disabled; preset: disabled) Active: active (running) since Wed 2023-01-04 23:03:23 EST; 34s ago Main PID: 73567 (netdata) Tasks: 54 (limit: 2362) Memory: 66.2M CGroup: /system.slice/netdata.service ├─73567 /usr/sbin/netdata -D ├─73569 /usr/bin/netdata --special-spawn-server ├─73715 bash /usr/lib/netdata/plugins.d/tc-qos-helper.sh 1 ├─73720 /usr/lib/netdata/plugins.d/nfacct.plugin 1 └─73723 /usr/lib/netdata/plugins.d/apps.plugin 1 ``` ## Step 3 – Access Netdata Monitoring Dashboard At this point, Netdata is started and listens on port 19999. You can check it with the following command. ``` ss -antpl | grep 19999 ``` You should see the following output. ``` LISTEN 0 0 0.0.0.0:19999 0.0.0.0:* users:(("netdata",pid=73567,fd=6)) LISTEN 0 0 *:19999 *:* users:(("netdata",pid=73567,fd=7)) ``` Now, open your web browser and access the Netdata web interface using the URL **http://your-server-ip:19999.** You should see the Netdata dashboard on the following screen. **System Overview** ![netdata system overview](https://www.atlantic.net/wp-content/uploads/2023/01/p1-5.png)   **Disk Usage** ![netdata disk usage](https://www.atlantic.net/wp-content/uploads/2023/01/p2-3.png) **Memory Usage** ![netdata memory usage](https://www.atlantic.net/wp-content/uploads/2023/01/p3-3.png) **Networking State** ![netdata network usage](https://www.atlantic.net/wp-content/uploads/2023/01/p4-3.png) **IPv4 Networking** ![netdata ipv4 usage](https://www.atlantic.net/wp-content/uploads/2023/01/p5-2.png) ## Conclusion In this guide, we explained how to install the Netdata monitoring tool on Arch Linux. You can now install the Netdata agent on the client machine and start monitoring them via the Netdata dashboard. You can now deploy the Netdata monitoring tool on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Which Compliance Standards Require an IPS? > URL: https://www.atlantic.net/hipaa-compliant-hosting/which-compliance-standards-require-an-ips/ | Published: 2023-01-27 | Updated: 2025-09-15 | Author: Gilad Maayan ## What Is an Intrusion Prevention System? An intrusion prevention system (IPS) is a network security tool that monitors network traffic and analyzes it for signs of malicious activity or policy violations. If such activity is detected, the IPS can take various actions to prevent the activity from succeeding. These actions might include blocking the traffic, sending an alert to a security administrator, or quarantining the offending traffic. Also known as an intrusion detection system (IDS), an IPS aims to detect and prevent security threats in real time rather than waiting for the threats to be detected and dealt with after the fact. This makes [IPS an important](https://www.catonetworks.com/intrusion-prevention-system/) part of an overall security strategy, as it can help to protect networks and systems from attacks that might otherwise go undetected. ## IPS for PCI DSS Compliance PCI DSS stands for Payment Card Industry Data Security Standard. It sets security standards to ensure that all companies that accept, process, store or transmit credit card information maintain a secure environment. The PCI DSS was developed by the Payment Card Industry Security Standards Council (PCI SSC), a group of the major payment card brands (Visa, Mastercard, American Express, Discover, and JCB). The standards are designed to help protect cardholder data from being accessed, used, or disclosed without authorization. To comply [with PCI DSS](https://www.exabeam.com/explainers/pci-compliance/pci-compliance-a-quick-guide/), companies must meet security requirements, including network architecture, security management, and access controls. ### PCI DSS Requirement 11.4 PCI DSS Requirement 11.4 states that organizations must employ detection and prevention techniques to mitigate network intrusions. Organizations can use an IPS to monitor their network activity and alert security administrators if any suspicious activity is detected to meet this requirement, as well as implement active security measures to block threats. According to PCI DSS Requirement 11.4, organizations must implement controls to detect and prevent network intrusions, protect the cardholder data environment (CDE), and maintain the security of their systems. These controls include: - Using IPS technology to monitor and protect networks from security threats. - Monitoring all traffic in the CDE and at critical points in the CDE to identify potential security issues. - Alerting employees to potential security threats. - Keeping intrusion detection and prevention engines, signatures, and baselines up to date to ensure that the organization’s security systems are effective. ## IPS for GDPR Compliance The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy for all individuals within the European Union (EU) and the European Economic Area (EEA). It also addresses the export of personal data outside the EU and EEA. The GDPR strengthens and expands the rights of individuals to control how their data is collected, used, and shared and places several new obligations on organizations that handle personal data. The GDPR requires organizations to take appropriate technical and organizational measures to protect personal data from unauthorized access, use, or disclosure. An IPS can help organizations to meet this requirement by detecting and preventing security threats in real-time. This helps ensure personal data’s confidentiality by blocking traffic attempting to exfiltrate data from an organization’s systems. ## IPS for HIPAA Compliance The Health Insurance Portability and Accountability Act (HIPAA) is a U.S. federal law that establishes standards for protecting certain health information. HIPAA aims to ensure the privacy and security of protected health information (PHI) while allowing for the appropriate use and disclosure of this information when necessary for patient care or other authorized purposes. HIPAA applies to a wide range of organizations and individuals, including healthcare providers, health plans, and healthcare clearinghouses, as well as their business associates who handle PHI on their behalf. HIPAA sets forth several requirements for the handling of PHI, including requirements for physical, technical, and administrative safeguards to protect data. Violations of HIPAA can result in civil and criminal penalties for covered entities and their business associates. HIPAA also gives individuals the right to request access to their PHI and corrections if they believe it is incorrect. The HIPAA Security Rule 164.306 stipulates the security obligations of organizations handling PHI, including - Ensuring electronic PHI’s confidentiality, integrity, and availability. - Protecting against anticipated misuse of PHI and other security threats. - Ensuring that all employees comply with HIPAA requirements. Intrusion prevention systems (IPS) are important for [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) because they can help covered entities and their business associates to protect relevant health information. ## How to Choose an Intrusion Prevention System for a Regulated Industry ### Detection Capabilities An IPS with strong detection capabilities is more likely to identify and prevent a wider range of threats, which can help protect a network or system better. Several factors can impact an IPS’s detection capabilities, including the types of threats it is designed to detect, the algorithms and techniques it uses to analyze traffic, and the possible level of customization and tuning. Some IPS products offer a wide range of detection options, while others may be more limited in the types of threats they are able to detect. When evaluating an IPS, it is important to consider the specific security threats and policy violations that the IPS is designed to detect, as well as the overall effectiveness of its detection capabilities. This will help to ensure that the IPS is well-suited to the needs of the organization and able to provide the level of protection that is needed. In most cases, organizations should combine multiple detection methods to cover a broad range of threats. ### Contextual Analysis This is important because it determines how well the IPS is able to understand and interpret the context in which traffic is occurring. Security threats or policy violations often depend on the context in which they occur. For example, an IPS that has a strong context understanding might be able to differentiate between normal network traffic and traffic that is part of a security threat, such as a distributed denial-of-service (DDoS) attack. This can help the IPS to more accurately identify and prevent threats, rather than mistakenly blocking legitimate traffic. Some IPS products offer a wide range of context-understanding capabilities, such as the ability to analyze traffic at different layers of the network stack and to understand the relationships between different types of traffic. Other IPS products may have more limited context-understanding capabilities. When evaluating an IPS, it is important to consider the level of context understanding that the IPS is able to provide, as well as how this context understanding is used to identify and prevent threats. ### Threat Intelligence Threat intelligence refers to information about current and emerging security threats that can be used to improve an organization’s security posture. An IPS that has access to a wide range of threat intelligence sources and that is able to use this intelligence to identify and prevent threats is more likely to be effective at protecting a network or system. This is because such an IPS will be able to stay up-to-date on the latest security threats and use this information to identify and prevent threats that might otherwise go undetected. There are a number of ways that an IPS can use threat intelligence, including by analyzing traffic for indicators of compromise (IOCs) and by using [machine learning algorithms](https://www.aporia.com/learn/machine-learning-model/machine-learning-challenges-and-solutions/) to identify patterns of behavior that are associated with security threats. Some IPS products offer their threat intelligence feeds, while others can be configured to use third-party threat intelligence sources. ## Conclusion Several compliance standards require using an intrusion prevention system (IPS). The most important standards include the PCI DSS, GDPR, and HIPAA, which require organizations to implement an IPS as part of their security strategy. The right IPS can help businesses protect their networks and systems from security threats and demonstrate compliance with these and other compliance standards. Atlantic.Net provides a complete suite of managed and security services to include IPS solutions and more. Contact [sales@atlantic.net](mailto:sales@atlantic.net) to find out more about [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and PCI-compliant hosting with Atlantic.Net. --- # How to Install Jenkins on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-jenkins-on-arch-linux/ | Published: 2023-01-28 | Updated: 2023-11-14 | Author: Hitesh Jethva Jenkins is an open-source automation tool based on Java. It helps developers to build, test, and deploy software projects automatically. Jenkins is an important part of DevOps, allowing you to continuously deliver your software by integrating with different technologies. It offers a lot of plugins that help you to integrate various DevOps stages. Jenkins is a self-contained Java-based program that can be run on Linux, macOS, and other Unix-like operating systems. This post will show you how to install Jenkins on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Jenkins By default, the Jenkins package is included in the Arch Linux default repository. You can install it easily with the following command. ``` pacman -S jenkins ``` You will also need to install the fontconfig package on your server. You can install it using the following command. ``` pacman -S fontconfig ``` Jenkins also installs Java automatically. You can check whether you have installed Java with the following command. ``` archlinux-java status ``` You will get the following output. ``` Available Java environments: java-11-openjdk (default) ``` To check the Java version, run the following command. ``` java --version ``` You should see the following output. ``` openjdk 11.0.17 2022-10-18 OpenJDK Runtime Environment (build 11.0.17+1) OpenJDK 64-Bit Server VM (build 11.0.17+1, mixed mode) ``` ## Step 3 – Configure Jenkins Next, you will need to edit the Jenkins default configuration file and define your Java path. ``` nano /etc/conf.d/jenkins ``` Change the following lines: ``` JAVA=/usr/lib/jvm/java-11-openjdk/bin/java JAVA_ARGS="-Xmx2048m -XX:MaxPermSize=512m -Djava.awt.headless=true" ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Now, start the Jenkins service using the following command. ``` systemctl start jenkins ``` You can check the status of Jenkins with the following command. ``` systemctl status jenkins ``` You should see the following output. ``` ● jenkins.service - Extendable continuous integration server Loaded: loaded (/usr/lib/systemd/system/jenkins.service; disabled; preset: disabled) Active: active (running) since Wed 2023-01-04 23:44:26 EST; 25s ago Main PID: 75311 (sh) Tasks: 40 (limit: 2362) Memory: 240.1M CGroup: /system.slice/jenkins.service ├─75311 /bin/sh -c "eval \$JENKINS_COMMAND_LINE" └─75312 /usr/lib/jvm/java-11-openjdk/bin/java -Xmx2048m -XX:MaxPermSize=512m -Djava.awt.headless=true -jar /usr/share/java/jenki> Jan 04 23:44:35 archlinux jenkins[75312]: ************************************************************* Jan 04 23:44:35 archlinux jenkins[75312]: ************************************************************* Jan 04 23:44:35 archlinux jenkins[75312]: ************************************************************* Jan 04 23:44:35 archlinux jenkins[75312]: Jenkins initial setup is required. An admin user has been created and a password generated. Jan 04 23:44:35 archlinux jenkins[75312]: Please use the following password to proceed to installation: Jan 04 23:44:35 archlinux jenkins[75312]: d8c00da0dc784653ad1dfbe40d8e0b17 Jan 04 23:44:35 archlinux jenkins[75312]: This may also be found at: /var/lib/jenkins/secrets/initialAdminPassword Jan 04 23:44:35 archlinux jenkins[75312]: ************************************************************* Jan 04 23:44:35 archlinux jenkins[75312]: ************************************************************* Jan 04 23:44:35 archlinux jenkins[75312]: ************************************************************* ``` ## Step 4 – Access Jenkins Dashboard At this point, Jenkins is installed and listens on port **8090.** You can check it with the following command. ``` ss -antpl | grep java ``` You should see the following output. ``` LISTEN 0 0 *:8090 *:* users:(("java",pid=74709,fd=8)) ``` Now, open your web browser and access the Jenkins web interface using the URL **http://your-server-ip:8090.** You should see the Jenkins login screen. ![jenkins password screen](https://www.atlantic.net/wp-content/uploads/2023/01/p1-4.png) Next, retrieve the Jenkins root password using the following command. ``` cat /var/lib/jenkins/secrets/initialAdminPassword ``` You should see the Jenkins password in the following output. ``` d8c00da0dc784653ad1dfbe40d8e0b17 ``` Type the above password in the Jenkins screen and click on the **Continue** button. You should see the Jenkins plugin installation screen. ![jenkins plugin installation screen](https://www.atlantic.net/wp-content/uploads/2023/01/p2-2.png) Click on the **Install suggested plugins.** You should see the admin user creation screen. ![jenkins admin user creation ](https://www.atlantic.net/wp-content/uploads/2023/01/p3-2.png) Set your admin username, password, and email, then click on the **Save and Continue** button. You should see the Instance configuration screen. ![jenkins instance configuration](https://www.atlantic.net/wp-content/uploads/2023/01/p4-2.png) Set your Jenkins URL and click on the **Save and Finish** button. You should see the following screen. ![jenkins installed](https://www.atlantic.net/wp-content/uploads/2023/01/p5-1.png) Click on **Start using Jenkins.** You should see the Jenkins dashboard on the following screen. ![jenkins dashboard](https://www.atlantic.net/wp-content/uploads/2023/01/p6.png) ## Conclusion In this tutorial, we explained how to install Jenkins on Arch Linux 8. You can now integrate Jenkins with any software technology and start to build, test and deploy your application automatically. You can also try to deploy Jenkins on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Set Up Kubernetes Cluster Using Minikube on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-set-up-kubernetes-cluster-using-minikube-on-arch-linux/ | Published: 2023-01-29 | Updated: 2024-06-02 | Author: Hitesh Jethva Kubernetes is a free and open-source platform that allows you to deploy, scale, and manage containerized applications automatically. It supports various container runtimes such as Docker, containerd, CRI-O, and any implementation of the Kubernetes CRI (Container Runtime Interface). Kubernetes automates several container-related tasks, including deployment, rollouts, service discovery, storage provisioning, load balancing, autoscaling, and more. This post will show you how to install Kubernetes on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Docker Engine Kubernetes requires Docker Engine to be installed on your server. If not installed, you can install it with the following command. ``` pacman -S docker ``` Once Docker is installed, enable the Docker service using the following command. ``` systemctl enable docker ``` Next, restart your system to apply the changes. ``` reboot ``` ## Step 3 – Install Minikube Minikube provides an easier way to deploy a Kubernetes cluster for local development. The Minikube package is available in the Arch Linux default repository by default. You can install it with the following command. ``` pacman -S minikube ``` After the successful installation, start Minikube with the following command. ``` minikube start --force ``` This command will set up a local Kubernetes cluster on your server. ``` 😄 minikube v1.28.0 on Arch (kvm/amd64) ❗ minikube skips various validations when --force is supplied; this may lead to unexpected behavior ✨ Automatically selected the docker driver. Other choices: ssh, none 🛑 The "docker" driver should not be used with root privileges. If you wish to continue as root, use --force. 💡 If you are running minikube within a VM, consider using --driver=none: 📘 https://minikube.sigs.k8s.io/docs/reference/drivers/none/ 📌 Using Docker driver with root privileges 👍 Starting control plane node minikube in cluster minikube 🚜 Pulling base image ... 💾 Downloading Kubernetes v1.25.3 preload ... > preloaded-images-k8s-v18-v1...: 385.44 MiB / 385.44 MiB 100.00% 40.76 M > gcr.io/k8s-minikube/kicbase: 386.27 MiB / 386.27 MiB 100.00% 26.76 MiB > gcr.io/k8s-minikube/kicbase: 0 B [________________________] ?% ? p/s 10s 🔥 Creating docker container (CPUs=2, Memory=2200MB) ... 🐳 Preparing Kubernetes v1.25.3 on Docker 20.10.20 ... ▪ Generating certificates and keys ... ▪ Booting up control plane ... ▪ Configuring RBAC rules ... 🔎 Verifying Kubernetes components... ▪ Using image gcr.io/k8s-minikube/storage-provisioner:v5 🌟 Enabled addons: default-storageclass, storage-provisioner 💡 kubectl not found. If you need it, try: 'minikube kubectl -- get pods -A' 🏄 Done! kubectl is now configured to use "minikube" cluster and "default" namespace by default ``` ## Step 4 – Verify Kubernetes Cluster You can now verify the Kubernetes cluster using the following command. ``` minikube kubectl -- get pods -A ``` You should get the following output. ``` > kubectl.sha256: 64 B / 64 B [-------------------------] 100.00% ? p/s 0s > kubectl: 42.93 MiB / 42.93 MiB [------------] 100.00% 45.96 MiB p/s 1.1s NAMESPACE NAME READY STATUS RESTARTS AGE kube-system coredns-565d847f94-2dq5q 1/1 Running 0 54s kube-system etcd-minikube 1/1 Running 0 66s kube-system kube-apiserver-minikube 1/1 Running 0 67s kube-system kube-controller-manager-minikube 1/1 Running 0 66s kube-system kube-proxy-g7w2q 1/1 Running 0 54s kube-system kube-scheduler-minikube 1/1 Running 0 67s kube-system storage-provisioner 1/1 Running 1 (23s ago) 65s ``` To get information about nodes, use the following command. ``` minikube kubectl -- get nodes -A ``` You will get the following output. ``` NAME STATUS ROLES AGE VERSION minikube Ready control-plane 109s v1.25.3 ``` ## Step 5 – Access the Minikube Dashboard By default, the Minikube dashboard is disabled, so you must enable it first. Run the following command to enable the Minikube dashboard. ``` minikube dashboard ``` You can now retrieve the Minikube URL with the following command. ``` minikube dashboard --url ``` You should see your Minikube URL in the following output. ``` 🤔 Verifying dashboard health ... 🚀 Launching proxy ... 🤔 Verifying proxy health ... http://127.0.0.1:38999/api/v1/namespaces/kubernetes-dashboard/services/http:kubernetes-dashboard:/proxy/ ``` Minikube dashboard is now enabled and listens on port **38999** on localhost. You can access the Minikube dashboard only from the localhost. You must use the SSH port forwarding method to access the Minikube dashboard from the remote system. Log in to your Linux desktop system and forward your SSH port using the following command. ``` ssh -L 38999:127.0.0.1:38999 -fN root@your-server-ip ``` You will be asked to provide your server’s root password to enable SSH port forwarding. You can now open your web browser and access the Minikube dashboard using the URL **http://127.0.0.1:38999/api/v1/namespaces/kubernetes-dashboard/services/http:kubernetes-dashboard:/proxy/.** You should see the Minikube dashboard on the following screen. ![kubernetes dashboard](https://www.atlantic.net/wp-content/uploads/2023/01/p1-3.png) ## Conclusion This tutorial explained how to install the Kubernetes cluster with Minikube on Arch Linux 8. You can follow this tutorial to deploy a Kubernetes cluster for local development. You can also try to deploy Kubernetes on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install a TeamSpeak 3 Server on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-a-teamspeak-3-server-on-arch-linux/ | Published: 2023-02-07 | Updated: 2023-11-14 | Author: Hitesh Jethva TeamSpeak is a VoIP communication system used in online multiplayer gaming. It allows users to join channels and chat with other online gamers in real-time. It’s a reliable and lightweight tool and provides AES-256 encryption, minimal latency, and high audio quality. TeamSpeak is very popular with the gaming community thanks to the rise of 3D sound effects in games. It allows users to hear the action of other players as they collaborate and work through a game in real-time. In this post, we will show you how to install a TeamSpeak server on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install TeamSpeak Server First, create a user for TeamSpeak with the following command. ``` adduser --disabled-login teamspeak ``` Next, log in as a TeamSpeak user with the following command. ``` su - teamspeak ``` Next, download the latest version of TeamSpeak with the following command. ``` wget https://files.teamspeak-services.com/releases/server/3.13.7/teamspeak3-server_linux_amd64-3.13.7.tar.bz2 ``` Once the download is completed, extract the downloaded file using the following command. ``` tar -xvzf teamspeak3-server_linux_amd64-3.13.7.tar.bz2 ``` Next, copy all files from the extracted directory to your current directory. ``` cp teamspeak3-server_linux_amd64/* . ``` Next, create a blank license agreement file. ``` touch .ts3server_license_accepted ``` Next, exit from the TeamSpeak user with the following command. ``` exit ``` ## Step 3 – Create a systemd Service File for TeamSpeak Next, you will need to create a systemd service file to manage the TeamSpeak service via systemd. ``` nano /lib/systemd/system/ts3server.service ``` Add the following lines: ``` [Unit] Description=Teamspeak Service Wants=network.target [Service] WorkingDirectory=/home/teamspeak User=teamspeak ExecStart=/home/teamspeak/ts3server_minimal_runscript.sh ExecStop=/home/teamspeak/ts3server_startscript.sh stop ExecReload=/home/teamspeak/ts3server_startscript.sh restart Restart=always RestartSec=15 [Install] WantedBy=multi-user.target ``` Save and close the file then reload the systemd daemon with the following command. ``` systemctl daemon-reload ``` Next, start and enable the TeamSpeak service using the following command. ``` systemctl start ts3server systemctl enable ts3server ``` You can also verify the service status using the following command. ``` systemctl status ts3server ``` ## Step 4 – Set an Admin Password For security purposes, it is recommended to set an administrative password for TeamSpeak. First, stop the TeamSpeak service with the following command. ``` systemctl stop ts3server ``` Next, log in as a TeamSpeak server and set an admin password with the following command. ``` su - teamspeak ./ts3server_startscript.sh start serveradmin_password=yourpassword ``` Next, stop the TeamSpeak service with the following command. ``` ./ts3server_startscript.sh stop ``` Finally, exit from the TeamSpeak user and start the TeamSpeak service: ``` exit systemctl start ts3server ``` ## Step 5 – Connect TeamSpeak Server First, you will need to download and install the TeamSpeak client on your desktop machine. You can download it from the [TeamSpeak download](https://teamspeak.com/en/downloads/) page. ``` wget https://files.teamspeak-services.com/releases/client/3.5.6/TeamSpeak3-Client-linux_amd64-3.5.6.run ``` Once the download is completed, set executable permissions and install it with the following command. ``` chmod 755 TeamSpeak3-Client-linux_amd64-3.5.6.run ./TeamSpeak3-Client-linux_amd64-3.5.6.run ``` Once the installation is complete, navigate to the TeamSpeak install directory with the following command. ``` cd TeamSpeak3-Client-linux_amd64 ``` Next, launch the TeamSpeak client with the following command. ``` bash ts3client_runscript.sh ``` You should see the TeamSpeak client on the following screen. ![teamspeak](https://www.atlantic.net/wp-content/uploads/2023/02/p1-12.png) Click on the **Connection** => **Connect** button. You should see the following screen. ![teamspeak connection](https://www.atlantic.net/wp-content/uploads/2023/02/p2-8.png) Provide your TeamSpeak server IP, admin password then click on the **Connect** button to connect to the TeamSpeak server. ## Conclusion In this post, you learned how to install the TeamSpeak server on Arch Linux. You also learned how to install the TeamSpeak client and connect to the TeamSpeak server. You can try the TeamSpeak server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # What Lessons Can HIPAA Compliance Teach Other Industries When It Comes to IT Operations? > URL: https://www.atlantic.net/hipaa-compliant-hosting/what-lessons-can-hipaa-compliance-teach-other-industries-when-it-comes-to-it-operations/ | Published: 2023-03-01 | Updated: 2025-04-11 | Author: Richard Bailey HIPAA is the federal legislation that controls how the security and privacy standards of protected health information are governed. Atlantic.Net has been providing [HIPAA-compliant hosting services](https://www.atlantic.net/hipaa-compliant-hosting/) to healthcare institutions across the United States. In addition, we are experts in upholding the physical, technical and administrative safeguards of the Health Insurance Portability and Accountability Act of 1996. Achieving HIPAA compliance is challenging, but it is a proven method of reducing the risk and potential damage to the healthcare industry. HIPAA must be taken seriously and adhered to at all levels to be successful. One of the easiest ways to help achieve this is to outsource IT services to a HIPAA-compliant [hosting provider like Atlantic.Net](https://www.atlantic.net/managed-services/). HIPAA is all about the security and integrity of data, and the founding principles of HIPAA can be applied to numerous other tech industries outside of healthcare. So what lessons can HIPAA Compliance teach other sectors when it comes to IT operations? ## Lesson 1: Encrypt Everything HIPAA places [significant emphasis on encryption](https://www.atlantic.net/resources/documents/brochures/pdf/what-encryption-does-atlantic-net-brochure.pdf), and although encryption is not a mandatory requirement of the legislation, HIPAA-covered businesses must have a good reason not to implement an encryption strategy. All industries will benefit from the full disk encryption of local and attached storage (such as Atlantic.Net’s Secure Block Storage) HIPAA recommends using complete end-to-end encryption (E2EE); this networking standard only permits the sender and receiver to view or access critical data. In addition, our experts recommend that you encrypt all data in transit, for example, when transferring data to and from Atlantic.Net servers – the simplest way to do this is over an encrypted VPN. Another example is the mandatory encryption of data using SSL/TLS certificates. This method introduces a secured data transfer connection that protects data when traversing private networks and the public internet. In addition, certificates prevent snooping and preserve the integrity of a website. ## Lesson 2: Invest in a Web Application Firewall The security of personal data and business web applications is becoming an increasing concern. Industries are already expected to meet security standards that comply with their relevant sector. For example, businesses responsible for user transactions or sharing personal information have a duty to protect all data. This is why tools such as a [Web Application Firewall](https://www.atlantic.net/hipaa-compliant-hosting/why-waf-configuration-matters-for-the-healthcare-industry/) (WAF) are so popular. A WAF protects and enhances the security of individual web applications. For example, a typical application consists of a front, mid, and back tier. The WAF protects the entire stack by ensuring only legitimate traffic passes between the stack and that internet traffic is from a legitimate source. Provisioning a WAF is the best way to protect against malicious scripts infecting your website and against zero-day malware. However, the WAF requires configuring and continuous management, which is why the Atlantic.Net WAF managed service is so popular. If you opt to self-manage, ensure the block lists and allow lists are regularly updated and reviewed, and the WAF is monitored 24x7x365. ## Lesson 3: Know What Sensitive Data You Store and Protect the Data Lifecycle This is another complex requirement of HIPAA; you must know what protected data you keep on your server and take measures to prevent unauthorized changes to the data. For example, do you know what data is on your servers? Or what information is stored inside an application? Data governance is critical for a modern business to comply with data protection laws. Audit your infrastructure, identify sensitive data, and ensure security measures protect the data. Tools like an IPS ([intrusion prevention system](https://www.atlantic.net/resources/documents/brochures/pdf/ips-atlantic-net-brochure.pdf)) can detect changes in data integrity and alert a SIEM platform. This approach creates a highly secure environment for sensitive business data. ## Lesson 4: Invest in Business Continuity and Disaster Recovery Maintaining critical business services during a disaster is crucial to HIPAA compliance. The HIPAA security rule demands the development of a process to follow in the event of a crisis or disaster scenario. Many large enterprise customers already invest in disaster recovery solutions, but small and medium-sized businesses have growing business continuity and disaster recovery requirements. “Business continuity” refers to a tried and tested recovery plan and a solution to continue business operations. The first step of business continuity is always to have a trusted backup solution that replicates data to an alternative location. Next, draw up a disaster recovery plan (DRP) that covers the business’s technical and administrative responsibilities. For example, if you outsource your IT, your DRP should also involve your hosting provider. The DRP details the steps taken to continue operations, such as who to contact in the event of a disaster, where employees will work from, and a playbook outlining how to fail over core business services to an alternative location in the event of a catastrophic failure. See our [detailed whitepaper](https://www.atlantic.net/resources/documents/whitepapers/pdf/hipaa-disaster-recovery-atlantic-net-whitepaper.pdf) on the DRP process if you want to learn more about this critical business continuity element. ## Lesson 5: Choose an Accredited Hosting Provider Atlantic.Net is an award-winning [HIPAA-compliant hosting provider](https://www.atlantic.net/hipaa-compliant-hosting/) with over 30 years of experience. We provide effective hosting solutions to an extensive list of leading healthcare clients. Since 1994, Atlantic.Net has built a reputation as a market-leading Hosting Solutions Provider renowned for simplifying complex technologies and providing exceptional Infrastructure as a Service (IAAS). Atlantic.Net operates SSAE 18 SOC 2 and SOC2 audited and certified hosting solutions to meet the advanced IT needs of businesses. In addition, we are proud of our HIPAA-compliant hosting, HITECH, and PCI Ready options. [Contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) to find out how, heading through 2022, Atlantic.Net can help your organization meet and exceed HIPAA requirements with a managed or unmanaged hosting solution customized to meet your business’s needs. Learn more about our [HIPAA-compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. --- # Most Promising Start-Ups to Watch in 2023 > URL: https://www.atlantic.net/dedicated-server-hosting/most-promising-start-ups-to-watch-in-2023/ | Published: 2023-03-06 | Updated: 2025-09-15 | Author: Richard Bailey A startup is a type of business that is new and innovative, offering something unique to the market. The tech industry is full of startups searching for new and creative ways to improve the way we do business. Startups always look for ways to enhance their products and services to create value, meaning that startups are frequently willing to try new things and experiment with new ideas. It’s no secret that the United States is a hotbed for technology startups. In fact, according to a report from [Startup Genome](https://startupgenome.com/reports/gser-fintechedition), the United States has more startup ecosystems than any other country in the world. And within the tech ecosystem, plenty of startups are worth watching in 2024. This article will look at the top IT startups in the United States and abroad to watch in 2023. These startups come from various industries, and they’re all doing amazing things with technology. Without further ado, here are the most promising startups to watch in 2024. ## 1. Sweep Sweep is a French startup that creates innovation by enabling businesses to take control of their climate emissions, from tracking and reducing emissions to contributing to exciting climate projects worldwide. At its heart, Sweep is a data company that uses AI to predict carbon emissions from your business fleet. For example, you may have a logistics team, delivery personnel, and an integrated supplier network, all of which contribute to your organization’s carbon footprint. The Sweep app will calculate and suggest the most eco-friendly routes for your business, saving you money and the planet. It also offers insights into recycling resources, switching to sustainable suppliers, and the impact of improving transportation usage. You can gain insights on how car sharing, switching to hybrid and electric company cars, and using public transport for business trips can reduce your emissions., ## 2. Vita Mojo Vita Mojo is a technology company based in London that produces state-of-the-art software and mobile applications for the restaurant industry. Their USP is cashless transactions for the hospitality sector. This might not sound unique today, but they started doing this before Covid-19 changed everyone’s need for cashless retail. The pandemic uniquely positioned the business to grow and fulfill the hospitalities demand for cashless table service apps. As a result, they have some of the biggest names in the restaurant industry in the UK and Europe and are quickly growing internationally. Their tech powers digital ordering, point-of-sale systems, and kitchen management, to home delivery networks for takeaways. ## 3. SeekOut SeekOut is a recruitment tech application that aims to simplify managing existing employees and help recruit new ones. As an organization, it is essential to stay ahead of the curve and seek out the latest and greatest in AI and hiring technology. This is where SeekOut comes in. As an AI-powered talent search engine, they can help you find and hire the best talent for your company. Not only that, but they also offer a wide range of services to help you grow and retain your talent. If you’re looking for a company that can help you find and hire top talent, then SeekOut is a perfect choice. ## 4. Moveworks Moveworks is a bot business that automatically resolves employees’ tech issues. There is no better option for companies looking to improve their workplace and attract the best talent than Moveworks. Their AI platform helps employers understand employees’ needs and when they need them. Bots are trained to do simple tasks like resetting passwords, organizing meetings, and answering technical questions. In addition, Moveworks shines when integrating automation into the business, such as automating the onboarding process for new starters, from the application, communication, contracts, and even automated account creation on the user’s first day. ## 5. Starburst Starburst is a fast-growing startup that creates an abstraction layer between all your data sources. In a traditional business setup, data is kept in a database, business intelligence systems, perhaps mainframes, servers, and any of the numerous cloud database offerings. Instead, Starburst integrates every endpoint into a seamless end-to-end solution that can read and write data to all your data sources without the complexity of data movement and copies. This is a big deal because it creates a single pane of glass where data scientists can query the entire data stack to make much more accurate decisions. ## 6. Immuta Immuta is a startup that is focused on accelerating secure data access. Their Data Security Platform helps organizations protect their data and keep it safe. Immuta lets you create self-sovereign, self-custodial digital identities and keep them safe. This means no more passwords, no more user names, and no more digital identities which can be lost, taken, or stolen. Immuta integrates with data applications like Snowflake, Data bricks, RedShift, Starburst, and Big Query. It creates unified access and trust between each stack layer, resulting in a seamless experience for the user. ## 7. StackBlitz StackBlitz is a developer tool to rapidly create, test, and deploy mobile web or app solutions. The platform provides an online editor to build and test web or mobile applications and allows developers to code live within a web browser. Its USP is that you only need a web browser to use a programming application and IDE, making it mobile and tablet friendly. In 2024, there will be several promising startups to watch. These companies are creating new ways to improve the lives of their customers, employees, and communities. With continued innovation and growth, these startups will continue to make an impact in the years to come. ## How Can Atlantic.Net Help? If you are a fledgling startup looking for a cloud partner, consider adopting a leading cloud service provider as your partner to power the technology your business demands. With over 30 years of proven experience, our full suite of managed services and trusted professional support team will build the perfect customized hosting solution to support your business or organization. Atlantic.Net is SOC 2, and SOC 3 certified, HIPAA and HITECH audited via qualified and independent third-party auditors. In addition, we provide 24x7x365 support, monitoring, and world-class data center infrastructure for [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) and VPS hosting. You can find out more information by [contacting our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)! --- # Cloud Infrastructure Trusted for Mission-Critical Success Since 1994 > URL: https://www.atlantic.net/ | Updated: 2026-09-16 For over 32 years, Atlantic.Net has delivered enterprise-grade cloud, dedicated, and clustered infrastructure for organizations with demanding performance, security, and compliance requirements. From fully managed cloud environments and dedicated bare metal servers to NVIDIA-powered GPU platforms and custom high-performance clusters, our solutions are engineered to support mission-critical workloads with exceptional reliability, scalability, and security. - HIPAA - PCI DSS - SOC 2 - 100% Uptime SLA Uptime: 100% Trusted since: 1994 ## HIPAA Hosting Protect ePHI with HIPAA and HITECH audited cloud or dedicated infrastructure, a Business Associate Agreement available with every plan, and 24/7 support for Windows and Linux environments. - Managed Security - SSAE 18 - SOC 2 Audited - Encrypted VPN & Storage - HIPAA and HITECH Audited - Business Associate Agreement ## PCI Hosting Protect cardholder data with a turnkey PCI DSS 4.0 ready cloud, dedicated, or custom environment backed by managed firewalls, encryption, vulnerability scanning, and 24/7/365 USA-based expert support. - Managed Firewall - P2P Encrypted VPN - Fully Encrypted Backups - Intrusion Prevention Systems - SOC 2, SOC 3, & HIPAA Audited ## Dedicated Hosting Get a private, physical Dedicated Server with full root access, your choice of CPU, disk, memory, operating system, and control panel, plus 24/7/365 USA-based support. - Dedicated Servers - Bare Metal Servers - Dedicated GPU Hosting - Managed & Unmanaged - RAID Storage: NVMe or SATA SSDs ## Bare Metal Hosting Run demanding workloads on single-tenant physical servers with direct access to dedicated CPU, RAM, storage, and networking, no virtualization overhead, configurable Intel Xeon or AMD EPYC processors, and 24/7/365 USA-based support. - Dedicated Physical Servers - Enterprise-Grade Hardware - Customizable Configurations - Compliance-Ready Infrastructure - Managed & Unmanaged ## Cloud Platform Provision Cloud Virtual Servers, Secure Block Storage, private networking, DNS, snapshots, and automated backups through the ACP control panel or RESTful API, with all-inclusive pricing and 24/7/365 US-based engineer support. - Cloud Hosting - Dedicated Hosts - Secure Block Storage - Virtual Private Cloud - API, Backup, Snapshots, DNS ## GPU Hosting Launch H100 NVL or L40S GPU instances for AI/ML, HPC, rendering, and simulation workloads with shared or dedicated GPU allocation, high-speed NVMe storage, and flexible billing. - Up in 60 Seconds - GPU Cloud Hosting - Massive Computing Power - Security Defined Infrastructure - NVIDIA Partner Network Cloud Partner ## Solving Your Toughest Challenges From your first consultation to smooth transition to a stable platform, you’ll benefit from our innovative and result-oriented approach to your continued digital transformation. ### Staying Ahead of the Curve From meeting the strictest security, privacy, and compliance requirements to ensuring a robust and scalable infrastructure ready for AI/ML applications, our Managed Cloud Services and Solutions are designed to help bring focus to your core business and applications. Our Compliance Hosting solutions are a perfect fit for financial services and healthcare organizations that require the most robust security levels for their data. Certified and audited by third-party independent auditors, Atlantic.Net Compliance Hosting Solutions fulfill HIPAA, HITECH, PCI, or SOC requirements. Our innovative Dedicated GPU Infrastructure, accelerated by NVIDIA, provides a scalable and powerful platform to unleash the full potential of your generative artificial intelligence (AI) workloads, train large language models (LLMs), and deploy natural language processing (NLP) in real time! ### [Keep Your Data Secure](https://www.atlantic.net/managed-services/firewall/) Leverage our full suite of Managed Security Services featuring FortiGate firewalls to ensure your critical data remains secure and protected. Managed Firewall ### [Latest Cloud Technology](https://www.atlantic.net/cloud-platform/) Build, test, develop, and deploy cutting edge solutions more quickly, easily, and simply by leveraging the latest technology. Cloud Platform ### [Regulatory Compliance](https://www.atlantic.net/compliance-hosting/) Address your industry’s regulatory mandates for HIPAA, HITECH, PCI-DSS, and GDPR compliance. Compliance Hosting ### [Disaster Recovery and Backup](https://www.atlantic.net/disaster-recovery/) Prepare your business for the worst-case scenario by protecting your crucial business data. Disaster Recovery ### [Large-Scale HPC Platform](https://www.atlantic.net/gpu-server-hosting/) Deploy and scale cutting-edge AI/ML workloads on a dedicated NVIDIA GPU platform built for exceptional performance and enterprise-scale growth. NVIDIA GPU Hosting ### [Seamless Migration](https://www.atlantic.net/managed-services/migration-services/) Move your applications and data onto our platform with expert-managed migrations that minimize downtime and risk. Migration Services ### [Gain Efficiencies with Managed Services](https://www.atlantic.net/managed-services/) Gain a clear, significant advantage with our managed services to boost efficiency and productivity. Managed Services ### [Uptime, Low Latency, and Redundancy](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/) Maximize uptime and avoid downtime with a powerful infrastructure built for speed and availability. 100% Uptime SLA ### [Always-Available Expert Support](https://www.atlantic.net/hosting-services-provider/support-team/) Get help the moment you need it from a knowledgeable support team that is available around the clock, every day of the year. Our Support Team ### [World-Class Data Center Infrastructure](https://www.atlantic.net/hipaa-data-centers/) Gain rapid access to our secure and robust infrastructure, a superior network, and a wealth of cloud hosting resources. Our Data Centers ## Cloud Availability in Multiple Global Regions Deploy close to your users from eight international data centers worldwide, with new regions on the way. ## A Support Team Backed by Decades of Experience With over three decades of experience, our support team is always here to assist you. You’ll have 24/7/365 access to a crop of dedicated veterans, capable of solving any technical problem you throw their way. ## The Atlantic.Net Difference - ### World-Class Infrastructure - 8 Global Data Centers - Fully audited and certified - 24/7 Expert Support - High availability solutions - Fully redundant network - ### 32 Years of Excellence! - Award-winning service - High touch approach - 100+ Countries Served - Stable & Profitable - Latest AI Services - ### Turn-Key Compliance - SOC 2 and SOC 3 certified - HITRUST audited - HIPAA audited - PCI ready - GDPR ready ## More Resources [2026 Bare Metal Adoption Trends: Why Enterprises Are Choosing Single-Tenant Infrastructure A look at the data behind the move to bare metal.](https://www.atlantic.net/dedicated-server-hosting/bare-metal-adoption-trends-single-tenant-infrastructure/) [HIPAA-Compliant Hosting Requirements 2026 Healthcare Hosting Guide What healthcare organizations need from a hosting provider.](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/) [Managed Services by Atlantic.Net Let our team manage your servers, security, and backups.](https://www.atlantic.net/managed-services/) [HIPAA Compliant Hosting Solutions Audited hosting for healthcare workloads, backed by a Business Associate Agreement.](https://www.atlantic.net/hipaa-compliant-hosting/) [Read Our Success Stories Reviews and testimonials from customers in over 100 countries.](https://www.atlantic.net/hosting-services-provider/atlantic-net-reviews-and-testimonials/) [White Papers and eBooks In-depth guides on cloud, compliance, and security.](https://www.atlantic.net/about-us/whitepapers/) [Read Our Latest Blog News, guides, and deep dives from our team.](https://www.atlantic.net/blog/) [Download Our Brochures Shareable overviews of our services and solutions.](https://www.atlantic.net/brochures/) ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Blog > URL: https://www.atlantic.net/blog/ | Updated: 2026-09-04 The latest articles, as listed on page one of https://www.atlantic.net/blog/. The Markdown twin of every article is listed in https://www.atlantic.net/sitemap-llms.xml. ## [Public vs Private vs Hybrid Cloud: Key Differences](https://www.atlantic.net/cloud-platform/public-vs-private-vs-hybrid-cloud/) > Markdown: https://www.atlantic.net/cloud-platform/public-vs-private-vs-hybrid-cloud.md | Published: 2026-09-04 | Author: Hitesh Jethva | Category: Cloud Platform Compare public, private, and hybrid cloud models by cost, control, scalability, security, and use case to choose the right cloud strategy. ## [Best Cloud Disaster Recovery Providers in 2026](https://www.atlantic.net/disaster-recovery/best-cloud-disaster-recovery-providers/) > Markdown: https://www.atlantic.net/disaster-recovery/best-cloud-disaster-recovery-providers.md | Published: 2026-09-04 | Author: Robert Agar | Category: Disaster Recovery Compare the best cloud disaster recovery providers, their features, benefits, and drawbacks to find the right DR solution for your business. ## [AI Infrastructure Hosting: Complete Guide for AI Workloads](https://www.atlantic.net/gpu-server-hosting/ai-infrastructure-hosting-guide/) > Markdown: https://www.atlantic.net/gpu-server-hosting/ai-infrastructure-hosting-guide.md | Published: 2026-09-04 | Author: Hitesh Jethva | Category: GPU Server Hosting Learn how to choose AI infrastructure hosting, GPUs, storage, networking, cloud models, security, deployment, and cost strategies for AI workloads. ## [How to Prepare for Black Friday 2026 with PCI-Compliant Hosting](https://www.atlantic.net/pci-compliant-hosting/black-friday-pci-compliant-hosting/) > Markdown: https://www.atlantic.net/pci-compliant-hosting/black-friday-pci-compliant-hosting.md | Published: 2026-09-04 | Author: Richard Bailey | Category: PCI Hosting Prepare for Black Friday 2026 with PCI DSS v4.0.1 hosting, load testing, fraud controls, segmentation, backups, and recovery planning for peak traffic. ## [Why Atlantic.Net Is a Strong HIPAA Hosting Alternative to LuxSci](https://www.atlantic.net/hipaa-compliant-hosting/atlantic-net-hipaa-hosting-alternative-luxsci/) > Markdown: https://www.atlantic.net/hipaa-compliant-hosting/atlantic-net-hipaa-hosting-alternative-luxsci.md | Published: 2026-09-04 | Author: Richard Bailey | Category: HIPAA Compliant Hosting See why Atlantic.Net is a strong LuxSci alternative for HIPAA hosting, with a BAA, managed security, daily backups, migration help, and 24/7 support. ## [Web Hosting Red Flags: 10 Signs You’re With The Wrong Provider](https://www.atlantic.net/cloud-platform/web-hosting-red-flags/) > Markdown: https://www.atlantic.net/cloud-platform/web-hosting-red-flags.md | Published: 2026-08-28 | Author: Richard Bailey | Category: Cloud Platform Spot 10 web hosting red flags, from downtime and slow speeds to hidden fees, weak security, poor support, and provider lock-in. ## [Server Hardening Standards for Security and Compliance](https://www.atlantic.net/managed-services/server-hardening-standards-security-compliance/) > Markdown: https://www.atlantic.net/managed-services/server-hardening-standards-security-compliance.md | Published: 2026-08-28 | Author: Robert Agar | Category: Managed Services Learn server hardening standards, including CIS Benchmarks, DISA STIGs, NIST guidance, compliance requirements, and a practical security checklist. ## [Discrete GPU: Integrated Graphics vs. Discrete Graphics](https://www.atlantic.net/gpu-server-hosting/integrated-vs-discrete-graphics/) > Markdown: https://www.atlantic.net/gpu-server-hosting/integrated-vs-discrete-graphics.md | Published: 2026-08-28 | Author: Dr. Tehseen Zia | Category: GPU Server Hosting Compare integrated vs. discrete graphics by performance, VRAM, power, cost, gaming, video editing, AI workloads, and cloud GPU use. ## [Cloud Vs. Traditional Data Center: Which Is Right For You In 2026?](https://www.atlantic.net/cloud-platform/cloud-vs-traditional-data-center/) > Markdown: https://www.atlantic.net/cloud-platform/cloud-vs-traditional-data-center.md | Published: 2026-08-21 | Author: Dr. Assad Abbas | Category: Cloud Platform Compare cloud and traditional data centers in 2026, including cost, security, scalability, performance, staffing, compliance, and hybrid options. ## [On-Premise vs Colocation vs Cloud — Which Is Right for 2026?](https://www.atlantic.net/cloud-platform/on-premises-vs-colocation-vs-cloud-2026/) > Markdown: https://www.atlantic.net/cloud-platform/on-premises-vs-colocation-vs-cloud-2026.md | Published: 2026-08-21 | Author: Dr. Assad Abbas | Category: Cloud Platform Compare on-premises, colocation, and cloud for 2026. Explore costs, control, security, scalability, and the best fit for your business. ## [Hyper-Converged Infrastructure Vs. Traditional Three-Tier Infrastructure: A Practical Comparison For 2026](https://www.atlantic.net/cloud-platform/hyper-converged-vs-traditional-infrastructure/) > Markdown: https://www.atlantic.net/cloud-platform/hyper-converged-vs-traditional-infrastructure.md | Published: 2026-08-21 | Author: Dr. Assad Abbas | Category: Cloud Platform Compare HCI and traditional infrastructure for 2026, including scalability, cost, management, security, performance, and the best use cases. ## [OpenClaw vs. Hermes: Which AI Agent Should You Deploy?](https://www.atlantic.net/cloud-platform/openclaw-vs-hermes-which-ai-agent-should-you-deploy/) > Markdown: https://www.atlantic.net/cloud-platform/openclaw-vs-hermes-which-ai-agent-should-you-deploy.md | Published: 2026-08-15 | Author: Hitesh Jethva | Category: Cloud Platform Compare OpenClaw and Hermes on Atlantic.Net Cloud: messaging-first assistant or tool-driven task agent, plus setup, model providers, and resource needs. ## [What Is an Attestation of Compliance (AoC): PCI DSS Guide](https://www.atlantic.net/pci-compliant-hosting/pci-dss-attestation-of-compliance-aoc/) > Markdown: https://www.atlantic.net/pci-compliant-hosting/pci-dss-attestation-of-compliance-aoc.md | Published: 2026-08-14 | Author: Robert Agar | Category: PCI Hosting Learn what a PCI DSS Attestation of Compliance is, who needs one, how assessments work, and how to maintain compliance year-round ## [GPU vs TPU vs NPU: Choosing the Right AI Accelerator](https://www.atlantic.net/gpu-server-hosting/gpu-vs-tpu-vs-npu-ai-accelerators/) > Markdown: https://www.atlantic.net/gpu-server-hosting/gpu-vs-tpu-vs-npu-ai-accelerators.md | Published: 2026-08-14 | Author: Dr. Tehseen Zia | Category: GPU Server Hosting Compare GPUs, TPUs, and NPUs for AI training, cloud inference, edge computing, cost, power efficiency, frameworks, and deployment needs ## [GPU Memory Bandwidth: Calculation & Optimization Guide](https://www.atlantic.net/gpu-server-hosting/gpu-memory-bandwidth/) > Markdown: https://www.atlantic.net/gpu-server-hosting/gpu-memory-bandwidth.md | Published: 2026-08-07 | Author: Dr. Tehseen Zia | Category: GPU Server Hosting Learn how GPU memory bandwidth works, calculate peak GB/s, benchmark real performance, and optimize machine learning and HPC workloads. ## [Zero Trust Implementation Roadmap: Step-by-Step Guide](https://www.atlantic.net/cloud-platform/zero-trust-implementation-roadmap/) > Markdown: https://www.atlantic.net/cloud-platform/zero-trust-implementation-roadmap.md | Published: 2026-08-07 | Author: Robert Agar | Category: Cloud Platform Build a zero trust roadmap covering IAM, ZTNA, microsegmentation, access policies, monitoring, governance, rollout, and maturity. ## [Hot Standby Server Guide to High Availability and Disaster Recovery in 2026](https://www.atlantic.net/cloud-platform/hot-standby-server-high-availability-disaster-recovery/) > Markdown: https://www.atlantic.net/cloud-platform/hot-standby-server-high-availability-disaster-recovery.md | Published: 2026-08-06 | Author: Dr. Assad Abbas | Category: Cloud Platform Learn how hot standby servers support high availability and disaster recovery with replication, failover testing, security, backups, and recovery planning. ## [Bare Metal vs RTOS: Choosing the Right Embedded Approach in 2026](https://www.atlantic.net/dedicated-server-hosting/bare-metal-vs-rtos-embedded-design/) > Markdown: https://www.atlantic.net/dedicated-server-hosting/bare-metal-vs-rtos-embedded-design.md | Published: 2026-07-31 | Author: Dr. Assad Abbas | Category: Dedicated Server Hosting Compare bare metal, RTOS, and embedded Linux to choose the right embedded architecture for timing, resources, security, and maintenance in 2026. ## [Dedicated Server for Game Hosting: High-Performance Dedicated Game Servers in 2026](https://www.atlantic.net/dedicated-server-hosting/dedicated-server-game-hosting/) > Markdown: https://www.atlantic.net/dedicated-server-hosting/dedicated-server-game-hosting.md | Published: 2026-07-31 | Author: Dr. Assad Abbas | Category: Dedicated Server Hosting Learn how to choose a dedicated server for game hosting with the right hardware, low latency, DDoS protection, backups, and management. ## [How to Secure a Self-Hosted OpenClaw Deployment](https://www.atlantic.net/cloud-platform/how-to-secure-a-self-hosted-openclaw-deployment/) > Markdown: https://www.atlantic.net/cloud-platform/how-to-secure-a-self-hosted-openclaw-deployment.md | Published: 2026-07-31 | Author: Hitesh Jethva | Category: Cloud Platform Secure your self-hosted OpenClaw deployment. Learn steps to configure HTTPS, set strong firewall rules, and protect database against attacks. --- # HIPAA Compliant Hosting Solutions > URL: https://www.atlantic.net/hipaa-compliant-hosting/ | Updated: 2026-09-16 Protect ePHI with HIPAA and HITECH audited cloud or dedicated infrastructure, a Business Associate Agreement available with every plan, and 24/7 support for Windows and Linux environments. HIPAA Hosting Requirements - HIPAA & HITECH Audited - SOC 2 & SOC 3 Certified - Encryption & MFA - 24/7 Support Uptime SLA: 100% Available with all plans: BAA ## HIPAA-Compliant Hosting Services and Solutions by Atlantic.Net Secure & Managed HIPAA Cloud and Dedicated Hosting Windows and Linux HIPAA Hosting HIPAA-Compliant Hosting by Atlantic.Net™ is SOC 2 and SOC 3 certified, HIPAA and HITECH audited, and designed to secure and protect critical health data, electronic protected health information (ePHI), and records. We are audited by a qualified, independent third-party CPA firm to validate the integrity of our operational controls and compliance services. ## Looking For a HIPAA Compliant Server? Atlantic.Net provides customized HIPAA hosting plans to meet all your HIPAA hosting needs. The ongoing monthly cost greatly depends upon variables like security services, and server specifications. ## HIPAA Compliance Hosting Plans & Cost - Linux and Windows HIPAA Hosting packages: Here are a few standard Linux and Windows HIPAA hosting pricing plans and packages: ### Linux plans ### HIPAA Developer Linux Managed Cloud Server $552.31 Per Month 6 vCPU 16GB RAM 200GB SSD Storage 10TB Monthly Data Transfer - Fully Managed FortiGate Firewall - Business Associates Agreement - Onsite Daily Backups - Server Management - Bi-Weekly Vulnerability Scans - Managed VPN 5 Accounts **View 8 more plan services** - cPanel 5 Account License - Off-site Daily Backups - 4 Hours of Migration Service - Multi-Factor Authentication - Trend Micro Security Suite* - Fully Managed Disaster Recovery Services - Network Edge Protection* - Load Balancing ### HIPAA Business Linux Managed Cloud Server $644.16 Per Month 6 vCPU 16GB RAM 200GB SSD Storage 10TB Monthly Data Transfer - Fully Managed FortiGate Firewall with IPS - Business Associates Agreement - Onsite Daily Backups - Server Management - Bi-Weekly Vulnerability Scans - Managed VPN 5 Accounts **View 8 more plan services** - cPanel 5 Account License - Off-site Daily Backups - 4 Hours of Migration Service - Multi-Factor Authentication - Trend Micro Security Suite* - Fully Managed Disaster Recovery Services - Network Edge Protection* - Load Balancing ### HIPAA DR Hosting Linux Managed Cloud Server $973.27 Per Month 6 vCPU 16GB RAM 200GB SSD Storage 10TB Monthly Data Transfer - Fully Managed FortiGate Firewall with IPS - Business Associates Agreement - Onsite Daily Backups - Server Management - Bi-Weekly Vulnerability Scans - Managed VPN 5 Accounts **View 8 more plan services** - cPanel 5 Account License - Off-site Daily Backups - 4 Hours of Migration Service - Multi-Factor Authentication - Trend Micro Security Suite* - Fully Managed Disaster Recovery Services - Network Edge Protection* - Load Balancing ### Windows plans ### HIPAA Developer Windows Managed Cloud Server $611.56 Per Month 6 vCPU 16GB RAM 200 GB SSD Storage 10TB Monthly Data Transfer - Fully Managed FortiGate Firewall - Business Associates Agreement - Onsite Daily Backups - Server Management - Bi-Weekly Vulnerability Scans - Managed VPN 5 Accounts **View 8 more plan services** - Windows License - Off-site Daily Backups - 4 Hours of Migration Service - Multi-Factor Authentication - Trend Micro Security Suite* - Fully Managed Disaster Recovery Services - Network Edge Protection* - Load Balancing ### HIPAA Business Windows Managed Cloud Server $679.64 Per Month 6 vCPU 16GB RAM 200GB SSD Storage 10TB Monthly Data Transfer - Fully Managed FortiGate Firewall with IPS - Business Associates Agreement - Onsite Daily Backups - Server Management - Bi-Weekly Vulnerability Scans - Managed VPN 5 Accounts **View 7 more plan services** - Off-site Daily Backups - 4 Hours of Migration Service - Multi-Factor Authentication - Trend Micro Security Suite* - Fully Managed Disaster Recovery Services - Network Edge Protection* - Load Balancing ### HIPAA DR Hosting Windows Managed Cloud Server $1,026.62 Per Month 6 vCPU 16GB RAM 200GB SSD Storage 10TB Monthly Data Transfer - Fully Managed FortiGate Firewall with IPS - Business Associates Agreement - Onsite Daily Backups - Server Management - Bi-Weekly Vulnerability Scans - Managed VPN 5 Accounts **View 7 more plan services** - Off-site Daily Backups - 4 Hours of Migration Service - Multi-Factor Authentication - Trend Micro Security Suite* - Fully Managed Disaster Recovery Services - Network Edge Protection* - Load Balancing ### HIPAA Custom Larger Complex Deployments Custom VM Sizes - Fully Managed FortiGate Firewall with IPS - Business Associates Agreement - Onsite Daily Backups - Server Management - Bi-Weekly Vulnerability Scans - Managed VPN 5 Accounts **View 8 more plan services** - cPanel 5 Account License - Off-site Daily Backups - 4 Hours of Migration Service - Multi-Factor Authentication - Trend Micro Security Suite* - Fully Managed Disaster Recovery Services - Network Edge Protection* - Load Balancing Migration services under the HIPAA Business and HIPAA Enterprise plans are free for up to four hours and billed at $160.00 per hour after the first four hours. Pricing based on 12-month term A one-time $150.00 setup fee is required to configure the FortiGate firewall. ## Looking for HIPAA compliant hosting, but do not know where to start? We can help with a customized solution to meet your business requirements. - IT Architecture Design, Security, & Guidance. - Flexible Private, Public, & Hybrid Hosting. - Full suite of Security Services ### HIPAA Compliant Website Hosting Our HIPAA Compliant Web Hosting Platform is secured to industry standards, providing a highly durable, feature-rich solution, powered by the latest tech, offering breakneck performance - available in both dedicated and cloud server environments and backed by our 100% uptime SLA. Contact Us to Get Started ### HIPAA-Compliant Cloud Hosting Security, scalability, high-speed data transfers, and performance are the focus of our Cloud Hosting Solutions. Atlantic.Net's HIPAA Cloud solutions offer fast provisioning, ongoing management, and round-the-clock monitoring. [Download HIPAA White Paper](https://www.atlantic.net/about-us/whitepapers/) ## What Is HIPAA-Compliant Hosting? HIPAA-compliant hosting is a web hosting solution that meets and exceeds the required administrative safeguards, physical safeguards, and technical safeguards mandated by the HIPAA regulations of 1996 (Health Insurance Portability and Accountability Act). Managed service providers, HIPAA-covered entities like healthcare providers, and relevant third parties are bound by HIPAA regulations to protect and uphold patient data integrity. The web, database, or storage solution could either be cloud-based or run on a dedicated server with the necessary security features. A service provider offering HIPAA-compliant Linux or Windows hosting must sign a Business Associates Agreement. ## HIPAA-Compliant Hosting vs Standard Web Hosting | Feature | Standard Web Hosting | HIPAA-Compliant Hosting | | --- | --- | --- | | Handles ePHI (Electronic Protected Health Information) | Not permitted | Designed to securely process and store ePHI | | Business Associate Agreement (BAA) | Not provided | Required under HIPAA regulations | | Data Encryption | Optional | Mandatory (data at rest and in transit) | | Access Controls | Basic account permissions | Strict role-based access controls (RBAC) | | Audit Logging | Limited or unavailable | Required logging and monitoring of system activity | | Security Safeguards | Standard hosting protections | Administrative, physical, and technical safeguards required by HIPAA | | Compliance Monitoring | Not included | Continuous compliance and security monitoring | | Disaster Recovery | Basic backups | HIPAA-compliant backup and disaster recovery procedures | | Breach Notification Procedures | Not defined | Required under HIPAA breach notification rule | ## HIPAA Cloud Hosting and Storage HIPAA-Compliant Cloud Hosting and Storage should be audited and certified to the required standards of the HIPAA Security Rule by an independent third party. The service is architected for enhanced privacy and ultra-secure access controls; the result is all the benefits of the cloud in a consumable, compliant service. HIPAA Cloud Storage is ideal for mission-critical applications without compromising speed, security, and reliability, great for storing large datasets, file transfers, file storage, online storage, imaging, and health records requiring enhanced encryption. ## Secure Block Storage (SBS) Atlantic.Net's user-friendly, highly redundant, easily accessible, and scalable Secure Block Storage (SBS) is ideal for a mission-critical application platforms requiring robust and scalable storage. Need to run large queries on datasets? No problem! SBS has low latency and high performance for any HIPAA-compliant cloud storage workload. Click here to learn more about our Secure Block Storage (SBS). ## HIPAA-Compliant Database Hosting Need a secured, reliable, and high-performance database? We've got you covered! Our secure and efficient solutions work with a variety of SQL platforms, both proprietary and open source. Whether you're hosting sensitive healthcare records, AI applications, or large data sets and images, rest assured your databases are backed by our 100% uptime SLA! ## Here are the databases we support: ### Microsoft SQL (MS SQL): Microsoft SQL Server can support small or large data warehouses in a user-friendly package. Data is secured with Always-On encryption technology, row-level security, dynamic data masking, transparent data encryption (TDE), and robust auditing. ### MySQL: MySQL features easy access and interaction with the server. Triggers, stored procedures, and views enhance development efficiency and productivity. MySQL is faster, cost-effective, and reliable, with a solid security layer protecting sensitive data from intruders. ### Windows HIPAA-Compliant Hosting Need Windows? No problem! Our HIPAA-Compliant Windows Hosting supports all versions of: Windows Server 2022 Windows Server 2019 Windows Server 2016 Running older versions of Windows? We can still help. Get in touch today! Contact Us To Get Started ### Linux HIPAA-Compliant Hosting Need Linux? No problem! In addition to FreeBSD and Arch Linux, our HIPAA-Compliant Linux Hosting supports: Ubuntu Debian Rocky Linux CentOS Oracle Linux Fedora and many more! Contact Us To Get Started ### One-Click HIPAA-Compliant Apps These preconfigured apps start in seconds with only a few mouse clicks. Apps include: LAMP/LEMP WordPress Nextcloud MySQL cPanel/WHM Contact Us To Get Started ## HIPAA-Compliant Hosting Demo: Whether you need comprehensive, fully managed HIPAA-compliant hosting services for HIPAA servers or unmanaged hosting solutions, we can assist with all your HIPAA compliance hosting needs. Our high-performance HIPAA-Compliant Website, Database, and Storage servers are available as both Dedicated Servers and Cloud-based HIPAA-compliant environments, backed by our 100% uptime SLA. Watch a brief video demonstrating our HIPAA hosting solution capabilities. ## HIPAA Hosting Features ### Service Organization Control Ensures internal controls and best practices for physical security, availability, processing integrity, confidentiality, and privacy. ### HIPAA Audited Ensures our processes, policies, data centers, facilities, and hosting solutions comply with the latest HIPAA audit protocols. ### HITECH Audited Stringent testing to comply with HITECH Act security standards, policies, and protocols. ## Why Choose Atlantic.Net? - HIPAA and HITECH Audited - Celebrating 32 years of excellence - 100% Uptime Service Level Agreement - World-Class Data Center Infrastructure - High Touch Approach - Emphasis on Security and Compliance - Stability and Strategic Advantage - Industry Leading Certifications - Specialists at HIPAA-Compliant Hosting - 24/7 Support via Phone and Email - Industry Awards and Partnerships - Trend Micro Deep Security Suite - Fully Managed Firewall Appliance - Multi-Factor Authentication - Load Balancing - Encrypted Backup, Storage & VPN - Fully Managed Daily Backups - Log Inspection System - GDPR Ready - PCI/DSS Ready - NIST Certified Data Centers - EU/US Privacy Shield Compliant Data Centers ## Start Your HIPAA Project With a Fully Audited HIPAA Platform Today! HIPAA-Compliant Server & Storage, Encrypted VPN, Security Firewall, Offsite Backup, Disaster Recovery, Business Associates Agreement (BAA) & more! ## HIPAA-Compliant Hosting Explained HIPAA-compliant hosting refers to cloud or dedicated server infrastructure designed to protect electronic protected health information (ePHI) in accordance with HIPAA security rules. Organizations such as hospitals, telehealth platforms, medical SaaS providers, and healthcare startups must use compliant infrastructure when storing or processing patient data. Key features of HIPAA-compliant hosting include: ### Business Associate Agreement (BAA) ### Encrypted storage and transmission ### Audit logging and monitoring ### Secure HIPAA-certified data centers ### Network firewalls and Intrusion Prevention Systems ## Who Needs HIPAA-Compliant Hosting? - Hospitals and healthcare providers - Telehealth platforms - Medical SaaS companies - Healthcare mobile apps - Medical billing and claims platforms - Electronic health record (EHR) systems ## Key Requirements for HIPAA-Compliant Hosting Environments | HIPAA Requirement | Description | Why It Matters for Healthcare Applications | | --- | --- | --- | | Business Associate Agreement (BAA) | A legally required contract between a healthcare organization and its hosting provider. | Ensures the hosting provider accepts responsibility for safeguarding ePHI. | | Encryption | Encryption of protected health information both in transit and at rest. | Prevents unauthorized access to sensitive patient data. | | Access Controls | Role-based access control (RBAC) and authentication policies limiting system access. | Ensures only authorized personnel can access healthcare systems. | | Audit Logging | Detailed logging and monitoring of system access and administrative actions. | Provides traceability for security events and compliance audits. | | Administrative Safeguards | Policies, workforce training, and risk assessments required by HIPAA. | Establishes governance and compliance processes. | | Physical Safeguards | Secure data centers with controlled facility access and environmental protections. | Prevents unauthorized physical access to healthcare infrastructure. | | Technical Safeguards | Security technologies such as firewalls, intrusion detection, and system monitoring. | Protects healthcare applications from cyber threats. | | Backup and Disaster Recovery | Secure backups and recovery procedures to maintain availability of healthcare systems. | Ensures patient data remains available during outages or disasters. | | Breach Notification Compliance | Processes required to report data breaches involving protected health information. | Ensures healthcare organizations meet HIPAA breach notification rules. | ## HIPAA-Compliant Hosting Requirements Checklist Implementing HIPAA compliance can be complicated and requires a clear understanding or compliance and technology. HIPAA compliance hosting involves integrating cloud server hosting solutions with security and managed services to achieve HIPAA compliance. The end solution must include a Business Associates Agreement. HIPAA Hosting Requirements Atlantic.Net's HIPAA Hosting meets all the requirements of HIPAA compliance in accordance with the HIPAA Privacy Rule and Security Rule. Here are the nine elements which we provide as a part of our HIPAA Hosting offering: ### Firewall A fully implemented firewall in your server environment is a must to meet HIPAA server requirements. Atlantic.Net's servers combine perimeter and server-side firewalls with solutions specifically designed to protect against security threats. Most importantly, we deploy, maintain, and manage the firewalls. ### Encrypted VPN Your virtual private network (VPN) must have strong encryption mechanism. Atlantic.Net's ensures that your VPN is encrypted to meet the HIPAA requirements and safeguards. ### Onsite and Offsite Backups HIPAA requires that you back up data locally and externally (onsite and offsite). Local onsite backups ensure quick recovery times if something goes wrong, while the offsite backups can significantly help after a catastrophic failure. On and offsite backups from Atlantic.Net can help you meet this need. ### Multi-Factor Authentication Multi-factor authentication involves the verification of user identity using a combination of factors like a piece of information that only the user knows, authenticate with a secure application, text message, or a biometric factor. Atlantic.Net offers multi-factor authentication solutions to protect your environment from unauthorized access. ### Private Hosted Environment Your server should be set up in a way that it is isolated from other machines on the platform. Atlantic.Net's experienced engineers can help you to properly set up a private infrastructure and help avoid missteps. Ensuring your data and environments are properly segmented from other machines is extremely important for the integrity of your data. ### SSL Certificates For HIPAA compliance, you need secure sockets layer (SSL) certificates established for any domains and subdomains hosting healthcare information or where sensitive ePHI is accessed. Any part of your site that needs login credentials should have an SSL. ### SOC 2 TYPE II and SOC 3 TYPE II Certifications Atlantic.Net features heightened security with fully-managed firewalls, encrypted VPNs, storage, and backup, and intrusion detection and prevention systems, all backed by an infrastructure that has received SOC 2 and SOC 3 compliant reports. The audit for the reports is based on the AICPA guidelines, including the Trust Service Principles. These tests of operating effectiveness include controls relevant to security and availability principles. These reports replaced the previous Statement on Auditing Standards No. 70 reports, as the SAS 70 standard has been retired. ### HIPAA Audited Atlantic.Net provides a secure environment that offers medical companies and patients online protection through its award-winning HIPAA-Compliant Server solutions in an environment built to safeguard ePHI. A HIPAA server alone does not make you HIPAA-compliant. Compliance is determined by adherence to the privacy and security rules outlined by HIPAA. HIPAA servers only address one aspect of those requirements. You are still required to meet administrative and technical specifications of the HIPAA Security Rule to be compliant. ### Business Associate Agreement (BAA) If you use any outside entity to handle ePHI, including a server infrastructure company, you must have a Business Associate Agreement (BAA) signed with that organization to ensure that your business associate meets their HIPAA responsibilities. That document does not relieve you of your responsibilities related to HIPAA, but delineates the external organization's role, liability for breaches, and more. Atlantic.Net offers a BAA as a standard part of the HIPAA hosting offering. Partnering with a trusted HIPAA-compliant cloud hosting provider such as Atlantic.Net can take the hassle out of compliance. Safeguard sensitive patient data with Atlantic.Net's HIPAA-compliant hosting solutions. Our world-class infrastructure and expert support ensures peace of mind for your Healthcare organization. Contact us to discuss your HIPAA requirements. For faster application deployment, free IT architecture design, and assessment, call [866-618-DATA (3282)](tel:+18666183282) or email us at [sales@atlantic.net](mailto:sales@atlantic.net). ## Looking For HIPAA-Compliant Hosting? We Can Help With A Free Assessment. - IT Architecture Design, Security, & Guidance. - Flexible Private, Public, & Hybrid Hosting. - 24x7x365 Security, Support, & Monitoring. ## More Resources ### HIPAA-Compliant Hosting Requirements 2026 Healthcare Hosting Guide [Read the Blog >](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/) ### Benefits of Bare Metal Hosting for Enterprise IT [Read the Blog >](https://www.atlantic.net/dedicated-server-hosting/benefits-bare-metal-hosting-enterprise/) ### HIPAA Compliant Hosting Solutions [Read More >](https://www.atlantic.net/hipaa-compliant-hosting/) ### PCI-Compliant Hosting Solutions [Read More >](https://www.atlantic.net/pci-compliant-hosting/) ## HIPAA Hosting FAQs ### Does HIPAA hosting come with multi-factor authentication and audit logs? Yes. Atlantic.Net offers multi-factor authentication as part of our HIPAA hosting environment, and audit logging is a core component of a HIPAA-ready setup, providing a clear record of who accessed ePHI, when they accessed it, and what activities occurred. ### How do I get fully managed HIPAA hosting for startups and clinics? Choose a managed HIPAA hosting environment that includes a signed business associate agreement, security hardening, backups, vulnerability scanning, and ongoing operational support. Atlantic.Net offers managed HIPAA hosting for clinics, healthcare startups, and other organizations that need a compliant environment without building and maintaining everything in-house. ### Does Atlantic.Net offer HIPAA-compliant private clouds? Yes. Atlantic.Net offers HIPAA-ready private cloud environments for healthcare workloads that need stronger isolation, dedicated resources, and managed support. ### How do I evaluate HIPAA-compliant hosting providers for my medical practice? Start with the essentials: a business associate agreement, strong access controls, encryption, audit logging, backups, disaster recovery options, and dependable support. For most medical practices, managed HIPAA hosting is the better choice because it reduces the compliance and infrastructure work your staff has to handle. ### How do I evaluate the best HIPAA hosting platforms for telehealth applications? Look for a hosting platform that can support HIPAA requirements end-to-end: a signed BAA, secure access controls, reliable performance, encryption, logging, and a hosting model that fits your team's technical resources. For telehealth, it also helps to [choose a HIPAA hosting provider](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-hosting-an-in-depth-buyers-guide/) that can support both growth and high availability from the start. ### How do I choose HIPAA hosting for EMR or EHR systems? Choose a hosting environment that protects ePHI through encryption, MFA, access controls, audit logs, backups, and secure administrative access. For EMR and EHR systems, dedicated or strongly isolated environments are often the best fit because they give you better control over security, performance, and data separation. ### Should HIPAA hosting services include business associate agreements? Yes. A business associate agreement should be included whenever a hosting provider stores, processes, or transmits ePHI on your behalf. If a provider will not sign a BAA for a HIPAA workload, it is usually not the right provider for that environment. ### What features should you look for in HIPAA-certified cloud servers? There is no official HIPAA certification for a server, so the better question is what a HIPAA-ready hosting environment should include. Look for a signed BAA, encryption in transit and at rest, multi-factor authentication, audit logging, backups, disaster recovery options, vulnerability management, and a hosting team that understands compliance-driven environments. ### Can you get affordable HIPAA hosting with 24/7 compliance support? Yes. Atlantic.Net offers HIPAA-compliant hosting with 24/7 support and managed security services, making compliance more practical for startups, clinics, and smaller healthcare organizations. Affordable HIPAA hosting usually means choosing the right-sized environment and support level, not simply the lowest monthly price. ### How do you migrate from standard hosting to a HIPAA-compliant environment? Start by identifying where ePHI resides, selecting the appropriate compliant hosting model, signing the BAA, and preparing the new environment with secure access, logging, backups, and hardening before cutover. Atlantic.Net also offers migration support, which is useful when you need to move healthcare workloads into a managed, HIPAA-ready environment with reduced risk and downtime. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # HIPAA Security Services > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-security/ | Updated: 2026-09-16 Protect systems that store, process, or transmit ePHI with managed firewalls, encrypted VPN, IDS/IPS, anti-malware, integrity monitoring, and audit controls mapped to the HIPAA Security Rule. - HIPAA & HITECH Audited - BAA Available - 24/7/365 Monitoring - SOC 2 & SOC 3 Type II HIPAA Technical Safeguards: 5 Support & Monitoring: 24/7/365 ## Managed HIPAA-Compliant Security Our industry-leading Managed Services let us cover cybersecurity and compliance, so you can stay focused on your core competencies. The following managed services are configured and operated by Atlantic.Net for HIPAA compliance: - Intrusion Detection / Prevention Service - Anti-Malware Protection - Dedicated Firewalls and Encrypted VPN - Network Address Translation (NAT) - Trend Micro Deep Security Package ## HIPAA Intrusion Detection Service Our Intrusion Detection Service (IDS) works off a continually updated database of malware and other potential hazards, and features customizable security infrastructure that we tune to your specific needs. We routinely test and re-test all components of IDS/IPS and perform upgrades on an as-needed basis. Threats are monitored and prevented in real time. Our Intrusion Detection Service also features a powerful firewall appliance that connects to each interface, monitoring everything from CPU usage to gateway response rate. If you require traffic shaping or simultaneous-connection limits, both are easily configurable. All of this is delivered cost-effectively - meaning you'll have access to world-class security at a much lower cost structure than hiring your own cybersecurity staff. ## Anti-Malware Protection HIPAA regulation expects healthcare organizations to use anti-malware controls as part of their security posture. Atlantic.Net's engineers deploy Trend Micro Anti-Malware to protect clients from malicious software. ## Dedicated Firewalls and Encrypted VPN In addition to intrusion detection, Atlantic.Net provides a powerful set of managed firewall components designed for affordability and security. We can build out-of-the-box solutions for almost any configuration, including Linux servers and Cisco ASA Firewalls. Reporting maintains historical information on every aspect of network security - CPU utilization, firewall states, WAN gateways, and traffic shaping. By default, we deploy a stateful firewall that lets you granularly control your states. That includes limits on states per host, new connections per second, state timeouts, state types, and simultaneous client connections. Multiple state-handling modes are available: - Keep state - works with all protocols. Default for all rules. - Modulate state - works only with TCP. Atlantic.Net's firewall appliance generates strong Initial Sequence Numbers (ISNs) on behalf of the host. - Synproxy state - proxies incoming TCP connections to help protect servers from spoofed TCP SYN floods. Includes the functionality of "keep state" and "modulate state" combined. - None - does not keep any state entries for the traffic. Rarely desirable, but available for limited circumstances. ## Several state-table optimization options are also available: Our dedicated firewalls are connected to a management service that eases the burden of monitoring. The same service lets us implement encrypted VPN connections (OpenVPN, IPsec, and PPTP supported by default) to and from your hosted servers. HIPAA compliance requirements are central to the entire process - from management through maintenance and troubleshooting. Learn more on the Managed Firewall Service page. - Normal - the default algorithm. - High latency - useful for high-latency links such as satellite connections; expires idle connections later than normal. - Aggressive - expires idle connections more quickly. Uses hardware resources more efficiently but can drop legitimate connections. - Conservative - tries to avoid dropping legitimate connections at the expense of increased memory usage and CPU utilization. ## Network Address Translation (NAT) All Atlantic.Net Managed Services clients have access to our Network Address Translation utility, which lets them quickly and easily shape how their network functions. It features straightforward configuration for port forwarding (including port ranges and multiple public IPs), outbound NAT, and advanced load balancing for both inbound and outbound connections. Integrated with the firewall appliance, it can be set up with full redundancy via pfsync and CARP. ## Looking for HIPAA-Compliant Hosting? We can help with a free assessment. - IT architecture design, security & guidance. - Flexible private, public & hybrid hosting. - 24x7x365 security, support & monitoring. ## Trend Micro™ Deep Security Packages By choosing one of Atlantic.Net's Managed Trend Micro Deep Security packages, you will be equipped to mitigate major security challenges in the cyber landscape. Trend Micro™ Deep Security Suite key features: ### Virtual environments Preserve performance and consolidation ratios with comprehensive agentless security built specifically to maximize protection for virtual environments. ### Optimized for server environments Optimizes security operations to avoid antivirus storms commonly seen in full system scans and pattern updates from traditional security capabilities. ### Virtual patching Shield vulnerabilities before they can be exploited - eliminating the operational pains of emergency patching, frequent patch cycles, and costly system downtime. ### Compliance Demonstrate compliance with multiple regulatory requirements including PCI DSS 4.0, HIPAA, HITECH, FISMA / NIST 800-53, NERC, and more. Learn more about Trend Micro Deep Security Suite. ## HIPAA Security Rule - Technical Safeguards Mapped to Atlantic.Net Services | HIPAA Security Rule Safeguard | Atlantic.Net Managed Service | What It Covers | | --- | --- | --- | | Access Control (§ 164.312(a)) | Dedicated firewalls, MFA, VPN, NAT | Granular firewall rules, multi-factor authentication, encrypted access paths | | Audit Controls (§ 164.312(b)) | Log management, IDS/IPS | Centralized logs, forensic-grade audit trails, alert escalation | | Integrity (§ 164.312(c)) | Trend Micro Deep Security (integrity monitoring), encrypted backups | File & registry change detection; verifiable backups | | Person or Entity Authentication (§ 164.312(d)) | Multi-Factor Authentication, VPN credentialing | Verified identity for SSH, RDP, and admin access | | Transmission Security (§ 164.312(e)) | SSL/TLS termination, encrypted VPN, FortiGate firewall | End-to-end encryption in transit, SSL inspection, DDoS mitigation | | Anti-Malware (HIPAA Security Rule expectation) | Trend Micro Anti-Malware | Anti-malware engine deployed across managed servers | | Contingency Plan (§ 164.308(a)(7)) | Veeam Backup & Replication, HIPAA Disaster Recovery | Backups, off-site replication, RTO/RPO-driven failover | ## Get Help with HIPAA Compliance Atlantic.Net is ready to help you reach compliance quickly across SOC 2, SOC 3, HIPAA, and HITECH - all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at sales@atlantic.net. ## Start Your HIPAA Project With a Fully Audited HIPAA Platform Today HIPAA-compliant compute & storage, encrypted VPN, security firewall, BAA, off-site backup, disaster recovery, and more. ## Frequently Asked Questions About HIPAA Security Services ### What does HIPAA-compliant security mean for hosted infrastructure? HIPAA-compliant security is the set of administrative, physical, and technical safeguards applied to systems that store, process, or transmit ePHI. The HIPAA Security Rule (45 CFR § 164.312) specifies the technical safeguards: access control, audit controls, integrity, person/entity authentication, and transmission security. Atlantic.Net's managed services map to each of those expectations. ### What's the difference between Intrusion Detection and Intrusion Prevention? An IDS sits out-of-band, passively monitors network traffic, and alerts. An IPS sits inline on the data path and actively blocks malicious traffic in real time. Atlantic.Net's HIPAA security stack offers both patterns; the FortiGate Firewall as a Service consolidates IPS into the firewall layer. ### Does HIPAA require anti-malware? The HIPAA Security Rule requires covered entities to "implement procedures for guarding against, detecting, and reporting malicious software" (45 CFR § 164.308(a)(5)(ii)(B)). Atlantic.Net deploys Trend Micro Anti-Malware on managed servers as part of the security services package to satisfy this expectation. ### What VPN protocols does Atlantic.Net support? OpenVPN and IPsec are the primary supported protocols for client-based and site-to-site VPN tunnels. PPTP is supported for legacy clients but is not recommended for new deployments due to known weaknesses. VPN sits inside the same managed-service envelope as the firewall. ### How does NAT help HIPAA-compliant deployments? Network Address Translation lets you expose only the services that need to be public while keeping the rest of the environment behind private IPs. It also enables port forwarding and outbound traffic shaping. In a HIPAA context, NAT reduces the attack surface and gives you cleaner audit boundaries between public-facing and ePHI-bearing systems. ### What does Trend Micro Deep Security add on top of standard endpoint AV? Deep Security combines anti-malware with intrusion prevention, integrity monitoring, log inspection, and virtual patching on a single platform optimized for virtualized and cloud environments. It avoids the "AV storm" pattern and supports compliance obligations under PCI DSS 4.0, HIPAA, HITECH, FISMA / NIST 800-53, and more. ### Are these security services bundled with HIPAA hosting plans? Most HIPAA hosting plans include the core security services (firewall, BAA, vulnerability scans, encrypted VPN, server management, backups). Add-ons such as Trend Micro Deep Security, Multi-Factor Authentication, Network Edge Protection, Disaster Recovery, and Load Balancing are available on the higher-tier plans or as a la carte additions. ### Will Atlantic.Net sign a Business Associate Agreement (BAA)? Yes. Atlantic.Net signs a HIPAA BAA with customers handling ePHI. The BAA documents the contractual obligations Atlantic.Net assumes as a Business Associate under HIPAA. Contact the Atlantic.Net Sales Department to obtain a copy. ### How is HIPAA security audited at Atlantic.Net? Atlantic.Net's hosting infrastructure is independently audited annually for HIPAA AT-C 105 / 205, SOC 2 Type II, SOC 3 Type II, HITECH, and PCI DSS 4.0. Customers can cite Atlantic.Net's audited controls in their own audits. SOC reports are available to customers under NDA; SOC 3 is public. ### How are HIPAA security services priced? Pricing depends on the underlying hosting product, the data volume protected, and the bundled security and managed services. Contact our sales team for a quote tailored to your environment and compliance scope. ## HIPAA Hosting Features ### Business Associate Agreement ### Intrusion Prevention Service ### Fully Managed Firewall ### Vulnerability Scans ### File Integrity Monitoring ### Anti-Malware Protection ### SSL Certificate ### Log Management System ### Multi-Factor Authentication ### Trend Micro Deep Security ### Encrypted Backup ### Encrypted VPN ### Encrypted Storage ### Network Edge/DDoS Protection ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # HIPAA-Compliant WordPress Hosting > URL: https://www.atlantic.net/hipaa-compliant-wordpress-hosting/ | Updated: 2026-09-16 Host WordPress on HIPAA and HITECH audited infrastructure with a signed BAA, managed FortiGate firewall with IPS, encrypted VPN and daily backups, log management, vulnerability scans, and 24/7/365 US-based support. - BAA Signed by Atlantic.Net - SOC 2 & SOC 3 Type II - Managed Firewall, VPN & MFA - AES-256 Daily Backups Available with All HIPAA Plans: BAA US-Based Support: 24/7/365 ## HIPAA-Compliant WordPress Hosting by Atlantic.Net At Atlantic.Net, our HIPAA Compliant Hosting is SOC 2 Type II and SOC 3 Type II certified and HIPAA audited - designed to secure critical data, records, and HIPAA WordPress installations. Most importantly, Atlantic.Net signs the Business Associate Agreement (BAA) with HIPAA WordPress hosting customers. By choosing to host your HIPAA website on Atlantic.Net's servers, you can rest assured that your data and interactions between devices are shielded by a robust security layer. Setup is fast, and the entire infrastructure meets the standards mandated by the HIPAA regulation. ## HIPAA-Compliant WordPress Hosting Plans & Cost Atlantic.Net provides turn-key HIPAA WordPress hosting plans to help you achieve fast compliance without breaking the budget. Three standard plans cover the most common scopes; a custom plan covers everything else. ### HIPAA Developer Linux Managed Cloud Server $552.31 Per Month 6 vCPU 16GB RAM 200GB SSD Storage 10TB Monthly Data Transfer - Fully Managed FortiGate Firewall - Business Associate Agreement - On-site Daily Backups - Server Management - Scheduled Vulnerability Scans - Managed VPN, 5 Accounts **View 8 more plan services** - cPanel 5 Account License - Off-site Daily Backups - 4 Hours of Migration Service - Multi-Factor Authentication - Trend Micro Security Suite* - Fully Managed Disaster Recovery Services - Network Edge Protection* - Load Balancing ### HIPAA Business Linux Managed Cloud Server $644.16 Per Month 6 vCPU 16GB RAM 200GB SSD Storage 10TB Monthly Data Transfer - Fully Managed FortiGate Firewall with IPS - Business Associate Agreement - On-site Daily Backups - Server Management - Scheduled Vulnerability Scans - Managed VPN, 5 Accounts **View 8 more plan services** - cPanel 5 Account License - Off-site Daily Backups - 4 Hours of Migration Service - Multi-Factor Authentication - Trend Micro Security Suite* - Fully Managed Disaster Recovery Services - Network Edge Protection* - Load Balancing ### HIPAA DR Hosting Linux Managed Cloud Server $973.27 Per Month 6 vCPU 16GB RAM 200GB SSD Storage 10TB Monthly Data Transfer - Fully Managed FortiGate Firewall with IPS - Business Associate Agreement - On-site Daily Backups - Server Management - Scheduled Vulnerability Scans - Managed VPN, 5 Accounts **View 8 more plan services** - cPanel 5 Account License - Off-site Daily Backups - 4 Hours of Migration Service - Multi-Factor Authentication - Trend Micro Security Suite* - Fully Managed Disaster Recovery Services - Network Edge Protection* - Load Balancing ### HIPAA Custom Larger complex deployments Custom VM Sizes - Fully Managed FortiGate Firewall with IPS - Business Associate Agreement - On-site Daily Backups - Server Management - Scheduled Vulnerability Scans - Managed VPN, 5 Accounts **View 8 more plan services** - cPanel 5 Account License - Off-site Daily Backups - 4 Hours of Migration Service - Multi-Factor Authentication - Trend Micro Security Suite* - Fully Managed Disaster Recovery Services - Network Edge Protection* - Load Balancing Migration services under the HIPAA Business and HIPAA DR Hosting plans are free for up to four hours and billed at $160.00 per hour after the first four hours. Pricing based on a 12-month term. ## What Is HIPAA-Compliant WordPress Hosting? If your WordPress website interacts with electronic protected health information (ePHI), ensuring that your WordPress website is HIPAA-compliant under the Health Insurance Portability and Accountability Act (HIPAA) of 1996 is a must. The site must adhere to the administrative, physical, and technical requirements set forth by the HIPAA regulations, and the service provider is required to sign a BAA (Business Associate Agreement). To deliver HIPAA compliance within WordPress, the first step is to understand the basics of HIPAA-compliant services for IT and hosting. Relative to the specific deployment, perform a risk analysis and then build a HIPAA-compliant website on WordPress with the technical safeguards described below. ## Can WordPress Be HIPAA-Compliant? WordPress does not offer its users a HIPAA-compliant hosting service, meaning that an out-of-the-box WordPress.com website will not meet the necessary HIPAA regulations. With no mention of HIPAA on its website, WordPress is unlikely to provide a signed Business Associate Agreement (BAA). However, organizations can take measures to ensure that their WordPress site meets the HIPAA regulations - most importantly forming a partnership with a HIPAA-compliant hosting solutions provider such as Atlantic.Net. ## HIPAA WordPress Hosting Features To help you meet and exceed the parameters set forth by the HIPAA Security Rule for your WordPress site, Atlantic.Net provides the following protections as part of HIPAA-Compliant WordPress Hosting: ### Fully Managed Firewall Our full-spectrum FortiGate firewall guards your network's periphery against malicious intruders, from implementation through round-the-clock log monitoring. As part of our HIPAA-compliant services, Atlantic.Net maintains close oversight of your network gateway points, a robust security response in the event of a breach, and regularly scheduled device health checks. ### Intrusion Detection Service Intrusion Detection Service (IDS) monitors network traffic for abnormal activity, such as late-night logins or access to files by unauthorized agents. This security layer complements the firewall by scanning for attacks that originate from within the network. Atlantic.Net's IDS/IPS operates inside our SOC 2 Type II and SOC 3 Type II audited environment. ### Encrypted VPN This service protects your data transmission by sending it via an encrypted VPN tunnel. Additional web hosting services include SSL/TLS certificates to validate ownership for sites that house access points to sensitive data and client connections. ### Encrypted Backup Our encrypted backup service takes your HIPAA compliance to the next level, automatically encrypting your data before it is written to disk using AES-256. Each encryption key used to conceal data is itself encrypted with master keys. ### Log Management System Critical to meeting HIPAA compliance requirements, our log management service oversees the full administration of transmission, analysis, storage, archiving, and disposal of your log data. ### HIPAA WordPress Installation in Seconds The WordPress application is housed on a LAMP stack using a current Ubuntu LTS release. As an option, you can add your SSH key and select backups. ## HIPAA-Compliant WordPress Hosting Requirements Making sure your WordPress instance is hosted on a secure and stable HIPAA-compliant hosting infrastructure is the first step to a HIPAA-compliant WordPress website. Below are the technical safeguards you should layer in alongside compliant hosting. ### Person or Entity Authentication Include an authentication method to verify the identity of the person or entity accessing your data. At minimum, confirm that privileges are valid and transmission devices are sound. ### Access Controls WordPress offers a combination of security configurations to help prevent unauthorized parties from accessing your data. You can modify user roles or use a plugin module to disable access to certain users. ### Audit Controls Audit controls let you deploy equipment, programs, and processes to monitor access points and behavior within IT portals that contain highly sensitive ePHI. ### Integrity Controls To make sure that the integrity of your data is maintained, install a tool that verifies and reports that no alteration or destruction of data is taking place. ### Transmission Security Add a layer of transmission security to protect against compromise of the electronic protected health information flowing through the system. ### Risk Analysis Risk Analysis is a HIPAA Security Rule requirement, so by gathering the necessary knowledge you are attending to a critical compliance step and taking proactive action to minimize liability. To assess current risks, clarify the purpose of your WordPress site (publicly accessible vs. internal), the ePHI you process, store, or transfer, the security controls and policies in place to safeguard that data, and the threat landscape and potential impacts on your organization. ## WordPress.com vs. HIPAA-Compliant WordPress Hosting | Capability | WordPress.com / Generic Host | Atlantic.Net HIPAA WordPress | | --- | --- | --- | | Business Associate Agreement (BAA) | Not available | Signed by Atlantic.Net | | HIPAA-audited infrastructure | No | HIPAA AT-C 105/205, SOC 2/3 Type II, HITECH | | Managed firewall with IPS | Self-managed if available | FortiGate Firewall as a Service included | | Encrypted VPN access | Customer-implemented | Managed VPN included | | Encrypted on-site & off-site backups | Limited | Daily on-site and off-site backups, AES-256 | | Vulnerability scanning | Self-managed | Bi-weekly scans included | | Log management for HIPAA audit | Limited | Full log retention & review | | cPanel licensing | Add-on / self-managed | 5-account cPanel license included | | Migration support | Self-service | 4 hours included; engineer-led cutover | | 24/7/365 US-based support | Tiered / outsourced | Engineer-staffed since 1994 | ## Launch a HIPAA-Compliant WordPress Site Launch a HIPAA-compliant WordPress site effortlessly. Atlantic.Net's hosting solution provides the security and support you need to fast-track your online presence. Contact us to get started today. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at sales@atlantic.net. ## Start Your HIPAA Project With a Fully Audited HIPAA Platform Today HIPAA-compliant compute & storage, encrypted VPN, security firewall, BAA, off-site backup, disaster recovery, and more. ## Business Associate Agreement (BAA) Available with All HIPAA Hosting Plans ### Service Organization Control Ensures internal controls and best practices for physical security, availability, processing integrity, confidentiality, and privacy. ### HIPAA Audited Ensures our processes, policies, data centers, facilities, and hosting solutions comply with the latest HIPAA Audit Protocols. ### HITECH Audited Stringent testing to comply with HITECH Act security standards, policies, and protocols. ## Looking for HIPAA-Compliant Hosting? We can help with a free assessment. - IT architecture design, security & guidance. - Flexible private, public & hybrid hosting. - 24x7x365 security, support & monitoring. ## Making WordPress HIPAA-Compliant Why is HIPAA compliance needed? Healthcare organizations and their service providers want to avoid federal fines and prevent their systems from being compromised. Healthcare data breaches have been consistently increasing over the last ten years, so it is even more critical to pay attention to defenses for protected health information (PHI) - particularly the electronic protected health information (ePHI) safeguarded within data environments, including with your web host. If you are a healthcare company or otherwise interact with individuals' ePHI, your first consideration should always be verifying that the system is HIPAA-compliant. A HIPAA-compliant hosting company has the necessary protections in place to meet and exceed the parameters of the HIPAA Security Rule (managed firewall, encrypted VPN, encrypted backup, log management system, intrusion detection service, etc.) and is audited under SOC 2 / SOC 3. To understand HIPAA compliance further, read A Beginner's HIPAA Compliance Guide. ## Start with Risk Analysis While having the right host is critical, you need more than HIPAA-compliant hosting services to protect yourself from violation. The preliminary step is a risk analysis. A risk analysis is key because it gives you two basic positive outcomes: assurance that the system serving your HIPAA-compliant WordPress installation can properly safeguard the data, and a documented foundation for the HIPAA Security Rule's expectations. A risk analysis is necessary, not optional, if you want your WordPress site to be HIPAA-compliant. You cannot skip this step on the assumption that you have no risk, and it is not an aspect of your business that you can entirely entrust to a third party - your organization is ultimately liable. Reviewing the current risks present in your system lets you build the best strategy moving forward; once you have the risk analysis documentation in place, you can focus on making your HIPAA compliance program sustainable. What is involved in a risk analysis to properly protect your WordPress hosting environment from violating the HIPAA regulation? You'll need to answer important questions about your environment: - What is the purpose of the WordPress site? - What groups of people need access? - What types of ePHI will it be processing, storing, or transferring? - Will the WordPress instance be publicly accessible, or is the system only for internal purposes? - What security controls are in place to safeguard it? - What are your policies and procedures to handle the security needs of its data? - What does the threat landscape look like, and what individual concerns apply? - What are the chances that threats will be deployed, and what are the potential impacts? ## Five Technical Safeguards for HIPAA-Compliant WordPress & Hosting Once you have answered the risk-analysis questions, it is time to think in terms of the controls you want to implement on your HIPAA WordPress site. You will be able to meet the requirements set by the Health and Human Services Department (HHS) through the standard system, plugins, or custom tools. Your HIPAA-compliant web hosting environment should meet five key control requirements - all of them described by the HIPAA Security Rule's language on technical safeguards. First, your HIPAA-compliant environment will need access controls. A covered entity or business associate needs to put physical security controls, technologies, and systems in place. WordPress provides a combination of security configurations and plugins to achieve this; modifying user roles ensures permissions work for administrators, the public, and staff. Note that the standard authorization capabilities within WordPress are basic. You may need a plugin to disable a content type or module when users are not authorized - for instance, to allow users to edit content while not giving them access to ePHI within calendar registrations. Second, you will need audit controls: deploying computing equipment, programs, and processes to monitor access and behavior within IT portals that contain ePHI. Third, HIPAA-compliant WordPress hosting requires integrity controls. Data integrity must be maintained - data is not destroyed or unintentionally altered - and a mechanism should be installed that verifies no alteration or destruction is occurring. Fourth, the Security Rule requires person or entity authentication. Verify identities of users through person or entity authentication methods. At minimum, confirm that privileges and the transmission device are valid. Finally, a HIPAA-compliant organization has to build transmission security into its environment. These methods protect against compromise of the ePHI flowing through the infrastructure. ## WordPress with a HIPAA-Compliant Hosting Provider Considering all these controls, it becomes apparent that a big piece of any HIPAA-compliant WordPress site is the hosting company. It is a much simpler route than reinventing the wheel, since HIPAA regulations can be complex. Before you can build HIPAA-compliant WordPress, you need a web host with the healthcare IT knowledge to set up a system that will protect you from a HIPAA breach. At Atlantic.Net, our healthcare hosting is SOC 2 Type II and SOC 3 Type II certified and HIPAA audited - designed to secure critical data, records, and HIPAA WordPress installations. Reach out to us about our HIPAA-compliant WordPress hosting plans. ## HIPAA-Compliant WordPress Hosting FAQs ### What is HIPAA-Compliant WordPress Hosting? It's a hosting service specifically designed for WordPress websites that handle electronic protected health information (ePHI). It ensures the website adheres to the strict administrative, physical, and technical requirements outlined in the HIPAA regulations. The service is well suited for healthcare organizations that want to develop and improve their online presence, interact with patients, and advertise their services. ### Can WordPress itself be HIPAA-compliant? WordPress out-of-the-box is not HIPAA-compliant. However, it can be made compliant by partnering with a HIPAA-compliant hosting provider like Atlantic.Net and implementing additional security measures such as a Managed Firewall, Intrusion Prevention System, encrypted backups, disaster recovery, and more. ### What are the key features Atlantic.Net offers for HIPAA WordPress Hosting? Our HIPAA Compliant platform meets and exceeds mandatory HIPAA compliance requirements: a fully managed FortiGate firewall with IPS, intrusion detection, encrypted VPN and backups, log management, bi-weekly vulnerability scans, cPanel licensing, and quick WordPress installation. ### What are the requirements for making a WordPress website HIPAA-compliant beyond just hosting? You need to implement features such as person or entity authentication, access controls, audit controls, integrity controls, and transmission security. The Security Rule's technical safeguards section enumerates the controls; the on-page "HIPAA-Compliant WordPress Hosting Requirements" section walks through each one. ### Why is a Risk Analysis important for HIPAA compliance in WordPress hosting? A Risk Analysis is mandated by the HIPAA Security Rule. It helps identify potential vulnerabilities and threats to your system, allowing you to implement necessary safeguards and minimize liability. It is the first step both regulators and auditors expect to see when evaluating your compliance posture. ### How does Atlantic.Net secure WordPress sites for HIPAA compliance? We use end-to-end encryption, SSL/TLS certificates, managed firewalls, intrusion detection, encrypted backups, and log management to keep your site and patient data safe at all times. The full stack runs inside our HIPAA AT-C 105 / 205 audited environment. ### Can I migrate my existing WordPress site to Atlantic.Net HIPAA hosting? Absolutely. We'll help you move your site quickly and securely with near-zero downtime, so your visitors and patients never experience a disruption. The first 4 hours of migration time are included with the HIPAA Business and HIPAA DR Hosting plans. ### What industries benefit from HIPAA-Compliant WordPress Hosting? HIPAA-compliant WordPress hosting fits telehealth providers, medical practices, health insurance companies, healthcare SaaS platforms, life sciences organizations, and any organization that handles patient data and needs to stay compliant. ### Does Atlantic.Net provide resources like case studies and white papers on HIPAA-compliant hosting? Yes. Atlantic.Net offers a comprehensive library of resources, including detailed [case studies](https://www.atlantic.net/press-room/case-studies/) and [white papers](https://www.atlantic.net/about-us/whitepapers/). Explore those sections to learn more about HIPAA-compliant hosting. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Power Pharma & BioTech Scientific Innovation > URL: https://www.atlantic.net/life-sciences-pharma-biotech/ | Updated: 2026-09-16 Accelerate genomics, drug discovery, simulation, clinical trial data, and AI workloads with on-demand cloud, GPU, dedicated, and bare metal infrastructure backed by audited security and eight global data center locations. - HIPAA & HITECH Audited - BAA Available - 8 Global Data Centers - 32 Years of Experience Global Data Centers: 8 On-Demand Nodes: 1000s ## Pharma & BioTech Solutions Partnering with an experienced managed hosting provider can help life sciences companies drive innovation, accelerate discovery, and stay ahead of regulatory expectations. With a significant number of heavily regulated healthcare clients, Atlantic.Net provides a secure, reliable, and affordable HIPAA cloud hosting environment – well suited for life sciences organizations that work with healthcare big data. If you need a fully compliant solution with the required adherence to regulatory or compliance requirements, Atlantic.Net provides secure managed services that will help you take your research to the next level. Alternatively, if you need complex computations at a fast pace without the regulatory overhead, the Atlantic.Net public cloud solution can also help you get up and running in seconds. You have access to thousands of machines ready to be turned on with the click of a button across eight global data centers. ## Atlantic.Net Pharma & BioTech Cloud Solutions Looking for a fully managed or unmanaged hosting service? Whatever your needs, Atlantic.Net is here for you with over 32 years of experience providing some of the world's leading universities, biotech, healthcare, and life sciences companies with fully compliant, high-performance infrastructure designed to maximize organizational potential. ### Drive Innovation and Development Innovation in life sciences is driven by the analysis of big data. Companies in pharmaceuticals, biotechnology, and research require on-demand high-performance computing to advance innovation, discovery, and development. Atlantic.Net provides the capacity to crunch enormous data sets, opening a world of potential and insight. Power your innovation with the latest cloud technology, backed by unparalleled support. ### Speed Up Discovery Science moves fast, and life sciences companies must too. Shortening time to market provides a competitive advantage to pharmaceutical and medical-device firms. Strengthening your computational power with a leading cloud hosting solution increases your organization's speed and efficiency, placing you at the forefront of discovery. Turn up a single or thousands of cloud instances in seconds and accelerate the discovery process. ### Enhance Collaboration Enhancing global collaboration is key to driving innovation and growth in life sciences. Efficient collaboration between academia and industry requires secure connections for around-the-clock information exchange. Atlantic.Net enables collaboration with services running across eight global data center locations spanning the United States, Canada, Singapore, and the UK. Our global reach lets clients position resources internationally, supporting interoperability with reliable and secure transactions. Users can work concurrently on the same server via the Atlantic.Net Windows Remote Desktop Service. Where data must traverse the network securely, you can implement a Private VPN connection so teams work on a centralized project in a secure, encrypted environment. ### Provide Flexible Scalability A scalable approach is essential in life sciences. Genetic data analysis – increasingly important in drug discovery and personalized medicine – demands highly available, elastic compute resources. Atlantic.Net cloud servers can scale up in seconds; choose the upgraded plan needed, and additional nodes can be added for large-scale and complex genomic analysis. On-demand scalability also lets clients run small-scale experimental models first, then employ additional resources at the click of a button to determine the viability of a large-scale task. ### Unleash the Potential of AI AI and Machine Learning (AI/ML) are reshaping life sciences, transforming areas such as diagnostics and R&D. Big pharma in particular is turning to AI-driven solutions to boost drug discovery, using deep learning to identify novel drug targets and promising candidates. Atlantic.Net helps you leverage AI for real-time data access and analysis to reduce costs and accelerate your workload. AI and ML powered by Atlantic.Net's fast cloud servers give you instant compute resources – from a single server to thousands – and take research to the next level at an accelerated rate. If you are working on proprietary data that needs security and compliance, we can power your server with additional security and management services to ensure the integrity of your clinical-trial data, with public and private cloud offerings available for any scenario. ### Simplify Security and Compliance Atlantic.Net delivers an extensive list of security measures suited to projects that involve sensitive personal information or Protected Health Information (PHI). The Atlantic.Net Cloud provides clients with fully managed firewall solutions, a robust intrusion detection service, multi-factor authentication, an encrypted virtual private network (VPN), on-site and off-site backup, robust log management, and more. Many top universities rely on our cloud platform for their research computations. You can take advantage of the same platform – specifically designed for fast, futuristic, and reliable services. Contact us today to find out how Atlantic.Net can provide a hosting solution tailored to the needs of your organization. Accelerate research and innovation with Atlantic.Net's IT solutions tailored for life sciences and big pharma. Contact us to learn how we can support your mission-critical initiatives. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at sales@atlantic.net. ## Start Your HIPAA Project With a Fully Audited HIPAA Platform Today HIPAA-compliant compute & storage, encrypted VPN, security firewall, BAA, off-site backup, disaster recovery, and more. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Frequently Asked Questions About Pharma & BioTech Hosting ### Why do pharma and biotech companies need specialized hosting? Pharma, biotech, and life sciences workloads typically combine high-performance computing demands (genomic analysis, AI/ML drug discovery, simulation), strict regulatory requirements (HIPAA, HITECH, GxP, FDA 21 CFR Part 11 alignment), and the need to collaborate globally across academia and industry. General-purpose hosting rarely covers all three. Specialized hosting that's audited, scalable, and engineer-supported addresses the regulatory and operational reality these teams work in. ### Is Atlantic.Net's pharma & biotech hosting HIPAA-compliant? Yes. The hosting environment is independently audited under HIPAA AT-C 105 / 205, SOC 2 Type II, SOC 3 Type II, HITECH, and PCI DSS 4.0. A HIPAA Business Associate Agreement (BAA) is available for customers handling ePHI. The audited controls can be cited in your audit documentation, reducing the cost and time to compliance. ### What kind of compute resources are available for genomic and AI workloads? Atlantic.Net offers Cloud Virtual Servers, Dedicated Hosts, [GPU Cloud Hosting](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/), and Bare Metal Servers. AI/ML and large-scale genomic analyses commonly land on GPU-accelerated instances or Dedicated Hosts; lower-intensity research workloads run cost-effectively on Cloud Virtual Servers. Capacity scales from a single instance to thousands of nodes for parallel computational jobs. ### Can I run a hybrid public-and-private setup? Yes. Many regulated customers run sensitive workloads on the HIPAA-compliant private side and run non-sensitive simulations or modeling on the lower-cost public-cloud side. Both sides live inside the same Atlantic.Net Cloud Platform with consistent tooling, monitoring, and engineering support. ### How does Atlantic.Net support clinical-trial data integrity? Through the audited HIPAA environment plus add-on managed services: FortiGate firewall, IPS, MFA, Trend Micro Deep Security with integrity monitoring, Veeam backup, log management, and DR. Together these controls help support trial data integrity expectations consistent with FDA 21 CFR Part 11 and similar audit requirements. ### Where are Atlantic.Net's data centers located? Atlantic.Net operates eight data center locations: New York, Dallas, San Francisco, Toronto, London, Ashburn, Singapore, and Orlando. International placement supports collaboration with global research teams and lets you keep data within the jurisdiction your trial or partnership requires. ### Will Atlantic.Net sign a Business Associate Agreement? Yes. Atlantic.Net signs a HIPAA BAA with customers who handle ePHI. The BAA details our contractual obligations to safeguard PHI as required under HIPAA. Contact our Sales Department to obtain a copy. ### How quickly can I scale up for a large genomic or AI run? Cloud Virtual Servers provision in seconds via the ACP control panel or RESTful API. Larger reservations – thousands of nodes for a short-window simulation, dedicated GPU clusters for AI training – are coordinated with the Atlantic.Net team and typically available within hours to days depending on the request. ### What managed services are commonly used by life sciences customers? FortiGate Firewall, Multi-Factor Authentication, Trend Micro Deep Security, server management, Veeam backup, and Disaster Recovery are the most-frequently bundled services for regulated life sciences workloads. Each one sits inside the same audited environment so controls compose cleanly without separate compliance perimeters. ### How is Pharma & BioTech hosting priced? Pricing depends on the chosen hosting product (Cloud, Dedicated, GPU, Bare Metal), the data volume protected, and the bundled managed services. Atlantic.Net offers all-inclusive Secure Cloud plans and on-demand cloud pricing. Contact the sales team for a quote tailored to your workload. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # PCI-Compliant Hosting Solutions > URL: https://www.atlantic.net/pci-compliant-hosting/ | Updated: 2026-09-16 Protect cardholder data with a turnkey PCI DSS 4.0 ready cloud, dedicated, or custom environment backed by managed firewalls, encryption, vulnerability scanning, and 24/7/365 USA-based expert support. - PCI DSS 4.0 Ready - Managed Firewall & IPS - 24/7/365 USA-Based Support Ready hosting: PCI DSS 4.0 Uptime SLA: 100% ## PCI-Compliant Web Hosting Plans If your business accepts credit card payments and requires PCI compliance online, we've got you covered with our PCI-compliant hosting. You can focus on running your business knowing your PCI-compliant servers are securely and properly handling your customers' sensitive credit card information when processing credit card payments in a secure environment on your website or app. All Atlantic.Net PCI-compliant hosting packages listed below have been specially designed to provide more for less and help businesses achieve PCI compliance affordably. ### PCI DR Hosting Linux $973.27 per month Server Type Cloud Processor 6 vCPUs Memory 16GB Storage 200GB Data Transfer 10TB - Fully Managed FortiGate Firewall with IPS - Onsite Daily Backups - Off-Site Daily Backups - Managed VPN 5 Accounts - cPanel 5 Account License - Fully Managed Hosting **View 6 more plan services** - Multi-Factor Authentication - Trend Micro Security Suite* - Scheduled Vulnerability Scans - 4 Hours of Migration Service - Fully Managed Disaster Recovery Services - Load Balancing ### PCI DR Hosting Windows $1,026.62 per month Server Type Cloud Processor 6 vCPUs Memory 16GB Storage 200GB Data Transfer 10TB - Fully Managed FortiGate Firewall with IPS - Onsite Daily Backups - Off-Site Daily Backups - Managed VPN 5 Accounts - Fully Managed Hosting - Multi-Factor Authentication **View 5 more plan services** - Trend Micro Security Suite* - Scheduled Vulnerability Scans - 4 Hours of Migration Service - Fully Managed Disaster Recovery Services - Load Balancing ### PCI DR Hosting Custom Large Complex Deployments Custom VM Sizes - Fully Managed FortiGate Firewall with IPS - Onsite Daily Backups - Off-Site Daily Backups - Managed VPN 5 Accounts - cPanel 5 Account License - Fully Managed Hosting **View 8 more plan services** - Multi-Factor Authentication - Trend Micro Security Suite* - Scheduled Vulnerability Scans - 4 Hours of Migration Service - Fully Managed Disaster Recovery Services - Linux or Windows License - Network Edge Protection WAF / CDN / DDoS - Load Balancing *Pricing based on 12-month term *All plans are available in every location for Managed Server clients. ## PCI Hosting Services and Solutions by Atlantic.Net PCI Hosting by Atlantic.Net™ is SOC 2 and SOC 3 certified, designed to secure and protect critical financial data. If your company requires PCI-DSS compliance (that is, adherence to the PCI Data Security Standard), Atlantic.Net's managed security and compliance hosting services coupled with our Cloud Platform and Dedicated Hosting will provide you the easy button to help achieve and exceed your credit card industry PCI compliance requirements! ## What Is PCI-Compliant Hosting? PCI-compliant hosting is a web hosting solution that meets the security standards known as the PCI DSS (Payment Card Industry Data Security Standard) set by the Payment Card Industry Security Standards Council. Every merchant that accepts credit cards must abide by these standards and implement policies and procedures to ensure compliance with PCI standards. PCI Compliance is all about protecting financial data, and specifically, the way that merchants process card payments, transmit payment data, and how they digitally store transaction records. The Payment Card Industry Security Standards Council is an alliance of major credit card companies in charge of the standards to meet PCI DSS requirements. Top PCI Hosting Provider With our expanded network capacity and hardened data centers, your business will be able to achieve the uptime and cyber-security requirements for PCI compliance. You can meet your customers' needs and accept online payments while maintaining PCI compliance and reducing your overall cost. Gain the competitive advantage you need with ease with our PCI-Compliant Servers, backed by a 100% SLA. ## PCI Compliant Hosting Services Full line of hosting services to provide a turnkey hosting solution! ### Cloud Hosting Atlantic.Net provides secure PCI-Compliant Web Hosting Service in our agile virtual environment, supporting a variety of e-commerce platforms. Our storage, memory, and compute-optimized platform will boost the performance of your online applications and network connectivity, while 100% uptime will ensure your online retail store remains live, searchable, and relevant, building customer trust. The benefit in hosting your PCI-compliant application virtually is that it is fast and easy to adjust your storage needs depending on traffic and usage, keeping your investment budget-friendly. ### Dedicated Hosting Boosting and supporting high traffic websites and high activity grids is our specialty. The robustness, high security, and meeting of the strictest compliance standards of our Dedicated Hosting environment ensure your data will remain safeguarded and its transfer seamless. Designed to handle massive amounts of data at lightning speeds, our PCI-compliant servers feature enterprise-grade solid state drives. Our extensive networks are backed by redundant high-speed connections ensuring you're always online. To maximize your investment, we offer a plethora of plans to fit any business website, small or large, with the aim to elevate its online retailing. ### Compliant Hosting Our data centers were built to fulfill the strictest requirements, eliminating regulations concerns. Our data centers are routinely inspected. We are SOC 2 TYPE II and SOC 3 TYPE II certified to ensure that we are up to the exacting standards to secure the most sensitive data. Leave the monitoring of changes to your PCI-compliant hosting provider, Atlantic.Net, as you focus on growing your business. ## PCI-Compliant Hosting Features - Managed Firewall - Fully Encrypted Backups - SOC 2, SOC 3, and HIPAA Audited - User and Point to Point Encrypted VPN - Managed Intrusion Prevention System - ACP OnSite and Offsite Backup and Replication - WAF, CDN, and DDoS protection via Network Edge Protection - Disk Encryption (standard) for all Cloud Hosts and VMs ## Looking for PCI-Compliant Hosting? We Can Help With A Free Assessment. - IT Architecture Design, Security, & Guidance. - Flexible Private, Public, & Hybrid Hosting. - 24x7x365 Security, Support, & Monitoring. ## PCI Compliance Simplified! Our turnkey PCI ready hosting solution backed by over 32 years of experience, ensures that you gain maximum efficiencies and helps you bring focus to your core business and applications. Service Organization Control Ensures best practices for internal controls, physical security, availability, processing integrity, confidentiality, and privacy. ## More Resources ### Benefits of Bare Metal Hosting for Enterprise IT [Read More](https://www.atlantic.net/dedicated-server-hosting/benefits-bare-metal-hosting-enterprise/) ### HIPAA-Compliant Hosting Requirements 2026 Healthcare Hosting Guide [Read More](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/) ### What Is PCI Compliance? 12 Requirements, PCI Levels, and Penalties [Read More](https://www.atlantic.net/pci-compliant-hosting/what-is-pci-compliance/) ### HIPAA Compliant Hosting Solutions [Read More](https://www.atlantic.net/hipaa-compliant-hosting/) ## Full-Stack Managed Services All the services you need to make your IT project come to life. ### Atlantic.Net Firewall [Learn More](https://www.atlantic.net/managed-services/firewall/) ### Multi-Factor Authentication [Learn More](https://www.atlantic.net/managed-services/multi-factor-authentication/) ### Managed Server Hosting [Learn More](https://www.atlantic.net/managed-services/server-management/) ### Network Edge/DDoS Protection [Learn More](https://www.atlantic.net/managed-services/network-edge-protection/) ### Trend Micro Deep Security [Learn More](https://www.atlantic.net/managed-services/trend-micro-deep-security-suite/) ### Server Management [Learn More](https://www.atlantic.net/managed-services/server-management/) ### Consulting Agreements [Learn More](https://www.atlantic.net/managed-services/consulting/) ### Managed Veeam Backup [Learn More](https://www.atlantic.net/managed-services/veeam-services/) ## Start Your PCI Project Today! PCI Compliant Compute & Storage, Encrypted VPN, Security Firewall, BAA, Offsite Backup, Disaster Recovery, & More! ## Get Help with PCI Compliance and Protect Cardholder Data Atlantic.Net stands ready to help you attain fast compliance with a range of certifications, such as SOC 2 and SOC 3, HIPAA, and HITECH, all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, call [866-618-DATA (3282)](tel:+18666183282), or email us at [sales@atlantic.net](mailto:sales@atlantic.net). The promotional offer is only valid with a minimum of a one-year agreement and cannot be used without an agreement. ## Read More About PCI-Compliant Hosting - What Is PCI Compliance? - PCI Compliance Requirements for Cybersecurity - PCI Compliance Checklist for Small Businesses - Cloud PCI Compliance Key Requirements ## PCI Cloud Hosting vs PCI Dedicated Hosting vs Custom PCI Hosting | Feature | PCI Cloud Hosting | PCI Dedicated Hosting | Custom PCI Hosting | | --- | --- | --- | --- | | Infrastructure | Virtual cloud servers with dedicated PCI security stack | Single-tenant physical servers with full hardware isolation | Custom-configured VMs or physical servers tailored to your requirements | | Scalability | Rapid horizontal and vertical scaling on demand | Vertical scaling by upgrading physical hardware | Fully customizable scaling based on deployment architecture | | Performance | Optimized for e-commerce and web application workloads | Maximum performance with direct hardware access | Tuned to your specific workload and traffic patterns | | Managed Firewall | Fully Managed FortiGate Firewall with IPS | Fully Managed FortiGate Firewall with IPS | Fully Managed FortiGate Firewall with IPS | | Disaster Recovery | Fully managed DR services included | Fully managed DR services included | Fully managed DR services included | | Network Edge Protection | Available as add-on | Available as add-on | WAF, CDN, and DDoS protection included | | Load Balancing | Available as add-on | Available as add-on | Included | | Operating System | Linux or Windows (plan-specific) | Linux or Windows (plan-specific) | Linux or Windows included | | Best For | E-commerce sites, SaaS platforms, and growing businesses | High-traffic retailers, financial services, and large databases | Large complex deployments with specialized compliance needs | | Starting Price | From $973.27/mo (Linux) or $1,026.62/mo (Windows) | Contact sales for dedicated pricing | Contact sales for custom quote | ## PCI DSS 4.0 Compliance PCI DSS 4.0 became mandatory in March 2025, replacing the previous 3.2.1 standard. The updated standard introduces stricter authentication requirements, expanded encryption mandates, continuous security monitoring, and a greater emphasis on risk-based approaches to protecting cardholder data. Organizations that process, store, or transmit credit card information must now meet PCI DSS 4.0 requirements or face significant penalties. Atlantic.Net's PCI-compliant hosting infrastructure is designed to help you meet and exceed PCI DSS 4.0 requirements. Our fully managed security stack – including managed FortiGate firewalls with IPS, multi-factor authentication, bi-weekly vulnerability scanning, intrusion detection, encrypted backups, and disk encryption – addresses the core technical controls required under the new standard. Combined with our SOC 2 Type II and SOC 3 Type II certified data centers, Atlantic.Net provides the audit-ready foundation your business needs to maintain compliance. For a detailed walkthrough of PCI DSS 4.0 requirements and how they affect your hosting environment, see our PCI DSS 4.0 Hosting Checklist. ## Why Choose Atlantic.Net for PCI-Compliant Hosting - Turnkey PCI DSS 4.0 ready hosting environment - Fully managed FortiGate firewalls with intrusion prevention - SOC 2 Type II and SOC 3 Type II certified data centers - Multi-factor authentication, encrypted VPN, and disk encryption standard - Bi-weekly vulnerability scanning with Trend Micro Security Suite - Onsite and off-site daily encrypted backups with disaster recovery - 24/7/365 USA-based expert support and managed services - 100% Uptime SLA with redundant high-speed network connections - Over 32 years of hosting experience across regulated industries - Flexible plans from cloud to dedicated to fully custom deployments ## Common Use Cases for PCI-Compliant Hosting - E-commerce websites and online retail storefronts processing credit card payments - SaaS platforms with subscription billing and recurring payment processing - Payment gateways and payment processor infrastructure - Financial services applications handling cardholder data - Hospitality and travel booking systems with online payments - Healthcare organizations processing patient co-pays and billing - Non-profit donation platforms accepting credit card contributions - Multi-location retail businesses with centralized payment processing ## Always On With hosted data centers in key metropolitan areas, we are prepared to support every geography with our extensive network and superior customer service. Our global presence reduces response latency and ensures that both you and your customers will never have to wait on your website. We stand by to assist you in choosing the website eCommerce platform that's best for you. ## See Additional Guides on Bare Metal Cloud Topics We have authored in-depth guides on several other topics that can also be useful as you explore the world of hybrid cloud. ### [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) Authored by Atlantic.Net - [[Guide] HIPAA-Compliant Hosting | Award Winning HIPAA Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) - [[Guide] What is Protected Health Information (PHI)?](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) - [[Blog] RTLS and Healthcare](https://www.atlantic.net/hipaa-compliant-hosting/rtls-and-healthcare-can-real-time-location-system-security-improve-your-healthcare-operations/) - [[Product] Atlantic.Net HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) ### [What is PCI Compliance?](https://www.atlantic.net/pci-compliant-hosting/what-is-pci-compliance/) Authored by Atlantic.Net - [[Guide] What Is PCI Compliance? 12 Requirements, PCI Levels, and Penalties](https://www.atlantic.net/pci-compliant-hosting/what-is-pci-compliance/) - [[Blog] How to Reduce Your PCI Scope When Accepting Payments](https://www.atlantic.net/pci-compliant-hosting/reduce-pci-scope-accepting-payments/) - [[Product] Atlantic.Net PCI-Compliant Hosting](https://www.atlantic.net/pci-compliant-hosting/) ### [VPS Hosting](https://www.atlantic.net/vps-hosting/) Authored by Atlantic.Net - [[Guide] Cloud VPS Hosting | Virtual Private Servers](https://www.atlantic.net/vps-hosting/) - [[Guide] High-Performance & Affordable Linux VPS Hosting](https://www.atlantic.net/vps-hosting/linux-vps-hosting/) - [[Blog] Does Using SaaS Make My IT Environment More Secure or Less Secure?](https://www.atlantic.net/vps-hosting/does-using-saas-make-my-it-environment-more-secure-or-less-secure/) - [[Product] Atlantic.Net Cloud Platform | Scalable, Secure Cloud Solutions](https://www.atlantic.net/cloud-platform/) ## PCI Hosting FAQ ### How do you host a payment processing app in a PCI-certified infrastructure? The better goal is to host the application in a PCI-ready environment that supports your PCI DSS requirements. That usually means segmented infrastructure, managed firewalls, controlled access, encryption, logging, vulnerability scanning, and a deployment design that keeps the cardholder data environment as small and controlled as possible. ### Does Atlantic.Net offer fully managed PCI-compliant hosting environments? Yes. Atlantic.Net offers fully managed PCI hosting environments with security controls including firewalls, intrusion detection, encrypted storage, and vulnerability scanning. ### Can Atlantic.Net assist with PCI DSS Level 1 or 2 audits? Atlantic.Net can support your PCI audit process by providing PCI-ready infrastructure, security controls, and supporting documentation. It should be treated as audit support, not as a replacement for your own compliance team, assessor, or required PCI validation process. ### How do you ensure eCommerce hosting meets PCI standards? Start by reducing PCI scope wherever possible, then build a properly segmented, secure cardholder data environment. In practice, that means controlling access, protecting stored and transmitted data, logging system activity, scanning for vulnerabilities, and keeping the environment aligned with the PCI DSS requirements that apply to your business. ### What type of hosting is best for PCI DSS compliance? That depends on the size and complexity of your payment environment. Dedicated servers and private cloud environments are often the best fit when you need stronger isolation, more control, and a simpler path to securing a cardholder data environment. PCI-ready cloud hosting can also work well for smaller or growing businesses when it is designed and managed correctly. ### Do you offer PCI-compliant cloud services for startups? Yes. Atlantic.Net offers PCI-ready cloud and infrastructure options that can work well for startups that need secure payment hosting without building a full compliance-oriented environment from scratch. ### What features should PCI-compliant web hosting include? Look for network segmentation, managed firewalls, intrusion detection, encrypted storage, encrypted backups, multi-factor authentication, vulnerability scanning, centralized logging, and access to documentation that supports your PCI assessment process. ### How do you assess a PCI-compliant hosting provider for trust and reliability? Look for a provider with published uptime commitments, strong security controls, clear compliance documentation, 24/7 support, and experience supporting regulated environments. You want a provider that can support both the technical side of PCI and the operational discipline needed to maintain it. ### Does Atlantic.Net offer secure hosting for credit card data storage? Yes. Atlantic.Net offers PCI-ready hosting environments designed to secure payment-related data with managed security controls, encryption, and segmented infrastructure. Your application design, access policies, and compliance processes still need to be handled correctly on your side. ### Does Atlantic.Net PCI hosting include vulnerability scanning? Yes. Atlantic.Net includes vulnerability scanning as part of its PCI hosting offering, helping identify security issues before they become compliance or operational problems. ## A Support Team Backed by Decades of Experience With over three decades of experience, our support team is always here to assist you. You’ll have 24/7/365 access to a crop of dedicated veterans, capable of solving any technical problem you throw their way. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # PCI Security Services > URL: https://www.atlantic.net/pci-compliant-hosting/pci-security-services/ | Updated: 2026-09-16 Protect cardholder data environments with managed firewalls, edge protection, IDS/IPS, AES-256 encrypted VPN, MFA, anti-malware, and biweekly vulnerability scans operated by Atlantic.Net engineers. - PCI DSS 4.0 Aligned - AES-256 Encrypted VPN - Biweekly Vulnerability Scans - 24/7/365 Support Managed Security Services: 10+ Global Data Centers: 8 ## PCI Security Services by Atlantic.Net Atlantic.Net's managed PCI-ready security service is designed to safeguard server infrastructure and protect critical data in a secure and compliant environment. Our PCI-ready managed security service enables our clients to stay focused on their core business. Atlantic.Net provides and manages security aspects of the hosting environment to help attain fast compliance by meeting and exceeding industry standards. Our support team not only ensures your IT infrastructure is always available, but also stands ready to provide expert counsel for peace of mind. Our highly trained engineers understand your success is our success, so we will never leave you hanging. Here are a few key PCI-ready managed services to help you with all your compliance needs: - Managed Firewall - Managed Edge Protection - Intrusion Detection Service (IDS) - Fully Managed VPN - Multi-Factor Authentication (MFA) - Anti-Malware Protection - Dedicated Resources Backed by Dedicated Cloud Hosts - Onsite/Offsite Backup and Replication Capabilities - Vulnerability Scans - Trend Micro™ DEEP SECURITY Packages ## Looking for PCI Compliant Hosting? We Can Help With A Free Assessment. - IT Architecture Design, Security, & Guidance. - Flexible Private, Public, & Hybrid Hosting. - 24x7x365 Security, Support, & Monitoring. ### Managed Firewall A professionally managed firewall service gives our clients a peace-of-mind that each layer of the network is protected to the highest of standards. Our experienced network engineering team has designed our network service to be logical, robust, and secure. The Managed Firewall Service includes a customized and fully managed firewall stack connected to the Atlantic.Net network, isolating your traffic from all other traffic. A redundant firewall stack configuration is also available upon request and is designed with affordability and security in mind. One-size-fits-all does not apply here; we strive to go beyond basic security protocols and do more than necessary to ensure security and compliance. By default, all Atlantic.Net clients have access to our Network Address Translation Utility that integrates with our managed firewall. It is designed to allow quick and easy network shaping functions, configurable port forwarding, outbound NAT, and advanced load balancing for both inbound and outbound connectivity. ### Managed Edge Protection We offer Edge Services that will shield your environment against a Distributed Denial of Service attack, which is a large-scale assault on server infrastructure with the intention to overload a web server with fake requests to bring the system down. Atlantic.Net can implement managed DDoS protection technology that will automatically thwart unwanted requests. We also provide Content Delivery Networks (CDN) to help reduce the attack surface of your website. With a CDN, a user request for content on your site is cached at the network edge, resulting in less load and less exposure of front-end services. Web Application Firewall (WAF) is another available service that uses policy-defined protection for web applications by monitoring and filtering traffic via the network edge. ### Intrusion Prevention System (IPS) Our optional Intrusion Detection Service (IDS) intelligently and proactively monitors network activity for our managed firewall customers. The intrusion prevention system resides directly on the network, protecting against local vulnerabilities at the network layer. Our IDS shields your system from global exploits and increases visibility into applications accessing the network, which helps intelligent protection against known and zero-day attacks and automatically delivers rules that guard the network against newly discovered vulnerabilities. A bidirectional stateful firewall decreases the attack surface of your physical and virtual servers, centralizes management of server firewall policy, and prevents Denial of Service (DoS) attacks. ### Fully Managed VPN The VPN offering is available as a User VPN and a Point-to-Point VPN tunnel. We implement an encrypted AES-256 VPN tunnel that supports OpenVPN and IPSec by default that exceeds PCI-DSS standards. The service includes the management, maintenance, and troubleshooting of VPN connectivity. ### Anti Malware Protection: Atlantic.Net's engineers trust Trend Micro Anti-Malware to protect systems from malicious software. If your team is required to meet PCI compliance standards, Atlantic.Net has your Anti-Malware and Anti-Virus needs to be covered. ### Multi-Factor Authentication (MFA) In conjunction with a strong password policy, and secured VPNs and encryption, Multi-Factor Authentication (MFA) is the defacto choice for securing all computer assets. With a managed service, MFA can easily be set up at scale, and MFA authentication software can be distributed, for example, to a user's mobile phone. Securing infrastructure with MFA will create added protection; each user will need not only a username and password but also a pin and a code generated from a mobile app, just like Internet banking. ### Onsite/Offsite Backup and Replication Capabilities Our highly available backup solutions offer on-site storage for local backups, replication, and off-site storage capabilities at any of our eight global data center regions. ### Vulnerability Scans Our managed Services include biweekly vulnerability scans for host servers or configured websites. Upon request, we can also assist with evaluating scan results and implement requested firewall rules to mitigate potential issues. ### Dedicated Resources Backed by Dedicated Cloud Hosts Atlantic.Net Dedicated Cloud Hosts provide unmatched performance and can greatly assist with PCI transactions. Our Dedicated Hosts can help eliminate noisy neighbors and make compliance and security much easier. ## Trend Micro™ Deep Security Suite – Deep Security Modules: Trend Micro™ DEEP SECURITY Anti-Malware Package: Anti-malware integration helps protect virtual machines against viruses, spyware, and other malware, which included Web Reputation that strengthens protection against web threats to servers and virtual desktops. This is done by integrating Trend Micro™ Smart Protection Network™ web reputation capabilities to safeguard users and applications by blocking access to malicious URLs. Trend Micro™ DEEP SECURITY Network Security Package: Intrusion Detection (IDS) shields your system from global exploits and increases visibility into applications accessing the network, which helps intelligent protection against known and zero-day attacks and automatically delivers rules that guard the network against newly discovered vulnerabilities. The bidirectional stateful firewall decreases the attack surface of your physical and virtual servers, centralizes management of server firewall policy, and prevents Denial of Service (DoS) attacks. Trend Micro™ DEEP SECURITY System Security Package: By monitoring critical operating system and application files, such as directories, registry keys, and values, Integrity Monitoring detects and reports malicious and unexpected changes to files, the hypervisor, and systems registry in real-time Log Inspection optimizes the identification of key security events buried in log files across the data center, which the SIEM system correlates, reports, and archives. Event tagging replicates actions for similar events across the entire data center, reducing cost, while agentless configuration adds security to virtual machines without adding footprint. ## Trend Micro™ Deep Security Suite By choosing one of Atlantic.Net's Managed Trend Micro™ DEEP SECURITY packages, you will be equipped to mitigate major security challenges in the cyber landscape. ### Virtual Environments: Preserve performance and consolidation ratios with comprehensive agentless security built specifically to maximize protection for virtual environments. ### Optimized for Server Environments: Optimizes security operations to avoid antivirus storms commonly seen in full system scanning and pattern updates from traditional security capabilities. ### Virtual patching: Shield vulnerabilities before they can be exploited, eliminating the operational pains of emergency patching, frequent patch cycles, and costly system downtime. ### Compliance: Demonstrate compliance with a number of regulatory requirements including PCI DSS 3.0, HIPAA, HITECH, FISMA/NIST, NERC, SSAE 18, and more. Learn more about Trend Micro Deep Security. ## Get Help with PCI Compliance Atlantic.Net stands ready to help you attain fast compliance with a range of certifications, such as SOC 2 and SOC 3, HIPAA, and HITECH, all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282), or email us at sales@atlantic.net. The one-month free offer is only valid with a minimum of a one-year agreement and the promotion cannot be applied without an agreement. The offer is only valid in the Orlando region and does not apply to bare-metal servers and dedicated server hosting plans. ## Start Your PCI Project Today! PCI Compliant Server & Storage, Encrypted VPN, Security Firewall, Offsite Backup, Disaster Recovery, & More! ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Cloud Platform (ACP) by Atlantic.Net > URL: https://www.atlantic.net/cloud-platform/ | Updated: 2026-09-16 Provision Cloud Virtual Servers, Secure Block Storage, private networking, DNS, snapshots, and automated backups through the ACP control panel or RESTful API, with all-inclusive pricing and 24/7/365 US-based engineer support. - All-Inclusive Pricing - HIPAA & HITECH - SOC 2 & SOC 3 Type II - PCI DSS 4.0 US-Based Engineer Support: 24/7/365 Years of Experience: 30+ ## Cloud Platform The Atlantic.Net Cloud Platform is engineered to deliver fault-tolerant, ultra-fast performance for the workloads driving your computing strategy forward. The Atlantic.Net Cloud is built around all-inclusive pricing and world-class infrastructure, backed by expert advisors and an always-available support team via phone or email. Our highly available Cloud Platform includes award-winning Cloud Servers, Secure Block Storage, one-click applications, DNS, dedicated private nodes, private networking, RESTful API, data backup, and a full suite of managed services. ## On-Demand Cloud Plans | | | | | | | | | | --- | --- | --- | --- | --- | --- | --- | --- | | General Purpose | G3.2GB | 2GB | 1 | 50GB | 3 TB | On-Demand: $10.0/mo $0.0149/hr; 1-Year: $9.0/mo $0.0134/hr; 3-Year: $8.0/mo $0.0119/hr | On-Demand: $16.5/mo $0.0246/hr; 1-Year: $15.5/mo $0.0231/hr; 3-Year: $15.5/mo $0.0231/hr | | General Purpose | G3.4GB | 4GB | 2 | 80GB | 5 TB | On-Demand: $20.0/mo $0.0298/hr; 1-Year: $18.0/mo $0.0268/hr; 3-Year: $17.0/mo $0.0253/hr | On-Demand: $33.0/mo $0.0491/hr; 1-Year: $31.0/mo $0.0461/hr; 3-Year: $30.0/mo $0.0446/hr | | General Purpose | G3.8GB | 8GB | 4 | 160GB | 6 TB | On-Demand: $40.0/mo $0.0595/hr; 1-Year: $37.0/mo $0.0551/hr; 3-Year: $34.0/mo $0.0506/hr | On-Demand: $66.0/mo $0.0982/hr; 1-Year: $63.0/mo $0.0938/hr; 3-Year: $59.5/mo $0.0885/hr | | General Purpose | G3.16GB | 16GB | 6 | 320GB | 7 TB | On-Demand: $80.0/mo $0.119/hr; 1-Year: $74.0/mo $0.1101/hr; 3-Year: $68.0/mo $0.1012/hr | On-Demand: $132.5/mo $0.1972/hr; 1-Year: $125.5/mo $0.1868/hr; 3-Year: $119.5/mo $0.1778/hr | | General Purpose | G3.32GB | 32GB | 8 | 640GB | 8 TB | On-Demand: $160.0/mo $0.2381/hr; 1-Year: $147.0/mo $0.2188/hr; 3-Year: $136.0/mo $0.2024/hr | On-Demand: $265.0/mo $0.3943/hr; 1-Year: $250.5/mo $0.3728/hr; 3-Year: $238.0/mo $0.3542/hr | | General Purpose | G3.48GB | 48GB | 12 | 960GB | 9 TB | On-Demand: $240.0/mo $0.3571/hr; 1-Year: $220.0/mo $0.3274/hr; 3-Year: $204.0/mo $0.3036/hr | On-Demand: $397.5/mo $0.5915/hr; 1-Year: $375.5/mo $0.5588/hr; 3-Year: $358.5/mo $0.5335/hr | | General Purpose | G3.64GB | 64GB | 16 | 1280GB | 10 TB | On-Demand: $320.0/mo $0.4762/hr; 1-Year: $294.0/mo $0.4375/hr; 3-Year: $272.0/mo $0.4048/hr | On-Demand: $529.5/mo $0.7879/hr; 1-Year: $500.5/mo $0.7448/hr; 3-Year: $477.0/mo $0.7098/hr | | General Purpose | G3.96GB | 96GB | 20 | 1920GB | 11 TB | On-Demand: $480.0/mo $0.7143/hr; 1-Year: $441.6/mo $0.6571/hr; 3-Year: $408.0/mo $0.6071/hr | On-Demand: $795.5/mo $1.1838/hr; 1-Year: $754.5/mo $1.1228/hr; 3-Year: $718.5/mo $1.0692/hr | | General Purpose | G3.128GB | 128GB | 24 | 2560GB | 12 TB | On-Demand: $640.0/mo $0.9524/hr; 1-Year: $589.0/mo $0.8765/hr; 3-Year: $544.0/mo $0.8095/hr | On-Demand: $1,059.0/mo $1.5759/hr; 1-Year: $1,003.0/mo $1.4926/hr; 3-Year: $953.0/mo $1.4182/hr | | General Purpose | G3.192GB | 192GB | 32 | 3840GB | 13 TB | On-Demand: $960.0/mo $1.4286/hr; 1-Year: $883.2/mo $1.3143/hr; 3-Year: $816.0/mo $1.2143/hr | On-Demand: $1,588.5/mo $2.3638/hr; 1-Year: $1,506.5/mo $2.2418/hr; 3-Year: $1,435.5/mo $2.1362/hr | | Compute Optimized | C2.8GB | 8GB | 4 | 40GB | 10 TB | On-Demand: $211.0/mo $0.314/hr; 1-Year: $137.0/mo $0.2039/hr; 3-Year: $67.0/mo $0.0997/hr | On-Demand: $254.5/mo $0.3787/hr; 1-Year: $173.0/mo $0.2574/hr; 3-Year: $96.0/mo $0.1429/hr | | Compute Optimized | C2.16GB | 16GB | 8 | 80GB | 10 TB | On-Demand: $418.0/mo $0.622/hr; 1-Year: $271.0/mo $0.4033/hr; 3-Year: $133.0/mo $0.1979/hr | On-Demand: $505.5/mo $0.7522/hr; 1-Year: $343.0/mo $0.5104/hr; 3-Year: $190.5/mo $0.2835/hr | | Compute Optimized | C2.32GB | 32GB | 16 | 160GB | 10 TB | On-Demand: $828.0/mo $1.2321/hr; 1-Year: $538.0/mo $0.8006/hr; 3-Year: $263.0/mo $0.3914/hr | On-Demand: $1,002.0/mo $1.4911/hr; 1-Year: $682.0/mo $1.0149/hr; 3-Year: $378.0/mo $0.5625/hr | | Compute Optimized | C2.64GB | 64GB | 20 | 350GB | 10 TB | On-Demand: $1,451.0/mo $2.1592/hr; 1-Year: $943.0/mo $1.4033/hr; 3-Year: $461.0/mo $0.686/hr | On-Demand: $1,777.5/mo $2.6451/hr; 1-Year: $1,216.5/mo $1.8103/hr; 3-Year: $685.0/mo $1.0194/hr | | Storage Optimized | S2.16GB | 16GB | 2 | 500GB | 10 TB | On-Demand: $248.0/mo $0.369/hr; 1-Year: $161.0/mo $0.2396/hr; 3-Year: $105.0/mo $0.1563/hr | On-Demand: $317.5/mo $0.4725/hr; 1-Year: $221.5/mo $0.3296/hr; 3-Year: $160.0/mo $0.2381/hr | | Storage Optimized | S2.32GB | 32GB | 4 | 1TB | 10 TB | On-Demand: $425.0/mo $0.6324/hr; 1-Year: $276.0/mo $0.4107/hr; 3-Year: $180.0/mo $0.2679/hr | On-Demand: $557.0/mo $0.8289/hr; 1-Year: $392.5/mo $0.5841/hr; 3-Year: $286.5/mo $0.4263/hr | | Storage Optimized | S2.64GB | 64GB | 8 | 2TB | 10 TB | On-Demand: $778.0/mo $1.1577/hr; 1-Year: $506.0/mo $0.753/hr; 3-Year: $330.0/mo $0.4911/hr | On-Demand: $1,035.0/mo $1.5402/hr; 1-Year: $734.5/mo $1.093/hr; 3-Year: $540.5/mo $0.8043/hr | | Storage Optimized | S2.96GB | 96GB | 12 | 3TB | 10 TB | On-Demand: $1,097.0/mo $1.6324/hr; 1-Year: $713.0/mo $1.061/hr; 3-Year: $465.0/mo $0.692/hr | On-Demand: $1,475.0/mo $2.1949/hr; 1-Year: $1,051.5/mo $1.5647/hr; 3-Year: $777.5/mo $1.157/hr | | Storage Optimized | S2.128GB | 128GB | 16 | 4TB | 10 TB | On-Demand: $1,414.0/mo $2.1042/hr; 1-Year: $919.0/mo $1.3676/hr; 3-Year: $599.0/mo $0.8914/hr | On-Demand: $1,913.0/mo $2.8467/hr; 1-Year: $1,367.0/mo $2.0342/hr; 3-Year: $1,013.5/mo $1.5082/hr | | Memory Optimized | M2.16GB | 16GB | 2 | 40GB | 10 TB | On-Demand: $163.0/mo $0.2426/hr; 1-Year: $106.0/mo $0.1577/hr; 3-Year: $52.0/mo $0.0774/hr | On-Demand: $223.5/mo $0.3326/hr; 1-Year: $161.0/mo $0.2396/hr; 3-Year: $101.5/mo $0.151/hr | | Memory Optimized | M2.32GB | 32GB | 4 | 80GB | 10 TB | On-Demand: $318.0/mo $0.4732/hr; 1-Year: $207.0/mo $0.308/hr; 3-Year: $101.0/mo $0.1503/hr | On-Demand: $439.0/mo $0.6533/hr; 1-Year: $316.5/mo $0.471/hr; 3-Year: $200.0/mo $0.2976/hr | | Memory Optimized | M2.64GB | 64GB | 8 | 160GB | 10 TB | On-Demand: $630.0/mo $0.9375/hr; 1-Year: $409.0/mo $0.6086/hr; 3-Year: $200.0/mo $0.2976/hr | On-Demand: $871.5/mo $1.2969/hr; 1-Year: $627.5/mo $0.9338/hr; 3-Year: $397.5/mo $0.5915/hr | | Memory Optimized | M2.128GB | 128GB | 16 | 350GB | 10 TB | On-Demand: $1,246.0/mo $1.8542/hr; 1-Year: $810.0/mo $1.2054/hr; 3-Year: $396.0/mo $0.5893/hr | On-Demand: $1,727.5/mo $2.5707/hr; 1-Year: $1,246.5/mo $1.8549/hr; 3-Year: $790.0/mo $1.1756/hr | *All plans are available in every location for Managed Server clients. *The hourly rate is determined by dividing the monthly rate by 672 hours (28 days). If your server is online for more than 672 hours in a calendar month, you will only be billed the monthly rate. *Prices listed above are based on the service being utilized for the period specified. *All Servers include one IPv4 Address. Additional IPs are available for $3.65/month ($0.005431/hour) *Unlimited inbound bandwidth. If free outbound bandwidth is exceeded, each additional GB is $0.02 *Optional Daily Backups are available for 20% of the server price. Minimum $1.00/month. *cPanel licensing cost starts at $23 per month ## What Is a Cloud Platform? A cloud platform is a suite of on-demand computing services delivered over the internet ‐ servers, storage, databases, networking, and applications that you provision and scale through software rather than physical hardware. The right platform delivers scalability, flexibility, and cost-effective IT for businesses without the overhead of running your own data center. ## Cloud Platform Features ### The ACP Control Panel The intuitive, easy-to-use, and secure ACP control panel lets you create and manage cloud virtual servers, block storage, SSH keys, private and public IPs, DNS records, and more ‐ all in one place. ### Snapshots Save a point-in-time copy of your Cloud Virtual Server's local storage. Restore your server to the snapshot moment, transfer a copy to another location, or create a new server directly from a snapshot. ### Cloud Virtual Servers Atlantic.Net offers Windows, Linux, and FreeBSD Cloud Virtual Servers combining the most advanced innovations and technology ‐ backed by redundant SSD storage for peace of mind. A faster Cloud hosting environment optimized for performance, scalability, affordability, and reliability. ### Fast, Simplified Compliance Audited accreditations include: HIPAA, HITECH, SOC 2 Type II, SOC 3 Type II, PCI DSS 4.0 ### ACP Cloud Backups Atlantic.Net's proprietary storage solution and extensive cloud platform combine to deliver on-site and off-site backup and replication services that are fast, robust, and fault-tolerant. Backup is fully automated and configurable to your retention requirements. ### Dedicated Hosts Dedicated Hosts are private computing nodes fully reserved for your use, with no shared resources and no noisy-neighbor issues. Create Cloud Virtual Servers, block storage, SSH keys, private and public IPs, and DNS records under one user-friendly interface on your own dedicated host node. ### Secure Block Storage Create flexible elastic storage for your cloud virtual servers. Scale storage up or down, and move storage between servers as workloads shift. Replication is included as a standard feature of our highly redundant storage platform. ### Managed and Security Services Pair your Cloud Platform deployment with Atlantic.Net's full suite of managed services ‐ FortiGate firewall, Trend Micro Deep Security, multi-factor authentication, server management, Veeam backup, and consulting ‐ so your team can focus on the application instead of operating the infrastructure. ## Cloud Hosting Models ‐ Choosing the Right Atlantic.Net Product | Model | Best For | Resource Sharing | Atlantic.Net Product | | --- | --- | --- | --- | | Public Cloud (multi-tenant) | General-purpose workloads, dev/test, web apps, APIs | Shared hardware, isolated VMs | Cloud Hosting (CVS) | | Dedicated Host (single-tenant cloud) | Workloads needing predictable performance, no noisy-neighbor risk | Single tenant, your VMs only | Dedicated Hosts | | Managed Private Cloud | Regulated and high-security workloads under HIPAA, PCI, SOC 2 | Single tenant with managed services bundled | Managed Private Cloud | | GPU Cloud | AI/ML training, inference, rendering, scientific computing | Shared or dedicated GPU resources | GPU Cloud Hosting | | Inference Cloud | Production model serving with predictable latency | Reserved inference capacity | Inference Cloud | | Bare Metal Servers | Maximum performance, custom hypervisors, specialty workloads | Dedicated physical hardware | Bare Metal Servers | ## More Resources ### VMware vs Hyper-V: Which Is Best? [VMware vs Hyper-V: Which Is Best?](https://www.atlantic.net/vps-hosting/microsoft-hyper-v-or-vmware/) ### What Is Dedicated Server Hosting? [What Is Dedicated Server Hosting?](https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/) ### Managed Services by Atlantic.Net [Managed Services by Atlantic.Net](https://www.atlantic.net/managed-services/) ### What Is VPS Hosting? Buyer's Guide and Expert Tips [What Is VPS Hosting? Buyer's Guide and Expert Tips](https://www.atlantic.net/vps-hosting/what-is-vps-buyers-guide-and-expert-tips/) ## Cloud Platform by Atlantic.Net With over three decades of experience, our support team is always here to assist. You'll have 24/7/365 access to a team of dedicated veterans capable of solving any technical problem you bring them. ## Full-Stack Managed Services ### Network Edge / DDoS Protection [Network Edge / DDoS Protection](https://www.atlantic.net/managed-services/network-edge-protection/) ### Trend Micro Deep Security [Trend Micro Deep Security](https://www.atlantic.net/managed-services/trend-micro-deep-security-suite/) ### FortiGate Firewall [FortiGate Firewall](https://www.atlantic.net/managed-services/firewall/) ### Server Management [Server Management](https://www.atlantic.net/managed-services/server-management/) ### Consulting Agreements [Consulting Agreements](https://www.atlantic.net/managed-services/consulting/) ### Multi-Factor Authentication [Multi-Factor Authentication](https://www.atlantic.net/managed-services/multi-factor-authentication/) ## Secure Cloud Hosting Plans ### Fortress Standard Cloud Hosting - Linux Secure, isolated infrastructure with essential protections $373.24 Per Month 4 CPU's 16 GB of Ram 100 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - cPanel 5 Account License - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Fortress Business Cloud Hosting - Linux Enhanced security layers and hardened configurations $744.88 Per Month 8 vCPU's 32 GB of Ram 300 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - cPanel 5 Account License - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Fortress Enterprise Cloud Hosting - Linux Compliance-ready security for regulated and mission-critical workloads $1,468.75 Per Month 8 vCPU's 64 GB of Ram 500 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - cPanel 5 Account License - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Fortress Custom Fortress Custom Cloud Hosting Maximum security, customization, and premium SLAs Custom Cloud Hosting - Onsite Daily Backups - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Fortress Standard Cloud Hosting - Windows Secure, isolated infrastructure with essential protections $385.22 Per Month 4 CPU's 16 GB of Ram 100 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Fortress Business Cloud Hosting - Windows Enhanced security layers and hardened configurations $799.57 Per Month 8 vCPU's 32 GB of Ram 300 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Fortress Enterprise Cloud Hosting - Windows Compliance-ready security for regulated and mission-critical workloads $1,786.89 Per Month 8 vCPU's 64 GB of Ram 500 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement *$150-$300 setup fee applies *Pricing based upon 12-month term commitment, and month to month option is available with a 20% premium. ***Save up to 30% off above listed pricing with longer billing terms*** These plans do not include HIPAA Compliant Hosting. You can choose a HIPAA Hosting plans by clicking here. ## Frequently Asked Questions About the Cloud Platform ### What is the Atlantic.Net Cloud Platform (ACP)? The Atlantic.Net Cloud Platform (ACP) is a fully managed, compliant cloud infrastructure platform offering Cloud Virtual Servers, Secure Block Storage, snapshots, automated backups, dedicated hosts, and a full suite of managed services. It is delivered from SOC 2 Type II, HIPAA, HITECH, and PCI DSS-aligned data centers and managed via the ACP control panel or RESTful API. ### What's included in the Cloud Platform? Cloud Virtual Servers (Windows, Linux, FreeBSD), Secure Block Storage, snapshots, the ACP control panel, RESTful API, DNS, private and public IPs, SSH key management, automated backups and replication, dedicated hosts, GPU-accelerated and inference cloud options, and full-stack managed services (firewall, IPS, MFA, Trend Micro, server management, Veeam backup, consulting). ### How does the Atlantic.Net Cloud Platform compare to AWS, Azure, and GCP? ACP is a focused, all-inclusive cloud platform: predictable pricing (no per-hour egress, snapshot, or API surprises), US-based 24/7/365 support staffed by engineers, and an audited compliance environment with HIPAA BAAs and PCI DSS attestations available out of the box. Where the hyperscalers compete on breadth (hundreds of services), ACP competes on simplicity, predictable cost, and concierge-grade managed services for regulated industries. ### Which operating systems are supported on Cloud Virtual Servers? Windows Server, multiple Linux distributions (Ubuntu LTS, Debian, Rocky Linux, AlmaLinux, RHEL, FreeBSD), and one-click deployments for common stacks such as cPanel/WHM, LAMP, LEMP, MySQL, NextCloud, and WordPress. Custom images are supported on request. ### Is the Cloud Platform HIPAA, PCI DSS, or SOC 2 compliant? Yes. The Cloud Platform operates from infrastructure independently audited for SOC 2 Type II, SOC 3 Type II, HIPAA, HITECH, and PCI DSS 4.0. A HIPAA Business Associate Agreement (BAA) is available for customers handling ePHI. Atlantic.Net's audited controls can be cited directly in your audit documentation. ### What is the difference between Cloud Hosting and Dedicated Hosts? Cloud Hosting (Cloud Virtual Servers) places your VMs on shared multi-tenant hardware with strong isolation between VMs. Dedicated Hosts give you the entire physical hypervisor node for your own VMs only ‐ no shared resources and no noisy-neighbor risk. Dedicated Hosts are typically chosen for workloads with predictable high performance requirements or strict isolation needs. ### What is Secure Block Storage? Secure Block Storage (SBS) is elastic block-storage that attaches to your Cloud Virtual Servers. You can resize volumes, detach and re-attach to a different VM, and rely on built-in replication for redundancy. SBS is typically used for application data, databases, and anything that needs to survive a server replacement or scale beyond local-disk limits. ### How do snapshots work? A snapshot is a point-in-time image of a Cloud Virtual Server's local storage. You can roll a server back to a snapshot, create a brand-new server from a snapshot, or transfer a snapshot to another data center for off-site recovery. Snapshots are commonly used as quick rollback points before risky changes and as the seed for cloning environments. ### Where are the Atlantic.Net data centers located? Atlantic.Net operates a global footprint with data centers in Ashburn, Dallas, New York, Orlando, San Francisco, Toronto, London, and Singapore. Workloads can be placed in the region closest to your users or replicated across regions for disaster recovery. ### How is the Cloud Platform priced? The Cloud Platform offers two pricing models: predictable Secure Cloud plans with all-inclusive monthly pricing and on-demand cloud plans billed per hour. Atlantic.Net pricing is all-inclusive, with no surprise charges for snapshots, API calls, or basic egress. Contact sales for custom-sized environments. ## Cloud Availability in Multiple Global Regions Deploy close to your users from eight international data centers worldwide, with new regions on the way. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # High-Performance Cloud VPS Hosting with Full Root Control > URL: https://www.atlantic.net/vps-hosting/ | Updated: 2026-09-16 Deploy Linux, Windows, or FreeBSD virtual servers in under 30 seconds with guaranteed resources, RAID-10 protected SSD storage, and 24x7 USA-based support. - Full Root Access - Guaranteed Server Resources - RAID-10 Protected SSD Storage - 24x7 USA-Based Support Deploy in: Under 30 sec Uptime SLA: 100% ## VPS Hosting in the Cloud VPS Hosting from Atlantic.Net gives you the freedom to create and deploy one or many virtual servers in seconds. By combining the most advanced VPS hosting innovations and resources available, the Atlantic.Net Cloud offers simplicity, security, scalability, and reliability that will not only improve your virtual private server performance but also reduce your costs. With Atlantic.Net, you get the full suite of Cloud VPS hosting services: compute, redundant storage platforms, One-Click Apps, DNS, private networking, Onsite Backups, Offsite Backups, Secure Block Storage, and more, all backed by 24x7 support and a full range of managed services your business needs to succeed. This is part of an extensive series of guides about compliance management. ## What is Cloud VPS Hosting? A Virtual Private Server (VPS) allows users to take advantage of the latest cloud technology backed by high-performing redundant systems. It gives the same full root access and administrative server control without incurring the costs associated with running a dedicated server environment. VPS hosting is very flexible and can be used for hosting websites, databases, applications, storage, and more. Cloud VPS hosting is the perfect solution if you are looking for an easy-to-use, scalable, and performant option for your hosting needs. VPS hosting is best defined as a hosting solution that offers the affordability of a shared hosting account with the power, flexibility, and performance of dedicated server hosting. ## VPS Hosting Plans and Pricing Choose the perfect VPS hosting plan for your needs. | | | | | | | | | | --- | --- | --- | --- | --- | --- | --- | --- | | General Purpose | G3.2GB | 2GB | 1 | 50GB | 3 TB | On-Demand: $10.0/mo $0.0149/hr; 1-Year: $9.0/mo $0.0134/hr; 3-Year: $8.0/mo $0.0119/hr | On-Demand: $16.5/mo $0.0246/hr; 1-Year: $15.5/mo $0.0231/hr; 3-Year: $15.5/mo $0.0231/hr | | General Purpose | G3.4GB | 4GB | 2 | 80GB | 5 TB | On-Demand: $20.0/mo $0.0298/hr; 1-Year: $18.0/mo $0.0268/hr; 3-Year: $17.0/mo $0.0253/hr | On-Demand: $33.0/mo $0.0491/hr; 1-Year: $31.0/mo $0.0461/hr; 3-Year: $30.0/mo $0.0446/hr | | General Purpose | G3.8GB | 8GB | 4 | 160GB | 6 TB | On-Demand: $40.0/mo $0.0595/hr; 1-Year: $37.0/mo $0.0551/hr; 3-Year: $34.0/mo $0.0506/hr | On-Demand: $66.0/mo $0.0982/hr; 1-Year: $63.0/mo $0.0938/hr; 3-Year: $59.5/mo $0.0885/hr | | General Purpose | G3.16GB | 16GB | 6 | 320GB | 7 TB | On-Demand: $80.0/mo $0.119/hr; 1-Year: $74.0/mo $0.1101/hr; 3-Year: $68.0/mo $0.1012/hr | On-Demand: $132.5/mo $0.1972/hr; 1-Year: $125.5/mo $0.1868/hr; 3-Year: $119.5/mo $0.1778/hr | | General Purpose | G3.32GB | 32GB | 8 | 640GB | 8 TB | On-Demand: $160.0/mo $0.2381/hr; 1-Year: $147.0/mo $0.2188/hr; 3-Year: $136.0/mo $0.2024/hr | On-Demand: $265.0/mo $0.3943/hr; 1-Year: $250.5/mo $0.3728/hr; 3-Year: $238.0/mo $0.3542/hr | | General Purpose | G3.48GB | 48GB | 12 | 960GB | 9 TB | On-Demand: $240.0/mo $0.3571/hr; 1-Year: $220.0/mo $0.3274/hr; 3-Year: $204.0/mo $0.3036/hr | On-Demand: $397.5/mo $0.5915/hr; 1-Year: $375.5/mo $0.5588/hr; 3-Year: $358.5/mo $0.5335/hr | | General Purpose | G3.64GB | 64GB | 16 | 1280GB | 10 TB | On-Demand: $320.0/mo $0.4762/hr; 1-Year: $294.0/mo $0.4375/hr; 3-Year: $272.0/mo $0.4048/hr | On-Demand: $529.5/mo $0.7879/hr; 1-Year: $500.5/mo $0.7448/hr; 3-Year: $477.0/mo $0.7098/hr | | General Purpose | G3.96GB | 96GB | 20 | 1920GB | 11 TB | On-Demand: $480.0/mo $0.7143/hr; 1-Year: $441.6/mo $0.6571/hr; 3-Year: $408.0/mo $0.6071/hr | On-Demand: $795.5/mo $1.1838/hr; 1-Year: $754.5/mo $1.1228/hr; 3-Year: $718.5/mo $1.0692/hr | | General Purpose | G3.128GB | 128GB | 24 | 2560GB | 12 TB | On-Demand: $640.0/mo $0.9524/hr; 1-Year: $589.0/mo $0.8765/hr; 3-Year: $544.0/mo $0.8095/hr | On-Demand: $1,059.0/mo $1.5759/hr; 1-Year: $1,003.0/mo $1.4926/hr; 3-Year: $953.0/mo $1.4182/hr | | General Purpose | G3.192GB | 192GB | 32 | 3840GB | 13 TB | On-Demand: $960.0/mo $1.4286/hr; 1-Year: $883.2/mo $1.3143/hr; 3-Year: $816.0/mo $1.2143/hr | On-Demand: $1,588.5/mo $2.3638/hr; 1-Year: $1,506.5/mo $2.2418/hr; 3-Year: $1,435.5/mo $2.1362/hr | | Compute Optimized | C2.8GB | 8GB | 4 | 40GB | 10 TB | On-Demand: $211.0/mo $0.314/hr; 1-Year: $137.0/mo $0.2039/hr; 3-Year: $67.0/mo $0.0997/hr | On-Demand: $254.5/mo $0.3787/hr; 1-Year: $173.0/mo $0.2574/hr; 3-Year: $96.0/mo $0.1429/hr | | Compute Optimized | C2.16GB | 16GB | 8 | 80GB | 10 TB | On-Demand: $418.0/mo $0.622/hr; 1-Year: $271.0/mo $0.4033/hr; 3-Year: $133.0/mo $0.1979/hr | On-Demand: $505.5/mo $0.7522/hr; 1-Year: $343.0/mo $0.5104/hr; 3-Year: $190.5/mo $0.2835/hr | | Compute Optimized | C2.32GB | 32GB | 16 | 160GB | 10 TB | On-Demand: $828.0/mo $1.2321/hr; 1-Year: $538.0/mo $0.8006/hr; 3-Year: $263.0/mo $0.3914/hr | On-Demand: $1,002.0/mo $1.4911/hr; 1-Year: $682.0/mo $1.0149/hr; 3-Year: $378.0/mo $0.5625/hr | | Compute Optimized | C2.64GB | 64GB | 20 | 350GB | 10 TB | On-Demand: $1,451.0/mo $2.1592/hr; 1-Year: $943.0/mo $1.4033/hr; 3-Year: $461.0/mo $0.686/hr | On-Demand: $1,777.5/mo $2.6451/hr; 1-Year: $1,216.5/mo $1.8103/hr; 3-Year: $685.0/mo $1.0194/hr | | Storage Optimized | S2.16GB | 16GB | 2 | 500GB | 10 TB | On-Demand: $248.0/mo $0.369/hr; 1-Year: $161.0/mo $0.2396/hr; 3-Year: $105.0/mo $0.1563/hr | On-Demand: $317.5/mo $0.4725/hr; 1-Year: $221.5/mo $0.3296/hr; 3-Year: $160.0/mo $0.2381/hr | | Storage Optimized | S2.32GB | 32GB | 4 | 1TB | 10 TB | On-Demand: $425.0/mo $0.6324/hr; 1-Year: $276.0/mo $0.4107/hr; 3-Year: $180.0/mo $0.2679/hr | On-Demand: $557.0/mo $0.8289/hr; 1-Year: $392.5/mo $0.5841/hr; 3-Year: $286.5/mo $0.4263/hr | | Storage Optimized | S2.64GB | 64GB | 8 | 2TB | 10 TB | On-Demand: $778.0/mo $1.1577/hr; 1-Year: $506.0/mo $0.753/hr; 3-Year: $330.0/mo $0.4911/hr | On-Demand: $1,035.0/mo $1.5402/hr; 1-Year: $734.5/mo $1.093/hr; 3-Year: $540.5/mo $0.8043/hr | | Storage Optimized | S2.96GB | 96GB | 12 | 3TB | 10 TB | On-Demand: $1,097.0/mo $1.6324/hr; 1-Year: $713.0/mo $1.061/hr; 3-Year: $465.0/mo $0.692/hr | On-Demand: $1,475.0/mo $2.1949/hr; 1-Year: $1,051.5/mo $1.5647/hr; 3-Year: $777.5/mo $1.157/hr | | Storage Optimized | S2.128GB | 128GB | 16 | 4TB | 10 TB | On-Demand: $1,414.0/mo $2.1042/hr; 1-Year: $919.0/mo $1.3676/hr; 3-Year: $599.0/mo $0.8914/hr | On-Demand: $1,913.0/mo $2.8467/hr; 1-Year: $1,367.0/mo $2.0342/hr; 3-Year: $1,013.5/mo $1.5082/hr | | Memory Optimized | M2.16GB | 16GB | 2 | 40GB | 10 TB | On-Demand: $163.0/mo $0.2426/hr; 1-Year: $106.0/mo $0.1577/hr; 3-Year: $52.0/mo $0.0774/hr | On-Demand: $223.5/mo $0.3326/hr; 1-Year: $161.0/mo $0.2396/hr; 3-Year: $101.5/mo $0.151/hr | | Memory Optimized | M2.32GB | 32GB | 4 | 80GB | 10 TB | On-Demand: $318.0/mo $0.4732/hr; 1-Year: $207.0/mo $0.308/hr; 3-Year: $101.0/mo $0.1503/hr | On-Demand: $439.0/mo $0.6533/hr; 1-Year: $316.5/mo $0.471/hr; 3-Year: $200.0/mo $0.2976/hr | | Memory Optimized | M2.64GB | 64GB | 8 | 160GB | 10 TB | On-Demand: $630.0/mo $0.9375/hr; 1-Year: $409.0/mo $0.6086/hr; 3-Year: $200.0/mo $0.2976/hr | On-Demand: $871.5/mo $1.2969/hr; 1-Year: $627.5/mo $0.9338/hr; 3-Year: $397.5/mo $0.5915/hr | | Memory Optimized | M2.128GB | 128GB | 16 | 350GB | 10 TB | On-Demand: $1,246.0/mo $1.8542/hr; 1-Year: $810.0/mo $1.2054/hr; 3-Year: $396.0/mo $0.5893/hr | On-Demand: $1,727.5/mo $2.5707/hr; 1-Year: $1,246.5/mo $1.8549/hr; 3-Year: $790.0/mo $1.1756/hr | *All plans are available in every location for Managed Server clients. *The hourly rate is determined by dividing the monthly rate by 672 hours (28 days). If your server is online for more than 672 hours in a calendar month, you will only be billed the monthly rate. *Prices listed above are based on the service being utilized for the period specified. *All Servers include one IPv4 Address. Additional IPs are available for $3.65/month ($0.005431/hour) *Unlimited inbound bandwidth. If free outbound bandwidth is exceeded, each additional GB is $0.02 *Optional Daily Backups are available for 20% of the server price. Minimum $1.00/month. *cPanel licensing cost starts at $23 per month ## Why Choose Atlantic.Net as Your VPS Hosting Provider? Atlantic.Net has been providing top-notch hosting and VPS solutions for over 32 years. Our cloud hosting environment is built upon a platform that uses the latest hardware and virtualization technology. The result is a high-performance hosting server environment that outperforms the competition. We offer easy-to-use, fast, cost-effective VPS web hosting services. Our packages and plans are based upon your growing needs and can be scaled up depending upon your business requirements. Every VPS Hosting Plan is offered with the option of on-demand or term discount to help you enjoy significant cost savings. Our hourly plans are designed to give you the best of all worlds, with the ability to deploy servers cost-effectively at an hourly rate, all while giving you the option to lock into cost savings with a plan of your liking through a term discount. Whether you prefer self-management and want to engage us for unmanaged VPS hosting services or opt for our array of managed VPS hosting offerings, Atlantic.Net is the ideal VPS hosting provider and platform to power your hosting needs. ## USA VPS Hosting Atlantic.Net has been headquartered in the USA since inception in 1994 and takes pride in providing VPS hosting from five USA regions. Atlantic.Net provides 100% USA-based support with VPS hosting regions in New York, Dallas, Ashburn, San Francisco, and Orlando. ## Top VPS Hosting Features Every Atlantic.Net Cloud VPS features enhanced scalability options, guaranteed server resources, and enterprise-grade RAID-10 protected SSD storage as standard. Choose Atlantic.Net for your Cloud VPS and benefit from these features: ### Full Root Access Root access is essential for the everyday management of virtual machines, which is why our VPS hosting puts the power to manage your server in your hands with full root access. Unlike most VPS hosts who may not provide root access, with Atlantic.Net you get Full Root Access to the operating systems for easy virtual server management and VPS configuration. ### User-Friendly Control Panel Simplify server administration with the intuitive and user-friendly Atlantic.Net VPS Control Panel. If you're not already familiar with web hosting control panels, you can create and manage your private servers, storage, snapshots, backups, networking, and much more with a few simple clicks. ### Dedicated IP Address A static, dedicated IP address with IPv4 and IPv6 support enables you to publish from your server with ease. Every server includes one dedicated IPv4 address with additional IPv4 addresses available. You can add 16 IPv6 addresses to your Cloud VPS at no additional cost in all Atlantic.Net Cloud locations. ### Complete Customization Host unlimited domains, create unlimited email addresses, create advanced web servers, or deploy a system-critical database. The Atlantic.Net Cloud gives you the flexibility to choose your operating system, content management system (like WordPress), server control panels like cPanel, applications, and much more! ### Scale as You Go Need more CPU power, disk space, or memory for your Cloud VPS? No problem! Simple scalability options allow you to start with the resources you need today and scale up as needed in the future with a simple click in the control panel or call to our API. ## VPS Hosting in the Cloud Made Easy! Atlantic.Net’s Cloud provides an easy-to-use control panel and API that puts you in complete control of your Cloud VPS. Atlantic.Net has an extensive list of One-Click Apps and Windows, Linux, and FreeBSD Operating Systems to choose from. Whether you need a VPS in the USA, Canada, the UK, or Asia, our cloud VPS can be turned up in less than 30 seconds. Need help deciding on the best solution to meet your needs? Our helpful advisors are available to discuss your requirements and help you make the right choice. Our USA-based support team stands ready to provide phone support 24 hours a day and seven days a week; this is one more way we make VPS Hosting in the cloud easy. ## Linux VPS Hosting in the Cloud Take the complexity out of your server setup by deploying your own Linux virtual private server in the Atlantic.Net Cloud. The Atlantic.Net control panel offers multiple flavors of Linux and FreeBSD to fulfill all your requirements, with new operating system instance types being added frequently. Unsure how to manage Linux-based operating systems or FreeBSD operating systems? Check out our technical tutorials. ## Linux VPS Pricing Plans Everything you need is included in our monthly Linux VPS pricing plans. - Ubuntu 16.04 LTS Server 32-Bit - Ubuntu 16.04 LTS Server 64-Bit - Ubuntu 18.04 LTS Server 64-Bit - Ubuntu 20.04 LTS Server 64-Bit - Ubuntu 22.04 LTS Server 64-bit - Ubuntu 24.04 LTS Server 64-bit - Debian 11.11.0 Server 64-Bit - Debian 12.11.0 Server 64-bit - Debian 13.0.0 Server 64-bit - Oracle Linux 7.9 64-bit - Oracle Linux 8.10 64-bit - Oracle Linux 9.6 64-bit - Oracle Linux 10.0 64-bit - Rocky Linux 8.10 64-bit - Rocky Linux 9.6 64-bit - Rocky Linux 10.0 64-bit - CentOS 6.9 Server 32-Bit - CentOS 6.9 Server 64-Bit - CentOS 7.9 Server 64-Bit - CentOS 8.2 Server 64-Bit - Fedora 42 Server 64-Bit - FreeBSD 13.0 Server 64-Bit - Arch Linux Server 64-Bit - AlmaLinux 8.10 64-bit - AlmaLinux 9.6 64-bit - AlmaLinux 10.0 64-bit - cPanel/WHM on AlmaLinux 64-bit ## Windows VPS Hosting in the Cloud Microsoft Windows Server is still one of the most popular operating systems around the world. Atlantic.Net takes the hassle out of deploying a Windows Server. We provide Windows VPS hosting that automatically takes care of the operating system licensing, activation, and deployment for you. All you need to do is choose which version of Windows Server you want. - Windows Server 2025 Datacenter (Desktop Experience) - Windows Server 2025 Datacenter - Windows Server 2022 Datacenter (Desktop Experience) - Windows Server 2022 Datacenter - Windows Server 2019 Datacenter (Desktop Experience) - Windows Server 2019 Datacenter - Windows Server 2016 Datacenter (with Containers/Docker) - Windows Server 2016 Datacenter - Windows Server 2012 R2 Datacenter (Desktop Experience) - Windows Server 2012 R2 Datacenter - Windows Server 2008 R2 SP1 Datacenter ## Bring Your Own Operating System and License Atlantic.Net not only provides your favorite Windows, Linux, and FreeBSD distributions, but you can also bring your own operating system or application along with your own license to the Atlantic.Net Cloud by using the Custom ISO feature! ### Automated Backups Backups are a powerful way to protect and restore your data. Backups can be scheduled daily or more frequently to ensure you have the coverage you need. Recovery is easy. You can choose to recover individual files or restore your entire Cloud VPS with a simple click or API call. ### 100% Uptime SLA Our highly redundant architecture ensures that your VPS hosting services stay up and running even when components misbehave. Backed by our 100% up-time SLA, Atlantic.Net guarantees that all critical infrastructure components will be available 100% of the time in a given month (excluding scheduled maintenance) or we will provide you with a credit for the impacted services. ### Secure Block Storage Attach a secure block storage volume to your virtual private server in just a few clicks. Choose from 50GB to 16TB per volume and attach up to 8 volumes per server. ### RESTful API Provision, manage and scale your resources easily using Atlantic.Net's easy-to-use RESTful Application Program Interface. ### On-Demand VPS Hosting at the Right Price We know that cost is of utmost importance to our customers, which is why we give the option to only pay for what you need. With our pay-as-you-go model, you can consume as much or as little resources as you need. Turn up, scale, and turn down workloads anytime, or receive a significant discount on your VPS hosting by selecting a term period for your services to run. ### Dedicated Resources Atlantic.Net VPS server performance is off the charts, and you get dedicated bandwidth, memory, CPU power, and storage IO for each Cloud VPS you deploy. ### Snapshots Running out of resources? Not a problem; live migrate to a larger host with no downtime! The dedicated hosting platform scales as your business grows, start with a relatively small dedicated host safe in the knowledge that you can upgrade your plan whenever you choose. Enjoy the freedom of being able to migrate dedicated instances or launch instances live between the hosts. ## A Support Team Backed by Decades of Experience With over three decades of experience, our support team is always here to assist you. You’ll have 24/7/365 access to a crop of dedicated veterans, capable of solving any technical problem you throw their way. ## One-Click Cloud VPS Hosting Apps Did you know that with the Atlantic.Net control panel or API, you can launch a range of 1-Click Apps in under 30 seconds? These Apps are built upon a patched and secure Operating System, and each App is configured to industry standards by our team of engineers. Each App is updated regularly to incorporate important features and security updates. ### LAMP/LEMP Stack Deploy an Apache or Nginx based application stack in under 30 seconds. These apps come with MySQL and PHP pre-configured, are patched with security updates, and offer full root access. ### WordPress WordPress is the world's most popular content management system (CMS). It empowers you to create rich content websites and blogs, literally within minutes. Each 1-Click App is updated, patched, and secured to Atlantic.Net exacting standards and comes with full root access. ### MySQL MySQL is the most popular database choice. It’s perfect for production workloads, easy to manage, offers great security, is incredibly reliable, and a fully-featured community edition is completely free. ### NextCloud Need your own highly secured and private Cloud Storage and collaboration solution? NextCloud is the answer. It's secure, quick, and can sync with any of your devices. Our 1-Click App is patched, security-hardened, and comes with full root access. ### cPanel/WHM cPanel and WHM web hosting control panel options are simple point-and-click web hosting that provides the tools for super simple VPS web hosting. You can create unlimited email accounts, unlimited domains, and unlimited websites. cPanel is the most powerful web hosting control panel on the market, which can be added to any of our VPS hosting plans starting at $18 per month. ### Docker Docker lets you containerize practically any server or application image, then run it nested on a Virtual Server. Best of all, it uses a tiny amount of resources. This gives you the flexibility to have multiple applications running in containers on one or more servers. An Atlantic.Net VPS will crush Docker workloads, even on a lower spec VPS hosting plan, and each 1-Click app is patched, security-hardened and comes with full root access. ### Node.js Node is a favorite with web developers due to it being fast, scalable, and great for data-intensive web host applications. Take the complexity away of creating your own Node.js server and deploy the pre-configured Atlantic.Net NodeJS 1-click App, patched, security-hardened, and with full root access. ### mesibo mesibo offers a comprehensive solution for in-app messaging, calls, conferencing, and chatbot functionalities. With its robust end-to-end encryption protocol, mesibo ensures the highest level of security for communication. The one-click messaging application hosted on the Atlantic.Net cloud, enables customers to set up communication services, like messaging, calls, and conferencing, in under 30 seconds. ## Point, Click, Deploy VPS – It’s That Easy! Instantly create, deploy, and manage your Linux and Windows infrastructure from the Atlantic.Net Cloud control panel. This control panel gives you the ability to deploy as many virtual private servers as you need with a couple of clicks of your mouse. All our virtual private server instances self-configure and will deploy into the high-performing Atlantic.Net data center of your choice. ## VPS Hosting FAQs ### How much does VPS hosting cost? Typically, a VPS web hosting account with Atlantic.Net is billed hourly, and you only pay for what you use. Plans start at $10 per month billed hourly and scale up to hundreds of dollars, depending upon your specific requirements. Generally, VPS hosting is cheaper than dedicated server hosting. ### Is VPS better than VPN? VPS and VPN are completely different services, but VPS offers much more than a VPN. You can provision a VPS server and set up a VPN using it, which you might say makes VPS a better service than a VPN. ### Is a Virtual Private Server or Dedicated Server Hosting right for me? In general, if you only have the need for a few VPS servers and you don’t see your workload continuing to grow, a Cloud VPS server is a great, and cost-effective solution that will most likely meet your needs. That being said, you may still want to take advantage of the added benefits that come with a Dedicated Host. Dedicated Hosts are private computing nodes that are fully dedicated to a single customer's use with no shared resources or noisy neighbors, which can occur with shared hosting plans. This service is ideal for any customer that has a growing need for security, compliance, or a powerful infrastructure, or for a customer looking for the flexibility and cost-effectiveness that comes with having their own physical server or dedicated server computing infrastructure. ### Why do Windows Virtual Private Servers cost more than Linux VPS? All of the Linux Distributions we feature on the Atlantic.Net Cloud have zero licensing costs. The Linux operating system fosters an open-source community, and you will find an abundance of enterprise-grade applications available online that are completely free to use. However, Microsoft charges a license fee for each Windows Server instance. As your web hosting provider, we take care of the web server licensing process for you and the amount you are billed each month includes the licensing fee. We provide multiple versions of Microsoft Windows Server – including Windows Server 2025, 2022, 2019, 2016, 2012 R2, and 2008 R2 SP1 – in Datacenter and Standard editions, with and without Desktop Experience. ### What is the difference between a Cloud VPS and a Dedicated Server? A Cloud VPS is a virtual server hosted on a shared platform with guaranteed system resources (CPU, Disk Space, and Memory). A dedicated host is a physical dedicated server or physical servers that are dedicated to a single user, and the user has all the resources on the server. The Atlantic.Net Cloud VPS service offers both VPS and dedicated hosts within the same environment, so you get all the perks on either platform. The workload of a VPS server varies from running websites, workstations, or general-purpose servers. A dedicated host is usually used for hosting a significant number of websites or apps, intensive workloads, large numbers of VPS, or large production databases. Whether you choose a VPS in our Public Cloud or to deploy VPS on your Dedicated Hosts, any Cloud VPS will be available in a matter of seconds after being deployed. If you are interested in learning more about our dedicated hosts and if they are right for you, please [contact one of our helpful advisors](https://cloud.atlantic.net/?page=signup). ### In which regions can I get Atlantic.Net Virtual Private Server (VPS) Hosting? Our cloud platform VPS hosting plan is available in all our Atlantic.Net data centers. United States of America VPS Hosting: Cloud VPS hosting in the USA is served by our Orlando, New York, Dallas, San Francisco, and Ashburn region data centers. Canada VPS Hosting: Cloud VPS hosting in Canada is served by our Toronto region data center. UK VPS Hosting: Cloud VPS hosting in the UK is served by our London region data center. Asia VPS Hosting: Cloud VPS hosting in Asia is served by our Singapore region data center. Europe VPS Hosting: Cloud VPS hosting in Europe will be served by our upcoming Amsterdam region data center. ### Why should I choose Virtual Private Server (VPS) from Atlantic.Net? VPS hosting is best defined as a hosting solution that offers the affordability of shared hosting with the power and performance of dedicated hosting. To recap, shared hosting is when your server shares unreserved resources on a host. Dedicated hosting is exactly the opposite; your dedicated server is reserved solely for you and has 100% access to all resources on the host. A VPS hosting service strikes a great balance between a shared hosting environment and dedicated hosting services, as you get the benefits of having guaranteed resources on a host despite sharing the physical server with other clients. For example, if your VPS comes with 200 GB of storage, you get 200 GB of storage to use exclusively. If your VPS comes with 64 GB of memory, no other VPS can use that memory. The resources are always there, no matter what. Virtual private server hosting also offers the cost benefits of shared hosting, as VPS hosting is only a small percentage more expensive than shared hosting but is usually significantly cheaper than dedicated hosting. ### Should I consider going with a cheap VPS company instead? Many businesses search for cheap VPS hosting to save on overhead costs and maximize profit. However, remember that just as you want to keep costs low and maximize profit, your VPS host is not an exception. One area where some lower-quality hosting providers try to cut corners is on their data center infrastructure. For example, a cheap VPS host may not see the need to maintain a redundant network because they do not see it as critical to day-to-day operations. However, without a highly redundant, secure, and well-connected network infrastructure, your website could experience downtime, lags, and not function properly. Another major problem when using low-quality or cheap VPS hosts is that they may oversell VPS platforms, making one physical host machine run too many customers, causing server crashes and/or poor server performance. These hosting providers depend on the unlikelihood of every VPS account using their full resource allocation all at once. However, if performance demands meet the server’s capacity, your website and applications will be reduced to a slow, unresponsive mess. Always research VPS hosting providers to ensure their service quality is up to your standards. ## See Additional Guides on Key Compliance Management Topics Together with our content partners, we have authored in-depth guides on several other topics that can also be useful as you explore the world of compliance management. ### [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) Authored by Atlantic.Net - [[Guide] HIPAA-Compliant Hosting | 2025 Award Winning HIPAA Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) - [[Guide] What is Protected Health Information (PHI) in 2025? Atlantic.Net](https://www.atlantic.net/hipaa-compliant-hosting/) - [[Blog] RTLS and Healthcare](https://www.atlantic.net/hipaa-compliant-hosting/rtls-and-healthcare-can-real-time-location-system-security-improve-your-healthcare-operations/) - [[Product] Atlantic.Net HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) ### [What is VPS](https://www.atlantic.net/vps-hosting/what-is-vps-buyers-guide-and-expert-tips/) Authored by Atlantic.Net - [[Guide] Expert Tips for Choosing the Best VPS Hosting Provider](https://www.atlantic.net/vps-hosting/what-is-vps-buyers-guide-and-expert-tips/) - [[Guide] VPS Hosting vs. Shared Hosting: Which is Right for You?](https://www.atlantic.net/vps-hosting/vps-hosting-vs-shared-hosting-pros-cons-differences-and-expert-tips/) - [[Blog] How Secure is the Cloud?](https://www.atlantic.net/hipaa-compliant-hosting/how-secure-is-the-cloud/) - [[Product] Atlantic.Net Cloud Platform | Scalable, Secure Cloud Solutions](https://www.atlantic.net/cloud-platform/) ### [PCI Compliant Hosting](https://www.atlantic.net/pci-compliant-hosting/) Authored by Atlantic.Net - [[Guide] PCI Hosting Solutions](https://www.atlantic.net/pci-compliant-hosting/) - [[Guide] PCI DSS Cybersecurity Requirements: A Practical Guide](https://www.atlantic.net/pci-compliant-hosting/what-is-pci-compliance/) - [[Blog] How to Reduce Your PCI Scope When Accepting Payments](https://www.atlantic.net/pci-compliant-hosting/reduce-pci-scope-accepting-payments/) ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." --- # Cloud Backups > URL: https://www.atlantic.net/cloud-platform/backups/ | Updated: 2026-09-16 Protect critical workloads with automated snapshot schedules, file-level recovery, full-system restore, off-site copies, and replication options aligned to your RPO and RTO goals. - 5-Minute Backup Option - File-Level Recovery Included - Full-System Restore Included - Off-Site Copies Available Fastest Schedule: 5 Min Recovery Scope: File + Full ## Cloud Backups Data is the lifeblood of modern businesses, and safeguarding it has never been more important. Cloud backups offer a technical solution for protecting critical data from unexpected events like hardware failures. Modern backup solutions use the cloud's scalability and accessibility to ensure data remains secure and readily available for recovery, minimizing downtime and potential losses. Backups are an essential part of everyday IT operations. Atlantic.Net offers class-leading backup and replication services to a wide range of clients. Using our cloud infrastructure, our managed backups are fast, robust, and fault-tolerant – with proven reliability and near-zero resource overhead. Automated schedules and seamless integration with existing systems let businesses maintain up-to-date backups without disrupting operations – enhancing data protection, optimizing IT resources, and reducing operational costs. ## What Are Cloud Backups? Cloud backups involve creating copies of data and storing them securely on a disk-based remote server, accessible via the internet. The backups serve as a safety net, letting businesses restore information to a previous point in time in case of data loss or corruption. Unlike traditional backups that rely on physical media, cloud backups offer enhanced scalability, accessibility, and cost-effectiveness. For additional protection, backups can be copied to multiple locations to add redundancy in the event of a catastrophic failure. ## Backup Frequency These frequencies enable our service to meet and exceed stringent Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO). The result is an agile, quick response to any urgent recovery scenario. Our backup technology is highly configurable, and the snapshot-based backup runs automatically on a predefined schedule. The standard service offering is set at: - 5 Minutes – recommended for priority-one servers - 15 Minutes – recommended for business-critical systems - Hourly – commonly used for file servers or application servers - Daily – for low-priority servers such as workstations or terminals ### File-Level Recovery File-level recovery is included with all of our cloud server backups at no additional cost. It lets you recover individual files from a selected backup instead of restoring the full system from a point-in-time backup. ### Full System Restore Full system restore is included with all of our cloud server backups at no additional cost. Restore your entire Cloud Server to the point-in-time of the selected backup with the click of a button. ### Off-Site Backups Off-site snapshot backups are available at all of Atlantic.Net's data center locations. Choose which off-site location your data is transferred to and stored within. Transferring backups off-site creates a number of advantages: it allows for disaster recovery in unforeseen circumstances. If your systems are struck by a disaster, the data can be rapidly redeployed in a disaster recovery service – meeting and usually exceeding your RTO and RPO requirements. ### Replication Atlantic.Net offers snapshot replication services that take your disaster recovery plan to the next level. Our cloud platform snapshot replication service replicates your cloud VPS to one or more failover computing nodes so you can recover quickly in the event of unforeseen issues. Nodes can be in the same data center or in another remote data center location. This flexibility offers a unique high-availability scenario. The frequency at which snapshot replication refreshes the data is configured to the same standards as our snapshot backups. ## Achieving Mission-Critical Business Objectives with Cloud Backups Cloud backups play a pivotal role in meeting mission-critical business objectives. By safeguarding data against loss and corruption, cloud backups ensure business continuity, minimizing downtime and financial repercussions. The ability to quickly restore data to a previous state lets organizations recover from disruptions seamlessly – maintaining productivity and customer satisfaction. ## RPO and RTO and Their Benefits to Businesses Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss in the event of a disruption; Recovery Time Objective (RTO) outlines the targeted timeframe for restoring operations. Cloud backups let businesses fine-tune RPO and RTO, aligning them with their specific needs. Minimizing data loss and downtime safeguards revenue streams, preserves brand reputation, and supports compliance with regulatory requirements. ## How Atlantic.Net Cloud Helps Hit Your RPO and RTO Targets Atlantic.Net Cloud lets businesses optimize their RPO and RTO through flexible, customizable backup solutions. With frequent backups and rapid restoration, we help you recover quickly and minimize disruptions. By tailoring backup frequencies and storage locations, you strike the right balance between data protection and cost-efficiency, aligning the backup strategy with your business goals. Ready to enhance your data protection strategy and achieve peace of mind? Contact Atlantic.Net today, and let our experts help you create a cloud backup solution that ensures seamless backup and recovery for your business. ## Frequently Asked Questions About Cloud Backups ### What's the difference between RPO and RTO? RPO (Recovery Point Objective) is the maximum acceptable amount of data loss measured in time – how far back the recovered data can be from the moment of failure. RTO (Recovery Time Objective) is the maximum acceptable downtime between an outage and the application being available again. Backup frequency drives RPO; the recovery architecture (warm standby, hot failover, cold restore) drives RTO. ### How frequent can backups be? Atlantic.Net's standard offering supports four tiers: 5-minute (for priority-one servers), 15-minute (business-critical systems), hourly (file/app servers), and daily (workstations and terminals). All run on a predefined snapshot schedule with near-zero resource overhead. ### What restore options are available? File-level recovery (restore individual files from any backup point) and full system restore (one-click point-in-time restore of the entire Cloud Server) are both included with all cloud server backups at no additional cost. ### How does off-site backup work? Off-site snapshot backups are available across Atlantic.Net's eight global data center locations. You choose the destination region for your off-site copy – useful for satisfying the 3-2-1 backup rule and for accelerating disaster recovery if your primary region is disrupted. ### What's the difference between backup and replication? Backup creates point-in-time copies you can roll back to. Replication keeps a near-live mirror of a workload on one or more failover nodes, so when the primary fails the secondary can take over quickly. Atlantic.Net offers both, and most production environments use them together: replication for fast failover, backup for point-in-time rollback or compliance retention. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Secure Block Storage (SBS) > URL: https://www.atlantic.net/cloud-platform/block-storage/ | Updated: 2026-09-16 Attach encrypted, NVMe-based block storage to your Atlantic.Net Cloud Server, scale volumes from 10 GB to 16 TB without downtime on supported operating systems, and move storage between servers within the same region. - 100% NVMe SSD - 10 GB to 16 TB Volumes - Encryption at Rest - Isolated Storage Network Max Volumes per Server: 15 Max Burst IOPS: 10,000 ## Secure Block Storage (SBS) Atlantic.Net's Block Storage volumes allow you to easily attach additional storage to your Atlantic.Net Cloud Servers. You can use Secure Block Storage (SBS) for your file, database, application, and backup storage needs. Designed for 100% availability, Secure Block Storage (SBS) is automatically replicated multiple times to protect your data from component failure. You can increase storage on-the-fly and move your SBS between your Cloud Servers within the same region. SBS Specifications: - Pure NVMe based Block Storage - Volume Size: 10 GB to 16 TB - Max volumes per server: 15 - Max IOPS per volume: 7,500 - Max burst IOPS per volume: 10,000 - Max throughput per volume: 300 MB/s - Max burst throughput per volume: 450 MB/s - All-inclusive pricing: 10 cents per GB per month. ## Need a Scalable & Customized Storage Solution? We Can Provide Custom Plans. ### High Performance Designed with 100% NVMe SSD drive, SBS is designed to meet the needs of your demanding high throughput and IOPs based workloads. ### High Availability Designed for 99.999% availability, Secure Block Storage (SBS) volumes are automatically replicated multiple times across a redundant and highly available cluster of storage servers to protect your data from component failure. ### Flexible Add, attach, detach, and move your SBS between your Cloud Servers in the same region for the perfect mix of compute and storage for your files, databases, applications, and backups. ### Scalable Increase cloud block storage space by dynamically scaling each of your Secure Block Storage (SBS) up to 16TB. ### Secure Secure Block Storage (SBS) volumes are automatically encrypted at rest and are connected to your Cloud Server over an isolated storage network. ### Simple Pricing Straight-forward, all-inclusive pricing: 10 cents per GB per month. Volume and term discounts are available. ## Cloud Availability in Multiple Global Regions Deploy close to your users from eight international data centers worldwide, with new regions on the way. ## Secure Block Storage FAQ ### How redundant is SBS? Designed for 99.999% availability, SBS is automatically replicated multiple times across a redundant and highly available cluster of storage servers to protect your data from component failure. ### Can I move my SBS between servers in the same location? Yes, you can move your SBS between your servers in the same location. ### Can I move my SBS between servers in different locations? Not currently, but it is on our roadmap. ### Is there a limit on how many SBS volumes I can connect to my Cloud Server? You can connect up to 15 volumes per Cloud Server. ### Can an SBS be attached to more than one Cloud Server at the same time? No, SBS can only be attached to one server at a time. However, SBS can be used as the backing storage for a shared file system, like NFS, that multiple servers/clients can connect to. ### Will I be able to take on-demand snapshots of my SBS and restore my volume from them? No. However, we plan to offer this feature soon. ### If I pay for backups of my Cloud Server, does that include backups of my attached SBS? No, however we do have backup solutions available through our sales team and plan to roll out on-demand options as well. ### Can I add an SBS on the Add Server page when creating a new Cloud Server? No. However, we plan to offer this feature soon. ### You mentioned that you can scale Volumes with no downtime, but I noticed the asterisks there. Can you please explain? Currently, all of our Cloud Server operating systems, except Windows Server 2016, support live scaling of Block Storage Volumes. This means that for all other Cloud Server operating systems, you can resize your Volume while it is connected to your running server. For Windows Server 2016, you will either have to reboot your Cloud Server or detach and reattach the Volume to get your Cloud Server to recognize the additional space after resizing a volume. This is a limitation of Windows Server 2016. ### Is the storage that backs SBS hard disk (HDD) or solid-state disk-based (SSD)? The storage that backs SBS is 100% NVMe SSD based. This ensures you can take advantage of the amazing speed that comes with NVMe SSDs. NVMe, if you are not familiar, stands for non-volatile memory express and is the successor to the SATA drive interface. It allows SSDs to transfer data directly over the server's PCIe bus instead of going over the much slower SATA interface. ### What are the specs of SBS? Pure NVMe based Block Storage; Volume Size: 10 GB to 16 TB; Max volumes per server: 15; Max IOPS per volume: 7,500; Max burst IOPS per volume: 10,000; Max throughput per volume: 300 MB/s; Max burst throughput per volume: 450 MB/s; All-inclusive pricing: 10 cents per GB per month. ### Is SBS encrypted? Yes, every SBS is automatically encrypted at rest using LUKS encryption and is connected to your Cloud Server over an isolated storage network to ensure a secure environment for customer data. ### What is the minimum increment when scaling the capacity of SBS? The minimum scaling increment is 10 GB. ### How does SBS compare to a SAN? A SAN is typically defined as a dedicated storage area network that provides direct access to block-level storage devices with a finite amount of capacity and performance. SBS offers block storage as well, with clear advantages over a SAN in that SBS provides easily scalable capacity, performance, and redundancy coupled with no management costs. ### How does SBS compare to a NAS? A NAS is typically defined as network-attached storage that provides a shared file system, such as NFS, that multiple servers can connect to at the same time. In contrast, SBS is a block-level device that can only be directly attached to one server at a time but provides more flexibility. For example, SBS can be used to provide additional storage capacity for a Cloud Server or can be used as the backing storage for a shared file system, like NFS, that multiple clients can connect to. ### Do you plan to offer SBS at additional locations? Yes, we plan to offer SBS at our other Cloud locations. Currently, SBS is available in our USA-EAST-1 (Orlando, FL) location. Details regarding the launch of SBS at additional locations will be released in the coming months. ## Read More About Block Storage ### [What Is Block Storage?](https://www.atlantic.net/vps-hosting/what-is-block-storage/) - [What Is Block Storage?](https://www.atlantic.net/vps-hosting/what-is-block-storage/) - [Pros and Cons of Offsite and Onsite Data Storage](https://www.atlantic.net/hipaa-compliant-hosting/pros-and-cons-of-onsite-and-offsite-data-storage/) ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Virtual Private Cloud > URL: https://www.atlantic.net/cloud-platform/virtual-private-cloud/ | Updated: 2026-09-16 Run cloud resources inside a 100% logically separated virtual network with managed firewall, VPN, private and BGP routing, plus the redundancy, performance, and scalability of the Atlantic.Net Cloud. - 100% Logical Isolation - Managed Firewall & VPN - Private & BGP Routing - HIPAA, PCI, SOC & NIST Network Isolation: 100% Logical Firewall Default: All Ports Closed ## Secure Virtual Private Cloud Atlantic.Net Virtual Private Cloud (VPC) enables you to have complete logical isolation on a virtual network using the Atlantic.Net Cloud. VPC is like a physical network that you would see in a data center; however, it completely resides on Atlantic.Net's Cloud services and is 100% logically separated from other VPCs in the Atlantic.Net Cloud. This allows you to have a secure and compliant network, as with a dedicated host, while adding all the features of cloud-like scalability. ## What Is Virtual Private Cloud? A virtual private cloud (VPC) is a logically isolated section of a public cloud, providing a secure and private environment for organizations to launch and manage cloud resources with enhanced control over network configuration and security. ## Atlantic.Net VPC Benefits ### Security and Compliance By logically segmenting your network from all other networks in the Atlantic.Net Cloud, Atlantic.Net VPC helps secure your environment for today's unique compliance requirements, such as HIPAA, HITECH, PCI, SOC, NIST, etc. ### Managed Atlantic.Net completely manages your VPC network and builds it to fit the model you require. Our Security Operations Center (SOC) team works extensively with you and your team to determine the proper setup for your environment while making sure it fits with your organization's compliance needs. ### In the Atlantic.Net Cloud Atlantic.Net VPC allows you to keep all the redundancy, performance, and scalability of the Atlantic.Net Cloud while adding the security to pass and exceed the compliance standards your organization must adhere to. ## Atlantic.Net VPC Features ### Firewall Restrict access to your servers with the Atlantic.Net Managed Firewall. ### VPN Securely connect to your Atlantic.Net VPC on a smartphone, computer, office, etc. via Atlantic.Net's VPN. ### Intrusion Detection Service Atlantic.Net's Intrusion Detection Service analyzes network traffic flows and blocks the malicious security threats from coming into your VPC. ### Logging Atlantic.Net captures network traffic going in and out of your VPC and integrates this into an easy-to-read report. ### Load Balance Distribute incoming traffic load across multiple Atlantic.Net servers for improved performance and redundancy. ### BGP Routing Enable Border Gateway Protocol (BGP) to your VPN and route your own IP ranges to Atlantic.Net's Cloud infrastructure. ### Private Routing Connect between other cloud servers without the need for an external IP address. ### VPC to VPC Connect your VPC network across other projects or even other companies (upon request) with secure VPN tunnels. ## Use Cases We can easily customize the network configurations on your Atlantic.Net VPC. Below are some popular use cases with VPC; however, Atlantic.Net VPC is not limited to this. Please consult your Atlantic.Net sales representative to consult on all available options. ## Atlantic.Net VPC with Managed Firewall In this scenario, the Firewall NATs a public IP address to the private IP address on the server. By default, all ports on the firewall are closed. To open a port, a request needs to be made to our SOC team detailing the specific port to open. For example, you may be running a web server, and you would need to open port 443 to allow HTTPS traffic to flow through. ## Atlantic.Net VPC with VPN and NAT In this scenario, we have the same functionality as the VPC with the Atlantic.Net Managed Firewall, but with the addition of a secure virtual private network (VPN) from your network. This gives your company's system admins, developers, and other authorized personnel a secure way of accessing the environment. Atlantic.Net uses IPsec and OpenVPN to connect, and we can connect our firewall to your firewall or our firewall to your device. Public IPs still NAT to private IPs, and ports can still be opened and closed. ## Atlantic.Net VPC with VPN without NAT Like Atlantic.Net's VPC with VPN and NAT, we can create a secure tunnel from your corporate network to the Atlantic.Net cloud infrastructure. Additionally, we can completely segment off the public network to the cloud servers. This creates a complete extension of your network into the VPC. ## Atlantic.Net VPC with Load Balancing In this scenario, we have added load balancing to the VPC. With load balancing, incoming traffic can be distributed across multiple Atlantic.Net Cloud servers. This creates better performance and additional redundancy. ## Atlantic.Net VPC with Replication In this scenario, we have added replication to another site with VPC for redundancy purposes. This creates a hot copy of your server to a completely different facility. In a disaster event, we can fail everything over from one facility to the next. ## Want to build a scalable and agile cloud infrastructure? Our Virtual Private Cloud empowers your business to grow. Contact us today to explore the benefits of VPC and take your cloud to the next level. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at sales@atlantic.net. ## Virtual Private Cloud FAQ ### How is a VPC different from a public cloud? A public cloud places your workloads on shared multi-tenant network infrastructure. A Virtual Private Cloud carves out a logically isolated network segment that only your organization can route traffic into – same underlying cloud, but private subnets, private routing, and dedicated firewall/VPN policies. ### Which compliance frameworks does Atlantic.Net VPC support? Atlantic.Net VPC is designed to help meet the network-segmentation requirements of HIPAA, HITECH, PCI DSS, SOC 2 / SOC 3, and NIST control families. Final compliance still depends on the workloads and policies you deploy on top of the VPC; our SOC team helps architect the network so it aligns with the framework you're attesting to. ### How do I connect my office network to my VPC? Atlantic.Net builds an IPsec or OpenVPN tunnel between your office firewall and the VPC firewall (firewall-to-firewall) – or, for individual users, a client-to-firewall tunnel from a laptop or phone. Once the tunnel is up, your private subnets are reachable as if they were an extension of your corporate LAN. ### Can I bring my own IP address ranges? Yes. Atlantic.Net supports BGP routing into VPC, so customers with their own ASN and allocated IP space can advertise those prefixes to the Atlantic.Net network and route traffic into the VPC over the BGP session. ### Does VPC support multi-site disaster recovery? Yes. The "VPC with Replication" architecture replicates servers from a primary VPC to a secondary VPC in another Atlantic.Net facility. In a disaster event, traffic can be failed over to the secondary site to keep services online. ### How do I open a port on the VPC managed firewall? All VPC firewall ports are closed by default. To open a port, submit a request to the Atlantic.Net SOC team specifying the port, protocol, and source/destination scope. The SOC team applies the rule and confirms back once it is live. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # VoIP Cloud Servers for Low-Latency Unified Communications > URL: https://www.atlantic.net/voip-cloud-servers/ | Updated: 2026-09-16 Host PBX, SIP trunking, gateways, and conference servers on highly redundant, reliable, secure, and low-latency cloud infrastructure with Windows or Linux flexibility. - Hosted PBX - SIP Trunking - Windows or Linux - Pay-As-You-Go VoIP Technology Experience: 32 Years Cloud Billing: Pay As You Go Atlantic.Net has been heavily involved with VoIP technology throughout its 30-year history. Leading VoIP companies rely on Atlantic.Net to provide highly redundant, reliable, secure, and low latency cloud servers. ### Remote Interoperability To connect a remote worker with a hosted VoIP solution, you simply need a cell phone or laptop and an Internet connection. It’s that simple! An employee can not only connect to personalized call centers, call queuing systems, and team messaging, but also integrate with automated response services and even social media. ### Hosted PBX Keep your costs down by hosting your own PBX (Private Branch Exchange) and benefit from immediate performance on the very latest server hardware. You can add on backups, offsite replication, and snapshots with the click of a mouse. Need to expand? No problem! Each cloud server plan can be upgraded within a few clicks. ### SIP Trunking Connect your phone system to the outside world via your SIP Trunking provider. Install your next telephone system on the Atlantic.Net Cloud Platform and get ready for security-conscious, high-performance cloud infrastructure to underpin your mission-critical phone system. ### Cost-Effective Get timely, accurate monthly billings on all Atlantic.Net solutions. Interested in open-source? Get the fantastic FreePBX, FusionPBX, and Asterisk projects, ideal for businesses looking to keep costs down. You can combine an open-source PBX with the flexible Atlantic.Net pay-as-you-go cloud model to drive costs down substantially, as we bill you only for what you use! ### Easy to Maintain Digital telephone technology has revolutionized the digital workplace, and today, cloud-hosted phone systems can be found in nearly every business. Enhanced voice clarity and agile interoperability will keep your on-premise and remote workforce engaged and impress your clients. ### Flexibility Choose Windows or Linux for the host operating system to build out your Cloud VoIP gateways, Cloud SIP, and conference servers. Onboard a licensed IP PBX system from the many providers out there, then choose a cloud-hosted, dedicated, or colocation server option. ### Connectivity Atlantic.Net has a selection of world-leading network carrier partners. Our high-speed, low-latency network throughput works seamlessly with a softphone, physical VoIP phone, whether over a VPN or the Internet, adding greater flexibility and future-proofing options. ## VoIP Cloud Servers FAQ ### What is a VoIP cloud server? A VoIP cloud server is a telephony server hosted in the cloud, used to make and receive VoIP calls. VoIP, or Voice over IP, is a technology that lets you place phone calls from any device connected to the Internet, desk phone, softphone, mobile, or browser-based client. ### What are the benefits of using VoIP cloud servers? There are many benefits to using VoIP cloud servers, including: Reliability: VoIP cloud servers are hosted in secure data centers and are backed up regularly. This means that you can be confident that your VoIP service will be available when you need it. Security: VoIP cloud servers use the latest security technologies to protect your data and calls. This means that you can be confident that your conversations are private. Low latency: VoIP cloud servers have low latency, which means that there is little or no delay in your calls. This makes for a more natural and enjoyable calling experience. Easy to use and maintain: VoIP cloud servers are easy to use and maintain. You don't need any special hardware or software to use them. Scalability: VoIP cloud servers can be easily scaled up or down to meet your needs. This means that you can always get the right amount of service for your business. ### What features do VoIP cloud servers offer? VoIP cloud servers offer a variety of features, including: Auto attendant: An auto attendant can answer your calls and direct them to the appropriate extension or voicemail box. Call forwarding: Call forwarding allows you to forward your calls to another number, such as your cell phone or another office. Call recording: Call recording allows you to record your calls for training or quality assurance purposes. Voicemail: Voicemail allows you to receive messages when you are unavailable. Video conferencing: Video conferencing allows you to see and hear the person you are talking to. ### How much do VoIP cloud servers cost? The cost of VoIP cloud servers varies depending on the features and plan you choose. Atlantic.Net offers pay-as-you-go cloud plans so you only pay for the resources you actually use. [Contact our solutions team](https://www.atlantic.net/about-us/corporate-contact/) for a quote tailored to your call volume and PBX requirements. ### How can I sign up for VoIP cloud servers? You can sign up for VoIP cloud servers by [contacting Atlantic.Net](https://www.atlantic.net/about-us/corporate-contact/), or call 866-618-DATA (3282) to speak with a solutions architect. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Cloud Containers for Portable, Scalable Application Deployment > URL: https://www.atlantic.net/cloud-platform/cloud-containers/ | Updated: 2026-09-16 Deploy Docker containers today on Atlantic.Net Cloud Virtual Servers in any of eight data center locations. ACP Container Engine and Managed Kubernetes are currently in development and available through preview access. - One-Click Docker Deployment - Ubuntu LTS Support - Windows Server 2022 / 2025 - 8 Data Center Locations Cloud Server Deployment: Under 30 Sec Managed Orchestration: Preview Access The Atlantic.Net Research and Development teams are building an autoscaling container orchestration and deployment platform for the Atlantic.Net Cloud Platform. Container services create an abstraction layer away from the environment they run on. Containers are lightweight, easy to deploy, and scale very well. Whether you are looking to leverage libraries of vendor-approved, pre-built containers or your own existing application containers, the Atlantic.Net Container Engine will provide the support and functionality you are looking for. ## Docker support is currently available. ACP Container Engine and Managed Kubernetes (K8s) are coming soon. Email feedback@atlantic.net with the subject "Requesting preview access to Container Engine and/or Managed Kubernetes" for an exclusive preview invite. ## Docker Docker is synonymous with containerization. It remains the most widely used standard for container applications, with a developer community that is second to none. Docker support is currently available on Atlantic.Net as a one-click application on current Ubuntu LTS releases, and on Windows Server 2022 / 2025 Datacenter (with Containers/Docker as a server-based deployment). Both can be deployed in any of our eight data center locations in under 30 seconds. ### Container Engine Currently in development, the ACP Container Engine is our solution for managed container deployment. Your Docker containers are stored securely within the Atlantic.Net Cloud in a private Docker registry. You can build and deploy containers automatically on an ultra-fast, highly available platform. ### Managed Kubernetes Currently in development, Managed Kubernetes (K8s) is coming soon to the Atlantic.Net Cloud Platform. Originally created by Google, Kubernetes is now fully open-source and actively maintained by the Cloud Native Computing Foundation (CNCF). K8s is an orchestration platform for container deployment automation, simplifying the running and maintenance of containers at scale. Kubernetes is the service mesh that manages the deployment of resources (workers). It intelligently manages resources, a strong fit for Docker cloud CI/CD. ## Read More About Cloud Containers [Containers in Cloud Computing](https://www.atlantic.net/vps-hosting/containers-cloud-computing/) from Atlantic.Net A Guide to [Container Hosting](https://www.atlantic.net/vps-hosting/container-hosting/) ## Frequently Asked Questions About Cloud Containers ### What container technologies does Atlantic.Net support? Docker is currently available as a one-click application on Atlantic.Net's Cloud Platform. ACP Container Engine and Managed Kubernetes (K8s) are in development and available through preview. ### How do I get preview access to Container Engine or Managed Kubernetes? Email feedback@atlantic.net with the subject "Requesting preview access to Container Engine and/or Managed Kubernetes". The Atlantic.Net team will respond with a preview invite and onboarding details. ### What's the difference between Docker and Kubernetes? Docker packages applications into portable containers; it's the standard for building and running individual containerized apps. Kubernetes orchestrates many containers across many hosts, handling scheduling, scaling, rolling updates, networking, and self-healing for production fleets. Most teams use both: Docker (or another OCI-compatible runtime) to build images, Kubernetes to run them at scale. ### Can I run containers on Atlantic.Net Cloud Virtual Servers today? Yes. Docker is available as a one-click application on supported Linux and Windows Server images. You can deploy a Cloud Virtual Server in under 30 seconds and run containerized workloads immediately, while the managed orchestration layer (ACP Container Engine, Managed Kubernetes) is preparing for general availability. ### Where will containers be hosted geographically? Atlantic.Net's container deployments run inside the same eight global data center regions used for the rest of the Cloud Platform: New York, Dallas, San Francisco, Ashburn, Orlando, Toronto, London, and Singapore. You can place containers close to your users or replicate across regions for resilience. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # About Atlantic.Net > URL: https://www.atlantic.net/about-us/ | Updated: 2026-09-16 Learn about Atlantic.Net's history, community involvement, and key milestones. Atlantic.Net is a global cloud services provider with more than 32 years of experience, delivering both managed and unmanaged cloud hosting solutions. This long-standing track record makes Atlantic.Net one of the most experienced hosting providers in the world. With a focus on security, compliance, and simplifying user experience, Atlantic.Net provides a large-scale, high-performance computing (HPC) platform to enable innovative AI/ML models on our dedicated and Cloud GPU platform, designed for unparalleled scalability and performance. Atlantic.Net provides business-class dedicated and cloud hosting solutions globally through data centers in New York, London, San Francisco, Singapore, Toronto, Dallas, Ashburn, and Orlando regions. With always-available expert support and a range of certifications such as SSAE 18 SOC 2 and SOC 3, HIPAA, and HITECH audits, Atlantic.Net is known for providing reliable and exceptional service, simplifying complex technologies, and building a brand that businesses have trusted since 1994. Atlantic.Net's mission is to empower businesses worldwide with innovative, secure, and compliant cloud hosting solutions, delivering exceptional customer service through a customer-centric approach. ## Atlantic.Net, Inc. Trusted hosting solutions provider Our reputation is founded upon over thirty years of direction and counsel given to CEOs, managers, engineers, developers, entrepreneurs, and IT professionals. Atlantic.Net provides an array of hosting services, including cloud, GPU, dedicated, colocation, private virtualisation, and managed hosting. ## Manoj "Marty" Puranik Founder, President, and CEO Manoj "Marty" Puranik is the founder, president, and CEO of Atlantic.Net. Marty's strengths as a leader and visionary have helped him lead a successful business for over three decades. Atlantic.Net thrives thanks to Marty's strategic acumen, technical prowess, and his valuable old-fashioned habits of resourcefulness, modesty, and discipline. ## Success Stories Here are some of the reasons why organizations of all sizes choose Atlantic.Net. ## Atlantic.Net's History 1994 - Atlantic.Net is established in Gainesville, Florida as Internet Connect Company Computers (ICC Computers) 1995 - Atlantic.Net launches first commercial Internet services 1996 - Atlantic.Net expands services to Tampa & Orlando 1997 - Atlantic.Net Internet service available on the Space Coast - Internet Connect Company renamed Atlantic.Net, launches service in 9 cities - Atlantic.Net acquires First Coast Internet & Worldwide Internet - Atlantic.Net Internet becomes available in Jacksonville - Atlantic.Net cans “SPAM” - Atlantic.Net hosts WRRX’s website 1998 - Atlantic.Net doubles revenue. Acquires 3 additional ISPs 1999 - Atlantic.Net completes 10th acquisition and expands to Mississippi & Louisiana - Atlantic.Net CEO named to Board of Directors of the Florida Internet Service Providers Association - Atlantic.Net becomes CLEC certified - Atlantic.Net introduces Webmail - Atlantic.Net nominated for 1999 Florida 100 - Atlantic.Net recognized as 15th fastest growing private company in Florida - Atlantic.Net creates Web Division - Atlantic.Net CEO in running for Entrepreneur of the Year® - Atlantic.Net CEO honored at Entrepreneur of the YearAward banquet 2000 - Atlantic.Net named 1 of the 500 fastest growing companies by Inc. Magazine - Atlantic.Net launches service in Georgia. & Alabama, opens 24/7/365 call center 2001 - Atlantic.Net makes Florida 100 for third year in a row - Atlantic.Net offers nationwide dial-up and launches DSL service - Atlantic.Net named to Inc. Magazine list for 2nd year - Atlantic.Net introduces True Private Networks 2002 - Atlantic.Net makes Florida 100 list for fourth year in a row - Atlantic.Net enters strategic partnership with ClearChannel Broadcasting - Atlantic.Net opens office in Orlando - Atlantic.Net becomes 1st Orlando ISP to offer high speed dial-up, completes 16th acquisition - Atlantic.Net launches nationwide long-distance phone service - Atlantic.Net named among Inc. Magazine’s 500 Fastest-Growing Private Companies in America for the third year in a row 2003 - Atlantic.Net opens 1st data center operation in Orlando, Florida - Atlantic.Net CEO named as finalist in American Business Awards (SM) - AAA and Atlantic.Net team up to offer discounted Internet access - Progress Telecom Enhanced Ethernet chosen by Atlantic.Net 2005 - Atlantic.Net expands data center services to include VoIP systems 2008 - Continued growth makes Atlantic.Net the #1 data center in central Florida 2009 - Atlantic.Net launches managed hosting services for government agencies and businesses worldwide - Orlando Magic selects Atlantic.Net as its Official Server Host - Atlantic.Net completes SAS 70 certification 2010 - Thoughts.com selects Atlantic.Net for colocation service - Atlantic.Net introduces Cloud offering and Virtualization services 2011 - Atlantic.Net Adds Cloud Computing API - Atlantic.Net begins Hosted Solutions offering, allowing organizations to fully outsource their IT Infrastructure - Atlantic.Net Expands Across the U.S. 2012 - Atlantic.Net completes SSAE-16 Type II certification 2014 - Atlantic.Net offers hosting services with local presence in Toronto, Canada - Atlantic.Net offers hosting services with local presence in Silicon Valley, California. 2015 - Atlantic.Net Offers HIPAA Audited Hosting Solution to give medical companies and patients protection - Atlantic.Net Continues to Expand With The Opening Of Its State-of-the-Art Data Center Location in New York City - Atlantic.Net expands into Europe with new London data center 2016 - Atlantic.Net adds Business Partner Program to attract channel partners - Atlantic.Net adds new Business Cloud Hosting plans 2017 - Atlantic.Net Announces Windows Server Container Support in the Cloud - Atlantic.Net Announces Cloud Platform That Encrypts All Customer Data Stored At Rest Automatically - Atlantic.Net Announces Nextcloud One-Click App for Its Public Cloud 2018 - Atlantic.Net attains SSAE-18 Certification in compliance with AICPA Standard Principles - Atlantic.Net Releases Secure Block Storage (SBS) for its Cloud Servers - Atlantic.Net Named 2018 MedTech Breakthrough Award Winner - Atlantic.Net Announces Collaboration with Leading Innovator in Enterprise Software, VMware - Atlantic.Net Launches New Data Center Hosting Facility in Northern Virginia, With Close Proximity to Washington, D.C. - Atlantic.Net Recognized in Gartner 2017 Market Guide for Cloud Service Providers to Healthcare Delivery Organizations - Atlantic.Net Receives TMC’s 2018 Cloud Computing Security Excellence Award - Atlantic.Net Announces Partnership with Veeam to Enhance Protection and Availability of Critical Data 2019 - Atlantic.Net Named a 2019 Tech Elite Solution Provider by CRN - Atlantic.Net Celebrates 25 Years of Innovative Services and Customer Growth - Atlantic.Net Recognized as a Representative Vendor by Gartner for the Second Time 2020 - Atlantic.Net Announces File-Level Recovery to Help Further Strengthen Company’s Cloud Backup Offerings - Atlantic.Net Announces New Initiatives to Help America’s Small to Mid-Size Businesses During the COVID-19 Pandemic - Ubersmith Brings Together 50 Disparate Business Operations Systems at Atlantic.Net 2021 - Atlantic.Net Expands the Free G3.2GB Promo in New York and Toronto Data Centers - Expands the Free G3.2GB Promo in New York and Toronto Data Centers - Atlantic.Net Technology Wins 2021 BIG Innovation Award - Atlantic.Net Expands the Free G3.2GB Promo in San Francisco Data Center - Atlantic.Net Named to CRN’s Managed Service Provider 500 List - Atlantic.Net now accepts PayPal payments - Atlantic.Net Honored As Bronze Stevie® Award Winner In 2021 American Business Awards® - Atlantic.Net, Inc. Named Winner of the Coveted Global InfoSec Awards during RSA Conference 2021 - Atlantic.Net Expands the Free G3.2GB Promo in Dallas and London Data Center - Atlantic.Net Introduces Rocky Linux as a New Cloud VPS Operating System 2022 - Windows Server 2022 Is Now Available on the Atlantic.Net Cloud Platform (ACP) - Atlantic.Net, Inc. Honored as gold and silver Stevie® award winner in 2022 American business awards® - Atlantic.Net Named Winner of the Coveted Global InfoSec Awards during RSA Conference 2022 - Atlantic.Net Wins 2022 Fortress Cyber Security Award 2023 - Atlantic.Net Launches a New Website to Enhance User Experience and Accessibility - Atlantic.Net Named Winner of the Coveted Global InfoSec Awards During RSA Conference 2023 - Atlantic.Net honored as Bronze Stevie® award winner in the 2023 American Business Awards® - Atlantic.Net and mesibo introduce world’s first one-click real-time communication-platform-as-a-service - Atlantic.Net Shortlisted at The SaaS Awards 2023 International SaaS Awards Program Announces Initial Shortlist - Atlantic.Net Named “Top InfoSec Innovator” in Cyber Defense Magazine’s 11th Annual InfoSec Awards - Atlantic.Net Named a Global Leader in Cloud Computing - Atlantic.Net, Inc. Named Winner of the Coveted Top InfoSec Innovator Awards for 2023 - Atlantic.Net Offers $250 Credit to Try Cloud Platform, Adds Spanish Customer Support 2024 - Atlantic.Net expands its international footprint to eight global data center regions with new Singapore region 2025 - Atlantic.Net signs a multi-year partnership with the San Jose Earthquakes. 2026 - Atlantic.Net Launches Fortress Portfolio to Reinforce Commitment to Secure Hosting Solutions. ### Key Milestones - 1994 – Atlantic.Net starts as "Internet Connect Company," providing dial-up and web hosting services. - 1995 – Atlantic.Net launches its first commercial Internet services. - 1999 – Atlantic.Net becomes CLEC certified. - 1999 – Atlantic.Net introduces Webmail. - 2001 – Atlantic.Net introduces True Private Networks. - 2001 – Atlantic.Net offers nationwide dial-up and launches DSL service. - 2002 – Atlantic.Net launches nationwide long-distance phone service. - 2002 – Atlantic.Net named among Inc. Magazine's 500 Fastest-Growing Private Companies in America for the third year in a row. - 2003 – Atlantic.Net opens its first data center operation in Orlando, Florida. - 2005 – Atlantic.Net expands data center services to include VoIP systems. - 2009 – Orlando Magic selects Atlantic.Net as its official server host. - 2009 – Atlantic.Net completes SAS 70 certification. - 2010 – Atlantic.Net introduces cloud and virtualisation services. - 2011 – Atlantic.Net begins Hosted Solutions, allowing organisations to fully outsource their IT infrastructure. - 2012 – Atlantic.Net completes SSAE-16 Type II certification. - 2015 – Atlantic.Net offers HIPAA-audited hosting solutions to give medical companies and patients protection. - 2018 – Atlantic.Net attains SSAE-18 certification in compliance with AICPA Standard Principles. - 2024 – Atlantic.Net expands its international footprint to eight global data center regions with a new Singapore region. - 2025 – Atlantic.Net signs a multi-year partnership with the San Jose Earthquakes. - 2026 - Atlantic.Net Launches Fortress Portfolio to Reinforce Commitment to Secure Hosting Solutions. ## Cloud Availability in Multiple Global Regions Deploy close to your users from eight international data centers worldwide, with new regions on the way. ## Career Opportunities We're regularly on the lookout for new faces to add to our team of engineers and professionals. If you're interested in a career at Atlantic.Net, you can check out available employment opportunities here. We'll be happy to hear from you. ## Always Available Support Customer satisfaction is, always has been, and forever will be paramount at Atlantic.Net. With our always-available bilingual phone and email support, you can depend on us. ## Award-Winning Service We've repeatedly been recognised for our work in the hosting industry, having been awarded numerous national and international business awards. Some of the awards include: - Inc. 500 for three years in a row - Florida 100 for four years in a row - Gold Stevie winner - Global Infosec Award - CRN Tech Elite 250 - eHealthcare Leadership Award - Excellence in Customer Service Award - GOLD GLOBEE® Award - AI Excellence Award - Fortress Cyber Security Award – and many more ## Community Involvement Grassroots and open-source technology initiatives are key to the growth of the evolving technology ecosystem. Atlantic.Net is dedicated to promoting grassroots technology initiatives and open-source organizations. Listed below are initiatives and charities we have supported over the years: - San Jose Earthquakes - TIE Silicon Valley - American Telehealth Association - Northern California Cricket Association - Open Silicon Valley - USA Youth Cricket Western Conference - Cupertino Chamber of Commerce - California Cricket Academy - HIMSS Northern California Chapter - Southern California Linux Expo - Orlando WordCamp - Tampa WordCamp - Seattle WordCamp - Orlando JS - ONETUG - Orlando Devs - Dev Fest FL - SQL Orlando - BarCamp - BarCamp Orlando - BarCamp Charleston SC - BarCamp Miami - BarCamp Tampa Bay - BarCamp Sarasota - BarCamp Deland - iSummit - Founding Member of Cloud Advisory Council - Florida Linux Alliance - Florida Linux Show – Orlando - Florida Blogger & Social Media Conference - DotNetNuke Tampa - Startup Weekend Orlando - Orlando Tech Meetup - Orlando.NET User Group - Orlando PHP User Group - Central Florida Information and Technology Society - Citrus IT Alliance - Florida Technology Journal - Kids House of Seminole - HFMA - State Bar of Texas - Federation of Internet Solution Providers of the Americas - Ubuntu Summit - Urban Rethink - Disaster Recovery Journal - ISACA - opensource.org - Hopkins Program for International Education in Gynecology and Obstetrics - Computer.org - Southeast Linux Fest - IEEE - HIMSS Austin Chapter - Healthcare Information and Management Systems Society (HIMSS) - Academy Health - Association for Healthcare Documentation Integrity - AAERT - American Public Media - NPR - CentOS - Florida Justice Technology Center - ADA American Dental Association - Drupal.org - HIMSS Central & North Florida Chapter - Association of Contingency Planners ## Non-Profit Organizations and Charity Involvement - MRS Equine Sanctuary, Inc. - Florida Association of Computer User Groups - Central Florida Computer Society - Humane Society of Alachua County - Global Missions Fellowship - Sumter County Library Systems - Kids Universe, Inc. - Thomas E. Langley Medical Center - Autism Speaks - Russell Home for Atypical Children - Make-A-Wish Foundation Central and North Florida Chapter - Diamonds Are Forever supporting the Muscular Dystrophy Association - NJABL.org - State Bar of Georgia - American Bar Association - Illinois State Bar Association ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Atlantic.Net 100% Uptime SLA > URL: https://www.atlantic.net/hosting-services-provider/100-uptime-sla/ | Updated: 2026-09-16 Atlantic.Net offers industry-leading service levels backed by a 100% Uptime SLA. Atlantic.Net guarantees that all critical infrastructure components will be available 100% of the time in a given month, excluding scheduled maintenance. ## 100% Uptime SLA ### Cloud Hosting Atlantic.Net provides 100% Uptime SLA for Cloud Servers. [Click here for the details.](https://www.atlantic.net/cloud-service-level-agreement/) ### Managed and Dedicated Hosting Atlantic.Net provides 100% Uptime SLA for Managed and Dedicated Hosting. [Click here for the details.](https://www.atlantic.net/dedicated-server-service-level-guarantee/) ### Colocation Hosting Atlantic.Net provides 100% Uptime SLA for Colocation. [Click here for the details.](https://www.atlantic.net/colocation-master-services-agreement/) ## Ready to talk right now? Contact Atlantic.Net Today. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Atlantic.Net Technical Support > URL: https://www.atlantic.net/hosting-services-provider/support-team/ | Updated: 2026-09-16 Always available support by phone and email. ## A Support Team Backed by Decades of Experience With over three decades of experience, our support team is always here to assist you. You’ll have 24/7/365 access to a crop of dedicated veterans, capable of solving any technical problem you throw their way. ## How can we help you? ### Can I speak to a consultant or a sales advisor? 866-618-3282 – [sales@atlantic.net](mailto:sales@atlantic.net) ### I have questions about my bill. [cbilling@atlantic.net](mailto:cbilling@atlantic.net) ### Who can answer my colocation questions? [colocation@atlantic.net](mailto:colocation@atlantic.net) ### I can't access my server. [dedicatedservers@atlantic.net](mailto:dedicatedservers@atlantic.net) ### Is there something wrong with the Cloud? [cloudsupport@atlantic.net](mailto:cloudsupport@atlantic.net) ### Please connect me with Shared Hosting support. [websupport@atlantic.net](mailto:websupport@atlantic.net) ### Is there someone there who can help me with a remote connection? [support@atlantic.net](mailto:support@atlantic.net) ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # World-Class Data Center Infrastructure > URL: https://www.atlantic.net/hipaa-data-centers/ | Updated: 2026-09-16 Power your mission-critical workloads with secure, high-performance infrastructure spanning North America, Europe, and Asia. Speak with our experts today. Established in 1994, Atlantic.Net is a global Dedicated Server Hosting provider. You have invested significant time and money in your business; protect your investment within Atlantic.Net's world-class infrastructure spanning eight regions across the USA, Canada, United Kingdom, and Singapore. Our secure, enterprise-grade infrastructure delivers rapid access to high-performance cloud, network, and hosting resources for carriers, healthcare organizations, SaaS providers, e-commerce businesses, application service providers, and other bandwidth-intensive enterprises. From compliance-focused hosting environments to mission-critical workloads with stringent security and regulatory requirements, our platform is designed to meet the demands of organizations of every size. Whether you need a single server or a highly available, fully scalable cluster deployment, Atlantic.Net provides the flexibility, performance, and global reach to support your growth. Backed by fully managed services, a 100% uptime SLA, and always-available U.S.-based human support, we help ensure your infrastructure remains secure, reliable, and ready for what's next. ### [New York, USA](https://www.atlantic.net/hipaa-data-centers/new-york-hosting/) ### [San Francisco, USA](https://www.atlantic.net/hipaa-data-centers/san-francisco-california-hosting/) ### [Dallas, USA](https://www.atlantic.net/hipaa-data-centers/dallas-texas-hosting/) ### [Ashburn, USA](https://www.atlantic.net/hipaa-data-centers/ashburn-virginia-hosting/) ### [Orlando, USA](https://www.atlantic.net/orlando-colocation-hosting-data-center/) ### [London, UK](https://www.atlantic.net/hipaa-data-centers/london-uk-hosting/) ### [Toronto, Canada](https://www.atlantic.net/hipaa-data-centers/toronto-canada-hosting/) ### [Singapore](https://www.atlantic.net/hipaa-data-centers/singapore-hosting/) ## Data Center Hosting Host your infrastructure in strategically located data centers across the United States, United Kingdom, Canada, and Singapore, bringing enterprise-grade performance closer to your users worldwide. Built for mission-critical workloads, our secure, compliant, and scalable platform supports everything from single-server deployments to large-scale clustered environments. Rest easy knowing your infrastructure is backed by industry-leading reliability, robust security controls, and the flexibility to grow with your business. ## Global Hosting Provider Our data center facilities have completed audits and certifications for compliance with HIPAA and HITECH by a qualified independent third-party auditing firm. Clients enjoy an industry-leading service-level agreement, world-class data center infrastructure, superior on-site security, a full suite of cloud and dedicated server hosting, managed services, and compliant hosting solutions. Atlantic.Net provides top-notch cloud services in carrier-neutral infrastructure backed by multiple top-tier network providers. Our systems automatically select the fastest route to transport your data and redirect traffic to alternative carriers in case of a carrier outage. We continuously monitor network connectivity in our data centers to deliver the highest quality infrastructure, bandwidth, and redundancy in the industry – backing our 100% Network and Infrastructure SLA. Atlantic.Net is ready to help you reach compliance quickly across SOC 2, SOC 3, HIPAA, and HITECH – all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, visit www.atlantic.net, call 866-618-DATA (3282), or email us at sales@atlantic.net. ## Atlantic.Net Data Center Regions at a Glance Eight regions support latency-sensitive workloads, regulatory data residency, and disaster-recovery designs that span multiple continents. | Location | Region | Why Customers Choose It | | --- | --- | --- | | New York | US East | Financial services proximity, low latency to NYC and the Northeast | | Ashburn | US East | Sits inside one of the world's largest internet-exchange clusters | | Orlando | US Southeast | Strategically located for the U.S. and South America. | | Dallas | US Central | Strong central-US peering, alternative DR region for East/West coast workloads | | San Francisco | US West | West-coast latency, technology-sector proximity | | Toronto | Canada | Canadian data residency for PIPEDA-aligned workloads | | London | United Kingdom | EU/UK data residency, GDPR-friendly placement | | Singapore | Asia-Pacific | APAC reach, low-latency to Southeast Asia and Australia | ## Enterprise Data Center FAQs ### What is a data center? A data center is a secure, centralized facility that houses computer systems, servers, storage, and networking equipment. Data centers provide the essential power, cooling, and connectivity required for data processing, storage, and the distribution of IT services. ### How does a data center help businesses? Data centers provide reliable, scalable, and secure IT infrastructure, allowing businesses to focus on core operations instead of managing complex IT systems. They enable efficient data management, application hosting, disaster recovery, and business continuity. ### What are the top considerations before choosing a data center? Data centers serve a wide range of IT systems. Choosing the right one depends on your needs. Key points to consider: HIPAA compliance: healthcare organizations need a data center that adheres to HIPAA's strict physical, technical, and administrative safeguards for protecting patient data. Security: physical and cybersecurity controls that safeguard sensitive data. Data centers are classified into tiers based on infrastructure, performance, redundancy, and cost. Reliability: high uptime guarantees and redundancy measures minimize downtime. Atlantic.Net offers a 100% Uptime SLA. Scalability: the data center should accommodate future growth and changing IT needs – both logical and physical expansion. Location: proximity to your business or target audience impacts network latency and accessibility. You may want a location close to your head office for easier day-to-day management, or one on core internet backbones for top-tier performance. Cost: evaluate total cost of ownership, including power, cooling, bandwidth, and support services. ### Why is HIPAA compliance crucial for data centers handling healthcare data? HIPAA compliance ensures patient data is handled securely and confidentially, safeguarding patient privacy and avoiding costly penalties. The HIPAA Security Rule and HITECH Act both apply directly to the infrastructure layer that hosts ePHI. ### What security features should I look for in a HIPAA-compliant data center? A HIPAA-compliant hosting environment should combine strong physical and cybersecurity protections, including secure firewalls, controlled facility access, 24×7 monitoring, intrusion prevention, encryption, and both on-site and off-site backups. With independently audited infrastructure and compliance-focused controls, Atlantic.Net helps organizations protect sensitive data while supporting HIPAA, HITECH, SOC, and PCI compliance requirements. ### How does a data center ensure high availability and minimize downtime? Redundant power supplies, backup generators, multiple network carriers, and redundant cooling systems keep operations continuous. Atlantic.Net backs this with a 100% network and infrastructure SLA and continuous multi-carrier monitoring. ### Can a data center help my business scale its IT infrastructure? Yes. Data centers offer flexible solutions that let businesses add or remove resources as IT needs evolve, supporting growth and agility. Atlantic.Net's eight regions also let you spread workloads across geographies for performance or DR. ### What is the role of a data center in disaster recovery and business continuity? Data centers provide secure off-site storage and backup capabilities, enabling businesses to quickly recover data and resume operations in the event of a disaster or outage. Atlantic.Net's geographically disparate locations support 3-2-1-style backup designs and cross-region failover for HIPAA contingency-plan requirements. ### Where are Atlantic.Net's data centers located? Atlantic.Net operates eight regions: New York, San Francisco, Dallas, Ashburn, and Orlando in the United States; Toronto in Canada; London in the United Kingdom; and Singapore. Each location is HIPAA-audited and tied into the global Atlantic.Net Cloud Platform. ## Cloud Availability in Multiple Global Regions Deploy close to your users from eight international data centers worldwide, with new regions on the way. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Atlantic.Net's Certifications and Partnerships > URL: https://www.atlantic.net/hosting-services-provider/certifications-and-partnerships/ | Updated: 2026-09-16 ## Certifications and Partnerships Atlantic.Net is committed to maintaining the highest service levels by establishing partnerships with top-tier industry-leaders and participating in leading certification programs. We are proud to highlight our alliances, partnerships, and certifications below: ### NVIDIA Partner Network Cloud Partner (NCP) As an official NVIDIA Partner Network Cloud Partner (NCP). Atlantic.Net helps customers learn, build, test, develop, and deploy NVIDIA solutions more quickly through the Atlantic.Net Cloud. NVIDIA's accelerated computing platform drives and delivers our data processing capabilities. Together, we are shaping the future of cloud technology with a shared commitment to excellence. ### Microsoft – Certified Partner Our Engineers are certified in the latest Microsoft Server technology. We continue to consistently demonstrate capability, expertise, and commitment to the deployment and support of all our Microsoft platforms. We have direct access to the experts at Microsoft if there are any further support needs. ### AMD Atlantic.Net utilizes AMD to deliver high-performance computing powered by AMD EPYC™ processors. Our infrastructure provides exceptional scalability, efficiency, and processing power for demanding workloads like AI and data analytics. ### Intel Atlantic.Net is Intel's Titanium Partner, which represents the top tier of the Intel partner Alliance. We use enterprise-grade Intel Xeon CPUs, Intel SSDs, and associated hardware in our IT server infrastructure. Only Intel offers the best performance, compatibility, and durability to provide our customers the best in class stability and proficiency. ### Samsung Our data centers use ultra-fast, high capacity storage from Samsung. This extremely reliable storage is the backbone of our hosting solutions and helps us to deliver a low-latency, rapid response data bank for our compute infrastructure. ### Super Micro Super Micro has been the exclusive server provider of Atlantic.Net for over a decade, and their cutting-edge server technology is seamlessly integrated into our cloud platform, creating a technological synergy built upon trust and reliability that defines our hosting experience. ### HIPAA Audited Atlantic.Net is regularly audited for HIPAA regulatory compliance for hosting solutions and data center infrastructure. Our support, management, business controls, and processes are fully compliant and adhere to the HIPAA standards. Annual audit is performed by an independent third-party CPA firm. ### SSAE18 Audited Atlantic.Net is regularly audited and is compliant to SOC1 and SOC2 SSAE18 reporting standards. These standards ensure our internal controls, security policies, data processing and client confidentiality are among the highest standards available for a managed service provider. ### AICPA SOC Atlantic.Net is audited and compliant to AICPA service organization control reporting. These standards ensure our information management and network technology assurance adheres to AICPA best practice and ethical standards. ### HITECH Audited Atlantic.Net is audited and compliant with the Health Information Technology for Economic and Clinical Health Act (HITECH) standards for privacy and security of confidential Electronic Health Record (EHR) data. ### cPanel Our partnership with cPanel empowers our clients by providing best-in-class site management for all website hosting needs. cPanel WHM also gives our clients the ability to manage their hosting infrastructure without the need for direct access to the server. Atlantic.Net have direct priority support from cPanel if required. ### PCI Ready The Atlantic.Net hosting solutions are PCI ready to help you conduct all of your online business needs. We provide secure, robust and proven network and compute architecture to help your company become PCI Compliant for the added security of your online transactions. ### Cloud Advisory Council As a member of the Cloud Advisory Council we strive for highest standards in secure and managed private clouds. The CAC enables Atlantic.Net to chart the future of cloud technology and position our products to ensure they maximize the capability of present day and future cloud technology. ### VMware Partner Professional Solution Provider VMware is the global leader in server virtualization for the software defined data center. Our partnership enables Atlantic.Net to offer agile, high performance VMware solutions which drive productivity, offer flexible scalability and introduce significant cost savings to our clients. ### Red Hat Certified Our team of Red Hat Certified System Administrators (RHCSA) and Red Hat Certified System Engineers (RHCE) are highly skilled and adept in all flavors of Linux. We are specialists in Red Hat Enterprise Linux and associated applications and middleware. Our experts are available to help with all your open system needs. ### GDPR Ready As a service provider for reliable cloud services across the globe, Atlantic.Net is ready for the General Data Protection Regulations that protect the processing of our client's personal information in and outside the European Union. All data relevant to our European Clients can be protected per the GDPR guidelines. ### Privacy Shield Ready As a member of the Cloud Advisory Council we strive for highest standards in secure and managed private clouds. The CAC enables Atlantic.Net to chart the future of cloud technology and position our products to ensure they maximize the capability of present day and future cloud technology. ## Network Connectivity Atlantic.Net is a carrier-neutral network provider. Our clients can opt to choose a preferred individual carrier or leverage one of our many fully managed Network Providers. ### CenturyLink - Level3 - TW Telecom CenturyLink – Level 3 - TW Telecom diverse fiber networks give our clients a choice of high speed and low latency Tier 1 fiber network provider services. These redundant links into our data centers provide some of the best reliability and fails safes available for your business. CenturyLink has acquired Level 3's and TW Telecom's networks, however, Atlantic.Net continues to operate all three diverse fiber networks. ### Verizon You can choose our redundant, Tier 1 high speed Verizon network circuits for your business network services, internet connectivity or as a competitive local exchange carrier (CLEC). Verizon provides a fully-managed, point-to-point circuit over dedicated paths to Atlantic.Net and our clients. ### Spectrum Spectrum Business services (formally BrightHouse) and Atlantic.Net can offer our clients high speed internet connectivity and dedicated VoIP telephony systems. Spectrum network connectivity gives our clients even more choice when choosing the best network carrier. ### Crown Castle Fiber Crown Castle Fiber is a part of the Atlantic.Net carrier portfolio. They specialize in fiber networks services, dedicated ISP, and data center mission-critical network connectivity. We believe choosing local and global network providers gives our clients the best choice for their business needs. ### Cogent Atlantic.Net leverages network services from Cogent Communications. Access to their network enables us to achieve delivery of high quality internet, Ethernet, and colocation services to SMB and the Enterprise. ### AT&T As the world's largest telecommunications company, AT&T provides Atlantic.Net a variety of options to offer our clients for network carrier services. This includes high speed fiber connectivity, dedicated VPN, Flexware, and network professional services. ## Security and Compliance Atlantic.Net's Data Center infrastructure is routinely inspected, and is fully audited and SOC 2 TYPE II and SOC 3 TYPE II certified. Rest assured, your systems are secure with Atlantic.Net Hosting Solutions. Utilizing our solutions eliminates regulation concerns, as we offer PCI, HIPAA, and SOC 2 TYPE II and SOC 3 TYPE II compliance. We take care of regulatory compliance, so that you can focus on growing your business. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Experience 32 Years of Award-Winning Service and Trusted Infrastructure > URL: https://www.atlantic.net/hosting-services-provider/award-winning-service/ | Updated: 2026-09-16 ## Award-Winning Service Atlantic.Net has earned national and international recognition for its innovative services and solutions, growth, and superior customer service. We extend our gratitude to our staff, business partners and loyal customers for helping us rise to the top! ### BIG Innovation award 2026 ### Infrastructure & Cloud HealthTech 2026 ### Excellence in Customer Service 2026 ### Enterprise Technology 2026 ### Healthcare Technology 2026 BRONZE STEVIE® WINNER ### Cutting Edge AI Healthcare Compliant Cloud 2026 ### Best Customer Support 2026 [Atlantic.Net Reviews](https://sourceforge.net/software/product/Atlantic.Net/) ### Leader Summer 2026 [Atlantic.Net Reviews](https://sourceforge.net/software/product/Atlantic.Net/) ### Leader Spring 2026 ### Top Dedicated Hosting 2026 [Atlantic.Net Reviews](https://slashdot.org/software/p/Atlantic.Net/) [Atlantic.Net Reviews](https://topbusinesssoftware.com/products/Atlantic.Net/reviews/) ### Silver GLOBEE Award AI-Powered Cloud Computing 2025 ### Fortress Cyber Security 2025 ### AI/ ML Solution - 2025 BRONZE STEVIE® WINNER ### Most Innovative Cloud Hosting Storage Solutions 2025 ### 2025 AI Excellence Award Cloud Hosting and Storage Solutions ### AI Governance Platforms 2025 [Atlantic.Net Reviews](https://sourceforge.net/software/product/Atlantic.Net/) [Atlantic.Net Reviews](https://topbusinesssoftware.com/products/Atlantic.Net/reviews/) [Atlantic.Net Reviews](https://slashdot.org/software/p/Atlantic.Net/) ### Technology Compliance Solution 2025 [Atlantic.Net Reviews](https://sourceforge.net/software/product/Atlantic.Net/) ### Silver GLOBEE Award Cybersecurity 2025 ### Fortress Cyber Security 2024 ### Connected Digital Health Compliance 2024 ### IaaS 2024 BRONZE STEVIE® WINNER ### Excellence in Customer Service 2024 ### Most Innovative Cloud Hosting Storage Solutions 2024 ### Best Security Infrastructure Enterprise 2024 ### Top Infosec Innovator 2023 ### Cloud Computing 2023 ### Healthcare Technology 2023 BRONZE STEVIE® WINNER ### Cloud Platform 2023 BRONZE STEVIE® WINNER ### Cybersecurity Healthcare Practices 2023 ### GOLD GLOBEE® Award 2022 ### Fortress Cyber Security 2022 ### Excellence in Customer Service 2022 ### Cloud Storage & Backup 2022 GOLD STEVIE® WINNER ### Healthcare Technology 2022 SILVER STEVIE® WINNER ### Top 50 Most Innovative Products 2022 ### eHealthcare Leadership 2021 ### Publisher’s Choice Compliance Award 2022 ### Healthcare Technology 2021 BRONZE STEVIE® WINNER ### 2021 ### 2021 ### Healthcare Technology 2020 GOLD STEVIE® WINNER ### Cutting Edge in Compliance 2021 ### 3 years in a row ### Cloud Platform 2020 SILVER STEVIE® WINNERS ### 2019 ### 2 years in a row ### 2019 ### 2019 ### 2019 ### 4 Years in a row ### 2018 ### 2017 ### 2016 ### 2015 ### 2014 ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Atlantic.Net Testimonials and Success Stories > URL: https://www.atlantic.net/hosting-services-provider/atlantic-net-reviews-and-testimonials/ | Updated: 2026-09-16 ## Testimonials Look what our clients and business partners are saying about us: ### - Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform. " ### - Jason Coleman VP of Information Technology, Orlando Magic "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." ### - Erin Chapple General Manager for Windows Server, Microsoft Corp. "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services. " ### - John Beck CTO/CSO ShareSafe Solutions "There were two DDoS attacks last year where, on both occasions, our services were restored within five minutes at Atlantic.Net. With another vendor, we were down for up to four hours. The other cloud companies I'll call and get a technician who just makes a support ticket. I have to wait for my support ticket to be seen in the support queue and acted upon. They just don't seem to have the same sense of urgency. " ### - Ojash Shrestha Founder & CEO of Novelty Technology "After months of research and years of experience with other hosting providers, we finally switched to Atlantic.Net and we couldn't be happier. Their customer support is PHENOMENAL. They worked with us to create, customize and configure environments for each one of our clients. We look forward to working more with Atlantic.Net" ### - Joseph Nompleggi VP of Product Development of Complete Healthcare Solutions "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals " ### - Bill Harris President, Trade Web "Atlantic.Net is the absolute best Data Center operation we have ever worked with. We trust Atlantic.Net. We always know they will take care of us and our customers. " ### - Jerry Brown President, ResLogic.com "Your facility provides a non-compromising enterprise level hosting environment at very competitive pricing. As a virtual Internet company, we have very stringent hosting requirements and any downtime could be catastrophic for us. During our initial installation, I have seen firsthand how Atlantic.Net operates and I don't think we could be in better hands. Thanks again! " ### - Roy Johnson Chief Information Officer, HD Publishing Group "The engineers at Atlantic.Net are top notch. Our business relies on 100% network uptime and Atlantic.Net's World Class Data Center facility right in our backyard operates at a level we haven't seen in other facilities. The fact Atlantic.Net has been around since 1994 and operates a profitable business with extremely low debt adds an extra layer of security in today's tough business environment. " ### - Farhan Shamsi Co-founder of Genensys. "We are in the business of providing highly-regulated electronic medical records, which requires a secure hosting platform, Atlantic.Net provides a turn-key and secure hosting framework for our application compliance needs, offering excellent value in both price and service. " ### - Christian Grover Director of IT, TalentKeepers "Their hands-on support has been second to none when issues have arisen and they have kept the lines of communication open while working any problem. For their stellar communication, knowledge, the customer comes first attitude, I will always recommend Atlantic.Net as a premier hosting provider. We may not be their largest client, but you'd never know since they treat us like we are! I'd bet my career on Atlantic.Net!" " ## Success Stories ### [ShareSafe Solutions Chose Atlantic.Net Hosting Solutions](https://www.atlantic.net/press-room-signup/?f=/resources/documents/case-studies/ShareSafe-Atlantic-Net-Case-Study.pdf) ### [CHS Chose Atlantic.Net Hosting Solutions](https://www.atlantic.net/press-room-signup/?f=/resources/documents/case-studies/HIPAA-Compliant-Hosting-Atlantic-Net-Case-Study.pdf) ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Atlantic.Net Press Room > URL: https://www.atlantic.net/press-room/ | Updated: 2026-09-16 Welcome to the Atlantic.Net newsroom. We appreciate your interest and look forward to assisting you. Whether you are conducting research related to the industry or looking for more information about Atlantic.Net, our media team is ready to help. ## In The News ### Blog [Blog](https://www.atlantic.net/blog/) ### Press Releases [Press Releases](https://www.atlantic.net/press-releases/) ### In The News [In The News](https://www.atlantic.net/press-room/news/) ### White Papers [White Papers](https://www.atlantic.net/about-us/whitepapers/) ### Case Studies [Case Studies](https://www.atlantic.net/press-room/case-studies/) ### Brochures [Brochures](https://www.atlantic.net/brochures/) ### Logos and Badges [Logos and Badges](https://www.atlantic.net/press-room/logos/) ## Ready to talk right now? Contact Atlantic.Net Public Relations: ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Contact Atlantic.Net > URL: https://www.atlantic.net/about-us/corporate-contact/ | Updated: 2026-09-16 ### Sales 866-618-DATA (3282) International: +1-408-335-0825 Sales Inquiries and Support: sales@atlantic.net Hours of Operation: Monday through Friday, 8:00 AM to 5:00 PM (Eastern & Pacific) ### Billing 866-618-DATA (3282) Billing Email Support: cbilling@atlantic.net Hours of Operation: Monday through Friday, 8:00 AM to 5:00 PM (Eastern, except on major US holidays) ### Human Resources 866-618-DATA (3282) Human Resources: hr@atlantic.net Legal: legal@atlantic.net ### Marketing 866-618-DATA (3282) Marketing: marketing@atlantic.net Acquisitions: acquisitions@atlantic.net ### Corporate Headquarters 866-618-DATA (3282) International: +1-408-335-0825 Toll-Free in the USA: 866-618-DATA (3282) Fax: +1 407 660 8094 Email: info@atlantic.net ### Support 866-618-DATA (3282) Dedicated Server Support: dedicatedservers@atlantic.net Colocation Support: colocation@atlantic.net General Support Requests: support@atlantic.net Reporting Abuse: abuse@atlantic.net Media Relations: pr@atlantic.net ## Schedule a demo Schedule a no-obligation call with our team to learn how Atlantic.Net can help you get more for less with our award-winning dedicated, cloud server, and compliance hosting solutions. Pick a time that works for you The booking calendar is provided by Calendly, a third-party service that sets its own cookies once loaded. Prefer a new tab? [Open the calendar on Calendly](https://calendly.com/anet-sguiliano/call-to-go-over-new-hosting-projects). ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # USA Dedicated Server Hosting > URL: https://www.atlantic.net/dedicated-server-hosting/ | Updated: 2026-09-16 Get a private, physical Dedicated Server with full root access, your choice of CPU, disk, memory, operating system, and control panel, plus 24/7/365 USA-based support. - Custom CPU, Disk & Memory - Full Root Access - No Setup Fee - 100% Network Uptime SLA Network uptime SLA: 100% Trusted since: 1994 ## American Dedicated Server Hosting Unleash the huge server power of Atlantic.Net dedicated server hosting services, America's most experienced dedicated server hosting provider. Each private, physical dedicated server comes with full root access, backed by the latest hardware specifications and USA-based support. Atlantic.Net provides various types of dedicated server hosting options, all available with discounts for long-term contracts. Dedicated Servers are a standalone hardware offering not tied into any existing Cloud platforms or hypervisors, such as the Atlantic.Net Cloud Platform. The hardware is solely set up for your requirements along with any additional Managed Services to ensure the hosting environment meets your needs. ## Dedicated Server Hosting Plans Our Dedicated Servers are custom-built to your specification with a choice of CPU, Disk, and Memory (RAM). Each server is available with full root access for complete server control. Our dedicated hosting services come with a dedicated network IP address, free SSL certificate, and support for a wide selection of operating systems and control panel options to supercharge your web hosting experience. Here are a few of our most popular dedicated server plans: ### Standard Dedicated Servers 3.4GHz Xeon E-2236 (6-Cores/12-Threads) 64GB DDR4 RAM 2 x 480GB SSD Hardware RAID1 20TB Transfer - 1Gbps Port ### Business Dedicated Servers 2 x 2.1GHz Xeon E5-2620 V3 (12-Cores/24-Threads) 64GB DDR4 RAM 4 x 1.92 TB SSD Hardware RAID1 20TB Transfer - 1Gbps Port ### Enterprise Dedicated Servers 2 x 2.6GHz Xeon Gold 6140 (36-Cores/72-Threads) 128GB DDR4 RAM 4 x 1.92TB SSD Hardware RAID10 20TB Transfer - 1Gbps Port ### Custom Dedicated Servers Custom Dedicated Servers *Due to global supply-chain volatility, Dedicated Host pricing is subject to change but will be confirmed prior to deployment. ## Don't see the plan or feature you are looking for in a dedicated server? Our 100% USA-based dedicated support team can build and configure the customized server solution for you to help get you started. Whether you need extra RAM, high traffic website solutions, extra SSD storage options, Windows operating system licensing, control panels, or additional IP addresses; we will be happy to build a customized server solution for you to help deliver high performance, highly available server infrastructure. ## Benefits of USA-Based Dedicated Hosting with Atlantic.Net - Atlantic.Net does not outsource support, and we speak your language; Atlantic.Net offers 24/7/365 USA-based English and Spanish language phone and email support, and our data center locations have USA-based onsite server technicians. - Typically, USA data centers connect with more networks, providing more redundancy, lower latency, and a higher quality of service. - Atlantic.Net's data center infrastructure is fully audited and compliance-ready for PCI, HIPAA, and HITECH hosting. - Deal confidently with Atlantic.Net – we are a profitable, privately owned company with little to no debt. - Atlantic.Net is a USA-based company with the same original founder since its inception in 1994. - Atlantic.Net has been in business for 32 years, much longer than the big-name hosting providers. ## Dedicated Hosting Features ### Intel Dedicated Servers Dedicated servers are all about raw computing power provided by the latest Intel Xeon Scalable processors and powerful Intel Xeon E-series server processors. Intel gives you extra flexibility, guaranteed access to the physical resources you demand, and a great range of cost options. Intel processors feature multiple cores and multiple threads, each clocked at ultra-high speeds, making them capable of adding intense bursts of CPU cycles on demand. These servers provide the physical resources you demand, ideal for all business applications, web hosting, machine learning, multi-user apps, big data, and reseller cPanel hosting with multi-site hosting capabilities. ### AMD Dedicated Servers Our dedicated hosting lineup also features the enterprise-grade power of the latest AMD EPYC™ series processors, delivering industry-leading performance and exceptional core density. AMD processors are an affordable and incredibly powerful choice for managing demanding workloads, providing extensive I/O, superior memory bandwidth, and robust security features. With a high core and thread count, AMD servers accelerate performance for data-intensive applications, virtualization, cloud computing, and high-performance computing (HPC), ensuring you have the power and efficiency to meet your business requirements. ### The Cost-Effective Alternative All the Benefits of Owning Your Own Server...at a Fraction of the Cost! Free up your workspace and save your cash. Let us absorb the expense of buying new equipment, hiring maintenance engineers, and purchasing software upgrades. ### Dedicated Hosting Upgrade Options Upgrade options include Website Statistics, Managed Monitoring, Managed Data Backup, Managed Firewall Security Services, Plesk Dedicated Server Control Panel, Additional Memory and Storage, and Managed Hosting Packages. ### Fast, High-Bandwidth Connections and High-Speed Data Transfer Get access to multiple redundant connections to the Internet backbone. Servicing websites with high traffic volumes is an Atlantic.Net specialty. Our global yet USA-centric network consists of vast connectivity and storage capabilities to deliver unparalleled dedicated server hosting solutions. We design and implement custom dedicated hosting packages for clients who require premium data transfer and superior server performance in a maintenance-free solution. ### The Latest Technology and Top Computing Power Dedicated servers eliminate the need to constantly upgrade or replace obsolete equipment. As our client, your custom-built dedicated server is always powered by a fast processor and the newest software - ideal for resource-intensive applications. Our machines can support multiple database-driven sites, streaming media, and complex e-commerce sites. Besides that, we can host email, DNS, and SQL servers. ### Dedicated Hosting Services with Root Access and Admin Privileges Need dedicated servers? Need full administrator privileges? Need root access to your server and website? We've got you covered! Each server is available as a managed or unmanaged server. You can choose to manage the hosting solution internally, or you can outsource some or all of the server administration responsibility to Atlantic.Net. There is no setup fee, no matter which dedicated hosting solution you choose. Upgrade your dedicated server with managed services and network security add-ons like Managed Firewalls, Intrusion Detection services, Onsite and Offsite Backups, CDN, Web Application Firewalls, and DDoS Protection. ### Choose the Best Infrastructure for Your Business Applications Dedicated hosting is the number one choice for established businesses or entrepreneurs wanting to expand their infrastructure virtualization. A dedicated hosting environment can be customized indefinitely. Enjoy the flexibility of choosing your operating system, control panel, storage servers, CPU, Disk, and Memory. Our support teams will work directly with you to meet your exacting requirements. There are no hidden costs and no setup fee; you just pay for the server and the hosting. With the option of managed servers, our teams can provide the complete management of your server infrastructure. Managed services are available to look after the network resources, load balancers, bandwidth, firewall, and storage. ## Your Servers, Your Operating System, Your Rules! You have full root access to the secure shell of your dedicated server. You have control over server management features. Pick any Operating System or Hypervisor, then choose the type of hard disk, whether that's the premium solid-state disk (fast!) or NVMe (really, really fast!). Unlike other hosting providers, you get to choose your support experience. We will be involved as much or as little as you want. ## Looking for Dedicated Hosting? We Can Help With A Free Assessment. - IT Architecture Design, Security, & Guidance. - Flexible Private, Public, & Hybrid Hosting. - 24x7x365 Security, Support, & Monitoring. ### New York Data Center Only 11 miles from Manhattan, this facility is ideal for clients who desire close proximity with the financial centers and exchanges. [View Location](https://www.atlantic.net/hipaa-data-centers/new-york-hosting/) ### San Francisco Data Center Our bay-area data center is ideal for clients who desire to keep their data local and close to San Francisco and Silicon Valley. [View Location](https://www.atlantic.net/hipaa-data-centers/san-francisco-california-hosting/) ### Ashburn Data Center Located just outside Washington, D.C, right next door to Dulles International Airport, in the heart of Data Center Alley. [View Location](https://www.atlantic.net/hipaa-data-centers/ashburn-virginia-hosting/) ### Dallas Data Center At the heart of the city of Dallas, Texas, our USA-Central-1 data center offers convenience to clients across the United States and those looking for direct links into Central America. [View Location](https://www.atlantic.net/hipaa-data-centers/dallas-texas-hosting/) ### Orlando Data Center Our Orlando center offers a secure and robust carrier-neutral colocation platform with multiple redundant connections to the Internet backbone. [View Location](https://www.atlantic.net/orlando-colocation-hosting-data-center/) ## Why Choose Atlantic.Net for Dedicated Server Hosting? Unlike many other dedicated server hosting providers, we own and operate a network backed by diverse high-speed direct connections to the Internet. Our system automatically selects the fastest route to transport data, perfect for a high-traffic website. Each Dedicated Host, Bare Metal Server, or Dedicated Server provides dizzying data transfer speeds for our client's hosted environments, offering optimum server performance without the hassle of server maintenance. For over 32 years, USA-based Atlantic.Net has helped thousands of organizations with industry-leading hosting solutions and powerful servers, and we can do the same for you as well! ### AICPA SOC 2 and SOC 3 Certified World Class Data Center Infrastructure Our state-of-the-art AICPA SOC 2 and SOC 3 certified infrastructure is monitored 24/7/365 by our Security Operations Center. All Dedicated Servers are housed in our secure, redundant, fire-monitored, climate-controlled facility. Unlike other dedicated server hosting providers, our dedicated team is available around the clock to respond to your needs. Atlantic.Net offers America's Leading Dedicated Server Service Level Agreement. ### Network Uptime – 100% SLA Guaranteed Atlantic.Net ensures that the network will be available 100% of the time in a given month excluding scheduled maintenance. Network uptime includes the functioning of all network infrastructure such as routers, switches, and cabling, but does not include software and services running on your dedicated server. ### Hardware – 100% SLA Guaranteed Atlantic.Net ensures all hardware components in your dedicated server and will replace any failed components at no cost to you, backed by 100% SLA guarantee. ### Infrastructure – 100% SLA Guaranteed Atlantic.Net ensures that all critical infrastructure components, including power supplied to your server and HVAC, will be available 100% for the time in a given month excluding scheduled maintenance, backed by 100% SLA guarantee. ## Worth the Investment A dedicated server is ideal if you are starting to outgrow your existing hosting environment. Not only do you get the dedicated server resources using high-end server equipment, but you can use it for as long or as little as you want. Do you need to offload your workload to a superfast web host, perhaps for Black Friday and Christmas sales peak? Or do you need continued investment in dedicated server resources to expand your company? Whatever your needs, a dedicated server package from Atlantic.Net gives you the server control you need to take your business to the next level. ## Unlimited Inbound Bandwidth Our dedicated hosts all come with unlimited, unmetered inbound bandwidth. Your dedicated server is available around the clock with no sharing resources, giving you unlimited inbound bandwidth to your dedicated server, perfect if you have a high-traffic site or users located globally. ### Unparalleled USA-Based Support Available Atlantic.Net is involved as much or as little as you require. Our customer service is available for users 24x7x365 to offer support and mentoring for website hosting, operating system software, or to discuss your storage needs. We know that some dedicated server customers just need the hardware, and they want to run the show in-house - this approach is absolutely fine, and we endeavor to give you the best tools to make this possible. However, if you need help, assistance, additional storage options, or to leverage extra managed services or even have a fully managed server, just know that we are a phone call or email away. ### The Latest Operating Systems With Atlantic.Net's dedicated server plans, you can provision the latest or an older supported version of Microsoft Windows Server, Ubuntu Server, CentOS, Rocky Linux, Fedora, and more! We even roll up the latest operating system updates, making deployment a quick and easy process, minimizing the manual effort needed to get your OS updated. We can even take care of the software licenses for you! If you require the newest versions or an internal piece of software requires you to utilize an older operating system, no worries! Atlantic.Net has the versions and Operating Systems you need. ### A Cost-Effective Alternative All the benefits of owning your own server at a fraction of the cost! Whether you are looking for a cheap dedicated server or a highly available dedicated hosting platform in the USA, our customized solutions are a perfect fit for large resellers looking for the ultimate performance, a consultancy support team, root access, and more. No matter what dedicated server plan you choose, free up your workspace and save valuable resources and costs as we provide a fully managed hosting service. Let us absorb the expense of buying new cloud hosting equipment, hiring maintenance engineers, or purchasing software upgrades. ## Managed Service Options for Your Dedicated Server Hosting Service Whether you use Dedicated Hosting or Cloud Hosting, you can purchase add-ons that integrate directly with your environment. Our Dedicated Server plans not only offer more power for your hosted environment, but Atlantic.Net's Managed offerings complement our Dedicated Hosting Servers. Talk to us about our Dedicated Server Hosting options, including our fully Managed Dedicated Servers. - Managed Security Firewall - Intrusion Detection Service (IDS) - Onsite and Offsite Backups - Content Delivery Network (CDN) - Web Application Firewall - Advanced DDoS Protection ## Cloud Availability in Multiple USA Regions Experience unmatched performance and control with Atlantic.Net's Dedicated Servers. Customize your solution and achieve your IT goals with highly configurable servers. Contact us to build your ideal dedicated server. For faster application deployment, free IT architecture design, and assessment, call 866-618-3282 or email us at sales@atlantic.net. ## Fortress Dedicated Server Plans ### Fortress Standard Dedicated Servers Secure, isolated infrastructure with essential protections $1,047.94 Per Month 3.4GHz Xeon E-2236 (6-Cores/12-Threads) 64GB DDR4 RAM 2 x 480GB SSD Hardware RAID1 20TB Transfer - 1Gbps Port - Fully Managed FortiGate Firewall with IPS - Server Management - Scheduled Vulnerability Scans - Managed VPN 5 Accounts - Veeam On-site Daily Backups - Veeam Off-site Daily Backups - 4 Hours of Migration Service - Multi-Factor Authentication - Trend Micro Security Suite* - Network Edge Protection* - Load Balancing ### Fortress Business Dedicated Servers Enhanced security layers and hardened configurations $1,261.85 Per Month 2 x 2.1GHz Xeon E5-2620 V3 (12-Cores/24-Threads) 64GB DDR4 RAM 4 x 1.92 TB SSD Hardware RAID1 20TB Transfer - 1Gbps Port - Fully Managed FortiGate Firewall with IPS - Server Management - Scheduled Vulnerability Scans - Managed VPN 5 Accounts - Veeam On-site Daily Backups - Veeam Off-site Daily Backups - 4 Hours of Migration Service - Multi-Factor Authentication - Trend Micro Security Suite* - Network Edge Protection* - Load Balancing ### Fortress Enterprise Dedicated Servers Compliance-ready security for regulated and mission-critical workloads $1,702.27 Per Month 2 x 2.6GHz Xeon Gold 6140 (36-Cores/72-Threads) 128GB DDR4 RAM 4 x 1.92TB SSD Hardware RAID10 20TB Transfer - 1Gbps Port - Fully Managed FortiGate Firewall with IPS - Server Management - Scheduled Vulnerability Scans - Managed VPN 5 Accounts - Veeam On-site Daily Backups - Veeam Off-site Daily Backups - 4 Hours of Migration Service - Multi-Factor Authentication - Trend Micro Security Suite* - Network Edge Protection* - Load Balancing ### Fortress Custom Dedicated Servers Maximum security, customization, and premium SLAs Custom Dedicated Servers - Fully Managed FortiGate Firewall with IPS - Server Management - Scheduled Vulnerability Scans - Managed VPN 5 Accounts - Veeam On-site Daily Backups - Veeam Off-site Daily Backups - 4 Hours of Migration Service - Multi-Factor Authentication - Trend Micro Security Suite* - Network Edge Protection* - Load Balancing *$450 setup fee applies *Pricing based upon 12-month term commitment *Prices based upon Linux Operating System. Windows Operating System available at an additional cost. ***Save up to 30% off above listed pricing with longer billing terms*** *Due to global supply-chain volatility, Dedicated Host pricing is subject to change but will be confirmed prior to deployment. ## More Resources ### What Is Dedicated Server Hosting? [Read More >](https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/) ### What Is a Bare Metal Server? Benefits, Use Cases, and Best Practices [Read More >](https://www.atlantic.net/dedicated-server-hosting/what-is-a-bare-metal-server-benefits-use-cases-and-best-practices/) ### Virtual Private Cloud by Atlantic.Net [Read More >](https://www.atlantic.net/cloud-platform/virtual-private-cloud/) ### Managed Private Cloud by Atlantic.Net [Read More >](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/) ## Read More About Dedicated Server Hosting - Atlantic.Net's Dedicated Server Options - Dedicated Hosts on the Atlantic.Net Cloud Platform ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Dedicated Hosts > URL: https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/ | Updated: 2026-09-16 Deploy a configurable physical host in seconds through the Atlantic.Net Cloud Platform, place multiple instances on dedicated hardware, bring eligible software licenses, and launch instances at no extra charge. - Deploy in Seconds via ACP - Multiple Instances per Host - Bring Your Own Licenses - Pay Per Host, Instances Free Provisioning Time: Seconds Global Data Center Locations: 8 ## Dedicated Hosts Dedicated Hosts are perfect for anyone wanting superb performance with the flexibility of cloud interconnectivity all from the same host. All Dedicated Hosts are preloaded with Atlantic.Net's Cloud Platform and can be directly integrated into all Atlantic.Net Cloud services. Dedicated Hardware is also a great choice for any business required to meet regulation and compliance obligations. Atlantic.Net Dedicated Cloud Hosts are a configurable dedicated instance designed to accommodate all of your hosting requirements in one easy package. Rapidly deploy a dedicated host (it literally takes seconds) all via the ACP cloud console. ## What Is a Dedicated Host? A dedicated host is a physical server exclusively allocated to a single user or organization, providing maximum performance, security, and control for resource-intensive applications and sensitive data. ## Dedicated Hosts Pricing Plans | | | | | | | | --- | --- | --- | --- | --- | --- | | D2.B | 128 GB | 6 Cores / 12 Threads (vCPU) @ 3.4GHz | 960 GB SATA RAID 1 | 10 TB | On-Demand: $598/mo $0.89/hr; 1-Year: $386/mo $0.57/hr; 3-Year: $266/mo $0.39/hr | | D5.A | 256 GB | 20 Cores / 40 Threads (vCPUs) @ 2.4GHz | 4.8 TB NVMe RAID 10 | 10 TB | On-Demand: $1,568/mo $2.33/hr; 1-Year: $1,011/mo $1.50/hr; 3-Year: $697/mo $1.03/hr | | DH1.A | 128 GB | 10 Cores / 20 Threads (vCPUs) @ 2.7GHz | 1.6 TB NVMe RAID 1 | 10 TB | On-Demand: $1,671/mo $2.48/hr; 1-Year: $827.82/mo $1.23/hr; 3-Year: $498.73/mo $0.74/hr | | DH2.A | 256 GB | 20 Cores / 40 Threads (vCPUs) @ 2.7GHz | 3.2 TB NVMe RAID 10 | 10 TB | On-Demand: $2,151/mo $3.20/hr; 1-Year: $1,095.58/mo $1.63/hr; 3-Year: $641.53/mo $0.95/hr | | DH2.B | 256 GB | 20 Cores / 40 Threads (vCPUs) @ 2.7GHz | 6.4 TB NVMe RAID 10 | 10 TB | On-Demand: $2,423/mo $3.60/hr; 1-Year: $1,247.07/mo $1.85/hr; 3-Year: $722.32/mo $1.07/hr | | DH2.C | 256 GB | 20 Cores / 40 Threads (vCPUs) @ 2.7GHz | 12.8 TB NVMe RAID 10 | 10 TB | On-Demand: $2,770/mo $4.12/hr; 1-Year: $1,440.49/mo $2.14/hr; 3-Year: $825.48/mo $1.22/hr | | DH3.A | 512 GB | 20 Cores / 40 Threads (vCPUs) @ 2.7GHz | 3.2 TB NVMe RAID 10 | 10 TB | On-Demand: $2,436/mo $3.62/hr; 1-Year: $1,254.13/mo $1.86/hr; 3-Year: $726.09/mo $1.08/hr | | DH3.B | 512 GB | 20 Cores / 40 Threads (vCPUs) @ 2.7GHz | 6.4 TB NVMe RAID 10 | 10 TB | On-Demand: $2,616/mo $3.89/hr; 1-Year: $1,354.39/mo $2.01/hr; 3-Year: $779.56/mo $1.16/hr | | DH3.C | 512 GB | 20 Cores / 40 Threads (vCPUs) @ 2.7GHz | 12.8 TB NVMe RAID 10 | 10 TB | On-Demand: $3,074/mo $4.57/hr; 1-Year: $1,609.68/mo $2.39/hr; 3-Year: $915.72/mo $1.36/hr | | DH4.A | 1024 GB | 20 Cores / 40 Threads (vCPUs) @ 2.7GHz | 3.2 TB NVMe RAID 10 | 10 TB | On-Demand: $2,509/mo $3.73/hr; 1-Year: $1,294.99/mo $1.93/hr; 3-Year: $747.88/mo $1.11/hr | | DH4.B | 1024 GB | 20 Cores / 40 Threads (vCPUs) @ 2.7GHz | 6.4 TB NVMe RAID 10 | 10 TB | On-Demand: $2,724/mo $4.05/hr; 1-Year: $1,414.68/mo $2.11/hr; 3-Year: $811.72/mo $1.21/hr | | DH4.C | 1024 GB | 20 Cores / 40 Threads (vCPUs) @ 2.7GHz | 12.8 TB NVMe RAID 10 | 10 TB | On-Demand: $3,182/mo $4.73/hr; 1-Year: $1,669.96/mo $2.48/hr; 3-Year: $947.87/mo $1.41/hr | | DH5.A | 2048 GB | 40 Cores / 80 Threads (vCPUs) @ 2.7GHz | 3.2 TB NVMe RAID 10 | 10 TB | On-Demand: $2,794/mo $4.15/hr; 1-Year: $1,453.55/mo $2.16/hr; 3-Year: $832.45/mo $1.24/hr | | DH5.B | 2048 GB | 40 Cores / 80 Threads (vCPUs) @ 2.7GHz | 6.4 TB NVMe RAID 10 | 10 TB | On-Demand: $2,951/mo $4.39/hr; 1-Year: $1,541.36/mo $2.29/hr; 3-Year: $879.28/mo $1.31/hr | | DH5.C | 2048 GB | 40 Cores / 80 Threads (vCPUs) @ 2.7GHz | 12.8 TB NVMe RAID 10 | 10 TB | On-Demand: $3,467/mo $5.15/hr; 1-Year: $1,828.52/mo $2.72/hr; 3-Year: $1,032.43/mo $1.54/hr | | DH6.A | 4096 GB | 40 Cores / 80 Threads (vCPUs) @ 2.7GHz | 3.2 TB NVMe RAID 10 | 10 TB | On-Demand: $3,586/mo $5.33/hr; 1-Year: $1,894.91/mo $2.82/hr; 3-Year: $1,067.84/mo $1.59/hr | | DH7.A | 8192 GB | 40 Cores / 80 Threads (vCPUs) @ 2.7GHz | 6.4 TB NVMe RAID 10 | 10 TB | On-Demand: $5,684/mo $8.45/hr; 1-Year: $2,113.76/mo $3.15/hr; 3-Year: $1,184.56/mo $1.76/hr | *Due to global supply-chain volatility, Dedicated Host pricing is subject to change but will be confirmed prior to deployment. ## Looking for a Customized Server? We can build a customized solution for you. Custom Larger Complex Deployments ## A High Performance Dedicated Host, Ready for You in Seconds The deployment process is super simple; it's the exact same way you deploy all other servers available from Atlantic.Net: - Log into the ACP Cloud Console - https://cloud.atlantic.net - Choose the hosting plan you want from the Dedi Hosts menu - Deploy your instance in seconds! ### No Lead Time: Each Dedicated Host Is Available Now! There is no lead time on the dedicated host fleet; each physical server plan is available from the cloud console. Our technical experts can enable your cloud account to have access to over forty customizable plans (if required) on top of the three standard plans available to all. ### Customized Dedicated Host Plans An on-demand dedicated host can utilize the default plan configurations, or you can just call or email us with the physical server CPU cores, RAM, storage needed, and any other requirements, and we will do the rest. Physical dedicated hosts plans can be upgraded as needed. Choose from: System Memory: From 128GB to 8TB of RAM CPU Cores: From 6 to 40+ CPU cores Storage: Up to 12.8TB NVMe RAID 10, and SATA SSD available ACP hosts and dedicated instances are available at all eight of our global data center locations, strategically located throughout the United States, Canada, Asia, and Europe. Each dedicated host plan is competitively priced, and you can transfer eligible software licenses to keep costs down. ### Automatic Instance Placement on the Same Physical Server Atlantic.Net operates an instance placement scheme that allows you to create any dedicated instance on any ACP Dedicated Hosts you have signed up for. With Atlantic.Net's instance placement scheme, you are assigned a Dedicated Host ID automatically via the ACP console, and you can deploy any new dedicated instance directly onto a specific Dedicated Host or any other host you have with Atlantic.Net. Dedicated Hosts enable you to run as few or as many dedicated instances on the same host as you like with multiple instance size support. As your business grows, you can purchase more Dedicated Hosts and split the stack workload between your hosts using instance placement controls. Controlling instance placement is easy from the Atlantic.Net cloud console. ### Licensing Costs - Dedicated Hosts Dedicated Hosts enable greater visibility and access to the physical server hardware. Latency is minimal on our Dedicated Hosts. It's a perfect choice if you opt to bring your own license (BYOL). We know many of our customers have already heavily invested in critical business applications such as Oracle, Microsoft SQL Server licenses, or Exchange Server. BYOL allows you to transfer those licenses onto Atlantic.Net Dedicated Hosts. Simply pick a dedicated host (single host) that has the same physical cores as set out by the terms and conditions of your license fulfillment. ### Dedicated Host Pricing and Billing With a Dedicated Host, you can maximize your investment by deploying multiple dedicated instances on top of your dedicated host with multiple instance-size support. This can be achieved using any of the available one-click applications provided by Atlantic.Net. You can leverage your own virtualization per your preference, for example, via Linux, containerization via Docker, or even by Web Hosting Management (WHM) with applications such as cPanel. Dedicated Host Instance billing is simple and straightforward. All you pay for is the dedicated physical server(s); there is no charge to launch instances, deploy an instance family, or consistently deploy multiple instance types! Unlike most other Cloud Providers, with Atlantic.Net you just pay for the dedicated host! Another great example of why you should choose us when comparing dedicated hosts. ### Windows Server Licensing The only extra charge we have to enforce is to manage licensing for Microsoft Windows Server; this is applied to instances automatically and is required for Microsoft products only. This practice is enforced because Microsoft does require license affinity on Windows Server AMIs. If you have any queries about licensing, please contact the team. Additionally, we offer a generous discount for sustained usage agreements for host billing starting from monthly, one-year, and three-year terms for our on-demand instances. ### Hybrid Cloud Options Launch Cloud instances on your Dedicated Hosts and Atlantic.Net's Public Cloud Platform based on your project needs. Whether you deploy on only one service, both, or even decide to add on a specialized hosting need, Atlantic.Net's Dedicated Host fleet has you covered with all types of hybrid cloud models. ## Dedicated Hosts vs. Cloud Hosting vs. Bare Metal | Feature | Dedicated Hosts | Cloud Hosting | Bare Metal Servers | | --- | --- | --- | --- | | Hardware Access | Exclusive physical server with cloud orchestration | Shared virtualized infrastructure | Exclusive physical server, no virtualization layer | | Deployment Speed | Seconds via ACP console | Seconds via ACP console | Custom provisioning | | Instance Placement | Multiple instances on one physical host | Single instance per deployment | Single tenant, full server | | BYOL Support | Yes – ideal for SQL Server, Oracle, Exchange | Limited | Yes | | Scalability | Live migration to larger hosts | On-demand resize | Upgrade via provisioning | | Billing Model | Pay per host (instances free) | Hourly / monthly per instance | Monthly or custom | | Best For | Multi-instance workloads, BYOL, compliance | Dev/test, bursty apps, rapid scaling | Single-tenant performance, full control | | Compliance | HIPAA, PCI DSS, SOC 2/3, GDPR | HIPAA, PCI DSS, SOC 2/3, GDPR | HIPAA, PCI DSS, SOC 2/3, GDPR | | Uptime SLA | 100% | 100% | 100% | ## Dedicated Host Use Cases Atlantic.Net Dedicated Hosts combine the isolation of physical hardware with the flexibility of cloud orchestration, making them ideal for a wide range of enterprise workloads. ### Database Hosting Run Microsoft SQL Server, Oracle, MySQL, or PostgreSQL on dedicated hardware with guaranteed CPU and memory resources, eliminating noisy-neighbor performance issues. ### BYOL Licensing Transfer existing server-bound software licenses (SQL Server, Windows Server, Oracle, Exchange) to Atlantic.Net Dedicated Hosts and reduce per-core licensing costs. ### Compliance Workloads Meet HIPAA, PCI DSS, SOC 2/3, and GDPR requirements on physically isolated infrastructure with full control over the security configuration of every instance. ### Web Hosting Clusters Host dozens to thousands of websites on a single Dedicated Host using cPanel, WHM, or containerized deployments – paying only for the host, not per instance. ### Virtualization Platforms Deploy Hyper-V, KVM, or Docker containers on dedicated hardware with full root access and the freedom to provision any plan type on the same physical server. ### Hybrid Cloud Deployments Combine Dedicated Hosts with Atlantic.Net cloud instances for a hybrid architecture – run sensitive workloads on dedicated hardware while bursting to the cloud for elasticity. ## Dedicated Host Features: Launch Cloud instances on your Dedicated Hosts and Atlantic.Net's Public Cloud Platform based on your project needs. Whether you deploy only on Dedicated Hosts, set up Dedicated Hosts and Cloud in tandem, or need a customized solution, Atlantic.Net has you covered with a variety of hybrid cloud models. ### Metrics Graphs View usage metrics graphs for all your Cloud Servers and Dedicated Instances on your Dedicated Host. Monitor the physical servers and your instance family on one intuitive interface, offering additional visibility into your environment. ### Bring Your Own Licenses for Software Reduce licensing costs by using your own server-bound software licenses, perfect for Microsoft Windows Server, SQL Server, and other server-bound software licenses. ### Compliance Ready Secure and ready to help you address and meet your compliance and regulatory requirements. Atlantic.Net is an expert in compliance hosting, and we specialize in HIPAA-Compliant and PCI Compliant dedicated physical servers and virtual machines. ### Manage Your Resources View and manage all RAM, CPU, and Disk space in use on your Dedicated Host. It doesn't matter if you have a single dedicated host or a cluster of physical servers; everything can be managed directly from the Atlantic.Net cloud console. ### Provision Any Plan Type Freedom and flexibility to provide any plan. Deploy instances on the same physical server, change your plan, migrate and grow as your business grows. The freedom to provision any plan type and controlling instance placement is hugely popular with our customers. ### Scale Up with Live Migrations Running out of resources? Not a problem; live migrate to a larger dedicated host with no downtime! The Dedicated Host Platform scales as your business grows. Start with a relatively small dedicated host with the option to always upgrade whenever you choose. Enjoy the freedom of being able to migrate dedicated instances or launch instances live between the hosts. ### Optional Backups Daily, Hourly, and 15-Minute Frequency for Onsite and Offsite Backups for your instance. They are a great way to address corporate compliance as well as provide the peace of mind that your critical business data is safe. ## The Advantages of Dedicated Hosts Maximize security and resource isolation with Dedicated Hosts. Atlantic.Net provides the performance and flexibility you need. Reach out to us and let's explore how Dedicated Hosts can exceed your needs. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at sales@atlantic.net. ### Unmatched Performance and Resource Isolation A dedicated server will offer much superior performance as you have exclusive access to the entire server's resources (CPU cores, RAM, storage), especially when compared to shared Virtual Private Servers (VPS). This eliminates the "noisy neighbor" effect, ensuring consistent performance at all times. ### Enhanced Security and Compliance With complete control over your server environment, dedicated hosts are ideal for businesses with strict security and compliance requirements. They are particularly well-suited for industries such as healthcare (HIPAA) and finance (PCI DSS) because you can customize the security controls exactly to your liking. ### Flexibility and Control You have full administrative access (root access) to your dedicated host, allowing you to install and configure any software or operating system that meets your needs. This is crucial for businesses with specific software requirements or custom server configurations. ### Cost-Effectiveness and Licensing Benefits Dedicated hosts can be a cost-effective solution for businesses with heavy software licensing needs (e.g., Microsoft SQL Server, Oracle). You can leverage your existing software licenses (BYOL) and avoid per-user or per-core licensing fees, optimizing your software investment. ### Scalability and High Availability Dedicated hosts can be easily scaled up or down to meet changing business requirements. You can add more resources or even migrate to a larger dedicated host with minimal downtime, ensuring your applications remain available. ### Hybrid Cloud Capabilities Dedicated hosts seamlessly integrate with public cloud platforms, enabling hybrid cloud deployments. You can run cloud instances on your dedicated hosts while leveraging Atlantic.Net cloud services for additional flexibility and scalability. ### Simplified Management and Support Atlantic.Net's dedicated hosts are fully managed, providing 24/7 support and proactive monitoring. This frees you from the complexities of server management, allowing you to focus on your core business. ## Frequently Asked Questions for Dedicated Hosts ### What is the difference between Dedicated Hosts and Dedicated Instances? Dedicated Hosts are dedicated physical servers that reside in the Atlantic.Net data centers. You can purchase one or many Dedicated Hosts. A dedicated instance is a server that runs on the Dedicated Hosts. You can run multiple dedicated instances on a Dedicated Host up to the resource limit of the host. Instance placement controls depend on available physical cores, memory, and disk space being available. ### Do I need a Dedicated Host? Dedicated Hosts are a perfect fit for companies that have hit a certain level of resources and now can receive pricing discounts. Also, a Dedicated Host is ideal for organizations looking to remove all noisy neighbor scenarios or working towards meeting regulation or compliance requirements. ### What are the advantages of a Dedicated Host? Dedicated Hosts will save growing businesses cash, help them address corporate compliance and regulatory requirements, and provide powerful, dedicated resources to their cloud assets. Resources are ring-fenced in a protected environment (perfect to address corporate compliance) meaning only your servers have 100% resource guarantees – there are no noisy neighbors here! ### How many websites can I manage on the same physical server? The number of websites will depend on many different factors. Are you including the possibility of additional plugins in your scope? Are you utilizing cPanel and WordPress solely or allowing other types of software? Atlantic.Net's Dedicated Hosts range greatly in terms of vCPUs, RAM, and Disk Space, so the size of Dedicated Host will affect how many sites you are able to host. Some of our largest customers utilize a cluster of Dedicated Hosts for one website, while other resellers will use one Dedicated Host to serve up to 1,000 websites. ### Why should I buy Dedicated Hosts from Atlantic.Net? ACP's Dedicated Hosts provide options and scalability to your business while also aiding in obtaining and meeting compliance requirements and regulations. The unmatched performance of our Dedicated Hosts, term pricing, and Atlantic.Net's 24x7 support are the reasons why Atlantic.Net has one of the lowest customer churn rates in the industry when comparing Dedicated Hosts! Atlantic.Net also has Managed Services that enable our engineers to help with issues your team may run into with your Dedicated Host that are outside our scope of support. We pride ourselves on never saying "no" and always providing a path forward. ### When would you use Dedicated Hosts? Dedicated Hosts have many use cases; they are a great fit for small and medium databases (such as SQL Server) and for businesses that need guaranteed baseline CPU performance. Perhaps you have existing Dedicated Hosts you want to offload individual services to improve performance on your stack. Dedicated Hosts are great at hosting virtual machines of varying instance sizes. Hyper-V on Windows Server is a popular choice for a specific Dedicated Host, as Microsoft offers generous per VM software licenses if you choose Windows Server. As a result, you can run an entire Windows-based Hyper-V platform only paying for software licenses against each host – these benefits save money. ### Which operating system options are available as dedicated instances? Linux Operating Systems: CentOS, Ubuntu, Rocky, Fedora, Debian, Oracle Linux, Rocky Linux, Arch Linux, and FreeBSD. Windows Operating Systems: Windows Server 2016, Windows Server 2019, and Windows Server 2022. ### How do I assess the reliability of dedicated hosting providers? Look for a real SLA, strong uptime commitments, reliable hardware replacement policies, 24/7 support, proactive monitoring, and infrastructure designed for redundancy. A reliable dedicated hosting provider should be able to support both performance and operational continuity, not just raw server specs. ### Does Atlantic.Net offer bare-metal dedicated servers with no setup fees? Yes. Atlantic.Net offers bare-metal dedicated servers, and there is no setup fee for our dedicated hosting solutions. ### Does Atlantic.Net offer both managed and unmanaged dedicated server plans? Yes. Atlantic.Net offers both managed and unmanaged dedicated server options, so you can choose whether you want Atlantic.Net to handle day-to-day server operations or keep full responsibility in-house. ### Does Atlantic.Net's dedicated hosting support custom hardware configurations? Yes. Atlantic.Net supports custom dedicated server configurations, which is useful when you need specific CPU, memory, storage, or security requirements. ### Can I buy dedicated servers with DDoS protection included? Atlantic.Net offers DDoS protection for dedicated servers, but it is best treated as an added security service rather than something you should assume is included by default with every server. ### What are the key benefits of using a dedicated server over a VPS? A dedicated server gives you exclusive access to the hardware, more predictable performance, deeper control over security and configuration, and better isolation from other workloads. It is usually the better choice when performance consistency, compliance, or full administrative control matters more than the lower entry cost of VPS hosting. ### How many virtual machines can fit on a Dedicated Host? The number of virtual machines you can fit on a dedicated host depends on the physical server's resources (CPU cores, RAM, storage), the resource requirements of each VM, and the virtualization software you use. Different virtualization technologies have varying levels of overhead, impacting the number of VMs that can be efficiently supported. ## Read More About Dedicated Server Hosting ### [Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/) - [Dedicated Server Hosting Plans](https://www.atlantic.net/dedicated-server-hosting/) - [Atlantic.Net's Dedicated Server Options](https://www.atlantic.net/dedicated-server-hosting/) ## Cloud Availability in Multiple Global Regions Deploy close to your users from eight international data centers worldwide, with new regions on the way. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # USA Bare Metal Server Hosting > URL: https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/ | Updated: 2026-09-16 Run demanding workloads on single-tenant physical servers with direct access to dedicated CPU, RAM, storage, and networking, no virtualization overhead, configurable Intel Xeon or AMD EPYC processors, and 24/7/365 USA-based support. - Single-Tenant Dedicated Hardware - No Virtualization Overhead - Full Root Access - 24/7/365 Expert Support Virtualization Overhead: None USA-Based Expert Support: 24/7/365 ## Bare Metal Servers Tired of sharing resources in the cloud? Bare metal servers put you back in control. No more noisy neighbors hogging CPU or memory – you get the full power of the server, dedicated solely to your applications. Businesses are investing heavily in Bare Metal options, especially in recent years to accommodate the surge in hardware components needed for AI-based applications and Large Language Modeling. ## Bare Metal Server Hosting Plans When your applications demand raw power and uncompromising high performance computing, dedicated bare metal servers reign supreme. Unlike shared environments or virtualized cloud server instances, bare metal gives you exclusive access to the entire server's dedicated hardware resources. Atlantic.Net's bare metal servers are housed in SOC 2 and HIPAA-compliant, USA-based data centers. Compare our bare metal plans and choose the perfect fit for your needs: ### BM.C1 Bare Metal Hosting 1 Year Term: $315.84 Per Month ($0.47/hr); 2 Year Term: $282.24 Per Month ($0.42/hr); 3 Year Term: $248.64 Per Month ($0.37/hr) - 1 x Intel Xeon E-2236 @ 3.4GHz - 6 Cores / 12 Threads - 64GB RAM - 2 x 480GB SATA - 10TB Data Transfer ### BM.C2 Bare Metal Hosting 1 Year Term: $618.24 Per Month ($0.92/hr); 2 Year Term: $544.32 Per Month ($0.81/hr); 3 Year Term: $483.84 Per Month ($0.72/hr) - 2 x Intel Xeon Gold 6140 @ 2.3Ghz - 36 Cores / 72 Threads - 128GB RAM - 4 x 1920GB SATA - 10TB Data Transfer ### BM.C3 Bare Metal Hosting 1 Year Term: $806.40 Per Month ($1.20/hr); 2 Year Term: $705.60 Per Month ($1.05/hr); 3 Year Term: $624.96 Per Month ($0.93/hr) - 2 x Intel Xeon Gold 6140 @ 2.3Ghz - 36 Cores / 72 Threads - 256GB RAM - 4 x 3840GB SATA - 10TB Data Transfer ### Custom Bare Metal Hosting Custom Bare Metal Hosting Tailored CPU, RAM, storage, and networking built to fit your exact workload. $150 setup fee applies. The fee is waived with a 12-month or longer-term commitment. For custom server configurations, setup fees may vary based on specific requirements. *Prices listed above are based on the term selected. *Prices based upon Linux Operating System. Windows Operating System available at an additional cost. ***Save up to 30% off above listed pricing with longer billing terms*** *Due to global supply-chain volatility, Bare Metal pricing is subject to change but will be confirmed prior to deployment. ## Custom Bare Metal Servers Not finding the server solution to meet your needs? Send a quote request with your specific requirements, and our sales team will gladly help you with the ideal solution. ## What Is a Bare Metal Server? A bare metal server is a dedicated physical server rented exclusively to a single customer. Unlike virtual servers, bare metal hosting provides direct access to the server's CPU, RAM, storage, and network resources without a virtualization layer, resulting in predictable performance and full hardware control. - Single-tenant physical hardware - No virtualization overhead - Full root access - High performance and predictable workloads ## Bare Metal Server Hosting A Bare Metal Server, also known as a dedicated server, is a physical computer rented exclusively to a single user or organization. It is a distinct piece of physical hardware, rather than a virtual server or virtual machine that runs on shared computing resources. Atlantic.Net has bare metal colocation centers throughout the United States. Customers lease Bare Metal from us for several reasons. Firstly, there is no need to purchase expensive servers, storage, or GPUs. The upfront costs with leasing are a fraction of purchasing the hardware resources outright. Secondly, our customers have the freedom to install the operating systems and applications that best suit their needs directly onto the Bare Metal Server. Your teams can procure licenses for whatever software your business needs. You can also reach out to Atlantic.Net for licensing, we have close relationships with some of the biggest software providers in the Industry. Bare Metal Hosting services offer stand-alone machines. These are distinct from dedicated cloud servers as they are not typically integrated with the public cloud. Think of it as a server, that's built and installed in our data centers. Once you lease the device, we give you access to the server and any assistance needed to get the server operational. You can pick either an off-the-shelf configuration or perhaps customize your very own supercomputer. ### What Is Bare Metal Server Hosting? Bare metal server hosting is a managed service from specialist MSPs like Atlantic.Net who focus on renting a physical server and providing direct access to the server hardware components. This service offers businesses optimal server performance and customization, ideal for handling demanding workloads. Customers are free to use the server as they wish, and if needed, the servers can be integrated into Atlantic.Net managed services, offering a blend of dedicated hardware and cloud service benefits. ### Dedicated Server Hosting Plans Our Bare Metal Hosting plans are configurable to your needs. You can either utilize the default hosting plan configuration or contact us with your RAM and disk space needs, and we will do the rest. Our hosting plans can be upgraded to fit your growing requirements, and you can choose servers with resources from a wide range of deployable resources. Each Bare Metal Hosting plan is competitively priced against other bare metal providers, and we offer generous discounts for contracted terms with either one, two, or three-year terms. ## Bare Metal Server Hosting Features ### Intel Bare Metal Servers Our bare metal offerings include servers built on the powerful Intel Xeon Scalable and Xeon E-series processors. These platforms provide a flexible and reliable platform with guaranteed access to all physical resources. With high-speed cores and threads, Intel servers are ideal for a wide range of business applications, web hosting, and multi-user apps that require consistent, reliable performance and burst capabilities. ### AMD Bare Metal Servers We also offer bare metal servers featuring the high-performance AMD EPYC™ series processors. These servers provide exceptional core density and memory bandwidth, making them a great option for computationally intensive tasks, large databases, virtualization, and big data analytics. AMD's architecture delivers the raw power needed for the most demanding workloads, but best of all, it provides an incredibly cost-effective path to elite performance. ## USA Bare Metal Server Hosting Our infrastructure is strategically located in data centers throughout the United States, Canada, Asia, and Europe. Bare Metal Hosting is available in select data center regions. Our data center regions are concentrated in the United States of America, including New York, San Francisco, Dallas, Ashburn, and Orlando. Atlantic.Net holds SOC 2 Type II, HIPAA, and PCI DSS certifications and was recognized by Cyber Defense Magazine as Most Innovative Cloud Hosting Provider (2025). Our USA-based support staff stands ready to assist you 24/7/365 with all your Bare Metal Hosting needs. ## A Single Tenant Environment Bare Metal Servers are single-tenant physical servers. This means you avoid the performance interference often found in shared hosting environments. You have root access to the hardware of the dedicated server, giving complete control over your leased physical servers. This allows you to create a custom server platform, maximizing performance and eliminating the overhead often found with virtual machines. You have the freedom to host any service or application you choose. ## Bare Metal Hosting Benefits Bare Metal Servers provide several benefits, including: ### 1: Isolation Layer 2 network virtualization can isolate customer workloads from other customer activity. Bare Metal Servers offer a high degree of isolation, which is important for meeting stringent security and compliance requirements. Layer 2 network virtualization allows customer workloads to be completely isolated from other tenants, ensuring that data and applications are secure from potential threats that might come from shared virtual environments. This isolation also means that performance is not impacted by the activities of other users, providing consistent and reliable service. This makes it suitable for running sensitive applications and storing critical data. ### 2: Control Unlike virtualized environments, Bare Metal Servers do not come with a pre-installed hypervisor, allowing users to have complete control over their server infrastructure. This means you can choose and install the operating system that best fits your needs, as well as any applications and software configurations without any limitations imposed by a hypervisor. The added control also extends to hardware configurations and network settings, providing the flexibility to optimize the server's performance for specific workloads. You can tailor the server environment to meet unique requirements, ensuring that the infrastructure is aligned with your operational goals. ### 3: Visibility Private cloud customers can have greater visibility into the underlying infrastructure of a Bare Metal Server within the cloud services. Bare Metal Servers provide enhanced visibility into the underlying infrastructure of virtual private servers, which is particularly beneficial for private cloud customers. Having an increased visibility allows you to monitor and manage the server environment more effectively, gaining insights into performance metrics, resource utilization, and potential bottlenecks. Such transparency also aids in security management. You can track access logs, network traffic, and other critical data points, enabling you to detect and respond to security threats swiftly. ### 4: Processing Power Having dedicated resources ensures consistent performance, supporting large, steady-state workloads. Since the resources of a Bare Metal Server are dedicated to a single tenant, there are no resource contention issues, resulting in consistent and reliable performance across multiple servers. This makes it suitable for running high-performance computing applications, data-intensive tasks, and other demanding workloads that require significant processing power. ## Buy Bare Metal Server Hosting with Full Confidence Get the speed, convenience, and peace of mind you deserve with Atlantic.Net Bare Metal Hosting. We build and deploy standard and custom-hosted servers for our clients who require full control and root access. Our clients benefit by leveraging additional resources available on the Atlantic.Net Cloud Platform for expansion, additional compute, additional storage, and more! Our Bare Metal Hosting Service is flexible, giving your business the power over the server with Atlantic.Net standing ready to assist you. Our engineers are always standing by for your call, or you can trust your expertise and use root access to fix any technical issues you may encounter. Our Hosting is designed to wrap around your requirements while also offering the ability to pick and choose our Managed Service offerings like Firewall, Intrusion Detection, Server Management, Onsite and Offsite Backups, Replication, and much more! Harness the raw power of Bare Metal Servers, each configurable to your exact needs. Atlantic.Net delivers unmatched flexibility and high-performance hardware now. Contact us to configure your custom solution. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at sales@atlantic.net. ## Bare Metal vs Cloud vs Dedicated Cloud Hosts: Infrastructure Performance Comparison | Infrastructure Feature | Bare Metal Server | Virtual Cloud Server | Dedicated Cloud Host | | --- | --- | --- | --- | | Hardware Access | Direct access to physical CPU, RAM, storage, and network hardware | Virtualized resources shared across multiple tenants | Dedicated hypervisor host running isolated virtual machines | | Performance Consistency | Maximum and fully predictable performance with no hypervisor overhead | Performance may fluctuate depending on shared resource usage | High performance with reserved host resources | | Virtualization Layer | No hypervisor – runs directly on physical hardware | Runs on a shared hypervisor platform | Runs on a dedicated hypervisor host | | Isolation Level | Complete single-tenant hardware isolation | Multi-tenant environment | Single-tenant host with isolated virtual machines | | Scalability | Vertical scaling by upgrading physical hardware | Rapid horizontal and vertical scaling | Scalable VM workloads within a dedicated host environment | | Compliance & Security | Ideal for strict compliance environments (HIPAA, PCI DSS, SOC 2) | Compliance depends on shared infrastructure policies | Strong compliance posture with dedicated host isolation | | Typical Workloads | AI/ML training, large databases, GPU workloads, high-performance computing | Web apps, SaaS platforms, development environments | Enterprise cloud, hybrid deployments, large application clusters | | Resource Contention | None – resources are fully dedicated | Possible due to multi-tenant resource sharing | Minimal – resources dedicated at host level | | Management Flexibility | Full root access with complete hardware control | Limited to virtual machine configuration | Control over VM clusters on a dedicated host | | Summary | Best for maximum performance, AI workloads, and compliance-sensitive applications. | Best for flexible cloud workloads and rapid scaling. | Best for hybrid environments needing dedicated infrastructure with cloud flexibility. | ## Why Choose Atlantic.Net Bare Metal Servers - Single-tenant dedicated hardware - Intel Xeon and AMD EPYC processors - High-performance NVMe and SSD storage - Global data centers in the US, Canada, Europe, and Asia - 24/7/365 expert support - Optional managed services and security solutions ## Common Use Cases for Bare Metal Servers - AI and machine learning workloads - High-traffic websites and ecommerce platforms - Large databases and analytics systems - Virtualization and private cloud infrastructure - Compliance-regulated workloads (HIPAA, PCI DSS) - Game hosting and low-latency applications ## Bare Metal FAQ ### How do you choose between bare metal and virtualized hosting? Pick bare metal when you need raw performance and complete customization over the server hardware. Pick a virtualized host when you are happy with great performance, but are not concerned about the virtualization overhead. Virtualized still gives plenty of performance, but bare metal is the way to go if you have mission-critical workloads. ### Does affordable bare-metal hosting typically include fast NVMe storage? NVMe is usually standard on bare-metal servers; however, it depends on the hosting provider. Bare Metal flexibility lets you configure the server exactly as you need. Perhaps you need NVMe for the Operating System and/or Database, but you are happy with mechanical drives for database flat file archives. Bare Metal gives you this flexibility in abundance. ### Will my bare metal cloud hosting plan offer full root access? Yes. With bare metal, you are configured as the system administrator. You get full root access and have complete control over the underlying hardware and the operating system. ### Which industries use bare-metal hosting for compliance and performance? Bare Metal is very popular with small, medium, and large businesses. At Atlantic.Net, bare metal is particularly popular with our HIPAA hosting clients, cPanel resellers, and our Financial and Legal Customers. Developers prefer bare-metal options with AI GPUs for advanced analytics and private LLMs. ### How do you migrate from cloud to bare metal infrastructure? The migration path from cloud to bare metal depends on the workload, application architecture, and business requirements. In many cases, we perform lift-and-shift migrations or virtualized-to-physical migrations for existing customers. For new customers, we provide [Managed Migration Services](https://www.atlantic.net/managed-services/migration-services/) with a structured migration process that includes discovery, infrastructure planning, secure data migration, server provisioning, environment hardening, testing, and final cutover. ### Do single-tenant bare metal environments typically offer DDoS protection? Yes, at Atlantic.Net, [DDoS protection](https://www.atlantic.net/managed-services/network-edge-protection/) is available as an optional configurable service. We offer a class-leading network-edge service with one of the most reliable DDoS detection and protection solutions available. ### What are the benefits of using bare metal servers for databases? Local databases are a perfect fit for bare-metal servers. Databases are designed to function in memory with extensive access to CPU and disk resources. On bare metal, there is no contention, making high-performance, ultra-low-latency databases easy to achieve. ### Is bare metal hosting the best option for high-performance workloads? Yes–bare metal is designed for high performance, offering dedicated hardware and consistent resources. That said, whether it is the best option depends on your specific workload and scaling needs. ### Can I get bare metal servers with instant provisioning? Yes, some bare metal providers offer fast or near-instant provisioning. However, actual setup time depends on the server configuration, availability, and any custom requirements. If you need instant provisioning, perhaps a dedicated [cloud server](https://www.atlantic.net/cloud-platform/cloud-hosting/) or a [dedicated cloud](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) host would be a better fit. ### Which providers offer bare-metal servers with custom OS installations? Many providers offer custom OS installs, including Atlantic.Net. Availability may vary based on hardware, operating system compatibility, and setup needs, so it is best to confirm your exact OS or image requirements when ordering. ### Do bare metal servers come with custom OS installs? Bare-metal servers can support custom OS installations, depending on the hardware configuration, operating system compatibility, and deployment requirements. Atlantic.Net offers flexible bare metal solutions, and custom OS installation options are available based on your specific setup needs. ## See Additional Guides on Key Hybrid Cloud Topics Together with our content partners, we have authored in-depth guides on several other topics that can also be useful as you explore the world of hybrid cloud. ### [Data Migration](https://www.atlantic.net/managed-services/migration-services/) Authored by Atlantic.Net - [[Guide] Custom Migration Services from Atlantic.Net](https://www.atlantic.net/managed-services/migration-services/) - [[Guide] Best Cloud Migration Solution](https://www.atlantic.net/vps-hosting/best-cloud-migration-solution/) - [[Blog] Cybersecurity Lessons Learned and Best Practices](https://www.atlantic.net/dedicated-server-hosting/lessons-learned-in-2022-about-cybersecurity-for-2023-and-beyond/) - [[Product] Atlantic.Net Cloud Platform | Scalable, Secure Cloud Solutions](https://www.atlantic.net/cloud-platform/) ### [PCI Compliant Hosting](https://www.atlantic.net/pci-compliant-hosting/) Authored by Atlantic.Net - [[Guide] PCI Compliant Hosting Solutions](https://www.atlantic.net/pci-compliant-hosting/) - [[Guide] PCI DSS Cybersecurity Requirements](https://www.atlantic.net/pci-compliant-hosting/what-is-pci-compliance/) - [[Blog] How to Secure SSH Server on Arch Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-secure-ssh-server-on-arch-linux/) - [[Product] Atlantic.Net Cloud Platform | Scalable, Secure Cloud Solutions](https://www.atlantic.net/cloud-platform/) ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Managed Private Cloud > URL: https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/ | Updated: 2026-09-16 Run enterprise workloads on single-tenant dedicated virtualization infrastructure with your choice of Hyper-V, VMware, or KVM, backed by 24/7/365 management, monitoring, and support. - Hyper-V, VMware, or KVM - Up-to-OS Management - Built-In Replication & Failover - Self-Service VM Portal Management, Monitoring & Support: 24/7/365 Supported Hypervisors: 3 ## Managed Private Cloud by Atlantic.Net Tap into the best technologies available through Managed Virtualization. Atlantic.Net's Managed Virtualization provides a flexible managed private cloud hosting solution that utilizes enterprise-level hardware running industry standard hypervisor software. This allows you to decrease operational costs compared to dedicated hosting, improve system resource utilization, and maintain greater control over your growing infrastructure. Supported Managed Private Cloud Hypervisors Not every virtualized environment is the same. Our goal is to deploy the best solution for you! Regardless of which hypervisor you choose, we manage and support your virtualized configuration, 24x7x365. ## Secure Cloud Hosting Plans ### Fortress Standard Cloud Hosting - Linux Secure, isolated infrastructure with essential protections $373.24 Per Month 4 CPU's 16 GB of Ram 100 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - cPanel 5 Account License - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Fortress Business Cloud Hosting - Linux Enhanced security layers and hardened configurations $744.88 Per Month 8 vCPU's 32 GB of Ram 300 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - cPanel 5 Account License - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Fortress Enterprise Cloud Hosting - Linux Compliance-ready security for regulated and mission-critical workloads $1,468.75 Per Month 8 vCPU's 64 GB of Ram 500 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - cPanel 5 Account License - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Fortress Custom Fortress Custom Cloud Hosting Maximum security, customization, and premium SLAs Custom Cloud Hosting - Onsite Daily Backups - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Fortress Standard Cloud Hosting - Windows Secure, isolated infrastructure with essential protections $385.22 Per Month 4 CPU's 16 GB of Ram 100 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Fortress Business Cloud Hosting - Windows Enhanced security layers and hardened configurations $799.57 Per Month 8 vCPU's 32 GB of Ram 300 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Fortress Enterprise Cloud Hosting - Windows Compliance-ready security for regulated and mission-critical workloads $1,786.89 Per Month 8 vCPU's 64 GB of Ram 500 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement *$150-$300 setup fee applies *Pricing based upon 12-month term commitment, and month to month option is available with a 20% premium. ***Save up to 30% off above listed pricing with longer billing terms*** These plans do not include HIPAA Compliant Hosting. You can choose a HIPAA Hosting plans by clicking here. ## What is Managed Private Cloud? A managed private cloud provides organizations with dedicated cloud infrastructure managed by a third-party server hosting provider. A managed private cloud is generally a dedicated cloud server reserved for a single user and managed by a managed service provider (MSP). The cloud server could be a single stand-alone server or an array or multiple private cloud servers in a cluster for the sole use of a single customer. What Is Included with a Managed Private Cloud? With a managed private cloud, the MSP provides additional services to include server deployment, system updates, clustering, configuration, operating system management, ongoing support, server administration, monitoring, maintenance, provisioning hypervisor, system updates, backup, replication, setting up failover systems, load balancing, and more. ## Managed Private Cloud Features ### System Environment Up-to-OS management and support. Active administration of host server resources, including CPU, network, and hard disk utilization. ### Advanced Certifications Microsoft Certified Professionals, and Red Hat Enterprise Linux Certified Engineers on staff to assist with all VM design, configuration, and deployment. ### VM Provisioning VM creation, cloning, and removing. Initial private networking setup and VLAN tagging (to segment traffic between individual VMs). A self-service portal enables you to start, stop, and console in to any configured VM. ### System Updates Prior to updating the host server, each new update is reviewed and tested to ensure that there are no issues with the system. Any necessary restarts will be scheduled. Hyper-V deployments make use of cluster aware updating, ensuring 100% uptime while updating each node in the cluster. ### Replication and Failover Virtual Machine replication is designed to provide cross-node fault tolerance by increasing the necessary storage, memory, and CPU requirements for a separate dedicated computing node. Having these resources dedicated and waiting allow for a Low Recovery Point Objective (RPO). ### Advanced Monitoring SNMP and hypervisor specific system performance monitoring to ensure hardware and host servers functioning. Customized monitoring available for memory, CPU, load average, network, I/O, and drive health monitors. ### Clustering Offers the ability to migrate VM to another host server in case of system failure or load balancing between servers. Allows for redistribution of Virtual Machines amongst multiple host servers and the ability to configure a shared storage node to provide VM Hypervisor management and automated failover of a clustered computing node. This is done by increasing memory/CPU per computing node, since VM hard disks are located on a shared storage. ### Additional VM Services Atlantic.Net will ensure your hardware, virtualization hypervisor, and all VMs are always functioning properly. If you encounter an issue relating to OS-level or system configuration, our certified professionals can assist you under a consulting agreement. ### World Class Managed Private Cloud Infrastructure Our state-of-the-art SOC 2 TYPE II and SOC 3 TYPE II certified data center infrastructure is monitored 24/7/365 by our network operations center. Your virtualized server infrastructure is housed in our secure, climate-controlled facility with multiple direct connections to the Internet backbone. ## Get Help with Managed Private Cloud Whether you are looking to free-up resources to bring focus to your core business or need additional resources to help you cope with growth, Atlantic.Net stands ready to assist you with Managed Private Cloud services and solutions. Atlantic.Net can help you provision and manage your own private cloud environment with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282), or email us at sales@atlantic.net. ## Managed Private Cloud vs Public Cloud vs Dedicated Hosting | Infrastructure Feature | Managed Private Cloud | Public Cloud | Dedicated Hosting | | --- | --- | --- | --- | | Tenancy | Single-tenant dedicated virtualization host | Multi-tenant shared infrastructure | Single-tenant physical server | | Management | Fully managed by MSP (hypervisor, OS, updates, monitoring) | Self-managed or partially managed by cloud provider | Self-managed or optional managed services | | Hypervisor Support | Choice of Hyper-V, VMware, or KVM | Provider-defined hypervisor (no choice) | No hypervisor – runs directly on physical hardware | | Scalability | VM-level scaling within dedicated host capacity | Rapid horizontal and vertical scaling on demand | Vertical scaling by upgrading physical hardware | | Performance Consistency | Predictable – dedicated resources with no noisy neighbors | Variable – shared resources may cause contention | Maximum – direct hardware access with no virtualization overhead | | Replication & Failover | Built-in VM replication, clustering, and automated failover | Provider-dependent availability zones and redundancy | Requires separate backup and DR configuration | | Compliance | Ideal for HIPAA, PCI DSS, SOC 2 with managed compliance support | Depends on provider shared-responsibility model | Strong compliance posture with full hardware isolation | | Typical Workloads | Enterprise apps, multi-VM environments, compliance-regulated workloads | Web apps, SaaS platforms, dev/test environments | AI/ML, large databases, GPU workloads, high-performance computing | | Operational Overhead | Low – MSP handles infrastructure management | Medium – self-service with provider tools | High – customer manages all server operations | | Summary | Best for organizations needing dedicated infrastructure with full management and compliance support. | Best for flexible, on-demand workloads with rapid scaling. | Best for maximum performance and complete hardware control. | ## Why Choose Atlantic.Net Managed Private Cloud - Single-tenant dedicated virtualization infrastructure - Choice of Hyper-V, VMware, or KVM hypervisors - 24/7/365 management, monitoring, and support by certified engineers - SOC 2 Type II and SOC 3 Type II certified data centers - Built-in VM replication, clustering, and automated failover - Compliance-ready for HIPAA, PCI DSS, and SOC requirements - Self-service portal for VM start, stop, and console access - Global data centers in the US, Canada, Europe, and Asia ## Common Use Cases for Managed Private Cloud - Enterprise application hosting with multi-VM architectures - Healthcare and HIPAA-regulated workloads requiring managed compliance - Financial services and PCI DSS environments - Development, staging, and production environment separation - Disaster recovery and business continuity with VM replication - Organizations migrating from on-premises virtualization to a hosted model - Businesses needing dedicated infrastructure without in-house server management ## Managed Private Cloud FAQ ### What hypervisors does Atlantic.Net support for managed private cloud? Atlantic.Net supports three industry-standard hypervisors: Microsoft Hyper-V, VMware, and KVM. Our team will help you select and deploy the best hypervisor for your specific workload requirements, and we manage and support your virtualized configuration 24/7/365. ### How does managed private cloud differ from dedicated hosting? Dedicated hosting provides a single physical server with direct hardware access and no virtualization layer. Managed private cloud runs on dedicated hardware but adds a hypervisor layer, enabling you to create, clone, and manage multiple virtual machines on a single host or cluster. Atlantic.Net fully manages the hypervisor, OS updates, monitoring, and failover, reducing your operational overhead. ### Is managed private cloud suitable for HIPAA and PCI compliance? Yes. Atlantic.Net's managed private cloud infrastructure is housed in SOC 2 Type II and SOC 3 Type II certified data centers and is well-suited for HIPAA, PCI DSS, and other compliance-regulated workloads. Single-tenant isolation, managed security updates, and 24/7 monitoring all contribute to a strong compliance posture. ### What level of management does Atlantic.Net provide? Atlantic.Net provides up-to-OS management, which includes hypervisor provisioning, system updates, clustering, VM replication, failover configuration, SNMP monitoring, and hardware management. For OS-level or application-specific support beyond the standard scope, our certified professionals can assist under a consulting agreement. ### Can I manage my own virtual machines on a managed private cloud? Yes. Atlantic.Net provides a self-service portal that enables you to start, stop, and console in to any configured VM. While we handle the underlying infrastructure, hypervisor management, and updates, you retain full control over your virtual machines and the applications running inside them. ### Does managed private cloud include disaster recovery and failover? Yes. Atlantic.Net's managed private cloud includes VM replication designed for cross-node fault tolerance, allowing for a low Recovery Point Objective (RPO). Clustering capabilities enable automated failover between host servers, and shared storage configurations ensure your VMs can migrate seamlessly in the event of hardware failure. ### How do I migrate my existing infrastructure to a managed private cloud? Atlantic.Net provides [Managed Migration Services](https://www.atlantic.net/managed-services/migration-services/) with a structured process that includes discovery, infrastructure planning, secure data migration, VM provisioning, environment hardening, testing, and final cutover. Whether you are migrating from on-premises virtualization or another hosting provider, our team will ensure a smooth transition. ### What monitoring is included with managed private cloud? Atlantic.Net provides SNMP and hypervisor-specific system performance monitoring around the clock. This includes customized monitoring for memory, CPU, load average, network throughput, I/O performance, and drive health. Our network operations center monitors your infrastructure 24/7/365 to detect and resolve issues proactively. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Atlantic.Net Orlando Colocation Data Center > URL: https://www.atlantic.net/orlando-colocation-hosting-data-center/ | Updated: 2026-09-16 House your business-critical hardware in a 129,000+ square-foot, carrier-neutral Orlando facility with redundant power and cooling, diverse connectivity, compliance-ready deployment options, and 24x7x365 security and remote hands. - Cabinets, Cages & Private Suites - N+1 Generators & Mechanical Systems - Key Card & Biometric Access - 100% Uptime SLA Facility: 129,000+ sq ft Campus: 16 acres ## Orlando Colocation Hosting Data Center You have invested real time and money in the hardware that powers your business. Protect that investment with Atlantic.Net colocation hosting in Orlando, Florida, now housed within a 129,000+ square-foot, carrier-neutral facility operated by CoreSite, an American Tower Company. The Orlando data center sits on a 16-acre campus with access to internet exchanges reaching South America and multiple connectivity options for low-latency regional and global reach. It is purpose-built for healthcare service providers, SaaS platforms, application service providers, and other bandwidth-intensive businesses that need rapid access to a high-performance network and data center infrastructure. Whether you need a single cabinet or a private cage, Atlantic.Net Orlando colocation gives you the physical security, power redundancy, and compliance posture to run business-critical workloads with confidence. The facility is staffed 24x7x365 with qualified security personnel and offers technical remote hands and customer service support. ## Orlando hosts all of Atlantic.Net's class-leading services, including: ### Cloud Hosting Services ### HIPAA Compliant Hosting ### Infrastructure-as-a-Service ### Managed Services ### Dedicated Hosts ### Dedicated and Bare Metal Hosting ## Fully Customizable Hosting We not only provide colocation hosting in a secure data center, but we also provide a set of diverse cloud services to help you take your IT infrastructure to the next level. The Atlantic.Net Cloud Platform is engineered to provide fault-tolerant and ultra-fast performance to drive your computing strategy into the future. The Atlantic.Net Cloud is revolutionizing the IT landscape with an all-inclusive pricing, world-class infrastructure, all backed by expert advisors and always available support team via phone or email. Our highly available Cloud Platform includes award-winning Cloud Servers, Secure Block Storage, one-click applications, DNS, dedicated private nodes, USA dedicated servers, private networking, RESTful API, data backup, a full suite of managed services, and more. ## Carrier-Neutral Connectivity The Orlando data center is a carrier-neutral facility with diverse points of entry and multiple top-tier network providers. Atlantic.Net continuously monitors network connectivity to deliver the highest quality infrastructure, bandwidth, and redundancy available. Interconnection options include: - Software-Defined Networking: Open Cloud Exchange for on-demand, private connections to cloud and network providers - Peering Exchanges: Any Exchange for internet peering - Enterprise Internet: Blended IP from 10Mbps to 10Gbps - Cross Connects: Single-mode fiber (SMF) - Diversity: Diverse points of entry (POE) ## Compliance and Certifications The Orlando data center holds the following certifications and audit reports: ### SOC 1 Type 2 Financial reporting controls ### SOC 2 Type 2 Security, availability, and confidentiality controls ### ISO 27001 Information security management ### NIST 800-53 Federal Security Framework ### PCI DSS Payment Card Industry Data Security Standard ### HIPAA Protected health information safeguards The Atlantic.Net Orlando colocation supports specialized compliance hosting, from PCI-compliant e-commerce environments to HIPAA-compliant healthcare infrastructure. Atlantic.Net provides a legally binding Business Associate Agreement (BAA) for customers handling electronic Protected Health Information (ePHI). No matter how sensitive your data is, it will be protected. All racks, servers, and cages are monitored around the clock and housed within an audited, compliance-ready environment. ## Colocation Options ### Private Cage Colocation Designed for enterprise-level requirements, private cages are tailored to fit any space, data, and power configuration. With access to a multi-million-dollar infrastructure, cages are the right choice for large enterprises or organizations with strict physical isolation requirements. ### Cabinet Colocation For businesses that need data center-grade housing without a full cage, cabinet colocation offers a scalable, customizable option. Available in multiple configurations, cabinets can be sized to your exact requirements and expanded as your business grows. ### Additional Colocation Services AC and DC power circuits Antenna and rooftop space available Turn-key fitout Secure parking, WiFi, office space, and conference rooms on-site ## Building | Specification | Detail | | --- | --- | | Square Footage | 129,000+ | | Campus | 16-acre site | | Deployments | Cabinets, cages, and private suites; rooftop space available | | Fitout | Turn-key | | Power Availability | AC and DC | | Floor Load Capacity | Raised floor loading: 1,250 lbs per tile, up to 2,000 lbs per tile in select areas | | Clear Height | 10 ft above 36-inch raised floor to ceiling; 22 ft from slab to roof deck | ## Security | Specification | Detail | | --- | --- | | Access Control | Key cards and biometric scanners; controlled data center access | | Cameras | Perimeter and interior IP-DVR | | Security Officers | 24x7x365 qualified security personnel | ## Structure | Specification | Detail | | --- | --- | | Hardened Exterior | Roof designed to withstand 160 MPH wind | | Loading Dock | Sheltered exterior | | Column Spacing | 56 ft x 32 ft | ## Cooling and Environmental Controls | Specification | Detail | | --- | --- | | Cooling | Variable speed CRAHs with humidification control | | Chillers | Magnetic bearing chillers, variable speed pumps, and cooling towers | | Life Safety | Dual-interlock pre-action dry-pipe sprinkler system | | Lighting | LED only | | Monitoring | RF Code readers for pinpoint temperature and humidity accuracy within customer deployments | ## Power and Reliability | Specification | Detail | | --- | --- | | Utilities | Diverse underground utility feeds from a high-reliability electrical grid | | Generators | N+1 redundancy | | Fuel Storage | 48 hours, on-site | | UPS/PDU/RPP | N+1 UPS and 2N distribution | | Electrical | UPS systems with wet-cell batteries | | Water Storage | On-site well water backup | | Mechanical | N+1 redundancy on chillers, pumps, cooling towers, and CRAHs; UPS-powered pumps for high-density water cooling | | BMS Controls | Mission-critical controls and monitoring with automated logic | | Operations | 24x7x365 remote hands | | Uptime | 100% uptime SLA | ## Orlando Colocation FAQ ### What is included with Atlantic.Net Orlando colocation hosting? Power, cooling, redundant Internet connectivity, physical security, and 24/7 monitoring from our on-site security operations center. Customers can choose 5U shared colocation, individual cabinets, or fully customized cages, with optional managed services and remote hands available. ### Is the Atlantic.Net Orlando data center SOC 2 audited? Yes. The Orlando facility is AICPA SOC 2 Type 2 and SOC 3 certified, plus Type 1 HIPAA AT-C 105 and AT-C 205 audited. Audits are performed annually and cover organizational, environmental, physical, and logical security controls. ### Is Orlando colocation HIPAA compliant? Yes. The Orlando facility is HIPAA AT-C 105/205 audited and supports HIPAA-compliant colocation deployments under a Business Associate Agreement (BAA) with Atlantic.Net. ### What power and cooling redundancy does Orlando provide? Generator backup covers 100% of customer peak load, with a 24-hour on-site fuel supply and guaranteed refueling contracts. Power is delivered through parallel-redundant UPS modules in an N+1 configuration. Cooling uses data-grade HVAC with continuous temperature and humidity control. ### What physical security does the Orlando data center include? 24/7/365 controlled access, biometric finger scanners and proximity card readers, locking cabinets and cages, and closed-circuit digital camera monitoring with 90-day video retention. The facility is staffed by a dedicated on-site security operations center. ### What sizes of colocation are available in Orlando? 5U shared colocation for smaller workloads, individual cabinets in scalable configurations from quarter rack to full rack, and fully customized private cages for enterprise deployments. ### Where is the Atlantic.Net Orlando data center located? Atlantic.Net's flagship data center is in Orlando, Florida. It is the company's headquarters facility and has been in continuous operation since 1994. ## Get Started If you are interested in colocation hosting in Orlando or want to discuss your infrastructure requirements, contact an Atlantic.Net advisor. - USA: 866-618-DATA (3282) - International: +1-408-335-0825 - Email: sales@atlantic.net Atlantic.Net also offers HIPAA- and PCI-compliant colocation in its New York, Ashburn, San Francisco, Dallas, Toronto, and London data centers. If you’re interested in hosting in this data center region, contact an advisor at 866.618.3282 or email us [sales@atlantic.net](mailto:sales@atlantic.net). Atlantic.Net provides world-class hosting services and solutions at eight global data center regions in our [New York](https://www.atlantic.net/hipaa-data-centers/new-york-hosting/), [London](https://www.atlantic.net/hipaa-data-centers/london-uk-hosting/), [San Francisco](https://www.atlantic.net/hipaa-data-centers/san-francisco-california-hosting/), [Orlando](https://www.atlantic.net/orlando-colocation-hosting-data-center/), [Ashburn](https://www.atlantic.net/hipaa-data-centers/ashburn-virginia-hosting/), [Toronto](https://www.atlantic.net/hipaa-data-centers/toronto-canada-hosting/), [Singapore](https://www.atlantic.net/hipaa-data-centers/singapore-hosting/), and [Dallas](https://www.atlantic.net/hipaa-data-centers/dallas-texas-hosting/) locations. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Disaster Recovery and Business Continuity for HIPAA Compliance > URL: https://www.atlantic.net/disaster-recovery/ | Updated: 2026-09-16 Protect mission-critical applications and ePHI with geographically separated off-site backup and replication, active monitoring, optional managed failover, and engineer-led recovery to your pre-agreed RTO and RPO. - Geographically Separated Sites - Optional Managed Failover - 5-Minute Backup Options - 24x7x365 Support & Monitoring Backup Frequency: 5 min Network uptime SLA: 100% ## Disaster Recovery and Business Continuity for HIPAA Compliance At Atlantic.Net, we've spent the last three decades preparing for the next disaster by combining experience, expertise, and world-class hosting infrastructure to provide the most secure HIPAA Disaster Recovery hosting solution – designed for uninterrupted business continuity. To minimize risk and help you get back to business quickly, Atlantic.Net offers off-site backup and replication of your mission-critical data away from the primary facility. This ensures smooth data recovery in the event of a local outage or regional disaster. Our Disaster Recovery solutions are ideal for privacy, security, and compliance work that requires adherence to the strictest government regulations. ## Looking for HIPAA-Compliant Hosting? We can help with a free assessment. - IT architecture design, security & guidance. - Flexible private, public & hybrid hosting. - 24x7x365 security, support & monitoring. ## Managed Disaster Recovery Service One major prerequisite of HIPAA compliance for managed service providers is to demonstrate proficiency at protecting client infrastructure in a disaster recovery (DR) scenario. Atlantic.Net has a successful track record over thirty years, standing tall among service providers with award-winning service backed by always-available support. The end goal: a robust Disaster Recovery service for businesses of all sizes. Our HIPAA-compliant hosting is available in multiple geographically disparate locations. We actively monitor and manage client services and, if a failure is detected, our advanced optional managed disaster recovery solution can fail services over from a primary data center to a secondary site. This enables Atlantic.Net to offer top-level RTOs and RPOs and gives our clients the confidence that they can depend on our disaster recovery service. In the event of a disaster, we will recover applications and data within a pre-agreed service-level agreement, ensuring that healthcare data is protected and readily available. ## Start Your HIPAA Project With a Fully Audited HIPAA Platform Today HIPAA-compliant compute & storage, encrypted VPN, security firewall, BAA, off-site backup, disaster recovery, and more. ## HIPAA Managed Backup The rapid growth of data, shrinking backup windows and budgets, scaling issues, and multiplatform environments in healthcare all present significant challenges for server administrators. Atlantic.Net's experts can help – whether you're looking to back up HIPAA-compliant cloud hosting servers or HIPAA-compliant dedicated servers. Through our powerful Server Backup Manager – a fast, affordable platform for both Linux and Windows – we perform backups at daily, hourly, 15-minute, or 5-minute increments for each HIPAA client, whichever they request. Incremental backups are done at the block level for advanced speed, and clients have full control over when, where, and how their data is stored. Data is by default kept in our HIPAA-compliant SOC 2 Type II and SOC 3 Type II data centers, secured through on-site measures and a suite of robust HIPAA-compliant security software. In addition to a host of customization options, the hosting backup platform is also equipped with robust monitoring tools, portable backups, point-in-time snapshots, and the ability to perform a bare-metal restore at any point in time. We support HIPAA-compliant backups for the majority of virtualized platforms, as well as a wide range of SQL servers and databases. Atlantic.Net is recognized worldwide by top DR/BC professionals and has worked with: - Disaster Recovery and Business Continuity Planners - Information Technology Managers - Consultants - Auditors - Corporate Safety - Risk Managers - Security Managers ## Veeam Backup and Replication Service by Atlantic.Net Protect your IT investment with our best-in-class backup solution for private and public cloud-hosted services. We harness the power of Veeam backup and replication software to provide always-on protection for your infrastructure. The service is monitored, managed, and maintained around the clock by our dedicated staff and engineers, with world-class RTO & RPO (recovery time objective and recovery point objective) service levels and seamless data protection. ## Backup Frequency Tiers and What They Mean for RPO | Backup Frequency | Approximate RPO | Best For | Storage Trade-off | | --- | --- | --- | --- | | Daily | Up to 24 hours of data loss | Static content, dev/test, archival | Lowest storage footprint | | Hourly | Up to 60 minutes of data loss | Internal apps, low-rate transactional systems | Moderate storage footprint | | 15-Minute | Up to 15 minutes of data loss | EHR/EMR systems, claims processing, regulated workloads | Higher storage footprint, block-level incrementals | | 5-Minute | Up to 5 minutes of data loss | High-frequency healthcare transactions, mission-critical ePHI | Highest storage footprint, near-continuous protection | RTO (Recovery Time Objective) – how long the recovery itself takes – is determined separately by the chosen DR architecture (warm standby, hot failover, cold restore). The Atlantic.Net DR team will help size both RPO and RTO during planning. Read more on RTO vs. RPO. ### Disaster Recovery and Business Continuity Strategy You can always be proactive, but unfortunately, you can't always be retroactive when it comes to disaster recovery and business continuity. The last thing a business needs is to experience the regret of not having properly prepared. Fortunately, there are ways to safeguard your business against events beyond your control – including natural disasters. ### What Is Your Data Worth? Losing even one day's worth of data can create a significant setback in operations – disrupting business continuity, amassing monetary and time costs, and resulting in lost productivity and lost business. Taking steps to protect your data is essential to prevent compromising the reputation and trust you've worked so hard to build. ## Why Choose Atlantic.Net? Our state-of-the-art facilities are fully audited for SOC 2 Type II and SOC 3 Type II compliance and provide critical technology platforms combined with fully managed IT infrastructure. Built to withstand category-5 hurricanes and earthquakes, Atlantic.Net facilities are SSAE 18, HIPAA, and HITECH certified and offer unparalleled security. We have facilities in eight data center locations to bolster heavy traffic demands of those key metropolitan areas and to offer off-site storage hosting. Our locations include New York, Dallas, San Francisco, Toronto, London, Ashburn, Singapore, and Orlando. 100% Up-Time SLA. Atlantic.Net is home of the 100% uptime commitment. With years of experience in networking and compute optimization, we make sure the solution you choose is easily implemented, scalable, and efficient. Our redundant architecture ensures that data loss is no longer on your worry list. The flexibility of our customized approach guarantees that you will only be charged for the protection you truly need. Our ability to scale your business requirements up or down keeps your costs low and your solution lean. ## HIPAA Hosting Features ### Business Associate Agreement ### Intrusion Prevention Service ### Fully Managed Firewall ### Vulnerability Scans ### File Integrity Monitoring ### Anti-Malware Protection ### SSL Certificate ### Log Management System ### Multi-Factor Authentication ### Trend Micro Deep Security ### Encrypted Backup ### Encrypted VPN ### Encrypted Storage ### Network Edge/DDoS Protection ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Get Help with HIPAA Compliance Atlantic.Net stands ready to help you attain fast compliance across SOC 2, SOC 3, HIPAA, and HITECH – all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at sales@atlantic.net. ## Frequently Asked Questions About HIPAA Disaster Recovery ### What is HIPAA Disaster Recovery? HIPAA Disaster Recovery is a managed disaster-recovery and business-continuity service for healthcare workloads, designed to meet the HIPAA Security Rule's contingency-planning requirements (45 CFR § 164.308(a)(7)). It combines off-site backup, replication, monitored failover, and engineer-led recovery so ePHI remains protected and accessible during a disruption. ### What's the difference between backup and disaster recovery? Backup is a copy of your data, stored separately from production, that you can restore from. Disaster recovery is the entire process of getting your application and infrastructure running again after an outage – which may include backups, replication to a secondary site, network reconfiguration, DNS updates, and engineer-led cutover. You need backup to do disaster recovery; you need disaster recovery to use that backup at production scale. ### What is RTO and RPO? RTO (Recovery Time Objective) is the maximum acceptable downtime between an outage and the application being available again. RPO (Recovery Point Objective) is the maximum acceptable amount of data loss, measured in time – how far back from the disaster the recovered data is. Tighter RTO/RPO targets cost more (in storage, replication, and standby capacity); looser targets cost less. The DR architecture is sized to hit both. [Full RTO vs. RPO guide](https://www.atlantic.net/disaster-recovery/rto-vs-rpo/). ### How frequent can backups be? Atlantic.Net supports daily, hourly, 15-minute, and 5-minute backup tiers, with block-level incrementals to keep the backup window short and the storage footprint manageable. The right tier depends on your RPO target (see the on-page Backup Frequency Tiers table) and the workload's transaction rate. ### Where are off-site backups stored? Off-site copies are stored in a different Atlantic.Net data center, geographically separated from your primary facility, inside the same audited HIPAA environment. Atlantic.Net operates eight data center locations worldwide (New York, Dallas, San Francisco, Toronto, London, Ashburn, Singapore, and Orlando), so you can pick a secondary region that satisfies your distance and jurisdictional requirements. ### How does Veeam Backup & Replication fit into Atlantic.Net's DR? Veeam Backup & Replication is one of the platforms Atlantic.Net uses to deliver always-on protection across virtual, physical, and cloud workloads. Atlantic.Net engineers handle Veeam licensing, agent installation, policy configuration, and recovery; customers keep visibility through the [Managed Veeam Service](https://www.atlantic.net/managed-services/veeam-services/). ### Does Atlantic.Net's DR meet HIPAA Security Rule contingency requirements? Yes. The HIPAA Security Rule's contingency-plan standard (§ 164.308(a)(7)) calls for data backup, disaster recovery, and emergency-mode operation plans. Atlantic.Net's Managed Disaster Recovery is delivered from infrastructure independently audited under HIPAA AT-C 105 / 205, with a Business Associate Agreement (BAA) available to customers handling ePHI. ### What is a bare-metal restore? A bare-metal restore brings an entire server – operating system, applications, configuration, and data – back to a fresh physical or virtual server, without depending on the original hardware. It is the workhorse pattern for recovering a server that cannot be repaired in place after a hardware or facility loss. ### How quickly can I fail over to a secondary site? It depends on the architecture you choose. A hot-failover site with replicated data can take over within minutes; a warm-standby site typically takes tens of minutes to a few hours; a cold-restore from backups can take longer depending on volume and bandwidth. The Atlantic.Net DR team will design the architecture to your RTO target and pre-agree it as part of the SLA. ### How is Managed Disaster Recovery priced? Pricing depends on the protected workload size, the chosen RTO/RPO targets, the secondary-site architecture (hot, warm, cold), and the data volume backed up and retained. Contact our sales team for a quote tailored to your environment. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Managed Services > URL: https://www.atlantic.net/managed-services/ | Updated: 2026-09-16 Extend your capabilities at a fraction of the cost with a tailored service wrap for cloud, dedicated, on-premises, or hybrid environments. Certified engineers handle 24/7/365 monitoring, security, backups, patching, and troubleshooting so your team can focus on core business. - 24/7/365 Certified Engineers - 8 Global Data Center Regions - SOC 2 & SOC 3 - HIPAA, HITECH & PCI DSS Uptime SLA: 100% Years of Experience: 30+ ## Atlantic.Net Managed Services Our Managed Services are versatile and extensive, including diverse services in the areas of Managed Security, Intrusion Detection Service, Migration Services, and more. These services can be tailored to your particular requirements. If you include any of these high-touch, "white glove" services with your Atlantic.Net Hosting solution, you will have a team of certified and expert engineers at your service, performing real-time monitoring and consultation. You need a trusted partner who understands the ins and outs of cutting-edge technology and how to provide a secure, efficient, and scalable digital environment. That's where Atlantic.Net comes in. With our Managed Services, your business gains efficiency, scalability, and an unmatched level of security. We provide the cutting-edge cloud computing solutions you need while allowing you to focus on what matters, growing your core business. ## Why Choose Atlantic.Net for Managed Services? Every managed service we offer is backed by the best resources available and coupled with system designs of unmatched quality. Our operations are regularly refined through continual testing, and are backed by a team of seasoned engineers. ### 32 Years of Experience Founded in 1994, Atlantic.Net has been delivering hosting and managed services for over three decades. Our longevity reflects a track record of reliability, adaptability, and deep technical expertise that newer providers simply cannot match. ### Compliance-Ready Infrastructure Our data centers are independently audited and certified for SSAE 18 SOC 2 & SOC 3, HIPAA, HITECH, and PCI DSS. You inherit a compliant foundation from day one, no need to build it from scratch. ### 100% Uptime SLA We back every managed service engagement with a 100% uptime SLA. Our redundant power, cooling, and network infrastructure across 8 global data center regions ensures your workloads are always available. [100% uptime SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/) ### 8 Global Data Center Regions Deploy closer to your users with data centers in Orlando, New York, Dallas, San Francisco, Ashburn, Toronto, London, and Singapore. Geographic diversity supports data sovereignty requirements and reduces latency for global workloads. ### High-Touch, Consultative Approach We don't offer cookie-cutter solutions. Every engagement starts with a consultative assessment to design an infrastructure and service wrap tailored to your specific workload, compliance, and performance requirements. ### 24/7/365 Certified Engineers Our always-available support team is staffed by certified engineers who provide real-time monitoring, incident response, and proactive consultation. No phone tag, no ticket queues, direct access to the experts who manage your environment. ## Managed Services vs. In-House IT Understanding the key differences helps you decide whether outsourcing IT operations to a managed service provider is the right move for your organization. | Factor | In-House IT | Atlantic.Net Managed Services | | --- | --- | --- | | Cost Structure | High CapEx: salaries, benefits, hardware purchases, maintenance contracts, and ongoing training | Predictable OpEx: flexible monthly pricing with no upfront capital investment or hidden costs | | Scalability | Scaling up requires hiring, procurement, and lead times of weeks or months | On-demand scaling across private, public, and hybrid cloud environments within hours | | Expertise | Limited to the skills of your current team; specialized knowledge gaps are common | Team of certified engineers with 32 years of multi-domain expertise across security, compliance, and infrastructure | | Compliance | You bear the full burden of achieving and maintaining certifications (HIPAA, PCI DSS, SOC 2) | Pre-audited infrastructure: SSAE 18 SOC 2 & SOC 3, HIPAA, PCI DSS, and HITECH certified environments ready from day one | | Availability | Typically business-hours coverage; after-hours incidents may go undetected until next day | 24/7/365 monitoring, support, and incident response backed by a 100% uptime SLA | | Security | Requires significant investment in tools, SIEM platforms, and dedicated security staff | Full-stack security included: managed firewall, MFA, Trend Micro Deep Security, IPS, and DDoS protection | | Time to Deploy | Weeks to months for procurement, configuration, and testing | Rapid deployment with pre-configured, compliance-ready environments across 8 global data centers | | Disaster Recovery | Must design, implement, and test your own DR strategy, often neglected due to cost | Managed Veeam backup, replication, and DR planning built into the service with regular testing | | Focus | IT team divides attention between maintenance tasks and strategic projects | Your team focuses on core business while Atlantic.Net handles day-to-day infrastructure operations | ## Managed Services Use Cases by Industry Every industry faces unique compliance, security, and infrastructure challenges. Atlantic.Net's managed services are tailored to meet the specific demands of your sector. ### Healthcare & Life Sciences Compliance: HIPAA, HITECH, GDPR Healthcare organizations handle protected health information (PHI) that demands the highest levels of encryption, access control, and audit logging. Atlantic.Net provides HIPAA-compliant hosting with BAA coverage, managed firewall, MFA, intrusion prevention, and Veeam backup, ensuring your electronic health records, telehealth platforms, and clinical applications remain secure and audit-ready at all times. [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) ### E-commerce & Retail Compliance: PCI DSS Online retailers processing credit card transactions must maintain PCI DSS compliance to protect cardholder data. Atlantic.Net's PCI-compliant hosting environment combined with managed load balancing, DDoS protection, and server management ensures your storefront stays fast, secure, and available during peak traffic events like Black Friday and flash sales. [PCI-compliant hosting](https://www.atlantic.net/pci-compliant-hosting/) ### Financial Services Compliance: SOC 2, PCI DSS, GLBA Banks, fintech startups, and insurance companies require rigorous data protection and audit trails. Atlantic.Net's SOC 2/SOC 3 audited infrastructure, combined with managed security services including Trend Micro Deep Security and intrusion prevention, provides the defense-in-depth architecture that regulators and auditors expect. ### SaaS & Software Companies Key needs: Scalability, uptime, performance SaaS providers need infrastructure that scales seamlessly with user growth while maintaining sub-second response times. Atlantic.Net's managed private cloud and load balancing services, backed by a 100% uptime SLA and 8 global data center regions, give software companies the performance foundation their customers depend on. ### Government & Public Sector Compliance: NIST, FedRAMP, FISMA Government agencies require hosting partners with demonstrated security postures and data sovereignty controls. Atlantic.Net's US-based data centers, comprehensive compliance certifications, and managed security services provide the trusted infrastructure needed for citizen-facing applications and sensitive government workloads. ### Legal & Professional Services Key needs: Data confidentiality, disaster recovery Law firms and professional services organizations handle privileged client information that demands strict access controls and robust disaster recovery. Atlantic.Net's managed Veeam backup, encrypted storage, and consultative approach ensure your client data remains confidential, recoverable, and protected against ransomware and data loss. ## Managed Services The Experience You Need With The Support You Want. - Full Range of Managed Services. - Flexible Private, Public, & Hybrid Cloud Hosting. - 24x7x365 Security, Support, & Monitoring. ## Full-Stack Managed Services All the services you need to make your IT project come to life. ### [Atlantic.Net Firewall](https://www.atlantic.net/managed-services/firewall/) ### [Multi-Factor Authentication](https://www.atlantic.net/managed-services/multi-factor-authentication/) ### [Managed Server Hosting](https://www.atlantic.net/managed-services/server-management/) ### [Network Edge/DDoS Protection](https://www.atlantic.net/managed-services/network-edge-protection/) ### [Trend Micro Deep Security](https://www.atlantic.net/managed-services/trend-micro-deep-security-suite/) ### [Consulting Agreements](https://www.atlantic.net/managed-services/consulting/) ### [Managed Veeam Backup](https://www.atlantic.net/managed-services/veeam-services/) ### [Load Balancing](https://www.atlantic.net/managed-services/load-balancing/) ### [Migration Services](https://www.atlantic.net/managed-services/migration-services/) ## Atlantic.Net Firewall The segregated firewall service protects the network perimeter and strategic points. It's the first line of defense; and scrutinizes every bit of data entering or leaving your systems, keeping malicious intruders at bay. With the managed firewall service, you can rest easy knowing your digital footprint is protected against cyber threats. ## Multi-Factor Authentication Password security is a vital layer of defense in every network. Complex passwords are now standard, and Atlantic.Net's [Multi-Factor Authentication](https://www.atlantic.net/managed-services/multi-factor-authentication/) service adds further protection to ensure your environment is hardened against external threats. MFA adds an extra layer of security by requiring multiple forms of validated authentication, making it more challenging for unauthorized users to break in. This service protects your sensitive information and systems behind numerous security checkpoints. ## Trend Micro Deep Security Trend Micro is a top-tier security product, and Atlantic.Net use the latest versions of Deep Security to provide an [all-in-one security solution](https://www.atlantic.net/managed-services/trend-micro-deep-security-suite/). From virtual patching and intrusion detection to anti-malware, this service ensures your IT environment and any in-scope remote device remains locked down and safe from a myriad of cyber threats. ## Database Hosting Atlantic.Net offers fully managed database hosting services, supporting a range of SQL and NoSQL options. Popular databases like MySQL, PostgreSQL, MongoDB, and Redis are available. Our Database Hosting and Administration services offer full support for a range of SQL and NoSQL options managed by our experienced team. We ensure optimal configuration, performance, and security while handling backups, updates, and troubleshooting. ## Database Administration Our experienced team of database administrators (DBAs) ensures your databases' optimal configuration, performance, and security. In addition, we handle backups, updates, performance tuning, and troubleshooting. ## High Availability and Replication Thanks to our High Availability and Replication features, there is no fear of hardware failures or disruptions. Your data remains accessible and safe, even during unexpected disruptions. Our teams ensure continuous access and data redundancy using Atlantic.Net's database replication and clustering options. ## Scalability Is your business growing? We grow with you. Our Scalability options make upgrading your storage, processing power, and database instances a breeze, aligning seamlessly with your evolving data loads and user demands. ## Security and Compliance We prioritize data security, implementing robust measures like encrypted connections, firewall protection, intrusion prevention systems, and regular security audits. Compliance with industry standards like [HIPAA and GDPR is ensured](https://www.atlantic.net/hipaa-compliant-hosting/). ## Server Management With Atlantic.Net's [Server Management service](https://www.atlantic.net/managed-services/server-management/), your servers are in good hands. Our engineers handle everything from system monitoring and patching to backup management and troubleshooting. It's like having a team of IT experts on call, ready to ensure your servers are always up, running and performing at their best. ## Managed Veeam Backup Atlantic.Net's Managed Veeam [Backup service](https://www.atlantic.net/cloud-platform/backups/) ensures your data is always safe and secure. Ensuring your physical and virtual servers are backed up and can be quickly recovered if needed. This is a powerful ally in maintaining business continuity and safeguarding against data loss. ## Intrusion Prevention System The [Intrusion Prevention System](https://www.atlantic.net/managed-services/intrusion-detection-service/) service is a digital watchdog. It patrols the network and interconnected systems, scanning for malicious activities. Alerting is automated via a SIEM platform to identify and block potential threats. It's like having your team of cyber operatives working around the clock to keep your IT environment safe and secure. Unlock your IT potential with Atlantic.Net Managed Services. Streamline IT operations and accelerate growth with a comprehensive range of security, infrastructure management, data protection, recovery, and transformative managed services. Contact us today for a personalized consultation. For faster application deployment, free IT architecture design, and assessment, call 866-618-3282 or email us at [sales@atlantic.net](mailto:sales@atlantic.net). ## Managed Services The Experience You Need With The Support You Want. - Full Range of Managed Services. - Flexible Private, Public, & Hybrid Cloud Hosting. - 24x7x365 Security, Support, & Monitoring. ## What Are Managed Services? Managed services are services provided to a company or organization by a third party that shift the responsibility for specific processes, functions, and operations from that company to the third party. While managed services apply to several activities, they frequently refer to IT solutions, offering a proactive approach to modernizing business operations by making them cloud-ready and future-proof. Managed services give companies the time needed to focus on their core competencies without the burden of managing IT operations in-house. Outsourcing IT services maximizes your business's efficiency, providing peace of mind and knowing that you are in the capable hands of a team of experts. MSPs deliver a comprehensive service wrap for new and existing environments, from network management and data backup to cybersecurity and a managed cloud computing platform. Managed services are designed to optimize your business performance, providing the critical IT support needed to thrive in a competitive market. ## Frequently Asked Questions About Managed Services ### What is the difference between managed services and cloud hosting? Cloud hosting provides the underlying infrastructure (virtual servers, storage, and networking) while managed services add a layer of expert human oversight on top of that infrastructure. With managed services, Atlantic.Net's certified engineers handle day-to-day operations including monitoring, patching, security management, backup, and troubleshooting so your team can focus on strategic initiatives rather than routine maintenance. You can use managed services with cloud hosting, dedicated servers, or hybrid environments. ### How much do managed services cost? Managed services pricing varies based on the scope and complexity of your environment. Atlantic.Net uses a consultative approach: we assess your infrastructure, compliance requirements, and performance goals before providing a custom quote. This ensures you only pay for the services you need. There are no hidden fees or long-term lock-in contracts. Contact our sales team for a personalized consultation and pricing estimate. ### What compliance certifications does Atlantic.Net hold? Atlantic.Net's data centers and managed services infrastructure are independently audited and certified for SSAE 18 SOC 2 and SOC 3, HIPAA, HITECH, and PCI DSS compliance. These certifications are maintained through annual audits conducted by third-party assessors. This means your workloads inherit a pre-certified, compliance-ready foundation from day one, significantly reducing the time and cost of achieving your own regulatory compliance. ### Can I customize which managed services I use? Yes. Atlantic.Net's managed services are fully modular. You can select individual services such as managed firewall, multi-factor authentication, server management, or Veeam backup, or combine them into a comprehensive full-stack managed solution. Our consultative approach ensures we tailor the service wrap to match your specific needs, budget, and compliance requirements rather than forcing a one-size-fits-all package. ### What is the typical onboarding timeline? Onboarding timelines vary based on the complexity of your environment, but most managed services engagements follow a structured process: initial consultation and assessment (1 to 2 weeks), architecture design and planning (1 to 2 weeks), migration and deployment (1 to 4 weeks), and handover to ongoing management. Simple environments can be fully onboarded in as little as two weeks, while complex multi-site deployments with compliance requirements may take four to eight weeks. ### Do you offer 24/7 support? Yes. Atlantic.Net provides 24/7/365 support for all managed services customers. Our support team is staffed by certified engineers (not outsourced call center agents) who have direct access to your environment and can resolve issues in real time. You can reach us by phone at [866-618-3282](tel:+18666183282), via [email](mailto:sales@atlantic.net), or through live chat on our website. Our 24/7 NOC proactively monitors your infrastructure and responds to automated alerts before issues impact your operations. ### What industries do Atlantic.Net managed services support? Atlantic.Net serves a wide range of industries including healthcare and life sciences (HIPAA-compliant hosting), e-commerce and retail (PCI DSS-compliant infrastructure), financial services (SOC 2 audited environments), SaaS and software companies, government and public sector agencies, legal and professional services firms, education, and media and entertainment. Our compliance certifications and flexible infrastructure make us particularly well-suited for regulated industries where data security and audit readiness are critical. ### Can Atlantic.Net manage my existing infrastructure? Yes. Atlantic.Net's managed services can be applied to your existing infrastructure whether it is hosted on our platform, on-premises, or with another provider. Our [migration services](https://www.atlantic.net/managed-services/migration-services/) team can also help you transition workloads to Atlantic.Net's infrastructure if you decide to consolidate. We support private, public, and hybrid cloud environments, giving you the flexibility to manage your entire IT estate through a single partner. ### How does Atlantic.Net handle disaster recovery? Atlantic.Net provides managed disaster recovery through our [Veeam backup services](https://www.atlantic.net/managed-services/veeam-services/), database replication, and high-availability clustering. We work with you to design a DR strategy that meets your recovery time objectives (RTO) and recovery point objectives (RPO). Our geographically distributed data centers enable cross-region replication, and our engineers regularly test backup and failover procedures to ensure your business can recover quickly from any disruption. ### What is the difference between managed services and managed hosting? Managed hosting typically refers to the management of the physical or virtual server infrastructure itself: hardware maintenance, OS patching, and uptime monitoring. Managed services is a broader term that encompasses managed hosting plus additional layers such as security management (firewall, MFA, IPS), backup and disaster recovery, application-level support, compliance management, and strategic IT consulting. Atlantic.Net offers both, and you can scale from basic managed hosting to full-stack managed services as your needs evolve. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Server Management Services > URL: https://www.atlantic.net/managed-services/server-management/ | Updated: 2026-09-16 Let Atlantic.Net engineers handle server hardening, operating system patching, monitoring, database and web server configuration, migrations, and 24/7/365 incident response across supported Linux and Windows platforms. - 24/7/365 Incident Response - Critical Patches Daily - OnWatch Platinum Monitoring - Linux & Windows Support Critical Patching: Daily General Patching: Monthly ## Server Management Services from Atlantic.Net Atlantic.Net's Managed Server Services free your team from day-to-day server administration so you can focus on the applications and outcomes that move your business forward. US-based engineers handle operating system patching, security hardening, monitoring, database and web server configuration, backups, and 24/7/365 incident response across the most widely used Linux and Windows platforms. Whether you run a single web server or a multi-tier production environment, Managed Server Services scale with your workload – and they pair with our SOC 2 Type II, HIPAA, HITECH, and PCI DSS-aligned hosting infrastructure for regulated workloads. ## What Is Managed Server Management? Server management is the operational discipline of keeping a server running securely, reliably, and at peak performance: installing and patching the operating system, hardening it against attacks, monitoring its health, configuring services such as databases and web servers, and responding to incidents the moment they happen. Done well, it is invisible – your applications stay up, your data stays safe, and your engineering team stays focused on shipping. When you outsource server management to Atlantic.Net, our engineers take on those operational responsibilities under a clearly defined scope. You retain administrative control of your server, application code, and business logic; we handle the underlying platform. ### Available Operating Systems ### Atlantic.Net One-Click Apps ### General Features ### Database Service Support ### Control Panel Support ### DNS Support ### Email Server Support ### File Sharing ### FTP, FTPS, SFTP ### Load Balancing ### OnWatch Platinum Monitoring Platform ### Server Migrations ### Server Patching and Updates ### Vulnerability Scans ### Web Server Support ### Web Service Support - SSL ### VPN Support ## Available Operating Systems Atlantic.Net One-Click Apps: cPanel/WHM, LAMP, LEMP, MySQL, NextCloud, WordPress. - Windows Server: 2016, 2019, 2022 - Rocky Linux: 8 - Debian: 10, 11 - Ubuntu: 20.04 LTS, 22.04 LTS ### General Features - Server deployment following industry best practices, including server hardening - General baseline performance metrics completed and provided upon initial release - 20% discount on Atlantic.Net Professional Service Agreements - Dedicated Account Representative - Upon request, troubleshoot issues relating to server network connectivity, host load, and server operating systems - Reinstall server operating system as needed ### Database Service Support Note: This does not include site code or query analysis - Supported platforms: MSSQL 2017/2019; MySQL 5.7+, 8.x recommended; Percona 5.7+, MariaDB 10.4+ - Assist with setting up local database backups - Installation and secure configuration of database users - Assist with import of remote databases - Assist with setting up new databases and database users - Assist with basic security changes ### Control Panel Support Note: Support is always current LTS version - cPanel / WHM - Plesk - Drupal ### DNS Support - Web portal available to allow clients to make their own changes - Assist with importing customer-provided DNS information to Atlantic.Net DNS servers - Implement DNS changes on Atlantic.Net DNS servers and help facilitate migrations to Atlantic.Net services - Assist with advanced DNS configurations, such as setting up domain keys and SPF records - Assist with troubleshooting DNS resolution problems ### Email Server Support - Install and configure mail server on Windows or Linux, including Mail Transfer Agent (MTA) and Webmail portals - Enable anti-spam and anti-malware settings by configuring email virus and spam scanners, rate-limits, and Real-time Blackhole List checks - Assist with setting up mail-related DNS records - Assist with setting up new domains - Assist with setting up new users - Assist with troubleshooting mail delivery and mail queue issues - Provide customer with settings needed to set up email client for receiving email ### File Sharing - Includes support for Windows and Linux file shares - Assist with setup and mapping of NFS shared folder - Assist with setup and mapping of Samba/SMB shared folder - Assist with setup and mapping of SSHFS shared folder - Assist with setup and mapping of Windows shared drive ### FTP, FTPS, SFTP - Includes support for Linux and Windows systems - Assist with setup and configuration of FTP, FTPS, and SFTP - Assist with setup of new users ### Load Balancing (optional add-on) - Configure load balancing to distribute incoming application traffic across multiple servers - Configure load balancing service type – Round Robin, Static Round Robin, Least Connections, IP Source - Configure load balancing features – sticky sessions, health checks, SSL termination, multi-port, connection throttling - Note: GeoIP Load Balancing also available via Edge Protection service ### OnWatch Platinum Monitoring Platform - ICMP monitoring - SNMP-based CPU usage - SNMP-based RAM usage - SNMP-based Disk I/O - SNMP-based NIC throughput - Hardware RAID status (if applicable) - Website, email, MySQL port status ### Server Migrations - Assist with migrating client data from another hosting provider and with getting started on Atlantic.Net's Managed Platform server ### Server Patching and Updates - Upon request, install requested updates and patches - Automated patching service available - Critical patches installed daily - General patches installed monthly - Schedule times for server reboots after patching, if needed - Upon request, pre-patch report on the current status of pending updates - Upon request, post-patch report on the application of the latest updates ### Vulnerability Scans Note: This does not include support for site code or query analysis - Scheduled vulnerability scans across the supported operating system fleet - Findings reviewed by the Atlantic.Net engineering team and prioritized for remediation ### Web Server Support - Includes support for Windows IIS, Apache, and Nginx - Install and configure requested common web extensions, such as PHP - Apply general security tweaks and performance optimizations - Assist with setting up new websites - Assist with setting up domain redirects and rewrites - Assist with setting up custom logging - Assist with enabling web authentication - Assist with server-generated outbound email issues - Assist with troubleshooting connectivity to a SQL server - Assist with troubleshooting permissions and file issues - Assist with evaluating customer logs ### Web Service Support - SSL - Assist with order and setup of SSL for hosted domain ### VPN Support - Assist with configuration of Client-based VPN (user authentication) - Assist with configuration of Site-to-Site tunnels - Assist with setup of access lists to ensure VPN is restricted to specific servers and accounts - Upon request, modify VPN configuration settings ## Notes Atlantic.Net is unable to assist with website or database content generation, scripting, or programming. Atlantic.Net may request removal of any installed third-party application prior to troubleshooting server issues if there is reason to believe the application may impact server performance or reliability. ## Self-Managed vs. Atlantic.Net Managed Server Services | Responsibility | Self-Managed | Atlantic.Net Managed | | --- | --- | --- | | OS install & hardening | You | Atlantic.Net engineers | | Security & OS patching | You | Atlantic.Net - critical patches daily, general patches monthly | | 24/7 monitoring & alerting | You - typically requires third-party tooling | Atlantic.Net OnWatch Platinum platform | | Web server (Apache, Nginx, IIS) setup | You | Atlantic.Net | | Database installation & configuration | You | Atlantic.Net - MSSQL, MySQL, MariaDB, Percona | | DNS & mail server administration | You | Atlantic.Net | | Vulnerability scanning | You - typically requires a third-party scanner | Atlantic.Net | | VPN & secure remote access | You | Atlantic.Net | | Server migration assistance | You | Atlantic.Net | | Application code, logic & query optimization | You | You (out of scope; available via Professional Services) | | Compliance documentation (HIPAA, PCI, SOC 2) | You | Atlantic.Net audit-aligned environment with documentation available | | Incident response & troubleshooting | You | Atlantic.Net 24/7/365 US-based support | Focus on your core business while we handle the day-to-day management of your servers. Experience proactive monitoring, expert support, and guaranteed uptime - partner with Atlantic.Net for 24x7x365 server management that delivers results. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at sales@atlantic.net. ## Frequently Asked Questions About Managed Server Services ### What are managed server services? Managed server services shift day-to-day server administration - patching, monitoring, security hardening, database and web server configuration, backups, and incident response - from your team to a service provider. Atlantic.Net's engineers operate your servers under a defined scope while you keep administrative control of your applications and data. ### Which operating systems do Atlantic.Net's Managed Server Services support? Windows Server 2016, 2019, and 2022; Rocky Linux 8; Debian 10 and 11; and Ubuntu 20.04 LTS and 22.04 LTS. Long-term support (LTS) versions are recommended so that security patches remain available throughout the lifetime of your deployment. ### Do I keep root or administrator access to my server? Yes. Atlantic.Net Managed Server Services are collaborative - you retain root or administrator access. Our engineers work alongside your team, and major changes are coordinated through your dedicated account representative. ### How is this different from unmanaged or self-managed hosting? With unmanaged hosting you are responsible for the operating system, patching, security, monitoring, and every supporting service (database, web server, mail, DNS). With Atlantic.Net Managed Server Services, our US-based engineers take on those tasks under a defined scope, freeing your team to focus on application code and business logic. ### What's included in monitoring? The OnWatch Platinum monitoring platform tracks ICMP availability, SNMP-based CPU, RAM, disk I/O, and NIC throughput, hardware RAID status, and the health of HTTP/HTTPS, mail, and MySQL ports. Alerts route to our 24/7 NOC for triage. ### Are managed servers part of HIPAA-compliant or PCI-compliant hosting? Yes. Atlantic.Net's Managed Server Services run inside the same SOC 2 Type II, HIPAA, HITECH, and PCI DSS 4.0-audited infrastructure that backs our compliance hosting products. Customers under those regimes can cite our managed-server controls in audit documentation, and a Business Associate Agreement (BAA) is available for HIPAA workloads. ### Can Atlantic.Net help migrate servers from another hosting provider? Yes. Server migrations are part of the Managed Server Services scope. Our engineers help plan and execute migrations from on-premises, colocation, or other cloud providers onto Atlantic.Net's Cloud Platform or Dedicated Server Hosting. ### How is server patching handled? Critical patches are installed daily and general patches monthly. Automated patching is available, and pre-patch and post-patch reports are provided on request. Reboot windows are scheduled with you in advance. ### What is not included in Managed Server Services? Atlantic.Net does not write or debug application code, perform query analysis, or manage third-party application internals. If a third-party application appears to be impacting server stability we may request its removal during troubleshooting. Application-layer support is available separately through our Professional Services agreements. ### How are Managed Server Services priced? Pricing is based on the number and type of servers, the operating systems supported, and the level of database, web, and security services required. Contact our sales team for a quote tailored to your environment. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Migration Services > URL: https://www.atlantic.net/managed-services/migration-services/ | Updated: 2026-09-16 Move production and development workloads from on-premises, cloud, or another provider with Standard, Advanced, or Enterprise migration support, engineer-led planning, Migration Success credits, and cutovers available 24/7/365. - Defined Data & Full-Environment Moves - BMR & P2V on Enterprise - Near-Zero Downtime in Most Scenarios - 24/7/365 Cutover Availability Migration Success Credit: Up to $6,000 Typical Timeline: 2–6 weeks ## Migration Services Atlantic.Net knows that migrating production and development environments can be daunting for IT teams that are already stretched thin. We offer three tiered migration services covering the full range from defined-directory data moves up to full bare-metal restores and Physical-to-Virtual (P2V) migrations – most clients fit one of the three cleanly. If you have custom requirements, that's not a problem. Your Atlantic.Net Sales Representative, alongside an Atlantic.Net Managed Services Engineer, will build a custom-fit plan for your team. Migration credits earned on lower tiers can be applied toward a higher tier of service. Atlantic.Net strives to never say no and always provide a pathway to success. ## Migration Services Tiers Atlantic.Net offers three types of migration service to suit your business needs: ### Standard Migrations The Standard Migration service covers migrating defined data directories from your current system – on-premises or at another provider – into Atlantic.Net. Atlantic.Net's Security Operations Center (SOC) handles the data move and ensures all of your specified data lands in the new environment. Common Standard migrations include cPanel migrations, file share migrations, and Plesk migrations – we run these for new clients daily. We aim to make the entire migration process seamless and affordable. Through our Migration Success program, customers bringing a new environment to Atlantic.Net qualify for a migration credit applied to the account when the account meets a minimum revenue requirement of $500. The credit caps at 4 hours, an $800 value.* ### Advanced Migrations The next step up is the Atlantic.Net Advanced Migration. The migration is assigned to a dedicated engineer who works through your current and target environment plans, reviews both for compatibility, and helps build the migration plan. Once both teams are confident in the plan, the Atlantic.Net engineer sets up systems that fall under Atlantic.Net's scope of support for Managed Services, migrates all specified data, and verifies the new environment is working correctly per the plan. The customer signs off on the migration when complete. As with the Standard tier, Advanced Migrations are designed to be seamless and priced competitively in the industry. The Advanced package is also available with the Migration Success program: a migration credit applies if you bring a new environment to Atlantic.Net, opt for Atlantic.Net's Managed Services per VM, and meet a minimum of $800 in monthly revenue with a 12-month commitment. The credit caps at 10 hours, a $3,000 value.* ### Enterprise Migrations Enterprise Migrations cover everything from the Standard and Advanced services and add the engineering team's most complex moves: complete bare-metal restores (BMR) and Physical-to-Virtual (P2V) migrations. Atlantic.Net's Professional Services teams bring decades of combined experience. After the Advanced Migration setup steps, engineers use specialist software to perform a pre-seed of your current environment to Atlantic.Net's Cloud environments – minimizing the configuration changes required on your side and enabling testing of the systems before any cutover, with the same software you currently run. Enterprise workloads are typically the most challenging migrations. The number of engineers assigned to a project scales to the work. Planning is the bulk of the engagement, and we recognize that many clients also need a fast migration once the plan is locked in. As with Standard and Advanced, Enterprise Migrations are designed to be seamless and competitively priced, and the package is available under the Migration Success program: a migration credit applies if you bring a new environment to Atlantic.Net, opt for Managed Services per VM, and meet a minimum of $1,200 in monthly revenue with a 12-month commitment. The credit caps at 20 hours, a $6,000 value.* No two migrations are the same. Atlantic.Net's cloud-migration expertise will deliver your project as quickly as possible – most scenarios complete with near-zero downtime. *Migrations typically take 2–6 weeks, depending on scope. *All pre-planning migration work is performed Monday through Friday between 9 AM and 5 PM Eastern; migration cutover can be performed 24/7/365. *Migration services that require allocation of a large timeframe are billed at $200.00 per hour for unmanaged servers and $160.00 per hour for managed servers. ## Migration Tier Comparison | Capability | Standard | Advanced | Enterprise | | --- | --- | --- | --- | | Migrate defined data directories | Yes | Yes | Yes | | cPanel, Plesk, and file-share migrations | Yes | Yes | Yes | | Performed by | SOC team | Dedicated engineer | Dedicated engineering team | | Pre-migration environment review | – | Yes | Yes | | Custom migration plan | – | Yes | Yes | | Customer sign-off workflow | – | Yes | Yes | | Bare-Metal Restore (BMR) | – | – | Yes | | Physical-to-Virtual (P2V) migration | – | – | Yes | | Pre-seed of source environment to Atlantic.Net Cloud | – | – | Yes | | Cutover testing before go-live | – | – | Yes | | Multiple engineers per project (as needed) | – | – | Yes | | Migration Success credit cap | 4 hours / $800 | 10 hours / $3,000 | 20 hours / $6,000 | | Minimum revenue for credit eligibility | $500 | $800/month, 12-month commit | $1,200/month, 12-month commit | ## Migrate with confidence. Minimize disruption and downtime with Atlantic.Net's proven migration services. Contact us today to plan your transition. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at sales@atlantic.net. ## Frequently Asked Questions About Migration Services ### What is Atlantic.Net's Migration Service? The Migration Service is a three-tier engagement (Standard, Advanced, Enterprise) that brings your workloads onto Atlantic.Net's Cloud Platform or Dedicated Server Hosting. Each tier scales the engineering depth and the work covered – from defined-directory data moves up through full bare-metal restores and Physical-to-Virtual (P2V) migrations – with optional Migration Success credits offsetting cost when revenue thresholds are met. ### What types of migrations are supported? Defined-directory data migrations, cPanel migrations, Plesk migrations, and file-share migrations on Standard. Full environment migrations with engineer-led planning on Advanced. Bare-metal restores (BMR), Physical-to-Virtual (P2V) migrations, and pre-seeded cutovers on Enterprise. Source environments commonly include on-premises infrastructure, colocation, AWS, Azure, GCP, and other cloud or hosting providers. ### What's the difference between Standard, Advanced, and Enterprise migrations? Standard moves specific data directories using SOC engineers – best for cPanel, Plesk, and file-share moves. Advanced assigns a dedicated engineer who reviews both environments, builds a custom plan, executes the move, and walks through customer sign-off. Enterprise adds the most complex work: bare-metal restores, P2V migrations, pre-seeded cutovers, and engineering teams sized to the project. The comparison matrix above breaks the differences down line by line. ### What is the Migration Success program? The Migration Success program offsets migration cost when you bring a new environment to Atlantic.Net and meet a minimum monthly revenue (and, on the higher tiers, a 12-month commitment with Managed Services per VM). Migration credit caps scale with the tier – 4 hours ($800) on Standard, 10 hours ($3,000) on Advanced, and 20 hours ($6,000) on Enterprise. ### How long does a migration take? Migrations typically take 2 to 6 weeks, depending on the scope of work. Pre-planning happens Monday through Friday, 9 AM to 5 PM Eastern; migration cutover can be performed 24/7/365 to minimize impact on business hours. ### Will my services experience downtime during the migration? Most scenarios complete with near-zero downtime. On Enterprise tier, engineers pre-seed the source environment to Atlantic.Net's Cloud, which lets us test the new environment before the cutover; only the final cutover causes a brief, planned switchover. Standard and Advanced migrations have a comparable pattern scaled to the work involved. ### What is a bare-metal restore (BMR)? A bare-metal restore brings an entire server – operating system, applications, configuration, and data – back to a fresh physical or virtual server, without depending on the original hardware. BMR is the standard pattern for moving from on-premises servers or third-party hosts onto Atlantic.Net's infrastructure when the source cannot be reached for an in-place agent install. ### What is a Physical-to-Virtual (P2V) migration? A Physical-to-Virtual (P2V) migration converts a workload running on physical hardware into a virtual machine on Atlantic.Net's Cloud Platform. The OS, applications, and data move into a hypervisor-managed VM that you can scale, snapshot, replicate, and back up like any other cloud workload. P2V is included on the Enterprise tier. ### How is migration priced if I don't qualify for a Migration Success credit? Migration services that require allocation of a large timeframe are billed at $200.00 per hour for unmanaged servers and $160.00 per hour for managed servers. Atlantic.Net's sales team will scope the engagement and confirm pricing before the work begins. ### Can Atlantic.Net help me migrate from AWS, Azure, or on-premises? Yes. Common source environments include on-premises servers, colocation, AWS, Azure, GCP, and other cloud or hosting providers. The Atlantic.Net engineering team scopes the move, builds the migration plan, executes the cutover, and validates the new environment so your team can sign off with confidence. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # FortiGate Firewall as a Service > URL: https://www.atlantic.net/managed-services/firewall/ | Updated: 2026-09-16 Protect cloud and dedicated infrastructure with a next-generation firewall that combines IPS, SSL inspection, VPN, application control, web filtering, and round-the-clock monitoring from Atlantic.Net's US-based Security Operations Center. - Built-In Fortinet IPS - SSL/TLS Deep Inspection - AI-Powered Threat Protection - US-Based 24/7/365 SOC SOC Monitoring: 24/7/365 Security Stack: NGFW + IPS ## FortiGate Firewall as a Service Your hosted infrastructure lives behind a perimeter that can inspect encrypted traffic, help detect and block known, unknown, and zero-day threats, stop ransomware, and protect cloud, dedicated, and remote-user connections simultaneously. FortiGate Firewall as a Service delivers an enterprise-grade firewall estate as a managed subscription. No appliance to buy, no licensing to chase, no firewall engineer to hire. Atlantic.Net configures, updates, and monitors your FortiGate platform - the most widely deployed network firewall in the world - around the clock from our US-based Security Operations Center. One service replaces the separate Managed Firewall and IPS products we previously offered, and adds everything a modern next-generation firewall brings: AI-powered threat intelligence, SSL inspection, application control, VPN, and web filtering on a single platform. ## What Is FortiGate Firewall as a Service? FortiGate Firewall as a Service (FWaaS) is a managed Fortinet FortiGate next-generation firewall deployed in front of your Atlantic.Net cloud or dedicated server infrastructure. Firewalling and intrusion prevention run natively on the same platform, alongside VPN, SSL inspection, application control, web filtering, and inline AI-based malware detection. Atlantic.Net engineers handle provisioning, policy configuration, firmware, signature updates, and threat response. You retain visibility and approval over policy changes and keep full control of your servers. The service consolidates two products Atlantic.Net used to sell separately, Managed Firewall and Intrusion Detection System, into one integrated platform with a single policy framework and one support relationship. ## Fully Managed Next-Generation Firewall Atlantic.Net configures, tunes, and maintains your FortiGate. Rule changes, firmware, and signature updates are handled by our engineers. No hardware to rack, no license renewals to track, no in-house firewall specialist required. ## What's Included ### Built-In Intrusion Prevention (IPS) Every deployment includes the Fortinet IPS engine with regularly updated FortiGuard signatures and threat intelligence. Known exploits, CVEs, and attack patterns are blocked in-line in the same pass as firewall enforcement. No separate appliance, no chained inspection points. ### AI-Powered Threat Protection FortiGuard AI-powered security services apply machine learning to known, unknown, zero-day, and AI-generated threats. Inline malware prevention inspects unknown files in real time and produces a verdict without waiting for a signature release. Data loss prevention rules watch outbound traffic for sensitive patterns on enterprise-tier subscriptions. ### Site-to-Site and Remote Access VPN IPsec and Remote VPN Access out of the box. Connect branch offices and colocated infrastructure over encrypted tunnels. Support remote users with managed accounts, multi-factor authentication, and policy-based access to specific resources. ### SSL/TLS Deep Inspection SSL inspection lets your firewall, IPS, and content policies see inside encrypted sessions without crippling throughput. The blind spot that covers most modern malware delivery closes. ### Application Control, Web, and DNS Filtering Allow, block, or restrict traffic by the specific application generating it, not just port or protocol. Web filtering blocks malicious, phishing, and policy-violating URLs. DNS security and botnet protection cut off command-and-control callbacks before data exfiltration or lateral movement. ### 24/7/365 SOC Monitoring Atlantic.Net's US-based Security Operations Center watches your deployment around the clock. When attacks escalate or FortiGate flags traffic our engineers need to investigate, response happens immediately, not at the start of the next business day. ## Audited Compliance Alignment FortiGate FWaaS operates inside Atlantic.Net's SOC 2 Type II, SOC 3 Type II, HIPAA, HITECH, PCI DSS 4.0, and NIST 800-53 audited environments. The same platform is already part of Atlantic.Net's HIPAA and PCI-compliant hosting stacks. If you run a regulated workload, your firewall controls can be cited directly in audit documentation. ## Protect your network from evolving threats. Atlantic.Net's Managed Firewall delivers comprehensive security with 24/7 monitoring. Contact us to safeguard your data. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at sales@atlantic.net. ## Business Outcomes ### One Platform, Lower Total Cost Running separate firewall, IPS, VPN, web filtering, and sandbox products means multiple contracts, multiple consoles, and multiple skill sets. A Forrester Total Economic Impact study of Fortinet NGFW with FortiGuard AI-powered services reported a 318% three-year ROI, payback in under 6 months, a 50% reduction in network outages, and 40% cost savings compared to the baseline. ### Compliance Without the Assembly Work For workloads under HIPAA, PCI DSS 4.0, SOC 2, or NIST 800-53, firewall and IPS controls are not optional. FortiGate FWaaS is delivered within Atlantic.Net's audited environments, with documentation available for your compliance team. The same platform already underpins our HIPAA-compliant and PCI-compliant hosting services. ### Faster Response to Emerging Threats FortiGuard Labs processes threat telemetry at a scale no individual organization can match. When a new exploit appears in the wild, signatures propagate across every managed FortiGate within minutes. Your defenses update continuously, without your team having to track CVE feeds. ### Business Continuity: You Do Not Have to Babysit Most serious breaches trace back to a perimeter failure: an unpatched appliance, a misconfigured rule, a missed IPS signature. A fully managed FortiGate deployment removes those failure modes from your team's shoulders. Continuous updates, continuous monitoring, continuous response, handled by engineers whose job it is. ## Who Needs FortiGate FWaaS | Business Type | Why FortiGate Fits | | --- | --- | | Healthcare and telehealth | HIPAA-aligned firewall plus IPS in an audited environment, with a BAA available | | E-commerce and payment platforms | PCI DSS 4.0 firewall and IPS requirements covered in one service | | Financial services and fintech | NGFW, IPS, DLP, and SSL inspection for sensitive workflows, with a strong audit trail | | SaaS applications | Hybrid-ready firewall covering cloud and colocated assets under one policy | | Regulated industries | NIST 800-53 alignment and audit documentation available | | Businesses without dedicated security staff | Managed service reduces the need for a full-time firewall engineer | | Hybrid-environment operators | Cloud, dedicated, and remote-user traffic protected under one policy framework | ## A Platform You Can Trust FortiGate is the most widely deployed network firewall in the world. Fortinet is recognized as a Leader in the Gartner Magic Quadrant for Network Firewalls and the Forrester Wave for Enterprise Firewalls, with particular recognition for unified management and consistent AI-powered security across hybrid environments. The threat intelligence driving your deployment comes from FortiGuard Labs, Fortinet's global threat research operation, which processes trillions of security events every day across six million firewalls, three million web gateways, twenty million email systems, ten million endpoints, and five million sandbox detonations. When a threat is detected anywhere in that fleet, your FortiGate benefits within minutes. ## Atlantic.Net operates that platform for you from our audited data center infrastructure - 100% uptime SLA on network, hardware, and power. - 24/7/365 US-based support - phone, email, chat, no outsourcing. - Atlantic.Net since 1994 - 32 years hosting mission-critical workloads. ## Frequently Asked Questions ### What is FortiGate Firewall as a Service? A managed, subscription-based deployment of a Fortinet FortiGate next-generation firewall, operated by Atlantic.Net engineers in front of your hosted infrastructure. It includes firewalling, intrusion prevention (IPS), SSL inspection, VPN, application control, web filtering, and AI-powered threat protection in one platform. Atlantic.Net's Security Operations Center handles configuration, updates, monitoring, and incident response. ### How is this different from the old Atlantic.Net Managed Firewall and IPS services? FortiGate FWaaS replaces both with a single integrated service on the Fortinet FortiGate platform. IPS is built directly into the solution. The new service also adds next-generation capabilities the older products did not provide: SSL inspection, application control, web and DNS filtering, AI-powered malware detection, and continuously updated FortiGuard threat intelligence. ### What's the difference between FortiGate FWaaS and a basic stateful firewall? A basic stateful firewall makes allow/deny decisions on connection state, ports, and protocols. A next-generation firewall like FortiGate also inspects application-layer content, enforces application identity (not just port number), runs intrusion prevention, decrypts and inspects SSL/TLS traffic, blocks malicious URLs, and applies AI-powered threat intelligence inline. The same device replaces several point products and produces a single audit trail. ### Do I need FortiGate FWaaS if I already have software firewalls on my servers? Host-based firewalls (iptables, Windows Firewall, security groups) enforce rules at the operating system level on traffic that has already reached your server. FortiGate inspects and filters upstream before traffic touches your infrastructure, and applies IPS, application control, and deep packet inspection that host firewalls cannot. Most enterprise-grade security postures use both. ### Is FortiGate FWaaS included in HIPAA-compliant or PCI-compliant hosting? Yes. A fully managed FortiGate firewall with IPS is part of both Atlantic.Net's HIPAA-compliant and PCI-compliant hosting stacks. Customers who do not require full HIPAA or PCI compliance but want FortiGate-level network security can subscribe to FortiGate FWaaS as a standalone managed service. ### What does the Atlantic.Net team actually manage? Provisioning and rule configuration, firmware and signature updates, policy tuning, performance monitoring, incident detection, SOC escalation, and reporting. You define the access and security policies you need; we implement and maintain them. Policy changes are made on request through your account team and approved before going live. ### Can FortiGate FWaaS protect servers I have at another data center or cloud? FortiGate FWaaS deploys in front of Atlantic.Net-hosted infrastructure (cloud and dedicated). Hybrid scenarios involving servers at another data center or cloud provider are supported through site-to-site VPN tunnels back to your Atlantic.Net environment. The Atlantic.Net team will scope the topology with you during onboarding. ### How long does FortiGate FWaaS deployment take? Most standalone deployments are operational within a few business days after the policy review is complete. Complex deployments - large rule migrations, multi-site VPN topologies, or audit-driven integrations - may take longer. Atlantic.Net engineers handle the implementation; you sign off on the policy before traffic flows. ### What does "AI-powered" actually mean in FortiGuard threat protection? FortiGuard Labs trains machine-learning models on the trillions of daily telemetry events seen across the FortiGate fleet. Inline malware prevention scores unknown files in real time and produces a verdict before signatures exist. Anomaly-based detection flags traffic that doesn't match known-good baselines. The result is faster blocking of zero-day, polymorphic, and AI-generated threats than signature-only engines deliver. ### How is FortiGate FWaaS priced? FortiGate FWaaS is priced based on the deployment tier, the services activated (NGFW, IPS, AI-powered threat protection, DLP, and so on), and the scale of the protected environment. Contact the Atlantic.Net sales team for a quote tailored to your infrastructure. ## Chat With Sales | Call Us: 866-618-3282 | Contact Us To Get Started Atlantic.Net - Secure Cloud Hosting & Infrastructure Since 1994 ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Multi-Factor Authentication Service > URL: https://www.atlantic.net/managed-services/multi-factor-authentication/ | Updated: 2026-09-16 Verify every login to Linux SSH, Windows RDP, hosted applications, and cloud workloads with managed MFA, role-based policies, device health checks, and flexible second-factor methods. - SOC 2 Type II Infrastructure - HIPAA & HITECH Audited - PCI DSS 4.0 Aligned - Role-Based Access Policies Supported Methods: 4 Server Access: SSH + RDP ### Multi-Factor Authentication Service Verify and authenticate users' identities before granting access to your server environment. Atlantic.Net's Managed Multi-Factor Authentication Service is the easiest way for users to confirm who they are before being granted access to your Linux (SSH) and Windows (RDP) servers, hosted applications, and cloud workloads. The service deploys, integrates, and operates inside Atlantic.Net's SOC 2 Type II, HIPAA, HITECH, and PCI DSS-aligned hosting infrastructure, so the same MFA controls protecting your servers can be cited in your audit documentation. ### What Is Multi-Factor Authentication (MFA)? Multi-Factor Authentication requires two or more methods (also called factors) to verify your identity. Factors typically combine something you know – like a username and password – with something you have, such as a smartphone app that approves authentication requests, or something you are, such as a fingerprint or face scan. You may also see MFA called Two-Factor Authentication (2FA) when only two factors are required. 2FA is a subset of MFA; the terms are used interchangeably in many products. ### Why Do I Need Multi-Factor Authentication? Multi-Factor Authentication is one of the most effective controls against remote attacks such as phishing, social engineering, credential stuffing, and brute-force password attempts. By integrating MFA with your Linux and Windows servers, attackers cannot access your accounts without also possessing the physical device needed to complete the second factor – even if the password has been stolen. ### Did You Know? - An employee or contractor is responsible for 2 out of 3 insider threat incidents. - Negligence-based insider threats cost on average $3.8 million per year. - 52% of users re-use the same password across multiple logins. - Microsoft has reported that MFA blocks more than 99.9% of automated account-compromise attacks. ### How Does the Multi-Factor Authentication Service Work? During login, a verification code or push approval is required in addition to the user's username and password. This adds a second layer of security to the account: even if a password is leaked or guessed, an attacker cannot complete the login without the second factor. ### Atlantic.Net's Managed Multi-Factor Authentication Atlantic.Net's Managed MFA delivers multi-factor authentication as a convenient single sign-on experience. Once cleared, the user gains access to enterprise files and applications – both on-premises and in the cloud – under a single policy framework. Beyond verifying user identity, the service inspects the health of each device. By checking for the presence of essential security controls and out-of-date software, it can block high-risk or potentially compromised machines from connecting in the first place. Administrators retain control to enforce stricter access policies, such as requiring up-to-date software before login, lowering the attack surface against your confidential data. ## Verification Methods Verification can happen by text message, phone call, an authentication app on a smartphone, or a one-time bypass code. Authentication-app codes work even when the user's phone has no cell signal. Administrators can choose one or more of the methods below to verify their users. ### SMS Passcodes A passcode sent to your phone via SMS. Simply enter the code into the login prompt. ### Phone Callbacks Answer a phone call and press any key to complete the login process. ### TOTP Passcodes Open an authentication app on your smartphone and enter the displayed code into the login prompt. These are known as time-based one-time passcodes (TOTP). ### Bypass Codes Useful for lost devices or to provide single-event access for contractors. ## Managed Multi-Factor Authentication Features Atlantic.Net's Managed MFA integrates with most on-premises and cloud applications, including Office 365, Salesforce, Box, Dropbox, Google Workspace, Slack, and DocuSign. SDKs and client libraries cover project management apps such as Confluence, Jira, Splunk, and Drupal, plus Python, Ruby, Classic ASP, and Java to extend MFA into custom applications. ### Easy Registration Facilitate secure access and manage logins for thousands of users via bulk user import, self-enrollment, and advanced admin capabilities including APIs. ### Protected Logins Choose from several MFA methods and set user access policies that match your organization's security needs. ### Policy Enforcement Set up role-based, custom access policies built on parameters that fit your needs. ### Device Hygiene Quickly identify unmanaged onsite and mobile devices and at-risk software. ### Endpoint Access Analyze security insights to differentiate corporate from personal devices, and control which endpoints can access which applications. ### Attack Prevention Identify and contain risky users by mapping software vulnerabilities on their devices via a phishing simulator. ### Endpoint Remediation Automatically prompt users to update their own devices. ### App Protection Protect your cloud apps with secure logins and control which internal apps can be accessed by remote users. ## How MFA Methods Compare | Method | What the User Needs | Strength vs. Phishing | Works Offline | Best For | | --- | --- | --- | --- | --- | | Password only (single-factor) | Username + password | Weak – vulnerable to phishing, leaks, brute force | Yes | Legacy systems (not recommended) | | SMS passcode | Phone with cell signal | Moderate – vulnerable to SIM-swap attacks | No | Consumer apps, low-risk accounts | | Phone callback | Phone with cell signal | Moderate | No | Helpdesk, healthcare front desks | | TOTP authenticator app | Smartphone with TOTP app | Strong | Yes | Enterprise standard for SSH/RDP/SSO | | Push approval | Smartphone with MFA app | Strong – resistant to credential phishing | No (needs data) | Daily enterprise sign-ins | | One-time bypass code | Pre-issued code | Single-use only | Yes | Lost devices, contractor access, break-glass | Improve your security posture with multi-factor authentication. Atlantic.Net's experts can seamlessly implement MFA to protect your applications and servers. Contact us to harden your servers against unauthorized access. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at sales@atlantic.net. ## Frequently Asked Questions About Multi-Factor Authentication ### What is multi-factor authentication (MFA)? Multi-factor authentication is a login control that requires two or more independent factors to confirm a user's identity: something they know (password), something they have (phone, hardware token), or something they are (fingerprint, face). Even if one factor is stolen, an attacker cannot complete the login without the others. ### What is the difference between MFA and 2FA? Two-Factor Authentication (2FA) is a specific case of MFA where exactly two factors are required – typically a password plus a one-time code or push approval. MFA is the broader term that covers two or more factors. Most products use the terms interchangeably. ### Which verification methods does Atlantic.Net's Managed MFA support? SMS passcodes, phone callbacks, time-based one-time passcodes (TOTP) from an authenticator app, and one-time bypass codes for lost devices or single-event access. Push approval and additional methods are available through specific integrations on request. ### Does the service work for Linux SSH and Windows RDP? Yes. Atlantic.Net's Managed MFA integrates with Linux SSH and Windows RDP so that every interactive login requires a second factor in addition to the user's password. ### Can users self-enroll, or does an admin have to register every user? Both. Administrators can bulk-import users via CSV or API, and end users can self-enroll their own devices through a guided workflow. Role-based policies allow you to require self-enrollment by a specific deadline. ### What happens if a user loses their phone or authenticator device? An administrator can issue a one-time bypass code to allow the user a single login without the lost factor. The user re-enrolls a new device inside that session, and the bypass code is invalidated. Lost-device workflows are part of the managed service and do not require a support ticket for routine cases. ### Is MFA required for HIPAA, PCI DSS, or SOC 2 compliance? MFA is either explicitly required or strongly expected by all three. PCI DSS 4.0 requires MFA for all access into the cardholder data environment. HIPAA's Security Rule expects organizations to implement reasonable authentication controls, and MFA is the de-facto baseline for protecting ePHI. SOC 2 auditors look for MFA on administrative and remote access paths. Atlantic.Net's Managed MFA is delivered inside the same audited environment that backs our HIPAA-compliant and PCI-compliant hosting. ### How does MFA integrate with single sign-on (SSO)? Once a user clears MFA, they receive a single-sign-on session that grants access to enterprise files and applications – both on-premises and in the cloud – without re-prompting for the second factor on every app. Session length and re-authentication intervals are policy-driven and tunable per role. ### Can I require MFA only for specific roles or sensitive systems? Yes. Policies are role-based and resource-aware: you can require MFA on production servers and admin consoles while leaving low-risk internal applications under password-only login. Most regulated customers require MFA across the board. ### How is the Managed Multi-Factor Authentication Service priced? Pricing is based on the number of users protected and the integrations required. Contact our sales team for a quote tailored to your environment. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Trend Micro Deep Security Services > URL: https://www.atlantic.net/managed-services/trend-micro-deep-security-suite/ | Updated: 2026-09-16 Protect server workloads with one managed platform for anti-malware, IDS/IPS, web reputation, host firewall, integrity monitoring, and log inspection, backed by Atlantic.Net's US-based NOC. - Physical, Virtual & Cloud Coverage - 24/7/365 US-Based NOC - Six Controls, One Platform - SOC 2, HIPAA & PCI DSS Alignment Log Formats Analyzed: 100+ Managed Packages: 3 ## Trend Micro™ Deep Security Take full advantage of virtualization and cloud computing - in both public and private environments - by leveraging Trend Micro Deep Security. Atlantic.Net's security engineers deploy and manage Deep Security, a comprehensive platform for physical, virtual, and cloud servers designed to protect your data center and cloud workloads from breaches and business disruptions while helping you achieve operational compliance. Deep Security consolidates anti-malware, intrusion detection and prevention, web reputation, host firewall, integrity monitoring, and log inspection into one agent and one policy framework. The platform was purpose-built for hybrid environments and avoids the "AV storms" that legacy endpoint antivirus tools cause when running on virtualized hosts. ### Trend Micro Virtualization Security Protects virtual desktops and servers against zero-day malware and network attacks while minimizing operational impact from resource inefficiencies and emergency patching. ### Trend Micro Cloud Security Enables service providers to offer a multi-tenant cloud environment with security policies that can be extended to cloud workloads and managed centrally with consistent, context-aware policies. ### Flexible and Integrated Server Security Consolidates server security functions into a comprehensive, integrated, and flexible platform that helps manage and optimize protection across physical, virtual, and cloud servers. Integrated modules include anti-malware, web reputation, host firewall, intrusion detection, integrity monitoring, and log inspection - ensuring server, application, and data security across every environment. ## Why Choose Atlantic.Net to Manage Your Trend Micro™ Deep Security? Atlantic.Net deploys and manages Trend Micro Deep Security on your hosted servers. Our monitoring platform receives alerts and notifications from every protected workload in real time, so issues are resolved as they happen. The combination of hardware, software, and managed service delivers round-the-clock, in-depth protection against advanced threats. Atlantic.Net has been securing customer infrastructure since 1994. Our US-based Network Operations Center (NOC) stands by 24/7/365 so your team can focus on the core business while we keep your workloads protected. ## Trend Micro™ Deep Security Suite Packages Atlantic.Net can install and manage one of the following packages on your hosted servers: ### Trend Micro Deep Security Anti-Malware Delivers an anti-malware agent to extend protection to physical, virtual, and cloud servers. Optimizes security operations to avoid the antivirus storms commonly seen during full system scans and pattern updates with traditional security tools. Protects against sophisticated attacks in virtual environments by isolating malware from the critical operating system and security components. ### Trend Micro Deep Security Integrity Monitoring Monitors critical operating system and application files - directories, registry keys, and values - to detect and report malicious or unexpected changes in real time. Uses Intel TPM/TXT technology to perform hypervisor integrity monitoring for any unauthorized changes to the hypervisor, extending security and compliance to the hypervisor layer. Reduces administrative overhead with trusted event tagging that automatically replicates actions for similar events across the entire data center. ### Trend Micro Deep Security Log Inspection Collects and analyzes operating system and application logs in over 100 log file formats, identifying suspicious behavior, security events, and administrative events across your data center. Assists with PCI DSS section 10.6 compliance by surfacing important security events buried in multiple log entries. Forwards events to a SIEM or centralized logging server for correlation, reporting, and archiving. ## Self-Managed Endpoint AV vs. Managed Trend Micro Deep Security What changes when you move from per-server endpoint antivirus to Trend Micro Deep Security managed by Atlantic.Net? The table below summarizes the differences most teams care about. | Capability | Self-Managed Endpoint AV | Trend Micro Deep Security via Atlantic.Net | | --- | --- | --- | | Coverage across physical, virtual, and cloud servers | Often limited or fragmented | Yes - purpose-built for hybrid environments | | Anti-malware | Yes | Yes - agent-based with hypervisor optimizations | | Intrusion detection and prevention (IDS/IPS) | Typically a separate product | Built into the same platform and policy | | Integrity monitoring (files, registry, hypervisor) | Typically a separate product | Yes - including Intel TPM/TXT hypervisor monitoring | | Log inspection (100+ log formats) | Typically a separate product | Yes | | Web reputation | Typically a separate product | Yes | | Avoids "AV storms" in virtualized hosts | No | Yes - agentless options reduce scan contention | | 24/7 management and monitoring | You | Atlantic.Net NOC, 24/7/365 | | PCI DSS section 10.6 (audit trail) coverage | Partial | Yes - log inspection mapped to PCI DSS 10.6 | | Audited environment (SOC 2, HIPAA, PCI DSS) | You | Atlantic.Net audited infrastructure | | Centralized, context-aware policy across the fleet | No | Yes | By choosing one of the Managed Trend Micro™ Deep Security packages from Atlantic.Net, you get a defense system tuned to your environment plus a team of engineers watching it around the clock. We keep all systems updated against evolving threats and tune protection to your real workloads. Purpose-built for virtualized and cloud environments, the solution eliminates coverage gaps to maximize system performance. Defend against advanced threats with Trend Micro Deep Security. Atlantic.Net delivers comprehensive protection for your server workloads against the latest cybersecurity threats. Contact us to fortify your security. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at sales@atlantic.net. ## Frequently Asked Questions About Trend Micro Deep Security ### What is Trend Micro Deep Security? Trend Micro Deep Security is a server-protection platform purpose-built for hybrid environments. It consolidates anti-malware, intrusion detection and prevention, web reputation, host firewall, integrity monitoring, and log inspection into a single agent and policy framework that works across physical, virtual, and cloud workloads. ### What does Atlantic.Net's Managed Trend Micro Deep Security service include? Atlantic.Net engineers handle deployment, policy configuration, signature and engine updates, performance tuning, monitoring, and incident response. Alerts are watched 24/7/365 by our US-based Network Operations Center, and the service is delivered from inside our SOC 2, HIPAA, and PCI DSS-aligned hosting infrastructure. ### What environments does Deep Security protect? Physical servers, virtual machines (including VMware), and cloud workloads on Atlantic.Net's Cloud Platform and Dedicated Server Hosting. Policies travel with the workload across hybrid deployments, so a virtual machine keeps the same protection profile when it moves between hosts. ### Which Deep Security modules are included? The available packages are Anti-Malware, Integrity Monitoring, and Log Inspection. Anti-Malware delivers agent-based protection optimized to avoid AV storms; Integrity Monitoring watches files, registry keys, and the hypervisor itself (via Intel TPM/TXT) for unauthorized change; Log Inspection collects and analyzes events across 100+ log formats to surface suspicious activity. ### How is this different from running endpoint antivirus on each server? Traditional endpoint AV protects against malware but typically does not include IDS/IPS, integrity monitoring, log inspection, or web reputation in the same product. It also often causes "AV storms" on virtualized hosts during full scans or pattern updates. Deep Security consolidates those controls into one platform with virtualization-aware optimizations and centralized policy. ### Does Deep Security help with PCI DSS or HIPAA compliance? Yes. Log Inspection maps directly to PCI DSS section 10.6 (review of audit logs). Anti-Malware addresses PCI DSS Requirement 5. Integrity Monitoring supports PCI DSS Requirement 11.5 and HIPAA's expectation of detecting unauthorized change to ePHI environments. Atlantic.Net's deployment runs inside the same audited infrastructure that backs our HIPAA-compliant and PCI-compliant hosting. ### What is integrity monitoring and why does it matter? Integrity monitoring watches the files, directories, and registry keys that shouldn't change without an approved reason - system binaries, configuration files, security policies, and (with Intel TPM/TXT) the hypervisor itself. Unauthorized change is one of the earliest signals of an active intrusion, ransomware staging, or insider abuse, and several compliance frameworks require this control. ### Can I add Deep Security to existing Atlantic.Net hosted servers? Yes. The service is available as an add-on to existing Atlantic.Net Cloud Platform and Dedicated Server Hosting environments. Our engineers handle agent installation, policy provisioning, and the cutover to managed monitoring with minimal disruption. ### Does the agent slow down my servers? Deep Security was built specifically for virtualized and cloud environments and uses agent and agentless options to keep overhead low. Scan scheduling, deduplication, and hypervisor-aware optimizations avoid the "AV storm" pattern in which dozens of VMs scan at once and saturate the host. Atlantic.Net engineers tune the deployment to match your workload profile. ### How is the Managed Trend Micro Deep Security service priced? Pricing is based on the package selected (Anti-Malware, Integrity Monitoring, Log Inspection, or a combined suite), the number and type of protected workloads, and the environments under coverage. Contact our sales team for a quote tailored to your environment. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # DDoS Protected Server Hosting > URL: https://www.atlantic.net/managed-services/network-edge-protection/ | Updated: 2026-09-16 Filter attacks before they reach your servers with always-on DDoS mitigation, a managed ModSecurity WAF covering the OWASP Top 10, an included global CDN, and web optimization monitored 24/7/365 by Atlantic.Net's US-based NOC. - Always-On DDoS Mitigation - Managed WAF & OWASP Top 10 - Global CDN Included - No Code or Hardware Changes Monitoring & Response: 24/7/365 DDoS Pricing: Fixed ## Network Edge Protection Services Secure your valuable data with a managed Web Application Firewall, Content Delivery Network, and web optimization - all backed by always-on DDoS mitigation. Atlantic.Net's Managed Network Edge Protection lets you stay focused on your core business while our engineers absorb attacks, enforce policy, and accelerate delivery at the network perimeter. What Is Network Edge Protection? Network edge protection is a set of security and performance controls deployed at the network perimeter - the boundary between the public internet and your servers - to safeguard workloads against unauthorized access, DDoS attacks, application-layer abuse, and other cyber threats. The goal is to preserve the confidentiality, integrity, and availability of customer data while keeping legitimate traffic fast. ## What's Included ### DDoS Protection Denial-of-service (DoS) attacks interrupt an authorized user's access to a computer network. They have grown more frequent and more complex, including distributed (DDoS) and distributed reflector (DRDoS) variants - coordinated traffic floods from large botnets that make the source much harder to identify. Modern attacks bypass traditional on-site defenses. Atlantic.Net's edge protection technology is designed to ensure that DDoS, DRDoS, and any service-denial traffic never reach your internet properties. The DDoS network is built to contain and repel advanced attacks - including UDP and ICMP floods, SYN/ACK abuse, DNS amplification, and Layer 7 application-layer attacks. Atlantic.Net's DDoS protection pricing is fixed, so a traffic spike during an attack does not turn into an unpredictable bill. The primary objective is your safety and operational continuity. ### Robust Web Application Firewall The integrated Web Application Firewall (WAF) inspects web traffic for suspicious activity and automatically filters out illegitimate requests based on rule sets that Atlantic.Net applies for you - or custom rules you can request. The WAF examines GET and POST-based HTTP requests and applies rules such as the ModSecurity core rule set covering the OWASP Top 10 vulnerabilities, deciding what to block, challenge, or let pass. It blocks comment spam, cross-site scripting (XSS), and SQL injection. The WAF protects your internet property against attacks - including zero-day vulnerabilities - without compromising performance, while supporting PCI compliance requirements for online merchants. Coverage extends across the OWASP Top 10 plus custom rules for explicit attack patterns. Implementation does not require changes to your network architecture. ### Website Optimization Web optimization streamlines content delivery by bundling JavaScript files, minimizing network connections, and compressing resource size to boost performance. Traffic is routed through the least-congested portions of our network. The goal is to ensure that the various content types - including third-party resources embedded in your site - do not compromise loading time, regardless of the network or device used to access the content. The system automatically adapts presentation and delivery for different screen shapes and sizes while preserving speed and reliability for a seamless mobile experience. Activating these services is fast, requires no code changes, and adds no hardware. Features include: Automatic HTTPS rewrites - dynamically rewriting insecure URLs for both performance and security. Automatic content caching - intelligently caching the objects required to render your site quickly. Accelerated mobile links - drastically reducing mobile page-load time. Automatic minification - removing unnecessary characters from HTML, CSS, and JavaScript. Mix and match these features to take application performance to the next level. ### Seamless Content Delivery Network (CDN) With servers positioned across key global points, Atlantic.Net's network delivers your content to customers with high speed and reliability. Lightweight infrastructure with integrated load balancing and built-in failover preserves performance while improving security. A smaller footprint translates to optimal use of power and cooling while preserving the integrity and seamless flow of your data. As information travels, the CDN caches data and routes traffic by server proximity, so users reach your content quickly regardless of location. The system is easy to set up, with affordable and predictable pricing. The platform is designed for the future. The network is continuously updated to integrate with emerging technologies. The mission is 100% uptime alongside access to state-of-the-art delivery solutions. ## Self-Managed Network Security vs. Managed Network Edge Protection | Capability | Self-Managed Network Security | Atlantic.Net Network Edge Protection | | --- | --- | --- | | DDoS mitigation | Per-attack scrubbing fees or outages | Always-on mitigation at the network edge | | Coverage of advanced attacks (Layer 7, SYN/ACK, DNS amplification, DRDoS) | Often partial | Yes - designed against modern attack types | | Web Application Firewall (OWASP Top 10) | Separate product, separate vendor | Built in - ModSecurity-based managed rule set | | Custom WAF rules | Limited or self-built | Yes - configured and managed by Atlantic.Net | | Content Delivery Network (CDN) | Separate vendor and contract | Built in | | Web optimization (HTTPS rewrites, caching, minification) | Self-implemented | Built in, no code changes required | | Pricing during a DDoS attack | Variable - subject to traffic-based spike billing | Fixed | | 24/7 monitoring and response | You | Atlantic.Net NOC, US-based | | Network architecture changes required | Usually yes - integrating multiple vendors | None - transparent at the edge | | Compliance posture (PCI DSS) | You | Atlantic.Net audited environment | | Time to deploy | Weeks to months for multi-vendor stack | Days | ## Frequently Asked Questions About Network Edge Protection ### What is network edge protection? Network edge protection is a set of security and performance controls deployed at the boundary between the public internet and your servers. It typically combines always-on DDoS mitigation, a web application firewall, a content delivery network, and web optimization. The goal is to absorb attacks and accelerate legitimate traffic before either reaches your application. ### What's included in Atlantic.Net's Network Edge Protection? Always-on DDoS mitigation against UDP/ICMP floods, SYN/ACK abuse, DNS amplification, and Layer 7 attacks; a Web Application Firewall (WAF) covering OWASP Top 10 with managed and custom rules; web optimization (HTTPS rewrites, automatic caching, accelerated mobile links, automatic minification); and a global Content Delivery Network. The service is monitored 24/7/365 by our US-based Network Operations Center. ### How does this differ from on-server iptables or host firewalls? Host firewalls (iptables, Windows Firewall, security groups) enforce rules at the operating system level on traffic that has already reached your server. Network Edge Protection inspects and filters traffic upstream, before it touches your infrastructure, and applies DDoS mitigation, WAF rules, and CDN routing that host firewalls cannot. Most production environments use both. ### What types of DDoS attacks are mitigated? Volumetric attacks targeting UDP and ICMP, protocol attacks such as SYN/ACK floods, reflection and amplification attacks (including DNS amplification), distributed reflector denial-of-service (DRDoS), and Layer 7 application-layer attacks targeting HTTP/HTTPS endpoints. ### Will my pricing spike during a DDoS attack? No. Atlantic.Net's DDoS protection pricing is fixed, so traffic-volume fluctuations during an attack do not turn into an unpredictable bill. You pay for protection, not for absorbing attack traffic. ### How does the Web Application Firewall (WAF) work? The WAF inspects GET and POST HTTP/HTTPS requests against rule sets (including the ModSecurity core rule set covering the OWASP Top 10) and blocks, challenges, or allows traffic accordingly. It defends against SQL injection, cross-site scripting, comment spam, and common zero-day patterns without requiring changes to your application code or network architecture. ### Can I customize WAF rules for my application? Yes. Atlantic.Net engineers maintain the managed baseline rule set, and custom rules can be added on request to address application-specific attack patterns or business logic. Rule changes follow a review-and-approve workflow through your account team. ### Is the Content Delivery Network (CDN) included? Yes. The CDN is bundled into Network Edge Protection. Globally distributed cache nodes and proximity-based routing accelerate content delivery, and integrated load balancing with built-in failover preserves availability without a separate vendor or contract. ### Does Network Edge Protection help with PCI DSS compliance? Yes. PCI DSS 4.0 requires defenses against well-known attack patterns and access controls at the network perimeter. The Network Edge Protection WAF and DDoS mitigation map directly to those requirements, and the service runs inside the same audited infrastructure that backs our PCI-compliant and HIPAA-compliant hosting. ### Do I need to change my network architecture to use it? No. Network Edge Protection deploys transparently in front of your existing infrastructure - no code changes, no new hardware. The usual change is a DNS update so traffic flows through Atlantic.Net's edge before reaching your servers. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Managed Veeam Service from Atlantic.Net > URL: https://www.atlantic.net/managed-services/veeam-services/ | Updated: 2026-09-16 Protect physical, virtual, and cloud workloads with Veeam licensing, policy design, off-site repository storage, 24/7/365 monitoring, automatic integrity validation, and engineer-led recovery managed by Atlantic.Net. - Windows & Linux Workloads - On-Site & Off-Site Backups - Bare-Metal to File-Level Restore - 24/7/365 US-Based NOC Monitoring Coverage: 24/7/365 Backup Baseline: 3-2-1 Rule ## Veeam Backup Agents Atlantic.Net's Veeam Backup and Replication Agent service provides an industry-leading data protection suite that helps guarantee data integrity across both physical and virtual infrastructure. Lightweight backup agents work with Microsoft Windows Server and Linux servers to deliver enterprise-grade features, high performance, and broad compatibility. Make our fast, affordable, and proven backup technology the cornerstone of your data protection strategy – with Atlantic.Net engineers configuring, monitoring, and recovering on your behalf. ## Key Capabilities of Veeam ### Reduce Costs After a full backup seed has completed, an incremental backup is scheduled which copies only new or changed data blocks, reducing backup size. Advanced deduplication technology further reduces backup-set size. ### Incremental Forever Technology After the initial full backup, only new or changed blocks are captured indefinitely – no scheduled re-fulls. Synthetic-full operations stitch incrementals together at the repository so restores remain fast while data movement stays minimal across the network and storage. ### High-Speed Backup and Recovery Incremental backups are fast and use minimal system resources. Recovery is quick and reliable, with each backup validated for integrity before being marked successful. ### Onsite and Offsite Backup Capabilities The highly available solution offers on-site storage for local backups and off-site storage capability at any of our global data center locations – supporting the 3-2-1 backup rule as a baseline. ### Veeam Agents Veeam Agents fully support Microsoft Windows and Linux distributions and deliver comprehensive backup and recovery for all workloads – virtual, physical, and cloud-based. ### Linux Supported Distributions 64-bit and 32-bit support for Debian 11/12, Ubuntu 20.04/22.04 LTS, Rocky Linux 8/9, AlmaLinux 8/9, RHEL 8/9, Oracle Linux 8/9, Fedora, openSUSE, and SLES. Modern long-term support (LTS) kernels are recommended. ### Windows Supported Distributions 64-bit and 32-bit support for Microsoft Windows 10 and 11 (client OS), and Windows Server 2016, 2019, 2022, and 2025. Active long-term support versions are recommended so security patches remain available throughout the deployment lifetime. ## Available Backup Types Include ### Restoring options: Back up and restore your entire virtual or physical server to the original location or a newly provisioned environment. Bare-metal restore is supported directly to a dedicated server or hypervisor – private cloud or public cloud. ### Volume-level: Back up and restore an entire hard drive or a partition in its entirety to protect against corrupt files and volume degradation. ### Granular file-level: Restore individual files from any backup file to any reachable destination server in minutes. Achieve peace of mind with reliable backups and rapid recovery. Atlantic.Net's Managed Veeam Service ensures your data is protected and available 24x7x365. Contact us to implement a proven and robust backup strategy. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at sales@atlantic.net. ## Self-Managed Veeam vs. Managed Veeam from Atlantic.Net | Capability | Self-Managed Veeam | Atlantic.Net Managed Veeam | | --- | --- | --- | | Veeam licensing | You source and manage | Included with the service | | Initial setup and policy design | You | Atlantic.Net engineers | | Agent install on Windows and Linux servers | You install per server | Atlantic.Net | | Off-site backup repository | You provision | Atlantic.Net data center storage included | | 24/7 backup job monitoring | You | Atlantic.Net NOC, US-based | | Backup integrity validation | You schedule | Automatic on every successful backup | | Bare-metal and granular file restores | You execute | Atlantic.Net handles on request | | Capacity planning and storage tiering | You | Yes | | Compliance posture (SOC 2, HIPAA, PCI DSS) | You | Atlantic.Net audited environment | | Restore SLA support | You | Yes – with engineer-led recovery | | Time to first successful backup | Weeks to months | Days | ## Frequently Asked Questions About Managed Veeam ### What is Veeam Backup and Replication? Veeam Backup and Replication is an enterprise data-protection platform that backs up and replicates virtual, physical, and cloud workloads. It supports image-level VM backups, agent-based server backups, granular file-level restore, bare-metal restore, replication for disaster recovery, and integrity validation of every restore point. ### What does Atlantic.Net's Managed Veeam Service include? Veeam licensing, agent installation on supported Windows and Linux servers, backup policy design, scheduled execution, integrity validation, off-site repository storage, 24/7/365 monitoring from our US-based NOC, and engineer-led recovery on request. The service runs inside our SOC 2 Type II, HIPAA, HITECH, and PCI DSS-aligned hosting infrastructure. ### Which operating systems do the Veeam agents support? Microsoft Windows 10 and 11, Windows Server 2016, 2019, 2022, and 2025; and Linux distributions including Debian 11/12, Ubuntu 20.04/22.04 LTS, Rocky Linux 8/9, AlmaLinux 8/9, RHEL 8/9, Oracle Linux 8/9, Fedora, openSUSE, and SLES. Active long-term support versions are recommended. ### What types of restores can I perform? Three primary restore patterns are supported. Bare-metal restore brings an entire server back to the original or a newly provisioned environment, including direct restore to a dedicated server or hypervisor (private or public cloud). Volume-level restore returns an entire drive or partition. Granular file-level restore brings individual files back to any reachable destination server in minutes. ### How does Veeam's Incremental Forever technology work? After the initial full backup seed, only new or changed data blocks are captured indefinitely – no scheduled re-fulls. Synthetic-full operations stitch incrementals together at the repository so restores remain fast while network and storage usage stay minimal. Combined with deduplication and compression, this drastically reduces both backup windows and repository footprint. ### Where are the backups stored? The Managed Veeam Service supports on-site storage for local backups and off-site storage in Atlantic.Net's global data centers. Customers can place primary and secondary repositories in different regions to satisfy the 3-2-1 backup rule (three copies of data, on two different media, with one off-site). Cloud-tier targets such as Amazon S3, Azure Blob Storage, and Google Cloud Storage are also supported on request. ### Does Managed Veeam help with HIPAA, PCI DSS, or SOC 2 compliance? Yes. Backup and recoverability are explicit controls in HIPAA's Security Rule, PCI DSS, and SOC 2 trust criteria. Atlantic.Net's Managed Veeam runs inside the same audited environment that backs our HIPAA-compliant and PCI-compliant hosting, with documented procedures available to your compliance team. A Business Associate Agreement (BAA) is available for HIPAA workloads. ### How is data protected in transit and at rest? Veeam supports end-to-end AES-256 encryption: data is encrypted at the source, in transit, and at rest in the repository. Atlantic.Net engineers configure encryption keys, key rotation, and access policy as part of the managed service so encrypted backups never block legitimate recovery. ### What is the difference between Veeam Cloud Backup and Veeam Backup & Replication? Veeam Cloud Backup is the off-site cloud target where backup copies live; Veeam Backup & Replication is the platform that creates, schedules, and recovers those backups on premises and in the cloud. Most regulated customers run both: Backup & Replication produces the backups, Cloud Backup stores the off-site copy. Atlantic.Net's Managed Veeam Service covers both. ### How is the Managed Veeam Service priced? Pricing is based on the number and type of protected workloads, the data volume backed up and retained, and the retention period. Atlantic.Net partners with Veeam to offer competitive bundled pricing. [Contact Atlantic.Net](https://www.atlantic.net/about-us/corporate-contact/) for a quote tailored to your environment. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Managed Load Balancing > URL: https://www.atlantic.net/managed-services/load-balancing/ | Updated: 2026-09-16 Distribute traffic across healthy web and application servers with managed health checks, automatic failover, SSL termination, sticky sessions, and four supported balancing algorithms, delivered alongside Atlantic.Net's Managed Firewall. - Round Robin & Least Connections - Health Checks & Automatic Failover - SSL/TLS Termination - Integrated Managed Firewall Supported Algorithms: 4 Pool Health Monitoring: 24/7 ## Load Balancing Today's modern high-traffic websites are expected to serve millions of concurrent sessions and still deliver fast, reliable web pages and digital content. A load balancer is a cost-effective, performance-enhancing solution - and Atlantic.Net delivers it as a managed service alongside our Managed Firewall. Load balancing distributes traffic across a pool of web and application servers, and it can dramatically improve customer experience under sustained or bursty load. Our service lets you add diverse application and web servers into a load-balancing pool to deliver a faster, more reliable experience to your customers and end users. ## What Is Load Balancing? Load balancing is a technique that distributes incoming network traffic across multiple servers to ensure optimal resource utilization, improved performance, and high availability for applications - especially during peak usage periods. The load balancer sits in front of your application fleet, decides which server should answer each request, and routes around servers that are unhealthy or saturated. ## What Can Load Balancing Do For Me? Take the complexity and the technology headache off your team's plate by using Atlantic.Net's Managed Load Balancing service to enhance the performance and reliability of your business-critical websites: - Load Balancing - distribute incoming application traffic across multiple Atlantic.Net servers for an improved customer experience. - Ensure High Availability - increase reliability, redundancy, and failover capability by sending requests only to healthy servers, providing continuity during unexpected outages. - Flexibility - add or remove servers as demand changes - perfect for clients with seasonal peaks or busy promotional periods. - Increase Scalability - Atlantic.Net's Managed Load Balancing grows with your business. Whether you start small or scale aggressively, the service adapts. - Reduced Downtime - during scheduled maintenance, live services stay online while individual servers are updated. - Increase Performance - provide better response times to web services by distributing the workload. ## Load Balancing Algorithms Atlantic.Net's Managed Firewall and Load Balancing service supports the load balancing algorithms most teams need: - Round Robin - this simple algorithm sends incoming traffic to the next available server in the load-balancing cluster, in sequence (node 1, node 2, node 3, and so on). - Static Round Robin - this method allocates a weighting or priority to a particular server, so incoming traffic is distributed to the preferred node(s) in the cluster when available. - Least Connections - the load balancer tracks the number of open connections per server and sends each new request to the least busy server. - IP Source - connections are distributed based on the source IP address. This is a great option for geolocation-aware load balancing. As long as the same set of servers is healthy, a given client IP always lands on the same server. ## Load Balancing Features Atlantic.Net's Managed Firewall and Load Balancing service combines the most popular techniques in load-balancing technology, backed by the Atlantic.Net Firewall Service so you get security plus traffic distribution under one managed offering. For more information, email sales@atlantic.net. - Sticky Sessions - this efficiency feature keeps a user connected to the same web server for the duration of their session, avoiding the cost of re-opening session state on multiple servers and reducing overhead. - Health Checks - the load balancer probes pool members for availability and health. Unhealthy nodes are flagged and bypassed until they recover. - SSL Termination - SSL/TLS encryption is decoded on the load balancer before traffic reaches the web server. This improves performance and reduces the cryptographic workload on backend nodes. - Multi-Port Balancing - this advanced technique routes traffic configured for a specific application port to one or more servers, giving application developers more performance flexibility. - Connection Throttling - protects the load-balancing pool when specific incoming requests demand significant resources, preventing bandwidth-heavy applications from impacting the entire cluster. ## Self-Hosted Load Balancer vs. Atlantic.Net Managed Load Balancing | Capability | Self-Hosted (HAProxy / Nginx) | Atlantic.Net Managed Load Balancing | | --- | --- | --- | | Setup, configuration, and hardening | You | Atlantic.Net engineers | | Algorithms (Round Robin, Static RR, Least Connections, IP Source) | Yes - manual configuration | Yes - pre-configured and tunable | | Sticky sessions | Yes | Yes | | Health checks and automatic failover of unhealthy nodes | Yes - you tune intervals and thresholds | Yes - managed defaults | | SSL/TLS termination | Yes - you manage certificate lifecycle | Yes - certificate handling included | | Multi-port balancing and connection throttling | Yes | Yes | | Integrated with managed firewall and DDoS mitigation | No - separate stack | Yes - same managed service | | High availability of the load balancer itself | You build the HA pair | Yes - HA included | | 24/7 monitoring of pool health | You | Atlantic.Net NOC, US-based | | Compliance posture (SOC 2, HIPAA, PCI DSS) | You | Atlantic.Net audited environment | | Time to deploy | Days to weeks | Hours | Ensure optimal application performance and reliability. Atlantic.Net's Managed Load Balancing delivers high availability and predictable scalability. Contact us to add resilience to your infrastructure. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at sales@atlantic.net. ## Frequently Asked Questions About Load Balancing ### What is load balancing? Load balancing is a technique that distributes incoming network traffic across a pool of servers so no single server is overloaded. The load balancer sits in front of the application fleet, decides which server should answer each request, and routes around servers that are unhealthy or saturated. The result is better performance, higher availability, and more predictable scaling under load. ### Why do I need load balancing? Any application that needs to stay online during a server failure, scale beyond a single server's capacity, or absorb traffic spikes is a candidate for load balancing. Common drivers are seasonal peaks, marketing-driven traffic surges, regulatory uptime requirements, and the need to perform zero-downtime maintenance on individual servers. ### Which load-balancing algorithms does Atlantic.Net support? Round Robin, Static (Weighted) Round Robin, Least Connections, and IP Source. Round Robin and Static Round Robin distribute by sequence and weight; Least Connections sends each new request to the least-busy server; IP Source pins traffic from a given client IP to a specific server, useful for geolocation-aware routing or session affinity at the network layer. ### What's the difference between Round Robin and Least Connections? Round Robin distributes traffic by simple sequence regardless of how busy each server is, which is fine for short, similar requests but can overload a server stuck on a slow request. Least Connections looks at the actual open-connection count and routes to the least-loaded server, which handles long-lived or uneven workloads more gracefully. ### Does the service include SSL termination? Yes. SSL/TLS termination on the load balancer decrypts incoming HTTPS traffic before it reaches your backend servers. This centralizes certificate management and reduces the cryptographic workload on each web server, improving throughput. End-to-end encryption between the load balancer and backends is supported when policy requires it. ### What are sticky sessions and when should I use them? Sticky sessions (also called session affinity) keep a given user pinned to the same backend server for the duration of their session. They are useful for applications that store session state in local memory and cannot share that state across servers. Stateless applications - those that store session data in a shared cache or database - do not need sticky sessions and benefit from more even load distribution without them. ### How are server failures detected and handled? The load balancer continuously runs health checks against every server in the pool. When a server fails its check - for example, no response on the configured port within the configured timeout - it is taken out of rotation automatically and skipped until subsequent checks confirm it has recovered. Atlantic.Net's NOC is also alerted so engineers can investigate the underlying issue. ### Can I add or remove servers from the pool dynamically? Yes. Servers can be added to or drained from the pool on request, which is what makes the service well suited to seasonal peaks, marketing launches, or rolling maintenance. Atlantic.Net engineers handle the change so existing sessions are not disrupted. ### Does this integrate with Atlantic.Net's Managed Firewall? Yes. Managed Load Balancing is delivered alongside Atlantic.Net's Managed Firewall on the same FortiGate-based platform, so you get traffic distribution and perimeter security under a single managed contract, with one policy framework and one support relationship. GeoIP load balancing is also available via the Network Edge Protection service. ### How is the Managed Load Balancing service priced? Pricing is based on the size of the load-balanced pool, the throughput required, and the bundled features (SSL termination, GeoIP, integration with Managed Firewall). Contact our sales team for a quote tailored to your environment. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Managed Consulting Services > URL: https://www.atlantic.net/managed-services/consulting/ | Updated: 2026-09-16 Choose the Consulting Action Plan tier that fits your work, from application installation and configuration through clustering, hypervisor and SAN architecture, BGP routing, database administration, and compliance audit engineering. - 4 Consulting Action Plan Tiers - Application to Architecture Support - Senior Engineer-Led Tier 4 - Compliance Audit Engineering CAP Service Levels: 4 Highest CAP Level: Tier 4 ## Managed Consulting Services Beyond hosting infrastructure protected by deep security, Atlantic.Net offers a comprehensive, four-tier Managed Consulting Action Plan (CAP). The right tier for your organization depends on the architecture you operate within and the depth of engineering support your applications and team need. Each tier inherits the capabilities of the tier below it and adds new ones – from click-and-execute application support at Tier 1 up to senior-engineer architecture work at Tier 4. The summary table below shows what's included at each level so you can match the engagement to the work. ### Tier 1 CAP Tier 1 covers the basic layer of support: click/execute applications and rudimentary configuration changes. Includes data migration via File Transfer Protocol (FTP) and installation of free cross-platform clients such as FileZilla on Windows. This level of CAP covers the most fundamental configuration tasks – for example, installation of basic Windows applications. Package management on RPM-based distributions (Rocky Linux, AlmaLinux, RHEL, Oracle Linux) is also covered: YUM on older systems, DNF on RHEL 8+ and modern derivatives. Both let you handle automatic updates and dependency resolution from the command line. ### Tier 2 CAP Tier 2 is ideal for basic application management. It includes installation and configuration of cPanel or Plesk to create a streamlined web hosting environment for new sites, reseller accounts, email accounts, and DNS entries via a web-based interface. The Tier 2 service level includes site migration for the platforms above as well as web server software such as Microsoft IIS or Apache. It also covers installing and configuring applications under our Managed Scope of Support for non-managed customers. Tier 2 work is usually completed by a Customer Support Technician; basic tasks traditionally associated with Tier 1 work (dial-up and web-hosting support) are completed by an SOC technician. ### Tier 3 CAP Tier 3 includes everything in Tier 1 and Tier 2, plus tasks suited for high-level, customized applications. Examples include kernel recompilation and the setup of Linux-based clustering – Pacemaker (the modern successor to the original Heartbeat project) for high-availability cluster management, and DRBD for distributed replicated block storage. Tier 3 also covers hypervisor setup as a foundation for failover, high availability, and storage area network (SAN) deployments that provide consolidated block-level data storage. Both Type 1 and Type 2 hypervisors are supported – Type 1 includes Xen (which lets multiple operating systems run concurrently on the same hardware) and VMware ESXi for deploying and serving virtual machines, while Type 2 includes Microsoft Hyper-V running on Windows Server. To guarantee a robust level of service, Tier 3 ensures that the Customer Support Technician responding to a request is highly skilled and well versed in the issue at hand. ### Tier 4 CAP On top of all the lower tiers, Tier 4 adds high-end services such as Border Gateway Protocol (BGP) routing for traffic across the public internet. BGP is most relevant to network teams at organizations that connect to two or more ISPs, where it is essential to maintain fast connectivity and add redundancy. Tier 4 also covers database administration and repair, and engineering support for compliance audits. Tier 4 CAP work is performed by a senior engineer and includes the implementation of leading-edge and advanced current technologies. ## CAP Tier Comparison | Capability | Tier 1 | Tier 2 | Tier 3 | Tier 4 | | --- | --- | --- | --- | --- | | Click/execute applications & basic config changes | Yes | Yes | Yes | Yes | | FTP & data migration (FileZilla, command-line clients) | Yes | Yes | Yes | Yes | | YUM / DNF package management on RPM-based Linux | Yes | Yes | Yes | Yes | | cPanel / Plesk install & configuration | – | Yes | Yes | Yes | | Site migrations and IIS / Apache configuration | – | Yes | Yes | Yes | | Applications under Managed Scope of Support | – | Yes | Yes | Yes | | Kernel recompilation | – | – | Yes | Yes | | HA clustering (Pacemaker, DRBD) | – | – | Yes | Yes | | Hypervisor setup (Xen, VMware ESXi, Microsoft Hyper-V) | – | – | Yes | Yes | | SAN setup & storage architecture | – | – | Yes | Yes | | BGP routing for multi-ISP connectivity | – | – | – | Yes | | Database administration & repair | – | – | – | Yes | | Engineering support for compliance audits | – | – | – | Yes | | Engineer assigned | SOC Technician | Customer Support Technician | Senior Customer Support Technician | Senior Engineer | ## Have a vision for your IT but need help to make it happen? Our expert consultants provide strategic guidance and tailored solutions to help you achieve your goals. Schedule a consultation today and let's turn your vision into reality. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at sales@atlantic.net. ## Frequently Asked Questions About Managed Consulting ### What is Atlantic.Net's Managed Consulting Service? Managed Consulting is a four-tier engagement framework – the Consulting Action Plan, or CAP – that puts Atlantic.Net engineers on your IT projects. Tier 1 covers click-and-execute application support; Tier 4 covers senior-engineer architecture work like BGP routing, database administration, and compliance audit support. Each tier inherits the capabilities of the tier below it. ### What does CAP stand for? CAP stands for Consulting Action Plan. It's the framework Atlantic.Net uses to scope consulting engagements to a specific tier of work and engineer skill level so that pricing and outcomes are predictable. ### How do I choose the right tier? Pick the tier that matches the most complex work you anticipate. If you need basic application installation and configuration changes, Tier 1 or Tier 2 is enough. If you need clustering, hypervisor setup, or SAN architecture, Tier 3 is the right starting point. If you need BGP, database administration, or compliance audit engineering, Tier 4 is required. The Atlantic.Net sales team will help you scope the right tier based on the work you describe. ### What's included in Tier 1? Click/execute application support, basic configuration changes, FTP-based data migration with clients like FileZilla, and package management on RPM-based Linux (YUM on older systems, DNF on RHEL 8+ and modern Rocky/AlmaLinux). Tier 1 work is performed by an SOC technician. ### What's the difference between Tier 2 and Tier 3? Tier 2 focuses on application-management work: installing and configuring control panels (cPanel, Plesk), web servers (IIS, Apache), and applications under our Managed Scope of Support. Tier 3 adds infrastructure-level work: kernel recompilation, HA clustering with Pacemaker and DRBD, hypervisor setup (Xen, VMware ESXi, Hyper-V), and SAN architecture. Tier 3 work is performed by a senior Customer Support Technician. ### When should I consider Tier 4? Tier 4 is for organizations that need senior-engineer-led work. Common triggers are BGP routing for multi-ISP connectivity, deep database administration and repair, complex storage architecture, and engineering support for HIPAA, PCI DSS, or SOC 2 compliance audits. Tier 4 work is performed by a senior engineer. ### Does CAP include compliance audit support? Tier 4 includes engineering support for compliance audits – helping you produce documentation, evidence, and configuration artifacts your auditor needs. Atlantic.Net does not perform the audit itself; that is done by a third-party assessor. The hosting infrastructure your workloads run in is independently audited for SOC 2 Type II, HIPAA, HITECH, and PCI DSS, and those audited controls are available for your audit team to cite. ### Can I upgrade or downgrade tiers later? Yes. Tier changes are coordinated through your account team. Most customers start at the tier that matches their current architecture and move up as projects expand or as their environment matures. ### Does CAP cover existing third-party applications? Tier 2 and above cover applications that fall under our Managed Scope of Support. Application logic, custom code, and query analysis are out of scope across all tiers; those are typically handled through a Professional Services agreement. ### How is the Managed Consulting service priced? Pricing is based on the tier selected, the scope of the engagement, and the engineer level required. Atlantic.Net's sales team will scope the work and provide a quote tailored to your environment. ## A Support Team Backed by Decades of Experience With over three decades of experience, our support team is always here to assist you. You’ll have 24/7/365 access to a crop of dedicated veterans, capable of solving any technical problem you throw their way. ## Cloud Availability in Multiple Global Regions Deploy close to your users from eight international data centers worldwide, with new regions on the way. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Careers at Atlantic.Net > URL: https://www.atlantic.net/about-us/careers/ | Updated: 2026-09-16 ## Join the Winning Team! We are excited to welcome you to our Careers page, where you will find opportunities to advance in the world of hosting, cloud services, and managed services! ## Who We Are Atlantic.Net is made up of seasoned professionals who have been with the organization for many years. Since our beginnings in the mid-1990s, we've evolved from a dial-up internet company to a leading global cloud service provider. Atlantic.Net is still managed by the original Founder and CEO, Marty Puranik, who takes pride in running a successful business since 1994. ## Why Work at Atlantic.Net? Atlantic.Net is an excellent place to work because of the stability that comes from our focus on a long-term strategy for success. The company is self-funded (we do not take funding from venture capital firms or Wall Street) and continues to grow revenues year over year! Atlantic.Net's ability to pivot and refocus business strategies has shielded us from the ups and downs of the economy, helping protect our team from volatility and provide a stable work opportunity regardless of the economic conditions. If you are open to change, love to learn new ideas, and are interested in a career with great growth potential, you've come to the right place. Join a team of entrepreneurs who enjoy freedom at work, have a passion for delivering outstanding products and services, and believe in adapting to and learning new technology for many years to come! ## About Atlantic.Net Established in 1994, Atlantic.Net is a market-leading hosting provider, with presence at state-of-the-art data centers in New York, London, Toronto, San Francisco, Singapore, Dallas, Ashburn, and Orlando regions. Over the decades, we've steadily built a reputation as an exceptional hosting company known for simplifying complex technologies, providing top-quality services, and demonstrating our trustworthiness to our clients time and time again. ## The Atlantic.Net Difference ### World Class Infrastructure Eight International data centers Fully Audited and Certified Always available support team High availability solutions Fully redundant network ### 32 Years of Excellence! Award-winning service High touch approach Customers in over 100 countries Profitable and stable provider Leading business partner program ### Turn-Key Compliance SOC 2 and SOC 3 certified HITRUST audited HIPAA audited PCI ready GDPR ready --- # How to Install Typo3 CMS on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-typo3-cms-on-arch-linux/ | Published: 2023-03-08 | Updated: 2024-04-19 | Author: Hitesh Jethva Typo3 is a free and open-source content management system written in PHP language. It is a simple, flexible, and professional CMS that offers services and solutions for teams across industries. It is a great alternative to popular CMS platforms like WordPress, Joomla, and Drupal. Additionally, it can be installed on all major operating systems and runs on Apache, Nginx, and IIS web servers. In this post, we will show you how to install Typo3 CMS on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list if you have not done so already. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Apache and PHP Typo3 CMS is written in PHP and runs on a web server, so you will need to install the Apache web server and PHP on your server. First, install the Apache web server package with the following command: ``` pacman -Sy apache ``` After the successful installation, start and enable the Apache service with the following command: ``` systemctl start httpd systemctl enable httpd ``` Next, install PHP and other required extensions using the following command: ``` pacman -Sy php php-gd php-cgi php-intl php-apache unzip ``` Next, edit the PHP configuration file and enable the required extensions: ``` nano /etc/php/php.ini ``` Add / Modify the following lines. ``` extension=pdo_mysql extension=gd extension=json extension=mysqli extension=intl extension=xml extension=bcmath max_execution_time = 300 max_input_vars = 1500 memory_limit = 128M ``` Save and close the file when you are finished. ## Step 3 – Install and Configure MariaDB Database First, install the MariaDB server with the following command: ``` pacman -S libmariadbclient mariadb mariadb-clients ``` Next, initialize the MariaDB database with the following command: ``` mysql_install_db --user=mysql --basedir=/usr --datadir=/var/lib/mysql ``` Next, start and enable the MariaDB service with the following command: ``` systemctl start mysqld systemctl enable mysqld ``` Next, log in to the MariaDB console using the following command: ``` mysql ``` Once you are logged in, create a database and user for Typo3 CMS: ``` CREATE DATABASE typo3; GRANT ALL ON typo3.* TO typo3@localhost IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 4 – Download Typo3 CMS First, download the latest version of Typo3 CMS with the following command. ``` wget --content-disposition https://get.typo3.org/11.5.12 ``` Once the download is completed, extract the downloaded file with the following command. ``` tar -xvzf typo3_src-11.5.12.tar.gz ``` Next, move the extracted directory to the Apache web root: ``` mv typo3_src-11.5.12 /srv/http/typo3 ``` Next, change the ownership of the Typo3 directory to Apache: ``` chown -R http:http /srv/http/typo3/ chmod -R 775 /srv/http/typo3/ ``` ## Step 5 – Create an Apache Virtual Host Configuration File Next, you will need to create an Apache virtual host configuration file to host Typo3 CMS on the internet. ``` nano /etc/httpd/conf/extra/typo3.conf ``` Add the following lines: ``` ServerAdmin admin@example.com DocumentRoot "/srv/http/typo3" ServerName typo3.example.com DirectoryIndex index.php Options FollowSymlinks AllowOverride All Require all granted ErrorLog /var/log/httpd/error.log CustomLog /var/log/httpd/access.log combined ``` Save and close the file when you are finished. Next, edit the Apache main configuration file. ``` nano /etc/httpd/conf/httpd.conf ``` Uncomment the following line: ``` Include conf/extra/httpd-vhosts.conf LoadModule mpm_prefork_module modules/mod_mpm_prefork.so LoadModule rewrite_module modules/mod_rewrite.so ``` Comment on the following line: ``` #LoadModule mpm_event_module modules/mod_mpm_event.so ``` Add the following lines: ``` LoadModule php_module modules/libphp.so AddHandler php-script .php Include conf/extra/php_module.conf Include conf/extra/typo3.conf ``` Save and close the file when you are done. Next, restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 6 – Access Typo3 CMS Now, open your web browser and access the Typo3 CMS using the URL **http://typo3.example.com.** You should see the following screen. ![typo3 welcome page](https://www.atlantic.net/wp-content/uploads/2023/03/p1.png) Next, open your terminal and create an empty file using the following command. ``` touch /srv/http/typo3/FIRST_INSTALL ``` Next, go back to the web browser and **refresh** the page. You should see the following page. ![typo3 prerequisites check](https://www.atlantic.net/wp-content/uploads/2023/03/p2.png) Click on **No problems detected, continue with installation**. You should see the following page. ![typo3 database configuration](https://www.atlantic.net/wp-content/uploads/2023/03/p3.png) Provide your database username and password and click on the **Continue** button. You should see the following page. ![typo3 database selection](https://www.atlantic.net/wp-content/uploads/2023/03/p4.png) Select your database and click on the **Continue** button. You should see the following page. ![typo3 admin configuration](https://www.atlantic.net/wp-content/uploads/2023/03/p5.png) Provide your admin username, password, email, and site name, and click on the **Continue** button. Once the installation has been completed, you should see the following page. ![typo3 installation done](https://www.atlantic.net/wp-content/uploads/2023/03/p6.png) Select **Take me straight to the backend** and click on **Open the TYPO3 Backend**. You should see the Typo3 login page. ![typo3 login page](https://www.atlantic.net/wp-content/uploads/2023/03/p7.png) Provide your admin username and password and click on the **Login** button. You should see the Typo3 dashboard on the following page. ![typo3 dashboard](https://www.atlantic.net/wp-content/uploads/2023/03/p8.png) ## Conclusion Congratulations! You have successfully installed Typo3 CMS with Apache on Arch Linux. You can now build awesome websites using the Typo3 CMS. You can also try Typo3 CMS on one of our [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Atlantic.Net Brochures > URL: https://www.atlantic.net/brochures/ | Updated: 2026-09-16 ## Atlantic.Net Brochures ### [GPU Hosting](https://www.atlantic.net/resources/documents/brochures/pdf/gpu-hosting-by-atlantic-net.pdf) ### [Cloud Platform](https://www.atlantic.net/resources/documents/brochures/pdf/cloud-platform-atlantic-net-brochure.pdf) ### [ACP Cloud Platform](https://www.atlantic.net/resources/documents/brochures/pdf/acp-cloud-platform-atlantic-net-brochure.pdf) ### [ACP HIPAA Compliant](https://www.atlantic.net/resources/documents/brochures/pdf/acp-hipaa-compliant-baseline-atlantic-net-brochure.pdf) ### [HIPAA Cloud Services](https://www.atlantic.net/resources/documents/brochures/pdf/hipaa-cloud-services-atlantic-net-brochure.pdf) ### [PCI Security](https://www.atlantic.net/resources/documents/brochures/pdf/pci-security-atlantic-net-brochure.pdf) ### [PCI Requirements](https://www.atlantic.net/resources/documents/brochures/pdf/pci-hosting-requirements-atlantic-net-brochure.pdf) ### [HIPAA Requirements](https://www.atlantic.net/resources/documents/brochures/pdf/hipaa-compliant-hosting-requirements-checklist-atlantic-net-brochure.pdf) ### [Dedicated Hosts](https://www.atlantic.net/resources/documents/brochures/pdf/dedicated-hosts-atlantic-net-brochure.pdf) ### [Managed Cloud](https://www.atlantic.net/resources/documents/brochures/pdf/managed-cloud-atlantic-net-brochure.pdf) ### [Virtual Private Cloud](https://www.atlantic.net/resources/documents/brochures/pdf/virtual-private-cloud-atlantic-net-brochure.pdf) ### [ACP Cloud Backups](https://www.atlantic.net/resources/documents/brochures/pdf/acp-cloud-backups-atlantic-net-brochure.pdf) ### [Managed Virtualization](https://www.atlantic.net/resources/documents/brochures/pdf/managed-virtualization-hosting-atlantic-net-brochure.pdf) ### [HIPAA Compliant Hosting](https://www.atlantic.net/resources/documents/brochures/pdf/hipaa-complaint-hosting-atlantic-net-brochure.pdf) ### [Veeam Backup Agents](https://www.atlantic.net/resources/documents/brochures/pdf/veeam-backup-agents-atlantic-net-brochure.pdf) ### [Hosting Responsibility Model](https://www.atlantic.net/resources/documents/brochures/pdf/responsibility-model-atlantic-net-brochure.pdf) ### [Network Edge Protection](https://www.atlantic.net/resources/documents/brochures/pdf/network-edge-protection-atlantic-net-brochure.pdf) ### [Encryption](https://www.atlantic.net/resources/documents/brochures/pdf/cloud-encryption-platform-atlantic-net-brochure.pdf) ### [What Encryption Does Atlantic.Net Use](https://www.atlantic.net/resources/documents/brochures/pdf/what-encryption-does-atlantic-net-brochure.pdf) ### [Multi-Factor Authentication](https://www.atlantic.net/resources/documents/brochures/pdf/multi-factor-authentication-service-atlantic-net-brochure.pdf) ### [Firewall Appliance](https://www.atlantic.net/resources/documents/brochures/pdf/firewall-appliance-atlantic-net-brochure.pdf) ### [Managed Firewall](https://www.atlantic.net/resources/documents/brochures/pdf/managed-firewall-atlantic-net-brochure.pdf) ### [Trend Micro Deep Security](https://www.atlantic.net/resources/documents/brochures/pdf/trend-micro-deep-security-atlantic-net-brochure.pdf) ### [Load Balancing](https://www.atlantic.net/resources/documents/brochures/pdf/load-balancing-atlantic-net-brochure.pdf) ### [Performance Matters](https://www.atlantic.net/resources/documents/brochures/pdf/performance-matters-atlantic-net-brochure.pdf) ### [Server Management Services](https://www.atlantic.net/resources/documents/brochures/pdf/server-management-services-atlantic-net-brochure.pdf) ### [Migration Services](https://www.atlantic.net/resources/documents/brochures/pdf/migration-services-atlantic-net-brochure.pdf) ### [ASH-VA Data Center Fact Sheet](https://www.atlantic.net/resources/documents/brochures/pdf/ash-va-data-center-fact-sheet-atlantic-net-brochure.pdf) ### [ORL-FL Data Center Fact Sheet](https://www.atlantic.net/resources/documents/brochures/pdf/orl-fl-data-center-fact-sheet-atlantic-net-brochure.pdf) ### [What Makes Atlantic.Net HIPAA Compliant](https://www.atlantic.net/resources/documents/brochures/pdf/what-makes-atlantic-net-hipaa-compliant-atlantic-net-brochure.pdf) ### [SSL Certificates](https://www.atlantic.net/resources/documents/brochures/pdf/ssl-certificates-atlantic-net.pdf) ### [SSL Certificates Pricing](https://www.atlantic.net/resources/documents/brochures/pdf/ssl-certificates-pricing-atlantic-net.pdf) ### [Reduce Health Tech Hosting Costs](https://www.atlantic.net/resources/documents/brochures/pdf/reduce-health-tech-hosting-costs.pdf) ### [Atlantic.Net vs. The Hyperscale Providers](https://www.atlantic.net/resources/documents/brochures/pdf/atlantic-net-vs-the-hyperscale-providers.pdf) ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # How to Install PrestaShop Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-prestashop-arch-linux/ | Published: 2023-03-09 | Updated: 2023-11-15 | Author: Hitesh Jethva Prestashop is a free and open-source e-commerce platform used to host your own online shop on the web. It uses a web template system that allows you to customize shop themes and add new features through add-on modules. Prestashop provides an addons marketplace where developers can sell themes and modules to merchants. In this post, we will show you how to install Prestashop on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Nginx Web Server First, install the latest version of the Nginx web server on your system with the following command. ``` pacman -S nginx-mainline ``` Next, start the Nginx service and enable it to start at system reboot. ``` systemctl start nginx systemctl enable nginx ``` ## Step 3 – Install and Configure PHP First, install the PHP, PHP-FPM, and other PHP extensions using the following command. ``` pacman -S php php-fpm php-gd unzip ``` Once all the packages are installed, edit the PHP configuration file. ``` nano /etc/php/php.ini ``` Add/modify the following lines: ``` file_uploads = On allow_url_fopen = On memory_limit = 256M upload_max_filesize = 64M date.timezone = Asia/Kolkata extension=pdo_dblib extension=pdo_mysql extension=gd extension=json extension=xml extension=mysqli extension=intl ``` Save and close the file when you are done. Then, start the PHP-FPM service and enable it to start at system reboot. ``` systemctl start php-fpm systemctl enable php-fpm ``` ## Step 4 – Install and Configure MariaDB Database Prestashop uses a MariaDB as a database backend. So you will need to install the MariaDB on your server. You can install it with the following command. ``` pacman -S mariadb ``` After installing the MariaDB server, initialize the MariaDB database with the following command. ``` mysql_install_db --user=mysql --basedir=/usr --datadir=/var/lib/mysql ``` Next, start the MariaDB service and enable it to start at system reboot. ``` systemctl start mysqld systemctl enable mysqld ``` Next, connect to the MariaDB shell with the following command. ``` mysql ``` Once you are connected, create a database and user for Prestashop using the following command. ``` CREATE DATABASE prestashop; GRANT ALL ON prestashop.* TO prestashop@localhost IDENTIFIED BY 'securepassword'; Next, flush the privileges and exit from the MariaDB shell with the following command. ``` ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 5 – Download Typo3 First, go to the Prestashop official download page and download the latest version using the following command. ``` wget https://assets.prestashop3.com/dst/edition/corporate/8.0.1/prestashop_edition_basic_version_8.0.1.zip ``` Once the download is completed, create a directory for Prestashop and extract the downloaded file. ``` mkdir -p /var/www/html/ unzip prestashop_edition_basic_version_8.0.1.zip -d /var/www/html/prestashop ``` Next, change the ownership of the Prestashop directory. ``` chown -R http:http /var/www/html/prestashop/ ``` ## Step 6 – Configure Nginx for Prestashop Next, you will need to create an Nginx virtual host for Prestashop. First, create a directory to store Nginx virtual host. ``` mkdir /etc/nginx/sites-enabled ``` Next, create an Nginx configuration file for Prestashop. ``` nano /etc/nginx/sites-enabled/prestashop.conf ``` Add the following configurations. ``` server { listen 80; root /var/www/html/prestashop; index index.php index.html index.htm; server_name prestashop.example.com; location / { rewrite ^/api/?(.*)$ /webservice/dispatcher.php?url=$1 last; rewrite ^/([0-9])(-[_a-zA-Z0-9-]*)?(-[0-9]+)?/.+\.jpg$ /img/p/$1/$1$2.jpg last; rewrite ^/([0-9])([0-9])(-[_a-zA-Z0-9-]*)?(-[0-9]+)?/.+\.jpg$ /img/p/$1/$2/$1$2$3.jpg last; rewrite ^/([0-9])([0-9])([0-9])(-[_a-zA-Z0-9-]*)?(-[0-9]+)?/.+\.jpg$ /img/p/$1/$2/$3/$1$2$3$4.jpg last; rewrite ^/([0-9])([0-9])([0-9])([0-9])(-[_a-zA-Z0-9-]*)?(-[0-9]+)?/.+\.jpg$ /img/p/$1/$2/$3/$4/$1$2$3$4$5.jpg last; rewrite ^/([0-9])([0-9])([0-9])([0-9])([0-9])(-[_a-zA-Z0-9-]*)?(-[0-9]+)?/.+\.jpg$ /img/p/$1/$2/$3/$4/$5/$1$2$3$4$5$6.jpg last; rewrite ^/([0-9])([0-9])([0-9])([0-9])([0-9])([0-9])(-[_a-zA-Z0-9-]*)?(-[0-9]+)?/.+\.jpg$ /img/p/$1/$2/$3/$4/$5/$6/$1$2$3$4$5$6$7.jpg last; rewrite ^/([0-9])([0-9])([0-9])([0-9])([0-9])([0-9])([0-9])(-[_a-zA-Z0-9-]*)?(-[0-9]+)?/.+\.jpg$ /img/p/$1/$2/$3/$4/$5/$6/$7/$1$2$3$4$5$6$7$8.jpg last; rewrite ^/([0-9])([0-9])([0-9])([0-9])([0-9])([0-9])([0-9])([0-9])(-[_a-zA-Z0-9-]*)?(-[0-9]+)?/.+\.jpg$ /img/p/$1/$2/$3/$4/$5/$6/$7/$8/$1$2$3$4$5$6$7$8$9.jpg last; rewrite ^/c/([0-9]+)(-[_a-zA-Z0-9-]*)(-[0-9]+)?/.+\.jpg$ /img/c/$1$2.jpg last; rewrite ^/c/([a-zA-Z-]+)(-[0-9]+)?/.+\.jpg$ /img/c/$1.jpg last; rewrite ^/([0-9]+)(-[_a-zA-Z0-9-]*)(-[0-9]+)?/.+\.jpg$ /img/c/$1$2.jpg last; try_files $uri $uri/ /index.php?$args; } rewrite ^images_ie/?([^/]+)\.(jpe?g|png|gif)$ js/jquery/plugins/fancybox/images/$1.$2 last; rewrite ^/api/?(.*)$ /webservice/dispatcher.php?url=$1 last; rewrite ^(/install(?:-dev)?/sandbox)/(.*) /$1/test.php last; #Replace 'admin_xxxxx' in this block with the name of your admin directory. location /admin_xxxxx { if (!-e $request_filename) { rewrite ^/.*$ /admin_xxxxx/index.php last; } } location ~ ^/(app|bin|cache|classes|config|controllers|docs|localization|override|src|tests|tools|translations|travis-scripts|vendor|var)/ { deny all; } location ~ \.(yml|log|tpl|twig|sass)$ { deny all; } location ~ \.php$ { fastcgi_pass unix:/var/run/php-fpm/php-fpm.sock; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } } ``` Save the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following lines after http{: ``` server_names_hash_bucket_size 64; include sites-enabled/*; ``` Save the file, then verify the Nginx configuration. ``` nginx -t ``` You will get the following output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 7 – Access Prestashop Web UI Now, open your web browser and access the Prestashop web installation using the URL **http://prestashop.example.com.** You should see the language selection page. ![PrestaShop language selection screen](https://www.atlantic.net/wp-content/uploads/2023/03/p1-1.png) Select your language and click on the **Next** button. You should see the license agreement page. ![Prestashop license agreement](https://www.atlantic.net/wp-content/uploads/2023/03/p2-1.png) Accept the license agreement and click on the **Next** button. You should see the Store information page. ![prestashop information screen 1](https://www.atlantic.net/wp-content/uploads/2023/03/p5-1.png) ![prestashop information screen 2](https://www.atlantic.net/wp-content/uploads/2023/03/p6-1.png) Provide your shop name, county, and account details, and click on the **Next** button. You should see the content of the store page. ![prestashop store information](https://www.atlantic.net/wp-content/uploads/2023/03/p7-1.png) Select your required options and click on the **Next** button. You should see the database configuration page. ![prestashop database configuration](https://www.atlantic.net/wp-content/uploads/2023/03/p8-1.png) Define your database settings and click on the **Test your database connection now**. If everything is fine, you should see the following page. ![prestashop database test](https://www.atlantic.net/wp-content/uploads/2023/03/p9.png) Click on the **Next** button. Once the installation is finished, you should see the following page. ![prestashop installation done](https://www.atlantic.net/wp-content/uploads/2023/03/p10.png) Before login, remove the Prestashop installation directory using the following command. ``` rm -rf /var/www/html/prestashop/install/ ``` Next, click on the **Manage your store** button. You should see the Prestashop login page. ![prestashop login](https://www.atlantic.net/wp-content/uploads/2023/03/p11.png) Provide your email address and password and click on the **LOG IN** button. You should see the Prestashop dashboard on the following page. ![prestashop dashboard](https://www.atlantic.net/wp-content/uploads/2023/03/p12.png) ## Conclusion In this post, you learned how to install Prestashop on Arch Linux with Nginx. You have now enough knowledge to install Prestashop easily on your server and start your own online business. You can try Prestashop on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # What is an Apache Server? > URL: https://www.atlantic.net/vps-hosting/what-is-an-apache-server/ | Updated: 2026-09-16 Apache HTTP Server is a free, open-source web server developed by the Apache Software Foundation. It delivers HTML, CSS, JavaScript, and media to web browsers over HTTP and HTTPS, runs primarily on Linux and other Unix-like systems, and powers a substantial share of the public web. ## What is an Apache Server? An Apache Server is a web server application that delivers content such as HTML pages, multimedia and CSS Style sheets over the internet. Apache is a community-developed web application published by the Apache Software Foundation. It is arguably the most popular web server software available on the World Wide Web and is most commonly found on Unix based operating systems such as Linux, OSX, Solaris and FreeBSD. Apache is open source, and as such, it is developed and maintained by a large group of global volunteers. One of the key reasons Apache is so popular is that the software is free for anyone to download and use. There is no direct support or maintenance provided by the Apache foundation; however, there are vast amounts of documentation and online forums to gain help from the community. Commercial support for Apache is available from [web hosting companies](https://www.atlantic.net/), such as Atlantic.Net. An [Apache Server](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/how-to-configure-apache-create-website-configuration-centos-7/) is implemented by service providers to offer clients web hosting solutions, like Atlantic.Net's [HIPAA compliant website hosting](https://www.atlantic.net/hipaa-compliant-hosting/), and content delivery. ## NCSA HTTPd Web Server The foundations of the Apache web server started in the US at the National Center for Supercomputing Applications (NCSA). A team, including key developer Robert McCool wrote the NCSA HTTPd Web Server. This was one of the earliest client-server web servers available. In the early 1990s, the NCSA HTTPd web server powered an overwhelming majority of the Internet’s websites. Robert McCool left the NSCA in 1994, and soon after, the NCSA ceased development of HTTPd Web Server. In 1995, the Apache Foundation started to take shape, with developers beginning to update and share the HTTPd Web Server source code with the aim to further its development; this eventually culminated in the open source Apache Webserver being released. ## Advantages of Using Apache Apache Web Server is well-optimized and can handle a large amount of traffic and data transfer on minimal hardware requirements. Apache is easily scalable; as a website grows, system administrators can easily increase the number of web servers in their web hosting farm. Above all, Apache is free. This is a huge advantage over web servers in the marketplace which have expensive licensing models, not to mention require more hardware resources. ## How does an Apache Web Server work? Apache is a multitasking program which gathers data from a server to deliver content from the server filesystem to a client request. The client is usually a web browser, and the filesystem is where the website content is stored. The web server can interact with modules, databases and applications to create data and content; this data is then published to the client (usually a desktop web browser). Apache is capable of publishing multiple requests simultaneously to several clients at once. The only limiting factor is the hardware capabilities of the server itself. ## Who uses an Apache Web Server? Apache Web Server is used by approximately 47% of all internet websites, and of the top one million websites, Apache is used on nearly 69% of them. Linux is the most popular operating system to use with Apache. Most [WordPress hosting providers](https://www.atlantic.net/vps-hosting/how-to-install-wordpress-ubuntu-20-04/) offer Apache on Linux hosting hardware, often teamed with management applications such [as cPanel](https://partnernoc.cpanel.net/res/4861/atlanticnet.htm). Some of the world’s biggest companies trust Apache Server, including Apple, Google, PayPal and Adobe. ## References i Www6.uniovi.es. (2018). NCSA httpd Overview. [online] Available at: http://www6.uniovi.es/~antonio/ncsa_httpd/Overview.html [Accessed 10 May 2018]. ii Apache.org. (2018). ASF History Project. [online] Available at: https://www.apache.org/history/ [Accessed 9 May 2018]. iii W3techs.com. (2018). Usage Statistics and Market Share of Apache for Websites, May 2018. [online] Available at: https://w3techs.com/technologies/details/ws-apache/all/all [Accessed 11 May 2018]. iv Calin, B. (2018). Statistics from the top 1,000,000 websites - Acunetix. [online] Acunetix. Available at: https://www.acunetix.com/blog/articles/statistics-from-the-top-1000000-websites/ [Accessed 11 May 2018]. v W3techs.com. (2018). Usage Statistics and Market Share of Apache for Websites, May 2018. [online] Available at: https://w3techs.com/technologies/details/ws-apache/all/all [Accessed 11 May 2018]. ### [Related Guides](https://www.atlantic.net/vps-hosting/what-is-an-iis-server/) - [What Is an IIS Server?](https://www.atlantic.net/vps-hosting/what-is-an-iis-server/) - [What Is Web Server Hosting?](https://www.atlantic.net/dedicated-server-hosting/what-is-web-server-hosting/) - [What Is MySQL?](https://www.atlantic.net/dedicated-server-hosting/what-is-mysql/) - [Atlantic.Net Linux VPS Hosting](https://www.atlantic.net/vps-hosting/linux-vps-hosting/) ## Disclaimer: * This post is for informational purposes only and does not constitute professional, legal, financial, or technical advice. Each situation is unique and may require guidance from a qualified professional. Readers should conduct their own due diligence before making any decisions. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # What Is an IIS Server? (Internet Information Services Server) > URL: https://www.atlantic.net/vps-hosting/what-is-an-iis-server/ | Updated: 2026-09-16 Internet Information Services (IIS) is a web server developed by Microsoft for the Windows Server family. It serves HTTP and HTTPS content over a modular request pipeline, integrates natively with ASP.NET / .NET, and is enabled as an optional server role on most editions of Windows Server. ## What Is an IIS Server? A Microsoft IIS Server is a web application developed by Microsoft for Windows Server operating systems. Its primary function is to deliver website content over the Internet to end-users. IIS is available as an installable server role in most editions of Microsoft Windows Server, allowing users to enable web hosting capabilities easily. ## How Do Web Servers Work? The web server front end facilitates the delivery of website content to end users over the Internet. It handles incoming requests from browsers and responds with the appropriate web pages, images, and all the resources required to display content. ## How Does a Windows Server IIS Handle Web Requests? Internet Information Services (IIS) processes web requests through a modular architecture that efficiently handles incoming HTTP/HTTPS requests from a client. When a user enters a URL and clicks on a link, the web server processes the request. The server then opens a request-processing pipeline consisting of several stages to handle the incoming request. To see this in action, you can open your browser's developer options and refresh this page. You will see the pipeline in action. The pipeline begins with the HTTP.sys request, which is responsible for receiving and processing incoming requests. The request then passes through various modules, including access application development features, centralized SSL certificate support, configuration file, FTP server, and transport layer security. Each module performs specific tasks related to the request. This modular design allows administrators to customize the IIS web server behavior and optimize performance according to the website's requirements. ## How Does an IIS Web Server Work? IIS works as a multi-threaded, event-driven web server. When a request arrives at the IIS server, it is assigned to an application pool that runs in isolation. This process, known as the worker process or w3wp.exe, is responsible for handling the request and generating the response to send back to the client. IIS supports two modes of operation: Classic mode and Integrated mode. In Classic mode, IIS primarily relies on the ISAPI (Internet Server Application Programming Interface) extensions to handle requests. However, the Integrated mode was introduced in IIS server 7.0 and offered better compatibility with ASP.NET applications and other web frameworks. ## How IIS Processes Requests IIS processes incoming requests sequentially through the request-processing pipeline. Each stage in the Internet information services pipeline performs a specific task, such as authenticating the user, handling static or dynamic content, applying security measures, and caching responses. As the request passes through the pipeline, IIS determines which handler should be responsible for processing the request based on the requested file extension or URL. The handler generates the response, and IIS sends it back to the client. ## IIS works with ASP.NET Core IIS integrates with ASP.NET Core, Microsoft's modern and cross-platform framework for building complex web applications. Applications can be hosted on IIS using the ASP.NET Core Module, a native IIS module that forwards requests to the ASP.NET Core runtime. This integration enables developers to utilize IIS's robust features and scalability while building dynamic and powerful browser-based applications using ASP.NET Core. It allows for easy deployment, configuration, and management of applications on Windows servers. ## Versions of IIS Each major version of IIS has shipped alongside a Windows release, adding features and architectural changes over time. As of this writing, IIS 10 is the current major version: Microsoft has not released an "IIS 11"; subsequent Windows Server releases continue to ship IIS 10 with feature and reliability updates. - IIS 1.0 (1995): Initial release, distributed as an add-on for Windows NT 3.51. - IIS 2.0 (1996): Included with Windows NT 4.0 Server. - IIS 3.0 (1996): Included with Windows NT 4.0 Service Pack 3; introduced Active Server Pages (ASP). - IIS 4.0 (1997): Released as part of the Windows NT 4.0 Option Pack. - IIS 5.0 (2000): Included with Windows 2000 Server. - IIS 5.1 (2001): Included with Windows XP Professional (development use). - IIS 6.0 (2003): Included with Windows Server 2003; introduced the worker-process isolation model and the HTTP.sys kernel-mode HTTP listener. - IIS 7.0 (2008): Included with Windows Server 2008 and Windows Vista; introduced the modular architecture and Integrated mode. - IIS 7.5 (2009): Included with Windows Server 2008 R2 and Windows 7. - IIS 8.0 (2012): Included with Windows Server 2012 and Windows 8. - IIS 8.5 (2013): Included with Windows Server 2012 R2 and Windows 8.1. - IIS 10.0 (2016): Initial release with Windows Server 2016 and Windows 10. Subsequent updates ship with Windows Server 2019 (2018), Windows Server 2022 (2021), Windows Server 2025 (2024), and Windows 11. There is no separate "IIS 11": Microsoft has continued to update IIS 10 in place rather than incrementing the major version. Note: Years in parentheses indicate the initial release date of each IIS version. Microsoft publishes Windows Server lifecycle dates separately at the Microsoft Lifecycle site. ## Features of an IIS Server Internet Information Services is a top choice for hosting online applications and IIS websites due to its impressive features. Let's delve deeper into some of the key features that make IIS a preferred web server: ### Native .NET and ASP.NET Support IIS has native support for .NET and ASP.NET frameworks, making it an excellent platform for developers who prefer Microsoft technologies. This seamless integration allows developers to easily leverage these frameworks' full potential to build robust and dynamic cloud applications. ### Integration with Visual Studio One of the significant advantages of IIS is its seamless integration with Microsoft's development environment, Visual Studio. This integration streamlines web application development, offering developers a familiar and efficient development experience. With Visual Studio's tools and features working harmoniously with IIS, developers can debug, test, and deploy their internet applications seamlessly, enhancing productivity and reducing the time to market. ### Application Pool IIS utilizes the concept of application pools, which isolate digital applications from one another within the web server environment. This isolation prevents one application from affecting the performance or stability of others, enhancing security and reliability. Each application pool runs as a separate worker process, ensuring that even if one application encounters issues or crashes, it won't disrupt the functioning of other applications running on the same server. ### Scalability Scalability becomes crucial as IIS websites and applications experience increased traffic. IIS offers an excellent solution for scaling up to meet high demands by supporting the deployment of multiple servers and implementing load balancing. Administrators can distribute the incoming requests across various servers to ensure optimal performance and handle large numbers of concurrent users effectively. ### Security IIS provides a range of robust security features, such as various authentication methods, SSL encryption for secure data transmission, request filtering to prevent malicious requests, and IP restrictions to control access to the client and web server. ### URL Rewrites IIS incorporates URL rewriting capabilities, allowing administrators to manipulate URLs for improved search engine optimization (SEO) or to redirect requests. This powerful feature enables website owners to create user-friendly URLs, enhance SEO rankings, and manage URL structures effectively, ensuring a better user experience and improved visibility on search engines. ### Compression To optimize website performance and reduce bandwidth usage, IIS offers the option to compress web content before transmitting it to clients. The server can efficiently deliver content by compressing data, leading to faster load times and improved user experience, particularly for users with slower internet connections or accessing websites from mobile devices. ### Centralized Management In enterprise environments with multiple websites and web-based applications, centralized management becomes essential. IIS supports centralized management, enabling administrators to efficiently oversee and control multiple instances of IIS across various servers from a single location. ### Dynamic Caching IIS incorporates capabilities to optimize performance and reduce server workload. Frequently accessed content is cached browser side, allowing the server to quickly serve content to subsequent requests without repeatedly processing the same data. Dynamic caching significantly improves user response times, leading to a smoother and more responsive browsing experience. ### Support for PHP and Other Technologies While IIS natively supports .NET and ASP.NET, it is versatile enough to accommodate other technologies, including PHP and various scripting languages. This flexibility allows developers to choose the technology best suited to their project requirements. Whether building online applications using Microsoft's technologies or embracing popular open-source solutions like PHP, IIS provides the necessary infrastructure and compatibility to meet diverse development needs. ## How to Set Up an IIS Server Setting up an Internet Information Services (IIS) web server is crucial for hosting Internet applications effectively. Follow these steps to configure your IIS server for optimal performance: - Install Windows Server: Ensure you have a licensed copy of Microsoft Windows Server, a major operating system, installed on your machine. You can spin one up on the Atlantic.Net Cloud Platform. - Install IIS: To set up IIS, navigate to "Server Manager" and add the "Web Server (IIS)" role to your server. Or Type the following into PowerShell: Install-WindowsFeature Web-Server,Web-Common-Http,Web-Mgmt-Console - Configure IIS: Customize IIS settings based on your web application's requirements. You can set up bindings that determine how IIS responds to requests on your domain or server node. Configure domain accounts for secure access to resources. - Application Pool: One of the essential components of IIS is the Application Pool. Create an application pool for your website, specifying the .NET version and other configurations. This segregation helps in efficiently managing resources and isolating applications for improved security. - Deploy Web Application: Once your IIS server is ready, deploy your web application to the designated website directory. This directory can be set up on your local user folders or a remote server node. - Test the Website: After deploying your web application, it's crucial to thoroughly test the website to ensure it is accessible and functioning as expected. Log requests using IIS to monitor the application's performance and identify potential issues. - Web Applications and Web Developers: IIS supports hosting online platforms developed by web developers using various technologies, including WCF services. Web developers can build and deploy applications efficiently using IIS's open system platforms. - IIS Worker Processes: IIS worker processes, also known as application pools, play a vital role in handling incoming requests. You can configure how many IIS worker processes run to optimize performance, considering hardware or reference memory limitations. Security features like Windows Authentication (Windows Auth) can be enabled to control access to your web programs effectively. - IIS Configuration Files: The IIS configuration files hold essential settings for your web server. These files can be modified to fine-tune various aspects of your IIS setup, including worker processes and other Windows features. ## What Are the Key Advantages of Using IIS? IIS offers several key advantages that make it a popular choice among web developers and businesses: ### Native Windows Integration Being developed by Microsoft, IIS provides seamless integration with Windows Server operating systems. This integration allows for efficient resource utilization and easy management using familiar Windows operating system tools like Server Manager and other web management tools. ### Performance and Scalability IIS is designed to handle high volumes of web traffic and can efficiently manage multiple client requests simultaneously through its multi-threaded architecture and worker processes. This capability makes it suitable for hosting web tools in data centers and serving large user bases. ### Security Features IIS includes robust security features, such as Windows Authentication, to protect browser applications and sensitive data. Administrators can configure security settings and access controls through Windows Active Directory, ensuring a secure environment for web hosting. ### Modular Architecture The modular design of IIS allows administrators to customize the web server behavior by adding or removing modules as needed. This flexibility enables fine-tuning performance and functionality based on specific application requirements. ### Support for Multiple Web Technologies IIS supports various web technologies, including ASP.NET, PHP, and static HTML files. This broad compatibility allows developers to choose the most suitable technology for their internet applications and host them on the same server. ### Application Pool Isolation IIS employs application pools to isolate web-based applications from one another. If one application experiences issues, it does not affect others running on the same server. This isolation improves stability and security across hosted applications. ### Efficient Caching Mechanisms IIS includes built-in caching mechanisms to store frequently accessed content, reducing the response time for subsequent requests and improving overall server performance. ### Web Deploy and Management IIS provides tools like Web Deploy, allowing web developers to publish web applications easily and manage website settings efficiently. ### Support for .NET Framework IIS seamlessly supports .NET Framework applications, widely used for building robust and feature-rich web applications. ### IIS GUI The IIS Management Console offers a user-friendly graphical interface for configuring and managing web servers and websites, making it accessible even to those with limited technical expertise. ## Understanding Ports IIS uses two primary ports to identify specific services and applications. The first port is Port 80, the default port for HTTP traffic. Whenever users access a website without specifying a port in the URL, the Windows IIS server automatically assumes that they are connecting through Port 80. This port facilitates the communication of unencrypted data between the server and the client. The second port is Port 443, designated as the default port for HTTPS traffic. Unlike HTTP, HTTPS ensures a secure and encrypted data transmission between the server and the client, protecting sensitive information from unauthorized access. IIS listens on both Port 80 and Port 443 by default. Still, system administrators possess the flexibility to configure IIS to listen on different ports as required by their specific needs and configurations. This ability to customize port settings allows for greater adaptability and ensures the smooth functioning of web services within the IIS environment. ## Application Pools: What Are They and How Do They Work? Application pools are a fundamental concept in IIS that enables isolation and enhanced performance for web applications. An application pool represents a group of web applications or websites with the same settings and runtime environment. Each application pool operates independently, meaning that if one web application within a pool experiences issues, it does not affect other applications in different pools. ### Understanding Application Pools Application pools are a fundamental concept in IIS that enables isolation and enhanced performance for web applications. An application pool represents a group of web applications or websites with the same settings and runtime environment. Each application pool operates independently, meaning that if one web application within a pool experiences issues, it does not affect other applications in different pools. ### App Pool Users Each application pool runs under a specific user identity known as the app pool user. This user identity determines the permissions and access rights to runtime data that the applications in the collection have on the server. By default, IIS uses the "ApplicationPoolIdentity," which provides a unique identity for each application pool. App pool users can be customized to use different virtual user accounts based on security and access requirements. For example, administrators can configure the app pool to run under a domain user account for applications requiring access to specific network resources. ### Adding an Application Pool Using IIS Manager To add an application pool in IIS: - Open the IIS Manager. - Navigate to the "Application Pools" node. - Right-click and select "Add Application Pool." - Name the new application pool and choose the .NET version and other settings. - Save the configuration. ### App Pool Recycling App pool recycling is where IIS periodically restarts the application pool to ensure optimal performance and memory management. Recycling helps prevent memory leaks and other issues arising from long-running applications. Administrators can set recycling conditions based on the number of requests, specific time intervals, or memory usage thresholds. When these conditions are met, IIS will recycle the app pool, starting fresh worker processes to handle incoming requests. ## IIS vs. Apache IIS and Apache are two of the most widely used web servers. Each of these web servers has its strengths and weaknesses: ### Platform IIS is native to Windows and tightly integrated with Microsoft technologies, making it an excellent choice for organizations using Windows-based infrastructure. On the other hand, Apache is open-source and runs on multiple platforms, including Windows, Linux, and macOS. ### Performance Both servers can deliver excellent performance, but performance comparisons depend on the specific use case and configuration. ### Security IIS and Apache have robust security features. While IIS has improved significantly in safety over the years, Apache's open-source nature has often been praised for its quick response to vulnerabilities and community-driven security audits. ### Ease of Use IIS may have an advantage in ease of use for Windows administrators already familiar with Microsoft products and terminology. Apache might require a steeper learning curve for those less experienced with Linux or open-source software. ### Popularity Apache historically held a larger share of the web server market, especially on Linux servers. However, IIS has gained popularity, particularly in enterprise environments, due to its seamless integration with other Microsoft products. ## Are you ready to take your web hosting to the next level? Look no further than the Atlantic.Net Cloud Platform! Harness the power of cutting-edge technology and enjoy seamless web hosting with our optimized IIS server system. Why choose Atlantic.Net Cloud Platform for your web server needs? Here's why: Hassle-free Setup: Installing IIS on our cloud platform is a breeze. With just a few clicks, you can install IIS and have your web server up and running, making hosting a stress-free experience. We offer the following flavors of Windows Server: - Windows Server 2025 Datacenter (Desktop Experience) - Windows Server 2025 Datacenter - Windows Server 2022 Datacenter (Desktop Experience) - Windows Server 2022 Datacenter - Windows Server 2019 Datacenter (Desktop Experience) - Windows Server 2019 Datacenter - Windows Server 2016 Datacenter (with Containers/Docker) - Windows Server 2016 Datacenter - Windows Server 2012 R2 Datacenter (Desktop Experience) - Windows Server 2012 R2 Datacenter - Windows Server 2008 R2 SP1 Datacenter High-Performance Servers: Experience lightning-fast website loading times with our robust infrastructure. Expert Support: Our team of experts is always here to assist you. We've covered everything, from setting up your domain account to configuring Apache HTTP Server and IIS worker processes. Seamless Integration: Whether coming from an Apache Server background or transitioning from other platforms, our cloud platform supports smooth integration with Apache Software Foundation and other open system platforms. Scalability and Flexibility: Need more resources? No problem! Our cloud platform allows you to scale up as needed. Enhanced Security: Your web server's security is our top priority. Benefit from advanced security features, including virtual users, server node isolation, and user mode, safeguarding your data and applications. Don't miss this opportunity to elevate your web hosting experience. Join Atlantic.Net Cloud Platform today and unleash the true potential of your web server. Experience your web applications' seamless performance, unmatched support, and unparalleled security. Get started now and witness the difference! Sign up today and see why the Atlantic.Net Cloud Platform is perfect for your IIS server hosting needs. Don't wait! Take the leap and experience hosting excellence with Atlantic.Net! ## Related Guides ### [What Is an Apache Server?](https://www.atlantic.net/vps-hosting/what-is-an-apache-server/) ### [What Is Web Server Hosting?](https://www.atlantic.net/dedicated-server-hosting/what-is-web-server-hosting/) ### [Atlantic.Net Windows VPS Hosting](https://www.atlantic.net/vps-hosting/windows-vps-hosting/) ### [What Is MSSQL?](https://www.atlantic.net/dedicated-server-hosting/what-is-mssql/) ## Disclaimer: * This post is for informational purposes only and does not constitute professional, legal, financial, or technical advice. Each situation is unique and may require guidance from a qualified professional. Readers should conduct their own due diligence before making any decisions. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # What is Block Storage? > URL: https://www.atlantic.net/vps-hosting/what-is-block-storage/ | Updated: 2026-09-16 Block storage is a way of storing data as fixed-size, individually addressable blocks on a storage area network (SAN) or cloud storage service. Each block can be presented to a server as a raw volume – typically over Fibre Channel or iSCSI – and treated as if it were a directly attached disk. **On this page** 1. What is Block Storage? 2. How Does Block Storage Work? 3. Use Cases of Block Storage 4. Block Storage in the Cloud 5. Advantages of Block Storage 6. Disadvantages of Block Storage 7. References ## What is Block Storage? There are three common ways to organize and store data on modern enterprise storage devices – File Level, Object Level and Block Level. Block Level Storage refers specifically to saving data in volumes called blocks. Block storage is when a raw volume of data storage is presented to a server, usually from a storage attached network (SAN), and each volume block can function as an individual hard drive or storage repository. Block storage can be presented to any operating system as a mounted drive volume. A storage consultant can allocate almost any size of data volume to a server. The end user will simply see this as a mapped drive or a local hard drive on the server's operating system. The server operating systems can access the storage blocks over high-speed Fiber Channel or iSCSI connectivity options, according to ENTERPRISEstorageFORUM. This is part of an extensive series of guides about cloud storage. ## How Does Block Storage Work? The target server operating system can be either physical or virtual; however, physical servers require additional storage controllers to access the raw SAN block volumes. On a SAN, files are split into evenly sized blocks of data, and the size of each block is determined by the manufacturers hardware capabilities and the storage architect's infrastructure design, according to Data Center Knowledge. Block sizes can vary if flash storage or standard disk storage is used, and choosing the correct block size for the client data is vital to ensure maximum performance. Each data block is then given a location ID by the operating system to keep track of where each block of data is written to on the SAN. In Object and File level storage principles, metadata is used to arrange the data in a specific hierarchical method on disk, and this metadata usually contains information such as name of file, size and where and when it was written to disk. In object data, metadata also includes the object ID. With block storage (sometimes referred to as virtual storage), metadata is not used for tracking the data, and instead the operating system must track the read/write block unique location identifiers. ## Use Cases of Block Storage Typically, block storage is used where high IO throughput and a low latency network-based storage operation is needed. This might be the case with database servers or business critical software application servers that demand fast, reliable performance. Databases such as Oracle or SAP Hana frequently reside on block level storage. Block storage is also natively supported by VMware virtual machines, as this enables service providers to build fast and versatile virtual infrastructure. This versatility enables the creation of custom solutions like HIPAA compliant storage. Block storage can be used in almost any typical datacenter scenario, whether it be a standard file system for a server or a resilient RAID implementation. The user will need to consider the cost of block level implementation and the performance requirements of any given technical solution, weighing the benefits of block level storage. ## Block Storage in the Cloud Block storage is a very popular service offered by managed service providers. It enables users to have on-demand storage allocated to any cloud instance; in many cases this process takes minutes to complete. This data on demand is protected by high availability and data replication technology, and volumes can be amended by an automated service. Data is secure and encrypted at rest, ensuring that it is impossible for other target servers to access your data. In a cloud scenario, block storage can be an affordable option to extend volume capacity as needed. ## Advantages of Block Storage Block storage is a very popular storage method in the modern data center, says CloudAcademy, thanks to many distinct advantages. Those advantages include: ### Performance Block storage is extremely fast storage and is most frequently used by applications requiring rapid input output operations per seconds (IOPS), such as database servers. This low latency, rapid IO data access is one of the key reasons block storage is so popular. ### Reduced filesystem overhead Many applications are block storage aware, such as PHP, Apache, Exchange, SharePoint etc. When the software can write direct to the storage blocks, it removes the additional overhead put on the Operating System filesystem read/write activities. This eliminates IO bottlenecks, as the system does not need to write the data twice. ### Flexibility Data volumes are extremely flexible, volumes can be extended easily with no downtime as your business grows, and new block volumes can be added as needed. ### Agility Another key advantage is that Block Storage can be moved from one server to another server with relative ease. With a simple amendment of the iSCSI target path, the data can be pointed to another server. ### Bootable Operating systems can boot direct from block storage presented via storage area networks. All that is needed is a physical or virtual server with a BIOS capable of SAN boot. ### Permissions Access management and data permissions are easy to manage with block storage and can be controlled directly by the storage or the host operating system. ## Disadvantages of Block Storage Block storage is not always the perfect storage solution, and it's important to consider the few drawbacks of using it. The user must determine if the disadvantages overshadow the advantages of block storage. ### Locked to server The storage block volume is locked to one individual server at a time and cannot be accessed elsewhere in the environment from a different target server. There are some software workarounds to combat this, but this all adds to IO overhead. ### Limited Metadata The limited amount of information stored in block storage metadata is significantly less than in file or object level storage. Some applications which rely on detailed metadata may suffer. ### Cost Cloud block storage can be an affordable option for many; however, for managed service providers, as Storage Attached Networks (SAN) requires a high level of capital expenditure and highly skilled storage subject matter experts to manage the data arrays optimization. ## References i Dufrasne, B. (2014). IBM XIV storage system architecture and implementation. [Poughkeepsie, New York]: IBM Corporation, International Technical Support Organization. Newsletter Subscribe to our newsletter and stay updated. Ready to Deploy? Launch secure, compliant, enterprise-grade infrastructure with confidence. ## See Additional Guides on Key Cloud Storage Topics Together with our content partners, we have authored in-depth guides on several other topics that can also be useful as you explore the world of cloud storage. ### [Kubernetes Storage](https://cloudian.com/guides/kubernetes-storage/kubernetes-storage-101-concepts-and-best-practices/) Authored by Cloudian - [[Guide] Kubernetes Storage 101: Concepts and Best Practices](https://cloudian.com/guides/kubernetes-storage/kubernetes-storage-101-concepts-and-best-practices/) - [[Guide] Kubernetes Security: The Complete Guide](https://cloudian.com/guides/kubernetes-storage/kubernetes-security-the-complete-guide/) - [[Product] Enterprise-Class, S3-Compatible Object Storage Software](https://cloudian.com/) ### [S3 Storage](https://cloudian.com/blog/s3-storage-behind-the-scenes/) Authored by Cloudian - [[Guide] S3 Storage: How It Works, Use Cases and Tutorial?](https://cloudian.com/blog/s3-storage-behind-the-scenes/) - [[Guide] S3 API: Common Actions, Examples, and Quick Tutorial](https://cloudian.com/blog/s3-api-actions-authentication-and-code-examples/) - [[Whitepaper] Object Storage: Customer Insights and Best Practices](https://cloudian.com/blog/analyst-insight-delivering-enterprise-grade-data-storage-solutions/) - [[Product] Enterprise-scale data management for capacity-intensive workflows](https://cloudian.com/products/hyperstore/) ### [File Upload](https://cloudinary.com/blog/automating_file_upload_and_sharing) Authored by Cloudinary - [[Guide] Automating File Upload and Sharing](https://cloudinary.com/blog/automating_file_upload_and_sharing) - [[Guide] AJAX File Upload - Quick Tutorial & Time Saving Tips](https://cloudinary.com/blog/file_upload_with_ajax) - [[Blog] Implement Dynamism in Static Sites With Serverless Functions](https://cloudinary.com/blog/implement_dynamism_in_static_sites_with_serverless_functions) - [[Product] Cloudinary Assets | AI-Powered Digital Asset Management](https://cloudinary.com/products/digital_asset_management) ## Related Guides ### [Read More About Block Storage](https://www.atlantic.net/cloud-platform/block-storage/) - [Pros and Cons of Offsite and Onsite Data Storage](https://www.atlantic.net/hipaa-compliant-hosting/pros-and-cons-of-onsite-and-offsite-data-storage/) - [Atlantic.Net's Block Storage Service](https://www.atlantic.net/cloud-platform/block-storage/) ### [Related Guides](https://www.atlantic.net/dedicated-server-hosting/what-is-a-san/) - [What Is a SAN?](https://www.atlantic.net/dedicated-server-hosting/what-is-a-san/) - [Atlantic.Net Secure Block Storage](https://www.atlantic.net/cloud-platform/block-storage/) - [What Is Server Virtualization?](https://www.atlantic.net/vps-hosting/what-is-server-virtualization/) - [What Is VMware?](https://www.atlantic.net/dedicated-server-hosting/what-is-vmware/) ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # What is Colocation Hosting? > URL: https://www.atlantic.net/orlando-colocation-hosting-data-center/what-is-colocation-hosting/ | Updated: 2026-09-16 Colocation hosting is a service where you place your own server hardware in a third-party data center and rent space, power, cooling, network connectivity, and physical security. You own the equipment; the colocation provider owns the facility and supporting infrastructure. **On this page** 1. What is Colocation Hosting? 2. How Colocation Hosting Works 3. Colocation Hosting for Security 4. Additional Benefits of Colocation Hosting 5. Negatives of Colocation Hosting ## What is Colocation Hosting? Colocation hosting is similar to dedicated hosting, with one notable exception. In dedicated hosting, customers rent servers as well as the infrastructure needed to house and maintain them. In colocation hosting, companies own their own hardware, but are looking to augment its usefulness by renting server space in a data center, which provides benefits like improved Internet bandwidth, server cooling systems and climate control, and reliable power. Colocation hosting can be compared to owning a boat and renting a berth for it at the closest port of call. The boat remains in your possession and you can access it at any time, but you're still enjoying the services of the port – including security for your vessel and the ability to use the facility's equipment to maintain and get the most out of your boat. This is part of an extensive series of guides about hybrid cloud. ## How Colocation Hosting Works In order to establish a colocation hosting arrangement, the customer must have their own physical server – one that they own. The customer isn't renting a server from the hosting provider; rather, they are merely leasing space like they would at a rental storage company. The customer physically transports the server to the colocation hosting provider's place of business, typically a data center. The customer only rents space within the data center or colocation site, but maintains ownership and control of all hardware and software settings for that server. By communicating with the colocation hosting provider's team, the customer can quickly upgrade or downgrade features like bandwidth and rackspace to fit the business needs. ## Colocation Hosting for Security A top reason most companies employ colocation hosting is for the security it provides. While many former colocation users have made the move to cloud technology because of its ease of use, endless resources, and competitive pricing, there are some things cloud cannot do, according to Who's Hosting This; primarily, it's the level of control you have over your server compared to cloud. Many industries, such as health care, have specific rules of compliance that must be met for legal purposes (like HIPAA and HITECH) when it comes to data and its privacy. Many industries' rules state that data was be kept in a secure, on-site location, which colocation can provide because it is stored in the colocation provider's secure data center. Your server is taken to the provider's location and stored there securely while you pick and choose what services you wish to use, according to TechRadar. ## Additional Benefits of Colocation Hosting With colocation hosting, a small-to-midsized company can achieve a reasonable facsimile of enterprise-level hosting capabilities thanks to the shared hosting environment and on-site support. This can allow your company to play on a fairly even field when it comes to technology, even if it is a fraction of the size of the competition. Additional benefits include: ### High bandwidth and low latency Your server is plugged in to the colocation hosting provider's network, giving it access to industrial-strength connection speeds. Additionally, you can contract with third-party providers like Spectrum or CenturyLink for even more connectivity options. ### Unlimited power No hosting situation is 100% free of risk, but you're transferring the safety of your server from your office to a location built to prevent loss of electricity. A colocation hosting facility has access to steady power supplies, battery backups, and generators. ### On-premises monitoring Most data centers will employ security professionals or support technicians who monitor the premises 24 hours a day, 7 days a week, and 365 days a year for unauthorized visitors. They control who has access to the data center. ### Advanced climate control systems Maintaining the perfect temperature and humidity requirements for servers to operate at optimal efficiency can be a tricky balance to achieve. A colocation hosting facility will have tailored climate control systems that allow the data center managers to properly maintain ideal environmental conditions. ### Live monitoring of equipment In a typical office, your first indication that hardware is in need of maintenance, update, or replacement is when something fails, slowing or stopping your employees' production. With colocation hosting, IT professionals are monitoring your equipment constantly to ensure it is performing optimally. ### Better management In your own brick-and-mortar location, your servers might be managed by a contract IT person, a part-time worker, or a full-time employee who wears several different hats. Upgrading or downloading your server's capabilities in this environment involves lots of moving parts. When using a colocation hosting provider, a simple email or phone call will perform the same work, without adding to your budget or reducing employee productivity. ## Negatives of Colocation Hosting Several of the positives of colocation hosting rest in the same space as one of the negatives: If you want to replace your server or make changes to it personally, it requires driving to the colocation facility and having the staff remove it for you. Even done quickly, this is a process that effectively takes your business offline for at least a few minutes. Additionally, many colocation providers have locked in prices on the cost of electricity and bandwidth that you pay for several months of uninterrupted service. Should you choose this course and then prices for either service fall, you'll be stuck paying the locked-in price. Newsletter Subscribe to our newsletter and stay updated. Ready to Deploy? Launch secure, compliant, enterprise-grade infrastructure with confidence. ## See Additional Guides on Key Hybrid Cloud Topics Together with our content partners, we have authored in-depth guides on several other topics that can also be useful as you explore the world of hybrid cloud. ### [Cloud Migration](https://faddom.com/what-is-cloud-migration/) Authored by Faddom - [[Guide] Data Center Migration: Complete Guide 2025](https://faddom.com/what-is-data-center-migration/) - [[Guide] Cloud Migration to AWS: 3 Phases, 7 Rs and 5 Free Tools to Get You Started](https://faddom.com/cloud-migration-to-aws-3-phases-7-rs-and-5-free-tools-to-get-you-started/) - [[Blog] How Secure is the Cloud?](https://www.atlantic.net/hipaa-compliant-hosting/how-secure-is-the-cloud/) - [[Product] Faddom | Instant Application Dependency Mapping Tool](https://faddom.com/) ### [Nutanix](https://faddom.com/nutanix-history-products-and-top-5-alternatives/) Authored by Faddom - [[Guide] Nutanix: History, Products, and Top 5 Alternatives -](https://faddom.com/nutanix-history-products-and-top-5-alternatives/) - [[Guide] Nutanix vs. VMware: 5 Key Differences and How to Choose](https://faddom.com/vmware-vs-nutanix/) - [[Product] Faddom | Instant Application Dependency Mapping Tool](https://faddom.com/) ### [VMware Storage](https://cloudian.com/guides/vmware-storage/vmware-storage/) Authored by Cloudian - [[Guide] VMware Storage: Understand Your Options](https://cloudian.com/guides/vmware-storage/vmware-storage/) - [[Guide] VMware Cloud Services: The Most Popular Services Explained](https://cloudian.com/guides/vmware-storage/vmware-cloud-services/) - [[Announcement] Cloudian Raises $60 Million in Funding to Accelerate Hybrid Cloud Data Management](https://cloudian.com/blog/transforming-enterprise-data-management-hybrid-cloud/) - [[Product] Enterprise-Class, S3-Compatible Object Storage Software](https://cloudian.com/) ### [Read More About Colocation Hosting](https://www.atlantic.net/orlando-colocation-hosting-data-center/) - [How to Choose the Best Colocation Facility](https://www.atlantic.net/orlando-colocation-hosting-data-center/things-to-look-for-when-identifying-the-best-site-for-colocation/) - [Orlando Colocation Hosting](https://www.atlantic.net/orlando-colocation-hosting-data-center/) ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # What is Database Hosting? > URL: https://www.atlantic.net/dedicated-server-hosting/what-is-database-hosting/ | Updated: 2026-09-16 Database hosting is a managed service that runs and maintains a database management system (such as MySQL, Microsoft SQL Server, or a vector database) on infrastructure operated by a hosting provider. The provider handles the server, storage, security hardening, backups, and 24×7 availability so applications can read and write data without you operating the underlying database stack. ## What Is Database Hosting? Database hosting is a service that provides a secure and scalable environment to store, manage, and access your critical business data 24x7x365. Database hosting is essential for almost every modern data-driven application. Deploying a managed database from a specialist hosting provider gives you immediate access to your preferred database platform and a database that is optimized for performance, high availability, and robust security. By opting for database hosting, you free your team to focus on strategic initiatives, confident that your database is managed and protected by a dedicated team of professionals. ## What Is MySQL Database Hosting? MySQL database hosting is a type of database hosting that capitalizes on the power and flexibility of the popular open-source database management system MySQL. It's cost-effective and offers excellent cross-platform compatibility. MySQL is easy to manage, and easy to learn but also robust, fast, and highly secure. MySQL hosting is an ideal choice for businesses seeking a reliable and adaptable solution for their data storage needs. ## What Is Vector Database Hosting? Purpose-built for the complexities of machine learning and AI, vector database hosting is a type of database hosting designed to deliver efficient storage and retrieval of high-dimensional vector data. Managed solutions eliminate the complexities of implementation and maintenance, allowing organizations to unlock the full potential of their AI applications. Data requires a secure environment that supports rapid access whenever necessary; database hosting providers create and maintain such an environment for their clients. The client’s databases can be the sole inhabitants of the server, or they can share the server with applications that rely heavily on data, such as a business website or software solution. They are particularly useful for enterprises that utilize platforms like Enterprise Resource Planning (ERP) and Customer Relation Management (CRM). These types of platforms consume enormous amounts of memory. If they are to function at a speed capable supporting business uses, then a database hosting providers must deliver consistent speed and high availability. ## Requirements for Database Hosting While most hosting companies can run a web server, databases take a special combination of physical components and technical savvy to implement. The database host must configure the hosting environment to make the data quickly accessible, allow room for growth, and make the database secure enough to resist attacks or corruption. According to PC Magazine, [databases subject to certain compliance standards](https://www.pcmag.com/article2/0,2817,2370235,00.asp) (for example, PCI ready standards or [HIPAA compliant database](https://www.atlantic.net/hipaa-compliant-hosting/) standards) require specific RAID (redundant array of independent disk) levels to house data. ## Benefits of using Database Hosting A company can host its own database, but the advantages offered by database hosting companies can simplify matters. ### Availability: Database hosting companies employ either clustered physical servers or a cloud-based environment that duplicates all servers and internal connections for redundancy. This results in zero downtime for your database. ### Security: Hosting companies stake their reputations and future sales on your data’s protection. Database hosting companies use active monitoring of all traffic to your database servers to keep an eye out for all suspicious activity, not just cyber attacks. For example, a higher-than-expected number of users on your server could raise a red flag, and the hosting provider will have in-place protocol developed in conjunction with your organization so that a proper response can be executed. ### Load balancing: When traffic ramps up on your website, load balancers can distribute it so that your infrastructure continues to run optimally. ### Customized solutions: If you’re purchasing hardware to fit your specific needs, the costs can add up quickly, and when your business grows or your needs change, you may find yourself at square one. Thanks to economies of scale, a database hosting company can meet your hardware needs at a fraction of the cost. ## MySQL Database Hosting MySQL is one of the oldest database management systems still in mainstream use. An open-source software created by Oracle, it’s both free to use and free to customize to your own specific needs, since its code is publicly available. MySQL is also popular because it can run on any platform, be it Linux, UNIX, Windows, etc. It has tools for database management, data optimization and data querying. There are paid versions of MySQL available for commercial use as well. While it is a very flexible database, MySQL is not designed to be scalable, which can make it an unworthy choice for companies expecting to grow. ## Microsoft SQL (MSSQL) Database Hosting Similar to MySQL in its database management applications, MSSQL is Microsoft’s contribution to the database management software industry. Because of its affiliation with Microsoft, any company hosting MSSQL databases needs to have the latest version of Internet Information Services (IIS) along with specific Windows server and technical support expertise. When using Microsoft products, all products must be patched and upgraded as soon as new releases become available. ## Conclusion Database hosting can require an enormous amount of memory, processing power and resource dedication. While it is entirely possible for companies to host their own databases, larger hosting companies can mitigate costs by using the economics of scale with physical hardware or cloud resources to offer scalable, affordable solutions to give your databases a platform that keep them safe, secure and instantly available for your needs. ## Disclaimer: * This post is for informational purposes only and does not constitute professional, legal, financial, or technical advice. Each situation is unique and may require guidance from a qualified professional. Readers should conduct their own due diligence before making any decisions. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # What is MSSQL? > URL: https://www.atlantic.net/vps-hosting/what-is-mssql/ | Updated: 2026-09-16 Microsoft SQL Server (MSSQL) is a relational database management system (RDBMS) developed by Microsoft. It uses Transact-SQL (T-SQL) and runs primarily on Windows Server (with cross-platform Linux and container support since SQL Server 2017), offering an integrated stack of database engine, integration, reporting, and analysis services for transactional and analytical workloads. ## What is MSSQL? Microsoft SQL Server (commonly abbreviated MSSQL) is a relational database management system (RDBMS) developed and licensed by Microsoft. It uses Transact-SQL (T-SQL), Microsoft's extended dialect of SQL, as its primary query language. MSSQL runs natively on Windows Server and, since SQL Server 2017, also on Linux and as Docker containers, making it one of the few enterprise RDBMS platforms with first-party cross-platform support. MSSQL is shipped in several editions to fit different workloads and budgets: Express (free, lightweight, with database size limits) for small deployments, Web for hosting providers, Standard for general business workloads, Enterprise for mission-critical high-availability deployments, and Developer (free, full Enterprise feature set, non-production use only). Beyond the database engine itself, the SQL Server suite includes Integration Services (SSIS) for ETL, Reporting Services (SSRS) for enterprise reporting, and Analysis Services (SSAS) for OLAP and data-mining workloads, making it a complete data platform rather than just a database. MSSQL is widely deployed for both transactional (OLTP) and analytical (OLAP) workloads across enterprise environments (financial services, healthcare, retail, ERP, CRM, and line-of-business applications), running on premise, in the cloud, and in hybrid architectures. Atlantic.Net offers [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) and [cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) environments suitable for MSSQL workloads of every size. ## A Brief History of MSSQL SQL syntax and MSSQL are related but distinct. SQL syntax is the language used to query databases, and MSSQL is the Microsoft database product suite which uses SQL syntax. The very first versions of SQL server were developed by Ashton Tate, Sybase and Microsoft between 1988 to 1993 and were built on Unix-based operating systems. As Microsoft started to dominate desktop operating systems in the early 1990’s, focus shifted to develop SQL Server for Windows. In 1993, SQL Server 4.21 was released, and this was the first SQL database platform created for Microsoft Windows to take advantage of the graphical user interface. Up to now, Sybase had licensed their Dbase database technology to Microsoft; this technology was widely used in SQL Server, but the terms of the license did not allow Microsoft to change the source code without explicit consent from Sybase. In 1994, the companies parted ways, and Microsoft shifted development focus to release SQL Server 6.0 (SQL95). They quickly followed in 1996 with SQL Server 6.5, which introduced Internet and Data Warehousing support for the fledgling World Wide Web. In 1998, Microsoft completely rewrote SQL Server 7.0 removing any legacy Sybase functions and adding a vast amount of new features. SQL Server 2000 was released to coincided with Windows Server 2000. This started off the SQL Server suite release cycle familiar today, all subsequent versions of SQL have been upgraded with added features and services and generally coincide with an Operating System release date. ## Why Choose MSSQL MSSQL server is an incredibly popular database solution used today, and one of its strongest advantages is its ease of use. MSSQL comes with many excellent tools which make database development a fast and agile process. SQL Server management studio allows any approved user to manage and maintain the databases, run SQL queries, perform backups and analyze performance charts. MSSQL integrates with Visual Studio to give your DevOps team a powerful, familiar platform to create and manage custom applications which seamlessly integrate with MSSQL Server. ## MSSQL Main Features There are many products which make up the SQL Server database platform, but there are 4 key services built into MSSQL which define it and make it a popular choice as a database management system (DBMS). These options are available to install when deploying the MSSQL instance. The latest releases of MSSQL are not just compatible with Windows; more recently, Microsoft has offered SQL for Linux (Red hat and SUSE), as well as Docker container platforms. ## Database Engine The SQL Database engine is the core of the MSSQL product suite. This was the original product which is used to store, process and secure data. The data is stored in one or many database instances. Some of the key database engine features include storing data in instance tables, and the ability to do XML data import, Blob data management (Binary Large Objects), DB Triggers, transaction logs, data compression, data search and maintenance plans, to name a few. ## Integration Services (SSIS) SSIS is a data movement tool which can import and export data from a database. It is widely used to design ETL processes (Extract, Transform, Load). You can extract data from almost any source (for example, other databases, text files or Excel documents), transform it by merging, filtering, sorting fields or aggregating data, and you can load this data into a destination, often a shared folder or even another database/application. ## Reporting Services (SSRS) SSRS is a comprehensive reporting platform for SQL Server which is used to create and deploy several types of paginated reports. SSRS can report on any data in a database and display it in either simple charts or complex data visualizations. SSRS can report on almost any database source data. Reports can be displayed on the reporting services website or integrated into any application supporting .NET. SSRS statements are commonly used by companies to display KPIs like sales data or number of orders processed per hour and thus are one of the features most highly sought by executive teams. ## Analysis Services (SSAS) SSAS is a multidimensional, online analytical processing (OLAP) and data mining server. SSAS is a separate database which is fed data via SSIS from any other data source to build cubes of relational data in a data warehouse. This is a highly efficient database allowing deep queries to run in near-instant timing across vast amounts of data. An example of a typical SSAS statements would be the analysis of all sales in the EMEA region for a particular month; SSAS will allow you to do this using MDX expressions. ## Summary MSSQL Server is one of the best [database solutions available today](https://www.atlantic.net/hosting-services-provider/) in the SQL marketplace. If you are looking for a secure, easy to manage and high-performance database management system for your [compliant database](https://www.atlantic.net/hipaa-compliant-hosting/), then MSSQL should be a serious option to consider. It enables users to analyze data, forecast sales and even predict customer behaviour using business intelligence analytics. ## References i Microsoft SQL Server - US (English). (2018). SQL Server 2017 on Windows and Linux | Microsoft. [online] Available at: https://www.microsoft.com/en-us/sql-server/sql-server-2017 [Accessed 8 May 2018]. ii Spenik, M; Sledge O (2000). Microsoft SQL Server 2000 DBA survival guide. SAMS. Chapter 2. ISBN 0672324687. iii Harris, Scott; Curtis Preston (2007). Backup & Recovery: Inexpensive Backup Solutions for Open Systems. O'Reilly. p. 562. ISBN 0596102461. iv Docs.microsoft.com. (2018). Install SQL Server Database Engine. [online] Available at: https://docs.microsoft.com/en-us/sql/database-engine/install-windows/install-sql-server-database-engine?view=sql-server-2017 [Accessed 8 May 2018]. v Docs.microsoft.com. (2018). SQL Server Integration Services. [online] Available at: https://docs.microsoft.com/en-gb/sql/integration-services/sql-server-integration-services?view=sql-server-2017 [Accessed 9 May 2018]. vi Docs.microsoft.com. (2018). What is SQL Server Reporting Services (SSRS). [online] Available at: https://docs.microsoft.com/en-gb/sql/reporting-services/create-deploy-and-manage-mobile-and-paginated-reports?view=sql-server-2017 [Accessed 9 May 2018]. vii Whigham, S. (2018). SQL Server 2008/R2 Analysis Services (Training Course) | LearnItFirst. [online] Learnitfirst.com. Available at: http://www.learnitfirst.com/Course165 [Accessed 9 May 2018]. viii Mehta, S. (2018). SQL Server Analysis Services (SSAS) Tutorial. [online] Mssqltips.com. Available at: https://www.mssqltips.com/sqlserver-tutorial/2000/sql-server-analysis-services-ssas-tutorial/ [Accessed 9 May 2018]. ## Disclaimer: * This post is for informational purposes only and does not constitute professional, legal, financial, or technical advice. Each situation is unique and may require guidance from a qualified professional. Readers should conduct their own due diligence before making any decisions. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # What is MySQL? > URL: https://www.atlantic.net/dedicated-server-hosting/what-is-mysql/ | Updated: 2026-09-16 MySQL is an open-source relational database management system (RDBMS) that uses Structured Query Language (SQL). Originally developed by MySQL AB and now stewarded by Oracle, it runs on all major operating systems and is widely used as the backing database for LAMP-stack applications, web hosting, and content-management platforms such as WordPress. ## What is MySQL? MySQL is an open source, relational database management system (RDBMS) based on structured query language (SQL). MySQL is available on all major operating systems, including [Windows](https://www.atlantic.net/dedicated-server-hosting/how-to-install-mysql-windows-server-2012/), [Linux](https://www.atlantic.net/vps-hosting/how-to-install-lamp-arch-linux/) and Solaris. It is free to use for individuals and non-production environments under the GNU General Public License; however, if used commercially, a commercial licence is required. MySQL, like other relational databases, stores data in tables, columns and rows. Each entry is defined by a unique identifier. Its raison d'être has always been the performance and reliability of the database. MySQL was designed and optimized for the web development arena; it is arguably the most common database used in web server deployments. MySQL works very well with Apache and PHP and is often the go to database for [LAMP stack deployments](https://www.atlantic.net/vps-hosting/how-to-install-apache-mysql-php-lamp-stack-ubuntu-16-04/). MySQL powers 9 out of 10 websites on the internet today, and is the database chosen by Facebook, Twitter and Wikipedia. MySQL was created by a Swedish company called MySQL AB in 1995. During its early years, the development focus was speed and productivity, rather than feature sets. New features, however, were subsequently added with every major release, but MySQL AB always concentrated on speed, reliability and above all, offering an easy-to-use database focused on web applications. During the late 1990’s, due to its significant performance advantages, MySQL became the database of choice for many companies. The Database market expanded and grew rapidly since the introduction of MySQL. It played a significant part in the history of the internet, enabling inexperienced users access to a free database, resulting in an explosion of websites for blogs, forums and online articles. MySQL was successful because it is easy to use, simple to install, and uses a query language that is simple to understand. For Example, the SHOW DATABASES command will list the available database in MySQL. It was designed for people who are not experts in Database management, empowering inexperienced users, whilst at the same time offering enough complexity to cater for advanced DBA’s. From 2001 onwards, MySQL AB began to add features that appealed to the enterprise markets, such as BDB and InnoDB support (a storage engine used in eCommerce), sub queries, prepared statements, stored procedure etc. With each revision of MySQL, more enterprise grade features were added. Again, the growth of MySQL allowed users to pick up these feature sets with relative ease. Sun Microsystems purchased MySQL AB in 2008; later, in 2009, Oracle acquired the company after buying Sun Microsystems. Recent versions of MySQL are now very rich in product features whilst still maintaining strong performance ability. With Oracle’s drive to the cloud, they have recently started positioning MySQL as the go-to cloud database platform alongside existing, more traditional Oracle database platforms. ## MySQL Versions Since 2007, MySQL started to introduce differing versions of its core MySQL product. These editions focused around the community and enterprise versions of MySQL. This change in strategy presented users with a choice, as both applications use the same source code, but were offered with differing support levels available to the end user. The community edition is supported by the MySQL open source global community via a documentation hub, online blogs, IRC channels and forums. The enterprise editions are supported by dedicated technical support teams, which offer hotfixes and service pack support, and more recently include enterprise exclusive features such as Enterprise Backup, Enterprise Monitor, Enterprise Security and Enterprise Audit modules. ## MySQL Forks Since the purchase of MySQL by Oracle, many of the original development teams have left and set up what are known as fork development companies. These are essentially open source RDBMS software houses which are creating new RDBMS software using the original GNU source code for MySQL. [Popular examples include MariaDB and Percona.](https://www.atlantic.net/vps-hosting/what-is-mysql-vs-mariadb-vs-percona/) ## MySQL Management Tools There are several tools available to manage and maintain MySQL. In typical Linux installations, DB management is done via the command line using the MySQL client. The MySQL client can be used to create databases, set up permissions and access rights. Additionally, there are several popular GUI tools including SQLyog, phpMyAdmin, MySQL Query Browsers, Navicat, MySQL Administrator and MySQL Workbench. Additionally, there are online database management suites like [Heimdall Data](https://www.heimdalldata.com/). Each tool does similar tasks, including creating new tables, importing/exporting data, managing users and permissions, backups and restores, and creating triggers, views and stored procedures of the data. phpMyAdmin is widely used on Linux, and SQLyog and Workbench are popular on Windows. These tools are very similar in functionality to the Microsoft SQL Server studio. Some of the applications are free, while others offer free trials but require a license for full functionality. All tools are relatively simple to learn at a basic level and can offer enterprise grade features. ## References i Oracle.com. (2018). Top 10 Reasons to Choose MySQL for Web - based Applications A MySQL Strategy Whitepaper. [online] Available at: http://www.oracle.com/us/products/mysql/mysql-wp-top10-webbased-apps-461054.pdf [Accessed 15 May 2018]. ii Top 10 Reasons to Choose MySQL for Web - based Applications A MySQL Strategy Whitepaper. [online] Available at: http://www.oracle.com/us/products/mysql/mysql-wp-top10-webbased-apps-461054.pdf [Accessed 15 May 2018]. iii Cabral, S. and Murphy, K. (2009). MySQL administrator's bible. Indianapolis, Ind.: Wiley Publishing. iv Pachev, A. (2003). MySQL enterprise solutions. Indianapolis, Ind.: Wiley. v Cabral, S. and Murphy, K. (2009). MySQL administrator's bible. Indianapolis, Ind.: Wiley Publishing. vi Slideshare.net. (2018). MySQL Features & Implementation. [online] Available at: https://www.slideshare.net/osscube/mysql-features-implementation [Accessed 14 May 2018]. ## Disclaimer: * This post is for informational purposes only and does not constitute professional, legal, financial, or technical advice. Each situation is unique and may require guidance from a qualified professional. Readers should conduct their own due diligence before making any decisions. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # What is PaaS (Platform as a Service)? > URL: https://www.atlantic.net/dedicated-server-hosting/what-is-paas/ | Updated: 2026-09-16 Platform as a Service (PaaS) is a cloud computing model in which a provider delivers a complete development and runtime platform – operating system, runtimes, middleware, databases, and management tooling – over the internet. Customers deploy and operate their applications on the platform without managing the underlying servers, network, or storage. **On this page** 1. What is PaaS? 2. PaaS vs. Other Cloud Computing Service Models 3. Who Is the Ideal PaaS Customer? 4. What Is Included in PaaS? 5. Why Choose PaaS Over Other Service Models? ## What is PaaS? Platform-as-a-service (PaaS) is a cloud-based computing model that provides clients with a platform that enables them to both develop and run business applications at speeds which usually far exceed those available using on-site solutions. As this platform is delivered via a service provider, clients need not worry about building and maintaining the expensive infrastructure that would normally be required for the development and running of such software. PaaS is usually provided on a subscription basis, which ensures that the costs of the service are pre-determined and easily manageable. ## PaaS vs. Other Cloud Computing Service Models PaaS is one of three main cloud computing service models, alongside [IaaS (Infrastructure-as-a-service)](https://www.atlantic.net/dedicated-server-hosting/what-is-iaas/) and [SaaS (Software-as-a-service)](https://www.atlantic.net/vps-hosting/what-is-saas-hosting/). These models provide a scaled level of service, starting with IaaS which provides the user with access to cloud-based infrastructure, such as compute, storage and networking. PaaS goes a step further, and in addition to infrastructure access, clients are provided with a platform including the necessary tools to develop, test and manage their own applications. The highest level of service then being SaaS, which provides clients with subscription based, ready-to-use applications that are hosted centrally. ## Who Is the Ideal PaaS Customer? PaaS is usually focused towards web developers and software engineers who do not want to have the extra workload of managing and maintaining the associated infrastructure required to run PaaS services. PaaS can be provided via public, private or hybrid [cloud hosting](https://www.atlantic.net/cloud-platform/) solutions and are designed to support the complete application lifecycle of building, testing, deploying, managing and updating, according to [Microsoft.](https://azure.microsoft.com/en-gb/overview/what-is-paas/) ## What Is Included in PaaS? [Managed Service Providers (MSPs)](https://www.atlantic.net/managed-services/server-management/) typically provide the host operating system for server-side scripting, the host application (often a programming language), and, frequently, a database (MySQL, Postgres SQL, etc). They will also host the server software, including automatic upgrades and patching, technical support, the backend storage platform, hosted network access, and often specific tools to aid in the design and development of applications. Programming languages such as Go, Node.js, Java, PHP, Python, and Ruby are frequently bundled with PaaS services. You will essentially be given access to server with one or more of these languages installed and configured automatically, and all other platform services, such as software configuration files, will automatically be configured for you by the provider. Access will be via a web browser, SSH or thin client. This allows the user to focus on the code and software to run on the platform service. As cloud services have matured, the content available on a PaaS has changed and evolved. More features are being added, and the landscape of PaaS is changing rapidly. Due to these changes, the service model division lines between IaaS, PaaS, and SaaS are shifting and often overlapping. Cloud storage platforms, payment gateways, and automated WordPress deployments are examples of how the classification of PaaS has changed in recent years. Implementing code in Docker containers is another popular recent addition to PaaS service providers portfolio. ## Why Choose PaaS Over Other Service Models? Currently, the most popular choice of cloud-based computing service is SaaS. This is because this delivery system offers ease of use as well as savings on time and cost, with a reduced need for maintaining on-site infrastructure. Whilst PaaS is currently the least popular model of cloud-based service, [it is growing in popularity more rapidly](https://www.forbes.com/sites/louiscolumbus/2017/04/29/roundup-of-cloud-computing-forecasts-2017/#4a48f38331e8) than either IaaS or SaaS. Organizations who opt to use PaaS for their business needs can expect to benefit from its many advantages. The major appeal of PaaS over SaaS is the freedom clients must develop their own software for use on the platform. Clients also have full control over which users can access this software and the overall maintenance of the software. The service provider will generally manage all other aspects of the infrastructure, ensuring that while clients have the freedom for application development, they also have the required support in place. As applications developed using PaaS are often accessed via the Internet, this means that they can be accessible to colleagues scattered across different geographical locations. As use of PaaS increases, organizations are finding that they must choose the right PaaS cloud service provider for their project. Consuming PaaS services can lead to vendor lock-in, meaning that your code has been designed to run on a particular service provider’s infrastructure, so you want to make sure the MSP is still at the forefront of Cloud PaaS services now and in the future. Performance also must be a serious consideration; often the larger PaaS service providers leverage shared compute, which can mean performance IO decreases for the user. While this may not be widespread, it is always imperative to think of the future of your code when opting for a PaaS cloud provider to ensure your code will run quickly and efficiently. Newsletter Subscribe to our newsletter and stay updated. Ready to Deploy? Launch secure, compliant, enterprise-grade infrastructure with confidence. ## Disclaimer: * This post is for informational purposes only and does not constitute professional, legal, financial, or technical advice. Each situation is unique and may require guidance from a qualified professional. Readers should conduct their own due diligence before making any decisions. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # What is SaaS (Software as a Service Hosting)? > URL: https://www.atlantic.net/vps-hosting/what-is-saas-hosting/ | Updated: 2026-09-16 Software as a Service (SaaS) is a cloud computing model in which a provider hosts a complete application and delivers it to customers over the internet on a subscription basis. The customer accesses the software through a web browser or API without installing or operating the underlying servers, runtime, or storage. **On this page** 1. What is SaaS Hosting? 2. SaaS Hosting 101 3. Five features every company should expect from its SaaS Host Environment 4. Advantages of IaaS 5. What is SaaS (Software as a Service)? 6. SaaS versus Traditional Software 7. What is SaaS (Software as a Service)? 8. SaaS Concerns 9. SaaS Dedicated Hosting 10. Conclusion ## What is SaaS Hosting? If your company develops software, software as a service (SaaS) hosting could open a new realm of business opportunities. SaaS is a software delivery model wherein the software is delivered to the user online in a subscription-based or pay-as-you-go model, allowing for continual updates, the ability to access the software nearly anywhere, and the option for the customer to stop or start using the software service at will. SaaS Hosting is a type of web hosting service wherein your software application and files are stored on a hosting provider's servers, allowing your customers to access your software solution or application through the Internet. ## SaaS Hosting 101 In SaaS hosting, your company's software/app resides on dedicated or virtual servers that run the app. Customers access the software interface through the Internet - via either a local client specifically built for the software or through a browser. They never actually have a copy of the software on their own workstation or other Internet-capable device. With SaaS hosting, the software is maintained and updated at the server level, generally avoiding the need for the end user to update or patch the software. SaaS hosting is also a smart investment for actual software developers. With third-party hosting, the software developers don't have to manage the infrastructure requirements of hosting the software in-house. Moreover, when the software needs to be upgraded, it can be done in seconds in the cloud environment, rather than asking the end user to download the latest version (or a patch if a physical copy of the software was purchased). While SaaS can in theory be supported with any type of hosting environment, typically they feature the following: - Cloud environments: These solutions are both virtualized and scalable, meaning they can grow at the same rate your company grows. They are used for hosting the application, its data and its storage. - Content delivery network (CDN): A CDN is a network of distributed servers that send Web pages and other content such as videos to end-users around the world. - Security: The more widespread your SaaS is and the more popular it gets, the more unwanted attention it is likely to receive. A good SaaS hosting environment will have dedicated protection against distributed denial of service (DDoS) attacks and other known forms of trying to disrupt or disable your service. ## Five features every company should expect from its SaaS Host Environment Research by SkyHigh Networks shows that SaaS is the fastest-growing use for cloud technology. This year, nearly one-third of all applications in the worldwide enterprise market will be based in SaaS, and SaaS revenue will increase to $50.8 billion from $22.6 billion in 2013, a surge of 125%. From these figures, we can take away that SaaS hosting is an enormously competitive market where the largest software developers have the advantage of being pursued by hosting companies. When comparing companies to hire as your SaaS hosting solution, here are five essential features you should look for. ### Availability: The most singular essential characteristic of SaaS hosting is availability, according to a LinkedIn study. Your end-users will want the right to log in and use your application no matter where they are or what time it is. If demand is widespread, your app will be used all over the world, which means use and collaboration across a dozen time zones. This means your SaaS hosting solution must be able to ensure uptime and reliability 100% of the time. ### Ease of Use: The moment a user starts to struggle with your SaaS is the moment they move on to one of your competitors, never to return. The challenge then becomes making your app easy to use, but doing so in a way that doesn't risk exposing your customers' business data. Security is the key; the more robust the cybersecurity of the hosting company, the more faith end-users and enterprises will have in your product, according to a report by Blissfully. ### Room for Documentation and User Support: Just because your app seems intuitive to you or your developers doesn't mean it will be that way for a first-time user. Hosting your app is great, but you should consider that your hosting environment may need to support things like 24/7 customer support, a video or interactive tutorial for new users, a feedback system to report bugs, or a documentation guide that goes over the app from wire to wire. ### Tools for Analytics: Your SaaS hosting provider should be able to assist with gathering metrics to support analysis of access, behavior and usage within the hosting environment. All of these metrics will help you improve your business. Standard metrics include how many people are using the app, where they are signing in from and what time of day (or night) they are online, how long they spend online, and what purposes they are using the SaaS for. ### Single Sign-On: To help sell your SaaS to bigger clients like SMBs and full-scale enterprises, you should make accessing your product as convenient as possible. Having single sign-on in the provider environment streamlines your customers' ability to get on and off your service quickly. It also cuts down on the number of passwords each employee has to remember, which will improve perception of your software. ## Advantages of IaaS While many larger companies prefer the security of housing all of their infrastructure components in a private server farm, the benefits of IaaS are difficult to look past. Here are a few ways that IaaS deployment has far outstripped its physical component first cousin. ### Cost savings: Migration to IaaS can often mean substantial cost savings. It's not just the price of maintaining and running server infrastructure, but the reduction of downtime that often results from moving to IaaS, along with a drop in the cost of replacing old equipment or savings from eliminating internal IT services from a business. ### Scalability: Nearly every business works towards exponential growth in demand for their product or service. But when that moment comes, many are caught flat-footed because they don't have the processing power or budget to scale their business up to match demand. A similar situation can occur when business is doing a special promotion or sale. Employing IaaS allows a business to add just as much infrastructure as is necessary to keep up with demand without having to invest in new local hardware. ### Backup and Disaster Recovery: Whether a website crashes due to high demand or a hurricane knocks out electrical services for days, IaaS gives businesses the ability to overcome a worst-case scenario. With a company's data, processes and disaster recovery protocol stored safely in the cloud, returning to normal operations can be a much simpler proposition. ### Incorporating SaaS and PaaS: When a company thoroughly incorporates IaaS into its internal processes, its management typically becomes aware of the convenience and cost-saving ability of other 'as a service' offerings. SaaS (software as a service) is the great equalizer of small companies that no longer have to buy another copy of the same software every time a new employee comes aboard. Both IaaS and SaaS are good opening steps to moving an organization's whole operation online with PaaS (platform as a service). With PaaS, Employees can login from anywhere in the world and use the exact same system that office workers are seeing. That sort of collaborative power increases efficiency and can mean long-term improvements in profitability. ## What is SaaS (Software as a Service)? Software as a Service is based entirely on the Internet, and it is an approach to software distribution by which software providers host a combination of servers, databases, and code to create applications that can be accessed by users from connected devices. Software as a Service (SaaS) brings the power of a firm's workflow to any user anywhere in the world at anytime. SaaS replaces the traditional notion of buying physical copies of software and installing them on local hardware located inside a brick-and-mortar office. Using SaaS also shifts the burden of responsibility for licensing, support and installation to the cloud provider. Some of the most popular applications available, particularly those used for marketing, networking, customer service and collaboration, are actually SaaS, including: - Google Apps - Microsoft 365 - Salesforce - Citrix GoToMeeting - Cisco WebEx - Slack - Dropbox ## SaaS versus Traditional Software There are two key distinctions between SaaS and traditional software. In traditional software, users purchase the software up front and install it on their own computers. With SaaS, users subscribe to the software without paying any money up front. The provider charges a monthly subscription rate, and the user can cancel their subscription when they stop needing it. Traditional software is licensed individually and usually limited to a single device, and when updates come out, they must be downloaded or purchased and installed. In the SaaS model, bulk licensing is easier, applications can be used across multiple devices with a single login, the application can be updated online instantaneously, and the cost of onboarding additional users is small, since all files are contained within the cloud provider's environment. ## What is SaaS (Software as a Service)? While cost is a central reason for using SaaS in your business environment, there are plenty of other advantages to moving your software to a cloud provider. They include: Scalability: When your developers need to expand your business to meet a growth in demand, you don't want to be caught flat-footed or unable to rise to the occasion. Your SaaS provider can provide more space, more power, and more instances of any particular app with the click of a button. If the increased demand is due to a special event or a busy time of year, your provider can also scale your SaaS back down to normal constraints after the event has ended. Availability: If you're in your office, you're doing work using SaaS. If you're taking a personal day, you're on your laptop using SaaS. If you have a business trip, you're on the airplane using SaaS. No matter where you are or what device you're using, you can be in the same workspace all the time. SaaS provides flexibility and business efficiency and ensures your employees are never out of the loop. No Hardware Costs for Cloud-Based SaaS: All of the processing power for SaaS is available from the cloud provider. This means there is also no extra cost for using extra processing power at your office, which can reduce the bottom line and make your work environment greener. SaaS is a good starter project for IaaS and PaaS. SaaS is the most basic of the three layered models that are at the heart of the cloud provider model for organizations. The other two layers are Infrastructure as a Service (IaaS) and Platform as a Service (PaaS). While SaaS can be as small as one app, IaaS and PaaS represent seismic shifts in the way your firm does business. IaaS includes services and processes such as website hosting, big data analysis, backup, disaster recovery, provision of room for testing by developers and more. PaaS means hosting your entire platform online, allowing complete platform access with a single login. ## SaaS Concerns When firms do vital work in online environment, particularly a new one, the untested solution can give management cause for concern. A few of those commonly-heard questions (with answers) are listed below. Data: We've all seen the news where giant corporations see their data hacked out of cloud data centers or through third-party apps and sold to the highest bidder or released to the general public. SaaS vendors are generally able to provide more specific security measures for their customers because they have expectations of what sort of data is passing in and out of the SaaS environment and know how to lock down suspicious items. Another pervasive fear is that the SaaS provider will end up 'owning' any uploaded data. This is something for each firm to hammer out when agreeing to a service level agreement (SLA) with the SaaS vendor. Putting the definition of data ownership on paper will take away any worries. Vendor Reliability: Firms go out of business every day. What happens when your SaaS provider breathes its last? Most SaaS companies will pay in advance to keep their data centers active in such an event, which will allow customers to export data, something that is nearly always written into SLAs, and migrate that data to a new vendor. ## SaaS Dedicated Hosting If your SaaS applications require a dedicated hosting solution, Atlantic.Net has what you need. We offer flexible options for setting up dedicated SaaS hosting environments that are customized to provide optimal service for your software. Your success matters to us. That's why we take the time to work with you to identify your specific dedicated hosting requirements. Then we develop a personalized hosting plan designed to meet those requirements within your budget. Whether that means hosting on our servers, colocating your servers in one of our datacenters, or using a combination of dedicated and cloud servers, we find the best arrangement to provide the service and confidence you need for your SaaS applications. ## Conclusion Statistics show that by 2020, packaged software will fall to just 10% of sales for new enterprises. As of 2017, 56% of companies were already using at least one provider of SaaS. With unlimited usage options and space to grow, SaaS is an integral part of the current and future business model. Newsletter Subscribe to our newsletter and stay updated. Ready to Deploy? Launch secure, compliant, enterprise-grade infrastructure with confidence. ## Ready to Get Started with SaaS Hosting? Atlantic.Net offers affordable SaaS Hosting solutions built on highly available infrastructure with top-tier technical support. Find out how to take advantage of our Dedicated Server Hosting Plans. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # What is Server Virtualization? > URL: https://www.atlantic.net/vps-hosting/what-is-server-virtualization/ | Updated: 2026-09-16 Server virtualization is the practice of using a software layer called a hypervisor to partition a single physical server into multiple isolated virtual machines, each running its own operating system and applications. It is the foundation of modern cloud computing, VPS hosting, and consolidated data center deployments. ## What is server virtualization? Server Virtualization is a technology which enables the creation of a virtual instance of any operating system on a virtual platform. Before server virtualization became mainstream, each individual operating system required a physical platform, typically a dedicated server with CPU, Disk, Memory and other associated hardware to host the operating system. On a physical server, an operating system has access to all available computing resources of the host hardware. As servers have become more powerful, this approach has proven very wasteful on hardware resource availability. In typical server virtualization, many virtual machines are associated to a physical server, a hypervisor is used to share the host hardware with each individual virtual machine. Server virtualization allows resources to be shared with many other virtual machines, enabling organizations to greatly reduce their datacenter hardware footprint and the associated costs of running vast amounts of physical hardware. ## A Brief History of Server Virtualization While server virtualization has recently exploded in popularity, the technology of virtualization has been in development for well over 50 years. During the 1960s, IBM pioneered the first virtualization of system memory; this was the precursor to virtual hardware. In the 1970s, IBM virtualized a proprietary operating system for the first time called VM/370. This OS-Level virtualization had little use outside of mainframe computing, but it eventually evolved into a product which became z/VM, the first commercially marketed virtual platform for servers. Today, server virtualization dominates the IT industry, with many companies moving towards fully virtualized cloud-managed IT ecosystems. The popularity of virtualization increased greatly in the late 1990s, with VMware’s release of VMware workstation. This product enabled the virtualization of any x86/x64 architecture and brought virtualization mainstream. It was now possible to run Linux, Windows and MacOS on the same host hardware. This ground-breaking technology has played a key role in shaping IT infrastructure services for the last 20 years. How does server virtualization work? In all fully virtualized server platforms there must be a host or vendor hardware available. This hardware, usually a server, requires virtualization software called a hypervisor. The hypervisor presents generic virtualized hardware to every operating system that is installed onto the hypervisor. This generic hardware includes all components required by the operating systems to start, components such as hard disks, SCSI drivers, network drivers, CPU and memory allocations. The virtual machine can only interact with the generic hardware and is independent from any other VM; the hypervisor manages the host resources and allocates to each VM. The administrator can then set the hypervisor to allocate different resources to each virtual machine depending on its requirements. Today, virtualization technology can deploy almost any operating system; Linux, Windows, Aix are widely virtualized. More recently, hardware manufacturers have started offering virtual appliances of their hardware devices. A good example of this is Network Load Balancers, which typically would have been a physical device in a rack, but today, they are often virtualized. Host hardware has become so powerful that offering a virtualized dedicated appliance is more commonplace. ### Types of Hypervisor The Hypervisor is the key software required to enable server virtualization. There are 2 types of hypervisor available. The Type 1 hypervisor, which is often called a “bare-metal”, is a hypervisor which is installed directly on top of the host hardware. A type 1 hypervisor directly manages all the server hardware resources installed inside the bare-metal tin. Each hardware resource is then allocated to the virtual machines via the Hypervisor Operating System. A typical Type 1 example is VMware vSphere ESXi. The Type 2 Hypervisor runs directly on top of a conventional operating system as a process or application. This kind of hypervisor virtualizes the hardware resources of the conventional operating system. While Type 2 hypervisor have some architecture limitations, they are still very popular in non-production environments. A typical example of a Type 2 hypervisor is VMware Workstation or Virtual Box. ### Server virtualization hypervisors There are many types of hypervisor available today. The most popular is the vSphere ESXi hypervisor from VMware. VMware has dominated virtualization, and as a result, this hypervisor is used extensively throughout the world’s datacenters. Microsoft introduced its hypervisor called Hyper-V in 2008. Microsoft bundles Hyper-V with all Microsoft server operating systems and has recently started bundling it with Windows 10 Professional. The hypervisor with the leading market share in the open source community is called Xen. Xen was created by Cambridge university in the late 1990s and is a key player today. In 2006, Xen it was selected by Amazon as the virtual platform for its cloud-based Amazon Web Services (EC2). Amazon dominates the cloud ecosystem, and this has lead other companies to use Xen as a commercial product; Rackspace uses Xen, as well as Citrix, who markets it as Citrix XenServer. ### Hardware manufacturers and server virtualization Server Virtualization is not just used by software manufacturers. IBM, who manufacture most of their server hardware as well, also play a significant role in server virtualization. IBM platforms System P, System I and System Z use a para-virtual hypervisor. Essentially, all the guest virtual machines are aware of each other and their resource requirements via the host. The host hardware resources are sliced up and allocated to the Virtual Machine (or Logical Partition). IBM Z/VM founded this para-virtualized technique, and nearly all IBM mainframe solutions use this method of virtualization. For Example, IBM System P uses a pooled virtualized hardware layer that is managed by a HMC to distribute resources to logical partitions. Each partition is aware of the other partitions’ requirements, and resources are shared to ensure each server has at least the minimum hardware that it has been defined. ### Benefits of server virtualization Arguably the key benefits of virtualization to an organization are its flexibility and cost savings potential. Server Virtualization is much more efficient on host hardware than individual physical servers. As a result, companies need to procure significantly less hardware for new infrastructure, and older, less economical hardware can be migrated to new efficient hardware. This all benefits the environment, as datacenters will require less power and cooling. The consolidation of hardware also reduces the datacenter footprint; this will reduce the costs associated with managed service providers. Functionality is also a key benefit of virtualization. Key functions such as the ability to roll back changes made to systems using a snapshot eliminated the previous requirement to rebuild a server from scratch. Other key server management features, such as vMotion, Cloning, Fault tolerance, DRS and High Availability changed how server administrators could increase uptime of infrastructure and offer better service level agreements to customers. New virtual machines can be deployed near-instantly using templates, and more recently it has become possible to build an entire new virtual infrastructure from scripts, again improving server provisioning drastically. Tools such as Terraform can be used to build the infrastructure, and other configuration toolsets such as Ansible can be used to configure the newly deployed infrastructure exactly and uniformly to your requirements. Disaster recovery (DR) has benefitted greatly from server virtualization as well. No longer do you need to restore from tape to reprovisioned hardware; instead the entire virtual infrastructure can be replicated between sites, and using tools such as VMware Site Recovery Manager, the DR process can be automated. Products such as CloudEndure can replicate servers direct to the cloud and replicate entire infrastructure in a staging area, which can be activated when a DR scenario is invoked. ## Disclaimer: * This post is for informational purposes only and does not constitute professional, legal, financial, or technical advice. Each situation is unique and may require guidance from a qualified professional. Readers should conduct their own due diligence before making any decisions. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # What is VMware? > URL: https://www.atlantic.net/dedicated-server-hosting/what-is-vmware/ | Updated: 2026-09-16 VMware is a virtualization and cloud-computing software vendor whose products (including the ESXi hypervisor, vSphere management suite, vSAN software-defined storage, and the broader VMware Cloud portfolio) let organizations run multiple virtual machines and full software-defined data centers on shared physical hardware. ## What is VMware? VMware is a software company that specializes in virtualization and cloud computing. It provides an alternative to dedicated hosts. In 2024, VMware was acquired by Broadcom, raising questions about the future of its products and uncertainty about future licensing costs. This has led many organizations to consider alternatives such as Nutanix. VMware's solution categories include: - Virtualization: Creates a software layer that allows a computer's hardware to be divided into multiple virtual machines (VMs). Each VM can run its own operating system and act like a separate computer. - Networking: Simplifies application delivery and automates operations with network virtualization and load balancing. - Cloud infrastructure: Deploys private cloud infrastructure solutions. - Software-defined data center (SDDC): Virtualizes almost every computing function into a software-defined data center. - Storage software: Allows IT departments to place application workloads on the most cost-effective compute resource. VMware's main products include: - VMware vSphere - VMware ESXi - VMware vCloud - VMware Hyper Converged Infrastructure (HCI) - VMware Horizon - VMware Fusion - VMware Workstation - VMware Player - VMware ThinApp - VMware Cloud Management Services VMware has a large and loyal user base, but also has its critics. Some say that VMware has a very deep product lineup, and its software is mature and battle-tested. Others say that VMware is complex, has fewer compatibility options and costly licensing fees. ## VMware vSphere Arguably the best-known product by VMware is vSphere. vSphere includes many products, most notably the ESXi hypervisor and the vCenter suite of applications. To use many of the licensed enterprise-class features of vSphere, such as cloning servers, vMotion, high availability and DRS, this requires a vCenter server. The vCenter Server (VC) is a licensed product that allows you to configure, deploy, and manage the entire virtual machine lifecycle from a centralized location. It is used to manage multiple ESXi hosts. itself is a virtual machine, deployed during the installation of vSphere. It is available as an appliance (vCSA) or as an installer for a Windows Server instance. Each virtual environment requires at least 1 vCenter server. Once installed, vCenter can be accessed via a web GUI and can manage the entire connected virtualized estate. It is used to simplify management of VMs, complete daily admin tasks, and complete virtualized infrastructure management. vCenter provides access to all the connected clusters, hosts, networking, and storage from one easy-to-manage web interface. For a developer, VMware PowerCLI can be used to automate management of vSphere. ### VMware ESXi ESXi is an operating system installed on a compatible enterprise-class server. ESXi is powered by the VMKernel, which manages the virtual machines allowing them to be created and interacted with. The VMKernel directly manages the host I/O between allocated resources and the virtual machines. Users can connect directly to an ESXi host IP using the vSphere Web Client and start deploying virtual infrastructure. Managing a single host is acceptable in a lab environment; however, in an enterprise environment, multiple hosts are used with numerous storage and networking components. ### VMware vCloud The VMware vCloud suite is a software-defined datacenter solution based on a vSphere private cloud implementation. It has evolved from vSphere due to the changing demands of Cloud / IT managed service providers. It offers a full cloud solution with datacenter virtualization, automated operations (VMware Aria), high availability, resilient infrastructure, and, more recently, infrastructure delivery automation (vSAN / NSX). VMware vCloud includes several key features. It uses vSphere for computing and VMware Aria Automation for a policy-defined compute automation, for example, creating a policy-driven automated host deployment. vRealize Operations manager is also included; this is a capacity management suite and licensing manager used to monitor the entire virtual infrastructure and predict future capacity requirements. A typical vCloud Cloud Management setup consists of at least 2 sites. Each site is connected by a dark fiber, and each has multiple hosts and replicated storage. vCloud includes the VMware vCenter Site Recovery Manager (SRM), a high availability disaster recovery solution which replicates data between sites. In the event of a disaster, SRM will use predefined policies to failover servers and services from Site A to Site B. It is an automated process and enables managed service providers to offer 99.99% (always online) uptime capability. ## VMware Hyper Converged Infrastructure (HCI) A more recent trend of VMware has been to virtualize more hardware-based datacenter features into its products. Since the release of vSphere 5.0 in 2014, VMware has offered 2 products aimed at virtualizing the storage and network fabrics of a datacenter. Traditionally, datacenters would consist of several ESXi hosts, various storage devices (SAN) and associated SAN Switches, as well as the network infrastructure layer. VMware vSAN and VMware NSX provide a storage virtualization layer and a network virtualization layer in what VMware calls a hyper-converged infrastructure. vSAN is a software-defined enterprise-class storage solution. vSAN can use any typical server storage as part of a larger virtual storage device. vSAN then applies deduplication and compression to the data to minimize the VM footprint, which in turn can provide better performance than traditional storage infrastructure can. There is no need for a dedicated storage SME, as all policy creation and storage management is done in vCenter. vSAN can be scaled up simply by adding more storage to the provisioned vSAN Hosts. VMware has also recently introduced NSX, which provides virtualization of the entire network fabric. It provides a secure, agile virtual network which is managed by vCenter. NSX can virtualize the role of any firewall, switch, router or load balancer. Network policies can be applied per server, allowing you to isolate infrastructure to different parts of the network, thus improving overall network security. NSX network templates can be deployed instantly, enabling professionals to build network infrastructure from their workspace in a few clicks. ### VMware Horizon The software discussed so far is typically used for datacenter-based infrastructure services, but VMware also has a large presence in the desktop workspace. VMware Horizon is the VMware virtual desktop environment (VDI), which allows desktop and applications to be delivered directly to the user on any type of workstation. This is commonly used within organizations to provide employees access to a centralized and identity-controlled application stack. ### VMware Workstation VMware Workstation is a desktop virtualization software that enables users to run multiple operating systems simultaneously on a single Windows or Linux PC. It is intended for professionals such as developers, testers, and IT administrators who need to create, test, and deploy software across various platforms. Workstation offers advanced features including support for the latest hardware, robust networking capabilities, integration with VMware vSphere, and comprehensive snapshots for easy rollback. ### VMware Fusion VMware Fusion is intended for Mac users, providing the capability to run Windows, Linux, and other operating systems alongside macOS without rebooting. Fusion is popular among developers and IT professionals who need to test applications across different OS environments. It offers advanced features like integration with VMware vSphere, support for DirectX 11, and a simplified user interface. Fusion also supports the latest macOS features, making it a useful tool for creating and managing virtual machines on Mac hardware. ### VMware Player VMware Player, also known as VMware Workstation Player, is a free, simplified version of VMware Workstation aimed at home users and students. It allows users to create and run virtual machines on a Windows or Linux PC. VMware Player supports basic virtualization needs with the ability to run restricted VMs created by VMware Workstation or VMware Fusion Pro. It’s a suitable tool for users who need to run multiple operating systems on a single PC without advanced management features. ### VMware ThinApp VMware ThinApp is an application virtualization solution that packages applications into self-contained executable files. This allows applications to be run without installation, providing compatibility across different versions of Windows and reducing conflicts with other software. ThinApp simplifies application deployment and management, enabling IT administrators to deliver, update, and manage applications more efficiently. It also enhances security by isolating applications from the underlying operating system and other applications ### VMware Cloud Services The VMware cloud is the offering from VMware for cloud-based infrastructure services. It is heavily integrated with Amazon Web Services (AWS) and offers the user a cloud-based service of many of the popular VMware applications discussed here. This eliminates the requirement for local datacenter services and the cost associated with it, and enables many individuals or companies to leverage VMware products for their personal use. Many businesses are moving toward the cloud as part of their future IT strategy. ## VMware Pros and Cons When evaluating whether to use VMware, organizations should consider the following advantages and disadvantages. ### VMWare Pros - Established market presence: VMware has been a leading provider in virtualization and cloud infrastructure for over two decades. Its extensive experience and innovation have given it a reputation as a reliable and advanced solution provider. - Maturity and robustness: VMware's products are known for their stability and reliability. Years of development and real-world testing have resulted in a mature product lineup that can handle demanding enterprise environments. - Integration with legacy systems: VMware solutions offer strong compatibility and integration with existing legacy systems, enabling organizations to modernize their IT infrastructure without the need for a complete overhaul. - Comprehensive management tools: VMware provides an extensive suite of management tools that simplify the administration of virtual environments. Tools like vCenter Server and VMware PowerCLI offer centralized control and automation capabilities, making it easier to manage large-scale deployments. ### VMWare Cons - Complex infrastructure: VMware solutions can be complex to set up and manage, often requiring specialized knowledge and skills. This complexity can increase the time and effort needed for deployment and ongoing management. - Limited compatibility options: While VMware offers integration with many systems, it has fewer compatibility options compared to some of its competitors. This limitation can restrict the flexibility organizations have when choosing hardware and software components. - Costly scalability: Scaling VMware environments can be expensive due to the licensing costs associated with its products. As organizations grow their virtual infrastructure, the incremental costs can become a financial burden. - Inflexible licensing: VMware's licensing model can be inflexible, often requiring long-term commitments and offering limited options for customization. This can be a disadvantage for organizations that need more adaptable licensing solutions. - High license costs: The cost of VMware licenses is generally higher compared to some alternative solutions. These high costs can be a deterrent for smaller organizations or those with limited budgets. - Uncertainty due to Broadcom acquisition: The acquisition of VMware by Broadcom has introduced uncertainty regarding the future direction of VMware's product offerings and pricing models. This can make it difficult for organizations to plan their long-term IT strategies. ## Disclaimer: * This post is for informational purposes only and does not constitute professional, legal, financial, or technical advice. Each situation is unique and may require guidance from a qualified professional. Readers should conduct their own due diligence before making any decisions. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # What is Web Server Hosting? > URL: https://www.atlantic.net/dedicated-server-hosting/what-is-web-server-hosting/ | Updated: 2026-09-16 Web server hosting is a service in which a hosting provider runs web server software (such as Apache, NGINX, or IIS) on its infrastructure to deliver your website's pages, files, and applications to visitors over HTTP and HTTPS. The hosting provider handles the underlying server, networking, and base operating system so your site is reachable on the public internet 24×7. ## What is Web Server Hosting? At its most fundamental level, web server hosting is exactly what it implies: a server platform that hosts websites. A web server handles the HTTP requests when end-users seek out web pages. The web server does not necessarily host all the files that an HTTP request is calling for from each website, but it acts as the facilitator to acquire those files to make the request happen as quickly as possible. For most websites' owners, utilizing a host can be both economically wise and convenient, as the host also provides space for hundreds or even thousands of other websites employing similar resources. ## Web Server Applications: Apache, IIS, and NGINX Web server applications help the server support HTTP requests. There are several web server applications available today, both commercial and open source. Three of the most popular are the Apache HTTP web server, the Microsoft IIS Web Server and the NGINX web application platform. Apache HTTP web server is an open source web application created by the Apache Software Foundation and available free with support from the Apache open source community. Commercial support is provided by managed service providers. Because Apache is a modular application, it works natively with applications such as MySQL, Tomcat, and PHP. Apache powers a large percentage of the internet websites and can be scaled to handle high volumes of traffic on minimal hardware. Apache is popular with the Linux community and is trusted by some of the biggest companies online. Microsoft IIS (Internet Information Services) server is a licensed web server application and an installable role bundled with all Microsoft Windows Server products. Technical support is provided by dedicated managed service providers, and MSPs have direct access to Microsoft technical support channels. IIS easily integrates with existing Microsoft products, such as Office, SharePoint, and PowerShell. IIS is incredibly popular with enterprises due to its user-friendly design and ability to delegate control to different support teams. NGINX is a little different from IIS and Apache; not only is NGINX an HTTP web server, but it is also a reverse proxy (front end), a proxy mail server (POP3/IMAP/SMTP) and a generic TCP/UDP proxy server for load balancing. NGINX is an open source application that is incredibly well optimised, allowing it to scale well for heavy workloads. The additional services offered by NGINX are popular with web developers, as NGINX offers a full suite of applications to run a website from a single server. You can even combine NGINX and Apache on a single server. NGINX can be used as a proxy to an Apache web server, giving developers the flexibility of both web servers. ## Benefits of using Web Server Hosting ### Increased Speed For nearly all web hosting situations, faster websites are better websites. Generally, the faster a website loads, the more sales and conversions the site will generate. End-users are notoriously impatient with slow-loading sites; according to Retail Dive, every second of additional loading time results in a 7% drop in conversion rate. And don’t forget that Google uses loading speed as a variable in its search rankings. ### Higher Availability In the digital world, availability refers to the amount of time required to respond to a request made by an end-user. Achieving high availability involves eliminating single points of failure. Higher availability means better reliability and tougher security and also lowers the risk of a website crashing. ### Data Protection Up-to-date security technology is a must in web server hosting. That includes data centers that are state-of-the-art, with airtight security to keep watch of clients’ most sensitive data. Most web server hosts will custom-build their data centers for specific client purposes and have security watching them 24/7/365 to ensure they stay secure. ### Scalability One of the most buzzworthy words of the past decade, scalability, is all about letting a business, technology, or service grow bigger (or become smaller) as the need arises. If your company is running its own web server, growth means extra costs of buying new hardware and configuring it properly. When your organization’s web server is hosted by a world-class data center, growing to match demand is as simple as sending an email or making a quick phone call. ## Dedicated Servers vs. Cloud Hosting There are two environments where a website can be hosted - a dedicated physical server or a cloud server. Both have their strengths and weaknesses depending on an organization’s specific needs. Below is a breakdown of each environment, along with a deeper dive into its individual strengths and weaknesses. ### Dedicated servers Dedicated servers are tangible hardware devices. They are often used by organizations that stress data security and processing capacity. Dedicated servers are tangible hardware devices. They are often used by organizations that stress data security and processing capacity. They excel when websites are high-functioning, with content that requires lots of memory. For instance, a company that makes tractors might have multiple videos of every vehicle posted online, along with tech specs and a treasure trove of proprietary data on various components, upgrades, etc. Keeping that information on a physical, in-house server makes more sense than putting it in the cloud. The end-users’ requests to play hundreds of videos means that a dedicated server makes sense. On the downside, as with most physical hardware, technology tends to get outdated quickly, which leads to higher capital expenses in replacing equipment, performing maintenance or upgrading via patches, etc. The same is true for scaling up or down. More memory must be added, or perhaps entirely new hardware purchased, to handle the increased flow of traffic. ### Cloud-hosted servers Cloud servers are only virtual for the client, and the physical servers running the cloud servers exist offsite. All of the hardware is located in a data center. All information is uploaded by the client to the cloud environment, whether it’s a website, database, application, or something else. The strengths of having your web server hosted in the cloud are mainly convenience and cost. For starters, the economies of scale will mean your firm pays far less for memory space and processing power than it would with a dedicated server, since most websites don’t demand enormous consumption of either. Your firm is paying for exactly the amount of space it needs - no more, no less. If your firm has a definitive busy season, a definitive slow season, or both, you can also easily scale your needs up or down as demand requires, saving money and time. The biggest negative for cloud-hosted servers is that data may exist on a shared physical server that is running multiple virtual servers. Firms which inherently deal with risky data or that must adhere to strict compliance regulations on how they store and move data often may worry that the cloud not secure or advanced enough for their purposes and should seek out a cloud provider that makes security a priority, or private cloud hosting. ## Disclaimer: * This post is for informational purposes only and does not constitute professional, legal, financial, or technical advice. Each situation is unique and may require guidance from a qualified professional. Readers should conduct their own due diligence before making any decisions. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Atlantic.Net Acceptable Use Policy > URL: https://www.atlantic.net/acceptable-use-policy/ | Updated: 2026-09-16 Atlantic.Net is proud to provide our customers a variety of services including infrastructure as a service, cloud VPS, colocation services, managed virtual servers, and more. Atlantic.Net discourages activities that may infringe on the rights of others, including but not limited to security violations, copyright violations, harassment and violation of individual privacy rights. This Acceptable Use Policy (AUP) serves as notice that Atlantic.Net reserves the right to terminate or otherwise restrict use of any user’s account found to be in violation of any of Atlantic.Net’s guidelines. This AUP may be revised from time to time to reflect additional protections put in place. Continued use of Atlantic.Net services constitutes acceptance of any revised or additional terms of this AUP. If you do not agree to the terms of this agreement please contact us at USA: 1.866.618.3282 or INT:**1.321.206.3730** or **[support@atlantic.net](mailto:support@atlantic.net)** so that we may initiate termination of the account. USE OF YOUR ACCOUNT shall constitute your approval of the AUP. **Definitions** You, Customer, Client, Subscriber, and User refer to the party utilizing Atlantic.Net services. **Personal Files** Atlantic.Net is not responsible for backups of user’s personal files and information unless Customer specifically is paying Atlantic.Net to do so. Additionally, Atlantic.Net reserves the right to delete any information pertaining to user’s accounts within a reasonable time that user is no longer a customer of Atlantic.Net. **Domain Registration Fees** Domain Registration Fees are nonrefundable after five (5) days from the time of registration. If the customer requests a refund during the initial five (5) days, they will incur a $2.00 processing fee. **Network IP address assignments** Any network IP address assignments issued by Atlantic.Net are the property of Atlantic.Net and are considered to be loaned to the Client. In the event service with Atlantic.Net is discontinued for any reason, such addresses will revert to Atlantic.Net. Users shall not use IP addresses not assigned by Atlantic.Net. **No Warranties** Atlantic.Net makes no warranties of any kind, whether expressed or implied, for the service it is providing. Atlantic.Net also disclaims any warranty of merchantability or fitness for a particular purpose. Atlantic.Net will not be responsible for damages the customer suffers. This includes loss of revenue, loss of data resulting from delays, non-deliveries, misdeliveries, or service interruptions caused by its’s own negligence, subscriber’s errors or omissions, or due to the fault of third parties. **Contact Information** Atlantic.Net may need to communicate with its’s customers through email. It is the responsibility of the customer to furnish to Atlantic.Net the appropriate contact email address for such correspondence. It is the responsibility of the customer to check email sent to the primary login email address on the account. It is the responsibility of the customer to contact Atlantic.Net of any changes to their account, such as phone number, address, credit card information, etc. Customer will be required to provide verification for security purposes authorizing them to make any changes to that account. **Taxes** Atlantic.Net shall not be liable for any taxes or other fees to be paid in accordance with or related to purchases made from Client or Atlantic.Net’s server. Client agrees to take full responsibility for all taxes and fees of any nature associated with such products sold. **Termination** Termination of any account will only take place upon phone request or by email. Atlantic.Net can be reached 24 hours a day at USA: 1.866.618.3282 or INT: 1.321.206.3730 or by emailing [support@atlantic.net](mailto:support@atlantic.net) **Cloud Service Limitations** Users may not use the network for open proxies, CDN services, running Torrents or Seed Servers, TOR, cryptocurrency mining/generating, IRC or IRC bots, reselling services through their account to provide free bandwidth to others. **Prohibited Activities** To better ensure that Atlantic.Net accounts are not used for illegal/improper purposes, Atlantic.Net has delineated those activities that are deemed illegal or improper. Individuals who engage in the following activities may be subject to account termination or restrictions placed upon their accounts: **Obscene Materials/Speech** Using Atlantic.Net’s network to store or disseminate or otherwise make available child pornography is expressly prohibited. Any account found in violation of this prohibition will be terminated. Atlantic.Net is required by Federal law to notify law officials when it becomes aware of child pornography on its network. **Spamming** Sending unsolicited bulk and/or commercial messages over the Internet is prohibited. Any individuals who are responsible for assigned IP addresses being added to a Realtime Blackhole List will incur a $50.00 clean-up fee per affected IP, which is neither negotiable nor refundable. Maintaining an open SMTP relay, or using SMTP services for spam or other malicious purposes, is prohibited. **Intellectual Property Violations** Engaging in any activity that may violate the intellectual property rights of another is prohibited. Protected intellectual property rights include, without limitation, copyrights, trademarks, service marks, software piracy, trade secrets, patents held personally and by corporate entities. Atlantic.Net is required by law to comply with orders to restrict accounts that have been found to violate the intellectual property rights of others. **Licensing** All software used on our services must be properly licensed and be in compliance with laws of the geography where the software is being used. For customers that license Microsoft software products via Physical CPU count, CPU Core count, Subscriber Access License (SAL), Client Access License (CAL) or any other licensing models through Atlantic.Net, you agree to acquire the correct amount of licensing in correlation with the accepted licensing model and Microsoft’s Service Provider License Agreement (SPLA) software licensing standards.  You also agree your usage will not exceed your purchased license quantity. For SAL licensing, you agree to acquire and assign a SAL for each user that is authorized to access your instances of Microsoft software directly and indirectly, regardless of actual access to the server software.  For physical and virtualization operating environments, you agree to increase your Core Count or any other applicable resource only after purchasing adequate licensing through Atlantic.Net to keep your software usage properly licensed. Customers are prohibited from removing, modifying or obscuring any copyright, trademark or other proprietary rights notices that are contained in or on any Microsoft Products. Customers are prohibited from reverse engineering, decompiling, or disassembling the Microsoft Products, except to the extent that such activity is expressly permitted by applicable law. Microsoft is not held liable to the extent permitted by applicable law, nor are there any warranties by Microsoft and any liability by Microsoft or its suppliers for any damages, whether direct, indirect, or consequential, arising from the Microsoft Software Services. Customer information may be disclosed to Microsoft or Microsoft resellers as required by Atlantic.Net’s vendors and agreements. Customer agrees that when utilizing Microsoft software, that Microsoft is a third party beneficiary of the End User Agreements, including this Acceptable Use Policy (AUP), with the right to enforce provisions of this agreement and others signed with Atlantic.Net to ensure and verify compliance of the End User. **High Risk Use** Any of Atlantic.Net Services are not designed or intended for high-risk applications, for use as online control systems or use in hazardous environments requiring fail-safe performance, such as in, but not limited to, the operation of nuclear facilities, aircraft navigation or communications systems, air traffic control, life support, weapons systems or in any other device or system in which function or malfunction of the software could result in death, personal injury or physical or environmental damage. Any such use or application by you is outside the scope of this agreement and you are not authorized to use the Services in any such application. **Defamatory/Abusive Language** The use of Atlantic.Net’s network to post or otherwise transmit harassing, abusive, or threatening language is expressly prohibited. **Illegal or Unauthorized Access** Any access to other networks through Atlantic.Net must comply with the rules appropriate for that network. Unlawful or intrusive access is strictly prohibited and includes, but is not limited to attempting to penetrate security measures and/or port scanning. Such activities will result in termination of service and/or legal measures. Distribution of Internet Viruses, Worms, Trojan Horses, or other activities which Atlantic.Net reserves the sole right to be Destructive or Malicious are prohibited. **Facilitating a Violation of This AUP** Advertising, transmitting, or otherwise making available any software, program, product, or service that is designed to violate this AUP may result in the suspension or termination of your account or such other action as Atlantic.Net deems appropriate. Atlantic.Net reserves the right to determine if the engagement in activities, whether lawful or unlawful, may be harmful to its subscribers, operations, and reputation, goodwill, or customer relations. **Third-Party Subscribers** In the event that a user of Atlantic.Net’s service is an ISP or reseller, any violations of user’s (third party) subscribers may be addressed directly by Atlantic.Net terminating or placing restrictions on that subscriber’s account. Atlantic.Net expects that the user will assist Atlantic.Net in enforcing the terms of this AUP against the user’s subscribers. **Privacy** Atlantic.Net recognizes that the Internet is not a completely secure form of communication. Atlantic.Net respects the privacy of its users and will not intentionally monitor communications from its users unless it is directed by governmental authorities to do so. Moreover, Atlantic.Net will disclose any information about its users in order to comply with a court order, subpoena, summons, discovery request, warrant, statute, regulation, or governmental request. Atlantic.Net assumes no obligation to inform the user if such information is requested. **Right to Damages** In the event that an act or omission by the User that constitutes a violation of this AUP causes economic damage to Atlantic.Net, Atlantic.Net will have a right to claim and collect economic damage from the User. **Indemnification** User agrees that it shall defend, indemnify, save and hold Atlantic.Net harmless from any and all demands, liabilities, losses, costs, and claims, including reasonable attorney’s fees, (“Liabilities”) asserted against Atlantic.Net, its agents, its customers, servants, officers, and employees, that may arise or result from any service provided or performed or agreed to be performed or any product sold by User, its agents, employees or assigns. User agrees to defend, indemnify and hold harmless Atlantic.Net against Liabilities arising out of (i) any injury to person or property caused by any products sold or otherwise distributed in connection with Atlantic.Net’s server, (ii) any material supplied by User infringing or allegedly infringing on the proprietary rights of a third party, (iii) copyright infringement and (iv) any defective product which Client sold on Atlantic.Net’s server. --- # Atlantic.Net Cloud Service Level Agreement > URL: https://www.atlantic.net/cloud-service-level-agreement/ | Updated: 2026-09-16 Atlantic.Net offers an Industry Leading Cloud Service Level Agreement (SLA). ## Network Uptime –100% SLA Atlantic.Net guarantees the network will be available 100% of the time in a given month. **If it takes us more than 30 minutes to resolve the network issue from the time the trouble ticket is opened, Atlantic.Net will credit 5% of the monthly usage fee for each additional 30 minutes of downtime (up to 100% of customer’s monthly usage fee for the specific Cloud Server affected).**Network uptime includes the functioning of all network infrastructures such as routers, switches, and cabling, but does not include software and services running on your Cloud Server. Network downtime exists when your Cloud Server is unable to transmit and receive data and Atlantic.Net records such failure in the Atlantic.Net trouble ticket system. Network downtime is measured from the time a trouble ticket is opened. ## Cloud Server Hardware – 100% SLA Atlantic.Net guarantees all hardware components that power your cloud server and will replace any failed components at no cost to you. Once Atlantic.Net determines the cause of the problem, hardware replacement begins. If it takes us more than one hour from the time the cause is identified to replace the faulty hardware, Atlantic.Net will credit 5% of the monthly usage fee per additional hour of downtime (up to 100% of your monthly usage fee for the specific Cloud Server affected). ## Infrastructure – 100% SLA Atlantic.Net guarantees all critical infrastructure components, including power supplied to your Cloud Server and HVAC, will be available  100% of the time in a given month. If it takes us more than 30 minutes to resolve the infrastructure issue from the time the trouble ticket is opened, Atlantic.Net will credit 5% of the monthly usage fee per additional 30 minutes of downtime (up to 100% of your monthly usage fee for the specific Cloud Server affected). Critical infrastructure includes the functioning of all power, HVAC, and cabling. Infrastructure downtime exists when your Cloud Server is shut down due to power or cooling issues and is measured from the time a trouble ticket is opened. **SLA Exemptions:** -  SLA credits will not be issued if the downtime has been caused by scheduled maintenance or if a cloud customer is in breach of any Atlantic.Net service agreements. -  Events of force majeure, including acts of war, god, earthquake, flood, embargo, riot, sabotage, labor disputes, government act, or failure of the Internet are exempt from the Service Level Guarantee. -  Downtime that resulted from modifications or changes of the operating system, database, application code, or other customer code not provided by Atlantic.Net will be exempt from the Service Level Guarantee. **SLA Details:** - ** **To receive an SLA credit, you must email **Cloudsupport@Atlantic.Net** within thirty **(30)** days of the incident. In the email, please provide details on how your Atlantic.Net cloud services were adversely affected. -  This Service Level Guarantee is your sole and exclusive remedy in the event that the Atlantic.Net cloud platform is unavailable. The maximum total credit for the monthly billing period shall not exceed 100% of your monthly usage fee for the specific Atlantic.Net Cloud service affected during said billing period. This Service Level Guarantee is part of your agreement with Atlantic.Net Cloud, along with the Atlantic.Net Cloud Terms of Service, the Acceptable Use Policy, and therefore is subject to the terms and conditions stated therein. -  Due to the Atlantic.Net Cloud billing cycle, Atlantic.Net has 60 days to issue a credit from the date of the incident. --- # Atlantic.Net Cloud Terms of Service > URL: https://www.atlantic.net/cloud-terms-service/ | Updated: 2026-09-16 ## ATLANTIC.NET CLOUD TERMS OF SERVICE This Cloud Terms of Service (“Terms of Service”) is by and between Atlantic.Net, Inc., a Delaware corporation (“we” or “Atlantic.Net”), and the customer who orders Atlantic.Net’s cloud services (“you” or “Customer”).  These Terms of Service form part of an agreement (this/the “Agreement”) between Atlantic.Net and Customer.  The Agreement (as defined below) governs the provision of Atlantic.Net’s cloud services and the use of Atlantic.Net’s service constitutes acceptance and agreement to Atlantic.Net’s Terms of Service. By accepting the Agreement via electronic click-through authorization, Customer acknowledges that it has read and fully understands all of the terms and conditions set forth in the Agreement and hereby agrees to abide by the terms and conditions hereof. Your use of Atlantic.Net Services is governed by these Terms of Service, Atlantic.Net’s Acceptable Use Policy, the terms of your Order, Atlantic.Net’s Cloud Service Level Agreement, and Atlantic.Net’s Privacy Policy.  The term “Agreement” as used herein shall collectively refer to the Order, Terms of Service, Service Level Agreement, Acceptable Use Policy, and Privacy Policy.  If the individual who submits an Order or indicates agreement on the Atlantic.Net website does so on behalf of a company or other legal entity, the individual represents that he or she has authority to bind that entity to the Agreement.  This Agreement is the complete and exclusive agreement between you and Atlantic.Net regarding its subject matter and supersedes and replaces any prior agreement, understanding, or communication, written or oral. 1.         **Defined Terms**.  Some words used in the Agreement have particular meanings: **“Acceptable Use Policy” or “AUP”** means Atlantic.Net’s Acceptable Use Policy posted on Atlantic.Net’s website, as may be amended from time to time. **“Business Day”**means 8:00 a.m. – 5:00 p.m. Monday through Friday, United States Eastern Standard time, excluding federal public holidays in the United States. **“Confidential Information”** means all information disclosed by one of us to the other, whether before or after the effective date of the Agreement, that the recipient should reasonably understand to be confidential, including: (i) for you, all information transmitted to or from, or stored on, the Atlantic.Net cloud system, (ii) for Atlantic.Net, unpublished prices and other terms of service, audit and security reports, product development plans, data center designs (including non-graphic information you may observe on a tour of a data center), server configuration designs, and other proprietary information or technology, and (iii) for both of us, information that is marked or otherwise conspicuously designated as confidential. Information that is developed by one of us on our own, without reference to the other’s Confidential Information, or that becomes available to one of us other than through violation of the Agreement or applicable law, shall not be “Confidential Information” of the other party. **“Order”** means either: (i) the online order form that you submit to Atlantic.Net via the Atlantic.Net website, or (ii) any other written order form (either in electronic or paper form) provided to you by Atlantic.Net for signature that describes the Services you are purchasing, and that is signed by you, either manually or electronically. **“Privacy Policy”** shall mean Atlantic.Net’s Privacy Policy posted on Atlantic.Net’s website, as may be amended from time to time. **“Service Level Agreement”**shall mean the Atlantic.Net’s Server Cloud Service Level Agreement posted on Atlantic.Net’s website, as may be amended from time to time. **“Services”** means those services described in the Order. 2.         **Atlantic.Net’s Obligations**.  Contingent on Atlantic.Net’s acceptance of your Order, Customer’s satisfaction of Atlantic.Net’s credit approval requirements, and subject to these Terms of Service, Atlantic.Net agrees to provide the Services. 3.         **Customer’s Obligations**.  You may use our services, provided that you are of legal age to form a binding contract and are not barred from receiving such services under the laws of the United States or other jurisdictions. In order to access our services, you are required to provide current and factual identification, contact, and other information as part of the registration process. You agree to do each of the following: (i) comply with applicable law and the AUP (ii) pay when due the fees for the Services, (iii) use reasonable security precautions in light of your use of the Services, (iv) cooperate with Atlantic.Net’s reasonable investigation of outages, security problems, and any suspected breach of the Agreement, (v) keep your billing contact and other account information up to date; and (vi) immediately notify Atlantic.Net of any unauthorized use of your account or any other breach of security.  In the event of a dispute between us regarding the interpretation of applicable law or the AUP, Atlantic.Net’s reasonable determination shall control. 4.         **Access to the Services**.  You may access the Services via the cloud server administration interface on Atlantic.Net’s website.  Atlantic.Net may modify the cloud server administration interface or Application Programming Interface (“API”) at any time or may transition to new APIs. Your use of any API you download from the Atlantic.Net website is governed by the license terms included with the code in the file named “COPYING” or “LICENSE” or like caption. 5.         **Service Level Agreement**.  The Cloud Service Level Agreement listed below is part of this Agreement for those Services you are buying and may be viewed at: [https://www.atlantic.net/cloud-service-level-agreement/](https://www.atlantic.net/cloud-service-level-agreement/) .  Atlantic.Net shall not be liable for interruptions in the Services or any other failure of the Services except as specifically set forth in the Service Level Agreement and in this Section 5.  In the event of hardware failure: (i) Atlantic.Net will make reasonable efforts to recover lost data, upon Customer’s request, but data recovery is not guaranteed; and (ii) Atlantic.Net will provide such credits as are required by the Service Level Agreement (if any).  In the event that Customer is dissatisfied with the Services, Customer’s sole remedies are those listed in the Service Level Agreement and in this Section 5, or termination of this Agreement as authorized pursuant to Section 10.  All Services, whether or not addressed in the Service Level Agreement, are provided pursuant to the provisions of Section 14 below and the other terms and conditions of this Agreement. 6.         **Term**.  The initial term for each Order begins on the date we make the Services available for your use and continues for the period stated in the Order.  If no period is stated in the Order, then the initial term shall be one month.  Upon expiration of the initial term, the Order will automatically renew for successive renewal terms equal to the initial term, unless and until one of us gives the other a written notice of termination for convenience prior to the expiration of the initial term, or then-current renewal term, as applicable. If the services purchased are offered on an hourly basis your term will start when we make the Services available for your use and will continue until you delete them. You must follow Atlantic.Net’s non-renewal process accessible from the Atlantic.Net Cloud control panel to give an effective notice of non-renewal. 7.         **Fees**.  Atlantic.Net will charge you the fees stated in your Order.  If you have made a minimum commitment in your Order, and your actual usage does not meet or exceed the minimum commitment, Atlantic.Net will charge you the difference between your minimum commitment and your actual usage. Unless you have made other arrangements, [Atlantic.Net](http://atlantic.net/) will charge you without invoice as follows: (i) for recurring fees, in advance, on or around the first day of each billing cycle, (ii) for non-recurring fees (such as fees for initial set-up or overages) on or around the date incurred, or on or around the first day of the billing cycle that follows the date incurred, and (iii) when new or unverified users that have exceeded a predetermined usage threshold each time the threshold is reached. Once the user has a reliable payment history, this threshold will be removed automatically. Unless otherwise agreed in the Order, your billing cycle will be monthly, beginning on the date that Atlantic.Net first makes the Services available to you.  Atlantic.Net may charge interest on overdue amounts at 1.5% per month (or the maximum legal rate if it is less than 1.5%).  If any amount is overdue by more than thirty (30) days, and Atlantic.Net brings a legal action to collect or engages a collection agency, you must also pay Atlantic.Net’s reasonable costs of collection, including attorney fees and court costs.  All fees are stated and will be charged in US Dollars.  Any “credit” that we may owe you, such as a credit for failure to meet a service level guaranty, will be applied to fees due from you for services, and will not be paid to you as a refund.  Charges that are not disputed within sixty (60) days of the date charged are conclusively deemed accurate.  You must provide Atlantic.Net with accurate factual information to help Atlantic.Net determine if any tax is due with respect to the provision of the Services, and if Atlantic.Net is required by law to collect taxes on the provision of the Services, you must pay Atlantic.Net the amount of the tax that is due or provide satisfactory evidence of your exemption from the tax. Any credit that we may owe you, such as a credit for a Service Level Agreement remedy, will be applied to unpaid fees for services or future services at our option. 8.         **Fee Increases**.  If you are under a month-to-month contract, then we may increase fees at any time on thirty (30) days advance written notice.  If the initial term of your Agreement is longer than one month, then we may increase your fees effective as of the first day of the renewal term that first begins thirty days from the day of our written notice of a fee increase. 9.         **Suspension**.  We may suspend your Services without liability if: (i) we reasonably believe that the Services are being used (or have been or will be used) in violation of the Agreement, (ii) we discover that you are, or are affiliated in any manner with, a person who has used similar services abusively in the past; (iii) you don’t cooperate with our reasonable investigation of any suspected violation of the Agreement; (iv) we reasonably believe that your Services have been accessed or manipulated by a third party without your consent, (v) we reasonably believe that suspension of the Services is necessary to protect our network or our other customers, (vi) a payment for the Services is overdue, or (vii) suspension is required by law.  We will give you reasonable advance notice of a suspension under this paragraph and a chance to cure the grounds on which the suspension are based, unless we determine, in our reasonable commercial judgment, that a suspension on shorter or contemporaneous notice is necessary to protect Atlantic.Net or its other customers from imminent and significant operational or security risk.  If the suspension was based on your breach of your obligations under the Agreement, then we may continue to charge you the fees for the Services during the suspension and may charge you a reasonable reinstatement fee (not to exceed $150) upon reinstatement of the Services. 10.       **Credit Authorization.  **The Customer hereby authorizes Atlantic.Net and gives consent to Atlantic.Net under applicable privacy laws for Atlantic.Net. to obtain credit information and bank and other financial references regarding the Customer for the purposes of assessing the Customer’s credit worthiness. The Customer will promptly execute and deliver to Atlantic.Net such further documents and assurances and take such further actions as Atlantic.Net may from time to time reasonably request in order to carry out the intent and purpose of this Section.  The Customer authorizes Atlantic.Net to post pending charges to credit, debit and prepaid cards provided to be used for payment of subscription services to determine the Customer’s creditworthiness. 11.       **Termination for Breach**. 11.1     We may terminate the Agreement for breach on written notice if: (i) we discover that the information you provided to us about yourself or your proposed use of the Services was materially inaccurate or incomplete, (ii) if you are an individual, you were not at least 18 years old or otherwise did not have the legal capacity to enter into the Agreement at the time you submitted the Order for Services, or if you are an entity or fiduciary, the individual submitting the Order for Services did not have the legal right or authority to enter into the Agreement on behalf of the person represented to be the customer, (iii) your payment of any invoiced amount is overdue, and you do not pay the overdue amount within three (3) days of our written notice, (iv) a credit report indicates you no longer satisfy Atlantic.Net’s credit approval requirements, provided that if we terminate on these grounds, we must give you a reasonable opportunity to migrate your environment out of Atlantic.Net in an orderly fashion, (v) you use your Service in violation of the AUP and fail to remedy the violation within ten (10) days of our written notice, (vi) you violate the AUP more than once, even if you cure each violation, or (vii) you fail to comply with any other provision of the Agreement and do not remedy the failure within thirty (30) days of our notice to you describing the failure. (viii) if you violate our acceptable use policy or a credit report indicates you no longer satisfy Atlantic.Net’s credit approval requirements within (30) days of your cloud hosting account being activated, we may terminate your account immediately and without notice. 11.2     You may terminate the Agreement for breach on written notice if: (i) we materially fail to provide the Services as agreed and do not remedy that failure within ten (10) days of your written notice describing the failure, or (ii) we materially fail to meet any other obligation stated in the Agreement and do not remedy that failure within thirty (30) days of your written notice describing the failure. 12.       **Access to Data**. 12.1     You will not have access to your data stored on the Atlantic.Net cloud system during a suspension or following termination. 12.2     Although the Atlantic.Net cloud service may be used as a backup service, you agree that you will maintain at least one additional current copy of your programs and data stored on the Atlantic.Net cloud system somewhere other than on the Atlantic.Net cloud system. 12.3    **Security and Backup**. Customer is responsible for properly configuring and using the ATLANTIC.NET services and taking appropriate action to secure, protect, and backup Customer’s content in a manner that will provide appropriate security and availability. 13.       **Unauthorized Access to Your Data or Use of the Services**.  Atlantic.Net is not responsible to you for unauthorized access to your data or the unauthorized use of the Services unless the unauthorized access or use results from Atlantic.Net’s failure to meet its security obligations stated in the Agreement. You are responsible for the use of the Services by any employee of yours, any person to whom you have given access to the Services, and any person who gains access to your data or the Services as a result of your failure to use reasonable security precautions, even if such use was not authorized by you. 14.       **Warranties, Disclaimers, and Limitations of Liability**. 14.1     ATLANTIC.NET MAKES NO EXPRESS OR IMPLIED WARRANTIES, INCLUDING WITHOUT LIMITATION WARRANTIES OF TITLE, NONINFRINGEMENT, MERCHANTABILITY, OR FITNESS FOR A PARTICULAR PURPOSE.  You acknowledge that there are risks inherent in Internet connectivity that could result in the loss of your privacy, Confidential Information, and property.  Atlantic.Net has no obligation to provide security other than as stated in this Agreement.  Atlantic.Net does not warrant that the Services will be uninterrupted, error-free, completely secure, or free from viruses or other harmful components. The Service is provided with no warranties regarding security, reliability, protection from attacks, data integrity, or data availability (including without limitation data integrity or availability related to cloud storage features of the Services).  Except to the extent specifically provided in the Service Level Agreement, THE SERVICES ARE PROVIDED ON AN “AS IS” AND “AS AVAILABLE” BASIS.  No communication between Customer and Atlantic.Net will create a warranty or in any way alter or restrict any disclaimer of warranty or limitation of liability set forth in this Section 14 or elsewhere in this Agreement.  As used in the previous sentence, “communications” include, without limitation, marketing materials and representations of salespeople, the advice provided by Atlantic.Net or any of its representatives, quotes, and any Order or other ordering document. 14.2     ATLANTIC.NET WILL NOT BE LIABLE FOR ANY CONSEQUENTIAL, INCIDENTAL, INDIRECT, EXEMPLARY, PUNITIVE, OR MULTIPLE DAMAGES, EVEN IF ADVISED IN ADVANCE OF THE POSSIBILITY OF SUCH DAMAGES. ATLANTIC.NET’S MAXIMUM LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT WILL NOT EXCEED THE TOTAL AMOUNT OF FEES PAID BY CUSTOMER DURING THE THREE (3) MONTHS PRECEDING THE INJURY GIVING RISE TO THE CLAIM. 14.3     Except to the extent specifically provided in Section 5 above, and except to the extent that applicable law specifically forbids such limitation of liability, ATLANTIC.NET WILL HAVE NO LIABILITY WHATSOEVER FOR ANY CLAIMS, LOSSES, ACTIONS, DAMAGES, SUITS, OR PROCEEDINGS RESULTING FROM ANY OF THE FOLLOWING OR FROM ANY ATLANTIC.NET EFFORTS TO ADDRESS OR MITIGATE ANY OF THE FOLLOWING: (i) SECURITY BREACHES, INCLUDING WITHOUT LIMITATION EAVESDROPPING, THIRD PARTY ACCESS TO CUSTOMER DATA OR TO ASSIGNED COMPUTERS, THIRD PARTY ACCESS TO OR MISUSE OF PASSWORDS PROVIDED TO ATLANTIC.NET, AND INTERCEPTION OF TRAFFIC SENT OR RECEIVED USING THE SERVICE; (ii) RELEASE OR EXPOSURE, FOR ANY OTHER REASON, OF PERSONALLY IDENTIFIABLE INFORMATION OR OTHER PRIVATE DATA, INCLUDING DATA BELONGING TO CUSTOMER’S OWN CUSTOMERS AND OTHER USERS; (iii) DENIAL OF SERVICE ATTACKS, VIRUSES, WORMS, AND OTHER INTENTIONAL INTERFERENCE BY THIRD PARTIES, INCLUDING WITHOUT LIMITATION BY OTHER ATLANTIC.NET CUSTOMERS; (iv) LOSS OF DATA OR LOSS OF ACCESS TO DATA; (v) ACTIONS OF THIRD PARTIES, INCLUDING WITHOUT LIMITATION OTHER ATLANTIC.NET CUSTOMERS AND THIRD PARTY PRODUCTS AND SERVICES PROVIDERS; (vi) ACTIONS OF ATLANTIC.NET EMPLOYEES, AGENTS, OR CONTRACTORS ACTING OUTSIDE THE SCOPE OF THEIR DUTIES; (vii) MISTAKES, OMISSIONS, INTERRUPTIONS, DELETIONS OF FILES, ERRORS, DEFECTS, DELAYS IN OPERATION, OR OTHER FAILURES OF PERFORMANCE OF THE SERVICE, INCLUDING WITHOUT LIMITATION ACCIDENTAL DISCONNECTION AND TERMINATION OF SERVICE; AND (viii) THE ACCURACY, COMPLETENESS, AND USEFULNESS OF THE SERVICE. THE PROVISIONS OF THIS SUBSECTION 14.3 APPLY, WITHOUT LIMITATION, EVEN IF CUSTOMER PURCHASES SERVICE FEATURES ADDRESSING SECURITY, DATA INTEGRITY, DATA BACKUP, ATTACK PROTECTION, VIRUSES, SPAM, MONITORING, OR SYSTEM INTEGRITY. Atlantic.Net does not control and has not thoroughly reviewed all the websites linked to Atlantic.Net’s website or run by Atlantic.Net’s customers or by providers of third-party products and services. With the exception of its own website, Atlantic.Net is not responsible or liable for the content or practices of any website, including without limitation third-party websites referenced in the preceding sentence. 14.4     THE LIABILITIES LIMITED BY THIS SECTION 14 APPLY: (i) TO LIABILITY FOR NEGLIGENCE; (ii) REGARDLESS OF THE FORM OF ACTION, WHETHER IN CONTRACT, TORT, STRICT PRODUCT LIABILITY, OR OTHERWISE; (iii) EVEN IF ATLANTIC.NET IS ADVISED IN ADVANCE OF THE POSSIBILITY OF THE DAMAGES IN QUESTION AND EVEN IF SUCH DAMAGES WERE FORESEEABLE; AND (iv) EVEN IF CUSTOMER’S REMEDIES FAIL OF THEIR ESSENTIAL PURPOSE. Atlantic.Net’s limitations and exclusions of liability and disclaimers of warranty, set forth in this Section 14 and elsewhere in this Agreement apply equally to Atlantic.Net’s officers, employees, agents, contractors, representatives, suppliers, subsidiaries, parents, and affiliated companies. Customer acknowledges and agrees that Atlantic.Net has set its prices and entered into this Agreement in reliance upon such limitations of liability and that such limitations of liability form an essential basis of the bargain between Atlantic.Net and Customer. 15.       **Indemnification. **If we, our affiliates, or any of our or their respective employees, agents, or suppliers (the “Atlantic.Net Indemnitees”) are faced with a legal claim by a third party arising out of your actual or alleged gross negligence, willful misconduct, violation of law, failure to meet the security obligations required by the Agreement, violation of the AUP, or violation of Section 16 (Export Matters) of the Agreement, then you will pay the cost of defending the claim (including reasonable attorney fees) and any damages award, fine, or other amount that is imposed on the Atlantic.Net Indemnitees as a result of the claim.  Your obligations under this Section include claims arising out of the acts or omissions of your employees, any other person to whom you have given access to the Services, and any person who gains access to the Services as a result of your failure to use reasonable security precautions, even if the acts or omissions of such persons were not authorized by you.  If you resell the Services, the grounds for indemnification stated above also include any claim brought by your customers or end-users arising out of your resale of the Services.  We will choose legal counsel to defend the claim, provided that these decisions must be reasonable and must be promptly communicated to you. You must comply with our reasonable requests for assistance and cooperation in the defense of the claim. We may not settle the claim without your consent, although such consent may not be unreasonably withheld. You must pay expenses due under this Section as we incur them. 16.       **Export Matters**.  You represent and warrant that you are not on the United States Department of Treasury, Office of Foreign Asset Controls list of Specially Designated National and Blocked Persons and are not otherwise a person to whom Atlantic.Net is legally prohibited to provide the Services. You may not use the Services for the development, design, manufacture, production, stockpiling, or use of nuclear, chemical or biological weapons, weapons of mass destruction, or missiles, in a country listed in Country Groups D: 4 and D: 3, as set forth in Supplement No. 1 to the Part 740 of the United States Export Administration Regulations, nor may you provide administrative access to the Service to any person (including any natural person or government or private entity ) that is located in or is a national of Cuba, Iran, Libya, Sudan, North Korea or Syria or any country that is embargoed or highly restricted under United States export regulations. 17.       **Confidential Information**.  Each of us agrees not to use the other’s Confidential Information except in connection with the performance or use of the Services, as applicable, the exercise of our respective legal rights under the Agreement, or as may be required by law.  Each of us agrees not to disclose the other’s Confidential Information to any third person except as follows: (i) to our respective service providers, agents, and representatives, provided that such service providers, agents, or representatives agree to confidentiality measures that are at least as stringent as those stated in these General Terms and Conditions; (ii) to law enforcement or government agency if required by a subpoena or other compulsory legal process, or if either of us believes, in good faith, that the other’s conduct may violate applicable criminal law as required by law; or (iii) in response to a subpoena or other compulsory legal process, provided that each of us agrees to give the other written notice of at least seven days prior to disclosing Confidential Information under this Section (or prompt notice in advance of disclosure, if seven days advance notice is not reasonably feasible), unless the law forbids such notice. 18.       **Third-Party Software**.  In addition to the terms of our Agreement, your use of any third-party software is governed by the third party’s software license terms. 19.       **Who May Use The Services**.  You may resell the Services, but you are responsible for use of the Services by any third party to the same extent as if you were using the Services yourself.  If you resell any part of the Services then you must include in a written agreement with your customers the content of Section 21 (No High-Risk Use).  Unless otherwise agreed, Atlantic.Net will provide support only to you, not to any other person you authorize to use the Services.  There are no third-party beneficiaries to the Agreement, meaning that third parties do not have any rights against either of us under the Agreement.  Regardless of the status of the business relationship between you and any third party, the Agreement shall continue to remain in full force and effect. 20.       **Notices**.  Notices to Atlantic.Net under the Agreement shall be given in writing via first class mail or established and well-known express courier to the Legal Department, at Atlantic.Net’s principal office address posted on Atlantic.Net’s website, currently: Legal 440 West Kennedy Blvd, Suite 3 Orlando, FL 32810 Notices to Customer shall be given via electronic mail to the individual designated as the Contact on the Order or by means reasonable under the circumstances, including an e-mail to a known contact.  Notices are deemed received on the day delivered, or if that day is not a Business Day, on the first Business Day following the day delivered. 21.       **No High-Risk Use**.  You may not use the Services in any situation where failure or fault of the Services could lead to death or serious bodily injury of any person, or to physical or environmental damage.  For example, you may not use or permit any other person to use, the Services in connection with aircraft or other modes of human mass transportation, nuclear or chemical facilities, or Class III medical devices under the Federal Food, Drug, and Cosmetic Act. 22.       **Ownership of Intellectual Property**.  Each of us retains all right, title, and interest in and to our respective trade secrets, inventions, copyrights, and other intellectual property.  Any intellectual property developed by Atlantic.Net during the performance of the Services shall belong to Atlantic.Net unless we have agreed with you in advance in writing that you shall have an interest in the intellectual property. 23.       **IP Addresses**.  Upon expiration or termination of the Agreement, you must discontinue use of the Services and relinquish use of the IP addresses and server names assigned to you by Atlantic.Net in connection with Services, including pointing the DNS for your domain name(s) away from Atlantic.Net Services. 24.       **Assignment/Subcontractors**.  You may not assign the Agreement without Atlantic.Net’s prior written consent.  We may assign the Agreement in whole or in part as part of a corporate reorganization or a sale of our business, and we may transfer your Confidential Information as part of any such transaction.  Atlantic.Net may use third-party service providers to perform all or any part of the Services, but Atlantic.Net remains responsible to you under this Agreement for work performed by its third-party service providers to the same extent as if Atlantic.Net performed the Services itself. 25.       **Force Majeure**.  Neither of us will be in violation of the Agreement if the failure to perform the obligation is due to an event beyond our control, such as significant failure of a part of the power grid, significant failure of the Internet, natural disaster, war, riot, insurrection, epidemic, strikes or other organized labor action, terrorism, or other events of a magnitude or type for which precautions are not generally taken in the industry. 26.       **Construction and Enforcement**.  The Agreement shall be construed in accordance with the laws of the State of Florida, without application of the principles or conflicts of laws.  If it becomes necessary for any party to institute legal action to enforce the terms and conditions of the Agreement, the successful party will be awarded reasonable attorney’s fees at all trial and appellate levels, expenses, and costs.  Any suit, action or proceeding with respect to the Agreement shall be brought in the state or federal courts located in Orange County in the State of Florida.  The parties hereto hereby accept the exclusive jurisdiction of those courts for the purpose of any such suit, action or proceeding.  Venue for any such action, in addition to any other venue permitted by statute, will be Orange County, Florida.  The parties hereto hereby irrevocably waive, to the fullest extent permitted by law, any objection that any of them may now or hereafter have to the laying of venue of any suit, action or proceeding arising out of or relating to the Agreement or any judgment entered by any court in respect thereof brought in Orange County, Florida, and hereby further irrevocable waive any claim that any suit, action or proceeding brought in Orange County, Florida, has been brought in an inconvenient forum. 27.       **Entire Agreement; Amendment**.  The Agreement constitutes the entire agreement between the parties hereto with respect to the subject matter hereof and supersedes and terminates any prior communication, agreement, or understanding, whether written or oral. 28.       **Severability**.  In the event that any of the provisions of the Agreement, or portions thereof, are held to be unenforceable or invalid by any court of competent jurisdiction, the validity and enforceability of the remaining provisions, or portions thereof, shall not be affected thereby. 29.       **Survival of Representations, Warranties, Covenants, and Agreements**.  The representations, warranties, covenants, and agreements contained herein shall survive the termination of the Agreement. 30.          **Change**     ATLANTIC.NET HEREBY RESERVES THE RIGHT TO AMEND, ALTER, MODIFY, REPLACE OR SUSPEND, FROM TIME TO TIME IN ITS SOLE DISCRETION, ALL OR ANY PORTION OF THIS TERMS OF SERVICE, THE SERVICE LEVEL AGREEMENT, THE ACCEPTABLE USE POLICY OR THE PRIVACY POLICY.  CURRENT COPIES OF ATLANTIC.NET’S TERMS OF SERVICE, SERVICE LEVEL AGREEMENT, ACCEPTABLE USE POLICY, AND PRIVACY POLICY MAY BE REVIEWED OR PRINTED BY CUSTOMER ON ATLANTIC.NET’S WEBSITE. CUSTOMER HEREBY REPRESENTS AND WARRANTS THAT IT HAS READ, UNDERSTOOD, AND ACCEPTED THE TERMS OF SERVICE, THE SERVICE LEVEL AGREEMENT, THE ACCEPTABLE USE POLICY, AND THE PRIVACY POLICY.** **CUSTOMER’S USE OF THE SERVICES AFTER ANY SUCH CHANGES ARE IMPLEMENTED CONSTITUTES ACCEPTANCE OF THE CHANGES.  PLEASE CONSULT THE TERMS AND CONDITIONS OF THE ABOVE DOCUMENTS REGULARLY. 31.          **Not A Legal Advice.**Atlantic.Net provides general information on a wide range of topics that includes compliance, best practices, and cybersecurity on its website and blog with the best effort to help educate users. The information is intended for general information only and is not legal advice nor the best fit for all scenarios. Atlantic.Net’s postings will be updated from time to time, however, there will be cases where the information may be out of date. The information is provided “as is” without any representations or warranties, express or implied, and may not constitute the most up-to-date legal or other information. We make no representations or warranties in relation to the information in the informational content and blogs and all liability with respect to actions taken or not taken based on the contents of this article are hereby expressly disclaimed. You must not rely on the information in the informational and educational resources as an alternative to legal advice from your attorney or other professional legal services provider. If you have any specific questions about any legal matter you should consult your CPA, attorney, auditors, cybersecurity experts, or other professional legal services for legal and best practice advice. Our website may contain links to and from other third-party websites as referenced resources deemed fit by the publisher with or without any cause. Such links are only for the convenience of the reader, user or browser; we do not recommend or endorse the contents of any third-party sites. Updated: August 12, 2021 --- # Atlantic.Net Colocation Policies and Regulations > URL: https://www.atlantic.net/colocation-policies-regulations/ | Updated: 2026-09-16 The colocation facility will be accessible 24 hours a day, 7 days a week, except in the event of an emergency. Atlantic.Net shall use reasonable efforts to provide advance notice to Customer regarding material changes to or suspension of the hours of operation. Customer will assure its officers, employees, technicians, agents, representatives, subcontractors, and visitors who are granted access to the building and the colocation facility, comply with the policies and procedures set forth herein and individual facility policies. Customer will be responsible for any damages caused by its officers, employees, technicians, agents, representatives, subcontractors, shipping providers, and visitors. Atlantic.Net may provide a kitchenette, conference room, restrooms, and work area in the colocation facilities. Use of any of the foregoing will be in accordance with the policies and procedures set forth herein or as posted at the colocation facilities. Customer shall comply with all laws, orders, and regulations of all governmental bodies having jurisdiction over the building and/or Customer’s activities and with all of building owner’s and Atlantic.Net’s policies and procedures.   ## GENERAL RULES AND REGULATIONS   ### CUSTOMER EQUIPMENT #### Equipment Delivery & Storage Atlantic.Net will accept delivery of and store customer’s equipment in accordance with the guidelines set forth below. Due to limited storage space in each colocation facility, Atlantic.Net, at its sole discretion, has the right to deny or limit the amount of storage space and storage time to customers. #### Delivery Scheduling Due to individual building requirements at each site, all Customer deliveries must be scheduled at least 48 hours in advance with Atlantic.Net’s Network Operations Center (NOC), reachable toll-free at 866-618-3282. In the event a loading dock is required for the delivery of the equipment, Customer shall be responsible for any applicable charges imposed by the landlord or building manager, if any. If Atlantic.Net has not been notified of equipment arrival, Atlantic.Net will deny acceptance of shipment. #### Third Party Equipment Delivery If the equipment is delivered by a third party, Atlantic.Net facility personnel will receive it on behalf of Customer, provided that Customer pre-scheduled the delivery with Atlantic.Net’s NOC. If Atlantic.Net has not been notified of equipment arrival, Atlantic.Net will deny acceptance of shipment. Include the following packing and shipping information: - Customer account number - Customer ticket number (assigned by Atlantic.Net) on the shipping label - Atlantic.Net colocation facility address - Customer cabinet or cage number (assigned by Atlantic.Net) - Special instructions Customer shall prepay all shipments, freight, packages, etc. Atlantic.Net will not accept shipments that require any payment, whatsoever. Customer is responsible for all shipping and/or freight claims. If the shipment is large and cannot be easily brought into the Data Center then it is the responsibility of the Customer to have the shipping company bring the equipment into the Data Center from the building loading dock. Upon receipt of Customer’s equipment, Atlantic.Net will provide the following: - Verify that the shipment is for the correct colocation facility. - Conduct a thorough visual inspection of the external packaging for possible damage. - Inventory all boxes and verify that the carton count matches shipping receipt. - Place the equipment in Customer’s Space or store the equipment in a secured area until Customer’s Space is ready or available in accordance with the equipment storage policy. - Notify Customer of receipt of all shipments, damages, or shortages, if any. In the event of damaged external packaging, Atlantic.Net will accept the equipment and indicate, “damaged shipment/freight” on the shipping receipt and request the delivery driver to countersign acknowledging delivery of “damaged shipment/freight.” In the event of a discrepancy, Atlantic.Net will accept the shipment and indicate “short shipment/freight” on the shipping receipt and request the delivery driver to countersign acknowledging delivery of “short shipment/freight.” #### Storage If Customer’s equipment can be safely locked in the Customer’s Space, no storage charges will apply. However, once the initial customer build has been completed no spare equipment can be stored in cardboard boxes within the confines of a customer’s space or any portion of the colocation floor. If there is not enough storage area in a Customer’s Space, Atlantic.Net will store Customer’s equipment in a designated and secure storage area if there is space to do so at the discretion of the site Operations Manager and the Atlantic.Net NOC. Customer will have fifteen (15) days in which to retrieve its equipment from the storage area from the date the equipment was delivered, after which, storage fees will apply. All equipment left in Atlantic.Net storage areas for more than forty-five (45) days will be shipped to a Customer specified location at Customer’s sole cost and expense. Atlantic.Net is not responsible for loss or damage to Customer equipment stored in Atlantic.Net facilities or in transit if returned to Customer. #### Inventory of Equipment Atlantic.Net requires an inventory of Customer equipment configuration upon execution of a colocation contract or installation. Atlantic.Net has the right to conduct, upon reasonable advance notice to Customer, an inventory of Customer’s equipment and equipment configurations during the term of Customer’s license. Customer is required to notify Atlantic.Net of any significant change in equipment, including, but not limited to, upgrades, reconfigurations, and deinstallations. #### Installation Prior to the use of the Space, Customer shall install or have Atlantic.Net install within Customer’s Space an appropriate number of (i) patch panels, (ii) DSX panels for category 5 twisted pair, coax, single and multi-mode fiber, or (iii) other appropriate point of demarcation equipment number. Atlantic.Net may modify the appropriate amount of demarcation equipment required by Atlantic.Net from time to time in its reasonable discretion. Upon such modification, Customer shall install or have Atlantic.Net install within the Space licensed by Customer, the appropriate amount of demarcation equipment. Customer is solely responsible for any connections, wiring, and items inside Customer’s Space between the demarcation equipment and Customer’s equipment. All wiring, connections, circuitry, and utility ports shall be labeled to include appropriate information in accordance with Atlantic.Net standard procedure for identification purposes. Upon Customer’s request and if Customer provides the required information, Atlantic.Net shall provide such labels. However, Atlantic.Net shall have no liability with respect to such labels, even if Atlantic.Net provides the labels. All cables, interconnections, demarcation equipment, and wiring must be cleanly wrapped and tied together and kept within the applicable cabinet or rack within the Space licensed by Customer in a manner satisfactory to Atlantic.Net. Upon request, Atlantic.Net shall assist with cleanly wrapping wiring, interconnections, Customer demarcation equipment wiring or cables through our Remote Hands services. Customer shall not permit any wiring, interconnections, Customer’s demarcation equipment connections or cables to enter any other space outside of Customer’s cabinet, rack or Customer licensed Space. Customer shall not install any equipment that cannot be securely affixed or bolted into a cabinet or rack in a manner reasonably acceptable to Atlantic.Net. Any and all equipment that is too large or heavy for a rack or cabinet (including, but not limited to large servers) shall be fastened, securely affixed or bolted directly to the floor by an Atlantic.Net technician. Customer shall not stack or rest any equipment on any other equipment. In addition, nothing may be mounted on cage walls that may restrict the airflow through the Atlantic.Net facility. No equipment shall be placed directly on the floor. The equipment shall be at least 6 inches off the floor using either shelves or rack rails. No other method shall be used. (i.e. Cardboard boxes to elevate equipment). ### SECURITY #### General Atlantic.Net facilities are physically secure installations that are accessible to authorized customers 24x7x365. A closed-circuit television security system typically is located at all entrances. A biometric scanner/card access system controls access to the facility. All visitors at the facility must sign in and state their affiliation to an Atlantic.Net Customer. Customer may not prop open any doors within the Atlantic.Net facility. No one may shield his or her face in any manner from the Atlantic.Net security system. All Customer employees, vendors, and visitors must display their access badge or visitor badge prominently AT ALL TIMES. All customers shall present an “access list” of permitted employees that are allowed entry to the facility and access to the customer space. Any Customers that wish to grant access to an employee not on the permitted “access list” must ensure that the employee is accompanied by someone on the “access list’ at all times. Customers are responsible for all actions of their employees. #### Access/Security Badges Upon execution of a colocation contract, Customer must also complete Atlantic.Net Security Form prior to the issuance of security badges. The Security Form contains information on which Customer employees or Customer vendor employees are authorized by the Customer to enter an Atlantic.Net facility on the Customer’s behalf. It is the Customer’s responsibility to keep the Security Form updated at all times by contacting Atlantic.Net’s Network Operations Center at 866-618-3282 with any changes. The standard number of security badges issued will be in accordance with the number of cabinets or amount of Space licensed by Customer. Upon the first visit to every facility, Customer authorized personnel are required to contact Atlantic.Net personnel to go through the identification and badge issuance process. All persons accessing the facility will be required to show a valid driver’s license or other government-issued form of picture identification. Once Customer’s identification is confirmed, Atlantic.Net personnel will build the Customer into the palm scanner system. Once this process is completed, Customer will have access to its Space and shared areas of the colocation facility without further need of assistance from Atlantic.Net personnel. Customer must have a minimum of one cabinet or cage space to obtain access or security badges or 24/7 unescorted access to the facility. #### Additional and replacement security badges If a badge is lost or stolen, Customer must contact Atlantic.Net Network Operations Center at 866-618-3282 immediately. A completed Security Card Form is required to order additional or replacement security badges and must be submitted to Atlantic.Net Network Operations Center by fax at 407-660-8094 for proper authentication and processing. Customer’s identification number and password will be required when requesting additional security badges due to possible additional charges. Customers will be assessed a replacement fee for any lost badges at the then applicable rate. #### Customer Sponsored Visitors Facility tours must be scheduled at least 48 hours in advance by contacting your Sales Representative. Please allow 1 business day for confirmation of tour approval. Atlantic.Net at its sole discretion may apply tour charges. Customer will be informed at the time of confirmation if Customer will incur a charge for the tour. All tours must be canceled 24 hours in advance or tour charges may apply. All visitors entering the colocation facility will be required to sign in on the visitor roster, present a valid driver’s license or other government-issued form of picture identification, and sign a Nondisclosure Agreement. Customers are required to escort their sponsored visitors in the facility at all times, including entering and exiting the facility. #### Escalation Procedures The following escalation procedure has been established to ensure a timely response to Customer’s critical needs and is triggered upon Customer’s call to Atlantic.Net Network Operations Center at 866-618-3282 | **Level** | **Interval** | **Title** | **Phone** | | --- | --- | --- | --- | | 1st Level | 0-2 Hours | Network Operations Center | 866-618-3282 | | 2nd Level | 2+ Hours | Senior Network Operations Engineer | 866-618-3282 | #### Power Power provided will be based solely on accepted equipment configurations as set forth on any applicable executed colocation contract. Atlantic.Net cannot guarantee additional power for equipment reconfigurations or upgrades. Atlantic.Net may provide redundant A and B feeds for DC power. Atlantic.Net may, with 24 hours notice; temporarily remove from service any individual DC power feed for maintenance of the power infrastructure. Customer may not use a redundant power feed as an individual power feed. All individual power runs are to be installed and maintained by Atlantic.Net. Customers may not install any batteries in the colocation facility. Customer must inform Atlantic.Net immediately upon discovery of any worn, frayed or cut cables by contacting our Atlantic.Net Network Operations Center at 866-618-3282. To ensure the safety of the Atlantic.Net facility, each cabinet installed in the Space may have a circuit maximum of 60 Amps AC (7,200 watts) or 60 Amps DC power. Each rack may have a circuit maximum of 100 Amps AC (12,000 watts) or 120 Amps DC power. All equipment utilized in an Atlantic.Net facility must meet Underwriter Laboratory (UL) listing or a similarly recognized governing board. No soldering or open flames are allowed. Customers may not plug any equipment into receptacles or courtesy power outlets without the express written permission of Atlantic.Net. No equipment specifically designed to emit Radio Frequency (RF) energy is permitted to be installed in the Customer Space or to be operated within the Atlantic.Net facility without express written consent of an authorized Atlantic.Net representative. No device that is specifically designed to emit an electrical control signal on either AC or DC power lines is permitted to be installed in the Customer Space or to be operated within the Atlantic.Net facility without the express written consent of an authorized Atlantic.Net representative. #### Use of Colocation Facilities, Building and Customer Space Customer shall maintain its Space in an orderly and clean manner and in good repair and condition, satisfactory to Atlantic.Net. Customer shall keep the Space free of litter, cartons, packing materials or packaging, and related items (collectively “waste materials”). Customer shall deposit all waste materials in designated trash receptacles that may be located in the colocation facility or within or outside of the building. Under no circumstances shall waste materials be discarded or left in the colocation facility or the building. Customer shall deposit all non-hazardous waste in appropriate receptacles located outside the building. Atlantic.Net does not provide and is not responsible for providing receptacles for Customer waste materials. Customer shall ensure that their Space is in compliance with all Federal and State Occupational Safety and Health Organization (OSHA) standards. Customer will be responsible for all damage that may be caused by failure to comply with any OSHA standards within the space and under the customer’s control. Customer shall not eat, drink, or smoke within the colocation facility or the building, except in areas designated by Atlantic.Net or the building management. Customers shall not bring any weapons, including guns, knives or mace, alcohol; or drugs within the colocation facility or the building. Customer shall not photograph, videotape, or film any areas in the colocation facility or the entrances to the colocation facility. Customer, its officers, employees, technicians, agents, representatives, subcontractors, and visitors shall behave in a courteous and professional manner at all times while in an Atlantic.Net colocation facility or the building in which the colocation facility is located. Customer, its officers, employees, technicians, agents, representatives, subcontractors, and visitors shall not touch, access, tamper, or interfere with another customer’s or Atlantic.Net’s Space or equipment without such customer’s written authorization, even if Customer owns equipment within another customer’s Space. Customer, its officers, employees, technicians, agents, representatives, subcontractors, and visitors shall not loiter or solicit within the colocation facility, the building in which the colocation facility is located, or on the grounds that the colocation facility is located. Customer shall not do or permit anything to be done, or fail to do or permit anything to be done in, on, or about the building that might constitute or result in a private or public nuisance or waste. Customer shall not make any alterations, additions, or improvements to the Space without the prior written consent of Atlantic.Net, which shall be in Atlantic.Net’s sole discretion. Customer shall not, nor shall Customer permit others to: (i) fail to maintain a suitable environment as specified by Atlantic.Net; (ii) alter, tamper with, adjust or repair any equipment or property of Atlantic.Net or any other property (other than its own equipment inside Customer’s Space) located within the colocation facility or the building; or (iii) abuse or fraudulently access the building or the colocation facility to obtain or attempt to obtain service by any means or device with intent to avoid payment, unauthorized access, alteration or destruction, or any attempt thereof, of any information of Atlantic.Net or any other customer of Atlantic.Net by means of devise, use of any equipment in violation of the law or in aid of any unlawful act, use any equipment so as to interfere with the use of the Telecommunications Network operated by Atlantic.Net or customers or authorized users or in a manner which, in the opinion of Atlantic.Net is not in accordance with its generally accepted standards of Telecommunications access and use. Customer shall wear slip-resistant shoes while on the data center floor and inform Atlantic.Net technicians immediately of any unsafe facility conditions of which the Customer is aware (e.g., loose ladder racks, slick floors or electrical issues). Each Customer cage and cabinet in Atlantic.Net facilities are designed to provide colocation to an individual customer and Atlantic.Net does not allow more than one customer per customer cage or customer cabinet in any Atlantic.Net facility. Customer agrees to safely configure, operate, and maintain equipment in Customer’s Space. This includes appropriate engineering and design of equipment systems in adherence to manufacturer specifications. Failure to comply with these safety measures can result in an order to remedy or shut down unsafe equipment. Cubicle workstations may be utilized on a first come first serve basis and must be vacated and cleaned daily. Customer may not leave equipment in the work area without a Customer technician present. #### Conference Rooms A conference room is available in most Atlantic.Net facilities. Customers can reserve conference rooms for periods of 2 to 4 hours by calling Atlantic.Net Network Operations Center at 866-618-3282. Customers will be charged a minimum of two hours and additional hours in one hour increments. Cancellation charges shall apply if rooms are not canceled 24 hours prior to the scheduled time. #### Order Processing and Invoicing Upon order acceptance and approval, Atlantic.Net will (i) issue a letter acknowledging the order and inform Customer of the Target Installation Completion (“TIC”) date. The TIC date indicates when the customer space and services are customer ready”. The TIC date also represents the date that monthly recurring billing will begin, regardless of whether Customer actually occupies the Space. Activation fees are due immediately in order to initiate the installation process. Orders may have more than one TIC date for Space and power. Atlantic.Net deployment team may engage Customer during the installation planning stage at which time mutual tasks, responsibilities, and timeframes will be identified and committed with regard to the TIC date. Cross-connects will be billed when installed by Atlantic.Net. Atlantic.Net will not be responsible for delays of the TIC date caused by Customer. Customer can request one-time services such as remote hands, conference rooms, etc., by calling Atlantic.Net Network Operations Center at 866-618-3282. Once a month, Atlantic.Net will invoice the customer for all fees associated with service requests performed during the prior month. Any consultive work to be performed by Atlantic.Net must be paid for by credit card before work commences. #### Change Orders Changes to an executed Colocation Contract must be made in writing using the appropriate Change Order Form and submitted to Atlantic.Net. Any changes made to the initial Order Form may cause serious delays and change fees will apply. Installation fees associated with a Change Order are due and payable when the Change Order is submitted to Atlantic.Net. #### Confidentiality Atlantic.Net maintains the confidentiality of Customer’s identity within the colocation facility, including, but not limited to, the location of Customer’s equipment. Customer may not post any signage in the Atlantic.Net facilities, including Customer cages or cabinets. Customer may, at its discretion, and provided Customer completes the required documentation, have its name displayed on Atlantic.Net standard customer signage. [Orlando Colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/). --- # Atlantic.Net Dedicated Server Service Level Guarantee > URL: https://www.atlantic.net/dedicated-server-service-level-guarantee/ | Updated: 2026-09-16 Atlantic.Net offers an Industry Leading Dedicated Server Service Level Guarantee. ## Atlantic.Net offers an Industry Leading Dedicated Server Service Level Guarantee. ### Network Uptime – 100% Guaranteed Atlantic.Net offers an Industry Leading Dedicated Server Service Level Guarantee. Atlantic.Net guarantees that the network will be available 100% of the time in a given month excluding scheduled maintenance. If it takes us more than 30 minutes to resolve the network issue from the time the trouble ticket is opened, Atlantic.Net will refund the customer 5% of the monthly fee for each additional 30 minutes of downtime (up to 100% of customer’s monthly fee for the specific equipment affected). Network uptime includes the functioning of all network infrastructure such as routers, switches, and cabling, but does not include software and services running on your server. Network downtime exists when your server is unable to transmit and receive data and Atlantic.Net records such failure in the Atlantic.Net trouble ticket system. Network Downtime is measured from the time a trouble ticket is opened. ### Hardware – 100% Guaranteed Atlantic.Net guarantees all hardware components in your server and will replace any failed components at no cost to you. Once Atlantic.Net determines the cause of the problem, hardware replacement will commence. If it takes us more than one hour to replace the faulty hardware from the time the cause is determined, Atlantic.Net will refund 5% of the monthly fee per additional hour of downtime (up to 100% of your monthly fee for the specific server affected). Excludes reloading operating systems, applications, and rebuilding RAID arrays. If Customer blocks or otherwise prevents Atlantic.Net’s hardware monitoring systems from monitoring the Customer’s affected server, Customer will not be eligible for a hardware-related SLA refund. ### Infrastructure – 100% Guaranteed Atlantic.Net guarantees that all critical infrastructure components including power supplied to your server and HVAC, will be available 100% for the time in a given month excluding scheduled maintenance. If it takes us more than 30 minutes to resolve the infrastructure issue from the time the trouble ticket is opened, Atlantic.Net will refund 5% of the monthly fee per additional 30 minutes of downtime (up to 100% of your monthly fee for the specific server affected). Critical infrastructure includes the functioning of all power, HVAC, and cabling but does not include the power supplies on customers’ servers. Infrastructure downtime exists when your server is shut down due to power or cooling issues and is measured from the time a trouble ticket is opened. --- # Atlantic.Net Domain Registration Agreement > URL: https://www.atlantic.net/domain-registration-agreement/ | Updated: 2026-09-16 **1.**In this Registration Agreement (“Agreement”) “Registrant”, “you” and “your” refers to the registrant of each domain name registration, “we”, “us” and “our” refer to Tucows.com Co., and “Services” refers to the domain name registration services provided by us as offered through _____________________________________, the Registration Service Provider (“Reseller”). Any reference to a “registry,” “Registry” or “Registry Operator” shall refer to the registry administrator of the applicable TLD or ccTLD. This Agreement explains our obligations to you and explains your obligations to us for the Services. By agreeing to the terms and conditions set forth in this Agreement, you are also agreeing to be bound by the rules and regulations set forth by a registry for that particular registry only. **2. SELECTION OF A DOMAIN NAME.**You acknowledge and agree that we cannot guarantee that you will obtain a desired domain name registration, even if an inquiry indicates that a domain name is available at the time of your application for same. You represent that, to the best of your knowledge and belief, neither the registration of the domain name nor the manner in which it is directly or indirectly to be used, infringes upon the legal rights of a third party and further, that the domain name is not being registered for nor shall it at any time whatsoever be used for any unlawful purpose. **3. FEES.**As consideration for the Services, you agree to pay Reseller the applicable service(s) fees prior to the effectiveness of a desired domain name registration or any renewal thereof. All fees payable hereunder are non-refundable even if your domain name registration is suspended, canceled, or transferred prior to the end of your current registration term. As further consideration for the Services, you agree to: (1) provide certain current, complete and accurate information about you as required by the registration process, and (2) maintain and update this information as needed to keep it current, complete, and accurate. All such information shall be referred to as account information (“Account Information”). You represent that the Account Information and all other statements put forth in your application are true, complete, and accurate. Both Tucows and each registry reserves the right to terminate your domain name registration if: (i) information provided by you or your agent is false, inaccurate, incomplete, unreliable, misleading or otherwise secretive; or (ii) you have failed to maintain, update and keep your Account Information true, current, complete, accurate and reliable. You acknowledge that a breach of this Section 3 will constitute a material breach of our Agreement which will entitle either us or a registry to terminate this Agreement immediately upon such breach without any refund and without notice to you. **4. TERM.**This Agreement will remain in effect during the term of your domain name registration as selected, recorded, and paid for at the time of registration or any renewal thereof. Should the domain name be transferred to another registrar, the terms and conditions of this Agreement shall cease. **5. MODIFICATIONS TO AGREEMENT.**You acknowledge that the practice of registering and administering domain names is constantly evolving; therefore, you agree that Tucows may modify this Agreement, or any other related and/or applicable agreement, as is necessary to comply with its agreements with ICANN, a registry or any other entity or individual, as well as to adjust to changing circumstances. Your continued use of the domain name registered to you will constitute your acceptance of this Agreement with any revisions. If you do not agree to any change, you may request that your domain name registration be canceled or transferred to a different accredited registrar. You agree that such cancellation or request for transfer will be your exclusive remedy if you do not wish to abide by any change to this Agreement, or any other related and/or applicable agreement. **6. MODIFICATIONS TO YOUR ACCOUNT.**In order to change any of your account information with us, you must use the Account Identifier and Password that you selected when you opened your account with us. You agree to safeguard your Account Identifier and Password from any unauthorized use. In no event shall we be liable for the unauthorized use or misuse of your Account Identifier or Password. **7. NO GUARANTY.**You acknowledge that registration or reservation of your chosen domain name does not confer immunity from objection to the registration, reservation, or use of the domain name. **8. DOMAIN NAME DISPUTES.**You agree that, if the registration or reservation of your domain name is challenged by a third party, you will be subject to the provisions specified in the dispute policy adopted by the applicable registry. You agree that in the event a domain name dispute arises with any third party, you will indemnify and hold us harmless pursuant to the terms and conditions contained in the applicable policy. If Tucows is notified that a complaint has been filed with a judicial or administrative body regarding your domain name, Tucows may, at its sole discretion, suspend your ability to use your domain name or to make modifications to your registration records until (i) Tucows is directed to do so by the judicial or administrative body, or (ii) Tucows receives notification by you and the other party contesting your domain that the dispute has been settled. Furthermore, you agree that if you are subject to litigation regarding your registration or use of your domain name, Tucows may deposit control of your registration record into the registry of the judicial body by supplying a party with a registrar certificate from us. **9. POLICY.**You agree that your registration of the domain name shall be subject to suspension, cancellation, or transfer pursuant to a Tucows, registry, ICANN or government-adopted policy, or pursuant to any registrar or registry procedure not inconsistent with a Tucows, registry, ICANN or government-adopted policy, (1) to correct mistakes by us or a registry in registering the name or (2) for the resolution of disputes concerning the domain name. **10. AGENCY.**Should you intend to license the use of a domain name to a third party you shall nonetheless be the domain name holder of record and are therefore responsible for providing your own full contact information and for providing and updating accurate technical and administrative contact information adequate to facilitate timely resolution of any problems that arise in connection with the domain name. You shall accept liability for harm caused by wrongful use of the domain name. You represent that you will secure the agreement of any third party to the terms and conditions in this Agreement **11. ANNOUNCEMENTS.**We reserve the right to distribute information to you that is pertinent to the quality or operation of our services and those of our service partners. These announcements will be predominately informative in nature and may include notices describing changes, upgrades, new products or other information to add security or to enhance your identity on the Internet. **12. LIMITATION OF LIABILITY.**You agree that our entire liability, and your exclusive remedy, with respect to any Services(s) provided under this Agreement and any breach of this Agreement is solely limited to the amount you paid for the initial registration of your domain name. Tucows and its directors, employees, affiliates, subsidiaries, agents and third-party providers, ICANN, and the applicable registries shall not be liable for any direct, indirect, incidental, special, or consequential damages resulting from the use or inability to use any of the Services or for the cost of procurement of substitute services. Because some states do not allow the exclusion or limitation of liability for consequential or incidental damages, in such states, our liability is limited to the extent permitted by law. We disclaim any and all loss or liability resulting from, but not limited to: (1) loss or liability resulting from access delays or access interruptions; (2) loss or liability resulting from data non-delivery or data mis-delivery; (3) loss or liability resulting from acts of God; (4) loss or liability resulting from the unauthorized use or misuse of your account identifier or password; (5) loss or liability resulting from errors, omissions, or misstatements in any and all information or services(s) provided under this Agreement; (6) loss or liability resulting from the interruption of your Service. You agree that we will not be liable for any loss of registration and use of your domain name, or for interruption of business, or any indirect, special, incidental, or consequential damages of any kind (including lost profits) regardless of the form of action whether in contract, tort (including negligence), or otherwise, even if we have been advised of the possibility of such damages. **13. INDEMNITY.**You agree to release, indemnify, and hold Tucows, its contractors, agents, employees, officers, directors and affiliates, ICANN, the applicable registries, and their respective directors, officers, employees, agents, and affiliates harmless from all liabilities, claims, and expenses, including attorney’s fees, of third parties arising out of or relating to the registration or use of the domain name registered in your name including without limitation infringement by you or a third party with access to your Account Identifier and Password. You also agree to release, indemnify and hold us harmless pursuant to the terms and conditions contained in the applicable Dispute Policy. When we are threatened with suit by a third party, we may seek written assurances from you concerning your promise to indemnify us; your failure to provide those assurances may be considered by us to be a breach of your Agreement and may result in the suspension or cancellation of your domain name. This indemnification obligation will survive the termination or expiration of this Agreement. **14. TRANSFER OF OWNERSHIP.**The person named as registrant on the WHOIS shall be the registered name holder. The person named as administrative contact at the time the controlling Account Identifier and Password are secured shall be deemed the designate of the registrant with the authority to manage the domain name. You agree that prior to transferring ownership of your domain name to another person (the “Transferee”) you shall require the Transferee to agree, in writing to be bound by all the terms and conditions of this Agreement. If the Transferee fails to be bound in a reasonable fashion (as determine by us in our sole discretion) to the terms and conditions in this Agreement, any such transfer will be null and void. **15. BREACH.**You agree that failure to abide by any provision of this Agreement, any operating rule or policy, or the Dispute Policy provided by us, may be considered by us to be a material breach and that we may provide a written notice, describing the breach, to you. If within thirty (30) calendar days of the date of such notice, you fail to provide evidence, which is reasonably satisfactory to us, that you have not breached your obligations under the Agreement, then we may delete the registration or reservation of your domain name. Any such breach by you shall not be deemed to be excused simply because we did not act earlier in response to that, or any other breach by you. **16. DISCLAIMER OF WARRANTIES.**You agree that your use of our Services is solely at your own risk. You agree that such Service(s) is provided on an “as is,” “as available” basis. We expressly disclaim all warranties of any kind, whether express or implied, including but not limited to the implied warranties of merchantability, fitness for a particular purpose, and non-infringement. We make no warranty that the Services will meet your requirements, or that the Service(s) will be uninterrupted, timely, secure, or error-free; nor do we make any warranty as to the results that may be obtained from the use of the Service(s) or as to the accuracy or reliability of any information obtained through the Service or that defects in the Service will be corrected. You understand and agree that any material and/or data downloaded or otherwise obtained through the use of Service is done at your own discretion and risk and that you will be solely responsible for any damage to your computer system or loss of data that results from the download of such material and/or data. We make no warranty regarding any goods or services purchased or obtained through the Service or any transactions entered into through the Service. No advice or information, whether oral or written, obtained by you from us or through the Service shall create any warranty not expressly made herein. **17. INFORMATION.**As part of the registration process, you are required to provide us certain information and to update us promptly as such information changes such that our records are current, complete, and accurate. You are obliged to provide us the following information: (a) your name and postal address (or, if different, that of the domain name holder); (b) the domain name being registered; (c) the name, postal address, e-mail address, and voice and fax (if available) telephone numbers of the administrative contact for the domain name; (d) the name, postal address, e-mail address, and voice and fax (if available) telephone numbers of the billing contact for the domain name; and (e) the name, postal address, e-mail address, and voice and fax (if available) telephone numbers of the technical contact for the domain name. Any voluntary information we request is collected in order that we can continue to improve the products and services offered to you through your Reseller. **18. DISCLOSURE AND USE OF REGISTRATION INFORMATION.**You agree and acknowledge that we will make the domain name registration information you provide available to ICANN, to the registry administrators, law enforcement agencies, and to other third parties as applicable. You further agree and acknowledge that we may make publicly available, or directly available to third-party vendors, some or all, of the domain name registration information you provide, for purposes of inspection (such as through our WHOIS service) or other purposes as required or permitted by ICANN and applicable laws. (a) You hereby consent to any and all such disclosures and use of, and guidelines, limits and restrictions on disclosure or use of, the information provided by you in connection with the registration of a domain name (including any updates to such information), whether during or after the term of your registration of the domain name. You hereby irrevocably waive any and all claims and causes of action you may have arising from such disclosure or use of your domain name registration information by us. (b) You may access your domain name registration information in our possession to review, modify or update such information, by accessing our domain manager service, or similar service, made available by us through your Reseller. (c) We will not process or maintain data about any identified or identifiable natural person that we obtain from you in a way incompatible with the purposes and other limitations which we describe in this Agreement. (d) We will take reasonable precautions to protect the information we obtain from you from our loss, misuse, unauthorized disclosure, alteration, or destruction of that information. **19. OBLIGATION TO MAINTAIN WHOIS.**Your willful provision of inaccurate or unreliable information, your wilful failure promptly to update the information provided to us, or any failure to respond to inquiries by us addressed to the email address of the registrant, the administrative, billing or technical contact appearing in the WHOIS directory with respect to a domain name concerning the accuracy of contact details associated with the registration shall constitute a material breach of this Agreement and be a basis for cancellation of the domain name registration. Any information collected by us concerning an identified or identifiable natural person (“Personal Data”) will be used in connection with the registration of your domain name(s) and for the purposes of this Agreement and as required or permitted by ICANN or an applicable registry policy. **20. REVOCATION.**We, in our sole discretion, reserve the right to deny, cancel, suspend, transfer or modify any domain name registration to correct a mistake, protect the integrity and stability of the company and any applicable registry, to comply with any applicable laws, government rules, or requirements, requests of law enforcement, in compliance with any dispute resolution process, or to avoid any liability, civil or criminal. You agree that we shall not be liable to you for loss or damages that may result from our refusal to register or cancel, suspend, transfer or modify your domain name registration. **21. INCONSISTENCIES WITH REGISTRY POLICIES.**In the event that this Agreement may be inconsistent with any term, condition, policy, or procedure of an applicable registry, the term, condition, policy, or procedure of the applicable registry shall prevail. **22. NON-WAIVER.**Our failure to require performance by you of any provision hereof shall not affect the full right to require such performance at any time thereafter; nor shall the waiver by us of a breach of any provision hereof be taken or held to be a waiver of the provision itself. **23. NOTICES.**Any notice, direction, or other communication given under this Agreement shall be in writing and given by sending it via e-mail or via regular mail. In the case of e-mail, valid notice shall only have been deemed to be given when an electronic confirmation of delivery has been obtained by the sender. E-mail notification to Tucows must be sent to [lhutz@tucows.com](mailto:lhutz@tucows.com). Any notice to you will be sent to the e-mail address provided by you in your WHOIS record. Any e-mail communication shall be deemed to have been validly and effectively given on the date of such communication, if such date is a business day and such delivery was made prior to 4:00 p.m. EST, otherwise it will be deemed to have been delivered on the next business day. In the case of regular mail notice, valid notice shall be deemed to have been validly and effectively given five (5) business days after the date of mailing Postal notices to Tucows shall be sent to: TUCOWS Inc. Registrant Affairs Office 96 Mowat Avenue Toronto, Ontario M6K 3M1 CANADA Attention: Legal Affairs and in the case of notification to you shall be sent to the address specified in the “Administrative Contact” in your WHOIS record. **24. ENTIRETY.**You agree that this Agreement, the applicable dispute policy, and the rules and policies published by Tucows and any applicable registry or other governing authority are the complete and exclusive agreement between you and us regarding our Services. **25. GOVERNING LAW.**THIS AGREEMENT SHALL BE GOVERNED BY AND INTERPRETED AND ENFORCED IN ACCORDANCE WITH THE LAWS OF PROVINCE OF ONTARIO AND THE FEDERAL LAWS OF CANADA APPLICABLE THEREIN WITHOUT REFERENCE TO RULES GOVERNING CHOICE OF LAWS. ANY ACTION RELATING TO THIS AGREEMENT MUST BE BROUGHT IN ONTARIO AND YOU IRREVOCABLY CONSENT TO THE JURISDICTION OF SUCH COURTS. **26. INFANCY.**You attest that you are of legal age to enter into this Agreement. **27. FORCE MAJEURE.**You acknowledge and agree that neither we nor the applicable registry shall be responsible for any failures or delays in performing our respective obligations hereunder arising from any cause beyond our reasonable control, including but not limited to, acts of God, acts of civil or military authority, fires, wars, riots, earthquakes, storms, typhoons, and floods. **28. PRIVACY.**Information collected about you is subject to the terms of Tucows’ privacy policy, the terms of which are hereby incorporated by reference. Tucows’ privacy policy can be found at:[privacy policy](http://www.opensrs.com/privacy/) **29. CONTROLLING LANGUAGE.**In the event that you are reading this Agreement in a language other than the English language, you acknowledge and agree that the English language version hereof shall prevail in case of inconsistency or contradiction in interpretation or translation. **30. TLD’S.**The following additional provisions apply to any domain names that you register through Tucows with the various registries: (a) **.com/net domains:** In the case of a “.com” or “.net” registration, the following terms and conditions will apply: (i) Submission to UDRP. Registrant agrees to submit to proceedings under ICANN’s Uniform Domain Dispute Policy (“UDRP”) ( [http://www.icann.org/dndr/udrp/policy.htm](http://www.icann.org/dndr/udrp/policy.htm)) and comply with the requirements set forth by the Registry; these policies are subject to modification. (b) **.org domains:** In the case of a “.org” registration, the following terms and conditions will apply: (i) Submission to UDRP. Registrant agrees to submit to proceedings under ICANN’s Uniform Domain Dispute Policy (“UDRP”) ([http://www.icann.org/dndr/udrp/policy.htm](http://www.icann.org/dndr/udrp/policy.htm)) and comply with the requirements set forth by the Registry. These policies are subject to modification. (c) **.info domains:** In the case of a “.info” registration, the following terms and conditions will apply: (i) Registrant’s Personal Data. You consent to the use, copying, distribution, publication, modification, and other processing of Registrant’s personal data by Afilias, the.INFO registry, and its designees and agents, in a manner consistent with the purposes specified pursuant to its contract. (ii) Submission to UDRP. Registrant agrees to submit to proceedings under ICANN’s Uniform Domain Dispute Policy (“UDRP”) ( [http://www.icann.org/dndr/udrp/policy.htm](http://www.icann.org/dndr/udrp/policy.htm)) and comply with the requirements set forth by the Registry. These policies are subject to modification. (iii) Reservation of Rights. Tucows and Afilias expressly reserve the right to deny, cancel, transfer, or modify any registration that either registrar or Afilias deems necessary, at its discretion, to protect the integrity and stability of the registry, to comply with any applicable law, any government rule or requirement, any request of law enforcement, any dispute resolution process, or to avoid any liability, civil or criminal, on the part of the registrar and/or Afilias, as well as their affiliates, subsidiaries, executives, directors, officers, managers, employees, consultants, and agents. The registrar and Afilias also reserve the right to suspend a domain name or its registration data during resolution of a dispute. (d) **.biz domains.**In the case of a “.biz” registration, the following terms and conditions will apply: (i) .biz Restrictions. Registrations in the .biz top-level domain must be used or intended to be used primarily for bona fide business or commercial purposes. For the purposes of the .biz registration restrictions, “bona fide business or commercial use” shall mean the bona fide use or bona fide intent to use the domain name or any content, software, materials, graphics or other information thereon, to permit Internet users to access one or more host computers through the DNS: (A) to exchange goods, services, or property of any kind; (B) in the ordinary course of business; or (C) to facilitate (i) the exchange of goods, services, information or property of any kind; or (ii) the ordinary course of trade or business. For more information on the .biz restrictions, which are incorporated herein by reference, please see: [http://www.icann.org/tlds/agreements/biz/registry-agmt-appl-18apr01.htm](http://www.icann.org/tlds/agreements/biz/registry-agmt-appl-18apr01.htm). (ii) Selection of a Domain Name. You represent that: (A) the data provided in the domain name registration application is true, correct, up to date and complete, and that you will continue to keep all of the information provided correct, up-to-date and complete; (B) to the best of the your knowledge and belief, neither this registration of a domain name nor the manner in which it is directly or indirectly to be used infringes upon the legal rights of a third party; (C) that the domain name is not being registered for nor shall it at any time whatsoever be used for any unlawful purpose whatsoever; (D) the registered domain name will be used primarily for bona fide business or commercial purposes and not (a) exclusively for personal use, or (b) solely for the purposes of (1) selling, trading or leasing the domain name for compensation, or (2) the unsolicited offering to sell, trade or lease the domain name for compensation; (E) you have the authority to enter into this Registration Agreement; and (F) the registered domain name is reasonably related to your business or intended commercial purpose at the time of registration. (iii) Provision of Registration Data. As part of the registration process, you are required to provide us with certain information and to keep the information true, current, complete, and accurate at all times. The information includes the following: (A) your full name; (B) your postal address; (C) your e-mail address; (D) your voice telephone number; (E) your fax number (if applicable); (F) the name of an authorized person for contact purposes in the case of a registrant that is an organization, association, or corporation; (G) the IP addresses of the primary nameserver and any secondary nameserver for the domain name; (H) the corresponding names of the primary and secondary nameservers; (I) the full name, postal address, e-mail address, voice telephone number, and, when available, fax number of the administrative, technical, and billing contacts, and the name holder for the domain name; and (J) any remark concerning the domain name that should appear in the WHOIS directory. (K) You agree and understand that the foregoing registration data will be publicly available and accessible on the WHOIS directory as required by ICANN and/or registry policies, and may be sold in bulk in accordance with the ICANN agreement. (iv) Domain Name Disputes. You acknowledge having read and understood and agree to be bound by the terms and conditions of the following documents, as they may be amended from time to time, which are hereby incorporated and made an integral part of this Agreement: (A) The Uniform Domain Name Dispute Resolution Policy (“Dispute Policy), available at:[http://www.icann.org/dndr/udrp/policy.htm](http://www.icann.org/dndr/udrp/policy.htm); (B) The Restrictions Dispute Resolution Criteria and Rules (“RDRP”), available at:[http://www.icann.org/tlds/agreements/biz/registry-agmt-appm-27apr01.htm](http://www.icann.org/tlds/agreements/biz/registry-agmt-appm-27apr01.htm); (collectively, the “Dispute Policies”). (v) The Dispute Policy sets forth the terms and conditions in connection with a dispute between a Registrant and any party other than the Registry or Registrar over the registration and use of an Internet domain name registered by Registrant. (vi) The RDRP sets forth the terms under which any allegation that a domain name is not used primarily for business or commercial purposes shall be endorsed on a case-by-case, fact specific basis by an independent ICANN-accredited dispute provider. (e) **.name domains.**In the case of a “.name” registration, the following terms and conditions will apply: (i) .name Restrictions. Registrations in the .name top-level domain must constitute an individual’s “Personal Name”. For purposes of the .name restrictions (the “Restrictions”), a “Personal Name” is a person’s legal name, or a name by which the person is commonly known. A “name by which a person is commonly known” includes, without limitation, a pseudonym used by an author or painter, or a stage name used by a singer or actor. (ii) .name Representations. As a .name domain name registrant, you hereby represent that: (A) the registered domain name or second level domain (“SLD”) e-mail address is your Personal Name. (B) the data provided in the domain name registration application is true, correct, up to date and complete and that you will continue to keep all of the information provided correct, current and complete, (C) to the best of the your knowledge and belief, neither this registration of a domain name nor the manner in which it is directly or indirectly to be used infringes upon the legal rights of a third party; (D) that the domain name is not being registered for nor shall it at any time whatsoever be used for any unlawful purpose whatsoever; (E) the registration satisfies the Eligibility Requirements found at:[http://www.icann.org/tlds/agreements/name/registry-agmt-appl-8aug03.htm](http://www.icann.org/tlds/agreements/name/registry-agmt-appl-8aug03.htm); and (F) you have the authority to enter into this Registration Agreement. (iii) E-mail Forwarding Services. The Services for which you have registered may, at your option, include e-mail forwarding. To the extent you opt to use e-mail forwarding, you are obliged to do so in accordance with all applicable legislation and are responsible for all use of e-mail forwarding, including the content of messages sent through e-mail forwarding. You undertake to familiarize yourself with the content of and to comply with the generally accepted rules for Internet and e-mail usage. This includes, but is not limited to the Acceptable Use Policy, available at[aup pdf](http://www.nic.name/downloads/aup.pdf)as well as the following restrictions. Without prejudice to the foregoing, you undertake not to use e-mail forwarding: (A) to encourage, allow or participate in any form of illegal or unsuitable activity, including but not restricted to the exchange of threatening, obscene or offensive messages, spreading computer viruses, breach of copyright and/or proprietary rights or publishing defamatory material; (B) to gain illegal access to systems or networks by unauthorized access to or use of the data in systems or networks, including all attempts at guessing passwords, checking or testing the vulnerability of a system or network or breaching the security or access control without the sufficient approval of the owner of the system or network; (C) to interrupt data traffic to other users, servers or networks, including, but not restricted to, mail bombing, flooding, Denial of Service (DoS) attacks, wilful attempts to overload another system or other forms of harassment; or (D) for spamming, which includes, but is not restricted to, the mass mailing of unsolicited e-mail, junk mail, the use of distribution lists (mailing lists) which include persons who have not specifically given their consent to be placed on such distribution list. Users are not permitted to provide false names or in any other way to pose as somebody else when using e-mail forwarding. (iv) Registry reserves the right to implement additional anti-spam measures, to block spam or mail from systems with a history of abuse from entering Registry’s e-mail forwarding. However, due to the nature of such systems, which actively block messages, Registry shall make public any decision to implement such systems a reasonable time in advance, so as to allow you or us to give feedback on the decision. (v) You understand and agree that Registry may delete material that does not conform to clause (c) above or that in some other way constitutes a misuse of e-mail forwarding. You further understand and agree that Registry is at liberty to block your access to e-mail forwarding if you use e-mail forwarding in a way that contravenes this Agreement. You will be given prior warning of discontinuation of the e-mail forwarding unless it would damage the reputation of Registry or jeopardize the security of Registry or others to do so. Registry reserves the right to immediately discontinue e-mail forwarding without notice if the technical stability of e-mail forwarding is threatened in any way, or if you are in breach of this Agreement. On discontinuing e-mail forwarding, Registry is not obliged to store any contents or to forward unsent e-mail to you or a third party. (vi) You understand and agree that to the extent either we and/or Registry is required by law to disclose certain information or material in connection with your e-mail forwarding, either we and/or Registry will do so in accordance with such requirement and without notice to you. (vii) Domain Name Dispute Policy. If you reserved or registered a domain name through us, or transferred a domain name to us from another registrar, you agree to be bound by the dispute policy that is incorporated herein and made a part of this Agreement by reference. The current version of the Dispute Policy may be found at [the Dispute Policy](http://www.tucowsdomains.com/topic/disputes-and-complaints/). Please take the time to familiarize yourself with this policy. In addition, you hereby acknowledge that you have read and understood and agree to be bound by the terms and conditions of the following documents, as they may be amended from time to time, which are hereby incorporated and made an integral part of this Agreement. (A) the Eligibility Requirements (the “Eligibility Requirements”), available at:[http://www.icann.org/tlds/agreements/name/registry-agmt-appl-8aug03.htm](http://www.icann.org/tlds/agreements/name/registry-agmt-appl-8aug03.htm); (B) the Eligibility Requirements Dispute Resolution Policy (the “ERDRP”), available at: [ccpit patent](http://www.ccpit-patent.com.cn/node/1231/1232) ; and (C) the Uniform Domain Name Dispute Resolution Policy (the “UDRP”), available at:[http://www.icann.org/dndr/udrp/policy.htm](http://www.icann.org/dndr/udrp/policy.htm). (viii) The Eligibility Requirements dictate that Personal Name domain names and Personal Name SLD e-mail addresses will be granted on a first-come, first-served basis. The following categories of Personal Name Registrations may be registered: (i) the Personal Name of an individual; (ii) the Personal Name of a fictional character, if you have trademark or service make rights in that character’s Personal Name; (iii) in addition to a Personal Name registration, you may add numeric characters to the beginning or the end of the Personal Name so as to differentiate it from other Personal Names. (ix) The ERDRP applies to challenges to (i) registered domain names and SLD e-mail address registrations within .name on the grounds that a Registrant does not meet the Eligibility Requirements, and (ii) to Defensive Registrations (as defined by the Registry) within .name. (x) The UDRP sets forth the terms and conditions in connection with a dispute between a Registrant and party other than the Registry or Tucows over the registration and use of an Internet domain name registered by a Registrant. **31. ccTLD’S** (a) **.ca domains.**In the case of a “.ca” registration, the following terms and conditions will apply: (i) Domain Name Dispute Policy. If you reserved or registered a domain name through us, or transferred a domain name to us from another registrar, you agree to be bound by the Dispute Policy, which is incorporated herein and made a part of this Agreement by reference. The current version of the Dispute Policy may be found at[CIRA](http://www.cira.ca/cdrp/). Please take the time to familiarize yourself with this policy. (ii) Registry Policy. You agree that your registration of the domain name shall be subject to suspension, cancellation, or transfer pursuant to any Registry-adopted policy, or pursuant to any registrar or registry procedure not inconsistent with a Registry adopted policy, (1) to correct mistakes by Tucows or the Registry in registering the name or (2) for the resolution of disputes concerning the domain name. (iii) Transfer of Ownership. Any transfer of ownership in and to a domain name registration shall be affected in accordance with registry policies and procedures. (iv) Registry Agreement and Policy. You acknowledge and understand that by accepting the terms and conditions of this agreement you shall be bound by the Registry’s Registrant Agreement, the Registry’s policies and any pertinent rules or policies that exist now or in the future and which are posted on the Registry website at [registraragreement pdf](http://www.cira.ca/assets/Documents/Legal/Registrars/registraragreement.pdf). You are responsible for monitoring the Registry’s site on a regular basis. In the event that you do not wish to be bound by a revision or modification to any Registry agreement or policy, your sole remedy is to cancel your domain name registration by following the appropriate Registry policy regarding such cancellation. (v) You acknowledge and agree that the Registry shall not be liable to you for any loss, damage, or expense arising out of the Registry’s failure or refusal to register a domain name, its failure or refusal to renew a domain name registration, its registration of a domain name, its failure or refusal to renew a domain name registration, its renewal of a domain name registration, its failure or refusal to transfer a domain name registration, its transfer of a domain name registration, its failure or refusal to maintain or modify a domain name registration, its maintenance of a domain name registration, its modification of a domain name registration, its failure to cancel a domain name registration or its cancellation of a domain name registration from the Registry; (b) **.cc Domains.**In the case of a “.cc” registration, the following terms and conditions will apply: (i) Domain Name Dispute Policy. If you reserved or registered a domain name through us, or transferred a domain name to us from another registrar, you agree to be bound by the Dispute Policy that is incorporated herein and made a part of this Agreement by reference. The current version of the Dispute Policy may be found at [DNDR](https://www.icann.org/resources/pages/dndr-2012-02-25-en). Please take the time to familiarize yourself with this policy. (ii) Registry Policy. You acknowledge and understand that by accepting the terms and conditions of this agreement you shall be bound by Registry policies and any pertinent rules or policies that exist now or in the future and which are posted on the Registry website at [http://www.nic.cc](http://www.nic.cc/). You are responsible for monitoring the Registry’s site on a regular basis. In the event that you do not wish to be bound by a revision or modification to any Registry policy, your sole remedy is to cancel your domain name registration by following the appropriate Registry policy regarding such cancellation. (c) **.cn Domains.**In the case of a “.cn” registration, the following terms and conditions shall apply: (i) “Registry” means the China Internet Network Information Center, which is the authority responsible for the administration of the national top-level domain of the People’s Republic of China and the Chinese domain name system; (ii) “Registry Gateway” means the service provided by the Registry Operator that facilitates the registration of .cn domain names by registrars operating outside of the People’s Republic of China; (iii) “Registry Operator” means Neustar, Inc., the company authorized to facilitate the registration of .cn domain names by registrars operating outside of the People’s Republic of China. (iv) Restrictions. You agree that you shall not register or use a domain name that is deemed by CNNIC to: (A) be against the basic principles prescribed in the Constitution of the Peoples Republic of China (“PRC”); (B) jeopardize national security, leak state secrets, intend to overturn the government or disrupt the integrity of the PRC; (C) harm national honor and national interests of the PRC; (D) instigate hostility or discrimination between different nationalities or disrupt the national solidarity of the PRC; (E) spread rumors, disturb public order, or disrupt social stability of the PRC; (F) spread pornography, obscenity, gambling, violence, homicide, terror or instigate crimes in the PRC; (G) insult, libel against others and infringe other people’s legal rights and interests in the PRC; or (H) take any other action prohibited in laws, rules, and administrative regulations of the PRC. (v) Business or Organization Representation. .cn domain name registrations are intended for businesses and organizations and not for individual use. By registering a .cn name, you accordingly represent that you have registered the domain name on behalf of a business or organization. It should be noted that, although .cn policy is permissive in terms of registration, and enforcement is generally in reaction to a complaint (as opposed to proactive review), registrations that are not associated with an organization or business may be subject to deletion. The foregoing prevents an individual from registering a .cn domain name for a business operating as a sole proprietorship. (vi) Domain Name Disputes. You acknowledge having read and understood and agree to be bound by the terms and conditions of the CNNIC Domain Name Dispute Policy & Rules for CNNIC Dispute Resolution Policy (“Dispute Policy”), as they may be amended from time to time, which are hereby incorporated and made an integral part of this Agreement. The Dispute Policy is currently found at: [ccpit patent](http://www.ccpit-patent.com.cn/node/1231/1232). (vii) You acknowledge that, pursuant to the Dispute Policy, Registrars must comply with all reasonable requests from the applicable domain name dispute resolution institutions including the provision of all relevant evidence in any domain name disputes in the specified time frames. (viii) If we are notified that a complaint has been filed with a judicial or administrative body regarding your use of our domain name registration services, you agree not to make any changes to your domain name record without our prior approval. We may not allow you to make changes to such domain name record until (i) we are directed to do so by the judicial or administrative body, or (ii) we receive notification from you and the other party contesting your registration and use of our domain name registration services that the dispute has been settled. Furthermore, you agree that if you are subject to litigation regarding your registration and use of our domain name registration services, we may deposit control of your domain name record into the registry of the judicial body by supplying a party with a registrar certificate from us. (ix) Adherence to Policies. You agree to comply with all applicable laws, regulations, and policies of the Peoples Republic of China’s governmental agencies and the China Internet Network Information Centre (“CNNIC”), including but not limited to the following rules and regulations: (A) Provisional Administrative Rules for Registration of Domain Names in China (currently at[cnnic](https://cnnic.com.cn/PublicS/fwzxxgzcfg/201208/t20120830_35735.htm)); (B) Detailed Implementation Rules for Registration of Domain Names in China (currently at[cnnic](https://cnnic.com.cn/PublicS/fwzxxgzcfg/201208/t20120830_35735.htm)); (C) Chinese Domain Names Dispute Resolution Policy (currently at[ccpit patent](http://www.ccpit-patent.com.cn/node/1231/1232)); and (D) CNNIC Implementing Rules of Domain Name Registration (currently at[cnnic](https://cnnic.com.cn/PublicS/fwzxxgzcfg/201208/t20120830_35735.htm)). You acknowledge that you have read and understood and agree to be bound by the terms and conditions of the policies of the CNNIC, as they may be amended from time to time. (x) Suspension and Cancellation. You agree that your registration of the domain name shall be subject to suspension, cancellation, or transfer pursuant to any Tucows, Registry Operator, CNNIC or government-adopted policy, or pursuant to any registrar or registry procedure not inconsistent with a CNNIC or government-adopted policy, (1) to correct mistakes by a party in registering the name, (2) for the resolution of disputes concerning the domain name, (3) to protect the integrity and stability of the registry, (4) to comply with any applicable laws, government rules or requirements, requests of aw enforcement, (5) to avoid any liability, civil or criminal, on the part of Tucows, Registry Operator or CNNIC, as well as their affiliates, subsidiaries, directors, representatives, employees and stockholders or (6) for violations of this Agreement. Tucows, Registry Operator and CNNIC also reserve the right to “freeze” a domain name during the resolution of a dispute. (xi) Jurisdiction. For the adjudication of disputes concerning or arising from the use of the domain name, the Registrant shall submit, without prejudice to other potentially applicable jurisdictions, to the jurisdiction of the courts (1) of the Registrant’s domicile, (2) where Tucows is located, and (3) the People’s Republic of China. (xii) Governing Law. For the adjudication of a dispute concerning or arising from the use of a .cn domain, such dispute will be governed under the Laws of the Peoples Republic of China. (d) **.de domains.**In the case of a “.de” registration, the following terms and conditions will apply: (i) Selection of a Domain Name. You represent that: (A) you have reviewed and have accepted the Registry’s Terms and Conditions and the Registry’s Guidelines and have provided your Reseller with written confirmation of same; (B) either you or the person designated as the administrative contact for the domain name shall be resident or shall have a branch in Germany; (C) to the best of your knowledge and belief, neither this registration of a domain name nor the manner in which it is directly or indirectly to be used infringes upon the legal rights of a third party and, further, that the domain name is not being registered for nor shall it at any time whatsoever be used for any unlawful purpose whatsoever. (ii) Domain Name Disputes. You agree that, if the registration or reservation of your domain name is challenged by a third party, you will be subject to the provisions specified by the Registry or any court of law. You agree that in the event a domain name dispute arises with any third party, you will indemnify and hold us harmless pursuant to the terms and conditions specified by the Registry or any court of law. (iii) Registry Policies. You agree to be bound by the Registry’s Registration Terms and Conditions and the Registration Guidelines. English language translations of the Registry’s documents are provided for convenience; in the event of a discrepancy between the English and the German language agreements, the terms of the German agreement will prevail. The Registry documents may be found at: **11.2. English:** (A) Registration Terms and Conditions [Terms and Conditions](http://www.denic.de/en/bedingungen.html) (B) Registration Guidelines [Guidelines](http://www.denic.de/en/richtlinien.html) (C) DENIC direct pricelist [direct pricelist](http://www.denic.de/en/preisliste.html) **11.3. German:** (D) DENIC-Registrierungsbedingungen [Registrierungsbedingungen](http://www.denic.de/de/bedingungen.html) (E) DENIC-Registrierungsrichtlinien [Registrierungsrichtlinien](http://www.denic.de/de/richtlinien.html) (F) DENIC-Preisliste [preis liste](http://www.denic.de/de/preisliste.html)(e) **.tv domains.**In the case of a “.tv” registration, the following terms and conditions will apply: (i) Domain Name Dispute Policy. If you reserved or registered a domain name through us, or transferred a domain name to us from another Registrar, you agree to be bound by the Dispute Policy that is incorporated herein and made a part of this Agreement by reference. The current version of the Dispute Policy may be found at [http://www.icann.org/dndr/udrp/policy.htm](http://www.icann.org/dndr/udrp/policy.htm). Please take the time to familiarize yourself with this policy. (ii) Policy. You agree that your registration of the .tv domain name shall be subject to suspension, cancellation, or transfer pursuant to any ICANN or government adopted policy, or pursuant to any Registrar or registry procedure not inconsistent with an ICANN or government-adopted policy, (1) to correct mistakes by us or the applicable Registry in registering the name or (2) for the resolution of disputes concerning the domain name. You acknowledge that you have reviewed the .tv General Terms of Service which may be found at: [tv General Terms](http://www.tv/en-def-5066945b5fcc/en/policies/tos.shtml)and expressly agree to the terms outlined therein. (f) **co.uk, .org.uk, ltd.uk, net.uk, plc.uk and me.uk domains.**In the case of a co.uk, .org.uk, ltd.uk, net.uk, plc.uk or me.uk registration, the following terms and conditions will apply: (i) “Nominet UK” means the entity granted the exclusive right to administer the registry for .uk domain name registrations. (ii) Domain Name Dispute Policy. If you reserved or registered a domain name through us, or transferred a domain name to us from another registrar, you agree to be bound by the Dispute Policy which is incorporated herein and made a part of this Agreement by reference. The current version of the Dispute Policy may be found at: [Dispute Policy](http://www.nominet.org.uk/disputes/). Please take the time to familiarize yourself with this policy. (iii) Nominet UK Policy. You agree that your registration of the domain name shall be subject to suspension, cancellation, or transfer pursuant to any Nominet UK-adopted policy, term or condition, or pursuant to any registrar or registry procedure not inconsistent with a Nominet UK-adopted policy, (1) to correct mistakes by a registrar or the registry in registering the name, or (2) for the resolution of disputes concerning the domain name. The current Nominet UK terms and conditions can be found at:[UK terms and conditions](http://www.nominet.org.uk/registrants/aboutdomainnames/legal/terms/) When you submit a request for a domain name registration with Tucows and/or Reseller, you will be entering into two contracts – one contract with Tucows and/or Reseller and one contract with Nominet UK. Tucows and your Reseller will act as agents on your behalf by submitting your application to Nominet for you, however, you will still be entering into a direct contract between you and Nominet UK. This is a separate contract from this agreement; may be found at http://resellers.tucows.com/contracts/uk/ukterms. Tucows and Reseller must also make you aware that by accepting Nominet’s terms and conditions you are consenting to Nominet using your personal data for a variety of reasons. In particular, your name and address may be published as part of Nominet’s WHOIS look-up service. (iv) Transfer of Ownership. Any transfer of ownership in and to a domain name registration shall be affected in accordance with Nominet UK policies and procedures.. (g) **.us domains.**In the case of a “.us” registration, the following terms and conditions will apply: (i) “DOC” means the United States of America Department of Commerce. (ii) us Nexus Requirement. Only those individuals or organizations that have a substantive lawful connection in the United States are permitted to register for .usTLD domain names. Registrants in the .usTLD must satisfy the nexus requirement (“Nexus” or “Nexus Requirements”) set out at: [the ustld nexus requirements](http://www.neustar.us/the-ustld-nexus-requirements/). (iii) Selection of a Domain Name. You certify and represent that: (A) You have and shall continue to have, a bona fide presence in the United States on the basis of real and substantial lawful contacts with, or lawful activities in, the United States as defined in Section (ii) hereinabove; (B) The listed name servers are located within the United States; (C) The data provided in the domain name registration application is true, correct, up to date, and complete, and that you will continue to keep all of the information provided correct, up-to-date and complete; (D) To the best of your knowledge and belief, neither this registration of a domain name nor the manner in which it is directly or indirectly to be used infringes upon the legal rights of a third party; (E) That the domain name is not being registered for nor shall it at any time whatsoever be used for any unlawful purpose whatsoever; (F) You have the authority to enter into this Registration Agreement. (iv) Domain Name Dispute Policy. If you reserved or registered a domain name through us, or transferred a domain name to us from another registrar, you agree to be bound by the Dispute Policy and the usDRP, as defined below, that is incorporated herein and made a part of this Agreement by reference. Please take the time to familiarize yourself with these policies. (A) Domain Name Disputes. You acknowledge having read and understood and agree to be bound by the terms and conditions of the following documents, as they may be amended from time to time, which are hereby incorporated and made an integral part of this Agreement: (B) The Nexus Dispute Policy (“Dispute Policy), available at: [nexus dispute policy pdf](http://web.neustar.biz/policies/docs/nexus_dispute_policy.pdf). The Dispute Policy will provide interested parties with an opportunity to challenge a registration not complying with the Nexus Requirements. (C) The usTLD Dispute Resolution Policy (“usDRP”) available at: [neustar us](http://www.neustar.us/ustld-dispute-resolution-policy/). The usDRP is intended to provide interested parties with an opportunity to challenge a registration based on alleged trademark infringement. In addition to the foregoing, you agree that, for the adjudication of disputes concerning or arising from use of the Registered Name, you shall submit, without prejudice to other potentially applicable jurisdictions, to the jurisdiction of the courts (i) of your domicile, (ii) where Tucows is located, and (iii) the United States. (v) Policy. You agree that your registration of the domain name shall be subject to suspension, cancellation, or transfer pursuant to any Tucows, Registry Operator, the DOC or government-adopted policy, or pursuant to any registrar or registry procedure not inconsistent with a DOC or government-adopted policy, (1) to correct mistakes by us or the applicable Registry in registering the name or (2) for the resolution of disputes concerning the domain name. The Registry Operator’s policies can be found at [policies](http://www.neustar.us/policies). (vi) Indemnity. The DOC shall be added to the parties you have agreed to indemnify in Section 13 hereinabove. (vii) Information. As part of the registration process, you are required to provide us certain information and to update us promptly as such information changes such that our records are current, complete, and accurate. You are obliged to provide us the following information: (A) Your full name, postal address, e-mail address and telephone number and fax number (if available) (or, if different, that of the domain name holder); (B) The domain name being registered; (C) The name, postal address, e-mail address, and telephone number and fax number (if available) telephone numbers of the administrative contact, the technical contact, and the billing contact for the domain name; (D) The IP addresses and names of the primary nameserver and any secondary nameserver(s) for the domain name; (E) In addition to the foregoing, you will be required to provide additional Nexus Information. The Nexus Information requirements are set out at [the ustld nexus requirements](http://www.neustar.us/the-ustld-nexus-requirements/). Any other information, which we request from you at registration, is voluntary. Any voluntary information we request is collected for the purpose of improving the products and services offered to you through your Reseller. (viii) Disclosure and Use of the Registration Information. You agree and acknowledge that we will make the domain name registration information you provide available to the DOC, to the Registry Operator, and to other third parties as applicable. You further agree and acknowledge that we may make publicly available, or directly available to third-party vendors, some, or all, of the domain name registration information you provide, for purposes of inspection (such as through our WHOIS service) or other purposes as required or permitted by the DOC and applicable laws. You hereby consent to any and all such disclosures and use of information provided by you in connection with the registration of a domain name (including any updates to such information), whether during or after the term of your registration of the domain name. You hereby irrevocably waive any and all claims and causes of action you may have arising from such disclosure or use of your domain name registration information by us. You may access your domain name registration information in our possession to review, modify or update such information, by accessing our domain manager service, or similar service, made available by us through your Reseller. We will not process data about any identified or identifiable natural person that we obtain from you in a way incompatible with the purposes and other limitations which we describe in this Agreement. We will take reasonable precautions to protect the information we obtain from you from our loss, misuse, unauthorized access or disclosure, alteration, or destruction of that information. ACCEPTANCE OF AGREEMENT. YOU ACKNOWLEDGE THAT YOU HAVE READ THIS AGREEMENT AND AGREE TO ALL ITS TERMS AND CONDITIONS. YOU HAVE INDEPENDENTLY EVALUATED THE DESIRABILITY OF THE SERVICE AND ARE NOT RELYING ON ANY REPRESENTATION AGREEMENT, GUARANTEE OR STATEMENT OTHER THAN AS SET FORTH IN THIS AGREEMENT. --- # Atlantic.Net Hosting Master Services Agreement > URL: https://www.atlantic.net/hosting-master-services-agreement/ | Updated: 2026-09-16 This Hosting Master Services Agreement is between ATLANTIC.NET, Inc., a Delaware corporation (“ATLANTIC.NET”) and the organization or individual person whose name appears on the signature line of the Agreement or on any document that incorporates the Agreement by reference (“Customer”) and is effective on the Effective Date. **1.**Defined Terms. Capitalized terms shall have the following meanings or the meanings assigned to them in the other Sections of the Agreement: **“Agreement”**shall mean the Service Order Form(s), this Master Services Agreement, the Service Level Agreement, any ATLANTIC.NET Addendum to this Master Services Agreement, and the AUP, collectively. Any conflict between the documents shall be resolved by reading the documents in the foregoing order of precedence. **“AUP”**shall mean ATLANTIC.NET’s Acceptable Use Policy, posted on Atlantic.Net’s website, as it may be amended from time to time in accordance with Section 6 (AUP) of this Master Services Agreement. **“Business Day”**shall mean Monday through Friday, 8:00 a.m. to 5:00 p.m., Eastern Time, excluding any United States Federal Holiday. **“Effective Date”**shall mean the day that Customer accepts the Agreement, either by signing ATLANTIC.NET’s Service Order Form or this Master Services Agreement or by using the Service. **“Service Commencement Date”**shall mean the date ATLANTIC.NET generates an e-mail message to Customer that provides access codes and passwords for use in connection with the Hosting Service. **“Service Level Agreement”**shall mean the Service Level Agreement incorporated by reference in the Service Order Form, as it may be amended from time to time by written agreement of the parties. **“Service Order Form”**shall mean the ATLANTIC.NET Dedicated Server Service Order Form accepted by Customer, as it may be amended from time to time in accordance with the Agreement, and any subsequent or additional Service Order Forms that incorporate this Master Services Agreement by reference. **“Service” or “Services”**shall mean the Hosting Service and any Supplemental Service(s) (as defined in Section 3) provided by ATLANTIC.NET to Customer pursuant to the Agreement. **2. Term**. The initial service term of the Agreement shall begin on the Service Commencement Date and continue for the period stated in the Service Order Form (the **“Initial Term”**) and automatically renew for successive terms equal to the initial term unless canceled by either party in writing at least thirty days before the expiration of the current term (the “Term”). The Initial Term applicable to any Service Order Form executed subsequent to the Effective Date shall begin on the Service Commencement Date stated in that Service Order Form and continue for the period stated in that Service Order Form. **3. Services**. Contingent upon Customer’s satisfaction of ATLANTIC.NET’s credit approval requirements and on ATLANTIC.NET’s verification of the information provided by Customer for the purpose of establishing the Service, ATLANTIC.NET agrees to provide the Hosting Service in accordance with the terms of the Agreement. In addition, ATLANTIC.NET may from time to time perform certain additional services on an hourly fee basis (the “Supplemental Services”), such as the customization of the Hosting Service at Customer’s request, services described in the AUP, and other professional technical services. Supplemental Services will be performed only on Customer’s advance approval and will be invoiced at ATLANTIC.NET’s published rates or other rates approved in advance in writing by Customer, provided, however, that ATLANTIC.NET may perform Supplemental Services for the fees stated in the AUP as necessary to remediate problems caused by AUP violations without obtaining advance Customer consent. **4. Payments**. **(a). AGREEMENT TO PROVIDE SERVICES AND PAY FEES; SERVICE LEVEL AGREEMENT.** Pursuant to the Agreement, ATLANTIC.NET has agreed to provide certain services (**“Services”**) to the Customer, and the Customer has agreed to pay certain fees (**“Fees”**) to ATLANTIC.NET in consideration therefore. ATLANTIC.NET shall have the right to increase the Fees after 12 (twelve) months of service in proportion to increases in the Consumer Price Index and/or electricity costs applicable to the geographic area where the Building is located, plus two percent (2%). ATLANTIC.NET shall have the right to increase software license fees at any time for software in proportion to increases from the owner of the product. Customer shall have the right to purchase additional Services offered by ATLANTIC.NET from time to time on terms and conditions to be agreed upon in writing. **(b). PAYMENT OF FEES; DUE DATE; LATE CHARGE; DEFAULT INTEREST**. Customer agrees to pay the monthly and set up fees stated in the Service Order Form and ATLANTIC.NET’s standard fees for Supplemental Services as described in Section 3 (Services) above. ATLANTIC.NET may require payment in full of its first invoice before beginning the Service. On or before the first (1st) day of each and every month during the Term hereof (each, a **“Due Date”**), Customer agrees to and shall pay the Fees to ATLANTIC.NET, in advance, for the Services to be rendered by ATLANTIC.NET to Customer during said month, without offset, deduction or credit of any kind and in good and drawable funds. If Customer for any reason fails to pay the Fees to ATLANTIC.NET by the Due Date of any month during the Term hereof, Customer will be assessed an administrative charge in the amount which is equal to five (5%) of the overdue Fees (**“Administrative Charge”**); in addition, ATLANTIC.NET may charge interest on all due but unpaid Fees at the lesser of 1.5% per month or the maximum non-usurious rate under applicable law (**“Default Interest”**) until paid in full. Customer agrees to and shall pay to ATLANTIC.NET for all costs of collection of the Fees, Default Interest and Late Charges plus ATLANTIC.NET’s attorneys’ fees, costs, expenses, and court costs and fees paid or incurred in connection therewith. Customer’s obligation to pay the Fees, Default Interest, and Late Charges shall survive the expiration or earlier termination of the Hosting Master Service Agreement. If Customer requests that Atlantic.Net provide services not specifically set forth herein and Atlantic.Net agrees to provide such services, Customer agrees to pay ATLANTIC.NET’s standard fee for such service at the time such service is rendered or such charge as the parties may mutually agree upon prior to the delivery of the service. Invoices for Supplemental Services, excess data transfer, reinstatement of service, switching and upgrade fees and other non-recurring amounts are due on receipt. Customer acknowledges that it is responsible for excess data transfer fees that may result from a denial of service or other attack on its ATLANTIC.NET servers. Credits due under the Service Level Agreement may be given, at ATLANTIC.NET’s option, against the invoice for the month in which the event(s) occurred or the invoice for the following month. Payments must be made in United States dollars. ATLANTIC.NET may suspend any or all Services to Customer if payment for any Service is overdue. A Reinstatement Fee equal to seventy-five dollars ($75.00) will be assessed for suspended Services and must be collected with the overdue Fees for the account to be reinstated. Fees not disputed within sixty (60) days of due date are conclusively deemed accurate. **(c) Early Termination**. Customer acknowledges that the amount of the monthly recurring fee for the Hosting Service is based on Customer’s agreement to pay the fee for the entire Initial Term. In the event ATLANTIC.NET terminates the Agreement for Customer’s breach of the Agreement in accordance with Section 13 (Termination), or Customer terminates the Hosting Service other than for ATLANTIC.NET’s breach in accordance with Section 13 (Termination), all fees due under the Agreement, including the monthly recurring fees for the remaining portion of the Term, are due on the Business Day following termination of the Hosting Service. **5. Customer Obligations**. Customer agrees to do all of the following at its expense: **(a) Security Precautions.**Use reasonable security precautions in connection with its use of the Services and, if Customer resells ATLANTIC.NET’s services, require its customers and end-users to use reasonable security precautions; **(b) Security and Backup**. Customer is responsible for properly configuring and using the ATLANTIC.NET services and taking appropriate action to secure, protect, and backup Customer’s content in a manner that will provide appropriate security and availability; **(c) Law, AUP**. Comply with laws applicable to Customer’s use of the Services and with ATLANTIC.NET’s AUP, and if Customer resells ATLANTIC.NET’s Service, require its customers and end-users to comply with applicable law and ATLANTIC.NET’s AUP; and **(d) Investigation of AUP.**Cooperate with ATLANTIC.NET’s reasonable investigation of any suspected violation of the AUP. **6. AUP**. Customer agrees that ATLANTIC.NET may, in its reasonable commercial judgment consistent with industry standards, amend the AUP from time to time to further detail or describe reasonable restrictions and conditions on Customer’s use of the Services. Amendments to the AUP are effective on the earlier of ATLANTIC.NET’s notice to Customer that an amendment has been made, or the beginning of any Renewal Term or Extended Term. However, if: (i) the amendment would materially and adversely affect Customer, (ii) Customer provides ATLANTIC.NET with a written notice describing its objection to the amendment in reasonable detail within five (5) Business Days of the effective date of the amendment, and (iii) ATLANTIC.NET does not agree to waive the amendment as to Customer within five (5) Business Days of Customer’s notice, then Customer may terminate the Agreement without liability as provided in Section 13 (Termination). **7. Suspension of Service**. Customer agrees that ATLANTIC.NET may suspend Services to Customer without notice and without liability if: (i) ATLANTIC.NET reasonably believes that the Services are being used in violation of the AUP; (ii) Customer fails to cooperate with any reasonable ATLANTIC.NET investigation of any suspected violation of the AUP; (iii) there is a denial of service attack on Customer’s servers or other event for which ATLANTIC.NET reasonably believes that the suspension of Services is necessary to protect its network or its other customers; (iv) as requested by a law enforcement or government agency; or (v) payment for any Service is overdue. Information on ATLANTIC.NET’s servers will be unavailable during a suspension of Services. **8. Warranties**. **(a) Reciprocal**. ATLANTIC.NET represents and warrants to Customer, and if Customer is not an individual, Customer represents and warrants to ATLANTIC.NET, that: (i) it has the power and authority and the legal right to enter into the Agreement and to perform its obligations under the Agreement; (ii) it has taken all necessary action on its part to authorize the execution and delivery of the Agreement; and, (iii) the execution and delivery of the Agreement and the performance of its obligations hereunder do not conflict with or violate applicable laws or regulations, and do not conflict with or constitute a default under its charter documents. If Customer is an individual, Customer represents and warrants to ATLANTIC.NET that he or she is at least 18 years of age. **(b) Customer**. Customer represents and warrants to ATLANTIC.NET that: (i) the information Customer has provided and will provide to ATLANTIC.NET for purposes of establishing and maintaining the Services is accurate; and (ii) Customer shall not provide access to the Service to any person (including any natural person or government or private entity) that is located in or is a national of any embargoed or highly restricted country under United States Export Regulations, which include as of August 2005 Cuba, Iran, Libya, North Korea, Sudan or Syria. **9. Unauthorized Use of Service**. Customer is generally responsible for the security of the servers provided pursuant to this Agreement, and ATLANTIC.NET agrees only to perform the specific security services described in the Service Order Form or other portion of the Agreement. Customer shall be responsible for any unauthorized use of the Services by any person and shall pay all fees incurred for its account by any person using the Services unless such unauthorized use results from ATLANTIC.NET’s failure to perform its obligations under the Agreement. **10. Indemnification**. The parties agree that the indemnification obligations defined in this Section shall be in lieu of and supersede any indemnification obligations that may otherwise exist by law. **(a) Customer**. Customer agrees to indemnify and hold harmless ATLANTIC.NET, ATLANTIC.NET’s affiliates, and each of their respective officers, directors, attorneys, agents, and employees from and against any and all claims, demands, liabilities, obligations, losses, damages, penalties, fines, punitive damages, amounts in interest, expenses and disbursements of any kind and nature whatsoever (including reasonable attorneys’ fees) brought by a third party under any theory of legal liability arising out of or related to: (i) the actual or alleged use of the Services in violation of: (A) the AUP, (B) any other portion of the Agreement, or (C) applicable law, by any person regardless of whether such person has been authorized to use the Services by Customer, except for unauthorized use that results from ATLANTIC.NET’s failure to perform its obligations under the Agreement, or (ii) any dispute regarding the control of Customer’s account with ATLANTIC.NET. Without limitation of the foregoing, Customer shall pay ATLANTIC.NET $200.00 per hour for time reasonably spent by ATLANTIC.NET personnel to respond to third party complaints regarding Customer’s use or alleged use of the Services in violation of the AUP, including complaints under the Digital Millenium Copyright Act. **(b) Reciprocal**. Each party agrees to indemnify and hold harmless the other party, the other party’s affiliates, and each of their respective officers, directors, attorneys, agents, and employees from and against any and all claims, demands, liabilities, obligations, losses, damages, penalties, fines, punitive damages, amounts in interest, expenses and disbursements of any kind and nature whatsoever (including reasonable attorneys’ fees) brought by a third party under any theory of legal liability arising out of or related to the indemnifying party’s actual or alleged infringement or misappropriation of a third party’s copyright, trade secret, patent, trademark, or other proprietary right. **(c) Procedures**. A party seeking indemnification under this Section shall provide prompt notice of its claim for indemnification to the indemnifying party; provided, however, that failure to give prompt notice shall not affect the indemnifying party’s obligations under this Section unless and to the extent that the failure materially prejudices the defense of the matter. The indemnified party will have the right to select counsel to defend it in respect of any indemnified matter under this Section; provided, however, that the counsel selected must be reasonably satisfactory to the indemnifying party. The indemnified party will keep the indemnifying party informed of the status of any litigation or dispute resolution procedure, will give reasonable consideration to the suggestions and requests of the indemnifying party with respect to the conduct of the litigation or dispute resolution procedure, and will not settle any matter covered by this Section without the prior consent of the indemnifying party, which shall not be unreasonably withheld. Notwithstanding anything in this Section to the contrary, if the indemnifying party is indemnifying multiple persons related to the subject matter of the indemnification, the indemnifying party shall have the right to seek consolidation of all such actions and to select counsel to defend the actions. Amounts due under this Section shall be paid as incurred and may be offset against other amounts due under the Agreement. **11. Disclaimer of Warranties**. ATLANTIC.NET DOES NOT WARRANT OR REPRESENT THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, OR COMPLETELY SECURE. CUSTOMER ACKNOWLEDGES THAT THERE ARE RISKS INHERENT IN INTERNET CONNECTIVITY THAT COULD RESULT IN THE LOSS OF CUSTOMER’S PRIVACY, CONFIDENTIAL INFORMATION, AND PROPERTY. TO THE EXTENT PERMITTED BY APPLICABLE LAW, ATLANTIC.NET DISCLAIMS ANY AND ALL WARRANTIES NOT EXPRESSLY STATED IN THE AGREEMENT INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NONINFRINGEMENT. CUSTOMER IS SOLELY RESPONSIBLE FOR THE SUITABILITY OF THE SERVICES CHOSEN. ALL GOODS AND SERVICES ARE PROVIDED ON AN “AS IS” BASIS, EXCEPT AS EXPRESSLY STATED IN THE SERVICE LEVEL AGREEMENT OR OTHER PORTION OF THE AGREEMENT. **12. Limitation of Damages**. The parties agree that the allocations of risk made in this Section are reasonable and that they would not enter into the Agreement without these limitations on liability. THE CREDITS DESCRIBED IN THE SERVICE LEVEL AGREEMENT AND SERVICE ORDER FORM ARE CUSTOMER’S SOLE REMEDIES FOR ATLANTIC.NET’S FAILURE TO MEET THE GUARANTEES AND WARRANTIES STATED IN THOSE DOCUMENTS, PROVIDED THAT THIS PROVISION DOES NOT LIMIT CUSTOMER’S RIGHT TO TERMINATE THIS AGREEMENT AS PROVIDED IN SECTION 13 (TERMINATION) BELOW IF SUCH FAILURE(S) CONSTITUTE A MATERIAL BREACH OF THIS AGREEMENT. EXCEPT AS DESCRIBED IN THE SERVICE LEVEL AGREEMENT, ATLANTIC.NET SHALL NOT BE LIABLE TO THE CUSTOMER FOR HARM CAUSED BY OR RELATED TO CUSTOMER’S USE OF THE SERVICES OR INABILITY TO USE THE SERVICES UNLESS THE HARM WAS CAUSED BY ATLANTIC.NET’S GROSS NEGLIGENCE OR WILLFUL MISCONDUCT. NEITHER PARTY SHALL BE LIABLE TO THE OTHER FOR ANY LOST PROFITS, OR ANY INDIRECT, SPECIAL, INCIDENTAL, CONSEQUENTIAL OR PUNITIVE LOSS OR DAMAGE OF ANY KIND, OR FOR DAMAGES THAT COULD HAVE BEEN AVOIDED BY THE USE OF REASONABLE DILIGENCE, ARISING IN CONNECTION WITH THE AGREEMENT, EVEN IF THE PARTY HAS BEEN ADVISED OR SHOULD BE AWARE OF THE POSSIBILITY OF SUCH DAMAGES. NOTWITHSTANDING ANYTHING ELSE IN THE AGREEMENT TO THE CONTRARY, THE MAXIMUM AGGREGATE LIABILITY OF ATLANTIC.NET AND ANY OF ITS EMPLOYEES, AGENTS, OR AFFILIATES, UNDER ANY THEORY OF LAW (INCLUDING BREACH OF CONTRACT, TORT, STRICT LIABILITY, AND INFRINGEMENT) SHALL BE A PAYMENT OF MONEY NOT TO EXCEED THE AMOUNT PAID BY CUSTOMER FOR THE HOSTING SERVICE FOR THE THREE MONTHS PRIOR TO THE OCCURRENCE OF THE EVENT(S) GIVING RISE TO THE CLAIM. NO CLAIM MAY BE ASSERTED BY EITHER PARTY AGAINST THE OTHER PARTY WITH RESPECT TO ANY EVENT, ACT, OR OMISSION THAT OCCURRED MORE THAN TWO (2) YEARS PRIOR TO SUCH CLAIM BEING ASSERTED. **13. Termination**. **(a) Customer**. The Agreement may be terminated by Customer prior to the expiration of the Initial Term, any Renewal Term, or Extended Term without liability (except for amounts due for Services through the effective date of termination) as follows: (i) ATLANTIC.NET fails in a material way to provide the Hosting Service in accordance with the terms of the Agreement and does not cure the failure within ten (10) days of Customer’s written notice describing the failure in reasonable detail, (ii) ATLANTIC.NET materially violates any other provision of the Agreement and fails to cure the violation within thirty (30) days of Customer’s written notice describing the violation in reasonable detail, or (iii) as provided in Section 6 (AUP) upon thirty (30) days advance written notice in the event of an amendment to the AUP that materially and adversely affects Customer and that is not waived by ATLANTIC.NET. **(b) ATLANTIC.NET**. The Agreement may be terminated by ATLANTIC.NET prior to the expiration of the Initial Term, any Renewal Term, or Extended Term, without liability as follows: (i) upon five (5) Business Days notice if Customer is overdue on the payment of any amount due under the Agreement; (ii) Customer materially violates any other provision of the Agreement, including the AUP, and fails to cure the violation within thirty (30) days of a written notice from ATLANTIC.NET describing the violation in reasonable detail; (iii) upon one (1) Business Days notice if Customer’s Service is used in violation of a material term of the AUP more than once; or (iv) upon reasonable notice if ATLANTIC.NET is threatened with a legal claim for copyright or patent infringement related to the provision of the Service and is unable to modify the Service in a way that avoids an ongoing risk of liability. **14. Confidentiality**. **(a) Confidential Information**. Confidential Information is: (i) with respect to ATLANTIC.NET, ATLANTIC.NET’s unpublished prices for services, audit and security reports, server configuration designs and other proprietary technology, (ii) with respect to Customer, content transmitted to or from, or stored by Customer on, ATLANTIC.NET’s servers, and (iii) with respect to both parties, other information that is conspicuously marked as “confidential” or if disclosed in non-tangible form, is verbally designated as “confidential” at the time of disclosure and confirmed as confidential in a written notice given within one (1) day of disclosure; but excluding any information which is independently developed by a non-disclosing party as shown by such party’s written business records, is or becomes generally available to the non-disclosing party or the public other than through violation of the Agreement, or is required to be disclosed by law or regulation. Each party agrees not to disclose the other’s confidential information to any third party except to its service providers, agents and representatives who need to know the information to represent or advise it with respect to the subject matter of the Agreement; and provided that such service providers, agents and representatives are bound by confidentiality restrictions at least as stringent as those stated in the Agreement. **(b) ATLANTIC.NET’s Use of Customer’s Name and Logo.** Customer agrees that ATLANTIC.NET may publicly disclose that ATLANTIC.NET is providing services to Customer and may include Customer’s name and logo in promotional materials, including press releases, on ATLANTIC.NET’s Web site, and marketing collateral. **(c) Requests for Customer Information**. Notwithstanding anything to the contrary above, Customer agrees that ATLANTIC.NET may, without notice to Customer, (i) report to the appropriate authorities any conduct by Customer or any of Customer’s customers or end-users that ATLANTIC.NET believes violates applicable law, and (ii) provide any information, including Confidential Information, it has about Customer or any of its customers or end-users in response to a formal or informal request from a law enforcement or government agency. ATLANTIC.NET may provide any information, including Confidential Information, it has about Customer or its customers or end-users in response to a formal request in a civil action that on its face meets the requirements for such a request. **15. Software**. Customer agrees not to remove, modify or obscure any copyright, trademark, or other proprietary rights notices that appear on any software provided by ATLANTIC.NET. Customer may not reverse engineer, decompile, or disassemble any ATLANTIC.NET provided software, except and only to the extent that such activity is expressly permitted by applicable law notwithstanding this limitation, or is permitted by the terms of any “open source” license that governs the use of the software. **16. Third Party Products**. As a convenience to Customer, ATLANTIC.NET may from time to time arrange for Customer’s purchase or license of third party software, services, and other products not included as part of the Service, and/or may provide support to Customer in relation to those products. ATLANTIC.NET MAKES NO REPRESENTATIONS OR WARRANTY WHATSOEVER REGARDING SUCH THIRD-PARTY PRODUCTS AND RELATED SUPPORT SERVICES AND THEY ARE PROVIDED “AS IS.” Customer’s use of third-party software, services, and other products is governed by the terms of any license or other agreement between Customer and the third party. **17. Notices**. Notices to ATLANTIC.NET under the Agreement shall be given in writing via first class mail or established and well-known express courier to Legal Counsel, ATLANTIC.NET HOSTING, at ATLANTIC.NET’s principal office address posted on www.ATLANTIC.NET, currently: 440 West Kennedy Blvd, Suite 3 Orlando, FL 32810 Notices to Customer shall be given via electronic mail to the individual designated as the Contact on the Service Order Form or by means reasonable under the circumstances, including an e-mail to a known contact. Notices are deemed received on the day delivered, or if that day is not a Business Day, on the first Business Day following the day delivered. **18. Miscellaneous**. **(a) Solicitation of ATLANTIC.NET Employees**. Customer agrees that it shall not solicit any ATLANTIC.NET employee with whom Customer has had direct contact in connection with this Agreement for employment with Customer or any other person during the term of this Agreement and for twelve (12) months following termination of this Agreement. Notwithstanding the foregoing, Customer shall not be precluded from (i) hiring an employee of ATLANTIC.NET who independently approaches Customer, or (ii) conducting general recruiting activities, such as participation in job fairs or publishing advertisements in publications or on Web sites for general circulation. In the event of a violation of this provision, in addition to any other right ATLANTIC.NET may have at law or in equity, Customer shall make a one-time payment to ATLANTIC.NET in the amount of fifty percent (50%) of the employee’s base salary for one year. **(b) Ownership**. Each party acknowledges and agrees that the other party retains exclusive ownership and rights in its trade secrets, inventions, copyrights, and other intellectual property and that ATLANTIC.NET shall own any intellectual property that it may develop in the course of performing the Services. Customer does not acquire any ownership interest or rights to possess ATLANTIC.NET’s server(s) or other hardware and has no right of physical access to the hardware. Upon termination of the Agreement, Customer agrees to promptly release any Internet protocol numbers, addresses, or address blocks assigned to Customer in connection with the Service (but not any URL or top-level domain or domain name) and agrees that ATLANTIC.NET may take steps to change or remove any such IP addresses. **(c) Governing Law, Jurisdiction, Venue**. The Agreement shall be governed by the laws of the State of Florida, exclusive of its choice of law principles, and the laws of the United States of America, as applicable. The Agreement shall not be governed by the United Nations Convention on the International Sale of Goods. EXCLUSIVE VENUE FOR ALL DISPUTES ARISING OUT OF OR RELATING TO THE AGREEMENT SHALL BE THE STATE AND FEDERAL COURTS IN ORANGE COUNTY, FLORIDA, AND EACH PARTY IRREVOCABLY CONSENTS TO SUCH PERSONAL JURISDICTION AND WAIVES ALL OBJECTIONS THERETO. **(d) Modifications**. Except for the following, the Agreement may be amended only by a formal written agreement signed by both parties: (i) amendments of the AUP as described in Section 6, above, (ii) a Renewal Term may be agreed by means of ATLANTIC.NET’s renewal process, and (iii) changes to the “Server Specifications,” “Software and Services,” or fees section of an existing Service Order Form may be made by an exchange of correspondence (including electronic mail) that includes both parties’ express consent to the change. The terms on either party’s purchase order or other business forms are not binding on the other party unless they are expressly incorporated into a formal written agreement signed by both parties. **(e) Non-Waiver**. A party’s failure or delay in enforcing any provision of the Agreement will not be deemed a waiver of that party’s rights with respect to that provision or any other provision of the Agreement. A party’s waiver of any of its rights under the Agreement is not a waiver of any of its other rights with respect to a prior, contemporaneous, or future occurrence, whether similar in nature or not. **(f) Captions**. The captions in the Agreement are not part of the Agreement but are for the convenience of the parties. **(g) Counterparts**. Any documents signed in connection with the Agreement may be signed in multiple counterparts, which taken together will constitute one original. **(h) Survival**. The following provisions will survive expiration or termination of the Agreement: fees, indemnity obligations, confidentiality obligations, provisions limiting liability and disclaiming warranties, provisions regarding ownership of intellectual property, these miscellaneous provisions, and other provisions that by their nature are intended to survive termination of the Agreement. **(i) Force Majeure**. Neither party shall be in default of any obligation under the Agreement if the failure to perform the obligation is due to any event beyond that party’s control, including, without limitation, significant failure of a portion of the power grid, significant failure of the Internet, natural disaster, war, riot, insurrection, epidemic, strikes or other organized labor action, terrorist activity, or other events of a magnitude or type for which precautions are not generally taken in the industry. **(j) No Third-Party Beneficiaries**. There are no third-party beneficiaries to the Agreement. Neither insurers nor the customers of resellers are third-party beneficiaries to the Agreement. **(k) Severability**. In the event any term of this Agreement is held unenforceable by a court having jurisdiction, the remaining portion of the Agreement will remain in full force and effect, provided that the Agreement without the unenforceable provision(s) is consistent with the material economic incentives of the parties leading to the Agreement. **(l) Relationship Between the Parties**. The parties are independent contractors and not partners or joint venturers. Neither party is the agent of the other and neither party may represent to any person that it has the power to bind the other on any agreement. The Agreement is non-exclusive. ATLANTIC.NET may provide service to any person, including a competitor of Customer. **(m) Assignment**. Customer may not transfer the Agreement without ATLANTIC.NET’s prior written consent. ATLANTIC.NET’s approval for assignment is contingent on the assignee meeting ATLANTIC.NET’s credit approval criteria. ATLANTIC.NET may assign the Agreement in whole or in part. **(n) Agreement**. The Service Order Form(s), Service Level Agreement, ATLANTIC.NET’s AUP, and any ATLANTIC.NET Addendum to this Master Services Agreement accepted by Customer are hereby incorporated in this Master Services Agreement by reference and together collectively constitute the Agreement. The Agreement is the complete and exclusive agreement between the parties regarding its subject matter and supersedes and replaces any prior agreement, understanding or communication, written or oral. **(o) Not A Legal Advice.** Atlantic.Net provides general information on a wide range of topics that includes compliance, best practices, and cybersecurity on its website and blog with the best effort to help educate users. The information is intended for general information only and is not legal advice nor the best fit for all scenarios.  Atlantic.Net’s postings will be updated from time to time, however, there will be cases where the information may be out of date.  Please consult with your CPA, attorney, auditors, and cybersecurity experts for legal and best practice advice.  ** Updated: March 3, 2021 --- # Atlantic.Net Service Policies > URL: https://www.atlantic.net/service-policies/ | Updated: 2026-09-16 ### General Policies - [Acceptable Use Policy](https://www.atlantic.net/acceptable-use-policy/) - [Digital Millennium Copyright Act](https://www.atlantic.net/digital-millennium-copyright-act/) - [Bandwidth and Backup Overages](https://www.atlantic.net/bandwidth-backup-overages/) - [Registration Agreement](https://www.atlantic.net/domain-registration-agreement/) - [Privacy Policy](https://www.atlantic.net/privacy-policy/) - [AI Policy](https://www.atlantic.net/ai-policy/) - [Domain Name Dispute Resolution](https://www.atlantic.net/domain-registration-agreement/) - [ADA Compliance Statement](https://www.atlantic.net/ada-compliance-statement/) ### Cloud Servers & VPS - [Cloud Service Level Agreement](https://www.atlantic.net/cloud-service-level-agreement/) - [Cloud Terms of Service](https://www.atlantic.net/cloud-terms-service/) ### Colocation - [Colocation Master Service Agreement](https://www.atlantic.net/colocation-master-services-agreement/) - [Colocation Policies and Regulations](https://www.atlantic.net/colocation-policies-regulations/) - [Acceptable Use of Rack Space at Atlantic.Net Facilities](https://www.atlantic.net/acceptable-use-of-rack-space-at-atlantic-net-facilities/) ### Dedicated Servers - [Hosting Master Service Agreement](https://www.atlantic.net/hosting-master-services-agreement/) - [Dedicated Server Service Level Guarantee](https://www.atlantic.net/dedicated-server-service-level-guarantee/) ## Disclaimer The content published on the Atlantic.Net website, as well as material contributed to third-party websites, is provided for informational purposes only. It does not constitute professional, legal, financial, or technical advice. Every situation is unique and may require specialized guidance from a qualified professional. Readers should conduct their own due diligence and evaluate all information carefully before making any decisions. --- # Bandwidth and Backup Overages > URL: https://www.atlantic.net/bandwidth-backup-overages/ | Updated: 2026-09-16 ### Bandwidth and Backup Overages Policy and Price Determination The following clause is included in all of Atlantic.Net’s colocation and dedicated service customer contracts and amendments. The clause states the method of measurement and the cost of exceeding the bandwidth usage for each of three different contracted services. Bandwidth / Backup Overages: Customer agrees to pay $0.05 per 1 gigabyte of data transfer in excess of the amount included in the monthly recurring fee for bandwidth contracted under “Monthly Transfer” model. Customer agrees to pay the price per megabit per second (Mbps), as stated in the contract, for each additional Mbps over their contracted amount based on 95-percentile bandwidth overage billing. Also, customer agrees to pay $2.50 per 1 gigabyte of data transfer in excess of the backup subscription for the specified backup period. All overages and usage data is determined solely by Atlantic.Net. ## “Monthly Transfer” Model Customers that are under the “Monthly Transfer” model will have a total of bandwidth transfer allowed during a month stated on their contract. The item Data Transfer will usually be listed under “Server Specifications” with the amount of total bandwidth contracted for (example: 5000 GB) under the heading of “Description”. This is the amount of data transferred between your account and other internet users. Remember that this not only includes your website, but also your emails, FTP, and other applications you may use. Check your statistics. The control panel gives you a monthly tally, so you know how much you have used. If you do not have access to the control through Helpdesk, please contact commercial billing at 866-618-3282 extension 7070. Under the contract, the customer agrees to pay $0.05 per 1 gigabyte of data transfer in excess of the amount included in the monthly recurring fee for bandwidth contracted. ## 95-Percentile Bandwidth Overage To account for the instances in which the customer’s traffic bursts over their minimum committed bandwidth, Atlantic.Net utilizes a billing method referred to as the “95th Percentile Rule”. Under the 95-percentile bandwidth billing method, Atlantic.Net customers can exceed their contracted bandwidth limit for brief periods of time (totaling 5%) without incurring the financial costs associated with increasing their contracted bandwidth amount. Customer agrees to pay the price per megabit per second (Mbps), as stated in the Colocation Contract, for each additional Mbps over their contracted amount, based on 95-percentile bandwidth overage billing. The contracted Mbps amount is defined as the bandwidth number listed in the Internet Access Quantity field on the Colocation Service Order Form. Atlantic.Net’s bandwidth monitoring records sample data points, which reflect how much bandwidth a customer is utilizing in that particular instance. The inbound and outbound traffic level for each service connection is measured every 5 minutes. During the month, all the data samples for the inbound and outbound traffic are collected in a database. Over the course of the month, the highest 5% of both the inbound and outbound traffic levels are discarded, and the next highest remaining data sample on either the inbound or outbound is the “95th Percentile” value, which is used as the basis for the calculation of any additional monthly charges. If your usage falls below the minimum monthly committed amount after we’ve taken off the top 5%, you will not incur any additional usage charges. ## Calculation Example for 95-Percentile Bandwidth Overage: An example: Let’s say Atlantic.Net’s customer has contracted for 40Mbps per month. Atlantic.Net collects data samples for one month and sorts them from highest to lowest, discarding the top 5%. For the purpose of this example, the 95th percentile for the month was 68Mbps. The customer will be billed for the additional charges of 68Mbps, minus the previously invoiced 40Mbps of contractually committed bandwidth, or 28Mbps. The additional 28Mbps of overage will be invoiced at the price per megabit per second (Mbps), as stated in the contract. ## Backup Subscription Atlantic.Net’s customers have the option of purchasing backup services for computer systems. These customers agree to pay $2.50 per 1 gigabyte of data transfer in excess of the backup subscription for the specified backup period. --- # Digital Millennium Copyright Act > URL: https://www.atlantic.net/digital-millennium-copyright-act/ | Updated: 2026-09-16 In order to afford a suitable level of security and responsibility for copyright holders many ISPs and Web Hosting Providers, including Atlantic.Net, have registered with the United States Patent and Trademark Office under the Digital Millennium Copyright Act. If you believe that your copyrighted work has been copied and is accessible on an Atlantic.Net hosted site in a way that constitutes copyright infringement, you may notify Atlantic.Net by providing its designated agent with the following information: 1. the electronic or physical signature of the owner of the copyright or the person authorized to act on the owner’s behalf. 2. a description of the copyrighted work that you claim has been infringed and a description of the infringing activity. 3. identification of the location where the original or an authorized copy of the copyrighted work exists, for example, the URL of the website where it is posted or the name of the book in which it has been published. 4. identification of the URL or other specific location on this site where the material that you claim is infringing is located; you must include enough information to allow us to locate the material. 5. your name, address, telephone number, and email address. 6. a statement by you that you have a good faith belief that the disputed use is not authorized by the copyright owner, its agent, or the law. 7. a statement by you, made under penalty of perjury, that the above information in your Notice is accurate and that you are the copyright owner or are authorized to act on the copyright owner’s behalf. Our agent for notice of claims of copyright infringement on this site can be reached as follows: By mail: General Counsel Atlantic.Net, Inc. 440 West Kennedy Blvd. Suite 3 Orlando, FL 32810 By fax: 321-234-0288 This contact information is only for reporting copyright infringement. --- # Atlantic.Net in the News > URL: https://www.atlantic.net/press-room/news/ | Updated: 2026-09-16 ## In The News **Business RadioX - 6/22/2026** [Cloud Innovation Meets Enterprise Security](https://businessradiox.com/podcast/atlantabusinessradio/atlantic-net/) **CyberNews - 4/15/2026** [Faster Websites with Dedicated or Cloud Hosting](https://cybernews.com/partner-content/faster-websites-with-dedicated-or-cloud-hosting/) **CyberNews - 4/13/2026** [How to Choose the Best Web Hosting Provider](https://cybernews.com/partner-content/how-to-choose-the-best-web-hosting-provider/) **Dental Economics - 4/8/2026** [Securing dental office documents in the cloud: Utilizing HIPAA-compliant hosting solutions](https://www.dentaleconomics.com/practice/article/55362635/securing-dental-office-documents-in-the-cloud-utilizing-hipaa-compliant-hosting-solutions) **Medical Economics - 4/1/2026** [Practical steps to achieve HIPAA compliance in the cloud](https://www.medicaleconomics.com/view/practical-steps-to-achieve-hipaa-compliance-in-the-cloud) **Market Research Future - 4/1/2026** [Managed Hosting Market](https://www.marketresearchfuture.com/reports/managed-hosting-market-33476) **Market Research Future - 4/1/2026** [Managed Hosting Market Companies](https://www.marketresearchfuture.com/reports/managed-hosting-market/companies) **CyberNews - 3/25/2026** [How Secure Is the Cloud in 2026? Risks, Security Controls, and Best Practices](https://cybernews.com/partner-content/how-secure-is-the-cloud-in-2026-risks-security-controls-and-best-practices/) **CyberNews - 3/18/2026** [What’s New with HIPAA-Compliant Hosting in 2026](https://cybernews.com/partner-content/whats-new-with-hipaa-compliant-hosting-in-2026/) **Winners' Circle - 3/12/2026** [31 Years in the Cloud: Why Secure AI Infrastructure Is Healthcare's Next Frontier](https://www.youtube.com/watch?v=3tp7tOJKvJA&list=PLK-zrJbJ0LY8H6LEzalgLhAxesEjWBYu1&index=2.) **CyberNews - 3/5/2026** [Is Bare Metal Hosting Best for E-commerce?](https://cybernews.com/partner-content/is-bare-metal-hosting-best-for-e-commerce/) **Winning BIG - 3/3/2026** [The HIPAA-Compliant Cloud Crisis Nobody's Talking About (And How One Company Cracked It)](https://www.bintelligence.com/blog/the-hipaa-compliant-cloud-crisis-nobodys-talking-about-and-how-one-company-cracked-it) **CyberNews - 3/2/2026** [Best HIPAA-compliant web hosting (2026)](https://cybernews.com/best-web-hosting/hipaa-compliant-web-hosting/) **All Things Open - 3/3/2026** [Getting started with OpenClaw: Complex tasks from simple chat](https://allthingsopen.org/articles/getting-started-openclaw-autonomous-agent) **Healthcare Tech Outlook - 2/27/2026** [Why Healthcare Leaders Can't Treat HIPAA Hosting as an IT Afterthought](https://www.healthcaretechoutlook.com/cxoinsights/marty-puranik-nid-4883.html) **Data Center Frontier - 2/25/2026** [Aeroderivative Turbines Move to the Center of AI Data Center Power Strategy](https://www.datacenterfrontier.com/energy/article/55358731/aeroderivative-turbines-move-to-the-center-of-ai-data-center-power-strategy) **Market Research Future - 2/15/2026** [High Availability Server Market](https://www.marketresearchfuture.com/reports/high-availability-server-market-26540) **Investors Hangout - 01/13/2026** [Tech Trends Influencing AI and Cybersecurity by 2026](https://investorshangout.com/predictions-for-the-future-navigating-tech-trends-in-2026-500313-/) **Tech Radar Pro - 02/11/2026** [Powerful cloud hosting at affordable prices](https://www.techradar.com/pro/website-hosting/atlantic-net-review) **Market Research Future - 2/2/2026** [Top Industry Leaders in the High Availability Server Market Companies](https://www.marketresearchfuture.com/reports/high-availability-server-market/companies) **VMblog, 1/28/2026** [Atlantic.Net 2026: Six Tech Predictions That Will Shape AI, Cybersecurity, and Infrastructure](https://vmblog.com/archive/2026/01/28/atlantic-net-2026-six-tech-predictions-that-will-shape-ai-cybersecurity-and-infrastructure.aspx) **Yahoo! Finance, 1/13/2026** [Ten Tech Predictions That Will Shape AI, Cybersecurity, and Infrastructure in 2026](https://finance.yahoo.com/news/atlantic-net-ceo-ten-tech-123100798.html?guccounter=1) **Healthcare Business Today, 1/9/2026** [From Legacy to Resiliency: A Roadmap for Modernizing Healthcare Infrastructure Securely](https://www.healthcarebusinesstoday.com/healthcare-it-hipaa-cloud-migration/) **Consumer Affairs, 1/7/2026** [Public WiFi mistakes that could leave your personal data wide open](https://www.consumeraffairs.com/news/public-wifi-mistakes-that-could-leave-your-personal-data-wide-open-010726.html) **Part B News, 12/31/2025** [PBN eyes the future: AI growth, fee-based practice changes, compliance concerns and more](https://pbn.decisionhealth.com/Articles/Detail.aspx?id=550145) **Straits Research, 12/27/2025** [Cloud Infrastructure Service Market Size & Outlook, 2025-2033](https://straitsresearch.com/report/cloud-infrastructure-service-market) **Straits Research, 12/27/2025** [Atlantic.Net in the Global Cloud Infrastructure Service Market](https://straitsresearch.com/article/atlantic-net-in-the-global-cloud-infrastructure-service-market) **DesignRush, 12/26/2025** [AI’s Hidden Risk: 91% of Organizations Admit Cloud Gaps Amid Growing AI Threats](https://news.designrush.com/ai-security-cloud-risks-bare-metal) **Straits Research, 12/17/2025** [Healthcare Cloud Infrastructure Market Size & Outlook, 2025-2033](https://straitsresearch.com/report/healthcare-cloud-infrastructure-market) **Straits Research, 12/17/2025** [Atlantic.Net’s Role in the Evolving Healthcare Cloud Infrastructure Market](https://straitsresearch.com/article/atlantic-net-role-in-the-evolving-healthcare-cloud-infrastructure-market) **Muncie Voice, 12/14/2025** [Social Media Poses Hack Risks to Businesses](https://muncievoice.com/37765/social-media-poses-hack-risks-to-businesses/) **Inkl, 12/12/2025** [Cyber Expert Reveals How Everyday Social Media Posts Can Turn Small Firms Into Hacker Targets](https://www.inkl.com/news/cyber-expert-reveals-how-everyday-social-media-posts-can-turn-small-firms-into-hacker-targets?section=personalized) **International Business Times, 12/12/2025** [Cyber Expert Reveals How Everyday Social Media Posts Can Turn Small Firms Into Hacker Targets](https://www.ibtimes.co.uk/cyber-expert-reveals-how-everyday-social-media-posts-can-turn-small-firms-hacker-targets-1762360) **CoreSite, 12/8/2025** [Delivering Infrastructure that Enables Intense AI/ML Workloads](https://www.coresite.com/customer-stories/delivering-infrastructure-that-enables-intense-ai-ml-workloads) **Healthcare Business Today, 12/8/2025** [Securing the Internet of Medical Things: A Zero Trust Imperative](https://www.healthcarebusinesstoday.com/zero-trust-security-iomt-healthcare/#google_vignette) **Straits Research, 12/6/2025** [Bare Metal Cloud Market Size & Outlook, 2025-2033](https://straitsresearch.com/report/bare-metal-cloud-market) **Healthcare Focus, 12/5/2025** [Securing the Internet of Medical Things: A Zero Trust Imperative](https://www.healthcarebusinesstoday.com/zero-trust-security-iomt-healthcare/) **Straits Research, 12/5/2025** [Straits Research Recognizes Atlantic.Net as a Key Player in the Global Bare Metal Cloud Market](https://straitsresearch.com/article/atlantic-net-featured-in-bare-metal-cloud-report) **Unite.ai, 12/1/2025** [HIPAA and AI: What Healthcare Leaders Must Know Before Deploying Intelligent Tools](https://www.unite.ai/hipaa-and-ai-what-healthcare-leaders-must-know-before-deploying-intelligent-tools/) **Designrush, 11/28/2025** [Atlantic.Net Deepens Its Presence in $32.6B Sports Tech Market With Earthquakes Deal](https://news.designrush.com/atlanticnet-deepens-presence-326b-dollar-sports-tech-market-earthquakes-deal) **The Tech Musk - 11/27/2025** [Atlantic.Net CEO Reveals 10 Tech Predictions That Will Define AI, Cybersecurity, and Infrastructure in 2026](https://thetechmusk.com/atlantic-net-ceo-reveals-10-tech-predictions-that-will-define-ai-cybersecurity-and-infrastructure-in-2026/) **DevOps.com, 11/21/2025** [Three Strategies for Winning the AI Race With DevOps](https://devops.com/three-strategies-for-winning-the-ai-race-with-devops/) **Hipther, 11/18/2025** [Cybersecurity Expert Warns Of 6 Website Security Mistakes Leaving New Entrepreneurs Exposed](https://hipther.com/latest-news/2025/11/18/102698/cybersecurity-expert-warns-of-6-website-security-mistakes-leaving-new-entrepreneurs-exposed/0/) **Muncie Voice, 11/09/2025** [Businesses Face Cyberattacks This Holiday Season](https://muncievoice.com/37372/businesses-face-cyberattacks-this-holiday-season/) **CPA Practice Advisor, 10/31/2025** [6 Strategies to Protect SMBs From a Cyberattack This Holiday Season](https://www.cpapracticeadvisor.com/2025/10/31/6-strategies-to-protect-smbs-from-a-cyberattack-this-holiday-season/172078/) **Yahoo! Creators, 10/28/2025** [3 mistakes you’re making with airport Wi-Fi, and what to do instead, according to a cloud security expert](https://creators.yahoo.com/lifestyle/story/3-mistakes-youre-making-with-airport-wi-fi--and-what-to-do-instead-according-to-a-cloud-security-expert-024259790.html) **Travelling For Business, 10/27/2025** [Why You Should Never Connect to Free Airport WiFi, According to a Cloud Security Expert](https://travellingforbusiness.co.uk/advice/why-you-should-never-connect-to-free-airport-wifi-according-to-a-cloud-security-expert/) **11Alive News, 10/09/2025** [The Take | OpenAI-AMD deal could boost Atlanta tech](https://www.11alive.com/video/news/local/11alive-news-the-take-openaiamd-deal-could-boost-atlanta-tech-10925/85-bef7ffa9-ed8d-410b-8bc8-56c4ef21d527) **TechNewsWorld, 9/24/2025** [Secret Service Telecom Takedown Sparks Mobile Security Fears](https://www.technewsworld.com/story/secret-service-telcom-takedown-raises-concerns-about-mobile-net-security-179931.html) **Passionate Pulse Podcast - 9/23/2025** [https://www.youtube.com/watch?v=9IQnN6AT8sw](https://www.youtube.com/watch?v=9IQnN6AT8sw) **Data Bridge Market Research, 9/18/2025** [Global Bare Metal Cloud Market Size Report](https://www.databridgemarketresearch.com/reports/global-bare-metal-cloud-market) **Data Bridge Market Research, 9/18/2025** [Atlantic.Net Recognized in Data Bridge Market Research’s 2025 Prism Grid as a Niche Leader for Bare Metal Cloud](https://www.databridgemarketresearch.com/press-release/bare-metal-cloud-market) **Market Research Future, 9/7/2025** [Bare Metal Cloud Market Research Report](https://www.marketresearchfuture.com/reports/bare-metal-cloud-market-7032) **Market Research Future, 9/7/2025** [Bare Metal Cloud Market Companies: Leading Vendors](https://www.marketresearchfuture.com/reports/bare-metal-cloud-market/companies) **Markets and Markets, 9/5/2025** [Top Companies in Bare Metal Cloud Market - Oracle (US), AWS (US), IBM (US), Google (US) and Microsoft (US)](https://www.marketsandmarkets.com/ResearchInsight/bare-metal-cloud-market.asp) **Medical Economics, 8/26/2025** [How to ensure patient privacy in the cloud](https://www.medicaleconomics.com/view/how-to-ensure-patient-privacy-in-the-cloud) **All Things Open, 8/25/2025** [4 ways your company can support open source right now](https://allthingsopen.org/articles/4-ways-support-open-source-now) **Engineering News-Record, 8/19/2025** [Joule, Caterpillar Partner to Deliver Utah 4-GW Power and Hyperscale Computing Campus](https://www.enr.com/articles/61225-joule-caterpillar-partner-to-deliver-utah-4-gw-power-and-hyperscale-computing-campus) **Healthcare Business Today, 8/8/2025** [Healthcare Remains a Top Target for Cybersecurity Attacks: How to Ensure Your Cloud is Secure](https://www.healthcarebusinesstoday.com/healthcare-cybersecurity-cloud-security/) **All Things Open, 8/5/2025** [Why open source is critical for the continued advancement of new tech](https://allthingsopen.org/articles/open-source-future-tech-stack) **Tech Radar, 8/4/2025** [Is your cloud hosting ready for AI GPU accelerators?](https://www.techradar.com/pro/is-your-cloud-hosting-ready-for-ai-gpu-accelerators-here-are-5-things-you-need-to-know) **Reworked, 7/25/2025** [SharePoint ToolShell Attack Triggers Urgent Need to Rethink On-Prem Defense](https://www.reworked.co/information-management/sharepoint-toolshell-attack-triggers-urgent-need-to-rethink-on-prem-defense/) **AI Journal, 7/11/2025** [Leveraging AI in the Cloud: Compliance Challenges under HIPAA](https://aijourn.com/leveraging-ai-in-the-cloud-compliance-challenges-under-hipaa/) **Markets and Markets, 6/30/2025** [Top Companies in Cloud Computing Market - Google (US), Salesforce (US), Microsoft (US), AWS (US), and Oracle (US)](https://www.marketsandmarkets.com/ResearchInsight/cloud-computing-market.asp) **Fox 5 Atlanta, 6/23/2025** [South Fulton weighs pros, cons of data centers](https://www.fox5atlanta.com/news/south-fulton-debates-economic-gains-environmental-costs-new-data-centers) **AI Journal, 6/13/2025** [How AI Is Transforming the Medical Field and Improving Our Health](https://aijourn.com/how-ai-is-transforming-the-medical-field-and-improving-our-health/) **Medical Economics, 5/28/2025** [Your data, your patients, your future: Why health care needs the cloud](https://www.medicaleconomics.com/view/your-data-your-patients-your-future-why-health-care-needs-the-cloud) **WSBTV.com, 5/16/2025** [Cox Communications, Charter combining in major deal](https://www.wsbtv.com/news/local/atlanta/cox-communications-charter-combining-major-deal/SHBCIBLZRVHSTABQTONQC3WFLA/) **Yahoo! Finance, 5/16/2025** [Cox Communications, Charter combining in major deal](https://finance.yahoo.com/news/cox-communications-charter-combining-major-121952871.html?guccounter=1) **MSN, 5/16/2025** [Cox Communications, Charter combining in major deal](https://www.msn.com/en-us/money/topstocks/cox-communications-charter-combining-in-major-deal/vi-AA1EVfoM) **Website Planet, 5/16/2025** [From Dorm Room to Data Centers](https://www.websiteplanet.com/blog/interview-atlanticnet/) **Healthcare Business Today - 5/4/2025** [How AI Can Help With HIPAA Compliance Auditing](https://www.healthcarebusinesstoday.com/ai-hipaa-compliance-auditing-solutions/) **Silicon Valley Business Journal - 2/25/2025** [Quakes partner with global cloud service provider](https://www.bizjournals.com/sanjose/news/2025/02/25/sj-earthquakes-partnership-atlantic-net.html) **HIPAAHQ - 6/1/2024** [Choosing a HIPAA Compliant Website Builder](https://www.hipaahq.com/choosing-a-hipaa-compliant-website-builder/) **TechTarget - 5/23/2024** [Managing Databases in a Hybrid Cloud: 8 Key Considerations](https://www.techtarget.com/searchdatamanagement/tip/Managing-databases-in-a-hybrid-cloud-key-considerations) **Technology - 5/21/2024** [Performing PCI Compliance Testing](https://www.technology.org/2024/05/21/how-to-perform-pci-compliance-testing/) **HIPAAHQ - 2/23/2024** [Most Common HIPAA Violations](https://www.hipaahq.com/the-most-common-hipaa-violations-and-penalties-and-how-to-avoid-them/) **HIPAAHQ - 2/23/2024** [Most Common Violations and Penalties](https://www.hipaahq.com/the-most-common-hipaa-violations-and-penalties-and-how-to-avoid-them/) **Tech Day Asia - 2/1/2024** [Atlantic.Net opens Singapore data centre amidst cloud investment surge](https://datacenternews.asia/story/atlantic-net-opens-singapore-data-centre-amidst-cloud-investment-surge) **GrabHosts - 1/5/2024** [Atlantic.Net Review 2024: Performance, Pricing, & Support](https://grabhosts.net/atlantic-net-review/) **Mobile App Daily - 12/12/2023** [What are the PCI violations and penalties](https://www.mobileappdaily.com/feed/what-are-the-pci-violations-and-penalties) **Network World - 12/5/2023** [EU approves $1.3B in aid for cloud, edge computing](https://www.networkworld.com/article/1251281/eu-approves-1-3b-in-aid-for-cloud-edge-computing.html) **Fox 23 Tulsa - 12/2/2023** [How damaging are cyberattacks to big organizations?](https://www.fox23.com/news/how-damaging-are-cyberattacks-to-big-organizations/article_c4789aae-918e-11ee-a26e-172ecb0e79d1.html) **Cyber Security Intelligence - 10/17/2023** [The Expensive Costs Of HIPAA Noncompliance & How To Avoid Them](https://www.cybersecurityintelligence.com/blog/the-expensive-costs-of-hipaa-noncompliance-and-how-to-avoid-them-7248.html) **CyberDB - 10/5/2023** [What Evidence Do You Need to Demonstrate HIPAA Compliance?](https://www.cyberdb.co/what-evidence-do-you-need-to-demonstrate-hipaa-compliance/) **Ranktracker - 9/23/2023** [Website Security & Protection: How to Secure a WordPress Website](https://www.ranktracker.com/blog/website-security-protection-how-to-secure-a-word-press-website/) **WebDesign.org - 8/25/2023** [What are the major changes in PCI DSS 4.0 that impact your business?](https://www.webdesign.org/what-are-the-major-changes-in-pci-dss-4-0-that-impact-your-business.23766.html) **Tech Times, 07/13/2023** [How to Solve the Challenges of PCI Compliance for Small Businesses](https://www.techtimes.com/articles/293756/20230713/how-to-solve-the-challenges-of-pci-compliance-for-small-businesses.htm) **Tech Times, 06/15/2023** [Top 5 HIPAA-compliant Hosting Providers in 2023](https://www.techtimes.com/articles/292535/20230613/top-5-hipaa-compliant-hosting-providers-2023.htm) **Hosting Seekers - 05/25/2023** [What Factors Should I Consider Before Moving to VPS Hosting?](https://www.hostingseekers.com/blog/when-it-is-time-to-upgrade-to-vps-hosting/) **Paubox - 05/15/2023** [HIPAA compliant WordPress hosting; A comprehensive guide 2023](https://www.paubox.com/blog/hipaa-compliant-wordpress-hosting-a-comprehensive-guide-2023) **Cloud Tweaks - 05/12/2023** [Atlantic.Net Cloud Platform Offers Cloud-Based Hosting Solutions](https://cloudtweaks.com/2023/05/atlantic-net-platform-acp-hosting/) **WP Daily Themes - 05/11/2023** [Top HIPAA WordPress Hosting](https://www.wpdailythemes.com/review/top-hipaa-wordpress-hosting/) **HIT Consultant- 4/26/2023** [What Is A HIPAA-Compliant Infrastructure?](https://hitconsultant.net/2023/04/26/hipaa-compliant-infrastructure/) **Host Search - 04/21/2023** [Eight Benefits of Choosing VPS Hosting for Your Business](https://www.hostsearch.com/articles/eight-benefits-of-choosing-vps-hosting-for-your-business.asp) **Healthcare Business Today - 4/21/2023** [Eight Benefits of Chosing VPS Hosting for Your Business](https://www.hostsearch.com/articles/eight-benefits-of-choosing-vps-hosting-for-your-business.asp/) **Updated Land - 4/20/2023** Atlantic.Net Review: Best HIPAA-Compliant Hosting **Healthcare Business Today - 4/11/2023** [How to check if your server hosting is HIPAA compliant](https://www.healthcarebusinesstoday.com/how-to-check-if-your-server-hosting-is-hipaa-compliant/) **CPA Praactice Advisor - 2/8/2023** [How to Securely Host ePHI on a Public-Facing Website](https://www.cpapracticeadvisor.com/2022/09/29/the-pros-and-cons-of-offsite-data-storage/70928/) **hipaahq.com - 1/13/2023** [How to Securely Host ePHI on a Public-Facing Website](https://www.hipaahq.com/how-to-securely-host-ephi-on-a-public-facing-website/) **healthtechzone.com - 9/6/2022** [Why Are HIPAA Risk Assessments Important?](https://www.healthtechzone.com/topics/healthcare/articles/2022/09/06/453396-why-hipaa-risk-assessments-important.htm) **Host Search, 08/05/2022** [Four Reasons to Use Dedicated Hosting for Headless Commerce](https://www.hostsearch.com/articles/four-reasons-to-use-dedicated-hosting-for-headless-commerce.asp) **Cloud Tweaks, 08/04/2022** [What’s the difference between a shared server and a dedicated server?](https://cloudtweaks.com/2022/08/shared-server-vs-dedicated-server/) **TMC Net, 08/03/2022** [What are Virtual Private Servers and What are Their Benefits?](https://www.tmcnet.com/topics/articles/2022/08/03/453097-what-virtual-private-servers-what-their-benefits.htm) **Electronic Health Reporter, 7/21/2022** [How To Avoid the High Cost of HIPAA Noncompliance](https://electronichealthreporter.com/how-to-avoid-the-high-cost-of-hipaa-noncompliance/) **Health IT Answer, 07/15/2022** [Top Considerations when Choosing a HIPAA Hosting Provider](https://www.healthitanswers.net/top-considerations-when-choosing-a-hipaa-hosting-provider/) **AHIMA Journal 06/28/ 2022** [Maintaining Compliance: Data Challenges for IoMT Devices](https://journal.ahima.org/page/maintaining-compliance-data-challenges-for-iomt-devices) **G2.com 06/28/2022** [What Is PIPEDA? Everything You Need to Know for Compliance](https://learn.g2.com/pipeda) **IS Partners 06/22/2022** [Protecting Patient Records and Transforming Healthcare in the Cloud](https://www.ispartnersllc.com/blog/protecting-patients-records-compliance-cloud/) **Patient Calls 06/14/2022** [What to Look for in a Business Associate Agreement](https://www.patientcalls.com/blog/hipaa-business-associate-agreement/) **Healthcare Business Today 06/10/2022** [Seven Very Common HIPAA Violations and How to Avoid Them](https://www.healthcarebusinesstoday.com/seven-very-common-hipaa-violations-and-how-to-avoid-them/) **Arkenea 05/27/2022** [A Comprehensive Guide To Telehealth HIPAA Compliance](https://arkenea.com/blog/telehealth-hipaa-compliance/) **Telehealth.org 05/08/2022** How to Effectively Compose a HIPAA Breach Notification **HostSearch 02/03/2022** [How RAID Arrays Improve Performance and Data Protection](https://www.hostsearch.com/articles/how-raid-arrays-improve-performance-and-data-protection.asp) **Techopedia 11/5/2021** [Techopedia How to Maintain HIPAA Compliance on a Budget](https://www.techopedia.com/how-to-maintain-hippa-compliance-on-a-budget/2/34587) **Health IT Answers 10/11/2021** [Fight the Phish](https://www.healthitanswers.net/fight-the-phish/) **ISACA.org 10/6/2021** [Seven Tips for Protecting Your HIPAA Database](https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2021/seven-tips-for-protecting-your-hipaa-database) **VM Blog 10/1/2021** [Atlantic.Net 2022 Predictions: Threats to the Supply Chain and Cloud Compute to Dominate 2022](https://vmblog.com/archive/2021/10/01/atlantic-net-2022-predictions-threats-to-the-supply-chain-and-cloud-compute-to-dominate-2022.aspx#.YWWablVBxPb) **Paubox 9/22/2021** [Protecting patients records, maintaining compliance, and transforming healthcare in the cloud](https://www.paubox.com/blog/protecting-patients-records-maintaining-compliance-transforming-healthcare-cloud/) **Datacenters.com 9/17/2021** [9 Best Practices for Ensuring Cloud Compliance of Healthcare Data](https://www.datacenters.com/news/9-best-practices-for-ensuring-cloud-compliance-of-healthcare-data) **Host Advice 09/16/2021** [HostAdvice Speaks to Brett Haines of Atlantic.Net](https://hostadvice.com/blog/web-hosting/interviews/hostadvice-speaks-to-brett-haines-of-atlantic/) **IS Partners 09/11/2021** [Offsite Backup and Disaster Recovery for HIPAA Compliance in 2021](https://www.ispartnersllc.com/blog/offsite-backup-disaster-recovery-hipaa-compliance/) **Cyber News 9/5/2021** [Atlantic.Net review: should it be your next scaling partner?](https://cybernews.com/best-web-hosting/atlanticnet-review/) **Datacenters.com 8/26/2021** [Dedicated Cloud Hosts: Security and Compliance Considerations](https://www.datacenters.com/news/dedicated-cloud-hosts-security-and-compliance-considerations) **Cloud Zero 8/13/2021** [Cloud Agnostic: What Does It Really Mean](https://www.cloudzero.com/blog/cloud-agnostic) **Domain Informer 8/12/2021** [Why Is Disaster Recovery Needed for HIPAA Compliance?](https://www.domaininformer.com/guides/general_information/articles/210812-why-disaster-recovery-needed-hipaa-compliance) **Host Review 8/11/2021** [Guide To Healthcare Data Storage For HIPAA Compliance](https://www.hostreview.com/blog/210811-guide-to-healthcare-data-storage-for-hipaa-compliance) **Phone.com 8/5/2021** [HIPAA Compliant Video Calls: What you Should Know](https://www.phone.com/hipaa-compliant-video-calls-what-you-should-know/) **Cyber Defense Magazine 7/19/2021** [Exploring the Synergies Between HIPAA Compliance and Cybersecurity](https://www.cyberdefensemagazine.com/exploring-the-synergies/) **Drupal 6/30/2021** [Drupal How to Find the Best Solution for Drupal Hosting Requirements](https://www.drupal.org/association/supporters/blog/how-to-find-the-best-solution-for-drupal-hosting-requirements) **Drupal 6/30/2021** [Drupal Best Practices for a HIPAA Compliant Drupal Platform](https://www.drupal.org/association/supporters/blog/best-practices-for-a-hipaa-compliant-drupal-platform) **Blog Automox 6/25/2021** Automox Atlantic.Net Chooses Automox for Server and Patch Management **Security Boulevard 6/8/2021** [Security Boulevard Best Practices for Ransomware Defense](https://securityboulevard.com/2021/06/best-practices-for-ransomware-defense/) **Cyber Defense Magazine 6/1/2021** [Cyber Defense Magazine Exploring the Synergies Between HIPAA Compliance and Cybersecurity](https://www.cyberdefensemagazine.com/newsletters/june-2021/mobile/index.html) **Renal And Urology News 5/12/2021** [Renal and Nurology news HIPAA Needs to Keep Up With Information Technology](https://www.renalandurologynews.com/home/departments/hipaa-compliance/hipaa-privacy-rule-information-technology-protected-health-information/) **Chief Healthcare Executive 5/10/2021** [Chief Healthcare Executive How to Mitigate the Insider Threat to Healthcare](https://www.chiefhealthcareexecutive.com/view/how-to-mitigate-the-insider-threat-to-healthcare) **Security News Paper 4/28/2021** [Security Newspaper As cybercriminals exploit the covid-19 pandemic, what can you do to defend yourself?](https://www.securitynewspaper.com/2021/04/28/as-cybercriminals-exploit-the-covid-19-pandemic-what-can-you-do-to-defend-yourself/) **Website Planet 4/19/2021** [Atlantic.Net, a Market-Leading Hosting Provider](https://www.websiteplanet.com/blog/atlantic-net-interview/) **Hosting Data 4/16/2021** [How Secure is the Cloud](https://hostingdata.co.uk/how-secure-is-the-cloud/) **Electronic Health Reporter 4/15/2021** [How To Respond To A HIPAA Breach](https://electronichealthreporter.com/how-to-respond-to-a-hipaa-breach/) **Cyber Security Magazine 4/9/2021** [Cyberattackers are Exploiting the Pandemic, How Can You Prepare?](https://cybersecuritymagazine.com/cyberattackers-are-exploiting-the-pandemic-how-can-you-prepare/) **eLearning Industry 3/12/2021** [How To Create An eLearning Cybersecurity Plan](https://elearningindustry.com/how-to-create-elearning-cybersecurity-plan) **TMC Net 3/12/2021** [What is cloud computing?](https://cloud-computing.tmcnet.com/columns/articles/448271-what-cloud-computing.htm) **Health Tech Zone 3/12/2021** [What is Considered a HIPAA Breach in 2021?](https://www.healthtechzone.com/topics/healthcare/articles/2021/03/12/448269-what-considered-hipaa-breach-2021.htm) **Tech Zone 360 3/12/2021** [Shared vs VPS Hosting, Cloud vs VPS Hosting & VPS vs VPN: Know the Differences](https://www.techzone360.com/topics/techzone/articles/2021/03/12/448270-shared-vs-vps-hosting-cloud-vs-vps-hosting.htm) **VPLS 1/28/2021** [How to Counter the Insider Threat to Stay HIPAA Compliant](https://www.vpls.com/blog/insider-threat-hipaa-compliant/) **Arizona Telemedicine 1/28/2021** [How to Keep Your Telemedicine Platform HIPAA Compliant](https://telemedicine.arizona.edu/blog/how-keep-your-telemedicine-platform-hipaa-compliant-ehealth-rules-covid-generation) **UberSmith 1/22/2021** [SaaS, Cloud, or any business, when profitability matters!](https://ubersmith.com/a-valued-partnership-atlantic-net-ubersmith/) **Yahoo Finance 1/14/2021** [The Top Hosting Providers & Domain Registrars in 2021, According to DesignRush](https://finance.yahoo.com/news/top-hosting-providers-domain-registrars-114000828.html) **Medical Economics 12/3/2020** [Choosing a HIPAA Cloud Hosting Provider: What are the Key Factors?](https://www.medicaleconomics.com/view/choosing-a-hipaa-cloud-hosting-provider) **ISACA 12/2/2020** [Security and Compliance: What to Expect in 2021](https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/security-and-compliance-what-to-expect-in-2021) **ProviderTech 11/3/2020** [7 Tips for Preventing the Most Common HIPAA Violations](https://www.providertech.com/7-tips-for-preventing-the-most-common-hipaa-violations/) **Electronic Health Reporter 10/21/2020** [Why Are HIPAA Risk Assessments Important?](https://electronichealthreporter.com/why-are-hipaa-risk-assessments-important/) **VMblog 10/16/2020** [In 2021, US Healthcare Organizations will rapidly propel IT workloads to the Cloud](https://vmblog.com/archive/2020/10/16/atlantic-net-2021-predictions-us-healthcare-organizations-will-rapidly-propel-it-workloads-to-the-cloud.aspx#.X4mVfu1OmGg) **VPS BenchMarks 10/8/2020** [What Are the Greatest Security Threats To Your Dedicated Server Hosting Platform?](https://www.vpsbenchmarks.com/posts/how_do_cloud_providers_protect_you_from_the_greatest_security_threats_to_a_vps) **Serchen 10/7/2020** [How to Improve Enterprise Server Management](https://blog.serchen.com/how-to-improve-enterprise-server-management/) **HITECH Answers 10/5/2020** [Cybersecurity Awareness Month: If You Connect It, Protect It](https://www.healthitanswers.net/if-you-connect-it-protect-it/) **ComplianceOnline 9/29/2020** [What Should a HIPAA Data Backup Plan Look Like?](https://www.complianceonline.com/resources/hipaa-data-backup-plan.html?channel=RES_HEALTHCARE) **Serchen 09/10/2020** [Phishing, Spoofing, and Whaling: Tips for Staying Safe](https://blog.serchen.com/phishing-spoofing-and-whaling-tips-for-staying-safe/) **Rick's Cloud 09/02/2020** [Cloud vs Dedicated Hosting: Which Is Right For Me?](https://rickscloud.com/cloud-hosting-vs-dedicated-hosting-which-is-right-for-me/) **Ecommerce Times 08/25/2020** [5 Cloud Trends for 2020 and Beyond](https://www.ecommercetimes.com/story/86816.html) **VPN Ranks 08/17/2020** [You've Been Hit with Ransomware, What Now?](https://www.vpnranks.com/blog/youve-been-hit-with-ransomware-what-now/) **CloudTweaks 08/14/2020** [What is the Difference Between a VPS and a Cloud VPS?](https://cloudtweaks.com/2020/08/difference-between-vps-and-cloud-vps/) **Health IT Answers 08/05/2020** [Why Encryption is Essential in Healthcare Cybersecurity Strategies](https://www.healthitanswers.net/why-encryption-is-essential-in-healthcare-cybersecurity-strategies/) **Cyber Defense Magazine 07/06/2020** [7 Security Precautions to Protect Remote Workers During the COVID-19 Pandemic](https://www.cyberdefensemagazine.com/7-security-precautions/) **CPO Magazine 06/24/2020** [How Will 5G Change Your Enterprise Threat Model?](https://www.cpomagazine.com/cyber-security/how-will-5g-change-your-enterprise-threat-model/) **HIPAA HQ 06/18/2020** [How Can You Maintain HIPAA Compliance When Accessing Information on Your Devices?](https://www.hipaahq.com/how-can-you-maintain-hipaa-compliance-when-accessing-information-on-your-devices/) **Jotform 05/27/2020** [How to Maintain HIPAA Compliance in a Remote Work Environment](https://www.jotform.com/blog/hipaa-compliant-remote-work/) **Secure Blitz 05/15/2020** [Most Effective Cybersecurity Strategy For A Small Business](https://secureblitz.com/effective-cybersecurity-strategy-for-a-small-business/) **Dzone 04/30/2020** [13 Ways to Secure Your Cloud VPS](https://dzone.com/articles/13-ways-to-secure-your-cloud-vps) **Threat Stack 04/29/2020** [Experts & AppSec Professionals Reveal the Biggest AppSec Compliance Mistakes](https://www.threatstack.com/blog/18-compliance-experts-application-security-professionals-reveal-the-biggest-compliance-related-mistakes-companies-are-making-when-it-comes-to-application-security-monitoring) **Security Magazine 04/22/2020** [Important Questions to Answer Before Paying a Ransomware Demand](https://www.securitymagazine.com/articles/92200-important-questions-to-answer-before-paying-a-ransomware-demand) **IT Pro 04/02/2020** [How technology is changing health care](https://www.itpro.co.uk/marketing-comms/communications/355204/how-technology-is-changing-healthcare) **Forbes 03/26/2020** [Amazon Files Objection To DoD Motion To Revise Microsoft JEDI Decision](https://www.forbes.com/sites/waynerash/2020/03/26/amazon-files-objection-to-dod-motion-to-revise-microsoft-jedi-decision/) **Fortune 03/18/2020** [How hackers are exploiting the coronavirus, and how to protect yourself](https://fortune.com/2020/03/18/hackers-coronavirus-cybersecurity/) **AIThority 03/17/2020** [Is the Coronavirus Threat Forcing Businesses to Create a Remote Workforce?](https://www.aithority.com/guest-authors/is-the-coronavirus-threat-forcing-businesses-to-create-a-remote-workforce/) **International Business Times 03/16/2020** [U.S. Health And Human Services Department Hit By Cyberattack As Concerns Over The Coronavirus Continue](https://www.ibtimes.com/us-health-human-services-department-hit-cyberattack-concerns-over-coronavirus-2940983) **Media Post 02/29/2020** [Cocooning From Coronavirus To Boost Ecommerce, Advertising Platforms, Local Search](https://www.mediapost.com/publications/article/347774/cocooning-from-coronavirus-to-boost-ecommerce-adv.html) **Information Age 02/26/2020** [Tech titans in arms race to win JEDI cloud war](https://www.information-age.com/tech-titans-arms-race-win-jedi-cloud-war-123487919/) **VMBlog 02/19/2020** [Does the empire strike back when we learn what happens to the $10 billion JEDI contract?](https://vmblog.com/archive/2020/02/19/does-the-empire-strike-back-when-we-learn-what-happens-to-the-10-billion-jedi-contract.aspx) **Inverse 02/15/2020** [Amazon Is Fighting Microsoft Tooth-and-nail Over A Pentagon Contract](https://www.inverse.com/innovation/amazon-gets-judge-to-halt-microsofts-contract-with-the-pentagon) **WebMD 02/05/2020** [Coronavirus Rumor Mill Rampant With Bogus News](https://www.webmd.com/lung/news/20200205/coronavirus-rumor-mill-rampant-with-bogus-news) **USA TODAY 02/03/2020** [Hackers are using coronavirus fears to send you a computer virus: How to stop them](https://www.usatoday.com/story/tech/2020/02/03/hackers-use-coronavirus-spread-computer-viruses-inject-malware/4644439002/) **Data Center Knowledge 01/21/2020** [Should Data Centers Have Common Physical Infrastructure Security Standards?](https://www.datacenterknowledge.com/security/should-data-centers-have-common-physical-infrastructure-security-standards) **The Entrepreneur Way 01/13/2020** [Getting out There and Doing it Yourself with Marty Puranik Founder and Owner of Atlantic](https://theentrepreneurway.com/podcast/1440-getting-out-there-and-doing-it-yourself-with-marty-puranik-founder-and-owner-of-atlantic/) **Enterprise AI 01/08/2020** [Machine Learning, Clouds & Pills: Biopharma AI’s Big Impact](https://www.enterpriseai.news/2020/01/08/machine-learning-clouds-pills-biopharma-ais-big-impact/) **Data Center Knowledge 01/07/2020** [Say Goodbye to Windows Server 2008, and Hello to Azure?](https://www.datacenterknowledge.com/security/say-goodbye-windows-server-2008-and-hello-azure) **CPO Magazine 12/10/2019** [How Can Enterprises Win the Cybersecurity Arms Race?](https://www.cpomagazine.com/cyber-security/how-can-enterprises-win-the-cybersecurity-arms-race/) **Forbes 12/02/2019** [What Is The Cost Of A Data Breach?](https://www.forbes.com/sites/forbestechcouncil/2019/12/02/what-is-the-cost-of-a-data-breach/#548a42ec29e7) **Forbes 11/22/2019** [Bluetooth Hacks Keep Evolving, Will Your Cybersecurity Strategy?](https://www.infosecurity-magazine.com/opinions/bluetooth-hacks-strategy/) **Forbes 10/31/2019** [Defense Win By Microsoft To Boost All Cloud Services](https://www.forbes.com/sites/waynerash/2019/10/31/defense-win-by-microsoft-to-boost-all-cloud-services/#1f64fa3f72a8) **Cloud Tech 10/25/2019** [If your enterprise is still on the fence around cloud - here's what you need to know today](https://www.cloudcomputing-news.net/news/2019/oct/25/if-your-enterprise-still-fence-around-cloud-heres-what-you-need-know-today/) **Jotform 10/24/2019** [The Insider Threat to HIPAA Compliance: Data Breach](https://www.jotform.com/blog/insider-threat-to-hipaa-compliance-data-breach/) **Security Magazine 10/24/2019** [Why Enterprises Cannot Afford to Ignore AI and Emergent Technology in Their Cybersecurity Strategy](https://www.securitymagazine.com/articles/91143-why-enterprises-cannot-afford-to-ignore-ai-and-emergent-technology-in-their-cybersecurity-strategy) **Data Center Knowledge 10/23/2019** [Survey: Most Enterprises Still Blame End-User Incompetence for Security Lapses](https://www.datacenterknowledge.com/security/survey-most-enterprises-still-blame-end-user-incompetence-security-lapses) **Forbes 10/18/2019** [16 IT Architecture 'Red Flags' That Signal You're Due For An Overhaul](https://www.forbes.com/sites/forbestechcouncil/2019/10/18/16-it-architecture-red-flags-that-signal-youre-due-for-an-overhaul/#1b89d0031609) **Ecommerce Times 10/02/2019** [Leaked Audio Reveals Zuckerberg Spinning Hard](https://www.ecommercetimes.com/story/86270.html) **Technews World 10/01/2019** [Congress Eyes Google's Chrome Encryption Plans](https://www.technewsworld.com/story/86268.html) **Chat Bots Journal 10/01/2019** [Business Not Keeping Up With AR/VR Have A Lot To Lose!](https://chatbotsjournal.com/business-not-keeping-up-with-ar-vr-have-a-lot-to-lose-1a64b0e5040a) **Medcity News 09/29/2019** [The Importance of HIPAA Risk Assessments](https://medcitynews.com/2019/09/the-importance-of-hipaa-risk-assessments/) **Toolbox 09/26/2019** [6 Trends in Server Management You’ll See in 2020](https://www.toolbox.com/blogs/peterkowalke/6-trends-in-server-management-youll-see-in-2020-092519) **Jotform 09/23/2019** [Data Security Training: Your Workforce Reference Guide](https://www.jotform.com/blog/data-security-training/) **Forbes 09/19/2019** [Tech Perspective: 13 Common Business Discussions Tech Experts Should Be In On](https://www.forbes.com/sites/forbestechcouncil/2019/09/19/tech-perspective-13-common-business-discussions-tech-experts-should-be-in-on/#5784ae5a639f) **Electronic Health Reporter 09/17/2019** [What is Considered a HIPAA Breach in 2019?](https://electronichealthreporter.com/what-is-considered-a-hipaa-breach-in-2019/) **Get Referralmd 09/16/2019** [Do You Have a HIPAA Data Backup Plan?](https://getreferralmd.com/2019/09/do-you-have-a-hipaa-data-backup-plan/) **Washington Examiner 09/12/2019** [5G comes with unique security risks](https://www.washingtonexaminer.com/policy/5g-comes-with-unique-security-risks) **Hipaahq 09/10/2019** [Can Wearables Be HIPAA Compliant?](https://www.hipaahq.com/can-wearables-be-hipaa-compliant/) **Varonis 09/09/2019** [52 Key Cybersecurity Tips: Your Playbook for Unrivaled Security](https://www.varonis.com/blog/cybersecurity-tips/) **Forbes 09/09/2019** [Staying Ahead Of Ever-Changing Data Compliance Regulations: 13 Tips From Tech Experts](https://www.forbes.com/sites/forbestechcouncil/2019/09/09/staying-ahead-of-ever-changing-data-compliance-regulations-13-tips-from-tech-experts/#447e2e6f2a0f) **Rasmussen 09/09/2019** [What Is Cyber Security? A Beginner’s Guide](https://www.rasmussen.edu/degrees/technology/blog/what-is-cyber-security/) **Eccouncil 09/06/2019** [HOW SECURE ARE YOUR OFFICE’S BLUETOOTH DEVICES, REALLY?](https://blog.eccouncil.org/how-secure-are-your-offices-bluetooth-devices-really/) **Forbes 08/30/2019** [How To Choose A Secure And Reliable Virtual Private Network: 12 Tips From Tech Experts](https://www.forbes.com/sites/forbestechcouncil/2019/08/30/how-to-choose-a-secure-and-reliable-virtual-private-network-12-tips-from-tech-experts/#2556921c349d) **Redneck 08/20/2019** [WHAT IS CYBER SECURITY? THE FACTS YOU NEED TO KNOW ABOUT THIS FAST-GROWING FIELD](https://www.redneck-puters.com/what-is-cyber-security-the-facts-you-need-to-know-about-this-fast-growing-field/) **Fitsmallbusiness 08/20/2019** [Cyber Insurance Coverage Checklist](https://fitsmallbusiness.com/cyber-insurance-coverage-checklist/) **Searchaws 08/15/2019** [What you need to know about Cloudera vs. AWS for big data](https://searchaws.techtarget.com/feature/What-you-need-to-know-about-Cloudera-vs-AWS-for-big-data) **Malcare 08/06/2019** [Building A HIPAA Compliant Website(Beginner’s Guide)](https://www.malcare.com/blog/hipaa-compliant-website/) **Forbes 08/05/2019** [Can AI Be Used To Bolster Cybersecurity?](https://www.forbes.com/sites/forbestechcouncil/2019/08/05/can-ai-be-used-to-bolster-cybersecurity/#635d08b27e1e) **Zdnet 08/01/2019** [How industry cloud technology is changing healthcare](https://www.zdnet.com/article/how-industry-cloud-technology-is-changing-healthcare/) **Theranest 07/23/2019** [How to Stay HIPAA Compliant in the World of Social Media](https://www.theranest.com/blog/how-to-stay-hipaa-compliant-in-the-world-of-social-media/) **Digitalguardian 07/15/2019** [Social Engineering Attacks: Common Techniques & How to Prevent an Attack](https://digitalguardian.com/blog/social-engineering-attacks-common-techniques-how-prevent-attack) **Reckontalk 07/13/2019** [How Hosting Services Can Propel Your Business To The Next Level](https://www.reckontalk.com/how-hosting-services-can-propel-your-business/) **Analyticsinsight 07/02/2019** [AUGMENTED REALITY SHOULD BE A PART OF YOUR NEW BUSINESS STRATEGY](https://www.analyticsinsight.net/augmented-reality-should-be-a-part-of-your-new-business-strategy/) **Disruptordaily 06/29/2019** [What Technology Will Most Impact The Future Of Healthcare?](https://www.disruptordaily.com/healthcare-technology-trends/) **Thomasnet 06/27/2019** [How to Protect Your Manufacturing Assets Against the Growing Threat of Cybercrime](https://www.thomasnet.com/insights/how-to-protect-your-manufacturing-assets-against-the-growing-threat-of-cybercrime/) **Opploans 06/27/2019** [Watch Out for Phishing!](https://www.opploans.com/blog/watch-out-for-phishing/) **Safeopedia 06/24/2019** [Straight From the Experts: How Will AI Fit Into Health and Safety in the Workplace?](https://www.safeopedia.com/straight-from-the-experts-how-will-ai-fit-into-health-and-safety-in-the-workplace/2/8092) **Hitechanswers 06/19/2019** [Is HIPAA Physical Security just as Important as HIPAA Cybersecurity?](https://www.hitechanswers.net/is-hipaa-physical-security-just-as-important-as-hipaa-cybersecurity/) **Forbes 06/18/2019** [12 Not-So-Obvious Lessons All Industries Can Learn From Big Tech](https://www.forbes.com/sites/forbestechcouncil/2019/06/18/12-not-so-obvious-lessons-all-industries-can-learn-from-big-tech/#3830041d1785) **Gartner 06/17/2019** [Market Guide for Cloud Service Providers to Healthcare Delivery Organizations](https://www.gartner.com/en/documents/3939839) **HIPAA HQ 06/14/2019** [What is HIPAA Compliant Secure Email?](https://www.hipaahq.com/what-is-hipaa-compliant-secure-mail/) **Learn G2 06/14/2019** [13 Cyber Security Tips From the Experts](https://learn.g2.com/cyber-security-tips) **Lightedge 06/11/2019** [Healthcare IoT Adoption in the HIPAA Compliance Landscape](https://www.lightedge.com/blog/healthcare-iot-adoption/) **Hostingpill 06/10/2019** [Atlantic.Net Review (2019): Is It The Best Choice?](https://hostingpill.com/hosting-reviews/atlantic-net/) **Prweb 06/06/2019** [2019 MedTech Breakthrough Awards Recognize "Breakthrough" Digital Health and Medical Technology Products and Companies](https://www.prweb.com/releases/2019_medtech_breakthrough_awards_recognize_breakthrough_digital_health_and_medical_technology_products_and_companies/prweb16358422.htm) **Hitconsultant 06/06/2019** [2019 MedTech Breakthrough Award Category Winners Announced](https://hitconsultant.net/2019/06/06/medtech-breakthrough-award-winners/#.XUCRtZMza-q) **Upjourney 06/06/2019** [How Has Technology Changed Our Lives](https://upjourney.com/how-has-technology-changed-our-lives) **Temboo 06/05/2019** [A Fantastic Voyage Into the Internet of Medical Things](https://blog.temboo.com/internet-of-medical-things-iomt/) **MRC Productive 05/23/2019** [5 IT trends to watch in 2019 and beyond](https://www.mrc-productivity.com/blog/2019/05/5-it-trends-to-watch-in-2019-and-beyond/) **Reddit 05/15/2019** [I'm a Managing Consultant who performs HIPAA Compliance and Cybersecurity Audits](https://www.reddit.com/r/technology/comments/bp0fim/im_a_managing_consultant_who_performs_hipaa/) **Digital Guardian 04/30/2019** [The Best Tools & Techniques for Employee Security Awareness Training](https://digitalguardian.com/blog/best-tools-techniques-employee-security-awareness-training) **Telebehavioral Health Institute 04/30/2019** [Why Healthcare Data is a Common Target for Hackers](https://telehealth.org/blog/healthcare-data/) **Digital Guardian 04/26/2019** [Social Engineering Attacks: Common Techniques & How to Prevent an Attack](https://digitalguardian.com/blog/social-engineering-attacks-common-techniques-how-prevent-attack) **Dinezh.com 04/23/2019** [4 of the Most At-Risk Industries for Cyber Attacks](https://dinezh.com/4-of-the-most-at-risk-industries-for-cyber-attacks/) **Forbes 04/19/2019** [4 of the Most At-Risk Industries for Cyber Attacks](https://www.forbes.com/sites/forbestechcouncil/2019/04/19/15-tech-experts-predict-the-next-big-topics-in-encryption-and-cybersecurity/#721699fe134c) **Ecommerce Times 04/16/2019** [Hackers Use Microsoft Help Desk to Pull Off Massive Email Breach](https://www.ecommercetimes.com/story/Hackers-Use-Microsoft-Help-Desk-to-Pull-Off-Massive-Email-Breach-85958.html) **Done Deal WholeSale 04/16/2019** [Hackers Use Microsoft Help Desk to Pull Off Massive Email Breach](https://donedealwholesale.com/2019/04/hackers-use-microsoft-help-desk-to-pull-off-massive-email-breach/) **My Corporation 04/11/2019** [Go Green All Year Long, Business Owners](https://blog.mycorporation.com/2019/04/go-green-business-owners/) **Bit Rebels 04/11/2019** [How To Protect Your Brand Online](http://www.bitrebels.com/business/how-to-protect-your-brand-online/) **Cyberflorida 04/11/2019** [How to Protect Your Network Through Penetration Testing](https://cyberflorida.org/2019/04/11/how-to-protect-your-network-through-penetration-testing/) **Paubox 04/09/2019** [How to Ensure Your Employees Aren’t a Threat to HIPAA Compliance](https://www.paubox.com/blog/how-to-ensure-your-employees-arent-a-threat-to-hipaa-compliance) **Jotform 04/02/2019** [How Can You Prevent Medical Identity Theft](https://www.jotform.com/blog/how-can-you-prevent-medical-identity-theft/) **BestCompany 03/27/2019** [2019 Identity Theft and Scam Trends: Part 2](https://bestcompany.com/identity-theft/blog/2019-identity-theft-and-scam-trends-part-2) **BestCompany 03/27/2019** [2019 Identity Theft and Scam Trends: Part 1](https://bestcompany.com/identity-theft/blog/2019-identity-theft-and-scam-trends) **Forbes 03/26/2019** [Are Current HIPAA Regulations Enough To Protect Sensitive Data?](https://www.forbes.com/sites/forbestechcouncil/2019/03/26/are-current-hipaa-regulations-enough-to-protect-sensitive-data/#6851df965839) **RT Insights | Real Time Business Insights 03/19/2019** [How Edge Computing Can Lead to the First Real Smart City](https://www.rtinsights.com/how-edge-computing-can-lead-to-the-first-real-smart-city/) **Hfma.org Mar 2019** [The ROI of HIPAA Compliance](https://www.hfma.org/Content.aspx?id=63162) **Healthcare Business Today 03/10/2018** [Nine Fundamentals of Mobile Device Management](https://www.healthcarebusinesstoday.com/nine-fundamentals-of-mobile-device-management/) **HipaaHQ 2019** [Keys to a HIPAA Compliant Cloud](https://www.hipaahq.com/keys-to-a-hipaa-compliant-cloud/) **IOT for All 03/06/2019** [IoT Security by Design](https://www.iotforall.com/iot-security-by-design/) **Healthcare Business Today 03/05/2019** [HIPAA Compliance in the Era of Cloud](https://www.healthcarebusinesstoday.com/hipaa-compliance-in-the-era-of-cloud/) **Slidedeck 03/04/2019** [Cheap vs. Premium Hosting (Is the Higher Cost Justified?)](https://www.slidedeck.com/premium-hosting/) **hfma 03/01/2019** [HIPAA IT Predictions for 2019](https://www.hfma.org/Content.aspx?id=62818) **ReferralMD Mar 2019** [Blockchain and IoHT: Disrupting and Impacting Healthcare](https://getreferralmd.com/2019/03/blockchain-and-ioht-disrupting-and-impacting-healthcare/) **ISACA 2019** [Protecting Patient Records in 2019 and Beyond](http://www.isaca.org/Knowledge-Center/Blog/Lists/Posts/Post.aspx?ID=1142) **Healthcare Business Today 02/28/2019** [Confronting the HIPAA Risk of the Aging Network Printer](https://www.healthcarebusinesstoday.com/confronting-the-hipaa-risk-of-the-aging-network-printer/) **Security Boulevard: Home 02/26/2019** [How to Convince Employees to Care About Security Training](https://securityboulevard.com/2019/02/how-to-convince-employees-to-care-about-security-training/) **Get Tech 02/21/2019** [32 VALUABLE STARTUP LESSONS FROM SUCCESSFUL ENTREPRENEURS](https://get.tech/blog/startup-lessons-entrepreneurs/) **Healthcare Business Today 02/20/2019** [HIPAA Storage Requirements Explained](https://www.healthcarebusinesstoday.com/hipaa-storage-requirements-explained/) **TechOpedia 02/20/2019** [Two-Factor Authentication: A Top Priority for HIPAA Compliance](https://www.techopedia.com/two-factor-authentication-a-top-priority-for-hipaa-compliance/2/33761) **Electronic Health Reporter 02/08/2019** [What is Your HIPAA DATA Backup Plan](https://electronichealthreporter.com/what-is-your-hipaa-data-backup-plan/) **PayJunction Blog 02/05/2019** [Everything to Know About PCI Compliance](https://blog.payjunction.com/pci-compliance/) **APN News 02/01/2019** [Facebook says Apple is restoring a key developer tool](https://www.apnews.com/2f31e57004484157884ee0b12a766e3c) **Inc. Magazine 01/31/2019** [17 Daily Habits Practiced by Highly Successful People](https://www.inc.com/christina-desmarais/17-daily-habits-practiced-by-highly-successful-people.html) **Craig Mullins 01/29/2019** [Best Cheap VPS Hosting and Web Servers](http://www.craig-mullins.com/vps-hosting/) **Mcknights 01/28/2019** [How to ensure your employees aren't a threat to HIPAA compliance](https://www.mcknights.com/marketplace/marketplace-experts/how-to-ensure-your-employees-arent-a-threat-to-hipaa-compliance/) **Perimeter81 01/23/2019** [10 InfoSec Trends CISOs Are Excited About Seeing in 2019](https://www.perimeter81.com/blog/network/ciso-infosec-trends/) **Cyberchimps 01/23/2019** [Best WordPress Hosting Companies: For Every Budget](https://cyberchimps.com/best-wordpress-hosting-companies-for-every-budget/) **Name Cheap 01/22/2019** [How to Budget for Cybersecurity Effectively](https://www.namecheap.com/blog/how-to-budget-for-cybersecurity/) **HFMA 01/22/2019** [HIPAA IT Predictions for 2019](https://www.hfma.org/Content.aspx?id=62818) **USA Today 01/18/2019** [Is 2019 the year we stand up for protecting our privacy? Apple CEO Tim Cook says it's time](https://www.usatoday.com/story/tech/columnist/baig/2019/01/18/apple-ceo-tim-cook-seeks-landmark-privacy-reform-amid-data-breaches/2606333002/) **G2 Crowd 01/17/2019** [Penetration Testing](https://learn.g2crowd.com/penetration-testing) **Gillware 01/16/2019** [Five Ways to Prepare for a Data Breach in 2019](https://www.gillware.com/blog/articles/five-ways-prepare-data-breach-2018/) **Inside Big Data 01/14/2019** [“Above the Trend Line”: Your Industry Rumor Central for 1/14/2019](https://insidebigdata.com/2019/01/14/trend-line-industry-rumor-central-1-14-2019/) **DevOps 01/11/2019** [How to Automate HIPAA Compliance with DevOps](https://devops.com/how-to-automate-hipaa-compliance-with-devops/) **Mojafarma 01/05/2019** [24-business-owners-hard-hitting-work-ethic-quotes-to-keep-you-motivated/](https://mojafarma.wordpress.com/2017/05/01/24-business-owners-hard-hitting-work-ethic-quotes-to-keep-you-motivated/) **Devrix 01/05/2019** [How to Effectively Drive B2B Sales [Expert Roundup]](https://devrix.com/tutorial/b2b-sales-techniques-expert-roundup/) **Forbes Technology Council 01/04/2019** [Learning from 2018 cybersecurity incidents: Perform due diligence](https://www.forbes.com/sites/forbestechcouncil/2019/01/04/what-net-neutrality-in-california-could-mean-for-facebook-google-and-apple/#5a335ebe39c0) **Forbes 01/04/2019** [What Net Neutrality In California Could Mean For Facebook, Google And Apple](https://www.forbes.com/sites/forbestechcouncil/2019/01/04/what-net-neutrality-in-california-could-mean-for-facebook-google-and-apple/#270be8c539c0) **Opploans Mar 2018** [Don’t Let a Phishing Scam Lead to Bad Credit!](https://www.opploans.com/blog/dont-let-a-phishing-scam-lead-to-bad-credit/) **HipaaHQ 2018** [What Are the Most Common HIPAA Violations and How to Prevent Them](https://www.hipaahq.com/what-are-the-most-common-hipaa-violations-and-how-to-prevent-them/) **Tech Target: 12/31/2018** [Learning from 2018 cybersecurity incidents: Perform due diligence](https://searchcio.techtarget.com/feature/Learning-from-2018-cybersecurity-incidents-Perform-due-diligence) **SC Magazine: 12/26/2018** [Data Breaches Caused by Misconfigured Servers](https://www.scmagazine.com/home/opinions/data-breaches-caused-by-misconfigured-servers/) **Payments Source: 12/24/2018** [PayThink New breaches put social media data in the spotlight](https://www.paymentssource.com/opinion/new-breaches-put-social-media-data-in-the-spotlight?feed=00000152-a2fb-d118-ab57-b3ff6e310000) **Data Center Knowledge: 12/21/2018** [Report of Gaping Security Holes at US Missile Defense Systems Data Centers Shocks Experts](https://www.datacenterknowledge.com/security/report-gaping-security-holes-us-missile-defense-systems-data-centers-shocks-experts) **CloudFuze 12/17/2018** [How Will Advances in Cloud Storage & Hosting Help the Future of Gaming?](https://www.cloudfuze.com/how-will-advances-in-cloud-storage-hosting-help-the-future-of-gaming/) **SlideDesk 12/12/2018** [Technical Safeguards for Your HIPAA-Compliant WordPress Site](https://www.slidedeck.com/hipaa-compliant-wordpress-hosting/) **Computer Dealer News: 12/05/2018** [Atlantic.Net announces partnership with Veeam](https://www.computerdealernews.com/news/atlantic-net-announces-partnership-with-veeam/63198) **Pay junction 12/04/2018** [PCI SECURITY TIME AND COSTS TO REACH COMPLIANCE](https://blog.payjunction.com/pci-security-time-costs/) **WHNT News 19: 12/02/2018** [Milwaukee Journal Sentinel](https://whnt.com/2018/12/01/what-to-do-if-youre-affected-by-the-marriott-data-breach/) **ERP In News 12/02/2018** [10 Cybersecurity Protocols Every Tech Professional Should Follow](https://erpinnews.com/10-cybersecurity-protocols-every-tech-professional-should-follow) **Pressreader: 12/02/2018** [Some ways to protect yourself](https://www.pressreader.com/usa/milwaukee-journal-sentinel/20181202/282067688001996) **MRP systems software | ERP software systems 12/02/2018** [10 Cybersecurity Protocols Every Tech Professional Should Follow](http://statiicouk.blogspot.com/2018/12/10-cybersecurity-protocols-every-tech.html) **Security Info Watch: 11/30/2018** [Massive Marriott data breach exposes data of 500M customers](https://www.securityinfowatch.com/security-executives/article/12438185/massive-marriott-data-breach-exposes-data-of-500m-customers) **Florida Justice Technology Center 11/30/2018** [Cybersecurity: The Risks of Using Outdated IT Systems](https://floridajusticetechnologycenter.org/cybersecurity-the-risks-of-using-outdated-it-systems/) **FirstSiteGuide 11/30/2018** [How to Backup Your WordPress Website](https://firstsiteguide.com/backup-wordpress-site/) **The Future of Things 2018** [IoT Risks and GDPR Create Pressure for New Healthcare Security Solutions](https://thefutureofthings.com/12068-iot-risks-and-gdpr-create-pressure-for-new-healthcare-security-solutions/) **CyberChimps 11/29/2018** [PCI vs HIPAA: A compliance comparison](https://cyberchimps.com/how-to-make-your-wordpress-site-hipaa-compliant/) **WPEka 11/29/2018** [How to Make Your WordPress Site HIPAA-Compliant](https://bestcompany.com/identity-theft/blog/2019-identity-theft-and-scam-trends) **TechTarget: 11/28/2018** [Marriott discloses Starwood data breach affecting 500 million guests](https://searchsecurity.techtarget.com/news/252453583/Marriott-discloses-Starwood-data-breach-affecting-500-million-guests) **Forbes: 11/28/2018** [Overcoming A Cybersecurity Breach: 12 Tips For Young Tech Professionals](https://www.forbes.com/sites/forbestechcouncil/2018/11/20/overcoming-a-cybersecurity-breach-12-tips-for-young-tech-professionals/#666ca87518f7) **Forbes 11/28/2018** [10 Cybersecurity Protocols Every Tech Professional Should Follow](https://www.forbes.com/sites/forbestechcouncil/2018/11/28/10-cybersecurity-protocols-every-tech-professional-should-follow/#4258d4473ae8) **Forbes 11/20/2018** [Overcoming A Cybersecurity Breach: 12 Tips For Young Tech Professionals](https://www.forbes.com/sites/forbestechcouncil/2018/11/20/overcoming-a-cybersecurity-breach-12-tips-for-young-tech-professionals/#47d7a12118f7) **MRC Productivity 11/20/2018** [5 (more) challenges facing CIOs and IT leaders in 2019 (Part 2)](https://www.mrc-productivity.com/blog/2018/11/5-more-challenges-facing-cios-and-it-leaders-in-2019-part-2/) **Security Metrics 2018** [Cost Effective Data Security Best Practices In The Workplace](https://www.securitymetrics.com/blog/cost-effective-data-security-best-practices-workplace) **Referral MD 11/05/2018** [Healthcare Cloud on the Ground: Fog Computing Powers the IoMT Referral MD](https://getreferralmd.com/2018/11/fog-computing-powers-iomt-healthcare/) **Over Land Partners 11/05/2018** [6 Ways Businesses Are Using Augmented and Virtual Reality Today](https://blog.overlandpartners.com/6-ways-businesses-are-using-augmented-and-virtual-reality-today/) **Business.com 11/01/2018** [Is Cloud Hosting the Best IT Solution for Your Business?](https://www.business.com/articles/is-cloud-best-for-your-business/) **Medium 10/31/2018** [How will GDPR affect AI?](https://medium.com/datadriveninvestor/how-will-gdpr-affect-ai-3f10ed25e4c4) **Medium 10/30/2018** [How will GDPR affect AI?](https://medium.com/@atlanticnetdallas/how-will-gdpr-affect-ai-3f10ed25e4c4) **Inside Big Data 10/29/2018** [Your Industry Rumor Central for 10/29/2018](https://insidebigdata.com/2018/11/12/trend-line-industry-rumor-central-10-29-2018-2/) **AI Report 10/29/2018** [Virtual and Augmented Reality Technologies are Now Very Much a Part of Many Businesses Today](http://ai-report.net/news/view/24839) **Forbes Technology Council 10/26/2018** [What Is Your Data Center Migration Strategy?](https://www.forbes.com/sites/forbestechcouncil/2018/10/26/what-is-your-data-center-migration-strategy/#3cb1603663a6) **InGage Technologies 10/24/2018** [6 Ways Businesses Are Using Augmented and Virtual Reality Today](https://www.myingage.com/blog/6-ways-businesses-are-using-augmented-and-virtual-reality-today/) **CMS WiRE 10/23/2018** [6 Ways Businesses Are Using Augmented and Virtual Reality Today](https://www.cmswire.com/digital-workplace/6-ways-businesses-are-using-augmented-and-virtual-reality-today/) **Next Big Future 10/19/2018** [Atlantic.Net validates space based cloud operations](https://www.nextbigfuture.com/2018/10/puranik-ceo-of-atlantic-net-validates-space-based-cloud-operations.html) **Ivanti 10/18/2018** [Data Center Security: IT Experts Share Top Insights](https://www.ivanti.com/blog/data-center-security-it-experts-share-top-insights) **ISACA 2018** [Action Plan for HIPAA-Compliant Cloud](http://www.isaca.org/Knowledge-Center/Blog/Lists/Posts/Post.aspx?List=ef7cbc6d-9997-4b62-96a4-a36fb7e171af&ID=1083) **Mobi Health News 10/15/2018** [Why healthcare data may be more secure with cloud computing](https://www.mobihealthnews.com/content/why-healthcare-data-may-be-more-secure-cloud-computing) **ReferralMD Oct 2018** [Protecting Patient Records in 2018 and Beyond](https://getreferralmd.com/2018/10/protecting-patient-records-in-2018-and-beyond/) **Data Center Frontier 10/09/2018** [Sale-Leaseback Emerges as a Portfolio Building Strategy](https://datacenterfrontier.com/sale-leaseback-emerges-as-a-portfolio-building-strategy/) **Block Tribune 10/08/2018** [Crypto jacking: A New Cyber Threat](https://blocktribune.com/cryptojacking-a-new-cyber-threat/) **Quora 10/08/2018** [Are there any HIPAA compliant hosting providers affordable enough for a bootstrapped startup?](https://www.quora.com/Are-there-any-HIPAA-compliant-hosting-providers-affordable-enough-for-a-bootstrapped-startup) **Cloud Computing News 10/05/2018** [Cloud migration best practices: Preparing for change](https://www.cloudcomputing-news.net/news/2018/may/10/cloud-migration-best-practices-preparing-change/) **Tele Health 10/04/2018** [Cybersecurity and HIPAA Compliance](https://telehealth.org/blog/cybersecurity-and-hipaa-compliance/) **Telebehavioral Health Institute 10/04/2018** [Cybersecurity and HIPAA Compliance Go Hand in Hand: Here’s Why](https://telehealth.org/blog/cybersecurity-and-hipaa-compliance/) **Referral Management Software 10/04/2018** [Protecting Patient Records in 2018 and Beyond](http://www.isaca.org/Knowledge-Center/Blog/Lists/Posts/Post.aspx?List=ef7cbc6d-9997-4b62-96a4-a36fb7e171af&ID=1083) **CMS WiRE 10/03/2018** [8 Augmented Reality Companies Changing the Digital Workplace](https://www.cmswire.com/digital-workplace/8-augmented-reality-companies-changing-the-digital-workplace/) **Digital Health Buzz 10/01/2018** [How Block Chain will transform the medical industry](https://digitalhealthbuzz.com/2018/09/how-blockchain-will-transform-the-medical-industry/) **Compliance & Ethics Blog 10/01/2018** [What is considered a HIPAA breach](http://complianceandethics.org/what-is-considered-a-hipaa-breach-in-2018/) **Coin News Telegraph 09/27/2018** [Why Enterprises are Looking to Blockchain for Better Data Privacy](https://coinnewstelegraph.com/why-enterprises-are-looking-to-blockchain-for-better-data-privacy/) **Healthcare IT Answers 9/26/2018** [HIPAA breaches](https://www.hitechanswers.net/what-is-considered-a-hipaa-breach-in-2018/) **CMS WiRE 09/26/2018** [Why Enterprises Are Looking to Blockchain for Better Data Privacy](https://www.cmswire.com/information-management/why-enterprises-are-looking-to-blockchain-for-better-data-privacy/) **Vixen Now 09/26/2018** [WHY ENTERPRISES ARE LOOKING TO BLOCKCHAIN FOR BETTER DATA PRIVACY](https://vixennow.com/2018/09/26/why-enterprises-are-looking-to-blockchain-for-better-data-privacy/) **Becker's Healthcare 9/25/2018** [How HIPAA has evolved](https://www.beckersasc.com/asc-quality-infection-control/how-hipaa-has-evolved-what-ascs-can-do-to-keep-up-5-qs-with-atlantic-net-ceo-marty-puranik.html) **TexasBar Blog 09/24/2018** [Sponsored Content: How is Cloud Computing Secured?](https://blog.texasbar.com/2018/09/articles/sponsored-content/sponsored-content-how-is-cloud-computing-secured/) **Healthcare Guys 09/22/2018** [Will Cybersecurity Ultimately Fail Without the Use of AI?](https://www.healthcareguys.com/2018/09/22/will-cybersecurity-ultimately-fail-without-the-use-of-ai/) **CloudTweaks 09/10/2018** [HIPAA RISK ASSESSMENT GUIDE FOR SMALLER PRACTICES](https://cloudtweaks.com/2018/09/hipaa-risk-assessment-guide/) **NgData 09/10/2018** [30 Marketing Leaders Reveal the Single Biggest Benefit That Digital Transformation Can Have for Banks](https://www.ngdata.com/biggest-benefit-of-digital-transformation-for-banks/) **Techtly 09/10/2018** [6 Free Windows Task Manager Alternatives](https://www.techtly.com/rationale-in-irrationality-the-coming-of-cloud-bust/) **Orlando Business Journal 9/7/2018** [Q&A: "5 ways blockchain can benefit Orlando health care firms"](https://www.bizjournals.com/orlando/news/2018/09/07/5-ways-blockchain-can-benefit-orlando-health-care.html) **Data Economy 9/5/2018** [Company Feature: Ashburn Data Center](https://data-economy.com/atlantic-net-adds-northern-virginia-to-its-cloud-data-centre-locations/) **Commercial Observer 9/5/2018** [Company Feature: Ashburn Data Center](https://commercialobserver.com/2018/09/orlando-based-cloud-service-provider-opens-data-center-near-dc/) **Healthcare It Today 09/05/2018** [HIPAA Breach Investigations: What You Should Know](https://www.healthcareittoday.com/2018/09/05/hipaa-breach-investigations-what-you-should-know/) **Tech News World 9/4/2018** [Byline: "5 Important Healthcare Cloud Security Factors to Weigh"](https://www.technewsworld.com/story/85520.html) **Healthcare Analytics News 8/23/2018** [Byline on HIT Cloud growth](https://www.hcanews.com/news/9-reasons-why-the-hit-cloud-is-growing) **HCAnews.com 8/23/2018** [Byline: "9 Reasons Why the HIT Cloud Is Growing"](https://www.hcanews.com/news/9-reasons-why-the-hit-cloud-is-growing) **Tech News World 8/21/2018** [5 important healthcare cloud security factors to weigh, ran on Tech News World](https://www.technewsworld.com/story/85520.html) **Digital Guardian 08/16/2018** [Finserv Data Security: Key Concerns for Banks & Credit Unions](https://digitalguardian.com/blog/top-data-security-concerns-banks-credit-unions) **Digital Guardian 8/14/2018** [Blog: " How to Safeguard Your Business Data With Encryption "](https://digitalguardian.com/blog/how-safeguard-your-business-data-encryption) **CIO Dive 8/13/2018** [Feature: "Atlantic.Net Announces Collaboration with Leading Innovator in Enterprise Software, Vmware"](https://www.ciodive.com/press-release/20180808-atlanticnet-announces-collaboration-with-leading-innovator-in-enterprise-s/) **"Oracle's C-Suite Magazine 8/13/2018 "** [Expert Commentary: "How scalable cloud keeps companies of all sizes nimble and competitive"](https://blogs.oracle.com/profit/the-great-equalizer) **Electronic Health Reporter 8/7/2018** [Blog: " What Are HIPAA Compliant Storage Requirements? "](http://electronichealthreporter.com/what-are-hipaa-compliant-storage-requirements) **Health Works Collective 07/31/2018** [Why You Should Perform a HIPAA Risk Assessment](https://www.healthworkscollective.com/why-you-should-perform-hipaa-risk-assessment/) **Tech Insurance 07/31/2018** [Top 4 Phishing Scams IT Consultants Need to Know About](http://www.techinsurance.com/blog/cyber-security/top-4-phishing-scams-it-consultants-need-to-know-about/) **TechTarget 7/26/2018** [Expert Commentary: "Repurpose legacy storage systems for reliability and savings"](https://searchstorage.techtarget.com/tip/Repurpose-legacy-storage-systems-for-reliability-and-savings) **Gillware 7/24/2018** [Blog: " Five Ways to Prepare for a Data Breach in 2018 "](https://www.gillware.com/data-recovery-lab/five-ways-prepare-data-breach-2019/) **IT Business Edge 07/24/2018** [Addressing Third-Party Security Risks](https://www.itbusinessedge.com/articles/addressing-third-party-security-risks.html) **Techopedia 7/23/2018** [Blog: " 10 Steps to Strengthen Your IoT Security "](https://www.techopedia.com/10-steps-to-strengthen-your-iot-security/2/33447) **Digital Guardian 07/19/2018** [Top 3 Considerations When Moving to a Cloud-Based Security Platform](https://digitalguardian.com/blog/top-3-considerations-when-moving-cloud-based-security-platform) **Cyber Chimps 7/10/2018** [Blog: " Earning ROI by Moving to the Cloud "](https://cyberchimps.com/earning-roi-by-moving-to-the-cloud) **VPSBenchmarks 07/09/2018** [GDPR Compliance in the Cloud](https://www.vpsbenchmarks.com/posts/gdpr_compliance_in_the_cloud) **Inside Big Data 7/08/2018** [Blog: " Net Neutrality and Impact on Cloud Computing "](https://insidebigdata.com/2018/07/08/net-neutrality-impact-cloud-computing) **Pay Junction 7/10/2018** [Blog: " PCI Security: Time and Costs to Reach Compliance "](https://blog.payjunction.com/pci-security-time-costs) **SecurityMetrics 07/03/2017** [Cloud Security: What Businesses Need To Know](http://blog.securitymetrics.com/2018/07/cloud-security-what-businesses-need-to_17.html) **RTInsights 7/1/2018** [Q&A: "Brain Trust Q&A: Two Sides of Global Cloud"](https://www.rtinsights.com/brain-trust-qa-two-sides-of-global-cloud/) **MarketWatch 6/17/2018** [Expert Commentary: "The end of net neutrality could mean you pay for faster access to sites like Facebook"](https://www.marketwatch.com/story/the-end-of-net-neutrality-could-mean-you-pay-for-faster-access-to-sites-like-facebook-2018-06-14) **Business Insider 6/15/2018** [Byline: "5 futuristic Westworld technologies and when they'll be a reality" (Pick up from The Next Web)](https://www.businessinsider.com/westworld-technology-how-long-to-become-real-2018-6?IR=T) **Fupping 06/15/2018** [6 Ways Guest Posting Can Help Your Business Grow](https://fupping.com/benskute/2018/06/30/marketing-101-6-ways-guest-posting-can-help-your-business-grow/) **TechTarget 6/14/2018** [Company Feature: "Ceph-based cloud block storage service debuts from Atlantic.Net"](https://searchstorage.techtarget.com/tip/Repurpose-legacy-storage-systems-for-reliability-and-savings) **Pauboxhipaa 06/14/2018** [Hacking and Human Error: Two Enemies of HIPAA Compliance](https://pauboxhipaa.wordpress.com/2018/06/14/hacking-and-human-error-two-enemies-of-hipaa-compliance/) **Thouthe19 06/14/2018** [Hacking and Human Error: Two Enemies of HIPAA Compliance](https://thouthe19.wordpress.com/2018/06/14/hacking-and-human-error-two-enemies-of-hipaa-compliance/) **Beacquaid19 06/14/2018** [Hacking and Human Error: Two Enemies of HIPAA Compliance](https://beacquaid19.wordpress.com/2018/06/14/hacking-and-human-error-two-enemies-of-hipaa-compliance/) **Fupping 06/14/2018** [Marketing 101: 6 Ways Guest Posting Can Help Your Business Grow](https://fupping.com/snax_item/build-a-brand/) **It Security Central 6/13/2018** [Blog: " Seven Questions to Ask Your IT Security Consultant "](https://itsecuritycentral.teramind.co/2018/06/13/seven-questions-to-ask-your-it-security-consultant) **Paubox 6/13/2018** [Blog: " Hacking and Human Error: Two Enemies of HIPAA Compliance"](https://www.paubox.com/blog/hacking-and-human-error-hipaa-compliance) **Security Metrics 6/11/2018** [Blog: " Cloud Security: What Businesses Need To Know "](https://www.securitymetrics.com/blog/cloud-security-what-businesses-need-know) **VPS Benchmarks 6/9/2018** [Blog: " GDPR Compliance in the Cloud "](https://www.vpsbenchmarks.com/posts/gdpr_compliance_in_the_cloud) **The Next Web 6/3/2018** [Contributors: " 5 futuristic Westworld technologies and when they’ll be a reality"](https://thenextweb.com/contributors/2018/06/03/5-futuristic-westworld-technologies-and-when-theyll-be-a-reality) **CIO 5/31/2018** [Expert Commentary: "How to lead a virtual team: 5 keys for success"](https://www.cio.com/article/3276452/collaboration/how-to-lead-a-virtual-team-5-keys-for-success.html) **WPEka 05/30/2018** [Atlantic.Net - A Reliable Web Hosting Provider For All Businesses Needs](https://www.wpeka.com/atlantic-web-hosting-provider.html) **SlideDeck 05/30/2018** [Atlantic.Net - Popular Web Hosting Provider For All Business Size](https://www.slidedeck.com/popular-web-hosting-provider/) **Network World 5/17/2018** [Opinion: " Rationale in irrationality: The coming of cloud bust?"](https://www.networkworld.com/article/3273884/cloud-computing/rationale-in-irrationality-the-coming-of-cloud-bust.html) **Layer.nl 05/17/2018** [IDG Contributor Network: Rationale in irrationality: The coming of cloud bust?](http://layer.nl/bericht/news-item/idg-contributor-network-rationale-in-irrationality-the-coming-of-cloud-bust/) **Network World 5/17/2018** [Byline: "Rationale in irrationality: The coming of cloud bust?"](https://www.networkworld.com/article/3273884/cloud-computing/rationale-in-irrationality-the-coming-of-cloud-bust.html) **ISACA.org 5/11/2018** [Byline: "The Impact of Net Neutrality on Cloud Computing"](http://www.isaca.org/Knowledge-Center/Blog/Lists/Posts/Post.aspx?ID=1005) **ISACA 5/11/2018** [Blog: " The Impact of Net Neutrality on Cloud Computing"](http://www.isaca.org/Knowledge-Center/Blog/Lists/Posts/Post.aspx?ID=1005) **Cloud Tech 5/10/2018** [Byline: "Cloud migration best practices: Preparing for change"](https://urldefense.proofpoint.com/v2/url?u=https-3A__www.cloudcomputing-2Dnews.net_news_2018_may_10_cloud-2Dmigration-2Dbest-2Dpractices-2Dpreparing-2Dchange_&d=DwMFaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=UChi3C1F2KzF3gDdKeDIWT0Y2FVnGxM) **Icloud 05/10/2018** [CLOUD MIGRATION BEST PRACTICES: PREPARING FOR CHANGE](https://icloud.pe/blog/cloud-migration-best-practices-preparing-for-change/) **Cloud Computing News 5/10/2018** [News: "Cloud migration best practices: Preparing for change"](https://www.cloudcomputing-news.net/news/2018/may/10/cloud-migration-best-practices-preparing-change) **eWeek 5/4/2018** [Microsoft Windows Server Containers Land on Atlantic.Net’s Cloud](http://www.eweek.com/cloud/microsoft-windows-server-containers-land-on-atlantic.net-s-cloud) **eWeek 5/3/2018** [Expert Commentary: "Exquinix Connects Miami, Paris to Microsoft Azure ExpressRoute"](http://www.eweek.com/cloud/equinix-connects-miami-paris-to-microsoft-azure-expressroute) **ISACA.org 4/26/2018** [Byline: "The Importance of Securing Your cloud"](http://www.isaca.org/Knowledge-Center/Blog/Lists/Posts/Post.aspx?ID=998) **RTInsights 4/26/2018** [Byline: "What is the Key to Multi-Cloud Unity?"](https://www.rtinsights.com/what-is-the-key-to-multi-cloud-unity/) **Network World 4/5/2018** [Opinion: "The serverless cloud provider was last year, what can we expect to change?"](https://www.networkworld.com/article/3268104/data-center/the-serverless-cloud-provider-was-last-year-what-can-we-expect-to-change.html) **ISACA 4/26/2018** [Blog: "The Importance of Securing Your Cloud"](http://www.isaca.org/Knowledge-Center/Blog/Lists/Posts/Post.aspx?List=ef7cbc6d-9997-4b62-96a4-a36fb7e171af&ID=998) **TechTarget 4/20/2018** [Expert Commentary: "Ten important steps for testing backups"](https://searchdatabackup.techtarget.com/tip/Ten-important-steps-for-testing-backups/) **Computer America 4/6/2018** [Podcast: "What Atlantic.Net offers and the future of cloud computing"](https://computeramerica.com/2018/04/06/atlantic-net-interview-mt-gox-speaks-out-facebooks-new-unsend-feature-walmart-changes/) **Amplify Intelligence 04/06/2018** [17 essential security steps for SMBs shared by 21 global experts](https://www.amplifyintelligence.com/small-business/security-for-smbs/) **Network World 4/5/2018** [Byline: "The Serverless Cloud Provider was Last Year, what can we expect to change"](https://www.networkworld.com/article/3268104/data-center/the-serverless-cloud-provider-was-last-year-what-can-we-expect-to-change.html) **Technology Blog Writer Podcast 4/4/2018** [Podcast: "Marty Puranik, CEO of Atlantic.Net Share his tech startup story"](http://techblogwriter.co.uk/atlantic-net/) **Tech Company News 3/30/2018** [Q&A: "Hosting Solutions Provider Atlantic.Net Delivers Hosting Solutions For Growing Businesses"](http://techcompanynews.com/hosting-solutions-provider-atlantic-net-delivers-hosting-solutions-growing-businesses/) **TeleHealth 3/28/2018** [Blog: "Augmented Reality Solution"](https://telehealth.org/blog/augmented-reality-solution) **ISACA 3/21/2018** [Blog: "What Role Will IoT Play in Edge Computing?"](http://www.isaca.org/Knowledge-Center/Blog/Lists/Posts/Post.aspx?List=ef7cbc6d-9997-4b62-96a4-a36fb7e171af&ID=973) **Business.com 3/2/2018** [Article: "5 Benefits of Cloud Hosting for Small Businesses"](https://www.business.com/articles/5-benefits-of-cloud-hosting-for-smb) **Reddit Mar 2018** [I'm a Managing Consultant who performs HIPAA Compliance and Cybersecurity Audits: AMA about security and how sensitive medical records are handled online!](https://www.reddit.com/r/technology/comments/6suv6a/im_a_managing_consultant_who_performs_hipaa/) **Business Mar 2018** [My name is Adnan Raja and I'm the Vice President of Marketing for Atlantic.Net, a trusted web hosting solution.](https://www.business.com/advice/member/p/adnan-raja/) **Tech beacon Mar 2018** [IT Ops analytics: IT gets its game on with better business alignment](https://techbeacon.com/it-ops-analytics-it-gets-its-game-better-business-alignment) **ISACA.org 3/22/2018** [Byline: "What role will IoT play in edge computing?"](https://www.isaca.org/Knowledge-Center/Blog/Lists/Posts/Post.aspx?ID=973) **Data Center Knowledge 3/20/2018** [Expert Commentary: "With much of the data center stack open source, security is a special challenge"](http://www.datacenterknowledge.com/security/much-data-center-stack-open-source-security-special-challenge/) **Health Management Technology 3/15/2018** [Byline: "How cloud computing meets healthcare needs"](https://www.healthmgttech.com/cloud-computing-meets-healthcare-needs) **Information Management 3/9/2018** [Opinion : "How to ensure your cloud storage is compliant with GDPR ?"](https://www.information-management.com/opinion/how-to-ensure-your-cloud-storage-is-compliant-with-gdpr) **High Tech Newz Mar 2018** [im-a-managing-consultant-who-performs-hipaa-compliance-and-cybersecurity-audits-ama-about-security-and-how-sensitive-medical-records-are-handled-online](http://www.hightechnewz.com/im-a-managing-consultant-who-performs-hipaa-compliance-and-cybersecurity-audits-ama-about-security-and-how-sensitive-medical-records-are-handled-online) **eWeek 3/5/2018** [Expert Commentary: "Microsoft azure stack coming to government customers in mid-2018"](http://www.eweek.com/cloud/microsoft-azure-stack-coming-to-government-customers-in-mid-2018) **Business 03/02/2018** [5 Benefits of Cloud Hosting for Small Businesses](https://www.business.com/articles/5-benefits-of-cloud-hosting-for-smb/) **Digital Guardian 02/28/2018** [EXPERTS ON TOP INFOSEC CONSIDERATIONS FOR FINANCIAL SERVICES COMPANIES](https://digitalguardian.com/blog/infosec-concerns-financial-services-companies) **Healthmqttech 2/27/2018** [Blog: "How cloud computing meets healthcare needs ?"](https://www.healthmgttech.com/cloud-computing-meets-healthcare-needs) **HIPAA HQ 2/26/2018** [Blog: "Does HIPAA Compliance Equal Security?"](https://www.hipaahq.com/hipaa-compliance-equal-security) **Maintenance Care 2/26/2018** [Blog: "Biggest Healthcare Data Breaches Stress Importance Of HIPAA Compliance"](https://blog.maintenancecare.com/blog/biggest-healthcare-data-breaches-stress-importance-of-hipaa-compliance) **Network World 2/22/2018** [Byline: "Emerging blockchain-based distribution storage market and its effect on cloud computing"](https://www.networkworld.com/article/3257706/storage/emerging-blockchain-based-distribution-storage-market-and-its-effect-on-cloud-computing.html/) **OnPage 2/09/2018** [Expert Commentary: "The Importance of Disaster Recovery for HIPAA Compliance"](https://www.onpage.com/disaster-recovery-hipaa-compliance) **Digital Guardian 02/05/2018** [INFOSEC PROFESSIONALS REVEAL THE TOP INFORMATION SECURITY CONCERNS FOR 2018 & BEYOND](https://digitalguardian.com/blog/infosec-pros-on-top-infosec-concerns-for-2018-beyond) **Digital Guardian 02/05/2018** [INFOSEC PROFESSIONALS REVEAL THE TOP INFORMATION SECURITY CONCERNS FOR 2018 & BEYOND](https://digitalguardian.com/blog/infosec-pros-on-top-infosec-concerns-for-2018-beyond) **Text Request 01/30/2018** [18 Digital Marketing Tips Most People Don't Know About](https://www.textrequest.com/blog/digital-marketing-tips/) **Knect365 01/25/2018** [Five Medical Tech Advancements That Will Have Massive Impact in Healthcare for 2018](https://knect365.com/pharmanext/article/8b25c9ec-c930-4ccf-915d-9fe54f408246/five-medical-tech-advancements-impact-in-healthcare-for-2018) **Data Center Knowledge 1/23/2018** [Expert Commentary: "Spectre, meltdown hit on-prem windows servers hardest"](http://www.datacenterknowledge.com/security/spectre-meltdown-hit-prem-windows-servers-hardest/) **TechTarget 1/16/2018** [Expert Commentary: "Chip bugs hit cloud computing usage less than first feared"](http://searchcloudcomputing.techtarget.com/news/450433293/Chip-bugs-hit-cloud-computing-usage-less-than-first-feared) **Medium 01/16/2018** [34 Reasons Why Even Small Businesses Should Consider Hiring A Cybersecurity Expert](https://medium.com/thrive-global/34-reasons-why-even-small-businesses-should-consider-hiring-a-cybersecurity-expert-4b9025fb1da9) **Medium 01/15/2018** [34 Reasons Why Even Small Businesses Should Consider Hiring A Cybersecurity Expert](https://medium.com/thrive-global/34-reasons-why-even-small-businesses-should-consider-hiring-a-cybersecurity-expert-4b9025fb1da9) **American Banker 1/15/2018** [Expert Commentary: "Fears mount about Meltdown, Spectre threats to cloud computing"](https://www.americanbanker.com/news/fears-mount-about-meltdown-spectre-threats-to-cloud-computing/) **All About Circuits 1/15/2018** [Expert Commentary: "Anatomy of a Security Flaw Announcement: The Strange Timeline of Spectre and Meltdown"](https://www.allaboutcircuits.com/news/spectre-meltdown-anatomy-major-security-flaw-announcements/) **Digital Edge 1/11/2018** [Editor : "Are You Ready To Ditch Your Old Servers And Move Into The Cloud?"](https://www.digitaledge.org/are-you-ready-to-ditch-your-old-servers-and-move-into-the-cloud) **Inbound Logistics 1/11/2018** [News: "Five Reasons to Consider Cloud Services for Your Supply Chain"](http://www.inboundlogistics.com/cms/article/five-reasons-to-consider-cloud-services-for-your-supply-chain) **Enterprise Cloud News 01/08/2018** [Expert Commentary: "'Spectre & Meltdown' - What Cloud Users Need to Know "](http://www.enterprisecloudnews.com/author.asp?section_id=570&doc_id=739483&) **Medium 01/06/2018** [99 Totally Serious Ways To Create A Great Work Culture](https://journal.thriveglobal.com/99-totally-serious-ways-to-create-a-great-work-culture-e7d093bdad23) **Thouthe19 01/05/2018** [Is WordPress HIPAA Compliant?](https://thouthe19.wordpress.com/2018/01/05/is-wordpress-hipaa-compliant/) **Beacquaid19 01/05/2018** [Is WordPress HIPAA Compliant?](https://beacquaid19.wordpress.com/2018/01/05/is-wordpress-hipaa-compliant/) **The Digital Bridges 01/04/2018** [Learning Lessons from Hurricane Irma: Is Cloud the Answer?](http://www.thedigitalbridges.com/lessons-hurricane-irma-is-cloud-answer/) **Paubox 01/04/2018** [Is WordPress HIPAA Compliant?](https://www.paubox.com/blog/wordpress-hipaa-compliant) **Network World 12/27/2017** [Opinion: "Mega increase in cloud adoption underway"](https://www.networkworld.com/article/3244475/cloud-computing/mega-increase-in-cloud-adoption-underway.html) **Rasmussen College 12/06/2017** [5 Healthcare Technology Trends to Follow in 2018](http://www.rasmussen.edu/degrees/health-sciences/blog/healthcare-technology-trends/) **VM Blog 11/30/2017** [Expert Commentary: "Is Your Infrastructure Costing You Too Much"](http://vmblog.com/archive/2017/11/30/is-your-infrastructure-costing-you-too-much.aspx#.W35YHugzbIW) **Creative Click Media 11/22/2017** [Business Owners Tell All: Which Apps Are You Thankful For?](https://creativeclickmedia.com/business-owners-tell-all-apps/) **Security Metrics 11/15/2017** [Expert Commentary: "5 Security Best Practices For Protecting Your HIPAA-Compliant Data"](https://www.securitymetrics.com/blog/5-security-best-practices-protecting-your-hipaa-compliant-data) **IT Briefcase 11/12/2017** [2015 Cloud Hosting Predictions & Forecasts](http://www.itbriefcase.net/2015-cloud-hosting-predictions-forecasts) **Pay Junction 11/09/2017** [3 Considerations When Selecting Cloud Service Providers](https://blog.payjunction.com/cloud-service-providers/) **Business 11/08/2017** [Just How Secure Is the Cloud?](https://www.business.com/articles/how-secure-is-cloud/) **Thriveworks 11/06/2017** [10 Employers Reveal the Key to a Happy, Healthy Workplace](http://thriveworks.com/blog/employers-reveal-key-happy-healthy-workplace/) **Paubox 11/03/2017** [A Look Inside the First Ever HIPAA Compliant Email Conference](https://www.paubox.com/blog/hipaa-compliant-email-conference-2017) **Paubox 11/03/2017** [First Annual Paubox SECURE Conference Tackles Big Digital Health Security Topics](https://www.paubox.com/blog/paubox-secure-digital-health-security) **Digital guardian 10/31/2017** [ENDPOINT DETECTION AND RESPONSE (EDR) SOLUTIONS: EXPERT TIPS & STRATEGIES](https://digitalguardian.com/blog/endpoint-detection-response-edr-solutions) **Paubox 10/29/2017** [Three Sponsors Join Paubox SECURE Conference](https://www.paubox.com/blog/three-sponsors-join-paubox-secure-conference) **Electronic Health Reporter 10/25/2017** [Security-Best-Practices-Protecting-Hipaa-Compliant-Data](http://electronichealthreporter.com/security-best-practices-protecting-hipaa-compliant-data/) **Tom's Guide 10/25/2017** [Free vs. Paid VPNs: Which Should You Choose?](https://www.tomsguide.com/us/free-vs-paid-vpn,news-24992.html) **Paubox 10/17/2017** [How This Company Chose Their HIPAA Compliant Hosting Plan](https://www.paubox.com/blog/hipaa-compliant-hosting/) **Health Works Collective 10/11/2017** [Cost of Non-Compliance with HIPAA and HITECH](https://www.healthworkscollective.com/cost-of-non-compliance-with-hipaa-and-hitech/) **Rasmussen 10/09/2017** [4 of the Most At-Risk Industries for Cyber Attacks](http://www.rasmussen.edu/degrees/technology/blog/industries-for-cyber-attacks/) **VM blog 09/28/2017** [Atlantic.Net 2018 Predictions: The Cloud, Security and Healthcare Compliance in 2018 and Beyond](http://vmblog.com/archive/2017/09/28/atlantic-net-2018-predictions-the-cloud-security-and-healthcare-compliance-in-2018-and-beyond.aspx#.Wc6v8tOGP64) **Doxy 09/28/2017** [How Telemedicine Delivers Privacy, Security & Compliance Affordably](https://doxy.me/blog/2017/09/28/privacy-security/) **PayJunction 09/26/2017** [Experts Share 6 Sales Tips to Grow Your Business](https://blog.payjunction.com/sales-tips-business/) **KnowledgeNet 09/08/2017** [Securing the Internet of Things](https://www.knowledgenet.com/dont-use/securing-the-internet-of-things/) **Digital guardian 08/31/2017** [CLOUD COMPUTING SECURITY BENEFITS: INFOSEC PROS REVEAL THE TOP BENEFITS OF THE CLOUD](https://digitalguardian.com/blog/cloud-computing-security-benefits) **IT Security Central 08/29/2017** [An Inside Look at Healthcare Cyber Security and HIPAA Compliance](https://itsecuritycentral.teramind.co/2017/08/29/an-inside-look-at-healthcare-cyber-security-and-hipaa-compliance/) **CEO Blog Nation 08/25/2017** [14 Entrepreneurs Share How They Use Blogging for Business](http://rescue.ceoblognation.com/2017/08/25/14-entrepreneurs-share-use-blogging-business/) **Rasmussen College 08/21/2017** [What Is Digital Marketing? A Beginner's Guide to Modern Marketing](http://www.rasmussen.edu/degrees/business/blog/what-is-digital-marketing/) **My Corporation 08/01/2017** [Staying Relevant In Business: Experts Weigh In](https://blog.mycorporation.com/2017/08/experts-weigh-stay-relevant/) **CallMiner 07/26/2017** [The Most Important Algorithms for Marketing Data Analysts to Understand](https://callminer.com/blog/important-algorithms-marketing-data-analysts-understand/) **Channelnomics 07/17/2017** [Trend Micro’s Atlantic.Net Collaboration](https://www.channelnomics.com/channelnomics-us/news/3013967/todays-channel-rundown-17-july-2017) **IT Briefcase 07/17/2017** [Atlantic.Net Announces Managed Hosting Solutions Backed by Trend Micro’s World-Class Security Suite](http://www.itbriefcase.net/atlantic-net-announces-managed-hosting-solutions) **Free Press Web 07/14/2017** [5-things-it-departments-can-do-to-get-organized-during-the-summer-break/](http://freepressweb.com/5-things-it-departments-can-do-to-get-organized-during-the-summer-break/) **Quora 07/11/2017** [Which companies provides HIPAA compliance services in cloud?](https://www.quora.com/Which-companies-provides-HIPAA-compliance-services-in-cloud) **CEO Blog Nation: 06/21/2017** [entrepreneurs-share-favorite-inspirational-business-quote](http://hear.ceoblognation.com/2017/06/21/24-entrepreneurs-share-favorite-inspirational-business-quote/) **CEO Blog Nation: 06/19/2017** [36-entrepreneurs-explain-favorite-podcasts-businesses-entrepreneurs](http://rescue.ceoblognation.com/2017/06/19/36-entrepreneurs-explain-favorite-podcasts-businesses-entrepreneurs/) **I Find Viral 06/10/2017** [im-a-managing-consultant-who-performs-hipaa-compliance-and-cybersecurity-audits-ama-about-security-and-how-sensitive-medical-records-are-handled-online-via-rtechnology](http://ifindviral.com/im-a-managing-consultant-who-performs-hipaa-compliance-and-cybersecurity-audits-ama-about-security-and-how-sensitive-medical-records-are-handled-online-via-rtechnology/) **Container Journal 06/08/2017** [Atlantic.Net Unfurls Windows Server Container Cloud Service](https://containerjournal.com/2017/06/08/atlantic-net-unfurls-windows-server-container-cloud-service/) **Web Host Industry Review 06/08/2017** [After 24 Years in Hosting, Atlantic.Net Sees Lots of Runway for Industry Growth](http://www.thewhir.com/web-hosting-news/after-24-years-in-hosting-atlantic-net-sees-lots-of-runway-for-industry-growth) **Information Management 06/05/2017** [5 ways machine learning is impacting cloud computing](https://www.information-management.com/opinion/5-ways-machine-learning-is-impacting-cloud-computing?feed=0000015a-13e1-deb4-ab5e-9bfd65d50000) **ReadWrite 06/05/2017** [In the coming cloud computing war, storage is the next front](https://readwrite.com/2017/06/05/in-the-coning-cloud-computing-war-hl1/) **Trinium Ventures 05/26/2017** [podcasts-that-will-help-you-become-a-better-entrepreneur](http://triniumventures.com/2017/05/26/24-podcasts-that-will-help-you-become-a-better-entrepreneur/) **TechCrunch 05/25/2017** [Atlantic.Net brings Windows Container support to its cloud hosting platform](https://techcrunch.com/2017/05/25/atlantic-net-brings-windows-server-container-support-to-its-cloud/) **Cloud Computing Journal 05/25/2017** [Atlantic.Net Announces Windows Server Container Support in the Cloud](http://news.sys-con.com/node/4090690) **Stackify 05/12/2017** [20 IT Leaders Reveal the Biggest Mistakes IT Management Teams Make When Implementing Application Performance Monitoring Solutions](https://stackify.com/mistakes-implementing-application-performance-monitoring-solutions/) **Stackify 05/08/2017** [25 App Developers and Cloud Pros Reveal the Biggest Advantages to Hosting Your App in the Cloud](https://stackify.com/app-cloud-hosting-biggest-advantages/) **IdeaMensch 05/06/2017** [Manoj “Marty” Puranik, Founder, President and CEO of Atlantic](https://ideamensch.com/manoj-marty-puranik/) **Manta 2017** [Atlantic.Net](https://www.manta.com/c/mh1gy6l/atlantic-net) **Hotfrog US 2017** [About Atlantic.Net](https://www.hotfrog.com/business/tx/dallas/atlantic-net_42766627) **Tech republic 2017** [5-things-it-departments-can-do-to-get-organized-during-the-summer-break/](http://www.techrepublic.com/article/5-things-it-departments-can-do-to-get-organized-during-the-summer-break/) **WPEka 10/01/2016** [Top 20 Best WordPress Web Hosting Providers: Guide](https://www.wpeka.com/top-20-best-wordpress-hosting-providers.html) **Data Economy 07/15/2015** [Atlantic.Net To Open New Datacentre With Infinity](https://data-economy.com/atlantic-net-to-open-new-datacentre-with-infinity/) **Channel Futures 07/14/2015** [Atlantic.Net Expands Portfolio with New Cloud Servers](http://www.channelfutures.com/cloud-services/atlanticnet-expands-portfolio-new-cloud-servers) **Inc. Magazine 06/26/2015** [6 Ways to Push Through a Sales Plateau](https://www.inc.com/christina-desmarais/6-ways-to-push-through-a-sales-plateau.html) **Orlando Business Journal 06/12/2015** [Orlando cloud-hosting firm hiring for data center expansion](https://www.bizjournals.com/orlando/news/2015/06/12/orlando-cloudhosting-firm-hiring-for-data-center.html) **TechCrunch 05/14/2015** [Atlantic.Net Hopes To Challenge DigitalOcean As It Expands To Europe And Asia](https://techcrunch.com/2015/05/14/atlantic-net-hopes-to-challenge-digitalocean-as-it-expands-to-europe-and-asia/) **Channel Futures 05/05/2015** [Atlantic.Net To Open Data Center In NYC](http://www.channelfutures.com/cloud-services/atlanticnet-open-data-center-nyc) **Computer Weekly.com 05/04/2015** [Atlantic.Net unveils New York datacentre and sets out UK expansion plans](http://www.computerweekly.com/news/4500245572/AtlanticNet-unveils-New-York-datacentre-and-sets-out-UK-expansion-plans) **New York Business Journal 05/04/2015** [Florida cloud storage provider guns for NYC startup market](https://www.bizjournals.com/newyork/blog/techflash/2015/05/florida-cloud-storage-atlantic-net-silicon-alley.html) **Xconomy New York 05/04/2015** [Cloud Host Atlantic.Net Opens Data Center Aimed at NY Startup Scene](https://www.xconomy.com/new-york/2015/05/04/cloud-host-atlantic-net-opens-data-center-aimed-at-ny-startup-scene/) **DataCenter Knowledge 03/31/2015** [Atlantic.net to Expand International Cloud Data Center Footprint](http://www.datacenterknowledge.com/archives/2015/03/31/atlantic-net-to-expand-international-cloud-data-center-footprint) **CRN 03/27/2015** [Atlantic.Net Expands Data Center Footprint In U.S., Europe and Asia](http://www.crn.com/news/cloud/300076306/atlantic-net-expands-data-center-footprint-in-u-s-europe-and-asia.htm) **CloudExpo 03/10/2015** [The Future of Cloud Hosting](http://cloudcomputing.sys-con.com/node/3172750) **Forbes 02/20/2015** [Atlantic.Net Delivers Windows Experience: A Better Implementation Of Something That Shouldn’t Exist](https://www.forbes.com/sites/benkepes/2015/02/20/atlantic-net-delivers-windows-experience-a-better-implementation-of-something-that-shouldnt-exist/3/#5d5cae5f5675) **Venture Beat 02/14/2015** [These nerds are working hard in data centers on Valentine’s Day](https://venturebeat.com/2015/02/14/valentines-day-in-the-data-center/) **Venture Beat 02/09/2015** [The Amazon and Microsoft clouds are in Seattle, but that’s not where devs are going next](https://venturebeat.com/2015/02/09/the-amazon-and-microsoft-clouds-are-in-seattle-but-thats-not-where-devs-are-going-next/) **Information Week 01/19/2015** [FreeBSD Gains Ground With Small Cloud Providers](https://www.informationweek.com/cloud/infrastructure-as-a-service/freebsd-gains-ground-with-small-cloud-providers/d/d-id/1318656?piddl_msgorder=asc) **451 Research 12/19/2014** [Atlantic.Net gives cloud pricing a push with $0.99-per-month VM](https://451research.com/report-short?entityId=83157%27) **Enterprise Networking Planet 12/18/2014** [Cloud Provider Atlantic.Net Moves In and Gives Back to San Francisco](http://www.enterprisenetworkingplanet.com/datacenter/cloud-provider-atlantic.net-moves-in-and-gives-back-to-san-francisco.html) **Information Week 12/16/2014** [Atlantic.Net Cloud Stretches To The Pacific](https://www.informationweek.com/cloud/infrastructure-as-a-service/atlanticnet-cloud-stretches-to-the-pacific/d/d-id/1318174) **DataCenter Knowledge 12/16/2014** [Atlantic.Net Launches First West Coast Data Center](http://www.datacenterknowledge.com/archives/2014/12/16/atlantic-net-opens-first-california-data-center) **Channel Futures 10/30/2014** [Atlantic.Net Targets Startups with 99-Cent Server](http://www.channelfutures.com/cloud-services/atlanticnet-targets-startups-99-cent-server) **TechCrunch 09/30/2014** [Atlantic.Net Launches $0.99/Month SSD-Based Servers To Challenge DigitalOcean](https://techcrunch.com/2014/09/30/atlantic-net-launches-0-99month-ssd-based-vps-hosting-service/) **The Whir 09/30/2014** [Atlantic.Net Taps Trend Micro for Managed Hosting Security](http://www.thewhir.com/web-hosting-news/atlantic-net-taps-trend-micro-for-managed-hosting-security) **Information Week 09/30/2014** [Atlantic.Net Challenges Amazon With Cheap Cloud Server](https://www.informationweek.com/cloud/platform-as-a-service/atlanticnet-challenges-amazon-with-cheap-cloud-server/d/d-id/1316135) **Forbes 09/30/2014** [More Moves In The Cloud Price War: Atlantic.Net Launches 99 Cent Servers](https://www.forbes.com/sites/benkepes/2014/09/30/more-moves-in-the-cloud-price-war-atlantic-net-launches-99-cent-servers/#538a87d83274) **InsightaaS 09/05/2014** [Atlantic.Net launches cloud in Canada](http://insightaas.com/atlantic-net-launches-cloud-in-canada/) **CRN 07/30/2014** [VPS Hosting, Cloud Provider Atlantic.Net Builds Data Centers In Toronto, Dallas](http://www.crn.com/news/cloud/300073556/vps-hosting-cloud-provider-atlantic-net-builds-data-centers-in-toronto-dallas.htm) **GIGAOM 07/29/2014** [N](https://gigaom.com/2014/07/29/cloud-provider-atlantic-net-expands-data-centers-in-toronto-and-dallas/) **Datacenter Dynamics 07/29/2014** [Atlantic.Net, expanding the Cloud into Europe](http://www.datacenterdynamics.com/content-tracks/colo-cloud/atlanticnet-expanding-the-cloud-into-europe/88093.article) **DataCenter Knowledge 07/29/2014** [Atlantic.Net Expands Cloud to Dallas, Toronto Data Centers](http://www.datacenterknowledge.com/archives/2014/07/29/atlanticnets-new-dallas-and-canadian-cloud) **tele health 05/10/2014** [Which Cloud Storage Services are HIPAA Compliant?](https://telehealth.org/blog/which-cloud-storage-services-are-hipaa-compliant/) **Orlando Business Journal 05/18/2012** [Plan for how workers will access company data](http://www.bizjournals.com/orlando/print-edition/2012/05/18/plan-for-how-workers-will-access.html) **Orlando Business Journal 04/29/2012** [Celebrity skin](http://www.bizjournals.com/orlando/stories/2002/04/29/tidbits.html) **Orlando Business Journal 08/12/2011** [Another round of shocking power rate hikes ahead?](http://www.bizjournals.com/orlando/print-edition/2011/08/12/another-round-of-shocking-power-rate.html) **Orlando Business Journal 08/12/2011** [Just say no to rate hikes](http://www.bizjournals.com/orlando/print-edition/2011/08/12/just-say-no-to-rate-hikes.html) **Orlando Business Journal 06/03/2011** [Storm watch: Get a plan in place before you need it](http://www.bizjournals.com/orlando/print-edition/2011/06/03/storm-watch-get-a-plan-in-place.html) **Orlando Business Journal 04/22/2011** [White House unveils strategy for online ID credentials](http://www.bizjournals.com/orlando/print-edition/2011/04/22/white-house-unveils-strategy-for.html) **Orlando Business Journal 08/09/2010** [Atlantic.Net, Complete Healthcare team up](http://www.bizjournals.com/orlando/stories/2010/08/09/daily8.html) **Redmond Channel Partner 03/01/2010** [4 Smart Pricing Strategies for 2010](http://rcpmag.com/articles/2010/03/01/4-smart-pricing-strategies-for-2010.aspx) **Orlando Business Journal 02/15/2010** [Non-medical firms that don’t protect patient records face fines under new privacy law](http://orlando.bizjournals.com/orlando/stories/2010/02/15/story16.html?surround=etf&ana=e_article&b=12662100002868521) **Orlando Business Journal 06/22/2009** [Forty Under 40: The class of 2009](http://orlando.bizjournals.com/orlando/stories/2009/06/22/focus3.html?page=13) **Orlando Business Journal 05/04/2009** [Atlantic.Net Adding 60-plus high wage jobs](http://orlando.bizjournals.com/orlando/stories/2009/05/04/story3.html) **Orlando Business Journal 03/16/2009** [Atlantic.Net gets Magic contract](http://orlando.bizjournals.com/orlando/stories/2009/03/16/daily32.html) **Orlando Sentinel 03/09/2009** [Atlantic.Net data center: Quiet giant makes noise](http://www.orlandosentinel.com/technology/orl-cfbcover-data-center-030909,0,7441431.story) **Gainesville Sun 10/10/2003** [Atlantic.Net now offers high-speed access](http://news.google.com/newspapers?id=C7QpAAAAIBAJ&sjid=UOwDAAAAIBAJ&dq=atlantic.net&pg=6397%2C2225815) **IndUS Business Journal 10/10/2003** [Manoj Puranik: Data Smarts](http://www.indusbusinessjournal.com/ME2/dirmod.asp?sid=&nm=Archive&type=Publishing&mod=Publications%3A%3AArticle&mid=8F3A7027421841978F18BE895F87F791&tier=4&id=364BB05E892F45A5A16D02F93E20FAFB) **Orlando Business Journal 10/06/2003** [Marketing, Internet firm sign reseller agreement](http://www.bizjournals.com/orlando/stories/2003/10/06/daily42.html) **Tampa Business Journal 08/25/2003** [Progress Telecom Product chosen by Atlantic.Net](http://www.bizjournals.com/tampabay/stories/2003/08/25/daily9.html) **Orlando Business Journal 08/25/2003** [Atlantic.Net buys Ethernet from Progress Telecom](http://www.bizjournals.com/orlando/stories/2003/08/25/daily11.html) **Orlando Business Journal 06/30/2003** [AAA, Atlantic.Net team up on discounted Internet access](http://www.bizjournals.com/orlando/stories/2003/06/30/daily17.html) **Memphis Business Journal 06/30/2003** [AAA South to offer Internet Access](http://www.bizjournals.com/memphis/stories/2003/06/30/daily10.html) **Tampa Business Journal 06/30/2003** [AAA strikes deal with Atlantic.Net](http://www.bizjournals.com/tampabay/stories/2003/06/30/daily15.html) **Orlando Business Journal 05/19/2003** [Atlantic.Net acquired Web hosting operation](http://www.bizjournals.com/orlando/stories/2003/05/19/daily43.html) **Orlando Business Journal 03/03/2003** [Power to the PSC: Uncertainty for telecom?](http://www.bizjournals.com/orlando/stories/2003/03/03/newscolumn2.html) **Gainesville Sun 02/07/2003** [Byline: “5 reasons to consider cloud services for your supply chain](http://www.inboundlogistics.com/cms/article/five-reasons-to-consider-cloud-services-for-your-supply-chain/) **Orlando Business Journal 02/03/2003** [Atlantic.Net ties into Progress Energy’s fiber-optic network](http://www.bizjournals.com/orlando/stories/2003/02/03/daily46.html) **Jacksonville Business Journal 02/03/2003** [Firm casts a wider net](http://www.bizjournals.com/jacksonville/stories/2003/02/03/daily40.html) **Jacksonville Business Journal 11/25/2002** [Company develops Internet spam tool](http://www.bizjournals.com/jacksonville/stories/2002/11/25/daily20.html) **Orlando Business Journal 11/04/2002** [This week in business: Water, water everywhere](http://www.bizjournals.com/orlando/stories/2002/11/04/weekinbiz.html) **Jacksonville Business Journal 10/21/2002** [Atlantic.Net makes Inc. 500 list](http://www.bizjournals.com/jacksonville/stories/2002/10/21/daily41.html) **Orlando Business Journal 10/21/2002** [Atlantic.Net makes Inc. 500 list](http://www.bizjournals.com/orlando/stories/2002/10/21/daily39.html) **Orlando Business Journal 09/23/2002** [Atlantic.Net expands in Southeast](http://www.bizjournals.com/orlando/stories/2002/09/23/daily16.html) **Jacksonville Business Journal 09/16/2002** [Atlantic.Net ties into Progress Energy’s fiber-optic network](http://www.bizjournals.com/jacksonville/stories/2002/09/16/daily10.html) **Jacksonville Business Journal 07/05/2002** [NE Florida company trying to lure WorldCom customers](http://www.bizjournals.com/jacksonville/stories/2002/07/08/daily25.html) **Orlando Business Journal 07/01/2002** [Kellers’s math; putting the ‘net on hold](http://www.bizjournals.com/orlando/stories/2002/07/01/newscolumn5.html) **Gainesville Sun 05/22/2002** [Atlantic.Net opening new office in Orlando](http://news.google.com/newspapers?id=v9wnAAAAIBAJ&sjid=O-wDAAAAIBAJ&dq=atlantic.net&pg=6278%2C4568870) **Orlando Business Journal 05/20/2002** [Gainesville Internet, telecommunications firm opens Maitland office](http://www.bizjournals.com/orlando/stories/2002/05/20/daily42.html) **Jacksonville Business Journal 05/20/2002** [Atlantic.Net moves into new market](http://www.bizjournals.com/jacksonville/stories/2002/05/20/daily17.html) **Jacksonville Business Journal 04/29/2002** [Atlantic.Net partner with Clear Channel](http://www.bizjournals.com/jacksonville/stories/2002/04/29/daily3.html) **Gainesville Sun 04/27/2002** [Atlantic.Net to Host Sites for Orlando Radio Stations](http://news.google.com/newspapers?id=ciUSAAAAIBAJ&sjid=SuwDAAAAIBAJ&dq=atlantic.net&pg=6371%2C5409356) **-Austin Business Journal 01/21/2002** [Florida telecom company entering Austin market](http://www.bizjournals.com/austin/stories/2002/01/21/daily51.html) **Small Business Computing Magazine 01/17/2002** [Plug In and Log On](http://www.smallbusinesscomputing.com/buyersguide/article.php/683671) **Business Week 04/23/2001** [Roll Your Own Internet](https://www.bloomberg.com/news/articles/2001-04-22/roll-your-own-internet) **Jacksonville Business Journal 05/28/2001** [Two NE Florida firms invited to Inc. 500 conference](http://www.bizjournals.com/jacksonville/stories/2001/05/28/daily10.html) **Orlando Business Journal 06/11/2001** [Ella Park Centre to get DSL Service](http://www.bizjournals.com/orlando/stories/2001/06/11/daily13.html) **Jacksonville Business Journal 06/11/2001** [Atlantic.Net Enters agreement with Orlando property](http://www.bizjournals.com/jacksonville/stories/2001/06/11/daily12.html) **Gainesville Sun 09/20/2001** [Atlantic.Net offers national access](http://news.google.com/newspapers?id=maMpAAAAIBAJ&sjid=YOwDAAAAIBAJ&dq=atlantic.net&pg=6479%2C5214245) **Jacksonville Business Journal 09/24/2001** [Atlantic.Net launches dial-up service nationwide](http://www.bizjournals.com/jacksonville/stories/2001/09/24/daily6.html) **Gainesville Sun 10/12/2001** [Atlantic.Net on list of growing companies](http://news.google.com/newspapers?id=frozAAAAIBAJ&sjid=XuwDAAAAIBAJ&dq=atlantic.net&pg=4972%2C2469309) **Jacksonville Business Journal 10/29/2001** [New Internet service allows private exchange of data](http://www.bizjournals.com/jacksonville/stories/2001/10/29/daily24.html) **The Florida Times-Union 11/02/2000** [New ISP for Palatka](http://jacksonville.com/tu-online/stories/062298/bus_1h7techn.html) **Gainesville Sun 11/02/2000** [Atlantic.Net Service](http://news.google.com/newspapers?id=Ub0zAAAAIBAJ&sjid=IuwDAAAAIBAJ&dq=atlantic.net&pg=2547%2C246385) **Jacksonville Business Journal 10/30/2000** [Florida 100 list features local firms](http://www.bizjournals.com/jacksonville/stories/2000/10/30/story7.html) **Jacksonville Business Journal 10/09/2000** [Atlantic.Net named to Inc. 500 list](http://www.bizjournals.com/jacksonville/stories/2000/10/09/daily7.html) **Jacksonville Business Journal 06/19/2000** [Atlantic.Net launches service in North Carolina](http://www.bizjournals.com/jacksonville/stories/2000/06/19/daily22.html) **Jacksonville Business Journal 03/20/2000** [Gainesville Internet company makes acquisition](http://www.bizjournals.com/jacksonville/stories/2000/03/20/daily4.html) **Jacksonville Business Journal 03/20/2000** [Atlantic.Net keeps buying](http://www.bizjournals.com/jacksonville/stories/2000/03/20/daily12.html) **Gainesville Sun 02/10/2000** [Online Precautions Urged](http://news.google.com/newspapers?id=P90nAAAAIBAJ&sjid=IOwDAAAAIBAJ&dq=atlantic.net&pg=6717%2C2230440) **Gainesville Sun 02/02/2000** [Atlantic.Net Expands](http://news.google.com/newspapers?id=N90nAAAAIBAJ&sjid=IOwDAAAAIBAJ&dq=atlantic.net&pg=4765%2C202634) **Jacksonville Business Journal 01/31/2000** [Atlantic.Net expands into Georgia and Alabama](http://www.bizjournals.com/jacksonville/stories/2000/01/31/daily8.html) **Jacksonville Business Journal 01/10/2000** [Atlantic.Net expansion technology](http://www.bizjournals.com/jacksonville/stories/2000/01/10/daily11.html) **Internet.Com 12/01/1998** [Doing Business with Atlantic.Net](http://isp-ceo.net/profiles/2002/atlanticnet.html) **Jacksonville Business Journal 11/08/1999** [Atlantic.Net buys Winter Park firm](http://www.bizjournals.com/jacksonville/stories/1999/11/08/daily1.html) **Gainesville Sun 10/11/1999** [Optimistic, Lucky? Maybe an entrepreneur](http://news.google.com/newspapers?id=L-gRAAAAIBAJ&sjid=DuwDAAAAIBAJ&dq=atlantic.net&pg=5872%2C3239643) **Jacksonville Business Journal 09/20/1999** [Firm Starts Webcare for day care](http://www.bizjournals.com/jacksonville/stories/1999/09/20/daily13.html) **Jacksonville Business Journal 08/23/1999** [Atlantic.Net expands outside Florida](http://www.bizjournals.com/jacksonville/stories/1999/08/23/daily10.html) **Englewood Herald-Tribune 07/31/1999** [UF alums find their calling on Internet](http://news.google.com/newspapers?id=3B0iAAAAIBAJ&sjid=5X0EAAAAIBAJ&dq=manoj%20marty%20puranik&pg=4731%2C6503412) **Tampa Business Journal 07/26/1999** [Online assistance Available for creating new Web sites](http://www.bizjournals.com/tampabay/stories/1999/07/26/newscolumn2.html) **Orlando Business Journal 07/26/1999** [Web access company takes on entire state](http://www.bizjournals.com/orlando/stories/1999/07/26/story6.html) **Gainesville Sun 07/21/1999** [Atlantic.Net Expands Again](http://news.google.com/newspapers?id=v80zAAAAIBAJ&sjid=bOwDAAAAIBAJ&dq=atlantic.net&pg=2996%2C5019791) **Gainesville Sun 07/15/1999** [Local on Net panel](http://news.google.com/newspapers?id=u80zAAAAIBAJ&sjid=bOwDAAAAIBAJ&dq=atlantic.net&pg=5261%2C4093811) **Jacksonville Business Journal 07/12/1999** [North Florida Internet firm growing South Florida roots](http://www.bizjournals.com/jacksonville/stories/1999/07/12/newscolumn5.html) **Gainesville Sun 06/17/1999** [Atlantic.Net Expands](http://news.google.com/newspapers?id=ytoRAAAAIBAJ&sjid=EOsDAAAAIBAJ&dq=atlantic.net&pg=3167%2C3702000) **Jacksonville Business Journal 01/04/1999** [Atlantic.Net begins 56K Internet service in St. Augustine](http://www.bizjournals.com/jacksonville/stories/1999/01/04/daily5.html) **Internet.Com 06/02/1998** [Whole Sale Dialup Directory: Atlantic.Net](http://isp-ceo.net/services/wholesalers/atlanticnet.html) **The Florida Times-Union 05/31/1998** [Student spawned firm among fastest growing](http://jacksonville.com/tu-online/stories/102100/bus_4396058.html) **The Florida Times-Union 04/11/1998** [Ahead of the game Internet firm](http://jacksonville.com/tu-online/stories/081299/bus_1E1tech_.html) **The Florida Times-Union 03/01/1998/** [Atlantic.Net buys SC Internet firm](http://jacksonville.com/tu-online/stories/072700/bus_3645271.html) **The Florida Times-Union 02/15/1998** [Atlantic.Net acquires 12th Internet provider](http://jacksonville.com/tu-online/stories/032500/bus_2561470.html) **The Florida Times-Union 01/31/1998** [ISP Moves In](http://jacksonville.com/tu-online/stories/070697/tech_rai.html) **The Hosting News 11/31/1997** [Web Host Interview with Adnan Raja of Atlantic.Net](http://www.thehostingnews.com/web-host-interview-with-adnan-raja-of-atlantic-net-12220.html) **Reuters 07/24/1997** [Orlando Magic Selects Atlantic.Net as Official Server Host](http://www.reuters.com/article/pressRelease/idUS145316+18-Mar-2009+BW20090318) **My Fox Orlando 03/31/1997** [US moving toward 'smart' debit cards, analysts predict](http://www.myfoxorlando.com/story/24636994/us-moving-toward-smart-debit-cards-say-analyst) **HostSearch 01/31/1997** [Atlantic.Net Interview](http://www.hostsearch.com/interview/atlanticnet_interview_july_2011.asp) ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Privacy Policy > URL: https://www.atlantic.net/privacy-policy/ | Updated: 2026-09-16 ***Atlantic.Net, Inc. Privacy Policy*** Atlantic.Net, Inc. (herein referred to as “Atlantic.Net”) values your business, respects your privacy, and is committed to maintaining the integrity and confidentiality of the personal data we collect. The following explains our data compilation methodology as well as the use and management of your private information.  When you visit our website, use our services, or provide your personal information to Atlantic.Net, you are agreeing to the terms of this Privacy Policy Statement. **The Information Atlantic.Net Collects** Atlantic.Net gathers data from its customers and the users (and potential users) of its website and services to help improve content, gather customer interest, behavior, and demographic information, provide targeted information about our company and its products and services, and enhance user experience. The data we collect comes primarily from you when you visit our website or create an account on our website, purchase a product or service, or engage in customer support activity. The data we collect may include personal information or other data that could identify you individually, such as: - Your name - Contact information (email address, mailing address, phone number) - Payment information (collected, but not stored by Atlantic.Net) - IP addresses, Browser details, Device info, Operating System, URL info, etc. - Live chat messages - Telephone and email conversations - Products and services engaged and metrics associated with those services - Other personal data that is voluntarily provided - Other third-party profile data available online through our affiliates and partners Atlantic.Net may use cookies to gather personal information and to utilize analytics software to track and target prospective customers. A cookie is a unique identifier that helps identify website users and tracks their activity. Cookies are not executable code, do not contain viruses, and can be disabled in the web browser’s security settings. Please note, disabling cookies may limit the level of personalization provided during a visit. Atlantic.Net may also monitor usage by tracking which pages on the website are viewed, the number of unique views, as well as time spent on a page. Atlantic.Net may compile information from third-party providers (including Atlantic.Net affiliates located in the European Union and the UK), such as site redirects, search engine queries, and SEO tools. We may also make use of publicly available data such as names, email addresses, and mailing addresses. Furthermore, our advertisements may use tracking technology to determine the effectiveness of advertising campaigns. Atlantic.Net does not market or provide services, or knowingly collect any information, from children under the age of 16 in accordance with the Children’s Online Privacy Protection Act (COPPA) and the General Data Protection Regulation (GDPR). **Advertising and Analytics** We partner with third-party platforms, including **Google Ads** and **Microsoft Advertising (Bing Ads)**, **OpenAI (ChatGPT Ads)**, **Improvely**, and **Simpli.fi**, to measure the effectiveness of our advertising campaigns and improve our services. These platforms may collect and process certain data from your interactions with our website, such as: - **Google Click Identifier (GCLID)** and **Microsoft Click ID (MSCLKID)** - **Email addresses** and other user-provided identifiers - **IP address**, browser type, and device information This data may be shared with these advertising partners to: - Attribute conversions (e.g., form submissions, purchases) to ad interactions - Improve ad targeting and performance measurement - Enable features like **Enhanced Conversions** and **Customer Match** We also use analytics and session-measurement tools, including **Google Analytics** and **Hotjar**, to understand how visitors use our website. All shared data is handled in accordance with applicable privacy laws, including the **General Data Protection Regulation (GDPR)** and the **California Consumer Privacy Act (CCPA)**. We use **hashing** and other privacy-preserving techniques to protect your information and also rely on Google and Bing ad networks to ensure utmost data privacy for audience targeting. You can learn more about how these platforms use your data by visiting: - Google’s Privacy & Terms - Microsoft Privacy Statement You may opt out of personalized advertising by visiting: - Google Ads Settings - Microsoft Ad Settings **Service Providers That Process Form Submissions** When you submit a form on this website, such as a contact request, a sales inquiry, or a newsletter signup, the details you provide are processed on our behalf by **Apollo.io**, which holds our customer relationship management records, and by **Brevo**, which delivers our email newsletters. Submissions are also checked by **Cloudflare Turnstile**, a service that confirms a form was completed by a person rather than an automated script. Each of these providers processes your information only to deliver the service we have engaged it for, under contract, and is not permitted to use it for its own purposes. **How Atlantic.Net Uses Information Collected** Atlantic.Net may use personal information in the following ways: - To personalize your web experience based on your individual needs and patterns. - To deliver and maintain our Products and Services. - To improve our website and service offerings based on your feedback. - To improve customer service and the delivery of support. - To process transactions. - To facilitate marketing analytics, such as A/B Testing. - To communicate with you via email. The email address provided may be used periodically to process orders, provide notifications of new or updated products and services, provide billing notifications, share newsletters, announce promotions, or warn of system maintenance. - To communicate important information to you via mail, web, or telephone. - To prevent or detect fraud or abuses of our Website. - To use data for marketing, remarketing, and prospecting purposes. **Disclosure of Personal Information** Atlantic.Net does not sell, trade, or transfer personal information to any unrelated entities, with the exception of trusted third parties who perform functions on our behalf. We may be required to disclose information in compliance with court orders, subpoenas, summons, discovery requests, warrants, statutes, regulations, or governmental requests or to enforce our legal rights and protect the rights and safety of others. We assume no obligation to inform users if such information is requested. **Lawfulness of Processing** Atlantic.Net makes every effort to conform to all applicable laws and regulations when collecting and using the personal information described above.  Our methods of collection and use are determined by the types of data collected and the particular context in which we collect it. We will primarily collect and use personal information when we are entering into an agreement to provide products and services to you and we need that data for the performance of our agreement. By entering into such an agreement with us and by agreeing to our privacy policy, you are providing consent to use your information as necessary. We will also collect information when you have provided specific consent to receive certain types of communication from us (newsletters, product/service announcements, promotions, etc.) or to customize your experience on our website. **California Privacy Rights (CCPA/CPRA)** If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including: - **Right to Know**: You may request information about the categories and specific pieces of personal data we collect, use, disclose, or share. - **Right to Delete**: You may request the deletion of personal information we have collected from you, subject to certain exceptions. - **Right to Correct**: You may request correction of inaccurate personal information. - **Right to Opt-Out**: You may opt out of the sale or sharing of your personal information, if applicable. - **Right to Limit Use of Sensitive Personal Information**: You may request limits on the use and disclosure of sensitive personal data. To exercise any of these rights, please contact us at **[info@atlantic.net](mailto:info@atlantic.net)** or call us at **[insert phone number]**. You may also designate an authorized agent to make requests on your behalf. Atlantic.Net does not sell personal information as defined under the CCPA/CPRA. **Data Privacy Framework Policy for the EU and Switzerland** Atlantic.Net, Inc. complies with the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland. To learn more, please visit the official site at [https://www.dataprivacyframework.gov](https://www.dataprivacyframework.gov/). **Opt-In / Opt-Out, Access, and Right-to-be-Forgotten Procedures** You may be requested to Opt-In to specific types of processing when providing personal information to Atlantic.Net. This procedure verifies that you understand and consent to our collecting and using your information in accordance with this Privacy Policy as well as any applicable governmental regulations. Please understand that by not Opting-In there may be some products and services that may be unavailable to you. You may Opt-Out after having chosen to receive certain types of communication from us, if they are not related to the performance of a service agreement.  At your request, we will discontinue such communication. If you wish to opt out, please notify us at [opt-out@atlantic.net](mailto:opt-out@atlantic.net) or write us at Business Development; Atlantic.Net, Inc.; 440 West Kennedy Blvd.; Suite 3; Orlando, FL 32810.  Please note that it may take up to 10 days to process your request. Due to the nature of our Service Level Agreement (SLA), you cannot opt out of Service and Maintenance Notifications. Atlantic.Net recognizes that citizens in the EU and other designated countries may request access to the personal information we maintain about them, under the GDPR. Under certain circumstances, Atlantic.Net will provide an individual access to their Personal Information and will allow the individual to correct, amend or delete inaccurate data. Atlantic.Net will also allow an individual to limit the use or disclosure of their personal data, according to applicable law. An individual who seeks access, or who seeks to correct, amend, or delete data, or who seeks to limit the use or disclosure of personal data should direct his query to [opt-out@atlantic.net](mailto:opt-out@atlantic.net) or write us at the address detailed above. If requested to remove or limit the use of data, we will respond within a reasonable timeframe. **Scope of Privacy Policy** This privacy policy applies to information collected through our website, but may also apply to other collected information as required by law. **SECURITY OF YOUR INFORMATION** Atlantic.Net is committed to taking reasonable security measures to protect the confidentiality of the information in our possession. To that end, we utilize technologies and measures designed to protect information from unauthorized access, use, or disclosure. The measures we use are designed to provide a level of security appropriate to the risk of processing your personal information. Databases with personal information are accessible only by Atlantic.Net employees who are bound by a confidentiality and nondisclosure agreement. **Server Data** Atlantic.Net provides services that include acting as an Internet Service Provider, a Colocation Services Provider, a Managed Services Provider, and a Cloud Services Provider to customers. When providing these services, we do not determine the purposes and/or means of processing any private data that our customers may store or transmit via those services. When providing these services, Atlantic.Net is acting only as a channel for data owned and handled by third parties. Each individual Atlantic.Net customer determines the sensitivity of their data, identifies the appropriate methods to secure and protect that data, and may request Atlantic.Net to assist, when applicable, in protecting that data. Atlantic.Net** **does not store customer passwords or private SSH keys and has no access to customers’ server data. **Changes to our Privacy Policy** Atlantic.Net reserves the right to modify this Privacy Policy at any time and without notice to customers or the public. This Privacy Policy was last updated as of September 12, 2026. **Contacting Us** If you have any questions regarding this privacy policy, please contact us: Atlantic.Net, Inc. 440 West Kennedy Blvd. Suite 3 Orlando, FL 32810 [info@atlantic.net](mailto:info@atlantic.net) --- # Atlantic.Net Speed Test > URL: https://www.atlantic.net/speed-test/ | Updated: 2026-09-16 ## The speed you need and the network you can depend on! Atlantic.Net operates world-class carrier-neutral data center facilities, consisting of multiple top tiered network providers. Our system is designed to automatically select the fastest route to transfer your data. Test our networks now: Please contact our support team at support@atlantic.net to request a speed test for your location. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Atlantic.Net Technical Support > URL: https://www.atlantic.net/support/ | Updated: 2026-09-16 Always available support by phone and email. ## A Support Team Backed by Decades of Experience With over three decades of experience, our support team is always here to assist you. You’ll have 24/7/365 access to a crop of dedicated veterans, capable of solving any technical problem you throw their way. ## How can we help you? ### Can I speak to a consultant or a sales advisor? 866-618-3282 – [sales@atlantic.net](mailto:sales@atlantic.net) ### I have questions about my bill. [cbilling@atlantic.net](mailto:cbilling@atlantic.net) ### Who can answer my colocation questions? [colocation@atlantic.net](mailto:colocation@atlantic.net) ### I can't access my server. [dedicatedservers@atlantic.net](mailto:dedicatedservers@atlantic.net) ### Is there something wrong with the Cloud? [cloudsupport@atlantic.net](mailto:cloudsupport@atlantic.net) ### Please connect me with Shared Hosting support. [websupport@atlantic.net](mailto:websupport@atlantic.net) ### Is there someone there who can help me with a remote connection? [support@atlantic.net](mailto:support@atlantic.net) --- # Atlantic.Net Case Studies > URL: https://www.atlantic.net/press-room/case-studies/ | Updated: 2026-09-16 ## Atlantic.Net Case Studies ### [Complete HealthCare](https://www.atlantic.net/press-room/case-studies/complete-healthcare-download/) ### [ShareSafe](https://www.atlantic.net/press-room/case-studies/sharesafe-solutions-download/) ### [ACP vs AWS & Azure](https://www.atlantic.net/press-room/case-studies/acp-vs-aws-azure-download/) ### [NVIDIA Mellanox InfiniBand](https://www.atlantic.net/press-room/case-studies/nvidia-mellanox-infiniband-download/) ### [NVIDIA Mellanox Connected Clouds](https://www.atlantic.net/press-room/case-studies/nvidia-mellanox-connected-clouds-download/) ### [Super Micro](https://www.atlantic.net/press-room/case-studies/super-micro-download/) ### [Eaton Data Center](https://www.atlantic.net/press-room/case-studies/eaton-data-center-download/) ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Atlantic.Net Branding Guidelines > URL: https://www.atlantic.net/press-room/logos/ | Updated: 2026-09-16 ## Atlantic.Net Logos and Badges You can use any of these logos and badges to display on your website using your referral link. ### Default Atlantic.Net Logo [PNG](https://www.atlantic.net/resources/images/anet/anet-logo-default.png) [SVG](https://www.atlantic.net/resources/images/anet/anet-logo-default.svg) ### White Atlantic.Net Logo [PNG](https://www.atlantic.net/resources/images/anet/anet-logo-white.png) [SVG](https://www.atlantic.net/resources/images/anet/anet-logo-white.svg) ### Black Atlantic.Net Logo [PNG](https://www.atlantic.net/resources/images/anet/anet-logo-black.png) [SVG](https://www.atlantic.net/resources/images/anet/anet-logo-black.svg) ### Default Powered By Logo [PNG](https://www.atlantic.net/resources/images/anet/anet-powered-by-logo-default.png) [SVG](https://www.atlantic.net/resources/images/anet/anet-powered-by-logo-default.svg) ### White Powered By Logo [PNG](https://www.atlantic.net/resources/images/anet/anet-powered-by-logo-white.png) [SVG](https://www.atlantic.net/resources/images/anet/anet-powered-by-logo-white.svg) ### Black Powered By Logo [PNG](https://www.atlantic.net/resources/images/anet/anet-powered-by-logo-black.png) [SVG](https://www.atlantic.net/resources/images/anet/anet-powered-by-logo-black.svg) ## More Resources [Download PNG](https://www.atlantic.net/resources/images/anet/anet-hipaa-logo.png) [Download PNG](https://www.atlantic.net/resources/images/anet/anet-hitech-logo.png) [Download PNG](https://www.atlantic.net/resources/images/anet/anet-baa-logo.png) [Download PNG](https://www.atlantic.net/resources/images/anet/anet-soc-logo.png) [Download PNG](https://www.atlantic.net/resources/images/anet/anet-pci-logo.png) [Download PNG](https://www.atlantic.net/resources/images/anet/anet-gdpr-logo.png) ## Atlantic.Net Color Palette Here are the official color schemes for Atlantic.Net. Primary brand color #1B38DB Secondary brand color #1E9EE4 --- # Atlantic.Net Partner Directory > URL: https://www.atlantic.net/about-us/partners-directory/ | Updated: 2026-09-16 ### [iPlum](https://www.iplum.com/) iPlum is a HIPAA-compliant business communication platform that provides healthcare organizations with secure calling, texting, and voicemail through a dedicated second line on any personal device. The platform includes encrypted messaging, call recording, auto-attendants, and team account management, with a signed BAA for covered entities. ### [BytaGig](https://www.bytagig.com/) BytaGig is a recognised managed IT and cybersecurity provider delivering high-quality technology solutions and dependable outsourced support to organisations nationwide. Their services are designed to enhance operational efficiency, strengthen security postures, and ensure reliable business continuity. With a commitment to professionalism and customer satisfaction, BytaGig serves as a trusted long-term technology partner. ### [ASA Computers](https://www.asacomputers.com/) Founded in 1989 and headquartered in Fremont, California, ASA Computers is a leading IT solution provider for AI, HPC, cloud, and data centers. They take pride in providing superior server-to-rack design with a wide variety of engineering capabilities and services to address all IT infrastructure needs. ### [AMAX](https://www.amax.com/) AMAX is a global provider of cutting-edge cloud, data center, HPC, and next-generation computing technologies designed for high efficiency and optimal performance. As a full-service technology partner, AMAX tailors both solutions and programs to meet specific needs. ### [Novelty Technology](https://www.noveltytechnology.com/) Providing end-to-end solutions from concept and strategy to design and implementation to hosting and support. ### [Let’s Talk](https://letstalkinteractive.com/) The nation’s leading provider of telemedicine solutions, virtual med-carts, provider networks, web development, customised software solutions, and behavioural health management and care. ### [Medcurity](https://medcurity.com/) Medcurity helps healthcare organizations manage HIPAA security risk and compliance through expert guidance and an AI-powered platform. Its solutions include Security Risk Analysis, HIPAA training, policy management, vendor and BAA tracking, and network security services. Medcurity works with private practices, FQHCs, rural hospitals, and multisite healthcare organizations nationwide to identify risks, organize remediation, and maintain audit-ready documentation. ### [SNS System Inc.](https://snssystem.com/) SNS System Inc. is a leading global business consulting and IT service company, providing software development and HIPAA-compliant cloud hosting for financial and clinical services. They combine complex industry and functional expertise, leading technology practices, and an advanced global delivery model to enable organisations to unlock their business potential. ### [DataStream Insurance](https://datastreaminsurance.com/) With unique access to the world’s largest database of claims data, powerful modelling technologies, and a ground-breaking approach to individually analysing a business’s security systems and digital risk profile, DataStream offers insurance tailored to each company they work with. ### [American Cyber Security Management](https://www.americancsm.com/) American Cyber Security Management (ACSM) is a leader in data privacy and security. Their on-demand assessment, implementation, and sustainability services support GDPR compliance, reduce security risks, and enable the reliability, integrity, and security of applications. ### Scribo Scribo is a cybersecurity messaging platform with a privacy component not found in the current marketplace. The NIST 800-171 compliant platform has 256-bit AES encryption, secure private messages, e-signing, large file transmission, and receipts. ### [HIPAATraining.com](https://www.hipaatraining.com/) For over 18 years HIPAATraining.com, a Digital Compliance company, has been helping organisations attain fast HIPAA compliance with minimum administrative effort. Their comprehensive HIPAA awareness training provides each course participant with a nationally recognised certification. Their bilingual program provides cumulative discounts with no contracts and live human phone support five days a week. ### [Naologic Inc.](https://naologic.com/) Naologic offers a completely visual, no-code application platform that helps small and medium-sized businesses build or customise their own marketing, sales, operations, HR, training, or purchasing applications, all without a single line of code and fully compliant with HIPAA regulations. ### [Paubox](https://www.paubox.com/) Compliant email has never been so easy. Secure every email without extra steps for both senders and recipients. Every part of your email is secure, including subject lines and calendar reminders. Works with Microsoft 365, Google Workspace, and Salesforce. ### [Accountable](https://www.accountablehq.com/) Accountable provides companies with a complete solution to all the administrative requirements set out under HIPAA. Their platform is streamlined into five key checklists: assigning privacy officers, adopting policies and procedures, employee training, compliance risk assessment, and Business Associate Agreement. ### [Total HIPAA](https://www.totalhipaa.com/) Total HIPAA Compliance offers a comprehensive and cost-effective solution for quickly developing and implementing your organisation’s personalised HIPAA compliance plan. Their compliance package, HIPAA Prime, provides interactive online HIPAA training, a thorough risk assessment, and compliance materials customised to meet industry-specific requirements. ### [Compliancy Group](https://compliancy-group.com/) HIPAA should be simple. That’s why Compliancy Group is HIPAA software with expert Compliance Coaches holding your hand to simplify compliance. Built by auditors, Compliancy Group includes everything you need for HIPAA compliance, giving confidence in your compliance plan, increasing patient loyalty, and improving the profitability of your organisation while reducing risk. ### [IS Partners, LLC](https://www.ispartnersllc.com/) I.S. Partners, LLC is a CPA firm specialising in SOC, PCI DSS, and HITRUST examinations using a streamlined audit solution model. They communicate clearly, educate as needed, and unite all critical expertise to help clients achieve clean audit opinions. They offer a customer-focused suite of risk and compliance audit and assessment services designed to help businesses meet their specific goals. ### [VoIPX International](https://voipxpbx.com/) VoIPX International is a 100% US-based company established in 2009 and headquartered in New York. VoIPX is a leading provider of cloud-based business phone services in the US and around the globe. They are dedicated to businesses focused on cost savings and time management for their telecom needs. --- # Atlantic.Net Whitepapers > URL: https://www.atlantic.net/about-us/whitepapers/ | Updated: 2026-09-16 ## Atlantic.Net Whitepapers [Bare Metal Cloud vs. Traditional Dedicated Servers](https://www.atlantic.net/about-us/bare-metal-cloud/) [Rapid Diagnostics, Precise Insights: Transforming Medical Applications with Atlantic.Net GPUs](https://www.atlantic.net/about-us/whitepapers/rapid-diagnostics-precise-insights/) [HIPAA IT Infrastructure Guide](https://www.atlantic.net/about-us/whitepapers/hipaa-it-infrastructure-guide/) [Cloud & Managed Hosting for Healthcare Professionals](https://www.atlantic.net/about-us/whitepapers/cloud-managed-hosting-for-healthcare-professionals/) [HIPAA Compliance Developer Guide](https://www.atlantic.net/about-us/whitepapers/hipaa-compliance-developer-guide/) [IT Solutions for Healthcare](https://www.atlantic.net/about-us/whitepapers/it-solutions-for-healthcare/) [HIPAA Disaster Recovery](https://www.atlantic.net/about-us/whitepapers/hipaa-disaster-recovery-guide/) [HIPAA Compliance Fundamentals](https://www.atlantic.net/about-us/whitepapers/hipaa-compliance-fundamentals/) [HIPAA Python Applications Guide](https://www.atlantic.net/about-us/whitepapers/hipaa-python-applications-guide/) [HIPAA WordPress Guide and Checklist](https://www.atlantic.net/about-us/whitepapers/hipaa-wordpress-guide-and-checklist/) [How to Make Storage HIPAA Compliant](https://www.atlantic.net/about-us/whitepapers/how-to-make-storage-hipaa-compliant/) [Why Encryption is Essential in Healthcare Cybersecurity](https://www.atlantic.net/about-us/whitepapers/why-encryption-is-essential-in-healthcare-cybersecurity/) [HIPAA LAMP Stack Guide](https://www.atlantic.net/about-us/whitepapers/hipaa-lamp-stack-guide/) [HIPAA LEMP Stack Guide](https://www.atlantic.net/about-us/whitepapers/hipaa-lemp-stack-guide/) [HIPAA WordPress Guide](https://www.atlantic.net/about-us/whitepapers/hipaa-wordpress-guide/) [HIPAA cPanel Guide](https://www.atlantic.net/about-us/whitepapers/hipaa-cpanel-guide/) [Introduction to Virtualization](https://www.atlantic.net/about-us/whitepapers/introduction-to-virtualization/) [Ransomware in the Wild](https://www.atlantic.net/about-us/whitepapers/ransomware-in-the-wild/) [Multi-Factor Authentication](https://www.atlantic.net/about-us/whitepapers/multifactor-authentication/) [Overview of Redundant Systems](https://www.atlantic.net/about-us/whitepapers/overview-of-redundant-systems/) [Power Infrastructure](https://www.atlantic.net/about-us/whitepapers/power-infrastructure/) [Choosing a Data Center](https://www.atlantic.net/about-us/whitepapers/choosing-a-data-center/) ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Ashburn, Virginia Cloud Hosting and Dedicated Hosting > URL: https://www.atlantic.net/hipaa-data-centers/ashburn-virginia-hosting/ | Updated: 2026-09-16 ## Ashburn/Reston Colocation Data Center Region Our Reston / Ashburn colocation data center hosting region in northern Virginia is ideal for clients who desire a data center in close proximity with Washington D.C., as this data center is only 15 miles outside of the capitol. Our data center region in Ashburn, Virginia is equipped to provide not only colocation hosting, but also Atlantic.Net's full suite of hosting services and solutions, including Cloud, Managed, Dedicated, PCI, and HIPAA Compliant Hosting, and Private Cloud Hosting. In addition, our Reston facility is not only located just outside the Ashburn data center alley, but away from the flight path, proving to be a safer data center location than Ashburn while still strategically located less than 22 miles away from Washington, D.C. IPv4 and IPv6 support is available at this data center. ## Ashburn Cloud Hosting Ashburn, Virginia is one of our most popular cloud hosting locations. It is uniquely placed just outside Washington, D.C., right next door to Dulles International Airport, in the heart of Data Center Alley. Ashburn is home to some of the largest data center providers in the United States, meaning the facilities are world-class, the network connectivity is some of the fastest available on the planet, and you can connect to nearly every provider imaginable. That's why Atlantic.Net has made a home in Ashburn, Virginia. We have created a major colocation data center that features enhanced hosting options, including: - Cloud VPS Hosting - Colocation Hosting - HIPAA Hosting - Compliance Hosting - IPv6 Support - Cloud Services - Managed Services ## Carrier-Neutral Data Center: Network Providers Our hosting facility in Ashburn is powered by a world-class data center infrastructure. It is carrier-neutral, so your business is always treated with prioritized delivery, allowing for the highest-quality network possible. ## HIPAA, PCI DSS, SSAE 18, SOC 2 AND ISAE 3402 COMPLIANT Our Reston/Ashburn data center hosting infrastructure is fully audited and HIPAA, PCI DSS, SSAE 18, SOC 2, and ISAE 3402 compliant. Our hosting operations are routinely and systematically inspected, so you can rest assured your system is secure with Atlantic.Net. We are so confident in the quality of our data center in Ashburn that we offer our clients a [100% uptime SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/) on both network and infrastructure. ## Colocation Hosting in Reston/Ashburn Atlantic.Net's Reston/Ashburn colocation hosting facility provides a secure, stable platform for carriers, competitive local exchangers (CLECs), Internet Service Providers (ISPs) and all other bandwidth-intensive organizations. ## Ashburn Colocation Hosting The Ashburn data center boasts impressive specifications to meet the demands of modern commercial entities, particularly those seeking top-tier cloud hosting and dedicated server solutions in the Virginia region. Here's a detailed breakdown of its features: ### Generator Power Capacity With 2,000 kW capacity, enterprises can rely on uninterrupted power supply to keep their cloud hosting and dedicated servers running smoothly, even during outages or peak demand periods. ### Cooling Redundancy (N+2) Designed with the advantages of N+2 redundancy, the cooling system guarantees optimal temperature regulation for the servers, which is essential for maintaining their performance and longevity, especially in high-density cloud hosting environments. ### 18″ Raised Floor This feature is excellent for those self-hosting; it allows for efficient airflow control and cable management and ensures plenty of working space when racking and cabling server infrastructure, perfect for facilitating easy maintenance and upgrades. ### Piller UNIBLOCK Diesel Rotary UPS and Generators These cutting-edge UPS and generators, configured for a 900 kW dedicated critical load in a 2N configuration, provide unparalleled reliability and resilience to power disruptions. Our refueling contracts mean we can indefinitely run off generator power as needed. ### 14 DX CRAC Units with Rooftop Air-Cooled Condensers (N+2) The cooling infrastructure, consisting of DX CRAC units and rooftop air-cooled condensers, ensures optimal cooling efficiency and redundancy. ### Floor Loading Up to 200 (lbs/sq. Ft.) ### Fiber and Building Entry with Multiple Diverse Entrances Companies can benefit from high-speed, reliable Internet connectivity with multiple diverse entrance points. This gives our clients many choices when opting for network carriers. ### Peering Exchanges The data center's peering exchanges facilitate enhanced network connectivity, allowing faster data transmission and improved performance. ### Security Measures The campus environment is safeguarded 24/7 by staffed security, Pan-Tilt-Zoom and infrared camera systems, and biometric and photo badge access. ### Compliance Certifications The data center complies with industry standards such as HIPAA, PCI DSS, SSAE 18, SOC 2, and ISAE 3402, assuring businesses seeking encrypted Ashburn cloud server solutions for sensitive data handling. ### Parking Availability Clients needing to work onsite, perhaps for engineering work, have the convenience of onsite parking facilities, which enhance accessibility for personnel managing colocation dedicated server deployments and rack installations. ## Ashburn Cloud Hosting Data Center Our Ashburn cloud hosting service facility offers a wide range of services, including rack cabinet hosting, cage colocation, Ashburn dedicated servers, VPS hosting, virtual servers, and managed hosting. ## Ashburn Hosting Options ### Rack Cabinets Rack cabinets are physical enclosures designed to house and organize data center servers, network equipment, and other computing hardware. We can host your existing racks and provide a secure, private, and organized environment for your infrastructure. ### Cage Colocation Cage colocation involves renting a dedicated, locked cage within the data center to house and manage your company's servers and networking equipment. We provide enhanced physical security and control over the infrastructure, making it ideal for enterprises seeking to fully manage their infrastructure. ### Ashburn Dedicated Servers Ashburn dedicated servers offer full control of your exclusive server, including full root access, making them suitable for companies with specific performance and security requirements in a server environment. ### Cloud Hosting Atlantic.Net cloud hosting involves hosting websites, applications, or services on virtual servers we provision and manage. The benefits include scalability, flexibility, and reliability, with SSD VPS, unlimited bandwidth, and easy scaling to meet growing website demands. You can access our cloud service from here. ### Managed Hosting Managed Hosting is when Atlantic.Net takes care of server management tasks on behalf of the client website. Services available include managed firewalls, backups, disaster recovery, server management, and more. ### Virtual Private Server Hosting Plans Our Ashburn cloud hosting is available in a wide variety of hosting plans. ### General Purpose General Purpose Plans (G3 series) range from the entry-level G3.2GB at $10/month to the enterprise-level G3.192GB at $960/month, offering balanced processing unit, RAM, and storage allocations. ### Storage Optimized Storage Optimized Plans (S2 series) include S2.16GB at $248/month and S2.64GB at $778/month, catering to applications with significant storage bandwidth requirements while maintaining adequate CPU and RAM resources. ### Memory Optimized RAM Optimized Plans (M2 series) feature M2.16GB at $163/month and M2.64GB at $630/month, designed for RAM-heavy environments with full bandwidth and optimized RAM performance. ### CPU Optimized Compute Optimized Plans (C2 series) encompass C2.8GB at $211/month and C2.64GB at $1,451/month, targeting applications demanding intense computational power with an optimized multicore microprocessor, RAM, and storage allocation. ## Available Operating Systems Atlantic.Net has a large number of one-click applications and operating systems that deploy in under 30 seconds. You need a Linux server; just give it a name, pick your plan and location, and then hit deploy. You will be able to connect to the server in under 30 seconds. ## Linux Choose from a wide range of popular Linux distributions, including - Ubuntu 16.04 LTS Server 32-Bit - Ubuntu 16.04 LTS Server 64-Bit - Ubuntu 18.04 LTS Server 64-Bit - Ubuntu 20.04 LTS Server 64-Bit - Ubuntu 22.04 LTS Server 64-bit - Ubuntu 24.04 LTS Server 64-bit - Ubuntu 26.04 LTS Server 64-bit - Debian 11.11.0 Server 64-Bit - Debian 12.11.0 Server 64-bit - Debian 13.0.0 Server 64-bit - Oracle Linux 7.9 64-bit - Oracle Linux 8.10 64-bit - Oracle Linux 9.6 64-bit - Oracle Linux 10.0 64-bit - Rocky Linux 8.10 64-bit - Rocky Linux 9.6 64-bit - Rocky Linux 10.0 64-bit - CentOS 6.9 Server 32-Bit - CentOS 6.9 Server 64-Bit - CentOS 7.9 Server 64-Bit - CentOS 8.2 Server 64-Bit - Fedora 42 Server 64-Bit - FreeBSD 13.0 Server 64-Bit - Arch Linux Server 64-Bit - AlmaLinux 8.10 64-bit - AlmaLinux 9.6 64-bit - AlmaLinux 10.0 64-bit - cPanel/WHM on AlmaLinux 64-bit Each distribution is available in various release versions and editions (32-bit or 64-bit), ensuring compatibility with a wide range of customer applications. Altogether, we offer users 40 distinct open-source builds for general release. ## Windows Server If you prefer Windows, we offer all major versions and editions, including - Windows Server 2025 Datacenter (Desktop Experience) - Windows Server 2025 Datacenter - Windows Server 2022 Datacenter (Desktop Experience) - Windows Server 2022 Datacenter - Windows Server 2019 Datacenter (Desktop Experience) - Windows Server 2019 Datacenter - Windows Server 2016 Datacenter (with Containers/Docker) - Windows Server 2016 Datacenter - Windows Server 2012 R2 Datacenter (Desktop Experience) - Windows Server 2012 R2 Datacenter - Windows Server 2008 R2 SP1 Datacenter We offer every major revision of Windows virtual server. Each operating system version is available in different editions (Server Edition, Desktop Experience, Container Edition) ## Why Choose Atlantic.Net for Ashburn Cloud Hosting When considering a cloud hosting provider in Ashburn, choose Atlantic.Net. Situated in Ashburn, our SSD VPS solutions offer advantages such as unlimited bandwidth and full root access, empowering companies to customize their virtual private server environment to their exact needs. With KVM virtualization technology and a wide range of operating systems, including CentOS Linux and various Windows platforms, you can easily install, configure, and customize your VPS to support your business website and applications. Atlantic.Net's cloud hosting in Ashburn ensures secure and reliable service with guaranteed CPU resources and 100% SSD storage, catering to high-traffic websites and data-intensive applications. Our support team is available to assist with installation, configuration, and any technical issues you may encounter, ensuring a seamless experience for users worldwide. Plus, with flexible payment options including PayPal, industries across America and beyond can easily upgrade and customize their VPS. Choose Atlantic.Net for cloud hosting or [USA dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/), where security, reliability, and scalability support your business growth. ## Ashburn Data Center FAQ ### Where is the Atlantic.Net Ashburn data center located? The facility sits in Ashburn, Virginia, just outside Washington, D.C., next to Dulles International Airport, in the heart of Northern Virginia's Data Center Alley. ### Is the Atlantic.Net Ashburn data center HIPAA compliant? Yes. The Ashburn facility is HIPAA, PCI DSS, SSAE 18, SOC 2, and ISAE 3402 audited and supports HIPAA-compliant deployments under a Business Associate Agreement (BAA) with Atlantic.Net. ### What power capacity and redundancy does Ashburn provide? 2,000 kW generator capacity backed by Piller UNIBLOCK Diesel Rotary UPS in a 2N configuration with a 900 kW dedicated critical load. Refueling contracts allow indefinite generator runtime during extended outages. ### What cooling redundancy does the Ashburn data center use? N+2 cooling redundancy, delivered by 14 DX CRAC units with rooftop air-cooled condensers, plus an 18″ raised floor for efficient airflow management. ### What hosting options are available at Ashburn? Cloud VPS hosting, dedicated servers, colocation (rack cabinets and cage colocation), HIPAA hosting, compliance hosting, and a full suite of managed services. ### What is the SLA on Ashburn cloud and dedicated hosting? Atlantic.Net provides a [100% uptime SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/) on both network and infrastructure for Ashburn-hosted services. ### What network connectivity does the Ashburn data center provide? Carrier-neutral connectivity with multiple diverse fiber entrances and on-site peering exchanges, allowing customers to choose from many top-tier network providers. If you’re interested in hosting in this data center region, contact an advisor at 866.618.3282 or email us [sales@atlantic.net](mailto:sales@atlantic.net). Atlantic.Net provides world-class hosting services and solutions at eight global data center regions in our [New York](https://www.atlantic.net/hipaa-data-centers/new-york-hosting/), [London](https://www.atlantic.net/hipaa-data-centers/london-uk-hosting/), [San Francisco](https://www.atlantic.net/hipaa-data-centers/san-francisco-california-hosting/), [Orlando](https://www.atlantic.net/orlando-colocation-hosting-data-center/), [Ashburn](https://www.atlantic.net/hipaa-data-centers/ashburn-virginia-hosting/), [Toronto](https://www.atlantic.net/hipaa-data-centers/toronto-canada-hosting/), [Singapore](https://www.atlantic.net/hipaa-data-centers/singapore-hosting/), and [Dallas](https://www.atlantic.net/hipaa-data-centers/dallas-texas-hosting/) locations. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Dallas Cloud Hosting and Dedicated Server Hosting > URL: https://www.atlantic.net/hipaa-data-centers/dallas-texas-hosting/ | Updated: 2026-09-16 ## Dallas, Texas Data Center Region Atlantic.Net provides innovative and award-winning infrastructure hosting services and solutions from the Dallas data center region. This Texas data center, operated by NTT, is ideal for businesses in need of high-availability hosting in a 230,000 square feet, 16-megawatt colocation facility. High availability, resiliency, flexibility, and efficiency are critical concerns in the development of all our systems. Since reliability is fundamental to your experience, we offer a 100% up-time SLA. This Dallas data center region can support Cloud, Dedicated, PCI, and HIPAA compliant hosting. IPv4 and IPv6 support is available at this data center. ## Dallas Cloud Hosting Located in the heart of the city of Dallas, Texas, our USA-Central-1 data center offers convenience to clients across the United States and those looking for direct links into Central America. We offer a wide range of services from this carrier-neutral location, including [USA dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/), cloud services, HIPAA hosting, PCI DSS hosting, and much more. ## Location: Dallas, Texas Our Texas cloud center is operated by NTT TX1. The host facility is located at 2008 Lookout Drive, Garland, Texas, in the greater Dallas area, perfect for businesses needing high-availability hosting. The Dallas cloud network facility is built from the ground up to be highly available, resilient, flexible, and efficient. Since reliability is fundamental to your experience, we offer a 100% uptime SLA. IPv6 support is also available in this region for our [cloud](https://www.atlantic.net/vps-hosting/) and [dedicated hosting services](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/). ## Carrier Neutral Data Center: Network Providers The data center in Dallas, Texas is a carrier-neutral facility. Your business always is treated with prioritized delivery, allowing the highest-quality network possible. ## 100% Up-time Network We provide a 100% Up-time SLA (service level agreement). This represents a commitment to our clients that all hardware and software is running continuously, aside from scheduled maintenance. ## SSAE 16 SOC 1 TYPE II and SOC 2 TYPE II, ISO 27001, PCI DSS, FISMA, and HIPAA The Atlantic.Net Texas hosting infrastructure has been audited and is SSAE 16 (SOC 1) TYPE II and SOC 2 TYPE II, ISO 27001, PCI DSS, FISMA, and HIPAA Audited. SSAE 16 is a widely recognized auditing standard developed by the American Institute of Certified Public Accountants (AICPA). The SSAE 16 standard demonstrates the adequate design and operating effectiveness of controls to safeguard our customers. ## Dallas Cloud Hosting Plans Dallas cloud hosting offers a comprehensive selection of hosting plans. All Dallas cloud servers come with SSD storage as standard and high-speed connections throughout. You can opt for Windows cloud hosting and Linux distributions. Each Dallas cloud hosting plan includes access to pre-installed operating systems and software licensing (where applicable), all at a convenient and affordable monthly cost. Choose from 24 virtual private server hosting plans available in four categories: ### General Purpose Our G3 plans range from 1 vCPU and 2 GB RAM to 96 vCPU and 192 GB RAM. These are perfect for everyday use, such as website and application hosting. ### Storage Optimized Our S2 plans feature added SSD storage for those who need extra space. The plans start at 500 GB SSD storage and scale up to 4 TB SSD storage. ### Memory Optimized Our M2 plans are perfect for database cloud servers or any application that demands lots of memory. Plans range from 16 GB RAM to 128 GB of high-speed ECC RAM. ### Compute Optimized Our C2 plans are for those who need a gold-standard, high-MHz CPU per cycle. Plans start at 4 vCPU and go up to 20 vCPU. ## Dallas Cloud Server Hosting Benefits ### Cloud Hosting Control Panel Our user-friendly cloud hosting control panel offers easy management and configuration of server resources, with easy access to snapshots, block storage, SSH keys, private and public IPs, DNS, and Atlantic.Net's Teams collaboration tool, all from the ACP Control Panel. [ACP Control Panel](https://cloud.atlantic.net/?page=userlogin) ### Linux Distributions We support a range of Linux distributions for cloud servers, including Ubuntu, Debian, CentOS, Rocky Linux, Oracle Linux, Fedora, FreeBSD, and Arch Linux. ### One-Click Applications All Linux distributions deploy in less than 30 seconds. Plus, we have a wide range of one-click applications featuring popular pre-configured servers built by the experts at Atlantic.Net: choose from LAMP / LEMP stacks, WordPress, Docker, Node.js, cPanel, and more. ### Rapid Windows Cloud Server Setup For Windows users, every edition from 2008, 2012, 2016, 2019, and 2022 is available in multiple flavors and licensed for you to use. The cost is built into the cloud hosting plan. Windows cloud servers typically deploy in about 60 seconds. ### Expert Support Our US-based dedicated support team is available 24/7 to assist with cloud server setup, management, and troubleshooting. ### SSD Storage Atlantic.Net Dallas servers use SSD storage, ensuring better performance and low latency for websites and applications. ### Root Access We provide administrative privileges to cloud servers as standard, allowing complete control over your server environment. Windows Server users have immediate access via a local Administrator account. ## Dedicated Dallas Cloud Servers Our dedicated cloud servers offer unmatched speed and reliability. With dedicated IP addresses and DDoS protection, our Dallas cloud servers help keep your online presence secure and uninterrupted. Enjoy instant setup and unlimited access to your cloud server, allowing you to customize and manage as desired. Choose from various operating systems, including the latest versions of Linux, and access a wealth of resources to support your needs. Our [dedicated support team](https://www.atlantic.net/support/) is always available to assist you with queries or concerns, ensuring a seamless experience for our customers. Experience the convenience of managing your hosting environment with SSH access and enjoy peace of mind with our robust security measures. ## Dallas Cloud Managed Services Atlantic.Net managed services are available in our Dallas, Texas, network operations center. To complement our hosting experience, maximize your IT support with various managed services. ### Server Management Take the stress out of server management and let our team of experts manage your server's day-to-day operations. Our support teams proactively monitor your operating system and respond to alerts such as high CPU, disk, or memory. ### Atlantic.Net Managed Firewall Our intelligent perimeter network firewalls isolate your servers from the outside world. The firewall responds automatically to threats, blocking them before they enter the network. The firewall works hand-in-hand with our DDoS protection and intrusion prevention systems. ### Multifactor Authentication Protect your investment with MFA, a two-step process to log on and use software on your system. ### Endpoint Protection Need managed antivirus protection? We offer Trend Micro Deep Security as a managed service. It protects Dallas cloud customers against the latest threats, including viruses, malware, and ransomware. ### Managed Backup Our managed backup solution is the first line of defense against digital information loss. We protect your raw data using a secure 3-2-1 strategy, meaning three copies of your data are protected on our systems. ### Compliance Hosting Our Dallas location is one of our primary compliance hosting business locations. We offer the following options: Primary compliance: a highly secure facility holding ISO/IEC 27001 certification for its information security management system, providing comprehensive security including 24/7 on-site teams and compliance with additional standards like SOC 1/2 Type II, PCI DSS, HIPAA, and NIST 800-53. Additional compliance: the data center adheres to ISO 50001 (energy management) and SOC 1/2 Type II standards. Certification scope: the facility maintains ISO/IEC 27001 certification, confirming strict management of information security and confidentiality. Plenty more managed services are available for your Dallas cloud server: check out our [managed services pages](https://www.atlantic.net/managed-services/) for more information. ## Dallas, Texas Data Center Facility Features Our Texas Internet gateway is recognized as one of the "most beautiful data centers in the world". It is utilized by multiple carriers, so it serves as an integrated data center for telecommunications companies headquartered across the globe. ## Dallas Hosting Facility Features and Specifications ### Dallas Cloud Hosting Solutions The Dallas cloud hosting center is one of our most advanced data center locations. Here are some of the outstanding features available: ### Tier IV The Dallas cloud hosting facility exceeds the Tier IV standards of the Uptime Institute, delivering continuous uptime. ### Advanced Building Facilities With a 42-acre campus and 230,000 square feet of space, our Dallas cloud hosting facility is vast, with plenty of room for future growth and expansion. ### Data Center Hall Space The Atlantic.Net Dallas cloud server suite offers over 118,000 square feet of dedicated floor space, ideal for hosting virtual private servers (VPSes) with full connectivity and minimal latency. ### Power Feed Fed by two 138 kV lines connected to five transformers, the facility delivers class-leading redundancy with two redundant utility power circuits to each building, supporting 16 MW of critical IT load with redundant power and a dense fiber network. ### Generator Power Capacity The site has a 3,400 kW generator capacity, ensuring excellent uptime in the event of power interruptions. ### Cooling Redundancy Our Dallas cloud servers use waterless indirect-air-exchange cooling technology, with 74 rooftop cooling units maintaining optimal temperatures. ### Parking The site is secured with an anti-climb perimeter fence and dedicated customer parking, restricting public access for enhanced security. ### Security Security is the number one priority for Atlantic.Net. All Dallas cloud server facilities feature manned 24/7 security, strict access controls, and multi-level security zones throughout the building. ### Compliance Our Dallas cloud hosting facility complies with best-in-class industry standards including SSAE 16 SOC 1 Type II and SOC 2 Type II, ISO 27001, PCI DSS, FISMA, and HIPAA. ## Dallas, Texas Data Center Facility Specs | Specification | Detail | | --- | --- | | Data Center Tier | Exceeds the Tier IV standards of the Uptime Institute | | Building | 42-acre campus; 230,000 square feet | | Data Center Hall Space | 118,000 square feet | | Power Feed | Fed by two 138KV lines connected to five transformers, providing two redundant utility power circuits to each building | | Generator Power Capacity | 3400 kW | | Cooling Redundancy | Waterless cooling using indirect air exchange cooling technology; 74 total rooftop cooling units | | Parking | Anti-climb perimeter fence and secured dedicated customer parking with no public access | | Fiber and Building Entry | 3 diverse fiber entrances | | Security | High-security gated entrance to prevent unauthorized entry. Hardened building-within-a-building design. Multifactor identification and multi-level security zones. 9 layers of security to access the IT infrastructure. 24x7 manned security with centralized electronic access control systems | | Compliance | SSAE 16 SOC 1 Type II and SOC 2 Type II, ISO 27001, PCI DSS, FISMA, and HIPAA | ## Why Atlantic.Net Dallas? Looking for cloud hosting in Dallas? Experience the power of Atlantic.Net for your cloud hosting needs. Our Dallas cloud servers offer high-speed network connections, helping deliver fast performance for your website or application. With superuser access and DDoS protection, you have complete control and security over your cloud server, while our SSD storage helps deliver high performance and reliability. Upgrade to Atlantic.Net in Dallas today and experience the difference in cloud hosting. Whether you are a small business owner or a seasoned developer, our Linux-based hosting solutions offer the resources and flexibility you need to succeed. Don't wait any longer, [contact Atlantic.Net today](https://www.atlantic.net/about-us/corporate-contact/). ## Dallas Data Center FAQ ### Where is the Atlantic.Net Dallas data center located? The Atlantic.Net Dallas data center is hosted in the NTT TX1 facility at 2008 Lookout Drive, Garland, Texas, in the greater Dallas metro area. ### What Tier rating does the Dallas data center have? The Dallas hosting facility exceeds Uptime Institute Tier IV standards, which require concurrent maintainability and full fault tolerance for power, cooling, and network paths. ### What is the size of the Dallas hosting facility? The campus spans 42 acres with 230,000 square feet of total space and over 118,000 square feet of dedicated data center hall space. ### What power capacity does Dallas provide? Two 138 kV utility feeds across five transformers deliver 16 MW of critical IT load with redundant power circuits to each building, backed by 3,400 kW of generator capacity. ### What cooling does the Dallas data center use? Waterless indirect-air-exchange cooling with 74 rooftop cooling units maintains optimal data center temperatures without water consumption. ### Is the Dallas data center HIPAA compliant? Yes. The Dallas facility is audited against ISO/IEC 27001, ISO 50001, SOC 1 Type II, SOC 2 Type II, PCI DSS, FISMA, NIST 800-53, and HIPAA, and supports HIPAA-compliant deployments under a Business Associate Agreement (BAA). ### What hosting options are available in Dallas? Cloud hosting (24 plans across General Purpose, Storage Optimized, Memory Optimized, and Compute Optimized tiers), dedicated servers, HIPAA hosting, PCI DSS hosting, and a full suite of managed services. IPv6 is supported in this region. If you’re interested in hosting in this data center region, contact an advisor at 866.618.3282 or email us [sales@atlantic.net](mailto:sales@atlantic.net). Atlantic.Net provides world-class hosting services and solutions at eight global data center regions in our [New York](https://www.atlantic.net/hipaa-data-centers/new-york-hosting/), [London](https://www.atlantic.net/hipaa-data-centers/london-uk-hosting/), [San Francisco](https://www.atlantic.net/hipaa-data-centers/san-francisco-california-hosting/), [Orlando](https://www.atlantic.net/orlando-colocation-hosting-data-center/), [Ashburn](https://www.atlantic.net/hipaa-data-centers/ashburn-virginia-hosting/), [Toronto](https://www.atlantic.net/hipaa-data-centers/toronto-canada-hosting/), [Singapore](https://www.atlantic.net/hipaa-data-centers/singapore-hosting/), and [Dallas](https://www.atlantic.net/hipaa-data-centers/dallas-texas-hosting/) locations. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # London Cloud Hosting and Dedicated Hosting > URL: https://www.atlantic.net/hipaa-data-centers/london-uk-hosting/ | Updated: 2026-09-16 ## London Data Centre Region Atlantic.Net provides world-class hosting services and solutions from our UK hosting data center region. The UK data center region can support Cloud, Dedicated, PCI, and HIPAA compliant hosting. Regarded as one of the top data centers in the UK, this facility is managed and operated by Virtus Data Centers. Located 25 miles from Central London and 8 miles from Heathrow Airport, this facility is ideal for clients who wish to keep their data in the United Kingdom. ## London Cloud Hosting London is the epicentre of global trade and home to one of the biggest global transit networks in Europe. Atlantic.Net offers cloud hosting services from Virtus's state-of-the-art London4 data centre. We are conveniently located in Slough, about 8 miles from Heathrow Airport. ## Tier III Certified The Atlantic.Net UK Hosting Infrastructure is fully audited and Tier III certified. Our hosting operations are routinely and systematically inspected with focus on key control objectives in the areas of energy, environmental, information security and quality management. Rest assured, your system is secure with Atlantic.Net. ## Data Centre Hosting in the UK There are many reasons to choose Atlantic.net as your host in London: this world-class facility provides a secure, stable platform for carriers, competitive local exchangers (CLECs), Internet Service Providers (ISPs) and all other bandwidth-intensive organizations. So confident are we in the quality of our London data centre that we offer our clients a [100% uptime SLA on both network and infrastructure](https://www.atlantic.net/dedicated-server-service-level-guarantee/). ## Our UK Cloud Hosting Location The London cloud data centre hooks into all Atlantic.Net cloud services. You have access to more than 20 hosting plans: choose from all of the popular operating systems, including 14 Microsoft Windows Server configurations, 40+ open-source software builds (multiple Linux distributions), and various one-click applications such as WordPress, Docker, Node.js, and Nextcloud. With our London cloud hosting, you also get access to a wide range of managed services, including SSL certificates, DDoS protection, automated backup options, custom ISOs, and SSD storage as standard. All you need to do is pick your hosting resources and decide if you want Windows cloud servers, Linux cloud servers, or even dedicated servers. ## London Cloud Hosting Data Centre Our London data centre features the very latest technology to provide class-leading hosting facilities, deep security throughout, and excellent green credentials. Here are some of the highlights of Atlantic.Net at the London4 data centre: ## London Data Centre Features ### Cloud Server Facility The London cloud facility is expansive, covering 36,000 m² across multiple floors with a net technical area of 10,600 m². Benefit from a 24/7 fully-managed on-site Network Operations Centre (NOC) for seamless cloud hosting support. Our team works directly with the London office and has an around-the-clock support team available. Uptime is critical for your London cloud server: all our cloud servers come with a 100% uptime SLA, and the local facility is built to Uptime Institute Tier III standards. ### Power Our London cloud data centre is a powerhouse: 34 MVA powers the facility directly from the national grid, supporting 23 MW of IT load with an N+N inline UPS plant. Independent power feeds protect the data centre from unpredictable and unexpected outages. For your dedicated server, you can choose from various power resilience options, including N, N+1, and N+N configurations. Centralised N+1 high-voltage standby diesel generators provide a 48-hour run time at full load, with priority fuel contracts. The handover process is fully automated and tested daily. ### Data Centre Security Rely on our 24/7 on-site security team for the safety of your cloud hosting infrastructure. The compound is protected with a 4-metre-high perimeter fence, vehicle traps, and comprehensive IP CCTV coverage. Authentication and access policy control are enhanced by a biometric entry system and security bollards. ### Energy Efficiency Even with such impressive power available on demand, the data centre's energy-efficient design is remarkable. It has a Power Usage Effectiveness (PUE) of 1.25 and a highly efficient cooling system in an N+1 configuration. Advanced cooling design, waste-heat reuse through heat pumps, and free-cooling chillers are monitored through Data Centre Infrastructure Management (DCIM) for maximum energy optimisation. ### Controlled Environment Safety is enforced through a leak-detection system, a centralised N+1 fire-suppression system, and Aspirated Smoke Detection (VESDA). ### Green Credentials London4 is committed to sustainability with a BREEAM Very Good design rating and recycling initiatives for equipment packaging. ## London Cloud Hosting Plans We have a wide range of UK cloud hosting plans to suit online business or personal users. Looking for a powerful web hosting server? You can easily run multiple websites on our cloud hosts, with multiple IP addresses to choose from. Plans range from lightweight options to powerhouse nodes capable of running the most intense business-class web apps, all at an affordable price. The hosting plans are available in four categories: ### General Purpose Ideal for everyday use, these cloud servers strike a great balance between cost and performance. You are always guaranteed the resources you pay for in all our cloud servers, but General Purpose is a great fit for developers, web hosting, and self-managed applications. ### Storage Optimized Does your UK cloud server require high-performance storage or intense I/O writes? Choose our Storage Optimized cloud hosting option. This plan is perfect for databases or projects with heavy storage utilisation. ### Memory Optimized Beneficial for specific applications that require ample RAM to operate efficiently, such as databases, content management systems, e-commerce web hosting, and data analytics. ### Compute Optimized Tailored for applications that demand high computational power and processing speed. Common workloads include gaming servers, media encoding and streaming, development build environments, and scientific / research applications. Our London cloud servers are controlled via an easy-to-use control panel. You control every aspect of your VPS, and you can add or remove managed services on demand. The panel features a streamlined user experience, simplified server management, control of your backups, and is fully customisable. ## Linux London Cloud Server We offer all popular Linux distributions, each with numerous versions and editions to choose from, ensuring the best compatibility with your web applications. We even offer older versions of popular Linux distributions to make the cloud migration process as simple as possible. - Ubuntu 16.04 LTS Server 32-bit - Ubuntu 16.04 LTS Server 64-bit - Ubuntu 18.04 LTS Server 64-bit - Ubuntu 20.04 LTS Server 64-bit - Ubuntu 22.04 LTS Server 64-bit - Ubuntu 24.04 LTS Server 64-bit - Ubuntu 26.04 LTS Server 64-bit - Debian 11.11.0 Server 64-bit - Debian 12.11.0 Server 64-bit - Debian 13.0.0 Server 64-bit - Oracle Linux 7.9 64-bit - Oracle Linux 8.10 64-bit - Oracle Linux 9.6 64-bit - Oracle Linux 10.0 64-bit - Rocky Linux 8.10 64-bit - Rocky Linux 9.6 64-bit - Rocky Linux 10.0 64-bit - CentOS 6.9 Server 32-bit - CentOS 6.9 Server 64-bit - CentOS 7.9 Server 64-bit - CentOS 8.2 Server 64-bit - Fedora 42 Server 64-bit - FreeBSD 13.0 Server 64-bit - Arch Linux Server 64-bit - AlmaLinux 8.10 64-bit - AlmaLinux 9.6 64-bit - AlmaLinux 10.0 64-bit - cPanel/WHM on AlmaLinux 64-bit ## Windows Virtual Private Server Hosting If Windows is your preferred operating system, we've got you covered. We offer every major revision of Windows virtual server. Each operating system version is available in multiple editions (Server Edition, Desktop Experience, Container Edition): - Windows Server 2025 Datacenter (Desktop Experience) - Windows Server 2025 Datacenter - Windows Server 2022 Datacenter (Desktop Experience) - Windows Server 2022 Datacenter - Windows Server 2019 Datacenter (Desktop Experience) - Windows Server 2019 Datacenter - Windows Server 2016 Datacenter (with Containers / Docker) - Windows Server 2016 Datacenter - Windows Server 2012 R2 Datacenter (Desktop Experience) - Windows Server 2012 R2 Datacenter - Windows Server 2008 R2 SP1 Datacenter ## London Compliance Hosting Our London cloud hosting service is the place to be for compliance hosting. We offer a wide range of services for customers looking for best-in-class security. Trust in our ISO certifications (ISO 9001:2008, ISO 14001:2004, ISO 27001:2013, ISO 50001:2011) for a secure and reliable cloud hosting environment in London. We offer PCI-ready platforms that provide a solid foundation for your online financial transactions, a HIPAA and HITECH-approved hosting option, and GDPR-compliant cloud servers that ensure your data is handled in line with European data protection regulations. ## London Managed Services ### Atlantic.Net Managed Firewall The segregated Atlantic.Net managed firewall service acts as a shield, safeguarding strategic points of the network perimeter. It is the first line of defence, scanning all incoming and outgoing data and automatically blocking potential malicious activity. ### Multi-Factor Authentication Multi-Factor Authentication (MFA) introduces an extra layer of risk protection by enforcing multiple layers of validated authentication for root access, making it more challenging for unauthorised users to break into your systems. ### Compliance with Trend Micro Using the latest versions and features of Trend Micro's Deep Security, Atlantic.Net offers a premium compliance product. This all-in-one real-time protection solution helps keep your system secure against evolving threats. ### Fully Managed Database Hosting Atlantic.Net's fully managed database hosting services support a variety of SQL and NoSQL options, including popular databases like MySQL, PostgreSQL, MongoDB, and Redis. ### Grow Your Business Is your business expanding? Our scalability options make upgrading storage, processing power, and database instances seamless, aligning effortlessly with your evolving data loads and user demands. ### Endpoint Protection and Compliance Assurance We prioritise client data protection with encrypted connections, firewall protection, DDoS prevention, intrusion detection and prevention systems, and regular audit trails. Compliance with industry standards including PCI, HIPAA, and GDPR is supported. ### Comprehensive Server Care With our server management service, your servers are expertly handled. Our engineers take care of everything from system monitoring and patching to backup management and troubleshooting. ### Proactive Network Security The intrusion prevention service proactively monitors the network and interconnected systems for malicious activity. Automated alerts via a SIEM platform promptly identify and block potential threats. ### 24x7 Technical Support No matter the technical issues you may be facing, our team is available around the clock for help and guidance. ## Maximum Performance with London Cloud Hosting from Atlantic.Net Unlock the power of London cloud hosting: - Experience superior performance with our high-speed SSD storage. - Help secure your virtual private server with our highly secure infrastructure. - Benefit from low-latency connections for a seamless online experience. - Take full control with our user-friendly control panel. Why choose Atlantic.Net for London cloud hosting? - Expert support team: our dedicated support team is ready to assist you 24/7. - Full access: enjoy full access and control over your virtual private server. - Windows cloud: opt for Windows cloud hosting for a versatile operating system. - UK data centre: experience low-latency hosting in our state-of-the-art UK data centre. Your virtual server, your rules: - Customise your cloud with pre-installed operating systems, including Windows Server and Linux. - Host your website with ease and cater to your customers' needs seamlessly. Transparent and affordable hosting: - No hidden fees: say goodbye to hidden charges and enjoy transparent pricing. - Dedicated server options: explore dedicated server options for robust hosting solutions. - Highly secure: trust in our highly secure virtual private servers to safeguard your data. Choose [Atlantic.Net](https://www.atlantic.net/about-us/corporate-contact/) for London cloud hosting, where performance meets security. ## Facility Technical Specifications ### FACILITY - 36,000 m2 facility including plant area over 10,600 m2 net technical space - 24/7 fully-managed on-site NOC - HD and UHD ready with over 40kW in a rack supported as standard - Built to Uptime Tier III standard ### POWER - 34 MVA incoming diversely routed supply from National Grid - 23 MW of IT load - Centralized N+N inline UPS plant - Variety of power resilience options; N, N+1, and N+N - Centralized N+1 HV standby diesel generators with 48-hour run time at full load - Priority fuel contracts ### CONNECTIVITY - Access to a wide variety of carrier connectivity solutions - Carrier-neutral data center - Access to public and private cloud via VIRTUS Cloud Connect ### SECURITY - 24/7 on-site security team - 4-meter high perimeter fence - Car parks fitted with Vehicle Traps - Internal and External IP CCTV with complete site coverage - Full authentication & access policy control - Security bollards at building perimeter - Biometric entry system ### ENERGY EFFICIENCY - Design PUE 1.25 - Highly efficient cooling system configured as N+1 - Highly efficient UPS systems - DCIM metering and monitoring - Heat pumps for waste heat reuse in communal parts - Advanced cooling design - Free cooling chillers ### SERVICES - Rack, Pod, Cage and Suite colocation options available - Remote Hands services 24/7 - On-site build room/storage room - 24/7 hot desk area - Managed office space available - On-line real-time interactive environmental monitoring system VIRTUS Intelligent Portal (VIP) - Secure on-site parking - Meeting rooms and kitchen area - VIRTUS Intelligent Portal - Customer DCIM ### CONTROLLED ENVIRONMENT - Leak detection system - Centralized N+1 fire suppression system - Aspirated Smoke Detection - VESDA ### GREEN CREDENTIALS - Designed to BREEAM Very Good - Recycling of equipment packaging ### LONDON4 CERTIFICATION - ISO 9001:2008 (Quality Management) - ISO 14001:2004 (Environmental Management) - ISO 27001:2013 (Information Security Management) - ISO 50001:2011 (Energy Management) ## London Data Centre FAQ ### Where is the Atlantic.Net London data centre located? The Atlantic.Net London facility is hosted in the Virtus London4 data centre in Slough, approximately 8 miles from Heathrow Airport. ### What Tier rating does the London facility have? The London4 facility is built to Uptime Institute Tier III standards, with concurrent maintainability for power and cooling paths. ### Is the London data centre HIPAA and GDPR compliant? Yes. The London facility holds ISO 9001:2008, ISO 14001:2004, ISO 27001:2013, and ISO 50001:2011 certifications, supports HIPAA / HITECH-compliant hosting under a Business Associate Agreement (BAA), and provides GDPR-compliant cloud servers in line with European data protection regulations. ### What power capacity does the London data centre provide? 34 MVA from the national grid supports 23 MW of IT load with an N+N inline UPS plant. Centralised N+1 high-voltage standby diesel generators provide a 48-hour run time at full load with priority refuelling contracts. Dedicated server customers can choose N, N+1, or N+N power-resilience configurations. ### How energy-efficient is the London facility? The London4 facility runs at a Power Usage Effectiveness (PUE) of 1.25, with waste-heat reuse via heat pumps, free-cooling chillers, and DCIM-monitored optimisation. The building carries a BREEAM Very Good design rating. ### What physical security protects the London data centre? A 24/7 on-site security team, a 4-metre-high perimeter fence, vehicle traps, full IP CCTV coverage, biometric entry, and security bollards. Fire safety includes leak detection, an N+1 fire-suppression system, and VESDA aspirated smoke detection. ### What hosting options are available in London? Cloud VPS hosting (4 plan classes: General Purpose, Storage Optimized, Memory Optimized, Compute Optimized, with 20+ configurations), dedicated servers, HIPAA / HITECH-approved hosting, GDPR-compliant cloud servers, and a full suite of managed services. Linux (40+ distributions) and Windows Server (14 versions) are supported. If you’re interested in hosting in this data center region, contact an advisor at 866.618.3282 or email us [sales@atlantic.net](mailto:sales@atlantic.net). Atlantic.Net provides world-class hosting services and solutions at eight global data center regions in our [New York](https://www.atlantic.net/hipaa-data-centers/new-york-hosting/), [London](https://www.atlantic.net/hipaa-data-centers/london-uk-hosting/), [San Francisco](https://www.atlantic.net/hipaa-data-centers/san-francisco-california-hosting/), [Orlando](https://www.atlantic.net/orlando-colocation-hosting-data-center/), [Ashburn](https://www.atlantic.net/hipaa-data-centers/ashburn-virginia-hosting/), [Toronto](https://www.atlantic.net/hipaa-data-centers/toronto-canada-hosting/), [Singapore](https://www.atlantic.net/hipaa-data-centers/singapore-hosting/), and [Dallas](https://www.atlantic.net/hipaa-data-centers/dallas-texas-hosting/) locations. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Toronto Cloud Hosting and Dedicated Hosting > URL: https://www.atlantic.net/hipaa-data-centers/toronto-canada-hosting/ | Updated: 2026-09-16 ## Toronto Data Center Region Our data center hosting region in Toronto is operated by ColoGlobal and is regarded as one of the top data centers in Canada. It is fully equipped with multiple high-speed fiber connections. Multiple and redundant upstream connections to Tier1 bandwidth providers enable the premium network. ## Hosting in Canada There are many reasons to choose Atlantic.net as your Toronto hosting provider: this world-class facility provides a secure, stable platform for carriers, competitive local exchangers (CLECs), Internet Service Providers (ISPs), and all other bandwidth-intensive organizations. The Canada region data center can support Cloud, Dedicated, PCI, and HIPAA compliant hosting. ## Carrier Neutral Data Center: Network Providers Our Toronto hosting facility is carrier-neutral so that your business always is treated with prioritized delivery, allowing the highest-quality network possible. ## 100% Uptime Network We provide a [100% Up-time SLA](https://www.atlantic.net/dedicated-server-service-level-guarantee/) (service level agreement). This document represents a commitment to our clients that all hardware and software is running continuously, aside from scheduled maintenance. ## Toronto, Canada Cloud Hosting Atlantic.Net is proud to offer hosting resources in Canada. Our Toronto data center is in the heart of Canada's biggest city, its largest metro market and a central interconnect for global communications. Toronto is a city of immense culture, with over 3 million people calling the capital of Ontario home. All our servers are located in Scarborough, an eastern suburb of Toronto. We are delighted to offer all of our core business services from this strategic location, which is covered by our 100% uptime SLA. We have partnered with Cologix, North America's leading network-neutral hyperscale provider and one of the top data center operators in Canada. ## Lightning-Fast Toronto Virtual Private Server Hosting Experience world-class hosting facilities in the heart of vibrant Toronto. You get fast, low-latency service, a reliable virtual server, and access to a host of connectivity options at the network edge and the Toronto Internet Exchange. Build and deploy a reliable cloud server and enjoy better performance, enhanced security, and uninterrupted operation, all at an affordable price. You simply need to pick the operating system, select the hosting plan, and hit deploy. Your Toronto cloud server will be ready in about 30 seconds. Our one-click applications are available on Windows or various Linux distributions. Each comes with full resources: a dedicated IP address as standard, solid-state (SSD) storage, and high-speed networking infrastructure. With root access enabled out of the box, you gain full control over your data security. ## Toronto Data Center Features - SAS 70 Type II/SSAE 16 certified - 24x7x365 CCTV Monitored Security - Perimeter Fencing with Automatic Gates - Interior and Exterior Hi-Res Cameras - 24x7x365 manned and monitored - Biometric authentication with man trap - N+1 UPS Systems with A+B Feeds Available - N+1 Generators - High Priority Diesel Refueling - 24x7x365 Network Operations Center - Backup Power Systems: UPS and diesel generator power systems N+1 - Environmental Control: State of the art climate control systems N+1 - Fire Suppression: Pre-action dry pipe sprinkler system with clean agent fire extinguishers - Data Center Security: Security card and biometric access and DVR camera systems ### PCI, HIPAA, HITECH, SAS 70 Type II / SSAE 16 certified Toronto cloud services meet the highest industry standards for information assurance and reliability. ### 24x7x365 CCTV-monitored security Our virtual server locations are safeguarded by continuous CCTV monitoring, enhancing cloud-hosting access controls. ### Perimeter fencing with automatic gates Physical security measures including automatic gates provide an extra layer of protection for your virtual server. ### Interior and exterior high-resolution cameras High-resolution cameras provide comprehensive surveillance both inside and outside the facility. ### Biometric authentication with mantrap Secure access is enforced using biometric authentication and mantrap entry systems. ### N+1 UPS systems with A+B feeds Uninterrupted power is supported by N+1 UPS systems and A+B feeds for reliable cloud-hosting services. Advanced climate-control systems maintain optimal operating conditions for your virtual server. ### N+1 generators Additional generators provide continuous power backup for your virtual server. Dual backup power systems (UPS and diesel generators) help keep your Toronto cloud server online during outages. ### High-priority diesel refueling Our commitment to uninterrupted service includes high-priority diesel refueling contracts for the Toronto facility. ### 24x7x365 Network Operations Center Our network operations center operates around the clock, overseeing the smooth functioning of cloud-hosting services. ### Fire suppression Pre-action dry-pipe sprinkler system with clean-agent fire extinguishers. Server suites use cutting-edge fire suppression for enhanced protection. ### IT-hub security Access to our suites is secured through a combination of access-control cards, biometric access, and DVR camera systems. ## Green Features Utilizing the natural Canadian temperature and air to cool the facility, UV reflecting roofing to prevent sunlight associated heat and local wells for cooling and water supplies make this one of the most energy-efficient and green facilities available. - The primary source of water for the data center in Toronto is from an onsite well with a redundant connection to city water. This provides the best level of redundancy to the cooling system, coupled with a reduction of their carbon footprint. - Natural air is utilized during the cooler months to cool water from the water well. This cool air helps provide cooling inside the data center and helps lower energy consumption. - With a Power Usage Effectiveness (PUE) rating of between 1.3 and 1.4, this data center uses the most efficient products and technologies on the market to deliver increased power densities and high reliability. - Toronto hosting facility utilizes a high performance and emissive cool roof with white membrane delivering high solar reflectance. Efficient roof reflects UV rays and heat to minimize the carbon footprint. - A chilled water cooling system utilizes the industry's most efficient chillers along with heat exchangers, N+1 chillers, N+1 cooling towers, and N+1 CRAC units. - The facility utilizes the most efficient transformers with onsite redundancy. ## Toronto Cloud Hosting Features Atlantic.Net offers its full range of IT-managed services from our Toronto cloud-hosting location. We offer virtual servers, including cloud hosting, dedicated cloud hosting, and compliance hosting. Our HIPAA-compliant services are hugely popular across the United States, and we have a large number of healthcare customers who trust Atlantic.Net every day to keep their protected health information safe and compliant with HIPAA standards. Each hosting plan is highly customizable. We offer four distinct classes of cloud servers, with a total of 20 options tailored to diverse hosting needs. ## Atlantic.Net Cloud Services The cloud-hosting lineup includes: ### General Purpose General Purpose plans (G3 series) range from the entry-level G3.2GB at $10/month to the enterprise-level G3.192GB at $960/month, offering balanced CPU, RAM, and storage allocations. ### Storage Optimized Storage Optimized plans (S2 series) include S2.16GB at $248/month and S2.64GB at $778/month, catering to applications with significant storage bandwidth requirements while maintaining adequate CPU and RAM resources. ### Memory Optimized Memory Optimized plans (M2 series) feature M2.16GB at $163/month and M2.64GB at $630/month, designed for RAM-heavy environments with full bandwidth and optimized RAM performance. ### CPU Optimized Compute Optimized plans (C2 series) encompass C2.8GB at $211/month and C2.64GB at $1,451/month, targeting applications demanding intense computational power with a balanced allocation of CPU, RAM, and storage. ## Linux Virtual Servers Our Toronto cloud-hosting location supports a wide range of open-source distributions for cloud hosting: - Ubuntu 16.04 LTS Server 32-bit - Ubuntu 16.04 LTS Server 64-bit - Ubuntu 18.04 LTS Server 64-bit - Ubuntu 20.04 LTS Server 64-bit - Ubuntu 22.04 LTS Server 64-bit - Ubuntu 24.04 LTS Server 64-bit - Ubuntu 26.04 LTS Server 64-bit - Debian 11.11.0 Server 64-bit - Debian 12.11.0 Server 64-bit - Debian 13.0.0 Server 64-bit - Oracle Linux 7.9 64-bit - Oracle Linux 8.10 64-bit - Oracle Linux 9.6 64-bit - Oracle Linux 10.0 64-bit - Rocky Linux 8.10 64-bit - Rocky Linux 9.6 64-bit - Rocky Linux 10.0 64-bit - CentOS 6.9 Server 32-bit - CentOS 6.9 Server 64-bit - CentOS 7.9 Server 64-bit - CentOS 8.2 Server 64-bit - Fedora 42 Server 64-bit - FreeBSD 13.0 Server 64-bit - Arch Linux Server 64-bit - AlmaLinux 8.10 64-bit - AlmaLinux 9.6 64-bit - AlmaLinux 10.0 64-bit - cPanel/WHM on AlmaLinux 64-bit Each flavor is available in different release versions and editions (32-bit or 64-bit) for added compatibility. In total, we have 40 open-source builds available on general release. ## Windows Server Cloud Hosting Many of our Toronto customers prefer Windows Server. With administrator privileges, you have full control of and access to the Microsoft features and software you rely on. There's no need to run through a complicated install: each Windows instance is deployed automatically and is ready to use in about 60 seconds. Each version is available in multiple editions (Server Edition, Desktop Experience, Container Edition): - Windows Server 2025 Datacenter (Desktop Experience) - Windows Server 2025 Datacenter - Windows Server 2022 Datacenter (Desktop Experience) - Windows Server 2022 Datacenter - Windows Server 2019 Datacenter (Desktop Experience) - Windows Server 2019 Datacenter - Windows Server 2016 Datacenter (with Containers / Docker) - Windows Server 2016 Datacenter - Windows Server 2012 R2 Datacenter (Desktop Experience) - Windows Server 2012 R2 Datacenter - Windows Server 2008 R2 SP1 Datacenter ## Managed Services The full stack of Atlantic.Net managed services is available as part of our Toronto cloud hosting. Each is available on a pay-as-you-go model, with discounted 2-year and 3-year options. See our [managed services page](https://www.atlantic.net/managed-services/) for further details. ### Atlantic.Net Firewall The segregated firewall service protects the network perimeter and strategic points. It is the first line of defense, scrutinizing every bit of data entering or leaving your systems and keeping malicious intruders at bay. ### Multi-Factor Authentication Password confidentiality is a vital layer of defense in every network. Atlantic.Net's multi-factor authentication service adds further protection to ensure your environment is hardened against external threats. MFA adds an extra layer of risk protection by requiring multiple forms of validated authentication for root access, making it more challenging for unauthorized users to break in. [Multi-Factor Authentication](https://www.atlantic.net/managed-services/multi-factor-authentication/) ### Trend Micro Deep Security Trend Micro is a top-tier compliance product, and Atlantic.Net uses the latest versions and features of Deep Security to provide an all-in-one real-time protection solution. [Trend Micro Deep Security](https://www.atlantic.net/managed-services/trend-micro-deep-security-suite/) ### Database Hosting Atlantic.Net offers fully managed database hosting services, supporting a range of SQL and NoSQL options. Popular databases like MySQL, PostgreSQL, MongoDB, and Redis are available. ### Database Administration Our experienced database administrators (DBAs) ensure your databases' optimal configuration, performance, and security. We also handle backups, updates, performance tuning, and troubleshooting. ### High Availability and Replication Thanks to our high availability and replication features, hardware failures and disruptions don't take you down. Your data remains accessible and safe, even during unexpected disruptions, using Atlantic.Net's database replication and clustering options. ### Scalability Is your business growing? We grow with you. Our scalability options make upgrading your storage, processing power, and database instances straightforward, aligning with your evolving data loads and user demands. ### Security and Compliance We prioritize client data protection with encrypted connections, firewall protection, DDoS defense, intrusion-prevention systems, and regular audit trails. We also support compliance with PCI, HIPAA, and GDPR. ### Server Management With our server management service, your virtual servers are in good hands. Our engineers handle everything from system monitoring and patching to backup management and troubleshooting. [Server Management](https://www.atlantic.net/managed-services/server-management/) ### Managed Veeam Backup Atlantic.Net's managed Veeam backup service backs up your physical and virtual servers and supports rapid recovery when needed. [Managed Veeam Backup](https://www.atlantic.net/cloud-platform/backups/) ### Intrusion Prevention System The intrusion prevention service patrols the network and interconnected systems, scanning for malicious activity. Alerting is automated via a SIEM platform to identify and block potential threats. [Intrusion Prevention System](https://www.atlantic.net/managed-services/intrusion-prevention-service/) ## Canada Cloud Hosting from Atlantic.Net Toronto is one of the most popular geographical locations for customers in Canada, the United States, and Europe. This virtual private server location provides great global bandwidth for all your traffic, perfect for hosting websites, business applications, or a high-performance database cloud server. Atlantic.Net offers all of our core services from Canada, and all our servers are built from the ground up to deliver a highly secure and resilient service. You can choose from a wide selection of cloud server operating systems, including 40 Linux distributions, 14 versions of Windows Server, and 20 different ways to configure your Canada cloud server. Sign up today and get the performance advantages your business deserves. Don't wait, secure your Toronto cloud hosting today. ## Toronto Data Center FAQ ### Where is the Atlantic.Net Toronto data center located? The Atlantic.Net Toronto facility is hosted in Cologix's data center in Scarborough, an eastern suburb of Toronto, Ontario, Canada. ### Is the Atlantic.Net Toronto data center HIPAA compliant? Yes. The Toronto facility is PCI, HIPAA, HITECH, and SAS 70 Type II / SSAE 16 certified, and supports HIPAA-compliant deployments under a Business Associate Agreement (BAA) with Atlantic.Net. ### Does Toronto hosting keep data inside Canada? Workloads provisioned in the Toronto region are physically hosted in Canada at the Scarborough Cologix facility, supporting customers with Canadian data residency requirements. ### What power and cooling redundancy does the Toronto facility provide? N+1 UPS systems with A+B power feeds, N+1 diesel generators, high-priority refueling contracts, and advanced climate-control systems for optimal operating conditions. ### What physical security measures protect the Toronto facility? 24x7x365 CCTV monitoring, perimeter fencing with automatic gates, interior and exterior high-resolution cameras, biometric authentication, mantrap entry, and pre-action dry-pipe sprinklers with clean-agent fire extinguishers. Suite access is gated by access-control cards, biometric access, and DVR camera systems. ### What hosting options are available in Toronto? Cloud VPS hosting (4 plan classes: G3 General Purpose, S2 Storage Optimized, M2 Memory Optimized, C2 Compute Optimized, with 20 total configurations), dedicated cloud hosting, HIPAA-compliant hosting, and a full suite of managed services. Linux (40 distributions) and Windows Server (14 versions) are supported. ### What network connectivity does Toronto provide? Cologix is North America's leading network-neutral hyperscale operator and provides direct access to the Toronto Internet Exchange (TorIX) and a wide range of global carriers, supporting low-latency connectivity for customers across Canada, the United States, and Europe. If you’re interested in hosting in this data center region, contact an advisor at 866.618.3282 or email us [sales@atlantic.net](mailto:sales@atlantic.net). Atlantic.Net provides world-class hosting services and solutions at eight global data center regions in our [New York](https://www.atlantic.net/hipaa-data-centers/new-york-hosting/), [London](https://www.atlantic.net/hipaa-data-centers/london-uk-hosting/), [San Francisco](https://www.atlantic.net/hipaa-data-centers/san-francisco-california-hosting/), [Orlando](https://www.atlantic.net/orlando-colocation-hosting-data-center/), [Ashburn](https://www.atlantic.net/hipaa-data-centers/ashburn-virginia-hosting/), [Toronto](https://www.atlantic.net/hipaa-data-centers/toronto-canada-hosting/), [Singapore](https://www.atlantic.net/hipaa-data-centers/singapore-hosting/), and [Dallas](https://www.atlantic.net/hipaa-data-centers/dallas-texas-hosting/) locations. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # San Francisco/ Santa Clara Cloud Hosting and Dedicated Hosting > URL: https://www.atlantic.net/hipaa-data-centers/san-francisco-california-hosting/ | Updated: 2026-09-16 ## San Francisco/ Santa Clara Data Center Region Our Santa Clara, California Data Center region is ideal for clients who desire to keep their data local and close to San Francisco and Silicon Valley. Regarded as one of the top data centers in California, this facility is managed and operated by The Digital Realty Trust. ## San Francisco, California Hosting Santa Clara, the heart of Silicon Valley, is home to Atlantic.Net's state-of-the-art West Coast data center. Whether you're launching a San Francisco cloud server, building a high-traffic website, or managing mission-critical applications, this data center delivers the power, speed, and security your online projects demand. IPv4 and IPv6 support is available in this region with [our cloud server](https://www.atlantic.net/vps-hosting/) and [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) options. Our San Francisco data center hosting infrastructure is fully audited and SOC 2, SOC 3, and HIPAA compliant. Our hosting operations are routinely and systematically inspected, so you can rest assured your system is secure with Atlantic.Net. ## San Francisco Cloud Hosting Plans We have a wide range of cloud hosting plans to suit online business or personal users. The plans vary from lightweight options to powerhouse nodes capable of running the most intense business-class web apps, all at an affordable price. The hosting plans are available in four categories: ### General Purpose Ideal for everyday use, these cloud servers offer a balanced blend of cost and performance, perfect for developers, web hosting, and self-managed applications. ### Storage Optimized If your projects demand high-performance storage or intensive I/O, our storage-optimized cloud hosting is the answer. It is ideal for databases or data-intensive applications. ### Memory Optimized Choose this option if your applications require ample RAM, such as databases, content management systems, e-commerce platforms, or data analytics tools. ### Compute Optimized Our compute-optimized cloud plans are tailored for gaming servers, media encoding, development environments, and scientific / research applications, ensuring maximum processing power and speed. ## Intuitive Control & Customization Our San Francisco cloud servers are managed through an intuitive control panel, giving you complete control over your environment. Easily add or remove managed services as your needs evolve. The control panel offers streamlined server management, backup control, and extensive customization options. ## Available Operating Systems Atlantic.Net has a large number of one-click applications and operating systems that deploy in under 30 seconds. You need a Linux server; just give it a name, pick your plan and location, and then hit deploy. You will be able to connect to the server in under 30 seconds. ## Linux Choose from a wide range of popular Linux distributions, including - Ubuntu 16.04 LTS Server 32-Bit - Ubuntu 16.04 LTS Server 64-Bit - Ubuntu 18.04 LTS Server 64-Bit - Ubuntu 20.04 LTS Server 64-Bit - Ubuntu 22.04 LTS Server 64-bit - Ubuntu 24.04 LTS Server 64-bit - Ubuntu 26.04 LTS Server 64-bit - Debian 11.11.0 Server 64-Bit - Debian 12.11.0 Server 64-bit - Debian 13.0.0 Server 64-bit - Oracle Linux 7.9 64-bit - Oracle Linux 8.10 64-bit - Oracle Linux 9.6 64-bit - Oracle Linux 10.0 64-bit - Rocky Linux 8.10 64-bit - Rocky Linux 9.6 64-bit - Rocky Linux 10.0 64-bit - CentOS 6.9 Server 32-Bit - CentOS 6.9 Server 64-Bit - CentOS 7.9 Server 64-Bit - CentOS 8.2 Server 64-Bit - Fedora 42 Server 64-Bit - FreeBSD 13.0 Server 64-Bit - Arch Linux Server 64-Bit - AlmaLinux 8.10 64-bit - AlmaLinux 9.6 64-bit - AlmaLinux 10.0 64-bit - cPanel/WHM on AlmaLinux 64-bit Each distribution is available in various release versions and editions (32-bit or 64-bit), ensuring compatibility with a wide range of customer applications. Altogether, we offer users 40 distinct open-source builds for general release. ## Windows Server If you prefer Windows, we offer all major versions and editions, including - Windows Server 2025 Datacenter (Desktop Experience) - Windows Server 2025 Datacenter - Windows Server 2022 Datacenter (Desktop Experience) - Windows Server 2022 Datacenter - Windows Server 2019 Datacenter (Desktop Experience) - Windows Server 2019 Datacenter - Windows Server 2016 Datacenter (with Containers/Docker) - Windows Server 2016 Datacenter - Windows Server 2012 R2 Datacenter (Desktop Experience) - Windows Server 2012 R2 Datacenter - Windows Server 2008 R2 SP1 Datacenter We offer every major revision of Windows virtual server. Each operating system version is available in different editions (Server Edition, Desktop Experience, Container Edition) ## Compliance Hosting Our San Francisco cloud hosting prioritizes data security and compliance. We adhere to ISO certifications (ISO 9001:2008, ISO 14001:2004, ISO 27001:2013, ISO 50001:2011) for a secure hosting environment. We also offer: - PCI-ready platforms; - HIPAA / HITECH-approved hosting; - and CCPA and GDPR-compliant cloud servers to meet your specific regulatory needs. ## Why Choose Atlantic.Net's San Francisco Data Center? ### Strategic Location & Unrivaled Connectivity Strategically located in the heart of Silicon Valley, our data center delivers fast connectivity and minimizes latency for your West Coast users and beyond. ### High-Performance Hosting Solutions Scalable Cloud Servers: Our virtual private servers (VPSes) offer scalable, affordable, and customizable hosting configurations. Choose from various Linux cloud server options (including Ubuntu and Arch Linux) or Windows Server, all with SSD storage for exceptional speed. You get full root access and a dedicated IP address for complete control over your virtual environment. Powerful Dedicated Servers: Our dedicated servers are the ideal choice for maximum performance and resources. They offer dedicated hardware resources, full root access, and the flexibility to customize your server to your exact needs. ### Reliability & Security You Can Trust Industry-Leading Uptime: Our data center infrastructure is designed for redundancy and high availability, backed by a 100% uptime SLA. You can trust us to keep your online projects running smoothly. Stringent Security: Our data center is SOC 2, SOC 3, and HIPAA compliant, and our team of experts implements rigorous security measures and regular updates to safeguard your data and infrastructure. Flexible Management Options: The Atlantic.Net control panel gives you complete control of our cloud hosting services. Implement teams to delegate cloud server management, upgrade your virtual servers on demand, and integrate the data center cloud features you need, such as backups, IPv6, block storage, snapshots, and more, all from our easy-to-use control panel. ## Host in California There are many reasons to choose Atlantic.Net as your San Francisco host. Our world-class cloud server and dedicated hosting provide a secure, stable platform for organizations of all sizes. We are so confident in the quality of our hosting services in California that we offer our clients a [100% uptime SLA on both network and infrastructure](https://www.atlantic.net/dedicated-server-service-level-guarantee/). This world-class facility provides a secure, stable platform for carriers, competitive local exchangers (CLECs), Internet Service Providers (ISPs), and all other bandwidth-intensive organizations. This Santa Clara data center region can support Cloud, Dedicated, PCI, and HIPAA compliant hosting. ## Data Center Features and Certifications Our state-of-the-art San Francisco data center is built to deliver the speed, reliability, and security your online presence demands. Strategically located in the heart of the tech world, we minimize latency for your websites and applications, ensuring optimal performance for your users in the USA and beyond. ## Facility Highlights ### Robust infrastructure - 2-story facility with 198,000 sq. ft. of space - Flood Zone X (unshaded), outside the 100-year floodplain - Seismic Zone 4 construction for earthquake resistance - ICB floor loading up to 250 lbs/sq. ft. - Fiber and building entry: multiple diverse entrances - Roof rights available - Parking available ### Uninterruptible power - 7,533 kW utility power capacity with redundant feeds - 5,950 kW UPS power capacity with 2N redundancy - 12,000 kW generator power capacity with N+1 redundancy - Power density 250-350 W/sq. ft. - DC power not available ### Efficient cooling - N+1, 2N cooling redundancy - Roof membrane and reinforced concrete decking ### Top-tier security - 24/7 on-site security personnel - CCTV camera systems with 90-day retention - Biometric and photo badge access - Mantrap entry into the data center suite - Full perimeter fencing - SOC 2, SOC 3, and HIPAA compliant ## Why Our San Francisco Cloud Hosting is the Smart Choice By hosting your cloud server with us, you gain: ### Full Control Manage your virtual machines with the operating system of your choice. ### Class-Leading Reliability Benefit from redundant power and cooling systems to keep your online presence up 24/7. ### Ironclad Security Rest easy knowing your data is protected by the latest security measures. ### SFMIX Peering Connect directly to major Internet exchanges for optimal network performance. Ready to supercharge your online presence? Explore our affordable cloud hosting plans today and experience the difference our San Francisco data center makes. ## Build, Scale, and Secure Your Digital Infrastructure in Atlantic.Net's San Francisco Data Center Atlantic.Net's San Francisco data center is more than just a place to host your servers: it's the foundation for your digital success. We offer various payment methods and competitive pricing to fit your budget. Whether you're a growing business or an established enterprise, we're here to support your digital journey with cutting-edge technology and exceptional US-based customer service. ## San Francisco Data Center FAQ ### Where is the Atlantic.Net San Francisco data center located? The facility is in Santa Clara, California (the heart of Silicon Valley) and is operated by Digital Realty Trust. ### Is the San Francisco data center HIPAA compliant? Yes. The San Francisco facility is SOC 2, SOC 3, and HIPAA audited, and additionally holds ISO 9001:2008, ISO 14001:2004, ISO 27001:2013, and ISO 50001:2011 certifications. HIPAA-compliant deployments are supported under a Business Associate Agreement (BAA) with Atlantic.Net. ### What power capacity does the San Francisco facility provide? 7,533 kW of utility power capacity with redundant feeds, 5,950 kW of UPS capacity in 2N redundancy, and 12,000 kW of generator capacity in N+1 redundancy. ### What seismic and flood ratings does the San Francisco building carry? A 2-story, 198,000-square-foot building with ICB floor loading up to 250 lbs/sq. ft. The site is rated Seismic Zone 4 for earthquake resistance and sits in Flood Zone X (unshaded), outside the 100-year floodplain. ### What cooling redundancy does the San Francisco data center use? N+1 / 2N cooling redundancy, with a roof membrane and reinforced concrete decking for thermal stability and structural protection. ### Is the San Francisco facility connected to SFMIX? Yes. The data center peers directly with SFMIX (the San Francisco Bay Area Internet Exchange) for optimized regional network performance, in addition to direct access to other major Internet exchanges. ### What hosting options are available in San Francisco? Cloud VPS hosting (General Purpose, Storage Optimized, Memory Optimized, and Compute Optimized tiers), dedicated servers, HIPAA-compliant hosting, PCI-ready platforms, and managed services. IPv4 and IPv6 are supported. ## Contact Us Today Ready to experience the power of Atlantic.Net's San Francisco data center? [Contact our team today](https://www.atlantic.net/about-us/corporate-contact/) to discuss your cloud hosting, dedicated server, or colocation needs. Let us help you unlock the full potential of your online projects. If you’re interested in hosting in this data center region, contact an advisor at 866.618.3282 or email us [sales@atlantic.net](mailto:sales@atlantic.net). Atlantic.Net provides world-class hosting services and solutions at eight global data center regions in our [New York](https://www.atlantic.net/hipaa-data-centers/new-york-hosting/), [London](https://www.atlantic.net/hipaa-data-centers/london-uk-hosting/), [San Francisco](https://www.atlantic.net/hipaa-data-centers/san-francisco-california-hosting/), [Orlando](https://www.atlantic.net/orlando-colocation-hosting-data-center/), [Ashburn](https://www.atlantic.net/hipaa-data-centers/ashburn-virginia-hosting/), [Toronto](https://www.atlantic.net/hipaa-data-centers/toronto-canada-hosting/), [Singapore](https://www.atlantic.net/hipaa-data-centers/singapore-hosting/), and [Dallas](https://www.atlantic.net/hipaa-data-centers/dallas-texas-hosting/) locations. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # New York Cloud, Dedicated, PCI, and HIPAA compliant hosting > URL: https://www.atlantic.net/hipaa-data-centers/new-york-hosting/ | Updated: 2026-09-16 ## New York Data Center Region Our New York data center facility is operated by the Digital Realty Trust, making it the most interconnected colocation data center in the New York City area. This facility is ideal for clients, who desire close proximity with the Financial centers and exchanges, as this facility is only 11 miles outside of Manhattan. The New York region can support Cloud, Dedicated, PCI, and HIPAA compliant hosting. ## Data Center Hosting in New York City This NYC hosting facility provides a secure, stable platform for carriers, competitive local exchangers (CLECs), Internet Service Providers (ISPs), and all other bandwidth-intensive organizations. So confident are we in the quality of our New York data center that we offer our clients a [100% uptime SLA on both network and infrastructure](https://www.atlantic.net/dedicated-server-service-level-guarantee/). ## Atlantic.Net New York City Data Center Located just 11 miles from Manhattan, Atlantic.Net's New York City data center is in the heart of America's global business metropolis. The data center features state-of-the-art facilities designed to meet the demanding needs of global businesses and developers in the American Northeast and across the globe. NYC hosts all of Atlantic.Net's class-leading services, including: - Cloud Hosting Services - HIPAA-Compliant Hosting - Infrastructure-as-a-Service - Managed Services - Dedicated Hosts - and much more The Atlantic.Net Cloud Platform provides both IPv4 and IPv6 support in this region. ## New York City Virtual Private Server Hosting Plans We offer a wide selection of high-performance cloud hosting plans designed to meet the unique demands of your projects. All cloud hosting plans feature SSD storage, ultra-high bandwidth, and low latency. NVMe options are available on dedicated server hosting. Each plan is categorized based on resource optimization, ensuring an ideal balance between power and affordability. Our plans include: ## General Purpose Our General Purpose plans provide a well-rounded blend of processing power, memory, and storage, making them perfect for various applications like web hosting, small databases, and development environments. ## Storage Optimized If your projects involve large databases, data warehousing, or applications with intensive input/output (I/O) operations, our Storage Optimized plans are the ideal choice. They offer generous SSD storage capacity and optimized configurations for maximum disk throughput. ## Memory Optimized Our Memory Optimized plans are designed to excel at memory-intensive workloads like high-traffic websites, real-time analytics, or in-memory databases. These servers have large amounts of RAM to ensure smooth operation and rapid responsiveness when under heavy loads. ## Compute Optimized Our Compute Optimized plans are engineered for CPU-intensive tasks like video encoding, machine learning, scientific simulations, and high-performance computing. These servers feature powerful processors with multiple cores to deliver exceptional performance. ## Self-Hosted Cloud Server with Managed Services We offer a unique solution for those who desire the control of a self-hosted environment without the burden of server management. You can lease dedicated data center space for your server hardware. Our experienced team will handle the transfer of existing equipment to ensure a smooth setup. Our experts can provide around-the-clock maintenance, security, and ongoing support so you can focus on your core business deliverables. With our managed self-hosted options, you can: ### Bring Your Own We can host your existing server environment at any of our colocation centers. ### Integrate with Managed Services Integrating existing hardware with the Atlantic.Net Cloud platform opens the door to a wide range of managed services. Each service is designed to provide the optimal performance and reliability you desire. ### Complete Control Install your preferred operating system, software, and configurations exactly as you need them. ### Hands-Off Management We can manage as much (or as little) as you like. We can take care of all server administration, security patches, backups, monitoring, and more. ### 24/7 Support Our experts are available around the clock to address any concerns or issues. Our self-hosted option enables businesses and individuals who need the flexibility and control of a self-hosted environment but prefer to leave the world-class data center facilities and technical management to professional IT consultants. Whether you choose our pre-configured plans or opt for the flexibility of our managed self-hosted solution, we are committed to providing reliable, high-performance cloud solutions that enable your projects and businesses to thrive. ## Available Operating Systems Atlantic.Net has a large number of one-click applications and operating systems that deploy in under 30 seconds. You need a Linux server; just give it a name, pick your plan and location, and then hit deploy. You will be able to connect to the server in under 30 seconds. ## Linux Choose from a wide range of popular Linux distributions, including - Ubuntu 16.04 LTS Server 32-Bit - Ubuntu 16.04 LTS Server 64-Bit - Ubuntu 18.04 LTS Server 64-Bit - Ubuntu 20.04 LTS Server 64-Bit - Ubuntu 22.04 LTS Server 64-bit - Ubuntu 24.04 LTS Server 64-bit - Ubuntu 26.04 LTS Server 64-bit - Debian 11.11.0 Server 64-Bit - Debian 12.11.0 Server 64-bit - Debian 13.0.0 Server 64-bit - Oracle Linux 7.9 64-bit - Oracle Linux 8.10 64-bit - Oracle Linux 9.6 64-bit - Oracle Linux 10.0 64-bit - Rocky Linux 8.10 64-bit - Rocky Linux 9.6 64-bit - Rocky Linux 10.0 64-bit - CentOS 6.9 Server 32-Bit - CentOS 6.9 Server 64-Bit - CentOS 7.9 Server 64-Bit - CentOS 8.2 Server 64-Bit - Fedora 42 Server 64-Bit - FreeBSD 13.0 Server 64-Bit - Arch Linux Server 64-Bit - AlmaLinux 8.10 64-bit - AlmaLinux 9.6 64-bit - AlmaLinux 10.0 64-bit - cPanel/WHM on AlmaLinux 64-bit Each distribution is available in various release versions and editions (32-bit or 64-bit), ensuring compatibility with a wide range of customer applications. Altogether, we offer users 40 distinct open-source builds for general release. ## Windows Server If you prefer Windows, we offer all major versions and editions, including - Windows Server 2025 Datacenter (Desktop Experience) - Windows Server 2025 Datacenter - Windows Server 2022 Datacenter (Desktop Experience) - Windows Server 2022 Datacenter - Windows Server 2019 Datacenter (Desktop Experience) - Windows Server 2019 Datacenter - Windows Server 2016 Datacenter (with Containers/Docker) - Windows Server 2016 Datacenter - Windows Server 2012 R2 Datacenter (Desktop Experience) - Windows Server 2012 R2 Datacenter - Windows Server 2008 R2 SP1 Datacenter We offer every major revision of Windows virtual server. Each operating system version is available in different editions (Server Edition, Desktop Experience, Container Edition) ## Compliance Hosting Atlantic.Net is famous for its world-leading compliant hosting services. Our New York cloud hosting prioritizes data security and compliance. We adhere to HIPAA, HITECH, ISO 14001, ISO 27001, ISO 9001, PCI DSS, Privacy Shield, SOC 2, SOC 2 Type 2, and SOC 3 for a secure hosting environment. Tailor your cloud solution to your unique requirements with our specialized options: - PCI-ready platforms: for secure payment processing environments. - HIPAA / HITECH-approved hosting: specifically designed for healthcare providers and their partners. - CCPA and GDPR-compliant cloud servers: ensuring your business adheres to global data privacy standards. ## SOC2, SOC3, HIPAA and PCI Compliant Our NYC Data Center Hosting Infrastructure is fully audited and SOC2 and SOC3 certified as well as [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/) and [PCI compliant](https://www.atlantic.net/pci-compliant-hosting/). Our hosting operations are routinely and systematically inspected so you can rest assured, your system is secure with Atlantic.Net. ## FACILITY SPECS - Building: 7 stories; 211,000 (sq. Ft.) - Flood Zone: Zone X (Unshaded): Outside 500-year flood plain - Seismic: Zone 2A - Utility Power Capacity: 11,000 (kW) - UPS Power Capacity: 4,950 (kW) - UPS Redundancy: N+1, 2N - Power Density: Up to 175 (W/sq. Ft.) - DC Power: Not Available - Generator Power Capacity: 9,000 (kW) - Generator Redundancy: N+1, 2N - Cooling Redundancy: N+1 - Roof: Membrane and Reinforced Concrete Decking - Roof Rights Available - ICB - Floor Loading: Up to 200 (lbs/sq. Ft.) - Fiber and Building Entry: Multiple Diverse Entrances - Peering Exchanges: Digital Realty Internet Exchange - Security: Campus Environment: 24x7 manned security - Full PTZ and Infrared Camera Systems - Biometric and Photo Badge Access - Man Trap into the Data Center Suites - Elevator Authentication - Crash-rated, Anti-climb Fence - SOC2, SOC3, HIPAA, and PCI Compliant - Parking Available ## New York Cloud Server Key Features & Benefits What do you get from our NYC data center facility? Let's dig deeper. ## Strategic Location New York has a dense concentration of businesses and financial hubs that demand high-quality data services. Our facility boasts excellent connectivity with numerous Internet exchange points and fiber-optic cable landings, ensuring fast and reliable data transmission. A stable regulatory environment, potential economic incentives, and the ability to provide disaster recovery and business continuity make New York City a strong strategic choice for your data center. ## Unmatched Connectivity Our facility has direct access to hundreds of leading network carriers, ensuring fast and reliable connections for your applications. We are a carrier-neutral business with ultra-high-speed network connections to the most popular core network providers. Being in New York gives you many choices. ## Data Center Specifications for Cloud Hosting in the New York City Area This data center, strategically located in the New York City area, is designed to meet the demanding requirements of modern business. The facility features top-tier performance, superb reliability, high-performance hosting, and robust security: ## Infrastructure - Power capacity: 4,000 kW (with 11,000 kW building capacity). The high power capacity is essential for our clients' energy-intensive operations. The building capacity ensures the data center can scale to meet future demand. - UPS redundancy: N+1 to 2N (4,950 kW UPS capacity). Uninterruptible Power Supply (UPS) systems with N+1 to 2N redundancy guarantee uninterrupted power delivery, protecting your New York City cloud server from downtime and data loss during outages. - Power density: up to 175 W/sq. ft. This efficient power density maximizes the use of space, allowing the data center to host a higher number of New York cloud servers while maintaining optimal operating conditions. - Cooling redundancy: N+1. Redundant cooling systems with N+1 configuration help prevent disruptions due to overheating. - Generator power capacity: 9,000 kW. Our generators provide continuous backup power during prolonged outages, ensuring that your services remain online even in adverse conditions. - Generator redundancy: N+1, 2N. N+1 and 2N generator redundancy guarantees seamless power switchover in case of primary generator failure, ensuring uninterrupted operations. ## Security The data center's physical security measures protect the facility from unauthorized access. These measures include: - 24/7 manned security: for around-the-clock monitoring and immediate response to any security concerns. - Biometric card key and photo badge access: multi-factor entrance authentication for added protection. - Full PTZ and infrared camera systems: a comprehensive surveillance and CCTV system. - Mantrap entry to data center suites: adds an extra layer of security to prevent unauthorized entry. - Elevator authentication: restricts access to specific floors within the data center. - Crash-rated, anti-climb fence: provides a formidable physical barrier against intrusion. ## Building - Size: 7 stories, 211,000 sq. ft. A spacious facility provides ample room for customer deployments and future expansion as your hosting needs evolve. - Flood zone: Zone X (unshaded), outside the 500-year floodplain. The location's minimal flood risk safeguards your virtual servers from storm surge water damage. - Seismic zone: 2A. The low seismic activity in the region reduces the risk of earthquake-related disruptions to your New York City cloud hosting services. - Floor loading: up to 200 lbs/sq. ft. Ensures the structural integrity of the building can handle the weight of dense server racks. - Parking available: plenty of convenient parking for staff, clients, and deliveries simplifies access to the data center. ## Key Advantages of Cloud Hosting Services You now know the data-center-specific features that set Atlantic.Net's New York cloud hosting data center apart from the competition. What other class-leading features are available? ### #1: Dedicated Servers Available NYC offers dedicated resources, personalized service, and a range of IP addresses for your New York cloud server. When you buy cloud hosting here, you can expect guaranteed uptime, full control over your virtual environment, and high availability. ### #2: Cloud Hosting New York plans offer cloud and dedicated infrastructure options, giving you the flexibility to choose the best solution for your needs. ### #3: Full Root Access and Administrator Roles With full root access for Linux and full admin roles for Windows, plus 'teams' collaboration within an intuitive control panel, you can customize your virtual servers to perfectly match your business requirements. ### #4: Support Team Available 24x7x365 Our expert advisors are available to provide personalized support and ensure optimal performance for your Windows and Linux cloud hosting plans. ### #5: Developer-Friendly We offer a range of features designed for web developers to streamline development and deployment, including one-click apps like WordPress, LAMP, LEMP, Docker, Node.js, Mesibo, Nextcloud, MySQL, cPanel, and more. ### #6: Scalable Solutions When you outgrow your existing environment, it's simple with Atlantic.Net to scale up and reprovision cloud hosting resources to meet the required demand. ### #7: Compliance Hosting Our data center adheres to ISO certifications and offers PCI-ready platforms, HIPAA / HITECH-approved hosting, and CCPA / GDPR-compliant cloud servers. ## Why Choose Atlantic.Net in NYC? New York is a growing tech center for the entire United States. It's a great location for services inside the US and for anyone working in Europe and the wider world. Atlantic.Net's New York hosting data center delivers a great blend of cutting-edge technology, robust infrastructure, and unparalleled customer support. ## Choose Atlantic.Net Hosting Solutions New York offers all of Atlantic.Net's award-winning hosting solutions. ### ACP Cloud Platform Atlantic.Net's Cloud Platform (ACP) offers a fault-tolerant, maximum-performance infrastructure built for the future. It's revolutionizing how businesses operate, offering transparent, all-inclusive pricing and world-class infrastructure backed by expert support, available 24/7 via phone or email. This robust platform includes award-winning cloud servers, secure block storage, simplified one-click application deployment, DNS management, dedicated private nodes, secure private networking, a flexible RESTful API, comprehensive data backup, and a full suite of managed services to streamline your operations. ### Dedicated Hosting Unleash unparalleled power and control with Atlantic.Net's dedicated server hosting solutions. Each private physical server is equipped with the latest hardware and offers full root access for complete customization. Atlantic.Net provides a variety of dedicated server options tailored to your specific needs, all available on demand and with cost-effective long-term contracts. These servers are standalone and fully optimized for your requirements and independent of any cloud platforms or hypervisors. We'll work with you to configure your hardware and add any managed services to ensure a hosting environment perfectly suited to your business. ### HIPAA-Compliant Hosting Ensure the security and integrity of sensitive patient data with Atlantic.Net's HIPAA-compliant hosting solutions. Our web hosting services exceed the stringent administrative, physical, and technical safeguards mandated by HIPAA regulations. Whether you're a healthcare provider, a managed service provider, or a relevant third party, Atlantic.Net's secure infrastructure protects your patient data with the utmost care. Our solutions, available on both dedicated servers and in the cloud, offer the flexibility to meet your specific needs while ensuring full compliance with HIPAA regulations. When you choose Atlantic.Net, we'll sign a Business Associate Agreement to solidify our commitment to safeguarding your data. Trust us to provide a secure and compliant foundation for your healthcare operations. ### PCI-Compliant Hosting Secure your customers' payment data with Atlantic.Net's PCI-compliant hosting solutions. We adhere to the stringent security standards set by the Payment Card Industry Data Security Standard (PCI DSS), safeguarding sensitive cardholder information and ensuring compliance with industry regulations. As a merchant accepting credit cards, trust Atlantic.Net to provide a protected hosting environment for financial data at every stage of the transaction process. From payment processing and data transmission to the secure storage of transaction records, we have the expertise and infrastructure to keep your customers' information safe. Our commitment to PCI compliance ensures that you can focus on your business with peace of mind, knowing that your payment processing is secure and meets the highest industry standards set by the Payment Card Industry Security Standards Council. ### Managed Services With Atlantic.Net's comprehensive managed services, you can maximize your business efficiency and focus on what you do best. We take the burden of managing your IT operations off your shoulders, providing a proactive approach to modernizing your business and ensuring it's future-proof. Our team of experts handles everything from network management and data backup to cybersecurity. Our managed services are tailored to optimize your performance and deliver the critical IT support you need to thrive in today's competitive market. ## New York Data Center FAQ ### Where is the Atlantic.Net New York data center located? Approximately 11 miles from Manhattan, in a Telx / Digital Realty facility, one of the most interconnected colocation centers in the NYC metro area. ### Is the Atlantic.Net New York data center HIPAA compliant? Yes. The New York facility is audited against HIPAA, HITECH, ISO 14001, ISO 27001, ISO 9001, PCI DSS, Privacy Shield, SOC 2, SOC 2 Type 2, and SOC 3, and supports HIPAA-compliant deployments under a Business Associate Agreement (BAA). ### What power capacity does the New York data center provide? 4,000 kW of provisioned power capacity (with up to 11,000 kW of building capacity), backed by 4,950 kW of UPS in N+1 to 2N redundancy and 9,000 kW of generator capacity in N+1 / 2N redundancy. Power density supports up to 175 W/sq. ft. ### What cooling redundancy does the New York facility use? N+1 cooling redundancy, designed to prevent disruptions due to overheating during component maintenance or single-unit failures. ### What is the building size and structural rating of the New York data center? A 7-story, 211,000-square-foot building with floor loading up to 200 lbs/sq. ft. The site sits in Flood Zone X (outside the 500-year floodplain) and Seismic Zone 2A. ### What hosting options are available in New York? Cloud hosting (General Purpose, Storage Optimized, Memory Optimized, and Compute Optimized plans), dedicated servers, HIPAA-compliant hosting, PCI-compliant hosting, and a full suite of managed services. Self-hosted (BYO hardware) colocation is also available. ### Is the New York facility carrier-neutral? Yes. The Telx / Digital Realty facility is fully carrier-neutral, with direct access to hundreds of leading domestic and international network carriers and Internet exchange points. ## Are you ready to start hosting in New York? [Contact the team today](https://www.atlantic.net/about-us/corporate-contact/) to learn more about the services offered and how to get started. ## Ready to spin up a cloud server now? [Create an account on the ACP platform](https://cloud.atlantic.net/?page=userlogin) right now! If you’re interested in hosting in this data center region, contact an advisor at 866.618.3282 or email us [sales@atlantic.net](mailto:sales@atlantic.net). Atlantic.Net provides world-class hosting services and solutions at eight global data center regions in our [New York](https://www.atlantic.net/hipaa-data-centers/new-york-hosting/), [London](https://www.atlantic.net/hipaa-data-centers/london-uk-hosting/), [San Francisco](https://www.atlantic.net/hipaa-data-centers/san-francisco-california-hosting/), [Orlando](https://www.atlantic.net/orlando-colocation-hosting-data-center/), [Ashburn](https://www.atlantic.net/hipaa-data-centers/ashburn-virginia-hosting/), [Toronto](https://www.atlantic.net/hipaa-data-centers/toronto-canada-hosting/), [Singapore](https://www.atlantic.net/hipaa-data-centers/singapore-hosting/), and [Dallas](https://www.atlantic.net/hipaa-data-centers/dallas-texas-hosting/) locations. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Atlantic.Net’s Stability and High-Touch Approach > URL: https://www.atlantic.net/about-us/high-touch-approach/ | Updated: 2026-09-16 ## Atlantic.Net High-Touch Approach We are always here to assist you: we solve complex problems. Our team will meet with you to customise a hosting solution catered specifically to your needs. ## Stability and Cost Advantage Atlantic.Net is an infrastructure hosting solutions provider that has been a rock in the industry since 1994. While other companies have come and gone, we remain a constant clients can count on. Our adherence to a sound and proven business model, combined with the steady adoption of innovative technology, helps us steer your business through this century's technological turbulence. Organisations rely on us for peace of mind while keeping the cost of high-touch service in check. Here are some of the key differentiators: - Managed service provider with a track record of financial stability since 1994. - Substantial investment in technology and performance. - Innovative company with a consistent R&D budget to stay ahead of the curve. - Long-term strategic partner with a roadmap to success. ## Consultative Sales Approach ### We're proactive. We manage your infrastructure so it adapts to changing circumstances. For example, we anticipated additional traffic to an NBA team site after a conference win. There's no rest on weekends. ### We're diligent. By designing a customised consolidation strategy for a major ASP, we substantially reduced their server footprint and helped them save money month after month. ### We're determined. To help a leading healthcare provider comply with HIPAA, PCI, and SSAE 18 SOC 1 / SOC 2 (formerly SSAE 16), we researched the necessary compliance solutions and made them happen. ## Custom-Designed Solutions The high-touch approach doesn't just guide us, it defines us. High Touch means taking pride in our work and giving our customers personal attention, focus, accountability, integrity, flexibility, responsiveness, and innovation. High Touch is the reason thousands of small, medium, and Fortune 500 companies rely on Atlantic.Net cloud hosting solutions to protect their mission-critical infrastructure. ## Ongoing High-Touch Service Our multi-tiered support personnel work with you and monitor your environment to help keep your business protected; complete customer satisfaction is our top priority. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Atlantic.Net: Award-Winning Hosting Provider Since 1994 > URL: https://www.atlantic.net/hosting-services-provider/ | Updated: 2026-09-16 ## Why Choose Atlantic.Net Established in 1994, Atlantic.Net is a trusted cloud services provider. Our reputation is founded upon over thirty years of direction and counsel given to CEOs, managers, engineers, developers, and IT professionals. Our SMB and enterprise clients rely on our support and services to make their businesses grow and prosper. Customer satisfaction is, always has been, and forever will be paramount at Atlantic.Net. You can depend on us. Tomorrow's computing, today! ## Here are some of the reasons why organizations of all sizes choose Atlantic.Net: - 100% Uptime Service Level Agreement - World Class Data Center Infrastructure - Atlantic.Net High Touch Approach - Industry Leading Certifications and Partnerships - Award-Winning Service - A Support Team Backed By Decades Of Experience - Client Testimonials ## High Availability Infrastructure There is no reason to reinvent the hosting solutions wheel when Atlantic.Net provides one that is rolling along flawlessly. We provide the best cloud services, web hosting, and managed services to enable you to focus on your core competencies. Click here to learn more about our World Class Data Center Infrastructure. ## Hosting Services by Atlantic.Net Atlantic.Net provides an array of hosting services, to include cloud, dedicated, colocation, private virtualization, and managed hosting. Our highly available infrastructure can accommodate projects of any scale or size. When you entrust your data into the hands of Atlantic.Net, you will gain a support team backed by decades of experience. We can assist by creating customized solutions that fit your business goals. Our state-of-the-art infrastructure is SSAE 18, HIPAA, and HITECH compliant and housed in secure, climate-controlled facilities with constant monitoring and multiple direct connections to the Internet backbone to ensure the availability and safety of your data. ### Cloud Platform The Atlantic.Net Cloud Platform is backed by an industry-leading 100% Uptime SLA. Designed for unparalleled performance and maximum flexibility, our Cloud Platform guarantees blazing fast speeds for servers and applications. Our highly available on-demand cloud platform allows for instant scale-up and customization affordably. Private, public, hybrid services, Cloud Containers, and VoIP Cloud Servers are also available. [Learn more about our Cloud Platform](https://www.atlantic.net/cloud-platform/) ### GPU Hosting Atlantic.Net GPU Hosting is engineered for AI workloads, with superb performance that enables scientific research, 3D graphics and rendering, medical imaging, climate modeling, and more. Experience unparalleled performance with dedicated cloud servers equipped with the revolutionary NVIDIA accelerated computing platform. [Learn more about our GPU Hosting](https://www.atlantic.net/gpu-server-hosting/) ### Dedicated Server Hosting Offering dizzying speeds of large data transfers while assuring optimum server performance, Dedicated Server Hosting is ideal for complex security, compliance, and privacy requirements. [Learn more about our Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/) ### Colocation Hosting A secure and stable colocation service enables you to place your server infrastructure in our world-class data center environment. This hosting service gives you maximum control of your server infrastructure, as you are only leasing power, space and bandwidth. Our network combines diverse, redundant, scalable, and high-speed connections to the internet backbone to ensure that the system automatically selects the fastest route for your data. [Learn more about our Colocation Hosting](https://www.atlantic.net/orlando-colocation-hosting-data-center/) ### Managed Services Managing the containment, flow, and security of data on a dedicated or cloud environment can be time-consuming. Our Managed Services are designed to save time, effort, and resources by helping organizations focus on their core business. This greatly improves resource utilization, increases productivity, and decreases operational costs. [Learn more about our Managed Services](https://www.atlantic.net/managed-services/) ## Cloud Availability in Multiple Global Regions Deploy close to your users from eight international data centers worldwide, with new regions on the way. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # How to Install Backdrop CMS on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-backdrop-cms-on-arch-linux/ | Published: 2023-03-10 | Updated: 2024-04-19 | Author: Hitesh Jethva Backdrop is a simple, lightweight, and powerful content management system used for building professional websites. It is written in PHP and is a fork of the Drupal project. It offers a simple and user-friendly web UI where users can create web pages easily. If you are looking for a simple and powerful CMS, then Backdrop CMS is the right choice for you. In this post, we will show you how to install Backdrop CMS on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Apache and PHP First, install the Apache web server with the following command: ``` pacman -Sy apache ``` After the successful installation, start and enable the Apache service with the following command: ``` systemctl start httpd systemctl enable httpd ``` Next, install the PHP and other required extensions using the following command: ``` pacman -Sy php php-gd php-cgi php-intl php-apache unzip ``` After the installation, edit the PHP configuration file and enable the required extensions: ``` nano /etc/php/php.ini ``` Add/modify the following lines: ``` extension=pdo_mysql extension=gd extension=json extension=mysqli extension=intl extension=xml ``` Save and close the file when you are finished. ## Step 3 – Install and Configure MariaDB Database First, install the MariaDB server with the following command: ``` pacman -S libmariadbclient mariadb mariadb-clients ``` Next, initialize the MariaDB database with the following command: ``` mysql_install_db --user=mysql --basedir=/usr --datadir=/var/lib/mysql ``` Next, start and enable the MariaDB service with the following command: ``` systemctl start mysqld systemctl enable mysqld ``` Next, connect to the MariaDB console using the following command: ``` mysql ``` Once you are connected, create a database and user for Backdrop: ``` CREATE DATABASE backdrop; GRANT ALL ON backdrop.* TO backdrop@localhost IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 4 – Download Backdrop CMS First, download the latest version of Backdrop CMS from their official download page. ``` curl -s https://api.github.com/repos/backdrop/backdrop/releases/latest|grep browser_download_url|grep backdrop.zip|cut -d '"' -f 4|wget -qi - ``` Once the download is completed, extract it to the Apache web root directory with the following command: ``` unzip backdrop.zip mv backdrop /srv/http/backdrop ``` Next, change the ownership of the Backdrop directory to Apache: ``` chown -R http:http /srv/http/backdrop/ chmod -R 775 /srv/http/backdrop/ ``` ## Step 5 – Configure Apache for Backdrop CMS Next, you will need to create an Apache virtual host configuration file to host Backdrop CMS on the web. ``` nano /etc/httpd/conf/extra/backdrop.conf ``` Add the following configurations: ``` ServerAdmin admin@example.com DocumentRoot /srv/http/backdrop ServerName backdrop.example.com Options FollowSymLinks AllowOverride All Require all granted ErrorLog /var/log/httpd/error.log CustomLog /var/log/httpd/access.log combined ``` Save and close the file, then edit the Apache main configuration file. ``` nano /etc/httpd/conf/httpd.conf ``` Uncomment the following lines: ``` Include conf/extra/httpd-vhosts.conf LoadModule mpm_prefork_module modules/mod_mpm_prefork.so ``` Comment the following line: ``` #LoadModule mpm_event_module modules/mod_mpm_event.so ``` Add the following lines: ``` LoadModule php_module modules/libphp.so AddHandler php-script .php Include conf/extra/php_module.conf Include conf/extra/backdrop.conf ``` Save and close the file. Then, restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 6 – Access Backdrop CMS Now, open your web browser and access the Backdrop CMS web interface using the URL **http://backdrop.example.com.** You should see the language selection screen. ![backdrop cms language selection screen](https://www.atlantic.net/wp-content/uploads/2023/03/p1-2.png) Select your language and click on the **SAVE AND CONTINUE** button. You should see the database configuration screen. ![backdrop cms database configuration screen](https://www.atlantic.net/wp-content/uploads/2023/03/p2-2.png) Define your database user and password and click on the **SAVE AND CONTINUE** button. You should see the site configuration page. ![backdrop cms site configuration](https://www.atlantic.net/wp-content/uploads/2023/03/p5-2.png) Provide your site information, admin username, and password, and click on the **SAVE AND CONTINUE** button. You should see the Backdrop CMS dashboard on the following page. ![backdrop cms dashboard](https://www.atlantic.net/wp-content/uploads/2023/03/p6-2.png) ## Conclusion In this guide, we explained how to install Backdrop CMS with Apache on Arch Linux. You can now use Backdrop CMS in the production environment to create and manage your website via a web browser. You can also try Backdrop CMS on one of our [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Craft CMS on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-craft-cms-on-arch-linux/ | Published: 2023-03-11 | Updated: 2024-04-19 | Author: Hitesh Jethva Craft CMS is an open-source, flexible, and user-friendly content management system for creating custom digital experiences on the web. Craft doesn’t have a website builder, so you will need to write your own HTML code to build a website. It is designed with web developers in mind and helps them to build beautiful websites in a modern fashion. In this post, we will show you how to install Craft CMS with Apache on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Apache and PHP First, you will need to install the Apache web server and PHP on your server. First, install the Apache package using the following command. ``` pacman -Sy apache ``` After installing the Apache web server, start and enable the Apache service with the following command: ``` systemctl start httpd systemctl enable httpd ``` Next, install PHP and other required extensions using the following command: ``` pacman -Sy php php-gd php-cgi php-intl php-apache unzip ``` Next, edit the PHP configuration file and enable the required extensions: ``` nano /etc/php/php.ini ``` Add/modify the following lines: ``` extension=pdo_mysql extension=gd extension=json extension=mysqli extension=intl extension=xml extension=bcmath ``` Save and close the file when you are finished. ## Step 3 – Create a Database for Craft CMS Craft CMS uses a MariaDB as a database backend. Install the MariaDB server with the following command: ``` pacman -S libmariadbclient mariadb mariadb-clients ``` Next, initialize the MariaDB database with the following command: ``` mysql_install_db --user=mysql --basedir=/usr --datadir=/var/lib/mysql ``` Next, start and enable the MariaDB service with the following command: ``` systemctl start mysqld systemctl enable mysqld ``` Next, connect to the MariaDB console using the following command: ``` mysql ``` Once you are connected, create a database and user for Craft CMS: ``` CREATE DATABASE craft; GRANT ALL ON craft.* TO craft@localhost IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 4 – Install Craft CMS First, install the Composer package using the following command. ``` pacman -S composer ``` Next, change the directory to the Apache web root and install Craft CMS using the following command. ``` cd /srv/http composer create-project craftcms/craft ``` Answer all the questions as shown below to install and configure Craft CMS on your server. ``` See https://craftcms.com/knowledge-base/craft-console-root for details on why that’s a bad idea. Proceed anyway? (yes|no) [no]:yes ______ .______ ___ _______ .___________. / || _ \ / \ | ____|| | | ,----'| |_) | / ^ \ | |__ `---| |----` | | | / / /_\ \ | __| | | | `----.| |\ \----./ _____ \ | | | | \______|| _| `._____/__/ \__\ |__| |__| A N E W I N S T A L L ______ .___ ___. _______. / || \/ | / | | ,----'| \ / | | (----` | | | |\/| | \ \ | `----.| | | | .----) | \______||__| |__| |_______/ Craft commands should not be run as the root/super user. See https://craftcms.com/knowledge-base/craft-console-root for details on why that’s a bad idea. Proceed anyway? (yes|no) [no]:yes Craft commands should not be run as the root/super user. See https://craftcms.com/knowledge-base/craft-console-root for details on why that’s a bad idea. Proceed anyway? (yes|no) [no]:yes Generating an application ID ... done (CraftCMS--f4491c3a-22ba-4fd1-ba62-53f69cb52c42) Craft commands should not be run as the root/super user. See https://craftcms.com/knowledge-base/craft-console-root for details on why that’s a bad idea. Proceed anyway? (yes|no) [no]:yes Generating a security key ... done (Ca1TEYLF_a-rixBWMFoeXgK9GledS5qD) Welcome to Craft CMS! Are you ready to begin the setup? (yes|no) [no]:yes Craft commands should not be run as the root/super user. See https://craftcms.com/knowledge-base/craft-console-root for details on why that’s a bad idea. Proceed anyway? (yes|no) [no]:yes Craft commands should not be run as the root/super user. See https://craftcms.com/knowledge-base/craft-console-root for details on why that’s a bad idea. Proceed anyway? (yes|no) [no]:yes Craft commands should not be run as the root/super user. See https://craftcms.com/knowledge-base/craft-console-root for details on why that’s a bad idea. Proceed anyway? (yes|no) [no]:yes Which database driver are you using? (mysql or pgsql) [mysql] Database server name or IP address: [127.0.0.1] Database port: [3306] Database username: [root] craft Database password: Database name: craft Database table prefix: Testing database credentials ... success! Saving database credentials to your .env file ... done Install Craft now? (yes|no) [yes]:yes Craft commands should not be run as the root/super user. See https://craftcms.com/knowledge-base/craft-console-root for details on why that’s a bad idea. Proceed anyway? (yes|no) [no]:yes Craft commands should not be run as the root/super user. See https://craftcms.com/knowledge-base/craft-console-root for details on why that’s a bad idea. Proceed anyway? (yes|no) [no]:yes Username: [admin] Email: hitjethva@gmail.com Password: Confirm: Site name: MY Site Site URL: http://craft.example.com Site language: [en-US] ``` Next, change the ownership of the Craft CMS directory to Apache: ``` chown -R http:http /srv/http/craft/ chmod -R 775 /srv/http/craft/ ``` ## Step 5 – Configure Apache for Craft CMS Next, you will need to create an Apache virtual host configuration file for Craft CMS. ``` nano /etc/httpd/conf/extra/craft.conf ``` Add the following lines: ``` ServerAdmin admin@example.com DocumentRoot "/srv/http/craft/web" ServerName craft.example.com DirectoryIndex index.php Options Indexes FollowSymLinks AllowOverride All Require all granted ErrorLog /var/log/httpd/error.log CustomLog /var/log/httpd/access.log combined ``` Next, edit the Apache main configuration file. ``` nano /etc/httpd/conf/httpd.conf ``` Uncomment the following line: ``` Include conf/extra/httpd-vhosts.conf LoadModule mpm_prefork_module modules/mod_mpm_prefork.so LoadModule rewrite_module modules/mod_rewrite.so ``` Comment the following line: ``` #LoadModule mpm_event_module modules/mod_mpm_event.so ``` Add the following lines: ``` LoadModule php_module modules/libphp.so AddHandler php-script .php Include conf/extra/php_module.conf Include conf/extra/craft.conf ``` Save and close the file. Next, restart the Apache service to apply the changes: ``` systemctl restart httpd ``` ## Step 6 – Access Craft CMS Now, open your web browser and access the Craft CMS admin page using the URL **http://craft.example.com/admin/login.** You should see the Craft CMS login page. ![Craft CMS Login Screen](https://www.atlantic.net/wp-content/uploads/2023/03/p1-3.png) Provide your admin user name and password and click on the **Sign in** button. You should see the Craft CMS dashboard on the following page. ![Craft CMS Dashboard Screen](https://www.atlantic.net/wp-content/uploads/2023/03/p2-3.png) ## Conclusion Congratulations! You have successfully installed Craft CMS on Arch Linux. You have now enough knowledge to host your own website with Craft CMS. You can now try Craft CMS on one of our [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) plans from Atlantic.Net! --- # How to Install phpBB on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-phpbb-on-arch-linux/ | Published: 2023-03-12 | Updated: 2023-11-14 | Author: Hitesh Jethva phpBB is a free, open-source, and flat-forum bulletin board software written in PHP scripting language. It is also known as a “PHP Bulletin Board” and is used to create a discussion forum where people can post topics and other people can reply to those topics. Compared to other forum software, phpBB is a popular and widely used open-source forum script found all over the web. In this post, we will explain how to install the phpBB forum on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Nginx Web Server phpBB requires a web server to be installed on your server. If not installed, you can install Nginx with the following command. ``` pacman -S nginx-mainline ``` Next, start and enable the Nginx service with the following command. ``` systemctl start nginx systemctl enable nginx ``` ## Step 3 – Install and Configure PHP First, install the PHP, PHP-FPM, and other PHP extensions using the following command. ``` pacman -S php php-fpm php-gd unzip ``` After the successful installation, edit the PHP configuration file and change the necessary settings. ``` nano /etc/php/php.ini ``` Add/modify the following lines: ``` memory_limit = 512M post_max_size =32M upload_max_filesize = 32M date.timezone = Asia/Kolkata extension=gd extension=json extension=xml extension=ldap extension=mysqli extension=imagemagick extension=curl extension=intl ``` Save and close the file, then start the PHP-FPM service and enable it to start at system reboot. ``` systemctl start php-fpm systemctl enable php-fpm ``` ## Step 4 – Create a Database for phpBB phpBB uses MariaDB as a database backend, so you will need to install MariaDB on your server. ``` pacman -S mariadb ``` After installing the MariaDB server, initialize the MariaDB database with the following command. ``` mysql_install_db --user=mysql --basedir=/usr --datadir=/var/lib/mysql ``` Next, start the MariaDB service and enable it to start at system reboot. ``` systemctl start mysqld systemctl enable mysqld ``` Next, log into the MariaDB shell with the following command. ``` mysql ``` Next, create a database and user for phpBB using the following command. ``` CREATE DATABASE phpbb; GRANT ALL ON phpbb.* TO phpbb@localhost IDENTIFIED BY 'securepassword'; Next, flush the privileges and exit from the MariaDB shell with the following command. ``` ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 5 – Download phpBB First, download the latest version of phpBB from their official download page. ``` wget https://download.phpbb.com/pub/release/3.3/3.3.10/phpBB-3.3.10.zip ``` Once the download is completed, unzip the downloaded file with the following command. ``` unzip phpBB-3.3.10.zip ``` Next, create a directory for phpBB and move the phpBB to this directory. ``` mkdir -p /var/www/html/ mv phpBB3 /var/www/html/phpbb ``` Next, change the ownership of the phpBB directory. ``` chown -R http:http /var/www/html/phpbb/ ``` ## Step 6 – Create an Nginx Virtual Host for phpBB Next, you will need to create an Nginx virtual host configuration file to host phpBB on Nginx. First, create a directory to store Nginx virtual host. ``` mkdir /etc/nginx/sites-enabled ``` Next, create an Nginx configuration file for phpBB. ``` nano /etc/nginx/sites-enabled/phpbb.conf ``` Add the following configurations. ``` server { listen 80; server_name phpbb.example.com; root /var/www/html/phpbb; index index.php index.html index.htm; error_log /var/log/nginx/example.com.error.log warn; access_log /var/log/nginx/example.com.access.log; location / { try_files $uri $uri/ @rewriteapp; # Pass the php scripts to FastCGI server specified in upstream declaration. location ~ \.php(/|$) { include fastcgi.conf; fastcgi_split_path_info ^(.+\.php)(/.*)$; fastcgi_param PATH_INFO $fastcgi_path_info; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; fastcgi_param DOCUMENT_ROOT $realpath_root; try_files $uri $uri/ /app.php$is_args$args; fastcgi_pass unix:/var/run/php-fpm/php-fpm.sock; } # Deny access to internal phpbb files. location ~ /(config\.php|common\.php|cache|files|images/avatars/upload|includes|(? URL: https://www.atlantic.net/compliance-hosting/ | Updated: 2026-09-16 Build healthcare, payment, SaaS, and other regulated workloads on independently audited infrastructure supporting HIPAA / HITECH, PCI DSS 4.0, SOC 2 Type II, SOC 3 Type II, GDPR, and NIST 800-53-aligned controls. - Independently Audited - BAA Available - PCI AoC on Request - 24x7x365 Support & Monitoring Frameworks Supported: 6 Years in IT: 30+ ## Compliance Hosting Solutions Atlantic.Net's compliance hosting solutions are a strong fit for financial services, healthcare organizations, marketing agencies, and other verticals that require the highest levels of performance and security for their data. Our infrastructure is certified and audited by independent third-party auditors against HIPAA, HITECH, PCI DSS, GDPR, and SOC requirements. We deliver first-rate physical and environmental controls, technical safeguards, and continuous oversight, and we own and operate SOC 2 Type II, SOC 3 Type II, and HIPAA AT-C 105 / 205 audited and certified data center infrastructure. ## Compliance Hosting in the USA, Europe, and Beyond Whether you are looking to strengthen the compliance-covered part of your organization with our award-winning hosting services, or your European or Asian organization is looking to migrate workloads to American territory, Atlantic.Net can help. ## Compliance Hosting Simplified with a Full Suite of Services Whatever your compliance hosting setup requires, Atlantic.Net stands ready with Dedicated Server Hosting, Cloud Server Hosting, GPU Hosting, Bare Metal Hosting, and a full suite of Managed Services. ## Looking for HIPAA Compliant Hosting? We can help with a free assessment. - IT architecture design, security & guidance. - Flexible private, public & hybrid hosting. - 24x7x365 security, support & monitoring. ## What Is Compliance Hosting? Compliance hosting is a managed hosting service that adheres to specific industry regulations and standards to ensure the security and privacy of sensitive data. Compliance is essential for businesses handling confidential information - particularly in healthcare, finance, and e-commerce. Compliance hosting is designed to protect organizations from data breaches, legal repercussions, and reputational damage by implementing industry-standard security measures and adhering to the safeguards laid out in the relevant legislation. In particular, compliance hosting helps ensure adherence to HIPAA, PCI DSS, GDPR, SOC 2, and similar frameworks - safeguarding both your business and your clients. Failure to adequately protect confidential business data can be catastrophic. Compliance hosting mitigates that risk through firewalls, encryption, access controls, intrusion detection and prevention, and continuous monitoring - providing a secure environment so you can focus on the business without the constant worry of non-compliance. ### HIPAA Compliance and Certifications Atlantic.Net has been independently audited and was found to be in full compliance with HIPAA - meeting the standards for physical and environmental controls, technical safeguards, and management oversight of the environment. ### We Sign Business Associate Agreements As your hosting provider, Atlantic.Net will sign a Business Associate Agreement (BAA), which is required by service providers managing and handling HIPAA-protected information. The BAA details our contractual obligations to safeguard protected health information. Contact our Sales Department to obtain a copy. ### HITECH Audited Atlantic.Net is certified and audited by a third-party independent auditing firm to be in compliance with HITECH. ### PCI Compliance If you are looking for an e-commerce PCI compliance hosting solution, we can help with our award-winning hosting service. We have been in business since 1994, understand the compliance requirements, and let you focus on your core business. ### SOC 2 and SOC 3 Certified Atlantic.Net hosting solutions feature heightened security with fully managed firewalls, VPNs with encryption, and intrusion detection and prevention systems - backed by infrastructure that has received SOC 2 Type II and SOC 3 Type II reports. The audit follows AICPA guidelines including the Trust Service Principles, with tests of operating effectiveness and controls relevant to security and availability principles. ### HIPAA Audited Atlantic.Net establishes a secure environment that provides medical organizations and patients online protection through HIPAA-Compliant Hosting solutions. These solutions help secure personal information in an environment built to safeguard ePHI (electronic protected health information). Note that HIPAA hosting alone does not make you HIPAA-compliant - compliance is determined by adherence to the privacy and security rules outlined by HIPAA. HIPAA hosting addresses one important aspect; you remain responsible for the administrative and technical specifications of the HIPAA Security Rule. ### Pharma & BioTech Solutions Partnering with a highly regulated managed hosting provider can help life sciences companies drive innovation, boost global collaboration, and deliver enhanced security and compliance. With a significant number of heavily regulated healthcare clients, Atlantic.Net provides a secure, reliable, and affordable HIPAA cloud hosting environment - well suited for life sciences organizations working with healthcare big data. ### Managed HIPAA Security Fully managed and compliant security keeps watch over your environment so you can stay focused on your core competencies. ### Digital Advertising Digital ad platforms manage billions of ad-impression purchases every month across display and mobile channels. That kind of operation requires secure networks backed by solid infrastructure. The Atlantic.Net platform's robust processing capability and uncompromised security nurture your investment while delivering a superior customer experience. ### General Data Protection Regulation (GDPR) Compliance The General Data Protection Regulation (EU) 2016/679 ("GDPR"), in force since May 25, 2018, is a regulation on data protection and privacy for all individuals within the European Union. The regulation governs how businesses collect and use personal data. Businesses are required to process personal data according to the regulation, allow individuals to exercise rights in respect of their personal data (access, deletion, etc.), and ensure adequate security protections are in place. Atlantic.Net provides secure, GDPR-ready services across all of its product ranges. ## Compliance Frameworks Atlantic.Net Supports The table below summarizes the major compliance frameworks Atlantic.Net's hosting infrastructure aligns with, the typical industries each one covers, and the documents available for your audit team. | Framework | Industry | Atlantic.Net Coverage | Customer Document | | --- | --- | --- | --- | | HIPAA / HITECH | Healthcare, telehealth, life sciences | Independently audited HIPAA AT-C 105 / 205 environment with security & privacy controls | Business Associate Agreement (BAA) | | PCI DSS 4.0 | E-commerce, payment processors | PCI DSS 4.0-aligned hosting environment | PCI Attestation of Compliance (AoC) on request | | SOC 2 Type II | SaaS, regulated industries, security-conscious enterprises | Audited and certified annually by independent assessor | SOC 2 Type II report available under NDA | | SOC 3 Type II | Public summary of SOC 2 controls | Audited and certified annually | SOC 3 Type II report (public) | | GDPR | Organizations processing EU resident data | GDPR-ready services across product ranges | Data Processing Agreement (DPA) on request | | NIST 800-53 | Federal contractors, regulated industries | Aligned controls across the audited environment | Control mapping available on request | ## Why Choose Atlantic.Net for Compliance Hosting? Atlantic.Net has been in the IT industry for over 32 years. We understand the critical importance of data security and compliance, and our hosting solutions are designed to meet the stringent requirements of HIPAA, HITECH, PCI DSS, GDPR, and SOC. We go beyond the basics, providing comprehensive features such as Business Associate Agreements, intrusion detection, firewalls, vulnerability scans, and encryption to protect your sensitive data. Our data centers carry numerous certifications, including NIST alignment, SOC 2 Type II, SOC 3 Type II, HIPAA AT-C 105 / 205, HITECH, and PCI DSS - further demonstrating our commitment to excellence and security. When you choose Atlantic.Net, you can trust that your data is in safe hands. ## HIPAA Hosting Features ### Business Associate Agreement ### Intrusion Prevention Service ### Fully Managed Firewall ### Vulnerability Scans ### File Integrity Monitoring ### Anti-Malware Protection ### SSL Certificate ### Log Management System ### Multi-Factor Authentication ### Trend Micro Deep Security ### Encrypted Backup ### Encrypted VPN ### Encrypted Storage ### Network Edge/DDoS Protection ## Start Your HIPAA Project With a Fully Audited HIPAA Platform Today HIPAA-compliant compute & storage, encrypted VPN, security firewall, BAA, off-site backup, disaster recovery, and more. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Get Help with HIPAA Compliance Atlantic.Net is ready to help you reach compliance quickly across SOC 2 / SOC 3, HIPAA, HITECH, PCI DSS, and GDPR - all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, call 866-618-3282 or email us at sales@atlantic.net. ## Frequently Asked Questions About Compliance Hosting ### What is compliance hosting? Compliance hosting is managed hosting that adheres to specific industry regulations and standards - HIPAA, HITECH, PCI DSS, GDPR, SOC 2, and similar frameworks - to ensure the security and privacy of sensitive data. The hosting provider documents and implements controls (physical, environmental, technical, administrative) that customers can cite in their own audits, reducing the time and cost of achieving compliance. ### Which compliance frameworks does Atlantic.Net support? HIPAA / HITECH (with BAA), PCI DSS 4.0, SOC 2 Type II, SOC 3 Type II, GDPR (with DPA), and NIST 800-53-aligned controls. The infrastructure is independently audited and certified annually. The on-page comparison table maps each framework to industry coverage, what Atlantic.Net provides, and the customer-facing document available. ### What is HIPAA / HITECH compliance hosting? HIPAA / HITECH compliance hosting is a hosting environment whose infrastructure, controls, and operating practices are designed to safeguard electronic protected health information (ePHI). Atlantic.Net's hosting infrastructure is independently audited under HIPAA AT-C 105 / 205 and a HIPAA Business Associate Agreement (BAA) is available for customers handling ePHI. ### What is PCI DSS compliance hosting? PCI DSS compliance hosting is a hosting environment that meets the security requirements of the Payment Card Industry Data Security Standard (PCI DSS 4.0 in the current revision). The standard governs how organizations handle credit-card data. Atlantic.Net offers PCI DSS-aligned hosting and provides a PCI Attestation of Compliance (AoC) on request. ### What is SOC 2 / SOC 3, and what's the difference? SOC 2 and SOC 3 are AICPA reports on a service organization's controls over security, availability, processing integrity, confidentiality, and privacy. SOC 2 is detailed and shared under NDA with customers and their auditors; SOC 3 is a public-facing summary. Atlantic.Net is audited annually for both SOC 2 Type II and SOC 3 Type II. ### What is GDPR compliance hosting? GDPR compliance hosting is a hosting environment that supports the requirements of the EU General Data Protection Regulation (Regulation (EU) 2016/679). It includes data-processing safeguards, audit-friendly controls, and the ability to support data-subject rights such as access and deletion. Atlantic.Net provides a Data Processing Agreement (DPA) and GDPR-ready infrastructure across product lines. ### Will Atlantic.Net sign a Business Associate Agreement (BAA)? Yes. Atlantic.Net signs a HIPAA Business Associate Agreement with customers handling protected health information (ePHI). The BAA details Atlantic.Net's contractual obligations to safeguard PHI as required under HIPAA. Contact the Atlantic.Net Sales Department to obtain a copy. ### Is hosting alone enough to be HIPAA-compliant? No. HIPAA compliance is determined by the covered entity's overall adherence to the HIPAA Privacy and Security Rules - including administrative, physical, and technical safeguards in your application and operations, not just the hosting layer. HIPAA-compliant hosting covers one important aspect (the infrastructure your application runs on) and gives you a documented, audited foundation, but the customer still owns the rest of the compliance perimeter. ### Which Atlantic.Net hosting products are compliance-aligned? Compliance alignment runs across the product line: Cloud Hosting on the Atlantic.Net Cloud Platform, Dedicated Server Hosting, Bare Metal Hosting, GPU Cloud Hosting, Managed Private Cloud, and HIPAA-Compliant WordPress Hosting are all delivered from the same audited infrastructure. Add-on managed services (firewall, IPS, MFA, Trend Micro Deep Security, Veeam backup) are part of the same compliance scope. ### How is compliance hosting priced? Pricing depends on the underlying hosting product (cloud, dedicated, bare metal, GPU) and the bundled managed services. Compliance attestations such as the BAA and PCI AoC are not separate line-item charges. Contact the Atlantic.Net sales team for a quote tailored to your environment and compliance scope. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # How to Install DokuWiki on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-dokuwiki-on-arch-linux/ | Published: 2023-03-13 | Updated: 2023-11-14 | Author: Hitesh Jethva DokuWiki is a free and open-source Wiki software tool written in PHP language. It does not require any database to store its content. It is highly versatile and has a clean and readable syntax. It allows users to create, edit and delete web pages via a web-based dashboard. DokuWiki has built-in authentication extensions that allow users to store user IDs and passwords using various methods. In this post, we will show you how to install DokuWiki on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Nginx First, you will need to install the Nginx web server on your system. You can install it with the following command. ``` pacman -S nginx-mainline ``` Next, start and enable the Nginx service with the following command. ``` systemctl start nginx systemctl enable nginx ``` ## Step 3 – Install and Configure PHP First, install the PHP and other PHP extensions using the following command. ``` pacman -S php php-fpm php-gd ``` After successful installation, edit the PHP configuration file. ``` nano /etc/php/php.ini ``` Add/modify the following lines: ``` extension=gd extension=json extension=xml extension=ldap extension=mysqli ``` Save and close the file, then start the PHP-FPM service and enable it to start at system reboot. ``` systemctl start php-fpm systemctl enable php-fpm ``` ## Step 4 – Install DokuWiki First, download the latest version of DokuWiki from their official download page. ``` wget https://download.dokuwiki.org/src/dokuwiki/dokuwiki-stable.tgz ``` Once the download is completed, create a directory for DokuWiki and extract the downloaded file. ``` mkdir -p /var/www/html/dokuwiki tar xzf dokuwiki-stable.tgz -C /var/www/html/dokuwiki/ --strip-components=1 ``` Next, change the ownership of the DokuWiki directory. ``` chown -R http:http /var/www/html/dokuwiki/ ``` ## Step 5 – Configure Nginx for DokuWiki First, create a directory to store Nginx virtual host. ``` mkdir /etc/nginx/sites-enabled ``` Next, create an Nginx configuration file for DokuWiki. ``` nano /etc/nginx/sites-enabled/dokuwiki.conf ``` Add the following configurations. ``` server { server_name dokuwiki.example.com; root /var/www/html/dokuwiki; location / { index doku.php; try_files $uri $uri/ @dokuwiki; } location ~ ^/lib.*\.(gif|png|ico|jpg)$ { expires 30d; } location ^~ /conf/ { return 403; } location ^~ /data/ { return 403; } location @dokuwiki { rewrite ^/_media/(.*) /lib/exe/fetch.php?media=$1 last; rewrite ^/_detail/(.*) /lib/exe/detail.php?media=$1 last; rewrite ^/_export/([^/]+)/(.*) /doku.php?do=export_$1&id=$2 last; rewrite ^/(.*) /doku.php?id=$1 last; } location ~ \.php$ { fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_pass unix:/var/run/php-fpm/php-fpm.sock; fastcgi_index index.php; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_intercept_errors off; fastcgi_buffer_size 16k; fastcgi_buffers 4 16k; } } ``` Save the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following lines after http{: ``` server_names_hash_bucket_size 64; include sites-enabled/*; ``` Save the file, then verify the Nginx configuration. ``` nginx -t ``` You will get the following output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 6 – Access DokuWiki Now, open your web browser and access the DokuWiki using the URL **https://dokuwiki.example.com/install.php.** You should see the following screen. ![Dokuwiki installation page](https://www.atlantic.net/wp-content/uploads/2023/03/p1-7.png) Provide all necessary information and click on the **Save** button to save the information. You should see the DokuWiki dashboard on the following screen. ![Dokuwiki dashboard](https://www.atlantic.net/wp-content/uploads/2023/03/p3-4.png) You will also need to remove the install.php file from your server. ``` rm -f /var/www/html/dokuwiki/install.php ``` ## Conclusion Congratulations! You have successfully installed DokuWiki with Nginx on Arch Linux. You can now deploy your own Wiki website using DokuWiki. You can now install DokuWiki on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install MediaWiki on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-mediawiki-on-arch-linux/ | Published: 2023-03-14 | Updated: 2023-11-15 | Author: Hitesh Jethva MediaWiki is a free and open-source wiki software tool used to build Wikipedia-like websites. It is written in PHP and allows for data to be written to a read-write database and read from read-only databases. It is used by students, teachers, and businesses to create materials, resources, and instructional presentations. It comes with a user-friendly web interface that helps you to add and edit wiki content, creating a group-moderated website. In this post, we will show you how to install MediaWiki on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Nginx By default, the Nginx package is included in the Arch Linux default repository. You can install it with the following command. ``` pacman -S nginx-mainline ``` After installing the Nginx, start and enable the Nginx service using the following command. ``` systemctl start nginx systemctl enable nginx ``` ## Step 3 – Install and Configure PHP MediaWiki is a PHP-based application, so you will also need to install PHP and other extensions to your server. You can install all of them using the following command. ``` pacman -S php php-fpm php-gd unzip ``` Next, edit the PHP configuration file and enable all the required PHP extensions. ``` nano /etc/php/php.ini ``` Add / Modify the following lines: ``` memory_limit = 512M post_max_size =32M upload_max_filesize = 32M date.timezone = Asia/Kolkata extension=gd extension=json extension=xml extension=ldap extension=mysqli extension=imagemagick extension=curl extension=intl extension=iconv ``` Save and close the file, then start the PHP-FPM service and enable it to start at system reboot. ``` systemctl start php-fpm systemctl enable php-fpm ``` ## Step 4 – Install and Configure MariaDB Database First, install MariaDB with the following command. ``` pacman -S mariadb ``` Once the MariaDB server is installed, initialize the MariaDB database with the following command. ``` mysql_install_db --user=mysql --basedir=/usr --datadir=/var/lib/mysql ``` Next, start and enable the MariaDB service using the following command. ``` systemctl start mysqld systemctl enable mysqld ``` Next, connect to the MariaDB shell: ``` mysql ``` Next, create a database and user using the following command. ``` CREATE DATABASE mediawiki; GRANT ALL ON mediawiki.* TO mediawiki@localhost IDENTIFIED BY 'securepassword'; Next, flush the privileges and exit from the MariaDB shell with the following command. ``` ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 5 – Download Mediawiki First, download the latest version of MediaWiki from their official download page using the following command. ``` wget https://releases.wikimedia.org/mediawiki/1.39/mediawiki-1.39.2.zip ``` Once the download is finished, extract the downloaded file with the following command. ``` unzip mediawiki-1.39.2.zip ``` Next, create an Nginx web root directory and move Mediawiki inside the Nginx web root. ``` mkdir -p /var/www/html/ mv mediawiki-1.39.2 /var/www/html/mediawiki ``` Next, change the ownership of the Mediawiki directory. ``` chown -R http:http /var/www/html/mediawiki/ ``` ## Step 6 – Configure Nginx for Mediawiki Next, you will need to create an Nginx virtual host configuration file to serve Mediawiki. First, create a directory to store Nginx virtual host. ``` mkdir /etc/nginx/sites-enabled ``` Next, create an Nginx configuration file for MediaWiki. ``` nano /etc/nginx/sites-enabled/mediawiki.conf ``` Add the following configurations. ``` server { listen 80; server_name mediawiki.example.com; root /var/www/html/mediawiki; index index.php; error_log /var/log/nginx/mediawiki.error; access_log /var/log/nginx/mediawiki.access; location / { try_files $uri $uri/ /index.php; } location ~ /\.ht { deny all; } location ~ \.php$ { fastcgi_pass unix:/var/run/php-fpm/php-fpm.sock; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } } ``` Save the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following lines after http{: ``` server_names_hash_bucket_size 64; include sites-enabled/*; ``` Save the file when you are done. Then, verify the Nginx configuration. ``` nginx -t ``` You will see the following output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Next, restart the Nginx service to implement the changes. ``` systemctl restart nginx ``` ## Step 7 – Perform Mediawiki Web Installation Now, open your web browser and access Mediawiki using the URL **http://mediawiki.example.com/.** You should see the following screen. ![MediaWIki welcome screen](https://www.atlantic.net/wp-content/uploads/2023/03/p1-5.png) Click on the **Set up the wiki**. You should see the language selection screen. ![MediaWIki language selction screen](https://www.atlantic.net/wp-content/uploads/2023/03/p2-5.png) Select your language and click on the **Continue** button. You should see the terms of service page. ![MediaWIki term of service screen](https://www.atlantic.net/wp-content/uploads/2023/03/p3-3.png) Read the term of service and click on the **Continue** button. You should see the database settings page. ![MediaWIki database screen](https://www.atlantic.net/wp-content/uploads/2023/03/p4-2.png) Define your database settings and click on the **Continue** button. You should see the following page. ![MediaWIki database confirmationscreen](https://www.atlantic.net/wp-content/uploads/2023/03/p6-4.png) Click on the **Continue** button. You should see the Mediawiki site configuration page: ![MediaWIki site configuration screen](https://www.atlantic.net/wp-content/uploads/2023/03/p7-3.png) Define your site name, admin username, and password, and click on the **Continue** button. You should see the following page: ![MediaWIki site installation screen](https://www.atlantic.net/wp-content/uploads/2023/03/p8-2.png) Click on the **Continue** button. Once the installation has been finished, you should see the following page. ![Mediawiki installation done](https://www.atlantic.net/wp-content/uploads/2023/03/p9-2.png) Click on the **enter your wiki**. You should see your Mediawiki dashboard on the following screen. ![mediawiki dashboard](https://www.atlantic.net/wp-content/uploads/2023/03/p10-2.png) ## Conclusion Congratulations! You have successfully installed Mediawiki with Nginx on Arch Linux. You can now start deploying your own Wiki website using MediaWiki. You can also try Mediawiki on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Tutorials and How-To Articles from Atlantic.Net > URL: https://www.atlantic.net/tutorials/ | Updated: 2026-09-16 Step-by-step guides and how-tos for Linux, cloud, GPU, security and compliant hosting. **Filters** Type[All](https://www.atlantic.net/tutorials/)[Tutorials](https://www.atlantic.net/tutorials/?type=tutorial)[How-Tos](https://www.atlantic.net/tutorials/?type=how-to) Product[All](https://www.atlantic.net/tutorials/)[VPS Hosting](https://www.atlantic.net/tutorials/?product=vps-hosting)[Dedicated Server Hosting](https://www.atlantic.net/tutorials/?product=dedicated-server-hosting)[HIPAA Compliant Hosting](https://www.atlantic.net/tutorials/?product=hipaa-compliant-hosting)[GPU Server Hosting](https://www.atlantic.net/tutorials/?product=gpu-server-hosting)[PCI Hosting](https://www.atlantic.net/tutorials/?product=pci-compliant-hosting)[Cloud Platform](https://www.atlantic.net/tutorials/?product=cloud-platform) Topic[All](https://www.atlantic.net/tutorials/)[Web Servers](https://www.atlantic.net/tutorials/?topic=web-servers)[Programming](https://www.atlantic.net/tutorials/?topic=programming)[Databases](https://www.atlantic.net/tutorials/?topic=databases)[CMS & Websites](https://www.atlantic.net/tutorials/?topic=cms-websites)[GPU Computing](https://www.atlantic.net/tutorials/?topic=gpu-computing)[AI & Machine Learning](https://www.atlantic.net/tutorials/?topic=ai-machine-learning)[Security](https://www.atlantic.net/tutorials/?topic=security)[DevOps & CI/CD](https://www.atlantic.net/tutorials/?topic=devops-cicd)[Linux Commands](https://www.atlantic.net/tutorials/?topic=linux-commands)[Monitoring & Observability](https://www.atlantic.net/tutorials/?topic=monitoring-observability) Tech[All](https://www.atlantic.net/tutorials/)[Nginx](https://www.atlantic.net/tutorials/?tech=nginx)[PHP](https://www.atlantic.net/tutorials/?tech=php)[MySQL](https://www.atlantic.net/tutorials/?tech=mysql)[Docker](https://www.atlantic.net/tutorials/?tech=docker)[LAMP Stack](https://www.atlantic.net/tutorials/?tech=lamp-stack)[WordPress](https://www.atlantic.net/tutorials/?tech=wordpress)[LEMP Stack](https://www.atlantic.net/tutorials/?tech=lemp-stack)[Python](https://www.atlantic.net/tutorials/?tech=python)[PostgreSQL](https://www.atlantic.net/tutorials/?tech=postgresql)[cPanel](https://www.atlantic.net/tutorials/?tech=cpanel) OS[All](https://www.atlantic.net/tutorials/)[Ubuntu](https://www.atlantic.net/tutorials/?os=ubuntu)[Fedora](https://www.atlantic.net/tutorials/?os=fedora)[CentOS](https://www.atlantic.net/tutorials/?os=centos)[Oracle Linux](https://www.atlantic.net/tutorials/?os=oracle-linux)[Arch Linux](https://www.atlantic.net/tutorials/?os=arch-linux)[Rocky Linux](https://www.atlantic.net/tutorials/?os=rocky-linux)[Debian](https://www.atlantic.net/tutorials/?os=debian)[Windows](https://www.atlantic.net/tutorials/?os=windows)[Windows Server](https://www.atlantic.net/tutorials/?os=windows-server) 1216 tutorials Tutorial Cloud Platform ### [How to Secure a Self-Hosted OpenClaw Deployment](https://www.atlantic.net/cloud-platform/how-to-secure-a-self-hosted-openclaw-deployment/) Jul 31, 2026 Tutorial Cloud Platform ### [How to Connect OpenClaw & Hermes to OpenAI, Anthropic, or OpenRouter](https://www.atlantic.net/cloud-platform/how-to-connect-openclaw-hermes-to-openai-anthropic-or-openrouter/) Jul 31, 2026 Tutorial Cloud Platform ### [How To Set Up Hermes Agent On An Atlantic.Net Cloud Server](https://www.atlantic.net/cloud-platform/how-to-set-up-hermes-agent-on-an-atlantic-net-cloud-server/) Jul 30, 2026 Tutorial Cloud Platform ### [How to Install OpenClaw on an Atlantic.Net Cloud Server](https://www.atlantic.net/cloud-platform/how-to-install-openclaw-on-an-atlantic-net-cloud-server/) Jul 29, 2026 Tutorial VPS Hosting ### [How to Install and Use the Ping Command in Linux (Debian & Ubuntu)](https://www.atlantic.net/vps-hosting/how-to-install-and-use-the-ping-command-in-linux/) Debian · Ubuntu Jun 18, 2026 Tutorial VPS Hosting ### [How to Find the Top Memory Consuming Processes in Linux](https://www.atlantic.net/vps-hosting/find-top-10-running-processes-by-memory-and-cpu-usage/) Jun 18, 2026 How-To VPS Hosting ### [How to Install Asterisk and FreePBX on Ubuntu](https://www.atlantic.net/vps-hosting/how-to-install-asterisk-and-freepbx-on-ubuntu/) Ubuntu Jun 18, 2026 Tutorial Dedicated Server Hosting ### [How to Use AUR with Arch Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-use-aur-with-arch-linux/) Arch Linux Jun 17, 2026 Tutorial Dedicated Server Hosting ### [How to Set and Change Hostname in Rocky Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-set-and-change-hostname-in-rocky-linux/) Rocky Linux Jun 17, 2026 How-To Managed Services ### [How to Improve CDN Performance in 2026: Metrics, Monitoring, and Strategies](https://www.atlantic.net/managed-services/improve-cdn-performance/) May 14, 2026 How-To Dedicated Server Hosting ### [How to Choose a Bare Metal Hosting Provider for Enterprise Workloads in 2026](https://www.atlantic.net/dedicated-server-hosting/choose-bare-metal-hosting-provider/) May 3, 2026 How-To Cloud Platform ### [How to Reduce Cloud Hosting Infrastructure Costs in 2026: 7 Architectural Tips Every CTO Should Know](https://www.atlantic.net/cloud-platform/reduce-cloud-hosting-costs/) May 1, 2026 How-To HIPAA Compliant Hosting ### [How to Become HIPAA Compliant: A Practical 10-Step Checklist](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-10-step-checklist/) Apr 24, 2026 How-To HIPAA Compliant Hosting ### [How to Make a HIPAA-Compliant Website: 2026 Guide](https://www.atlantic.net/hipaa-compliant-hosting/how-to-make-website-hipaa-compliant/) Apr 14, 2026 How-To Cloud Platform ### [How to Verify Cloud Server Disk Performance Before You Buy](https://www.atlantic.net/cloud-platform/verify-cloud-server-disk-performance-before-you-buy/) Apr 3, 2026 How-To GPU Server Hosting ### [How to Choose a Bare Metal Hosting Provider for Your AI Project in 2026](https://www.atlantic.net/gpu-server-hosting/how-to-choose-a-bare-metal-hosting-provider-for-your-ai-project-in-2025/) Feb 15, 2026 How-To VPS Hosting ### [How to Find the Top Cloud Hosting Providers in 2026](https://www.atlantic.net/vps-hosting/how-to-find-the-top-cloud-hosting-providers/) Feb 15, 2026 How-To Dedicated Server Hosting ### [How to Choose a Dedicated Server for High Traffic Websites](https://www.atlantic.net/dedicated-server-hosting/choose-dedicated-server-high-traffic-websites/) Jan 27, 2026 How-To HIPAA Compliant Hosting ### [How to Store and Secure 25TB+ of Patient Data in the Cloud](https://www.atlantic.net/hipaa-compliant-hosting/how-to-store-and-secure-25tb-of-patient-data-in-the-cloud/) Nov 30, 2025 How-To HIPAA Compliant Hosting ### [How to Choose the Top HIPAA-Compliant Hosting Services for Secure and Compliant Data Management](https://www.atlantic.net/hipaa-compliant-hosting/how-to-choose-the-top-hipaa-compliant-hosting-services-for-secure-and-compliant-data-management/) Nov 6, 2025 Tutorial GPU Server Hosting ### [How to Train DeepSeek with Custom Knowledge Base Using LoRA on Ubuntu 24.04 GPU](https://www.atlantic.net/gpu-server-hosting/how-to-train-deepseek-with-custom-knowledge-base-using-lora-on-ubuntu-24-04-gpu/) Ubuntu Oct 14, 2025 Tutorial GPU Server Hosting ### [How to Build a Multi-User Web Interface for DeepSeek with Streamlit on Ubuntu 24.04 GPU Server](https://www.atlantic.net/gpu-server-hosting/how-to-build-a-multi-user-web-interface-for-deepseek-with-streamlit-on-ubuntu-24-04-gpu-server/) Ubuntu Oct 13, 2025 Tutorial GPU Server Hosting ### [How to Run Jupyter Notebooks in the Browser with JupyterLite on Ubuntu 24.04 GPU server](https://www.atlantic.net/gpu-server-hosting/how-to-run-jupyter-notebooks-in-the-browser-with-jupyterlite-on-ubuntu-24-04-gpu-server/) Ubuntu Oct 12, 2025 Tutorial GPU Server Hosting ### [How to Use DeepSeek R1 for Code Generation and Debugging on Ubuntu 24.04 GPU Server](https://www.atlantic.net/gpu-server-hosting/how-to-use-deepseek-r1-for-code-generation-and-debugging-on-ubuntu-24-04-gpu-server/) Ubuntu Oct 11, 2025 --- # How to Install Angular on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-angular-on-arch-linux/ | Published: 2023-03-15 | Updated: 2023-11-15 | Author: Hitesh Jethva Angular is a component-based framework used for building single-page client applications using HTML and TypeScript. Supported by Google, it is the perfect framework for building large-scale, powerful, and easy-to-serve web apps. It is cross-platform and offers a wide range of features and benefits, including reduced development time, unit test friendliness, and more. In this post, we will show you how to install Angular on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Node JS and NPM First, download and run the following script to install NVM on your system. ``` curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.2/install.sh | bash ``` You will get the following output. ``` export NVM_DIR="$HOME/.nvm" [ -s "$NVM_DIR/nvm.sh" ] && \. "$NVM_DIR/nvm.sh" # This loads nvm => Close and reopen your terminal to start using nvm or run the following to use it now: ``` Next, activate the NVM environment variable using the following command. ``` export NVM_DIR="$HOME/.nvm" [ -s "$NVM_DIR/nvm.sh" ] && \. "$NVM_DIR/nvm.sh" # This loads nvm ``` Next, check the NVM version with the following command. ``` nvm --version ``` Output. ``` 0.39.2 ``` Next, install the latest version of Node JS using the following command. ``` nvm install --lts ``` You will get the following output. ``` Installing latest LTS version. Downloading and installing node v18.14.2... Downloading https://nodejs.org/dist/v18.14.2/node-v18.14.2-linux-x64.tar.xz... ####################################################################################################################################### 100.0% Computing checksum with sha256sum Checksums matched! Now using node v18.14.2 (npm v9.5.0) Creating default alias: default -> lts/* (-> v18.14.2) ``` To verify the Node JS version, run the following command. ``` node --version ``` Output. ``` v18.14.2 ``` ## Step 3 – Install Angular CLI Angular provides a CLI tool used to install and manage Angular applications via the command line interface. First, install Angular CLI with the following command. ``` npm install -g @angular/cli ``` After the installation, you can verify the Angular version with the following command. ``` ng version ``` You should see the following output. ``` Thank you for sharing pseudonymous usage data. Should you change your mind, the following command will disable this feature entirely: ng analytics disable --global Global setting: enabled Local setting: No local workspace configuration file. Effective status: enabled _ _ ____ _ ___ / \ _ __ __ _ _ _| | __ _ _ __ / ___| | |_ _| / △ \ | '_ \ / _` | | | | |/ _` | '__| | | | | | | / ___ \| | | | (_| | |_| | | (_| | | | |___| |___ | | /_/ \_\_| |_|\__, |\__,_|_|\__,_|_| \____|_____|___| |___/ Angular CLI: 15.2.1 Node: 18.14.2 Package Manager: npm 9.5.0 OS: linux x64 Angular: ... Package Version ------------------------------------------------------ @angular-devkit/architect 0.1502.1 (cli-only) @angular-devkit/core 15.2.1 (cli-only) @angular-devkit/schematics 15.2.1 (cli-only) @schematics/angular 15.2.1 (cli-only) ``` ## Step 4 – Create an Angular Application First, install the Git package using the following command. ``` pacman -S git ``` Next, create a new Angular application using the following command. ``` ng new myapp ``` Once the application is created, you will get the following output. ``` ? Would you like to add Angular routing? No ? Which stylesheet format would you like to use? CSS CREATE myapp/README.md (1059 bytes) CREATE myapp/.editorconfig (274 bytes) CREATE myapp/.gitignore (548 bytes) CREATE myapp/angular.json (2695 bytes) CREATE myapp/package.json (1036 bytes) CREATE myapp/tsconfig.json (901 bytes) CREATE myapp/tsconfig.app.json (263 bytes) CREATE myapp/tsconfig.spec.json (273 bytes) CREATE myapp/.vscode/extensions.json (130 bytes) CREATE myapp/.vscode/launch.json (474 bytes) CREATE myapp/.vscode/tasks.json (938 bytes) CREATE myapp/src/favicon.ico (948 bytes) CREATE myapp/src/index.html (291 bytes) CREATE myapp/src/main.ts (214 bytes) CREATE myapp/src/styles.css (80 bytes) CREATE myapp/src/assets/.gitkeep (0 bytes) CREATE myapp/src/app/app.module.ts (314 bytes) CREATE myapp/src/app/app.component.css (0 bytes) CREATE myapp/src/app/app.component.html (23083 bytes) CREATE myapp/src/app/app.component.spec.ts (953 bytes) CREATE myapp/src/app/app.component.ts (209 bytes) ✔ Packages installed successfully. ``` Next, navigate to the myapp directory and run the application using the following command. ``` cd myapp ng serve --host 0.0.0.0 --port 8080 ``` Once the application started successfully, you should see the following output. ``` ✔ Browser application bundle generation complete. Initial Chunk Files | Names | Raw Size vendor.js | vendor | 1.71 MB | polyfills.js | polyfills | 314.26 kB | styles.css, styles.js | styles | 209.39 kB | main.js | main | 45.98 kB | runtime.js | runtime | 6.51 kB | | Initial Total | 2.28 MB Build at: 2023-03-03T15:38:15.307Z - Hash: 70299a3e44f1744b - Time: 12653ms ** Angular Live Development Server is listening on 0.0.0.0:8080, open your browser on http://localhost:8080/ ** ✔ Compiled successfully. ``` ## Step 5 – Access Angular Application At this point, Angular is installed on your server. Now, it’s time to access it via a web browser. Open your web browser and access the Angular web interface using the URL **http://your-server-ip:8080.** You should see the Angular page on the following screen. ![Angular dashboard](https://www.atlantic.net/wp-content/uploads/2023/03/p1-6.png) ## Conclusion In this tutorial, we explained how to install Angular on Arch Linux. We also create a sample Angular app and test it via a web browser. You can now start creating and deploying your own Angular application on the production server. Try Angular on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # On the FDIC Response to the Silicon Valley Banking Crisis: They Hurt the Wrong People > URL: https://www.atlantic.net/announcements/they-hurt-the-wrong-people/ | Published: 2023-03-16 | Updated: 2025-09-15 | Author: Marty You can learn a lot by simple observation. Last week, there was a brouhaha as several banks nearly collapsed, and then some did. The usual discourse will be set with educated people explaining how something was right, wrong, or neither. A joint statement by the FDIC, the Federal Reserve, and the United States Treasury affirmed their resolve to protect the system. While most coverage will try to confuse you with a labyrinth of econobabble whose goal is to convince you that it’s too complex and you can’t understand it, the reality is quite simple. In their attempt to hurt the right people, they accidentally hurt the wrong people. ## How Did This Happen? First, we must examine how we arrived here. In the post-2008 financial crisis, the economy was in rough shape. Simply put, there were too few jobs/businesses and too many workers. To solve that, the government decided to flood the markets with “easy money,” lending below the inflation rate, which led to a torrent of economic activity that would absorb the jobless. This created the cancer capitalists that built companies that never made money but soared in value as their businesses (and losses) grew. The money to be made was not in profit but in the shares they could sell of companies highly valued on their ever-growing promises of dominance in the future. Who doesn’t want to be in early for the next Google or Facebook? It would be great! Because these companies didn’t need to make money, they could be very inefficient in almost every facet. In fact, to maximize valuation, you needed to overpay and over-hire. Why wouldn’t you if you would dominate the on-demand dog-washing market? Are you going to be the market leader or not? **Go big or go home!** This coalesced nicely with government policy — it absorbed workers into the market, and they got paid an above-market rate. It was a win/win except for legacy companies that made money or were good at getting good returns on their investments. Those legacy companies didn’t help *solve* the problem; they were efficient, which *was* the problem. The new companies were the ones that would freely spend more on just sales and marketing than they brought in revenue, not the old guard. These companies were very inefficient, which made them fabulous (at least to the government). Sure, people were getting fabulously wealthy on questionable investing principles, but that was a small price to pay because it solved the problem of the greater good — we had enough “startups” to absorb the unemployed. People were attached to society, and all was good. People could complain about politics, taxes, or whatever while subscribing to environmentally sustainable seasonal doormats from hot startups. Life went on. ## Pandemic Stimulus **Then came the pandemic**, which led to massive stimulus to avert a massive depression, which swung things the other way. We made a society with too many businesses and not enough workers. Simple enough! We’ll tighten things up. We don’t really need fake companies anymore. After all, there need to be more workers for the real economy now. Think of it like a balloon; government policy inflated it (through free money programs), and now it intended to do the opposite, deflating it, which would re-balance the economy. This controlled demolition was coordinated by the brightest policymakers in the land to hurt people who work for a living so that they would be in the office at 9 am instead of hot yoga classes. Unfortunately, the government can’t control how things deflate exactly. The most fragile parts will break first if you put enough strain on any system. If you put enough weight on your body, your weakest joints will eventually snap first. It is expected! Instead of having the ordinary workers of society “deflate” in an orderly manner, the weakest “joint” turned out to be the newly rich and their risky investments. Imagine how frustrating it is for policymakers when the nouveau rich, who skimmed money from society by creating fake companies for a phony economy, are getting pulverized while the working class still had good jobs and long waits Friday night at Olive Garden. After all, who has more than $250,000 in cash in a bank account? Who needed saving? *Not the average Joe or Jane.* At this point, it is essential to understand why hurting the wrong people means it will hurt more when they hurt the right people. Imagine there are 5 friends, with 1 person (call him “Rich”) having $20, and everyone else has $5. The government, learning from the 2008 crisis that they a) went too slow and b) too small on stimulus, decides to do the opposite, so the crisis this time is abbreviated. They create free money programs that double everyone’s savings. Now Rich has $40, and his four friends have $10. Net-net, everyone is $40 “wealthier” (Rich has $20 extra, and the four friends have $20 extra combined). Everyone feels so good they buy a big drink and popcorn combo when they go to the movies. Now the economy has become hot *(because everyone feels too good)*, and you have runaway inflation, angering everyone. ## Handling Inflation Something must be done. Easy! **We’ll reverse the free money programs by raising interest rates and making things more challenging.** Unfortunately, Rich, being rich, has his money in with all the other rich people doing rich people’s stuff. Even more unfortunate because government policy is disproportionately whooshing away the stuff rich people have (because it’s the highest beta or moves the most relative to the real economy, like startup investments). Rich’s bank is now collapsing. The bank only has government guarantees for $20, so Rich is out $20. Excellent! It is working; over time, Rich’s friend’s assets will deflate (but slower because they aren’t in as sophisticated investment vehicles that can lose money quickly). Then, life can return to normal. Oops! *Rich wasn’t the one who the government wanted to hurt.* They had hurt the wrong person. Something must be done! Quick, we’ll coordinate at the highest levels of government. We’ll bail out Rich, but we won’t call it a bailout. We’ll say we’re protecting the people we are trying to hurt by keeping Rich, rich. We’ll say it’s to save the payrolls of small businesses. Who could be against that? So, Rich…well, **he gets to stay rich.** He receives the gains of the stimulus but none of the losses. However, the government still has an overarching problem they are trying to solve there is still too much money. They are still trying to remove the $40 they created. Rich being rich is now “systemically important,” so he must stay richer. The losses must come from somewhere else. ## The Problem with the Plan And that is where the plan delivers the chef’s kiss — **they will hurt the people they want to hurt even more.** Instead of Rich’s friends, each losing $5 to get things back to where they were, they each have to lose $5 plus the amount Rich should have lost ($20), so the friends each have to lose an additional $5, leaving them broke. So, we’re left with rich Rich, who has $40 and laments to his broke friends; *I wish you worked harder to vacation in the south of France with me, but you can’t.* Try harder! The real lesson is that it’s simple. We can learn what’s going on through simple observation. Clearly, the government is trying to slow the economy to dampen inflation and return the world to normal. When they hurt the right people, like in 2008 when people lost their homes, assets, and livelihood – it made sense because it was *“free markets”* and *“capitalism.”* However, when they hurt the wrong people (like the banks, the rich, or the politically connected), protecting them is deemed *“systemically important”* because we are really saving everyday people’s jobs. The problem is that when they hurt the right people, there won’t be any help. There will be free markets. Pull yourself up by your bootstraps. When that happens, we’ll know they are hurting the right people. There is a firehose of opinions you can listen to that will opine on what happened last week. Of course, you will be implored to believe that the issues are too complex and sophisticated to understand the grift. But just by simple observation, you can distill it to what it really is. **They hurt the wrong people.** This also means it will be much worse for those they plan to hurt when they hurt the right people. *This is an opinion piece.* --- # Digital Advertising Solutions > URL: https://www.atlantic.net/digital-advertising/ | Updated: 2026-09-16 Run data-intensive advertising platforms on scalable cloud, dedicated, colocation, or hybrid infrastructure backed by high-speed networking, audited environments, and 24/7/365 engineering support. - Low-Latency Networking - Cloud, Dedicated & Hybrid - Audited Compliance Environments - 24/7/365 Engineering Support Global Data Centers: 8 Regions Engineering Support: 24/7/365 ## Digital Advertising Digital ad platforms manage billions of ad impression purchases every month on various ad channels, from display to mobile. Such a massive operation requires secure networks backed by a solid infrastructure. Buyers and publishers need round-the-clock access to reliable data management and analytics to allow for the real-time adjustments that guarantee the accuracy and efficiency of the bidding process. A reliable platform ensures customer retention and can help you expand your reach. The Atlantic.Net platform’s robust processing capability and uncompromised security nurtures your investment while delivering a superior customer experience. ## The Perfect Fit Today’s digital ad ecosystem is rapidly pivoting from a human-managed marketplace to automated demand-side and sell-side platforms (DSPs and SSPs). They in turn demand lightning-speed, high accuracy advertising distribution channels across the digital domain. What makes Atlantic.Net an exceptional choice is the customized agility, high security, and technical compliance of its hosting environment, which was built to store and move massive amounts of data. Atlantic.Net’s servers operate in a low latency ecosystem with packets moving at high rates, all of which is crucial for web applications managing large scale campaigns and a centralized flow of ads across multiple platforms. Atlantic.Net features a higher concentration of facilities across metropolitan areas, such as New York, Dallas, Toronto, San Francisco, London, and Orlando, to further boost the speed of connections in saturated ad network markets. ## Rapid Expansion Without Compromise Cloud, Dedicated, Colocation, and Hybrid Hosting If you’re part of a company running data-intensive digital applications, you need a hosting platform that is reliable and scalable. Atlantic.Net provides a full suite of services to include Cloud, VPS, Dedicated, Colocation, Managed and Hybrid Hosting to ensure a fully scalable and custom-tailored solution for your growing business. Atlantic.Net offers you a time-tested and secure cloud hosting platform to fulfill these unique needs. Our RESTful API enables you to power and scale your web applications quickly and easily via your team's chosen deployment tools. Our cloud hosting control panel gives you control over your cloud servers to seamlessly and conveniently build and manage your cloud environment. Boosting and supporting high traffic websites and high productivity grids is Atlantic.Net’s strength. Our redundant high-speed network guarantees unsurpassed connectivity to sustain the ongoing effectiveness of your platform. Our Bare Metal Dedicated Servers and ACP Dedicated Cloud Hosts provide the option of dedicated resources for your team, whether that is in our Atlantic.Net Cloud Platform or a private environment. Atlantic.Net provides the optionality for you and your team to tackle any new obstacle thrown your way. ## Regulatory Compliance: Web advertisers process billions of ad impressions every month, including details such as ad sharing, location, pricing/auctioning, the identity of buyers and publishers, and their unique preferences. This data deserves proper safeguarding. That’s why our data centers are audited to meet and exceed various government regulatory requirements and safeguards such as GDPR, CCPA, HIPAA, PCI-DSS, and more. We are regularly audited and certified (SOC 2 TYPE II and SOC 3 TYPE II) to ensure that our data centers are up to these exacting standards. Our Compliant Hosting is perfect for ensuring that when in transfer or in storage, the critical data and records of your customers are encrypted, backed up, and shielded by fully integrated security layers and intrusion prevention system. ## Flexible Customization and Added Value At Atlantic.Net, we help you design a plan to match your unique requirements and budget. Whether you operate on a business or a development platform, we will tailor an environment to satisfy both you and your client base. We strive to offer maximum flexibility, and our team stands by to assist you every step of the way. Our Managed Services are specially designed to help our clients get more for less and our Engineering team will never leave you hanging. The Engineering team is waiting to help 24x7x365. Our Managed Services and Security Services help bring focus to your core business so that you can continue to grow your business. ## A Support Team Backed by Decades of Experience With over three decades of experience, our support team is always here to assist you. You’ll have 24/7/365 access to a crop of dedicated veterans, capable of solving any technical problem you throw their way. ## Cloud Availability in Multiple Global Regions Deploy close to your users from eight international data centers worldwide, with new regions on the way. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # How to Monitor Node.js Applications Using PM2 Web Dashboard > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-monitor-node-js-applications-using-pm2-web-dashboard/ | Published: 2023-03-17 | Updated: 2024-06-05 | Author: Hitesh Jethva Node.js is an open-source JavaScript runtime environment built on Chrome’s V8. It is mainly used to execute JavaScript code outside a web browser. It uses an asynchronous, event-driven model, perfect for data-intensive applications. After deploying a Node.js application, you may need a tool to monitor your application. This is where PM2 can help. PM2 is a popular process manager used for managing and monitoring Node.js applications. It allows you to monitor Node.js applications via CLI and a web-based dashboard. In this post, we will show you how to install and use PM2 to monitor Node.js applications. ## Step 1 – Install Nodejs First, install the necessary dependencies using the following command. ``` apt-get install -y ca-certificates curl gnupg ``` Next, download the Node.js GPG key. ``` mkdir -p /etc/apt/keyrings curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg ``` Next, add the NodeSource repo to the APT source list. ``` echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_18.x nodistro main" | tee /etc/apt/sources.list.d/nodesource.list ``` Then, update the repository index and install the Ndoe.js with the following command. ``` apt update apt-get install -y nodejs ``` Next, verify the Node.js version using the following command. ``` node -v ``` Output. ``` v18.19.0 ``` ## Step 2 – Create a Simple Nodejs Application Next, you will need a Node.js application that you want to monitor using PM2. First, create a directory for your application. ``` mkdir app ``` Next, create an application file. ``` cd app nano app.js ``` Add the following code: ``` const http = require('http'); const hostname = 'localhost'; const port = 3000; const server = http.createServer((req, res) => { res.statusCode = 200; res.setHeader('Content-Type', 'text/plain'); res.end('Your Nodejs App is Working!\n'); }); server.listen(port, hostname, () => { console.log(`Server running at http://${hostname}:${port}/`); }); ``` Save and close the file when you are done. ## Step 3 – Install and Use PM2 to Manage Nodejs Application First, install PM2 using the following command. ``` npm install pm2 -g ``` Next, start the Node.js application using PM2. ``` pm2 start app.js ``` Output. ``` [PM2] Spawning PM2 daemon with pm2_home=/root/.pm2 [PM2] PM2 Successfully daemonized [PM2] Starting /root/app/app.js in fork_mode (1 instance) [PM2] Done. ┌────┬────────┬─────────────┬─────────┬─────────┬──────────┬────────┬──────┬───────────┬──────────┬──────────┬──────────┬──────────┐ │ id │ name │ namespace │ version │ mode │ pid │ uptime │ ↺ │ status │ cpu │ mem │ user │ watching │ ├────┼────────┼─────────────┼─────────┼─────────┼──────────┼────────┼──────┼───────────┼──────────┼──────────┼──────────┼──────────┤ │ 0 │ app │ default │ N/A │ fork │ 55173 │ 0s │ 0 │ online │ 0% │ 33.0mb │ root │ disabled │ └────┴────────┴─────────────┴─────────┴─────────┴──────────┴────────┴──────┴───────────┴──────────┴──────────┴──────────┴──────────┘ ``` You can now list your application using the following command. ``` pm2 list ``` Output ``` ┌────┬────────┬─────────────┬─────────┬─────────┬──────────┬────────┬──────┬───────────┬──────────┬──────────┬──────────┬──────────┐ │ id │ name │ namespace │ version │ mode │ pid │ uptime │ ↺ │ status │ cpu │ mem │ user │ watching │ ├────┼────────┼─────────────┼─────────┼─────────┼──────────┼────────┼──────┼───────────┼──────────┼──────────┼──────────┼──────────┤ │ 0 │ app │ default │ N/A │ fork │ 55173 │ 16s │ 0 │ online │ 0% │ 51.2mb │ root │ disabled │ └────┴────────┴─────────────┴─────────┴─────────┴──────────┴────────┴──────┴───────────┴──────────┴──────────┴──────────┴──────────┘ ``` To stop and delete the application, run the following command. ``` pm2 stop app.js pm2 delete app.js ``` To reload the application after making changes, run the following command. ``` pm2 reload app.js ``` To add the application at system startup, run the following command. ``` pm2 startup ``` To check the application log, run the following command. ``` pm2 logs ``` Output. ``` PM2 | 2023-07-30T10:23:06: PM2 log: BUS socket file : /root/.pm2/pub.sock PM2 | 2023-07-30T10:23:06: PM2 log: Application log path : /root/.pm2/logs PM2 | 2023-07-30T10:23:06: PM2 log: Worker Interval : 30000 PM2 | 2023-07-30T10:23:06: PM2 log: Process dump file : /root/.pm2/dump.pm2 PM2 | 2023-07-30T10:23:06: PM2 log: Concurrent actions : 2 PM2 | 2023-07-30T10:23:06: PM2 log: SIGTERM timeout : 1600 PM2 | 2023-07-30T10:23:06: PM2 log: =============================================================================== PM2 | 2023-07-30T10:23:06: PM2 log: App [app:0] starting in -fork mode- PM2 | 2023-07-30T10:23:06: PM2 log: App [app:0] online PM2 | 2023-07-30T10:23:36: PM2 log: Process 0 in a stopped status, starting it PM2 | 2023-07-30T10:23:36: PM2 log: Stopping app:app id:0 PM2 | 2023-07-30T10:23:36: PM2 log: App [app:0] exited with code [0] via signal [SIGINT] PM2 | 2023-07-30T10:23:37: PM2 log: pid=55173 msg=process killed PM2 | 2023-07-30T10:23:37: PM2 log: App [app:0] starting in -fork mode- PM2 | 2023-07-30T10:23:37: PM2 log: App [app:0] online /root/.pm2/logs/app-error.log last 15 lines: /root/.pm2/logs/app-out.log last 15 lines: 0|app | Server running at http://localhost:3000/ 0|app | Server running at http://localhost:3000/ ``` ## Step 4 – Monitor Nodejs Application Using PM2 Dashboard PM2 also provides a web-based dashboard that allows you to monitor and diagnose Node.js applications in real-time. To use the PM2 dashboard, go to **https://app.pm2.io,** then sign up as shown in the following screenshot. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p1-7.png) After the successful login, copy the pm2 link command from the above screenshot and run it on your server. ``` pm2 link 30ew4cpwzxopx3v tzc9tp9s2oc0wkf ``` You will see the following output: ``` [PM2 I/O] Using: Public key: tzc9tp9s2oc0wkf | Private key: 30ew4cpwzxopx3v | Machine name: fedora-e930 [+] PM2+ activated! ``` Now, refresh the PM2 dashboard page. You should see that your server is connected and showing a list of all your Nodejs applications in expanded mode. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p2-7.png) ## Step 5 – Monitor Nodejs Using pm2-server-monit You can also use the pm2-server-monit module to monitor your application’s CPU, disk, and memory usage, network speed, and other key aspects of your server. You can install the pm2-server-monit module with the following command. ``` pm2 install pm2-server-monit ``` Output: ``` ⇆ PM2+ activated | Instance Name: fedora-e930 | Dash: https://app.pm2.io/#/r/tzc9tp9s2oc0wkf ┌────┬─────────────────────┬─────────────┬─────────┬─────────┬──────────┬────────┬──────┬───────────┬──────────┬──────────┬──────────┬──────────┐ │ id │ name │ namespace │ version │ mode │ pid │ uptime │ ↺ │ status │ cpu │ mem │ user │ watching │ ├────┼─────────────────────┼─────────────┼─────────┼─────────┼──────────┼────────┼──────┼───────────┼──────────┼──────────┼──────────┼──────────┤ │ 0 │ app │ default │ N/A │ fork │ 55202 │ 5m │ 1 │ online │ 0% │ 52.4mb │ root │ disabled │ └────┴─────────────────────┴─────────────┴─────────┴─────────┴──────────┴────────┴──────┴───────────┴──────────┴──────────┴──────────┴──────────┘ Module ┌────┬──────────────────────────────┬───────────────┬──────────┬──────────┬──────┬──────────┬──────────┬──────────┐ │ id │ module │ version │ pid │ status │ ↺ │ cpu │ mem │ user │ ├────┼──────────────────────────────┼───────────────┼──────────┼──────────┼──────┼──────────┼──────────┼──────────┤ │ 1 │ pm2-server-monit │ 3.0.0 │ 55367 │ online │ 0 │ 0% │ 26.9mb │ root │ └────┴──────────────────────────────┴───────────────┴──────────┴──────────┴──────┴──────────┴──────────┴──────────┘ ``` Once installed, go back to your PM2 dashboard. You should see your server’s key metrics on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p3-6.png) If you want to remove your server from the PM2 dashboard, run the following command: ``` pm2 unlink ``` Output: ``` [PM2 I/O] Permanently disable agent... [PM2 I/O] Agent interaction ended ``` ## Conclusion In this post, we showed you how to install Node.js, create a Node.js application and then manage it via the command line. Then, we explained how to install the PM2 dashboard and monitor your application via a web-based dashboard. You can now deploy the Node.js application on [virtual private server hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! and start monitoring it using the PM2 dashboard. --- # How to Install Golang on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-golang-on-arch-linux/ | Published: 2023-03-19 | Updated: 2023-11-14 | Author: Hitesh Jethva Go, also known as Golang or Go language, is an open-source programming language developed by Google. It is a high-level language used for developing web applications, cloud, and networking services. Compared to other programming languages, Golang runs faster, compiles quicker, is easy to maintain and support, and allows for shorter software development lifecycles. In this post, we will show you how to install Golang on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file then update all the package index with the following command: ``` pacman -Syu ``` ## Step 2 – Install Golang First, visit the Golang official website, pick the latest version of Golang, and download it with the following command. ``` wget https://go.dev/dl/go1.20.1.linux-amd64.tar.gz ``` Once the download is completed, extract the downloaded file with the following command. ``` tar -C /usr/local -xzf go1.20.1.linux-amd64.tar.gz ``` You can verify the content of the extracted file with the following command. ``` ls /usr/local/go ``` You should see the following output. ``` api bin CONTRIBUTING.md doc LICENSE PATENTS README.md src VERSION AUTHORS codereview.cfg CONTRIBUTORS lib misc pkg SECURITY.md test ``` ## Step 3 – Create Golang Environment Variable Next, you will need to create or edit the .bashrc file and define your Golang installation path. ``` nano ~/.bashrc ``` Add the following line: ``` export PATH=$PATH:/usr/local/go/bin ``` Save and close the file, then activate the environment variable with the following command. ``` source ~/.bashrc ``` You can now verify the Go version with the following command. ``` go version ``` You should see the Go version in the following output. ``` go version go1.18.1 linux/amd64 ``` ## Step 4 – Create a Project with Golang First, create a project directory for Golang using the following command. ``` mkdir project ``` Next, navigate to the project directory and initialize the project with the following command. ``` cd project go mod init go.example.com/hello ``` Next, create a hello application file with the following command. ``` nano hello.go ``` Add the following code. ``` package main import "fmt" func main() { fmt.Println("Hello, Go is working") } ``` Save and close the file, then run the Go application using the following command. ``` go run hello.go ``` If everything is fine, you should see the following output. ``` Hello, Go is working ``` ## Conclusion In this post, we showed you how to install Golang on Arch Linux. We also created a sample project with Golang. You can now start developing cloud and web applications using Golang. Deploy the Go application on a [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) plan from Atlantic.Net! --- # How to Install Dstat Monitoring Tool on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-dstat-monitoring-tool-on-arch-linux/ | Published: 2023-03-20 | Updated: 2023-11-15 | Author: Hitesh Jethva Dstat is a versatile tool used for monitoring several system resources such as CPU, Memory, Network, Processes, and more. It is a great replacement for older tools such as vmstat, iostat, mpstat, netstat, and ifstat. It displays system resources in a real-time. Dstat is written in Python and allows you to export a generated result in an Excel sheet If you are looking for an all-in-one system resource monitoring tool, then Dstat is the right choice for you. In this post, we will show you how to install and use the Dstat monitoring tool on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Dstat By default, the Dstat utility is included in the Arch Linux default repository. You can install it using the following command. ``` pacman -S dstat ``` Once Dstat is installed, you can see all Dstat options with the following command. ``` dstat --help ``` You should see the following screen. ![Dstat help page](https://www.atlantic.net/wp-content/uploads/2023/03/p1-1.png) ## Step 3 – How to Use Dstat to Monitor System Resources. To display the CPU usage information, run the following command. ``` dstat -c ``` You should see the following screen. ![cpu usage](https://www.atlantic.net/wp-content/uploads/2023/03/p1-8.png) To display the memory usage information, run the following command. ``` dstat -m ``` You should see the following screen. ![dstat memory usage](https://www.atlantic.net/wp-content/uploads/2023/03/p3-5.png) To display CPU usage with load average, run the following command. ``` dstat -cl ``` You should see the following screen. ![dstat cpu usage](https://www.atlantic.net/wp-content/uploads/2023/03/p4-3.png) To display the most expensive CPU process with the most expensive memory process, run the following command. ``` dstat --top-cpu-adv --top-latency --top-mem ``` You should see the following screen. ![most expensive cpu usage](https://www.atlantic.net/wp-content/uploads/2023/03/p5-3.png) To display to CPU and Memory consuming processes, run the following command. ``` dstat -c --top-cpu -dn --top-mem ``` You should see the following screen. ![dstat cpu and memory consuming processes](https://www.atlantic.net/wp-content/uploads/2023/03/p6-5.png) If you want to display the time, CPU, mem, and system load stats with a one-second delay between 5 updates, run the following command. ``` dstat --time --cpu --mem --load 1 5 ``` You should see the following screen. ![dstat laod status](https://www.atlantic.net/wp-content/uploads/2023/03/p7-4.png) To list all available Dstat plugins, run the following command. ``` dstat --list ``` You should see all plugins on the following screen. ![list dstat plugins](https://www.atlantic.net/wp-content/uploads/2023/03/p8-3.png) To display information in vmstat format, use the following command: ``` dstat --vmstat ``` You should see the following screen. ![vmstat](https://www.atlantic.net/wp-content/uploads/2023/03/p9-3.png) To display the output without color, run the following command. ``` dstat --nocolor ``` ## Conclusion In this post, we showed you how to install and use Dstat to monitor server performance and system resources via the command line. You can now use Dstat on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # VPS Hosting Pricing > URL: https://www.atlantic.net/vps-hosting/pricing/ | Updated: 2026-09-16 Compare General Purpose, Compute Optimized, Storage Optimized, and Memory Optimized VPS plans starting at $8 per month or $0.0119 per hour, with hourly pay-as-you-go flexibility, post-paid billing, and discounted 1- and 3-year commitments. - Plans from $8/Month - Hourly Pay-As-You-Go - 1- & 3-Year Discounts - 100% Uptime SLA Starting Monthly: $8 Starting Hourly: $0.0119 ## Affordable and Cost-Effective VPS Hosting Plans We offer affordable and cost-effective VPS hosting with strong value in VPS pricing. Our packages and plans are based on your growing needs and can be scaled up or down depending on your business requirements. Every VPS hosting plan comes with a term discount to help you enjoy meaningful cost savings. Our hourly plans are designed to give you the best of all worlds, with the ability to deploy servers cost-effectively at an hourly rate, while giving you the option to lock into cost savings with a term commitment. While we are not the cheapest, we take pride in providing high-quality VPS service backed by a 100% uptime SLA. ## All-Inclusive Pricing and Post-Paid Billing Atlantic.Net provides top-notch VPS hosting with plans starting at only $8.00 per month or $0.0119 per hour. Our VPS hosting plans are all-inclusive, which means there are no surprise bills. Best of all, our VPS hosting plans are billed in arrears: another way Atlantic.Net helps small businesses budget with a post-paid option. Say hello to all-inclusive VPS hosting plans and goodbye to surprise bills. ## Affordable VPS Hosting Pricing & Plans | | | | | | | | | | --- | --- | --- | --- | --- | --- | --- | --- | | General Purpose | G3.2GB | 2GB | 1 | 50GB | 3 TB | On-Demand: $10.0/mo $0.0149/hr; 1-Year: $9.0/mo $0.0134/hr; 3-Year: $8.0/mo $0.0119/hr | On-Demand: $16.5/mo $0.0246/hr; 1-Year: $15.5/mo $0.0231/hr; 3-Year: $15.5/mo $0.0231/hr | | General Purpose | G3.4GB | 4GB | 2 | 80GB | 5 TB | On-Demand: $20.0/mo $0.0298/hr; 1-Year: $18.0/mo $0.0268/hr; 3-Year: $17.0/mo $0.0253/hr | On-Demand: $33.0/mo $0.0491/hr; 1-Year: $31.0/mo $0.0461/hr; 3-Year: $30.0/mo $0.0446/hr | | General Purpose | G3.8GB | 8GB | 4 | 160GB | 6 TB | On-Demand: $40.0/mo $0.0595/hr; 1-Year: $37.0/mo $0.0551/hr; 3-Year: $34.0/mo $0.0506/hr | On-Demand: $66.0/mo $0.0982/hr; 1-Year: $63.0/mo $0.0938/hr; 3-Year: $59.5/mo $0.0885/hr | | General Purpose | G3.16GB | 16GB | 6 | 320GB | 7 TB | On-Demand: $80.0/mo $0.119/hr; 1-Year: $74.0/mo $0.1101/hr; 3-Year: $68.0/mo $0.1012/hr | On-Demand: $132.5/mo $0.1972/hr; 1-Year: $125.5/mo $0.1868/hr; 3-Year: $119.5/mo $0.1778/hr | | General Purpose | G3.32GB | 32GB | 8 | 640GB | 8 TB | On-Demand: $160.0/mo $0.2381/hr; 1-Year: $147.0/mo $0.2188/hr; 3-Year: $136.0/mo $0.2024/hr | On-Demand: $265.0/mo $0.3943/hr; 1-Year: $250.5/mo $0.3728/hr; 3-Year: $238.0/mo $0.3542/hr | | General Purpose | G3.48GB | 48GB | 12 | 960GB | 9 TB | On-Demand: $240.0/mo $0.3571/hr; 1-Year: $220.0/mo $0.3274/hr; 3-Year: $204.0/mo $0.3036/hr | On-Demand: $397.5/mo $0.5915/hr; 1-Year: $375.5/mo $0.5588/hr; 3-Year: $358.5/mo $0.5335/hr | | General Purpose | G3.64GB | 64GB | 16 | 1280GB | 10 TB | On-Demand: $320.0/mo $0.4762/hr; 1-Year: $294.0/mo $0.4375/hr; 3-Year: $272.0/mo $0.4048/hr | On-Demand: $529.5/mo $0.7879/hr; 1-Year: $500.5/mo $0.7448/hr; 3-Year: $477.0/mo $0.7098/hr | | General Purpose | G3.96GB | 96GB | 20 | 1920GB | 11 TB | On-Demand: $480.0/mo $0.7143/hr; 1-Year: $441.6/mo $0.6571/hr; 3-Year: $408.0/mo $0.6071/hr | On-Demand: $795.5/mo $1.1838/hr; 1-Year: $754.5/mo $1.1228/hr; 3-Year: $718.5/mo $1.0692/hr | | General Purpose | G3.128GB | 128GB | 24 | 2560GB | 12 TB | On-Demand: $640.0/mo $0.9524/hr; 1-Year: $589.0/mo $0.8765/hr; 3-Year: $544.0/mo $0.8095/hr | On-Demand: $1,059.0/mo $1.5759/hr; 1-Year: $1,003.0/mo $1.4926/hr; 3-Year: $953.0/mo $1.4182/hr | | General Purpose | G3.192GB | 192GB | 32 | 3840GB | 13 TB | On-Demand: $960.0/mo $1.4286/hr; 1-Year: $883.2/mo $1.3143/hr; 3-Year: $816.0/mo $1.2143/hr | On-Demand: $1,588.5/mo $2.3638/hr; 1-Year: $1,506.5/mo $2.2418/hr; 3-Year: $1,435.5/mo $2.1362/hr | | Compute Optimized | C2.8GB | 8GB | 4 | 40GB | 10 TB | On-Demand: $211.0/mo $0.314/hr; 1-Year: $137.0/mo $0.2039/hr; 3-Year: $67.0/mo $0.0997/hr | On-Demand: $254.5/mo $0.3787/hr; 1-Year: $173.0/mo $0.2574/hr; 3-Year: $96.0/mo $0.1429/hr | | Compute Optimized | C2.16GB | 16GB | 8 | 80GB | 10 TB | On-Demand: $418.0/mo $0.622/hr; 1-Year: $271.0/mo $0.4033/hr; 3-Year: $133.0/mo $0.1979/hr | On-Demand: $505.5/mo $0.7522/hr; 1-Year: $343.0/mo $0.5104/hr; 3-Year: $190.5/mo $0.2835/hr | | Compute Optimized | C2.32GB | 32GB | 16 | 160GB | 10 TB | On-Demand: $828.0/mo $1.2321/hr; 1-Year: $538.0/mo $0.8006/hr; 3-Year: $263.0/mo $0.3914/hr | On-Demand: $1,002.0/mo $1.4911/hr; 1-Year: $682.0/mo $1.0149/hr; 3-Year: $378.0/mo $0.5625/hr | | Compute Optimized | C2.64GB | 64GB | 20 | 350GB | 10 TB | On-Demand: $1,451.0/mo $2.1592/hr; 1-Year: $943.0/mo $1.4033/hr; 3-Year: $461.0/mo $0.686/hr | On-Demand: $1,777.5/mo $2.6451/hr; 1-Year: $1,216.5/mo $1.8103/hr; 3-Year: $685.0/mo $1.0194/hr | | Storage Optimized | S2.16GB | 16GB | 2 | 500GB | 10 TB | On-Demand: $248.0/mo $0.369/hr; 1-Year: $161.0/mo $0.2396/hr; 3-Year: $105.0/mo $0.1563/hr | On-Demand: $317.5/mo $0.4725/hr; 1-Year: $221.5/mo $0.3296/hr; 3-Year: $160.0/mo $0.2381/hr | | Storage Optimized | S2.32GB | 32GB | 4 | 1TB | 10 TB | On-Demand: $425.0/mo $0.6324/hr; 1-Year: $276.0/mo $0.4107/hr; 3-Year: $180.0/mo $0.2679/hr | On-Demand: $557.0/mo $0.8289/hr; 1-Year: $392.5/mo $0.5841/hr; 3-Year: $286.5/mo $0.4263/hr | | Storage Optimized | S2.64GB | 64GB | 8 | 2TB | 10 TB | On-Demand: $778.0/mo $1.1577/hr; 1-Year: $506.0/mo $0.753/hr; 3-Year: $330.0/mo $0.4911/hr | On-Demand: $1,035.0/mo $1.5402/hr; 1-Year: $734.5/mo $1.093/hr; 3-Year: $540.5/mo $0.8043/hr | | Storage Optimized | S2.96GB | 96GB | 12 | 3TB | 10 TB | On-Demand: $1,097.0/mo $1.6324/hr; 1-Year: $713.0/mo $1.061/hr; 3-Year: $465.0/mo $0.692/hr | On-Demand: $1,475.0/mo $2.1949/hr; 1-Year: $1,051.5/mo $1.5647/hr; 3-Year: $777.5/mo $1.157/hr | | Storage Optimized | S2.128GB | 128GB | 16 | 4TB | 10 TB | On-Demand: $1,414.0/mo $2.1042/hr; 1-Year: $919.0/mo $1.3676/hr; 3-Year: $599.0/mo $0.8914/hr | On-Demand: $1,913.0/mo $2.8467/hr; 1-Year: $1,367.0/mo $2.0342/hr; 3-Year: $1,013.5/mo $1.5082/hr | | Memory Optimized | M2.16GB | 16GB | 2 | 40GB | 10 TB | On-Demand: $163.0/mo $0.2426/hr; 1-Year: $106.0/mo $0.1577/hr; 3-Year: $52.0/mo $0.0774/hr | On-Demand: $223.5/mo $0.3326/hr; 1-Year: $161.0/mo $0.2396/hr; 3-Year: $101.5/mo $0.151/hr | | Memory Optimized | M2.32GB | 32GB | 4 | 80GB | 10 TB | On-Demand: $318.0/mo $0.4732/hr; 1-Year: $207.0/mo $0.308/hr; 3-Year: $101.0/mo $0.1503/hr | On-Demand: $439.0/mo $0.6533/hr; 1-Year: $316.5/mo $0.471/hr; 3-Year: $200.0/mo $0.2976/hr | | Memory Optimized | M2.64GB | 64GB | 8 | 160GB | 10 TB | On-Demand: $630.0/mo $0.9375/hr; 1-Year: $409.0/mo $0.6086/hr; 3-Year: $200.0/mo $0.2976/hr | On-Demand: $871.5/mo $1.2969/hr; 1-Year: $627.5/mo $0.9338/hr; 3-Year: $397.5/mo $0.5915/hr | | Memory Optimized | M2.128GB | 128GB | 16 | 350GB | 10 TB | On-Demand: $1,246.0/mo $1.8542/hr; 1-Year: $810.0/mo $1.2054/hr; 3-Year: $396.0/mo $0.5893/hr | On-Demand: $1,727.5/mo $2.5707/hr; 1-Year: $1,246.5/mo $1.8549/hr; 3-Year: $790.0/mo $1.1756/hr | *All plans are available in every location for Managed Server clients. *The hourly rate is determined by dividing the monthly rate by 672 hours (28 days). If your server is online for more than 672 hours in a calendar month, you will only be billed the monthly rate. *Prices listed above are based on the service being utilized for the period specified. *All Servers include one IPv4 Address. Additional IPs are available for $3.65/month ($0.005431/hour) *Unlimited inbound bandwidth. If free outbound bandwidth is exceeded, each additional GB is $0.02 *Optional Daily Backups are available for 20% of the server price. Minimum $1.00/month. *cPanel licensing cost starts at $23 per month ## The hosting plans are available in four categories ### General Purpose Ideal for everyday use, these VPS plans strike a great balance between cost and performance. You are always guaranteed the resources you pay for in all our VPS servers, but General Purpose is a strong fit for developers, web hosting, and self-managed applications. ### Storage Optimized Does your VPS require high-performance storage space or intense I/O writes? Choose our storage-optimized VPS hosting option. This plan is well suited for databases or projects with heavy storage utilisation. ### Memory Optimized Beneficial for applications that require ample RAM to operate efficiently, such as databases, content management systems, e-commerce hosting, and data analytics. ### Compute Optimized This type of VPS plan is tailored for applications that demand high computational power and processing speed. Common workloads include gaming servers, media encoding and streaming, development build environments, and scientific / research applications. ## Learn More About VPS Server Hosting Pricing ### How am I billed? You will be billed monthly on the anniversary of the date you registered for the Atlantic.Net Cloud. You will only be billed for the cloud servers you deploy and the data transfer used in the previous month. For a detailed billing section in the Cloud Control Panel, navigate to **Account Info → Payment and Billings**. Here you can update your payment information and view your entire billing history and activity. You can also create billing alerts for added peace of mind. ### How will I be billed for my use of Atlantic.Net Cloud Services? Atlantic.Net offers a clear breakdown of billing costs prior to deploying a VPS. The cost of each VPS plan is shown right before you click deploy. We offer three types of payment terms: 1. A pay-as-you-go pricing model 2. One-year commitment discounted rate 3. Three-year commitment discounted rate The pay-as-you-go pricing model has no minimum fee: you can spin up a server for 5 hours or 5 months and you will only be charged for what you use. You pay for the services you need for as long as you want to use them, with no need for long-term contracts or complex licensing agreements. Cloud services are billed on an hourly basis up to the monthly cap rate. The hourly rate is determined by dividing the monthly rate by 672 hours (28 days). If you use a service for more than 672 hours in a month, you will only be billed for the monthly rate. ### If I power my Cloud VPS off, will I still be charged for it? Yes. We bill for your cloud server from the time you create it until you delete it. If you stop your server, we still have to reserve CPU, memory, and storage resources even though the server is not running. ### Can I upgrade my VPS plan at any time? Yes. You can easily upgrade your VPS plan at any time through the Atlantic.Net Cloud Control Panel. This flexibility lets you scale your resources based on your current needs and avoid overpaying for unused capacity. Take a snapshot of the server, recreate the instance using a larger hosting plan, then restore the snapshot: the entire process takes only a few minutes. ### What operating systems are supported on your VPS hosting? The Atlantic.Net Cloud Platform supports a wide range of popular operating systems, including Linux distributions (CentOS, Ubuntu, Debian, AlmaLinux, Rocky Linux, and more), Windows Server, and FreeBSD. You can choose the operating system that best suits your requirements during the server deployment process. In total, we have 40+ Linux builds and 14 Windows Server versions to choose from. ### How does VPS pricing work, and what factors influence it? VPS pricing varies significantly depending on the provider. Typically, billing is associated with the resources allocated: CPU, RAM, storage, and bandwidth. Additional charges may exist for advanced features or specific contract terms. Hourly billing is increasingly popular because it provides flexibility for short-term projects or testing environments. Atlantic.Net supports hourly pay-as-you-go billing and offers discounts for longer-term commitments (annual or multi-year plans). It's worth comparing pricing from different providers while also considering performance, reliability, customer support, and additional features that contribute to overall value. ### What are the different types of VPS plans available, and how do I choose the right one for my needs? Atlantic.Net offers four main categories of VPS plans on the ACP: - **General Purpose:** balanced performance and cost, suitable for most applications. - **Storage Optimized:** high-performance storage for databases or projects with heavy I/O. - **Memory Optimized:** fast RAM for applications requiring significant memory resources, such as databases. - **Compute Optimized:** high computational power for demanding applications like gaming or media processing. The best choice depends on your specific requirements. Consider the nature of your applications, expected workload, and resource demands when selecting a plan. [Reach out to our support team for further help](https://www.atlantic.net/about-us/corporate-contact/). ### What are the benefits of pre-paid vs. post-paid billing for VPS hosting? Pre-paid billing requires payment in advance for services, while post-paid billing lets you pay after using the services. Billing flexibility is important for our customers: some clients prefer to pay upfront, others require payments on demand. With ACP you get that flexibility and more. **Why choose pre-paid?** - Cost control: pay upfront for a specific period, avoiding unexpected charges. - Budgeting: predictable expenses, easier to plan finances. - No credit checks: suitable for individuals or businesses with limited credit history. - Potential discounts: Atlantic.Net offers deep discounts for 1- to 3-year commitments. **Why choose post-paid?** - Flexibility: pay only for resources used, ideal for variable workloads. - Scalability: easily upgrade or downgrade resources as needed. - No upfront costs: no need to commit to a large payment upfront. - Better cash flow: pay for services after they have been used. The best billing model depends on your specific needs and preferences. Consider your budget, resource requirements, and desired level of flexibility when making a decision. ## Read More About VPS Hosting ### [VPS Hosting](https://www.atlantic.net/vps-hosting/) - [VPS Hosting](https://www.atlantic.net/vps-hosting/) - [Windows VPS Hosting](https://www.atlantic.net/vps-hosting/windows-vps-hosting/) - [Linux VPS Hosting](https://www.atlantic.net/vps-hosting/linux-vps-hosting/) - [What Is Web Server Hosting?](https://www.atlantic.net/dedicated-server-hosting/what-is-web-server-hosting/) - [WordPress VPS Hosting](https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/) ## A Support Team Backed by Decades of Experience With over three decades of experience, our support team is always here to assist you. You’ll have 24/7/365 access to a crop of dedicated veterans, capable of solving any technical problem you throw their way. ## Cloud Availability in Multiple Global Regions Deploy close to your users from eight international data centers worldwide, with new regions on the way. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." --- # How to Install TinyProxy on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-tinyproxy-on-arch-linux/ | Published: 2023-03-21 | Updated: 2023-11-17 | Author: Hitesh Jethva TinyProxy is a lightweight and small-footprint Proxy server designed for Linux-based operating systems. It is fast, configurable, and also can be used as a reverse proxy. It offers an access control feature that helps you to block and unblock specific websites. It is an ideal solution for use cases such as embedded deployments requiring a full-featured HTTP proxy. In this post, we will show you how to install TinyProxy on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install TinyProxy By default, the TinyProxy package is included in the Arch Linux main repository. You can simply install it with the following command. ``` pacman -S tinyproxy ``` Once the TinyProxy is installed on your server, you can proceed to the next step. ## Step 3 – Configure TinyProxy Next, you will need to edit the TinyProxy main configuration file and modify it as per your requirements. You can edit it with the following command. ``` nano /etc/tinyproxy/tinyproxy.conf ``` Change the following configurations. ``` Port 8888 Listen your-server-ip LogFile "/var/log/tinyproxy/tinyproxy.log" PidFile "/var/run/tinyproxy/tinyproxy.pid" BasicAuth user password Allow client-machine-ip ``` Save and close the file, then create a log directory and file with the following command. ``` mkdir /var/log/tinyproxy touch /var/log/tinyproxy/tinyproxy.log ``` Next, start and enable the TinyProxy service with the following command. ``` systemctl start tinyproxy systemctl enable tinyproxy ``` You can now verify the status of TinyProxy using the following command. ``` systemctl status tinyproxy ``` You should see the following output. ``` ● tinyproxy.service - Tinyproxy Web Proxy Server Loaded: loaded (/usr/lib/systemd/system/tinyproxy.service; disabled; preset: disabled) Active: active (running) since Sat 2023-03-04 03:40:34 UTC; 3min 53s ago Process: 64007 ExecStart=/usr/bin/tinyproxy -c /etc/tinyproxy/tinyproxy.conf (code=exited, status=0/SUCCESS) Main PID: 64009 (tinyproxy) Tasks: 1 (limit: 2362) Memory: 1.4M CGroup: /system.slice/tinyproxy.service └─64009 /usr/bin/tinyproxy -c /etc/tinyproxy/tinyproxy.conf Mar 04 03:40:34 archlinux tinyproxy[64009]: Added basic auth user : user Mar 04 03:40:34 archlinux tinyproxy[64009]: Setting "Via" header to 'tinyproxy' Mar 04 03:40:34 archlinux tinyproxy[64009]: Reloading config file finished Mar 04 03:40:34 archlinux tinyproxy[64009]: listen_sock called with addr = '69.28.85.116' Mar 04 03:40:34 archlinux tinyproxy[64009]: trying to listen on host[69.28.85.116], family[2], socktype[1], proto[6] Mar 04 03:40:34 archlinux tinyproxy[64009]: listening on fd [0] Mar 04 03:40:34 archlinux tinyproxy[64009]: Now running as group "tinyproxy". Mar 04 03:40:34 archlinux tinyproxy[64009]: Now running as user "tinyproxy". Mar 04 03:40:34 archlinux tinyproxy[64009]: Setting the various signals. Mar 04 03:40:34 archlinux tinyproxy[64009]: Starting main loop. Accepting connections. ``` At this point, TinyProxy is installed and listens on port 8888. You can check it with the following command. ``` ss -antpl | grep tinyproxy ``` You should see the following output. ``` LISTEN 0 0 69.28.85.116:8888 0.0.0.0:* users:(("tinyproxy",pid=64009,fd=0)) ``` ## Step 4 – Define Proxy Setting on Web Browser Next, you will need to configure your web browser and define your proxy server. Go to the client machine, open the Firefox browser, and click on the **settings.** You should see the following screen. ![firefox setting](https://www.atlantic.net/wp-content/uploads/2023/03/p1-9.png) Now, click on the settings under the **Network Settings.** You should see the proxy setting screen. ![firefox proxy setting](https://www.atlantic.net/wp-content/uploads/2023/03/p2-6.png) Define your TinyProxy server IP, Port, and click on the **Ok** button. Now, type the URL **https://whatismyipaddress.com/** in your web browser. You will be asked to provide a username and password. ![authenticate tiny proxy](https://www.atlantic.net/wp-content/uploads/2023/03/p3-6.png) Provide your username and password and click on the **Sign in** button to authentic TinyProxy. You should see your server IP on the following screen. ![whatismyip screen](https://www.atlantic.net/wp-content/uploads/2023/03/p4-4.png) ## Conclusion In this tutorial, we explained how to install TinyProxy and configure it on Arch Linux. You can now use TinyProxy to browse the Internet anonymously. You can also deploy TinyProxy on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Cloud Hosting FAQ > URL: https://www.atlantic.net/faq/ | Updated: 2026-09-16 ## General ### What is the Atlantic.Net Cloud Platform? The ultra-fast Atlantic.Net Cloud Platform allows our users to deploy virtual machines in a matter of seconds. The platform is fully redundant, highly available, and available in eight locations inside the United States, Canada, Asia, and Europe, with more coming online soon. You can scale up when needed, you only have to pay for what you use, and you can cancel your cloud server at any time with no commitments, saving you significant time and money. Our Cloud servers are built to stringent security best practices, and all servers have root access (or Windows Administrator) privileges enabled and available upon launch. The Atlantic.Net Cloud Platform combines simplicity, security, and scalability with the reliability of the latest virtualization and cloud hosting platform technology. ### What Is VPS Hosting in the Cloud? A Virtual Private Server (VPS) is a viable alternative to dedicated server hosting, which allows users to take advantage of the latest cloud technology backed by redundant systems. [Many clients prefer VPS for hosting](https://www.atlantic.net/vps-hosting/what-can-you-do-with-a-vps-and-cloud-server/) to a physical machine because they get the same full root access and administrative server control as they would with a dedicated machine without incurring the costs associated with running a dedicated environment. What sets VPS hosting in the cloud apart from old-fashioned VPSes is speed, agility, reliability, and affordability. All of these benefits are a result of virtually managing numerous physical servers that work together to process, store, and transfer client data. ### What is the difference between a Cloud Server and a Dedicated Server? A Cloud Server is a virtual server hosted on a shared platform with guaranteed system resources (CPU, Disk, and Memory). A dedicated host is a physical host dedicated to a single user, and the user has all the resources on the server. The Atlantic.Net cloud service offers both cloud and dedicated hosts within the same environment, so you get all the perks on either platform. The workload of a cloud server varies from running websites, workstations, or general-purpose servers. A dedicated host is usually used for hosting a significant number of websites or intensive workloads, such as a production database server. The choice on offer is paramount to our customer's satisfaction. All cloud servers will be available in a matter of seconds after being deployed, but if you want a dedicated host, then we need to do a little extra work behind the scenes. [Contact the Atlantic.Net team](https://www.atlantic.net/about-us/corporate-contact/) to find out more about our Dedicated Hosts. ### What is the difference between Atlantic.Net's Cloud VPS and a traditional VPS? Cloud VPS hosting is usually much more affordable and cost-effective than traditional dedicated hosting, as system administrators can control costs until your company grows into needing a more advanced Dedicated Host environment. Traditional VPS is offered as a contracted service with fixed features (CPU, RAM, and Hard Drive). With most VPS offerings, the resources you pay for are not guaranteed and are often oversold. Our Cloud VPS allows you to pay for only what you use and easily scale RAM, CPU, and Storage with a simple click or API call. We guarantee access to the defined system resources that you are paying for when you need them, but you can also burst to use additional resources when we have spare capacity available. ### How easy is it to use a cloud server? If you know how to use a server in your day-to-day business operations, then you will know how to use a cloud server. The only major difference that the Virtual Machine is cloud-based. Many of our customers choose Windows Server as their operating system of choice; most do this as it provides a user-friendly and familiar platform that is compatible with all the popular Microsoft products and every mainstream application. Our more experienced customers may choose to opt for a Linux platform, Linux can certainly be a more difficult platform to grasp; however, you only need to know the basics to get ahead, and the benefits that Linux offers are absolutely worth the extra effort. With Linux, you do not pay extra for licensing your operating system, and the overwhelming majority of applications are free (open-source) on all Linux Distributions. Deploying a cloud server using the [Atlantic.Net cloud management platform](https://cloud.atlantic.net/?page=userlogin) is an intuitive, extremely user-friendly process to follow. The clean design and clearly labeled sections present you with the tools and options you need. Point, click, deploy - it's that easy! ### Why should I choose cloud hosting? Cloud hosting is best defined as an intermediary hosting solution that offers the affordability of shared hosting with the power and performance of dedicated hosting. To recap, shared hosting is when your server shares unreserved resources on a host. Dedicated hosting is exactly the opposite; your server has 100% access to all resources on the host. Cloud hosting strikes a great balance between the two, as you get the benefits of having guaranteed resources on a host despite sharing with other clients. If you buy 2 vCPU, you get 2 vCPU to use exclusively. If you buy 64GB Ram, no other server can use that but you. The resources are always there, no matter what. A server also offers the cost benefits of shared hosting, as VPS hosting is only a small percentage more expensive than shared hosting but is significantly cheaper than dedicated hosting. ### Where is the Atlantic.Net Cloud Hosting available? Our cloud platform is available in eight global data center locations. United States: Orlando, New York, Dallas, San Francisco, Ashburn. Canada: Toronto. Europe: London, Amsterdam [coming soon]. Asia: Singapore. ### Can I scale up my Cloud Server? Yes, you can scale up your Cloud Server to a larger configuration anytime you wish. If you would like to scale up your server, please do so from the control panel by selecting "Reprovision." To ensure your data remains persistent, you can utilize the Atlantic.Net snapshot service to migrate your data, or you can restore using the Backup Service. A scale down option is not currently available. ### Do you provide console access, and if so, why might I need it? Yes, we provide console access to all of our Linux and Windows Cloud Servers using a VNC client/server configuration. This is an extremely useful feature if you are troubleshooting or accidentally block yourself via firewall rules from accessing your box via SSH (Linux) or terminal services (Windows). Once connected, simply log on with your credentials and you will have full control of the server to resolve any server-side issue. Need any extra help? Get in touch with us. ### Can I purchase additional IPs? Yes, they are $0.005431 per hour per IP address ($3.65/month). You can acquire and manage additional IP addresses via the Atlantic.Net Cloud Server control panel. ### Do you offer private IPs? Yes, private IPs are available. If your Cloud Server does not have a dedicated private IP address assigned and you would like one, [please contact support](https://www.atlantic.net/about-us/corporate-contact/). ### Do you offer Data Backup? Yes, Optional Daily Server Backup is available and can be enabled via the Atlantic.Net Cloud Control Panel for 20% of the server's price. There are two ways you can enable the backup: When building a new server, click the checkbox at the bottom of the page to enable backups. Navigate to Servers > Add Server > Locate the checkbox at bottom of the form: To add a backup to an existing server, navigate to your cloud server and select the server you want to back up. Locate "Backup Status" and click the status link "Disabled" and amend to "Enabled". This includes the ability to restore your server from a given backup via the Atlantic.Net Cloud Server Control Panel. ### I have a suggestion, to whom do I send it? If you have recommendations on how we can improve our Cloud Server experience, please let us know by emailing [feedback@atlantic.net](mailto:feedback@atlantic.net). ## Billing ### How am I billed? You will be billed monthly on the anniversary of the date you registered for the [Atlantic.Net](https://www.atlantic.net/) Cloud. You will only be billed for the cloud services you deploy and the data transfer used in the previous month. Note: New or unverified users that have exceeded a predetermined usage threshold may be charged for that usage each time the threshold is reached. Once the user has a reliable payment history, we'll remove this threshold automatically. For a detailed billing section on the Cloud Control Panel Navigate to Account Info > Payment and Billings. Here you can update your payment information and view your entire billing history and activity. You can also create billing alerts for added peace of mind. [Please refer to our cloud server pricing section for details.](https://www.atlantic.net/vps-hosting/pricing/) ### How is data transfer billed? In-bound (ingress) data transfer is free. If the free amount of outbound data transfer included in your plan is exceeded, you pay for the additional outbound data transfer you use during a billing cycle. [Please refer to our cloud server pricing section for details](https://www.atlantic.net/vps-hosting/pricing/). Unlimited inbound bandwidth. If free outbound bandwidth is exceeded, each additional GB is $0.02 ### Why do Windows servers cost more than Linux servers? All of the Linux Distributions we feature on the Atlantic.Net cloud have zero licensing costs to provision. Linux fosters an open-source community, and you will find an abundance of enterprise-grade applications available online that are completely free to use. Microsoft charges a license fee for each Windows Server instance. We pay Microsoft on your behalf, and the amount you are billed each month includes the licensing fee. We provide the following versions of Microsoft Windows Server: 2008 R2 SP1 Datacenter, 2012 R2 Datacenter (Desktop Experience and Server Core Editions), 2016 Datacenter Edition (Desktop Experience, Server Core and Containers Editions), 2019 Datacenter (Desktop Experience and Server Core Editions). ### How will I be billed for my use of Atlantic.Net Cloud Services? Atlantic.Net offers a clear breakdown of billing costs prior to deploying a server. The cost of each cloud plan is available right before you click deploy. We offer three types of payment terms: A pay-as-you-go pricing model. One year commitment discounted rate. Three-year commitment discounted rate. The pay-as-you-go pricing model comes with no minimum fee; you can spin up a server for 5 hours or 5 months and you will only be charged what you use. You pay for the services you need for as long as you want to use them, and there is no need for long-term contracts or complex licensing agreements. Cloud Services are billed on an hourly basis up to the monthly cap rate. The hourly rate is determined by dividing the monthly rate by 672 hours (28 days). If you use a service for more than 672 hours in a month, you will only be billed for the monthly rate (672 hours). Visit our [VPS Pricing page](https://www.atlantic.net/vps-hosting/pricing/) to compare plans and discover the great discount rates for committed usage terms. ### If I power my Cloud Server off, will I still be charged for it? Yes, we bill for your cloud server from the time you create it until you delete it. If you stop your server, we still have to reserve CPU, memory, and storage resources even though the server is not running. ### Can I take advantage of multiple promotional offers and stack the promotional credits for free service? Promotional credits are non-refundable with no cash value, and cannot be combined with other promotional credit offers. ## Support ### What level of support can I expect? Atlantic.Net is available to assist you 24/7/365 via phone and email. We have a team of experts dedicated to our Cloud Platform that can help with any Cloud Server query. We actively monitor and maintain the data center, network, and all the hardware that powers your cloud servers. You have full control to manage your cloud servers, including the operating system, server applications, and code. Need assistance beyond Atlantic.Net's covered support items listed below? No problem! We offer hourly support, [just call us to discuss your needs](https://www.atlantic.net/about-us/corporate-contact/). Atlantic.Net Fully Supports: Data Center, Network Server, Cloud Platform Hardware. You Are Responsible For: Your Application Code and Content, Applications, Operation System, Security Patches, Custom Applications. Need help with Billing? email [cbilling@atlantic.net](mailto:cbilling@atlantic.net) ### How safe is my data? The integrity of our customer's data is something we take very seriously. We have architected highly redundant Cloud Platforms that are designed to protect your data in the event of any technical issues. All data is stored on a highly redundant infrastructure that is backed up on a daily basis. ### What operating system distributions do you offer? Currently we offer those Operating Systems listed below and have many more planned. Linux/UNIX: Ubuntu 16.04 LTS Server 32-Bit, Ubuntu 16.04 LTS Server 64-Bit, Ubuntu 18.04 LTS Server 64-Bit, Ubuntu 20.04 LTS Server 64-Bit, Ubuntu 22.04 LTS Server 64-Bit, Ubuntu 24.04 LTS Server 64-bit, Ubuntu 26.04 LTS Server 64-Bit, Debian 11.11.0 Server 64-Bit, Debian 12.11.0 Server 64-bit, Debian 13.0.0 Server 64-bit, Oracle Linux 7.9 64-bit, Oracle Linux 8.10 64-bit, Oracle Linux 9.6 64-bit, Oracle Linux 10.0 64-bit, Rocky Linux 8.10 64-bit, Rocky Linux 9.6 64-bit, Rocky Linux 10.0 64-bit, CentOS 6.9 Server 32-Bit, CentOS 6.9 Server 64-Bit, CentOS 7.9 Server 64-bit, CentOS 8.2 Server 64-Bit, Fedora 42 Server 64-Bit, FreeBSD 13.0 Server 64-Bit, Arch Linux Server 64-Bit, AlmaLinux 8.10 64-bit, AlmaLinux 9.6 64-bit, AlmaLinux 10.0 64-bit, cPanel/WHM on AlmaLinux 64-bit. Windows Server: Windows Server 2025 Datacenter (Desktop Experience), Windows Server 2025 Datacenter, Windows Server 2022 Datacenter (Desktop Experience), Windows Server 2022 Datacenter, Windows Server 2019 Datacenter (Desktop Experience and Server Core Editions), Windows Server 2019 Datacenter (Desktop Experience), Windows Server 2019 Datacenter, Windows Server 2016 Datacenter Edition (Desktop Experience, Server Core and Containers Editions), Windows Server 2016 Datacenter (with Containers/Docker), Windows Server 2016 Datacenter, Windows Server 2012 R2 Datacenter (Desktop Experience and Server Core Editions), Windows Server 2012 R2 Datacenter (Desktop Experience), Windows Server 2012 R2 Datacenter, Windows Server 2008 R2 SP1 Datacenter. One Click Apps: LAMP on Ubuntu 24.04 LTS Server 64-Bit, LEMP on Ubuntu 24.04 LTS Server 64-Bit, WordPress on Ubuntu 24.04 LTS Server 64-Bit, Nextcloud on Ubuntu 24.04 LTS Server 64-Bit, Node.js on Ubuntu 24.04 LTS Server 64-Bit, Docker on Ubuntu 20.04 LTS Server 64-Bit, cPanel/WHM on CentOS 7.7 Server 64bit, MySQL on Ubuntu 18.04 LTS Server 64-Bit. ### What is the network throughput for a Cloud Server? The network throughput to each server varies depending on which cloud plan you select. The larger the Cloud Server chosen, the larger your Internet connection will be. Please refer to our Cloud Server pricing section for details. ### Why does my Processor display as QEMU when it is a genuine Intel Xeon Processor? Our Cloud utilizes a technology called QEMU, an extremely efficient platform that manages physical CPU sockets fantastically. This technology allows the Cloud Servers to achieve near-native performance by processing requests directly on the Cloud Host's Intel Xeon CPUs using host-passthrough technology. We use core isolation to guarantee your server the CPU performance you pay for. Thus, the processor(s) in your Cloud Server display as QEMU. ### How much CPU power do I have with my Cloud Server? Each Cloud Server has a pre-defined number of virtual CPUs. Each virtual CPU is allocated a number of CPU cycles based on the size of the cloud plan. The bigger the plan, the more CPU cycles you are allocated. It does not matter if you choose a small or large plan, the CPU cycles you pay for are guaranteed to your server. As an example: a 2048 MB Cloud Server has double the amount of CPU cycles of a 1024 MB Cloud Server, and a 4096 MB Cloud Server has double the amount of CPU cycles of a 2048 MB Cloud Server, and so on. Additionally, with Atlantic.Net's Cloud Servers, you can also burst to use additional CPU cycles when they are not in use. ### How many users reside on each Cloud node? The number of users on each Cloud node (the hardware that powers your Cloud Servers) varies depending on the type of Cloud Server each user purchases. Our proprietary Cloud technology intelligently allocates a cloud node (host) according to resource demands. The server load is balanced between every Cloud Node we own, and we do not oversell the resources of the Cloud node. This ensures the resources you are paying for are always available to you. ## API ### Where can I read more about the Atlantic.Net Cloud API? Our Cloud API is a RESTful Query interface designed to allow users to programmatically manage Atlantic.Net Cloud services. Calls are made over the Internet by sending HTTPS requests to the Atlantic.Net Cloud API Server. You can learn more about our [API Documentation](https://www.atlantic.net/docs/api/). ## Terms ### What is your Service Level Agreement (SLA)? Atlantic.Net Cloud Servers come with a [100% Uptime SLA](https://www.atlantic.net/cloud-service-level-agreement/) which includes the following: 100% Network Uptime SLA with Money Back Guarantee. 100% Hardware Replacement SLA with Money Back Guarantee. 100% Infrastructure Uptime SLA with Money Back Guarantee. ### What is the Network Uptime –100% SLA? Atlantic.Net guarantees the network will be available 100% of the time in a given month. If it takes us more than 30 minutes to resolve the network issue from the time the trouble ticket is opened, Atlantic.Net will credit 5% of the monthly usage fee for each additional 30 minutes of downtime (up to 100% of customer's monthly usage fee for the specific Cloud Server affected). Network uptime includes functioning of all network infrastructures such as routers, switches, and cabling, but does not include software and services running on your Cloud Server. Network downtime exists when your Cloud Server is unable to transmit and receive data and Atlantic.Net records such failure in the Atlantic.Net trouble ticket system. Network downtime is measured from the time a trouble ticket is opened. ### What is the Cloud Server Hardware – 100% SLA Atlantic.Net guarantees all hardware components that power your cloud server and will replace any failed components at no cost to you. Once Atlantic.Net determines the cause of the problem, hardware replacement begins. If it takes us more than one hour from the time the cause is identified to replace the faulty hardware, Atlantic.Net will credit 5% of the monthly usage fee per additional hour of downtime (up to 100% of your monthly usage fee for the specific Cloud Server affected). ### What is the Infrastructure – 100% SLA Atlantic.Net guarantees all critical infrastructure components, including power supplied to your Cloud Server and HVAC, will be available 100% of the time in a given month. If it takes us more than 30 minutes to resolve the infrastructure issue from the time the trouble ticket is opened, Atlantic.Net will credit 5% of the monthly usage fee per additional 30 minutes of downtime (up to 100% of your monthly usage fee for the specific Cloud Server affected). Critical infrastructure includes functioning of all power, HVAC, and cabling. Infrastructure downtime exists when your Cloud Server is shut down due to power or cooling issues and is measured from the time a trouble ticket is opened. ### What is Exempt from the SLA Guarantee? SLA credits will not be issued if the downtime has been caused by scheduled maintenance or if a cloud customer is in breach of any Atlantic.Net service agreements. Events of force majeure, including acts of war, god, earthquake, flood, embargo, riot, sabotage, labor disputes, government act, or failure of the Internet are exempt from the Service Level Guarantee. Downtime that resulted from modifications or changes of the operating system, database, application code, or other custom code not provided by Atlantic.Net will be exempt from the Service Level Guarantee. ## Referrals ### How does the referral program work? Customers have a unique referral code link assigned to their account. Anyone you refer to Atlantic.Net that completes the signup using the referral link will receive a $15 service credit instantly. In appreciation for you referring us new business, we will provide you with a $30 service credit automatically after the referred person bills (and pays) $30. Your unique referral code can be viewed in the Account section of the Atlantic.Net control panel by clicking on your email address > account > and scrolling down to the Referral section. ### Is there a limit on how many people I can refer? There is no limit on the amount of people you can refer. The more you refer, the more you can earn. ### When will I receive an account credit? When a customer you referred bills (and pays) $30 on their account, you will receive a $30 service credit on your next billing cycle. ### Can I promote my referral link using Google Adwords or other Advertising networks? No. You may not bid on branded keywords that include Atlantic.Net. ### Where can I download logos and badges to help promote my referral link? You can download logos, badges and banners of Atlantic.Net from our [Branding page](https://www.atlantic.net/press-room/logos/). ### Will my credit expire? Any unused credits will expire one year after the time they applied if not used. ## VAT ### What is EU VAT? EU VAT (European Union Value Added Tax) is a tax on consumer spending within the territory of a European Union (EU) Member State. VAT is not included in the prices displayed on Atlantic.Net's website. When applicable, VAT is charged and will be itemized on invoices and billing information. ### Who is charged EU VAT? Atlantic.Net is required to charge VAT on all sales to non-business European Union customers. The collected VAT is then paid to the appropriate EU country. EU based Customers can view their VAT charges by visiting their Account Page and reviewing their monthly invoices. However, if you are a registered business inside of the EU, you may enter your VAT ID by updating your Account information on the Account page. Once your VAT ID is verified, Atlantic.Net will not include a VAT charge on your future invoices. Please note that, registered businesses may still be required to manually account for this tax. ### Instructions on how to enter your VAT ID: Login to [cloud.atlantic.net](https://cloud.atlantic.net/?page=userlogin). Click your email address. Click "Account". Click "Update Account Information". Enter your VAT ID. ### What are the EU VAT rates for each member country? Below is a list of the VAT rates applicable to each EU member country as of January 1, 2016 that may be charged to EU customers. Austria 20%, Belgium 21%, Bulgaria 20%, Croatia 25%, Cyprus 19%, Czech Republic 21%, Denmark 25%, Estonia 20%, Finland 24%, France 20%, Germany 19%, Greece 24%, Hungary 27%, Ireland 23%, Italy 22%, Latvia 21%, Lithuania 21%, Luxembourg 17%, Malta 18%, Netherlands 21%, Poland 23%, Portugal 23%, Romania 19%, Slovakia 20%, Slovenia 22%, Spain 21%, Sweden 25%, United Kingdom 20%. ## SBS ### What is Secure Block Storage (SBS)? Atlantic.Net's Secure Block Storage allows you to easily attach additional storage to your Atlantic.Net Cloud Servers. You can use SBS for your file, database, application, and backup storage needs. ### How can I add an SBS to a Cloud Server? You can attach a SBS to your Cloud Server through the Atlantic.Net Cloud Control Panel (https://cloud.atlantic.net/?page=userlogin) or by contacting our sales department. ### How redundant is SBS? Designed for 99.999% availability, SBS is automatically replicated multiple times across a redundant and highly available cluster of storage servers to protect your data from component failure. ### Can I move my SBS between servers in the same location? Yes, you can move your SBS between your servers in the same location. ### Can I move my SBS between servers in different locations? Not currently, but it is on our roadmap. ### Is there a limit on how many SBS volumes I can connect to my Cloud Server? You can connect up to eight volumes per Cloud Server ### Can a SBS be attached to more than one Cloud Server at the same time? No, SBS can only be attached to one server at a time. However, SBS can be used as the backing storage for a shared file system, like NFS, that multiple servers/clients can connect to. ### Will I be able to take on-demand snapshots of my SBS and restore my volume from them? No. However, we plan to offer this feature soon. ### If I pay for backups for my Cloud Server, does that include backups of my attached SBS? No. However, we plan to offer this feature soon. ### Can I add an SBS on the Add Server page when creating a new Cloud Server? No. However, we plan to offer this feature soon. ### You mentioned that you can scale Volumes with no downtime, but I noticed the asterisks there. Can you please explain? Currently, all of our Cloud Server operating systems, except Windows Server 2016, support live scaling of Block Storage Volumes. This means that for all other Cloud Server operating systems, you can resize your Volume while it is connected to your running server. For Windows Server 2016, you will either have to reboot your Cloud Server or detach and reattach the Volume to get your Cloud Server to recognize the additional space after resizing a volume. This is a limitation of Windows Server 2016. ### Is the storage that backs SBS hard disk (HDD) or solid state disk-based (SSD)? Both! Data stored on volumes are first written to NVMe SSDs and then transferred to HDDs. This allows customers to take advantage of the large storage capacities that HDDs provide while benefiting from the amazing speed that comes with NVMe SSDs. NVMe, if you are not familiar, stands for non-volatile memory express and is the successor to the SATA drive interface. It allows SSDs to transfer data directly over the server's PCIe bus instead of going over the much slower SATA interface. ### What are the specs of SBS? Volume Size: 50 GB - 16 TB per volume. Max volumes per server: 8. Max IOPS per volume: 500. Max throughput per volume: 500 MB/s. Max throughput per server: 1,750 MB/s. Burst up to 250 MB/s per TB. Note: 1 TB = 1,000 GB. ### Is SBS encrypted? Yes, every SBS is automatically encrypted at rest using LUKS encryption and is connected to your Cloud Server over an isolated storage network to provide a secure environment for customer data. ### Are volume or term discounts available for SBS? Yes, please contact sales for details. ### What is the minimum increment when scaling the capacity of SBS? The minimum scaling increment is 50 GB. ### How does SBS compare to a SAN? A SAN is typically defined as dedicated storage area network that provides direct access to block-level storage devices with a finite amount of capacity and performance. SBS offers block storage as well, with clear advantages over a SAN in that SBS provides easily scalable capacity, performance, and redundancy coupled with no management costs. ### How does SBS compare to a NAS? A NAS is typically defined as network attached storage that provides a shared file system, such as NFS, that multiple servers can connect to at the same time. In contrast, SBS is a block level device that can only be directly attached to one server at a time but provides more flexibility. For example, SBS can be used to provide additional storage capacity for a Cloud Server or can be used as the backing storage for a shared file system, like NFS, that multiple clients can connect to. ### Do you plan to offer SBS at additional locations? Yes, we plan to offer SBS at our other Cloud locations. Currently, SBS is available in our USA-EAST-1 (Orlando, FL) location. Details regarding the launch of SBS at additional locations will be released in the coming months. ### How does SBS compare to AWS EBS ST1? Atlantic.Net Cloud (ANC) SBS is a similar, but more flexible, feature-rich, and performant solution than AWS EBS ST1. AWS EBS ST1 has a minimum volume size of 500 GB, ANC SBS has a minimum size of 50 GB. ANC SBS has been benchmarked to show it is on average 2.7x faster than AWS EBS ST1 for a 2 TB volume size. Additionally, ANC SBS will soon release additional features that are not available with AWS EBS ST1 such as scheduled backups, and off-site replication. ### How does SBS compare to Azure's Managed Disks? Atlantic.Net Cloud (ANC) SBS is a similar, but more flexible, feature-rich, and performant solution than Azure Managed Disks. In addition to the cost of your volume, with Azure Managed Disks you are billed for the number of IOPS you perform on your Volume, with ANC SBS you are not billed for the IOPS you use, which greatly simplifies planning and billing. ANC SBS has been benchmarked to show it is on average 11x faster than Azure Managed Disks for a 2 TB volume size. Additionally, ANC SBS will soon release additional features that are not available with Azure Managed Disks such as off-site replication. ## Cloud Availability in Multiple Global Regions Deploy close to your users from eight international data centers worldwide, with new regions on the way. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # How to Install Wildfly Server on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-wildfly-server-on-arch-linux/ | Published: 2023-03-22 | Updated: 2024-06-04 | Author: Hitesh Jethva WildFly, formerly known as JBoss Application Server, is an open-source web application server used to build amazing applications. It is popular among users and developers worldwide who want to develop enterprise-grade Java applications. WildFly provides necessary features that reduce development time, manage resources more efficiently, and save money for users. In this tutorial, we will explain how to install Wildfly on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list if you have not done so already. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Java WildFly is a Java-based application server, so you will require Java to be installed on your server. You can install the latest version of Java using the following command. ``` pacman -S jre17-openjdk ``` Once installed, verify the Java installation using the following command. ``` java --version ``` You should see the Java version in the following output. ``` openjdk 17.0.6 2023-01-17 OpenJDK Runtime Environment (build 17.0.6+10) OpenJDK 64-Bit Server VM (build 17.0.6+10, mixed mode) ``` ## Step 3 – Download and Install Wildfly Before starting, it is a good idea to create a dedicated user and group to run the Wildfly application server. You can create a user and group with the following command. ``` groupadd -r wildfly useradd -r -g wildfly -d /opt/wildfly -s /sbin/nologin wildfly ``` Next, download the latest version of Wildfly using the following command. ``` wget https://github.com/wildfly/wildfly/releases/download/26.1.3.Final/wildfly-26.1.3.Final.zip ``` Once the download is completed, unzip the downloaded file with the following command. ``` pacman -S unzip unzip wildfly-26.1.3.Final.zip ``` Next, move the extracted directory to /opt with the following command. ``` mv wildfly-26.1.3.Final /opt/wildfly ``` Next, change the ownership of the Wildfly directory. ``` chown -RH wildfly: /opt/wildfly ``` ## Step 4 – Configure Wildfly First, create a configuration directory for Wildfly using the following command. ``` mkdir -p /etc/wildfly ``` Next, copy the Wildfly configuration file to the /etc/wildfly. ``` cp /opt/wildfly/docs/contrib/scripts/systemd/wildfly.conf /etc/wildfly/ ``` Next, edit the Wildfly configuration file. ``` nano /etc/wildfly/wildfly.conf ``` Change the file as shown below: ``` # The configuration you want to run WILDFLY_CONFIG=standalone.xml # The mode you want to run WILDFLY_MODE=standalone # The address to bind to WILDFLY_BIND=0.0.0.0 WILDFLY_CONSOLE_BIND=0.0.0.0 ``` Next, copy the launch.sh file to the bin directory. ``` cp /opt/wildfly/docs/contrib/scripts/systemd/launch.sh /opt/wildfly/bin/ ``` Next, edit the launch.sh file. ``` nano /opt/wildfly/bin/launch.sh ``` Find the following lines: ``` $WILDFLY_HOME/bin/domain.sh -c $2 -b $3 $WILDFLY_HOME/bin/standalone.sh -c $2 -b $3 ``` Replace them with the following lines: ``` $WILDFLY_HOME/bin/domain.sh -c $2 -b $3 -bmanagement $4 $WILDFLY_HOME/bin/standalone.sh -c $2 -b $3 -bmanagement $4 ``` Save and close the file when you are done. ## Step 5 – Configure Systemd Service File for Wildfly First, copy the Wildfly sample configuration file. ``` cp /opt/wildfly/docs/contrib/scripts/systemd/wildfly.service /etc/systemd/system/ ``` Next, edit the Wildfly service file and make some changes. ``` nano /etc/systemd/system/wildfly.service ``` Find the following line. ``` ExecStart=/opt/wildfly/bin/launch.sh $WILDFLY_MODE $WILDFLY_CONFIG $WILDFLY_BIND ``` Replace it with the following line. ``` ExecStart=/opt/wildfly/bin/launch.sh $WILDFLY_MODE $WILDFLY_CONFIG $WILDFLY_BIND $WILDFLY_CONSOLE_BIND ``` Save and close the file, then set the execution permission. ``` chmod +x /opt/wildfly/bin/*.sh ``` Next, reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the Wildfly service with the following command. ``` systemctl start wildfly systemctl enable wildfly ``` You can verify the Wildfly status using the following command. ``` systemctl status wildfly ``` You will get the following output. ``` ● wildfly.service - The WildFly Application Server Loaded: loaded (/etc/systemd/system/wildfly.service; disabled; preset: disabled) Active: active (running) since Mon 2023-02-06 13:42:44 UTC; 6s ago Main PID: 45915 (launch.sh) Tasks: 118 (limit: 4700) Memory: 254.2M CGroup: /system.slice/wildfly.service ├─45915 /bin/bash /opt/wildfly/bin/launch.sh standalone standalone.xml 0.0.0.0 ├─45918 /bin/sh /opt/wildfly/bin/standalone.sh -c standalone.xml -b 0.0.0.0 └─46106 java "-D[Standalone]" -server -Xms64m -Xmx512m -XX:MetaspaceSize=96M -XX:MaxMetaspaceSize=256m -Djava.net.preferIPv4Stac> Feb 06 13:42:44 archlinux systemd[1]: Started The WildFly Application Server. ``` ## Step 6 – Add Wildfly Admin User Next, you will need to add an administrator user to manage the Wildfly. You can add it with the following command. ``` /opt/wildfly/bin/add-user.sh ``` You will be asked to select the user types as shown below: ``` What type of user do you wish to add? a) Management User (mgmt-users.properties) b) Application User (application-users.properties) (a): ``` Type a for management user and press the Enter key. You will be asked to provide a username and password as shown below. ``` Enter the details of the new user to add. Using realm 'ManagementRealm' as discovered from the existing property files. Username : hjethva Password recommendations are listed below. To modify these restrictions edit the add-user.properties configuration file. - The password should be different from the username - The password should not be one of the following restricted values {root, admin, administrator} - The password should contain at least 8 characters, 1 alphabetic character(s), 1 digit(s), 1 non-alphanumeric symbol(s) Password : Re-enter Password : ``` Provide your username and password and press the Enter key. Answer all the questions to add a user. ``` What groups do you want this user to belong to? (Please enter a comma separated list, or leave blank for none)[ ]: About to add user 'hjethva' for realm 'ManagementRealm' Is this correct yes/no? yes Added user 'hjethva' to file '/opt/wildfly/standalone/configuration/mgmt-users.properties' Added user 'hjethva' to file '/opt/wildfly/domain/configuration/mgmt-users.properties' Added user 'hjethva' with groups to file '/opt/wildfly/standalone/configuration/mgmt-groups.properties' Added user 'hjethva' with groups to file '/opt/wildfly/domain/configuration/mgmt-groups.properties' Is this new user going to be used for one AS process to connect to another AS process? e.g. for a slave host controller connecting to the master or for a Remoting connection for server to server Jakarta Enterprise Beans calls. yes/no? yes ``` ## Step 7 – Access Wildfly Web Interface Now, open your web browser and type the URL **http://your-server-ip:8080** to access the Wildfly. You should see the following screen. ![Wildfly default screen](https://www.atlantic.net/wp-content/uploads/2023/02/p1-1024x506.png) You can also access the administration console using the URL **http://your-server-ip:9990/console.** You will be redirected to the Wildfly login screen. ![Wildfly login screen](https://www.atlantic.net/wp-content/uploads/2023/02/p2.png) Provide your username and password and click on the **Sign in** button. You should see the Wildfly administrative dashboard on the following screen. ![Wildfly admin dashboard](https://www.atlantic.net/wp-content/uploads/2023/02/p3-1024x508.png) ## Conclusion Congratulations! You have successfully installed the Wildfly application server on Arch Linux. You can now build and deploy Java applications using the Wildfly application server. You can test the Wildfly application server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Windows VPS Hosting with Full Administrator Control > URL: https://www.atlantic.net/vps-hosting/windows-vps-hosting/ | Updated: 2026-09-16 Deploy a Windows Server VPS in minutes with SSD storage, full Administrator access, licensed Windows Server editions, and the flexibility to add backups, snapshots, block storage, and public IPs. - Full Administrator Access - SSD Storage Standard - Windows Licensing Included - 100% Uptime SLA Deployment Speed: In Minutes Global Data Centers: 8 Locations ## VPS Windows Hosting Experience an ultra-fast Windows Server on the Atlantic.Net Cloud Platform. We provide VPS hosting services designed to meet and exceed your most demanding hosting needs. Every virtual private server is built on SSD storage as standard, hosted on premium cloud server hosts running cutting-edge hardware with low latency and high bandwidth IOPs. Our VPS hosting is attached to a network backbone that handles even the most intense workload with ease, ensuring your Windows VPS hosting experience is smooth and reliable. All Windows VPS solutions are available on our cloud infrastructure on-demand. A Windows VPS server can be deployed in just a few minutes, allowing for rapid deployment of critical business applications. All Windows Server VPS accounts have access to Atlantic.Net Cloud Resources and can be self-managed directly from the control panel. Backups, Snapshots, Elastic Block Storage, and public IPs can be added with ease, giving you complete control over your Windows virtual server. ## Why Dedicated Resources Matter With pre-allocated server resources, you benefit from dedicated resources such as CPU, RAM, and storage that are not shared with other users. This is a significant upgrade over shared hosting, where other users' activity can impact your server performance. A Windows virtual private server ensures consistent high performance, making it especially suitable for hosting Microsoft web applications, databases, and providing secure remote desktop access. Additionally, every server VPS includes built-in security features such as Windows Firewall and regular software updates from Microsoft. ## What Is Windows VPS Hosting? A Windows Virtual Private Server (VPS) is an easy, cost-effective, and scalable compute service in a multi-tenant environment. It enables users to take advantage of the latest cloud server technology backed by high-performing redundant systems. By choosing a Windows VPS server, you gain full Administrative access and server management capabilities. A Windows virtual server provides a user-friendly interface, similar to a personal computer desktop environment, simplifying management for those accustomed to Windows. These VPS servers are ideal for: - Hosting Windows-dependent workloads for a website. - Forex trading platforms requiring 24/7 uptime. - Web applications and databases. - Remote desktop environments for global teams. Virtual servers are essential for developing and deploying applications, especially for businesses relying on Microsoft technologies like the .NET Framework and SQL Server. ## Windows VPS Hosting Pricing and Plans Our VPS offerings feature affordable pricing with flexible plans starting as low as $15.00 per month for Windows environments (Linux plans start as low as $4 per month). Whether you need a small VPS plan for testing or a powerful Windows Server for a production environment, our costs are transparent. We guarantee no hidden fees or surprise charges. While free VPS options exist elsewhere, they often come with restrictions. Atlantic.Net provides a high-quality VPS Windows environment that balances cost and power. ## Windows VPS Hosting Pricing | | | | | | | | | | --- | --- | --- | --- | --- | --- | --- | --- | | General Purpose | G3.2GB | 2GB | 1 | 50GB | 3 TB | On-Demand: $10.0/mo $0.0149/hr; 1-Year: $9.0/mo $0.0134/hr; 3-Year: $8.0/mo $0.0119/hr | On-Demand: $16.5/mo $0.0246/hr; 1-Year: $15.5/mo $0.0231/hr; 3-Year: $15.5/mo $0.0231/hr | | General Purpose | G3.4GB | 4GB | 2 | 80GB | 5 TB | On-Demand: $20.0/mo $0.0298/hr; 1-Year: $18.0/mo $0.0268/hr; 3-Year: $17.0/mo $0.0253/hr | On-Demand: $33.0/mo $0.0491/hr; 1-Year: $31.0/mo $0.0461/hr; 3-Year: $30.0/mo $0.0446/hr | | General Purpose | G3.8GB | 8GB | 4 | 160GB | 6 TB | On-Demand: $40.0/mo $0.0595/hr; 1-Year: $37.0/mo $0.0551/hr; 3-Year: $34.0/mo $0.0506/hr | On-Demand: $66.0/mo $0.0982/hr; 1-Year: $63.0/mo $0.0938/hr; 3-Year: $59.5/mo $0.0885/hr | | General Purpose | G3.16GB | 16GB | 6 | 320GB | 7 TB | On-Demand: $80.0/mo $0.119/hr; 1-Year: $74.0/mo $0.1101/hr; 3-Year: $68.0/mo $0.1012/hr | On-Demand: $132.5/mo $0.1972/hr; 1-Year: $125.5/mo $0.1868/hr; 3-Year: $119.5/mo $0.1778/hr | | General Purpose | G3.32GB | 32GB | 8 | 640GB | 8 TB | On-Demand: $160.0/mo $0.2381/hr; 1-Year: $147.0/mo $0.2188/hr; 3-Year: $136.0/mo $0.2024/hr | On-Demand: $265.0/mo $0.3943/hr; 1-Year: $250.5/mo $0.3728/hr; 3-Year: $238.0/mo $0.3542/hr | | General Purpose | G3.48GB | 48GB | 12 | 960GB | 9 TB | On-Demand: $240.0/mo $0.3571/hr; 1-Year: $220.0/mo $0.3274/hr; 3-Year: $204.0/mo $0.3036/hr | On-Demand: $397.5/mo $0.5915/hr; 1-Year: $375.5/mo $0.5588/hr; 3-Year: $358.5/mo $0.5335/hr | | General Purpose | G3.64GB | 64GB | 16 | 1280GB | 10 TB | On-Demand: $320.0/mo $0.4762/hr; 1-Year: $294.0/mo $0.4375/hr; 3-Year: $272.0/mo $0.4048/hr | On-Demand: $529.5/mo $0.7879/hr; 1-Year: $500.5/mo $0.7448/hr; 3-Year: $477.0/mo $0.7098/hr | | General Purpose | G3.96GB | 96GB | 20 | 1920GB | 11 TB | On-Demand: $480.0/mo $0.7143/hr; 1-Year: $441.6/mo $0.6571/hr; 3-Year: $408.0/mo $0.6071/hr | On-Demand: $795.5/mo $1.1838/hr; 1-Year: $754.5/mo $1.1228/hr; 3-Year: $718.5/mo $1.0692/hr | | General Purpose | G3.128GB | 128GB | 24 | 2560GB | 12 TB | On-Demand: $640.0/mo $0.9524/hr; 1-Year: $589.0/mo $0.8765/hr; 3-Year: $544.0/mo $0.8095/hr | On-Demand: $1,059.0/mo $1.5759/hr; 1-Year: $1,003.0/mo $1.4926/hr; 3-Year: $953.0/mo $1.4182/hr | | General Purpose | G3.192GB | 192GB | 32 | 3840GB | 13 TB | On-Demand: $960.0/mo $1.4286/hr; 1-Year: $883.2/mo $1.3143/hr; 3-Year: $816.0/mo $1.2143/hr | On-Demand: $1,588.5/mo $2.3638/hr; 1-Year: $1,506.5/mo $2.2418/hr; 3-Year: $1,435.5/mo $2.1362/hr | | Storage Optimized | S2.16GB | 16GB | 2 | 500GB | 10 TB | On-Demand: $248.0/mo $0.369/hr; 1-Year: $161.0/mo $0.2396/hr; 3-Year: $105.0/mo $0.1563/hr | On-Demand: $317.5/mo $0.4725/hr; 1-Year: $221.5/mo $0.3296/hr; 3-Year: $160.0/mo $0.2381/hr | | Storage Optimized | S2.32GB | 32GB | 4 | 1TB | 10 TB | On-Demand: $425.0/mo $0.6324/hr; 1-Year: $276.0/mo $0.4107/hr; 3-Year: $180.0/mo $0.2679/hr | On-Demand: $557.0/mo $0.8289/hr; 1-Year: $392.5/mo $0.5841/hr; 3-Year: $286.5/mo $0.4263/hr | | Storage Optimized | S2.64GB | 64GB | 8 | 2TB | 10 TB | On-Demand: $778.0/mo $1.1577/hr; 1-Year: $506.0/mo $0.753/hr; 3-Year: $330.0/mo $0.4911/hr | On-Demand: $1,035.0/mo $1.5402/hr; 1-Year: $734.5/mo $1.093/hr; 3-Year: $540.5/mo $0.8043/hr | | Storage Optimized | S2.96GB | 96GB | 12 | 3TB | 10 TB | On-Demand: $1,097.0/mo $1.6324/hr; 1-Year: $713.0/mo $1.061/hr; 3-Year: $465.0/mo $0.692/hr | On-Demand: $1,475.0/mo $2.1949/hr; 1-Year: $1,051.5/mo $1.5647/hr; 3-Year: $777.5/mo $1.157/hr | | Storage Optimized | S2.128GB | 128GB | 16 | 4TB | 10 TB | On-Demand: $1,414.0/mo $2.1042/hr; 1-Year: $919.0/mo $1.3676/hr; 3-Year: $599.0/mo $0.8914/hr | On-Demand: $1,913.0/mo $2.8467/hr; 1-Year: $1,367.0/mo $2.0342/hr; 3-Year: $1,013.5/mo $1.5082/hr | | Memory Optimized | M2.16GB | 16GB | 2 | 40GB | 10 TB | On-Demand: $163.0/mo $0.2426/hr; 1-Year: $106.0/mo $0.1577/hr; 3-Year: $52.0/mo $0.0774/hr | On-Demand: $223.5/mo $0.3326/hr; 1-Year: $161.0/mo $0.2396/hr; 3-Year: $101.5/mo $0.151/hr | | Memory Optimized | M2.32GB | 32GB | 4 | 80GB | 10 TB | On-Demand: $318.0/mo $0.4732/hr; 1-Year: $207.0/mo $0.308/hr; 3-Year: $101.0/mo $0.1503/hr | On-Demand: $439.0/mo $0.6533/hr; 1-Year: $316.5/mo $0.471/hr; 3-Year: $200.0/mo $0.2976/hr | | Memory Optimized | M2.64GB | 64GB | 8 | 160GB | 10 TB | On-Demand: $630.0/mo $0.9375/hr; 1-Year: $409.0/mo $0.6086/hr; 3-Year: $200.0/mo $0.2976/hr | On-Demand: $871.5/mo $1.2969/hr; 1-Year: $627.5/mo $0.9338/hr; 3-Year: $397.5/mo $0.5915/hr | | Memory Optimized | M2.128GB | 128GB | 16 | 350GB | 10 TB | On-Demand: $1,246.0/mo $1.8542/hr; 1-Year: $810.0/mo $1.2054/hr; 3-Year: $396.0/mo $0.5893/hr | On-Demand: $1,727.5/mo $2.5707/hr; 1-Year: $1,246.5/mo $1.8549/hr; 3-Year: $790.0/mo $1.1756/hr | | Compute Optimized | C2.8GB | 8GB | 4 | 40GB | 10 TB | On-Demand: $211.0/mo $0.314/hr; 1-Year: $137.0/mo $0.2039/hr; 3-Year: $67.0/mo $0.0997/hr | On-Demand: $254.5/mo $0.3787/hr; 1-Year: $173.0/mo $0.2574/hr; 3-Year: $96.0/mo $0.1429/hr | | Compute Optimized | C2.16GB | 16GB | 8 | 80GB | 10 TB | On-Demand: $418.0/mo $0.622/hr; 1-Year: $271.0/mo $0.4033/hr; 3-Year: $133.0/mo $0.1979/hr | On-Demand: $505.5/mo $0.7522/hr; 1-Year: $343.0/mo $0.5104/hr; 3-Year: $190.5/mo $0.2835/hr | | Compute Optimized | C2.32GB | 32GB | 16 | 160GB | 10 TB | On-Demand: $828.0/mo $1.2321/hr; 1-Year: $538.0/mo $0.8006/hr; 3-Year: $263.0/mo $0.3914/hr | On-Demand: $1,002.0/mo $1.4911/hr; 1-Year: $682.0/mo $1.0149/hr; 3-Year: $378.0/mo $0.5625/hr | | Compute Optimized | C2.64GB | 64GB | 20 | 350GB | 10 TB | On-Demand: $1,451.0/mo $2.1592/hr; 1-Year: $943.0/mo $1.4033/hr; 3-Year: $461.0/mo $0.686/hr | On-Demand: $1,777.5/mo $2.6451/hr; 1-Year: $1,216.5/mo $1.8103/hr; 3-Year: $685.0/mo $1.0194/hr | *All plans are available in every location for Managed Server clients. *The hourly rate is determined by dividing the monthly rate by 672 hours (28 days). If your server is online for more than 672 hours in a calendar month, you will only be billed the monthly rate. *Prices listed above are based on the service being utilized for the period specified. *All Servers include one IPv4 Address. Additional IPs are available for $3.65/month ($0.005431/hour) *Unlimited inbound bandwidth. If free outbound bandwidth is exceeded, each additional GB is $0.02 *Optional Daily Backups are available for 20% of the server price. Minimum $1.00/month. *cPanel licensing cost starts at $23 per month ## Supported Operating Systems The choice of operating systems depends entirely on your use case. Our latest Windows virtual servers run on Windows Server 2025. In addition to the Windows operating system, we offer various Linux distributions such as Debian and Ubuntu. This variety makes our platform ideal for those who need a Linux VPS alongside their Windows environment for integrated management of different technologies. ## Global Data Centers Our VPS Windows services are available in multiple data centers globally to ensure low latency: ## USA Locations New York, San Francisco, Dallas, Ashburn, and Orlando. ## International Locations Toronto (Canada), Singapore, and London (UK). ## Dedicated Server and Private Hosting For large enterprises that require even more power, we offer a dedicated server environment. These dedicated hosts can be deployed directly from our platform. Unlike a standard virtual server, a dedicated server is a private computing node fully dedicated to a single customer. ## Dedicated Host Highlights ### Dedicated Environment Absolutely no shared VPS resources or "noisy neighbors." ### Specific Server Configuration Customize your hardware and software to meet unique requirements. ### Security & Compliance Launch your Windows Server in a secure environment that is HIPAA-compliant. ### On-Demand Scaling Add or remove dedicated server resources in just minutes. ## Advanced Management and Access ### Administrative Access and Complete Control Our Windows VPS hosting provides full administrative (root) access. This allows you to install any software, modify the Windows operating system settings, and manage your databases without restrictions. Admin access is essential for the everyday management of VPS servers. ### Remote Desktop Protocol (RDP) Every Windows Server VPS supports Remote Desktop Protocol. This allows you to log into your server from any personal computer, providing a familiar GUI for server management. Whether you are managing multiple websites or running complex web applications, remote desktop makes the process intuitive. ## Backup and Data Integrity Protecting your data is a top priority. We offer automated backups and recovery services. You can configure your VPS plan to include daily backups, ensuring that your website and databases are always secure. Our cloud infrastructure allows for rapid deployment of snapshots if you need to restore your server to a previous state. When protecting data in transit, we support the latest encryption standards, including TLS 1.2 and 1.3. ## Networking and Connectivity Our VPS hosting services include unmetered bandwidth options and unlimited traffic on specific paths to ensure your web hosting remains fast and accessible. ### IPv4 and IPv6 Every Windows VPS includes a dedicated IPv4 address, with 16 IPv6 addresses available at no extra cost in all Atlantic.Net Cloud locations. ### High Performance Our network handles demanding VPS resource needs, ensuring your users have a lag-free experience. ## Exceptional Customer Support We have provided technical support for over 32 years. Our USA-based support team is available 24/7/365 via phone or email at no extra cost. Whether you have a question about your VPS plan or need help with a specific server configuration, our customer support is always ready to assist. ## Why Choose Atlantic.Net? With over 32 years of experience, we provide a balance of high-end performance and human-centric support. Our USA-based team is available 24/7/365 via phone or email at no extra cost. Whether you are a developer deploying a .NET app or an enterprise seeking a compliant dedicated environment, we can customize a solution for you. ## Windows VPS Hosting Solutions Available in All Eight Global Data Center Locations - United States Data Centers: Orlando, New York, Dallas, San Francisco, Ashburn - Canada Data Center: Toronto - United Kingdom Data Center: London - Europe Data Center: Amsterdam (coming soon) - Asia Data Center: Singapore ## Cloud Availability in Multiple Global Regions Deploy close to your users from eight international data centers worldwide, with new regions on the way. Atlantic.Net can help you achieve your goals with state-of-the-art virtual private server hosting technology. We are happy to provide a Windows VPS server hosting solution customised to meet your organisation’s needs, just ask. Speak with one of our specialists at [866-618-3282](tel:+18666183282) about getting Windows VPS hosting today. ## Windows VPS Hosting FAQ ### Can I scale my Windows VPS? Yes, you can scale up your VPS resources anytime. From the control panel, select “Reprovision” to upgrade your CPU, RAM, and storage. This ensures your hosting grows with your business. ### Why does a Windows Server cost more than a Linux VPS? A Linux VPS utilizes open-source operating systems like Ubuntu or Debian, which have no licensing fees. Microsoft charges a fee for the Windows operating system, which is included in the price of your Windows VPS hosting. ### How quickly can I start? You can have your Windows VPS running in just a few minutes. Our rapid deployment system automates the setup, so you can install your software and launch your website almost immediately. ### Do you offer support for large enterprises? Yes, our dedicated server and dedicated environment options are specifically designed for large enterprises with high-security hosting needs. ## Read More About VPS Hosting ### [VPS Hosting](https://www.atlantic.net/vps-hosting/) - [VPS Hosting](https://www.atlantic.net/vps-hosting/) - [VPS Pricing](https://www.atlantic.net/vps-hosting/pricing/) - [Linux VPS Hosting](https://www.atlantic.net/vps-hosting/linux-vps-hosting/) - [What Is Web Server Hosting?](https://www.atlantic.net/dedicated-server-hosting/what-is-web-server-hosting/) - [WordPress VPS Hosting](https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/) ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." --- # How to Install Apache Solr on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-solr-on-arch-linux/ | Published: 2023-03-23 | Updated: 2023-11-16 | Author: Hitesh Jethva Apache Solr is a popular open-source search platform built on Apache Lucene. It is written in Java and used to build search applications. Solr provides distributed indexing, replication, and load-balanced querying to achieve data querying in near real-time. It offers very useful features, including full-text search capability, easy monitoring, real-time indexing, optimized for high-volume traffic, and more. This post will show you how to install Apache Solr on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Java JDK First, you will need to install Java on your server. You can install it using the following command. ``` pacman -S jre17-openjdk ``` Once installed, you can verify the Java version with the following command. ``` java --version ``` You will get the following output. ``` openjdk 17.0.6 2023-01-17 OpenJDK Runtime Environment (build 17.0.6+10) OpenJDK 64-Bit Server VM (build 17.0.6+10, mixed mode) ``` ## Step 3 – Install Apache Solr Apache Solr is available in the Arch Linux default repository. You can install it using the following command. ``` pacman -S solr ``` After the installation, start and enable the Apache Solr service using the following command. ``` systemctl start solr systemctl enable solr ``` You can also check the Apache Solr status with the following command. ``` systemctl status solr ``` You will see the following output. ``` ● solr.service - Solr full text search engine Loaded: loaded (/usr/lib/systemd/system/solr.service; disabled; preset: disabled) Active: active (running) since Mon 2023-02-06 13:22:26 UTC; 2min 22s ago Main PID: 60050 (java) Tasks: 40 (limit: 2362) Memory: 637.6M CGroup: /system.slice/solr.service └─60050 java -server -Xms512m -Xmx512m -XX:+UseG1GC -XX:+PerfDisableSharedMem -XX:+ParallelRefProcEnabled -XX:MaxGCPauseMillis=2> Feb 06 13:22:34 archlinux solr[60050]: 2023-02-06 13:22:34.532 WARN (main) [] o.a.s.c.CoreContainer Not all security plugins configured! au> Feb 06 13:22:35 archlinux solr[60050]: 2023-02-06 13:22:35.040 INFO (main) [] o.a.s.c.CorePropertiesLocator Found 0 core definitions underne> Feb 06 13:22:35 archlinux solr[60050]: 2023-02-06 13:22:35.243 INFO (main) [] o.e.j.s.h.ContextHandler Started o.e.j.w.WebAppContext@33a053d> Feb 06 13:22:35 archlinux solr[60050]: 2023-02-06 13:22:35.274 INFO (main) [] o.e.j.s.RequestLogWriter Opened /var/log/solr/2023_02_06.reque> Feb 06 13:22:35 archlinux solr[60050]: 2023-02-06 13:22:35.289 INFO (main) [] o.e.j.s.AbstractConnector Started ServerConnector@aa22f1c{HTTP> Feb 06 13:22:35 archlinux solr[60050]: 2023-02-06 13:22:35.290 INFO (main) [] o.e.j.s.Server Started @7940ms Feb 06 13:24:14 archlinux solr[60050]: 2023-02-06 13:24:14.606 INFO (qtp2085886997-19) [] o.a.s.c.TransientSolrCoreCacheDefault Allocating t> Feb 06 13:24:14 archlinux solr[60050]: 2023-02-06 13:24:14.638 INFO (qtp2085886997-19) [] o.a.s.s.HttpSolrCall [admin] webapp=null path=/adm> Feb 06 13:24:14 archlinux solr[60050]: 2023-02-06 13:24:14.688 INFO (qtp2085886997-18) [] o.a.s.s.HttpSolrCall [admin] webapp=null path=/adm> Feb 06 13:24:15 archlinux solr[60050]: 2023-02-06 13:24:15.982 INFO (qtp2085886997-19) [] o.a.s.s.HttpSolrCall [admin] webapp=null path=/adm> lines 1-19/19 (END) ``` By default, Apache Solr listens on port 8993. You can verify it using the following command. ``` ss -altnp | grep 8983 ``` You will get the following output. ``` LISTEN 0 0 [::ffff:127.0.0.1]:8983 *:* users:(("java",pid=60050,fd=138)) ``` ## Step 4 – Configure Nginx as a Reverse Proxy for Apache Solr First, install the Nginx web server package using the following command. ``` pacman -S nginx ``` Next, start and enable the Nginx service with the following command. ``` systemctl start nginx systemctl enable nginx ``` Next, create a directory for the Nginx configuration with the following command. ``` mkdir /etc/nginx/sites-enabled ``` Next, edit the Nginx main configuration file and define your directory. ``` nano /etc/nginx/nginx.conf ``` Add the following lines below the line http{: ``` include sites-enabled/*; server_names_hash_bucket_size 64; ``` Next, create an Nginx virtual host configuration file with the following command: ``` nano /etc/nginx/sites-enabled/solr.conf ``` Add the following lines. ``` Server { listen 80; server_name solr.example.com; location / { proxy_pass http://127.0.0.1:8983; } } ``` Save and close the file, then verify Nginx for any syntax configuration errors: ``` nginx -t ``` You will get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 5 – Access Apache Solr Now, open your web browser and access the Apache Solr web UI using the URL **http://solr.example.com.** You should see the Apache Solr web UI on the following screen. ![Solr dashboard](https://www.atlantic.net/wp-content/uploads/2023/02/p1-1-1024x511.png) ## Conclusion In this tutorial, we showed you how to install Apache Solr on Arch Linux. You can now start building your search application using the Apache Solr platform. You can test Apache Solr on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # What Is Cloud Hosting? > URL: https://www.atlantic.net/vps-hosting/what-is-cloud-hosting/ | Updated: 2026-09-16 Cloud hosting is a web hosting model in which applications and websites run on a network of virtual servers backed by pooled physical hardware, allowing on-demand scaling of CPU, RAM, and storage. It is also referred to as Infrastructure as a Service (IaaS). **On this page** 1. What Is Cloud Hosting? 2. The Benefits of Public Cloud Hosting 3. Who Uses Public Cloud? 4. Types of Cloud Hosting 5. Atlantic.Net Cloud Servers 6. The Benefits of Atlantic.Net’s Cloud 7. Cloud Computing with Atlantic.Net: Changing the Landscape of Hosting for the Better ## What Is Cloud Hosting? Cloud hosting is a type of web hosting that allows businesses to make applications and websites available on the internet using a network of virtual and physical servers. It's also known as infrastructure as a service (IaaS). With cloud hosting, a third-party provider manages the cloud infrastructure, security, and maintenance, while the client may be able to customize hardware and applications, and scale servers online. Cloud hosting offers several benefits, including: - Scalability and flexibility: The ability to increase capacity in real-time to meet demand surges - Redundancy and reliability: Cloud hosting solutions are supported by high-performance computing data centers with backup power supplies and cooling systems - CPU and memory: Each cloud server is allocated a set amount of CPU cores and RAM, which can be easily scaled up as needed - Storage: Cloud platforms enable storage with SSDs, which outperform traditional hard drives, offering faster read and write speeds - Cost savings: Cloud hosting can reduce equipment installation and maintenance costs - Support: Providers like Atlantic.Net offer comprehensive support to ensure your cloud hosting experience is seamless When choosing a cloud hosting provider, you should consider factors such as: - Scalability and flexibility - Pricing - Performance - Reliability - Security - Customer support ## The Benefits of Public Cloud Hosting Scalability in IT systems is the ability to quickly add large amounts of computing power on-demand, according to the needs of the IT system. A company that experiences a major increase in demand for resources can meet that demand using a RESTful API and rapidly adding virtual machines to scale the system. Organizations using a private cloud have resources reserved for them but with the trade-off of less scaling capacity. Here are some of the main benefits of hosting applications in a public cloud. Multi-Region Redundancy and Availability: Public cloud providers usually have several data centers across different countries and continents. Adding cloud servers in a different data center can improve performance without requiring a major financial investment. This ensures that systems remain operational in the event of a regional outage. It also allows organizations to take advantage of the physical infrastructure closest to their user base, which can reduce latency and avoid the costs of cross-region data transfers. Multi-Tenant Pricing Model: In a utility-based cloud computing model, all expenses are operating expenses, rather than capital expenses. Everything is billed according to use, with no up-front cost and no commitment. The broad sharing of resources between many organizations in a public cloud can produce economies of scale and reduce costs, while making technologies available that would be impractical for a company to deploy on its own. Data Security and Compliance: Public cloud hosting providers invest heavily in security measures to protect client data. These measures include encryption, access controls, and regular security audits. For organizations in regulated industries such as healthcare, finance, and government, public cloud providers often offer compliance with standards like HIPAA, PCI-DSS, and GDPR. By leveraging the security and compliance expertise of cloud providers, companies can ensure their data remains secure and meets regulatory requirements without the need for significant in-house resources. Rapid Deployment and Innovation: Cloud providers offer a range of pre-configured templates and services that allow organizations to launch new projects quickly. This enables companies to innovate faster, test new ideas, and bring products to market more swiftly than with traditional on-premises infrastructure. Access to advanced technologies such as AI, machine learning, and big data analytics, which are readily available in public clouds, can further accelerate innovation. ## Who Uses Public Cloud? Organizations that have different IT demands at different times, or in different regions, can benefit from public cloud’s scalability and cost efficiency. To maintain performance with dedicated resources would require purchasing as much capacity as would be needed during peak periods. Those with variable workloads can add capacity as needed, rather than attempting to project future requirements. Companies offering online stores and web services companies, software developers, and web hosts can gain efficient scalability, which in turn delivers tremendous performance and availability at the lowest possible cost. The organizations most likely to achieve the greatest benefit from Atlantic.Net’s Public Cloud, therefore, are often those with unpredictable or highly variable network traffic, those serving customers or end-users with data which is not regulated or particularly sensitive, as well as those looking to reduce capital expenses. ## Types of Cloud Hosting ### Public Cloud Public Cloud is typically configured by the user via a control panel and/or RESTful API. Cloud server instances can be created by you in seconds, easily scaled up, and deleted whenever you wish. You only pay for what you use with our cloud servers. We offer on-demand pricing, as well as discounted term pricing for those users who plan to deploy their resources for 12 months or longer. Additionally, we have created one-click install applications for the more commonly used server configurations, such as LAMP, LEMP, WordPress, Node.js, October CMS, cPanel/WHM, and more. Cloud servers may also be easily scaled as needed. This allows users to maintain and configure their set-up without having to request outside help each time minor changes or upgrades are needed. Public cloud can be easily configured for website hosting, WordPress hosting, eCommerce, email servers, Forex trading, file storage and sharing, cloud databases, file backups, test and development servers, remote desktop environments, and much more. ### Private Cloud Private Cloud, or private virtualization, provides you the same redundancies as our Public Cloud offerings, but with the added security of dedicated hardware. Our team will work with you to custom-design a private cloud computing environment that suits your company’s needs. With Private Cloud also comes the opportunity to install any supported operating system. With Private Cloud, you get redundant networking, power, and storage. We can also setup custom replication clusters to help reduce any downtime. With replication, each of your cloud servers are being synchronized on two different physical servers. If one of your physical cloud servers goes down, it will fail-over to the other machine. Private Cloud is a great fit for those managing especially sensitive data that cannot afford any downtime. ### Hybrid Cloud Hybrid Cloud gives you the best of both worlds. For your very sensitive data and critical workloads, you can deploy a custom Private Cloud environment. For development environments and less critical workloads, like customer-facing web sites, those can be easily deployed in our Public Cloud. This type of hybrid environment is especially useful when combined with container technologies like Docker. Your less-critical applications can be updated frequently and retain great global reliability across our global data centers, all while keeping your sensitive databases secluded in the private cloud. ### Managed Cloud is set up initially by our cloud technicians, and is released to you once the setup and basic configuration is completed. Managed cloud also offers configurations with Atlantic.Net’s firewall and intrusion detection system solutions for greater security. These important security measures are administered by Atlantic.Net technicians. This provides you with the peace of mind that additional security brings along with an optimally configured server environment. If a user needs a more complex configuration or does not have the technical resources or time to devote, managed cloud is typically a great fit. ## Atlantic.Net Cloud Servers Unlike traditional shared hosting, Atlantic.Net Cloud Hosting assigns dedicated resources to each cloud server, rather than many different users’ websites and applications competing for computing resources. Each cloud server receives a partitioned drive with storage space only accessible from within their own operating instance. Each cloud server is assigned a dedicated amount of RAM and CPU cores (threads). In addition to the resources you are paying for, your cloud server can also burst to use additional server resources during non-peak times. Cloud servers may be used for web hosting, application development, or remote-accessible desktop work environments, and much more. To understand this migration, first we need to look at the most common types of server hosting available. In addition to dedicated server hosting and compliant hosting offerings such as HIPAA hosting and PCI hosting, Atlantic.Net offers multiple types of cloud hosting: Public Cloud, Private Cloud, Hybrid Cloud, and Managed Cloud. ## The Benefits of Atlantic.Net’s Cloud ### Scaling and Flexibility Traditional VPS devices can’t resize the server on demand, or re-prioritize server resources dynamically. Atlantic.Net has the ability to increase the size of a cloud server instance on demand in seconds. Atlantic.Net Public Cloud offers you a pay-as-you-go pricing model with no minimum fee. You only pay for the services you need, for as long as you use them, without requiring long-term contracts or complex licensing agreements. Services are billed on an hourly basis up to the monthly cap rate. The hourly rate is determined by dividing the monthly rate by 672 hours (28 days). If you use a service for more than 672 hours in a month, you will only be billed for the monthly rate (672 hours). This allows the freedom and flexibility to spin up a server, use it as long as you need, delete the server, and only pay for the time you used. ### Performance: CPU Cycles The dedication of CPU cycles is an important part of a true Cloud infrastructure. With virtual private servers, the CPU cycles is often shared across users with no resource guarantees. This can cause conflicts in utilization as clients with a greater computational need may monopolize the CPU, slowing down all other users. Additionally, some hosts will overclock their CPUs so they can claim higher CPU cycles. Atlantic.Net provides dedicated CPU cycles, utilizes quality CPUs, does not overclock them The CPU speeds shown in a server are the minimum speed it will process at, not “under optimal conditions.” Atlantic.Net guarantees that each device gets a minimum of an Intel Xeon E5-2620, as we are constantly upgrading and expanding, it may be higher depending on which system your servers are provisioned on. Each system has a certain number of guaranteed threads, determined by the size and options associated with the selected Cloud Server plan. We not only guarantee access to the CPU cycles you are paying for when you need them, but you can also burst to use additional CPU cycles when they are not in use. ### Memory Some providers over-provision memory for use between multiple virtual machines. Atlantic.Net provides dedicated memory. This prevents resources from being tied up by another user on the server. Additionally, many VPS companies do not use Error-correcting code (ECC) RAM that can detect and correct the most common kinds of internal data corruption due to the increased hardware costs. At Atlantic.Net, our entire Cloud Hosting environment runs on ECC RAM to prioritize data accuracy and system stability. ### Storage Many Cloud or VPS servers still use traditional hard drives. The average hard drive speed is 7200 RPM, equating to about 80-160 MB/s. If you are writing many small files, this can slow down to as little as 0.7-1.3MB/s. At Atlantic.Net, all our Cloud Servers are powered by enterprise-grade solid state drives (SSDs), providing blazing fast performance for your servers and applications. SSDs provide read and write speeds of 4x – 5x the speeds of hard drives. Atlantic.Net installs the operating system directly on the SSD storage associated with your Cloud Server. A Linux based operating system install is around 5GB or less and a Windows operating system install is about 15GB or less. If you require a large amount of storage space for your server, please consider our Storage Optimized Cloud Servers. They put an emphasis on storage space rather than CPU and RAM, and will provide the most amount of storage per dollar. ### IPs On Demand Many VPS devices only allow one public IP per server. All Atlantic.Net Cloud Servers come with one static public IP address. However, you can also provision additional IPs on demand. This means that not only do you get an IP to yourself, it also allows you to attach multiple additional IPs to the server, for network routing or hosting multiple websites. Additionally, each Atlantic.Net cloud account is assigned a private IP range to allow local networks to be set up between multiple servers in the same datacenter. Some cloud hosting companies charge for private IPs, or for the traffic on these ranges. All Atlantic.Net private network traffic is provided without any cost to you. ### Location Some Cloud or VPS hosting only has one location to choose from. Atlantic.Net has multiple data centers in the United States, Canada, and Europe, with locations coming to Asia in the near future. For optimum personal or business use, different data centers can be chosen to reduce latency times, allow separated distribution, or increase redundancies. ### Redundancy Some providers utilize fully redundant infrastructure, others don’t. Atlantic.Net Cloud services are hosted in top-notch data centers. This means all our cloud and new deployments have redundant infrastructure components, dual-power feeds, generator backup, and multiple redundant network uplinks. We also have redundant HVAC systems and 24 hour in-person staffing at all our data centers. This provides a supremely fault-tolerant system, allowing us to provide a 100% network uptime SLA. At Atlantic.Net, our Cloud Servers are backed by RAID 10 storage protection, this is the best option currently available for I/O intensive applications and to prevent storage related downtime. Without the disk mirroring and disk striping of RAID 10, a drive failure could potentially cause downtime or data loss. Some providers do not utilize any type of storage redundancy in their Cloud, an unnecessary risk for your important data. Some providers only offer the option of weekly backups of your files, while Atlantic.Net offers daily backups of your entire Cloud Server. This provides you with the peace of mind that you can restore your important data if the need arises, such when files are accidentally deleted, you need to revert an update to your server or code, etc. Atlantic.Net’s daily backups are accessible for immediate restore through our cloud portal for your convenience. ### Support Atlantic.Net is available to assist you 24/7/365 via phone, email, and chat. We monitor and maintain the data center, network, and all the hardware that powers your Cloud Servers. We also provide a large amount of articles in our Community on commonly asked questions and technical walk-throughs. ## Cloud Computing with Atlantic.Net: Changing the Landscape of Hosting for the Better Cloud Hosting tends to be a cost-effective middle ground, allowing rapid customization and upgrade potential. Recently, small businesses have begun moving towards cloud hosting to meet their everyday needs. It allows small businesses to operate in an affordable environment, while still maintaining a dedicated resource pool. Atlantic.Net utilizes RAID-10 and other redundant architecture to prevent system downtime, and maintains a 100% uptime SLA. Any of our Cloud Hosting solutions may also include a firewall appliance and intrusion detection system (IDS) for greater security. At Atlantic.Net, our World-class cloud hosting platform provides you with the freedom to choose the plans that best fit your budget and business needs. Our plans are designed to provide maximum flexibility to business as well as developers. Please contact us via email at sales@atlantic.net or via phone at 866-618-3282 . Our team would be happy to guide you towards the solution that is ideal for your business needs. Newsletter Subscribe to our newsletter and stay updated. Ready to Deploy? Launch secure, compliant, enterprise-grade infrastructure with confidence. ## See Additional Guides on Key IaaS Topics Together with our content partners, we have authored in-depth guides on several other topics that can also be useful as you explore the world of IaaS. ### [Digital Asset Management](https://cloudinary.com/guides/digital-asset-management/digital-asset-management) Authored by Cloudinary - [[Guide] Digital Asset Management: Benefits & Best Practices (2025)](https://cloudinary.com/guides/digital-asset-management/digital-asset-management) - [[Guide] What is Metadata?](https://cloudinary.com/guides/digital-asset-management/what-is-metadata) - [[Blog] New for DAM: Media Library Extension for Chrome](https://cloudinary.com/blog/new_for_dam_media_library_extension_for_chrome) - [[Product] Cloudinary Assets | AI-Powered Digital Asset Management](https://cloudinary.com/products/digital_asset_management) ### [AWS Cost Optimization](https://www.finout.io/blog/aws-cost-optimization-6-free-tools-10-hacks-to-cut-aws-bills) Authored by Finout - [[Guide] Top 5 Free & Open Source AWS Cost Optimization Tools](https://www.finout.io/blog/free-and-open-source-aws-cost-monitoring-tools) - [[Guide] Top 10 AWS Cost Optimization Best Practices & Why You Need Them](https://www.finout.io/blog/aws-cost-optimization-best-practices) - [[Webinar] How To Create a Cost-Effective AWS Environment](https://www.finout.io/blog/how-to-create-a-cost-effective-aws-environment) - [[Product] Finout | Enterprise-Grade FinOps Platform](https://www.finout.io/) ### [FinOps](https://www.finout.io/blog/finops-guide) Authored by Finout - [[Guide] AWS FinOps: Why, How, and 6 Tools to Get You Started](https://www.finout.io/blog/aws-finops-why-how-and-6-tools-to-get-you-started) - [[Guide] Top 50 FinOps Tools to Consider in 2025](https://www.finout.io/blog/finops-tools-guide) - [[Webinar] Mastering Kubernetes Spend-Efficiency](https://www.finout.io/blog/mastering-kubernetes-spend-efficiency) - [[Product] Finout | Enterprise-Grade FinOps Platform](https://www.finout.io/) ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # What is PCI Hosting? > URL: https://www.atlantic.net/what-is-pci-hosting/ | Updated: 2026-09-16 PCI hosting is a hosting service offered by managed service providers whose data center, network, and operational practices are aligned with the Payment Card Industry Data Security Standard (PCI DSS). It gives merchants and service providers a foundation for processing, storing, and transmitting cardholder data within the controls expected by Visa, Mastercard, American Express, and the other card brands. ## Frequently Asked Questions ### What is PCI Hosting? Payment Card Industry [(PCI) hosting](https://www.atlantic.net/pci-compliant-hosting/) is a type of web hosting service using datacenter infrastructure provided by [managed service providers (MSPs)](https://www.atlantic.net/pci-compliant-hosting/) which is PCI-ready. In this case, PCI-ready means the MSP follows the rules and guidelines laid out by payment card providers to enforce the data security standards expected to secure clients' payment card data. These rules were designed to defend against the theft of debit and credit card numbers and merchant information, as well as prevent fraudulent transactions and credit card cloning in the retail sector. PCI data standards are recognised worldwide and thus, internationally, organizations that handle bankcard transactions online must use [PCI hosting providers who meet the strict requirements](http://www.theukcardsassociation.org.uk/security/What_is_PCI DSS.asp) of the payment card industry (or maintain PCI compliance on their own, if hosting internally). PCI hosting enables clients or merchants to apply for PCI Data Security Standard (DSS) compliance, which is essential for any business that accepts any type of payment card such as American Express, Visa, JCB, or MasterCard. [PCI compliance was introduced in 2004](https://www.vantiv.com/vantage-point/safer-payments/history-of-pci-data-security-standards) to provide a unified framework for improving security and reducing the threat of data breaches for all card providers. PCI-ready hosting providers can adhere to the security controls defined by the Security Standards Council (SSC); these standards create a set of rules which must be complied with in order to gain the [PCI compliance](https://www.atlantic.net/pci-compliant-hosting/) certification, and these rules apply to everyone who wishes to take card payments. There are 12 standards which make up the PCI Data Security Standard, and PCI ready hosting providers must meet these standards for the client to be able to apply and pass PCI DSS compliance certification. [These standards](https://www.pcisecuritystandards.org/document_library?category=pcidss&document=pci_dss) primarily focus on the securing of an infrastructure provider's physical network, employees and secure business processes. All data networks (physical and wireless) must be secured with firewalls, which are regularly maintained with software updates and have a valid access control management process. The firewalls are managed by a specialist network team, who manage and restrict traffic from untrusted networks. All vendor-supplied hardware default passwords are changed and then hardened with complex secure passwords and strong cryptography (SSL/TLS Certificates). The Managed Service Provider must do everything possible to protect cardholder data, working with clients to ensure [that only the data that is needed](https://www.atlantic.net/pci-compliant-hosting/reduce-pci-scope-accepting-payments/) is digitally stored, and that any data that is retained is masked and protected. PCI hosting providers will secure server hardware both physically and within the Operating System by ensuring the server infrastructure is protected from vulnerabilities. This includes regular patch management and anti-virus definition updates. Strong access control measures are implemented to restrict unnecessary physical access to data center operations. PCI hosting providers also restrict logon access to the server environment. This can be achieved via two-factor authentication and will add greater protection to the servers that host the payment card information. Limiting access to those on a need-to-know basis enables hosting providers greater auditing control. This is further enhanced by ensuring all users have unique IDS which are protected with complex, regularly changed passwords. PCI requirements only apply to the cardholder data environment (CDE); they do not apply to a client's entire infrastructure. Usually the CDE is an isolated network segment, [but this does mean that any data transmitted externally is encrypted](https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf). The MSP is responsible for documenting, updating and consistently monitoring and testing PCI ready processes to ensure the best practices requirements are followed and adhered to. This is done by implementing a PCI Hosting security policy and conducting regular vulnerability testing. ## Disclaimer: * This post is for informational purposes only and does not constitute professional, legal, financial, or technical advice. Each situation is unique and may require guidance from a qualified professional. Readers should conduct their own due diligence before making any decisions. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # What is Private Hosting? > URL: https://www.atlantic.net/what-is-private-hosting/ | Updated: 2026-09-16 Private hosting is an umbrella term for hosting arrangements in which infrastructure, databases, and servers are dedicated to a single organization rather than shared. The two most common forms are virtual private hosting (VPS) and private cloud hosting: both isolate the customer's compute and storage from other tenants. ## What is Private Hosting? Private Hosting is a hosting arrangement such that an organization’s infrastructure, databases, and servers all exist in an exclusive location inaccessible to anyone outside the company or the private hosting provider. This type of hosting is often used by large companies in need of enterprise-grade functionality. In the early days of the Internet, private hosting was done completely on-site for big companies. They would invest in servers housed in the organizations’ headquarters or a private data center. ## Virtual Private Hosting (VPS Hosting) In the 2000s, improvements in software and hardware capabilities -led to the development of the virtual private server (VPS). VPS technology allows software called a “hypervisor” to use the physical hardware of a server, such as memory, CPU and networking capabilities. Each virtual server acts like a normal operating system with its own applications, email software, Internet browsing capabilities, etc. Each user has his or her own unique user ID, password, and authentication code to sign on with. For an example of the benefits of VPS Hosting, consider a company with offices in different parts of the world. Say a chemical news bureau is headquartered in London but also has other offices in world energy hub cities such as Houston and Shanghai. Rather than redundantly set up the Texas and China offices with all of the same hardware and servers in London, a VPS hosting solution is established. A virtual server powered in the UK allows users in Houston and Shanghai to log on through a virtual server and see the exact same desktop and shared file servers as their colleagues in London. ## Positives of using Virtual Private Hosting ### Availability Virtual servers are spread across hundreds of computing nodes, but they only run on one node at a time. If a server on one node encounters an issue, it can be easily migrated to another node. While this alleviates downtime compared to a physical machine, it doesn't completely prevent it. This also simplifies load balancing and disaster recovery. ### Reduced Hardware Maintenance Computers that do a lot of ‘heavy lifting’ from running various apps and performing lots of high-level commands wind up needing a lot of maintenance to make sure they don’t suffer from any number of system decay issues. When using a VPS, the actual hardware is only doing one thing - logging on to the virtual server - taking up considerably less local memory and resources. ### Scalability While dedicated private hosting requires the purchase of additional hardware, adding a server or memory space can be done instantaneously with a VPS as long as there is space on the computer to configure additional virtual servers. ## Private Cloud Hosting Private Cloud Hosting, also known as a private cloud, is a situation in which a company’s private infrastructure, services, and databases are placed in a cloud computing environment that is inaccessible except for employees of the business and the hosting company. The actual servers hosting private clouds do not contain information or resources for any other organization, differentiating them from public cloud environments. Private Cloud Hosting has several advantages over both Virtual Private Hosting and Public Cloud Hosting. ## Positives of using Private Cloud Hosting ### Better Security Security in the cloud is a concern for many enterprises, so private cloud hosting companies tend to emphasize security in the service offering. Public clouds have lots and lots of entry points because of the high number of clients and users accessing the shared server space. Private clouds contain just one organization and often have to be custom-built to comply with specific industry standards. ### Quicker Response Times Every single function of the applications and infrastructure is the responsibility of the cloud-computing provider, not the enterprise itself. This means all IT challenges and solutions are managed by the experts doing the hosting. Because downtime costs the provider not only in money but also in reputation, cloud providers have round-the-clock service available to remedy any hiccup. ### Instant Updating When new versions of software become available, there’s no hands-on updating done by your IT department, nor is there the need for users to delay starting their workday as they watch a progress bar and spinning clock icon slowly install the latest version. All of this is done during non-business hours and with advance notice from the cloud-hosting provider. ## Conclusion Private hosting is essential for some enterprises seeking the ultimate in security safeguards and the ability to scale their server capabilities at will. While VPS hosting is a viable solution for many firms, private cloud hosting a powerful option for large organizations given its advances in security, functionality, and ease of upgrades. ## Disclaimer: * This post is for informational purposes only and does not constitute professional, legal, financial, or technical advice. Each situation is unique and may require guidance from a qualified professional. Readers should conduct their own due diligence before making any decisions. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # What Is a HIPAA Business Associate Agreement (BAA)? > URL: https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/ | Updated: 2026-09-16 A Business Associate Agreement (BAA) is the HIPAA-required contract between a Covered Entity (or upstream Business Associate) and any third party – such as a hosting provider – that creates, receives, stores, or transmits Protected Health Information (PHI) on its behalf. The BAA defines permitted uses, security requirements, breach-notification obligations, and the parties' respective liability for ePHI. ## What Is a BAA? The HIPAA Privacy Rule amendment in 2003 introduced a new administrative safeguard declaring that all covered entities must have a signed Business Associate Agreement (BAA) in place with all Business Associates (BA) and Covered Entities that manage, process or archive Protected Health Information (PHI). In order to both comply with the law and assure our clients that we’re committed to keeping their information safe, we’ve drafted up a HIPAA Business Associate Agreement, or BAA. BAAs are a type of HIPAA-Compliant documentation that is critical to our relationship with healthcare firms and medical practitioners alike, as it firmly establishes the legal parameters for our use of ePHI. The following three components are central to this contract: Business associate’s role – the exact nature of the third party’s interaction with the healthcare data, including any forms of use and disclosure. Limitations – the prohibition of the third party from any forms of use or disclosure not stated in the agreement. Security requirements – the necessity for extensive security technologies and protocols to guard against any unauthorized use or disclosure. In conjunction with our SOC 2 TYPE II and SOC 3 TYPE II certified data center, our BAA documentation shows that we’re committed to keeping the private healthcare information of our clients both safe and secure. Moreover, BAAs show that we’re willing to go beyond the minimum standards of compliance established in HIPAA. Healthcare organizations that choose us as a host have the peace of mind that can only come from knowing that they’re partnered with a veteran - and one that’s completely committed to their best interests, at that. For more information about our HIPAA Business Associate Agreement or to request a copy of our agreement, please contact us today! ## When Is a HIPAA BAA Required? A BAA is not necessarily a single standalone agreement; BAAs often include a combination of service level agreements, response times for incidents, and RTO and RPO guarantees for a disaster recovery solution. With HIPAA BAA, there are two types of business associate relationships: - BAA between a Covered Entity and a Business Associate - BAA between a Business Associate and a subcontractor ## What Is a Subcontractor in a BAA? Subcontractors are vendors and third parties that provide Atlantic.Net with services for our day-to-day business operations. Any vendor Atlantic.Net engages with as part of our HIPAA compliant business offerings will sign the BAA if offering in-scope services; this task is managed by Atlantic.Net. ## What Does a BAA Achieve? A HIPAA BAA creates a bond of liability, outlining the shared responsibilities of the Covered Entity and the Business Associate (in this case, Atlantic.Net). Atlantic.Net’s BAA offers assurances regarding our HIPAA and HITECH accreditations and details the guarantees we provide for each of the administrative, physical, and technical safeguards we implement to protect ePHI. ## What Guarantees Does Atlantic.Net’s BAA Offer? As a trusted business associate, Atlantic.Net can sign a business associate agreement to: - Adhere and uphold the requirements of HIPAA legislation, including the Security and Privacy rule amendments - Provide a HITECH compliant hosting environment - Not disclose PHI, except as permitted by law - Document the in-scope PHI to be transferred, processed and archived by Atlantic.Net on behalf of the CE - Demonstrate that proven protections are in place to prevent unlawful PHI disclosures, including technical solutions such as a VPN, TLS encryption, DR capability, and managed firewall capabilities. - Provide guaranteed escalation processes to manage any ePHI breach notifications - Upon request, Atlantic.Net must give the HHS access to the HIPAA policy documentation and detailed logging information of user activity - When the contract ceases, if feasible, ePHI must be returned to the Covered Entity or evidence must be provided to confirm the destruction of ePHI ### Do Business Associates Have to Comply with HIPAA? Absolutely yes. As one of the leading HIPAA compliant hosting companies in the United States, Atlantic.Net (and our healthcare partners utilizing our award-winning cloud platform) are directly impacted by a BAA. Atlantic.Net is a Business Associate of each healthcare organization with whom we process, store, manage or otherwise deal with PHI, and therefore, we are obliged to sign a contract of service with each organization to guarantee our HIPAA compliance status. ### Who Is Considered a Business Associate Under HIPAA? A Business Associate is someone that handles or processes Protected Health Information on behalf of the covered entity. According to the HHS.gov website: “Business associate functions and activities include claims processing or administration; data analysis, processing or administration; utilization review; quality assurance; billing; benefit management; practice management; and repricing. Business associate services are: legal; actuarial; accounting; consulting; data aggregation; management; administrative; accreditation; and financial” ### What Is an Example of a Business Associate of a HIPAA Covered Entity? Atlantic.Net is a business associate of our healthcare customers as our systems are used to store, manage and process protected health information. ### If I Share ePHI with Other Companies, Do I Need to Sign a Business Associate Agreement with Them? The quick answer is yes, but there are some exceptions. If Protected Health Information is shared it must be for a valid reason, and it can only be stored and processed as needed. Redacted PHI is different, if no personally identifiable information is used (such as name, address, social security number) then the information can be shared. ### As a Software Vendor, What Do I Need to Do to Become a HIPAA-Compliant Business Associate? The Business Associate (BA) governs the BA’s creation, use, maintenance, and disclosure of PHI. A typical software vendor has multiple external subcontractors and may also need to sign a BASA. ## More About BAAs: How the BAA Fits in – Basic HIPAA Elements & Definitions A brief review of HIPAA and its primary component parts allows us to place the business associate’s agreement in context. The vast majority of healthcare companies must abide by the parameters of the Health Insurance Portability and Accountability Act (HIPAA), an Act passed by the United States Congress in 1996 that safeguards American citizens’ health data. The data that falls under the auspices of the law – as governed by the Department of Health & Human Services (HHS) – is designated, collectively, as protected health information (PHI). PHI is typically handled by covered entities. Organizations in that category include healthcare providers, healthcare plans, and healthcare clearinghouses. Examples of each type of HIPAA-compliant organization are as follows: - providers – doctors, dentists, nursing homes, pharmacies, etc. - plans – health insurance companies, HMOs, Medicare, Medicaid, etc. - clearinghouses – transcription services, etc. Any of the above organizations necessarily handle PHI as a central responsibility of their business. The Privacy Rule and Security Rule of HIPAA require covered entities to protect patient data from loss, theft, or any other misuse. A covered entity can choose to work with a business associate, outsourcing certain aspects of operations to a trusted third party. In order to appropriately place responsibility into the hands of the external organization, both companies must agree to the terms of a BAA. By signing the agreement, the business associate agrees to safeguard PHI and to perform its obligations to the covered entity within the guidelines of HIPAA. ## Characteristics of a HIPAA BAA According to the HIPAA guidelines, a BAA must do the following: - Describe the specific ways in which PHI is being used (transferred, processed, and/or stored) by the business associate, along with any ways in which they are being contracted by the covered entity to disclose PHI; - Establish that the business associate cannot use or disclose any health data beyond the purposes established in the agreement, except in special cases when cooperating with law enforcement; - Dictate that the business associate must have strong, proven protections established that disallow any malicious or otherwise unlawful PHI disclosure, use, or access – one part of which is the electronic means stipulated by the HIPAA Security Rule (including VPN capability and SSL encryption within a firewall-secured private network); - Stipulate that the business associate must immediately notify the covered entity if PHI is used or disclosed in a manner that goes beyond the parameters established in the agreement, such as in the event of a data breach; - Direct the business associate that it must protect data but also make it readily available, so that individuals can get access to their medical records as established by the law and have the ability to revise their PHI according to the amending/accounting guidelines set forth in HIPAA; - Outline the business associate to follow the Privacy Rule of HIPAA (to whatever degree the covered entity is entrusting the business associate to handle privacy-related activities); - State that the business associate must allow the Department of Health & Human Services access to its policy documents and all accounting files that pertain to PHI use and disclosure – whether the applicable data is obtained directly from the covered entity or representing its interests – so that the US government can properly determine compliance; - Delineate the need for the business associate to return any PHI to the covered entity or to completely delete all PHI data – whether that data was obtained via the covered entity or in the business associate’s capacity as its representative – if and when the agreement between the two parties ends, if such return or deletion is possible and reasonably accomplished; - Hold the business associate responsible for its relationship with subcontractors who may additionally be exposed to PHI, so that they are held accountable with the same requirements that pertain to the business associate; and - Allow the covered entity to cancel the agreement at any time if the business associate is in noncompliance with any of its stipulations. ## HIPAA Business Associate Agreement by Atlantic.Net As one of the leading HIPAA compliant hosting companies in the United States, Atlantic.Net (and our healthcare partners utilizing our award-winning cloud platform) are directly impacted by this amendment. Atlantic.Net can be a Business Associate of each healthcare organization with whom we process, store, manage or otherwise deal with PHI, and therefore, we are legally obliged to sign a contract of service with each organization to guarantee our HIPAA compliance status. According to The Health Insurance Portability and Accountability Act (HIPAA), there are two different types of organizations that must ensure compliance: covered entities and business associates. Atlantic.Net™ falls into the latter category, a third-party entity contracted to handle ePHI (electronic protected health information). ## Read More About HIPAA IT Compliance ### [HIPAA IT Compliance Guide](https://www.atlantic.net/hipaa-data-centers/hipaa-compliant-it-infrastructure-guide/) - [HIPAA IT Compliance Guide](https://www.atlantic.net/hipaa-data-centers/hipaa-compliant-it-infrastructure-guide/) - [Best HIPAA Compliant Fax Service](https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-fax-services-in-2021/) - [Best HIPAA Compliant Email Service](https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-email-service-in-2021/) - [Best HIPAA Compliant VOIP Service](https://www.atlantic.net/hipaa-compliant-hosting/top-10-best-hipaa-compliant-voip-providers/) ### [Top Considerations for a HIPAA-Compliant Database](https://www.atlantic.net/hipaa-compliant-hosting/top-10-considerations-for-a-hipaa-compliant-database/) - [Top Considerations for a HIPAA-Compliant Database](https://www.atlantic.net/hipaa-compliant-hosting/top-10-considerations-for-a-hipaa-compliant-database/) - [Best Healthcare Software Development Companies](https://www.atlantic.net/hipaa-compliant-hosting/top-10-healthcare-software-development-companies/) - [Best HIPAA Consulting Companies](https://www.atlantic.net/hipaa-compliant-hosting/top-10-hipaa-consulting-companies/) - [Is It HIPPA or HIPAA?](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-vs-hippa/) ## Want to know more about the technical safeguards of our HIPAA hosting solution? Check out our HIPAA hosting page. Navigate the complexities of HIPAA compliance with confidence. Atlantic.Net will sign a BAA and guide you through the BAA process, ensuring your healthcare data is secure. Contact us to discuss your compliance needs. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at sales@atlantic.net. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # How to Install Apache Kafka on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-kafka-on-arch-linux/ | Published: 2023-03-24 | Updated: 2023-11-15 | Author: Hitesh Jethva Apache Kafka is a free, open-source Distributed Data Streaming Technology used for real-time data pipelines. It is used by thousands of companies for high-performance data pipelines, stream processing, and data integration at scale. Kafka can handle a high volume of data and enables you to pass messages from one end-point to another. In this post, we will show you how to install Apache Kafka on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Java JDK Apache Kafka is a Java-based software, so Java must be installed on your system. You can install it by simply running the following command. ``` pacman -S jre17-openjdk curl ``` After the successful installation, you can verify the Java version using the following command. ``` java --version ``` You will get the following output. ``` openjdk 17.0.6 2023-01-17 OpenJDK Runtime Environment (build 17.0.6+10) OpenJDK 64-Bit Server VM (build 17.0.6+10, mixed mode) ``` ## Step 3 – Install Apache Kafka First, create a dedicated user to run Apache Kafka using the following command. ``` useradd -r -d /opt/kafka -s /usr/sbin/nologin kafka ``` Next, download the latest version of Apache Kafka from their official download page. ``` curl -fsSLo kafka.tgz https://downloads.apache.org/kafka/3.3.2/kafka_2.13-3.3.2.tgz ``` Once the download is completed, extract the downloaded file with the following command. ``` tar -xzf kafka.tgz ``` Next, move the extracted directory to /opt. ``` mv kafka_2.13-3.3.2 /opt/kafka ``` Next, change the ownership of the Kafka directory. ``` chown -R kafka:kafka /opt/kafka ``` Next, create a Kafka log directory using the following command. ``` sudo -u kafka mkdir -p /opt/kafka/logs ``` Next, edit the Kafka configuration file and define your log directory. ``` sudo -u kafka nano /opt/kafka/config/server.properties ``` Change the following line: ``` log.dirs=/opt/kafka/logs ``` Save and close the file when you are done. ## Step 4 – Create a Systemd Service File for Kafka It is recommended to create a systemd service file to manage the Kafka service. First, create a Zookeeper service file using the following command. ``` nano /etc/systemd/system/zookeeper.service ``` Add the following configuration. ``` [Unit] Requires=network.target remote-fs.target After=network.target remote-fs.target [Service] Type=simple User=kafka ExecStart=/opt/kafka/bin/zookeeper-server-start.sh /opt/kafka/config/zookeeper.properties ExecStop=/opt/kafka/bin/zookeeper-server-stop.sh Restart=on-abnormal [Install] WantedBy=multi-user.target ``` Next, create a Kafka service file: ``` nano /etc/systemd/system/kafka.service ``` Add the following configuration. ``` [Unit] Requires=zookeeper.service After=zookeeper.service [Service] Type=simple User=kafka ExecStart=/bin/sh -c '/opt/kafka/bin/kafka-server-start.sh /opt/kafka/config/server.properties > /opt/kafka/logs/start-kafka.log 2>&1' ExecStop=/opt/kafka/bin/kafka-server-stop.sh Restart=on-abnormal [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable both services using the following command. ``` systemctl enable zookeeper kafka systemctl start zookeeper kafka ``` You can check the status of both services using the following command. ``` systemctl status zookeeper kafka ``` You will get the service status in the following output. ``` ● zookeeper.service Loaded: loaded (/etc/systemd/system/zookeeper.service; enabled; preset: disabled) Active: active (running) since Mon 2023-02-06 05:05:11 UTC; 17s ago Main PID: 54782 (java) Tasks: 34 (limit: 4700) Memory: 68.5M CGroup: /system.slice/zookeeper.service └─54782 java -Xmx512M -Xms512M -server -XX:+UseG1GC -XX:MaxGCPauseMillis=20 -XX:InitiatingHeapOccupancyPercent=35 -XX:+ExplicitG> Feb 06 05:05:13 archlinux zookeeper-server-start.sh[54782]: [2023-02-06 05:05:13,594] INFO zookeeper.snapshot.compression.method = CHECKED (o> Feb 06 05:05:13 archlinux zookeeper-server-start.sh[54782]: [2023-02-06 05:05:13,594] INFO Snapshotting: 0x0 to /tmp/zookeeper/version-2/snap> Feb 06 05:05:13 archlinux zookeeper-server-start.sh[54782]: [2023-02-06 05:05:13,598] INFO Snapshot loaded in 11 ms, highest zxid is 0x0, dig> Feb 06 05:05:13 archlinux zookeeper-server-start.sh[54782]: [2023-02-06 05:05:13,598] INFO Snapshotting: 0x0 to /tmp/zookeeper/version-2/snap> Feb 06 05:05:13 archlinux zookeeper-server-start.sh[54782]: [2023-02-06 05:05:13,598] INFO Snapshot taken in 0 ms (org.apache.zookeeper.serve> Feb 06 05:05:13 archlinux zookeeper-server-start.sh[54782]: [2023-02-06 05:05:13,625] INFO zookeeper.request_throttler.shutdownTimeout = 1000> Feb 06 05:05:13 archlinux zookeeper-server-start.sh[54782]: [2023-02-06 05:05:13,626] INFO PrepRequestProcessor (sid:0) started, reconfigEnab> Feb 06 05:05:13 archlinux zookeeper-server-start.sh[54782]: [2023-02-06 05:05:13,660] INFO Using checkIntervalMs=60000 maxPerMinute=10000 max> Feb 06 05:05:13 archlinux zookeeper-server-start.sh[54782]: [2023-02-06 05:05:13,662] INFO ZooKeeper audit is disabled. (org.apache.zookeeper> Feb 06 05:05:24 archlinux zookeeper-server-start.sh[54782]: [2023-02-06 05:05:24,979] INFO Creating new log file: log.1 (org.apache.zookeeper> ● kafka.service Loaded: loaded (/etc/systemd/system/kafka.service; enabled; preset: disabled) Active: active (running) since Mon 2023-02-06 05:05:21 UTC; 15s ago Main PID: 55164 (sh) Tasks: 73 (limit: 4700) Memory: 316.6M CGroup: /system.slice/kafka.service ├─55164 /bin/sh -c "/opt/kafka/bin/kafka-server-start.sh /opt/kafka/config/server.properties > /opt/kafka/logs/start-kafka.log 2> └─55165 java -Xmx1G -Xms1G -server -XX:+UseG1GC -XX:MaxGCPauseMillis=20 -XX:InitiatingHeapOccupancyPercent=35 -XX:+ExplicitGCInv> Feb 06 05:05:21 archlinux systemd[1]: Started kafka.service. ``` ## Step 5 – Create a Topic in Kafka At this point, Kafka is installed and running. Now, it’s time to verify Kafka. To verify Kafka, create a topic named MyTopic using the following command. ``` sudo -u kafka /opt/kafka/bin/kafka-topics.sh --create --bootstrap-server localhost:9092 --replication-factor 1 --partitions 1 --topic MyTopic ``` You can now verify your created topic using the following command. ``` sudo -u kafka /opt/kafka/bin/kafka-topics.sh --list --bootstrap-server localhost:9092 ``` Sample output. ``` MyTopic ``` Kafka provides a command line client called producer that will take input from a file or from standard input and send it out as messages to the Kafka cluster. Run the following command to type a few messages into the console to send to the server. ``` sudo -u kafka /opt/kafka/bin/kafka-console-producer.sh --broker-list localhost:9092 --topic MyTopic ``` Type some messages as shown below: ``` >Hi How are you? >I am fine ``` Now, open another terminal and run the consumer command line tool to read data from the Kafka cluster and display it to the output. ``` sudo -u kafka /opt/kafka/bin/kafka-console-consumer.sh --bootstrap-server localhost:9092 --topic MyTopic --from-beginning ``` You will get the messages in the following output. ``` Hi How are you? I am fine ``` ## Conclusion In this tutorial, we explained how to install Apache Kafka on Arch Linux. We also verified Kafka using producer and consumer. Try installing a Kafka server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Medical AI > URL: https://www.atlantic.net/hipaa-compliant-hosting/medical-ai/ | Published: 2023-03-25 | Updated: 2024-11-09 | Author: Richard Bailey Medical or healthcare AI provides the healthcare system with artificial intelligence (AI) and machine learning (ML) technologies. The use of AI in medicine has gained significant attention in recent years, as the technology can revolutionize healthcare by enabling more accurate and efficient diagnosis, treatment, and patient care. AI can transform frontline healthcare services by enabling more accurate and efficient diagnosis, treatment, and patient care. There is also significant scope for Ai automation to reduce the workload of physicians and improve patient satisfaction. In addition, advanced AI can interpret large amounts of medical data, including patient records, medical images, clinical research, and genomic data. The next generation of AI tools is inbound, and you have probably heard of one of the most popular, ChatGPT. However, this Generative Pre-Trained Transformer is more than just a platform to tell jokes, write homework, or even give you cooking recipes. Researchers are excited by the potential that the technology behind chatGPT can impact the healthcare industry. Trained AI algorithms can identify patterns and trends in patient data that human doctors might miss. In this article, we will discover what technologies like chatGPT will offer the healthcare industry today and in the future. ## Chatbots Virtual medical consultations are one use case for AI in the medical field that utilizes Chat GPT for medical data processing. With the help of the natural language processing (NLP) capabilities of Chat GPT, it is possible to create an AI-powered virtual assistant that can interact with patients and help doctors diagnose and treat medical conditions remotely. Here’s how it could work: when patients schedule a virtual medical consultation, they are directed to a trained AI-powered chatbot with access to a vast dataset of medical data, symptoms, diagnoses, treatments, and drug interactions. The chatbot could ask patients questions to collect information about their medical history, symptoms, and current condition. It could then use this information to generate a preliminary diagnosis and suggest a treatment plan. The doctor could then review the chatbot’s diagnosis and treatment plan and use it as a starting point for further evaluation and treatment. The doctor could also use the chatbot to help educate the patient about their condition and answer any questions they may have. Using an AI-powered chatbot for virtual medical consultations could have several benefits: - Reduce the need for in-person visits, which could be especially useful in areas with limited access to healthcare. - Improve healthcare delivery efficiency by automating patient information collection and generating preliminary diagnoses. - Improve patient outcomes by providing patients with more immediate access to medical care and allowing them to receive more personalized treatment plans. ## Medical Research AI services can analyze large amounts of medical data, such as electronic health records, research papers, and clinical trials, enabling researchers to identify patterns and insights that may be difficult to uncover through traditional research methods. *Text mining* techniques extract meaningful insights and patterns from data sources such as electronic health records, research papers, and clinical trials. As a result, AI can identify new research opportunities or suggest hypotheses for further investigation. ChatGPT can automatically generate *literature reviews* by summarizing key findings and conclusions from relevant research papers saving researchers significant time and effort and allowing them to focus their attention elsewhere. *Data analysis* tasks, such as data cleaning and preprocessing, can be handled by ChatGPT, helping researchers identify inconsistencies or errors in their data and ensure that their data is suitable for analysis. Generative Pretrained Transformers can analyze patients’ medical records and suggest personalized treatment plans based on their medical history, symptoms, and other factors, utilizing advanced [machine learning](https://www.databricks.com/glossary/machine-learning-models) techniques. This approach can help to improve the effectiveness of medical treatments and reduce the risk of adverse events. ChatGPT can provide*clinical decision support* by helping healthcare providers diagnose diseases and recommend appropriate treatments, helping to improve the accuracy of diagnoses and reducing the risk of medical errors. ## Speed Up Medical Diagnosis AI is unlikely to replace human expertise fully. However, it can help medical professionals handle the pressures of frontline services. However, here are some ways tools like chatGPT can do this: - **Answering patient questions:** Patients often have many questions about their health conditions, treatments, and medications. ChatGPT can provide easy-to-understand answers to these questions using language that patients are familiar with, helping patients feel more informed and empowered when making decisions about their health. - **Explaining medical terms:** Medical terminology can confuse and overwhelm patients. ChatGPT can help by explaining medical terms in a way that patients can understand without using technical jargon, helping patients to understand their conditions and treatments better. - **Providing health tips:** Patients can learn expert tips for managing their health conditions and promoting overall wellness from AI toolsets. For example, AI can provide information on healthy eating, exercise, and stress management techniques. - **Sharing resources:** ChatGPT can direct patients to reliable resources for further information on their health conditions, including websites, support groups, and other resources that can help patients learn more about their needs and connect with others who may be going through similar experiences. - **Supporting self-care:** ChatGPT can encourage patients to take an active role in their healthcare by providing tips and guidance on self-care. This can include advice on monitoring symptoms, managing medications, and making lifestyle changes to improve their health. ## Private ChatGPT Servers Did you know that ChatGPT can be deployed on-premise? It can be installed locally or in cloud infrastructure, allowing organizations more control over their data and resources. It can be instrumental in industries such as healthcare, finance, or government, where data privacy and security are critical. Atlantic.Net is a cloud hosting provider that offers a range of hosting services, including virtual private servers (VPS), dedicated servers, and cloud hosting. Running ChatGPT on Atlantic.Net servers can provide several benefits, including scalability, reliability, and security. Atlantic.Net offers various hosting options, including [VPS](https://www.atlantic.net/vps-hosting/) and [HIPAA-Compliant cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) options and a 100% uptime guarantee. High availability is essential for organizations that require continuous access to their chat interfaces, such as those in the healthcare or finance industries. Finally, running ChatGPT on Atlantic.Net servers can provide enhanced security. Atlantic.Net range of security features includes firewalls, intrusion detection and prevention, and data encryption to help protect their customer’s data and applications, and essential requirements when using AI services that access sensitive or confidential information. Organizations must set up their virtual machine or cloud server instance, install the necessary software frameworks, and train and deploy the ChatGPT model. Atlantic.Net offers a range of customizable hosting plans to meet your organization’s specific needs. --- # How to Install GlassFish Server on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-glassfish-server-on-arch-linux/ | Published: 2023-03-26 | Updated: 2023-11-14 | Author: Hitesh Jethva GlassFish is an open-source Java application server used for the development and deployment of Java-based web applications. GlassFish is a flexible, lightweight, and production-ready application that provides many easy-to-use tools to manage, deploy, scale and set up Java-based applications. If you are looking for an enterprise-grade open-source platform for deploying Java applications, then Glassfish is the best option for you. In this post, we will show you how to install GlassFish on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Java First, you will need to install Java on your server. You can install it using the following command. ``` pacman -S jre17-openjdk ``` After installing Java, you can check the Java version using the following command. ``` java --version ``` You will get the following output. ``` openjdk 17.0.6 2023-01-17 OpenJDK Runtime Environment (build 17.0.6+10) OpenJDK 64-Bit Server VM (build 17.0.6+10, mixed mode) ``` ## Step 3 – Download and Install GlassFish First, visit the GlassFish official download page and download the latest version of GlassFish using the following command. ``` wget https://download.eclipse.org/ee4j/glassfish/glassfish-7.0.1.zip ``` Once the download is completed, unzip the downloaded file using the following command. ``` pacman -S unzip unzip glassfish-7.0.1.zip ``` Next, move the extracted directory to /opt using the following command. ``` mv glassfish7 /opt/ ``` Next, export the GlassFish path to the ~/.bashrc file. ``` echo "export PATH=$PATH:/opt/glassfish7/bin" >> ~/.bashrc ``` After that, reload the ~/.bashrc file using the following command. ``` source ~/.bashrc ``` ## Step 4 – Start GlassFish Server You can now use the asadmin command to start the GlassFish server. ``` asadmin start-domain ``` You will get the following output. ``` Waiting for domain1 to start ............ Waiting finished after 11,935 ms. Successfully started the domain : domain1 domain Location: /opt/glassfish7/glassfish/domains/domain1 Log File: /opt/glassfish7/glassfish/domains/domain1/logs/server.log Admin Port: 4,848 Command start-domain executed successfully. ``` You can verify the GlassFish server using the following command. ``` asadmin list-domains ``` Sample output. ``` domain1 running Command list-domains executed successfully. ``` ## Step 5 – Set GlassFish Admin Password By default, there is not any password for the GlassFish admin user, so you can set it using the following command. ``` asadmin change-admin-password ``` You will be asked to provide your admin user: ``` Enter admin user name [default: admin]> ``` Just press the Enter key and you will be asked to provide your admin password. ``` Enter the admin password> ``` Just press the Enter key without typing anything. You will be asked to set a new admin password as shown below. ``` Enter the new admin password> Enter the new admin password again> Command change-admin-password executed successfully. ``` Next, you will also need to enable the admin user. You can enable it using the following command. ``` asadmin --port 4848 enable-secure-admin ``` You will be asked to provide your admin user and password to enable it as shown below. ``` Enter admin user name> admin Enter admin password for user "admin"> You must restart all running servers for the change in secure admin to take effect. Command enable-secure-admin executed successfully. ``` ## Step 6 – Create a Systemd Service File for GlassFish Before starting, stop the GlassFish server using the following command. ``` asadmin stop-domain ``` Next, create a systemd service file using the following command. ``` nano /usr/lib/systemd/system/glassfish.service ``` Add the following configurations. ``` [Unit] Description = GlassFish Server v7.1.0 After = syslog.target network.target [Service] ExecStart = /usr/bin/java -jar /opt/glassfish7/glassfish/lib/client/appserver-cli.jar start-domain ExecStop = /usr/bin/java -jar /opt/glassfish7/glassfish/lib/client/appserver-cli.jar stop-domain ExecReload = /usr/bin/java -jar /opt/glassfish7/glassfish/lib/client/appserver-cli.jar restart-domain Type = forking [Install] WantedBy = multi-user.target ``` Save the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the GlassFish service using the following command. ``` systemctl start glassfish systemctl enable glassfish ``` To verify the GlassFish service, run the following command. ``` systemctl status glassfish ``` Sample output. ``` ● glassfish.service - GlassFish Server v7.1.0 Loaded: loaded (/usr/lib/systemd/system/glassfish.service; disabled; preset: disabled) Active: active (running) since Mon 2023-02-06 11:41:57 UTC; 22s ago Process: 59110 ExecStart=/usr/bin/java -jar /opt/glassfish7/glassfish/lib/client/appserver-cli.jar start-domain (code=exited, status=0/SU> Main PID: 59125 (java) Tasks: 77 (limit: 2362) Memory: 195.5M CGroup: /system.slice/glassfish.service └─59125 /usr/lib/jvm/java-17-openjdk/bin/java -cp /opt/glassfish7/glassfish/modules/glassfish.jar -DWALL_CLOCK_START=2023-02-06T> Feb 06 11:41:44 archlinux systemd[1]: Starting GlassFish Server v7.1.0... Feb 06 11:41:57 archlinux java[59110]: Waiting for domain1 to start ........... Feb 06 11:41:57 archlinux java[59110]: Waiting finished after 10,943 ms. Feb 06 11:41:57 archlinux java[59110]: Successfully started the domain : domain1 Feb 06 11:41:57 archlinux java[59110]: domain Location: /opt/glassfish7/glassfish/domains/domain1 Feb 06 11:41:57 archlinux java[59110]: Log File: /opt/glassfish7/glassfish/domains/domain1/logs/server.log Feb 06 11:41:57 archlinux java[59110]: Admin Port: 4,848 Feb 06 11:41:57 archlinux java[59110]: Command start-domain executed successfully. Feb 06 11:41:57 archlinux systemd[1]: Started GlassFish Server v7.1.0. ``` ## Step 7 – Access GlassFish Web UI At this point, GlassFish is installed and listens on port 4848. You can now access it using the URL **http://your-server-ip:4848.** You should see the GlassFish login page: ![Glassfish login page](https://www.atlantic.net/wp-content/uploads/2023/02/p1-2-1024x464.png) Type your admin username and password and click on the **Login** button. You should see the GlassFish dashboard on the following page. ![Glassfish dashboard page](https://www.atlantic.net/wp-content/uploads/2023/02/p2-1-1024x506.png) ## Conclusion In this post, we explained how to install a GlassFish server on Arch Linux. You can now deploy, manage and scale Java applications using your GlassFish server. You can try to set up a GlassFish server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Django on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-django-on-arch-linux/ | Published: 2023-03-27 | Updated: 2023-11-14 | Author: Hitesh Jethva Django is an open-source web framework used for developing Python-based websites. It is built by experienced developers to make it easier for the rapid development of secure and maintainable websites. It is based on the Model View Template design that reduces a lot of hassles that a developer has to face during the development of a website. In this post, we will show you how to install Django on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Python Dependencies Django is a Python-based application. So you will need to install Python and other dependencies to your server. You can install all of them using the following command. ``` pacman -S python python-pip ``` Next, update the PIP package with the following command. ``` pip3 install --upgrade pip ``` Next, install the virtualenv package. ``` pip3 install virtualenv ``` Next, verify the PIP version using the following command. ``` pip3 --version ``` You will get the following output. ``` pip 23.0 from /usr/lib/python3.10/site-packages/pip (python 3.10) ``` ## Step 3 – Install and Configure MySQL Database Server First, install the MySQL server using the following command. ``` pacman -S mysql ``` Next, initialize the MySQL database using the following command. ``` mysql_install_db --user=mysql --basedir=/usr --datadir=/var/lib/mysql ``` Next, start and enable the MySQL service with the following command. ``` systemctl start mysqld systemctl enable mysqld ``` Next, log into the MySQL shell with the following command. ``` mysql ``` Once logged in, create a database and user for Django: ``` CREATE DATABASE django; CREATE USER 'django'@'localhost' IDENTIFIED BY 'yourpassword'; ``` Next, grant all the privileges to the Django database with the following command. ``` GRANT ALL ON django.* TO 'django'@'localhost'; ``` Now, flush the privileges and exit from the MySQL shell with the following command. ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 4 – Install Django Arch Linux First, create a Django project directory and create a virtual environment for Django using the following command. ``` mkdir django cd django python3 -m venv djangoenv ``` Next, activate the virtual environment with the following command. ``` source djangoenv/bin/activate ``` Next, install Django using the following command. ``` pip install django ``` You will get the following output. ``` Collecting django Downloading Django-4.1.6-py3-none-any.whl (8.1 MB) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 8.1/8.1 MB 29.9 MB/s eta 0:00:00 Collecting asgiref<4,>=3.5.2 Downloading asgiref-3.6.0-py3-none-any.whl (23 kB) Collecting sqlparse>=0.2.2 Using cached sqlparse-0.4.3-py3-none-any.whl (42 kB) Installing collected packages: sqlparse, asgiref, django Successfully installed asgiref-3.6.0 django-4.1.6 sqlparse-0.4.3 [notice] A new release of pip available: 22.3.1 -> 23.0 [notice] To update, run: pip install --upgrade pip ``` Next, install the MySQL client package. ``` pip install mysqlclient ``` Next, create a Django project with the following command. ``` django-admin startproject djangoproject . ``` Next, edit the Django configuration file with the following command. ``` nano djangoproject/settings.py ``` Add your server IP or domain name as shown below: ``` ALLOWED_HOSTS = ['your_server_ip'] ``` Find the following database section. ``` DATABASES = { 'default': { 'ENGINE': 'django.db.backends.sqlite3', 'NAME': BASE_DIR / 'db.sqlite3', } } ``` And replace them with the following lines. ``` DATABASES = { 'default': { 'ENGINE': 'django.db.backends.mysql', 'NAME': 'django', 'USER': 'django', 'PASSWORD': 'yourpassword', 'HOST': '127.0.0.1', 'PORT' : '3306', } } ``` Next, add/modify the following lines: ``` import os STATIC_URL='/static/' STATIC_ROOT=os.path.join(BASE_DIR, 'static/') MEDIA_URL='/media/' MEDIA_ROOT=os.path.join(BASE_DIR, 'media/') ``` Save and close the file when you are done. Then, migrate the database with the following command. ``` ./manage.py makemigrations ./manage.py migrate ``` You will get the following output. ``` Operations to perform: Apply all migrations: admin, auth, contenttypes, sessions Running migrations: Applying contenttypes.0001_initial... OK Applying auth.0001_initial... OK Applying admin.0001_initial... OK Applying admin.0002_logentry_remove_auto_add... OK Applying admin.0003_logentry_add_action_flag_choices... OK Applying contenttypes.0002_remove_content_type_name... OK Applying auth.0002_alter_permission_name_max_length... OK Applying auth.0003_alter_user_email_max_length... OK Applying auth.0004_alter_user_username_opts... OK Applying auth.0005_alter_user_last_login_null... OK Applying auth.0006_require_contenttypes_0002... OK Applying auth.0007_alter_validators_add_error_messages... OK Applying auth.0008_alter_user_username_max_length... OK Applying auth.0009_alter_user_last_name_max_length... OK Applying auth.0010_alter_group_name_max_length... OK Applying auth.0011_update_proxy_permissions... OK Applying auth.0012_alter_user_first_name_max_length... OK Applying sessions.0001_initial... OK ``` ## Step 5 – Create a Django Superuser Next, create an administrative user for Django using the following command. ``` ./manage.py createsuperuser ``` Define your email address and password as shown below: ``` Username (leave blank to use 'root'): hiteshj Email address: admin@example.com Password: Password (again): Superuser created successfully. ``` Next, copy all static files with the following command. ``` ./manage.py collectstatic ``` ## Step 6 – Start Django Server At this point, Django is installed and configured. You can now start Django using the following command. ``` ./manage.py runserver 0.0.0.0:8000 ``` You should see the following output. ``` Watching for file changes with StatReloader Performing system checks... System check identified no issues (0 silenced). February 06, 2023 - 08:00:46 Django version 4.1.6, using settings 'djangoproject.settings' Starting development server at http://0.0.0.0:8000/ Quit the server with CONTROL-C. ``` ## Step 7 – Access Django Web UI Django is now started and listens on port 8000. You can now access it using the URL **http://your-server-ip:8000/admin.** You should see the Django login page on the following screen. ![Django login page](https://www.atlantic.net/wp-content/uploads/2023/02/p1-3-1024x489.png) Provide your admin username and password and click on the **Login** button. You should see the Django dashboard on the following screen. ![Django dashboard page](https://www.atlantic.net/wp-content/uploads/2023/02/p2-2-1024x369.png) ## Conclusion Congratulations! You have successfully installed and configured Django on Arch Linux. You can now start developing and deploying Python applications using the Django framework. You can set up a Django on a [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # High-Performance Linux VPS Hosting with Full Root Access > URL: https://www.atlantic.net/vps-hosting/linux-vps-hosting/ | Updated: 2026-09-16 Deploy a Linux virtual private server in under 30 seconds with guaranteed resources, redundant SSD or NVMe storage, and hourly or monthly billing. - Guaranteed Resources - Full Root Access - SSD/NVMe Storage - 100% Uptime SLA Provisioning: Under 30 sec US-Based Support: 24/7/365 ## Linux VPS Hosting Experience strong reliability, fast performance, and a choice of multiple Linux distributions on our Linux VPS hosting platform. Each customer is guaranteed the allocated server resources they pay for thanks to the way the ACP cloud servers isolate and ring-fence resources. Linux VPS hosting by Atlantic.Net offers the affordability of shared hosting with the power and performance of dedicated hosting, with an ultra-fast Linux virtual private server experience on the Atlantic.Net Cloud Platform. Our highly available and affordable Linux VPS hosting platform provides monthly and hourly plans with discounts for term commitments, backed by redundant SSD or NVMe storage and world-class network and infrastructure. With all Linux VPS hosting accounts, our customers receive a security-defined experience and strong performance, all wrapped into a user-friendly cloud console. All Linux virtual private servers are available on our cloud platform or as a cloud-connected dedicated host for even the most resource-intensive workloads. ## What Is Linux VPS Hosting? Linux VPS hosting is a hosting service designed to support Linux virtual private servers. A Linux VPS enables users to take advantage of cloud-server technology backed by redundant systems, affordably. Linux VPS hosting is a strong alternative to dedicated hosting and to on-premise physical machines because of the cost advantage with benefits like full root access and administrative server controls without incurring the costs associated with running a dedicated environment. Linux VPS hosting in the cloud is also far more powerful than traditional non-cloud VPS servers because of its speed, agility, reliability, and affordability. You can spin up a Linux VPS in under 30 seconds and pay only for what you use. ## Linux VPS Hosting Pricing & Plans | | | | | | | | | --- | --- | --- | --- | --- | --- | --- | | General Purpose | G3.2GB | 2GB | 1 | 50GB | 3 TB | On-Demand: $10.0/mo $0.0149/hr; 1-Year: $9.0/mo $0.0134/hr; 3-Year: $8.0/mo $0.0119/hr | | General Purpose | G3.4GB | 4GB | 2 | 80GB | 5 TB | On-Demand: $20.0/mo $0.0298/hr; 1-Year: $18.0/mo $0.0268/hr; 3-Year: $17.0/mo $0.0253/hr | | General Purpose | G3.8GB | 8GB | 4 | 160GB | 6 TB | On-Demand: $40.0/mo $0.0595/hr; 1-Year: $37.0/mo $0.0551/hr; 3-Year: $34.0/mo $0.0506/hr | | General Purpose | G3.16GB | 16GB | 6 | 320GB | 7 TB | On-Demand: $80.0/mo $0.119/hr; 1-Year: $74.0/mo $0.1101/hr; 3-Year: $68.0/mo $0.1012/hr | | General Purpose | G3.32GB | 32GB | 8 | 640GB | 8 TB | On-Demand: $160.0/mo $0.2381/hr; 1-Year: $147.0/mo $0.2188/hr; 3-Year: $136.0/mo $0.2024/hr | | General Purpose | G3.48GB | 48GB | 12 | 960GB | 9 TB | On-Demand: $240.0/mo $0.3571/hr; 1-Year: $220.0/mo $0.3274/hr; 3-Year: $204.0/mo $0.3036/hr | | General Purpose | G3.64GB | 64GB | 16 | 1280GB | 10 TB | On-Demand: $320.0/mo $0.4762/hr; 1-Year: $294.0/mo $0.4375/hr; 3-Year: $272.0/mo $0.4048/hr | | General Purpose | G3.96GB | 96GB | 20 | 1920GB | 11 TB | On-Demand: $480.0/mo $0.7143/hr; 1-Year: $441.6/mo $0.6571/hr; 3-Year: $408.0/mo $0.6071/hr | | General Purpose | G3.128GB | 128GB | 24 | 2560GB | 12 TB | On-Demand: $640.0/mo $0.9524/hr; 1-Year: $589.0/mo $0.8765/hr; 3-Year: $544.0/mo $0.8095/hr | | General Purpose | G3.192GB | 192GB | 32 | 3840GB | 13 TB | On-Demand: $960.0/mo $1.4286/hr; 1-Year: $883.2/mo $1.3143/hr; 3-Year: $816.0/mo $1.2143/hr | | Compute Optimized | C2.8GB | 8GB | 4 | 40GB | 10 TB | On-Demand: $211.0/mo $0.314/hr; 1-Year: $137.0/mo $0.2039/hr; 3-Year: $67.0/mo $0.0997/hr | | Compute Optimized | C2.16GB | 16GB | 8 | 80GB | 10 TB | On-Demand: $418.0/mo $0.622/hr; 1-Year: $271.0/mo $0.4033/hr; 3-Year: $133.0/mo $0.1979/hr | | Compute Optimized | C2.32GB | 32GB | 16 | 160GB | 10 TB | On-Demand: $828.0/mo $1.2321/hr; 1-Year: $538.0/mo $0.8006/hr; 3-Year: $263.0/mo $0.3914/hr | | Compute Optimized | C2.64GB | 64GB | 20 | 350GB | 10 TB | On-Demand: $1,451.0/mo $2.1592/hr; 1-Year: $943.0/mo $1.4033/hr; 3-Year: $461.0/mo $0.686/hr | | Storage Optimized | S2.16GB | 16GB | 2 | 500GB | 10 TB | On-Demand: $248.0/mo $0.369/hr; 1-Year: $161.0/mo $0.2396/hr; 3-Year: $105.0/mo $0.1563/hr | | Storage Optimized | S2.32GB | 32GB | 4 | 1TB | 10 TB | On-Demand: $425.0/mo $0.6324/hr; 1-Year: $276.0/mo $0.4107/hr; 3-Year: $180.0/mo $0.2679/hr | | Storage Optimized | S2.64GB | 64GB | 8 | 2TB | 10 TB | On-Demand: $778.0/mo $1.1577/hr; 1-Year: $506.0/mo $0.753/hr; 3-Year: $330.0/mo $0.4911/hr | | Storage Optimized | S2.96GB | 96GB | 12 | 3TB | 10 TB | On-Demand: $1,097.0/mo $1.6324/hr; 1-Year: $713.0/mo $1.061/hr; 3-Year: $465.0/mo $0.692/hr | | Storage Optimized | S2.128GB | 128GB | 16 | 4TB | 10 TB | On-Demand: $1,414.0/mo $2.1042/hr; 1-Year: $919.0/mo $1.3676/hr; 3-Year: $599.0/mo $0.8914/hr | | Memory Optimized | M2.16GB | 16GB | 2 | 40GB | 10 TB | On-Demand: $163.0/mo $0.2426/hr; 1-Year: $106.0/mo $0.1577/hr; 3-Year: $52.0/mo $0.0774/hr | | Memory Optimized | M2.32GB | 32GB | 4 | 80GB | 10 TB | On-Demand: $318.0/mo $0.4732/hr; 1-Year: $207.0/mo $0.308/hr; 3-Year: $101.0/mo $0.1503/hr | | Memory Optimized | M2.64GB | 64GB | 8 | 160GB | 10 TB | On-Demand: $630.0/mo $0.9375/hr; 1-Year: $409.0/mo $0.6086/hr; 3-Year: $200.0/mo $0.2976/hr | | Memory Optimized | M2.128GB | 128GB | 16 | 350GB | 10 TB | On-Demand: $1,246.0/mo $1.8542/hr; 1-Year: $810.0/mo $1.2054/hr; 3-Year: $396.0/mo $0.5893/hr | *All plans are available in every location for Managed Server clients. *The hourly rate is determined by dividing the monthly rate by 672 hours (28 days). If your server is online for more than 672 hours in a calendar month, you will only be billed the monthly rate. *Prices listed above are based on the service being utilized for the period specified. *All Servers include one IPv4 Address. Additional IPs are available for $3.65/month ($0.005431/hour) *Unlimited inbound bandwidth. If free outbound bandwidth is exceeded, each additional GB is $0.02 *Optional Daily Backups are available for 20% of the server price. Minimum $1.00/month. *cPanel licensing cost starts at $23 per month ## Top Features of Linux VPS Hosting All Linux VPS servers have guaranteed access to pre-allocated system resources with high levels of user freedom. Our Linux virtual private servers offer top performance affordably, backed by always-available US-based phone and email support, redundant SSD storage, and multiple one-click applications including LAMP/LEMP stacks, cPanel/WHM, Node.js, Docker, and MySQL. Every Linux VPS comes standard with DNS, RESTful API, private networking, a user-friendly control panel, full administrator access, a dedicated IP address, optional onsite and offsite backups, Secure Block Storage, snapshots, and more. ## Linux VPS Supported Operating Systems Our Linux VPS hosting can be deployed using a variety of Linux distributions including multiple versions of Ubuntu, Debian, Oracle Linux, Rocky Linux, AlmaLinux, CentOS, Fedora, Arch Linux, and FreeBSD. A Linux VPS is deployed via the one-click application from the Atlantic.Net cloud image library. Each Linux cloud server is available as a 32-bit or 64-bit revision, and we include multiple versions of each distribution for the broadest compatibility, with SSD storage as standard. - Ubuntu: Ubuntu is one of the most widely deployed server distributions thanks to its intuitive defaults and broad community support. - Rocky Linux: the modern community-driven RHEL-compatible distribution backed by some of the biggest names in the industry, providing a free, drop-in alternative for CentOS workloads. - AlmaLinux: another community-driven RHEL-compatible distribution, with long support windows and full binary compatibility with RHEL. - Debian: with three decades of development, Debian offers a highly tuned and reliable experience, particularly strong for containerised applications. - Fedora: sponsored by Red Hat, Fedora pairs strong stability with the latest tooling from upstream open-source repositories. - FreeBSD: a lightweight Unix-like server OS with high reliability and uncomplicated licensing. - Arch Linux: a minimal, rolling-release distribution that suits users who want a hands-on, fully customised setup. - CentOS: despite the last release being CentOS 8.5, we still offer this distribution because many customers continue to rely on it. - Oracle Linux: RHEL-compatible distribution with the optional Unbreakable Enterprise Kernel (UEK). ## Popular Linux VPS Applications You can run any software you like on Atlantic.Net's Linux VPS, with ample resources for leading web applications, website hosting, and modern AI workloads. ## Linux VPS Hosting Data Center Regions Linux VPS hosting is available in five US regions (New York, San Francisco, Dallas, Ashburn, and Orlando) plus Toronto (Canada), London (UK), and Singapore. ## Linux VPS Support Our hosting services and solutions are supported free of cost by our US-based phone and email support team 24/7/365. The open-source movement is driven by a philosophy that all software should be free and developed for the exact needs of the users. All open-source software is available free of charge. If you need help with open-source software on your Linux cloud server, you can reach out to an Atlantic.Net support engineer for assistance, consider a support contract with the vendor, or go it alone. Check out our procedures library, which demonstrates the latest open-source projects and popular tech solutions for Linux servers: [new procedures](https://www.atlantic.net/tutorials/) are added every month. Learn how to build your own mail servers, cloud services, and web development platforms from our intuitive control panel, all in a few clicks. ## Why We Offer the Best Linux VPS Hosting Reliability is at the forefront of an ACP virtual private server. We are confident in our highly redundant cloud computing infrastructure, and we offer a 100% uptime guarantee. Atlantic.Net guarantees that all critical infrastructure components will be available 100% of the time in a given month, excluding scheduled maintenance. To explore our cloud server guarantees in further detail, see the [Cloud Service Level Agreement](https://www.atlantic.net/cloud-service-level-agreement/). Backed by our 100% SLA, we stand ready to accommodate all your Linux workloads with always-available support. ## Dedicated Linux Cloud Server You can also use a Dedicated Cloud Host: an exclusive, private computing node fully dedicated to a single use. This powerful, dedicated-hardware cloud infrastructure service integrates directly with other Atlantic.Net services. It is a strong choice for private data security requirements: with the dedicated resources of our cloud servers, there are no shared resources or noisy neighbours. Meet and exceed your urgent need for growth with a dedicated virtual private server that leverages customisable and powerful cloud computing infrastructure plans, perfect for customers looking to embed security best practices, meet exacting compliance needs, or simply benefit from the flexibility and cost-effectiveness of dedicated cloud infrastructure. ## Integrate with Atlantic.Net Managed Services A Linux cloud server can integrate directly with Atlantic.Net's optional managed services. ### Atlantic.Net Cloud Backups Our advanced proprietary cloud storage solution delivers on-site and off-site backup and replication services that are fast, robust, and fault-tolerant. Our backup technology is fully automated and configurable to meet your needs. ### Always Up, Whenever You Need Us If something goes wrong with your Linux virtual servers, you shouldn't have to wait to get support. We make it easy to get in touch: eliminate phone tag and slow email replies. 24/7 support by phone, chat, or email. ### Level Up Your IT with Our Expertise Training new staff with the skills you need can be costly. Level up your IT department's skills by leveraging our 32 years of experience to help with your Linux virtual servers. Our dedicated support staff have the right expertise to solve problems in any industry. Here are some of the top questions we are asked about our Linux server hosting. ## Top Linux VPS Hosting FAQ ### Which Linux distribution is best for VPS? The operating system you choose depends entirely on the use case of your virtual server. The most popular Linux virtual servers on our platform run Ubuntu, Rocky Linux, and CentOS. We also offer a choice of operating systems, one-click applications, and hosting control panel options like cPanel. ### What operating systems do you offer for virtual servers? We offer the following Linux distributions for cloud virtual servers: **Linux / Unix** - Ubuntu 16.04 LTS Server 32-bit - Ubuntu 16.04 LTS Server 64-bit - Ubuntu 18.04 LTS Server 64-bit - Ubuntu 20.04 LTS Server 64-bit - Ubuntu 22.04 LTS Server 64-bit - Ubuntu 24.04 LTS Server 64-bit - Ubuntu 26.04 LTS Server 64-bit - Debian 11.11.0 Server 64-bit - Debian 12.11.0 Server 64-bit - Debian 13.0.0 Server 64-bit - Oracle Linux 7.9 64-bit - Oracle Linux 8.10 64-bit - Oracle Linux 9.6 64-bit - Oracle Linux 10.0 64-bit - Rocky Linux 8.10 64-bit - Rocky Linux 9.6 64-bit - Rocky Linux 10.0 64-bit - CentOS 6.9 Server 32-bit - CentOS 6.9 Server 64-bit - CentOS 7.9 Server 64-bit - CentOS 8.2 Server 64-bit - Fedora 42 Server 64-bit - FreeBSD 13.0 Server 64-bit - Arch Linux Server 64-bit - AlmaLinux 8.10 64-bit - AlmaLinux 9.6 64-bit - AlmaLinux 10.0 64-bit - cPanel/WHM on AlmaLinux 64-bit Note: we do not offer Red Hat Enterprise Linux as an option for Linux cloud virtual servers. ### Can I host my own Linux Cloud VPS? Yes. You can leverage an Atlantic.Net dedicated host to build and maintain your own cloud VPS platform. We offer competitive rates to resellers, unlimited traffic options, redundant storage, and the tools needed to run your own VPS-management platform. Contact our team to get easy access to cPanel and other providers. ### How am I billed? You will be billed monthly on the anniversary of the date you registered for the Atlantic.Net Cloud. You will only be billed for the Linux virtual cloud servers you deploy and the data transfer used in the previous month. For a detailed billing section in the Cloud Control Panel, navigate to **Account Info → Payment and Billings**. Here you can update your payment information and view your entire billing history. [Please refer to our cloud server pricing section for details](https://www.atlantic.net/vps-hosting/pricing/). ### How is data transfer billed? Inbound (ingress) data transfer is free. If the free amount of outbound data transfer included in your plan is exceeded, you pay for the additional outbound data transfer used during the billing cycle. Unlimited inbound bandwidth. If free outbound bandwidth is exceeded, each additional GB is $0.02. [Please refer to our cloud server pricing section for details](https://www.atlantic.net/vps-hosting/pricing/). ### Are Linux virtual servers good for web hosting? cPanel/WHM web hosting control panels are simple point-and-click Linux virtual hosting tools that simplify management of cloud-based virtual servers. You can create unlimited email accounts, domains, and websites, a strong fit for Linux cloud VPS hosting on the ACP platform. ### What is the difference between a Cloud VPS and a dedicated server? A Cloud VPS is a virtual server hosted on a shared platform with guaranteed system resources (CPU, disk, and memory). A dedicated host is a physical host dedicated to a single user, where the user has access to all the resources on the server. The Atlantic.Net Cloud service offers both VPS and dedicated hosts within the same environment, so you get the benefits of either platform. The workload of a VPS varies from running websites and workstations to general-purpose cloud servers. A dedicated host is usually used for hosting a significant number of websites or apps, intensive workloads, large numbers of virtual machines, or large production databases. Whether you choose a VPS in our public cloud or to deploy VPSes on dedicated hosts, cloud servers will be available within seconds of being deployed. ### What are the advantages of Linux VPS hosting? With Linux VPS hosting, you have isolation from all other VPS users in our data centers, giving you guaranteed resources, high performance, and a reliable Linux cloud server plan. No matter what other customers might be doing on the server, your Linux cloud server is unaffected. You also get full root access to the operating system, giving you complete control over the cloud server. You can install whatever applications you desire and make any configuration changes you might need. ### What is a KVM VPS? A KVM (Kernel-based Virtual Machine) is a cloud server backed by virtualisation directly in the Linux kernel. System resources are dedicated and shared among KVM VPSes, with isolation of CPU, disk, and memory at the hardware layer. ### Why should I choose Atlantic.Net for cloud VPS hosting? VPS hosting offers the affordability of shared hosting with the power and performance of dedicated hosting. Shared hosting puts your server on a host with unreserved resources; a dedicated server gives you 100% access to all resources on the host. VPS strikes a balance between the two: you get the benefits of guaranteed resources on a host while still sharing the underlying hardware with other clients. If your VPS comes with 200 GB of storage and 64 GB of memory, those resources are exclusively yours, regardless of what other tenants do. ### What one-click apps do you offer on VPS hosting? Our one-click apps are a popular feature of our virtual cloud servers. They let you automatically deploy a predefined, secure, updated instance in seconds. Try it out at [cloud.atlantic.net](https://cloud.atlantic.net/?page=userlogin) and locate the Applications tile. We currently offer the following one-click apps, with more being added regularly: - LAMP on Ubuntu 24.04 LTS Server 64-bit - LEMP on Ubuntu 24.04 LTS Server 64-bit - WordPress on Ubuntu 24.04 LTS Server 64-bit - Nextcloud on Ubuntu 24.04 LTS Server 64-bit - Node.js on Ubuntu 24.04 LTS Server 64-bit - Docker on Ubuntu LTS - cPanel/WHM on AlmaLinux - OctoberCMS on Ubuntu LTS - MySQL on Ubuntu LTS ### Is your Linux VPS hosting cheap? We provide high-quality service at affordable prices. We don't claim to be the cheapest, but always-available phone support, no upfront cost, and post-paid billing keep things very affordable. ## Read More About VPS Hosting ### [VPS Hosting](https://www.atlantic.net/vps-hosting/) - [VPS Hosting](https://www.atlantic.net/vps-hosting/) - [VPS Pricing](https://www.atlantic.net/vps-hosting/pricing/) - [Windows VPS Hosting](https://www.atlantic.net/vps-hosting/windows-vps-hosting/) - [What Is Web Server Hosting?](https://www.atlantic.net/dedicated-server-hosting/what-is-web-server-hosting/) - [WordPress VPS Hosting](https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/) ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." --- # WordPress VPS Hosting > URL: https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/ | Updated: 2026-09-16 Launch a preconfigured WordPress VPS with Linux, MySQL, Apache, and PHP in under 30 seconds, then scale guaranteed CPU, memory, and SSD resources through the Atlantic.Net Cloud Platform. - One-Click WordPress - Full Root Access - Guaranteed VPS Resources - 100% Uptime SLA Deployment Time: Under 30 sec Data Center Locations: 8 ## WordPress VPS Hosting VPS WordPress hosting from Atlantic.Net allows customers to design, manage, and deploy secure, high-performance websites on a WordPress virtual private server in seconds. The Atlantic.Net VPS Cloud offers simplicity, security, scalability, and reliability to improve WordPress performance and reduce costs, built upon our ultra-high-speed hosting environment with fast SSDs and redundant storage. ## What Is WordPress VPS Hosting? WordPress VPS hosting provides a dedicated WordPress instance on a virtual server environment directly to the customer, offering a preconfigured, performance-tuned, security-controlled platform for one or many WordPress websites. ## WordPress VPS Hosting Plans | | | | | | | | | | --- | --- | --- | --- | --- | --- | --- | --- | | General Purpose | G3.2GB | 2GB | 1 | 50GB | 3 TB | On-Demand: $10.0/mo $0.0149/hr; 1-Year: $9.0/mo $0.0134/hr; 3-Year: $8.0/mo $0.0119/hr | On-Demand: $16.5/mo $0.0246/hr; 1-Year: $15.5/mo $0.0231/hr; 3-Year: $15.5/mo $0.0231/hr | | General Purpose | G3.4GB | 4GB | 2 | 80GB | 5 TB | On-Demand: $20.0/mo $0.0298/hr; 1-Year: $18.0/mo $0.0268/hr; 3-Year: $17.0/mo $0.0253/hr | On-Demand: $33.0/mo $0.0491/hr; 1-Year: $31.0/mo $0.0461/hr; 3-Year: $30.0/mo $0.0446/hr | | General Purpose | G3.8GB | 8GB | 4 | 160GB | 6 TB | On-Demand: $40.0/mo $0.0595/hr; 1-Year: $37.0/mo $0.0551/hr; 3-Year: $34.0/mo $0.0506/hr | On-Demand: $66.0/mo $0.0982/hr; 1-Year: $63.0/mo $0.0938/hr; 3-Year: $59.5/mo $0.0885/hr | | General Purpose | G3.16GB | 16GB | 6 | 320GB | 7 TB | On-Demand: $80.0/mo $0.119/hr; 1-Year: $74.0/mo $0.1101/hr; 3-Year: $68.0/mo $0.1012/hr | On-Demand: $132.5/mo $0.1972/hr; 1-Year: $125.5/mo $0.1868/hr; 3-Year: $119.5/mo $0.1778/hr | | General Purpose | G3.32GB | 32GB | 8 | 640GB | 8 TB | On-Demand: $160.0/mo $0.2381/hr; 1-Year: $147.0/mo $0.2188/hr; 3-Year: $136.0/mo $0.2024/hr | On-Demand: $265.0/mo $0.3943/hr; 1-Year: $250.5/mo $0.3728/hr; 3-Year: $238.0/mo $0.3542/hr | | General Purpose | G3.48GB | 48GB | 12 | 960GB | 9 TB | On-Demand: $240.0/mo $0.3571/hr; 1-Year: $220.0/mo $0.3274/hr; 3-Year: $204.0/mo $0.3036/hr | On-Demand: $397.5/mo $0.5915/hr; 1-Year: $375.5/mo $0.5588/hr; 3-Year: $358.5/mo $0.5335/hr | | General Purpose | G3.64GB | 64GB | 16 | 1280GB | 10 TB | On-Demand: $320.0/mo $0.4762/hr; 1-Year: $294.0/mo $0.4375/hr; 3-Year: $272.0/mo $0.4048/hr | On-Demand: $529.5/mo $0.7879/hr; 1-Year: $500.5/mo $0.7448/hr; 3-Year: $477.0/mo $0.7098/hr | | General Purpose | G3.96GB | 96GB | 20 | 1920GB | 11 TB | On-Demand: $480.0/mo $0.7143/hr; 1-Year: $441.6/mo $0.6571/hr; 3-Year: $408.0/mo $0.6071/hr | On-Demand: $795.5/mo $1.1838/hr; 1-Year: $754.5/mo $1.1228/hr; 3-Year: $718.5/mo $1.0692/hr | | General Purpose | G3.128GB | 128GB | 24 | 2560GB | 12 TB | On-Demand: $640.0/mo $0.9524/hr; 1-Year: $589.0/mo $0.8765/hr; 3-Year: $544.0/mo $0.8095/hr | On-Demand: $1,059.0/mo $1.5759/hr; 1-Year: $1,003.0/mo $1.4926/hr; 3-Year: $953.0/mo $1.4182/hr | | General Purpose | G3.192GB | 192GB | 32 | 3840GB | 13 TB | On-Demand: $960.0/mo $1.4286/hr; 1-Year: $883.2/mo $1.3143/hr; 3-Year: $816.0/mo $1.2143/hr | On-Demand: $1,588.5/mo $2.3638/hr; 1-Year: $1,506.5/mo $2.2418/hr; 3-Year: $1,435.5/mo $2.1362/hr | | Compute Optimized | C2.8GB | 8GB | 4 | 40GB | 10 TB | On-Demand: $211.0/mo $0.314/hr; 1-Year: $137.0/mo $0.2039/hr; 3-Year: $67.0/mo $0.0997/hr | On-Demand: $254.5/mo $0.3787/hr; 1-Year: $173.0/mo $0.2574/hr; 3-Year: $96.0/mo $0.1429/hr | | Compute Optimized | C2.16GB | 16GB | 8 | 80GB | 10 TB | On-Demand: $418.0/mo $0.622/hr; 1-Year: $271.0/mo $0.4033/hr; 3-Year: $133.0/mo $0.1979/hr | On-Demand: $505.5/mo $0.7522/hr; 1-Year: $343.0/mo $0.5104/hr; 3-Year: $190.5/mo $0.2835/hr | | Compute Optimized | C2.32GB | 32GB | 16 | 160GB | 10 TB | On-Demand: $828.0/mo $1.2321/hr; 1-Year: $538.0/mo $0.8006/hr; 3-Year: $263.0/mo $0.3914/hr | On-Demand: $1,002.0/mo $1.4911/hr; 1-Year: $682.0/mo $1.0149/hr; 3-Year: $378.0/mo $0.5625/hr | | Compute Optimized | C2.64GB | 64GB | 20 | 350GB | 10 TB | On-Demand: $1,451.0/mo $2.1592/hr; 1-Year: $943.0/mo $1.4033/hr; 3-Year: $461.0/mo $0.686/hr | On-Demand: $1,777.5/mo $2.6451/hr; 1-Year: $1,216.5/mo $1.8103/hr; 3-Year: $685.0/mo $1.0194/hr | | Storage Optimized | S2.16GB | 16GB | 2 | 500GB | 10 TB | On-Demand: $248.0/mo $0.369/hr; 1-Year: $161.0/mo $0.2396/hr; 3-Year: $105.0/mo $0.1563/hr | On-Demand: $317.5/mo $0.4725/hr; 1-Year: $221.5/mo $0.3296/hr; 3-Year: $160.0/mo $0.2381/hr | | Storage Optimized | S2.32GB | 32GB | 4 | 1TB | 10 TB | On-Demand: $425.0/mo $0.6324/hr; 1-Year: $276.0/mo $0.4107/hr; 3-Year: $180.0/mo $0.2679/hr | On-Demand: $557.0/mo $0.8289/hr; 1-Year: $392.5/mo $0.5841/hr; 3-Year: $286.5/mo $0.4263/hr | | Storage Optimized | S2.64GB | 64GB | 8 | 2TB | 10 TB | On-Demand: $778.0/mo $1.1577/hr; 1-Year: $506.0/mo $0.753/hr; 3-Year: $330.0/mo $0.4911/hr | On-Demand: $1,035.0/mo $1.5402/hr; 1-Year: $734.5/mo $1.093/hr; 3-Year: $540.5/mo $0.8043/hr | | Storage Optimized | S2.96GB | 96GB | 12 | 3TB | 10 TB | On-Demand: $1,097.0/mo $1.6324/hr; 1-Year: $713.0/mo $1.061/hr; 3-Year: $465.0/mo $0.692/hr | On-Demand: $1,475.0/mo $2.1949/hr; 1-Year: $1,051.5/mo $1.5647/hr; 3-Year: $777.5/mo $1.157/hr | | Storage Optimized | S2.128GB | 128GB | 16 | 4TB | 10 TB | On-Demand: $1,414.0/mo $2.1042/hr; 1-Year: $919.0/mo $1.3676/hr; 3-Year: $599.0/mo $0.8914/hr | On-Demand: $1,913.0/mo $2.8467/hr; 1-Year: $1,367.0/mo $2.0342/hr; 3-Year: $1,013.5/mo $1.5082/hr | | Memory Optimized | M2.16GB | 16GB | 2 | 40GB | 10 TB | On-Demand: $163.0/mo $0.2426/hr; 1-Year: $106.0/mo $0.1577/hr; 3-Year: $52.0/mo $0.0774/hr | On-Demand: $223.5/mo $0.3326/hr; 1-Year: $161.0/mo $0.2396/hr; 3-Year: $101.5/mo $0.151/hr | | Memory Optimized | M2.32GB | 32GB | 4 | 80GB | 10 TB | On-Demand: $318.0/mo $0.4732/hr; 1-Year: $207.0/mo $0.308/hr; 3-Year: $101.0/mo $0.1503/hr | On-Demand: $439.0/mo $0.6533/hr; 1-Year: $316.5/mo $0.471/hr; 3-Year: $200.0/mo $0.2976/hr | | Memory Optimized | M2.64GB | 64GB | 8 | 160GB | 10 TB | On-Demand: $630.0/mo $0.9375/hr; 1-Year: $409.0/mo $0.6086/hr; 3-Year: $200.0/mo $0.2976/hr | On-Demand: $871.5/mo $1.2969/hr; 1-Year: $627.5/mo $0.9338/hr; 3-Year: $397.5/mo $0.5915/hr | | Memory Optimized | M2.128GB | 128GB | 16 | 350GB | 10 TB | On-Demand: $1,246.0/mo $1.8542/hr; 1-Year: $810.0/mo $1.2054/hr; 3-Year: $396.0/mo $0.5893/hr | On-Demand: $1,727.5/mo $2.5707/hr; 1-Year: $1,246.5/mo $1.8549/hr; 3-Year: $790.0/mo $1.1756/hr | *All plans are available in every location for Managed Server clients. *The hourly rate is determined by dividing the monthly rate by 672 hours (28 days). If your server is online for more than 672 hours in a calendar month, you will only be billed the monthly rate. *Prices listed above are based on the service being utilized for the period specified. *All Servers include one IPv4 Address. Additional IPs are available for $3.65/month ($0.005431/hour) *Unlimited inbound bandwidth. If free outbound bandwidth is exceeded, each additional GB is $0.02 *Optional Daily Backups are available for 20% of the server price. Minimum $1.00/month. *cPanel licensing cost starts at $23 per month ## WordPress VPS Hosting Features ### 100% Uptime SLA Atlantic.Net WordPress servers come with a 100% uptime SLA which includes the following: 100% network uptime SLA with money-back guarantee 100% hardware replacement SLA with money-back guarantee 100% infrastructure uptime SLA with money-back guarantee ### Scale Up Your Cloud Server With Atlantic.Net WordPress VPS hosting, when your business needs more resources to power your server, a simple click or API call lets you increase the processing, memory, and storage to scale up your WordPress site. ### Daily Cloud Backup We'll automatically back up everything stored on your WordPress server once per day for 20% of the server price. There is a minimum $1.00 USD backup charge. Backups are enabled with a simple checkbox, and for an additional fee, backup data can be replicated to any Atlantic.Net data center. ### Snapshots Snapshots save a point-in-time copy of your cloud server's local storage. You can use snapshots to restore your server to the point in time when the snapshot was taken, transfer a copy of your snapshot to another location, or create a new server from a snapshot – making it easier to configure a geo-redundant WordPress site. ### Freedom and Flexibility We believe in giving our members freedom and flexibility with hourly and monthly VPS WordPress hosting pricing, plus discounted pricing with longer-term commitments. No contract required. ### RAID-10 Cloud Storage Atlantic.Net's redundant architecture keeps your VPSes and apps available even when components misbehave. Backed by storage-optimized servers with strong disk performance, our VPS hosting plans are ready to handle I/O-intensive applications. VPS plans also include flexible disk storage sizes, types, and speeds, including local SSD storage and Secure Block Storage (SBS). You can allocate up to 4 TB of SSD storage locally or up to 16 TB using SBS. ### WordPress VPS IP Address Our VPS hosting includes one public IPv4 address per server and one private IPv4 range as standard. Additional public IPv4 addresses are available for $3.65/month ($0.005431/hour). Additional IPv6 addresses are free of charge and available in all Atlantic.Net Cloud locations. ### Improved Performance with Guaranteed Resources Guaranteed dedicated resources. Atlantic.Net WordPress VPS offers guaranteed system resources 24/7. We not only guarantee access to the CPU cycles you are paying for when you need them – you can also burst to use additional CPU cycles when they are not in use. ### RESTful API Power and scale web applications easily using Atlantic.Net's RESTful Application Program Interface for VPS hosting. ### Fully Managed Service Want to manage just the content of your site and have someone else handle the operating system, security updates, and performance? We offer an array of fully managed services for your WordPress VPS. With our managed services you get access to an expert team of engineers ready to keep your server updated, secure, optimised, and highly available. Contact our sales team to learn more about how managed services can save you time. ### Simple Licensing With the Atlantic.Net one-click application, there are no license fees to consider. The WordPress virtual private server is a completely open-source platform, meaning it costs you nothing to license. ## One-Click WordPress VPS Hosting Our WordPress VPS hosting options are available across a large range of configuration plans – small, medium, or large setups, compute-tuned with high memory availability, or with multiple high-end CPU configurations. In less than 30 seconds, you can launch Atlantic.Net's one-click WordPress application on the Atlantic.Net Cloud Platform at one of our eight data center locations. Our one-click WordPress VPS hosting is configured with an up-to-date Linux operating system, a secure MySQL database, an Apache web server frontend, and PHP optimised for security and performance. You get root access to the server and full access to the control panel. ## Setting Up a WordPress VPS Server Is as Simple as 1, 2, 3 Our one-click WordPress hosting is easy. - Log in to cloud.atlantic.net and click "Add Server." Don't have an account? Sign up here. - On the "Add Server" page, give your server a name, click on the "Applications" tab and select WordPress, choose your data center location, choose a server plan, and select whether you want SSH or cloud backups. - Click "Create Server" and your WordPress VPS will be ready in under 30 seconds. ## WordPress VPS Hosting Q&A ### What are the benefits of using Atlantic.Net's WordPress VPS hosting? It offers strong performance, scalability, reliability, and security, allowing you to design, manage, and deploy WordPress websites quickly and efficiently. We have data center locations throughout the United States, Canada, Europe, and Asia. ### What is the uptime guarantee Atlantic.Net provides for its WordPress servers? Each of our data center locations is built to high standards of failover and redundancy. We are confident in our platform and offer a 100% uptime SLA, which covers network uptime, hardware replacement, and infrastructure uptime, all backed by a money-back guarantee. ### How can I scale my WordPress site on Atlantic.Net's VPS hosting? You can easily scale up your server's resources (CPU, memory, storage) with a simple click or API call to accommodate your growing business needs. ### What storage options are available for Atlantic.Net's VPS plans? You have flexible disk storage sizes, types, and speeds, including local SSD storage and Secure Block Storage (SBS). You can allocate up to 4 TB of SSD storage locally or up to 16 TB using SBS. ### How easy is it to set up a WordPress VPS server on Atlantic.Net? It's straightforward. We offer one-click WordPress hosting, allowing you to launch a WordPress application in under 30 seconds with a pre-configured Linux operating system, MySQL database, Apache web server, and PHP (LAMP stack). ## A Support Team Backed by Decades of Experience With over three decades of experience, our support team is always here to assist you. You’ll have 24/7/365 access to a crop of dedicated veterans, capable of solving any technical problem you throw their way. ## Cloud Availability in Multiple Global Regions Deploy close to your users from eight international data centers worldwide, with new regions on the way. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." --- # How to Install pgAdmin on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-pgadmin-on-arch-linux/ | Published: 2023-03-28 | Updated: 2023-11-14 | Author: Hitesh Jethva pgAdmin is an open-source platform for managing PostgreSQL servers via GUI. It is a cross-platform solution that enables businesses to create, view, and modify PostgreSQL objects. It offers a simple and user-friendly web-UI to interact with the Postgres database sessions. If you are looking for an open-source administration panel for managing PostgreSQL, then pgAdmin is the best choice for you. In this post, we will show you how to install pgAdmin on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install PostgreSQL By default, the PostgreSQL package is included in the Arch Linux main repository. You can install it using the following command: ``` pacman -S postgresql ``` Once the PostgreSQL is installed, you can verify the PostgreSQL version using the following command: ``` postgres --version ``` You will get the following output: ``` postgres (PostgreSQL) 15.1 ``` Next, initialize the PostgreSQL database with the following command: ``` sudo -u postgres initdb --locale en_US.UTF-8 -D /var/lib/postgres/data ``` Next, start the PostgreSQL service using the following command. ``` systemctl start postgresql ``` By default, there is not any password for postgres user. To set it, log in with Postgres user and set the password using the following command: ``` su - postgres psql -c "alter user postgres with password 'password'" ``` Next, exit from the PostgreSQL shell with the following command. ``` exit ``` ## Step 3 – Install pgAdmin First, install the PIP package using the following command. ``` pacman -S python-pip ``` Next, update the setuptools package to the latest version. ``` python -m pip install --upgrade setuptools ``` Next, install the pgAdmin4 package using the PIP command. ``` pip install pgadmin4 ``` Once pgAdmin is installed you can proceed to the next step. ## Step 4 – Start pgAdmin Next, run the following command to start the pgAdmin4. ``` pgadmin4 ``` You will be asked to set a user and password as shown below to start the server. NOTE: Configuring authentication for SERVER mode. Enter the email address and password to use for the initial pgAdmin user account: Email address: hitjethva@gmail.com Password: Retype password: pgAdmin 4 – Application Initialisation ================= Starting pgAdmin 4. Please navigate to http://127.0.0.1:5050 in your browser. 2023-02-06 05:58:30,522: WARNING werkzeug: WebSocket transport not available. Install simple-websocket for improved performance. * Serving Flask app ‘pgadmin’ (lazy loading) * Environment: production WARNING: This is a development server. Do not use it in a production deployment. Use a production WSGI server instead. * Debug mode: off Note: Don’t do anything on this terminal because it will stop the pgAdmin4 server. ## Step 5 – Install Nginx for pgAdmin4 At this point, pgAdmin is started and listens on port 5050. Now, you will need to configure Nginx as a reverse proxy to access the pgAdmin web UI. Open another terminal and install the Nginx with the following command. ``` pacman -S nginx ``` Next, edit the Nginx configuration file: ``` nano /etc/nginx/nginx.conf ``` Add the following line above the last line: ``` server { listen 8080; server_name _; location / { proxy_pass http://127.0.0.1:5050; } } ``` Save and close the file, then restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 6 – Access pgAdmin4 Web UI Now, open your web browser and access the pgAdmin4 web interface using the URL **http://your-server-ip:8080.** You should see the pgAdmin4 login screen. ![pgAdmin login page](https://www.atlantic.net/wp-content/uploads/2023/02/p1-4-1024x482.png) Provide your email address and password and click on the **Login** button. You should see the pgAdmin default dashboard on the following screen: ![pgAdmin dashboard page](https://www.atlantic.net/wp-content/uploads/2023/02/p2-3-1024x502.png) Next, click on the **Add New Server** button. You should see the following screen: ![pgAdmin define server name](https://www.atlantic.net/wp-content/uploads/2023/02/p3-1.png) In the **General** tab, provide the name of the server and click on the **Connection** tab. You should see the following screen: ![pgAdmin connection page](https://www.atlantic.net/wp-content/uploads/2023/02/p4.png) Provide the Hostname or IP address of the server that you want to connect to, as well as the Port number, PostgreSQL username, and password, and click on the **Save** button. Once the connection has been established, you should see the detailed information about your PostgreSQL database in the left pane: ![pgAdmin connected](https://www.atlantic.net/wp-content/uploads/2023/02/p5-1024x503.png) ## Conclusion In this post, you learned how to install pgAdmin4 on Arch Linux. You can now use pgAdmin4 to connect any remote PostgreSQL server and manage it via a web interface. You can try the pgAdmin on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Apache Spark on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-spark-on-arch-linux/ | Published: 2023-03-29 | Updated: 2023-11-16 | Author: Hitesh Jethva Apache Spark is a data processing framework used for executing data engineering, data science, and machine learning on single-node machines or clusters. It is designed for fast computation and used in big data workloads to quickly perform processing tasks. It provides high-level APIs in Scala, Java, Python, and R, and an optimized engine that supports general computation graphs for data analysis. In this tutorial, we will explain how to install Apache Spark on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Java Apache Spark is based on Java, so you will need to install Java JDK on your server. Run the following command to install Java: ``` pacman -S jre17-openjdk ``` Once installed, you can verify the Java installation using the following command. ``` java --version ``` You will get the following output. ``` openjdk 17.0.6 2023-01-17 OpenJDK Runtime Environment (build 17.0.6+10) OpenJDK 64-Bit Server VM (build 17.0.6+10, mixed mode) ``` ## Step 3 – Install Scala You will also need to install Scala on your server. You can install it using the following command. ``` pacman -S scala ``` After the installation, verify the Scala version: ``` scala --version ``` Sample output. ``` Scala code runner version 2.13.8-20220325-005602-unknown -- Copyright 2002-2021, LAMP/EPFL and Lightbend, Inc. ``` To connect to the Scala console, run the following command. ``` scala ``` You will get the following console. ``` Welcome to Scala 2.13.8-20220325-005602-unknown (OpenJDK 64-Bit Server VM, Java 17.0.6). Type in expressions for evaluation. Or try :help. ``` Verify Scala using the following command. ``` scala> println("Testing") ``` Sample output. ``` Testing ``` ## Step 4 – Install Apache Spark First, visit the Apache Spark download page, pick the download URL, and download it with the following command. ``` wget https://archive.apache.org/dist/spark/spark-3.3.1/spark-3.3.1-bin-hadoop3.tgz ``` Once the download is completed, extract the downloaded file using the following command. ``` tar -xzf spark-3.3.1-bin-hadoop3.tgz ``` Next, move the extracted directory to /mnt. ``` mv spark-3.3.1-bin-hadoop3 /mnt/spark ``` Next, create a ~/.bashrc file and define your Apache Spark path. ``` nano ~/.bashrc ``` Add the following lines: ``` export SPARK_HOME=/mnt/spark export PATH=$PATH:$SPARK_HOME/bin:$SPARK_HOME/sbin ``` Next, activate the environment variable using the following command. ``` source ~/.bashrc ``` ## Step 5 – Start Spark Master and Worker Node At this point, Apache Spark is installed on your server. You can now start the Spark master with the following command. ``` start-master.sh ``` Sample output. ``` starting org.apache.spark.deploy.master.Master, logging to /mnt/spark/logs/spark-root-org.apache.spark.deploy.master.Master-1-archlinux.out ``` By default, Spark master listens on port 8080. You can check it with the following command. ``` ss -tpln | grep 8080 ``` Sample output. ``` LISTEN 0 0 *:8080 *:* users:(("java",pid=57901,fd=265)) ``` Now, open your web browser and access the Spark master using the URL **http://your-server-ip:8080.** You should see the following screen. ![Spark master dashboard](https://www.atlantic.net/wp-content/uploads/2023/02/p1-5-1024x470.png) Next, start the Spark Worker using the following command. ``` start-worker.sh spark://your-server-ip:7077 ``` Now, go back to the Spark master web interface and reload the page. You should see the added worker on the following screen. ![Worker added to the master dashboard](https://www.atlantic.net/wp-content/uploads/2023/02/p2-4-1024x475.png) ## Step 6 – Create a Systemd Service File for Apache Spark Before creating systemd service file, stop both the worker and master service using the following command. ``` stop-worker.sh stop-master.sh ``` Next, create a Spark master service using the following command. ``` nano /etc/systemd/system/spark-master.service ``` Add the following configuration. ``` [Unit] Description=Apache Spark Master After=network.target [Service] Type=forking User=root Group=root ExecStart=/mnt/spark/sbin/start-master.sh ExecStop=/mnt/spark/sbin/stop-master.sh [Install] WantedBy=multi-user.target ``` Next, create a Spark worker service file. ``` nano /etc/systemd/system/spark-worker.service ``` Add the following configuration. ``` [Unit] Description=Apache Spark Worker After=network.target [Service] Type=forking User=root Group=root ExecStart=/mnt/spark/sbin/start-slave.sh spark://your-server-ip:7077 ExecStop=/mnt/spark/sbin/stop-slave.sh [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start both the Master and Worker services using the following command. ``` systemctl start spark-master spark-worker ``` You can check the status of both services using the following command. ``` systemctl status spark-master spark-worker ``` You should see the following output. ``` ● spark-master.service - Apache Spark Master Loaded: loaded (/etc/systemd/system/spark-master.service; disabled; preset: disabled) Active: active (running) since Mon 2023-02-06 05:28:09 UTC; 19s ago Process: 58118 ExecStart=/mnt/spark/sbin/start-master.sh (code=exited, status=0/SUCCESS) Main PID: 58151 (java) Tasks: 34 (limit: 4700) Memory: 159.2M CGroup: /system.slice/spark-master.service └─58151 /usr/lib/jvm/java-17-openjdk/bin/java -cp "/mnt/spark/conf/:/mnt/spark/jars/*" -Xmx1g org.apache.spark.deploy.master.Mas> Feb 06 05:28:06 archlinux systemd[1]: Starting Apache Spark Master... Feb 06 05:28:06 archlinux start-master.sh[58131]: starting org.apache.spark.deploy.master.Master, logging to /mnt/spark/logs/spark-root-org.a> Feb 06 05:28:09 archlinux systemd[1]: Started Apache Spark Master. ● spark-worker.service - Apache Spark Worker Loaded: loaded (/etc/systemd/system/spark-worker.service; disabled; preset: disabled) Active: active (running) since Mon 2023-02-06 05:28:09 UTC; 19s ago Process: 58119 ExecStart=/mnt/spark/sbin/start-slave.sh spark://your-server-ip:7077 (code=exited, status=0/SUCCESS) Main PID: 58157 (java) Tasks: 40 (limit: 4700) Memory: 170.5M CGroup: /system.slice/spark-worker.service └─58157 /usr/lib/jvm/java-17-openjdk/bin/java -cp "/mnt/spark/conf/:/mnt/spark/jars/*" -Xmx1g org.apache.spark.deploy.worker.Wor> Feb 06 05:28:06 archlinux systemd[1]: Starting Apache Spark Worker... Feb 06 05:28:06 archlinux start-slave.sh[58119]: This script is deprecated, use start-worker.sh Feb 06 05:28:06 archlinux start-slave.sh[58133]: starting org.apache.spark.deploy.worker.Worker, logging to /mnt/spark/logs/spark-root-org.ap> Feb 06 05:28:09 archlinux systemd[1]: Started Apache Spark Worker. ``` ## Conclusion In this post, you learned how to install Apache Spark on Arch Linux. You can now use Apache Spark in data science, and machine learning project to handle high workloads. You can try to install the Apache Spark server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Atlantic.Net Referral Program > URL: https://www.atlantic.net/cloud-referral-program/ | Updated: 2026-09-16 ## $15 credit for them & a $30 credit for you! Help us spread the word! Anyone you refer gets a $15 credit. Once they sign up and spend $30, you'll get a $30 credit. The more you refer, the more you can earn! ## How it works ### Tell your friends or site visitors about our cloud services ### They sign up using your referral link and get a $15 credit. ### You earn a $30 credit when they spend $30 with us. If you don't have an account, [sign up at cloud.atlantic.net](https://cloud.atlantic.net/?page=signup) to get your referral link. You can also download our logos and badges on the [press room logos page](https://www.atlantic.net/press-room/logos/). ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # How to Install Prometheus on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-prometheus-on-arch-linux/ | Published: 2023-03-30 | Updated: 2023-11-18 | Author: Hitesh Jethva Prometheus is a free and open-source monitoring solution written in the Go language. It was developed by SoundCloud and adopted by CNCF in 2016. It collects metrics data from HTTP endpoints and stores that data in a time series database. Prometheus helps system administrators diagnose problems. It is an independent service and does not need to rely on remote services like network storage. In this post, we will show you how to install Prometheus monitoring solution on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list if you have not done so already. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Prometheus Arch Linux By default, the Prometheus package is included in the Arch Linux default repository. You can install it using the following command. ``` pacman -S prometheus ``` After installing Prometheus, start the Prometheus service and enable it to start at system reboot. ``` systemctl start prometheus systemctl start prometheus ``` To verify the Prometheus service status, run the following command. ``` systemctl status prometheus ``` You should see the following output. ``` ● prometheus.service - Prometheus service Loaded: loaded (/usr/lib/systemd/system/prometheus.service; disabled; preset: disabled) Active: active (running) since Mon 2023-02-06 08:17:38 UTC; 7s ago Main PID: 57007 (prometheus) Tasks: 6 (limit: 2362) Memory: 29.4M CGroup: /system.slice/prometheus.service └─57007 /usr/bin/prometheus --config.file=/etc/prometheus/prometheus.yml --storage.tsdb.path=/var/lib/prometheus/data Feb 06 08:17:38 archlinux prometheus[57007]: ts=2023-02-06T08:17:38.749Z caller=tls_config.go:232 level=info component=web msg="Listening on"> Feb 06 08:17:38 archlinux prometheus[57007]: ts=2023-02-06T08:17:38.749Z caller=tls_config.go:235 level=info component=web msg="TLS is disabl> Feb 06 08:17:38 archlinux prometheus[57007]: ts=2023-02-06T08:17:38.749Z caller=head.go:683 level=info component=tsdb msg="WAL segment loaded> Feb 06 08:17:38 archlinux prometheus[57007]: ts=2023-02-06T08:17:38.749Z caller=head.go:720 level=info component=tsdb msg="WAL replay complet> Feb 06 08:17:38 archlinux prometheus[57007]: ts=2023-02-06T08:17:38.751Z caller=main.go:1014 level=info fs_type=EXT4_SUPER_MAGIC Feb 06 08:17:38 archlinux prometheus[57007]: ts=2023-02-06T08:17:38.751Z caller=main.go:1017 level=info msg="TSDB started" Feb 06 08:17:38 archlinux prometheus[57007]: ts=2023-02-06T08:17:38.751Z caller=main.go:1197 level=info msg="Loading configuration file" file> Feb 06 08:17:38 archlinux prometheus[57007]: ts=2023-02-06T08:17:38.786Z caller=main.go:1234 level=info msg="Completed loading of configurati> Feb 06 08:17:38 archlinux prometheus[57007]: ts=2023-02-06T08:17:38.786Z caller=main.go:978 level=info msg="Server is ready to receive web re> Feb 06 08:17:38 archlinux prometheus[57007]: ts=2023-02-06T08:17:38.786Z caller=manager.go:953 level=i ``` At this point, Prometheus is installed and listens on port 9090. You can verify it using the following command. ``` ss -antpl | grep prometheus ``` You will get the following output. ``` LISTEN 0 0 *:9090 *:* users:(("prometheus",pid=57007,fd=7)) ``` ## Step 3 – Configure Nginx as a Reverse Proxy for Prometheus It is always a good idea to use Nginx as a reverse proxy to access Prometheus at port 80. First, install the Nginx package using the following command. ``` pacman -S nginx ``` Once installed, start and enable the Nginx service using the following command. ``` systemctl start nginx systemctl enable nginx ``` Next, create a directory to store the Nginx configuration. ``` mkdir /etc/nginx/sites-enabled ``` Next, you will need to define your directory in the Nginx configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following lines below the line http{: ``` include sites-enabled/*; server_names_hash_bucket_size 64; ``` Next, create an Nginx virtual host configuration file with the following command: ``` nano /etc/nginx/sites-enabled/prometheus.conf ``` Add the following configuration. ``` server { listen 80; server_name prometheus.example.com; location / { proxy_pass http://127.0.0.1:9090; } } ``` Save and close the file, then verify the Nginx for any syntax configuration error: ``` nginx -t ``` You will get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 4 – Access Prometheus Web UI At this point, Prometheus is installed on your server. You can now access it using the URL **http://prometheus.example.com.** You should see the Prometheus dashboard on the following screen. ![prometheus dashboard](https://www.atlantic.net/wp-content/uploads/2023/02/p1-6-1024x465.png) ## Conclusion In this tutorial, we explained how to install Prometheus on Arch Linux. You can now implement the Prometheus monitoring tool in your server environment and start monitoring metrics of all servers and applications from the central location. You can test the Prometheus server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Strapi with Nginx on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-strapi-with-nginx-on-arch-linux/ | Published: 2023-03-31 | Updated: 2023-11-17 | Author: Hitesh Jethva Strapi is a free, open-source, and headless content management system built with JavaScript. Compared to other CMS, Strapi doesn’t provide a front-end. You will need to rely on API to design your content structure. Strapi provides an easier way to build your website, integrating with popular frameworks like React and Next.js. This post will show you how to install the Strapi App on Arch Linux. ## Prerequisites - An **IPV6 IP address** associated with your instance ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Node.js Before starting, you will need to install Node.js on your server. First, install NVM with the following command. ``` curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.2/install.sh | bash ``` Once NVM is installed, you should see the following output. ``` export NVM_DIR="$HOME/.nvm" [ -s "$NVM_DIR/nvm.sh" ] && \. "$NVM_DIR/nvm.sh" # This loads nvm => Close and reopen your terminal to start using nvm or run the following to use it now: ``` Next, activate the NVM environment variable using the following command. ``` export NVM_DIR="$HOME/.nvm" [ -s "$NVM_DIR/nvm.sh" ] && \. "$NVM_DIR/nvm.sh" # This loads nvm ``` Now, install the latest version of Node.js with the following command. ``` nvm install --lts ``` You will get the following output. ``` Installing latest LTS version. Downloading and installing node v18.14.2... Downloading https://nodejs.org/dist/v18.14.2/node-v18.14.2-linux-x64.tar.xz... ####################################################################################################################################### 100.0% Computing checksum with sha256sum Checksums matched! Now using node v18.14.2 (npm v9.5.0) Creating default alias: default -> lts/* (-> v18.14.2) ``` Next, find the location of Node.js with the following command. ``` which node ``` Output. ``` /root/.nvm/versions/node/v18.14.2/bin/node ``` Next, create a symbolic link of Node.js with the following command. ``` ln -s /root/.nvm/versions/node/v18.14.2/bin/node /usr/bin/node ``` ## Step 3 – Install and Configure PostgreSQL If you want to use a database for the Strapi, you will need to install PostgreSQL on your server. You can install it with the following command. ``` pacman -S postgresql ``` Next, initialize the PostgreSQL database with the following command. ``` sudo -u postgres initdb --locale en_US.UTF-8 -D /var/lib/postgres/data ``` Next, start and enable the PostgreSQL service with the following command. ``` systemctl start postgresql systemctl enable postgresql ``` Next, connect to the PostgreSQL shell: ``` sudo -u postgres psql ``` Next, set the Postgres password and create a database with the following command. ``` ALTER USER postgres PASSWORD 'password'; create database project; ``` Finally, exit from the PostgreSQL shell with the following command. ``` \q ``` ## Step 4 – Install Strapi You can use the npx command line tool to install Strapi on your server. ``` npx create-strapi-app@latest project --no-run ``` You will be asked to select the installation type: ``` ? Choose your installation type (Use arrow keys) ❯ Quickstart (recommended) Custom (manual settings) ``` Select your installation type and press the Enter key to finish the installation. ``` ? Choose your installation type Quickstart (recommended) Creating a quickstart project. Creating a new Strapi application at /root/project. Creating files. Dependencies installed successfully. Your application was created at /root/project. Available commands in your project: npm run develop Start Strapi in watch mode. (Changes in Strapi project files will trigger a server restart) npm run start Start Strapi without watch mode. npm run build Build Strapi admin panel. npm run strapi Display all available commands. You can start by doing: npm run develop cd /root/project ``` Next, navigate to your project directory and build your application with the following command. ``` cd project npm run build ``` You will get the following output. ``` > project@0.1.0 build > strapi build Building your admin UI with development configuration... ✔ Webpack Compiled successfully in 25.78s Admin UI built successfully ``` Next, edit the server.js file. ``` nano ./config/server.js ``` Make the following changes. ``` module.exports = ({ env }) => ({ host: env('HOST', '0.0.0.0'), port: env.int('PORT', 1337), url: 'http://app.example.com', app: { keys: env.array('APP_KEYS'), }, }); ``` Save and close the file, then run your Strapi app with the following command. ``` npm run develop ``` You should see the following output. ``` [2023-02-24 09:25:18.097] info: The Users & Permissions plugin automatically generated a jwt secret and stored it in .env under the name JWT_SECRET. Project information ┌────────────────────┬──────────────────────────────────────────────────┐ │ Time │ Fri Feb 24 2023 09:25:19 GMT+0000 (Coordinated … │ │ Launched in │ 2503 ms │ │ Environment │ development │ │ Process PID │ 76628 │ │ Version │ 4.6.2 (node v18.14.2) │ │ Edition │ Community │ │ Database │ sqlite │ └────────────────────┴──────────────────────────────────────────────────┘ Actions available One more thing... Create your first administrator 💻 by going to the administration panel at: ┌──────────────────────────────┐ │ http://app.example.com/admin │ └──────────────────────────────┘ ``` Press the CTRL+C to stop the application. ## Step 5 – Create a Systemd Service File for Strapi Next, you must create a systemd file to manage the Strapi service. You can create it with the following command. ``` nano /etc/systemd/system/strapi.service ``` Add the following configuration. ``` [Unit] Description=Strapi Project After=network.target [Service] Type=simple WorkingDirectory=/root/project User=root ExecStart=/usr/bin/node /root/project/node_modules/.bin/strapi develop [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the Strapi service with the following command. ``` systemctl start strapi systemctl enable strapi ``` You can check the status of the Strapi service with the following command. ``` systemctl status strapi ``` You should see the following output. ``` ● strapi.service - Strapi Project Loaded: loaded (/etc/systemd/system/strapi.service; disabled; preset: disabled) Active: active (running) since Fri 2023-02-24 09:33:23 UTC; 59s ago Main PID: 76830 (node) Tasks: 18 (limit: 4700) Memory: 235.3M CGroup: /system.slice/strapi.service ├─76830 /usr/bin/node /root/project/node_modules/.bin/strapi develop └─76837 /root/.nvm/versions/node/v18.14.2/bin/node /root/project/node_modules/.bin/strapi develop Feb 24 09:33:30 archlinux node[76837]: │ Version │ 4.6.2 (node v18.14.2) │ Feb 24 09:33:30 archlinux node[76837]: │ Edition │ Community │ Feb 24 09:33:30 archlinux node[76837]: │ Database │ sqlite │ Feb 24 09:33:30 archlinux node[76837]: └────────────────────┴──────────────────────────────────────────────────┘ Feb 24 09:33:30 archlinux node[76837]: Actions available Feb 24 09:33:30 archlinux node[76837]: One more thing... Feb 24 09:33:30 archlinux node[76837]: Create your first administrator 💻 by going to the administration panel at: Feb 24 09:33:30 archlinux node[76837]: ┌──────────────────────────────┐ Feb 24 09:33:30 archlinux node[76837]: │ http://app.example.com/admin │ Feb 24 09:33:30 archlinux node[76837]: └──────────────────────────────┘ ``` ## Step 6 – Configure Nginx for Strapi App Next, you must install and configure Nginx as a reverse proxy for Strapi App. First, install the Nginx package with the following command. ``` pacman -S nginx-mainline ``` After the successful installation, create a directory to store Nginx virtual host files. ``` mkdir /etc/nginx/sites-enabled ``` Next, create a Strapi virtual host configuration file. ``` nano /etc/nginx/sites-enabled/strapi.conf ``` Add the following configuration. ``` # Strapi server upstream strapi { server 127.0.0.1:1337; } server { listen 80; server_name app.example.com; # Proxy Config location / { proxy_pass http://strapi; proxy_http_version 1.1; proxy_set_header X-Forwarded-Host $host; proxy_set_header X-Forwarded-Server $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header Host $http_host; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "Upgrade"; proxy_pass_request_headers on; } } ``` Save and close the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following lines after http{: ``` server_names_hash_bucket_size 64; include sites-enabled/*; ``` Save and close the file, then verify the Nginx configuration using the following command. ``` nginx -t ``` You should see the following output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart Nginx to apply the changes. ``` systemctl restart nginx ``` ## Step 7 – Access Strapi Web Interface Now, open your web browser and access the Strapi web UI using the URL **http://app.example.com/admin.** You should see the Strapi default page on the following screen. ![Strapi registration page](https://www.atlantic.net/wp-content/uploads/2023/02/p1-7.png) Provide your name, email, and password then click on the **Let’s start** button. You should see the Strapi dashboard on the following screen. ![Strapi dashboard page](https://www.atlantic.net/wp-content/uploads/2023/02/p2-5-1024x507.png) ## Conclusion In this post, you learned how to install the Strapi on Arch Linux. You also learned how to use Nginx as a reverse proxy for the Strapi. You can now create your own application using Strapi and deploy it on the live server. You can now try to deploy Strapi on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Ensure Your Veeam Backups Are Not Vulnerable to Ransomware > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-ensure-your-veeam-backups-are-not-vulnerable-to-ransomware/ | Published: 2023-04-05 | Updated: 2025-09-15 | Author: Richard Bailey Veeam Backup & Replication is an enterprise-grade backup platform from Veeam Software that provides an industry-leading data protection suite for virtual and physical workloads. Atlantic.Net has partnered with Veeam Software and integrated our [Managed Veeam Service](https://www.atlantic.net/managed-services/veeam-services/) into most of our cloud and on-premise hosting solutions. Data protection is an essential business practice to uphold the integrity of mission-critical business data. Daily backups are the minimum requirement of most businesses. Personal users can also reap the benefits of a sensible backup solution to keep hold of precious files or treasured family photographs. Ransomware is a serious and growing concern. Ransomware attacks can render files and folders useless as they become encrypted, making them impossible to access unless a ransom for the decryption key is paid to the threat actor. In addition, it’s possible the ransomware attack may not be identified immediately, resulting in the infected files being backed up automatically as part of a predefined backup schedule. The worst-case scenario is when the data is restored, but the backup is infected with ransomware, and critical files are encrypted and inaccessible. In this article, we will discover the advanced protections offered in Veeam that specifically target ransomware, and we will learn how Atlantic.Net hosting services offer world-class protection against ransomware. ## How Does Ransomware Threaten Data Protection? A [secure backup](https://www.atlantic.net/cloud-platform/backups/) is considered the last line of defense against ransomware. If all else fails, at least you have a good backup to restore. Consider what would happen if your backup was a dud. Would you pay the ransom? The U.S. government advises never to pay the ransom simply because it encourages hackers to continue these campaigns. Businesses should make backup planning part of their cybersecurity defense plan. It requires backups to be planned, tested, and regularly reviewed to maintain a robust security posture. If you’re in the IT industry or work in an IT-adjacent role, you may have frequently heard, “oh, just restore it from backup” as a solution. Unfortunately, sometimes the solution is not that simple, especially when swathes of critical business infrastructure have been taken down by ransomware. For these reasons, it is essential to have a backup solution that protects against ransomware infecting your server backups. ## How to Amend Your Backup Strategy to Defend Against Ransomware The first step in defending against ransomware in your backups is to review your existing backup schedule in great detail. It is essential to introduce procedural best practices when managing backups. This should include: - **Review Existing Backup Schedule:** Take time to review the existing backup configuration. Ensure all in-scope servers are backed up correctly and that you have selected the required disk or VM-level backup. Ask yourself which disks need backup. Do you need a copy of the system state? - **Check Your Backup Start and Finish Times:** Check that your backups start within the start window and finish when expected. Treat a missed backup the same as a failed backup. - **Always Alert Against Backup Failures:** Any backup issues should be alerted against and resolved by a support team. If the backup fails, do you need to re-run it manually? Has the backup failed or over-run? - **Educate Your Employees:** Training staff about the latest cybersecurity threats is a great way to improve the business’s security posture. Employees are the human firewall. They protect your business from phishing, social engineering, and accidental disclosure (all key attack vectors for hackers), so ensuring they are well-trained will improve security. - **Follow the 3-2-1 Rule of Backups:** This rule is[fundamental to data protection](https://www.atlantic.net/disaster-recovery/what-is-a-3-2-1-backup-strategy/) because it offers the best protection for mission-critical data. There should be at least *three*copies of important data, on at least *two*different types of media, with at least *one*of these copies being offsite. To defend against ransomware, Veeam recommends introducing an “air-gapped, offline or immutable” backup – this means a copy of your organization’s data that’s offline and inaccessible. Your backup device can’t be remotely hacked or corrupted without an internet or other network connection. ## How Can Veeam Protect Against Ransomware? Veeam has several built-in protections that combine to create additional layers of security to help defend against ransomware. Ultra-resilient media underlines ransomware protection. We have already mentioned offline, air-gapped and immutable backups. This is achieved by leveraging immutable backups from your cloud provider or by using a hardened repository for the data. If you are still using tape backups, use tapes that support WORM (Write Once Read Many). In extreme cases, you may want to consider removable disk media or rotation of backup drives – however, this method is costly. Other ways Veeam can protect against ransomware are: - **Use the Veeam Backup Schedule:** Your business’s backup schedule defines what protection you enforce. Data retention dictates how long backup media is kept and in what data cycle. The most common methods are daily, weekly, monthly, and yearly backups. Where you save, the weekly and monthly are essential. Do you keep them offline? Do you commit to an offsite location? Do you send a tape backup offsite to a secured location? - **Trusted Immutability:** Veeam supports multiple storage layers locally and in the cloud. Having a secured hardened repository onsite and then offloading data to a multi-site cloud provider like Atlantic.Net would fulfill trusted immutability. Veeam refers to this as ‘copy mode’ and ‘move mode.’ - **Backup Verification:** Knowing that you have a good backup is critical when restoring data. Reviewing logs and backup reports is possible, but verifying the data is the only way to be entirely confident of a good backup. You could perform a test restore, but this is a lengthy process. Veeam uses a tool called SureBackup that runs multiple tests on your backups to confirm the data is malware free and that the data can be recovered. ## Atlantic.Net Veeam Managed Service Atlantic.Net is a global cloud services provider with over 25 years of experience, specializing in Windows, Linux, and FreeBSD server hosting. [Veeam Backup](https://www.atlantic.net/managed-services/veeam-services/) is used extensively throughout the business, and we are delighted with its performance and the protection standards it affords. Atlantic.Net provides business-class [dedicated](https://www.atlantic.net/dedicated-server-hosting/) and [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions focusing on security, compliance, and simplifying the user experience. Atlantic.Net offers fully-managed environments, security, and compliance-focused solutions across all its hosting facilities in San Francisco, New York, London, Toronto, Dallas, Ashburn, and Orlando. With a range of certifications, along with SSAE 18, SOC 2, SOC 3, HIPAA, and HITECH-audited data center infrastructure, Atlantic.Net is a security-first provider. For more information, please visit [www.atlantic.net](https://www.atlantic.net). --- # How to Install React.js with Nginx on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-react-js-with-nginx-on-arch-linux/ | Published: 2023-04-08 | Updated: 2023-11-17 | Author: Hitesh Jethva React is a free and open-source JavaScript library used for creating a web front-end. Its declarative, efficient, and flexible library allows you to compose complex UIs from small and isolated pieces. It is developed by Facebook and maintained by Meta and a community of individual developers and companies. You can use React.js with server-side, client, and other frameworks. This post will explain how to install React.js with Nginx on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Nodejs and NPM First, you will need to install the Nodejs and NPM on your server. You can install both packages using the following command. ``` pacman -S nodejs npm ``` After the installation, you can verify Nodejs with the following command. ``` node --version ``` ## Step 3 – Install create-react-app Next, you will need to install the **create-react-app** package on your server. You can install it using NPM: ``` npm install -g create-react-app ``` After the installation, you can verify the installation using the following command. ``` create-react-app --version ``` ## Step 4 – Create a React App Next, you will need to install all tools needed to run React app. First, create a new React app using the create-react-app command. ``` create-react-app web-app ``` Once the application is created, you should see the following output. ``` Success! Created web-app at /root/web-app Inside that directory, you can run several commands: npm start Starts the development server. npm run build Bundles the app into static files for production. npm test Starts the test runner. npm run eject Removes this tool and copies build dependencies, configuration files and scripts into the app directory. If you do this, you can’t go back! We suggest that you begin by typing: cd web-app npm start Happy hacking! ``` ## Step 5 – Start React App Next, navigate to the web-app directory and start the React app using the following command. ``` cd web-app npm start ``` You should see the following output. ``` Compiled successfully! You can now view web-app in the browser. http://localhost:3000 Note that the development build is not optimized. To create a production build, use npm run build. webpack compiled successfully ``` Press the **CTRL+C** to stop the application. ## Step 6 – Create a Systemd Service File for React App Next, you will need to create a systemd file to manage the React app. You can create it with the following command. ``` nano /lib/systemd/system/react.service ``` Add the following code: ``` [Service] Type=simple User=root Restart=on-failure WorkingDirectory=/root/web-app ExecStart=npm start -- --port=3000 ``` Save and close the file, then reload the daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the React service using the following command. ``` systemctl start react systemctl enable react ``` You can check the service status with the following command. ``` systemctl status react ``` You should see the following output. ``` ● react.service Loaded: loaded (/usr/lib/systemd/system/react.service; static) Active: active (running) since Fri 2023-02-24 09:03:41 UTC; 5s ago Main PID: 74477 (npm start --por) Tasks: 29 (limit: 4700) Memory: 167.2M CGroup: /system.slice/react.service ├─74477 "npm start --port=3000" ├─74488 node /root/web-app/node_modules/.bin/react-scripts start --port=3000 └─74495 /usr/bin/node /root/web-app/node_modules/react-scripts/scripts/start.js --port=3000 Feb 24 09:03:41 archlinux systemd[1]: Started react.service. Feb 24 09:03:42 archlinux npm[74477]: > web-app@0.1.0 start Feb 24 09:03:42 archlinux npm[74477]: > react-scripts start --port=3000 ``` ## Step 7 – Configure Ngonx for React App By default, React app listens on the local host, so you will need to configure Nginx as a reverse proxy to access the React app from the remote machine. First, install the Nginx package with the following command. ``` pacman -S nginx-mainline ``` Next, start and enable the Nginx service using the following command. ``` systemctl start nginx systemctl enable nginx ``` Next, create a directory to store Nginx virtual host. ``` mkdir /etc/nginx/sites-enabled ``` Next, create an Nginx virtual host configuration file. ``` nano /etc/nginx/sites-enabled/react.conf ``` Add the following configuration. ``` upstream react_backend { server localhost:3000; } server { listen 80; server_name react.example.com; location / { proxy_pass http://react_backend/; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forward-For $proxy_add_x_forwarded_for; proxy_set_header X-Forward-Proto http; proxy_set_header X-Nginx-Proxy true; proxy_redirect off; } } ``` Save and close the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following lines after the line http {: ``` server_names_hash_bucket_size 64; include sites-enabled/*; ``` Save the file, then verify the Nginx configuration. ``` nginx -t ``` Output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Next, restart the Nginx service to implement the changes. ``` systemctl restart nginx ``` ## Step 8 – Access React App Now, open your web browser and access the React App using the URL **http://react.example.com.** You should see the React default page on the following screen. ![React dashboard page](https://www.atlantic.net/wp-content/uploads/2023/02/p1-8-1024x542.png) ## Conclusion In this tutorial, we showed you how to install React JS application on Arch Linux. We also configured Nginx as a reverse proxy for React app. Try to install React.js on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How To Install Cacti Monitoring Tool on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-cacti-monitoring-tool-on-arch-linux/ | Published: 2023-04-09 | Updated: 2023-11-15 | Author: Hitesh Jethva Cacti is a free, open-source, web-based monitoring tool used for monitoring remote systems via a web browser. It is a frontend application for RRDTool that allows users to poll services at specific intervals and graph the resulting data. With Cacti, you can monitor remote server and network devices such as routers, switches, and more. It uses SNMP protocol to collect various system metrics such as CPU, memory disk space, and bandwidth utilization. In this post, we will show you how to install the Cacti monitoring tool on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Cacti Arch Linux By default, the Cacti monitoring package is included in the Arch Linux default repository. You can install it by simply running the following command. ``` pacman -S cacti ``` Once Cacti is installed, you can proceed to install Nginx and PHP. ## Step 3 – Install Nginx and PHP Next, you will need to install Nginx, PHP, and other required extensions to host Cacti on the Internet. You can install all of them by running the following command. ``` pacman -S nginx-mainline php php-fpm php-gd php-intl ``` Once all the packages are installed, edit the php.ini configuration file and modify the default settings. ``` nano /etc/php/php.ini ``` Add/modify the following lines: ``` extension=gd extension=gettext extension=gmp extension=ldap extension=mysqli extension=pdo_mysql extension=snmp extension=sockets extension=intl memory_limit = 512M max_execution_time = 300 ``` Save and close the file, then create a PHP-FPM configuration file for Cacti: ``` nano /etc/php/php-fpm.d/cacti.conf ``` Add the following lines: ``` [cacti] user = cacti group = cacti listen = /run/cacti/cacti.sock listen.owner = http listen.group = http pm = ondemand pm.max_children = 4 ``` Save and close the file, then start and enable the Nginx and PHP-FPM services using the following command. ``` systemctl start nginx php-fpm systemctl enable nginx php-fpm ``` ## Step 4 – Install and Configure MariaDB Database Cacti uses a MariaDB as a database backend, so you will need to install the MariaDB on your server. You can install it with the following command. ``` pacman -S mariadb ``` After installing the MariaDB server, initialize the MariaDB database with the following command. ``` mysql_install_db --user=mysql --basedir=/usr --datadir=/var/lib/mysql ``` Next, edit the MariaDB configuration file and tweak some default settings: ``` nano /etc/my.cnf ``` Add/modify the following lines: ``` [mysqld] innodb = ON collation-server = utf8mb4_unicode_ci max_heap_table_size = 128M tmp_table_size = 64M join_buffer_size = 2M innodb_file_format = Barracuda innodb_large_prefix = 1 innodb_buffer_pool_size = 2048M innodb_flush_log_at_timeout = 3 innodb_read_io_threads = 32 innodb_write_io_threads = 16 innodb_io_capacity = 5000 innodb_io_capacity_max = 10000 innodb_doublewrite = OFF sort_buffer_size = 4M ``` Next, start and enable the MariaDB service with the following command. ``` systemctl start mysqld systemctl enable mysqld ``` Next, log into the MariaDB shell with the following command. ``` mysql ``` Once you are logged in, create a database and user using the following command. ``` MariaDB [(none)]> CREATE DATABASE cactidb; MariaDB [(none)]> GRANT ALL ON cactidb.* TO cactiuser@localhost IDENTIFIED BY 'some_password'; MariaDB [(none)]> GRANT SELECT ON mysql.time_zone_name TO cactiuser@localhost; ``` Next, flush the privileges and exit from the MariaDB shell with the following command. ``` MariaDB [(none)]> FLUSH PRIVILEGES; MariaDB [(none)]> EXIT; ``` Next, import the Cacti database and timezone data with the following command. ``` mysql -u root -p cactidb URL: https://www.atlantic.net/life-sciences-pharma-biotech/biotech-ai/ | Published: 2023-04-10 | Updated: 2024-11-09 | Author: Richard Bailey Biotech AI is an emerging field that combines the principles of biotechnology with the capabilities of artificial intelligence (AI). Biotech AI uses machine learning algorithms and other techniques such as unsupervised, reinforcement, and deep learning to analyze complex biological data, identify patterns and insights, and develop new drugs and treatments. The integration of biotech and AI has the power to transform the healthcare and medical research landscape. The potential impact is immense by facilitating the drug discovery process, creating tailored treatment plans, and enhancing the precision and speed of medical diagnosis and treatment. In this article, we will explore the innovative ways in which AI is revolutionizing the biotech industry and what exciting opportunities this cutting-edge technology will bring to our everyday lives in the future. ## Drug Discovery The drug discovery process is a complex and costly endeavor, typically taking a decade or more and incurring expenses upwards of **$2 billion** to introduce a new drug to the market. Fortunately, the emergence of AI in biotech promises to streamline and accelerate this process. With its ability to analyze vast amounts of data, AI is well-suited to identify new drug targets and evaluate the efficacy of potential treatments. Groundbreaking work in this field has already been carried out, such as [Deep Genomics](https://www.deepgenomics.com/) use of machine learning algorithms to study genomic data and identify genetic mutations that cause diseases. Similarly, [Atomwise](https://www.atomwise.com/) has harnessed the power of machine learning to predict the binding affinity between molecules and protein targets, enabling the creation of new drug candidates based on this information. Such advances hold tremendous promise for the biotech industry, offering the potential to transform medical research and enhance people’s lives worldwide. ## Optimizing Drug Efficacy In addition to accelerating drug discovery, biotech AI can potentially optimize the effectiveness of existing drugs by leveraging data from clinical trials to predict which patients are most likely to benefit from a particular treatment. One remarkable example is the work of a UK-based company, [BenevolentAI](https://www.benevolent.com/research), which applied AI to analyze clinical trial data for [Baricitinib](https://www.olumiant.com/rheumatoid-arthritis), a drug commonly used to treat rheumatoid arthritis. The company’s analysis uncovered the drug’s effectiveness in combating COVID-19, leading to the development of a clinical trial to further investigate its efficacy in treating the disease. By unlocking new insights from existing data, AI is revolutionizing the way medical professionals approach treatment, offering the potential for more precise and personalized care. The potential benefits of repurposing existing drugs for novel therapeutic applications are increasingly being recognized across the medical field. With the aid of AI, it is now possible to analyze the molecular structure of drugs and predict how they may interact with various proteins in the body, thus identifying new uses for drugs that have already been approved by regulatory agencies. This approach can significantly accelerate drug development, particularly for conditions requiring new treatments. For example, Insilico Medicine, a US-based biotech company, is harnessing the power of AI to repurpose existing drugs to develop treatments for new and existing diseases. Such innovative applications of AI highlight its transformative potential to unlock novel therapeutic options and revolutionize medical treatment. ## Precision Medicine Precision medicine is a burgeoning healthcare paradigm that considers individual variability in genes, environment, and lifestyle to tailor treatment plans uniquely for each patient. By enabling the analysis of vast amounts of patient data, AI can identify personalized treatment options that can improve outcomes while minimizing side effects. For instance, [Sophia Genetics](https://www.sophiagenetics.com/technology/sophia-ddm-for-genomics/) leverages AI to analyze patients’ genomic data, enabling physicians to identify optimal treatment options based on each patient’s genetic profile. Through such innovative approaches, AI is transforming the field of medicine, empowering clinicians to deliver more personalized and effective treatments. ## Genomics The field of genomics involves the study of an organism’s complete DNA sequence, including its genes, and has emerged as a promising area for disease diagnosis and treatment. With the advent of AI, researchers can now analyze vast amounts of genetic data, which can be used to identify disease risk factors and potential treatments. By analyzing a patient’s DNA, researchers can identify genetic mutations that may be associated with a higher risk of developing certain diseases. This information can facilitate the development of early detection tests, enabling clinicians to diagnose diseases at earlier stages when they may be more treatable. Furthermore, AI can aid in identifying potential therapeutic targets for various diseases, leading to the development of novel treatments that can improve patient outcomes. AI’s ability to analyze genomic data can revolutionize disease diagnosis and treatment, paving the way for more precise, personalized, and effective healthcare. ## Better Collaboration The advancement of biotech AI demands deep collaboration between researchers and practitioners across diverse disciplines, such as biology, computer science, and medicine. This multidisciplinary approach fosters a more innovative problem-solving mindset and enables researchers to approach challenges from fresh perspectives, leading to novel solutions. Collaboration among researchers from multiple disciplines facilitates faster and more accurate diagnosis, resulting in quicker treatment and improved patient outcomes. For instance, AI-powered imaging analysis can assist radiologists in identifying potential issues more quickly and accurately, allowing for more effective treatment. Furthermore, AI can help research teams identify patterns and insights that may not be immediately apparent to the human eye, enabling them to work together to tackle complex problems. By promoting effective collaboration, biotech AI has the potential to accelerate research and development, ultimately leading to the discovery of new treatments and cures for various diseases. ## Atlantic.Net and BioTech AI Biotech AI is an exciting field with tremendous potential to advance healthcare and medical research. However, it can also be complex and challenging, requiring deep collaboration between researchers and practitioners. This is where Atlantic.Net’s managed services can greatly assist biotech AI companies. Atlantic.Net’s managed services offer cutting-edge technology solutions to help biotech companies optimize their data analysis, streamline their workflows, and improve collaboration. Our experts in cloud computing, data security, and compliance can assist with building and deploying scalable infrastructure, ensuring data privacy and security, and complying with regulatory requirements. With our managed services, biotech companies can focus on innovation and research without worrying about the complexity of managing IT infrastructure. Our team provides customized solutions that meet the unique needs of biotech companies, whether they are just starting out or looking to expand their operations. In conclusion, Atlantic.Net’s managed services offer a reliable and secure way to [manage complex biotech infrastructure](https://www.atlantic.net/life-sciences-pharma-biotech/), enabling companies to focus on innovation and research. With our expertise in cloud computing and data security, we can help biotech AI companies accelerate their pace of research, reduce costs, and ultimately, bring life-saving treatments to patients faster. Don’t hesitate to [contact us](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) to learn more about how we can assist you in achieving your biotech AI goals. --- # How To Install Sails.js Framework with Nginx on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-sails-js-framework-with-nginx-on-arch-linux/ | Published: 2023-04-11 | Updated: 2024-06-04 | Author: Hitesh Jethva Sails is a free, open-source, popular MVC framework for Node.js. It is built on Express and used for building scalable production-ready Node.js applications. It is very similar to the Ruby on Rails web framework used to quickly build REST APIs, single-page apps, and real-time apps. It has a powerful code generator that helps you to build your application with less coding. This post will show you how to install Sails JS with Nginx on Arch Linux. ## Prerequisites - A fresh Arch Linux server - A root password configured on your server - An **IPV6 IP address** associated with your instance ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Node JS and NPM First, install NVM on your system with the following command. ``` curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.2/install.sh | bash ``` You will get the following output. ``` export NVM_DIR="$HOME/.nvm" [ -s "$NVM_DIR/nvm.sh" ] && \. "$NVM_DIR/nvm.sh" # This loads nvm => Close and reopen your terminal to start using nvm or run the following to use it now: ``` Next, run the following command to activate the NVM environment variable. ``` export NVM_DIR="$HOME/.nvm" [ -s "$NVM_DIR/nvm.sh" ] && \. "$NVM_DIR/nvm.sh" # This loads nvm ``` Now, verify the NVM version using the following command. ``` nvm --version ``` Output. ``` 0.39.2 ``` Next, install the latest version of Node JS using the following command. ``` nvm install --lts ``` You will get the following output. ``` Installing latest LTS version. Downloading and installing node v18.14.2... Downloading https://nodejs.org/dist/v18.14.2/node-v18.14.2-linux-x64.tar.xz... ####################################################################################################################################### 100.0% Computing checksum with sha256sum Checksums matched! Now using node v18.14.2 (npm v9.5.0) Creating default alias: default -> lts/* (-> v18.14.2) ``` To verify the Node JS version, run the following command. ``` node --version ``` Output. ``` v18.14.2 ``` Next, find the Node JS installation path using the following command. ``` which node ``` You will get the following output. ``` /root/.nvm/versions/node/v18.14.2/bin/node ``` Next, use the above path to create a symbolic link for Node JS. ``` ln -s /root/.nvm/versions/node/v18.14.2/bin/node /usr/bin/node ``` ## Step 3 – Install Sails JS You can use the NPM to easily install the Sails JS on your server. ``` npm -g install sails ``` You will see the following output. ``` added 230 packages in 10s 6 packages are looking for funding run `npm fund` for details npm notice npm notice New patch version of npm available! 9.5.0 -> 9.5.1 npm notice Changelog: https://github.com/npm/cli/releases/tag/v9.5.1 npm notice Run npm install -g npm@9.5.1 to update! npm notice ``` ## Step 4 – Create a Sails JS Application First, create a directory to hold Sails JS with the following command. ``` mkdir sails ``` Next, navigate to the Sails directory and create a Sails app with the following command. ``` cd sails sails new app ``` You will be asked to select the template: ``` Choose a template for your new Sails app: 1. Web App · Extensible project with auth, login, & password recovery 2. Empty · An empty Sails app, yours to configure (type "?" for help, or to cancel) ? 1 ``` Type 1 and press the Enter key to continue. ``` = info: Installing dependencies... Press CTRL+C to cancel. (to skip this step in the future, use --fast) info: Created a new Sails app `app`! ``` Next, change the directory to the app directory and start the Sails app with the following command. ``` cd app sails lift ``` You will see the following output. ``` info: Starting app... info: Initializing project hook... (`api/hooks/custom/`) info: Initializing `apianalytics` hook... (requests to monitored routes will be logged!) info: ·• Auto-migrating... (alter) info: Hold tight, this could take a moment. info: ✓ Auto-migration complete. debug: Running v0 bootstrap script... (looks like this is the first time the bootstrap has run on this computer) info: info: .-..-. info: info: Sails <| .-..-. info: v1.5.4 |\ info: /|.\ info: / || \ info: ,' |' \ info: .-'.-==|/_--' info: `--'-------' info: __---___--___---___--___---___--___ info: ____---___--___---___--___---___--___-__ info: info: Server lifted in `/root/sails/app` info: To shut down Sails, press + C at any time. info: Read more at https://sailsjs.com/support. debug: ------------------------------------------------------- debug: :: Fri Feb 24 2023 10:13:10 GMT+0000 (Coordinated Universal Time) debug: Environment : development debug: Port : 1337 debug: ------------------------------------------------------- ``` Press the **CTRL+C** to stop the application Next, find the Sails installation path with the following command. ``` which sails ``` Output. ``` /root/.nvm/versions/node/v18.14.2/bin/sails ``` Use the above path to create a symbolic link of Sails binary. ``` ln -s /root/.nvm/versions/node/v18.14.2/bin/sails /usr/bin/sails ``` ## Step 5 – Create a Systemd Service File for Sails JS Next, it is a good idea to create a systemd file to manage the Sails JS service. ``` nano /lib/systemd/system/sails.service ``` Add the following configurations. ``` [Unit] After=network.target [Service] Type=simple User=root WorkingDirectory=/root/sails/app ExecStart=/usr/bin/sails lift Restart=on-failure [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the Sails service with the following command. ``` systemctl start sails systemctl enable sails ``` You can check the status of the Sails service with the following command. ``` systemctl status sails ``` You will get the following output. ``` ● sails.service Loaded: loaded (/usr/lib/systemd/system/sails.service; disabled; preset: disabled) Active: active (running) since Fri 2023-02-24 10:15:30 UTC; 4s ago Main PID: 56668 (node) Tasks: 22 (limit: 4700) Memory: 174.2M CGroup: /system.slice/sails.service ├─56668 node /usr/bin/sails lift └─56677 grunt Feb 24 10:15:32 archlinux sails[56668]: info: ____---___--___---___--___---___--___-__ Feb 24 10:15:32 archlinux sails[56668]: info: Feb 24 10:15:32 archlinux sails[56668]: info: Server lifted in `/root/sails/app` Feb 24 10:15:32 archlinux sails[56668]: info: To shut down Sails, press + C at any time. Feb 24 10:15:32 archlinux sails[56668]: info: Read more at https://sailsjs.com/support. Feb 24 10:15:32 archlinux sails[56668]: debug: ------------------------------------------------------- Feb 24 10:15:32 archlinux sails[56668]: debug: :: Fri Feb 24 2023 10:15:32 GMT+0000 (Coordinated Universal Time) Feb 24 10:15:32 archlinux sails[56668]: debug: Environment : development Feb 24 10:15:32 archlinux sails[56668]: debug: Port : 1337 Feb 24 10:15:32 archlinux sails[56668]: debug: ------------------------------------------------------- ``` ## Step 6 – Install Nginx for Sails JS Next, you will need to install and configure Nginx as a reverse proxy for Sails JS. First, install the Nginx package using the following command. ``` pacman -S nginx-mainline ``` Next, start and enable the Nginx service with the following command. ``` systemctl start nginx systemctl enable nginx ``` Next, create a directory to store Nginx virtual host. ``` mkdir /etc/nginx/sites-enabled ``` Next, create an Nginx configuration file for Sails JS. ``` nano /etc/nginx/sites-enabled/sails.conf ``` Add the following configuration. ``` server { listen 80; server_name sails.example.com; location / { proxy_pass http://localhost:1337/; proxy_set_header Host $host; proxy_buffering off; } } ``` Save the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following lines after http{: ``` server_names_hash_bucket_size 64; include sites-enabled/*; ``` Save the file then verify the Nginx configuration. ``` nginx -t ``` You will get the following output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 7 – Access Sails JS Web UI Now, open your web browser and access the Sails JS web interface using the URL **http://sails.example.com.** You should see the Sails JS registration page on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/02/p2-6-1024x508.png) Provide your name, email, password then click on the **Create account** button. You should see the Sails JS dashboard on the following screen. ![Sails dashboard page](https://www.atlantic.net/wp-content/uploads/2023/02/p1-9-1024x506.png) ## Conclusion In this tutorial, we explained how to install Sails JS on Arch Linux. We also explained how to configure Nginx as a reverse proxy for Sails JS. You can now start deploying your Sails JS app on the production environment. You can now install Sails JS on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # What is a SAN (Storage Area Network)? > URL: https://www.atlantic.net/dedicated-server-hosting/what-is-a-san/ | Updated: 2026-09-16 A Storage Area Network (SAN) is a centrally managed, high-speed block-storage network that presents pools of raw data to one or more servers over a dedicated network (typically Fibre Channel or iSCSI) so attached hosts can use the storage as if it were directly attached. ## What is a SAN? A Storage Area Network (SAN) is a centrally managed, high-speed storage network consisting of one or more vendor [storage systems, storage management software, application servers and network hardware](http://www.redbooks.ibm.com/redbooks/pdfs/sg245470.pdf) that allows users to access and utilize business information data. A SAN storage platform presents pools of raw data to a server infrastructure over a dedicated network connection. ## SAN Storage Hardware SAN devices are usually connected by independent high-speed iSCSI or Fibre Channel (FC and FCoE) network protocol hardware. Fibre Channel connectivity enables immensely fast data throughput between the storage array and the attached server device(s). Typically, the data transfer speeds of fibre-channel SAN storage start at around 4 Gbps, ranging up to 128 Gbps and faster. Speed varies by vendor and the type of SAN technology infrastructure, but the very latest storage fabric can now [break 200 Gbps transfer rates](http://www.mellanox.com/related-docs/whitepapers/WP_Introducing_200G_HDR_InfiniBand_Solutions.pdfusg=AOvVaw0kckH0RZWCo9bltFqgl0em). This allows the attached servers to be presented with a storage LUN, or storage volume, that performs as if the data disks were directly attached storage (DAS). SAN storage is compatible with physical and virtual server infrastructure. A SAN is connected to a physical server or physical ESX (virtual) host either directly using Fibre Channel cables or through a SAN Switch (again, with Fibre Channel or Fibre Channel over Ethernet cabling). Each host server must have at least one, but usually two, HBAs (host bus adapters) for a resilient connection to the storage. An HBA is an installable hardware storage controller card. Many server manufacturers include HBA connections directly on system boards; however, it is common practice to purchase additional high-speed HBA riser cards to pair with the SAN fabric and storage devices in the host environment. A SAN Switch (or Fibre Channel switch) is a part of the Storage Area Network fabric which enables the storage to communicate over the network. The SAN storage usually plugs directly into an FC SAN Switch using Fibre Channel cabling and SFP modules. The rest of the enterprise network fabric will also route via the FC SAN, switch allowing the storage to be presented to each individual server. This connectivity will either be via a directly attached (redundant) fibre connection, or via ultra-high-speed InfiniBand network fabric connections. ## How Does a SAN Work? A SAN uses block level storage functionality to present raw storage to a [logical unit](https://www.techopedia.com/definition/321/logical-unit-number-lun) (LUN) which is then presented to a target device. A LUN is a block of raw data, which can vary in size significantly, but is usually made up of a group of disks and presented to a target as a LUN in RAW state. Unlike an NAS, where data is presented to the operating system in a readable format, the LUN can only be read by a storage controller and interpreted by the operating system software-based initiator. A LUN requires an initiator on the host operating system to attach the LUN, such as the Microsoft iSCSI initiator configuration tool. Each LUN is given a unique identifier by the SAN, and the server’s hardware controller and the software initiator must be configured with the same LUN ID to interact with the raw data. ## The Future of SAN Storage SAN storage has been present in data centers around the world for several decades. Storage vendors continually improve features and add new features to benefit modern hyper-converged data centers. Scalability, manageability, and efficiency are the key areas of continued improvement, according to Network World. Organizations demand increasing data availability; therefore, SAN storage must scale as an organization grows. There are two key technologies which are becoming more common in modern SAN storage devices: ### Unified SAN Storage Traditionally, SAN storage exclusively used block-level data architecture; today, this definition is changing, and often you will find a SAN storage device which is classed as “Unified” SAN Storage. This means the storage is consolidated and can be used for block level SAN storage, NFS file level NAS storage and Object-Level data objects. Essentially, unified storage gives the ultimate flexibility for managed service providers and offers users a more general-purpose SAN storage device. EMC VNX and Netapp Filers are good examples of unified SAN storage. ### Converged Storage Another emerging technology which is likely to influence SAN storage design in the future is converged storage appliances. These devices combine storage and compute nodes into one modular package. Essentially, they are servers with plenty of storage directly attached, but with a software layer over the hardware to present the device as a storage node. VMware vSAN is an example of how converged storage is growing in popularity. ### [Related Guides](https://www.atlantic.net/dedicated-server-hosting/what-is-block-storage/) - [What Is Block Storage?](https://www.atlantic.net/dedicated-server-hosting/what-is-block-storage/) - [What Is Server Virtualization?](https://www.atlantic.net/dedicated-server-hosting/what-is-server-virtualization/) - [What Is VMware?](https://www.atlantic.net/dedicated-server-hosting/what-is-vmware/) - [Atlantic.Net Secure Block Storage](https://www.atlantic.net/cloud-platform/block-storage/) ## Disclaimer: * This post is for informational purposes only and does not constitute professional, legal, financial, or technical advice. Each situation is unique and may require guidance from a qualified professional. Readers should conduct their own due diligence before making any decisions. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # What Is Private Cloud Hosting? > URL: https://www.atlantic.net/vps-hosting/what-is-private-cloud-hosting/ | Updated: 2026-09-16 Private cloud hosting is a cloud computing model in which compute, storage, and networking resources are dedicated to a single organization. The underlying hardware is single-tenant (either on-premises or hosted by a managed service provider), which gives the organization stronger isolation, predictable performance, and tighter control over compliance than a shared public-cloud environment. ## What Is Private Cloud? Private cloud hosting, also known as a hosted private cloud, is a computing environment that is dedicated to a single organization and runs off-premises on a third-party vendor's cloud servers. This is different from a public cloud, where services are shared among multiple customers of the cloud vendor. In a private cloud, the underlying hardware layer is segregated from other clients' infrastructure, providing isolated access to all resources for a single customer. ## Advantages of Private Cloud Hosting Private cloud hosting services can offer many advantages, including: - Availability: Guaranteed access to resources in the event of a local outage - Scalability: High-demand scalability options - Resources: More resources than other options - Support: A support team is available - Management: The service provider can manage cloud resources, including maintenance, upgrades, and security management ## Deployment of Private Cloud Private clouds can be hosted in several ways, including: - On-premises: Hosted in the customer's data center - Independent cloud provider: Hosted on the infrastructure of an independent cloud provider - Rented infrastructure: Built on rented infrastructure in an offsite data center - Virtual hosting: Provides cloud functionality without setting up physically redundant servers ## What is the Difference Between Private and Public Cloud? ### What are Public Clouds? Public clouds are environments where resources and services are made available to multiple clients over the Internet. Unlike private clouds, public clouds are owned and operated by third-party cloud service providers, such as Atlantic.Net, Amazon Web Services (AWS), Microsoft Azure, and Google Cloud. These providers manage and maintain the infrastructure, allowing customers to access computing resources on a pay-as-you-go basis. Public clouds offer high scalability and flexibility, with resources being dynamically allocated as needed. However, because resources are shared among many users, there can be concerns about data privacy and compliance, making them less suitable for sensitive data or mission-critical applications. ### What are Private Clouds? Private clouds are typically utilized by companies with sensitive data, management, or workload demands beyond those practical for a shared environment. In the early days of private cloud, some organizations chose to host a private cloud on-premises. The benefits of private cloud are maximized when the organization leverages the data center resources of a reliable cloud provider, like Atlantic.Net. This removes the responsibility of providing and maintaining critical redundant systems like cooling, power, networking, storage, and infrastructure that normally lie far outside the core competency of most companies. ## The Advantages of Private Cloud Hosting ### Availability Virtual servers are spread across hundreds of computing nodes, but they only run on one node at a time. If a server on one node encounters an issue, it can be easily migrated to another node. While this alleviates downtime compared to a physical machine, it doesn't completely prevent it. This also simplifies load balancing and disaster recovery. ### Scalability While dedicated private hosting requires the purchase of additional hardware, adding a server or memory space can be done instantaneously with a VPS as long as there is space on the computer to configure additional virtual servers. ### Resources Clients have dedicated access to more computing resources than in typical on-premises setups, ensuring that the performance and availability are not impacted by other users. The cloud’s isolation provides a consistent and predictable environment, suitable for workloads requiring steady performance. Clients can also customize their resource allocation. ### Support Private cloud hosting typically includes dedicated support from the service provider, which can be crucial for maintaining the environment and troubleshooting issues. This support often extends beyond basic technical assistance to include strategic guidance on optimizing cloud usage, security best practices, and compliance management. ### Management Management services in private cloud hosting often include monitoring, maintenance, updates, and security. The cloud provider handles routine tasks such as patching software, upgrading hardware, and managing backups, allowing organizations to focus on their core business activities. ## Private Cloud Hosting Models Private cloud can be deployed in a variety of ways, to include: - Private Hosting On-Premises - Private Hosting with an Independent Cloud Provider - Private Hosting on Rented Infrastructure - Virtual Private Hosting (VPS Hosting) - Atlantic.Net’s Private Cloud ### Private Hosting On-Premises Private hosting is a hosting arrangement such that an organization’s infrastructure, databases, and servers all exist in an exclusive location inaccessible to anyone outside the company or the private hosting provider. This type of hosting is often used by large companies in need of enterprise-grade functionality. In the early days of the Internet, private hosting was done completely on-site for big companies. They would invest in servers housed in the organizations’ headquarters or a private data center. ### Private Hosting with an Independent Cloud Provider Private hosting with an independent cloud provider involves utilizing the provider's infrastructure to host a company's dedicated cloud environment. This setup allows organizations to benefit from the provider's expertise in managing data centers, networking, and security while maintaining control over their data and applications. Independent providers often offer flexible options for customization and can tailor the infrastructure to meet specific business requirements. This model is particularly beneficial for organizations that need the reliability and scalability of a cloud environment without the complexities of managing physical hardware. ### Private Hosting on Rented Infrastructure Private hosting on rented infrastructure involves leasing servers and other hardware from a third-party data center, rather than purchasing and maintaining them outright. This model offers the benefits of private cloud hosting, such as dedicated resources and enhanced security, without the capital expenditure associated with buying and housing hardware. The hosting provider typically manages the physical infrastructure, while the client retains control over the software and applications running on it. This approach differs from traditional private hosting with a cloud provider in that the rented infrastructure often includes a broader range of services, such as managed IT support, network management, and storage solutions. Companies can customize their environment to fit their specific needs, with the flexibility to expand or contract resources as required. Additionally, this model provides a middle ground between fully on-premises solutions and fully outsourced cloud services. ### Virtual Private Hosting (VPS Hosting) In the 2000s, improvements in software and hardware capabilities led to the development of the virtual private server (VPS). VPS technology allows software called a “hypervisor” to use the physical hardware of a server, such as memory, CPU and networking capabilities. Each virtual server acts like a normal operating system with its own applications, email software, Internet browsing capabilities, etc. Each user has his or her own unique user ID, password, and authentication code to sign on with. For an example of the benefits of VPS Hosting, consider a company with offices in different parts of the world. Say a chemical news bureau is headquartered in London but also has other offices in world energy hub cities such as Houston and Shanghai. Rather than redundantly set up the Texas and China offices with all of the same hardware and servers in London, a VPS hosting solution is established. A virtual server powered in the UK allows users in Houston and Shanghai to log on through a virtual server and see the exact same desktop and shared file servers as their colleagues in London. ### Atlantic.Net’s Private Cloud The dedicated infrastructure of Atlantic.Net’s Private Cloud solutions allow the highest degree of visibility and control of any cloud environment, ultimately providing the peace of mind your company expects and deserves. Having dedicated resources also guarantees they will be available when they are needed, making planning easier than in a public cloud model in which a “noisy neighbour” could take up resources, potentially impacting other users in the cloud. Because new resources can be spun up and spun down as needed, Atlantic.Net’s Private Cloud retains much of the scalability and elasticity of a public cloud. It is also similarly resilient because the virtualized server workload can be redistributed to different pieces of hardware in the event of a failure. ## Private Cloud Setups Available From Atlantic.Net There are several setups available for Atlantic.Net’s Private Cloud solutions, each defined by the hypervisor controlling them: ### Hyper-V Microsoft Hyper-V is a popular hypervisor (virtual machine manager) that is strategically suited for those primarily using Windows Servers. Those who do so may already be comfortable with its interface and features, like Windows Active Directory, which Hyper-V uses for access control in certain circumstances. It also comes loaded with many features that enable easy maintenance, security, backups, and live migration.. Hyper-V can also be deployed as a “bare metal” hypervisor, meaning it does not run on an underlying operating system. Accessing hardware resources directly provides better performance, scalability, and stability. ### KVM Kernel-based Virtual Machine (KVM) is an open source hypervisor for the Linux operating system, as opposed to a bare metal hypervisor. While it is bundled with Linux, KVM supports running a wide variety of operating systems as “guests,” including Windows. One of the most-widely used cloud hypervisors in the world, KVM is touted as providing a low-cost alternative without sacrificing performance, scalability, or security. ### VMware VMware vSphere is a popular enterprise platform for deploying and managing private cloud. It is designed to run VMware's ESXi bare metal hypervisor. While vSphere is designed to work with other VMware cloud and virtualization products, it also supports Hyper-V and KVM based virtual machines. vSphere ESXi trades some of the flexibility and features of Hyper-V for a smaller footprint and more simplicity, which contribute to its strong security and ease of use. ## Conclusion The decision to run a private cloud, and the choice of which kind of private cloud technologies to use should be made based on the needs of your organization. If your company needs custom provisioning and automation, security, and a greater degree of control and flexibility, you will achieve the greatest benefit from deploying a private cloud. ## How Can Atlantic.Net Help? Atlantic.Net’s Private Cloud Solutions are especially ideal for companies in the healthcare, payment, telecommunication, and web hosting industries, as well as businesses with rapidly increasing infrastructure needs. Whatever kind of Cloud is right for your organization, successfully delivering its benefits to your business and its customers requires starting with a realistic plan, following that plan, and partnering with the right service provider. Atlantic.Net has over thirty years of experience, with expert staff that are available to assist you and your company’s needs 24/7. Contact us today, and we will work with you to create a custom Private Cloud Solution that is perfect for your business. Our plans are designed to provide maximum flexibility to business as well as developers. Please contact us via email at sales@atlantic.net or via phone at 866-618-3282 . Our team would be happy to guide you towards the solution that is ideal for your business needs. ## Disclaimer: * This post is for informational purposes only and does not constitute professional, legal, financial, or technical advice. Each situation is unique and may require guidance from a qualified professional. Readers should conduct their own due diligence before making any decisions. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # What is Colocation Hosting? > URL: https://www.atlantic.net/what-is-colocation-hosting/ | Updated: 2026-09-16 Colocation hosting is a service where you place your own server hardware in a third-party data center and rent space, power, cooling, network connectivity, and physical security. You own the equipment; the colocation provider owns the facility and supporting infrastructure. **On this page** 1. What is Colocation Hosting? 2. How Colocation Hosting Works 3. Colocation Hosting for Security 4. Additional Benefits of Colocation Hosting 5. Negatives of Colocation Hosting ## What is Colocation Hosting? Colocation hosting is similar to dedicated hosting, with one notable exception. In dedicated hosting, customers rent servers as well as the infrastructure needed to house and maintain them. In colocation hosting, companies own their own hardware, but are looking to augment its usefulness by renting server space in a data center, which provides benefits like improved Internet bandwidth, server cooling systems and climate control, and reliable power. Colocation hosting can be compared to owning a boat and renting a berth for it at the closest port of call. The boat remains in your possession and you can access it at any time, but you're still enjoying the services of the port – including security for your vessel and the ability to use the facility's equipment to maintain and get the most out of your boat. This is part of an extensive series of guides about hybrid cloud. ## How Colocation Hosting Works In order to establish a colocation hosting arrangement, the customer must have their own physical server – one that they own. The customer isn't renting a server from the hosting provider; rather, they are merely leasing space like they would at a rental storage company. The customer physically transports the server to the colocation hosting provider's place of business, typically a data center. The customer only rents space within the data center or colocation site, but maintains ownership and control of all hardware and software settings for that server. By communicating with the colocation hosting provider's team, the customer can quickly upgrade or downgrade features like bandwidth and rackspace to fit the business needs. ## Colocation Hosting for Security A top reason most companies employ colocation hosting is for the security it provides. While many former colocation users have made the move to cloud technology because of its ease of use, endless resources, and competitive pricing, there are some things cloud cannot do, according to Who's Hosting This; primarily, it's the level of control you have over your server compared to cloud. Many industries, such as health care, have specific rules of compliance that must be met for legal purposes (like HIPAA and HITECH) when it comes to data and its privacy. Many industries' rules state that data was be kept in a secure, on-site location, which colocation can provide because it is stored in the colocation provider's secure data center. Your server is taken to the provider's location and stored there securely while you pick and choose what services you wish to use, according to TechRadar. ## Additional Benefits of Colocation Hosting With colocation hosting, a small-to-midsized company can achieve a reasonable facsimile of enterprise-level hosting capabilities thanks to the shared hosting environment and on-site support. This can allow your company to play on a fairly even field when it comes to technology, even if it is a fraction of the size of the competition. Additional benefits include: ### High bandwidth and low latency Your server is plugged in to the colocation hosting provider's network, giving it access to industrial-strength connection speeds. Additionally, you can contract with third-party providers like Spectrum or CenturyLink for even more connectivity options. ### Unlimited power No hosting situation is 100% free of risk, but you're transferring the safety of your server from your office to a location built to prevent loss of electricity. A colocation hosting facility has access to steady power supplies, battery backups, and generators. ### On-premises monitoring Most data centers will employ security professionals or support technicians who monitor the premises 24 hours a day, 7 days a week, and 365 days a year for unauthorized visitors. They control who has access to the data center. ### Advanced climate control systems Maintaining the perfect temperature and humidity requirements for servers to operate at optimal efficiency can be a tricky balance to achieve. A colocation hosting facility will have tailored climate control systems that allow the data center managers to properly maintain ideal environmental conditions. ### Live monitoring of equipment In a typical office, your first indication that hardware is in need of maintenance, update, or replacement is when something fails, slowing or stopping your employees' production. With colocation hosting, IT professionals are monitoring your equipment constantly to ensure it is performing optimally. ### Better management In your own brick-and-mortar location, your servers might be managed by a contract IT person, a part-time worker, or a full-time employee who wears several different hats. Upgrading or downloading your server's capabilities in this environment involves lots of moving parts. When using a colocation hosting provider, a simple email or phone call will perform the same work, without adding to your budget or reducing employee productivity. ## Negatives of Colocation Hosting Several of the positives of colocation hosting rest in the same space as one of the negatives: If you want to replace your server or make changes to it personally, it requires driving to the colocation facility and having the staff remove it for you. Even done quickly, this is a process that effectively takes your business offline for at least a few minutes. Additionally, many colocation providers have locked in prices on the cost of electricity and bandwidth that you pay for several months of uninterrupted service. Should you choose this course and then prices for either service fall, you'll be stuck paying the locked-in price. Newsletter Subscribe to our newsletter and stay updated. Ready to Deploy? Launch secure, compliant, enterprise-grade infrastructure with confidence. ## See Additional Guides on Key Hybrid Cloud Topics Together with our content partners, we have authored in-depth guides on several other topics that can also be useful as you explore the world of hybrid cloud. ### [Cloud Migration](https://faddom.com/what-is-cloud-migration/) Authored by Faddom - [[Guide] Data Center Migration: Complete Guide 2025](https://faddom.com/what-is-data-center-migration/) - [[Guide] Cloud Migration to AWS: 3 Phases, 7 Rs and 5 Free Tools to Get You Started](https://faddom.com/cloud-migration-to-aws-3-phases-7-rs-and-5-free-tools-to-get-you-started/) - [[Blog] How Secure is the Cloud?](https://www.atlantic.net/hipaa-compliant-hosting/how-secure-is-the-cloud/) - [[Product] Faddom | Instant Application Dependency Mapping Tool](https://faddom.com/) ### [Nutanix](https://faddom.com/nutanix-history-products-and-top-5-alternatives/) Authored by Faddom - [[Guide] Nutanix: History, Products, and Top 5 Alternatives -](https://faddom.com/nutanix-history-products-and-top-5-alternatives/) - [[Guide] Nutanix vs. VMware: 5 Key Differences and How to Choose](https://faddom.com/vmware-vs-nutanix/) - [[Product] Faddom | Instant Application Dependency Mapping Tool](https://faddom.com/) ### [VMware Storage](https://cloudian.com/guides/vmware-storage/vmware-storage/) Authored by Cloudian - [[Guide] VMware Storage: Understand Your Options](https://cloudian.com/guides/vmware-storage/vmware-storage/) - [[Guide] VMware Cloud Services: The Most Popular Services Explained](https://cloudian.com/guides/vmware-storage/vmware-cloud-services/) - [[Announcement] Cloudian Raises $60 Million in Funding to Accelerate Hybrid Cloud Data Management](https://cloudian.com/blog/transforming-enterprise-data-management-hybrid-cloud/) - [[Product] Enterprise-Class, S3-Compatible Object Storage Software](https://cloudian.com/) ### [Read More About Colocation Hosting](https://www.atlantic.net/orlando-colocation-hosting-data-center/) - [How to Choose the Best Colocation Facility](https://www.atlantic.net/orlando-colocation-hosting-data-center/things-to-look-for-when-identifying-the-best-site-for-colocation/) - [Orlando Colocation Hosting](https://www.atlantic.net/orlando-colocation-hosting-data-center/) ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # What is Managed Hosting? > URL: https://www.atlantic.net/dedicated-server-hosting/what-is-managed-hosting/ | Updated: 2026-09-16 Managed hosting is a hosting service in which the provider operates the server hardware and the software stack on top of it (operating system, security updates, monitoring, backups, and often middleware and applications) so the customer can focus on the application and the data rather than day-to-day infrastructure operations. ## What is Managed Hosting? Managed hosting is a service wherein a third-party provider is responsible for the administration, problem-solving, and maintenance and organization’s hardware or cloud computing resources. Usually, the company that provides the managed hosting also provides the [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) or the cloud-hosting environment. ## How does Managed Hosting Work? In order to establish a managed hosting arrangement, the customer can either have a cloud VPS or a dedicated server. The managed hosting adds an optional layer of management services to the server to enable the customers bring focus to their core business and enjoy substantial cost savings. This helps them streamline their cost structure and rely on the hosting provider to help save time and resources. The cost savings from not having additional in-house resources to conduct basic tasks like server backup, and security services can go a long way in savings that can be easily substantiated. By communicating with the hosting provider's team, the customer can quickly upgrade or downgrade features to fit the business needs. ## What are the Benefits of Managed Hosting? The main advantage of managed hosting is easy to see: nearly any mishap that could that befall your servers and networks are now the responsibility of another party, one that stakes its branding and reputation on managing servers. Other benefits are more subtle but can pay off in terms of lower costs and improved efficiency in the short and long-term for your organization. ### Reduced Costs: Hardware and its maintenance and upgrades are expensive, even if they are tax deductible. The worst part is that when something breaks, you have to replace it, and replace it fast, which means you can’t wait around for the best bargain. When someone else is leasing you the equipment and maintaining it, all those costs are rolled into your monthly fee, and any breakdowns are repaired seamlessly by the managed hosting company. ### Flexibility: No two businesses look alike and have the same needs, but when you buy your own hardware, you’re might purchase something you won’t use to its full capabilities. Managed hosting is a solution that embodies flexibility. Your organization’s individual needs and budget will be factored in to creating a managed hosting solution that works for you, minimizing waste. ### IT Savings: Employing IT professionals can be expensive. Hiring a full-time IT worker can feel unnecessary when they don’t really have 40 hours of work to do each week, but when something fails, you’re desperate for their services. Having the built-in IT services of a managed hosting company gives you the freedom to either give your in-house IT team different responsibilities, or if there is no other role for IT in the organization, reduce the position to a part-time or on-call role. ## What is included in Managed Hosting? Different managed hosting providers offer different services, and different organizations want various levels of control when it comes to how their servers are managed. Regardless, here are some of the managed hosting services that come standard from nearly every provider. Security: One of the top needs of every organization is keeping its systems, processes, and proprietary information safe. Common functions performed include: - Firewall configuration - Spam filtering - Virus scans - Operating system upgrades Monitoring Servers:Scanning servers to look for errors or potential threats is an important piece of maintaining a server’s performance and security. The managed host provider does this routinely to catch little glitches before they become major disruptions. Additionally, intrusion detection systems or intrusion prevention systems help mitigate server data breaches or unauthorized access. Monitoring Servers: Scanning servers to look for errors or potential threats is an important piece of maintaining a server’s performance and security. The managed host provider does this routinely to catch little glitches before they become major disruptions. Additionally, intrusion prevention systems help mitigate server data breaches or unauthorized access. Backup and Disaster Recovery: Some companies fail to anticipate the threat of a business-crippling disaster. According to InvenioIT, 30% of businesses have no disaster recovery strategy in place. If that statistic doesn’t scare you, a study by Touche Ross says that 90% of businesses that don’t have a strategy in place will fail. Hurricanes, earthquakes, and fires all happen every year. A managed host provider can back up critical information and processes so that your company continues to run smoothly no matter what happens. IT Support: This might be the most comforting feature offered by a managed hosting provider. The more reputable providers have support in the form of telephone operators, email responders, or live chat agents available 24/7/365. Server Maintenance: As any IT person can tell you, this is a full-time, painstaking job. Having a managed hosting provider in charge of your server’s lifecycle frees up your own IT staff for more on-site functionality. ## Managed Hosting from Atlantic.Net Our Managed Server Hosting adds a layer of business-essential Managed Services to our award-winning hosting services. Our hosting services include Cloud Hosting, [Dedicated Hosting](https://www.atlantic.net/dedicated-server-hosting/), Private Virtualization or Colocation Hosting services. ## Why Choose Managed Hosting? Atlantic.Net’s award-winning Managed Server Hosting eliminates the complexity of managing your server environment and returns focus to your business. Our certified engineers monitor your hosting environment around the clock to ensure your business is up and running 100% of the time. We handle everything from basic maintenance and server administration tasks to troubleshooting and technical support. Our Managed Services are versatile and extensive, including diverse services in the areas of Managed Security, Managed Storage Services, OS Management Services, and Managed Network Services. These services can be tailored for your particular requirements. If you include any of these high-touch, “white glove” services with your Atlantic.Net Hosting solution, whether that's [Dedicated Hosting](https://www.atlantic.net/dedicated-server-hosting/), VPS Hosting, or HIPAA Hosting, you will have a team of certified and expert engineers at your service, performing double-duty in real-time monitoring and consultative capacities. ## Guaranteed Infrastructure Whether you choose Public, Private, [Dedicated Servers](https://www.atlantic.net/dedicated-server-hosting/) or Virtualization Hosting, we back all our services with world class infrastructure and 100% up-time guarantee. - Guaranteed Resources - SOC 3 Certified Data Centers - RAID 10 - 100% Solid-State Drives (SSD) - Fully Redundant Power and Networking - Global Regions for Redundancy and Low Latency - Tier 1 Multi-homed (Redundant) Bandwidth Providers - RESTful API (Application Programming Interface) Made and managed in USA. No outsourcing, no finger pointing. No up-front capital expense. One low monthly price. ## Managed Server Hosting Features Our Managed Hosting features help you secure your infrastructure and provide tools that make your business more efficient. - Fully Managed Firewall Appliance - Security Analysis and Reporting - On-Demand Updates and Patches - 100% SLA (Service Level Agreement) - VPN (Virtual Private Network) Access - Optional Load Balancing of TCP/HTTP Traffic - Intrusion Prevention System (IPS) - Fully Managed Daily Backups ### 24/7/365 Engineer Support We are always here. You can reach our support department 24/7/365 through phone, email and chat. ### Dedicated Account Manager Hosting Environment Architects available to custom fit to your workloads to cope with any challenge ### Trend Micro Deep Security Our security suite includes anti-malware, network security, log inspection, and integrity monitoring ## Disclaimer: * This post is for informational purposes only and does not constitute professional, legal, financial, or technical advice. Each situation is unique and may require guidance from a qualified professional. Readers should conduct their own due diligence before making any decisions. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # How To Install Glances Monitoring Tool on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-glances-monitoring-tool-on-arch-linux/ | Published: 2023-04-12 | Updated: 2023-11-15 | Author: Hitesh Jethva Glances is a free, open-source, cross-platform monitoring tool used for monitoring system metrics such as CPU, memory, disk, and more. It provides a command line as well as a web-based interface where you can easily monitor all system resources. Compared to other monitoring tools such as top, atop, and htop, Glances can monitor other useful resources such as filesystem I/O, network I/O, and sensor readouts. In this post, we will show you how to install the Glances monitoring tool on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Required Dependencies Before starting, you will need to install some required dependencies on your server. First, install the Python PIP package using the following command. ``` pacman -S python-pip ``` Next, install the bottle module with the following command. ``` pip install bottle ``` Once you are done, you can proceed to install Glances. ## Step 3 – Install Glances Monitoring Tool By default, the Glances tool is included in the Arch Linux default repository. You can install it using the following command. ``` pacman -S glances ``` Once Glances is installed, you can verify the Glances version with the following command. ``` glances --version ``` You will get the following output. ``` Glances v3.3.0 with PsUtil v5.9.4 Log file: /tmp/glances-root.log ``` Next, start and enable the Glances service with the following command. ``` systemctl start glances systemctl enable glances ``` You can also check the Glances status using the following command. ``` systemctl status glances ``` You should get the following output. ``` ● glances.service - Glances Server Loaded: loaded (/usr/lib/systemd/system/glances.service; disabled; preset: disabled) Active: active (running) since Fri 2023-02-24 10:25:36 UTC; 26s ago Main PID: 57020 (glances) Tasks: 1 (limit: 4700) Memory: 18.8M CGroup: /system.slice/glances.service └─57020 /usr/bin/python /usr/bin/glances -s Feb 24 10:25:36 archlinux systemd[1]: Started Glances Server. ``` ## Step 4 – How to Use Glances Glances provides a command line interface that allows you to monitor your system resources via the command line. Open your command line interface and run the following command. ``` glances ``` You should see the Glances monitoring shell on the following screen. ![Glances command interface](https://www.atlantic.net/wp-content/uploads/2023/02/p1-10-1024x524.png) Press the **h** key to see all available options as shown below: ![Glances help information](https://www.atlantic.net/wp-content/uploads/2023/02/h-1024x581.png) Press the q key to exit from the Glances shell. ## Step 5 – Create a Systemd Service for Glances Web You can also monitor the system resources via a web-based interface. To do so, you will need to start Glances in web server mode. First, create a systemd service for Glances web. ``` nano /usr/lib/systemd/system/glancesweb.service ``` Add the following configurations: ``` [Unit] Description = Glances in Web Server Mode After = network.target [Service] ExecStart = /usr/bin/glances -w -t 5 [Install] WantedBy = multi-user.target ``` Save and close the file then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the Glances web service: ``` systemctl start glancesweb systemctl enable glancesweb ``` To check the status of the service, run the following command. ``` systemctl status glancesweb ``` You will get the following output. ``` glancesweb.service - Glances in Web Server Mode Loaded: loaded (/usr/lib/systemd/system/glancesweb.service; disabled; preset: disabled) Active: active (running) since Fri 2023-02-24 10:29:23 UTC; 4s ago Main PID: 57076 (glances) Tasks: 1 (limit: 4700) Memory: 19.9M CGroup: /system.slice/glancesweb.service └─57076 /usr/bin/python /usr/bin/glances -w -t 5 Feb 24 10:29:23 archlinux systemd[1]: Started Glances in Web Server Mode. ``` At this point, the Glances web is started and listens on ports **61208** and **61209.** You can check it using the following command. ``` ss -antpl | grep glances ``` You should see the following output. ``` LISTEN 0 0 0.0.0.0:61208 0.0.0.0:* users:(("glances",pid=57076,fd=4)) LISTEN 0 0 0.0.0.0:61209 0.0.0.0:* users:(("glances",pid=57020,fd=4)) ``` ## Step 6 – Access Glances Web Now, open your web browser and access the Glances Web UI using the URL **http://your-server-ip:61208.** You should see the following screen. ![Glances web interface](https://www.atlantic.net/wp-content/uploads/2023/02/web-1024x510.png) ## Conclusion In this post, we explained how to install the Glances monitoring tool on Arch Linux. We also explained how to enable the Glances web server mode to access it via a web-based interface. You can now start monitoring your system resources via the web browser. You can now implement the Glances monitoring tool on a [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Varnish Cache with Nginx on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-varnish-cache-with-nginx-on-arch-linux/ | Published: 2023-04-13 | Updated: 2023-11-18 | Author: Hitesh Jethva Varnish cache, also known as a reverse caching proxy, is a web application accelerator designed for content-heavy dynamic websites. It is used to cache content in front of the web server and optimize web pages for faster loading times. It handles all inbound requests before they land on your web server’s backend. In this post, we will show you how to set up the Varnish cache with Nginx on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list if you have not done so already. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Varnish Cache By default, the Varnish package is included in the Arch Linux default repository. You can install it by running the following command. ``` pacman -S varnish ``` After the successful installation, start the Varnish service and enable it to start after the system reboot. ``` systemctl start varnish systemctl enable varnish ``` By default, Varnish listens on port 6081. You can check it using the following command. ``` ss -antpl | grep 6081 ``` You will get the following output. ``` LISTEN 0 0 0.0.0.0:6081 0.0.0.0:* users:(("cache-main",pid=46376,fd=3),("varnishd",pid=46281,fd=3)) LISTEN 0 0 *:6081 *:* users:(("cache-main",pid=46376,fd=5),("varnishd",pid=46281,fd=5)) ``` ## Step 3 – Install Nginx Next, you will need to install the Nginx as a backend server. You can install it using the following command. ``` pacman -S nginx-mainline ``` Once installed, start and enable the Nginx service using the following command. ``` systemctl start nginx systemctl enable nginx ``` By default, Nginx listens on port 80, so you will need to change the Nginx default port to 8080. You can change it by editing the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Change the following line: ``` listen 8080; ``` Save and close the file, then restart the Nginx to apply the changes. ``` systemctl restart nginx ``` ## Step 4 – Configure Varnish to Work With Nginx Next, you will need to edit the Varnish service file and change port **6081** to **80.** ``` nano /usr/lib/systemd/system/varnish.service ``` Find the following lines: ``` ExecStart=/usr/sbin/varnishd \ -a :6081 \ -a localhost:8443,PROXY \ -p feature=+http2 \ -f /etc/varnish/default.vcl \ -s malloc,256m ``` Replace them with the following lines: ``` ExecStart=/usr/sbin/varnishd \ -a :80 \ -a localhost:8443,PROXY \ -p feature=+http2 \ -f /etc/varnish/default.vcl \ -s malloc,256m ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, restart the Varnish service using the following command. ``` systemctl restart varnish ``` Next, edit the Varnish configuration file and define your backend web server. ``` nano /etc/varnish/default.vcl ``` Change the following lines as per your Nginx backend server IP and port. ``` backend default { .host = "127.0.0.1"; .port = "8080"; } ``` Save and close the file when you are done. ## Step 5 – Verify Varnish Cache At this point, the Varnish cache is installed and configured as a front end for the Nginx web server. You can now check it using the curl command. ``` curl -I http://localhost ``` If everything is fine, you will get the following output. ``` HTTP/1.1 200 OK Server: nginx/1.23.3 Date: Thu, 26 Jan 2023 14:41:04 GMT Content-Type: text/html Content-Length: 615 Last-Modified: Tue, 13 Dec 2022 17:30:37 GMT ETag: "6398b6bd-267" X-Varnish: 5 3 Age: 3 Via: 1.1 archlinux (Varnish/7.2) Accept-Ranges: bytes Connection: keep-alive ``` You can also check the Varnish log to see the caching-related information. ``` varnishlog ``` You should see the following output. ``` - RespHeader Age: 13 - RespHeader Via: 1.1 archlinux (Varnish/7.2) - RespHeader Accept-Ranges: bytes - VCL_call DELIVER - VCL_return deliver - Timestamp Process: 1674744107.428200 0.000149 0.000149 - RespProtocol HTTP/1.1 - RespStatus 304 - RespReason Not Modified - Filters - RespUnset Content-Length: 615 - RespHeader Connection: keep-alive - Timestamp Resp: 1674744107.428263 0.000212 0.000063 - ReqAcct 538 0 538 287 0 287 - End * << Session >> 11 - Begin sess 0 HTTP/1 - SessOpen 49.34.251.188 44732 a0 104.245.35.248 80 1674744107.418188 25 - Link req 12 rxreq - SessClose RX_CLOSE_IDLE 5.016 - End * << Session >> 32771 - Begin sess 0 HTTP/1 - SessOpen 49.34.251.188 44730 a0 104.245.35.248 80 1674744107.512357 31 - SessClose RX_CLOSE_IDLE 5.005 - End * << Session >> 13 - Begin sess 0 HTTP/1 - SessOpen 49.34.251.188 44734 a0 104.245.35.248 80 1674744107.844468 32 - SessClose RX_CLOSE_IDLE 5.001 - End ``` ## Conclusion Congratulations! You have successfully installed and configured the Varnish cache with Nginx on Arch Linux. You can now use Varnish cache as a front-end proxy server to speed up your web server performance. You can test the Varnish cache on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure Memcached on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-memcached-on-arch-linux/ | Published: 2023-04-14 | Updated: 2024-06-01 | Author: Hitesh Jethva Memcache is a free, open-source, general-purpose memory caching system used to speed up dynamic database-driven websites. It is a high-performance and in-memory data store that offers an open-source solution for delivering faster response times. Memcached is distributed, meaning you can easily scale up compute capacity by adding new nodes. In this post, we will explain how to install Memcached on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux., so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Memcached By default, the Memcached package is available in the Arch Linux default repository. You can search the Memcached package using the following command. ``` pacman -Ss memcached ``` You will get the following list: ``` extra/memcached 1.6.17-1 [installed] Distributed memory object caching system extra/prometheus-memcached-exporter 0.10.0-1 Exports metrics from memcached servers for consumption by Prometheus community/gambas3-gb-memcached 3.17.3-8 (gambas3) Memcached client component community/libmemcached-awesome 1.1.3-1 [installed] C/C++ client library and tools for the memcached server community/nginx-mod-memc 0.19-11 Extended version of the standard memcached module for nginx community/perl-cache-memcached 1.30-4 client library for memcached (memory cache daemon) community/php-legacy-memcached 3.2.0-2 PHP Legacy extension for interfacing with memcached via libmemcached library community/php-memcached 3.2.0-2 PHP extension for interfacing with memcached via libmemcached library community/python-binary-memcached 0.31.0-1 A pure python module to access memcached via its binary protocol with SASL auth support community/python-memcached 1.59-10 Python interface to memcached community/python-pylibmc 1.6.1-7 Quick and small memcached client for Python ``` Now, install the Memcached package using the following command. ``` pacman -S memcached libmemcached ``` After the installation, verify the Memcached version with the following command. ``` memcached --version ``` You should see the following output. ``` memcached 1.6.17 ``` ## Step 3 – Manage Memcached Service By default, the Memcached service is managed by systemd. You can start and stop it using the systemctl utility. To start the Memcached service, run the following command. ``` systemctl start memcached ``` To enable the Memcached service, run the following command. ``` systemctl enable memcached ``` You can check the status of the Memcached service using the following command. ``` systemctl status memcached ``` You will get the following output. ``` ● memcached.service - memcached daemon Loaded: loaded (/usr/lib/systemd/system/memcached.service; disabled; preset: disabled) Active: active (running) since Mon 2023-01-30 14:36:32 UTC; 4s ago Main PID: 47816 (memcached) Tasks: 10 (limit: 2362) Memory: 1.4M CGroup: /system.slice/memcached.service └─47816 /usr/bin/memcached -m 64 -c 1024 -l 127.0.0.1,::1 -o modern,drop_privileges Jan 30 14:36:32 archlinux systemd[1]: Started memcached daemon. ``` At this point, Memcached is installed and listens on port 11211. You can check it with the following command. ``` ss -antpl | grep memcache ``` You should see the following output. ``` LISTEN 0 0 127.0.0.1:11211 0.0.0.0:* users:(("memcached",pid=47816,fd=22)) LISTEN 0 0 [::1]:11211 *:* users:(("memcached",pid=47816,fd=23)) ``` ## Step 4 – Install Memcached PHP Extension If you want to use Memcached with your PHP-based application then you will need to install the Memcached PHP extensions. You can install it with other packages using the following command. ``` pacman -S php php-memcached php-fpm ``` Now, start and enable the PHP-FPM service using the following command. ``` systemctl start php-fpm systemctl enable php-fpm ``` ## Step 5 – Install Nginx To verify the PHP Memcached extension, you will need to install the Nginx to your system. You can install it with the following command. ``` pacman -S nginx-mainline ``` Next, start and enable the Nginx service with the following command. ``` systemctl start nginx systemctl enable nginx ``` ## Step 6 – Verify Memcache PHP Extension To verify the Memcached PHP extension, create a simple info.php file inside the Nginx web root directory. ``` nano /usr/share/nginx/html/info.php ``` Add the following code: ``` ``` Next, edit the Nginx main configuration file and define your PHP location. ``` nano /etc/nginx/nginx.conf ``` Find the following lines: ``` location / { root /usr/share/nginx/html; index index.html index.htm; } ``` Add the following lines after the above lines: ``` location ~ \.php$ { fastcgi_pass unix:/var/run/php-fpm/php-fpm.sock; fastcgi_index index.php; root /usr/share/nginx/html; include fastcgi.conf; } ``` Save and close the file, then restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` Now, open your web browser and access the info.php file using the URL **http://your_server_ip/info.php.** You should see the Memcached on the following screen. ![Verify memcached for PHP](https://www.atlantic.net/wp-content/uploads/2023/01/p1-2-1024x565.png) ## Conclusion Congratulations! You have successfully installed and tested Memcached on Arch Linux. You can now use Memcached with your PHP-based application to improve application performance. You can try the Memcached on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Fail2Ban to Secure SSH Server on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-fail2ban-to-secure-ssh-server-on-arch-linux/ | Published: 2023-04-15 | Updated: 2024-06-02 | Author: Hitesh Jethva Fail2ban is a powerful, free, open-source firewall service that is used to stop brute-force login attempts from the remote system. It is simple and lightweight, providing different filters to monitor Apache, SSH, and other programs for suspicious activity. It runs in the background and monitors the logs of different services and blocks clients that repeatedly fail authentication checks. Fail2Ban protects your Linux server against many security threats, such as dictionary, DoS, DDoS, and brute-force attacks. In this post, we will show you how to install the Fail2Ban firewall on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Fail2Ban Firewall By default, the Fail2Ban package is available in the Arch Linux default repository. You can install it using the following command. ``` pacman -S fail2ban ``` After installing the Fail2Ban package, start the Fail2Ban service and enable it to start at system reboot. ``` systemctl start fail2ban systemctl enable fail2ban ``` ## Step 3 – Secure SSH with Fail2Ban SSH is one of the most popular protocols used to manage the remote server via the command line, so the SSH service is always vulnerable to brute-force login attacks. In this section, we will show you how to protect SSH with Fail2Ban. Fail2Ban default configuration file located at **/etc/fail2ban/jail.conf.** It is always recommended to create a new Fail2Ban configuration file. ``` nano /etc/fail2ban/jail.local ``` Add the following lines: ``` [sshd] enabled = true port = ssh filter = sshd logpath = %(sshd_log)s backend = %(sshd_backend)s maxretry = 3 bantime = 300 ignoreip = 127.0.0.1 ``` Save and close the file, then restart the SSH service to apply the changes. ``` systemctl restart fail2ban ``` ## Step 4 – Verify Fail2Ban At this point, Fail2Ban is installed and configured to secure the SSH server against brute-force login attacks. You can now monitor your Fail2Ban using the fail2ban-client tool. To check the status of the SSH jail, run the following command. ``` fail2ban-client status sshd ``` You should see the list of all IPs blocked by Fail2Ban in the following output: ``` Status for the jail: sshd |- Filter | |- Currently failed: 1 | |- Total failed: 8 | `- Journal matches: _SYSTEMD_UNIT=sshd.service + _COMM=sshd `- Actions |- Currently banned: 1 |- Total banned: 1 `- Banned IP list: 49.34.165.39 ``` To check the status of all jails, run the following command. ``` fail2ban-client status ``` You will get the following output. ``` Status |- Number of jail: 1 `- Jail list: sshd ``` You can also check the Fail2Ban log for more information: ``` tail -f /var/log/fail2ban.log ``` You should see the following output. ``` 2023-01-31 05:03:53,142 fail2ban.filter [54073]: INFO [sshd] Found 49.34.165.39 - 2023-01-31 05:03:52 2023-01-31 05:04:03,144 fail2ban.filter [54073]: INFO [sshd] Found 49.34.165.39 - 2023-01-31 05:04:02 2023-01-31 05:04:03,339 fail2ban.actions [54073]: NOTICE [sshd] 49.34.165.39 already banned 2023-01-31 05:04:07,686 fail2ban.filter [54073]: INFO [sshd] Found 49.34.165.39 - 2023-01-31 05:04:07 2023-01-31 05:04:11,435 fail2ban.filter [54073]: INFO [sshd] Found 49.34.165.39 - 2023-01-31 05:04:11 ``` ## Step 5 – Working with Fail2Ban Command Line Fail2Ban also allows you to block and unblock remote IPs manually via the command line. To unblock a blocked IP, run the following command: ``` fail2ban-client set sshd unbanip remote-ip ``` If you want to block an untrusted IP, run the following command: ``` fail2ban-client set sshd banip remote-ip ``` ## Conclusion Congratulations! You have successfully installed and configured the Fail2Ban firewall on Arch Linux. Your server is now protected from brute-force login attempts. You can now install the Fail2Ban on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure Ansible on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-ansible-on-arch-linux/ | Published: 2023-04-16 | Updated: 2023-11-15 | Author: Hitesh Jethva Ansible is a free and open-source automation tool used for automating administrative tasks on multiple Linux servers. It is an agentless tool and supports Linux, Windows, and VMware cloud servers. It is a simple and lightweight alternative to other automation tools, including Chef and Puppet. It is primarily designed for IT professionals for application deployment, system updates, cloud provisioning, configuration management, and much more. In this post, we will show you how to install Ansible on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Ansible By default, the Ansible package is included in the Arch Linux default repository. You can install it with the following command. ``` pacman -S ansible ``` After the successful installation, you can verify the Ansible version using the following command. ``` ansible --version ``` You will get the following output. ``` ansible [core 2.14.1] config file = /etc/ansible/ansible.cfg configured module search path = ['/root/.ansible/plugins/modules', '/usr/share/ansible/plugins/modules'] ansible python module location = /usr/lib/python3.10/site-packages/ansible ansible collection location = /root/.ansible/collections:/usr/share/ansible/collections executable location = /usr/bin/ansible python version = 3.10.9 (main, Dec 19 2022, 17:35:49) [GCC 12.2.0] (/usr/bin/python) jinja version = 3.1.2 libyaml = True ``` ## Step 3 – Configure SSH Key-based Authentication Ansible uses SSH to connect to the remote server, so you will need to set up password-less key-based SSH authentication for remote Linux hosts that you want to manage. First, generate an SSH key on the Ansible server with the following command: ``` ssh-keygen -t rsa ``` You will get the following output. ``` Generating public/private rsa key pair. Enter file in which to save the key (/root/.ssh/id_rsa): Enter passphrase (empty for no passphrase): Enter same passphrase again: Your identification has been saved in /root/.ssh/id_rsa Your public key has been saved in /root/.ssh/id_rsa.pub The key fingerprint is: SHA256:vNxc7Y1vQAX7odhmpn1fZq4BdkMpXAh8xBUoflyEDl4 root@archlinux The key's randomart image is: +---[RSA 3072]----+ | ..+.**o | | +.E..o.| | o Bo.+o | | . o *+o..| | S o+B+ .| | . + o*+.+ | | o o. .+o=| | .*+| | .o+| +----[SHA256]-----+ ``` Next, copy the generated key to the remote Linux hosts with the following command: ``` ssh-copy-id -i ~/.ssh/id_rsa.pub root@your-remote-host-ip ``` You will be asked to provide the remote server password to copy the SSH key. ``` Number of key(s) added: 1 Now try logging into the machine, with: "ssh 'root@209.23.11.45'" and check to make sure that only the key(s) you wanted were added. ``` Next, check the SSH password-less login with the following command: ``` ssh root@your-remote-host-ip ``` ## Step 4 – Configure Ansible Hosts Next, you will need to configure Ansible hosts to define your remote Linux servers. ``` nano /etc/ansible/hosts ``` Add your remote server information as shown below: ``` [servers] server1 ansible_ssh_host=your-remote-host-ip ansible_ssh_port=22 ansible_ssh_user=root ``` Save and close the file when you are finished. ## Step 5 – How to Use Ansible At this point, Ansible is installed and configured. Now, it’s time to check how Ansible works. Let’s run the following command on the Ansible server to check the connectivity of remote hosts. ``` ansible -m ping all ``` If everything is fine, you should get the following output: ![Ansible check connectivity of all hosts](https://www.atlantic.net/wp-content/uploads/2023/01/p1-1024x187.png) To test the connectivity of specific hosts like server1, run the following command: ``` ansible -m ping server1 ``` You should see the following output. ![Ansible check connectivity of specific hosts](https://www.atlantic.net/wp-content/uploads/2023/01/p2-1024x187.png) ## Step 6 – Ansible Adhoc Commands Ansible provides ad-hoc commands to manage remote Linux hosts directly via the command line. To check the memory usage of all Ansible hosts, run the following command: ``` ansible -m shell -a "free -m" all ``` You should see the following screen: ![Ansible check memory usage of remote hosts](https://www.atlantic.net/wp-content/uploads/2023/01/p3-1024x144.png) To check the uptime of all Ansible hosts, run the following command: ``` ansible -m shell -a "uptime" all ``` You should see the following screen: ![Ansible check uptime of remote hosts](https://www.atlantic.net/wp-content/uploads/2023/01/p4-1024x157.png) To check the disk usage of all Ansible hosts, run the following command: ``` ansible -m shell -a "df -h" all ``` You should see the following screen: ![Ansible check disk usage of remote hosts](https://www.atlantic.net/wp-content/uploads/2023/01/p5-1024x239.png) ## Conclusion In this post, we explained how to install Ansible on Arch Linux. You can now use Ansible to provision and manage multiple Linux hosts using Ansible. You can deploy an Ansible server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure Squid Proxy on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-squid-proxy-on-arch-linux/ | Published: 2023-04-17 | Updated: 2024-06-05 | Author: Hitesh Jethva Squid is a free, open-source, fully featured proxy server that provides proxy and cache services for Hyper Text Transport Protocol. It reduces bandwidth, reduces server load, and improves response times by caching and reusing frequently-requested web pages. It also offers access control features that help you to filter Internet traffic. Generally, Squid proxies only HTTP connections and supports other protocols including FTP, Gopher, SSL, and WAIS. In this post, we will show you how to install the Squid proxy server on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Squid Proxy Server By default, the Squid package is included in the Arch Linux default repository. You can install it using the following command. ``` pacman -S squid ``` After installing the Squid proxy, start and enable the Squid service using the following command. ``` systemctl start squid systemctl enable squid ``` By default, Squid listens on port 3128. You can check it with the following command. ``` ss -antpl | grep squid ``` You will get the following output. ``` LISTEN 0 0 *:3128 *:* users:(("squid",pid=52872,fd=12)) ``` ## Step 3 – Configure Squid Authentication Before deploying Squid proxy in your organization, it is recommended to configure user-based authentication on Squid so only valid users can access the internet via Squid proxy. First, install the Apache package with the following command. ``` pacman -S apache ``` Next, create a file to store the Squid user and password. ``` touch /etc/squid/squid_passwd chown proxy /etc/squid/squid_passwd ``` Next, create a new user and set a password. ``` htpasswd /etc/squid/squid_passwd squiduser ``` Set your password as shown below: ``` New password: Re-type new password: Adding password for user squiduser ``` Next, edit the Squid configuration file and enable the authentication. ``` nano /etc/squid/squid.conf ``` Add the following lines at the beginning of the file. ``` auth_param basic program /usr/lib64/squid/basic_ncsa_auth /etc/squid/squid_passwd acl ncsa_users proxy_auth REQUIRED http_access allow ncsa_users ``` Save and close the file, then restart the Squid proxy service to apply the changes: ``` systemctl restart squid ``` ## Step 4 – Configure Squid to Anonymize Traffic Next, you will also need to configure Squid to mask client IP addresses and anonymize the traffic. You can do it by editing Squid’s main configuration file. ``` nano /etc/squid/squid.conf ``` Add the following lines at the beginning of the file. ``` forwarded_for off request_header_access Allow allow all request_header_access Authorization allow all request_header_access WWW-Authenticate allow all request_header_access Proxy-Authorization allow all request_header_access Proxy-Authenticate allow all request_header_access Cache-Control allow all request_header_access Content-Encoding allow all request_header_access Content-Length allow all request_header_access Content-Type allow all request_header_access Date allow all request_header_access Expires allow all request_header_access Host allow all request_header_access If-Modified-Since allow all request_header_access Last-Modified allow all request_header_access Location allow all request_header_access Pragma allow all request_header_access Accept allow all request_header_access Accept-Charset allow all request_header_access Accept-Encoding allow all request_header_access Accept-Language allow all request_header_access Content-Language allow all request_header_access Mime-Version allow all request_header_access Retry-After allow all request_header_access Title allow all request_header_access Connection allow all request_header_access Proxy-Connection allow all request_header_access User-Agent allow all request_header_access Cookie allow all request_header_access All deny all ``` Save and close the file, then restart the Squid proxy service to apply the changes: ``` systemctl restart squid ``` ## Step 5 – Verify Squid Proxy Now, your Squid proxy is installed and configured. It’s time to verify whether Squid is working or not. To test the Squid proxy, you will need to define your Squid proxy on your desktop computer’s browser settings. On the desktop system, open Mozilla Firefox and click on **Edit** => **Preferences** as shown below: ![firefox settings](https://www.atlantic.net/wp-content/uploads/2023/01/p1-1-1024x552.png) Scroll down to the **Network Settings** section and click on **Settings.** You should see the following page: ![firefox proxy settings](https://www.atlantic.net/wp-content/uploads/2023/01/p2-1.png) Select the Manual proxy configuration radio button, enter your Squid server IP address in the HTTP Host field and 3128 in the Port field, select the **“Use this proxy server for all protocols”** check box, and click on the **OK** button to save the settings. Your browser is now configured to browse the Internet through the Squid proxy. To verify it, type the URL **https://www.whatismyip.com/.** You will be asked to provide a username and password as shown below: ![squid proxy authentication](https://www.atlantic.net/wp-content/uploads/2023/01/p3-1-1024x584.png) Provide your Squid proxy server username and password which you created earlier and click on the **OK** button. You should see the following page: ![whatismyip page](https://www.atlantic.net/wp-content/uploads/2023/01/p4-1-1024x549.png) ## Conclusion Congratulations! You have successfully installed the Squid proxy server on Arch Linux. You can now implement Squid proxy in your organization to cache the content and filter the internet traffic. You can try the Squid proxy server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Secure SSH Server on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-secure-ssh-server-on-arch-linux/ | Published: 2023-04-18 | Updated: 2026-05-30 | Author: Hitesh Jethva OpenSSH is a secure shell protocol that provides a secure channel over an unsecured network. It allows the system administrator to manage Linux servers remotely over a secure channel. It works on a client-server architecture and allows users to connect to the SSH server remotely. Unlike unsecured protocols, SSH encrypts the traffic, login sessions, and passwords. OpenSSH is one of the most popular and widely used protocols. In this post, we will show you how to secure an SSH server on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirrorlist configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Change SSH Default Port By default, SSH listens on port 22. So it is vulnerable to DDoS attacks. In this case, it would be recommended to change the default SSH port to a port greater than 1024. To change the SSH port, edit the SSH configuration file. ``` nano /etc/ssh/sshd_config ``` Find the following line: ``` Port 22 ``` And, replaced it with the following line: ``` Port 8087 ``` Save and close the file then restart the SSH service to apply the changes. ``` systemctl restart sshd ``` ## Step 3 – Disable SSH Root Login The root user has unlimited access to the file system, so the root account is the most valuable target for hackers. You can disable the SSH root login by editing the SSH configuration file. ``` nano /etc/ssh/sshd_config ``` Find the following line: ``` #PermitRootLogin prohibit-password ``` Replaced it with the following line. ``` PermitRootLogin no ``` Save and close the file then restart the SSH service to apply the changes. ## Step 4 – Limit SSH Access It is also a good practice to grant only limited users access to the SSH server remotely. You can define the allow and deny list via SSH configuration file. ``` nano /etc/ssh/sshd_config ``` Add the following line: ``` AllowUsers user1 user2 user3 ``` Save and close the file, then restart the SSH service to apply the changes. ``` systemctl restart sshd ``` ## Step 5 – Enable Key-based Authentication It is a good idea to use an SSH key instead of a password to authenticate the SSH server. To do so, first, edit the SSH configuration file and enable the key-based authentication. ``` nano /etc/ssh/sshd_config ``` Change the following line: ``` PubkeyAuthentication yes ``` Save and close the file then restart the SSH service. ``` systemctl restart sshd ``` ## Step 6 – Disable Password Login It is also a good idea to disable password authentication and enable key-based authentication. ``` nano /etc/ssh/sshd_config ``` Find and change the following line: ``` PasswordAuthentication no ``` Save and close the file, then restart the SSH service to apply the changes. ``` systemctl restart sshd ``` ## Conclusion In this post, we explained how to secure an OpenSSH server on Arch Linux. I hope this guide will help you to secure your SSH server in a production environment. You can secure the SSH server on [VPS server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install SonarQube on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-sonarqube-on-arch-linux/ | Published: 2023-04-19 | Updated: 2023-11-15 | Author: Hitesh Jethva SonarQube is an open-source and self-hosted code quality analysis tool used to check code in several programming languages via plugins. It allows development teams to find bugs and code duplication in a software application. It helps developers to decrease application size, code complexity, time, and cost of maintenance and makes code easier to read and understand. It is written in Java and supports several databases including Postgres, MySQL, Oracle, and SQL Server. In this post, we will show you how to install SonarQube on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Java JDK SonarQube is based on Java, so you will need to install Java on your server. You can install it with the following command. ``` pacman -S jdk17-openjdk unzip ``` Once Java is installed, you can verify it using the following command. ``` java --version ``` You will get the Java version information in the following output. ``` openjdk 17.0.6 2023-01-17 OpenJDK Runtime Environment (build 17.0.6+10) OpenJDK 64-Bit Server VM (build 17.0.6+10, mixed mode) ``` ## Step 3 – Install and Configure PostgreSQL First, install the PostgreSQL server with the following command. ``` pacman -S postgresql ``` Next, initialize the PostgreSQL database with the following command. ``` sudo -u postgres initdb --locale en_US.UTF-8 -D /var/lib/postgres/data ``` Next, start and enable the PostgreSQL service using the following command. ``` systemctl start postgresql systemctl enable postgresql ``` Next, connect to the PostgreSQL shell. ``` sudo -u postgres psql ``` Next, create a database and user for SonarQube: ``` CREATE USER sonarqube WITH PASSWORD 'password'; CREATE DATABASE sonarqube OWNER sonarqube; GRANT ALL PRIVILEGES ON DATABASE sonarqube TO sonarqube; ``` Next, exit from the PostgreSQL shell with the following command. ``` \q ``` ## Step 4 – Download SonarQube First, create a dedicated user to run SonarQube. ``` useradd -b /opt/sonarqube -s /bin/bash sonarqube ``` Next, download the latest version of SonarQube using the following command. ``` wget https://binaries.sonarsource.com/Distribution/sonarqube/sonarqube-9.9.0.65466.zip ``` Once the download is completed, unzip the downloaded file with the following command. ``` unzip sonarqube-9.9.0.65466.zip ``` Next, move the extracted directory to /opt using the following command. ``` mv sonarqube-9.9.0.65466 /opt/sonarqube ``` Next, change the ownership of the SonarQube directory. ``` chown -R sonarqube:sonarqube /opt/sonarqube ``` Next, edit the SonarQube configuration file. ``` nano /opt/sonarqube/conf/sonar.properties ``` Change the following lines as per your settings. ``` sonar.jdbc.username=sonarqube sonar.jdbc.password=password sonar.web.javaOpts=-Xmx512m -Xms128m -XX:+HeapDumpOnOutOfMemoryError sonar.web.javaAdditionalOpts=-server sonar.web.host=0.0.0.0 sonar.web.port=9000 sonar.log.level=INFO sonar.path.logs=logs ``` Save and close the file when you are done. ## Step 5 – Create a Systemd Service File for SonarQube Next, you will need to create a systemd service file to manage the SonarQube service. You can create it with the following command. ``` nano /etc/systemd/system/sonarqube.service ``` Add the following configurations. ``` [Unit] Description=SonarQube service After=syslog.target network.target [Service] Type=forking ExecStart=/opt/sonarqube/bin/linux-x86-64/sonar.sh start ExecStop=/opt/sonarqube/bin/linux-x86-64/sonar.sh stop User=sonarqube Group=sonarqube Restart=always LimitNOFILE=65536 LimitNPROC=4096 [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the SonarQube service. ``` systemctl start sonarqube systemctl enable sonarqube ``` You can check the status of SonarQube using the following command. ``` systemctl status sonarqube ``` Output. ``` ● sonarqube.service - SonarQube service Loaded: loaded (/etc/systemd/system/sonarqube.service; disabled; preset: disabled) Active: active (running) since Sun 2023-03-26 04:42:04 UTC; 17s ago Process: 1008 ExecStart=/opt/sonarqube/bin/linux-x86-64/sonar.sh start (code=exited, status=0/SUCCESS) Main PID: 1033 (java) Tasks: 119 (limit: 4685) Memory: 1.1G CPU: 33.270s CGroup: /system.slice/sonarqube.service ├─1033 java -Xms8m -Xmx32m --add-exports=java.base/jdk.internal.ref=ALL-UNNAMED --add-opens=java.base/java.lang=ALL-UNNAMED --add-opens=java.base/java.nio> ├─1058 /usr/lib/jvm/java-17-openjdk/bin/java -XX:+UseG1GC -Djava.io.tmpdir=/opt/sonarqube/temp -XX:ErrorFile=/opt/sonarqube/logs/es_hs_err_pid%p.log -Des.> └─1168 /usr/lib/jvm/java-17-openjdk/bin/java -Djava.awt.headless=true -Dfile.encoding=UTF-8 -Djava.io.tmpdir=/opt/sonarqube/temp -XX:-OmitStackTraceInFast> Mar 26 04:42:04 archlinux systemd[1]: Starting SonarQube service... Mar 26 04:42:04 archlinux sonar.sh[1008]: /usr/bin/java Mar 26 04:42:04 archlinux systemd[1]: Started SonarQube service. Mar 26 04:42:04 archlinux sonar.sh[1008]: Starting SonarQube... Mar 26 04:42:04 archlinux sonar.sh[1008]: Started SonarQube. ``` ## Step 6 – Access SonarQube Web UI At this point, SonarQube is installed and running. Now, open your web browser and access the SonarQube web interface using the URL **http://your-server-ip:9000.** You should see the SonarQube login page: ![](https://www.atlantic.net/wp-content/uploads/2023/04/p1-6.png) Provide the default admin username and password as **admin/admin** then click on the **Login** button. You should see the password change screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/p2-7.png) Change your default password, then click on the **Update**button. You should see the SonarQube dashboard on the following screen.**![](https://www.atlantic.net/wp-content/uploads/2023/04/p3-4.png)** ## Conclusion In this post, we explained how to install SonarQube on Arch Linux. You can now create your first project manually or import it from the other DevOps platform. You can now try to deploy SonarQube on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # What Is CloudOps and How Can it Improve Your Compliance Efforts? > URL: https://www.atlantic.net/vps-hosting/what-is-cloudops-and-how-can-it-improve-your-compliance-efforts/ | Published: 2023-04-20 | Updated: 2025-09-15 | Author: Gilad Maayan ## What Is CloudOps? CloudOps, short for Cloud Operations, refers to the practices, tools, and methodologies used to manage and optimize cloud-based infrastructure and services. It involves the deployment, monitoring, and management of cloud-based applications and infrastructure in a way that ensures high availability, scalability, and performance. [CloudOps encompasses a range of activities](https://spot.io/cloudops/), including the management of virtualized infrastructure, the deployment of cloud-native applications, the automation of operations, and the implementation of security and compliance measures. It also involves the monitoring of resource usage, performance, and cost, and the implementation of strategies to optimize these factors. In essence, CloudOps is the practice of managing and optimizing cloud-based infrastructure and services in a way that maximizes their efficiency, reliability, and performance. It is an essential aspect of cloud computing, as it enables organizations to fully leverage the benefits of cloud-based technologies while ensuring that they are operating at peak efficiency. ## The Pillars of Cloud Operations The pillars of CloudOps refer to the key principles and practices that underpin the effective management and optimization of cloud-based infrastructure and services. The four pillars of CloudOps are: **Abstraction** Abstraction involves creating a layer of abstraction between the underlying infrastructure and the applications that run on it. This is typically achieved through the use of containerization or virtualization technologies, which allow applications to run in isolated environments that are independent of the underlying hardware or operating system. Abstraction enables greater flexibility and agility, as applications can be moved between different cloud environments or infrastructures without the need for significant modifications. This makes it easier for organizations to take advantage of the benefits of cloud computing, such as scalability and cost savings, without being tied to a specific cloud provider or infrastructure. **Provisioning** Provisioning refers to the process of deploying and configuring cloud resources, such as virtual machines (VMs), storage, and network resources. Effective provisioning is essential to ensure that applications have access to the resources they need to operate efficiently. Cloud-based infrastructure is typically provisioned using Infrastructure as Code (IaC) tools, which allow infrastructure to be defined and deployed using code. This enables consistent, repeatable deployments that can be automated and easily scaled up or down as needed. **Policy-driven** Policy-driven refers to the use of policies to govern the management and operation of cloud-based infrastructure and services. Policies can be used to enforce security and compliance measures, optimize resource usage, and automate management tasks. Cloud providers typically offer a range of policy-based services, such as identity and access management (IAM), network security, and resource tagging. These services enable organizations to define and enforce policies that govern how their cloud-based infrastructure and services are managed and operated. **Automation** Automation involves the use of tools and technologies to automate the deployment, management, and optimization of cloud-based infrastructure and services. This can help to reduce the workload on IT staff, increase efficiency and consistency, and improve the overall performance and reliability of cloud-based applications and infrastructure. Automation is typically achieved through the use of DevOps tools and practices, such as [continuous integration and continuous deployment (CI/CD)](https://codefresh.io/learn/ci-cd/), infrastructure automation, and monitoring and alerting. These tools and practices enable organizations to automate many of the tasks involved in managing and optimizing their cloud-based infrastructure and services, freeing up IT staff to focus on more strategic initiatives. Together, these pillars provide a framework for effective CloudOps, helping organizations to manage and optimize their cloud-based infrastructure and services in a way that maximizes their efficiency, reliability, and performance. ## CloudOps for Compliance CloudOps, which is the set of practices and processes for managing and optimizing cloud infrastructure and applications, can significantly improve compliance efforts in the following ways: - **Automation**: Automation is a key component of CloudOps and can significantly improve compliance efforts. By automating compliance checks and controls, organizations can reduce manual effort, minimize the risk of human error, and ensure that compliance is consistently enforced across their cloud infrastructure and applications. - **Standardization**: CloudOps also emphasizes the standardization of processes and infrastructure. By standardizing cloud infrastructure and applications, organizations can reduce complexity, minimize the risk of misconfiguration, and ensure that compliance controls are consistently applied. - **Visibility**: CloudOps provides visibility into cloud infrastructure and applications, enabling organizations to identify and remediate compliance issues quickly. By continuously monitoring cloud resources and applications, organizations can identify issues and risks before they become larger problems. - **Scalability**: CloudOps also enables organizations to scale cloud resources and applications in a compliant manner. By automating the provisioning and scaling of cloud resources, organizations can quickly respond to changes in demand and ensure that compliance controls are consistently applied. - **Resilience**: CloudOps also focuses on resilience and business continuity. By implementing [disaster recovery and business continuity](https://www.atlantic.net/disaster-recovery/) plans, organizations can ensure that critical data and applications are protected in the event of an outage or disaster, which is crucial for maintaining compliance. ## Implementing CloudOps ### Create an Effective Cloud Migration Strategy Developing a [comprehensive cloud migration strategy](https://bluexp.netapp.com/blog/cloud-migration-strategy-challenges-and-steps) is critical to a successful cloud implementation. This strategy should involve assessing existing applications and workloads to determine which ones are suitable for migration to the cloud, and which cloud environment and services are most appropriate for each workload. The migration strategy should also take into account factors such as security and compliance requirements (such as [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/)), data governance, and application dependencies. It’s important to define a clear migration path for each workload and to ensure that the migration process is well-planned and executed to minimize disruption to the business. ### Build a “Minimum Viable” Cloud Starting with a minimum viable cloud environment can help to reduce complexity and minimize costs while enabling the organization to gain experience with cloud-based technologies and identify areas for optimization and improvement. A minimum viable cloud typically includes only the essential infrastructure and services required to support critical business applications and workloads. As the organization gains experience and confidence with the cloud, additional infrastructure and services can be added as needed. ### Champion a Cultural Shift Implementing CloudOps often involves a cultural shift within the organization, as IT teams must adapt to new ways of working and collaborating. This requires strong leadership and communication, as well as a focus on training and education to ensure that IT staff have the skills and knowledge they need to succeed in a cloud-based environment. Championing a cultural shift involves encouraging a mindset of continuous improvement and collaboration, as well as adopting new tools and processes to support cloud-based operations. DevOps practices, for example, can help to break down silos between development and operations teams and enable more streamlined and efficient processes for managing cloud-based infrastructure and services. ### Automate Security Security is a critical consideration when implementing CloudOps, and automation can play a key role in ensuring that cloud-based infrastructure and services are secure and compliant. Automated security tools can help to identify and remediate security vulnerabilities, enforce security policies and controls, and detect and respond to security incidents in real-time. This can help to reduce the risk of security breaches and ensure that the organization remains compliant with relevant regulations and standards. ## Conclusion In conclusion, CloudOps is the practice of managing and optimizing cloud-based infrastructure and services in a way that maximizes their efficiency, reliability, and performance. By implementing CloudOps, organizations can gain significant benefits in terms of scalability, agility, and cost savings, while also improving their compliance efforts. Implementing CloudOps requires careful planning, execution, and ongoing management, but can offer significant benefits in terms of efficiency, agility, and scalability. By following best practices and focusing on key areas such as migration strategies, cloud environment design, cultural shifts, and security automation, organizations can successfully implement CloudOps and achieve their cloud computing goals. --- # Atlantic.Net Launches a New Website to Enhance User Experience and Accessibility > URL: https://www.atlantic.net/press-releases/atlantic-net-launches-a-new-website-to-enhance-user-experience-and-accessibility/ | Published: 2023-04-20 | Updated: 2024-06-03 | Author: Editorial Team ORLANDO, FLORIDA—April 20, 2023— Atlantic.Net, a leading cloud hosting provider, launched a new website in April 2023 to enhance user experience and accessibility. The new website’s modern design and user-friendly interface enable easy access to all of Atlantic.Net’s cloud hosting solutions and services. Marty Puranik, Founder and CEO of Atlantic.Net, said, “We are thrilled to launch our new website, which is the result of a comprehensive redesign and development process that took into consideration the feedback of our customers and the latest web design trends. Our new website will enable our customers to access our [cloud hosting solutions](https://www.atlantic.net/vps-hosting/) and services easily, and we are confident that it will enhance their experience with Atlantic.Net.” The new website features optimization for desktop and mobile devices, improved navigation, and enhanced search functionality, making it easier for users to find resources and information. It also offers a range of resources for customers, including an extensive knowledge base, tutorials, and a [popular blog](https://www.atlantic.net/blog/), where users can find up-to-date information about the latest trends and best practices in cloud hosting. Customers can also access Atlantic.Net’s customer portal, which provides a centralized location for managing their accounts, billing, and support requests. “We are committed to providing our customers with the best possible experience and support, and our new website is an important part of that commitment,” added Puranik. “We look forward to continuing to innovate and improve our offerings to help businesses thrive in the digital age.” Atlantic.Net is a leading cloud hosting provider offering businesses secure, scalable, and reliable solutions. The company has [data centers](https://www.atlantic.net/hipaa-data-centers/) in the United States, Canada, and the United Kingdom. **About Atlantic.Net** Atlantic.Net is a global cloud services provider with over 29 years of experience, specializing in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions to include [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [PCI hosting](https://www.atlantic.net/pci-compliant-hosting/), backed by 24/7/365 support through their global data centers located in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. ### Contact: Email: pr@atlantic.net Ph: 321- 206-1371 --- # How eCommerce Companies Can Protect Both Their and Customer Data In Six Ways > URL: https://www.atlantic.net/pci-compliant-hosting/how-ecommerce-companies-can-protect-both-their-and-customer-data-in-six-ways/ | Published: 2023-04-21 | Updated: 2025-09-15 | Author: Alexander Wise The significance of data for business growth can not be underestimated. And the fact that data is critical for decision-making and overall business operation increases the importance of data protection. This is true for the eCommerce industry, which is growing rapidly thanks to tech development and the fact it gives customers outstanding and smooth shopping experiences. As eCommerce businesses continue to grow and prosper, [data security](https://www.atlantic.net/pci-compliant-hosting/pci-security-services/) is becoming more important than ever. Thus, eCommerce businesses should focus on creating a strong data protection system. In this article, we will convert key strategies online stores can implement to protect their and customer data. ## Main Benefits of Data Protection for eCommerce Businesses There is no doubt that data plays a significant role in decision-making and overall business growth. So let’s discuss why eCommerce companies should care about protecting that valuable data. **✓ To protect payment information** Successful eCommerce businesses and decentralized eCommerce marketplaces maintain sensitive data, like customer information, product information, and financial records. Thus, it is vital to protect payment information from any security breaches, whether from unauthorized access or theft. **✓ Prevent fraud** One of the main perks of following data security measures is avoiding identity theft and payment fraud. Thus, eCommerce businesses can secure their buyer’s financial data and prevent financial losses. **✓ Build credibility  ** Data loss and breaches can damage the store’s reputation; thus, having a strong data security system can boost brand reputation and credibility. Moreover, companies with a strong reputation can attract and retain customers. **✓ Increase customer trust  ** Customers will shop at eCommerce stores when they know that eCommerce store cares about protecting their sensitive data and prioritize data protection. This is vital for word-of-mouth marketing efforts, as eCommerce buyers will recommend their family and friends to a business that takes data protection seriously. **✓ Improve business continuity ** Following data protection best practices and having recovery plans can guarantee eCommerce business continuity. **✓ Increases sales** By employing effective data protection measures, eCommerce stores can boost sales, as chances are higher that customers will purchase from businesses that prioritize data security. ## Six tactics eCommerce companies can protect both their and customer data Now that we’ve discussed the advantages of data protection for eCommerce companies, we will shift to policies that companies should implement to successfully protect customers’ data from security threats. ## 1. Safely back up your data One of the first steps that eCommerce companies should take to protect both their and customers’ data is data backups. Basically, this involves creating copies of crucial and sensitive data and storing them in a separate location. Regularly doing data backups can help ensure that customer data is not lost in case of malicious actions. Data backup is an essential part of running a successful eCommerce site. Thus, it is crucial to do regular audits also help you stay on top of the latest threats and ensure that your data is always safe. There are several tactics you should follow to make the process more effective. First, define what data you should back up. It can be valuable customer data, product, or financial records. The next step should be choosing which backup solution the eCommerce store needs and which suits the eCommerce business objectives and budget.  You can use several backup methods, such as manual backups, automatic backups, and cloud backups.   Another important consideration is that backups should not be one-time thing; making the backup process weekly or monthly will be beneficial. Lastly, eCommerce companies should store backups securely to guarantee that they’re protected from unauthorized access. Going through every step of this process ensures online stores have a reliable backup solution catering to all their needs. ## 2. Implement a strong password policy A strong password policy is a fundamental component that can strengthen the security policy and protect your customers’ data. Thus, it is crucial to encourage your eCommerce buyers to enter a strong password with a minimum length, special characters, and numbers during the registration or purchase. Require customers to create passwords at least eight characters long and include numbers and symbols. This will make it more difficult to hack passwords and protects from attacks. Moreover, eCommerce stores should require customers to change their passwords regularly. This will prevent old passwords from being used and reduce the risk of unauthorized access. Another beneficial tactic is employing extra security tactics, such as two-factor authentication, which takes us to the next point. ## 3․ Consider two-factor and multi-factor authentication Authentication strategies should be an integral part of data security efforts as they can give that extra layer of security. Multi-factor authentication requires users to enter their password and authenticate their access using another device like their mobile. For example, SMS can be deployed as an extra verification layer to protect your e-commerce business from fraudulent activity and make it harder for scammers to access user accounts. eCommerce companies should consider finding high-quality [multi-factor authentication services](https://www.atlantic.net/managed-services/multi-factor-authentication/) to help protect buyers and their data. Two-factor and multi-factor authentication offer an extra layer of security and provide another opportunity for your eCommerce company to connect with them. Additionally, when an eCommerce store decides to implement SMS as a verification layer, then it also makes it possible to build tailored campaigns based on the customer buying journey. ## 4. Educate your employees Educating customers on how to protect their own data, such as creating strong passwords and not sharing personal information, can also help protect both their data and the eCommerce company’s data. As part of this, educate employees on the risks their actions or mistakes could pose to data security and notify them about threats. **✔ Organize training sessions** eCommerce companies should organize regular training sessions on data security measures. These sessions can cover topics such as password security, phishing scams, and properly handling sensitive data. The training can also include giving tips for identifying and reporting suspicious actions. Furthermore, checking whether employees understand the importance of creating strong passwords is vital, and you should recommend regularly changing them. **✔ Establish clear policies and procedures** Another step is to develop clear policies and procedures for handling sensitive data and ensure that your employees understand them thoroughly. These policies should guide employees on how to store and share sensitive and crucial information. Also, you may consider giving your employees tips about Shopify bulk product image upload, as it helps to upload product images quickly and save valuable time. **✔ Monitor access to sensitive data** It is crucial to limit access to sensitive data and give those employees who need it to perform their daily tasks. Lastly, it will be important to schedule regular team meetings and use the Office 365 group calendar in that process, and effectively discuss data protection strategies. ## 5. Educate customers as well Online stores should not only dedicate effort to their employees but also should educate their customers as well.  Also, these companies should consider implementing onboarding tools or affordable Walkme alternatives making the onboarding stage as effective as possible and increasing increase customer retention. First and foremost, share your privacy policies on the eCommerce website and explain what data you collect, how you use it, and how you protect it. The next step is to provide a secure checkout option and offer secure payment options. Moreover, it is important to suggest to customers the option to use two-factor authentication to protect their accounts and add an extra layer of security. You should not only give password management tips to customers but also encourage them to use strong passwords and give tips on creating and managing them, such as using a password manager. Furthermore, it’s crucial to communicate with eCommerce buyers with a secure communication platform and consider taking email security measures when customers share sensitive data via email. Lastly, eCommerce companies should keep customers updated about privacy policy changes. Be open with customers in case data breaches happen, showcase they are responsible, and take necessary steps to minimize the impact. ## 6. Use encryption techniques The last recommendation we give to eCommerce businesses is to implement encryption methods to reduce both external and internal threats and guarantee high-level security. These techniques will help to protect sensitive data, such as passwords and credit card details, and are one of the effective ways to protect an e-commerce company’s data from securing your consumers’ information as well. Moreover, they help to increase search engine visibility, and best practice suggests that eCommerce websites that use encryption tactics rank higher. ## To Sum Up There is no doubt that a strong data protection strategy can ensure business growth. Therefore, eCommerce companies should dedicate their time and effort to keeping both their company and customer data safe from various security threats, and [PCI-compliant hosting](https://www.atlantic.net/pci-compliant-hosting/) can assist in making sure you’re meeting these standards. Following these steps, we have suggested an online store build to avoid data breaches, increasing customer retention and, as a result, a skyrocketing eCommerce company. --- # How to Install reveal.js on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-reveal-js-on-arch-linux/ | Published: 2023-04-23 | Updated: 2023-11-17 | Author: Hitesh Jethva reveal.js is a free and open-source HTML presentation framework. It allows users to create a simple and beautiful presentation via a web browser. You’ll need a browser with support for CSS 3D transforms to see it in its full glory. With reveal.js, you can create a presentation that supports mobile gestures, such as pinch and slide. In this post, we will show you how to install reveal.js with Nginx on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Node.js and NPM Before starting, you will need to install Node.js and NPM packages on your server. You can install both packages with the following command: ``` pacman -S nodejs npm ``` Once both packages are installed, you can verify the Node.js version with the following command. ``` node --version ``` You should see the following output. ``` v19.8.1 ``` ## Step 3 – Install reveal.js First, install the Git package using the following command. ``` pacman -S git ``` Next, download the latest version of reveal.js with the following command. ``` git clone https://github.com/hakimel/reveal.js.git ``` Once the download is completed, navigate to the reveal.js directory and install all the required dependencies using the following command. ``` cd reveal.js npm install ``` You can now run reveal.js with the following command. ``` npm start ``` If everything is fine, you will get the following output. ``` > reveal.js@4.4.0 start > gulp serve [13:33:30] Using gulpfile ~/reveal.js/gulpfile.js [13:33:30] Starting 'serve'... [13:33:30] Starting server... [13:33:30] Server started http://localhost:8000 [13:33:30] LiveReload started on port 35729 [13:33:30] Running server ``` Press the CTRL+C to stop the application. ## Step 4 – Create a Systemd Service File for reveal.js It is recommended to create a systemd file to manage reveal.js. You can create it with the following command. ``` nano /lib/systemd/system/reveal.service ``` Add the following lines. ``` [Service] Type=simple User=root Restart=on-failure WorkingDirectory=/root/reveal.js ExecStart=npm start ``` Save and close the file, then reload the system to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the reveal.js service. ``` systemctl start reveal.service systemctl enable reveal.service ``` To check the service status, run the following command. ``` systemctl status reveal.service ``` You will get the following output. ``` ● reveal.service Loaded: loaded (/usr/lib/systemd/system/reveal.service; static) Active: active (running) since Sat 2023-03-25 13:35:33 UTC; 35s ago Main PID: 7113 (npm start) Tasks: 22 (limit: 4685) Memory: 259.6M CPU: 15.621s CGroup: /system.slice/reveal.service ├─7113 "npm start" └─7124 "gulp serve" Mar 25 13:35:33 archlinux systemd[1]: Started reveal.service. Mar 25 13:35:34 archlinux npm[7113]: > reveal.js@4.4.0 start Mar 25 13:35:34 archlinux npm[7113]: > gulp serve Mar 25 13:35:36 archlinux npm[7124]: [13:35:36] Using gulpfile ~/reveal.js/gulpfile.js Mar 25 13:35:36 archlinux npm[7124]: [13:35:36] Starting 'serve'... Mar 25 13:35:36 archlinux npm[7124]: [13:35:36] Starting server... Mar 25 13:35:36 archlinux npm[7124]: [13:35:36] Server started http://localhost:8000 Mar 25 13:35:36 archlinux npm[7124]: [13:35:36] LiveReload started on port 35729 Mar 25 13:35:36 archlinux npm[7124]: [13:35:36] Running serve ``` ## Step 5 – Configure Nginx as a Reverse Proxy First, install the Nginx package with the following command. ``` pacman -S nginx-mainline ``` Next, start and enable the Nginx service with the following command. ``` systemctl start nginx systemctl enable nginx ``` Next, create a directory to store the Nginx virtual host. ``` mkdir /etc/nginx/sites-enabled ``` Next, create an Nginx configuration file for reveal.js. ``` nano /etc/nginx/sites-enabled/reveal.conf ``` Add the following configuration. ``` upstream reveal_backend { server localhost:8000; } server { listen 80; server_name reveal.example.com; location / { proxy_pass http://reveal_backend/; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forward-For $proxy_add_x_forwarded_for; proxy_set_header X-Forward-Proto http; proxy_set_header X-Nginx-Proxy true; proxy_redirect off; } } ``` Save the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following lines after http{: ``` server_names_hash_bucket_size 64; include sites-enabled/*; ``` Save the file, then verify the Nginx configuration using the following command. ``` nginx -t ``` You will get the following output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 6 – Access reveal.js Web UI Now, open your web browser and access the reveal.js web interface using the URL **http://reveal.example.com.** You should see the reveal default slide on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/p1-5.png) ## Conclusion In this post, we explained how to install reveal.js on Arch Linux. We also showed you how to configure Nginx as a reverse proxy for reveal.js. You now try to deploy reveal.js on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install phpIPAM on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-phpipam-on-arch-linux/ | Published: 2023-04-24 | Updated: 2023-11-17 | Author: Hitesh Jethva phpIPAM is a free, open-source, lightweight, and modern IP address monitoring tool for system and network administrators. It uses MySQL as a database system and is written in PHP, jQuery libraries, Ajax, and HTML5/CSS3. phpIPAM gives you a real-time inventory of used and unassigned IP addresses with other details like subnets, status, hostname, and more. This post will show you how to install phpIPAM with Nginx on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Nginx The Nginx package is included in the Arch Linux default repository by default. You can install it with the following command. ``` pacman -S nginx-mainline ``` After installing Nginx, start and enable the Nginx service using the following command. ``` systemctl start nginx systemctl enable nginx ``` ## Step 3 – Install and Configure PHP phpIPAM is a PHP-based application, so you must install PHP and other extensions to your server. You can install all of them using the following command. ``` pacman -S php php-fpm php-gd unzip ``` Next, you must install the Pear PHP extension to your system. You can download and install it with the following command. ``` wget http://pear.php.net/go-pear.phar php go-pear.phar ``` Next, edit the PHP configuration file and enable all the required PHP extensions. ``` nano /etc/php.ini ``` Add/modify the following lines. ``` extension=pdo_mysql extension=gd extension=json extension=mysqli extension=intl extension=xml extension=bcmath extension=gmp extension=iconv extension=gettext extension=sockets ``` Save and close the file, then start the PHP-FPM service and enable it to start at system reboot. ``` systemctl start php-fpm systemctl enable php-fpm ``` ## Step 4 – Install and Configure MariaDB Database Next, you will need to install the MariaDB database on your system. You can install it with the following command. ``` pacman -S mariadb ``` Once the MariaDB server is installed, initialize the MariaDB database with the following command. ``` mysql_install_db --user=mysql --basedir=/usr --datadir=/var/lib/mysql ``` Next, start and enable the MariaDB service using the following command. ``` systemctl start mysqld systemctl enable mysqld ``` Next, connect to the MariaDB shell: ``` mysql ``` Next, create a database and user for phpIPAM using the following command. ``` CREATE DATABASE phpipam; GRANT ALL ON phpipam.* TO phpipam@localhost IDENTIFIED BY 'password'; FLUSH PRIVILEGES; ``` Next, exit from the MariaDB with the following command. ``` QUIT; ``` ## Step 5 – Install phpIPAM First, download the latest version of phpIPAM to the Nginx root directory. ``` mkdir /var/www/html git clone --recursive https://github.com/phpipam/phpipam.git /var/www/html/phpipam ``` Next, navigate to the phpipam directory and copy the sample configuration file. ``` cd /var/www/html/phpipam cp config.dist.php config.php ``` Next, edit the configuration file. ``` nano config.php ``` Add the following line: ``` $allow_untested_php_versions=true; ``` Define your database settings: ``` /** * database connection details ******************************/ $db['host'] = 'localhost'; $db['user'] = 'phpipam'; $db['pass'] = 'password'; $db['name'] = 'phpipam'; $db['port'] = 3306; ``` Save and close the file, then import the phpIPAM database. ``` cd /var/www/html/phpipam mysql -u root -p phpipam < db/SCHEMA.sql ``` Next, change the ownership of the phpipam directory. ``` chown -R http:http /var/www/html/phpipam ``` ## Step 6 – Configure Nginx for phpIPAM Next, you must create an Nginx virtual host configuration file to serve phpIPAM. First, create a directory to store the Nginx virtual host. ``` mkdir /etc/nginx/sites-enabled ``` Next, create an Nginx configuration file for phpIPAM. ``` nano /etc/nginx/sites-enabled/phpipam.conf ``` Add the following configuration. ``` server { listen 80; # root directory server_name ipam.example.com; index index.php; root /var/www/html/phpipam; location / { try_files $uri $uri/ /index.php$is_args$args; } location ~ \.php$ { try_files $uri =404; fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_pass unix:/run/php-fpm/php-fpm.sock; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_index index.php; include fastcgi_params; } } ``` Save the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following lines after http{: ``` server_names_hash_bucket_size 64; include sites-enabled/*; ``` Save the file when you are done. Then, verify the Nginx configuration. ``` nginx -t ``` You will see the following output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Next, restart the Nginx service to implement the changes. ``` systemctl restart nginx ``` ## Step 7 – Access phpIPAM Web UI Now, open your web browser and access the phpIPAM web interface using the URL **http://ipam.example.com.** You should see the phpIPAM welcome screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/p1-2.png) Click on the **New phpipam** installation. You should see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/p2-2.png) Click on the **MySQL/MariaDB import instructions.** You should see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/p3-1.png) Provide your phpIPAM database details and click on the **install phpipam** database. You should see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/p4-1.png) Click on the **Login.** You should see your phpIPAM login screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/p6-1.png) Provide phpIPAM admin username **admin** and password as **ipamadmin**, then click the **Login** button. You should see the change password screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/p8-2.png) Change your default password and click on the **Save password.** Then, click on the **Dashboard** button. You should see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/p9-1.png) ## Conclusion Congratulations! You have successfully installed the phpIPAM password management tool on Arch Linux. You can now easily install phpIPAM on your server and test it. You can also try to deploy phpIPAM on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install OpenNMS on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-opennms-on-arch-linux/ | Published: 2023-04-25 | Updated: 2023-11-15 | Author: Hitesh Jethva OpenNMS is a free, open-source, self-hosted network monitoring and network management solution developed by OpenNMS Group. It helps you to visualize and monitor everything on your local and remote networks. OpenNMS can be integrated with business applications and workflows to monitor your networks. It comes with a web-based interface that allows you to monitor everything from a central place. In this post, we will show you how to install the OpenNMS monitoring tool with Docker on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Docker First, you will need to install Docker and Docker Compose on your server. You can install both packages with the following command. ``` pacman -S docker docker-compose ``` Once the Docker is installed, enable the Docker service to start at system reboot. ``` systemctl enable docker ``` Next, restart your system to apply the system. ``` reboot ``` ## Step 3 – Create a Docker Compose File for OpenNMS First, create a directory to store OpenNMS configurations. ``` mkdir opennms ``` Next, navigate to the OpenNMS directory and create a docker-compose.yml file. ``` cd opennms nano docker-compose.yml ``` Add the following configuration. ``` version: '3' volumes: data-postgres: {} data-opennms: {} services: database: image: postgres:12 container_name: database environment: - TZ=Europe/Berlin - POSTGRES_USER=postgres - POSTGRES_PASSWORD=postgres volumes: - data-postgres:/var/lib/postgresql/data healthcheck: test: [ "CMD-SHELL", "pg_isready -U postgres" ] interval: 10s timeout: 30s retries: 3 horizon: image: opennms/horizon:27.1.1 container_name: horizon environment: - TZ=Europe/Berlin - POSTGRES_HOST=database - POSTGRES_PORT=5432 - POSTGRES_USER=postgres - POSTGRES_PASSWORD=postgres - OPENNMS_DBNAME=opennms - OPENNMS_DBUSER=opennms - OPENNMS_DBPASS=opennms volumes: - data-opennms:/opt/opennms/share/rrd - ./overlay:/opt/opennms-overlay command: ["-s"] ports: - "8980:8980/tcp" - "8101:8101/tcp" - "61616:61616/tcp" healthcheck: test: [ "CMD", "curl", "-f", "-I", "http://localhost:8980/opennms/login.jsp" ] interval: 1m timeout: 5s retries: 3 ``` Save and close the file when you are done. ## Step 4 – Create OpenNMS Container Your docker-compose.yml file for OpenNMS is now ready to deploy OpenNMS. Run the following command inside the netbox directory to launch the Netbox container. ``` docker-compose up -d ``` If everything is fine, you will get the following output. ``` ✔ horizon 12 layers [⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿] 0B/0B Pulled 116.7s ✔ 7a0437f04f83 Pull complete 16.2s ✔ 14e88814ab83 Pull complete 17.1s ✔ 15d4a57fa9b3 Pull complete 38.0s ✔ 48f60c15ef49 Pull complete 39.0s ✔ 40326c4bdfdf Pull complete 80.7s ✔ 8fe30d1fc55f Pull complete 80.9s ✔ a0a9efee3070 Pull complete 81.1s ✔ 736b43559f0f Pull complete 81.2s ✔ fc4845e5d963 Pull complete 81.4s ✔ 0be5443a0ce9 Pull complete 115.5s ✔ bb3010fe38e5 Pull complete 115.6s ✔ 570c6a68cf58 Pull complete 115.7s ✔ database 13 layers [⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿] 0B/0B Pulled 40.3s ✔ f1f26f570256 Pull complete 18.1s ✔ 1c04f8741265 Pull complete 19.4s ✔ dffc353b86eb Pull complete 19.7s ✔ 18c4a9e6c414 Pull complete 20.6s ✔ 81f47e7b3852 Pull complete 23.7s ✔ 5e26c947960d Pull complete 24.5s ✔ a2c3dc85e8c3 Pull complete 24.8s ✔ 17df73636f01 Pull complete 25.1s ✔ 05add2dd64c8 Pull complete 37.9s ✔ f8eca8be8b3c Pull complete 38.2s ✔ cdf9a1dad65d Pull complete 38.4s ✔ 194ad2944d69 Pull complete 38.8s ✔ 66763d72b3d4 Pull complete 39.0s [+] Running 5/5 ✔ Network opennms_default Created 0.1s ✔ Volume "opennms_data-postgres" Created 0.0s ✔ Volume "opennms_data-opennms" Created 0.0s ✔ Container horizon Started 1.5s ✔ Container database Started 1.3s ``` You can also verify the Netbox container using the following command. ``` docker-compose ps ``` You will get the following output. ``` NAME IMAGE COMMAND SERVICE CREATED STATUS PORTS database postgres:12 "docker-entrypoint.s…" database 21 seconds ago Up 19 seconds (healthy) 5432/tcp horizon opennms/horizon:27.1.1 "/entrypoint.sh -s" horizon 21 seconds ago Up 18 seconds (health: starting) 0.0.0.0:8101->8101/tcp, :::8101->8101/tcp, 1162/udp, 0.0.0.0:8980->8980/tcp, :::8980->8980/tcp, 10514/udp, 0.0.0.0:61616->61616/tcp, :::61616->61616/tcp ``` ## Step 5 – Access OpenNMS Web Interface At this point, OpenNMS is started and listens on port 8980. Now, open your web browser and access OpenNMS using the URL **http://your-server-ip:8980.** You should see the OpenNMS login page. ![](https://www.atlantic.net/wp-content/uploads/2023/04/p1-8.png) Provide the OpenNMS default admin username and password as **admin/admin** then click on the **Login** button. You should see the OpenNMS dashboard on the following page. ![](https://www.atlantic.net/wp-content/uploads/2023/04/p2-8.png) ## Conclusion Congratulations! You have successfully installed OpenNMS with Docker on Arch Linux. You can now start monitoring your local and remote networks from a central location. You can also try to deploy the OpenNMS monitoring solution on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Netbox on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-netbox-on-arch-linux/ | Published: 2023-04-26 | Updated: 2023-11-14 | Author: Hitesh Jethva Netbox is an IP address management and data center infrastructure management tool for modeling and documenting modern networks. It is designed for network and infrastructure to empower engineers with network automation. It helps you to make your work easier by creating a map of every device in the data center. It is free and open-source so you don’t need to pay for this solution. In this post, we will show you how to install Netbox on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Require Dependencies First, you will need to install Redis and other Python dependencies on your server. You can install all of them by running the following command. ``` pacman -S redis python python-pip git ``` After the successful installation, start and enable the Redis service with the following command. ``` systemctl start redis systemctl enable redis ``` ## Step 3 – Install and Configure PostgreSQL Netbox uses PostgreSQL as a database backend, so you will need to install PostgreSQL on your server. First, install PostgreSQL using the following command. ``` pacman -S postgresql ``` Next, initialize PostgreSQL with the following command. ``` sudo -u postgres initdb --locale en_US.UTF-8 -D /var/lib/postgres/data ``` Next, start and enable the PostgreSQL service. ``` systemctl start postgresql systemctl enable postgresql ``` Next, log in to PostgreSQL with the following command. ``` sudo -u postgres psql ``` Next, create a database and user for Netbox using the following command. ``` CREATE USER netbox WITH PASSWORD 'password'; CREATE DATABASE netbox OWNER netbox; GRANT ALL PRIVILEGES ON DATABASE netbox TO netbox; ALTER DATABASE netbox OWNER TO netbox; ``` Finally, exit from the PostgreSQL shell with the following command. ``` \q ``` ## Step 4 – Install and Configure Netbox First, create a dedicated netbox user with the following command. ``` useradd -U netbox ``` Next, create a netbox directory and download the latest version of netbox inside the /opt/netbox. ``` mkdir /opt/netbox cd /opt/netbox git clone -b master https://github.com/netbox-community/netbox.git . ``` Next, change the ownership of the netbox directory. ``` chown -R root:netbox /opt/netbox/ ``` Next, navigate to the netbox directory and copy the sample configuration file. ``` cd /opt/netbox/netbox/netbox cp configuration_example.py configuration.py ``` Next, generate the secret key. ``` /opt/netbox/netbox/generate_secret_key.py ``` Output. ``` e1y$sW(RBxLfT0Qn9592j_5^^ESOXDavM+n0iT+wP!4Y6XEYn% ``` Next, edit the Netbox configuration file. ``` nano /opt/netbox/netbox/netbox/configuration.py ``` Define your allowed hosts, database, and secret key as shown below: ``` ALLOWED_HOSTS = ['*'] # PostgreSQL database configuration. See the Django documentation for a complete list of available parameters: # https://docs.djangoproject.com/en/stable/ref/settings/#databases DATABASE = { 'NAME': 'netbox', # Database name 'USER': 'netbox', # PostgreSQL username 'PASSWORD': 'password', # PostgreSQL password 'HOST': 'localhost', # Database server 'PORT': '', # Database port (leave blank for default) 'CONN_MAX_AGE': 300, # Max database connection age } SECRET_KEY = 'e1y$sW(RBxLfT0Qn9592j_5^^ESOXDavM+n0iT+wP!4Y6XEYn%' ``` Save and close the file. Then, navigate to the /opt/netbox directory and run the upgrade.sh script to install all required dependencies. ``` cd /opt/netbox/ ./upgrade.sh ``` If everything is fine, you should see the following output. ``` netbox.service ExecStart: /opt/netbox/venv/bin/gunicorn netbox-rq.service ExecStart: /opt/netbox/venv/bin/python After modifying these files, reload the systemctl daemon: > systemctl daemon-reload -------------------------------------------------------------------- Upgrade complete! Don't forget to restart the NetBox services: > sudo systemctl restart netbox netbox-rq ``` Next, activate the Netbox virtual environment with the following command. ``` source /opt/netbox/venv/bin/activate ``` Next, navigate to the netbox directory: ``` cd /opt/netbox/netbox ``` Next, create a super user for Netbox: ``` python3 manage.py createsuperuser ``` Define your admin user and password as shown below: ``` Username (leave blank to use 'root'): admin Email address: admin@example.com Password: Password (again): Superuser created successfully. ``` ## Step 5 – Create a Systemd Service File for Netbox First, copy the gunicorn and another service file to the desired location. ``` cp /opt/netbox/contrib/gunicorn.py /opt/netbox/gunicorn.py cp -v /opt/netbox/contrib/*.service /etc/systemd/system/ ``` Next, deactivate from the Python virtual environment. ``` deactivate ``` Next, reload the systemd daemon, start both netbox services, and enable them to start at system reboot. ``` systemctl daemon-reload systemctl start netbox netbox-rq systemctl enable netbox netbox-rq ``` Wait for some time to start the Netbox completely. Then, check the Netbox listening port with the following command. ``` ss -antpl | grep 8001 ``` You should see the following output. ``` LISTEN 0 0 127.0.0.1:8001 0.0.0.0:* users:(("gunicorn",pid=62051,fd=5),("gunicorn",pid=62050,fd=5),("gunicorn",pid=62049,fd=5),("gunicorn",pid=62048,fd=5),("gunicorn",pid=62047,fd=5),("gunicorn",pid=62045,fd=5)) ``` ## Step 6 – Configure Nginx as a Reverse Proxy At this point, Netbox is installed and listening on port 8001 on localhost. To access Netbox from the outside network, you will need to configure Nginx as a reverse proxy for Netbox. First, install Nginx with the following command. ``` pacman -S nginx-mainline ``` After installing Nginx, start and enable the Nginx service using the following command. ``` systemctl start nginx systemctl enable nginx ``` Next, create a directory to store Nginx virtual host files. ``` mkdir /etc/nginx/sites-enabled ``` Next, create an Nginx configuration file for Netbox. ``` nano /etc/nginx/sites-enabled/netbox.conf ``` Add the following configuration. ``` server { listen 80; # CHANGE THIS TO YOUR SERVER'S NAME server_name netbox.example.com; client_max_body_size 25m; location /static/ { alias /opt/netbox/netbox/static/; } location / { proxy_pass http://127.0.0.1:8001; proxy_set_header X-Forwarded-Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-Proto $scheme; } } ``` Save and close the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following lines after http{: ``` server_names_hash_bucket_size 64; include sites-enabled/*; ``` Save the file when you are done. Then, verify the Nginx configuration. ``` nginx -t ``` You will see the following output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Next, restart the Nginx service to implement the changes. ``` systemctl restart nginx ``` ## Step 7 – Access Netbox Web Interface Now, open your web browser and access the Netbox using the URL **http://netbox.example.com.** You should see the Netbox welcome screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/netbox-welcome-page.png)     Click on the **Login** button. You should see the Netbox login page. ![](https://www.atlantic.net/wp-content/uploads/2023/04/netbox-login-page.png) Provide your admin username and password and click on the **Sign in** button. You should see the Netbox dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/netbox-dashboard.png) ## Conclusion In this post, we explained how to install Netbox on Arch Linux. We also showed you how to configure Nginx as a reverse proxy for Netbox. You can now use Netbox in your organization and start managing all devices from a web browser. You can implement Netbox on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Jenkins with Docker and Docker Compose on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-jenkins-with-docker-and-docker-compose-on-arch-linux/ | Published: 2023-04-27 | Updated: 2024-06-02 | Author: Hitesh Jethva Jenkins is an accessible, open-source, self-hosted automation server that helps developers automate all parts of the software development process. It is based on Java and offers 1800+ plugins to support the automation of all kinds of tasks. Jenkins aims to continuously deliver your software by integrating with many testing and deployment technologies. It is cross-platform and can run on all major platforms including, macOS, Linux, and Windows. In this post, we will show you how to install Jenkins on Arch Linux. ## Step 1 – Configure the Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Docker In this post, we will use Docker to deploy Jenkins. You can install Docker and Docker Compose using the following command. ``` pacman -S docker docker-compose ``` Once the Docker is installed, enable the Docker service to start at system reboot. ``` systemctl enable docker ``` Next, restart your system to apply the system. ``` reboot ``` ## Step 3 – Create a Docker Compose File for Jenkins First, create directories for Jenkins using the following command. ``` mkdir jenkins jenkins_home ``` Next, navigate to the Jenkins directory and create a docker-compose.yml file. ``` cd jenkins nano docker-compose.yml ``` Add the following configurations. ``` version: '3.7' services: jenkins: image: jenkins/jenkins:lts privileged: true user: root ports: - 8080:8080 - 50000:50000 container_name: jenkins-lts volumes: - ~/jenkins_home:/var/jenkins_home - /var/run/docker.sock:/var/run/docker.sock - /usr/local/bin/docker:/usr/local/bin/docker ``` Save and close the file when you are done. ## Step 4 – Start Jenkins Container At this point, the docker-compose.yml file is ready to launch the Jenkins container. Run the following command inside the Jenkins directory to create a container. ``` docker-compose up -d ``` You should see the following output. ``` [+] Running 14/14 ✔ jenkins 13 layers [⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿] 0B/0B Pulled 24.0s ✔ 32fb02163b6b Pull complete 8.9s ✔ c09d5e9e1188 Pull complete 14.3s ✔ a56533012712 Pull complete 15.0s ✔ 7936e107ffe7 Pull complete 15.1s ✔ 3ca683058265 Pull complete 15.2s ✔ c2ecd304b4b8 Pull complete 17.4s ✔ be3512d810d6 Pull complete 17.5s ✔ 56b37d7c2a7a Pull complete 17.9s ✔ 99ed1e723e52 Pull complete 22.5s ✔ 256db5485b13 Pull complete 22.6s ✔ ee8c7eaf5e6b Pull complete 22.7s ✔ 509f66c2f317 Pull complete 22.8s ✔ 820296a845d6 Pull complete 22.9s [+] Running 2/2 ✔ Network jenkins_default Created 0.1s ✔ Container jenkins-lts Started 0.6s ``` You can verify the Jenkins container status using the following command. ``` docker-compose ps ``` You will get the following output. ``` NAME IMAGE COMMAND SERVICE CREATED STATUS PORTS jenkins-lts jenkins/jenkins:lts "/usr/bin/tini -- /u…" jenkins About a minute ago Up About a minute 0.0.0.0:8080->8080/tcp, :::8080->8080/tcp, 0.0.0.0:50000->50000/tcp, :::50000->50000/tcp ``` You will also need Jenkins’s initial admin password to perform the Jenkins web-based installation. You can get the Jenkins admin password with the following command. ``` docker exec jenkins-lts cat /var/jenkins_home/secrets/initialAdminPassword ``` You should see the password in the following output. ``` 99b844a4ad13404796e1ab8bcf05edd1 ``` You can also check the Jenkins logs to get the password. ``` docker logs jenkins-lts | less ``` You should see the following output. ``` Jenkins initial setup is required. An admin user has been created and a password generated. Please use the following password to proceed to installation: 99b844a4ad13404796e1ab8bcf05edd1 Running from: /usr/share/jenkins/jenkins.war webroot: /var/jenkins_home/war This may also be found at: /var/jenkins_home/secrets/initialAdminPassword ************************************************************* ************************************************************* ************************************************************* 2023-03-26 05:25:19.934+0000 [id=28] INFO jenkins.InitReactorRunner$1#onAttained: Completed initialization 2023-03-26 05:25:19.956+0000 [id=22] INFO hudson.lifecycle.Lifecycle#onReady: Jenkins is fully up and running 2023-03-26 05:25:20.151+0000 [id=44] INFO h.m.DownloadService$Downloadable#load: Obtained the updated data file for hudson.tasks.Maven.MavenInstaller 2023-03-26 05:25:20.153+0000 [id=44] INFO hudson.util.Retrier#start: Performed the action check updates server successfully at the attempt #1 ``` ## Step 5 – Access Jenkins Web UI At this point, Jenkins is installed and listens on port 8080. You can now access it using the URL **http://your-server-ip:8080.** You should see the Jenkins initial setup password screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/jenkins-getting-started.png) Provide your password and click on the **Continue** button. You should see the customized Jenkins screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/jenkins-install-plugins.png) Click on Install **suggested plugins.** You should see the Getting Started screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/jenkins-create-account.png) Create your new admin user and click on the **Save and Continue** buttons. You should see the instance configuration screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/jenkins-instance-configuration.png) Click on the **Save and Finish** button. You should see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/jenkins-ready.png) Click on the **Start using Jenkins.** You should see the Jenkins dashboard. ![](https://www.atlantic.net/wp-content/uploads/2023/04/jenkins-dashboard.png) ## Conclusion In this post, we explained how to install Jenkins with Docker on Arch Linux. You can now explore the Jenkins features and implement them in your organization to automate all kinds of tasks. You can also try to deploy Jenkins on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Atlantic.Net Named Winner of the Coveted Global InfoSec Awards During RSA Conference 2023 > URL: https://www.atlantic.net/press-releases/atlantic-net-named-winner-of-the-coveted-global-infosec-awards-during-rsa-conference-2023/ | Published: 2023-04-27 | Updated: 2024-06-11 | Author: Mustafa Muhi Atlantic.Net Wins **Best Solution: Cybersecurity Healthcare Practices** IN 11th Annual Global InfoSec Awards at #RSAC 2023 ORLANDO, FLORIDA — APRIL 27, 2023 — Atlantic.Net was awarded “Best Solution: Cybersecurity Healthcare Practices” by Cyber Defense Magazine (CDM), the industry’s leading electronic information security magazine. “We’re thrilled to receive one of the most prestigious and coveted cybersecurity awards in the world from Cyber Defense Magazine during their 11th anniversary as an independent cybersecurity news and information provider.  We knew the competition would be tough, and the judges were leading infosec experts from around the globe, so we couldn’t be more pleased to receive this award,” said Marty Puranik, CEO of Atlantic.Net. ![GIA 2023](https://www.atlantic.net/wp-content/themes/anet/img/company/awards/gia-2023.png) “Atlantic.Net embodies three major features we judges look for to become winners: understanding tomorrow’s threats, today, providing a cost-effective solution and innovating in unexpected ways that can help mitigate cyber risk and get one step ahead of the next breach,” said Gary S. Miliefsky, Publisher of Cyber Defense Magazine. Please join us at the #RSAC RSA Conference 2023, [RSA conference](https://www.rsaconference.com/usa) today, as we share our red-carpet experience and proudly display our trophy online at our website, our blog and our social media channels. Atlantic.Net was founded in 1994 by two University of Florida students, Marty Puranik and Jose Sanchez. Originally, the company began as an ISP on the East Coast and quickly expanded its reach to become a major provider of internet services in the region. Over the years, Atlantic.Net has evolved into a world-class hosting provider, offering a range of cloud computing, [VPS](https://www.atlantic.net/vps-hosting/), [dedicated hosting services](https://www.atlantic.net/dedicated-server-hosting/), and compliance hosting solutions. One of the key areas of specialization for Atlantic.Net is its extensive range of [HIPAA-compliant hosting solutions](https://www.atlantic.net/hipaa-compliant-hosting/). These solutions cater to many healthcare clients, making Atlantic.Net a preferred hosting provider for the healthcare industry. The company’s diverse client base includes Ivy League universities, biotech and pharma companies, medical practices, and small and medium-sized businesses. Atlantic.Net also serves enterprise clients, providing them with reliable and secure hosting solutions that meet their specific needs. With multiple locations throughout the US, Canada, and the United Kingdom, Atlantic.Net is committed to providing its clients with reliable, secure, and scalable hosting solutions. Its portfolio of hosting solutions is designed to cater to businesses of all sizes, from startups to large enterprises. The company’s commitment to security and reliability and exceptional customer support makes Atlantic.Net a preferred hosting provider for businesses worldwide. **About Atlantic.Net** Atlantic.Net is a global cloud services provider with over 29 years of experience, specializing in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions, backed by 24/7/365 support through their global data centers located in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. **About CDM InfoSec Awards** This is Cyber Defense Magazine’s tenth year of honoring InfoSec innovators from around the Globe. Our submission requirements are for any startup, early stage, later stage, or public companies in the INFORMATION SECURITY (INFOSEC) space who believe they have a unique and compelling value proposition for their product or service. Learn more at [www.cyberdefenseawards.com](https://www.cyberdefenseawards.com) **About the Judging** The judges are CISSP, FMDHS, CEH, certified security professionals who voted based on their independent review of the company submitted materials on the website of each submission including but not limited to data sheets, white papers, product literature and other market variables. CDM has a flexible philosophy to find more innovative players with new and unique technologies, than the one with the most customers or money in the bank. CDM is always asking “What’s Next?” so we are looking for best of breed, next generation InfoSec solutions. ### **Atlantic.Net, Inc. Media Inquiries:** Contact: Email:        pr@atlantic.net Ph:             1-321- 206-1371 **CDM Media Inquiries:** Contact:                 Irene Noser, Marketing Executive Email:                     [marketing@cyberdefensemagazine.com](mailto:marketing@cyberdefensemagazine.com) Toll Free (USA):    1-833-844-9468 International:       1-646-586-9545 --- # How to install GitLab with Docker and Docker Compose on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-gitlab-with-docker-and-docker-compose-on-arch-linux/ | Published: 2023-04-28 | Updated: 2024-06-02 | Author: Hitesh Jethva GitLab is an open-source DevOps and DevSecOps platform and code repository. It is designed for large DevOps and DevSecOps projects and offers online code storage and capabilities for issue tracking and CI/CD. GitLab helps organizations speed up software development by delivering software faster and more efficiently. One of the significant advantages of GitLab is that it allows developers to collaborate in every project phase, automate the entire DevOps lifecycle, and achieve the best possible results. This post will show you how to install GitLab with Docker on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Docker In this post, we will use Docker to install GitLab, so you must install both Docker and Docker Compose packages on your server. Run the following command to install both packages. ``` pacman -S docker docker-compose ``` Once installed, enable the Docker service to start at system reboot. ``` systemctl enable docker ``` Next, restart your system to apply the system. ``` reboot ``` ## Step 3 – Create a Docker-Compose File for GitLab First, create a directory storing GitLab configurations. ``` mkdir gitlab ``` Next, export the directory path using the following command. ``` export GITLAB_HOME=$(pwd)/gitlab ``` Next, navigate to the GitLab directory and create a docker-compose.yml file. ``` cd gitlab nano docker-compose.yml ``` Add the following configurations: ``` version: '3.7' services: web: image: 'gitlab/gitlab-ce:latest' restart: always hostname: 'localhost' container_name: gitlab-ce environment: GITLAB_OMNIBUS_CONFIG: | external_url 'http://localhost' ports: - '8080:80' - '8443:443' volumes: - '$GITLAB_HOME/config:/etc/gitlab' - '$GITLAB_HOME/logs:/var/log/gitlab' - '$GITLAB_HOME/data:/var/opt/gitlab' networks: - gitlab gitlab-runner: image: gitlab/gitlab-runner:alpine container_name: gitlab-runner restart: always depends_on: - web volumes: - /var/run/docker.sock:/var/run/docker.sock - '$GITLAB_HOME/gitlab-runner:/etc/gitlab-runner' networks: - gitlab networks: gitlab: name: gitlab-network ``` Save and close the file when you are done. ## Step 4 – Launch GitLab Container At this point, the docker-compose.yml file is ready to start the GitLab container. Run the following command inside the GitLab directory to launch the GitLab container. ``` docker-compose up -d ``` You should see the following output. ``` [+] Running 13/13 ✔ gitlab-runner 3 layers [⣿⣿⣿] 0B/0B Pulled 15.9s ✔ 9621f1afde84 Pull complete 2.1s ✔ d98190f30ae9 Pull complete 14.6s ✔ d147c4edb07a Pull complete 14.8s ✔ web 8 layers [⣿⣿⣿⣿⣿⣿⣿⣿] 0B/0B Pulled 152.1s ✔ 5544ebdc0c7b Pull complete 4.5s ✔ c5213c581bf5 Pull complete 8.2s ✔ a58d99176887 Pull complete 8.5s ✔ 7ae8a2c59be5 Pull complete 8.8s ✔ 2017c98fba37 Pull complete 9.0s ✔ 2f81550514d7 Pull complete 9.2s ✔ b7e289348f9c Pull complete 9.4s ✔ d5fd7dcd275c Pull complete 151.3s [+] Running 3/3 ✔ Network gitlab-network Created 0.1s ✔ Container gitlab-ce Started 0.8s ✔ Container gitlab-runner Started 1.3s ``` You can verify the GitLab container status using the following command. ``` docker-compose ps ``` You should see the following output. ``` NAME IMAGE COMMAND SERVICE CREATED STATUS PORTS gitlab-ce gitlab/gitlab-ce:latest "/assets/wrapper" web 31 seconds ago Up 30 seconds (health: starting) 22/tcp, 0.0.0.0:8080->80/tcp, :::8080->80/tcp, 0.0.0.0:8443->443/tcp, :::8443->443/tcp gitlab-runner gitlab/gitlab-runner:alpine "/usr/bin/dumb-init …" gitlab-runner 31 seconds ago Up 29 seconds ``` You can also verify the GitLab listening ports using the following command. ``` ss -antpl | grep docker ``` You will get the following output. ``` LISTEN 0 4096 0.0.0.0:8080 0.0.0.0:* users:(("docker-proxy",pid=12635,fd=4)) LISTEN 0 4096 0.0.0.0:8443 0.0.0.0:* users:(("docker-proxy",pid=12617,fd=4)) LISTEN 0 4096 [::]:8080 [::]:* users:(("docker-proxy",pid=12641,fd=4)) LISTEN 0 4096 [::]:8443 [::]:* users:(("docker-proxy",pid=12622,fd=4)) ``` ## Step 5 – Access GitLab Web UI At this point, GitLab is started and listening on port **8080.** You can now access it using the URL **http://your-server-ip:8080.** You should see the GitLab login screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/gitlab-login-page.png)   Next, go back to your GitLab terminal interface and retrieve the GitLab password with the following command. ``` docker exec -it gitlab-ce grep 'Password:' /etc/gitlab/initial_root_password ``` You should see the GitLab password in the following output. ``` Password: Kx1MoTQ80iKJkA3SXatepaFCOfsi/DkLe3MXEplfERU= ``` Next, return to the GitLab login screen, type your password, and click the **Sign in** button. You should see the GitLab dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/gitlab-dashboard.png) ## Conclusion In this post, we explained how to install GitLab on Arch Linux. You can now implement GitLab in your development environment, making the development process faster. You can also try to deploy GitLab on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Bitwarden Password Manager on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-bitwarden-password-manager-on-arch-linux/ | Published: 2023-04-29 | Updated: 2024-06-01 | Author: Hitesh Jethva Bitwarden is a fast, open-source password management solution trusted by millions of users worldwide. It stores all your passwords and sensitive information in an encrypted vault. You can store and manage all your login credentials in a central location and sync them across all devices. Bitwarden offers a client application for mobile, desktop, browser extensions, command line interface, and web interface. In this post, we will show you how to install the Bitwarden password manager on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Docker Bitwarden can be installed using Docker, so Docker and Docker Compose packages must be installed on your server. If not installed, you can install both by running the following command. ``` pacman -S docker docker-compose ``` Once Docker is installed, enable the Docker service to start at system reboot. ``` systemctl enable docker ``` Next, restart your system to apply the system. ``` reboot ``` ## Step 3 – Install Bitwarden First, download the Bitwarden installation script using the following command. ``` curl -Lso bitwarden.sh https://go.btwrdn.co/bw-sh ``` Next, set executable permissions on the downloaded file. ``` chmod +x bitwarden.sh ``` Now, run the downloaded script to start the installation. ``` ./bitwarden.sh install ``` You will be asked to define your domain or IP address, select Let’s Encrypt SSL and database as shown below: ``` _ _ _ _ | |__ (_) |___ ____ _ _ __ __| | ___ _ __ | '_ \| | __\ \ /\ / / _` | '__/ _` |/ _ \ '_ \ | |_) | | |_ \ V V / (_| | | | (_| | __/ | | | |_.__/|_|\__| \_/\_/ \__,_|_| \__,_|\___|_| |_| Open source password management solutions Copyright 2015-2023, 8bit Solutions LLC https://bitwarden.com, https://github.com/bitwarden =================================================== bitwarden.sh version 2023.3.0 Docker version 23.0.1, build a5ee5b1dfc Docker Compose version 2.17.0 (!) Enter the domain name for your Bitwarden instance (ex. bitwarden.example.com): 104.219.55.77 (!) Do you want to use Let's Encrypt to generate a free SSL certificate? (y/n): n (!) Enter the database name for your Bitwarden instance (ex. vault): vault ``` Answer all the questions then press the **Enter** key. You will be asked to provide your Bitwarden installation id and key: ``` 2023.3.0: Pulling from bitwarden/setup 3f9582a2cbe7: Pull complete d866aec6058e: Pull complete 11332129480d: Pull complete 9f9b514859b0: Pull complete b709e83c5e9e: Pull complete 1f8900615ea1: Pull complete 47137b35c8bf: Pull complete b7b87e36a4d9: Pull complete 223d50917a39: Pull complete 23ee09621502: Pull complete Digest: sha256:e09da2acdedd62819dd1fe774935d1a215058244cc6e1c18203bb65cf845f70c Status: Downloaded newer image for bitwarden/setup:2023.3.0 docker.io/bitwarden/setup:2023.3.0 (!) Enter your installation id (get at https://bitwarden.com/host): Installation ID (!) Enter your installation key: Installation Key ``` Provide your installation ID and key and press the **Enter** key. You will be asked for SSL certificates. ``` (!) Do you have a SSL certificate to use? (y/n): n (!) Do you want to generate a self-signed SSL certificate? (y/n): y ``` Choose your preferred options and press the **Enter** key. Once the installation is completed, you will get the following output. ``` Generating self signed SSL certificate. Generating a RSA private key ....................................++++ .................................................++++ writing new private key to '/bitwarden/ssl/self/104.219.55.77/private.key' ----- Generating key for IdentityServer. Generating a RSA private key ..............................++++ ........++++ writing new private key to 'identity.key' ----- Building nginx config. Building docker environment files. Building docker environment override files. Building FIDO U2F app id. Building docker-compose.yml. Installation complete If you need to make additional configuration changes, you can modify the settings in `./bwdata/config.yml` and then run: `./bitwarden.sh rebuild` or `./bitwarden.sh update` Next steps, run: `./bitwarden.sh start` ``` ## Step 4 – Start the Bitwarden After successful installation, you can start the Bitwarden using the following command. ``` ./bitwarden.sh start ``` If everything is fine, you will get the following output. ``` [+] Running 89/11 ✔ events 5 layers [⣿⣿⣿⣿⣿] 0B/0B Pulled 28.3s ✔ identity 5 layers [⣿⣿⣿⣿⣿] 0B/0B Pulled 41.9s ✔ icons 5 layers [⣿⣿⣿⣿⣿] 0B/0B Pulled 39.2s ✔ notifications 5 layers [⣿⣿⣿⣿⣿] 0B/0B Pulled 31.7s ✔ web 11 layers [⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿] 0B/0B Pulled 30.5s ✔ nginx 15 layers [⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿] 0B/0B Pulled 10.2s ✔ mssql 9 layers [⣿⣿⣿⣿⣿⣿⣿⣿⣿] 0B/0B Pulled 82.1s ✔ api 9 layers [⣿⣿⣿⣿⣿⣿⣿⣿⣿] 0B/0B Pulled 11.2s ✔ sso 5 layers [⣿⣿⣿⣿⣿] 0B/0B Pulled 17.7s ✔ attachments 4 layers [⣿⣿⣿⣿] 0B/0B Pulled 27.5s ✔ admin 5 layers [⣿⣿⣿⣿⣿] 0B/0B Pulled 40.0s [+] Running 13/13 ✔ Network docker_default Created0.0s ✔ Network docker_public Created0.1s ✔ Container bitwarden-attachments Started2.4s ✔ Container bitwarden-sso Started4.9s ✔ Container bitwarden-mssql Started1.0s ✔ Container bitwarden-web Started1.8s ✔ Container bitwarden-identity Started4.0s ✔ Container bitwarden-notifications Started4.2s ✔ Container bitwarden-api Started4.9s ✔ Container bitwarden-events Started4.8s ✔ Container bitwarden-icons Started4.7s ✔ Container bitwarden-admin Started4.7s ✔ Container bitwarden-nginx Started6.6s 2023.3.0: Pulling from bitwarden/setup Digest: sha256:e09da2acdedd62819dd1fe774935d1a215058244cc6e1c18203bb65cf845f70c Status: Image is up to date for bitwarden/setup:2023.3.0 docker.io/bitwarden/setup:2023.3.0 Bitwarden is up and running! =================================================== visit http://104.219.55.77 to update, run `./bitwarden.sh updateself` and then `./bitwarden.sh update` ``` You can now verify the Bitwarden container status with the following command. ``` docker ps ``` You should see the following output. ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 158a32601c48 bitwarden/nginx:2023.3.0 "/entrypoint.sh" 24 seconds ago Up 17 seconds (health: starting) 80/tcp, 0.0.0.0:80->8080/tcp, :::80->8080/tcp, 0.0.0.0:443->8443/tcp, :::443->8443/tcp bitwarden-nginx ff726721653e bitwarden/admin:2023.3.0 "/entrypoint.sh" 24 seconds ago Up 19 seconds (health: starting) 5000/tcp bitwarden-admin 82165ad0a2fb bitwarden/attachments:2023.3.0 "/entrypoint.sh" 24 seconds ago Up 22 seconds (health: starting) bitwarden-attachments b066cc257c91 bitwarden/web:2023.3.0 "/entrypoint.sh" 24 seconds ago Up 22 seconds (health: starting) bitwarden-web 3556668964b6 bitwarden/notifications:2023.3.0 "/entrypoint.sh" 24 seconds ago Up 20 seconds (health: starting) 5000/tcp bitwarden-notifications 4d283de21017 bitwarden/identity:2023.3.0 "/entrypoint.sh" 24 seconds ago Up 20 seconds (health: starting) 5000/tcp bitwarden-identity e46b0bc8fbf5 bitwarden/api:2023.3.0 "/entrypoint.sh" 24 seconds ago Up 19 seconds (health: starting) 5000/tcp bitwarden-api 50409251986e bitwarden/mssql:2023.3.0 "/entrypoint.sh" 24 seconds ago Up 23 seconds (health: starting) bitwarden-mssql 83b214e36cd7 bitwarden/events:2023.3.0 "/entrypoint.sh" 24 seconds ago Up 19 seconds (health: starting) 5000/tcp bitwarden-events e5090c0b53e2 bitwarden/sso:2023.3.0 "/entrypoint.sh" 24 seconds ago Up 19 seconds (health: starting) 5000/tcp bitwarden-sso cc449cb26fb8 bitwarden/icons:2023.3.0 "/entrypoint.sh" 24 seconds ago Up 19 seconds (health: starting) 5000/tcp ``` ## Step 5 – Access Bitwarden Web UI At this point, Bitwarden is started and listening on port 80. You can access it using the URL **https://your-server-ip.** You should see the Bitwarden login page. ![](https://www.atlantic.net/wp-content/uploads/2023/04/bitwarden-create-account.jpg) Click on the **Create account** page. You should see the following page. ![](https://www.atlantic.net/wp-content/uploads/2023/04/define-account-information.jpg) Define your email, username, and password, and click on the **Create account** button. You should see your login screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/provide-master-password.png) Provide your master password and click on **Login with** **master** password. You should see the Bitwarden dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/04/bitwarden-dashboard.png) ## Conclusion In this post, you learned how to install the Bitwarden password manager on Arch Linux. You can now implement Bitwarden in your organization and start managing all credentials from a central location. You can try to install Bitwarden password manager on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install AzuraCast Radio Management Suite on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-azuracast-radio-management-suite-on-arch-linux/ | Published: 2023-04-30 | Updated: 2024-06-05 | Author: Hitesh Jethva AzuraCast is a free, open-source, and self-hosted radio station suite that lets you get a web radio station up and running in minutes. It comes with a powerful and intuitive interface that helps you manage every aspect of your radio station via a web browser. You can perform several tasks such as uploading media, managing playlists, and creating local mount points and remote relays via a web-based interface. AzureCast supports remote relays that broadcast your radio signal to any remote server on Icecast. In this post, we will show you how to install AzuraCast Web Radio Management Suite on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Docker The AzuraCastsuite is available as a Docker container, so Docker and Docker Compose packages must be installed on your server. If not installed, you can install both by running the following command. ``` pacman -S docker docker-compose ``` Once Docker is installed, enable the Docker service to start at system reboot. ``` systemctl enable docker ``` Next, restart your system to apply the system. ``` reboot ``` After the successful restart, you can verify the Docker status using the following command. ``` systemctl status docker ``` ## Step 3 – Install AzuraCast First, create a directory to store AzuraCast configuration files. ``` mkdir -p /var/azuracast ``` Next, navigate to the AzuraCast directory and download the AzuraCast installation script. ``` cd /var/azuracast curl -fsSL https://raw.githubusercontent.com/AzuraCast/AzuraCast/main/docker.sh > docker.sh ``` Next, set executable permissions on the downloaded file. ``` chmod a+x docker.sh ``` Next, start the AzuraCast installation using the following command. ``` ./docker.sh install ``` You will be asked to switch to the stable release channel. ``` Checking installation requirements for AzuraCast... [PASS] Operating System: Linux [PASS] Architecture: x86_64 [PASS] Command Present: curl [PASS] Command Present: awk [PASS] User Permissions [PASS] Installation Directory [PASS] All requirements met! Docker is already installed! Continuing... Docker Compose is already installed. Continuing... Your current release channel is 'Rolling Release'. Switch to 'Stable' release channel? [y/N] N ``` Type **N** and press the **Enter** key. You will be asked to select the language. ``` Select Language [English (Default)]: [en_US] English (Default) [cs_CZ] čeština [de_DE] Deutsch [es_ES] Español [fr_FR] Français [el_GR] ελληνικά [it_IT] Italiano [hu_HU] magyar [nl_NL] Nederlands [pl_PL] Polski [pt_PT] Português [pt_BR] Português do Brasil [ru_RU] Русский язык [sv_SE] Svenska [tr_TR] Türkçe [zh_CN] 簡化字 [ko_KR] 한국어 > ``` Just press the **Enter** key to select the English language. You will be asked to use a custom port. ``` AzuraCast Installer =================== Welcome to AzuraCast! Complete the initial server setup by answering a few questions. AzuraCast is currently configured to listen on the following ports: * HTTP Port: 80 * HTTPS Port: 443 * SFTP Port: 2022 * Radio Ports: 8000,8005,8006,8010,8015,8016,8020,8025,8026,8030,8035,8036,8040,8045,8046,8050,8055,8056,8060,8065,8066,8070,8075,8076,8090,8095,8096,8100,8105,8106,8110,8115,8116,8120,8125,8126,8130,8135,8136,8140,8145,8146,8150,8155,8156,8160,8165,8166,8170,8175,8176,8180,8185,8186,8190,8195,8196,8200,8205,8206,8210,8215,8216,8220,8225,8226,8230,8235,8236,8240,8245,8246,8250,8255,8256,8260,8265,8266,8270,8275,8276,8280,8285,8286,8290,8295,8296,8300,8305,8306,8310,8315,8316,8320,8325,8326,8330,8335,8336,8340,8345,8346,8350,8355,8356,8360,8365,8366,8370,8375,8376,8380,8385,8386,8390,8395,8396,8400,8405,8406,8410,8415,8416,8420,8425,8426,8430,8435,8436,8440,8445,8446,8450,8455,8456,8460,8465,8466,8470,8475,8476,8480,8485,8486,8490,8495,8496 Customize ports used for AzuraCast? (yes/no) [no]: > ``` Just press the **Enter** key to use the default ports. You will be asked to enable the custom plugins. ``` Enable Custom Code Plugins (yes/no) [no]: > ``` Press the Enter key to enable the default plugins. You will be asked to enable the web-based Docker image updates. ``` Enable web-based Docker image updates (yes/no) [yes]: > ``` Press the Enter key to use the default option. Once the installation has been completed, you should see the following output. ``` Writing configuration files... Restarting all radio stations... -------------------------------- 0 [▓░░░░░░░░░░░░░░░░░░░░░░░░░░░] [OK] AzuraCast installation complete! Visit http://209.23.10.234 to complete setup. [+] Running 2/2 ✔ Container azuracast_updater Started 0.7s ✔ Container azuracast Started 4.7s ``` ## Step 4 – Access AzuraCast Web UI Now, open your web browser and access AzuraCast using the URL **http://your-server-IP.** You should see the AzuraCast Setup page.   ![](https://www.atlantic.net/wp-content/uploads/2023/04/p1-1.png) Set your email address, and password then click on the **CREATE ACCOUNT.** You should see the”Create a radio station” page. ![](https://www.atlantic.net/wp-content/uploads/2023/04/p2-1.png) ![](https://www.atlantic.net/wp-content/uploads/2023/04/p3.png) Provide your radio station information and click on the **CREATE AND CONTINUE.** You should see the “Customize AzuraCast” page. ![](https://www.atlantic.net/wp-content/uploads/2023/04/p5.png) Define all settings and click on **SAVE AND CONTINUE.** You should see the following page. ![](https://www.atlantic.net/wp-content/uploads/2023/04/p6.png) Click on the **MANAGE** button. You should see the following page. ![](https://www.atlantic.net/wp-content/uploads/2023/04/p7.png) Click on the **Music Files.** You should see the following page. ![](https://www.atlantic.net/wp-content/uploads/2023/04/p8-1.png) Click on the **SELECT FILES** to upload any MP3 file to AzuraCast. Once the file is added, you should see the following page. ![](https://www.atlantic.net/wp-content/uploads/2023/04/p9.png) You can now add these uploaded files to your playlist and start playing it via a web browser. ## Conclusion In this post, we explained how to install the AzuraCast radio station management tool on Arch Linux. You can now easily set up your own online radio station using AzuraCast. You can now try to set up AzuraCast on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Apache with Nginx as a Reverse Proxy on Arch Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-with-nginx-as-a-reverse-proxy-on-arch-linux/ | Published: 2023-05-02 | Updated: 2024-06-03 | Author: Hitesh Jethva A reverse proxy is an intermediate server that sits between clients and web servers. It serves as a front-end and is responsible for handling all client requests and forwarding them to the backend server. For better privacy and security, you may need to implement a reverse proxy in front of a web server. Apache and Nginx both are very popular open-source web servers used by thousands of users worldwide. Nginx hosts static websites, proxy servers, and caching servers. While Apache is used to host dynamic websites, you can also configure Nginx as a reverse proxy for Apache webserver to get advantages of both web servers. In this post, we will show you how to configure Nginx as a reverse proxy for the Apache web servers on Arch Linux. ## Step 1 – Configure Repository By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list. You can do it by editing the mirror list configuration file: ``` nano /etc/pacman.d/mirrorlist ``` Remove all lines and add the following lines: ``` ## Score: 0.7, United States Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.8, United States Server = http://lug.mtu.edu/archlinux/$repo/os/$arch Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch ## Score: 0.9, United Kingdom Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch ## Score: 1.5, United Kingdom Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch ## Score: 6.6, United States Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch ## Score: 6.7, United States Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch ## Score: 6.8, United States Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch ## Score: 7.1, India Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch ## Score: 10.1, United States Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch ``` Save and close the file, then update all the package indexes with the following command: ``` pacman -Syu ``` ## Step 2 – Install Apache Web Server First, open your terminal and install the Apache package with the following command. ``` pacman -S apache ``` After successful installation, start and enable the Apache service with the following command. ``` systemctl start httpd systemctl enable httpd ``` You can also verify the Apache status using the following command. ``` systemctl status httpd ``` Output. ``` ● httpd.service - Apache Web Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; preset: disabled) Active: active (running) since Sun 2023-03-26 05:46:34 UTC; 3min 7s ago Main PID: 14223 (httpd) Tasks: 9 (limit: 4685) Memory: 45.5M CPU: 207ms CGroup: /system.slice/httpd.service ├─14223 /usr/bin/httpd -k start -DFOREGROUND ├─14224 /usr/bin/httpd -k start -DFOREGROUND ├─14225 /usr/bin/httpd -k start -DFOREGROUND ├─14226 /usr/bin/httpd -k start -DFOREGROUND ├─14227 /usr/bin/httpd -k start -DFOREGROUND ├─14228 /usr/bin/httpd -k start -DFOREGROUND ├─14231 /usr/bin/httpd -k start -DFOREGROUND ├─14232 /usr/bin/httpd -k start -DFOREGROUND └─14233 /usr/bin/httpd -k start -DFOREGROUND Mar 26 05:46:34 archlinux systemd[1]: Started Apache Web Server. ``` ## Step 3 – Configure Apache as a Backend Server By default, Apache listens on port 80. To configure Apache as a backend server, you will need to change the Apache default port. You can change it by editing the Apache main configuration file. ``` nano /etc/httpd/conf/httpd.conf ``` Change the following line. ``` Listen 8000 ``` Save and close the file, then restart the Apache service to implement the changes. ``` systemctl restart httpd ``` You can now check the Apache listening port using the following command. ``` ss -antpl | grep httpd ``` You should see the new Apache port in the following output. ``` LISTEN 0 511 *:8000 *:* users:(("httpd",pid=14233,fd=4),("httpd",pid=14232,fd=4),("httpd",pid=14231,fd=4),("httpd",pid=14228,fd=4),("httpd",pid=14227,fd=4),("httpd",pid=14226,fd=4),("httpd",pid=14225,fd=4),("httpd",pid=14224,fd=4),("httpd",pid=14223,fd=4)) ``` ## Step 4 – Create a Simple Page for Apache Next, you will need to create a simple HTML page to test the Apache server. You can create it with the following command. ``` nano /srv/http/index.html ``` Add the following code: ``` Welcome

Welcome to Apache Web Server

``` Save and close the file when you are done. ## Step 5 – Install and Configure Nginx as a Reverse Proxy First, install the Nginx package using the following command. ``` pacman -S nginx-mainline ``` After installing Nginx, start and enable the Nginx service using the following command. ``` systemctl start nginx systemctl enable nginx ``` Next, create a directory to store Nginx virtual host. ``` mkdir /etc/nginx/sites-enabled ``` Next, create an Nginx configuration file to forward traffic to the Apache backend server. ``` nano /etc/nginx/sites-enabled/apache.conf ``` Add the following configuration. ``` upstream apache_backend { server localhost:8000; } server { listen 80; server_name apache.example.com; location / { proxy_pass http://apache_backend/; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forward-For $proxy_add_x_forwarded_for; proxy_set_header X-Forward-Proto http; proxy_set_header X-Nginx-Proxy true; proxy_redirect off; } } ``` Save and close the file, then edit the Nginx configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following lines after http{: ``` server_names_hash_bucket_size 64; include sites-enabled/*; ``` Save the file when you are done. Then, verify the Nginx configuration. ``` nginx -t ``` You will see the following output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Next, restart the Nginx service to implement the changes. ``` systemctl restart nginx ``` ## Step 6 – Verify Nginx Proxy At this point, Nginx is installed and configured to forward traffic to the Apache backend server. You can test it using the URL **http://apache.example.com** in your web browser. You should see the Apache backend page on the following screen. ![Verify Nginx](https://www.atlantic.net/wp-content/uploads/2023/04/verify-nginx.png) ## Conclusion In this tutorial, you learned how to configure Nginx as a reverse proxy for the Apache web server. You can use this guide to implement this setup in the production environment. Try this setup on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Best Use of the Cloud in a Multi-Cloud Environment > URL: https://www.atlantic.net/vps-hosting/best-use-of-the-cloud-in-a-multi-cloud-environment/ | Published: 2023-05-05 | Updated: 2024-09-24 | Author: Richard Bailey Large enterprise businesses sometimes invest and develop a multi-cloud strategy that spans cloud services across multiple providers and often on-premises infrastructure. A multi-cloud setup might be considered a romantic idea that is hard to achieve, so businesses often choose relevant services from various cloud providers to create a resilient service mesh. ## Why Choose Multi-Cloud? Multi-cloud is adopted to improve infrastructure resilience, meet compliance demands, reduce the chances of downtime, and diminish any concerns around vendor lock-in. Although your multi-cloud journey may include backups, disaster recovery, or isolating applications, every business uses multi-cloud differently. Multi-cloud environments introduce significant challenges surrounding their management and implementation. For example, data governance has added complexity because data is located at various touch points within different cloud providers. In addition, multi-cloud is expensive, and it requires having experienced technical teams that are skilled in multiple cloud vendors. There are numerous pros and cons to having a multi-cloud strategy. This article will discover the best use of the cloud in a multi-cloud environment. ## More Than Just Public and Private: What Is Multi-Cloud? Multi-cloud is precisely what it sounds like; it is when businesses leverage multiple public and private clouds. But what exactly does that mean? Of course, the public cloud is any publicly available cloud provider, including the heavyweight providers AWS, Google Cloud, and Azure. But other providers, including Atlantic.Net, are a genuine alternative to the hyper-scale providers. “Private cloud” is a name often given to non-public shared hosting environments. For businesses, this is hosting at a [colocation](https://www.atlantic.net/orlando-colocation-hosting-data-center/what-is-colocation-hosting/); perhaps it is a virtual cloud running on VMware or OpenStack. On the other hand, it may be an on-premise hybrid stack that connects directly to the cloud, such as AWS Outposts, Azure Stack, and Google Anthos. A multi-cloud configuration is desirable for many reasons: - **Introduce Low Latency:** It doesn’t matter how big the cloud provider is; not all cloud providers have a point of presence in the parts of the world where your customers are located. A good example might be a European or American company serving customers in China, the Middle East, Australasia, and regions of East Asia. Customers may choose to leverage providers with a strong presence in these areas. - **Offer A Better User Experience: **Being closer to your customers will result in a much faster connection and response for the customer, improving the user experience dramatically. - **Keep Sensitive Data On-Premise:** Many businesses have compliance requirements that enforce data sovereignty because some personal data is too important to be allowed in the public realm, typically information the government keeps on you. To combat this problem, a multi-cloud configuration enables you to use the power of the cloud while keeping sensitive data onsite. - **Automate Tasks:** To be an efficient and influential player in a multi-cloud world, automation must be embedded within your organization. It’s much easier to manage and secure a multi-cloud platform using infrastructure as code than attempting to manage manually. Combining IAC and having some control plane allows engineers, operators, and developers to have a simple way to deploy resources throughout every cloud ecosystem. - **Increase Visibility:** It’s critical to have a holistic view of the multi-cloud infrastructure; this is commonly achieved using [Grafana](https://www.atlantic.net/dedicated-server-hosting/how-to-install-grafana-on-oracle-linux-8/) and [Prometheus](https://www.atlantic.net/dedicated-server-hosting/how-to-install-prometheus-system-monitoring-tool-on-oracle-linux-8/). Monitoring tools like these are vendor agnostic and widely used. ## Multi-Cloud Use Cases How multi-cloud configurations are used varies from customer to customer. Multi-cloud helps businesses reuse infrastructure assets they have already procured and provides cost-effective options. But there are five everyday use cases Atlantic.Net engineers witness. - **Tiered/Layered Applications:** This approach is used by businesses looking for global-scale resilience. Applications, particularly those running in containers or Kubernetes, are the scale between providers. A Kubernetes stack will happily scale across service providers by providing rapid and resilient networking. ** ** - **Partitioned Application**: Partitioned apps are usually servers that operate independently but as part of a stack. You might run the frontend in AWS and the backend and midtier in Atlantic.Net. This approach lowers the risk of downtime. - **Edge Computing:** Multi-cloud users can create a central control plane at the network edge that reduces application load and improves performance. - **Analytics**: A Multi-cloud setup is perfect for data analytics; heavy transactions are processed on-premises to improve performance and lower costs, and cloud-native services, such as AI and managed data lakes, are offloaded to the cloud. - **Bursting:** Bursting happens when a business uses private servers; however, workloads are burst to run in the cloud to improve processing time. This setup is popular with Big Pharma businesses that need intense CPU cycles to process massive datasets quickly. ## Obstacles to Overcome Multi-cloud is still reserved for the most prominent companies with deep pockets, and there are several obstacles to overcome even to consider multi-cloud as a viable option. First, to avoid an administration headache, the business should have single sign-on (SSO) enabled; this allows users and engineers to log into all environments with a single username, password, and MFA credential. Unified cloud security posture management ([CSPM](https://www.wiz.io/academy/what-is-cloud-security-posture-management-cspm)) is needed for multi-cloud environments. Tools like CloudStrike and Checkpoint are designed to identify misconfiguration issues and compliance risks. Additionally, infrastructure as code is required for security compliance and infrastructure deployment across vendors to manage everything. ## Make Atlantic.Net Part Of Your Multi-Cloud Strategy Atlantic.Net provides world-class hosting services, including [virtual private servers](https://www.atlantic.net/vps-hosting/), dedicated hosting, HIPAA hosting, and more. Our custom cloud platform is robust and user-friendly. Why not experiment with it as part of your multi-cloud strategy? You can spin our 1-click applications in under 30 seconds from the intuitive [cloud management portal](https://cloud.atlantic.net/?page=userlogin). --- # Do You Need To Be HIPAA-Compliant When Selling Medical Supplies Online and Collecting Insurance Information? > URL: https://www.atlantic.net/hipaa-compliant-hosting/do-you-need-to-be-hipaa-compliant-when-selling-medical-supplies-online-and-collecting-insurance-information/ | Published: 2023-05-07 | Updated: 2025-09-15 | Author: Richard Bailey The rules of HIPAA-Compliance apply to any business entity when protected health information is involved. For example, when PHI is electronically processed, stored, and managed, the physical, administrative, and technical safeguards of HIPAA compliance must apply. When it comes to selling medical supplies online or collecting insurance information, the same rules apply; if it involves PHI, the entity must be HIPAA-Compliant. The article will break down these situations, discover when HIPAA-Compliance is needed, and learn if HIPAA applies in all circumstances. Unfortunately, these types of businesses often confuse medical professionals because the distinction between what rules apply is often unclear and difficult to comprehend in some cases. ## Do You Need to Be HIPAA-Compliant When Selling Medical Supplies? Countless online medical supply distributors sell everything you need for a hospital or medical practice. Everyday items include medical equipment such as EKG machines, Ventilators, and Dopplers. They also sell consumables like bandages, facemasks, and everyday medical kits. Some medical devices fall under HIPAA compliance; however, if the equipment is brand new and straight from the factory, then HIPAA compliance does not apply because the equipment is brand new and has never been in touch with a patient. The complexities arise when medical supplies are traded or resold. Nearly all medical equipment requires the healthcare professional to log on to the device; the patient’s details are often required, and the equipment may locally store medical imagery, doctor’s notes, and potentially various touch points for protected health information. In addition, the devices usually have an internal memory slot and often hard drives built to save vital information. Any medical devices that transmit, receive, or record health information need to be HIPAA compliant. In addition, any data saved onto the instrument must do so with the patient’s consent. The required HIPAA-compliant safeguards must involve: - **Privileged Access:** Only authorized and privileged should be able to log onto the medical device. Use Multi-Factor Authentication to protect it, and no shared or automated logins. All sessions must be traceable, and users should automatically log off after a few minutes. - **Encryption**: All data saved to the medical device must be encrypted to at least AES256 encryption standards. This will protect the data if the hard drive is removed after the medical supplier has sold it. In addition, encrypt all email communications, mainly if the email contains PHI. - **Manage Patient Data:** If the medical device is being resold, it is the device owner’s responsibility to ensure that patient data is removed before being sold. If you cannot remove the data, regretfully, the device will need to be professionally destroyed, and a certificate of destruction is required. - **NPI Number:** A valid National Provider Identifier (NPI) is needed on all reseller medical devices; covered healthcare providers must use the NPIs in the administrative and financial transactions adopted under HIPAA. - **FDA Approval:** Many medical supplies offer specialist equipment containing laser products or other cutting-edge technology. A license is required to sell Class 1 equipment online that can be bought online, but any equipment above Class 3 requires FDA approval. ## Do You Need to Be HIPAA-Compliant When Collecting Insurance Information? The requirements of HIPAA compliance are much clearer when collecting insurance information because if any [protected health information](https://www.searchbug.com/info/business-industry-health-medical/) is included in the claim, then its imperative to abide by the HIPAA legislation. PHI is any information about health status, provision of health care, or payment for health care that is created or collected by a Covered Entity and can be linked to a specific individual. Protected Information includes over 18 identifiers. These include: - Name - Address - Date of Birth - Specific Dates related to healthcare including birthdate, admission date, discharge date, date of death, and exact age if over 89 - Telephone numbers - Fax number / Email address - Social Security Number - Medical record number - Health plan beneficiary number - Account numbers such as Insurance Account details - Certificate or license number - Vehicle identifiers and serial numbers, including license plate numbers - Device identifiers and serial numbers - Internet Protocol (IP) Address - Biometrics (fingerprints or optics) - Photographic image – Photographic images are not limited to pictures of the face. - Any other characteristic that could uniquely identify the individual When collecting insurance information, almost all identifiers are used. Therefore, HIPAA compliance must apply. ## How to Become HIPAA-Compliant The best way to uphold the integrity of PHI is to outsource critical IT systems to host your Medical supply business or provide the platform for collecting insurance information. HIPAA regulations are extensive and require significant investment to be achieved. Outsourcing removes the overwhelming majority of these concerns. To summarize the complexity of becoming HIPAA compliant, here are some of the mandatory and advisory requirements of HIPAA. - Network layer encryption to [NIST cryptographic standards.](https://csrc.nist.gov/Projects/cryptographic-standards-and-guidelines) - Centrally managed access controls with MFA. - Identity and authenticate all sources of PHI. - Encrypt all endpoint devices, including medical devices. - Detailed activity auditing, such as SEIM - All touchpoints must feature automated logoff - The hosting location (data center) requires controlled access measures. - All user workstations must limit access to health data. - Mobile devices must restrict access to health data. - All items must be traceable (inventory) - A risk assessment is needed to identify weak touchpoints. - Risk assessment is an ongoing process. - Train employees on all PHI access protocols. - Employees must know what can and cannot be shared. - Achieve ongoing business continuity. - Test your contingency planning. - Block unauthorized access. - Document all security incidents. - Respond promptly to patient access requests. - An NPP is required to inform patients of data-sharing policies. Atlantic.Net is an award-winning [HIPAA-compliant hosting provider](https://www.atlantic.net/hipaa-compliant-hosting/) with over 25 years of experience, providing world-class hosting solutions to leading healthcare clients. Atlantic.Net operates SSAE 18 SOC 2 and SOC2 audited and certified hosting solutions to meet the advanced IT needs of businesses. In addition, we are proud of our HIPAA-compliant hosting, HITECH, and PCI-ready options. [Contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) to find out how Atlantic.Net can help your organization meet and exceed HIPAA requirements with a managed or unmanaged hosting solution customized to meet your business’s needs. Learn more about our [HIPAA-compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. --- # How to Install Apache Web Server on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-web-server-on-fedora/ | Published: 2023-05-11 | Updated: 2023-11-16 | Author: Hitesh Jethva Free, open-source Apache is one of the most popular web server software solutions available. It is developed and maintained by the Apache Foundation. It is used by approximately 47% of websites all over the world. It’s easy to use, customizable, and designed to host dynamic websites. It is cross-platform software and can be installed on Windows, macOS, and Linux. In this guide, we will show you how to install the Apache web server on Fedora 34. ## Step 1 – Install Apache Web Server By default, the Apache package is included in the Fedora 34 default repo. You can install it with the following command. ``` dnf update -y ``` ``` dnf install httpd -y ``` After the successful installation, you can see detailed information about Apache with the following command. ``` rpm -qi httpd ``` You will get the following output. ``` Name : httpd Version : 2.4.53 Release : 1.fc34 Architecture: x86_64 Install Date: Thursday 13 April 2023 10:58:31 PM Group : Unspecified Size : 4932592 License : ASL 2.0 Signature : RSA/SHA256, Thursday 17 March 2022 01:00:49 PM, Key ID 1161ae6945719a39 Source RPM : httpd-2.4.53-1.fc34.src.rpm Build Date : Thursday 17 March 2022 12:43:53 PM Build Host : buildvm-x86-27.iad2.fedoraproject.org Packager : Fedora Project Vendor : Fedora Project URL : https://httpd.apache.org/ Bug URL : https://bugz.fedoraproject.org/httpd Summary : Apache HTTP Server Description : The Apache HTTP Server is a powerful, efficient, and extensible web server. ``` ## Step 2 – Manage Apache Service By default, the Apache service is managed by systemd. You can easily start, stop and enable the Apache service via systemctl command. To start the Apache service, run the following command. ``` systemctl start httpd ``` To enable the Apache service, run the following command. ``` systemctl enable httpd ``` To check the status of the Apache service, run the following command. ``` systemctl status httpd ``` You will get the following output. ``` ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; vendor preset: disabled) Active: active (running) since Thu 2023-04-13 22:58:51 EDT; 4s ago Docs: man:httpd.service(8) Main PID: 1539 (httpd) Status: "Started, listening on: port 80" Tasks: 177 (limit: 4666) Memory: 14.2M CPU: 99ms CGroup: /system.slice/httpd.service ├─1539 /usr/sbin/httpd -DFOREGROUND ├─1540 /usr/sbin/httpd -DFOREGROUND ├─1541 /usr/sbin/httpd -DFOREGROUND ├─1542 /usr/sbin/httpd -DFOREGROUND └─1543 /usr/sbin/httpd -DFOREGROUND Apr 13 22:58:51 fedora systemd[1]: Starting The Apache HTTP Server... ``` To stop the Apache service, run the following command. ``` systemctl stop httpd ``` ## Step 3 – Access the Apache Test Page At this point, the Apache web server is started and listening on port 80. You can verify it with the following command. ``` ss -antpl | grep :80 ``` You should see the Apache listening port in the following output. ``` LISTEN 0 511 *:80 *:* users:(("httpd",pid=1543,fd=4),("httpd",pid=1542,fd=4),("httpd",pid=1541,fd=4),("httpd",pid=1539,fd=4)) ``` Now, open your web browser and access the Apache test page using the URL **http://your-server-ip.** ![Apache test page](https://www.atlantic.net/wp-content/uploads/2023/04/p1-10.png) ## Step 4 – Create and Host a Simple Website with Apache First, create an Apache website directory using the following command. ``` mkdir /var/www/html/website ``` Next, create an index.html file: ``` nano /var/www/html/website/index.html ``` Add the following content: ```

Welcome to Apache Web Server

Success! Apache server on Fedora is working!

``` Next, set the permissions and ownership to the Apache website directory. ``` chown -R apache:apache /var/www/html/website chmod -R 755 /var/www/html/website ``` Next, create an Apache virtual host configuration file. ``` nano /etc/httpd/conf.d/web.conf ``` Add the following configuration: ``` ServerName web.example.com DocumentRoot /var/www/html/website DirectoryIndex index.html ErrorLog /var/log/httpd/example.com_error.log CustomLog /var/log/httpd/example.com_requests.log combined ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart httpd ``` ## Step 5 – Access Apache Website At this point, the Apache web server is configured to serve HTML websites. You can now access it using the URL **http://web.example.com.** You should see your website on the following screen. ![Apache virtual hosting test page](https://www.atlantic.net/wp-content/uploads/2023/04/p2-9.png) ## Conclusion In this post, we showed you how to install the Apache web server on Fedora 34. We also created a simple website and host it using an Apache web server. You can now easily use Apache to host your own website on the internet. You can try Apache on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # What Is a PCI Compliance Manager, and Does Your Organization Need One? > URL: https://www.atlantic.net/pci-compliant-hosting/what-is-a-pci-compliance-manager-and-does-your-organization-need-one/ | Published: 2023-05-12 | Updated: 2025-09-15 | Author: Gilad Maayan ## What Is PCI Compliance? [PCI compliance](https://www.atlantic.net/pci-compliant-hosting/what-is-pci-compliance/) refers to adherence to the PCI DSS—Payment Card Industry Data Security Standard—which includes several security standards devised to ensure that companies that handle payment card data keep their data environment secure. They apply to any organization that processes, transmits, or stores debit or credit card information. A group of leading credit card companies, including Visa, American Express, Mastercard, JCB International, and Discover developed the standards. To [achieve PCI compliance](https://www.exabeam.com/explainers/pci-compliance/pci-compliance-a-quick-guide/), businesses must implement a series of security measures that protect against data breaches, including maintaining a secure network, regularly monitoring and testing security systems, and restricting access to cardholders’ data. PCI compliance is essential for businesses that handle credit card transactions, as failure to comply can result in costly fines, legal action, and damage to the company’s reputation. PCI DSS standards are regulated by the PCI SSC (Payment Card Industry Security Standards Council). The council continues developing and maintaining the PCI DSS and additional security standards to help protect cardholders’ data from theft and fraud. The PCI SSC is also responsible for ensuring that all entities that handle payment card data comply with the requirements of PCI DSS. ## What Is a PCI Audit? A PCI audit aims to evaluate the company’s security measures, policies, procedures, and systems to ensure they comply with the PCI DSS. The audit is conducted by a PCI SSC-certified Qualified Security Assessor (QSA) who has been trained to assess an organization’s compliance level. The auditor typically reviews the company’s security controls to identify any vulnerabilities or weaknesses and provides recommendations for remediation. The PCI audit process usually involves several steps, including reviewing the company’s documentation, evaluating the company’s systems and processes, and submitting a final report to the PCI SSC. This is similar to a traditional [IT audit process](https://faddom.com/it-audit-processes/) but adapted to the specific requirements of PCI DSS. PCI audits are mandatory for any company that handles credit card data, including merchants, service providers, and payment processors. PCI audits help ensure that companies are properly protecting sensitive credit card data and can help prevent data breaches and associated financial losses. ## What Is a Compliance Manager? A compliance manager is a professional ensuring that a company or organization complies with relevant laws, regulations, policies, and standards. Compliance managers work across different industries and sectors, including finance, healthcare, technology, and manufacturing. A compliance manager must have strong analytical and communication skills and a thorough understanding of relevant laws and regulations. They must be able to work collaboratively with other departments and stakeholders and have the ability to develop and implement effective compliance strategies that mitigate risk and ensure organizational success. ## What Do PCI Compliance Managers Do? PCI compliance managers work with stakeholders across the organization to develop and implement policies and procedures that ensure PCI DSS compliance and help to protect credit card data from theft and fraud. A PCI compliance manager might perform some specific tasks: - Developing and implementing procedures and policies to ensure PCI DSS compliance. - Conduct regular risk assessments to identify vulnerabilities and potential areas of non-compliance. - Managing the PCI compliance program and overseeing the work of other employees involved in compliance efforts. - Monitoring compliance performance and ensuring corrective actions are taken to address any issues. - Working with external auditors to conduct PCI compliance assessments and audits. - Providing training to employees on PCI compliance issues and best practices for protecting credit card data. - Staying up-to-date on changes to the PCI DSS and ensuring that the organization complies with any new requirements. ## Who Is Qualified to Be a PCI Compliance Manager? To be qualified as a PCI compliance manager, one should possess a combination of relevant education, work experience, and professional certifications. Generally, a PCI compliance manager must have a deep understanding of the PCI DSS and the ability to apply its requirements in practice. Here are some qualifications that can help one become a PCI compliance manager: - **Education:** A bachelor’s degree in a relevant field such as computer science, information systems, or cybersecurity is typically required. Advanced degrees such as a Master’s in information systems security or cybersecurity are highly valued. - **Work experience:** Candidates for a PCI compliance manager role should have at least 5 years of experience working in a related field such as information security, risk management, or compliance. Candidates with experience in the payments industry, such as merchants, payment processors, or banks, are highly valued. - **Professional certifications:** Professional certifications such as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or PCIP (Payment Card Industry Professional) can help to demonstrate knowledge and expertise in the PCI DSS and related areas. ## Does Your Organization Need a Dedicated PCI Compliance Manager? Regardless of what your organization does, if it processes credit or debit card transactions, it is obligated to comply with the PCI standards. Having a PCI compliance manager can be extremely beneficial. Here are some reasons why your organization may need a dedicated PCI compliance manager: - **Ensuring compliance**: The PCI DSS is a complex and evolving standard, and it can be difficult to stay up-to-date on the latest requirements and changes. A PCI compliance manager can help ensure that your organization complies with the standard and can avoid penalties and other consequences of non-compliance. - **Managing risk**: Processing payment card transactions carry inherent risks, including the risk of security incidents such as data breaches. A PCI compliance manager can help identify and manage these [security compliance risks](https://www.hackerone.com/knowledge-center/security-compliance-ten-regulations-and-four-tips-success) by conducting regular risk assessments and implementing appropriate controls to mitigate potential threats. - **Protecting customer data**: Protecting customers’ sensitive payment card data is essential for maintaining their trust and confidence in your organization. A PCI compliance manager can help ensure that your organization’s payment card processing systems are secure and that customer data is properly protected. - **Streamlining processes**: Compliance with the PCI DSS can be a complex and time-consuming process involving multiple departments and stakeholders. A PCI compliance manager can help streamline the compliance process by coordinating efforts across departments and ensuring everyone is on the same page. - **Responding to incidents**: In the event of a security incident or data breach, a PCI compliance manager can [help coordinate incident response](https://www.cynet.com/incident-response/) and ensure that appropriate remediation measures are taken. ## Conclusion In conclusion, a PCI compliance manager is a professional responsible for ensuring that a company or organization complies with the PCI DSS. They develop and implement policies and procedures, conduct risk assessments, monitor compliance performance, and train employees on compliance issues. The need for a PCI compliance manager depends on several factors, such as the organization’s size, the scope of credit card transactions, and the organization’s level of PCI compliance expertise. Ultimately, organizations that handle credit card data must take PCI compliance seriously to protect themselves and their customers from the risks of data theft and fraud. --- # How to Install Nginx Web Server on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-nginx-web-server-on-fedora/ | Published: 2023-05-13 | Updated: 2023-11-17 | Author: Hitesh Jethva Nginx, also called engine-ex, is an open-source, high-performance web server used to host a website on the Internet. Nginx is also used as a reverse proxy, load-balancer, caching, and media streaming. It is lightweight, high-performance, and specially used to serve static files. It has an HTTPS capability and is designed for maximum performance and to handle the high-loaded website. In this post, we will show you how to install the Nginx web server on Fedora 34. ## Step 1 – Install Nginx Web Server By default, the Nginx package is included in the Fedora 34 default repo. You can install it with the following command. ``` dnf update -y dnf install nginx ``` Once Nginx is installed, run the following command to see detailed information about the Nginx package: ``` rpm -qi nginx ``` You will get the following output. ``` Name : nginx Epoch : 1 Version : 1.22.0 Release : 1.fc34 Architecture: x86_64 Install Date: Thursday 13 April 2023 11:08:55 PM Group : Unspecified Size : 154661 License : BSD Signature : RSA/SHA256, Wednesday 25 May 2022 08:56:23 AM, Key ID 1161ae6945719a39 Source RPM : nginx-1.22.0-1.fc34.src.rpm Build Date : Wednesday 25 May 2022 08:36:04 AM Build Host : buildhw-x86-05.iad2.fedoraproject.org Packager : Fedora Project Vendor : Fedora Project URL : https://nginx.org Bug URL : https://bugz.fedoraproject.org/nginx Summary : A high performance web server and reverse proxy server Description : Nginx is a web server and a reverse proxy server for HTTP, SMTP, POP3 and IMAP protocols, with a strong focus on high concurrency, performance and low memory usage. ``` ## Step 2 – Manage the Nginx Service Nginx service is managed by systemd in Fedora 34. You can use the systemctl command to start, stop, restart, and enable the Nginx service. To start the Nginx service, run the following command. ``` systemctl start nginx ``` To enable the Nginx service, run the following command. ``` systemctl enable nginx ``` To stop the Nginx service, run the following command. ``` systemctl stop nginx ``` To verify the Nginx status, run the following command. ``` systemctl status nginx ``` You will get the Nginx status in the following output. ``` ● nginx.service - The nginx HTTP and reverse proxy server Loaded: loaded (/usr/lib/systemd/system/nginx.service; disabled; vendor preset: disabled) Drop-In: /usr/lib/systemd/system/nginx.service.d └─php-fpm.conf Active: active (running) since Thu 2023-04-13 23:08:59 EDT; 5s ago Process: 6314 ExecStartPre=/usr/bin/rm -f /run/nginx.pid (code=exited, status=0/SUCCESS) Process: 6315 ExecStartPre=/usr/sbin/nginx -t (code=exited, status=0/SUCCESS) Process: 6316 ExecStart=/usr/sbin/nginx (code=exited, status=0/SUCCESS) Main PID: 6317 (nginx) Tasks: 3 (limit: 4666) Memory: 3.2M CPU: 95ms CGroup: /system.slice/nginx.service ├─6317 nginx: master process /usr/sbin/nginx ├─6318 nginx: worker process └─6319 nginx: worker process ``` ## Step 3 – Access the Nginx Test Page At this point, Nginx is installed and listens on port 80. You can check it with the following command. ``` ss -antpl | grep :80 ``` You will get the following output. ``` LISTEN 0 511 0.0.0.0:80 0.0.0.0:* users:(("nginx",pid=6319,fd=10),("nginx",pid=6318,fd=10),("nginx",pid=6317,fd=10)) LISTEN 0 511 [::]:80 [::]:* users:(("nginx",pid=6319,fd=11),("nginx",pid=6318,fd=11),("nginx",pid=6317,fd=11)) ``` Now, open your web browser and access the Nginx test page using the URL **http://your-server-ip.** You should see the Nginx test page on the following screen. ![Nginx test page](https://www.atlantic.net/wp-content/uploads/2023/04/p1-11.png) ## Step 4 – Create a Sample Website Next, create a website directory with the following command. ``` mkdir /var/www/html/nginxsite ``` Next, create a simple HTML file inside the website directory. ``` nano /var/www/html/nginxsite/index.html ``` Add the following configurations: ``` Welcome to Nginx!

Success! The Nginx server block is working!

``` Save and close the file, then set the ownership to the website directory. ``` chown -R nginx:nginx /var/www/html/nginxsite ``` ## Step 5 – Create an Nginx Virtual Host Next, create an Nginx virtual host to host your website on the web. ``` nano /etc/nginx/conf.d/nginxsite.conf ``` Add the following configurations: ``` server { listen 80; server_name nginx.example.com; root /var/www/html/nginxsite/; index index.html index.htm; location / { try_files $uri $uri/ =404; } } ``` Save and close the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line below the line http{: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then verify the Nginx for any syntax error. ``` nginx -t ``` You will get the following output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart Nginx to apply the changes. ``` systemctl restart nginx ``` ## Step 6 – Verify Nginx Website Now, open your web browser and access the Nginx website using the URL **http://nginx.example.com.** You should see the following screen. ![nginx virtual hosting test page](https://www.atlantic.net/wp-content/uploads/2023/05/nginx-virtual-hosting-test-page.png) ## Conclusion Congratulations! You have successfully installed the Nginx web server on Fedora 34. You can now host your own website on the internet using the Nginx web server. You can also deploy Nginx on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install a LAMP Stack on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-a-lamp-stack-on-fedora/ | Published: 2023-05-14 | Updated: 2023-11-15 | Author: Hitesh Jethva A LAMP stack is made from four open-source software components: Linux, Apache, MariaDB/MySQL, and PHP. LAMP uses Apache as a web server, Linux as an operating system, MariaDB as a database backend, and PHP as a processing language. Developers and web hosting owners use LAMP to host a website online. It is customizable, so users can replace any component with another open-source solution per their needs. This post will show you how to install a LAMP stack on Fedora 34. ## Step 1 – Install Apache Web Server Apache web server is the first and most important component of the LAMP server. You can install it using the following commands. ``` dnf update -y ``` ``` dnf install httpd -y ``` Once installed, start and enable the Apache service using the following command. ``` systemctl start httpd systemctl enable httpd ``` Next, verify the Apache status using the following command. ``` systemctl status httpd ``` You will get the following output. ``` ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; vendor preset: disabled) Active: active (running) since Thu 2023-04-13 23:01:38 EDT; 1s ago Docs: man:httpd.service(8) Main PID: 1995 (httpd) Status: "Started, listening on: port 80" Tasks: 177 (limit: 4666) Memory: 14.1M CPU: 100ms CGroup: /system.slice/httpd.service ├─1995 /usr/sbin/httpd -DFOREGROUND ├─1996 /usr/sbin/httpd -DFOREGROUND ├─1997 /usr/sbin/httpd -DFOREGROUND ├─1998 /usr/sbin/httpd -DFOREGROUND └─1999 /usr/sbin/httpd -DFOREGROUND ``` ## Step 2 – Install MariaDB Database Server MariaDB is a database server used as a database backend for any web application. You can install the MariaDB server with the following command. ``` dnf install mariadb-server -y ``` Next, start and enable the MariaDB server with the following command. ``` systemctl start mariadb systemctl enable mariadb ``` By default, the MariaDB server listens on port 3306. You can check it with the following command. ``` ss -antpl | grep 3306 ``` You will get the following output. ``` LISTEN 0 80 *:3306 *:* users:(("mariadbd",pid=4542,fd=20)) ``` Next, run the following script to secure the MariaDB installation. ``` mysql_secure_installation ``` You will be asked to provide your current password: ``` Enter current password for root (enter for none): ``` Just press the Enter key. You will be asked to change the root password. ``` OK, successfully used password, moving on... Setting the root password or using the unix_socket ensures that nobody can log into the MariaDB root user without the proper authorisation. You already have your root account protected, so you can safely answer 'n'. Switch to unix_socket authentication [Y/n] n ... skipping. You already have your root account protected, so you can safely answer 'n'. Change the root password? [Y/n] Y New password: Re-enter new password: ``` Set your new password and press the Enter key. You will be asked to remove the anonymous users: ``` Password updated successfully! Reloading privilege tables.. ... Success! By default, a MariaDB installation has an anonymous user, allowing anyone to log into MariaDB without having to have a user account created for them. This is intended only for testing, and to make the installation go a bit smoother. You should remove them before moving into a production environment. Remove anonymous users? [Y/n] Y ``` Type Y and press the Enter key. You will be asked to disallow root login remotely. ``` ... Success! Normally, root should only be allowed to connect from 'localhost'. This ensures that someone cannot guess at the root password from the network. Disallow root login remotely? [Y/n] Y ``` Type Y and press the Enter key. You will be asked to remove the test database. ``` ... Success! By default, MariaDB comes with a database named 'test' that anyone can access. This is also intended only for testing, and should be removed before moving into a production environment. Remove test database and access to it? [Y/n] Y ``` Type Y and press the Enter key. You will be asked to reload the privilege tables. ``` - Dropping test database... ... Success! - Removing privileges on test database... ... Success! Reloading the privilege tables will ensure that all changes made so far will take effect immediately. Reload privilege tables now? [Y/n] Y ``` Type Y and press the Enter key to finish the process. ``` ... Success! Cleaning up... All done! If you've completed all of the above steps, your MariaDB installation should now be secure. Thanks for using MariaDB! ``` ## Step 3 – Install PHP By default, PHP 7.4 is included in the Fedora 34 default repo. You can install PHP with other extensions using the following command. ``` dnf install php php-common php-mysqlnd php-curl php-xml php-json php-gd php-mbstring -y ``` After the successful installation, verify the PHP version with the following command. ``` php -v ``` You should see the PHP version in the following output. ``` PHP 7.4.28 (cli) (built: Feb 15 2022 13:23:10) ( NTS ) Copyright (c) The PHP Group Zend Engine v3.4.0, Copyright (c) Zend Technologies with Zend OPcache v7.4.28, Copyright (c), by Zend Technologies ``` ## Step 4 – Verify PHP Installation To verify the PHP installation, create an info.php file. ``` nano /var/www/html/info.php ``` Add the following code. ``` ``` Save and close the file, then create an Apache virtual host. ``` nano /etc/httpd/conf.d/phpinfo.conf ``` Add the following configuration: ``` ServerName phpinfo.example.com DocumentRoot /var/www/html/ DirectoryIndex info.php ErrorLog /var/log/httpd/example.com_error.log CustomLog /var/log/httpd/example.com_requests.log combined ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart httpd ``` Now, open your web browser and verify the PHP installation using the URL **http://phpinfo.example.com.** You should see your PHP information on the following screen. ![Verify PHP LAMP](https://www.atlantic.net/wp-content/uploads/2023/04/p1-12.png) ## Conclusion In this post, we explained how to install Apache, MariaDB, and PHP on Fedora 34. We also showed you how to verify the PHP version using the Apache server. You can now try to deploy the LAMP server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install a LEMP Stack on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-a-lemp-stack-on-fedora/ | Published: 2023-05-15 | Updated: 2023-11-15 | Author: Hitesh Jethva LEMP is an open-source web application stack from Linux, Nginx, MariaDB/MySQL, and PHP. LEMP represents L for Linux, E for Nginx, M for MariaDB/MySQL, and P for PHP/Perl/Python. All components are used together to host a web application on the internet. LEMP is popular due to its scalability, high performance, open-source, flexibility, and security. If you are looking for an open-source stack for website deployment, then LEMP is your best choice. This post will show you how to install a LEMP stack on Fedora 34. ## Step 1 – Install Nginx Nginx is the first component of the LEMP stack. You can install it by running the following command. ``` dnf install nginx -y ``` Once installed, start and enable the Nginx service with the following command. ``` systemctl start nginx systemctl enable nginx ``` Next, check the active status of Nginx with the following command. ``` systemctl status nginx ``` You will get the following output. ``` ● nginx.service - The nginx HTTP and reverse proxy server Loaded: loaded (/usr/lib/systemd/system/nginx.service; disabled; vendor preset: disabled) Drop-In: /usr/lib/systemd/system/nginx.service.d └─php-fpm.conf Active: active (running) since Thu 2023-04-13 23:11:45 EDT; 32s ago Process: 6342 ExecStartPre=/usr/bin/rm -f /run/nginx.pid (code=exited, status=0/SUCCESS) Process: 6343 ExecStartPre=/usr/sbin/nginx -t (code=exited, status=0/SUCCESS) Process: 6344 ExecStart=/usr/sbin/nginx (code=exited, status=0/SUCCESS) Main PID: 6345 (nginx) Tasks: 3 (limit: 4666) Memory: 3.3M CPU: 102ms CGroup: /system.slice/nginx.service ├─6345 nginx: master process /usr/sbin/nginx ├─6346 nginx: worker process └─6347 nginx: worker process ``` ## Step 2 – Install PHP and PHP-FPM You will need to install PHP, PHP-FPM, and other PHP extensions to host PHP-based applications on your Nginx server. You can install all of them with the following command. ``` dnf install php php-fpm php-common php-mysqlnd php-json php-curl -y ``` Next, exit the PHP-FPM configuration file: ``` nano /etc/php-fpm.d/www.conf ``` Replace apache with nginx as shown below: ``` user = nginx group = nginx ``` Save and close the file, then start and enable the PHP-FPM service: ``` systemctl start php-fpm systemctl enable php-fpm ``` You can also verify the PHP version with the following command. ``` php -v ``` You should see the PHP version in the following output. ``` PHP 7.4.28 (cli) (built: Feb 15 2022 13:23:10) ( NTS ) Copyright (c) The PHP Group Zend Engine v3.4.0, Copyright (c) Zend Technologies with Zend OPcache v7.4.28, Copyright (c), by Zend Technologies ``` ## Step 3 – Install MariaDB Database Server You will also need to install MariaDB server as a database backend to your server. You can install it with the following command. ``` dnf install mariadb-server -y ``` Next, start and enable the MariaDB service using the following command. ``` systemctl start mariadb systemctl enable mariadb ``` Next, secure the MariaDB installation with the following command. ``` mysql_secure_installation ``` You will be asked to provide your current password: ``` Enter current password for root (enter for none): ``` Just press the Enter key. You will be asked to change the root password. ``` OK, successfully used password, moving on... Setting the root password or using the unix_socket ensures that nobody can log into the MariaDB root user without the proper authorisation. You already have your root account protected, so you can safely answer 'n'. Switch to unix_socket authentication [Y/n] n ... skipping. You already have your root account protected, so you can safely answer 'n'. Change the root password? [Y/n] Y New password: Re-enter new password: ``` Set your new password and press the Enter key. You will be asked to remove the anonymous users: ``` Password updated successfully! Reloading privilege tables.. ... Success! By default, a MariaDB installation has an anonymous user, allowing anyone to log into MariaDB without having to have a user account created for them. This is intended only for testing, and to make the installation go a bit smoother. You should remove them before moving into a production environment. Remove anonymous users? [Y/n] Y ``` Type Y and press the Enter key. You will be asked to disallow root login remotely. ``` ... Success! Normally, root should only be allowed to connect from 'localhost'. This ensures that someone cannot guess at the root password from the network. Disallow root login remotely? [Y/n] Y ``` Type Y and press the Enter key. You will be asked to remove the test database. ``` ... Success! By default, MariaDB comes with a database named 'test' that anyone can access. This is also intended only for testing, and should be removed before moving into a production environment. Remove test database and access to it? [Y/n] Y ``` Type Y and press the Enter key. You will be asked to reload the privilege tables. ``` - Dropping test database... ... Success! - Removing privileges on test database... ... Success! Reloading the privilege tables will ensure that all changes made so far will take effect immediately. Reload privilege tables now? [Y/n] Y ``` Type Y and press the Enter key to finish the process. ``` ... Success! Cleaning up... All done! If you've completed all of the above steps, your MariaDB installation should now be secure. Thanks for using MariaDB! ``` ## Step 4 – Host a PHP Website with Nginx Next, create a simple info.php file inside the Nginx web root directory. ``` nano /var/www/html/info.php ``` Add the following code: ``` ``` Save and close the file, then create an Nginx virtual server block to define the info.php file. ``` nano /etc/nginx/conf.d/phpinfo.conf ``` Add the following configurations: ``` server { listen 80; server_name phpinfo.example.com; root /var/www/html/; index info.php; location ~ \.php$ { fastcgi_pass unix:/run/php-fpm/www.sock; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_index index.php; include fastcgi_params; } } ``` Save and close the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line below the line http{: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then verify the Nginx configuration: ``` nginx -t ``` If everything is fine, you should see the following output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 5 – Access PHP Website Page Now, open your web browser and access the PHP page using the URL **http://phpinfo.example.com.** You should see the PHP page on the following screen. ![Verify PHP LEMP](https://www.atlantic.net/wp-content/uploads/2023/04/p1-13.png) ## Conclusion In this post, you learned how to install the LEMP stack on Fedora 34. You also learned how to host a PHP-based website using the LEMP server. You can now easily host any PHP-based website with LEMP. Try to host a website with a LEMP stack on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # What Is a Cloud Managed Service Provider and What Do They Do? > URL: https://www.atlantic.net/managed-services/what-is-a-cloud-managed-service-provider-and-what-do-they-do/ | Published: 2023-05-17 | Updated: 2025-04-11 | Author: Richard Bailey Modern businesses are shifting towards cloud-based solutions for their IT infrastructure in today’s digital transformation landscape. However, while public cloud services offer numerous benefits to clients, managing them can prove to be a complex and challenging process. To address this obstacle, [cloud managed service providers](https://www.atlantic.net/managed-services/what-are-managed-services/) have emerged as expert service providers by offering various services and technical solutions designed to help businesses offload cloud infrastructure’s complex management and maintenance to a team of dedicated professionals. ## What is a Managed Cloud Services Provider? A managed cloud service provider is a third-party company offering technical services to help organizations manage their own cloud environments, resources, and IT systems. When approached by their customer, a managed services provider proposes a range of management services to support hybrid cloud environments, public cloud services, and private cloud services to their customers. They specialize in providing managed cloud services that help organizations drive their day-to-day business cloud operations well. This might include initiatives for cloud migration, cloud deployments, database management, helping with business processes, business continuity (disaster recovery), development of cloud-native applications, and data protection guarantees. Clients expect help with cloud operations, integration services, centralized services, cloud integration, cloud engineering, cloud adoption best practice, and cloud environment recommendations. These recommendations could cover enterprise networks, digital transformation, cloud apps, application services, cloud and transformation services, machine learning, managed security, ongoing management, infrastructure management, and above all else, a reliable and robust infrastructure. A managed cloud service provider delivers diverse services, including professional services, cloud migration services, cloud deployment services, business process management, business continuity management, cloud-native application management, and data protection services such as snapshots, backups, and restores. Cloud managed service providers deliver the ongoing management of cloud resources, integration services, and centralized services to help organizations manage their cloud applications. The range of managed services is extensive and intricate, with each business requiring dynamic access to meet evolving needs. ## Why Are Cloud Managed Services Important? With the increasing importance of cloud technology, the demand for Cloud MSPs is rising. The global cloud-managed services market is projected to reach a whopping $160 billion by 2027, according to a report by [MarketsandMarkets](https://www.marketsandmarkets.com/Market-Reports/cloud-managed-service-market-195317068.html). This growth is driven by the many benefits that Cloud MSPs offer, such as cost savings, improved security, and increased efficiency. All businesses have realized that the cloud is the future, and the majority already have [cloud migration projects](https://www.atlantic.net/managed-services/migration-services/) in flight. Cloud managed services are important for several reasons; some of the most important are: ### Expertise On-Hand [Managed service providers](https://www.atlantic.net/managed-services/what-is-a-managed-service-provider-a-brief-guide-to-msps/) (MSPs) have experts who understand the technical aspects of cloud computing addition; they have experience handling different cloud platforms, applications, and technologies, making them ideal for managing cloud services for organizations. Experts can help organizations select the appropriate cloud services that meet their specific requirements, such as storage, computing power, security, and compliance. MSPs experts manage the day-to-day operations of cloud services, including monitoring, maintenance, and troubleshooting. Including managing the hardware and software platforms, patching, security updates, and upgrades, ensuring customers get the most value from their cloud investments. ### Cost-Effective Solutions Cloud managed services can help organizations save money by reducing the need for in-house IT staff and infrastructure. In addition, within managed services, organizations can avoid the costs of maintaining servers, hardware, and software. Managed Service Providers (MSPs) introduce cost-effectiveness in several ways, including: #### Reduced IT staffing costs Reduce the costs associated with hiring and managing in-house IT staff. MSPs provide a team of experts who can handle all aspects of managing the cloud environment, including maintenance, security, and troubleshooting, allowing you to free up resources and focus on core business objectives. #### Financial Scalability: Public cloud providers enable organizations to scale their cloud services up or down as needed based on changes in demand or business requirements. This can help organizations avoid over or under-provisioning resources, reducing the risk of unnecessary costs. #### Predictable pricing Cloud providers offer predictable pricing models, such as monthly or annual subscriptions, which can help organizations manage their cloud adoption costs better. There is no need for upfront investments in hardware and software, which can reduce costs for organizations. #### Access to advanced technologies A managed service provider gives access to advanced cloud technologies and environments that might be too expensive or complex to implement in-house. This can help organizations stay competitive without investing significant resources into new technologies, hardware, and expensive licensing. ### Managed Security Cloud managed service providers offer advanced security features to protect organizations’ data and systems from cyber threats. Multiple physical, technical, and administrative security measures are required to ensure client data confidentiality, integrity, and availability. #### Physical Security: Physical security measures are put in place to protect the data center’s physical infrastructure from unauthorized access, theft, and damage. Tier 1 data centers are typically equipped with the following: - **Biometric access controls:** allow only authorized personnel to enter the data center. The data centers also have multiple layers of access controls, including badge readers, proximity sensors, and biometric scanners. - **Video surveillance:** Data centers must have 24/7 video surveillance which monitors all the activity inside the data center**.** - **Environmental controls:** Data centers should have sophisticated HVAC systems to ensure optimal equipment temperature and humidity levels. - **Fire suppression systems:** The data centers have advanced fire suppression systems that can detect and extinguish any fire that might occur. #### Technical Security Technical security measures are implemented to prevent unauthorized access, data breaches, and cyber-attacks. Look for technical security measures, such as: - **Network security:** The company employs firewalls, intrusion detection and prevention systems, and VPNs to protect its network from unauthorized access. - **Encryption**: Data and network encryption protect sensitive data in transit and at rest. Look for a managed service provider that uses SSL/TLS encryption for website traffic and data encryption for stored data. - **Anti-malware protection:** Good security comes from highly secure endpoints; look for managed services that offer cloud services for anti-malware protection that detect and remove malware automatically. #### Administrative Security It’s critical to know that behind the scenes, your managed service provider has the administrative security measures in place to ensure that relevant policies and procedures are followed and that their employees are trained to handle your data correctly. - **Employee background checks:** The provider’s employees should be background checked to ensure a clean record. - **Access controls:** Software access controls restrict access to sensitive data to only authorized personnel. - **Security policies:** A comprehensive set of security policies and procedures that are regularly reviewed and updated ensures that your business is safe. - **Employee training:** Cybersecurity is a serious business. Regular security training must be provided to the MSPs employees, ensuring they know the latest security threats and how to prevent them. ### Scalability Managed services allow organizations to scale their cloud resources up or down as needed easily. This means that organizations can quickly adapt to changing business needs without worrying about the technical details of adding or removing resources from the cloud. ### Reliability Cloud managed service providers ensure high uptime and reliability for to cloud services offered to their clients. They use redundancy and failover mechanisms, providing their clients’ services are always available, even during an outage or hardware failure. ## What Is Included in Cloud Managed Services? Cloud MSPs provide services encompassing cloud infrastructure management, security, and compliance management, big data analytics, backup, recovery, and round-the-clock technical support. This allows businesses to focus on their core business operations while leaving the management of their cloud infrastructure in the capable hands of experts. So, whether you’re a small business looking to move your IT infrastructure to the cloud or a large enterprise looking to optimize your already existing servers with cloud systems, a Cloud MSP can provide the support and expertise you need to succeed in today’s fast-paced digital world. ## Managed Cloud Services Organizations can delegate the management of their cloud infrastructure to third-party providers, who offer a comprehensive set of services collectively known as managed cloud services. These services include the management of enterprise networking, server hosting, server management, backup, security, and consulting agreements, among others. Below are some of the critical services provided by managed cloud services: ### Managed Enterprise Networking Third-party providers offering managed enterprise networking services can help organizations guarantee their network infrastructure’s security, reliability, and performance optimization. These services often include routing, switching, firewalling, load balancing, and virtual private networking (VPN). ### Intrusion Protection Systems Intrusion protection systems are designed to detect and prevent unauthorized access to an organization’s network. Managed cloud service providers offer intrusion protection systems as part of their security services. An IPS is a security tool designed to monitor and prevent unauthorized access to a network or system; it analyzes network traffic, identifies potential security threats, and takes action to prevent them. ### Multi-Factor Authentication (MFA) Multi-Factor Authentication (MFA) is becoming increasingly popular as a security mechanism for protecting online accounts from unauthorized access. MFA requires users to provide two or more forms of authentication before they can access their accounts. This is typically accomplished by requiring *something the user knows*, such as a password or PIN, *something the user has*, such as a smart card or security token, or *something the user is*, such as a fingerprint or facial recognition. By requiring multiple forms of authentication, MFA makes it much more difficult for hackers to gain unauthorized access to an account, even if they have obtained the user’s password through a data breach or other means. Managed cloud services can provide MFA solutions to improve the security of an organization’s cloud environment. MFA can be implemented for all users or those with access to sensitive data or critical systems. MFA can be used with other security measures, such as firewalls, intrusion detection and prevention systems, and data encryption, to provide a layered approach to security that makes it more difficult for attackers to breach the system. ### Managed Server Hosting Managed server hosting services allow organizations to host their applications and data on servers managed by third-party providers. This includes services like server deployment, configuration, monitoring, and maintenance. ### Network Edge Protection/DDoS Network edge protection services help organizations defend against Distributed Denial of Service (DDoS) attacks by monitoring incoming traffic and blocking suspicious requests. Network Edge Protection services are a powerful tool for defending against DDoS attacks. By monitoring incoming traffic and blocking suspicious requests, these services can help to reduce the impact of attacks and improve the overall security posture of an organization’s network. If your organization is at risk of DDoS attacks, it may be worth considering a Network Edge Protection service as part of your cybersecurity strategy. ### Trend Micro Security Trend Micro is a leading provider of cloud security solutions, including endpoint protection, network security, and cloud security. In addition, managed cloud services can provide Trend Micro security solutions to enhance the security of an organization’s cloud environment. Trend Micro also offers a range of network security solutions, including firewalls, intrusion prevention systems, and advanced threat detection and response tools. These solutions help organizations protect their networks from cyber attacks, including DDoS attacks, malware infections, and other threats. In addition to endpoint and network security, Trend Micro offers cloud security solutions designed to help organizations protect their cloud-based systems and applications. This includes cloud workload protection, container security, and cloud security posture management tools. By providing comprehensive security solutions specifically designed for the cloud, Trend Micro can help organizations take full advantage of the benefits of cloud computing while minimizing the risk of security incidents. ### Managed Private Cloud Managed private cloud services provide organizations with dedicated cloud infrastructure third-party provider managers. This includes services like server deployment, configuration, monitoring, and maintenance. Unlike public cloud services, a private cloud is a dedicated environment designed to meet an organization’s unique needs. Managed private cloud services offer a range of benefits for organizations, including enhanced security, reliability, and flexibility. With a private cloud, organizations can quickly scale their resources up or down as needed, allowing them to respond to changing business needs without costly hardware purchases or upgrades. This full cloud transformation can help organizations to improve their agility and adaptability, enabling them to stay competitive in a rapidly-evolving business landscape. ### Server Management Server management services help organizations ensure that their servers run efficiently, securely, and reliably. This includes services like server patching, backup and recovery, and performance monitoring. Server management services ensure an organization’s servers run efficiently, securely, and reliably. These services include server patching, backup and recovery, and performance monitoring. They are critical to minimizing downtime, optimizing performance, and ensuring the security of an organization’s data and systems. Organizations can benefit from expert support and guidance by outsourcing server management to a third-party provider while focusing their resources on more strategic initiatives. ### Consulting Agreements Managed cloud service providers can offer consulting services to help organizations plan, design, and implement their cloud infrastructure. This includes services like cloud readiness assessments, migration planning, and architecture design. ### Managed Backup Managed services often include a managed backup service like Veeam Backup, a popular backup and recovery solution for virtualized environments. Managed cloud services can provide Veeam backup solutions to ensure an organization’s data is backed up and recoverable during a disaster. Organizations can leverage their expertise and resources to improve their cloud environment’s performance, security, and reliability by partnering with a managed cloud service provider. ## How Do I Choose a Cloud Managed Service Provider? Atlantic.Net is the top choice when choosing the best-managed cloud services provider. The company has over 28 years of experience within the cloud industry, providing secure and reliable cloud solutions to clients worldwide. In addition, our expertise in cloud hosting, virtualization, disaster recovery, and compliance management sets it apart from other managed cloud service providers. ### Range of Services Atlantic.Net offers a comprehensive range of cloud services to meet the unique needs of businesses across various industries. The company’s managed cloud services include server management, monitoring, security, backup, and disaster recovery. Additionally, Atlantic.Net provides private and public cloud, hybrid cloud, and cloud migration services to help businesses modernize their IT infrastructure. ### Reputation and Customer Satisfaction Rating Atlantic.Net has a proven track record of delivering exceptional cloud solutions to its clients, with a 100% uptime SLA. The company has received [numerous industry awards](https://www.atlantic.net/hosting-services-provider/award-winning-service/) and accolades for its cloud services, including the 2020 Cloud Hosting Service Provider of the Year Award by Acquisition International. ### Pricing Structure Atlantic.Net offers flexible pricing models to suit different business needs, including pay-as-you-go and fixed-fee pricing. The company’s pricing is transparent, with no hidden costs or setup fees. This makes it easier for businesses to plan and budget their cloud computing expenses. ## Level of Support Atlantic.Net provides 24/7 customer support to its clients, with a dedicated team of cloud experts available to address any issues or concerns. In addition, the company offers proactive monitoring and management of its clients’ enterprise-grade cloud technologies, ensuring optimal performance and security. This level of support ensures that businesses can focus on their core operations while our professional services teams manage the complexities of the hyper-scale cloud environment. Atlantic.Net is committed to delivering exceptional reliability and performance to our clients as a cloud managed service provider. Our 100% uptime SLA sets us apart from competitors like Google Cloud Platform, Oracle Cloud, Alibaba Cloud, Tata Consultancy Services, AWS Cloud, and Microsoft Azure. ## Atlantic.Net: The Managed Cloud Service Provider Looking for a cloud managed service provider to help you optimize your cloud resources, secure your cloud infrastructure, and meet your business objectives? Look no further than our team of experienced professionals! As a leading provider of managed cloud services, we offer various infrastructure management services, including managed services, cloud security, and data protection. Atlantic.Net is a leading managed cloud service provider that offers a range of cloud solutions to help organizations optimize their IT infrastructure, enhance security, and improve business performance. With a strong focus on customer service and satisfaction, Atlantic.Net offers various services, including managed private cloud, intrusion protection systems, network edge protection, server management, and multi-factor authentication solutions. With a team of experienced IT professionals and a commitment to innovation and excellence, Atlantic.Net is dedicated to helping organizations leverage the power of [cloud technology](https://www.cloudzero.com/blog/what-is-the-cloud) to drive business success. Whether an organization wants to migrate to the cloud, enhance security, or optimize server performance, Atlantic.Net has the expertise in IT services and solutions to meet its needs. In today’s fast-paced and ever-evolving business landscape, having a reliable and secure IT infrastructure is essential to success. By [partnering with Atlantic.Net](https://www.atlantic.net/about-us/corporate-contact/), organizations can benefit from expert support, guidance, and customized solutions, tailored to their specific needs, helping them stay ahead of the competition and achieve their business objectives. --- # What Is a Managed Services Agreement (MSA)? > URL: https://www.atlantic.net/managed-services/what-is-a-managed-services-agreement-msa/ | Published: 2023-05-25 | Updated: 2025-04-11 | Author: Richard Bailey Managed Services Agreements (MSA) are legal contracts between a managed services provider (MSP) and their client outlining the technical requirements and responsibilities necessary to ensure that experts manage and monitor their IT systems regularly. As modern businesses increasingly rely on technology to streamline their operations, efficient and dependable IT support has become increasingly vital. This article will provide an in-depth overview of Managed Services Agreements, including their key features, benefits, and how to craft a bespoke managed service agreement that perfectly fits your business needs. ## Why Your Business Needs a Managed Services Agreement Given that every business has unique IT requirements, it is crucial to develop tailored Managed Services Agreements that cater to your specific needs. Below, we’ve outlined the most typical features of MSAs and the factors to consider when drafting a customized agreement. ### Managed Services Provider Term of Agreement The term of the agreement is a crucial aspect of a Managed Services Agreement. The term refers to the duration of the agreement, which can range from a few months to several years, depending on the agreement’s nature. The term of the agreement is an essential component of consideration because it determines the level of commitment between the Managed Service Provider (MSP) and the client. MSPs typically offer a discounted rate for longer agreement terms. Consider your IT system requirements over the next 12 – 36 months and try to determine where you want to be as a business during that time. A reputable provider will work with you to determine the most suitable terms. ### Managed Services Contract Service Level Agreement (SLA) A critical component of the MSC is the SLA, or [service level agreement](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/), which sets the minimum standards for delivering IT solutions. The SLA typically includes provisions for minimum response time, escalation procedures, and problem-resolution processes. The payment structure, including monthly fees and any additional consultation, is also outlined in the contract. An IT support and maintenance model clearly explains the configuration covered, costs, and potential risks associated with delivering support. By including a liability protection clause, the service provider limits their responsibility for any breach of contract beyond reasonable control, ensuring customer satisfaction while protecting both parties from unforeseen circumstances and additional costs that may affect service delivery. This contractual language safeguards against any potential issues and helps establish a mutually beneficial relationship between the service provider and the customer. The SLA in a Managed Services Contract should include a termination provision, allowing either party to terminate the service agreement with a minimum number of days’ written notice, if there is a breach. The effective date of the contract and the due date for payment should also be specified. The force majeure clause in an MSP contract should outline any events that may prevent the service provider from delivering services and absolve them of any liability in such circumstances. The MSP should also include provisions for client information protection and business practices that comply with applicable laws and regulations. The contract should specify the minimum amount of software code, substitute equipment, and lost data required to render services. Escalation procedures and problem-resolution processes should be in place to ensure timely and effective service delivery. ### What Managed Services Agreements Do for Clients and Companies A Managed Services Agreement (MSA) is essential for businesses looking to streamline IT operations, reduce costs, and improve efficiency. Here are some ways in which an MSA can benefit your business: #### **Enhanced Cost Savings:** A well-crafted MSA can save businesses by improving productivity, reducing downtime, and preventing costly IT failures. MSPs will make reasonable efforts to identify areas of inefficiency in the client’s IT infrastructure and implement cost-effective solutions that improve operations. #### **Proactive IT Support:** A managed service agreement can provide proactive IT support by regularly monitoring and maintaining your IT systems and identifying and addressing issues before they become significant problems. This can help your business avoid costly downtime and improve overall system performance. #### **Access to Expertise:** A [managed services](https://www.atlantic.net/managed-services/what-are-managed-services/) contract provides businesses access to skilled IT professionals who can provide guidance and support on IT-related matters. These professionals offer valuable insights and knowledge about the latest IT trends and technologies, which can help businesses stay ahead of the competition. #### **Scalability and Flexibility:** These are crucial features that allow businesses to scale their IT resources up or down as needed. This can be particularly beneficial for businesses with fluctuating IT needs, such as seasonal businesses. #### **Improved Security:** Contracted services ensure your IT systems are secure, protecting them from cyber-attacks and data breaches. With the increasing threat of cybercrime, ensuring the security of your IT infrastructure has quickly become the number one critical concern for businesses of all sizes. ## What Does a Managed Services Agreement Usually Contain? A Managed Services Agreement (MSA) is a legally binding contract that outlines the vital aspects of the business relationship between a Managed Service Provider (MSP) and their client. It establishes a clear understanding of each party’s roles, responsibilities, and expectations. To ensure a mutually beneficial and transparent partnership, it is crucial to incorporate several critical clauses within the MSA. ### Scope of Services: Defining the specific services rendered by the MSP to the client is pivotal. It encompasses details such as the types of devices or systems covered under the agreement, the designated service hours, and the expected response time for resolving any issues that may arise. This clause can outline the software and hardware that the MSP will utilize, as well as any supplementary services that may be available. By formulating a comprehensive scope of services, potential misunderstandings or disputes can be minimized. ### Service Level Agreement (SLA): The SLA is a vital component of the MSA as it establishes the performance metrics the MSP commits to delivering. These metrics typically include uptime, response time, and issue resolution time. By clearly defining the agreed-upon service levels, both parties can have a shared understanding of the expected quality of service. Moreover, the SLA should also outline the consequences or remedies that will be implemented if the MSP fails to meet the established service levels. ### Payment Terms: The payment clause within the MSA should provide detailed information regarding the financial aspects of the agreement. It should specify the total cost of the services rendered, including any additional fees or charges applicable during the agreement term. The payment terms should clearly outline the payment schedule, including the frequency and basis of payments (e.g., monthly). Additionally, this clause may address any late payment fees or penalties to ensure both parties know the financial obligations of the services provided. ### Confidentiality and Security: As data protection and privacy are of utmost importance, the MSA should include a section that addresses confidentiality and security. This clause should highlight the measures the MSP will undertake to protect the client’s sensitive data and ensure its confidentiality. It may encompass elements such as encryption protocols, access controls, and [data backup](https://www.atlantic.net/cloud-platform/backups/) procedures. Furthermore, the clause should also outline the client’s responsibilities in safeguarding any confidential information from the MSP. ### Intellectual Property Rights: In the managed services model context, intellectual property may be created or utilized. Therefore, it is essential to include a clause outlining the ownership and rights associated with any intellectual property developed during the agreement. This clause clarifies the respective rights of the MSP and the client and ensures that intellectual property matters are properly addressed. ### Liability Clause: The liability clause establishes the responsibilities and obligations of both the MSP and the client regarding any damages or losses that may occur during the provision of services. It should outline the circumstances under which each party may be held liable and the extent of their liability. Additionally, the clause should address indemnification obligations and include any exclusions or limitations of liability the parties have agreed upon. ### Termination and Exit: This agreement section outlines the conditions under which either party can terminate the contract before its designated end date. It should include the notice period required for termination, the specific reasons for termination, and any associated fees or penalties that may apply. ### Clear Understanding: The MSA should ensure a clear understanding between the MSP and the client by providing concise and unambiguous terms. This ensures that both parties comprehend their obligations, expectations, and rights as outlined in the document. ### Duly Authorized Representatives: Throughout the MSA, it is important to specify that all actions and agreements undertaken by the parties are executed by their authorized delegates, ensuring that the individuals signing the agreement have the required authority. ### Valid Exemption Certificate: If relevant, the MSA can include a provision stating that the client must provide a valid exemption certificate for any applicable taxes or fees, relieving the MSP from any responsibility or liability regarding such taxes or fees. ### Unauthorized Use: The agreement should address the unauthorized use of the MSP’s services or materials, outlining the consequences and potential liabilities for such breaches. ### Other Costs and Lost Profits: The MSA should clarify any other costs or lost profits that may arise from the provision of services, ensuring that both parties are aware of their potential financial implications. ### Ensure Profitability: The MSA may include provisions or clauses that aim to ensure the profitability of both the MSP and the client. This could involve mutual cooperation, performance milestones, or other mechanisms to support achieving financial goals. ## Cost of Managed IT Services The cost of IT Service Management can vary depending on several factors, with cost considerations such as the scope of services, the duration of the agreement, and the MSP’s expertise. Additionally, the cost of Proactive IT Management can vary by geographic location and business size. Typically, MSPs charge a monthly fee that covers all IT services provided, ranging from a few hundred dollars to several thousand dollars depending on the complexity of the IT infrastructure and required services. Some MSPs may also charge additional fees for specific services or projects. ## Service Outside Normal Working Hours Most MSPs provide IT support during normal working and regular business hours, typically 8 am to 5 pm, Monday to Friday. However, some [managed service providers](https://www.atlantic.net/managed-services/what-is-a-managed-service-provider-a-brief-guide-to-msps/) can offer 24/7 support as part of managed services contract for an additional fee. Businesses with service calls should consider their IT needs and determine whether they require round-the-clock support. The service provider should clarify the process for raising after-hours support and the associated fees within the service agreement. ## Service Provider Potential Contract Issues When drafting a managed services contract, include clear language outlining the services covered by the entire agreement and the payment structure. The managed services contract should also include a termination clause and an unforeseeable circumstances clause that outlines the actions to be taken in case of unforeseen circumstances that prevent the MSP from delivering services. The managed services contract should also include liability protection and valid exemption certificates to protect both parties. It is also essential to clarify the responsibilities of both parties, including the client’s obligation to provide necessary client information and the MSP’s obligation to render services to the problem client in a timely manner and efficient manner. The contract should also include a hierarchy of escalation and a minimum response time to resolve issues promptly. In case of early termination, the contract should outline the consequences of such failure for both parties and include language that holds one party or both parties liable for any breach of the contract. ## How Does A MSA Differ From A Statement of Work? A Managed Services Agreement is a comprehensive agreement that outlines all aspects of the MSP’s services, including the scope of services, the payment schedule, terms, and SLA. In contrast, the scope of work (SOW) or statement of work (SOW) outlines a specific project or task that the MSP will complete. While an MSA provides ongoing IT support, an SOW or SOW is a one-off project that the MSP will complete. ## Atlantic.Net Managed Services Are you tired of managing your IT infrastructure alone? Are you tired of impossible contract language? Then look no further than Atlantic.Net’s Managed Services Agreement. With Atlantic.Net as your IT Managed Solutions provider, you can trust that your IT environment is in expert hands. Our team of experienced professionals will manage everything from monitoring and managing your servers to keeping your data secure and ensuring maximum uptime. Choosing Atlantic.Net as your Outsourced IT Services provider means you’ll have access to our state-of-the-art data centers, advanced security solutions, and cutting-edge technology. We provide 24/7/365 support to resolve any issues quickly and efficiently. By partnering with Atlantic.Net, you can focus on your business goals and leave the IT management to the experts. Don’t let IT issues hold you or your clients back; choose Atlantic.Net as your MSP today. --- # Supply Chain Risk Management: Operational and Compliance Aspects > URL: https://www.atlantic.net/vps-hosting/supply-chain-risk-management-operational-and-compliance-aspects/ | Published: 2023-05-26 | Updated: 2025-09-15 | Author: Gilad Maayan ## Understanding Supply Chain Risk Management (SCRM) Supply Chain Risk Management (SCRM) is a methodical process for recognizing, evaluating, and alleviating risks within a supply chain. SCRM aims to reduce disruptions and maintain business continuity by addressing potential vulnerabilities across the entire supply chain lifecycle, from procuring raw materials to delivering finished goods or services. Key elements of SCRM include: - **Risk identification:** Recognizing potential risks that may impact the supply chain through techniques like risk assessments, audits, and supplier evaluations. - **Risk assessment:** Estimating the likelihood and severity of identified risks, considering factors such as probability, operational impact, financial consequences, and potential damage to reputation. - **Risk mitigation:** Creating strategies to lessen or eliminate identified risks by implementing actions like supplier diversification, quality control processes, improved information sharing among supply chain stakeholders, or investing in advanced technologies for real-time data visibility. - **Risk monitoring and reporting:** Constantly tracking risk levels within the supply chain using tools like Key Performance Indicators (KPIs), dashboards, or scorecards, and routinely reporting findings to relevant stakeholders, including senior management. ## The Significance of SCRM Supply chain risks have multiple causes, including natural disasters, geopolitical events, cyber-attacks, or pandemics like COVID-19. These disruptions can lead to production or delivery delays, resulting in financial losses for businesses: - **Financial losses:** When an organization faces supply chain disruption for any of the reasons as mentioned earlier, it incurs financial losses in the form of inventory costs and revenue loss from delayed deliveries or canceled orders. - **Damaged reputation:** A company’s reputation may suffer if it fails to deliver products or services on time due to supply chain issues. This failure can lead customers to seek alternatives elsewhere, negatively impacting sales. - **Lack of flexibility:** Organizations without adequate contingency plans cannot react quickly when confronted with unforeseen situations, such as supplier bankruptcy or sudden demand spikes, resulting in further delays in delivery times. ## Supply Chain Risk Management: Operational and Compliance Aspects SCRM involves identifying, assessing, and mitigating risks associated with the procurement, production, and distribution of goods and services. It includes operational and compliance aspects, essential for a comprehensive approach to minimizing vulnerabilities. **Operational aspects include:** - **Supplier risk assessment:** Evaluate suppliers based on their financial stability, quality of goods and services, delivery performance, and overall reliability. This helps to identify potential issues early and establish contingency plans. Furthermore, [optimizing delivery operations](https://getcircuit.com/teams/blog/efficient-delivery) through strategic supplier partnerships can enhance efficiency and mitigate potential risks in the supply chain. - **Inventory management:** Implement inventory control measures to reduce the likelihood of stockouts, overstocking, or obsolescence. This includes using just-in-time (JIT) inventory systems, safety stock management, and demand forecasting. - **Automated software testing:** For software-based products, [use CI/CD pipelines](https://codefresh.io/learn/ci-cd-pipelines/) to automate the testing process, including unit tests, integration tests, and performance tests to ensure that potential bugs or vulnerabilities are detected and addressed early in the development process. [Automate software deployment](https://codefresh.io/learn/software-deployment/) to ensure high reliability and repeatability. - **Business continuity planning:** Develop plans to address potential disruptions, such as natural disasters, geopolitical events, or supplier bankruptcies. This involves identifying critical processes, creating backup plans, and conducting regular simulations to ensure preparedness. - **Transportation and logistics:** Optimize transportation routes and modes, and maintain visibility into the shipping process to minimize delays and disruptions. Establish relationships with multiple carriers and consider using a transportation management system (TMS) to streamline logistics. - **Information sharing and collaboration:** Foster collaboration among supply chain partners to enable real-time visibility into operations, improve communication, and facilitate joint risk management initiatives. **Compliance aspects:** - **Regulatory compliance:** Ensure compliance with applicable local, national, and international regulations, such as import/export controls, customs requirements, and environmental regulations. This can help avoid fines, penalties, and disruptions to operations. - **Ethical sourcing and labor practices:** Implement policies to ensure responsible sourcing and adherence to labor standards, such as fair wages, working conditions, and human rights. This can protect brand reputation and minimize the risk of boycotts or negative publicity. - **Data security and privacy:** Establish robust data protection measures to prevent unauthorized access, data breaches, and potential legal liabilities, both in the physical and [software supply chain](https://www.mend.io/resources/blog/software-supply-chain-attacks/). This includes adhering to relevant data protection regulations like GDPR or CCPA. - **Quality management:** Implement quality management systems (QMS) to ensure the quality of goods and services and compliance with relevant industry standards, such as ISO 9001. This helps to maintain customer satisfaction and prevent product recalls or legal issues. - **Corporate social responsibility (CSR):** Integrate CSR principles into the supply chain management strategy, including environmental sustainability, community engagement, and ethical business practices. This can enhance brand reputation, customer loyalty, and long-term success. Effective supply chain risk management requires a holistic approach addressing operational and compliance aspects. Organizations that implement robust strategies and processes can minimize disruptions, maintain operational efficiency, and protect their brand reputation. ## Conclusion Supply chain risk management is an essential component of an organization’s operations, encompassing identifying potential risks and applying strategies to mitigate them, ensuring a seamless supply chain. To enhance efficiency and reduce disruptions, consider adopting the best practices mentioned in this article to develop a robust supply chain risk management strategy. Doing so can minimize interruptions and guarantee that your business maintains smooth operations even during challenging circumstances. ## **Make Atlantic.Net Part Of Your Cloud Strategy** Atlantic.Net provides world-class [VPS hosting](https://www.atlantic.net/vps-hosting/) services and compliant hosting solutions. Contact us today, and let us help you achieve operational and compliance excellence. --- # What Are IT Managed Services? > URL: https://www.atlantic.net/managed-services/what-are-it-managed-services/ | Published: 2023-05-27 | Updated: 2025-09-15 | Author: Richard Bailey Managed services are IT solutions a third-party organization delivers to a customer, ranging from network and system monitoring to security management, data backup, and disaster recovery. In today’s digital age, businesses rely on technology more than ever. From managing customer data to facilitating seamless communication and collaboration, technology plays a vital role in the success of modern organizations. However, managing IT services has become increasingly complex and time-consuming as technology evolves. Previously, companies often developed an in-house IT team to handle all technology needs. But with the rapid pace of cloud computing and technological advancements, plus the associated costs, this approach is no longer practical or cost-effective for many businesses. Fortunately, [managed IT services](https://www.atlantic.net/managed-services/what-are-managed-services/) offer an answer to these challenges. ## Managed Services Providers With a [managed service provider](https://www.atlantic.net/managed-services/what-is-a-managed-service-provider-a-brief-guide-to-msps/) (MSP), businesses can offload the administrative headache of managing their IT infrastructure to experts in the field. This allows them to focus on their core business operations and helps to guarantee their own IT service providers’ needs are offloaded to experienced professionals. In this post, we will explore the benefits of client costs when using managed IT services and the various available services. We will also discuss the factors businesses must consider when choosing an MSP to ensure they find the right partner to meet their unique needs. Whether you’re a small business owner looking to offload your IT responsibilities or a larger organization needing comprehensive IT support, managed IT services can provide the solutions you need to stay competitive in today’s digital workplace. ### Types of Managed IT Services Managed IT services come in many different flavors. Here are some of the most common types of managed services: #### Managed Networking Managed network services are outsourced IT services that involve remote monitoring, managing, and maintaining a company network infrastructure. This typically includes installing, configuring, and maintaining network hardware and software components such as routers, switches, firewalls, servers, and storage devices. By using managed network services, companies can leverage the expertise and resources of a third-party service provider to ensure their network is operating efficiently and securely. This, under vendor management, can help reduce costs, increase network performance, help guarantee the availability of network connections and improve overall productivity. Managed IT services can also include proactive maintenance and support to prevent network issues from occurring, reducing downtime and minimizing the impact of any issues that do occur. Overall, managed network services can be an effective way for companies to improve their network infrastructure while focusing on their core business objectives. #### Server Monitoring Your server infrastructure is the lifeblood of your business, be it virtual private servers, dedicated servers, or even physical tin. Network and system monitoring involves scrutinizing your company’s IT infrastructure to detect and troubleshoot issues before they become significant problems. Standard monitoring metrics include server performance (CPU, Disk, and Memory), network traffic and availability, SNMP traps, infrastructure alerts, and automating security threats. For example, if a server goes down, your MSP will be alerted immediately and can work to resolve the issue before it even impacts your business; when your managed IT company is contracted to monitor systems proactively, they often resolve the problem before you even knew you had one. Persistent issues may require hardware maintenance; your MSP can arrange for an engineer to resolve more complicated issues within a service-level agreement. #### Managed Security platform Security management protects your company’s sensitive information from various cybersecurity threats. This includes firewall management, antivirus and antispyware protection, and intrusion detection. With cyber-attacks on your private networks rising, having a dedicated team of IT professionals to manage your cyber security is becoming increasingly important. #### Data Backup and Disaster Recovery Data backup and disaster recovery involve creating backups of your company’s critical data and planning to recover that data quickly in the event of a disaster. Businesses should follow the 3-2-1 rule of backups which involves creating three copies of your data, storing them on two different types of media, and keeping one copy offsite. Whether a natural disaster like a hurricane or a cyber attack such as ransomware, having a solid disaster recovery plan in place can mean the difference between quickly getting back to business as usual and being out of commission for days or weeks. ## The Managed Service Provider Strategic Advantage: Why Your Business Should Consider IT Managed Services Now that we have a grasp on the different types of managed IT services let’s explore the benefits of utilizing managed IT services: #### Reduced IT Spending Outsourcing your IT systems to managed services providers can lead to significant cost savings in the real world. By entrusting your technology needs to a team of experts, you can reduce the time and resources required to manage your IT infrastructure in-house. Here are some of the specific ways that outsourcing to a managed services provider can save you money: #### **Reduced Labor Costs:** By outsourcing your IT systems to a managed services provider, you can avoid the need to hire and train a full-time IT staff. This can save your business significant money on salaries, benefits, and other overhead costs. #### **Scalable Costs:** Managed services and managed service providers typically offer a range of pricing plans based on your specific needs, allowing you to scale up or down as your business requirements change. This can help you avoid the cost of investing in additional hardware, software, or personnel that may be necessary to manage your IT infrastructure as a service only. #### **Improved Efficiency:** IT support companies can help optimize your IT systems for maximum efficiency, reducing the likelihood of downtime, errors, and other issues that can cost your business time and money. Additionally, a team of experts can often identify and resolve IT issues more quickly than an in-house team, reducing the time and cost required to resolve problems. #### **Access to Advanced Technology:** A managed cloud services provider can often provide access to advanced business technology services that may be too expensive or complex for your business to manage independently. This can help your business stay competitive by leveraging cutting-edge cloud technology without the high cost of ownership. #### **Enhanced Security:** IT outsourcing managed service providers are security experts, helping to protect your IT systems from cyber threats that can be costly to recover from. By outsourcing your IT security needs to a managed services and security provider, you can avoid the costs associated with data breaches, system downtime, and other security challenges. ### Dependable Service Managed IT services offer a valuable benefit in the form of dependable support. With a team of skilled professionals on hand 24/7, MSPs can promptly resolve any IT-related issues, keeping your operations running smoothly and minimizing disruptions. ### Leverage Expert Knowledge As we mentioned earlier, MSPs bring a high level of expertise. By outsourcing your IT needs to an MSP, you can tap into that expertise and ensure your company’s internal IT team and infrastructure runs smoothly and efficiently. ### Growth of Cyber Attacks Cyber threats are a reality that businesses cannot ignore. The risks are numerous and constantly evolving, from data breaches to ransomware attacks. As such, businesses must proactively safeguard their sensitive information and prevent potential cyber-attacks. When a business outsources its IT systems to an MSP, it can benefit from various security measures, including firewalls, intrusion detection systems, and antivirus software. MSPs continuously monitor systems to detect and respond to real-time security breaches. ### Help Achieving Compliance Managed IT services can help ensure compliance with hosting solutions that meet and exceed GDPR, PCI-DSS, ISO, Hitech, and [HIPAA regulatory requirements](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/). In addition, choosing a compliant managed service provider reduces the risk of breaching compliance which can result in financial penalties and legal action. The best-managed IT services include training and awareness programs to educate employees on best practices for compliance, cybersecurity, and legislation, minimizing human error risk and strengthening most business owners’ overall security posture. Together, these measures help prevent cyber attacks and data loss while improving the overall security of a business’s IT systems. ## Professional Services IT service providers typically have in-house teams of seasoned IT professionals available for projects and ad-hoc technical needs, such as system design upgrades or technical expertise. Whether implementing a new technology solution or upgrading an existing one, an MSP can help ensure a seamless transition and that your company’s IT infrastructure runs efficiently. ## Experience the Power of Atlantic.Net’s IT Managed Service Are you tired of dealing with unreliable IT systems that hinder your business’s growth and productivity? Look no further than Atlantic.Net’s IT-managed services provider. Our comprehensive suite of services provides organizations with the scalability, security, and reliability they need to succeed in today’s digital landscape. With Atlantic.Net, you can use various cloud hosting services, including Virtual Private Cloud (VPC), public and private cloud, and hybrid cloud solutions. Our cloud hosting services offer increased scalability, reduced costs, and enhanced uptime, allowing your business to operate efficiently. ### Unleash Your Business Potential with IT Managed Services In addition to cloud hosting, Atlantic.Net offers various managed services to protect your business’s critical data and assets. Our Managed Security Services include the following: #### firewall management Our experienced network engineers have designed a logical and robust network service to secure client data and your business. Here’s what our Managed Firewall Service includes: - **Fully managed firewall**stack connected to the Atlantic.Net network - **Redundant firewall stack** configuration upon request - **Proprietary stateful firewall**for customized solutions #### NETWORK EDGE PROTECTION Our Managed IT services include additional Edge Services to shield your environment further: - **DDoS Protection:** Automatically thwart unwanted network requests. - **Content Delivery Networks (CDN):** to reduce your website’s attack surface and speed up global content delivery. - **Web Application Firewall (WAF):** monitor and filter traffic via the network edge. - **Intrusion Prevention System (IPS):** Real-time threat monitoring and prevention #### vulnerability scanning As part of the managed cloud services offering, the service checks for vulnerabilities on the client’s network and internal IT systems: - **Expertise**: Scans are conducted by an experienced team of security professionals - **Detailed Verbose Reporting:** Reports are generated with detailed information on identified vulnerabilities - **Scalable:** The service is scalable and customizable to meet the specific needs of each client - **Identification:** The scanning service helps clients identify and address vulnerabilities before they can be exploited - **Improved Security Posture:** Regular vulnerability scanning can reduce the risk of data breaches and other security incidents - **Compliance:** vulnerability scanning service helps clients maintain compliance with industry regulations and standards. #### Migration Services Our managed migration services are the ideal solution to get you started. The three critical steps in the migration process are assessment, migration, and optimization. - **Three migration packages are available:** Standard, Advanced, and Enterprise - **Expert Migration:** handle the migration process seamlessly and disruption-free - **Cost Savings:** Increases efficiency and reduces costs - **Fast:** Gets workloads running in the Atlantic.Net cloud quickly and easily #### Managed Backup and Disaster Recovery - **Managed Backups:** Daily, weekly, or monthly backups are taken automatically and stored offsite in secure Atlantic.Net data centers to your retention requirements. - **Disaster Recovery:** Atlantic.Net provides disaster recovery services to ensure business continuity in the event of a disaster, with options for managed or self-managed solutions - **Replication:** Data is replicated in real-time to a secondary location for disaster recovery purposes - **RPO and RTO:** Recovery Point Objective (RPO) and Recovery Time Objective (RTO) can be tailored to meet specific business needs Looking for a dedicated cloud environment? Atlantic.Net’s Managed Private Cloud services offer dedicated resources, secure connectivity, and a range of management and support services to meet the unique needs of your business. We also offer these platform services: #### Managed Database Services - Offers a range of managed database services, including MySQL, PostgreSQL, MariaDB, and MongoDB - Provides highly available and scalable database solutions - Offers database administration, monitoring, backups, and disaster recovery - Optimizes database performance to ensure efficient operations #### Managed Hosting Services - Provides fully managed hosting services for websites and applications - Offers a variety of hosting solutions, including cloud hosting, VPS hosting, and dedicated hosting - Provides 24/7 monitoring, support, and management - Ensures high availability, reliability, and security for the hosted environment ## Choose Atlantic.Net IT Managed Services Atlantic.Net is a leading managed service provider offering a comprehensive selection of managed services to global businesses across various sectors. With over three decades of experience, Atlantic.Net has established itself as a dependable managed services provider that offers 24/7 technical support, remote monitoring, and remote application hosting services, among many others. We specialize in remote support from our specialist in-house teams from our Orlando-based network operations center (NOC). All managed IT services deliver comprehensive service-level agreements to ensure each client receives a dependable service. ### Say Goodbye to IT Headaches with Managed Services Our experts took remote monitoring and managed IT services further by offering various services, such as managed security services, mobile device management, backup services, mobile device management, and cloud computing solutions. Atlantic.Net managed cloud services model is built around proactively monitoring systems, allowing businesses to focus on their core operations. You can rest easy knowing that your network infrastructure and other computer infrastructure are in safe hands, and you can depend on our U.S based technical support teams whenever needed. Control your costs with our pay-as-you-go service tier, allowing businesses to pay only for the services they use. This option is attractive for small businesses that still require dependable IT support but also desire to help to avoid extensive overhead costs and the administrative headaches associated with managed services being kept in-house. As a global market leader with channel partners in various locations, we are constantly looking for new business development opportunities to expand our services and meet the needs of both IT and non-IT businesses. With Atlantic.Net, you can be confident that you receive top-of-the-line services from a dependable service provider. ### Managed Services are Essential for Business Continuity and Growth Are you tired of managing your IT infrastructure and struggling with the latest cybersecurity threats? Look no further than Atlantic.Net! As a top-tier managed service provider, we offer a comprehensive suite of managed IT and cloud services to help you streamline your operations and keep your business running smoothly. Our managed services model allows us to provide end-to-end solutions tailored to your unique needs. From cybersecurity services to network monitoring, our service offerings are designed to help you maximize your resources and minimize risk. ### Discover the Power of IT Managed Services for Your Organization We partner with the best application service providers and offer cutting-edge services tools to ensure that your IT services are always up to date. Our team of experts has the skills and experience to manage your IT infrastructure, so you can focus on growing your business. We offer utility services, internal IT, desk services, managed platform services, and more to meet your IT needs. Plus, we work with third-party organizations and SaaS platforms to ensure that you have access to the latest technology and software. When you choose Atlantic.Net as your next managed IT services company, you’ll benefit from our industry-leading service providers typically provide. In addition, we pride ourselves on our ability to deliver high-quality managed services that help businesses like yours thrive. For example, we use a managed platform to provide reliable and secure cloud services, and our agent software helps us detect and prevent social engineering attacks. Our centralized platform makes it easy to manage your IT infrastructure from one place, and our team of experts is available 24/7 to provide support whenever needed. We also offer server space on our cloud platform, so you can use the latest technology without investing in your platforms. Whether you’re a small or medium-sized business, we have the expertise to help you succeed. So why wait? [Contact us](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)today to learn more about our managed IT and cloud services, and let us help you take your business to the next level! --- # What is the Future of AI, ChatGPT, and Bard? > URL: https://www.atlantic.net/vps-hosting/what-is-the-future-of-ai-chatgpt-and-bard/ | Published: 2023-05-28 | Updated: 2024-11-09 | Author: Richard Bailey The rise of artificial intelligence (AI) is transforming the world as we know it. AI technology has revolutionized various industries, from self-driving cars to intelligent virtual assistants. In this article, we will explore the future of AI, the Generative Pretraining Transformer (better known as ChatGPT), and Bard, discussing their potential applications, integration with human creativity, and the ethical challenges they pose. ## Navigating the AI Controversy If you have been watching the news in the last six months, you will know there has been a lot of noise surrounding AI. Many countries have [banned AI tools](https://www.digitaltrends.com/computing/these-countries-chatgpt-banned/) like ChatGPT, including Italy and China, and business leaders have called for [AI development to be paused for six months](https://www.theguardian.com/technology/2023/mar/31/ai-research-pause-elon-musk-chatgpt)to be ethically reviewed and discussed in Congress. Despite all the uproar, AI tools like ChatGPT and Bard are hugely popular. As of April 2023, ChatGPT has [approximately 173 million monthly users​​](https://nerdynav.com/chatgpt-statistics/). In comparison, Google Bard, released in March 2023, has around [30 million monthly visits](https://contentdetector.ai/articles/google-bard-statistics)​. ## Advancements in AI and Machine Learning AI and machine learning have come a long way since their inception. Recently, AI has become more sophisticated and capable of performing complex tasks and has found its way into various industries, including finance, healthcare, and education. One of the most significant advancements in AI and machine learning has been the development of chat GPT. ### Impact of ChatGPT GPT-4.0 is the latest version of chat GPT from OpenAI for paid users. Free users must stick with version 3.5. However, both are extremely capable of natural language generation and understanding. In addition, GPT can generate human-like text, making it useful for content creation, writing, and translation. With GPT-4, businesses can generate content quickly and easily, freeing time for other tasks. However, it can generate biased or offensive content, and there are significant concerns about its impact on the job market. Despite these challenges, GPT-3.5 and 4.0 have significant potential in various industries, including journalism, marketing, and education. ### Bard – A New Tool for Creative Writing and Storytelling Bard is an AI-based tool for creative writing and storytelling. However, Bard lacks emotional intelligence and creativity. Therefore, writers must balance automation and human ingenuity. ## Integration of AI and Human Creativity AI has yet to be ready to replace humans; many users see it as a valuable tool to enhance creativity. However, as AI technology advances, there is a growing interest in integrating it into everyday life. Although AI can provide writers, artists, and musicians with valuable tools, it can only partially replace human creativity. Therefore, there is a need to balance automation and human ingenuity to produce the best results. Additionally, the integration of AI and human creativity raises ethical concerns surrounding the ownership of creative works generated by AI tools and how AI impacts the job market. Therefore, it is essential to consider the ethical implications of AI and human creativity integration. ## Challenges in AI Ethics and Responsibility The rise of AI has presented significant ethical challenges, and there are concerns about the misuse of AI. For example, using facial recognition technology for surveillance can perpetuate biases and discrimination. Furthermore, as the technology is still very new, there is a need to develop responsible AI practices. Here are some of the ethical concerns surrounding the future of AI: 1. **Bias in AI**: AI models are trained on large datasets, sometimes including biased data. This can lead to discriminatory outcomes, like an AI system that differentiates based on race, gender, or other factors. Avoiding bias in AI is a significant challenge that requires careful dataset curation and model testing. 2. **Transparency and explainability**: AI models, particularly deep learning models, are often called “black boxes” because it can be challenging to understand how they make decisions. However, this lack of transparency can be problematic when understanding why an AI system made a particular decision. 3. **Data privacy**: AI systems often need large amounts of data to train and operate effectively. This can raise privacy concerns, particularly when sensitive personal data is involved. Ensuring that AI systems respect privacy and comply with data protection regulations is a significant challenge. 4. **Accountability**: If an AI system makes a mistake or causes harm, it can be challenging to determine who is responsible. Is it the creators of the AI, the users, or the people who provided the data? This issue of accountability is a crucial ethical question. 5. **Fairness and equity**: Ensuring that AI systems are fair and don’t disproportionately harm or benefit specific groups of people is a critical ethical challenge. This ties in with the issue of bias but also includes questions about access to AI technology and the impacts of AI on employment and economic inequality. 6. **Autonomy**: As AI systems become more capable, there are concerns about the potential for AI to infringe on human freedom. This can be persuasive AI technologies that influence human behavior or more speculative concerns about superintelligent AI systems that act beyond human control. 7. **The moral and legal status of AI**: As AI systems become more advanced, questions arise about their moral and legal status. Should sophisticated AI systems be granted some form of legal personhood or rights? This is a contentious issue and a challenging area of AI ethics. ### **Future of AI in Education and Healthcare** Two industries that benefit substantially from AI implementation are education and healthcare. AI can personalize learning, provide feedback, and assess student progress in education. In addition, AI can be used in healthcare for disease diagnosis, treatment recommendations, and drug development. ### **Emerging Trends in AI** AI integration propels the advancement of emerging trends, with one notable focus being on intelligent robotics. These robots can undertake intricate and hazardous tasks while engaging with humans. In the realm of [customer support](https://www.atlantic.net/hosting-services-provider/support-team/), businesses leverage AI chatbots to offer round-the-clock assistance, addressing customer inquiries, resolving complaints, and aiding in troubleshooting. Furthermore, content creators benefit from AI-powered tools that automate content generation for blogs, social media, and various other platforms. Businesses are seamlessly incorporating AI models to streamline tasks like scheduling and email management. A prime example of this integration can be observed in Microsoft’s Office products, where AI technology is used to summarize your upcoming week as well as visualize previous working weeks. The influence of AI extends to the realm of video games as well, where it plays a crucial role in generating dynamic dialogues and narratives. Additionally, AI infuses non-player characters with lifelike personalities and creates procedural content, including generic landscapes and awe-inspiring vistas. ### **Conclusion** AI, ChatGPT, and Bard have significant potential to transform various industries. Therefore, it is essential to consider the ethical implications of AI and develop responsible practices. Furthermore, as AI technology advances, finding the balance between automation and human creativity is crucial to produce the best results. --- # Unleashing the Power of AI: Transforming Business Operations Today > URL: https://www.atlantic.net/vps-hosting/unleashing-the-power-of-ai-transforming-business-operations-today/ | Published: 2023-05-29 | Updated: 2026-05-30 | Author: Richard Bailey Artificial Intelligence (AI) has transitioned from being a mere buzzword to headline news as a powerful tool that’s starting to fundamentally reshape the contours of the world. Moreover, the transformative prowess of AI is no longer confined to the realms of science fiction. It is an absolute force driving efficiency and innovation in today’s business landscape—AI introduces vast and varied capabilities, from automating tedious tasks to refining intricate business processes. This article will serve as a comprehensive guide, shedding light on the diverse applications of AI in the business world. We will explore how AI automates routine tasks, enhances processes, and revolutionizes customer service. We’ll explore real-world examples of AI implementation, demonstrating its potential to drive productivity and innovation. ## AI at Work: Real-World Success Stories and Innovations Artificial Intelligence (AI) is being utilized innovatively to solve everyday business problems. Here are some real-world examples of industries thriving with AI. 1. **Manufacturing and Robotics**: AI is helping to automate tasks in the global manufacturing industry. For example, [Miso Robotics](https://misorobotics.com/flippy-2/) has developed Flippy 2, an AI-equipped robot that helps automate kitchen tasks like frying food. Similarly, iRobot has created [Roomba](https://www.irobot.co.uk/en_GB/roomba.html), an intelligent vacuum that uses AI to scan room sizes, identify obstacles, and remember the most efficient routes for cleaning your house. 2. **Intelligent Assistants**: AI is the backbone of the smart assistant, integrated into phones, cars, and home devices. Siri, Alexa, Cortana, and Bixby are household names that work by using natural language processing, machine learning, and cloud computing to respond to user requests. 3. **Healthcare Management**: Artificial Intelligence plays a significant role in healthcare by diagnosing and managing diseases, predicting patient outcomes, and analyzing medical images. For instance, [the Renal Research Institute utilizes deep learning](https://pubmed.ncbi.nlm.nih.gov/36723278/), a subset of AI, to evaluate a patient’s arterio-venous vascular access (a type of blood vessel access for dialysis) using images taken from smartphones or tablets. 4. **Financial Services**: AI powers the financial industry, especially automated investing. You may have heard of *robo-advisors*, AI routines that use algorithms to manage and optimize a person’s investment portfolio. 5. **Travel and Hospitality**: AI is already extensively used by virtual travel booking agents. Companies like Expedia and Booking.com use AI to provide personalized travel recommendations based on users’ known behaviors and preferences. 6. **Advertising and Marketing:** AI is optimizing cross-border communication in brand campaigns. For example, with [AI dubbing](https://www.veed.io/tools/voice-dubber/ai-dubbing), businesses can automate multilingual content production, ensuring consistent tone and delivery while reducing localization costs and accelerating global market entry. ## Eliminating the Mundane: AI’s Role in Automating Repetitive Tasks Using AI to automate repetitive tasks is already hugely popular, freeing time for employees to focus on creative endeavors. AI-driven software already manages data entry and [invoice processing automation](https://rossum.ai/blog/invoice-processing-automation-guide/), minimizing errors and saving time. Its ability to learn from data and improve accuracy boosts business productivity and efficiency. AI enhances robotics and automation in manufacturing by enabling machine learning algorithms to learn and adapt. This adaptability empowers robots to handle complex tasks and make informed decisions, revolutionizing manufacturing. AI is also transforming customer service. For example, AI-powered chatbots are increasingly prevalent, providing round-the-clock support and efficiently handling basic inquiries on websites and social media platforms. This automation enables businesses to offer faster and more efficient customer service 24/7. ## Revitalizing Customer Engagement: The Emergence of AI Chatbots Chatbots are revolutionizing not only customer service but also making a significant impact on marketing and sales. AI can actively guide customers toward products of interest and provide personalized recommendations. Moreover, chatbots actively gather valuable customer feedback and data, contributing to improving products and services. AI drives Natural Language Processing (NLP) advancements, empowering computers to understand and interpret human language. NLP enables businesses to analyze customer feedback, social media posts, and reviews, extracting insights into customer behavior and preferences. ## Amplify Sales and Marketing with Predictive Analytics Predictive analytics uses data, statistical algorithms, and machine learning to predict future outcomes based on historical data. For example, predictive analytics can identify potential customers, forecast sales, and optimize marketing campaigns in sales and marketing. This powerful tool enables businesses to make data-driven decisions, increasing their likelihood of success. The retail industry is heavily influenced by customer behavior. For the leading online retailers, AI is driving sales, creating reliable predictive habits to push other sales while building an accurate data profile of their customers. ## Smarter Supply Chains Supply chain management is a complex process with many moving parts. AI-powered solutions can streamline this process, optimizing inventory management by predicting demand and adjusting stock levels accordingly. AI can also identify bottlenecks in the supply chain and suggest solutions, ensuring smooth operations. ## Reimagining HR: Streamlining Processes with Innovative AI-based Tools HR is vital to any business operation, but it can be resource-intensive. AI-based tools can streamline HR processes, assisting with resume screening and onboarding tasks and any bulk tasks such as updating all employee tax codes. AI can also help businesses identify potential issues before they escalate, such as high-risk employees considering leaving the company. For instance, IBM’s AI tool, [Watson](https://www.ibm.com/products/watson-orchestrate/human-resources), can analyze employees’ feedback and sentiments, helping identify high-risk staff, reducing the burden on HR teams, and making the HR processes more efficient and effective. ## Enhancing Cybersecurity through Machine Learning With the rise in cyber-attacks, cybersecurity is a growing concern for businesses. AI-powered solutions can help companies to protect their networks and data. For example, machine learning algorithms can analyze network traffic and identify potential threats, keeping businesses ahead of cybercriminals. Machine learning can predict future attack patterns based on past data, allowing businesses to proactively defend themselves against cyber threats. ## Leveraging AI for Financial Foresight Financial planning and analysis are crucial but can be complex and time-consuming. AI-powered solutions can streamline these processes, providing deeper insights into economic trends and enabling more accurate forecasting. AI can also identify potential risks and opportunities, equipping businesses with the information they need to make informed decisions. ## Utilizing Natural Language Processing to Enhance Business Communication Natural Language Processing (NLP) is revolutionizing customer interactions and business operations. For example, NLP can extract insights from unstructured data like emails or customer feedback, assist with compliance by analyzing legal documents, and identify potential risks. NLP also impacts research and development, helping businesses identify breakthroughs and patent opportunities. AI is reshaping business operations across industries, offering increased efficiency, insights, and cost savings. By leveraging AI-powered solutions, businesses can unlock their full potential and achieve unprecedented success. Revolutionize your business with [Atlantic.Net’s AI-ready cloud platform](https://www.atlantic.net/cloud-platform/)! Seamlessly integrate, scale, and secure your AI applications. Experience high performance and expert support. [Embrace the future of AI today.](https://www.atlantic.net/about-us/corporate-contact/) --- # How to Install phpMyAdmin on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-phpmyadmin-on-fedora/ | Published: 2023-05-30 | Updated: 2023-11-15 | Author: Hitesh Jethva phpMyAdmin is an open-source tool used to manage databases via the web interface. It is written in PHP and was built to handle the administration of MySQL over the Internet. Creating and managing a database manually is very difficult for any beginner user. In that case, phpMyAdmin helps users to create and manage databases and execute database queries via a GUI interface. This tutorial will show you how to install phpMyAdmin on Fedora 34. ## Step 1 – Install the LAMP Server First, install the Apache and MariaDB server with the following command. ``` dnf install httpd mariadb-server -y ``` Once both packages are installed, start and enable the MariaDB service with the following command. ``` systemctl start httpd mariadb systemctl enable httpd mariadb ``` Next, install the PHP Remi repository with the following command. ``` dnf install -y http://rpms.remirepo.net/fedora/remi-release-34.rpm ``` Next, enable the PHP Remi repo with the following command. ``` dnf module enable -y php:remi-8.1 ``` Then, install PHP with other required extensions using the following command. ``` dnf install php php-fpm php-mysqlnd php-opcache php-gd php-xml php-mbstring php-curl php-pecl-imagick ``` ## Step 2 – Secure the MariaDB Installation Next, you must set the MariaDB root password and secure the installation. You can do it with the following command. ``` mysql_secure_installation ``` Answer all the questions as shown below: ``` Change the root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` ## Step 3 – Install phpMyAdmin By default, the phpMyAdmin package is not included in the Fedora 34 default repo, so you will need to install it from the Remi repo. Run the following command to install the phpMyAdmin to your server. ``` dnf --enablerepo=remi,remi-test install phpMyAdmin ``` Once the phpMyAdmin is installed, you can verify the phpMYAdmin package information with the following command. ``` rpm -qi phpMyAdmin ``` You will get the following output. ``` Name : phpMyAdmin Version : 5.2.0 Release : 1.fc34.remi Architecture: noarch Install Date: Thursday 13 April 2023 11:52:18 PM Group : Unspecified Size : 46210128 License : GPLv2+ and MIT and BSD and LGPLv3 and MPLv2.0 Signature : RSA/SHA256, Thursday 12 May 2022 01:30:06 AM, Key ID b19527f1478f8947 Source RPM : phpMyAdmin-5.2.0-1.fc34.remi.src.rpm Build Date : Thursday 12 May 2022 01:27:46 AM Build Host : builder.remirepo.net Packager : Remi Collet Vendor : Remi's RPM repository URL : https://www.phpmyadmin.net/ Bug URL : https://forum.remirepo.net/ Summary : A web interface for MySQL and MariaDB Description : phpMyAdmin is a tool written in PHP intended to handle the administration of MySQL over the Web. Currently it can create and drop databases, create/drop/alter tables, delete/edit/add fields, execute any SQL statement, manage keys on fields, manage privileges,export data into various formats and is available in 50 languages ``` ## Step 4 – Configure Apache for phpMyAdmin By default, phpMYAdmin is accessible only from the local machine. To access the phpMyAdmin from the remote machine, you will need to edit the phpMYAdmin configuration file and make some changes. ``` nano /etc/httpd/conf.d/phpMyAdmin.conf ``` Find the following line: ``` Require local ``` And replace it with the following line: ``` Require all granted ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart httpd ``` ## Step 5 – Access phpMyAdmin Now, open your web browser and access the phpMyAdmin using the URL **http://your-server-ip/phpmyadmin.** You should see the phpMyAdmin login page. ![phpMYAdmin login](https://www.atlantic.net/wp-content/uploads/2023/04/p1-14.png) Type your MariaDB root username and password and click on the **Login** button. You should see the phpMyAdmin dashboard on the following screen. ![phpmyadmin dashboard](https://www.atlantic.net/wp-content/uploads/2023/05/p2.png) ## Conclusion In this tutorial, we explained how to install phpMyAdmin with Apache on Fedora 34. You can now create and manage the MariaDB database via the phpMyAdmin dashboard. Try to deploy phpMyAdmin on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Prometheus Server on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-prometheus-server-on-fedora/ | Published: 2023-05-31 | Updated: 2023-11-25 | Author: Hitesh Jethva Prometheus is a free, open-source software solution that provides monitoring and alerting functionality for cloud-native environments. It gathers metrics from different target sources, organizes them, displays the results, and can trigger alerts when specified conditions are matched. It is designed for monitoring, recording, and processing any purely numeric time series in the Kubernetes environment. If you are looking for an open-source and web-based monitoring solution, then Prometheus is your best option. This post will show you how to install the Prometheus server on Fedora. ## Step 1 – Install Prometheus First, install some required dependencies using the following command. ``` dnf install curl wget nano ``` Next, visit the Prometheus official website and download the latest version of Prometheus using the following command. ``` wget https://github.com/prometheus/prometheus/releases/download/v2.44.0/prometheus-2.44.0.linux-amd64.tar.gz ``` Once the download is completed, extract the downloaded file with the following command. ``` tar -xvf prometheus-2.44.0.linux-amd64.tar.gz ``` Next, rename the extracted directory using the following command. ``` mv prometheus-2.44.0.linux-amd64 prometheus-files ``` ## Step 2 – Configure Prometheus First, create a dedicated user to run Prometheus. ``` useradd --no-create-home --shell /bin/false prometheus ``` Next, create the required directories for Prometheus. ``` mkdir /etc/prometheus mkdir /var/lib/prometheus ``` Next, change the ownership of the Prometheus directory. ``` chown prometheus:prometheus /etc/prometheus chown prometheus:prometheus /var/lib/prometheus ``` Next, copy Prometheus tools to the system location. ``` cp prometheus-files/prometheus /usr/local/bin/ cp prometheus-files/promtool /usr/local/bin/ ``` Then, change the ownership of the Prometheus tools binary. ``` chown prometheus:prometheus /usr/local/bin/prometheus chown prometheus:prometheus /usr/local/bin/promtool ``` Next, copy other required configuration files to the Prometheus directory and change their ownership. ``` cp -r prometheus-files/consoles /etc/prometheus cp -r prometheus-files/console_libraries /etc/prometheus chown -R prometheus:prometheus /etc/prometheus/consoles chown -R prometheus:prometheus /etc/prometheus/console_libraries ``` Next, create a Prometheus configuration file using the following command. ``` nano /etc/prometheus/prometheus.yml ``` Add the following configuration. ``` global: scrape_interval: 10s scrape_configs: - job_name: 'prometheus' scrape_interval: 5s static_configs: - targets: ['localhost:9090'] ``` Save and close the file, then change the file ownership. ``` chown prometheus:prometheus /etc/prometheus/prometheus.yml ``` ## Step 3 – Create a Systemd Service File Creating a systemd service file to manage the Prometheus service is a good idea. You can make it using the following command. ``` nano /etc/systemd/system/prometheus.service ``` Add the following lines. ``` [Unit] Description=Prometheus Wants=network-online.target After=network-online.target [Service] User=prometheus Group=prometheus Type=simple ExecStart=/usr/local/bin/prometheus \ --config.file /etc/prometheus/prometheus.yml \ --storage.tsdb.path /var/lib/prometheus/ \ --web.console.templates=/etc/prometheus/consoles \ --web.console.libraries=/etc/prometheus/console_libraries [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the configuration changes. ``` systemctl daemon-reload ``` Next, restart the Prometheus service. ``` systemctl start prometheus ``` You can now verify the Prometheus active status using the following command. ``` systemctl status prometheus ``` Output: ``` ● prometheus.service - Prometheus Loaded: loaded (/etc/systemd/system/prometheus.service; disabled; vendor preset: disabled) Active: active (running) since Tue 2023-06-06 03:33:07 EDT; 4s ago Main PID: 28510 (prometheus) Tasks: 7 (limit: 4666) Memory: 67.7M CPU: 497ms CGroup: /system.slice/prometheus.service └─28510 /usr/local/bin/prometheus --config.file /etc/prometheus/prometheus.yml --storage.tsdb.path /var/lib/prometheus/ --web.console.templates=/etc/prome> Jun 06 03:33:07 fedora prometheus[28510]: ts=2023-06-06T07:33:07.985Z caller=head.go:669 level=info component=tsdb msg="On-disk memory mappable chunks replay completed> Jun 06 03:33:07 fedora prometheus[28510]: ts=2023-06-06T07:33:07.985Z caller=head.go:677 level=info component=tsdb msg="Replaying WAL, this may take a while" Jun 06 03:33:07 fedora prometheus[28510]: ts=2023-06-06T07:33:07.985Z caller=head.go:748 level=info component=tsdb msg="WAL segment loaded" segment=0 maxSegment=0 Jun 06 03:33:07 fedora prometheus[28510]: ts=2023-06-06T07:33:07.985Z caller=head.go:785 level=info component=tsdb msg="WAL replay completed" checkpoint_replay_duratio> Jun 06 03:33:07 fedora prometheus[28510]: ts=2023-06-06T07:33:07.988Z caller=main.go:1037 level=info fs_type=XFS_SUPER_MAGIC Jun 06 03:33:07 fedora prometheus[28510]: ts=2023-06-06T07:33:07.988Z caller=main.go:1040 level=info msg="TSDB started" Jun 06 03:33:07 fedora prometheus[28510]: ts=2023-06-06T07:33:07.988Z caller=main.go:1220 level=info msg="Loading configuration file" filename=/etc/prometheus/promethe> Jun 06 03:33:08 fedora prometheus[28510]: ts=2023-06-06T07:33:08.028Z caller=main.go:1257 level=info msg="Completed loading of configuration file" filename=/etc/promet> Jun 06 03:33:08 fedora prometheus[28510]: ts=2023-06-06T07:33:08.028Z caller=main.go:1001 level=info msg="Server is ready to receive web requests." Jun 06 03:33:08 fedora prometheus[28510]: ts=2023-06-06T07:33:08.028Z caller=manager.go:995 level=info component="rule manager" msg="Starting rule manager..." ``` ## Step 4 – Access Prometheus Web UI At this point, Prometheus is installed and listening on port 9090. Now, open your web browser and access the Prometheus dashboard using the URL **http://prometheus-server-ip:9090/graph.** You should see the Prometheus dashboard on the following screen. ![prometheus dashboard](https://www.atlantic.net/wp-content/uploads/2023/06/p1-1-1.jpg) ## Conclusion In this post, we learned how to install the Prometheus monitoring solution on Fedora. You can now explore Prometheus and start monitoring your cloud-native applications using Prometheus. Try to install and deploy Prometheus monitoring on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install WordPress on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-wordpress-on-fedora/ | Published: 2023-05-31 | Updated: 2023-11-19 | Author: Hitesh Jethva WordPress is the most popular content management system in the world. This open-source CMS offers a simple, easy-to-use web interface where users can create and manage blogs and websites. WordPress is written in PHP and uses MariaDB as a database backend. It helps beginners create a website and blog without coding knowledge. WordPress is gaining popularity due to its simplicity, flexibility, extendability, customizable and large community. This post will show you how to install WordPress with Apache on Fedora 34. ## Step 1 – Install Apache and PHP First, install the Apache server with the following command. ``` dnf update -y dnf install httpd -y ``` Once installed, verify the Apache version using the following command. ``` httpd -v ``` You will get the Apache version in the following output. ``` Server version: Apache/2.4.53 (Fedora) Server built: Mar 17 2022 00:00:00 ``` Next, start and enable the Apache service with the following command. ``` systemctl start httpd systemctl enable httpd ``` Next, install PHP with other required extensions using the following command. ``` dnf install php php-fpm php-mysqlnd php-opcache php-gd php-xml php-mbstring php-curl php-pecl-imagick php-pecl-zip libzip -y ``` Next, edit the PHP configuration file and change the default settings suitable to your needs: ``` nano /etc/php.ini ``` Change the following settings: ``` max_execution_time = 300 max_input_time = 300 memory_limit = 512M post_max_size = 256M upload_max_filesize = 256M ``` Save and close the file, then start and enable the PHP-FPM service with the following command. ``` systemctl start php-fpm systemctl enable php-fpm ``` ## Step 2 – Install and Configure MariaDB Database First, install the MariaDB server with the following command. ``` dnf install mariadb-server -y ``` Next, start the MariaDB service and enable it to start at system reboot. ``` systemctl start mariadb systemctl enable mariadb ``` Next, log in to the MariaDB shell with the following command. ``` mysql ``` Once you are connected to MariaDB, create a database and user for WordPress: ``` MariaDB [(none)]> CREATE DATABASE wpdb; MariaDB [(none)]> GRANT ALL PRIVILEGES ON wpdb.* TO 'wpuser'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command. ``` MariaDB [(none)]> FLUSH PRIVILEGES; MariaDB [(none)]> EXIT; ``` ## Step 3 – Download WordPress First, navigate to the Apache web root directory and download the latest version of WordPress with the following command. ``` cd /var/www/html/ wget https://www.wordpress.org/latest.tar.gz ``` Next, extract the downloaded file using the tar command. ``` tar -xvf latest.tar.gz ``` Next, rename the default WordPress configuration file. ``` cd wordpress cp wp-config-sample.php wp-config.php ``` Next, edit the WordPress configuration file: ``` nano wp-config.php ``` Define your database settings as shown below: ``` /** The name of the database for WordPress */ define( 'DB_NAME', 'wpdb' ); /** Database username */ define ('DB_USER', 'wpuser'); /** Database password */ define( 'DB_PASSWORD', 'password' ); /** Database hostname */ define( 'DB_HOST', 'localhost' ); ``` Save and close the file, then change the permission and ownership of the WordPress directory. ``` chown -R apache:apache /var/www/html/wordpress chmod -R 755 /var/www/html/wordpress ``` ## Step 4 – Create an Apache Virtual Host for WordPress Next, you will need to create an Apache virtual host to define your WordPress directory and domain. ``` nano /etc/httpd/conf.d/wp.conf ``` Add the following configurations: ``` ServerAdmin admin@example.com ServerName wp.example.com DocumentRoot /var/www/html/wordpress Allowoverride all ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart httpd ``` ## Step 5 – Perform WordPress Web-based Installation Now, open your web browser and access the WordPress installation wizard using the URL **http://wp.example.com.** You should see the following screen: ![wordpress site configuration](https://www.atlantic.net/wp-content/uploads/2023/04/p1-15.png) Provide your WordPress site name, admin username, and password, and click the **Install** button. You should see the following screen. ![wordpress configured](https://www.atlantic.net/wp-content/uploads/2023/04/p2-10.png) Click on the **Login** button. You should see the WordPress administrative login page: ![wordpress login page](https://www.atlantic.net/wp-content/uploads/2023/04/p3-5.png) Provide your admin username and password and click on the **Login** button. You should see the WordPress dashboard on the following screen. ![Wordpress dashboard](https://www.atlantic.net/wp-content/uploads/2023/04/p4-3.png) ## Conclusion This post showed you how to install WordPress with Apache on Fedora 34. You can now explore WordPress and start creating your own website from the WordPress dashboard. You can also try to deploy WordPress on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How HIPAA Compliance Impacts Your Reputation as a Healthcare Provider > URL: https://www.atlantic.net/uncategorized/how-hipaa-compliance-impacts-your-reputation-as-a-healthcare-provider/ | Published: 2023-06-03 | Updated: 2025-09-15 | Author: Richard Bailey In the healthcare sector, your reputation is paramount. Patients entrust you with their most personal information, expecting it to remain secure and confidential. Sadly, data breaches and HIPAA violations have become increasingly prevalent in recent years. This article will explore how maintaining your business to the best possible HIPAA compliance standards is vital in safeguarding your reputation. But before that, let’s quickly revisit the essentials of HIPAA and understand its significance. ## Safeguarding Sensitive Health Data HIPAA is an acronym for the Health Insurance Portability and Accountability Act. This federal legislation establishes a binding framework of guidelines to ensure the privacy and security of protected health information (PHI). PHI encompasses an individual’s name, address, social security number, or medical records; the provisions under HIPAA solidify its inviolable safeguarding nature. Adhering to HIPAA regulations is mandatory for healthcare providers across the United States. This legal requirement necessitates safeguarding patient privacy and maintaining the confidentiality of sensitive information. Non-compliance carries substantial repercussions, as elaborated in the following section. It is crucial to emphasize that all healthcare providers, including doctors, dentists, hospitals, insurance companies, and business associates, must abide by HIPAA regulations. It’s important to note that HIPAA compliance is not optional. All healthcare providers, including doctors, dentists, hospitals, insurance companies, and all business associates, must follow HIPAA regulations. ## **Repercussions of HIPAA Violations** There are strict rules that legally enforce the reporting of all significant HIPAA violations to the United States Department of Health and Human Services ( HHS). All violations are investigated and reported on the [HIPAA Wall of Shame](https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf). Let’s look at some of the most significant repercussions that may happen in the event of a severe breach of patient confidentiality. ## **Negative Impact on Patient Trust** HIPAA violations harm patient trust. Patients place immense trust in healthcare providers to ensure the safety and security of their personal information. A breach of this trust can have devastating consequences on the reputation of your healthcare business. Patients may experience feelings of violation, embarrassment, or anger when their protected health information (PHI) is compromised. Additionally, they may be concerned about potential repercussions, including the risk of fraud and identity theft. It is not uncommon for patients to switch healthcare providers or avoid seeking medical care altogether immediately after a breach. Rebuilding patient trust after a HIPAA violation is a long and challenging process, but you will likely lose patients forever. ## **Impact on Healthcare Provider’s Reputation** HIPAA violations that affect over 500 patients [must be reported](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html) to the local or national news. Before too long, your business may be all over the headlines for the wrong reasons. The reputation of a healthcare provider hinges on their adeptness in safeguarding patient privacy and upholding confidentiality. Patients who feel their sensitive information is unsafe with a particular provider may seek care elsewhere, resulting in the healthcare provider losing patients and revenue. Moreover, violations lead to negative publicity and potential legal action, further damaging a healthcare provider’s reputation. Therefore, it’s essential to take HIPAA compliance seriously and to prioritize patient privacy and security. ## **Legal Consequences of HIPAA Violations** Noncompliance with HIPAA regulations carries legal ramifications, such as fines and potential legal action. The Office for Civil Rights (OCR) enforces HIPAA and can impose substantial penalties on healthcare providers found in violation. These fines vary from $100 to $50,000 per violation, and for repeated offenses, healthcare providers may face a maximum penalty of $1.5 million annually. In addition to fines, healthcare providers can also face legal action from patients whose PHI has been compromised. Patients can sue for damages, including emotional distress, lost wages, and medical expenses. Legal action can be costly and time-consuming and can further damage a healthcare provider’s reputation. ## **Steps to Ensure HIPAA Compliance** Becoming HIPAA compliant is a significant undertaking requiring a comprehensive [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) program that documents the policies and procedures required to protect PHI. In addition, you will need a digital IT infrastructure capable of adhering to HIPAA’s physical, technical, and administrative safeguards. Healthcare providers must undertake regular risk assessments to identify PHI, plus any potential vulnerabilities in their systems and processes. This can help them proactively prevent data breaches and privacy violations. In addition, all employees must be trained, and ongoing monitoring must be done to ensure everyone follows the rules. ## The Positive Impact of HIPAA Compliance on Healthcare Providers and Patients Although achieving HIPAA compliance can present challenges, it brings numerous advantages for both healthcare providers and patients. Healthcare providers who comply with HIPAA regulations experience enhanced patient trust, increased satisfaction, and protection against potential legal and financial ramifications. For patients, HIPAA compliance ensures the safety and security of their personal information, resulting in greater peace of mind and improved health outcomes. By trusting compliant healthcare providers, patients feel empowered to actively pursue medical care and openly share sensitive information, fostering a robust patient-provider relationship. Ultimately, HIPAA compliance is a win-win for everyone involved. ## **Maintaining Your Business Reputation with Atlantic.Net’s HIPAA Hosting** If your healthcare organization needs help with managed healthcare hosting. Atlantic.Net is an expert in HIPAA compliance. We will help your business maintain its excellent reputation through [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/). This is how we do it: 1. **Certified and Audited**: Atlantic.Net’s [state-of-the-art data centers](https://www.atlantic.net/hipaa-compliant-hosting/) have achieved rigorous certification in SOC 2 and SOC 3, making us compliant with HIPAA regulations. Our unwavering commitment to security and protection extends to critical health data, ePHI, and health records. To reinforce our dedication, we subject our managed services to thorough audits conducted by reputable third-party firms. 2. **Comprehensive Solutions**: Our offerings include high-performance Dedicated Servers and Cloud-based environments designed to ensure HIPAA compliance for your websites, databases, and storage. With our 100% uptime Service Level Agreement (SLA), you can trust us to deliver reliable and secure HIPAA-compliant hosting solutions. 3. **Fast and Reliable Hosting**: All Atlantic.Net HIPAA hosting servers are backed by SSD storage, ultrafast networking, and Intel’s latest hardware. The infrastructure is highly available, and we offer a suite of managed services that relieve the headaches of managing your servers. 4. **HIPAA-Compliant Servers**: Servers are available in various Windows and Linux offerings. You can access our 1-click applications that spin up a fully configured server or application in about 30 seconds. Pricing for these HIPAA-compliant dedicated servers is discounted based on term commitment. 5. **Advanced Security Features**: Our hosting services come with a range of security features, including a Firewall for HIPAA Compliant Web Hosting, HIPAA-Compliant Encrypted VPN, HIPAA-Compliant Offsite Backups, SSL certificates for HIPAA Compliance, SOC 2 and SOC 3 Certifications, Business Associate Agreement (BAA), Multi-Factor Authentication, Trend Micro Anti-Malware Service, Intrusion Prevention Service, and Network Edge Protection. 6. **HIPAA-Compliant Cloud Hosting and Storage:** Our Cloud Hosting and Storage solution undergoes thorough audits and certification to meet the stringent standards of the HIPAA Security Rule, conducted by an independent third party. With a design that prioritizes privacy and implements robust access controls, our service offers a perfect blend of speed, security, and reliability. It excels in securely storing vast datasets, facilitating file transfers, accommodating online storage needs, supporting imaging tasks, and safeguarding highly encrypted health records. 7. **Secure Block Storage (SBS)**: Atlantic.Net’s user-friendly, highly redundant, easily accessible, and scalable SBS is ideal for a mission-critical HIPAA-compliant application platform requiring robust block storage. As a healthcare provider, your reputation is everything. HIPAA compliance is essential for protecting patient privacy and maintaining patient trust. Failure to comply can result in severe consequences, including legal and financial penalties, loss of patients, and damage to your reputation. By taking proactive steps to ensure HIPAA compliance, healthcare providers can protect their patient’s privacy and security, as well as their reputations and financial well-being. It’s a small price to pay for the peace of mind that comes with knowing you’re doing everything possible to protect your patients’ sensitive information. --- # How to Install Vue.JS on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-vue-js-on-fedora/ | Published: 2023-06-03 | Updated: 2023-11-18 | Author: Hitesh Jethva Vue.js is an open-source, lightweight, and progressive JavaScript framework that offers intuitive API and world-class documentation. It provides an easier way to build user interfaces and single-page applications. It offers a lot of features, such as a range of tools, virtual DOM modeling, adoptable DOM manipulation benefits, and more. In this post, we will show you how to install the Vue.js framework on Fedora. ## Step 1 – Install Nodejs and NPM First, you will need to install Node.js and NPM on your server. By default, Node.js and NPM are included in the Fedora default repo. You can install both using the following command. ``` dnf install -y nodejs npm ``` Once both packages are installed, you can verify the Node version using the following command. ``` node --version ``` Output. ``` v14.19.0 ``` To verify the NPM version, run the following command. ``` npm --version ``` Output. ``` 6.14.16 ``` ## Step 2 – Install Vue CLI Vue.js provides a CLI tool to create and manage the Vue.js website via the command line. First, install the Vue.js CLI with the NPM command. ``` npm install -g @vue/cli ``` After the successful installation, you can verify the Vue.js version with the following command. ``` vue --version ``` Output. ``` @vue/cli 5.0.8 ``` ## Step 3 – Create a Website Using Vuejs Let’s create a simple website named **examplesite** with the following command. ``` vue create examplesite ``` Once the website is created, you will see the following output. ``` Vue CLI v5.0.8 ✨ Creating project in /root/examplesite. ⚙️ Installing CLI plugins. This might take a while... > yorkie@2.0.0 install /root/examplesite/node_modules/yorkie > node bin/install.js setting up Git hooks can't find .git directory, skipping Git hooks installation > core-js@3.30.2 postinstall /root/examplesite/node_modules/core-js > node -e "try{require('./postinstall')}catch(e){}" added 862 packages from 463 contributors and audited 863 packages in 119.173s 93 packages are looking for funding run `npm fund` for details found 0 vulnerabilities 🚀 Invoking generators... 📦 Installing additional dependencies... added 100 packages from 63 contributors and audited 963 packages in 17.628s 106 packages are looking for funding run `npm fund` for details found 0 vulnerabilities ⚓ Running completion hooks... 📄 Generating README.md... 🎉 Successfully created project examplesite. 👉 Get started with the following commands: $ cd examplesite $ npm run serve ``` Next, navigate to the **examplesite** directory and run the website using the following command. ``` cd examplesite npm run serve ``` You will get the following output. ``` DONE Compiled successfully in 11251ms 4:05:29 am App running at: - Local: http://localhost:8080/ - Network: unavailable Note that the development build is not optimized. To create a production build, run npm run build. ``` ## Step 4 – Access Vuejs Website At this point, Vue.js is installed and running on port 8080. Now, open your web browser and access the Vue.js website using the URL **http://your-server-ip:8080.** You should see the Vue.js sample test page on the following screen. ![vue.js](https://www.atlantic.net/wp-content/uploads/2023/06/p1-2.jpg) ## Conclusion In this guide, we explained how to install Vue.js and create a simple website using Vue CLI. You can now use Vue.js. You can now explore the VUe.js features and start building a fast and user-friendly website quickly. Try to install Vue.js on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Gatsby.js Node Framework on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-gatsby-js-node-framework-on-fedora/ | Published: 2023-06-04 | Updated: 2023-11-23 | Author: Hitesh Jethva Gatsby is an open-source framework based on React. It designed for performance, with scalability and security in mind. It helps you to build a fast, secure, and powerful website within minutes. Gatsby uses the most recent web technologies, such as React, GraphQL, and Webpack. This will help developers build blazing-fast websites and apps. It offers 2500+ plugins to create static sites based on sources such as Markdown documents, MDX, images, and numerous Content Management Systems such as WordPress, Drupal, and more. In this post, we will show you how to install Gatsby.js framework on Fedora. ## Step 1 – Install Node.js and NPM First, install the required dependencies using the following command. ``` dnf update -y dnf install -y gcc-c++ make ``` Gatsby requires Node.js version 18.0.0 or greater to be installed on your server. By default, Node.js latest version is not included in the Fedora repo, so you will need to install Node.js via NVM. First, run the following script to install NVM. ``` curl https://raw.githubusercontent.com/creationix/nvm/master/install.sh | bash ``` Next, run the following command to load the environment variable. ``` source ~/.bashrc ``` Next, install Node.js with the following command. ``` nvm install v18.0.0 ``` Output: ``` Downloading and installing node v18.0.0... Downloading https://nodejs.org/dist/v18.0.0/node-v18.0.0-linux-x64.tar.xz... ################################################################################################################################################################# 100.0% Computing checksum with sha256sum Checksums matched! Now using node v18.0.0 (npm v8.6.0) Creating default alias: default -> v18.0.0 ``` Next, verify the Node.js version with the following command. ``` node --version ``` Output: ``` v18.0.0 ``` ## Step 2 – Install Gatsby CLI Gatsby offers a command line tool to create a website easily via command line. You can install it with the NPM command. ``` npm -g install gatsby-cli ``` After successful installation, verify the Gatsby version with the following command. ``` gatsby --version ``` Output: ``` Gatsby CLI version: 5.10.0 ``` ## Step 3 – Create a Website with Gatsby First, install the Git package with the following command. ``` dnf install git ``` Next, create a new website using the following command. ``` gatsby new ``` You will be asked several questions to create a website. Once the website is created, you will see the following output. ``` create-gatsby version 3.10.0 Welcome to Gatsby! This command will generate a new Gatsby site for you in /root with the setup you select. Let's answer some questions: What would you like to call your site? ✔ · My Gatsby Site What would you like to name the folder where your site will be created? ✔ root/ my-gatsby-site ✔ Will you be using JavaScript or TypeScript? · JavaScript ✔ Will you be using a CMS? · No (or I'll add it later) ✔ Would you like to install a styling system? · No (or I'll add it later) ✔ Would you like to install additional features with other plugins? Thanks! Here's what we'll now do: 🛠 Create a new Gatsby site in the folder my-gatsby-site 🔌 Install gatsby-transformer-remark ✔ Created site from template ▸ Installing Gatsby... ✔ Created site from template ✔ Installed Gatsby ✔ Installed plugins ✔ Created site in my-gatsby-site 🔌 Setting-up plugins... info Adding gatsby-transformer-remark info Adding gatsby-source-filesystem info Installed gatsby-transformer-remark in gatsby-config success Adding gatsby-transformer-remark to gatsby-config - 0.326s info Installed gatsby-source-filesystem in gatsby-config success Adding gatsby-source-filesystem (pages) to gatsby-config - 0.341s Author identity unknown *** Please tell me who you are. Run git config --global user.email "you@example.com" git config --global user.name "Your Name" to set your account's default identity. Omit --global to set the identity only in this repository. Initial git commit failed - removing git support 🎉 Your new Gatsby site My Gatsby Site has been successfully created at /root/my-gatsby-site. Start by going to the directory with cd my-gatsby-site Start the local development server with npm run develop See all commands at https://www.gatsbyjs.com/docs/reference/gatsby-cli/ ``` ## Step 4 – Run a Gatsby Website At this point, the Gatsby website is created in the my-gatsby-site directory. Now, it’s time to run it. First, change the directory to the Gatsby website. ``` cd my-gatsby-site ``` Next, run the Gatsby website with the following command. ``` gatsby develop -H your-server-ip ``` You will see the following output. ``` ⠀ http://69.28.88.130:8000/ ⠀ View GraphiQL, an in-browser IDE, to explore your site's data and schema ⠀ http://69.28.88.130:8000/___graphql ⠀ Note that the development build is not optimized. To create a production build, use gatsby build ⠀ success Building development bundle - 27.035s success Writing page-data.json and slice-data.json files to public directory - 0.179s - 3/4 22.30/s ``` ## Step 5 – Access Gatsby Web UI At this point, the Gatsby website is created and listens on port 8000. Now, open your web browser and access the Gatsby website using the URL **http://your-server-ip:8000.** You should see the following screen. ![gatsby dashboard](https://www.atlantic.net/wp-content/uploads/2023/06/p1-1.jpg) You can also access the Gatsby graph using the URL **http://your-server-ip:8000/___graphql.** You should see the following screen. ![Gatsby graph](https://www.atlantic.net/wp-content/uploads/2023/06/p2-1.jpg) ## Step 6 – Create a Systemd Service for Gatsby At this point, Gatsby is installed and running. However, you will need to run it manually after the system reboot, so you will need to create a systemd service file to manage the Gatsby website via systemctl. First, create a symbolic link of the Node.js binary using the following command. ``` ln -s /root/.nvm/versions/node/v18.0.0/bin/node /usr/bin/ ``` Next, create a systemd service file for Gatsby: ``` nano /etc/systemd/system/gatsby.service ``` Add the following configuration. ``` [Unit] Description=Github webhook After=network.target [Service] Environment=PATH=/root/my-gatsby-site Type=simple User=root ExecStart=/usr/local/bin/gatsby develop -H your-server-ip Restart=on-failure [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd service to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the Gatsby service. ``` systemctl start gatsby systemctl enable gatsby ``` You can now verify the status of Gatsby with the following command. ``` systemctl status gatsby ``` Output: ``` ● gatsby.service Loaded: loaded (/etc/systemd/system/gatsby.service; disabled; vendor preset: disabled) Active: active (running) since Tue 2023-06-06 04:42:30 EDT; 14s ago Main PID: 33717 (node) Tasks: 27 (limit: 4666) Memory: 489.5M CPU: 20.422s CGroup: /system.slice/gatsby.service ├─33717 node /usr/local/bin/gatsby develop -H 69.28.88.130 ├─33728 /root/.nvm/versions/node/v18.0.0/bin/node /root/my-gatsby-site/.cache/tmp-33717-yOMn7pP7ifjY └─33761 /root/.nvm/versions/node/v18.0.0/bin/node /root/my-gatsby-site/node_modules/gatsby-worker/dist/child.js ``` ## Conclusion Congratulations! You have successfully installed the Gatsby.js framework and created a sample website using the Gatsby.js. You can now build a fast and scalable website easily using the Gatsby framework. Try to install the Gatsby framework on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Drupal on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-drupal-on-fedora/ | Published: 2023-06-04 | Updated: 2023-11-16 | Author: Hitesh Jethva Drupal is an open-source CMS that allows users to build the versatile, structured content needed for dynamic web experiences. It is an alternate solution to other CMSes like WordPress and Joomla. It offers great features like reliability, high performance, excellent security, easy content authoring, and more. Drupal offers more than 30000 modules that help users to create blogs, forums, polls, and any kind of website. This post will explain how to install Drupal CMS on Fedora 34. ## Step 1 – Install Apache and MariaDB Server First, install the Apache and MariaDB server with the following command. ``` dnf update -y dnf install httpd mariadb-server -y ``` Once both packages are installed, start and enable both Apache and MariaDB services with the following command. ``` systemctl start httpd mariadb systemctl enable httpd mariadb ``` ## Step 2 – Install PHP Next, you will need to install the latest version of PHP on your server. First, install the Remi PHP repository using the following command. ``` dnf install -y http://rpms.remirepo.net/fedora/remi-release-34.rpm ``` Next, enable the Remi PHP module with the following command. ``` dnf module enable -y php:remi-8.1 ``` Next, install PHP with other required extensions using the following command. ``` dnf install php php-fpm php-mysqlnd php-opcache php-gd php-xml php-mbstring php-curl php-pecl-imagick php-pecl-zip libzip ``` Once PHP is installed, you can verify the PHP version with the following command. ``` php -v ``` You should see the following output. ``` PHP 8.1.9 (cli) (built: Aug 2 2022 13:02:24) (NTS gcc x86_64) Copyright (c) The PHP Group Zend Engine v4.1.9, Copyright (c) Zend Technologies with Zend OPcache v8.1.9, Copyright (c), by Zend Technologies ``` Next, edit the PHP configuration file and change the default settings: ``` nano /etc/php.ini ``` Change the following lines: ``` max_execution_time = 300 max_input_time = 300 memory_limit = 512M post_max_size = 256M upload_max_filesize = 256M ``` Save and close the file, then start and enable the PHP-FPM service to implement the changes. ``` systemctl start php-fpm systemctl enable php-fpm ``` ## Step 3 – Create a Database for Drupal Next, you will need to create a database and user for Drupal. First, log in to the MariaDB shell with the following command. ``` mysql ``` Once logged in, create a database and user with the following command. ``` MariaDB [(none)]> CREATE DATABASE drupaldb; MariaDB [(none)]> GRANT ALL PRIVILEGES ON drupaldb.* TO 'drupaluser'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command. ``` MariaDB [(none)]> FLUSH PRIVILEGES; MariaDB [(none)]> EXIT; ``` ## Step 4 – Download Drupal First, download the latest version of Drupal with the following command. ``` wget https://www.drupal.org/download-latest/tar.gz ``` Next, extract the downloaded file with the following command. ``` tar -zxf tar.gz ``` Next, move the extracted directory to the Apache web root: ``` mv drupal-10.0.7 /var/www/html/drupal ``` Next, navigate to the Drupal site directory and copy the default setting file. ``` cd /var/www/html/drupal/sites/default cp -p default.settings.php settings.php ``` Next, create a files directory. ``` mkdir files ``` Next, change the ownership and permissions of the Drupal directory. ``` chown -R apache:apache /var/www/html/drupal chmod -R 755 /var/www/html/drupal ``` ## Step 5 – Configure Apache for Drupal Next, create an Apache virtual host configuration file for Drupal. ``` nano /etc/httpd/conf.d/drupal.conf ``` Add the following configurations: ``` ServerAdmin admin@example.com ServerName drupal.example.com DocumentRoot /var/www/html/drupal Allowoverride all ``` Save and close the file, then restart the Apache service to apply the changes. ## Step 6 – Access Drupal Web UI Now, open your web browser and access the Drupal web installation wizard using the URL **http://drupal.example.com.** You should see the language selection page: ![drupal language selection](https://www.atlantic.net/wp-content/uploads/2023/05/p1.png) Select your language and click on the **Save and Continue button**. You should see the select installation profile page: ![drupal select installation profile](https://www.atlantic.net/wp-content/uploads/2023/05/p2-1.png) Select your installation profile and click on the **Save and Continue button**. You should see the database configuration page. ![drupal database configuration](https://www.atlantic.net/wp-content/uploads/2023/05/p3.png) Provide your Drupal database username, password, and database name, and click on the **Save and Continue button**. You should see the Site configuration page. ![drupal site configuration](https://www.atlantic.net/wp-content/uploads/2023/05/p5.png) ![drupal site configuration](https://www.atlantic.net/wp-content/uploads/2023/05/p6.png)   Provide all required information and click on the **Save and Continue button**. You should see the Drupal dashboard on the following page. ![Drupal dashboard](https://www.atlantic.net/wp-content/uploads/2023/05/p7.png) ## Conclusion This post explained how to install Drupal with Apache on Fedora 34. You can now use Drupal to host your own website on the web. Try to host a Drupal website on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Choose the Best Hosting Provider for Your Business > URL: https://www.atlantic.net/vps-hosting/how-to-choose-the-best-hosting-provider-for-your-business/ | Published: 2023-06-05 | Updated: 2025-09-15 | Author: Richard Bailey Every business needs a reliable, high-performance IT infrastructure to succeed. But behind every great company is a dedicated hosting provider ensuring your IT systems and core servers function at peak performance, diligently working to ensure your systems operate at their absolute best. Selecting the appropriate hosting provider for your business is crucial in determining your enterprise’s performance, security, and profitability. This article will explain the best hosting provider features and demonstrate how cloud computing can take your business to the next level. ## What a Hosting Provider Should Offer A hosting provider is much more than someone who keeps the lights; it is the backbone of your digital presence and your digital enabler. But what exactly sets a leading hosting provider apart from the rest? 1. **Hosting Types:** While shared hosting is cost-effective, it involves sharing resources with other websites, potentially affecting performance. On the other hand, [Virtual Private Server (VPS) hosting](https://www.atlantic.net/vps-hosting/) offers dedicated resources for your server, guaranteeing enhanced performance and security. Dedicated servers take this a step further, offering an entire server for your business, while cloud platforms provide unmatched scalability and resilience. 2. **Performance:** The speed and uptime of your IT Systems are integral to the user experience. Slow or frequently unavailable systems will deter potential customers and harm your business’s reputation. A top-notch hosting provider guarantees high uptime and speedy performance. 3. **Security:** Cyber threats are a rising concern for businesses. The best hosting providers offer robust security measures, such as firewalls, SSL certificates, and regular backups, to protect your business from the latest cyber threats. 4. **Customer Support:** When problems arise, prompt and effective customer support can be a lifesaver. Look for a hosting provider with a reputation for delivering top-notch customer service. 5. **Scalability:** As your business grows, so do your IT needs. Look for a hosting provider that can scale its services according to your evolving needs. ## **Amplifying Your Business with Atlantic.Net** Now that you understand what to look for in a hosting provider, let’s delve into the world-class hosting services offered by Atlantic.Net and why they are the ideal choice for your business. **Unparalleled Hosting Options:** Atlantic.Net provides a wide range of hosting options designed to cater to the specific needs of your business. We offer VPS hosting, cloud hosting, and dedicated servers, allowing you to select the ideal hosting solution for your requirements. So whether you need the flexibility and scalability of [VPS hosting](https://www.atlantic.net/vps-hosting/), the power and resources of [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/), or the agility and efficiency of cloud hosting, Atlantic.Net has options to suit your business needs. **Exceptional Performance:** Atlantic.Net guarantees a 100% uptime guarantee and utilizes state-of-the-art technology to ensure your website runs quickly and smoothly. With Atlantic.Net, your website’s performance is never a concern. **Impeccable Security:** With Atlantic.Net, your website’s security is paramount. They offer advanced security measures, including Managed Firewall, Intrusion Detection services, and Automated Backups. With Atlantic.Net, you can rest easy knowing your business is in safe hands. **24/7/365 Customer Support:** We actively focus on delivering exceptional customer service, backed by our experienced US-based support team that remains available 24/7/365 to assist with any issues that may arise promptly **Scalable Solutions:** Atlantic.Net understands that your business’s needs may change. Therefore, we offer scalable hosting solutions to accommodate your growing business. Choosing the right hosting provider for your business is a significant decision that can shape your digital presence’s trajectory. With its impressive range of hosting options, guaranteed performance, robust security, exceptional customer service, and scalable solutions, Atlantic.Net is the hosting provider your business needs to thrive in the digital era. Don’t settle for less when it comes to your business. Experience the Atlantic.Net difference today and empower your business to achieve unprecedented success. Whether you’re looking for cloud, VPS, dedicated server, colocation, or managed hosting, Atlantic.Net has you covered. The [ACP cloud platform](https://cloud.atlantic.net/?page=userlogin) is designed for unparalleled performance and maximum flexibility, offering blazing-fast speeds for servers and applications with a [100% uptime](https://www.atlantic.net/hosting-services-provider/) guarantee. On the other hand, if you’re seeking fault-tolerant and ultra-fast performance, look no further than Atlantic.Net’s VPS hosting, backed by an expert support team available round the clock. For businesses with complex security, compliance, and privacy requirements, Atlantic.Net’s dedicated server hosting provides dizzying speeds of large data transfers while assuring optimum server performance. In addition, with colocation hosting, you can place your server infrastructure in a secure data center environment, offering maximum control while leasing power, space, and bandwidth. Moreover, Atlantic.Net’s managed services help save time, effort, and resources by handling data containment, flow, and security on a dedicated or cloud environment, allowing you to focus more on your core business. With a legacy stretching back to 1994, Atlantic.Net has built a reputation as a trusted hosting solutions provider, always putting customer satisfaction at the forefront of its operations. You’re not just choosing a hosting provider; you’re choosing a partner committed to your business’s growth and prosperity. Switch to Atlantic.Net today and [give your business the digital presence it deserve](https://www.atlantic.net/about-us/corporate-contact/)s. Unlock your business’s potential and experience the power of world-class hosting. Begin your journey today. --- # How to Setup a Basic ELK Stack on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-setup-a-basic-elk-stack-on-fedora/ | Published: 2023-06-06 | Updated: 2023-11-27 | Author: Hitesh Jethva An ELK stack is a group of three popular open-source components: Elasticsearch, Logstash, and Kibana. An ELK stack helps you to capture logs of all your systems and applications and analyze and create a visual dashboard for application monitoring. Elasticsearch is a search engine, Logstash is a server‑side data processing pipeline and Kibana lets users visualize data with charts and graphs in Elasticsearch. In this post, we will show you how to install the ELK stack on Fedora ## Step 1 – Install Java JDK ELK stack is based on Java, so Java JDK must be installed on your server. If not installed, you can install it with the following command. ``` dnf update -y ``` ``` dnf install java-openjdk-devel java-openjdk ``` Once Java JDK is installed, you can verify it with the following command. ``` java -version ``` You will get the Java version in the following output. ``` openjdk version "11.0.10" 2021-01-19 OpenJDK Runtime Environment 18.9 (build 11.0.10+9) OpenJDK 64-Bit Server VM 18.9 (build 11.0.10+9, mixed mode, sharing) ``` ## Step 2 – Install Elasticsearch By default, the Elasticsearch package is not included in the Fedora default repo, so you will need to create an Elasticsearch repo on your server. You can create it with the following command. ``` nano /etc/yum.repos.d/elasticsearch.repo ``` Add the following configuration. ``` [elasticsearch-8.x] name=Elasticsearch repository for 8.x packages baseurl=https://artifacts.elastic.co/packages/8.x/yum gpgcheck=1 gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch enabled=1 autorefresh=1 type=rpm-md ``` Save and close the file, then import the Elasticsearch key using the following command. ``` rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch ``` Next, clean all package caches with the following command. ``` yum clean all yum makecache ``` Finally, install the Elasticsearch package with the following command. ``` dnf install elasticsearch ``` Next, start the enable the Elasticsearch service with the following command. ``` systemctl enable --now elasticsearch.service ``` You can verify the status of Elasticsearch with the following command. ``` systemctl status elasticsearch ``` Output. ``` ● elasticsearch.service - Elasticsearch Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; enabled; vendor preset: disabled) Active: active (running) since Mon 2023-06-05 12:11:26 EDT; 13s ago Docs: https://www.elastic.co Main PID: 132617 (java) Tasks: 75 (limit: 4666) Memory: 2.3G CPU: 1min 2.533s CGroup: /system.slice/elasticsearch.service ├─132617 /usr/share/elasticsearch/jdk/bin/java -Xms4m -Xmx64m -XX:+UseSerialGC -Dcli.name=server -Dcli.script=/usr/share/elasticsearch/bin/elasticsearch -> ├─132673 /usr/share/elasticsearch/jdk/bin/java -Des.networkaddress.cache.ttl=60 -Des.networkaddress.cache.negative.ttl=10 -Djava.security.manager=allow -X> └─132706 /usr/share/elasticsearch/modules/x-pack-ml/platform/linux-x86_64/bin/controller Jun 05 12:10:55 freepbx systemd[1]: Starting Elasticsearch... Jun 05 12:11:26 freepbx systemd[1]: Started Elasticsearch. ``` Next, you will need to set the Elasticsearch password. You can set it with the following command. ``` /usr/share/elasticsearch/bin/elasticsearch-reset-password -u elastic -i ``` Set your password as shown below. ``` This tool will reset the password of the [elastic] user. You will be prompted to enter the password. Please confirm that you would like to continue [y/N]y Enter password for [elastic]: Re-enter password for [elastic]: Password for the [elastic] user successfully reset. ``` Next, verify Elasticsearch using the following command. ``` curl --cacert /etc/elasticsearch/certs/http_ca.crt -u elastic https://localhost:9200 ``` You will be asked to provide your password to perform the query. After the successful authentication, you will get the following output. ``` Enter host password for user 'elastic': { "name" : "freepbx", "cluster_name" : "elasticsearch", "cluster_uuid" : "g13oMGscTzqXwHqacXMYwg", "version" : { "number" : "8.8.0", "build_flavor" : "default", "build_type" : "rpm", "build_hash" : "c01029875a091076ed42cdb3a41c10b1a9a5a20f", "build_date" : "2023-05-23T17:16:07.179039820Z", "build_snapshot" : false, "lucene_version" : "9.6.0", "minimum_wire_compatibility_version" : "7.17.0", "minimum_index_compatibility_version" : "7.0.0" }, "tagline" : "You Know, for Search" } ``` ## Step 3 – Install Kibana You can run the following command to install Kibana on your server. ``` dnf install kibana ``` After the successful installation, you will need to edit the Kibana configuration file and define your server name and host. You can edit it with the following command. ``` nano /etc/kibana/kibana.yml ``` Change the following lines: ``` server.host: "0.0.0.0" server.name: "kibana.example.com" elasticsearch.hosts: ["http://localhost:9200"] ``` Save and close the file. Then, start the Kibana service and enable it to start at system reboot. ``` systemctl enable --now kibana ``` You can now check the Kibana status with the following command. ``` systemctl status kibana ``` Output: ``` ● kibana.service - Kibana Loaded: loaded (/usr/lib/systemd/system/kibana.service; enabled; vendor preset: disabled) Active: active (running) since Mon 2023-06-05 12:17:15 EDT; 12s ago Docs: https://www.elastic.co Main PID: 133181 (node) Tasks: 11 (limit: 4666) Memory: 216.5M CPU: 13.397s CGroup: /system.slice/kibana.service └─133181 /usr/share/kibana/bin/../node/bin/node /usr/share/kibana/bin/../src/cli/dist Jun 05 12:17:15 freepbx systemd[1]: Started Kibana. Jun 05 12:17:21 freepbx kibana[133181]: [2023-06-05T12:17:21.001-04:00][INFO ][node] Kibana process configured with roles: [background_tasks, ui] ``` Now, open your web browser and access the Kibana dashboard using the URL **http://your-server-ip:5601/.** You will be asked to provide a token as shown below. ![provide token](https://www.atlantic.net/wp-content/uploads/2023/06/p1.jpg) Now, run the following command to generate a token for enrollment. ``` /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s kibana ``` Output. ``` eyJ2ZXIiOiI4LjguMCIsImFkciI6WyI2OS4yOC44NS4yMTY6OTIwMCJdLCJmZ3IiOiI2YzE4YjcxZDlhNjVmNDlkM2Q2NWMwOTgyNmEwMDdhZTIzODVmYmIxMDQ5NjkxMjRjYTcyYTE0YWJiY2MxNTkwIiwia2V5IjoiV21wYWpJZ0JHNkV5OE5RQmhSNTk6SEdCdWhTaWxTaWlTS0ltZTR4eXFQUSJ9 ``` Copy and paste the above token to the browser and click on **Configure Elastic.** You should see the verification screen. ![verify via code](https://www.atlantic.net/wp-content/uploads/2023/06/p2.jpg) Now, get the verification code, open your terminal, and run the following command. ``` /usr/share/kibana/bin/kibana-verification-code ``` Output: ``` Your verification code is: 459 529 ``` Paste the above code to the web browser and click on the **verify** button. After the successful verification, you should see the Elastic login page. ![elastic login](https://www.atlantic.net/wp-content/uploads/2023/06/p3.jpg) Provide your username, password and click on the **Log In** button. You should see the Kibana dashboard on the following screen. ![elk dashboard](https://www.atlantic.net/wp-content/uploads/2023/06/p4.jpg) ## Step 4 – Install Logstash Logstash is an open-source, and server-side data processing pipeline that allows you to collect data from different sources, transform it, and send it to your desired destination. You can install it with the following command. ``` dnf install logstash ``` After the installation, start and enable the Logstash service with the following command. ``` systemctl start logstash systemctl enable logstash ``` ## Conclusion In this post, we explained how to install a complete ELK stack such as Elasticsearch, Kibana, and Logstash on Fedora. You can now implement the ELK stack in your development environment and start monitoring your application via the Kibana dashboard. Let’s try to deploy and implement an ELK stack on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install PHP on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-php-on-fedora/ | Published: 2023-06-06 | Updated: 2023-11-18 | Author: Hitesh Jethva PHP, also called “PHP: Hypertext Preprocessor,” is a widely-used, open-source scripting language for managing dynamic content. It is a server-side scripting language that is embedded in HTML. Generally, PHP is used with Apache and Nginx web servers to build dynamic websites, static websites, and web applications. It is also a general-purpose language that you can use to make many projects, including Graphical User Interfaces. This post will show you how to install PHP 5.6, 7.4, 8.0, and 8.1 on Fedora 34. ## Install PHP 8.1 By default, PHP 8.1 is not included in the Fedora 34 default repo, so you will need to install the PHP Remi repository on your server. You can install it with the following command. ``` dnf install -y http://rpms.remirepo.net/fedora/remi-release-34.rpm ``` Next, enable the Remi repository with the following command. ``` dnf module install php:remi-8.1 ``` Next, install PHP 8.1 with other extensions with the following command. ``` dnf install -y php php-common php-cli ``` After the installation, verify the PHP version using the following command. ``` php -v ``` You should get the following output. ``` PHP 8.1.9 (cli) (built: Aug 2 2022 13:02:24) (NTS gcc x86_64) Copyright (c) The PHP Group Zend Engine v4.1.9, Copyright (c) Zend Technologies with Zend OPcache v8.1.9, Copyright (c), by Zend Technologies ``` ## Install PHP 8.0 First, reset the PHP default module with the following command. ``` dnf module reset php -y ``` Next, install the Remi module for PHP 8.0 with the following command. ``` dnf module install php:remi-8.0 ``` Next, install PHP and other extensions using the following command. ``` dnf install -y php php-common php-cli ``` Once all the packages are installed, you can verify the PHP version with the following command. ``` php -v ``` You should see the following output. ``` PHP 8.0.22 (cli) (built: Aug 2 2022 08:01:15) ( NTS gcc x86_64 ) Copyright (c) The PHP Group Zend Engine v4.0.22, Copyright (c) Zend Technologies with Zend OPcache v8.0.22, Copyright (c), by Zend Technologies ``` ## Install PHP 7.4 First, reset the PHP default module with the following command. ``` dnf module reset php -y ``` Next, install the Remi module for PHP 7.4 with the following command. ``` dnf module install php:remi-7.4 -y ``` Next, install PHP with other extensions using the following command. ``` dnf install -y php php-common php-cli ``` Finally, verify the PHP version using the following command. ``` php -v ``` You should see the following output. ``` PHP 7.4.30 (cli) (built: Jun 7 2022 08:38:19) ( NTS ) Copyright (c) The PHP Group Zend Engine v3.4.0, Copyright (c) Zend Technologies with Zend OPcache v7.4.30, Copyright (c), by Zend Technologies ``` ## Install PHP 5.6 First, reset the PHP default module with the following command. ``` dnf module reset php -y ``` Next, install PHP 5.6 with the following command. ``` dnf --enablerepo=remi install php56 ``` After the installation, you can verify the PHP installation using the following command. ``` php56 -v ``` You should see the following output. ``` PHP 5.6.40 (cli) (built: Jun 7 2022 00:00:00) Copyright (c) 1997-2016 The PHP Group Zend Engine v2.6.0, Copyright (c) 1998-2016 Zend Technologies ``` ## Install PHP Extensions You can also install some required PHP extensions with the following command. ``` dnf install -y php-mysqlnd php-gd php-curl php-json -y ``` You can verify the installed PHP extensions using the following command. ``` php -m | grep -i mysql ``` You should see the following output. ``` mysqli mysqlnd pdo_mysql ``` ## Conclusion This tutorial showed you how to install PHP 5.6, 7.4, 8.0, and 8.1 on Fedora 34. You can now easily install any PHP version on your server as per your needs. Try to install PHP on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Atlantic.Net honored as Bronze Stevie® award winner in the 2023 American Business Awards® > URL: https://www.atlantic.net/press-releases/atlantic-net-honored-as-bronze-stevie-award-winner-in-cloud-platform-2023-american-business-awards/ | Published: 2023-06-07 | Updated: 2023-09-05 | Author: Editorial Team **Stevie winners will be presented their awards on June 13 in New York** ORLANDO, FLORIDA – June 7, 2023 – Atlantic.Net, Inc. was named the winner of a BRONZE Stevie® Award in the Cloud Platform category in the 21st Annual American Business Awards® today. The American Business Awards are the U.S.A.’s premier business awards program. All organizations operating in the U.S.A. are eligible to submit nominations – public and private, for-profit, and non-profit, large and small. Nicknamed the Stevies for the Greek word meaning “crowned,” the awards will be presented to winners at a gala ceremony at the Marriott Marquis Hotel in New York on Tuesday, June 13. Tickets are now on sale. More than 3,700 nominations from organizations of all sizes and in virtually every industry were submitted this year for consideration in a wide range of categories, including Startup of the Year, Executive of the Year, Best New Product or Service of the Year, Marketing Campaign of the Year, Thought Leader of the Year, and App of the Year, among others. Atlantic.Net, Inc. was nominated in the Cloud Platform category for their exceptional Cloud Platform. Atlantic.Net has shown remarkable innovation and excellence in the cloud platform category, leading the industry with their focus on security, compliance, and simplifying the user experience. Judges praised Atlantic.Net’s commitment to providing business-class dedicated and cloud hosting solutions, backed by 24/7/365 support through their global data centers. “It’s an honor to be recognized for our contributions to the cloud industry,” said Marty Puranik, CEO of Atlantic.Net. “This award is a testament to the hard work and dedication of our team, and we’re excited to continue delivering the best cloud solutions for businesses around the world.” More than 230 professionals worldwide participated in the judging process to select this year’s Stevie Award winners. “It is very gratifying for us to be able to recognize the achievements of such a wide variety of organizations, teams, and individuals in the 21st ABAs, and we look forward to bringing them together in New York on June 13 to celebrate with them,” said Maggie Miller, president of the Stevie Awards. Details about The American Business Awards and the list of 2023 Stevie winners are available at www.StevieAwards.com/ABA. **About Atlantic.Net ** Atlantic.Net is a global cloud services provider with over 29 years of experience, specializing in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions, backed by 24/7/365 support through their global data centers located in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. **About the Stevie Awards** Stevie Awards are conferred in eight programs: the Asia-Pacific Stevie Awards, the German Stevie Awards, the Middle East & North Africa Stevie Awards, The American Business Awards®, The International Business Awards®, the Stevie Awards for Women in Business, the Stevie Awards for Great Employers, and the Stevie Awards for Sales & Customer Service. Stevie Awards competitions receive more than 12,000 entries each year from organizations in more than 70 nations. Honoring organizations of all types and sizes and the people behind them, the Stevies recognize outstanding performances in the workplace worldwide. Learn more about the Stevie Awards at www.StevieAwards.com. **Sponsors of the 2023 American Business Awards include HCL America, Melissa Sones Consulting, and SoftPro.** ### Atlantic.Net, Inc. Media Inquiries: Contact: Email: [pr@atlantic.net](mailto:pr@atlantic.net) Ph: 1-321- 206-1371**** --- # How to Install Magento on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-magento-on-fedora/ | Published: 2023-06-07 | Updated: 2026-06-11 | Author: Hitesh Jethva Magento is an open-source e-commerce software platform written in PHP. It helps online merchants to create a flexible shopping cart system with ease. It is a highly customizable and resource-intensive application for medium to large stores. Magento is simple and user-friendly, so beginner users can host a fully-functional online shopping cart system without any programming knowledge. This post will show you how to install [Magento Hosting](https://www.mgt-commerce.com/magento-hosting/) on Fedora. ## Step 1 – Install the LAMP Server First, install the Apache web server package using the following command. ``` dnf install httpd -y ``` By default, PHP 8.1 is not included in the Fedora 34 default repo, so you will need to install the PHP Remi repository on your server. You can install it with the following command. ``` dnf install -y http://rpms.remirepo.net/fedora/remi-release-34.rpm ``` Next, enable the Remi repository with the following command. ``` dnf module install php:remi-8.1 ``` Next, install PHP and other required extensions using the following command. ``` dnf install php-mysqlnd php-xml php-cli php-soap php-opcache php-iconv php-pear php-bcmath php-gd php-mbstring php-json php-devel unzip wget -y yum --enablerepo=remi install php-intl php-sodium php-zip ``` Next, edit the PHP configuration file and change some default settings. ``` nano /etc/php.ini ``` Change the following values: ``` memory_limit = 1024M upload_max_filesize = 256M zlib.output_compression = on max_execution_time = 300 date.timezone = UTC ``` Save and close the file, then start and enable the Apache service using the following command. ``` systemctl start httpd systemctl enable httpd ``` ## Step 2 – Install and Configure MySQL Server First, install the MySQL server repository using the following command. ``` rpm -ivh https://dev.mysql.com/get/mysql80-community-release-fc34-2.noarch.rpm rpm --import https://repo.mysql.com/RPM-GPG-KEY-mysql-2022 ``` Next, install the MySQL server package using the following command. ``` dnf install mysql-community-server -y ``` Next, start and enable the MySQL service with the following command. ``` systemctl enable mysqld systemctl start mysqld ``` Next, retrieve the MySQL root password. ``` grep 'A temporary password is generated' /var/log/mysqld.log | tail -1 ``` You will get the root password in the following output. ``` 2023-04-22T12:41:00.940040Z 6 [Note] [MY-010454] [Server] A temporary password is generated for root@localhost: 3ak*CpiARf3L ``` Next, secure the MySQL installation and change the MySQL root password. ``` mysql_secure_installation ``` You will be asked to provide your existing MySQL root password. ``` Securing the MySQL server deployment. Enter password for user root: ``` Provide your root password and press the Enter key. You will be asked to set a new password. ``` The existing password for the user account root has expired. Please set a new password. New password: Re-enter new password: ``` Set your root password and press the Enter key to continue. You will be asked to remove the anonymous user, remove the test database, disallow root login, and reload the privileges table as shown below. ``` Remove anonymous users? (Press y|Y for Yes, any other key for No) : Y Disallow root login remotely? (Press y|Y for Yes, any other key for No) : Y Remove test database and access to it? (Press y|Y for Yes, any other key for No) : Y Reload privilege tables now? (Press y|Y for Yes, any other key for No) : Y ``` Now, log in to your MySQL as a root user. ``` mysql -u root -p ``` Next, create a database and user for Magento using the following command. ``` CREATE DATABASE magento; CREATE USER 'magento'@'localhost' IDENTIFIED BY 'Secur_&pas%3_sword'; ``` Next, grant all the privileges to the Magento database. ``` GRANT ALL ON magento.* TO 'magento'@'localhost'; ``` Next, flush the privileges and exit from the MariaDB shell: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download Magento First, install Composer using the following command. ``` curl -sS https://getcomposer.org/installer | php mv composer.phar /usr/local/bin/composer chmod +x /usr/local/bin/composer ``` Next, navigate to the Apache root directory and download the latest version of Magento with the following command. ``` cd /var/www/html composer create-project --repository-url=https://repo.magento.com/ magento/project-community-edition=2.4.5 magento2 ``` You will be asked to provide your Magento key and password to download it from their website. Next, change the ownership of the Magento directory. ``` chown -R apache:apache /var/www/html/magento2 ``` Next, navigate to the Magento directory and set all necessary permissions. ``` cd /var/www/html/magento2 find var generated vendor pub/static pub/media app/etc -type f -exec chmod g+w {} + find var generated vendor pub/static pub/media app/etc -type d -exec chmod g+ws {} + chown -R apache:apache . chmod u+x bin/magento ``` ## Step 4 – Configure Apache for Magento Next, create an Apache virtual host configuration file for Magento. ``` nano /etc/httpd/conf.d/magento.conf ``` Add the following configurations. ``` ServerAdmin admin@example.com ServerName magento.example.com DocumentRoot /var/www/html/magento2/ DirectoryIndex index.php Options Indexes FollowSymLinks MultiViews AllowOverride All Order allow,deny allow from all ErrorLog /var/log/httpd/magento_error.log CustomLog /var/log/httpd/magento_access.log combined ``` Save and close the file then restart the Apache service to apply the changes. ``` systemctl restart httpd ``` ## Step 5 – Install Magento First, navigate to the Magento directory and run the following command to install Magento on your server. ``` cd /var/www/html/magento2/ sudo -u apache bin/magento setup:install --admin-firstname="magento" --admin-lastname="admin" --admin-email="admin@example.com" --admin-user="admin" --admin-password="Your_Secure@Password123" --db-name="magento" --db-host="localhost" --db-user="magento" --db-password="Secur_&pas%3_sword" --language=en_US --currency=USD --timezone=UTC --cleanup-database --base-url=http://"magento.example.com" ``` You will get the following error. ``` Could not validate a connection to Elasticsearch. No alive nodes found in your cluster ``` You will need to disable Elasticsearch to resolve this error. ``` sudo -u apache bin/magento module:disable {Magento_Elasticsearch,Magento_Elasticsearch6,Magento_Elasticsearch7} ``` Next, run the following command again to install Magento. ``` sudo -u apache bin/magento setup:install --admin-firstname="magento" --admin-lastname="admin" --admin-email="admin@example.com" --admin-user="admin" --admin-password="Your_Secure@Password123" --db-name="magento" --db-host="localhost" --db-user="magento" --db-password="Secur_&pas%3_sword" --language=en_US --currency=USD --timezone=UTC --cleanup-database --base-url=http://"magento.example.com" ``` Once the Magento is installed, you will get the following output. ``` [SUCCESS]: Magento installation complete. [SUCCESS]: Magento Admin URI: /admin_kroki9 Nothing to import. ``` Next, you must install the Magento cron module and disable the two-factor authentication module. ``` cd /var/www/html/magento2 sudo -u apache bin/magento cron:install sudo -u apache bin/magento module:disable Magento_TwoFactorAuth ``` ## Step 6 – Access Magento Web Interface Now, open your web browser and access the Magento web UI using the URL **http://magento.example.com//admin_kroki9.** You will be asked to provide a Magento admin username and password. ![magento login](https://www.atlantic.net/wp-content/uploads/2023/04/p1-16.png) Type your username, password and click on the **Login** button. You should see the Magento dashboard on the following screen. ![magento dashboard](https://www.atlantic.net/wp-content/uploads/2023/05/p2-2.png) ## Conclusion You learned how to install Magento with Apache on Fedora in this post. You can now start your online store using the Magento platform. You can now deploy Magento on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install FreePBX VoIP Solution Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-freepbx-voip-solution-fedora/ | Published: 2023-06-08 | Updated: 2023-11-23 | Author: Hitesh Jethva Free and open-source FreePBX is the world’s most popular communications software system for configuring, controlling, and managing Asterisk PBX software. It comes with a graphical user interface that helps beginner users to manage VOIP via a web browser. FreePBX offer includes lots of functionality including VoIP, PBX, Fax, IVR, voice-mail, and email functions. It is designed for application developers, students, hackers, systems integrators, and others who want to create custom solutions with Asterisk. In this post, we will show you how to install FreePBX on Fedora. ## Step 1 – Install Required Dependencies Before starting, you will need to install some dependencies required to build the FreePBX system. You can install all of them using the following command. ``` dnf update -y dnf -y groupinstall "Development Tools" dnf install -y gcc-c++ libedit-devel uuid-devel libuuid-devel autoconf automake libtool ncurses-devel sendmail sendmail-cf newt-devel libxml2-devel libtiff-devel gtk2-devel subversion kernel-devel git crontabs cronie cronie-anacron wget vim sqlite-devel net-tools gnutls-devel unixODBC ``` Next, you will also need to install the Jansson package on your system. You can compile it with the following command. ``` git clone https://github.com/akheron/jansson.git cd jansson autoreconf -i ./configure --prefix=/usr/ make make install ``` ## Step 2 – Install Asterisk Server Asterisk is a core part of any VOIP software, so you will need to download and compile it in your system. First, visit the Asterisk official download page and download the latest version of Asterisk using the following command. ``` wget http://downloads.asterisk.org/pub/telephony/asterisk/asterisk-20-current.tar.gz ``` Once the download is completed, extract the downloaded file using the following command. ``` tar xvfz asterisk-20-current.tar.gz ``` Next, navigate to the Asterisk directory and configure it with the following command. ``` cd asterisk-20.3.0 ./configure --libdir=/usr/lib64 ``` Output: ``` configure: Menuselect build configuration successfully completed .$$$$$$$$$$$$$$$=.. .$7$7.. .7$$7:. .$$:. ,$7.7 .$7. 7$$$$ .$$77 ..$$. $$$$$ .$$$7 ..7$ .?. $$$$$ .?. 7$$$. $.$. .$$$7. $$$$7 .7$$$. .$$$. .777. .$$$$$$77$$$77$$$$$7. $$$, $$$~ .7$$$$$$$$$$$$$7. .$$$. .$$7 .7$$$$$$$7: ?$$$. $$$ ?7$$$$$$$$$$I .$$$7 $$$ .7$$$$$$$$$$$$$$$$ :$$$. $$$ $$$$$$7$$$$$$$$$$$$ .$$$. $$$ $$$ 7$$$7 .$$$ .$$$. $$$$ $$$$7 .$$$. 7$$$7 7$$$$ 7$$$ $$$$$ $$$ $$$$7. $$ (TM) $$$$$$$. .7$$$$$$ $$ $$$$$$$$$$$$7$$$$$$$$$.$$$$$$ $$$$$$$$$$$$$$$$. configure: Package configured for: configure: OS type : linux-gnu configure: Host CPU : x86_64 configure: build-cpu:vendor:os: x86_64 : pc : linux-gnu : configure: host-cpu:vendor:os: x86_64 : pc : linux-gnu : ``` Next, run the following command to install additional modules. ``` make menuselect ``` You should see the following screen. **Core Sound Module** ![install core sound module](https://www.atlantic.net/wp-content/uploads/2023/06/install-core-sound-module.jpg) **MOH Module** ![install moh module](https://www.atlantic.net/wp-content/uploads/2023/06/install-moh-module.jpg) **Extra Sound Module** ![install extra sound module](https://www.atlantic.net/wp-content/uploads/2023/06/install-extra-sound-module.jpg) Use the up and down arrow keys to select and install all additional modules. Once you are done, click on the **Save and Exit** button to save the changes. Next, run the following command to install other required packages. ``` ./contrib/scripts/install_prereq install ./contrib/scripts/get_mp3_source.sh ``` Finally, install Asterisk using the following commands. ``` make make install ``` Next, generates an Asterisk configuration file using the following command. ``` make samples make config ldconfig ``` ## Step 3 – Configure Asterisk First, create a dedicated user and group for Asterisk. ``` groupadd asterisk useradd -r -d /var/lib/asterisk -g asterisk asterisk ``` Next, add the Asterisk user to the audio and dialout group. ``` usermod -aG audio,dialout asterisk ``` Next, set proper ownership to the Asterisk configuration directories. ``` chown -R asterisk.asterisk /etc/asterisk /var/{lib,log,spool}/asterisk /usr/lib64/asterisk ``` Next, edit the Asterisk configuration file. ``` nano /etc/sysconfig/asterisk ``` Uncomment and change the following line. ``` AST_USER="asterisk" AST_GROUP="asterisk" ``` Next, edit another configuration file. ``` nano /etc/asterisk/asterisk.conf ``` Uncomment and change the following line. ``` runuser = asterisk ; The user to run as. rungroup = asterisk ; The group to run as. ``` Save and close the file, then reload the systemd daemon to implement the changes. ``` systemctl daemon-reload ``` Next, start and enable the Asterisk service. ``` systemctl start asterisk systemctl enable asterisk ``` Next, verify the Asterisk connection with the following command. ``` asterisk -rvv ``` If everything is fine, you will get the following output. ``` Asterisk 20.3.0, Copyright (C) 1999 - 2022, Sangoma Technologies Corporation and others. Created by Mark Spencer Asterisk comes with ABSOLUTELY NO WARRANTY; type 'core show warranty' for details. This is free software, with components licensed under the GNU General Public License version 2 and other licenses; you are welcome to redistribute it under certain conditions. Type 'core show license' for details. ========================================================================= Running as user 'asterisk' Running under group 'asterisk' Connected to Asterisk 20.3.0 currently running on freepbx (pid = 112072) freepbx*CLI> ``` Now, exit from the Asterisk console. ``` exit ``` ## Step 4 – Install the LAMP Server Next, you will need to install Apache, MariaDB, and PHP on your server. You can install all of them using the following command. ``` dnf install mariadb mariadb-server httpd php php-pear php-cgi php-common php-curl php-mbstring php-gd php-mysqlnd php-gettext php-bcmath php-zip php-xml php-json php-process php-snmp ``` Next, edit the PHP configuration file and define max_upload size. ``` nano /etc/php.ini ``` Change the following line. ``` upload_max_filesize = 20M ``` Next, modify another PHP configuration using the following command. ``` sed -i 's/\(^memory_limit = \).*/\1128M/' /etc/php.ini sed -i 's/^\(User\|Group\).*/\1 asterisk/' /etc/httpd/conf/httpd.conf sed -i 's/AllowOverride None/AllowOverride All/' /etc/httpd/conf/httpd.conf sed -i 's/\(^user = \).*/\1asterisk/' /etc/php-fpm.d/www.conf sed -i 's/\(^group = \).*/\1asterisk/' /etc/php-fpm.d/www.conf sed -i 's/\(^listen.acl_users = \).*/\1apache,nginx,asterisk/' /etc/php-fpm.d/www.conf ``` Next, start and enable, Apache, MariaDB, and PHP-FPM services. ``` systemctl start php-fpm httpd mariadb systemctl enable php-fpm httpd mariadb ``` Next, install Node.js and NPM using the following command. ``` dnf install nodejs npm ``` ## Step 5 – Install and Configure FreePBX First, download the latest version of FreePBX from their official website. ``` wget http://mirror.freepbx.org/modules/packages/freepbx/freepbx-16.0-latest.tgz ``` Once the FreePBX is downloaded, extract the downloaded file. ``` tar vxfz freepbx-16.0-latest.tgz ``` Next, navigate to the FreePBX directory and stop the Asterisk service. ``` cd freepbx systemctl stop asterisk ``` Next, start the Asterisk service using the following command. ``` ./start_asterisk start ``` Next, install the FreePBX with the following command. ``` ./install --webroot=/var/www/html -n ``` You will see the following output. ``` Setting Permissions... Setting base permissions...Done in 1 seconds Setting specific permissions... 50724 [============================] Finished setting permissions Generating default configurations... Finished generating default configurations You have successfully installed FreePBX ``` Next, delete Firewall and install other packages with the following command. ``` fwconsole ma disablerepo commercial fwconsole ma installall fwconsole ma delete firewall ``` Next, reload and restart the fwconsole with the following command. ``` fwconsole reload fwconsole restart ``` ## Step 6 – Create a Systemd Service for FreePBX Next, create a systemd service for FreePBX with the following command. ``` nano /etc/systemd/system/freepbx.service ``` Add the following configuration. ``` [Unit] Description=FreePBX VoIP Server After=mariadb.service [Service] Type=oneshot RemainAfterExit=yes ExecStart=/usr/sbin/fwconsole start -q ExecStop=/usr/sbin/fwconsole stop -q [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable FreePBX with the following command. ``` systemctl start freepbx systemctl enable freepbx ``` You can verify the status of FreePBX using the following command. ``` systemctl status freepbx ``` Output. ``` ● freepbx.service - FreePBX VoIP Server Loaded: loaded (/etc/systemd/system/freepbx.service; disabled; vendor preset: disabled) Active: active (exited) since Mon 2023-06-05 11:56:26 EDT; 6s ago Process: 129579 ExecStart=/usr/sbin/fwconsole start -q (code=exited, status=0/SUCCESS) Main PID: 129579 (code=exited, status=0/SUCCESS) CPU: 19.129s Jun 05 11:56:23 freepbx runuser[129849]: pam_unix(runuser:session): session closed for user asterisk Jun 05 11:56:23 freepbx runuser[129860]: pam_unix(runuser:session): session opened for user asterisk(uid=992) by (uid=0) Jun 05 11:56:24 freepbx runuser[129860]: pam_unix(runuser:session): session closed for user asterisk Jun 05 11:56:24 freepbx runuser[129887]: pam_unix(runuser:session): session opened for user asterisk(uid=992) by (uid=0) Jun 05 11:56:24 freepbx runuser[129887]: pam_unix(runuser:session): session closed for user asterisk Jun 05 11:56:24 freepbx runuser[129919]: pam_unix(runuser:session): session opened for user asterisk(uid=992) by (uid=0) Jun 05 11:56:25 freepbx runuser[129919]: pam_unix(runuser:session): session closed for user asterisk Jun 05 11:56:25 freepbx runuser[129942]: pam_unix(runuser:session): session opened for user asterisk(uid=992) by (uid=0) Jun 05 11:56:26 freepbx runuser[129942]: pam_unix(runuser:session): session closed for user asterisk Jun 05 11:56:26 freepbx systemd[1]: Finished FreePBX VoIP Server. ``` ## Step 7 – Access FreePBX Web UI Now, open your web browser and access the FreePBX web interface using the URL **http://your-server-ip.** You should see the FreePBX configuration page. ![freepbx initial setup](https://www.atlantic.net/wp-content/uploads/2023/06/freepbx-initial-setup.jpg) Set your admin user account and click on the **Setup System** button. You should see the following screen: ![freepbx panel selection](https://www.atlantic.net/wp-content/uploads/2023/06/freepbx-panel-selection.jpg) Click on the **FreePBX Administration.** You should see the FreePBX login screen: ![freepbx login](https://www.atlantic.net/wp-content/uploads/2023/06/freepbx-login.jpg) Provide your admin username, password, and click on the **Continue** button. You should see the FreePBX dashboard on the following screen: ![freepbx dashboard](https://www.atlantic.net/wp-content/uploads/2023/06/freepbx-dashboard.jpg) ## Conclusion In this guide, we explained how to install FreePBX with Asterisk on Fedora. You can now deploy FreePBX in your local environment, build your own VOIP server, and start making free calls to other users. Try to install and deploy FreePBX on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How To Install Apache Maven On Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-maven-on-fedora/ | Published: 2023-06-08 | Updated: 2023-11-14 | Author: Hitesh Jethva Apache Maven is an open-source project management tool used for managing Java projects. Using Maven, you can manage the project’s reporting, build, and documentation from a central place. It can also manage written projects in languages such as C#, Ruby, Scala, etc. It is based on the POM model and hosted by the Apache Software Foundation. This post will show you how to install Apache Maven on Fedora. ## Step 1 – Install Java JDK Apache Maven is a Java-based software, so Java must be installed on your server. If not installed, you can install it using the following command. ``` dnf install java-11-openjdk -y ``` After installing Java JDK, you can verify the Java installation using the following command. ``` java --version ``` You should see the Java version in the following output. ``` openjdk 11.0.15 2022-04-19 OpenJDK Runtime Environment 18.9 (build 11.0.15+10) OpenJDK 64-Bit Server VM 18.9 (build 11.0.15+10, mixed mode, sharing) ``` ## Step 2 – Download and Install Apache Maven First, visit the Apache Maven official website, pick the latest version of Maven, and download it with the following command. ``` wget https://dlcdn.apache.org/maven/maven-3/3.9.1/binaries/apache-maven-3.9.1-bin.tar.gz ``` Once the download is completed, extract the downloaded file with the following command. ``` tar -xvzf apache-maven-3.9.1-bin.tar.gz ``` Next, move the extracted directory to the /opt directory. ``` mv apache-maven-3.9.1 /opt/maven ``` ## Step 3 – Create an Environment Variable for Maven Next, you will need to create an environment variable file and define the path of the Maven. ``` nano /etc/profile.d/maven.sh ``` Add the following lines. ``` export M2_HOME=/opt/maven export PATH=${M2_HOME}/bin:${PATH} ``` Save and close the file, then activate the environment variable with the following command. ``` source /etc/profile.d/maven.sh ``` Now, verify the Apache Maven version with the following command. ``` mvn -version ``` You should see the Maven version in the following output. ``` Apache Maven 3.9.1 (2e178502fcdbffc201671fb2537d0cb4b4cc58f8) Maven home: /opt/maven Java version: 11.0.15, vendor: Red Hat, Inc., runtime: /usr/lib/jvm/java-11-openjdk-11.0.15.0.10-1.fc34.x86_64 Default locale: en_IN, platform encoding: UTF-8 OS name: "linux", version: "5.12.8-300.fc34.x86_64", arch: "amd64", family: "unix" ``` ## Step 4 – Create a Project Using Maven First, create a directory for the Maven project. ``` mkdir project ``` Next, navigate to the project directory and create a project using the following command. ``` cd project mvn archetype:generate -DgroupId=com.example.app \ -DartifactId=test-app \ -DarchetypeArtifactId=maven-archetype-quickstart \ -DinteractiveMode=false ``` You should see the following output. ``` [INFO] ---------------------------------------------------------------------------- [INFO] Using following parameters for creating project from Old (1.x) Archetype: maven-archetype-quickstart:1.0 [INFO] ---------------------------------------------------------------------------- [INFO] Parameter: basedir, Value: /root/project [INFO] Parameter: package, Value: com.example.app [INFO] Parameter: groupId, Value: com.example.app [INFO] Parameter: artifactId, Value: test-app [INFO] Parameter: packageName, Value: com.example.app [INFO] Parameter: version, Value: 1.0-SNAPSHOT [INFO] project created from Old (1.x) Archetype in dir: /root/project/test-app [INFO] ------------------------------------------------------------------------ [INFO] BUILD SUCCESS [INFO] ------------------------------------------------------------------------ [INFO] Total time: 7.381 s [INFO] Finished at: 2023-04-22T02:53:57-04:00 [INFO] ------------------------------------------------------------------------ ``` Next, navigate to the application directory and build a package for your project using the following command. ``` cd test-app mvn package ``` You should see the following output. ``` [INFO] Building jar: /root/project/test-app/target/test-app-1.0-SNAPSHOT.jar [INFO] ------------------------------------------------------------------------ [INFO] BUILD SUCCESS [INFO] ------------------------------------------------------------------------ [INFO] Total time: 6.213 s [INFO] Finished at: 2023-04-22T02:55:21-04:00 [INFO] ------------------------------------------------------------------------ ``` ## Conclusion In this post, we explained how to install Apache Maven on Fedora. You can now use Apache Maven with other programming languages and manage your project from the central location. In addition, you can now use Apache Maven on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install OpenNMS Monitoring Solution on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-opennms-monitoring-solution-on-fedora/ | Published: 2023-06-09 | Updated: 2024-06-04 | Author: Hitesh Jethva OpenNMS is a free, open-source, enterprise-grade network monitoring tool for Linux systems. It is used to visualize and monitor local as well as public networks via web browsers. It offers alarm generation, comprehensive fault, performance, and traffic monitoring from a single place. OpenNMS is customizable and can be integrated easily with other applications. If you are looking for a powerful and scalable monitoring solution, then OpenNMS is the right choice for you. In this post, we will show you how to install the OpenNMS monitoring server on Fedora. ## Step 1 – Install Java JDK OpenNMS is a Java-based application, so you will need Java installed on your server. You can install it using the following command. ``` dnf install java-11-openjdk-devel curl unzip -y ``` Once Java is installed, you can verify the Java version with the following command. ``` java -version ``` Output. ``` openjdk version "11.0.15" 2022-04-19 OpenJDK Runtime Environment 18.9 (build 11.0.15+10) OpenJDK 64-Bit Server VM 18.9 (build 11.0.15+10, mixed mode, sharing) ``` ## Step 2 – Install OpenNMS Server By default, the OpenNMS package is not included in the Fedora default repo, so you will need to install the OpenNMS repo on your server. Run the following command to install both the OpenNMS repo and key. ``` rpm --import https://yum.opennms.org/OPENNMS-GPG-KEY dnf install https://yum.opennms.org/repofiles/opennms-repo-stable-rhel8.noarch.rpm ``` Next, install the OpenNMS with the following command. ``` dnf install opennms -y ``` ## Step 3 – Configure PostgreSQL OpenNMS uses PostgreSQL as a database backend. By default, PostgreSQL will be installed automatically during the OpenNMS installation. First, initialize the PostgreSQL database. ``` postgresql-setup --initdb --unit postgresql ``` Output. ``` * Initializing database in '/var/lib/pgsql/data' * Initialized, logs are in /var/lib/pgsql/initdb_postgresql.log ``` Next, start and enable the PostgreSQL service. ``` systemctl start postgresql systemctl enable postgresql ``` Next, log in to PostgreSQL, create an OpenNMS user, and set a password. ``` su - postgres createuser -P opennms Enter password for new role: Enter it again: ``` Next, create an OpenNMS database and set a Postgres password. ``` createdb -O opennms opennms psql -c "ALTER USER postgres WITH PASSWORD 'password';" exit; ``` Next, edit the PostgreSQL configuration file. ``` nano /var/lib/pgsql/data/pg_hba.conf ``` Find the following lines: ``` # IPv4 local connections: host all all 127.0.0.1/32 ident # IPv6 local connections: host all all ::1/128 ident ``` And replace them with the following lines: ``` host all all 127.0.0.1/32 md5 host all all ::1/128 md5 ``` Save and close the file, then restart the PostgreSQL service to apply the changes. ``` systemctl restart postgresql ``` ## Step 4 – Configure OpenNMS Next, you will need to edit the OpenNMS configuration file and define your database. ``` nano /opt/opennms/etc/opennms-datasources.xml ``` Change the following configurations as per your database. ``` ``` Save and close the file, then check the Java environment. ``` /opt/opennms/bin/runjava -s ``` Output. ``` runjava: Looking for an appropriate JVM... runjava: Checking for an appropriate JVM in JAVA_HOME... runjava: Skipping... JAVA_HOME not set. runjava: Checking JVM in the PATH: "/usr/lib/jvm/java-11-openjdk-11.0.15.0.10-1.fc34.x86_64/bin/java"... runjava: Found an appropriate JVM in the PATH: "/usr/lib/jvm/java-11-openjdk-11.0.15.0.10-1.fc34.x86_64/bin/java" runjava: Value of "/usr/lib/jvm/java-11-openjdk-11.0.15.0.10-1.fc34.x86_64/bin/java" stored in configuration file. ``` Next, install the OpenNMS packages using the following command. ``` /opt/opennms/bin/install -dis ``` Next, start and enable the OpenNMS service. ``` systemctl enable --now opennms ``` You can now verify the OpenNMS service status using the following command. ``` systemctl status opennms ``` Output. ``` ● opennms.service - OpenNMS server Loaded: loaded (/usr/lib/systemd/system/opennms.service; enabled; vendor preset: disabled) Active: active (running) since Thu 2023-06-08 04:03:09 EDT; 5s ago Process: 4850 ExecStart=/opt/opennms/bin/opennms -s start (code=exited, status=0/SUCCESS) Process: 5806 ExecStartPost=/bin/sleep 3 (code=exited, status=0/SUCCESS) Main PID: 5807 (java) Tasks: 37 (limit: 2328) Memory: 175.7M CPU: 15.981s CGroup: /system.slice/opennms.service ├─5805 bash /opt/opennms/bin/opennms -s start └─5807 /usr/lib/jvm/java-11-openjdk-11.0.15.0.10-1.fc34.x86_64/bin/java --add-modules=java.base,java.compiler,java.datatransfer,java.desktop,java.instrume> Jun 08 04:03:11 fedora opennms[5807]: [INFO] Successfully loaded jicmp6 library. Jun 08 04:03:12 fedora opennms[5807]: [DEBUG] System property 'opennms.library.jicmp' set to '/usr/lib64/libjicmp.so. Attempting to load jicmp library from this locat> Jun 08 04:03:12 fedora opennms[5807]: [INFO] Successfully loaded jicmp library. Jun 08 04:03:12 fedora opennms[5807]: [DEBUG] System property 'opennms.library.jicmp6' set to '/usr/lib64/libjicmp6.so. Attempting to load jicmp6 library from this lo> Jun 08 04:03:12 fedora opennms[5807]: [INFO] Successfully loaded jicmp6 library. Jun 08 04:03:12 fedora opennms[5807]: [INFO] Using ICMP implementation: org.opennms.netmgt.icmp.best.BestMatchPinger Jun 08 04:03:12 fedora opennms[5807]: [INFO] IPv4 ICMP available? true Jun 08 04:03:12 fedora opennms[5807]: [INFO] IPv6 ICMP available? true Jun 08 04:03:12 fedora opennms[5807]: [INFO] Invocation doTestLoadLibraries successful for MBean OpenNMS:Name=TestLoadLibraries Jun 08 04:03:12 fedora opennms[5807]: [INFO] Invoking init on object OpenNMS:Name=Eventd ``` ## Step 5 – Access OpenNMS Dashboard At this point, OpenNMS is installed and listening on port 8980. You can check it with the following command. ``` ss -antpl | grep :8980 ``` Output. ``` LISTEN 0 50 *:8980 *:* users:(("java",pid=5807,fd=1193)) ``` Now, open your web browser and access the OpenNMS dashboard using the URL **http://your-server-ip:8980/opennms.** You should see the OpenNMS login page. ![opennms login](https://www.atlantic.net/wp-content/uploads/2023/06/a1.jpg) Provide the default username and password as admin/admin then click on the **Login** button. You should see the OpenNMS dashboard on the following screen. ![opennms dashboard](https://www.atlantic.net/wp-content/uploads/2023/06/a2.jpg) ## Conclusion Congratulations! You have successfully installed and configured the OpenNMS network monitoring tool on Fedora. You can now add your local and remote devices to the OpenNMS and start monitoring them via the OpenNMS dashboard. You can now easily install and implement OpenNMS on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Deploy TDengine on the Atlantic.Net Cloud Platform > URL: https://www.atlantic.net/vps-hosting/how-to-deploy-tdengine-on-the-atlantic-net-cloud-platform/ | Published: 2023-06-09 | Updated: 2024-12-05 | Author: Richard Bailey TDengine is a high-performance, distributed, scalable time-series database designed to handle large volumes of data in real-time. Developed by the TDengine team, this open-source software is optimized for IoT, industrial, and financial applications. TDengine provides features such as high-speed data insertion and querying, real-time data processing, SQL-based data analytics, and data compression. This procedure will provide a detailed guide to creating a TDengine database on an Ubuntu instance running on the Atlantic.Net Cloud Platform. ## Pre-requisites To create an Atlantic.Net account, you can follow these steps: 1. Go to the Atlantic.Net website at[Atlantic.Net](https://www.atlantic.net/) and click on the “Sign Up” button in the top right corner of the page. 2. On the sign-up page, fill in your information, including your name, email address, and password. You will also need to select a security question and provide an answer. 3. Review the terms and conditions and privacy policy, and then click on the “Create Account” button to submit your registration. 4. Once you have submitted your registration, you will receive an email from Atlantic.Net with a link to activate your account. Click on the link in the email to activate your account. 5. Once your account is activated, you can log in to the Atlantic.Net Cloud Control Panel to create and manage your cloud servers and other services. You may need to provide additional information, such as your billing information and verification documents, to complete your registration and start using Atlantic.Net services. ## Step 1 – Log in to your Atlantic.Net Account Click the following link to be directed to the [Login page](https://cloud.atlantic.net/?page=userlogin). Fill in your details to log in. ![](https://www.atlantic.net/wp-content/uploads/2023/06/1-ACP-login.png) ## Step 2 – Create an Ubuntu Instance on Atlantic.Net Now it’s time to build it; in this example, we will install **Ubuntu 22.04 LTS 64bit.** *Click on* the **“Add Server”** button to create a new cloud server. ![](https://www.atlantic.net/wp-content/uploads/2023/06/2-add-server.png) On the “Add a Server” page, *type a name* for your server. ![](https://www.atlantic.net/wp-content/uploads/2023/06/3-server-name.png) *Scroll down* to find the Ubuntu operating system and click the “**Ubuntu**” button to see the versions. We installed 22.04 LTS 64-bit; select it and continue. ![](https://www.atlantic.net/wp-content/uploads/2023/06/4-ubuntu-version.png) *Choose the region* that you want to use for your Ubuntu instance. In this example, we will use **USA-East-3** (Ashburn, VA). ![](https://www.atlantic.net/wp-content/uploads/2023/06/5-server-location.png) *Choose the payment term*: on-demand, one year, or three years. Various discounts are available, but we will choose **on-demand for added flexibility.** ![](https://www.atlantic.net/wp-content/uploads/2023/06/6-payment-term.png) *Choose the instance plan*. TDengine recommends at least 4GB RAM (more for production workloads). In this demo, we will choose the **G3.4GB plan.** ![](https://www.atlantic.net/wp-content/uploads/2023/06/7-instance-plan.png) You can also select *additional options*, such as backups and IPV6, and add your own SSH keys if needed. When you have selected everything you need, click the **“Create Server”** button. ![](https://www.atlantic.net/wp-content/uploads/2023/06/8-ssh-key.png) Wait about **30 seconds**for your server to be created. Once your server is ready, you can log in to it using SSH and start using it. The credentials are provided on screen and emailed to the primary email address on your account. ![](https://www.atlantic.net/wp-content/uploads/2023/06/9-tde-credentials.png) ## Step 3 – Enable SSH on your instance There are numerous ways to enable SSH on your server. To connect to the server, use a GUI SSH client, such as[PuTTY on Windows](https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html) or [iTerm2](https://iterm2.com/) on macOS. Download and install the client on your local machine, enter the server’s IP address and login credentials, and connect to the server. In this example, I will be using iTerm2 on macOS. ``` ssh username@server_ip_address ``` Replace *username* with your VPS username and *server_ip_address*with your VPS’s public IP address. ## Step 4 – Update OS and Prep System for TDEngine Update the Ubuntu package list by running the following command: ``` apt update -y ``` Install the prerequisite packages by running the following command: ``` apt install gcc cmake build-essential git libssl-dev libjansson-dev libsnappy-dev liblzma-dev libz-dev zlib1g pkg-config -y ``` *Note*: You will be prompted “which services should be restarted,” leave the default selected and select “ok.” ## Step 5 – Download and Install the TDEngine To keep things simple we will install TDEngine using the pre-made packages from the official documentation. Use wget to download the latest package. ``` wget https://www.tdengine.com/assets-download/3.0/TDengine-server-3.0.3.0-Linux-x64.tar.gz ``` ![](https://www.atlantic.net/wp-content/uploads/2023/06/10-wget.png) Untar the downloaded package. ``` tar -zxvf TDengine-server-3.0.3.0-Linux-x64.tar.gz ``` Navigate to the TDEngine folder and install. ``` cd TDengine-server-3.0.3.0/ ``` ``` ./install.sh ``` Note: When asked for an FQDN, just hit enter. You will be prompted to enter an email address. ![](https://www.atlantic.net/wp-content/uploads/2023/06/11-fqdn.png) Start and Enable the TAOS service. ``` systemctl start taosd ``` ``` systemctl enable taosd ``` Check the status of the TAOS service to ensure that it has been installed correctly. ``` systemctl status taosd ``` ![](https://www.atlantic.net/wp-content/uploads/2023/06/12-taos-status.png) ## Step 6 – Try out the TAOS CLI To access the command line interface, simply type: ``` taos ``` ![](https://www.atlantic.net/wp-content/uploads/2023/06/13-taos-cli.png) To create a database enter the following: ``` CREATE DATABASE atlanticdemo; USE atlanticdemo; CREATE TABLE t (ts TIMESTAMP, speed INT); INSERT INTO t VALUES ('2019-07-15 00:00:00', 10); INSERT INTO t VALUES ('2019-07-15 01:00:00', 20); SELECT * FROM t; ``` You will see this output: ![](https://www.atlantic.net/wp-content/uploads/2023/06/14-create-database.png) ## **Conclusion** In this tutorial, we explained how to install TDengine on Ubuntu Linux. We also showed you how to create a simple database using the TAOS CLI. You can now start exploring the possibilities of this superfast database. You can try to install TDEngine on[dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Reveal.js on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-reveal-js-on-fedora/ | Published: 2023-06-10 | Updated: 2023-11-18 | Author: Hitesh Jethva Reveal.js is a free and open-source HTML presentation framework that helps you make a beautiful presentation via a web browser. It uses open web technologies to make a presentation, change styles with CSS, include an external web page using an iframe, and use JavaScript API to add custom behavior. In this post, we will show you how to install Reveal.js on Fedora. ## Step 1 – Install Nodejs and NPM First, you will need to install Node.js and NPM packages on your server. You can install both packages with the following command. ``` dnf install nodejs npm -y ``` Once both packages are installed, you can verify the Node.js version with the following command. ``` node --version ``` ``` Output. ``` ``` v14.19.0 ``` ## Step 2 – Install Revealjs First, install the Git package using the following command. ``` dnf install git ``` Next, download the latest version of Reveal.js using the following command. ``` git clone https://github.com/hakimel/reveal.js.git ``` Next, navigate to the downloaded directory and install all required dependencies using the following command. ``` cd reveal.js npm install ``` Next, run the following command to run the Reveal.js application. ``` npm start ``` You will get the following output. ``` > reveal.js@4.5.0 start /root/reveal.js > gulp serve [05:18:41] Using gulpfile ~/reveal.js/gulpfile.js [05:18:41] Starting 'serve'... [05:18:41] Starting server... [05:18:41] Server started http://localhost:8000 [05:18:41] LiveReload started on port 35729 [05:18:41] Running server ``` Press the CTRL+C to stop the application. We will create a systemd service file to manage the application in the next section. ## Step 3 – Create a Systemd Service File for Revealjs Next, create a systemd unit file to manage the Reveal.js application. ``` nano /lib/systemd/system/reveal.service ``` Add the following code. ``` [Service] Type=simple User=root Restart=on-failure WorkingDirectory=/root/reveal.js ExecStart=npm start ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the Reveal service with the following command. ``` systemctl start reveal systemctl enable reveal ``` You can verify the active status of Reveal.js using the following command. ``` systemctl status reveal ``` Output. ``` ● reveal.service Loaded: loaded (/usr/lib/systemd/system/reveal.service; static) Active: active (running) since Sat 2023-05-20 05:19:14 EDT; 4s ago Main PID: 12825 (npm) Tasks: 22 (limit: 4666) Memory: 128.8M CPU: 5.232s CGroup: /system.slice/reveal.service ├─12825 npm └─12836 gulp serve May 20 05:19:14 fedora systemd[1]: Started reveal.service. May 20 05:19:15 fedora npm[12825]: > reveal.js@4.5.0 start /root/reveal.js May 20 05:19:15 fedora npm[12825]: > gulp serve May 20 05:19:18 fedora npm[12836]: [05:19:18] Using gulpfile ~/reveal.js/gulpfile.js May 20 05:19:18 fedora npm[12836]: [05:19:18] Starting 'serve'... May 20 05:19:18 fedora npm[12836]: [05:19:18] Starting server... May 20 05:19:18 fedora npm[12836]: [05:19:18] Server started http://localhost:8000 May 20 05:19:18 fedora npm[12836]: [05:19:18] LiveReload started on port 35729 May 20 05:19:18 fedora npm[12836]: [05:19:18] Running server ``` ## Step 4 – Configure Nginx for Revealjs Application At this point, the Reveal.js application is running and listening on localhost on port 8000, so you will need to configure Nginx as a reverse proxy to access the Reveal.js application from the remote machine. First, install the Nginx package using the following command. ``` dnf install nginx ``` Next, start and enable the Nginx service using the following command. ``` systemctl start nginx systemctl enable nginx ``` Next, create an Nginx virtual host configuration file. ``` nano /etc/nginx/conf.d/reveal.conf ``` Add the following configuration. ``` upstream reveal_backend { server localhost:8000; } server { listen 80; server_name reveal.example.com; location / { proxy_pass http://reveal_backend/; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forward-For $proxy_add_x_forwarded_for; proxy_set_header X-Forward-Proto http; proxy_set_header X-Nginx-Proxy true; proxy_redirect off; } } ``` Save and close the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after http{: ``` server_names_hash_bucket_size 64; ``` Save the file, then restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 5 – Access Revealjs Web UI Now, open your web browser and access the Reveal.js presentation using the URL **http://reveal.example.com.** You should see the Reveal.js default presentation on the following screen. ![revealjs dashboard](https://www.atlantic.net/wp-content/uploads/2023/05/revealjs-dashboard.jpg) ## Conclusion In this post, we explained how to install the Reveal.js presentation framework on Fedora. We also configured Nginx as a reverse proxy to access Reveal.js on the internet. Try to install Reveal.js on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install MySQL Server on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-mysql-server-on-fedora/ | Published: 2023-06-10 | Updated: 2023-11-14 | Author: Hitesh Jethva Free, open-source MySQL is one of the most popular database management systems. MySQL is used as a database backend for websites and web-based applications. It is very popular due to its stability, robustness, and ease of use. Also, MySQL is compatible with all major Linux operating systems, including Fedora, Debian, Ubuntu, CentOS, and more. It is primarily used with LAMP and LEMP stack to host web applications. This post will show you how to install MySQL server on Fedora. ## Step 1 – Add MySQL 8 Repository The MySQL 8 package is not included in the Fedora official repository by default, so you will need to create a MySQL repo in your server. You can create it by running the following command. ``` rpm -ivh https://dev.mysql.com/get/mysql80-community-release-fc34-2.noarch.rpm rpm --import https://repo.mysql.com/RPM-GPG-KEY-mysql-2022 ``` Next, verify the added repo using the following command. ``` dnf repolist all | grep mysql | grep enabled ``` You should see the MySQL repo in the following output. ``` mysql-connectors-community MySQL Connectors Community enabled mysql-tools-community MySQL Tools Community enabled mysql80-community MySQL 8.0 Community Server enabled ``` ## Step 2 – Install MySQL 8 You can now install the MySQL community server package using the following command. ``` dnf install mysql-community-server -y ``` Once MySQL is installed, start and enable the MySQL service using the following command. ``` systemctl enable mysqld systemctl start mysqld ``` Next, check the status of the MySQL service with the following command. ``` systemctl status mysqld ``` You should see the following output. ``` ● mysqld.service - MySQL Server Loaded: loaded (/usr/lib/systemd/system/mysqld.service; enabled; vendor preset: disabled) Active: active (running) since Sat 2023-04-22 03:19:40 EDT; 7s ago Docs: man:mysqld(8) http://dev.mysql.com/doc/refman/en/using-systemd.html Process: 7609 ExecStartPre=/usr/bin/mysqld_pre_systemd (code=exited, status=0/SUCCESS) Main PID: 7681 (mysqld) Status: "Server is operational" Tasks: 38 (limit: 4666) Memory: 455.2M CPU: 6.985s CGroup: /system.slice/mysqld.service └─7681 /usr/sbin/mysqld Apr 22 03:19:30 fedora systemd[1]: Starting MySQL Server... Apr 22 03:19:40 fedora systemd[1]: Started MySQL Server. ``` Next, verify the MySQL version with the following command. ``` mysqld --version ``` You will get the following output. ``` /usr/sbin/mysqld Ver 8.0.28 for Linux on x86_64 (MySQL Community Server - GPL) ``` ## Step 3 – Secure MySQL Installation The MySQL root password is set during the MySQL installation, you can retrieve it from its log file. ``` grep 'A temporary password is generated' /var/log/mysqld.log | tail -1 ``` You should see the MySQL root password in the following output. ``` 2023-04-22T07:19:33.946612Z 6 [Note] [MY-010454] [Server] A temporary password is generated for root@localhost: 3ksZatoy ``` Next, run the following script to secure the MySQL installation. ``` mysql_secure_installation ``` You will be asked to set a new MySQL password as shown below. ``` Securing the MySQL server deployment. Enter password for user root: ``` Provide your existing root password and press the Enter key. You will be prompted to set a new password. ``` The existing password for the user account root has expired. Please set a new password. New password: Re-enter new password: ``` Set your new password and press the Enter key. You will be asked to remove the anonymous user. ``` Remove anonymous users? (Press y|Y for Yes, any other key for No) : Y ``` Type Y and press the Enter key. You will be asked to disallow root login. ``` Disallow root login remotely? (Press y|Y for Yes, any other key for No) : Y ``` Type Y and press the Enter key. You will be asked to remove the test database. ``` Remove test database and access to it? (Press y|Y for Yes, any other key for No) : Y ``` Type Y and press the Enter key. You will be asked to reload the privileges table. ``` Reload privilege tables now? (Press y|Y for Yes, any other key for No) : Y ``` Type Y and press the Enter key to finish securing MySQL. ## Step 4 – Create a Database and User in MySQL First, log in to MySQL shell using the following command. ``` mysql -u root -p ``` Provide your root password to log in, then create a database and user using the following command. ``` CREATE DATABASE testdb; CREATE USER 'testuser'@'localhost' IDENTIFIED BY 'Your1_S@ecu&re*Pa(sswo)r-d'; ``` Next, grant all the privileges to testdb database with the following command. ``` GRANT ALL PRIVILEGES ON testdb.* TO testuser@localhost; ``` Next, flush the privileges and exit from MySQL using the following command. ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 5 – Uninstall MySQL Server To remove the MySQL server from your system, run the following command. ``` dnf remove mysql-community-server ``` Next, clear the package cache using the following command. ``` dnf clean all ``` Next, remove the MySQL data directory. ``` rm -rf /var/lib/mysql ``` ## Conclusion This tutorial showed you how to install MySQL 8 on Fedora. We also explained how to secure the MySQL installation, set a root password and create a database and user. You can now easily install and manage MySQL on your server. Try to install MySQL server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Java on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-java-on-fedora/ | Published: 2023-06-11 | Updated: 2023-11-14 | Author: Hitesh Jethva Free, open-source Java is one of the most popular programming languages in the world. It is used to build different software applications, including mobile, gaming, big data processing, embedded systems, and web-based applications. It is an object-oriented, multi-platform, and network-centric language and platform. This post will show you how to install Java on Fedora. ## Step 1 – Install Java OpenJDK By default, Java OpenJDK is available in the Fedora default repo. You can search the list of all available Java versions using the following command. ``` dnf search openjdk ``` You should see the following output. ``` java-1.8.0-openjdk-openjfx-slowdebug.x86_64 : OpenJDK x OpenJFX connector for packages with debugging on and no optimisation. his package adds symliks finishing Java FX : integration to java-1.8.0-openjdk-slowdebug java-1.8.0-openjdk-slowdebug.x86_64 : OpenJDK 8 Runtime Environment unoptimised with full debugging on java-1.8.0-openjdk-src.x86_64 : OpenJDK 8 Source Bundle java-1.8.0-openjdk-src-fastdebug.x86_64 : OpenJDK 8 Source Bundle for packages with debugging on and optimisation java-1.8.0-openjdk-src-slowdebug.x86_64 : OpenJDK 8 Source Bundle for packages with debugging on and no optimisation java-11-openjdk.x86_64 : OpenJDK 11 Runtime Environment java-11-openjdk.i686 : OpenJDK 11 Runtime Environment java-11-openjdk-demo.x86_64 : OpenJDK 11 Demos java-11-openjdk-demo-fastdebug.x86_64 : OpenJDK 11 Demos optimised with full debugging on java-11-openjdk-demo-slowdebug.x86_64 : OpenJDK 11 Demos unoptimised with full debugging on java-11-openjdk-devel.i686 : OpenJDK 11 Development Environment java-11-openjdk-devel.x86_64 : OpenJDK 11 Development Environment java-latest-openjdk-src-slowdebug.x86_64 : OpenJDK 18 Source Bundle for packages with debugging on and no optimisation java-latest-openjdk-static-libs.x86_64 : OpenJDK 18 libraries for static linking java-latest-openjdk-static-libs-fastdebug.x86_64 : OpenJDK 18 libraries for static linking optimised with full debugging on java-latest-openjdk-static-libs-slowdebug.x86_64 : OpenJDK 18 libraries for static linking unoptimised with full debugging on openjdk-asmtools-javadoc.noarch : Javadoc for openjdk-asmtools ======================================================================== Name Matched: openjdk ========================================================================= openjdk-asmtools.noarch : To develop tools create proper & improper Java '.class' files ======================================================================= Summary Matched: openjdk ======================================================================= icedtea-web.x86_64 : Additional Java components for OpenJDK - Java Web Start implementation ``` You can now install specific versions of Java OpenJDK to your system easily. For example, to install Java 11, run the following command. ``` dnf install java-11-openjdk -y ``` You can verify the Java version using the following command. ``` java --version ``` Output. ``` openjdk 11.0.15 2022-04-19 OpenJDK Runtime Environment 18.9 (build 11.0.15+10) OpenJDK 64-Bit Server VM 18.9 (build 11.0.15+10, mixed mode, sharing) ``` If you want to install Java 8, run the following command. ``` dnf install java-1.8.0-openjdk.x86_64 -y ``` To install the latest Java version, run the following command. ``` dnf install java-latest-openjdk -y ``` ## Step 2 – Set Java Default Version Java allows you to switch between multiple Java versions easily. Run the following command to set a default Java version. ``` alternatives --config java ``` You will be asked to set the default Java version as shown below. ``` There are 3 programs which provide 'java'. Selection Command ----------------------------------------------- *+ 1 java-11-openjdk.x86_64 (/usr/lib/jvm/java-11-openjdk-11.0.15.0.10-1.fc34.x86_64/bin/java) 2 java-1.8.0-openjdk.x86_64 (/usr/lib/jvm/java-1.8.0-openjdk-1.8.0.332.b09-1.fc34.x86_64/jre/bin/java) 3 java-latest-openjdk.x86_64 (/usr/lib/jvm/java-18-openjdk-18.0.1.0.10-1.rolling.fc34.x86_64/bin/java) Enter to keep the current selection[+], or type selection number: 3 ``` Type 3 and press the Enter key to set the Java latest version as the default version. Now, verify the newly set Java version with the following command. ``` java --version ``` You will get the following. ``` openjdk 18.0.1 2022-04-19 OpenJDK Runtime Environment 22.3 (build 18.0.1+10) OpenJDK 64-Bit Server VM 22.3 (build 18.0.1+10, mixed mode, sharing) ``` ## Step 3 – Install Oracle Java To install Oracle Java, login to the Oracle Java website and download Java 16 to your server. After downloading Java 16, copy it to the Java directory. ``` cp jdk-16.0.2_linux-x64_bin.tar.gz /usr/local/java ``` Next, navigate to the Java directory and extract the downloaded file. ``` cd /usr/local/java tar xvzf jdk-16.0.2_linux-x64_bin.tar.gz ``` Next, edit the profile file and define the location of Java 16. ``` nano /etc/profile ``` Add the following lines. ``` JAVA_HOME=/usr/local/java/jdk-16.0.2 PATH=$PATH:$HOME/bin:$JAVA_HOME/bin export JAVA_HOME export PATH ``` Save and close the file, then reload the Java environment variable using the following command. ``` source /etc/profile ``` Next, set Oracle Java 16 as the default version with the following command. ``` update-alternatives --install "/usr/bin/java" "java" "/usr/local/java/jdk-16.0.2/bin/java" 1 update-alternatives --set java /usr/local/java/jdk-16.0.2/bin/java ``` Now, check the Java version with the following command. ``` java --version ``` You should see the Java version in the following output. ``` java 16.0.2 2021-07-20 Java(TM) SE Runtime Environment (build 16.0.2+7-67) Java HotSpot(TM) 64-Bit Server VM (build 16.0.2+7-67, mixed mode, sharing) ``` ## Conclusion This post showed you how to install Java OpenJDK and Oracle JDK on Fedora. We also explained how to switch between multiple Java versions. You can now use any Java version with your application easily. You can now deploy Java applications on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Atlantic.Net honored as Bronze Stevie® award winner in the 2023 American Business Awards® > URL: https://www.atlantic.net/press-releases/atlantic-net-honored-as-bronze-stevie-award-winner-in-2023-american-business-awards/ | Published: 2023-06-12 | Updated: 2024-06-05 | Author: Editorial Team **Stevie winners will be presented their awards on June 13 in New York** ORLANDO, FLORIDA – June 12, 2023 – Atlantic.Net, Inc. was named the winner of a BRONZE Stevie® Award in the Healthcare Technology Solution category in the 21st Annual American Business Awards® today. The American Business Awards are the U.S.A.’s premier business awards program. Atlantic.Net has been applauded for its remarkable strides in the healthcare technology sector, providing secure and compliant cloud hosting and storage solutions that meet the stringent requirements of the Health Insurance Portability and Accountability Act (HIPAA). Judges recognized Atlantic.Net’s dedication to security, compliance, and user experience as critical factors in their award-winning services. “We’re thrilled to be recognized for our commitment to advancing healthcare technology solutions,” said Marty Puranik, CEO of Atlantic.Net. “This award reinforces our dedication to providing secure and compliant cloud services that meet the needs of healthcare providers and patients alike.” More than 230 professionals worldwide participated in the judging process to select this year’s Stevie Award winners. “It is very gratifying for us to be able to recognize the achievements of such a wide variety of organizations, teams, and individuals in the 21st ABAs, and we look forward to bringing them together in New York on June 13 to celebrate with them,” said Maggie Miller, president of the Stevie Awards. **About Atlantic.Net ** Atlantic.Net is a global cloud services provider with over 29 years of experience, specializing in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions, backed by 24/7/365 support through their global data centers located in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. **About the Stevie Awards** Stevie Awards are conferred in eight programs: the Asia-Pacific Stevie Awards, the German Stevie Awards, the Middle East & North Africa Stevie Awards, The American Business Awards®, The International Business Awards®, the Stevie Awards for Women in Business, the Stevie Awards for Great Employers, and the Stevie Awards for Sales & Customer Service. Stevie Awards competitions receive more than 12,000 entries each year from organizations in more than 70 nations. Honoring organizations of all types and sizes and the people behind them, the Stevies recognize outstanding performances in the workplace worldwide. Learn more about the Stevie Awards at [www.StevieAwards.com](https://www.StevieAwards.com/). --- # How to Install Tomcat on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-tomcat-on-fedora/ | Published: 2023-06-12 | Updated: 2023-11-19 | Author: Hitesh Jethva Apache Tomcat is an open-source web server for hosting a Java-based application online. Tomcat offers a user-friendly web interface where users can easily deploy and manage Java applications. Apache Tomcat is written in Java and contributed to by developers worldwide. It is designed to handle dynamic Java-based web content using the HTTP protocol. This post will show you how to install Apache Tomcat on Fedora. ## Step 1 – Install Java JDK Apache Tomcat is based on Java, so you will require Java to be installed on your server. You can install Java OpenJDK 11 with the following command. ``` dnf update -y dnf install java-11-openjdk -y ``` After the installation, verify the Java version with the following command. ``` java --version ``` Output: ``` openjdk 11.0.15 2022-04-19 OpenJDK Runtime Environment 18.9 (build 11.0.15+10) OpenJDK 64-Bit Server VM 18.9 (build 11.0.15+10, mixed mode, sharing) ``` ## Step 2 – Install Apache Tomcat First, visit the Apache Tomcat official website and download the latest version of Tomcat using the following command. ``` wget https://dlcdn.apache.org/tomcat/tomcat-10/v10.1.8/bin/apache-tomcat-10.1.8.tar.gz ``` Once the download is finished, extract the downloaded file with the following command. ``` tar -xvzf apache-tomcat-10.1.8.tar.gz ``` Next, move the extracted directory to /opt with the following command. ``` mv apache-tomcat-10.1.8 /opt/tomcat ``` Next, create a group and user for Tomcat using the following command. ``` groupadd --system tomcat useradd -M -d /opt/tomcat -g tomcat tomcat ``` Next, change the ownership of Apache Tomcat: ``` chown -R tomcat:tomcat /opt/tomcat ``` ## Step 3 – Create a Systemd Service File for Tomcat Next, you must create a **systemd** service file to manage Tomcat via systemd. ``` nano /etc/systemd/system/tomcat.service ``` Add the following configurations. ``` [Unit] Description=Apache Tomcat 10 After=network.target syslog.target [Service] User=tomcat Group=tomcat Type=oneshot ExecStart=/opt/tomcat/bin/startup.sh ExecStop=/opt/tomcat/bin/shutdown.sh RemainAfterExit=yes [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to implement the changes. ``` systemctl daemon-reload ``` Next, start and enable the Tomcat service. ``` systemctl start tomcat systemctl enable tomcat ``` You can now check the Tomcat status using the following command. ``` systemctl status tomcat ``` Output. ``` ● tomcat.service - Apache Tomcat 10 Loaded: loaded (/etc/systemd/system/tomcat.service; disabled; vendor preset: disabled) Active: active (exited) since Sat 2023-04-22 03:28:40 EDT; 4s ago Process: 8379 ExecStart=/opt/tomcat/bin/startup.sh (code=exited, status=0/SUCCESS) Main PID: 8379 (code=exited, status=0/SUCCESS) Tasks: 34 (limit: 4666) Memory: 101.6M CPU: 5.147s CGroup: /system.slice/tomcat.service └─8393 /usr/bin/java -Djava.util.logging.config.file=/opt/tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager> Apr 22 03:28:40 fedora systemd[1]: Starting Apache Tomcat 10... Apr 22 03:28:40 fedora startup.sh[8379]: Tomcat started. Apr 22 03:28:40 fedora systemd[1]: Finished Apache Tomcat 10. ``` ## Step 4 – Create an Administrative User for Tomcat Next, you must create an admin user to access the Tomcat management interface. ``` nano /opt/tomcat//onf/tomcat-users.xml ``` Add the following lines above the last line: ``` ``` Save and close the file when you are finished. ## Step 5 – Allow Tomcat Remote Login By default, Tomcat is accessible only from the local host. You will need to enable remote access by editing the Tomcat configuration file. To allow remote access to the Manager app, edit the context.xml file. ``` nano /opt/tomcat/webapps/manager/META-INF/context.xml ``` Remove the following lines. ``` ``` To allow remote access to the Host Manager app, edit the context.xml file. ``` nano /opt/tomcat/webapps/host-manager/META-INF/context.xml ``` Remove the following lines. ``` ``` Save and close the file, then restart the Tomcat service to apply the changes. ``` systemctl restart tomcat ``` ## Step 6 – Access Tomcat Web Interface Now, open your web browser and access the Tomcat administrative interface using the URL **http://your-server-ip:8080.** You should see the following screen. ![Tomcat dashbaord](https://www.atlantic.net/wp-content/uploads/2023/04/p1-17.png) Click on the **Manager App.** You will be asked for authentication. ![Tomcat login](https://www.atlantic.net/wp-content/uploads/2023/05/p2-3.png) Provide a Tomcat admin username and password and click on the **Sign in** button. You should see the Manager App dashboard. ![Manager app dashboard](https://www.atlantic.net/wp-content/uploads/2023/05/p3-1.png) Click on the **Host Manager.** You should see the Host Manager dashboard on the following screen. ![host manager app](https://www.atlantic.net/wp-content/uploads/2023/05/p5-1.png) ## Conclusion In this tutorial, we explained how to install Tomcat 10 on Fedora. We also showed you how to enable Tomcat remote access. You can now easily create and deploy Java-based applications via the Tomcat web dashboard. You can try Tomcat on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install NextCloud on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-nextcloud-on-fedora/ | Published: 2023-06-13 | Updated: 2023-11-27 | Author: Hitesh Jethva Nextcloud is an open-source client-server software used for file hosting services. It is an alternate solution for DropBox, Google Drive, and IDrive. It allows you to access, share, and protect files, calendars, contacts, communication & more at home and in your enterprise. With Nextcloud, you can synchronize your data between multiple devices and exchange your information with several other users. Additionally, you have complete control over your data. This post will show you how to install Nextcloud on Fedora. ## Step 1 – Install Apache and PHP First, install Apache web server using the following command. ``` dnf install httpd -y ``` Next, add the Repi repository to install the latest PHP version. ``` dnf install -y http://rpms.remirepo.net/fedora/remi-release-34.rpm ``` Next, reset the default PHP module and enable the Remi repository with the following command. ``` dnf module reset php -y dnf module install php:remi-8.1 ``` Next, install PHP using the following command. ``` dnf install php php-gd php-curl php-dom php-xml php-simplexml php-mbstring php-json -y ``` Next, install other required PHP extensions using the following command. ``` yum --enablerepo=remi install php-intl php-zip ``` Finally, start and enable the Apache service using the following command. ``` systemctl enable --now httpd ``` ## Step 2 – Install and Configure MariaDB Database First, install MariaDB on your server. ``` dnf install mariadb mariadb-server -y ``` Next, start and enable the MariaDB service. ``` systemctl enable --now mariadb ``` Next, log in to the MariaDB shell with the following command. ``` mysql ``` Once you are connected, create a user and database for Nextcloud. ``` create database nextcloud; create user 'nextcloud'@'localhost' identified by 'password'; ``` Next, grant all the privileges on the Nextcloud database. ``` grant all privileges on nextcloud.* to 'nextcloud'@'localhost'; ``` Next, flush the privileges and exit from the MariaDB shell. ``` flush privileges; exit; ``` ## Step 3 – Download and Install Nextcloud First, download the latest version of Nextcloud using the following command. ``` wget https://download.nextcloud.com/server/releases/latest.tar.bz2 ``` Next, extract the downloaded file with the following command. ``` tar -xjf latest.tar.bz2 ``` Next, move the extracted directory to the Apache web root. ``` mv nextcloud /var/www/html/nextcloud ``` Next, create a data directory for Nextcloud. ``` mkdir /var/www/html/nextcloud/data ``` Next, change the ownership of Nextcloud. ``` chown -R apache:apache /var/www/html/nextcloud ``` ## Step 4 – Configure Apache for Nextcloud Next, create an Apache virtual server block to host Nextcloud on the web. ``` nano /etc/httpd/conf.d/nextcloud.conf ``` Add the following configurations. ``` ServerName nextcloud.example.com DocumentRoot /var/www/html/nextcloud ErrorLog /var/log/httpd/nextcloud_error.log CustomLog /var/log/httpd/nextcloud_requests.log combined Options +FollowSymlinks AllowOverride All Dav off SetEnv HOME /var/www/html/nextcloud SetEnv HTTP_HOME /var/www/html/nextcloud ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart httpd ``` ## Step 5 – Access Nextcloud Interface Now, open your web browser and access Nextcloud using the URL **http://nextcloud.example.com.** You should see the following screen. ![nextcloud configuration](https://www.atlantic.net/wp-content/uploads/2023/04/p1-18.png) Provide all required information and click on the **Install** button. Once the Nextcloud is installed, you should see the following screen. ![Nextcloud dashboard](https://www.atlantic.net/wp-content/uploads/2023/05/p3-2.png) ## Conclusion In this post, we explained how to install Nextcloud with Apache on Fedora. You can now install Nextcloud client software on your desktop or mobile device and then sync and share your data with other users. Try to install Nextcloud on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # HIPAA Compliance in the Age of Telemedicine: What You Need to Consider > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-in-the-age-of-telemedicine-what-you-need-to-consider/ | Published: 2023-06-14 | Updated: 2025-09-15 | Author: Richard Bailey The Healthcare Industry has traditionally been playing catchup in the cloud computing revolution. This is partly due to the complexities surrounding data governance, and the complexity of ensuring digitizing healthcare services align with the stringent rules of HIPAA-Compliance. Times are changing fast, and HIPAA-Compliance hosting services are helping to drastically reshape the healthcare world, with telemedicine leading the charge. As a result, healthcare services extend beyond the physical confines of clinics and hospitals. Although we saw during the Covid-19 pandemic how popular remote consultations and diagnosis at hospitals became, telemedicine promises unprecedented access to medical services for millions of individuals across the globe. However, the digital transformation of healthcare brings significant data security and privacy challenges. The Health Insurance Portability and Accountability Act (HIPAA) is at the forefront of these concerns, a critical regulatory requirement for healthcare providers in the digital age. ## **Understanding HIPAA Compliance in Telemedicine** [HIPAA compliance](https://www.hhs.gov/hipaa/index.html) is a cornerstone of healthcare data management, ensuring the privacy and security of patient information. HIPAA legislation requires healthcare providers and their associates to implement adequate safeguards to uphold the data integrity of electronic protected health information (ePHI). In telemedicine, HIPAA compliance encompasses a broad range of considerations, including the secure transmission and storage of patient data during video consultations, the management of electronic health records, and the handling of data from emerging technologies like wearable devices, IoT devices, and intelligent applications. ## **The Impact of Wearable Devices, Smart Apps, and Remote Patient Monitoring (RPM) on Data Security** Innovations in healthcare technology, such as wearable devices, smart apps, and RPM, are revolutionizing patient care. These tools allow healthcare providers to monitor patients’ health in real-time, offering the potential for earlier intervention, better disease management, and improved patient outcomes. However, these technologies also introduce significant data security considerations. Protecting this information becomes paramount as these devices collect, store, and transmit sensitive health data. Failure to comply with HIPAA regulations can lead to severe penalties, making it critical for healthcare providers to incorporate robust security measures into the architecture of these new technologies. ## **Ensuring Data Integrity and Protecting ePHI in Telemedicine** Protecting [ePHI](https://www.atlantic.net/hipaa-compliant-hosting/protecting-phi-cloud/) requires a multi-faceted approach. Data encryption, both during transmission and when stored, is an essential first step. Healthcare providers must also use secure communication platforms for telemedicine consultations to prevent unauthorized access to sensitive data. Regular risk assessments are another crucial data protection component, helping identify and address potential vulnerabilities proactively. Lastly, healthcare providers must prioritize training on HIPAA regulations and data security protocols to ensure all employees understand their role in protecting patient information. But HIPAA compliance is about more than just data security—it also requires ensuring data integrity. As a result, healthcare providers must ensure that ePHI remains accurate and consistent over its entire lifecycle. This can include implementing data validation processes, regularly backing up data to prevent loss, and creating audit trails to track any changes to information. ## **Best Practices for Achieving HIPAA Compliance in Telemedicine** Achieving HIPAA compliance in telemedicine is a continuous process that requires dedication to achieving best practices. These include conducting regular risk assessments to identify potential threats to data security, educating staff about HIPAA regulations and their role in data protection, and implementing robust access controls. To ensure that only those with a legitimate need can access patient data. It’s also essential to track data access and use monitoring systems to prevent data breaches. Regular updates and reviews of security policies and ongoing staff education and training are also vital in maintaining HIPAA compliance. Working with HIPAA-compliant vendors is equally important when choosing a telehealth partner. These vendors should have robust security measures to protect PHI and be willing to sign a Business Associate Agreement (BAA), as HIPAA requires. Beyond these, healthcare providers must also educate their patients about security best practices. Patients play an essential role in protecting their health information, especially in telemedicine, where much communication and data sharing happens outside the traditional healthcare setting. Therefore, patients should be informed about security best practices through various channels, such as videos, websites, or emails. ## **Atlantic.Net: Your Trusted Partner for HIPAA-Compliant Hosting Services** With the complexities of HIPAA compliance, healthcare providers often benefit from partnering with specialized service providers. Atlantic.Net is a trusted name in this domain, offering HIPAA-compliant hosting services tailored to the needs of healthcare providers. In addition, with a commitment to data security and privacy, Atlantic.Net provides HIPAA hosting services, ensuring that your patient’s data is always protected. Our engineers also conduct routine security audits to identify and address potential vulnerabilities, safeguarding your data from breaches. Our platform team secures the hosting platform to industry standards, providing a durable and feature-rich environment powered by cutting-edge technology, delivering unrivaled performance in both dedicated and cloud server configurations, all backed by a 100% uptime Service Level Agreement (SLA). Atlantic.Net offers HIPAA-compliant web hosting plans with ultra-fast data processing capabilities and high availability, featuring robust security measures, high performance, and guaranteed reliability for efficient health data management. Additionally, Atlantic.Net provides [HIPAA-compliant dedicated servers](https://www.atlantic.net/hipaa-compliant-hosting/should-you-choose-cloud-or-dedicated-hosting-for-hipaa-compliance/) for both Windows and Linux platforms. These offerings ensure compliance with the HIPAA Security Rule and offer discounted pricing based on term commitment​[1](https://www.atlantic.net/hipaa-compliant-hosting/)​. In the age of telemedicine, HIPAA compliance is a critical consideration for healthcare providers. The dynamic nature of digital health technologies and the evolving threat landscape make data security a challenging yet essential task. By understanding the nuances of HIPAA compliance in telemedicine, leveraging technology wisely, and following best practices, healthcare providers can ensure the secure management of patient data, maintain the trust of their patients, and uphold their commitment to care. --- # How to Install Apache Solr on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-solr-on-fedora/ | Published: 2023-06-15 | Updated: 2023-11-14 | Author: Hitesh Jethva Apache Solr is an open-source search platform written in Java. It offers many features, including full-text search, hit highlighting, faceted search, real-time indexing, dynamic clustering, database integration, and rich document handling. It is primarily used to serve data to users based on their queries. This post will show you how to install Apache Solr on Fedora. ## Step 1 – Install Java First, you will need to install Java JDK on your server. You can install it using the following command. ``` dnf install java-17-openjdk -y ``` Once Java is installed, you can verify the Java version with the following command. ``` java --version ``` You will get the Java version information in the following output. ``` openjdk 17.0.3 2022-04-19 OpenJDK Runtime Environment 21.9 (build 17.0.3+7) OpenJDK 64-Bit Server VM 21.9 (build 17.0.3+7, mixed mode, sharing) ``` ## Step 2 – Install Apache Solr First, download the latest version of Apache Solr from their official website. ``` wget https://dlcdn.apache.org/solr/solr/9.2.0/solr-9.2.0.tgz ``` Once the download is completed, you can extract it with the following command. ``` tar xzf solr-9.2.0.tgz solr-9.2.0/bin/install_solr_service.sh --strip-components=2 ``` Next, run the Solr installation script to install Apache Solr to your server. ``` bash ./install_solr_service.sh solr-9.2.0.tgz ``` Once Solr is installed, you will get the following output. ``` Solr process 2001 running on port 8983 { "solr_home":"/var/solr/data", "version":"9.2.0 92c5515e2918c22513f7aa527d6c6db943150fea - houston - 2023-03-20 20:30:42", "startTime":"2023-04-23T02:32:06.818Z", "uptime":"0 days, 0 hours, 0 minutes, 15 seconds", "memory":"66.5 MB (%13) of 512 MB"} ``` You can check the status of Apache Solr using the following command. ``` service solr status ``` You will see the following output. ``` Found 1 Solr nodes: Solr process 2001 running on port 8983 { "solr_home":"/var/solr/data", "version":"9.2.0 92c5515e2918c22513f7aa527d6c6db943150fea - houston - 2023-03-20 20:30:42", "startTime":"2023-04-23T02:32:06.818Z", "uptime":"0 days, 0 hours, 0 minutes, 50 seconds", "memory":"69.5 MB (%13.6) of 512 MB"} ``` ## Step 3 – Configure Apache Solr for Remote Access At this point, Apache Solr is installed and listening on port 8983 on localhost. You can check it with the following command. ``` ss -antpl | grep 8983 ``` You will see the following output. ``` LISTEN 0 50 [::ffff:127.0.0.1]:8983 *:* users:(("java",pid=2001,fd=48)) ``` Next, you will need to edit the Solr configuration file and allow remote access. ``` nano /etc/default/solr.in.sh ``` Change the following line. ``` SOLR_JETTY_HOST="0.0.0.0" ``` Save and close the file, then restart the Solr service to apply the changes. ``` service solr restart ``` ## Step 4 – Enable Solr Authentication By default, anyone can access Apache Solr without authentication, so it is a good idea to secure the Solr with a user and password. To enable the authentication, create a security.json file. ``` nano /var/solr/data/security.json ``` Add the following code. ``` { "authentication":{ "blockUnknown": true, "class":"solr.BasicAuthPlugin", "credentials":{"solr":"IV0EHq1OnNrj6gvRCwvFwTrZ1+z1oBbnQdiVC3otuq0= Ndd7LKvVBAaZIF0QAVi1ekCfAJXr1GGfLtRUXhgrF8c="}, "realm":"My Solr users", "forwardCredentials": false }, "authorization":{ "class":"solr.RuleBasedAuthorizationPlugin", "permissions":[{"name":"all", "role":"admin"}], "user-role":{"solr":"admin"} } } ``` This file creates the default admin user and password pairing of **solr:SolrRocks.** Finally, restart the Apache Solr service to apply the changes. ``` service solr restart ``` ## Step 5 – Access Apache Solr Now, open your web browser and access Apache Solr using the URL **http://your-server-ip:8983.** You should see the Apache Solr login page. ![Sorl login](https://www.atlantic.net/wp-content/uploads/2023/05/p2-4.png) Provide your admin username and password and click on the **Login** button. You should see the Apache Solr web interface on the following screen.   ![Apache solr login](https://www.atlantic.net/wp-content/uploads/2023/04/p1-19.png)   ## Conclusion Congratulations! You have successfully installed Apache Solr on Fedora. You can now integrate Apache Solr with your application to serve data to all users. Try to install Apache Solr on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Apache Kafka on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-kafka-on-fedora/ | Published: 2023-06-16 | Updated: 2023-11-16 | Author: Hitesh Jethva Apache Kafka is an open-source distributed event streaming platform developed by the Apache Software Foundation. It is written in Java and Scala and used for high-performance data pipelines and streaming analytics. Apache Kafka is a distributed message broker designed to handle large volumes of data. It is highly scalable and can run on one or more servers. This tutorial will show you how to install Apache Kafka on Fedora. ``` ``` ## Step 1 – Install Java OpenJDK First, install the Java JDK using the following commands. ``` dnf update -y ``` ``` dnf install java-11-openjdk -y ``` After installing Java, verify the Java installation with the following command. ``` java --version ``` Output. ``` openjdk 11.0.15 2022-04-19 OpenJDK Runtime Environment 18.9 (build 11.0.15+10) OpenJDK 64-Bit Server VM 18.9 (build 11.0.15+10, mixed mode, sharing) ``` ## Step 2 – Install Apache Kafka First, visit the Kafka official download page, pick the latest Kafka version, and run the following command to download it to your server. ``` wget https://downloads.apache.org/kafka/3.4.0/kafka_2.13-3.4.0.tgz ``` Next, extract the downloaded file using the following command. ``` tar xzf kafka_2.13-3.4.0.tgz ``` Next, move the extracted directory to /usr/local directory. ``` mv kafka_2.13-3.4.0 /usr/local/kafka ``` ## Step 3 – Create a Systemd Service File for Kafka Next, you must create a **systemd** service file to manage the Kafka service via systemd. First, create a Zookeeper service file. ``` nano /etc/systemd/system/zookeeper.service ``` Add the following configurations. ``` [Unit] Description=Apache Zookeeper server Documentation=http://zookeeper.apache.org Requires=network.target remote-fs.target After=network.target remote-fs.target [Service] Type=simple ExecStart=/usr/bin/bash /usr/local/kafka/bin/zookeeper-server-start.sh /usr/local/kafka/config/zookeeper.properties ExecStop=/usr/bin/bash /usr/local/kafka/bin/zookeeper-server-stop.sh Restart=on-abnormal [Install] WantedBy=multi-user.target ``` Save the file, then create a Kafka service file. ``` nano /etc/systemd/system/kafka.service ``` Add the following configurations. ``` [Unit] Description=Apache Kafka Server Documentation=http://kafka.apache.org/documentation.html Requires=zookeeper.service [Service] Type=simple Environment="JAVA_HOME=/usr/lib/jvm/jre-11-openjdk" ExecStart=/usr/bin/bash /usr/local/kafka/bin/kafka-server-start.sh /usr/local/kafka/config/server.properties ExecStop=/usr/bin/bash /usr/local/kafka/bin/kafka-server-stop.sh [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` ## Step 4 – Start Apache Kafka Now, start the Apache Kafka and Zookeeper services and enable them to start at system reboot. ``` systemctl start zookeeper systemctl start kafka systemctl enable zookeeper systemctl enable kafka ``` You can now check the status of Kafka using the following command. ``` systemctl status kafka ``` Output. ``` ● kafka.service - Apache Kafka Server Loaded: loaded (/etc/systemd/system/kafka.service; disabled; vendor preset: disabled) Active: active (running) since Sat 2023-04-22 23:21:35 EDT; 4s ago Docs: http://kafka.apache.org/documentation.html Main PID: 4830 (java) Tasks: 54 (limit: 4666) Memory: 306.7M CPU: 6.974s CGroup: /system.slice/kafka.service └─4830 /usr/lib/jvm/jre-11-openjdk/bin/java -Xmx1G -Xms1G -server -XX:+UseG1GC -XX:MaxGCPauseMillis=20 -XX:InitiatingHeapOccupancyPercent=35 -XX:+Explicit> Apr 22 23:21:40 fedora bash[4830]: [2023-04-22 23:21:40,176] INFO [ExpirationReaper-0-Heartbeat]: Starting (kafka.server.DelayedOperationPurgatory$ExpiredOperationReap> Apr 22 23:21:40 fedora bash[4830]: [2023-04-22 23:21:40,196] INFO [ExpirationReaper-0-Rebalance]: Starting (kafka.server.DelayedOperationPurgatory$ExpiredOperationReap> Apr 22 23:21:40 fedora bash[4830]: [2023-04-22 23:21:40,200] INFO Successfully created /controller_epoch with initial epoch 0 (kafka.zk.KafkaZkClient) Apr 22 23:21:40 fedora bash[4830]: [2023-04-22 23:21:40,223] INFO [GroupCoordinator 0]: Starting up. (kafka.coordinator.group.GroupCoordinator) Apr 22 23:21:40 fedora bash[4830]: [2023-04-22 23:21:40,244] INFO [GroupCoordinator 0]: Startup complete. (kafka.coordinator.group.GroupCoordinator) Apr 22 23:21:40 fedora bash[4830]: [2023-04-22 23:21:40,245] INFO Feature ZK node created at path: /feature (kafka.server.FinalizedFeatureChangeListener) Apr 22 23:21:40 fedora bash[4830]: [2023-04-22 23:21:40,300] INFO [TransactionCoordinator id=0] Starting up. (kafka.coordinator.transaction.TransactionCoordinator) Apr 22 23:21:40 fedora bash[4830]: [2023-04-22 23:21:40,309] INFO [MetadataCache brokerId=0] Updated cache from existing to latest FinalizedFeaturesAndEpoch(fe> Apr 22 23:21:40 fedora bash[4830]: [2023-04-22 23:21:40,327] INFO [TransactionCoordinator id=0] Startup complete. (kafka.coordinator.transaction.TransactionCoordinator) Apr 22 23:21:40 fedora bash[4830]: [2023-04-22 23:21:40,334] INFO [Transaction Marker Channel Manager 0]: Starting (kafka.coordinator.transaction.TransactionMarkerChan> ``` ## Step 5 – Create a Topic in Kafka At this point, Kafka is installed on your server. To test Kafka, create a topic named FedoraTopic. ``` cd /usr/local/kafka bin/kafka-topics.sh --create --bootstrap-server localhost:9092 --replication-factor 1 --partitions 1 --topic FedoraTopic ``` Next, verify your created topic using the following command. ``` ./bin/kafka-topics.sh --bootstrap-server=localhost:9092 --list ``` Output: ``` FedoraTopic ``` Now, execute the producer and type a few messages into the console to send to the server. ``` ./bin/kafka-console-producer.sh --broker-list localhost:9092 --topic FedoraTopic >Hi >How are you ``` Next, open another terminal and run the consumer to read data from the Kafka cluster and display messages to standard output. ``` ./bin/kafka-console-consumer.sh --bootstrap-server localhost:9092 --topic FedoraTopic --from-beginning Hi How are you ``` ## Conclusion In this post, we explained how to install Apache Kafka on Fedora. We also create a sample topic and show you how producer and consume work. You can now install Kafka on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Use PostgreSQL on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-postgresql-on-fedora/ | Published: 2023-06-17 | Updated: 2023-11-23 | Author: Hitesh Jethva PostgreSQL is a powerful, free, open-source relational database management software. It is very popular due to its reliability, stability, and support for open technical standards. It is versatile and expandable so that you can use it in various specialized use cases with a powerful extension ecosystem. If you want to create highly scalable computing environments in your organization, then PostgreSQL is the best option. This guide will show you how to install and use the PostgreSQL server on Fedora. ## Step 1 – Enable PostgreSQL Repo By default, Fedora provides a PostgreSQL version 13 via its default repo, so you must enable the PostgreSQL 14 repo in your server. First, reset the default PostgreSQL repo with the following command. ``` dnf update -y dnf module reset postgresql -y ``` Next, enable the PostgreSQL 14 repo with the following command. ``` dnf module enable postgresql:14 ``` You will see the following output. ``` Last metadata expiration check: 0:02:34 ago on Sunday 07 May 2023 04:12:57 AM. Dependencies resolved. ======================================================================================================================================================================== Package Architecture Version Repository Size ======================================================================================================================================================================== Enabling module streams: postgresql 14 Transaction Summary ======================================================================================================================================================================== Is this ok [y/N]: y Complete! ``` ## Step 2 – Install PostgreSQL 14 Now, run the following command to install PostgreSQL 14 on your server. ``` dnf install postgresql-server postgresql ``` After the installation, initialize the PostgreSQL database with the following command. ``` postgresql-setup --initdb ``` You will get the following output. ``` * Initializing database in '/var/lib/pgsql/data' * Initialized, logs are in /var/lib/pgsql/initdb_postgresql.log ``` ## Step 3 – Start PostgreSQL Service Now, start the PostgreSQL service and enable it to start at system reboot with the following command. ``` systemctl enable --now postgresql ``` You can now check the status of PostgreSQL with the following command. ``` systemctl status postgresql ``` You will get the following output. ``` ● postgresql.service - PostgreSQL database server Loaded: loaded (/usr/lib/systemd/system/postgresql.service; enabled; vendor preset: disabled) Active: active (running) since Sun 2023-05-07 04:16:16 EDT; 8s ago Process: 17972 ExecStartPre=/usr/libexec/postgresql-check-db-dir postgresql (code=exited, status=0/SUCCESS) Main PID: 17975 (postmaster) Tasks: 8 (limit: 4666) Memory: 15.8M CPU: 67ms CGroup: /system.slice/postgresql.service ├─17975 /usr/bin/postmaster -D /var/lib/pgsql/data ├─18002 postgres: logger ├─18004 postgres: checkpointer ├─18005 postgres: background writer ├─18006 postgres: walwriter ├─18007 postgres: autovacuum launcher ├─18008 postgres: stats collector └─18009 postgres: logical replication launcher May 07 04:16:16 fedora systemd[1]: Starting PostgreSQL database server... ``` You can check the PostgreSQL version with the following command. ``` postgres --version ``` Output: ``` postgres (PostgreSQL) 14.1 ``` By default, PostgreSQL runs on port 5432. You can check it with the following command. ``` ss -antpl | grep -i postmaster ``` Output. ``` LISTEN 0 244 127.0.0.1:5432 0.0.0.0:* users:(("postmaster",pid=17975,fd=7)) LISTEN 0 244 [::1]:5432 [::]:* users:(("postmaster",pid=17975,fd=6)) ``` ## Step 4 – Configure PostgreSQL for Remote Access By default, PostgreSQL is accessible only from the local system. You can allow remote access by editing the PostgreSQL configuration file. ``` nano /var/lib/pgsql/data/postgresql.conf ``` Change the following line: ``` listen_addresses = '*' ``` Save and close the file, then edit another configuration file. ``` nano /var/lib/pgsql/data/pg_hba.conf ``` Find the following lines: ``` # IPv4 local connections: host all all 127.0.0.1/32 ident # IPv6 local connections: host all all ::1/128 ident ``` Replace them with the next line: ``` # Accept from anywhere host all all 0.0.0.0/0 md5 ``` Save and close the file, then restart the PostgreSQL service to reload the changes. ``` systemctl restart postgresql ``` ## Step 5 – Set PostgreSQL Password By default, no password is assigned to the Postgres user. For security reasons, setting a strong password for the Postgres user is a good idea. First, log in to PostgreSQL with the following command. ``` su - postgres ``` Once logged in, set a password for the Postgres user. ``` psql -c "alter user postgres with password 'securepassword'" ``` Finally, exit from the Postgres Shell with the following command. ``` exit ``` ## Conclusion In this post, we explained how to install PostgreSQL 14 on Fedora. We also showed you how to enable PostgreSQL remote access and set a Postgres password. You can now try PostgreSQL on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Use SQLite on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-sqlite-on-fedora/ | Published: 2023-06-18 | Updated: 2023-11-22 | Author: Hitesh Jethva SQLite is a free, open-source, lightweight database engine written in C. It is a library for implementing a small, fast, self-contained, high-reliability, full-featured SQL database engine. Compared to other databases, SQLite engine is not a standalone process, and you will need to link it statically or dynamically as per your requirement. In this post, we will show you how to install SQLite from a source on Fedora. ## Step 1 – Remove SQLite Default Installation By default, SQLite is already installed on the Fedora server. However, the installed SQLite version is an outdated version, so removing the SQLite and installing it again from the source is better. First, verify the SQLite installed version with the following command. ``` sqlite3 --version ``` Output: ``` 3.34.1 2021-01-20 14:10:07 10e20c0b43500cfb9bbc0eaa061c57514f715d87238f4d835880cd846b9ealt1 ``` Next, remove the SQLite package using the following command. ``` dnf remove sqlite ``` ## Step 2 – Install SQLite from the Source First, install all the required packages needed to compile SQLite. ``` dnf -y groupinstall "Development Tools" ``` Next, download the latest version of SQLite from their official website. ``` wget https://www.sqlite.org/2023/sqlite-autoconf-3410200.tar.gz ``` Next, extract the downloaded file using the following command. ``` tar -xvzf sqlite-autoconf-3410200.tar.gz ``` Next, navigate to the extracted directory and configure it with the following command. ``` cd sqlite-autoconf-3410200 ./configure ``` Output: ``` checking for zlib.h... yes checking for library containing deflate... -lz checking for library containing system... none required checking that generated files are newer than configure... done configure: creating ./config.status config.status: creating Makefile config.status: creating sqlite3.pc config.status: executing depfiles commands config.status: executing libtool commands ``` Next, run the following command to compile and install SQLite to your server. ``` make make install ``` Output: ``` /usr/bin/mkdir -p '/usr/local/bin' /bin/sh ./libtool --mode=install /usr/bin/install -c sqlite3 '/usr/local/bin' libtool: install: /usr/bin/install -c sqlite3 /usr/local/bin/sqlite3 /usr/bin/mkdir -p '/usr/local/include' /usr/bin/install -c -m 644 sqlite3.h sqlite3ext.h '/usr/local/include' /usr/bin/mkdir -p '/usr/local/share/man/man1' /usr/bin/install -c -m 644 sqlite3.1 '/usr/local/share/man/man1' /usr/bin/mkdir -p '/usr/local/lib/pkgconfig' /usr/bin/install -c -m 644 sqlite3.pc '/usr/local/lib/pkgconfig' make[1]: Leaving directory '/root/sqlite-autoconf-3410200' ``` Next, create a symbolic link of SQLite binary. ``` ln -s /usr/local/bin/sqlite3 /usr/bin/ ``` Then, verify the SQLite version with the following command. ``` sqlite3 --version ``` Output: ``` 3.41.2 2023-03-22 11:56:21 0d1fc92f94cb6b76bffe3ec34d69cffde2924203304e8ffc4155597af0c191da ``` ## Step 3 – Create a Database and Table in SQLite First, create a new database using the following command. ``` sqlite3 mydb.db ``` Output: ``` SQLite version 3.41.2 2023-03-22 11:56:21 Enter ".help" for usage hints. sqlite> ``` Next, exit from the SQLite shell with the following command. ``` .exit ``` Next, change the database to mydb.db database and create a table named students using the following command. ``` sqlite3 mydb.db CREATE TABLE students (id INTEGER PRIMARY KEY, name TEXT, position TEXT); ``` Next, insert some rows in the created table. ``` INSERT INTO students (name, position) VALUES ('Hitesh Jethva', '12th'); INSERT INTO students (name, position) VALUES ('Jay Jethva', '10th'); INSERT INTO students (name, position) VALUES ('Vyom Jethva', '5th'); ``` You can now verify the inserted data using the following command. ``` SELECT * FROM students; ``` You will see all your data in the following output. ``` 1|Hitesh Jethva|12th 2|Jay Jethva|10th 3|Vyom Jethva|5th ``` ## Conclusion In this post, we showed you how to install SQLite from the source on Fedora. We also explained how to create a database and table in SQLite. You can now try SQLite on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install & Configure Firewalld Firewall on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-configure-firewalld-firewall-on-fedora/ | Published: 2023-06-19 | Updated: 2024-06-04 | Author: Hitesh Jethva Firewalld, a firewall daemon, is a tool for Linux-based operating systems. It is an alternative to iptables and implements persistent network traffic rules. Using Firewalld, you can control network traffic flow in and out of the Linux server. It provides a command line interface where users can add, remove and manage firewall rules. This post will show you how to install and use the Firewalld firewall tool on Fedora. ## Step 1 – Install Firewalld By default, the Firewalld package is included in the Fedora default repo. You can install it easily using the following command. ``` dnf install firewalld -y ``` After installing the Firewalld package, start the Firewalld service and enable it to start at system reboot with the following command: ``` systemctl start firewalld systemctl enable firewalld ``` To verify Firewalld’s running status, run the following command: ``` firewall-cmd --state ``` Output. ``` running ``` ## Step 2 – List Firewall Zones By default, Firewalld contains some zones. Each zone contains services and ports. You will need to assign an interface to each zone. To get a list of all available zones, run the following command. ``` firewall-cmd --get-zones ``` You will see the following output. ``` FedoraServer FedoraWorkstation block dmz drop external home internal nm-shared public trusted work ``` If you want to list default zones, run the following command. ``` firewall-cmd --get-default-zone ``` Output: ``` public ``` To see active zones, run the following command. ``` firewall-cmd --get-active-zones ``` ## Step 3 – Display Zone Information If you want to see the detailed information for any zone, run the following command. ``` firewall-cmd --info-zone public ``` Output: ``` public target: default icmp-block-inversion: no interfaces: sources: services: dhcpv6-client mdns ssh ports: protocols: forward: no masquerade: no forward-ports: source-ports: icmp-blocks: rich rules: ``` ## Step 4 – Set a Default Zone You can set any zone as a default zone using the following command. ``` firewall-cmd --set-default-zone=home ``` After setting up the default zone, you can verify it using the following command. ``` firewall-cmd --get-default-zone ``` ## Step 5 – List All Services There are many services available in Firewalld. You can get a list of all services using the following command. ``` firewall-cmd --get-services ``` Output: ``` RH-Satellite-6 RH-Satellite-6-capsule amanda-client amanda-k5-client amqp amqps apcupsd audit bacula bacula-client bb bgp bitcoin bitcoin-rpc bitcoin-testnet bitcoin-testnet-rpc bittorrent-lsd ceph ceph-mon cfengine cockpit collectd condor-collector ctdb dhcp dhcpv6 dhcpv6-client distcc dns dns-over-tls docker-registry docker-swarm dropbox-lansync elasticsearch etcd-client etcd-server finger foreman foreman-proxy freeipa-4 freeipa-ldap freeipa-ldaps freeipa-replication freeipa-trust ftp ganglia-client ganglia-master git grafana gre high-availability http https imap imaps ipp ipp-client ipsec irc ircs iscsi-target isns jenkins kadmin kdeconnect kerberos kibana klogin kpasswd kprop kshell kube-apiserver ldap ldaps libvirt libvirt-tls lightning-network llmnr managesieve matrix mdns memcache minidlna mongodb mosh mountd mqtt mqtt-tls ms-wbt mssql murmur mysql nbd nfs nfs3 nmea-0183 nrpe ntp nut openvpn ovirt-imageio ovirt-storageconsole ovirt-vmconsole plex pmcd pmproxy pmwebapi pmwebapis pop3 pop3s postgresql privoxy prometheus proxy-dhcp ptp pulseaudio puppetmaster quassel radius rdp redis redis-sentinel rpc-bind rquotad rsh rsyncd rtsp salt-master samba samba-client samba-dc sane sip sips slp smtp smtp-submission smtps snmp snmptrap spideroak-lansync spotify-sync squid ssdp ssh steam-streaming svdrp svn syncthing syncthing-gui synergy syslog syslog-tls telnet tentacle tftp tftp-client tile38 tinc tor-socks transmission-client upnp-client vdsm vnc-server wbem-http wbem-https wsman wsmans xdmcp xmpp-bosh xmpp-client xmpp-local xmpp-server zabbix-agent zabbix-server ``` ## Step 6 – Add Ports to Firewalld Zones You can easily add or remove ports to any Firewalld zones via the command line. For example, run the following command to add ports 8001 and 22 to the public zone. ``` firewall-cmd --zone=public --permanent --add-port=8001/tcp --add-port=22/tcp ``` Next, reload the Firewalld to implement the changes. ``` firewall-cmd --reload ``` You can verify the added ports using the following command: ``` firewall-cmd --info-zone public ``` Output: ``` public target: default icmp-block-inversion: no interfaces: sources: services: dhcpv6-client mdns ssh ports: 8001/tcp 22/tcp protocols: forward: no masquerade: no forward-ports: source-ports: icmp-blocks: rich rules: ``` Run the following command if you want to remove port 22 from the public zone. ``` firewall-cmd --zone=public --permanent --remove-port=22/tcp ``` ## Step 7 – Add Services to Firewalld Zones Run the following command to add an FTP service to the public zone. ``` firewall-cmd --zone=public --permanent --add-service=ftp ``` Next, reload the Firewalld daemon to apply the changes. ``` firewall-cmd --reload ``` To remove the added service, run the following command. ``` firewall-cmd --zone=public --permanent --remove-service=ftp ``` ## Step 8 – Enable IP Masquerading IP Masquerading is a method that allows hosts with a private IP address to communicate with the Internet via an Internet gateway. First, verify whether the IP Masquerading is enabled using the following command. ``` firewall-cmd --zone=public --query-masquerade ``` You should see the following output. ``` no ``` Next, enable the IP Masquerading for the public zone using the following command. ``` firewall-cmd --zone=public --add-masquerade ``` Next, reload the Firewalld daemon to apply the changes. ``` firewall-cmd --reload ``` To disable the IP masquerading, run the following command: ``` firewall-cmd --zone=public --remove-masquerade ``` ## Conclusion In this post, we showed you how to install Firewalld on Fedora. We also explained how to add and remove ports and services to Firewalld. You can now implement Firewalld on your server to protect it from DDoS attacks. You can also try Firewalld on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install WildFly Server on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-wildfly-server-on-fedora/ | Published: 2023-06-20 | Updated: 2023-11-25 | Author: Hitesh Jethva WildFly, also known as JBoss, is an open-source and lightweight application server for building Java applications. It is cross-platform and offers a web-based interface that makes managing and configuring WildFly via a web browser easier. It is based on pluggable subsystems and is designed to provide users with a fast and stable Java runtime environment. This post will show you how to install WildFly on Fedora. ## Step 1 – Install Java OpenJDK WildFly is a Java-based application, so Java JDK must be installed on your server. You can install it with the following command. ``` dnf install java-11-openjdk.x86_64 ``` Once Java JDK is installed, you can verify the Java installation using the following command. ``` java --version ``` You will see the following output. ``` openjdk 11.0.15 2022-04-19 OpenJDK Runtime Environment 18.9 (build 11.0.15+10) OpenJDK 64-Bit Server VM 18.9 (build 11.0.15+10, mixed mode, sharing) ``` ## Step 2 – Install WildFly and Configure First, visit the WildFly official website, copy the URL of the latest WildFly version, and download it using the following command. ``` wget https://github.com/wildfly/wildfly/releases/download/28.0.0.Final/wildfly-28.0.0.Final.zip ``` Once WildFly is downloaded, unzip the downloaded file with the following command. ``` unzip wildfly-28.0.0.Final.zip ``` Next, move the extracted directory to /opt. ``` mv wildfly-28.0.0.Final /opt/wildfly ``` Next, create a user and group for WildFly with the following command. ``` groupadd --system wildfly useradd -s /sbin/nologin --system -d /opt/wildfly -g wildfly wildfly ``` Next, create a WildFly configuration directory and copy all necessary files inside that directory. ``` mkdir /etc/wildfly cp /opt/wildfly/docs/contrib/scripts/systemd/wildfly.conf /etc/wildfly/ cp /opt/wildfly/docs/contrib/scripts/systemd/wildfly.service /etc/systemd/system/ cp /opt/wildfly/docs/contrib/scripts/systemd/launch.sh /opt/wildfly/bin/ ``` Next, change the permissions and ownership of the wildfly directory. ``` chmod +x /opt/wildfly/bin/launch.sh chown -R wildfly:wildfly /opt/wildfly ``` ## Step 3 – Start WildFly Server At this point, WildFly is installed and configured. Now, reload the systemd daemon using the following command. ``` systemctl daemon-reload ``` Next, start and enable the WildFly service with the following command. ``` systemctl start wildfly systemctl enable wildfly ``` You can now check the status of WildFly using the following command. ``` systemctl status wildfly ``` You will get the following output. ``` ● wildfly.service - The WildFly Application Server Loaded: loaded (/etc/systemd/system/wildfly.service; disabled; vendor preset: disabled) Active: active (running) since Sun 2023-05-07 03:40:18 EDT; 6s ago Main PID: 35612 (launch.sh) Tasks: 63 (limit: 4666) Memory: 174.3M CPU: 9.503s CGroup: /system.slice/wildfly.service ├─35612 /bin/bash /opt/wildfly/bin/launch.sh standalone standalone.xml 0.0.0.0 ├─35613 /bin/sh /opt/wildfly/bin/standalone.sh -c standalone.xml -b 0.0.0.0 └─35709 java -D[Standalone] -Xms64m -Xmx512m -XX:MetaspaceSize=96M -XX:MaxMetaspaceSize=256m -Djava.net.preferIPv4Stack=true -Djboss.modules.system.pkgs=o> ``` By default, WildFly listens on port 8080. You can check it with the following command. ``` ss -tunelp | grep 8080 ``` Output. ``` tcp LISTEN 0 4096 0.0.0.0:8080 0.0.0.0:* users:(("java",pid=35709,fd=496)) uid:993 ino:56961 sk:1003 cgroup:/system.slice/wildfly.service <-> ``` Now, open your web browser and access the WildFly test page using the URL **http://your-server-ip:8080.** You will see the WildFly test page on the following screen. ![Wildfly test page](https://www.atlantic.net/wp-content/uploads/2023/05/p1.jpg) ## Step 4 – Create an Administrator User Next, you must add an admin user to access the WildFly admin interface. You can create it with the following command. ``` /opt/wildfly/bin/add-user.sh ``` You should see the following output. ``` What type of user do you wish to add? a) Management User (mgmt-users.properties) b) Application User (application-users.properties) (a): ``` Just press the Enter key to create a management user. You will be asked to define your username and password: ``` Enter the details of the new user to add. Using realm 'ManagementRealm' as discovered from the existing property files. Username : adminuser Password recommendations are listed below. To modify these restrictions edit the add-user.properties configuration file. - The password should be different from the username - The password should not be one of the following restricted values {root, admin, administrator} - The password should contain at least 8 characters, 1 alphabetic character(s), 1 digit(s), 1 non-alphanumeric symbol(s) Password : Re-enter Password : What groups do you want this user to belong to? (Please enter a comma separated list, or leave blank for none)[ ]: About to add user 'adminuser' for realm 'ManagementRealm' Is this correct yes/no? yes Added user 'adminuser' to file '/opt/wildfly/standalone/configuration/mgmt-users.properties' Added user 'adminuser' to file '/opt/wildfly/domain/configuration/mgmt-users.properties' Added user 'adminuser' with groups to file '/opt/wildfly/standalone/configuration/mgmt-groups.properties' Added user 'adminuser' with groups to file '/opt/wildfly/domain/configuration/mgmt-groups.properties' ``` ## Step 5 – Allow WildFly Remote Access By default, the WildFly admin interface can be accessed only from the local host, so you must edit the WildFly startup script file and enable the remote access. ``` nano /opt/wildfly/bin/launch.sh ``` Change the following lines: ``` if [[ "$1" == "domain" ]]; then $WILDFLY_HOME/bin/domain.sh -c $2 -b $3 else $WILDFLY_HOME/bin/standalone.sh -c $2 -b $3 -bmanagement=0.0.0.0 fi ``` Save and close the file, then restart the WildFly service to apply the changes. ``` systemctl restart wildfly ``` ## Step 6 – Access WildFly Admin Interface Now, open your web browser and access the WildFly admin interface using the URL **http://your-server-ip:9990.** You should see the WildFly login page. ![wildfly login page](https://www.atlantic.net/wp-content/uploads/2023/05/p2-5.png) Provide your admin username, password and click on the **Login** button. You should see the WildFly dashboard on the following screen. ![wildfly dashboard](https://www.atlantic.net/wp-content/uploads/2023/05/p3.jpg) ## Conclusion In this post, we explained how to install WildFly on Fedora. You can now build and deploy a Java application in the production environment. Try to install WildFly on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Netbox on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-netbox-on-fedora/ | Published: 2023-06-21 | Updated: 2023-11-24 | Author: Hitesh Jethva Netbox is an IP address management and data center infrastructure management tool developed by the DigitalOcean team. It is built on the Django Python framework and designed to address the needs of network and infrastructure engineers. It has a simple and user-friendly interface where you can manage all devices, racks, and IP addresses from a central place. This post will show you how to install Netbox on Fedora. ## Step 1 – Install and Configure PostgreSQL Netbox uses PostgreSQL as a database backend, so you will need to install and configure PostgreSQL on your server. First, reset the default PostgreSQL repo and enable the PostgreSQL version 14 repo using the following command. ``` dnf update -y dnf module reset postgresql -y dnf module enable postgresql:14 ``` Next, install the PostgreSQL server using the following command. ``` dnf install postgresql-server postgresql ``` After the installation, initialize the PostgreSQL database with the following command. ``` postgresql-setup --initdb ``` Next, start and enable the PostgreSQL service with the following command. ``` systemctl enable --now postgresql ``` Next, edit the PostgreSQL configuration file: ``` nano /var/lib/pgsql/data/pg_hba.conf ``` Change the following lines: ``` host all all 127.0.0.1/32 md5 host all all ::1/128 md5 ``` Save the file, then restart the PostgreSQL using the following command. ``` systemctl restart postgresql ``` Next, log in to the PostgreSQL shell. ``` sudo -u postgres psql ``` Once logged in, set the Postgres password, and create a database and user with the following command. ``` ALTER USER postgres WITH PASSWORD 'securepassword'; CREATE DATABASE netboxdb; CREATE USER netbox WITH ENCRYPTED PASSWORD 'securepassword'; GRANT ALL PRIVILEGES ON DATABASE netboxdb TO netbox; \q ``` ## Step 2 – Install Redis Server Netbox also requires Redis to be installed on your server. You can install it with the following command. ``` dnf install redis -y ``` Once installed, start and enable the Redis service to start at system reboot. ``` systemctl start redis systemctl enable redis ``` ## Step 3 – Install and Configure Netbox First, install all the required dependencies using the following command. ``` dnf -y groupinstall "Development Tools" ``` Next, add a user for Netbox. ``` useradd -r -d /opt/netbox -s /usr/sbin/nologin netbox ``` Next, create a Netbox directory and download the latest Netbox version inside that directory. ``` mkdir -p /opt/netbox cd /opt/netbox git clone -b master --depth 1 https://github.com/netbox-community/netbox.git . ``` Next, change the ownership of the Netbox directory. ``` chown -R netbox:netbox /opt/netbox ``` Next, rename the Netbox configuration file and generate a secret key. ``` cd /opt/netbox/netbox/netbox sudo -u netbox cp configuration_example.py configuration.py sudo -u netbox python3 ../generate_secret_key.py ``` Output: ``` %ACU8k^7fR6Uk+aZiYfXtYmS&7cTor+tv1XB74eN#gs$%lGRu( ``` Next, edit the Netbox configuration file and define your database settings, allowed hosts, and secret key. ``` nano configuration.py ``` Change the following lines: ``` # domain and IP address ALLOWED_HOSTS = ['0.0.0.0', 'netbox.example.com'] # database configuration DATABASE = { 'NAME': 'netboxdb', # Database name 'USER': 'netbox', # PostgreSQL username 'PASSWORD': 'securepassword', # PostgreSQL password 'HOST': 'localhost', # Database server 'PORT': '', # Database port (leave blank for default) 'CONN_MAX_AGE': 300, # Max database connection age (seconds) } SECRET_KEY = '%ACU8k^7fR6Uk+aZiYfXtYmS&7cTor+tv1XB74eN#gs$%lGRu(' ``` Next, run the following command to create a virtual environment for Netbox. ``` sudo -u netbox /opt/netbox/upgrade.sh ``` Output: ``` WARNING: No existing virtual environment was detected. A new one has been created. Update your systemd service files to reflect the new Python and gunicorn executables. (If this is a new installation, this warning can be ignored.) netbox.service ExecStart: /opt/netbox/venv/bin/gunicorn netbox-rq.service ExecStart: /opt/netbox/venv/bin/python After modifying these files, reload the systemctl daemon: > systemctl daemon-reload -------------------------------------------------------------------- Upgrade complete! Don't forget to restart the NetBox services: > sudo systemctl restart netbox netbox-rq ``` ## Step 4 – Create a Superuser for Netbox Next, activate the Netbox virtual environment using the following command. ``` source /opt/netbox/venv/bin/activate ``` Next, create a superuser for Netbox. ``` cd /opt/netbox/netbox python3 manage.py createsuperuser ``` Define your Netbox admin user and password. ``` Username (leave blank to use 'root'): admin Email address: hitjethva@gmail.com Password: Password (again): Superuser created successfully. ``` Next, create a symbolic link of Netbox housekeeping. ``` ln -s /opt/netbox/contrib/netbox-housekeeping.sh /etc/cron.daily/netbox-housekeeping ``` Finally, deactivate from the virtual environment. ``` deactivate ``` ## Step 5 – Create a Systemd Service File for Netbox First, cop the Gunicorn configuration file. ``` cp /opt/netbox/contrib/gunicorn.py /opt/netbox/gunicorn.py ``` Next, copy all the service files from Netbox to the systemd directory. ``` cp -v /opt/netbox/contrib/*.service /etc/systemd/system/ ``` Next, reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the Netbox service using the following command. ``` systemctl start netbox netbox-rq systemctl enable netbox netbox-rq ``` You can now verify the status of the Netbox service with the following command. ``` systemctl status netbox netbox-rq ``` Output: ``` ● netbox.service - NetBox WSGI Service Loaded: loaded (/etc/systemd/system/netbox.service; disabled; vendor preset: disabled) Active: active (running) since Sun 2023-05-07 04:39:29 EDT; 11s ago Docs: https://docs.netbox.dev/ Main PID: 51952 (gunicorn) Tasks: 6 (limit: 4666) Memory: 408.1M CPU: 13.030s CGroup: /system.slice/netbox.service ├─51952 /opt/netbox/venv/bin/python3 /opt/netbox/venv/bin/gunicorn --pid /var/tmp/netbox.pid --pythonpath /opt/netbox/netbox --config /opt/netbox/gunicorn> ├─51954 /opt/netbox/venv/bin/python3 /opt/netbox/venv/bin/gunicorn --pid /var/tmp/netbox.pid --pythonpath /opt/netbox/netbox --config /opt/netbox/gunicorn> ├─51955 /opt/netbox/venv/bin/python3 /opt/netbox/venv/bin/gunicorn --pid /var/tmp/netbox.pid --pythonpath /opt/netbox/netbox --config /opt/netbox/gunicorn> ├─51956 /opt/netbox/venv/bin/python3 /opt/netbox/venv/bin/gunicorn --pid /var/tmp/netbox.pid --pythonpath /opt/netbox/netbox --config /opt/netbox/gunicorn> ├─51957 /opt/netbox/venv/bin/python3 /opt/netbox/venv/bin/gunicorn --pid /var/tmp/netbox.pid --pythonpath /opt/netbox/netbox --config /opt/netbox/gunicorn> └─51958 /opt/netbox/venv/bin/python3 /opt/netbox/venv/bin/gunicorn --pid /var/tmp/netbox.pid --pythonpath /opt/netbox/netbox --config /opt/netbox/gunicorn> May 07 04:39:29 fedora systemd[1]: Started NetBox WSGI Service. May 07 04:39:29 fedora gunicorn[51952]: [2023-05-07 04:39:29 -0400] [51952] [INFO] Starting gunicorn 20.1.0 May 07 04:39:29 fedora gunicorn[51952]: [2023-05-07 04:39:29 -0400] [51952] [INFO] Listening at: http://127.0.0.1:8001 (51952) May 07 04:39:29 fedora gunicorn[51952]: [2023-05-07 04:39:29 -0400] [51952] [INFO] Using worker: gthread May 07 04:39:29 fedora gunicorn[51954]: [2023-05-07 04:39:29 -0400] [51954] [INFO] Booting worker with pid: 51954 May 07 04:39:29 fedora gunicorn[51955]: [2023-05-07 04:39:29 -0400] [51955] [INFO] Booting worker with pid: 51955 May 07 04:39:30 fedora gunicorn[51956]: [2023-05-07 04:39:30 -0400] [51956] [INFO] Booting worker with pid: 51956 May 07 04:39:30 fedora gunicorn[51957]: [2023-05-07 04:39:30 -0400] [51957] [INFO] Booting worker with pid: 51957 May 07 04:39:30 fedora gunicorn[51958]: [2023-05-07 04:39:30 -0400] [51958] [INFO] Booting worker with pid: 51958 ● netbox-rq.service - NetBox Request Queue Worker Loaded: loaded (/etc/systemd/system/netbox-rq.service; disabled; vendor preset: disabled) Active: active (running) since Sun 2023-05-07 04:39:29 EDT; 11s ago Docs: https://docs.netbox.dev/ Main PID: 51953 (python3) Tasks: 3 (limit: 4666) Memory: 137.0M CPU: 6.628s CGroup: /system.slice/netbox-rq.service ├─51953 /opt/netbox/venv/bin/python3 /opt/netbox/netbox/manage.py rqworker high default low └─51961 /opt/netbox/venv/bin/python3 /opt/netbox/netbox/manage.py rqworker high default low May 07 04:39:29 fedora systemd[1]: Started NetBox Request Queue Worker. May 07 04:39:36 fedora python3[51953]: 08:39:36 Worker rq:worker:31d3dacea44b473cb9a5be6e63ab6480 started with PID 51953, version 1.14.1 May 07 04:39:36 fedora python3[51953]: 08:39:36 Subscribing to channel rq:pubsub:31d3dacea44b473cb9a5be6e63ab6480 May 07 04:39:36 fedora python3[51953]: 08:39:36 *** Listening on high, default, low... ``` ## Step 6 – Configure Nginx as a Reverse Proxy for Netbox Next, you must install and configure Nginx as a reverse proxy to access the Netbox from the remote machine. First, install the Nginx package using the following command. ``` dnf install nginx -y ``` Next, start and enable the Nginx service. ``` systemctl start nginx systemctl enable nginx ``` Next, create a Netbox virtual host configuration file. ``` nano /etc/nginx/conf.d/netbox.conf ``` Add the following configuration. ``` server { listen 80; server_name netbox.example.com; client_max_body_size 25m; location /static/ { alias /opt/netbox/netbox/static/; } location / { proxy_pass http://127.0.0.1:8001; proxy_set_header X-Forwarded-Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-Proto $scheme; } } ``` Next, edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after **http{:** ``` server_names_hash_bucket_size 64; ``` Save and close the file, then restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 7 – Access Netbox Web Interface Now, open your web browser and access the Netbox admin interface using the URL **http://netbox.example.com.** You should see the following page. ![netbox dashbaord](https://www.atlantic.net/wp-content/uploads/2023/05/p1-1.jpg) Click on the **login** button. You should see the Netbox Login page. ![netbox login page](https://www.atlantic.net/wp-content/uploads/2023/05/p2-6.png) Provide your admin username, password and click on the **Sign IN** button. You should see the Netbox dashboard on the following screen. ![netbox admin dashboard](https://www.atlantic.net/wp-content/uploads/2023/05/p3-1.jpg) ## Conclusion In this tutorial, we learned how to install Netbox on Fedora. We also learned to use Nginx as a reverse proxy to access the Netbox outside the network. You can now use Netbox in your organization to manage all devices from the central place. You can now try Netbox on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Use PIP Package Manager on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-pip-package-manager-on-fedora/ | Published: 2023-06-22 | Updated: 2024-06-04 | Author: Hitesh Jethva PIP is a Python package manager allowing you to install and manage packages not part of the Python standard library. All Python packages are hosted on an online repository called Python Package Index. PIP connects this repository, then downloads and installs Python packages to your system. PIP provides a simple and easiest way to install locally user-defined projects using a setup.py file. PIP is a command line utility that helps you to install, reinstall, or uninstall packages with a single command. This post will show you how to install and manage Python packages using PIP on Fedora. ## Install PIP on Fedora By default, the PIP package is not installed on Fedora, so you will need to install it first. You can install it using the following command. ``` dnf install python3-pip ``` Once the PIP package is installed, you can verify the PIP version with the following command. ``` pip3 --version ``` Output. ``` pip 21.0.1 from /usr/lib/python3.9/site-packages/pip (python 3.9) ``` It is also recommended to upgrade PIP to the latest version. You can upgrade it with the following command. ``` pip3 install --upgrade pip ``` Output. ``` Requirement already satisfied: pip in /usr/lib/python3.9/site-packages (21.0.1) Collecting pip Downloading pip-23.1.2-py3-none-any.whl (2.1 MB) |████████████████████████████████| 2.1 MB 12.6 MB/s Installing collected packages: pip Successfully installed pip-23.1.2 ``` Now, verify the PIP version again with the following command. ``` pip3 --version ``` Output: ``` pip 23.1.2 from /usr/local/lib/python3.9/site-packages/pip (python 3.9) ``` To see all available options of the PIP command, run the following command. ``` pip3 --help ``` Output. ``` Usage: pip3 [options] Commands: install Install packages. download Download packages. uninstall Uninstall packages. freeze Output installed packages in requirements format. inspect Inspect the python environment. list List installed packages. show Show information about installed packages. check Verify installed packages have compatible dependencies. config Manage local and global configuration. search Search PyPI for packages. cache Inspect and manage pip's wheel cache. index Inspect information available from package indexes. wheel Build wheels from your requirements. hash Compute hashes of package archives. completion A helper command used for command completion. debug Show information useful for debugging. help Show help for commands. ``` ## Manage Packages with PIP PIP provides a simple and easiest way to install and manage Python packages via the command line. For example, to install the scrapy package, run the following command. ``` pip3 install scrapy ``` To verify the package information, run the following command. ``` pip3 show scrapy ``` Output: ``` Name: Scrapy Version: 2.8.0 Summary: A high-level Web Crawling and Web Scraping framework Home-page: https://scrapy.org Author: Scrapy developers Author-email: pablo@pablohoffman.com License: BSD Location: /usr/local/lib/python3.9/site-packages Requires: cryptography, cssselect, itemadapter, itemloaders, lxml, packaging, parsel, protego, PyDispatcher, pyOpenSSL, queuelib, service-identity, setuptools, tldextract, Twisted, w3lib, zope.interface Required-by: ``` To get a list of all available packages, run the following command. ``` pip3 list ``` Output. ``` Package Version ------------------ --------- argcomplete 1.12.0 attrs 23.1.0 Automat 22.10.0 certifi 2022.12.7 cffi 1.15.1 charset-normalizer 3.1.0 constantly 15.1.0 cryptography 40.0.2 cssselect 1.2.0 dbus-python 1.2.16 decorator 4.4.2 distro 1.5.0 filelock 3.12.0 gpg 1.15.1 hyperlink 21.0.0 idna 3.4 incremental 22.10.0 itemadapter 0.8.0 itemloaders 1.1.0 jmespath 1.0.1 libcomps 0.1.15 lxml 4.9.2 nftables 0.1 ntpsec 1.2.0 packaging 23.1 parsel 1.8.1 pexpect 4.8.0 ``` To list all outdated packages, run the following command. ``` pip3 list --outdated ``` Output: ``` Package Version Latest Type --------------- ------- ------------ ----- argcomplete 1.12.0 3.0.8 wheel dbus-python 1.2.16 1.3.2 sdist decorator 4.4.2 5.1.1 wheel distro 1.5.0 1.8.0 wheel libcomps 0.1.15 0.1.15.post1 wheel ptyprocess 0.6.0 0.7.0 wheel PyGObject 3.40.1 3.44.1 sdist python-augeas 0.5.0 1.1.0 sdist python-dateutil 2.8.1 2.8.2 wheel setuptools 53.0.0 67.7.2 wheel six 1.15.0 1.16.0 wheel slip 0.6.4 20191113 sdist systemd-python 234 235 sdist ``` To install any package, run the following command. ``` pip3 uninstall scrapy ``` Output: ``` Found existing installation: Scrapy 2.8.0 Uninstalling Scrapy-2.8.0: Would remove: /usr/local/bin/scrapy /usr/local/lib/python3.9/site-packages/Scrapy-2.8.0.dist-info/* /usr/local/lib/python3.9/site-packages/scrapy/* Proceed (Y/n)? Y Successfully uninstalled Scrapy-2.8.0 ``` ## Conclusion This post explained how to install and manage Python packages with PIP. You can now use PIP in your development environment to install any Python dependency. You can now try PIP on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Setup SSH Key-Based Authentication on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-setup-ssh-key-based-authentication-on-fedora/ | Published: 2023-06-23 | Updated: 2024-06-04 | Author: Hitesh Jethva SSH is a secure shell protocol that provides secure login from one machine to another. Linux system administrators use it to manage and control remote servers via the command line. Public Key Authentication is a secure method to connect remote SSH servers using a public key instead of a password. It uses a cryptographic key pair for validation that helps prevent brute-force attacks. It helps the system administrator log in to many accounts without managing many different passwords. This post will show you how to set up SSH public key authentication on Fedora. ## Step 1 – Generate an SSH Public Key First, you must generate an SSH key pair on your local system to authenticate your remote server. Run the following command on your local Linux system to generate an SSH key pair. ``` ssh-keygen -t rsa ``` You will be asked to define a location to save the key pair. ``` Generating public/private rsa key pair. Enter file in which to save the key (/home/vyom/.ssh/id_rsa): /home/vyom/.ssh/id_rsa already exists. Overwrite (y/n)? y ``` Type Y, press the Enter key to save the key at the default location, and overwrite an existing key pair. You will be asked to set a passphrase for the key pair. ``` Enter passphrase (empty for no passphrase): Enter same passphrase again: ``` Just press Enter to continue. You should see the following output. ``` Your identification has been saved in /home/vyom/.ssh/id_rsa Your public key has been saved in /home/vyom/.ssh/id_rsa.pub The key fingerprint is: SHA256:i0kzweXQHdq6SjAGbvdroC8Nn601rfsEp/OnATLedJI vyom@ubuntupc The key's randomart image is: +---[RSA 3072]----+ | ...... | | . +.o. | | . o o . | | . . o . | | o B E S | | ..+.X & o | | =.+@ * | | o +ooO .. | | ooo=o+o | +----[SHA256]-----+ ``` The above command will generate SSH key pairs at /home/vyom/.ssh/id_rsa. ## Step 2 – Copy SSH Key to Remote Server Next, you must copy your generated public key to the remote server. There are many ways to copy an SSH key to the remote server. ### Copy SSH Key Using ssh-copy-id You can copy an SSH public key to the remote server using the ssh-copy-id command. ``` ssh-copy-id root@ssh-server ``` You will be asked to provide the root password of the remote machine to copy the public key. ``` root@104.245.35.103's password: Number of key(s) added: 2 Now try logging into the machine, with: "ssh 'root@104.245.35.103'" and check to make sure that only the key(s) you wanted were added. ``` ### Copy SSH Key Using SSH You can also use the SSH and cat command to copy the public key to the remote server. ``` cat ~/.ssh/id_rsa.pub | ssh root@ssh-server "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys" ``` ### Copy SSH Key Manually If you have not accessed the remote server via SSH, you can copy the content of the id_rsa.pub file to the ~/.ssh/authorized_keys file on a remote server. First, run the cat command on your local system to display the content of the id_rsa.pub file. ``` cat ~/.ssh/id_rsa.pub ``` Output. ``` ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDO4fELhgdYFQyh6Iox65p2q4HPRRlkkuX3ReNJ6vmONPgptJTwvB1YUjK1V8BDfj9JPtEUw0nSW668OVuLI0xceDOjVmmYgNBpgt8UlIxJlIIDqFjcXx/Yk3in+cK7aVRIgyFfmjMsQ0lghnZzrO35XncGqRU3xq8n8AGzTk82ZkxccpqVXOdjLN7DqdNLWa0hvz+mGmDCXqQra5hyi36RDbY5krwqvlgg2+nEWGfjspMdjLQaFbcOucmN0EBK2pMoDfUzZ3yAmiqoJswUj1H9u9Jk7/ASIpF7JaxIUrg6A8UI5qCkskPoWPKl8/b0vQmF7+e+bAdf9bsaZbj6Gq5yMkwBED8LitlMtytxE63wSbvaVOXWU3s8ULkHXOJ2L1iF3+H8oU/qM8D4FOBQ7Je1Ujtikye/YtF0dFDx+kfv2gAYRgauCReIQXNc/2/dN3E/kW/7/EtOHATip9CWROtVVsdwPL8ayPaZ4J05UZVx74B9USCLDXbGtiCTUs5PP3k= vyom@ubuntupc ``` Next, copy the above content then login to your remote server, and create a .ssh directory; ``` mkdir -p ~/.ssh ``` Next, create an authorized_keys file. ``` nano ~/.ssh/authorized_keys ``` Paste the content of the id_rsa.pub file. ``` ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDO4fELhgdYFQyh6Iox65p2q4HPRRlkkuX3ReNJ6vmONPgptJTwvB1YUjK1V8BDfj9JPtEUw0nSW668OVuLI0xceDOjVmmYgNBpgt8UlIxJlIIDqFjcXx/Yk3in+cK7aVRIgyFfmjMsQ0lghnZzrO35XncGqRU3xq8n8AGzTk82ZkxccpqVXOdjLN7DqdNLWa0hvz+mGmDCXqQra5hyi36RDbY5krwqvlgg2+nEWGfjspMdjLQaFbcOucmN0EBK2pMoDfUzZ3yAmiqoJswUj1H9u9Jk7/ASIpF7JaxIUrg6A8UI5qCkskPoWPKl8/b0vQmF7+e+bAdf9bsaZbj6Gq5yMkwBED8LitlMtytxE63wSbvaVOXWU3s8ULkHXOJ2L1iF3+H8oU/qM8D4FOBQ7Je1Ujtikye/YtF0dFDx+kfv2gAYRgauCReIQXNc/2/dN3E/kW/7/EtOHATip9CWROtVVsdwPL8ayPaZ4J05UZVx74B9USCLDXbGtiCTUs5PP3k= vyom@ubuntupc ``` Next, edit the SSH configuration file on the remote machine and disable the password-based authentication. ``` nano /etc/ssh/sshd_config ``` Change the following line: ``` PasswordAuthentication no ``` Save and close the file, then restart the SSH service to apply the changes. ``` systemctl restart sshd ``` ## Step 3 – Verify Remote Server Login Using SSH Key At this point, SSH public key authentication is set up between your local and remote systems. Now it’s time to authenticate the remote server using the SSH key. Run the following command on your local system to authenticate the remote server. ``` ssh root@ssh-server-ip ``` If everything is fine, you will get into the remote server, as shown below. ``` Last login: Sun May 7 03:20:15 2023 from 49.34.56.34 [root@fedora ~]# ``` ## Conclusion In this post, we explained how to set up an SSH key-based authentication on the Fedora server. You can now easily use SSH key-based authentication in your local system to manage multiple servers via SSH. You can now try to set up SSH key-based authentication on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Node.js on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-node-js-on-fedora/ | Published: 2023-06-24 | Updated: 2024-01-18 | Author: Hitesh Jethva Node.js is a free, open-source, cross-platform JavaScript runtime environment. It is a backend that runs on Linux, Windows, and Mac. It is used to build scalable server-side and networking applications. It provides an event-driven and asynchronous environment to build different applications such as command line, web, chat, and more. This post will show you how to install Node.js on Fedora. ## Install Node.js Using Default Repo By default, Node.js is available in the Fedora default repo. You can install it with the following command. ``` dnf install nodejs ``` After the installation, you can verify the Node.js version with the following command. ``` node -v ``` Output: ``` v14.19.0 ``` To remove the Node.js from your server, run the following command. ``` dnf remove -y nodejs npm ``` ## Install Node.js Using Node Source First, install all required dependencies using the following command. ``` dnf install -y gcc-c++ make ``` Next, add the Node source repo with the following command. ``` curl -sL https://rpm.nodesource.com/setup_18.x | bash - ``` After that, install Node.js with the following command. ``` dnf install nodejs ``` You can verify the Node.js version with the following command. ``` node -v ``` Output: ``` v18.19.0 ``` Now, remove Node.js using the following command. ``` dnf remove -y nodejs npm ``` ## Install Node.js Using NVM NVM provides a simple and easiest way to install multiple versions of Node.js via the command line. First, install Node.js with the following command. ``` curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/master/install.sh | bash ``` Next, activate the NVM environment with the following command. ``` source ~/.bashrc ``` Next, use the following command to install Node.js version 16.14. ``` nvm install v16.14 ``` Output: ``` Downloading and installing node v16.14.2... Downloading https://nodejs.org/dist/v16.14.2/node-v16.14.2-linux-x64.tar.xz... ################################################################################################################################################################# 100.0% Computing checksum with sha256sum Checksums matched! Now using node v16.14.2 (npm v8.5.0) Creating default alias: default -> v16.14 (-> v16.14.2) ``` You can now verify the Node.js version with the following command. ``` node -v ``` Output: ``` v16.14.2 ``` ## Create a Sample App Using Node.js First, create an app.js file with the following command. ``` nano app.js ``` Add the following code. ``` var http = require('http'); http.createServer(function (req, res) { res.writeHead(200, {'Content-Type': 'text/plain'}); res.end('Node.js is installed on Fedora'); }).listen(3001, "0.0.0.0"); console.log('Server running at http://0.0.0.0:3001/'); ``` Next, run the Node.js application using the following command. ``` node --inspect app.js ``` You will get the following output. ``` Debugger listening on ws://127.0.0.1:9229/a9c46826-65d4-4088-83ae-fbd1e917832a For help, see: https://nodejs.org/en/docs/inspector Server running at http://0.0.0.0:3001/ ``` Now, open your web browser and access the Node.js application using the URL **http://your-server-ip:3001.** You should see your sample application on the following screen. ![Node.js dashboard](https://www.atlantic.net/wp-content/uploads/2023/05/p1-1.png) ## Conclusion This tutorial explained how to install Node.js using different ways on Fedora. We also showed you how to create and run a Node.js application. You can now try Node.js on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Disaster Recovery Plan > URL: https://www.atlantic.net/disaster-recovery/disaster-recovery-plan/ | Published: 2023-06-25 | Updated: 2025-09-15 | Author: Richard Bailey ## What Is a Disaster Recovery Plan (DRP)? A Disaster Recovery Plan (DRP) is a detailed, step-by-step strategy to restore the ordinary business operations of an organization’s IT infrastructure following a disaster scenario that affects the primary business site. When disaster strikes, the DRP becomes an essential playbook for restoring critical business servers, guiding the recovery team through the process to minimize disruption to operations and ensure the continuity of cloud services. A [disaster recovery](https://www.atlantic.net/disaster-recovery/) plan should include the end-to-end process of how your business should respond during a crisis. It is a prepared document incorporating a clearly defined business continuity strategy. The DRP explains what strictly your business classifies as a disaster and outlines the critical in-scope assets relevant to an overall business continuity plan. The RDP documents which employees are vital to the disaster recovery strategy and explain the communication passage throughout the disaster recovery plans. Furthermore, the DRP explains how to recover the business, such as failing over critical IT systems to a secondary location or recovering from backups. Once service is restored, it is essential to revisit the whole network disaster recovery plan, understand the lessons learned, and develop a fail-back strategy to restore services to their primary location. This is a high-level summary of how disaster recovery plans work, but join us in this article as we delve into the fascinating world of technology recovery strategies, disaster recovery, business continuity, and disaster restoration. ## Types of Disaster Recovery Plan There are several types of disaster recovery plans, and understanding these can help businesses choose the most cost-effective solution and strategy to prevent data loss and minimize business impact analysis and downtime. - **Data Backup**: The simplest form of an IT disaster recovery plan involves storing business data either offsite or at a secondary location. The backup data becomes a recovery point objective to minimize the impact of catastrophic events. It’s essential to ensure that all critical servers are backed up using a predefined backup schedule. - **Hot Sites**: These are typically facilities designed to maintain up-to-date copies of data at all times, such as a data center. Hot sites are used to maintain highly available data replicas of critical servers, using server and storage replication, and businesses can failover services to the hot site rapidly. - **Cold Sites**: These are secondary, less frequently used facilities with essential infrastructure that businesses can switch to in the event of a natural disaster or significant business disruption. The alternate site will typically provide office space and leased server infrastructure during a disaster. Server recovery generally is a slower process, usually from backups. - **Disaster Recovery as a Service:** DRaaS is a cloud-based solution capable of seamlessly migrating business services to the cloud. - **Backup as a Service (BaaS)**: Like DRaaS, this cloud-based solution focuses on backing up an organization’s data, ensuring data availability during a disaster. - **Physical Fortification of Data Center**: This strategy involves using physical disaster recovery tools, such as fire suppression tools and backup power sources, to protect the data center from disasters. However, this strategy is not effective against cyberattacks. - **Virtualization** involves backing up data or replicating an organization’s entire virtual computing environment offsite. VMware vSphere replication is a standard tool used in this scenario, and it’s often used in private clouds. - **Point-in-Time Copies**: This strategy involves taking a snapshot of a database or application at a given moment. The image can then be restored, provided it’s stored offsite or on a virtual machine unaffected by the disaster. - **Instant Recovery**: Similar to point-in-time copies, instant recovery takes a snapshot of an entire virtual machine. This can then be restored to recover systems and data. ## How Does Disaster Recovery Differ from a Simple Backup? While backups are crucial when a disaster occurs, they are not a complete solution. Backups involve storing copies of data, which can be used to restore lost data. However, a disaster recovery plan goes beyond just data recovery. A DRP incorporates recovery objectives, recovery time objectives, recovery point objectives, and business continuity planning. It outlines the steps to recover data and return the entire system to normal business operations, including critical systems, business processes, and other aspects of the IT infrastructure. ## What to Include in a Disaster Recovery Plan ##### **#1: Define What a Disaster Recovery Scenario Is** A Disaster Recovery (DR) scenario refers to a catastrophic event that disrupts the regular operation of critical assets of the business. These disruptive events could range from cyber attacks to power outages, natural disasters, human error, hardware failure, or equipment failure. A DR scenario typically results in losing access to business applications, data streams, critical documents, and other system components, significantly jeopardizing your business operations. ##### **#2: Know When to Declare a Disaster** Understanding when to declare a disaster is crucial to minimizing downtime and loss of data. A disaster should be reported when the disruption to your normal operations exceeds the acceptable threshold defined in your disaster recovery plan. Declaring a disaster requires accurate timing and should only be declared by authorized persons predefined in the DRP. ##### **#3: How to Invoke Disaster Recovery?** Invoking a disaster recovery plan involves activating your technology and internal disaster recovery strategies. This could include switching to a disaster recovery site, starting backup systems, or rerouting network traffic. The disaster recovery plan should clearly define the process, and everyone involved should know the steps to take. ##### **#4: Communication** During a DR scenario, clear and efficient communication is critical. The disaster recovery incident management plan should include a list of key personnel to be contacted, their roles and responsibilities, and the methods of communication to be used. This may involve liaising with external entities such as data security services or technology partners. ##### **#5: Key Roles and Responsibilities** The recovery management team is the backbone of the disaster recovery process. Their roles and responsibilities should be clearly outlined in the disaster recovery plan. This includes managing communications and internal recovery strategies, overseeing the functionality of the disaster recovery site, and maintaining the continuity of business applications and services. ##### **#6: Run Books** Your disaster recovery plan should include detailed steps to maintain business operations during a disaster. These might involve relocating to a disaster recovery center, switching to redundant systems, implementing manual processes, or utilizing cloud-based applications. ##### **#7: Set a Recovery Time Objective** The Recovery Time Objective (RTO) is the maximum acceptable time your business or government agencies can operate without the disrupted service. Your disaster recovery plan should detail your RTO for each critical service and the strategies to achieve these objectives. ##### **#8: Set a Recovery Point Objective** The Recovery Point Objective (RPO) for backup data is the maximum acceptable amount of data loss measured in time. In other words, the age of the files must be recovered from backup storage for normal operations to resume if a computer, system, or network goes down. Your disaster recovery plan should state your RPO for each critical or sensitive data set. ##### **#9: Define the Disaster Recovery Process** Your disaster recovery plan should include clearly defined disaster recovery procedures and processes illustrated with a flowchart of activities. This will serve as a visual guide for the disaster recovery team and ensure a systematic approach to disaster recovery. Tech teams should be able to follow predefined run-books to complete the required disaster recovery tasks. ##### **#10: Root Cause Analysis** After the immediate disaster response procedures and the disaster is under control, it’s essential to conduct a root cause business impact analysis to identify what caused the disaster and how it can be prevented in the future. Lessons learned from risk analysis should be incorporated into an updated disaster recovery plan template to ensure continuous improvement. ##### **#11: Continuously Test and Evolve the DR Plan** The disaster recovery plan should not be a static document. Regular testing and updating of the plan are necessary to account for changes in technology, personnel, and business needs after natural disasters. A disaster recovery testing strategy is critical to successful DR. Updating your disaster recovery plan to reflect any deficiencies, errors, and omissions identified during the DR process is crucial. ## What to Include in a Business Continuity Plan **Write a Mission Statement for the Plan:** Describe the business continuity plan’s objectives, including when it needs to be completed and the budget for disaster and recovery preparation. **Set Up Governance:** Describe the business continuity team, including names or titles, role designations, and contact information. Define roles, lines of authority and succession, and accountability. **Write the Plan Procedures and Appendices:** This is the core of your plan and should include procedures, agreements, and resources. The goal should be specific, potentially using diagrams and illustrations. Remember to include checklists and work instructions, and note who on the team is responsible for knowing plan details. **Detail a Training Program:** Determine the curriculum and timelines for initial and refresher training. Specify which roles will actively lead training and who must receive training. **Set Procedures for Testing Recovery and Response:** Create test guidelines and schedules for testing. To review the plan, consider reaching out to people who did not write the plan. Put together the forms and checklists that attendees will use during tests. **Establish a Process for Capturing Insights:** Build debriefs into your processes; these meetings should occur after training sessions and as after-action reports for incidents. ## Disaster Recovery Plan Examples Examples of disaster recovery plans can be found in various industries. For instance, check out the [Atlantic.Net DRP for healthcare](https://www.atlantic.net/resources/documents/whitepapers/pdf/hipaa-disaster-recovery-atlantic-net-whitepaper.pdf) workloads. ## Scope and Objectives of DR Planning The scope of disaster recovery planning is broad, encompassing all aspects of the organization’s IT infrastructure. Its primary objective is to minimize the impact of a disaster on business operations and to ensure the swift recovery of critical systems and data. Another critical objective of disaster planning is to protect sensitive data, ensuring it remains secure even during a disaster. ## Business Continuity vs. Disaster Recovery Plans: Do You Need Both? Business continuity planning and disaster recovery planning are closely related but serve different purposes. Business continuity planning is about maintaining operations during a disaster, while a cloud disaster recovery plan focuses on restoring IT infrastructure and systems after a severe disaster. Both are critical to an organization’s resilience and should be part of a comprehensive risk assessment and management strategy. ## The Risks of Not Having a Business Continuity and Disaster Recovery Plan The risks of not having Business Continuity and Disaster Recovery Plans are far-reaching. From lost revenue during downtime to reputational damage due to data loss, the impact can be catastrophic. In [worst-case disaster scenarios](https://www.atlantic.net/disaster-recovery/the-importance-of-disaster-recovery-in-the-midst-of-a-natural-disaster/), companies without such a plan may never recover from a significant event. ## How Is Business Continuity Planning Different from Disaster Recovery Planning? While they are often used interchangeably, business continuity planning, enterprise resource management, and disaster recovery planning are distinct but interconnected components of a comprehensive approach to dealing with disruptions. A business continuity plan is about maintaining the essential functions of a business during and after a disaster. It encompasses everything from managing human resources to maintaining supply chains and information technology systems and ensuring that business operations continue to function. On the other hand, disaster recovery is a more focused subset of the business continuity plan. It deals explicitly with restoring IT infrastructure and systems, such as data centers and networks, after a disruption. This might involve strategies like data backup and disaster recovery sites, hardware and software restoration, and the implementation of alternate work sites for IT operations. ## Atlantic.Net Disaster Recovery Service Available in multiple geographically disparate locations, our advanced technology can fail servicer from a primary data center location to a secondary site, ensuring your data is protected and readily available during a disaster. Our state-of-the-art facilities are built to withstand even the most severe natural disasters and offer unparalleled security. We can meet heavy traffic demands with facilities in eight data center locations and provide offsite storage hosting. Take the first step towards virtualized disaster recovery plan to protect your business from the unforeseen. Contact [Atlantic.Net](https://www.atlantic.net/) today and give your business the disaster recovery solution it deserves. --- # Building a Cloud Disaster Recovery Plan: Tips and Approaches > URL: https://www.atlantic.net/disaster-recovery/building-a-cloud-disaster-recovery-plan-tips-and-approaches/ | Published: 2023-06-27 | Updated: 2025-09-15 | Author: Richard Bailey Cloud computing has introduced added versatility to modern disaster recovery strategies. Not only is cloud-based disaster recovery affordable, but it also introduces flexibility that was often out of reach for many small and medium-sized businesses. This article will delve into the distinctions between Cloud Disaster Recovery (Cloud DR) and traditional disaster recovery solutions. ## What Is Cloud Disaster Recovery (Cloud DR)? Cloud Disaster Recovery (Cloud DR) is a modern approach to traditional [disaster recovery](https://www.atlantic.net/disaster-recovery/) methods, leveraging the power and scalability of cloud computing to safeguard business-critical servers and applications, ensuring business continuity. Cloud DR isn’t merely a data backup process but a comprehensive strategy to rapidly restore key business operations in the event of a disaster. With Cloud DR, businesses can dynamically scale their DR resources to meet their evolving needs. This adaptability extends to the types of disasters it can handle. It provides robust solutions for large-scale disasters and minor, yet equally critical, incidents such as server failures or software glitches. Cloud DR typically involves replicating data and applications to a cloud environment, which can be a public, private, or hybrid cloud. This strategy allows businesses to maintain access to their vital data and applications, even if their primary IT infrastructure is compromised. Cloud DR enables faster recovery times compared to traditional DR methods, as the data and applications are readily accessible from the cloud, reducing the time and complexity associated with the recovery process. ## What Is the Difference Between DR and Failover? Failover and disaster recovery share many parallels; however, the two have crucial differences. Disaster recovery refers to the comprehensive strategy and procedures to restore and resume an organization’s IT infrastructure and operations following a disaster. Alternatively, failover is a specific process part of a broader disaster recovery plan. It refers to the automatic switching from a primary system to a redundant or standby system in the event of a failure or abnormal termination of the primary system. The goal of failover is for the secondary system to take over when the primary system fails. This failover server will be located in the cloud in a Cloud DR. ## Cloud-to-Cloud Disaster Recovery Strategies If your workloads are already in the cloud, you will need to understand cloud-to-cloud DR. There are different ways to approach multi-cloud DR; it’s not uncommon for businesses to have IT infrastructure in various geographical regions. Therefore, having redundancy between regions is vital. Perhaps you will have a synchronous database or storage replication between sites A and secondary site B. Another option is avoiding vendor lock-in and replicating your critical systems into a virtual machine replica in a different cloud provider. For example, you may have core systems running in AWS, but you use Atlantic.Net as a hot site. A hot site is a 1:1 replica of your systems using real-time replication. If you need a cold site, perhaps use an alternative site as a backup location for your production data. ## Selecting a Cloud DR Provider When choosing a cloud disaster recovery (DR) provider, several critical factors must be considered as part of your disaster recovery planning process. Research and shortlist your preferred vendors, and take careful consideration that the provider is capable of delivering: ### **Recovery Time and Recovery Point Objectives:** The Recovery Time Objective (RTO) is essential to disaster recovery strategies. It determines the full recovery time objective maximum duration your business can afford without its critical systems in the event of a cloud disaster. In your chosen cloud DRP, your provider should be able to restore data and resume operations within this time frame. Data loss tolerance is another critical part of the disaster recovery strategy. It outlines the maximum age of backup data your organization must recover after a disaster to resume normal operations. In a cloud disaster recovery strategy, ensure your DR provider can meet your RPO requirements and store backup data effectively. ### **Scalability, Flexibility, and Security:** Rapid scalability can be a crucial component of cloud disaster recovery solutions in the event of a disaster. As your business and data storage needs grow, so will your need for disaster recovery efforts. A good cloud DR provider should be able to scale and adapt to your changing requirements. Whether handling increased data synchronization, improving performance, or providing more extensive coverage against potential disasters, your provider must be capable of evolving with you. In the wake of a disaster, protecting your mission-critical data is vital. Look for a DR provider with strong [security](https://www.atlantic.net/managed-services/what-are-managed-security-services-mss/) protocols in their cloud environments. This includes encryption, multi-factor authentication, and regular security audits. Furthermore, any provider that complies with industry-specific regulations such as GDPR, HIPAA, or SOC 2 is a good gauge of how seriously they take security. ### **Rigid Service Level Agreements (SLAs):** SLAs are contracts between you and your DR provider that specify the level of service you can expect. They should clearly outline the cloud vendor’s responsibilities, the expected recovery times ([RTO and RPO](https://www.atlantic.net/disaster-recovery/rto-vs-rpo/)), and the consequences if these are unmet. ### **Accurate Testing and Validation:** A comprehensive cloud DRP is only as good as its execution. Regular testing and validation of the plan are vital to ensure it works as expected when a natural disaster or disaster strikes. Ask potential cloud providers about their testing protocols and how often they test their cloud disaster recovery strategies and workflows. ### **Experience and Reputation:** While new players may offer innovative cloud technologies and disaster recovery options, a provider with a solid track record can offer an extra layer of reassurance. Look for case studies, customer reviews, and independent evaluations to assess a provider’s reputation. ### **Cost Structure:** The cost of cloud DR services and the potential for significant business costs can vary greatly. Be sure to understand the pricing structure and what it includes. Look for hidden costs like data transfer fees or costs associated with testing the recovery plan. ### **Customer Support:** When disaster strikes, you want to know a competent and responsive support team is ready to help. Look for a provider that offers 24/7 support, has a good response time, and communicates clearly and effectively. ### **Geographical Coverage:** Depending on your business, you may need a provider offering services across multiple data centers in different regions. This can help ensure business continuity even in the face of regional disasters, making it an essential component of any cloud-based disaster recovery plan. ## Are Cloud DR and DRaaS the Same? Cloud Disaster Recovery, often abbreviated as Cloud DR, encompasses various strategies and processes to secure data and ensure its swift restoration in a cloud environment when a disaster strikes. It is a critical component of modern disaster recovery strategies designed to minimize the chance of data loss during a disaster. Cloud DR typically involves cloud-to-cloud data center replication, where data and applications are deduplicated between a primary data center (or Region) and a chosen secondary data center (or Region) hosted in the cloud. This action creates a reliable backup data store location, ready and available around the clock to be accessed on-demand. When it’s time to invoke DR after a catastrophic event, the IT operations will shift from the primary location to a dedicated facility in a cloud-based secondary data center. This transfer lets businesses restore data and promptly resume critical operations, minimizing downtime and minimizing significant business costs. Cloud DR leverages various cloud services provided by different cloud vendors, including public, private, or hybrid models. This flexibility allows businesses to choose a disaster recovery solution that fits their needs and preferences. In contrast, Disaster Recovery as a Service (or DRaaS) offers a uniquely different proposition. DRaaS is a specialized service provided by some third-party cloud providers with the explicit purpose of managing disaster recovery efforts. The service provider handles everything from creating data backups to restoring affected data and failing over critical servers, thus allowing businesses to focus on their core operations. DRaaS providers typically offer a comprehensive suite of services that include cloud storage for backups, data deduplication, regular DR testing, and managed IT operations such as failover and failback. These services provide a rounded, robust approach to disaster recovery planning and execution. DRaaS often presents an attractive option for businesses lacking the in-house resources or expertise to manage disaster recovery. Third-party providers handle all aspects of disaster recovery, from data mirroring to backup storage and even the restoration of critical files. Doing so ensures that even in the face of potential disasters, businesses can recover data and resume operations promptly. ## Have a Strong Cloud Backup Solution A robust cloud-native backup solution is the cornerstone of any effective Cloud Recovery Plan. It protects your data and ensures the business can quickly rebound in disaster. Organizations must carefully select a cloud backup solution that aligns with their specific needs and operational realities to gain these benefits. Implementing a cloud backup solution is more cost-effective than traditional, on-premises backup solutions. There is no need for significant upfront investment in hardware and the ongoing costs associated with maintenance and upgrades. Many cloud backup solutions offer automated backup options. This means that backups of data stored elsewhere can be scheduled regularly, ensuring that your data is always current, thus reducing the risk of data loss. ### Why Is a Cloud Disaster Recovery Plan Important? Businesses heavily depend on their information systems, making a cloud disaster recovery plan an indispensable asset. This plan is your defense mechanism against disruptions, from natural disasters to cyberattacks and anything else that could compromise your critical data and IT infrastructure. A cloud DRP is important for several reasons. Primarily, it guarantees business continuity, which is essential in maintaining customer trust and mitigating potential revenue losses. Without a robust disaster recovery solution, businesses risk prolonged downtime, damaging their reputation and competitive standing. Moreover, a cloud DRP protects against data loss. In the modern world, where data is valuable, losing critical data can lead to a business disaster. A cloud disaster recovery solution performs data replication and frequent backups, minimizing the risk of losing stored data when a disaster occurs. Finally, a cloud disaster recovery plan helps meet compliance with industry regulations that mandate businesses to have a disaster recovery (DR) plan. Not adhering to these regulations could result in substantial penalties and potential legal ramifications. ### Creating a Cloud-Based Disaster Recovery Plan Writing a Cloud DRP is similar to any other disaster recovery plan. Here are some of the critical areas to highlight: - **Risk Assessment:** Begin with a thorough business impact analysis to understand potential risks that could disrupt your operations. Identify essential systems, applications, data, and threats that threaten day-to-day business operations. - **Define Recovery Objectives:** With identified risks, define your Recovery Time Objective (RTO) and Recovery Point Objective (RPO). These values are essential, so spend time making sure the recommendations are accurate; remember the entire Cloud DRP recovery objectives must be achievable. - **Choose a Cloud Service Provider:** Selecting a reliable cloud provider is critical. Consider the provider’s reliability, security measures, compliance certifications, and the cost of their services. You can read more about[Atlantic.Net DRaaS here](https://www.atlantic.net/disaster-recovery/). - **Implement Backup and Replication Strategies:** Backups are a vital part of any DR strategy. It’s critical to utilize regular backups and a proven data replication strategy in cloud environments to ensure data availability and minimize data loss. - **Plan Testing and Updates:** Regularly testing and updating the DR plan is essential. This ensures the plan is effective and relevant as your business changes. Your chosen provider should perform at least one annual DR test. After each test, the DRP should be reviewed and updated as required. ## Cloud Disaster Recovery Planning with Atlantic.Net Cloud disaster recovery planning is an ongoing process involving regular review, testing, and updating of the plan. The planning process includes training staff members on their roles during a serious disaster event and how to execute the DR plan effectively. A proactive approach not only readies your organization for unexpected events but also helps to provide a roadmap for recovery, thereby ensuring the resilience and longevity of your business operations. Cloud-based DR leverages virtual machines and cloud resources, making it possible to recover data swiftly and effectively, even if your local data center is compromised. Cloud platforms offer an off-site DR solution, ensuring your critical data is secure and readily available when needed. Prepare for the unexpected with Atlantic.Net’s Cloud Disaster Recovery (DR) services. Safeguard your critical data from system failures, cyberattacks, and natural disasters. Benefit from our reliable infrastructure, flexible customization options, and rapid recovery solutions. Count on our expert support to ensure business continuity. Don’t wait for a crisis to strike—take proactive measures now. Visit [Atlantic.Net](https://www.atlantic.net/disaster-recovery/)‘s website to learn more and protect your data, ensuring uninterrupted operations and peace of mind. Act today with [Atlantic.Net](https://www.atlantic.net/about-us/corporate-contact/)‘s Cloud DR services to secure your business’s future. --- # How to Install and Use Docker on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-docker-on-fedora/ | Published: 2023-06-28 | Updated: 2023-11-23 | Author: Hitesh Jethva Docker is one of the most popular tools for deploying software in containers. This free tool helps you to make your application portable and run it on any platform without installing any dependencies. It is a relatively new platform and is constantly updated by a large developer community. With Docker, you can run multiple containers on the same hardware. Docker is an alternate solution for virtual machines that are lightweight and more resource-friendly. In this post, we will explain how to install and use Docker and Docker Compose on Fedora. ## Step 1 – Add Docker Repo By default, the Docker and Docker Compose packages are not included in the Fedora default repo, so you will need to add a Docker repo to the Yum repository. You can add it with the following command. ``` dnf update -y dnf -y install dnf-plugins-core dnf config-manager --add-repo https://download.docker.com/linux/fedora/docker-ce.repo ``` The above command will create a docker-ce.repo file in the Yum configuration directory. ## Step 2 – Install Docker and Docker Compose Now, run the following command to install Docker, Docker Compose, and other packages to Fedora. ``` dnf install docker-ce docker-ce-cli containerd.io docker-compose-plugin docker-compose -y ``` After the successful installation, start and enable the Docker service using the following command. ``` systemctl start docker systemctl enable docker ``` You can now verify the Docker version using the following command. ``` docker --version ``` Output: ``` Docker version 20.10.17, build 100c701 ``` To check the Docker service status, run the following command. ``` systemctl status docker ``` Output: ``` ● docker.service - Docker Application Container Engine Loaded: loaded (/usr/lib/systemd/system/docker.service; disabled; vendor preset: disabled) Active: active (running) since Sat 2023-05-20 03:54:38 EDT; 8min ago TriggeredBy: ● docker.socket Docs: https://docs.docker.com Main PID: 5219 (dockerd) Tasks: 13 Memory: 41.4M CPU: 1min 31.505s CGroup: /system.slice/docker.service └─5219 /usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock ``` If you want to see more information about Docker, run the following command. ``` docker info ``` Output: ``` Client: Context: default Debug Mode: false Plugins: app: Docker App (Docker Inc., v0.9.1-beta3) buildx: Docker Buildx (Docker Inc., v0.8.2-docker) compose: Docker Compose (Docker Inc., v2.6.0) scan: Docker Scan (Docker Inc., v0.17.0) Server: Containers: 0 Running: 0 Paused: 0 Stopped: 0 Images: 0 Server Version: 20.10.17 Storage Driver: overlay2 Backing Filesystem: xfs Supports d_type: true Native Overlay Diff: true userxattr: false Logging Driver: json-file Cgroup Driver: systemd Cgroup Version: 2 Plugins: Volume: local Network: bridge host ipvlan macvlan null overlay Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog Swarm: inactive Runtimes: io.containerd.runc.v2 io.containerd.runtime.v1.linux runc Default Runtime: runc Init Binary: docker-init containerd version: 10c12954828e7c7c9b6e0ea9b0c02b01407d3ae1 runc version: v1.1.2-0-ga916309 init version: de40ad0 Security Options: ``` ## Step 3 – Verify Docker After installing Docker, you will need to verify Docker. Let’s download and run the hello-world container. ``` docker run hello-world ``` This will pull the hello-world Docker image from the Docker Hub repository and create a container for it. ``` Unable to find image 'hello-world:latest' locally latest: Pulling from library/hello-world 719385e32844: Pull complete Digest: sha256:fc6cf906cbfa013e80938cdf0bb199fbdbb86d6e3e013783e5a766f50f5dbce0 Status: Downloaded newer image for hello-world:latest Hello from Docker! This message shows that your installation appears to be working correctly. To generate this message, Docker took the following steps: 1. The Docker client contacted the Docker daemon. 2. The Docker daemon pulled the "hello-world" image from the Docker Hub. (amd64) 3. The Docker daemon created a new container from that image which runs the executable that produces the output you are currently reading. 4. The Docker daemon streamed that output to the Docker client, which sent it to your terminal. To try something more ambitious, you can run an Ubuntu container with: $ docker run -it ubuntu bash Share images, automate workflows, and more with a free Docker ID: https://hub.docker.com/ For more examples and ideas, visit: https://docs.docker.com/get-started/ ``` You can verify the downloaded image using the following command. ``` docker images ``` Output. ``` REPOSITORY TAG IMAGE ID CREATED SIZE hello-world latest 9c7a54a9a43c 2 weeks ago 13.3kB ``` To check the status of the hello-world container, run the following command. ``` docker ps -a ``` Output. ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 2f37b19f050d hello-world "/hello" About a minute ago Exited (0) About a minute ago flamboyant_lovelace ``` ## Step 4 – How to Use Docker Docker allows you to pull and run any operating system inside the container. Let’s pull the Fedora image and create a container using the following command. ``` docker run -dit fedora:latest ``` You will see the following output. ``` Unable to find image 'fedora:latest' locally latest: Pulling from library/fedora 86c577c44422: Pull complete Digest: sha256:88b02539d545dcc81f1a991b06fd2a6e7c550f4192ed3625843926b56522a37c Status: Downloaded newer image for fedora:latest a2a919fc421cce733984fc8ed69259bcab045e50c14cbc185cd4e38efe72bcd5 ``` You can verify the running container using the following command. ``` docker ps ``` Output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES a2a919fc421c fedora:latest "/bin/bash" 10 seconds ago Up 9 seconds beautiful_euler ``` To connect the running container, run the following command. ``` docker exec -it a2a919fc421c /bin/bash ``` You will get into the Fedora container as shown below. ``` [root@a2a919fc421c /]# ``` Now, verify the Fedora version using the following command. ``` cat /etc/os-release ``` Output: ``` NAME="Fedora Linux" VERSION="38 (Container Image)" ID=fedora VERSION_ID=38 VERSION_CODENAME="" PLATFORM_ID="platform:f38" PRETTY_NAME="Fedora Linux 38 (Container Image)" ANSI_COLOR="0;38;2;60;110;180" LOGO=fedora-logo-icon CPE_NAME="cpe:/o:fedoraproject:fedora:38" DEFAULT_HOSTNAME="fedora" HOME_URL="https://fedoraproject.org/" DOCUMENTATION_URL="https://docs.fedoraproject.org/en-US/fedora/f38/system-administrators-guide/" SUPPORT_URL="https://ask.fedoraproject.org/" BUG_REPORT_URL="https://bugzilla.redhat.com/" REDHAT_BUGZILLA_PRODUCT="Fedora" REDHAT_BUGZILLA_PRODUCT_VERSION=38 REDHAT_SUPPORT_PRODUCT="Fedora" REDHAT_SUPPORT_PRODUCT_VERSION=38 SUPPORT_END=2024-05-14 VARIANT="Container Image" VARIANT_ID=container ``` Finally, exit from the Fedora container using the following command. ``` [root@a2a919fc421c /]# exit ``` ## Step 5 – Remove Docker and Docker Compose You can remove the Docker, Docker Compose, and other packages using the following command. ``` dnf remove docker-ce docker-ce-cli containerd.io docker-compose-plugin docker-compose -y ``` Now, clean all package caches using the following command. ``` dnf clean all ``` ## Conclusion In this post, we explained how to install Docker and Docker Compose on Fedora. We also show you how to use Docker to run any container. You can now try to install Docker and Docker Compose on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Jenkins on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-jenkins-on-fedora/ | Published: 2023-06-29 | Updated: 2023-11-25 | Author: Hitesh Jethva Open-source Jenkins is one of the most widely used automation tools for building and managing applications. It supports all major programming languages including, Python, C++, PHP, etc. Jenkins is a Java-based tool used by developers to automate tasks in the software development cycle. It offers a large plugin library that helps you to make the necessary changes to applications before going into production. In this post, we will show you how to install Jenkins on Fedora. ## Step 1 – Install Java OpenJDK Jenkins is written in Java, so Java JDK must be installed on your server. If not installed, you can install it easily using the following command. ``` dnf install java-17-openjdk -y ``` After the installation, verify the Java installation using the following command. ``` java --version ``` Output: ``` openjdk 17.0.3 2022-04-19 OpenJDK Runtime Environment 21.9 (build 17.0.3+7) OpenJDK 64-Bit Server VM 21.9 (build 17.0.3+7, mixed mode, sharing) ``` ## Step 2 – Add Jenkins Repo By default, Jenkins is not included in the Fedora default repo, so you will need to add the Jenkins repo to your server. You can install it with the following command. ``` wget -O /etc/yum.repos.d/jenkins.repo https://pkg.jenkins.io/redhat-stable/jenkins.repo ``` Output: ``` --2023-05-20 00:29:02-- https://pkg.jenkins.io/redhat-stable/jenkins.repo Resolving pkg.jenkins.io (pkg.jenkins.io)... 151.101.2.133, 151.101.194.133, 151.101.130.133, ... Connecting to pkg.jenkins.io (pkg.jenkins.io)|151.101.2.133|:443... connected. HTTP request sent, awaiting response... 200 OK Length: 85 Saving to: ‘/etc/yum.repos.d/jenkins.repo’ /etc/yum.repos.d/jenkins.repo 100%[=====================================================================================>] 85 --.-KB/s in 0s 2023-05-20 00:29:02 (2.71 MB/s) - ‘/etc/yum.repos.d/jenkins.repo’ saved [85/85] ``` Next, import the Jenkins GPG key with the following command. ``` rpm --import https://pkg.jenkins.io/redhat-stable/jenkins.io-2023.key ``` Next, verify the added repo using the following command. ``` dnf repolist ``` Output: ``` repo id repo name fedora Fedora 34 - x86_64 fedora-cisco-openh264 Fedora 34 openh264 (From Cisco) - x86_64 fedora-modular Fedora Modular 34 - x86_64 jenkins Jenkins-stable updates Fedora 34 - x86_64 - Updates updates-modular Fedora Modular 34 - x86_64 - Updates ``` ## Step 3 – Install Jenkins Now, you can install Jenkins using the DNF command line utility. ``` dnf install jenkins -y ``` Once the Jenkins is installed, start and enable the Jenkins service with the following command. ``` systemctl start jenkins systemctl enable jenkins ``` You can now verify the status of Jenkins with the following command. ``` systemctl status jenkins ``` Output: ``` ● jenkins.service - Jenkins Continuous Integration Server Loaded: loaded (/usr/lib/systemd/system/jenkins.service; disabled; vendor preset: disabled) Active: active (running) since Sat 2023-05-20 00:31:56 EDT; 16s ago Main PID: 3926 (java) Tasks: 51 (limit: 4666) Memory: 1.2G CPU: 47.408s CGroup: /system.slice/jenkins.service └─3926 /usr/bin/java -Djava.awt.headless=true -jar /usr/share/java/jenkins.war --webroot=/var/cache/jenkins/war --httpPort=8080 May 20 00:31:38 fedora jenkins[3926]: 8c1c142cc9fd44fc8297c0e8b881fed1 May 20 00:31:38 fedora jenkins[3926]: This may also be found at: /var/lib/jenkins/secrets/initialAdminPassword May 20 00:31:38 fedora jenkins[3926]: ************************************************************* May 20 00:31:38 fedora jenkins[3926]: ************************************************************* May 20 00:31:38 fedora jenkins[3926]: ************************************************************* May 20 00:31:56 fedora jenkins[3926]: 2023-05-20 04:31:56.753+0000 [id=31] INFO jenkins.InitReactorRunner$1#onAttained: Completed initialization May 20 00:31:56 fedora jenkins[3926]: 2023-05-20 04:31:56.789+0000 [id=24] INFO hudson.lifecycle.Lifecycle#onReady: Jenkins is fully up and running May 20 00:31:56 fedora systemd[1]: Started Jenkins Continuous Integration Server. May 20 00:31:56 fedora jenkins[3926]: 2023-05-20 04:31:56.946+0000 [id=48] INFO h.m.DownloadService$Downloadable#load: Obtained the updated data file for> May 20 00:31:56 fedora jenkins[3926]: 2023-05-20 04:31:56.947+0000 [id=48] INFO hudson.util.Retrier#start: Performed the action check updates server succ> ``` ## Step 4 – Access Jenkins Web Interface At this point, Jenkins is installed and listening on port 8080. You can verify it with the following command. ``` ss -antpl | grep 8080 ``` Output. ``` LISTEN 0 50 *:8080 *:* users:(("java",pid=3926,fd=9)) ``` Next, retrieve the Jenkins initial admin password with the following command. ``` cat /var/lib/jenkins/secrets/initialAdminPassword ``` Output: ``` 8c1c142cc9fd44fc8297c0e8b881fed1 ``` Now, open your web browser and access the Jenkins web interface using the URL **http://your-server-ip:8080.** You should see the Jenkins initial password screen. ![jenkins initial password screen](https://www.atlantic.net/wp-content/uploads/2023/05/p1-1-1.jpg) Provide your password and click on the **Continue** button. You should see the following screen. ![install suggested plugins](https://www.atlantic.net/wp-content/uploads/2023/05/p2-2.jpg) Click on the **Install suggested plugins.** You should see the following screen. ![jenkins crreate account](https://www.atlantic.net/wp-content/uploads/2023/05/p4-1.jpg) Define your admin user, password, and email, and click on the **Save and Finish** button. You should see the following screen. ![Jenkins instance configuration](https://www.atlantic.net/wp-content/uploads/2023/05/p6.jpg) Define your Jenkins URL and click on the **Start using Jenkins** button. You should see the Jenkins dashboard on the following screen. ![Jenkins dashboard](https://www.atlantic.net/wp-content/uploads/2023/05/p7.jpg) ## Conclusion In this tutorial, we showed you how to install Jenkins on Fedora. You can now implement Jenkins in your development team to streamline the software development process. Try to install and implement Jenkins on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install OpenNMS on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-opennms-on-fedora/ | Published: 2023-06-30 | Updated: 2023-11-18 | Author: Hitesh Jethva OpenNMS, also called “Open Network Management System,” is a free and cross-platform network management platform for Linux and Windows-based operating systems. It is a Java-based tool designed to monitor critical services on remote machines via SNMP and JMX. OpenNMS comes with a web-based console that helps you to monitor and administer networks and applications. In this tutorial, we will show you how to install OpenNMS on Fedora. ## Step 1 – Install Java JDK OpenNMS is based on Java, so you will need to install the Java JDK on your server. You can install it with the following command. ``` dnf install java-11-openjdk ``` After the successful installation, you can verify the Java installation with the following command. ``` java --version ``` Output. ``` openjdk 11.0.15 2022-04-19 OpenJDK Runtime Environment 18.9 (build 11.0.15+10) OpenJDK 64-Bit Server VM 18.9 (build 11.0.15+10, mixed mode, sharing) ``` ## Step 2 – Install and Configure PostgreSQL Database OpenNMS uses PostgreSQL as a database backend, so you will need to install and configure PostgreSQL to your server. First, disable the default PostgreSQL repo and enable the PostgreSQL 14 repo with the following command. ``` dnf module reset postgresql -y dnf module enable postgresql:14 ``` Next, install the PostgreSQL server with the following command. ``` dnf install postgresql-server postgresql ``` Next, initialize the PostgreSQL database using the following command. ``` postgresql-setup --initdb ``` Next, start and enable the PostgreSQL service with the following command. ``` systemctl enable --now postgresql ``` Next, log in to PostgreSQL: ``` su - postgres psql ``` Create a database and user for OpenNMS with the following command. ``` create user opennms; create database opennms owner opennms; grant all privileges on database opennms to opennms; ``` Next, set OpenNMS and Postgres password with the following command. ``` ALTER USER opennms WITH ENCRYPTED password 'secure_password'; ALTER USER postgres WITH PASSWORD 'secure_password'; ``` Finally, exit from the PostgreSQL shell with the following command. ``` \q exit ``` Next, edit the PostgreSQL configuration file. ``` nano /var/lib/pgsql/data/pg_hba.conf ``` Find the following lines: ``` host all all 127.0.0.1/32 ident host all all ::1/128 ident ``` And replace them with the following lines: ``` host all all 127.0.0.1/32 md5 host all all ::1/128 md5 ``` Save and close the file, then reload PostgreSQL to implement the changes. ``` systemctl reload postgresql ``` ## Step 3 – Install and Configure OpenNMS First, add the OpenNMS repo and import the GPG key using the following command. ``` dnf -y install https://yum.opennms.org/repofiles/opennms-repo-stable-rhel8.noarch.rpm rpm --import https://yum.opennms.org/OPENNMS-GPG-KEY ``` Next, install the OpenNMS package with the following command. ``` dnf install opennms -y ``` Next, edit the OpenNMS database configuration file. ``` nano /opt/opennms/etc/opennms-datasources.xml ``` Define your database details as shown below. ``` ``` Save and close the file, then run the following command to detect the Java environment. ``` /opt/opennms/bin/runjava -s ``` Output: ``` runjava: Looking for an appropriate JVM... runjava: Checking for an appropriate JVM in JAVA_HOME... runjava: Skipping... JAVA_HOME not set. runjava: Checking JVM in the PATH: "/usr/lib/jvm/java-11-openjdk-11.0.15.0.10-1.fc34.x86_64/bin/java"... runjava: Found an appropriate JVM in the PATH: "/usr/lib/jvm/java-11-openjdk-11.0.15.0.10-1.fc34.x86_64/bin/java" runjava: Value of "/usr/lib/jvm/java-11-openjdk-11.0.15.0.10-1.fc34.x86_64/bin/java" stored in configuration file. ``` Next, complete the OpenNMS setup using the following command. ``` /opt/opennms/bin/install -dis ``` Output: ``` Processing SystemIDMigratorOffline: Updates OpenNMS system ID to a random UUID. - Running pre-execution phase - Running execution phase - Saving the execution state - Running post-execution phase Finished in 0 seconds Upgrade completed successfully! Start OpenNMS Service ``` Now, start the OpenNMS service and enable it to start at system reboot with the following command. ``` systemctl start opennms systemctl enable opennms ``` You can now check the status of OpenNMS with the following command. ``` systemctl status opennms ``` Output: ``` ● opennms.service - OpenNMS server Loaded: loaded (/usr/lib/systemd/system/opennms.service; disabled; vendor preset: disabled) Active: active (running) since Sat 2023-05-20 00:44:49 EDT; 2s ago Process: 6347 ExecStart=/opt/opennms/bin/opennms -s start (code=exited, status=0/SUCCESS) Process: 7330 ExecStartPost=/bin/sleep 3 (code=exited, status=0/SUCCESS) Main PID: 7329 (java) Tasks: 44 (limit: 4666) Memory: 313.7M CPU: 21.271s CGroup: /system.slice/opennms.service ├─7328 bash /opt/opennms/bin/opennms -s start └─7329 /usr/lib/jvm/java-11-openjdk-11.0.15.0.10-1.fc34.x86_64/bin/java --add-modules=java.base,java.compiler,java.datatransfer,java.desktop,java.instrume> ``` ## Step 4 – Access OpenNMS Web UI At this point, OpenNMS is started and listening on port 8980. You can verify it with the following command. ``` ss -antpl | grep 8980 ``` Output. ``` LISTEN 0 50 *:8980 *:* users:(("java",pid=7329,fd=1197)) ``` Now, open your web browser and access the OpenNMS web interface using the URL **http://your-server-ip:8980/opennms.** You should see the OpenNMS login page. ![opennms login page](https://www.atlantic.net/wp-content/uploads/2023/05/p1-2.jpg) Provide the default username and password as **admin/admin** then click on the **LOGIN** button. You should see the OpenNMS dashboard on the following screen. ![opennms dashboard](https://www.atlantic.net/wp-content/uploads/2023/05/p2-1.jpg) ## Conclusion In this post, we explained how to install OpenNMS on Fedora. I hope you have now enough knowledge to install and set up OpenNMS in your environment easily. You can now install OpenNMS on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install phpIPAM on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-phpipam-on-fedora/ | Published: 2023-07-01 | Updated: 2023-11-26 | Author: Hitesh Jethva phpIPAM is a free, open-source, PHP-based IP Address management tool. Its aim is to provide lightweight, modern, and useful IP address management via a web-based console. It is written in PHP and uses MySQL as a database backend. phpIPAM provides real-time statistics of used and unused IP addresses with subnets, status, hostname, and more information. It also offers some advanced features such as PowerDNS integration, NAT support, VLAN management, REST API, AD, LDAP, Radius authentication, and more. In this post, we will show you how to install and configure the phpIPAM IP address management tool on Fedora. ## Step 1 – Install the LAMP Server First, you will need to install Apache, MariaDB, and PHP on your server. You can install all of them with the following command. ``` dnf update -y dnf install httpd mariadb-server php ``` Next, install other required PHP extensions with the following command. ``` dnf install php-{mysqlnd,curl,gd,intl,pear,xmlrpc,mbstring,gettext,gmp,json,xml,fpm} ``` Next, start and enable the Apache, MariaDB, and PHP-FPM services using the following command. ``` systemctl enable --now httpd php-fpm mariadb ``` ## Step 2 – Create a Database and User for phpIPAM Next, you will need to create a database and user for phpIPAM. First, log in to MySQL shell using the following command. ``` mysql ``` Once logged in, create a database and user with the following command. ``` CREATE DATABASE phpipam; GRANT ALL ON phpipam.* TO phpipam@localhost IDENTIFIED BY 'securepassword'; ``` Next, flush the privileges and exit from the MySQL shell with the following command. ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download phpIPAM First, install the GIT package with the following command. ``` dnf install git -y ``` Next, download the latest version of phpIPAM using the following command. ``` git clone --recursive https://github.com/phpipam/phpipam.git /var/www/html/phpipam ``` Next, navigate to the phpipam directory and copy the sample configuration file. ``` cd /var/www/html/phpipam cp config.dist.php config.php ``` Next, edit the config.php file and define your database settings. ``` nano config.php ``` Change the following lines as per your database settings. ``` $db['host'] = 'localhost'; $db['user'] = 'phpipam'; $db['pass'] = 'securepassword'; $db['name'] = 'phpipam'; $db['port'] = 3306; ``` Save and close the file, then change the ownership of the phpIPAM directory. ``` chown -R apache:apache /var/www/html/phpipam ``` ## Step 4 – Create an Apache Virtual Host Next, you will need to create an Apache virtual host configuration file to define your phpIPAM. ``` nano /etc/httpd/conf.d/phpipam.conf ``` Add the following configurations. ``` ServerAdmin admin@example.com DocumentRoot "/var/www/html/phpipam" ServerName phpipam.example.com Options Indexes FollowSymLinks AllowOverride All Require all granted ErrorLog "/var/log/httpd/phpipam-error_log" CustomLog "/var/log/httpd/phpipam-access_log" combined ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart httpd ``` Next, import the phpIPAM schema to the phpIPAM database. ``` mysql -u root -p phpipam < /var/www/html/phpipam/db/SCHEMA.sql ``` ## Step 5 – Access phpIPAM Web Interface Now, open your web browser and access the phpIPAM web interface using the URL **http://phpipam.example.com.** You should see the phpIPAM login screen. ![phpipam login screen](https://www.atlantic.net/wp-content/uploads/2023/05/p1-3.png) Provide the default username and password as admin/admin then click on the **Login** button. You should see the default password reset screen. ![phpipam reset password](https://www.atlantic.net/wp-content/uploads/2023/05/p2.jpg) Define your new password and click on the **Save password** button. You should see the following screen. ![phpipam update password](https://www.atlantic.net/wp-content/uploads/2023/05/p3-2.jpg) Click on the **Dashboard** button. You should see the phpIPAM dashboard on the following screen. ![phpipam dashboard](https://www.atlantic.net/wp-content/uploads/2023/05/p4.jpg) ## Conclusion In this guide, we explained how to install and configure the phpIPAM IP address management tool on Fedora. phpIPAM is a very useful tool for system administrators to manage the hardware inventory of the entire infrastructure from the central place. You can now deploy the phpIPAM solution on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install SonarQube on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-sonarqube-on-fedora/ | Published: 2023-07-02 | Updated: 2023-11-25 | Author: Hitesh Jethva SonarQube is a free, open-source, self-managed code review tool that systematically helps you deliver clean code. It is a very useful quality analysis tool to scan source code for potential bugs and vulnerabilities and generates a report. SonarQube supports up to 30 programming languages and provides reports such as duplicate code, coding standards, code complexity, and security recommendation. This post will show you how to install the SonarQube code analysis tool on Fedora. ## Step 1 – Install Java OpenJDK SonarQube is written in Java, so Java JDK must be installed on your server. If not installed, you can install it with the following command. ``` dnf install java-17-openjdk -y ``` Once Java is installed, you can verify the Java installation using the following command. ``` java --version ``` Output: ``` openjdk 17.0.3 2022-04-19 OpenJDK Runtime Environment 21.9 (build 17.0.3+7) OpenJDK 64-Bit Server VM 21.9 (build 17.0.3+7, mixed mode, sharing) ``` ## Step 2 – Install and Configure PostgreSQL Database First, disable the default PostgreSQL repo and enable the PostgreSQL 14 repo. ``` dnf module reset postgresql -y dnf module enable postgresql:14 ``` Next, install the PostgreSQL server with the following command. ``` dnf install postgresql-server postgresql ``` Next, initialize the PostgreSQL database using the following command. ``` postgresql-setup --initdb ``` Next, start the PostgreSQL service and enable it to start at system reboot. ``` systemctl enable --now postgresql ``` Next, log in to the PostgreSQL shell with the following command. ``` su - postgres psql ``` Next, create a database and user for SonarQube. ``` create user sonar; create database sonar owner sonar; grant all privileges on database sonar to sonar; ``` Next, set a password for the sonar user, then exit from the PostgreSQL shell. ``` ALTER USER sonar WITH ENCRYPTED password 'secure_password'; \q exit ``` Next, edit the PostgreSQL configuration file. ``` nano /var/lib/pgsql/data/pg_hba.conf ``` Find the following lines: ``` host all all 127.0.0.1/32 ident host all all ::1/128 ident ``` And, replace them with the following lines: ``` host all all 127.0.0.1/32 md5 host all all ::1/128 md5 ``` Save and close the file, then reload the PostgreSQL service to implement the changes. ``` systemctl reload postgresql ``` ## Step 3 – Install and Configure SonarQube First, create a dedicated user to run SonarQube. ``` useradd -M -d /opt/sonarqube/ -r -s /bin/bash sonar ``` Next, download the latest version of SonarQube. ``` wget https://binaries.sonarsource.com/Distribution/sonarqube/sonarqube-9.9.1.69595.zip ``` Next, unzip the SonarQube and move the unzipped directory to /opt ``` unzip sonarqube-9.9.1.69595.zip mv sonarqube-9.9.1.69595 /opt/sonarqube ``` Next, change the ownership of the SonarQube directory. ``` chown -R sonar:sonar /opt/sonarqube ``` Next, edit the SonarQube configuration file. ``` nano /opt/sonarqube/conf/sonar.properties ``` Define your database settings, host, port, Java options, and data directory. ``` sonar.jdbc.username=sonar sonar.jdbc.password=secure_password sonar.jdbc.url=jdbc:postgresql://localhost/sonar ##How you will access SonarQube Web UI sonar.web.host=0.0.0.0 sonar.web.port=9000 ##Java options sonar.web.javaOpts=-Xmx512m -Xms128m -XX:+HeapDumpOnOutOfMemoryError sonar.search.javaOpts=-Xmx512m -Xms512m -XX:MaxDirectMemorySize=256m -XX:+HeapDumpOnOutOfMemoryError ##Also uncomment the following Elasticsearch storage paths sonar.path.data=data sonar.path.temp=temp ``` Save and close the file, then create a new wrapper.conf file and define your Java path. ``` nano /opt/sonarqube/conf/wrapper.conf ``` Add the following line. ``` wrapper.java.command=/usr/lib/jvm/jre-openjdk/bin/java ``` Save and close the file when you are done. ## Step 4 – Create a Systemd Service File for SonarQube Next, create a systemd file to manage the SonarQube service. ``` nano /etc/systemd/system/sonarqube.service ``` Add the following lines. ``` [Unit] Description=SonarQube service After=syslog.target network.target [Service] Type=forking ExecStart=/opt/sonarqube/bin/linux-x86-64/sonar.sh start ExecStop=/opt/sonarqube/bin/linux-x86-64/sonar.sh stop LimitNOFILE=65536 LimitNPROC=4096 User=sonar Group=sonar Restart=on-failure [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the SonarQube service. ``` systemctl start sonarqube systemctl enable sonarqube ``` You can verify the SonarQube status using the following command. ``` systemctl status sonarqube ``` Output. ``` ● sonarqube.service - SonarQube service Loaded: loaded (/etc/systemd/system/sonarqube.service; disabled; vendor preset: disabled) Active: active (running) since Sat 2023-05-20 00:16:07 EDT; 4s ago Process: 3092 ExecStart=/opt/sonarqube/bin/linux-x86-64/sonar.sh start (code=exited, status=0/SUCCESS) Main PID: 3115 (java) Tasks: 34 (limit: 4666) Memory: 164.0M CPU: 8.664s CGroup: /system.slice/sonarqube.service ├─3115 java -Xms8m -Xmx32m --add-exports=java.base/jdk.internal.ref=ALL-UNNAMED --add-opens=java.base/java.lang=ALL-UNNAMED --add-opens=java.base/java.nio> └─3140 /usr/lib/jvm/java-17-openjdk-17.0.3.0.7-1.fc34.x86_64/bin/java -XX:+UseG1GC -Djava.io.tmpdir=/opt/sonarqube/temp -XX:ErrorFile=/opt/sonarqube/logs/> May 20 00:16:07 fedora systemd[1]: Starting SonarQube service... May 20 00:16:07 fedora sonar.sh[3092]: /usr/bin/java May 20 00:16:07 fedora sonar.sh[3092]: Starting SonarQube... May 20 00:16:07 fedora sonar.sh[3092]: Started SonarQube. May 20 00:16:07 fedora systemd[1]: Started SonarQube service. ``` ## Step 5 – Access SonarQube Web Dashboard Now, open your web browser and access the SonarQube web UI using the URL **http://server-ip:9000.** You should see the SonarQube login screen. ![Sonarqube Login](https://www.atlantic.net/wp-content/uploads/2023/05/p1-2.png) Provide the default username and password as admin/admin then click on the **Log in** button. You should see the password change screen. ![SOnarqube password change](https://www.atlantic.net/wp-content/uploads/2023/05/p2-7.png) Set your new admin password then click on the **Update** button. You should see the SonarQube dashboard on the following screen. ![Sonarqube dashboard](https://www.atlantic.net/wp-content/uploads/2023/05/p3-3.png) ## Conclusion In this guide, we explained how to install the SonarQube tool on Fedora. You can now add your project from Git or another repository and start analyzing your code via a web-based interface. Try to install SonarQube on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Varnish Cache with Nginx on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-varnish-cache-with-nginx-on-fedora/ | Published: 2023-07-03 | Updated: 2023-11-25 | Author: Hitesh Jethva Varnish is a popular, free, open-source, caching solution used to speed up your web server. It saves the frequently accessed content in memory and serves it from the cache instead of being processed by the web server. Varnish is a web application accelerator and is also used as caching HTTP reverse proxy. It offers very useful features such as Gzip compression, private CDN, HTTP streaming pass & fetch, and more. In this tutorial, we will show you how to install Varnish Cache with Apache on Fedora. ## Step 1 – Install Varnish Cache By default, the Varnish Cache is included in the Fedora default repo. You can install it easily using the following command. ``` dnf install varnish -y ``` After installing Varnish, start and enable the Varnish service using the following command. ``` systemctl start varnish systemctl enable varnish ``` You can verify the Varnish status with the following command. ``` systemctl status varnish ``` Output. ``` ● varnish.service - Varnish Cache, a high-performance HTTP accelerator Loaded: loaded (/usr/lib/systemd/system/varnish.service; disabled; vendor preset: disabled) Active: active (running) since Sat 2023-05-20 05:04:41 EDT; 6s ago Process: 9365 ExecStart=/usr/sbin/varnishd -a :6081 -f /etc/varnish/default.vcl -s malloc,256m (code=exited, status=0/SUCCESS) Main PID: 9366 (varnishd) Tasks: 217 Memory: 90.5M CPU: 750ms CGroup: /system.slice/varnish.service ├─9366 /usr/sbin/varnishd -a :6081 -f /etc/varnish/default.vcl -s malloc,256m └─9386 /usr/sbin/varnishd -a :6081 -f /etc/varnish/default.vcl -s malloc,256m ``` To verify the Varnish version, run the following command. ``` varnishd -V ``` Output. ``` varnishd (varnish-6.5.2 revision e7233b0ad2639043341819d19a8d2e418e94ce1b) Copyright (c) 2006 Verdens Gang AS Copyright (c) 2006-2020 Varnish Software ``` By default, Varnish listens on port 6081. You can check it with the following command. ``` netstat -tunlp | grep 6081 ``` Output. ``` tcp 0 0 0.0.0.0:6081 0.0.0.0:* LISTEN 9366/varnishd tcp6 0 0 :::6081 :::* LISTEN 9366/varnishd ``` ## Step 2 – Install Apache Web Server You can install the Apache server with the following command. ``` dnf install httpd -y ``` After installing the Apache server, start and enable the Apache service with the following command. ``` systemctl start httpd systemctl enable httpd ``` ## Step 3 – Change Apache Default Port Next, you will need to change the Apache default port from 80 to 8080. You can change it with the following command. ``` nano /etc/httpd/conf/httpd.conf ``` Change the following line from 80 to 8080. ``` Listen 8080 ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart httpd ``` Now, verify the Apache listening port using the following command. ``` ss -antpl | grep httpd ``` Output. ``` LISTEN 0 511 *:8080 *:* users:(("httpd",pid=9801,fd=4),("httpd",pid=9800,fd=4),("httpd",pid=9799,fd=4),("httpd",pid=9797,fd=4)) ``` ## Step 4 – Change Varnish Default Port Next, you will also need to edit the Varnish systemd file and change the Varnish port to 80. ``` systemctl edit --full varnish ``` Change the following line as shown below: ``` ExecStart=/usr/sbin/varnishd -a :80 -f /etc/varnish/default.vcl -s malloc,1g ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, restart the Varnish service to apply the changes. ``` systemctl restart varnish ``` ## Step 5 – Verify Varnish At this point, Varnish is installed and configured to listen on port 80. Now, when you make any web request, it will pass via the Varnish server. You can verify the Varnish cache with the following command. ``` curl -I http://localhost ``` If everything is fine, you will see the following output. ``` HTTP/1.1 403 Forbidden Date: Sat, 20 May 2023 09:09:44 GMT Server: Apache/2.4.53 (Fedora) Last-Modified: Fri, 26 Mar 2021 17:49:58 GMT ETag: "211a-5be742910bd80" Accept-Ranges: bytes Content-Length: 8474 Content-Type: text/html; charset=UTF-8 X-Varnish: 2 Age: 0 Via: 1.1 varnish (Varnish/6.5) Connection: keep-alive ``` ## Conclusion In this post, we will show you how to install Varnish with Apache on Fedora. You can now implement a Varnish cache on your web server to speed up the web page delivery. You can now deploy Varnish Cache on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # HIPAA Compliance and the Role of Technology in Healthcare Security > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-and-the-role-of-technology-in-healthcare-security/ | Published: 2023-07-03 | Updated: 2025-09-15 | Author: Richard Bailey The Health Insurance Portability and Accountability Act (HIPAA) stands as a cornerstone in maintaining the privacy and security of patient information. Enacted in 1996, HIPAA sets the standard for protecting sensitive patient data, ensuring that any entity dealing with protected health information (PHI) does so in a manner that preserves the confidentiality and integrity of patient data. Patient health and well-being rely on expert medical professional teams with access to modern healthcare tech. The United States is home to some of the most advanced medical technology in the world. Even the latest cutting-edge technology must be HIPAA compliant, especially when processing and managing patient data. ## The Role of Technology in Healthcare Security Technology has revolutionized healthcare, from electronic health records (EHRs) to telemedicine, wearable devices, and [AI-driven](https://www.atlantic.net/vps-hosting/unleashing-the-power-of-ai-transforming-business-operations-today/) diagnostics. These advancements have improved the quality of care and the efficiency of healthcare delivery. However, with these benefits come challenges, particularly in ensuring the security of the vast amounts of data generated and processed. An Electronic Health Record (EHR) is a secure digital version of a patient’s medical history. Advanced technology protects EHRs through encryption, strong authentication, regular updates, and compliance with privacy regulations like HIPAA. [Telemedicine](https://www.atlantic.net/hipaa-compliant-hosting/a-comprehensive-guide-to-developing-a-telemedicine-application-in-2021/) uses technology to enable remote healthcare services, allowing patients to consult with healthcare professionals from anywhere. Robust security measures, including encryption, authentication, and adherence to privacy regulations, protect patient data during telehealth sessions, ensuring privacy and confidentiality. Telemedicine provides convenient and secure access to healthcare, improving patient experiences and expanding healthcare accessibility. Wearable devices rely on technology to ensure the protection of user data. Advanced encryption techniques are employed to secure the transmission and storage of collected personal information. HIPAA privacy regulations, and the General Data Protection Regulation (GDPR), govern personal data collection, storage, and use. Healthcare organizations increasingly rely on technology to store, process, and transmit PHI. This includes EHRs, cloud-based storage solutions, and digital communication platforms. While these technologies offer numerous benefits, such as improved accessibility to patient data and streamlined communication, they also present potential vulnerabilities that could be exploited, leading to data breaches. ## HIPAA and Technology HIPAA effectively addresses these concerns by providing a comprehensive framework for healthcare organizations to protect and secure patients’ sensitive information, known as Protected Health Information (PHI). One crucial aspect of HIPAA is the Security Rule, which focuses explicitly on safeguarding electronic PHI (ePHI). The Security Rule establishes three distinct types of security safeguards that must be implemented to ensure compliance: ### **#1: Administrative safeguards:** These safeguards involve creating, selecting, implementing, and maintaining security measures that effectively safeguard ePHI. They also encompass the management of workforce behavior regarding protecting this sensitive information. Specific examples include: - Implementing comprehensive security policies and procedures, such as access control and authentication measures, to regulate and monitor the workforce’s access to ePHI. - Conducting regular risk assessments and vulnerability scans to identify potential security gaps and mitigate risks. - Providing ongoing security training and awareness programs for employees to educate them about best practices for safeguarding ePHI. - Developing and implementing incident response plans to address and mitigate security breaches or incidents effectively. ### **#2: Physical safeguards: ** These safeguards comprise tangible measures, policies, and procedures to protect electronic information systems, infrastructure, and equipment against natural hazards, environmental threats, and unauthorized access. The objective is to create a physical barrier preventing unauthorized individuals from accessing ePHI. - Installing security cameras and access control systems to monitor and control physical access to areas where electronic information systems and equipment storing ePHI are located. - Implementing measures such as locked server rooms, secure cabinets, and biometric authentication systems to restrict physical access to ePHI. - Safely disposing of physical media (such as hard drives, CDs, or printed records) that contain ePHI through secure destruction methods like shredding or degaussing. ### **#3: Technical safeguards: ** These safeguards encompass the utilization of technology, in conjunction with appropriate policies and procedures, to secure ePHI and control access to it. This involves implementing robust technological measures that protect electronic information from unauthorized disclosure or alteration. - Encrypting ePHI during storage and transmission protects it from unauthorized access or interception. For example, secure protocols like SSL/TLS are used for data transmission over networks. - Implementing firewalls and intrusion detection systems to monitor and control network traffic and identify potential threats or unauthorized access attempts. - Requiring strong passwords, multi-factor authentication, or biometric verification for accessing systems or applications containing ePHI. - Regularly applying security patches and updates to software, operating systems, and applications to address known vulnerabilities. If you would like to know more, look at our [HIPAA Checklist for 2023](https://www.atlantic.net/hipaa-data-centers/hipaa-compliant-it-infrastructure-guide/). ## Conclusion In conclusion, HIPAA compliance is critical to healthcare security, particularly in technology. As healthcare organizations continue to adopt and integrate new technologies, the importance of adhering to HIPAA regulations cannot be overstated. By doing so, healthcare organizations can ensure the privacy and security of patient data and improve the quality and efficiency of care delivery. Navigating the complexities of HIPAA compliance can be challenging, particularly regarding technology. However, you don’t have to do it alone. Atlantic.Net offers award-winning [HIPAA-compliant hosting services](https://www.atlantic.net/hipaa-compliant-hosting/), providing secure, reliable, and compliant solutions tailored to your organization’s needs. [Contact Atlantic.Net](https://www.atlantic.net/about-us/corporate-contact/) today to learn how we can help you ensure the security and compliance of your healthcare technology systems. --- # How to Install Teamspeak 3 Server on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-teamspeak-3-server-on-fedora/ | Published: 2023-07-04 | Updated: 2023-11-26 | Author: Hitesh Jethva TeamSpeak is a popular open-source VoIP communication system for online gaming. It is very similar to a telephone conference call and is used for audio communication between users on a chat channel. It is cross-platform and allows multiple users to talk or listen to other TeamSpeak users. It offers a wide range of features including good voice quality, less bandwidth usage, in-game overlay, real-time communication, an intuitive user interface, and more. In this post, we will show you how to install a TeamSpeak server on Fedora. ## Step 1 – Install TeamSpeak Server First, you will need to install some dependencies on your server. You can install all of them with the following command. ``` dnf update -y dnf install nano wget perl tar net-tools bzip2 ``` Next, create a dedicated user to run the TeamSpeak server. ``` adduser teamspeak -d /opt/teamspeak ``` Next, download the latest version of TeamSpeak from its official website. ``` wget https://files.teamspeak-services.com/releases/server/3.13.7/teamspeak3-server_linux_amd64-3.13.7.tar.bz2 ``` Once the download is finished, extract the downloaded file. ``` tar -xvjf teamspeak3-server_linux_amd64-3.13.7.tar.bz2 ``` Next, move the extracted directory to /opt and change its ownership. ``` mv teamspeak3-server_linux_amd64/* /opt/teamspeak/ chown -R teamspeak: /opt/teamspeak ``` Next, create a license file for the TeamSpeak server. ``` touch /opt/teamspeak/.ts3server_license_accepted ``` ## Step 2 – Create a Systemd Service File Next, you will need to create a systemd service file to manage the TeamSpeak service. You can create it with the following command. ``` nano /lib/systemd/system/teamspeak.service ``` Add the following configurations. ``` [Unit] Description=Team Speak 3 Server After=network.target [Service] WorkingDirectory=/opt/teamspeak/ User=teamspeak Group=teamspeak Type=forking ExecStart=/opt/teamspeak/ts3server_startscript.sh start inifile=ts3server.ini ExecStop=/opt/teamspeak/ts3server_startscript.sh stop PIDFile=/opt/teamspeak/ts3server.pid RestartSec=15 Restart=always [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl --system daemon-reload ``` Then, start the TeamSpeak service and enable it to start at system reboot. ``` systemctl start teamspeak systemctl enable teamspeak ``` You can check the status of TeamSpeak using the following command. ``` systemctl status teamspeak ``` Output. ``` ● teamspeak.service - Team Speak 3 Server Loaded: loaded (/usr/lib/systemd/system/teamspeak.service; disabled; vendor preset: disabled) Active: active (running) since Tue 2023-06-06 03:27:55 EDT; 4s ago Process: 28389 ExecStart=/opt/teamspeak/ts3server_startscript.sh start inifile=ts3server.ini (code=exited, status=0/SUCCESS) Main PID: 28396 (ts3server) Tasks: 21 (limit: 4666) Memory: 19.9M CPU: 3.887s CGroup: /system.slice/teamspeak.service └─28396 ./ts3server inifile=ts3server.ini daemon=1 pid_file=ts3server.pid ``` ``` Jun 06 03:27:55 fedora ts3server_startscript.sh[28396]: apikey= "BAB8M-HTaXJwunk8MOsGOMja4eODG-f5k0EEICI" Jun 06 03:27:55 fedora ts3server_startscript.sh[28396]: ------------------------------------------------------------------ Jun 06 03:27:57 fedora ts3server_startscript.sh[28396]: ------------------------------------------------------------------ Jun 06 03:27:57 fedora ts3server_startscript.sh[28396]: I M P O R T A N T Jun 06 03:27:57 fedora ts3server_startscript.sh[28396]: ------------------------------------------------------------------ Jun 06 03:27:57 fedora ts3server_startscript.sh[28396]: ServerAdmin privilege key created, please use it to gain Jun 06 03:27:57 fedora ts3server_startscript.sh[28396]: serveradmin rights for your virtualserver. please Jun 06 03:27:57 fedora ts3server_startscript.sh[28396]: also check the doc/privilegekey_guide.txt for details. Jun 06 03:27:57 fedora ts3server_startscript.sh[28396]: token=yiVk2d4Kuh5NxREKL69lXw23w83L5rxTy7tDt7UG Jun 06 03:27:57 fedora ts3server_startscript.sh[28396]: ------------------------------------------------------------------ ``` You can check the TeamSpeak logs for more information. ``` cat /opt/teamspeak/logs/* ``` Output. ``` 2023-06-06 07:27:55.821060|INFO |ServerLibPriv | |TeamSpeak 3 Server 3.13.7 (2022-06-20 12:21:53) 2023-06-06 07:27:55.821228|INFO |ServerLibPriv | |SystemInformation: Linux 5.12.8-300.fc34.x86_64 #1 SMP Fri May 28 15:20:54 UTC 2021 x86_64 Binary: 64bit 2023-06-06 07:27:55.826637|INFO |DatabaseQuery | |dbPlugin name: SQLite3 plugin, Version 3, (c)TeamSpeak Systems GmbH 2023-06-06 07:27:55.826714|INFO |DatabaseQuery | |dbPlugin version: 3.11.1 2023-06-06 07:27:55.827188|INFO |DatabaseQuery | |checking database integrity (may take a while) 2023-06-06 07:27:55.842195|INFO |SQL | |db_CreateTables() tables created 2023-06-06 07:27:55.888533|WARNING |Accounting | |Unable to open licensekey.dat, falling back to limited functionality 2023-06-06 07:27:55.889007|INFO |Accounting | |Licensing Information 2023-06-06 07:27:55.889049|INFO |Accounting | |licensed to : Anonymous 2023-06-06 07:27:55.889066|INFO |Accounting | |type : No License 2023-06-06 07:27:55.889088|INFO |Accounting | |starting date : Tue Feb 1 00:00:00 2022 2023-06-06 07:27:55.889105|INFO |Accounting | |ending date : Thu Jul 1 00:00:00 2027 2023-06-06 07:27:55.889120|INFO |Accounting | |max virtualservers: 1 2023-06-06 07:27:55.889134|INFO |Accounting | |max slots : 32 2023-06-06 07:27:57.249724|INFO | | |Puzzle precompute time: 1293 2023-06-06 07:27:57.250634|INFO |FileManager | |listening on 0.0.0.0:30033, [::]:30033 2023-06-06 07:27:57.251912|INFO |VirtualSvrMgr | |executing monthly interval 2023-06-06 07:27:57.252123|INFO |VirtualSvrMgr | |reset virtualserver traffic statistics 2023-06-06 07:27:57.286585|INFO |Query | |Using a query thread pool size of 2 2023-06-06 07:27:57.313059|INFO |Query | |listening for query on 0.0.0.0:10011, [::]:10011 2023-06-06 07:27:57.313285|INFO | | |creating QUERY_SSH_RSA_HOST_KEY file: ssh_host_rsa_key 2023-06-06 07:27:58.216597|INFO | | |myTeamSpeak identifier revocation list was downloaded successfully - all related features are activated 2023-06-06 07:27:58.683529|INFO |Query | |listening for ssh query on 0.0.0.0:10022, [::]:10022 2023-06-06 07:27:58.683752|INFO |Query | |listening for http query on 0.0.0.0:10080, [::]:10080 2023-06-06 07:27:58.684059|INFO |CIDRManager | |updated query_ip_allowlist ips: 127.0.0.1/32, ::1/128, 2023-06-06 07:27:57.311762|INFO |VirtualServerBase|1 |listening on 0.0.0.0:9987, [::]:9987 2023-06-06 07:27:57.312526|WARNING |VirtualServer |1 |-------------------------------------------------------- 2023-06-06 07:27:57.312560|WARNING |VirtualServer |1 |ServerAdmin privilege key created, please use the line below 2023-06-06 07:27:57.312577|WARNING |VirtualServer |1 |token=yiVk2d4Kuh5NxREKL69lXw23w83L5rxTy7tDt7UG ``` ## Step 3 – Configure Firewall The TeamSpeak server is now installed and listens on ports 10011, 9987, and 30033. You can check them using the following command. ``` ss -antpl | grep ts3server ``` Output. ``` LISTEN 0 128 0.0.0.0:10011 0.0.0.0:* users:(("ts3server",pid=28396,fd=55)) LISTEN 0 128 0.0.0.0:10080 0.0.0.0:* users:(("ts3server",pid=28396,fd=60)) LISTEN 0 128 0.0.0.0:10022 0.0.0.0:* users:(("ts3server",pid=28396,fd=58)) LISTEN 0 128 0.0.0.0:30033 0.0.0.0:* users:(("ts3server",pid=28396,fd=35)) LISTEN 0 128 [::]:10011 [::]:* users:(("ts3server",pid=28396,fd=56)) LISTEN 0 128 [::]:10080 [::]:* users:(("ts3server",pid=28396,fd=61)) LISTEN 0 128 [::]:10022 [::]:* users:(("ts3server",pid=28396,fd=59)) LISTEN 0 128 [::]:30033 [::]:* users:(("ts3server",pid=28396,fd=36)) ``` Now, run the following commands to allow all TeamSpeak ports. ``` firewall-cmd --zone=public --add-port=9987/udp --permanent firewall-cmd --zone=public --add-port=10011/tcp --permanent firewall-cmd --zone=public --add-port=30033/tcp --permanent ``` Next, reload the firewall service to implement the changes. ``` firewall-cmd --reload ``` ## Conclusion Congratulations! You have successfully installed and configured the TeamSpeak server on Fedora. You can now download the TeamSpeak client on your mobile or PC, join the TeamSpeak server and start communicating with other members. You can also install the TeamSpeak server on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Monit Monitoring Tool on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-monit-monitoring-tool-on-fedora/ | Published: 2023-07-05 | Updated: 2023-11-25 | Author: Hitesh Jethva Monit is a free, lightweight, low-resource usage monitoring solution for Linux-based operating systems. It is easy to set up and can monitor different services, CPU usage, memory usage, uptime, load, and more. It also restarts any services automatically if it fails. If there are problems, one or more recipients will be informed by email. You can configure Monit to monitor server applications, network connections and services, harddisks, sha1 checksum of files, size change, timestamp, folder change, and more. This post will show you how to install the Monit monitoring tool on Fedora. ## Step 1 – Install Monit By default, the Monit package is included in the Fedora default repo. You can install it easily using the following command. ``` dnf install monit ``` Once the Monit is installed, you can run it using the following command. ``` monit ``` Output. ``` New Monit id: d6c8428d05bae2b22aabf013036d2919 Stored in '/root/.monit.id' Starting Monit 5.30.0 daemon with http interface at [localhost]:2812 ``` You can now check basic system information using the following command. ``` monit status ``` Output. ``` Monit 5.30.0 uptime: 0m System 'fedora' status OK monitoring status Monitored monitoring mode active on reboot start load average [0.50] [0.25] [0.15] cpu 0.0%usr 0.0%sys 0.0%nice 0.0%iowait 0.0%hardirq 0.0%softirq 0.0%steal 0.0%guest 0.0%guestnice memory usage 282.6 MB [14.3%] swap usage 0 B [0.0%] uptime 15m boot time Tue, 06 Jun 2023 12:46:10 filedescriptors 1888 [0.0% of 9223372036854775807 limit] data collected Tue, 06 Jun 2023 13:01:05 ``` ## Step 2 – Configure Monit Next, you must edit the Monit configuration file to set an admin password, enable the web UI, and allow outside access. ``` nano /etc/monitrc ``` Change the following lines. ``` set httpd port 2812 #use address localhost => only accept connection from localhost (drop if you use M/Monit) use address 0.0.0.0 allow 0.0.0.0/0 allow admin:monit ``` Save and close the file, then reload the Monit to apply the changes. ``` monit reload ``` ## Step 3 – Access Monit Web UI At this point, Monit is installed and listens on port 2812. Now, open your web browser and access the Monit web dashboard using the URL **http://your-server-ip:2812.** You should see the Monit monitoring dashboard on the following screen. ![monit dashboard](https://www.atlantic.net/wp-content/uploads/2023/06/p1-3.jpg) Provide your Monit admin username and password and click the **Sign in** button. You should see the Monit dashboard on the following screen. ![monit dashboard](https://www.atlantic.net/wp-content/uploads/2023/06/p2-2.jpg) ## Step 4 – Monitor Nginx with Monit To monitor a service, you will need to configure Monit for that service. In this section, we will configure Monit to monitor the Nginx service. First, install the Nginx package using the following command. ``` dnf install nginx ``` Next, start and enable the Nginx service to start at system reboot. ``` systemctl start nginx systemctl enable nginx ``` Next, create a new Monit configuration file. ``` nano /etc/monit.d/nginx-monitor ``` Add the following configurations. ``` check process nginx with pidfile /run/nginx.pid start program "/usr/bin/systemctl start nginx.service" stop program "/usr/bin/systemctl stop nginx.service" if failed port 80 protocol http then restart ``` Save and close the file, then verify Monit for any syntax errors. ``` monit -t ``` Output. ``` Control file syntax OK ``` Next, reload the Monit service to implement the changes. ``` monit reload ``` Next, monitor the Nginx service via the command line. ``` monit status ``` You should see the Nginx service status in the following output. ``` Monit 5.30.0 uptime: 2m Process 'nginx' status OK monitoring status Monitored monitoring mode active on reboot start pid 2201 parent pid 1 uid 0 effective uid 0 gid 0 uptime 0m threads 1 children 1 cpu - cpu total - memory 0.1% [1.2 MB] memory total 0.3% [6.1 MB] security attribute kernel filedescriptors 13 [1.3% of 1024 limit] total filedescriptors 30 read bytes 0 B/s [0 B total] disk read bytes 0 B/s [0 B total] disk read operations 0.0 reads/s [0 reads total] write bytes 0 B/s [0 B total] disk write bytes 0 B/s [0 B total] disk write operations 0.0 writes/s [0 writes total] port response time 0.882 ms to localhost:80 type TCP/IP protocol HTTP data collected Tue, 06 Jun 2023 13:06:21 System 'fedora' status OK monitoring status Monitored monitoring mode active on reboot start load average [0.78] [0.34] [0.18] cpu 0.9%usr 0.9%sys 0.0%nice 0.0%iowait 0.1%hardirq 0.1%softirq 2.4%steal 0.0%guest 0.0%guestnice memory usage 287.2 MB [14.5%] swap usage 0 B [0.0%] uptime 20m boot time Tue, 06 Jun 2023 12:46:10 filedescriptors 1920 [0.0% of 9223372036854775807 limit] data collected Tue, 06 Jun 2023 13:06:21 ``` You can also open the Monit dashboard to monitor Nginx via a web browser. ![Monitor Nginx](https://www.atlantic.net/wp-content/uploads/2023/06/p5.jpg) ## Step 5 – Verify Monit Functionality One of the best advantages of Monit is that it can start any service automatically if it stops. Let’s stop the Nginx service using the following command to test it. ``` systemctl stop nginx ``` Next, verify the log file to check whether the Monit starts the Nginx service. ``` tail -f /var/log/messages ``` The following output indicates that the Nginx service is started automatically by Monit. ``` Jun 6 13:07:51 fedora monit[1263]: 'nginx' process is not running Jun 6 13:07:51 fedora monit[1263]: 'nginx' trying to restart Jun 6 13:07:51 fedora monit[1263]: 'nginx' start: '/usr/bin/systemctl start nginx.service' Jun 6 13:07:51 fedora systemd[1]: Starting The nginx HTTP and reverse proxy server... Jun 6 13:07:51 fedora nginx[2242]: nginx: the configuration file /etc/nginx/nginx.conf syntax is ok Jun 6 13:07:51 fedora nginx[2242]: nginx: configuration file /etc/nginx/nginx.conf test is successful Jun 6 13:07:51 fedora systemd[1]: Started The nginx HTTP and reverse proxy server. Jun 6 13:07:51 fedora audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=kernel msg='unit=nginx comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' ``` You can also check the Nginx active status with the following command. ``` systemctl status nginx ``` Output. ``` ● nginx.service - The nginx HTTP and reverse proxy server Loaded: loaded (/usr/lib/systemd/system/nginx.service; disabled; vendor preset: disabled) Active: active (running) since Tue 2023-06-06 13:07:51 EDT; 22s ago Process: 2241 ExecStartPre=/usr/bin/rm -f /run/nginx.pid (code=exited, status=0/SUCCESS) Process: 2242 ExecStartPre=/usr/sbin/nginx -t (code=exited, status=0/SUCCESS) Process: 2243 ExecStart=/usr/sbin/nginx (code=exited, status=0/SUCCESS) Main PID: 2244 (nginx) Tasks: 2 (limit: 2328) Memory: 2.2M CPU: 80ms CGroup: /system.slice/nginx.service ├─2244 nginx: master process /usr/sbin/nginx └─2245 nginx: worker process Jun 06 13:07:51 fedora systemd[1]: Starting The nginx HTTP and reverse proxy server... Jun 06 13:07:51 fedora nginx[2242]: nginx: the configuration file /etc/nginx/nginx.conf syntax is ok Jun 06 13:07:51 fedora nginx[2242]: nginx: configuration file /etc/nginx/nginx.conf test is successful Jun 06 13:07:51 fedora systemd[1]: Started The nginx HTTP and reverse proxy server. ``` ## Conclusion This post explained how to install and configure the Monit monitoring solution on Fedora Linux. You can now add more services to Monit and start monitoring them from the central dashboard. You can deployMonit monitoring solution on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install GlassFish Server on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-glassfish-server-on-fedora/ | Published: 2023-07-06 | Updated: 2023-11-15 | Author: Hitesh Jethva GlassFish is an open-source platform used to host Java applications. It allows web developers to easily build scalable and portable Java applications. GlassFish also enables high availability clustering and load balancing and supports different user authentication methods such as file-based, LDAP, certificate, JDBC, digest, PAM, Solaris, and custom realms. In this post, we will show you how to install GlassFish 7 on Fedora. ## Step 1 – Install Java JDK GlassFish is a Java-based application, so you will need to install Java JDK on your server. You can install it using the following command. ``` dnf install java-11-openjdk ``` After the Java installation, you can verify the Java version using the following command. ``` java -version ``` Output. ``` openjdk version "11.0.15" 2022-04-19 OpenJDK Runtime Environment 18.9 (build 11.0.15+10) OpenJDK 64-Bit Server VM 18.9 (build 11.0.15+10, mixed mode, sharing) ``` ## Step 2 – Install GlassFish First, create a dedicated user to run GlassFish. ``` useradd -m -d /opt/glassfish6 -U -s /bin/false glassfish ``` Next, download the latest version of GlassFish using the following command. ``` wget https://www.eclipse.org/downloads/download.php?file=/ee4j/glassfish/glassfish-7.0.5.zip -O glassfish-7.0.5.zip ``` Next, unzip the downloaded file with the following command. ``` unzip glassfish-7.0.5.zip ``` Next, move the extracted directory to the /opt directory. ``` mv glassfish7 /opt/glassfish ``` Next, change the ownership of the glassfish directory. ``` chown -R glassfish:glassfish /opt/glassfish ``` ## Step 3 – Create a Systemd Service File Next, you will need to create a systemd service file to manage the GlassFish service via systemctl command. ``` nano /lib/systemd/system/glassfish.service ``` Add the following configurations. ``` [Unit] Description = GlassFish Server v7 After = syslog.target network.target [Service] User=glassfish ExecStart=/opt/glassfish/bin/asadmin start-domain ExecReload=/opt/glassfish/bin/asadmin restart-domain ExecStop=/opt/glassfish/bin/asadmin stop-domain Type = forking [Install] WantedBy = multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Now, start and enable the GlassFish service. ``` systemctl start glassfish systemctl enable glassfish ``` You can also check the GlassFish status with the following command. ``` systemctl status glassfish ``` You will see the following output. ``` ● glassfish.service - GlassFish Server v7 Loaded: loaded (/usr/lib/systemd/system/glassfish.service; disabled; vendor preset: disabled) Active: active (running) since Sat 2023-06-24 06:58:42 EDT; 7s ago Process: 48226 ExecStart=/opt/glassfish/bin/asadmin start-domain (code=exited, status=0/SUCCESS) Main PID: 48246 (java) Tasks: 95 (limit: 4666) Memory: 334.8M CPU: 35.922s CGroup: /system.slice/glassfish.service └─48246 /usr/lib/jvm/java-11-openjdk-11.0.15.0.10-1.fc34.x86_64/bin/java -cp /opt/glassfish/glassfish/modules/glassfish.jar -DWALL_CLOCK_START=2023-06-24T> Jun 24 06:58:24 fedora systemd[1]: Starting GlassFish Server v7... ``` ## Step 4 – Set GlassFish Admin Password By default, the GlassFish default admin password is not set, so you will need to set it before login GlassFish via web browser. You can set the admin password using the following command. ``` sudo -u glassfish /opt/glassfish/bin/asadmin --port 4848 change-admin-password ``` You will be asked to provide the username. ``` Enter admin user name [default: admin]>admin ``` Provide the admin user and hit the Enter key. You will be asked to provide the admin password. ``` Enter the admin password> ``` Just press the Enter key. You will be asked to set a new password. ``` Enter the new admin password> Enter the new admin password again> Command change-admin-password executed successfully. ``` By default, GlassFish web-based login is disabled, so you will also need to enable it via command line. ``` sudo -u glassfish /opt/glassfish/bin/asadmin --port 4848 enable-secure-admin ``` Provide your admin password to enable the secure login. ``` Enter admin user name> admin Enter admin password for user "admin"> You must restart all running servers for the change in secure admin to take effect. Command enable-secure-admin executed successfully. ``` Finally, restart the GlassFish service to apply the changes. ``` systemctl restart glassfish ``` ## Step 5 – Access GlassFish Web UI At this point, GlassFish is installed and configured. Now, open your web browser and access the GlassFish test page using the URL **http://your-server-ip:8080.** ![](https://www.atlantic.net/wp-content/uploads/2023/06/glassfish-test-page.png) You can also access the GlassFish admin panel using the URL **http://your-server-ip:4848.** You should see the GlassFish login screen. ![](https://www.atlantic.net/wp-content/uploads/2023/06/glassfish-login-page.png) Provide your admin username and password and click on **Login.** You should see the GlassFish dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/06/glassfish-dashboard.png) ## Conclusion In this post, we showed you how to install GlassFish on Fedora. We also set the GlassFish admin password and enable the secure login. You can now start deploying your Java application using the GlassFish platform. You can now deploy GlassFish on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure Nagios on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-nagios-on-fedora/ | Published: 2023-07-07 | Updated: 2023-11-13 | Author: Hitesh Jethva Nagios is a free and open-source monitoring solution that helps system administrators keep an eye on network infrastructure. It allows you to add and monitor remote servers, switches, and routers from a single place. Nagios offers a lot of plugins that help you to add additional functionality to your server. Nagios makes it easier to quickly detect any issues on servers and send alerts to minimize application downtime for users. In this tutorial, we will show you how to install the Nagios monitoring server on Fedora. ## Step 1 – Install Required Dependencies Before starting, you will need to install Apache, PHP, and additional required dependencies on your server. You can install all of them using the following command. ``` dnf install httpd httpd-tools php gcc glibc glibc-common gd gd-devel make net-snmp openssl-devel -y ``` Once all the packages are installed, you can proceed to the next step. ## Step 2 – Install Nagios By default, the Nagios package is not available in the Fedora default repo, so you will need to compile it from the source. First, add a Nagios user and add it to the Nagios group. ``` useradd nagios usermod -G nagios nagios ``` Also, add the Apache user to the Nagios group. ``` usermod -G nagios apache ``` Next, create a directory for Nagios. ``` mkdir /root/nagios ``` Then, navigate inside the Nagios directory and download the latest version of Nagios and Nagios plugins. ``` cd /root/nagios wget https://assets.nagios.com/downloads/nagioscore/releases/nagios-4.4.9.tar.gz wget https://nagios-plugins.org/download/nagios-plugins-2.3.3.tar.gz ``` Next, extract both downloaded files. ``` tar -xf nagios-4.4.9.tar.gz tar -xf nagios-plugins-2.3.3.tar.gz ``` Next, change the directory to the extracted directory and configure it with the following command. ``` cd nagios-4.4.9/ ./configure --with-command-group=nagios ``` Output: ``` General Options: ------------------------- Nagios executable: nagios Nagios user/group: nagios,nagios Command user/group: nagios,nagios Event Broker: yes Install ${prefix}: /usr/local/nagios Install ${includedir}: /usr/local/nagios/include/nagios Lock file: /run/nagios.lock Check result directory: /usr/local/nagios/var/spool/checkresults Init directory: /lib/systemd/system Apache conf.d directory: /etc/httpd/conf.d Mail program: /bin/mail Host OS: linux-gnu IOBroker Method: epoll Web Interface Options: ------------------------ HTML URL: http://localhost/nagios/ CGI URL: http://localhost/nagios/cgi-bin/ Traceroute (used by WAP): /usr/bin/traceroute ``` Next, install the Nagios using the following command. ``` make all make install ``` Next, install the Init script, command mode, and sample configuration files using the following command. ``` make install-init make install-commandmode make install-config ``` Next, install the Nagios web interface using the following command. ``` make install-webconf ``` Next, create a user and password for Nagios. ``` htpasswd -s -c /usr/local/nagios/etc/htpasswd.users nagiosadmin ``` Set your password as shown below. ``` New password: Re-type new password: Adding password for user nagiosadmin ``` Next, restart the Apache service to apply the changes. ``` systemctl restart httpd ``` ## Step 3 – Install Nagios Plugins First, change the directory to the Nagios plugins and configure it with the following command. ``` cd /root/nagios/nagios-plugins-2.3.3 ./configure --with-nagios-user=nagios --with-nagios-group=nagios ``` Now, install it with the following command. ``` make make install ``` Now, verify the Nagios configuration using the following command. ``` /usr/local/nagios/bin/nagios -v /usr/local/nagios/etc/nagios.cfg ``` If everything is fine, you will see the following output. ``` Checking objects... Checked 8 services. Checked 1 hosts. Checked 1 host groups. Checked 0 service groups. Checked 1 contacts. Checked 1 contact groups. Checked 24 commands. Checked 5 time periods. Checked 0 host escalations. Checked 0 service escalations. Checking for circular paths... Checked 1 hosts Checked 0 service dependencies Checked 0 host dependencies Checked 5 timeperiods Checking global event handlers... Checking obsessive compulsive processor commands... Checking misc settings... Total Warnings: 0 Total Errors: 0 Things look okay - No serious problems were detected during the pre-flight check ``` ## Step 4 – Start Nagios Service At this point, Nagios is installed on your server. Now, enable the Apache and Nagios service using the following command. ``` systemctl enable nagios systemctl enable httpd ``` Then, restart the Nagios service to apply the changes. ``` systemctl restart nagios ``` You can verify the status of Nagios using the following command. ``` systemctl status nagios ``` You will see the following output. ``` ● nagios.service - Nagios Core 4.4.9 Loaded: loaded (/usr/lib/systemd/system/nagios.service; disabled; vendor preset: disabled) Active: active (running) since Sat 2023-06-24 06:46:41 EDT; 8s ago Docs: https://www.nagios.org/documentation Process: 47713 ExecStartPre=/usr/local/nagios/bin/nagios -v /usr/local/nagios/etc/nagios.cfg (code=exited, status=0/SUCCESS) Process: 47714 ExecStart=/usr/local/nagios/bin/nagios -d /usr/local/nagios/etc/nagios.cfg (code=exited, status=0/SUCCESS) Main PID: 47715 (nagios) Tasks: 6 (limit: 4666) Memory: 5.0M CPU: 81ms CGroup: /system.slice/nagios.service ├─47715 /usr/local/nagios/bin/nagios -d /usr/local/nagios/etc/nagios.cfg ├─47717 /usr/local/nagios/bin/nagios --worker /usr/local/nagios/var/rw/nagios.qh ├─47718 /usr/local/nagios/bin/nagios --worker /usr/local/nagios/var/rw/nagios.qh ├─47719 /usr/local/nagios/bin/nagios --worker /usr/local/nagios/var/rw/nagios.qh ├─47720 /usr/local/nagios/bin/nagios --worker /usr/local/nagios/var/rw/nagios.qh └─47721 /usr/local/nagios/bin/nagios -d /usr/local/nagios/etc/nagios.cfg ``` ## Step 5 – Access Nagios Web Interface At this point, Nagios is installed and running on your server. Now, open your web browser and access the Nagios web UI using the URL **http://your-server-ip/nagios.** You will see the Nagios login screen. ![](https://www.atlantic.net/wp-content/uploads/2023/06/nagios-login.png) Provide your username, password and click on the **Sign in** button. After the successful authentication, you should see the Nagios dashboard. ![](https://www.atlantic.net/wp-content/uploads/2023/06/nagios-dashboard.png) Click on the **Hosts** in the left pane, you will see your host information on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/06/nagios-localhost-info.png) ## Conclusion In this post, we showed you how to install Nagios from the source on Fedora. You can now add remote servers to your Nagios server and start monitoring them from the Nagios UI. Try to implement the Nagios monitoring server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Apache with Nginx as a Reverse Proxy on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-with-nginx-as-a-reverse-proxy-on-fedora/ | Published: 2023-07-08 | Updated: 2024-06-01 | Author: Hitesh Jethva Apache and Nginx are very popular and powerful web servers used to host websites on the internet. Each web server has its own pros and cons. When you are planning to host multiple websites on a single server which has varied requirements, you should use Apache as a web server and use Nginx as a reverse proxy server in front of the Apache webserver to handle a large number of requests. This post will show you how to use Nginx as a reverse proxy in front of the Apache web server on Fedora. ## Step 1 – Install Apache and PHP First, install Apache and PHP packages with the following command. ``` dnf install httpd php php-cli -y ``` Next, you will need to configure Apache to run as a backend web server on a non-standard port. You can do it by editing the Apache main configuration file. ``` nano /etc/httpd/conf/httpd.conf ``` Change the listen port from 80 to 8080 as shown below. ``` Listen 8080 ``` Save and close the file, then restart the Apache service to implement the changes. ``` systemctl restart httpd ``` Next, verify the Apache listening port using the following command. ``` ss -antpl | grep httpd ``` You will see the following output. ``` LISTEN 0 511 *:8080 *:* users:(("httpd",pid=11652,fd=4),("httpd",pid=11651,fd=4),("httpd",pid=11650,fd=4),("httpd",pid=11648,fd=4)) ``` Now, create a sample PHP file to test the Apache server. ``` nano /var/www/html/info.php ``` Add the following code. ``` ``` Save and close the file, then open your web browser and access the PHP page using the URL **http://your-server-ip:8080/info.php.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/06/apache-php-info-page.png) ## Step 2 – Configure Nginx as a Reverse Proxy Now, you will need to configure Nginx as a reverse proxy for the Apache backend server. First, install the Nginx server with the following command. ``` dnf install nginx -y ``` Next, start and enable the Nginx service with the following command. ``` systemctl start nginx systemctl enable nginx ``` Next, create an Nginx virtual host configuration file. ``` nano /etc/nginx/conf.d/proxy.conf ``` Add the following lines. ``` server { listen 80; server_name test.example.com; location ~ \.php$ { proxy_pass http://your-server-ip:8080; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } } ``` Save and close the file, then restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 3 – Verify Nginx Server At this point, Nginx is installed and configured as a reverse proxy for the Apache server. You can now access your PHP page via Nginx using the URL **http://test.example.com.** ![](https://www.atlantic.net/wp-content/uploads/2023/06/apache-php-info-page.png) ## Conclusion In this post, we showed you how to install Apache and configured it as a backend server. Then, we explained how to use Nginx as a reverse proxy to forward all requests to the Apache web server. Now you can implement high-performance websites on a single server. You can now try to use Nginx as a reverse proxy on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Fail2Ban to Secure SSH Server on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-fail2ban-to-secure-ssh-server-on-fedora/ | Published: 2023-07-09 | Updated: 2024-06-02 | Author: Hitesh Jethva Fail2ban is an open-source intrusion prevention tool used to add firewall rules to reject IP addresses for a specified amount of time. It is written in Python and designed to protect servers from brute-force attacks. Fail2ban continuously monitors the system logs for any malicious activity and scans files for any entries matching identified patterns. If any matching pattern is found, then Fail2ban blocks the destination IP for a specified amount of time. In this post, we will show you how to install Fail2ban to protect the SSH server on Fedora. ## Step 1 – Install Fail2ban By default, Fail2ban is included in the Fedora default repository. You can install it by running the following command. ``` dnf install fail2ban -y ``` Once the Fail2ban is installed, start and enable the Fail2ban service using the following command. ``` systemctl start fail2ban systemctl enable fail2ban ``` ## Step 2 – Configure Fail2ban Next, you will need to create a Fail2ban configuration file for SSH service. You can create it with the following command. ``` nano /etc/fail2ban/jail.local ``` Add the following lines. ``` [DEFAULT] ignoreip = your-server-ip bantime = 300 findtime = 300 maxretry = 3 banaction = iptables-multiport backend = systemd [sshd] enabled = true ``` Save and close the file, then restart the Fail2ban to apply the changes. ``` systemctl restart fail2ban ``` You can also check the status of Fail2ban with the following command. ``` systemctl status fail2ban ``` Output. ``` ● fail2ban.service - Fail2Ban Service Loaded: loaded (/usr/lib/systemd/system/fail2ban.service; disabled; vendor preset: disabled) Active: active (running) since Sat 2023-06-24 03:55:11 EDT; 7s ago Docs: man:fail2ban(1) Process: 12514 ExecStartPre=/bin/mkdir -p /run/fail2ban (code=exited, status=0/SUCCESS) Main PID: 12515 (fail2ban-server) Tasks: 5 (limit: 9497) Memory: 11.4M CPU: 257ms CGroup: /system.slice/fail2ban.service └─12515 /usr/bin/python3 -s /usr/bin/fail2ban-server -xf start Jun 24 03:55:11 fedora systemd[1]: Starting Fail2Ban Service... Jun 24 03:55:11 fedora systemd[1]: Started Fail2Ban Service. Jun 24 03:55:11 fedora fail2ban-server[12515]: Server ready ``` ## Step 3 – Verify Fail2ban At this point, Fail2ban is installed and configured to protect your SSH server. Now, it’s time to verify it. First, check the added SSH service using the following command. ``` fail2ban-client status ``` Output. ``` Status |- Number of jail: 1 `- Jail list: sshd ``` Try to connect your SSH server from any remote machine with an incorrect password three times. ``` ssh root@your-server-ip ``` After three failed attempts you are blocked from authentication for five minutes. Now, run the following command on your SSH server to check the IP address blocked by Fail2ban. ``` fail2ban-client status sshd ``` You will see the following output. ``` Status for the jail: sshd |- Filter | |- Currently failed: 3 | |- Total failed: 12 | `- Journal matches: _SYSTEMD_UNIT=sshd.service + _COMM=sshd `- Actions |- Currently banned: 1 |- Total banned: 2 `- Banned IP list: 190.1.81.12 ``` You can also check the log file to see the blocked IP. ``` tail -5 /var/log/secure | grep 'Failed password' ``` Output: ``` June 24 03:15:03 fedora sshd[11196]: Failed password for invalid user root from 190.1.81.12 port 55738 ssh2 ``` If you want to unblock the blocked IP address, run the following command. ``` fail2ban-client set sshd unbanip 190.1.81.12 ``` You can also block this IP again using the following command. ``` fail2ban-client set sshd banip 190.1.81.12 ``` ## Conclusion In this post, we explained how to secure an SSH server with Fail2ban on Fedora. We also showed you how to monitor Fail2ban via the command line. You can now use Fail2ban to help protect your server against DDoS attacks; try implementing Fail2ban on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure Ansible on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-ansible-on-fedora/ | Published: 2023-07-10 | Updated: 2025-04-20 | Author: Hitesh Jethva Ansible is an open-source automation tool sponsored by Red Hat. It is written in Python and makes it easier to configure systems and deploy software on multiple servers from the central server. Ansible is cross-platform and primarily intended for IT professionals for application deployment, server updates, configuration management, and many day-to-day tasks. In this post, we will show you how to install Ansible on Fedora. ## Step 1 – Install Ansible By default, the Ansible package is included in the Fedora default repo. You can install it easily using the following command. ``` dnf install ansible -y ``` Once Ansible is installed, you can verify the Ansible version using the following command. ``` ansible --version ``` Output: ``` ansible 2.9.27 config file = /etc/ansible/ansible.cfg configured module search path = ['/root/.ansible/plugins/modules', '/usr/share/ansible/plugins/modules'] ansible python module location = /usr/lib/python3.9/site-packages/ansible executable location = /usr/bin/ansible python version = 3.9.5 (default, May 14 2021, 00:00:00) [GCC 11.1.1 20210428 (Red Hat 11.1.1-1)] ``` ## Step 2 – Setting Up SSH Key-Based Authentication Next, you will need to set up an SSH key-based authentication between the Ansible host and a remote host. First, create an SSH key pair on the Ansible host with the following command. ``` ssh-keygen -t rsa ``` You will see the generated key in the following output. ``` Generating public/private rsa key pair. Enter file in which to save the key (/root/.ssh/id_rsa): Created directory '/root/.ssh'. Enter passphrase (empty for no passphrase): Enter same passphrase again: Your identification has been saved in /root/.ssh/id_rsa Your public key has been saved in /root/.ssh/id_rsa.pub The key fingerprint is: SHA256:aPKqkVGXq7wmohJ/nCCZon730+x5Wrxeo+3K091Sr4o root@fedora The key's randomart image is: +---[RSA 3072]----+ | | | . | | . o | | . . o | | o. . + S | |* .+ = . .| |o+ooo.. o o.o..o| |+ oo=+ . o++=.o.o| |=oo=+ ..o+E*=+.o | +----[SHA256]-----+ ``` Next, copy the generated SSH key to the remote host with the following command. ``` ssh-copy-id root@remote-host-ip ``` Output: ``` /usr/bin/ssh-copy-id: INFO: Source of key(s) to be installed: "/root/.ssh/id_rsa.pub" The authenticity of host '192.168.200.200 (192.168.200.200)' can't be established. ED25519 key fingerprint is SHA256:qBNfJ6Vud/6TCt9bHOa1JwouYDrVuU5g/JhfAxfu3FM. This key is not known by any other names Are you sure you want to continue connecting (yes/no/[fingerprint])? yes /usr/bin/ssh-copy-id: INFO: attempting to log in with the new key(s), to filter out any that are already installed /usr/bin/ssh-copy-id: INFO: 1 key(s) remain to be installed -- if you are prompted now it is to install the new keys root@192.168.200.200's password: Number of key(s) added: 1 Now try logging into the machine, with: "ssh 'root@192.168.200.200'" and check to make sure that only the key(s) you wanted were added. ``` ## Step 3 – Configure Ansible Inventory Next, you will need to edit the Ansible inventory file and define your remote host IP address and SSH username. ``` nano /etc/ansible/hosts ``` Add the following configuration at the end of the file. ``` [fedora] server1 ansible_host=remote-host-ip ansible_user=root [all:vars] ansible_python_interpreter=/usr/bin/python3 ``` Save and close the file, then verify your added configuration using the following command. ``` ansible-inventory --list -y ``` You will see the following output. ``` all: children: fedora: hosts: server1: ansible_host: 192.168.200.200 ansible_user: root ungrouped: {} ansible --list-hosts all hosts (1): server1 ``` ## Step 4 – Use Ansible to Manage Remote Host At this point, Ansible is installed and configured to manage the remote host. Now, let’s get our hands dirty with Ansible. First, check the connectivity between the Ansible host and the remote host using the following command. ``` ansible -m ping all ``` If the connection is successful, you will see the following output. ``` server1 | SUCCESS => { "changed": false, "ping": "pong" } ``` To verify the operating system version of the remote host, run the following command. ``` ansible -m shell -a "cat /etc/fedora-release" fedora ``` After the successful command execution, you will see the following output. ``` server1 | CHANGED | rc=0 >> Fedora release 34 (Thirty Four) ``` To install Nginx on the remote host, run the following command. ``` ansible -m shell -a "dnf install nginx" fedora ``` To verify the Nginx installation, run the following command. ``` ansible -m shell -a "nginx -v" fedora ``` Output: ``` server1 | CHANGED | rc=0 >> nginx version: nginx/1.20.2 ``` To check the uptime of the remote host, run the following command. ``` ansible -m shell -a "uptime" fedora ``` Output: ``` server1 | CHANGED | rc=0 >> 04:15:35 up 3:53, 2 users, load average: 0.24, 0.14, 0.05 ``` If you want to check the disk space of the remote host, run the following command. ``` ansible -m shell -a "df -h" fedora ``` Output: ``` server1 | CHANGED | rc=0 >> Filesystem Size Used Avail Use% Mounted on devtmpfs 3.9G 0 3.9G 0% /dev tmpfs 3.9G 124K 3.9G 1% /dev/shm tmpfs 1.6G 664K 1.6G 1% /run /dev/sda1 160G 4.0G 157G 3% / tmpfs 3.9G 168K 3.9G 1% /tmp tmpfs 796M 0 796M 0% /run/user/0 ``` ## Conclusion In this tutorial, we showed you how to install Ansible on Fedora. Then, we explained how to configure Ansible to manage remote hosts with hands-on examples. You can now use Ansible to manage and monitor multiple servers from the central place. You can try Ansible to manage multiple servers on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure Memcached on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-memcached-on-fedora/ | Published: 2023-07-11 | Updated: 2023-11-15 | Author: Hitesh Jethva Memcached is an open-source and high-performance memory caching system used to speed up dynamic websites by caching data in memory. Generally, it is used to cache API calls, database, and page rendering chunks. It uses an in-memory data store to provide website users with cached elements quickly. Memcached is simple, lightweight, easy to use, and flexible in terms of application development. In this tutorial, we will show you how to install Memcached on Fedora. ## Step 1 – Install Memcached By default, the Memcached package is included in the Fedora default repo. You can install it using the following commands. ``` dnf update -y dnf install memcached libmemcached -y ``` Once Memcached is installed, start and enable the Memcached service with the following command. ``` systemctl start memcached systemctl enable memcached ``` You can verify the status of Memcached with the following command. ``` systemctl status memcached ``` Output. ``` ● memcached.service - memcached daemon Loaded: loaded (/usr/lib/systemd/system/memcached.service; disabled; vendor preset: disabled) Active: active (running) since Sat 2023-06-24 03:40:40 EDT; 3s ago Main PID: 10494 (memcached) Tasks: 10 (limit: 9497) Memory: 1.6M CPU: 29ms CGroup: /system.slice/memcached.service └─10494 /usr/bin/memcached -p 11211 -u memcached -m 64 -c 1024 -l 127.0.0.1,::1 Jun 24 03:40:40 fedora systemd[1]: Started memcached daemon. ``` By default, Memcached listens on port 11211. You can check it with the following command. ``` ss -antpl | grep memcached ``` Output. ``` LISTEN 0 1024 127.0.0.1:11211 0.0.0.0:* users:(("memcached",pid=10494,fd=27)) LISTEN 0 1024 [::1]:11211 [::]:* users:(("memcached",pid=10494,fd=28)) ``` The Memcached default configuration file is located at **/etc/sysconfig/memcached.** You can check the default options with the following command. ``` cat -n /etc/sysconfig/memcached ``` Output: ``` 1 PORT="11211" 2 USER="memcached" 3 MAXCONN="1024" 4 CACHESIZE="64" 5 OPTIONS="-l 127.0.0.1,::1" ``` You can check the above options as per your requirements. ## Step 2 – Enable Memcached for PHP Application If you want to use Memcached for PHP-based applications then you will need to install the Memcached PHP extensions to your server. You can install it with the following command. ``` dnf install php-pecl-memcache php-pecl-memcached -y ``` ## Step 3 – Verify Memcached for PHP To verify Memcached, first install Nginx and PHP. ``` dnf install nginx php php-cli -y ``` Next, create a sample PHP info file. ``` nano /var/www/html/info.php ``` Add the following code. ``` ``` Save and close the file, then create a symlink of the info.php file. ``` ln -s /var/www/html/info.php /usr/share/nginx/html/ ``` Next, start and enable the Nginx with the following command. ``` systemctl start nginx systemctl enable nginx ``` Now, open your web browser and access the PHP info page using the URL **http://your-server-ip/info.php.** ![](https://www.atlantic.net/wp-content/uploads/2023/06/php-info-page.png) ## Conclusion In this post, we explained how to install Memcached on Fedora. Then, we explained how to use Memcached with PHP and verify it. You can now use Memcached to help speed up your PHP applications. Try to use Memcached on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Atlantic.Net Cloud Platform > URL: https://www.atlantic.net/cloud-platform/atlantic-net-cloud-platform-50-off/ | Updated: 2026-09-16 Up to 50% OFF vs. the Big Guys ### Cloud Virtual Servers ### Secure Block Storage ### Snapshots ### Regulatory Compliance ### ACP Control Panel ### Dedicated Hosts ### Cloud Backups ### Managed Services ## A Cost-Effective, High-Performance Hosting Solution Vs. AWS and Microsoft Azure Atlantic.Net has been providing IT and Networking to the industry since 1994, building a reputation for delivering cutting-edge hosting and IT management services. The Atlantic.Net Cloud Platform (ACP) is a user-friendly, cloud-based hosting solution that offers cost-effective cloud instances running various Windows, Linux, and FreeBSD editions. The ACP platform is architectured for enhanced security. Every Cloud Server is optimized for super-fast performance, vigorous resilience, and scalability. Join us as we dive deeply into how the ACP platform performs against AWS and Azure. ## Save up to 50% or more compared to the big-name cloud server hosting providers. - Eight Global Data Center Locations. - Flexible Private, Public, & Monitoring. - 24x7x365 Security, Support, & Monitoring. ## Technical Comparison: The plans we compared include a small, medium, and large option for each provider. ## Hosting Data Package Comparison w/ Upgrade - Small | | Atlantic.Net | Amazon Web Services(AWS) | Microsoft Azure | | --- | --- | --- | --- | | Category | General Purpose | General Purpose | General Purpose | | Plan | G3.4GB | C5ad.Large | Standard_D2plds_v5 | | RAM | 4GB | 4GB | 4GB | | vCPU | 2 | 2 | 2 | | SSD | 80GB | 75GB | 75GB | | Transfer | 5TB | 5TB | 5TB | | Windows | $29 per month | $240.81 per month | $457.48 per month | | Linux | $17 per month | $178.76 per month | $223.54 per month | Notes 1. Microsoft Azure charges $33.496 per 1 TB for data transfer cost upgrade. 2. Amazon Web Services (AWS) only offers default transfer speeds. It is not upgradable. Confirmed this with AWS chat support representative. 3. Amazon Web Services (AWS) charges $0.03 in overage costs per 1GB, so for a 8TB transfer speed, this will cost an additional $240. ## Hosting Data Package Comparison Default - Medium | | Atlantic.Net | Amazon Web Services(AWS) | Microsoft Azure | | --- | --- | --- | --- | | Category | General Purpose | General Purpose | General Purpose | | Plan | G3.16GB | C5ad.2xLarge | Standard_D8plds_v5 | | RAM | 16GB | 16GB | 16GB | | vCPU | 6 | 8 | 8 | | SSD | 320GB | 300GB | 300GB | | Transfer | 7TB | 10Gbps | 477MB | | Windows | $115.5 per month | $363.18 per month | $492.75 per month | | Linux | $68 per month | $153.96 per month | $224.11 per month | ## Hosting Data Package Comparison Default - Large | | Atlantic.Net | Amazon Web Services(AWS) | Microsoft Azure | | --- | --- | --- | --- | | Category | General Purpose | General Purpose | General Purpose | | Plan | G3.32GB | C5ad.4xLarge | Standard_D2plds_v5 | | RAM | 32GB | 32GB | 32GB | | vCPU | 8 | 16 | 16 | | SSD | 640GB | 300GB | 600GB | | Transfer | 8TB | 10Gbps | 954MB | | Windows | $230.5 per month | $726.42 per month | $985.50 per month | | Linux | $136 per month | $331.64 per month | $448.22 per month | ## Save up to 50% or more compared to the big-name cloud server hosting providers. - Bring focus to your core business. - Secure & Compliant Hosting. - Affordable Cloud & Dedicated Hosting. ## Unbeatable Pricing for Every Budget ACP offers budget-friendly pricing starting at $29 for Windows and $17 for Linux. With a lightning-fast setup and a robust G3.4GB package, you can unleash the power of ACP at an affordable price. Compare our prices with AWS and Azure to see the significant savings. Our fixed pricing structure ensures transparency and delivers added value with no hidden costs. | Cost | ACP Windows | ACP Linux | AWS Windows | AWS Linux | AZURE Windows | AZURE Linux | | --- | --- | --- | --- | --- | --- | --- | | Small: 4GB RAM, 2 vCPU processors80GB SSD storage space | $29 | $17 | $90 | $28 | $123 | $123 | | Medium: 16GB RAM, 6 vCPU processors 320GB SSD storage space | $115 | $68 | $363 | $153 | $492 | $224 | | Large: 32GB RAM, 8 vCPU processors 640GB SSD storage space | $230 | $136 | $726 | $331 | $985 | $448 | ### Seamless Scalability for Growing Businesses ACP excels in scalability, empowering businesses to grow and adapt effortlessly. With ACP's cloud hosting solutions, expand your operations seamlessly. The user-friendly control panel and snapshot features simplify server and storage management, giving you complete control. ### Elevate Performance for Unparalleled Success Immerse your business in peak performance with ACP's optimized hosting solutions. Streamline operations and achieve unrivaled efficiency. Small businesses and large enterprises alike benefit from seamless online experiences. ### Tailored to Your Unique Needs Customization knows no bounds with ACP. Need more RAM and vCPU processors? Consider it done. Dedicated nodes support personalized VM sizing, accommodating your ever-growing requirements. ### Supercharge Your Digital Operations ACP's formidable hardware strength minimizes server downtime, turbocharges performance, and maximizes efficiency. ### Need Even More Power? No Problem. We've got you covered with customizable options. ### Data Transfer: ACP Outshines, Outperforms, Outmatches! Our basic package generously includes 5TB of transfer capacity, the medium plan offers 7TB, and the large plans start at 8TB transfer - a substantial step up from the offerings of AWS and Microsoft Azure's basic packages. While AWS and Azure provide 1GB of free monthly data transfer, with costs applied for additional data, ACP keeps things simple and expansive with a much larger initial allowance. ## Unlock the Power of ACP: Unbeatable Value, Unmatched Performance! Why settle for less when you can have it all with the Atlantic.Net Cloud Platform (ACP)? Compared to AWS and Microsoft Azure, ACP delivers exceptional value, putting up to $800 back in your pocket each month for Windows and up to $500 for Linux. It's a no-brainer, ACP is the cost-effective solution your business needs! Let's talk about the advantages. Atlantic.Net leaves competitors in the dust with its winning combination of premium features, competitive pricing, and top-notch customer support. Get ready for the best hosting experience available. ACP offers sky-high transfer capacity, roomy storage space, and rock-solid hardware configurations, all at a fraction of the cost you'll find elsewhere. ACP is the dynamic trio of performance, scalability, and affordability. Experience the lightning-fast speed, seamless growth opportunities, and an unbelievable price. Our technical prowess, wallet-friendly pricing, and user-friendly approach firmly establish us as a leading force in cloud hosting solutions. Oh, and did we mention round-the-clock support? We've got your back whenever you need us! Unleash the power of the Atlantic.Net Cloud Platform today and embrace a hosting experience that's second to none. Join countless businesses of all sizes who have already made the smart choice. It's time to unlock your full potential with ACP, where value, performance, and success collide! But don't just take our word for it; here is evidence demonstrating the advantages of picking Atlantic.Net. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # How to Install Tinyproxy on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-tinyproxy-on-fedora/ | Published: 2023-07-12 | Updated: 2023-11-17 | Author: Hitesh Jethva Tinyproxy is a lightweight, free, and open-source proxy solution for the Linux operating system. It is designed for embedded devices where a full-featured HTTP proxy is required, but the system resources for a larger proxy are unavailable. It is easy to install and configure and requires a little amount of space on operating systems. It offers a filtering capability to block or allow a certain domain by creating a blacklist and whitelist. This post will show you how to install a Tinyproxy on Fedora. ## Step 1 – Install Tinyproxy By default, the Tinyproxy package is included in the Fedora default repository. You can install it using the following command. ``` dnf update -y dnf install tinyproxy -y ``` Once the installation is completed, you can verify the Tinyproxy version using the following command. ``` tinyproxy -v ``` Output. ``` tinyproxy 1.10.0 ``` ## Step 2 – Configure Tinyproxy Next, you will need to edit the Tinyproxy main configuration file and modify some default settings. ``` nano /etc/tinyproxy/tinyproxy.conf ``` Change the following configurations. ``` Port 8888 Listen your-server-ip LogFile "/var/log/tinyproxy/tinyproxy.log" PidFile "/var/run/tinyproxy/tinyproxy.pid" BasicAuth user password Allow client-machine-ip ``` Save and close the file, then create a log file for Tinyproxy. ``` touch /var/log/tinyproxy/tinyproxy.log ``` ## Step 3 – Start Tinyproxy Service Now, start and enable the Tinyproxy service using the following command. ``` systemctl start tinyproxy systemctl enable tinyproxy ``` You can now check the status of Tinyproxy with the following command. ``` systemctl status tinyproxy ``` You will see the following output. ``` ● tinyproxy.service - small, efficient HTTP/SSL proxy daemon Loaded: loaded (/usr/lib/systemd/system/tinyproxy.service; disabled; vendor preset: disabled) Active: active (running) since Fri 2023-06-23 22:59:12 EDT; 3s ago Docs: man:tinyproxy(8) Process: 1967 ExecStart=/usr/bin/tinyproxy (code=exited, status=0/SUCCESS) Main PID: 1969 (tinyproxy) Tasks: 11 (limit: 2328) Memory: 4.6M CPU: 23ms CGroup: /system.slice/tinyproxy.service ├─1969 /usr/bin/tinyproxy ├─1970 /usr/bin/tinyproxy ├─1971 /usr/bin/tinyproxy ├─1972 /usr/bin/tinyproxy ├─1973 /usr/bin/tinyproxy ├─1974 /usr/bin/tinyproxy ├─1975 /usr/bin/tinyproxy ├─1976 /usr/bin/tinyproxy ├─1977 /usr/bin/tinyproxy ├─1978 /usr/bin/tinyproxy └─1979 /usr/bin/tinyproxy ``` By default, Tinyproxy listens on port 8888. You can check it with the following command. ``` ss -antpl | grep tinyproxy ``` Output. ``` LISTEN 0 1024 104.219.55.141:8888 0.0.0.0:* users:(("tinyproxy",pid=1979,fd=0),("tinyproxy",pid=1978,fd=0),("tinyproxy",pid=1977,fd=0),("tinyproxy",pid=1976,fd=0),("tinyproxy",pid=1975,fd=0),("tinyproxy",pid=1974,fd=0),("tinyproxy",pid=1973,fd=0),("tinyproxy",pid=1972,fd=0),("tinyproxy",pid=1971,fd=0),("tinyproxy",pid=1970,fd=0),("tinyproxy",pid=1969,fd=0)) ``` ## Step 4 – Define Proxy Settings on Web Browser Next, you will need to edit your browser settings and define your proxy server on the client machine. First, open your web browser and open the settings windows. ![](https://www.atlantic.net/wp-content/uploads/2023/06/firefox-setting.png) Scroll down the page and click on **Settings.** You should see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/06/define-proxy.png) Define your proxy server IP, Port, and click on the **OK** button to save the changes. Now, open another tab on your web browser and try to access **https://google.com.** You will be asked to provide your proxy username and password as shown below. ![](https://www.atlantic.net/wp-content/uploads/2023/06/proxy-authentication.png) Provide your username and password and click on the **Sign in** button. After successful authentication, you can able to access the Google website. ![](https://www.atlantic.net/wp-content/uploads/2023/06/google-page.png) ## Conclusion In this tutorial, we have explained how to install Tinyproxy on Fedora. We also showed you how to configure Tinyproxy and verify it from the client machine. You can use Tinyproxy on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Netdata Monitoring Tool on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-netdata-monitoring-tool-on-fedora/ | Published: 2023-07-13 | Updated: 2023-11-15 | Author: Hitesh Jethva Netdata is a scalable, distributed, real-time monitoring tool for Linux-based operating systems. It is used to monitor CPU, Memory, Processes, Network bandwidth, Database, and more via a web-based interface. It helps system administrators to find and troubleshoot system-related issues. It is written in C, Python, Javascript and can be installed on all major Linux operating systems. This guide will show you how to install the Netdata monitoring tool on Fedora. ## Step 1 – Install Netdata Netdata package is included in the Fedora default repository. You can install it easily using the following command. ``` dnf install netdata -y ``` Once Netdata is installed, you can start the Netdata service and enable it to start at system reboot with the following command. ``` systemctl start netdata systemctl enable netdata ``` To check the status of Netdata, use the following command. ``` systemctl status netdata ``` Output: ``` ● netdata.service - Real time performance monitoring Loaded: loaded (/usr/lib/systemd/system/netdata.service; disabled; vendor preset: disabled) Active: active (running) since Fri 2023-06-23 23:57:02 EDT; 4s ago Process: 3549 ExecStartPre=/bin/mkdir -p /var/cache/netdata (code=exited, status=0/SUCCESS) Process: 3550 ExecStartPre=/bin/chown -R netdata:netdata /var/cache/netdata (code=exited, status=0/SUCCESS) Process: 3551 ExecStartPre=/bin/mkdir -p /var/run/netdata (code=exited, status=0/SUCCESS) Process: 3552 ExecStartPre=/bin/chown -R netdata:netdata /var/run/netdata (code=exited, status=0/SUCCESS) Main PID: 3553 (netdata) Tasks: 31 (limit: 2328) Memory: 41.9M CPU: 1.637s CGroup: /system.slice/netdata.service ├─3553 /usr/sbin/netdata -P /var/run/netdata/netdata.pid -D ├─3555 /usr/sbin/netdata --special-spawn-server ├─3681 /usr/bin/bash /usr/libexec/netdata/plugins.d/tc-qos-helper.sh 1 ├─3682 /usr/libexec/netdata/plugins.d/apps.plugin 1 ├─3689 /usr/bin/python3 /usr/libexec/netdata/plugins.d/python.d.plugin 1 └─3690 /usr/libexec/netdata/plugins.d/nfacct.plugin 1 ``` By default, Netdata listens on port 19999. You can check it with the following command. ``` ss -antpl | grep 19999 ``` Output. ``` LISTEN 0 4096 127.0.0.1:19999 0.0.0.0:* users:(("netdata",pid=3553,fd=7)) LISTEN 0 4096 [::1]:19999 [::]:* users:(("netdata",pid=3553,fd=6)) ``` ## Step 2 – Configure Netdata By default, Netdata can be accessed only from the local host, so if you want to access Netdata from the remote system then you will need to edit the Netdata configuration file and bind it with the server IP. ``` nano /etc/netdata/netdata.conf ``` Find the following line. ``` bind to = localhost ``` And replace it with the following line. ``` bind to = your-server-ip ``` Save and close the file, then restart the Netdata service to apply the changes. ``` systemctl restart netdata ``` ## Step 3 – Monitor System Performance with Netdata Now, open your web browser and access the Netdata web UI using the URL **http://your-server-ip:19999.** You should see the Netdata dashboard. ![netdata dashboard](https://www.atlantic.net/wp-content/uploads/2023/06/p1-1.png) **Disk** ![disk](https://www.atlantic.net/wp-content/uploads/2023/06/disk.png) **RAM** ![](https://www.atlantic.net/wp-content/uploads/2023/06/ram.png) Network ![](https://www.atlantic.net/wp-content/uploads/2023/06/network.png) Swap ![](https://www.atlantic.net/wp-content/uploads/2023/06/swap.png) ## Conclusion In this post, we explained how to install the Netdata monitoring tool on Fedora. We also showed you how to enable remote access for Netdata. You can now implement Netdata on your server to monitor all major system metrics via a central dashboard. Now, use Netdata to monitor system performance on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure Samba Server on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-samba-server-on-fedora/ | Published: 2023-07-14 | Updated: 2023-11-15 | Author: Hitesh Jethva Samba is an open-source implementation of SMB networking protocol used for sharing files and printers across different operating systems. It helps system administrators to share files between multiple operating systems. Samba can also be used to join a Linux machine to Windows active directory domain controller. If you are looking for an open-source file-sharing solution, then Samba is the best choice for you. In this post, we will show you how to install the Samba server on Fedora. ## Step 1 – Install Samba Server By default, the Samba package is included in the Fedora default repository. You can install it with other packages using the following command. ``` dnf install samba samba-common samba-client ``` Once all the packages are installed, you can proceed to the next step. ## Step 2 -Create a Samba User Next, you will need to create a user and group to control access on Samba Share. Let’s create a new user using the following command. ``` useradd smbuser ``` Next, set a password for the Samba user. ``` smbpasswd -a smbuser ``` Set the password as shown below. ``` New SMB password: Retype new SMB password: Added user smbuser. ``` Next, create a Samba group with the following command. ``` groupadd smbgroup ``` Next, add smbuser to smbgroup. ``` usermod -g smbgroup smbuser ``` ## Step 3 -Create a Public Share with Samba With Samba, you can create a public share for all users in a network. It can be accessed without providing a user or password. First, create a directory for Public share using the following command. ``` mkdir -p /data/share/public ``` Next, set the permission and ownership to the Public share. ``` chmod -R 755 /data/share/public chown -R nobody:nobody /data/share/public ``` Next, create some files inside the Public directory. ``` cd /data/share/public touch public1 public2 ``` Next, back up the Samba main configuration file and create a new one. ``` mv /etc/samba/smb.conf /etc/samba/smb.conf.bak nano /etc/samba/smb.conf ``` Add the following lines to define your public share. ``` [global] workgroup = WORKGROUP server string = Samba Server %v netbios name = sambaserver security = user map to guest = bad user dns proxy = no ntlm auth = true [Public] path = /data/share/public browsable =yes writable = yes guest ok = yes read only = no ``` Save and close the file, then test the configuration with the following command. ``` testparm ``` Next, start and enable both smb and nmb services. ``` systemctl start smb nmb systemctl enable smb nmb ``` ## Step 4 -Verify Public Share Now, you can verify your Public share using the following command. ``` smbclient -L samba-server-ip ``` Just press the enter key without providing any password to list your share. ``` Enter WORKGROUP\root's password: Sharename Type Comment --------- ---- ------- Public Disk IPC$ IPC IPC Service (Samba Server 4.14.12) SMB1 disabled -- no workgroup available ``` Next, access the Public share with the following command. ``` smbclient //samba-ip-address/public ``` You will get into the Samba share. ``` Enter WORKGROUP\root's password: Try "help" to get a list of possible commands. ``` Run the following command to list all files inside the public share directory. ``` smb: \> ls ``` You will see both files in the following output. ``` . D 0 Fri Jun 23 22:45:10 2023 .. D 0 Fri Jun 23 22:49:40 2023 public1 N 0 Fri Jun 23 22:45:10 2023 public2 N 0 Fri Jun 23 22:45:10 2023 52416512 blocks of size 1024. 50410328 blocks available ``` ## Step 5 – Create a Private Share with Samba Private share is very useful when you want to control access to the share. Let’s create a private share with the following command. ``` mkdir -p /data/share/private ``` Next, create two files inside the private share. ``` cd /data/share/private touch private1 private2 ``` Now, set permissions and ownership on the private share. ``` chmod -R 770 /data/share/private chown -R root:smbgroup /data/share/private ``` Now, edit the Samba configuration file. ``` nano /etc/samba/smb.conf ``` Add the following configurations to define your private share. ``` [Private] path = /data/share/private valid users = @smbgroup guest ok = no writable = no browsable = yes ``` Save and close the file, then restart both services to apply the changes. ``` systemctl restart smb nmb ``` ## Step 6 – Verify Private Share Now, you can access your private share using the following command. ``` smbclient //samba-ip-address/private -U smbuser ``` Provide your smbuser password to access the share as shown below. ``` Enter WORKGROUP\smbuser's password: Try "help" to get a list of possible commands. smb: \> ls . D 0 Fri Jun 23 22:50:26 2023 .. D 0 Fri Jun 23 22:49:40 2023 private1 N 0 Fri Jun 23 22:50:26 2023 private2 N 0 Fri Jun 23 22:50:26 2023 52416512 blocks of size 1024. 50410392 blocks available smb: \> ``` To exit from the Samba shell, run the following command. ``` smb: \> exit ``` ## Conclusion In this post, we explained how to install the Samba server on Fedora. We also showed you how to create a public and private share with Samba. You can now use this solution in your local network to share files between multiple systems. You can now share files and folders with Samba on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure Wireguard VPN Server on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-wireguard-vpn-server-on-fedora/ | Published: 2023-07-16 | Updated: 2024-06-01 | Author: Hitesh Jethva WireGuard is an open-source and modern VPN solution known for its simplicity and ease of use. Initially designed for Linux, it is now also available for MacOS, BSD, IOS, and Android. Compared to other VPN software, WireGuard is simple and easy to set up. It also provides client apps for desktops and mobile devices from the platform app store. If you are looking for a simple and user-friendly VPN solution then WireGuard is the best option for you. This post will show you how to install WireGuard VPN on Fedora.| ## Step 1 – Enable IP Forwarding Before starting, you will need to set up IP forwarding on your server. To do so, create a new file. ``` nano /etc/sysctl.d/99-custom.conf ``` Add the following line. ``` net.ipv4.ip_forward=1 ``` Save and close the file, then apply the above configuration with the following command. ``` sysctl -p /etc/sysctl.d/99-custom.conf ``` ## Step 2 – Install WireGuard VPN First, install the WireGuard package using the following command. ``` dnf install wireguard-tools -y ``` Next, generate a public and private key using the following command. ``` wg genkey | tee /etc/wireguard/privatekey | wg pubkey | tee /etc/wireguard/publickey ``` You will see the generated key in the following output. ``` LR9Sv+v+wRat5+Ui4gbfSamfNFIjce6hbG5UJATD3Tc= ``` ## Step 3 – Configure WireGuard VPN Next, create a new configuration file with the following command. ``` nano /etc/wireguard/wg0.conf ``` Add the following configurations. ``` [Interface] Address = 10.0.0.1/24 SaveConfig = true ListenPort = 51820 PrivateKey = PostUp = firewall-cmd --zone=public --add-port 51820/udp && firewall-cmd --zone=public --add-masquerade PostDown = firewall-cmd --zone=public --remove-port 51820/udp && firewall-cmd --zone=public --remove-masquerade ``` **Note:** Replace the PrivateKey with your generated private key. Now, start the firewalld service with the following command. ``` systemctl start firewalld ``` ## Step 4 – Enable WireGuard Interface At this point, WireGuard is installed and configured. Now, you can bring up the WireGuard interface with the following command. ``` wg-quick up wg0 ``` You will see the following output. ``` [#] ip link add wg0 type wireguard [#] wg setconf wg0 /dev/fd/63 [#] ip -4 address add 10.0.0.1/24 dev wg0 [#] ip link set mtu 1420 up dev wg0 [#] firewall-cmd --zone=public --add-port 51820/udp && firewall-cmd --zone=public --add-masquerade success ``` You can verify your WireGuard installation with the following command. ``` wg show wg0 ``` If everything is fine, you will see the following output. ``` interface: wg0 public key: 0xQfsv/vwayO9aesmpD25t6DGmgF74daHXHLv4n3XW4= private key: (hidden) listening port: 51820 ``` Next, enable the WireGuard interface to start at system boot. ``` systemctl enable wg-quick@wg0 ``` ## Step 5 – Install and Configure WireGuard Client First, install the WireGuard VPN client on the client machine. ``` dnf install wireguard-tools -y ``` Next, generate a public and private key with the following command. ``` wg genkey | tee /etc/wireguard/privatekey | wg pubkey | tee /etc/wireguard/publickey ``` Output: ``` SRF4C7HGesORyRhguW44OG0eSOz2u80la2QmtWAUbVU= ``` Next, create a WireGuard client configuration file. ``` nano /etc/wireguard/wg0.conf ``` Add the following lines. ``` [Interface] PrivateKey = SRF4C7HGesORyRhguW44OG0eSOz2u80la2QmtWAUbVU= Address = 10.0.0.2/24 [Peer] PublicKey = LR9Sv+v+wRat5+Ui4gbfSamfNFIjce6hbG5UJATD3Tc= Endpoint = server-ip:51820 AllowedIPs = 0.0.0.0/0 ``` **Note:** Replaced PrivateKey with your client key and **PublicKey** with your server key. Now, run the following command on your server machine to add your client key. ``` wg set wg0 peer SRF4C7HGesORyRhguW44OG0eSOz2u80la2QmtWAUbVU= allowed-ips 10.0.0.2 ``` **Note:** Replaced **SRF4C7HGesORyRhguW44OG0eSOz2u80la2QmtWAUbVU** with your key generated on the client machine. Finally, bring up the WireGuard interface on the client machine. ``` wg-quick up wg0 ``` Output: ``` [#] ip link add wg0 type wireguard [#] wg setconf wg0 /dev/fd/63 [#] ip -4 address add 10.0.0.2/24 dev wg0 [#] ip link set mtu 1420 up dev wg0 [#] wg set wg0 fwmark 51820 ``` Now, go back to your server machine and verify your VPN connection using the following command. ``` wg ``` You should see the allocated IP address of the client machine in the following output. ``` interface: wg0 public key: 0xQfsv/vwayO9aesmpD25t6DGmgF74daHXHLv4n3XW4= private key: (hidden) listening port: 51820 peer: SRF4C7HGesORyRhguW44OG0eSOz2u80la2QmtWAUbVU= allowed ips: 10.0.0.2/32 ``` ## Conclusion In this post, we showed you how to install the WireGuard VPN server on Fedora. You can now use VPN to protect your users by encrypting user data and masking their IP addresses. You can now try to implement WireGuard VPN on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Apache Spark on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-spark-on-fedora/ | Published: 2023-07-17 | Updated: 2023-11-14 | Author: Hitesh Jethva Apache Spark is a free and open-source analytics engine used for executing data engineering, data science, and machine learning on a single server or cluster. It is a distributed processing system that utilizes in-memory caching to perform processing tasks on very large data sets. Some of the key features of Apache Spark are shown below. - Fault tolerance. - Dynamic In Nature. - Lazy Evaluation. - Real-Time Stream Processing. - Speed. - Reusability. - Advanced Analytics. - In Memory Computing. This post will show you how to install Apache Spark on Fedora. ## Step 1 – Install Java JDK Apache Spark is written in Java, so Java JDK must be installed on your server. You can install it with the following command. ``` dnf install java-11-openjdk-devel -y ``` Once Java is installed, you can verify the Java installation using the following command. ``` java --version ``` Output: ``` openjdk 11.0.15 2022-04-19 OpenJDK Runtime Environment 18.9 (build 11.0.15+10) OpenJDK 64-Bit Server VM 18.9 (build 11.0.15+10, mixed mode, sharing) ``` ## Step 2 – Install Apache Spark First, download the latest version of Apache Spark using the wget command. ``` wget https://dlcdn.apache.org/spark/spark-3.4.1/spark-3.4.1-bin-hadoop3.tgz ``` After the successful download, extract the downloaded file with the following command. ``` tar -xvf spark-3.4.1-bin-hadoop3.tgz ``` Next, move the extracted directory to the /opt directory. ``` mv spark-3.4.1-bin-hadoop3 /opt/spark ``` Next, add a user to run Spark then set the ownership of the Spark directory. ``` useradd spark chown -R spark:spark /opt/spark ``` ## Step 3 – Create a Systemd Service File Next, create a systemd service file to manage the Spark master service. ``` nano /etc/systemd/system/spark-master.service ``` Add the following configurations. ``` [Unit] Description=Apache Spark Master After=network.target [Service] Type=forking User=spark Group=spark ExecStart=/opt/spark/sbin/start-master.sh ExecStop=/opt/spark/sbin/stop-master.sh [Install] WantedBy=multi-user.target ``` Save and close the file, then create a service file for Spark slave. ``` nano /etc/systemd/system/spark-slave.service ``` Add the following configurations. ``` [Unit] Description=Apache Spark Slave After=network.target [Service] Type=forking User=spark Group=spark ExecStart=/opt/spark/sbin/start-slave.sh spark://your-server-ip:7077 ExecStop=/opt/spark/sbin/stop-slave.sh [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon. ``` systemctl daemon-reload ``` Next, start and enable the Spark master service. ``` systemctl start spark-master systemctl enable spark-master ``` You can check the Spark master status using the following command. ``` systemctl status spark-master ``` Output: ``` ● spark-master.service - Apache Spark Master Loaded: loaded (/etc/systemd/system/spark-master.service; disabled; vendor preset: disabled) Active: active (running) since Sat 2023-06-24 04:26:29 EDT; 4s ago Process: 16172 ExecStart=/opt/spark/sbin/start-master.sh (code=exited, status=0/SUCCESS) Main PID: 16184 (java) Tasks: 34 (limit: 9497) Memory: 209.8M CPU: 17.803s CGroup: /system.slice/spark-master.service └─16184 /usr/lib/jvm/java-11-openjdk-11.0.15.0.10-1.fc34.x86_64/bin/java -cp /opt/spark/conf/:/opt/spark/jars/* -Xmx1g org.apache.spark.deploy.master.Mast> Jun 24 04:26:25 fedora systemd[1]: Starting Apache Spark Master... Jun 24 04:26:25 fedora start-master.sh[16178]: starting org.apache.spark.deploy.master.Master, logging to /opt/spark/logs/spark-spark-org.apache.spark.deploy.master.Ma> Jun 24 04:26:29 fedora systemd[1]: Started Apache Spark Master. ``` ## Step 4 – Access Spark Web Interface At this point, Spark is installed and running on port 8080. Now, open your web browser and access Apache Spark using the URL **http://your-server-ip:8080.** You should see the Spark dashboard on the following screen. ![apache spark dashboard](https://www.atlantic.net/wp-content/uploads/2023/06/p1.png) Now, start and enable the Spark slave service with the following command. ``` systemctl start spark-slave systemctl enable spark-slave ``` Now, go back to the Spark web interface and reload the page. You should see that a new worker node has been added to the Spark. ![see added worker node](https://www.atlantic.net/wp-content/uploads/2023/06/p2.png) ## Conclusion In this tutorial, you learned how to install Apache Spark on Fedora. You can now start creating your machine learning and data science project and deploy it using Apache Spark. You can now deploy Apache Spark on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install WordPress on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-wordpress-on-oracle-linux-10/ | Published: 2023-07-18 | Updated: 2025-12-05 | Author: Hitesh Jethva WordPress is a free, open-source, self-hosted CMS software solution that allows you to host a blog or website on the internet. It is very popular for beginners who don’t know how to code a website. WordPress is secure, fast, customizable, and comes with tons of themes and plugins that help you to extend the functionality of your website. It is written in PHP and uses MySQL/MariaDB as a database backend. This popular platform is a great choice for getting a website up and running quickly. commerce. In this post, we will explain how to install WordPress using a LAMP stack on OracleLinux 10. ## Step 1 – Install LAMP Stack Before starting, install the LAMP stack components like Apache web server and MariaDB using the following command: ``` dnf install httpd mariadb-server -y ``` After installing both packages, you will need to install PHP and other PHP extensions to your system. You can install PHP with other extensions using the following command: ``` dnf install php php-cli php-fpm php-json php-gd php-mbstring php-pdo php-xml php-mysqlnd php-pecl-zip curl -y ``` Once all the packages are installed, start and enable Apache, PHP-FPM, and MariaDB services using the following command: ``` systemctl start httpd mariadb php-fpm systemctl enable httpd mariadb php-fpm ``` ## Step 2 – Create a Database for WordPress WordPress uses MySQL/MariaDB to store the contents, so you will need to create a database and user for WordPress: First, connect to the MariaDB with the following command: ``` mysql ``` Once you are connected, create a database and user with the following command: ``` CREATE DATABASE wordpressdb; CREATE USER `wordpressuser`@`localhost` IDENTIFIED BY 'securepassword'; ``` Next, grant all the privileges to the WordPress database using the following command: ``` GRANT ALL ON wordpressdb.* TO `wordpressuser`@`localhost`; ``` Next, flush the privileges and exit from the MariaDB with the following command: ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download WordPress Next, change the directory to the Apache default web root directory and download the latest version of WordPress with the following command: ``` cd /var/www/html curl https://wordpress.org/latest.tar.gz --output wordpress.tar.gz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar xf wordpress.tar.gz ``` Next, change the directory to WordPress and rename the WordPress configuration file: ``` cd wordpress mv wp-config-sample.php wp-config.php ``` Next, set proper ownership of the WordPress directory with the following command: ``` chown -R apache:apache /var/www/html/wordpress chmod -R 755 /var/www/html/wordpress ``` ## Step 4 – Configure Apache to Host WordPress Next, you will need to create an Apache virtual host file to host the WordPress. You can create it with the following command: ``` nano /etc/httpd/conf.d/wordpress.conf ``` Add the following lines: ``` ServerAdmin root@localhost ServerName wordpress.example.com DocumentRoot /var/www/html/wordpress Options Indexes FollowSymLinks AllowOverride all Require all granted ErrorLog /var/log/httpd/wordpress_error.log CustomLog /var/log/httpd/wordpress_access.log common ``` Save and close the file, then restart the Apache service to apply the configuration changes: ``` systemctl restart httpd ``` ## Step 5 – Access WordPress Installer Now, open your web browser and access the WordPress installer using the URL **http://wordpress.example.com**. You should see the following screen: ![WordPress Select Language](https://www.atlantic.net/wp-content/uploads/2022/05/p1-13.png) Select your language and click on the **Continue** button. You will be redirected to the following screen: ![WordPress Site Configuration](https://www.atlantic.net/wp-content/uploads/2022/05/p2-11.png) Provide your site information and click on the **Install** **WordPress** button. You should see the following screen: ![WordPress Installed](https://www.atlantic.net/wp-content/uploads/2022/05/p3-6.png) Click on the**Log In** button. You should see the following screen: ![WordPress Login Page](https://www.atlantic.net/wp-content/uploads/2022/05/p4-5.png) Provide your admin username and password and click on the **Log In** button. You should see the WordPress dashboard on the following screen: ![WordPress Dashboard](https://www.atlantic.net/wp-content/uploads/2022/05/p5-4-1024x508.png) ## Conclusion In the above guide, we learned how to install WordPress with LAMP on OracleLinux 10. You can now install the necessary plugins and themes and start creating your first website from the WordPress dashboard. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Jenkins on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-jenkins-on-oracle-linux-10/ | Published: 2023-07-19 | Updated: 2025-12-05 | Author: Hitesh Jethva Jenkins is a powerful, free automation tool used in the software development life cycle. It is a Java-based tool that allows you to build, test and deploy code automatically. Jenkins offers many plugins built for Continuous Integration purposes. It allows developers to integrate changes to the project and send a fresh build to users. Jenkins is cross-platform so it can be installed on all major operating systems. It has more than 147,000 active installations and over 1 million users around the world. In this post, we will show you how to install Jenkins on Oracle Linux 10. ## Step 1 – Install Java Jenkins is a Java-based tool, so Java must be installed on your server. If not installed you can install it using the following command: ``` dnf install java-21-openjdk -y ``` Once the Java is installed, verify the Java version using the following command: ``` java --version ``` Sample output: ``` openjdk 21.0.9 2025-10-21 LTS OpenJDK Runtime Environment (Red_Hat-21.0.9.0.10-1.0.1) (build 21.0.9+10-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.9.0.10-1.0.1) (build 21.0.9+10-LTS, mixed mode, sharing) ``` ## Step 2 – Add Jenkins Repository By default, Jenkins is not included in the OracleLinux 8 default repository so you will need to create a Jenkins repo on your system. You can create it using the following command: ``` wget -O /etc/yum.repos.d/jenkins.repo https://pkg.jenkins.io/redhat-stable/jenkins.repo ``` Next, download and import the Jenkins GPG key with the following command: ``` rpm --import https://pkg.jenkins.io/redhat-stable/jenkins.io-2023.key ``` Next, verify the Jenkins repo using the following command: ``` dnf repolist ``` Sample output: ``` repo id repo name jenkins Jenkins-stable ol10_UEKR8 Oracle Linux 10 UEK Release 8 (x86_64) ol10_appstream Oracle Linux 10 Application Stream Packages (x86_64) ol10_baseos_latest Oracle Linux 10 BaseOS Latest (x86_64) ``` ## Step 3 – Install Jenkins Now you can install Jenkins using the following command: ``` dnf install jenkins --nobest ``` Once Jenkins is installed, start Jenkins and enable it to start at system reboot: ``` systemctl start jenkins systemctl enable jenkins ``` You can now check the status of Jenkins using the following command: ``` systemctl status jenkins ``` Sample output: ``` ● jenkins.service - Jenkins Continuous Integration Server Loaded: loaded (/usr/lib/systemd/system/jenkins.service; disabled; preset: disabled) Active: active (running) since Fri 2025-12-05 06:25:22 EST; 4s ago Invocation: d960e39e32d948bca823331f4c5b05b0 Main PID: 63537 (java) Tasks: 45 (limit: 24812) Memory: 571.3M (peak: 585.4M) CPU: 13.725s CGroup: /system.slice/jenkins.service └─63537 /usr/bin/java -Djava.awt.headless=true -jar /usr/share/java/jenkins.war --webroot=/var/cache/jenkins/war --httpPort=808. ``` By default, Jenkins listens on port 8080. You can verify it with the following command: ``` ss -antpl | grep 8080 ``` Sample output: ``` LISTEN 0 50 *:8080 *:* users:(("java",pid=13177,fd=117)) ``` ## Step 4 – Configure Nginx as a Reverse Proxy for Jenkins It is a good idea to install and configure Nginx as a reverse proxy for Jenkins. First, install the Nginx web server with the following command: ``` dnf install nginx -y ``` After installing Nginx, create an Nginx configuration file for Jenkins: ``` nano /etc/nginx/conf.d/jenkins.conf ``` Add the following lines: ``` upstream jenkins { server 127.0.0.1:8080 fail_timeout=0; } server { listen 80; server_name jenkins.example.com; location / { proxy_set_header Host $host:$server_port; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_pass http://jenkins; # Required for new HTTP-based CLI proxy_http_version 1.1; proxy_request_buffering off; proxy_buffering off; # Required for HTTP-based CLI to work over SSL } } ``` Save and close the file when you are finished. Then, edit the Nginx main configuration file: ``` nano /etc/nginx/nginx.conf ``` Define the hash bucket size as shown below: ``` http { server_names_hash_bucket_size 64; ``` Next, verify Nginx for any syntax errors: ``` nginx -t ``` Sample output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, start the Nginx service and enable it to start at system reboot: ``` systemctl start nginx systemctl enable nginx ``` ## Step 5 – Access Jenkins Dashboard Now, you can access the Jenkins web interface using the URL **http://jenkins.example.com** from the web browser. You should see the following screen: ![Jenkins Login](https://www.atlantic.net/wp-content/uploads/2022/05/p1-14.png)Now, open your terminal and retrieve the Jenkins setup password using the following command: ``` cat /var/lib/jenkins/secrets/initialAdminPassword ``` Sample output: ``` 000a6fdc7f9d4d05b39029d776f34fd6 ``` Now, paste the above password and click on the **Continue** button. You should see the following screen: ![Jenkins Plugins Installation](https://www.atlantic.net/wp-content/uploads/2022/05/p2-12.png) Now, select ‘**Install using suggested plugins**‘ or ‘Select plugins to install‘. You should see the following screen: ![Jenkins Admin User Creation](https://www.atlantic.net/wp-content/uploads/2022/05/p3-7-1024x627.png) Now, provide your admin user information and click on the **Save and Continue** button. You should see the following screen: ![Jenkins Define URL](https://www.atlantic.net/wp-content/uploads/2022/05/p4-6.png) Now, provide your Jenkins URL and click on the **Save and Finish** button. You should see the following screen: ![Jenkins Installed](https://www.atlantic.net/wp-content/uploads/2022/05/p-1.png) Click on the **Start Using Jenkins**. You should see the Jenkins Dashboard on the following screen: ![Jenkins Dashboard](https://www.atlantic.net/wp-content/uploads/2022/05/p6-3-1024x512.png) ## Conclusion In this post, we explained how to install Jenkins on OracleLinux 10 with Nginx as a reverse proxy. You can now use Jenkins in your software development environment and automate the development process with ease. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Craft CMS with Nginx on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-craft-cms-with-nginx-on-oracle-linux-10/ | Published: 2023-07-20 | Updated: 2025-12-05 | Author: Hitesh Jethva Craft CMS is a free and open-source content management system used for creating custom digital experiences on the web. It is flexible, extensible, and designed for website owners who want more control and more powerful performances from their CMS. Craft CMS has a user-friendly web interface and offers tons of plugins that help you to add more functionality to your website. It is an alternative to WordPress for development-oriented publishers. In this step-by-step guide, we will show you how to install Craft CMS with Nginx on OracleLinux 10. ## Step 1 – Install LEMP Server Before starting, you will need to install the Nginx web server, MariaDB database, PHP, and other required extensions to your server. You can install all packages using the below command. ``` dnf install nginx mariadb-server php php-cli php-fpm php-common php-bcmath php-curl php-gd php-json php-mbstring php-mysqli php-pgsql php-zip php-intl php-xml php-pdo -y ``` After installing all the packages, edit the php.ini file and change some recommended settings: ``` nano /etc/php.ini ``` Change the following settings: ``` memory_limit = 256M date.timezone = Asia/Kolkata ``` Save and close the file, then edit the php-fpm configuration file and change the user and group from apache to nginx: ``` nano /etc/php-fpm.d/www.conf ``` Change the following lines: ``` user = nginx group = nginx ``` Save and close the file then start Nginx, MariaDB, and PHP-FPM service and enable them to start at system reboot: ``` systemctl start nginx mariadb php-fpm systemctl enable nginx mariadb php-fpm ``` ## Step 2 – Create a Database and User Next, you will need to create a database and user for Craft CMS. First, log in to MySQL with the following command: ``` mysql ``` Once you are logged in, create a database and user with the following command: ``` create database craftdb; grant all on craftdb.* to craftuser@localhost identified by 'securepassword'; ``` Next, flush the privileges and exit from MariaDB with the following command: ``` flush privileges; quit; ``` ## Step 3 – Install Composer Composer is a dependency manager for PHP used for resolving PHP dependencies for your project. First, download the Composer setup PHP file with the following command: ``` php -r "copy('https://getcomposer.org/installer', 'composer-setup.php');" ``` Next, fetch the Composer Hash value and match it with the downloaded file: ``` HASH="$(wget -q -O - https://composer.github.io/installer.sig)" php -r "if (hash_file('SHA384', 'composer-setup.php') === '$HASH') { echo 'Installer verified'; } else { echo 'Installer corrupt'; unlink('composer-setup.php'); } echo PHP_EOL;" ``` If everything is fine, you should get the following output: ``` Installer verified ``` Next, run the following command to install Composer on your system: ``` php composer-setup.php --install-dir=/usr/local/bin --filename=composer ``` Once Composer is installed, verify the Composer version using the following command: ``` composer -V ``` You should get the following output: ``` Composer version 2.9.2 2025-11-19 21:57:25 ``` ## Step 4 – Install Craft CMS First, navigate to the Nginx web root directory and download the latest version of Craft CMS using the Composer tool: ``` cd /var/www/html/ ``` ``` composer create-project craftcms/craft craft ``` During the installation, you will be asked to provide database credentials, admin username, password, and Craft URL as shown below: ``` > @php craft setup/welcome ______ .______ ___ _______ .___________. / || _ \ / \ | ____|| | | ,----'| |_) | / ^ \ | |__ `---| |----` | | | / / /_\ \ | __| | | | `----.| |\ \----./ _____ \ | | | | \______|| _| `._____/__/ \__\ |__| |__| A N E W I N S T A L L ______ .___ ___. _______. / || \/ | / | | ,----'| \ / | | (----` | | | |\/| | \ \ | `----.| | | | .----) | \______||__| |__| |_______/ Generating an application ID ... done (CraftCMS--be1f09c9-cd35-4bfe-a01b-d611282eea19) Generating a security key ... done (HaBt-G01s1pwVPNXmb1iAQZDI0M1lpuh) Welcome to Craft CMS! Are you ready to begin the setup? (yes|no) [no]:yes Generating an application ID ... done (CraftCMS--f06f8153-f389-4603-97b7-c683b8cd422d) Which database driver are you using? [mysql,pgsql,?]: mysql Database server name or IP address: [127.0.0.1] Database port: [3306] Database username: [root] craftuser Database password: Database name: craftdb Database table prefix: Testing database credentials ... success! Saving database credentials to your .env file ... done Install Craft now? (yes|no) [yes]:yes Username: [admin] Email: admin@example.com Password: Confirm: Site name: mysite Site URL: http://craft.example.com Site language: [en-US] installed Craft successfully (time: 6.230s) Generating project config files from the loaded project config ... done ``` Next, change the ownership of the Craft CMS directory and PHP session directory to Nginx: ``` chown -R nginx:nginx /var/www/html/craft chown -R nginx:nginx /var/lib/php/session ``` ## Step 5 – Configure Nginx for Craft CMS Next, you will need to create an Nginx virtual host configuration file for Craft CMS. You can create it with the following command: ``` nano /etc/nginx/conf.d/craft.conf ``` Add the following configuration: ``` server { listen 80; server_name craft.example.com; root /var/www/html/craft/web; index index.php; location / { try_files $uri/index.html $uri $uri/ /index.php?$query_string; } location ~ [^/]\.php(/|$) { try_files $uri $uri/ /index.php?$query_string; fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_pass unix:/run/php-fpm/www.sock; fastcgi_index index.php; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_param PATH_INFO $fastcgi_path_info; fastcgi_param HTTP_PROXY ""; } } ``` Save the file, then edit the Nginx main configuration file: ``` nano /etc/nginx/nginx.conf ``` Define the hash bucket size: ``` http { server_names_hash_bucket_size 64; ``` Next, verify Nginx for any syntax configuration error using the following command: ``` nginx -t ``` You should get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 6 – Access Craft CMS Now, open your web browser and access the Craft CMS website using the URL **http://craft.example.com**. You should see the following screen: ![Craft CMS Welcome Screen](https://www.atlantic.net/wp-content/uploads/2022/05/p1-15-1024x550.png) Click on the **Go to your control panel**. You will be redirected to the Craft CMS login page: ![Craft CMS Login Screen](https://www.atlantic.net/wp-content/uploads/2022/05/p2-13-1024x507.png) Provide your admin username, password, and click on the **Login** button. You should see the Craft CMS dashboard on the following screen: ![Craft CMS Dashboard Screen](https://www.atlantic.net/wp-content/uploads/2022/05/p4-7-1024x488.png) ## Conclusion In this post, we explained how to install Craft CMS with Nginx on OracleLinux 10. You can now explore the Craft CMS and start building your website easily from the Craft CMS dashboard. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Edge Security > URL: https://www.atlantic.net/managed-services/edge-security/ | Published: 2023-07-21 | Updated: 2025-05-14 | Author: Richard Bailey Edge computing is an IT framework that challenges the traditional centralized computing model. Instead of relying solely on distant data centers or the cloud to handle data processing tasks, edge computing brings computation and data storage closer to the source of data generation. This decentralization of computing resources enables faster processing and real-time analytics, reducing latency and enhancing users’ overall system performance. In this article, we will discover the intricate world of edge security, exploring its challenges, best practices, and the cutting-edge solutions available to ensure the safety and integrity of edge computing environments. By understanding the vital role of edge security in edge computing, organizations can confidently embrace this transformative technology while safeguarding their sensitive data and preserving their digital ecosystem’s security. This is part of an extensive series of guides about [information security](https://www.exabeam.com/explainers/information-security/information-security-goals-types-and-applications/). ## Edge Security Device Risks Edge computing devices, like IoT sensors and mobile Internet devices, are exposed to various security risks. To give you an idea of the vast scale of edge computing, there are estimated to be around [20 billion IoT devices](https://cdn.comparitech.com/wp-content/uploads/2022/06/IoT-Analytics-devices-forecast-2025.jpg), and that’s just IoT sensors, not to mention other edge computing devices like smart devices, smart cameras, uCPE equipment, edge servers, and edge networking infrastructure. The vast proliferation of these devices, and their often remote or unsecured locations, make them easy targets for malicious activity. With their direct access to the network, they can be used to infiltrate and compromise the entire enterprise network infrastructure, allowing attackers to steal sensitive data or disrupt business operations. ## What Makes A Good Edge Security Solution? Very early IoT devices had very weak security policies, and these early challenges prompted the ISACA to publish information concerning the [most common weaknesses](https://www.isaca.org/resources/isaca-journal/issues/2019/volume-1/security-issues-in-iot-challenges-and-countermeasures): - Insecure web interface - Insufficient authentication/authorization - Insecure network services - Lack of transport encryption - Privacy concerns - Insecure cloud interface - Insecure mobile interface - Insufficient security configurability - Insecure software/firmware - Poor physical security A robust edge security solution must blend intrusion prevention systems, access control, and web filtering. It should protect data in transit and at rest, leveraging encryption and other security tools and protocols. Security controls that provide real-time threat detection and the ability to respond quickly to potential breaches are also critical. ## Cloud networks, IoT, and computing on the edge Cloud networks and IoT are driving the growth of edge computing, bringing computation and data storage closer to the data source. However, this shift also raises new edge security challenges. ### Increased attack surface: With the expansion of edge computing, the number of entry points for potential cyberattacks increases, providing more opportunities and tools for hackers to infiltrate systems and devices. Each IoT device can potentially be used as an access point to a corporate network, resulting in a much larger attack surface for hackers to target. ### Vulnerabilities in IoT devices: IoT devices are often built with cost-efficiency in mind, sacrificing robust security measures. This makes them attractive targets for cybercriminals seeking to exploit weaknesses in these devices for unauthorized device access or data theft. ### Limited computational power: Edge devices typically have limited processing capabilities compared to traditional data centers, making implementing complex security measures across multiple devices challenging and leaving many organizations susceptible to certain attacks. ### Lack of standardized security protocols: The rapid growth of edge computing has resulted in a lack of uniform security standards across different devices, cloud services, and networks. This lack of consistency can lead to gaps in protection and difficulties in managing security effectively. ### Data privacy concerns: Data privacy concerns of IoT devices at the network edge revolve around potential vulnerabilities and unauthorized access, as sensitive information is often transmitted and processed closer to the devices themselves, increasing security risks such as data breaches and misuse. Implementing strong encryption protocols, regularly updating firmware and software, introducing secure authentication mechanisms, and establishing robust access controls are essential measures to safeguard IoT devices at the network edge, protecting data from potential threats and unauthorized access. ### Latency and availability risks: While edge computing aims to reduce latency, if security protocols hinder the efficient flow of data, it could affect system availability and responsiveness, leading to potential disruptions in critical operations. To protect against latency and availability risks with edge security, implementing robust data caching, edge computing capabilities, and redundant communication channels can optimize data processing, minimize delays, and ensure continuous operation even during network disruptions. ### Supply chain vulnerabilities: As the edge computing ecosystem involves various components from different manufacturers and vendors, it becomes challenging to ensure the security of the entire supply chain, making it susceptible to compromise at any point in the chain. To safeguard against supply chain vulnerabilities, organizations can implement stringent supplier vetting processes, establish end-to-end visibility across the supply chain, and diversify sourcing options to mitigate potential disruptions and reduce the impact of security breaches or logistical challenges. ### Difficulty in monitoring and management: With a distributed perimeter computing architecture, managing security across numerous devices and locations becomes more complex, making it harder for companies to monitor and respond promptly to security threats. ### Insider threats: The proliferation of edge computing may increase the potential for insider threats as individuals with access to edge devices or access control to networks might be tempted to misuse their privileges for personal gain or to harm the organization. To mitigate insider threats, companies can implement access controls and least privilege principles, conduct regular employee training on cybersecurity best practices, monitor user activities, and establish a culture of trust and transparency while also encouraging employees to report any suspicious activities. ### Regulatory challenges: As edge computing crosses geographical boundaries, complying with different regional data protection and privacy regulations can be daunting, requiring organizations to navigate complex legal and compliance issues. Addressing regulatory challenges requires organizations to stay updated on relevant laws and industry standards, establish comprehensive compliance programs, conduct regular audits, and collaborate with legal experts to ensure adherence to data privacy, security, and other regulatory requirements. ## The best practices for edge computing security “Zero Trust” is the cornerstone of edge computing security best practices. According to Fortinet, there are three core principles to Zero Trust at the network core and the edge. 1. Enhanced device visibility and segmentation 2. Strong identity-based access controls 3. Ability to secure endpoints on and off your corporate network To safeguard edge devices within a public cloud infrastructure effectively, implementing a Zero Trust approach becomes essential. This approach ensures the physical security of connected devices and addresses the specific edge security requirements arising in growing industries. To protect your organization against potential threats at the edge, developing a comprehensive cloud security strategy that covers all aspects of edge security is imperative. ## Implement Zero Trust Edge Access with Secure Access Service Edge (SASE) Whether access attempts originate from within or outside the network, Zero Trust ensures that trust is never assumed by default. When combined with the robust SASE framework, organizations fortify their defenses by granting network access exclusively to authenticated and authorized users or devices. Secure Access Service Edge (SASE) is a cloud-based networking and security model that unifies WAN capabilities with cloud-native security services. It prioritizes identity-centric access, Zero Trust security, and user-centric policy enforcement to simplify management, enhance security, manage and optimize performance for modern cloud-first and mobile-centric environments. This powerful synergy bolsters protection and safeguards the corporate network k countless potential threats. ## What does edge computing security look like today? Securing edge environments is critical; organizations must extend their security policies beyond the confines of traditional networks and data centers to encompass all edge devices. In particular, IoT and mobile devices have faced challenges in catching up with robust security controls. Early releases often lacked adequate security measures, which fortunately changed rapidly. Nevertheless, prioritizing the security of edge devices remains imperative. ## Protecting your organization against the edge Decentralized computing introduces unique security challenges that transcend traditional enterprise security measures. To ensure comprehensive protection, organizations must diligently address the distinctive risks associated with edge devices, including physical security and potential vulnerabilities arising from their location or configuration. Implementing a robust and all-encompassing enterprise and edge security risk strategy can effectively mitigate these risks, safeguarding your organization against potential threats. ## Atlantic.Net Network Edge Protection Managed Services **Are you looking for a way to protect your network from cyberattacks and malware?**[Atlantic.Net](https://www.atlantic.net/managed-services/network-edge-protection/)‘[s Network Edge Protection](https://www.atlantic.net/managed-services/network-edge-protection/) managed services and tools can help you protect your network from threats, including DDoS attacks, web application attacks, and malware. With 24/7 monitoring and support, you can be confident that your network is always secure. With Atlantic.Net, you get: - A team of experts that monitor your network 24/7 identifies and blocks threats and keeps your data safe. - A robust Web Application Firewall (WAF) that can block unauthorized content, including cross-site scripting attacks, and SQL injections - DDoS protection that can absorb Distributed Denial of Service (DDoS) attacks - Proactive maintenance and management - Scalability to meet your business needs - Atlantic.Net’s Network Edge Protection managed services are backed by a 100% uptime SLA. - We have a proven track record of protecting our customers’ networks from cyberattacks. - We offer a free consultation to help you assess your network security needs. Protect your data, protect your reputation, and protect your future with Atlantic.Net’s Network Edge Protection. Stay safe, stay secure, [contact us now](https://www.atlantic.net/about-us/corporate-contact/), and experience the peace of mind you deserve. ### See Additional Guides on Key Information Security Topics Together with our content partners, we have authored in-depth guides on several other topics that can also be useful as you explore the world of [information security](https://www.exabeam.com/explainers/information-security/information-security-goals-types-and-applications/). #### [Vulnerability Assessment](https://www.cycognito.com/learn/vulnerability-assessment/) *Authored by CyCognito* - [[Guide] Vulnerability Assessment: Process, Challenges & Best Practices ](https://www.cycognito.com/learn/vulnerability-assessment/) - [[Guide] Complete Guide to Vulnerability Scanning ](https://www.cycognito.com/learn/vulnerability-assessment/vulnerability-scanning.php) - [Product] CyCognito | Proactively Secure Your Attack Surface #### [Insider Threat](https://www.exabeam.com/explainers/insider-threats/insider-threats/) *Authored by Exabeam* - [[Guide] What is an Insider Threat? 4 Defensive Strategies ](https://www.exabeam.com/explainers/insider-threats/insider-threats/) - [[Guide] How Privilege Escalation Works and 6 Ways to Prevent It ](https://www.exabeam.com/explainers/insider-threats/how-privilege-escalation-works-and-6-ways-to-prevent-it/) - [[Whitepaper] 2024 State of the Security Team Research ](https://www.exabeam.com/blog/infosec-trends/a-cisos-analysis-the-2024-state-of-security-report/) - [[Product] Exabeam | AI-Driven Security Operations](https://www.exabeam.com/) #### [DDoS Protection](https://www.radware.com/cyberpedia/ddospedia/ddos-protection-techniques-types-and-7-solutions-to-know-in-2024/) *Authored by Radware* - [[Guide] Anti-DDoS: 6 Techniques, Solution Types & 8 Key Considerations](https://www.radware.com/cyberpedia/ddospedia/anti-ddos/) - [[Guide] DDoS Protection: Techniques, Types & 7 Solutions to Know in 2024](https://www.radware.com/cyberpedia/ddospedia/ddos-protection-techniques-types-and-7-solutions-to-know-in-2024/) - [[Product] Radware DDoS Attack Mitigation and Defense](https://www.radware.com/products/ert/) --- # How to Install, Configure, and Run Elasticsearch on Oracle Linux 10 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-elasticsearch-on-oracle-linux-10/ | Published: 2023-07-22 | Updated: 2025-12-04 | Author: Hitesh Jethva Elasticsearch is an open-source search and analytic engine used to add search functionality to web-based applications. It is capable of searching and analyzing a large amount of data. It is powerful, stable, scalable, and supports RESTful with an HTTP URI to manipulate data. It is based on the Lucene library, written in Java, and is dual-licensed under the source-available Server Side Public License and the Elastic license. It has the ability to index many types of content including, a website search, application search, security analytics, enterprise search, geospatial data analysis and visualization, and more. In this post, we will show you how to install and configure Elasticsearch on OracleLinux 10. ## Step 1 – Install Java Elasticsearch is a Java-based application, so you will need to install Java on your server. You can install it by running the following commands: ``` dnf update -y ``` ``` dnf install java-21-openjdk-devel -y ``` Once Java is installed, verify the Java version using the following command: ``` java --version ``` Sample output: ``` java --version openjdk 21.0.9 2025-10-21 LTS OpenJDK Runtime Environment (Red_Hat-21.0.9.0.10-1.0.1) (build 21.0.9+10-LTS) OpenJDK 64-Bit Server VM (Red_Hat-21.0.9.0.10-1.0.1) (build 21.0.9+10-LTS, mixed mode, sharing) ``` ## Step 2 – Create Elasticsearch Repository By default, Elasticsearch is not included in the OracleLinux 10 default repository, so you will need to create a repository for it. First, download and import the GPG key with the following command: ``` rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch ``` Next, create an Elasticsearch repo with the following command: ``` nano /etc/yum.repos.d/elasticsearch.repo ``` Add the following lines: ``` [elasticsearch] name=Elasticsearch repository for 8.x packages baseurl=https://artifacts.elastic.co/packages/8.x/yum gpgcheck=1 gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch enabled=1 autorefresh=1 type=rpm-md ``` Save and close the file when you are finished. ## Step 3 – Install and Configure Elasticsearch After creating an ElasticSearch repo, install the Elasticsearch package with the following command: ``` dnf install elasticsearch -y ``` After installing Elasticsearch, edit the Elasticsearch main configuration file: ``` nano /etc/elasticsearch/elasticsearch.yml ``` Change the following lines: ``` cluster.name: my-cluster node.name: oracle # Data paths path.data: /var/lib/elasticsearch path.logs: /var/log/elasticsearch # Bind locally for testing network.host: 127.0.0.1 http.port: 9200 xpack.security.enabled: true xpack.security.http.ssl.enabled: false #cluster.initial_master_nodes: ["oracle"] ``` Save and close the file, then start the Elasticsearch service and enable it to start at system reboot: ``` systemctl start elasticsearch systemctl enable elasticsearch ``` You can also check the status of Elasticsearch with the following command: ``` systemctl status elasticsearch ``` You should get the following output: ``` ● elasticsearch.service - Elasticsearch Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; disabled; preset: disabled) Active: active (running) since Thu 2025-12-04 22:33:09 EST; 6s ago Invocation: 268d1c8a0340493b903bd594982d6ef5 Docs: https://www.elastic.co Main PID: 58459 (java) Tasks: 107 (limit: 24812) Memory: 2.4G (peak: 2.4G) CPU: 40.050s CGroup: /system.slice/elasticsearch.service ├─58459 /usr/share/elasticsearch/jdk/bin/java -Xms4m -Xmx64m -XX:+UseSerialGC -Dcli.name=server -Dcli.script=/usr/share/elasticsearch/bin/elasticsearch -Dcli.libs=lib/too> ├─58519 /usr/share/elasticsearch/jdk/bin/java -Des.networkaddress.cache.ttl=60 -Des.networkaddress.cache.negative.ttl=10 -XX:+AlwaysPreTouch -Xss1m -Djava.awt.headless=tr> └─58539 /usr/share/elasticsearch/modules/x-pack-ml/platform/linux-x86_64/bin/controller Dec 04 22:32:41 oracle systemd[1]: Starting elasticsearch.service - Elasticsearch... Dec 04 22:33:09 oracle systemd[1]: Started elasticsearch.service - Elasticsearch. ``` ## Step 4 – How to Use Elasticsearch At this point, ElasticSearch is installed and running. Now, we will need to reset the Elasticsearch default password to test the Elasticsearch functionality. Run the following command to reset the password. ``` /usr/share/elasticsearch/bin/elasticsearch-reset-password -u elastic --url http://localhost:9200 ``` You should see the following output: ``` This tool will reset the password of the [elastic] user to an autogenerated value. The password will be printed in the console. Please confirm that you would like to continue [y/N]y Password for the [elastic] user successfully reset. New value: i3EDZtY*6zK7fe*ZIovE ``` Now, run the following command to test the Elasticsearch API using the password: ``` curl -X GET 'http://localhost:9200' -u elastic ``` Sample output: ``` Enter host password for user 'elastic': { "name" : "oracle", "cluster_name" : "my-application", "cluster_uuid" : "TrgZPfVGSZyP64fkf0E9Dw", "version" : { "number" : "8.19.8", "build_flavor" : "default", "build_type" : "rpm", "build_hash" : "e34ace04b64e9bfa3f9e785b08e6d81f8efe314b", "build_date" : "2025-11-26T23:06:12.342148294Z", "build_snapshot" : false, "lucene_version" : "9.12.2", "minimum_wire_compatibility_version" : "7.17.0", "minimum_index_compatibility_version" : "7.0.0" }, "tagline" : "You Know, for Search" } ``` ## Conclusion In the above guide, we explained how to install and use Elasticsearch on OracleLinux 10. You can now use Elasticsearch with your application to search and analyze data. Give it a try on your [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Django Web Framework on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-django-web-framework-on-fedora/ | Published: 2023-07-23 | Updated: 2023-11-15 | Author: Hitesh Jethva Django is a Python-based web application framework used for developing dynamic websites and applications. It offers a set of tools that lets developers build scalable web applications. Its aim is to simplify the deployment of complex web applications and also handle the crucial part of deployment, authentication, and security. In this post, we will demonstrate how to install and use Django on Fedora Linux. ## Step 1 – Install Python Django is a Python-based application, so Python must be installed on your system. You can install it using the following command. ``` dnf install python3 python3-pip -y ``` Once the installation is complete, you can verify the Python version with the following command. ``` python3 --version ``` You will see the Python version in the following output. ``` Python 3.9.5 ``` ## Step 2 – Install Django Django code is hosted on GitHub. You can install it easily using the PIP package manager. ``` pip3 install Django ``` Once Django is installed, you can verify it with the following command. ``` django-admin --version ``` You will see the following output. ``` 4.2.3 ``` ## Step 3 – Create a Django Application Django provides a Django-admin command line utility that allows you to create a Django application via CLI. Let’s create a Django application named djangoapp. ``` django-admin startproject djangoapp ``` Next, navigate to the djangoapp directory and start the migration process using the following command. ``` cd djangoapp python3 manage.py migrate ``` Output: ``` Operations to perform: Apply all migrations: admin, auth, contenttypes, sessions Running migrations: Applying contenttypes.0001_initial... OK Applying auth.0001_initial... OK Applying admin.0001_initial... OK Applying admin.0002_logentry_remove_auto_add... OK Applying admin.0003_logentry_add_action_flag_choices... OK Applying contenttypes.0002_remove_content_type_name... OK Applying auth.0002_alter_permission_name_max_length... OK Applying auth.0003_alter_user_email_max_length... OK Applying auth.0004_alter_user_username_opts... OK Applying auth.0005_alter_user_last_login_null... OK Applying auth.0006_require_contenttypes_0002... OK Applying auth.0007_alter_validators_add_error_messages... OK Applying auth.0008_alter_user_username_max_length... OK Applying auth.0009_alter_user_last_name_max_length... OK Applying auth.0010_alter_group_name_max_length... OK Applying auth.0011_update_proxy_permissions... OK Applying auth.0012_alter_user_first_name_max_length... OK Applying sessions.0001_initial... OK ``` ## Step 4 – Create a Django Superuser Account It is recommended to secure the Django via username and password. You can create a super admin account with the following command. ``` python3 manage.py createsuperuser ``` Set your admin username and password as shown below: ``` Username (leave blank to use 'root'): admin Email address: hitjethva@gmail.com Password: Password (again): Superuser created successfully. ``` ## Step 5 – Run Django Application By default, Django can be accessed only from the local host. To access Django from the outside world, you will need to edit the Django configuration file and define your server IP. ``` nano djangoapp/settings.py ``` Define your server IP address as shown below: ``` ALLOWED_HOSTS = ['your_server_ip'] ``` Save and close the file, then run the Django application with the following command. ``` python3 manage.py runserver 0.0.0.0:8000 ``` You will see the following output. ``` Watching for file changes with StatReloader Performing system checks... System check identified no issues (0 silenced). July 13, 2023 - 10:31:08 Django version 4.2.3, using settings 'djangoapp.settings' Starting development server at http://0.0.0.0:8000/ Quit the server with CONTROL-C. ``` ## Step 6 – Access Django Application At this point, Django is installed and listens on port 8000. You can now access it using the URL **http://your-server-ip:8000.** If everything is fine, you will see Django on the following screen. ![django dashboard](https://www.atlantic.net/wp-content/uploads/2023/07/django-dashboard-min.png) ## Conclusion In this guide, we explained how to install Django on Fedora Linux. We also explained how to set the Django administrator password and run the Django application. You can now easily build your Python application and host using the Django framework. Now, deploy your Django application on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Golang on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-golang-on-fedora/ | Published: 2023-07-24 | Updated: 2023-11-15 | Author: Hitesh Jethva Go is a high-level open-source programming language developed by Google. It is very similar to C and is used to build secure, scalable systems. It is a general-purpose language and is especially useful for distributed systems and cloud services. Go is known for its concurrency and ability to run multiple tasks simultaneously. If you are looking for solving complex computational problems, then Go is the best option for you. In this post, we will show you how to install and use Golang on Fedora Linux. ## Step 1 – Install Golang By default, the Golang package is included in the Fedora default repo. You can install it using the following command. ``` dnf -y install go ``` Once Golang is installed, you can verify the Golang version using the following command. ``` go version ``` You will see the following output. ``` go version go1.16.15 linux/amd64 ``` ## Step 2 – Create an Application with Golang First, create an application directory using the following command. ``` mkdir go ``` Next, create another directory inside the Go directory. ``` cd go mkdir -p src/helloworld ``` Next, create a new application named helloworld.go. ``` cd src/helloworld nano helloworld.go ``` Add the following code. ``` package main import "fmt" func main() { fmt.Printf("hello, world\n") } ``` Save and close the file when you are done. ## Step 3 – Run the Golang Application Now, change the directory to helloworld and initialize the application using the following command. ``` cd /root/go/src/helloworld go mod init ``` Next, build the application with the following command. ``` go build ``` Now, run your application using the following command. ``` ./helloworld ``` If everything is fine, you will see the following output. ``` hello, world ``` ## Conclusion In this post, we showed you how to install Golang on Fedora Linux. You can now start building your own Golang application and hosted it in the production environment. You can now use Golang on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Angular on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-angular-on-fedora/ | Published: 2023-07-25 | Updated: 2025-08-04 | Author: Hitesh Jethva Angular is a versatile, free, open-source web application framework developed by Google. It is used to build efficient and scalable single-page mobile and desktop applications. It is fully extensible and works well with other libraries. It is based on TypeScript and provides building blocks to quickly set up a maintainable, scalable app. In this post, we will show you how to install Angular on Fedora Linux. ## Step 1 – Install Node.js Before starting, the Node.js package must be installed on your system. Follow the below steps to install the latest stable version of Node.js. First, install all the required dependencies using the following commands. ``` dnf update -y ``` ``` dnf install -y gcc-c++ make ``` Next, add the Node source repo with the following command. ``` curl -sL https://rpm.nodesource.com/setup_18.x | bash - ``` After that, install Node.js with the following command. ``` dnf install nodejs git -y ``` You can verify the Node.js version with the following command. ``` node -v ``` Output. ``` v18.19.0 ``` ## Step 2 – Install Angular CLI Angular provides a CLI utility to initialize, develop and maintain Angular applications via a command line interface. You can install it via the NPM command. ``` npm install -g @angular/cli ``` After installing Angular, you can verify its version with the following command. ``` ng version ``` Output: ``` Global setting: enabled Local setting: No local workspace configuration file. Effective status: enabled _ _ ____ _ ___ / \ _ __ __ _ _ _| | __ _ _ __ / ___| | |_ _| / △ \ | '_ \ / _` | | | | |/ _` | '__| | | | | | | / ___ \| | | | (_| | |_| | | (_| | | | |___| |___ | | /_/ \_\_| |_|\__, |\__,_|_|\__,_|_| \____|_____|___| |___/ Angular CLI: 16.1.4 Node: 18.11.0 Package Manager: npm 8.19.2 OS: linux x64 Angular: ... Package Version ------------------------------------------------------ @angular-devkit/architect 0.1601.4 (cli-only) @angular-devkit/core 16.1.4 (cli-only) @angular-devkit/schematics 16.1.4 (cli-only) @schematics/angular 16.1.4 (cli-only) ``` ## Step 3 – Create an Angular Application You can now create an Angular application using the following command. ``` ng new angular-app ``` Once the Angular application is created, navigate inside the created application and start it using the following command. ``` cd angular-app ng serve --host 0.0.0.0 --port 8080 ``` If everything is fine, you will see the following output. ``` ✔ Browser application bundle generation complete. Initial Chunk Files | Names | Raw Size vendor.js | vendor | 2.28 MB | polyfills.js | polyfills | 333.16 kB | styles.css, styles.js | styles | 230.46 kB | main.js | main | 48.10 kB | runtime.js | runtime | 6.52 kB | | Initial Total | 2.89 MB Build at: 2023-07-13T13:43:45.597Z - Hash: 46dc314ca09e79ec - Time: 9220ms ** Angular Live Development Server is listening on 0.0.0.0:8080, open your browser on http://localhost:8080/ ** ✔ Compiled successfully. ``` ## Step 4 – Access Angular Application At this point, your Angular application is starting and listening on port 8080. You can now access it using the URL **http://your-server-ip:8080.** You should see the following screen. ![angular dashboard](https://www.atlantic.net/wp-content/uploads/2023/07/angular-dashboard.png) ## Step 5 – Build Angular Application for Production If you want to use your application for production, use the “ng build” command. ``` ng build ``` You will see the following output. ``` ✔ Browser application bundle generation complete. ✔ Copying assets complete. ✔ Index html generation complete. Initial Chunk Files | Names | Raw Size | Estimated Transfer Size main.034889dcd4e28a74.js | main | 204.80 kB | 56.01 kB polyfills.da805e0bf15a1686.js | polyfills | 33.02 kB | 10.63 kB runtime.fe3a75fab6275a44.js | runtime | 900 bytes | 514 bytes styles.ef46db3751d8e999.css | styles | 0 bytes | - | Initial Total | 238.69 kB | 67.14 kB Build at: 2023-07-13T13:47:06.202Z - Hash: a0b04b4abae2d0b9 - Time: 66579ms ``` The above command will create a ‘dist/’ directory in your project folder with the compiled Angular application. You can check it with the following command. ``` ls dist/angular-app/ ``` You will see all application files in the following output. ``` 3rdpartylicenses.txt favicon.ico index.html main.034889dcd4e28a74.js polyfills.da805e0bf15a1686.js runtime.fe3a75fab6275a44.js styles.ef46db3751d8e999.css ``` ## Conclusion In this post, you learned how to install Angular and create a sample application via the CLI tool. You have now an Angular environment ready to build an interactive single-page application. You can now try to deploy the Angular application on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How To Install Glances Monitoring Tool on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-glances-monitoring-tool-on-fedora/ | Published: 2023-07-26 | Updated: 2023-11-16 | Author: Hitesh Jethva Glances is an open-source, cross-platform monitoring solution that allows real-time monitoring of CPU, memory, disk, and more. With Glances, you can also monitor filesystem I/O, network I/O, and sensor readouts to display CPU and other hardware temperatures. It is written in Python and can be installed on Windows and Linux operating systems. In this post, we will show you how to install and use Glances to monitor system performance on Fedora Linux. ## Step 1 – Install Required Dependencies Glances is a Python-based application, so you will need to install Python and other required packages on your server. Run the following command to install all of them. ``` dnf update -y dnf install python3 python3-pip ``` Also, install the bottle module using the following command. ``` pip3 install bottle ``` Once all the packages are installed, you can proceed to the next step. ## Step 2 – Install Glances By default, the Glances package is included in the Fedora default repo. You can install it using the following command. ``` dnf install glances -y ``` Once Glances is installed, you can verify it with the following command. ``` rpm -qi glances ``` You will see the Glances package information on the following output. ``` Name : glances Version : 3.1.4.1 Release : 9.fc34 Architecture: noarch Install Date: Thu 13 Jul 2023 11:43:40 PM EDT Group : Unspecified Size : 6644599 License : GPLv3 Signature : RSA/SHA256, Tue 26 Jan 2021 06:20:56 AM EST, Key ID 1161ae6945719a39 Source RPM : glances-3.1.4.1-9.fc34.src.rpm Build Date : Tue 26 Jan 2021 06:08:15 AM EST Build Host : buildvm-ppc64le-27.iad2.fedoraproject.org Packager : Fedora Project Vendor : Fedora Project URL : https://github.com/nicolargo/glances Bug URL : https://bugz.fedoraproject.org/glances Summary : CLI curses based monitoring tool Description : Glances is a CLI curses based monitoring tool for both GNU/Linux and BSD. ``` ## Step 3 – Run Glances in Standalone Mode After Glances installation, you can run the Glances in a standalone mode to show all the details in the current terminal interface. ``` glances ``` You will see your system information on the following screen. ![glances cli dashboard](https://www.atlantic.net/wp-content/uploads/2023/07/glances-cli-dashboard.png) ## Step 4 – Run Glances in Web Mode You can also run Glances in web mode. In this mod, you can access the Glances web interface from the remote machine and monitor the system performance. Let’s run Glances in web mode using the -w option. ``` glances -w ``` You will see the following output. ``` Glances Web User Interface started on http://0.0.0.0:61208/ ``` Now, open your web browser and access the Glances web dashboard using the URL **http://your-server-ip:61208.** You will see the Glances dashboard on the following screen. ![glances web dashboard](https://www.atlantic.net/wp-content/uploads/2023/07/glances-web-dashboard.png) ## Conclusion In this post, we explained how to install the Glances monitoring tool on Fedora Linux. You can now use Glances in a production environment to monitor your server performance in real-time. You can now try to use the Glances monitoring tool on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install InfluxDB on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-influxdb-on-fedora/ | Published: 2023-07-27 | Updated: 2023-11-14 | Author: Hitesh Jethva InfluxDB is a free and open-source time series database written in the Go programming language. It is designed to store time series data for operations monitoring, application metrics, IoT sensor data, and real-time analytics. It can store data ranging from hundreds of thousands of points per second. It is gaining popularity due to its fast processing and low latency features. In this post, we will show you how to install InfluxDB on Fedora Linux. ## Step 1 – Create InfluxDB Repo By default, the InfluxDB package is not included in the Fedora default repo, so you will need to create a repo for that. ``` nano /etc/yum.repos.d/influxdb.repo ``` Add the following lines. ``` [influxdb] name = InfluxDB Repository - RHEL baseurl = https://repos.influxdata.com/rhel/8/x86_64/stable/ enabled = 1 gpgcheck = 1 gpgkey = https://repos.influxdata.com/influxdata-archive_compat.key ``` Save and close the file when you are finished. ## Step 2 – Install InfluxDB You can now install the InfluxDB using the following command. ``` dnf install influxdb2 influxdb2-cli ``` After installing InfluxDB, you can verify the InfluxDB version with the following command. ``` influx version ``` You will see the following output. ``` Influx CLI dev (git: none) build_date: 2023-04-28T14:24:14Z ``` You can also see the detailed information on InfluxDB with the following command. ``` rpm -qi influxdb2 ``` Output. ``` Name : influxdb2 Version : 2.7.1 Release : 1 Architecture: x86_64 Install Date: Thu 13 Jul 2023 10:32:32 AM EDT Group : default Size : 103759839 License : MIT Signature : RSA/SHA512, Fri 28 Apr 2023 01:47:08 PM EDT, Key ID d8ff8e1f7df8b07e Source RPM : influxdb2-2.7.1-1.src.rpm Build Date : Fri 28 Apr 2023 09:28:30 AM EDT Build Host : ip-10-0-35-48.ec2.internal Relocations : / Packager : support@influxdb.com Vendor : InfluxData URL : https://influxdata.com Summary : Distributed time-series database. Description : Distributed time-series database. ``` ## Step 3 – Start InfluxDB Service After installing InfluxDB, start the InfluxDB service and enable it to start at system reboot. ``` systemctl start influxdb systemctl enable influxdb ``` You can now check the status of InfluxDB with the following command. ``` systemctl status influxdb ``` You will see the following output. ``` ● influxdb.service - InfluxDB is an open-source, distributed, time series database Loaded: loaded (/usr/lib/systemd/system/influxdb.service; enabled; vendor preset: disabled) Active: active (running) since Thu 2023-07-13 10:33:15 EDT; 4s ago Docs: https://docs.influxdata.com/influxdb/ Process: 15431 ExecStart=/usr/lib/influxdb/scripts/influxd-systemd-start.sh (code=exited, status=0/SUCCESS) Main PID: 15432 (influxd) Tasks: 8 (limit: 4666) Memory: 46.1M CPU: 599ms CGroup: /system.slice/influxdb.service └─15432 /usr/bin/influxd ``` ## Step 4 – Access InfluxDB At this point, InfluxDB is started and listens on port 8086. You can check it with the following command. ``` ss -tunelp| grep 8086 ``` You will see the following output. ``` tcp LISTEN 0 4096 *:8086 *:* users:(("influxd",pid=15432,fd=9)) uid:992 ino:129931 sk:100b cgroup:/system.slice/influxdb.service v6only:0 <-> ``` Now, open your web browser and access the InfluxDB web interface using the URL **http://your-server-ip:8086.** You will see InfluxDB user welcome screen. ![influxdb welcome page](https://www.atlantic.net/wp-content/uploads/2023/07/influxdb-welcome-page.png) Click on the **GET STARTED** button. You will see the InfluxDB setup screen. ![setup user](https://www.atlantic.net/wp-content/uploads/2023/07/setup-user.png) Define your username and password and click on **CONTINUE.** You should see the following screen. ![installation completed](https://www.atlantic.net/wp-content/uploads/2023/07/installation-completed.png) Click on the **QUICK START** button. You should see the InfluxDB dashboard on the following screen. ![influxdb dashboard](https://www.atlantic.net/wp-content/uploads/2023/07/influxdb-dashboard.png) ## Conclusion In this tutorial, we showed you how to install InfluxDB on Fedora Linux. You can now manage all your databases from the central location via a web browser. You can now deploy InfluxDB on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Atlantic.Net and mesibo Introduce World’s First One-Click Real-Time Communication-Platform-as-a-Service (CPaaS) > URL: https://www.atlantic.net/cloud-platform/atlantic-net-and-mesibo-introduce-worlds-first-one-click-real-time-communication-platform-as-a-service-cpaas/ | Published: 2023-08-01 | Updated: 2025-09-15 | Author: Alexander Wise ![Infograph](https://www.atlantic.net/wp-content/themes/anet/img/resources/misc/mesibo-infographic.jpg) Atlantic.Net and mesibo released the **world’s first** **one-click deployable real-time Communication-Platform-as-a-Service (CPaaS) for businesses and developers.** This partnership brings together Atlantic.Net, a leading global cloud services provider, and mesibo, the leading and most secure CPaaS provider, to enable enterprises, solution integrators, and developers worldwide with easy access to a highly secure and robust real-time communication platform in just one click. The partnership between Atlantic.Net and mesibo facilitates the adoption of self-hosted CPaaS for businesses covered by regulatory compliance standards, **even if they lack technical expertise**, thanks to Atlantic.Net’s optional cybersecurity and compliance managed services. The collaboration marks a significant and disruptive shift in the CPaaS industry, providing businesses with seamless access to self-hosted CPaaS services through Atlantic.Net’s cloud infrastructure. This partnership empowers customers with the world’s most secure and scalable communication platform, enabling them to easily add secure end-to-end encrypted messaging, calls, conferencing, and AI-driven chatbots into their applications and websites. This will result in increased customer market penetration in today’s app-driven landscape, where**90% of apps, such as ridesharing, social media, telemedicine, financial services, customer support, multi-party games, and more, rely on real-time communication.** The CPaaS one-click messaging application will be hosted on the Atlantic.Net cloud, enabling customers to set up communication services, like messaging, calls, and conferencing, in under 30 seconds. Atlantic.Net is offering a free-to-use G3.2GB cloud server for one full year, making it even more cost-effective for businesses to host mesibo CPaaS. --- # Atlantic.Net and mesibo introduce world’s first one-click real-time communication-platform-as-a-service > URL: https://www.atlantic.net/press-releases/atlantic-net-and-mesibo-introduce-worlds-first-one-click-real-time-communication-platform-as-a-service/ | Published: 2023-08-01 | Updated: 2024-06-11 | Author: Editorial Team **ATLANTIC.NET AND MESIBO INTRODUCE WORLD’S FIRST ONE-CLICK REAL-TIME COMMUNICATION-PLATFORM-AS-A-SERVICE (CPaaS)** **Atlantic.Net and mesibo Revolutionize $12 Billion CPaaS Industry with Secure Self-Hosted** **Real-Time Communication Platform in a Single Click** **Groundbreaking Collaboration Enables Businesses and Developers to Effortlessly** **Harness Power of Real-Time Communication & AI** Orlando, Florida and Palo Alto, California, August 1, 2023 — Atlantic.Net https://www.atlantic.net and mesibo https://mesibo.com/ released today the world’s first one-click deployable real-time Communication-Platform-as-a-Service (CPaaS) for businesses and developers. This partnership brings together Atlantic.Net, a leading global cloud services provider, and mesibo, the leading and most secure CPaaS provider, to enable enterprises, solution integrators, and developers worldwide with easy access to a highly secure and robust real-time communication platform in just one click. Businesses are changing the way they use CPaaS solutions. The growing emphasis on data protection, security, and regulatory compliance has led businesses to favor self-hosted CPaaS platforms over third-party CPaaS services. This trend is particularly relevant for organizations dealing with sensitive or regulated data, such as medical records, financial information, and AI training data. By adopting self-hosted CPaaS solutions, these organizations gain greater control over data protection measures, allowing them to implement specific security protocols and ensure compliance with industry regulations, like HIPAA, SEC, and others. The partnership between Atlantic.Net and mesibo facilitates the adoption of self-hosted CPaaS for businesses covered by regulatory compliance standards, even if they lack technical expertise, thanks to Atlantic.Net’s optional cybersecurity and compliance managed services. The demand for reliable CPaaS platforms has skyrocketed, with over 8.9 million apps contributing to this unprecedented growth. Moreover, the rise of AI and LLM (Large Language Model) technologies, like ChatGPT, has intensified the demand for a scalable communication platform, as AI and LLM depend heavily on effective and reliable real-time communication channels. Consequently, the CPaaS market has grown from $2 billion in 2016 to $12.5 billion in 2022 and is projected to reach $45.3 billion by 2027. **A Milestone Partnership for CPaaS Industry and for Businesses** The collaboration marks a significant and disruptive shift in the CPaaS industry, providing businesses with seamless access to self-hosted CPaaS services through Atlantic.Net’s cloud infrastructure. This partnership empowers customers with the world’s most secure and scalable communication platform, enabling them to easily add secure end-to-end encrypted messaging, calls, conferencing, and AI-driven chatbots into their applications and websites. This will result in increased customer market penetration in today’s app-driven landscape, where **90% of apps, such as ridesharing, social media, telemedicine, financial services, customer support, multi-party games, and more, rely on real-time communication.** The combined expertise of both organizations will immensely benefit enterprises and developers. Leveraging mesibo’s unparalleled expertise in communication technology and Atlantic.Net’s comprehensive suite of Cloud and Managed Services, along with a 100% uptime SLA and support for HIPAA and PCI compliance, the one-click CPaaS platform promises exceptional performance and security. The CPaaS one-click messaging application will be hosted on the Atlantic.Net cloud, enabling customers to set up communication services, like messaging, calls, and conferencing, in under 30 seconds. Atlantic.Net is offering a free-to-use G3.2GB cloud server for one full year, making it even more cost-effective for businesses to host mesibo CPaaS. “In today’s landscape, where real-time messaging, streaming video, and games dominate, latency has become a crucial indicator of success. A centralized cloud infrastructure alone is unable to meet these latency requirements. Therefore, we have made the strategic decision to capitalize on our partnership with hosting providers rather than providing the services ourselves — a win-win for both parties,” said Yusuf Motiwala, Founder & CEO of mesibo. “Offering mesibo’s secure messaging platform as a one-click installation allows our customers to effortlessly expand their customer service features. Customers choose us for secure cloud services, so including the world’s most secure messaging platform among our one-click apps just makes sense,” said Marty Puranik, Founder and CEO of Atlantic.Net. “For over 29 years, we’ve promised our customers powerful, easy-to-use hosting solutions, and mesibo helps us fulfill that promise.” **About Atlantic.Net** Atlantic.Net is a global cloud services provider with over 29 years of experience, specializing in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions. With millions of servers worldwide and a focus on security, compliance, and a simplified user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions, backed by 24/7/365 support through their global data centers located in New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando. Atlantic.Net provides a secure, affordable platform at all-inclusive pricing. From meeting the strictest security, privacy, and compliance requirements to ensuring a robust and scalable hosting environment, Atlantic.Net’s Compliance Hosting Solutions are a perfect fit for financial services and healthcare organizations that require the most robust security levels for their data. Certified and audited by third-party independent auditors, Atlantic.Net Compliance Hosting Solutions fulfill HIPAA, HITECH, PCI, and SOC requirements. For more information, see www.atlantic.net. **About mesibo** mesibo is a leading provider of real-time and secure Communication Platform as a Service (CPaaS). mesibo offers a comprehensive solution for in-app messaging, calls, conferencing, and chatbot functionalities. The platform goes beyond cloud-based services by empowering customers to opt for self-hosting, providing them with enhanced security and control over their communication processes and data. With its robust end-to-end encryption protocol, mesibo ensures the highest level of security for communication. Since its launch, mesibo has rapidly gained traction, with more than 11,000 developers from over 40 countries choosing to deploy it in their apps across diverse markets. These markets span telemedicine, dating, social networking, governments, enterprise communication, ridesharing, hospitality, and even unconventional areas like integrating with hardware, such as coffee machines, weighing machines, and televisions. This widespread adoption speaks volumes about the significance of robust communication solutions within today’s app landscape. For more information, see www.mesibo.com. Photos: [Google Drive](https://drive.google.com/drive/folders/1Awmxyo0-0ETgRn0rKvP4wgtnrhy3JkiG?usp=sharing) Atlantic.Net Agency Press Contact: Karen Thomas/Eva Yutani Thomas PR (631) 549-7575 kthomas@thomaspr.com / eyutani@thomaspr.com Atlantic.Net Company Contact: (321) 206-1371 pr@atlantic.net Mesibo Company Contact: support@mesibo.com --- # How to Install Strapi with Nginx on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-strapi-with-nginx-on-fedora/ | Published: 2023-08-04 | Updated: 2024-01-18 | Author: Hitesh Jethva Strapi is a free, open-source, next-generation headless CMS used to develop websites, mobile applications, eCommerce sites, and APIs. It helps developers to create an API without using any database and backend. Strapi gives you the freedom to use your favorite tools and allows content editors to streamline content delivery across any device. In this post, we will show you how to install Strapi CMS on Fedora Linux. ## Step 1 – Install Node.js Strapi is based on Node.js, so you will need to install Node.js on your server. First, install all required dependencies using the following command. ``` dnf install -y gcc-c++ make git ``` Next, add the Node source repo with the following command. ``` curl -sL https://rpm.nodesource.com/setup_18.x | bash - ``` After that install Node.js with the following command. ``` dnf install nodejs ``` You can verify the Node.js version with the following command. ``` node -v ``` ``` v18.19.0 ``` ## Step 2 – Install PostgreSQL Strapi uses PostgreSQL as a database backend, so you will need to install PostgreSQL on your server. First, enable the PostgreSQL module. ``` dnf module enable postgresql:13 ``` Next, install the PostgreSQL server using the following command. ``` dnf install postgresql-server ``` Then, initialize the PostgreSQL database. ``` postgresql-setup --initdb ``` After that, start and enable the PostgreSQL service. ``` systemctl enable postgresql systemctl start postgresql ``` Next, connect to the PostgreSQL shell. ``` sudo -u postgres psql ``` Next, set the PostgreSQL password and create a Strapi database. ``` ALTER USER postgres PASSWORD 'password'; create database strapi; ``` Next, exit from the PostgreSQL shell. ``` \q ``` ## Step 3 – Create a Strapi Application You can use the **npx** command line utility to easily create a Strapi app. ``` npx create-strapi-app@latest strapi --no-run ``` You will see the following output. ``` Need to install the following packages: create-strapi-app@4.11.5 Ok to proceed? (y) y ? Choose your installation type Quickstart (recommended) ``` Next, navigate to the **strapi** directory and build the application with the following command. ``` cd strapi npm run build ``` Output: ``` > strapi@0.1.0 build > strapi build ``` Building your admin UI with development configuration… ``` ✔ Webpack Compiled successfully in 30.45s Admin UI built successfully ``` Next, edit the server.js file and define your domain. ``` nano ./config/server.js ``` Change the following lines: ``` module.exports = ({ env }) => ({ host: env('HOST', '0.0.0.0'), port: env.int('PORT', 1337), url: 'http://strapiapp.example.com', app: { keys: env.array('APP_KEYS'), }, webhooks: { populateRelations: env.bool('WEBHOOKS_POPULATE_RELATIONS', false), }, }); ``` Save and close the file, then run Strapi in development mode. ``` npm run develop ``` If everything is fine, you will get the following output. ``` Project information ┌────────────────────┬──────────────────────────────────────────────────┐ │ Time │ Thu Jul 13 2023 10:06:52 GMT-0400 (Eastern Dayl… │ │ Launched in │ 2236 ms │ │ Environment │ development │ │ Process PID │ 13769 │ │ Version │ 4.11.5 (node v18.11.0) │ │ Edition │ Community │ │ Database │ sqlite │ └────────────────────┴──────────────────────────────────────────────────┘ Actions available One more thing... Create your first administrator 💻 by going to the administration panel at: ┌────────────────────────────────────┐ │ http://strapiapp.example.com/admin │ └────────────────────────────────────┘ ``` Press the **CTRL+C** to stop the application. ## Step 4 – Create a Systemd Service for Strapi It is recommended to create a systemd file to manage the Strapi service. ``` nano /etc/systemd/system/strapi.service ``` Add the following configurations. ``` [Unit] Description=Strapi Project After=network.target [Service] Type=simple WorkingDirectory=/root/strapi User=root ExecStart=/usr/bin/node /root/strapi/node_modules/.bin/strapi develop [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the Strapi service to start at system reboot. ``` systemctl start strapi systemctl enable strapi ``` You can verify the Strapi service status using the following command. ``` systemctl status strapi ``` Output: ``` ● strapi.service - Strapi Project Loaded: loaded (/etc/systemd/system/strapi.service; disabled; vendor preset: disabled) Active: active (running) since Thu 2023-07-13 10:12:23 EDT; 3s ago Main PID: 14102 (node) Tasks: 14 (limit: 4666) Memory: 224.7M CPU: 4.403s CGroup: /system.slice/strapi.service ├─14102 /usr/bin/node /root/strapi/node_modules/.bin/strapi develop └─14116 /usr/bin/node /root/strapi/node_modules/.bin/strapi develop Jul 13 10:12:23 fedora systemd[1]: Started Strapi Project. ``` ## Step 5 – Configure Nginx for Strapi App First, install the Nginx package with the following command. ``` dnf install nginx ``` Next, create a new Nginx virtual host configuration file. ``` nano /etc/nginx/conf.d/strapi.conf ``` Add the following configurations: ``` # Strapi server upstream strapi { server 127.0.0.1:1337; } server { listen 80; server_name strapiapp.example.com; # Proxy Config location / { proxy_pass http://strapi; proxy_http_version 1.1; proxy_set_header X-Forwarded-Host $host; proxy_set_header X-Forwarded-Server $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header Host $http_host; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "Upgrade"; proxy_pass_request_headers on; } } ``` Save and close the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http{: ``` server_names_hash_bucket_size 64; ``` Save the file, then verify the Nginx configuration. ``` nginx -t ``` You should see the following output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, start the Nginx service to implement the changes. ``` systemctl start nginx ``` ## Step 6 – Access Strapi Web UI At this point, Strapi is installed and configured. You can now access the Strapi web interface using the URL **http://strapiapp.example.com/admin.** You should see the user registration page. ![strapi registration page](https://www.atlantic.net/wp-content/uploads/2023/07/strapi-registration-page.png) Provide your name, email, and password, and click on the **Let’s start** button. You will be redirected to the Strapi dashboard. ![strapi dashboard](https://www.atlantic.net/wp-content/uploads/2023/07/strapi-dashboard.png) ## Conclusion In this post, we have shown you how to install Strapi on Fedora Linux. We also installed and configured Nginx as a reverse proxy for Strapi. You can now use Strapi in the production environment to create an API easily. Try to deploy the Strapi application on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Atlantic.Net Shortlisted at The SaaS Awards 2023 International SaaS Awards Program Announces Initial Shortlist > URL: https://www.atlantic.net/press-releases/atlantic-net-shortlisted-at-the-saas-awards-2023-international-saas-awards-program-announces-initial-shortlist/ | Published: 2023-08-05 | Updated: 2024-06-03 | Author: Editorial Team Orlando, Florida – August 5, 2023 – Atlantic.Net has been shortlisted in the 2023 SaaS Awards program. Now in its 8th year, The SaaS Awards continues to celebrate the ultimate SaaS innovations across the globe. Entries were received from North America, Canada, Europe, the Middle East, and Australasia. The program’s categories for 2023 include ‘Bespoke SaaS Solution,’ ‘Best SaaS Product for Business Intelligence or Analytics,’ and ‘Most Agile or Responsive SaaS Solution of the Year,’ among others, covering a broad gamut of industries with innovative SaaS solutions. James Williams, Head of Operations at The SaaS Awards, said: “Year after year, we are thrilled by the intensity of the competition and innovation showcased in each entry. The quality of this year’s submissions indicates a thrilling competition ahead in the next stages of the program. Identifying which of these exceptional SaaS solutions comes out absolutely on top will not be easy. The organizations announced today as shortlistees, including Atlantic.Net, embody the remarkable quality and level of innovation achieved this year. Our esteemed panel of judges is delighted to recognize such world-beating SaaS innovators.” Marty Puranik, founder, president, and CEO of Atlantic.Net, said, “Being shortlisted for the prestigious SaaS Awards is a testament to our relentless pursuit of excellence. For nearly three decades, our primary goal has been to provide solutions to businesses of all sizes. This recognition is a reaffirmation that our efforts are being acknowledged on an international scale.” SaaS Awards finalists will be announced on Tuesday, August 16, 2023, with the final winners revealed on September 13, 2023. The program will return in 2024 to continue recognizing international SaaS excellence across various industries. Hundreds of entries were received at The SaaS Awards 2023 from across the globe. To view the full shortlist, please visit:[https://www.cloud-awards.com/2023-saas-awards-shortlist/](https://www.cloud-awards.com/2023-saas-awards-shortlist/). The Cloud Awards and The Cloud Security Awards are now accepting nominations for their respective programs, recognizing excellence in cloud computing and cloud security. The early entry deadline for The Cloud Awards is September 1, 2023. About Atlantic.Net:   Atlantic.Net is a global cloud services provider with over two decades of experience, specializing in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions. Solutions are offered across hosting facilities in San Francisco, New York, London, Toronto, Dallas, Ashburn, and Orlando. For more information, please visit [www.atlantic.net](https://www.atlantic.net) --- # How to Install pgAdmin on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-pgadmin-on-fedora/ | Published: 2023-08-07 | Updated: 2023-11-15 | Author: Hitesh Jethva pgAdmin is an advanced open-source database management tool that allows you to manage PostgreSQL databases via a web browser. It provides a Graphical User Interface to interact with remote and local PostgreSQL and perform database operations. pgAdmin is written in Python and jQuery and supports all the features found in PostgreSQL. In this guide, we will show you how to install pgAdmin on Fedora Linux. ## Step 1 – Install PostgreSQL First, list all available PostgreSQL versions using the following command. ``` dnf module list postgresql ``` You will see the following output. ``` Last metadata expiration check: 0:05:00 ago on Thu 13 Jul 2023 06:28:07 AM EDT. Fedora Modular 34 - x86_64 Name Stream Profiles Summary postgresql 9.6 client, server [d] PostgreSQL module postgresql 10 client, server [d] PostgreSQL module postgresql 11 client, server [d] PostgreSQL module postgresql 12 client, server PostgreSQL module postgresql 13 client, server PostgreSQL module Fedora Modular 34 - x86_64 - Updates Name Stream Profiles Summary postgresql 9.6 client, server [d] PostgreSQL module postgresql 10 client, server [d] PostgreSQL module postgresql 11 client, server [d] PostgreSQL module postgresql 12 client, server PostgreSQL module postgresql 13 client, server PostgreSQL module postgresql 14 client, server PostgreSQL module Hint: [d]efault, [e]nabled, [x]disabled, [i]nstalled ``` Next, enable the latest PostgreSQL version with the following command. ``` dnf module enable postgresql:14 ``` Next, install PostgreSQL 14 on your server. ``` dnf install postgresql-server -y ``` After the successful installation, initialize the PostgreSQL database. ``` postgresql-setup --initdb ``` Output: ``` * Initializing database in '/var/lib/pgsql/data' * Initialized, logs are in /var/lib/pgsql/initdb_postgresql.log ``` Next, start and enable the PostgreSQL service. ``` systemctl enable postgresql systemctl start postgresql ``` To verify the PostgreSQL status, run the following command. ``` systemctl status postgresql ``` You will see the following output. ``` ● postgresql.service - PostgreSQL database server Loaded: loaded (/usr/lib/systemd/system/postgresql.service; disabled; vendor preset: disabled) Active: active (running) since Thu 2023-07-13 06:34:19 EDT; 6s ago Process: 2277 ExecStartPre=/usr/libexec/postgresql-check-db-dir postgresql (code=exited, status=0/SUCCESS) Main PID: 2279 (postmaster) Tasks: 8 (limit: 4666) Memory: 15.9M CPU: 53ms CGroup: /system.slice/postgresql.service ├─2279 /usr/bin/postmaster -D /var/lib/pgsql/data ├─2280 postgres: logger ├─2282 postgres: checkpointer ├─2283 postgres: background writer ├─2284 postgres: walwriter ├─2285 postgres: autovacuum launcher ├─2286 postgres: stats collector └─2287 postgres: logical replication launcher ``` ## Step 2 – Install pgAdmin By default, pgAdmin is not included in the Fedora default repo, so you will need to install the pgAdmin repo to your server. ``` rpm -Uvh https://ftp.postgresql.org/pub/pgadmin/pgadmin4/yum/pgadmin4-fedora-repo-2-1.noarch.rpm ``` Once the repo is created, install the pgAdmin with the following command. ``` dnf install pgadmin4-web -y ``` Next, install other required packages with the following command. ``` dnf install policycoreutils-python-utils -y ``` ## Step 3 – Configure the pgAdmin User Account To access the pgAdmin web interface, you will need to set up a user and password for pgAdmin. Run the following script to set up an admin account. ``` /usr/pgadmin4/bin/setup-web.sh ``` You will be asked to provide your email and password as shown below. ``` Setting up pgAdmin 4 in web mode on a Redhat based platform... Creating configuration database... NOTE: Configuring authentication for SERVER mode. Enter the email address and password to use for the initial pgAdmin user account: Email address: hitjethva@gmail.cpom Password: Retype password: pgAdmin 4 - Application Initialisation ====================================== Creating storage and log directories... Configuring SELinux... /usr/pgadmin4/bin/setup-web.sh: line 100: semanage: command not found /usr/pgadmin4/bin/setup-web.sh: line 102: semanage: command not found The Apache web server is not running. We can enable and start the web server for you to finish pgAdmin 4 installation. Continue (y/n)? y Created symlink /etc/systemd/system/multi-user.target.wants/httpd.service → /usr/lib/systemd/system/httpd.service. Apache successfully enabled. Apache successfully started. You can now start using pgAdmin 4 in web mode at http://127.0.0.1/pgadmin4 ``` The above command will start the Apache server automatically. You can verify it with the following command. ``` systemctl status httpd ``` Output: ``` ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; enabled; vendor preset: disabled) Active: active (running) since Thu 2023-07-13 06:36:50 EDT; 19s ago Docs: man:httpd.service(8) Main PID: 3297 (httpd) Status: "Total requests: 0; Idle/Busy workers 100/0;Requests/sec: 0; Bytes served/sec: 0 B/sec" Tasks: 205 (limit: 4666) Memory: 35.0M CPU: 305ms CGroup: /system.slice/httpd.service ├─3297 /usr/sbin/httpd -DFOREGROUND ├─3298 /usr/sbin/httpd -DFOREGROUND ├─3299 /usr/sbin/httpd -DFOREGROUND ├─3300 /usr/sbin/httpd -DFOREGROUND ├─3301 /usr/sbin/httpd -DFOREGROUND └─3302 /usr/sbin/httpd -DFOREGROUND Jul 13 06:36:50 fedora systemd[1]: Starting The Apache HTTP Server... ``` ## Step 4 – Access pgAdmin Web Interface At this point, pgAdmin is installed and listens on port 80. You can access it using the URL **http://your-server-ip/pgadmin4.** You should see the pgAdmin login screen. ![pgadmin web login](https://www.atlantic.net/wp-content/uploads/2023/07/pgadmin-web-login-min.png) Provide your email address and password and click on **Login**. You will see the pgAdmin dashboard on the following screen. ![pgadmin dashboard](https://www.atlantic.net/wp-content/uploads/2023/07/pgadmin-dashboard.png) ## Conclusion In this tutorial, we explained how to install pgAdmin on Fedora Linux. You can now add your remote PostgreSQL server to pgAdmin and start managing them via the central dashboard. You can now use pgAdmin to monitor a PostgreSQL server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How To Install Cacti Monitoring Tool on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-cacti-monitoring-tool-on-fedora/ | Published: 2023-08-08 | Updated: 2023-11-16 | Author: Hitesh Jethva Cacti is an open-source web-based monitoring and graphing tool. It provides an extensible and fault management framework for users to monitor network applications. It is a frontend to RRDTool that stores all of the necessary information to create graphs and populate them with data in a MySQL database. Cacti uses the SNMP protocol to monitor different network devices including routers, servers, and switches. If you are looking for an open-source solution to monitor your IT infrastructure then Cacti is the best option for you. In this post, we will show you how to install Cacti Monitoring Tool on Fedora Linux. ## Step 1 – Install Required Dependencies First, you will need to install development tools on your server. You can install all of them using the following commands. ``` dnf update -y ``` ``` dnf groupinstall "Development Tools" -y ``` Next, install other required dependencies using the command given below. ``` dnf install -y net-snmp net-snmp-utils rrdtool -y ``` Once all the packages are installed, you can proceed to the next step. ## Step 2 – Install Apache, MariaDB, and PHP First, install Apache and MariaDB with the following command. ``` dnf install httpd mariadb-server -y ``` Once installed, start and enable both Apache and MariaDB services. ``` systemctl enable --now httpd mariadb ``` Next, install PHP and other required extensions using the following command. ``` dnf install -y php php-{mysqlnd,curl,gd,intl,pear,ldap,xmlrpc,snmp,mbstring,gettext,gmp,json,xml,common} ``` Next, edit the PHP configuration file and change some default settings. ``` nano /etc/php.ini ``` Change the following settings. ``` date.timezone = UTC memory_limit = 512M max_execution_time = 300 ``` Save and close the file, then start and enable the PHP-FPM service. ``` systemctl enable --now php-fpm ``` ## Step 3 – Configure MariaDB Database First, log in to your MariaDB shell with the following command. ``` mysql ``` Once you are logged in, create a database and user for Cacti. ``` CREATE DATABASE cacti; GRANT ALL ON cacti.* TO 'cacti'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB console. ``` FLUSH PRIVILEGES; exit; ``` Next, edit the MariaDB default configuration file and tweak some settings. ``` nano /etc/my.cnf.d/mariadb-server.cnf ``` Add the following lines below [mysqld] ``` character-set-server=utf8mb4 collation-server=utf8mb4_unicode_ci max_heap_table_size=128M tmp_table_size=128M join_buffer_size=128M innodb_buffer_pool_size=1024M innodb_doublewrite=ON innodb_flush_log_at_timeout=3 innodb_read_io_threads=32 innodb_write_io_threads=16 innodb_buffer_pool_instances=10 innodb_file_format=Barracuda innodb_large_prefix=1 innodb_io_capacity=5000 innodb_io_capacity_max=10000 ``` Save and close the file, then restart the MariaDB service. ``` systemctl restart mariadb ``` ## Step 4 – Install and Configure Cacti First, change the directory to the Apache web root and download the latest version of Cacti. ``` cd /var/www/html/ wget --no-check-certificate https://www.cacti.net/downloads/cacti-latest.tar.gz ``` Next, extract the downloaded file. ``` tar -xvzf cacti-latest.tar.gz ``` Then, rename the extracted directory to cacti ``` mv cacti-1.2.24 cacti ``` Next, import the Cacti schema to the cacti database. ``` cd cacti mysql -u root -p cacti < /var/www/html/cacti/cacti.sql ``` Also, import the timezone information to MySQL. ``` mysql_tzinfo_to_sql /usr/share/zoneinfo | mysql -u root -p mysql ``` Next, log in to the MariaDB shell and change the default CHARACTER SET. ``` mysql GRANT SELECT ON mysql.time_zone_name TO cacti@localhost; ALTER DATABASE cacti CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci; ``` Next, flush the privileges and exit from the MariaDB shell. ``` FLUSH PRIVILEGES; EXIT; ``` Next, copy the Cacti configuration file and edit it with nano editor. ``` cp /var/www/html/cacti/include/config.php.dist /var/www/html/cacti/include/config.php nano /var/www/html/cacti/include/config.php ``` Define your database settings. ``` $database_type = 'mysql'; $database_default = 'cacti'; $database_hostname = 'localhost'; $database_username = 'cacti'; $database_password = 'password'; $database_port = '3306'; ``` Next, create a log file for Cacti and set proper permission on the Cacti directory. ``` touch /var/www/html/cacti/log/cacti.log chown -R apache:apache /var/www/html/cacti ``` Finally, restart both the Apache and PHP-FPM services to apply the changes. ``` systemctl restart httpd php-fpm ``` ## Step 6 – Access Cacti Web Installation Wizard Now, open your web browser and access your Cacti installation via **http://your-server-ip/cacti.** You will see the Cacti login screen. ![cacti login page](https://www.atlantic.net/wp-content/uploads/2023/07/cacti-login-page.png) Provide Cacti with the default username and password as admin/admin then click on the **Login** button. You will see the change password screen. ![change password](https://www.atlantic.net/wp-content/uploads/2023/07/change-password.png) Set your new password and click on the **Save** button. You will see the License agreement screen. ![license agreement](https://www.atlantic.net/wp-content/uploads/2023/07/license-agreement.png) Accept the agreement and click on **Begin.** You will see the MySQL setting screen. ![mysql settings](https://www.atlantic.net/wp-content/uploads/2023/07/mysql-settings.png) Click on the **Next** button. You should see the Installation Type screen. ![choose installation type](https://www.atlantic.net/wp-content/uploads/2023/07/choose-installation-type.png) Select your server and click on the **Next** button. You will see the check directory permission screen. ![check directory permission](https://www.atlantic.net/wp-content/uploads/2023/07/unnamed-file.png) Confirm all permissions and click on the **Next** button. You will see the verify binary location screen. ![verify binary location](https://www.atlantic.net/wp-content/uploads/2023/07/verify-binary-location.png) Click on the **Next** button. You will see the Input validation screen. ![input validation](https://www.atlantic.net/wp-content/uploads/2023/07/input-validation.png) Click on the **Next** button. You will see the Profile setting page. ![set default profile](https://www.atlantic.net/wp-content/uploads/2023/07/set-default-profile.png) Select all required options and click on the **Next** button. You will see the template setup screen. ![template setup](https://www.atlantic.net/wp-content/uploads/2023/07/template-setup.png) Click on the **Next** button. You will see the Server Collation screen. ![server colation](https://www.atlantic.net/wp-content/uploads/2023/07/server-colation.png) Click on the **Next** button. You will see the Confirm installation screen. ![confirm installation](https://www.atlantic.net/wp-content/uploads/2023/07/confirm-installation.png) Confirm the installation and click on the **Install** button. Once the Cacti is installed, you will see the following screen. ![cacti installation done](https://www.atlantic.net/wp-content/uploads/2023/07/cacti-installation-done.png) Click on the **Get Started** button. You will see the Cacti dashboard page. ![cacti dashboard](https://www.atlantic.net/wp-content/uploads/2023/07/cacti-dashboard.png) ## Conclusion In this guide, we showed you how to install the Cacti monitoring tool on Fedora Linux. You can now add a remote server to Cacti and start monitoring them via a web-based dashboard. You can now start using Cacti for monitoring servers hosted on a [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Bard vs. ChatGPT: What’s the Difference? > URL: https://www.atlantic.net/managed-services/bard-vs-chatgpt-whats-the-difference/ | Published: 2023-08-10 | Updated: 2024-11-09 | Author: Richard Bailey Artificial Intelligence has hit the mainstream recently, with two notable names emerging as the leading AI platforms: Bard and ChatGPT. Both are impressive products in their own right, but each has unique characteristics and applications that set them apart, creating a fascinating comparison. AI is here to stay, and there is a lot of buzz in the media about our future being powered by AI. This article will discuss the critical differences between the big AI players, and we will also consider the ethical implications of an AI-driven future. ## Bard and ChatGPT: Merging Creativity and AI Bard was released on March 21, 2023, and is named after the bards of Celtic cultures, who were professional storytellers trained to remember and recite stories and poems. Bard was initially released as a limited beta in the United States and the United Kingdom. However, On May 10, 2023, Bard was released to the public and is now available in over 180 countries and territories. Built by Alphabet Inc., Google’s parent company, Bard has been turning heads with its ability to generate intriguing narratives and stories. It is estimated that Bard has [30 million](https://contentdetector.ai/articles/google-bard-statistics) monthly users. It has quickly gained recognition for its potential in the creative industries, with writers, filmmakers, and other creatives praising its capabilities. On the other hand, we have ChatGPT, a creation from OpenAI released on November 30, 2022. The Generative Pre-trained Transformer is an extensive language model trained to simulate human-like text. ChatGPT has been instrumental in reshaping conversations about AI’s place in society. From answering queries to writing essays and even generating poetry, ChatGPT’s versatility has made it a household name. ## Bard and ChatGPT: Empowering Expression, Elevating Communication Bard and ChatGPT share many similarities; they are both AI tools trained using extensive source data with a technique called deep learning. Both versions can now use the internet to gain up-to-date information (although this is currently only a paid feature for ChatGPT). While both products were developed using advanced machine-learning techniques, they each carry distinct identities. Bard’s primary function is to weave compelling narratives, making it an ideal tool for creative exploration. ChatGPT is a conversational tool that excels in various tasks, from customer support to education. Both platforms have gained instant recognition from users and industry experts as a highly positive tools for creative thinking. The impact of AI has also been discussed in Congress, further validating its effectiveness and future potential. The impact of Bard and ChatGPT is undeniable. Bard’s influence is inspiring new ways of storytelling and content creation. Meanwhile, ChatGPT’s broad applicability has made it an invaluable asset across numerous industries, redefining the concept of AI assistance. ## Unraveling the Main Differences Between Bard and ChatGPT Bard can access real-time information from the internet, allowing it to stay updated with the latest developments. ChatGPT’s knowledge base is static, with its data sources ending in 2021. The language models employed by these chatbots also differ. According to[TechTarget](https://www.techtarget.com/whatis/feature/Bard-vs-ChatGPT-Whats-the-difference), Bard operates on Google’s latest language model, PaLM 2, which is touted for its superior capabilities in common sense reasoning, logic, and mathematics. In contrast, ChatGPT operates on the GPT-3.5 language model, with the more advanced GPT-4 model available in its premium version, ChatGPT Plus. The choice of language model can significantly influence the chatbot’s ability to understand and generate human-like responses. Bard generates multiple chunks of information, providing a more detailed response to user queries. ChatGPT creates content in a single text prompt, providing a concise and direct response. This approach can be advantageous for straightforward questions. While Bard and ChatGPT share the common goal of simulating human-like conversations and generating AI-powered content, their unique characteristics and capabilities set them apart. Understanding these differences can help users choose the chatbot that best suits their needs and preferences. ## Advantages of Conversational AI If you use AI tools, you will be well aware of the advantages they bring to the table. However, if you are new to AI, let’s delve into the key advantages on offer: - **Precision**: GPT models consistently demonstrate remarkable accuracy in their predictions. This proficiency can be attributed to their extensive training on vast and diverse datasets, encompassing a wide range of text and code. - **Quickness**: One standout feature of GPT models is their exceptional speed. This remarkable swiftness can be attributed to the deep learning methodologies employed during their training, enabling them to deliver prompt and efficient responses. - **Versatility**: These powerful tools can seamlessly tackle a broad spectrum of tasks, encompassing various domains. From generating coherent and creative text to facilitating language translation, AI models exhibit remarkable adaptability. ## Disadvantages of Conversational AI While conversational AI presents immense potential to revolutionize human-computer interaction, it’s crucial to acknowledge and address the challenges associated with these tools. Here are a few significant concerns to consider: - **Bias**: AI models trained on datasets created by humans can inadvertently inherit biases in the training data. It’s essential to be mindful of this inherent limitation and take proactive measures to mitigate bias, ensuring fair and equitable outcomes. - **Privacy**: The utilization of AI models raises valid concerns about data privacy. As these models can accumulate and retain personal information, there exists a potential risk of misuse, such as identity theft or unsolicited spam. Ensuring robust privacy safeguards is imperative to protect user data. - **Safety**: AI models can generate content autonomously, introducing a safety concern. Despite built-in protection, there is a potential for these models to produce harmful or malicious content. ## Navigating the Ethical Landscape of AI The ethical considerations surrounding the use of AI are becoming increasingly important. These considerations span multiple issues, from data privacy and transparency to fairness and accountability. Data privacy is a paramount concern in AI ethics. AI systems rely on vast amounts of data, some of which may be personal or sensitive. Ensuring this data is collected, stored, and used ethically to respect user privacy is crucial. Transparency, another key ethical issue, involves communicating how an AI system works and makes decisions. Users have a right to understand the mechanisms behind the AI tools they interact with, mainly when used in high-stakes contexts, such as healthcare or finance. Fairness in AI refers to the imperative to avoid bias in AI systems. AI models should be trained and tested on diverse datasets to ensure they don’t perpetuate harmful biases. Moreover, AI applications should be designed to promote inclusivity and equal opportunity. Accountability is also essential in AI ethics. When AI systems make mistakes or cause harm, who is responsible should be clear. This involves establishing robust mechanisms for oversight and redress. The ethical use of AI also involves considering its societal implications, such as its impact on jobs and the digital divide. As AI continues to evolve, it’s crucial that its benefits are broadly shared and do not exacerbate existing inequalities. ## Next Steps If you’re interested in discovering how AI can perform in a network and help your business succeed, contact our sales team at sales@atlantic.net to learn more about how [our managed](https://www.atlantic.net/managed-services/) services offerings can work with AI to improve your IT infrastructure! --- # What Is Code Documentation and How It Will Affect Your Next Compliance Audit? > URL: https://www.atlantic.net/hipaa-compliant-hosting/what-is-code-documentation-and-how-it-will-affect-your-next-compliance-audit/ | Published: 2023-08-22 | Updated: 2026-05-04 | Author: Gilad Maayan In software development, transparency and compliance have become integral to the process. One of the key factors facilitating these qualities is code documentation—the practice of writing explanatory comments, notes, and methodology descriptions accompanying computer code. This article explores the concept of code documentation, its importance, and how it can impact the outcome of your next compliance audit. We will explore the different types of compliance audits prevalent in software development projects and the role code documentation plays in each. By understanding and implementing effective code documentation strategies, software developers and organizations can enhance their software quality and ensure they are well-prepared for any compliance requirements that affect their organization. ## What Is Code Documentation? Code Documentation is the written text, notes, or comments that go hand in hand with computer code. It is intended to clarify the “what,” “how,” and “why” of the code for future reference. The aim is to make the code understandable for the other developers and your future self who may work on the same project later. Code Documentation is not merely about commenting on every line or function in your code. It’s about providing high-level context and explaining why certain decisions were made during development. It also serves as a guide for developers to understand the flow of the system or software. Without proper documentation, even the most beautifully written code can become obscure. It can lead to confusion, increased development time, and ultimately, degradation of the code quality. Get more [background on code documentation](https://swimm.io/learn/code-documentation/code-documentation-benefits-challenges-and-tips-for-success/) in this detailed blog post. ## Types of Compliance Audits in Software Development Compliance audits are becoming crucial to software development, especially in regulated industries. They ensure that the software and the development process meet specific standards and regulations. Compliance audits in software development can be broadly classified into two categories: internal and external audits. ### Internal Audits The organization’s own audit team conducts internal audits. The aim is to evaluate the organization’s internal controls’ effectiveness and identify improvement areas. For example, an internal audit might focus on the software development process to ensure that the developers follow the organization’s best practices and standards. Internal audits also assess the quality of the code and the documentation. They check if the code is clean, maintainable, and well-documented. The internal audit team can provide feedback and recommendations to the development team, which can be used to improve the overall quality of the software. ### External Audits Conversely, external audits are conducted by an independent third-party organization. These audits are often more rigorous and formal than internal audits. They aim to ensure that the organization’s software and processes comply with industry standards and regulations. External audits can be beneficial as they provide an unbiased software assessment. They can identify potential issues and vulnerabilities that might have been overlooked during the internal audits. Moreover, passing an external audit can boost the organization’s reputation as it demonstrates its commitment to quality and compliance. ## Common Compliance Standards in Software Development There are several key compliance standards that software projects need to adhere to. These standards provide guidelines and best practices that ensure the software’s quality, security, and privacy. ### ISO 27001: Information Security Management ISO 27001 is an international standard that provides a framework for information security management. It helps organizations manage and protect their information assets. In software development, ISO 27001 requires developers to implement security controls in their software to safeguard the information. ### PCI DSS: Payment Card Industry Data Security Standard If your software deals with payment card information, then [PCI DSS compliance](https://www.atlantic.net/pci-compliant-hosting/what-is-pci-compliance/) is necessary. It mandates that developers follow certain practices to ensure cardholder data security. ### GDPR: General Data Protection Regulation GDPR is a regulation in EU law that protects EU citizens’ privacy and personal data. If your software collects or processes EU citizens’ data, then you must ensure that it complies with GDPR. This means that you need to implement specific measures in your software to protect the personal data and provide transparency to the users about how their data is used. ## Role of Code Documentation in Compliance Audits Compliance audits are rigorous assessments that inspect an organization’s adherence to regulatory guidelines. Code documentation plays a crucial role in these audits, establishing evidence of compliance, facilitating audit procedures, and demonstrating security measures. ### Establishing Evidence of Compliance Code documentation serves as a blueprint of the software development process. It details every function, method, and class within the codebase, thus providing a comprehensive overview of the software’s inner workings. This, in turn, can be used as tangible evidence of complying with specific coding standards and practices. For instance, if your code documentation clearly describes how user data is encrypted, it can establish compliance with data protection regulations. Similarly, if the documentation outlines the software’s accessibility features, it can demonstrate adherence to accessibility laws. Therefore, maintaining thorough, up-to-date code documentation can help establish evidence of compliance during audits. ### Facilitating Audit Procedures During a compliance audit, auditors need to analyze the software’s code to ensure it adheres to regulatory guidelines. A comprehensive code document makes this task significantly more manageable. Instead of trawling through thousands of lines of code, auditors can refer to the documentation to understand the software’s functionality and assess its compliance. Moreover, well-documented code can expedite the audit process, as auditors can quickly identify and focus on areas relevant to the regulations being audited. It simplifies their task, ensuring a more efficient and effective audit process. ### Demonstrating Security Measures Compliance audits often include checks to ensure the software has adequate security measures. A well-maintained code document can effectively demonstrate these measures. By detailing how the code handles user data, manages authentication and authorization, encrypts sensitive information, and responds to potential security threats, the documentation can provide auditors with the evidence they need to verify the software’s security compliance. This not only aids in passing the audit but also reinforces the trust of clients and users in your software. ## How to Prepare Your Code Documentation for Compliance Audits Preparing your code documentation for compliance audits doesn’t have to be daunting. By following a few key steps, you can ensure your documentation is audit-ready. ### Regular Review and Update of Documentation In the fast-paced world of software development, code changes are inevitable. As the code evolves, so should its documentation. Regularly reviewing and updating your code documentation ensures that it accurately reflects the current state of the software. This is particularly crucial during compliance audits, as outdated or inaccurate documentation can lead to misunderstandings, non-compliance findings, and even audit failures. By establishing a routine for documentation updates, you can ensure your code documentation remains a reliable, up-to-date resource for auditors. ### Integration of Documentation Process in the SDLC The Software Development Life Cycle (SDLC) is a systematic process for developing software that ensures its quality and correctness. Integrating the documentation process into the SDLC can help ensure the documentation is as thorough and accurate as possible. Developers can provide real-time, detailed descriptions of the software’s functionality by documenting the code as it’s written. This results in more accurate documentation and saves time and effort in the long run, as there’s no need to document the code retroactively. ### Document Security Measures As mentioned earlier, code documentation can effectively demonstrate the software’s security measures. Detailed documentation of your software’s security protocols, data handling practices, and response mechanisms to potential threats can give auditors a clear picture of your software’s security compliance. In addition, documenting any security-related code changes or updates can prove your commitment to maintaining robust security measures, further boosting your chances of a successful audit. ### Use Documentation Tools In today’s technologically advanced world; several tools can aid documentation. These tools can automate parts of the process, ensure consistency, and even check for errors or omissions. By leveraging these tools, you can streamline the documentation process, making it easier to maintain up-to-date, comprehensive code documentation. ## Conclusion In conclusion, code documentation is not just a nicety but a necessity in software development. It plays a crucial role in compliance audits, helping establish evidence of compliance, facilitating audit procedures, and demonstrating security measures. By regularly reviewing and updating your documentation, integrating the documentation process into the SDLC, documenting your security measures, and using documentation tools, you can ensure your code documentation is always audit-ready. Audit readiness is particularly important for [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) – learn more about our [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/). --- # Vendor Management for HIPAA Business Associates > URL: https://www.atlantic.net/hipaa-compliant-hosting/vendor-management-for-hipaa-business-associates/ | Published: 2023-08-23 | Updated: 2025-09-15 | Author: Gilad Maayan ## What Are HIPAA Business Associates? HIPAA business associates are entities or individuals that perform functions or activities involving the use or disclosure of protected health information (PHI) on behalf of a HIPAA covered entity. This could include data analysis, processing or administration of claims, patient safety activities, and more. It is important to note that a business associate is not an employee of the covered entity but an independent contractor. HIPAA business associates play an important role in the healthcare industry. They provide essential services to healthcare organizations and providers and are responsible for ensuring that the PHI is protected according to HIPAA regulations. It’s a daunting task, but vital to maintain trust and security of patients and healthcare providers alike. ## Understanding HIPAA Requirements for Business Associates ### Business Associate Agreement (BAA) Requirements A business associate agreement (BAA) is a legally binding document between a HIPAA covered entity and a business associate. It outlines the responsibilities of the business associate in regard to the handling and protection of PHI. In essence, it serves as a contract, stipulating the terms and conditions under which the business associate can access and use PHI. The BAA is vital to maintaining compliance with HIPAA regulations. It outlines the rights and responsibilities of the business associate and provides a means for the covered entity to ensure that the business associate is upholding its end of the bargain. In other words, it’s a way for covered entities to hold their business associates accountable for their actions. The BAA should typically include provisions for how the business associate will use and disclose PHI, what safeguards they will implement to protect the data, as well as what they will do in the event of a data breach. It should also stipulate the terms for termination of the agreement. Getting this document right is crucial, as it forms the basis of your compliance with HIPAA regulations. ### Importance of Compliance with HIPAA Regulations Compliance with HIPAA regulations is not just a legal requirement but a fundamental aspect of doing business in the healthcare industry. The privacy and security of patient data is a top priority, and failure to uphold these standards can have severe consequences. This includes hefty fines, potential lawsuits, and damage to your business’s reputation. The [Office for Civil Rights (OCR)](https://www.hhs.gov/ocr/index.html), which enforces HIPAA, has been known to issue fines reaching into the millions of dollars for violations. These can occur due to breaches but also from non-compliance with the administrative, physical, and technical safeguards outlined in the HIPAA Security Rule. Therefore, it’s critical to ensure that your business is fully compliant with all aspects of HIPAA. Moreover, compliance is not a one-time event but an ongoing process. This means regularly reviewing and updating your policies and procedures, training your employees, and conducting periodic audits to ensure your safeguards are effective. Remember, protecting the privacy and security of patient data is not just about avoiding penalties but about maintaining the trust of your clients and the individuals whose data you handle. ## Vendor Selection Process for HIPAA Business Associates ### Identifying Vendor Requirements The first step in the vendor selection process is to identify your specific needs and requirements. This could include the types of services you require, the volume of data you need to handle, and any specific security or compliance requirements you have. This will help you narrow your options and focus on vendors that meet your specific needs. Consider the vendor’s reputation and track record concerning data security. Have they had any data breaches in the past? What do their current and former clients say about them? This information can provide valuable insights into the risks of using them as a HIPAA Business Associate. ### Conducting Due Diligence Once you have identified your requirements, the next step is to conduct due diligence on potential vendors. This involves researching each vendor thoroughly, checking their references, and interviewing them to understand their capabilities and reliability. You should also review their compliance documentation, such as HIPAA risk assessment, policies and procedures, and training materials. This can help you understand how they approach compliance and whether they have the necessary safeguards to protect your data. Moreover, consider conducting an on-site visit if possible. This will allow you to see firsthand how the vendor operates and to verify that they are following their stated policies and procedures. ### Vendor Selection Criteria Once you have conducted your due diligence, the final step is to select a vendor. This decision should be based on various factors, including their ability to meet your specific requirements, their commitment to compliance, and their track record of reliability and security. One of the most important criteria is the vendor’s understanding of and commitment to [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). Do they have a robust compliance program in place? Do they provide regular training to their employees? Do they conduct periodic audits to ensure compliance? Another critical factor is the vendor’s technical capabilities. Can they handle the volume of data you need to process? Do they have robust security measures in place to protect your data? Do they offer the specific services you require? ## Establishing Vendor Management Policies and Procedures ### Vendor Management Framework For large organizations working with numerous HIPAA Business Associates, it can be beneficial to implement a vendor management framework. This structure forms the backbone of the strategic planning, execution, and management of all vendor relationships. A well-defined vendor management framework enhances operational efficiency and ensures regulatory compliance. A [vendor management system](https://enterprise.fiverr.com/blog/vendor-management-systems/) is a technology solution often used to implement and manage vendor management frameworks. The framework should include a clear outline of the roles and responsibilities of all parties involved. It should also define vendor selection, management, and evaluation processes. It’s critical to ensure the framework is flexible enough to accommodate changes in the business environment or regulatory landscape. Moreover, the framework should provide measures for managing and mitigating risks associated with vendor relationships. ### Documentation and Record-Keeping Requirements The HIPAA Privacy Rule mandates creating and maintaining written privacy policies and procedures, along with employee training records. These documents serve as evidence of the organization’s efforts to comply with the law. In this respect, it is vital to maintain records of all vendor contracts, agreements, and correspondences. These documents should detail the scope of services provided, the responsibilities of each party, and the terms of the business relationship. Additionally, records of all risk assessments, incident response activities, and audit findings should be meticulously maintained. ### Risk Assessment and Mitigation Strategies Risk assessment is a critical process that identifies potential threats to the confidentiality, integrity, and availability of protected health information (PHI). It’s a systematic process that involves identifying potential threats, assessing their impact, and developing mitigation strategies. As part of HIPAA risk assessments, organizations should consider their third-party vendors, including but not limited to HIPAA Business Associates. Even after carefully vetting Business Associates, it is essential to consider the chance that a data breach or security failure at one of these vendors will negatively impact the organization. ### Incident Response and Breach Notification Procedures Despite the best efforts and safeguards, incidents can occur. Therefore, it’s crucial to have well-defined incident response and breach notification procedures in place. The incident response process must consider incidents that involve, or originate from, HIPAA Business Associates. The incident response process should include steps for identifying, containing, and eliminating the threat. It should also detail the procedures for assessing the impact of the breach and notifying the affected parties. The HIPAA Breach Notification Rule requires covered entities to notify individuals affected by a breach of their unsecured PHI, the Secretary of Health and Human Services (HHS), and, in some cases, the media. ### Vendor Performance Monitoring and Auditing Finally, it is vital to monitor and audit the performance of vendors regularly. This process involves evaluating the vendor’s compliance with the agreed-upon terms and conditions, their performance against set benchmarks, and their adherence to the regulatory requirements. Vendor audits can either be conducted internally or by third-party auditors. Regardless of who performs the audit, the process should be thorough, unbiased, and transparent. The findings of the audit should be documented, and necessary corrective measures should be implemented promptly. ## Conclusion Implementing a comprehensive vendor management program in the healthcare industry can be complex and challenging. However, with a well-defined framework, meticulous record-keeping, effective risk assessment, and mitigation strategies, robust incident response and breach notification procedures, and regular vendor performance monitoring and auditing, you can ensure your organization is compliant and mitigate vendor-related compliance risks. --- # Top 10 Cloud VoIP Providers > URL: https://www.atlantic.net/voip-cloud-servers/cloud-voip-providers/ | Published: 2023-09-03 | Updated: 2025-06-04 | Author: Richard Bailey Voice Over Internet Protocol, or [VoIP](https://www.atlantic.net/voip-cloud-servers/cloud-voip/), is a technology that lets you make phone calls over an internet connection instead of relying on a traditional phone system or landlines. VoIP is compatible with numerous devices, such as computers, laptops, smartphones, desk phones, and dedicated VoIP Phones. VoIP introduces substantial cost savings for businesses and offers many new features, such as voice conferencing, video conferencing, voicemail, auto-attendants, transcription, and more. In this top 10, we will introduce you to our favorite VoIP providers in the United States and explain why we like them. Then, it’s up to you to see which fits your needs. Remember to consider your budget carefully and understand the features you need from a VoIP provider. ## #10: RingCentral ### Why RingCentral Stands Out RingCentral is a unified communications provider that offers features beyond making VoIP calls. For about $20 per user per month, you get unlimited calling, SMS, MMS, Interact Voice Response (IVR), voice mail, and more. Premium subscriptions give you access to a whiteboard, phone system insights, call recording, call center features, unlimited calls, video conferencing, unlimited cloud storage for voice and video calls, transcripts, etc. ### Who Can Benefit from RingCentral RingCentral is a global business VoIP service provider with plans suitable for businesses of all sizes and home users. Its cloud-based phone service is also ideal for a remote workforce. To install the RingCentral App, you only need a laptop or smartphone (plus a reliable internet connection). ### Pros - Integrates voice calls, video conferencing, chat, faxing, voicemail - Plans for businesses of all sizes, easy to add/remove users - User-friendly interface and mobile app - Uptime guarantees, robust security features - International calling, local phone numbers in various countries ### Cons - May require additional costs for advanced features - The free plan has limited features - Advanced features have a learning curve - Premium subscription is expensive - Focuses on business users, less suitable for individuals/small teams ## #9: Vonage ### Why Vonage Stands Out Vonage is a budget-friendly VoIP phone service provider that offers a range of services, from basic call-only options to feature-packed premium options. Vonage also has some excellent international calling plans, which are perfect for calling overseas. Vonage users enjoy a user-friendly interface with unlimited calling plans, auto attendant, call recording, and a fully featured Vonage mobile app. ### Who Can Benefit from Vonage Vonage is ideal for businesses on a budget, startups, and those looking to streamline business communications costs. If you have a traveling workforce, Vonage features fantastic mobile integration. It allows users to make and receive calls, manage voicemail, and access other features from anywhere with an internet connection. This can be a significant benefit for companies with employees who work remotely or travel frequently. ### Pros - Easy to use and manage - Reliable call quality - Feature-rich, including unlimited calling and texting - User-friendly mobile app - Scalable for businesses of all sizes - Uptime guarantee ### Cons - Can be expensive compared to some competitors - Limited flexibility in plan options (e.g., contracts, month-to-month) - Customer service may not be readily available (chat only) - App functionality issues reported by some users ## #8: Mitel MiCloud ### Why Mitel MiCloud Stands Out Mitel MiCloud is known for its scalability and ability to be customized to fit the needs of businesses of all sizes. It comes with loads of features, including video conferencing, call recording, voicemail transcription, and integrations with various CRM and business productivity tools. Mitel MiCloud prioritizes security and reliability, making it a good choice for businesses that handle sensitive information. ### Who Can Benefit from Mite MiCloud Mitel targets medium—and large-sized businesses that need a feature-rich business communications platform. It works great with call centers because it features detailed call routing and workflow configuration. Data can also be kept on-premise if you have enhanced compliance needs. ### Pros - Ease of use - Call quality - Customer support - Scalability - Features ### Cons - Cost - Limited integrations (depending on specific needs) - Complexity (for some features) ## #7: DialPad ### Why DialPad Stands Out Dialpad has several innovative features that focus on artificial intelligence (AI), like real-time transcription, call analytics with sentiment detection (agent evaluation), and AI-powered voicemail summaries. It is user-friendly and easy to use, plus DialPad can integrate with Salesforce, Zendesk, Asana, Trello, and much more. ### Who Can Benefit from DialPad Businesses interested in using AI to improve communication efficiency and gain insights from your incoming calls will like DialPad. It is also highly versatile for service-driving teams; features like call recording, transcription, and analytics can be beneficial to customer relationship management. ### Pros - Cloud-based and mobile friendly - User-friendly interface - Call quality and reliability - Integrations (with many popular business tools) - Advanced features (like call recording and transcription) ### Cons - Cost may be expensive for small businesses - Limited free trial options no longer offers a free tier - Learning curve for some advanced features - Customer support has had some questionable reviews ## #6: Zoom Phone ### Why Zoom Phone Stands Out Zoom Phone positions itself as a cloud phone system, an extension of the familiar Zoom meeting experience. It offers a cloud-based phone system that integrates seamlessly with Zoom. They target businesses of all sizes and offer great scalability, allowing you to scale your business phone system as your needs grow. It boasts an extensive global network, with enabled features like international calling and local business phone numbers. ### Who Can Benefit from Zoom Phone Zoom gained a lot of popularity during the COVID-19 pandemic, and as a result, many people are already familiar with the user interface of Zoom products. Zoom Phone’s cloud-based features and mobile phone app make it ideal for businesses with remote or mobile workforces, allowing them to stay connected and make calls from anywhere. ### Pros - Affordability with competitive pricing, especially for basic plans - Integration with Zoom meetings - User-friendly interface - Strong audio and video quality - Suitable for small and growing businesses ### Cons - Limited collaboration features, such as no document sharing or task management - Fewer customer support options compared to some competitors ## #5: OnSip ### Why OnSip Stands Out OnSip caters to a niche within the VoIP market that prioritizes simplicity, affordability, and ease of use. But you also get a massive list of features, including voicemail to email, auto attendants, call recording, blocking, music on hold, call monitoring and management, and call center queue features. OnSIP offers flexible pay-as-you-go options and unlimited calling plans, allowing you to avoid long-term commitments and adjust your service based on usage. ### Who Can Benefit from OnSip With its focus on simplicity, affordability, and scalability, OnSIP can be a good fit for small businesses and startups. Compared to some of the more prominent players, it may lack some of the more advanced features; however, it’s very affordable. If you have a technical team, you can keep the cost even lower by self-hosting an open-source version of the VoIP phone system. ### Pros - Customization - Reliability - Customer support - Pay-as-you-go business phone system - Ease of Use ### Cons - Technical knowledge needed - Mobile app - Pricing complexity - Limited Integrations ## #4: Cisco UCM ### Why Cisco UCM Stands Out Cisco UCM (Unified Communications Manager) is an enterprise VoIP platform that focuses on enhanced features, security, and reliability, including voicemail, auto attendant, call recording, video and audio conferencing, and various business tools. The UCM suite caters to the complex communication needs of large organizations. It’s a dependable business communications system featuring strong security protocols and enhanced encryption standards. It accommodates a large number of users and can be customized to fit specific workflows and communication requirements. ### Who Can Benefit from Cisco UCM With its extensive features, scalability, and robust security, Cisco UCM is well-suited for large organizations with intricate communication needs, a focus on information security, and strict data privacy regulations. If you can afford the expensive licensing costs and have the technical skills to implement and manage the solution, you will get one of the very best VoIP phone services available that can [scale](https://community.cisco.com/t5/unified-communications-infrastructure/im-and-presence-maximum-number-of-users/td-p/4843066) to over 75,000 users. ### Pros - Scalability - Feature-rich - Integration with Cisco ecosystem - Voice quality - Reliability ### Cons - Cost - Complexity - On-premises deployment - Remote work limitations - Licensing complexity ## #3:Grasshopper ### Why Grasshopper Stands Out Grasshopper is known for its intuitive interface and straightforward setup process. This makes it ideal for small businesses or those that don’t require a complex communication system with many features. Grasshopper offers a good mobile app that allows users to make and receive calls, manage voicemail, and access extra smartphone features. Grasshopper generally falls on the budget-friendly end of the business VoIP services spectrum, making it an attractive option for cost-conscious businesses. They offer various plans with features tailored to small business needs. ### Who Can Benefit from Grasshopper Grasshopper’s easy setup, user-friendly interface, and focus on core functionalities make it ideal for smaller companies that are new to VoIP services and don’t require a complex system with extensive features. ### Pros - Ease of use - Affordability - Mobile friendly - Multiple phone number options - Professional features like greetings and call forwarding ### Cons - Limited features compared to some competitors - No video conferencing - Scalability limitations may not be ideal for large teams - Customer support has mixed reviews ## #2: Nextiva ### Why Nextiva Stands Out Number 2 is Nextiva, a well-rounded option that stands out in the VoIP market with a potent combination of features, user-friendliness, and customer service. It features unlimited calling, cloud-native connectivity, team messaging, free faxing service, voicemail, call routing, call analytics (reporting), and robust security built in. It’s a unified communications platform that integrates various features, such as cloud phone service, video conferencing, team messaging, and customer relationship management (CRM) tools. Nextiva is known for its user-friendly interface and straightforward setup process. They prioritize customer satisfaction and boast “Amazing Service” as a core part of their brand identity. They offer 24/7 customer support to assist you with any questions or issues. ### Who Can Benefit from Nextiva Nextiva’s scalability and range of features make it suitable for small businesses, startups, and even mid-sized organizations. If you want a platform that integrates various communication channels and features, Nextiva can streamline your workflows and centralize communication data. While pricing might be slightly higher than some competitors, particularly for the most feature-rich plans, you still get a comprehensive suite of VoIP services, tools, and utilities. ### Pros - Cost-effective, potentially lower per-user cost for larger teams - Unlimited domestic calling - Feature rich - User-friendly interface - Excellent customer service ### Cons - Pricing tiers - Limited reporting features in basic plans - Potential scalability issues have been reported by some users ## #1: 8×8 ### Why 8×8 Stands Out Our number one pick is cloud-based VoIP service 8×8. They offer a comprehensive solution for VoIP business phone systems with a global reach. Featuring an uptime SLA of 99.999%, 8×8 is a reliable VoIP platform with extensive contact center features like Intelligent Customer Assistant, call recording, call routing, and agent/supervisor workspaces. You get a business phone, video conferencing, team chat, integration with teams, and a virtual front desk. 8×8 also boasts excellent security and compliance features built to OWASP security standards. Its global network enables features like international calling, local phone numbers in various countries, and potentially improved call quality for geographically dispersed teams. ### Who Can Benefit from 8×8 8×8 provides a solid and reliable platform that integrates various communication channels and functionalities that improve centralized communication and collaboration. Each scalable plan is suitable for small businesses, startups, and even large enterprises. The platform is cloud-native and boasts real global reach; this is a major benefit for teams with remote workforces or those with business locations in different global regions. For all of these leading features, it’s no surprise that 8×8 is not cheap, however, they offer best-in-class features and service which makes them great value for money. ### Pros - A complete unified business communications package - Scalability with flexible plans - Reliability, known for great uptime and clear call quality - Strong security features - Offers competitive pricing with various plans. ### Cons - The interface may require some familiarization with advanced features. - May not integrate with all desired business tools. - Some reviews mention inconsistency in customer support experiences. That’s our Top 10 best voice over internet protocol phone service and system providers for 2024. If you are still unsure which to choose you may be interested to know that you can also go down the self-hosting route. You can even combine some of the services above with our hosting options. It requires a bit more technical know-how, but Atlantic.Net has support available 24/7, and archives of detailed procedures that will show you how to create your very own VoIP service hosted on Atlantic.Net servers. ##### **Want to find out more?** ## **Atlantic.Net’s Open-Source VoIP Solutions** It’s easy to set up a VoIP Phone System on Atlantic.Net servers. Ditch traditional phone systems and upgrade your business phone system to the latest VoIP service. ### Infrastructure Setup: Start by setting up a virtual server on [Atlantic.Net’s cloud platform](https://cloud.atlantic.net/?page=userlogin). Our user-friendly interface and extensive documentation simplify the process. Choose a server configuration that suits your business size and expected call volume. ### Installation of VoIP Software: Once your server is up, install your preferred open-source VoIP software, such as Asterisk or FreeSWITCH. Atlantic.Net supports various operating systems, ensuring compatibility with most other modern VoIP systems and solutions. While Linux is commonly chosen, you can find telephony software for almost every OS. Check out our blog for our favorite cloud-based phone system. ### Configuration: After installation, customize the VoIP phone system software to meet your business requirements. This involves setting up multiple phone numbers, extensions, voicemail, call routing, and other necessary features. Refer to the software documentation for guidance, and grab a coffee as you dive into the setup process. ### Security Measures: Atlantic.Net’s virtual private servers boast top-notch security features. Utilize the built-in firewall services to safeguard your VoIP setup. Schedule regular backups to maintain data integrity and availability. ### Integration and Testing: Once configured, integrate the VoIP phone system with your other business tools. Conduct thorough testing to ensure excellent call quality, stable connections, and seamless functionality of integrated features. ### Maintenance: Use Atlantic.Net’s monitoring tools to monitor server health, usage statistics, and potential threats. Also, update your VoIP software regularly and monitor the system for optimal performance. ## Build Your VoIP Phone System with Atlantic.Net Traditional phones (analog phones) fall short of today’s standards. With the surge in remote work, businesses still need reliable cloud phone systems for seamless call handling and integration with desktop and mobile devices; having a robust VoIP phone system is indispensable. Why settle for less when Atlantic.Net offers top-tier VoIP hosting services? Ensure your business phone system is efficient and HIPAA-compliant with our solutions. Benefit from unlimited calling, crystal-clear call recording, and the flexibility to receive calls on your computer or mobile device, and desktop apps. Ditch your traditional phone systems and embrace the future with access to the best VoIP service providers. Whether you choose to integrate with Microsoft Teams, leverage session initiation protocol, or seek the very best business cloud VoIP services and hosting, Atlantic.Net has you covered. Our VoIP technology extends beyond calls, offering advanced features like virtual fax, internet protocol-based communications, and seamless integration with your existing broadband internet connection. ##### **Discover the Best [CLOUD VOIP Services](https://www.atlantic.net/voip-cloud-servers/) with****Atlantic.Net****Now!** --- # How to Check Linux CPU Usage or Utilization > URL: https://www.atlantic.net/vps-hosting/how-to-check-linux-cpu-usage-or-utilization/ | Published: 2023-09-07 | Updated: 2024-06-01 | Author: Hitesh Jethva Monitoring the performance of the CPU is an essential task for any system administrator who needs to measure the performance of a system. This will help you to debug system processes, manage system resources, and make system decisions. There are several tools available for checking CPU usage in Linux. In this post, we will demonstrate a few methods to check and monitor CPU usage in Linux. **NOTE: This article assumes that your base system is updated with the latest available packages.** ## 1. Check CPU Usage with top Command Top is a very useful command-line tool that helps you to monitor all running processes in real-time. It will display information about the readout of users, tasks, CPU load, and memory usage in real-time. By default, the top command updates the data every 5 seconds. Now, let’s start using the top command to monitor the CPU usage: ``` top ``` You should see the all running processes on the following screen: ![Top command](https://www.atlantic.net/wp-content/uploads/2021/08/p1-10.png) Type **P** to sort all running processes by **CPU** **usage**. You should see the following screen: ![Sort process by CPU usage](https://www.atlantic.net/wp-content/uploads/2021/08/p2-9.png) Type **M** to sort all running processes by **Memory** **usage**. You should see the following screen: ![Sort process by Memory usage](https://www.atlantic.net/wp-content/uploads/2021/08/p3-4.png) Type **I** to hide all **idle** processes. You should see the following screen: ![Hide process](https://www.atlantic.net/wp-content/uploads/2021/08/p4-4.png) Type **S** to sort all processes by how long the processes have been running: ![Sort process by running time](https://www.atlantic.net/wp-content/uploads/2021/08/p5-3.png) Type **U** to view all processes owned by a specific user. You should see the following screen: ![Sort process by owned user](https://www.atlantic.net/wp-content/uploads/2021/08/p6-2.png) ## 2. Check CPU Usage with mpstat Command Mpstat is a part of the sysstat package. For Debian or Ubuntu operating systems, you can install it using the following command: ``` apt-get install sysstat -y ``` For CentOS or RHEL operating systems, you can install it using the following command: ``` yum install sysstat -y ``` Now, run the mpstat command without any options. This will display usage for each processor: ``` mpstat ``` Sample output: ``` Linux 4.4.0-148-generic (newpc) Monday 23 August 2021 _x86_64_ (4 CPU) 12:28:46 IST CPU %usr %nice %sys %iowait %irq %soft %steal %guest %gnice %idle 12:28:46 IST all 18.30 0.01 3.44 8.26 0.00 0.16 0.00 0.00 0.00 69.82 ``` To display a report for the first processor, run: ``` mpstat -P 0 ``` Sample output: ``` Linux 4.4.0-148-generic (newpc) Monday 23 August 2021 _x86_64_ (4 CPU) 12:29:35 IST CPU %usr %nice %sys %iowait %irq %soft %steal %guest %gnice %idle 12:29:35 IST 0 18.16 0.01 3.94 8.68 0.00 0.27 0.00 0.00 0.00 68.93 ``` To display the report of all processors, run: ``` mpstat -P ALL ``` Sample output: ``` Linux 4.4.0-148-generic (newpc) Monday 23 August 2021 _x86_64_ (4 CPU) 12:45:50 IST CPU %usr %nice %sys %iowait %irq %soft %steal %guest %gnice %idle 12:45:50 IST all 16.38 0.01 3.11 7.33 0.00 0.15 0.00 0.00 0.00 73.02 12:45:50 IST 0 16.28 0.01 3.58 7.76 0.00 0.25 0.00 0.00 0.00 72.12 12:45:50 IST 1 16.25 0.01 3.06 7.10 0.00 0.05 0.00 0.00 0.00 73.52 12:45:50 IST 2 16.38 0.01 2.87 7.39 0.00 0.24 0.00 0.00 0.00 73.11 12:45:50 IST 3 16.60 0.01 2.93 7.07 0.00 0.06 0.00 0.00 0.00 73.34 ``` To display average CPU usage for 3 times at 2-second intervals: ``` mpstat -P ALL 2 3 ``` Sample output: ``` Linux 4.4.0-148-generic (newpc) Monday 23 August 2021 _x86_64_ (4 CPU) 12:47:58 IST CPU %usr %nice %sys %iowait %irq %soft %steal %guest %gnice %idle 12:48:00 IST all 23.30 0.00 4.99 4.74 0.00 0.00 0.00 0.00 0.00 66.97 12:48:00 IST 0 29.02 0.00 5.18 6.74 0.00 0.00 0.00 0.00 0.00 59.07 12:48:00 IST 1 26.53 0.00 6.12 4.59 0.00 0.51 0.00 0.00 0.00 62.24 12:48:00 IST 2 22.96 0.00 3.57 2.04 0.00 0.00 0.00 0.00 0.00 71.43 12:48:00 IST 3 14.14 0.00 5.05 5.56 0.00 0.00 0.00 0.00 0.00 75.25 12:48:00 IST CPU %usr %nice %sys %iowait %irq %soft %steal %guest %gnice %idle 12:48:02 IST all 21.58 0.00 5.87 5.11 0.00 0.13 0.00 0.00 0.00 67.31 12:48:02 IST 0 25.13 0.00 9.23 9.23 0.00 0.51 0.00 0.00 0.00 55.90 12:48:02 IST 1 28.72 0.00 7.18 8.21 0.00 0.00 0.00 0.00 0.00 55.90 12:48:02 IST 2 18.88 0.00 3.06 1.53 0.00 0.00 0.00 0.00 0.00 76.53 12:48:02 IST 3 13.85 0.00 4.10 1.03 0.00 0.00 0.00 0.00 0.00 81.03 12:48:02 IST CPU %usr %nice %sys %iowait %irq %soft %steal %guest %gnice %idle 12:48:04 IST all 24.78 0.00 5.11 5.87 0.00 0.13 0.00 0.00 0.00 64.11 12:48:04 IST 0 30.37 0.00 3.66 10.47 0.00 0.00 0.00 0.00 0.00 55.50 12:48:04 IST 1 27.78 0.00 6.06 9.09 0.00 0.00 0.00 0.00 0.00 57.07 12:48:04 IST 2 23.23 0.00 5.56 1.01 0.00 0.00 0.00 0.00 0.00 70.20 12:48:04 IST 3 17.86 0.00 5.10 3.57 0.00 0.51 0.00 0.00 0.00 72.96 Average: CPU %usr %nice %sys %iowait %irq %soft %steal %guest %gnice %idle Average: all 23.22 0.00 5.33 5.24 0.00 0.09 0.00 0.00 0.00 66.13 Average: 0 28.15 0.00 6.04 8.81 0.00 0.17 0.00 0.00 0.00 56.82 Average: 1 27.67 0.00 6.45 7.30 0.00 0.17 0.00 0.00 0.00 58.40 Average: 2 21.69 0.00 4.07 1.53 0.00 0.00 0.00 0.00 0.00 72.71 Average: 3 15.28 0.00 4.75 3.40 0.00 0.17 0.00 0.00 0.00 76.40 ``` ## 3. Check CPU Usage with sar Command The sar command is also used for collecting and reporting system activity information. You can use the sar command with the -u option to track CPU performance. The following command will display CPU usage every 2 seconds. ``` sar -u 2 ``` Sample output: ``` Linux 4.4.0-148-generic (newpc) Monday 23 August 2021 _x86_64_ (4 CPU) 12:53:26 IST CPU %user %nice %system %iowait %steal %idle 12:53:28 IST all 5.30 0.00 2.02 2.52 0.00 90.16 12:53:30 IST all 2.90 0.00 1.39 1.13 0.00 94.58 12:53:32 IST all 3.57 0.00 2.04 0.76 0.00 93.63 ``` The above command will run indefinitely. You can stop it using CTRL+C. ## 4. Check CPU Usage with iostat Command The iostat displays information on device utilization and the system’s average CPU utilization since the last reboot. Run the iostat command without any option will display the information about CPU utilization, device utilization, and network file system utilization. ``` iostat ``` You should see the following output: ``` Linux 4.4.0-148-generic (newpc) Monday 23 August 2021 _x86_64_ (4 CPU) avg-cpu: %user %nice %system %iowait %steal %idle 16.41 0.01 3.31 6.83 0.00 73.44 Device: tps kB_read/s kB_wrtn/s kB_read kB_wrtn loop0 0.01 0.04 0.00 373 0 loop1 0.01 0.04 0.00 387 0 loop2 2.59 2.62 0.00 23279 0 loop3 0.00 0.01 0.00 116 0 loop4 0.01 0.02 0.00 143 0 loop5 28.67 28.70 0.00 255344 0 loop6 0.01 0.04 0.00 385 0 loop7 0.00 0.01 0.00 121 0 sda 34.36 383.67 600.72 3413776 5345096 ``` Use the -c option to break the CPU utilization into user processes, system processes, I/O wait, and idle time. ``` iostat -c ``` Sample output: ``` Linux 4.4.0-148-generic (newpc) Monday 23 August 2021 _x86_64_ (4 CPU) avg-cpu: %user %nice %system %iowait %steal %idle 16.40 0.01 3.31 6.82 0.00 73.46 ``` ## 5. Check CPU Usage with vmstat Command The vmstat command will display the information about system processes, memory, swap, I/O, and CPU performance. It will display the average details since the last reboot. Run the vmstat command without any options as shown below: ``` vmstat ``` Sample output: ``` procs -----------memory---------- ---swap-- -----io---- -system-- ------cpu----- r b swpd free buff cache si so bi bo in cs us sy id wa st 3 1 1028672 130972 124344 1212276 19 71 101 150 341 818 17 3 73 7 0 ``` The following command will update vmstat report every 2 seconds: ``` vmstat 2 ``` Sample output: ``` procs -----------memory---------- ---swap-- -----io---- -system-- ------cpu----- r b swpd free buff cache si so bi bo in cs us sy id wa st 2 1 1032572 233396 125196 1129256 19 70 100 149 345 830 17 3 73 7 0 2 0 1032572 232976 125212 1129596 0 0 0 112 3051 8697 40 10 42 8 0 0 1 1032572 233040 125224 1130468 0 0 0 1510 3109 8631 43 9 41 8 0 ``` Press CTRL+C to close the vmstat. ## Conclusion In the above guide, we explained different methods to check CPU usage in Linux. These tools can help you to track processor usage and the performance of your system. Give it a try today on your [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # What Are the HIPAA Business Continuity and Disaster Recovery Requirements? > URL: https://www.atlantic.net/disaster-recovery/what-are-the-hipaa-disaster-recovery-and-business-continuity-requirements/ | Published: 2023-09-09 | Updated: 2025-02-07 | Author: Richard Bailey To comply with HIPAA, healthcare companies and their business associates must formulate a robust contingency plan in case of an event that disrupts operations. These plans have smaller component plans such as a [Disaster Recovery Plan](https://www.atlantic.net/disaster-recovery/) (DRP) and an Emergency Mode Operation Plan, or Contingency Plan. This business continuity strategy requires healthcare organizations to be capable of recovering critical IT systems that handle Electronic Patient Health Information (ePHI) into a disaster recovery location while ensuring critical business functions continue in the event of a crisis. The aim of the emergency mode operation plan and disaster recovery plan is to establish the role, responsibilities, and procedures needed in a real-world disaster recovery scenario. Disaster recovery planning will typically define 5 key specifications. ## The Data Backup Plan Essentially, all ePHI must be identified and backed up using a [HIPAA compliant backup solution](https://www.atlantic.net/managed-services/veeam-services/). The data backup schedule should be pre-defined according to the organization’s specific needs, but might typically be a daily, monthly and annual backup policy. A number of HIPAA security safeguards should be enforced in storing ePHI backup data, such as encryption at rest and encryption for transferred data. The data backup plan must also include controls over how backup data is accessed and by whom, especially when considering restoration of data. ## The HIPAA Disaster Recovery Plan (DRP) The HIPAA disaster recovery plan is a detailed set of processes and procedures that defines how a healthcare organization and the business associate responsible for IT services will respond to a disaster scenario. A HIPAA disaster recovery plan will typically aim to answer: - **What Is a Disaster Recovery Scenario?** – A typical disaster scenario will be when access to electronic protected health information (ePHI) data and systems is severely interrupted for some reason, such as a technical outage, human error, terrorism, or a natural disaster. A good example to consider: what would happen if your production data center were destroyed? How would the healthcare provider continue to operate, and how would the managed service provider (MSP) recover from such a disaster? Under HIPAA requirements, the MSP must empower the healthcare organization with the ability to failover production services to a secondary disparate location, restore critical IT systems and services, and restore the electronic protected health information to a specific point in time prior to the disaster. - **When to Declare a Disaster Scenario** – The healthcare organization and the IT service provider will have a business agreement that will stipulate when to declare a disaster. This could be from a certain timeframe since a system outage began, or the HIPAA disaster recovery plan might be invoked by approved personnel, usually a senior manager or executive. In most managed service companies, invoking DR is a manual process that must follow a strict authorization procedure. - **How to Invoke Disaster Recovery** – Healthcare personnel must be aware of how to invoke the HIPAA disaster recovery plan. For example, phoning the IT Provider and providing a pre-agreed security key to approve HIPAA disaster recovery plan activation. The MSP must also have a strategy of how to escalate to on-call technical experts or stakeholders. This is usually done through a DR Lead who is responsible for communications channels. This process may also involve moving technical personnel to a remote command center if the hosting site has been compromised. - **Who to Contact and How Communication Flows During a DR Scenario –**Modern MSPs have automated monitoring systems that automatically notify DR personnel; however, the names and contact numbers of key persons must be published within the HIPAA disaster recovery plan. Each personnel must know who they report too, and how communication flows in a disaster recovery scenario. This is usually done via a call tree. - **Description of Key Roles and Responsibilities of Anyone Assigned to the Recovery Team** – All DR personnel must understand their role and where they fall within the chain of command in a DR scenario, including network engineers, server engineers, and database engineers. - **Define Recovery Time Objectives** – The HIPAA disaster recovery plan will state the contracted RTO objectives. This refers to how long the healthcare organization can operate without critical IT systems and the time allowed for the MSP to be able to set up new IT infrastructure in a secondary location. This may be set to 24 hours, meaning the MSP has 24 hours to get the servers and infrastructure running in DR. With today’s modern cloud failover technologies, the RTO can be as low as near zero. - **Define Recovery Point Objectives** – The HIPAA disaster recovery plan will state the contracted RPO objectives, which show what point in the processing cycle an organization can recover to, or what point in time data can be restored to. For example, an RPO of 15 minutes means the data cannot be more than 15 minutes old. ## The Emergency Mode Operation Plan An emergency mode operation plan must also be pre-defined and practiced, ensuring HIPAA disaster recovery plan processes are achievable while keeping electronic protected health information secure. The MSP will be responsible for ensuring that the correct technical and management teams are available during a HIPAA disaster recovery scenario and ultimately that they are responsible for restoring the service. It is important that the MSP work with the healthcare organization so that HIPAA specifications of the emergency mode operation plan can be met: - **How to Keep the Business Running in the Event of a Disaster –** This will define what critical IT infrastructure is needed to keep the healthcare organization operating. Source machines requiring restoration to the cloud during a DR scenario will be identified (meaning any server containing ePHI). Priority must be allocated to HIPAA-compliant servers and systems that are business critical, such as Active Directory services, database systems, networking hardware, and backend storage with ePHI data. - **Define What the Recovery Process is and Create a Definition of Required Activities**– This will be a step-by-step process from the MSP outlining how they are going to restore services to ensure minimal disruption in line with RPO and RTO specifications, sometimes referred to as *service blueprints*. If the system is automated, it will form a recovery plan run book of how to bring the systems back online and in what order. HIPAA compliance rules stipulate that only authorized users can perform these processes and require that all ePHI data is protected. - **Conduct Post DR Activities and Review Lessons Learned –**Once services have been failed over and systems are running in DR, the MSP and healthcare organization must work together to test systems and access. Any issues experienced must be resolved or captured in a “lessons learned” meeting for future reference. ## Testing and Revision Procedures The testing and any subsequent revisions of the data backup plan, disaster recovery plan, and emergency mode operation plan are a highly recommended (although not mandatory) part of HIPAA compliance. Essentially, the healthcare organization and MSP must test all of the above plans, as well as test the technical aspects of the failover and failback process, ensuring that the process works and that the system is capable of disaster recovery in a secondary site. Annual DR tests are advised. If during testing and revision procedures changes to the plan are required, they should be enacted immediately after testing. Recommendations and changes should be discussed and implemented under change control to ensure future tests are successful. ## Application and Data Criticality Analysis Another non-mandatory recommendation for HIPAA compliance is to identify the systems that store and manage ePHI data and ensure priority is given to data backup and continuity planning – this is called application and data criticality analysis. Most MSPs follow this recommendation, as it forms the basis of any automated failover strategy. The MSP needs to know what systems are classed as critical and which contain ePHI. That way, the best RPO can be delivered by restoring service to critical systems and restoring critical business processes as a priority. To summarize, HIPAA Disaster Recovery and Business Continuity Planning are a significant part of HIPAA compliance. HIPAA compliance demands the MSP can transfer critical business systems containing ePHI into a disaster recovery location. MSPs and healthcare organizations must not overlook the importance of HIPAA Disaster Recovery, and businesses need to comprehend what may happen to them if they fail to have a working DR strategy. By choosing a [HIPAA-compliant MSP](https://www.atlantic.net/hipaa-compliant-hosting/), you can have peace of mind that these rigorous criteria have been met and exceeded. --- # Multi-Factor Authentication vs 2FA – What Is the Best Login Security? > URL: https://www.atlantic.net/hipaa-compliant-hosting/two-factor-authentication-vs-multi-factor-authentication-the-best-log-in-security/ | Published: 2023-09-10 | Updated: 2024-09-10 | Author: Richard Bailey When securing access to sensitive IT infrastructure, professionals must consider what authentication methods are going to be implemented to protect the data and content stored within. ## Why Use Two-Factor or Multi-Factor Authentication? With the prominent and growing concerns of cybercrime and internet security in the computing industry, a simple single-factor authentication process with a standard username and password to access online accounts, computers, servers or even banking services is insufficient. To maintain security, it is essential that only approved users or authorized personnel are granted privileged access to IT solutions and services. Most organizations choose to implement a security standard that uses either Two-Factor Authentication (2FA) or Multi-Factor Authentication (MFA). Both 2FA and MFA are secure authentication methods that share similar security techniques that require the user to prove their user identity; however, there are fundamental differences between them, and although you may not realize it, it is quite likely that you already use these authentication solutions in your day-to-day lives. ## What Is Two-Factor Authentication (2FA)? Two-factor authentication (2FA) is a security practice wherein access is granted to a user upon provision of two different authentication factors. ## What Is an Authentication Factor? An authentication factor is a type of security credential used to verify a specific user’s identity before they are granted access to a system or place, typically **something only they know** (also called a knowledge factor, usually a password) with a **security item they have**(also called a possession factor). This item is usually a physical device provided by an organization or 3rd parties, such as a mobile phone, a PKI security card, or an RSA Secure Token. These secured items often display a changeable code or PIN. The user must enter their Username and Password, as well as the PIN code to access or log in. As most of the population carry smartphones, many organizations opt to send SMS text codes to users when either accessing secure sites and services or when conducting sensitive transactions, such as removing funds from digital financial services like PayPal or Skrill. Applications have also been developed, like One-Time Password (OTP) Authentication, which generates a security key that only you and the provider share. Timed One-Time Password (TOTP) apps add a further level of security, as the PIN code or security key a TOTP generates will change at a predefined timed interval. Two-factor authentication is extremely popular on the Internet and is used by organizations like Amazon and Google services like Gmail and YouTube. Many business compliance standards, such as Healthcare HIPAA standards, or SOC1/SOC2/SOC3 SSAE, demand that at least two-factor authentication be implemented for the protection of sensitive data and transactions. This is because it is a much more difficult authentication method to compromise. Server-side authentication devices and those of the user need to be aligned, which makes security breaches unlikely. ## What Is Multi-Factor Authentication (MFA)? Multi-factor authentication (MFA) is a security practice like two-factor authentication but with an additional layer of complexity to secure login access. A user is required to provide three authentication factors – **something only they know** (again usually a password) with a **security item they have** (a possession factor) and **something** **unique to the user** (such as a fingerprint or retina scan – a biometric factor). In extremely secure environments, there may be even more than three authentication factors required to gain access. [MFA](https://www.atlantic.net/vps-hosting/atlantic-net-trusted-access-guide-to-multi-factor-authentication/) is a favored authentication method among Managed Service Providers (MSPs), as requiring multiple authentication factors offers significant protection to enterprise files and applications. Besides verifying the identity of each user, the systems can diagnose the health of each multi-factor authentication device. By establishing the presence of vital security controls and checking for out-of-date software, multi-factor authentication can easily block high-risk or infected machines or devices. ## What Is Single-Factor Authentication? In single-factor authentication (SFA), only a single password needs to be compromised or cracked to gain unauthorized access. There are password-cracking tools available online that can breach low-quality or common passwords in a matter of seconds. In SFA, it is the user’s responsibility to ensure that a strong password is created, and IT infrastructure administrators cannot always guarantee an employee is not going to use low standards or share their simple passwords. ## 2FA vs MFA vs SFA: What Authentication Methods Are Best? Multi-factor authentication (MFA) is generally more secure. Adding additional authentication factors will increase the security of the system and make it harder for unauthorized users to gain access, as each additional authentication factor requires users to provide additional proof of their user identity. However, ease of use must be balanced with security in authentication practices. While strong security is a core concern in IT, it is important to consider the user and how security impacts the user. Not everyone is technically skilled and two-factor authentication and multi-factor authentication can create barriers within a system that less savvy users will have difficulty surmounting. Best practice should achieve a balance where the system is secure while not hindering the user experience. Both two-factor authentication and multi-factor authentication are significantly more secure than single-factor authentication. Two-factor authentication and multi-factor authentication enforce additional layers of protection which the user must adhere to in order to gain appropriate system access.  Warnings can be flagged if an incorrect part of the two-factor authentication or multi-factor authentication is entered, and often IT systems will email the user stating that a failed login attempt has been monitored. Two-factor authentication and multi-factor authentication cannot be used in every scenario and are not a foolproof answer to a good password policy; for example, consider a scenario where a user has a mobile phone device that acts as a PIN code generator to access a system. If the user has no signal or if the mobile phone is in the repair shop, then the user will not get access because they do not have the ability to provide the appropriate authentication factor. To counteract these problems, two-factor authentication and multi-factor authentication are often only required at first log-in or when accessing sensitive data from a new terminal. Once initial trust is established through the use of cookies, single-factor authentication is often acceptable for future use for a certain period of time. For help with [VPS hosting](https://www.atlantic.net/vps-hosting/) for your organization’s data, contact Atlantic.Net today! --- # Atlantic.Net Named “Top InfoSec Innovator” in Cyber Defense Magazine’s 11th Annual InfoSec Awards > URL: https://www.atlantic.net/press-releases/atlantic-net-named-top-infosec-innovator-in-cyber-defense-magazines-11th-annual-infosec-awards/ | Published: 2023-09-12 | Updated: 2024-06-03 | Author: Editorial Team WASHINGTON, D.C. (BUSINESSWIRE) SEPTEMBER  12, 2023 – Atlantic.Net has been named a finalist for the Top InfoSec Innovator from Cyber Defense Magazine (CDM), the industry’s leading electronic information security magazine. Judging continues through October 2023, when winners will be announced online, in print, and during Cyber Defense Con 2023 on October 26-27, 2023 in Orlando, Florida. A select group of winners will be given the opportunity to showcase their innovative solutions to the Top Global CISOs during their invitation only conference at[https://www.cisoconference.com](https://www.cisoconference.com). “We’re thrilled to receive this recognition in one of the most prestigious and coveted cybersecurity awards from Cyber Defense Magazine during their 11th anniversary as an independent cybersecurity news and information provider. We knew the competition at Cyber Defense Con would be tough, and with leading infosec experts from around the globe judging the event, we couldn’t be more pleased to be finalists,” said Marty Puranik, founder, president, and CEO of Atlantic.Net. “We scoured the globe looking for cybersecurity innovators that could make a huge difference and potentially help turn the tide against the exponential growth in cyber-crime. Atlantic.Net is worthy of being named a finalist in these coveted awards and consideration for deployment in your environment,” said Yan Ross, Editor of Cyber Defense Magazine. Our team is thrilled to be among the distinguished finalists of the 11th Annual InfoSec Awards. **About Atlantic.Net** Atlantic.Net is a global web hosting provider with over two decades of experience, specializing in managed and non-managed Windows, Linux, and FreeBSD server hosting solutions. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions. Solutions are offered across their hosting facilities in San Francisco, New York, London, Toronto, Dallas, Ashburn, and Orlando. With 24/7/365 support, Atlantic.Net is dedicated to providing excellent customer service. For more information, please visit[https://www.atlantic.net](https://www.atlantic.net). **About Cyber Defense Awards** This is Cyber Defense Magazine’s eleventh year of honoring InfoSec innovators from around the Globe. Our submission requirements are for any startup, early stage, later stage, or public companies in the INFORMATION SECURITY (INFOSEC) space who believe they have a unique and compelling value proposition for their product or service. Learn more at[www.cyberdefenseawards.com](http://www.cyberdefenseawards.com). **About Cyber Defense Magazine** Cyber Defense Magazine is the premier source of cyber security news and information for InfoSec professions in business and government. We are managed and published by and for ethical, honest, passionate information security professionals. Our mission is to share cutting-edge knowledge, real-world stories and awards on the best ideas, products, and services in the information technology industry. We deliver electronic magazines every month online for free, and special editions exclusively for the RSA Conferences and Cyber Defense Conferences.  CDM is a proud member of the Cyber Defense Media Group. Learn more about us at[https://www.cyberdefensemagazine.com](https://www.cyberdefensemagazine.com) and visit[https://www.cyberdefensetv.com](https://www.cyberdefensetv.com) and[https://www.cyberdefenseradio.com](https://www.cyberdefenseradio.com) to see and hear some of the most informative interviews of many of these award-winning company executives. Search for a Cybersecurity job at[https://www.cyberdefenseprofessionals.com](https://www.cyberdefenseprofessionals.com) or post an infosec job for free, anytime   --- # How to Install Bitwarden Password Manager on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-bitwarden-password-manager-on-fedora/ | Published: 2023-09-12 | Updated: 2024-06-01 | Author: Hitesh Jethva Bitwarden is a free and open-source password manager used to store sensitive information such as passwords in an encrypted vault. It can be available in a variety of client applications including mobile applications, browser extensions, web interfaces, and desktop apps. Compared to other password managers, Bitwarden is free and includes all the necessary password management features. In this post, we will show you how to install the Bitwarden password manager on Fedora Linux. ## Step 1 – Install Docker and Docker Compose By default, the Docker and Docker Compose packages are not included in the Fedora default repo, so you will need to add a Docker repo to the Yum repository. You can add it with the following command. ``` dnf -y install dnf-plugins-core dnf config-manager --add-repo https://download.docker.com/linux/fedora/docker-ce.repo ``` The above command will create a docker-ce.repo file in the Yum configuration directory. Now, run the following command to install Docker, Docker Compose, and other packages to Fedora. ``` dnf install docker-ce docker-ce-cli containerd.io docker-compose-plugin docker-compose -y ``` After successful installation, start and enable the Docker service using the following command. ``` systemctl start docker systemctl enable docker ``` You can now verify the Docker version using the following command. ``` docker --version ``` Output. ``` Docker version 20.10.17, build 100c701 ``` ## Step 2 – Install Bitwarden Bitwarden provides a script to install Bitwarden to your server automatically via the command line. First, download the auto installation script using the following command. ``` curl -Lso bitwarden.sh https://go.btwrdn.co/bw-sh ``` Next, set executable permissions to the script. ``` chmod +x bitwarden.sh ``` Next, run the following command to start the installation. ``` ./bitwarden.sh install ``` You will be asked to provide your domain name or IP address as shown below: ``` _ _ _ _ | |__ (_) |___ ____ _ _ __ __| | ___ _ __ | '_ \| | __\ \ /\ / / _` | '__/ _` |/ _ \ '_ \ | |_) | | |_ \ V V / (_| | | | (_| | __/ | | | |_.__/|_|\__| \_/\_/ \__,_|_| \__,_|\___|_| |_| Open source password management solutions Copyright 2015-2023, 8bit Solutions LLC https://bitwarden.com, https://github.com/bitwarden =================================================== bitwarden.sh version 2023.7.2 Docker version 20.10.17, build 100c701 docker-compose version 1.28.6, build unknown (!) Enter the domain name for your Bitwarden instance (ex. bitwarden.example.com): 192.168.10.10 ``` Provide your server IP and press the Enter key. You will be asked for SSL installation, database name, Bitwarden installation key, region, and self-signed installation as shown below: ``` (!) Do you want to use Let's Encrypt to generate a free SSL certificate? (y/n): n (!) Enter the database name for your Bitwarden instance (ex. vault): vault (!) Enter your installation id (get at https://bitwarden.com/host): 60baaac0-2c35-4b4b-80ea-b06001083c0b (!) Enter your installation key: LfhbacCe5EYy4pn2L5if (!) Enter your region (US/EU) [US]: US (!) Do you have a SSL certificate to use? (y/N): N (!) Do you want to generate a self-signed SSL certificate? (y/N): y ``` Provide all required information and press the Enter key. Once the Bitwarden is installed, you will see the following output. ``` Generating self signed SSL certificate. Generating a RSA private key .......................++++ ............................................++++ writing new private key to '/bitwarden/ssl/self/192.168.10.10/private.key' ----- Generating key for IdentityServer. Generating a RSA private key .................................................................................................................................................................++++ .........................++++ writing new private key to 'identity.key' ----- !!!!!!!!!! WARNING !!!!!!!!!! You are using an untrusted SSL certificate. This certificate will not be trusted by Bitwarden client applications. You must add this certificate to the trusted store on each device or else you will receive errors when trying to connect to your installation. Building nginx config. Building docker environment files. Building docker environment override files. Building FIDO U2F app id. Building docker-compose.yml. Installation complete If you need to make additional configuration changes, you can modify the settings in `./bwdata/config.yml` and then run: `./bitwarden.sh rebuild` or `./bitwarden.sh update` ``` ## Step 3 – Start Bitwarden Next, run the following command to start Bitwarden. ``` ./bitwarden.sh start ``` If everything is fine, you will get the following output. ``` _ _ _ _ | |__ (_) |___ ____ _ _ __ __| | ___ _ __ | '_ \| | __\ \ /\ / / _` | '__/ _` |/ _ \ '_ \ | |_) | | |_ \ V V / (_| | | | (_| | __/ | | | |_.__/|_|\__| \_/\_/ \__,_|_| \__,_|\___|_| |_| Open source password management solutions Copyright 2015-2023, 8bit Solutions LLC https://bitwarden.com, https://github.com/bitwarden =================================================== bitwarden.sh version 2023.7.2 Docker version 20.10.17, build 100c701 docker-compose version 1.28.6, build unknown Bitwarden is up and running! =================================================== visit https://192.168.10.10 to update, run `./bitwarden.sh updateself` and then `./bitwarden.sh update` ``` ## Step 4 – Access Bitwarden Web UI At this point, Bitwarden is installed and running on your server. You can now access the Bitwarden web interface using the URL **https://your-server-ip.** You will see the account creation page: ![Bitwarden welcome page](https://www.atlantic.net/wp-content/uploads/2023/08/p1-12.png) Provide your email address and click on **Create account.** You will see the following screen. ![Bitwarden account creation page](https://www.atlantic.net/wp-content/uploads/2023/08/p2-11.png) Provide all the required information and click on **Create Account**. You will see the Bitwarden login screen. ![Bitwarden login screen](https://www.atlantic.net/wp-content/uploads/2023/08/p3-10.png) Provide your username and click on **Continue.** You will see the following screen. ![bitwarden password screen](https://www.atlantic.net/wp-content/uploads/2023/08/p4-7.png) Provide your password and click on **Login** with a master password. You will see the Bitwarden dashboard on the following screen. ![Bitwarden dashboard](https://www.atlantic.net/wp-content/uploads/2023/08/p5-6.png) ## Conclusion In this guide, we explained how to install the Bitwarden password manager using Docker on Fedora Linux. Now you can explore the Bitwarden features and use Bitwarden in your company to manage all credentials from the web-based interface. Try Bitwarden on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install React.js with Nginx on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-react-js-with-nginx-on-fedora/ | Published: 2023-09-13 | Updated: 2024-06-01 | Author: Hitesh Jethva React JS is a free and open-source JavaScript library used for building single-page applications, web frontends, and UI components. React is lightweight and makes your application faster to load. It has a helpful and interactive developer toolset that helps you to debug your application easily. In this post, we will show you how to install React JS and configure Nginx as a reverse proxy on Fedora Linux. ## Step 1 – Install Node.js Before starting, you will need to install Node.js on your server. First, install all the Node.js dependencies using the following command. ``` dnf install -y gcc-c++ make ``` Then, add the Node source repo to get the latest Node.js version. ``` curl -sL https://rpm.nodesource.com/setup_18.x | bash - ``` Next, install the Node.js package with the following command. ``` dnf install nodejs git ``` Now, verify the Node.js version using the following command. ``` node -v ``` Output. v18.19.0 ## Step 2 – Install React JS and Create an Application First, you will need to install the create-react-app tool on your server. The create-react-app tool helps you create and deploy applications quickly. You can install it via the NPM command as shown below: ``` npm install -g create-react-app ``` You can now verify the create-react-app version with the following command. ``` create-react-app --version ``` Output. ``` 5.0.1 ``` Now, run the following command to create your first application. ``` create-react-app my-app ``` You will see the following output. ``` Success! Created my-app at /root/my-app Inside that directory, you can run several commands: npm start Starts the development server. npm run build Bundles the app into static files for production. npm test Starts the test runner. npm run eject Removes this tool and copies build dependencies, configuration files and scripts into the app directory. If you do this, you can’t go back! We suggest that you begin by typing: cd my-app npm start Happy hacking! ``` ## Step 3 – Run the React JS Application At this point, your React application is created on your server. Now, it’s time to run it. First, navigate inside your app directory and run the following command to start your application. ``` cd my-app npm start ``` You will see the following output. ``` Compiled successfully! You can now view my-app in the browser. http://localhost:3000 Note that the development build is not optimized. To create a production build, use npm run build. webpack compiled successfully ``` Now, open your web browser and access your React JS app using the URL **http://your-server-ip:3000.** You will see your application on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p1-11.png) ## Step 4 – Create a Systemd File for React JS Next, you will need to create a system file to manage your application service via the command line. You can create it using the following command. ``` nano /lib/systemd/system/react.service ``` Add the following code: ``` [Service] Type=simple User=root Restart=on-failure WorkingDirectory=/root/my-app ExecStart=npm start -- --port=3000 ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Now, start and enable the React JS service. ``` systemctl start react systemctl enable react ``` ## Step 5 – Configure Nginx as a Reverse Proxy It is a good idea to set up Nginx as a reverse proxy for the React JS app. First, install the Nginx package using the following command. ``` dnf install nginx ``` Next, start and enable the Nginx service with the following command. ``` systemctl start nginx systemctl enable nginx ``` Next, create an Nginx virtual server block. ``` nano /etc/nginx/conf.d/react.conf ``` Add the following configurations: ``` upstream react_backend { server localhost:3000; } server { listen 80; server_name react.example.com; location / { proxy_pass http://react_backend/; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forward-For $proxy_add_x_forwarded_for; proxy_set_header X-Forward-Proto http; proxy_set_header X-Nginx-Proxy true; proxy_redirect off; } } ``` Save and close the file. then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following lines after the line http {: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then restart the Nginx service to reload the changes. ``` systemctl restart nginx ``` You can now access your React JS application using the URL **http://react.example.com.** ## Conclusion Congratulations! You have successfully installed and deployed React JS on Fedora Linux. You can now start building your own single-page application using the React framework. You can now deploy a React JS application on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Symfony Framework on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-symfony-framework-on-fedora/ | Published: 2023-09-14 | Updated: 2025-04-22 | Author: Hitesh Jethva Symfony is a free and open-source PHP web application framework for building web applications, APIs, microservices, and web services. It provides tools and features for building scalable PHP web applications with a robust caching system. It has comprehensive documentation and an active community, making it an excellent resource for [Symfony developers](https://www.toptal.com/symfony) looking to create high-quality PHP web applications. This post will show you how to install the Symfony framework on Fedora Linux. ## Step 1 – Install the LAMP Server Symfony is based on PHP, so you will need to install the LAMP server on your server. First, install the Apache and MariaDB server using the following command. ``` dnf install httpd mariadb-server -y ``` Next, add the PHP Remi repo to get the latest PHP version. ``` dnf install -y http://rpms.remirepo.net/fedora/remi-release-34.rpm dnf module install php:remi-8.1 ``` Next, install PHP with other required PHP extensions using the following command. ``` dnf install php php-cli php-common php-spl php-fpm php-hash php-ctype php-json php-mbstring php-gd php-curl php-mysqli php-xml php-gmp php-xmlrpc php-bcmath php-soap php-ldap unzip -y ``` Next, start and enable Apache, MariaDB, and PHP-FPM. ``` systemctl start httpd mariadb php-fpm systemctl enable httpd mariadb php-fpm ``` ## Step 2 – Install Symfony First, install Composer with the following command. ``` wget https://getcomposer.org/installer -O composer-installer.php php composer-installer.php --filename=composer --install-dir=/usr/local/bin ``` Next, navigate to the Apache web root directory and install Symfony 6 with the following command. ``` cd /var/www/html composer create-project symfony/website-skeleton symfony6 ``` Next, set proper permission and ownership to the Symfony directory. ``` chown -R apache:apache /var/www/html/symfony6 chmod -R 755 /var/www/html/symfony6 ``` Now, change the directory to Symfony and start the Symfony server with the following command. ``` cd /var/www/html/symfony6 php -S 0.0.0.0:8000 -t public ``` You will see the following output. ``` [Thu Aug 17 00:17:19 2023] PHP 8.1.9 Development Server (http://0.0.0.0:8000) started ``` Now, open your web browser and access Symfony using the URL **http://your-server-ip:8000.** You will see the following screen. Next, press CTRL+C to stop the Symfony server. We will configure Apache for Symfony. ## Step 3 – Configure Apache for Symfony 6 Next, you must create an Apache virtual host configuration file for Symfony. ``` nano /etc/httpd/conf.d/symfony.conf ``` Add the following configuration: ``` ServerAdmin admin@example.com DocumentRoot "/var/www/html/symfony6/public" ServerName symfony.example.com AllowOverride All Order Allow,Deny Allow from All ErrorLog "/var/log/httpd/example.com-error_log" CustomLog "/var/log/httpd/example.com-access_log" combined ``` Save and close the file when you are done. Then, restart the Apache service to apply the changes. ``` systemctl restart httpd ``` ## Step 4 – Access Symfony Web Interface Now, open your web browser and access the Symfony dashboard using the URL **http://symfony.example.com.** ![symfony dashboard](https://www.atlantic.net/wp-content/uploads/2023/08/p1-13.png) ## Conclusion In this post, we showed you how to install Symfony6 on Fedora Linux. You can build and deploy a scalable PHP application using the Symfony framework. You can now try Symfony on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install PrestaShop on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-prestashop-on-fedora/ | Published: 2023-09-16 | Updated: 2023-11-18 | Author: Hitesh Jethva PrestaShop is a free online shopping cart platform that allows users to create an online store and sell products to an online audience. It is a simple and feature-rich application that provides the best shopping cart experience for both merchants and customers. It is written in the PHP language and Symfony PHP framework with support for the MySQL database management system. PrestaShop is available in 65 different languages and is used by many shops worldwide. This post will explain how to install PrestaShop on Fedora Linux. ## Step 1 – Install the LAMP Server By default, the Apache and MariaDB server packages are available in the Fedora default repo. You can install both of them using the following command. ``` dnf install httpd mariadb-server ``` Once both packages are installed, you will need to install the latest PHP version to your system. To do so, add the PHP Remi repo to your system. ``` dnf install -y http://rpms.remirepo.net/fedora/remi-release-34.rpm dnf module install php:remi-8.1 ``` Next, install PHP with other required extensions using the following command. ``` dnf install php php-zip php-xml php-gd php-curl php-fpm php-xmlrpc php-mbstring php-mysqli php-bcmath php-dom php-posix php-cli php-pdo php-posix php-fileinfo php-json php-iconv -y yum --enablerepo=remi install php-intl php-zip ``` Then, edit the PHP configuration file and modify the default settings. ``` nano /etc/php.ini ``` Change the following lines. ``` max_input_vars = 3000 post_max_size = 64M upload_max_filesize = 64M max_execution_time = 600 memory_limit = 256M date.timezone = UTC ``` Save and close the file, then start and enable the Apache, MariaDB, and PHP-FPM services using the following command. ``` systemctl start httpd mariadb php-fpm systemctl enable httpd mariadb php-fpm ``` ## Step 2 – Configure Database for PrestaShop Next, you will need to create a database and user for PrestaShop. First, log in to the MariaDB shell with the following command. ``` mysql ``` Next, create a database and user for PrestaShop. ``` CREATE DATABASE prestadb; CREATE USER 'prestauser'@'localhost' IDENTIFIED BY 'password'; GRANT ALL PRIVILEGES ON prestadb.* TO 'prestauser'@'localhost'; ``` Then, flush the privileges and exit from the MariaDB console. ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install PrestaShop First, download the latest version of PrestaShop using the following command. ``` wget https://github.com/PrestaShop/PrestaShop/releases/download/8.1.0/prestashop_8.1.0.zip ``` Next, create a directory for PrestaShop and extract the downloaded file inside the PrestaShop directory. ``` mkdir /var/www/html/prestashop unzip prestashop_8.1.0.zip -d /var/www/html/prestashop ``` Next, set proper permissions and ownership to the PrestaShop directory. ``` chown -R apache:apache /var/www/html/prestashop chmod -R 775 /var/www/html/prestashop ``` ## Step 4 – Create an Apache Virtual Host for PrestaShop Now, create an Apache virtual host configuration file to host PrestaShop on the web. ``` nano /etc/httpd/conf.d/prestashop.conf ``` Add the following content. ``` ServerName prestashop.example.com DocumentRoot /var/www/html/prestashop Options -Indexes +FollowSymLinks AllowOverride All ErrorLog /var/log/httpd/prestashop-error.log CustomLog /var/log/httpd/prestashop-access.log combined ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart httpd ``` ## Step 5 – Access PrestaShop Web UI Now, open your web browser and access PrestaShop using the URL **http://prestashop.example.com.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p1-5.png) Select your language and click on **Next.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p2-5.png) Agree on the license and click on **Next.** You will see the store configuration screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p3-4.png) Define your store information and click on **Next.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p4-2.png) Select demo installation and click on **Next.** You will see the database configuration screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p5-3.png) Define your database settings and click on **Next.** Once the installation is finished, you will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p7-1.png) Now, open your terminal and remove the **Install** folder before logging in to the backend. ``` rm -rf /var/www/html/prestashop/install ``` Next, click on **Manage your store.** You will see the PrestaShop login screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p8-1.png) Provide your email and password then click on **LOG IN**. You will see the PrestaShop dashboard. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p9-2.png) ## Conclusion Congratulations! You have successfully installed PrestaShop with Apache on Fedora Linux. You can now deploy PrestaShop on your own server and sell the products online. You can now test PrestaShop on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Craft CMS on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-craft-cms-on-fedora/ | Published: 2023-09-17 | Updated: 2024-06-01 | Author: Hitesh Jethva Craft is a user-friendly and flexible CMS platform used to build a website using customizable themes and templates. It is based on the Yii2 framework and differentiates itself by putting your content first and providing an adaptable experience to the user. You can connect Craft CMS to other marketing tools like Salesforce, Mailchimp, Hubspot, and countless more. In this tutorial, we will explain how to install Craft CMS on Fedora Linux. ## Step 1 – Install LEMP Server First, install the Nginx and MariaDB server with the following command. ``` dnf install nginx mariadb-server -y ``` Once both packages are installed, add the PHP Remi repository to get the latest PHP version. ``` dnf install -y http://rpms.remirepo.net/fedora/remi-release-34.rpm dnf module install php:remi-8.1 ``` Next, install PHP and other required extensions using the following command. ``` dnf install php php-cli php-fpm php-common php-curl php-gd php-json php-mbstring php-mysqli php-pgsql php-xml php-pdo -y yum --enablerepo=remi install php-intl php-zip ``` Next, edit the PHP configuration file. ``` nano /etc/php.ini ``` Change the following lines: ``` memory_limit = 256M date.timezone = UTC ``` Next, edit the PHP-FPM configuration file. ``` nano /etc/php-fpm.d/www.conf ``` Change the user and group from apache to nginx. ``` user = nginx group = nginx ``` Save and close the file then start and enable Nginx, MariaDB, and PHP-FPM services. ``` systemctl start nginx mariadb php-fpm systemctl enable nginx mariadb php-fpm ``` ## Step 2 – Configure MariaDB Craft CMS uses MariaDB to store its content, so you will need to create a database and user for MariaDB. First, connect to the MariaDB shell using the following command. ``` mysql ``` Once you are connected, create a database and user for Craft CMS. ``` create database craftdb; grant all on craftdb.* to craftuser@localhost identified by 'securepassword'; ``` Next, flush the privileges and exit from MariaDB using the following command. ``` flush privileges; exit; ``` ## Step 3 – Install Craft CMS First, download the Composer setup file and run it to install the Composer using the following command. ``` php -r "copy('https://getcomposer.org/installer', 'composer-setup.php');" HASH="$(wget -q -O - https://composer.github.io/installer.sig)" php -r "if (hash_file('SHA384', 'composer-setup.php') === '$HASH') { echo 'Installer verified'; } else { echo 'Installer corrupt'; unlink('composer-setup.php'); } echo PHP_EOL;" php composer-setup.php --install-dir=/usr/local/bin --filename=composer ``` Next, change the directory to the Nginx web root and install the Craft CMS using the following command. ``` cd /var/www/html/ composer create-project craftcms/craft craftcms ``` During the installation, you will be asked to set your admin username, password, and other information as shown below. ``` Proceed anyway? (yes|no) [no]:yes Which database driver are you using? (mysql or pgsql) [mysql] Database server name or IP address: [127.0.0.1] Database port: [3306] Database username: [root] craftuser Database password: Database name: craftdb Database table prefix: Testing database credentials ... success! Saving database credentials to your .env file ... done Install Craft now? (yes|no) [yes]:yes Username: [admin] Email: admin@example.com Password: Invalid input. Password: Confirm: Site name: MySite Site URL: http://craftcms.example.com Site language: [en-US] ``` Next, set proper permissions and ownership to the Craft CMS directory. ``` chown -R nginx:nginx /var/www/html/craftcms chmod -R 777 /var/www/html/craftcms chown -R nginx:nginx /var/lib/php/session chmod 777 -R /var/lib/php/session ``` ## Step 4 – Configure Nginx for Craft CMS Next, create an Nginx virtual host configuration file. ``` nano /etc/nginx/conf.d/craft.conf ``` Add the following configurations: ``` server { listen 80; server_name craftcms.example.com; root /var/www/html/craftcms/web; index index.php; location / { try_files $uri/index.html $uri $uri/ /index.php?$query_string; } location ~ [^/]\.php(/|$) { try_files $uri $uri/ /index.php?$query_string; fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_pass unix:/run/php-fpm/www.sock; fastcgi_index index.php; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_param PATH_INFO $fastcgi_path_info; fastcgi_param HTTP_PROXY ""; } } ``` Save and close the file, then edit the Nginx configuration file. ``` nano /etc/nginx.nginx.conf ``` Add the following line after the line http{: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 5 – Access Craft CMS Now, open your web browser and access the Craft CMS using the URL **http://craftcms.example.com.** You will see the Craft CMS welcome page. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p1-1.png) Click on **Go to your control panel**. You will see the Craft CMS login page. ![p2](https://www.atlantic.net/wp-content/uploads/2023/08/p2-1.png) Provide your admin username and password and click on the **Sign in** button. You will be redirected to the Craft CMS dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p3.png) ## Conclusion In this post, we explained how to install Craft CMS using the LEMP server. You can now easily design and build a beautiful website using the Craft CMS. You can now deploy Craft CMS on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install phpBB on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-phpbb-on-fedora/ | Published: 2023-09-18 | Updated: 2024-06-01 | Author: Hitesh Jethva phpBB is a free and open-source bulletin board software solution written in the PHP scripting language. It is one of the most popular CMS platforms used by thousands of professionals around the globe. phpBB supports file attachments, full-text search, notifications, and more. Its aim is to connect groups of people to come together to have discussions, share information, and learn from each other. This post will show you how to install phpBB forum software on Fedora Linux. ## Step 1 – Install LEMP Server First, install the Nginx and MariaDB server using the following command. ``` dnf install nginx mariadb-server -y ``` Once installed, add the PHP Remi repo to your system. ``` dnf install -y http://rpms.remirepo.net/fedora/remi-release-34.rpm dnf module install php:remi-8.1 ``` Next, install the PHP with other required packages on your server. ``` dnf install php php-mysqlnd php-fpm php-xml php-cli php-soap php-opcache php-iconv php-pear php-bcmath php-gd php-mbstring php-json php-devel unzip wget -y yum --enablerepo=remi install php-intl php-sodium php-zip ``` Once all the packages are installed, edit the PHP configuration file and change some default settings. ``` nano /etc/php.ini ``` Change the following lines. ``` max_execution_time = 180 max_input_time = 90 memory_limit = 256M upload_max_filesize = 64M ``` Next, edit the PHP-FPM configuration file and change the user and group from apache to nginx. ``` nano /etc/php-fpm.d/www.conf ``` Change the following lines: ``` user = nginx group = nginx ``` Save and close the file. Then, start and enable the Nginx, MariaDB, and PHP-FPM services. ``` systemctl start nginx mariadb php-fpm systemctl enable nginx mariadb php-fpm ``` ## Step 2 – Create a phpBB Database and User phpBB uses MariaDB/MySQL as a database backend, so you will need to create a database and user for phpBB. First, connect to the MariaDB shell. ``` mysql ``` Once you are connected, create a database and user for phpBB. ``` CREATE DATABASE phpbb; CREATE USER 'phpbbuser'@'localhost' IDENTIFIED BY 'password'; GRANT ALL ON phpbb.* TO 'phpbbuser'@'localhost' IDENTIFIED BY 'password' WITH GRANT OPTION; ``` Next, flush the privileges and exit from the MariaDB shell. ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download phpBB Software First, download the latest version of phpBB using the following command. ``` wget https://download.phpbb.com/pub/release/3.3/3.3.10/phpBB-3.3.10.zip ``` Once the download is completed, unzip the downloaded file. ``` unzip phpBB-3.3.10.zip ``` Then, move the extracted directory to the Nginx web root directory. ``` mv phpBB3 /var/www/html/phpbb ``` Next, install the Composer PHP dependency manager using the following command. ``` dnf install composer ``` Next, navigate to the phpBB directory. ``` cd /var/www/html/phpbb ``` Then, remove the default vendor directory and install other PHP dependencies using Composer. ``` rm -rf vendor composer install ``` Next, change the permission and ownership of the phpBB directory. ``` chown -R nginx:nginx /var/www/html/phpbb chmod -R 775 /var/www/html/phpbb ``` ## Step 4 – Configure Nginx for phpBB Next, create an Nginx virtual host configuration file. ``` nano /etc/nginx/conf.d/phpbb.conf ``` Add the following configurations: ``` server { listen 80; server_name phpbb.example.com; root /var/www/html/phpbb; index index.php index.html index.htm; access_log /var/log/nginx/phpbb-access.log; error_log /var/log/nginx/phpbb-error.log; location / { try_files $uri $uri/ @rewriteapp; # Pass the php scripts to FastCGI server specified in upstream declaration. location ~ \.php(/|$) { include fastcgi.conf; fastcgi_pass unix:/run/php-fpm/www.sock; fastcgi_split_path_info ^(.+\.php)(/.*)$; fastcgi_param PATH_INFO $fastcgi_path_info; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; fastcgi_param DOCUMENT_ROOT $realpath_root; try_files $uri $uri/ /app.php$is_args$args; fastcgi_intercept_errors on; } # Deny access to internal phpbb files. location ~ /(config\.php|common\.php|cache|files|images/avatars/upload|includes|(? URL: https://www.atlantic.net/vps-hosting/how-to-install-mediawiki-on-fedora/ | Published: 2023-09-19 | Updated: 2024-06-01 | Author: Hitesh Jethva MediaWiki is a free and open-source wiki system that allows you to put texts, photos, and movies on your MediaWiki page. It allows you to keep every change without deleting the previous versions. MediaWiki is simple and easy to use so any beginner user can change the text and content of the page without much training. MediaWiki uses PHP to process the data and MariaDB as a database backend. This post will show you how to install MediaWiki on Fedora Linux. ## Step 1 – Install Apache, MariaDB, and PHP First, install the Apache and MariaDB server using the following command. ``` dnf install httpd mariadb-server -y ``` Next, add the PHP Remi repository to install the latest PHP version. ``` dnf install -y http://rpms.remirepo.net/fedora/remi-release-34.rpm dnf module install php:remi-8.1 ``` Next, install PHP and other required extensions with the following command. ``` dnf install php php-mysqlnd php-gd php-xml php-mbstring php-json yum --enablerepo=remi install php-intl php-sodium php-zip ``` Next, start and enable the Apache and MariaDB services using the following command. ``` systemctl start mariadb httpd systemctl enable mariadb httpd ``` ## Step 2 – Create a Database for MediaWiki Next, you will need to create a database and user to store the MediaWiki data. First, log in to the MariaDB shell. ``` mysql -u root -p ``` Once you are connected to MariaDB, create a database and user for MediaWiki. ``` CREATE DATABASE mediawikidb; GRANT ALL PRIVILEGES ON mediawikidb.* TO 'mediawikiuser'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB shell. ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download MediaWiki First, visit the MediaWiki download page and download the latest version of MediaWiki using the following command. ``` wget https://releases.wikimedia.org/mediawiki/1.40/mediawiki-1.40.0.tar.gz ``` Once the download is completed, extract the downloaded file and copy it to the Apache web root. ``` tar -xvzf mediawiki-1.40.0.tar.gz mv mediawiki-1.40.0 /var/www/html/mediawiki ``` Next, change the ownership of the mediawiki directory. ``` chown -R apache:apache /var/www/html/mediawiki ``` ## Step 4 – Configure Apache for MediaWiki Next, you will need to create an Apache virtual host configuration file to host MediaWiki. ``` nano /etc/httpd/conf.d/media.conf ``` Add the following configurations: ``` ServerName media.example.com DocumentRoot /var/www/html/mediawiki ErrorLog /var/log/httpd/error.log CustomLog /var/log/httpd/requests.log combined ``` Save and close the file then restart the Apache service to apply the changes. ``` systemctl restart httpd ``` ## Step 5 – Access MediaWiki Open your web browser and access the MediaWiki installation using the URL **http://media.example.com.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p1-3.png) Click on the **setup wiki.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p2-3.png) Select your language and click on **Continue.** You will see the prerequisites check screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p3-2.png) Click on **Continue.** You will see the database configuration screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p4.png) Define your database settings and click on **Continue.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p5-1.png) Select “use the same account as for installation” and click on **Continue.** You will see the MediaWiki configuration screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p6-1.png) ![](https://www.atlantic.net/wp-content/uploads/2023/08/p7.png) Define your wiki name, admin username, and password, and click on **Continue.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p8.png) Click on **Continue** to start the installation. Once the database setup is completed, you will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p9.png) Click on **Continue.** Once the installation is finished, you will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p10.png) Now, download **LocalSettings.php** from the above page and copy it to the MediaWiki root directory. Then, click on the **Enter your wiki.** You will see the MediaWiki dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p11.png) ## Conclusion In this post, we learned how to install MediaWiki with Apache on Fedora and host your own wiki site on the internet. You can now easily host MediaWiki on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Typo3 CMS on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-typo3-cms-on-fedora/ | Published: 2023-09-20 | Updated: 2024-06-01 | Author: Hitesh Jethva TYPO3 is an open-source and platform-independent content management system that allows users to post and maintain their content on the web. It is based on PHP and used for Web Content Management (WCM) and Enterprise Content Management (ECM). It is compatible with many operating systems like Linux, Windows, macOS, and OS/2. If you are looking for an open-source digital content publishing platform, then TYPO3 is the best option for you. This post will show you how to install TYPO3 CMS on Fedora Linux. ## Step 1 – Install Apache, MariaDB, and PHP Let’s start with installing the Apache and MariaDB server on your system. ``` dnf install httpd mariadb-server -y ``` Next, add the PHP Remi repo to get the latest PHP version. ``` dnf install -y http://rpms.remirepo.net/fedora/remi-release-34.rpm dnf module install php:remi-8.1 ``` Next, install PHP with additional PHP extensions using the following command. ``` dnf install php php-mysqlnd php-fpm php-xml php-cli php-soap php-opcache php-iconv php-pear php-bcmath php-gd php-mbstring php-json php-devel unzip wget -y yum --enablerepo=remi install php-intl php-zip ``` Next, edit the PHP configuration file. ``` nano /etc/php.ini ``` Change the following values. ``` memory_limit = 512M max_execution_time = 300 max_input_vars = 2000 date.timezone = UTC post_max_size = 30M upload_max_filesize = 30M ``` Save and close the file then start and enable the Apache and MariaDB service using the following command. ``` systemctl start httpd mariadb systemctl enable httpd mariadb ``` ## Step 2 – Create a Database for TYPO3 Now, connect to the MariaDB console using the command given below. ``` mysql ``` Once you are connected, create a database and user for TYPO3. ``` create database typo3cms CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci; create user 'typo3cms'@localhost identified by 'password'; grant all privileges on typo3cms.* to 'typo3cms'@localhost; ``` Next, flush the privileges and exit from the MariaDB using the following command. ``` flush privileges; exit; ``` ## Step 3 – Install TYPO3 First, download the latest version of TYPO3 CMS using the following command. ``` curl -L -o typo3_src.tgz https://get.typo3.org/12.4.4 ``` Once the download is completed, extract the downloaded file. ``` tar -xvzf typo3_src.tgz ``` Next, move the extracted directory to the Apache web root. ``` mv typo3_src-12.4.4 /var/www/html/typo3 ``` Next, change the ownership of the TYPO3 directory. ``` chown -R apache:apache /var/www/html/typo3 ``` ## Step 4 – Configure Apache for TYPO3 Next, create an Apache virtual host configuration file for TYPO3. ``` nano /etc/httpd/conf.d/typo3.conf ``` Add the following configurations: ``` ServerAdmin admin@example.com DocumentRoot /var/www/html/typo3/ ServerName typo3.example.com Protocols h2 http/1.1 Options FollowSymlinks AllowOverride All Require all granted ErrorLog /var/log/httpd/typo3-error.log CustomLog /var/log/httpd/typo3-access.log combined RewriteEngine on RewriteBase / RewriteCond %{REQUEST_FILENAME} !-f RewriteRule ^(.*) index.php [PT,L] ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart httpd ``` ## Step 5 – Access TYPO3 CMS Before accessing the TYPO3 web installation wizard, create a blank file inside the TYPO3 CMS directory. ``` touch /var/www/html/typo3/FIRST_INSTALL ``` Next, open your web browser and access the TYPO3 CMS using the URL **http://typo3.example.com.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p1-4.png) Click on **“No problem detected, continue with the installation”**. You will see the database setup screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p2-4.png) Define your database username and password and click on the **Continue** button. You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p3-3.png) Select your database and click on the **Continue** button. You will see the TYPO3 account configuration screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p4-1.png) Define your admin username, password, and email, then click on **Continue.** Once the installation is completed, you will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p5-2.png) Select Take me to the backend and click on **Open the TYPO3 Backend**. You will see the TYPO3 CMS login screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p6-2.png) Provide your admin username and password and click on **Login.** You will see the TYPO3 dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p9-1.png) ## Conclusion Congratulations! You have successfully installed TYPO3 CMS on Fedora Linux. You can now explore the TYPO3 dashboard, test all its features, and start implementing it in your organization. You can now try TYPO3 CMS on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Atlantic.Net Named a Global Leader in Cloud Computing > URL: https://www.atlantic.net/press-releases/atlantic-net-named-a-global-leader-in-cloud-computing/ | Published: 2023-09-20 | Updated: 2026-03-02 | Author: Editorial Team Orlando, Florida—September 20, 2023—The Business Intelligence Group awarded Atlantic.Net a 2023 Stratus Award for Cloud Computing in their annual business award program. The award recognizes the companies, products, and people offering unique solutions that take advantage of cloud technologies. Atlantic.Net, a renowned cloud services provider, has been at the forefront of offering innovative and secure cloud solutions. With a rich history spanning more than two decades, the company has continually evolved to provide state-of-the-art services, including cloud hosting, managed services, and healthcare-compliant solutions, facilitating businesses worldwide in their digital transformation journey. “We are immensely honored to receive this recognition,” said Marty Puranik, CEO of Atlantic.Net. “This award is a testament to our relentless pursuit of excellence and innovation in the cloud computing sector. We remain committed to providing our clients with the very best cloud hosting services that are both reliable and highly secure.” “Atlantic.Net is one of the leaders in the cloud, helping to develop the infrastructure we need to store and host the data and applications driving our society,” said Maria Jimenez, Chief Nominations Officer of Business Intelligence Group. “We are so proud to recognize all of the winners in this year’s award program.” “I am so proud of our employees and partners for their dedication and hard work,” Puranik continued. “We know that the work you are doing is transforming the digital world as we know it and our technology will continue to lead the industry.” ### About Atlantic.Net Atlantic.Net is a global cloud services provider with a focus on security, compliance, and simplifying complex infrastructures. With over 29 years of experience, Atlantic.Net is dedicated to offering organizations a range of customized and cost-effective cloud solutions that cater to their unique business needs. The company’s commitment to excellence has positioned it as a leader in the industry, recognized for its innovation and customer-centric approach. ### About Business Intelligence Group The Business Intelligence Group was founded with the mission of recognizing true talent and superior performance in the business world. Unlike other industry and business award programs, business executives—those with experience and knowledge—judge the programs. The organization’s proprietary and unique scoring system selectively measures performance across multiple business domains and then rewards those companies whose achievements stand above those of their peers. For more information, please contact: [Atlantic.Net Support](https://www.atlantic.net/about-us/corporate-contact/) Sales: 866-618-3282 INTL: +1-408-335-082 --- # How to Install DokuWiki on Fedora > URL: https://www.atlantic.net/vps-hosting/how-to-install-dokuwiki-on-fedora/ | Published: 2023-09-21 | Updated: 2024-06-01 | Author: Hitesh Jethva DokuWiki is an open-source PHP-based wiki software developed by Andreas Gohr. It is very similar to MediaWiki and doesn’t require a database. It offers a simple yet powerful syntax that allows users to create structured texts easily. DokuWiki comes with all the necessary features to create a website along with SEO, authentication, and much more. This post will show you how to install DokuWiki on Fedora Linux. ## Step 1 – Install Apache and PHP First, install the Apache web server package using the following command. ``` dnf install httpd -y ``` Next, add the PHP Remi repository to get the latest PHP version. ``` dnf install -y http://rpms.remirepo.net/fedora/remi-release-34.rpm dnf module install php:remi-8.1 ``` Next, install the PHP and other required dependencies using the following command. ``` dnf install php php-mysqlnd php-fpm php-xml php-cli php-soap php-opcache php-iconv php-pear php-bcmath php-gd php-mbstring php-json php-devel unzip wget -y ``` Next, start and enable the Apache service with the following command. ``` systemctl start httpd systemctl enable httpd ``` ## Step 2 – Download DokuWiki First, download the latest version of DokuWiki using the following command. ``` wget https://download.dokuwiki.org/src/dokuwiki/dokuwiki-stable.tgz ``` Next, extract the downloaded file to the Apache web root directory. ``` mkdir /var/www/html/dokuwiki tar xzf dokuwiki-stable.tgz --strip-components=1 -C /var/www/html/dokuwiki/ ``` Next, change the ownership of the DokuWiki directory. ``` chown -R apache:apache /var/www/html/dokuwiki ``` ## Step 3 – Create an Apache Virtual Host for DokuWiki Next, you will need to create an Apache virtual host configuration file. ``` nano /etc/httpd/conf.d/dokuwiki.conf ``` Add the following configurations: ``` ServerAdmin admin@example.com ServerName doku.example.com DocumentRoot /var/www/html/dokuwiki AllowOverride All Require all denied Order allow,deny Deny from all ErrorLog /var/log/httpd/dokuwiki_error.log CustomLog /var/log/httpd/dokuwiki_access.log combined ``` Save and close the file then copy the .htaccess file. ``` cp /var/www/html/dokuwiki/.htaccess{.dist,} ``` Next, restart the Apache service to apply the changes. ``` systemctl restart httpd ``` ## Step 4 – Access DokuWiki Now, open your web browser and access the DokuWiki web UI using the URL **http://doku.example.com/install.php.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p1-2.png) Provide all required information and click on the **Save** button. You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p2-2.png) Click on **your new DokuWiki**. You will see the DokuWiki dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p3-1.png) ## Conclusion Congratulations! You have successfully installed DokuWiki on Fedora Linux. You can now start creating your own wiki website easily using DokuWiki. Try to host your own wiki site on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Multi-Factor Authentication Examples > URL: https://www.atlantic.net/managed-services/multi-factor-authentication-examples/ | Published: 2023-09-23 | Updated: 2025-09-15 | Author: Richard Bailey Securing online accounts and safeguarding sensitive information is a fundamental protection required to protect your personal details and privacy. Multi-factor authentication (MFA) is the primary security component used in modern business and our day-to-day lives. MFA is a proven technology that offers a robust method to verify the identity of authorized users. Through the MFA process, users are required to provide multiple authentication factors to prove their identity. Enhanced security layers like MFA minimize the risk of unauthorized access to digital assets. This article will explore a few examples of multi-factor authentication, illustrating how it remains a secure and reliable authentication method in various online services. ## How Does MFA Work? Understanding how multi-factor authentication works is essential in grasping its effectiveness in securing online accounts. The process involves verifying the user’s identity in multiple different ways. It usually requires something the user knows (like a password), something the user possesses (like a mobile device or security token), and sometimes, unique biological characteristics such as biometric data like fingerprints or facial recognition. When users log on, they are first prompted to enter a valid username, followed by a primary authentication factor, usually a password. Following this, additional authentication factors are requested, such as a one-time password sent to the user’s mobile device or a push notification through mobile apps like Google Authenticator. A layered approach ensures that even if one factor is compromised, unauthorized users still have to bypass additional layers to gain access, thus creating much higher security controls. ## Identification Through Something the User Possesses MFA evolves around users possessing a validated item that the IT system already knows. These are elements that the user physically includes, such as mobile devices, smart cards, or hardware tokens that have been pre-configured for the system. For example, when you start a new job, one of the first things you must do is set up IT system access. You will often be asked to scan a [QR code](https://www.adobe.com/express/feature/image/qr-code-generator) and then authenticate a sequence of numbers displayed on your MFA devices. Most likely, this will be your cell phone. Upon entering a password, the user will receive a push notification on their mobile device, requiring them to approve the login attempt. Security tokens and physical tokens are other common possession factors. These devices generate one-time passwords or personal identification numbers that the user must enter during authentication. By leveraging something the user possesses, it becomes exceedingly difficult for unauthorized users to gain access, as they would need physical possession of the device or token. ## Three Main Types of Authentication Factors Multi-factor authentication revolves around three primary types of authentication factors: knowledge factors, possession factors, and inherence factors. Understanding these concepts will give you a good grasp of the available MFA authentication methods. ### Knowledge Factors (something you know): Knowledge factors are pivotal as they encompass information exclusively known to the user, instantly creating a security layer to safeguard sensitive data and online assets. These factors are typically something the user knows intimately, such as passwords, personal identification numbers (PINs), or answers to security questions. ### Possession Factors (something you have): As discussed earlier, these are items that the user possesses, ranging from mobile devices to security keys and hardware tokens. These factors add an extra layer of security by requiring physical possession of a device or token. The cell phone is arguably the most commonly used device, with security tokens being reserved for specialist security needs such as getting root access to a cloud account/organization. ### Inherence Factors (something you are): These involve unique biological characteristics of the user, such as fingerprints, voice recognition, or facial recognition. Biometric authentication is becoming increasingly popular because it provides secure and quick authentication based on the user’s unique biological traits. ## How Does Multi-Factor Authentication Work? This section delves deeper into the intricacies of how multi-factor authentication works. The process begins with the user initiating a login attempt, where they must provide multiple verification forms. This could involve entering a password (knowledge factor), followed by a one-time code sent to their mobile phone (possession factor), and possibly a biometric scan (inherence factor). Adaptive multi-factor authentication takes this a step further by incorporating risk-based authentication. This method assesses the risk level of a login attempt based on various parameters such as the location of the attempt, the device used, and the user’s behavior patterns. Depending on the assessed risk, the system might require additional factors to ensure the legitimacy of the attempt. By integrating multiple layers of verification, MFA creates a robust security framework that effectively restricts access to only authorized users, safeguarding sensitive information and digital assets from unauthorized access. ## Other Types of Multi-Factor Authentication Apart from the commonly known types, other forms of multi-factor authentication are gaining traction in the security landscape. These include methods such as: ### SMS-Based Authentication: This type of MFA is used extensively with Online retailers and websites that need you to prove who you are. The users receive a one-time password (OTP) via SMS on their mobile phones; you insert this time-sensitive value when prompted, typically straight after inputting the correct username and password. ### Smart Cards: A physical token that stores user identities and grants access when inserted into a reader. You may have seen this in the workplace: employees are given a security pass with a chip embedded in many large organizations. This chip is programmed with authentication that can open doors, unlock laptops, etc. ### Security Keys: Hardware devices authorize access through USB, NFC, or Bluetooth connections. These are typically heavily encrypted devices that give superusers access to core systems. System engineers require such keys when working on sensitive systems such as military, financial, and healthcare-related platforms. ### Proprietary Software: Software solutions that integrate with business rules to create a customized MFA solution. Larger organizations may need to control their MFA authentication methods at source; as a result, custom servers are built in-house, typically with a token authentication factor. A popular example is [RSA authentication](https://www.turbogeek.co.uk/how-to-install-rsa-authentication-in-linux/). As you can tell, various multi-factor authentication examples offer diverse ways to secure user accounts, each adding a unique layer of security to the authentication process. ## How MFA Protects User’s Identity It’s obvious to see the importance of MFA. If you have yet to secure your business with MFA, here are some compelling reasons to start [this process today](https://www.atlantic.net/managed-services/multi-factor-authentication/). ### Enhanced Security: The primary purpose of MFA is to bolster security. By requiring multiple forms of verification, MFA makes it more difficult for unauthorized users to gain access to an account, as they would need to bypass several layers of security. ### Mitigation of Phishing Attacks: Even if a user’s password is compromised through phishing, the attacker still needs to bypass additional authentication steps, significantly reducing the chance of successful phishing attacks. ### Protection Against Credential Stuffing: In cases where usernames and passwords are stolen, MFA is an additional barrier, preventing attackers from gaining access using just the stolen credentials. Dictionary attacks are much more successful if a form of MFA is enabled. Hackers can spam your endpoint with bogus login requests. ### Dynamic Codes: Tools like Google Authenticator, Authy, and Okta can generate active codes that are valid for a short period, making it difficult for attackers to use stolen codes at a later time because they expire rapidly. ### Real-Time Alerts: Through push notifications, users receive real-time alerts for login attempts, allowing them to approve or deny access instantly and be alerted to unauthorized access attempts. ### Reduced Reliance on Passwords: MFA minimizes the reliance on passwords alone for security, which historically has been a weak point in cybersecurity due to issues with weak passwords. ### Customizable Security Protocols: Organizations can tailor MFA systems to meet their specific security needs, allowing for a flexible and robust approach to securing user identities. ### Compliance with Regulatory Requirements: Many industries, such as healthcare, have regulations that require the use of MFA, helping to ensure that organizations adhere to best practices in protecting user data. ### Voice Recognition: This innovative method capitalizes on the unique patterns in a user’s voice to verify their identity. Analyzing vocal characteristics ensures that access is granted only when a verbal match is detected, adding a personalized touch to security protocols. These approaches can be utilized singularly or in various combinations to construct a robust multi-factor authentication system. By tailoring the system to meet specific security needs, organizations can ensure a fortified and resilient security infrastructure, safeguarding sensitive user information from potential breaches. ## Protect Remote Access to Company Resources Remote working has remained a common practice in the post-COVID era. This has resulted in countless businesses investing in their network and VPN systems to create secure access to company resources. Today, remote access to company resources has become a necessity. Implementing a multi-factor authentication system ensures that only authorized users can access sensitive company data, even from remote locations. This approach uses multiple authentication factors, including mobile apps and biometric data, to verify the user’s identity, thus maintaining the integrity and security of company resources. ### Adaptive Authentication or Risk-Based Authentication To bolster security, many businesses have introduced adaptive authentication to protect remote access to sensitive assets. This, also known as risk-based authentication, takes a dynamic approach to security. The MFA system assesses the risk level of each login attempt based on various parameters, such as the user’s location, time of access, and behavior patterns. Depending on the assessed risk, the system might require additional authentication factors, thus creating a flexible and responsive security framework that adapts to potential threats in real time. ### Always-On Approach The always-on approach to multi-factor authentication means that the system continually assesses and verifies the user’s identity, even after the initial login. This could involve periodic requests for additional factors, such as biometric verification or one-time passwords, to ensure the account remains secure. ### Identification Through Location and Time This authentication approach considers the login attempt’s geographical location and time as significant factors in the authentication process. Suppose a login attempt is made from an unusual place or at an odd hour. In that case, the system might trigger additional authentication requirements to verify the user’s identity, adding an extra layer of security sensitive to the login attempt’s context. ## What’s the Difference between MFA and Two-Factor Authentication (2FA)? While MFA involves using two or more authentication factors, 2FA is a subset of MFA that uses precisely two factors to verify the user’s identity. These factors can be any combination of knowledge, possession, or inherence factors. In contrast, MFA can involve two or more of these factors, potentially offering a higher level of security by incorporating a broader range of verification methods. ## How do MFA and Single Sign-On (SSO) Differ? While both MFA and Single Sign-On (SSO) aim to enhance security and streamline the login process, they differ significantly in their approaches. MFA focuses on verifying the user’s identity through multiple layers of authentication, whereas SSO allows users to access multiple accounts or services with a single set of credentials. SSO simplifies the login process but should ideally be used with MFA to bolster security, as it can be a potential vulnerability if a single set of credentials is compromised. ### Elevate Your Business Security with Atlantic.Net’s Managed Multi-Factor Authentication Service Atlantic.Net’s Multi-Factor Authentication (MFA) service ensures that users prove who they are in multiple ways before they can access your server environment. Our highly secure MFA service is great at stopping different kinds of online attacks, including phishing and account hijacking, providing an extra layer of security even if someone knows your password. But it’s not just about confirming the identity of each user. The service also checks the safety of each device trying to connect, blocking high-risk or outdated software. It works smoothly with many in-house and cloud apps, offering features like easy sign-up, secure logins, and tools to help you set and enforce your own access rules. The service will help you quickly spot and manage unsafe devices and software and even help prevent attacks by identifying risky users through a phishing simulator. With this service, you can set up stronger access rules, reduce weak spots, and protect your confidential data more effectively. You can choose from various verification methods to match your company’s needs, including SMS passcodes, phone callbacks, or one-time passcodes. Ready to boost your security? To find out more or to get started with Atlantic.Net’s Managed Multi-Factor Authentication Service, call an advisor at 866-618-DATA (3282), email [sales@atlantic.net](mailto:sales@atlantic.net), or fill out the form on [our contact page](https://www.atlantic.net/about-us/corporate-contact/). Let Atlantic.Net help you build a safer and more resilient business environment. --- # Disaster Recovery vs. Business Continuity > URL: https://www.atlantic.net/disaster-recovery/disaster-recovery-vs-business-continuity/ | Published: 2023-09-24 | Updated: 2024-09-11 | Author: Richard Bailey Understanding business continuity and disaster recovery is critical to safeguard an organization’s ability to maintain normal operations before, during, and after a disruptive event. Modern businesses are heavily invested in IT and cloud systems, which provide critical and essential business functions that are needed around the clock. Disaster Recovery and Business Continuity planning are essential business strategies designed to ensure the continuation of core business services during a disaster. Disaster Recovery focuses on the technical requirements to ensure services are fault tolerant. Business continuity ensures the business maintains trading and includes processes encompassing the business’s administrative and functional side. This article will dive into the world of disaster recovery and business continuity as we learn how the best businesses protect their existence with tried and tested disaster recovery plans. ## What Is Business Continuity and Disaster Recovery? Business continuity is a proactive strategy that ensures critical business functions and processes remain operational during and after a catastrophic event, such as natural disasters, power outages, or cyber-attacks. The goal is to minimize disruption and maintain business operations at an optimal level. A typical business continuity plan involves risk management strategies that focus on preventing data loss and facilitating the recovery of critical systems in the event of a disruption. Business continuity management is a comprehensive approach encompassing various aspects, including business impact analysis, which helps identify and mitigate potential business continuity risks. On the other hand, disaster recovery is a subset of business continuity focusing specifically on IT infrastructure and data protection. The disaster recovery process involves the implementation of policies and procedures to enable the recovery or continuation of vital technology infrastructure and systems following a disaster. A proper disaster recovery plan is essential to restore business processes with minimal downtime, ensuring data backups are utilized effectively to resume operations swiftly. Disaster recovery planning includes delineating recovery tasks and setting up emergency office locations to facilitate a quick return to normal business operations. ## What Are the Key Differences Between Business Continuity and Disaster Recovery? Though closely related, these two concepts have distinct roles to play in ensuring the seamless operation of business processes, especially in the face of unforeseen challenges. Let’s dissect the critical differences between these two vital components. Business continuity, a comprehensive strategy, is designed to ensure the uninterrupted functioning of critical business operations. It encompasses a broad spectrum of organizational facets, including *personnel management* and *supply chain stability*, aiming to mitigate risks and maintain business operations at a functional level during and after a disruptive event. On the other hand, disaster recovery is a specialized segment within business continuity, focusing primarily on restoring IT infrastructure and data post-disruption. This strategy is centered on minimizing downtime and data loss, with a detailed plan to recover essential IT systems and data swiftly and efficiently. It delineates a clear *recovery time objective*, outlining the acceptable periods for system downtime and data loss, ensuring a quick return to business operations. Business continuity involves a meticulous *risk management process*and business impact analysis during the planning phase. This process identifies potential risks and develops strategies to mitigate the adverse effects of business interruptions, fostering a resilient operational framework. In contrast, disaster recovery involves crafting a technical plan that outlines steps to restore critical IT systems and data, focusing on minimal downtime and ensuring data protection. The implementation of these strategies involves different teams within the organization. Business continuity requires a collaborative approach, with various departments working together to maintain business operations. It necessitates coordination and communication across other business sectors, including operations and human resources. Conversely, disaster recovery is spearheaded by the IT department, working closely with a specialized team to restore critical systems and ensure data recovery, focusing on technical expertise and IT resources. Regular testing is vital to both strategies, ensuring their effectiveness in real-time scenarios. Business continuity tests the organization’s readiness to handle a disruptive event, involving drills and simulations to evaluate the plan’s effectiveness. Meanwhile, disaster recovery focuses on technical drills to test the IT infrastructure’s resilience and the effectiveness of data backup solutions. ## What Is BCP in Disaster Recovery? Business Continuity Planning in disaster recovery is a blueprint that guides organizations in maintaining business operations and minimizing downtime during a disaster scenario. The strategies and protocols are designed to safeguard critical business processes and functions. A typical business continuity plan demonstrates how to resume operations swiftly, ensuring minimal disruption to business operations and facilitating a smooth transition back to normalcy. Within the broader framework of disaster recovery, BCP plays a pivotal role. It outlines the steps necessary to restore and maintain business operations, including recovering critical systems and data, while addressing other vital areas such as supply chain management, personnel coordination, and facility restoration. Engineers will need detailed blueprints that explain how to invoke DR, the order to bring systems online, and access to the required blueprints. Furthermore, BCP in disaster recovery involves establishing a team of specialists to implement the disaster recovery plan. This team works closely with business leaders and the IT department to coordinate recovery efforts, minimizing business interruption and restoring everyday operations as quickly as possible. ## What’s the Key Difference Between Business Resilience and Business Continuity? Business resilience focuses on building a robust framework that allows an organization to anticipate, respond to, and recover from disruptions, ensuring survival and an opportunity to thrive and grow. It involves crafting strategies that promote a resilient organizational culture, one that is capable of adapting to changing circumstances swiftly. It encompasses a broader spectrum, including financial stability, supply chain resilience, and developing a flexible business model that can withstand and adapt to changing market dynamics. Business resilience integrates continuity and disaster recovery plans into a comprehensive strategy focusing on long-term sustainability and growth. The scope and approach are critical differences between business resilience and business continuity. While business continuity is more about maintaining critical business operations during disruptions, business resilience takes a broader view, focusing on the organization’s ability to adapt and evolve in a changing environment. ## Why Are Business Continuity Planning and Disaster Recovery Planning Important? Business Continuity and Disaster Recovery (BCDR) are influential policies that impact many different types of modern businesses. Understanding what would happen to your business during a disaster is essential. Here are some of the critical ways BCDR can safeguard the future of your business: - **Lower financial risk:** Disruptions can lead to immediate and long-term financial repercussions that may cause customers to leave en masse during a severe outage. BCDR strategies reduce risk by ensuring rapid recovery of operations and minimizing the duration and cost of downtime. - **Guarding brand reputation and customer trust:** Brand reputation is invaluable in our connected and social media-driven society. BCDR is pivotal in upholding an organization’s image, demonstrating a commitment to service continuity and customer satisfaction. Customers are likely to remain loyal if they receive good service. - **Ensuring Legal and Regulatory Compliance:** Many sectors mandate strict disaster recovery and business continuity measures. For example, DR is a mandatory requirement of [HIPAA Compliance](https://www.atlantic.net/hipaa-compliant-hosting/). BCDR ensures adherence to these regulations, preventing potential legal complications and penalties. - **Enhancing Organizational Resilience:** Beyond recovery, BCDR promotes resilience, preparing organizations to adapt and evolve. This proactive approach strengthens the organization’s capacity to face and overcome future challenges. - **Facilitating Swift Recovery:** Time is critical when a disaster strikes, so a recovery time objective (RTO) is crucial. Disaster recovery planning needs to be capable of hitting the RTO targets with a suitable technical solution. The good news is that when you choose Cloud Computing DR services, the RTO margins drop considerably. - **Protecting Data and Intellectual Property:** Data integrity and protection are vital even during a disaster. BCDR strategies must prioritize data backup and protection, ensuring the integrity and security of critical information and intellectual assets. - **Promoting a Culture of Preparedness:** BCDR promotes a proactive culture within businesses; with regular training and DR tests, businesses can empower employees to handle any emergency. ## The Risks of Not Having Business Continuity and Disaster Recovery Plans There are so many risks that businesses expose themselves to when there is no business continuity and disaster recovery planning in place. Such risks threaten the company’s operational stability and can have far-reaching implications on the financial health and reputation of the business. In this section, we outline the possible challenges organizations may encounter without robust business continuity strategies and disaster recovery safeguards in place: **Normal Operations Halted**: If a disaster strikes, the lack of a business continuity plan can lead to a complete halt of business operations, causing significant business interruption and hampering the business operational flow. **Delayed Reaction:** In the absence of a disaster recovery plan, organizations may experience lag in addressing disruptions, which can amplify the adverse effects of the disaster. Delays are caused by not having the correct people working on the incident and no clear plan (runbooks) to resolve the issues. In the worst case scenarios, it could result in the business going under. **Increased Costs**: The absence of a disaster recovery strategy can result in escalating costs due to extended downtime and the need for emergency management measures. If your data center is destroyed by natural disasters, having no business continuity plan can be the key difference between business trading and making income. **Loss of Revenue**: Without business continuity management, organizations might experience a substantial loss of revenue due to business interruption and the inability to maintain business continuity. Effective business continuity plans and disaster planning can protect revenue streams, retain customers, and ensure business partners that key performance indicators are being met. **Client Trust**: A lack of proactive strategies to manage disruptions can erode client trust, especially if the business cannot maintain a semblance of everyday operations during a critical event. **Brand Image**: The absence of a disaster recovery strategy can tarnish the brand image, as it may indicate a lack of preparedness to manage crises effectively. **Non-compliance**: Organizations might face legal repercussions for not adhering to industry-specific regulations that mandate the implementation of business continuity and disaster recovery plans. Remember that fines and penalties can be incurred if your business cannot implement effective crisis management. **Penalties**: The lack of adherence to risk management protocols and the absence of a risk identification process can result in hefty fines and sanctions. The HIPAA enforcement rule is one example; healthcare providers can be fined up to $50,000 per violation. **Data Vulnerability**: Without a disaster recovery plan, organizations are at a higher risk of data loss and security breaches, compromising sensitive information. Reviewing your business continuity plan with the disaster recovery team is essential to ensure your backup strategy is fit for purpose. Also, investigate technical DR solutions such as failover, virtual site recovery systems, etc. **IT Infrastructure**: The lack of a structured disaster recovery plan can put the IT infrastructure at risk, making it susceptible to unauthorized remote access and cyberattacks during data breaches. **Market Position**: The absence of business continuity focuses, and emergency response plans can result in a loss of competitive advantage, as organizations might not be able to resume business running swiftly post-disruption. **Innovation Stagnation**: Without contingency planning, organizations might find it challenging to innovate and grow, as resources might be diverted to manage the aftermath of disruptions. ## How to Identify Business Continuity Risks This process is integral to disaster recovery planning, ensuring that organizations are well-prepared to mitigate the impacts of disruptions and maintain operational stability. Here, we detail a systematic approach to identifying business continuity risks: **Understanding Critical Functions**: Begin by identifying the critical functions within your organization. Analyze how disruptions affect these functions and the potential consequences on business continuity. Conduct risk assessments, implement regular audits, and develop contingency plans to mitigate potential disruptions. **Data Gathering**: Collect data from various departments to understand the potential impact of disruptions on different facets of business operations. To effectively gather data, [consider utilizing surveys or questionnaires](https://heysurvey.io/), conducting interviews with department heads, analyzing existing reports, and leveraging technology to monitor and record real-time data. **Identifying Potential Threats**: List potential threats such as natural disasters, cybersecurity breaches, and other disaster scenarios. Understand how these threats can impact business continuity. **Vulnerability Assessment**: Evaluate the vulnerabilities in your current system, including gaps in disaster recovery strategy and the IT infrastructure. To conduct a comprehensive risk assessment, scrutinize elements like network security protocols, data encryption methods, firewall configurations, backup solutions, and server and storage system resilience. **Developing Mitigation Strategies**: Based on the risk assessment, develop strategies to mitigate identified risks. This could involve enhancing disaster recovery processes or improving the business continuity plan. **Resource Allocation**: Allocate necessary resources for risk management, ensuring sufficient recovery systems are in place to handle potential disruptions. **Drafting the Plan**: Create comprehensive business continuity plans that outline the steps to restore regular operations during a disruption. **Integration with Disaster Recovery Plan**: Ensure that the business continuity plan is well-integrated with the disaster recovery plan, offering a cohesive approach to managing disruptions. **Regular Drills**: Conduct regular drills to test the effectiveness of business continuity plans and disaster recovery strategies. This helps in identifying areas for improvement and making necessary adjustments. **Continuous Improvement**: Adopt a culture of constant improvement, where feedback from drills is used to enhance business continuity management and disaster recovery planning. **Employee Training**: Train employees on the procedures outlined in the business continuity and disaster recovery plans, ensuring they are well-prepared to respond effectively during a crisis. **Creating Awareness**: Develop programs to create awareness about potential risks and the importance of business continuity planning among employees. Want to know more about Disaster Recovery Planning? [Check out this detailed guide.](https://www.atlantic.net/resources/documents/whitepapers/pdf/hipaa-disaster-recovery-atlantic-net-whitepaper.pdf) ## Why Communication Is a Critical Business Continuity Strategy Communication is vital in business continuity and disaster recovery planning, facilitating coordinated efforts and ensuring the seamless execution of recovery strategies. Here, we explore why communication is deemed critical during disaster situations: ### Coordination of Recovery Efforts - **Unified Response**: Effective communication ensures a suitable response to disaster situations, fostering collaboration between various departments and teams involved in disaster recovery planning. - **Efficient Execution of Disaster Recovery Plan**: Communication facilitates the efficient execution of the disaster recovery plan, ensuring that all teams are aligned and aware of their respective roles and responsibilities. ### Minimizing Panic and Confusion - **Clear Instructions**: During a disaster, clear and concise communication can help minimize panic and confusion, enabling employees to respond calmly and effectively. - **Guidance and Direction**: Clear guidance and direction through well-structured communication channels can help maintain order and structure, even when standard operations are disrupted. ### Informing Stakeholders - **Keeping Stakeholders Informed**: Communication plays a vital role in maintaining stakeholders, including employees, customers, and partners, informed about the situation and the steps being taken to restore business continuity. - **Maintaining Customer Trust**: Transparent communication with customers can help keep trust, as organizations can provide regular updates on the recovery process and measures to restore normal operations. ### Legal and Regulatory Compliance - **Adherence to Regulations**: In many industries, timely and accurate communication during disaster situations is mandated by regulations. Effective communication ensures compliance with these legal requirements, avoiding potential penalties. - **Documentation for Risk Management**: Proper documentation of communications during a disaster can be a vital tool in risk management, helping organizations analyze the response and make necessary improvements for future preparedness. ### Ensuring Swift Recovery - **Quick Decision Making**: Effective communication facilitates quick decision-making, enabling organizations to respond swiftly to evolving situations and implement the disaster recovery plan without delays. - **Resource Mobilization**: Communication aids in rapidly mobilizing resources, ensuring that the necessary assets are deployed promptly to restore business continuity. ### Enhancing Organizational Resilience - **Learning and Adaptation**: Post-disaster communication serves as a tool for learning and adaptation, helping organizations analyze the response and integrate lessons learned into business continuity planning for future resilience. - **Culture of Preparedness**: Regular communication about potential risks and preparedness measures fosters a culture of readiness within the organization, enhancing overall resilience. ## Disaster Recovery Services from Atlantic.Net With over three decades of experience, Atlantic.Net has the trusted expertise of a security-focused and highly redundant world-class hosting infrastructure, including the capability to failover critical systems to alternative locations during unforeseen disasters. Our Infrastructure is meticulously designed to the stringent requirements of SOC2 and SOC 3 Type 2, HIPAA, and HITECH compliance, offering a robust disaster recovery hosting solution that safeguards critical data. Leveraging the power of Veeam backup replication software, Atlantic.Net provides always-on protection for your infrastructure, monitored and managed by a dedicated team of experts. Atlantic.Net’s disaster recovery service is robust and flexible, offering private, public, and hybrid hosting solutions. We ensure top-level RTOs and RPOs, giving clients confidence in proven disaster recovery technology. Our facilities are built to withstand even the most severe natural disasters, including hurricanes and earthquakes, ensuring the safety and accessibility of your data at all times. To safeguard your business against unforeseen disasters and ensure smooth data recovery, [contact Atlantic.Net](https://www.atlantic.net/about-us/corporate-contact/) today. Our team is ready to assist you with fast compliance, 24x7x365 support, and a world-class data center infrastructure designed to meet your needs. Let Atlantic.Net be your trusted partner in securing a resilient and compliant business future. --- # How to Install Laravel Framework on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-laravel-framework-on-fedora/ | Published: 2023-09-26 | Updated: 2023-11-15 | Author: Hitesh Jethva Laravel is an open-source PHP web framework with expressive and elegant syntax. It is robust, easy to understand, and follows a model-view-controller design pattern. Laravel provides a set of tools and resources to build modern PHP applications. If you are looking for an open-source framework to create extensible PHP-based websites and web applications at scale, then Laravel is the best option for you. In this post, we will show you how to install Laravel on Fedora Linux. ## Step 1 – Install LEMP Server First, install the Nginx and MariaDB server using the following command. ``` dnf install nginx mariadb-server ``` Next, add the PHP Remi repository with the following command. ``` dnf install -y http://rpms.remirepo.net/fedora/remi-release-34.rpm dnf module install php:remi-8.1 ``` Then, install PHP with additional PHP extensions using the following command. ``` dnf install php php-cli php-common php-fpm php-spl php-hash php-ctype php-json php-mbstring php-gd php-curl php-mysqli php-xml php-gmp php-xmlrpc php-bcmath php-soap php-ldap unzip -y ``` Once all the packages are installed, start and enable Nginx, MariaDB, and PHP-FPM services. ``` systemctl start php-fpm nginx mariadb systemctl enable php-fpm nginx mariadb ``` Next, edit the PHP-FPM configuration file. ``` nano /etc/php-fpm.d/www.conf ``` Change the following lines. ``` listen.owner = nginx listen.group = nginx ``` Then, edit the PHP configuration file. ``` nano /etc/php.ini ``` Change the following values. ``` date.timezone = UTC cgi.fix_pathinfo=1 ``` Save and close the file, then restart the PHP-FPM service to reload the changes. ``` systemctl restart php-fpm ``` ## Step 2 – Install Laravel Before starting, you will need to install PHP Composer on your server. You can install it with the following command. ``` wget https://getcomposer.org/installer -O composer-installer.php php composer-installer.php --filename=composer --install-dir=/usr/local/bin ``` Next, change the directory to the Apache root and create a Laravel project with the following command. ``` cd /var/www/html composer create-project --prefer-dist laravel/laravel laravelsite ``` Once the Laravel is installed, you will see the following output. ``` > @php artisan vendor:publish --tag=laravel-assets --ansi --force INFO No publishable resources for tag [laravel-assets]. No security vulnerability advisories found > @php artisan key:generate --ansi INFO Application key set successfully. ``` Next, set proper permissions and ownership to the Laravel directory. ``` chown -R nginx:nginx /var/www/html/laravelsite/storage/ chown -R nginx:nginx /var/www/html/laravelsite/bootstrap/cache/ chmod -R 0777 /var/www/html/laravelsite/storage/ chmod -R 0775 /var/www/html/laravelsite/bootstrap/cache/ ``` ## Step 3 – Configure Nginx for Laravel Next, create an Nginx virtual host configuration file to host Laravel on the Internet. ``` nano /etc/nginx/conf.d/laravel.conf ``` Add the following lines: ``` server { listen 80; server_name laravel.yourdomain.com; root /var/www/html/laravelsite/public; index index.php; charset utf-8; gzip on; gzip_types text/css application/javascript text/javascript application/x-javascript image/svg+xml text/plain text/xsd text/xsl text/xml image/x-icon; location / { try_files $uri $uri/ /index.php?$query_string; } location ~ \.php { include fastcgi.conf; fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_pass unix:/run/php-fpm/www.sock; } location ~ /\.ht { deny all; } } ``` Save and close the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following lines after the line http {: ``` server_names_hash_bucket_size 64; ``` Save the file, then verify the Nginx configuration for any syntax error. ``` nginx -t ``` You should get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx and PHP-FPM services to apply the changes. ``` systemctl restart php-fpm systemctl restart nginx ``` ## Step 4 – Access Laravel Site Now, Laravel is installed with Nginx on your server. You can now access it using the URL **http://laravel.yourdomain.com.** You will see the Laravel page on the following screen. ![Laravel dashboard](https://www.atlantic.net/wp-content/uploads/2023/08/p1-14.png) ## Conclusion Congratulations! You have successfully installed the Laravel framework on Fedora Linux. You can now start developing your PHP-based web application using the Laravel framework. You can now deploy the Laravel application on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install AzuraCast Radio Management Suite on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-azuracast-radio-management-suite-on-fedora/ | Published: 2023-09-27 | Updated: 2024-06-01 | Author: Hitesh Jethva AzuraCast is an open-source and self-hosted web radio management suite that helps you to get a web radio station up and running in minutes. It offers a powerful and intuitive web interface where you can manage every aspect of your radio station. You can upload media, manage playlists, create local mount points and remote relays, and view analytics and reports via a web browser. It also offers an API to build your own players and interfaces. In this post, we will show you how to install AzuraCast radio management solutions on Fedora Linux. ## Step 1 – Add Docker Repo By default, the Docker package is not included in the Fedora default repo, so you will need to add the repo for Docker. You can add the Docker repo using the following command. ``` dnf -y install dnf-plugins-core dnf config-manager --add-repo https://download.docker.com/linux/fedora/docker-ce.repo ``` The above command will create a docker-ce.repo file in the Yum configuration directory. ## Step 2 – Install Docker and Docker Compose Once the Docker repo is added to the Yum repository, you can install both Docker and Docker compose packages with the following command. ``` dnf install docker-ce docker-ce-cli containerd.io docker-compose-plugin docker-compose -y ``` After installing both packages, start and enable the Docker service. ``` systemctl start docker systemctl enable docker ``` You can now verify the Docker version using the following command. ``` docker --version ``` Output: ``` Docker version 20.10.17, build 100c701 ``` ## Step 3 – Install AzureCast First, create a directory to store all configuration files. ``` mkdir -p /var/azuracast ``` Next, download the AzureCast installation script using the following command. ``` cd /var/azuracast curl -fsSL https://raw.githubusercontent.com/AzuraCast/AzuraCast/main/docker.sh > docker.sh ``` Next, set the executable permissions on the downloaded script. ``` chmod a+x docker.sh ``` Next, start the AzureCast installation with the following command. ``` ./docker.sh install ``` You will be asked several questions as shown below: ``` Checking installation requirements for AzuraCast... [PASS] Operating System: Linux [PASS] Architecture: x86_64 [PASS] Command Present: curl [PASS] Command Present: awk [PASS] User Permissions [PASS] Installation Directory [PASS] All requirements met! Docker is already installed! Continuing... Docker Compose v2 is already installed. Continuing... Your current release channel is 'Rolling Release'. Switch to 'Stable' release channel? [y/N] N ``` Type N and press the Enter key. You will be asked to select a language. ``` Select Language [English (Default)]: [en_US] English (Default) [cs_CZ] čeština [de_DE] Deutsch [es_ES] Español [fr_FR] Français [el_GR] ελληνικά [it_IT] Italiano [hu_HU] magyar [nl_NL] Nederlands [pl_PL] Polski [pt_PT] Português [pt_BR] Português do Brasil [ru_RU] Русский язык [sv_SE] Svenska [tr_TR] Türkçe [zh_CN] 簡化字 [ko_KR] 한국어 > ``` Just press the Enter key to choose the English language. You will see the following output. ``` AzuraCast Installer =================== Welcome to AzuraCast! Complete the initial server setup by answering a few questions. AzuraCast is currently configured to listen on the following ports: * HTTP Port: 80 * HTTPS Port: 443 * SFTP Port: 2022 * Radio Ports: 8000,8005,8006,8010,8015,8016,8020,8025,8026,8030,8035,8036,8040,8045,8046,8050,8055,8056,8060,8065,8066,8070,8075,8076,8090,8095,8096,8100,8105,8106,8110,8115,8116,8120,8125,8126,8130,8135,8136,8140,8145,8146,8150,8155,8156,8160,8165,8166,8170,8175,8176,8180,8185,8186,8190,8195,8196,8200,8205,8206,8210,8215,8216,8220,8225,8226,8230,8235,8236,8240,8245,8246,8250,8255,8256,8260,8265,8266,8270,8275,8276,8280,8285,8286,8290,8295,8296,8300,8305,8306,8310,8315,8316,8320,8325,8326,8330,8335,8336,8340,8345,8346,8350,8355,8356,8360,8365,8366,8370,8375,8376,8380,8385,8386,8390,8395,8396,8400,8405,8406,8410,8415,8416,8420,8425,8426,8430,8435,8436,8440,8445,8446,8450,8455,8456,8460,8465,8466,8470,8475,8476,8480,8485,8486,8490,8495,8496 Customize ports used for AzuraCast? (yes/no) [no]: > ``` Just press the Enter key to select default ports. ``` Enable Custom Code Plugins (yes/no) [no]: > ``` Press the Enter key to enable the default plugins. ``` Enable web-based Docker image updates (yes/no) [yes]: > ``` Press the Enter key to use the default option. Once the installation has been completed, you should see the following output. ``` [OK] AzuraCast installation complete! Visit http://192.168.10.10 to complete setup. [+] Running 2/2 ⠿ Container azuracast_updater Started 1.6s ⠿ Container azuracast Started 14.2s ``` ## Step 4 – Access AzureCast Web Interface Now, open your web browser and access the AzureCast web interface using the URL **http://your-server-ip.** You will see the account creation page. ![azurecast account creation](https://www.atlantic.net/wp-content/uploads/2023/08/p1-10.png) Define your account information and click on the **CREATE ACCOUNT**. You will see the Create Radio Station page. ![azurecast create radio station](https://www.atlantic.net/wp-content/uploads/2023/08/p2-10.png) Provide all required information and click on **CREATE AND CONTINUE**. You should see the “**Customize AzuraCast**” page. ![azurecast customize](https://www.atlantic.net/wp-content/uploads/2023/08/p3-9.png) Select your required options and click on **SAVE AND CONTINUE**. You should see the following page. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p4-6.png) You can now add your music files and start playing them via a web browser. ## Conclusion Congratulations! You have successfully installed the AzuraCast radio station management tool on Fedora Linux and can now start your own radio station with AzureCast. You can now test AzureCast on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Dollibar ERP on Fedora Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-dollibar-erp-on-fedora-linux/ | Published: 2023-09-28 | Updated: 2024-06-01 | Author: Hitesh Jethva Dolibarr is an open-source ERP/CRM platform that helps you manage your organization’s activity, including, contacts, suppliers, invoices, orders, stocks, and more. It is written in PHP and designed for small, medium, or large companies, foundations, and freelancers. If you are looking for an affordable and self-hosted CRM/ERP solution then Dolibarr is the best option for you. In this post, we will explain how to install the Dolibarr CRM/ERP on Fedora Linux. ## Step 1 – Install the LAMP Server First, you will need to install a LAMP server on your system. You can install all the LAMP components using the command given below. ``` dnf install httpd mariadb-server php php-zip php-mysqlnd php-fpm php-xml php-cli php-soap php-opcache php-iconv php-pear php-bcmath php-gd php-mbstring php-json php-devel php-intl unzip wget -y ``` After installing the LAMP server, start and enable the Apache, PHP-FPM, and MariaDB services with the following command. ``` systemctl start httpd mariadb php-fpm systemctl enable httpd mariadb php-fpm ``` Next, edit the PHP configuration file and change some default settings. ``` nano /etc/php.ini ``` Change the following values. ``` memory_limit = 512M upload_max_filesize = 150M max_execution_time = 360 date.timezone = UTC ``` Save and close the file when you are done. ## Step 2 – Create a Database for Dolibarr Next, log in to the MariaDB shell using the following command. ``` mysql ``` After the login, create a database and user for Dolibarr. ``` MariaDB [(none)]> CREATE DATABASE dolibarrdb; MariaDB [(none)]> CREATE USER dolibarr; ``` Next, grant all the privileges to the Dolibarr database. ``` MariaDB [(none)]> GRANT ALL PRIVILEGES ON dolibarrdb.* TO 'dolibarr'@'localhost' IDENTIFIED BY 'password'; ``` Then, flush the privileges and exit from MariaDB using the following command. ``` MariaDB [(none)]> FLUSH PRIVILEGES; MariaDB [(none)]> EXIT ``` ## Step 3 – Download Dolibarr First, download the latest version of Dolibarr from the source forge website. ``` wget https://sourceforge.net/projects/dolibarr/files/Dolibarr%20ERP-CRM/16.0.0/dolibarr-16.0.0.zip ``` Once the download is completed, unzip the downloaded file. ``` unzip dolibarr-16.0.0.zip ``` Next, move the extracted directory to the Apache root directory. ``` mv dolibarr-16.0.0 /var/www/html/dolibarr ``` Then, change the ownership and permissions of Dolibarr. ``` chown -R apache:apache /var/www/html/dolibarr/ chmod -R 775 /var/www/html/dolibarr/ ``` ## Step 4 – Configure Apache for Dolibarr Now, create an Apache virtual host configuration file for Dolibarr. ``` nano /etc/httpd/conf.d/dolibarr.conf ``` Add the following code. ``` ServerAdmin admin@example.com ServerName dolibarr.example.com DocumentRoot /var/www/html/dolibarr/htdocs Options +FollowSymlinks AllowOverride All Require all granted ErrorLog /var/log/httpd/dolibarr.example.com-error.log CustomLog /var/log/httpd/dolibarr.example.com-access.log combined ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart httpd ``` ## Step 5 – Access Dolibarr Web UI Now, open your web browser and access the Dolibarr web installer using the URL **http://dolibarr.example.com.** You will see the language selection page. ![dolibarr select language](https://www.atlantic.net/wp-content/uploads/2023/08/p1-9.png) Click on **Next** step. You will see the prerequisites check page. ![Dolibarr Prerequisites check page](https://www.atlantic.net/wp-content/uploads/2023/08/p2-9.png) Click on the **Start** button to start the installation. You will see the web and database configuration page. ![Dolibarr database configuration page](https://www.atlantic.net/wp-content/uploads/2023/08/p3-8.png) Define your website and database configurations and click on **Next** step. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p4-5.png) Click on **Next** step. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p5-5.png) Ignore all errors and click on **Next** step. You will see the user creation page. ![dolibarr user creation page](https://www.atlantic.net/wp-content/uploads/2023/08/p6-4.png) Click on **Next** step. Once the installation is finished, you will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2023/08/p7-3.png) Now, create an **install.lock** file to secure the installation. ``` touch /var/www/html/dolibarr/htdocs/install.lock ``` Then, click on **Go to Dolibarr**. You will see the Dolibarr login page. ![dolibarr login page](https://www.atlantic.net/wp-content/uploads/2023/08/p8-3.png) Provide your admin username and password and click on **LOGIN.** You will see the Dolibarr dashboard. ![dolibarr dashboard](https://www.atlantic.net/wp-content/uploads/2023/08/p9-4.png) ## Conclusion Congratulations! You have successfully installed Dolibarr on Fedora Linux. You can now explore the Dolibarr and start using it in your organization to manage all things centrally. Try to deploy Dolibarr ERP on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install HumHub Social Network Platform on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-humhub-social-network-platform-on-fedora/ | Published: 2023-09-29 | Updated: 2024-06-02 | Author: Hitesh Jethva HumHub is an open-source social network software designed to help businesses build private or public social spaces within their organization. It is customizable and offers additional modules to extend its functionality. It is written on top of the Yii PHP framework and uses MariaDB as a database backend. In this post, we will show you how to install HumHub social network on Fedora Linux. ## Step 1 – Install Apache, MariaDB, and PHP Before starting, you will need to install the Apache web server, MariaDB, and PHP on your server. You can install all the packages using the following command. ``` dnf install httpd mariadb-server php php-zip php-mysqlnd php-fpm php-xml php-cli php-soap php-opcache php-iconv php-pear php-bcmath php-gd php-mbstring php-json php-devel php-intl unzip wget -y ``` Next, start and enable the Apache, MariaDB, and PHP-FPM services with the following command. ``` systemctl start httpd mariadb php-fpm systemctl enable httpd mariadb php-fpm ``` ## Step 2 – Create a Database for HumHub HumHub uses MariaDB or MySQL as a database backend, so you will need to create a database for HumHub. First, log in to the MariaDB shell using the following command. ``` mysql ``` Once you are logged in, create a database and user with the following command. ``` CREATE DATABASE humhub; CREATE USER 'humhub'@'localhost' IDENTIFIED BY 'secure_password'; ``` Next, grant all privileges to the HumHub database. ``` GRANT ALL PRIVILEGES ON humhub.* TO 'humhub'@'localhost'; ``` Next, flush the privileges and exit from the MariaDB with the following command. ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install HumHub First, download the latest version of HumHub with the following command. ``` wget https://download.humhub.com/downloads/install/humhub-1.14.3.tar.gz ``` Once the download is completed, extract the downloaded file. ``` tar -xvzf humhub-1.14.3.tar.gz ``` Next, move the extracted directory to the Apache web root. ``` mv humhub-1.14.3 /var/www/html/humhub ``` Then, change the ownership and permissions of the HumHub directory. ``` chmod -R 777 /var/www/html/humhub/ chown -R apache:apache /var/www/html/humhub/ ``` ## Step 4 – Configure Apache for HumHub Next, create an Apache virtual host configuration file to host HumHub on the web. ``` nano /etc/httpd/conf.d/humhub.conf ``` Add the following configurations: ``` ServerAdmin admin@example.com ServerName humhub.example.com DocumentRoot /var/www/html/humhub/ Options -Indexes +FollowSymLinks AllowOverride All ErrorLog /var/log/httpd/humhub.example.com-error.log CustomLog /var/log/httpd/humhub.example.com-access.log combined ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart httpd ``` ## Step 5 – Access HumHub Dashboard Now, open your web browser and access the HumHub web interface using the URL **http://humhub.example.com.** You will see the HumHub welcome page. ![humhub welcome page](https://www.atlantic.net/wp-content/uploads/2023/08/a1.png) Click on **Next.** You will see the requirements check page. ![humhub requirement check](https://www.atlantic.net/wp-content/uploads/2023/08/a2.png) If everything is fine, click on **Next.** You will see the database configuration page. ![humhub database settings](https://www.atlantic.net/wp-content/uploads/2023/08/a3.png) Define your database configuration and click on **Next.** You will see the Scheduled Jobs page. ![humhub schedule job](https://www.atlantic.net/wp-content/uploads/2023/08/a4.png) Click on **Next.** You will see the Pretty URLs page. ![humhub pretty url page](https://www.atlantic.net/wp-content/uploads/2023/08/a5.png) Click on **Next.** You will see the following page. ![Humhub social network page](https://www.atlantic.net/wp-content/uploads/2023/08/a6.png) Define your social network name and click on **Next.** You will see the following page. ![a7](https://www.atlantic.net/wp-content/uploads/2023/08/a7.png) Select your preferred option and click on **Next.** You will see the security settings page. ![](https://www.atlantic.net/wp-content/uploads/2023/08/a8.png) Define your preferred settings and click on **Next.** You will see the Modules selection page. ![humhub module section](https://www.atlantic.net/wp-content/uploads/2023/08/a9.png) Select your required modules and click on **Next.** You will see the Account creation page. ![humhub account creation page](https://www.atlantic.net/wp-content/uploads/2023/08/a10.png) Define your account details and click on **Create Admin Account.** You will see the following page. ![humhub installation start](https://www.atlantic.net/wp-content/uploads/2023/08/a11.png) Click on **Next.** Once the HumHub setup is completed, you will see the following page. ![humhub installation finished](https://www.atlantic.net/wp-content/uploads/2023/08/a12.png) Click on **Sign in**. You will see the HumHub dashboard on the following screen. ![Humhub dashboard](https://www.atlantic.net/wp-content/uploads/2023/08/a13.png) ## Conclusion In this post, we showed you how to install HumHub on Fedora Linux. You can now deploy the HumHub social network in your school, college, or organization to build your own community. Try to deploy HumHub social network on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure Squid Proxy on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-squid-proxy-on-fedora/ | Published: 2023-09-30 | Updated: 2024-06-01 | Author: Hitesh Jethva Squid is a free, open-source, widely used proxy server for Linux and Unix operating systems. It acts as an intermediary between clients and servers for web objects accessed through HTTP and HTTPS. It is also used as a proxy caching server to improve web server speed by caching frequently requested pages. Squid also allows you to control web access via access control rules. In this post, we will show you how to install the Squid proxy server on Fedora Linux. ## Step 1 – Install Squid Proxy By default, the Squid package is included in the Fedora operating system. You can install it by simply running the following command. ``` dnf install squid -y ``` After installing the Squid proxy package, start and enable the Squid service to start it at system reboot. ``` systemctl start squid systemctl enable squid ``` By default, the Squid proxy listens on port 3128. You can verify it using the following command. ``` ss -antpl | grep -i squid ``` Output. ``` LISTEN 0 4096 *:3128 *:* users:(("squid",pid=65118,fd=13)) ``` ## Step 2 – Create a Squid User You will need to create a user for Squid if you want to control Internet access. First, install the Apache tools package with the following command. ``` dnf install httpd-tools -y ``` Next, create a password file and change its ownership. ``` touch /etc/squid/squid_passwd chown squid /etc/squid/squid_passwd ``` Next, create a Squid user and set a password with the following command. ``` htpasswd /etc/squid/squid_passwd client1 ``` Set your user’s password as shown below. ``` New password: Re-type new password: Adding password for user client1 ``` ## Step 3 – Configure Squid Proxy Server In this section, we will configure user-based authentication in Squid proxy so that only the Squid user can access the internet. Edit the Squid configuration file. ``` nano /etc/squid/squid.conf ``` Add the following lines at the top of the file: ``` auth_param basic program /usr/lib64/squid/basic_ncsa_auth /etc/squid/squid_passwd acl ncsa_users proxy_auth REQUIRED http_access allow ncsa_users ``` Save and close the file when you are done. Then, restart the Squid service to apply the changes. ``` systemctl restart squid ``` ## Step 4 – Verify Squid Proxy Server At this point, your Squid proxy server is installed and configured. Now you will need to define your proxy server on the client’s machine. First, open the Firefox web browser on the client machine and open the settings. You will see the following screen. ![fireforx settings](https://www.atlantic.net/wp-content/uploads/2023/08/p1-8.png) Scroll down the page and click on **Settings.** You will see the following screen. ![define proxy settings](https://www.atlantic.net/wp-content/uploads/2023/08/p2-8.png) Define your proxy server IP and port, and click on **OK** to save the changes. Now, open a new tab in your browser and access the **whatismyip.com** website. You will be asked to authenticate the Squid server. ![authenticate squid proxy](https://www.atlantic.net/wp-content/uploads/2023/08/p3-7.png) Provide your Squid username and password and click on **Sign in.** After the successful authentication, you will be able to access the website. ![whatismyipaddress page](https://www.atlantic.net/wp-content/uploads/2023/08/p4-4.png) ## Conclusion In this post, you learned how to install and configure the Squid proxy server on Fedora Linux. You can now hide your identity and control Internet access using the Squid proxy server. Try out Squid proxy on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Terraform on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-terraform-on-fedora/ | Published: 2023-10-01 | Updated: 2025-08-26 | Author: Hitesh Jethva Terraform is an infrastructure-as-code tool that allows you to provision and manage infrastructure in any cloud created by HashiCorp. It provides a rich interface for orchestrating single or multi-cloud deployments. Using Terraform, you can provision all the infrastructure components in code. If you are looking for a tool to manage infrastructure components, such as computing, storage, and networking resources, then Terraform is the best tool. This post will show you how to install Terraform on Fedora Linux. ## Step 1 – Install Terraform from Hashicorp Repo By default, the Terraform package is unavailable in the Fedora default repo, so you will need to install it from the HashiCorp repo. First, update the server and install the HashiCorp repo with the following commands. ``` dnf update -y ``` ``` dnf config-manager addrepo --from-repofile=https://rpm.releases.hashicorp.com/fedora/hashicorp.repo ``` Next, verify the added repo with the following command. ``` dnf repolist ``` You will see the following output. ``` repo id repo name fedora Fedora 34 - x86_64 fedora-cisco-openh264 Fedora 34 openh264 (From Cisco) - x86_64 fedora-modular Fedora Modular 34 - x86_64 hashicorp Hashicorp Stable - x86_64 updates Fedora 34 - x86_64 - Updates updates-modular Fedora Modular 34 - x86_64 - Updates ``` Next, install Terraform using the following command. ``` dnf install terraform -y ``` After the installation, verify the Terraform version with the following command. ``` terraform --version ``` Output: ``` Terraform v1.13.0 on linux_amd64 ``` ## Step 2 – Install Terraform Manually You can also install Terraform manually by downloading it from GitHub. Run the following command to download the latest version of Terraform. ``` TER_VER=`curl -s https://api.github.com/repos/hashicorp/terraform/releases/latest | grep tag_name | cut -d: -f2 | tr -d \"\,\v | awk '{$1=$1};1'` wget https://releases.hashicorp.com/terraform/${TER_VER}/terraform_${TER_VER}_linux_amd64.zip ``` Once the download is completed, unzip the downloaded file. ``` unzip terraform_${TER_VER}_linux_amd64.zip ``` Next, move the Terraform binary to the system location. ``` mv terraform /usr/bin/ ``` Next, verify the Terraform version using the following command. ``` terraform --version ``` You will see the Terraform version in the following output. ``` Terraform v1.5.7 on linux_amd64 ``` ## Step 3 – How to Use Terraform You can see all available options for Terraform using the following command. ``` terraform ``` You will see the following output. ``` Main commands: init Prepare your working directory for other commands validate Check whether the configuration is valid plan Show changes required by the current configuration apply Create or update infrastructure destroy Destroy previously-created infrastructure All other commands: console Try Terraform expressions at an interactive command prompt fmt Reformat your configuration in the standard style force-unlock Release a stuck lock on the current workspace get Install or upgrade remote Terraform modules graph Generate a Graphviz graph of the steps in an operation import Associate existing infrastructure with a Terraform resource login Obtain and save credentials for a remote host logout Remove locally-stored credentials for a remote host metadata Metadata related commands output Show output values from your root module providers Show the providers required for this configuration refresh Update the state to match remote systems show Show the current state or a saved plan state Advanced state management taint Mark a resource instance as not fully functional test Experimental support for module integration testing untaint Remove the 'tainted' state from a resource instance version Show the current Terraform version workspace Workspace management ``` Now, let’s create a new project and see how to use Terraform to manage infrastructure. ``` mkdir projects ``` Next, create a Terraform main configuration file inside the project directory. ``` cd projects nano main.tf ``` Add your cloud provider’s information as shown below. ``` provider "aws" { access_key = "" secret_key = "" region = "us-west-1" } ``` Save and close the file, then initialize a Terraform working directory using the following command. ``` terraform init ``` You will see the following output. ``` Initializing the backend... Initializing provider plugins... - Finding latest version of hashicorp/aws... - Installing hashicorp/aws v5.16.2... - Installed hashicorp/aws v5.16.2 (signed by HashiCorp) Terraform has created a lock file .terraform.lock.hcl to record the provider selections it made above. Include this file in your version control repository so that Terraform can guarantee to make the same selections by default when you run "terraform init" in the future. Terraform has been successfully initialized! You may now begin working with Terraform. Try running "terraform plan" to see any changes that are required for your infrastructure. All Terraform commands should now work. If you ever set or change modules or backend configuration for Terraform, rerun this command to reinitialize your working directory. If you forget, other commands will detect it and remind you to do so if necessary. ``` Next, generate an execution plan using the following command. ``` terraform plan ``` Output: ``` No changes. Your infrastructure matches the configuration. Terraform has compared your real infrastructure against your configuration and found no differences, so no changes are needed. ``` Now, run the following command to build your infrastructure. ``` terraform apply ``` Output: ``` No changes. Your infrastructure matches the configuration. Terraform has compared your real infrastructure against your configuration and found no differences, so no changes are needed. Apply complete! Resources: 0 added, 0 changed, 0 destroyed. ``` If you want to destroy your infrastructure, run the following command. ``` terraform destroy ``` ## Conclusion In this post, we explained different ways to install Terraform on Fedora Linux. We also showed you how to use Terraform to deploy and manage infrastructure. You can now deploy and use Terraform on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How To Install Sails.js Framework with Nginx on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-sails-js-framework-with-nginx-on-fedora/ | Published: 2023-10-02 | Updated: 2024-06-02 | Author: Hitesh Jethva Sails.js is an open-source MVC back-end web framework built on top of JavaScript runtime. It allows developers to create custom, enterprise-grade Node.js apps quickly. It offers a modern approach to building web applications with real-time features, such as a live chat option for smooth customer experiences. It also allows you to share your code between the server and the client. This post will show you how to install Sails.js with Nginx on Fedora Linux. ## Step 1 – Install Nodejs First, update the server and install the required dependencies using the following commands. ``` dnf update -y ``` ``` dnf install curl gcc-c++ make -y ``` Next, add the Nodesource repository using the following command. ``` curl -sL https://rpm.nodesource.com/setup_18.x | bash - ``` Next, install the Node.js package with the following command. ``` dnf install nodejs -y ``` You can now verify the Node.js installation using the following command. ``` node --version ``` Output: ``` v18.19.0 ``` ## Step 2 – Install Sailsjs Framework You can use the NPM command line tool to install the Sails.js easily, as shown below. ``` npm -g install sails ``` Once Sails.js is installed, you can verify its version with the following command. ``` sails --version ``` Output. ``` 1.5.8 ``` ## Step 3 – Create an Application with Sailsjs Sails.js provides an easier way to create an application via the command line terminal. Let’s make an application called sailsapp with the following command. ``` sails new sailsapp ``` You will be asked to choose a template for your application. ``` Choose a template for your new Sails app: 1. Web App · Extensible project with auth, login, & password recovery 2. Empty · An empty Sails app, yours to configure (type "?" for help, or to cancel) ? 2 ``` Type 2 and press the Enter key to create an application. ``` info: Installing dependencies... Press CTRL+C to cancel. (to skip this step in the future, use --fast) ------------------------------------------------------------ Cancelled `npm install`. New app was generated successfully, but some dependencies in node_modules/ are probably still incomplete or missing. Before you can lift this app, you'll need to cd in and run: rm -rf node_modules && npm install For more help, visit https://sailsjs.com/support. ``` Next, change the directory to your application directory and remove the node modules. ``` cd sailsapp rm -rf node_modules ``` Next, install all the required dependencies using the NPM command. ``` npm install ``` Finally, start your application with the following command. ``` sails lift ``` You will see the following output. ``` info: Starting app... info: info: .-..-. info: info: Sails <| .-..-. info: v1.5.8 |\ info: /|.\ info: / || \ info: ,' |' \ info: .-'.-==|/_--' info: `--'-------' info: __---___--___---___--___---___--___ info: ____---___--___---___--___---___--___-__ info: info: Server lifted in `/root/sailsapp` info: To shut down Sails, press + C at any time. info: Read more at https://sailsjs.com/support. debug: ------------------------------------------------------- debug: :: Wed Sep 13 2023 11:25:30 GMT-0400 (Eastern Daylight Time) debug: Environment : development debug: Port : 1337 debug: Local : http://localhost:1337 debug: ------------------------------------------------------- ``` Press the CTRL+C to stop the application. ## Step 4 – Create a Systemd Service File for Sailsjs Next, create a systemd service file to manage your application. ``` nano /lib/systemd/system/sails.service ``` Add the following configurations. ``` [Unit] After=network.target [Service] Type=simple User=root WorkingDirectory=/root/sailsapp ExecStart=/usr/bin/sails lift Restart=on-failure [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon. ``` systemctl daemon-reload ``` Next, start and enable the Sails.js service. ``` systemctl start sails systemctl enable sails ``` You can also verify the status of your Sails.js service using the following command. ``` systemctl status sails ``` Output: ``` ● sails.service Loaded: loaded (/usr/lib/systemd/system/sails.service; disabled; vendor preset: disabled) Active: active (running) since Wed 2023-09-13 11:26:03 EDT; 5s ago Main PID: 2499 (node) Tasks: 22 (limit: 4666) Memory: 162.4M CPU: 4.090s CGroup: /system.slice/sails.service ├─2499 node /usr/bin/sails lift └─2507 grunt Sep 13 11:26:05 fedora sails[2499]: info: Sep 13 11:26:05 fedora sails[2499]: info: Server lifted in `/root/sailsapp` Sep 13 11:26:05 fedora sails[2499]: info: To shut down Sails, press + C at any time. Sep 13 11:26:05 fedora sails[2499]: info: Read more at https://sailsjs.com/support. Sep 13 11:26:05 fedora sails[2499]: debug: ------------------------------------------------------- Sep 13 11:26:05 fedora sails[2499]: debug: :: Wed Sep 13 2023 11:26:05 GMT-0400 (Eastern Daylight Time) Sep 13 11:26:05 fedora sails[2499]: debug: Environment : development Sep 13 11:26:05 fedora sails[2499]: debug: Port : 1337 Sep 13 11:26:05 fedora sails[2499]: debug: Local : http://localhost:1337 Sep 13 11:26:05 fedora sails[2499]: debug: ------------------------------------------------------- ``` ## Step 5 – Configure Nginx as a Reverse Proxy for Sailsjs You must configure the Nginx as a reverse proxy to access your application from the remote machine. First, install the Nginx server. ``` dnf install nginx -y ``` Next, create an Nginx configuration file. ``` nano /etc/nginx/conf.d/sails.conf ``` Add the following configurations. ``` server { listen 80; server_name sails.example.com; location / { proxy_pass http://localhost:1337/; proxy_set_header Host $host; proxy_buffering off; } } ``` Save and close the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http{: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then verify the Nginx configuration. ``` nginx -t ``` You should get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, start and enable the Nginx service with the following command. ``` systemctl start nginx systemctl enable nginx ``` ## Step 6 – Access Sailsjs Application At this point, the Sails.js application is installed on your server. You can now access it using the URL **http://sails.example.com.** You will see the Sails.js default dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p1-3.png) ## Conclusion This tutorial explained installing and creating a Sails.js application on Fedora Linux. We also showed you how to configure the Nginx as a reverse proxy to access the application from the outside world. You can now try to deploy the Sails.js application on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Zabbix Monitoring Tool on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-zabbix-monitoring-tool-on-fedora/ | Published: 2023-10-03 | Updated: 2023-11-15 | Author: Hitesh Jethva Zabbix is an open-source monitoring solution that allows system administrators to monitor networks, servers, virtual machines, and cloud services via a web-based interface. It offers prebuilt official and community-developed templates for integrating with networks, applications, and endpoints and can automate some monitoring processes. Zabbix also offers automation capabilities such as packet loss rate, memory utilization, predictive bandwidth trends, and downtime trends. This post will show you how to install a Zabbix server on Fedora Linux. ## Step 1 – Install LAMP Server First, update the server, and install the Apache and MariaDB servers with the following commands. ``` dnf update -y ``` ``` dnf -y install httpd mariadb-server ``` Next, add the PHP remi repository and install the PHP 7.4 remi module. ``` dnf install -y http://rpms.remirepo.net/fedora/remi-release-34.rpm dnf module install php:remi-7.4 ``` Next, install PHP with other required extensions. ``` dnf install php php-fpm php-gd php-mysqlnd ``` Next, edit the PHP-FPM configuration file. ``` nano /etc/php-fpm.d/www.conf ``` Modify the following lines. ``` listen = /run/php-fpm/zabbix.sock listen.allowed_clients = 0.0.0.0 ``` Save and close the file, then create a new Zabbix file. ``` nano /etc/php-fpm.d/zabbix.conf ``` Define your date and time zone. ``` php_value[date.timezone] = UTC ``` Next, edit the PHP configuration file. ``` nano /etc/php.ini ``` Change the following values. ``` post_max_size = 16M max_execution_time = 300 max_input_time = 300 ``` Save the file, then enable Apache, MariaDB, and PHP-FPM services. ``` systemctl start httpd mariadb php-fpm systemctl enable httpd mariadb php-fpm ``` ## Step 2 – Create a Zabbix Database Next, you will need to create a database and user for Zabbix. First, connect to the MariaDB shell. ``` mysql ``` Once you are connected, create a database and user for Zabbix. ``` CREATE DATABASE zabbix CHARACTER SET utf8 COLLATE utf8_bin; CREATE USER 'zabbix'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the Zabbix database. ``` GRANT ALL PRIVILEGES ON zabbix.* TO 'zabbix'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB shell. ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install Zabbix Server The Zabbix server package is unavailable in the Fedora default repo by default, so you will need to install the Zabbix repo to your server. You can install it with the following command. ``` rpm -Uvh https://repo.zabbix.com/zabbix/5.5/rhel/8/x86_64/zabbix-release-5.5-1.el8.noarch.rpm ``` Next, install the Zabbix server with other packages. ``` dnf install zabbix-server-mysql zabbix-web-mysql zabbix-apache-conf zabbix-sql-scripts zabbix-selinux-policy zabbix-agent ``` Next, download the Zabbix source. ``` wget https://cdn.zabbix.com/zabbix/sources/stable/5.0/zabbix-5.0.37.tar.gz ``` Next, extract the downloaded file. ``` tar zxvf zabbix-5.0.37.tar.gz ``` Next, change the directory to the extracted directory: ``` cd zabbix-5.0.37/database/mysql/ ``` Next, import the database schema, images, and data with the following commands. ``` mysql -uzabbix -p zabbix < schema.sql mysql -uzabbix -p zabbix < images.sql mysql -uzabbix -p zabbix < data.sql ``` Next, edit the Zabbix configuration. ``` nano /etc/zabbix_server.conf ``` Change the following lines to define your database. ``` DBHost=localhost DBName=zabbix DBUser=zabbix DBPassword=password ``` Save and close the file, then restart all required services with the following command. ``` systemctl restart zabbix-server zabbix-agent httpd php-fpm systemctl enable zabbix-server zabbix-agent httpd php-fpm ``` ## Step 4 – Access Zabbix Web Installation Now, open your web browser and access the Zabbix web installation using the URL **http://your-server-ip/zabbix.** You will see the Zabbix welcome screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p1-4.png) Click on **Next step.** You will see the pre-requisites check screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p2-3.png) Click on **Next step.** You will see the database configuration screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p3-1.png) Define your database settings and click on **Next step.** You will see the Zabbix server details screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p4-1.png) Provide your Zabbix host, port, name, and click on **Next step.** You will see the installation summary screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p5-1.png) Click on **Next step.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p6.png) Click on **Download the configuration file** to download the zabbix.conf.php file to your local machine. Next, create a new directory in your server with the following command. ``` mkdir -p /usr/share/zabbix/etc/zabbix/web/ ``` Next, copy zabbix.conf.php file to /usr/share/zabbix/etc/zabbix/web/. Next, go back to the web installation screen and click on the **Finish** button. You will see the Zabbix login screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p9.png) Provide the default username and password as Admin / zabbix, then click the **Sign in** button. You will see the Zabbix dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p10.png) ## Conclusion In this post, we showed you how to install the Zabbix monitoring server on Fedora. You can now add your remote servers to the Zabbix and monitor them via the Zabbix web interface. You can now deploy the Zabbix monitoring server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Bagisto eCommerce on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-bagisto-ecommerce-on-fedora/ | Published: 2023-10-04 | Updated: 2024-06-01 | Author: Hitesh Jethva Bagisto is a free and open-source eCommerce platform used for managing multi-tenant businesses. It helps users track inventory, monitor stock levels, and handle orders from a web-based UI. It is built on Laravel and Vue.js, a progressive Javascript framework, and was designed to enable anyone to develop and scale an online business. It provides extensions to support mobile number login, Stripe payment gateway, dropshipping, point-of-sale, and other options to extend the functionality. This post will show you how to install the Bagisto eCommerce platform on Fedora Linux. ## Step 1 – Install Nginx, MariaDB, and PHP First, update the server and install the Nginx and MariaDB servers using the following commands. ``` dnf update -y ``` ``` dnf install nginx mariadb-server -y ``` Next, add the PHP remi repository. ``` dnf install -y http://rpms.remirepo.net/fedora/remi-release-34.rpm dnf module install php:remi-8.0 ``` Then, install PHP with other required extensions using the following command. ``` dnf install php php-bcmath php-common php-curl php-fpm php-gd php-mbstring php-mysqlnd php-soap php-xml php-xsl php-devel php-pear libsodium-devel yum --enablerepo=remi install php-intl php-sodium php-zip ``` Next, install **libsodium** library and add it to the PHP configuration file. ``` pecl install libsodium echo "extension=sodium.so" >> /etc/php.ini ``` Next, start and enable the Nginx, MariaDB, and PHP-FPM services. ``` systemctl start nginx mariadb php-fpm systemctl enable nginx mariadb php-fpm ``` ## Step 2 – Create a Database for Bagisto Bagisto uses MariaDB as a database backend, so you will need to create a database and user for Bagisto. First, log in to MariaDB with the following command. ``` mysql ``` Next, create a database and user for Bagisto. ``` CREATE DATABASE bagisto; GRANT ALL on bagisto.* to bagisto@localhost identified by 'password'; ``` Next, flush the privileges and exit from MariaDB with the following command. ``` FLUSH PRIVILEGES; \q; ``` ## Step 3 – Install Node.js and Composer You will also need to install the Node.js and Composer to your server. First, install the Node.js package with the following command. ``` dnf install nodejs npm -y ``` Next, install Composer using the following command. ``` curl -sS https://getcomposer.org/installer -o composer-setup.php php composer-setup.php --install-dir=/usr/local/bin --filename=composer ``` You can verify the Composer version with the following command. ``` composer -V ``` Output: ``` Composer version 2.6.2 2023-09-03 14:09:15 ``` ## Step 4 – Install Bagisto First, navigate to the Nginx web root directory. ``` cd /var/www/html ``` Next, install Bagisto using Composer. ``` composer create-project bagisto/bagisto ``` You will see the following output. ``` > Webkul\Core\Events\ComposerEvents::postCreateProject ____ _ _ | __ ) __ _ __ _(_)___| |_ ___ | _ \ / _` |/ _` | / __| __/ _ \ | |_) | (_| | (_| | \__ \ || (_) | |____/ \__,_|\__, |_|___/\__\___/ |___/ Welcome to the Bagisto project! Bagisto Community is an open-source e-commerce ecosystem which is built on top of Laravel and Vue.js. Made with 💖 by the Bagisto Team. Happy helping :) ``` Next, edit the Bagisto environment file. ``` nano bagisto/.env ``` Modify the following lines. ``` APP_URL=http://bagisto.example.com DB_DATABASE=bagisto DB_USERNAME=bagisto DB_PASSWORD=password DB_PREFIX=bgs_ ``` Save and close the file, then install the Bagisto with the following command. ``` cd bagisto php artisan bagisto:install ``` You will see the following output. ``` ----------------------------- Congratulations! The installation has been finished and you can now use Bagisto. Go to http://bagisto.example.com/admin and authenticate with: Email: admin@example.com Password: admin123 Cheers! ``` Note down the admin username and password from the above output. ## Step 5 – Configure Nginx for Bagisto Next, you must create a Nginx virtual host configuration file to serve Bagisto. ``` nano /etc/nginx/conf.d/bagisto.conf ``` Add the following configurations. ``` server { listen 80; server_name bagisto.example.com; root /var/www/html/bagisto/public; add_header X-Frame-Options "SAMEORIGIN"; add_header X-Content-Type-Options "nosniff"; index index.php; charset utf-8; location / { try_files $uri $uri/ /index.php?$query_string; } location = /favicon.ico { access_log off; log_not_found off; } location = /robots.txt { access_log off; log_not_found off; } error_page 404 /index.php; location ~ \.php$ { fastcgi_pass unix:/run/php-fpm/www.sock; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; include fastcgi_params; } location ~ /\.(?!well-known).* { deny all; } } ``` Save the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http{: ``` server_names_hash_bucket_size 64; ``` Save the file, then set permissions and ownership to the Bagisto directory. ``` chown -R nginx:nginx /var/www/html/bagisto chmod -R 777 /var/www/html/bagisto ``` Finally, restart the Nginx and PHP-FPM services. ``` systemctl restart nginx php-fpm ``` ## Step 6 – Access Bagisto Web Interface Now, open your web browser and access the Bagisto admin panel using the URL **http://bagisto.example.com/admin/.** You will see the Bagisto login screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p1-2.png) Provide your admin username and password and click on the **Sign in** button. You will see the Bagisto dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p2-2.png) ## Conclusion Congratulations! You have successfully installed Bagisto on Fedora Linux. You can now explore the Bagisto features and start managing your stocks and inventory from a central location. Try to deploy Bagisto on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install GitLab on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-gitlab-on-fedora/ | Published: 2023-10-05 | Updated: 2024-06-01 | Author: Hitesh Jethva GitLab is an open-source repository and collaborative software development platform for DevOps projects. It is a self-hosted platform that provides a set of tools for managing and collaborating on software development projects. GitLab has built-in CI/CD capabilities that allow developers to automate the build, test, and deployment process. It also provides a centralized container registry to store Docker images and containers. This post will show you how to install GitLab on Fedora Linux. ## Step 1 – Install Required Dependencies Before starting, you will need to install some required dependencies on your server. You can install them using the following command. ``` dnf update -y ``` ``` dnf -y install postfix curl ``` Next, start and enable the Postfix service with the following command. ``` systemctl start postfix systemctl enable postfix ``` ## Step 2 – Install GitLab CE The GitLab package is not available in the Fedora default repo by default, so you will need to create a repo for GitLab. ``` nano /etc/yum.repos.d/gitlab-ce.repo ``` Add the following lines. ``` [gitlab_gitlab-ce] name=gitlab_gitlab-ce baseurl=https://packages.gitlab.com/gitlab/gitlab-ce/el/8/$basearch repo_gpgcheck=1 gpgcheck=1 enabled=1 gpgkey=https://packages.gitlab.com/gitlab/gitlab-ce/gpgkey https://packages.gitlab.com/gitlab/gitlab-ce/gpgkey/gitlab-gitlab-ce-3D645A26AB9FBD22.pub.gpg sslverify=1 sslcacert=/etc/pki/tls/certs/ca-bundle.crt metadata_expire=300 [gitlab_gitlab-ce-source] name=gitlab_gitlab-ce-source baseurl=https://packages.gitlab.com/gitlab/gitlab-ce/el/8/SRPMS repo_gpgcheck=1 gpgcheck=1 enabled=1 gpgkey=https://packages.gitlab.com/gitlab/gitlab-ce/gpgkey https://packages.gitlab.com/gitlab/gitlab-ce/gpgkey/gitlab-gitlab-ce-3D645A26AB9FBD22.pub.gpg sslverify=1 sslcacert=/etc/pki/tls/certs/ca-bundle.crt metadata_expire=300 ``` Save and close the file, then install the GitLab CE with the following command. ``` dnf install -y gitlab-ce ``` ## Step 3 – Configure GitLab CE After installing GitLab CE, you will need to define your domain to access the GitLab dashboard. You can do it by editing the GitLab default configuration file. ``` nano /etc/gitlab/gitlab.rb ``` Change the following line. ``` external_url 'http://gitlab.example.com' ``` Save and close the file, then reconfigure the GitLab CE with the following command. ``` gitlab-ctl reconfigure ``` You will see the following output. ``` Running handlers: [2023-09-12T11:22:48-04:00] INFO: Running report handlers Running handlers complete [2023-09-12T11:22:48-04:00] INFO: Report handlers complete Infra Phase complete, 571/1587 resources updated in 05 minutes 13 seconds Notes: Default admin account has been configured with following details: Username: root Password: You didn't opt-in to print initial root password to STDOUT. Password stored to /etc/gitlab/initial_root_password. This file will be cleaned up in first reconfigure run after 24 hours. NOTE: Because these credentials might be present in your log files in plain text, it is highly recommended to reset the password following https://docs.gitlab.com/ee/security/reset_user_password.html#reset-your-root-password. gitlab Reconfigured! ``` You can check the status of GitLab CE with the following command. ``` gitlab-ctl status ``` You will see the following output. ``` run: gitaly: (pid 9832) 100s; run: log: (pid 8777) 361s run: gitlab-exporter: (pid 9890) 96s; run: log: (pid 9175) 191s run: gitlab-kas: (pid 9860) 97s; run: log: (pid 8956) 336s run: gitlab-workhorse: (pid 9869) 97s; run: log: (pid 9069) 217s run: logrotate: (pid 8700) 376s; run: log: (pid 8708) 375s run: nginx: (pid 9098) 213s; run: log: (pid 9110) 210s run: node-exporter: (pid 9878) 98s; run: log: (pid 9157) 200s run: postgres-exporter: (pid 9933) 94s; run: log: (pid 9348) 158s run: postgresql: (pid 8820) 349s; run: log: (pid 8835) 346s run: prometheus: (pid 9898) 97s; run: log: (pid 9221) 177s run: puma: (pid 9016) 231s; run: log: (pid 9025) 229s run: redis: (pid 8737) 371s; run: log: (pid 8746) 370s run: redis-exporter: (pid 9892) 97s; run: log: (pid 9197) 186s run: sidekiq: (pid 9034) 225s; run: log: (pid 9042) 224s ``` ## Step 4 – Access GitLab CE Before accessing the GitLab CE, you will need to retrieve the GitLab login password. You can retrieve it with the following command. ``` cat /etc/gitlab/initial_root_password ``` You will see your root password in the following output. ``` # WARNING: This value is valid only in the following conditions # 1. If provided manually (either via `GITLAB_ROOT_PASSWORD` environment variable or via `gitlab_rails['initial_root_password']` setting in `gitlab.rb`, it was provided before database was seeded for the first time (usually, the first reconfigure run). # 2. Password hasn't been changed manually, either via UI or via command line. # # If the password shown here doesn't work, you must reset the admin password following https://docs.gitlab.com/ee/security/reset_user_password.html#reset-your-root-password. Password: RDr2u50wloMV7CqnPpVFPN3WwxTBt03yFtscw/eOlvg= # NOTE: This file will be automatically deleted in the first reconfigure run after 24 hours. ``` Now, open your web browser and access the GitLab CE using the URL **http://gitlab.example.com.** You will see the GitLab login screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p1-1.png) Provide your username and password and click on the **Sign in** button. You will see the GitLab CE dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p2-1.png) ## Step 6 – Uninstall GitLab CE To remove GitLab CE from your server, first stop GitLab CE with the following command. ``` gitlab-ctl stop ``` Next, remove GitLab CE using the following command. ``` gitlab-ctl uninstall ``` Output. ``` Terminating processes running under application users. This will take a few seconds. Your config files have been backed up to /root/gitlab-cleanse-2023-09-12T11:28. ``` ## Conclusion This tutorial taught you how to install GitLab CE on Fedora Linux. You can now create your first project via the GitLab CE dashboard to automate the build, test, and deployment process. You can now try to deploy GitLab CE on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Mautic Marketing Software on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-mautic-marketing-software-on-fedora/ | Published: 2023-10-06 | Updated: 2024-06-01 | Author: Hitesh Jethva Mautic is an open-source marketing automation software solution that allows you to create a multi-channel marketing campaign for your business. It is community-developed and offers all required features for a marketing platform, including lead management, campaign management, contacts and emails, and responsive email creation. Mautic is simple to use and inexpensive when compared to other similar software. This post will show you how to install Matic marketing software on Fedora Linux. ## Step 1 – Install Apache, MariaDB, and PHP First, update your server, then install the Apache web server and MariaDB server using the following commands. ``` dnf update -y ``` ``` dnf install httpd mariadb-server -y ``` Next, start and enable both the Apache and MariaDB services. ``` systemctl start httpd mariadb systemctl enable httpd mariadb ``` Next, add the PHP Remi repository using the following command. ``` dnf install -y http://rpms.remirepo.net/fedora/remi-release-34.rpm dnf module install php:remi-8.0 -y ``` Next, install the PHP with other required extensions using the following command. ``` dnf install -y php php-gd php-bcmath php-zip php-mysqlnd php-cgi php-pear php-xml php-mcrypt php-openssl php-opcache php-apcu php-memcached php-xdebug php-json php-mbstring php-curl php-common php-pear git ``` Once all the packages are installed, you can proceed to the next step. ## Step 2 – Create a Database and User Next, you will need to create a database and user for Mautic. First, connect to the MariaDB with the following command. ``` mysql ``` Next, create a database and user for Mautic. ``` CREATE DATABASE mautic; CREATE USER 'mautic'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the Mautic database. ``` GRANT ALL PRIVILEGES ON mautic.* TO 'mautic'@'localhost' IDENTIFIED BY 'password'; ``` Then, flush the privileges to apply the changes. ``` FLUSH PRIVILEGES; ``` Next, define the global InnoDB format and SQL mode. ``` SET GLOBAL innodb_default_row_format=DYNAMIC; SET GLOBAL sql_mode=(SELECT REPLACE(@@sql_mode,'ONLY_FULL_GROUP_BY','')); ``` Finally, exit from the MariaDB shell. ``` EXIT; ``` ## Step 3 – Install Node.js and Composer First, install Composer using the following command. ``` wget https://getcomposer.org/installer -O composer-installer.php php composer-installer.php --filename=composer --install-dir=/usr/local/bin ``` Next, install Node.js and NPM using the following command. ``` dnf install -y nodejs npm ``` Once both packages are installed, you can proceed to the next step. ## Step 4 – Install Mautic First, navigate to the Apache root directory and download the latest version of Mautic from the Git repository. ``` cd /var/www/html git clone https://github.com/mautic/mautic.git ``` Next, change the directory to mautic and install the required dependencies using the following command. ``` cd mautic composer install --ignore-platform-req=ext-imap --ignore-platform-req=ext-zip ``` Next, set proper permission and ownership to the Mautic directory. ``` chown -R apache:apache /var/www/html/mautic chmod -R 775 /var/www/html/mautic ``` ## Step 5 – Configure Apache for Mautic Next, create an Apache virtual host configuration file for Mautic. ``` nano /etc/httpd/conf.d/mautic.conf ``` Add the following configuration. ``` ServerAdmin admin@example.com DocumentRoot /var/www/html/mautic/ ServerName mautic.example.com Options FollowSymLinks AllowOverride All Order allow,deny allow from all ErrorLog /var/log/httpd/mautic_error_log CustomLog /var/log/httpd/mautic_access_log common ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart httpd ``` ## Step 6 – Access Mautic Web UI Now, open your web browser and access the Mautic web installation wizard using the URL **http://mautic.example.com.** You will see the environment check page. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p1.png) Click on **Next Step**. You will see the database configuration page. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p2.png) Define your Mautic database settings and click on **Next Step**. You will see the admin user creation page. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p3.png) Define your admin username and password and click on **Next** **Step**. You will see the Mautic login page. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p4.png) Provide your admin username and password, and click on the **login** button. You will see the Mautic dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p5.png) ## Conclusion Congratulations! You have successfully installed the Mautic marketing automation platform on Fedora Linux. You can now implement Mautic in your organization and create your marketing campaign using Mautic web UI. You can now try to deploy Mautic on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Install Apache2, MariaDB and PHP (FAMP) Stack on FreeBSD > URL: https://www.atlantic.net/dedicated-server-hosting/install-apache2-mariadb-and-php-famp-stack-on-freebsd/ | Published: 2023-10-14 | Updated: 2024-06-04 | Author: Hitesh Jethva A FAMP stack is a collection of open-source software used to enable a server to host a website or web application written in PHP language. FAMP uses FreeBSD as the operating system, Apache as the Web server, MySQL as the database management system, and PHP as the object-oriented scripting language. ## Step 1 – Install Apache Web Server By default, the Apache package is included in the FreeBSD default repo, so you can easily install it using the pkg command. First, update all the packages using the following command. ``` pkg update ``` Next, install the Apache web server package with the following command. ``` pkg install apache24 ``` Once Apache is installed, you can enable it to start at system reboot. ``` sysrc apache24_enable="YES" ``` Next, start the Apache service using the below command. ``` service apache24 start ``` To check the Apache service status, run the following command. ``` service apache24 status ``` Output: ``` apache24 is running as pid 1494. ``` ## Step 2 – Install MariaDB Server By default, the MariaDB package is included in the default repository. You can search all available package versions using the following command. ``` pkg search mariadb ``` You will see the following list. ``` mariadb-connector-c-3.3.4 MariaDB database connector for C mariadb-connector-odbc-3.1.17 MariaDB database connector for odbc mariadb1011-client-10.11.5 Multithreaded SQL database (client) mariadb1011-server-10.11.5 Multithreaded SQL database (server) mariadb105-client-10.5.21 Multithreaded SQL database (client) mariadb105-server-10.5.21 Multithreaded SQL database (server) mariadb106-client-10.6.14 Multithreaded SQL database (client) mariadb106-server-10.6.14 Multithreaded SQL database (server) p5-DBD-MariaDB-1.21 MariaDB driver for the Perl5 Database Interface (DBI) ``` Next, install the MariaDB server and client package from the above list using the following command: ``` pkg install mariadb1011-server-10.11.5 mariadb1011-client-10.11.5 ``` Once both packages are installed, enable the MariaDB package to start at system reboot. ``` sysrc mysql_enable="yes" ``` Next, start the MariaDB service. ``` service mysql-server start ``` Next, run the mysql_secure_installation script to secure the installation. ``` /usr/local/bin/mysql_secure_installation ``` Answer all the questions as shown below: ``` Enter current password for root (enter for none): Switch to unix_socket authentication [Y/n] Y Change the root password? [Y/n] Y New password: Re-enter new password: Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y Reload privilege tables now? [Y/n] Y ``` Next, verify the MariaDB databases using the following command. ``` mysql -u root -p -e "show databases" ``` You will see all default databases in the following output. ``` +--------------------+ | Database | +--------------------+ | information_schema | | mysql | | performance_schema | | sys | +--------------------+ ``` ## Step 3 – Install PHP You can install PHP with other extensions using the following command: ``` pkg install php80 mod_php80 php80-mbstring php80-zlib php80-curl php80-gd php80-mysqli nano-7.2 ``` After installing PHP, you must create a PHP configuration file for the Apache web server. You can create it with the following command: ``` nano /usr/local/etc/apache24/Includes/php.conf ``` Add the following configurations: ``` DirectoryIndex index.php index.html SetHandler application/x-httpd-php SetHandler application/x-httpd-php-source ``` Save and close the file, then create a simple info.php file to test the web server. ``` nano /usr/local/www/apache24/data/info.php ``` Add the following code: ``` ``` Save and close the file, then restart the Apache service to apply the changes. ``` service apache24 restart ``` Now, open your web browser and access the info.php file using the URL **http://your-server-ip/info.php**. You will see the PHP information page. ![PHP test page](https://www.atlantic.net/wp-content/uploads/2023/10/p2.png) ## Conclusion This post showed you how to install Apache, MariaDB, and PHP (FAMP) stack on FreeBSD. Using this stack, you can deploy any web application easily on the internet. Try to deploy the FAMP stack on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install PostgreSQL on FreeBSD > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-postgresql-on-freebsd/ | Published: 2023-10-15 | Updated: 2024-06-01 | Author: Hitesh Jethva PostgreSQL is an open-source, high-performance database management system suitable for large databases. It is used as a data store for mobile, geospatial, web, and analytics applications. It is cross-platform, offers complex data types, and supports Java, Python, Perl, Ruby, Go, C, C#, and many more languages. It can handle complex workloads while maintaining data integrity and reliability. ## Step 1 – Install PostgreSQL By default, the PostgreSQL package is included in the FreeBSD official repository. You can search all available PostgreSQL packages using the following command. ``` pkg search postgresql ``` You will see the following list: ``` postgresql15-server-15.4 PostgreSQL is the most advanced open-source database available anywhere postgresql15-tds_fdw-2.0.3 PostgreSQL foreign data wrapper to connect to TDS databases postgresql15-zhparser-2.2 PostgreSQL extension for full-text search of Chinese postgresql16-client-16.0 PostgreSQL database (client) postgresql16-contrib-16.0 The contrib utilities from the PostgreSQL distribution postgresql16-docs-16.0 The PostgreSQL documentation set postgresql16-plperl-16.0 Write SQL functions for PostgreSQL using Perl5 postgresql16-plpython-16.0 Module for using Python to write SQL functions postgresql16-pltcl-16.0 Module for using Tcl to write SQL functions postgresql16-server-16.0 PostgreSQL is the most advanced open-source database available anywhere prometheus-postgresql-adapter-0.6.0_14 Use PostgreSQL as a remote storage database for Prometheus py39-postgresql-1.3.0 Python 3 compatible PostgreSQL database driver and tools rubygem-azure_mgmt_postgresql-0.17.2 Microsoft Azure PostgreSQL Client Library for Ruby ``` Now, install the PostgreSQL server and client package using the following command: ``` pkg install postgresql16-server postgresql16-client nano-7.2 ``` Once both packages are installed, enable the PostgreSQL service to start at system reboot. ``` sysrc postgresql_enable=yes ``` Next, initialize the PostgreSQL database with the following command: ``` /usr/local/etc/rc.d/postgresql initdb ``` Output: ``` creating directory /var/db/postgres/data16 ... ok creating subdirectories ... ok selecting dynamic shared memory implementation ... posix selecting default max_connections ... 100 selecting default shared_buffers ... 128MB selecting default time zone ... UTC creating configuration files ... ok running bootstrap script ... ok performing post-bootstrap initialization ... ok syncing data to disk ... ok ``` Next, start the PostgreSQL service. ``` service postgresql start ``` You can verify the PostgreSQL service status using the following command: ``` service postgresql status ``` By default, PostgreSQL listens on port 5432. You can check it with the following command: ``` sockstat -l4 -P tcp ``` Output: ``` USER COMMAND PID FD PROTO LOCAL ADDRESS FOREIGN ADDRESS postgres postgres 2870 7 tcp4 127.0.0.1:5432 *:* ``` ## Step 2 – Configure PostgreSQL Authentication By default, PostgreSQL supports different authentication methods such as md5, RADIUS, PAM, LDAP, and more. In this section, we will set up the password-based authentication using MD5. First, edit the PostgreSQL configuration file. ``` nano /var/db/postgres/data16/pg_hba.conf ``` Find and change the following lines from trust to md5: ``` # TYPE DATABASE USER ADDRESS METHOD # "local" is for Unix domain socket connections only local all all trust # IPv4 local connections: host all all 127.0.0.1/32 md5 # IPv6 local connections: host all all ::1/128 md5 ``` Save and close the file, then restart the PostgreSQL service to apply the changes. ``` service postgresql restart ``` ## Step 3 – Create a User and Database in PostgreSQL First, connect to the Postgres with the following command: ``` su - postgres psql ``` Next, set the password for the default postgres user. ``` \password postgres ``` Next, create a new database named testdb and a user named testuser. ``` create database testdb; create user testuser with encrypted password 'password'; ``` Next, grant all the privileges on testdb database to testuser. ``` grant all privileges on database testdb to testuser; ``` Next, verify your created users using the following command: ``` \du ``` Output: ``` List of roles Role name | Attributes -----------+------------------------------------------------------------ postgres | Superuser, Create role, Create DB, Replication, Bypass RLS testuser | ``` Next, create a table named mytable with the following command: ``` create table mytable (id int, name text, site text); ``` Next, insert some data into the table. ``` insert into mytable (id,name,site) values (1,'myserver','atlantic.net'); ``` Next, retrieve the data from your table. ``` select * from mytable; ``` Output: ``` id | name | site ----+----------+-------------- 1 | myserver | atlantic.net (1 row) ``` You can now exit from the PostgreSQL shell with the following command. ``` \q ``` ## Conclusion In this post, we explained how to install PostgreSQL on FreeBSD. We also showed you how to create a database, user, and table in PostgreSQL. You can now easily use PostgreSQL as a database backend for your application. Try deploying a PostgreSQL server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Manage Packages with pkg Binary Package Manager on FreeBSD > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-manage-packages-with-pkg-binary-package-manager-on-freebsd/ | Published: 2023-10-16 | Updated: 2024-06-02 | Author: Hitesh Jethva Package manager is a collection of software tools used to install, remove upgrade, and manage programs in a computer system. Package management is an essential skill when working in a command-line interface. FreeBSD provides a pkg package manager to install and manage different packages via the command line. ## Step 1 – Getting Help Information Before working with a pkg package manager, we will show you how to use the pkg command with the help flag to find all sub-commands. To see all available options of the pkg command, run the following command: ``` pkg help ``` You will see all supported sub-commands in the following output: ``` Commands supported: add Compatibility interface to install a package alias List the command line aliases annotate Add, modify or delete tag-value style annotations on packages audit Reports vulnerable packages autoremove Removes orphan packages check Checks for missing dependencies and database consistency clean Cleans old packages from the cache config Display the value of the configuration options create Creates software package distributions delete Deletes packages from the database and the system fetch Fetches packages from a remote repository help Displays help information info Displays information about installed packages install Installs packages from remote package repositories and local archives lock Locks package against modifications or deletion plugins Manages plugins and displays information about plugins query Queries information about installed packages register Registers a package into the local database remove Deletes packages from the database and the system repo Creates a package repository catalogue rquery Queries information in repository catalogues search Performs a search of package repository catalogues set Modifies information about packages in the local database ssh Package server (to be used via ssh) shell Opens a debug shell shlib Displays which packages link against a specific shared library stats Displays package database statistics triggers Execute deferred triggers unlock Unlocks a package, allowing modification or deletion update Updates package repository catalogues updating Displays UPDATING information for a package upgrade Performs upgrades of packaged software distributions version Displays the versions of installed packages which Displays which package installed a specific file ``` If you want to see the help information of any sub-command, run the following command: ``` pkg help search ``` You will see how to use the pkg command with the search sub-command: ``` NAME pkg search – search package repository catalogues SYNOPSIS pkg search [-U] [-r reponame] [-S search] [-L label] [-Q query-modifier] [-Cegix] pattern pkg search [-cDdfopqRsU] [-r reponame] [-Cegix] pattern pkg search [--no-repo-update] [--repository reponame] [--search search] [--label label] [--query-modifier query-modifier] [--{case-sensitive,exact,glob,case-insensitive,regex}] pattern pkg search [--{comment,description,depends-on,full,origins,prefix}] [--{quiet,raw,size,no-repo-update}] [--repository reponame] [--{case-sensitive,exact,glob,case-insensitive,regex}] [--raw-format format] pattern ``` To see the help information about the install sub-command, run the following command: ``` pkg help install ``` You will see the following command: ``` NAME pkg install – install packages from remote package repositories or local archives SYNOPSIS pkg install [-AfIMnFqRUy] [-r reponame] [-Cgix] ... pkg install [--{automatic,force,no-scripts,ignore-missing}] [--{dry-run,fetch-only,quiet,recursive,no-repo-update,yes}] [--repository reponame] [--{case-sensitive,glob,case-insensitive,regex}] ... ``` ## Step 2 – Search Packages Using pkg Command The basic syntax to search a package is shown below. ``` pkg search package-name ``` For example, to search for Nginx packages, run the following command: ``` pkg search nginx ``` You will see all Nginx packages in the following output: ``` nginx-1.24.0_12,3 Robust and small WWW server nginx-devel-1.25.2_7 Robust and small WWW server nginx-lite-1.24.0,3 Robust and small WWW server (lite package) nginx-naxsi-1.24.0,3 Robust and small WWW server (plus NAXSI) nginx-prometheus-exporter-0.11.0_2 Prometheus exporter for NGINX and NGINX Plus stats nginx-ultimate-bad-bot-blocker-4.2020.03.2005_1 Nginx bad bot and other things blocker nginx-vts-exporter-0.10.7_14 Server that scraps NGINX vts stats and export them via HTTP p5-Nginx-ReadBody-0.07_1 Nginx embeded perl module to read and evaluate a request body p5-Nginx-Simple-0.07_1 Perl 5 module for easy to use interface for Nginx Perl Module p5-Test-Nginx-0.30 Testing modules for Nginx C module development py39-certbot-nginx-2.6.0 NGINX plugin for Certbot ``` To see the information about a specific package, use the -f flag followed by the package name. ``` pkg search -f nginx-1.24.0_12,3 ``` You will see the following output: ``` nginx-1.24.0_12,3 Name : nginx Version : 1.24.0_12,3 Origin : www/nginx Architecture : FreeBSD:13:amd64 Prefix : /usr/local Repository : FreeBSD [pkg+http://pkg.FreeBSD.org/FreeBSD:13:amd64/quarterly] Categories : www Licenses : BSD2CLAUSE Maintainer : joneum@FreeBSD.org WWW : https://nginx.com/ Comment : Robust and small WWW server ``` ## Step 3 – Install Packages Using pkg Command The basic syntax to install a package is shown below. ``` pkg install package-name ``` For example, to install an Nginx package, run the following command: ``` pkg install nginx ``` If you want to download the package without installing it on your system, run the following command: ``` pkg fetch nginx ``` To download the package with all of its dependencies use the -d flag. ``` pkg fetch -d nginx ``` You can see all fetched packages in the /var/cache/pkg directory. ``` ls /var/cache/pkg ``` Output: ``` brotli-1.1.0,1.pkg indexinfo-0.3.1~bd05368104.txz nettle-3.9.1.pkg brotli-1.1.0,1~2e5f90142a.pkg libassuan-2.5.6.pkg nettle-3.9.1~6bc5253893.pkg e2fsprogs-1.46.2.txz libassuan-2.5.6~7b204af578.pkg nginx-1.24.0_12,3.pkg e2fsprogs-1.46.2~a2abff02bc.txz libedit-3.1.20221030,1.pkg nginx-1.24.0_12,3~af8e35c324.pkg e2fsprogs-1.46.2~b1851d3194.txz libedit-3.1.20221030,1~02edf68058.pkg npth-1.6.pkg e2fsprogs-1.47.0.pkg libffi-3.4.4.pkg npth-1.6~55fe55fef2.pkg e2fsprogs-1.47.0~196e9c9c54.pkg libffi-3.4.4~3c80f31254.pkg p11-kit-0.24.1_2.pkg e2fsprogs-core-1.47.0.pkg libgcrypt-1.10.2.pkg p11-kit-0.24.1_2~d841595c85.pkg e2fsprogs-core-1.47.0~584e640d80.pkg libgcrypt-1.10.2~4ef2ab992e.pkg pcre2-10.42.pkg e2fsprogs-libblkid-1.46.2.txz libgpg-error-1.47.pkg pcre2-10.42~0252e988c3.pkg e2fsprogs-libblkid-1.46.2~11342cdd9e.txz libgpg-error-1.47~a11cc8f9f8.pkg perl5-5.34.1_3.pkg e2fsprogs-libblkid-1.46.2~d0aac929ad.txz libhsts-0.1.0.pkg perl5-5.34.1_3~be88f18f29.pkg ``` To remove packages from the cache directory, run the following command: ``` pkg clean ``` Output: ``` The following package files will be deleted: /var/cache/pkg/e2fsprogs-1.46.2~b1851d3194.txz /var/cache/pkg/gettext-runtime-0.21.txz /var/cache/pkg/e2fsprogs-1.46.2.txz /var/cache/pkg/e2fsprogs-libuuid-1.46.2~b78457aa6b.txz /var/cache/pkg/gettext-runtime-0.21~7f53ebc469.txz /var/cache/pkg/e2fsprogs-libuuid-1.46.2.txz /var/cache/pkg/e2fsprogs-libblkid-1.46.2~11342cdd9e.txz /var/cache/pkg/e2fsprogs-libblkid-1.46.2.txz /var/cache/pkg/indexinfo-0.3.1~bd05368104.txz /var/cache/pkg/indexinfo-0.3.1.txz /var/cache/pkg/e2fsprogs-libss-1.46.2~d0e44d1a51.txz /var/cache/pkg/indexinfo-0.3.1~75a19b3acb.txz /var/cache/pkg/e2fsprogs-libss-1.46.2.txz /var/cache/pkg/vim-tiny-8.2.2725~640683e659.txz /var/cache/pkg/vim-tiny-8.2.2725.txz /var/cache/pkg/vim-tiny-8.2.2725~a1de39a0a9.txz /var/cache/pkg/gettext-runtime-0.21~4f88146680.txz /var/cache/pkg/e2fsprogs-libuuid-1.46.2~b01e611407.txz /var/cache/pkg/e2fsprogs-libss-1.46.2~b2cac5e088.txz /var/cache/pkg/e2fsprogs-libblkid-1.46.2~d0aac929ad.txz /var/cache/pkg/e2fsprogs-1.46.2~a2abff02bc.txz The cleanup will free 5 MiB Proceed with cleaning the cache? [y/N]: y ``` To remove all cached packages, run the following command: ``` pkg clean -a ``` ## Step 4 – View Information About Installed Package The basic syntax to see the information about installed packages is shown below. ``` pkg info package-name ``` For example, to see the Nginx package information, run the following command: ``` pkg info nginx ``` You will see the following output: ``` nginx-1.24.0_12,3 Name : nginx Version : 1.24.0_12,3 Installed on : Sat Oct 14 08:53:08 2023 UTC Origin : www/nginx Architecture : FreeBSD:13:amd64 Prefix : /usr/local Categories : www Licenses : BSD2CLAUSE Maintainer : joneum@FreeBSD.org WWW : https://nginx.com/ Comment : Robust and small WWW server ``` ## Step 5 – Remove Packages Using pkg Command The basic syntax to remove a package is shown below. ``` pkg delete package-name ``` For example, to remove a package named nginx, run the following command: ``` pkg delete nginx ``` To remove additional dependencies that are installed with the package, run the following command: ``` pkg autoremove ``` ## Step 6 – Lock and Unlock Packages Using pkg Command Sometimes, you don’t want to upgrade a package on your server. In this case, you can lock that package so that pkg never upgrades it. To lock the Nginx package, run: ``` pkg lock nginx ``` To list all locked packages, run: ``` pkg lock -l ``` Output: ``` Currently locked packages: nginx-1.24.0_12,3 ``` To unlock an Nginx package, run: ``` pkg unlock nginx ``` To lock all packages, run: ``` pkg lock -a ``` To unlock all packages, run: ``` pkg unlock -a ``` ## Conclusion In this post, we showed you how to manage packages with the pkg command in FreeBSD. You can now easily install, remove, update, upgrade, and manage packages via the command line interface. Try to manage packages using the pkg command on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Configuring Basic HTTP Authentication with Nginx on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/configuring-basic-http-authentication-with-nginx-on-ubuntu-24-04/ | Published: 2023-10-17 | Updated: 2025-05-24 | Author: Hitesh Jethva Nginx is a popular free web server used to host a website or web application online. Sometimes you may need to protect some external sections that contain sensitive information on your website. In this case, you can implement password protection to secure your data. Nginx has the ability to secure web directories by setting up basic authentication. ## Step 1 – Install Nginx Web Server Before starting, Nginx must be installed on your server. If not installed, you can install it using the following command. ``` apt install nginx -y ``` Once Nginx is installed, start and enable the Nginx service. ``` systemctl start nginx systemctl enable nginx ``` ## Step 2 – Create a Password File Using OpenSSL To set up a basic authentication, you will need to create a password file to store username and password information. First, create a password file named .htpasswd and add a user called testuser. ``` sh -c "echo -n 'testuser:' >> /etc/nginx/.htpasswd" ``` Then, add a password for this user. ``` sh -c "openssl passwd -apr1 >> /etc/nginx/.htpasswd" ``` Set your user’s password as shown below. ``` Password: Verifying - Password: ``` You can now verify your username and encrypted password using the following command. ``` cat /etc/nginx/.htpasswd ``` Output: ``` testuser:$apr1$YyYXPvbO$JaXhAmiNPeapbbWano6gj. ``` ## Step 3 – Create a Password File Using Apache Utils You can also create a password file using the Apache Utils. In this method, you will need to install the apache2-utils package to your server. ``` apt install apache2-utils ``` Next, create a new user named newuser as shown below: ``` htpasswd /etc/nginx/.htpasswd newuser ``` Set a password for this user. ``` New password: Re-type new password: Adding password for user newuser ``` Next, verify your added user and password using the following command: ``` cat /etc/nginx/.htpasswd ``` Output: ``` testuser:$apr1$YyYXPvbO$JaXhAmiNPeapbbWano6gj. newuser:$apr1$du.hu6U1$JD8cjsbzPNv89NPBXaTRJ1 ``` ## Step 4 – Set Up Password Authentication in NGINX Next, you will need to add the password authentication directives to the NGINX configuration file for your website. ``` nano /etc/nginx/sites-enabled/default ``` Add the **auth_basic** and **auth_basic_user_file** directives to your existing configuration as shown below: ``` server { listen 80 default_server; listen [::]:80 default_server; root /var/www/html; index index.html; server_name _; location / { try_files $uri $uri/ =404; auth_basic "Basic Authentication"; auth_basic_user_file /etc/nginx/.htpasswd; } } ``` Save and close the file, then restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 5 – Verify the Password Authentication At this point, your Nginx website is protected with a password. You can now verify it using the URL **http://your-server-ip.** You will be asked to provide your username and password as shown below. ![Nginx login screen](https://www.atlantic.net/wp-content/uploads/2023/10/p1.png) Type your username and password and click on the **Sign In** button to access your website content. ## Conclusion In this post, you learned how to protect your web directory in Nginx with password authentication. Implementing password protection is essential to restrict access to sensitive content of your website. Try to set up a basic authentication with Nginx on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Deploying a Go Web Application Using Nginx on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/deploying-a-go-web-application-using-nginx-on-ubuntu-22-04/ | Published: 2023-10-18 | Updated: 2024-06-05 | Author: Hitesh Jethva Go is an open-source and general-purpose programming language developed by Google. It is cross-platform, lightweight, and simple to build with, making it an ideal choice for software developers. It produces compiled machine code binaries so you don’t need source code compilation to create an executable file. Go language syntax is very similar to C language and offers a rich set of features such as structural typing, garbage collection, memory safety, and more. ## Step 1 – Install Go Language By default, the Go package is included in the Ubuntu default repository. You can install it using the following command. ``` apt install golang-go -y ``` Once the Go package is installed, you can verify its version with the following command: ``` go version ``` Output: ``` go version go1.18.1 linux/amd64 ``` ## Step 2 – Create a Simple Go Application In this section, we will create a Go application that will print “Hello Go Application” when accessing the domain. First, create a project directory for your application. ``` mkdir project ``` Next, navigate to the project directory and initiate the project with the following command: ``` cd project go mod init go.example.com/app ``` Next, create a Go application file. ``` nano main.go ``` Add the following code: ``` package main import ( "fmt" "net/http" ) func main() { http.HandleFunc("/", func(w http.ResponseWriter, r *http.Request) { fmt.Fprintf(w, "Hello Go Application") }) http.HandleFunc("/greet/", func(w http.ResponseWriter, r *http.Request) { name:= r.URL.Path[len("/greet/"):] fmt.Fprintf(w, "Hello %s\n", name) }) http.ListenAndServe(":9990", nil) } ``` Save and close the file, then compile the file into the executable binary file. ``` go build main.go ``` You can see the executable binary file using the following command: ``` ls -l ``` Output: ``` total 6152 -rw-r--r-- 1 root root 35 Oct 15 15:43 go.mod -rwxr-xr-x 1 root root 6288896 Oct 15 15:44 main -rw-r--r-- 1 root root 408 Oct 15 15:44 main.go ``` ## Step 3 – Create a Systemd Service File for Your Application Next, you will need to create a systemd file to manage the Go application. ``` nano /lib/systemd/system/goweb.service ``` Add the following configurations: ``` [Unit] Description=goweb [Service] Type=simple Restart=always RestartSec=5s ExecStart=/root/project/main [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the Go service using the following command: ``` systemctl start goweb systemctl enable goweb ``` You can check the status of the Go service with the following command: ``` systemctl status goweb ``` Output: ``` ● goweb.service - goweb Loaded: loaded (/lib/systemd/system/goweb.service; disabled; vendor preset: enabled) Active: active (running) since Sun 2023-10-15 15:45:37 IST; 3s ago Main PID: 47830 (main) Tasks: 6 (limit: 9180) Memory: 1.1M CPU: 6ms CGroup: /system.slice/goweb.service └─47830 /root/project/main Oct 15 15:45:37 ubuntupc systemd[1]: Started goweb. ``` ## Step 4 – Configure Nginx as a Reverse Proxy Next, you will need to install and configure Nginx as a reverse proxy for the Go application. First, install the Nginx package with the following command: ``` apt install nginx ``` Next, create an Nginx virtual host configuration file. ``` nano /etc/nginx/conf.d/go.conf ``` Add the following configuration: ``` server { server_name go.example.com; location / { proxy_pass http://localhost:9990; } } ``` Save and close the file, then verify the Nginx for any syntax errors. ``` nginx -t ``` Output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Then, restart the Nginx service to reload the changes. ``` systemctl restart nginx ``` ## Step 5 – Access Go Application Now, open your web browser and access the Go application using the URL **http://go.example.com.** You will see the following screen. ![access go web page](https://www.atlantic.net/wp-content/uploads/2023/10/p1-1.png) You can also greet with a specific keyword using the URL **http://go.example.com:/greet/atlantic.** You will see the following screen. ![access Go greetings ](https://www.atlantic.net/wp-content/uploads/2023/10/p2-1.png) ## Conclusion In this post, we explained how to install Go and create a simple application on Ubuntu 22.04. We also configured the Nginx as a reverse proxy to access the application using the domain name. You can now deploy the Go application on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How To Install JFrog Artifactory on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-jfrog-artifactory-on-ubuntu-22-04/ | Published: 2023-10-19 | Updated: 2024-06-01 | Author: Hitesh Jethva JFrog Artifactory is a powerful open-source repository management software and DevOps solution used for managing and automating all software packages and artifacts during the application delivery process. JFrog Artifactory provides a central management portal from where you can host, store, and distribute all artifacts and binaries. It can be integrated easily with most CI/CD platforms with other DevOps tools. ## Step 1 – Install Java JDK JFrog is a Java-based software, so Java JDK must be installed on your server. If not installed, you can install it with the following command. ``` apt install -y default-jdk ``` Once Java JDK is installed, you can verify the Java version using the following command. ``` java -version ``` You will see the following output: ``` openjdk version "11.0.20.1" 2023-08-24 OpenJDK Runtime Environment (build 11.0.20.1+1-post-Ubuntu-0ubuntu122.04) OpenJDK 64-Bit Server VM (build 11.0.20.1+1-post-Ubuntu-0ubuntu122.04, mixed mode, sharing) ``` ## Step 2 – Install MariaDB Database JFrog uses MariaDB as a database backend, so you will need to install the latest MariaDB version on your server. First, add the MariaDB repository using the following command. ``` curl -LsS https://downloads.mariadb.com/MariaDB/mariadb_repo_setup | bash -s -- ``` Next, update the repository and install the MariaDB package with the following command. ``` apt update apt install mariadb-server mariadb-client -y ``` Once the installation is complete, start and enable the MariaDB service. ``` systemctl start mariadb systemctl enable mariadb ``` ## Step 3 – Install JFrog Artifactory By default, the JFrog Artifactory package is not included in the Ubuntu default repository, so you will need to add the JFrog Artifactory repository to APT. You can add it with the following command: ``` echo "deb https://releases.jfrog.io/artifactory/artifactory-debs xenial main" | tee -a /etc/apt/sources.list.d/artifactory.list curl -fsSL https://releases.jfrog.io/artifactory/api/gpg/key/public|sudo gpg --dearmor -o /etc/apt/trusted.gpg.d/artifactory.gpg ``` Next, update the repository cache with the following command: ``` apt update -y ``` Finally, install the JFrog Artifactory with the following command: ``` apt install jfrog-artifactory-oss ``` After successful installation, start and enable the JFrog Artifactory service: ``` systemctl start artifactory.service systemctl enable artifactory.service ``` You can verify the status of JFrog Artifactory with the following command: ``` systemctl status artifactory.service ``` Output: ``` ● artifactory.service - Artifactory service Loaded: loaded (/lib/systemd/system/artifactory.service; enabled; vendor preset: enabled) Active: active (running) since Sun 2023-10-15 10:50:35 UTC; 10s ago Process: 7599 ExecStart=/opt/jfrog/artifactory/app/bin/artifactoryManage.sh start (code=exited, status=0/SUCCESS) Main PID: 11264 (java) Tasks: 0 (limit: 9410) Memory: 191.8M CPU: 11.878s CGroup: /system.slice/artifactory.service ‣ 11264 /opt/jfrog/artifactory/app/third-party/java/bin/java -Djava.util.logging.config.file=/opt/jfrog/artifactory/app/artifactory/tomcat/conf/logging.pr> Oct 15 10:50:31 ubuntu su[11941]: pam_unix(su:session): session opened for user artifactory(uid=998) by (uid=0) Oct 15 10:50:32 ubuntu su[11941]: pam_unix(su:session): session closed for user artifactory Oct 15 10:50:32 ubuntu su[12065]: (to artifactory) root on none Oct 15 10:50:32 ubuntu su[12065]: pam_unix(su:session): session opened for user artifactory(uid=998) by (uid=0) Oct 15 10:50:33 ubuntu su[12182]: (to artifactory) root on none Oct 15 10:50:33 ubuntu su[12182]: pam_unix(su:session): session opened for user artifactory(uid=998) by (uid=0) Oct 15 10:50:34 ubuntu su[12309]: (to artifactory) root on none Oct 15 10:50:34 ubuntu su[12309]: pam_unix(su:session): session opened for user artifactory(uid=998) by (uid=0) Oct 15 10:50:35 ubuntu su[12309]: pam_unix(su:session): session closed for user artifactory Oct 15 10:50:35 ubuntu systemd[1]: Started Artifactory service. ``` Next, log in to the MariaDB shell with the following command: ``` mysql ``` Next, import the Artifactory data to the MariaDB database. ``` source /opt/jfrog/artifactory/app/misc/db/createdb_mariadb.sql; ``` Next, exit from the MariaDB shell. ``` exit; ``` ## Step 4 – Access JFrog Artifactory Web UI At this point, JFrog Artifactory is installed and listening on port 8082. You can check it with the following command: ``` ss -antpl | grep 8082 ``` Output: ``` LISTEN 0 4096 *:8082 *:* users:(("jf-router",pid=11783,fd=18)) ``` Now, open your web browser and access the JFrog Artifactory using the URL **http://server-ip:8082/ui/.** You will see the JFrog welcome page. ![JFrog login screen](https://www.atlantic.net/wp-content/uploads/2023/10/p1-3.png) Provide default admin username as “admin” and password as “password” then click on the **Login** button. You will see the Getting Started page. ![JFrog get started page](https://www.atlantic.net/wp-content/uploads/2023/10/p2-2.png) Click on **Get Started.** You will see the reset admin password screen. ![JFrog password reset screen](https://www.atlantic.net/wp-content/uploads/2023/10/p3.png) Set your password and click on **Next.** You will see the following screen. ![JFrog web url page](https://www.atlantic.net/wp-content/uploads/2023/10/p4.png) Provide your JFrog URL and click on the **Next** or **Skip** button. You will see the following screen. ![JFrog setup completed](https://www.atlantic.net/wp-content/uploads/2023/10/p6.png) Click on the **Finish** button. You will see the JFrog dashboard. ![JFrog dashboard](https://www.atlantic.net/wp-content/uploads/2023/10/p7.png) ## Conclusion In this post, we explained how to install and set up a JFrog Artifactory on Ubuntu 22.04. You can now deploy JFrog in the production environment and use it as a central repository manager to store all binaries and artifacts with ease. Try to deploy JFrog Artifactory on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Using MySQL with Ruby on Rails App on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/using-mysql-with-ruby-on-rails-app-on-ubuntu-22-04/ | Published: 2023-10-20 | Updated: 2024-06-04 | Author: Hitesh Jethva Ruby is an interpreted, high-level, and general-purpose language developed by Yukihiro Matsumoto. Ruby on Rails is a powerful web framework built on top of Ruby. It is used as a backend for several web applications such as GitHub, Spotify, and more. Ruby on Rails can also be integrated with several databases including MySQL, SQLite, and PostgreSQL. ## Step 1 – Install and Configure MySQL First, install the MySQL server and client library with the following command. ``` apt install mysql-server-8.0 libmysqlclient-dev ``` Once the MySQL server is installed, secure MySQL with the following command. ``` mysql_secure_installation ``` Answer all the questions as shown below. ``` Press y|Y for Yes, any other key for No: Y Remove anonymous users? (Press y|Y for Yes, any other key for No) : Y Disallow root login remotely? (Press y|Y for Yes, any other key for No) : Y Remove test database and access to it? (Press y|Y for Yes, any other key for No) : Y Reload privilege tables now? (Press y|Y for Yes, any other key for No) : Y ``` Next, connect to MySQL with the following command. ``` mysql -u root --skip-password ``` Set a password for the root user using the following command. ``` ALTER USER 'root'@'localhost' IDENTIFIED WITH mysql_native_password BY 'securepassword'; ``` Next, flush the privileges and exit from the MySQL shell. ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 2 – Install rbenv First, install all required dependencies using the following command. ``` apt install git curl libssl-dev libreadline-dev zlib1g-dev autoconf bison build-essential libyaml-dev libreadline-dev libncurses5-dev libffi-dev libgdbm-dev ``` After successful installation, install rbenv with the following command. ``` apt install rbenv libtool ``` Next, initialize rbenv. ``` rbenv init ``` Output: ``` eval "$(rbenv init -)" ``` Next, edit the .bashrc file and add the above output. ``` nano ~/.bashrc ``` Add the following line: ``` eval "$(rbenv init -)" ``` Next, reload the .bashrc file. ``` source ~/.bashrc ``` Next, install rbenv plugin to provide support for the rbenv install command. ``` mkdir -p "$(rbenv root)"/plugins git clone https://github.com/rbenv/ruby-build.git "$(rbenv root)"/plugins/ruby-build ``` Next, verify your rbenv configuration with the following command. ``` curl -fsSL https://github.com/rbenv/rbenv-installer/raw/main/bin/rbenv-doctor | bash ``` You will see the following output: ``` Checking for `rbenv' in PATH: /usr/bin/rbenv Checking for rbenv shims in PATH: OK Checking `rbenv install' support: /root/.rbenv/plugins/ruby-build/bin/rbenv-install (ruby-build 20231014-3-g1d9b4e2) Counting installed Ruby versions: none There aren't any Ruby versions installed under `/root/.rbenv/versions'. You can install Ruby versions like so: rbenv install 3.2.2 Auditing installed plugins: OK ``` ## Step 3 – Install Ruby First, list all available Ruby versions using the following command: ``` rbenv install -l ``` Next, install a specific Ruby version with the following command: ``` rbenv install 3.2.0 ``` Next, set the Ruby version as a global version: ``` rbenv global 3.2.0 ``` You can now verify the Ruby version with the following command: ``` ruby --version ``` Output: ``` ruby 3.0.2p107 (2021-07-07 revision 0db68f0233) [x86_64-linux-gnu] ``` ## Step 4 – Install Ruby on Rails First, install the gem bundler with the following command: ``` gem install bundler ``` Next, install Ruby on Rails using the following command: ``` gem install rails ``` Next, rehash Rails with the following command: ``` rbenv rehash ``` To verify the Rails version, run the following command: ``` rails -v ``` Output: ``` Rails 7.1.1 ``` Next, install the MySQL gem adapter to connect to the MySQL server. ``` gem install mysql2 ``` ## Step 5 – Create a Rails App and Configure MySQL Connection At this point, all the required components of Ruby on Rails are installed. Now, let’s create a new application named myapp with the following command: ``` rails new myapp -d mysql ``` Next, change the directory to myapp application and exit the database configuration file. ``` cd myapp nano config/database.yml ``` Define your MySQL root username and password as shown below: ``` default: &default adapter: mysql2 encoding: utf8mb4 pool: <%= ENV.fetch("RAILS_MAX_THREADS") { 5 } %> username: root password: securepassword socket: /var/run/mysqld/mysqld.sock ``` Save and close the file, then create the necessary databases with the following command. ``` rake db:create ``` ## Step 6 – Verify Configuration Finally, start the Rails server to verify the configuration. ``` rails server --binding=0.0.0.0 ``` If everything is fine, you will see the following output: ``` => Booting Puma => Rails 7.1.1 application starting in development => Run `bin/rails server --help` for more startup options Puma starting in single mode... * Puma version: 6.4.0 (ruby 3.2.0-p0) ("The Eagle of Durango") * Min threads: 5 * Max threads: 5 * Environment: development * PID: 69257 * Listening on http://0.0.0.0:3000 Use Ctrl-C to stop ``` Now, open your web browser and access the Ruby on Rails app using the URL **http://your-server-ip:3000.** You will see the following screen. ![access Ruby on Rails](https://www.atlantic.net/wp-content/uploads/2023/10/p1-2.png) ## Conclusion In this post, we explained how to install Ruby on Rails and connect it to the MySQL database on Ubuntu 22.04. Ruby on Rails supports several database engines. If you need concurrency and scaling, then MySQL will be a better choice for your project. You can now integrate MySQL with the Ruby on Rails application on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Use “Docker Push” and “Docker Pull” Command to Upload and Download Images To Docker Hub > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-use-docker-push-and-docker-pull-command-to-upload-and-download-images-to-docker-hub/ | Published: 2023-10-21 | Updated: 2024-06-06 | Author: Hitesh Jethva The Docker pull command is used for downloading Docker images from the Docker Hub or private registry. By default, it will download the images from the Docker Hub. You will need to specify the name of the private registry if you want to pull from it. The Docker push command is used to upload or share images to the Docker Hub registry. Before pushing an image to the Docker Hub, you will need to create an account on Docker Hub. ## Step 1 – Docker Pull Command In this section, we will show you how to pull a Docker image from the Docker Hub. The basic syntax to pull a Docker image from the Docker Hub is shown below: ``` docker pull [OPTIONS] NAME[:TAG|@DIGEST] ``` Run the Docker pull command followed by the –help option to see all available options. ``` docker pull --help ``` You will see all the options that you can use with the Docker pull command as shown below: ![](https://www.atlantic.net/wp-content/uploads/2023/10/Showing-docker-pull-help-information.png) To understand better, let’s download the Ubuntu 22.04 image from the Docker Hub. ``` docker pull ubuntu:22.04 ``` This will download the Ubuntu 22.04 image from the Docker Hub registry as shown below: ![](https://www.atlantic.net/wp-content/uploads/2023/10/Downloading-Ubuntu-22.04-image-from-the-Docker-Hub-registry.png) To verify your downloaded image, run the following command. ``` docker images ``` You will see your downloaded Ubuntu 22.04 image in the following output: ``` REPOSITORY TAG IMAGE ID CREATED SIZE ubuntu 22.04 d70eaf7277ea 12 days ago 72.9MB ``` ## Step 2 – Update and Commit an Image At this point, you have the Ubuntu 22.04 image in your system. Now, we will create a container from this image, install the Nginx package, and save this container to a new image named nginx-instance. First, create a new container from the Ubuntu 22.04 image. ``` docker run -t -i ubuntu:22.04 /bin/bash ``` This will create a new container and attach it to the bash shell as shown below: ``` root@013aecdd6919:/# ``` Now, update the package index and install the Nginx package inside the container. ``` root@013aecdd6919:/# apt-get update -y root@013aecdd6919:/# apt-get install nginx -y ``` Next, exit from the container with the following command: ``` root@013aecdd6919:/# exit ``` Next, locate your new container ID using the following command: ``` dokcer ps -a ``` You should get the container ID in the following output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 013aecdd6919 ubuntu:22.04 "/bin/bash" 3 minutes ago Exited (0) 33 seconds ago angry_mayer ``` Next, use the container ID from the above output and save the updated container with a new image named nginx-instance. ``` docker commit "013aecdd6919" nginx-instance ``` **Note:** Replace the 013aecdd6919 with your container ID. You can now verify your newly created “nginx-instance” image with the following command: ``` docker images ``` You will see your nginx-instance image in the following output. ``` REPOSITORY TAG IMAGE ID CREATED SIZE nginx-instance latest 12cefc9b5362 57 seconds ago 158MB ubuntu 22.04 d70eaf7277ea 12 days ago 72.9MB ``` ## Step 3 – Docker Push Command At this point, you have your own custom Docker image named nginx-instance in your system. We will now use the Docker push command to push the nginx-instance image to the Docker Hub registry. Note: To push an image to the Docker Hub registry, you will need to create an account on Docker Hub. First, log in to the Docker Hub using the docker login command: ``` docker login ``` You will be asked to provide your Docker Hub username and password as shown below: ![](https://www.atlantic.net/wp-content/uploads/2023/10/Logging-in-to-the-Docker-Hub-account.png) Next, tag the nginx-instance image that matches with your Docker Hub username: ``` docker tag 12cefc9b5362 hitjethva/nginx-instance:ubuntu ``` A brief explanation of the above command is shown below: - **12cefc9b5362** is the ID of the nginx-instance image. - **hitjethva** is your Docker Hub username. - **nginx-instance** is the name of the image that you want to push. You can now verify your tagged image using the following command: ``` docker images ``` You should see the following output: ``` REPOSITORY TAG IMAGE ID CREATED SIZE hitjethva/nginx-instance ubuntu 12cefc9b5362 12 minutes ago 158MB nginx-instance latest 12cefc9b5362 12 minutes ago 158MB ubuntu 22.04 d70eaf7277ea 12 days ago 72.9MB ``` Finally, push your **hitjethva/nginx-instance** image to the Docker Hub using the following command: ``` docker push hitjethva/nginx-instance ``` This will push an nginx-instance image to the Docker Hub registry as shown below. ![](https://www.atlantic.net/wp-content/uploads/2023/10/Pushing-an-Nginx-image-to-the-Docker-Hub.png) You can now login to the Docker Hub using your web browser and verify your nginx-instance image in Repositories: ![](https://www.atlantic.net/wp-content/uploads/2023/10/Verifying-an-Nginx-image-on-Docker-Hub-registry.png) ## Conclusion In this tutorial, you learned how to use the Docker pull and pull command to download and upload images to the Docker Hub registry. You can now start building your own custom Docker images, store them on the Docker Hub registry, and share them with other developers and users. Docker Hub service makes it easier for users to push their local images to Docker Hub and pull them from Docker Hub per their needs. Try to use Docker on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Cockpit Web Console on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-cockpit-web-console-on-fedora/ | Published: 2023-10-22 | Updated: 2024-06-01 | Author: Hitesh Jethva Cockpit is a free, open-source, web-based tool used to manage and administer multiple remote Linux servers via a web interface. It is lightweight, easy to use, and allows you to interact directly with the operating system from a real Linux session in a browser. It is designed for beginner users and helps them to perform many tasks such as starting containers, storage administration, network configuration, inspecting logs, and so on. In this post, we will show you how to install and use Cockpit on Fedora Linux. ## Step 1 – Install Cockpit By default, the Cockpit package is included in the Fedora default repo. You can install it using the following command. ``` dnf install cockpit -y ``` After installing Cockpit, start and enable the Cockpit service. ``` systemctl start cockpit systemctl enable cockpit ``` You can check the status of the Cockpit using the following command. ``` systemctl status cockpit ``` You will see the following output: ``` ● cockpit.service - Cockpit Web Service Loaded: loaded (/usr/lib/systemd/system/cockpit.service; static) Active: active (running) since Tue 2023-09-19 00:56:12 EDT; 3s ago TriggeredBy: ● cockpit.socket Docs: man:cockpit-ws(8) Process: 5239 ExecStartPre=/usr/sbin/remotectl certificate --ensure --user=root --group=cockpit-ws --selinux-type=etc_t (code=exited, status=0/SUCCESS) Main PID: 5250 (cockpit-tls) Tasks: 1 (limit: 2328) Memory: 1.1M CPU: 1.666s CGroup: /system.slice/cockpit.service └─5250 /usr/libexec/cockpit-tls Sep 19 00:56:10 fedora systemd[1]: Starting Cockpit Web Service... Sep 19 00:56:12 fedora remotectl[5249]: /usr/bin/chcon: can't apply partial context to unlabeled file '/etc/cockpit/ws-certs.d/0-self-signed.cert' Sep 19 00:56:12 fedora remotectl[5239]: remotectl: couldn't change SELinux type context 'etc_t' for certificate: /etc/cockpit/ws-certs.d/0-self-signed.cert: Child proc> Sep 19 00:56:12 fedora systemd[1]: Started Cockpit Web Service. ``` ## Step 2 – Configure Firewall If firewalld is installed and configured in your system then you will also need to allow Cockpit service via firewalld. You can allow it using the following command. ``` firewall-cmd --add-service=cockpit --permanent firewall-cmd --reload ``` ## Step 3 – Access Cockpit At this point, the Cockpit is started and listens on port 9090. You can check it with the following command. ``` ss -antpl | grep 9090 ``` You will see the following output: ``` LISTEN 0 4096 *:9090 *:* users:(("cockpit-tls",pid=5250,fd=3),("systemd",pid=1,fd=53)) ``` Now, open your web browser and access the Cockpit web interface using the URL **http://server_ip:9090.** You will see the Cockpit login page. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p1-5.png) Provide your root username and password and click on the **Login** button. You will see the Cockpit dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p2-4.png) Click on the **Services** button. You will see the status of all system services on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p3-2.png) Click on **Terminal.** You will see your Linux terminal screen on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p4-2.png) From here, you can run any command in your Linux system. ## Conclusion In this post, you learned how to install and use Cockpit on Fedora Linux. Cockpit is designed to enable beginner users to manage a Linux system without any advanced knowledge. Try to deploy Cockpit on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Full Guideline to Install Backdrop CMS on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/full-guideline-to-install-backdrop-cms-on-fedora/ | Published: 2023-10-23 | Updated: 2024-06-02 | Author: Hitesh Jethva Backdrop CMS is an open-source and community-developed content management system written in PHP. It is a fork of the Drupal project and offers an administration panel for managing CMS. It is a simple, lightweight, and mobile-friendly CMS that allows you to create, edit, and manage your content with ease. Backdrop CMS offers multiple add-ons, plugins, themes, and layouts that help you to increase the additional functionality. In this post, we will show you how to install Backdrop CMS on Fedora Linux. ## Step 1 – Install Apache, MariaDB, and PHP First, install the Apache and MariaDB server using the following command. ``` dnf install httpd mariadb-server -y ``` Next, install PHP with other required dependencies using the following command. ``` dnf install php php-cli php-fpm php-gd php-mysqlnd php-json php-curl php-pdo php-mbstring php-dom php-xml unzip -y ``` Once all the packages are installed, start and enable Apache, MariaDB, and PHP-FPM services. ``` systemctl start httpd mariadb php-fpm systemctl enable httpd mariadb php-fpm ``` ## Step 2 – Create a Database for Backdrop Next, you will need to create a database and user for Backdrop CMS. First, log in to MariaDB. ``` mysql ``` Next, create a database and user for Backdrop CMS. ``` CREATE DATABASE backdrop; CREATE USER 'backdrop'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the Backdrop database. ``` GRANT ALL PRIVILEGES ON backdrop.* TO 'backdrop'@'localhost'; ``` Finally, flush the privileges and exit from the MariaDB shell. ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download Backdrop First, download the latest version of Backdrop CMS with the following command. ``` wget https://github.com/backdrop/backdrop/releases/download/1.26.0/backdrop.zip ``` Next, unzip the downloaded file. ``` unzip backdrop.zip ``` Next, move the extracted directory to the Apache document root. ``` mv backdrop /var/www/html/backdrop ``` Next, set proper permissions and ownership to the Backdrop directory. ``` chown -R apache:apache /var/www/html/backdrop chmod -R 755 /var/www/html/backdrop ``` ## Step 4 – Configure Apache for Backdrop CMS Next, you will need to create an Apache virtual host configuration file for Backdrop CMS. ``` nano /etc/httpd/conf.d/backdrop.conf ``` Add the following configuration: ``` ServerAdmin admin@example.com ServerName backdrop.example.com DocumentRoot /var/www/html/backdrop allowoverride all allow from all TransferLog /var/log/httpd/backdrop_access.log ErrorLog /var/log/httpd/backdrop_error.log ``` Save and close the file, then restart the Apache service to implement the changes. ``` systemctl restart httpd ``` ## Step 5 – Access Backdrop CMS Now, open your web browser and access the Backdrop CMS using the URL **http://backdrop.example.com.** You will see the language selection screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p1-6.png) Select your language and click on **SAVE AND CONTINUE.** You will see the database configuration screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p2-5.png) Define your database configuration and click on **SAVE AND CONTINUE.** You will see the site configuration screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p3-3.png) Define your site information and click on **SAVE AND CONTINUE.** You will see the Backdrop CMS dashboard screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p4-4.png) ## Conclusion Congratulations! You have successfully installed Backdrop CMS with Apache on Fedora Linux. Now, explore the Backdrop CMS features and create your own website via the Backdrop CMS panel. Let’s deploy the Backdrop CMS on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure Nginx with PHP-FPM on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-nginx-with-php-fpm-on-fedora/ | Published: 2023-10-24 | Updated: 2024-06-03 | Author: Hitesh Jethva Nginx is an open-source HTTP server that allows developers to quickly build and deploy interactive websites. Nginx uses PHP-FPM (FastCGI Process Manager) for processing PHP pages. PHP-FPM uses less memory and CPU as compared to traditional CGI-based methods of running PHP. Configuring the Nginx with PHP-FPM can improve the website’s loading speed and allow it to handle a huge amount of traffic in no time. In this post, we will show you how to install Nginx with PHP-FPM on Fedora Linux. ## Step 1 – Install Nginx Web Server First, you will need to install the Nginx server package on your server. You can install it using the following command. ``` dnf install nginx -y ``` Once the Nginx package is installed, start and enable the Nginx service with the following command. ``` systemctl start nginx systemctl enable nginx ``` ## Step 2 – Install PHP and PHP-FPM Next, install the PHP and PHP-FPM packages using the following command. ``` dnf install php php-cli php-common php-fpm -y ``` After installing all the packages, start and enable the PHP-FPM service. ``` systemctl start php-fpm systemctl enable php-fpm ``` You can check the status of the PHP-FPM service with the following command. ``` systemctl status php-fpm ``` You will see the following output. ``` ● php-fpm.service - The PHP FastCGI Process Manager Loaded: loaded (/usr/lib/systemd/system/php-fpm.service; disabled; vendor preset: disabled) Active: active (running) since Tue 2023-09-19 01:06:35 EDT; 3s ago Main PID: 6994 (php-fpm) Status: "Ready to handle connections" Tasks: 6 (limit: 2328) Memory: 10.0M CPU: 74ms CGroup: /system.slice/php-fpm.service ├─6994 php-fpm: master process (/etc/php-fpm.conf) ├─6995 php-fpm: pool www ├─6996 php-fpm: pool www ├─6997 php-fpm: pool www ├─6998 php-fpm: pool www └─6999 php-fpm: pool www Sep 19 01:06:35 fedora systemd[1]: Starting The PHP FastCGI Process Manager... Sep 19 01:06:35 fedora systemd[1]: Started The PHP FastCGI Process Manager. ``` ## Step 3 – Configure PHP-FPM with Nginx Next, you will need to configure Nginx to run PHP with FPM. First, create a document root directory for your site. ``` mkdir -p /var/www/html/ ``` Next, create a sample info.php file. ``` nano /var/www/html/info.php ``` Add the following code: ``` ``` Save and close the file, then set proper ownership to info.php file. ``` chown -R nginx: /var/www/html/info.php ``` Next, create an Nginx virtual host configuration file. ``` nano /etc/nginx/conf.d/example.conf ``` Add the following configuration: ``` server { listen 80; server_name nginx.example.com; root /var/www/html/; index info.php; access_log /var/log/nginx/example.com.access.log; error_log /var/log/nginx/example.com.error.log; location ~ \.php$ { try_files $uri =404; fastcgi_pass unix:/run/php-fpm/www.sock; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg)$ { expires max; log_not_found off; } } ``` Save and close the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after http{. ``` server_names_hash_bucket_size 64; ``` Save and close the file, then verify the Nginx for any syntax errors. ``` nginx -t ``` Finally, restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 4 – Verify the Setup At this point, Nginx is configured to work with PHP-FPM. Now, open your web browser and verify your setup using the URL **http://nginx.example.com.** You will see your PHP information page on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p1-7.png) ## Conclusion In this tutorial, you have learned to configure the Nginx web server with PHP-FPM on the Fedora Linux system. You can also use PHP-FPM to run multiple PHP versions on a single machine. You can now deploy Nginx with PHP-FPM on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install Wiki.js on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-wiki-js-on-fedora/ | Published: 2023-10-25 | Updated: 2024-06-01 | Author: Hitesh Jethva Wiki.js is a free and open-source wiki software solution written in JavaScript and running on the Node.js runtime. It is cross-platform and is compatible with PostgreSQL, MySQL, MariaDB, MS SQL Server, or SQLite. It offers an intuitive admin panel that allows you to manage all aspects of your wiki. It has a built-in visual editor that allows you to write all content in Markdown files and sync with your remote Git repository. In this post, we will show you how to install Wiki.js on Fedora Linux. ## Step 1 – Install Nginx and MariaDB Before starting, you will need to install Nginx, MariaDB, Redis, and Node.js on your server. You can install all of them using the following command. ``` dnf install nginx mariadb-server nodejs npm redis -y ``` Once all the packages are installed, start and enable all required services. ``` systemctl start nginx mariadb redis systemctl enable nginx mariadb redis ``` ## Step 2 – Configure MariaDB Database Wiki.js uses MariaDB as a database backend, so you will need to create a database and user for Wiki.js. First, connect to the MariaDB shell. ``` mysql ``` Next, create a database and user for Wiki.js. ``` CREATE DATABASE wikijs; GRANT ALL PRIVILEGES ON wikijs.* TO 'wikijs'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB shell. ``` FLUSH PRIVILEGES; QUIT; ``` ## Step 3 – Download Wiki.js First, download the latest version of Wiki.js from Git Hub. ``` curl -s https://api.github.com/repos/Requarks/wiki/releases/latest \ | grep browser_download_url \ | grep -v windows \ | cut -d '"' -f 4 \ | wget -qi - ``` Next, create a directory for Wiki.js and extract the downloaded file inside that directory. ``` mkdir -p /var/www/html/wikijs tar zxf wiki-js.tar.gz -C /var/www/html/wikijs ``` Next, navigate to the Wiki.js directory and copy the sample configuration file. ``` cd /var/www/html/wikijs cp config.sample.yml config.yml ``` Next, edit the Wiki.js configuration file. ``` nano config.yml ``` Change the following lines. ``` port: 3000 type: mariadb host: localhost port: 3306 user: wikijs pass: 'password' db: wikijs bindIP: 0.0.0.0 ``` Save and close the file, then verify the configuration using the following command. ``` node server ``` If everything is fine, you will get the following output. ``` Loading configuration from /var/www/html/wikijs/config.yml... OK 2023-09-19T04:50:39.759Z [MASTER] info: ======================================= 2023-09-19T04:50:39.762Z [MASTER] info: = Wiki.js 2.5.300 ===================== 2023-09-19T04:50:39.762Z [MASTER] info: ======================================= 2023-09-19T04:50:39.763Z [MASTER] info: Initializing... 2023-09-19T04:50:40.675Z [MASTER] info: Using database driver mysql2 for mariadb [ OK ] 2023-09-19T04:50:40.688Z [MASTER] info: Connecting to database... 2023-09-19T04:50:40.789Z [MASTER] info: Database Connection Successful [ OK ] 2023-09-19T04:50:41.770Z [MASTER] warn: DB Configuration is empty or incomplete. Switching to Setup mode... 2023-09-19T04:50:41.771Z [MASTER] info: Starting setup wizard... 2023-09-19T04:50:41.980Z [MASTER] info: Starting HTTP server on port 3000... 2023-09-19T04:50:41.981Z [MASTER] info: HTTP Server on port: [ 3000 ] 2023-09-19T04:50:41.990Z [MASTER] info: HTTP Server: [ RUNNING ] 2023-09-19T04:50:41.990Z [MASTER] info: 🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻 2023-09-19T04:50:41.991Z [MASTER] info: 2023-09-19T04:50:41.991Z [MASTER] info: Browse to http://YOUR-SERVER-IP:3000/ to complete setup! 2023-09-19T04:50:41.991Z [MASTER] info: 2023-09-19T04:50:41.991Z [MASTER] info: 🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺 ``` Press CTRL+C to stop the server. ## Step 4 – Create a Systemd Service File for Wiki.js Next, create a systemd file to manage the Wiki.js service. ``` nano /etc/systemd/system/wiki.service ``` Add the following configuration: ``` [Unit] Description=Wiki.js After=network.target [Service] Type=simple ExecStart=/usr/bin/node server Restart=always User=nginx Environment=NODE_ENV=production WorkingDirectory=/var/www/html/wikijs [Install] WantedBy=multi-user.target ``` Save and close the file, then change the ownership of the Wiki.js directory. ``` chown -R nginx:nginx /var/www/html/wikijs ``` Next, reload the systemd daemon to reload the configuration. ``` systemctl daemon-reload ``` Finally, start and enable the Wiki.js service to start at the system reboot. ``` systemctl enable --now wiki.service ``` You can check the status of the Wiki.js using the following command. ``` systemctl status wiki ``` You will see the following output. ``` ● wiki.service - Wiki.js Loaded: loaded (/etc/systemd/system/wiki.service; enabled; vendor preset: disabled) Active: active (running) since Tue 2023-09-19 00:51:27 EDT; 4s ago Main PID: 4388 (node) Tasks: 11 (limit: 2328) Memory: 55.8M CPU: 1.710s CGroup: /system.slice/wiki.service └─4388 /usr/bin/node server Sep 19 00:51:28 fedora node[4388]: 2023-09-19T04:51:28.996Z [MASTER] warn: DB Configuration is empty or incomplete. Switching to Setup mode... Sep 19 00:51:28 fedora node[4388]: 2023-09-19T04:51:28.996Z [MASTER] info: Starting setup wizard... Sep 19 00:51:29 fedora node[4388]: 2023-09-19T04:51:29.181Z [MASTER] info: Starting HTTP server on port 3000... Sep 19 00:51:29 fedora node[4388]: 2023-09-19T04:51:29.182Z [MASTER] info: HTTP Server on port: [ 3000 ] Sep 19 00:51:29 fedora node[4388]: 2023-09-19T04:51:29.190Z [MASTER] info: HTTP Server: [ RUNNING ] Sep 19 00:51:29 fedora node[4388]: 2023-09-19T04:51:29.191Z [MASTER] info: 🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻🔻 Sep 19 00:51:29 fedora node[4388]: 2023-09-19T04:51:29.191Z [MASTER] info: Sep 19 00:51:29 fedora node[4388]: 2023-09-19T04:51:29.191Z [MASTER] info: Browse to http://YOUR-SERVER-IP:3000/ to complete setup! Sep 19 00:51:29 fedora node[4388]: 2023-09-19T04:51:29.192Z [MASTER] info: Sep 19 00:51:29 fedora node[4388]: 2023-09-19T04:51:29.192Z [MASTER] info: 🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺🔺 ``` ## Step 5 – Configure Nginx Virtual Host Next, create an Nginx virtual host configuration file for Wiki.js. ``` nano /etc/nginx/conf.d/wikijs.conf ``` Add the following configuration: ``` server { listen 80; server_name wiki.example.com; location / { proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_pass http://127.0.0.1:3000; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_next_upstream error timeout http_502 http_503 http_504; } } ``` Save and close the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after http{: ``` server_names_hash_bucket_size 64; ``` Save the file, then verify the Nginx configuration. ``` nginx -t ``` Output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 6 – Access Wiki.js Now, open your web browser and access Wiki.js using the URL **http://wiki.example.com.** You will see the site configuration screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p1-8.png) Define your admin email, password, and site URL, and click on **INSTALL.** You will see the Wiki.js login screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p2-6.png) Provide your admin username and password and click on **Log in.** You will see the Wiki.js welcome screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p3-4.png) Click on **ADMINISTRATION.** You will see the Wiki.js dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p4-5.png) ## Conclusion In this tutorial, you learned how to install Wiki.js with Nginx on Fedora Linux. You can now explore the Wiki.js administration panel and start creating your own Wiki site within a few minutes. You can now try Wiki.js on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Atlantic.Net, Inc. Named Winner of the Coveted Top InfoSec Innovator Awards for 2023 > URL: https://www.atlantic.net/press-releases/atlantic-net-inc-named-winner-of-the-coveted-top-infosec-innovator-awards-for-2023/ | Published: 2023-10-26 | Updated: 2024-06-11 | Author: Editorial Team *Atlantic.Net**Named TOP INFOSEC INNOVATOR WINNER IN 11th Cyber Defense Magazine’s Annual InfoSec Awards during* *CyberDefenseCon 2023  * ORLANDO, FL (BUSINESSWIRE) October 26, 2023 – Atlantic.Net is proud to announce we have been named the winner for the following award from Cyber Defense Magazine (CDM), the industry’s leading electronic information security magazine: *TOP INFOSEC INNOVATOR* “We’re thrilled to be a member on this coveted group of winners in the 11th year of [Cyber Defense Awards](http://www.cyberdefenseawards.com/), during [**CyberDefenseCon 2023**](https://www.cisoconference.com), where the Top Global CISOs exclusively gather by invitation only.  We knew the competition would be tough and with top judges who are leading infosec experts from around the globe, we couldn’t be more pleased,” said Marty Puranik of Atlantic.Net, Inc. “Atlantic.Net embodies three major features we judges look for with the potential to become winners: understanding tomorrow’s threats, today, providing a cost-effective solution and innovating in unexpected ways that can help mitigate cyber risk and get one step ahead of the next breach,” said Gary S. Miliefsky, Publisher of Cyber Defense Magazine. The full list of the Top InfoSec Innovators for 2023 is found here: [Top infosec innovators for 2023](https://cyberdefenseawards.com/top-infosec-innovators-for-2023/) **About Atlantic.Net** Atlantic.Net is an award-winning global cloud services provider with a focus on security, compliance, and simplifying complex infrastructures. With over 29 years of experience, Atlantic.Net is dedicated to offering developers and IT leaders at small, medium, and large organizations a range of on-demand, customized, and cost-effective cloud solutions that cater to their unique business needs. Having served clients like Lenovo, Newegg, NASA and Hilton, the company’s commitment to excellence has positioned it as a leader in the industry, recognized for its innovation and customer-centric approach. **About Cyber Defense Awards** This is Cyber Defense Magazine’s 11th year of honoring cybersecurity innovators, in this case the Top Global CISOs for 2023, on our Cyber Defense Awards platform. In this competition, judges for these and other prestigious awards includes cybersecurity industry veterans, trailblazers and market makers Gary Miliefsky of CDMG, Dr. Lindsey Polley de Lopez of VentureScope, Robert R. Ackerman Jr. of Allegis Cyber, Dino Boukouris of MomentumCyber and with much appreciation to emeritus judges Robert Herjavec of Cyderes, Dr. Peter Stephenson of CDMG and David DeWalt of NightDragon.  Top InfoSec Innovators for 2023 is found here: [top infosec innovators for 2023](https://cyberdefenseawards.com/top-infosec-innovators-for-2023/) and download The Black Unicorn Report for 2023: [The black unicorn report for 2023](https://cyberdefenseawards.com/the-black-unicorn-report-for-2023/) and Top Global CISOs Winners for 2023, here: [Top global cisos winners for 2023](https://cyberdefenseawards.com/top-global-cisos-winners-for-2023/). ### For Media Inquiries: [pr@atlantic.net](mailto:pr@atlantic.net) ***CDM M******edia*** ***I******n******qui******ries:*** Contact:                 Irene Noser, Marketing Executive Email:                     [marketing@cyberdefensemagazine.com](mailto:marketing@cyberdefensemagazine.com) Toll Free (USA):    1-833-844-9468 International:       1-646-586-9545 Website:               [www.cyberdefensemagazine.com](http://www.cyberdefensemagazine.com) --- # Email Security Requirements in Major Compliance Standards: HIPAA, GDPR, PCI DSS > URL: https://www.atlantic.net/hipaa-compliant-hosting/email-security-requirements-in-major-compliance-standards-hipaa-gdpr-pci-dss/ | Published: 2023-10-26 | Updated: 2025-09-15 | Author: Gilad Maayan Email has become an indispensable communication tool for both businesses and individuals. As such, the security of email communication is of paramount importance. From ensuring the confidentiality of patient health information under HIPAA, to protecting personal data under GDPR, to securing financial information as per PCI DSS, compliance with email security requirements is both a legal obligation and a best practice. However, simply adhering to the letter of these standards is not enough. With the evolving nature of cyber threats, it’s imperative that organizations remain vigilant, continuously update their security practices, and foster a culture of security awareness among their staff. The goal is not just compliance but the creation of a secure environment where the integrity, availability, and confidentiality of email data are preserved at all times. ## What Is Email Security? [Email security](https://perception-point.io/guides/email-security/email-security-threats-solutions-8-critical-best-practices/) is a broad term that refers to a variety of techniques and methodologies used to protect email accounts, content, and communication against unauthorized access, loss, or compromise. Cybercriminals and hackers are constantly on the prowl for weaknesses they can exploit, and email is often a prime target. Email security involves various methods and procedures to keep email data private and secure. These measures include the use of strong passwords, encryption, secure email gateways, and regularly updating and patching email software to ensure vulnerabilities are not exploited. Moreover, email security doesn’t only focus on the security of the email itself, but also on the security of the email infrastructure. It includes measures to secure the mail servers, the network connections to the mail servers, and the user’s end devices that receive the emails. ## Common Email Security Measures Required by Compliance Standards Many compliance standards have specific requirements related to email security. Below we provide specifics for HIPAA, GDPR, and PCI DSS. But first, let’s review some basic security measures that are common to these and many other compliance standards. ### End-to-End Encryption Most compliance standards emphasize the importance of encryption, particularly end-to-end encryption. This form of encryption ensures that only the sender and the intended recipient can read the email content, making it an essential tool for securing email communication. ### Multi-Factor Authentication Multi-factor authentication (MFA) is another common measure required by compliance standards. MFA requires users to provide two or more pieces of evidence to authenticate their identity when accessing their email accounts, adding an extra layer of security that makes it harder for unauthorized individuals to gain access. ### Regular Audits and Monitoring Regular audits and monitoring of email systems are another common requirement. Audits help organizations identify potential vulnerabilities and monitor the effectiveness of their security measures, while continuous monitoring enables them to detect and respond to threats in real time. ### Data Retention and Backup Another common requirement of compliance standards is proper data retention and backup strategies for business email. These strategies ensure that important emails can be recovered in the event of data loss, while also ensuring that unnecessary email data is not retained longer than necessary. ### Staff Training and Awareness Programs Finally, staff training and awareness programs are a typical requirement of compliance frameworks. This helps employees understand the importance of email security and equips them with the knowledge and skills to identify and respond to potential threats. ## HIPAA Email Security Requirements The Health Insurance Portability and Accountability Act (HIPAA) sets forth specific requirements for email security, especially for those handling protected health information (PHI). ### Encryption of Emails Containing Protected Health Information (PHI) Encryption is a method of converting information into an unreadable code to prevent unauthorized access. When it comes to emails containing PHI, encryption is crucial. HIPAA requires that all PHI transmitted over an open network must be encrypted to a standard that renders it unreadable, undecipherable, and unusable to unauthorized individuals. ### Authentication and Access Controls HIPAA also requires authentication measures to verify the identities of individuals who request access to PHI. This often involves the use of unique user identification, emergency access procedures, automatic logoff, and encryption and decryption procedures. ### Regular Audits and Monitoring of Email Systems Regular audits and monitoring are also a key part of HIPAA’s email security requirements. This involves keeping track of attempted access, successful and unsuccessful access, and any modifications or deletions of PHI. This helps in identifying any potential security threats and allows for swift action to mitigate them. ### Retention and Backup of Email Data HIPAA requires that PHI be retained for a certain period and that it can be restored in case of loss. For this, it’s important to have robust backup systems in place. This involves backing up email data regularly and ensuring that backups are secure. ### Training for Staff on Secure Email Communication Protocols Finally, staff training is an essential aspect of HIPAA’s email security requirements. It’s important that all staff members understand the importance of email security and are aware of the protocols in place to safeguard PHI. This can go a long way in preventing data breaches and ensuring compliance with HIPAA. ## GDPR Email Security Requirements The General Data Protection Regulation (GDPR), a regulation in EU law on data protection and privacy, also sets forth specific requirements for email security. ### Requirement for Explicit Consent for Email Marketing Under GDPR, explicit consent is required for email marketing. This means that organizations must obtain clear, affirmative consent from individuals before sending them marketing emails. It’s also important to keep records of these consents. ### Use of Encryption and Pseudonymization Techniques Similar to HIPAA, the GDPR also requires the use of encryption in certain circumstances. In addition to this, the GDPR encourages the use of pseudonymization techniques. This involves replacing identifiable data with artificial identifiers to protect individuals’ identities. ### Data Breach Notification Rules Related to Email Data GDPR has strict rules when it comes to data breaches. Organizations are required to notify the relevant supervisory authority of a breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. If the breach is high risk, the organization may also need to notify the individuals affected. ### Limitation and Purpose Specification: Only Collecting Relevant Email Data GDPR enforces a principle known as data minimization. This principle requires organizations to only collect personal data that’s necessary for a specified purpose. In the context of email security, this means only collecting relevant email data. For example, if an organization is sending out a newsletter, it only needs the recipient’s email address, not their physical address or financial information. Limiting the amount of information collected can reduce the potential damage in case of a data breach. ### Rights to Access, Rectify and Erase Personal Email Data Another aspect of GDPR is the empowerment of individuals regarding their personal data. The regulation provides individuals with the right to access their data, rectify any inaccuracies, and erase their data. In email security, this means that organizations should have mechanisms in place that allow individuals to review, correct, or delete their email data if they wish to do so. This reinforces the individual’s control over their data and indirectly strengthens email security by reducing unnecessary data storage. ## PCI DSS Email Security Requirements The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. Email communications often involve the transmission of such sensitive information, making PCI DSS highly relevant in the field of email security. ### Encryption of Emails Containing Cardholder Data One of the primary requirements of PCI DSS is the encryption of cardholder data during transmission over open, public networks. In the context of email security, this means that any emails containing cardholder data should be encrypted. Encryption converts the readable data into an unreadable format to anyone without the decryption key, ensuring the confidentiality of the information if intercepted during transmission. ### Strong Access Controls and Authentication Mechanisms PCI DSS also mandates strong access controls and authentication mechanisms. For email security, this could mean implementing multi-factor authentication (MFA) for accessing email accounts, especially those used for financial transactions. Access controls can also involve restricting access to certain email accounts only to specific individuals or roles within an organization. ### Regular Vulnerability Scans and Monitoring of Email Systems To maintain a secure environment, PCI DSS requires regular vulnerability scans and monitoring of systems. This means that organizations should regularly check their email systems for potential weaknesses or vulnerabilities that could be exploited by cybercriminals. Regular monitoring can also help detect any unusual or suspicious activity in the email system in real-time. ### Restriction of Cardholder Data to a Need-to-Know Basis Another key requirement of PCI DSS is restricting access to cardholder data on a need-to-know basis. This principle of ‘least privilege’ minimizes the number of individuals who can access sensitive data, thereby reducing the risk of internal threats and data breaches. ### Requirement for Security Policies and Staff Training Related to Email Handling Finally, PCI DSS emphasizes the importance of having robust security policies in place and providing staff training related to handling email. This helps ensure that all employees are aware of their responsibilities in maintaining email security and know how to identify and respond to potential threats. ## Conclusion In conclusion, email security is a complex field that is strongly impacted by regulations and compliance standards. By adhering to compliance requirements and implementing the security measures discussed above, organizations can support compliance efforts while also significantly enhancing the security of their email communications. **Author Bio: Gilad David Maayan** ![](https://www.atlantic.net/wp-content/uploads/2023/10/giladimage.jpg) Gilad David Maayan is a technology writer who has worked with over 150 technology companies including SAP, Imperva, Samsung NEXT, NetApp and Check Point, producing technical and thought leadership content that elucidates technical solutions for developers and IT leadership. Today he heads [Agile SEO](https://agileseo.co.il/), the leading marketing agency in the technology industry. LinkedIn:[Linkedin](https://www.linkedin.com/in/giladdavidmaayan/) --- # How to Install and Configure Redis on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-redis-on-fedora/ | Published: 2023-10-27 | Updated: 2024-06-01 | Author: Hitesh Jethva Redis is an in-memory data store used to store metadata about users’ profiles, authentication information, and manifest files. It is primarily used as an application cache or quick-response database. It is designed for real-time applications such as gaming, ad-tech, and financial services. It allows you to write fewer lines of code to store, access, and use data in your applications. In this post, we will show you how to install Redis on Fedora Linux. ## Step 1 – Install Redis By default, the Redis package is included in the Fedora default repo. You can install it using the following command. ``` dnf install redis -y ``` After the installation, start and enable the Redis service using the following command. ``` systemctl enable --now redis ``` You can check the status of the Redis service using the following command. ``` systemctl status redis ``` Output: ``` ● redis.service - Redis persistent key-value database Loaded: loaded (/usr/lib/systemd/system/redis.service; disabled; vendor preset: disabled) Drop-In: /etc/systemd/system/redis.service.d └─limit.conf Active: active (running) since Tue 2023-09-19 00:45:48 EDT; 14min ago Main PID: 4066 (redis-server) Status: "Ready to accept connections" Tasks: 5 (limit: 2328) Memory: 2.0M CPU: 1.619s CGroup: /system.slice/redis.service └─4066 /usr/bin/redis-server 127.0.0.1:6379 Sep 19 00:45:48 fedora systemd[1]: Starting Redis persistent key-value database... Sep 19 00:45:48 fedora systemd[1]: Started Redis persistent key-value database. ``` At this point, Redis is started and listens on port 6379. You can check it with the following command. ``` ss -antpl | grep -i redis ``` Output: ``` LISTEN 0 511 127.0.0.1:6379 0.0.0.0:* users:(("redis-server",pid=4066,fd=6)) LISTEN 0 511 [::1]:6379 [::]:* users:(("redis-server",pid=4066,fd=7)) ``` ## Step 2 – Configure Redis Redis’ default configuration file is located at /etc/redis/redis.conf. You will need to edit it to secure Redis. ``` nano /etc/redis/redis.conf ``` Change the following lines. ``` bind 0.0.0.0 requirepass yourpass appendonly yes appendfilename "appendonly.aof" ``` Save and close the file, then restart the Redis service to apply the changes. ``` systemctl restart redis ``` ## Step 3 – Verify Redis Connection At this point, Redis is installed and configured. Now, connect to the Redis instance using the Redis CLI. ``` redis-cli ``` Next, authenticate Redis using a password. ``` 127.0.0.1:6379> AUTH yourpass ``` Next, check the Redis connectivity. ``` 127.0.0.1:6379> PING ``` Output: ``` PONG ``` Run the following command to get Redis server information. ``` 127.0.0.1:6379> INFO Server ``` Output: ``` # Server redis_version:6.2.7 redis_git_sha1:00000000 redis_git_dirty:0 redis_build_id:63e4c6cb7f542ebb redis_mode:standalone os:Linux 5.12.8-300.fc34.x86_64 x86_64 arch_bits:64 monotonic_clock:POSIX clock_gettime multiplexing_api:epoll atomicvar_api:c11-builtin gcc_version:11.2.1 process_id:6207 process_supervised:systemd run_id:4e86466f757313d4572daf01911d9914c5cfb3ec tcp_port:6379 server_time_usec:1695099789257222 uptime_in_seconds:25 uptime_in_days:0 hz:10 configured_hz:10 lru_clock:600973 executable:/usr/bin/redis-server config_file:/etc/redis/redis.conf io_threads_active:0 ``` ## Step 4 – Benchmark Redis Redis has a built-in benchmark tool used to send a pre-defined number of requests to the server to measure performance. Let’s run the following command to check the average number of requests per second that Redis can handle. ``` redis-benchmark -a yourpass -h 127.0.0.1 -q ``` Output: ``` PING_INLINE: 165837.48 requests per second PING_BULK: 156006.25 requests per second SET: 156006.25 requests per second GET: 136425.66 requests per second INCR: 155038.77 requests per second LPUSH: 173913.05 requests per second RPUSH: 139275.77 requests per second LPOP: 136798.91 requests per second RPOP: 137362.64 requests per second SADD: 149031.30 requests per second HSET: 168067.22 requests per second SPOP: 151975.69 requests per second ZADD: 170648.45 requests per second ``` You can also use the -c and -t options to use 20 parallel connections to run 100000 SET requests on the server: ``` redis-benchmark -a yourpass -h 127.0.0.1 -p 6379 -n 100000 -c 20 ``` Output: ``` ====== PING_INLINE ====== 100000 requests completed in 3.87 seconds 20 parallel clients 3 bytes payload keep alive: 1 host configuration "save": 3600 1 300 100 60 10000 host configuration "appendonly": yes multi-thread: no Latency by percentile distribution: 0.000% <= 0.159 milliseconds (cumulative count 2129) 50.000% <= 0.391 milliseconds (cumulative count 50188) 75.000% <= 0.503 milliseconds (cumulative count 75368) 87.500% <= 0.567 milliseconds (cumulative count 88337) 93.750% <= 0.631 milliseconds (cumulative count 93856) 96.875% <= 0.703 milliseconds (cumulative count 97127) 98.438% <= 0.751 milliseconds (cumulative count 98549) 99.219% <= 0.791 milliseconds (cumulative count 99243) 99.609% <= 0.839 milliseconds (cumulative count 99630) 99.805% <= 0.999 milliseconds (cumulative count 99808) 99.902% <= 1.279 milliseconds (cumulative count 99903) 99.951% <= 1.599 milliseconds (cumulative count 99953) 99.976% <= 2.007 milliseconds (cumulative count 99976) 99.988% <= 2.151 milliseconds (cumulative count 99988) 99.994% <= 2.687 milliseconds (cumulative count 99994) 99.997% <= 2.791 milliseconds (cumulative count 99997) 99.998% <= 2.847 milliseconds (cumulative count 99999) 99.999% <= 2.863 milliseconds (cumulative count 100000) 100.000% <= 2.863 milliseconds (cumulative count 100000) ``` To see the real-time latency stats for your Redis server, run the following command. ``` redis-cli --latency ``` Output: ``` min: 0, max: 8, avg: 0.25 (5217 samples) ``` ## Conclusion In this post, we explained how to install the Redis server on Fedora Linux. We also showed you how to secure Redis with a password and verify its connectivity. Then, we used the redis-benchmark tool to measure the performance of the Redis server. You can now try Redis on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Caddy Web Server on Fedora > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-caddy-web-server-on-fedora/ | Published: 2023-10-28 | Updated: 2024-06-01 | Author: Hitesh Jethva Caddy is an open-source, cross-platform, enterprise-ready web server written in Go language. Caddy can be configured to serve websites directly from its file system, or it can proxy requests to other web servers. It is a cross-platform web server that runs on different operating systems such as Linux, macOS, Windows, BSD, and Solaris. If you are looking for a high-performance, flexible, and easy-to-use web server, then Caddy is the best option for you. In this post, we will show you how to install and use the Caddy web server on Fedora Linux. ## Step 1 – Install Caddy By default, the Caddy web server package is available in the Fedora default repository. You can install it using the following command. ``` dnf install caddy -y ``` Once the Caddy package is installed, you can verify the Caddy installation using the following command. ``` caddy version ``` You will see the Caddy version in the following output. ``` 2.3.0-1.fc34 ``` Next, edit the Caddy default configuration file. ``` nano /etc/caddy/Caddyfile ``` Make the following changes: ``` :80 { root * /usr/share/caddy file_server } ``` Save and close the file, then start and enable the Caddy service with the following command. ``` systemctl enable --now caddy ``` You can verify the Caddy service status using the following command. ``` systemctl status caddy ``` Output: ``` ● caddy.service - Caddy web server Loaded: loaded (/usr/lib/systemd/system/caddy.service; enabled; vendor preset: disabled) Active: active (running) since Tue 2023-09-19 01:10:59 EDT; 4s ago Docs: https://caddyserver.com/docs/ Process: 7150 ExecStartPre=/usr/bin/caddy validate --config /etc/caddy/Caddyfile (code=exited, status=0/SUCCESS) Main PID: 7155 (caddy) Tasks: 5 (limit: 2328) Memory: 16.7M CPU: 140ms CGroup: /system.slice/caddy.service └─7155 /usr/bin/caddy run --environ --config /etc/caddy/Caddyfile ``` Now, open your web browser and access the Caddy default page using the URL **http://your-server-ip.** You will see the Caddy default page on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p1-9.png) ## Step 2 – Create a New Site with Caddy In this section, we will create a new website using Caddy. First, create a document root and log directory for Caddy. ``` mkdir -p /var/www/example.com/html mkdir /var/log/caddy ``` Next, assign proper permissions to those directories. ``` chown caddy:caddy /var/www/example.com/html -R chown caddy:caddy /var/log/caddy ``` Next, create an Index page for your website. ``` nano /var/www/example.com/html/index.html ``` Add the following code: ``` Congratulations! Caddy is working

Congratulations! Caddy is working

``` Save and close the file when you are done. ## Step 3 – Configure Caddy for Your Website Next, you will need to configure the Caddy configuration file to serve your website. ``` nano /etc/caddy/Caddyfile ``` Remove the default configuration and add the following configuration. ``` caddy.example.com:80 { root * /var/www/example.com/html file_server encode gzip log { output file /var/log/caddy/example.access.log } @static { file path *.ico *.css *.js *.gif *.jpg *.jpeg *.png *.svg *.woff *.pdf *.webp } header @static Cache-Control max-age=5184000 } ``` Save and close the file, then validate the Caddy configuration. ``` caddy validate --adapter caddyfile --config /etc/caddy/Caddyfile ``` If everything is fine, you will see the following output. ``` 2023/09/19 05:12:35.854 INFO using provided configuration {"config_file": "/etc/caddy/Caddyfile", "config_adapter": "caddyfile"} 2023/09/19 05:12:35.860 INFO http server is listening only on the HTTPS port but has no TLS connection policies; adding one to enable TLS {"server_name": "srv0", "https_port": 443} 2023/09/19 05:12:35.861 INFO http enabling automatic HTTP->HTTPS redirects {"server_name": "srv0"} 2023/09/19 05:12:35.861 INFO tls.cache.maintenance started background certificate maintenance {"cache": "0xc0004902a0"} 2023/09/19 05:12:35.863 INFO tls.cache.maintenance stopped background certificate maintenance {"cache": "0xc0004902a0"} Valid configuration ``` Finally, restart the Caddy service to apply the changes. ``` systemctl restart caddy ``` ## Step 4 – Access the Caddy Website At this point, your Caddy web server is configured to serve your new website. Now, it’s time to verify the website. Open your web browser and access your website using the URL **http://caddy.example.com.** You will see your website page on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/09/p2-7.png) ## Conclusion Congratulations! You have successfully installed and configured the Caddy web server on Fedora Linux. You can now start deploying high-performance websites using the Caddy web server. Try to deploy the Caddy web server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Managed Kubernetes > URL: https://www.atlantic.net/managed-services/managed-kubernetes/ | Published: 2023-10-31 | Updated: 2025-04-11 | Author: Richard Bailey Kubernetes is an open-source platform that automates containerized application deployment, scaling, and management. Initially developed by Google, it has since been donated to the Cloud Native Computing Foundation (CNCF), which now maintains the project. The essence of Kubernetes lies in its ability to manage many containers, ensuring they interact seamlessly across multiple hosts. Containers are the building blocks of modern software architecture, encapsulating an application and its dependencies into a ‘container,’ making moving the application across various computing environments easier. When the number of containers grows, manual management becomes inefficient and error-prone. This is where Kubernetes comes into play. It offers a powerful orchestration system that allows for more efficient deployment and scaling of applications, reducing the burden on IT teams and streamlining the software delivery process. This article will help you to understand what Kubernetes clusters are, how they work, and what a fully managed Kubernetes service should involve. ## Key Components of Kubernetes Kubernetes comprises several key components that help in automating and managing containerized applications: **Control Plane**: The central control hub that manages the overall Kubernetes environment. It is responsible for scheduling deployments and maintaining the cluster’s desired state. **Worker Nodes**: These are the machines where containers are deployed. A node may host multiple containers depending on the requirements and configuration. **Pods**: The smallest deployable unit in a Kubernetes cluster is a pod, each containing one or more containers. **Service Discovery**: Kubernetes uses its internal DNS for service discovery, making it easier for applications within the cluster to find each other. **Traffic Distribution**: Automatically distributing incoming application traffic across multiple targets, such as pods or nodes, is a critical feature provided by Kubernetes. ## Kubernetes Cluster A Kubernetes cluster is a set of machines, known as nodes, that run containerized applications. These managed Kubernetes clusters can run on various environments, from on-premises servers to public cloud infrastructure. A cluster is generally composed of one master node that coordinates the activities of multiple worker nodes where the containers are deployed. ## Managed Kubernetes Services Enterprises that find it challenging to manage and deploy Kubernetes clusters on their own often turn to managed Kubernetes services. Such services cover various aspects of cluster management, such as scaling, monitoring, and security, allowing businesses to focus on application development rather than infrastructure management. ## Why Use Kubernetes? Kubernetes offers several benefits that make it a popular choice for organizations: **High Availability**: Kubernetes can automatically distribute and schedule containers across a cluster of machines to ensure that applications are highly available. **Scalability**: With built-in auto-scaling features, Kubernetes can easily adapt to the varying load on an application, scaling it up or down as needed. **Portability**: Being an open-source platform, Kubernetes can run on multiple types of infrastructure, providing businesses with flexibility in their deployment options. **Robust Ecosystem**: The vibrant community around Kubernetes offers a wealth of plugins, extensions, and add-ons that can be used to extend its capabilities. ## Innovate, deploy, and operate Kubernetes seamlessly Kubernetes is a transformative tool in its ability to facilitate containerized applications’ seamless deployment node management and operation. Here’s a closer look at how Kubernetes enables innovation, eases deployment, and simplifies operational tasks. ### Facilitating Innovation with Kubernetes Kubernetes encourages a culture of innovation by providing a robust and flexible platform for deploying containerized applications. Teams can iterate faster, experiment with new features, and make changes with minimal friction. The extensibility of the Kubernetes ecosystem also allows for the integration of third-party tools and services, thereby opening avenues for innovation. **Microservices Architecture**: Kubernetes is exceptionally well-suited for microservices, a modern architectural style that breaks down applications into loosely coupled, independently deployable components. This makes it easier to update specific parts of an application without affecting the whole system, accelerating innovation. **Built-in Monitoring**: Kubernetes offers a range of monitoring tools that provide insights into performance metrics, error rates, and usage patterns. This data can inform iterative development, enabling teams to build more reliable and user-centric applications. ### Simplified Deployment Process Deploying applications can be a cumbersome process that involves numerous steps, like provisioning servers, configuring software, and setting up databases. Kubernetes drastically simplifies this process: **Automated Rollouts and Rollbacks**: Kubernetes can manage the rollout of new features and configurations without causing downtime. It can also automate the rollback to a previous state if something goes wrong. **Configuration Management**: Kubernetes allows you to securely store and manage sensitive information, such as passwords and API keys. These configurations can be deployed and updated independently from the application code. **Multi-Environment Support**: Whether it’s a development, staging, or production environment, Kubernetes provides the toolset to manage them with a consistent workflow, reducing the chances of environment-specific bugs. ### Streamlined Operational Tasks Managing day-to-day operations of containerized applications becomes less cumbersome with Kubernetes: **Self-Healing Capabilities**: If a pod or node fails, Kubernetes automatically replaces it or reschedules the containers to other nodes. This ensures high availability without manual intervention. **Resource Optimization**: Kubernetes can automatically allocate and de-allocate resources, such as CPU and memory, based on your requirements and constraints. This leads to more efficient utilization of underlying hardware resources. **Access Management**: With Kubernetes Role-Based Access Control (RBAC), you can define what actions a user, or a group of users, can perform. This granularity in access management enhances the security posture of your applications. ## Load Balancer and Pod Autoscaling Resource optimization is a critical component in any Kubernetes environment. It distributes incoming application traffic across multiple nodes, thereby ensuring that no single node is overwhelmed with too much load. This is crucial for applications that experience varying traffic levels, as it helps maintain high availability and reliability. ### The Importance of Load Balancing in Managed Kubernetes In a managed K8s service, load balancing is often provided as a built-in feature, eliminating the need for manual configuration. This is particularly beneficial for businesses that may not have the expertise to set up and manage load-balancing resources. The fully managed service distributes the load across multiple nodes, enhancing the performance and reliability of your Kubernetes clusters. ### Types of Traffic Distribution in Kubernetes Kubernetes offers several types of traffic distribution, each serving a specific purpose: **Layer 4 Load Balancing**: Operates at the network layer and is generally faster but less flexible. **Layer 7 Load Balancing**: Operates at the application layer, offering more flexibility in terms of routing and traffic management. When utilizing traffic management in a managed Kubernetes environment, consider the following best practices: **Health Checks**: Ensure that your managed Kubernetes providers offer health checks to automatically remove unhealthy nodes from the connection pool. **Scalability**: Opt for a solution that scales clusters automatically based on the incoming traffic, ensuring optimal resource utilization. Pod autoscaling is another indispensable feature in Kubernetes, particularly for applications that experience fluctuating traffic patterns. It automatically adjusts the number of pod replicas in the cluster nodes of a deployment or replica set based on observed metrics like CPU utilization or custom metrics defined by the user. Pod autoscaling in Kubernetes operates on the principle of metrics collection. Metrics such as CPU and memory usage are collected and analyzed to determine whether to scale the pods in or out. The control plane plays a vital role in managing Kubernetes during this process, making decisions based on the metrics it receives. When leveraging pod autoscaling in a managed Kubernetes environment, keep the following best practices in mind: **Metric Selection**: Choose the right metrics that accurately reflect the performance and needs of your application. **Resource Limits**: Set appropriate resource limits and requests to ensure that the autoscale can make more accurate scaling decisions. ## Easy Deployment, from Development to Production In a managed Kubernetes environment, the service provider takes care of many of the complexities associated with deploying Kubernetes clusters. This includes initial setup and ongoing management tasks like updates, monitoring, and scaling. This ease of deployment is particularly beneficial for businesses that may not have extensive in-house expertise in Kubernetes but still want to leverage its powerful features for their applications. #### Development to Production Workflow Managed K8s services often have built-in CI/CD (Continuous Integration/Continuous Deployment) tools that make moving from development to production easier. These tools automate the testing and deployment phases, ensuring that code changes are automatically built, tested, and deployed to the Kubernetes clusters. This results in a more efficient and error-free development workflow. When leveraging the easy, flexible deployment options and features of a managed Kubernetes service, consider the following best practices: **Version Control**: Always use version control systems like Git to manage your Kubernetes configurations and application code. **Automated Testing**: Integrate automated testing into your CI/CD pipeline to catch issues early in development. **Monitoring and Alerts**: Utilize your managed Kubernetes service’s monitoring and alerting features to keep track of application performance and issues. ## Multiple versions and upgrades Keeping up with the rapid pace of Kubernetes updates is a challenging task. Each new version brings a host of improvements, bug fixes, and new features that can significantly impact your cluster’s performance and capabilities. Managed Kubernetes services excel in this area by offering support for multiple versions and seamless upgrades. #### Version Management Managing multiple versions in a Kubernetes cluster can be complex, but managed Kubernetes services simplify this process. They offer features like version rollback and phased rollouts, which allow you to test new versions in a controlled environment before deploying them across your entire cluster. #### Upgrades Upgrades in a managed Kubernetes service are typically automated, reducing the risk of human error and system downtime. Before any upgrade, it’s advisable to back up your cluster’s data and configurations. [Managed services](https://www.atlantic.net/managed-services/what-are-managed-services/) often provide tools for this, ensuring that you can quickly revert to a previous state in case of any issues. When managing multiple versions and upgrades in a managed Kubernetes environment, consider the following best practices: **Compatibility Checks**: Ensure that your applications and configurations are compatible with the new version before upgrading. **Staging Environment**: Use a staging environment to test new versions before rolling them out to production. **Scheduled Upgrades**: Take advantage of scheduled upgrades offered by many managed k8s services to minimize impact during peak business hours. ## Managed Kubernetes Service Providers When it comes to managed K8s services, there are several key players in the market that offer robust, feature-rich solutions. These providers often come with unique features, pricing models, and supported cloud environments, making it essential for businesses to choose the one that best aligns with their specific needs. #### Major Cloud Providers Many of the major cloud providers offer managed k8s services, each with its own set of features and benefits: **Google Kubernetes Engine (GKE)**: Offered by Google Cloud, GKE is known for its high-performance and premium networking features. It provides an environment for deploying, managing, and scaling containerized applications using Google’s infrastructure. **Amazon Elastic Kubernetes Service (EKS)**: One of Amazon’s vast cloud offerings, EKS integrates seamlessly with services like Amazon Virtual Private Cloud and offers robust security features, making it a popular choice for enterprises. **Azure Kubernetes Service (AKS)**: Provided by Microsoft, AKS offers deep integration with Azure’s suite of cloud services. It is known for its enterprise-grade security and compliance features. **VMware Tanzu Kubernetes Grid**: Unlike cloud-specific providers, VMware’s Tanzu Kubernetes Grid allows for multi-cloud and on-premises deployments, offering greater flexibility for businesses with complex infrastructure needs. #### Considerations for Choosing a Provider When selecting a managed Kubernetes service, consider the following: **Feature Set**: Different providers offer different features, such as auto-scaling, integrated CI/CD pipelines, and advanced monitoring tools. **Compliance and Security**: Ensure that the provider meets your organization’s compliance and security requirements. **Cost**: Pricing models can vary significantly between providers, so it’s important to understand the cost implications of your chosen solution. **Compatibility**: Ensure that the provider’s service is compatible with your existing infrastructure and tools. **Support and Maintenance**: Opt for providers that offer comprehensive support and automated management features, including updates and monitoring. **Community and Ecosystem**: A strong community and a rich ecosystem of third-party integrations can be valuable assets when working with Kubernetes. ## Running Kubernetes Clusters on Atlantic.Net Experience the power of Kubernetes with minikube on Atlantic.Net. Our cloud and dedicated servers provide the perfect environment for you to [deploy your minikube cluster](https://www.atlantic.net/?s=minikube&post_type%5B%5D=), offering you a streamlined, efficient way to manage your containerized applications. Elevate your DevOps game—get started with [Atlantic.Net today](https://www.atlantic.net/about-us/corporate-contact/)! --- # Server Management Tools > URL: https://www.atlantic.net/managed-services/server-management-tools/ | Published: 2023-11-01 | Updated: 2025-04-11 | Author: Richard Bailey ### Introduction to Server Management Tools Server management tools are crucial components in maintaining, monitoring, and optimizing computing environments, both virtual and physical. Server management software is designed to provide system administrators with suitable instruments to oversee server resources, manage servers, and maintain server health optimally. Server management tools are crucial for managing every server type, whether Windows, Linux, SQL, or cloud servers. Ensuring they operate efficiently is essential to ensure smooth day-to-day business operations. This article will look at the vital role that server management tools play within a modern digitally-focused enterprise, and we will learn what server management involves and discover the important role that managed service providers undertake in providing the critical skills needed to keep your systems running optimally. ### The Importance of Effective Server Management Effective server management is not just about managing servers; it’s about ensuring every component, from operating systems to network devices, works harmoniously, allowing businesses and IT professionals to focus on more strategic initiatives. Here is why effective server management is so critical: #### Server Health and Performance Maintaining optimal server health is crucial. Server management tools offer real-time insights into performance metrics and server overhead, enabling identifying and resolving performance issues before they impact business operations. #### Managing Multiple Server Environments Managing multiple servers can be complex, whether dealing with Linux, Windows, SQL, or physical and virtual servers. Effective server management software simplifies this, allowing system administrators to monitor and manage domains, ensure security, and oversee the entire infrastructure from a central location. #### Enhanced Security Cybersecurity threats arise daily, and robust server management solutions are indispensable. The best server management software offers comprehensive security solutions, including patch management and proactive monitoring, to promptly detect and mitigate potential security threats and vulnerabilities. #### Advanced Monitoring Systems Advanced server monitoring systems allow complete visibility of server domains, giving IT professionals detailed monitoring capabilities of servers, network traffic, and the health of network devices over the device’s lifetime, ensuring smooth business operations and data collaboration. #### Resource Optimization Server management tools enable businesses to optimize server resources effectively, managing both cloud services and physical servers efficiently. Capacity planning and resource allocation are streamlined, ensuring optimal server performance and resources are utilized efficiently. #### Empowering Businesses through Managed Services [Managed service providers](https://www.atlantic.net/managed-services/what-are-managed-services/) offering top server management software empower businesses by taking over the intricate tasks of server management, allowing business leaders to gain visibility and control over their IT environments. Remote monitoring and management services provided by these providers ensure that servers are always up-to-date and running efficiently. #### Contribution to Business Goals Effective server management directly contributes to achieving business goals by ensuring uninterrupted services, enhancing productivity, and allowing for swift and efficient resolution of any issues. This benefits your product performance and enables businesses to focus more on strategic growth and less on managing their IT environment. #### Impact on Operating Systems Proper server management has a considerable impact on the performance of operating systems. Whether dealing with cloud or physical servers, server management tools ensure that every operating system functions optimally, reducing the likelihood of system crashes and downtime. ## Understanding Server Management Software Server monitoring tools are indispensable, providing real-time insights into server health, network traffic, and performance metrics. These tools are particularly crucial for managing complex server ecosystems on Linux or Windows. ### Server Monitoring and Performance Tools When selecting a server monitoring tool, several key features must be considered. These include automated monitoring capabilities, real-time performance metrics, and remote monitoring and management. Additionally, generating custom reports can be invaluable for in-depth analysis. **SolarWinds Server & Application Monitor**: SolarWinds offers a comprehensive monitoring solution, including performance metrics and patch management. It’s ideal for businesses that require a robust, all-in-one solution. **PRTG Network Monitor**: Specializing in network traffic monitoring, this tool also provides excellent server monitoring features. It’s highly customizable and offers various options for network performance analysis. **Nagios**: Known for its flexibility, Nagios offers a wide range of monitoring services, including server, network, and database management. It’s open-source and highly customizable, making it a favorite among Linux users. **Zabbix**: This is another open-source option that excels in monitoring various server resources. It comes with a strong focus on security solutions and log management. **Datadog**: This cloud-based tool offers a unified view of an entire infrastructure, making it easier to manage servers, cloud services, and [SQL databases](https://www.door3.com/blog/how-to-migrate-and-convert-access-to-sql-server) from a central location. **ManageEngine OpManager**: This tool offers both network monitoring and server management features. It supports multiple platforms and allows for managing user accounts and domains. ### Automation and Configuration Management Tools This type of server management tool streamlines the deployment, maintenance, and scaling of server resources, thereby reducing manual errors and enhancing efficiency. Whether you’re dealing with Linux servers or Windows environments, these tools offer a range of functionalities that can significantly improve your server management processes. Manual configuration and management are no longer feasible or efficient. Automation tools help execute repetitive tasks, while configuration governance ensures that all server settings are consistent and compliant with organizational policies. Together, they enable IT teams to focus on more strategic tasks, such as capacity planning and performance optimization. **Ansible**: An open-source, highly extensible automation tool that can manage everything from task execution to configuration management. It is particularly strong in managing Linux-based systems. **Puppet**: This server management software is widely used for automating the provisioning and management of server resources. It offers a robust framework for defining and enforcing configurations across various systems. **Chef**: Primarily used for configuration management, Chef allows for the automation of infrastructure as code. It supports both Windows and Linux environments and integrates well with cloud services. **SaltStack**: This tool excels in configuration management and remote server administration. It offers a Python-based open-source platform that is both flexible and powerful. **Terraform**: is designed for efficiently building, changing, and versioning infrastructure. It can manage existing service providers and custom in-house solutions, making it highly versatile. **Microsoft Azure Automation**: Designed for the Azure cloud platform, this tool offers automation and configuration services that are deeply integrated with other Azure services. It’s beneficial for businesses invested in the Microsoft ecosystem. ## Benefits of Opting for Managed Service Providers Managed Service Providers (MSPs) like Atlantic.Net have become an invaluable resource for businesses looking to optimize their IT operations. By outsourcing various IT functions to specialized providers, companies can focus on their core competencies while benefiting from the expert management of their technology infrastructure. Here, we delve into some key advantages of partnering with an MSP. ### Expertise in Multiple Technologies MSPs like Atlantic.Net have a diverse team of experts skilled in different technologies. This multidisciplinary approach allows us to handle a wide range of tasks, including but not limited to: **Server Management**: Whether it’s Linux servers or Windows environments, MSPs have the tools and expertise to manage your server infrastructure’s day-to-day management. **Cloud Services**: MSPs can guide businesses through cloud migration, management, and security complexities, whether you are just starting your cloud journey or already cloud-enabled. **Database Management**: With specialized knowledge in database management, MSPs can optimize MySQL, Postgres, Redis, and SQL server performance and security. The advantages of multi-technological expertise offered by Managed Service Providers (MSPs) are diverse and include such benefits as: **Cost-Efficiency**: Opting for a single provider capable of managing a diverse range of technologies can significantly reduce the need for multiple vendors, leading to cost savings. **Seamless Integration**: MSPs ensure that various technologies are integrated smoothly, resulting in a more cohesive and efficient IT infrastructure. **Scalability**: MSPs can effortlessly adapt and scale their services to meet your evolving needs as your organization expands, thanks to their extensive technological expertise. In practical terms, this expertise can be demonstrated in several real-world applications: **Custom Reports**: Specialized reporting is often essential for auditing and decision-making processes. MSPs leverage their database management and analytics skills to generate custom reports from multiple data sources. **Enhanced Security Measures**: Security is paramount, and MSPs can implement advanced protocols across different platforms. This ensures a secure IT environment, safeguarding everything from server logs to user accounts. **Performance Optimization**: MSPs continuously monitor and analyze performance metrics, allowing them to fine-tune various IT infrastructure components for optimal functionality. This multi-faceted skill set makes MSPs an invaluable partner for businesses looking to optimize their IT operations. ### 24/7 Monitoring and Support One of the most appealing aspects of a managed service is the compelling advantage of around-the-clock support. Costs for such a service vary, so do your research. However, the benefits afforded to your business are substantial. Continuous monitoring enables MSPs to identify and address issues promptly (often before the customer is aware of a problem), minimizing downtime and mitigating potential revenue loss. The rapid response provided by MSP experts strengthens overall business continuity, making it a critical aspect of modern IT management. MSPs also offer proactive maintenance by constantly monitoring for signs of potential issues, such as server hardware issues. This preventive approach reduces the likelihood of severe disruptions, allowing businesses to operate more smoothly. The peace of mind gained from knowing that your IT infrastructure is under constant, expert surveillance is a game changer. You are secure in the knowledge that your technology base is well-managed. ### Enhanced Security Measures Managed Service Provider helps to enhance your business’s security posture. Today, cyber threats are increasingly sophisticated, and the advanced security protocols implemented by MSPs offer a robust line of defense. Security measures include log management, encrypted data storage, multi-factor authentication, DDoS protection, and Web Application Firewalls. By employing such comprehensive security solutions, MSPs ensure that internal and external threats are effectively mitigated, safeguarding crucial business data and IT infrastructure. MSPs like Atlantic.Net are highly experienced in compliance requirements across various industries, from healthcare to finance. This expertise allows our business to tailor security measures that meet specific regulatory standards, providing additional protection. ## Key Features of an Effective Server Management Solution A top-tier server management platform should offer functionalities ranging from sophisticated server monitoring to remote server administration tools for managed servers at multi-site operations. The platform must provide in-depth analytics, extend business oversight to the broader IT ecosystem, and include stringent security measures. Specialized tools for web server management and virtual infrastructure oversight are increasingly vital. Next, we will focus on three critical areas that your next management software company should be able to provide your business: ### #1: Robust Monitoring Capabilities Your chosen server monitoring system must have reliable and functional monitoring capabilities. To offer a comprehensive view of your IT infrastructure, monitoring capabilities must exceed essential server monitoring. Here’s why robust monitoring capabilities are a key feature: **Real-Time Insights**: Advanced monitoring tools provide real-time data on server performance, network traffic, and resource utilization. This enables IT teams to identify and address issues as they happen, minimizing downtime and enhancing overall system reliability. **Multi-Faceted Monitoring**: A robust monitoring system doesn’t just focus on servers. It also extends to other aspects of the IT environment, such as network performance, web servers, API throughput, container insights, etc. **Automated Alerts**: A key feature often requested is the ability to set up automatic alerts for specific events or thresholds. This ensures that IT teams are immediately notified of any issues, allowing for quick resolution and minimal impact on operations. **Historical Data Analysis**: Reviewing historical data can offer valuable insights into performance trends and potential bottlenecks. This is crucial for long-term planning and optimization efforts. **Security Monitoring**: Besides performance metrics, robust monitoring capabilities should include security features. This involves tracking unauthorized access attempts, monitoring server logs, and even automated scanning for vulnerabilities. **Remote Monitoring**: In an increasingly remote work environment, monitoring server resources and performance from anywhere is invaluable. Robust monitoring capabilities should offer secure and efficient remote access options. **User Activity Tracking**: Understanding user behavior is essential for security and performance optimization. Robust monitoring should include user activity tracking to identify any unusual behavior or potential security risks. ### #2: User-Friendly Interface The importance of a user-friendly interface cannot be overstated. While the backend may be packed with powerful features, the front end must be accessible and intuitive for users of varying technical expertise. Many customers expect at least read-only access to chosen server management tools. Therefore, here’s why a user-friendly interface is a key feature: **Ease of Use**: A well-designed server management software interface simplifies complex tasks that would otherwise need to be performed via the command line, making it easier for IT teams to manage servers, monitor server resources, and perform device management tasks. This ease of use can significantly reduce the time to respond to incidents. **Quick Onboarding**: A user-friendly interface ensures new team members can quickly get up to speed with the system. This is particularly beneficial for businesses with a high turnover rate or those that rely on temporary staff for specific projects. **Efficient Workflow**: An intuitive design can streamline the workflow, allowing IT professionals to perform multiple tasks from a central location. Whether remote server administration, inventory management, or web server monitoring, a user-friendly interface can make these tasks more efficient. **Reduced Error Rate**: A complicated or cluttered interface can lead to mistakes, which can be costly in a server management environment. A user-friendly interface minimizes this risk by providing clear instructions and straightforward navigation. **Enhanced Productivity**: Ultimately, an easy-to-use interface can boost productivity. IT teams can focus more on strategic tasks like infrastructure management and less on navigating a complicated system. **Remote Access**: In today’s work-from-home culture, accessing the server management system remotely is crucial. A user-friendly interface should extend to remote access capabilities, ensuring users can perform essential tasks from anywhere without a steep learning curve. ### #3: Comprehensive Reporting and Analytics Reporting and analytics tools enable businesses to make data-driven decisions, optimize performance, and enhance security measures. Data is quickly becoming a valuable asset for digital-focused enterprises. Here’s a closer look at why these key features are so vital: **Informed Decision-Making**: Robust reporting tools can give business leaders the visibility they need to make informed decisions. Whether it’s about resource allocation or security protocols, analytics can offer valuable insights into how the system is performing. **Performance Optimization**: Analytics can help IT teams identify real-time bottlenecks or performance issues. This enables proactive maintenance, allowing adjustments before issues escalate into significant problems. **Security Audits**: Comprehensive reports can be invaluable for security audits. They can provide a detailed account of server activities, user access, and security incidents, helping businesses comply with industry regulations. **Resource Planning**: Businesses can gain insights into server resource utilization through analytics. This is crucial for effective capacity planning, ensuring the infrastructure can handle current needs and scale for future growth. **Cost Management**: Detailed reports can also help in cost management by identifying underutilized resources or potential areas for optimization. This can lead to more efficient use of resources and, consequently, cost savings. **User Behavior Analysis**: Understanding how users interact with the system can offer insights into potential security risks or areas for improvement. Analytics tools can track user behavior, providing an additional security and usability assessment layer. **Customization**: The ability to customize reports allows businesses to focus on metrics most relevant to their operations. Whether it’s monitoring specific server resources or tracking particular performance metrics, customized reports offer targeted insights. ## Choosing the Right Managed Service Provider Now that you know the exclusive benefits of choosing the best server management tools available, it’s important to decide whether you want to go down the self-managed path or reach out to a managed service provider for help. ### Evaluating Provider Expertise and Reputation A provider’s track record can offer valuable insights into the quality and reliability of their services. We have created a list of what to look for: - **Industry Experience**: A provider with extensive experience will likely offer a more robust and reliable solution. Look for a management software company that has been in the business for several years and has a portfolio of successful implementations. If you work in healthcare, choose a partner that has been providing [HIPAA compliance services](https://www.atlantic.net/compliance-hosting/) for years. - **Customer Reviews**: [Customer testimonials and reviews](https://www.atlantic.net/hosting-services-provider/atlantic-net-reviews-and-testimonials/) can provide a candid look at what to expect from the provider. These can offer insights into the provider’s strengths and weaknesses, from monitoring capabilities to customer support. - **Certifications and Accreditations**: [Industry certifications](https://www.atlantic.net/hosting-services-provider/certifications-and-partnerships/) can testify to the provider’s expertise. Whether in security solutions or infrastructure management, certifications indicate a level of competence that industry authorities have recognized. - **Case Studies**: Many providers offer [case studies](https://www.atlantic.net/press-room/case-studies/) that detail how their solution has helped businesses solve specific challenges. These can provide practical examples of the provider’s expertise in robust monitoring, analytics, and security measures. - **Technical Support**: The availability and [quality of technical support](https://www.atlantic.net/hosting-services-provider/support-team/) are indicators of a provider’s commitment to customer satisfaction. Look for 24/7 monitoring and support providers, showing they are invested in their client’s success. ### Assessing Service Level Agreements (SLAs) Service Level Agreements (SLAs) are critical when selecting a server management solution. These legally binding documents outline the level of service you can expect from a provider, covering everything from uptime guarantees to response times for support queries. Here’s how to assess SLAs effectively: - **Uptime Guarantees**: An uptime guarantee is one of the most crucial elements in an SLA. This metric indicates the time the service is expected to be available. High uptime percentages, such as 99.9%, indicate a reliable service. - **Response and Resolution Times**: SLAs should specify the expected response and resolution times for technical issues. This is particularly important for businesses that require 24/7 monitoring and support to maintain continuous operations. - **Data Backup and Recovery**: An SLA should outline the provider’s data backup and recovery policies. This includes how frequently backups are made, where the data is stored, and the procedures for data recovery in case of a system failure. - **Security Protocols**: Given the increasing importance of cybersecurity, the SLA should detail the security measures in place. This can range from encryption methods to how the provider monitors server resources for potential security threats. - **Compliance Standards**: For businesses in regulated industries, the SLA should specify how the provider will help maintain compliance with relevant laws and regulations. This is especially important for features like inventory management and user activity tracking. - **Penalties and Remedies**: The SLA should also outline the penalties for service failures and the remedies available to the customer. This provides accountability and offers a course of action if the provider fails to meet the agreed-upon service levels. - **Flexibility and Scalability**: Your server management needs may change as your business grows. The SLA should offer flexibility to adjust services and costs accordingly, whether adding more server resources or scaling down. - **Exit Strategy**: Finally, the SLA should provide clear terms for contract termination, including any associated fees and the process for data retrieval upon service termination. ## The Role of Managed Service Providers in Server Management So, what do you get when you choose a managed service provider to manage your server infrastructure? ### Proactive Maintenance and Issue Resolution You get a managed service that focuses on keeping your estate healthy and operating at its peak performance. Here’s how: **Predictive Analytics**: Utilizing advanced monitoring software, MSPs can analyze performance metrics and usage patterns to predict potential issues before they become critical problems. This enables them to perform preventive maintenance, reducing the risk of severe disruptions. **Regular Updates and Patches**: Keeping software and hardware up-to-date is crucial for performance and security. MSPs manage this by regularly applying patches and updates, often during off-peak hours, to minimize impact on business operations. **Resource Optimization**: Through continuous monitoring and analytics, MSPs can optimize the allocation of server resources. This ensures that hardware and software are used efficiently, reducing costs and improving performance. **Incident Response Plans**: In the event of a security incident or system failure, MSPs have predefined incident response plans. These plans outline the steps for quick recovery and are regularly updated to adapt to new threats. ### Implementing Scalable and Flexible Solutions As businesses grow and evolve, so do their IT needs. MSPs are adept at adapting to these changing requirements, offering solutions that can scale with your business. Here’s how: **Modular Architecture**: Many MSPs offer solutions built on a modular architecture, allowing for easy addition or removal of features. Businesses can start with a basic setup and add more complex functionalities as their needs evolve. **Cloud Integration**: MSPs provide seamless integration with cloud services, offering a hybrid approach that combines the benefits of both on-premises and cloud-based solutions, which is great if your business is looking to scale quickly. **Automated Workflows**: To improve efficiency, MSPs can implement computerized workflows that streamline patch management, backups, and system updates. Automation not only saves time but also reduces the likelihood of human error. **Customizable Solutions**: MSPs offer a level of customization that allows businesses to tailor solutions to their specific needs. Whether it’s dedicated hosting, bare-metal server hosting, or even shared hosting, MSPs can adapt their offerings to meet your unique business requirements. ### Ensuring Optimal Server Performance and Uptime In the real world, businesses outsource IT systems to MSPS because they want a guaranteed uptime and an expert eye to keep their systems functioning as expected. It is not uncommon for growing businesses to outgrow their in-house capabilities. As a result, outsourcing empowers the company to grow at the pace your investors demand. As your business grows, you may want to consider: **Disaster Recovery Plans**: In addition to preventive measures, MSPs offer robust disaster recovery plans. These plans outline the data backup and recovery procedures, enabling quick restoration of services in the event of a catastrophic failure. **Audits and Assessments**: To maintain optimal performance, MSPs conduct regular audits and assessments of the server environment. These reviews help identify potential bottlenecks or vulnerabilities impacting server performance and uptime. **High Availability Configurations**: MSPs can set up high availability configurations that automatically switch to a backup server in case of failure. This ensures that services remain available even when individual components encounter issues. **Load Balancing**: MSPs often employ load-balancing techniques to distribute workloads efficiently across multiple servers. This ensures that no single server is overwhelmed, optimizing performance and reducing the risk of crashes. ## Exploring Advanced Server Management Techniques MSPs are at the forefront of implementing advanced server management techniques beyond traditional methods. These techniques leverage cutting-edge technologies and methodologies to offer superior performance, security, and scalability. **Artificial Intelligence and Machine Learning**: MSPs increasingly incorporate AI and machine learning algorithms into their monitoring software. These technologies can predict issues before they occur, allowing for preemptive action and reducing downtime. **Zero Trust Security Models**: In a zero-trust model, every access request is fully authenticated, authorized, and encrypted before granting access, regardless of where the request originates. This enhances security by minimizing the potential for internal threats. **Infrastructure as Code (IaC)**: This technique allows for the automated setup, configuration, and management of servers using code. IaC enables quick deployment and scaling of server resources, making it an ideal solution for agile and DevOps environments. **Serverless Architectures**: Businesses can run applications without worrying about the underlying server infrastructure in a serverless setup. This allows for automatic scaling and is particularly cost-effective as you only pay for the compute time you use. **Blockchain for Security**: While still a relatively new technology in server management, blockchain offers the potential for enhancing security, particularly in ensuring data integrity and secure, transparent transactions. **Edge Computing**: As IoT devices proliferate, edge computing becomes more relevant. This involves processing data closer to its source, reducing latency and bandwidth use. MSPs can manage edge computing environments as part of a comprehensive server management strategy. ## Future Trends in Server Management As technology evolves, server management is poised to undergo significant transformations. MSPs and IT professionals are closely watching several emerging trends that promise to redefine how servers are managed, optimized, and secure. Here’s a glimpse into the future of server management: **Hyperautomation**: Building on the current trend of automation, hyperautomation involves using advanced technologies like AI and machine learning to automate complex decision-making processes, not just tasks. This could revolutionize how server resources are allocated and optimized. **Quantum Computing**: While still in its relative infancy, quantum computing has the potential to bring about a paradigm shift in server management. Its ability to perform complex calculations at unprecedented speeds could be a game-changer for data analytics and security protocols. **5G Networks**: The continued rollout of 5G is expected to significantly impact server management by enabling faster and more reliable wireless communication. This could facilitate more efficient remote server administration and open new avenues for edge computing. **Sustainability**: As data centers consume vast energy, sustainability is becoming a focus. Future server management solutions may prioritize energy-efficient operations and integrate renewable energy sources. **Augmented Reality (AR)**: AR has the potential to aid in server management by providing real-time overlay data during physical server maintenance. This can guide technicians more effectively than traditional methods. **Blockchain Beyond Security**: While currently used primarily for security, blockchain has potential applications in server management for ensuring data integrity and creating transparent, unchangeable logs of all server activities. **AI-Driven Predictive Maintenance**: AI algorithms are expected to become more sophisticated, allowing for even more accurate predictive maintenance. This could minimize downtime by identifying and addressing issues before they become critical failures. **Human-AI Collaboration**: Future trends may see a more collaborative approach between human administrators and AI algorithms. AI can handle routine tasks, while humans focus on strategic decision-making guided by insights and recommendations from AI. ### Why Atlantic.Net’s Server Management is Essential for Your Business #### Comprehensive Service Suite At Atlantic.Net, we understand that managing a server infrastructure can be a complex and time-consuming task. That’s why we offer a comprehensive range of server management services to free up your IT resources, allowing you to focus on your core business. From operating system support, including Windows Server and Linux distributions, to database and cPanel assistance, our managed services are tailored to your needs. #### Security and Performance Security is a paramount concern for any business. Our server management services include vulnerability scans, patching, and updates, ensuring that your servers are always secure and up-to-date. Additionally, we offer web server support, including general security tweaks and performance optimizations. This ensures not only your data’s safety but also your servers’ optimal performance. #### Flexibility and Customization We offer support for various platforms and technologies, including MSSQL, MySQL, Apache, and Nginx. Whether you need assistance with email server setup, load balancing, or VPN configurations, our team is equipped to handle it all. Our managed services are not just about maintaining your servers; they’re about enhancing your entire hosted infrastructure. #### Monitoring and Support Our OnWatch Platinum Monitoring Platform keeps a vigilant eye on your servers, and our dedicated account representatives are always available to assist you with any issues. We also offer server migration services, making switching to Atlantic.Net’s managed platform easier. #### Cost-Effectiveness You can enjoy a 20% discount on Atlantic.Net Professional Service Agreements by leveraging our server management services. This makes our services efficient and cost-effective, providing you with excellent value for your investment. #### Testimonials Don’t just take our word for it. Industry leaders like Jason Coleman, VP of Information Technology at Orlando Magic, and Erin Chapple, General Manager for Windows Server at Microsoft Corp., have praised our infrastructure and technical expertise. #### Final Thoughts The need for reliable and efficient server management cannot be overstated. Atlantic.Net’s Server Management services offer a one-stop solution for all your server-related needs, ensuring your business runs smoothly and securely. Partner with us and experience the peace of mind of knowing your server infrastructure is in capable hands. For more information or to get started, contact an advisor at 866-618-DATA (3282), email [sales@atlantic.net](mailto:sales@atlantic.net), or fill out our online form. We’re dedicated to your success and ready to develop a hosting environment tailored to your business needs. --- # Managed Kubernetes Services > URL: https://www.atlantic.net/managed-services/managed-kubernetes-services/ | Published: 2023-11-03 | Updated: 2025-04-11 | Author: Richard Bailey Integrating Kubernetes into a public cloud infrastructure has become a standard practice for companies looking to manage containers and orchestrate their applications efficiently. Various cloud services vendors offer managed Kubernetes clusters, making it easier for businesses to deploy, manage, and scale applications without the complexities of handling the control plane or storing cluster data themselves. A managed Kubernetes service is a popular managed service provided by numerous cloud providers. Running Kubernetes at scale demands a lot of computing horsepower. Did you know you can also create and manage your own Kubernetes service on an Atlantic.Net cloud server running Docker or minikube? This article will uncover the complexities of managed K8s services, and we will discover how you can run your own K8s service on Atlantic.Net. ## The Evolution of Managed Kubernetes Services Managed K8s Services have come a long way since their inception. Initially considered a niche offering, they have evolved into a mainstream solution for businesses of all sizes. This transformation has been driven by the increasing complexity of managing Kubernetes clusters and the need for specialized expertise. Kubernetes was originally developed by Google, drawing from the company’s years of experience managing containerized applications at scale with their internal platform, Borg. Google [open-sourced](https://github.com/kubernetes/kubernetes) Kubernetes and officially announced it in mid-2014. Today, Managed K8s Services offer many features, from automated scaling to advanced security protocols, making them indispensable for modern enterprises. ## Managed Kubernetes Service vs. DIY When it comes to deploying Kubernetes clusters, organizations often face the dilemma of choosing between a managed service like Google Kubernetes Engine, Azure Kubernetes Service (AKS), or IBM Cloud Kubernetes Service, and a do-it-yourself (DIY) approach. While a DIY strategy offers greater control, it also comes with the burden of continuous monitoring, manual scaling, cluster management, and security management. If you are proficient in cloud computing, it is absolutely possible to do it yourself. On the other hand, Managed K8s Services from major cloud providers alleviate these challenges by automating many operational tasks, such as deploying cloud-native apps, allowing businesses to focus on application development and strategic initiatives in a public cloud environment ## Architectural Considerations for Kubernetes Clusters in Managed Services When you deploy Kubernetes clusters, the architecture plays a pivotal role in both performance and scalability. Managed Kubernetes providers like Amazon Elastic Kubernetes Service and Google Cloud often offer architectural best practices immediately. These can include optimized node configurations, efficient resource allocation, and even bare-metal servers for those who require it. Atlantic.Net can also provide dedicated and bare-metal servers. However, understanding these architectural choices is crucial, as they can significantly impact your application’s performance and overall cloud computing expenditure. ## Managed Kubernetes: Beyond the Basics Managed K8s Services often go beyond basic container orchestration. These services, including Tanzu Kubernetes Grid and Alibaba Cloud Container Service, offer additional features like built-in CI/CD pipelines, advanced monitoring dashboards, and integrated logging solutions. These features enhance operational efficiency and provide deeper insights into your Kubernetes environment. They can include built-in monitoring and health monitoring features that can be crucial for managing application availability. ## The Role of AI and Machine Learning in Managed Kubernetes Services Artificial Intelligence (AI) and Machine Learning (ML) are increasingly integrated into Managed K8s Services. These technologies enable predictive scaling, intelligent anomaly detection, and automated resource optimization. By leveraging AI and ML, businesses can achieve more efficient resource utilization and faster issue resolution. This is particularly true in fully managed Kubernetes solutions, where automated lifecycle management improves applications’ overall reliability and performance. ## Managed Kubernetes and Multi-Cloud Strategies The rise of multi-cloud architectures has added another layer of complexity to managing Kubernetes clusters. Managed Kubernetes Services, including those from major cloud services providers like AWS Cloud and Azure, often offer multi-cloud support. This allows you to run Kubernetes across different cloud providers seamlessly, from AWS infrastructure to Azure to Google Cloud. This capability is particularly beneficial for businesses looking to avoid vendor lock-in and optimize costs across multiple cloud environments. ## Popular Kubernetes Cluster Providers Google Kubernetes Engine (GKE) is a fully managed service that allows organizations to easily create production-ready clusters. It offers robust features, including advanced access management and a user-friendly Kubernetes dashboard. GKE is built on upstream Kubernetes, ensuring compatibility with standard Kubernetes toolchains. This makes it a go-to Kubernetes provider for those already invested in Google’s ecosystem. Azure Kubernetes Service (AKS) is Microsoft’s hosted Kubernetes service that simplifies deploying a managed cluster in Azure. One of its standout features is how Azure handles critical tasks like maintenance and upgrades without manual intervention. AKS integrates seamlessly with Azure’s suite of services, including Azure Virtual Machines and Amazon Virtual Private Cloud, providing a comprehensive solution for businesses. The service also offers robust control configurations, making managing and scaling clusters according to demand easier. ## Popular Hybrid Managed Kubernetes Services VMware Tanzu Kubernetes Grid (TKG) offers a unique approach to Kubernetes, especially for businesses that operate both on-premises and in the public cloud. TKG is designed to run on various infrastructures, including vSphere, AWS resources, and even Azure, making it a versatile choice. VMware Tanzu Kubernetes Grid provides a consistent, upstream-compatible environment for Kubernetes across different data centers and cloud environments. This allows organizations to manage their clusters through a single control plane, regardless of where they are deployed. Tanzu Kubernetes Grid also integrates well with Amazon EKS, which automatically manages certain aspects of your clusters, freeing up resources for other critical tasks. Like GKE and AKS, Tanzu also allows for the creation of production-ready clusters that can be automatically scaled as needed. This is particularly useful for businesses with fluctuating workloads and requiring the ability to scale clusters up or down quickly. ## The Economics of Managed Kubernetes: ROI and TCO Insights Understanding the economic impact of adopting a Managed Kubernetes Service is vital. While the upfront costs may be higher than a DIY approach, the total cost of ownership (TCO) often favors [managed services](https://www.atlantic.net/managed-services/what-are-managed-services/). This is particularly true when you factor in operational efficiencies, reduced downtime, and quicker time-to-market. Managed services, including Amazon Elastic Kubernetes Service and Azure Kubernetes Service (AKS), often handle critical tasks like load balancing and networking resources, providing a fully supported Kubernetes solution that can offer a better ROI in the long run. ## Securing Your K8s Cluster in a Managed Service Environment Security remains a paramount concern in Kubernetes. Managed services often have built-in security features like automated patching, role-based access control, and integrated firewalls. These services, whether they are from Google Cloud or third-party providers, align with various compliance requirements, ensuring that your data and applications are adequately protected. Features like networking and security services can be particularly beneficial. ## Managed Kubernetes: A Guide to Disaster Recovery and High Availability Ensuring high availability and robust disaster recovery mechanisms are critical aspects of any Kubernetes deployment. Managed K8s Services often offer automated backup solutions and failover capabilities. These services, including those from a cloud provider like Oracle Container Engine and DigitalOcean Kubernetes, ensure that your applications remain available even in the event of hardware failure or other catastrophic events. They often come with features like service discovery and associated storage solutions that can be crucial for maintaining business continuity. ## The Future of Managed Kubernetes: What to Expect in the Next Five Years As Kubernetes continues to evolve, so will the landscape of Managed K8s Services. We can expect to see further integration of AI and ML technologies, more robust multi-cloud support, and increasingly sophisticated security features. Businesses that stay ahead of these trends and adapt their Kubernetes strategies accordingly will be better positioned to leverage the full potential of this powerful orchestration platform. This will likely include more flexible deployment options, enhanced node management, and the ability to attach multiple nodes to existing infrastructure. ## Running Kubernetes Clusters on Atlantic.Net with Minikube Minikube is an open-source tool designed to enable developers to run Kubernetes clusters on individual servers. Developed as part of the [Kubernetes project](https://www.atlantic.net/dedicated-server-hosting/how-to-deploy-kubernetes-cluster-with-minikube-on-ubuntu-20-04/), minikube aims to provide a convenient way for developers to test and develop applications in a Kubernetes environment without requiring a full-scale, production-level cluster. It essentially creates a virtual machine on your local system and deploys a simple cluster containing a single node. The primary advantage of using minikube is its simplicity and ease of use. It offers a straightforward way to get a Kubernetes cluster up and running, making it an ideal choice for those who are new to the Kubernetes ecosystem or for developers who want to test their applications in a controlled environment. Minikube supports various hypervisors like VirtualBox, VMware Fusion, Hyper-V, and container runtimes like Docker. Another notable feature is its compatibility with various Kubernetes features and components, such as DNS, NodePorts, ConfigMaps, and Secrets. This allows developers to simulate a production-like environment on their local machines, facilitating more accurate testing and development. To manage the local cluster, minikube provides a command-line interface allowing users to start, stop, and manage their Kubernetes clusters. It also integrates seamlessly with kubectl, the command-line tool for interacting with a Kubernetes cluster, offering a cohesive experience for cluster management. Experience the power of Kubernetes with minikube on Atlantic.Net. Our cloud and dedicated servers provide the perfect environment for you to deploy your minikube cluster, offering you a streamlined, efficient way to manage your containerized applications. Elevate your DevOps game—get started with [Atlantic.Net today](https://www.atlantic.net/about-us/corporate-contact/)! --- # Optimizing Costs in the Cloud: VMs vs. VPS vs. Bare Metal > URL: https://www.atlantic.net/dedicated-server-hosting/optimizing-costs-in-the-cloud-vms-vs-vps-vs-bare-metal/ | Published: 2023-11-04 | Updated: 2025-09-10 | Author: Gilad Maayan Cloud cost optimization is the process of reducing your overall cloud spending by identifying mismanaged resources, eliminating waste, reserving capacity for higher discounts, and right-sizing computing services to scale. The objective is to understand cloud spending and usage, and then take strategic action to control and optimize expenses. This process is critical for businesses to ensure they are getting the most value from their cloud investment. Read this in-depth blog post for [more background on cloud cost optimization](https://spot.io/resources/cloud-optimization/cloud-optimization-the-4-things-you-must-optimize/). Cutting down on unnecessary costs doesn’t mean compromising on the quality of services. It’s about smart management and making the most of what you have. Let’s see how the principles of cloud cost optimization apply to three common cloud deployment models: VM, VPS, and bare metal servers. ## Three Options for Running Servers in the Cloud ### Virtual Private Servers (VPS) A Virtual Private Server (VPS) is a virtual machine sold as a service by an internet hosting service. A VPS runs its copy of an operating system, and customers have superuser-level access to that operating system instance, allowing them to install almost any software that runs on that OS. VPS provides a higher level of control compared to shared hosting. ### Virtual Machines (VMs) Virtual Machines (VMs) are emulations of computer systems. They can run applications and operating systems just like a physical computer. VMs are often used in cloud computing platforms to provide computing resources. They are a critical part of the infrastructure-as-a-service (IaaS) cloud service model. ### Bare Metal Bare Metal refers to a physical server dedicated to a single tenant, contrary to the concept of a virtual server that shares resources with other users. Although it is less flexible than its virtual counterparts, bare metal provides high performance and is ideal for data-intensive workloads that require superior processing power. ## VMs vs. VPS vs. Bare Metal: What Are the Differences? Now that we’ve understood the key concepts let’s delve into the specifics of each and how they impact your cloud costs. ### Pricing Models When it comes to VMs, VPS, and Bare Metal, their pricing models differ significantly. VMs and VPS usually have a pay-as-you-go pricing model, meaning you pay for what you use. On the other hand, Bare Metal servers often require a significant upfront investment but can be more cost-effective in the long run for high-demand applications. ### Performance and Resource Allocation Performance and resource allocation are other factors that play a significant role in the cost. VMs and VPS offer a shared resource environment where the physical server’s resources are divided among multiple users. On the other hand, Bare Metal servers provide dedicated resources, resulting in better performance but at a higher cost. ### Scalability and Flexibility Scalability and flexibility are key factors to consider when choosing between VMs, VPS, and Bare Metal. VMs and VPS offer a high degree of scalability and flexibility, allowing you to easily scale up or down based on your business needs. Bare Metal servers, on the other hand, offer less flexibility but provide a higher level of performance. ## VMs, VPS, and Bare Metal: Cost Optimization Strategies ### 1. Right-Sizing Resources - **Virtual Private Servers (VPS):** Right-sizing in a VPS context typically involves choosing the best plan that aligns with your resource requirements. You can adjust CPU, memory, and storage allocations based on your specific use case. Upgrading or downgrading is usually straightforward, allowing for dynamic resource management. - **Virtual Machines (VMs):** Cloud platforms often offer various VM types tailored for different needs—compute-optimized, memory-optimized, etc. Right-sizing here would involve choosing the correct VM type and scaling your VM instances according to your application’s demands. Dynamic resource allocation is often possible, allowing you to adapt to changing requirements without any downtime. - **Bare Metal:** Since these servers are not virtualized and are dedicated to a single tenant, right-sizing typically involves a more in-depth hardware selection process. The process is often less flexible and may require longer-term commitments. Make sure to evaluate your needs carefully before making a choice to avoid overprovisioning and unnecessary costs. ### 2. Managing Storage Costs - **VPS:** Storage costs can escalate quickly if not managed well. VPS usually offers various storage options like SSDs or HDDs. Choose the type of storage based on your application’s needs—SSDs for high-speed data access or HDDs for cheaper, less-critical data storage. - **VMs:** Similar to VPS, you can choose between high-performance SSDs and cost-effective HDDs. Additionally, many cloud providers offer cold or archival object storage services, which can be a cost-effective solution for infrequently accessed data. - **Bare Metal:** Bare Metal servers usually allow for extensive storage customization. High-performance RAID configurations or large-scale HDD deployments can be optimized for cost depending on the workload requirements. ### 3. Monitoring and Analyzing Usage - **VPS:** Most VPS providers offer built-in monitoring tools that can track CPU usage, data transfer, and disk utilization. Regularly checking these metrics can help you identify underutilized resources and allow you to downgrade or upgrade your plan accordingly. - **VMs:** Monitoring and logging services are usually more extensive for VMs, giving insights into not only resource usage but also network performance, application errors, etc. Utilize these metrics to identify inefficiencies and optimize configurations. - **Bare Metal:** Given that Bare Metal servers are often used for resource-intensive tasks, robust monitoring systems are essential. These could include hardware-level monitoring, network usage stats, and application performance metrics. Use this data to fine-tune your environment and potentially save costs. ### 4. Leveraging Reserved Instances and Discounts - **VPS:** Some providers offer discounts for long-term commitments. If your usage pattern is predictable, committing to a one or three-year plan can save substantial amounts. - **VMs:** Cloud providers often offer reserved instances, which come at a significantly lower cost if you can commit to a long-term contract. Additionally, they may offer spot instances—temporary resources at lower costs—that can be beneficial for non-critical, ephemeral workloads. - **Bare Metal:** Given the significant upfront costs, long-term contracts are standard in the Bare Metal environment. However, discounts can be negotiated for long-term commitments or high-volume usage. ### 5. Consider Total Cost of Ownership (TCO) - **VPS:** The TCO includes not just the cost of the server but also the overheads for maintenance, security, and potential software licenses. VPS costs are generally more transparent but still require budgeting for these additional costs. - **VMs:** While the compute costs may be straightforward, additional costs can include network transfer fees, additional services like load balancers, and monitoring solutions. Make sure to include these when calculating the TCO. - **Bare Metal:** Bare Metal servers typically have a higher TCO due to initial hardware costs, maintenance, and potential software licenses. However, they may offer better performance per dollar for specific, resource-intensive workloads, making the TCO favorable when considered over an extended period. ## Conclusion Cloud cost optimization is not a one-size-fits-all proposition; rather, it requires a nuanced approach tailored to the specific needs and objectives of each organization. In this article, we examined the three prevalent cloud deployment models—Virtual Private Servers (VPS), Virtual Machines (VMs), and Bare Metal—to understand how each can impact your overall cloud spending. While VPS and VMs offer flexibility and scalability with a pay-as-you-go pricing model, Bare Metal servers excel in providing superior performance, albeit at a higher upfront cost. Right-sizing resources, managing storage costs, monitoring usage, leveraging discounts, and taking into account the total cost of ownership are critical strategies that apply across all three models. The key takeaway is to align your choice of cloud deployment model with your specific business requirements—be it performance, scalability, or cost-effectiveness. Regularly reviewing and adjusting your cloud configurations can result in substantial cost savings without compromising the quality of services. Therefore, whether you’re running a small application or a data-intensive workload, smart management and continuous optimization are vital to getting the most value from your cloud investment. **Author Bio: Gilad David Maayan** Gilad David Maayan is a technology writer who has worked with over 150 technology companies including SAP, Imperva, Samsung NEXT, NetApp and Check Point, producing technical and thought leadership content that elucidates technical solutions for developers and IT leadership. Today he heads [Agile SEO](https://agileseo.co.il/), the leading marketing agency in the technology industry. --- # How to Add PHP-FPM Support on Apache and Nginx Web Server on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-add-php-fpm-support-on-apache-and-nginx-web-server-on-ubuntu/ | Published: 2023-11-28 | Updated: 2025-12-13 | Author: Hitesh Jethva Apache and Nginx are free, open-source, and popular – the most widely used web servers worldwide. Apache and Nginx both run on all Unix-based operating systems. Apache is known for its power, while Nginx is known for its speed. Nginx is also used as a reverse proxy for HTTP, HTTPS, IMAP, SMTP, and POP3 and as a load balancer. PHP-FPM (FastCGI Process Manager) is an alternative PHP FastCGI implementation specially designed for high-loaded websites. PHP-FPM allows you to run multiple versions of PHP at a time. PHP-FPM can be run differently than mod_PHP on a web server. If you want to host your web application with optimal performance, then PHP-FPM is the best choice. This tutorial will explain how to enable PHP-FPM support on Apache and Nginx web servers on Ubuntu. This procedure is compatible with Ubuntu 18.04, Ubuntu 22.04, Ubuntu 24.04 and Fedora 41. ## Add PHP-FPM Support on Apache and Nginx Web Server on Ubuntu In this section, we will show you how to enable PHP-FPM support on both Nginx and Apache web servers. ### Enable PHP-FPM Support on the Apache Web Server This section will teach us how to install and enable PHP-FPM support on the Apache web server. #### Step 1 – Install and Configure Apache and PHP-FPM First, install Apache and PHP-FPM by running the following command: ``` apt-get update -y apt-get install apache2 libapache2-mod-php libapache2-mod-fcgid php php-fpm php-cli -y ``` Once all the packages are installed, start the Apache and PHP-FPM service with the following command: ``` systemctl start apache2 systemctl start php8.3-fpm ``` **Note:** Replaced php8.3-fpm with your installed PHP version. Next, you will need to configure the Apache web server with PHP-FPM support. To do so, create a new Apache virtual host configuration file: ``` nano /etc/apache2/sites-available/example.com.conf ``` Add the following lines: ```     ServerAdmin admin@example.com     DocumentRoot /var/www/html/     DirectoryIndex info.php     ServerName apache.example.com             Options Indexes FollowSymLinks MultiViews        AllowOverride All        Order allow,deny        allow from all                # 2.4.10+ can proxy to unix socket         SetHandler "proxy:unix:/run/php/php8.3-fpm.sock|fcgi://localhost"         ErrorLog ${APACHE_LOG_DIR}/example.com_error.log     CustomLog ${APACHE_LOG_DIR}/example.com_access.log combined ``` **Note:** Replaced php8.3-fpm with your installed PHP version. Save and close the file. Then, enable the virtual host configuration file with the following command: ``` a2ensite apache.example.com ``` Next, you will need to enable a few modules for Apache2 to work with PHP-FPM: ``` a2enmod actions fcgid alias proxy_fcgi ``` Next, restart the Apache service using the following command: ``` systemctl restart apache2 ``` #### Step 2 – Test Apache Web Server Apache webserver is now configured with PHP-FPM support. It’s time to test whether PHP-FPM is loaded with Apache webserver or not. To test it, create a sample info.php file inside the Apache document root directory: ``` nano /var/www/html/info.php ``` Add the following lines: ``` ``` Save and close the file, then change the ownership of the info.php file to www-data: ``` chown www-data:www-data /var/www/html/info.php ``` Next, open your web browser and type the URL **http://apache.example.com**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2023/11/p1.png)     The above page indicates that PHP-FPM is loaded with the Apache web server. **Note:** Don’t forget to remove the info.php file after testing. ### Enable PHP-FPM Support on the Nginx Web Server This section will teach us how to install and enable PHP-FPM support on the Nginx web server. #### Step 1 – Install and Configure Nginx and PHP-FPM First, install Nginx and PHP-FPM by running the following command: ``` apt-get install nginx php php-fpm php-cli -y ``` Once all the packages are installed, start Nginx and PHP-FPM service with the following command: ``` systemctl start nginx systemctl start php7.2-fpm ``` Next, you will need to configure the Nginx web server with PHP-FPM support. To do so, create a new Nginx virtual host configuration file: ``` nano /etc/nginx/sites-available/example.com.conf ``` Add the following lines: ``` server {        listen 80;        root /var/www/html/;        index info.php;        server_name nginx.example.com;         location ~ \.php$ {          fastcgi_split_path_info ^(.+\.php)(/.+)$;          fastcgi_pass unix:/var/run/php/php8.3-fpm.sock;          fastcgi_index index.php;          include fastcgi_params;          fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;          fastcgi_intercept_errors off;          fastcgi_buffer_size 16k;          fastcgi_buffers 4 16k;          fastcgi_connect_timeout 600;          fastcgi_send_timeout 600;          fastcgi_read_timeout 600;        }    location / {       try_files $uri $uri/ =404;   } } ``` **Note:** Replaced php8.3-fpm with your installed PHP version. Save and close the file. Then, enable the Nginx virtual host with the following command: ``` ln -s /etc/nginx/sites-available/example.com.conf /etc/nginx/sites-enabled/ ``` Next, restart the Nginx and PHP-FPM service to apply the configuration changes: ``` systemctl restart nginx systemctl restart php7.2-fpm ``` #### Step 2 – Test Nginx Web Server The Nginx web server is now configured with PHP-FPM support. It’s time to test whether PHP-FPM is loaded with the Nginx web server or not. To test it, create a sample info.php file in the Nginx document root directory: ``` nano /var/www/html/info.php ``` Add the following lines: ``` ``` Save and close the file, then change the ownership of the info.php file to www-data: ``` chown www-data:www-data /var/www/html/info.php ``` Next, open your web browser and type the URL **http://nginx.example.com**. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2023/11/p2-1.png)   The above page indicates that PHP-FPM is loaded with the Nginx webserver. **Note:** Don’t forget to remove the info.php file after testing. ## Add PHP-FPM Support on Apache and Nginx Web Server on Fedora In this section, we will show you how to enable PHP-FPM support on both Nginx and Apache web servers. ### Enable PHP-FPM Support on the Nginx Web Server Here, we will show you how to enable PHP-FPM support on the Nginx Web Server on Fedora. #### Step 1 – Install and Configure Nginx and PHP-FPM First, you will need to install the Nginx server and PHP-FPM package on your server. You can install it using the following command. ``` dnf install nginx php php-cli php-common php-fpm -y ``` Once the Nginx package is installed, start and enable the Nginx and PHP-FPM server with the following command. ``` systemctl start nginx php-fpm systemctl enable nginx php-fpm ``` You can check the status of the PHP-FPM service with the following command. ``` systemctl status php-fpm ``` You will see the following output. ``` ● php-fpm.service - The PHP FastCGI Process Manager Loaded: loaded (/usr/lib/systemd/system/php-fpm.service; disabled; vendor preset: disabled) Active: active (running) since Tue 2025-12-10 01:06:35 EDT; 3s ago Main PID: 6994 (php-fpm) Status: "Ready to handle connections" Tasks: 6 (limit: 2328) Memory: 10.0M CPU: 74ms CGroup: /system.slice/php-fpm.service ├─6994 php-fpm: master process (/etc/php-fpm.conf) ├─6995 php-fpm: pool www ├─6996 php-fpm: pool www ├─6997 php-fpm: pool www ├─6998 php-fpm: pool www └─6999 php-fpm: pool www ``` Next, you will need to configure Nginx to run PHP with FPM. First, create a document root directory for your site. ``` mkdir -p /var/www/html/ ``` Next, create a sample info.php file. ``` nano /var/www/html/info.php ``` Add the following code: ``` ``` Save and close the file, then set proper ownership to info.php file. ``` chown -R nginx: /var/www/html/info.php ``` Next, create an Nginx virtual host configuration file. ``` nano /etc/nginx/conf.d/example.conf ``` Add the following configuration: ``` server { listen 80; server_name nginx.example.com; root /var/www/html/; index info.php; access_log /var/log/nginx/example.com.access.log; error_log /var/log/nginx/example.com.error.log; location ~ \.php$ { try_files $uri =404; fastcgi_pass unix:/run/php-fpm/www.sock; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg)$ { expires max; log_not_found off; } } ``` Save and close the file, then verify the Nginx for any syntax errors. ``` nginx -t ``` Finally, restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` #### Step 2 – Verify the Nginx At this point, Nginx is configured to work with PHP-FPM. Now, open your web browser and verify your setup using the URL **http://nginx.example.com.** You will see your PHP information page on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/11/p1-1.png) ### Enable PHP-FPM Support on the Apache Web Server Here, we will show you how to enable PHP-FPM support on the Apache Web Server on Fedora. #### Step 1 – Install  and Configure Apache and PHP-FPM First, you will need to install the Apache server and the PHP-FPM package on your server. You can install it using the following command. ``` dnf install httpd php php-cli php-common php-fpm -y ``` Once the Apache package is installed, start and enable the Apache and PHP-FPM server with the following command. ``` systemctl start httpd php-fpm systemctl enable httpd php-fpm ``` ``` Next, you will need to configure Apache to run PHP with FPM. First, create a document root directory for your site. ``` ``` mkdir -p /var/www/html/ ``` Next, create a sample info.php file. ``` nano /var/www/html/info.php ``` Add the following code: ``` ``` Save and close the file, then set proper ownership to info.php file. ``` chown -R Apache: /var/www/html/info.php ``` Next, create an Apache virtual host configuration file. ``` nano /etc/httpd/conf.d/example.conf ``` Add the following configuration: ``` ServerAdmin admin@example.com DocumentRoot /var/www/html/ DirectoryIndex info.php ServerName apache.example.com Options Indexes FollowSymLinks MultiViews AllowOverride All Order allow,deny allow from all SetHandler "proxy:unix:/run/php-fpm/www.sock|fcgi://localhost" ErrorLog /var/log/httpd/example.com_error.log CustomLog /var/log/httpd/example.com_access.log combined ``` Finally, restart the Apache service to apply the changes. ``` systemctl restart httpd ``` #### Step 2 – Verify the Apache At this point, Apache is configured to work with PHP-FPM. Now, open your web browser and verify your setup using the URL **http://apache.example.com.** You will see your PHP information page on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/11/p2-2.png) ## Conclusion Congratulations! You have successfully configured Nginx and Apache web servers with PHP-FPM support. I hope you now have enough knowledge to use PHP-FPM to run multiple versions of PHP at a time. To start with PHP-FPM on Apache and Nginx, sign up for a [VPS Hosting](https://www.atlantic.net/vps-hosting/) plan with Atlantic.Net today. --- # Detect Linux Security Holes and Rootkits with Rkhunter on Ubuntu > URL: https://www.atlantic.net/dedicated-server-hosting/detect-linux-security-holes-and-rootkits-with-rkhunter-on-ubuntu/ | Published: 2023-11-28 | Updated: 2025-05-19 | Author: Hitesh Jethva Rkhunter is a command-line utility that scans the local system for rootkits, backdoors, and possible local exploits. It also checks for hidden files, wrong permissions set on binaries, suspicious strings in the kernel, and many more potential security problems. Rkhunter works by comparing local files with hashes in an online database. It scans the Linux systems to determine if any rootkits infect the server. This tutorial will show you how to install and use Rkhunter to scan and detect security holes in Ubuntu. This procedure is compatible with Ubuntu 22.04 and Ubuntu 24.04. ## Step 1 – Install Rkhunter By default, Rkhunter is available in the Ubuntu 20.04 default repository. You can install it with the following commands: ``` apt-get update -y ``` ``` apt-get install rkhunter -y ``` Now, verify the installed version of Rkhunter with the following command: ``` rkhunter --version ``` You should get the following output: ``` Rootkit Hunter 1.4.6 ``` ## Step 2 – Configure Rkhunter Before starting, you will need to configure Rkhunter to scan your system. You can configure it by editing the file /etc/rkhunter.conf: ``` nano /etc/rkhunter.conf ``` Change the following lines: ``` UPDATE_MIRRORS=1 MIRRORS_MODE=0 WEB_CMD="" ``` Save and close the file when you are finished. Next, you must create /etc/default/rkhunter.conf file to automatically set up regular scans and updates with a cron job. ``` nano /etc/default/rkhunter.conf ``` Change the following lines: ``` CRON_DAILY_RUN="true" CRON_DB_UPDATE="true" APT_AUTOGEN="true" ``` Save and close the file when you are finished. Next, run the following command to verify any configuration errors: ``` rkhunter -C ``` ## Step 3 – Update the Database Rkhunter uses text data files to find suspicious activities on the system, so you must first update the text data file. You can edit it with the following command: ``` rkhunter --update ``` You should get the following output: ``` [ Rootkit Hunter version 1.4.6 ] Checking rkhunter data files... Checking file mirrors.dat                                  [ Updated ] Checking file programs_bad.dat                             [ No update ] Checking file backdoorports.dat                            [ No update ] Checking file suspscan.dat                                 [ No update ] Checking file i18n/cn                                      [ Skipped ] Checking file i18n/de                                      [ Skipped ] Checking file i18n/en                                      [ No update ] Checking file i18n/tr                                      [ Skipped ] Checking file i18n/tr.utf8                                 [ Skipped ] Checking file i18n/zh                                      [ Skipped ] Checking file i18n/zh.utf8                                 [ Skipped ] Checking file i18n/ja                                      [ Skipped ] ``` Next, update the Rkhunter data file with the current value by running the following command: ``` rkhunter --propupd ``` You should get the following output: ``` [ Rootkit Hunter version 1.4.6 ] File updated: searched for 179 files, found 135 ``` ## Step 4 – Start a System Check with Rkhunter At this point, Rkhunter is installed and configured. Now, perform the test scan against your system with the following command: ``` rkhunter --check ``` You should get the following output: ![](https://www.atlantic.net/wp-content/uploads/2021/01/rkhunter4-1.png) If you want to display only warning messages in the output, run the following command: ``` rkhunter --check --rwo ``` You should get the following output: ``` Warning: The SSH and rkhunter configuration options should be the same: SSH configuration option 'PermitRootLogin': yes Rkhunter configuration option 'ALLOW_SSH_ROOT_USER': no Warning: Suspicious file types found in /dev: /dev/shm/PostgreSQL.613016838: data ``` ## Step 5 – Setup Email Notifications It is also recommended to enable email notifications so that Rkhunter sends an email if a threat is found on your system. ``` nano /etc/rkhunter.conf ``` Change the following line: ``` MAIL-ON-WARNING=root@localhost ``` Save and close the file when you are finished. ## Conclusion Congratulations! You have successfully installed and configured Rkhunter on the Ubuntu 24.04 server. I hope you can now easily find backdoors and malware with rkhunter. After making any changes in your system, we recommend running the **rkhunter –propupd**command to update rkhunter to the new file properties. Try out Rkhunter on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Set up APT-Caching Server Using Apt-Cacher NG on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-set-up-apt-caching-server-using-apt-cacher-ng-on-ubuntu/ | Published: 2023-11-28 | Updated: 2025-05-24 | Author: Hitesh Jethva Apt-Cacher NG is a caching proxy server for Debian-based Linux distributions including Ubuntu, Debian, Linux Mint, etc. It creates a local cache of the Debian mirrors and other Linux distributions. When you use the apt command to install any package, the package is pulled from the official repositories, and the APT cache server caches that package in the system. When you install the same package again, it will download that package from the local caching server. This will save you a lot of time and internet bandwidth. In this post, we will explain how to set up an APT-Caching server using Apt-Cacher NG on Ubuntu. This procedure is compatible with Ubuntu 22.04 and Ubuntu 24.04. ## Step 1 – Install Apt-Cacher-NG By default, the Apt-Cacher-NG package is included in the Ubuntu default repository. You can install it using the following command: ``` apt-get update -y apt-get install apt-cacher-ng -y ``` Once the Apt-Cacher-NG package is installed, start the Apt-Cacher-NG service and enable it to start at system reboot: ``` systemctl start apt-cacher-ng systemctl enable apt-cacher-ng ``` You can check the status of Apt-Cacher-NG with the following command: ``` systemctl status apt-cacher-ng ``` Sample output: ``` ● apt-cacher-ng.service - Apt-Cacher NG software download proxy Loaded: loaded (/usr/lib/systemd/system/apt-cacher-ng.service; enabled; preset: enabled) Active: active (running) since Sat 2025-05-24 06:30:37 AST; 10s ago Main PID: 490755 (apt-cacher-ng) Tasks: 1 (limit: 4609) Memory: 2.1M (peak: 2.3M) CPU: 17ms CGroup: /system.slice/apt-cacher-ng.service └─490755 /usr/sbin/apt-cacher-ng -c /etc/apt-cacher-ng ForeGround=1 ``` By default, Apt-Cacher-NG listens on port 3142. You can check it with the following command: ``` ss -altnp | grep apt ``` Sample output: ``` LISTEN 0 250 0.0.0.0:3142 0.0.0.0:* users:(("apt-cacher-ng",pid=3748,fd=10)) LISTEN 0 250 [::]:3142 [::]:* users:(("apt-cacher-ng",pid=3748,fd=11)) ``` ## Step 2 – Configure Apt-Cacher-NG By default, Apt-Cacher NG does not serve HTTPS repositories, so you will need to enable it. To do so edit the Apt-Cacher-NG default configuration file: ``` nano /etc/apt-cacher-ng/acng.conf ``` Uncomment the following line: ``` PassThroughPattern: .* ``` Save and close the file, then restart the Apt-Cacher-NG service to apply the changes: ``` systemctl restart apt-cacher-ng ``` ## Step 3 – Configure Client System to use Apt-Cacher NG By default, all Ubuntu system uses Ubuntu repository to download and install packages, so you will need to configure your client system to use Apt-Cacher NG for package installation. To do so, create a new proxy configuration file: ``` nano /etc/apt/apt.conf.d/00aptproxy ``` Add the following line: ``` Acquire::http::Proxy "http://your-server-ip:3142"; ``` Save and close the file when you are finished. ## Step 4 – Verify APT-Cacher NG Now, let’s try to install the Apache package on the Client system using the following command: ``` apt-get install apache2 -y ``` The above command will find, download, and install an Apache package from the Apt-Cache NG server. You can check it using the following command on the server system: ``` tail -f /var/log/apt-cacher-ng/apt-cacher.log ``` Sample output: ``` 1629012079|I|91694|69.87.221.199|uburep/pool/main/a/apr/libapr1_1.6.5-1ubuntu1_amd64.deb 1629012079|O|91685|69.87.221.199|uburep/pool/main/a/apr/libapr1_1.6.5-1ubuntu1_amd64.deb 1629012079|I|85057|69.87.221.199|uburep/pool/main/a/apr-util/libaprutil1_1.6.1-4ubuntu2_amd64.deb 1629012079|O|85058|69.87.221.199|uburep/pool/main/a/apr-util/libaprutil1_1.6.1-4ubuntu2_amd64.deb 1629012079|I|10880|69.87.221.199|uburep/pool/main/a/apr-util/libaprutil1-dbd-sqlite3_1.6.1-4ubuntu2_amd64.deb 1629012079|O|10894|69.87.221.199|uburep/pool/main/a/apr-util/libaprutil1-dbd-sqlite3_1.6.1-4ubuntu2_amd64.deb 1629012079|I|9071|69.87.221.199|uburep/pool/main/a/apr-util/libaprutil1-ldap_1.6.1-4ubuntu2_amd64.deb 1629012079|O|9078|69.87.221.199|uburep/pool/main/a/apr-util/libaprutil1-ldap_1.6.1-4ubuntu2_amd64.deb 1629012079|I|29280|69.87.221.199|uburep/pool/main/j/jansson/libjansson4_2.12-1build1_amd64.deb 1629012079|O|29279|69.87.221.199|uburep/pool/main/j/jansson/libjansson4_2.12-1build1_amd64.deb 1629012079|I|1180480|69.87.221.199|uburep/pool/main/a/apache2/apache2-bin_2.4.41-4ubuntu3.4_amd64.deb 1629012079|O|1180482|69.87.221.199|uburep/pool/main/a/apache2/apache2-bin_2.4.41-4ubuntu3.4_amd64.deb 1629012079|I|158846|69.87.221.199|uburep/pool/main/a/apache2/apache2-data_2.4.41-4ubuntu3.4_all.deb 1629012079|O|158848|69.87.221.199|uburep/pool/main/a/apache2/apache2-data_2.4.41-4ubuntu3.4_all.deb 1629012079|I|84349|69.87.221.199|uburep/pool/main/a/apache2/apache2-utils_2.4.41-4ubuntu3.4_amd64.deb 1629012079|O|84354|69.87.221.199|uburep/pool/main/a/apache2/apache2-utils_2.4.41-4ubuntu3.4_amd64.deb 1629012079|I|95853|69.87.221.199|uburep/pool/main/a/apache2/apache2_2.4.41-4ubuntu3.4_amd64.deb 1629012079|O|95852|69.87.221.199|uburep/pool/main/a/apache2/apache2_2.4.41-4ubuntu3.4_amd64.deb 1629012079|I|17288|69.87.221.199|uburep/pool/main/s/ssl-cert/ssl-cert_1.0.39_all.deb 1629012079|O|17277|69.87.221.199|uburep/pool/main/s/ssl-cert/ssl-cert_1.0.39_all.deb ``` Apt-Cache NG also provides a web-based interface to display all reports. You can access it using the URL **http://your-server-ip:3142/acng-report.html**. You should see the following screen: ![APT-Cache NG Dashboard Page](https://www.atlantic.net/wp-content/uploads/2021/08/p1-7.png) ## Step 5 – Control Apt-Cacher NG Usage You can also set up access control for Apt-Cache NG so that only authenticated hosts can download the package from the Apt-Cacher NG server. You can use the /etc/hosts.allow and /etc/hosts.deny for controling access. For example, to allow 192.168.0.10 and 192.168.0.11 to use Apt-Cacher NG server, edit the /etc/hosts.allow file: ``` nano /etc/hosts.allow ``` Add the following line: ``` apt-cacher-ng : 192.168.0.10 192.168.0.11 ``` Save and close the file when you are finished. If you want to block the host 192.168.1.100 to use Apt-Cacher NG server, edit the /etc/hosts.deny file: ``` nano /etc/hosts.deny ``` Add the following line: ``` apt-cacher-ng : 192.168.1.100 ``` Save and close the file when you are finished. ## Conclusion In the above guide, we explained how to install and use Apt-Cache NG server on Ubuntu 24.04 server. You can now set up Apt-Cache NG in your local network to save a lot of internet bandwidth – try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Configure Postfix as a Send-Only SMTP Server on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-configure-postfix-as-a-send-only-smtp-server-on-ubuntu/ | Published: 2023-11-28 | Updated: 2025-05-14 | Author: Hitesh Jethva A mail server is handy when you own a website or web application and want to send transactional emails to users. Postfix is a free and open-source Mail Transfer Agent used to send and receive emails. Postfix is free, so you don’t need to rely on third-party service providers like Sendgrid or Pepipost. You can easily install and configure Postfix to send emails through your local application. This post will show you how to install and configure Postfix as a Send-Only SMTP server on Ubuntu. This procedure is compatible with Ubuntu 22.04 and Ubuntu 24.04. ## Step 1 – Setup Hostname Before starting, you must set up a fully qualified hostname on your server. You can set it up with the following command: ``` hostnamectl set-hostname email.linuxbuz.com ``` Next, edit the/etc/hosts file and add the following line: ``` nano /etc/hosts ``` Add the following line: ``` your-server-ip email.linuxbuz.com ``` Save and close the file when you are finished. ## Step 2 – Install Postfix The simplest and easiest way to install Postfix is to install a mailutils package to your system. You can install the mailutils package using the following command: ``` apt-get install mailutils -y ``` After the installation, run the following command to configure Postfix: ``` dpkg-reconfigure postfix ``` You will be asked to select the type of mail configuration as shown below: ![Postfix select internet site](https://www.atlantic.net/wp-content/uploads/2021/08/p1-9.png) Select Internet Site and hit **Enter**. You will be asked to provide your mail name as shown below: ![Postfix select domain name](https://www.atlantic.net/wp-content/uploads/2021/08/p2-8-1024x244.png) Provide your domain name and hit **Enter** to finish the installation. Next, check the status of Postfix using the following command: ``` systemctl status postfix ``` ## Step 3 – Configure Postfix as a Send-Only SMTP Server Next, you must configure Postfix to send an email from the local host. You can configure it by editing the Postfix main configuration file: ``` nano /etc/postfix/main.cf ``` Change the following line: ``` inet_interfaces = loopback-only ``` Save and close the file, then set the hostname directly in the Postfix configuration file using the following command: ``` postconf -e "myhostname = email.linuxbuz.com" ``` Next, verify your configured domain name using the following command: ``` postconf mydomain ``` You should get the following output: ``` mydomain = email.linuxbuz.com ``` You must verify the default domain name appended to sender and recipient addresses. ``` postconf myorigin ``` Sample output: ``` myorigin = /etc/mailname ``` Next, display the content of the above file using the following command: ``` cat /etc/mailname ``` You should see your domain in the following output: ``` email.linuxbuz.com ``` Finally, restart the Postfix service to apply the changes: ``` systemctl restart postfix ``` You can also check the status of Postfix with the following command: ``` systemctl status postfix ``` Sample output: ``` ● postfix.service - Postfix Mail Transport Agent Loaded: loaded (/lib/systemd/system/postfix.service; enabled; vendor preset: enabled) Active: active (exited) since Sun 2021-08-15 12:52:44 UTC; 9s ago Process: 4230 ExecStart=/bin/true (code=exited, status=0/SUCCESS) Main PID: 4230 (code=exited, status=0/SUCCESS) Aug 15 12:52:44 ubuntu2004 systemd[1]: Starting Postfix Mail Transport Agent... Aug 15 12:52:44 ubuntu2004 systemd[1]: Finished Postfix Mail Transport Agent. ``` ## Step 4 – Verify Postfix Server At this point, Postfix is installed and configured as a send-only SMTP server. Now, it’s time to send emails to an external email account. You can use the following command to send a simple email to the external email address: ``` echo "This is the body of the email" | mail -s "This is the subject line" user@yourdomain.com ``` You should now see the message in your Inbox or Spam folder. ## Step 5 – Forward System Mail Forwarding all system mail to your external email address is a good idea. This section will set up email forwarding for the root user. Edit the /etc/aliases file: ``` nano /etc/aliases ``` Find the following line: ``` postmaster: root ``` And replace it with the next line: ``` root: user@yourdomain.com ``` Save and close the file, then run the following command to apply the changes: ``` newaliases ``` Now, verify email forwarding by sending an email to the root user: ``` echo "This new email" | mail -s "This is new email" root ``` If everything is fine, you should receive an email at your external email address. ## Conclusion Congratulations! You have successfully set up a Postfix as a send-only SMTP server. You can now use this setup with your application to notify your users via email. Give it a try on your [VPS](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install ClamAV on Ubuntu and Scan for Vulnerabilities > URL: https://www.atlantic.net/vps-hosting/how-to-install-clamav-on-ubuntu-and-scan-for-vulnerabilities/ | Published: 2023-11-28 | Updated: 2025-05-24 | Author: Hitesh Jethva ClamAV is free and open-source antivirus software that can be used to find trojans and malicious software and other viruses in your system. It is simple, easy to use, and capable to scan over one million viruses and trojans. ClamAV supports various archive formats including Tar, Gzip, Zip, Bzip2, OLE2, Cabinet, CHM, BinHex, SIS, and also supports all mail file formats. It comes with several in-built tools, including a multi-threaded daemon and command-line interface to update the database automatically. In this tutorial, we will explain how to install and use ClamAV on Ubuntu. This procedure is compatible with Ubuntu 22.04 and Ubuntu 24.04. ## Step 1 – Install ClamAV By default, the ClamAV package is available in the Ubuntu 24.04 default repository. You can install it with the following command: ``` apt-get install clamav clamav-daemon -y ``` Once the ClamAV has been installed, you can proceed to update the virus database. ## Step 2 – Update the Virus Database Next, you will need to update the virus database in order for scanning to work. You can update it over the internet using the freshclam command. Before updating the database, you will need to stop the clamav-freshclam service. You can stop it with the following command: ``` systemctl stop clamav-freshclam ``` Next, update the database using the following command: ``` freshclam ``` Once the database is updated, you should get the following output: ``` ClamAV update process started at Sat May 24 06:56:25 2025 Sat May 24 06:56:25 2025 -> daily database available for download (remote version: 27647) Time: 1.8s, ETA: 0.0s [========================>] 61.67MiB/61.67MiB Testing database: '/var/lib/clamav/tmp.b9c6b8fb47/clamav-2d3a596f4aab3c1b28c30f9e4a4accc4.tmp-daily.cvd' ... Database test passed. Sat May 24 06:56:47 2025 -> daily.cvd updated (version: 27647, sigs: 2075674, f-level: 90, builder: raynman) Sat May 24 06:56:47 2025 -> main database available for download (remote version: 62) Time: 4.0s, ETA: 0.0s [========================>] 162.58MiB/162.58MiB Testing database: '/var/lib/clamav/tmp.b9c6b8fb47/clamav-63c6479294bf2cb9051abd5fd68e6589.tmp-main.cvd' ... Database test passed. Sat May 24 06:57:14 2025 -> main.cvd updated (version: 62, sigs: 6647427, f-level: 90, builder: sigmgr) Sat May 24 06:57:14 2025 -> bytecode database available for download (remote version: 336) Time: 0.1s, ETA: 0.0s [========================>] 277.52KiB/277.52KiB Testing database: '/var/lib/clamav/tmp.b9c6b8fb47/clamav-6b76e971e17cfc5e0258c20a5d6436e9.tmp-bytecode.cvd' ... Database test passed. Sat May 24 06:57:15 2025 -> bytecode.cvd updated (version: 336, sigs: 83, f-level: 90, builder: nrandolp) ``` Next, start the clamav-freshclam service and enable it to start at system reboot with the following command: ``` systemctl start clamav-freshclam systemctl enable clamav-freshclam ``` By default, freshclam stores all databases inside /var/lib/clamav/ directory. You can list them with the following command: ``` ls /var/lib/clamav/ ```   You should get the following output: ``` bytecode.cvd  daily.cvd  main.cvd ``` ## Step 3 – Use Clamscan to Scan the Directory Clamscan is used to scan files and directories for viruses and delete them immediately. The basic syntax of Clamscan is shown below: ``` clamscan [options] [files-or-directories] ``` A brief explanation of most commonly used options are shown below: - **–infected :** This option display a list of all infected files. - **–remove :** This option removes all infected files from your system. - **–recursive :** This option will scan all directories and sub-directories. For example, you can scan the /etc directory with the following command: ``` clamscan --infected --remove --recursive /etc ``` You should see the following output: ``` ----------- SCAN SUMMARY ----------- Known viruses: 8707441Engine version: 1.0.8Scanned directories: 305Scanned files: 1200Infected files: 0Data scanned: 4.56 MBData read: 2.14 MB (ratio 2.13:1)Time: 67.366 sec (1 m 7 s)Start Date: 2025:05:24 07:00:51End Date: 2025:05:24 07:01:59 ``` You can print all available option with clamscan using the following command: ``` clamscan -h ``` You should get the following output: ```                        Clam AntiVirus: Scanner 0.102.4            By The ClamAV Team: https://www.clamav.net/about.html#credits            (C) 2020 Cisco Systems, Inc.       clamscan [options] [file/directory/-]       --help                -h             Show this help     --version             -V             Print version number     --verbose             -v             Be verbose     --archive-verbose     -a             Show filenames inside scanned archives     --debug                              Enable libclamav's debug messages     --quiet                              Only output error messages     --stdout                             Write to stdout instead of stderr. Does not affect 'debug' messages.     --no-summary                         Disable summary at end of scanning     --infected            -i             Only print infected files     --suppress-ok-results -o             Skip printing OK files     --bell                               Sound bell on virus detection       --tempdir=DIRECTORY                  Create temporary files in DIRECTORY     --leave-temps[=yes/no(*)]            Do not remove temporary files     --gen-json[=yes/no(*)]               Generate JSON description of scanned file(s). JSON will be printed and also-                                          dropped to the temp directory if --leave-temps is enabled.     --database=FILE/DIR   -d FILE/DIR    Load virus database from FILE or load all supported db files from DIR     --official-db-only[=yes/no(*)]       Only load official signatures     --log=FILE            -l FILE        Save scan report to FILE     --recursive[=yes/no(*)]  -r          Scan subdirectories recursively     --allmatch[=yes/no(*)]   -z          Continue scanning within file after finding a match     --cross-fs[=yes(*)/no]               Scan files and directories on other filesystems     --follow-dir-symlinks[=0/1(*)/2]     Follow directory symlinks (0 = never, 1 = direct, 2 = always)     --follow-file-symlinks[=0/1(*)/2]    Follow file symlinks (0 = never, 1 = direct, 2 = always)     --file-list=FILE      -f FILE        Scan files from FILE     --remove[=yes/no(*)]                 Remove infected files. Be careful!     --move=DIRECTORY                     Move infected files into DIRECTORY     --copy=DIRECTORY                     Copy infected files into DIRECTORY     --exclude=REGEX                      Don't scan file names matching REGEX     --exclude-dir=REGEX                  Don't scan directories matching REGEX     --include=REGEX                      Only scan file names matching REGEX     --include-dir=REGEX                  Only scan directories matching REGEX       --bytecode[=yes(*)/no]               Load bytecode from the database     --bytecode-unsigned[=yes/no(*)]      Load unsigned bytecode     --bytecode-timeout=N                 Set bytecode timeout (in milliseconds)     --statistics[=none(*)/bytecode/pcre] Collect and print execution statistics     --detect-pua[=yes/no(*)]             Detect Possibly Unwanted Applications     --exclude-pua=CAT                    Skip PUA sigs of category CAT     --include-pua=CAT                    Load PUA sigs of category CAT     --detect-structured[=yes/no(*)]      Detect structured data (SSN, Credit Card)     --structured-ssn-format=X            SSN format (0=normal,1=stripped,2=both)     --structured-ssn-count=N             Min SSN count to generate a detect     --structured-cc-count=N              Min CC count to generate a detect     --scan-mail[=yes(*)/no]              Scan mail files     --phishing-sigs[=yes(*)/no]          Enable email signature-based phishing detection     --phishing-scan-urls[=yes(*)/no]     Enable URL signature-based phishing detection     --heuristic-alerts[=yes(*)/no]       Heuristic alerts     --heuristic-scan-precedence[=yes/no(*)] Stop scanning as soon as a heuristic match is found     --normalize[=yes(*)/no]              Normalize html, script, and text files. Use normalize=no for yara compatibility     --scan-pe[=yes(*)/no]                Scan PE files     --scan-elf[=yes(*)/no]               Scan ELF files     --scan-ole2[=yes(*)/no]              Scan OLE2 containers     --scan-pdf[=yes(*)/no]               Scan PDF files     --scan-swf[=yes(*)/no]               Scan SWF files     --scan-html[=yes(*)/no]              Scan HTML files     --scan-xmldocs[=yes(*)/no]           Scan xml-based document files     --scan-hwp3[=yes(*)/no]              Scan HWP3 files     --scan-archive[=yes(*)/no]           Scan archive files (supported by libclamav)     --alert-broken[=yes/no(*)]           Alert on broken executable files (PE & ELF)     --alert-encrypted[=yes/no(*)]        Alert on encrypted archives and documents     --alert-encrypted-archive[=yes/no(*)] Alert on encrypted archives     --alert-encrypted-doc[=yes/no(*)]    Alert on encrypted documents     --alert-macros[=yes/no(*)]           Alert on OLE2 files containing VBA macros     --alert-exceeds-max[=yes/no(*)]      Alert on files that exceed max file size, max scan size, or max recursion limit     --alert-phishing-ssl[=yes/no(*)]     Alert on emails containing SSL mismatches in URLs     --alert-phishing-cloak[=yes/no(*)]   Alert on emails containing cloaked URLs     --alert-partition-intersection[=yes/no(*)] Alert on raw DMG image files containing partition intersections     --nocerts                            Disable authenticode certificate chain verification in PE files     --dumpcerts                          Dump authenticode certificate chain in PE files       --max-scantime=#n                    Scan time longer than this will be skipped and assumed clean     --max-filesize=#n                    Files larger than this will be skipped and assumed clean     --max-scansize=#n                    The maximum amount of data to scan for each container file (**)     --max-files=#n                       The maximum number of files to scan for each container file (**)     --max-recursion=#n                   Maximum archive recursion level for container file (**)     --max-dir-recursion=#n               Maximum directory recursion level     --max-embeddedpe=#n                  Maximum size file to check for embedded PE     --max-htmlnormalize=#n               Maximum size of HTML file to normalize     --max-htmlnotags=#n                  Maximum size of normalized HTML file to scan     --max-scriptnormalize=#n             Maximum size of script file to normalize     --max-ziptypercg=#n                  Maximum size zip to type reanalyze     --max-partitions=#n                  Maximum number of partitions in disk image to be scanned     --max-iconspe=#n                     Maximum number of icons in PE file to be scanned     --max-rechwp3=#n                     Maximum recursive calls to HWP3 parsing function     --pcre-match-limit=#n                Maximum calls to the PCRE match function.     --pcre-recmatch-limit=#n             Maximum recursive calls to the PCRE match function.     --pcre-max-filesize=#n               Maximum size file to perform PCRE subsig matching.     --disable-cache                      Disable caching and cache checks for hash sums of scanned files. ``` ## Conclusion In the above guide, you learned how to install ClamAV and use it to remove the various types of viruses from your systems. You should now have enough knowledge to use ClamAV in the production environment to clean the system. Get started with ClamAV today on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Install eSpeak on Ubuntu > URL: https://www.atlantic.net/dedicated-server-hosting/install-espeak-on-ubuntu/ | Published: 2023-11-28 | Updated: 2025-05-19 | Author: Hitesh Jethva eSpeak is free and open-source software that can be used to convert text to voice in English and other languages. It can be installed on Windows and Linux-based operating systems. eSpeak takes input from the string or files and generates an audio format file. You can play this file using any player. In this tutorial, we will show you how to install eSpeak on an Ubuntu 24.04 server. This procedure is compatible with Ubuntu 22.04 and Ubuntu 24.04. ## Step 1 – Install eSpeak By default, this tool is available in all major Linux distributions. You can install it by just running the following command: ``` apt-get install espeak -y ``` Once the installation is finished, verify the installed version of eSpeak with the following command: ``` espeak --version ``` You should get the following output: ``` eSpeak text-to-speech: 1.48.15 16.Apr.15 Data at: /usr/lib/x86_64-linux-gnu/espeak-data ``` ## Step 2 – Generate Audio File with eSpeak Now, let’s speak the line “Hi Welcome to eSpeak” and record it to the file1.mp4 audio file: ``` espeak "Hi Welcome to eSpeak" -w file1.mp4 -g 60 -p 70 -s 100 -v en-us ``` You can now play the **file1.mp4** using any audio player. You can also specify the text file that you want to record in the mp4 format. First, create a sample file named file.txt: ``` nano file.txt ``` Add the following contents: ``` Atlantic Cloud offers hosting solutions customized to your business needs including cloud, managed, dedicated, HIPAA compliant, and more. ``` Save and close the file when you are finished. Next, run the following command to convert **file.txt** to the **mp4** audio format file named **file2.mp4**: ``` espeak -f file.txt -w file2.mp4 -g 60 -p 70 -s 100 -v en-us ``` You can now download file1.mp4 and file2.mp4 to your desktop computer and play both file to test. ## Conclusion In the above guide, you learned how to install eSpeak on Ubuntu 24.04. You can now easily convert any text file into an audio file. Try it today on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Python 3.14 on Rocky Linux > URL: https://www.atlantic.net/vps-hosting/how-to-install-python-3-10-on-rocky-linux/ | Published: 2023-11-28 | Updated: 2025-10-15 | Author: Hitesh Jethva The free and open-source programming language Python is one of the most popular high-level languages and object-oriented applications. Generally, it is used in automation, scripting, data analysis, machine learning, back-end development, handling big data, and performing complex mathematics. Due to its versatile features, it is a popular choice for both beginners and experienced developers. At the time of writing this article, Python 3.14 is the latest version of Python. In this post, we will show you how to install Python 3.14 on Rocky Linux. This procedure is compatible with Rocky Linux 9 and Rocky Linux 10. ## Step 1 – Install Required Dependencies First, you will need to install some dependencies required to compile Python 3.14. You can install all of them by running the following command: ``` dnf install tar curl gcc openssl-devel bzip2-devel libffi-devel zlib-devel wget make -y ``` Once all the dependencies are installed, you can proceed to the next step. ## Step 2 – Install Python 3.14 on Rocky Linux First, go to the Python official download page and download the latest version of Python using the following command: ``` wget https://www.python.org/ftp/python/3.14.0/Python-3.14.0.tar.xz ``` Once the download is completed, extract the downloaded file using the following command: ``` tar -xf Python-3.14.0.tar.xz ``` Next, change the directory to the extracted directory and configure Python using the following command: ``` cd Python-3.14.0 ./configure --enable-optimizations ``` Next, start the build process using the following command: ``` make -j 2 nproc ``` Finally, install Python 3.14 by running the following command: ``` make altinstall ``` After the successful installation, verify the Python installation using the following command: ``` python3.14 --version ``` You will get the following output: ``` Python 3.14.0 ``` ## Step 3 – Create a Virtual Environment in Python Python provides a venv module that allows you to create a virtual environment and deploy your application in an isolated environment. To create a virtual environment named app_env, run the following command: ``` python3.14 -m venv app_env ``` Next, activate the virtual environment using the following command: ``` source app_env/bin/activate ``` You will get the following shell: ``` (app_env) [root@RockyLinux ~]# ``` Now, you can use the PIP package manager to install any package and dependencies inside your virtual environment. For example, run the following command to install apache-airflow: ``` pip3.14 install apache-airflow ``` If you want to remove this package, run the command below: ``` pip3.14 uninstall apache-airflow ``` To exit from the Python virtual environment, run the following command: ``` deactivate ``` ## Conclusion In the above guide, we explained how to install Python 3.14 on Rocky Linux 10. You can now start developing your first application using the Python programming language. Try it today on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install And Setup Suricata IDS on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-setup-suricata-ids-on-ubuntu/ | Published: 2023-11-28 | Updated: 2024-09-25 | Author: Hitesh Jethva Suricata is a free, open-source, robust network threat detection engine developed by the Open Security Foundation. It is capable of real-time intrusion detection, intrusion prevention, and network security monitoring. Suricata comes with a powerful rule set that inspects the network traffic and detects complex threats. It supports all major operating systems including Linux, Windows, FreeBSD, and macOS, and also supports IPv4, IPv6, SCTP, ICMPv4, ICMPv6, and GRE. In this tutorial, we will show you how to install and configure Suricata IDS on Ubuntu. This procedure is compatible with Ubuntu 20.04 and Ubuntu 22.04. ## Step 1 – Install Required Dependencies First, you will need to install some dependencies required to compile Suricata from the source. You can install all of them with the following command: ``` apt-get update -yapt-get install rustc cargo make libpcre3 libpcre3-dbg libpcre3-dev build-essential autoconf automake libtool libpcap-dev libpcre2-dev libnet1-dev libyaml-0-2 libyaml-dev zlib1g zlib1g-dev libcap-ng-dev libcap-ng0 make libmagic-dev libjansson-dev libjansson4 pkg-config -y ``` By default, Suricata functions as an intrusion detection system (IDS). If you want to include intrusion prevention system (IPS) functionality, then you will need to install some more packages in your system. You can install them with the following command: ``` apt-get install libnetfilter-queue-dev libnetfilter-queue1 libnfnetlink-dev libnfnetlink0 -y ``` Once all the packages are installed, you will need to install the suricata-update tool to update the Suricata rules. You can install it with the following commands: ``` apt-get install python3-pip pip3 install --upgrade suricata-update ln -s /usr/local/bin/suricata-update /usr/bin/suricata-update ``` ## Step 2 – Install Suricata First, download the latest version of Suricata from their official website with the following command: ``` wget https://www.openinfosecfoundation.org/download/suricata-5.0.3.tar.gz ``` Once the download is completed, extract the downloaded file with the following command: ``` tar -xvzf suricata-5.0.3.tar.gz ``` Next, change the directory to the extracted directory and configure it with the following command: ``` cd suricata-5.0.3 ./configure --enable-nfqueue --prefix=/usr --sysconfdir=/etc --localstatedir=/var ``` Next, install the Suricata with the following command: ``` make make install-full ``` **Note**: This process will take over 10 minutes Next, install all rules with the following command: ``` make install-rules ``` By default, all rules are located at /var/lib/suricata/rules/suricata.rules: You can see it with the following command: ``` cat /var/lib/suricata/rules/suricata.rules ``` ## Step 3 – Configure Suricata The default Suricata configuration file is located at /etc/suricata/suricata.yaml. You will need to configure it to protect your internal network. You can do it by editing the file: ``` nano /etc/suricata/suricata.yaml ``` Change the following lines: ```     HOME_NET: "[192.168.1.0/24]"     EXTERNAL_NET: "!$HOME_NET" ``` Save and close the file when you are finished. **Note:** In the command above, replace **192.168.1.0/24** with your internal network. ## Step 4 – Test Suricata Against DDoS Before starting, you will need to disable packet offload features on the network interface on which Suricata is listening. First, install ethtool package with the following command: ``` apt-get install ethtool -y ``` Next, disable packet offload with the following command: ``` ethtool -K eth0 gro off lro off ``` Next, run the Suricata in NFQ mode with the following command: ``` suricata -c /etc/suricata/suricata.yaml -q 0 & ``` Next, go to the remote system and perform a simple DDoS attack test against the Suricata server using the hping3 tool as shown below: ``` hping3 -S -p 80 --flood --rand-source your-server-ip ``` On the Suricata server, check the Suricata logs with the following command: ``` tail -f /var/log/suricata/fast.log ``` You should see the following output: ``` 09/17/2020-07:29:52.934009  [**] [1:2402000:5670] ET DROP Dshield Block Listed Source group 1 [**] [Classification: Misc Attack] [Priority: 2] {TCP} 167.248.133.70:18656 -> your-server-ip:9407 ``` ## Conclusion Congratulations! You have successfully installed and configured Suricata IDS and IPS on Ubuntu 20.04 server. You can now explore the Suricata and create your own rules to protect your server from DDoS attack. Get started with Suricata on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net, and for more information, visit the Suricata [documentation](https://suricata.readthedocs.io/en/suricata-5.0.0/setting-up-ipsinline-for-linux.html) page. --- # How to Install Icecast Audio Streaming Server on Ubuntu > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-icecast-audio-streaming-server-on-ubuntu/ | Published: 2023-11-28 | Updated: 2025-05-23 | Author: Hitesh Jethva Icecast is an open-source audio/video streaming server that can be used to create your Internet radio stations. It supports Ogg, Opus, WebM, and MP3 streaming formats. You can also stream your media from your server and access it over the internet. It is optimized for MP3 streaming and allows to handle large music collections. In this tutorial, we will show you how to install Icecast Audio Streaming Server on Ubuntu. This procedure is compatible with Ubuntu 22.04 and Ubuntu 24.04. ## Step 1 – Install Icecast By default, the Icecast package is available in the Ubuntu 24.04 default repository. You can install it by just running the following command: ``` apt-get install icecast2 -y ``` During the installation, you will be asked to configure Icecast as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/11/icecast1.png) Select **Yes** and hit **Enter** to continue. You will be asked to provide a fully qualified domain name: ![](https://www.atlantic.net/wp-content/uploads/2020/11/icecast2.png) Provide your valid domain name and hit **Enter** to continue. You will be asked to set the password to control access to media resources: ![](https://www.atlantic.net/wp-content/uploads/2020/11/icecast3.png) Provide your password and hit **Enter** to continue. You will be asked to set a password to control access to stream relays: ![](https://www.atlantic.net/wp-content/uploads/2020/11/icecast4.png) Provide your password and hit **Enter** to continue. You will be asked to set your administrator password: ![](https://www.atlantic.net/wp-content/uploads/2020/11/icecast5.png) Provide your password and hit **Enter** to finish the installation. Once Icecast is installed, start the Icecast service and enable it to start at system reboot with the following command: ``` systemctl start icecast2 systemctl enable icecast2 ``` At this point, Icecast is started and listening on port 8000. You can check it with the following command: ``` ss -tunelp | grep 8000 ``` You should get the following output: ``` tcp LISTEN 0 5 0.0.0.0:8000 0.0.0.0:* users:(("icecast2",pid=1264,fd=4)) uid:108 ino:20678 sk:8 <-> ``` ## Step 2 – Configure Nginx as a Reverse Proxy for Icecast Next, you will need to install and configure Nginx as a reverse proxy to access Icecast. First, install the Nginx server with the following command: ``` apt-get install nginx -y ``` Once installed, create an Nginx virtual host configuration file: ``` nano /etc/nginx/sites-available/icecast.conf ``` Add the following lines: ``` server { listen 80; listen [::]:80; server_name icecast.example.com; access_log /var/log/nginx/access.log; error_log /var/log/nginx/error.log; location / { proxy_pass http://localhost:8000; } } ``` Save and close the file, then enable the virtual host with the following command: ``` ln -s /etc/nginx/sites-available/icecast.conf /etc/nginx/sites-enabled/ ``` Next, you will also need to set hash bucket size in Nginx main configuration file: ``` nano /etc/nginx/nginx.conf ``` Add the following line inside http {: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 3 – Access Icecast Web UI Now, open your web browser and access the Icecast web interface using the URL **http://icecast.example.com**. You should see the Icecast dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/icecast6.png) Click on the **Administration** tab. You will be redirected to the Icecast login page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/icecast7.png) Provide your admin username and password and click on the **Sign**–**in** button. You should see your Icecast admin dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2023/11/i1.png)   ## Conclusion Congratulations! You have successfully installed and configured the Icecast streaming server on Ubuntu 24.04. You can now install the Icecast application on your computer or mobile devices and access your music from everywhere. Install Icecast on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net and start using it today! --- # How to Set Up HTTP Strict Transport Security (HSTS) for Apache on Ubuntu > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-set-up-http-strict-transport-security-hsts-for-apache-on-ubuntu/ | Published: 2023-11-28 | Updated: 2025-05-18 | Author: Hitesh Jethva HTTP Strict Transport Security (HSTS) is a web security policy mechanism used for securing HTTPS websites against downgrade attacks. HSTS prevents your web browser from accessing the website over non-HTTPS connections. After installing SSL, some websites contain pages that serve requests over HTTP. In that case, to avoid the usage of HTTP protocol HSTS header was introduced, it forces your website to redirect URL from HTTP to HTTPS. In this post, we will show you how to enable HTTP Strict Transport Security (HSTS) for Apache on Ubuntu. This procedure is compatible with Ubuntu 22.04 and Ubuntu 24.04. ## Step 1 – Install and Configure Apache For the purpose of this tutorial, you will need to install the Apache webserver and create a virtual host configuration file to host a website. First, install the Apache webserver with the following command: ``` apt-get install apache2 -y ``` Once the installation is completed, create a new apache virtual host configuration file for domain test.example.com. ``` nano /etc/apache2/sites-available/test.conf ``` Add the following lines: ``` ServerName test.example.com ServerAdmin webmaster@example.com DocumentRoot /var/www/html/ DirectoryIndex index.html ``` Save and close the file, then enable the virtual host with the following command: ``` a2ensite test.conf ``` Next, restart the Apache to apply the changes: ``` systemctl restart apache2 ``` ## Step 2 – Secure Apache with Let’s Encrypt SSL Next, you will need to install the Certbot client to secure your website with SSL. You can install the Certbot client for Apache with the following command: ``` apt-get install python3-certbot-apache -y ``` Once the installation is completed, run the following command to install Let’s Encrypt SSL for your website test.example.com. ``` certbot --apache -d test.example.com ``` You will be asked to provide your email and accept the term of service: ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log Plugins selected: Authenticator apache, Installer apache Enter email address (used for urgent renewal and security notices) (Enter 'c' to cancel): hitjethva@gmail.com - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Please read the Terms of Service at https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf. You must agree in order to register with the ACME server at https://acme-v02.api.letsencrypt.org/directory - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - (A)gree/(C)ancel: A - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Would you be willing to share your email address with the Electronic Frontier Foundation, a founding partner of the Let's Encrypt project and the non-profit organization that develops Certbot? We'd like to send you email about our work encrypting the web, EFF news, campaigns, and ways to support digital freedom. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - (Y)es/(N)o: Y Obtaining a new certificate Performing the following challenges: http-01 challenge for test.example.com Waiting for verification... Cleaning up challenges Created an SSL vhost at /etc/apache2/sites-available/test-le-ssl.conf Enabled Apache socache_shmcb module Enabled Apache ssl module Deploying Certificate to VirtualHost /etc/apache2/sites-available/test-le-ssl.conf Enabling available site: /etc/apache2/sites-available/test-le-ssl.conf ``` Next, you will need to select whether or not to redirect HTTP traffic to HTTPS: ``` Please choose whether or not to redirect HTTP traffic to HTTPS, removing HTTP access. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 1: No redirect - Make no further changes to the webserver configuration. 2: Redirect - Make all requests redirect to secure HTTPS access. Choose this for new sites, or if you're confident your site works on HTTPS. You can undo this change by editing your web server's configuration. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Select the appropriate number [1-2] then [enter] (press 'c' to cancel): 2 ``` Type 2 and hit Enter to finish the installation: ``` Redirecting vhost in /etc/apache2/sites-enabled/test.conf to ssl vhost in /etc/apache2/sites-available/test-le-ssl.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Congratulations! You have successfully enabled https://test.example.com You should test your configuration at: https://www.ssllabs.com/ssltest/analyze.html?d=test.example.com - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - IMPORTANT NOTES: - Congratulations! Your certificate and chain have been saved at: /etc/letsencrypt/live/test.example.com/fullchain.pem Your key file has been saved at: /etc/letsencrypt/live/test.example.com/privkey.pem Your cert will expire on 2021-06-22. To obtain a new or tweaked version of this certificate in the future, simply run certbot again with the "certonly" option. To non-interactively renew *all* of your certificates, run "certbot renew" - Your account credentials have been saved in your Certbot configuration directory at /etc/letsencrypt. You should make a secure backup of this folder now. This configuration directory will also contain certificates and private keys obtained by Certbot so making regular backups of this folder is ideal. - If you like Certbot, please consider supporting our work by: Donating to ISRG / Let's Encrypt: https://letsencrypt.org/donate Donating to EFF: https://eff.org/donate-le - We were unable to subscribe you the EFF mailing list because your e-mail address appears to be invalid. You can try again later by visiting https://act.eff.org. ``` Your website test.example.com is now secured with Let’s Encrypt SSL. ## Step 3 – Enable HSTS Header Next, you will need to activate the HSTS header within your website virtual host configuration file. Edit your website virtual host configuration file: ``` nano /etc/apache2/sites-enabled/test-le-ssl.conf ``` Add the following line below the first line: ``` Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains" ``` ![](https://www.atlantic.net/wp-content/uploads/2021/03/p1-12-1024x288.png) Save and close the file then restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` ## Step 4 – Verify HSTS Header At this point, your website is configured with HSTS header. Now you should verify whether the HSTS header is activated or not. You can verify it with the following command: ``` curl -s -D- https://test.example.com/ | grep -i Strict ``` If everything is fine, you should get the following output: ``` Strict-Transport-Security: max-age=31536000; includeSubDomains ``` You can also verify it using the URL [ssl labs](https://www.ssllabs.com/ssltest/index.html). ![](https://www.atlantic.net/wp-content/uploads/2021/03/p2-7.png) ## Conclusion In the above guide, you learned how to enable HSTS header for Apache on Ubuntu 24.04. Your website is now secured with HSTS and it can be accessed only through HTTPS protocol. Try it on your [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) account from Atlantic.Net. --- # How to Configure Reverse Proxy for Node.js Application Using Apache on Ubuntu > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-configure-reverse-proxy-for-node-js-application-using-apache-on-ubuntu/ | Published: 2023-11-28 | Updated: 2025-05-16 | Author: Hitesh Jethva Node.js is a free, open-source, and popular JavaScript runtime environment built on Chrome’s V8 JavaScript engine. It’s used for traditional websites and back-end API services. Apache is an open-source and one of the most popular web servers in the world. You can also use Apache as a frontend proxy server for backend applications including, Node.js. In this post, we will show you how to configure Apache as a reverse proxy for the Node.js application on Ubuntu. This procedure is compatible with Ubuntu 22.04 and Ubuntu 24.04. ## Step 1 – Install Node.js First, install the necessary dependencies using the following command. ``` apt-get install -y ca-certificates curl gnupg ``` Next, download the Node.js GPG key. ``` mkdir -p /etc/apt/keyrings curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg ``` Next, add the NodeSource repo to the APT source list. ``` echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_22.x nodistro main" | tee /etc/apt/sources.list.d/nodesource.list ``` Then, update the repository index and install Node.js with the following command. ``` apt update apt-get install -y nodejs ``` Next, verify the Node.js version using the following command. ``` node -v ``` Output. ``` v22.15.1 ``` ## Step 2 – Create a Nodejs Application> Next, you will need to create a Node.js application to your server. First, create a directory for your application with the following command: ``` mkdir project ``` Next, change the directory to project and create a nodeapp.js file: ``` cd project nano nodeapp.js ``` Add the following lines: ``` const http = require('http'); const hostname = 'localhost'; const port = 8000; const server = http.createServer((req, res) => { res.statusCode = 200; res.setHeader('Content-Type', 'text/plain'); res.end('Welcome to Node.js!\n'); }); server.listen(port, hostname, () => { console.log(`Server running at http://${hostname}:${port}/`); }); ``` Save and close the file, then run the application with the following command: ``` node nodeapp.js ``` If everything is fine, you should get the following output: ``` Server running at http://localhost:8000/ ``` Press CTRL+C to stop the application. ## Step 3 – Create a Systemd Service File for Nodejs Next, you will need to create a systemd service file to manage the Node.js service. You can create it with the following command: ``` nano /lib/systemd/system/nodeapp.service ``` Add the following lines: ``` [Unit] Description=Node.js Application After=syslog.target network.target [Service] Type=simple User=root WorkingDirectory=/root/project Environment=NODE_ENV=production ExecStart=/usr/bin/node nodeapp.js Restart=always [Install] WantedBy=multi-user.target ``` Save the file when you are finished, then reload the systemd daemon to apply the configuration changes: ``` systemctl daemon-reload ``` Next, start the nodeapp service and enable it so that it can start automatically at system reboot: ``` systemctl start nodeapp systemctl enable nodeapp ``` Next, verify the status of the nodeapp service by running the following command: ``` systemctl status nodeapp ``` You should see the following output: ``` ● nodeapp.service - Node.js Application Loaded: loaded (/usr/lib/systemd/system/nodeapp.service; disabled; preset: enabled) Active: active (running) since Fri 2025-05-16 07:10:05 UTC; 4s ago Main PID: 79449 (node) Tasks: 11 (limit: 629145) Memory: 8.3M (peak: 9.1M) CPU: 44ms CGroup: /system.slice/nodeapp.service └─79449 /usr/bin/node nodeapp.js May 16 07:10:05 cyber.example.com systemd[1]: Started nodeapp.service - Node.js Application. May 16 07:10:05 cyber.example.com node[79449]: Server running at http://localhost:8000/ ``` ## Step 4 – Configure Apache as a Reverse Proxy First, install the Apache package with the following command: ``` apt-get install apache2 -y ``` Next, create an Apache virtual host configuration file for Node.js: ``` nano /etc/apache2/sites-available/nodeapp.conf ``` Add the following lines: ``` ServerName your-server-ip ProxyRequests Off ProxyPreserveHost On ProxyVia Full Require all granted ProxyPass / http://127.0.0.1:8000/ ProxyPassReverse / http://127.0.0.1:8000/ ``` Save and close the file, then enable the virtual host configuration file: ``` a2ensite nodeapp.conf ``` Next, disable the default virtual host configuration file and enable the required proxy modules with the following command: ``` a2dissite 000-default a2enmod proxy proxy_http rewrite headers expires ``` Finally, restart the Apache service to apply the changes: ``` systemctl restart apache2 ``` ## Step 5 – Access Nodejs Application Now, open your web browser and access your Node.js application using the URL **http://your-server-ip**. You should see your application in the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/03/p1-13.png) ## Conclusion In the above guide, you learned how to configure Apache as a reverse proxy for the Node.js application. This will help you to host your Node.js application from the local system to the production environment – try it on your [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) account from Atlantic.Net. Learn more about our [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/). --- # How to Setup Kerberos Server and Client on Ubuntu > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-setup-kerberos-server-and-client-on-ubuntu/ | Published: 2023-11-28 | Updated: 2025-05-23 | Author: Hitesh Jethva Kerberos is a network authentication protocol that provides authentication against the devices to enable secure communication between client and server. It uses secret-key cryptography for verifying users’ identities. Generally, Kerberos is used in POSIX authentication, Active Directory, NFS, and Samba. This tutorial will show you how to install the Kerberos server and client on Ubuntu. This procedure is compatible with Ubuntu 22.04 and Ubuntu 24.04. ## Prerequisites - Two fresh Ubuntu 24.04 VPSes on the Atlantic.Net Cloud Platform - A root password configured on your server ## Step 1 – Setup Hostname Resolution First, you must set up a fully qualified hostname on the server and client machine. On the server machine, set the fully qualified hostname with the following command: ``` hostnamectl set-hostname server.myexample.com ``` On the client machine, set the fully qualified hostname with the following command: ``` hostnamectl set-hostname client.myexample.com ``` Next, edit the /etc/hosts files on both server and client machines and set up the hostname resolution so both systems can communicate using the hostname. ``` nano /etc/hosts ``` Add the following lines: ``` your-server-ip server.myexample.com your-client-ip client.myexample.com ``` Save and close the file when you are finished. ## Step 2 – Install Kerberos Server Next, you must install the Kerberos server package on the server machine. You can install all the packages with the following command: ``` apt-get install krb5-kdc krb5-admin-server krb5-config -y ``` During the installation, you will be asked to provide Kerberos Realm, as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/11/kerberos1.png) Provide myexample.com and click on the **OK** button. You will be asked to provide the Kerberos server hostname as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/11/kerberos2.png) Provide server.myexample.com and click on the **OK** button. You will be asked to provide the hostname of the administrative server as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/11/kerberos3.png) Provide server.myexample.com and click on the **OK** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/kerberos5.png) Click on the **OK** button to finish the installation. ## Step 3 – Configure Kerberos Server Next, you will need to generate the password for the Kerberos Realm. You can generate it with the following command: ``` krb5_newrealm ``` You will be asked to provide a secure password as shown below: ``` This script should be run on the master KDC/admin server to initialize a Kerberos realm. It will ask you to type in a master key password. This password will be used to generate a key that is stored in /etc/krb5kdc/stash. You should try to remember this password, but it is much more important that it be a strong password than that it be remembered. However, if you lose the password and /etc/krb5kdc/stash, you cannot decrypt your Kerberos database. Loading random data Initializing database '/var/lib/krb5kdc/principal' for realm 'myexample.com', master key name 'K/M@myexample.com' You will be prompted for the database Master Password. It is important that you NOT FORGET this password. Enter KDC database master key: Re-enter KDC database master key to verify: Now that your realm is set up you may wish to create an administrative principal using the addprinc subcommand of the kadmin.local program. Then, this principal can be added to /etc/krb5kdc/kadm5.acl so that you can use the kadmin program on other computers. Kerberos admin principals usually belong to a single user and end in /admin. For example, if jruser is a Kerberos administrator, then in addition to the normal jruser principal, a jruser/admin principal should be created. Don't forget to set up DNS information so your clients can find your KDC and admin servers. Doing so is documented in the administration guide. ``` Next, you must add the admin user principle to the access control. You can do it by editing the following file: ``` nano /etc/krb5kdc/kadm5.acl ``` Add the following line: ``` */admin * ``` Save and close the file when you are finished. Next, you must add the admin principal to the Kerberos database. You can do it with the following command: ``` kadmin.local ``` You should see the following output: ``` Authenticating as principal root/admin@myexample.com with password. ``` Next, run the following command to add the principal name kuser: ``` kadmin.local: addprinc kuser ``` You will be asked to set the password as shown below: ``` WARNING: no policy specified for kuser@myexample.com; defaulting to no policy Enter password for principal "kuser@myexample.com": Re-enter password for principal "kuser@myexample.com": Principal "kuser@myexample.com" created. ``` Next, exit from the kadmin console with the following command: ``` kadmin.local: quit ``` Next, restart the Kerberos server with the following command: ``` systemctl restart krb5-admin-server ``` You can verify the status of Kerberos with the following command: ``` systemctl status krb5-admin-server ``` You should get the following output: - ``` ● krb5-admin-server.service - Kerberos 5 Admin Server Loaded: loaded (/usr/lib/systemd/system/krb5-admin-server.service; enabled; preset: enabled) Active: active (running) since Fri 2025-05-23 06:32:09 UTC; 4s ago Main PID: 9786 (kadmind) Tasks: 1 (limit: 2272) Memory: 648.0K (peak: 912.0K) CPU: 30ms CGroup: /system.slice/krb5-admin-server.service └─9786 /usr/sbin/kadmind -nofork ``` ## Step 4 – Install Kerberos Client Next, you must install the Kerberos client on the client machine. You can install it with the following command: ``` apt-get install krb5-user -y ``` During the installation, you will be asked to provide Kerberos Realm as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/11/kerberos7.png) Provide myexample.com and click on the **OK** button. You will be asked to provide the Kerberos server hostname as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/11/kerberos8.png) Provide server.myexample.com and click on the **OK** button. You will be asked to provide the hostname of the administrative as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/11/kerberos9.png) Provide server.myexample.com and click on the **OK** button. You should see the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/11/kerberos10.png) Click on the **OK** button to finish the installation. Next, authenticate to the Kerberos server and obtain a ticket from it with the following command: ``` kinit kuser ``` You will be asked to provide a password for the kuser principal as shown below: ``` Password for kuser@myexample.com: ``` Next, obtain a ticket with the following command: ``` klist ``` You should get the following output: ``` Ticket cache: FILE:/tmp/krb5cc_0 Default principal: kuser@myexample.com Valid starting Expires Service principal 05/23/2025 06:33:28 05/23/2025 16:33:28 krbtgt/myexample.com@myexample.com renew until 05/24/2025 06:33:23 ``` ## Step 5 – Verify Authentication Next, you will need to verify the details of the principal on the Kerberos server. On the Kerberos server machine, run the following command: ``` kadmin.local ``` Authenticating as principal root/admin@myexample.com with password. Next, print the principal details with the following command: ``` kadmin.local: getprinc kuser ``` You should get the following output: ``` Principal: kuser@myexample.com Expiration date: [never] Last password change: Fri May 23 06:31:54 UTC 2025 Password expiration date: [never] Maximum ticket life: 0 days 10:00:00 Maximum renewable life: 7 days 00:00:00 Last modified: Fri May 23 06:31:54 UTC 2025 (root/admin@myexample.com) Last successful authentication: Fri May 23 06:33:28 UTC 2025 Last failed authentication: [never] Failed password attempts: 0 Number of keys: 2 Key: vno 1, aes256-cts-hmac-sha1-96 Key: vno 1, aes128-cts-hmac-sha1-96 MKey: vno 1 Attributes: REQUIRES_PRE_AUTH Policy: [none] kadmin.local: quit ``` ## Conclusion Congratulations! You have successfully installed and configured the Kerberos server and client on Ubuntu 24.04. You can now use Kerberos on your network for the authentication of users. Try it on your [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) account from Atlantic.Net! Learn more about our [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/). --- # How to Install Consul Server on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-install-consul-server-on-ubuntu/ | Published: 2023-11-28 | Updated: 2025-05-25 | Author: Hitesh Jethva Consul is a service mesh solution offering a full-featured control plane, including segmentation functionality, configuration, and service discovery. These features may be used individually as required, or they may be used together for creating a full-service mesh. Consul operates over a data plane and supports both a proxy and a native integration model. Consul ships with a simple built-in proxy that ensures everything works out-of-the-box. Consul also supports 3rd party proxy integrations, such as Envoy. Key features of Consul include: - Service Discovery - Health Checking - KV Store - Secure Service Communication - Multi-Datacenter Capabilities In this tutorial, we will show you how to install a Consul server on Ubuntu. This procedure is compatible with Ubuntu 22.04 and Ubuntu 24.04. ## Step 1 – Install Consul Server First, install the required packages with the following command: ``` apt-get update -yapt-get install unzip gnupg2 curl wget -y ``` Next, download the latest version of Consul with the following command: ``` wget https://releases.hashicorp.com/consul/1.21.0/consul_1.21.0_linux_amd64.zip ``` Once the download is completed, unzip the downloaded file with the following command: ``` unzip consul_1.21.0_linux_amd64.zip ``` Next, move the consul binary to the /usr/local/bin directory with the following command: ``` mv consul /usr/local/bin/ ``` Next, verify the Consul version using the following command: ``` consul --version ``` You should get the following output: ``` Consul v1.21.0 Revision 4e96098f Build Date 2025-05-06T11:58:51Z Protocol 2 spoken by default, understands 2 to 3 (agent will automatically use protocol >2 when speaking to compatible agents) ``` ## Step 2 – Create Consul Service File First, you will need to create a separate user and group for Consul. You can create them with the following command: ``` groupadd --system consul useradd -s /sbin/nologin --system -g consul consul ``` Next, create required directories with the following command: ``` mkdir -p /var/lib/consul mkdir /etc/consul.d ``` Next, change the ownership and permission of those directories: ``` chown -R consul:consul /var/lib/consul chmod -R 775 /var/lib/consul chown -R consul:consul /etc/consul.d ``` Next, create a Consul systemd service file with the following command: ``` nano /etc/systemd/system/consul.service ``` Add the following lines: ``` [Unit] Description=Consul Service Discovery Agent After=network-online.target Wants=network-online.target [Service] Type=simple User=consul Group=consul ExecStart=/usr/local/bin/consul agent -server -ui \             -advertise=your-server-ip \             -bind=your-server-ip \             -data-dir=/var/lib/consul \             -node=consul-01 \             -config-dir=/etc/consul.d ExecReload=/bin/kill -HUP $MAINPID KillSignal=SIGINT TimeoutStopSec=5 Restart=on-failure SyslogIdentifier=consul [Install] WantedBy=multi-user.target ``` Save and close the file when you are finished. **Note**: Provide proper server-ip, data directory path, and config directory that you created earlier. Next, reload the systemd daemon with the following command: ``` systemctl daemon-reload ``` ## Step 3 – Configure Consul Server First, you will need to generate a key to the necessary length and encoding. You can generate it with the following command: ``` consul keygen ``` You should get the following output: ``` TJ8iw/XJ+0/BSUMGuLFWkeT23LmGnfhmF/qWgA25wZU= ``` Next, you will need to create a Json configuration file for Consul. You can create it with the following command: ``` nano /etc/consul.d/config.json ``` Provide your server IP, hostname and Consul key as shown below: ``` { "bootstrap": true, "server": true, "log_level": "DEBUG", "enable_syslog": true, "datacenter": "server1", "addresses" : { "http": "0.0.0.0" }, "bind_addr": "your-server-ip", "node_name": "ubuntu2404", "data_dir": "/var/lib/consul", "acl_datacenter": "server1", "acl_default_policy": "allow", "encrypt": "TJ8iw/XJ+0/BSUMGuLFWkeT23LmGnfhmF/qWgA25wZU=" } ``` Save and close the file when you are finished. Next, start the Consul service and enable it to start at system reboot with the following command: ``` systemctl start consul systemctl enable consul ``` Next, verify the status of the Consul with the following command: ``` ● consul.service - Consul Service Discovery Agent Loaded: loaded (/etc/systemd/system/consul.service; disabled; preset: enabled) Active: active (running) since Sun 2025-05-25 05:51:50 UTC; 5s ago Main PID: 16606 (consul) Tasks: 8 (limit: 4609) Memory: 30.0M (peak: 30.5M) CPU: 130ms CGroup: /system.slice/consul.service └─16606 /usr/local/bin/consul agent -server -ui -advertise=69.87.219.209 -bind=69.87.219.209 -data-dir=/var/lib/consul -node=consul-01 -config-dir=/etc/co> May 25 05:51:53 ubuntu24 consul[16606]: agent.server.cert-manager: CA has not finished initializing May 25 05:51:53 ubuntu24 consul[16606]: agent.server.cert-manager: ACLs have not finished initializing May 25 05:51:54 ubuntu24 consul[16606]: 2025-05-25T05:51:54.339Z [DEBUG] agent.server.cert-manager: ACLs have not finished initializing May 25 05:51:54 ubuntu24 consul[16606]: 2025-05-25T05:51:54.339Z [DEBUG] agent.server.cert-manager: CA has not finished initializing May 25 05:51:54 ubuntu24 consul[16606]: agent.server.cert-manager: ACLs have not finished initializing May 25 05:51:54 ubuntu24 consul[16606]: agent.server.cert-manager: CA has not finished initializing May 25 05:51:55 ubuntu24 consul[16606]: 2025-05-25T05:51:55.339Z [DEBUG] agent.server.cert-manager: ACLs have not finished initializing May 25 05:51:55 ubuntu24 consul[16606]: agent.server.cert-manager: ACLs have not finished initializing May 25 05:51:55 ubuntu24 consul[16606]: 2025-05-25T05:51:55.339Z [DEBUG] agent.server.cert-manager: CA has not finished initializing May 25 05:51:55 ubuntu24 consul[16606]: agent.server.cert-manager: CA has not finished initializing ``` At this point, the Consul server is started and listening on port 8500. You can check it with the following command: ``` ss -plunt | grep 8500 ``` You should get the following output: ``` tcp   LISTEN 0      4096                                  *:8500              *:*                                                                                users:(("consul",pid=5511,fd=17))            ``` ## Step 4 – Configure Nginx as a Reverse Proxy Next, it is a good idea to install and configure Nginx as a reverse proxy to access the Consul on port 80. First, install the Nginx server with the following command: ``` apt-get install nginx -y ``` Once installed, remove the Nginx default virtual host configuration file: ``` rm -rf /etc/nginx/sites-enabled/default ``` Next, create a Consul virtual host configuration file with the following command: ``` nano /etc/nginx/sites-available/consul.conf ``` Add the following lines: ``` server { listen 80 ; server_name your-server-ip; root /var/lib/consul; location / { proxy_pass http://127.0.0.1:8500; proxy_set_header   X-Real-IP $remote_addr; proxy_set_header   Host      $http_host; } } ``` Save and close the file, then activate the virtual host with the following command: ``` ln -s /etc/nginx/sites-available/consul.conf /etc/nginx/sites-enabled/ ``` Next, check the Nginx for any syntax errors with the following command: ``` nginx -t ``` You should get the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Next, restart the Nginx service with the following command: ``` systemctl restart nginx ``` If you get any errors, then you will need to edit the Nginx default server configuration file and set server_names_hash_bucket_size: ``` nano /etc/nginx/nginx.conf ``` Add the following line below **http {**: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 5 – Access Consul Dashboard Next, open your web browser and access the Consul web interface using the URL **http://your-server-ip/ui**. You should see the Consul dashboard in the following page: ![](https://www.atlantic.net/wp-content/uploads/2020/10/Consul-Dashboard.png) Click on the **Nodes** to list the active nodes in your server as shown below: ![](https://www.atlantic.net/wp-content/uploads/2023/11/c1.png) ## Conclusion Congratulations! You have successfully installed Consul server on Ubuntu 24.04. You can now add more client nodes to the Consul server and start managing them from the Consul dashboard. For more information, you can visit the Consul [documentation](https://www.consul.io/docs). Get started with Consul on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Configure strongSwan VPN on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-configure-strongswan-vpn-on-ubuntu/ | Published: 2023-11-28 | Updated: 2025-10-02 | Author: Hitesh Jethva A VPN allows you to access the Internet safely and securely on an untrusted public Wi-Fi network. You can connect to remote VPN servers using the encrypted connection and surf the web anonymously. strongSwan is free, open-source, and the most widely-used IPsec-based virtual private network implementation, allowing you to create an encrypted secure tunnel between two or more remote networks. strongSwan uses the IKEv2 protocol, which allows for direct IPSec tunneling between the server and the client. strongSwan stands for Strong Secure WAN and supports both versions of automatic keying exchange in IPsec VPN, IKE V1 and V2. In this tutorial, we will show you how to install and configure strongSwan VPN on Ubuntu. This procedure is compatible with Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04 and Ubuntu 24.04 ## Step 1 – Enable Kernel Packet Forwarding First, you will need to configure the kernel to enable packet forwarding for IPv4. You can configure it by editing the file /etc/sysctl.conf: ``` nano /etc/sysctl.conf ``` Add the following lines at the end of the file: ``` net.ipv4.ip_forward = 1 net.ipv6.conf.all.forwarding = 1 net.ipv4.conf.all.accept_redirects = 0 net.ipv4.conf.all.send_redirects = 0 ``` Save and close the file. Then, run the following command to reload the settings: ``` sysctl -p ``` ## Step 2 – Install strongSwan First, you will need to install the strongSwan IPSec daemon in your system. You can install it by simply running the following command: ``` apt-get install strongswan libcharon-extra-plugins strongswan-pki libtss2-tcti-tabrmd0 libtss2-esys-3.0.2-0 libstrongswan-extra-plugins -y ``` Once the installation is completed, you can proceed to the next step. ## Step 3 – Setting Up a Certificate Authority Now you will need to generate the VPN server certificate and key for the VPN client to verify the authenticity of the VPN server. First, generate a private key for self-signing the CA certificate using a PKI utility: ``` ipsec pki --gen --size 4096 --type rsa --outform pem > ca.key.pem ``` Next, create your root certificate authority and use the above key to sign the root certificate: ``` ipsec pki --self --in ca.key.pem --type rsa --dn "CN=VPN Server CA" --ca --lifetime 3650 --outform pem > ca.cert.pem ``` Next, you will need to create a certificate and key for the VPN server so that the client can verify the server’s authenticity using the CA certificate we just generated. First, create a private key for the VPN server with the following command: ``` ipsec pki --gen --size 4096 --type rsa --outform pem > server.key.pem ``` Next, generate the server certificate by running the following command: ``` ipsec pki --pub --in server.key.pem --type rsa | ipsec pki --issue --lifetime 2750 --cacert ca.cert.pem --cakey ca.key.pem --dn "CN=vpn.example.com" --san="vpn.example.com" --flag serverAuth --flag ikeIntermediate --outform pem > server.cert.pem ``` Next, you will need to copy the above certificate in the respective IPSec certificates directories as shown below: ``` mv ca.cert.pem /etc/ipsec.d/cacerts/ mv server.cert.pem /etc/ipsec.d/certs/ mv ca.key.pem /etc/ipsec.d/private/ mv server.key.pem /etc/ipsec.d/private/ ``` At this point, you have all of the certificates ready, and you can now proceed to the next step. ## Step 4 – Configure strongSwan strongSwan has a default configuration file located at /etc/ipsec.conf. It is recommended to rename the default configuration file and create a new file. To rename the default configuration file, run the following command: ``` mv /etc/ipsec.conf /etc/ipsec.conf.bak ``` Next, create a new configuration file as shown below: ``` nano /etc/ipsec.conf ``` Add the following lines: ``` config setup        charondebug="ike 2, knl 2, cfg 2, net 2, esp 2, dmn 2, mgr 2"        strictcrlpolicy=no        uniqueids=yes        cachecrls=no conn ipsec-ikev2-vpn      auto=add      compress=no      type=tunnel  # defines the type of connection, tunnel.      keyexchange=ikev2      fragmentation=yes      forceencaps=yes      dpdaction=clear      dpddelay=300s      rekey=no      left=%any      leftid=@vpn.example.com    # if using IP, define it without the @ sign      leftcert=server.cert.pem  # reads the VPN server cert in /etc/ipsec.d/certs      leftsendcert=always      leftsubnet=0.0.0.0/0      right=%any      rightid=%any      rightauth=eap-mschapv2      rightsourceip=192.168.0.0/24      rightdns=8.8.8.8      rightsendcert=never      eap_identity=%identity  # defines the identity the client uses to reply to an EAP Identity request. ``` Save and close the file when you are finished. **Where:** **config setup :** Specifies general configuration information for IPSec which applies to all connections. **charondebug :** Defines how much Charon debugging output should be logged. **leftid :** Specifies the domain name or IP address of the server. **leftcert :** Specifies the name of the server certificate. **leftsubnet :** Specifies the private subnet behind the left participant. **rightsourceip :** IP address pool to be assigned to the clients. **rightdns :** DNS to be assigned to clients. ## Step 5 – Configure Authentication At this point, your VPN server is configured to accept client connections. Next, you will need to configure client-server authentication credentials to define the RSA private keys for authentication and set up the EAP user credentials. ``` nano /etc/ipsec.secrets ``` Add the following lines: ``` : RSA "server.key.pem" vpnsecure : EAP "your-secure-password" ``` Save and close the file. Then, restart the strongSwan service and enable it to start at reboot: ``` systemctl restart strongswan-starter.service systemctl enable strongswan-starter.service ``` You can also verify the status of the strongSwan service using the following command: ``` systemctl status strongswan-starter.service ``` You should see the following output: ``` • strongswan.service - strongSwan IPsec IKEv1/IKEv2 daemon using ipsec.conf   Loaded: loaded (/lib/systemd/system/strongswan.service; enabled; vendor preset: enabled)   Active: active (running) since Fri 2020-05-08 08:02:08 UTC; 8s ago Main PID: 29947 (starter)    Tasks: 18 (limit: 2359)   CGroup: /system.slice/strongswan.service           ├─29947 /usr/lib/ipsec/starter --daemon charon --nofork           └─29973 /usr/lib/ipsec/charon --debug-ike 2 --debug-knl 2 --debug-cfg 2 --debug-net 2 --debug-esp 2 --debug-dmn 2 --debug-mgr 2 May 08 08:02:08 ubuntu1804 charon[29973]: 05[CFG]   eap_identity=%identity May 08 08:02:08 ubuntu1804 charon[29973]: 05[CFG]   dpddelay=300 May 08 08:02:08 ubuntu1804 charon[29973]: 05[CFG]   dpdtimeout=150 May 08 08:02:08 ubuntu1804 charon[29973]: 05[CFG]   dpdaction=1 May 08 08:02:08 ubuntu1804 charon[29973]: 05[CFG]   sha256_96=no May 08 08:02:08 ubuntu1804 charon[29973]: 05[CFG]   mediation=no May 08 08:02:08 ubuntu1804 charon[29973]: 05[CFG]   keyexchange=ikev2 May 08 08:02:08 ubuntu1804 charon[29973]: 05[CFG] adding virtual IP address pool 192.168.0.0/24 May 08 08:02:08 ubuntu1804 charon[29973]: 05[CFG]   loaded certificate "CN=vpn.example.com" from 'server.cert.pem' May 08 08:02:08 ubuntu1804 charon[29973]: 05[CFG] added configuration 'ipsec-ikev2-vpn' ``` You can also verify the strongSwan certificates using the following command: ``` ipsec listcerts ``` You should get the following output: ``` List of X.509 End Entity Certificates subject: "CN=vpn.example.com" issuer: "CN=VPN Server CA" validity: not before May 11 07:13:55 2025, ok not after Nov 20 07:13:55 2032, ok (expires in 2749 days) serial: 20:47:13:71:a8:8a:e7:65 altNames: vpn.example.com flags: serverAuth ikeIntermediate authkeyId: 90:9f:3f:b7:b1:12:8f:e3:d0:30:15:1b:49:39:94:c9:c9:8d:07:3c subjkeyId: 68:ff:aa:f4:6a:e6:40:d2:4f:8d:dd:1f:6a:16:df:9e:f1:76:f6:28 pubkey: RSA 4096 bits, has private key keyid: 02:0b:d8:03:cf:ee:3e:4f:8a:da:39:1b:fb:90:b2:10:f8:64:62:0e subjkey: 68:ff:aa:f4:6a:e6:40:d2:4f:8d:dd:1f:6a:16:df:9e:f1:76:f6:28 ``` At this point, your strongSwan VPN server is installed and configured. You can now proceed to install and configure the VPN client to connect the VPN server. ## Step 6 – Install and Configure strongSwan Client Log in to the client system and run the following command to install the strongSwan client packages: ``` apt-get install strongswan libcharon-extra-plugins -y ``` Once installed, disable the strongSwan service to start at boot: ``` systemctl disable strongswan-starter.service ``` Next, copy the ca.cert.pem file from the VPN server to the VPN client using the following command: ``` scp root@your-vpnserver-ip:/etc/ipsec.d/cacerts/ca.cert.pem /etc/ipsec.d/cacerts/ ``` Next, configure VPN client authentication by editing the file /etc/ipsec.secrets: ``` nano /etc/ipsec.secrets ``` Add the following line: ``` vpnsecure : EAP "your-secure-password" ``` Save and close the file. Then, edit the strongSwan default configuration file: ``` nano /etc/ipsec.conf ``` Add the following lines: ``` conn ipsec-ikev2-vpn-client    auto=start    right=vpn.example.com    rightid=vpn.example.com    rightsubnet=0.0.0.0/0    rightauth=pubkey    leftsourceip=%config    leftid=vpnsecure    leftauth=eap-mschapv2    eap_identity=%identity ``` Save and close the file. Then, restart the strongSwan service with the following command: ``` systemctl restart strongswan-starter.service ``` On the strongSwan server, check the VPN connection status using the following command: ``` ipsec status ``` You should see that the IP 192.168.0.5 assign to the VPN client: ``` Security Associations (1 up, 0 connecting): ipsec-ikev2-vpn-client[1]: ESTABLISHED 1 minutes ago, [vpnsecure]...192.168.0.1[vpn.example.com] ipsec-ikev2-vpn-client{1}:  INSTALLED, TUNNEL, reqid 1, ESP in UDP SPIs: 74ab87d0db9ea3d5_i 684cb0dbe4d1a70d_r ipsec-ikev2-vpn-client{1}:   192.168.0.5/32 === 0.0.0.0/0 ``` ### Step 7 – Connecting from a Windows Client Windows has a built-in VPN client that is fully compatible with the IKEv2 server we have configured. To connect, you will need to import the server’s Certificate Authority (CA) certificate to ensure Windows trusts the VPN server, and then configure the connection. #### Transfer the CA Certificate First, you need the ca.cert.pem file that was generated on your VPN server. Log in to your server and display the contents of the file: ``` cat /etc/ipsec.d/cacerts/ca.cert.pem ``` Copy the entire output to your clipboard, including the —–BEGIN CERTIFICATE—– and —–END CERTIFICATE—– lines. On your Windows machine, open Notepad, paste the copied text, and save the file as ca.cert.pem. Make sure you select “All Files” for the “Save as type” option to avoid it being saved as a .txt file. #### Install the CA Certificate on Windows For Windows to trust your VPN server, you must install the CA certificate into the “Trusted Root Certification Authorities” store for the **Local Computer**. 1. Press the **Windows Key + R** to open the Run dialog, type mmc.exe, and press Enter. This opens the Microsoft Management Console. 2. In the console, go to **File > Add/Remove Snap-in…**. 3. From the list of available snap-ins, select **Certificates** and click **Add >**. 4. A new window will pop up. Crucially, you must select **Computer account** and click **Next**. 5. Select **Local computer**, then click **Finish**, and finally **OK**. 6. In the main console window, expand **Certificates (Local Computer)**, then expand **Trusted Root Certification Authorities**, and click on the **Certificates** folder inside it. 7. Right-click on the **Certificates** folder and select **All Tasks > Import…**. 8. The Certificate Import Wizard will open. Click **Next**. 9. Click **Browse…** and locate the ca.cert.pem file you saved earlier. You may need to change the file type dropdown from “X.509…” to **“All Files (*.*)”** to see it. Select the file and click **Open**. 10. Click **Next**. Ensure the Certificate Store is shown as “**Trusted Root Certification Authorities**“. 11. Click **Next** again, and then **Finish**. You should see a message confirming the import was successful. #### Configure the VPN Connection in Windows Now you can create the VPN connection profile. 1. Open **Settings** > **Network & Internet** > **VPN**. 2. Click **Add a VPN connection**. 3. Fill out the form with the following details: - **VPN provider:** Windows (built-in) - **Connection name:** Give it a memorable name, like My strongSwan VPN. - **Server name or address:** vpn.example.com (Use the domain name you configured in Step 3 of the server setup). - **VPN type:** IKEv2 - **Type of sign-in info:** User name and password - **User name:** vpnsecure (The username you set in /etc/ipsec.secrets). - **Password:** your-secure-password (The password you set in /etc/ipsec.secrets). - *(You can leave the username and password fields blank if you prefer to be prompted for them each time you connect).* 4. Click **Save**. #### Connect to the VPN The new VPN connection will now appear in your VPN list. You can connect to it from the Settings page or by clicking the network icon in your system tray. Click on your VPN profile and click the **Connect** button. The status should change to “Connected”, and your internet traffic will now be securely routed through your Ubuntu strongSwan server. ## Conclusion Congratulations! You have successfully installed and configured strongSwan VPN Server and Client on Ubuntu 24.04. You are now securely traversing the internet protecting your identity, location, and traffic from snoopers and censors – get started on your VPS hosted Ubuntu server from Atlantic.Net today! Learn more about our [VPS hosting](https://www.atlantic.net/vps-hosting/) services and [Virtual private servers.](https://www.atlantic.net/vps-hosting/) --- # Install WordPress with Docker on Ubuntu > URL: https://www.atlantic.net/vps-hosting/install-wordpress-with-docker-on-ubuntu/ | Published: 2023-11-28 | Updated: 2023-11-29 | Author: Hitesh Jethva WordPress is a free, open-source, and widely used content management system. However, setting up a new web hosting environment with WordPress can be a time-consuming process.  Docker simplifies the whole process with a few commands that reduce the time and effort needed for installation. Docker is an open-source containerization application built to develop, test, and run multiple applications on the same machine. It is very useful for developers to create a test environment without wasting server space and memory. In this tutorial, we will show you how to install WordPress with Docker on Ubuntu. This procedure is compatible with Ubuntu 20.04 and Ubuntu 22.04. [jumpbox] ## Step 1 – Install Required Dependencies First, you will need to install some dependencies in your server. You can install all of them by running the following command: ``` apt-get update -yapt-get install mariadb-client apt-transport-https ca-certificates curl gnupg-agent software-properties-common -y ``` Once all the packages are installed, you can proceed to the next step. ## Step 2 – Install Docker By default, the latest version of Docker is not available in the Ubuntu 20.04 default repository, so it is a good idea to add the Docker official repository in your system. First, download and add the GPG key with the following command: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | apt-key add - ``` Next, add the Docker repository with the following command: ``` add-apt-repository "deb [arch=amd64] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" ``` Once the repository is added, you can install the Docker and Docker Compose using the following command: ``` apt-get install docker-ce docker-ce-cli containerd.io  -y ``` After installing both packages, check the installed version of Docker with the following command: ``` docker --version ``` You should get the following output: ``` Docker version 19.03.12, build 48a66213fe ``` ## Step 3 – Create a MariaDB Container First, you will need to download the MariaDB image from the Docker repository. You can download it with the following command: ``` docker pull mariadb ``` You should see the following output: ``` Using default tag: latest latest: Pulling from library/mariadb 3ff22d22a855: Pull complete e7cb79d19722: Pull complete 323d0d660b6a: Pull complete b7f616834fd0: Pull complete 78ed0160f03e: Pull complete a122e9306ac4: Pull complete 673e89352b19: Pull complete caf1e694359b: Pull complete 04f5e4f6ead3: Pull complete a41772aadb3d: Pull complete c3811aa2fa0a: Pull complete 655ad574d3c7: Pull complete 90ae536d75f0: Pull complete Digest: sha256:812d3a450addcfe416420c72311798f3f3109a11d9677716dc631c429221880c Status: Downloaded newer image for mariadb:latest docker.io/library/mariadb:latest ``` Next, create a directory structure for WordPress on your server: ``` mkdir ~/wordpress mkdir -p ~/wordpress/database mkdir -p ~/wordpress/html ``` Next, create a MariaDB container with name wordpressdb by running the following command: ``` docker run -e MYSQL_ROOT_PASSWORD=root-password -e MYSQL_USER=wpuser -e MYSQL_PASSWORD=password -e MYSQL_DATABASE=wpdb -v /root/wordpress/database:/var/lib/mysql --name wordpressdb -d mariadb ``` You should see an output similar to the following: ``` e8c780b34cdcb66db9278635b109debb1775d6a6b6785c4e74c8e0815e3ba5e3 ``` In the above command, here are the variables defined: - **MYSQL_ROOT_PASSWORD**: This option will configure MariaDB root password. - **MYSQL_USER**: This will create a new wpuser for WordPress. - **MYSQL_PASSWORD**: This will set the password for wpuser. - **MYSQL_DATABASE**: This will create a new database named wpdb for WordPress. - **-v /root/wordpress/database:/varlib/mysql**: This will link the database directory to the mysql directory. Next, check the IP address of MariaDB container with the following command: ``` docker inspect -f '{{ .NetworkSettings.IPAddress }}' wordpressdb ``` You should see the MariaDB container IP address in the following output: ``` 172.17.0.2 ``` Now, connect to your MariaDB container using the database user and password: ``` mysql -u wpuser -h 172.17.0.2 -p Enter password: ``` You should see the following output: ``` Welcome to the MariaDB monitor.  Commands end with ; or \g. Your MariaDB connection id is 3 Server version: 10.5.4-MariaDB-1:10.5.4+maria~focal mariadb.org binary distribution Copyright (c) 2000, 2018, Oracle, MariaDB Corporation Ab and others. Type 'help;' or '\h' for help. Type '\c' to clear the current input statement. ``` Now, verify the database with the following command: ``` show databases; ``` You should see your wpdb database in the following output: ``` +--------------------+ | Database           | +--------------------+ | information_schema | | wpdb               | +--------------------+ 2 rows in set (0.001 sec) ``` Now, exit from the MariaDB shell with the following command: ``` EXIT; ``` ## Step 4 – Create a WordPress Container First, download the WordPress image from the Docker repository using the following command: ``` docker pull wordpress:latest ``` You should see the following output: ``` latest: Pulling from library/wordpress bf5952930446: Pull complete a409b57eb464: Pull complete 3192e6c84ad0: Pull complete 43553740162b: Pull complete d8b8bba42dea: Pull complete eb10907c0110: Pull complete 10568906f34e: Pull complete 03fe17709781: Pull complete 98171b7166c8: Pull complete 3978c2fb05b8: Pull complete 71bf21524fa8: Pull complete 24fe81782f1c: Pull complete 7a2dfd067aa5: Pull complete a04586f4f8fe: Pull complete b8059b10e448: Pull complete e5b4db4a14b4: Pull complete 48018c17c4e9: Pull complete d09f106f9e16: Pull complete 2ce4312168ba: Pull complete 01f0fe2819ef: Pull complete Digest: sha256:19c6a3a796b1db1e6ee8bd3e8d5d69510885fa62255ce8bd07ee34d3878d0312 Status: Downloaded newer image for wordpress:latest docker.io/library/wordpress:latest ``` Next, create a new WordPress container named wpcontainer from the downloaded image using the following command: ``` docker run -e WORDPRESS_DB_USER=wpuser -e WORDPRESS_DB_PASSWORD=password -e WORDPRESS_DB_NAME=wpdb -p 8081:80 -v /root/wordpress/html:/var/www/html --link wordpressdb:mysql --name wpcontainer -d wordpress ``` This will create a new WordPress container and expose the port 80 on the container to port 8081 on the host machine. You can now verify your WordPress container with the following command: ``` curl -I localhost:8081 ``` You should get the following output: ``` HTTP/1.1 302 Found Date: Fri, 07 Aug 2020 04:44:36 GMT Server: Apache/2.4.38 (Debian) X-Powered-By: PHP/7.4.9 Expires: Wed, 11 Jan 1984 05:00:00 GMT Cache-Control: no-cache, must-revalidate, max-age=0 X-Redirect-By: WordPress Location: http://localhost:8081/wp-admin/install.php Content-Type: text/html; charset=UTF-8 ``` ## Step 5 – Configure Nginx as a Reverse Proxy Next, you will need to install and configure Nginx as a reverse proxy for the WordPress container so you can access your WordPress using port 80. First, install the Nginx web server with the following command: ``` apt-get install nginx -y ``` Once installed, create a new Nginx virtual host configuration file: ``` nano /etc/nginx/sites-available/wordpress ``` Add the following lines: ``` server {   listen 80;   server_name wp.example.com;   location / {     proxy_pass http://localhost:8081;     proxy_set_header Host $host;     proxy_set_header X-Real-IP $remote_addr;     proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;   } } ``` Save and close the file, then activate the virtual host with the following command: ``` ln -s /etc/nginx/sites-available/wordpress /etc/nginx/sites-enabled/ ``` Next, restart the Nginx service to apply the changes: ``` systemctl restart nginx ``` ## Step 6 – Access WordPress Interface Now, open your web browser and type the URL http://wp.example.com. You will be redirected to the WordPress installation wizard: ![](https://www.atlantic.net/wp-content/uploads/2020/09/WordPress-Language-1024x586.png) Select your language and click on the **Continue** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/09/WordPress-Information-1024x549.png) Provide your site name, admin username, email, and password and click on the **Install** **WordPress** button. Once the installation has been finished, you should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/09/WordPress-Login-1024x552.png) Provide your admin username and password and click on the **Log In** button. You should see the WordPress dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/09/WordPress-Dashboard-1024x536.png) ## Conclusion In this guide, you learned how to install and configure WordPress in the Docker environment on Ubuntu 20.04. You can now set up WordPress in a test environment – get started today on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Create a Sudo User in Rocky Linux > URL: https://www.atlantic.net/vps-hosting/how-to-create-a-sudo-user-in-rocky-linux/ | Published: 2023-11-28 | Updated: 2025-10-15 | Author: Hitesh Jethva In Linux or Unix-based operating systems, there are two types of users: a super-user (root) and an average or regular user. The root user has complete control of the operating system, and it has privileges to run administrative commands like installing, removing, and updating software packages, changing permissions, and configuring different services. The non-root users have limited interactions with an operating system environment, and they can perform only user-specific tasks. The sudo command, short for “super-user do,” is a Linux utility that allows an average user to run any commands with unlimited privileges. In this case, you must add an average user to the sudo Group to execute administrative commands. In this post, we will show you how to create a sudo user in Rocky Linux. This procedure is compatible with Rocky Linux 9 and Rocky Linux 10. ## Create a Normal User in Rocky Linux If you have not created any normal or no-root user on your system, you will need to create one user. Let’s create a new user named user1 with the following command: ``` adduser user1 ``` Next, set a password for this user with the following command: ``` passwd user1 ``` You will be asked to set a password as shown below: ``` Changing password for user user1. New password: Retype new password: passwd: all authentication tokens updated successfully. ``` #### **Also Read** [How to Change or Set User Passwords in Linux](https://www.atlantic.net/vps-hosting/how-to-change-or-set-user-passwords-in-linux/) ## Enable Wheel Group access for All Users Next, you must edit **/etc/sudoers** file and confirm that the wheel group is enabled. ``` nano /etc/sudoers ``` Make sure the following line exists: ``` %wheel ALL=(ALL) ALL ``` Save and close the file after the confirmation. ## Add a Normal User to the sudo (wheel) Group. Next, you must add your created user to the sudo (wheel) Group to grant it administrative privileges. You can use the **usermod** command to add a regular user to the wheel group. ``` usermod -aG wheel user1 ``` This command will add a user1 to the wheel group. ## Verify the Sudo User After adding a normal user to the sudo Group, you must verify whether the newly created user has sudo rights. To verify, switch the user to the user1 using the following command: ``` su - user1 ``` Next, run any administrative command with sudo: ``` sudo dnf update ``` If everything is fine, you will be asked to provide a password for user1: ``` We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. [sudo] password for user1: ``` Provide the password of user1 to run the above command. The above output confirms that the user has sudo rights and can run administrative commands. #### **Also Read** [How to Use the id Command in Linux](https://www.atlantic.net/vps-hosting/how-to-use-the-id-command-in-linux/) ## Conclusion In this post, we explained how to create a sudo user in Rocky Linux 10. You can now grant super-user privileges to any regular user in your Linux environment. Try it on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Use PIP Python Package Manager on Rocky Linux > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-pip-python-package-manager-on-rocky-linux/ | Published: 2023-11-28 | Updated: 2025-10-15 | Author: Hitesh Jethva Python is a general-purpose, high-level programming language used by developers around the world. PIP is a package manager for Python used for installing and managing additional packages. PIP allows you to manage full lists of packages and their corresponding version numbers. PIP provides a way to install user-defined projects locally with the use of a setup.py file. In this post, we will explain how to install and use PIP on Rocky Linux. This procedure is compatible with Rocky Linux 9 and Rocky Linux 10. ## Step 1 – Install PIP on Rocky Linux Before installing PIP, you will need to install Python on your system. You can install it by running the following command: ``` dnf install python312 -y ``` Once Python is installed, you can verify the Python version using the following command: ``` python3.12 --version ``` You should get the following output: ``` Python 3.12.9 ``` Next, install PIP using the following command: ``` dnf install python3.12-pip ``` Once PIP is installed, verify the installed version of PIP using the following command: ``` pip3 --version ``` You should see the following output: ``` pip 23.3.2 from /usr/lib/python3.12/site-packages/pip (python 3.12) ``` ## Step 2 – How to Update PIP It is recommended to update PIP to the latest version. You can update it using the following command: ``` pip3 install --upgrade pip ``` You should see the following output: ``` Installing collected packages: pip Successfully installed pip-25.1 ``` You can now verify the PIP version using the following command: ``` pip3 --version ``` You should see the following output: ``` pip 25.2 from /usr/local/lib/python3.9/site-packages/pip (python 3.12) ``` ## Step 3 – How to Use PIP You can list all important options available with PIP using the following command: ``` pip3 --help ``` You should see the following output: ``` Usage: pip3 [options] Commands: install Install packages. download Download packages. uninstall Uninstall packages. freeze Output installed packages in requirements format. list List installed packages. show Show information about installed packages. check Verify installed packages have compatible dependencies. config Manage local and global configuration. search Search PyPI for packages. cache Inspect and manage pip's wheel cache. wheel Build wheels from your requirements. hash Compute hashes of package archives. completion A helper command used for command completion. debug Show information useful for debugging. help Show help for commands. ``` To install a specific package, run the following command: ``` pip3 install wheel ``` To get detailed information about a package, run the following command: ``` pip3 show wheel ``` You will get the following output: ``` Name: wheel Version: 0.45.1 Summary: A built-package format for Python Home-page: https://github.com/pypa/wheel Author: Daniel Holth Author-email: dholth@fastmail.fm License: MIT Location: /usr/local/lib/python3.12/site-packages Requires: Required-by: ``` To list all installed packages, run the following command: ``` pip3 list ``` You should see the following output: ``` Package Version ------------------------- --------- attrs 23.2.0 charset-normalizer 3.3.2 cloud-init 24.4 cockpit 334.1 configobj 5.0.8 dasbus 1.7 dbus-python 1.3.2 distro 1.9.0 dnf 4.20.0 file-magic 0.4.0 idna 3.7 Jinja2 3.1.6 jsonpatch 1.33 jsonpointer 2.3 ``` To list all outdated packages, run the following command: ``` pip3 list --outdated ``` You should see the following output: ``` Package Version Latest Type ---------- ------- ------ ----- attrs 23.2.0 25.4.0 wheel charset-normalizer 3.3.2 3.4.4 wheel configobj 5.0.8 5.0.9 wheel dbus-python 1.3.2 1.4.0 sdist file-magic 0.4.0 0.4.1 wheel idna 3.7 3.11 wheel ``` To uninstall a specific package, run the following command: ``` pip3 uninstall wheel ``` ## Conclusion In the above post, you learned how to install and use PIP on Rocky Linux 10. You also learned how to manage Python packages with PIP. You can now easily use PIP to manage the Python dependencies. Get started with [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Configure Caddy Web Server with PHP on Rocky Linux > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-configure-caddy-web-server-with-php-on-rocky-linux/ | Published: 2023-11-28 | Updated: 2025-10-15 | Author: Hitesh Jethva Caddy is a free, open-source, lightweight, modern web server written in the Go language. You can use Caddy as a file server, dynamic server, and scalable reverse proxy. You can extend the server functionality via plugins. Caddy comes with a wide range of features, some of which are listed below: - Virtual hosting - Automatic HTTPS via Let’s Encrypt - Support HTTP/2 - Extensible with plugins - Runs without any external dependencies In this post, we will show you how to install the Caddy web server with PHP support on Rocky Linux. This procedure is compatible with Rocky Linux 9 and Rocky Linux 10. ## Step 1 – Install Caddy Web Server By default, the Caddy package is not included in the Rocky Linux 8 default repo, so you will need to enable the special repository in your system. ``` dnf install 'dnf-command(copr)' dnf copr enable @caddy/caddy ``` Once the repository is enabled, you can install the Caddy web server with the following command: ``` dnf install caddy -y ``` Once the Caddy is installed, verify the Caddy version using the following command: ``` caddy version ``` Sample output: ``` v2.10.2 h1:g/gTYjGMD0dec+UgMw8SnfmJ3I9+M2TdvoRL/Ovu6U8= ``` Next, start the Caddy service and enable it to start at system reboot: ``` systemctl start caddy systemctl enable caddy ``` Now, open your web browser and access the Caddy web server using the URL **http://your-server-ip**. You should see the Caddy test page on the following screen: ![Caddy test page](https://www.atlantic.net/wp-content/uploads/2021/11/p1-5-1024x547.png) ## Step 2 – Create a New Site On Caddy First, create a directory structure for the new website using the following command: ``` mkdir -p /var/www/example.com touch /var/log/caddy/example.access.log mkdir /var/log/caddy ``` Next, set proper ownership on the new website: ``` chown caddy:caddy /var/www/example.com chown caddy:caddy /var/log/caddy ``` Next, create an index.html page for the new website: ``` nano /var/www/example.com/index.html ``` Add the following lines: ``` Caddy Web Server

This is my first web page on Caddy!

``` Save and close the file when you are finished. ## Step 3 – Create a Virtual Host Configuration File Next, you will need to edit the Caddy configuration file to host the new website. You can edit it with the following command: ``` nano /etc/caddy/Caddyfile ``` Remove all lines and add the following lines: ``` test.example.com:80 { root * /var/www/example.com file_server encode gzip log { output file /var/log/caddy/example.access.log } @static { file path *.ico *.css *.js *.gif *.jpg *.jpeg *.png *.svg *.woff *.pdf *.webp } header @static Cache-Control max-age=5184000 } ``` Save and close the file when you are finished. Next, validate the Caddy configuration file: ``` caddy validate --adapter caddyfile --config /etc/caddy/Caddyfile ``` You should see the following output: ``` 2025/10/15 07:46:35.423 INFO using config from file {"file": "/etc/caddy/Caddyfile"} 2025/10/15 07:46:35.425 INFO adapted config to JSON {"adapter": "caddyfile"} 2025/10/15 07:46:35.425 WARN Caddyfile input is not formatted; run 'caddy fmt --overwrite' to fix inconsistencies {"adapter": "caddyfile", "file": "/etc/caddy/Caddyfile", "line": 2} 2025/10/15 07:46:35.425 WARN http.auto_https server is listening only on the HTTP port, so no automatic HTTPS will be applied to this server {"server_name": "srv0", "http_port": 80} 2025/10/15 07:46:35.426 INFO http servers shutting down with eternal grace period 2025/10/15 07:46:35.426 INFO tls.cache.maintenance started background certificate maintenance {"cache": "0xc000381e80"} 2025/10/15 07:46:35.426 INFO tls.cache.maintenance stopped background certificate maintenance {"cache": "0xc000381e80"} Valid configuration ``` Next, restart the Caddy service to apply the changes: ``` systemctl restart caddy ``` You can also check the Caddy service using the following command: ``` systemctl status caddy ``` You will get the following output: ``` ● caddy.service - Caddy Loaded: loaded (/usr/lib/systemd/system/caddy.service; disabled; preset: disabled) Active: active (running) since Wed 2025-10-15 03:49:36 EDT; 11s ago Invocation: 9752a862b5d14a52a0cb4d862b6f5afa Docs: https://caddyserver.com/docs/ Main PID: 1340 (caddy) Tasks: 6 (limit: 12342) Memory: 18.3M (peak: 20.3M) CPU: 89ms CGroup: /system.slice/caddy.service └─1340 /usr/bin/caddy run --environ --config /etc/caddy/Caddyfile ``` Now, open your web browser and access the Caddy website using the URL**http://test.example.com**. You should see your website on the following screen: ![Caddy HTML page](https://www.atlantic.net/wp-content/uploads/2021/11/p2-4-1024x514.png) ## Step 4 – Enable PHP Support on Caddy Web Server First, you will need to install PHP and other required extensions to your server. You can install all of them with the following command: ``` dnf install php-fpm php-cli php-gd -y ``` Once all the packages are installed, edit the Caddy configuration file: ``` nano /etc/caddy/Caddyfile ``` Define the php_fastcgi location as shown below: ``` test.example.com:80 { root * /var/www/example.com php_fastcgi unix//run/php-fpm/www.sock file_server encode gzip log { output file /var/log/caddy/example.access.log } @static { file path *.ico *.css *.js *.gif *.jpg *.jpeg *.png *.svg *.woff *.pdf *.webp } header @static Cache-Control max-age=5184000 } ``` Save and close the file, then edit the PHP-FPM file: ``` nano /etc/php-fpm.d/www.conf ``` Change the following lines: ``` user = caddy group = caddy listen.acl_users = apache,nginx,caddy ``` Save and close the file, then start the PHP-FPM service and enable it to start at system reboot: ``` systemctl start php-fpm systemctl enable php-fpm ``` Next, create a sample info.php page: ``` nano /var/www/example.com/info.php ``` Add the following line: ``` ``` Save and close the file, then restart the Caddy service to apply the changes. ``` systemctl restart caddy ``` Now, open your web browser and access the info.php page using the URL **http://test.example.com/info.php**. You will get the following page: ![](https://www.atlantic.net/wp-content/uploads/2023/11/c1-1.png) ## Conclusion In the above guide, we explained how to install Caddy with PHP on Rocky Linux 10. Caddy is a very good alternative to Apache and Nginx. You should try it in the production environment – get started on your [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Portainer Docker UI Web Interface on Debian > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-portainer-docker-ui-web-interface-on-debian/ | Published: 2023-11-28 | Updated: 2025-09-05 | Author: Hitesh Jethva Portainer is a lightweight, free, open-source Docker management UI that allows you to manage your Docker container from a web browser. It provides a simple and user-friendly web interface to build and manage containers, images, networks, volumes, registries, services, and nodes. Portainer is a handy tool for users who don’t know the Linux command line. This post will show you how to install Portainer Docker UI on Debian. This procedure is compatible with Debian 11 and Debian 12. ## Step 1 – Install Docker CE Before installing Portainer, Docker CE must be installed on your server. You can install Docker CE by following the below steps: ``` apt-get update -y ``` First, install the required dependencies using the following command: ``` apt-get install apt-transport-https ca-certificates curl gnupg2 software-properties-common ``` Next, add the Docker CE repository with the following command: ``` curl -fsSL https://download.docker.com/linux/debian/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/debian \ $(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null ``` Next, update the repository and install Docker CE with the following command: ``` apt-get update -y apt-get install docker-ce docker-ce-cli containerd.io -y ``` Once Docker is installed, verify the Docker installation using the following command: ``` docker version ``` You should see the following output: ``` Client: Docker Engine - Community Version: 28.4.0 API version: 1.51 Go version: go1.24.7 Git commit: d8eb465 Built: Wed Sep 3 20:57:37 2025 OS/Arch: linux/amd64 Context: default ``` ## Step 2 – Install Docker Compose You will also need to install Docker Compose to your system. First, download the latest version of Docker Compose binary using the following command: ``` wget https://github.com/docker/compose/releases/download/v2.39.2/docker-compose-linux-x86_64 ``` Next, copy the downloaded binary to the system path: ``` cp docker-compose-linux-x86_64 /usr/local/bin/docker-compose ``` Next, set executable permissions to the Docker Compose binary: ``` chmod +x /usr/local/bin/docker-compose ``` Next, verify the Docker Compose installation using the following command: ``` docker-compose --version ``` You should see the following output: ``` Docker Compose version v2.39.2 ``` ## Step 3 – Install Portainer UI First, create a volume to store Portainer data using the following command: ``` docker volume create portainer_data ``` Next, run the following command to download the Portainer image from the Docker Hub registry, create a container, and expose the container on port 9000: ``` docker run -d -p 8000:8000 -p 9000:9000 --name=portainer --restart=always -v /var/run/docker.sock:/var/run/docker.sock -v portainer_data:/data portainer/portainer ``` You should see the following output: ``` Unable to find image 'portainer/portainer:latest' locally latest: Pulling from portainer/portainer 94cfa856b2b1: Pull complete 49d59ee0881a: Pull complete a2300fd28637: Pull complete Digest: sha256:fb45b43738646048a0a0cc74fcee2865b69efde857e710126084ee5de9be0f3f Status: Downloaded newer image for portainer/portainer:latest 69d06a5c41851cc85df1924aa77566d2f38978faad5c27f52e089af8a0dc931e ``` You can verify the running container using the following command: ``` docker ps ``` You should see the following output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 69d06a5c4185 portainer/portainer "/portainer" 12 seconds ago Up 11 seconds 0.0.0.0:8000->8000/tcp, :::8000->8000/tcp, 0.0.0.0:9000->9000/tcp, :::9000->9000/tcp portainer ``` ## Step 4 – Access Portainer UI Now, open your web browser and access the Portainer UI using the URL **http://your-server-ip:9000**. You should see the following page: ![Portainer password set page](https://www.atlantic.net/wp-content/uploads/2021/12/p1-5-1024x581.png) Set your admin user and password and click on the **Create** **user** button. You will be asked to select the Docker environment that you want to manage: ![Portainer select docker environment](https://www.atlantic.net/wp-content/uploads/2021/12/p2-4-1024x498.png) Select the local environment and click on the **Connect** button. You should see the Portainer UI on the following page: ![Portainer dashboard](https://www.atlantic.net/wp-content/uploads/2021/12/p3-1-1024x534.png) ## Conclusion Congratulations! You have successfully installed Portainer UI on Debian 11. You can now create, deploy, and manage Docker containers from a web browser. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure Postgres 17 on Ubuntu > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-postgres-17-on-ubuntu/ | Published: 2023-12-04 | Updated: 2025-05-29 | Author: Hitesh Jethva PostgreSQL, a popular open-source object-relational database system, is renowned for its reliability, feature robustness, and performance, facilitating the development of complex, fault-tolerant applications. This post will explain how to install and configure PostgreSQL 17 on Ubuntu. This procedure is compatible with Ubuntu 22.04 and Ubuntu 24.04. ## Step 1 – Update Server and Install Pre-Requisites Once you are logged in to your server, run the following command to update your base system with the latest available packages. ``` apt-get update -y ``` Install the following prerequisites: ``` apt install gnupg gnupg2 gnupg1 -y ``` ## Step 2 – Install PostgreSQL 17 The latest version of PostgreSQL is not included in the Ubuntu default repository, so you will need to add the PostgreSQL official repository to the APT. You can add it with the following command: ``` sh -c 'echo "deb http://apt.postgresql.org/pub/repos/apt $(lsb_release -cs)-pgdg main" > /etc/apt/sources.list.d/pgdg.list' ``` Next, download and add the PostgreSQL GPG key using the following command: ``` wget -qO- https://www.postgresql.org/media/keys/ACCC4CF8.asc | tee /etc/apt/trusted.gpg.d/pgdg.asc &>/dev/null ``` Next, update the repository cache and install PostgreSQL 17 using the following command: ``` apt-get update -y apt install postgresql-17 postgresql-client-17 -y ``` **Please be aware** that the configured PostgreSQL repository mentioned above is capable of downloading the most recent version of PostgreSQL. As of this update, PostgreSQL is operating on version 17, with the release of version 18 imminent. To ensure the installation of the latest version at any time, modify the command above as follows: ``` apt-get -y install postgresql ``` After installing PostgreSQL, check the status of the PostgreSQL with the following command: ``` systemctl status postgresql ``` You will get the following output: ``` ● postgresql.service - PostgreSQL RDBMS Loaded: loaded (/usr/lib/systemd/system/postgresql.service; enabled; preset: enabled) Active: active (exited) since Sun 2025-05-11 08:31:02 UTC; 7min ago Main PID: 69995 (code=exited, status=0/SUCCESS) CPU: 3ms May 11 08:31:02 ubuntu systemd[1]: Starting postgresql.service - PostgreSQL RDBMS... May 11 08:31:02 ubuntu systemd[1]: Finished postgresql.service - PostgreSQL RDBMS. ``` You can also verify the PostgreSQL version using the command below: ``` sudo -u postgres psql -c "SELECT version();" ``` You will get the following output: ``` version ---------------------------------------------------------------------------------------------------------------------------------- PostgreSQL 17.5 (Ubuntu 17.5-1.pgdg24.04+1) on x86_64-pc-linux-gnu, compiled by gcc (Ubuntu 13.3.0-6ubuntu2~24.04) 13.3.0, 64-bit ``` ## Step 3 – Create a Database and User in PostgreSQL First, you can connect to PostgreSQL with the following command: ``` su - postgres psql ``` You will get the following shell: ``` psql (17.5 (Ubuntu 17.5-1.pgdg24.04+1))Type "help" for help. postgres=# ``` Next, create a superuser named root with the following command: ``` CREATE ROLE root WITH LOGIN SUPERUSER CREATEDB CREATEROLE PASSWORD 'securepassword'; ``` Run the following command to verify the superuser: ``` \du ``` You will get the following output: ``` List of roles Role name | Attributes | Member of -----------+------------------------------------------------------------+----------- postgres | Superuser, Create role, Create DB, Replication, Bypass RLS | {} root | Superuser, Create role, Create DB | {} ``` To create a database named dbname, run: ``` create database dbname; ``` To create a new user named dbuser, run: ``` create user dbuser with encrypted password 'dbpassword'; ``` To grant all privileges to the dbname to dbuser, run: ``` grant all privileges on database dbname to dbuser; ``` To list all databases, run: ``` \l ``` You will get the following output: ``` List of databases Name | Owner | Encoding | Collate | Ctype | Access privileges -----------+----------+----------+-------------+-------------+----------------------- dbname | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | =Tc/postgres + | | | | | postgres=CTc/postgres+ | | | | | dbuser=CTc/postgres postgres | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | template0 | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | =c/postgres + | | | | | postgres=CTc/postgres template1 | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | =c/postgres + | | | | | postgres=CTc/postgres (4 rows) ``` To exit from the PostgreSQL shell, run: ``` \q exit ``` ## Step 4 – Configure PostgreSQL for Remote Access By default, PostgreSQL is configured for local access only. If your application and database servers are hosted on a different server, then you must configure PostgreSQL for remote access. You can configure it by editing the file pg_hba.conf: ``` nano /etc/postgresql/17/main/pg_hba.conf ``` Find the following line: ``` local all all peer ``` And replace it with the following line: ``` local all all trust ``` Next, add the following line: ``` host all all 0.0.0.0/0 md5 ``` Save and close the file when you have finished. Next, you will also need to edit the PostgreSQL main configuration file and change the listening port: ``` nano /etc/postgresql/17/main/postgresql.conf ``` Change the following line: ``` listen_addresses='*' ``` Save and close the file, then restart the PostgreSQL service to apply the changes: ``` systemctl restart postgresql ``` You can now check the PostgreSQL listening port using the following command: ``` ss -antpl | grep 5432 ``` You will get the following output: ``` LISTEN 0 244 0.0.0.0:5432 0.0.0.0:* users:(("postgres",pid=19030,fd=5)) LISTEN 0 244 [::]:5432 [::]:* users:(("postgres",pid=19030,fd=6)) ``` Now, go to the remote system and connect to the PostgreSQL instance using the following command: ``` psql 'postgres://root:securepassword@104.245.34.223:5432/postgres?sslmode=disable' ``` If everything is fine, you will get the following shell: ``` psql (17.5 (Ubuntu 17.5-1.pgdg24.04+1)) Type "help" for help. postgres=# ``` ## Conclusion You learned how to install and configure PostgreSQL 17 on Ubuntu in the above post. You can now start developing high-performance and complex applications with the PostgreSQL database backend. Try it on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Create and Install a Self-Signed SSL Certificate on Ubuntu > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-create-and-install-a-self-signed-ssl-certificate-on-ubuntu/ | Published: 2023-12-05 | Updated: 2024-06-03 | Author: Hitesh Jethva When you are shopping or banking online, you want to make sure the websites you are on are using HTTPS, which you can verify by noting a green padlock icon is in the address bar. HTTPS is the secure version of HTTP, a protocol used between a browser and a web server. Technically, HTTPS refers to HTTP over Secure Socket Layer (SSL). HTTPS means all communications between your browser and the web server are encrypted. Behind HTTPS, an SSL certificate plays an important role in building trust between a browser and a web server. In short, an SSL certificate is a web server’s digital certificate issued by a third party that verifies the identity of the web server and its public key. A self-signed certificate is a certificate that is not signed by a certificate authority (CA). It is used internally within labs or business environments. However, this certificate has the same level of encryption as trusted certificates. In this tutorial, we will show you how to generate a self-signed certificate and configure Apache to use this certificate. ## Step 1 – Install Apache Web Server Before starting, an Apache webserver must be installed on your server. If not installed, you can install it with the following command: ``` apt-get install apache2 openssl -y ``` Once Apache is installed, you can proceed to the next step. ## Step 2 – Generate Self-Signed Certificate SSL uses public and private keys. The private key resides on the server and is used to encrypt the content, while the public key is used to decrypt the content and is shared among the clients. First, you will need to generate a private key and a certificate signing request (CSR) for your domain. You can generate it with the following command: ``` openssl req -nodes -newkey rsa:2048 -keyout /etc/ssl/private/private.key -out /etc/ssl/private/request.csr ``` You will be asked to provide your certificate information including Common Name, Organization, City, State, and Country as shown below: ``` Generating a RSA private key ..........................................................................+++++ ............................................................................................+++++ writing new private key to '/etc/ssl/private/private.key' ----- You are about to be asked to enter information that will be incorporated into your certificate request. What you are about to enter is what is called a Distinguished Name or a DN. There are quite a few fields but you can leave some blank For some fields there will be a default value, If you enter '.', the field will be left blank. ----- Country Name (2 letter code) [AU]:US State or Province Name (full name) [Some-State]:Newyork Locality Name (eg, city) []:Newyork Organization Name (eg, company) [Internet Widgits Pty Ltd]:Atlantic Organizational Unit Name (eg, section) []:IT Common Name (e.g. server FQDN or YOUR name) []:Atlantic Email Address []:admin@example.com Please enter the following 'extra' attributes to be sent with your certificate request A challenge password []: An optional company name []: ``` Once your request.csr is generated, you can generate the SSL certificate with the following command: ``` openssl x509 -in /etc/ssl/private/request.csr -out /etc/ssl/private/certificate.crt -req -signkey /etc/ssl/private/private.key -days 365 ``` You should get the following output: ``` Signature ok subject=C = US, ST = Newyork, L = Newyork, O = Atlantic, OU = IT, CN = Atlantic, emailAddress = admin@example.com Getting Private key ``` At this point, the certificate (certificate.crt) and key (private.key) file are ready to be used with the Apache webserver. ## Step 3 – Configure Apache to Use SSL Now, you will need to configure Apache to use the certificate which you have generated in the previous step. First, open the Apache default SSL configuration file: ``` nano /etc/apache2/sites-available/default-ssl.conf ``` Define your domain name and SSL certificate as shown below: ``` ServerAdmin admin@example.com ServerName your-server-ip DocumentRoot /var/www/html ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined SSLEngine on SSLCertificateFile /etc/ssl/private/certificate.crt SSLCertificateKeyFile /etc/ssl/private/private.key SSLOptions +StdEnvVars SSLOptions +StdEnvVars ``` Save and close the file, then enable the virtual host file with the following command: ``` a2ensite default-ssl.conf ``` Next, open the Apache default virtual host configuration file as shown below: ``` nano /etc/apache2/sites-available/000-default.conf ``` Define your domain name and add a Redirect directive, pointing all traffic to the SSL version of the site: ``` ServerAdmin admin@example.com ServerName your-server-ip DocumentRoot /var/www/html ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined Redirect "/" "https://your-server-ip/ ``` Next, enable the SSL and header module with the following command: ``` a2enmod ssl a2enmod headers ``` Finally, reload the Apache service to implement the changes: ``` systemctl reload apache2 ``` At this point, your Apache web server is configured to use an SSL certificate. ## Step 4 – Verify Your SSL Server Now, open your web browser and type the URL https://your-server-ip. You will be redirected to the warning page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/selfsigned1.png) This is because your certificate is not signed by trusted certificate authorities. This is expected and normal. Just ignore it and click on the proceed to your host. You will be redirected to the Apache default page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/selfsigned2.png) In the browser address bar, you will see a lock with a “not secure” notice. That means the certificate is not validated but is still encrypting your connection. ## Conclusion In this guide, you learned how to generate a self-signed certificate and configure your Apache web server to use this certificate for client connections. You can now easily deploy the SSL in your internal network and encrypt the connections. Try out a self-signed certificate on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! Learn more about our [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/). --- # How to Install and Configure Zammad Ticketing System on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-configure-zammad-ticketing-system-on-ubuntu/ | Published: 2023-12-06 | Updated: 2025-05-25 | Author: Hitesh Jethva Zammad is an open-source ticketing system written in Ruby specially designed for customer support teams. It allows you to deal with customer queries and complaints from various channels, including web forms, Twitter, Facebook, email, chat, and more. Zammad also provides an API to integrate your telephone system. It offers a rich set of features including auto-save, full-text search, two-factor-authentication, and external authentication via Twitter, Facebook, LinkedIn, or Google. In this tutorial, we will learn how to install Zammad Ticketing System on Ubuntu. This procedure is compatible with Ubuntu 22.04 and Ubuntu 24.04. ## Step 1 – Install Java Zammad requires Java to be installed on your server. You can install Java JDK with the following command: ``` apt-get install default-jdk -y ``` Once installed, verify the installed version of Java using the following command: ``` java -version ``` You should get the following output: ``` openjdk 21.0.7 2025-04-15 OpenJDK Runtime Environment (build 21.0.7+6-Ubuntu-0ubuntu124.04) OpenJDK 64-Bit Server VM (build 21.0.7+6-Ubuntu-0ubuntu124.04, mixed mode, sharing) ``` ## Step 2 – Install ElasticSearch Zammad uses Elasticsearch to provide the search function. By default, ElasticSearch is not available in the Ubuntu 24.04 default repository, so you will need to add the ElasticSearch repository to your system. You can add it with the following commands: ``` apt-get install apt-transport-https gnupg -y wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | apt-key add - curl -fsSL https://artifacts.elastic.co/GPG-KEY-elasticsearch | gpg --dearmor | tee /etc/apt/trusted.gpg.d/elasticsearch.gpg> /dev/null echo "deb [signed-by=/etc/apt/trusted.gpg.d/elasticsearch.gpg] https://artifacts.elastic.co/packages/7.x/apt stable main"| tee -a /etc/apt/sources.list.d/elastic-7.x.list > /dev/null ``` Next, update the repository and install ElasticSearch with the following command: ``` apt-get update -y apt-get install elasticsearch -y ``` Once installed, start the ElasticSearch service and enable it to start at boot: ``` systemctl start elasticsearch systemctl enable elasticsearch ``` Next, you will need to allow Elasticsearch to index file attachments. You can do it with the following command: ``` /usr/share/elasticsearch/bin/elasticsearch-plugin install ingest-attachment ``` You should get the following output: ``` -> Installing ingest-attachment -> Downloading ingest-attachment from elastic [=================================================] 100% @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @ WARNING: plugin requires additional permissions @ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ * java.lang.RuntimePermission accessClassInPackage.sun.java2d.cmm.kcms * java.lang.RuntimePermission accessDeclaredMembers * java.lang.RuntimePermission getClassLoader * java.lang.reflect.ReflectPermission suppressAccessChecks * java.security.SecurityPermission createAccessControlContext * java.security.SecurityPermission insertProvider * java.security.SecurityPermission putProviderProperty.BC See http://docs.oracle.com/javase/8/docs/technotes/guides/security/permissions.html for descriptions of what these permissions allow and the associated risks. Continue with installation? [y/N]y -> Installed ingest-attachment ``` Edit the Elasticsearch configuration file. ``` nano /etc/elasticsearch/elasticsearch.yml ``` Set max content length. ``` http.max_content_length: 400mb ``` Next, restart ElasticSearch to apply the changes: ``` systemctl restart elasticsearch ``` ## Step 3 – Install Zammad By default, Zammad is not available in the Ubuntu 24.04 default repository, so you will need to add Zammad repository in your system. First, download and add the GPG key with the following command: ``` curl -fsSL https://dl.packager.io/srv/zammad/zammad/key | gpg --dearmor | tee /etc/apt/keyrings/pkgr-zammad.gpg> /dev/null ``` Next, add the Zammad repository with the following command: ``` echo "deb [signed-by=/etc/apt/keyrings/pkgr-zammad.gpg] https://dl.packager.io/srv/deb/zammad/zammad/stable/ubuntu 24.04 main"| tee /etc/apt/sources.list.d/zammad.list > /dev/null ``` Next, update the repository and install Zammad with the following command: ``` apt-get update -y apt-get install zammad -y ``` Next, you will need to configure Zammad to work with Elasticsearch, add extra Elasticsearch index name space, and set the max attachment size. You can do that with the following command: ``` zammad run rails r "Setting.set('es_url', 'http://localhost:9200')" zammad run rails r "Setting.set('es_user', 'elastic')" zammad run rake zammad:searchindex:rebuild zammad run rails r "Setting.set('es_index', Socket.gethostname.downcase + '_zammad')" zammad run rails r "Setting.set('es_attachment_ignore', [ '.png', '.jpg', '.jpeg', '.mpeg', '.mpg', '.mov', '.bin', '.exe', '.box', '.mbox' ] )" zammad run rails r "Setting.set('es_attachment_max_size_in_mb', 50)" ``` ## Step 4 – Start Zammad By default, Zammad service is managed by systemd. First, start and enable the Zammad service. ``` systemctl start zammad systemctl enable zammad ``` Verify the status of Zammad service. ``` systemctl status zammad ``` Output. ``` ● zammad.service Loaded: loaded (/etc/systemd/system/zammad.service; enabled; preset: enabled) Active: active (running) since Sun 2025-05-25 04:57:50 UTC; 1s ago Main PID: 11744 (sleep) Tasks: 1 (limit: 4609) Memory: 360.0K (peak: 612.0K) CPU: 3ms CGroup: /system.slice/zammad.service └─11744 /bin/sleep infinity ``` Next, remove the Nginx default virtual host file. ``` rm -rf /etc/nginx/sites-enabled/default ``` Next, restart the Nginx service. ``` systemctl restart nginx ``` ## Step 5 – Access Zammad Web Interface Now, open your web browser and access the Zammad web interface using the URL **http://your-server-ip**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/zammad2.png) Click on the **Setup** **new** **System**. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/zammad3.png) Provide your admin username, password, and email and click on the **Create** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/zammad4.png) Provide your Organization name, upload a logo, provide system URL, and click on the **Next** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/zammad5.png) Select your MTA and click on the **Continue** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/zammad6.png) Click on the **Skip** button. You should see the Zammad dashboard in the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/10/zammad7.png) ## Conclusion In this guide, you learned how to install and configure the Zammad ticketing system on Ubuntu 24.04. Try hosting your own online ticketing system with Zammad on [VPS Hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net. --- # How to Install and Configure Supervisor on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-install-and-configure-supervisor-on-ubuntu/ | Published: 2023-12-07 | Updated: 2025-05-25 | Author: Hitesh Jethva In Linux, Supervisor offers an efficient way to manage processes on UNIX systems, automating the restart of crashed processes and providing precise up/down status information. In this tutorial, we will learn how to install Supervisor and configure it to manage the Nginx process on Ubuntu. This procedure is compatible with Ubuntu 22.04 and Ubuntu 24.04. ## Step 1 – Install Supervisor By default, the Supervisor package is available in the Ubuntu default repository. You can install it with the following commands: ``` apt-get update -y ``` ``` apt-get install supervisor -y ``` After installing Supervisor, you can verify the installed version of the Supervisor with the following command: ``` supervisord -v ``` You should get the following output: ``` 4.2.5 ``` Next, verify the status of the Supervisor service with the following command: ``` systemctl status supervisor ``` You should get the following output: ``` ● supervisor.service - Supervisor process control system for UNIX Loaded: loaded (/usr/lib/systemd/system/supervisor.service; enabled; preset: enabled) Active: active (running) since Sun 2025-05-25 09:30:18 UTC; 22s ago Docs: http://supervisord.org Main PID: 109733 (supervisord) Tasks: 1 (limit: 4609) Memory: 22.1M (peak: 24.1M) CPU: 217ms CGroup: /system.slice/supervisor.service └─109733 /usr/bin/python3 /usr/bin/supervisord -n -c /etc/supervisor/supervisord.conf May 25 09:30:18 ubuntu24 systemd[1]: Started supervisor.service - Supervisor process control system for UNIX. May 25 09:30:18 ubuntu24 supervisord[109733]: 2025-05-25 09:30:18,405 CRIT Supervisor is running as root. Privileges were not dropped because no user is specified in May 25 09:30:18 ubuntu24 supervisord[109733]: 2025-05-25 09:30:18,405 WARN No file matches via include "/etc/supervisor/conf.d/*.conf" May 25 09:30:18 ubuntu24 supervisord[109733]: 2025-05-25 09:30:18,409 INFO RPC interface 'supervisor' initialized May 25 09:30:18 ubuntu24 supervisord[109733]: 2025-05-25 09:30:18,409 CRIT Server 'unix_http_server' running without any HTTP authentication checking May 25 09:30:18 ubuntu24 supervisord[109733]: 2025-05-25 09:30:18,410 INFO supervisord started with pid 109733 ``` ## Step 2 – Enable Supervisor Web Interface Supervisor provides a web-based interface to manage all processes, but it is disabled by default. You can enable it by editing the file /etc/supervisor/supervisord.conf. ``` nano /etc/supervisor/supervisord.conf ``` Add the following lines: ``` [inet_http_server] port=*:9001 username=admin password=admin ``` Save and close the file, then restart the Supervisor service to apply the changes: ``` systemctl restart supervisor ``` ## Step 3 – Manage the Nginx Process with Supervisor In this section, we will learn how to control the Nginx process with Supervisor. First, install the Nginx server with the following command: ``` apt-get install nginx -y ``` After installing Nginx, you will need to stop and disable the Nginx service as we will use Supervisor to manage the Nginx process. You can stop and disable the Nginx service with the following command: ``` systemctl stop nginx systemctl disable nginx ``` Next, you will need to create a standalone configuration file for each service that you want to manage. You can create an Nginx configuration file with the following command: ``` nano /etc/supervisor/conf.d/nginx.conf ``` Add the following lines: ``` [program:nginx] command=/usr/sbin/nginx -g "daemon off;" autostart=true autorestart=true startretries=5 numprocs=1 startsecs=0 process_name=%(program_name)s_%(process_num)02d stderr_logfile=/var/log/supervisor/%(program_name)s_stderr.log stderr_logfile_maxbytes=10MB stdout_logfile=/var/log/supervisor/%(program_name)s_stdout.log stdout_logfile_maxbytes=10MB ``` Save and close the file when you are finished. Next, tell the Supervisor to know about the new config: ``` supervisorctl reread ``` You should get the following output: ``` nginx: available ``` Next, tell Supervisor to start the Nginx service: ``` supervisorctl update ``` You should get the following output: ``` nginx: added process group ``` Next, verify whether Supervisor started the Nginx service with the following command: ``` supervisorctl ``` You should get the following output: ``` nginx:nginx_00                   RUNNING   pid 15717, uptime 0:00:13 ``` If you want to stop the Nginx service, run the following command: ``` stop nginx:nginx_00 ``` Output: ``` nginx:nginx_00: stopped ``` To start the Nginx service again, run the following command: ``` start nginx:nginx_00 ``` Output: ``` nginx:nginx_00: started ``` Now, exit from the Supervisor shell with the following command: ``` exit ``` You can also verify the Nginx process with the following command: ``` ps aux | grep nginx ``` You should get the following output: ``` root       15721  0.0  0.4  57176 10064 ?        S    14:14   0:00 nginx: master process /usr/sbin/nginx - g daemon off; www-data   15722  0.0  0.2  57828  5340 ?        S    14:14   0:00 nginx: worker process www-data   15723  0.0  0.2  57828  5340 ?        S    14:14   0:00 nginx: worker process ``` ## Step 4 – Access Supervisor Web Interface You can now access the Supervisor web interface using the URL **http://your-server-ip:9001**. You will be asked to provide a username and password as shown below: ![](https://www.atlantic.net/wp-content/uploads/2021/01/supervisor1.png) Provide your admin username and password that you have defined in the configuration file, then click on the **Sign-in** button. You should see the Supervisor web interface in the following page: ![](https://www.atlantic.net/wp-content/uploads/2021/01/supervisor2.png) ## Conclusion In this guide, you learned how to install Supervisor and enable the web interface on Ubuntu. You also learned how to control the Nginx process with Supervisor. Try controlling processes on your Linux [VPS hosting](https://www.atlantic.net/vps-hosting/) account with Atlantic.Net! --- # How to Create Samba Share on Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-create-samba-share-on-ubuntu/ | Published: 2023-12-08 | Updated: 2025-05-13 | Author: Hitesh Jethva Samba, also known as “Server Message Block,” is a Common Internet File System protocol used for sharing files, directories, and print services across a network on Linux. It allows you to grant read, write, and anonymous access permissions on a shared directory. It is extremely useful for those who use both Windows and Linux systems on their network. In this post, we will explain how to install and use Samba to share files and directories on Ubuntu. This procedure is compatible with Ubuntu 22.04 and Ubuntu 24.04. ## Step 1 – Install Samba Server By default, the Samba package is included in the Ubuntu repository. You can install it using the following command: ``` apt-get install samba samba-common-bin acl -y ``` Once installed, start the Samba services and enable them to start at system reboot: ``` systemctl start smbd nmbd systemctl enable smbd nmbd ``` You can check the installed version of Samba with the following command: ``` smbd --version ``` Output: ``` Version 4.19.5-Ubuntu ``` ## Step 2 – Create a Private Share with Samba In this section, we will show you how to create a private share using Samba so that only authenticated users can access the share. To do so, edit the Samba main configuration file: ``` nano /etc/samba/smb.conf ``` Next, add the following lines at the end of the file: ``` [Private] comment = private share path = /data/private/ browseable = yes guest ok = no writable = yes valid users = @samba ``` Save and close the file, then create a new user with the following command: ``` adduser user1 ``` You should see the following output: ``` Adding user `user1' ... Adding new group `user1' (1000) ... Adding new user `user1' (1000) with group `user1' ... Creating home directory `/home/user1' ... Copying files from `/etc/skel' ... New password: Retype new password: passwd: password updated successfully Changing the user information for user1 Enter the new value, or press ENTER for the default Full Name []: Room Number []: Work Phone []: Home Phone []: Other []: Is the information correct? [Y/n] Y ``` Next, set a Samba password with the following command: ``` smbpasswd -a user1 ``` You should see the following output: ``` New SMB password: Retype new SMB password: Added user user1. ``` Next, create a Samba group with the following command: ``` groupadd samba ``` Next, add user1 to the samba group: ``` gpasswd -a user1 samba ``` Next, create a shared folder that you have specified in the smb.conf file: ``` mkdir -p /data/private touch /data/private/file1 ``` Next, provide read and write permissions to the Samba share: ``` setfacl -R -m "g:samba:rwx" /data/private ``` Next, check the Samba configuration file for any errors with the following command: ``` testparm ``` Next, restart the Samba service to apply the changes: ``` systemctl restart smbd nmbd ``` ## Step 3 – Create a Public Share with Samba In this section, we will show you how to create a public share with Samba so everyone can access the public share without providing a username and password. To create a public share, edit the Samba main configuration file: ``` nano /etc/samba/smb.conf ``` Add the following lines at the end of the file: ``` [Public] comment = public share path = /data/public/ browseable = yes writable = yes guest ok = yes ``` Save and close the file, then create a public directory: ``` mkdir -p /data/public/ touch /data/public/file2 ``` Next, set proper permissions on the public directory: ``` setfacl -R -m "u:nobody:rwx" /data/public ``` Next, restart the Samba service to apply the changes: ``` systemctl restart smbd nmbd ``` ## Step 4 – Access Samba Share from Linux In order to access the Samba share, you will need to install the Samba client on the Linux system. You can install it using the following command: ``` apt-get install smbclient cifs-utils -y ``` Next, run the following command to access the private share from the Samba server: ``` smbclient //samba-ip-address/private -U user1 ``` You will be asked to provide a password for user1: ``` Enter WORKGROUP\user1's password: Try "help" to get a list of possible commands. ``` Once you are connected, run the following command to list Samba share: ``` smb: \> list 0: server=69.87.221.84, share=private ``` Next, list all the files in the private share directory: ``` smb: \> ls ``` You should see the following output: ``` . D 0 Sun May 11 08:17:58 2025 .. D 0 Sun May 11 08:18:13 2025 file1 N 0 Sun May 11 08:17:58 2025 51538400 blocks of size 1024. 47348972 blocks available ``` Next, exit from the Samba shell with the following command: ``` smb: \> exit ``` If you want to connect to the Public share, run the following command: ``` smbclient //samba-ip-address/public ``` Just press Enter without providing any password: ``` Enter WORKGROUP\root's password: Try "help" to get a list of possible commands. smb: \> ``` Next, run the following command to list all files in the Public share: ``` smb: \> ls ``` Output: ``` . D 0 Sun May 11 08:18:17 2025 .. D 0 Sun May 11 08:18:13 2025 file2 N 0 Sun May 11 08:18:17 2025 51538400 blocks of size 1024. 47348972 blocks available ``` ## Step 5 – Mount Samba Share on Linux Samba also allows you to mount a shared directory to the client system so you can access and use it. First, create a directory on the client system where you want to mount the Samba share: ``` mkdir /mount ``` Next, run the following command to mount the Private share directory to the client system: ``` mount -t cifs -o username=user1 //samba-ip-address/private /mount ``` You will be asked to provide a password of user1 to mount the directory: ``` Password for user1@//69.87.221.84/private: ********* ``` Next, verify the mounted directory with the following command: ``` df -h ``` You should see your Private shared directory mounted on the /mount directory: ``` Filesystem Size Used Avail Use% Mounted on udev 981M 0 981M 0% /dev tmpfs 199M 2.2M 197M 2% /run /dev/sda1 50G 1.9G 46G 4% / tmpfs 994M 0 994M 0% /dev/shm tmpfs 5.0M 0 5.0M 0% /run/lock tmpfs 994M 0 994M 0% /sys/fs/cgroup tmpfs 199M 0 199M 0% /run/user/0 //69.87.221.84/private 50G 4.0G 46G 9% /mount ``` Now, access the Samba share locally using the following command: ``` ls /mount/ ``` You should see the following output: ``` file1 ``` ## Conclusion In the above guide, you learned how to install Samba and use it to share files and directories between Linux systems. Give it a try on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install and Use Podman on Ubuntu > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-podman-on-ubuntu/ | Published: 2023-12-10 | Updated: 2023-12-15 | Author: Hitesh Jethva Podman is a tool used for developing, managing, and running containers and images. It is developed by Red Hat and designed to be a drop-in Docker replacement. Podman is very similar to Docker. The main difference is that Docker needs the Docker Engine daemon while Podman doesn’t require a daemon to run containers. It supports multiple image formats and several ways to load images. In this post, we will show you how to install and use Podman on an Ubuntu server. This procedure is compatible with Ubuntu 20.04 and Ubuntu 22.04. ## Step 1 – Install Podman First, you will need to install some dependencies required to install Podman. You can install them with the following command: ``` apt-get install curl wget gnupg2 -y ``` Next, source your Ubuntu release and add the Podman repository with the following command: ``` source /etc/os-release sh -c "echo 'deb http://download.opensuse.org/repositories/devel:/kubic:/libcontainers:/stable/xUbuntu_${VERSION_ID}/ /' > /etc/apt/sources.list.d/devel:kubic:libcontainers:stable.list" ``` Next, download and add the GPG key with the following command: ``` wget -nv https://download.opensuse.org/repositories/devel:kubic:libcontainers:stable/xUbuntu_${VERSION_ID}/Release.key -O- | apt-key add - ``` Next, update the repository and install Podman with the following command: ``` apt-get update -qq -y apt-get -qq --yes install podman ``` After installing Podman, verify the Podman version with the following command: ``` podman --version ``` You should get the following output: ``` podman version 3.1.2 ``` You can also check more information with the following command: ``` podman info ``` You should see the following output: ``` host: arch: amd64 buildahVersion: 1.20.1 cgroupManager: systemd cgroupVersion: v1 conmon: package: 'conmon: /usr/libexec/podman/conmon' path: /usr/libexec/podman/conmon version: 'conmon version 2.0.27, commit: ' cpus: 2 distribution: distribution: ubuntu version: "20.04" eventLogger: journald hostname: ubuntu2004 idMappings: gidmap: null uidmap: null kernel: 5.4.0-29-generic ``` ## Step 2 – Add OCI Registry When you pull an image using the Podman command, it will look for a list of registries from the registry configuration file /etc/containers/registries.conf. You can edit and add different registries in the configuration file. ``` nano /etc/containers/registries.conf ``` Add the following lines at the end of the file: ``` [registries.search] registries=["registry.access.redhat.com", "registry.fedoraproject.org", "docker.io"] ``` Save and close the file when you are finished. ## Step 3 -Working with Podman In this section, we will show you how to search and pull images and run a container with the Podman command. To search for Debian-10 images, run the following command: ``` podman search debian-10 ``` You should see all Debian 10 images in the following output: ``` INDEX NAME DESCRIPTION STARS OFFICIAL AUTOMATED docker.io docker.io/dokken/debian-10 Debian 10 image for use with kitchen-dokken 0 docker.io docker.io/pythonpillow/debian-10-buster-x86 0 docker.io docker.io/diodonfrost/debian-10-ansible DEPRECATED - move to diodonfrost/ansible-deb... 0 docker.io docker.io/ingescape/debian-10-with-zyre 0 docker.io docker.io/alvistack/debian-10 0 docker.io docker.io/naparuba/debian-10-python3 0 docker.io docker.io/ursa/debian-10 0 docker.io docker.io/naparuba/debian-10 0 docker.io docker.io/opencpu/debian-10 OpenCPU server of Debian 10 0 docker.io docker.io/mesaguy/debian-10-kitchen-ansible-x86_64 Debian 10 image for testing Ansible playbook... 0 [OK] docker.io docker.io/mesaguy/debian-10-boot-x86_64 Debian 10 image, bootable for testing purpos... 0 [OK] docker.io docker.io/couchbasebuild/debian-10-gcc 0 docker.io docker.io/radarhere/debian-10-buster-x86 0 docker.io docker.io/nkbvs/debian-10_i386_cpp_base 0 docker.io docker.io/quentinjdu21/debian-10 0 docker.io docker.io/mitting/debian-10-web 0 docker.io docker.io/freehackquest/debian-10-for-cpp-build Docker with preinstalled g++, cmake, make, m... 0 docker.io docker.io/lbelmarletelier/debian-10-builder 0 docker.io docker.io/armpits/debian-10-armhf Docker import of minimal Debian chroot. 0 docker.io docker.io/arthurpicht/debian-10 Basic debian 10 "Buster" image with extended... 0 ``` To download the Nginx image, run the following command: ``` podman pull nginx ``` You should see the following output: ``` ✔ docker.io/library/nginx:latest Trying to pull docker.io/library/nginx:latest... Getting image source signatures Copying blob 596b1d696923 done Copying blob 8283eee92e2f done Copying blob 69692152171a done Copying blob febe5bd23e98 done Copying blob 351ad75a6cfa done Copying blob 30afc0b18f67 done Copying config d1a364dc54 done Writing manifest to image destination Storing signatures d1a364dc548d5357f0da3268c888e1971bbdb957ee3f028fe7194f1d61c6fdee ``` To list all downloaded images, run the following command: ``` podman images ``` You should see the following output: ``` REPOSITORY TAG IMAGE ID CREATED SIZE docker.io/library/nginx latest d1a364dc548d 2 weeks ago 137 MB ``` To create a new container from the Nginx image, run the following command: ``` podman run -dit nginx ``` You can now check the Nginx container with the following command: ``` podman ps ``` You should see the following output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES c1692863973d docker.io/library/nginx:latest nginx -g daemon o... 20 seconds ago Up 19 seconds ago priceless_lewin ``` To create a new image from the running Nginx container, run the following command: ``` podman commit --author "Author Name Hitesh" c1692863973d docker.io/library/new-nginx ``` You should see the following output: ``` Getting image source signatures Copying blob 02c055ef67f5 skipped: already exists Copying blob 766fe2c3fc08 skipped: already exists Copying blob 83634f76e732 skipped: already exists Copying blob 134e19b2fac5 skipped: already exists Copying blob 5c865c78bc96 skipped: already exists Copying blob 075508cf8f04 skipped: already exists Copying blob af6431b8bf0b done Copying config bf2a70efe3 done Writing manifest to image destination Storing signatures bf2a70efe38f99b363f8f0b7dfd395d3aec81571ed03ac7b0898954379f16768 ``` You can now check the newly created image with the following command: ``` podman images ``` You should see the following output: ``` REPOSITORY TAG IMAGE ID CREATED SIZE docker.io/library/new-nginx latest bf2a70efe38f 22 seconds ago 137 MB docker.io/library/nginx latest d1a364dc548d 2 weeks ago 137 MB ``` To stop the running container, run the following command: ``` podman stop container-id ``` To remove the running container, run the following command: ``` podman remove container-id ``` To stop and start the latest container, run the following command: ``` podman stop --latest podman start --latest ``` To remove the latest container, run the following command: ``` podman rm --latest ``` ## Conclusion In the above guide, you learned how to install and use Podman on an Ubuntu server. Podman is a great tool for managing containers and images – give it a try on your [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) account from Atlantic.Net. You can explore the Podman for more interesting features. --- # How to Set Up an FTP Server with ProFTPD in Ubuntu > URL: https://www.atlantic.net/vps-hosting/how-to-set-up-an-ftp-server-with-proftpd-in-ubuntu/ | Published: 2023-12-11 | Updated: 2025-07-04 | Author: Hitesh Jethva Transferring files over the FTP protocol is one of the most popular methods of uploading files to a server. ProFTPD is a reliable, free, open-source FTP server that allows you to create an FTP connection between your local system and a web server. ProFTP comes with a options that are not available in many other FTP software options. It provides a rich set of features including tls/ssl support, anonymous FTP, multiple virtual FTPs, shadow password suite support, the ability to run as a configurable non-privileged user, support for IPv6, and many more. In this tutorial, we will explain how to install a ProFTP server on Ubuntu. This procedure is compatible with Ubuntu 18.04, Ubuntu 22.04, and Ubuntu 24.04. We will also show you how to encrypt the entire transmission with SSL/TLS. ## Step 1 – Install ProFTP By default, the ProFTP package is available in the Ubuntu 18.04 default repository. You can install it by just running the following command: ``` apt-get update -y apt-get install proftpd proftpd-mod-crypto -y ``` Once the installation is finished, start the ProFTP service and enable it to start after system reboot using the following command: ``` systemctl start proftpd systemctl enable proftpd ``` You can also verify the status of the ProFTP service with the following command: ``` systemctl status proftpd ``` You should get the following output: ``` ● proftpd.service - ProFTPD FTP Server Loaded: loaded (/usr/lib/systemd/system/proftpd.service; enabled; preset: enabled) Active: active (running) since Thu 2025-05-15 05:27:40 UTC; 9s ago Docs: man:proftpd(8) Process: 28055 ExecStartPre=/usr/sbin/proftpd --configtest -c $CONFIG_FILE $OPTIONS (code=exited, status=0/SUCCESS) Process: 28057 ExecStart=/usr/sbin/proftpd -c $CONFIG_FILE $OPTIONS (code=exited, status=0/SUCCESS) Main PID: 28058 (proftpd) Tasks: 1 (limit: 629145) Memory: 1.9M (peak: 3.0M) CPU: 31ms CGroup: /system.slice/proftpd.service └─28058 "proftpd: (accepting connections)" ``` ## Step 2 – Create a Self-signed SSL/TLS Certificate By default, FTP is not secured because passwords and data are transferred in clear text, so it is recommended to secure your FTP with SSL/TLS. To do so, run the following command to generate a self-signed SSL/TLS certificate for the server. ``` openssl req -x509 -nodes -newkey rsa:2048 -keyout /etc/ssl/private/serverkey.pem -out /etc/ssl/certs/servercertificate.pem -days 365 ``` **Answer all the questions as shown below:** During the installation, you will be asked a number of questions. These questions will be specific to you. ![](https://www.atlantic.net/wp-content/uploads/2020/12/ftp1.png) ## Step 3 – Configure ProFTPD to use SSL/TLS Next, you will need to configure ProFTP to use the SSL/TLS certificate created above. You can do it by editing the file /etc/proftpd/tls.conf: ``` nano /etc/proftpd/tls.conf ``` Add the following lines below : ``` TLSRSACertificateFile /etc/ssl/certs/servercertificate.pem TLSRSACertificateKeyFile /etc/ssl/private/serverkey.pem TLSEngine on TLSRequired on TLSProtocol TLSv1.2 TLSv1.3 TLSOptions NoSessionReuseRequired TLSVerifyClient off TLSLog /var/log/proftpd/tls.log ``` Save and close the file when you are finished. ![](https://www.atlantic.net/wp-content/uploads/2020/12/ftp2.png) Next, edit the /etc/proftpd/modules.conf file and enable the TLS module. ``` nano /etc/proftpd/modules.conf ``` Uncomment the following line: ``` LoadModule mod_tls.c ``` ## Step 4 – Configure ProFTP ProFTP’s default configuration file is located at /etc/proftpd/proftpd.conf. You will need to edit this file and make some changes: ``` nano /etc/proftpd/proftpd.conf ``` Change the following lines per your requirements: ``` UseIPv6 on ServerName "FTP Server" Port 21 RequireValidShell on AuthOrder mod_auth_pam.c* mod_auth_unix.c Include /etc/proftpd/tls.conf ``` Save and close the file when you are finished. The config file should look similar to this: ![](https://www.atlantic.net/wp-content/uploads/2020/12/ftp3.png) Then, restart the ProFTP service to apply the changes: ``` systemctl restart proftpd ``` A brief explanation of each option is shown below: - **UseIPV6** : Enables or disables the IPv6 support. - **ServerName** : Specifies your FTP Server name. - **Port** : Specifies the port of your FTP server. - **RequireValidShell** : Enables logging in for users, even for those who don’t have a valid shell in /etc/shells to log in. - **AuthOrder** : Enables the use of local passwords. - **Include /etc/proftpd/tls.conf** : Enables TLS/SSL support. ## Step 5 – Create a ProFTP User At this point, ProFTP is installed and configured with TLS/SSL support. Next, you will need to create a user for ProFTP. You can create a new user named user1 with the following command: ``` adduser user1 ``` You should get the following output, and you will also be prompted to enter a password and some user information. ``` Adding user `user1' ... Adding new group `user1' (1000) ... Adding new user `user1' (1000) with group `user1' ... Creating home directory `/home/user1' ... Copying files from `/etc/skel' ... Enter new UNIX password: Retype new UNIX password: passwd: password updated successfully Changing the user information for user1 Enter the new value, or press ENTER for the default Full Name []: FTP User Room Number []: Work Phone []: Home Phone []: Other []: Is the information correct? [Y/n] Y ``` Next, change the home directory of user1 to /var/www/ using the following command: ``` usermod -m -d /var/www user1 ``` Next, change the ownership of the /var/www/ directory: ``` chown -R user1:user1 /var/www ``` Next, log in with user1 by running the following command: ``` su - user1 ``` Next, create a sample file and directories with the following command: ``` touch file1.txt file2.txt mkdir dir1 dir2 ``` ## Step 6 – Access ProFTP with FTP Client Now, download and install the FileZilla FTP client in your local system. Read the installation to ensure no additional bloatware is installed, as FileZilla is supported by bundled applications. Next, open the FileZilla client and create a new site from the site manager. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/ftp5.png) Next, provide the IP address of your FTP server, select Require explicit FTP over TLS, select Normal in Logon Type, provide your FTP username and password, and click on the **Connect** button. You will be prompted with a certificate as shown below: ![](https://www.atlantic.net/wp-content/uploads/2020/12/ftp6.png) Accept the certificate and click on the **OK** button. Once the connection has been established successfully, you should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2020/12/ftp8.png) ## Conclusion In the above guide, we learned how to install ProFTP on Ubuntu. We also learned how to secure an FTP connection with TLS/SSL. If your installation is not working you can check the ProFTP log file at /var/log/proftpd/proftpd.log. Get started with ProFTP on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net today! --- # How to Setup Atlantic.Net Email > URL: https://www.atlantic.net/vps-hosting/how-to-setup-atlantic-net-email/ | Published: 2023-12-12 | Updated: 2026-03-03 | Author: Alexander Wise In this guide, you will find detailed steps for how to setup your Atlantic.Net email account using general account settings. Please note that Atlantic.Net does not provide support for third-party email applications, but we provide the following information so you can configure access with a program that you are familiar with. We recommend taking your device to a local technician if you have trouble configuring the application, or to your phone provider if you need assistance configuring your phone or tablet. If the settings do not work on your device, we recommend that you use the webmail provided by Atlantic at [webmail.atlantic.net](https://webmail.atlantic.net). ## Email Server Information The following information remains the same whether you set up the application as a POP3 or IMAP client: - Incoming server: mail.atlantic.net - Outgoing server: mail.atlantic.net - Username: full email address ## IMAP Client Setup To set up your email as an IMAP client, use these ports and settings: - Incoming port: 993 - Outgoing port: 587 or 2500 - As this is a TLS/SSL encrypted connection, the TTL/TLS settings must be set to “yes”/”auto”. If this configuration doesn’t work, you can use the default ports: - Incoming port: 143 - Outgoing port: 25 - The TLS/SSL setting should be set to “no” when configuring this. It is not recommended to check your email over these ports when using an insecure connection (e.g., an airport wi-fi or anywhere else where malicious packet sniffers may be in use). ## POP3 Client Setup To set up your email as a POP3 client, use these ports and settings: - Incoming port: 995 - Outgoing port: 587 or 2500 - As this is a TLS/SSL encrypted connection, the TTL/TLS settings must be set to “yes”/”auto”. If this configuration doesn’t work, you can use the default ports: - Incoming port: 110 - Outgoing port: 25 - When configuring this, set TLS/SSL to “no.” It is not recommended to check your email over these ports when using an insecure connection (e.g., an airport wi-fi or anywhere else where malicious packet sniffers may be in use). --- # How to Configure and Install LAMP Stack on Ubuntu 22.04 > URL: https://www.atlantic.net/vps-hosting/how-to-configure-and-install-lamp-stack-on-ubuntu-22-04/ | Published: 2023-12-14 | Updated: 2025-12-13 | Author: Alexander Wise The LAMP stack is one of the most popular and reliable web development environments used to host dynamic websites and web applications. The term LAMP stands for Linux, Apache, MySQL, and PHP, four open-source components that work together to deliver content-driven websites. Here’s what each component does: - **Linux** acts as the operating system that runs the server. - **Apache** is the web server that handles HTTP requests and serves web pages. - **MySQL** stores and manages application data. - **PHP** processes dynamic content and connects your website to the database. You often use a LAMP stack to run applications like WordPress, Drupal, Laravel, custom PHP websites, and internal business tools. It offers flexibility, strong community support, and long-term stability. In this guide, you will learn how to install and configure Linux, Apache, MySQL, and PHP on Ubuntu. This procedure is compatible with Ubuntu 18.04, Ubuntu 20.04, and Ubuntu 22.04. ## Step 1 – Updated System Packages It’s a good practice to start with an updated system. You will update all packages in the next section, but confirm your system boots and works normally. Start by refreshing the local package index. ``` apt update -y ``` This command fetches the latest package information from Ubuntu repositories. Next, upgrade all installed packages to their latest versions. ``` apt upgrade -y ``` If your server is new or hasn’t been updated in a long time, you can run a full upgrade. ``` apt full-upgrade -y ``` This handles dependency changes and kernel updates more effectively. If the upgrade installs a new kernel or core system components, reboot the server. ``` reboot ``` ## Step 2 – Install Apache Web Server Apache is the web server that handles incoming HTTP requests and serves web pages to users. It is one of the most widely used web servers and works reliably on Ubuntu. Install Apache using the APT package manager. ``` apt install apache2 -y ``` Once the installation finishes, Apache is installed on your system. Apache usually starts automatically after installation. You should still verify and enable it to start on boot. ``` systemctl start apache2 systemctl enable apache2 ``` Confirm that Apache is running without errors. ``` systemctl status apache2 ``` You should see an active (running) status. Now, open a web browser and enter your server’s IP address to verify the Apache installation. ``` http://your_server_ip ``` If Apache is working, you will see the Apache2 Ubuntu Default Page. This confirms that the web server is installed and serving content correctly. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p1-12.png) ## Step 3 – Install MySQL Database Server MySQL is the database component of the LAMP stack. It stores and manages data for your web applications, such as user accounts, posts, and settings. Most PHP applications, including WordPress and Laravel, rely on MySQL to function properly. Install the MySQL server package using APT. ``` apt install mysql-server -y ``` After installation, MySQL is installed but may not be fully secured. Now, start and enable the MySQL service. ``` systemctl start mysql systemctl enable mysql ``` Verify that MySQL is active. ``` systemctl status mysql ``` Run the built-in security script to harden your MySQL setup. ``` mysql_secure_installation ``` During the setup: - Set a root password (or confirm socket-based authentication) - Remove anonymous users - Disallow remote root login - Remove the test database - Reload privilege tables Choose **Y** for recommended security options. ## Step 4 – Install PHP and Required PHP Modules PHP is the scripting language that processes dynamic content in the LAMP stack. It works with Apache to generate web pages and connects to MySQL to fetch and store data. Without PHP, your server can only serve static HTML files. Install PHP and the Apache PHP module. ``` apt install php libapache2-mod-php -y ``` This installs PHP and allows Apache to process PHP files. Install additional PHP extensions. ``` apt install php-mysql php-cli php-curl php-zip php-gd php-mbstring php-xml php-bcmath -y ``` These extensions support database connections, file uploads, APIs, and XML handling. Verify that PHP is installed correctly. ``` php -v ``` You should see the installed PHP version. ``` PHP 8.1.2-1ubuntu2.22 (cli) (built: Jul 15 2025 12:11:22) (NTS) Copyright (c) The PHP Group Zend Engine v4.1.2, Copyright (c) Zend Technologies with Zend OPcache v8.1.2-1ubuntu2.22, Copyright (c), by Zend Technologies ``` Verify that the PHP module is enabled. ``` apache2ctl -M | grep php ``` If PHP is enabled, you will see output similar to: ``` php_module (shared) ``` ## Step 5 – Test PHP Processing At this stage, Apache and PHP are installed and configured. Now you need to confirm that Apache can correctly process PHP files. The easiest way to test this is by creating a simple PHP file and accessing it through your web browser. Create a new PHP file inside the default Apache document root. ``` nano /var/www/html/phpinfo.php ``` Add the following content: ``` ``` Now, open a web browser and access the PHP test page using the URL: ``` http://your_server_ip/phpinfo.php ``` If PHP is working, you will see the PHP information page. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p2-9.png) The phpinfo() page exposes sensitive server information. Remove it after testing. ``` rm -rf /var/www/html/phpinfo.php ``` ## Conclusion You have successfully installed and configured the LAMP stack on Ubuntu. Your system is now running Apache to serve web pages, MySQL to store application data, and PHP to process dynamic content. Each component works together to create a stable and flexible environment for hosting modern web applications. --- # Atlantic.Net Colocation Agreement > URL: https://www.atlantic.net/colocation-master-services-agreement/ | Updated: 2026-09-16 This COLOCATION MASTER SERVICES AGREEMENT, including the Schedule of Equipment and the Service Level Agreement attached hereto (collectively, these **“Terms and Conditions”**) is made a part of the document entitled, “COLOCATION SERVICE ORDER FORM” (the **“Colocation Service Order Form”**) entered into and executed by and between Atlantic.Net, Inc. (**“ATLANTIC.NET”**) and the Customer identified in the Colocation Service Order Form.  The term “**Agreement**” shall mean these Terms and Conditions, the Colocation Service Order Form, and the Acceptable Use Policy.  These Terms and Conditions are incorporated by reference into the Colocation Service Order Form as if fully set forth therein.  ATLANTIC.NET and Customer acknowledge and agree that upon execution of the Colocation Service Order Form, they shall be legally bound by the Agreement.  Capitalized terms not defined in these Terms and Conditions shall have the same meaning as in the Colocation Service Order Form. 1. **THE LEASE.**ATLANTIC.NET leased certain premises in the building where ATLANTIC.NET’s data center is located.  (“**Building**”) and which may be identified on the Colocation Service Order Form from the Building’s owner (“**Owner**”) pursuant to a lease agreement (**“Lease”**). Pursuant to the Lease, ATLANTIC.NET has the right to execute and enter into this Agreement for the Space in the Premises located within the Building.  Customer is not a party to or a beneficiary under the Lease and has no rights thereunder. 2. **GRANT OF LICENSE; TERM; PERMITTED USES; NO REAL PROPERTY INTEREST.** Customer owns the computer and related communications equipment (**“Equipment”**) more particularly described in the Schedule of Equipment attached hereto as Exhibit “A” and incorporated herein by reference. (a) Grant of License. Subject to the terms and conditions set forth in this Agreement, ATLANTIC.NET hereby grants to Customer the right and non-exclusive license (**“License”**) to install and operate the Equipment in the specific space or spaces (**“Space”**) located in the premises (**“Premises”**) in the Building, as specified by ATLANTIC.NET during the Term of this Agreement and solely to use the Space for the Permitted Uses set forth below and for no other purposes.  Notwithstanding the foregoing, ATLANTIC.NET reserves the right to relocate, change or otherwise substitute replacement space in the Premises for the Space at any time during the Term hereof, provided that the replacement space is substantially similar in size and configuration to the original Space. (b) Term. This Agreement and the License shall commence on the Effective Date set forth in the Colocation Service Order Form and shall each automatically renew for successive terms equal to the initial term unless canceled by either party in writing at least thirty days before the expiration of the current term (the **“Term”**). Provided, however, the Term shall terminate prior to the scheduled date of termination if subject to Sections 11, 12, and/or 13 below. (c) Permitted Uses. Customer has the right to use the Space solely for the purpose of (i) installation of the Equipment in the Space, (ii) maintaining the Equipment, (iii) operating the Equipment, and (iv) removing the Equipment (the **“Permitted Uses”**). Unless otherwise agreed by ATLANTIC.NET in writing, Customer shall perform the Permitted Uses at its sole cost and expense. Customer shall not use or allow or permit the use of the Space for any use or purpose other than a Permitted Use. (d) Not a Grant of an Interest in Real Property. Customer represents, warrants, covenants, acknowledges and agrees that it does not have, has not been granted and will not own or hold any real property interest in the Space, the Premises or the Building; that Customer is a licensee not a tenant or lessee of the Space; and that Customer does not have any of the rights, privileges or remedies that a tenant or lessee would have under a real property lease or occupancy agreement. 1. **Fees & Requirements to Begin Service**. On the date of execution of the Colocation Service Order Form, Customer agrees to and shall pay to ATLANTIC.NET that amount which is equal to the sum of (a) the cost to install the racks, cabinets, cages, custom space, electrical circuits, fiber optic connections, cable, panels and other items necessary for the Equipment to function in the Space (**“Expense Component”**), plus (b) a prepayment equal to the number of month’s recurring fees determined by Atlantic.Net (the **“Fee Component”**) (hereinafter together, the **“Fees Required to Begin Service”**). The Expense Component shall be applied by ATLANTIC.NET to pay the costs and expenses referenced in the Colocation Service Order Form. The Expense Component is not refundable to Customer, and shall be deemed earned by ATLANTIC.NET upon receipt. The Fee Component shall be applied by ATLANTIC.NET to prepayment of the Fee due from Customer for the first month or months of the Term. The Fee Component is not refundable to Customer, and shall be deemed earned by ATLANTIC.NET upon receipt.  On the date of execution of the Colocation Service Order Form, Customer shall deliver to ATLANTIC.NET all required certificates of insurance as set forth in Section 8 below.  Customer shall not engage in any of the Permitted Uses until all of the requirements of this Section 3 have been fully satisfied. 2. **AGREEMENT TO PROVIDE SERVICES AND PAY FEES; SERVICE LEVEL AGREEMENT; SECURITY AGREEMENT**. Pursuant to the Colocation Service Order Form, ATLANTIC.NET has agreed to provide certain services (**“Services”**) to the Customer, and the Customer has agreed to pay certain fees (**“Fees”**) to ATLANTIC.NET in consideration therefore. The Services include the License. ATLANTIC.NET shall have the right to increase the Fees: (a) twelve (12) months after performance of the Services first commences in proportion to increases in the Consumer Price Index applicable to the geographic area where the Building is located, plus two percent (2%) and/or (b) anytime in proportion to increases in electricity costs applicable to the geographic area where the Building is located. Customer shall have the right to purchase additional Services offered by ATLANTIC.NET from time to time on terms and conditions to be agreed upon in writing. ATLANTIC.NET agrees to provide the Services in accordance with and pursuant to the terms and conditions set forth in the Service Level Agreement attached hereto as Exhibit “B” and incorporated herein by reference. Customer agrees to pay the price per megabit per second (Mbps) for the contracted amount of bandwidth defined in the Internet Access Quantity field on the Colocation Service Order Form, and the rate stated in the Colocation Service Order Form for any additional Mbps over such contracted amount. All Fees and other sums which are or may hereafter be owed to ATLANTIC.NET by the Customer under this Agreement (including without limitation Default Interest, Late Charges and attorney’s fees and other costs of collection are called the “**Obligations**”.  In order to secure the payment and performance of the Obligations, the Customer hereby grants to ATLANTIC.NET a security interest, within the meaning of Article 9 of the Uniform Commercial Code (the “**UCC**”) in all Equipment, cable, wiring, connecting lines, and other installations, equipment or property of the Customer now or hereafter installed or placed in the Space or Premises.  Except with respect to ATLANTIC.NET’s security interest, the parties agree that the Uniform Commercial Code shall not apply to the Agreement. 1. **PAYMENT OF FEES; DUE DATE; LATE CHARGE; DEFAULT INTEREST**. (a)  Payment of Fees.  On or before the first (1st) day of each and every month during the Term hereof (each, a **“Due Date”**), Customer agrees to and shall pay the Fees to ATLANTIC.NET, in advance, for the Services to be rendered by ATLANTIC.NET to Customer during said upcoming month, without offset, deduction or credit of any kind and in good and drawable funds. If Customer for any reason fails to pay the Fees to ATLANTIC.NET by the Due Date of any month during the Term hereof, Customer will be assessed an administrative charge in the amount which is equal to five (5%) of the overdue Fees (**“Administrative Charge”**); in addition, ATLANTIC.NET may charge interest on all due but unpaid Fees at the lesser of 1.5% per month or the maximum non-usurious rate under applicable law (**“Default Interest”**) until paid in full. Customer agrees to and shall pay to ATLANTIC.NET for all costs of collection of the Fees, Default Interest and Late Charges plus ATLANTIC.NET’s attorneys’ fees, costs, expenses, and court costs and fees paid or incurred in connection therewith. Customer’s obligation to pay the Fees, Default Interest and Late Charges shall survive the expiration or earlier termination of the Agreement.  If Customer requests that Atlantic.Net provide services not specifically set forth herein and Atlantic.Net agrees to provide such services, Customer agrees to pay ATLANTIC.NET’s standard fee for such service at the time such service is rendered or such charge as the parties may mutually agree upon prior to the delivery of the service and such services shall be included within the definition of “**Services**”. ATLANTIC.NET may suspend or otherwise cease performing any or all Services to Customer if payment for any Service is not timely paid in full.  Such suspension shall include, without limitation, denying Customer access to the Space or Premises and changing locks and access codes.  Time is of the essence with respect to Customer’s performance and the making of payments hereunder.  A Reinstatement Fee equal to seventy-five dollars ($75.00) will be assessed for suspended Services and must be collected with the overdue Fees for the account to be reinstated.  Fees not disputed within sixty (60) days of due date are conclusively deemed accurate and all Services subject to those undisputed Fees shall be deemed fully accepted and by ATLANTIC.NET and in full compliance with this Agreement. (b)  Taxes.  Customer is responsible for all taxes under this Agreement, however designated, levied, or based on such charges excluding income taxes payable by ATLANTIC.NET, and Customer’s tax obligations include, without limitation, all state and local privilege taxes, sales and use taxes, excise taxes based on gross revenue, and ad valorem or personal property taxes (collectively, “**Tax**”).  Customer agrees that if any of the foregoing is paid by ATLANTIC.NET, Customer shall reimburse ATLANTIC.NET for the amount paid plus any related expenses incurred and interest assessed.  Unless otherwise stated as a separate line item on any bill or invoice provided by ATLANTIC.NET, all payments required by this Agreement are exclusive of any applicable Tax. 1. **RULES AND REGULATIONS**. Customer agrees to and shall abide by and honor all rules, regulations, policies, and procedures with regard to the use of the Space, the Premises and the Building from time to time published by ATLANTIC.NET (whether written or published on ATLANTIC.NET’s website) 2. **CONFIDENTIALITY**. ATLANTIC.NET and Customer, for itself, its agents, employees, and representatives, agrees that it will not divulge any confidential or proprietary information it receives from the other party, except as may be required by law. 3. **INSURANCE**. Customer agrees to and shall maintain in force and effect during the Term of this Agreement one or more policies of commercial general liability insurance, with a company licensed to do business within the state where the Building is located, insuring Customer against all hazards and risks customarily insured against by persons locating equipment such as the Equipment in space in buildings such as the Space in the Building. The policy shall be written on a per-occurrence basis with blanket contractual liability coverage, with respect to use of the Space in the Premises and operation of Customer’s business therein, with a combined single limit coverage of not less than One Million Dollars ($1,000,000) and aggregate umbrella coverage of not less than an additional One Million Dollars ($1,000,000). Customer shall maintain property insurance (inclusive of coverage for data, media, and electronic data processing perils) written on a “Special Form” basis at full replacement cost value. Customer’s policies shall contain provisions providing that such insurance shall be primary insurance insofar as Customer is concerned, with any other insurance maintained by ATLANTIC.NET being excess and noncontributing with the insurance of Customer required hereunder; and the same shall provide coverage for the contractual liability of Customer to indemnify ATLANTIC.NET. Each of Customer’s policies shall name ATLANTIC.NET and any additional persons, or entities that ATLANTIC.NET may reasonably designate in writing, as “additional insureds”.  All such policies shall provide that Customer’s insurer waives all rights of subrogation against ATLANTIC.NET. Customer shall procure and maintain workers’ compensation insurance complying with the law of the state where the Building is located, whether or not said coverage is required by law, and employer’s liability insurance with limits of no less than One Million Dollars ($1,000,000).  Each such policy shall provide that it cannot be canceled or modified unless ATLANTIC.NET is given thirty (30) calendar days advance written notice of such cancellation or modification. The insurance requirements set forth herein are independent of Customer’s indemnification and other obligations hereunder and shall not be construed or interpreted in any way to restrict, limit, or modify Customer’s indemnification and other obligations, or to limit Customer’s liability.  Customer shall obtain all insurance policies with carriers having an A.M. Best rating of A- VIII or better.  Prior to occupying the Space or engaging in any of the Permitted Uses, and at any time thereafter upon ATLANTIC.NET’s request, Customer shall submit to ATLANTIC.NET evidence that Customer has the insurance policies required hereunder in effect and shall provide to ATLANTIC.NET certificates, with copies of all applicable endorsements attached, to ATLANTIC.NET. Customer shall ensure that ATLANTIC.NET receives at least ten (10) days prior written notice before any policy is canceled or materially modified. 4. **INDEMNITY**. Customer and its respective officers, directors, shareholders, employees, agents, representatives, parent companies, affiliated companies, and subsidiary companies (each, as an **“Indemnifying Party”**) each hereby agree to and shall indemnify, defend, protect and hold the ATLANTIC.NET and its respective officers, directors, shareholders, employees, agents, representatives, parent companies, affiliated companies, and subsidiary companies (each, as an **“Indemnified Party”**) free and harmless from and against all Claims (defined below) for damages (including but not limited to attorneys’ fees, costs, and expenses), injury and death arising out of or relating directly or indirectly to the failure or alleged failure by the Indemnifying Party to comply with this Agreement, the License granted hereunder and Customer’s use of the Space.  For purposes of this Section, the term **“Claims”**means any and all claims, causes of action (whether based on tort or contract law principles, law or equity, or otherwise), charges, assessments, fines, and penalties of any kind (including consultant and expert expenses, court costs, and reasonable attorneys’ fees and costs. This indemnification extends to and includes (a) Claims for injury to any persons (including death at any time resulting from that injury), and loss of, injury or damage to, or destruction of real or personal property (including all loss of use resulting from that loss, injury, damage, or destruction of the Space or Premises). The provisions of this Section shall survive the termination, cancellation, or expiration of this Agreement for any reason. The Indemnified Party seeking indemnification under this Section shall give the Indemnifying Party prompt notice of any claim asserted or threatened against such Indemnified Party on the basis of which such Indemnified Party intends to seek indemnification, but the obligations of the Indemnifying Party shall not be conditioned upon receipt of such notice except to the extent that the Indemnifying Party is actually prejudiced by such failure to give notice). The Indemnifying Party shall promptly assume the defense of any Indemnified Party, with counsel reasonably satisfactory to such Indemnitee, and the fees and expenses of such counsel shall be at the sole cost and expense of the Indemnifying Party. Notwithstanding the foregoing, any Indemnified Party shall be entitled, at its expense, to employ counsel separate from counsel for the Indemnifying Party and from any other party in such action, proceeding, or investigation. An Indemnified Party may not agree to a settlement of a Claim without the prior written approval of the Indemnifying Party, which approval shall not be unreasonably withheld. No Indemnifying Party may agree to a settlement of a Claim against an Indemnified Party unless such settlement includes a full release of the Indemnified Party. 5. **DISCLAIMER OF WARRANTIES**.  THIS AGREEMENT PROVIDES LICENSES AND SERVICES AND IS NOT A SALE OF GOODS.  ATLANTIC.NET PROVIDES THE SPACE AND THE SERVICES ON AN “AS-IS WHERE-IS” BASIS AND WITH “ALL FAULTS” AND MAKES NO WARRANTIES OF ANY KIND OR NATURE, WHETHER EXPRESSED OR IMPLIED, WITH RESPECT TO THE SERVICES, THE SPACE, THE PREMISES, THE BUILDING, THE LICENSE, OR ANY OTHER RIGHTS, OBLIGATIONS OR PERFORMANCE UNDER THIS AGREEMENT, INCLUDING, WITHOUT LIMITATION ANY WARRANTIES OF MERCHANTABILITY, NON-INFRINGEMENT OR FITNESS FOR A PARTICULAR PURPOSE, WHICH ARE ALL HEREBY DISCLAIMED.  ATLANTIC.NET SHALL NOT BE RESPONSIBLE FOR ANY DELAYS OF ANY KIND, REGARDLESS OF CAUSE.  In the event of any breach of this Agreement by ATLANTIC.NET, Customer’s sole and exclusive remedy shall be as follows:  upon delivery of written notice to ATLANTIC.NET of the breach, ATLANTIC.NET shall, in its sole discretion, re-perform or correct any Services or other breaches, or provide to Customer a refund or credit in accordance with the terms and conditions of the Service Level Agreement attached hereto as Exhibit B.  THE FOREGOING OBLIGATIONS AND REMEDIES SET FORTH IN THE PRECEDING SENTENCE SHALL CONSTITUTE CUSTOMER’S SOLE AND EXCLUSIVE REMEDY FOR ANY BREACH OF THIS AGREEMENT, WHICH REMEDIES SHALL APPLY EVEN IF THEY FAIL OF THEIR ESSENTIAL PURPOSE. 6. **EVENT OF DEFAULT BY CUSTOMER**. The occurrence of any one or more of the following shall constitute an **“Event of Default”**by Customer under this Agreement: (a) on or after the twentieth (20th) calendar day of each month during the Term hereof, Customer for any reason fails to pay to ATLANTIC.NET any Fees, Obligations or any other amount due hereunder, or (b) on or after the 20th day after the date when due, Customer fails to pay to any other person or entity to whom Customer is required by the Agreement to make payment of any amount required by the Agreement to be paid; or (c) Customer fails to perform any obligation or covenant set forth in this Agreement and is not cured within ten (10) business days following receipt of written notice thereof. 7. **ATLANTIC.NET’S REMEDY UPON DEFAULT; TERMINATION**. (a)  Rights in the Event of Default by Customer.  In addition to all other rights and remedies granted to ATLANTIC.NET in the Agreement and available under applicable law, (including, but not limited to, the right to charge and collect Late Charges), upon the occurrence of an Event of Default by Customer, all obligations of ATLANTIC.NET to provide to Customer the Services and use of or access to the Space under this Agreement shall immediately and automatically terminate without further notice to Customer and ATLANTIC.NET shall have the right to: (i) cease providing the Services to Customer and cease providing access to or use of the Space and Premises and change locks and access codes, without notice to Customer, and (ii) remove the Equipment from the Space and Premises without notice to Customer in accordance with Section 12(c) below; and (iii) terminate this Agreement, subject to the continuing rights of ATLANTIC.NET under this Agreement to require payment of the Obligations and to exercise the remedies provided in Section 12(c) below. (b) Termination Obligations.  Customer agrees that, upon the cancellation, expiration, or termination of the License or this Agreement for any reason whatsoever, Customer shall, within ten (10) days, make payment in full on all Obligations under this Agreement, including all outstanding Fees, Default Interest, Late Charges, and other amounts, and promptly remove or have removed, at Customer’s sole cost and expense, all Equipment and all cable, wiring, connecting lines, and other installations, equipment or property installed or placed by or for Customer in the Space or Premises and restore those portions of the Space and Premises damaged by such removal to their original condition as it existed immediately prior to the installation or placement of such items. (c)  Right to Remove Equipment.  If Customer fails to promptly make full payment to ATLANTIC.NET of all Obligations and fails to remove any Equipment or other items as set forth in Section 12(b) above, or if ATLANTIC.NET has the right to remove the Equipment as set forth in Section 12(a) above, then, to the fullest extent permitted by law, ATLANTIC.NET shall have the right to take and hold possession of the Equipment, and ATLANTIC.NET shall have all of the rights of a secured party with respect to the Equipment and all other collateral for the Obligations.  ATLANTIC.NET may, at Customer’s expense: (i) remove and store such Equipment and items; (ii) delete and remove all software, information data, and other stored items from the Equipment without retaining any copies or backups; and (iii) restore those portions of the Space and Premises damaged by such removal to their original condition as it existed immediately prior to the installation or placement of such items.  All costs and expenses incurred in connection with (i), (ii), and (iii) in the preceding sentence shall be included within the definition of “**Obligations**”.  ATLANTIC.NET may, unless all outstanding Obligations are paid to ATLANTIC.NET within ten (10) days after written notice to the Customer, dispose of the Equipment and other collateral for the Obligations at public or private sale, in the manner permitted under the Uniform Commercial Code, and may exercise any other remedy available to ATLANTIC.NET at law or in equity. (d)  Customer’s Removal of Equipment.  Notwithstanding anything to the contrary contained in this Agreement, Customer shall not be permitted to remove any of Customer’s Equipment from the Space or Premises at any time when Customer is subject to an Event of Default, delinquent in meeting any of its payment obligations, or is otherwise in breach of any other material term under this Agreement.  Full payment shall be a condition of Customer receiving access to the Space and Premises and Customer’s removal of its Equipment. (e)  Payment upon Termination.  Upon the termination or cancellation of this Agreement for any reason whatsoever prior to the end of the then-current term other than termination or cancellation as a result of a default by ATLANTIC.NET under Section 13 below, all Fees and other costs, expenses, and amounts for the License, the Services and any other Obligations incurred during the full Term of the Agreement shall be immediately and automatically accelerated and due and payable in full to ATLANTIC.NET within ten (10) days of the date of such termination or cancellation 1. **EVENT OF DEFAULT BY ATLANTIC.NET**. The failure by ATLANTIC.NET to perform any obligation or covenant set forth in this Agreement, if the same is not cured within ten (10) business days following receipt of written notice thereof, shall constitute an **“Event of Default”**by ATLANTIC.NET. Upon the occurrence of such Event of Default, Customer may terminate the Agreement upon not less than three (3) business days’ written notice to ATLANTIC.NET. 2. **ATTORNEYS’ FEES**. If any legal or administrative action or proceeding is brought by either party against the other party to enforce or interpret any term or provision of this Agreement, the prevailing party in said action or proceeding shall be entitled to recover from the party not prevailing its reasonable attorneys’ fees and costs incurred in connection with the prosecution or defense of such action or proceeding. The foregoing includes, without limitation, attorneys’ fees and costs of investigation incurred in appellate and remand proceedings, or costs incurred in establishing the right to indemnification. 3. **ASSIGNMENT**. The License and obligations under this Agreement are personal to Customer, and ATLANTIC.NET has entered into this Agreement and granted the License to Customer after an evaluation of creditworthiness and experience.  Customer may not assign, sub-license or transfer this Agreement or the Space or License in whole or in part, whether by contract, merger, reorganization, or the sale of all or substantially all of the stock, equity, or control of Customer, and Customer will not allow any other person or entity to use the Space or License for any reason, without first obtaining the prior written consent of ATLANTIC.NET, which consent may be granted or withheld in ATLANTIC.NET’s sole and absolute discretion.  Any purported assignment or delegation without the required consent shall be null and void and of no legal force or effect. 4. **GOVERNING LAW**. The Agreement and all documents and instruments executed in connection therewith or herewith shall be governed by and interpreted in accordance with the substantive laws of the State of Florida without regard to principles of conflict of laws. The parties each agree that sole and exclusive jurisdiction and venue for any action or litigation arising from or relating to this Agreement shall be an appropriate court located in Orange County, Florida. 5. **NO WAIVER**. The failure of either party at any time to enforce any right or remedy available to it under the Agreement or under any other document or instrument executed in connection herewith or therewith shall not be construed to be a waiver of such right or remedy with respect to any other breach or failure by either party. 6. **LIMITATION OF LIABILITY**. (a) NOTWITHSTANDING ANY PROVISION OF THIS AGREEMENT TO THE CONTRARY AND TO THE FULLEST EXTENT PERMITTED BY LAW: (I) THE TOTAL AND AGGREGATE LIABILITY OF ATLANTIC.NET TO CUSTOMER FOR ANY REASON WHATSOEVER ARISING OUT OF OR RELATING TO THIS AGREEMENT OR THE LICENSE, THE SERVICES, PREMISES OR SPACE SHALL NOT, IN ANY EVENT, EXCEED THE TOTAL AMOUNT OF FEES ACTUALLY PAID TO ATLANTIC.NET BY CUSTOMER UNDER THIS AGREEMENT IN THE THREE (3) MONTH PERIOD IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE LIABILITY; AND (II) IN NO EVENT SHALL ATLANTIC.NET BE LIABLE TO CUSTOMER FOR ANY INDIRECT, SPECIAL, OR CONSEQUENTIAL DAMAGES, LOST PROFITS, INJURY TO BUSINESS OR REPUTATION, LOST DATA, BUSINESS OR CUSTOMERS, THE LOSS OF PROSPECTIVE PROFITS OR ANTICIPATED SALES OR ON ACCOUNT OF EXPENDITURES, INVESTMENTS, OR COMMITMENTS INCURRED IN CONNECTION WITH CUSTOMER’S BUSINESS WHICH RESULT FROM ANY OUTAGES OF THE SERVICES OR ANY OTHER FAILURE OF CONNECTIVITY OR ANY OTHER FAILURES. (b)  ATLANTIC.NET SHALL NOT, IN ANY CASE, BE LIABLE FOR ANY OF THE FOLLOWING: (I) THE CONTENT OF THE INFORMATION PASSING OVER ATLANTIC.NET’S NETWORK; (II) UNAUTHORIZED ACCESS OR DAMAGE TO, ALTERATION, THEFT, DESTRUCTION OR LOSS OF, EQUIPMENT, CUSTOMER’S RECORDS, INFORMATION, FILES OR DATA; (III) CLAIMS FOR DAMAGES CAUSED BY CUSTOMER; (IV) CLAIMS AGAINST CUSTOMER BY ANY OTHER PARTY; OR (V) ANY ACT OR OMISSION OF ANY OTHER PARTY FURNISHING SERVICES AND/OR PRODUCTS, OR THE INSTALLATION AND/OR REMOVAL OF ANY AND ALL EQUIPMENT OR SUPPLIES. (c) CUSTOMER AND ITS EMPLOYEES, AGENTS AND REPRESENTATIVES ASSUME ALL RISK, INCLUDING, WITHOUT LIMITATION, FALLS, AND ELECTRIC SHOCKS, AND RELEASES ATLANTIC.NET AND ITS AGENTS, EMPLOYEES, AND REPRESENTATIVES FROM ANY LIABILITY WHATSOEVER ARISING OUT OF ANY DAMAGE, LOSS OR INJURY TO PERSON AND/OR PROPERTY, EVEN IF CAUSED BY ATLANTIC.NET’S OWN NEGLIGENCE. (d)  ALL OF THE LIMITATIONS IN THIS SECTION 18 SHALL APPLY  EVEN IF ATLANTIC.NET HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES AND WHETHER ANY CLAIMS ARE BASED IN CONTRACT, TORT, STRICT LIABILITY, PRODUCT LIABILITY, OR OTHERWISE. 1. **NOTICES**. All notices and demands hereunder shall be in writing and shall be served by personal service by mail at the address of the receiving party set forth below (or at such different address as may be designated by such party by written notice to the other party). All Notices and other communications hereunder shall be in writing and shall be deemed to have been duly given as of the date of confirmed delivery or confirmed facsimile transmission. To be effective, Notices must be delivered to the attention of: **TO: ATLANTIC.NET, INC.** 440 West Kennedy Blvd, Suite 3 Orlando, FL, 32810 ATTN: Legal Department Telephone: (321) 206-3730 Fax: (407) 660-8094 **TO: Customer** Customer Contact Name and Address Listed in the Colocation Service Order Form. 1. **RIGHT TO ACCESS SPACE**. ATLANTIC.NET retains the right to access the Space at any time and from time to time to perform maintenance and repairs, to inspect the Equipment, and to perform the Services. 2. **FORCE MAJEURE**. The phrase **“Force Majeure”**means and refers to any of the following events: acts of war, acts of God; rebellion or sabotage or damage resulting therefrom; expropriation or confiscation of facilities by any governmental authority; compliance with any order of any governmental authority; acts of the government in its sovereign capacity which cause a delay, deferral or suspension in ATLANTIC.NET’s ability to provide the Services; subsidence; earthquakes; hurricanes; fires; floods; explosion; accidents; quarantine restrictions; freight or other embargoes; casualty loss; strikes; labor disputes; shortages of materials or transportation; electrical blackouts or brownouts; the failure of any utility provider to deliver electricity or water to the Premises; and the failure of Customer’s Equipment. Notwithstanding the above, Force Majeure shall not include (a) any event caused by the fault, negligence, failure to pay money, or financial inability of the party claiming Force Majeure, and (b) any event within the reasonable control of the party claiming Force Majeure. A party’s obligation to pay money to another party will not be delayed, affected, or changed by an event of Force Majeure. 3. **RELATIONSHIP OF THE PARTIES**. The parties agree that their relationship hereunder is in the nature of independent contractors. Neither party shall be deemed to be the agent, partner, joint venturer, or employee of the other, and neither shall have any authority to make any agreements or representations on the other’s behalf. Each party shall be solely responsible for the payment of compensation, insurance, and taxes of its own personnel, and such personnel are not entitled to the provisions of any employee benefits from the other party. Neither party shall have any authority to make any agreements or representations on the other’s behalf without the other’s written consent. Additionally, Atlantic.Net shall not be responsible for any costs and expenses arising from Customer’s performance of its duties and obligations pursuant to this Agreement. 4. **REPRESENTATIONS**. Both parties represent and warrant to the other: (1) that it is a duly organized and existing legal entity under the laws of its domicile if Customer is a corporation or partnership; (2) that it has full authority to enter this Agreement; (3) that the execution and/or performance of this Agreement does not and will not violate or interfere with any other agreement by which such warranting party is bound; and (4) that the warranting party will not enter into any agreement whose execution/performance would violate or interfere with this Agreement. 5. **INTERPRETATION**. Any rule of construction to the effect that ambiguities are to be resolved against the drafting party shall not apply to the interpretation and construction of this Agreement, and this Agreement shall be construed as having been jointly drafted by the parties.  The titles and headings for particular paragraphs, sections, and subsections of this Agreement have been inserted solely for reference purposes and shall not be used to interpret or construe the terms of this Agreement. Any purchase order or other instrument of Customer provided to ATLANTIC.NET or accompanying any payment is for Customer’s internal use only and its terms shall not alter or amend the terms of this Agreement. 6. **COUNTERPARTS**. This Agreement may be executed in one or more counterparts, each of which shall be deemed an original, but which together shall constitute one and the same document. 7. **SEVERABILITY**. Whenever possible, each provision of this Agreement shall be interpreted in such a manner as to be effective and valid under applicable law.  However, if any provision or the application of any provision to any party or circumstance shall be prohibited by or invalid under applicable law, such provision shall be reduced to such scope as is reasonable and enforceable if possible.  Otherwise, such provision shall be severed from this Agreement and ineffective to the extent of such prohibition or invalidity without it invalidating the remainder of the provisions of this Agreement or the application of the provision to the other parties or other circumstances. 8. **CONFIDENTIALITY**. Each party for itself, its agents, employees, and representatives agrees that it will not divulge any confidential or proprietary information it receives from the other party, except as may be required by law. The terms and conditions of this Contract shall be considered confidential or proprietary information under this paragraph. Neither party shall use the other party’s name in marketing materials including, but not limited to press releases, without the prior written consent of the other party. The obligations of confidentiality and indemnification stated herein shall survive the termination of any applicable License or Contract. 9. **ENTIRE AGREEMENT**. This Agreement, which includes the Colocation Service Order Form and these Terms and Conditions and the Schedule of Equipment, Exhibit “A” and the Service Level Agreement, Exhibit “B”, attached hereto, constitute the entire understanding of the parties related to the subject matter hereof. The parties have read this Agreement and agree to be bound by its terms, and further agree that it, together with all Exhibits hereto (the terms of which are incorporated herein by this reference), constitutes the complete and entire agreement of the parties and supersedes all and merges all previous communications, oral or written, and all other communications between them relating to the subject matter hereof. No representations or statements of any kind made by either party that is not expressly stated herein shall be binding on such party. The parties agree that there are no third-party beneficiaries to this Agreement, whether express or intended. 10. **NOT LEGAL ADVICE.** Atlantic.Net provides general information on a wide range of topics that includes compliance, best practices, and cybersecurity on its website and blog with the best effort to help educate users. The information is intended for general information only and is not legal advice nor the best fit for all scenarios.  Atlantic.Net’s postings will be updated from time to time, however, there will be cases where the information may be out of date.  Please consult with your CPA, attorney, auditors, and cybersecurity experts for legal and best practice advice.  ** **EXHIBIT “A”********SCHEDULE OF EQUIPMENT** A list of Equipment Customer plans to install and operate at the Premises shall be provided to ATLANTIC.NET by the Customer. **EXHIBIT “B”********SERVICE LEVEL AGREEMENT** ATLANTIC.NET agrees to and shall provide the Services to the Equipment in the Space in accordance with this Service Level Agreement. Capitalized terms not defined herein shall have the same meaning as in the Colocation Service Order Form and the Agreement: **Power** ATLANTIC.NET’s intention is to provide uninterrupted power to the Equipment in the Space; however, events occur from time to time that may interrupt the power delivered to the Equipment in the Space. In the event that Customer experiences an interruption in power delivery to the Equipment in the Space (a **“Power Interruption”**), excluding scheduled maintenance, ATLANTIC.NET shall, for each impacted power circuit in the Space, grant to Customer a percentage credit during the next succeeding month (a **“Power Interrupt Percentage Credit”**). Notwithstanding the foregoing, if a Power Interruption is caused by one or more events of Force Majeure or by the Customer exceeding 80% of a circuit breaker’s rating under continuous load, the Customer shall not be entitled to a Power Interrupt Percentage Credit. The Power Interrupt Percentage Credit shall be based on the following schedule: Per 15 Minutes of downtime: One hour of the Monthly fee allocable to the specific impacted power circuit. Power Interrupt Percentage Credits are not cumulative from month to month and apply only to the month in which the Power Interruption occurred. Customer shall not receive during any month of the Term hereof a Power Interrupt Percentage Credit, which cumulatively exceed 100% of the monthly Fee allocable to the power circuit(s) affected in the Space. Where possible, ATLANTIC.NET will provide Customer with directed remote hands-services (without charge) to power up affected Equipment on a best effort basis. **Network Uptime** (only applicable when Atlantic.Net provides Internet Access) Atlantic.Net guarantees that the network will be available 100% of the time in a given month excluding scheduled maintenance. Atlantic.Net will refund the Customer one hour of the monthly Internet Access fee per additional 15 minutes downtime (up to 100% of Customer’s monthly Internet Access fee). Network uptime includes functioning of all network infrastructure including router, switches, and cabling. Network downtime exists when a particular customer is unable to transmit and receive data and Atlantic.Net records such failure in the Atlantic.Net trouble ticket system. **Cross-Connects** ATLANTIC.NET’s cross-connects in the Premises are designed for 100% circuit availability. If ATLANTIC.NET’s cross-connects degrade outside acceptable Bellcore parameters (i.e., in excess of 1 minute) (a **“Degrade Interruption”**), excluding scheduled maintenance, ATLANTIC.NET shall, for each impacted cross-connect in the Space, grant to Customer a percentage credit during the next succeeding month (a **“Degrade Interrupt Percentage Credit”**). Notwithstanding the foregoing, if a Degrade Interruption is caused by one or more events of Force Majeure, the Customer shall not be entitled a Degrade Interrupt Percentage Credit. The Degrade Interrupt Percentage Credit shall be based on the following schedule: Per 15 Minutes of downtime: One hour of the Monthly fee allocable to the specifically impacted cross-connect. Degrade Interrupt Percentage Credits are not cumulative from month to month and apply only to the month in which the Degrade Interruption occurred. Customer shall not receive during any month of the Term hereof a Degrade Interrupt Percentage Credit which cumulatively exceeds 100% of the monthly Fee allocable to the cross-connects affected in the Space. **REFUNDS OR CREDITS** In order to qualify for a refund or credit pursuant to this Service Level Agreement, Customer must (a) contact ATLANTIC.NET’s Network Operations Center toll-free number [(866) 618-3282] or email [ colocation@atlantic.net] within one (1) business day of the occurrence of the event for which the refund or credit is being requested and open a “trouble ticket”, and (b) within ten (10) calendar days of the occurrence of the event deliver to ATLANTIC.NET (at ATLANTIC.NET’s notice address in the Agreement) written notice describing with precision the dates and time of the event, the length of the event (in minutes and hours), the type of event, which rack, cage, or cabinet in the Space was affected by the event, and what effect the event had on Customer’s ability to operate the Equipment during the event. Upon opening of the “trouble ticket” ATLANTIC.NET will commence investigating the facts which led to the event, and upon receipt of Customer’s written notice describing the event, ATLANTIC.NET and Customer shall make a joint examination of ATLANTIC.NET’s facility monitoring system records for the impacted cage, rack or cabinet in the Space. ATLANTIC.NET agrees to and shall make a determination of whether Customer is entitled to a refund or credit within thirty (30) calendar days from the occurrence of the event. Until such determination, Customer shall continue to pay on a timely basis all monthly Fees required by the Agreement without offset, credit or deduction. The amount of any refund or credit to which Customer is entitled to an impacted power circuit, Internet access, or cross-connect shall not exceed one hundred percent (100%) of the monthly Fee allocable to the specific impacted power circuit, Internet access, or cross-connect. Under no circumstance will Customer be entitled to a refund or credit if the event complained of was caused by an event of Force Majeure, scheduled maintenance, or Customer’s actions. **CUSTOMER’S RESPONSIBILITY** Customer agrees to and shall abide by and honor all rules, regulations, policies and procedures with regard to the use of the Space, the Premises, and the Building from time to time published by ATLANTIC.NET (whether written or published on ATLANTIC.NET’s website). By signing the Colocation Service Order Form the Customer agrees to be bound by these Terms and Conditions. Customer also acknowledges that it has reviewed Atlantic.Net’s Customer Policies & Procedures. Atlantic.Net, Inc. will confirm the delivery date after the order has been validated and approved. Installation charges are an estimate only. Final charges are subject to completion of installation. Atlantic.Net, Inc. cannot guarantee additional power for reconfiguration or upgrades of Customer Equipment, except as specified in this Agreement. Customer authorizes Atlantic.Net, Inc. to release Customer’s name to other Atlantic.Net potential and current customers. Customer agrees and acknowledges that it is solely responsible for ordering circuits directly from the carrier if Customer is not purchasing bandwidth from Atlantic.Net. Customer shall coordinate with the carrier the delivery and provisioning of circuits to Atlantic.Net, Inc. facilities. Atlantic.Net, Inc. may be able to assist only if circuit number(s) are provided. Customer understands that Atlantic.Net, Inc. is not responsible for commitments made by carriers. Updated: March 3, 2021 --- # Customer Intelligence and HIPAA: Critical Considerations > URL: https://www.atlantic.net/hipaa-compliant-hosting/customer-intelligence-and-hipaa-critical-considerations/ | Published: 2023-12-14 | Updated: 2026-02-28 | Author: Gilad Maayan ## What Is Customer Intelligence? Customer intelligence (CI) is an advanced system that helps businesses gather, analyze, and interpret customer data. This data can be collected from both internal and external sources, such as social media, customer feedback, purchase history, and more. CI aims to understand customer segments, predict future behavior, and devise strategies to enhance customer engagement and satisfaction. This valuable insight can be used to drive marketing campaigns, improve customer service, develop new products, and make strategic business decisions. However, collecting and using customer data comes with its challenges. Especially in the healthcare sector, where sensitive patient data is involved, organizations need to be extra careful. They must [balance their customer intelligence initiatives](https://staircase.ai/learn/customer-intelligence/) with stringent regulatory compliance, such as the Health Insurance Portability and Accountability Act (HIPAA). ## Challenges of Balancing Customer Intelligence and HIPAA Compliance HIPAA compliance is a prerequisite for any organization dealing with Protected Health Information (PHI). The law was enacted to safeguard patient health information from unauthorized access and misuse. Balancing the need for customer intelligence and adhering to HIPAA compliance can be a daunting task, considering the complexities involved. ### Restrictions on PHI Usage The first challenge lies in the restrictions imposed by HIPAA on the usage of PHI. Healthcare organizations can only use PHI for treatment, payment, and healthcare operations, unless they obtain a specific authorization from the patient. This means that using PHI for customer intelligence initiatives requires careful planning and explicit consent. ### Complexity and Re-identification Risks Another challenge is the complexity and re-identification risks associated with PHI. While HIPAA allows the use of de-identified data, re-identification risks remain. The process of de-identifying data is complex and requires thorough understanding and implementation of statistical and scientific methods to ensure that the data cannot be re-identified. ### Transparency Concerns Under HIPAA, patients have the right to know how their data is being used. Therefore, organizations need to be transparent about their data usage policies. Data obtained without clearly informing data subjects about its purpose might not be usable for customer intelligence projects. ### Vendor and Third-Party Management Lastly, managing vendors and third parties handling PHI is another hurdle. Organizations need to ensure that their partners, such as cloud computing, data analysis or machine learning solutions, are also HIPAA compliant, and any breach on their part can have serious repercussions for the organization. ## Best Practices for HIPAA-Compliant Customer Intelligence ### Identify Permissible Data Use The first step in maintaining HIPAA-compliant customer intelligence is to identify permissible data use. Not all patient information can be used freely, and healthcare organizations must be aware of what is permissible under HIPAA. HIPAA stipulates that Protected Health Information (PHI) can only be used for treatment, payment, and healthcare operations without explicit patient authorization. Any other use of PHI requires the patient’s express permission. Therefore, when using customer intelligence tools, it’s essential to ensure that the data being analyzed falls within these categories or has been authorized by the patient. Moreover, the minimum necessary rule under HIPAA requires that only the minimum necessary information be used or disclosed for a particular purpose. This rule applies to customer intelligence as well, and healthcare organizations must ensure that they are not collecting or analyzing more information than necessary. ### Implement Strong Data Governance Policies Data governance refers to the overall management of the availability, usability, integrity, and security of data used in an organization. In the context of HIPAA-compliant customer intelligence, implementing strong data governance policies is key. These policies should clearly outline how PHI is to be handled within the customer intelligence tool. This includes policies on data collection, storage, access, and disposal. For instance, only authorized personnel should have access to the data, and there should be strict controls on who can view or modify it. Additionally, data governance policies should include provisions for regular audits to ensure compliance. These audits can identify any potential weaknesses in the system and allow for corrective action to be taken promptly. ### De-identification of PHI Another best practice for HIPAA-compliant customer intelligence is the de-identification of PHI. De-identification involves removing specific identifiers from the data that could link it back to the individual. This makes it possible to use the data for analysis without infringing on the patient’s privacy. HIPAA provides two methods for de-identification: the expert determination method and the safe harbor method. The expert determination method involves a qualified expert confirming that the risk of re-identification is very low. The safe harbor method involves removing 18 specific identifiers such as names, geographical data, and dates related to the individual. However, it’s important to note that de-identified data can still be considered PHI if there is a reasonable basis to believe it can be used to identify the individual. Therefore, even when using de-identified data, it’s vital to continue adhering to the other HIPAA requirements. ### Use Strong Encryption for PHI both at Rest and in Transit One of the most critical aspects of HIPAA compliance is ensuring the security of PHI. This applies to customer intelligence as well, and healthcare organizations must use strong encryption for PHI both at rest and in transit. Encryption involves converting data into a code to prevent unauthorized access. When data is at rest (stored), it should be encrypted to prevent unauthorized access in case of a data breach. When data is in transit (being sent over a network), it should be encrypted to prevent interception during transmission. HIPAA doesn’t mandate a specific encryption standard, but it does require that the encryption used is strong enough to protect the data. Therefore, it’s crucial to select an encryption solution that is robust and meets the highest standards of data security. ### Achieving Transparency with Patients Transparency with patients is another best practice for HIPAA-compliant customer intelligence. Patients have a right to know how their data is being used, and healthcare organizations must communicate this clearly. This can be done through a Notice of Privacy Practices, which outlines how the patient’s PHI is used and disclosed by the organization. It also informs the patient of their rights regarding their PHI, such as the right to access their information and the right to request corrections. In addition to the Notice of Privacy Practices, healthcare organizations should also be transparent about their use of customer intelligence. This involves informing patients about how their data is being analyzed and the measures in place to protect their privacy. ### Ensure that all Vendors and Third Parties handling PHI sign BAAs Finally, it’s important to ensure that all vendors and third parties handling PHI sign Business Associate Agreements (BAAs). A BAA is a contract between a healthcare organization and a business associate that outlines the responsibilities of each party in relation to the safeguarding of PHI. When using third-party tools for customer intelligence, these vendors are considered business associates under HIPAA. Therefore, they must sign a BAA that stipulates they will adhere to the same HIPAA requirements as the healthcare organization. In conclusion, maintaining HIPAA compliance while leveraging customer intelligence can be a complex process. However, by adhering to these best practices, healthcare organizations can successfully navigate this landscape and reap the benefits of customer intelligence while also safeguarding patient privacy. --- # Atlantic.Net Offers $250 Credit to Try Cloud Platform, Adds Spanish Customer Support [Promotion Has Been Ended and Spanish Support Has Been Discontinued] > URL: https://www.atlantic.net/press-releases/atlantic-net-offers-250-credit-to-try-cloud-platform-adds-spanish-customer-support/ | Published: 2023-12-19 | Updated: 2026-03-27 | Author: Editorial Team *New customers get a $250 credit for 60 days and a free tier subscription for one year*[Promotion Has Been Ended and Spanish Support Has Been Discontinued] **ORLANDO, Fla.** **– Dec. 19, 2023 –**[Atlantic.Net,](https://www.atlantic.net/) a leading cloud hosting solutions provider, is offering a $250 credit to new customers who sign up for its cloud platform. The credit can be used for up to 60 days of Atlantic.Net’s full suite of Cloud services. This credit is provided in addition to an included one year of access to Atlantic.Net’s Free Tier. Atlantic.Net specializes in an array of hosting services including on-demand and turnkey cloud, dedicated hosts, dedicated servers, colocation, private virtualization, and managed hosting. The company provides scalable computing from seven secure data centers worldwide including New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando, each engineered to provide fault-tolerant, ultra-fast performance. The Atlantic.Net Cloud makes it easy to get started with no up-front capital required, postpaid billing, all-inclusive pricing, and the freedom to create and deploy one or many virtual servers in less than 30 seconds. Atlantic.Net’s Cloud Platform includes award-winning Cloud Servers, Secure Block Storage, one-click applications, DNS, dedicated private hosts, private networking, RESTful API, data backup, a full suite of managed services, and more. With one year of access to Atlantic.Net’s free tier, customers receive the following for free each month: G3.2 GB Cloud VPS hosting, 50GB of Secure Block Storage, and 50GB of free Snapshots, which allow users to save a point-in-time encrypted copy of their cloud server’s local storage. “We live in a world where cloud computing infrastructure is dominated by big tech companies. When you think of cloud, you think of them,” said Marty Puranik, CEO, and founder of Atlantic.Net. “The high cost of cloud computing, especially in certain parts of the world, makes it difficult for businesses to scale competitively. At Atlantic.Net, we want people to know that they have more options than they think. With our level of scalability and pricing, we are letting IT leaders know they have their choice of cloud platforms.” In addition to offering 24/7/365 phone and email customer support in the English language, Atlantic.Net is proud to announce it has launched Spanish-language customer support backed by a team of dedicated support engineers with almost three decades of experience. Spanish language email support is available 24/7/365, while Spanish language phone support is available 24 hours a day five days a week. For more information, please visit [Atlantic.Net](https://www.atlantic.net/). **About Atlantic.Net** Atlantic.Net is an award-winning global cloud services provider with a focus on security, compliance, and simplifying complex infrastructures. With over 29 years of experience, Atlantic.Net is dedicated to offering developers and IT leaders at small, medium, and large organizations a range of on-demand, customized, and cost-effective cloud solutions that cater to their unique business needs. Having served clients like Lenovo, Newegg, NASA, and Hilton, the company’s commitment to excellence has positioned it as a leader in the industry, recognized for its innovation and customer-centric approach. ### **Media Contact** 5WPR for Atlantic.Net [atlantic@5wpr.com](mailto:Atlantic@5wpr.com) --- # Atlantic.Net Offers $250 Credit to Try Cloud Platform, Adds Spanish Customer Support [Promotion Has Been Ended] > URL: https://www.atlantic.net/announcements/atlantic-net-offers-250-credit-to-try-cloud-platform-adds-spanish-customer-support/ | Published: 2023-12-19 | Updated: 2025-09-15 | Author: Alexander Wise *New customers get $250 credit for 60 days and a free tier subscription for one year [Promotion Has Been Ended]* We are happy to announce that Atlantic.net is offering a $250 credit to new customers who sign up for our cloud platform. The credit can be used for up to 60 days of Atlantic.Net’s full suite of Cloud services. This credit is provided in addition to an included one year of access to Atlantic.Net’s Free Tier. The promotion is available to customers worldwide from our seven secure data centers: New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando, each engineered to provide fault-tolerant and ultra-fast performance. The Atlantic.Net Cloud makes it easy to get started with no up-front capital required, postpaid billing, all-inclusive pricing, and the freedom to create and deploy one or many virtual servers in less than 30 seconds. Atlantic.Net’s Cloud Platform includes award-winning Cloud Servers, Secure Block Storage, one-click applications, DNS, dedicated private hosts, private networking, RESTful API, data backup, a full suite of managed services, and more. With one year of access to Atlantic.Net’s free tier, customers receive the following for free each month: G3.2 GB Cloud VPS hosting, 50GB of Secure Block Storage, and 50GB of free Snapshots, which allow users to save a point-in-time encrypted copy of their cloud server’s local storage. In addition to offering 24/7/365 phone and email customer support in the English language, we are proud to announce the launch of Spanish-language customer support backed by a team of dedicated support engineers with almost three decades of experience. Spanish language email support is available 24/7/365, while Spanish language phone support is available 24 hours a day five days a week. We are excited to continue to serve our customers after almost three decades and look forward to many more! --- # How Cloud-Based Technology Detects Red Flags and Suspicious Activities in Transactions > URL: https://www.atlantic.net/pci-compliant-hosting/how-cloud-based-technology-detects-red-flags-and-suspicious-activities-in-transactions/ | Published: 2023-12-21 | Updated: 2025-09-15 | Author: Alexander Wise Let’s face it, businesses now have more opportunities thanks to the development of digital technologies and the growing popularity of online transactions. But these developments also bring with them a number of difficulties, particularly when defending private financial data and**stopping questionable activity in transactions**. Whether you are a regular customer or a business owner, you must safeguard your financial information, so it is important to **recognize warning signs and fraudulent activity!**Thankfully, even though it may sound frightening, there are a few techniques you can pick up on to identify those warning signs before any harm is done quickly. Remember that knowledge is power, and you give yourself and your company a significant advantage when you study and conduct research, particularly in these delicate business areas. So, you must be wondering: What is cloud-based technology? Let’s get into it. ![](https://www.atlantic.net/wp-content/uploads/2023/12/george-prentzas-SRFG7iwktDk-unsplash.jpg) Photo by [Philipp Katzenberger](https://unsplash.com/@fantasyflip?utm_content=creditCopyText&utm_medium=referral&utm_source=unsplash) on [Unsplash](https://unsplash.com/photos/closeup-photo-of-turned-on-blue-and-white-laptop-computer-iIJrUoeRoCQ?utm_content=creditCopyText&utm_medium=referral&utm_source=unsplash) ## Cloud-based technology navigation The use of the internet to deliver computing services has changed dramatically with the advent of cloud-based technology, or cloud computing. Instead of depending on local computers or hardware, it enables users to access applications, storage, **and resources via a network or remote servers. ** This novel approach has had a profound effect on a wide range of industries, most notably banking and finance. Recently, several financial institutions have transitioned their transaction monitoring processes from traditional on-premise systems to cloud-based solutions. The primary drivers behind this shift have been the need for enhanced flexibility, quick adjustments to evolving regulatory demands, and the desire to take advantage of the **cutting-edge features provided by cloud computing.** Thanks to cloud-based solutions, financial institutions can respond to changing market conditions faster, cut costs associated with operations, and become more competitive overall in the ever-changing financial industry. ## Red flags and anomalies in transactions Recognizing any odd or abnormal behavior that might point to possible fraud or illegitimate activity is necessary to identify red flags and suspicious activities in transactions. It is critical to recognize these warning signs because they can help businesses avoid lawsuits, reputational damage, and financial losses. It is necessary to become acquainted with typical instances that fall into this category in order to obtain an understanding of how red flags in transactions are addressed by cloud-based technology: - **Transactions that are unusually large** in comparison to the usual patterns of activity for a particular account or company may give rise to suspicions about money laundering or other illegal activity. - **Suspicious login attempts** from unknown IP addresses or devices or at odd hours may indicate unauthorized access. - **Small, frequent and quick transactions** might also be signs of fraud. - **Customer complaints** may indicate possible problems, like unauthorized account access or charges that are not authorized. - **When a single person or organization uses multiple accounts** for similar transactions, this could indicate [fraud in money laundering](https://www.idnow.io/glossary/money-laundering/). - **Phishing emails**, suspicious emails, or requests for private information may be signs of impending fraud. - **Deals from high-risk countries** or regions might be flagged, especially if the company has not done any business there before. - **Activities within the organization**, such as unauthorized access or unusual transactions by employees, can also be considered red flags. However, these warning signs are easily manageable, particularly when we move on to the next section. Investigating the underlying accountability that goes along with the aforementioned inconveniences is necessary. Two critical areas of focus in this ongoing investigation are **data security and fraud prevention**. Maintaining the integrity of interactions is not impossible to achieve when it comes to cloud-based technology. These include secure data storage, multi-factor authentication, and encryption, real-time monitoring, advanced machine learning algorithms, and deriving insights from past data analysis. ## Real-time monitoring in the Cloud One of the primary methods of preventing fraud is real-time monitoring, which is a crucial advantage you can invest in. Cloud-based solutions transform the process, unlike conventional methods, where data processing and analysis may experience major time delays. Combining [the best transaction monitoring tool](https://seon.io/resources/transaction-monitoring-software-how-it-works-and-tips/) with cutting-edge technologies like artificial intelligence (AI) and machine learning (ML) makes it possible to gain immediate insight into transactions as they happen. *Real-time monitoring identifies anomalies in user behavior or deviations from typical transaction patterns quickly by utilizing complex pattern recognition algorithms. * With the help of machine learning, the system becomes more adaptive and can eventually identify changing fraudulent patterns. Automated responses can halt suspicious transactions, and predefined thresholds cause **instant alerts for possible fraud.** An additional degree of security is added by integration with authentication mechanisms. Businesses that receive immediate alerts are guaranteed prompt action, allowing for prompt confirmation or remedial actions in response to suspected fraudulent activity. Stated differently, the ability of real-time monitoring to promptly detect transaction anomalies is the most important feature. This is noteworthy because it enables businesses to react quickly to possibly deceitful activity and stop it before it causes serious problems. ## Machine learning secret in cloud-based transaction security In real-time, machine learning algorithms closely examine transaction patterns, acting as digital sentinels. They quickly identify and draw attention to any divergences from accepted standards with a hint of artificial intelligence, **serving as an alert early-warning system.** By observing your online activity, machine learning algorithms pick up on anomalous patterns. Examining your regular transactions and activities builds a digital fingerprint of what is deemed normal. They analyze vast amounts of data to find patterns and relationships by using **advanced mathematical models and statistical techniques.** *The algorithms quickly identify any deviations from this established norm.* Because the algorithms are developed to be sensitive to these variations, they function as a kind of alert buddy, sounding an alarm whenever they notice a transaction or activity that deviates from the patterns they have inferred from your typical behavior. Over time, these algorithms’ capacity to recognize abnormalities improves due to ongoing learning and adaptation. ### Analyzing historical data for suspicious patterns Cloud-based systems use complex algorithms and data processing methods to identify historical data. These algorithms are made to sort through large amounts of transactional history data and identify trends, abnormalities, and patterns. In cloud-based systems, Tableau, Power BI, and Google Analytics are examples of advanced analytics platforms useful for visual exploration when analyzing historical data. Big data frameworks like Apache Spark and [database systems like MySQL](https://www.atlantic.net/dedicated-server-hosting/what-is-mysql/) effectively manage**enormous datasets. ** Relevant data can be extracted using query languages like SQL, and storage can be centralized using data warehousing solutions like Amazon Redshift. By automating the identification of anomalies, specialized pattern recognition software improves the system’s capacity to proactively detect and handle probable fraudulent activity in historical transaction data. ![](https://www.atlantic.net/wp-content/uploads/2023/12/ed-hardie-RMIsZlv8qv4-unsplash.jpg) Photo by [Ed Hardie](https://unsplash.com/@impelling?utm_content=creditCopyText&utm_medium=referral&utm_source=unsplash) on [Unsplash](https://unsplash.com/photos/a-screenshot-of-a-phone-RMIsZlv8qv4?utm_content=creditCopyText&utm_medium=referral&utm_source=unsplash) ## Implementation of Multi-Factor Authentication Multi-factor authentication (MFA) is implemented by adding additional layers of security on top of the conventional username and password setup. Cloud platforms require users to experience additional verification steps, such as entering a one-time code sent to their mobile device or **using biometric identification such as fingerprints.** Multi-factor authentication (MFA) often incorporates several factors, such as something you own (a physical device, such as a smart card, security token, or mobile device that generates or receives a one-time code), something you know (a password or PIN), or both. [Biometric data](https://www.kaspersky.com/resource-center/definitions/biometrics) such as fingerprints, face recognition, and retinal scans are examples of what constitutes your unique identity. In addition to actions such as mouse clicks or keystroke patterns, other components—like geolocation data confirming the user’s location—provide information about where you are. *A stronger authentication procedure is achieved by combining these components and adding more factors, which lowers the possibility of unwanted access and possible security breaches.* ## Encryption and secure data storage Resilient encryption and data storage procedures are the cornerstones of data security in cloud environments. Like a secret code, encryption converts important data into an unintelligible format that can only be **interpreted with the right decryption key.** Cloud platforms use encryption to protect data during transmission and while stored in databases. Access controls, and authentication procedures are also implemented as part of secure data storage practices to prevent unwanted access. Encryption is a security measure used in cloud computing to protect sensitive data by converting it into an unreadable format. Cloud databases with access controls are used to store this encrypted data, which is safely transferred via protocols like HTTPS. Thanks to effective key management, only authorized users with the right credentials can decrypt the data**.** Regular audits and monitoring of access logs and encrypted data are necessary to detect and prevent potential cyberattacks to maintain the overall security posture. This strengthened protective layer preserves the confidentiality and integrity of sensitive data stored in the cloud, which guarantees that even in the event of unauthorized access, the encrypted data remains unintelligible. *Secure data storage combined with encryption creates a strong barrier against potential breaches and illegal intrusions.* ![](https://www.atlantic.net/wp-content/uploads/2023/12/philipp-katzenberger-iIJrUoeRoCQ-unsplash.jpg) Photo by [Philipp Katzenberger](https://unsplash.com/@fantasyflip?utm_content=creditCopyText&utm_medium=referral&utm_source=unsplash) on [Unsplash](https://unsplash.com/photos/closeup-photo-of-turned-on-blue-and-white-laptop-computer-iIJrUoeRoCQ?utm_content=creditCopyText&utm_medium=referral&utm_source=unsplash) ## Cloud-based technology means automation and scalability Using cloud-based technology is a smart move for companies of all kinds in this fast and technologically advanced era. Beyond its affordability and usefulness, this technology has arisen as a shining example of innovation, **enabling companies to take proactive measures against fraudulent activity.** In addition to improving security, it is about guiding companies and organizations toward a flexible and expanding future, ensuring no one falls behind the curve, and establishing a strong and competitive presence in the market. As a result, let us embrace the cloud rather than just adopt it since it will become essential to achieving the ever-changing business agenda. --- # How to Install Jupyter Lab on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-jupyter-lab-on-ubuntu-24-04/ | Published: 2023-12-22 | Updated: 2025-10-02 | Author: Hitesh Jethva Jupyter Lab is a powerful, open-source web-based interactive development environment for Python, R, and other programming languages. It provides a flexible and user-friendly environment for data science, machine learning, and scientific computing. In this tutorial, we’ll guide you through the step-by-step process of installing Jupyter Lab on Ubuntu 24.04. ## Step 1 – Install Python Jupyter Lab requires Python. You can install it using the following commands: ``` apt install python3 python3-pip python3-venv -y ``` Next, create and activate the Python virtual environment. ``` python3 -m venv jupyter_env source jupyter_env/bin/activate ``` ## Step 2 – Install Jupyter Lab Now, install the Jupyter Lab using the pip command. ``` pip3 install jupyterlab ``` This command installs Jupyter Lab and its dependencies. Next, run the Jupyter Lab locally using the following command. ``` jupyter lab --allow-root --ip=your-server-ip --no-browser ``` You will see the following output. ``` [I 2025-12-05 15:09:31.372 ServerApp] jupyterlab | extension was successfully loaded. [I 2025-05-12 15:09:31.373 ServerApp] Serving notebooks from local directory: /root [I 2025-05-12 15:09:31.373 ServerApp] Jupyter Server 2.11.2 is running at: [I 2025-05-12 15:09:31.373 ServerApp] http://ubuntu:8888/lab?token=aa67d76764b56c5558d876e56709be27446874dc810633ac [I 2025-05-12 15:09:31.373 ServerApp] http://127.0.0.1:8888/lab?token=aa67d76764b56c5558d876e56709be27446874dc810633ac [I 2025-05-12 15:09:31.373 ServerApp] Use Control-C to stop this server and shut down all kernels (twice to skip confirmation). [C 2025-05-12 15:09:31.378 ServerApp] To access the server, open this file in a browser: file:///root/.local/share/jupyter/runtime/jpserver-155660-open.html Or copy and paste one of these URLs: http://ubuntu:8888/lab?token=aa67d76764b56c5558d876e56709be27446874dc810633ac http://127.0.0.1:8888/lab?token=aa67d76764b56c5558d876e56709be27446874dc810633ac [I 2025-05-12 15:09:31.407 ServerApp] Skipped non-installed server(s): bash-language-server, dockerfile-language-server-nodejs, javascript-typescript-langserver, jedi-language-server, julia-language-server, pyright, python-language-server, python-lsp-server, r-languageserver, sql-language-server, texlab, typescript-language-server, unified-language-server, vscode-css-languageserver-bin, vscode-html-languageserver-bin, vscode-json-languageserver-bin, yaml-language-server ``` Press the **CTRL+C** to stop the server. ``` Shutdown this Jupyter server (y/[n])? y [C 2023-12-19 06:47:05.798 ServerApp] Shutdown confirmed [I 2023-12-19 06:47:05.800 ServerApp] Shutting down 4 extensions ``` ## Step 3 – Configure Jupyter Lab By default, Jupyter Lab doesn’t require a password to access the web interface. To secure Jupyter Lab, generate the Jupyter Lab configuration using the following command. ``` jupyter-lab --generate-config ``` Output. ``` Writing default config to: /root/.jupyter/jupyter_lab_config.py ``` Next, set the Jupyter Lab password. ``` jupyter-lab password ``` Set your password as shown below: ``` Enter password: Verify password: [JupyterPasswordApp] Wrote hashed password to /root/.jupyter/jupyter_server_config.json ``` You can verify your hashed password using the following command. ``` cat /root/.jupyter/jupyter_server_config.json ``` Output. ``` { "IdentityProvider": { "hashed_password": "argon2:$argon2id$v=19$m=10240,t=10,p=8$zf0ZE2UkNLJK39l8dfdgHA$0qIAAnKiX1EgzFBbo4yp8TgX/G5GrEsV29yjHVUDHiQ" } } ``` Make a note of this information, as you will need to add it to your config. Next, edit the Jupyter Lab configuration file. ``` nano /root/.jupyter/jupyter_lab_config.py ``` Define your server IP, hashed password, and other configurations as shown below: ``` c.ServerApp.ip = 'your-server-ip' c.ServerApp.open_browser = False c.ServerApp.password = 'argon2:$argon2id$v=19$m=10240,t=10,p=8$zf0ZE2UkNLJK39l8dfdgHA$0qIAAnKiX1EgzFBbo4yp8TgX/G5GrEsV29yjHVUDHiQ' c.ServerApp.port = 8888 ``` Make sure you format the file exactly as above. For example, the port number is not in brackets, and the False boolean must have a capital F. Save and close the file when you are done. ## Step 4 – Create a Systemctl Service File Next, create a systemd service file to manage the Jupyter Lab. ``` nano /etc/systemd/system/jupyter-lab.service ``` Add the following configuration: ``` [Service] Type=simple PIDFile=/run/jupyter.pid WorkingDirectory=/root/ ExecStart=/root/jupyter_env/bin/jupyter lab --config=/root/.jupyter/jupyter_lab_config.py --allow-root User=root Group=root Restart=always RestartSec=10 [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon. ``` systemctl daemon-reload ``` Next, start the Jupyter Lab service using the following command. ``` systemctl start jupyter-lab ``` You can now check the status of Jupyter Lab service using the following command. ``` systemctl enable --now jupyter-lab.service systemctl status jupyter-lab ``` Output. ``` ● jupyter-lab.service Loaded: loaded (/etc/systemd/system/jupyter-lab.service; disabled; preset: enabled) Active: active (running) since Mon 2025-05-12 04:50:20 UTC; 5s ago Main PID: 23862 (jupyter-lab) Tasks: 1 (limit: 4609) Memory: 64.9M (peak: 65.0M) CPU: 1.179s CGroup: /system.slice/jupyter-lab.service └─23862 /root/jupyter_env/bin/python3 /root/jupyter_env/bin/jupyter-lab --config=/root/.jupyter/jupyter_lab_config.py --allow-root ``` Jupyter Lab is now started and listening on port 8888. You can verify it with the following command. ``` ss -antpl | grep jupyter ``` Output. ``` LISTEN 0 128 104.219.55.40:8888 0.0.0.0:* users:(("jupyter-lab",pid=156299,fd=6)) ``` ## Step 5 – Access Jupyter Lab Now, open your web browser and access the Jupyter Lab web interface using the URL **http://your-server-ip:8888.** You will see the Jupyter Lab on the following screen. ![Jupyterlab login](https://www.atlantic.net/wp-content/uploads/2023/12/p1-1.png) Provide the password you set during the installation and click on Log in. You will see Jupyter Lab dashboard on the following screen: ![Jupyterlab dashboard](https://www.atlantic.net/wp-content/uploads/2023/12/p2-1.png) ## Conclusion Congratulations! You have successfully installed and configured Jupyter Lab on Ubuntu 24.04. You can now leverage the power of this interactive development environment for data exploration, analysis, and visualization. Explore the various features of Jupyter Lab, such as support for different programming languages, interactive widgets, and integration with version control systems. Try to deploy Jupyter Lab on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Jira on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-jira-on-ubuntu-24-04/ | Published: 2023-12-26 | Updated: 2025-05-23 | Author: Hitesh Jethva Jira is a widely used project management and issue-tracking tool developed by Atlassian. It is designed to help teams plan, track, manage, and report on their work. Jira is highly versatile and can be customized to suit various project management methodologies and workflows. One of its key strengths is its flexibility, making it suitable for different types of projects across various industries. In this tutorial, we’ll walk through the step-by-step process of installing Jira on Ubuntu 24.04. **Note: Its recommended to have an Ubuntu Server is at least 4GB of RAM available** ## Step 1 – Install MySQL Server Jira requires a database to store its data. Follow these steps to install and create a database and a dedicated user for Jira in MySQL: First, install the MySQL server using the following command. ``` apt-get install mysql-server unzip fontconfig -y ``` Once MySQL is installed, connect to MySQL using the following command. ``` mysql ``` Next, create a database and user for Jira: ``` CREATE DATABASE jiradb CHARACTER SET utf8mb4 COLLATE utf8mb4_bin; CREATE USER 'jirauser'@'localhost' IDENTIFIED BY 'password'; GRANT ALL ON jiradb.* TO 'jirauser'@'localhost' WITH GRANT OPTION; ``` Next, flush the privileges and exit from the MySQL shell. ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 2 – Download and Install Jira Visit the official Jira Software download page and copy the link to the Linux installer. On your Ubuntu server, use wget to download the Jira installer: ``` wget https://www.atlassian.com/software/jira/downloads/binary/atlassian-jira-software-10.3.6-x64.bin ``` Make the installer executable: ``` chmod a+x atlassian-jira-software-10.3.6-x64.bin ``` Run the installer to start the installation. ``` ./atlassian-jira-software-9.12.0-x64.bin ``` Follow the on-screen instructions. When prompted, specify the installation directory (default is /opt/atlassian/jira), and choose the appropriate option for launching Jira automatically. ``` This will install Jira Software 9.12.0 on your computer. OK [o, Enter], Cancel [c] Click Next to continue, or Cancel to exit Setup. Choose the appropriate installation or upgrade option. Please choose one of the following: Express Install (use default settings) [1], Custom Install (recommended for advanced users) [2, Enter], Upgrade an existing Jira installation [3] 1 Details on where Jira Software will be installed and the settings that will be used. Installation Directory: /opt/atlassian/jira Home Directory: /var/atlassian/application-data/jira HTTP Port: 8080 RMI Port: 8005 Install as service: Yes Install [i, Enter], Exit [e] Extracting files ... /opt/atlassian/jira/bin/tcnative-1.dll The file already exists. Would you like Setup to overwrite it? Yes [y], Yes to All [ya], No [n], No to All [na] y Please wait a few moments while Jira Software is configured. Installation of Jira Software 9.12.0 is complete Start Jira Software 9.12.0 now? Yes [y, Enter], No [n] Please wait a few moments while Jira Software starts up. Launching Jira Software ... Installation of Jira Software 9.12.0 is complete Your installation of Jira Software 9.12.0 is now ready and can be accessed via your browser. Jira Software 9.12.0 can be accessed at http://localhost:8080 Finishing installation ... ``` After the installation, verify that Jira is installed and running: ``` ss -antpl | grep java ``` Output: ``` LISTEN 0 1 [::ffff:127.0.0.1]:8005 *:* users:(("java",pid=3099,fd=461)) LISTEN 0 100 *:8080 *:* users:(("java",pid=3099,fd=218)) ``` ## Step 3 – Configure Jira Next, you will need to download the MySQL JDBC driver and copy it to the Jira installation directory. First, download the JDBC driver using the following command. ``` wget https://dev.mysql.com/get/Downloads/Connector-J/mysql-connector-java-8.0.18.zip ``` Once the download is completed, unzip the downloaded file with the following command. ``` unzip mysql-connector-java-8.0.18.zip ``` Next, copy the MySQL connector file to Jira: ``` cp mysql-connector-java-8.0.18/mysql-connector-java-8.0.18.jar /opt/atlassian/jira/lib ``` Next, stop and start Jira to reload the changes. ``` /etc/init.d/jira stop /etc/init.d/jira start ``` ## Step 4 – Access Jira Web UI Jira is now installed and configured. You can now access the Jira web UI using the URL **http://your-server-ip:8080.** You will see the database configuration page: ![](https://www.atlantic.net/wp-content/uploads/2023/12/p2-2.png) Define your database configuration and click on **Next**. You will see the application property configuration page: ![](https://www.atlantic.net/wp-content/uploads/2023/12/p3.png) Define your application title, mode, and URL, and click on **Next.** You will see the License page: ![](https://www.atlantic.net/wp-content/uploads/2023/12/p4.png) Provide your Jira license and click on **Next.** You will see the “Set up your administrator account” page. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p7.png) Provide all necessary details and click on **Next.** You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2023/12/p8.png) Click on **Finish.** Note: Depending on your Server Specs, It can take some time for Jira to finish configuring itself. You will see the Jira welcome page. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p9.png) Select your language and click on **Continue.** You will see the “Choose an avatar” page: ![](https://www.atlantic.net/wp-content/uploads/2023/12/p10.png) Select your avatar and click on **Next.** You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p11.png) Click on **Create sample project**. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p12.png) Select Scrum software development and click on **Next.** You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p13.png) Define your project and click on **Submit.** You will see your Jira dashboard on the following page. ![](https://www.atlantic.net/wp-content/uploads/2023/12/jira.png)   ## Conclusion Congratulations! You have successfully installed Jira on Ubuntu 24.04. You can now leverage the power of Jira for efficient project management and issue tracking. Explore the various features and plugins available in Jira to customize it according to your team’s needs. You can now deploy Jira to manage the project on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Snipe-IT on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-snipe-it-on-ubuntu-24-04/ | Published: 2023-12-27 | Updated: 2025-05-12 | Author: Hitesh Jethva Snipe-IT is an open-source web-based application designed for asset management. It is specifically focused on IT assets, making it a popular choice for managing and tracking hardware and software within an organization. The primary goal of Snipe-IT is to provide a centralized and efficient way for businesses to keep track of their assets, including computers, servers, software licenses, and other equipment. In this tutorial, we will walk through the step-by-step process of installing Snipe-IT on a server running Ubuntu 24.04. ## Step 1 – Install LEMP Stack Snipe-IT requires a LEMP (Linux, NGINX, MySQL, PHP) stack. You can install it using the following commands: ``` apt update -y ``` ``` apt install nginx mariadb-server php php-bcmath php-common php-ctype php-curl php-fileinfo php-fpm php-gd php-iconv php-intl php-mbstring php-mysql php-soap php-xml php-xsl php-zip git -y ``` Next, install PHP Composer using the following command. ``` apt install composer -y ``` After the successful installation, you can proceed to the next step. ## Step 2 – Create a Database You will also need to create a database and user for Snipe-IT. First, connect to the MySQL shell. ``` mysql ``` Once connected, create a database and user with the following command. ``` mysql> CREATE DATABASE snipeit; mysql> GRANT ALL ON snipeit.* TO snipeit@localhost identified by 'password'; ``` Next, flush the privileges and exit from the MySQL shell. ``` mysql> FLUSH PRIVILEGES; mysql> \q ``` ## Step 3 – Install Snipe-IT First, navigate to the NGINX web root directory and download the latest version of Snipe-IT using the following command. ``` cd /var/www/html git clone https://github.com/snipe/snipe-it ``` Next, change the directory to Snipe-IT and copy the sample environment file. ``` cd snipe-it cp .env.example .env ``` Next, edit the environment file. ``` nano .env ``` Define your app URL, database, and other information. ``` APP_URL=http://snipeit.example.com APP_TIMEZONE='UTC' DB_DATABASE=snipeit DB_USERNAME=snipeit DB_PASSWORD=password ``` Save and close the file, then set proper permissions and ownership. ``` chown -R www-data: /var/www/html/snipe-it chmod -R 755 /var/www/html/snipe-it ``` Next, update and install plugins and other required dependencies. ``` composer update --no-plugins --no-scripts composer install --no-dev --prefer-source --no-plugins --no-scripts ``` Next, generate the artisan key. ``` php artisan key:generate ``` Output. ``` ************************************** * Application In Production! * ************************************** Do you really wish to run this command? (yes/no) [no]: > yes Application key set successfully. ``` ## Step 4 – Create an Nginx Virtual Host Now, create a new Nginx virtual host for Snipe-IT. ``` nano /etc/nginx/conf.d/snipeit.conf ``` Add the following configuration. ``` server { listen 80; server_name snipeit.example.com; root /var/www/html/snipe-it/public; index index.php; location / { try_files $uri $uri/ /index.php?$query_string; } location ~ \.php$ { include fastcgi.conf; include snippets/fastcgi-php.conf; fastcgi_pass unix:/run/php/php8.3-fpm.sock; fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } } ``` Save the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http {: ``` server_names_hash_bucket_size 64; ``` Save the file, then restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 5 – Access Snipe-IT Web Interface Now, open your web browser and access the Snipe-IT web interface using the URL **http://snipeit.example.com.** You will see the pre-flight check page. ![](https://www.atlantic.net/wp-content/uploads/2023/12/s1.png)   Ensure all required dependencies are installed, then click the **Next: Create Database** Table. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p2-3.png) Click on the **Next: Create User.** You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p3-1.png) Define your site name, email, user, and password, then click **Next: Save User.** You will see the Snipe-IT dashboard. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p4-1.png) ## Conclusion Congratulations! You have successfully installed Snipe-IT on Ubuntu 24.04. You can now start using Snipe-IT to manage your organization’s assets efficiently. Remember to regularly update Snipe-IT and keep your system secure by following best practices for server administration. Explore the Snipe-IT documentation for additional features and customization options based on your organization’s needs. You can now deploy Snipe-IT on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Configure PHP OPcache on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-configure-php-opcache-on-ubuntu-24-04/ | Published: 2023-12-28 | Updated: 2025-05-25 | Author: Hitesh Jethva PHP OPcache, short for Opcode Cache, is a powerful performance optimization tool for PHP applications. It stores precompiled script bytecode in shared memory, reducing the need for PHP to load and parse scripts on each request. This significantly improves the execution speed of PHP applications by eliminating redundant compilation processes. In this tutorial, we will guide you through installing and configuring PHP OPcache on Ubuntu 24.04. ## Step 1 – Install PHP OPcache for Apache PHP OPcache is included in the PHP core starting from PHP 5.5. You can install it with Apache and other packages using the following command. ``` apt update -y apt-get install apache2 libapache2-mod-php php php-cli php-opcache php-mysql php-zip php-gd php-mbstring php-curl php-xml -y ``` Once the installation is completed, you can verify the PHP version using the following command. ``` php -version ``` Output. ``` PHP 8.3.6 (cli) (built: Mar 19 2025 10:08:38) (NTS) Copyright (c) The PHP Group Zend Engine v4.3.6, Copyright (c) Zend Technologies with Zend OPcache v8.3.6, Copyright (c), by Zend Technologies ``` ## Step 2 – Configure PHP OPcache To optimize PHP OPcache for your environment, you’ll need to modify the configuration settings. The configuration file for OPcache is usually located at /etc/php/{PHP_VERSION}/apache2/php.ini. Replace {PHP_VERSION} with your installed PHP version (e.g., 8.1). ``` nano /etc/php/8.3/apache2/php.ini ``` Adjust the following settings based on your application’s requirements: ``` opcache.enable=1 opcache.memory_consumption=128 opcache.max_accelerated_files=10000 opcache.revalidate_freq=200 ``` Next, restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` You can verify that OPcache is enabled and check its status by creating a PHP script with the following content: ``` php -i | grep opcache ``` Output. ``` opcache.max_file_size => 0 => 0 opcache.max_wasted_percentage => 5 => 5 opcache.memory_consumption => 128 => 128 opcache.opt_debug_level => 0 => 0 opcache.optimization_level => 0x7FFEBFFF => 0x7FFEBFFF opcache.preferred_memory_model => no value => no value opcache.preload => no value => no value opcache.preload_user => no value => no value opcache.protect_memory => Off => Off opcache.record_warnings => Off => Off opcache.restrict_api => no value => no value opcache.revalidate_freq => 2 => 2 opcache.revalidate_path => Off => Off opcache.save_comments => On => On opcache.use_cwd => On => On opcache.validate_permission => Off => Off opcache.validate_root => Off => Off opcache.validate_timestamps => On => On ``` ## Step 3 – Install PHP OPcache for NGINX You can install the PHP OPcache with NGINX by running the following command. ``` apt-get install nginx php-opcache php-fpm -y ``` For NGINX, the configuration file for PHP OPcache is usually located at /etc/php/{PHP_VERSION}/fpm/php.ini. You can edit it with the following command. ``` nano /etc/php/8.3/fpm/php.ini ``` Adjust the following settings based on your application’s requirements: ``` opcache.enable=1 opcache.memory_consumption=128 opcache.max_accelerated_files=3000 opcache.revalidate_freq=200 ``` Save and close the file, then restart NGINX and PHP-FPM services to apply the changes. ``` systemctl restart nginx systemctl restart php8.3-fpm ``` ## Conclusion Congratulations! You have successfully installed and configured PHP OPcache on your Ubuntu 24.04 server. OPcache plays a crucial role in enhancing the performance of PHP applications by reducing the overhead of script compilation. Remember to fine-tune the configuration settings based on your application’s requirements and monitor the server’s performance for further optimization opportunities. You can now try to deploy PHP OPcache on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install CakePHP on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-cakephp-on-ubuntu-22-04/ | Published: 2023-12-29 | Updated: 2024-01-22 | Author: Hitesh Jethva CakePHP is an open-source web application framework for PHP designed to make the development of web applications simpler, faster, and more maintainable. It follows the model-view-controller (MVC) architectural pattern, which separates an application into three interconnected components: Model (data and database logic), View (user interface and presentation), and Controller (application logic and flow control). In this tutorial, we will guide you through installing CakePHP on a server running Ubuntu 22.04. ## Step 1 – Install LAMP Server First, you will need to install Apache, MariaDB, PHP, and other required dependencies on your server. You can install all of them using the following command. ``` apt update -y apt install apache2 mariadb-server libapache2-mod-php php-mysql php-mbstring php-intl php-xml -y ``` Once all the packages are installed, run the following command to install PHP Composer. ``` wget -O composer-setup.php https://getcomposer.org/installer ``` ``` php composer-setup.php --install-dir=/usr/local/bin --filename=composer ``` You can verify the PHP Composer version with the following command. ``` composer -V ``` Output. ``` Composer version 2.6.5 2023-10-06 10:11:52 ``` ## Step 2 – Create a MySQL Database Before installing CakePHP, you need to create a MySQL dawget -O composer-setup.php https://getcomposer.org/installertabase where your application data will be stored. Log in to MySQL as the root user: ``` mysql ``` Enter the MySQL root password when prompted. Once logged in, create a new database and a user with the necessary privileges: ``` mysql> CREATE DATABASE cakephp; mysql> GRANT ALL on cakephp.* to cakephp@localhost identified by 'password'; ``` Next, flush the privileges and exit from MariaDB using the following command. ``` mysql> FLUSH PRIVILEGES; mysql> \q ``` ## Step 3 – Download and Install CakePHP Now, let’s download and install CakePHP using Composer. Navigate to your web server’s document root directory (e.g., /var/www/html/): Create a new CakePHP project using Composer: ``` cd /var/www/html composer create-project --prefer-dist cakephp/app project ``` Output. ``` PHP CodeSniffer Config installed_paths set to ../../cakephp/cakephp-codesniffer,../../slevomat/coding-standard No security vulnerability advisories found. Do you want to remove the existing VCS (.git, .svn..) history? [Y,n]? y > App\Console\Installer::postInstall Created `config/app_local.php` file Created `/var/www/html/project/logs` directory Created `/var/www/html/project/tmp/cache/views` directory Set Folder Permissions ? (Default to Y) [Y,n]? y Permissions set on /var/www/html/project/tmp/cache Permissions set on /var/www/html/project/tmp/cache/models Permissions set on /var/www/html/project/tmp/cache/persistent Permissions set on /var/www/html/project/tmp/cache/views Permissions set on /var/www/html/project/tmp/sessions Permissions set on /var/www/html/project/tmp/tests Permissions set on /var/www/html/project/tmp Permissions set on /var/www/html/project/logs Updated Security.salt value in config/app_local.php ``` Edit the default configuration file and modify it with your database connection details. ``` nano /var/www/html/project/config/app_local.php ``` Change the following settings: ``` 'Datasources' => [ 'default' => [ 'host' => 'localhost', /* * CakePHP will use the default DB port based on the driver selected * MySQL on MAMP uses port 8889, MAMP users will want to uncomment * the following line and set the port accordingly */ //'port' => 'non_standard_port_number', 'username' => 'cakephp', 'password' => 'password', 'database' => 'cakephp', ``` Save the changes and exit the text editor. Run the following commands to set the proper permissions: ``` chown -R www-data. /var/www/html/project ``` ## Step 4 – Create an Apache Virtual Host Next, you will need to create an Apache virtual host configuration file for CakePHP. ``` nano /etc/apache2/sites-available/cakephp.conf ``` Add the following configuration: ``` ServerAdmin admin@example.com ServerName cakephp.example.com DocumentRoot /var/www/html/project/ AllowOverride All Require all granted ErrorLog ${APACHE_LOG_DIR}/example.com_error.log CustomLog ${APACHE_LOG_DIR}/example.com_access.log combined ``` Save and close the file, then enable the Apache virtual host and rewrite module. ``` a2ensite cakephp a2enmod rewrite ``` Finally, restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` ## Step 5 – Access CakePHP Now, open your web browser and access CakePHP using the URL **http://cakephp.example.com.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p1-5.png) ## Conclusion Congratulations! You have successfully installed and configured CakePHP on Ubuntu 22.04. You can now begin building your web applications using CakePHP’s powerful features and conventions. Explore the CakePHP documentation to learn more about its capabilities and best practices for web development. Try to deploy CakePHP on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # What Is the HIPAA Enforcement Rule? > URL: https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-enforcement-rule/ | Published: 2024-01-02 | Updated: 2025-09-11 | Author: Richard Bailey The HIPAA Enforcement Rule is a pivotal component of U.S. Healthcare regulation and a rule that empowers the *Health and Human Services* (*HHS*) to enforce HIPAA compliance of the Health Insurance Portability and Accountability Act (HIPAA). The HIPAA Enforcement rules were created to ensure that entities entrusted with sensitive health information adhere to stringent physical, administrative, and technical safeguards. The HIPAA Enforcement Rule delineates the scope, responsibilities, and repercussions for non-compliance with the demands of safeguarding the confidentiality and integrity of patients’ electronic health records and data. Understanding the intricacies of the rules is crucial when understanding the landscape of healthcare information management and the consequential measures implemented to uphold patient rights. Atlantic.Net is an expert in HIPAA-compliant hosting; join us as this article explains everything you need to know about the HIPAA enforcement rule. ## Who is subject to HIPAA rules? The Enforcement Rule has authority over all Covered Entities, such as healthcare providers, health plans, and clearinghouses, along with any [Business Associates](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) responsible for handling or processing Protected Health Information (PHI). ## How does the HIPAA Enforcement Rule work? Compliance with the HIPAA Enforcement Rule is mandatory, and the potential consequences of non-compliance include civil money penalties and legal action for each HIPAA violation. The Office for Civil Rights (OCR) administers compliance reviews, audits, and investigations and is responsible for imposing civil penalties for HIPAA violations. Recognizing the importance of these privacy and security rules in protecting sensitive health information is a legal obligation and a fundamental step in ensuring the security of individually identifiable health information within the healthcare industry. Efforts toward voluntary compliance and corrective actions are crucial in meeting HIPAA privacy and security rules, preventing breaches, and maintaining HIPAA Compliance. ## How the Health and Human Services enforces HIPAA Privacy and HIPAA Security Rules. Enforcing HIPAA Privacy and Security Rules is the responsibility of the HHS Office for Civil Rights (OCR). When potential violations surface, the OCR investigates alleged breaches to ascertain whether covered entities or business associates have broken the established HIPAA rules and regulations. The enforcement framework encourages compliance while imposing heavy penalties for persistent non-compliance or violation. Should the OCR uncover violations, it may undertake various actions. For example, the OCR might impose civil monetary penalties in cases of willful neglect or repeated offenses. These HIPAA violation penalties range in severity based on the nature and extent of the violation. Typically, the OCR will mandate a corrective action plan to redress the identified compliance shortcomings. The HHS Office for Civil Rights seeks to educate covered entities and business associates about HIPAA rules, privacy practices, the Privacy Rule, and security requirements, offering technical assistance and guidance to ensure a better understanding of regulatory affairs. The goal is to foster compliance practices within the healthcare industry to reduce the need for a resolution agreement. In certain severe cases where violations occur due to deliberate or willful neglect, criminal penalties might be invoked against the covered entity or the business associate. The OCR may collaborate with HHS administrative law judges and law enforcement agencies to address any criminal violations, ensuring that those responsible face appropriate legal consequences. ## What does the HIPAA Enforcement Rule include? First and foremost, it defines the obligations of Covered Entities and Business associates to ensure compliance with HIPAA’s privacy, security, and breach notification rules. The OCR follows a sequence of steps: initiating inquiries based on complaints or disclosures, conducting preliminary reviews, and, if necessary, launching formal investigations involving interviews and record examinations. Should the OCR find violations, it can impose civil money penalties (CMPs) on the Covered Entity and Business Associate for failing to adhere to HIPAA regulations. The penalties range from $10,000 to $50,000 per violation and are a consequence of severe and willful violations under the HIPAA Enforcement Rule. As part of its enforcement action, the OCR considers various factors, such as the history of compliance by the Covered Entity and the nature of the violation, providing the Covered Entity the opportunity for corrective action before imposing penalties. In cases of disagreement, an administrative hearing is called for entities to challenge the OCR’s decisions. ## How many financial penalties have been imposed for violations of HIPAA? The U.S. Department of Health and Human Services Office for Civil Rights (OCR) has resolved 140 cases related to HIPAA violations by either reaching settlements or applying civil monetary penalties (CMPs). [The total amount involved in these cases stands at $137,018,772.00](https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/data/enforcement-highlights/index.html). These resolved cases cover a broad spectrum of violations and corrective actions, such as: - **Unauthorized disclosure of protected health information (PHI):** This violation tops the list and involves instances where PHI was shared with unauthorized individuals, groups, or the general public without proper authorization. - **Neglecting to establish suitable protective measures:** This violation encompasses failing to set up adequate policies and procedures to protect PHI from unauthorized access, use, disclosure, tampering, or destruction. - **Failing to grant individuals access to their PHI:** This breach refers to instances where individuals were not provided access to their medical records or were denied timely access as required by HIPAA regulations. ## Common HIPAA Violations that trigger HIPAA Enforcement Rule There are several common violations related to health care providers, to HIPAA’s Privacy and Security Rules. Covered Entities, including health care providers, often unbeknownst to themselves, fall into these violations, leading to criminal provision. Violations of the Security Rule, which mandates safeguarding ePHI are prevalent. Common violations of the Security Rule include disregarding the HIPAA Privacy Rule, which governs the use and disclosure of individuals’ health information. Healthcare providers occasionally mishandle or disclose this sensitive data without authorization, violating patients’ privacy rights. The OCR reviews complaints filed, describing alleged violations. They investigate to determine if there’s reasonable cause for a violation. Penalties, including criminal provisions and fines, can be imposed on entities found guilty. Criminal penalties might arise in cases where violations are intentional, especially for personal gain or under false pretenses. Entities failing to comply with the rules might be required to take improvement initiatives. The HIPAA Omnibus Rule and Interim Final Rule further strengthen provisions relating to patient privacy and security. To avoid penalties and maintain compliance, covered entities must prioritize adhering to the stringent HIPAA regulations and guidelines set by the OCR. ## Atlantic.Net HIPAA Complaint Hosting Services The most cost-effective and successful way to become HIPAA compliant is to outsource to a HIPAA Compliant Hosting provider. Immediately upon onboarding, you will benefit from a service that has matured into a high-security, high-performing, HIPAA-compliant solution that meets and exceeds the mandatory administrative, physical, and technical safeguards of HIPAA. Upholding the requirements of HIPAA is not an easy task to undertake, and it’s increasingly difficult to maintain compliance if you choose to go it alone. Atlantic.Net is committed to upholding the strict rules outlined in the HIPAA Business Associate Agreement (BAA). The agreement binds Atlantic.Net and its clients To the HIPAA Privacy and Security Rule when dealing with electronic Protected Health Information (ePHI). All Atlantic.Net data centers are designed with security at the forefront. Strong physical and technical measures like firewalls, IPS systems to stop intruders, and access controls to stop unauthorized entry are in place. Our systems are tested by external 3rd parties to ensure we keep our platform protected against all possibilities. Atlantic.Net uses encrypted VPNs to make sure data is safe when moving around, preventing others from listening in or taking it, and each customer’s data is protected with separate firewalls for added security. Reach out to our HIPAA Compliance specialists to open discussions about what Atlantic.Net can do for your health business. Our hosting service and wide selection of [HIPAA-compliant managed services](https://www.atlantic.net/hipaa-compliant-hosting/) are available for you to consume immediately. --- # How to Install CodeIgniter on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-codeigniter-on-ubuntu-24-04/ | Published: 2024-01-03 | Updated: 2025-05-19 | Author: Hitesh Jethva CodeIgniter 4 is a PHP web application framework that facilitates the development of dynamic, robust, and scalable web applications. It is the fourth major version of the CodeIgniter framework, which has been popular in the PHP community for its simplicity, lightweight nature, and performance. In this tutorial, we will guide you through the step-by-step process of installing CodeIgniter 4 on a server running Ubuntu 24.04. ## Step 1 – Install Apache and PHP First, you will need to install the Apache server and PHP on your system. You can install them by running the following command. ``` apt update -y apt install apache2 php php-cli php-common php-imap php-redis php-snmp php-xml php-zip php-mbstring php-curl libapache2-mod-php php-intl -y ``` After successful installation, start and enable the Apache service using the following command. ``` systemctl start apache2 systemctl enable apache2 ``` Next, verify the PHP version using the following command. ``` php -v ``` Output. ``` PHP 8.3.6 (cli) (built: Mar 19 2025 10:08:38) (NTS) Copyright (c) The PHP Group Zend Engine v4.3.6, Copyright (c) Zend Technologies with Zend OPcache v8.3.6, Copyright (c), by Zend Technologies ``` Next, install the PHP Composer with the following command. ``` curl -sS https://getcomposer.org/installer | php -- --install-dir=/usr/bin --filename=composer ``` You can verify the Composer installation using the below command. ``` composer --version ``` Output. ``` Composer version 2.8.9 2025-05-13 14:01:37 ``` ## Step 2 – Install CodeIgniter 4 First, navigate inside the Apache web root directory. ``` cd /var/www/html ``` Next, create a new CodeIgniter 4 project with the following command. ``` composer create-project codeigniter4/appstarter app ``` Next, set proper ownership to the project directory. ``` chown -R www-data:www-data /var/www/html/app ``` ## Step 3 – Configure Apache for CodeIgniter 4 Next, create a new Apache virtual host configuration file: ``` nano /etc/apache2/sites-available/codeigniter.conf ``` Add the following configuration: ``` ServerName web.example.com DocumentRoot /var/www/html/app/public AllowOverride All ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined ``` Save and close the file, then activate the Apache virtual host: ``` a2ensite codeigniter.conf ``` Next, restart the Apache service to apply the changes. ``` systemctl reload apache2 ``` ## Step 4 – Access CodeIgniter Web UI Now, open your web browser and access the CodeIgniter UI using the URL **http://web.example.com.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/01/p1-2.png)   ## Conclusion Congratulations! You have successfully installed and configured CodeIgniter 4 on Ubuntu 24.04. You can now begin building your web applications using CodeIgniter’s powerful features and elegant syntax. Explore the CodeIgniter documentation to learn more about its capabilities and best practices for web development. You can now install CodeIgniter 4 and start developing scalable web applications on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install JasperReports on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-jasperreports-on-ubuntu-22-04/ | Published: 2024-01-04 | Updated: 2024-01-22 | Author: Hitesh Jethva JasperReports is an open-source reporting library and business intelligence (BI) tool written in Java. It is widely used for creating dynamic, pixel-perfect reports that can be embedded into Java applications. JasperReports is part of the larger JasperSoft Business Intelligence Suite, which includes other tools for data analysis, visualization, and reporting. If you’re working on a project requiring robust reporting capabilities, installing JasperReports on your Ubuntu 22.04 server or local machine is crucial. This tutorial will guide you through the installation process, ensuring a smooth setup for your reporting needs. ## Step 1 – Install Java JDK JasperReports requires Java to run. Install the OpenJDK package using the following command: ``` apt install default-jdk unzip wget -y ``` After the installation, verify the Java installation using the following command. ``` java --version ``` Output. ``` openjdk 11.0.21 2023-10-17 OpenJDK Runtime Environment (build 11.0.21+9-post-Ubuntu-0ubuntu122.04) OpenJDK 64-Bit Server VM (build 11.0.21+9-post-Ubuntu-0ubuntu122.04, mixed mode, sharing) ``` ## Step 2 – Install and Configure MariaDB Server Next, you will need to install the MariaDB database server on your system. You can install it using the following command. ``` apt install mariadb-server -y ``` Once MariaDB is installed, connect to the MariaDB shell using the following command. ``` mysql ``` Next, create a user for Jasper report: ``` grant all on *.* to jasper@localhost identified by 'securepassword'; ``` Next, flush the privileges and exit from the MariaDB shell with the following command: ``` flush privileges; exit; ``` ## Step 3 – Install Tomcat Server You will also need to install and set up a Tomcat server on your system. First, add a user and group for Tomcat: ``` groupadd tomcat useradd -s /bin/bash -g tomcat -d /opt/tomcat tomcat ``` Next, create a directory for Tomcat: ``` mkdir /opt/tomcat ``` Next, download the latest version of Tomcat from its official website: ``` wget https://dlcdn.apache.org/tomcat/tomcat-9/v9.0.83/bin/apache-tomcat-9.0.83.tar.gz ``` Next, extract the downloaded file inside the /opt/tomcat directory. ``` tar -xzvf apache-tomcat-9.0.83.tar.gz -C /opt/tomcat --strip-components=1 ``` Next, set proper ownership and permissions on the Tomcat directory. ``` chown -R tomcat: /opt/tomcat sh -c 'chmod +x /opt/tomcat/bin/*.sh' ``` ## Step 4 – Create a Tomcat Service File Next, create a system service file for Tomcat: ``` nano /etc/systemd/system/tomcat.service ``` Add the following lines: ``` [Unit] Description=Apache Tomcat After=network.target [Service] Type=forking User=tomcat Group=tomcat Environment=JAVA_HOME=/usr/lib/jvm/java-1.11.0-openjdk-amd64 Environment=CATALINA_PID=/opt/tomcat/tomcat.pid Environment=CATALINA_HOME=/opt/tomcat Environment=CATALINA_BASE=/opt/tomcat Environment="CATALINA_OPTS=-Xms1024M -Xmx1024M -server -XX:+UseParallelGC" ExecStart=/opt/tomcat/bin/startup.sh ExecStop=/opt/tomcat/bin/shutdown.sh ExecReload=/bin/kill $MAINPID RemainAfterExit=yes [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon using the following command. ``` systemctl daemon-reload ``` ## Step 5 – Install and Configure JasperReports First, log in with a Tomcat user and download the JasperReports using the following command. ``` su - tomcat ``` ``` wget https://sourceforge.net/projects/jasperserver/files/JasperServer/JasperReports%20Server%20Community%20Edition%208.2.0/TIB_js-jrs-cp_8.2.0_bin.zip/download -O jasperreports_8.2.0.zip ``` Next, unzip the downloaded file with the following command. ``` unzip jasperreports_8.2.0.zip ``` Next, copy the MySQL property file with the following command: ``` cp -a jasperreports-server-cp-8.2.0-bin/buildomatic/sample_conf/mysql_master.properties jasperreports-server-cp-8.2.0-bin/buildomatic/default_master.properties ``` Next, edit the MySQL property file using the following command: ``` nano jasperreports-server-cp-8.2.0-bin/buildomatic/default_master.properties ``` Change the following lines: ``` CATALINA_HOME = /opt/tomcat CATALINA_BASE = /opt/tomcat dbHost=localhost dbUsername=jasper dbPassword=securepassword encrypt = true ``` Save and close the file, then install JasperReports: ``` cd jasperreports-server-cp-8.2.0-bin/buildomatic/ ``` ``` ./js-install-ce.sh ``` Output. ``` scalableAdhoc-refinement: deploy-webapp-ce: install-normal-ce: [echo] Installation successfully completed! BUILD SUCCESSFUL Total time: 3 minutes 59 seconds Checking Ant return code: OK ``` Next, edit the Tomcat policy configuration file: ``` nano /opt/tomcat/conf/catalina.policy ``` Add the following lines at the end of the file: ``` grant codeBase "file:/groovy/script" { permission java.io.FilePermission "${catalina.home}${file.separator}webapps${file.separator} jasperserver-pro${file.separator}WEB-INF${file.separator}classes${file.separator}-", "read"; permission java.io.FilePermission "${catalina.home}${file.separator}webapps${file.separator} jasperserver-pro${file.separator}WEB-INF${file.separator}lib${file.separator}*", "read"; permission java.util.PropertyPermission "groovy.use.classvalue", "read"; }; ``` Next, edit the applicationContext file. ``` nano /opt/tomcat/webapps/jasperserver/WEB-INF/applicationContext.xml ``` Find the following line: ``` class="com.jaspersoft.jasperserver.api.engine.jasperreports.util.PermissionsListProtectionDomainProvider"> ``` Add the following lines after the above lines: ``` ``` Save and close the file, then exit from the Jasper user: ``` exit ``` Finally, start the Tomcat service with the following command. ``` systemctl start tomcat ``` You can also check the Tomcat status using the following command. ``` systemctl status tomcat ``` Output. ``` ● tomcat.service - Apache Tomcat Loaded: loaded (/etc/systemd/system/tomcat.service; disabled; vendor preset: enabled) Active: active (running) since Wed 2023-12-06 13:54:12 UTC; 8s ago Main PID: 44609 (java) Tasks: 16 (limit: 4579) Memory: 410.4M CPU: 9.351s CGroup: /system.slice/tomcat.service └─44609 /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Djava.util.logging.config.file=/opt/tomcat/conf/logging.properties -Djava.util.logging.manager=or> Dec 06 13:54:12 ubuntu systemd[1]: Starting Apache Tomcat... Dec 06 13:54:12 ubuntu startup.sh[44602]: Tomcat started. Dec 06 13:54:12 ubuntu systemd[1]: Started Apache Tomcat. ``` ## Step 6 – Access JasperReports Now, open your web browser and access the JasperReport web UI using the URL **http://your-server-ip:8080/jasperserver/.** You will see the JasperReports login page: ![](https://www.atlantic.net/wp-content/uploads/2023/12/p1-7.png) Provide the following username and password. **username:** jasperadmin **password:** jasperadmin Then, click on the **Login** button. You will see the JasperReports dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p2-5.png) ## Conclusion Congratulations! You have successfully installed JasperReports on Ubuntu 22.04. You can now leverage the power of JasperReports to design, generate, and distribute feature-rich reports for your projects. The web-based interface provides a user-friendly environment for report management, making it accessible to both technical and non-technical users. Try to deploy JasperReport on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install October CMS on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-october-cms-on-ubuntu-22-04/ | Published: 2024-01-05 | Updated: 2024-01-22 | Author: Hitesh Jethva October CMS is a powerful, open-source content management system that empowers web developers and designers to create robust websites with ease. October CMS supports the development of RESTful APIs, making it suitable for creating not only traditional websites but also web applications and services that require API endpoints. This tutorial will guide you through the process of installing October CMS on Ubuntu 22.04, ensuring a smooth setup for your web development projects. ## Step 1 – Install LEMP Stack October CMS requires a LAMP (Linux, NGINX, MySQL, PHP) stack. Make sure you have Apache, MySQL, and PHP installed and configured. You can install them using the following commands: ``` apt update -y apt-get install nginx mariadb-server php php-cli php-common php-imap php-redis php-snmp php-xml php-zip php-mbstring php-curl php-mysqli php-intl php-bcmath php-gd php-fpm unzip -y ``` After installing all the packages, start and enable Nginx and MariaDB services: ``` systemctl start nginx mariadb systemctl enable nginx mariadb ``` ## Step 2 – Configure Database Next, you will need to create a new MySQL database and user for October CMS. First, access the MySQL shell: ``` mysql ``` Next, create a database and user for October CMS: ``` CREATE USER 'octobercms'@'localhost' IDENTIFIED BY 'password'; CREATE DATABASE octobercms; GRANT ALL PRIVILEGES ON octobercms.* TO 'octobercms'@'localhost'; ``` Next, flush the privileges: ``` FLUSH PRIVILEGES; ``` Then, exit from the MySQL shell using the following command. ``` EXIT; ``` ## Step 3 – Download October CMS Firstly, let’s download the latest version of October CMS. Open your terminal and navigate to the directory where you want to install October CMS: ``` cd /var/www/html ``` Next, download the latest version of October CMS: ``` wget https://octobercms.com/download -O october.zip ``` Once the download is completed, unzip the downloaded file. ``` unzip october.zip ``` Next, rename the extracted directory to octobercms: ``` mv install-master octobercms ``` Next, adjust the directory permissions to ensure that October CMS can function correctly: ``` chown -R www-data:www-data /var/www/html/octobercms ``` ## Step 4 – Configure Nginx for October CMS Create a new virtual host configuration file for October CMS. You can use a text editor like nano or vim: ``` nano /etc/nginx/conf.d/octobercms.conf ``` Add the following configuration to the file: ``` server { listen 80; server_name october.example.com; index index.php index.html; root /var/www/html/octobercms; location / { try_files $uri $uri/ /index.php?$query_string; } location ~ \.php$ { include snippets/fastcgi-php.conf; fastcgi_pass unix:/var/run/php/php8.1-fpm.sock; fastcgi_read_timeout 120s; } location ~ ^/favicon\.ico { try_files $uri /index.php; } location ~ ^/sitemap\.xml { try_files $uri /index.php; } location ~ ^/robots\.txt { try_files $uri /index.php; } location ~ ^/humans\.txt { try_files $uri /index.php; } location ~ ^/storage/app/uploads/public { try_files $uri 404; } location ~ ^/storage/app/media { try_files $uri 404; } location ~ ^/storage/temp/public { try_files $uri 404; } location ~ ^/modules/.*/assets { try_files $uri 404; } location ~ ^/modules/.*/resources { try_files $uri 404; } location ~ ^/modules/.*/behaviors/.*/assets { try_files $uri 404; } location ~ ^/modules/.*/behaviors/.*/resources { try_files $uri 404; } location ~ ^/modules/.*/widgets/.*/assets { try_files $uri 404; } location ~ ^/modules/.*/widgets/.*/resources { try_files $uri 404; } location ~ ^/modules/.*/formwidgets/.*/assets { try_files $uri 404; } location ~ ^/modules/.*/formwidgets/.*/resources { try_files $uri 404; } location ~ ^/modules/.*/reportwidgets/.*/assets { try_files $uri 404; } location ~ ^/modules/.*/reportwidgets/.*/resources { try_files $uri 404; } location ~ ^/plugins/.*/.*/assets { try_files $uri 404; } location ~ ^/plugins/.*/.*/resources { try_files $uri 404; } location ~ ^/plugins/.*/.*/behaviors/.*/assets { try_files $uri 404; } location ~ ^/plugins/.*/.*/behaviors/.*/resources { try_files $uri 404; } location ~ ^/plugins/.*/.*/reportwidgets/.*/assets { try_files $uri 404; } location ~ ^/plugins/.*/.*/reportwidgets/.*/resources { try_files $uri 404; } location ~ ^/plugins/.*/.*/formwidgets/.*/assets { try_files $uri 404; } location ~ ^/plugins/.*/.*/formwidgets/.*/resources { try_files $uri 404; } location ~ ^/plugins/.*/.*/widgets/.*/assets { try_files $uri 404; } location ~ ^/plugins/.*/.*/widgets/.*/resources { try_files $uri 404; } location ~ ^/themes/.*/assets { try_files $uri 404; } location ~ ^/themes/.*/resources { try_files $uri 404; } } ``` Save and close the file, then edit the Nginx main configuration file: ``` nano /etc/nginx/nginx.conf ``` Add the following line below the line {: ``` server_names_hash_bucket_size 64; ``` Save the file, then verify Nginx for syntax errors: ``` nginx -t ``` You should receive the following output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, reload the Nginx to apply the changes: ``` systemctl reload nginx ``` ## Step 5 – Access October CMS Now, open your web browser and access the October CMS using the URL **http://october.example.com/install.php.** You should see the October CMS welcome page. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p1-4.png) Select your language. You will see the **License agreement** page: ![](https://www.atlantic.net/wp-content/uploads/2023/12/p2-4.png) Click on **Agree and Continue.** You will see the database configuration page: ![](https://www.atlantic.net/wp-content/uploads/2023/12/p3-2.png) Define your database credentials and click on **Continue.** You will see the Licence key page: ![](https://www.atlantic.net/wp-content/uploads/2023/12/p4-2.png) Provide your key and click on **Install.** You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2023/12/p5.png) Click on the Administration Panel URL. You will see the **Create Account** page: ![](https://www.atlantic.net/wp-content/uploads/2023/12/p6.png) Provide your account information and click on **Create Account.** You will see the October CMS on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p7-1.png) ## Conclusion This tutorial has provided a step-by-step guide to install October CMS on Ubuntu 22.04. By following these instructions, you have set up a robust environment for web development and content management. As you delve deeper into October CMS, you’ll discover its versatility and the ease with which you can create and manage dynamic websites. Try to deploy October CMS on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install aaPanel on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-aapanel-on-ubuntu-24-04/ | Published: 2024-01-08 | Updated: 2025-07-04 | Author: Hitesh Jethva AAPanel, also known as “aaPanel” or “AAPanel Hosting Control Panel,” is an open-source web hosting control panel designed to simplify the process of managing web hosting services on Linux servers. It provides a user-friendly web-based interface that allows users, particularly those without extensive technical knowledge, to manage various aspects of their web hosting environment easily. In this tutorial, we will walk through the process of installing aaPanel on Ubuntu 24.04. ## Step 1 – Download and Install aaPanel aaPanel provides a convenient installation script that automates the installation process. Execute the following command to download the installation script: ``` wget https://www.aapanel.com/script/install_7.0_en.sh ``` Once the script is downloaded, make it executable using the following command. ``` chmod +x install_7.0_en.sh ``` Next, run the script to start the installation. ``` bash install_7.0_en.sh ``` Once the script is executed, the aaPanel installation wizard will start. Follow the on-screen prompts to configure various settings. The wizard will ask you for information such as the panel username, password, and whether you want to install additional components like Nginx, MySQL, and PHP. ``` | Copyright © 2015-2099 BT-SOFT(http://www.aapanel.com) All rights reserved. +---------------------------------------------------------------------- | The WebPanel URL will be http://SERVER_IP:7800 when installed. +---------------------------------------------------------------------- Do you want to install aaPanel to the /www directory now?(y/n): y install-ubuntu_6.0_en.sh: line 888: setenforce: command not found ---------------------------------------------------- Web service is alreday installed,installing aaPanel may affect existing sites. ---------------------------------------------------- Enter [yes] to force installation Enter yes to force installation: yes ---------------------------------------------------------------------- If you choose to enable SSL (self-signed certificate), you will use https access panel after installation. After logging in, you can go to the panel settings and change to Let's Encrypt certificate. SSL will be automatically enabled in 10 seconds. ---------------------------------------------------------------------- Do you need to enable the panel SSl ? (yes/n): n --------------------------------------------- Selected download node... Download node: https://node.aapanel.com Stopping Bt-Tasks... done Stopping Bt-Panel... done Starting Bt-Panel.... done Starting Bt-Tasks... done ================================================================== Congratulations! Installed successfully! ================================================================== aaPanel Internet Address: https://69.28.91.23:40700/5cf829ae aaPanel Internal Address: https://69.28.91.23:40700/5cf829ae username: pkl4bdzj password: 46c91774 Warning: If you cannot access the panel, release the following port (40700|888|80|443|20|21) in the security group ================================================================== Time consumed: 1 Minute! ``` After completing the installation wizard, aaPanel will be installed on your Ubuntu server. Note down the username and password from the above output. ## Step 2 – Access aaPanel Once the installation is complete, you can access aaPanel’s web interface using your server’s IP address and the configured port. Open your web browser and enter the URL **http://your_server_ip:40700/5cf829ae** ![](https://www.atlantic.net/wp-content/uploads/2024/01/a1.png)   Log in using the username and password you see after the installation process.   ![](https://www.atlantic.net/wp-content/uploads/2024/01/a2.png) #### Terminal Shell ![](https://www.atlantic.net/wp-content/uploads/2023/12/p4-3.png) #### App Store ![](https://www.atlantic.net/wp-content/uploads/2023/12/p5-1.png) #### Files ![](https://www.atlantic.net/wp-content/uploads/2023/12/p6-1.png) #### **Logs** ![](https://www.atlantic.net/wp-content/uploads/2023/12/p7-2.png) ## Conclusion Congratulations! You have successfully installed aaPanel on your Ubuntu 24.04 server. aaPanel’s user-friendly interface simplifies the management of server resources, making it an excellent choice for users of all skill levels. Explore the various features offered by aaPanel to streamline server administration tasks and enhance your web hosting experience. If you encounter any issues, refer to the official documentation or community forums for assistance. Let’s deploy aaPanel on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # A Guide to HIPAA Compliance in the Cloud > URL: https://www.atlantic.net/hipaa-compliant-hosting/a-guide-hipaa-compliance-in-the-cloud/ | Published: 2024-01-09 | Updated: 2024-09-11 | Author: Richard Bailey Cloud computing has transformed business services globally, and today, U.S. healthcare organizations are reaping the benefits of investing in cloud services early. However, U.S. healthcare and cloud service providers are bound by the Health Insurance Portability and Accountability Act (HIPAA); this legislation was created to protect health information and patient data privacy and can complicate the transition to the cloud. Some healthcare organizations may argue that legislation has slowed the desire to move healthcare services to the cloud. However, the rise of HIPAA-compliant IT hosting and Managed Services providers like Atlantic.Net has established a great trust in IT services designed to enforce the Administrative, Physical, and Technical safeguards of HIPAA compliance in the cloud. ## HIPAA and Cloud Computing HIPAA was created in 1996 when the Internet was in its infancy and Cloud computing services did not yet exist. Over time, as businesses digitized workloads and the first footprints of public cloud services computing took a foot in private data centers across the U.S., Healthcare businesses were trying to understand how the newly founded legislation, including the HIPAA Security rule and HIPAA Privacy Rule amendments in 2003, would affect their business. Healthcare providers were met with a dilemma: stick to old-fashioned paper records, manual processes, and cumbersome administration or venture into the unknown by attempting to become HIPAA compliant by going it alone. Thankfully, as cloud computing matured, another option was on the table: healthcare providers could now directly outsource healthcare IT systems to HIPAA-compliant cloud computing and cloud storage providers. ## How to Maintain HIPAA Compliance While Engaging Cloud Providers Atlantic.Net started its cloud computing services in 2010, and we quickly established a leading HIPAA-compliant cloud storage and hosting service over the next few years. Our business was one of the very first to give U.S. healthcare organizations the option to outsource not only data recovery and the hosting of their IT systems but also the option to purchase managed services that added real value and bolstered their accreditation of being HIPAA Compliant. The HIPAA compliance provider must be able to meet and exceed the mandatory requirements of HIPAA regulations. This can be challenging because the number of compulsory, recommended, and preferred safeguards is difficult to quantify. Approximately 80 HIPAA rules and guidelines relate directly to the HIPAA Privacy Rule, and about 100 regulations comprise the Administrative, Physical, and Technical Safeguards of the Security Rule. To complicate this further, while some HIPAA rules are mandatory, recommended, or simply nice to have, some HIPAA rules won’t apply to your healthcare organization! This creates a complex web of HIPAA requirements, health-related data confidentiality, integrity, and availability, so outsourcing to a HIPAA-compliant hosting partner is highly recommended. ### Sign a Business Associate Agreement for Cloud Services The very first requirement to be obtained is a Business Associate Agreement (BAA). When outsourcing, regardless of the extent of Protected Health Information (PHI) involvement, all Managed Service Providers offering HIPAA services to a covered entity (healthcare provider, health plan, or healthcare clearinghouse) must have a signed BAA in place. The BAA outlines their business associate status, the permitted uses and disclosures of PHI, and limitations on access to healthcare data, and stipulates the safeguards to be implemented by the MSP to protect PHI. BAAs should be reviewed and updated regularly, especially when cloud services or technology change. ### HIPAA Security Rule To be HIPAA compliant in the cloud, it is essential that your IT cloud services are configured and in compliance with the mandatory parts of the Security Rule. The security rule is divided into Administrative Safeguards, Physical Safeguards, and Technical Safeguards. #### Administrative Safeguards The Administrative Safeguards of the Security Rule revolve around establishing policies and procedures to manage security programs. Here are the key elements: - **Security Management Process:** Covered entities must create and implement policies and procedures to manage and maintain their security programs. This involves conducting risk assessments, managing risks, resolving risk issues, setting security policies, and providing relevant training to the workforce. - **Security Awareness and Training:** A HIPAA-Covered Entity and the Business Associates workforce must be educated about HIPAA security policies and procedures to safeguard protected health information. - **Workforce Security:** The business hiring, termination, and authorization process and procedures must be reworked for personnel accessing ePHI. This includes additional background checks for employees who have access to PHI systems. - **Disaster Recovery Plan:** Establishing a plan to restore operations and ePHI access in emergencies or disasters. This includes technical requirements and process changes, such as having access to alternative business premises in the event of a disaster. - **Contingency Plan:** Outlining procedures to recover ePHI in the event of its loss, corruption, or destruction. This should be part of a wider business continuity plan that includes a detailed response of who is responsible for each part of the contingency plan. #### Physical Safeguards Physical Safeguards under the HIPAA Security Rule focus on controlling access to electronic medical records and protecting physical equipment storing ePHI. Key requirements include: - **Facility Access Controls:** Implementing physical barriers and controls such as locks, security cameras, controlled entry systems, and visitor logs to restrict unauthorized access to data centers, healthcare equipment, and healthcare devices. - **Workstation and Device Security:** Securing workstations and devices accessing protected health information with robust passwords, encryption, and activity monitoring. Common fixes include screen locks and timeouts (usually after 30 seconds). - **Media Control:** Establishing procedures for the use, transfer, disposal, and reuse of electronic media containing ePHI to prevent unauthorized access or loss. One example is medical imaging; the HIPAA rules define how images are stored, shared, and accessed. - **Documentation:** Documenting physical security policies and procedures to demonstrate compliance with HIPAA. You need to know what IT systems contain ePHI, what ePHI you have saved to cloud storage, and how it is processed. - **Addressable Safeguards** include additional physical safeguards based on specific risk assessments, such as emergency evacuation procedures and 24/7 security guard coverage. #### Technical Safeguards The Technical Safeguards outlined in the HIPAA Security Rule aim to protect ePHI through technological measures. **Access Control:** - **Unique User IDs and Passwords:** Enforcing strong password policies and regular changes to prevent unauthorized access. User access must adhere to the principle of least privilege. - **Multi-Factor Authentication (MFA):** Implementing additional security measures like one-time codes or biometrics is mandatory. MFA should protect access to sensitive data such as websites, imaging data stores, etc. - **Role-Based Access Control (RBAC):** Granting ePHI access based on authorized personnel’s roles and responsibilities. This is controlling data on a ‘need to know’ basis. **Data Security:** - **Encryption:** It is essential to encrypt ePHI at rest and in transit to safeguard it from unauthorized access. It is one of the most effective ways of protecting sensitive data. - **Data Integrity:** Implementing measures to ensure the accuracy and completeness of ePHI, preventing unauthorized alteration. Knowing what in-scope data your systems process is a mandatory requirement of HIPAA, and the ability to restore data from backup is essential. - **Audit Controls:** Track and log user activity related to ePHI access for identifying potential breaches by using an SIEM solution and an intrusion protection service. Automate alerts need to be responded to around the clock; MSPs will have 24x7x365 support that can help here. #### Transmission Security: - **Secure Communication Protocols:** Use protocols like HTTPS and TLS/SSL certificates to encrypt protected health information communications over the Internet. - **Email Security:** Employing robust email security measures like encryption and digital signatures for ePHI sent via email. Tools are available that will intercept ePHI if unintentionally sent via email, blocking it before it leaves your infrastructure perimeter. - **Malware Protection:** Installing and maintaining effective anti-malware software is essential to protect against viruses and data leaks. - **Software Updates:** Applying security patches and updates promptly to mitigate known vulnerabilities is the most effective way to bolster your security posture. Updates should be monthly; all systems should run genuine, modern software. - **Data Backup and Recovery:** Regularly backing up ePHI and having procedures for data restoration in case of loss or system failure is the easiest way to protect our system from extended outages. It also helps satisfy the HIPAA requirement of ePHI, which must always be available. ### HIPAA Privacy Rule We must also consider the HIPAA requirements and Privacy Rules to ensure HIPAA Compliance in the Cloud. The Security Rule is black and white over its requirements. However, with the Privacy rules, the conditions are not so clear cut. The HIPAA Privacy Rule outlines situations where using and sharing PHI without individual permission is okay. These scenarios involve treatment, payment, healthcare operations, electronic health records, public health efforts, and specific conditions. Redacted protected health information stored data can also be used to train healthcare professionals or in educational studies. The HIPAA Privacy Rule gives people certain rights regarding their PHI. - **Access**: Patients can view and inspect their medical records. - **Amendment**: Patients can ask to fix any wrong or incomplete information. - **Accounting of Disclosures**: Patients have a right to know who has seen their PHI. - **Confidentiality**: Patients can also limit who else gets to know about their PHI. The HIPAA Privacy Rule includes several other vital components. - **Minimum Necessary Standard:** This mandates HIPAA-covered entities to only use, disclose, or request the least amount of PHI necessary for their intended purpose. - **Notice of Privacy Practices:** A Covered Entity must craft and provide individuals with a clear notice detailing their privacy practices and the rights individuals have regarding their PHI. - **Administrative Safeguards:** involves specific policies and procedures that a covered entity needs to adopt to safeguard PHI. This includes implementing security measures, training, and establishing breach notification protocols. - **Compliance Reviews and Complaints:** This section explains how the Department of Health and Human Services (HHS) enforces the rule by conducting compliance reviews and investigating individual complaints. - **Additional Provisions:** Covering a range of other subjects like marketing, research, and genetic information, these provisions further elaborate on how the rule applies in various contexts. ## The Complexities of HIPAA ### Example: HIPAA Compliant Cloud Storage To help illustrate how the Privacy and Security rules impact your healthcare business, let’s consider a customer who uses [Atlantic.Net HIPAA-compliant cloud storage](https://www.atlantic.net/resources/documents/whitepapers/pdf/how-to-make-storage-hipaa-compliant-atlantic-net-whitepaper.pdf). Storage is one of the most popular HIPAA services our customers choose. Data protection and data encryption are at the cornerstone of the cloud service, and it’s essential to enforce data classification and prevent a data breach. HIPAA-compliant cloud storage requires these safeguards to be in place: - **Network Encryption:** Use NIST cryptographic standards whenever you transmit protected health information. - **Data Access controls:** As per the HIPAA rules, each user must have a unique username, password, and PIN. - **Authenticate ePHI:** You must authenticate ePHI and protect it from unauthorized changes. - **Encrypt Devices:** The storage and all devices connected to it must be encrypted. - **Audit Activities:** All user access must be logged. - **Control Facility Access:** Your Provider must carefully track all data center access, including employees, engineers, and site visitors. - **Inventory:** All hardware, mobiles, and devices used to connect to the cloud storage must be inventoried. - **Block All Access By Default:** Access to every must be blocked (except of course a few authorized users). - **Risk Assessment:** Constantly evaluate Access controls and data handling practices. - **Train Your Staff:** Employees must be trained to use cloud storage. - **Document Security Incidents:** Employees should recognize and report any security event. As you can see, these are just the high-level requirements of a single HIPAA-compliant cloud service. Your HIPAA-compliant provider is responsible for multiple services. It is easy to see how complicated this entire process gets when you increase the scale of the operation. ## Atlantic.Net HIPAA Hosting Are you ready to take the next step to discover more about HIPAA Compliance in the cloud? Atlantic.Net has the complex infrastructure required for HIPAA hosting and HIPAA-managed services available. Here are the key HIPAA Services available from Atlantic.Net: - **Shared, VPS, Dedicated, and Cloud Server Hosting:** Choose the hosting plan that best suits your needs, all with HIPAA compliance built-in. - **Business Associate Agreement (BAA):** Atlantic.Net signs a BAA with you, outlining both parties’ responsibilities for protecting PHI. - **Security Features:** Strong security measures like intrusion prevention systems, firewalls, vulnerability scans, and encrypted backups help keep your data safe. - **Compliance Certifications:** Atlantic.Net is HIPAA audited and SOC 2 and SOC 3 certified, demonstrating their commitment to data security. - **Managed Intrusion Prevention System:** Continuously monitor your network for suspicious activity and prevent attacks. - **Anti-Malware Protection:** Protect your systems from malware and other threats. - **Dedicated Firewalls & Encrypted VPN:** Secure your network perimeter and encrypt your data in transit. - **Log Management and Analysis:** Keep track of all activity on your systems and identify potential security issues. - **HIPAA-Compliant WordPress Hosting:** Run your WordPress website with the same level of security and compliance as your other HIPAA data. - **HIPAA-Compliant Email Hosting:** Securely send and receive email with PHI protection. - **HIPAA-Compliant Disaster Recovery:** Ensure business continuity in the event of a disaster with a HIPAA-compliant backup and recovery solution. Are you in need of an infrastructure that can protect the health data of your organization? At [Atlantic.Net](https://www.atlantic.net/hipaa-compliant-hosting/), whatever your technical requirements, we can offer a top-grade [HIPAA-Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solution. Get a [HIPAA-Compliant Server Cost](https://www.atlantic.net/hipaa-compliant-hosting/) from one of our experts. [**Get a free consultation today!**](https://www.atlantic.net/hipaa-compliant-hosting/#GetStarted) --- # Installing and Configuring Laravel with Nginx on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/installing-and-configuring-laravel-with-nginx-on-ubuntu-24-04/ | Published: 2024-01-10 | Updated: 2025-05-14 | Author: Hitesh Jethva Laravel is an open-source PHP programming language framework based on the MVC architecture and the Symphony framework. It offers a set of tools to build modern PHP applications. Laravel is highly scalable, has elegant syntax and advanced features, and has built-in support for distributed cache systems, which help simplify web application development. ## Step 1 – Install LEMP Server Laravel runs on a web server, uses MySQL as a database backend, and is written in PHP, so you will need a LEMP stack installed on your server. You can install all LEMP server components using the following command. ``` apt install nginx mysql-server php php-fpm php-mbstring php-mysql php-xml php-bcmath php-curl zip unzip -y ``` After installing the LEMP stack, start and enable all necessary services. ``` systemctl start nginx mysql php8.3-fpm systemctl enable nginx mysql php8.3-fpm ``` ## Step 2 – Create a Database for Laravel Next, you will need to create a database and user for Laravel. First, connect to the MySQL with the following command. ``` mysql ``` Next, create a database and user for Laravel. ``` CREATE DATABASE laravel; CREATE USER 'laravel_user'@'%' IDENTIFIED WITH mysql_native_password BY 'password'; GRANT ALL ON laravel.* TO 'laravel_user'@'%'; ``` Next, flush the privileges and exit from the MySQL shell. ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install Laravel In this section, we will install Laravel using Composer. First, install the Composer with the following command. ``` curl -sS https://getcomposer.org/installer | php mv composer.phar /usr/local/bin/composer chmod +x /usr/local/bin/composer ``` Next, navigate to the Nginx web root and create a Laravel project. ``` cd /var/www/html composer create-project --prefer-dist laravel/laravel laravel ``` You will see the following output. ``` > @php artisan vendor:publish --tag=laravel-assets --ansi --force INFO No publishable resources for tag [laravel-assets]. No security vulnerability advisories found. > @php artisan key:generate --ansi INFO Application key set successfully. ``` Next, set proper permissions and ownership on the Laravel directory. ``` chown -R :www-data /var/www/html/laravel chmod -R 775 /var/www/html/laravel ``` Next, change the directory to Laravel and generate PHP artisan. ``` cd laravel php artisan key:generate ``` Next, run the migration to create the table. ``` php artisan migrate ``` Next, edit the environment variable file. ``` nano /var/www/html/laravel/.env ``` Define your Laravel database settings as shown below. ``` APP_URL=http://laravel.example.com LOG_CHANNEL=stack DB_CONNECTION=mysql DB_HOST=127.0.0.1 DB_PORT=3306 DB_DATABASE=laravel DB_USERNAME=laravel_user DB_PASSWORD=password ``` Save and close the file when you are done. ## Step 4 – Configure Nginx for Laravel Next, you must create a Nginx virtual host configuration file for Laravel. ``` nano /etc/nginx/conf.d/laravel.conf ``` Add the following configuration. ``` server { listen 80; server_name laravel.example.com; root /var/www/html/laravel/public; add_header X-Frame-Options "SAMEORIGIN"; add_header X-XSS-Protection "1; mode=block"; add_header X-Content-Type-Options "nosniff"; index index.html index.htm index.php; charset utf-8; location / { try_files $uri $uri/ /index.php?$query_string; } location = /favicon.ico { access_log off; log_not_found off; } location = /robots.txt { access_log off; log_not_found off; } error_page 404 /index.php; location ~ \.php$ { fastcgi_pass unix:/var/run/php/php8.3-fpm.sock; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; include fastcgi_params; } location ~ /\.(?!well-known).* { deny all; } } ``` Save and close the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http {: ``` server_names_hash_bucket_size 64; ``` Save the file, then verify Nginx for syntax errors. ``` nginx -t ``` Output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Next, restart the Nginx service to apply the changes. ``` systemctl reload nginx ``` ## Step 5 – Access Laravel Web UI At this point, Laravel is installed and configured with Nginx. Now, open your web browser and access the Laravel web UI using the URL **http://laravel.example.com.** You will see the Laravel sample page on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/01/p1-1.png)   ## Conclusion Congratulations! You have successfully installed Laravel with Nginx on Ubuntu 24.04. You can now explore the Laravel features and deploy your PHP-based application using the Laravel framework. You can now deploy Laravel on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Adminer on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-adminer-on-ubuntu-24-04/ | Published: 2024-01-11 | Updated: 2025-05-24 | Author: Hitesh Jethva Adminer is an open-source tool for managing multiple databases via a web-based interface. It is an alternative to phpMyAdmin and supports several databases such as MariaDB, MySQL, SQLite, Oracle, PostgreSQL, MongoDB, and Elasticsearch. It is lightweight, user-friendly, and has a clean interface that makes it easy to use and learn. ## Step 1 – Install Apache and PHP First, you will need a web server installed on your server. You can install the Apache server with PHP packages using the following command. ``` apt install apache2 php php-fpm php-curl libapache2-mod-php php-cli php-mysql php-gd -y ``` Once the Apache package is installed, start and enable the Apache service using the following command. ``` systemctl enable --now apache2 ``` You can verify the status of the Apache using the following command. ``` systemctl status apache2 ``` Output. ``` ● apache2.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/apache2.service; enabled; preset: enabled) Active: active (running) since Sat 2025-05-24 06:38:56 AST; 13s ago Docs: https://httpd.apache.org/docs/2.4/ Main PID: 502048 (apache2) Tasks: 6 (limit: 4609) Memory: 12.8M (peak: 13.0M) CPU: 125ms CGroup: /system.slice/apache2.service ├─502048 /usr/sbin/apache2 -k start ├─502052 /usr/sbin/apache2 -k start ├─502053 /usr/sbin/apache2 -k start ├─502054 /usr/sbin/apache2 -k start ├─502055 /usr/sbin/apache2 -k start └─502056 /usr/sbin/apache2 -k start ``` ## Step 2 – Install MySQL Server You will also need a database server to test the Adminer. Let’s install the MySQL server package with the following command. ``` apt install mysql-server -y ``` Once the MySQL server is installed, run the mysql_secure_installation script to secure the installation. ``` mysql_secure_installation ``` Answer all the questions as shown below: ``` Enter current password for root (enter for none): Switch to unix_socket authentication [Y/n] Y Change the root password? [Y/n] Y //Enter the password you want to set for MySQL root user Remove anonymous users? [Y/n] Y Disallow root login remotely? [Y/n] Y Remove test database and access to it? [Y/n] Y ``` Next, log in to the MySQL server. ``` mysql ``` Then, set the MySQL root password. ``` ALTER USER 'root'@'localhost' IDENTIFIED BY 'securepassword'; ``` Next, create a sample database and user. ``` CREATE DATABASE adminerdb; CREATE USER 'adminer'@'%' IDENTIFIED WITH mysql_native_password BY 'password'; GRANT ALL ON adminerdb.* TO 'adminer'@'%'; ``` Next, flush the privileges to reload the changes. ``` FLUSH PRIVILEGES; ``` Finally, exit from the MySQL shell. ``` EXIT; ``` ## Step 3 – Install Adminer By default, the Adminer package is included in the Ubuntu default repository. You can install it using the following command. ``` apt install adminer -y ``` Once the Adminer is installed, enable the Adminer configuration file with the following command. ``` a2enconf php*-fpm a2enconf adminer ``` Next, restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` ## Step 4 – Access Adminer Web UI Now, open your web browser and access the Adminer web UI using the URL **http://your-server-ip/adminer.** You will see the Adminer web interface. ![adminer login page](https://www.atlantic.net/wp-content/uploads/2023/10/p1-6.png) Provide your database username, password, and database, and click on the **connect** button. You will see the following screen. ![adminer dashboard page](https://www.atlantic.net/wp-content/uploads/2023/10/p2-4.png) You can now manage your database easily from the Adminer dashboard. ## Conclusion In this post, you learned how to install Adminer on Ubuntu 24.04. You can now connect more database servers via Adminer and start managing them from the web-based interface. Try to deploy the Adminer database management tool on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Tomcat 11 on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-tomcat-11-on-ubuntu-24-04/ | Published: 2024-01-12 | Updated: 2025-07-05 | Author: Hitesh Jethva Tomcat, also called Apache Tomcat, is an open-source web server and servlet container for deploying Java-based applications. It is lightweight, easy to use, has a robust ecosystem, and powers many large-scale web applications. Using Apache will boost your website performance and help you to have a better hosting experience. ## Step 1 – Install Java OpenJDK Apache Tomcat is a Java-based application, so you will need to install Java JDK on your server. You can install it using the following command. ``` apt install openjdk-17-jdk ``` Once Java is installed, you can verify the Java installation using the following command. ``` java -version ``` Output. ``` openjdk version "17.0.15" 2025-04-15 OpenJDK Runtime Environment (build 17.0.15+6-Ubuntu-0ubuntu124.04) OpenJDK 64-Bit Server VM (build 17.0.15+6-Ubuntu-0ubuntu124.04, mixed mode, sharing) ``` ## Step 2 – Download Apache Tomcat First, create a dedicated user to run Apache Tomcat. ``` useradd -r -m -U -d /opt/tomcat -s /bin/false tomcat ``` Next, download the Apache Tomcat from their official website. ``` wget -O tomcat.tar.gz https://dlcdn.apache.org/tomcat/tomcat-11/v11.0.7/bin/apache-tomcat-11.0.7.tar.gz ``` Then, extract the downloaded file. ``` tar xzf apache-tomcat-11.0.7.tar.gz ``` Next, move the extracted directory to /opt. ``` mv apache-tomcat-11.0.7/* /opt/tomcat/ ``` Next, set proper permissions and ownership on the Tomcat directory. ``` chown -R tomcat: /opt/tomcat sh -c 'chmod +x /opt/tomcat/bin/*.sh' ``` ## Step 3 – Create a Tomcat User Account Next, you must create an admin and manager account to access the Tomcat application. You can create it by editing tomcat-users.xml file. ``` nano /opt/tomcat/conf/tomcat-users.xml ``` Add the following lines above the last line. ``` ``` Save and close the file when you are done. ## Step 4 – Allow Remote Hosts to Access Tomcat By default, Tomcat is accessible only from the local host. To allow access from the remote host, you must modify Tomcat configuration files. To allow access to the Manager app, edit the context.xml file. ``` nano /opt/tomcat/webapps/manager/META-INF/context.xml ``` Remove the following line. ``` ``` To allow access to the Host Manager app, edit the context.xml file. ``` nano /opt/tomcat/webapps/host-manager/META-INF/context.xml ``` Remove the following line. ``` ``` Save and close the file. ## Step 5 – Create a Systemd Service File for Tomcat Next, you must create a systemd service file to manage the Tomcat service. ``` nano /etc/systemd/system/tomcat.service ``` Add the following lines. ``` [Unit] Description=Apache Tomcat 11 Web Application Server After=network.target [Service] Type=forking User=tomcat Group=tomcat Environment="JAVA_HOME=/usr/lib/jvm/java-17-openjdk-amd64" Environment="CATALINA_HOME=/opt/tomcat" Environment="CATALINA_BASE=/opt/tomcat" Environment="CATALINA_PID=/opt/tomcat/temp/tomcat.pid" Environment="CATALINA_OPTS=-Xms512M -Xmx1024M -server -XX:+UseParallelGC" ExecStart=/opt/tomcat/bin/startup.sh ExecStop=/opt/tomcat/bin/shutdown.sh [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start the Tomcat service with the following command. ``` systemctl start tomcat ``` You can check the status of Tomcat with the following command. ``` systemctl status tomcat ``` Output. ``` ● tomcat.service - Apache Tomcat 11 Web Application Server Loaded: loaded (/etc/systemd/system/tomcat.service; disabled; preset: enabled) Active: active (running) since Wed 2025-05-14 06:56:11 UTC; 4s ago Process: 6276 ExecStart=/opt/tomcat/bin/startup.sh (code=exited, status=0/SUCCESS) Main PID: 6283 (java) Tasks: 31 (limit: 4609) Memory: 112.0M (peak: 112.4M) CPU: 2.865s CGroup: /system.slice/tomcat.service └─6283 /usr/lib/jvm/java-17-openjdk-amd64/bin/java -Djava.util.logging.config.file=/opt/tomcat/conf/logging.properties -Djava.util.logging.manager=org.apa> May 14 06:56:11 ubuntu systemd[1]: Starting tomcat.service - Apache Tomcat 11 Web Application Server... May 14 06:56:11 ubuntu startup.sh[6276]: Tomcat started. May 14 06:56:11 ubuntu systemd[1]: Started tomcat.service - Apache Tomcat 11 Web Application Server. ``` ## Step 6 – Access Tomcat Web UI Now, open your web browser and access the Tomcat UI using the URL **http://your-server-ip:8080.** You will see the following page.   ![](https://www.atlantic.net/wp-content/uploads/2024/01/p1.png) Click on the **manager app, and you** will be asked to provide an admin username and password. ![Tomcat login page](https://www.atlantic.net/wp-content/uploads/2023/10/p2-3.png) Provide your admin username and password and click on **Sign in.** You will see the manager app dashboard. ![Tomcat manager page](https://www.atlantic.net/wp-content/uploads/2023/10/p3-1.png) Click **Host Manager** on the Tomcat Home page. You will see the Tomcat Host Manager on the following screen. ![Tomcat host manager page](https://www.atlantic.net/wp-content/uploads/2023/10/p4-1.png) ## Conclusion Congratulations! You have successfully installed Apache Tomcat 11 on Ubuntu 24.04. You can now build a Java application and deploy it using the Apache Tomcat. Try to deploy the Tomcat web server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install React.js on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-react-js-on-ubuntu-24-04/ | Published: 2024-01-15 | Updated: 2025-05-16 | Author: Hitesh Jethva React is an open-source JavaScript front-end library developed by Facebook and a large community of developers. It is lightweight, which makes your application faster to load. React can be integrated into various projects, which makes it a preferred choice for diverse applications. If you are looking to design interactive user interfaces for single-page applications, then React is the best option for you. ## Step 1 – Install Node.js First, install the necessary dependencies using the following command. ``` apt-get install -y ca-certificates curl gnupg ``` Next, download the Node.js GPG key. ``` mkdir -p /etc/apt/keyrings curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg ``` Next, add the NodeSource repo to the APT source list. ``` echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_22.x nodistro main" | tee /etc/apt/sources.list.d/nodesource.list ``` Then, update the repository index and install Node.js with the following command. ``` apt update apt-get install -y nodejs ``` Next, verify the Node.js version using the following command. ``` node -v ``` Output. ``` v22.15.1 ``` ## Step 2 – Create a React App First, install the create-react app using the NPM command. ``` npm install -g create-react-app ``` Next, create a new project for your application. ``` create-react-app test-project ``` You can verify all files of your project using the following command. ``` ls test-project/ ``` Output. ``` node_modules package.json package-lock.json public README.md src ``` ## Step 3 – Create a Systemd Service File Next, create a systemd service file to manage React application. ``` nano /lib/systemd/system/reactjs.service ``` Add the following configuration. ``` [Service] Type=simple User=root Restart=on-failure WorkingDirectory=/root/test-project ExecStart=npm start -- --port=3000 ``` Save and close the file, then reload the systemd daemon. ``` systemctl daemon-reload ``` Next, start and enable the React service. ``` systemctl start reactjs systemctl enable reactjs ``` You can now verify the React service status using the following command. ``` systemctl status reactjs ``` Output. ``` ● reactjs.service Loaded: loaded (/usr/lib/systemd/system/reactjs.service; static) Active: active (running) since Fri 2025-05-16 07:03:34 UTC; 4s ago Main PID: 79062 (npm start --por) Tasks: 29 (limit: 629145) Memory: 189.8M (peak: 190.0M) CPU: 5.129s CGroup: /system.slice/reactjs.service ├─79062 "npm start --port=3000" ├─79073 node /root/test-project/node_modules/.bin/react-scripts start --port=3000 └─79080 /usr/bin/node /root/test-project/node_modules/react-scripts/scripts/start.js --port=3000 ``` ## Step 4 – Configure Apache as a Reverse Proxy First, install the Apache package with the following command. ``` apt install apache2 -y ``` Next, create an Apache virtual host configuration file. ``` nano /etc/apache2/sites-available/reactjs.conf ``` Add the following configuration. ``` ServerName react.example.com ProxyRequests off ProxyPass / http://127.0.0.1:3000/ ProxyPassReverse / http://127.0.0.1:3000/ ``` Save and close the file, then activate the Apache virtual host and other required modules using the following commands. ``` a2ensite reactjs.conf a2enmod proxy a2enmod proxy_http ``` Finally, reload the Apache service to apply the changes. ``` systemctl reload apache2 ``` ## Step 5 – Access React Web UI Now, open your web browser and access the React web interface using the URL **http://react.example.com.** You will see the React web UI on the following screen. ![react dashboard](https://www.atlantic.net/wp-content/uploads/2023/10/p1-7.png) ## Conclusion Congratulations! You have successfully installed React.js on Ubuntu 24.04. You can now start creating your React application and deploy it to the production server. Build your React application and deploy it on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # What Is OCR Compliance? > URL: https://www.atlantic.net/hipaa-compliant-hosting/what-is-ocr-compliance/ | Published: 2024-01-16 | Updated: 2025-09-11 | Author: Richard Bailey Compliance with OCR standards involves following the directives outlined by the Office for Civil Rights under the Health Insurance Portability and Accountability Act (HIPAA). Any covered entity or business associate responsible for handling protected health information (PHI) in the United States must adhere to the OCR compliance protocols. This involves establishing and enforcing policies, security rules, and procedures to protect PHI, conducting staff training, and consistently evaluating and enhancing security measures to adapt to changes in the threat landscape. This article will uncover the role the OCR plays in HIPAA compliance for healthcare providers and how it upholds the rights of U.S. Healthcare patients. ## Health and Human Services The OCR is a division of the U.S. Department of Health and Human Services (HHS). They are responsible for investigating claims or complaints regarding potential HIPAA violations. The healthcare organization, clearinghouses, etc, are expected to self-refer in the event of a breach of compliance. The OCR is instrumental in providing technical assistance and conducting compliance reviews to facilitate voluntary compliance, avoiding the imposition of civil money penalties wherever possible, but if required, the OCR can also proceed with enforcement actions, including imposing fines upon persistent offenders or cases of gross misconduct. Their mandate extends to addressing complaints of disability discrimination and ensuring equal access to health care for all, irrespective of national origin, and carries the responsibility of imposing civil money penalties as a deterrent against violations while also fostering compliance and offering guidance and support to encourage adherence to civil rights laws. The HHS oversees the OCR’s operations, providing the necessary resources and support to enforce HIPAA regulations effectively. Furthermore, the department works tirelessly to promote public health initiatives and advance biomedical research while maintaining a strong focus on protecting individual privacy and civil rights within the healthcare domain. ## How OCR Enforces the HIPAA Privacy & Security Rules The Office for Civil Rights (OCR) holds the vital responsibility of enforcing the HIPAA Privacy and Security Rules, which serve as the cornerstone for safeguarding individuals’ health information. The OCR ensures that covered entities adhere to these rules by actively investigating complaints and conducting meticulous compliance reviews of covered entities. When violations are identified, OCR has the authority to impose penalties as stipulated by the law. In cases of noncompliance, OCR can impose significant penalties, ranging from $100 to $50,000 per violation, based on the severity and nature of the infraction. This authority acts as a deterrent, compelling covered entities receiving federal financial assistance to prioritize adherence to HIPAA regulations. - In 2019, [Advocate Health Care](https://www.hhs.gov/hipaa/for-professionals/compliance/enforcement/cases/advocate-health-care-network-agrees-pay-165-million-settle-hipaa-violation-charges) agreed to pay $165 million to settle HIPAA violation charges from a 2013 data breach that affected millions of patients. - In 2016, [UCLA Health System](https://www.hhs.gov/hipaa/for-professionals/compliance/enforcement/cases/ucla-health-system-agrees-pay-85-million-settle-hipaa-violation-charges) agreed to pay $8.5 million to settle charges related to the improper disclosure of protected health information (PHI) of nearly 4,500 patients. - In 2014, [HIPAA.com](https://www.hhs.gov/hipaa/for-professionals/compliance/enforcement/cases/hipaacom-excluded-federal-healthcare-programs), a company that provided HIPAA compliance services, was excluded from participating in federal healthcare programs after failing to take adequate measures to protect patient data. Upon receiving a complaint for investigation, the OCR will notify the alleged offender. There follows a knowledge-gathering stage where the OCR will reach out for evidence and review each side’s evidence. If the evidence is not strong enough, the complaint is dropped, and no further action is taken. If a violation has occurred, then a potential penalty is enforced. If, however, a severe breach has been uncovered with significant evidence of systemic wrongdoing is uncovered, the OCR will issue fines, impose civil money penalties, and, in extreme cases, pursue criminal provisions through the U.S. Department of Justice. ## Criminal Penalties for Civil Violations When the DOJ is involved, serious criminal violations may have potentially taken place. Anybody who “knowingly” discloses Protected Health Data could breach the Administrative Simplification Regulations, facing a $50,000 fine but 1 year in jail for each violation. Any expected violation that is committed under false pretenses, such as intentionally deceiving someone, might be hit with a $100,000 fine and five years in prison. If the person(s) were found guilty of selling or transferring protected health information, the fines could reach the eye-watering total of $250,000 per violation and 10 years in prison. ## Federal Civil Rights Laws Finally, if the violation is in breach of core federal civil rights laws, such as the Civil Rights Act of 1964, ADA, ADEA, and ECOA, the penalty may result in the healthcare organization being stuck off and excluded from participating in Medicare.   --- # Installing and Securing phpMyAdmin on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/installing-and-securing-phpmyadmin-on-ubuntu-22-04/ | Published: 2024-01-17 | Updated: 2024-06-01 | Author: Hitesh Jethva phpMyAdmin is an open-source and web-based tool for managing databases via a web browser. It allows users to interact with their databases without executing commands manually in a command-line interface. Using phpMyAdmin, you can import and export data in various formats, such as SQL, CSV, and XML. It is the preferred choice for web developers, database administrators, and website owners to simplify database management. ## Step 1 – Install Apache and PHP First, you will need to install Apache and PHP with all required PHP extensions. You can install them with the following command. ``` apt install apache2 wget unzip php php-zip php-json php-mbstring php-mysql ``` After the installation, start the Apache service and enable it to start at system reboot. ``` systemctl start apache2 systemctl enable apache2 ``` ## Step 2 – Install and Configure MySQL Next, you will also need to install the MySQL server on your system. ``` apt install mysql-server ``` After installing the MySQL server, connect to the MySQL shell using the following command. ``` mysql ``` Next, set the password for the root user. ``` ALTER USER 'root'@'localhost' IDENTIFIED BY 'securepassword'; ``` Then, flush the privileges and exit from the MySQL shell. ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install phpMyAdmin By default, the phpMyAdmin package is included in the Ubuntu default repository. You can install it using the following command. ``` apt install phpmyadmin -y ``` During the installation, you will be asked to set up a phpMyAdmin database using the dbconfig-common configuration package. ![phpmyadmin db config page](https://www.atlantic.net/wp-content/uploads/2023/10/p1-9.png) Click on **Yes** and press the **Enter** key. You will be asked to set a password for phpmyadmin user. ![phpmyadmin password setup page](https://www.atlantic.net/wp-content/uploads/2023/10/p2-6.png) Define your password and press the **Enter** key to finish the installation. ## Step 4 – Secure phpMyAdmin To secure the phpMyAdmin instance, it is recommended to add the Apache basic authentication in phpMyAdmin. To do so, edit the phpMyAdmin configuration file. ``` nano /etc/apache2/conf-available/phpmyadmin.conf ``` Find the following line: ``` DirectoryIndex index.php ``` Add the following line after the above line: ``` AllowOverride All ``` Save and close the file, then create a .htaccess file. ``` nano /usr/share/phpmyadmin/.htaccess ``` Add the following lines. ``` AuthType Basic AuthName "Restricted Access" AuthUserFile /etc/phpmyadmin/.htpasswd Require valid-user ``` Save and close the file, then create a user and set a password. ``` htpasswd -c /etc/phpmyadmin/.htpasswd user1 ``` Set a password as shown below. ``` New password: Re-type new password: Adding password for user user1 ``` Save and close the file, then reload the Apache service to apply the changes. ``` systemctl reload apache2 ``` ## Step 5 – Access phpMyAdmin Web UI Now, open your web browser and access the phpMyAdmin interface using the URL **http://your-server-ip/phpmyadmin.** You will be asked for the username and password specified in the .htaccess file. ![phpmyadmin login](https://www.atlantic.net/wp-content/uploads/2023/10/p3-2.png) Type your username and password and click on **Sign in.** You will see the phpMyAdmin login page. ![phpmyadmin main login](https://www.atlantic.net/wp-content/uploads/2023/10/p4-2.png) Provide your MySQL root username and password and click on **Go.** You will see the phpMyAdmin dashboard on the following page. ![phpmyadmin dashboard](https://www.atlantic.net/wp-content/uploads/2023/10/p5.png) ## Conclusion In this post, we explained how to install phpMyAdmin on Ubuntu 22.04. We also showed you how to secure the phpMyAdmin instance with the Apache authentication method. You can now deploy the phpMyAdmin in the production environment and start managing your databases via a web-based interface. Try to deploy phpMyAdmin on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # On-the-Go Connectivity: Cloud-Based Tools for Hiking Navigation Apps > URL: https://www.atlantic.net/vps-hosting/on-the-go-connectivity-cloud-based-tools-for-hiking-navigation-apps/ | Published: 2024-01-18 | Updated: 2025-09-11 | Author: Alexander Wise Outdoor enthusiasts are increasingly turning to navigation apps to enhance their trail experiences. These applications leverage cloud-based tools to provide real-time information, improve route planning, and offer interactive features for hikers. Integrating cloud-based tools into navigation apps revolutionizes how we explore the great outdoors. ## Real-time mapping and GPS accuracy One of the primary benefits of cloud-based tools in hiking navigation apps is the ability to access [real-time mapping and GPS data](https://telematica.com.au/real-time-tracking-map/). Traditional navigation apps rely solely on pre-loaded maps, limiting their accuracy and usefulness in remote or dynamically changing environments. Cloud-based solutions, on the other hand, enable hikers to receive up-to-date information about trail conditions, weather, and potential hazards. With real-time GPS accuracy, hikers can precisely track their location, ensuring they stay on the right path. Cloud connectivity allows apps to constantly update maps and adapt to changes in the landscape, providing users with the most current information available. This ensures a safer and more reliable hiking experience, especially in unfamiliar terrain. ## Dynamic route planning Cloud-based tools empower hiking navigation apps to offer dynamic route planning features. Hikers can input their preferences, such as distance, difficulty level, and points of interest, and the app can generate a customized [Walking Holidays Italy](https://bookatrekking.com/en/blog/walking-holidays-italy/) route in real-time. This adaptability is particularly useful when unexpected obstacles or changes in weather conditions require a shift in the planned route. Additionally, crowd-sourced data from other hikers can be integrated into the cloud, allowing the app to recommend popular routes, highlight scenic spots, and warn users about potential challenges. This collaborative approach to route planning enhances the overall hiking experience and encourages a sense of community among outdoor enthusiasts. ## Offline accessibility While cloud-based tools excel in providing real-time information, hiking navigation apps also recognize the importance of offline accessibility. Many outdoor adventures take place in areas with limited or no internet connectivity. To address this, navigation apps with cloud integration allow users to download maps and data for offline use. Hikers can preload maps onto their devices before embarking on a journey, ensuring access to crucial information even when disconnected from the internet. This offline capability enhances the reliability of navigation apps, making them suitable for a wide range of outdoor environments, from dense forests to remote mountain ranges. ## Community engagement and sharing Cloud connectivity fosters a sense of community among hikers. Navigation apps can incorporate social features that enable users to share their experiences, discoveries, and tips with the hiking community. This enhances the outdoor experience and creates a knowledge exchange and camaraderie platform. Hikers can upload photos, write reviews, and provide real-time updates about trail conditions. Cloud-based tools facilitate the seamless sharing of information, creating a vibrant community that supports and inspires fellow outdoor enthusiasts. This social aspect adds a new dimension to hiking navigation apps, transforming them into shared knowledge and adventure hubs. ## Examples of hiking navigation apps Here are great examples of hiking navigation apps that [Bookatrekking.com](https://bookatrekking.com/), a leading hiking company, recommends. ### OsmAnd It is one of the most popular applications among travelers. These are maps with convenient navigation that can work offline. There are quite a lot of settings. At first, it is confusing, but if you figure it out, you can find everything you need. Among the advantages are the walking routes, which you can’t find on any map, and the higher level of detail. The app also integrates information from Wikipedia so people can learn more about the objects they see on their way. ### AlpineQuest It is another helpful app that will keep you on your route. The developers have collected hundreds of maps from different suppliers for all regions of our planet. This allows travelers to use several maps in parallel and check the route by them. The application also has support for offline maps and the ability to save a cache of a given region. The digital terrain model allows you to display its topography, hills, and steep slopes. ### Mapy.cz It has marked routes and actual markings on the terrain. This application was developed in the Czech Republic, so many people call it indispensable in the European mountains. From the drawbacks, users would like more detailed information about the streams and lakes found on the route and their names. ### Traseo Traseo is a Polish mobile application with tourist maps that emphasizes the social component. Here, people can share their routes and exchange them with other users. You will find quite a few good ideas based on your expectations and on different parameters: terrain, duration, difficulty, and so on. ## Conclusion On-the-go connectivity powered by cloud-based tools has ushered in a new era for hiking navigation apps. Integrating real-time mapping, dynamic route planning, offline accessibility, and community engagement has elevated these apps into indispensable tools for outdoor enthusiasts. As technology advances, the marriage of cloud-based tools and hiking navigation apps is set to redefine how we connect with and explore the natural world. --- # How to Install GitLab CE on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-gitlab-ce-on-ubuntu-24-04/ | Published: 2024-01-19 | Updated: 2025-05-23 | Author: Hitesh Jethva GitLab is a repository manager and DevOps platform that allows developers to build and deliver secure software quickly. It offers tools to automate the development process – from building, to testing, to deployment. It has version control and issue tracking capability to manage source code changes and monitor issues, bugs, and feature requests. If you are looking for an all-in-one DevOps platform, then GitLab is the best choice for you. ## Step 1 – Install GitLab CE First, install the necessary dependencies using the following command. ``` apt install ca-certificates postfix -y ``` Next, add the GitLab CE repository with the following command. ``` curl -sS https://packages.gitlab.com/install/repositories/gitlab/gitlab-ce/script.deb.sh | bash ``` Next, install GitLab CE using the following command. ``` apt install gitlab-ce -y ``` Once GitLab CE is installed, you will see the following output. ``` It looks like GitLab has not been configured yet; skipping the upgrade script. *. *. *** *** ***** ***** .****** ******* ******** ******** ,,,,,,,,,***********,,,,,,,,, ,,,,,,,,,,,*********,,,,,,,,,,, .,,,,,,,,,,,*******,,,,,,,,,,,, ,,,,,,,,,*****,,,,,,,,,. ,,,,,,,****,,,,,, .,,,***,,,, ,*,. _______ __ __ __ / ____(_) /_/ / ____ _/ /_ / / __/ / __/ / / __ `/ __ \ / /_/ / / /_/ /___/ /_/ / /_/ / \____/_/\__/_____/\__,_/_.___/ Thank you for installing GitLab! GitLab was unable to detect a valid hostname for your instance. Please configure a URL for your GitLab instance by setting `external_url` configuration in /etc/gitlab/gitlab.rb file. Then, you can start your GitLab instance by running the following command: sudo gitlab-ctl reconfigure ``` ## Step 2 – Configure GitLab CE GitLab stores configuration information in GitLab.rb file. You will need to edit it and change the URL that points to your domain name. ``` nano /etc/gitlab/gitlab.rb ``` Change the following line with your domain name. ``` external_url 'http://gitlab.linuxbuz.com' ``` Save and close the file, then reconfigure GitLab to apply the changes. ``` gitlab-ctl reconfigure ``` Next, fetch the GitLab root password with the following command. ``` cat /etc/gitlab/initial_root_password ``` Output. ``` # 1. If provided manually (either via `GITLAB_ROOT_PASSWORD` environment variable or via `gitlab_rails['initial_root_password']` setting in `gitlab.rb`, it was provided before database was seeded for the first time (usually, the first reconfigure run). # 2. Password hasn't been changed manually, either via UI or via command line. # # If the password shown here doesn't work, you must reset the admin password following https://docs.gitlab.com/ee/security/reset_user_password.html#reset-your-root-password. Password: PrgBSc61QdgKtjyrfZPLVGLcUzCW5svzvIIGX9sNFeo= # NOTE: This file will be automatically deleted in the first reconfigure run after 24 hours. ``` ## Step 3 – Access GitLab CE Now, open your web browser and access the GitLab web interface using the URL **http://gitlab.linuxbuz.com.** You will see the GitLab login page. ![GitLab login page](https://www.atlantic.net/wp-content/uploads/2023/10/p1-8.png) Provide your GitLab username and password and click on the **Sign in** button. You will see the GitLab dashboard on the following screen. ![GitLab dashboard page](https://www.atlantic.net/wp-content/uploads/2023/10/p2-5.png) ## Step 4 – Enable SSL on GitLab For security reasons, it is always recommended to secure the GitLab instance with Let’s Encrypt SSL. To do so, edit the GitLab configuration file. ``` nano /etc/gitlab/gitlab.rb ``` Change the following lines. ``` external_url 'https://gitlab.linuxbuz.com' letsencrypt['enable'] = true letsencrypt['contact_emails'] = ['hitjethva@gmail.com'] letsencrypt['auto_renew'] = true letsencrypt['auto_renew_hour'] = 3 letsencrypt['auto_renew_day_of_month'] = "*/7" ``` Save and close the file, then reconfigure the GitLab to reload the changes. ``` gitlab-ctl reconfigure ``` Next, verify the GitLab status using the following command. ``` gitlab-ctl status ``` Output. ``` down: alertmanager: 0s, normally up, want up; run: log: (pid 133174) 4865s run: crond: (pid 136477) 4453s; run: log: (pid 135800) 4532s run: gitaly: (pid 133575) 4817s; run: log: (pid 132705) 5036s run: gitlab-exporter: (pid 133567) 4817s; run: log: (pid 133095) 4882s run: gitlab-kas: (pid 136429) 4455s; run: log: (pid 132893) 5016s run: gitlab-workhorse: (pid 133541) 4818s; run: log: (pid 133011) 4902s run: logrotate: (pid 155175) 1451s; run: log: (pid 132626) 5050s run: nginx: (pid 136437) 4455s; run: log: (pid 133030) 4896s run: node-exporter: (pid 133553) 4818s; run: log: (pid 133072) 4888s run: postgres-exporter: (pid 133846) 4784s; run: log: (pid 133224) 4860s run: postgresql: (pid 132748) 5028s; run: log: (pid 132763) 5024s run: prometheus: (pid 133594) 4816s; run: log: (pid 133145) 4870s run: puma: (pid 136086) 4504s; run: log: (pid 132958) 4912s run: redis: (pid 132660) 5045s; run: log: (pid 132670) 5042s run: redis-exporter: (pid 133569) 4817s; run: log: (pid 133120) 4876s run: registry: (pid 136444) 4454s; run: log: (pid 135880) 4526s run: sidekiq: (pid 136019) 4510s; run: log: (pid 132977) 4907s ``` You can now access the GitLab securely using the URL **https://gitlab.linuxbuz.com.** ## Conclusion In this tutorial, we explained how to install GitLab CE on Ubuntu 24.04. We also showed how to secure GitLab with Let’s Encrypt SSL. You can now create your first DevOps project on GitLab and automate your deployment process via a web-based interface. Try to set up a CI/CD pipeline with GitLab on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Joomla on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-joomla-on-ubuntu-24-04/ | Published: 2024-01-22 | Updated: 2025-05-22 | Author: Hitesh Jethva Joomla is a free and open-source content management system written in PHP. It is used for hosting and managing websites and online applications. Due to its flexibility, extensibility, and ease of use, it has become a popular choice for individuals, businesses, and organizations to build and maintain websites. Joomla provides an intuitive and user-friendly administrative interface that makes it relatively easy for non-technical users to create and manage website content. ## Step 1 – Install LAMP Server First, you must install Apache, MySQL, PHP, and other packages on your server. You can install all of them using the following command. ``` apt install apache2 mysql-server php libapache2-mod-php php-dev php-bcmath php-intl php-soap php-zip php-curl php-mbstring php-mysql php-gd php-xml unzip -y ``` After the successful installation, start and enable Apache service with the following command. ``` systemctl start apache2 systemctl enable apache2 ``` ## Step 2 – Create a Database Joomla uses MySQL as a database backend, so you will need to create a database and user for Joomla. First, connect to the MySQL shell. ``` mysql ``` Next, create a database and user for Joomla. ``` mysql> CREATE DATABASE joomla; mysql> CREATE USER 'joomla'@'localhost' IDENTIFIED BY 'securepassword'; ``` Then, grant all the privileges on the Joomla database. ``` mysql> GRANT ALL ON joomla.* TO 'joomla'@'localhost'; ``` Next, flush the privileges and exit from the MySQL shell. ``` mysql> FLUSH PRIVILEGES; mysql> EXIT; ``` ## Step 3 – Install Joomla CMS First, visit the Joomla official website and download the latest version of Joomla using the wget command. ``` wget https://downloads.joomla.org/cms/joomla5/5-3-0/Joomla_5-3-0-Stable-Full_Package.zip ``` Once the download is finished, unzip the downloaded file to the Apache web root directory. ``` unzip Joomla_5-3-0-Stable-Full_Package.zip -d /var/www/html/joomla ``` Next, change the ownership and permissions of the Joomla directory. ``` chown -R www-data:www-data /var/www/html/joomla/ chmod -R 755 /var/www/html/joomla/ ``` ## Step 4 – Configure Apache for Joomla Next, create an Apache virtual host configuration file for Joomla. ``` nano /etc/apache2/sites-available/joomla.conf ``` Add the following configurations. ``` ServerAdmin webmaster@example.com ServerName joomla.example.com DocumentRoot /var/www/html/joomla Options FollowSymlinks AllowOverride All Require all granted ErrorLog ${APACHE_LOG_DIR}/example.com_error.log CustomLog ${APACHE_LOG_DIR}/example.com_access.log combined ``` Save and close the file, then activate the Joomla virtual host with the following command. ``` a2ensite joomla.conf ``` Finally, restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` ## Step 5 – Access Joomla CMS Now, open your web browser and access the Joomla CMS using the URL **http://joomla.example.com.** You will see the language selection page. ![](https://www.atlantic.net/wp-content/uploads/2024/01/j1.png)   Select your language and click on the **Setup Login Data.** You will see the following page.   ![](https://www.atlantic.net/wp-content/uploads/2024/01/j2.png) Define your admin username and password and click on the **Setup Database Connection.** You will see the following page.   ![](https://www.atlantic.net/wp-content/uploads/2024/01/j3.png) Provide your database settings and click on the **Install Joomla** button. Once the Joomla is installed, you will see the following page.   ![](https://www.atlantic.net/wp-content/uploads/2024/01/j4.png) Click on the **Open Administrator.** You will see the Joomla login page.   ![](https://www.atlantic.net/wp-content/uploads/2024/01/j5.png) Provide your admin username and password, and click on the **login** button. You will see the Joomla Dashboard on the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/01/j6.png)   ## Conclusion In this tutorial, you learned how to install Joomla with Apache on the Ubuntu 24.04 server. You can now explore Joomla features and start creating your website from the Joomla dashboard. You can now build your website using Joomla CMS on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # EHR HIPAA: Top 10 EHR Solutions in 2026 > URL: https://www.atlantic.net/hipaa-compliant-hosting/top-10-hipaa-compliant-ehr-solutions/ | Published: 2024-01-23 | Updated: 2026-02-20 | Author: Richard Bailey The transition from paper records to electronic health records (EHR) has changed how healthcare providers manage patient information. Such a shift is governed by the Health Insurance Portability and Accountability Act (HIPAA), a federal law that establishes standards for protecting sensitive information. For healthcare organizations, maintaining EHR HIPAA-compliant status is a legal requirement and a fundamental part of patient trust. It involves the protection of ePHI (electronic Protected Health Information), which refers to any PHI that is covered under the HIPAA Security Rule and is produced, saved, transferred, or received in an electronic form. Safeguarding confidential patient information is essential to maintain privacy, prevent security breaches, and comply with HIPAA regulations. ## What Is the Health Insurance Portability and Accountability Act (HIPAA)? HIPAA compliance is a [vast subject](https://www.atlantic.net/?s=HIPAA&post_type%5B%5D=), but the principal idea is that all forms of digital patient data access are regulated. Business associates and covered entities must protect patient records as per HIPAA rules. Electronic health records are subject to stringent HIPAA rules and regulations. This includes adherence to the HIPAA Privacy and Security Rules of 2003. Several key rules relate directly to Electronic Health Records, such as: - Covered Entities must only disclose ePHI when authorized by the patient or in the event of [exceptional circumstances](https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html#:~:text=Covered%20entities%20may%20disclose%20protected,the%20target%20of%20the%20threat).). - The patient must be able to view their individually identifiable health information; if necessary, they have the right to request the data be updated, amended, or redacted. - All access requests and disclosures of ePHI from the EHR system must be auditable. - The EHR System is bound by HIPAA Technical Safeguards, including access controls, encryption, auditing, and data integrity controls. - The EHR System is bound by HIPAA Physical Safeguards, including controlled access to data centers and medical record facilities, staff training, and risk assessments. - The EHR System is bound by HIPAA Administrative Safeguards, such as security policies and procedures, plus remediation activities. ### Protected Health Information And Patient Data Protected health information includes any information in a medical record that can be used to identify an individual, including Social Security numbers, home address, insurance information, and demographic information. It also covers any medical information created, used, or disclosed in the course of providing a healthcare service. Healthcare organizations must handle data with care to avoid HIPAA violations. Willful neglect of these rules can lead to substantial fines and legal action by the HHS Office for Civil Rights. Beyond federal law, many state laws also provide additional protections for sensitive information. ## What Is an EHR Solution? An EHR solution is an electronic media software program designed to create and manage a patient’s complete medical history in a digital format. It goes beyond simply storing data; most provide standard tools and features that include: - **Clinical documentation:** Documenting patient encounters, diagnoses, procedures, medications, and allergies. - **Ordering and reviewing diagnostic tests:** Integrating with lab systems and imaging devices for smooth test requests and result viewing. - **Prescribing medications:** Sending electronic prescriptions directly to pharmacies, reducing errors and delays. - **Patient engagement:** Online access to records, appointments, and educational resources. - **Reporting and analytics:** Generating reports on practice performance, population health, and quality measures. Choosing the right EHR solution for your practice requires careful consideration of your specific needs and budget. For this reason, we have compiled our**Top 10 HIPAA-Compliant EHR Solutions** to help your healthcare organization achieve HIPAA Compliance. Remember that the software is only part of the solution; the [cloud infrastructure](https://www.atlantic.net/hipaa-compliant-hosting/) you use to operate the EHR system must also be HIPAA-compliant. ### Electronic Medical Records vs. Electronic Health Records While people often use the terms interchangeably, electronic medical records (EMR) and electronic health records (EHR) have a few distinct differences. - **Electronic medical records** are digital versions of the paper records in a single practice. They contain the medical and treatment history of the patients within that specific organization. - **Electronic health records** are built to go beyond standard clinical data collected in a provider’s office. They provide a broader view of a patient’s care. Health records are designed to be shared with other healthcare providers, such as laboratories and specialists. Allowing the patient’s medical record to follow them across different healthcare systems improves service delivery and patient safety. ## Technical Requirements For EHR HIPAA-Compliant Systems To protect electronic health records, certain security features are mandatory. Data encryption is one of the most effective ways to prevent security risks. By encrypting data both at rest and in transit (using TLS 1.2 or 1.3), organizations ensure that even if data is intercepted, it remains unreadable. Access controls are another requirement. Healthcare professionals should only have access to the specific patient records necessary for their job functions. Typically managed through unique user identification and automatic log-offs. Additionally, audit controls must be in place to record and examine activity in healthcare systems. These logs help identify any unauthorized attempts to access private information. ### The Role Of Covered Entities and Business Associates Organizations are classified as either covered entities or business associates. Covered entities include healthcare providers, health plans, and healthcare clearinghouses. These organizations are directly responsible for protecting patient information. Business associates are third-party vendors that provide services to covered entities, including EHR software companies and data storage providers. When a provider uses an EHR system, the software vendor acts as a business associate. A written contract, known as a HIPAA Business Associate Agreement (BAA), is required to ensure the vendor remains responsible for maintaining HIPAA-compliant status while handling sensitive information. All subsequent interactions are governed by this BAA. ### BAAs BAAs (BAAs) are a cornerstone of HIPAA compliance for healthcare providers, health plans, and other covered entities. These legally binding contracts define the responsibilities of business associates—such as vendors, contractors, and service providers—who handle, store, or process patient data on behalf of covered entities. A BAA requires business associates to implement stringent security measures to protect patient data and to comply with all relevant HIPAA regulations. This includes ensuring the confidentiality, integrity, and availability of health information throughout its lifecycle, whether in data storage, transmission, or processing. By establishing clear expectations and accountability, BAAs help healthcare organizations and their partners work together to safeguard sensitive health information and maintain compliance with federal law. ## Top 10 HIPAA-Compliant EHR Solutions For 2026 Choosing the right EHR system is a major decision for any practice. The following solutions are recognized for helping healthcare organizations maintain compliance while improving patient engagement in 2026. ### 1. Epic Systems ### ![](https://www.atlantic.net/wp-content/uploads/2024/01/Epic-Systems-Logo.png) Epic Systems is a market leader, particularly among large-scale healthcare organizations, academic medical centers, and multi-specialty hospital groups. The platform is renowned for its deep integration capabilities, allowing different departments to share patient data instantly while maintaining strict adherence to the HIPAA Security Rule. Because Epic handles massive volumes of ePHI, it employs some of the most advanced encryption and identity management protocols in the industry. - **Interoperability and Care Coordination:** Epic’s “Care Everywhere” network allows for the secure exchange of patient records with other organizations, ensuring that clinicians have a complete medical history regardless of where the patient was previously treated. - **Patient Engagement via MyChart:** A complete patient portal allows individuals to view test results, message their providers securely, and manage appointments, all within a HIPAA-compliant framework that protects data in transit using TLS 1.3. ### 2. Ezderm ![](https://www.atlantic.net/wp-content/uploads/2024/01/Ezderm_Logo.jpg) [Ezderm](https://www.ezderm.com/products/electronic-health-records) is the leading dermatology-first software platform, founded by a practicing dermatologist and engineered by specialists who understand the nuances of real dermatology workflows. Trusted by thousands of providers nationwide, Ezderm delivers a unified, silo-free system that includes EHR, practice management, revenue cycle management, patient engagement tools, and integrated payments. With every team working from the same real-time data, practices minimize errors, streamline operations, and improve both clinical and administrative efficiency. Security and data integrity are built directly into the platform’s architecture, including role-based permissions and oversight features such as complete audit logs. - **HIPAA-Ready Audit Trails:** Ezderm’s automated audit log captures and timestamps all critical system activity—edits, additions, deletions, and more—providing practices with clear, defensible documentation for HIPAA compliance and audit requirements. - **Purpose-Built for Dermatology:** Ezderm simplifies charting with specialized workflows for Mohs surgery, isotretinoin management, cosmetic procedures, malignancy tracking, biopsies, and more. Its proprietary 3D Anatomical Body Map allows clinicians to record lesion size and location with pinpoint precision, helping streamline documentation, follow-ups, and coding accuracy. ### 3. Oracle Cerner ### ![](https://www.atlantic.net/wp-content/uploads/2024/01/Oracle_Cerner_logo.png) Oracle Cerner provides a versatile electronic health platform that scales effectively from small, independent clinics to massive, global hospital networks. Following its acquisition by Oracle, the platform has gained enhanced cloud infrastructure capabilities, focusing on data-driven clinical outcomes. Cerner’s architecture is built to minimize security risks by automating many of the technical safeguards required for HIPAA-compliant data storage. - **Advanced Data Analytics:** The platform integrates clinical intelligence tools that help providers identify health trends and potential risks within their patient population while maintaining the anonymity and security of PHI. - **reliable Audit Logging:** Cerner provides detailed, automated audit trails that record every instance of data access or modification, helping organizations stay prepared for HIPAA audits and internal security reviews. ### 4. Athenahealth ### ![](https://www.atlantic.net/wp-content/uploads/2024/01/athenahealth-logo-png_seeklogo-507094.png) Athenahealth offers a cloud-native EHR system that is specifically designed to reduce the administrative burden on medical professionals. By combining clinical records with revenue cycle management and patient engagement tools, Athenahealth creates a unified environment for practice growth. Their cloud-based model ensures that security patches and HIPAA updates are applied universally and instantly across all user accounts. - **Integrated Revenue Cycle Management:** The software streamlines the billing process by linking clinical documentation directly to insurance claims, reducing coding errors while ensuring that financial data remains as secure as medical records. - **Mobile-First Provider Experience:** AthenaOne allows clinicians to document patient encounters, review charts, and manage orders from mobile devices, utilizing encrypted connections to prevent data leaks over public or private networks. ### 5. NextGen Healthcare ### ![](https://www.atlantic.net/wp-content/uploads/2024/01/NG_Logo_1024x768.png) NextGen Healthcare focuses on the specific needs of ambulatory and specialty practices. Their solution is highly customizable, allowing doctors to tailor their clinical workflows to match their specific medical field. NextGen emphasizes the importance of the patient-provider relationship by offering tools that facilitate secure communication and transparent access to health information. - **Specialty-Specific Content:** Unlike generic EHRs, NextGen provides pre-configured templates for over 25 different medical specialties, ensuring that clinicians can document care efficiently and accurately. - **Patient Consent Management:** The platform includes built-in tools for capturing and storing patient consent forms electronically, ensuring that ePHI is shared only in accordance with the HIPAA Privacy Rule and patient preferences. ### 6. eClinicalWorks ### ![](https://www.atlantic.net/wp-content/uploads/2024/01/ECW-healow-01b.png) As one of the most widely used EHR solutions in the United States, eClinicalWorks provides a complete platform that covers everything from clinical documentation to population health. The system is designed to be a “one-stop shop” for practice management, offering integrated telehealth features that became essential in the post-pandemic era and remain vital in 2026. - **Healow Telehealth Integration:** built-in features allows for secure, high-definition video consultations that are fully HIPAA-compliant, ensuring that remote care sessions are protected by the same encryption standards as in-office visits. - **AI-Driven Documentation:** The platform utilizes voice-recognition and AI-assisted scribing to help providers document encounters faster, allowing them to spend more time with patients without compromising the accuracy of the medical record. ### 7. Allscripts (Veradigm) ### ![](https://www.atlantic.net/wp-content/uploads/2024/01/Allscripts-Logo.jpg) Veradigm, formerly known as Allscripts, provides a sophisticated ecosystem of healthcare data and technology. Their EHR solutions are built with a focus on open architecture, allowing for easier integration with third-party diagnostic tools and labs. Veradigm places a heavy emphasis on mitigating the security risks associated with data exchange across different healthcare platforms. - **Open Connected Ecosystem:** By supporting industry-standard APIs, Veradigm allows practices to connect their EHR to a wide variety of specialized health apps while maintaining a secure, HIPAA-compliant core. - **Clinical Decision Support:** The system provides real-time alerts and evidence-based suggestions during the documentation process, helping to improve patient safety and ensure adherence to the latest clinical guidelines. ### 8. Practice Fusion ### ![](https://www.atlantic.net/wp-content/uploads/2024/01/practicefusion.png) Practice Fusion is a web-based EHR solution that has become a staple for independent practices and smaller clinics that require a straightforward, easy-to-implement system. Despite its streamlined interface, Practice Fusion does not compromise on security, providing all the necessary features to help small providers meet the requirements of the Health Insurance Portability and Accountability Act. - **Simplified E-Prescribing:** The platform allows providers to send prescriptions directly to pharmacies securely, reducing the risk of errors and ensuring that medication history is automatically updated in the patient’s record. - **Lab and Imaging Integration:** Practice Fusion connects with over 500 lab and imaging partners, allowing results to be delivered directly into the patient chart, which speeds up diagnosis and treatment planning. ### 9. DrChrono ### ![](https://www.atlantic.net/wp-content/uploads/2024/01/Partner_Logos_DrChrono.png) DrChrono is recognized for its mobile-first philosophy, having been one of the first EHRs built specifically for use on iPads and iPhones, making it an ideal choice for providers who are constantly on the move or who prefer a more tactile, tablet-based approach to patient care. The platform’s security architecture is specifically hardened for mobile data transmission. - **Customizable Medical Forms:** Providers can build their own digital forms and templates from scratch, ensuring that the data they collect is perfectly suited to their unique clinical needs. - **Billing and RCM Automation:** DrChrono includes automated billing features that track claims from submission to payment, providing practice managers with real-time visibility into the financial health of the organization. ### 10. Tebra (PatientPop) ### ![](https://www.atlantic.net/wp-content/uploads/2024/01/Tebra_-_primary_logo_-_growth_-_RGB.jpg) Tebra, the result of a merger between PatientPop and Kareo, provides an integrated “practice success” platform. It combines the clinical strength of a HIPAA-compliant EHR with the growth tools needed to attract and retain patients in a competitive market. Tebra emphasizes building patient trust by securing sensitive information from the very first digital interaction. - **Digital Front Door:** This feature manages the entire patient journey, from the initial online search and self-scheduling to the final bill payment, ensuring a smooth and secure experience for the patient. - **Secure Messaging and Payments:** Tebra provides an encrypted channel for all patient interactions, ensuring that everything from clinical questions to credit card information is handled within a secure, compliant environment. ## Why Atlantic.Net Is Your HIPAA-Compliant Hosting Partner At Atlantic.Net, we provide the reliable infrastructure necessary to host these complex EHR systems. We are HIPAA-compliant, and we offer a fully executed BAA to ensure your organization meets all federal requirements. Our hosting environment utilizes encryption for data in transit, and we provide the physical and administrative safeguards required by the Security Rule. By partnering with us, you can focus on patient care while we manage the underlying security of your ePHI. ### Managing Security Risks In Electronic Health While EHR software provides many benefits, it also introduces specific security risks. Cyberattacks targeting healthcare organizations are on the rise. To protect against these threats, organizations must conduct regular risk assessments that involve identifying potential vulnerabilities in how they collect, store, and transmit PHI. Data storage is a primary area of concern. Whether using on-site servers or cloud-based healthcare systems, the physical and technical security of the data must be verified. Encryption and multi-factor authentication are essential tools for preventing unauthorized access to medical records. ### Patient Consent And Engagement The HIPAA Privacy Rule gives patients control over their medical information. Patients must provide patient consent before their information is shared for purposes other than treatment, payment, or healthcare operations. Modern EHR systems enable patients to access their own records through patient portals. Transparency improves patient engagement and allows patients to take a more active role in their own healthcare. When patients use these portals, the provider is responsible for ensuring the connection is secure. Providing patients with access to their medical history and treatment plans creates a stronger relationship between the provider and the organization. ### Benefits of HIPAA Compliance Achieving and maintaining HIPAA compliance brings significant advantages to healthcare organizations. By prioritizing the security and confidentiality of patient information, healthcare providers can help patients trust and confidence in their services. reliable HIPAA compliance measures also enhance patient safety by reducing the risk of unauthorized access or data breaches, ensuring that health information remains accurate and protected. Compliance with HIPAA regulations helps organizations avoid costly fines and legal consequences, while strengthening their reputation within the healthcare industry. Effective HIPAA compliance also streamlines the secure exchange of health information between providers, patients, and other stakeholders, ultimately improving the quality, efficiency, and coordination of healthcare services. ### Challenges of HIPAA Compliance Despite its clear benefits, HIPAA compliance presents ongoing challenges for healthcare organizations. The complexity of HIPAA regulations requires continuous education and training for staff to ensure proper handling of patient data. As electronic health records and health information technology become more prevalent, organizations must address new security risks, such as cyber threats and potential data breaches. Ensuring that all business associates and vendors adhere to HIPAA standards adds another layer of complexity, demanding diligent oversight and regular assessments. Healthcare organizations must invest in advanced security measures, conduct frequent audits, and stay updated on regulatory changes to protect health records and maintain compliance. By proactively addressing these challenges, organizations can better safeguard patient data and uphold the highest standards of healthcare security. ### The Impact Of HIPAA Violations Failure to follow HIPAA rules can have devastating consequences for healthcare providers. The HHS Office for Civil Rights is responsible for enforcing these regulations. Violations are often categorized by the level of negligence involved. Cases of willful neglect carry the highest penalties. Beyond financial fines, HIPAA violations damage patient trust. When sensitive information or Social Security numbers are compromised, patients may feel their safety is at risk. Maintaining compliance is not just about avoiding federal law penalties; it is about protecting the people the practice serves. ### Best Practices For Health Information Technology To maintain a secure environment, healthcare organizations should follow several best practices: - **Employee Training**: All healthcare professionals and administrative staff must receive regular training on HIPAA rules and the proper handling of protected health information. - **BAAs**: Ensure that every vendor who has access to electronic PHI has signed a complete BAA. - **Regular Audits**: Use the audit features in your EHR system to monitor who is accessing patient records and why. - **Updated Security Software**: Keep all healthcare systems and electronic media updated with the latest security patches. - **Secure Communication**: Only use secure, encrypted channels to transmit PHI to other healthcare providers or health plans. ### The Future Of Electronic Health Records As health information technology continues to advance, the way we handle health records will change. The focus will remain on improving service delivery while protecting confidentiality. New developments in data encryption and secure data exchange will allow for even better coordination between healthcare systems. By choosing a reputable EHR HIPAA-compliant solution and staying diligent about security, healthcare providers can ensure they are meeting their legal obligations. The goal is to create a system where electronic health records support better clinical outcomes without compromising the privacy of the patient. ## Final Considerations for Healthcare Providers The transition to electronic health records is a central component of modern healthcare. It allows for more efficient management of medical history and treatment plans. However, efficiency must be balanced with a commitment to HIPAA compliance. Whether you are a small practice or a large organization, the responsibility to protect patient data is the same. By understanding the HIPAA Security Rule and the HIPAA Privacy Rule, you can navigate the requirements of the act. Choosing the right EHR software and maintaining a culture of security will protect your organization from HIPAA violations and ensure that patient trust remains high. Protecting sensitive information like Social Security numbers and demographic information is a continuous process. It requires ongoing monitoring of security risks and a commitment to following federal law. In doing so, healthcare providers can continue to deliver high-quality care while keeping patient records safe and confidential. --- # How To Set Up GitLab Continuous Integration (CI) Pipelines on Debian 12 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-set-up-gitlab-continuous-integration-ci-pipelines-on-debian-12/ | Published: 2024-01-24 | Updated: 2025-09-05 | Author: Hitesh Jethva In collaborative software development, having a robust version control system is paramount. GitLab, a web-based Git repository manager, provides a comprehensive platform for managing source code repositories, CI/CD pipelines, and collaboration among development teams. In this guide, we will walk through the process of installing GitLab on Debian 12, empowering you to enhance your team’s productivity and code management. ## Step 1 – Add GitLab Repository By default, GitLab is not included in the Debian default repository, so you will need to install it from the GitLab official repository. First, install all the required dependencies using the following command. ``` apt install curl debian-archive-keyring lsb-release ca-certificates apt-transport-https software-properties-common -y ``` Next, run the following script to add the GitLab repository. ``` curl -s https://packages.gitlab.com/install/repositories/gitlab/gitlab-ce/script.deb.sh | bash ``` Now, update the repository with the following command: ``` apt-get update -y ``` ## Step 2 – Install GitLab CE You can install the GitLab CE using the following command. ``` apt install gitlab-ce ``` Once the installation is finished, you will see the following output. ``` It looks like GitLab has not been configured yet; skipping the upgrade script. *. *. *** *** ***** ***** .****** ******* ******** ******** ,,,,,,,,,***********,,,,,,,,, ,,,,,,,,,,,*********,,,,,,,,,,, .,,,,,,,,,,,*******,,,,,,,,,,,, ,,,,,,,,,*****,,,,,,,,,. ,,,,,,,****,,,,,, .,,,***,,,, ,*,. _______ __ __ __ / ____(_) /_/ / ____ _/ /_ / / __/ / __/ / / __ `/ __ \ / /_/ / / /_/ /___/ /_/ / /_/ / \____/_/\__/_____/\__,_/_.___/ Thank you for installing GitLab! GitLab was unable to detect a valid hostname for your instance. Please configure a URL for your GitLab instance by setting `external_url` configuration in /etc/gitlab/gitlab.rb file. Then, you can start your GitLab instance by running the following command: sudo gitlab-ctl reconfigure ``` ## Step 3 – Configure GitLab CE You can edit the GitLab default configuration file with the following command. ``` nano /etc/gitlab/gitlab.rb ``` Define your domain name as shown below: ``` external_url 'http://gitlab.mydomain.com' ``` Save and close the file and reconfigure GitLab using the following command. ``` gitlab-ctl reconfigure ``` You will see the following output. ``` Notes: Default admin account has been configured with following details: Username: root Password: You didn't opt-in to print initial root password to STDOUT. Password stored to /etc/gitlab/initial_root_password. This file will be cleaned up in first reconfigure run after 24 hours. NOTE: Because these credentials might be present in your log files in plain text, it is highly recommended to reset the password following https://docs.gitlab.com/ee/security/reset_user_password.html#reset-your-root-password. gitlab Reconfigured! ``` ## Step 4 – Access GitLab CE Before accessing GitLab, you will need a root password to log into the GitLab interface. You can retrieve the GitLab root password with the following command. ``` cat /etc/gitlab/initial_root_password ``` You will see the following output. ``` # WARNING: This value is valid only in the following conditions # 1. If provided manually (either via `GITLAB_ROOT_PASSWORD` environment variable or via `gitlab_rails['initial_root_password']` setting in `gitlab.rb`, it was provided before database was seeded for the first time (usually, the first reconfigure run). # 2. Password hasn't been changed manually, either via UI or via command line. # # If the password shown here doesn't work, you must reset the admin password following https://docs.gitlab.com/ee/security/reset_user_password.html#reset-your-root-password. Password: 6MRtx/5pk7r7PqF3Ss8+EGu+Ihn8UQT8tt+vyHY/TVg= # NOTE: This file will be automatically deleted in the first reconfigure run after 24 hours. ``` Now, open your web browser and access GitLab CE using the URL **http://gitlab.mydomain.com.** You will see the GitLab login screen. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p1-11.png) Provide your admin username as root and the password from the above output, then click on **Sign In.** You will see the GitLab CE dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p2-8.png) ## Step 5 – Secure GitLab CE with Let’s Encrypt SSL For security reasons, it is always recommended to secure GitLab with SSL. To do so, edit the GitLab configuration file. ``` nano /etc/gitlab/gitlab.rb ``` Define your secure URL and change the following lines: ``` external_url 'https://gitlab.mydomain.com' letsencrypt['enable'] = true letsencrypt['contact_emails'] = ['user@mydomain.com'] letsencrypt['auto_renew'] = true letsencrypt['auto_renew_hour'] = 3 letsencrypt['auto_renew_day_of_month'] = "*/7" ``` Save and close the file, then reconfigure GitLab using the following command. ``` gitlab-ctl reconfigure ``` You can now access GitLab securely using the URL **https://gitlab.mydomain.com.** ## Step 6 – Manage GitLab CE If you want to change the GitLab root password, run the following command. ``` gitlab-rake 'gitlab:password:reset[root]' ``` Define your new password as shown below: ``` Enter password: Confirm password: Password successfully updated for user with username root. ``` To check the status of GitLab, run the following command. ``` gitlab-ctl status ``` To stop GitLab, run the following command. ``` gitlab-ctl stop ``` To restart GitLab, run: ``` gitlab-ctl restart ``` ## Conclusion Congratulations! You have successfully installed GitLab on Debian 12. GitLab provides a powerful and user-friendly version control and collaboration platform, offering features like code repositories, issue tracking, and continuous integration. Explore GitLab further to optimize your team’s workflow and streamline development. You can not implement the CI/CD pipeline using GitLab CE on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Setting Up a Redis Server as a Session Handler for PHP on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/setting-up-a-redis-server-as-a-session-handler-for-php-on-ubuntu-24-04/ | Published: 2024-01-25 | Updated: 2025-05-19 | Author: Hitesh Jethva In web development, efficient session management is crucial for maintaining user state across requests. Redis, a high-performance, in-memory data store, is an excellent choice for handling sessions in PHP applications. Redis offers several advantages when used as a session handler: - In-Memory Storage - Atomic Operations - Expiration Policies - Data Persistence In this guide, we will set up a Redis server as a session handler for PHP on Ubuntu 24.04, ensuring seamless and scalable session management. ## Step 1 – Install Redis Server By default, the Redis package is included in the Ubuntu default repository. You can install it using the following command. ``` apt-get install redis-server -y ``` Once the Redis server is installed, verify the Redis installation using the following command. ``` redis-cli ping ``` You will see the following output. ``` PONG ``` ## Step 2 – Configure Redis Server By default, Redis only allows connections to localhost. You will need to change this configuration to allow connections coming from other servers on the same private network as the Redis server. First, edit the Redis configuration file. ``` nano /etc/redis/redis.conf ``` Change the following line: ``` bind localhost your-server-ip ``` Next, change the following line to secure your Redis with a password: ``` requirepass securepassword ``` Save and close the file, then restart the Redis service to apply the configuration. ``` systemctl restart redis ``` ## Step 3 – Verify Redis Connection and Authentication Now, you will need to test Redis to see if the above configuration works. Run the following command to connect your Redis server. ``` redis-cli -h your-server-ip ``` Next, authenticate Redis with password: ``` AUTH securepassword ``` Now, try to access the data. ``` KEYS * ``` You should see the following output. ``` (empty array) ``` ## Step 4 – Install Apache and Redis Extension Next, you will need to install the Apache and Redis PHP extensions to connect Redis using PHP. You can install them with the following command. ``` apt-get install apache2 libapache2-mod-php php php-redis -y ``` Next, edit the PHP configuration file. ``` nano /etc/php/8.3/apache2/php.ini ``` Define your default session handler and session path: ``` session.save_handler = redis session.save_path = "tcp://your-server-ip:6379?auth=securepassword" ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` ## Step 5 – Verify Redis Session Handling To verify Redis session handling, you will need to create a PHP script to store information on sessions. Let’s create a test.php file. ``` nano /var/www/html/test.php ``` Add the following code: ``` URL: https://www.atlantic.net/dedicated-server-hosting/installing-and-configuring-lamp-on-ubuntu-22-04-with-ansible/ | Published: 2024-01-26 | Updated: 2024-06-04 | Author: Hitesh Jethva Ansible is an open-source automation tool that simplifies configuring and managing servers. It uses simple, human-readable YAML scripts, making them accessible to beginners and seasoned sysadmins. In web development, having a reliable and efficient server setup is crucial. The combination of Linux, Apache, MySQL, and PHP, commonly known as LAMP, forms a powerful stack for hosting dynamic web applications. In this blog post, we will explore installing and configuring a LAMP stack on Ubuntu 22.04 using Ansible, a powerful automation tool. ## Prerequisites - An Ubuntu 22.04 server for Ansible Management Node. - An Ubuntu 22.04 server for Ansible Target Node. - A valid, fully qualified domain name is pointed to the Target node’s IP address. ## Step 1 – Install Ansible on the Management Node By default, the latest version of Ansible is not available in Ubuntu’s default repository, so you will need to add it manually. First, install the required packages using the following command. ``` apt update -y apt install gnupg2 software-properties-common -y ``` Next, add the Ansible repository with the following command. ``` apt-add-repository ppa:ansible/ansible ``` Once the repository is updated, you can install Ansible using the following command. ``` apt install ansible -y ``` ## Step 2 – Setting Up SSH Password Less Authentication Next, you will need to set up SSH passwordless authentication on the Ansible management node to connect to the target node without providing an SSH password. First, generate an SSH key pair using the following command. ``` ssh-keygen -t rsa ``` You will see the following output: ``` Generating public/private rsa key pair. Enter file in which to save the key (/root/.ssh/id_rsa): Enter passphrase (empty for no passphrase): Enter same passphrase again: Your identification has been saved in /root/.ssh/id_rsa Your public key has been saved in /root/.ssh/id_rsa.pub The key fingerprint is: SHA256:5AcJyNZCKPRb9US/wZz/5OWGBE9PcArZj+hd9P9fCuY root@ubuntu22 The key's randomart image is: +---[RSA 3072]----+ |.. +.o...o .o. .| |. o = o.o.+ o..+.| | . o o +. *..o+o| | o o . =+.o+| | . S .o ooo+| | . ..=oo| | o .o=| | o . oo| | E . o| +----[SHA256]-----+ ``` Next, copy the generated key to the target node. ``` ssh-copy-id root@target-server-ip ``` Next, try to SSH into the target server without entering a password: ``` ssh root@target-server-ip ``` You should be able to log in without being prompted for a password. ## Step 3 – Configure Ansible Inventory and Roles Next, you must create an Ansible inventory file and roles on the management machine. First, create a directory for your project. ``` mkdir lamp ``` Next, navigate inside the lamp directory. ``` cd lamp ``` Next, create an inventory file. ``` nano inventory ``` Add the following lines: ``` [lamp-server] target-server-ip ansible_python_interpreter = /usr/bin/python3 ``` **Note:** Replace target-server-ip with your target server IP. Next, create directories to store Ansible variables and other configuration files. ``` mkdir files vars ``` Next, create a variable file inside the vars directory. ``` nano vars/default.yml ``` Define your MySQL root password, Apache user, domain name, and port as shown below: ``` mysql_root_password: "secure-password" app_user: "www-data" http_host: "lamp.example.com" http_conf: "lamp.example.conf" http_port: "80" disable_default: true ``` Then, create an Apache virtual host configuration file. ``` nano files/apache.conf ``` Add the following content: ``` ServerAdmin webmaster@localhost ServerName {{ http_host }} DocumentRoot /var/www/html ErrorLog /var/log/apache2/error.log CustomLog /var/log/apache2/access.log combined Options -Indexes DirectoryIndex index.php index.html index.cgi index.pl index.xhtml index.htm ``` Next, create a info.php file: ``` nano files/info.php ``` Add the following PHP code: ``` ``` Save and close the file when you are done. ## Step 4 – Configure Ansible Playbook Next, you will need to create an Ansible playbook to define all tasks to deploy the LAMP server on the target server. First, create a playbook file: ``` nano playbook.yml ``` Add the following configuration: ``` - hosts: all become: true vars_files: - vars/default.yml tasks: - name: Install prerequisites apt: name={{ item }} update_cache=yes state=latest force_apt_get=yes loop: [ 'aptitude' ] #Apache Configuration - name: Install LAMP Packages apt: name={{ item }} update_cache=yes state=latest loop: [ 'apache2', 'mariadb-server', 'python3-pymysql' 'php', 'mysql-python', 'libapache2-mod-php' ] - name: Create document root file: path: "/var/www/html/" state: directory owner: "{{ app_user }}" mode: '0755' - name: Set up Apache virtualhost template: src: "files/apache.conf" dest: "/etc/apache2/sites-available/{{ http_conf }}" notify: Reload Apache - name: Enable new site shell: /usr/sbin/a2ensite {{ http_conf }} notify: Reload Apache - name: Disable default Apache site shell: /usr/sbin/a2dissite 000-default.conf when: disable_default notify: Reload Apache # MySQL Configuration - name: Sets the root password mysql_user: name: root password: "{{ mysql_root_password }}" login_user: root login_password: "" login_unix_socket: /var/run/mysqld/mysqld.sock - name: Removes all anonymous user accounts mysql_user: name: '' host_all: yes state: absent login_user: root login_password: "{{ mysql_root_password }}" - name: Removes the MySQL test database mysql_db: name: test state: absent login_user: root login_password: "{{ mysql_root_password }}" # PHP Info Page - name: Sets Up PHP Info Page template: src: "files/info.php" dest: "/var/www/html/info.php" handlers: - name: Reload Apache service: name: apache2 state: reloaded - name: Restart Apache service: name: apache2 state: restarted ``` Save and close the file, then run the above playbook using the following command. ``` ansible-playbook -i inventory playbook.yml -u root ``` After the successful playbook execution, you will see the following output: ``` PLAY [all] ************************************************************************************************************************************************************* TASK [Gathering Facts] ************************************************************************************************************************************************* ok: [69.28.84.246] TASK [Install prerequisites] ******************************************************************************************************************************************* ok: [69.28.84.246] => (item=aptitude) TASK [Install LAMP Packages] ******************************************************************************************************************************************* ok: [69.28.84.246] => (item=apache2) changed: [69.28.84.246] => (item=mariadb-server) ok: [69.28.84.246] => (item=php) ok: [69.28.84.246] => (item=python3-pymysql) ok: [69.28.84.246] => (item=php-mysql) ok: [69.28.84.246] => (item=libapache2-mod-php) TASK [Create document root] ******************************************************************************************************************************************** ok: [69.28.84.246] TASK [Set up Apache virtualhost] *************************************************************************************************************************************** ok: [69.28.84.246] TASK [Enable new site] ************************************************************************************************************************************************* changed: [69.28.84.246] TASK [Disable default Apache site] ************************************************************************************************************************************* changed: [69.28.84.246] TASK [Sets the root password] ****************************************************************************************************************************************** [WARNING]: Option column_case_sensitive is not provided. The default is now false, so the column's name will be uppercased. The default will be changed to true in community.mysql 4.0.0. changed: [69.28.84.246] TASK [Removes all anonymous user accounts] ***************************************************************************************************************************** ok: [69.28.84.246] TASK [Removes the MySQL test database] ********************************************************************************************************************************* ok: [69.28.84.246] TASK [Sets Up PHP Info Page] ******************************************************************************************************************************************* ok: [69.28.84.246] RUNNING HANDLER [Reload Apache] **************************************************************************************************************************************** changed: [69.28.84.246] PLAY RECAP ************************************************************************************************************************************************************* 69.28.84.246 : ok=12 changed=5 unreachable=0 failed=0 skipped=0 rescued=0 ignored=0 ``` ## Step 5 – Verify LAMP Deployment At this point, the LAMP server is deployed on the target server. You can now verify it using the URL **http://lamp.example.com/info.php.** You will see the output of info.php on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p1-9.png) ## Conclusion Congratulations! You’ve successfully installed and configured a LAMP stack on Ubuntu 22.04 using Ansible. Automating the setup process with Ansible saves time and ensures consistency across multiple servers. As you continue exploring Ansible, you can adapt and expand your playbooks to suit the specific requirements of your web applications. This automation approach empowers developers to focus more on coding and less on manual server configurations. You can now use Ansible to automate LAMP server deployment on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Creating a Django App with Database Connection > URL: https://www.atlantic.net/dedicated-server-hosting/creating-a-django-app-with-database-connection/ | Published: 2024-01-26 | Author: Hitesh Jethva Django is a high-level, open-source web framework in Python that encourages rapid development and clean, pragmatic design. It follows the model-view-controller (MVC) architectural pattern, but it is commonly called the model-view-template (MVT) pattern in Django. Django’s primary goal is to make it easier for developers to build web applications by providing tools and conventions for everyday tasks. In this blog post, we’ll guide you through creating a Django app with a database connection. ## Step 1 – Install Python Django is a Python-based application framework, so you will need to install Python and other required dependencies on your server. You can install all of them with the following command. ``` apt install -y python3 python3-pip build-essential libssl-dev libffi-dev python3-dev python3-venv pkg-config ``` Once all the packages are installed, you can proceed to the next step. ## Step 2 – Install and Configure MySQL Next, install the MySQL server and other dependencies using the following command. ``` apt install mysql-server libmysqlclient-dev default-libmysqlclient-dev ``` Once the MySQL server is installed, connect to the MySQL shell with the following command. ``` mysql ``` Once connected, create a database and user with the following command. ``` CREATE DATABASE app_data; CREATE USER 'djangouser'@'localhost' IDENTIFIED WITH mysql_native_password BY 'password'; ``` Next, grant all the privileges to the app_data database. ``` GRANT ALL ON app_data.* TO 'djangouser'@'localhost'; ``` Next, flush the privileges and exit from MySQL using the following command. ``` FLUSH PRIVILEGES; EXIT; ``` Next, edit the MySQL configuration file and define your database credentials. ``` nano /etc/mysql/my.cnf ``` Add the following lines: ``` [client] database = app_data user = djangouser password = password default-character-set = utf8 ``` Save and close the file, reload the systemd daemon, and restart the MySQL service with the following command. ``` systemctl daemon-reload systemctl restart mysql ``` ## Step 3 – Install and Configure Django In this section, we will create a Django app with a database connection. First, create a Django app directory. ``` mkdir my_django_app ``` Next, navigate inside the created directory and create a Python virtual environment. ``` cd my_django_app python3 -m venv env ``` Next, activate the virtual environment. ``` . env/bin/activate ``` Next, install Django using the pip command. ``` pip install django ``` Next, create a Django project with the following command. ``` django-admin startproject myapp ``` Then, change the directory to myapp directory and install the required dependencies. ``` cd myapp pip install wheel pip install mysqlclient ``` Next, edit the Django setup file. ``` nano ~/my_django_app/myapp/myapp/settings.py ``` Define your server IP address and timezone: ``` ALLOWED_HOSTS = ['your_server_IP_address'] TIME_ZONE = 'America/New_York' ``` Find the following lines: ``` import os from pathlib import Path ``` Add the following lines above the above line: ``` STATIC_URL = '/static/' STATIC_ROOT = os.path.join(BASE_DIR, 'static') ``` Next, find the following lines: ``` DATABASES = { 'default': { 'ENGINE': 'django.db.backends.sqlite3', 'NAME': BASE_DIR / 'db.sqlite3', } } ``` And replace them with the following lines: ``` DATABASES = { 'default': { 'ENGINE': 'django.db.backends.mysql', 'OPTIONS': { 'read_default_file': '/etc/mysql/my.cnf', }, } } ``` Save and close the file, then apply the database settings using the following command. ``` python manage.py makemigrations python manage.py migrate ``` Next, create a super user for the Django app. ``` python manage.py createsuperuser ``` Define your admin username, email, and password as shown below: ``` Username (leave blank to use 'root'): admin Email address: admin@example.com Password: Password (again): Superuser created successfully. ``` ## Step 4 – Verify MySQL COnnection to the Django Application At this point, your Django application is installed and configured. Now, navigate inside your application directory and run your application using the following command. ``` cd ~/my_django_app/myapp/ python manage.py runserver your-server-ip:8000 ``` You will see the following output. ``` Watching for file changes with StatReloader Performing system checks... System check identified no issues (0 silenced). December 20, 2023 - 05:18:10 Django version 5.0, using settings 'myapp.settings' Starting development server at http://104.219.54.140:8000/ Quit the server with CONTROL-C. ``` Then, open your web browser and access your Django application using the URL **http://your-server-ip:8000.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p1-10.png) You can also access your Django admin interface using the URL **http://your-server-ip:8000/admin.** You will see the Django login screen. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p2-7.png) Provide your admin username and password and click on **Log in.** You will see the Django admin dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2023/12/p3-4.png) ## Conclusion Congratulations! You’ve successfully created a Django app with a database connection. Django’s powerful ORM and built-in development server make it easy to build feature-rich, data-driven web applications. This is just the beginning – as you explore Django further, you’ll discover its vast ecosystem and capabilities for building scalable and maintainable web projects. You can try deploying Django on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Five Data Storage Challenges Dominating Healthcare > URL: https://www.atlantic.net/hipaa-compliant-hosting/five-data-storage-challenges-dominating-healthcare/ | Published: 2024-01-29 | Updated: 2025-09-11 | Author: Alexander Wise So, you’re ready to step into a captivating world where healthcare and the delicate art of data storage converge?  It’s a fascinating symphony, where data engineering services and facility management harmonize to create a seamless experience, safeguarding the essence of patient care. But behind this technological masterpiece lie the difficulties healthcare providers face in protecting and storing their valuable data. So, let’s explore five common challenges in healthcare data storage and the crucial role played by data engineering services in overcoming these. ## Challenge #1: Security and Privacy Concerns With healthcare data storage, one of the most critical challenges is the need to safeguard the security and privacy of patient information. Like a treasured secret, data must be protected from prying eyes and potential breaches. Imagine a scenario where a patient’s medical history, replete with personal details and sensitive diagnoses, becomes vulnerable to unauthorized access. It’s a haunting tale of privacy invasion that threatens to disrupt the trust patients place in healthcare systems. Breaches of this nature not only compromise individual privacy but erode the foundation of patient-provider relationships. In this scenario, healthcare providers must: - Diligently adhere to regulations such as HIPAA and GDPR - Employ robust data encryption and implement strict access controls - Fortify their systems against potential cyber threats Only through the vigilant protection of patient data can healthcare providers maintain privacy and security. This is an ongoing performance that requires constant adaptation as technology advances and new threats emerge. An additional tip: if your healthcare organization has employees working remotely, remote desktop protocol (RDP) is a secure solution that’s worth exploring. [How secure is RDP](https://www.realvnc.com/en/blog/how-secure-is-rdp-over-the-internet/), you ask? Check out the guide we’ve linked to for valuable insights and best practices. ## Challenge #2: Managing Large Volumes of Data In the world of data storage, managing large volumes of information is a formidable task for healthcare providers. As the chorus of patient data grows louder, the need to handle and store vast amounts of information is paramount. Think about a bustling hospital where data fills every corner. Electronic health records, lab results, imaging scans, and other vital pieces of information flood the stage, creating a rich tapestry of patient data. Amidst this abundance, healthcare providers face the responsibility of managing and organizing data effectively. To handle this particular management challenge, [data backup](https://www.atlantic.net/disaster-recovery/how-to-data-backup-cloud-server/) must take center stage. This acts as a safety net, providing an assurance that no valuable notes or other information will be lost. A [data recovery clean room](https://www.databricks.com/blog/2022/06/28/introducing-data-cleanrooms-for-the-lakehouse.html) is another behind-the-scenes hero, with skilled professionals working diligently to retrieve data from damaged or corrupted storage devices. This helps avoid data loss when managing or moving lots of information (for example, from a legacy system to private cloud storage). ## Challenge #3: Data Interoperability Data interoperability in healthcare requires seamless data exchange between systems, akin to harmonizing different languages into a cohesive dialogue. Employing [data integration tools](https://airbyte.com/top-etl-tools-for-sources/top-data-integration-tools) facilitates this process, enabling healthcare providers to bridge gaps and ensure comprehensive patient care through interconnected systems. Picture a situation where healthcare systems speak different languages, making it difficult to share and integrate patient data. This lack of interoperability can lead to fragmented information and inefficiencies in care delivery. For example, a specialist may struggle to access a patient’s complete medical history, resulting in delays and potential errors in treatment decisions. To overcome this challenge, healthcare providers must strive to establish standardized formats and protocols that enable smooth data exchange. It should be a collaborative effort to create interconnected systems allowing for more comprehensive patient care. By achieving data interoperability, healthcare providers can gain a complete view of a patient’s health history, leading to improved diagnoses, treatment decisions, and overall healthcare outcomes. ## Challenge #4: Data Retention and Long-Term Preservation The challenge of data retention and long-term preservation is paramount when talking about healthcare data storage. Healthcare providers must ensure that patient information remains accessible and secure for years to come. It’s a delicate balance between scaling managed service providers and safeguarding the longevity of valuable data. Imagine a vast repository of patient data, holding the key to past diagnoses, treatments, and healthcare experiences. This data is invaluable not only in the present but for future research, reference, and continuity of care. Cloud-based storage solutions offer healthcare providers a reliable and scalable option for long-term data retention. By leveraging the power of the cloud, healthcare organizations can securely store and manage vast amounts of patient data while ensuring its availability and integrity. To address this challenge, healthcare providers must partner with managed service providers to establish effective data archiving practices and implement advanced storage technologies.Additionally, integrating [CRM platforms](https://www.atlantic.net/hipaa-compliant-hosting/top-5-hipaa-compliant-crm-software-tools/) into their data storage systems can enhance patient relationship management and facilitate personalized care delivery based on comprehensive patient data. ## Challenge #5: Cost and Budget Constraints Let’s say you’re a healthcare organization that’s aiming to implement state-of-the-art data storage solutions. The soaring costs associated with infrastructure, software, maintenance, and skilled personnel can present significant hurdles. These financial limitations can hinder your ability to acquire and maintain the necessary resources for efficient data storage. To tackle this challenge, you must carefully evaluate and prioritize your data storage needs. Seek out cost-effective solutions, such as cloud-based storage options, or outsource to third-party vendors to alleviate the burden of upfront capital expenditure. By adopting scalable and flexible storage models, you can optimize costs based on your fluctuating data storage demands. Moreover, healthcare organizations should actively seek out opportunities for cost optimization and process efficiency. By maximizing resource utilization and minimizing wastage, you can allocate your limited budget more effectively and ensure every dollar spent contributes to top-tier data storage solutions.Another way to do this is by implementing efficient data collection tools. These can streamline the process of gathering and organizing healthcare data, improving data storage efficiency and reducing costs. ## Future Trends and Technologies In the ever-evolving landscape of healthcare data storage, it’s imperative to keep an ear tuned to the future. Technology is ever-changing, presenting new opportunities and challenges for healthcare providers. By embracing emerging trends and innovative tech, healthcare organizations can compose a harmonious future for data storage and management. Top technology predictions set the stage for the future of the industry, and as we look ahead, several key trends emerge, including: - **Artificial intelligence (AI) and machine learning (ML).**AI and ML have tremendous potential for revolutionizing healthcare data storage. By leveraging intelligent algorithms, healthcare providers can extract valuable insights from vast amounts of data, enabling more accurate diagnoses, personalized treatments, and predictive analytics. AI-powered systems can also enhance data security by detecting and preventing potential breaches, fortifying both privacy and protection. - **Blockchain technology.** Blockchain has the potential to transform data storage in healthcare by enhancing security, privacy, and interoperability. Its decentralized nature ensures transparency and immutability, reducing the risk of unauthorized access and tampering. By leveraging blockchain, healthcare providers can maintain a trustworthy ledger of patient information, ensuring data integrity and facilitating seamless sharing between different entities. - **Edge computing.** With the proliferation of Internet of Things (IoT) devices, edge computing is becoming increasingly relevant in healthcare data storage. By processing data closer to the source, at the network edge, healthcare providers can reduce latency, enhance real-time analytics, and optimize data transfer. Edge computing brings data storage and analysis closer to the point of care, enabling faster and more efficient decision-making. - **Cloud computing.**The cloud continues to be a prominent player in healthcare data storage, offering scalability, flexibility, and cost-efficiency. [Cloud-based](https://www.atlantic.net/dedicated-server-hosting/replace-your-physical-tape-backups-with-atlantic-net-cloud-backups-and-save/) solutions allow healthcare providers to securely store, manage, and access large volumes of data without the need for extensive on-premises infrastructure. As the symphony of healthcare data expands, the cloud provides a harmonious backdrop, supporting seamless data sharing and collaboration across healthcare ecosystems. By embracing these trends and adopting appropriate technologies, healthcare organizations can compose a future where the potential of data storage is fully realized, leading to enhanced patient care and improved outcomes. ## Final Thoughts As we wrap up our journey through the realm of healthcare data storage, one thing becomes clear: the quest for a [unified data layer](https://www.databricks.com/glossary/unified-data-warehouse) is crucial. It sets organizations on the right path to create a harmonious and efficient healthcare system, where patient data, privacy, and innovation work seamlessly together. Throughout our exploration of challenges including security and privacy concerns, managing large volumes of data, and cost constraints, we’ve seen healthcare providers and professionals tirelessly working to find the best solutions for storing and managing data. This journey isn’t without its obstacles. It requires collaboration, innovation, and adaptability. From strengthening security measures through [cloud backups](https://www.atlantic.net/disaster-recovery/how-to-data-backup-cloud-server/) to connecting different data sources, from dealing with limited budgets to embracing new technologies, healthcare providers must approach these challenges with empathy and expertise, always putting patient well-being first. Looking ahead, we can glimpse a future where emerging technologies like artificial intelligence, blockchain, edge computing, and cloud solutions will play a part too. These advancements can help make healthcare data storage more efficient and enable personalized and transformative care experiences. The focus is not just on healthcare professionals but on patients. By safeguarding the security and privacy of their data, healthcare providers build trust and empower them to actively participate in their healthcare journeys. So, as we continue on this path, let’s move forward with passion, empathy, and a commitment to excellence. Let’s strive for a future where the unified data layer seamlessly integrates, empowering healthcare providers to make informed decisions and deliver more effective, patient-centered care. --- # Your Complete Guide to HIPAA Data Compliance > URL: https://www.atlantic.net/hipaa-compliant-hosting/your-complete-guide-to-hipaa-data-compliance/ | Published: 2024-01-30 | Updated: 2026-03-01 | Author: Richard Bailey Healthcare data is protected by law, and any personally identifiable information (PII) or Protected health information (PHI) is bound by federal laws in the United States. This article will cover all the HIPAA rules and regulations that guard our sensitive patient health information. Data is valuable; not only does it contain all sorts of interesting facts relevant to us, but it also has monetary value. Eric Schmidt, one of the founders of Google, [famously said](https://www.weforum.org/agenda/2019/04/how-much-data-is-generated-each-day-cf4bddf29f/), “We have created more data in the last two years than in the entire history of mankind.” Most of Google and Facebook’s revenue comes from buying and selling data. Data certainly makes the world go around; it creates insights into our lives, helps to predict our future, and holds the key to our health. Data in healthcare is a serious business; it’s illegal for healthcare organizations to sell your data to the highest bidder, and rightly so. ## A Definition of Health Insurance Portability and Accountability Act HIPAA was signed into federal law in 1996 by President Bill Clinton. HIPAA served two purposes: ### Purpose #1: Health Insurance Portability The often overlooked part of HIPAA was the initial requirements to fix “job lock,” a scenario where employees felt pressured to stay in unsatisfying jobs to keep their health insurance. HIPAA fixed this issue practically overnight by making health insurance policies portable. HIPAA also fixed another injustice in healthcare insurance, guaranteed health insurance coverage for pre-existing conditions, and broadened access to insurance coverage. ### Purpose #2: Administrative Simplification Provisions The second objective of HIPAA was to streamline healthcare transactions, such as healthcare claims processing. This made it more efficient and cost-effective for providers and insurers and made fraud and abuse harder. However, the administrative simplification provisions have evolved into the HIPAA safeguards we know today. It paved the way for the HIPAA Privacy Rule, HIPAA Security Rule, HIPAA Omnibus Rule, and the HIPAA Breach Notification Rule amendments. ## Who needs to be HIPAA compliant? Essentially, anyone who handles HIPAA data is in the scope of HIPAA compliance requirements. Those that create the data, those that process the data, and businesses or third parties involved in each step of processing protected health information. To simplify this categorization, the HHS Office for Civil Rights classifies all parties as a covered entity or a business associate. ### Covered Entities A Covered Entity (CE) is *an*organization that handles PHI during day-to-day business operations. Most businesses working in the healthcare industry are considered Covered Entities.  The U.S. Department of Health and Human Services (HHS) [officially defines](https://www.hhs.gov/hipaa/for-professionals/covered-entities/index.html) a CE as: - **Healthcare Providers** – doctors, dentists, nursing homes, pharmacies, etc. - **Health Plans** – health insurance companies, HMOs, Medicare, Medicaid, etc. - **Clearinghouses** – transcription services, etc. Each Covered Entity has a legal requirement to protect patient data from loss, theft, and misuse. The CE may work with a business associate to outsource specific business functions like cloud hosting. To appropriately place the responsibility into the hands of a Business Associate, all involved companies must agree to the terms of Business Associate Agreements (BAA). ### Business Associates These individuals or organizations perform certain functions or activities for a covered entity, such as billing services, medical transcription, or data storage. A Business Associate who also handles or processes PHI on behalf of the covered entity is classified as a business associate. Atlantic.Net is a business associate, as we provide [HIPAA-compliant hosting services](https://www.atlantic.net/compliance-hosting/) to the healthcare industry. Covered Entities may use our service to process and transmit protected health information. We sign a BAA with each of our healthcare clients to document our responsibilities and the guarantees we adhere to when handling PHI. ## What is Protected Health Information? Any patient-identifying information stored digitally falls under electronic protected health information (ePHI). Nevertheless, it’s crucial to grasp which data qualifies as protected health information (PHI) under HIPAA regulations. According to the [HHS](https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html), Protected Health Information is classified as: - **Past, present, or future physical or mental health condition:** This includes diagnoses, test results, medical history, medications, allergies, genetic information, etc. - **The provision of healthcare to the individual:** This includes details about appointments, procedures, treatments, referrals, etc. - **The past, present, or future payment for the provision of healthcare to the individual:** This includes insurance information, billing information, claims data, etc. Any information that can identify the patient is considered individually identifiable health information and is [in-scope of HIPAA legislation](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-188.pdf); this includes: ### Direct identifiers: - Full name - Postal address (including street name, city, state, and ZIP code) - Telephone number - Fax number - Email address - Social Security number (SSN) - Medical record number (MRN) - Health plan beneficiary number - Account number - Certificate/license number - Vehicle identifiers and serial numbers (including license plate numbers) - Device security identifiers and serial numbers - URLs - IP addresses - Biometric identifiers (e.g., fingerprints, facial images, iris scans, voiceprints) - Full-face photographic images and any comparable images - Dates (e.g., birth date, admission date, discharge date) ### Indirect identifiers: - City, state, and ZIP code - Elements of dates (e.g., year, month, day) - Age - Gender - Race - Ethnicity - Religion - Marital status - Occupation - Education level - Income level - Type of health insurance - Geographic location (e.g., city, neighborhood) - Type of medical treatment received - Dates of medical appointments - Unique identifying numbers assigned to individuals for research or other purposes Therefore, considering everything above, we can conclude what is PHI and what is not. ### What is Classified as Protected health information? PHI is: - A patient’s medical record containing their name, diagnosis, and treatment plan. - A laboratory report with the patient’s name and test results. - An X-ray with the patient’s name and date of birth. - A list of patients treated for a specific condition without including any names. ### What is NOT Classified as Protected health information? PHI is not: - Vital signs data without any patient identifiers. - Aggregate statistics about a population’s health, such as the number of people with diabetes in a city. - De-identified genetic data used for research purposes. As you can tell, classifying what is classified as protected health information is a complicated process. You have to [consider](https://www.atlantic.net/resources/documents/brochures/pdf/hipaa-compliant-hosting-requirements-checklist-atlantic-net-brochure.pdf) the HIPAA security rule checklist and the HIPAA Privacy rule to gather a complete understanding of what is in scope. HIPAA regulations bind any electronic protected health information that falls into these classifications. When creating applications and managing and maintaining data, it’s essential to remember these stringent guidelines of HIPAA data compliance. ## HIPAA Privacy Rule The HIPAA Privacy Rule was created to balance the need for secure medical data protection with the requirement of digitizing the patient information flow needed for quality healthcare and public cloud health services. The HIPAA Privacy Rule sets the standard for how protected health information can be collected, processed, and, in certain circumstances, disclosed. The Privacy Rule can be broken up into six key areas: ### #1: Authorization Protected health information can be disclosed when certain conditions are in place. The Privacy Rule already allows PHI to be disclosed with other healthcare providers involved in the patient’s care, as well as with insurance companies, billing services, or other services related to the cost of healthcare. PHI can also be shared as requested by healthcare operations, such as quality improvement, case management, and healthcare fraud and abuse detection. PHI can be shared if required by law, such as a criminal investigation; it can also be declared to authorize the next of kin or in cases where the patient’s well-being is threatened. ### #2: Minimum Required Standards When PHI is approved for collection, specific rules exist about what information can be collected. Covered entities and business associates are bound by the rule that only the minimum required data, data necessary for the patient’s care, can be collected. You are not allowed to harvest all the personal information you want. This approach encourages minimal data collection and the de-identification of PHI wherever possible. Consider personal biometrics; redacting any protected health information will allow the information to be used in research and training. ### #3: Individual Rights An essential human right is for the patient to be allowed access to inspect what information is held on record about them. The patient can also request for any inaccuracies to be corrected if they believe it is inaccurate or incomplete. The Privacy Rule also gives the patient the right to request restrictions on certain uses and disclosures of their PHI. The idea is to enforce the requirement that the patient controls their data. ### #4: Accounting for Disclosures You only need to view the [OCR Hall of Shame](https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf) to see that unauthorized data breaches still occur. It is a mandatory step of HIPAA compliance requirements to account for unauthorized disclosures of PHI. It doesn’t matter how big or small the incident is; the case must be reported to the OCR, who will pass judgment independently. The HIPAA Privacy Rule requires covered entities to maintain records of disclosures of PHI for purposes other than treatment, payment, or healthcare operations and allows individuals to request an accounting of these disclosures to track how their PHI has been shared. ### #5: Security Safeguards The HIPAA Privacy Rule directly references the HIPAA Security Rule by mandating covered entities to implement appropriate administrative, technical, and physical safeguards to protect PHI’s confidentiality, integrity, and availability. Including specific requirements for access controls, data encryption, and breach notification procedures. We will cover this in more detail in the section below. ### #6: Enforcement The Office for Civil Rights (OCR) within the Department of Health and Human Services (HHS) enforces the HIPAA Privacy Rule to ensure HIPAA compliance. The OCR can investigate complaints, conduct compliance reviews, and impose civil penalties for a HIPAA violation over how PHI is handled. ## HIPAA Security Rule The HIPAA Security Rule plays a vital role in upholding HIPAA Data Complaint. Launched in 2003, it helped to create the cornerstone of data security requirements covered entities and business associates must adhere to. The Security Rule sets out three main types of security measures that need to be put in place for compliance: ### Administrative safeguards The full suite of HIPAA administrative simplification regulations involves establishing, selecting, implementing, and maintaining security measures that effectively shield ePHI (electronically protected health information). This includes managing how the workforce behaves in safeguarding this sensitive patient data. Examples of administrative safeguards include: - Setting up comprehensive security policies and procedures, like access control and authentication measures, to monitor and regulate workforce access to ePHI. - Conducting a routine risk assessment and vulnerability scans to identify potential security gaps and manage security risks proactively. - Providing ongoing security training and awareness programs for employees to educate them about the best practices in securing ePHI. - Developing and implementing incident response plans to address and mitigate a security data breach or incidents effectively. ### Physical safeguards: Physical safeguards are tangible measures, policies, and procedures to safeguard electronic information systems, infrastructure, and equipment from natural hazards, environmental threats, and unauthorized access. The goal is to create a physical barrier preventing unauthorized individuals from accessing ePHI. Examples include : - Installing security cameras and access control systems to monitor and control physical access to areas where ePHI is stored. - Measures like locked server rooms, secure cabinets, and biometric authentication systems to limit physical access to ePHI. - Safely disposing of physical media (such as hard drives, CDs, or printed records) containing ePHI through secure destruction methods like shredding or degaussing. ### Technical safeguards: Technical safeguards encompass the use of technology, along with appropriate policies and procedures, to secure ePHI and control its access. This involves implementing solid technological measures to protect electronic information from unauthorized disclosure or alteration. Examples include: - Encrypting ePHI during storage and transmission to prevent unauthorized access or interception and using secure protocols like SSL/TLS for data transmission. - Implementing firewalls and intrusion detection systems to monitor and control network traffic, identifying potential threats or unauthorized access attempts. - Requiring robust passwords, multi-factor authentication, or biometric verification to access systems or applications containing ePHI. - Regularly applying security patches and updates to software, operating systems, and applications to fix known vulnerabilities. Ultimately, the HIPAA Security Rule aims to create trust between healthcare providers, patients, and any third parties by setting stringent standards to protect sensitive patient data, ensuring its confidentiality, integrity, and availability while promoting a secure healthcare ecosystem. ## How To Achieve HIPAA Data Compliance. As we have discovered so far, ensuring compliance with healthcare regulations of the Health Insurance Portability and Accountability Act (HIPAA), and particularly the Security Rule and Privacy Rule, is crucial for covered entities and business associates dealing with sensitive patient data. Achieving and maintaining HIPAA compliance involves various measures, including administrative, physical, and technical safeguards. HIPAA compliance requirements oblige covered entities to implement specific security measures and risk assessments. Healthcare organizations, including the covered healthcare providers and those who offer health plans, must ensure that integrity controls and access controls are in place to protect individually identifiable health information (IIHI). Failure to comply with such HIPAA regulations can lead to penalties, including civil money penalties for HIPAA violations or breaches. Covered entities and business associates are required to establish robust security management processes and regularly conduct risk analyses. Employee training is also vital to maintain HIPAA compliance and prevent data breaches. Maintaining compliance involves ensuring that electronic health records (EHRs) and medical records are secure and that breach notification rules are promptly followed in case of any data breaches. Partnering with reliable and reputable cloud service providers (CSPs) that demonstrate HIPAA compliance and are willing to enter into Business Associate Agreements can significantly aid in maintaining regulatory compliance. A suitable CSP (or Managed services provider) will help healthcare organizations navigate the complexities of HIPAA compliance and provide turnkey solutions tailored to specific compliance needs. It’s crucial to note that HIPAA compliance goes beyond just meeting the minimum requirements; it’s about safeguarding sensitive patient data and ensuring the security and privacy of healthcare information according to national standards. Complying with HIPAA regulations is a continuous process that requires diligence, accountability, and a comprehensive understanding of the privacy and security rules to protect patient data effectively. ## How Atlantic.Net Creates HIPAA Data Compliance Services Atlantic.Net is approaching 30 years of providing telecoms and IT solutions to a wide range of global customers. Healthcare organizations choose Atlantic.Net because we are big enough to handle the demands of their businesses but small enough to care immensely about how your business succeeds in the competitive healthcare industry. Our hosting service offers a secure environment for storing and managing electronic health records. We prioritize protecting patient data and implement advanced security measures to achieve this. Access control tools like passwords and PINs are used to prevent unauthorized entry, encrypting access to authorized personnel only, and fortifying the security of patient information. Our HIPAA platform encrypts all static data at rest (like files saved on disk) and data in transit (such as network traffic between Atlantic.Net and healthcare providers), adding an extra layer of security to hinder unauthorized access. A significant feature of our HIPAA hosting service is the SIEM-powered audit trail tools, recording access to patient information, changes made, and timestamps. This provides a comprehensive record of activities related to a patient’s electronic health record, allowing healthcare providers to monitor access and changes effectively. Additionally, we offer various features that further enhance electronic health record protection, including HIPAA-compliant web and database hosting, managed HIPAA cloud, dedicated servers, and secure block storage. These solutions are tailored for healthcare applications, surpassing the administrative, physical, and technical safeguards mandated by HIPAA. Our HIPAA-compliant hosting solutions are SOC 2 and SOC 3 certified, HIPAA and HITECH audited, reflecting our commitment to maintaining the highest security and compliance standards. The hosting platform is built to industry-leading standards, providing a robust, feature-rich solution powered by cutting-edge technology, ensuring high performance in dedicated and cloud server environments with a 100% uptime SLA. Furthermore, we offer managed services like backups, server management, intrusion prevention systems, vulnerability scans, anti-malware, and network security to further fortify the security of electronic health records. We comply with HIPAA by providing a Business Associate Agreement (BAA) with all HIPAA hosting plans, ensuring external organizations handling electronic protected health information meet HIPAA responsibilities. If you seek a reliable and secure solution for healthcare data needs that surpasses standards, consider [Atlantic.Net’s HIPAA-compliant data hosting service](https://www.atlantic.net/about-us/corporate-contact/)s. We aim not just to meet but to exceed these standards. --- # Atlantic.Net Expands International Footprint with New Singapore Region > URL: https://www.atlantic.net/press-releases/atlantic-net-expands-international-footprint-with-new-singapore-region/ | Published: 2024-01-31 | Updated: 2024-11-22 | Author: Editorial Team *Joins other cloud leaders as the Singapore government increases investments in cloud computing* **ORLANDO, Fla.** **– Jan. 31, 2024 –**[Atlantic.Net,](https://www.atlantic.net/) a leading cloud hosting solutions provider, today announced the opening of its Singapore cloud region in the world’s fastest-growing Asian market. This region’s opening comes at a pivotal moment as the Singapore government increases investments in cloud computing, including its Government Commercial Cloud (GCC) service that makes it easier for public sector agencies to manage and secure their use of public cloud services from companies like Amazon Web Services (AWS), Google Cloud and Microsoft Azure. “We’re excited to continue expanding our footprint globally, especially in a location that has proven its commitment to cloud through high-dollar investments and attracted the attention of leading cloud-based companies,” said Marty Puranik, CEO, and founder of Atlantic.Net. “The world is becoming even more connected with each passing day, especially as cloud computing investments increase. This expansion into Singapore will allow the Atlantic.Net team to further support partners in a blossoming region.” Atlantic.Net specializes in an array of hosting services including on-demand and turnkey cloud, dedicated hosts, dedicated servers, colocation, private virtualization, and managed hosting. In addition to Singapore, the company provides scalable computing from seven secure, data centers worldwide including New York, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando, each engineered to provide fault-tolerant and ultra-fast performance. All new customers will receive a free cloud server for a year, including 2GB RAM, 50 GB SSD disk, and 3TB monthly transfer. As cloud continues to be top of mind for both the Singapore government and businesses, Atlantic.Net is happy to be among the top cloud providers in the region. For more information, please visit [Atlantic.Net](https://www.atlantic.net/). **About Atlantic.Net** Atlantic.Net is an award-winning global cloud services provider with a focus on security, compliance, and simplifying complex infrastructures. With over 29 years of experience, Atlantic.Net is dedicated to offering developers and IT leaders at small, medium, and large organizations a range of on-demand, customized, and cost-effective cloud solutions that cater to their unique business needs. Having served clients like Lenovo, Newegg, NASA and Hilton, the company’s commitment to excellence has positioned it as a leader in the industry, recognized for its innovation and customer-centric approach. ### **Media Contact** 5WPR for Atlantic.Net [atlantic@5wpr.com](mailto:Atlantic@5wpr.com)   --- # Atlantic.Net Announces New Cloud Services in Singapore, Our First Asia-Pacific Region! > URL: https://www.atlantic.net/announcements/atlantic-net-unveils-exciting-new-chapter-with-grand-opening-of-singapore-cloud-region/ | Published: 2024-01-31 | Updated: 2025-09-11 | Author: Alexander Wise If you need low latency and fast access to the Asian market with Atlantic.Net’s signature power, speed, and reliability, our new Singapore, Asia-Pacific Cloud region has you covered! You can now create and manage fast Cloud Servers in our AP-Southeast-1 (Singapore, SG) region via the control panel or API. ![](https://www.atlantic.net/wp-content/uploads/2024/01/Singapore-v-2-04.jpg) With the addition of our Singapore Asia-Pacific region, members can now deploy [Cloud Servers](https://www.atlantic.net/vps-hosting/) and One-Click Applications in less than 30 seconds in eight global data center regions including New York, London, Toronto, San Francisco, Dallas, Ashburn, Singapore, and Orlando. The new region has the same features and pricing you are already used to, so launching a new server is fast and easy! This new environment represents Atlantic.Net’s commitment to providing the latest and most stable virtualization technologies, Enterprise NVMe Solid State Drives, updated core networking, and new 32- and 64-bit Operating System images for [Windows](https://www.atlantic.net/vps-hosting/windows-vps-hosting/) and [Linux Hosting](https://www.atlantic.net/vps-hosting/linux-vps-hosting/). All new customers will receive a free cloud server for a year, including 2GB RAM, 50 GB SSD disk, and 3TB monthly transfer. This year we are celebrating **30 years of customer success**. Thanks to all our members who have made this possible and continue to grow with us. To try out our cloud services in our new Singapore Asia-Pacific cloud region, get started in the [Atlantic.Net Control Panel](https://cloud.atlantic.net/?page=userlogin) today! --- # What Is a HIPAA Certification? > URL: https://www.atlantic.net/hipaa-compliant-hosting/what-is-a-hipaa-certification/ | Published: 2024-02-06 | Updated: 2026-09-15 | Author: Richard Bailey HIPAA certification refers to an official certification or recognition where business associates and covered entities demonstrate adherence to HIPAA’s stringent regulations and guidelines. Certification indicates that the best patient data protection, privacy, and security practices are followed. HIPAA certification confirms that an organization is committed to implementing and upholding the required safeguards to prevent data breaches and ensure the confidentiality and integrity of protected healthcare information. ## What Is a HIPAA Certification and Who Issues One? The government, the HHS, or the OCR do not issue it. So, what is a HIPAA certification? It is a status the organization must achieve by demonstrating the ability to meet and exceed the federal requirements of how to handle protected health information. Some Covered Entities and Business Associates undergo third-party assessments or audits to validate their compliance efforts. This step involves engaging an independent auditor or certification body to evaluate the organization’s policies, procedures, and technical safeguards to ensure they align with the strict HIPAA requirements. In this article, we will discover how your healthcare organization can achieve HIPAA compliance and learn why following the administrative, physical, and technical safeguards demanded by HIPAA compliance is the best way forward for your healthcare organization. ## What Is HIPAA Compliance? Healthcare entities, including covered entities and business associates, must comply with HIPAA regulations to safeguard sensitive patient data and achieve HIPAA Compliance. A covered entity is any healthcare organization, such as hospitals, clinics, or insurers handling patient information. Business associates are individuals or entities working alongside covered entities, handling patient data on their behalf. They must follow the HIPAA rules within a Business Associate Agreement (BAA). Failure to adhere to the legal obligations of HIPAA Compliance can result in severe consequences, including hefty penalties and reputational damage for a security violation or data breaches and non-compliance issues. HIPAA Certification can only be achieved by meeting the HIPAA Certification requirements. What this means is that your Covered Entity or Business Associate must meet the minimum HIPAA Standards as laid out in the HIPAA Security Rule (2003), the HIPAA Privacy Rule (2003), the Breach Notification Rules (2009), and the Final Omnibus Rule (2013). ### HIPAA Security Rule The full title of the HIPAA Security Rule decree is “[Security Standards for the Protection of Electronic Protected Health Information](https://www.hhs.gov/hipaa/for-professionals/security/index.html#:~:text=The%20HIPAA%20Security%20Rule%20establishes,maintained%20by%20a%20covered%20entity.&text=The%20Security%20Rule%20is%20located,and%20C%20of%20Part%20164.).” As the official title suggests, the Security Rule is a ruling that defines the exact stipulations required to safeguard ePHI, specifically relating to how the information is stored and transmitted between digital devices. The Security Rule is split into three HIPAA Standards: #### Physical Safeguards The physical safeguards refer to the implementation specifications for real-life physical controls on digital devices that store and handle e-PHI. Some of the critical areas for consideration are: - How old or faulty equipment is replaced – for example, how ePHI media is destroyed - What personnel access levels are granted to in-scope systems containing ePHI; specifically, covered entities must ensure that access is only granted to employees with a relevant level of authorization - How to train 3rd-party IT professionals when accessing the in-scope equipment for repairs #### Technical Safeguards The technical safeguards of the Security Rule are more easily defined and include the technical aspects of any networked computers or devices that communicate with each other and contain PHI in their transmissions. These safeguards include enhanced network security, perimeter firewalls, cybersecurity authentication protocols, and more. Any security measures that can be implemented on system software or hardware belonging to an external organization go to the security rule technical safeguards category. #### Administrative Safeguards The final standard, administrative safeguards, covers how covered entities must set up employee policies and procedures to comply with the Security Rule. Think of it as a separate, dedicated portion of employee training for management and staff, defining who gets access and what they can and cannot do once access is granted. ### HIPAA Privacy Rule Its full name is the “[Standards for Privacy of Individually Identifiable Health Information](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/standards-privacy-individually-identifiable-health-information/index.html).” This rule defines that patient health data must be traceable to a specific person to fall under the scope of HIPAA’s requirements. That wording allows anyone who wants to study health and medical trends the legal wiggle room to omit personally identifiable information before transmission. However, any patient data that contains Protected Health Information is bound by the HIPAA Privacy and security rules. ### Breach Notification Rules The U.S. Department of Health and Human Services (HHS) classifies two types of breaches. A breach that**does not disclose**PHI is considered “not a breach.” A breach that **does disclose** PHI must be classified as either an *intentional* or *unintentional* disclosure. Deliberate disclosure is regarded as a severe breach and typically involves significant penalties. ## What Information Is Classified as Protected Health Information? To be fully HIPAA Compliant and achieve HIPAA Certification, all parties that sign the Business Associate Agreement must know precisely what information is classified as electronic Protected Health Information. This is vital as a requirement of any awareness training program the healthcare provider offers. Your healthcare employees must know what constitutes PHI, failing to meet the requirements of a HIPAA Compliance Audit and the HIPAA Certification Program. According to the [National Library of Medicine](https://www.ncbi.nlm.nih.gov/books/NBK553131/), protected health information (PHI) is any health information that can identify an individual in possession of or transmitted by a “covered entity” or its business associates related to a patient’s past, present, or future health. To help simplify this, we have drawn up a real-world list of what constitutes Protected Health Information: - Patient name - Patient location (such as home addresses, cities, counties, or zip codes. This also includes location of treatment) - Dates relevant to the patient’s health or personal identity (such as birthdates, admission dates, discharge dates, and dates of passing) - Contact Information (such as Phone numbers | Fax details | Email addresses) - Social Security numbers - Medical record identifiers - Health insurance beneficiary identification (e.g., Health Insurance Claim Numbers) - Account numbers (Insurance or Payment information) - Certificate or license numbers - Vehicle identification information - Digital markers, such as PHI, saved locations. - IP addresses - Biometric data, including fingerprints, retinal scans, and voiceprints, and telehealth data - Photographs of patients, patient imagery, and patient photographic notes. It’s important to note that this list is not an exhaustive list of what is and is not PHI. But use it as a guideline, and you will be on the right track. As always, seek legal advice about your legal obligations before seeking HIPAA Certification requirements. ## Why Do Organizations Get Certified As HIPAA-Compliant? It’s important to ask why Healthcare Organizations undergo rigorous healthcare industry compliance training requirements. Here are six key reasons why it’s in healthcare professionals’ best interest to pass HIPAA Certification: ### You Are Legally Obliged to Be HIPAA-Compliant! Firstly, there’s a legal obligation tied to HIPAA certifications. HIPAA is a federal law that sets the bar for safeguarding sensitive patient health information. Covered entities like healthcare providers and health plans must comply. Certification is one way of helping to ensure that an organization adheres to these standards, lowering the risk of legal wrangling and hefty fines resulting from non-compliance. ### Uphold Data Integrity Secondly, it’s about data security. Achieving HIPAA compliance involves implementing robust measures to protect patient data. This includes encryption, access controls, regular risk assessments, and other protocols. We will discuss this later, but certification assures patients and stakeholders that their health information is safe. ### Healthcare Professional Reputation Thirdly, trust and reputation are key. Building patient trust is vital in healthcare. Obtaining certification shows an organization’s dedication to privacy and security, enhancing its reputation. Patients feel more secure entrusting their data to entities that comply with HIPAA standards. ### Organization’s Compliance Creates Business Opportunity Also, there’s the aspect of business opportunities. Being HIPAA-compliant can open doors to collaborations and partnerships that require strong data security assurances. It allows healthcare providers and related entities to expand their horizons. ### Data Protection Determines Compliance Plus, there’s a need to dodge data breaches. Compliance helps organizations proactively prevent breaches and cyberattacks. By following strict security and breach notification guidelines, entities reduce the risk of breaches that could compromise sensitive patient information. ### A Security Standards Audit Will Prevent Fines Lastly, avoiding penalties and fines is crucial. Non-compliance with HIPAA regulations can lead to substantial financial penalties. Certification protects against these repercussions and potential disruptions to their operations. Healthcare organizations pursue HIPAA compliance and certification programs to meet legal requirements, safeguard patient data, build trust, bolster their reputation, explore new opportunities, prevent breaches, and avoid penalties linked to non-compliance. ## Is HIPAA Training Required? Training is a fundamental component of HIPAA compliance for healthcare professionals. It equips them with the necessary knowledge to handle patient information securely and by HIPAA regulations, contributing significantly to achieving HIPAA certification for the organization. HIPAA training educates employees about the following: 1. **HIPAA regulations:** Understanding the law’s provisions, including privacy rules, security standards, and breach notification requirements. 2. **Safeguarding patient information:** Proper handling, access, and sharing of sensitive health data to maintain patient privacy. 3. **Security measures:** Learning about encryption, access controls, risk assessments, and incident management procedures to protect patient information from unauthorized access or breaches. 4. **Compliance requirements:** Understanding the organization’s policies and procedures to ensure adherence to HIPAA guidelines. ## Outsourcing Healthcare IT Systems Outsourcing your healthcare IT systems to a HIPAA-compliant cloud service provider such as Atlantic.Net can significantly support your healthcare organization in achieving HIPAA certification. Outsourcing will help healthcare providers achieve HIPAA compliance almost overnight, precisely all the technical requirements of HIPAA. You are safe knowing that your Protected Health Information is managed and maintained by a reputable HIPAA-compliant entity. Achieving HIPAA compliance is a two-way requirement. There are parts of the HIPAA requirements that MSPs like Atlantic.Net will grant you; however, numerous Privacy and Administrative safeguards are still required from the Covered entities. That being said, outsourcing can still be a big step forward on the road to achieving HIPAA certification. So what exactly does a HIPAA-compliant hosting and managed service provider like Atlantic.Net bring to the table? ### Heightened Security Measures: The HIPAA-compliant hosting provider ensures robust security aligned with HIPAA-certified requirements. Measures include using AES256 encryption of all static data that contains ePHI, encryption of the VPN used to connect the provider and the covered entity (plus any 3rd party), access controls to secure how or what can interact with PHI, and bi-annual audits to ensure the administrative, physical and technical safeguards of HIPAA are being upheld, and to protect all patient health information stored in the cloud. ### Compliance Expertise: Atlantic.Net provides access to a dedicated team with decades of experience and knowledge of all HIPAA regulations. We can advise on best practices and recommendations, assist in a physical site audit, and work with your certified HIPAA professional or compliance officer to achieve third-party HIPAA certification. Our experts ensure the hosted environment is configured to comply with HIPAA standards, ensuring data practices meet regulatory requirements. This includes not only the security requirements but also the physical security. ### Data Backup and Recovery: Reliable Managed Service Provides offer data backup and disaster recovery services as standard for all HIPAA hosting, ensuring secure data access in emergencies. Data backup is the bare minimum needed to protect PHI. We recommend all clients follow the 3-2-1 method of data recovery. It involves creating three copies of your data, storing them in two formats, and keeping one offsite. This method ensures data resilience and protection against various risks, including hardware failures, accidental deletions, and disasters. The 3-2-1 backup strategy aligns with the Health Insurance Portability Act’s requirements by providing a robust and secure backup mechanism. In the event of data loss or corruption, storing multiple copies in diverse formats minimizes the risk of data compromise. Keeping one copy offsite ensures continuity in case of on-site disasters, adding an extra layer of security and compliance with HIPAA’s emphasis on data availability and integrity ### Managed Services: Another critical area in Atlantic.Net that can speed up your HIPAA compliance certification is with a variety of managed services. We handle core system updates, patches, security protocols, backups, and the entire cloud platform, thus reducing your IT staff’s workload. We implement strict access controls to ensure that only authorized personnel can access sensitive patient data in the cloud. We control the cloud services and allow for flexibility in modifying services without compromising security or compliance, making scaling the system a breeze. We can even help provide training programs to educate staff on using the cloud platform securely and in compliance with HIPAA law. ## Atlantic.Net HIPAA Hosting Elevate healthcare data security with [Atlantic.Net’s HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/). Our robust measures include AES256 encryption, secure VPN, and bi-annual audits. Rely on our compliance expertise, 3-2-1 backup strategy, and managed services for a seamless path to HIPAA certification. Trust us to safeguard ePHI and ensure data integrity and availability. --- # HIPAA Log Retention Requirements > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-log-retention-requirements/ | Published: 2024-02-13 | Updated: 2025-09-11 | Author: Richard Bailey In the context of Health Insurance Portability and Accountability Act (HIPAA) compliance, logging plays a crucial role in ensuring the security and integrity of protected health information (PHI). Logging involves the systematic recording of events and activities within a HIPAA-compliant hosting platform, and both covered entities and business associates need to maintain an audit trail and monitor all access to sensitive healthcare data. Ensuring the proper implementation of logging and log retention is crucial for maintaining HIPAA Compliance. In the event of a breach, the accuracy of your logging records becomes vital as they serve as the critical resource for understanding the precise details of the incident. Precision in logging and efficient data ingestion empower healthcare professionals to comprehend in-demand data. This, in turn, provides the necessary guarantees, ensuring a clear understanding of what Protected Health Information (PHI) is retained, its location, the latest update timestamp, and a comprehensive history of record access or updates. This article explores the essential elements and best practices associated with logging in [HIPAA Compliant environments](https://www.atlantic.net/compliance-hosting/), emphasizing real-time monitoring, audit trails, and adherence to regulatory frameworks. ## HIPAA Compliance: What HIPAA Logging Requirements are Necessary for ePHI? Logging creates the fundamental foundations needed to be able to audit trails for all forms of PHI. HIPAA demands that all healthcare providers and organizations adopt proven logging practices that provide comprehensive information and ensure practicality. HIPAA requires logging to be enabled for system-wide successes and failures for all software and hardware involved in the storage, transmission, or handling of PHI. In particular, the hosting platform is used for critical PHI file access. The logging platform must be able to collect data about every single digital footprint that touches PHI. Compliant logging and log retention are not easy tasks to complete. It is also one of the most challenging elements of HIPAA to maintain in a HIPAA-compliant state. The logging and record retention requirements of applications, software, operating systems, and hardware vary from version to version. Keeping up with these changes requires a dedicated team of logging experts. Choose a logging application that automates collecting and filtering security events to sift through data efficiently and log to a secure remote Syslog or SEIM server running on dedicated hardware. Not sure how to do this? [Reach out](https://www.atlantic.net/hipaa-compliant-hosting/#GetStarted) to the experts at Atlantic.Net. ## HIPAA Security Rule Mandates for Auditing and HIPAA Logging Requirements The HIPAA Security Rule imposes rigid criteria for auditing and logging to ensure the confidentiality and integrity of healthcare data. Continuous monitoring is at the forefront of this requirement, emphasizing the preconditions of having a valid audit trail throughout a comprehensive logging solution. Healthcare organizations are advised to draw up a Security Policy Framework; this demonstrates the importance of event logging, but it also helps to emphasize the role of real-time monitoring and audit trails for operating systems and HIPAA applications. Specific policies, including those related to passwords and event logging, are integral to this framework, aligning with the broader objectives of safeguarding PHI. Adopting a proactive approach to logging is crucial; being reactive doesn’t align with HIPAA compliance standards. Therefore, it’s imperative to ensure that logs are enabled before incidents occur, enhancing their admissibility in legal proceedings. The Security Rule’s approach to monitoring login data is about having measures to audit login attempts and automatically notify if anything seems off. It’s important to gather and link various event data. Modern SEIM platforms and AI-powered security solutions are great at doing this. ## What Are the Retention Requirements of Hipaa-Compliant Data? Data Retention requirements are mandated by HIPAA and HITECH, the California Consumer Privacy Act (CCPA), GDPR, etc. It comes down to the fact that you can only retain HIPAA complaint data and medical records (such as electronic medical records) for as long as needed. This means you cannot gather every bit of data possible about a patient and cannot keep hold of the data indefinitely. There are rules about how long medical records can be kept and how medical records and protected health information data are destroyed. You don’t want your medical records found in a dumpster or left on the subway. The same goes for digital data; HIPAA regulates how data is destroyed. HIPAA does not specify a fixed retention period for all types of data. Instead, it emphasizes the need for covered entities to establish policies based on specific circumstances. ## So, How Should Protected Health Information Be Destroyed? Securing and destroying HIPAA-protected health information (PHI) is a mandatory safeguard of HIPAA compliance. Covered Entities and Business Associates must ensure that PHI is deleted ethically and within the HIPAA rules. Here are recommended steps for properly deleting and destroying PHI: ### Use Secure Deletion Methods: **Electronic PHI:** For digital records, use secure deletion methods such as overwriting, degaussing, or using secure deletion software to ensure that the data is irrecoverable. If your Storage Array has a disk failure, and there is a chance the disk contains PHI, the hard disk must undergo [certified destruction](https://www.atlantic.net/hipaa-compliant-hosting/top-5-places-you-need-to-be-using-encryption-in-your-it-architecture/). **Paper PHI:** If the covered entity still manages some medical records on paper, it’s essential to shred paper documents containing PHI using a cross-cut shredder to make reconstruction practically impossible. ### Implement Data Encryption: Data Encryption is a cornerstone requirement for HIPAA Data. Encrypt electronic PHI before deletion to add an extra layer of security. This ensures that even if data remnants exist, it remains unreadable without the encryption key. ### Verify Backups: Before deleting PHI, ensure that any backups containing the information are identified and securely deleted or overwritten. ### Document the Deletion Process: Maintain documentation of the deletion process, including dates, methods used, and individuals involved. This documentation is valuable for audits and demonstrating compliance. ### Work with Business Associates: If you use a third-party service provider or business associate to handle PHI, ensure they follow secure deletion and destruction practices. Include specific clauses in contracts outlining the proper disposal of PHI. ### Train Staff: Train staff on the importance of proper PHI disposal and provide clear procedure guidelines. Regularly update training to incorporate changes in technology or regulations. ### Secure Disposal of Media: If PHI is stored on physical media (CDs, DVDs, etc.), ensure secure destruction using methods such as shredding or incineration. ### Comply with State Laws: Be aware of and comply with any additional state laws regarding disposing of personal and health information, which may impose other requirements. ### Audit and Monitor: Regularly audit and monitor the deletion and destruction processes to ensure ongoing compliance. This includes using audit controls and conducting periodic checks on the effectiveness of the implemented procedures. ## What HIPAA Retention Requirements Exist for Other Documentation? Electronic Health Records and Medical notes are just part of the logging requirement. HIPAA retention requirements extend beyond electronic logs, including a broader spectrum of system data that is in scope and crucial for maintaining compliance. When drafting your Security Policy Framework, you should add specific policies related to passwords, event logging, and monitoring. Covered Entities must implement procedures for regularly reviewing records of information system activity and physical security maintenance records such as audit logs and security incident tracking reports, as mandated by [164.308(a)(1)(ii)(D)](https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/administrative/securityrule/adminsafeguards.pdf). Logging all firewall activity and monitoring wireless Access Points (APs) is essential. This comprehensive approach ensures entities have a holistic view of their networked information systems, from electronic audit trails to physical network infrastructure. ## If Business Associate Agreements Have No Fixed Time Limits, Does This Mean the Documentation Has to Be Retained Indefinitely? While the regulatory framework, including the Health Insurance Portability and Accountability Act (HIPAA), does not mandate a specific retention period for BAAs, it is essential to align document retention practices with broader compliance and security objectives. Organizations should align document retention policies with security protocols and regulatory guidelines, ensuring that records are maintained for a duration that serves historical reference and compliance needs. ## Why Is It So Important to Retain HIPAA Audit Logs? Retaining HIPAA audit logs is essential for several health and human services for crucial reasons; first and foremost, audit logs serve as a comprehensive record of system activities, providing a detailed account of access, modifications, and other critical events related to Protected Health Information (PHI). These logs act as a crucial tool for monitoring and investigating potential security incidents, ensuring the integrity and confidentiality of patient data. Continuous compliance with the Health Insurance Portability and Accountability Act (HIPAA) requires organizations to demonstrate diligence in monitoring and safeguarding PHI. Audit logs are tangible evidence of adherence to HIPAA regulations, showcasing the implementation of security measures, access controls, and incident response protocols. In the event of a security breach or an audit by regulatory authorities, retained audit logs become invaluable for forensic analysis. They enable organizations to trace the origin and impact of security incidents, aiding in identifying vulnerabilities and implementing corrective measures. Audit logs help contribute to proactive security measures by promoting the requirements of regular reviews and risk assessments of system activities. This proactive approach allows organizations to identify and address potential risks before they escalate, promoting a robust security posture. ## HIPAA Audit Log Requirements for Cloud Service Providers HIPAA log retention requirements and HIPAA audit logs are challenging to get right. This is why outsourcing HIPAA-compliant IT systems to a HIPAA Hosting Partner like Atlantic.Net is so popular. Our systems are built from the ground up to meet and exceed HIPAA’s administrative, physical, and technical requirements. Regarding audit logs, HIPAA mandates that Cloud Service Providers implement comprehensive logging practices to monitor and track activities within their cloud environments. When you sign up for Atlantic.Net HIPAA hosting, you get all this functionality straight out of the box. After an initial identification audit, where we work with the Covered Entity to discover and risk assess the location and state of PHI, we plug the client into an isolated Audit Logging platform. Our Logging Platform introduces these benefits: ### Access Monitoring: Our HIPAA-Compliant Hosting Platform and Managed Services introduce robust audit trails that monitor and log all access to electronically Protected Health Information (ePHI) stored in the cloud, including user activity details, login attempts, and modifications to sensitive data. ### Real-Time Monitoring: Continuous monitoring of all cloud systems is essential. Your chosen Managed Services Provider must implement mechanisms to capture and analyze real-time events, promptly detecting and responding to any unauthorized access or security incidents. This is achieved by creating a baseline of what is considered “normal activity” and then monitoring and reacting to potential abnormalities discovered on the network. Priority events are logged, and some events trigger automated fixes such as blocking access, while other events are triaged by a 24/7 security-focused team that filters out and determines what alerts are genuine. ### Data Integrity and Modification Tracking: Audit logs should provide a clear record of any changes made to ePHI, ensuring data integrity. This includes tracking alterations, deletions, and additions to electronic health records or stored health information. ### User Accountability: The Managed Service Provider must associate each audit log activity with a specific user identifier. This ensures accountability, allowing organizations to trace unauthorized or inappropriate access right down to the individual user. ### Encryption and Secure Storage: HIPAA requires that audit logs be stored securely and protected against unauthorized access. This often involves encrypting the logs and implementing secure storage practices to prevent tampering or alteration. If you choose to output logging to a third-party tool like Elastic, the same encryption policy extends to those applications, too. ### Retrieval and Analysis: Mechanisms must be in place to retrieve and analyze audit logs. Typically, this would be your IT department, or if you outsource the service, it will be your managed service provider. This is crucial during compliance audits or investigations, enabling organizations to demonstrate adherence to HIPAA requirements. ### Log Retention Period: While HIPAA does not specify a fixed retention period for audit logs, the Managed Service Provider must define and adhere to a reasonable timeframe to review audit logs. This duration should consider operational needs, compliance requirements, and the ability to support forensic analysis. ### Business Associate Agreements (BAAs): The Managed Service Provider must enter into a [Business Associate Agreement](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) with covered entities to outline the responsibilities and obligations concerning the handling of ePHI, including the implementation of security system reviews and maintenance of audit logs. ## Final Thoughts We have covered a lot of information in this article, so it’s essential to conclude the key points about HIPAA log retention requirements. Safeguarding patient data under HIPAA isn’t just a regulatory requirement; it’s the heartbeat of ethical healthcare practices. The journey through HIPAA log retention requirements unveils a complex environment where precision logging meets professional responsibility. Each logged event isn’t just a timestamp; it’s a record to protect and uphold patient trust, ensuring their information remains safe and accurate. A robust and proven platform must comply with HIPAA logging data retention and secure deletion requirements. Covered entities must validate their audit logs, providing evidence of conformity with the rules. It’s also about demonstrating a commitment to patient care and embracing a culture prioritizing privacy and integrity. Covered entities and business associates need to work together to embrace the changing requirements of Healthcare. From the secure destruction of paper PHI to the encryption of electronic records, every note resonates with the melody of patient confidentiality. Crucially, the role of cloud service providers is essential to successful HIPAA compliance. Entrusting HIPAA-compliant IT systems to experts like [Atlantic.Net](https://www.youtube.com/watch?v=-ixv6hivl4g) isn’t just outsourcing; it’s forging a partnership where compliance is a shared journey. It’s a commitment to real-time monitoring, proactive logging, and a collective responsibility to ensure that the sanctity of Protected Health Information endures. ## Atlantic.Net HIPAA Logging Atlantic.Net is a trusted HIT provider. Our clients trust us because we are experts on the subject and are fully transparent in all communications, as evidenced by this customer testimonial below: “Atlantic.Net’s reputation for 100% up-time, their secure infrastructure, and expertise in Healthcare IT were key components in finalizing our partnership,” said Complete Healthcare Solutions Vice President Joseph Nompleggi. Contact us today to see if we can help you meet your HIPAA compliance needs with any of our award-winning [HIPAA-compliant hosting or Dedicated Hosting](https://www.atlantic.net/hipaa-compliant-hosting/).   --- # Singapore Cloud & Dedicated Server Hosting with Atlantic.Net > URL: https://www.atlantic.net/hipaa-data-centers/singapore-hosting/ | Updated: 2026-09-16 ## Atlantic.Net Singapore Cloud Hosting Atlantic.Net's newest home is a state-of-the-art data center in Singapore's western business district. Singapore is a vibrant, multicultural Southeast Asian city-state renowned for its economic success, cleanliness, and iconic skyline. Atlantic.Net proudly offers all our award-winning cloud and VPS capabilities from the Singapore cloud data center exchange. Some of our service highlights include: - The Atlantic.Net Cloud Platform - Dedicated Cloud Hosts - Compliant Cloud Hosting Options - A Wide Range of Affordable Managed Services The site was completed in late 2022. The brand-new nine-story facility operates on 100% renewable energy, making it the cleaner, more sustainable choice for environmentally conscious businesses. ## Singapore SG5 IBX Atlantic.Net is one of the very first tenants in this modern, cutting-edge data center. We are partnering with the world's leading communications provider, Equinix, to deliver world-class cloud services and dedicated hosting options to a global audience. The Singapore SG5 site is uniquely located at an International Business Exchange (IBX) and offers unparalleled connectivity to 70 global Internet backbones. This hyper-connected site ensures your web applications and websites enjoy full bandwidth, exceptional speeds, and global reach connectivity. ## Singapore SG5 IBX Highlights Our Singapore cloud hosting site is designed to incorporate the highest reliability, sustainability, and security standards. Let's take a closer look at some of the highlights of this brand-new location: ### Resilience and Uptime Continuous Backup Power: Space is usually at a premium in Singapore, so the data center designers have cleverly placed the backup generators and high-efficiency water-cooled chillers on the roof to optimize space and cooling efficiency. Underground diesel fuel storage and lithium-ion UPS systems (known for their compact footprint) provide additional layers of redundancy, supporting continuous operation even during prolonged power outages. The clever design allows Atlantic.Net to maximize the space within our suites and offer great value for money to our customers. Redundancy Built In: All Atlantic.Net cloud-hosted servers in Singapore come with our class-leading 100% uptime SLA guarantee. We have invested heavily in the data center's redundancy features to make this guarantee work. The 2N / N+1 electrical system redundancy and N+1 cooling redundancy mean critical systems have at least two power feeds continuously supplying power and are ready to take over seamlessly in the event of a power interruption. All of this happens seamlessly in the background, minimizing the risk of downtime and helping to keep your infrastructure operational 24x7x365, even in the face of unexpected disruptions. ### Sustainability Green Mark Certification: The Green Mark Certification, established in 2005, is Singapore's benchmark for evaluating a building's environmental performance. This comprehensive rating system assesses factors such as energy efficiency, resource conservation, and indoor environmental quality, encouraging sustainable design and operation. The Green Mark certification underscores Atlantic.Net's dedication to sustainability, signifying that the facility has met rigorous standards for minimizing environmental impact while maximizing operational efficiency. ISO 50001 Certification: ISO 50001, a globally recognized energy management standard, highlights the Singapore data center's focus on continuously improving energy performance, reducing consumption, and lowering greenhouse gas emissions. ### Security and Compliance MAS TRM Compliance: Our Singapore cloud hosting site adheres to the Technology Risk Management (TRM) guidelines set by the Monetary Authority of Singapore (MAS), supporting financial institutions and other users of sensitive data. ISO 27001 Certification: This widely recognized information security management standard demonstrates Atlantic.Net Singapore's commitment to protecting customer data and maintaining a secure operating environment. PCI DSS Compliance: This certification validates that our Singapore cloud hosting site meets the strict security requirements for handling credit card information, providing peace of mind for ecommerce and financial-services customers. When combined with our ISO and TRM compliance, a Singapore cloud server supports the highest standards of financial-transaction security. ### Other Key Certifications ISO 14001: we uphold a rigorous environmental management system, minimizing our ecological footprint and promoting sustainability. ISO 22301: our business continuity management system supports resilience against disruptions, safeguarding your critical operations. ISO 9001: we maintain a robust quality management system, supporting consistent service delivery and customer satisfaction. OSPAR: we comply with stringent regulations for outsourced service providers in financial services, demonstrating our commitment to security and risk management. SOC 1 Type II and SOC 2 Type II: these reports validate our internal controls over financial reporting and your data's security, availability, processing integrity, confidentiality, and privacy. SS 564: our facility is built and operated according to the Singapore Standard for Green Data Centres, supporting energy efficiency and environmental responsibility. These comprehensive certifications attest to Atlantic.Net Singapore's excellent design and assure customers that their critical workloads are housed in a facility that meets high global standards for reliability, security, and sustainability. ## Singapore Cloud Hosting Plans Our Singapore cloud hosting plans are tailored to meet diverse needs, from individuals seeking to host multiple websites to enterprises demanding dedicated resources. Whether you're a Singapore cloud hosting newcomer or an experienced user, our versatile options have you covered. With SSD storage for fast performance as standard, ultra-high bandwidth, and high throughput, we deliver an optimal user experience for users across Asia. Our virtual private server offerings are designed to provide the performance, flexibility, and security you need for your online presence: ### General Purpose Cloud Hosting A user-friendly option ideal for web hosting, smaller databases, development environments, and projects with moderate resource requirements. Benefit from a user-friendly control panel and full control over your cloud server. ### Storage Optimized Cloud Hosting Designed for data-intensive applications needing ample SSD storage. Perfect for large databases, data warehousing, CDNs, and applications demanding high I/O operations. ### Memory Optimized Cloud Hosting Built for high-performing web applications that rely on vast memory resources. Ideal hosting for high-traffic websites, real-time analytics, in-memory databases, and caching servers. ### Compute Optimized Cloud Hosting Engineered for computationally demanding tasks that require raw processing power. Perfect for video encoding, machine learning, scientific simulations, big-data analysis, and any resource-intensive application where CPU performance is paramount. ## Available Operating Systems Atlantic.Net has many one-click applications and operating systems that deploy in under 30 seconds. Need a Linux server? Just give it a name, pick your plan and location, and hit deploy. You will be able to connect to the server in under 30 seconds. See how fast you can do it. Why not [give it a try now](https://cloud.atlantic.net/?page=userlogin)? ## Linux Take advantage of the most popular open-source Linux distributions available for your virtual private server, such as: - Ubuntu 16.04 LTS Server 32-bit - Ubuntu 16.04 LTS Server 64-bit - Ubuntu 18.04 LTS Server 64-bit - Ubuntu 20.04 LTS Server 64-bit - Ubuntu 22.04 LTS Server 64-bit - Ubuntu 24.04 LTS Server 64-bit - Ubuntu 26.04 LTS Server 64-bit - Debian 11.11.0 Server 64-bit - Debian 12.11.0 Server 64-bit - Debian 13.0.0 Server 64-bit - Oracle Linux 7.9 64-bit - Oracle Linux 8.10 64-bit - Oracle Linux 9.6 64-bit - Oracle Linux 10.0 64-bit - Rocky Linux 8.10 64-bit - Rocky Linux 9.6 64-bit - Rocky Linux 10.0 64-bit - CentOS 6.9 Server 32-bit - CentOS 6.9 Server 64-bit - CentOS 7.9 Server 64-bit - CentOS 8.2 Server 64-bit - Fedora 42 Server 64-bit - FreeBSD 13.0 Server 64-bit - Arch Linux Server 64-bit - AlmaLinux 8.10 64-bit - AlmaLinux 9.6 64-bit - AlmaLinux 10.0 64-bit - cPanel/WHM on AlmaLinux 64-bit We offer 32-bit and 64-bit editions of most of our Linux options for maximum compatibility. ## Windows Server We offer all major versions and editions of Microsoft Server if you prefer this operating system: - Windows Server 2025 Datacenter (Desktop Experience) - Windows Server 2025 Datacenter - Windows Server 2022 Datacenter (Desktop Experience) - Windows Server 2022 Datacenter - Windows Server 2019 Datacenter (Desktop Experience) - Windows Server 2019 Datacenter - Windows Server 2016 Datacenter (with Containers / Docker) - Windows Server 2016 Datacenter - Windows Server 2012 R2 Datacenter (Desktop Experience) - Windows Server 2012 R2 Datacenter - Windows Server 2008 R2 SP1 Datacenter ## Compliance Cloud Hosting Atlantic.Net is famous for its world-leading compliant cloud hosting services. Our Singapore cloud hosting prioritizes data security and compliance. We adhere to ISO 14001, ISO 27001, ISO 9001, PCI DSS, Privacy Shield, SOC 2, SOC 2 Type 2, and SOC 3 for a secure cloud hosting environment. Tailor your virtual private server solution to your unique requirements with our specialized options: - PCI-ready platforms: for secure payment processing environments. - HIPAA / HITECH-approved hosting: specifically designed for healthcare providers and their partners. - CCPA and GDPR-compliant cloud servers: ensuring your business adheres to global data privacy standards. ## Beyond Virtual Private Server: Dedicated Servers and More Our Singapore-based dedicated hosts offer unparalleled performance and complete isolation for businesses and projects with the most demanding requirements. Unlike shared hosting or cloud solutions where resources are shared among multiple users, a dedicated server gives you exclusive access to the entire server's processing power, memory, and storage. This translates to high speed, reliability, and customization options, making dedicated servers ideal for high-traffic websites, resource-intensive applications, big data analytics, and mission-critical operations. With our dedicated hosts in Singapore, you get: Strong performance: fast hardware, SSD storage (NVMe options available), and ultra-fast networking complete the package. Complete isolation: your server is not shared with anyone else, supporting maximum security, compliance, and stability over shared servers. Customization flexibility: tailor your server's hardware and software configurations to your exact specifications. Our dedicated host plans offer a wide range of Singapore cloud hardware. Scalability: easily upgrade your server resources as your needs evolve, even on our dedicated hosts. Security, support, and peace of mind: your online security is our top priority. We employ resolute security measures, including DDoS protection and SSL certificates, to safeguard your data and support smooth operation of your Singapore cloud server hosting. Our expert support team is available 24/7 to assist you with any questions. ## Singapore Cloud Servers: Key Features & Benefits Our Singapore-based virtual private servers (VPSes) are built on cutting-edge cloud computing technology and offer high performance, security, and scalability. Unmatched connectivity: direct access to numerous network carriers supports fast and reliable connections across Asia and the globe. High performance: SSD storage, dedicated resources, and low latency support optimal performance for your website and applications. Full root access: customize your cloud server to meet your exact requirements, giving you complete control. 24/7 expert support: our team of experts is available 24/7 to assist you with any questions or concerns. Developer-friendly: we are a cloud hosting provider that puts developers first. We fast-track deployments with one-click installations of popular applications like WordPress, cPanel, and MySQL, helping streamline the development lifecycle and speed up deployment. Scalable resources: easily upgrade your cloud resources as your website, application, and business grow. Secure cloud hosting: choose managed security measures, such as DDoS prevention and intrusion-protection systems, to protect your website and data from unauthorized access. Affordable pricing: our Singapore cloud hosting plans are competitively priced with no hidden fees. You can get deeper discounts when committing to one, two, or three years of hosting. User-friendly control panel: our intuitive control panel makes it easy to manage your cloud server, install popular applications, monitor your resources, and manage block storage, DNS, team users, logs, and more. Dedicated IP: get a dedicated IP address for enhanced security and SEO. Wide range of operating systems: choose from a variety of Linux and Microsoft Windows operating systems. ## Why Choose Atlantic.Net in Singapore? Atlantic.Net's Singapore cloud services are a strong choice for enterprise-scale, medium, and small businesses, developers, and anyone looking for a high-performance, user-friendly cloud hosting solution. Our Singapore-based servers offer low latency and exceptional connectivity throughout Asia, making them ideal for businesses targeting Singapore-based users and Asian markets. ## Ready to Get Started? [Contact our team today](https://www.atlantic.net/about-us/corporate-contact/) to learn more about our Singapore cloud hosting services, or create an account to spin up your cloud server right now. ## Singapore Data Center FAQ ### Where is the Atlantic.Net Singapore data center located? The Atlantic.Net Singapore facility is hosted in Equinix's SG5 IBX in Singapore's western business district. The nine-story site was completed in late 2022. ### Is the Singapore data center MAS TRM compliant? Yes. The Singapore facility adheres to the Monetary Authority of Singapore (MAS) Technology Risk Management (TRM) guidelines and complies with OSPAR for outsourced service providers in financial services. ### What sustainability credentials does the Singapore facility have? The site operates on 100% renewable energy and holds Singapore's Green Mark certification, ISO 50001 (energy management), ISO 14001 (environmental management), and SS 564 (Singapore Standard for Green Data Centres). ### What power and cooling redundancy does Singapore provide? 2N / N+1 electrical system redundancy with lithium-ion UPS, underground diesel fuel storage, and rooftop diesel backup generators. Cooling uses N+1 redundancy with rooftop water-cooled chillers for optimized space and efficiency. ### What network connectivity does the Singapore facility offer? The Equinix SG5 site is an International Business Exchange (IBX) with direct access to 70 global Internet backbones, supporting full bandwidth, low latency, and global reach for customers across Asia and beyond. ### Is the Singapore facility PCI DSS and ISO 27001 compliant? Yes. The Singapore facility holds ISO 27001 (information security management), ISO 9001 (quality management), ISO 22301 (business continuity), PCI DSS, SOC 1 Type II, and SOC 2 Type II certifications. ### What hosting options are available in Singapore? Cloud VPS hosting (4 plan classes: General Purpose, Storage Optimized, Memory Optimized, Compute Optimized), dedicated cloud hosts, HIPAA-aware compliance hosting, and a full suite of managed services. Linux (40+ distributions) and Windows Server (14 versions) are supported. If you’re interested in hosting in this data center region, contact an advisor at 866.618.3282 or email us [sales@atlantic.net](mailto:sales@atlantic.net). Atlantic.Net provides world-class hosting services and solutions at eight global data center regions in our [New York](https://www.atlantic.net/hipaa-data-centers/new-york-hosting/), [London](https://www.atlantic.net/hipaa-data-centers/london-uk-hosting/), [San Francisco](https://www.atlantic.net/hipaa-data-centers/san-francisco-california-hosting/), [Orlando](https://www.atlantic.net/orlando-colocation-hosting-data-center/), [Ashburn](https://www.atlantic.net/hipaa-data-centers/ashburn-virginia-hosting/), [Toronto](https://www.atlantic.net/hipaa-data-centers/toronto-canada-hosting/), [Singapore](https://www.atlantic.net/hipaa-data-centers/singapore-hosting/), and [Dallas](https://www.atlantic.net/hipaa-data-centers/dallas-texas-hosting/) locations. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # How to Install Zeek Network Security Monitoring Tool on Ubuntu 24.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-zeek-network-security-monitoring-tool-on-ubuntu-24-04/ | Published: 2024-02-22 | Updated: 2025-05-22 | Author: Hitesh Jethva Zeek, formerly known as Bro, is an open-source network security monitoring tool used to analyze network traffic in real-time. It captures packets and interprets their contents to provide insights into the activities and behaviors occurring on a network. Zeek Network Security Monitoring offers a powerful and flexible solution for organizations seeking to enhance their network security posture by gaining deeper insights into network traffic and detecting potential threats in real time. In this tutorial, we will show you how to install the Zeek tool on Ubuntu 24.04. ## Step 1 – Install Zeek The Zeek package is not included in the Ubuntu default repository, so you will need to add Zeek’s official repository to APT. First, download the Zeek GPG key. ``` curl -fsSL https://download.opensuse.org/repositories/security:zeek/xUbuntu_22.04/Release.key | gpg --dearmor | tee /etc/apt/trusted.gpg.d/security_zeek.gpg ``` Next, add the Zeek repository to the APT source file. ``` echo 'deb http://download.opensuse.org/repositories/security:/zeek/xUbuntu_24.04/ /' | tee /etc/apt/sources.list.d/security:zeek.list ``` Then, update the repository index and install Zeek using the following command. ``` apt update -y apt install zeek -y ``` Once the Zeek is installed, add Zeek path to .bashrc file. ``` echo "export PATH=$PATH:/opt/zeek/bin" >> ~/.bashrc ``` Reload the .bashrc file using the following command. ``` source ~/.bashrc ``` Next, verify the Zeek version using the following command. ``` zeek --version ``` Output. ``` zeek version 7.2.1 ``` ## Step 2 – Configure Zeek Zeek default configuration file is located at /opt/zeek/etc/networks.cfg. You can edit it using the nano editor. ``` nano /opt/zeek/etc/networks.cfg ``` Add your internal network as shown below: ``` 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 ``` Then, edit the Zeek node.cfg configuration file. ``` nano /opt/zeek/etc/node.cfg ``` Comment out the following line: ``` #[zeek] #type=standalone #host=localhost #interface=eth0 ``` Then, add the following configurations. ``` [zeek-logger] type=logger host=your-server-ip # [zeek-manager] type=manager host=your-server-ip # [zeek-proxy] type=proxy host=your-server-ip # [zeek-worker] type=worker host=your-server-ip interface=eth0 [zeek-worker-lo] type=worker host=localhost interface=lo ``` Save and close the file, then apply the above configurations using the following command. ``` zeekctl deploy ``` You will see the following output. ``` checking configurations ... installing ... creating policy directories ... installing site policies ... generating cluster-layout.zeek ... generating local-networks.zeek ... generating zeekctl-config.zeek ... generating zeekctl-config.sh ... stopping ... stopping workers ... stopping proxy ... stopping manager ... stopping logger ... starting ... starting logger ... starting manager ... starting proxy ... starting workers ... ``` You can check Zeek’s status using the **zeekctl** command. ``` zeekctl status ``` Output. ``` Name Type Host Status Pid Started zeek-logger logger 69.28.90.163 running 36001 23 May 04:28:12 zeek-manager manager 69.28.90.163 running 36066 23 May 04:28:15 zeek-proxy proxy 69.28.90.163 running 36119 23 May 04:28:17 zeek-worker worker 69.28.90.163 running 36194 23 May 04:28:19 zeek-worker-lo worker localhost running 36193 23 May 04:28:18 ``` ## Step 3 – Check Zeek Log Files By default, Zeek stores all log files at /opt/zeek/logs/current/. To see Zeek log files, run the following command. ``` ls -l /opt/zeek/logs/current/ ``` Output. ``` -rw-r--r-- 1 root zeek 1780 May 23 04:28 broker.log -rw-r--r-- 1 root zeek 1959 May 23 04:28 cluster.log -rw-r--r-- 1 root zeek 7895 May 23 04:29 conn.log -rw-r--r-- 1 root zeek 34524 May 23 04:28 loaded_scripts.log -rw-r--r-- 1 root zeek 209 May 23 04:28 packet_filter.log -rw-r--r-- 1 root zeek 666 May 23 04:28 reporter.log -rw-r--r-- 1 root zeek 621 May 23 04:28 stats.log -rw-r--r-- 1 root zeek 0 May 23 04:28 stderr.log -rw-r--r-- 1 root zeek 204 May 23 04:28 stdout.log -rw-r--r-- 1 root zeek 14391 May 23 04:29 telemetry.log -rw-r--r-- 1 root zeek 373 May 23 04:28 weird.log ``` Verify the Zeek cluster log file using the following command. ``` tail /opt/zeek/logs/current/cluster.log ``` Output. ``` 1709522449.760873 zeek-proxy got hello from zeek-worker (acda2560-8dd9-5192-9685-c430eb02c0aa) 1709522449.658879 zeek-worker got hello from zeek-proxy (d613130f-325e-5fc7-b3a1-82cf36ff604e) 1709522449.658879 zeek-worker got hello from zeek-manager (c31e3478-95d4-5eaa-8013-1953462da48b) 1709522449.658879 zeek-worker got hello from zeek-logger (0bc1f618-7d7a-53bf-b751-f2681f78ba4e) 1709522454.919369 zeek-logger got hello from zeek-worker-lo (853e3648-641e-5adb-8859-9b71f0cf4a6c) 1709522454.957199 zeek-proxy got hello from zeek-worker-lo (853e3648-641e-5adb-8859-9b71f0cf4a6c) 1709522454.915454 zeek-manager got hello from zeek-worker-lo (853e3648-641e-5adb-8859-9b71f0cf4a6c) ``` To check the Zeek connection status, run the following command. ``` tail /opt/zeek/logs/current/conn.log ``` Output. ``` 1709522458.533596 CghW2m4QTLngSVYKsl fe80::eaa2:4500:df31:71a0 135 ff02::1:ff00:bee 136 icmp - 2.001871 72 0 OTH T F 0 - 3 216 0 0 - 1709522460.758169 CLHor419mmTNILP5hc 2607:f170:14:12::f60 135 ff02::1:ff00:1 136 icmp - - - - OTH F F 0- 1 72 0 0 - ``` If you want to stop the Zeek, run the following command. ``` zeekctl stop ``` ## Conclusion By following the step-by-step installation guide outlined in this article, users can deploy Zeek on Ubuntu 24.04 and begin leveraging its capabilities to enhance their network security posture, detect malicious activities, and safeguard critical assets against cyber threats. Try to deploy Zeek on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install a CockroachDB Cluster on Ubuntu 22.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-a-cockroachdb-cluster-on-ubuntu-22-04/ | Published: 2024-02-23 | Updated: 2024-06-04 | Author: Hitesh Jethva CockroachDB is a distributed SQL database designed to handle large-scale, mission-critical applications with high availability and scalability requirements. One of its key features is its ability to create resilient clusters that can withstand failures and maintain data consistency across multiple nodes and data centers. This post will show you how to deploy a three-node CockroachDB cluster on Ubuntu 22.04. ## Prerequisites We will use the following IP addresses to demonstrate this tutorial. - **server1:** 172.16.0.10 - **server2:** 172.16.0.11 - **server3:** 172.16.0.12 ## Step 1 – Setup Time Synchronization Before starting, you will need to set up time synchronization between all servers. You can achieve it by setting up Chrony on each server. First, install the Chrony package on all servers. ``` apt update -y apt -y install chrony ``` Once installed, edit the Chrony configuration file. ``` nano /etc/chrony/chrony.conf ``` Remove default pools and add the following pools: ``` pool 0.id.pool.ntp.org iburst maxsources 4 pool 1.id.pool.ntp.org iburst maxsources 1 pool 2.id.pool.ntp.org iburst maxsources 1 pool 3.id.pool.ntp.org iburst maxsources 2 ``` Save and close the file, then restart the Chrony service to apply the changes. ``` systemctl restart chrony ``` ## Step 2 – Install CockroachDB Next, you will need to install CockroachDB on all servers. Follow the below steps to install CockroachDB on all servers. First, download the CockroachDB from their official website. ``` wget https://binaries.cockroachdb.com/cockroach-latest.linux-amd64.tgz ``` Next, extract the downloaded file. ``` tar -xvzf cockroach-latest.linux-amd64.tgz ``` Then, copy the extracted binary to the system location. ``` cp cockroach-*/cockroach /usr/local/bin/ ``` Next, verify the CockroachDB version using the following command. ``` cockroach version ``` Output. ``` Build Tag: v23.2.1 Build Time: 2024/02/15 22:46:26 Distribution: CCL Platform: linux amd64 (x86_64-pc-linux-gnu) Go Version: go1.21.5 X:nocoverageredesign C Compiler: gcc 6.5.0 Build Commit ID: 898cd6a363fd47bb92a03bac216f9bed0f64bc08 Build Type: release Enabled Assertions: false ``` ## Step 3 – Create Certificates for CockroachDB You will also need to generate server and client certificates for secure communication between all servers. First, create a certificate directory on all servers. ``` mkdir ~/certs ``` On server1, create a CA certificate. ``` cockroach cert create-ca --certs-dir=certs --ca-key=certs/ca.key ``` Next, copy the generated certificate to server2 and server3. ``` scp ~/certs/ca.crt ~/certs/ca.key root@172.16.0.11:~/certs/ ``` ``` scp ~/certs/ca.crt ~/certs/ca.key root@172.16.0.12:~/certs/ ``` Next, create a client certificate on all servers using the following command. ``` cockroach cert create-client root --certs-dir=certs --ca-key=certs/ca.key ``` On the server1, run the following command to generate the server certificate: ``` cockroach cert create-node localhost $(hostname) 172.16.0.10 --certs-dir=certs --ca-key=certs/ca.key ``` On the server2, run the following command to generate the server certificate: ``` cockroach cert create-node localhost $(hostname) 172.16.0.11 --certs-dir=certs --ca-key=certs/ca.key ``` On the server3, run the following command to generate the server certificate: ``` cockroach cert create-node localhost $(hostname) 172.16.0.12 --certs-dir=certs --ca-key=certs/ca.key ``` You can verify all generated certificates using the following command. ``` cockroach --certs-dir=certs cert list ``` Output. ``` Certificate directory: certs Usage | Certificate File | Key File | Expires | Notes | Error ---------+------------------+-----------------+------------+------------------------------------------+-------- CA | ca.crt | | 2034/03/12 | num certs: 1 | Node | node.crt | node.key | 2029/03/08 | addresses: localhost,node1,172.16.0.10 | Client | client.root.crt | client.root.key | 2029/03/08 | user: root | (3 rows) ``` ## Step 4 – Start CockroachDB Cluster Now, CockroachDB is installed and ready to start. Run the following command on server1 to start the CockroachDB cluster. ``` cockroach start --background --certs-dir=certs --advertise-host=172.16.0.10 --join=172.16.0.10,172.16.0.11,172.16.0.12 --background ``` Output. ``` * * WARNING: Running a server without --sql-addr, with a combined RPC/SQL listener, is deprecated. * This feature will be removed in a later version of CockroachDB. * * * INFO: initial startup completed. * Node will now attempt to join a running cluster, or wait for `cockroach init`. * Client connections will be accepted after this completes successfully. * Check the log file(s) for progress. * ``` Next, initialize the cluster with the following command. ``` cockroach init --certs-dir=certs --host=172.16.0.10 ``` You can verify the cluster listening port using the following command. ``` ss -antpl | grep 26257 ``` Output. ``` LISTEN 0 4096 *:26257 *:* users:(("cockroach",pid=15951,fd=27)) ``` To check the status of the cluster, run the following command. ``` cockroach node status --certs-dir=certs --host=172.16.0.10 ``` Output. ``` id | address | sql_address | build | started_at | updated_at | locality | is_available | is_live -----+---------------------+---------------------+---------+--------------------------------------+--------------------------------------+----------+--------------+---------- 1 | 172.16.0.10:26257 | 172.16.0.10:26257 | v23.2.1 | 2024-03-04 04:25:16.433259 +0000 UTC | 2024-03-04 04:25:31.579729 +0000 UTC | | true | true (1 row) ``` ## Step 5 – Add Remaining Server to CockroachDB Cluster On server2, run the following command to add server2 to the cluster. ``` cockroach start --background --certs-dir=certs --advertise-host=172.16.0.11 --listen-addr=172.16.0.11 --join=172.16.0.10:26257 ``` On server3, run the following command to add server3 to the cluster. ``` cockroach start --background --certs-dir=certs --advertise-host=172.16.0.12 --listen-addr=172.16.0.12 --join=172.16.0.10:26257 ``` Now, go to server1 and check the cluster status again. ``` cockroach node status --certs-dir=certs --host=172.16.0.10 ``` You will see all servers added to the cluster. ``` id | address | sql_address | build | started_at | updated_at | locality | is_available | is_live -----+---------------------+---------------------+---------+--------------------------------------+--------------------------------------+----------+--------------+---------- 1 | 172.16.0.10:26257 | 172.16.0.10:26257 | v23.2.1 | 2024-03-04 04:25:16.433259 +0000 UTC | 2024-03-04 04:26:28.617658 +0000 UTC | | true | true 2 | 172.16.0.11:26257 | 172.16.0.11:26257 | v23.2.1 | 2024-03-04 04:25:55.477023 +0000 UTC | 2024-03-04 04:26:28.735681 +0000 UTC | | true | true 3 | 172.16.0.12:26257 | 172.16.0.12:26257 | v23.2.1 | 2024-03-04 04:26:19.050073 +0000 UTC | 2024-03-04 04:26:31.148184 +0000 UTC | | true | true (3 rows) ``` ## Step 6 – Access CockroachDB Web UI CockroachDB also offers a web interface to monitor the cluster. First, go to server1 and log in to the CockroachDB shell. ``` cockroach sql --certs-dir=certs --host=172.16.0.10 ``` Next, create an admin username and password. ``` CREATE USER hitesh WITH PASSWORD 'securepassword'; ``` Then, exit from the CockroachDB shell. ``` exit; ``` Now, open your web browser and access the CockroachDB web interface using the URL **https://server1-ip-address:8080.** You will see the CockroachDB login page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p1.png) Provide your admin username and password and click on **Log in.** You will see the CockroachDB dashboard on the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p2.png) ## Step 7 – Test Database Replication After setting up the CockroachDB cluster, you will need to check whether or not the database is replicated between all servers. On Server1, log in to the CockroachDB shell. ``` cockroach sql --certs-dir=certs --host=172.16.0.10 ``` Create some databases using the following command. ``` create database testdb1; create database testdb2; ``` Now, verify the created databases. ``` show databases; ``` Output. ``` database_name | owner | primary_region | secondary_region | regions | survival_goal ----------------+-------+----------------+------------------+---------+---------------- defaultdb | root | NULL | NULL | {} | NULL postgres | root | NULL | NULL | {} | NULL system | node | NULL | NULL | {} | NULL testdb1 | root | NULL | NULL | {} | NULL testdb2 | root | NULL | NULL | {} | NULL ``` Next, go to server2 and log in to the CockroachDB shell. ``` cockroach sql --certs-dir=certs --host=172.16.0.11 ``` Now, verify whether the databases you created on server1 are replicated. ``` show databases; ``` You will see all databases in the following output. ``` database_name | owner | primary_region | secondary_region | regions | survival_goal ----------------+-------+----------------+------------------+---------+---------------- defaultdb | root | NULL | NULL | {} | NULL postgres | root | NULL | NULL | {} | NULL system | node | NULL | NULL | {} | NULL testdb1 | root | NULL | NULL | {} | NULL testdb2 | root | NULL | NULL | {} | NULL ``` ## Conclusion Overall, CockroachDB clusters offer a powerful and scalable solution for building highly available, distributed databases that can handle the demands of modern applications and workloads. Whether powering global-scale applications or providing real-time analytics, CockroachDB clusters provide the resilience, scalability, and performance required by today’s distributed systems. Try to deploy the CockroachDB cluster on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # HIPAA Contractor Agreements: A Practical Guide > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-contractor-agreements-a-practical-guide/ | Published: 2024-02-24 | Updated: 2025-09-11 | Author: Gilad Maayan ## What Is a HIPAA Contractor Agreement (Also Known as BAA)? A HIPAA contractor agreement, also known as a Business Associate Agreement (BAA), is a legal contract between a healthcare provider and a [third-party independent contractor](https://enterprise.fiverr.com/blog/what-is-an-independent-contractor/). This agreement ensures the contractor will appropriately safeguard any protected health information (PHI) they handle in the course of their work. The need for a HIPAA contractor agreement arises from the Health Insurance Portability and Accountability Act of 1996 (HIPAA). This act established national standards to protect sensitive patient health information from being disclosed without the patient’s consent. Any entity that deals with PHI must ensure all the required physical, network, and process security measures are in place and followed. The HIPAA contractor agreement is not just a legal necessity; it is also a practical tool for defining responsibilities and obligations. It helps contractors understand the seriousness of handling PHI and the repercussions of any breach. It also provides healthcare providers with assurance that their contractors are compliant and that patient data is in safe hands. ![](https://www.atlantic.net/wp-content/uploads/2024/02/HIPAA-Contractor-Agreement.jpg) ## Use Cases for HIPAA Contractor Agreements Here are a few scenarios in which your organization might need a HIPAA contractor agreement: ### IT and Network Security Professionals As the healthcare industry becomes increasingly digital, the role of IT and network security professionals has become more important than ever. These professionals are often responsible for building and maintaining the infrastructure that houses PHI. They may have access to this sensitive data during the course of their work. In this scenario, a HIPAA contractor agreement is crucial. It ensures that these professionals are aware of their responsibility to protect PHI, and it lays out the specific measures they must take to ensure data security. ### Medical Transcription Services Medical transcription services, which convert spoken medical reports into written documents, also have access to PHI. Due to the nature of their work, they might often deal with highly sensitive patient information. A HIPAA contractor agreement in this case ensures these services are aware of their obligations under HIPAA. It also provides a framework for the steps they must take to ensure the confidentiality, integrity, and accessibility of the PHI they handle. ### Cloud Storage Providers and Data Processing Vendors More and more healthcare providers are turning to cloud storage solutions and data processing vendors to manage their growing volumes of data. These entities may have access to, or be responsible for the storage and processing of, PHI. A HIPAA contractor agreement between healthcare providers and these entities is essential. It ensures that they understand their obligations to protect PHI and provides guidelines for how they should do so. ### Legal Services Legal professionals who work with healthcare providers may also have access to PHI, especially in cases involving medical malpractice or personal injury. These professionals must therefore also be covered by a HIPAA contractor agreement. This agreement ensures that the legal professionals understand their obligations under HIPAA. It outlines how they should safeguard PHI and the consequences if they fail to do so. ## Key Components of a HIPAA Contractor Agreement The HIPAA regulation requires that a Business Associate Agreement (BAA) include the following: ### Definitions and Scope This section defines key terms and outlines the scope of the agreement, including what constitutes PHI, the roles and responsibilities of both parties, and the purpose of the agreement. The definitions and scope should be clear and concise. They should leave no room for ambiguity and should be specific to the services provided by the contractor. ### Obligations and Activities of the Business Associate This section outlines the specific duties and responsibilities of the contractor in relation to the handling, use, and disclosure of PHI. This section should detail the specific activities the contractor will perform, how they will handle PHI, and the safeguards they will implement to protect the data. It should also outline the contractor’s obligations in the event of a data breach, including notification and remediation procedures. ### Safeguards for PHI Protection This section outlines the specific measures the contractor will take to protect PHI from unauthorized access, use, disclosure, alteration, and destruction. The safeguards section should detail the physical, technical, and administrative measures the contractor will implement. These may include secure data transmission protocols, encryption, access controls, employee training, and regular audits. ### Reporting of PHI Breaches One major component of a BAA is the stipulation for prompt reporting of PHI breaches. To comply with HIPAA, the agreement must clearly establish the timeframe and procedure for notifying the covered entity in case of any breach or unauthorized use of PHI. This reporting obligation is not only necessary to minimize harm but also to help the covered entity meet its own reporting obligations under HIPAA. Moreover, the agreement should also specify the information required in the breach notification. Typically, it includes the nature of the breach, the type of PHI involved, the individuals affected, and the corrective actions taken by the contractor. Having such a provision in place reinforces accountability and helps in mitigating the consequences of a breach. ### Subcontractors If a business associate delegates tasks involving PHI to a subcontractor, the agreement must extend HIPAA obligations to them. The subcontractor should be required to comply with the same privacy and security measures as the primary business associate. The agreement should also demand that the business associate enter into a similar agreement with the subcontractor. This requirement ensures that the subcontractor is legally bound to adhere to HIPAA rules, thus maintaining the security and confidentiality of PHI throughout the chain of custody. ### Amendment and Termination The procedures for amending or terminating the contract must also be clearly laid out in a BAA. Changes in regulations, business practices, or the nature of the services provided may necessitate adjustments to the agreement. The parties should have a clear understanding of how to make these amendments, which typically require mutual consent. For termination, the agreement should specify the conditions under which either party can terminate the contract. It should also detail the procedures for returning or destroying PHI upon termination. This is critical to ensure that PHI does not fall into the wrong hands after the contract ends. ### Compliance with HIPAA Rules The agreement should also clearly state that the contractor must comply with all applicable HIPAA rules. This includes the Privacy Rule, which sets standards for protecting individuals’ medical records and other personal health information, and the Security Rule, which requires appropriate administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and security of electronic PHI. The HIPAA Breach Notification Rule and the Enforcement Rule should also be part of this compliance requirement in the agreement. Adherence to these rules helps ensure that the contractor is fully aware of their responsibilities and the potential penalties for non-compliance. ## Managing and Maintaining HIPAA Contractor Agreements Here are a few ways your organization can more effectively manage your HIPAA contractor agreements (BAAs). ### Regular Review and Updates Managing BAAs is an ongoing process that involves regular reviews and updates. As healthcare laws and regulations are frequently updated, it’s important to ensure that your agreements remain compliant. Regularly reviewing the terms and conditions of your agreements can help identify any gaps or outdated provisions that may need to be amended. Additionally, changes in the services provided by the contractor or the way PHI is handled may require updates to the agreement. This proactive approach can help you stay ahead of potential issues and maintain the integrity of your HIPAA compliance program. ### Monitoring Compliance Monitoring the contractor’s compliance with the agreement is also crucial. This can involve regular audits or assessments to verify that the contractor is adhering to the stipulated privacy and security measures. Any identified non-compliance should be promptly addressed to prevent potential breaches and ensure ongoing adherence to HIPAA rules. Moreover, the agreement should provide for the right to monitor and audit the contractor’s practices. This gives the covered entity the necessary authority to verify compliance, providing an additional layer of security for PHI. ### Handling Breaches and Violations The agreement should clearly define how breaches and violations will be handled. This includes the procedure for reporting breaches, the corrective actions required, and the potential penalties for non-compliance. It’s important to have a well-defined process for dealing with breaches. This allows for prompt action, which can help minimize the damage and potential legal consequences. Regular communication with the contractor on this subject can also help ensure they understand their responsibilities and the seriousness of potential breaches. ### Documentation and Record-Keeping Keeping detailed records is an essential part of managing BAAs. This includes keeping copies of all signed agreements and any amendments, as well as records of audits or assessments. This documentation can serve as valuable evidence of your efforts to comply with HIPAA and can be critical in case of legal disputes or investigations. Additionally, it’s important to document any breaches or violations and the corrective actions taken. This can help you identify patterns, assess the effectiveness of your corrective measures, and make necessary improvements to your compliance program. ### Training and Awareness Finally, ensuring that everyone involved understands the importance of HIPAA compliance is crucial. This involves providing regular training and awareness programs for both your employees and the contractor’s staff. Such programs should cover the basics of HIPAA, the specific requirements of your agreement, and the potential consequences of non-compliance. Training and awareness are not just about avoiding penalties. They also help foster a culture of respect for patient privacy and the importance of safeguarding PHI. This can go a long way in preventing breaches and ensuring the success of your HIPAA compliance program. In conclusion, managing [HIPAA Business Associate Agreements](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) can be a complex task, but it’s essential for any entity dealing with PHI. By understanding the key components of these agreements and implementing practical strategies for managing and maintaining them, you can ensure your organization’s compliance with HIPAA and safeguard the privacy and security of the PHI in your care. --- # How to Install Jellyfin Media Server on Ubuntu 22.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-jellyfin-media-server-on-ubuntu-22-04/ | Published: 2024-02-26 | Updated: 2024-06-04 | Author: Hitesh Jethva Jellyfin is an open-source media server software designed to organize, manage, and stream media files across various devices within a network. It enables users to centralize their media collections, including movies, TV shows, music, and photos, and access them remotely from anywhere with an internet connection. In this tutorial, we will explain how to install the Jellyfin media server on Ubuntu 22.04. ## Step 1 – Install Jellyfin By default, the Jellyfin package is not included in the Ubuntu default repo, so you will need to add the Jellyfin official repository to APT. First, install all the required dependencies using the following command. ``` apt update -y apt install apt-transport-https ca-certificates gnupg2 curl git -y ``` Next, create a directory for keyrings and download the Jellyfin GPG key inside that directory. ``` mkdir -p /etc/apt/keyrings ``` ``` curl -fsSL https://repo.jellyfin.org/ubuntu/jellyfin_team.gpg.key | gpg --dearmor -o /etc/apt/trusted.gpg.d/jellyfin.gpg ``` Next, add the Jellyfin repository to the APT file. ``` echo "deb [arch=$( dpkg --print-architecture )] https://repo.jellyfin.org/$( awk -F'=' '/^ID=/{ print $NF }' /etc/os-release ) $( awk -F'=' '/^VERSION_CODENAME=/{ print $NF }' /etc/os-release ) main" | tee /etc/apt/sources.list.d/jellyfin.list ``` Then, update the repository index and install Jellyfin using the following command. ``` apt update ``` ``` apt install jellyfin ``` Once Jellyfin is installed, you can check its status using the following command. ``` systemctl status jellyfin ``` You will see the following output. ``` ● jellyfin.service - Jellyfin Media Server Loaded: loaded (/lib/systemd/system/jellyfin.service; enabled; vendor preset: enabled) Drop-In: /etc/systemd/system/jellyfin.service.d └─jellyfin.service.conf Active: active (running) since Mon 2024-03-04 03:38:47 UTC; 16s ago Main PID: 45223 (jellyfin) Tasks: 20 (limit: 4579) Memory: 89.6M CPU: 6.525s CGroup: /system.slice/jellyfin.service └─45223 /usr/bin/jellyfin --webdir=/usr/share/jellyfin/web --restartpath=/usr/lib/jellyfin/restart.sh --ffmpeg=/usr/lib/jellyfin-ffmpeg/ffmpeg ``` You can see all ports of Jellyfin using the following command. ``` ss -tulpn | grep jellyfin ``` Output. ``` udp UNCONN 0 0 0.0.0.0:1900 0.0.0.0:* users:(("jellyfin",pid=45223,fd=316)) udp UNCONN 0 0 127.0.0.1:36964 0.0.0.0:* users:(("jellyfin",pid=45223,fd=318)) udp UNCONN 0 0 0.0.0.0:7359 0.0.0.0:* users:(("jellyfin",pid=45223,fd=331)) udp UNCONN 0 0 0.0.0.0:36634 0.0.0.0:* users:(("jellyfin",pid=45223,fd=317)) tcp LISTEN 0 512 0.0.0.0:8096 0.0.0.0:* users:(("jellyfin",pid=45223,fd=310)) ``` ## Step 2 – Configure Apache for Jellyfin In this section, we will install and configure the Apache server as a reverse proxy for Jellyfin. First, install the Apache web server using the following command. ``` apt install apache2 -y ``` Next, enable all required modules with the following command. ``` a2enmod proxy proxy_http ssl proxy_wstunnel remoteip http2 headers ``` Next, create an Apache virtual host configuration file. ``` nano /etc/apache2/sites-available/jellyfin.conf ``` Add the following configuration. ``` ServerName jellyfin.example.com ErrorLog /var/log/apache2/jellyfin.example.com-error.log CustomLog /var/log/apache2/jellyfin.example.com-access.log combined DocumentRoot /var/www/html/jellyfin/public_html ProxyPreserveHost On # Tell Jellyfin to forward that requests came from TLS connections RequestHeader set X-Forwarded-Proto "https" RequestHeader set X-Forwarded-Port "443" ProxyPass "/socket" "ws://your-server-ip:8096/socket" ProxyPassReverse "/socket" "ws://your-server-ip:8096/socket" ProxyPass "/" "http://your-server-ip:8096/" ProxyPassReverse "/" "http://your-server-ip:8096/" ErrorLog /var/log/apache2/jellyfin.example.com-error.log CustomLog /var/log/apache2/jellyfin.example.com-access.log combined ``` Save and close the file, then activate the Jellyfin virtual host. ``` a2ensite jellyfin.conf ``` Next, verify the Apache configuration file. ``` apachectl configtest ``` Output. ``` Syntax OK ``` Finally, restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` You can check the Apache status using the following command. ``` systemctl status apache2 ``` Output. ``` ● apache2.service - The Apache HTTP Server Loaded: loaded (/lib/systemd/system/apache2.service; enabled; vendor preset: enabled) Active: active (running) since Mon 2024-03-04 03:40:53 UTC; 9s ago Docs: https://httpd.apache.org/docs/2.4/ Process: 46441 ExecStart=/usr/sbin/apachectl start (code=exited, status=0/SUCCESS) Main PID: 46446 (apache2) Tasks: 105 (limit: 4579) Memory: 8.8M CPU: 60ms CGroup: /system.slice/apache2.service ├─46446 /usr/sbin/apache2 -k start ├─46447 /usr/sbin/apache2 -k start └─46448 /usr/sbin/apache2 -k start Mar 04 03:40:53 ubuntu22 systemd[1]: Starting The Apache HTTP Server... ``` ## Step 3 – Access Jellyfin Web UI Now, open your web browser and access the Jellyfin web interface using the URL **http://jellyfin.example.com.** You will see the Jellyfin welcome page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p1-1.png) Select your language and click on **Next.** You will see the user account creation page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p2-1.png) Define your admin username and password and click on **Next.** You will see the media library setup page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p3.png) Add your media or click on **Next.** You will see the metadata language selection page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p4.png) Select your language and country and click on **Next.** You will see the remote access configuration page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p5.png) Click on **Next.** Once the setup is finished, you will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p6.png) Click on **Finish.** You will see the Jellyfin login page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p7.png) Provide your admin username and password and click on **Sign in.** You will see the Jellyfin dashboard on the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p8.png) ## Conclusion Jellyfin allows users to take control of their media experience and enjoy seamless streaming of movies, TV shows, music, and photos across their network. With its intuitive interface, robust features, and commitment to user privacy and security, Jellyfin offers a compelling alternative to proprietary media server solutions. You can now set up your own media server using Jellyfin [virtual private server](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Ensure Payment Security for Your eCommerce Store > URL: https://www.atlantic.net/pci-compliant-hosting/how-to-ensure-payment-security-for-your-ecommerce-store/ | Published: 2024-02-27 | Updated: 2026-03-01 | Author: Gilad Maayan Payment security protects potentially the most important sensitive information that your eCommerce store handles on a daily basis—cardholder data. For a hacker or fraudster, getting access to cardholder data is almost as good as winning the lottery. And with huge numbers of customers buying products online every day, the potential is enormous. Implementing payment security best practices mitigates the risks these cyberattacks pose to your eCommerce store. ## The continuous rise of eCommerce threats and its risks As the number of eCommerce businesses continues to grow, so do the threats that put them at risk. Hackers grow more sophisticated by the day, executing hard-to-spot phishing attacks or convincing social engineering schemes. Malware and ransomware have grown exponentially, controlled by the evolving creativity of black-hat hackers. And employees have more access to data than ever before, increasing the risk of accidental—and not-so-accidental—internal data breaches. ![](https://www.atlantic.net/wp-content/uploads/2024/02/shutterstock_1688525080.jpg) It’s no wonder that the cost of a data breach is at an all-time high. It’s not just the immediate financial loss you must be concerned with, as the subsequent reputational and legal costs can cause long-term economic repercussions. To avoid these risks, you need to implement stringent payment security. ## How to provide payment security for your eCommerce store You need to be aware of multiple layers of payment security. ### Choose secure and reputable payment gateways Physical point-of-sale (POS) card-reading devices have long been established as secure payment gateways in brick-and-mortar stores. [Payment gateway technologies](https://www.atlantic.net/pci-compliant-hosting/top-10-payment-processors/) authorize your customers’ debit and credit cards at the point of purchase, protecting transactions from unauthorized access and fraud. And protect from fraud you must. Globally, credit card fraud cost merchants and banks over [$30 billion](https://www.statista.com/statistics/1394119/global-card-fraud-losses/#:~:text=Card%20fraud%20losses%20across%20the,from%20the%20United%20States%20alone.) in 2021, an increase of over 10% from the previous year. The scary thing? The United States accounted for almost half ($12 billion) of this worldwide cost. In lieu of physical POS systems, eCommerce stores must use secure online payment gateways for card-not-present purchases. There are a few different types depending on your needs. They range from fully-hosted gateways such as PayPal, self-hosted gateways such as Stripe, and API-hosted gateways in which the entire process is handled by you directly on your website. Secure, reputable payment gateway technologies will be enforced with defensive features such as: - Data encryption - 3D secure authentication - Fraud detection and prevention - SSL and PCI DSS compliance Whichever payment gateways you choose, use [ERP software](https://www.sage.com/en-gb/erp/) to connect your online payment and financial data with your other back and front-end eCommerce systems. This will give you a more holistic view of the health of your business and provide you with more in-depth insight. On top of this, disconnected payment systems silo your transaction process and increase the risk of human error. This can leave your company open to exploitable vulnerabilities and data breaches. ERP integrates payments and syncs data, maximizing security, accuracy, and reliability. ### Implement SSL encryption to guarantee data confidentiality Secure socket layer (SSL) is an encryption protocol that secures website data communications, including sensitive payment information such as card numbers and contact information. Customers will know whether your website uses SSL (or its successor, TLS). As well as placing a lock symbol next to the URL, the URL will begin with “HTTPS” rather than “HTTP.” But if users aren’t paying attention, browsers will send an alert to warn customers that a website isn’t SSL-certified. ![](https://www.atlantic.net/wp-content/uploads/2024/02/incognito-mode-1.png) *[Image sourced](https://www.pandasecurity.com/en/mediacenter/panda-security/your-connection-is-not-private/) from pandasecurity.com* If your customers see this message, there’s only one thing they will do—bounce. Obtaining and installing an SSL certificate only takes a few steps. Just make sure to test and renew it to keep your website encrypted and your data secure. ### Maintain PCI DSS compliance in payment processing Closely adhere to the Payment Card Industry Data Security Standard (PCI DSS) to reliably achieve eCommerce payment security. PCI DSS is a global security standard set that dictates how businesses store, process, and transmit cardholder data. [Critical PCI DSS cybersecurity requirements](https://www.atlantic.net/pci-compliant-hosting/pci-dss-cybersecurity-requirements-a-practical-guide/) include: - Installing and regularly updating firewalls. - Encrypting data transmissions. - Maintaining secure, up-to-date business systems. - Storing cardholder data in secure locations. - Restricting who can access sensitive cardholder data using unique user identifiers. - Using updated anti-virus and anti-malware software. - Monitoring and tracking network access and user activity. - Performing in-depth, continuous testing. Businesses that aren’t PCI compliant risk not only cyberattacks and data breaches but also hefty fines of up to $100,000 per month. ### Enforce strong password rules and implement 2FA for admin access You might think that this goes without saying. And yet, a study by SpyCloud discovered that [70%](https://spycloud.com/blog/password-reuse/) of employees exposed to data breaches were reusing passwords. Even more eyebrow-raising is that Fortune 500 employees had a password reuse rate of 64%. ![](https://www.atlantic.net/wp-content/uploads/2024/02/password-reuse-rate.png) *[Data sourced](https://spycloud.com/blog/password-reuse/) from spycloud.com. Image created by writer* Enforce good password hygiene for employees *and*customers by specifying that passwords must: - **Be a required password length:** The more characters, the better. - **Include a variety of character combinations:** For example, an uppercase letter, a lowercase case letter, and a number. - **Use special characters:** Symbols and special characters strengthen your passwords. - **Be changed regularly:** Bonus points if the new password can’t be the same as the old passwords. Managing passwords takes a lot of work. Suggest using secure password managers like LastPass or NordPass to make passwords more manageable to keep track of. You should also implement two-factor authentication (2FA) or multi-factor authentication (MFA) on admin levels. These authentication methods require users to input two or more forms of identification, reducing the risk of unauthorized access. So, as well as a password, users may have to answer a security question, authenticate themselves using biometrics, or input a one-time code sent to a registered secondary device. ### Make sure your eCommerce platform and plugins are up to date Outdated eCommerce platforms and plugins can possess critical security flaws, compromising payment security. And yet, it’s not uncommon for eCommerce businesses to procrastinate performing updates and patches. Neglecting plugin updates is a particularly common offense. However, [94%](https://wpscan.com/statistics) of existing WordPress vulnerabilities can be attributed to plugins alone, according to WPScan. ![](https://www.atlantic.net/wp-content/uploads/2024/02/vulnerabilities-by-component.png) *[Image sourced](https://wpscan.com/statistics) from wpscan.com* If you found out there was an easy way for criminals to hack your physical security system, you’d update it, right? So, you need to do the same for your eCommerce site. Regularly check for updates as part of your daily or weekly processes. You should also consider investing in an eCommerce website security service that can simplify your security tools and manage your plugins. This makes it easier to protect your brand and keep your customers safe. ### Deploy fraud detection systems to monitor suspicious activities Fraud detection and prevention systems use artificial intelligence, machine learning, and statistical analysis to monitor and analyze transaction activity. A fraud detection system can analyze and extract patterns from vast volumes of historical data. This helps it intelligently differentiate fraudulent and non-fraudulent activity. From there, it can analyze real-time customer behaviors and create individual “profiles” based on transaction patterns and behaviors. So, if it detects behavioral anomalies, it can quickly flag the transaction as a suspicious activity. Here’s another critical reason to implement [cloud ERP solutions for small businesses](https://www.sage.com/en-gb/erp/small-business/). As they can assist in streamlining fraud detection and prevention. ERPs deliver full transparency, traceability, centralization, and control to your online payment data, mitigating the risk of fraud and errors. So, you can spend less time worrying about fraud and more time meeting the needs of your business. ### Only gather and retain essential customer payment data The less sensitive data you hold, the less devastating a data breach will be. Avoid collecting and keeping customer payment data you don’t need for this reason. It’s worth noting that PCI DSS rules against storing customer credit card data unless absolutely necessary. So, never retain any card information other than the name of the cardholder and, if needed, the PAN and/or expiration date. But remember, if you don’t need it, don’t keep it. ![](https://www.atlantic.net/wp-content/uploads/2024/02/shutterstock_2037588638.jpg) ### Train your team to spot cyber threats and sensitive data handling Your payment security processes are only as good as the team that governs them. It’s no use implementing a fancy cybersecurity system if your employees have no idea what a phishing attack is or have never heard of [GDPR](https://gdpr-info.eu/). So, provide comprehensive cybersecurity and data privacy training. Cover topics such as: - General Data Protection Regulation (GDPR) compliance. - Threat intelligence that covers the latest cybercrime trends. - Remote working best practices, such as VPN usage. - The [different types of cyberattacks](https://www.atlantic.net/dedicated-server-hosting/what-is-a-cyber-attack-common-attack-techniques-and-targets/), such as phishing and social engineering. - The protection of removable and mobile media, such as USB sticks and SD cards, as well as smartphones and laptops. ### Educate customers on secure online practices Tackle payment security from all angles and educate customers on shopping safely and securely online. There are lots of different fun, engaging ways that you can approach this. To give customers an interactive experience, why not host a live webinar discussing security best practices? Or, gamify the experience with a quiz or short role-playing game (complete with incentivizing rewards). You could also write blog posts or share social media posts that discuss online security. You don’t need to be preachy or use lots of tech-savvy jargon, though. Communicate in your brand voice as you would any other time, keeping it simple, clear, and helpful. ## Are your online payments secure? There are lots of things that you can do to enhance your eCommerce store’s payment security. Ideally, you should implement as many of the above methods as possible. The more layers of protection you put in place, the harder it will be for attackers and fraudsters to exploit your system. So, choose secure payment gateways, follow PCI DSS, deploy intelligent fraud detection systems, and make sure that employees know not to click on any suspicious-looking emails. --- # How to Install FreeScout Help Desk on Ubuntu 22.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-freescout-help-desk-on-ubuntu-22-04/ | Published: 2024-02-28 | Updated: 2024-06-04 | Author: Hitesh Jethva FreeScout Help Desk is an open-source customer support and ticketing system designed to streamline communication and collaboration within organizations. It offers a range of features to help businesses manage customer inquiries, resolve issues efficiently, and provide excellent customer service. In this post, we will explain how to install FreeScout Help Desk on Ubuntu 22.04. ## Step 1 – Install LEMP Server Before starting, you must install the Nginx, MariaDB, PHP and other PHP extensions on your server. You can install all of them using the following command. ``` apt update -y apt install nginx mariadb-server libmariadb-dev git php-fpm php-mysql php-mbstring php-xml php-imap php-zip php-gd php-curl php-intl ``` Once all the packages are installed, edit the php.ini file. ``` nano /etc/php/8.1/fpm/php.ini ``` Change the following settings. ``` memory_limit = 512M date.timezone = UTC upload_max_filesize = 16M cgi.fix_pathinfo=0 ``` Save and close the file, then restart the PHP-FPM service to apply the changes. ``` systemctl restart php8.1-fpm ``` ## Step 2 – Create a Database FreeScout uses MariaDB as a database backend, so you will need to create a database and user for FreeScout. First, connect to the MariaDB shell. ``` mysql ``` Once you are connected to the MariaDB shell, create a database and user. ``` CREATE DATABASE freescout CHARSET utf8mb4 COLLATE utf8mb4_unicode_ci; GRANT ALL PRIVILEGES ON freescout.* TO freescout@localhost IDENTIFIED BY "password"; ``` Next, flush the privileges using the following command. ``` FLUSH PRIVILEGES; ``` Finally, exit from the MariaDB shell using the following command. ``` EXIT; ``` ## Step 3 – Download FreeScout First, create a directory for FreeScout inside the Nginx web root directory. ``` mkdir -p /var/www/freescout ``` Then, navigate to the FreeScout directory and download the latest version of FreeScout inside that directory. ``` cd /var/www/freescout ``` ``` git clone https://github.com/freescout-helpdesk/freescout . ``` Next, set proper permissions and ownership to the FreeScout directory. ``` chown -R www-data:www-data /var/www/freescout find /var/www/freescout -type f -exec chmod 664 {} \; find /var/www/freescout -type d -exec chmod 775 {} \; ``` ## Step 4 – Configure Nginx for FreeScout Next, you will need to create a Nginx virtual host configuration file for FreeScout. ``` nano /etc/nginx/conf.d/freescout.conf ``` Add the following code. ``` server { listen 80; server_name freescout.example.com; root /var/www/freescout/public; index index.php index.html index.htm; error_log /var/www/freescout/storage/logs/web-server.log; location / { try_files $uri $uri/ /index.php?$query_string; } location ~ \.php$ { fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_pass unix:/run/php/php8.1-fpm.sock; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } # Uncomment this location if you want to improve attachments downloading speed. # Also make sure to set APP_DOWNLOAD_ATTACHMENTS_VIA=nginx in the .env file. #location ^~ /storage/app/attachment/ { # internal; # alias /var/www/freescout/storage/app/attachment/; #} location ~* ^/storage/attachment/ { expires 1M; access_log off; try_files $uri $uri/ /index.php?$query_string; } location ~* ^/(?:css|js)/.*\.(?:css|js)$ { expires 2d; access_log off; add_header Cache-Control "public, must-revalidate"; } location ~* ^/(?:css|fonts|img|installer|js|modules|[^\\\]+\..*)$ { expires 1M; access_log off; add_header Cache-Control "public"; } location ~ /\. { deny all; } } ``` Save and close the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http {: ``` server_names_hash_bucket_size 64; ``` Then, restart the Nginx service to reload the changes. ``` systemctl restart nginx ``` ## Step 5 – Access FreeScout Web UI Now, open your web browser and access the FreeScout web interface using the URL **http://freescout.example.com.** You will see the FreeScout installation page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p1-2.png) Click on **Check Requirements.** You will see the server requirements page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p2-2.png) Click on **Check Permissions.** You will see the Permissions page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p3-1.png) Click on **Configure Environments.** You will see the Settings page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p4-1.png) Define your website URL and click on **Setup Database.** You will see the Database setup page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p5-1.png) Define your database credentials and click on **Setup Application.** You will see the Language selection page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p6-1.png) Select your language and click on **Setup Admin.** You will see the admin user creation page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p7-1.png) Define your admin username, email, and password, and click on **Install.** You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p8-1.png) Click on Login. You will see the **FreeScout** login page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p9.png) Provide your admin username and password and click on **Login.** You will see the FreeScout dashboard on the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p10.png) ## Conclusion FreeScout Help Desk helps businesses to streamline their customer support operations and enhance overall efficiency. By following the installation steps outlined in this article, organizations can leverage FreeScout’s comprehensive features and user-friendly interface to effectively manage customer inquiries, resolve issues promptly, and deliver exceptional customer service. Try to deploy the FreeScout help desk on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Install Fathom Privacy Focused Web Analytics on Ubuntu 22.04 > URL: https://www.atlantic.net/vps-hosting/how-to-install-fathom-privacy-focused-web-analytics-on-ubuntu-22-04/ | Published: 2024-02-29 | Updated: 2024-06-04 | Author: Hitesh Jethva Fathom is a privacy-focused web analytics platform designed to provide website owners with valuable insights into visitor behavior while prioritizing user privacy and data protection. Unlike traditional analytics solutions that may compromise user privacy through invasive tracking methods, Fathom offers a streamlined approach that respects user anonymity and confidentiality. This tutorial will show you how to install Fathom Web Analytics on Ubuntu 22.04. ## Step 1 – Install Nginx and PostgreSQL First, you will need to install an Nginx web server and PostgreSQL database on your server. You can install both using the following command. ``` apt update -y apt install postgresql nginx ``` Next, connect to the PostgreSQL shell: ``` sudo -u postgres psql ``` Then, create a database and user for Fathom. ``` CREATE USER fathom WITH CREATEDB CREATEROLE PASSWORD 'password'; CREATE DATABASE fathomdb OWNER fathom; ``` You can exit from the PostgreSQL shell using the following command. ``` exit ``` ## Step 2 – Download Fathom First, download the latest version of Fathom from the Git repository. ``` wget https://github.com/usefathom/fathom/releases/download/v1.3.1/fathom_1.3.1_linux_amd64.tar.gz ``` Once the download is completed, extract the downloaded file to /usr/local/bin directory. ``` tar -C /usr/local/bin -xzf fathom_1.3.1_linux_amd64.tar.gz ``` Set execution permissions on the Fathom binary file. ``` chmod +x /usr/local/bin/fathom ``` Now, you can verify the Fathom version using the following command. ``` fathom --version ``` Output. ``` Fathom version 1.3.1, commit b252c743cc1ef1979f351ab77f99b2ae4aba9aa9, built at 2023-01-31T20:07:23Z ``` ## Step 3 – Configure Fathom First, add a user for Fathom. ``` useradd -r -d /opt/fathom fathom ``` Next, create a directory to store the Fathom configuration. ``` mkdir -p /opt/fathom ``` Set ownership to the Fathom directory. ``` chown -R fathom:fathom /opt/fathom ``` Then, generate a secret key. ``` head /dev/urandom | tr -dc A-Za-z0-9 | head -c 20 ; echo '' ``` Output. ``` hq0FyGDLQ6uJH2B2plC3 ``` Next, create a directory to store Fathom data. ``` cd /opt/fathom sudo -u fathom mkdir -p /opt/fathom/data ``` Then, create an environment variable file for Fathom. ``` sudo -u fathom nano /opt/fathom/data/.env ``` Add the following configurations. ``` FATHOM_GZIP=true FATHOM_DEBUG=true FATHOM_DATABASE_DRIVER="postgres" FATHOM_DATABASE_NAME="fathomdb" FATHOM_DATABASE_USER="fathom" FATHOM_DATABASE_PASSWORD="password" FATHOM_DATABASE_HOST="127.0.0.1" FATHOM_DATABASE_SSLMODE="disable" FATHOM_SECRET="hq0FyGDLQ6uJH2B2plC3" ``` Save and close the file, then navigate to the Fathom data directory and run the Fathom server using the following command. ``` cd /opt/fathom/data sudo -u fathom fathom server ``` If everything is fine, you will see the following output. ``` INFO[0000] Fathom version 1.3.1, commit b252c743cc1ef1979f351ab77f99b2ae4aba9aa9, built at 2023-01-31T20:07:23Z INFO[0000] Configuration file: /opt/fathom/data/.env INFO[0000] Connected to postgres database: fathomdb on 127.0.0.1 [DEPRECATED] packr.NewBox has been deprecated. Use packr.New instead. INFO[0000] Applied 26 database migrations! INFO[0000] Server is now listening on :8080 ``` Press CTRL+C to stop the server. ## Step 4 – Create a Service File Next, you will need to create a systemd file to manage Fathom server. You can create it using the following command. ``` nano /etc/systemd/system/fathom.service ``` Add the following lines: ``` [Unit] Description=Starts the fathom server Requires=network.target After=network.target [Service] Type=simple User=fathom Restart=always RestartSec=3 WorkingDirectory=/opt/fathom/data ExecStart=/usr/local/bin/fathom server [Install] WantedBy=multi-user.target ``` Save the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the Fathom service. ``` systemctl start fathom systemctl enable fathom ``` You can check the Fathom service using the following command. ``` systemctl status fathom ``` Output. ``` ● fathom.service - Starts the fathom server Loaded: loaded (/etc/systemd/system/fathom.service; disabled; vendor preset: enabled) Active: active (running) since Mon 2024-03-04 03:30:50 UTC; 16s ago Main PID: 38355 (fathom) Tasks: 6 (limit: 4579) Memory: 6.5M CPU: 45ms CGroup: /system.slice/fathom.service └─38355 /usr/local/bin/fathom server Mar 04 03:30:50 ubuntu22 systemd[1]: Started Starts the fathom server. Mar 04 03:30:50 ubuntu22 fathom[38355]: time="2024-03-04T03:30:50Z" level=info msg="Fathom version 1.3.1, commit b252c743cc1ef1979f351ab77f99b2ae4aba9aa9, built at 202> Mar 04 03:30:50 ubuntu22 fathom[38355]: time="2024-03-04T03:30:50Z" level=info msg="Configuration file: /opt/fathom/data/.env" Mar 04 03:30:50 ubuntu22 fathom[38355]: time="2024-03-04T03:30:50Z" level=info msg="Connected to postgres database: fathomdb on 127.0.0.1" Mar 04 03:30:50 ubuntu22 fathom[38355]: [DEPRECATED] packr.NewBox has been deprecated. Mar 04 03:30:50 ubuntu22 fathom[38355]: Use packr.New instead. Mar 04 03:30:50 ubuntu22 fathom[38355]: time="2024-03-04T03:30:50Z" level=info msg="Server is now listening on :8080" ``` ## Step 5 – Create an Admin User for Fathom Next, you will need to create an administrative user for Fathom. You can create it using the following command. ``` cd /opt/fathom/data sudo -u fathom fathom user add --email="hitjethva@gmail.com" --password="password" ``` You will see the following output. ``` INFO[0000] Fathom version 1.3.1, commit b252c743cc1ef1979f351ab77f99b2ae4aba9aa9, built at 2023-01-31T20:07:23Z INFO[0000] Configuration file: /opt/fathom/data/.env INFO[0000] Connected to postgres database: fathomdb on 127.0.0.1 [DEPRECATED] packr.NewBox has been deprecated. Use packr.New instead. INFO[0000] Created user hitjethva@gmail.com ``` ## Step 6 – Configure Nginx for Fathom Next, create an Nginx virtual host configuration file for Fathom. ``` nano /etc/nginx/conf.d/fathom.conf ``` Add the following lines: ``` server { listen 80; server_name fathom.example.com; location / { proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $remote_addr; proxy_set_header Host $host; proxy_pass http://127.0.0.1:8080; } } ``` Save the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http {: ``` server_names_hash_bucket_size 64; ``` Save the file, then verify the Nginx configurations for any syntax errors. ``` nginx -t ``` Output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 7 – Access Fathom Web Interface Now, open your web browser and access the Fathom web UI using the URL **http://fathom.example.com.** You will see the Fathom login page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p1-3.png) Provide your admin username and password and click on **Sign in.** You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p2-3.png) Define your site name and click on **Create Site.** You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p3-2.png) Click on **Update site name.** You will see the Fathom dashboard on the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p4-2.png) ## Conclusion By following the installation steps outlined in this article, users can deploy Fathom on their Ubuntu 22.04 servers and begin tracking essential metrics such as page views, unique visitors, and referrers securely and competently. Try to deploy Fathom on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! and start tracking visitor behaviors. --- # How to Install Grafana and Prometheus on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-grafana-and-prometheus-on-ubuntu-24-04/ | Published: 2024-03-01 | Updated: 2025-07-05 | Author: Hitesh Jethva Grafana is a leading open-source analytics and visualization platform that excels in monitoring, analysis, and observability. Originally created by Torkel Ödegaard in 2014, Grafana has evolved into a robust tool widely adopted by organizations and individuals alike for visualizing time-series data from various sources. Its flexibility, extensibility, and user-friendly interface make it a preferred choice for monitoring and analyzing complex systems, infrastructure, applications, and IoT devices. In this guide, we will explain how to install Grafana and Prometheus on Ubuntu 24.04. ## Step 1 – Add Grafana Repository First, install all the required dependencies using the following command. ``` apt install gnupg2 apt-transport-https software-properties-common wget ``` Next, download and add the Grafana GPG key. ``` wget -q -O - https://packages.grafana.com/gpg.key > grafana.key cat grafana.key | gpg --dearmor | tee /etc/apt/trusted.gpg.d/grafana.gpg > /dev/null ``` Then, add the Grafana repository to your APT source file. ``` echo 'deb [signed-by=/etc/apt/trusted.gpg.d/grafana.gpg] https://packages.grafana.com/oss/deb stable main' | tee /etc/apt/sources.list.d/grafana.list ``` Next, update the repository index using the following command. ``` apt update ``` ## Step 2 – Install and Configure Grafana Now you can install Grafana with the following command. ``` apt install grafana ``` Once Grafana is installed, reload the systemd daemon. ``` systemctl daemon-reload ``` Next, start the Grafana service using the following command. ``` systemctl start grafana-server ``` You can now check the status of Grafana using the following command. ``` systemctl status grafana-server ``` Output. ``` ● grafana-server.service - Grafana instance Loaded: loaded (/lib/systemd/system/grafana-server.service; disabled; vendor preset: enabled) Active: active (running) since Fri 2025-05-09 09:07:55 UTC; 5ms ago Docs: http://docs.grafana.org Main PID: 57756 ((grafana)) Tasks: 1 (limit: 4579) Memory: 256.0K CPU: 291us CGroup: /system.slice/grafana-server.service └─57756 "(grafana)" May 09 09:07:55 ubuntu24 systemd[1]: Started Grafana instance. ``` Next, edit the Grafana configuration file. ``` nano /etc/grafana/grafana.ini ``` Change the following lines. ``` http_addr = 127.0.0.1 # The http port to use http_port = 3000 # The public facing domain name used to access grafana from a browser domain = grafana.example.com ``` Save and close the file, then restart the Grafana service to apply the changes. ``` systemctl restart grafana-server ``` ## Step 3 – Install and Configure Nginx First, install the Nginx package. ``` apt install nginx ``` Next, create an Nginx virtual host configuration file. ``` nano /etc/nginx/conf.d/grafana.conf ``` Add the following configurations. ``` # this is required to proxy Grafana Live WebSocket connections. map $http_upgrade $connection_upgrade { default upgrade; '' close; } server { listen 80; server_name grafana.example.com; access_log /var/log/nginx/grafana-access.log; error_log /var/log/nginx/grafana-error.log; location / { proxy_set_header Host $http_host; proxy_pass http://localhost:3000/; } # Proxy Grafana Live WebSocket connections. location /api/live { rewrite ^/(.*) /$1 break; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection $connection_upgrade; proxy_set_header Host $http_host; proxy_pass http://localhost:3000/; } } ``` Save and close the file, then restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` Now, open your web browser and access Grafana using the URL http://grafana.example.com; you will see the Grafana login page. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p1-5.png) Provide the Grafana default username and password as **admin/admin,** then click on the **Login** button. You will see the Grafana change password screen. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p2-4.png) Set your new password and click on the **Submit** button. You will see the Grafana dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p3-2.png) ## Step 4 – Install and Configure Prometheus First, add a user and group for Prometheus. ``` groupadd --system prometheus useradd -s /sbin/nologin --system -g prometheus prometheus ``` Next, create the required directories for Prometheus. ``` mkdir /var/lib/prometheus for i in rules rules.d files_sd; do mkdir -p /etc/prometheus/${i}; done ``` Next, download the latest version of Prometheus from the Git repo. ``` curl -s https://api.github.com/repos/prometheus/prometheus/releases/latest|grep browser_download_url|grep linux-amd64|cut -d '"' -f 4|wget -qi - ``` Once the download is completed, extract the downloaded file. ``` tar xvf prometheus*.tar.gz ``` Next, change the directory to Prometheus and copy all required files to desired locations. ``` cd prometheus*/ mv prometheus promtool /usr/local/bin/ mv prometheus.yml /etc/prometheus/ ``` Set necessary permissions on the Prometheus directory. ``` for i in rules rules.d files_sd; do chown -R prometheus:prometheus /etc/prometheus/${i}; done for i in rules rules.d files_sd; do chmod -R 775 /etc/prometheus/${i}; done chown -R prometheus:prometheus /var/lib/prometheus/ ``` Next, install the Apache utils package. ``` apt install apache2-utils -y ``` Next, add a user for Prometheus. ``` htpasswd -nB hitesh ``` Set your password as shown below: ``` New password: Re-type new password: hitesh:$2y$05$rAWBwQJAByNKU6FncX33p.uZ1tPTqqc6LHVP2yGm3ZFnSnhrvdpne ``` Next, create the Prometheus main configuration file. ``` nano /etc/prometheus/web.yml ``` Define your username and password. ``` basic_auth_users: hitesh: $2y$05$rAWBwQJAByNKU6FncX33p.uZ1tPTqqc6LHVP2yGm3ZFnSnhrvdpne ``` Next, change ownership of the Prometheus configuration file. ``` chown prometheus: /etc/prometheus/web.yml ``` Next, edit the Prometheus configuration file. ``` nano /etc/prometheus/prometheus.yml ``` Change the following lines: ``` scrape_configs: # The job name is added as a label `job=` to any timeseries scraped from this config. - job_name: "prometheus" # metrics_path defaults to '/metrics' # scheme defaults to 'http'. basic_auth: username: 'admin' password: 'uniquepass' static_configs: - targets: ["127.0.0.1:9090"] ``` Save and close the file when you are done. ## Step 5 – Create a Systemd Service File for Prometheus Next, create a systemd file to manage the Prometheus service. ``` nano /etc/systemd/system/prometheus.service ``` Add the following configuration. ``` [Unit] Description=Prometheus Documentation=https://prometheus.io/docs/introduction/overview/ Wants=network-online.target After=network-online.target [Service] Type=simple User=prometheus Group=prometheus ExecReload=/bin/kill -HUP $MAINPID ExecStart=/usr/local/bin/prometheus \ --config.file=/etc/prometheus/prometheus.yml \ --storage.tsdb.path=/var/lib/prometheus \ --web.listen-address=0.0.0.0:9090 \ --web.config.file=/etc/prometheus/web.yml \ SyslogIdentifier=prometheus Restart=always [Install] WantedBy=multi-user.target ``` Save the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the Prometheus service. ``` systemctl start prometheus systemctl enable prometheus ``` You can now check the status of the Prometheus service using the following command. ``` systemctl status prometheus ``` Output. ``` ● prometheus.service - Prometheus Loaded: loaded (/etc/systemd/system/prometheus.service; disabled; vendor preset: enabled) Active: active (running) since Fri 2025-05-09 09:35:17 UTC; 3s ago Docs: https://prometheus.io/docs/introduction/overview/ Main PID: 58652 (prometheus) Tasks: 7 (limit: 4579) Memory: 15.4M CPU: 59ms CGroup: /system.slice/prometheus.service └─58652 /usr/local/bin/prometheus --config.file=/etc/prometheus/prometheus.yml --storage.tsdb.path=/var/lib/prometheus --web.console.templates=/etc/promet> ``` ## Step 6 – Install node_exporter The **node_exporter** is used to gather system metrics and expose an HTTP API that runs on the default TCP port ‘9100’. First, download the latest version of node_exporter. ``` curl -s https://api.github.com/repos/prometheus/node_exporter/releases/latest| grep browser_download_url|grep linux-amd64|cut -d '"' -f 4|wget -qi - ``` Once the download is complete, extract the downloaded file. ``` tar -xvf node_exporter*.tar.gz ``` Next, navigate to the extracted directory and copy the node_exporter binary file to the system location. ``` cd node_exporter*/ cp node_exporter /usr/local/bin ``` Now, verify the node_exporter version. ``` node_exporter --version ``` Output. ``` node_exporter, version 1.9.1 (branch: HEAD, revision: 7333465abf9efba81876303bb57e6fadb946041b) build user: root@35918982f6d8 build date: 20231112-23:53:35 go version: go1.23.7 platform: linux/amd64 tags: netgo osusergo static_build ``` Next, create a system file to manage the node_exporter service. ``` nano /etc/systemd/system/node_exporter.service ``` Add the following configurations. ``` [Unit] Description=Node Exporter Wants=network-online.target After=network-online.target [Service] User=prometheus ExecStart=/usr/local/bin/node_exporter [Install] WantedBy=default.target ``` Save the file, then reload the system daemon using the following command. ``` systemctl daemon-reload ``` Next, start the node_exporter service using the following command. ``` systemctl start node_exporter ``` You can verify the status of the node_exporter using the following command. ``` systemctl status node_exporter ``` Output. ``` ● node_exporter.service - Node Exporter Loaded: loaded (/etc/systemd/system/node_exporter.service; disabled; vendor preset: enabled) Active: active (running) since Fri 2025-05-09 09:37:47 UTC; 5s ago Main PID: 58716 (node_exporter) Tasks: 4 (limit: 4579) Memory: 2.4M CPU: 7ms CGroup: /system.slice/node_exporter.service └─58716 /usr/local/bin/node_exporter ``` ## Step 7 – Add node_exporter to Prometheus First, open the Prometheus configuration file. ``` nano /etc/prometheus/prometheus.yml ``` Add the following configuration under the scrape_configs section. ``` scrape_configs: .... .... - job_name: "node_exporter" static_configs: - targets: ["your-server-ip:9100"] ``` Save and close the file, then restart the Prometheus service to apply the changes. ``` systemctl restart prometheus ``` ## Step 8 – Access Prometheus Dashboard Now, open your web browser and access Prometheus using the URL **http://your-server-ip:9090.** You will see the Prometheus login page. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p4-2.png) Provide your admin username and password and click on the **Sign in.** You will see the Prometheus dashboard. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p6-1.png) To verify whether the **node_exporter** is active or not, type the Prometheus query such as **‘node_memory_Active_bytes’** and click **‘Execute’.** Then, you’ll receive the simple graph generated by Prometheus. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p7-1.png) Now click on the **‘Status’** menu at the top and select **‘Targets’.** You should see two different target scraps that are active and running. ‘Prometheus’ for gathering Prometheus server metrics, and the **‘node_exporter’** for gathering system metrics. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p8.png) ## Conclusion Throughout this guide, we’ve walked through the steps to install Grafana, configure data sources, create dashboards, and explore its rich features for monitoring and observability. With Grafana, you can monitor system performance, track key metrics, visualize trends, and troubleshoot issues effectively, empowering you to make informed decisions and optimize your infrastructure, applications, and services. You can now deploy the Grafana and Prometheus monitoring stack on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Umami Analytics on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-umami-analytics-on-ubuntu-22-04/ | Published: 2024-03-04 | Updated: 2024-06-02 | Author: Hitesh Jethva Umami is a sleek and modern open-source analytics platform designed to help website owners and developers gain insights into user behavior and engagement. Unlike traditional analytics solutions, Umami prioritizes privacy, offering a self-hosted alternative that gives you full control over your data without compromising on functionality or usability. Umami allows you to set up your own analytics platform, track website traffic, monitor user interactions, and analyze key metrics—all within a secure and customizable environment. In this guide, we will walk you through the step-by-step process of installing Umami on Ubuntu 22.04. ## Step 1 – Install Node.js Before starting, you will need to install some required dependencies to your server. You can install all of them using the following command. ``` apt install wget curl nano ufw software-properties-common dirmngr apt-transport-https gnupg2 ca-certificates lsb-release debian-archive-keyring unzip -y ``` Next, add the Node.js GPG key. ``` curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | gpg --dearmor -o /usr/share/keyrings/nodesource.gpg ``` Then, add the Node.js repository to APT. ``` echo "deb [signed-by=/usr/share/keyrings/nodesource.gpg] https://deb.nodesource.com/node_20.x nodistro main" | tee /etc/apt/sources.list.d/nodesource.list ``` Next, update the repository and install Node.js. ``` apt update apt install nodejs ``` You can now verify the Node.js version using the following command. ``` node --version ``` Output. ``` v20.11.0 ``` ## Step 2 – Install MariaDB Server First, install the MariaDB database server. ``` apt install mariadb-server -y ``` Once MariaDB is installed, log in to the MariaDB console using the following command. ``` mysql ``` Once you are logged in, create a database and user for Umami. ``` CREATE USER 'umamiuser'@'localhost' IDENTIFIED BY 'password'; CREATE DATABASE umami; ``` Then, grant all necessary privileges to the Umami database. ``` GRANT ALL PRIVILEGES ON umami.* TO 'umamiuser'@'localhost'; GRANT ALL ON *.* TO 'umami'@'localhost' IDENTIFIED BY 'password' WITH GRANT OPTION; ``` Next, flush the privileges to apply the changes. ``` FLUSH PRIVILEGES; ``` Next, exit from the MariaDB console using the following command. ``` EXIT; ``` ## Step 3 – Download Umami First, install the Yarn package using the following command. ``` npm install -g yarn ``` Next, download the latest version of Umami from the Git repo. ``` git clone https://github.com/mikecao/umami.git ``` Once the download is completed, navigate to the Umami directory and install all required dependencies. ``` cd umami yarn install ``` Next, generate a secret key. ``` openssl rand 30 | openssl base64 -A ``` Output. ``` WPKWGO1bEYMCBmgOl2Ch6AvO+sBs9j6h4BZC/Dw5 ``` Next, edit the .env file. ``` nano .env ``` Define your database and secret as shown below: ``` DATABASE_URL=mysql://umamiuser:password@localhost:3306/umami APP_SECRET=WPKWGO1bEYMCBmgOl2Ch6AvO+sBs9j6h4BZC/Dw5 DISABLE_TELEMETRY=1 TRACKER_SCRIPT_NAME=custom ``` Then, run the following command to bundle the app into static files for production. ``` yarn build ``` Next, install PM2 to manage your application. ``` yarn global add pm2 ``` Then, start the Umami application using PM2. ``` pm2 start yarn --name umami -- start ``` Output. ``` [PM2] Spawning PM2 daemon with pm2_home=/root/.pm2 [PM2] PM2 Successfully daemonized [PM2] Starting /usr/bin/yarn in fork_mode (1 instance) [PM2] Done. ┌────┬──────────┬─────────────┬─────────┬─────────┬──────────┬────────┬──────┬───────────┬──────────┬──────────┬──────────┬──────────┐ │ id │ name │ namespace │ version │ mode │ pid │ uptime │ ↺ │ status │ cpu │ mem │ user │ watching │ ├────┼──────────┼─────────────┼─────────┼─────────┼──────────┼────────┼──────┼───────────┼──────────┼──────────┼──────────┼──────────┤ │ 0 │ umami │ default │ N/A │ fork │ 46628 │ 0s │ 0 │ online │ 0% │ 43.8mb │ root │ disabled │ └────┴──────────┴─────────────┴─────────┴─────────┴──────────┴────────┴──────┴───────────┴──────────┴──────────┴──────────┴──────────┘ ``` ## Step 4 – Configure Nginx for Umami Next, you will need to configure Nginx as a reverse proxy to access the Umami from the outside world. First, install the Nginx web server. ``` apt install nginx ``` Then, create an Nginx virtual host file. ``` nano /etc/nginx/conf.d/umami.conf ``` Add the following configurations. ``` server { listen 80; server_name umami.example.com; access_log /var/log/nginx/umami.access.log; error_log /var/log/nginx/umami.error.log; location / { proxy_pass http://localhost:3000; proxy_set_header X-Real-IP $remote_addr; proxy_set_header Host $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; } } ``` Save the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http{: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then verify the Nginx for any syntax errors. ``` nginx -t ``` Output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, reload Nginx to implement the changes. ``` systemctl restart nginx ``` ## Step 5 – Access Umami Dashboard Now, open your web browser and access the Umami dashboard using the URL **http://umami.example.com.** You will see the Umami login page. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p1-6.png) Provide the default username as **admin** and password as **umami,** then click on the **Login** button. You should see the Umami dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p2-5.png) ## Conclusion In conclusion, Umami offers you a powerful and privacy-focused solution for tracking website analytics and gaining insights into user behavior. Throughout this guide, we’ve covered the steps to install Umami, configure its settings, and access its dashboard for monitoring website traffic and engagement. You can now try Umami on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Cloud Storage Services vs. On-Premises Storage: Critical Compliance Considerations > URL: https://www.atlantic.net/vps-hosting/cloud-storage-services-vs-on-premises-storage-critical-compliance-considerations/ | Published: 2024-03-05 | Updated: 2025-09-11 | Author: Alexander Wise ## What Are Cloud Storage Services? Cloud Storage Services offer a modern approach to data storage. Rather than storing data on physical servers within an organization, these services store data on virtual servers hosted on the internet. These servers are typically owned and managed by third-party service providers. One of the most significant advantages of cloud storage services is scalability. Unlike on-premises storage, increasing storage capacity on the cloud is as easy as adjusting your service plan. This flexibility allows organizations to scale their storage needs based on their current requirements. In addition to Atlantic.net, some popular cloud storage services include Microsoft OneDrive, Google Drive, and the [Elastic File Service (EFS)](https://bluexp.netapp.com/blog/aws-efs-is-it-the-right-storage-solution-for-you). The primary advantage of these services is that if something happens to your computer or network, your files will remain safe and accessible on the cloud. However, cloud storage services also come with their own set of challenges. The primary concern is data security, as data is stored on third-party servers. This requires a high level of trust in the service provider. Additionally, there can be concerns around data sovereignty, especially for organizations operating across different geographical locations. ## What Is On-Premises Storage? On-premises storage refers to the traditional data storage method where data is stored within the physical boundaries of an organization. This could be in the form of data centers, servers, or any physical storage infrastructure that the organization owns and operates. On-premises storage offers several advantages. Firstly, it provides higher control over data as the infrastructure is within the organization’s physical boundaries. Secondly, it offers a higher assurance of data security, especially for sensitive information, as physical access to the servers can be restricted. However, on-premises storage also comes with its challenges. It requires significant capital expenditure, as well as ongoing costs for maintenance and upgrades. It also necessitates a dedicated IT team to manage and troubleshoot the infrastructure. Additionally, scalability can be a concern as increasing data storage capacity may require additional physical infrastructure. ## Key Compliance Standards and Regulations Affecting Data Storage Compliance is a critical consideration when choosing between cloud storage services and on-premises storage. Several standards and regulations affect how data is stored, and non-compliance can lead to hefty fines and reputational damage. ### GDPR The [General Data Protection Regulation (GDPR)](https://www.atlantic.net/vps-hosting/gdpr-compliance-for-global-managed-service-providers/) is a European Union regulation that governs how organizations handle personal data. It applies to any organization that processes the personal data of individuals within the EU, regardless of where the organization is based. GDPR compliance requires that data be stored securely, with appropriate safeguards in place to protect against unauthorized access or data breaches. It also stipulates that individuals have the right to access their personal data, correct inaccuracies, and request the deletion of their data. For on-premises storage, GDPR compliance can be more straightforward, as the organization has direct control over the physical servers where data is stored. However, it also places the responsibility of securing the data squarely on the organization. For cloud storage services, GDPR compliance can be more complex. The responsibility of securing the data is shared between the organization and the cloud service provider. Therefore, it is crucial to choose a provider that can demonstrate robust security measures and GDPR compliance. ### SOC The Service Organization Control (SOC) standards are a set of auditing standards developed by the American Institute of Certified Public Accountants (AICPA). They are designed to provide assurance over a service organization’s controls that affect the user entities’ financial statement assertions. SOC compliance is particularly relevant for cloud storage services. SOC 2, for instance, focuses on a business’s non-financial reporting controls as they relate to the security, availability, processing integrity, confidentiality, and privacy of a system. Like GDPR, SOC compliance for cloud storage services requires a collaborative effort between the organization and the cloud service provider. The organization must ensure that the provider has the necessary controls in place to meet the SOC standards, and the provider, in turn, must be willing to undergo regular audits to demonstrate compliance. ## On-Premises Storage Compliance Advantages ### Complete Control Over Data Location and Security Measures When it comes to on-premises storage, one of the most significant advantages is the control organizations have over their data. With on-premises storage, data is stored on servers located within the organization’s physical location. This means that the organization has complete control over where their data is stored and the security measures put in place to protect it. With this control, comes the ability to customize the infrastructure according to the specific needs of the organization. These could be based on the type of data being handled, the scale of operations, or the industry-specific regulations that the organization needs to comply with. This level of control is particularly important for organizations operating in highly regulated industries. ### Easier to Ensure Data Sovereignty and Meet Locality-Specific Regulations Data sovereignty refers to the concept that data is subject to the laws of the country in which it is located. With on-premises storage, organizations can ensure that their data is stored within their own country, thereby making it easier to comply with locality-specific regulations. For instance, some countries have stringent regulations when it comes to data protection and privacy. These regulations specify that certain types of data must be stored within the country and cannot be transferred internationally. With on-premises storage, organizations can ensure that they are compliant with these laws. ### Direct Oversight of Compliance and Security Protocols Another advantage of on-premises storage is the direct oversight of compliance and security protocols. With the data stored on-site, organizations have the ability to monitor and manage the security protocols in place directly. This not only ensures that the organization complies with the relevant regulations, but also provides a sense of control over the data. In the event of a security breach or other incident, the organization can quickly respond and take appropriate action. This is a level of control and oversight that is often not possible with cloud storage services. ## Cloud Storage Services Compliance Advantages ### Flexibility in Meeting Diverse Regulatory Requirements Cloud storage services offer flexibility in meeting diverse regulatory requirements, making them an attractive option for organizations operating across various jurisdictions. These services are designed to adapt to different regulatory environments, providing compliance solutions that cater to the specific needs of different sectors and regions. For instance, a multinational corporation might need to comply with GDPR in Europe, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) in the United States, and other local regulations in different countries where it operates. Cloud storage providers often have the infrastructure and legal frameworks in place to meet these diverse requirements, reducing cost and complexity for organizations. ### Advanced Security Measures Provided by Cloud Service Providers While on-premises storage allows for direct control over security protocols, cloud storage services often come with advanced security measures that are hard to match. These providers have huge, dedicated security teams that work to ensure data protection. From encryption at rest and in transit, to advanced threat detection and response capabilities, cloud storage providers often employ state-of-the-art security measures. This not only ensures compliance with regulatory requirements but also provides an additional layer of protection against cyber threats. ### Regular Updates to Comply with the Latest Regulations Finally, cloud storage services are regularly updated to comply with the latest regulations. Regulatory requirements around data protection and privacy are constantly evolving. Cloud storage providers have the resources and expertise to keep up with these changes and ensure that their services are always compliant. This takes the burden off organizations, who otherwise would have to constantly monitor changes in regulations and update their on-premises storage infrastructure accordingly. ## Cloud Storage Services vs. On-Premises Storage: How to Choose? ### Compliance Requirements When comparing cloud storage services with on-premises storage, compliance requirements are a crucial factor. This is particularly true for industries that are heavily regulated, such as healthcare, finance, and government. These sectors frequently deal with sensitive information that demands stringent compliance with data protection laws and regulations. Cloud providers often have robust compliance programs to adhere to various regulatory standards. They invest heavily in security measures and conduct regular audits to ensure they meet compliance regulations. However, it’s essential to remember that although the cloud provider is responsible for the security of the cloud, you are responsible for the security of your data in the cloud. On the other hand, on-premises storage gives you total control over your data, including its security. This can be particularly beneficial for businesses with strict compliance requirements as it allows them to manage data security according to their specific needs. However, it’s crucial to note that this increased control also comes with increased responsibility. It’s up to you to ensure that your data is protected and compliant with relevant regulations. ### Data Sovereignty and Privacy Data sovereignty and privacy are other critical considerations when choosing between cloud and on-premises storage. Data sovereignty refers to the fact that digital data is subject to the laws of the country in which it’s located. This can pose challenges when using cloud storage services, as your data might be stored in multiple locations worldwide. Cloud providers often have multiple data centers spread across different countries, which could potentially lead to data sovereignty issues. Depending on the jurisdictions involved, your data may be subject to foreign laws and regulations, which may not provide the same level of data protection as your home country. On-premises storage, in contrast, ensures that your data remains within your organization’s physical location. This means you have full control over where your data resides and the laws that govern it. However, this also means you bear the responsibility for ensuring that your data is properly protected and compliant with local data sovereignty laws. ### Risk Management Risk management is another vital factor in the cloud vs. on-premises storage debate. Both options come with their unique set of risks that need to be managed effectively. With cloud storage services, the risks mainly stem from the shared responsibility model. While the cloud provider is responsible for securing the cloud infrastructure, you are responsible for securing your data within the cloud. This includes managing user access, data encryption, and data backups. There’s also the risk of vendor lock-in, where you become overly reliant on a single cloud provider and find it difficult to switch providers or move your data back on-premises. On-premises storage, on the other hand, comes with its risks. These include hardware failures, natural disasters, and security breaches. Since you have full control over your data, you are solely responsible for managing these risks. This includes investing in appropriate security measures, maintaining hardware, and ensuring data backups are carried out regularly. ### Vendor Assessment Finally, vendor assessment is a critical part of choosing between cloud storage services and on-premises storage. This involves evaluating potential vendors based on their ability to meet your specific business needs and compliance requirements. When assessing cloud providers, it’s important to consider their security measures, compliance certifications, and data center locations. It’s also essential to evaluate their service level agreements (SLAs) to understand their commitments regarding data availability and recovery In contrast, when considering on-premises storage, the evaluation process is more focused on hardware and software providers. This includes assessing the reliability of their hardware, the capabilities of their software, and their support services. In conclusion, choosing between cloud storage services and on-premises storage involves careful consideration of multiple factors. Compliance requirements, data sovereignty and privacy, risk management, and vendor assessment all play a critical role in this decision. --- # How to Install NetBox IRM on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-netbox-irm-on-ubuntu-24-04/ | Published: 2024-03-06 | Updated: 2025-05-15 | Author: Hitesh Jethva NetBox, an open-source web application designed to manage and document computer networks, stands as an invaluable tool for network engineers and administrators. With its intuitive interface and robust feature set, NetBox simplifies network infrastructure management, offering functionalities such as IP address management (IPAM), device inventory, circuit tracking, and more. This guide outlines the step-by-step process to install NetBox on Ubuntu 24.04. ## Step 1 – Install PostgreSQL Server NetBox uses PostgreSQL as a database engine, so you must install it on your server. You can install it with the following command. ``` apt update -y apt install postgresql postgresql-contrib -y ``` Next, verify the PostgreSQL service. ``` systemctl status postgresql ``` Output. ``` ● postgresql.service - PostgreSQL RDBMS Loaded: loaded (/usr/lib/systemd/system/postgresql.service; enabled; preset: enabled) Active: active (exited) since Wed 2025-05-14 04:44:25 UTC; 1 day 8h ago Main PID: 1444 (code=exited, status=0/SUCCESS) CPU: 1ms May 14 04:44:25 ubuntu systemd[1]: Starting postgresql.service - PostgreSQL RDBMS... May 14 04:44:25 ubuntu systemd[1]: Finished postgresql.service - PostgreSQL RDBMS. ``` Next, login to PostgreSQL. ``` sudo -i -u postgres psql ``` Create a database and user for Netbox. ``` CREATE DATABASE netbox; ``` ``` CREATE USER netbox WITH PASSWORD 'password'; ``` ``` ALTER DATABASE netbox OWNER TO netbox; ``` Exit from the PostgreSQL shell. ``` \q ``` ## Step 2 – Install Redis NetBox uses Redis for caching, so you will need to install it on your server. You can install it using the following command. ``` apt install redis -y ``` You can verify the Redis installation using the following command. ``` redis-server -v ``` Output. ``` Redis server v=7.0.15 sha=00000000:0 malloc=jemalloc-5.3.0 bits=64 build=3ec7bf4ec5bfafb8 ``` Next, edit the Redis configuration file. ``` nano /etc/redis/redis.conf ``` Change the following line to enable Redis authentication. ``` requirepass password ``` Save the file then restart the Redis to apply the changes. ``` systemctl restart redis-server ``` ## Step 3 – Install Netbox First, install all required dependencies. ``` apt install -y python3 python3-pip python3-venv python3-dev build-essential libxml2-dev libxslt1-dev libffi-dev libpq-dev libssl-dev zlib1g-dev ``` Next, create a directory for NetBox. ``` mkdir -p /opt/netbox/ ``` Then, change the directory to NetBox and download the latest version of NetBox from the Git repo. ``` cd /opt/netbox ``` ``` git clone -b master --depth 1 https://github.com/netbox-community/netbox.git . ``` ``` git config --global --add safe.directory /opt/netbox ``` Next, create a user and group for NetBox. ``` adduser --system --group netbox ``` Change the ownership of the NetBox directory. ``` chown --recursive netbox /opt/netbox ``` ``` chown --recursive netbox /opt/netbox/netbox/media/ ``` Next, rename the NetBox sample configuration file. ``` cd /opt/netbox/netbox/netbox/ ``` ``` cp configuration_example.py configuration.py ``` Then, generate a secret key. ``` python3 ../generate_secret_key.py ``` Output. ``` 3ChOm5a9!J)Ik*vxXNZBu&MdaQN545_Dyh93#PnII7uv_AeqNP ``` Next, edit the NetBox configuration file. ``` nano configuration.py ``` Change the following lines: ``` ALLOWED_HOSTS = ['netbox.example.com', ''] DATABASE = { 'NAME': 'netbox', 'USER': 'netbox', 'PASSWORD': 'password', 'HOST': 'localhost', 'PORT': '', 'CONN_MAX_AGE': 300, } REDIS = { 'tasks': { 'HOST': 'localhost', 'PORT': 6379, 'PASSWORD': 'password', 'DATABASE': 0, 'SSL': False, }, 'caching': { 'HOST': 'localhost', 'PORT': 6379, 'PASSWORD': 'password', 'DATABASE': 1, 'SSL': False, } } SECRET_KEY = '3ChOm5a9!J)Ik*vxXNZBu&MdaQN545_Dyh93#PnII7uv_AeqNP' ``` Save and close the file, then install NetBox using the following command. ``` /opt/netbox/upgrade.sh ``` ## Step 4 – Create a Netbox Admin User First, activate the NetBox virtual environment. ``` source /opt/netbox/venv/bin/activate ``` Next, create a superuser for NetBox. ``` cd /opt/netbox/netbox ``` ``` python3 manage.py createsuperuser ``` Define your user and password as shown below. ``` Username (leave blank to use 'root'): nadmin Email address: admin@example.com Password: Password (again): Superuser created successfully. ``` Next, create a symbolic link to the NetBox service file. ``` ln -s /opt/netbox/contrib/netbox-housekeeping.sh /etc/cron.daily/netbox-housekeeping ``` ## Step 5 – Start Netbox Server You can now start the NetBox server using the following command. ``` python3 manage.py runserver 0.0.0.0:8000 --insecure ``` Output. ``` System check identified no issues (0 silenced). May 15, 2025 - 13:15:59 Django version 5.0.10, using settings 'netbox.settings' Starting development server at http://0.0.0.0:8000/ Quit the server with CONTROL-C. ``` Now, open your web browser and access NetBox using the URL **http://netbox.example.com:8000.** You will see the NetBox following page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/n1.png)     Provide your admin username and password and click on **Sign In.** You will see the NetBox dashboard on the following screen.   ![](https://www.atlantic.net/wp-content/uploads/2024/03/n2.png) Finally, deactivate from the virtual environment using the following command. ``` deactivate ``` ## Step 6 – Create a Systemd Service File By default, Netbox comes with a pre-built system file to manage the NetBox. First, copy all required files to the desired location. ``` cp /opt/netbox/contrib/gunicorn.py /opt/netbox/gunicorn.py ``` ``` cp -v /opt/netbox/contrib/*.service /etc/systemd/system/ ``` GIve necessary permissions to /opt/netbox directory: ``` chmod -R 755 /opt/netbox chown -R netbox:netbox /opt/netbox ``` Next, reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start and enable the NetBox service. ``` systemctl start netbox netbox-rq ``` ``` systemctl enable netbox netbox-rq ``` You can now verify the NetBox service using the following command. ``` systemctl status netbox ``` Output. ``` ● netbox.service - NetBox WSGI Service Loaded: loaded (/etc/systemd/system/netbox.service; disabled; vendor preset: enabled) Active: active (running) since Thu 2025-05-15 03:20:32 UTC; 5s ago Docs: https://docs.netbox.dev/ Main PID: 113448 (gunicorn) Tasks: 6 (limit: 4579) Memory: 506.7M CPU: 6.533s CGroup: /system.slice/netbox.service ├─113448 /opt/netbox/venv/bin/python3 /opt/netbox/venv/bin/gunicorn --pid /var/tmp/netbox.pid --pythonpath /opt/netbox/netbox --config /opt/netbox/gunicor> ├─113450 /opt/netbox/venv/bin/python3 /opt/netbox/venv/bin/gunicorn --pid /var/tmp/netbox.pid --pythonpath /opt/netbox/netbox --config /opt/netbox/gunicor> ├─113451 /opt/netbox/venv/bin/python3 /opt/netbox/venv/bin/gunicorn --pid /var/tmp/netbox.pid --pythonpath /opt/netbox/netbox --config /opt/netbox/gunicor> ├─113452 /opt/netbox/venv/bin/python3 /opt/netbox/venv/bin/gunicorn --pid /var/tmp/netbox.pid --pythonpath /opt/netbox/netbox --config /opt/netbox/gunicor> ├─113453 /opt/netbox/venv/bin/python3 /opt/netbox/venv/bin/gunicorn --pid /var/tmp/netbox.pid --pythonpath /opt/netbox/netbox --config /opt/netbox/gunicor> └─113454 /opt/netbox/venv/bin/python3 /opt/netbox/venv/bin/gunicorn --pid /var/tmp/netbox.pid --pythonpath /opt/netbox/netbox --config /opt/netbox/gunicor> ``` ## Step 7 – Configure Nginx as a Reverse Proxy First, install the Nginx packages. ``` apt install nginx ``` Next, edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http{: ``` server_names_hash_bucket_size 64; ``` Then, create a new Nginx virtual host configuration file. ``` nano /etc/nginx/conf.d/netbox.conf ``` Add the following configurations. ``` server { listen 80; server_name netbox.example.com; access_log /var/log/nginx/netbox.access.log; error_log /var/log/nginx/netbox.error.log; client_max_body_size 25m; # Proxy everything over to the netbox server location /static/ { alias /opt/netbox/netbox/static/; } location / { proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-Host $http_host; proxy_pass http://127.0.0.1:8001; } } ``` Save the file then verify the Nginx for any syntax error. ``` nginx -t ``` Output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` You can now access NetBox using the URL http://netbox.example.com. ## Conclusion By following the installation process outlined in this guide, network administrators can harness the full potential of NetBox to streamline operations, enhance visibility, and maintain a well-documented network infrastructure. Embrace the power of NetBox on Ubuntu 24.04 and take control of your network infrastructure with confidence. Try to deploy NetBox on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Flask with Nginx and Gunicorn on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-flask-with-nginx-and-gunicorn-on-ubuntu-24-04/ | Published: 2024-03-07 | Updated: 2025-07-04 | Author: Hitesh Jethva Flask, a lightweight and versatile web framework for Python, empowers developers to build web applications with ease and flexibility. It allows developers to create web applications quickly and efficiently by providing the necessary tools and features without imposing too many constraints. When combined with Nginx, a high-performance web server renowned for its speed and efficiency, Flask-based applications can achieve optimal performance and scalability. This guide aims to walk you through the process of installing Flask with Nginx on Ubuntu 24.04. ## Step 1 – Install Required Dependencies Before starting, you will need to install Python and other required dependencies to your server. First, install the Python and Python virtual environment using the following command. ``` apt update -y apt install python3-pip python3-venv -y ``` Next, verify the Python version using the following command. ``` python3 --version ``` Output. ``` Python 3.12.3 ``` Next, install Nginx and Supervisor with the following command. ``` apt install nginx supervisor -y ``` ## Step 2 – Create a Flask Application First, create your application directory. ``` mkdir -p /var/www/myapp ``` Next, change the ownership of the application directory. ``` chown -R www-data:www-data /var/www/myapp ``` Then, navigate to your application directory and create a Python virtual environment. ``` cd /var/www/myapp python3 -m venv myenv ``` Next, activate the Python virtual environment. ``` source myenv/bin/activate ``` Next, install the Flask and Gunicorn. ``` pip install flask gunicorn ``` Next, create a application file. ``` nano app.py ``` Add the following code: ``` from flask import Flask app = Flask(__name__) @app.route('/') def hello(): return "Hello, World!" if __name__ == '__main__': app.run() ``` Save and close the file, then run the application with the following command. ``` gunicorn -w 4 -b 0.0.0.0:8000 app:app ``` You will see the following output. ``` [2024-02-15 03:29:22 +0000] [114941] [INFO] Starting gunicorn 21.2.0 [2024-02-15 03:29:22 +0000] [114941] [INFO] Listening at: http://0.0.0.0:8000 (114941) [2024-02-15 03:29:22 +0000] [114941] [INFO] Using worker: sync [2024-02-15 03:29:22 +0000] [114942] [INFO] Booting worker with pid: 114942 [2024-02-15 03:29:22 +0000] [114943] [INFO] Booting worker with pid: 114943 [2024-02-15 03:29:22 +0000] [114944] [INFO] Booting worker with pid: 114944 [2024-02-15 03:29:22 +0000] [114945] [INFO] Booting worker with pid: 114945 ``` Press CTRL+C to stop the application. Then, create a WSGI for your application. ``` nano wsgi.py ``` Add the following code: ``` from app import app if __name__ == "__main__": app.run(debug=True) ``` Now, verify your application using WSGI. ``` gunicorn -w 4 --bind 0.0.0.0:8000 wsgi:app ``` Now, open your web browser and access your Flask app using the URL **http://your-server-ip:8000.** You will see your Flask application on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p1-8.png) Press **CTRL+C** to stop the application. ## Step 3 – Create a Service File for the Flask App Next, create a supervisor configuration file to manage your Flask app via systemd. ``` nano /etc/supervisor/conf.d/myapp.conf ``` Add the following configurations. ``` [program:myapp] command=/bin/bash -c 'source /var/www/myapp/myenv/bin/activate; gunicorn -w 3 --bind unix:/var/www/myapp/ipc.sock wsgi:app' directory=/var/www/myapp user=www-data group=www-data autostart=true autorestart=true stdout_logfile=/var/www/myapp/myapp.log stderr_logfile=/var/www/myapp/error.log ``` Save and close the file, then restart the Supervisor to apply the changes. ``` systemctl restart supervisor ``` You can check the status of the Supervisor with the following command. ``` systemctl status supervisor ``` Output. ``` ● supervisor.service - Supervisor process control system for UNIX Loaded: loaded (/usr/lib/systemd/system/supervisor.service; enabled; preset: enabled) Active: active (running) since Thu 2025-05-15 12:17:28 UTC; 3s ago Docs: http://supervisord.org Main PID: 41835 (supervisord) Tasks: 5 (limit: 629145) Memory: 71.9M (peak: 72.1M) CPU: 631ms CGroup: /system.slice/supervisor.service ├─41835 /usr/bin/python3 /usr/bin/supervisord -n -c /etc/supervisor/supervisord.conf ├─41837 /var/www/myapp/myenv/bin/python3.12 /var/www/myapp/myenv/bin/gunicorn -w 3 --bind unix:/var/www/myapp/ipc.sock wsgi:app ├─41838 /var/www/myapp/myenv/bin/python3.12 /var/www/myapp/myenv/bin/gunicorn -w 3 --bind unix:/var/www/myapp/ipc.sock wsgi:app ├─41839 /var/www/myapp/myenv/bin/python3.12 /var/www/myapp/myenv/bin/gunicorn -w 3 --bind unix:/var/www/myapp/ipc.sock wsgi:app └─41840 /var/www/myapp/myenv/bin/python3.12 /var/www/myapp/myenv/bin/gunicorn -w 3 --bind unix:/var/www/myapp/ipc.sock wsgi:appp ``` ## Step 4 – Configure Nginx for Flask App First, create an Nginx virtual server block for the Flask app. ``` nano /etc/nginx/conf.d/myapp.conf ``` Add the following configurations. ``` server { listen 80; server_name app.example.com; location / { include proxy_params; proxy_pass http://unix:/var/www/myapp/ipc.sock; } } ``` Save and close the file, then restart the Nginx service to implement the changes. ``` systemctl restart nginx ``` Now, open your web browser and access your Flask App using the URL **http://app.example.com.** ## Conclusion Congratulations! You have successfully installed Flask with Nginx on Ubuntu 24.04. By following these steps, you can develop and deploy Flask-based web applications efficiently and securely. With Flask’s simplicity and flexibility combined with Nginx’s performance and reliability, you have a powerful platform for building robust web applications that can scale to meet the demands of your users. You can now test the Flask application on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Create a Chat Server Using Matrix Synapse and Element on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-create-a-chat-server-using-matrix-synapse-and-element-on-ubuntu-24-04/ | Published: 2024-03-08 | Updated: 2025-05-16 | Author: Hitesh Jethva Matrix Synapse is a high-performance communication server built on the Matrix open standard for decentralized communication. The Matrix protocol is designed to provide a secure, interoperable, and decentralized communication infrastructure, allowing users to exchange messages, participate in group chats, share files, and collaborate across different platforms and services. This comprehensive guide will walk you through the installation process, ensuring a seamless setup of Matrix Synapse on your Ubuntu 24.04 server. ## Step 1 – Add Matrix Synapse Repository By default, the Matrix Synapse package is not included in the Ubuntu default repository, so you will need to install it from its official repository. First, download the Matrix Synapse GPG key. ``` wget -O /usr/share/keyrings/matrix-org-archive-keyring.gpg https://packages.matrix.org/debian/matrix-org-archive-keyring.gpg ``` Then, add the Matrix Synapse repository to the APT source file. ``` echo "deb [signed-by=/usr/share/keyrings/matrix-org-archive-keyring.gpg] https://packages.matrix.org/debian/ $(lsb_release -cs) main" | tee /etc/apt/sources.list.d/matrix-org.list ``` Next, update the package index using the following command. ``` apt update -y ``` ## Step 2 – Install Matrix Synapse Now, install the Matrix Synapse package using the following command. ``` apt install matrix-synapse-py3 ``` You will be asked to provide your domain name as shown below: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p1-9.png) Provide your domain name and click on OK. Once Matrix Synapse is installed, start the Matrix Synapse service using the following command. ``` systemctl start matrix-synapse ``` You can now verify the status of Matrix Synapse using the following command. ``` systemctl status matrix-synapse ``` Output. ``` ● matrix-synapse.service - Synapse Matrix homeserver Loaded: loaded (/usr/lib/systemd/system/matrix-synapse.service; enabled; preset: enabled) Active: active (running) since Fri 2025-05-16 06:08:58 UTC; 10s ago Process: 76117 ExecStartPre=/opt/venvs/matrix-synapse/bin/python -m synapse.app.homeserver --config-path=/etc/matrix-synapse/homeserver.yaml --config-path=/etc/mat> Main PID: 76154 (python) Tasks: 8 (limit: 629145) Memory: 97.1M (peak: 98.6M) CPU: 3.994s CGroup: /system.slice/matrix-synapse.service └─76154 /opt/venvs/matrix-synapse/bin/python -m synapse.app.homeserver --config-path=/etc/matrix-synapse/homeserver.yaml --config-path=/etc/matrix-synapse> May 16 06:08:55 ubuntu24 matrix-synapse[76117]: Generating signing key file /etc/matrix-synapse/homeserver.signing.key May 16 06:08:57 ubuntu24 matrix-synapse[76154]: This server is configured to use 'matrix.org' as its trusted key server via the May 16 06:08:57 ubuntu24 matrix-synapse[76154]: 'trusted_key_servers' config option. 'matrix.org' is a good choice for a key May 16 06:08:57 ubuntu24 matrix-synapse[76154]: server since it is long-lived, stable and trusted. However, some admins may May 16 06:08:57 ubuntu24 matrix-synapse[76154]: wish to use another server for this purpose. May 16 06:08:57 ubuntu24 matrix-synapse[76154]: To suppress this warning and continue using 'matrix.org', admins should set May 16 06:08:57 ubuntu24 matrix-synapse[76154]: 'suppress_key_server_warning' to 'true' in homeserver.yaml. May 16 06:08:57 ubuntu24 matrix-synapse[76154]: -------------------------------------------------------------------------------- May 16 06:08:57 ubuntu24 matrix-synapse[76154]: Config is missing macaroon_secret_key May 16 06:08:58 ubuntu24 systemd[1]: Started matrix-synapse.service - Synapse Matrix homeserver. ``` At this point, Matrix Synapse is started and listens on port 8008. You can verify it using the command given below: ``` ss -plnt | grep 8008 ``` Output. ``` LISTEN 0 50 127.0.0.1:8008 0.0.0.0:* users:(("python",pid=2170,fd=14)) LISTEN 0 50 [::1]:8008 [::]:* users:(("python",pid=2170,fd=13)) ``` ## Step 3 – Configure Matrix Synapse First, generate the secret key using the following command. ``` cat /dev/urandom | tr -dc 'a-zA-Z0-9' | fold -w 32 | head -n 1 ``` Output. ``` c4eEv6cZCc1jXeHGbzFyzGB0RFPp2HfP ``` Next, edit the Matrix Synapse main configuration file. ``` nano /etc/matrix-synapse/homeserver.yaml ``` Change the following lines: ``` listeners: - port: 8008 tls: false type: http x_forwarded: true bind_addresses: ['127.0.0.1'] resources: - names: [client, federation] compress: false enable_registration: false registration_shared_secret: "c4eEv6cZCc1jXeHGbzFyzGB0RFPp2HfP" ``` Save and close the file, then restart the Matrix Synapse service to reload the changes. ``` systemctl restart matrix-synapse ``` ## Step 4 – Create an Administrative User Next, you will need to create an admin user to authenticate Matrix Synapse. You can create it using the following command. ``` register_new_matrix_user -c /etc/matrix-synapse/homeserver.yaml http://localhost:8008 ``` Define your user and password as shown below: ``` New user localpart [root]: madmin Password: Confirm password: Make admin [no]: yes Sending registration request... Success! ``` ## Step 5 – Download Let’s Encrypt SSL We will use the Let’s Encrypt SSL to secure the Matrix Synapse server. First, install the Nginx web server. ``` apt install nginx ``` Next, install the Certbot Let’s Encrypt client using the following commands. ``` snap install core ``` ``` snap refresh core ``` ``` snap install --classic certbot ``` ``` ln -s /snap/bin/certbot /usr/bin/certbot ``` Next, download the Let’s Encrypt SSL for your domain. ``` certbot certonly --nginx --agree-tos --no-eff-email --staple-ocsp --preferred-challenges http -m hitjethva@gmail.com -d matrix.linuxbuz.com ``` Next, generate the dhparam using the following command. ``` openssl dhparam -dsaparam -out /etc/ssl/certs/dhparam.pem 4096 ``` ## Step 6 – Configure Nginx for Matrix Synapse Next, you will need to configure Nginx as a reverse proxy for Matrix Synapse. First, edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http{: ``` server_names_hash_bucket_size 64; ``` Next, create an Nginx virtual host configuration file for Matrix Synapse. ``` nano /etc/nginx/conf.d/synapse.conf ``` Add the following configurations. ``` # enforce HTTPS server { # Client port listen 80; server_name matrix.linuxbuz.com; return 301 https://$host$request_uri; } server { server_name matrix.linuxbuz.com; # Client port listen 443 ssl http2; listen [::]:443 ssl http2; # Federation port listen 8448 ssl http2 default_server; listen [::]:8448 ssl http2 default_server; access_log /var/log/nginx/synapse.access.log; error_log /var/log/nginx/synapse.error.log; # TLS configuration ssl_certificate /etc/letsencrypt/live/matrix.linuxbuz.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/matrix.linuxbuz.com/privkey.pem; ssl_trusted_certificate /etc/letsencrypt/live/matrix.linuxbuz.com/chain.pem; ssl_protocols TLSv1.2 TLSv1.3; ssl_prefer_server_ciphers on; ssl_stapling on; ssl_stapling_verify on; ssl_dhparam /etc/ssl/certs/dhparam.pem; location /_matrix { proxy_pass http://localhost:8008; proxy_set_header X-Forwarded-For $remote_addr; # Nginx by default only allows file uploads up to 1M in size # Increase client_max_body_size to match max_upload_size defined in homeserver.yaml client_max_body_size 10M; } } # This is used for Matrix Federation # which is using default TCP port '8448' server { listen 8448 ssl; server_name matrix.linuxbuz.com; ssl_certificate /etc/letsencrypt/live/matrix.linuxbuz.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/matrix.linuxbuz.com/privkey.pem; location / { proxy_pass http://localhost:8008; proxy_set_header X-Forwarded-For $remote_addr; } } ``` Save and close the file, then reload Nginx to apply the changes. ``` systemctl restart nginx ``` ## Step 7 – Access Matrix Synapse You can now verify the Matrix Synapse installation using the URL **https://matrix.linuxbuz.com:8448/_matrix/static/** on your web browser. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p2-7.png) You can also verify your Matrix Synapse using the Riot web-based client **https://riot.im/app/#/login.** You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p3-4.png) Click on the **Edit** button. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p4-3.png) Provide your Matrix server URL and click on the **Continue** button. You should see the Matrix login page: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p5-3.png) Provide your admin username and password and click on the **Sign in** button. Once you are connected to the Matrix Synapse server. You should see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p6-2.png) ## Conclusion Congratulations! You have successfully installed Matrix Synapse on Ubuntu 24.04, providing a powerful platform for decentralized communication and collaboration. With Matrix Synapse configured and running, you can explore its rich features and integrate them into your communication workflows. Enjoy seamless and secure real-time messaging with Matrix Synapse on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Atlantic.Net Introduces a New Feature to Further Simplify User Experience for Developers Around the Globe > URL: https://www.atlantic.net/press-releases/atlantic-net-introduces-a-new-feature-to-further-simplify-user-experience-for-developers-around-the-globe/ | Published: 2024-03-19 | Updated: 2024-11-22 | Author: Editorial Team **Atlantic.Net Introduces a New Feature to Further Simplify User Experience for Developers Around the Globe** *Atlantic.Net Team (ANT) enables users to securely collaborate and share resources globally to boost productivity and efficiency* **ORLANDO, Fla. – March 19th, 2024 –** [Atlantic.Net](https://www.atlantic.net/), a leading cloud services provider, today released Atlantic.Net Teams (ANT), a new feature that allows users to securely collaborate and share resources like cloud servers, IP addresses, DNS, block storage, and more without having to share sensitive information like login credentials or billing information. By offering multi-level user access to better manage access to privileged information, Atlantic.Net has added an extra layer of security for organizations. “This exciting feature will increase collaboration between IT teams across the globe, boost productivity, and make teams more efficient,” said Marty Puranik, CEO, and founder of Atlantic.Net. “Our goal is to provide our customers with the best possible experience and support, and ANT is an important part of that commitment.” Highlights of the feature include the ability to create and invite others to join a Team, assign group permissions to Team users (like administrator, technical, billing, observer or custom groups), track actions users take via searchable user and service audit logs, set security permissions for users, and share essential information through notes that can be placed on resources. Atlantic.Net is helping developers thrive in the digital age by providing scalable computing from eight secure data centers worldwide, including New York, Singapore, London, San Francisco, Toronto, Dallas, Ashburn, and Orlando, each engineered to provide fault-tolerant and ultra-fast performance. For more information, please visit [Atlantic.Net](https://www.atlantic.net/). **About Atlantic.Net** Atlantic.Net is an award-winning global cloud services provider with a focus on security, compliance, and simplifying complex infrastructures. With over 30 years of experience, Atlantic.Net is dedicated to offering developers and IT leaders at small, medium, and large organizations a range of on-demand, customized, and cost-effective cloud solutions that cater to their unique business needs. Having served clients like Lenovo, Newegg, NASA and Hilton, the company’s commitment to excellence has positioned it as a leader in the industry, recognized for its innovation and customer-centric approach. ### Media Contact 5WPR for Atlantic.net atlantic@5wpr.com --- # Announcing Atlantic.Net Teams, an Efficient and Secure Collaboration Tool! > URL: https://www.atlantic.net/announcements/announcing-atlantic-net-teams-an-efficient-and-secure-collaboration-tool/ | Published: 2024-03-19 | Updated: 2025-03-06 | Author: Alexander Wise We are thrilled to announce the launch of Atlantic.Net Teams (ANT), our latest innovation in cloud collaboration. As Atlantic.Net celebrates its 30th anniversary of providing cutting-edge web services worldwide, ANT represents our commitment to empowering teams with secure and efficient collaboration tools. ![](https://www.atlantic.net/wp-content/uploads/2024/03/Announcing-Atlantic.Net-Teams2_1-1.jpg) ## What Is Atlantic.Net Teams? With ANT, users can effortlessly collaborate and share resources such as cloud servers, IP addresses, DNS, block storage, and more. This empowers teams to work together efficiently and effectively from anywhere in the world without sharing sensitive information like login credentials or billing information. Key Features of Atlantic.Net Teams: ## Secure Collaboration ANT enables users to securely collaborate without exposing sensitive information like login credentials or billing details. Teams can effortlessly share resources such as cloud servers, IP addresses, DNS, and block storage, facilitating seamless collaboration without risk. ## Multi-Level User Access Manage privileged information effectively with ANT’s multi-level user access. Assign specific roles such as administrator, technical, billing, observer, or custom groups, ensuring each team member has the appropriate level of access. ## Enhanced Security Measures ANT offers a range of security measures to safeguard data and resources. From requiring two-factor authentication for team users to setting password policies and preventing password reuse, Atlantic.Net enforces robust security protocols as standard. ## Resource Management Hub ANT includes a centralized resource management hub, allowing teams to track actions and access vital information effortlessly. From creating and inviting team members to setting security permissions and tracking user actions via audit logs, everything is conveniently accessible within the ANT interface. ## Global Accessibility Atlantic.Net boasts a global presence, with data centers strategically located in eight secure locations worldwide. Teams can leverage Atlantic.Net’s fault-tolerant infrastructure and ultra-fast performance by simplifying collaboration from New York to Singapore and London to San Francisco. ## Benefits of Atlantic.Net Teams (ANT) Streamlined Collaboration: ANT simplifies teamwork by enabling seamless collaboration, allowing teams to work together efficiently, regardless of their physical location. This creates controlled, smoother communication and project coordination. Heightened Productivity: By removing the complexity of sharing sensitive information and optimizing resource management, ANT significantly boosts productivity. Teams can focus more on their tasks, leading to accelerated project delivery and improved outcomes. SecOps: ANT prioritizes the security of data and resources with its comprehensive security measures. Teams can confidently collaborate, knowing their information is safeguarded against unauthorized access and cyber threats. Scalable Infrastructure: Atlantic.Net’s scalable computing infrastructure gives teams access to the resources they need to scale and expand their projects seamlessly. This ensures that the platform grows with the team’s requirements, effectively supporting their evolving needs. **All new customers will receive a free cloud server for a year, including 2GB RAM, 50 GB SSD disk, and 3TB monthly transfer.** **Ready to elevate your team’s collaboration experience? Get started in the [Atlantic.Net Control Panel](https://cloud.atlantic.net/?page=userlogin) today!** ![](https://www.atlantic.net/wp-content/uploads/2024/03/Announcing-Atlantic.Net-Teams2_2-1.jpg) --- # What Is a Managed Service Provider? A Brief Guide to MSPs > URL: https://www.atlantic.net/managed-services/what-is-a-managed-service-provider-a-brief-guide-to-msps/ | Published: 2024-03-24 | Updated: 2026-03-01 | Author: Richard Bailey ## What are Managed Service Providers? Managed Service Providers (MSPs) offer technical solutions and skilled resources to businesses and organizations needing help and guidance in deploying and managing information technology infrastructure; MSPs provide IT services to their customers and employees. ## What Is a Managed Service? Managed Service covers a broad spectrum of technical services, including network management, IT hosting services, security-as-service, cloud computing platforms, and data management and backup designed to help companies manage their IT infrastructure. ## **What are the Benefits of Using a Managed Service Provider?** When opting to outsource IT services to an MSP, users benefit from the expertise of the provider and they can immediately start consuming the managed services at a technical and administrative level. Managing and maintaining a private data center with the latest hardware, environmental controls, and a skilled team to keep the lights on is a costly process. It is difficult for small and medium businesses to create a private data center. Fortunately, this is precisely where Managed Service Providers (MSPs) can help. This article will introduce how managed service providers work and explain the most common benefits of using one. We’ll also discuss the pricing models available, allowing you to choose the best option for your budget and business needs. ## **Types of Managed Services Providers** The computer industry is expansive, and plenty of options are available when choosing your next [managed service provider](https://www.atlantic.net/managed-services/what-are-managed-services/). You need to weigh the costs vs. the required skillsets and choose the best provider that meets your needs. There are three managed service providers; all offer cloud-based hosting in either a public, private, or hybrid configuration. 1. ***Public Cloud:*** The hyper-scale cloud providers are the mainstream public cloud providers that offer global, scalable cloud infrastructure, vast infrastructure services, and global reach; however, most are prohibitively expensive and require a team of professionals to manage and maintain. 2. ***Private clouds*,** on the other hand, are usually chosen by organizations with specific needs, such as bespoke security or compliance requirements. Private cloud platforms are typically hosted within a choice of dedicated data center locations and offer more affordability, control, and customization than public clouds. 3. ***Hybrid clouds*** combine elements of both public and private clouds, allowing businesses to leverage the benefits of both worlds while maintaining greater control over their data. This is important for companies that have strict data residency rules. With thousands of managed service provider options, who you choose will depend on what cloud services you need and whether the provider can customize the solutions to your specific industry requirements or niches. Providers with a more personalized service will often better understand their customers’ needs and challenges. It’s crucial to align your business’s needs and requirements with the best-managed service provider. ## **What Do Managed Service Provider (MSP) Do?** The technical solutions offered by each cloud provider vary, but they all offer services within specific functions. What makes each provider unique is the service wrapper that brings the managed service together, creating a comprehensive solution that meets your individual needs. Let’s dig deeper into the core functions of an MSP, and what they do: - Network Infrastructure Management - Security-as-a-Service - Data Integrity - Server Management - Business continuity - Technical Support - Service Level agreements #### **#1: Network Infrastructure Management** The network layer demands skilled professionals who monitor the WAN/LAN for potential disruptions while ensuring it operates seamlessly and securely in-house. Customers expect an isolated environment that is easy to manage. #### **#2: Security-as-a-Service** When outsourcing IT, it’s essential to safeguard the company’s digital assets using robust security measures. You expect the provider to be resilient to cyber-attacks by providing an environment that secures a business’s reputation and finances. Proactive, around-the-clock security monitoring and intelligent logging systems identify and automatically address potential security breaches before they escalate. #### **#3: Data Integrity** A business’s lifeblood is its data, so managed service providers protect client data. Data encryption technology is implemented on static and moving data,  and a proven data backup strategy is crucial. An MSP will ensure that a business’s data is available 24/7 and is backed up regularly and securely. They will also provide the data that can be restored quickly during a disaster. #### **#4: Server Management** Businesses can offload the day-to-day management of servers to the managed service provider if required. This service includes the entire infrastructure’s remote monitoring and breakfix support. The typical provider setup includes a nerve center, such as a Network Operations Center (NOC), which employs 24/7/365 staff to respond to automated alerts about your systems. This will include low disk space warnings, high CPU, high memory usage, and technical support on demand. It’s easy to bolt on additional services like patch management, antivirus updates, and system upgrades. #### **#5: Business continuity** [Business continuity and disaster recovery](https://www.atlantic.net/disaster-recovery/) managed services help businesses to ensure that their critical systems and data are protected and can be recovered quickly in the event of a disruption, such as a natural disaster, cyber-attack, or human error. #### **#6: Technical Support** In the world of computers, things break or behave unexpectedly. Suppose you do not opt for full server management services; it’s great to have technical support available around the clock. You may need to fire off a quick question; tech teams can quickly get you the necessary answer. #### **#7: Service Level agreements** By offering Service Level Agreements (SLAs), outsourced IT providers demonstrate their commitment to providing exceptional IT support to their clients, backed by measurable performance metrics and clear expectations – ensuring your business receives the reliable support it deserves. ## **What are the benefits of Managed Service Providers?** As businesses grow, the demand for IT services will generally increase. Most modern companies would only function with a reliable IT platform. When you are ready to outsource to an MSP, you can unlock the potential in your business by purchasing on-demand solutions that would be cost-prohibitive if you went solo. What distinct benefits can your business unlock by outsourcing to an MSP? - Improved operational efficiency - Reduced downtime - Access to advanced technology - Scalability - Predictable costs - Increased productivity - Greater flexibility - Security-as-a-Service - Proactive maintenance - Faster response times - Compliance support - **Improved operational efficiency:** An MSP can bring decades of experience to your business and provide professional services to enhance your company’s operations. An MSP can help you move to market leverage solutions that fix legacy bottlenecks and workflow issues faster. - **Reduced downtime:** Keeping the lights on 24/7 is not easy, but 100% uptime guarantees are expected within the industry. 24/7 remote monitoring and support helps businesses address issues before they lead to system downtime. - **Access to advanced technology:** A strategic IT partner will have expert resources to help your business stay current with the latest technology and can help clients leverage innovations at a fraction of the cost. Managed cloud services, specialist software platforms, and other cutting-edge technology are available on demand in the cloud. - **Scalability:** Cloud hosting is excellent at providing scaling services out-of-the-box that can scale to meet the demands of predictable and unpredictable workloads. As your business grows, your needs will change, and being able to scale up system resources to meet your changing business demands is a game changer. - **Predictable costs:** Keeping track of expenses is essential, and MSPs provide several useful tools to keep on top of your spending. With a subscription model and a defined set of services, fixed-pricing business models allow you to budget for IT expenses more effectively and control budgetary expenditures. - **Increased productivity:** Managed service providers can help clients focus on core business functions, and their companies improve productivity by handling IT tasks and freeing internal resources. - **Greater flexibility:** On-demand and fixed-term two or three-year contracts are essential for growing businesses with changing business needs. - **Security-as-a-Service:** With expertise in cybersecurity and remote firewall administration, managed service providers can help clients protect against cyber threats. MSPs with a proven track record in security give you significant, tangible benefits such as round-the-clock monitoring, regular risk assessments, and the guaranteed implementation of best practices. - **Proactive maintenance:** Good MSPs provide application performance monitoring to watch your systems around the clock and handle the regular maintenance tasks necessary to keep IT systems running smoothly. - **Faster response times:** Tech support is available around the clock, helping businesses avoid costly outages and maintain native services whenever a problem occurs. - **Compliance support:** Regulations can be challenging to uphold in-house. Leveraging an MSP certified in HIPAA, PCI-DSS, HITECH, or ISO standards is an excellent start because an authoritative body has already vetted and validated their services. We have just scratched the surface of the potential benefits you can achieve from choosing your next MSP. Look for a Managed Service Provider to offer customized solutions that understand ‘one size doesn’t fit all.’ Proactive problem-solving reduces risk and helps your business improve continually. ## **How Much Does the Managed Service Provider Charge?** MSP’s generally offers flexible pricing models suitable for businesses of all shapes and sizes. - **Per-Device Pricing: **Per-device (server) pricing is a popular pricing model where small businesses can pay a fixed monthly fee per device managed by the MSP, perfect for smaller companies that keep on top of costs. - **Per-User Pricing: **Businesses pay a fixed fee per user managed by the MSP. The per-user model suits businesses with many users who want to manage their IT infrastructure costs effectively. - **Flat-Fee Pricing: **Flat-fee pricing is a comprehensive pricing model where businesses pay a fixed fee for a range of services the MSP provides. - **Hybrid Pricing: **Hybrid pricing model combines per-device and per-user pricing. MSP’s work closely with their customers to understand their business needs and design a pricing model that is both cost-effective and flexible. ## **Inside Managed Services** Atlantic.Net has provided IT services for nearly 30 years. We are proud of our relationships with our client base, who choose us because we understand their business needs. From solution design to early life support and beyond, Atlantic.Net is there every step of the way. Our team of experts, based in Orlando, Florida, proactively monitors the network and seamlessly manages security, data backups, and our vast cloud infrastructure service. Atlantic.Net is a reliable, experienced, and flexible Managed Service Provider that offers affordable, customized IT solutions with unparalleled support. Helping you streamline your IT operations, maximize efficiency, and minimize downtime. ## **Seamless Onboarding** At Atlantic.Net, we are committed to providing our customers with exceptional managed services tailored to their unique business needs. We will be involved in as much (or as little) as you wish. The onboarding process is essential to creating a customized solution to meet your business goals and objectives. 1. **Initiate Engagement: **After the commercial agreements are in place, our teams continue the initial discussions to scope the customer’s needs. 2. **Comprehensive Analysis: **Our experts draw up precisely what the customer wants and identify opportunities for improvement; potential challenges, vulnerabilities, and risks are highlighted at this stage. 3. **Customized Solution: **We develop a personalized solution that meets the client’s needs based on our analysis. We work with clients to determine the best hardware, software, and managed services for them. 4. **Implementation: **After the design has been finalized, we implement it! Ensuring all IT systems operate efficiently and securely. 5. **Provide Ongoing Maintenance and Support: **We provide continuous support to ensure the client’s IT systems and business processes remain secure, reliable, and efficient. At Atlantic.Net, we are passionate about providing our clients with the highest quality managed services. In addition, we are committed to delivering customized solutions aligned with our client’s goals and objectives. ## **Make Atlantic.Net Your Managed Service Provider** Our experts are here to provide ongoing support and ensure your systems remain secure and operate efficiently. Don’t settle for less – choose Atlantic.Net as your Managed Service Provider today and experience the difference. Learn more in our guide to[ managed hosting](https://www.atlantic.net/managed-services/what-is-a-managed-service-provider-a-brief-guide-to-msps/), or[ contact us](https://www.atlantic.net/about-us/corporate-contact/) now to get started! --- # Managed IT Services > URL: https://www.atlantic.net/managed-services/what-are-managed-it-services-overview-types-and-new-trends-to-watch-out-for/ | Published: 2024-03-25 | Updated: 2025-09-11 | Author: Richard Bailey ## What Are Managed IT Services? Managed IT Services provide a means of outsourcing the implementation, management, and maintenance of your IT infrastructure to a third-party managed services provider. In return for the continued management of their IT systems, the client typically pays the third-party vendor a monthly fee for support, technical assistance, and the day-to-day management of their managed IT service and other managed services used. The company providing the Managed IT Services is referred to as a Managed Service Provider (MSP). They work around the clock to monitor the entire IT infrastructure of their client and provide ongoing technical support where needed. This support may include critical first-, second-, and third-line support, such as IT operation, managed services, security management, remote application hosting services, and endpoint device governance. ## What Services Are Usually Included in Managed Services? The services offered under a managed services model can vary depending upon the individual needs of their client. In most circumstances, the service is unique to the client. This is because a white-glove approach to managed services often produces the best results for the client. Here, we will have a closer look at some commonly managed services: ### 24/7 Support Services & Monitoring Managed IT services typically offer their clients 24/7 support services and remote monitoring of managed computer systems. This means that the Managed Service Provider will be available around the clock to ensure the smooth operation of your managed IT services infrastructure and to address any problems as they arise. 24/7 monitoring allows the Managed Service Provider to proactively identify problems early on and to address them straight away, helping to minimize unplanned downtime and enhance business productivity, both in and out of hours. This could include tasks such as monitoring servers, infrastructure monitoring, network monitoring, updating software, improving system performance, and performing regular backups and restores. This service is particularly important for small and medium-sized businesses that may not have the resources to employ full-time IT support staff around the clock in-house. Outsourcing desk support and IT system monitoring needs to an MSP delivers big advantages; you can be assured that service never sleeps and the IT systems are being maintained to the highest standards throughout the day. ### Proactive Maintenance By actively monitoring a client’s IT infrastructure, an MSP can take proactive steps to prevent issues before they occur. Proactive maintenance as a managed service could involve monthly security patching, regular software updates, hardware checks, and performance optimization. Proactive maintenance reduces the need for reactive break fixes. Needless to say, support is available when the unexpected happens, but a proactive approach and professional services automation reduces the probability of having to resort to reactive maintenance. ### Data Backups & Recovery With an ever-increasing reliance on data, businesses must ensure that they have effective and up-to-date data integrity and data security procedures in place. With this in mind, data backups and recovery are incredibly important and a commonly requested feature of all managed service models. Data backup involves regularly making copies of important data and storing these copies in a secure location. We recommend the [3-2-1 approach](https://www.atlantic.net/disaster-recovery/what-is-a-3-2-1-backup-strategy/) to data protection, this ensures that if the original, sensitive data is lost, it can be easily recovered from a backup kept in various locations. MSPs typically offer a variety of backup options, including on-site and off-site backups, as well as cloud-based replicated backups. Additionally, MSPs typically provide their clients with a disaster recovery planning (DRP) service. This involves creating a comprehensive plan for dealing with disasters and minimizing any impact on the business. A proven backup strategy is a vital part of the DRP. The purpose of disaster recovery planning is to identify potential risks, develop response plans, and test those plans to ensure that they are effective for your business continuity. ### Managed Security services Managed security services help to protect organizations from any cybersecurity threats, including cyberattacks. These services typically offer remote assistance and include advanced threat detection, vulnerability assessment, security audits, penetration testing, and incident response. Many of the specialized security solutions offered by an MSP may not typically be available to an organization’s in-house teams. One of the hardest things to achieve for security compliance is accurate logging and auditing. The volume of logs created by modern security software is highly verbose; as a result, you may feel overwhelmed by the volume of alerts and information you receive. The best-managed service providers use intelligent tool sets and operating systems that only alert against issues that deviate from normal operations. Using SIEM tools, AI, and human interaction, logging platforms can distinguish genuine issues from false positives, and understand what issues require further investigation. This is where the power of Managed Security Services shines. ### Cloud Services Transitioning to the cloud can be a massive undertaking for businesses that do not already have a cloud presence. It requires significant planning, resources, and expertise to make cloud migration a success. The benefits of moving to the cloud are significant, including cost reductions, access to advanced managed services, and the ability for a business to rapidly scale up to meet growing demand. Working with an MSP helps to simplify this process for businesses and organizations. An MSP can help their clients to transition their infrastructure into the cloud. Look for professional services that focus on cloud migration, and pay particular attention to those that include helpful migration services. The help available varies on your requirements; cloud providers can offer a light touch advice service to help you get started, or you can reach out for end-to-end support on the entire migration process. Cloud providers’ service offerings include virtual machines, storage solutions, and a comprehensive range of resources tailored to meet diverse business needs. With a strong emphasis on security and compliance, Atlantic.Net’s cloud services provide businesses with a flexible and resilient enterprise computing foundation, empowering businesses to optimize performance, enhance scalability, and strategically position their business to become a cloud-first organization in the near future. ### Consultancy MSPs may offer a range of expert consultancy services to their clients as a means of improving and simplifying their daily IT operations. These consultancy services could include IT services, strategy consulting, project management information technology consulting, and security consulting. Atlantic.Net offers a wide range of managed Consulting Services as part of its Managed IT Services that go beyond conventional hosting solutions, adding a layer of deep security and offering clients a tailored approach through 4-Tiered Managed Consulting Service packages (CAP). The choice of CAP depends on the system architecture and support needs of each enterprise. - **Tier 1:** Fundamental support is provided, covering basic configurations and the installation of applications like Filezilla. - **Tier 2:** This tier focuses on web hosting environments, managing application service providers such as cPanel or Plesk, and providing support for seamless site migrations. - **Tier 3:** Advancing to high-level, customized applications; tier 3 encompasses tasks like recompiling kernels and configuring advanced clustering programs like Heartbeat and DRBD. - **Tier 4:** At the highest level, Tier 4 delivers top-tier support, including critical services like Border Gateway Protocol (BGP) routing for large organizations managing multiple ISPs. This tier also includes expert database administration, compliance audits, and the implementation of bleeding-edge technologies. Each tier ensures a comprehensive and specialized level of service quality, with Tier 4 support conducted by seasoned engineers adept at handling complex technological landscapes. ### Endpoint Management A common managed service is the remote monitoring and management of endpoint devices, such as laptops, desktops, and mobile devices. MSPs can work to ensure that endpoints are always updated, functional, and secure. Endpoint-managed services could include software updates, patch management, antivirus and malware protection, remote management, and ongoing device monitoring. ### Vendor Management MSPs can provide vendor management services, which allow them to manage third-party contractor relationships on behalf of their client. This may include third-party vendor selection, contract negotiation, and the continued monitoring of vendor performance. These tasks all help to ensure that clients are receiving value from their third-party contractors in support of a reliable managed IT service. ### Regulatory Compliance Regulatory compliance is essential for any business or organization, but strict compliance regulations can be hard to navigate. An MSP can help to simplify this process for its clients, helping them to comply with relevant laws, regulations, and industry standards, such as GDPR, HIPAA, and PCI-DSS. Their input could include compliance assessments, policy development, and ongoing compliance monitoring. These tasks, provided by compliance experts, aim to reduce the significant risks associated with non-compliance. ## Managed IT Services vs. Cloud Services – What’s the Difference? Managed IT services and Managed Cloud Services are both types of managed IT services, but they have several key differences, which we will explore below: ### Managed IT Services A Managed IT Service Provider generally offers a wide range of services, managing and supporting an organization’s entire IT infrastructure. This comprehensive selection of services may include managing servers, networks, and endpoints, as well as providing data backup, strategic IT planning, help desk services, managed print services, and cybersecurity services to other organizations. Unlike a cloud service provider, MSPs can provide their services either on-premises remotely, or through a hybrid structure, depending on the needs and requirements of their clients. For businesses with an internal IT team, it is often preferable to work with an MSP that can manage on-premises infrastructure, including local servers, workstations, and networking equipment. Managed IT services often involve a fixed monthly subscription, which provides an “all-inclusive” range of services. This all-inclusive pricing structure allows businesses to predict and monitor their monthly expenditure. ### Cloud Services Cloud Service Providers are a subset of managed IT services, which provide provisions such as software, storage, security, and processing power over the Internet. Cloud services primarily involve hosting data, cloud-based applications, and entire IT environments on remote servers. This provides organizations with unparalleled scalability and flexibility. Cloud Services can be deployed using public, private, or hybrid cloud deployment models depending on the unique security and scalability business requirements. Leveraging cloud computing technologies can help to reduce the need for extensive on-premises hardware. While MSPs can provide a degree of scalability, this is not comparable to the instant scalability offered by the cloud services providers. For businesses with varying workloads, cloud service providers allow businesses to rapidly adjust their computing resources to align with current demand. Many cloud service providers offer a flexible pay-as-you-go price or the per-user model. This means that clients only pay for the services they use rather than paying a fixed fee. For businesses with variable workloads, this can often result in significant cost savings. ### Choosing Between Managed IT Services and Cloud Service Providers Whether you choose to work with an MSP or a cloud service provider will depend upon the specific needs and requirements of your business. You should take time to consider the merits of each service provider, thinking about your individual IT budget, the complexity and scale of your internal IT systems, and your specific IT service needs and requirements. ## Benefits of Managed IT Services Leveraging managed IT services can offer significant benefits to organizations and businesses of all sizes. These benefits include: ### Bridging the Skills Gap Often, the skills possessed by a business’s workforce do not align fully with the skills required to support their IT infrastructure and business applications. This skills gap can lead to reduced productivity, decreased competitiveness, and increased costs for businesses. Partnering with an MSP can help to bridge this gap by providing the necessary time, skills, and experience. With an MSP, businesses can benefit from a team of experts who can help manage their IT needs and ensure that their infrastructure is running smoothly. ### Providing Access to Expertise The expertise and knowledge provided by a dedicated MSP can prove invaluable for a business or organization. An experienced MSP can provide their clients’ channel partners with expert knowledge and real-world experience on a range of important issues, including cybersecurity and industry compliance. ### Cost Savings MSPs typically operate using a regular monthly subscription model. This helps to minimize costs and enables businesses to benefit from predictable pricing, allowing them to factor a regular payment into their monthly expenditure. Using a managed services model also allows clients to cut down on the costs associated with full-time employees and on-site infrastructure. By using a managed IT services provider, businesses can have access to the latest technological innovations at an affordable price. ### Increased Reliability One key advantage of leveraging a managed platform for managed IT services is that they can help to ensure that IT systems are properly maintained and updated. This can help to prevent unnecessary downtime and ensure optimal functionality. As managed services are provided under a service level agreement (SLA), businesses know what they can expect and how these services will be provided and evaluated. Furthermore, as MSPs can provide round-the-clock support and remote monitoring, this helps to prevent downtime and ensures that employees and internal teams are able to remain productive even in the event of technical issues. ### Improved Productivity By outsourcing the management of your managed IT services to a third party, you can free up time for your internal staff to concentrate on the business’s core competencies. This will help to enhance the productivity and operational efficiency of the workforce. ## Atlantic.Net: Managed Service Provider Atlantic.Net is celebrating its [30th year in business.](https://www.atlantic.net/about-us/corporate-contact/) We offer a wide range of managed it services, and we are proud to be your chosen Managed Services Provider. Our US-based support teams provide around-the-clock service to a wide range of customers. We offer a “pay-as-you-go” model, allowing our clients to tailor their IT needs accordingly. We also offer discounted two or three-year plans. Managed IT Services from Atlantic.Net will significantly reduce your IT spending and client costs. Our experts can procure hardware and software on your behalf at discounted rates from our suppliers, and our seasoned professionals have the expertise that’s crucial to navigate complex network infrastructure. Our expertise spans countless industries; we specialize in cloud computing, cyber security, compliance, and cloud services, to name just a few. We consistently deliver when it comes to emerging services, providing cutting-edge solutions that address our clients’ evolving IT needs. Managed service offerings such as Network Edge service delivery, IoT management, managed security services, and managed DDOS prevention services are core to our managed services model. We are so confident in our technology that we offer an i[ndustry-leading 100% uptime SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/). --- # About Managed Website Services > URL: https://www.atlantic.net/managed-services/what-are-managed-website-services/ | Published: 2024-03-26 | Updated: 2024-09-11 | Author: Richard Bailey There are an estimated [1.13 billion](https://www.forbes.com/advisor/in/business/software/website-statistics/) websites online, and this staggering figure demonstrates the desire for businesses, organizations, and individuals to create an online presence, drive sales, and inform the world about their mission. Web design is only half the battle. Have you considered what is required for website hosting? An online presence comes with concerns over uptime reliability, maintenance, costs, scalability, backup, and restore; perhaps you may have compliance concerns, or maybe you struggle with the technical aspects of hosting a website. Below, we explore website management services and how they can help your organization. ## What Are Managed Website Services? Managed website services refer to outsourcing comprehensive website maintenance tasks to a third party. These technical tasks are designed to ensure the smooth running of a business or organization’s website and typically include the outsourced management of website maintenance, day-to-day hosting services, performance optimizations, backups, security monitoring, updates, and support and troubleshooting. With website management services, website owners can focus on growing their business, creating content for their site, and safely leaving the technical aspects of running a website to the website management specialists. ## What Do Website Management Services Include? Website management services include a diverse range of tasks designed to ensure that a website is kept up-to-date, secure, and operating efficiently. These web management services include: ### Website Hosting Services Your chosen website management company will play a key role in ensuring that your website is accessible on the Internet. Instead of hosting your website on your own network server, your website management provider can host it on their specialized servers. Choosing the right hosting provider is essential to maintaining your website’s uptime. How would you be impacted if your website experienced a prolonged period of downtime? If you are simply hosting a static website for information, then perhaps the impact would be minimal; however, if your website was a revenue stream for your business, every second your website is down costs you sales and income. Elastic cloud services are cloud instances (servers) that are resilient to downtime. You can design and scale your website to make it handle server issues with near-zero unexpected downtime. It’s also important to have your website running on the correct hardware. If you have a high-traffic website or a website with seasonal traffic, you need to be prepared for surges and usage spikes. Can your infrastructure cope with the demand? Does your server have the capacity for the usage demands? It’s possible for your website management services provider to scale the infrastructure on demand or when you know spikes in traffic are expected. ### Technical Maintenance Services A web management agency that provides not only hosting but also comprehensive maintenance services is invaluable. From managed WordPress hosting to web design and ongoing maintenance, the best website management companies offer full-service solutions. Your website is a reflection of your business. Outdated websites can turn away potential clients. A web design company that offers affordable, flat-fee services can help in redesigning and managing your website effectively. Positive user experiences, client testimonials, and a responsive design are crucial for online success. Regular updates and maintenance to your website’s software and plugins are absolutely essential to succeed and ensure ongoing compatibility and security. Web designers and project managers working on your website should prioritize ongoing maintenance, introducing new features and pages to keep your site fresh. This approach not only satisfies search engines but also enhances the user experience. ### Security Monitoring and Response Implementing security measures to protect against malware, hacking, and other cyber threats and responding to any breaches that occur. A reputable website management service employs state-of-the-art tools for continuous security monitoring, ensuring your digital assets remain safeguarded from potential threats. This proactive strategy not only addresses performance issues promptly but also provides small business owners and digital marketers with the confidence that their online business is well-protected. For small businesses relying on a WordPress website, the importance of a well-maintained and secure digital presence cannot be overstated. Whether it’s addressing an outdated website, implementing a website redesign, or adding new pages to enhance engagement, a web management agency specializing in full-service solutions caters to the diverse needs of its clients. ### Backup and Recovery Backup and restore processes are essential for websites, and establishing and maintaining regular backups of your website and providing a plan for recovery from data loss is a critical task. Daily backups are the minimum expected for production websites; if you have an eCommerce site, regular backups and snapshots (perhaps hourly) may be needed as well. It is recommended that businesses follow the 3-2-1[data backup](https://www.atlantic.net/cloud-platform/backups/) strategy, which ensures there are always three copies of data from all web server infrastructure. - **Three Copies:** Maintain at least three copies of your data. - **Two Different Storage Media:** Store the copies on at least two types of storage media, such as Tape Media and Hard Drive. - **One Off-Site Location:** Keep at least one copy of your data in a different physical location. ### Performance Optimization Monitoring the speed and functionality of your website and making adjustments to improve load times and overall [performance](https://www.atlantic.net/resources/documents/brochures/pdf/performance-matters-atlantic-net-brochure.pdf) is essential not only to satisfy your demanding customers but also for SEO rankings. Search engines hate badly optimized websites, and your site will rank very low if it is slow and cumbersome. Google’s SEO algorithms actively check the speed at which your websites load. Fast websites are ranked high, and slow websites are ranked lower—it’s that simple. It’s also important to consider the user experience. For example, if you have a retail e-commerce site and your digital transactions are slow and laggy, it’s highly likely the customer will look elsewhere and possibly buy from a competitor. ### Search Engine Optimization Ensure that your website is optimized for search engines, which includes updating meta tags, improving on-page SEO, and monitoring search engine rankings. Again, your website’s responsive design is essential for ranking higher. ### Analytics Monitoring Monitoring website traffic and user behavior to inform strategies for improvement and report on key performance indicators (KPIs). Website management services offer uptime reports, ### Content Management Adding, editing, or removing content, such as text, images, and multimedia, to keep the site fresh and relevant. This could include content associated with social media accounts and email marketing. ### eCommerce Management E-commerce services enable your website management provider to oversee your e-commerce store and payment processing systems. This service could include tasks such as product catalog management, order processing, and payment gateway integration. ### Ongoing Technical Support Providing ongoing support to deal with any technical issues with your website as and when they arise. ## Benefits of Outsourcing to Website Management Companies In order to grow and succeed, businesses of all sizes must foster a robust online web presence. By promoting their business online, companies can connect more effectively with their audience, build brand awareness, and broadly showcase their unique expertise. ### Benefit From Expertise Website management services are typically provided by web experts who have a deep understanding of the technical aspects of running a website. By using website management services, website owners can benefit from this expertise without having to spend time learning these skills themselves. ### Save Time Managing a website can be extremely time-consuming, particularly if you are unfamiliar with its technical aspects. By outsourcing the management of your website to a third party, you can focus your time on other aspects of your business, such as creating high-quality and engaging online content, marketing, and customer service. ### Cost-Savings Partnering with a top website management company can be a cost-effective decision, especially for smaller businesses. This is because it eliminates the need to hire and train a full internal team of web management experts. Website management companies typically charge a monthly subscription fee for their services, which can be customized to meet your specific needs. ### Scalability Each business or organization is unique, and its needs can vary greatly. Website management companies can scale their services either up or down depending on the company’s individual needs. This means that you can benefit from a flexible website management solution that can grow with your business while only paying for the services that you need and use. ### Enhanced Security Website management companies can deliver enhanced security features. These ensure that your website remains protected against security threats at all times without you having to worry. ### Website Optimization By outsourcing to a website management company, you will gain access to skilled search optimization experts. These experts can help you improve your website’s ranking and visibility in search engine results pages. A leading website management company can also help you improve your website’s user experience. This can include optimizing website speed, fixing broken links, improving navigation, and making the website mobile-friendly. You may also wish to outsource the creation of online content to a website management company. Content management specialists can help to ensure that the content on your website remains fresh and up to date. ## Choosing a Website Management Provider When it comes to establishing and maintaining an effective online presence, businesses and organizations often turn to website management services. These services include website maintenance, security monitoring, and digital marketing to ensure that websites remain functional, secure, and optimized for success. Website management services offer numerous benefits for small businesses, in particular. From affordable solutions to ongoing maintenance and support, these services can help small businesses establish a strong online presence, attract more leads, and enhance brand recognition. With so many options available, it’s important to consider several key factors to ensure you select the right partner for your specific needs. **Expertise and Experience:** Look for a website management company with a proven track record of success. Consider their experience in managing websites similar to yours and inquire about the expertise of their team members, and the technology they support. **Range of Services:** Assess each provider’s range of services. Do they offer comprehensive solutions that align with your requirements? Consider whether they offer services such as website hosting, maintenance, security monitoring, performance optimization, and technical support. **Customization and Flexibility:** Every business has unique needs, so seek a website management provider that offers customizable solutions. Ensure they can tailor their services to accommodate your specific goals, budget, and preferences. Enquire about their scalability to accommodate future growth or changes should your website flourish quickly. **Security Measures:** Evaluate each provider’s security measures, including malware detection, intrusion prevention, SSL certificate management, and regular security updates. Ensure they follow industry best practices to safeguard your website and sensitive data. **Support and Communication:** Assess the level of support and communication offered by each provider. Determine how accessible they are for addressing technical issues or inquiries, and inquire about their response times for resolving issues. Clear and transparent communication is essential for a successful partnership, so look for a provider offering 24x7x365 support. **Reputation and Reviews:** Research each website management provider’s reputation and reviews. Look for testimonials from satisfied clients and assess their overall reputation in the industry. A reputable provider with positive feedback is more likely to deliver reliable and high-quality services. **Cost and Value:** While cost is a factor, prioritize value over price when selecting a website management provider. Consider the return on investment (ROI) provided by their services, including the impact on your website’s performance, security, and overall success. Compare pricing models and ensure there are no hidden fees or unexpected costs. ## Website Hosting Services from Atlantic.Net Atlantic.Net has been providing IT services throughout the United States and beyond for over 30 years. We offer affordable hosting, including Virtual Private Servers, Dedicated Hosting, and Compliance Hosting. We also host a wide range of websites for our various customers, offering the best hosting solutions for various industries, including Healthcare, Big Pharma, Legal, Finance, E-Commerce, technology, and everything in between. We specialize in providing HIPAA-compliant WordPress hosting for our healthcare clients. Our state-of-the-art hosting solutions meet and exceed the strict administrative, physical, and technical safeguards of HIPAA Compliance. We also offer Dedicated and Virtual Private Servers that are perfect for your website management needs. Our VPS services can cater to small, medium, and enterprise-scale websites, and you can take the hosting experience to another level with our dedicated hosting. Perhaps you want to manage multiple sites or become a cPanel reseller. We have a website management hosting solution for you. All Atlantic.Net offers a [100% uptime SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/). We will protect your investment by guaranteeing class-leading uptime availability. Our hosting regions are strategically located across the United States, Canada, Europe, and Asia so you can reach direct to your customers. Ready to make your website hosting aspirations a reality? Need guidance hosting your website application in the cloud? [Contact the team today](https://www.atlantic.net/about-us/corporate-contact/). --- # A Guide to Managed Security Services [MSS] > URL: https://www.atlantic.net/managed-services/what-are-managed-security-services-mss/ | Published: 2024-03-27 | Updated: 2024-09-24 | Author: Richard Bailey Security services and cybersecurity functions should be the number one priority for your business. Cybersecurity is so important that it must influence all business decision-making ensure your business is protected against existential security threats. ## How Managed Security Services Help Managed security services (MSS) are used by businesses to offload the security burden to proven managed security service providers. Such providers have the security and compliance expertise already in-house, the correct toolsets, and a wide range of highly skilled technical resources available to help, advise, and commit to securing your digital business. Managed security service providers bring a variety of cybersecurity services to the table, covering everything from intrusion prevention, managing firewalls, vulnerability scanning, incident response, and overseeing Security Information and Event Management (SIEM) systems. The beauty of these services lies in their remote delivery straight from a cutting-edge Security Operations Center (SOC). This setup enables your business to thrive by giving you access to security expertise, know-how, and technology, all without the hassle of maintaining expensive in-house security teams. Let’s dig deeper and discover what a managed security service provider is and why they are crucial for addressing security concerns organizations face. ## What Are Managed Security Services? A managed security service provider is a third-party company responsible for securing assets, patching vulnerabilities, and managing risks across all client security devices, such as servers, laptops, and IoT devices. Comprehensive managed security services typically cover security monitoring and incident response as standard. Many organizations also opt for threat intelligence protection to proactively address emerging security threats as they occur. Security monitoring involves continuously monitoring, triaging, and resolving security events. A typical managed security service setup will monitor network traffic, endpoints, logs, audits, physical security systems, applications (email, databases), and cloud services. Security professionals respond to alerts 24/7, swiftly resolving issues or escalating them to internal security teams when necessary. Security experts can advise on handling internal and external threats and how to protect employees from social engineering. Managed security services providers have access to enterprise-grade hardware and software toolsets to assist with deep scanning of the internal network, helping to identify weaknesses, threats, and vulnerabilities. When a gap is pinpointed, an alert is triggered for triage and resolution. Specialists utilize advanced threat detection techniques, using intrusion protection systems to aid threat monitoring endpoint detection and penetration testing. These tools help engineers create a security baseline, which forms the groundwork needed to implement recommended improvements. Security audits, compliance monitoring, and vulnerability scanning are part of the comprehensive security initiatives managed by service providers to ensure compliance with regulatory requirements. To help address security issues, look for providers that offer managed firewall services and edge protection security software as standard. Look for an MSS for continuous monitoring, detection, and response of cybersecurity issues; this approach helps mitigate alert fatigue, ensuring that security incidents are continuously monitored and addressed. ## Benefits of Managed Security Services Managed security services come with a vast array of benefits and advantages that your business can leverage, each designed to enhance your cybersecurity posture. ### Access to Highly Skilled Professionals Cybersecurity professionals are in high demand, and as a result, salaries are high. These two factors make starting your own security team extremely challenging. Thankfully, using a managed security services provider allows you to tap into a highly skilled team of experts who are already aware of the latest cybersecurity threat landscape. ### Around-the-Clock Monitoring When signing up for an MSSP, you can benefit from a proven monitoring system. Monitoring systems are decentralized, making it easy for your business to plug into the monitoring system with minimal local configuration in most circumstances. MSSPs are equipped to respond swiftly to security incidents, minimizing the potential impact and downtime for the organization. ### Cost Savings As discussed earlier, maintaining a skilled security services team is very expensive. Your business can reduce operation costs significantly by outsourcing an internal security team to an MSSP. This allows you to divert the investment, perhaps you can focus on building and infrastructure services instead. These services are typically sold on a subscription or contractual basis, allowing organizations to predict and manage their cybersecurity costs more effectively. ### Access to Cutting Edge Technology MSSPs invest in the latest cybersecurity technologies, tools, and platforms, ensuring that their clients benefit from state-of-the-art security measures without the need for individual organizations to make significant upfront security investments. ### Focus on Compliance monitoring. Managed security services help to fast-track your business compliance needs. Once onboarded with an MSSP, a large number of the security requirements of compliance programs such as HIPAA, PCI-DSS, ISO, etc., are largely met. MSSPs are well-versed in regulatory compliance standards, helping clients maintain adherence to industry-specific regulations and avoid legal challenges. ### Tap into Global Threat Intelligence MSSPs have access to Threat Intelligence databases that give insights into emerging threats and vulnerabilities on a global scale. Knowledge is power, so knowing what threats are about is half the battle won, allowing you to implement advanced security measures and ensure a proactive stance in safeguarding organizations from potential cyberattacks. ## What Do Managed Security Services Include? Despite greater awareness of security challenges and the need for proactive security services, many businesses still struggle to meet the required standards to help guarantee protection against the latest cybersecurity risks. So what are you getting for your investment? - Comprehensive managed security services include continuous managed security monitoring, advanced threat detection, and incident response. MSSPs are responsible for addressing all security vulnerabilities and proactively managing potential exploits within a client’s network and company’s infrastructure. - You get access to a security team with the latest toolsets that can keep up with evolving cyberattacks. If issues do occur, they have the ability to address the issue and recover from the incident. - Perhaps the most important service included is the fact that you can hand over your security services to a proven security specialist. This can potentially release huge amounts of your time and resources to focus on core business activities, safe in the knowledge that security is in the hands of the experts. ## How Do I Choose a Manage Security Service Provider (MSSP)? It is vital to uphold the security of your business, so it’s essential to choose the best-managed security service provider for the job. Outsourcing is still a sizable investment, albeit much more affordable than going solo, so choosing the right people for the job is a critical business decision to get right. There are many factors you should have at the forefront of the decision-making process. ### **What Does the MSSP Offer?** Discover exactly the services offered by the MSSP. Learn what areas of information security they specialize in, network security, cloud security, endpoint security, data security, or even industry-specific compliance measures. Do they specialize in one area, or do they have capabilities in all areas? ### **24/7 Support Excellence** Proactive security requires 24x7x365 monitoring and response. Choose a provider that guarantees around-the-clock access to resources and a team that monitors your environment continuously. Look for a provider that offers a support hotline, a number where you can escalate priority concerns no matter the time of day. Look for robust Service Level Agreements (SLAs), and pay particular attention to alert response times and resolution times. ### **Resilient Support on Difficult Times** Pick a security provider that will be by your side during difficult times. We only need to look back a few years to realize the devastating consequences and events like a global pandemic have on the global population. What about natural disasters, major incidents, or theft? You need a provider who will be with you every step of the way. The best providers will help you to implement security contingency plans to incorporate into your very own disaster recovery plans. The provider’s security infrastructure needs to be colocated in a tier-3 or higher data center, one that guarantees automated failover and guaranteed 100% around-the-clock operation. ### **Proactive, Not Reactive Security Operations** Proactive security is when MSSP experts push for recommended changes within our business, the aim is to offer continuous improvement initiatives that improve your security posture over a period of time. You don’t want an MSSP that is reactive only, one that only responds after an issue has already happened. Proactive Security involves regular patching, regular training, 24×7 monitoring and threat intelligence, penetration testing, and subsequent fixes. ### **Realistic Budget** We have already discussed that security professionals are in high demand and that there is a shortage of skilled professionals in the sector. That being said, don’t let your MSSP charge exorbitant fees for security packages. Security services can be affordable, and remember you may only need a selective number of managed security services from your managed service provider. Most will offer a banded service, such as platinum, gold, silver, and bronze packages, with each banding increasing the number of services and the complexity of the service. ## Atlantic.Net: Your Managed Security Service Provider Atlantic.Net is celebrating our 30 years in the managed detection business, and we are proud to serve our customers. We offer a full range of managed security services for your business. Our team of experienced professionals will manage your security program, handle all security alerts, and ensure that you are fully compliant with all necessary regulations. With our comprehensive suite of services, including firewall, endpoint security, vulnerability management, and cloud security solutions, you can rest assured that your organization is fully protected. [Contact us today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) to learn more about how we can help secure your business. --- # Application Security Requirements in the HIPAA Framework > URL: https://www.atlantic.net/hipaa-compliant-hosting/application-security-requirements-in-the-hipaa-framework/ | Published: 2024-03-28 | Updated: 2025-09-11 | Author: Gilad Maayan ## What Is the HIPAA Framework? The Health Insurance Portability and Accountability Act (HIPAA) framework is a set of regulations that governs the use, sharing, and protection of personal health information (PHI). HIPAA sets standards for the protection of PHI held by covered entities, such as healthcare providers, health plans, and healthcare clearinghouses, as well as their business associates. ## What Does the HIPAA Framework Do? At its core, the HIPAA framework is designed to provide individuals with more control over their health information, set boundaries on the use and release of their health records, establish safeguards that healthcare providers and others must achieve to protect the privacy of health information, and hold violators accountable through civil and criminal penalties if they violate an individual’s privacy rights. For any organization developing software for the health industry, it is important to understand how the HIPAA regulations impact their applications. HIPAA has multiple cybersecurity requirements, and most of these can have [significant implications for application security](https://www.mend.io/blog/application-security/). ![HIPAA Application Security Requirements](https://www.atlantic.net/wp-content/uploads/2024/03/HIPAA-framework.jpg) ## Application Security Requirements under HIPAA Application security is a critical aspect of securing ePHI. It involves setting up measures to ensure that applications used in handling ePHI are secure from threats and vulnerabilities. Here are some of the important ways HIPAA impacts application security: ## Encryption of ePHI at Rest and in Transit HIPAA mandates the encryption of ePHI both at rest and in transit. This means that you need to encrypt data when it’s stored, such as on servers or devices, and when it’s moving, like during data transfers or communications. Encryption transforms data into a format that can’t be understood without a decryption key. It’s your first line of defense against unauthorized access. Even if an attacker manages to get hold of the data, they won’t be able to understand it without the decryption key. This requirement is crucial in preventing breaches and ensuring the confidentiality of ePHI. ## Authentication, Authorization, and Auditing Mechanisms Another key requirement under the HIPAA framework involves the implementation of robust authentication, authorization, and auditing mechanisms. Authentication is the process of verifying the identity of a user, system, or device before granting access to ePHI. Authorization determines what a user can do once they’re authenticated. This could involve setting permissions and privileges. Auditing, meanwhile, relates to tracking and recording user activities involving ePHI for future review or audit. By implementing these mechanisms, you can ensure that only authorized individuals have access to ePHI, and any actions they perform are properly recorded and can be held accountable. ## Data Integrity Controls and Regular Security Auditing To maintain the integrity of ePHI, HIPAA requires the implementation of data integrity controls and regular security auditing. Data integrity controls involve measures to ensure that ePHI remains accurate and consistent during its entire lifecycle. This could involve using checksums, hash functions, or digital signatures. Regular security auditing involves conducting periodic assessments to identify any potential security weaknesses or vulnerabilities. These audits can help detect irregularities, attempted breaches, or areas of non-compliance, allowing you to take corrective action promptly. ## Secure Coding Practices to Mitigate Vulnerabilities and Prevent Breaches Secure coding practices are critical when developing applications that handle ePHI. These practices involve techniques and strategies for writing code that is resilient against attacks and vulnerabilities. Secure coding can involve input validation, error handling, and the use of security libraries, among other things. By following these practices, you can prevent common security issues like SQL injection, cross-site scripting, and buffer overflows, which could potentially lead to breaches. ## Regular Security Assessments Finally, HIPAA-compliant software requires regular security assessments. These assessments involve evaluating your security controls, procedures, and policies to ensure they’re effective and compliant with the HIPAA framework. Security assessments can help prepare your organization for a compliance audit. During a compliance audit, you’ll need to demonstrate that you’ve implemented the necessary measures to protect ePHI. This could involve showing evidence that security measures like encryption, authentication, and secure coding are in place and effective. ## 6 Best Practices for Developing HIPAA-Compliant Applications ### 1. Identify ePHI within Your Application ePHI refers to any individually identifiable health information that is transmitted or maintained electronically. HIPAA regulations require you to protect the integrity, confidentiality, and availability of ePHI in your application. Identifying ePHI within your application is the first step towards ensuring its protection. Start by conducting a thorough audit of your application. Identify all data inputs, storage, processing, and output points. Determine where ePHI is generated, stored, and transmitted. Pay special attention to points where data is exchanged with other systems or accessed by users. Once you have identified all the ePHI within your application, you can begin to implement the necessary protective measures. ### 2. Implement Role-Based Access Controls (RBAC) for ePHI Once you have identified all instances of ePHI within your application, the next step is to implement role-based access controls (RBAC). RBAC is a way to restrict system access to authorized users. In the context of HIPAA, this means ensuring that users can only access the ePHI necessary for their role. Implementing RBAC involves defining user roles and permissions within your application. This may include roles such as administrators, healthcare providers, and patients. Each role should have a set of permissions that dictate what actions they can perform and what information they can access. By implementing RBAC, you can effectively limit the exposure of ePHI, reducing the risk of unauthorized access or data breaches. Remember, less is more when it comes to access control. Grant only the minimum necessary access to each role to perform its function. ### 3. Develop Written Policies for HIPAA Compliance within the Application HIPAA compliance isn’t just about the technical aspects of applications; it also involves administrative procedures. You need to develop clear, written policies and procedures for all aspects of HIPAA compliance within your application. These policies provide a framework for your team to follow, ensuring that everyone understands the importance of protecting ePHI and knows how to do it effectively. Your policies and procedures should cover topics such as access controls, encryption, data backup and recovery, incident response, and more. They should also include training programs to educate your team about HIPAA compliance and how to apply the policies and procedures in their daily work. ### 4. Have a Clear Breach Notification Plan in Place In the unfortunate event of a data breach involving ePHI, HIPAA’s Breach Notification Rule requires you to notify affected individuals, the Secretary of Health and Human Services, and in some cases, the media. Having a clear plan in place for breach notification is crucial to ensure a timely and appropriate response. Your breach notification plan should detail the steps to take following a breach, including assessing the scope and impact of the breach, notifying the appropriate parties, and mitigating the breach’s effects. It’s not just about following the rules; it’s about maintaining trust with your users and minimizing harm. ### 5. Ensure Third-Party Vendors who have Access to ePHI Sign BAAs If your application involves third-party vendors who have access to ePHI, you must ensure they sign Business Associate Agreements (BAAs). The BAA is a legal contract that outlines the responsibilities of both parties in protecting the ePHI. The BAA should specify the permitted uses and disclosures of ePHI, require the business associate to implement appropriate safeguards, and mandate reporting of any ePHI breaches. ### 6. Implement Continuous Security Monitoring Lastly, but no less important, is the implementation of continuous monitoring strategies. Cyber threats are constantly evolving, and you need to stay one step ahead to protect your application and the ePHI it handles. Continuous monitoring involves the real-time collection and analysis of data to detect and respond to threats. You should employ a variety of monitoring tools and techniques, such as network monitoring, log analysis, and intrusion detection systems. In the event of a suspected or confirmed security incident, you should have a response plan in place to quickly contain the incident and minimize its impact. In conclusion, developing HIPAA-compliant applications involves a comprehensive approach that integrates technical measures, administrative procedures, and continuous monitoring. By following the steps outlined in this article, you can navigate the application security requirements in the HIPAA framework and build applications that protect sensitive health information while delivering value to your users. **Author Bio: Gilad David Maayan** ![](https://www.atlantic.net/wp-content/uploads/2023/10/giladimage.jpg) Gilad David Maayan is a technology writer who has worked with over 150 technology companies including SAP, Imperva, Samsung NEXT, NetApp and Check Point, producing technical and thought leadership content that elucidates technical solutions for developers and IT leadership. Today he heads [Agile SEO](https://agileseo.co.il/), the leading marketing agency in the technology industry. LinkedIn: [LinkedIn](https://www.linkedin.com/in/giladdavidmaayan/) --- # How to Set Up BTCPay Server on Ubuntu 22.04 with Docker > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-set-up-btcpay-server-on-ubuntu-22-04-with-docker/ | Published: 2024-04-05 | Updated: 2024-06-02 | Author: Hitesh Jethva BTCPay Server is an open-source, self-hosted payment processor for Bitcoin and other cryptocurrencies. It enables merchants and businesses to accept Bitcoin payments directly without relying on third-party payment processors or intermediaries. BTCPay Server offers merchants a secure, privacy-focused, and customizable payment processing solution for accepting Bitcoin and other cryptocurrencies. In this tutorial, we will show you how to install the BTCPay server on Ubuntu 22.04. ## Step 1 – Install Docker CE Install the packages necessary to add a new repository over HTTPS: ``` apt install apt-transport-https ca-certificates git ``` Add Docker’s official repository and GPG key to your system: ``` echo "deb [signed-by=/etc/apt/keyrings/docker.gpg.key arch=amd64] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list wget --quiet -O - https://download.docker.com/linux/ubuntu/gpg | tee /etc/apt/keyrings/docker.gpg.key ``` After adding the repository, update the package index: ``` apt update ``` Finally, install the latest version of Docker CE: ``` apt install docker-ce -y ``` ## Step 2 – Install BTCPay Clone the BTCPay Server repository from GitHub to your server machine: ``` git clone https://github.com/btcpayserver/btcpayserver-docker.git ``` Change into the directory where you cloned the BTCPay Server repository: ``` cd ~/btcpayserver-docker/ ``` Export the environment variables that are necessary for BTCPay installation. ``` export BTCPAY_HOST="btc.linuxbuz.com" export NBITCOIN_NETWORK="mainnet" export BTCPAYGEN_CRYPTO1="btc" export BTCPAYGEN_REVERSEPROXY="empty" export BTCPAYGEN_EXCLUDE_FRAGMENTS="$BTCPAYGEN_EXCLUDE_FRAGMENTS;nginx-https" export BTCPAYGEN_LIGHTNING="lnd" export BTCPAY_ENABLE_SSH=true ``` Finally, install the BTCPay server using the following script. ``` . ./btcpay-setup.sh -i ``` Output: ``` [+] Running 8/0 ✔ Container tor Running 0.0s ✔ Container btcpayserver_bitcoind Running 0.0s ✔ Container btcpayserver_lnd_bitcoin Running 0.0s ✔ Container generated_lnd_bitcoin_rtl_1 Running 0.0s ✔ Container generated_postgres_1 Running 0.0s ✔ Container generated_nbxplorer_1 Running 0.0s ✔ Container tor-gen Running 0.0s ✔ Container generated_btcpayserver_1 Running 0.0s Installed bitcoin-cli.sh to /usr/local/bin: Command line for your Bitcoin instance Installed bitcoin-lncli.sh to /usr/local/bin: Command line for your Bitcoin LND instance Installed btcpay-clean.sh to /usr/local/bin: Command line for deleting old unused docker images Installed btcpay-down.sh to /usr/local/bin: Command line for stopping all services related to BTCPay Server Installed btcpay-restart.sh to /usr/local/bin: Command line for restarting all services related to BTCPay Server Installed btcpay-setup.sh to /usr/local/bin: Command line for restarting all services related to BTCPay Server Installed btcpay-up.sh to /usr/local/bin: Command line for starting all services related to BTCPay Server Installed btcpay-admin.sh to /usr/local/bin: Command line for some administrative operation in BTCPay Server Installed btcpay-update.sh to /usr/local/bin: Command line for updating your BTCPay Server to the latest commit of this repository Installed changedomain.sh to /usr/local/bin: Command line for changing the external domain of your BTCPay Server ``` To check the BTCPay server status, run the following command: ``` systemctl status btcpayserver.service ``` Output: ``` ● btcpayserver.service - BTCPayServer service Loaded: loaded (/etc/systemd/system/btcpayserver.service; enabled; vendor preset: enabled) Active: active (exited) since Sat 2024-04-06 03:57:39 UTC; 3min 2s ago Process: 33105 ExecStart=/bin/bash -c . "/etc/profile.d/btcpay-env.sh" && cd "$BTCPAY_BASE_DIRECTORY/btcpayserver-docker" && . helpers.sh && btcpay_up (code=exited> Main PID: 33105 (code=exited, status=0/SUCCESS) CPU: 206ms ``` You can also verify all running containers using the following command: ``` docker ps ``` Output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES aac50ed3aa24 shahanafarooqui/rtl:0.14.1 "/sbin/tini -g -- no…" 4 minutes ago Up 4 minutes 3000/tcp generated_lnd_bitcoin_rtl_1 0576ec248536 btcpayserver/btcpayserver:1.13.0 "/app/docker-entrypo…" 4 minutes ago Up 4 minutes 49392/tcp generated_btcpayserver_1 cfa1ce79b857 btcpayserver/lnd:v0.17.4-beta "/sbin/tini -g -- /d…" 4 minutes ago Up 4 minutes 8080-8081/tcp, 0.0.0.0:9735->9735/tcp, :::9735->9735/tcp btcpayserver_lnd_bitcoin 60ea110f3f31 btcpayserver/docker-gen:0.10.7 "/usr/local/bin/dock…" 4 minutes ago Up 4 minutes tor-gen b830c0ae554d nicolasdorier/nbxplorer:2.5.2 "dotnet NBXplorer.dll" 4 minutes ago Up 4 minutes 32838/tcp generated_nbxplorer_1 1dcf56ea4abd btcpayserver/bitcoin:26.0 "/entrypoint.sh bitc…" 4 minutes ago Up 4 minutes 8332-8333/tcp, 18332-18333/tcp, 18443-18444/tcp, 28332-28334/tcp, 39388/tcp, 43782/tcp btcpayserver_bitcoind bb7f0cd045f0 btcpayserver/tor:0.4.8.10 "./entrypoint.sh tor" 4 minutes ago Up 4 minutes 9050-9051/tcp tor 27182eb40921 btcpayserver/postgres:13.13 "/migrate-docker-ent…" 4 minutes ago Up 4 minutes 5432/tcp generated_postgres_1 ``` ## Step 3 – Configure the BTCPay Server Next, you will need to expose port **49392** for the BTCPay server. To do so, edit the BTCPay server configuration file. ``` nano ~/btcpayserver-docker/Generated/docker-compose.generated.yml ``` Add the following lines in the btcpayserver section. ``` ports: - "49392:49392" ``` Save and close the file, then restart the BTCPay service to apply the changes. ``` systemctl restart btcpayserver ``` ## Step 4 – Configure Nginx for BTCPay To configure Nginx as a reverse proxy for the BTCPay Server, you’ll need to create an Nginx server block (also known as a virtual host) to handle incoming requests and forward them to the BTCPay Server instance running on Docker. If Nginx is not already installed on your system, you can install it using the following command: ``` apt install -y nginx ``` Create a new Nginx configuration file for BTCPay Server: ``` nano /etc/nginx/conf.d/btcpay-server.conf ``` Add the following configuration. ``` map $http_x_forwarded_proto $proxy_x_forwarded_proto { default $http_x_forwarded_proto; '' $scheme; } # If we receive X-Forwarded-Port, pass it through; otherwise, pass along the # server port the client connected to map $http_x_forwarded_port $proxy_x_forwarded_port { default $http_x_forwarded_port; '' $server_port; } # If we receive Upgrade, set Connection to "upgrade"; otherwise, delete any # Connection header that may have been passed to this server map $http_upgrade $proxy_connection { default upgrade; '' close; } # Prevent Nginx Information Disclosure server_tokens off; # Default dhparam # Set appropriate X-Forwarded-Ssl header map $scheme $proxy_x_forwarded_ssl { default off; https on; } gzip_types text/plain text/css application/javascript application/json application/x-javascript text/xml application/xml application/xml+rss text/javascript; log_format vhost '$host $remote_addr - $remote_user [$time_local] ' '"$request" $status $body_bytes_sent ' '"$http_referer" "$http_user_agent"'; access_log off; # HTTP 1.1 support proxy_http_version 1.1; proxy_buffering off; proxy_set_header Host $http_host; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection $proxy_connection; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto; proxy_set_header X-Forwarded-Ssl $proxy_x_forwarded_ssl; proxy_set_header X-Forwarded-Port $proxy_x_forwarded_port; proxy_buffer_size 128k; proxy_buffers 4 256k; proxy_busy_buffers_size 256k; client_header_buffer_size 500k; large_client_header_buffers 4 500k; http2_max_field_size 500k; http2_max_header_size 500k; # Mitigate httpoxy attack (see README for details) proxy_set_header Proxy ""; server { server_name btc.linuxbuz.com; listen 80; access_log /var/log/nginx/btcpay.access; error_log /var/log/nginx/btcpay.error; client_max_body_size 100M; # Here is the main BTCPay Server application location / { proxy_pass http://127.0.0.1:49392; } # Include the next two stanzas if and only if you want to expose your lightning gRPC & RPC interfaces to the internet #location /lnrpc.Lightning { # grpc_pass grpcs://127.0.0.1:10009; #} #location /lnd-rest/btc/ { # rewrite ^/lnd-rest/btc/(.*) /$1 break; # proxy_pass https://127.0.0.1:8080/; #} # Include this stanza if you are planning to set up Ride The Lightning (RTL) location /rtl/ { proxy_pass http://127.0.0.1:3000/rtl/; } } ``` Save and close the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http{: ``` server_names_hash_bucket_size 64; ``` Save the file, then reload the Nginx service to apply the changes. ``` systemctl reload nginx ``` ## Step 5 – Enable SSL for the BTCPay Server To enable SSL for BTCPay Server using Let’s Encrypt, you can use Certbot, a tool provided by Let’s Encrypt, to obtain and install SSL certificates for your domain. ``` apt install certbot python3-certbot-nginx ``` Run Certbot to obtain an SSL certificate for your domain. ``` certbot --nginx --agree-tos --redirect --hsts --staple-ocsp --email hitjethva@gmail.com -d btc.linuxbuz.com ``` Output: ``` Saving debug log to /var/log/letsencrypt/letsencrypt.log Requesting a certificate for btc.linuxbuz.com Successfully received certificate. Certificate is saved at: /etc/letsencrypt/live/btc.linuxbuz.com/fullchain.pem Key is saved at: /etc/letsencrypt/live/btc.linuxbuz.com/privkey.pem This certificate expires on 2024-07-05. These files will be updated when the certificate renews. Certbot has set up a scheduled task to automatically renew this certificate in the background. Deploying certificate Successfully deployed certificate for btc.linuxbuz.com to /etc/nginx/conf.d/btcpay-server.conf Congratulations! You have successfully enabled HTTPS on https://btc.linuxbuz.com - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - If you like Certbot, please consider supporting our work by: * Donating to ISRG / Let's Encrypt: https://letsencrypt.org/donate * Donating to EFF: https://eff.org/donate-le - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ``` ## Step 6 – Access the BTCPay Server Now, open your web browser and access the BTCPay web interface using the URL **https://btc.linuxbuz.com.** You will see the BTCPay account creation page. ![](https://www.atlantic.net/wp-content/uploads/2024/04/p1-6.png) Define your email and password and click on the **Create account.** You will see the store creation page. ![](https://www.atlantic.net/wp-content/uploads/2024/04/p2-6.png) Define your store name, default currency, and price source, then click on **Create Store.** On the following page, you will see the BTCPay dashboard. ![](https://www.atlantic.net/wp-content/uploads/2024/04/p3-4.png) ## Conclusion You can now set up your own self-hosted BTCPay Server instance, empowering you to take full control of your payment processing infrastructure. With BTCPay Server, you can leverage the security and transparency of Bitcoin while enjoying the flexibility and customization options provided by a self-hosted solution. By hosting your own BTCPay Server, you can eliminate reliance on third-party payment processors, protect the privacy of your customers’ transactions, and maintain full control over your financial transactions. You can now host your BTCPay server on [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install SoftEther VPN Server on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-softether-vpn-server-on-ubuntu-24-04/ | Published: 2024-04-06 | Updated: 2025-09-30 | Author: Hitesh Jethva SoftEther VPN (Virtual Private Network) is open-source software developed by the SoftEther VPN Project. It is a versatile solution that supports various VPN protocols and features. SoftEther VPN can be installed on various operating systems, including Windows, Linux, macOS, FreeBSD, and Solaris. SoftEther VPN on a VPS provides a versatile and secure VPN solution that enables users to protect their privacy, bypass restrictions, and securely access remote resources over the internet. Whether for personal or business use, SoftEther VPN offers a powerful tool for ensuring secure and private communication online. This tutorial will show you how to install SoftEther VPN on Ubuntu 24.04. ## Step 1 – Install SoftEther VPN First, install the required packages using the following command: ``` apt-get install build-essential gnupg2 gcc make -y ``` Next, download the SoftEther VPN Server package from the official website. You can use wget to download the package directly from the command line: ``` wget https://github.com/SoftEtherVPN/SoftEtherVPN_Stable/releases/download/v4.44-9807-rtm/softether-vpnserver-v4.44-9807-rtm-2025.04.16-linux-x64-64bit.tar.gz ``` Once the download is complete, extract the contents of the package using the following command: ``` tar -xvzf softether-vpnserver-v4.44-9807-rtm-2025.04.16-linux-x64-64bit.tar.gz ``` Change into the extracted directory: ``` cd vpnserver ``` Run the make command to build the SoftEther VPN Server: ``` make ``` Once the build process is complete, move the vpnserver directory to /usr/local/: ``` cd .. mv vpnserver /usr/local/ ``` Set the correct permissions for the vpnserver directory: ``` cd /usr/local/vpnserver/ chmod 600 * chmod 700 vpnserver chmod 700 vpncmd ``` ## Step 2 – Create a Systemd File for SoftEther To manage the SoftEther VPN server as a proper system service, we will create a `systemd` unit file. This will allow the server to start automatically on boot and be managed with standard system commands. Create a new service file named `vpnserver.service` in the `/etc/systemd/system/` directory: ``` nano /etc/systemd/system/vpnserver.service ``` Add the following content to the file. This configuration tells systemd how to start, stop, and manage the vpnserver process. ``` [Unit] Description=SoftEther VPN Server After=network.target [Service] Type=forking ExecStart=/usr/local/vpnserver/vpnserver start ExecStop=/usr/local/vpnserver/vpnserver stop WorkingDirectory=/usr/local/vpnserver/ Restart=on-failure RestartSec=5s [Install] WantedBy=multi-user.target ``` Save and close the file. Now, reload the `systemd` daemon to make it aware of the new service: ``` systemctl daemon-reload ``` Enable the SoftEther VPN service to start automatically at system boot: ``` systemctl enable vpnserver ``` Finally, start the SoftEther VPN service: ``` systemctl start vpnserver ``` You will see the following output. ``` Let's get started by accessing to the following URL from your PC: https://69.28.85.145:5555/ or https://69.28.85.145/ Note: IP address may vary. Specify your server's IP address. A TLS certificate warning will appear because the server uses self signed certificate by default. That is natural. Continue with ignoring the TLS warning. ``` ## Step 3 – Configure SoftEther VPN Server Next, you will need to configure the SoftEther VPN Server using the vpncmd command line tool. Change to the directory where the SoftEther VPN Server is installed. By default, it is located in /usr/local/vpnserver/: ``` cd /usr/local/vpnserver ``` Run the vpncmd utility to access the SoftEther VPN Server console: ``` ./vpncmd ``` You will be asked to choose from the following options: ``` vpncmd command - SoftEther VPN Command Line Management Utility SoftEther VPN Command Line Management Utility (vpncmd command) Version 4.38 Build 9760 (English) Compiled 2021/08/17 22:32:49 by buildsan at crosswin Copyright (c) SoftEther VPN Project. All Rights Reserved. By using vpncmd program, the following can be achieved. 1. Management of VPN Server or VPN Bridge 2. Management of VPN Client 3. Use of VPN Tools (certificate creation and Network Traffic Speed Test Tool) Select 1, 2 or 3: 1 ``` Type **1** and press the **Enter** key. You will be asked to specify the hostname or IP address of the VPN server. ``` Specify the host name or IP address of the computer that the destination VPN Server or VPN Bridge is operating on. By specifying according to the format 'host name:port number', you can also specify the port number. (When the port number is unspecified, 443 is used.) If nothing is input and the Enter key is pressed, the connection will be made to the port number 8888 of localhost (this computer). Hostname of IP Address of Destination: Just press the Enter key to connect to the VPN console. If connecting to the server by Virtual Hub Admin Mode, please input the Virtual Hub name. If connecting by server admin mode, please press Enter without inputting anything. Specify Virtual Hub Name: Connection has been established with VPN Server "localhost" (port 443). You have administrator privileges for the entire VPN Server. VPN Server> ``` Next, set a password for the VPN. ``` ServerPasswordSet ``` Define your password as shown below: ``` Password: ****** Confirm input: ****** The command completed successfully. ``` Next, create a hub and set a password: ``` HubCreate myhub ``` Set your hub password as shown below. ``` HubCreate command - Create New Virtual Hub Please enter the password. To cancel press the Ctrl+D key. Password: ****** Confirm input: ****** The command completed successfully. ``` Next, change to your hub. ``` Hub myhub ``` Next, allow the hub to work as a virtual LAN. ``` SecureNatEnable ``` Output: ``` SecureNatEnable command - Enable the Virtual NAT and DHCP Server Function (SecureNat Function) The command completed successfully. ``` Next, create a VPN user. ``` UserCreate user1 ``` Define your username, description, and full username: ``` Assigned Group Name: User Full Name: User User Description: IT The command completed successfully. ``` Set a password for the VPN user. ``` UserPasswordSet user1 ``` Set a password for your user as shown below: ``` Please enter the password. To cancel press the Ctrl+D key. Password: ****** Confirm input: ****** The command completed successfully. ``` Enable the IPsec to get Multi-Protocol working. ``` IPsecEnable ``` Answer the following questions: ``` IPsecEnable command - Enable or Disable IPsec VPN Server Function Enable L2TP over IPsec Server Function (yes / no): yes Enable Raw L2TP Server Function (yes / no): yes Enable EtherIP / L2TPv3 over IPsec Server Function (yes / no): yes Pre Shared Key for IPsec (Recommended: 9 letters at maximum): vpnserver Default Virtual HUB in a case of omitting the HUB on the Username: myhub The command completed successfully. ``` Finally, exit from the VPN configuration wizard using the following command: ``` exit ``` ## Step 4 – Install SoftEther VPN Client Now, you will need to install the SoftEther VPN client on the Client machine. First, install all required dependencies. ``` apt-get install build-essential gnupg2 gcc make -y ``` Next, download the latest SoftEther VPN client package. ``` wget https://github.com/SoftEtherVPN/SoftEtherVPN_Stable/releases/download/v4.44-9807-rtm/softether-vpnclient-v4.44-9807-rtm-2025.04.16-linux-x64-64bit.tar.gz ``` Once the download is completed, extract the downloaded file. ``` tar -xvzf softether-vpnclient-v4.44-9807-rtm-2025.04.16-linux-x64-64bit.tar.gz ``` Navigate to the extracted directory and install it using the following command: ``` cd vpnclient make ``` Next, create a directory for the VPN client script. ``` mkdir /root/vpnscript ``` Navigate to the created directory and download all required scripts. ``` cd /root/vpnscript wget https://raw.githubusercontent.com/mfaizanse/intellexlab-files/main/softether-vpn-client/remove-client.sh wget https://raw.githubusercontent.com/mfaizanse/intellexlab-files/main/softether-vpn-client/setup-client.sh wget https://raw.githubusercontent.com/mfaizanse/intellexlab-files/main/softether-vpn-client/vpn-connect.sh wget https://raw.githubusercontent.com/mfaizanse/intellexlab-files/main/softether-vpn-client/vpn-disconnect.sh wget https://raw.githubusercontent.com/mfaizanse/intellexlab-files/main/softether-vpn-client/vpn_config ``` Set proper permissions on all scripts. ``` chmod 755 * ``` Edit the VPN client configuration file. ``` nano vpn_config ``` Define your VPN server IP, user, and gateway as shown below: ``` CLIENT_DIR="/root/vpnclient" NIC_NAME="nic1" ACCOUNT_NAME="user1" VPN_HOST_IPv4="vpn-server-ip" LOCAL_GATEWAY="gateway-ip-of-client-machine" ``` Save and close the file, then set up the VPN client using the following command: ``` ./setup-client.sh ``` You will be asked to provide your VPN server details. ``` vpncmd command - SoftEther VPN Command Line Management Utility SoftEther VPN Command Line Management Utility (vpncmd command) Version 4.38 Build 9760 (English) Compiled 2021/08/17 22:32:49 by buildsan at crosswin Copyright (c) SoftEther VPN Project. All Rights Reserved. Connected to VPN Client "localhost". VPN Client>AccountCreate user1 AccountCreate command - Create New VPN Connection Setting Destination VPN Server Host Name and Port Number: 69.28.85.145:443 Destination Virtual Hub Name: myhub Connecting User Name: user1 Used Virtual Network Adapter Name: nic1 The command completed successfully. vpncmd command - SoftEther VPN Command Line Management Utility SoftEther VPN Command Line Management Utility (vpncmd command) Version 4.38 Build 9760 (English) Compiled 2021/08/17 22:32:49 by buildsan at crosswin Copyright (c) SoftEther VPN Project. All Rights Reserved. Connected to VPN Client "localhost". VPN Client>AccountPassword user1 AccountPasswordSet command - Set User Authentication Type of VPN Connection Setting to Password Authentication Please enter the password. To cancel press the Ctrl+D key. Password: ****** Confirm input: ****** Specify standard or radius: radius The command completed successfully. ``` Finally, connect to your VPN server using the following command: ``` ./vpn-connect.sh ``` Once you are connected to the VPN server, you will get the following output: ``` vpncmd command - SoftEther VPN Command Line Management Utility SoftEther VPN Command Line Management Utility (vpncmd command) Version 4.38 Build 9760 (English) Compiled 2021/08/17 22:32:49 by buildsan at crosswin Copyright (c) SoftEther VPN Project. All Rights Reserved. Connected to VPN Client "localhost". VPN Client>AccountList AccountList command - Get List of VPN Connection Settings Item |Value ----------------------------+------------------------------------------- VPN Connection Setting Name |user1 Status |Connected VPN Server Hostname |69.28.85.145:443 (Direct TCP/IP Connection) Virtual Hub |myhub Virtual Network Adapter Name|nic1 The command completed successfully. ``` After the successful connection, a new VPN interface named vpn_nic1 has been created. You can check it using the following command: ``` ip a ``` Output: ``` 5: vpn_nic1: mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 1000 link/ether 5e:5c:6b:c6:ef:6f brd ff:ff:ff:ff:ff:ff inet6 fe80::5c5c:6bff:fec6:ef6f/64 scope link valid_lft forever preferred_lft forever ``` ## Conclusion By following the installation and configuration steps outlined in this guide, users can set up their own SoftEther VPN Server instance on Ubuntu 24.04 and customize it according to their specific requirements. Whether you’re a small business looking to establish a secure remote access solution or an individual user wanting to protect your online privacy, SoftEther VPN provides the tools and capabilities needed to achieve these goals. Try to deploy the SoftEther VPN server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Server Management: Linux > URL: https://www.atlantic.net/managed-services/server-management-in-linux/ | Published: 2024-04-07 | Updated: 2025-04-11 | Author: Richard Bailey Linux is a versatile, reliable, secure operating system and a great enterprise-grade product supporting practically every conceivable business application. Most Linux distributions are open-source software, meaning they are free with no licensing costs to use the software. ### Is Linux Server Management Difficult? Managing a Linux server is very different from using Windows or MacOS; many users are intimidated by the Linux command line and are concerned about a steep learning curve when trying to understand how the operating system works. The good news is that there are plenty of Linux server management utilities available that simplify the user experience and make it much easier for everyday users to manage Linux servers. These tools bridge the skills gap between novice and expert users, enabling even those unfamiliar with Linux server administration to perform Linux server management tasks efficiently. They provide an easy-to-use interface for executing commands, managing multiple servers, and handling network configuration with fine-grained control. This article will help you understand what Linux server management is and give examples of some of the most popular tools available that simplify server management, regardless of your skills with the Linux operating system. ## What Is Linux Server Management? Linux systems are hugely popular, lightweight, and offer superb reliability. It’s not uncommon for a [Linux server](https://www.atlantic.net/vps-hosting/linux-vps-hosting/) to remain up and running for years without needing to reboot, including servers that require regularly patched security updates. Linux is the operating system of choice for cloud deployments, and Linux administrators can natively integrate cloud services into the operating system. A user who sees the Linux shell for the first time might be wary about how to use it. Linux servers rarely use GUI or desktop applications. Instead, the preferred way to manage Linux is via the declarative command line tool. This puts off some users, but if you persevere, you will open a world of exciting tools that unlock Linux’s additional features. You can manage advanced system administrator features, databases, and web applications and deploy Linux server management software to make this process easier. Do you want to know some of the most popular Linux Server Management tools available? These are some favorites that simplify the day-to-day management of Linux. ## The Best Tools for Linux Server Management ### Cockpit Cockpit is a web-based server management tool that allows authorized users to manage the server remotely. Users are presented with an easy-to-use GUI and can access some of the critical server functions and server performance monitoring tools at the click of a button. The user does not need to learn how to SSH into the server. Users can stop/start/restart services, manage users and groups, configure network services and network settings, and view core server logs. A detailed hardware monitoring feature gives an overview of system performance, such as CPU, disk, and memory usage. You can also deploy virtual machines directly on your Linux server! For advanced users, a terminal emulator provides direct access to the shell. Cockpit also uses secure WebSockets for added security and RBAC permissions, so only authorized users can access specific features. ### phpMyAdmin This is another user-friendly web-based application interface that allows users to remotely manage MySQL and MariaDB databases. RBAC rules can be applied for each use to delegate the required permissions of data management. With phpMyAdmin, it’s easy to import and export database files and run queries against your data. If you are not familiar with SQL queries, a GUI feature called QueryByExample will help you build complex queries in minutes. ### Prometheus and Grafana Although technically two products, they work great together for monitoring and alerting on your Linux server. Prometheus is an open-source monitoring system that excels at collecting and storing metrics from various sources. Grafana is an open-source platform for visualizing data from monitoring systems like Prometheus. It allows the creation of informative dashboards for server health and performance. Together, these Linux server management tools give you a fantastic, holistic overview of exactly what is going on within your environment. ## What Types of Linux Distros are Ideal for Server Management? When it comes to managing Linux servers, there are a variety of distros to choose from, each catering to different needs. Linux server management tools are more or less universal and available for all the different Linux flavors. Debian is renowned for its reliability and consistent release schedule, while CentOS, despite its uncertain future, has successors like AlmaLinux and Rocky Linux as alternatives, each offering enterprise-grade stability and compatibility with Red Hat Enterprise Linus (RHEL). Ubuntu is another hugely popular distro because of its user-friendly options and widely supported platform. It’s based on Debian but comes with a more approachable interface and boasts a vibrant community for support, making it great for beginners or those who prioritize ease of use. If you’re more inclined towards cutting-edge technology, Fedora Server might be your go-to. It keeps you up-to-date with the latest software packages, perfect for environments that require staying on the bleeding edge. Other notable mentions include openSUSE, known for its versatility and user-friendly YaST package manager, and RHEL, the commercial counterpart to Fedora, offering top-tier stability and support, albeit with a paid license requirement. Choosing the best distro depends on your specific requirements. Consider factors like stability, ease of use, package availability, and community support. Asking yourself these questions may help you pinpoint a distribution that works for you. Are you running critical systems that must be up 24/7? Do you prefer a user-friendly interface, or are you comfortable diving into Linux administration? Do you need specific software packages or rely heavily on community support? Once you’ve weighed these factors, you can make an informed decision that aligns with your Linux server management needs, ensuring optimal performance, seamless operations, and efficient user management across multiple servers. ## Should I Choose an MSP to Help with Linux Server Management Software? Of course, it’s important to remember that should you not want to worry about managing multiple servers, you can always opt for server management services from an MSP. Managed service providers can take over the day-to-day management of your Linux servers. A team with dedicated resources, typically based in a remote network operations center (NOC), will remotely monitor and proactively, and when necessary, reactively fix issues across your Linux estate. Managed service providers make sense in many different scenarios. Here are some of the key benefits an MSP can provide. ### **Expertise and Experience**: MSPs are staffed with experts who know Linux server management inside out. They are experts in the Linux shell and can manage your server over SSH. Managed services work well if your in-house IT team lacks the specific knowledge needed to host Linux servers or if your server setup is complex. Tapping into their know-how could be a game-changer. ### **Freeing Up Resources**: By outsourcing Linux server management to an MSP, you’re allowing your in-house team to focus on what they do best rather than getting bogged down in server admin tasks. ### **24/7 Support and Monitoring**: You should expect your MSPs to offer 24/7 support and monitoring services. This typically involves a remote monitoring solution that continuously looks for alerts or threshold breaches from the Linux server. Automated alerts are generated and looked at by a technical engineer. This means someone constantly monitors your servers and spots issues before they become big problems. ### **Scalability**: Whether you’re managing a handful of servers or an expansive network, MSPs can scale their services to suit your needs. So, as your organization grows, they can grow right alongside you. ### **Cost Considerations**: There are obviously costs associated with outsourcing to an MSP. But consider the value: less downtime, smoother operations, and access to top-notch expertise. It could end up being a smart investment. ### **Security Boost**: MSPs can improve your security posture overnight. MSP technical engineers can implement best practices on your Linux server environment, introducing patching policies, implementing firewall configurations, setting up intrusion detection systems, deploying antivirus software, and establishing robust access control measures. ## What Are the Most Important Tasks in Managing a Linux Server? Linux servers perform a variety of tasks, and different uses will need access to different types of tasks. However, there are a core number of everyday tasks that are ubiquitous with Linux Server Management that system administrators would be expected to understand. You need to know how to configure and set up a Linux server correctly and securely. This involves configuring network settings, setting up user accounts, and fine-tuning security measures such as creating a patching schedule or configuring SELinux. Once the server is up and running, you need to monitor it. Monitoring CPU usage, disk space, and network traffic helps you catch issues before they escalate into major problems; it also enables you to understand how the system functions when you give it specific tasks to complete. It’s important to learn how to conduct regular software updates, which are vital to keeping your server secure and running smoothly. Whether it’s patching security vulnerabilities or installing the latest features, staying up-to-date is key. Some more advanced tasks may include creating and managing virtual servers on your Linux server; perhaps you need to deploy microservices or containers. Or you may require a dedicated server to act as a managed website host using software like cPanel or Plesk. Logging in Linux is crucial to troubleshooting when issues arise. Sometimes, the software doesn’t work correctly, or perhaps a configuration setting is slightly incorrect. The log files and journaling give you detailed insight, making it easy to pinpoint an issue. ## How Can Atlantic.Net Help? Are you looking for a leading hosting provider to host your Linux Operating System? Look no further than Atlantic.Net’s [VPS hosting service](https://www.atlantic.net/vps-hosting/). With 30 years of proven experience, our full suite of managed services and always-available professional support team can host your mission-critical Linux workload. For faster application deployment, visit us at [www.atlantic.net](http://www.atlantic.net), call 866-618-DATA (3282), or email us at [sales@atlantic.net](mailto:sales@atlantic.net). You can find out more information by [contacting our sales team](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) today! --- # Cloud VOIP > URL: https://www.atlantic.net/voip-cloud-servers/cloud-voip/ | Published: 2024-04-08 | Updated: 2025-09-11 | Author: Richard Bailey Voice Over Internet Protocol (VOIP) is a proven method of Internet-based voice communication technology. Traditional phone systems are quickly becoming a thing of the past as the modern flexibility and amazing cost savings offered by a VOIP phone system take over most business phone communications. Atlantic.Net provides world-class hosting and telephony networking connectivity to leading network carriers. Our eight data center locations feature ultra-low latency networking and superb reliability backed by our 100% uptime guarantee. If you are looking to host a [VoIP phone system hosting](https://www.atlantic.net/voip-cloud-servers/), why not consider Atlantic.Net? We have various locations across the United States, Europe, and Asia. ## What Are Cloud VoIP Services? A Voice Over Internet Protocol (VoIP) phone service is a modern communications method that allows you to make phone calls anywhere in the world using an internet connection instead of traditional copper landlines. An IP telephony system works seamlessly with existing landline phone lines and telephony exchanges. A VoIP phone system translates your voice into data packets that are securely transmitted across an internet connection from a public switched telephone network (PSTN). The voice quality is exceptionally clear, and the phone service enables many added features that are simply not available on traditional phone systems. VoIP phone systems can be hosted on-premise or consumed as a cloud-managed service. IP telephony systems come with many added features, such as conference and international calling, video conferencing capabilities, business SMS options, and call center features. Various cloud-based VoIP services are available from multiple providers in the United States. The types of services you get depend on the cost of the service, the licensing model you opt for, and the flexibility you need from the cloud VoIP platform. Let’s take a look at the types of phone systems that are available: ### On-Premise VoIP Phone Systems On-prem is a conventional VoIP business phone system or service in which the business owns, manages, and operates its phone system on-premise. It is typically hosted on dedicated hardware in a computer room, usually on a small cluster of virtual machines. On-prem suits businesses that have employees capable of managing the telephone system in-house; perhaps the business has additional unique needs or poor cloud connectivity coverage. ### Cloud-Based Phone Systems If you don’t want to host your own VoIP phone system, you can opt for a completely cloud-based solution. You simply provide the physical VoIP phones and connect to the provider over the Internet. The service is provided on a pay-as-you-go model, and you configure the physical phones to connect to the third-party service. This type of service relies heavily on having a reliable internet connection, but it can work out to be a very affordable option – perfect for startups and new cloud phone system users. ### Mobile VoIP Phone System Most cloud telephony providers support mobile phone VoIP services, in which cloud-enabled systems use existing WiFI and Mobile Networks to provide cell telephony services. These services work with both voice and data services and are suitable for businesses with a remote workforce or teams that are constantly on the move. ### SIP Trunking Session Initiation Protocol (SIP) enables the VoIP network to connect and interact with the public phone network (PSTN). This clever bit of tech seamlessly bridges both telecommunications networks and works great for high-volume lines such as call centers or helplines. Users can make external phone calls to any number using softphones, traditional phones, or wired phone sets. ### Cloud PBX A Cloud Private Branch Exchange (PBX) is software that allows the granular management of an in-house phone system. It’s sometimes referred to as a virtual PBX. Users can configure call routing, call forwarding, and auto-attendant features. Business-wide conference call features can be enabled for large-scale meetings. ### Direct Device Communications DDC is a fantastic cost-saving feature that allows any connected cloud-based phone systems inside the phone network to communicate with one another without incurring any costs. It’s a direct connection from one to one (or many) devices. In large businesses, this feature allows completely free inter-business communications ### Dedicated VoIP Cloud Phone System A more recent technology is direct-to-cloud VoIP services. The phone systems connect directly to a cloud phone service provider without the need for any internal phone hardware or software. Services like Vonage Business Communications, Zoom Phone, and RingCentral offer VoIP-enabled phones. ## Benefits of Cloud VOIP ### Video Conferencing Many VoIP service providers integrate both video calls and conferencing capabilities into their phone service. Video conferencing is now a technology that many businesses rely upon. The tech proved its worth during the COVID-19 pandemic by bringing businesses together remotely during the lockdown. Video conferencing helps improve engagement and communication between employees. Seeing the users’ facial expressions and emotions helps to improve communication and get the message across when compared with voice-only phone calls. Advanced features include document sharing, whiteboard, and recording options. Businesses like video conferencing because it increases flexibility, helps employees build relationships, and reduces travel costs. ### Voice Conferencing Sometimes you just don’t feel like being on camera. Perhaps you are feeling under the weather, or your kids are running around causing chaos while you’re trying to listen in to an important all-hands call. Voice conferencing is readily available for those who just need to listen in. Voice also brings a host of benefits; it helps remote employees feel included in conversations and increases participation in meetings. It also helps fit in with employees’ busy lifestyles; perhaps the user just needs to sit on mute in the car or listen on AirPods during a school run. If you have employees based offshore, and perhaps English is not their first language, voice transcription tools are available to help with voice conferencing calls—again, this improves engagement, participation, and inclusion. ### Voicemail When cell phones became mainstream in the 1990s, Voicemail changed the way we communicated. Prior to digital voicemail, people relied on clunky answer phone devices or had to write messages down. VoIP phone systems have expanded modern voicemail services to the next level so we never have to miss an important call again. VoIP Voicemail features standard message recording where callers can leave a voice message after the greeting you’ve recorded. You can also automate call diversion, perhaps to receive calls to your cell phone or a colleague if you are away. You can also access the voicemail from any source; it doesn’t have to be the device that has been called. Voicemail transcription is available, and users can leave detailed and lengthy messages. This, in turn, improves productivity because it doesn’t always matter if you miss a call, and it results in greater flexibility. ### Screen Sharing Screen sharing is a feature that allows you to virtually transmit the contents of your computer screen to other participants during a call. This functionality is often integrated into VoIP services alongside voice and video conferencing capabilities. Screen sharing is great for remote collaboration, video meetings, and presenting ideas to colleagues. It’s also widely used for technical support; IT engineers use it to remotely fix problems or offer guidance to employees. It promotes better customer support and is great for sales and demos and explaining complex topics to the wider business. Screen sharing is a versatile tool that can enhance communication, collaboration, and problem-solving in various situations, both personal and professional. If you need to virtually share a visual experience or work together on something on a screen, screen sharing is a powerful tool to consider. ### Remote Workforce Capabilities It’s [estimated](https://www.statista.com/topics/7145/remote-work-in-the-us/#topicOverview) that today, 26% of workers in the United States are remote workers; that is, they work at least 1 day a week from home. Across Europe, that figure is approximately 30%. These stats demonstrate the need to engage the remote workforce, and VoIP phone systems allow this to happen. Most people have an internet connection at home, and most employers also provide laptops. Add a headset and you have a softphone that can connect to a VoIP telephony system. It’s that simple. Even call center workers can work remotely with relative ease. It’s preferable to offer them dedicated VoIP telephones that can connect securely over a VPN to your Cloud PBX, but again, it’s relatively straightforward to set this up. This approach to Telephony creates a professional image for your business. Virtual routing takes the customer directly to your home worker, so it’s unlikely the customer would ever know the difference. The result is improved scalability, increased employee satisfaction, and a reduction in your business costs. ### Call Monitoring & Call Recording There are two common forms of call monitoring. The first is call quality monitoring, which focuses on the technical aspects of your VoIP calls, such as latency, jitter, and packet loss. VoIP providers log these statistics to give you an overview of the experience your customers and employees are getting from the phone system. Second is call recording and content monitoring. This is when the conversations are recorded. Most often this is for training and quality assurance reasons so businesses can ensure employees are offering a good experience. It can also be for compliance or for resolving disputes. Overall, the purpose is to improve the call quality, reduce downtime, increase productivity, and provide the best possible customer service. ### Call Forwarding Call forwarding in VoIP is a feature that lets you direct incoming calls to a different phone number or device. There are several examples of when this is useful. If in a meeting, an employee can set a desk phone to automatically forward to a cell phone. Likewise, if you have a team of on-call engineers, call forwarding can be used to automate dialing out the correct on-call engineer. ## How Much Does Cloud VOIP Cost? Investing in a VoIP phone system does come with a cost, but it’s important to understand that affordable, cost-effective solutions are absolutely available. Of course, you can spend a huge amount investing in an on-premise configuration with a dedicated state-of-the-art VoIP cloud-based phone system for every employee. But with cloud VoIP, it is much more affordable to get your VoIP phone system live, especially if you make some key decisions about how/where you are going to host the solution and what equipment you will be using. You can expect to pay between $10 and $30 per user per month. This price range would typically cover the basic functionality of the VoIP system, such as making and receiving calls. The more users you have, the more you will have to pay. Remember, the additional features increase the cost per user the most. Do your business communications require features like call recording, voicemail transcription, and video conferencing? Can they be cut to save expenditure? Also, you need to budget for VoIP phones (the physical devices); these can be purchased or rented from the provider. There are three types of pricing plans. Here are the key points to consider: ### **Flat-Rate Pricing Plans:** - Ideal for businesses that need predictable budgeting. - Often include unlimited calling within a specific geographical area. - Suitable for companies with high call volumes. - It may have a higher upfront cost but can lead to significant long-term savings. ### **Usage-Based Pricing Plans:** - Provide flexibility, ideal for smaller businesses or startups with variable call volumes. - Businesses are charged based on actual usage, paying only for what they use. - Economical for companies with lower or fluctuating call volumes. ### **Tiered Pricing Plans:** - Offer bundles of various features at different price points. - Advanced features such as call analytics, video conferencing, and software integrations. - It can increase costs but add value by enhancing productivity and streamlining workflows. Hopefully, you now have a better understanding of the costs associated with VoIP phone systems. Remember that you are in control of the budget, and cost savings can be made if you make the right decisions. ## What Are My Options When It Comes to Cloud VOIP Business Phone System Providers? There are many cloud VoIP providers available within the United States. We are lucky to have a very competitive market with plenty of choices to suit your business needs and budget. One of the biggest providers in the US is **RingCentral**, which is a very strong contender when it comes to picking a cloud VoIP provider. Prices range from $19.99 per user to about $34.99. Even the cheaper premiums offer a good set of features, including call forwarding, voicemail transcription, video conferencing, and integrations with Salesforce, Zendesk, and Microsoft 365. Another big player is a company called **DialPad**. They heavily focus on using AI to integrate the product with class-leading analytics and data-driven insights into call data with features like voice transcriptions and smart routing. Dialpad is known for its user-friendly interface and is a popular choice for non-technical users. **Nextiva** is another very popular provider of VoIP phone systems that target the business sector. Their features include business test messaging, online faxing, and mobile phone integration. You can also port your existing number to them without being charged extra. Even the basic premium plans include video conferencing, call recording, auto attendant, and call queues. Another popular choice is the **Zoom Phone**service. This budget-focused VoIP service provider starts at $10 per user per month. Despite the low cost, the feature set is very good. It integrates with Zoom Meetings and offers all the standard features, such as call routing and call recording. ## Choose Atlantic.Net Hosting for VoIP Cloud Phone Systems Atlantic.Net is celebrating 30 years in business, and we offer a wide range of hosting options for your next [VoIP cloud server](https://www.atlantic.net/voip-cloud-servers/) project. We have been heavily involved in VoIP technology throughout our history and customers choose our hosting capabilities to deploy and manage private VoIP solutions. To get started, all you need is a workforce with access to a cell phone or laptop and an internet connection. Next, host your private branch exchange (PBX) on Atlantic.Net servers. Choose Windows or Linux as the host operating system to build out your Cloud VoIP gateways, Cloud SIP, and conference servers. Then, onboard a licensed IP PBX system from one of the many providers and choose a cloud-hosted, dedicated, or colocation server option. You can add on backups, offsite replication, and snapshots with the click of a mouse. Need to expand? No problem! Each cloud server plan can be upgraded within a few clicks. Atlantic.Net has a selection of world-leading network carrier partners. Our high-speed, low-latency network throughput works seamlessly with a cloud phone systems softphone or physical VoIP phone, whether over a VPN or the Internet, adding greater flexibility and future-proofing options. If you’re ready to revolutionize your business’ unified communications with Atlantic.Net’s robust and flexible [VoIP services](https://www.atlantic.net/voip-cloud-servers/), don’t hesitate to take the next step. Contact an advisor today at 866-618-DATA (3282) or email at [sales@atlantic.net](mailto:sales@atlantic.net). --- # Cloud Managed Services > URL: https://www.atlantic.net/managed-services/what-are-cloud-managed-services/ | Published: 2024-04-09 | Updated: 2025-04-11 | Author: Richard Bailey **Cloud Managed Services** (or Managed Cloud Services) are IT services that provide either partial or complete management of a client’s cloud computing infrastructure. This includes all aspects of the Cloud, such as cloud migration, server management, and configuration, as well other services such as platform optimization, including security, backups, and system maintenance. The number of options available for cloud managed services may seem daunting at first, but consider that you can pick and choose the managed services that apply to your circumstances. You can opt for whatever cloud computing services will offer value to your business processes. Let’s discover cloud managed services and learn their pros and cons. This article aims to give you the information you need to make an informed decision about cloud managed services. ## What Is a Cloud Managed Service? A cloud [managed service](https://www.atlantic.net/managed-services/what-are-managed-services/) is outsourcing the management of your cloud infrastructure to a provider. A managed cloud services provider offers unique services that allow your business to offload the IT responsibility to the provider. The aim is to free up your business resources so that you can focus on your applications and business processes and let the managed service provider handle the cloud infrastructure. The services on offer concentrate on five key areas, including: ### Infrastructure Management Cloud providers are responsible for the core hardware of the cloud platform, such as the servers, storage, and network that power the environment. They are also responsible for the data center that hosts the cloud platform and local facilities like power and cooling. When considering the scale of cloud platforms, this is no easy undertaking. It takes teams of experts to keep the platform running optimally. ### Security and Compliance Security services are multi-layered, starting with the data center’s physical security, including around-the-clock CCTV, access controls, etc. Security is also needed at the hardware layer; servers, storage, and networks must all be encrypted, security-hardened, and regularly updated. Next, you also have the application layer that protects your cloud native applications against DDoS, Intrusion Protection, and Threat Detection and meets any compliance needs. ### Applications and End-User Support The most common application supported is the Operating System; most providers will typically include server management that helps with Windows, Linux, or Unix Operating Systems. Some providers will also offer support with Antivirus and Backup applications. If you need support with bespoke applications, such as help with Office 365 or Adobe Creative Suite—check with your provider to ensure these applications are in scope. When issues are encountered, having help available around the clock is essential. End User Support makes or breaks managed services. Check the small print for service level agreements and key performance indicator targets that the provider must reach to offer a greater level of service. ### Cloud Services A managed cloud platform is a complex, software-defined application managed in-house by teams of experts. The MSP is responsible for ensuring the cloud services are online 24/7. Whether the cloud platform is a public, private, or hybrid environment, the provider of hosted service is responsible for its availability. ### Backups and Disaster Recovery Backups are one of the most popular managed cloud services available. Every business needs to back up critical data. The backup schedules will vary, but at minimum, you should backup at least every 24 hours. It is recommended to follow the principle of a 3-2-1 backup strategy. ## What Are Some Typical Cloud Managed Service Examples? Let’s deep dive and discover more about specific services from cloud [managed services providers](https://www.atlantic.net/managed-services/what-is-a-managed-service-provider-a-brief-guide-to-msps/), in particular, cloud migration services and professional services : ### Cloud Migration Services Not every business has taken the plunge into the public cloud yet, and doing so may seem like an impossibly complicated task. Let a managed public cloud services provider like Atlantic.Net remove this burden with our [Cloud Migration Service](https://www.atlantic.net/managed-services/migration-services/). The migration is the end-to-end process of moving your existing systems into the cloud. Sometimes, it’s a simple case of lifting and shifting your workload onto a cloud instance. Complications arise when considering business-critical systems such as enterprise-grade databases and application servers. This is how the service works: **Discovery:** An assessment of the current infrastructure will help when creating a migration plan. The plan identifies services that can be moved quickly and pinpoint any potential hiccups, allowing a road map for migration. Remember, sometimes a server or service is unsuitable for a cloud deployment or migration; in these circumstances, we will work with you to determine a new cloud-ready solution. **Preparation:** Next, it’s time to prepare the existing infrastructure for its cloud journey. This involves tweaking core network and security settings and prepping your data for its journey to the public cloud. This step will involve creating a site-to-site VPN, and a plan will be finalized to determine the order in which services will be migrated. **Migration:** It’s time to move your apps and data. This could be done via a phased approach or a big bang (all in one go), depending on your business requirements. **Thorough Testing:** Testing is needed at each migration step to ensure everything runs smoothly. This includes checking for functional, load, and security issues. All self-service functions should undergo testing, and if you opt for managed services, make sure those options get tested, too. **Optimization**: Sometimes called ‘cloudification,’ this step involves fine-tuning your new cloud environment to ensure it’s optimized for the latest cloud platform. Streamlining operations and maximizing business continuity is essential to ensure all your services are up and running as they should be. **Ongoing Support:** Once everything’s up and running, you’ll want ongoing support for your cloud environment. Your managed cloud services provider should monitor things, provide updates on cloud security, and troubleshoot any problems. Remember, the right cloud-managed services provider can make all the difference when migrating cloud services. Look for a provider that will manage as much of the process as possible. ### Consulting and Professional Services Check if your managed cloud service provider offers consulting and professional services as part of their managed cloud service providers’ packages. One of the biggest appeals of managed cloud services is the ability to tap into the provider’s skills and knowledge. Sometimes, your business might be presented with a technical problem that must be solved. Unfortunately, not all businesses possess the right skills to do this in-house. However, when outsourcing cloud management, you can access their professional services and expert help with your cloud deployments. Professional services offer a hands-on and involved approach to implementing and managing hybrid cloud environments on-native applications and infrastructure. Expert engineers help businesses deploy, configure, and operate cloud native resources such as servers, storage, and databases. They also provide ongoing support and maintenance to ensure the cloud or hybrid cloud deployments are optimized and up-to-date. Cloud consulting and professional services benefit business strategy by offering organizations additional resources to make informed decisions about their chosen cloud strategy. ## Pros and Cons of Managed Cloud Services So, what are the benefits of cloud managed services? Are there any drawbacks? Here, we will explore the pros and cons to help you make a balanced argument about cloud-managed services. ### Resource Optimization A key service is performance monitoring of your cloud resources. This is when a probe or agent polls your systems for vital system information. Typically, it includes CPU, disk, and RAM, but it can be configured to report on pretty much any logged variable. MSPs provide detailed reports about the state of your infrastructure, and the ability to see the system history helps you discover bottlenecks or areas for improvement. Based on these reports, you can also introduce scaling to improve system stability during peak periods. ### Integration with Cloud Services Another key benefit is that managed services allow you to consume other cloud services on demand. For example, whether you have VPS hosting, dedicated hosting, a cloud-based solution, or a colocation suite, you can integrate and manage the server via a control panel and integrate additional services on demand—common examples include backups, snapshots, block storage, and assigning new IP address ranges. ### Predictable Costs Finance teams prefer it when IT departments run with a predictable operational expenditure (OPEX). Managed service fits perfectly here because MSPs use tiered subscription-based billing. The most common is on-demand billing, where you only pay for what you use, and because you know the costs in advance, it’s easy to predict your monthly expenditure. There are no hefty outgoings for procuring expensive servers, storage, and networking. You simply plug into the cloud provider or system and use it as needed. You can expect discounted rates for 1- to 3-year commitments for greater flexibility. ### Automatic Upgrades The MSP is responsible for cloud-based solutions, and one significant perk is that they manage all the upgrades needed on the host hardware and software. You simply don’t need to worry about it. If you have opted for server management services, the provider will even patch your operating system and applications for you [automatically](https://www.automox.com/blog/atlantic-net-chooses-automox). ### Network Security Opting for a managed service gives you instant access to a security-defined network architecture created from the ground up to be secure. Get instance access to encrypted network traffic, VPN connectivity, elastic IP addresses, managed network firewalls, web application firewalls, and the security offered by a segregated network. ### Disaster Recovery Capabilities DR and business continuity are vital for businesses that need guaranteed uptime in the event of a disaster. DR occurs when the core primary systems fail over to a replica set at a secondary location. DR is usually a paid-for add-on because it’s very expensive to implement and requires a skilled team of professionals to manage and test the service at regular intervals (usually twice per year). ### 24x7x365 Technical Support Having the required help available when an incident occurs can be a game changer for your business. Support teams monitor your servers around the clock and provide proactive and reactive support as needed. They are also available around the clock via phone or email. ### High Cost One possible negative is that managed services can prove expensive, especially if you tick every option box. Disaster recovery and server management typically cost the most because of the people’s power needed to support the infrastructure. ### Concerns of Multi-Tenant Model Some providers offer private cloud-managed services that are essentially large-scale virtual clusters with multiple customers spread out over the system, and this might have potential security implications in the event a 0-day exploit is discovered. ## How Do I Know If I Need a Managed Cloud Service Provider? If you have an IT hosting contract, consider whether a managed service would make your life easier and business operations more successful. Ask yourself these questions; if you answer yes to any of them, then perhaps managed cloud services are a good idea for your business. - **Do you lack IT expertise?** - **Are you concerned about your IT security?** - **Do you often experience downtime?** - **Are you struggling to manage your cloud environment?** - **Do you need to introduce cost savings?** If your in-house IT teams are small, you may miss vital skills needed to manage your environment. Likewise, a managed security service provider can help you implement and maintain strong security measures to protect your data and applications while introducing cost savings. ## How Do I Choose a Managed Cloud Services Provider? Finding a managed cloud service provider (MCSP) that fits your needs is crucial. Make sure they know your cloud platform and have the certifications to prove it. You want a provider that takes security seriously, with things like encryption and regular security checks in place. And if your business has compliance needs, such as HIPAA, PCI, or GDPR, make sure they know about that, too. Make sure their services match what you need, whether it’s help with moving to the Cloud, ongoing support, or ensuring everything keeps running smoothly. And it’s essential they can grow with you, so check they can handle your needs as your business expands. Want to know more? Transform your cloud management experience with Atlantic.Net’s comprehensive Cloud Managed Services, offering expert support, robust security measures, and scalable solutions tailored to your business needs. [Contact the team today](https://www.atlantic.net/about-us/corporate-contact/). --- # Customer Service Stars Shine Bright: Atlantic.Net Wins Customer Service Excellence Award for 2024 > URL: https://www.atlantic.net/press-releases/customer-service-stars-shine-bright-atlantic-net-wins-customer-service-excellence-award-for-2024/ | Published: 2024-04-10 | Updated: 2024-06-11 | Author: Alexander Wise *The Business Intelligence Group recognizes the top companies, executives, and products leading the way in customer service excellence in 2024. This year’s winners include those who are transforming the customer experience in today’s online-driven economy.* PHILADELPHIA, PA—April 10, 2024—Businesses that prioritize exceptional customer service are more likely to thrive. The Business Intelligence Group recognizes this with its annual [Excellence in Customer Service Awards](https://www.bintelligence.com/awards/excellence-in-customer-service-awards) program, honoring the companies, executives, and products leading the industry. Today, we are honored to announce the 102 customer service stars who are shining bright and improving customer outcomes. *![](https://www.atlantic.net/wp-content/uploads/2024/04/Excellence-CustServ-Award-2024.png)* This year’s 2024 [Excellence in Customer Service Awards](https://www.bintelligence.com/awards/excellence-in-customer-service-awards) judges recognized Atlantic.Net, Inc. as a winner of the **Technology of the Year Award** in the Business Intelligence Group 2024 Excellence in Customer Service Awards category. “We are delighted to have been named to this award along with other leading brands,” said Marty Puranik, Founder and CEO of Atlantic.Net. “This award is dedicated to our amazing, helpful, and always-available support service, who have offered so much commitment and success to our customers for the last 30 years.” For more information about Excellence in Customer Service, visit [Excellence in customer service awards](https://www.bintelligence.com/awards/excellence-in-customer-service-awards). **About Business Intelligence Group** The Business Intelligence Group was founded with the mission of recognizing true talent and superior performance in the business world. Unlike other industry award programs, these programs are judged by business executives having experience and knowledge. The organization’s proprietary and unique scoring system selectively measures performance across multiple business domains and then rewards those companies whose achievements stand above those of their peers. **About Atlantic.Net** Atlantic.Net is an award-winning global cloud services provider with a focus on security, compliance, and simplifying complex infrastructures. With over 30 years of experience, Atlantic.Net is dedicated to offering developers and IT leaders at small, medium, and large organizations a range of on-demand, customized, and cost-effective cloud solutions that cater to their unique business needs. Having served clients like Lenovo, Newegg, NASA, and Hilton, the company’s commitment to excellence has positioned it as a leader in the industry, recognized for its innovation and customer-centric approach. Contact Maria Jimenez Chief Nominations Officer +1 909-529-2737 jmaria@bintelligence.com Atlantic.Net Media Contact Email: pr@atlantic.net Phone: 321-206-1371 --- # Managed Network Services > URL: https://www.atlantic.net/managed-services/what-are-managed-network-services/ | Published: 2024-04-10 | Updated: 2025-04-11 | Author: Richard Bailey An IT Network is a complicated but fundamental part of computing infrastructure that underpins an entire technology stack. The network is a collection of connected devices, typically including servers, routers, data circuits, and network switches. It can also include any networked peripheral, such as a printer, laptop, or personal computer. Managed network services are when a provider looks after some or all of the network stack. This might include design and implementation or perhaps the day-to-day operations, performance, and always-on availability of the network. Let’s discover how Managed Network Services can improve your cloud network management experience. ## What Are Managed Network Services? Managed Network Services are when you outsource the management of your existing network to a managed network services provider. There are several different ways this happens: The managed network services provider will either remotely manage the existing network infrastructure or, typically, as part of a wider migration plan, the client environment leverages the provider’s existing service delivery network (SDN). Either way, the result is the same: the networking aspect of your digital framework is outsourced to the provider, which allows you to focus on running your business operations smoothly. Outsourcing introduces a huge amount of benefits that are felt throughout your business, especially when it comes to security, scalability, and compliance needs. Each provider’s services vary; it’s important to research that your chosen provider offers exactly the network services you need. The types of services available usually include supporting wide area networks (WAN) for faster and more efficient data transfer and handling the day-to-day tasks of network administration and provisioning, such as upgrades or installing and maintaining cabling infrastructure where applicable. Expect enhanced network monitoring to be included as standard, helping keep your network performing efficiently. [Managed service providers](https://www.atlantic.net/managed-services/what-is-a-managed-service-provider-a-brief-guide-to-msps/) will typically manage the security of perimeter firewalls and will implement secure virtual private networks (VPNs) to safeguard your data, we will dig into this in more detail later. ## How MSPs Can Help with Managed Network Services Outsourcing IT networking is very popular for businesses of all sizes because managed network service providers offer tangible benefits that can positively impact business performance. ### #1: Plug the Skills Gap Network engineering is technically demanding on your business, and if not handled diligently, day-to-day operations can introduce a lot of technical debt. When you outsource to a managed network service provider, you immediately get access to a team of highly skilled network professionals. Network engineering professionals are well-paid, and the best professionals can identify and fix complex issues almost instantly. Managed service providers pay good salaries to attract, hire, and keep top-rated talent. Small and medium-sized businesses can tap into this talent pool when opting for managed network services. The types of experts available to you include: #### Network Engineering Network engineers play a pivotal role in network management. They oversee the entire network architecture and implement [managed services](https://www.atlantic.net/managed-services/what-are-managed-services/) to meet service-level agreements and support business operations. With specialized expertise, they handle network downtime, manage security events, and offer advice on future technology and expansion. Network engineers provide technical support and regular maintenance and can advise on technology investments, such as disaster recovery solutions and ways to enhance your network security. #### Security Engineering Security engineers safeguard network management with security firewalls, intrusion protection systems, and DDoS protection capabilities. They manage the entire firewall architecture and design, configuration, and firmware/software updates to enhance operational efficiency and ensure compliance with regulations such as PCI and SOX. With expertise in firewall rule management and content filtering configuration, security engineers drive digital transformation initiatives, leveraging new technologies like SD-WAN for improved performance and customer satisfaction. #### Field Support Field support is vital for businesses that need on-site network assistance. From on-site installation to troubleshooting and repairs, field engineers are available to assist on demand. This service could be on-demand, visiting customer sites as needed, or perhaps a permanent arrangement can be organized with a constant support presence. #### Helpdesk Helpdesk professionals are available around the clock to provide essential support through incident response and troubleshooting. These teams work with SLAs and KPIs to offer fast response and fix rates to address technical issues and ensure business continuity. ### #2: Understand the Complex Nature of Networks Networks are complicated and come in all shapes and sizes. You need to be familiar with the hardware, the cabling requirements, software-defined networking, firewalls, Web Application Firewalls, virtual switches, and physical ASAs, not to mention cloud computing networking, route tables, VPCs, and security groups. With managed network services, you don’t have to worry about any technical requirements; the provider’s engineers are responsible for the network stack. You can sit back and relax, safe in the knowledge that your network management is in good hands. ### #3: Access to Network Management Partners Managed Network providers have access to the biggest providers, which introduces lots of benefits. It opens the door to ultra-high-speed connectivity from various network circuit providers at rates that smaller businesses cannot compete with. Managed service providers help businesses extend your businesses geographical reach without the need for significant investment in infrastructure or resources. This means faster deployment of services and applications to remote locations, ensuring consistent performance and reliability across the board. With regulations like PCI, HIPAA, GDPR, CCPA, and the protection of personally identifiable information (PII) becoming increasingly stringent, having dedicated network security experts with knowledge and skill sets in compliance is critical to success. Managed service providers specialize in implementing and maintaining robust security measures to ensure compliance with these regulations and protect sensitive data from cyber threats. By consolidating network infrastructure, optimizing resource utilization, and leveraging economies of scale, managed services providers can offer more cost-effective solutions than maintaining an in-house network team. The managed service model introduces predictable pricing models, and reduced operational expenses further contribute to long-term cost savings. Managed network services can fast-track business transformation initiatives. Whether implementing cloud technologies, adopting IoT solutions, or transitioning to a remote workforce model, a modern network will help accelerate your IT infrastructure programs. When combined with service level agreements (SLAs), businesses receive consistent performance, uptime, and responsiveness from their network infrastructure. ### #4: Enhance Your Security Posture Managed connectivity services will improve your security posture immediately as you onboard. A managed service provider will implement a network defined by managed security. Engineers will have spent years building, upgrading, and securing the service delivery network, using emerging technologies that enable enterprises to improve performance and embed secured access. As your business grows, so do the threats it will face. A managed network safeguards your environment from evolving threats. Attacks are thwarted at the network perimeter, zero-day exploits are blocked by the WAF, and network segregation protects all your internal traffic. ## Pros and Cons of Engaging Managed Network Services ### Pros #### Expertise We have already touched upon the expertise available from managed network services, but it’s important to recap because it remains one of the biggest advantages of network services. Providers have a proven track record in managing virtual network services, secure access service edge, and other essential components of modern network infrastructures. #### 24/7 Monitoring and Support Managed services providers offer round-the-clock monitoring and support, ensuring that businesses have secure access to their network services at all times. With this constant oversight, issues can be quickly identified and addressed, minimizing disruptions to business processes and enhancing overall performance and security. This proactive approach to service management helps businesses drive innovation and deliver an exceptional user journey. #### Access to Advanced Tools From machine learning algorithms to sophisticated analytics platforms, managed services providers offer a diverse set of tools to optimize network performance and enhance security. MSPs can afford the licensing required for the very best networking tools. #### Scalability Managed network services can help you scale your businesses on demand. The provider network will typically have much greater capacity, and you can be advised on upgrades and streamlining of your network layers. Whether you’re expanding into new markets or regions or adding new services, managed services providers can quickly adjust resources to accommodate these changes. This creates greater flexibility and enables enterprises to scale their network infrastructure seamlessly and cost-effectively. #### Focus on Your Core Business Needs When network services are outsourced, the burden of managing the network stack is diminished. Businesses can focus on their core business activities without having to worry about the complexities of managing their network infrastructure. Whether it’s local telephone services, remote application hosting services, or basic network access, managed service providers handle the day-to-day management of these services. #### Cost Savings By outsourcing network management to a single provider, businesses can achieve cost optimization and streamline their IT expenses. A provider running an SD-WAN with a built-in firewall and route tables will be more affordable than individual stacks. A better-performing network means more sales—how many times have you closed your browser if a retailer’s site can’t cope with Black Friday demand? Managed services providers offer predictable pricing models and flexible billing options, such as on-demand and discounts for one-, two-, or three-year commitments, enabling businesses to better manage their budgets and allocate resources where they are needed most. ### Cons #### Handing Over the Network to Someone Else One potential downside of engaging managed network services is the relinquishment of control over the network. While managed services providers offer enhanced security and reliability, some businesses may be hesitant to entrust their network infrastructure to a third party. However, by choosing a reputable managed services provider with a proven track record of performance and reliability, businesses can mitigate this risk and ensure that their network remains secure and reliable. #### Response Times Another potential drawback of engaging managed network services is the variability in response times. While managed services providers offer 24/7 monitoring and support, response times may vary depending on the provider and the level of service agreed upon. Delays in addressing issues could impact business operations and customer experience, so it’s important for businesses to carefully review and negotiate service-level agreements to ensure they meet the specific needs and expectations of the business. ## Managed Network Services Providers’ Pricing and Contract Structures Leveraging managed network services requires a well-thought-out business decision. You must ensure that the best application service providers are chosen and that the managed network supports the cloud services your customers demand. Contracts typically range from 1 to 5 years, with significant cost savings being made available for longer investments. Managed networking for cloud services is typically on-demand. The costs will vary and are dependent on numerous factors, such as: - **Service Level Agreements (SLAs):** Different SLAs may come with varying levels of support and response times, impacting the cost of managed network services. - **Scalability Requirements:** The network’s scalability needs, including potential growth or fluctuations in usage. - **Security Measures:** The complexity and depth of security protocols and measures implemented within the managed network can affect costs and managed security services. - **Redundancy and Failover Solutions:** Implementing redundant systems and failover solutions to ensure network reliability may increase the cost of managed connectivity services. - **Integration and Compatibility:** Compatibility with existing systems and the need for integration with other services or platforms can impact pricing for virtual network services. - **Customization and Configuration:** The degree of customization and configuration required to meet specific business goals can affect pricing for managed network solutions. - **Management Tools and Software:** Costs associated with management tools, software licenses, and monitoring solutions can contribute to overall service management expenses. - **Support and Maintenance:** The level of ongoing support and maintenance services provided by the managed service provider can influence costs for operational efficiency. - **Regulatory Compliance:** Compliance requirements such as GDPR, HIPAA, or industry-specific regulations may necessitate additional measures, impacting costs and business outcomes. - **Quality of Service (QoS) Requirements:** Meeting specific QoS requirements, such as prioritizing certain types of traffic, can affect pricing for basic network access. - **Service Provider Reputation and Expertise:** The reputation, experience, and expertise of the managed service provider may be reflected in the pricing of their services and solution providers. - **New Technologies:** Integration of new technologies and services provided by managed network service providers may influence costs and digital transformation. - **Geographical Location:** Location-related factors, such as local telephone services and remote application hosting services, can impact pricing for managed network services. - **Data Centers:** Hosting in data centers, whether in-house or remotely, can affect costs associated with managed network services. - **Latest Technologies:** Keeping up with the latest technology and industry advancements may impact pricing for managed network solutions. ### How Do I Know if I Need Network-Managed Services? It’s important to conduct due diligence to understand if and when your business needs managed network services. If done at the right time, your business can gain a competitive advantage. Is your business ready for Managed Network Services? Ask yourself these questions: #### Experiencing Downtime and Performance Degradation? Are frequent downtimes and performance issues hindering your productivity? Consistent interruptions in network services may indicate a need for professional management to enhance reliability and efficiency. #### Any Security Concerns? Is your system vulnerable to cyber threats? Heightened security risks, such as data breaches or malware attacks, demand robust protection mechanisms provided by managed services to safeguard your valuable assets. #### Suffering from Limited Network Resources? Are you struggling with inadequate network capacity or outdated infrastructure? Managed network services can optimize resource allocation and scalability, ensuring that your network keeps pace with evolving demands #### Facing Unpredictable Costs? Are you experiencing budget uncertainty due to unpredictable network expenses? Managed services offer predictable pricing models, eliminating unexpected costs associated with network maintenance and upgrades. #### Concerns Over Compliance Issues? Are you navigating complex regulatory requirements in your industry? Managed network services adhere to compliance standards and provide comprehensive solutions to address regulatory obligations. ### **Looking for a Reliable and Secure Managed Network Services Provider? Look No Further than Atlantic.Net!** With our cutting-edge web infrastructure, experienced team of professionals, and top-notch customer service, we are committed to providing you with the best-managed network services possible. Whether your organization needs help with network design, implementation, monitoring, or management, we’ve got you covered. Our services are tailored to meet the unique needs of your business, ensuring that your network runs smoothly and efficiently at all times. So why wait? Take the first step towards a better network today, and [contact us](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) to learn more about our managed network services. Our expert team is standing by to answer any questions you may have and help you get started! --- # Containers Cloud Computing What Are Containers in Cloud Computing? > URL: https://www.atlantic.net/vps-hosting/containers-cloud-computing/ | Published: 2024-04-11 | Updated: 2024-08-24 | Author: Richard Bailey ## **What Are Containers in Cloud Computing?** A [container](https://www.atlantic.net/vps-hosting/container-hosting/) is a lightweight, executable unit of software that packages an application’s code and dependencies (libraries, runtime environment, system tools) into a standardized unit. Containers are unique because they can run reliably across different environments within an isolated environment. Containers are lightweight because they share the host operating system kernel. This makes them extremely quick to boot, and typically, the container packages are available in small package sizes. The container images behave like application templates; they only have all the components needed to run. Most containers adhere to standardized specifications, like Docker containers, which are portable between cloud computing providers. However, the container runs in isolation using its own processes, filesystem, and networking—thus preventing conflicts and reducing security threats. ## **What are the uses of Containers in Cloud Computing?** Container workloads are widely used throughout public cloud computing environments and are an increasingly popular way to deploy application code in production environments. Container technology is not necessarily a new technology; in fact, its roots can be traced back to the 1970s, when Unix systems were used to isolate application code. Today, containerization is much more advanced and synonymous with tools like Docker and Kubernetes. Cloud providers have adopted container runtimes into cloud computing because they are a more efficient way of deploying cloud resources across private, public, and multi-cloud environments. ## **What are some of the examples of Container in Cloud Computing?** If you have never used containers before, it can be difficult to understand the concept and how they work. Let’s consider a real-world example to help demonstrate what a container is. Containers are very popular in website applications. Consider your favorite online retailer. The online store will have multiple different features, such as product search, shopping cart management, account management, and payment processing. As the user, you see the front-end website; all you are concerned about is the user experience and making your purchase. However, behind the scenes, multiple software containers (or microservices architecture) work together to create and power the user experience. The online retailer likely uses a container for the product, another for account management, more for payments, and so on. In fact, multiple containers are used to create the website, and these containers scale up to handle the website load on demand. If the website’s payment processing section experiences issues, engineers and developers can isolate that part of the web application and release a fix for the issue. The rest of the website’s microservices are not affected, and other users would have no idea there is an issue. ## **Benefits & Use Cases of Containers** - Lightweight - Portability - Resource Efficiency - Scalability - Fast Startup Times - Improved Developer Experience - Faster Deployment Process - Cost Optimization Features - Microservices Architecture Support - Managing Containerized Applications There are many business benefits to using containers in cloud computing. Here are some of the most common reasons why businesses choose to adopt containers for applications. ### Lightweight Containers are lightweight, typically less than 100 MB in size. This gives developers the added agility needed to create and build applications frequently, speeding up the development team’s work and improving the software development lifecycle. Thousands upon thousands of pre-made, containerized environment images can be pulled from a public or private registry and deployed anywhere in seconds. ### Portability Containers are unique because you can deploy them to almost any environment. You don’t need to worry about anything else apart from the container image. Before containers went mainstream, teams would need to build virtual machines for testing, development, and production. Today, containers can be created once and then pulled to anywhere they’re needed. It doesn’t matter what language your application is created in; there is a containerized runtime to deploy and release to. ### Resource Efficiency Containers are very efficient for several reasons. They have a smaller footprint, eliminating the need for separate operating systems, drivers, etc. Cgroups can be assigned to a container to efficiently allocate resources, kind of like quality of service for microservices. You can also run many more containers on a single instance, potentially running multiple applications using minimal CPU, Disk, and Memory. ### Scalability Scaling and containers go hand in hand. It’s so easy to scale up and down on demand. Triggers can be created that spin up more containers, for example, when CPU load hits 75%. Scaling features a minimum and maximum threshold and a desired configuration. This is to prevent containers from scaling out of control and perhaps saturating a downstream database. ### Fast Startup Times Startup speeds are generally significantly faster when using a container instead of a VM or VPS. This is because they are so lightweight. The execution code is also typically much faster within a container environment; optimized code will run much faster in a container. ### Improved Developer Experience Containers allow businesses to create consistent working environments for developers, which results in faster coding, testing, and debugging (and happy developers!). Combine this with fast startup times. Devs can deploy and destroy containers in seconds and test instantly. Containers also need fewer dependencies and are fantastic in hybrid cloud and native development teams. ### Faster Deployment Process Containers promote faster deployments through standardized packaging, rapid startup times, automation with orchestration tools, and seamless integration with CI/CD pipelines. This allows for quicker updates, easier rollbacks, and a more agile development process. ### Cost Optimization Features Containers are cheaper to run because you require less host hardware to deploy containers than you would if using virtual machines or physical hardware. Right-sizing applications easier, so you don’t waste resources and overspend on your cloud budget. Containers also speed up the development process, introducing cost savings there, too. During quiet periods, the application can be scaled right back to save on wasted computing costs. ### Microservices Architecture Support Microservices packaged neatly in containers offer a perfect fit for modular cloud containers, enabling independent development, testing, and deployment. This creates scalability at the service level, allowing for precise resource allocation and improved fault tolerance. With the flexibility to develop microservices in different programming languages coupled with standardized packaging and deployment through containers, businesses benefit from streamlined workflows and enhanced portability across diverse environments. ### Managing Containerized Applications Managing a containerized application is straightforward with the right tools and understanding of containerization principles. Containers provide a consistent environment for applications to run, making it easier to deploy and manage them compared to VMs or instances. With container orchestration platforms like Kubernetes or Docker Swarm, managing containerized applications becomes even easier. However, it’s important to remember that managing a containerized application still requires knowledge of container technology, networking, security, and monitoring practices. It’s essential to understand how to configure and optimize container resources, manage dependencies, make configuration files, handle data persistence, and troubleshoot issues that may arise. ## Is Kubernetes a Container? Kubernetes is not a container itself; it is an orchestration platform. Container orchestration platforms automate the deployment, scaling, and management of containerized applications, typically across a set of clusters or hosts. Kubernetes doesn’t create or directly run the containers in cloud computing, but it coordinates and runs the schedules containers rely on to remain efficient, reliable, and secure. Kubernetes is an open-source application, sometimes called a control plane, responsible for the efficiency and management of containers, including scaling and lifecycle options. It works great in complex environments that run large numbers of interconnected containers. ## What Is the Difference Between a VM and a Container? Virtual machines and containers are both virtualization technologies but they are very different. A VM is a software emulation of a physical computer that includes the operating system, virtual hardware, and any required application. VMs are a proven technology that has been mainstream for the last 20 years. VMs create isolated environments abstracted from the host operating system and underlying hardware itself. The only downside, especially when compared to the containers, is that VMs are big, bulky, and hog resources in comparison. In contrast, a container is a lightweight package containing an application and its dependencies. It shares the underlying operating system of the host machine but runs in isolation from other containers. This makes containers portable and fast to start up since they don’t need to boot a separate OS. ## Running Containers on Atlantic.Net Containerized applications and workloads can be deployed effortlessly on the Atlantic.Net Cloud Platform. Spanning eight strategically located data centers throughout the United States, Europe, and Asia, leverage our highly reliable virtual private servers to deploy your application on our Linux container environments. We support popular container runtimes like Docker, offering you the flexibility to choose the tools that best suit your needs. Whether you’re running on Linux, Windows, or Unix, our container platform always ensures reliable service. Join us today and discover the simplicity of containerized applications. Unlock the power and flexibility of running containers on the ACP cloud platform and unlock new possibilities for your cloud-native applications. We even offer super simple 1-click Docker deployments, and our [blog](https://www.atlantic.net/blog/) has extensive documentation on how to run various types of Docker containers on ACP Don’t miss out on this opportunity – [get started now](https://www.atlantic.net/about-us/corporate-contact/)! --- # HIPAA Compliant Software Development: Principles and Best Practices > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-software-development-principles-and-best-practices/ | Published: 2024-04-12 | Updated: 2024-09-24 | Author: Gilad Maayan ## What Is HIPAA Compliance? HIPAA, the Health Insurance Portability and Accountability Act, was enacted in 1996 by the U.S. Congress, with the goal of modernizing the flow of healthcare information. It was aimed at protecting the information of patients while allowing the transfer of health data required to provide high-quality health care. The HIPAA rules are designed to protect the privacy and security of certain health information. For software developers, it means that any software used to store, collect, process, or transmit protected health information (PHI) must be designed in such a way that it meets the requirements of HIPAA. In this article, we’ll briefly review HIPAA compliance requirements, cover the key principles of HIPAA-compliant development, and provide three best practices that can help your software comply with HIPAA: risk assessments, a [modern development paradigm called GitOps](https://codefresh.io/learn/gitops/), and backup and recovery practices. ## What Are HIPAA Compliance Requirements? Here is a brief overview of the [key requirements of the HIPAA regulation](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). ### HIPAA Privacy Rule The HIPAA Privacy Rule establishes national standards for the protection of individuals’ medical records and other personal health information (PHI). It applies to health plans, healthcare clearinghouses, and healthcare providers that conduct certain healthcare transactions electronically. The rule requires appropriate safeguards to protect the privacy of personal health information and sets limits and conditions on the uses and disclosures that may be made of such information without patient authorization. It also gives patients rights over their health information, including rights to examine and obtain a copy of their health records and to request corrections. ### HIPAA Security Rule The [HIPAA Security Rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/) sets standards for protecting the confidentiality, integrity, and availability of electronic protected health information (ePHI). Covered entities and their business associates must implement technical, physical, and administrative safeguards to secure ePHI. This includes measures like access control, data encryption, and the use of secure communication channels. The Security Rule is flexible, allowing organizations to tailor their security measures to their size, capabilities, and the potential risks to ePHI. ### HIPAA Enforcement Rule The HIPAA Enforcement Rule provides guidelines for investigations into HIPAA compliance violations, compliance reviews, and hearings. It establishes procedures for imposing civil money penalties on covered entities and their business associates that fail to comply with the HIPAA rules. The Enforcement Rule also outlines the process for entities to respond to complaints, the factors considered in determining penalties, and the rights to an administrative hearing. ### Breach Notification Rule The HIPAA Breach Notification Rule requires covered entities and their business associates to notify affected individuals, the Secretary of Health and Human Services, and in some cases, the media, of a breach of unsecured PHI. Notifications must be provided without unreasonable delay and in no case later than 60 days following the discovery of a breach. This rule aims to ensure that individuals are aware of breaches so they can take steps to protect themselves from potential harm. ### Omnibus Rule The HIPAA Omnibus Rule, enacted in 2013, strengthens the privacy and security protections established under HIPAA for individual health information. It expands the obligations of business associates of healthcare providers, plans, and clearinghouses, making them directly liable for compliance with certain HIPAA Privacy and Security Rule requirements. The Omnibus Rule also enhances limitations on the use and disclosure of PHI for marketing and fundraising purposes and prohibits the sale of PHI without individual authorization. ## 4 Principles of HIPAA-Compliant Software Development Here are the key principles of HIPAA-compliant software development. ### 1. Data Minimization: Only Collect Necessary Information In HIPAA-compliant software development, data minimization is a critical principle. It emphasizes collecting only the information necessary to fulfill a specific purpose, thereby reducing the risk of unauthorized access or disclosure. This approach not only aligns with privacy best practices but also minimizes potential damage in the event of a data breach. Developers must evaluate the necessity of each piece of PHI they intend to collect and process, ensuring that only essential data is handled. ### 2. Data Encryption at Rest and in Transit Encrypting data at rest and in transit is fundamental to safeguarding PHI. Encryption transforms readable data into an unreadable format that can only be decrypted with a specific key, significantly reducing the risk of data breaches. For HIPAA compliance, developers must ensure that PHI stored in databases, files, or transmitted over networks is encrypted using strong, industry-standard algorithms. This protects information from unauthorized access, whether it’s stored on a server or transmitted to another entity. ### 3. Access Control: Authorization and Authentication Mechanisms Implementing robust access control measures is essential for HIPAA compliance. This involves creating mechanisms for authentication, ensuring that only authorized individuals can access ePHI, and authorization, defining what authorized users can do with the data. Techniques such as multi-factor authentication, role-based access controls, and secure password policies help prevent unauthorized access to sensitive information. Regularly reviewing and updating access privileges is also crucial to accommodate changes in roles or employment status. ### 4. Audit Controls: Tracking Access and Changes to PHI Audit controls are critical for tracking access to and modifications of PHI. They help in identifying and investigating unauthorized activities or potential breaches by maintaining records of who accessed information, what changes were made, and when these activities occurred. Implementing comprehensive audit trails and monitoring systems enables organizations to detect anomalies in system use, ensuring accountability and facilitating the investigation of incidents. This principle is pivotal in maintaining the integrity and confidentiality of PHI. ## HIPAA Compliance Best Practices For Software Development ### Conduct a HIPAA Risk Assessment The first step in ensuring HIPAA compliance in your software development process is conducting a thorough risk assessment. This involves identifying potential threats and vulnerabilities that could affect the confidentiality, integrity, and availability of electronic protected health information (ePHI). Once these threats and vulnerabilities are identified, the next step is to assess the current security measures in place to protect against these risks. This involves evaluating your software’s security features, your team’s security practices, and your organization’s security policies and procedures. Lastly, the risk assessment process involves determining the potential impact of these threats and vulnerabilities on your organization and taking appropriate actions to mitigate these risks. This could involve implementing additional security measures, updating your software, or revising your security policies and procedures. ### Utilize GitOps for Configuration and Infrastructure Management GitOps, a modern development paradigm, leverages Git as a single source of truth for declarative infrastructure and applications. By utilizing GitOps, teams can enhance their ability to audit code changes and demonstrate adherence to safe coding practices, crucial for the protection of electronic protected health information (ePHI). The GitOps model automates the deployment process by using Git pull requests to initiate changes in the infrastructure, which then triggers automated pipelines to test, validate, and deploy those changes. This automation ensures that any change to the infrastructure or applications that handle ePHI is peer-reviewed, recorded, and traceable. In addition, GitOps offers an additional layer of security by facilitating rapid rollbacks and recovery from incidents, minimizing the impact of any breach or failure. With its emphasis on version control, immutability, and support for automated compliance checks, GitOps is an invaluable methodology for maintaining the integrity, confidentiality, and availability of ePHI in a HIPAA-compliant environment. ### Implement Data Backup and Disaster Recovery A data [backup and disaster recovery](https://www.atlantic.net/disaster-recovery/) plan is another essential component of HIPAA compliance in software development. This involves regularly backing up your ePHI, and implementing procedures to restore your [ePHI](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) in the event of a data loss or system failure. Your data backup plan should include details on how frequently your data is backed up, where your backups are stored, and how long your backups are retained. Your disaster recovery plan should include details on how your ePHI is restored, how quickly it can be restored, and what steps are taken to ensure the integrity and confidentiality of your ePHI during the recovery process. In conclusion, ensuring HIPAA compliance in your software development process involves implementing robust security measures, conducting regular risk assessments, and developing a comprehensive data backup and disaster recovery plan. By following these principles and best practices, you can protect your ePHI, comply with HIPAA requirements, and build trust with your patients and customers. Remember, when it comes to HIPAA compliance, it’s always better to be safe than sorry. **Author Bio: Gilad David Maayan** ![](https://www.atlantic.net/wp-content/uploads/2023/10/giladimage.jpg) Gilad David Maayan is a technology writer who has worked with over 150 technology companies including SAP, Imperva, Samsung NEXT, NetApp and Check Point, producing technical and thought leadership content that elucidates technical solutions for developers and IT leadership. Today he heads[Agile SEO](https://agileseo.co.il/), the leading marketing agency in the technology industry. LinkedIn:[Lindedin](https://www.linkedin.com/in/giladdavidmaayan/) --- # How to Deploy a NestJS Application with Nginx on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-deploy-a-nestjs-application-with-nginx-on-ubuntu-24-04/ | Published: 2024-04-13 | Updated: 2025-05-27 | Author: Hitesh Jethva NestJS is a progressive Node.js framework for building efficient, reliable, and scalable server-side applications. It leverages TypeScript to bring robust type-checking and enhanced developer productivity to the Node.js ecosystem. Angular’s architecture inspires NestJS and uses similar concepts such as modules, controllers, services, and decorators, making it familiar to developers with experience in Angular or similar frameworks. In this tutorial, we will show you how to deploy NestJS on Ubuntu 24.04. ## Step 1 – Install Node.js First, install the necessary dependencies using the following command. ``` apt-get install -y ca-certificates curl gnupg ``` Next, download the Node.js GPG key. ``` mkdir -p /etc/apt/keyrings curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg ``` Next, add the NodeSource repo to the APT source list. ``` echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_22.x nodistro main" | tee /etc/apt/sources.list.d/nodesource.list ``` Then, update the repository index and install Node.js with the following command. ``` apt update apt-get install -y nodejs ``` Next, verify the Node.js version using the following command. ``` node -v ``` Output. ``` v22.15.1 ``` ## Step 2 – Install NestJS You can use the NPM to install the Nest CLI easily. ``` npm i -g @nestjs/cli ``` Next, create a project for NestJS using the following command: ``` nest new project ``` Select the NPM package manager and press the Enter key to create a project. ``` ⚡ We will scaffold your app in a few seconds.. ? Which package manager would you ❤️ to use? (Use arrow keys) ❯ npm yarn pnpm ? Which package manager would you ❤️ to use? npm CREATE project/.eslintrc.js (663 bytes) CREATE project/.prettierrc (51 bytes) CREATE project/README.md (3340 bytes) CREATE project/nest-cli.json (171 bytes) CREATE project/package.json (1946 bytes) CREATE project/tsconfig.build.json (97 bytes) CREATE project/tsconfig.json (546 bytes) CREATE project/src/app.controller.ts (274 bytes) CREATE project/src/app.module.ts (249 bytes) CREATE project/src/app.service.ts (142 bytes) CREATE project/src/main.ts (208 bytes) CREATE project/src/app.controller.spec.ts (617 bytes) CREATE project/test/jest-e2e.json (183 bytes) CREATE project/test/app.e2e-spec.ts (630 bytes) ✔ Installation in progress... ☕ 🚀 Successfully created project project 👉 Get started with the following commands: $ cd project $ npm run start Thanks for installing Nest 🙏 Please consider donating to our open collective to help us maintain this package. 🍷 Donate: https://opencollective.com/nest ``` Next, change the directory to the project and download the typescript. ``` cd project git clone https://github.com/nestjs/typescript-starter.git ``` Then, install all the required dependencies. ``` npm install ``` Next, start your application. ``` npm run start ``` You will see the following output: ``` [Nest] 185741 - 03/14/2025, 3:17:45 PM LOG [NestFactory] Starting Nest application... [Nest] 185741 - 03/14/2025, 3:17:45 PM LOG [InstanceLoader] AppModule dependencies initialized +15ms [Nest] 185741 - 03/14/2025, 3:17:45 PM LOG [RoutesResolver] AppController {/}: +40ms [Nest] 185741 - 03/14/2025, 3:17:45 PM LOG [RouterExplorer] Mapped {/, GET} route +3ms [Nest] 185741 - 03/14/2025, 3:17:45 PM LOG [NestApplication] Nest application successfully started +2ms ``` Press the **CTRL + C** to stop the application. You can also test your application using the following command: ``` npm run test ``` You will see the following output: ``` > project@0.0.1 test > jest PASS src/app.controller.spec.ts (5.578 s) AppController root ✓ should return "Hello World!" (16 ms) Test Suites: 1 passed, 1 total Tests: 1 passed, 1 total Snapshots: 0 total Time: 5.679 s Ran all test suites. ``` ## Step 3 – Use PM2 to Manage the NestJS Application First, install PM2 using the following command: ``` npm install -g pm2 ``` Next, start your NestJS application using the following command: ``` pm2 start dist/src/main.js --name "nestjs.example.com" ``` Next, run the following command to start your application at system startup. ``` pm2 startup ``` Now, save your service configuration using the following command: ``` pm2 save ``` ## Step 4 – Configure Nginx for NestJS First, install the Nginx server using the following command: ``` apt install nginx -y ``` Next, create an Nginx virtual host for NestJS. ``` nano /etc/nginx/conf.d/nestjs.conf ``` Add the following configuration: ``` server { listen 80; server_name nestjs.example.com; location / { proxy_pass http://127.0.0.1:3000; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Host $host; proxy_cache_bypass $http_upgrade; } } ``` Save the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after the file http {: ``` server_names_hash_bucket_size 64; ``` Finally, restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 5 – Access the NestJS Application At this point, your NestJS application is created with Nginx as a reverse proxy. You can now access it using the URL **http://nestjs.example.com.** You will see the NestJS application on the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p1-5.png) ## Conclusion NestJS provides developers with a streamlined pathway to harnessing the power of this modern Node.js framework for building efficient and scalable server-side applications. By following the step-by-step guide outlined in this article, users can quickly set up NestJS on their Ubuntu systems, leveraging its robust features and architectural patterns to accelerate development workflows. You can now use the NestJS framework on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install FileRun on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-filerun-on-ubuntu-22-04/ | Published: 2024-04-14 | Updated: 2024-05-07 | Author: Hitesh Jethva FileRun is a self-hosted file-sharing and collaboration platform that provides users with a secure and feature-rich environment for managing and sharing files and documents. FileRun provides a comprehensive solution for organizations seeking a secure and user-friendly platform for file sharing and collaboration. Its self-hosted nature, robust security features, customization options, and integration capabilities make it a popular choice for businesses and individuals looking to streamline their file management and collaboration workflows while maintaining control over their data. In this tutorial, we will show you how to install FileRun on Ubuntu 22.04. ## Step 1 – Install Docker and Docker Compose First, install all the required dependencies using the following command: ``` apt-get install curl git build-essential apt-transport-https ca-certificates software-properties-common -y ``` Next, download the Docker GPG key: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg ``` Next, add the Docker repo to the APT source file. ``` echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null ``` Then, update the repository index and install Docker with Docker Compose. ``` apt update -y apt install docker-ce docker-compose-plugin -y ``` Next, verify the Docker Compose version. ``` docker compose version ``` Output: ``` Docker Compose version v2.24.7 ``` ## Step 2 – Create a Docker Compose File for FileRun First, create a directory for FileRun. mkdir filerun Next, create a docker-compose.yml file inside filerun directory. ``` cd filerun nano docker-compose.yml ``` Add the following lines: ``` version: '3.8' services: db: image: mariadb:10.5 container_name: filerun_mariadb environment: MYSQL_ROOT_PASSWORD: password MYSQL_USER: filerun MYSQL_PASSWORD: password MYSQL_DATABASE: filerundb volumes: - ./db:/var/lib/mysql web: image: alexphillips/filerun container_name: filerun environment: FR_DB_HOST: db FR_DB_PORT: 3306 FR_DB_NAME: filerundb FR_DB_USER: filerun FR_DB_PASS: password APACHE_RUN_USER: www-data APACHE_RUN_USER_ID: 33 APACHE_RUN_GROUP: www-data APACHE_RUN_GROUP_ID: 33 depends_on: - db links: - db - tika - elasticsearch ports: - "8080:80" volumes: - ./html:/var/www/html - ./user-files:/user-files tika: image: apache/tika container_name: filerun_tika elasticsearch: image: docker.elastic.co/elasticsearch/elasticsearch:6.8.23 container_name: filerun_search environment: - cluster.name=docker-cluster - bootstrap.memory_lock=true - "ES_JAVA_OPTS=-Xms512m -Xmx512m" ulimits: memlock: soft: -1 hard: -1 nofile: soft: 65535 hard: 65535 mem_limit: 1g volumes: - ./esearch:/usr/share/elasticsearch/data ``` Next, create a directory to store ElasticSearch data. ``` mkdir esearch ``` Next, edit the sysctl.conf file. ``` nano /etc/sysctl.conf ``` Add the following line: ``` vm.max_map_count = 262144 ``` Now, run the following command to apply the changes: ``` sysctl -w vm.max_map_count=262144 ``` Finally, restart the Docker service using the following command: ``` systemctl restart docker ``` ## Step 3 – Launch FileRun Container You can now run the following command to launch the FileRun container: ``` docker compose up -d ``` You can verify the created containers using the following command: ``` docker ps ``` Output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES ab1f1f2903c8 alexphillips/filerun "/init" 14 seconds ago Up 11 seconds 443/tcp, 0.0.0.0:8080->80/tcp, :::8080->80/tcp filerun 8ade817cb024 mariadb:10.5 "docker-entrypoint.s…" 14 seconds ago Up 12 seconds 3306/tcp filerun_mariadb c8ffd162cf69 apache/tika "/bin/sh -c 'exec ja…" 14 seconds ago Up 12 seconds 9998/tcp filerun_tika ``` ## Step 4 – Configure Nginx for FileRun First, install the Nginx server using the following command: ``` apt install nginx ``` Next, edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http {: ``` server_names_hash_bucket_size 64; ``` Next, create a new Nginx virtual host configuration file for FileRun. ``` nano /etc/nginx/conf.d/filerun.conf ``` Add the following configuration: ``` upstream backend { server 127.0.0.1:8080; keepalive 32; } server { listen 80; server_name filerun.example.com; access_log /var/log/nginx/filerun.access.log; error_log /var/log/nginx/filerun.error.log; location / { client_max_body_size 50M; proxy_set_header Connection ""; proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-Protocol $scheme; proxy_buffers 256 16k; proxy_buffer_size 16k; proxy_read_timeout 1800s; proxy_connect_timeout 1800s; proxy_http_version 1.1; proxy_pass http://backend; } } ``` Save and close the file, then restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 5 – Access FileRun Web UI Now, open your web browser and access the FileRun web interface using the URL **http://filerun.example.com.** You will see the FileRun welcome page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p1-6.png) Click on **Next.** You will see the server requirement page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p2-5.png) Click on **Next.** You will see the database setup page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p3-4.png) Provide your database details and click on **Next.** Once the installation is completed, you will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p4-4.png) Please note the superuser and password to log in to the FileRun web interface. Then, click on **Next**. You will see the FileRun login page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p5-3.png) Provide your username and password and click on **Sign in.** You will see the FileRun control panel. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p6-3.png) Click on **X** to close the control panel. You will be redirected to the FileRun dashboard. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p7-3.png) ## Conclusion By following the step-by-step installation guide provided in this article, users can quickly deploy FileRun on their Ubuntu servers and take advantage of its rich feature set and user-friendly interface. FileRun provides a seamless file-sharing and collaboration experience, with features like version control, granular access controls, file preview, annotation, and integration capabilities. Furthermore, FileRun’s customization options allow users to tailor the platform to their specific needs and branding requirements, creating a personalized and branded file-sharing environment for their organization. You can use FileRun as a file-sharing platform on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Create Remote Desktop Gateway via Apache Guacamole on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-create-remote-desktop-gateway-via-apache-guacamole-on-ubuntu-24-04/ | Published: 2024-04-15 | Updated: 2025-05-19 | Author: Hitesh Jethva Apache Guacamole is an open-source remote desktop gateway that allows users to access their desktop environments and applications from anywhere using just a web browser. It supports standard protocols such as VNC, RDP, and SSH, allowing users to securely connect to remote desktops and servers. It provides a cost-effective, flexible solution for remote access to desktop environments and applications. In this tutorial, we will show you how to install the Apache Guacamole remote desktop gateway on Ubuntu 24.04. ## Step 1 – Install Docker and Docker Compose By default, the latest version of Docker is not included in the Ubuntu main repository, so you will need to install it from Docker’s official repository. First, install all required dependencies using the following command: ``` apt-get install curl git build-essential apt-transport-https ca-certificates software-properties-common -y ``` Next, import the Docker GPG key. ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg ``` Then, add the Docker repository to the APT source file. ``` echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null ``` Next, update the repository and install Docker and Docker Compose using the following command: ``` apt update -y apt install docker-ce docker-compose-plugin -y ``` After the installation, you can verify the Docker Compose version using the following command: ``` docker compose version ``` Output: ``` Docker Compose version v2.35.1 ``` ## Step 2 – Download Apache Guacamole Server and Client Images First, download the Apache Guacamole server image from the DockerHub registry. ``` docker pull guacamole/guacd ``` Output: ``` Using default tag: latest latest: Pulling from guacamole/guacd 619be1103602: Pull complete 3c5b89584531: Pull complete 0019d47ab527: Pull complete b98fd7159241: Pull complete 4b51f493a70a: Pull complete Digest: sha256:2cfbd230c979d3fd7187e1aa3a7284be22d389f3fde3d18c27179403138bd696 Status: Downloaded newer image for guacamole/guacd:latest docker.io/guacamole/guacd:latest ``` Next, download the Guacamole client image using the following command: ``` docker pull guacamole/guacamole ``` Output: ``` Using default tag: latest latest: Pulling from guacamole/guacamole 23828d760c7b: Pull complete 8069355d5739: Pull complete c0818127cd97: Pull complete db15aff3aedb: Pull complete 2d8727e407d8: Pull complete 9074748e27d0: Pull complete 14b694a905ac: Pull complete 4e01fc5ea163: Pull complete 523f95617476: Pull complete fa289bf4ec66: Pull complete 197a4d4370e2: Pull complete 3fb5c1264eef: Pull complete 09f8140b30df: Pull complete Digest: sha256:53de0a604daa61aac98aad7764d5f9a6e7d1154a0a5e6b4952aa0d14a107eb80 Status: Downloaded newer image for guacamole/guacamole:latest docker.io/guacamole/guacamole:latest ``` You can now verify both downloaded images using the following command: ``` docker images ``` Output: ``` REPOSITORY TAG IMAGE ID CREATED SIZE guacamole/guacamole latest 275783b15e55 44 minutes ago 496MB guacamole/guacd latest dfa65bda7349 24 hours ago 149MB ``` ## Step 3 – Start Apache Guacamole MySQL Container You will also need a MySQL database container to authenticate Apache Guacamole. Let’s create a new MySQL container using the following command: ``` docker run --name guacamoledb -e MYSQL_ROOT_PASSWORD=password -e MYSQL_DATABASE=guacdb -d mysql/mysql-server ``` Next, create a directory to store the MySQL database. ``` mkdir -p /opt/guacamole/mysql ``` Then, generate MySQL initialization script. ``` docker run --rm guacamole/guacamole /opt/guacamole/bin/initdb.sh --mysql > /opt/guacamole/mysql/01-initdb.sql ``` Next, copy the MySQL script to the MySQL container. ``` docker cp /opt/guacamole/mysql/01-initdb.sql guacamoledb:/docker-entrypoint-initdb.d ``` Next, connect to the MySQL container using the docker exec command: ``` docker exec -it guacamoledb bash ``` Next, verify the MySQL initialization script. ``` cd /docker-entrypoint-initdb.d/ ls ``` Output: ``` 01-initdb.sql ``` Next, connect to the MySQL shell. ``` mysql -u root -p ``` Then, switch the database to guacd and initialize the Guacamole database: ``` use guacdb; source 01-initdb.sql; ``` You can now verify all tables using the following command: ``` show tables; ``` Output: ``` +---------------------------------------+ | Tables_in_guacdb | +---------------------------------------+ | guacamole_connection | | guacamole_connection_attribute | | guacamole_connection_group | | guacamole_connection_group_attribute | | guacamole_connection_group_permission | | guacamole_connection_history | | guacamole_connection_parameter | | guacamole_connection_permission | | guacamole_entity | | guacamole_sharing_profile | | guacamole_sharing_profile_attribute | | guacamole_sharing_profile_parameter | | guacamole_sharing_profile_permission | | guacamole_system_permission | | guacamole_user | | guacamole_user_attribute | | guacamole_user_group | | guacamole_user_group_attribute | | guacamole_user_group_member | | guacamole_user_group_permission | | guacamole_user_history | | guacamole_user_password_history | | guacamole_user_permission | +---------------------------------------+ 23 rows in set (0.00 sec) ``` Next, create a database and user for Guacamole. ``` create user guacadmin@'%' identified by 'password'; grant SELECT,UPDATE,INSERT,DELETE on guacdb.* to guacadmin@'%'; ``` Then, flush the privileges and exit from the MySQL shell. ``` flush privileges; exit; ``` Also, exit from the MySQL container using the following command: ``` exit ``` ## Step 4 – Launch Guacamole Server Container You can start the Apache Guacamole server container using the following command: ``` docker run --name guacamole-server -d guacamole/guacd ``` Next, verify the container log using the following command: ``` docker logs --tail 10 guacamole-server ``` Output. ``` guacd[1]: INFO: Guacamole proxy daemon (guacd) version 1.5.5 started guacd[1]: INFO: Listening on host 0.0.0.0, port 4822 ``` To check the container status, run the following command: ``` docker ps ``` Output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 5d35d837635b guacamole/guacd "/bin/sh -c '/opt/gu…" 23 seconds ago Up 22 seconds (health: starting) 4822/tcp guacamole-server e2b20f4860af mysql/mysql-server "/entrypoint.sh mysq…" 2 minutes ago Up 2 minutes (healthy) 3306/tcp, 33060-33061/tcp guacamoledb ``` ## Step 5 – Launch Guacamole Client Container To create an Apache Guacamole client container, run the following command: ``` docker run --name guacamole-client --link guacamole-server:guacd --link guacamoledb:mysql -e MYSQL_DATABASE=guacdb -e MYSQL_USER=guacadmin -e MYSQL_PASSWORD=password -d -p 80:8080 guacamole/guacamole ``` You can now check the status of the Apache Guacamole client container using the following command: ``` docker ps ``` Output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 56d69250007f guacamole/guacamole "/opt/guacamole/bin/…" 7 seconds ago Up 6 seconds 0.0.0.0:80->8080/tcp, :::80->8080/tcp guacamole-client 5d35d837635b guacamole/guacd "/bin/sh -c '/opt/gu…" 41 seconds ago Up 40 seconds (health: starting) 4822/tcp guacamole-server e2b20f4860af mysql/mysql-server "/entrypoint.sh mysq…" 3 minutes ago Up 2 minutes (healthy) 3306/tcp, 33060-33061/tcp guacamoledb ``` ## Step 6 – Access Apache Guacamole Dashboard Now, open your web browser and access the Apache Guacamole web interface using the URL **http://your-server-ip/guacamole.** You will see the Apache Guacamole web interface login page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p1-7.png) Provide default admin username as guacadmin and password as guacadmin, then click on the **Login** button. You will see the Apache Guacamole dashboard. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p2-6.png) Next, click on **guacaadmin** => **Settings** => **Connections.** You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p3-5.png) Click on **New Connection.** You will see the connection information page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p4-5.png) ![](https://www.atlantic.net/wp-content/uploads/2024/03/connection.png) ![](https://www.atlantic.net/wp-content/uploads/2024/03/p6-4.png) Provide your servername, protocol, IP address, port, username, and password, then click on the **Save** button to save the connection. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p7-4.png) Now, go back to **home** page and click on your server connection. Once you are connected to your server, you will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/04/p1-7.png)   ## Conclusion Following the step-by-step installation guide outlined in this article, users can quickly deploy Guacamole on their Ubuntu servers and benefit from its rich feature set and ease of use. Overall, Apache Guacamole empowers users to provide seamless remote access to their systems and applications, enhancing productivity and enabling flexible work environments while maintaining security and compliance requirements. You can use Apache Guacamole to manage multiple remote connections on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Seafile Self-Hosted Cloud Storage with Nginx on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-seafile-self-hosted-cloud-storage-with-nginx-on-ubuntu-24-04/ | Published: 2024-04-16 | Updated: 2025-05-27 | Author: Hitesh Jethva Seafile is a self-hosted cloud storage platform for secure file synchronization, sharing, and collaboration. It provides users with a robust and flexible solution to manage their files and data while maintaining full control over their infrastructure. Here are some key features and benefits of Seafile: - Secure File Storage - File Synchronization - Version Control - File Sharing and Collaboration - Customization and Extensibility - Scalability and Performance In this tutorial, we will show you how to install Seafile Self-Hosted Cloud Storage with Nginx on Ubuntu 24.04. ## Step 1 – Install Required Dependency Seafile is a Python-based application. To install it on your server, you will need to install Python and other required dependencies. You can do this using the following command: ``` apt-get install -y python3 sqlite3 python3-dev python3-setuptools python3-pip libmysqlclient-dev ldap-utils libldap2-dev python3-venv libsasl2-dev libssl-dev libmemcached-dev build-essential libffi-dev ``` ## Step 2 – Install and Configure Database First, install the MySQL database server using the following command: ``` apt install -y mysql-server ``` Next, connect to the MySQL shell. ``` mysql ``` Then, set the MySQL root password using the following command: ``` mysql> ALTER USER 'root'@'localhost' IDENTIFIED WITH mysql_native_password BY 'password'; ``` Next, create a database for Seafile. ``` mysql> CREATE DATABASE ccnet_db CHARACTER SET utf8; mysql> CREATE DATABASE seafile_db CHARACTER SET utf8; mysql> CREATE DATABASE seahub_db CHARACTER SET utf8; ``` Then, create a user for Seafile. ``` mysql> CREATE USER 'seafile'@'localhost' IDENTIFIED WITH mysql_native_password BY 'password'; ``` Then, the user will be granted all privileges on the three databases. ``` mysql> GRANT ALL PRIVILEGES ON `ccnet_db`.* to `seafile`@localhost; mysql> GRANT ALL PRIVILEGES ON `seafile_db`.* to `seafile`@localhost; mysql> GRANT ALL PRIVILEGES ON `seahub_db`.* to `seafile`@localhost; ``` Finally, flush the privileges and exit from the MySQL shell. ``` mysql> FLUSH PRIVILEGES; mysql> exit ``` ## Step 3 – Install Seafile First, create a user and directory for Seafile. ``` mkdir /opt/seafile adduser --home /opt/seafile --shell /bin/bash seafile ``` Then, change the ownership of the seafile directory. ``` chown -R seafile: /opt/seafile ``` Next, log in to the Seafile user . ``` su - seafile ``` Next, create and activate a Python virtual environment. ``` python3 -m venv python-venv source python-venv/bin/activate ``` Next, install other required packages using the PIP command: ``` pip3 install --timeout=3600 wheel django==4.2.* future==0.18.* mysqlclient==2.1.* pymysql pillow==10.2.* pylibmc captcha==0.5.* markupsafe==2.0.1 jinja2 sqlalchemy==2.0.18 psd-tools django-pylibmc django_simple_captcha==0.6.* djangosaml2==1.5.* pysaml2==7.2.* pycryptodome==3.16.* cffi==1.16.0 lxml python-ldap==3.4.3 ``` Download the latest version of the Seafile server. ``` wget https://s3.eu-central-1.amazonaws.com/download.seadrive.org/seafile-server_12.0.11_x86-64.tar.gz ``` Next, extract the downloaded file. ``` tar -xvf seafile-server_12.0.11_x86-64.tar.gz ``` Then, navigate to the extracted directory and configure Seafile. ``` cd seafile-server-12.0.11 ./setup-seafile-mysql.sh ``` Answer all the questions as shown below: ``` Press ENTER to continue ----------------------------------------------------------------- What is the name of the server? It will be displayed on the client. 3 - 15 letters or digits [ server name ] seafile-server What is the ip or domain of the server? For example: www.mycompany.com, 192.168.1.101 [ This server's ip or domain ] seafile.example.com Which port do you want to use for the seafile fileserver? [ default "8082" ] ------------------------------------------------------- Please choose a way to initialize seafile databases: ------------------------------------------------------- [1] Create new ccnet/seafile/seahub databases [2] Use existing ccnet/seafile/seahub databases [ 1 or 2 ] 2 What is the host of mysql server? [ default "localhost" ] What is the port of mysql server? [ default "3306" ] Which mysql user to use for seafile? [ mysql user for seafile ] seafile What is the password for mysql user "seafile"? [ password for seafile ] verifying password of user seafile ... done Enter the existing database name for ccnet: [ ccnet database ] ccnet_db verifying user "seafile" access to database ccnet_db ... done Enter the existing database name for seafile: [ seafile database ] seafile_db verifying user "seafile" access to database seafile_db ... done Enter the existing database name for seahub: [ seahub database ] seahub_db verifying user "seafile" access to database seahub_db ... done --------------------------------- This is your configuration --------------------------------- server name: seafile-server server ip/domain: seafile.example.com seafile data dir: /opt/seafile/seafile-data fileserver port: 8082 database: use existing ccnet database: ccnet_db seafile database: seafile_db seahub database: seahub_db database user: seafile ``` Next, create an environment file. ``` nano /opt/seafile/conf/.env ``` Add the below line: ``` JWT_PRIVATE_KEY=8d3d93aeaf95fddf34aa0e47bcb8fc19d2cb2d92a4f4e3cb6d4dd8e302e93014 ``` ## Step 4 – Start Seafile Server Now, please navigate to the seafile server directory and start it using the following command: ``` cd /opt/seafile/seafile-server-latest ./seafile.sh start ``` Then, start the SeaHub server using the following command: ``` ./seahub.sh start ``` You will be asked to set up your admin username and password as shown below. ``` LC_ALL is not set in ENV, set to en_US.UTF-8 Starting seahub at port 8000 ... ---------------------------------------- It's the first time you start the seafile server. Now let's create the admin account ---------------------------------------- What is the email for the admin account? [ admin email ] admin@example.com What is the password for the admin account? [ admin password ] Enter the password again: [ admin password again ] ---------------------------------------- Successfully created seafile admin ---------------------------------------- Seahub is started Done. ``` ## Step 5 – Configure Nginx for Seafile First, install the Nginx server using the following command: ``` apt install nginx ``` Next, create an Nginx virtual host configuration file. ``` nano /etc/nginx/conf.d/seafile.conf ``` Add the following configuration: ``` log_format seafileformat '$http_x_forwarded_for $remote_addr [$time_local] "$request" $status $body_bytes_sent "$http_referer" "$http_user_agent" $upstream_response_time'; server { listen 80; server_name seafile.example.com; server_tokens off; # Prevents the Nginx version from being displayed in the HTTP response header location / { proxy_pass http://127.0.0.1:8000; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Host $server_name; proxy_read_timeout 1200s; proxy_set_header X-Forwarded-Proto http; # used for view/edit office file via Office Online Server client_max_body_size 0; access_log /var/log/nginx/seahub.access.log seafileformat; error_log /var/log/nginx/seahub.error.log; } location /seafhttp { rewrite ^/seafhttp(.*)$ $1 break; proxy_pass http://127.0.0.1:8082; client_max_body_size 0; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_connect_timeout 36000s; proxy_read_timeout 36000s; proxy_send_timeout 36000s; send_timeout 36000s; # Uncomment the following line if you want to support uploads > 4GB # proxy_request_buffering off; access_log /var/log/nginx/seafhttp.access.log seafileformat; error_log /var/log/nginx/seafhttp.error.log; } location /media { root /opt/seafile/seafile-server-latest/seahub; } } ``` Then, edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http{: ``` server_names_hash_bucket_size 64; ``` Save the file, then restart the Nginx to apply the changes. ``` systemctl restart nginx ``` ## Step 6 – Access Seafile Web Interface Now, open your web browser and access the Seafile web UI using the URL **http://seafile.example.com.** You will see the Seafile login page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p1-8.png) Provide your admin username and password and click on **Log In.** You will see the Seafile dashboard on the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/04/seafile.png)   ## Conclusion Overall, Seafile provides a comprehensive solution for organizations seeking secure and flexible cloud storage and collaboration capabilities. Its self-hosted nature, robust security features, and extensive customization options make it a popular choice for businesses and individuals looking to take control of their data and workflows. You can now implement secure cloud storage using Seafile on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Atlantic.Net Honored as Finalist for the 2024 Cloud Security Awards > URL: https://www.atlantic.net/press-releases/atlantic-net-honored-as-finalist-for-the-2024-cloud-security-awards/ | Published: 2024-04-16 | Updated: 2024-06-11 | Author: Alexander Wise ORLANDO, Fla. – April 16, 2024 – Atlantic.Net proudly announces its inclusion in the prestigious shortlist for the 2024 Cloud Security Awards, competing in the esteemed category of Best Security Infrastructure in Enterprise. Now in its second year and with an expanded range of categories, The Cloud Security Awards program celebrates the latest innovations and advancements in cloud-based security solutions. The program received entries from organizations worldwide, including North America, Canada, Europe, the Middle East, and Australasia. The program for 2024 includes two new categories – ‘Best Use of AI in a Cloud Security Solution’ and ‘Best Security Solution for Physical Threat Detection’ – alongside last years’ favorites, ‘Best SaaS Security Solution’, ‘Best Cybersecurity Solution’ and ‘Cloud Security Innovator of the Year’, among others. All 25 categories focus on critical facets of cloud security in a rapidly and constantly evolving digital landscape. James Williams, CEO of The Cloud Awards, expressed his excitement, stating, “We are delighted to announce the shortlist for the 2024 edition of The Cloud Security Awards. The number and quality of the submissions we received pay tribute to the continued importance of cloud security.” He added, “The shortlisted applicants released today have made it through a tremendously competitive initial round of judging. They showcase outstanding cloud-based products and solutions that help organizations and individuals stay secure.” Marty Puranik, Founder and CEO of Atlantic.Net, shared his thoughts, saying, “We are truly honored to be shortlisted in the Best Security Infrastructure in Enterprise category for the 2024 Cloud Security Awards. This acknowledgment underlines the hard work my team has put into providing innovative and secure cloud solutions to our clients. We are grateful to be nominated and eagerly anticipate the next phase of this journey.” For a comprehensive list of the shortlisted candidates, please visit [2024 cloud security awards shortlist](https://www.cloud-awards.com/2024-cloud-security-awards-shortlist) The Cloud Awards and The SaaS Awards are now accepting nominations for their respective programs, recognizing excellence in cloud computing and software-as-a-service across various industries. Entries are also open for two brand new awards programs launched in February 2024: The A.I. Awards and The FinTech Awards, celebrating outstanding work in the fields of Artificial Intelligence and Financial Technologies, respectively. The next deadline for The SaaS Awards is Friday, 24 May 2024. **About the Cloud Awards  ** The Cloud Awards is an international program that has been recognizing and honoring industry leaders, innovators, and organizational transformation in cloud computing since 2011. The Cloud Awards comprises five awards programs, each uniquely celebrating success across cloud computing, software-as-a-service (SaaS), cloud security, artificial intelligence (AI), and financial technologies (FinTech). Winners are selected by a judging panel of international industry experts. For more information about the Cloud Awards, please visit [Cloud awards](https://www.cloud-awards.com/). **About The Cloud Security Awards   ** The Cloud Security Awards celebrates innovation in the cybersecurity industry. The program includes a wide range of categories, including Best Web Security Solution, Cloud Security Innovator of the Year, and Best Security Solution for Finance or Banking. **About Atlantic.Net** Atlantic.Net is a globally recognized cloud services provider that takes pride in its emphasis on security, compliance, and simplifying complex tech setups. With over 30 years of experience under our belt, we’re dedicated to offering developers and IT leaders at companies of all sizes a variety of customizable, on-demand, and budget-friendly cloud solutions tailored to their specific needs. Our client roster includes big names like Lenovo, Newegg, NASA, and Hilton, reflecting our industry leadership, innovation, and customer-centric ethos. Media Contact [pr@atlantic.net](mailto:pr@atlantic.net) --- # How to Install GLPI IT Inventory Management on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-glpi-it-inventory-management-on-ubuntu-24-04/ | Published: 2024-04-17 | Updated: 2025-07-04 | Author: Hitesh Jethva GLPI is an open-source IT asset management (ITAM) and service desk software solution used for managing inventory, tracking assets, and handling user support tickets. GLPI is a versatile and powerful IT inventory management solution suitable for organizations of all sizes. Its open-source nature, extensive feature set, and flexibility make it a popular choice among IT professionals for managing IT assets and providing efficient IT services. In this tutorial, we will show you how to install GLPI IT Inventory Management on Ubuntu 24.04. ## Step 1 – Install the LAMP Server Before starting, you need to make sure a LAMP server is installed on your server. If not installed, you can install it using the following command. ``` apt install apache2 mariadb-server php php-common php-mysql libapache2-mod-php php-gd php-curl php-json php-xmlrpc php-intl php-bcmath php-zip php-apcu php-mbstring php-fileinfo php-xml php-soap php-zip -y ``` After installing the LAMP server, edit the PHP configuration file and make a few changes. ``` nano /etc/php/8.3/apache2/php.ini ``` Change the following settings: ``` memory_limit = 512M date.timezone = UTC upload_max_filesize = 16M session.cookie_httponly = on ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` ## Step 2 – Create a Database for GLPI GLPI uses a MariaDB database to store data. First, log in to the MariaDB server console. ``` mysql ``` Once you are done, create a database and user. ``` CREATE DATABASE glpidb; CREATE USER glpi@localhost IDENTIFIED BY 'password'; ``` Then, grant all the privileges to the GLPI database. ``` GRANT ALL PRIVILEGES ON glpidb.* TO glpi@localhost; ``` Finally, flush the privileges and exit from the MariaDB shell. ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download GLPI First, navigate to the Apache web root directory and download the latest version of GLPI from the GitHub repository. ``` cd /var/www/ wget https://github.com/glpi-project/glpi/releases/download/10.0.18/glpi-10.0.18.tgz ``` Next, extract the downloaded file using the tar command. ``` tar -xf glpi-10.0.18.tgz ``` Then, change the ownership and permission of the glpi directory. ``` chown -R www-data:www-data /var/www/glpi chmod u+rw /var/www/glpi/{files,config} ``` ## Step 4 – Configure Apache for GLPI Next, create an Apache virtual host configuration file to host GLPI. ``` nano /etc/apache2/sites-available/glpi.conf ``` Add the following configuration: ``` ServerName glpi.example.com DocumentRoot /var/www/glpi/public # If you want to place GLPI in a subfolder of your site (e.g. your virtual host is serving multiple applications), # you can use an Alias directive: # Alias "/glpi" "/var/www/glpi/public" Require all granted RewriteEngine On # Redirect all requests to the GLPI router, unless file exists. RewriteCond %{REQUEST_FILENAME} !-f RewriteRule ^(.*)$ index.php [QSA,L] ``` Save the file, then activate the Apache virtual host. ``` a2ensite glpi.conf ``` Then, enable the Apache rewrite module. ``` a2enmod rewrite ``` Finally, restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` ## Step 5 – Access GLPI Web UI GLPI is now installed and configured. You can now access the GLPI web interface using the URL **http://glpi.example.com.** You will see the GLPI setup page: ![](https://www.atlantic.net/wp-content/uploads/2024/03/p1-4.png) Select your language and click on **OK.** You will see the GLPI license page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p2-4.png) Click on **Continue.** You will see the installation page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p3-3.png) Click on **Install** to start the installation. You will see the requirement check page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p4-3.png) Click on **Continue.** You will see the database setup page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p5-2.png) Define your database host, user, and password, then click on **Continue.** You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p6-2.png) Select your existing database and click on **Continue.** You will see the database initialization page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p7-2.png) Click on **Continue.** You will see the collect data page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p8-2.png) Click on **Continue.** You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p9-1.png) Click on **Continue** to finish the installation. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p10-1.png) Click on **Use GLPI.** You will see the GLPI login page. ![](https://www.atlantic.net/wp-content/uploads/2024/04/g1.png)   Provide the default username and password as glpi, then click on **Sign in.** You will see the GLPI dashboard on the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/04/g2.png)   Finally, remove the installation directory using the following command. ``` rm -rf /var/www/glpi/install/install.php ``` ## Conclusion GLPI provides organizations with a robust solution for efficiently managing their IT assets and streamlining IT service operations. By leveraging the power of open-source software, users gain access to a comprehensive suite of features including inventory management, asset tracking, service desk capabilities, incident and change management, as well as customizable reporting and analytics. You can try to deploy the GLPI on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Deploy .NET Core Applications on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-deploy-net-core-applications-on-ubuntu-24-04/ | Published: 2024-04-18 | Updated: 2025-05-12 | Author: Hitesh Jethva Deploying .NET Core applications on Linux offers several compelling use cases and advantages, even though .NET Core is a Microsoft technology traditionally associated with Windows environments. Here are some key reasons why deploying .NET Core applications on Linux can be beneficial: - Cross-Platform Compatibility - Cost Efficiency - Performance and Scalability - Containerization and Orchestration - Open-Source Ecosystem - Security and Stability In this tutorial, we will explain how to install the .NET Core Application on Ubuntu 24.04. ## Step 1 – Install .NET SDK Before starting, you will need a .NET SDK for development purposes. Follow the below steps to install it. First, install the SNAP package manager. ``` apt install snap ``` Next, install the .NET SDK version 8 using the following command. ``` snap install dotnet-sdk --classic --channel=8.0 ``` Next, create a symbolic link to .NET SDK. ``` ln -s /snap/bin/dotnet-sdk.dotnet /usr/bin/dotnet ``` You can now verify the .NET version using the following command. ``` dotnet --version ``` Output: ``` 8.0.407 ``` ## Step 2 – Create an Application Using .NET First, create a new application named MyApp using the following command: ``` dotnet new webapp -o MyApp --no-https ``` Next, navigate inside the MyApp directory and build the application using the following command: ``` cd MyApp dotnet build ``` Output: ``` MSBuild version 17.9.6+a4ecab324 for .NET Determining projects to restore... All projects are up-to-date for restore. MyApp -> /root/MyApp/bin/Debug/net8.0/MyApp.dll Build succeeded. 0 Warning(s) 0 Error(s) Time Elapsed 00:00:05.98 ``` Next, publish a .NET application for production using the following command: ``` dotnet publish -c Release -o /var/www/ --runtime linux-x64 ``` It will publish your .NET application with the Release configuration, targeting the Linux x64 runtime, and output the published files to the /var/www/ directory. ## Step 3 – Create a Systemd File for .NET Application Next, you will need to create a systemd file to manage your .NET application. You can create it using the following command: ``` nano /etc/systemd/system/app.service ``` Add the following configuration: ``` [Unit] Description=My .NET Core Application [Service] WorkingDirectory=/var/www/ ExecStart=/usr/bin/dotnet /var/www/MyApp.dll Restart=always # Restart service after 10 seconds if the dotnet service crashes: RestartSec=10 KillSignal=SIGINT SyslogIdentifier=dotnet-example User=root Environment=ASPNETCORE_ENVIRONMENT=Production [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` Next, start your .NET application service using the following command: ``` systemctl start app ``` You can check the status of your application using the following command: ``` systemctl status app ``` Output: ``` ● app.service - My .NET Core Application Loaded: loaded (/etc/systemd/system/app.service; disabled; preset: enabled) Active: active (running) since Mon 2025-05-12 05:48:35 UTC; 3s ago Main PID: 33371 (dotnet) Tasks: 0 (limit: 4609) Memory: 36.0K (peak: 8.9M) CPU: 37ms CGroup: /system.slice/app.service ‣ 33371 /snap/dotnet-sdk/256/dotnet /var/www/MyApp.dll May 12 05:48:35 ubuntu systemd[1]: Started app.service - My .NET Core Application. ``` ## Step 4 – Configure Nginx for the .NET Application Next, you will need to configure Nginx as a reverse proxy to expose your application on port 80. First, install the Nginx web server. ``` apt install nginx ``` Next, create an Nginx virtual host configuration file. ``` nano /etc/nginx/conf.d/app.conf ``` Add the following configuration: ``` server { listen 80; server_name app.example.com; location / { proxy_pass http://localhost:5000; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection keep-alive; proxy_set_header Host $host; proxy_cache_bypass $http_upgrade; } } ``` Save and close the file, then edit the Nginx main configuration: ``` nano /etc/nginx/nginx.conf ``` Add the following lines below the line http{: ``` server_names_hash_bucket_size 64; client_max_body_size 20M; ``` Save the file, then restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 5 – Access .NET Application At this point, your .NET application is created with Nginx as a reverse proxy. You can now access it using the URL **http://app.example.com.** ![](https://www.atlantic.net/wp-content/uploads/2024/04/dot.png)   ## Conclusion In this tutorial, we explained how to deploy a .NET application on Ubuntu 24.04. By embracing Linux as a deployment platform for .NET Core applications, organizations can achieve greater flexibility, efficiency, and innovation in their software development and deployment processes. Try to deploy your .NET application on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Deploy Spring Boot Application on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-deploy-spring-boot-application-on-ubuntu-24-04/ | Published: 2024-04-19 | Updated: 2025-05-14 | Author: Hitesh Jethva A Spring Boot application is a Java-based web application built using the Spring Boot framework. Spring Boot is an open-source framework designed to simplify the process of creating production-grade, stand-alone Spring-based applications. It provides various features and conventions that streamline configuration, dependency management, and application deployment. In this tutorial, we will show you how to deploy spring boot application on Ubuntu 24.04. ## Step 1 – Install Java JDK Spring Boot requires Java to be installed on your server. You can install it using the following command: ``` apt install openjdk-17-jdk-headless -y ``` After the successful installation, verify the Java version using the following command: ``` java -version ``` Output: ``` openjdk version "17.0.15" 2025-04-15 OpenJDK Runtime Environment (build 17.0.15+6-Ubuntu-0ubuntu124.04) OpenJDK 64-Bit Server VM (build 17.0.15+6-Ubuntu-0ubuntu124.04, mixed mode, sharing) ``` ## Step 2 – Install Spring Boot CLI Spring Boot CLI (Command Line Interface) is a command-line tool provided by the Spring Boot framework for quickly developing and testing Spring Boot applications without needing to set up a full-fledged project structure. It allows developers to write, run, and test Spring Boot applications with minimal configuration. There are multiple ways to install Spring Boot CLI. In this section, we will install Spring Boot CLI using SDKMAN. First, install the Zip and Unzip utility. ``` apt install unzip zip ``` Next, install SDKMAN using the following command: ``` curl -s https://get.sdkman.io | bash ``` Output: ``` All done! You are subscribed to the STABLE channel. Please open a new terminal, or run the following in the existing one: source "/root/.sdkman/bin/sdkman-init.sh" Then issue the following command: sdk help Enjoy!!! ``` Next, source the new SDKMAN! shell from the terminal window. ``` source "/root/.sdkman/bin/sdkman-init.sh" ``` Next, install the Spring Boot CLI using SDK. ``` sdk install springboot ``` ## Step 3 – Create a Spring Boot Application In this section, we will create a simple “Hello World” Spring Boot application using Maven. First, install Gradle using the following command. ``` sdk install gradle 8.14 ``` Next, generate a simple Spring Boot project named “hello” in the “hello-world” directory, with Gradle as the build tool. ``` spring init --build=gradle --dependencies=web --name=hello hello-world --type=gradle-project ``` Next, edit the HelloApplication.java file. ``` nano ~/hello-world/src/main/java/com/example/hello_world/HelloApplication.java ``` Modify is as shown below: ``` package com.example.hello_world; import org.springframework.boot.SpringApplication; import org.springframework.boot.autoconfigure.SpringBootApplication; import org.springframework.web.bind.annotation.RestController; import org.springframework.web.bind.annotation.RequestMapping; @SpringBootApplication public class HelloApplication { public static void main(String[] args) { SpringApplication.run(HelloApplication.class, args); } } @RestController class Hello { @RequestMapping("/") String index() { return "Hello world"; } } ``` Save and close the file. Then, navigate inside your application directory and create a new build with the following command: ``` cd hello-world ./gradlew build ``` ## Step 4 – Run Spring Boot Application First, run the application without building the jar file to test it quickly. ``` gradle bootRun ``` If everything is fine, you will see the following output: ``` > Task :bootRun . ____ _ __ _ _ /\\ / ___'_ __ _ _(_)_ __ __ _ \ \ \ \ ( ( )\___ | '_ | '_| | '_ \/ _` | \ \ \ \ \\/ ___)| |_)| | | | | || (_| | ) ) ) ) ' |____| .__|_| |_|_| |_\__, | / / / / =========|_|==============|___/=/_/_/_/ :: Spring Boot :: (v3.4.5) ``` Press CTRL+C to stop the application. ## Step 5 – Create a Systemd File It is always a good idea to create a systemd file to manage a Spring Boot application. You can create it using the following command: ``` nano /etc/systemd/system/helloworld.service ``` Add the following lines: ``` [Unit] Description=Spring Boot HelloWorld After=syslog.target After=network.target[Service] User=root Type=simple [Service] ExecStart=/usr/bin/java -jar /root/hello-world/build/libs/hello-world-0.0.1-SNAPSHOT.jar Restart=always StandardOutput=syslog StandardError=syslog SyslogIdentifier=helloworld [Install] WantedBy=multi-user.target ``` Save the file, then reload the systemd daemon. ``` systemctl daemon-reload ``` Now, start the Spring Boot service using the following command. ``` systemctl start helloworld ``` To check your application running status, run: ``` systemctl status helloworld ``` Output: ``` ● helloworld.service - Spring Boot HelloWorld Loaded: loaded (/etc/systemd/system/helloworld.service; disabled; preset: enabled) Active: active (running) since Thu 2025-05-15 04:13:26 UTC; 5s ago Main PID: 29166 (java) Tasks: 24 (limit: 629145) Memory: 119.4M (peak: 138.5M) CPU: 5.486s CGroup: /system.slice/helloworld.service └─29166 /usr/bin/java -jar /root/hello-world/build/libs/hello-world-0.0.1-SNAPSHOT.jar ``` ## Step 6 – Configure Nginx as a Reverse Proxy You will also need to configure Nginx reverse proxy to implement the application as a web service. First, install the Nginx package. ``` apt install nginx -y ``` Next, create an Nginx virtual host: ``` nano /etc/nginx/conf.d/helloworld.conf ``` Add the following configuration: ``` server { listen 80; server_name helloworld.example.com; location / { proxy_pass http://localhost:8080/; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-Port $server_port; } } ``` Save the file and then edit the Nginx main configuration file: ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http{: ``` server_names_hash_bucket_size 64; ``` Save and close the file, then verify Nginx for any syntax errors. ``` nginx -t ``` Output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes. ``` systemctl restart nginx ``` ## Step 7 – Access Spring Boot Application At this point, your Spring Boot application is created with Nginx as a reverse proxy. You can now access it using the URL **http://helloworld.example.com.** ![](https://www.atlantic.net/wp-content/uploads/2024/03/p1-17.png) ## Conclusion The Spring Boot application empowers developers to confidently build and deploy robust, production-grade applications while optimizing resource utilization and enhancing the development workflow. You can easily create and deploy your Spring Boot application on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install CyberPanel on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-cyberpanel-on-ubuntu-22-04/ | Published: 2024-04-20 | Updated: 2024-05-14 | Author: Hitesh Jethva CyberPanel is a web hosting control panel designed to simplify the process of managing web hosting servers and websites. It provides an intuitive and user-friendly interface for managing various aspects of server and website administration, including website deployment, domain management, email configuration, database management, security settings, and more. Its ease of use, performance optimization features, security enhancements, and resource efficiency make it a valuable tool for users looking to streamline their server administration tasks and improve the reliability and performance of their websites. In this tutorial, we will show you how to install CyberPanel on Ubuntu 22.04. ## Step 1 – Set Up Hostname First, you will need to set up your system’s hostname. You can do this using the following command: ``` hostnamectl set-hostname cyber.example.com ``` Next, set your timezone using the following command: ``` timedatectl set-timezone UTC ``` Next, edit the /etc/hosts file and bind your server IP with your hostname. ``` nano /etc/hosts ``` Add the following line: ``` server-ip cyber.example.com ``` Save and close the file once you are finished. ## Step 2 – Install CyberPanel CyberPanel provides an installation script that automates the installation process. You can download it using the curl command: ``` curl -o cyberpanel_installer.sh https://cyberpanel.net/install.sh ``` Once the download is complete, make it executable using the following command: ``` chmod +x cyberpanel_installer.sh ``` Next, run the CyberPanel installer script to install the CyberPanel. ``` ./cyberpanel_installer.sh ``` Once the installation script starts, you’ll be prompted to install the CyberPanel. ``` CyberPanel Installer v2.3.5 1. Install CyberPanel. 2. Exit. Please enter the number[1-2]: 1 ``` Type **1** and press the **Enter** key. You will be asked to choose the web server. ``` CyberPanel Installer v2.3.5 RAM check : 182/1977MB (9.21%) Disk check : 2/50GB (7%) (Minimal 10GB free space) 1. Install CyberPanel with OpenLiteSpeed. 2. Install Cyberpanel with LiteSpeed Enterprise. 3. Exit. Please enter the number[1-3]: 1 ``` Type **1** to select the OpenListeSpeed web server and press the **Enter** key. You will be asked whether or not to proceed with a full installation. ``` Install Full service for CyberPanel? This will include PowerDNS, Postfix and Pure-FTPd. Full installation [Y/n]: Y ``` Type **Y** and press the **Enter** key. You will be asked whether to install remote MySQL. ``` Do you want to setup Remote MySQL? (This will skip installation of local MySQL) (Default = No) Remote MySQL [y/N]: N ``` Type **N** and press the **Enter** key. You will be asked whether to install Memcached. ``` Press Enter key to continue with latest version or Enter specific version such as: 1.9.4 , 2.0.1 , 2.0.2 ...etc Branch name set to v2.3.5 Please choose to use default admin password 1234567, randomly generate one (recommended) or specify the admin password? Choose [d]fault, [r]andom or [s]et password: [d/r/s] Admin password will be provided once installation is completed... Do you wish to install Memcached process and its PHP extension? Please select [Y/n]: Y ``` Type **Y** and press the **Enter** key. You will be asked whether to install Redis. ``` Install Memcached process and its PHP extension set to Yes... Do you wish to install Redis process and its PHP extension? Please select [Y/n]: n ``` Type **n** and press the **Enter** key. Once the installation has been completed successfully, you will see the following output: ``` Would you like to set up a WatchDog (beta) for Web service and Database service ? The watchdog script will be automatically started up after installation and server reboot If you want to kill the watchdog , run watchdog kill Please type Yes or no (with capital Y, default Yes): Install Watchdog set to Yes... Installation time : 0 hrs 16 min 0 sec Visit: https://49.13.163.2:8090 Panel username: admin Panel password: ***** Run cyberpanel help to get FAQ info Run cyberpanel upgrade to upgrade it to latest version. Run cyberpanel utility to access some handy tools . Website : https://www.cyberpanel.net Forums : https://forums.cyberpanel.net Wikipage: https://docs.cyberpanel.net Docs : https://cyberpanel.net/docs/ Enjoy your accelerated Internet by CyberPanel & OpenLiteSpeed ################################################################### If your provider has a network-level firewall Please make sure you have opened following port for both in/out: TCP: 8090 for CyberPanel TCP: 80, TCP: 443 and UDP: 443 for webserver TCP: 21 and TCP: 40110-40210 for FTP TCP: 25, TCP: 587, TCP: 465, TCP: 110, TCP: 143 and TCP: 993 for mail service TCP: 53 and UDP: 53 for DNS service Agree to reboot the server after installations. ``` In the final step, you will be asked whether to restart your server. ``` Would you like to restart your server now? [y/N]: y ``` Type **y** and press the **Enter** key to restart your server. ## Step 3 – Access CyberPanel CyberPanel is now installed and configured. Now, open your web browser and access the CyberPanel web interface using the URL **https://your-server-ip:8090.** You will see the CyberPanel login page: ![](https://www.atlantic.net/wp-content/uploads/2024/04/p1-5.png) Enter the default username and password as admin/admin and press the **Sign in** button. You will see the CyberPanel dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/04/p2-5.png) ## Conclusion Following the step-by-step installation guide outlined in this article, users can quickly deploy CyberPanel on their Ubuntu servers and access a comprehensive suite of website hosting, email management, security, and more features. With CyberPanel, users can enjoy benefits such as performance optimization, ease-of-use, resource efficiency, and built-in security features. The intuitive interface of CyberPanel makes it accessible to users of all skill levels, while its robust feature set caters to the needs of both individual website owners and hosting providers. You can now deploy your website control panel on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How To Install OpenSearch on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-opensearch-on-ubuntu-24-04/ | Published: 2024-04-21 | Updated: 2025-05-11 | Author: Hitesh Jethva OpenSearch is an open-source search engine technology that enables users to build and deploy their search solutions. It’s developed as a community-driven project and is based on Elasticsearch, a distributed search and analytics engine. OpenSearch empowers users to build and deploy powerful search solutions that meet their specific needs, whether it’s searching through large datasets, analyzing real-time data streams, or building custom search applications. Its flexibility, scalability, and community-driven development make it a valuable tool for various use cases across industries. This tutorial will show you how to install OpenSearch on Ubuntu 24.04. ## Step 1 – Add OpenSearch Repository OpenSearch package is not included in the Ubuntu 24.04 default repository. So, you will need to add OpenSearch repository to your server. First, install the required dependencies. ``` apt -y install curl lsb-release gnupg2 ca-certificates ``` Next, import the GPG key to sign the OpenSearch packages. ``` curl -fsSL https://artifacts.opensearch.org/publickeys/opensearch.pgp| gpg --dearmor -o /etc/apt/trusted.gpg.d/opensearch.gpg ``` Next, add the OpenSearch repository to your system. ``` echo "deb https://artifacts.opensearch.org/releases/bundle/opensearch/2.x/apt stable main" | tee /etc/apt/sources.list.d/opensearch-2.x.list ``` Update the package lists to reflect the changes you made to the repository sources: ``` apt update -y ``` ## Step 2 – Install and Configure OpenSearch To install OpenSearch with an initial admin password set, you can use environment variables during the installation process. Here’s the command to install OpenSearch with the initial admin password set: ``` env OPENSEARCH_INITIAL_ADMIN_PASSWORD=Your1982_Something@Secure apt install opensearch ``` This command sets the initial admin password for OpenSearch to “Your1982_Something@Secure” during the installation process. Replace “Your1982_Something@Secure” with your desired password. Next, edit the OpenSearch default configuration file. ``` nano /etc/opensearch/opensearch.yml ``` Change the default values as per your requirements: ``` cluster.name: ocluster1 network.host: 0.0.0.0 http.port: 9200 discovery.type: single-node node.name: ${HOSTNAME} plugins.security.disabled: false plugins.security.ssl.http.enabled: false ``` Save and close the file, then reload the systemd daemon. ``` systemctl daemon-reload ``` Next, restart the OpenSearch service to apply the changes. ``` systemctl restart opensearch ``` You can check the status of OpenSearch using the following command: ``` systemctl status opensearch ``` Output: ``` ● opensearch.service - OpenSearch Loaded: loaded (/usr/lib/systemd/system/opensearch.service; disabled; preset: enabled) Active: active (running) since Mon 2025-05-12 03:44:10 UTC; 16s ago Docs: https://opensearch.org/ Main PID: 19669 (java) Tasks: 61 (limit: 4609) Memory: 1.3G (peak: 1.3G) CPU: 36.407s CGroup: /system.slice/opensearch.service ``` ## Step 3 – Install OpenSearch Dashboard The OpenSearch Dashboard, also known as the OpenSearch Kibana, is a web-based interface that allows users to interact with OpenSearch clusters, visualize data, and perform various data analysis tasks. It provides a user-friendly environment for exploring and analyzing data stored in OpenSearch. First, add the OpenSearch Dashboard repository. ``` echo "deb https://artifacts.opensearch.org/releases/bundle/opensearch-dashboards/2.x/apt stable main" | tee -a /etc/apt/sources.list.d/opensearch-2.x.list ``` Next, update the repository index and install the OpenSearch Dashboard. ``` apt update apt install opensearch-dashboards ``` Next, edit the OpenSearch Dashboard configuration file. ``` nano /etc/opensearch-dashboards/opensearch_dashboards.yml ``` Change the following settings: ``` server.host: "0.0.0.0" server.ssl.enabled: false opensearch.hosts: ["http://localhost:9200"] ``` Save and close the file, then restart the OpenSearch Dashboard service. ``` systemctl restart opensearch-dashboards ``` Check the OpenSearch Dashboard service status. ``` systemctl status opensearch-dashboards ``` Output: ``` ● opensearch-dashboards.service - "OpenSearch Dashboards" Loaded: loaded (/usr/lib/systemd/system/opensearch-dashboards.service; disabled; preset: enabled) Active: active (running) since Mon 2025-05-12 03:47:41 UTC; 2s ago Main PID: 20663 (node) Tasks: 11 (limit: 4609) Memory: 132.7M (peak: 132.7M) CPU: 2.772s CGroup: /system.slice/opensearch-dashboards.service └─20663 /usr/share/opensearch-dashboards/node/bin/node /usr/share/opensearch-dashboards/src/cli/dist May 12 03:47:41 ubuntu systemd[1]: Started opensearch-dashboards.service - "OpenSearch Dashboards". ``` ## Step 4 – Access OpenSearch Dashboard By default, OpenSearch Dashboard listens on port 5601. You can access it using the URL **http://your-server-ip:5601.** You will see the OpenSearch Dashboard login page. ![](https://www.atlantic.net/wp-content/uploads/2024/04/login.png)   Provide the OpenSearch Dashboard default username as a **admin** and password as **Your1982_Something@Secure**which you set earlier, then click on **Login.** You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/04/p2-4.png) Click on **Dismiss.** You will see the tenant selection page. ![](https://www.atlantic.net/wp-content/uploads/2024/04/p3-3.png) Select your tenant and click on **Confirm.** You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/04/p4-4.png) Click on **Explore on my own.** You will see the OpenSearch Dashboard on the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/04/p5-3.png) ## Conclusion Through the step-by-step installation process outlined in this guide, you’ve gained the necessary knowledge to set up OpenSearch on your Ubuntu system efficiently. With OpenSearch, you can harness the capabilities of a robust search and analytics engine, enabling you to index, search, and visualize data effectively. Whether you’re managing log data, monitoring system metrics, or conducting complex data analysis tasks, OpenSearch offers the flexibility and scalability to meet your needs. Try to deploy OpenSearch on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Django on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-django-on-ubuntu-22-04/ | Published: 2024-04-22 | Updated: 2024-05-07 | Author: Hitesh Jethva Django is a high-level Python web framework that encourages rapid development and clean, pragmatic design. It follows the Model-View-Controller (MVC) architectural pattern, although it’s often referred to as a Model-View-Template (MVT) framework because it technically uses templates rather than views. Its emphasis on simplicity, flexibility, and scalability makes it a popular choice among developers for web development projects. In this tutorial, we will show you how to install the Django framework on Ubuntu 22.04. ## Step 1 – Install Required Dependencies Before starting, you will need to install the latest version of Python and additional packages on your server. First, install the software-properties-common package. ``` apt install software-properties-common -y ``` Then, add the Python repository. ``` add-apt-repository ppa:deadsnakes/ppa -y ``` Next, update the repository cache and install the latest version of Python using the following command: ``` apt update apt install python3.10 -y ``` After the installation, you can verify the Python installation using the following command: ``` python3 --version ``` Output: ``` Python 3.10.12 ``` Next, install some additional packages using the following command: ``` apt install python3-pip python3.10-venv -y ``` ## Step 2 – Install Django First, navigate to the /opt directory and create a Python virtual environment. ``` cd /opt python3 -m venv django-venv ``` Next, activate the Python virtual environment. ``` source django-venv/bin/activate ``` Then install the Django using the PIP command: ``` pip3 install django ``` After the installation, you can verify the Django version using the following command: ``` django-admin --version ``` Output: ``` 5.0.3 ``` ## Step 3 – Create a Django Project Now, create a new Django project using the django-admin command: ``` django-admin startproject djangoproject . ``` Once the Django project is created, you can list all files and directories using the following command: ``` ls ``` Output: ``` djangoproject django-venv manage.py ``` Next, migrate the Django database using the command below: ``` python3 manage.py migrate ``` ## Step 4 – Create a Django Superuser Next, you will need to create a superuser to manage the Django admin dashboard. You can create it using the following command: ``` python3 manage.py createsuperuser ``` Set your admin user and password as shown below: ``` Username (leave blank to use 'root'): admin Email address: admin@example.com Password: Password (again): Superuser created successfully. ``` ## Step 5 – Start Django Project First, edit the Django configuration file and add your server IP in the allowed host. ``` nano djangoproject/settings.py ``` Change the following line: ``` ALLOWED_HOSTS = ['your-server-ip'] ``` Save and close the file, and then start your Django project using the following command: ``` python3 manage.py runserver your-server-ip:8000 ``` You will see the following output: ``` Watching for file changes with StatReloader Performing system checks... System check identified no issues (0 silenced). March 24, 2024 - 07:50:10 Django version 5.0.3, using settings 'djangoproject.settings' Starting development server at http://209.23.12.27:8000/ Quit the server with CONTROL-C. ``` ## Step 6 – Access Django Project At this point, your Django project is started and listening on port **8000.** You can now access it using the URL **http://your-server-ip:8000.** You will see the Django dashboard on the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p1-15.png) You can also access your Django admin dashboard using the URL **http://your-server-ip:8000/admin.** ## Conclusion By following the steps outlined in this guide, you can quickly set up Django and start building powerful web applications with ease. Whether you’re a seasoned developer or just starting, Django’s robust framework and extensive documentation make it a valuable tool for any project. You can now test the Django application on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Kubernetes Dashboard Using Helm > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-kubernetes-dashboard-using-helm/ | Published: 2024-04-23 | Updated: 2024-06-02 | Author: Hitesh Jethva Kubernetes Dashboard is a web-based user interface that allows users to manage and monitor Kubernetes clusters. It provides a graphical interface for performing common Kubernetes tasks, such as deploying applications, inspecting resources, and troubleshooting issues. Kubernetes Dashboard makes it easier for users to interact with and control their containerized applications and infrastructure. It is especially useful for users who prefer a graphical interface over command-line tools or who are new to Kubernetes and want an intuitive way to get started. In this tutorial, we will show you how to install Kubernetes Dashboard using Helm on Ubuntu 22.04. ## Prerequisites - A server running Ubuntu 22.04 with Kubernetes installed ## Step 1 – Add Kubernetes Dashboard Repo Helm is not included by default in the Ubuntu default repo, so you will need to install it using a script. First, download the Helm installation script. ``` curl -fsSL -o get_helm.sh https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 ``` Next, make the downloaded script executable. ``` chmod 700 get_helm.sh ``` Next, run the script to install Helm. ``` ./get_helm.sh ``` Next, add the Kubernetes Dashboard repo using Helm. ``` helm repo add kubernetes-dashboard https://kubernetes.github.io/dashboard/ ``` You can verify the added repo using the following command: ``` helm repo list ``` Output: ``` NAME URL kubernetes-dashboard https://kubernetes.github.io/dashboard/ ``` ## Step 2 – Install Kubernetes Dashboard Using Helm Now you can install Kubernetes Dashboard chart using Helm. You may want to specify a release name and namespace during installation. ``` helm upgrade --install kubernetes-dashboard kubernetes-dashboard/kubernetes-dashboard --create-namespace --namespace kubernetes-dashboard ``` Output: ``` ************************************************************************************************* *** PLEASE BE PATIENT: Kubernetes Dashboard may need a few minutes to get up and become ready *** ************************************************************************************************* Congratulations! You have just installed Kubernetes Dashboard in your cluster. To access Dashboard run: kubectl -n kubernetes-dashboard port-forward svc/kubernetes-dashboard-kong-proxy 8443:443 NOTE: In case port-forward command does not work, make sure that kong service name is correct. Check the services in Kubernetes Dashboard namespace using: kubectl -n kubernetes-dashboard get svc Dashboard will be available at: https://localhost:8443 ``` Once Kubernetes Dashboard is installed, you can verify it using the following command: ``` kubectl get svc -n kubernetes-dashboard ``` Output: ``` NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE kubernetes-dashboard-web ClusterIP 10.43.128.204 8000/TCP 12m kubernetes-dashboard-kong-manager NodePort 10.43.163.11 8002:32281/TCP,8445:31992/TCP 12m kubernetes-dashboard-auth ClusterIP 10.43.141.160 8000/TCP 12m kubernetes-dashboard-metrics-scraper ClusterIP 10.43.159.40 8000/TCP 12m kubernetes-dashboard-api ClusterIP 10.43.8.225 8000/TCP 12m kubernetes-dashboard-kong-proxy ClusterIP 10.43.208.190 443/TCP 12m ``` ## Step 3 – Generate Token for Kubernetes Dashboard Now, you will need to generate a token to access Kubernetes Dashboard. First, create a Kubernetes manifest file to create a service account. ``` nano k8s-dashboard-account.yaml ``` Add the following content: ``` apiVersion: v1 kind: ServiceAccount metadata: name: admin-user namespace: kube-system --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: admin-user roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: cluster-admin subjects: - kind: ServiceAccount name: admin-user namespace: kube-system ``` Next, apply the above configuration to the Kubernetes cluster. ``` kubectl create -f k8s-dashboard-account.yaml ``` Next, generate a token using the following command: ``` kubectl -n kube-system create token admin-user ``` Output: ``` eyJhbGciOiJSUzI1NiIsImtpZCI6IkIwbk5FWE0zVXppQV9aVWEyMndzRlNnMllIREpldUdVckVZdzFqUzcwalEifQ.eyJhdWQiOlsiaHR0cHM6Ly9rdWJlcm5ldGVzLmRlZmF1bHQuc3ZjLmNsdXN0ZXIubG9jYWwiLCJrM3MiXSwiZXhwIjoxNzExMTcwMjQwLCJpYXQiOjE3MTExNjY2NDAsImlzcyI6Imh0dHBzOi8va3ViZXJuZXRlcy5kZWZhdWx0LnN2Yy5jbHVzdGVyLmxvY2FsIiwia3ViZXJuZXRlcy5pbyI6eyJuYW1lc3BhY2UiOiJrdWJlLXN5c3RlbSIsInNlcnZpY2VhY2NvdW50Ijp7Im5hbWUiOiJhZG1pbi11c2VyIiwidWlkIjoiNTNhNjdhNjYtNDAyOC00MTFlLWI5YTctMzViZDJkYzUwOTc2In19LCJuYmYiOjE3MTExNjY2NDAsInN1YiI6InN5c3RlbTpzZXJ2aWNlYWNjb3VudDprdWJlLXN5c3RlbTphZG1pbi11c2VyIn0.XrTJC9WhaZrhRuo2buBXy48AnaGxsjHcLNCZpjpcXF5UQagR3GQgCpyArWWuGaw8Wu_-bCzHknsZ1oQ4kDLnwCrtgnG3bg18axuodvydMivw2iETtEZNTRJF989amM8fdO3xSQgNh9O59UjiebUtNNQ45d2Rmzxq1VoVpsL0hx9D0WIg-7iUZ305OKjufIBWx0nW_VBRaBE4kLWj3t7ykJdIE9qE0s12s7XjUnLvA1DWFWC_SoG08q8q4Y0LdThKz8wzVI87DR4KTlTTuSPJEZkI5hcZu02SkKaleNBYnFlabBD1IWXK18uY_5LAIFrjDgkCPUysCbAA_7F87dZ4sg ``` ## Step 4 – Access Kubernetes Dashboard To access Kubernetes Dashboard from the outside network, you will need to expose it using the port forward method. Run the following command to expose Kubernetes Dashboard. ``` kubectl port-forward -n kubernetes-dashboard service/kubernetes-dashboard-kong-proxy 10443:443 --address 0.0.0.0 & ``` You will see the following output: ``` Forwarding from 0.0.0.0:10443 -> 8443 ``` Now, open your web browser and access Kubernetes Dashboard using the URL **https://server-ip:10443.** You will be asked to enter a token to log in. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p1-14.png) Provide your generated token and click on **Sign in.** You will see Kubernetes Dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p2-12.png) ## Conclusion In this guide, you learned how to install Kubernetes Dashboard using Helm on Ubuntu 22.04. You can now manage and monitor Kubernetes pods, services, and logs via Kubernetes Dashboard. You can now start managing your Kubernetes cluster using Kubernetes Dashboard on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Kubernetes Using K3s On Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-kubernetes-using-k3s-on-ubuntu-24-04/ | Published: 2024-04-24 | Updated: 2025-05-27 | Author: Hitesh Jethva K3s is a lightweight, easy-to-install distribution of Kubernetes designed for resource-constrained environments, such as edge computing, IoT devices, and development/testing environments. It is developed by Rancher Labs, an organization known for its Kubernetes management platform. In this tutorial, we will show you how to install Kubernetes using K3s on Ubuntu 24.04. ## Step 1 – Install K3s First, install the curl package for a smooth K3s installation. ``` apt install curl -y ``` Next, use the curl command to download and run the K3s installation script. ``` curl -sfL https://get.k3s.io | sh - ``` Once K3s has been installed, you can verify the K3s service using the following command. ``` systemctl status k3s ``` Output: ``` ● k3s.service - Lightweight Kubernetes Loaded: loaded (/etc/systemd/system/k3s.service; enabled; preset: enabled) Active: active (running) since Tue 2025-05-27 07:04:59 UTC; 2s ago Docs: https://k3s.io Process: 23962 ExecStartPre=/bin/sh -xc ! /usr/bin/systemctl is-enabled --quiet nm-cloud-setup.service 2>/dev/null (code=exited, status=0/SUCCESS) Process: 23964 ExecStartPre=/sbin/modprobe br_netfilter (code=exited, status=0/SUCCESS) Process: 23968 ExecStartPre=/sbin/modprobe overlay (code=exited, status=0/SUCCESS) Main PID: 23975 (k3s-server) Tasks: 20 Memory: 464.0M (peak: 465.0M) CPU: 11.019s CGroup: /system.slice/k3s.service ├─23975 "/usr/local/bin/k3s server" └─23996 "containerd " ``` ## Step 2 – Access Kubernetes Cluster You will need to configure kubectl to access and interact with the Kubernetes cluster via the command line. First, create a directory to store kubectl configuration. ``` mkdir ~/.kube ``` Next, copy the Kubernetes configuration file inside the .kube directory. ``` cp /etc/rancher/k3s/k3s.yaml ~/.kube/config chmod 600 ~/.kube/config ``` Next, expose the path of the kubectl configuration file. ``` export KUBECONFIG=~/.kube/config ``` Next, verify the Kubernetes cluster nodes using the kubectl command. ``` kubectl get nodes ``` Output. ``` NAME STATUS ROLES AGE VERSION ubuntu24 Ready control-plane,master 51s v1.32.5+k3s1 ``` You can also see the Kubernetes cluster information using the following command. ``` kubectl cluster-info ``` Output: ``` Kubernetes control plane is running at https://127.0.0.1:6443 CoreDNS is running at https://127.0.0.1:6443/api/v1/namespaces/kube-system/services/kube-dns:dns/proxy Metrics-server is running at https://127.0.0.1:6443/api/v1/namespaces/kube-system/services/https:metrics-server:https/proxy ``` ## Step 3 – Create an Nginx Deployment To validate the Kubernetes installation, we will deploy a Nginx-based application and expose it via NodePort. First, create an Nginx deployment using the following command. ``` kubectl create deployment nginx-app --image nginx --replicas 2 ``` Next, verify the Nginx deployment using the following command. ``` kubectl get deployment nginx-app ``` Output. ``` NAME READY UP-TO-DATE AVAILABLE AGE nginx-app 2/2 2 2 10s ``` Next, verify the Nginx pods using the following command. ``` kubectl get pods ``` Output: ``` NAME READY STATUS RESTARTS AGE nginx-app-5777b5f95-lhcpp 1/1 Running 0 22s nginx-app-5777b5f95-2j6ld 1/1 Running 0 22s ``` Next, expose the nginx-app deployment using NodePort. ``` kubectl expose deployment nginx-app --type NodePort --port 80 ``` Next, get the IP address of nginx-app using the following command: ``` kubectl get svc nginx-app ``` Output: ``` NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE nginx-app NodePort 10.43.162.54 80:31588/TCP 5s ``` Now, use the IP address from the above output and run the curl command to access the nginx-app. ``` curl http://10.43.162.54 ``` If everything is fine, you will see the following output: ``` Welcome to nginx!

Welcome to nginx!

If you see this page, the nginx web server is successfully installed and working. Further configuration is required.

For online documentation and support please refer to nginx.org.
Commercial support is available at nginx.com.

Thank you for using nginx.

``` ## Conclusion Overall, K3s offers a compelling solution for scenarios where a full-fledged Kubernetes deployment may be impractical or overly resource-intensive. Its lightweight design, ease of installation, and focus on security make it an attractive choice for edge computing, IoT deployments, and development/testing environments. You can now easily deploy Kubernetes cluster using K3s on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Atlantic.Net Wins Bronze Stevie® Award at 2024 American Business Awards® > URL: https://www.atlantic.net/press-releases/atlantic-net-wins-bronze-stevie-award-at-2024-american-business-awards/ | Published: 2024-04-25 | Updated: 2024-06-05 | Author: Alexander Wise ORLANDO, Fla. – April 25, 2024 – Atlantic.Net announced today that they have been awarded a Bronze Stevie® Award for Infrastructure as a Service in the 22nd Annual American Business Awards®. This recognition highlights Atlantic.Net’s commitment to excellence and innovation in providing the very best Infrastructure-as-a-Service offering to our customers. The American Business Awards are the premier business awards program in the U.S., recognizing outstanding achievements across various industries. With over 3,700 nominations this year, the competition was tough, making Atlantic.Net’s Bronze Stevie win a significant accomplishment. “We are delighted to receive this recognition from the Stevie Awards,” said Marty Puranik, CEO of Atlantic.Net. “This award showcases the continued hard work and dedication of our teams. Everyone consistently strives to deliver exceptional cloud solutions and class-leading support to our customers. We remain committed to pushing the boundaries of innovation and providing secure, reliable, and high-performing cloud services for everyone.” Atlantic.Net, a leading global provider of cloud services, managed services, and VPS hosting, was evaluated by a panel of over 300 professionals worldwide. The panel recognized the company’s dedication to quality, customer service, and technological advancement. This Bronze Stevie Award further solidifies Atlantic.Net’s position as a cloud hosting and infrastructure service industry leader. “We are delighted to acknowledge the wide range of American organizations in The 2024 American Business Awards,” stated Michael Gallagher, founder and Executive Chairman of the Stevie Awards. “This year, we witnessed a surge in nominations in categories like Product Innovation, Innovation of the Year across diverse industries, and Technology Categories, mirroring the influence of new and emerging technologies shaping our nation. We look forward to honoring the achievements of Stevie winners on June 11th in New York City.” **About the Stevie Awards** Stevie Awards are conferred in nine programs: the Asia-Pacific Stevie Awards, the German Stevie Awards, the Middle East & North Africa Stevie Awards, The American Business Awards®, The International Business Awards®, the Stevie Awards for Great Employers, the Stevie Awards for Women in Business, the Stevie Awards for Sales & Customer Service, and the new Stevie Awards for Technology Excellence. Stevie Awards competitions receive more than 12,000 entries annually from organizations in more than 70 nations. Honoring organizations of all types and sizes and the people behind them, the Stevies recognize outstanding performances in the workplace worldwide. Learn more about the Stevie Awards at [Stevie Awards](https://www.stevieawards.com). **About Atlantic.Net** Atlantic.Net is a globally recognized cloud services provider emphasizing security, compliance, and simplifying complex tech setups. With over 30 years of experience, we’re dedicated to offering developers and IT leaders at companies of all sizes a variety of customizable, on-demand, and budget-friendly cloud solutions tailored to their specific needs. Atlantic.Net, Inc. Media Inquiries Contact: Email: [pr@atlantic.net](mailto:pr@atlantic.net) Ph: 1-321- 206-1371 --- # How to Install TYPO3 CMS on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-typo3-cms-on-ubuntu-22-04/ | Published: 2024-04-25 | Updated: 2024-05-07 | Author: Hitesh Jethva TYPO3 CMS is an open-source “Content Management System” used for building and managing websites, web applications, and digital experiences. It is written in PHP and is known for its flexibility, scalability, and extensive feature set. TYPO3 CMS is particularly popular among enterprises, large organizations, and institutions due to its robustness and capability to handle complex web projects. In this tutorial, we will explain how to install TYPO3 CMS on Ubuntu 22.04. ## Step 1 – Install Apache, MariaDB, and PHP First, install Apache, MariaDB, PHP and other PHP dependencies using the following command: ``` apt install apache2 mariadb-server php libapache2-mod-php php-cli php-common php-gmp php-curl php-mysql php-json php-intl php-mbstring php-xmlrpc php-gd php-xml php-zip php-imap ``` Next, edit the PHP configuration file. ``` nano /etc/php/8.1/apache2/php.ini ``` Change the following setting value as shown below: ``` max_execution_time = 240 memory_limit = 256M upload_max_filesize = 64M post_max_size = 64M max_input_vars = 1500 date.timezone = UTC ``` Save and close the file, then restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` ## Step 2 – Configure MariaDB Database TYPO3 stores data in the MariaDB database; therefore, you will need to create a database and user for TYPO3 CMS. First, connect to the MariaDB shell. ``` mysql ``` Once you are connected, create a database and user for TYPO3. ``` CREATE DATABASE typo3db; CREATE USER 'typo3user'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all privileges to the TYPO3 database. ``` GRANT ALL PRIVILEGES ON typo3db.* TO 'typo3user'@'localhost'; ``` Next, flush the privileges and exit from the MariaDB shell. ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install TYPO3 CMS First, download the latest version of TYPO3 CMS using the following command. ``` wget --content-disposition https://get.typo3.org/11.5.12 ``` Next, extract the downloaded file inside the Apache root directory. ``` tar -xvzf typo3_src-11.5.12.tar.gz -C /var/www/html ``` Next, change the directory to Apache web root and rename the extracted directory. ``` cd /var/www/html mv typo3_src-11.5.12 typo3 ``` Next, create a file to install TYPO3 CMS. ``` touch /var/www/html/typo3/FIRST_INSTALL ``` Next, give the necessary permission and ownership to the TYPO3 CMS directory. ``` chown -R www-data:www-data typo3 chmod -R 775 typo3 ``` ## Step 4 – Configure Apache for TYPO3 CMS First, create an Apache virtual host configuration file for TYPO3 CMS. ``` nano /etc/apache2/sites-available/typo3.conf ``` Add the following content: ``` ServerAdmin admin@your_domain.com DocumentRoot /var/www/html/typo3 ServerName typo3.example.com Options FollowSymlinks AllowOverride All Require all granted ErrorLog ${APACHE_LOG_DIR}/typo3_error.log CustomLog ${APACHE_LOG_DIR}/typo3_access.log combined ``` Save and close the file, then activate the Apache virtual host and enable the Apache rewrite module using the following command: ``` a2ensite typo3 a2enmod rewrite ``` Finally, restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` ## Step 5 – Access TYPO3 CMS Web UI Now, open your web browser and access the TYPO3 CMS web installation using the URL **http://typo3.example.com.** You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/03/p1-13.png) Click on **No problem detected, continue with installation**. You will see the database configuration page: ![](https://www.atlantic.net/wp-content/uploads/2024/03/p2-11.png) Define your database username and password and click on **Continue.** You will see the database selection page: ![](https://www.atlantic.net/wp-content/uploads/2024/03/p3-9.png) Select your existing database and click on **Continue.** You will see the administartor configuration page: ![](https://www.atlantic.net/wp-content/uploads/2024/03/p4-7.png) Define your admin username, password, and sitename, and click on **Continue.** Once the installation has been completed, you will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/03/p5-6.png) Select **Take me straight to backend** and click on **Open the TYPO3 Backend**. You will see the TYPO3 login page: ![](https://www.atlantic.net/wp-content/uploads/2024/03/p6-7.png) Provide your admin username and password and click on **Login.** You will see the TYPO3 CMS dashboard: ![](https://www.atlantic.net/wp-content/uploads/2024/03/p7-7.png) ## Conclusion Using TYPO3 CM, users can create powerful and versatile websites and digital experiences. With its robust feature set, flexibility, and scalability, TYPO3 CMS is a leading choice for enterprises, organizations, and developers looking to build sophisticated web projects. You can install TYPO3 CMS on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install phpBB on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-phpbb-on-ubuntu-22-04/ | Published: 2024-04-26 | Updated: 2024-06-01 | Author: Hitesh Jethva phpBB, which stands for “PHP Bulletin Board,” is an open-source internet forum software written in the PHP programming language. It allows users to create and manage online discussion forums where participants can post messages, engage in discussions, share files, and interact with each other. It provides a platform for communities to communicate, collaborate, and exchange information on various topics of interest. In this tutorial, we will show you how to install phpBB forum on Ubuntu 22.04. ## Step 1 – Install LAMP Server Before starting, you will need to install a LAMP server on your server. You can install it using the following command. ``` apt install apache2 mariadb-server php libapache2-mod-php php-gd php-curl openssl php-imagick php-intl php-json php-ldap php-common php-mbstring php-mysql php-imap php-sqlite3 php-net-ftp php-zip unzip php-pgsql php-ssh2 php-xml wget unzip -y ``` Once the LAMP server is installed, start and enable Apache and MariaDB services. ``` systemctl start apache2 systemctl start mariadb systemctl enable apache2 systemctl enable mariadb ``` ## Step 2 – Create a Database for phpBB phpBB uses MariaDB as a database backend, so you will need to create a database and user for phpBB. First, connect to the MariaDB server console: ``` mysql ``` Next, create a database and user: ``` CREATE DATABASE phpdb; GRANT ALL ON phpdb.* to 'phpbb'@'localhost' IDENTIFIED BY 'password'; ``` Next, flush the privileges and exit from the MariaDB shell. ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install phpBB Ubuntu 22.04 First, visit the phpBB download page, copy the URL of the latest phpBB, and download it using the following command. ``` wget https://download.phpbb.com/pub/release/3.3/3.3.7/phpBB-3.3.7.zip ``` Once the download is completed, unzip the downloaded file using the following command. ``` unzip phpBB-3.3.7.zip ``` Next, move the extracted directory to the Apache web root directory. ``` mv phpBB3 /var/www/html/phpbb ``` Next, set proper permissions and ownership. ``` chown -R www-data:www-data /var/www/html/phpbb chmod -R 775 /var/www/html/phpbb ``` ## Step 4 – Create an Apache Virtual Host for phpBB Next, you will need to create an Apache virtual host configuration file to host phpBB on the web. ``` nano /etc/apache2/sites-available/phpbb.conf ``` Add the following configuration: ``` ServerAdmin admin@example.com DocumentRoot /var/www/html/phpbb ServerName phpbb.example.com Options FollowSymlinks AllowOverride All Require all granted ErrorLog ${APACHE_LOG_DIR}/phpbb_error.log CustomLog ${APACHE_LOG_DIR}/phpbb_access.log combined ``` Save the file, then activate the Apache virtual host and rewrite the module using the following command: ``` a2ensite phpbb a2enmod rewrite ``` Finally, restart the Apache service to apply the changes. ``` systemctl restart apache2 ``` ## Step 5 – Access phpBB Web Interface Now, open your web browser and access the phpBB web interface using the URL **http://phpbb.example.com.** You will see the phpBB overview page: ![](https://www.atlantic.net/wp-content/uploads/2024/03/p1-12.png) Click on the **INSTALL** tab. You will see the Installation Welcome page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p2-10.png) Click on **Install.** You will see the administration configuration page: ![](https://www.atlantic.net/wp-content/uploads/2024/03/p3-8.png) Provide your admin username and password and click on **Submit.** You will see the database configuration page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p5-5.png) Provide your database user, password, and database, and click on **Submit.** You will see the server configuration page: ![](https://www.atlantic.net/wp-content/uploads/2024/03/p6-6.png) Provide all the required details and click on **Submit.** You will see the email configuration page: ![](https://www.atlantic.net/wp-content/uploads/2024/03/p7-6.png) Provide all necessary configurations and click on **Submit.** You will see the board configuration page: ![](https://www.atlantic.net/wp-content/uploads/2024/03/p8-4.png) Provide your board name and description and click on **Submit.** You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/03/p9-2.png) Click on **Take me to the ACP**. You will be redirected to the phpBB dashboard. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p10-2.png) ## Conclusion phpBB offers powerful online communities and discussion platforms to end users. With its user-friendly interface and extensive feature set, phpBB empowers users to create, customize, and manage forums tailored to their needs and preferences. You can now test phpBB on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install PHP 8.4 on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-php-8-4-on-ubuntu-24-04/ | Published: 2024-04-27 | Updated: 2025-05-10 | Author: Hitesh Jethva PHP (Hypertext Preprocessor) is a widely used open-source scripting language that is particularly well-suited for web development and can be embedded into HTML. With the release of PHP 8.4, developers gain access to new features, performance enhancements, and bug fixes that can significantly improve their web applications. However, upgrading PHP on your Ubuntu 24.04 server requires careful attention to ensure a smooth transition. In this guide, we’ll walk you through the process of installing PHP 8.4 on Ubuntu 24.04. ## Step 1 – Add PHP Repository To install PHP 8.4 on Ubuntu 24.04, you’ll need to add a repository containing PHP 8.4 packages and install PHP along with any necessary extensions. First, install all the necessary dependencies: ``` apt install curl gpg gnupg2 software-properties-common ca-certificates apt-transport-https lsb-release -y ``` Ondřej Surý maintains a repository with updated PHP versions for Ubuntu. Add this repository to your system: ``` add-apt-repository ppa:ondrej/php ``` Update the package index. ``` apt update -y ``` ## Step 2 – Install PHP 8.4 Now, you can install the PHP 8.4 using the following command: ``` apt -y install php8.4 ``` After successful installation, you can verify the PHP version using the following command: ``` php --version ``` Output: ``` PHP 8.4.7 (cli) (built: May 9 2025 06:54:31) (NTS) Copyright (c) The PHP Group Zend Engine v4.4.7, Copyright (c) Zend Technologies with Zend OPcache v8.4.7, Copyright (c), by Zend Technologies ``` ## Step 3 – Install Additional PHP Extensions Depending on your requirements, you may need to install additional PHP extensions. You can install some common PHP extensions using the following command: ``` apt install php8.4-{cli,pdo,mysql,zip,gd,mbstring,curl,xml,bcmath,common} ``` You can also install PHP Composer using the following command: ``` php -r "copy('https://getcomposer.org/installer', 'composer-setup.php');" php composer-setup.php --install-dir=/usr/local/bin --filename=composer ``` Output: ``` All settings correct for using Composer Downloading... Composer (version 2.8.8) successfully installed to: /root/composer.phar Use it: php composer.phar ``` Next, verify the Composer version using the following command: ``` composer --version ``` Output: ``` Composer version 2.8.8 2025-04-04 16:56:46 PHP version 8.4.7 (/usr/bin/php8.4) Run the "diagnose" command to get more detailed diagnostics output. ``` ## Step 4 – Verify PHP 8.4 Installation To verify that PHP is installed and configured correctly on your Ubuntu 24.04 system, you can create a simple PHP script and then execute it through your web server or the command line. Create a test.php file. ``` nano test.php ``` Add the following code: ``` ``` Save and close the file. Now, you have a test.php file containing a PHP script that will display information about your PHP installation. You can execute the test.php script directly from the command line. Open a terminal and navigate to the directory where test.php is located. Then, run the following command: ``` php test.php;echo ``` You will see the following output: ``` Hello World! ``` ## Conclusion By following the instructions provided in this tutorial, you’ve gained the knowledge and confidence to upgrade your PHP version safely and efficiently. With PHP 8.4, you’ll benefit from enhanced performance, new features, and bug fixes that can help optimize your web applications and improve overall server security. You can now upgrade your PHP version on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How To Install Home Assistant Core on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-home-assistant-core-on-ubuntu-24-04/ | Published: 2024-04-28 | Updated: 2025-09-30 | Author: Hitesh Jethva Home Assistant is an open-source home automation platform that allows users to control and automate various devices and services. It serves as a central hub for integrating smart devices, sensors, and other technologies, providing a unified interface for managing them. Home Assistant empowers users to create a smarter, more efficient, and more personalized home environment by bringing together disparate devices and technologies into a unified ecosystem. This tutorial will show you how to install Home Assistant on Ubuntu 24.04. ## Step 1 – Install Required Dependencies Home Assistant Core requires some dependencies to be installed. You can install them with the following command: ``` apt install -y tmux bluez libffi-dev libssl-dev libjpeg-dev zlib1g-dev autoconf build-essential libopenjp2-7 libturbojpeg0-dev tzdata ffmpeg liblapack3 liblapack-dev libatlas-base-dev software-properties-common ``` Once all the dependencies are installed, you can proceed to the next step. ## Step 2 – Install Python3.13 You will also need to install the latest version of Python to your server. First, add the Python PPA using the following command: ``` add-apt-repository ppa:deadsnakes/ppa ``` Next, install Python3.13 with additional packages. ``` apt install python3.13 python3.13-dev python3.13-venv -y ``` ## Step 3 – Install Home Assistant First, create a user account named “homeassistant” and set its default shell to “/bin/bash”. ``` useradd -rm homeassistant chsh -s /bin/bash homeassistant ``` Next, add a homeassistant user to the dialout group. ``` usermod -aG dialout homeassistant ``` Next, create a directory for your Home Assistant installation and set proper ownership. ``` mkdir /srv/homeassistant chown -R homeassistant:homeassistant /srv/homeassistant ``` Next, log in as a home assistant user and navigate to the home assistant directory. ``` sudo -u homeassistant -H -s cd /srv/homeassistant ``` Next, create a new virtual environment: ``` python3.13 -m venv . ``` Activate the virtual environment: ``` source bin/activate ``` Next, install the wheel package. ``` python3.13 -m pip install wheel ``` Output: ``` Collecting wheel Downloading wheel-0.43.0-py3-none-any.whl.metadata (2.2 kB) Downloading wheel-0.43.0-py3-none-any.whl (65 kB) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 65.8/65.8 kB 1.1 MB/s eta 0:00:00 Installing collected packages: wheel Successfully installed wheel-0.43.0 ``` Finally, install the Hone Assistant package. ``` pip3.13 install homeassistant ``` ## Step 4 – Initialize Home Assistant First, launch tmux session to run the Home Assistant. ``` tmux ``` Next, run the hass command to initialize the Home Assistant. ``` hass ``` This will install all the required basic dependencies on your server. Once all the dependencies are installed, open your web browser and access the Home Assistant web interface using the URL **http://your-server-ip:8123.** You will see the Home Assistant welcome page. ![](https://www.atlantic.net/wp-content/uploads/2024/04/p1-3.png) Click on **CREATE MY SMART HOME**. You will see the create user page: ![](https://www.atlantic.net/wp-content/uploads/2024/04/p2-3.png) Define your username and password and click on **CREATE ACCOUNT.** You will see the Home Location page. ![](https://www.atlantic.net/wp-content/uploads/2024/04/p3-2.png) Set your location and click on **NEXT.** You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/04/p4-3.png) Enable your desired settings and click on **NEXT.** You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/04/p5-2.png) Click on **FINISH.** You will see the HOME Assistant dashboard page. ![](https://www.atlantic.net/wp-content/uploads/2024/04/p6-1.png) ## Conclusion In this tutorial, you learned how to install Home Assistant on Ubuntu 24.04. Home Assistant provides users with a powerful and flexible platform for creating a smart home environment. Through its open-source nature and extensive community support, Home Assistant offers various integrations and customization options, allowing users to tailor their home automation setup to their specific needs and preferences. Try to deploy Home Assistant on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install osTicket on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-osticket-on-ubuntu-24-04/ | Published: 2024-04-29 | Updated: 2025-05-19 | Author: Hitesh Jethva osTicket is an open-source customer support ticket system that helps businesses efficiently manage customer inquiries, complaints, and other support-related issues. It supports multiple communication channels, including email piping (converting emails into tickets), web forms, and API integration, allowing businesses to manage customer inquiries from various sources. OsTicket is a flexible and customizable solution for businesses seeking an open-source ticketing system to streamline their customer support operations. In this tutorial, we will show you how to install osTicket on Ubuntu 24.04. ## Step 1 – Install Apache and PHP osTicket is a PHP-based application, so you will need to install Apache, PHP, and other PHP extensions on your server. You can install them using the following command: ``` apt install apache2 php php-cli php-common php-imap php-redis php-snmp php-xml php-zip php-mbstring php-curl php-mysqli php-gd php-intl php-apcu libapache2-mod-php unzip -y ``` After the installation, start and enable the Apache service. ``` systemctl start apache2 systemctl enable apache2 ``` ## Step 2 – Install and Configure MariaDB Database osTicket uses MariaDB as a database backend, so you will need to install and configure the MariaDB server. First, install the MariaDB database server using the following command: ``` apt install mariadb-server -y ``` Next, connect to the MariaDB shell. ``` mysql ``` After connecting to the MariaDB, create a database and user for osTicket. ``` CREATE DATABASE osticket; GRANT ALL PRIVILEGES ON osticket.* TO osticket@localhost IDENTIFIED BY "password"; ``` Next, flush the privileges and exit from the MariaDB. ``` FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install osTicket First, change the directory to Apache web root and download the latest osTicket version inside that directory. ``` cd /var/www/html curl -s https://api.github.com/repos/osTicket/osTicket/releases/latest | grep browser_download_url | cut -d '"' -f 4 | wget -i - ``` Next, unzip the downloaded file. ``` unzip osTicket*.zip -d osTicket ``` Next, copy the osTicket sample configuration file. ``` cp /var/www/html/osTicket/upload/include/ost-sampleconfig.php /var/www/html/osTicket/upload/include/ost-config.php ``` Then, set the necessary permissions and ownership to the osTicket directory. ``` chown -R www-data:www-data /var/www/html/osTicket/ chmod -R 775 /var/www/html/osTicket/ ``` ## Step 4 – Configure Apache for osTicket Next, create an Apache virtual host configuration file for osTicket. ``` nano /etc/apache2/sites-available/osticket.conf ``` Add the following configuration: ``` ServerName osticket.example.com DocumentRoot /var/www/html/osTicket/upload AllowOverride All ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined ``` Save and close the file, activate the Apache virtual host, and enable the Apache rewrite module. ``` a2enmod rewrite a2ensite osticket.conf ``` Finally, restart the Apache service to apply the changes. ``` systemctl reload apache2 ``` ## Step 5 – Access osTicket Web UI Now, open your web browser and access the osTicket using the URL http://osticket.example.com. You will see the osTicket prerequisites page. ![](https://www.atlantic.net/wp-content/uploads/2024/04/o1-1.png)   Click on **Continue.** You will see the osTicket configuration page. ![](https://www.atlantic.net/wp-content/uploads/2024/04/o2.png)   ![](https://www.atlantic.net/wp-content/uploads/2024/03/p3-7.png) Provide your helpdesk name, URL, admin username, password, email, and database credentials, then click on **Install Now.** Once the osTicket is installed, you will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/04/o3.png)   Click on **Your Staff Control Panel.** You will see the osTicket login page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p5-4.png) Provide your admin username and password and click on **Log In.** You will see the osTicket system settings page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p6-5.png) Modify the default settings as needed and click on the **Dashboard** tab. The osTicket dashboard will appear on the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p7-5.png) Finally, remove the osTicket installation directory using the following command: ``` rm -rf /var/www/html/osTicket/upload/setup/ ``` ## Conclusion osTicket provides businesses with a robust and customizable solution for managing customer support tickets efficiently. Using osTicket, organizations can centralize their support operations, streamline ticket management processes, and improve customer satisfaction. You can now test the osTicket application on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Odoo 18 on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-odoo-18-on-ubuntu-24-04/ | Published: 2024-04-30 | Updated: 2025-05-12 | Author: Hitesh Jethva Odoo is a suite of open-source business applications covering various needs such as CRM (Customer Relationship Management), e-commerce, accounting, inventory management, and project management. It is designed to be customizable and modular, allowing businesses to tailor it to their specific requirements. Odoo is built on a modular architecture, meaning users can start with the basic modules and add more functionalities as needed. It offers both an open-source and free-to-use community edition and an enterprise edition with additional features and support, which requires a subscription fee. In this tutorial, we will show you how to install Odoo 18 on Ubuntu 24.04. ## Step 1 – Install Required Dependencies Odoo is a Python-based software. Therefore, you will need to install Python and some additional dependencies on your server. You can install all of them using the following command: ``` apt-get install -y python3-pip python3-dev python3-venv libxml2-dev libxslt1-dev zlib1g-dev libsasl2-dev libldap2-dev build-essential libssl-dev libffi-dev libmysqlclient-dev libjpeg-dev libpq-dev libjpeg8-dev liblcms2-dev libblas-dev libatlas-base-dev -y ``` Next, install the NPM package manager. ``` apt-get install -y npm ``` Then, install other dependencies using NPM. ``` npm install -g less less-plugin-clean-css ``` Next, install the node-less package. ``` apt-get install -y node-less ``` Next, download wkhtmltopdf package and install it using the following command: ``` wget https://github.com/wkhtmltopdf/packaging/releases/download/0.12.6-1/wkhtmltox_0.12.6-1.bionic_amd64.deb ``` ``` dpkg -i wkhtmltox_0.12.6-1.bionic_amd64.deb ``` ``` apt install -f ``` ## Step 2 – Install PostgreSQL Odoo uses PostgreSQL as a database backend. You can install it using the following command: ``` apt-get install postgresql -y ``` After the successful installation, verify the PostgreSQL status using the following command: ``` systemctl status postgresql ``` Output: ``` ● postgresql.service - PostgreSQL RDBMS Loaded: loaded (/lib/systemd/system/postgresql.service; enabled; vendor preset: enabled) Active: active (exited) since Sat 2025-05-12 04:13:39 UTC; 9s ago Process: 16418 ExecStart=/bin/true (code=exited, status=0/SUCCESS) Main PID: 16418 (code=exited, status=0/SUCCESS) CPU: 1ms May 12 04:13:39 ubuntu24 systemd[1]: Starting PostgreSQL RDBMS... May 12 04:13:39 ubuntu24 systemd[1]: Finished PostgreSQL RDBMS. ``` Next, create a user for Odoo using the following command: ``` useradd -m -U -r -d /opt/odoo18 -s /bin/bash odoo18 ``` Also, create the same user for PostgreSQL. ``` su - postgres -c "createuser -s odoo18" ``` ## Step 3 – Install and Configure Odoo First, log in as an Odoo user and download the Odoo 18 using the following command: ``` su - odoo18 git clone https://www.github.com/odoo/odoo --depth 1 --branch 18.0 /opt/odoo18/odoo18 ``` Next, create a Python virtual environment for Odoo. ``` cd /opt/odoo18 python3 -m venv odoo18-venv ``` Next, activate the virtual environment. ``` source odoo18-venv/bin/activate ``` Next, update the pip to the latest version. ``` pip install --upgrade pip ``` Next, install the Weel package. ``` pip3 install wheel ``` Next, install additional Python dependencies. ``` pip3 install -r odoo18/requirements.txt ``` Finally, deactivate from the Python virtual environment. ``` deactivate ``` Also, log out of the Odoo user. ``` exit ``` Next, create a directory to store Odoo addons and give it proper ownership. ``` mkdir /opt/odoo18/odoo18-custom-addons chown -R odoo18:odoo18 /opt/odoo18/odoo18-custom-addons ``` Next, create a log directory and file for Odoo and set proper permissions. ``` mkdir -p /var/log/odoo18 touch /var/log/odoo18/odoo18.log chown -R odoo18:odoo18 /var/log/odoo18 ``` Next, create an Odoo configuration file. ``` nano /etc/odoo18.conf ``` Add the following lines: ``` [options] admin_passwd = master-password db_host = False db_port = False db_user = odoo18 db_password = False xmlrpc_port = 8069 logfile = /var/log/odoo18/odoo18.log addons_path = /opt/odoo18/odoo18/addons,/opt/odoo18/odoo18-custom-addons ``` ## Step 4 – Create a Systemd File for Odoo You will also need to create a system file to manage the Odoo service. ``` nano /etc/systemd/system/odoo18.service ``` Add the following lines: ``` [Unit] Description=odoo18 After=network.target postgresql@14-main.service [Service] Type=simple SyslogIdentifier=odoo18 PermissionsStartOnly=true User=odoo18 Group=odoo18 ExecStart=/opt/odoo18/odoo18-venv/bin/python3 /opt/odoo18/odoo18/odoo-bin -c /etc/odoo18.conf StandardOutput=journal+console [Install] WantedBy=multi-user.target ``` Save the file, then reload the systemd daemon. ``` systemctl daemon-reload ``` Now, start and enable the Odoo service. ``` systemctl start odoo18 systemctl enable odoo18 ``` You can now check the Odoo status using the following command: ``` systemctl status odoo18 ``` Output: ``` ● odoo18.service - odoo18 Loaded: loaded (/etc/systemd/system/odoo18.service; disabled; preset: enabled) Active: active (running) since Mon 2025-05-12 05:32:01 UTC; 3s ago Main PID: 32045 (python3) Tasks: 4 (limit: 4609) Memory: 90.4M (peak: 90.8M) CPU: 1.575s CGroup: /system.slice/odoo18.service └─32045 /opt/odoo18/odoo18-venv/bin/python3 /opt/odoo18/odoo18/odoo-bin -c /etc/odoo18.conf May 12 05:32:01 ubuntu systemd[1]: Started odoo18.service - odoo18. ``` ## Step 5 – Access Odoo Web Interface At this point, Odoo has started listening on port 8069. You can now access it using the URL **http://your-server-ip:8069.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/04/o1.png)   Provide your master password and Odoo database and click on **Create** **Database**. You will see the Odoo 18 login page. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p2-8.png) Provide your admin username and password and click on **Log in.** The Odoo dashboard will appear on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p3-6.png) ## Conclusion Odoo offers a powerful platform for managing various aspects of your business, from CRM to accounting to project management and beyond. By following the steps outlined in this guide, you can successfully set up Odoo 18 on your Ubuntu 24.04 system. Now try to deploy Odoo 18 on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Angular CLI on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-angular-cli-on-ubuntu-24-04/ | Published: 2024-05-01 | Updated: 2025-05-16 | Author: Hitesh Jethva Angular is a popular open-source web application framework primarily maintained by Google and a community of developers. It is used for building dynamic, single-page web applications (SPAs) and progressive web applications (PWAs). Angular is written in TypeScript, a superset of JavaScript, and offers a comprehensive set of features for front-end development. This tutorial will show you how to install Angular on Ubuntu 24.04. ## Step 1 – Install Nodejs Before starting, you will need to install Nodejs on your server. Follow the below steps to install the latest stable version of Nodejs. First, create a directory to store the Nodejs GPG key. ``` mkdir -p /etc/apt/keyrings ``` Download the Nodejs GPG key to the above directory. ``` curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | sudo gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg ``` Add the Nodejs repository to the APT source file. ``` echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_22.x nodistro main" | sudo tee /etc/apt/sources.list.d/nodesource.list ``` Update the repository index. ``` apt update ``` Finally, install the Nodejs using the following command: ``` apt install nodejs ``` After the installation, you can verify the Nodejs version using the following command: ``` node --version ``` Output: ``` v22.15.1 ``` ## Step 2 – Install Angular CLI Angular CLI is a powerful tool provided by the Angular team to streamline the development process of Angular applications. It offers a set of commands and tools that automate repetitive tasks and provide a structured workflow for creating, building, testing, and deploying Angular applications. First, update NPM with the latest version. ``` npm install npm@latest -g ``` Next, install Angular CLI using the NPM command: ``` npm install -g @angular/cli ``` After the installation, you can verify the Angular CLI version using the following command: ``` ng version ``` Output: ``` _ _ ____ _ ___ / \ _ __ __ _ _ _| | __ _ _ __ / ___| | |_ _| / △ \ | '_ \ / _` | | | | |/ _` | '__| | | | | | | / ___ \| | | | (_| | |_| | | (_| | | | |___| |___ | | /_/ \_\_| |_|\__, |\__,_|_|\__,_|_| \____|_____|___| |___/ Angular CLI: 19.2.12 Node: 22.15.1 Package Manager: npm 11.4.0 OS: linux x64 Angular: ... Package Version ------------------------------------------------------ @angular-devkit/architect 0.1902.12 (cli-only) @angular-devkit/core 19.2.12 (cli-only) @angular-devkit/schematics 19.2.12 (cli-only) @schematics/angular 19.2.12 (cli-only) ``` ## Step 3 – Create an Application Using Angular CLI You can easily use the ng command to create a new Angular application via the command line. ``` ng new angular-app ``` Select the CSS and press Enter to create a new Angular app. ``` ? Which stylesheet format would you like to use? (Use arrow keys) ❯ CSS [ https://developer.mozilla.org/docs/Web/CSS ] Sass (SCSS) [ https://sass-lang.com/documentation/syntax#scss ] Sass (Indented) [ https://sass-lang.com/documentation/syntax#the-indented-syntax ] Less [ http://lesscss.org ] ? Do you want to enable Server-Side Rendering (SSR) and Static Site Generation (SSG/Prerendering)? Yes ``` Next, change the directory to your application and start Angular locally. ``` cd angular-app ng serve ``` Press the CTRL+C to stop the application. ## Step 4 – Access Angular Application To make the Angular application accessible from the outside network, you will need to start it using the –host parameter. ``` ng serve --host 0.0.0.0 --port 3001 ``` This will start the Angular application on all network interfaces on port 3001, as shown below: ``` Watch mode enabled. Watching for file changes... ➜ Local: http://localhost:3001/ ➜ Network: http://209.23.9.25:3001/ ➜ press h + enter to show help ``` You can now access your Angular application using the URL **http://your-server-ip:3001** from your web browser. ![](https://www.atlantic.net/wp-content/uploads/2024/03/p1-9.png) ## Conclusion You can now easily install and use Angular on the Ubuntu 24.04 server. Overall, Angular is a comprehensive framework that empowers developers to build modern, responsive, and scalable web applications with ease. Its rich feature set, strong community support, and backing from Google make it a popular choice for web development projects of all sizes. Try Angular CLI on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Kubernetes In a HIPAA Compliant Environment: Key Considerations > URL: https://www.atlantic.net/hipaa-compliant-hosting/kubernetes-in-a-hipaa-compliant-environment-key-considerations/ | Published: 2024-05-02 | Updated: 2024-09-23 | Author: Gilad Maayan ## What Is Kubernetes and How Is It Used in Healthcare Applications? Kubernetes is an open-source platform designed to automate deploying, scaling, and operating application containers. It groups containers that make up an application into logical units for easy management and discovery. Kubernetes provides tools to deploy applications, scale them as needed, roll out new features, or roll them back to previous versions. It is also designed to work across different environments, including on-premise data centers, public clouds, and hybrid clouds. Kubernetes can be used for deploying and managing applications that handle sensitive patient data. It supports healthcare applications by providing scalable solutions that support large volumes of data and traffic, ensuring that these applications are always available when needed. Kubernetes also facilitates compliance with healthcare regulations by enabling organizations to preserve privacy. It supports security features that protect patient data while maintaining the flexibility to adapt to changing healthcare requirements. ![](https://www.atlantic.net/wp-content/uploads/2024/05/Kubernetes-HIPAA.jpg) ## HIPAA Requirements for Relevant Kubernetes To meet HIPAA compliance, Kubernetes deployments in healthcare must ensure the confidentiality, integrity, and availability of Protected Health Information (PHI). ### Ensuring Patient Data Availability Kubernetes clusters must be configured to withstand failures and continue to operate, providing access to PHI when needed. For high availability, Kubernetes uses replication controllers and services that continuously monitor the state of applications and automatically replace failed instances. Proper configuration and regular testing of failover mechanisms help ensure that PHI remains accessible during a system failure. ### Access Controls Kubernetes must be configured to ensure that PHI is only accessible to authorized individuals and systems. Kubernetes offers role-based access control (RBAC) mechanisms that allow fine-grained control over who can access what resources within the cluster. Administrators can limit access to only what is necessary for each user. They should regularly review and update access policies to reflect changes in personnel or job roles. ### Data Encryption Kubernetes supports encryption at rest by integrating with storage providers that offer encryption capabilities. For data in transit, Kubernetes can enforce SSL/TLS encryption for data moving between different parts of the application, ensuring that PHI is encrypted as it traverses the network. Key management practices must be used to safely store encryption keys. ### Audit Trails Kubernetes provides logging mechanisms that can capture detailed information about every action taken in the cluster, including who performed the action, what resources were accessed, and when it occurred. To meet HIPAA requirements, logs should be stored securely and kept for a required retention period. Regular review of audit logs can help quickly identify and address security issues. ## Best Practices and Considerations for Kubernetes in HIPAA-Compliant Environments Here are some things to consider when working with healthcare data in Kubernetes. ### 1. Implement Network Policies for Pod Communication By default, pods in a Kubernetes cluster can communicate with each other without restrictions. Malicious entities could potentially exploit this open communication channel. Implementing network policies allows administrators to explicitly define how pods communicate within the cluster, isolating sensitive workloads and minimizing the risk of unauthorized access. Administrators should identify and categorize the different types of traffic within the cluster. This involves mapping out which [Kubernetes services](https://komodor.com/learn/kubernetes-service-examples-basic-usage-and-troubleshooting/) need to communicate with each other and establishing clear rules that allow only necessary communications. A frontend application pod may need access to a backend database pod, but it should not have access to other backend services. ### 2. Implement a Backup and Disaster Recovery Strategy Backup and disaster recovery strategies involve regularly backing up both the data stored within the cluster and the cluster’s state, including configurations and secrets. In case of a failure or data loss, these backups can be used to restore operations quickly, minimizing downtime. A comprehensive strategy should include automated backup processes that capture data at regular intervals and store backups in a secure, off-site location. The disaster recovery plan should be tested regularly to ensure it can be executed effectively in an emergency. This could include drills simulating failure scenarios, including data corruption and cyber attacks. ### 3. Ensure Data Integrity During Transfer and Storage Kubernetes deployments must employ mechanisms that verify data has not been altered or corrupted. For data in transit, SSL/TLS encryption provides a secure channel that also allows for integrity checks. For data at rest, storage solutions with built-in checksums or application-level integrity checks can help ensure data remains unaltered from its original state. Kubernetes environments should leverage etcd’s built-in mechanisms for maintaining the integrity of its stored data, which is important for preserving the cluster’s state. Implementing regular integrity audits and employing tools that automatically detect and report anomalies can further enhance data integrity. ### 4. Continuously Monitor Kubernetes Clusters Monitoring should cover various aspects of the cluster, including performance metrics, resource utilization, network traffic, and security events. This allows administrators to gain insights into the state of their deployments, identify potential issues before they escalate, and ensure that the environment adheres to best practices for security and compliance. Integrating monitoring tools with alerting systems enables real-time notifications of critical events, allowing for prompt responses to potential threats or performance issues. This proactive approach to cluster management helps maintain high availability and secure operations. ### 5. Configure Alerts for Suspicious Activities Keeping track of suspicious behavior involves setting up automated notifications for events that could indicate a security breach or an attempt to access sensitive data without authorization. These indicators include multiple failed login attempts, unexpected changes in configurations, and unusual data access patterns. By defining clear criteria for what constitutes suspicious activity and using monitoring tools to detect such events, administrators can quickly respond to potential threats. Alert systems should be integrated with incident response workflows to ensure that alerts are quickly received and acted upon. This might involve triggering automated response actions to mitigate risks. ### 6. Implement Vulnerability Scanning and Remediation Regular vulnerability scanning and remediation are critical components of maintaining a secure Kubernetes environment. This process involves using automated tools to scan the components of the Kubernetes cluster, including the container images, host systems, and applications running within the cluster, for known vulnerabilities. Once vulnerabilities are identified, remediation measures, such as applying patches, updating software, or reconfiguring settings, must be taken to mitigate the risk they pose. Effective vulnerability management also includes regular reviews of the components used within the cluster to ensure they are up-to-date. A routine for scanning and updating components can help. ### 7. Conduct Compliance Audits and Reviews Regular compliance audits should assess the effectiveness of the security controls in place, verify compliance with access controls, encryption standards, and data protection policies, and identify areas for improvement. Reviews might include examining the processes for responding to incidents and breaches to ensure they are adequate and align with regulatory expectations. Engaging third-party auditors can provide an objective assessment of the compliance posture and help uncover issues that internal reviews might overlook. Findings from these audits should inform continuous improvement efforts, ensuring the Kubernetes environment remains secure and compliant. ## Conclusion Implementing best practices for Kubernetes in HIPAA-compliant environments requires a multi-faceted approach that encompasses network security, data protection, continuous monitoring, and regular compliance reviews. By addressing these critical areas, healthcare organizations can leverage Kubernetes to support their applications while ensuring the confidentiality, integrity, and availability of PHI. As the healthcare landscape continues to evolve, staying informed and adapting to new challenges will be key to maintaining a secure and compliant Kubernetes environment. --- **Author Bio: Gilad David Maayan** ![](https://www.atlantic.net/wp-content/uploads/2023/10/giladimage.jpg) Gilad David Maayan is a technology writer who has worked with over 150 technology companies including SAP, Imperva, Samsung NEXT, NetApp, and Check Point, producing technical and thought leadership content that elucidates technical solutions for developers and IT leadership. Today he heads [Agile SEO](https://agileseo.co.il/), the leading marketing agency in the technology industry. LinkedIn: [Linkedin](https://www.linkedin.com/in/giladdavidmaayan/) --- # How to Deploy Akaunting – An Opensource WaveApps & FreshBooks Alternative on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-deploy-akaunting-an-opensource-waveapps-freshbooks-alternative-on-ubuntu-22-04/ | Published: 2024-05-04 | Updated: 2024-06-05 | Author: Hitesh Jethva Akaunting is an open-source accounting software for small and medium-sized businesses (SMBs) and freelancers. It provides a comprehensive suite of features to manage finances, including invoicing, expense tracking, banking, and reporting. It helps organizations manage their finances effectively, streamline processes, and make informed business decisions. In this tutorial, we will show you how to install Akaunting on Ubuntu 22.04. ## Step 1 – Install LAMP Server Akaunting requires a web server with PHP and a database. You can install the LAMP (Linux, Apache, MySQL/MariaDB, PHP) stack using the following commands: ``` apt install apache2 mariadb-server php libapache2-mod-php php-imagick php-common php-mysql php-gd php-bcmath php-curl php-zip php-xml php-mbstring php-bz2 php-intl unzip -y ``` Once the LAMP server is installed, start and enable both Apache and MariaDB services: ``` systemctl start apache2 mariadb systemctl enable apache2 mariadb ``` ## Step 2 – Create a Database Log in to the MySQL/MariaDB shell as the root user: ``` mysql -u root -p ``` Then, create a database and user for Akaunting: ``` create database akaunting; create user 'akaunting'@'localhost' identified by 'yourpassword'; ``` Next, grant all the privileges to the Akaunting database. ``` grant all privileges on akaunting.* to 'akaunting'@'localhost'; ``` Finally, flush the privileges and exit from the MariaDB shell. ``` flush privileges; exit; ``` ## Step 3 – Download Akaunting Navigate to the Akaunting website and download the latest version of Akaunting. ``` wget -O Akaunting.zip https://akaunting.com/download.php?version=latest ``` Once the download is complete, extract the Akaunting files to the web server’s document root directory. ``` unzip Akaunting.zip -d /var/www/akaunting/ ``` Set the correct permissions for the Akaunting files and directories: ``` chown www-data:www-data /var/www/akaunting/ -R chmod -R 755 /var/www/akaunting ``` ## Step 4 – Configure Apache Create a new virtual host configuration file for Akaunting: ``` nano /etc/apache2/sites-available/akaunting.conf ``` Add the following lines: ``` ServerName akaunting.example.com DocumentRoot /var/www/akaunting/ DirectoryIndex index.php Options +FollowSymLinks AllowOverride All Require all granted ErrorLog ${APACHE_LOG_DIR}/akaunting.error.log CustomLog ${APACHE_LOG_DIR}/akaunting.access.log combined ``` Enable the Akaunting site and rewrite module. ``` a2ensite akaunting.conf a2enmod rewrite ``` Finally, restart the Apache service: ``` systemctl restart apache2 ``` ## Step 5 – Perform Akaunting Web-based Installation Open your web browser and navigate to the URL **http://akaunting.example.com.** You will see the Akaunting language selection page: ![](https://www.atlantic.net/wp-content/uploads/2024/04/p1-2.png) Select your language and click on **Next.** You will see the database configuration page: ![](https://www.atlantic.net/wp-content/uploads/2024/04/p2-2.png) Define your database settings and click on **Next.** You will see the admin user creation page: ![](https://www.atlantic.net/wp-content/uploads/2024/04/p4-2.png) Provide your admin user, password, and email and click on **Next.** You will see the Akaunting login page: ![](https://www.atlantic.net/wp-content/uploads/2024/04/p5-1.png) Enter your admin username and password and click on **Login.** You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/04/p6.png) Provide all required information and click on **Save.** You will see the currency page: ![](https://www.atlantic.net/wp-content/uploads/2024/04/p7.png) Add your new currency and click on **Next.** You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/04/p8.png) Click on **Skip** this. You will see the Akaunting dashboard on the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/04/p9.png) ## Conclusion This tutorial explained how to install Akaunting on Ubuntu 22.04 with Apache. By deploying Akaunting on Ubuntu, you gain control over your financial data while benefiting from the security, stability, and flexibility of the Ubuntu platform. Whether you’re tracking expenses, managing invoices, or generating financial reports, Akaunting provides the tools to streamline your accounting processes and make informed decisions. You can now host your own Akaunting software on a [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) by Atlantic.Net! --- # How to Install Apache CouchDB on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-apache-couchdb-on-ubuntu-22-04/ | Published: 2024-05-05 | Updated: 2024-06-03 | Author: Hitesh Jethva Apache CouchDB is an open-source NoSQL database management system that stores data in a schema-less JSON format, allowing for flexible and dynamic data modeling. Apache CouchDB offers organizations a robust and flexible NoSQL database solution with features such as distributed architecture, document-oriented storage, offline-first capabilities, RESTful API, and fault tolerance. By leveraging CouchDB, organizations can build scalable, resilient, and responsive applications that meet the demands of modern data-driven environments. In this tutorial, we will show you how to install Apache CouchDB on Ubuntu 22.04. ## Step 1 – Install Apache CouchDB To install Apache CouchDB on Ubuntu 22.04, you’ll need to add the CouchDB repository to your system. CouchDB provides a GPG key that is used to sign the repository packages. You can download and install this key using the following command: ``` curl https://couchdb.apache.org/repo/keys.asc | gpg --dearmor | sudo tee /usr/share/keyrings/couchdb-archive-keyring.gpg >/dev/null ``` Next, add the CouchDB repository to your system’s software sources list. You can create a new file for the CouchDB repository in the /etc/apt/sources.list.d/ directory: ``` echo "deb [signed-by=/usr/share/keyrings/couchdb-archive-keyring.gpg] https://apache.jfrog.io/artifactory/couchdb-deb/ $(lsb_release -cs) main" | tee /etc/apt/sources.list.d/couchdb.list ``` After adding the repository, update the package lists to ensure that Ubuntu recognizes the newly added CouchDB repository: ``` apt-get update -y ``` Once the repository is added and the package lists are updated, you can install CouchDB using the apt package manager: ``` apt-get install couchdb -y ``` You will be asked to install CouchDB in standalone or clustered mode. ![](https://www.atlantic.net/wp-content/uploads/2024/04/p1-1.png) Select Standalone and press the **Enter** key. You will be asked to set the Erlang value: ![](https://www.atlantic.net/wp-content/uploads/2024/04/p2-1.png) Set your desired value and press the Enter key. You will be asked to set a bind address: ![](https://www.atlantic.net/wp-content/uploads/2024/04/p3-1.png) Set your bind address and press the **Enter** key. You will be asked to set admin password. ![](https://www.atlantic.net/wp-content/uploads/2024/04/p4-1.png) Define your password and press the **Enter** key to complete the installation. ## Step 2 – Configure Apache CouchDB By default, Apache CouchDB listens on localhost on port 5984. To access CouchDB from an external system, you will need to edit the CouchDB configuration file to define a band address. ``` nano /opt/couchdb/etc/local.ini ``` Change the following lines: ``` [chttpd] port = 5984 bind_address = 0.0.0.0 ``` Save and close the file then start the CouchDB service. ``` systemctl start couchdb ``` You can check the status of CouchDB using the following command: ``` systemctl status couchdb ``` Output: ``` ● couchdb.service - Apache CouchDB Loaded: loaded (/lib/systemd/system/couchdb.service; enabled; vendor preset: enabled) Active: active (running) since Sat 2024-04-06 03:24:56 UTC; 48s ago Main PID: 14158 (beam.smp) Tasks: 28 (limit: 4579) Memory: 43.0M CPU: 5.853s CGroup: /system.slice/couchdb.service ├─14158 /opt/couchdb/bin/../erts-12.3.2.15/bin/beam.smp -SDio 16 -Bd -- -root /opt/couchdb/bin/.. -progname couchdb -- -home /opt/couchdb -- -boot /opt/co> ├─14171 /opt/couchdb/bin/../erts-12.3.2.15/bin/epmd -daemon └─14174 erl_child_setup 65536 ``` ## Step 3 – Verifying the Installation To verify the installation of CouchDB, use the curl command: ``` curl http://127.0.0.1:5984/ ``` Output: ``` {"couchdb":"Welcome","version":"3.3.3","git_sha":"40afbcfc7","uuid":"7f98ad06b2538ed9b4d6843bd6b5c07d","features":["access-ready","partitioned","pluggable-storage-engines","reshard","scheduler"],"vendor":{"name":"The Apache Software Foundation"}} ``` ## Conclusion Following the steps outlined in this guide, users can quickly set up CouchDB on their Ubuntu systems and begin leveraging its powerful data storage, retrieval, and synchronization features. Apache CouchDB is suitable for many use cases, from web and mobile applications to data synchronization hubs and offline-first solutions. You can now use CouchDB as a database backend on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Atlantic.Net Named Winner of the Coveted Global InfoSec Awards During RSA Conference 2024 > URL: https://www.atlantic.net/press-releases/atlantic-net-named-winner-of-the-coveted-global-infosec-awards-during-rsa-conference-2024/ | Published: 2024-05-05 | Updated: 2024-06-11 | Author: Alexander Wise *Atlantic.Net Wins Most Innovative Cloud Hosting and Storage Solutions IN 12**th**Annual Global InfoSec Awards at #RSAC 2024* SAN FRANCISCO (BUSINESSWIRE) MAY 6, 2024 – Atlantic.Net is proud to announce we have won the following award(s) from Cyber Defense Magazine (CDM), the industry’s leading electronic information security magazine: **Most Innovative Cloud Hosting and Storage Solutions** “We are delighted to win the Most Innovative Cloud Hosting and Storage Solutions award from Cyber Defense Magazine. This award reaffirms our commitment to delivering cutting-edge cloud services secured by best-in-class cybersecurity measures. We extend our sincere appreciation to Cyber Defense Magazine for this recognition,” said Marty Purinik of Atlantic.Net. Atlantic.Net embodies three major features we judges look for to become winners: understanding tomorrow’s threats, today, providing a cost-effective solution, and innovating in unexpected ways that can help mitigate cyber risk and get one step ahead of the next breach,” said Gary S. Miliefsky, Publisher of Cyber Defense Magazine. We’re thrilled to be a member of this coveted group of winners, located here:   [Cyber defense awards](http://www.cyberdefenseawards.com/) Please join us at the #RSAC RSA Conference 2024, [RSA conference](https://www.rsaconference.com/usa) today, as we share our red carpet experience and proudly display our trophy on our website, blog, and social media channels. **About Atlantic.Net** Atlantic.Net is a globally renowned provider of cloud services, boasting a strong focus on security, and compliance. With more than 30 years in the field, we’re committed to delivering a range of flexible, on-demand, and cost-effective cloud solutions that cater to the unique requirements of developers and IT leaders across businesses of every size **About Cyber Defense Magazine** Cyber Defense Magazine is the premier source of cyber security news and information for InfoSec professions in business and government. We are managed and published by and for ethical, honest, passionate information security professionals. Our mission is to share cutting-edge knowledge, real-world stories, and awards for the best ideas, products, and services in the information technology industry.  We deliver electronic magazines every month online for free, and special editions exclusively for the RSA Conferences. CDM is a proud member of the Cyber Defense Media Group. Learn more about us at [Cyber defense magazine](https://www.cyberdefensemagazine.com). ### Media Contact [pr@atlantic.net](mailto:pr@atlantic.net) ***CDM Media Inquiries:*** Contact:                 Irene Noser, Marketing Executive Email:                     [marketing@cyberdefensemagazine.com](mailto:marketing@cyberdefensemagazine.com) Toll Free (USA):    1-833-844-9468 International:       1-646-586-9545 Website: --- # Container Hosting > URL: https://www.atlantic.net/vps-hosting/container-hosting/ | Published: 2024-05-06 | Author: Richard Bailey Containers have revolutionized the delivery of cloud-enabled applications. The technology brings multiple benefits to businesses looking to deliver top-tier applications within a compliant, yet agile hosting platform. One of the fastest-growing solutions offered by managed service providers is containerized hosting based on either Docker or Kubernetes clusters. ## What Is Container Hosting? Many people think that containerized applications are a new technology, but in reality, the computer theory of containerized programs and processes started back in the early [1970s](https://www.aquasec.com/blog/a-brief-history-of-containers-from-1970s-chroot-to-docker-2016/). The precursor to the technology was chroot process isolation introduced in Unix V7. It wasn’t until 2004, when Solaris created boundary separation with Solaris containers, that containers took a form like those we use today; these were the very first business-ready, manageable containers running inside a host. In 2013, containers went mainstream when Docker offered the first solution with complete control over the container ecosystem and the concept of container management tools. Today, Kubernetes and microservices architecture are leading the pack, and businesses are frequently choosing container hosting platforms above traditional cloud hosting platforms. Specifically, container hosting refers to a service offered by Managed Service Providers that uses containerization technology to host and manage applications, typically in the same cloud infrastructure. Unlike virtual machines (VMs), containers share the host operating system’s kernel, making them more efficient and faster to start up. Container hosting allows you to run multiple applications on a single server instance, creating a highly efficient hosting ecosystem and reducing running costs. Plus, thanks to dependable scaling and management tools, managing containers is much simpler these days. They are lightweight, scalable, portable, and very fast to deploy! ## What Is a Container Host? A container host is often referred to as the container engine or runtime environment. A container platform typically consists of a collection of hosts that can span multiple environments and share resources on demand. Containerization is a very efficient way to host applications, and as a result, container hosts can manage many containers at once, much more than a virtualization hypervisor like VMware would be able to manage with like-for-like resources. The container host is responsible for managing the local resources such as CPU, disk, memory, block storage, and networking. It also manages the lifecycle of the containers, making decisions about when to start, stop, scale up, scale down, or restart containerized applications. It is the host operating system that isolates the underlying container operating system from each other, creating a secure and reliable abstraction layer. Container hosts are typically clustered together, which essentially means each host can communicate and share resources automatically. The runtime engine creates an abstraction layer that utilizes each host dynamically in a logical resource pool. The engine sees the available resources and uses them no matter the server location or host on which they are physically available. There are lots of different engines available for your Container Hosts, including: - **Docker:** The most popular and user-friendly for building, running, and managing containers. - **Kubernetes:** Not a runtime itself, but orchestrates container deployments across hosts. - **Rocket (Rkt):** Lightweight, secure alternative to Docker, good for efficiency. - **ContainerD:** Lightweight runtime focused on managing container lifecycle for Linux-based systems. - **Windows Containers (HyperV):** This is a Windows alternative with two options: lightweight containers or full virtualized containers (or virtual machines) with HyperV. - **RunC:** Core container runtime engine used by Docker and others, following [OCI](https://opencontainers.org/) standards. ## What Is the Difference between Kubernetes and Docker? Docker and Kubernetes are both synonymous with containerization, but it’s important to understand that while both are important tools, they each serve a different purpose. The easiest way to demonstrate the difference is to remember that Docker builds and runs containers, and Kubernetes manages how and where those containers run. Although they are different, Docker and Kubernetes complement each other and work great together for building, delivering, and managing containerized applications. Google originally developed Kubernetes but has since made it open-source. Kubernetes uses an API to control how and where containers are run. Kubernetes deploys, scales, and manages Docker containers in a node cluster. K8s features service discovery, load balancing, and health checks, being responsible for the entire lifecycle management of the container. On the other hand, Docker is used to build container images, typically using Dockerfiles that define the code to execute, the software libraries needed, and any environmental variables required. a Docker image can be run locally or on a larger Docker engine, and you have simple management tools to run Docker, such as stop, start, restart, console, and logging. Here is a key comparison between the two techs: **Docker**: - Focus on Individual Containers - Docker builds and runs containers - Docker operates directly on the hosting platforms - Relies on docker host networking configuration **Kubernetes**: - Manages Containerized applications at scale - Orchestrates deployments, networking, and scaling - Separate control plane managing the cluster (API access, controllers) - Provides service abstractions for container communication within the cluster ## Do I Need Different Types of Hosting for Different Types of Containers? No, containers are agnostic, meaning that they can run on any server, provided it supports the Docker engine or another runtime such as containers. This could be managed Docker hosting services or standalone Linux or Windows deployments hosting Docker. Simple applications with relatively light resource requirements will run perfectly on shared hosting platforms or on a bespoke docker hosting platform running on a virtual private server (VPS hosting). However, complex applications with high resource demands would benefit from a dedicated server, or maybe a Kubernetes orchestration cloud platform. For applications with fluctuating resource needs, cloud hosting with auto-scaling features can be ideal. This allows you to scale your container deployment up or down based on traffic demands. Consider your own hosting provider for containers’ security needs. Highly sensitive applications might require dedicated hosting or a private cloud environment for enhanced security controls compared to shared hosting. ## How Do I Choose the Best Container Hosting? Deciding where to run docker containers is an important business decision to make. For simplicity look for a cloud platform provider with an intuitive control panel to manage docker containers and a good choice of docker hosting solutions. When making this decision you may want to consider the following: ### Resource Requirements Evaluate your containerized application’s CPU, memory, and storage requirements. Cloud providers typically offer various instance types with different resource configurations. Choose one that aligns with your application’s demands. Take time to understand your traffic demands. Are you a seasonal business that needs specific scaling at certain times of the year? ### Cost Pricing is really important when choosing your preferred Docker hosting platform. There is an abundance of providers that will host Docker, but each offers different feature sets for a different price tag. Expect options for the pricing model, such as pay-as-you-go and reserved instance discounts, and make sure you opt for a suitable service plan. You need container resources that fit your business needs without breaking the bank. Typically, you would expect to pay significantly less for a self-managed VPS to host Docker than you would for a multi-region Kubernetes cluster. It’s possible to overpay for Docker containerization because it’s easy to overprovision the resources your application needs. Likewise, it’s also possible to under-spec your docker containerization requirements and then spend the next days and weeks retrospectively allocating more resources at a further cost. So get your capacity planning estimates correct before you invest in containerization. ### Performance Containers are fast! Not only are they fast to deploy and fast when in use, but they also can be quickly scaled on demand. However, remember that application bottlenecks may occur if you do not take the time to architect your software application to container best practices. Health checks should be in place to alert and monitor if a resource is over or under-utilized; if this is not done correctly, it’s easy for the application to crash or slow down, creating P1 and P2 incidents. ### Required Features The features offered by the cloud platform will make or break your choice. Do you need hosting in various global data centers? Do you require docker support, an elastic container service, automated resource management, or a private container registry? Look for a hosting provider that offers a built-in container registry that allows you to push and pull files and manage your private Docker images securely within the same platform. If you’re deploying complex applications with multiple containers, consider hosting solutions with integrated container orchestration platforms like Kubernetes to simplify management and automation tasks like deployment, automatic scaling up, and health checks. ### Security Ensure the hosting environment provides proper network isolation between your containers and other users or applications to reduce security risks and potential conflicts. Look for hosting options that offer container image scanning for vulnerabilities to help identify and address potential security issues before deployment. The provider itself must be a reputable web hosting provider. Viewing their certifications and partnerships will help you understand their security posture. Providers with certifications such as HIPAA, PCI-DSS, SOC2, and HITECH will undertake additional auditing that helps guarantee customer security. ### Ease of Use Docker and Kubernetes are not easy technologies for new starters, but the learning curve is manageable if they provide an easy-to-use hosting platform. The best docker hosting providers will offer Linux or Windows hosting with root access. Docker apps with custom health checks should be available at multiple locations. Expect a reliable underlying infrastructure and a variety of hosting plans. ## Where Can I Deploy My Docker Containers? Atlantic.Net has been providing IT services for decades, and this year, we are celebrating our 30th year in business. The Atlantic.Net Cloud Platform (ACP) is designed from the ground up to provide the best hosting experience possible, with the option for additional managed services should they be required. We have 8 state-of-the-art data center locations with global routing throughout the United States, Canada, Europe, and Asia. We feature a simple yet powerful, easy docker installation using our one-click installation button. You can deploy a powerful Docker host in less than 30 seconds with our custom applications. Want to go it alone? No problem. You can build your own Docker host of various Linux or Windows operating systems. You can also opt for various dedicated server hosting plans at many of our edge locations. With Atlantic.Net, you’ll experience unparalleled reliability for your container workloads. The highly redundant infrastructure, automated backups, and proactive monitoring ensure high availability and maximum uptime, granting you peace of mind and uninterrupted service. We even offer a [100% Uptime SLA.](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/) The ACP cloud only uses SSD storage, and our servers feature either AMD Epyc or Intel Xeon Processors. Atlantic.Net’s team of friendly experts is at your service 24/7. Whether you require assistance with setup, troubleshooting, or optimizing the performance of cloud infrastructure, we are available to lend a helping hand and guide you toward success. --- # How to Install CouchBase Database on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-couchbase-database-on-ubuntu-22-04/ | Published: 2024-05-07 | Updated: 2024-06-01 | Author: Hitesh Jethva Apache Couchbase is an open-source, distributed, NoSQL document-oriented database management system. It’s designed to store, manage, and retrieve data in flexible JSON-like documents. Couchbase is suitable for a wide range of use cases, from web and mobile applications to real-time analytics and caching layers. Its combination of performance, scalability, flexibility, and robust features makes it a compelling choice for organizations looking to modernize their data infrastructure. In this tutorial, we will show you how to install the CouchBase database on Ubuntu 22.04. **Note: Couchbase recommends a server with 4 Cores** ## Step 1 – Add CouchBase Repository CouchBase is not included in the Ubuntu default repository by default. Therefore, you will need to add the CouchBase repository to your server. First, install the required dependencies using the following command: ``` apt install apt-transport-https ca-certificates software-properties-common -y ``` Next, download the CouchBase repository package. ``` curl -O https://packages.couchbase.com/releases/couchbase-release/couchbase-release-1.0-noarch.deb ``` Next, install the downloaded package file. ``` dpkg -i couchbase-release-1.0-noarch.deb ``` Finally, update the repository index using the following command: ``` apt update ``` ## Step 2 – Install CouchBase You can install the CouchBase server package using the following command: ``` apt-get install couchbase-server-community ``` Once the CouchBase is installed, start the CouchBase service and enable it to start at system reboot. ``` systemctl start couchbase-server systemctl enable couchbase-server ``` You can check the status of CouchBase using the following command: ``` systemctl status couchbase-server ``` Output: ``` ● couchbase-server.service - Couchbase Server Loaded: loaded (/lib/systemd/system/couchbase-server.service; enabled; vendor preset: enabled) Active: active (running) since Sat 2024-04-06 03:15:30 UTC; 1min 41s ago Docs: https://docs.couchbase.com Main PID: 12511 (beam.smp) Tasks: 149 (limit: 4579) Memory: 224.3M CPU: 14.346s CGroup: /system.slice/couchbase-server.service ``` ## Step 3 – Access CouchBase Web Interface At this point, the CouchBase server is installed and listens on port 8091. You can check it using the following command: ``` ss -antpl | grep 8091 ``` Output: ``` LISTEN 0 128 0.0.0.0:8091 0.0.0.0:* users:(("beam.smp",pid=12640,fd=53)) ``` Now, open your web browser and access the CouchBase web interface using the URL **http://your-IP-address:8091.** You will see the CouchBase dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/04/p1.png) Click on **Setup** **New** **Cluster**. You will see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2024/04/p2.png) Define your cluster name, admin username, and password, and click on **Next**. You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/04/p3.png) Accept the term and click on **Finish with Defaults**. You will see the Couchbase dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/04/p4.png) ## Conclusion In this tutorial, we showed you how to install CouchBase on Ubuntu 22.04. With Couchbase, you gain access to features such as seamless scalability, high availability, flexible data modeling, and integrated caching, empowering you to handle diverse workloads and meet the evolving demands of modern applications. Try to deploy CouchBase on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Deploy TimescaleDB on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-deploy-timescaledb-on-ubuntu-22-04/ | Published: 2024-05-08 | Updated: 2025-07-20 | Author: Hitesh Jethva TimescaleDB is a time-series database designed to handle time-stamped data efficiently. Time-series data is indexed, listed, or graphed in time order. It’s often generated by sensors, IoT devices, or logging systems, where each data point is associated with a timestamp. TimescaleDB is a powerful solution for managing time-series data efficiently, offering scalability, performance, and flexibility for various use cases, such as IoT, financial data analysis, monitoring systems, and more. In this tutorial, we will show you how to deploy TimescaleDB on Ubuntu 22.04. ## Step 1 – Install PostgreSQL TimescaleDB is an extension for PostgreSQL, so you need to have PostgreSQL installed. First, add the PostgreSQL repository using the following command: ``` curl -fsSL https://www.postgresql.org/media/keys/ACCC4CF8.asc|gpg --dearmor -o /etc/apt/trusted.gpg.d/postgresql.gpg sh -c 'echo "deb http://apt.postgresql.org/pub/repos/apt $(lsb_release -cs)-pgdg main" > /etc/apt/sources.list.d/pgdg.list' ``` Then, update the repository index and install the latest version of PostgreSQL using the following command: ``` apt update -y apt install postgresql-12 -y ``` Next, set the PostgreSQL password using the following command: ``` su - postgres psql -c "alter user postgres with password 'password'" ``` Next, exit from the PostgreSQL shell. ``` exit ``` ## Step 2 – Install TimescaleDB Before installing TimescaleDB, you will need to install the OpenSSL library to your system. First, download the libssl Debian package. ``` wget https://nz2.archive.ubuntu.com/ubuntu/pool/main/o/openssl/libssl1.1_1.1.1f-1ubuntu2.24_amd64.deb ``` Next, install the downloaded package file using the dpkg: ``` dpkg -i libssl1.1_1.1.1f-1ubuntu2.22_amd64.deb ``` Next, add the TimescaleDB GPG key. ``` apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv-keys 55EE6BF7698E3D58D72C0DD9ECB3980CC59E610B ``` Next, create a TimescaleDB APT configuration file. ``` nano /etc/apt/sources.list.d/timescale-ubuntu-timescaledb-ppa-jammy.list ``` Add the TimescaleDB repository: ``` deb https://ppa.launchpadcontent.net/timescale/timescaledb-ppa/ubuntu/ focal main ``` Save and close the file, update the repository index, and install TimescaleDB with the following command: ``` apt update apt install timescaledb-postgresql-12 ``` Next, initialize TimescaleDB on your PostgreSQL instance: ``` timescaledb-tune --quiet --yes ``` Finally, restart the PostgreSQL service to apply the changes. ``` systemctl restart postgresql ``` ## Step 3 – Enable TimescaleDB To enable the TimescaleDB, edit the PostgreSQL main configuration file. ``` nano /etc/postgresql/12/main/postgresql.conf ``` Add the following line: ``` shared_preload_libraries = 'timescaledb' ``` Save and close the file, then restart the PostgreSQL service to apply the changes. ``` systemctl restart postgresql@12-main.service ``` Next, connect to the PostgreSQL shell: ``` su - postgres psql ``` Then, create a database and enable the TimescaleDB extension: ``` CREATE database db1; \c db1 CREATE EXTENSION IF NOT EXISTS timescaledb CASCADE; ``` Output: ``` WARNING: WELCOME TO _____ _ _ ____________ |_ _(_) | | | _ \ ___ \ | | _ _ __ ___ ___ ___ ___ __ _| | ___| | | | |_/ / | | | | _ ` _ \ / _ \/ __|/ __/ _` | |/ _ \ | | | ___ \ | | | | | | | | | __/\__ \ (_| (_| | | __/ |/ /| |_/ / |_| |_|_| |_| |_|\___||___/\___\__,_|_|\___|___/ \____/ Running version 1.7.5 For more information on TimescaleDB, please visit the following links: 1. Getting started: https://docs.timescale.com/getting-started 2. API reference documentation: https://docs.timescale.com/api 3. How TimescaleDB is designed: https://docs.timescale.com/introduction/architecture Note: TimescaleDB collects anonymous reports to better understand and assist our users. For more information and how to disable, please see our docs https://docs.timescaledb.com/using-timescaledb/telemetry. CREATE EXTENSION ``` You can verify that TimescaleDB is installed and functioning correctly by connecting to your database and checking its status: ``` psql -U postgres -h localhost -d db1 ``` Output: ``` psql (12.18 (Ubuntu 12.18-1.pgdg22.04+1)) SSL connection (protocol: TLSv1.3, cipher: TLS_AES_256_GCM_SHA384, bits: 256, compression: off) Type "help" for help. db1=# ``` ## Conclusion In this guide, we explained how to deploy TimescaleDB on Ubuntu 22.04. Users opt for TimescaleDB for several compelling reasons. Its optimized architecture is specifically tailored for time-series data ensures superior performance and scalability compared to traditional relational databases. TimescaleDB’s ability to handle large volumes of data while maintaining fast query response times makes it an ideal choice for time-series workloads. You can deploy TimescaleDB on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Harbor Docker Image Registry on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-harbor-docker-image-registry-on-ubuntu-24-04/ | Published: 2024-05-10 | Updated: 2025-05-18 | Author: Hitesh Jethva Harbor is an open-source cloud-native registry that provides a secure and scalable platform for storing, signing, and distributing container images. Developed by VMware, Harbor offers enterprises and developers a comprehensive solution for managing container artifacts, ensuring compliance, and promoting collaboration across the software development lifecycle. In this guide, we will show you how to install the Harbor registry on Ubuntu 24.04. ## Step 1 – Install Docker CE By default, the latest Docker version is unavailable in the Ubuntu default repo, so you will need to install it from their official repo. First, install all the necessary dependencies: ``` apt update -y apt install ca-certificates curl gnupg lsb-release -y ``` Next, create a directory to store the Docker GPG key. ``` mkdir -p /etc/apt/keyrings ``` Next, download the GPG key: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /etc/apt/keyrings/docker.gpg ``` Next, add the Docker repository to the APT source file. ``` echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null ``` Next, update the repository cache: ``` apt update -y ``` Finally, install Docker CE and other required tools using the following command: ``` apt install docker-ce docker-ce-cli containerd.io docker-compose-plugin -y ``` You can verify the status of the Docker service using the following command: ``` systemctl status docker ``` Output: ``` ● docker.service - Docker Application Container Engine Loaded: loaded (/usr/lib/systemd/system/docker.service; enabled; preset: enabled) Active: active (running) since Mon 2025-05-19 04:47:49 UTC; 3s ago TriggeredBy: ● docker.socket Docs: https://docs.docker.com Main PID: 20631 (dockerd) Tasks: 9 Memory: 20.9M (peak: 21.0M) CPU: 339ms CGroup: /system.slice/docker.service └─20631 /usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock ``` ## Step 2 – Install Harbor First, download the latest version of Harbor from the Git repository. ``` curl -s https://api.github.com/repos/goharbor/harbor/releases/latest | grep browser_download_url | cut -d '"' -f 4 | grep '\.tgz$' | wget -i - ``` Once the download is completed, extract the downloaded file using the tar command: ``` tar -xzvf harbor-online-installer-v2.12.3.tgz ``` Next, move the extracted directory to the /opt directory. ``` mv harbor /opt/ ``` Next, navigate to the Harbor directory and copy the Harbor configuration file. ``` cd /opt/harbor cp harbor.yml.tmpl harbor.yml ``` Next, edit the Harbor configuration file. ``` nano harbor.yml ``` Change the following lines: ``` hostname: reg.example.com harbor_admin_password: Harbor12345 ``` Remove the following lines: ``` https: # https port for harbor, default is 443 port: 443 # The path of cert and key files for nginx certificate: /your/certificate/path private_key: /your/private/key/path ``` Save and close the file when you are done. Next, run the following command to install the Harbor: ``` ./install.sh ``` You will see the following output: ``` [Step 4]: starting Harbor ... [+] Running 9/10 ⠧ Network harbor_harbor Created 1.8s ✔ Container harbor-log Started 0.4s ✔ Container harbor-db Started 0.9s ✔ Container harbor-portal Started 0.8s ✔ Container redis Started 1.0s ✔ Container registry Started 0.7s ✔ Container registryctl Started 1.0s ✔ Container harbor-core Started 1.2s ✔ Container nginx Started 1.6s ✔ Container harbor-jobservice Started 1.6s ✔ ----Harbor has been installed and started successfully.---- ``` You can verify all running containers using the following command: ``` docker compose ps ``` Output: ``` NAME IMAGE COMMAND SERVICE CREATED STATUS PORTS harbor-core goharbor/harbor-core:v2.12.3 "/harbor/entrypoint.…" core 4 seconds ago Up 2 seconds (health: starting) harbor-db goharbor/harbor-db:v2.12.3 "/docker-entrypoint.…" postgresql 4 seconds ago Up 3 seconds (health: starting) harbor-jobservice goharbor/harbor-jobservice:v2.12.3 "/harbor/entrypoint.…" jobservice 4 seconds ago Up 1 second (health: starting) harbor-log goharbor/harbor-log:v2.12.3 "/bin/sh -c /usr/loc…" log 4 seconds ago Up 3 seconds (health: starting) 127.0.0.1:1514->10514/tcp harbor-portal goharbor/harbor-portal:v2.12.3 "nginx -g 'daemon of…" portal 4 seconds ago Up 3 seconds (health: starting) nginx goharbor/nginx-photon:v2.12.3 "nginx -g 'daemon of…" proxy 4 seconds ago Up 2 seconds (health: starting) 0.0.0.0:80->8080/tcp, [::]:80->8080/tcp redis goharbor/redis-photon:v2.12.3 "redis-server /etc/r…" redis 4 seconds ago Up 3 seconds (health: starting) registry goharbor/registry-photon:v2.12.3 "/home/harbor/entryp…" registry 4 seconds ago Up 3 seconds (health: starting) registryctl goharbor/harbor-registryctl:v2.12.3 "/home/harbor/start.…" registryctl 4 seconds ago Up 3 seconds (health: starting) ``` ## Step 3 – Access Harbor Web UI At this point, the Harbor registry is installed in the Docker container. You can now access it using the URL **http://reg.example.com.** You will see the Harbor login page: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p1-2.png) Provide the default username **admin** and the password that you have configured via the configuration file **harbor.yml,** then click on the **LOG IN** button. You will see the Harbor dashboard on the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p2-2.png) ## Conclusion By deploying Harbor, you gain control over your container image lifecycle, ensuring compliance with security policies, regulatory requirements, and best practices for containerized application development and deployment. Harbor’s intuitive user interface, RESTful API, and integration capabilities enable seamless integration with your existing infrastructure, CI/CD pipelines, and identity providers, fostering collaboration and accelerating software delivery cycles. You can now try to host your own image hosting registry using Harbor on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install BookStack on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-bookstack-on-ubuntu-24-04/ | Published: 2024-05-11 | Updated: 2025-05-24 | Author: Hitesh Jethva BookStack is a versatile and user-friendly open-source platform for organizing and storing documentation. With its intuitive interface and powerful features, BookStack simplifies creating, managing, and sharing knowledge within organizations, teams, and communities. BookStack allows you to leverage its capabilities to streamline documentation workflows, improve collaboration, and ensure easy access to vital information. This guide will walk you through the step-by-step process of installing BookStack on Ubuntu 24.04. ## Step 1 – Install LEMP Stack Before starting, the LEMP stack must be installed on your server. First, install the Nginx web server using the following command: ``` apt update -y apt install nginx -y ``` Next, install PHP with other required dependencies using the following command: ``` apt install php php-fpm php-mbstring php-gd php-xml unzip php-bcmath php-curl php-mysql -y ``` Next, install the MariaDB database server with the following command: ``` apt install mariadb-server -y ``` Next, install the Composer using the following command: ``` apt install composer -y ``` You can verify the Composer installation using the following command: ``` composer --version ``` Output: ``` Composer 2.2.6 2022-02-04 17:00:38 ``` Once all the packages are installed, you can proceed to the next step. ## Step 2 – Create a Database First, secure the MariaDB installation using the following command: ``` mysql_secure_installation ``` Answer all the questions as shown below: ``` Enter current password for root (enter for none): Press Enter Switch to unix_socket authentication [Y/n] Type y Change the root password? [Y/n] Type n Remove anonymous users? [Y/n] Type y Disallow root login remotely? [Y/n] Type y Remove test database and access to it? [Y/n] Type y Reload privilege tables now? [Y/n] Type y ``` Next, log in to the MariaDB shell: ``` mysql ``` Once you are logged in, create a database and user for Bookstack: ``` create database bookstack; CREATE USER 'bookstackuser'@'localhost' identified by 'password'; ``` Next, grant all the privileges to the Bookstack database: ``` grant CREATE,ALTER,SELECT,INSERT,UPDATE,DELETE on `bookstack`.* to 'bookstackuser'@'localhost'; grant All on `bookstack`.* to 'bookstackuser'@'localhost'; ``` Next, flush the privileges and exit from the MariaDB shell. ``` flush privileges; exit; ``` ## Step 3 – Install Bookstack First, create a directory for Bookstack: ``` mkdir -p /var/www/html/bookstack ``` Next, navigate inside the Bookstack directory and download the latest version of Bookstack from the Git repository. ``` cd /var/www/html/bookstack git clone https://github.com/BookStackApp/BookStack.git --branch=release --single-branch . ``` Next, install all the required PHP dependencies using the following command: ``` composer install --no-dev ``` Next, copy the sample environment file. ``` cp .env.example .env ``` Next, edit the .env file. ``` nano .env ``` Define your application URL and database settings: ``` APP_URL=http://bookstack.example.com DB_HOST=localhost DB_DATABASE=bookstack DB_USERNAME=bookstackuser DB_PASSWORD=password ``` Save and close the file then migrate the database using the following commands: ``` php artisan key:generate php artisan migrate ``` You will be prompted by the above commands. Type [YES] to continue. Next, set proper permission and ownership to the Bookstack directory: ``` chown -R www-data:www-data /var/www/html/bookstack ``` ## Step 4 – Configure Nginx for Bookstack Next, create an Nginx virtual host configuration file to host Bookstack online. ``` nano /etc/nginx/conf.d/bookstack.conf ``` Add the following configurations: ``` server { listen 80; server_name bookstack.example.com; root /var/www/html/bookstack/public; index index.php index.html; location / { try_files $uri $uri/ /index.php?$query_string; } location ~ \.php$ { fastcgi_split_path_info ^(.+\.php)(/.+)$; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_param PATH_INFO $fastcgi_path_info; fastcgi_pass unix:/run/php/php8.3-fpm.sock; } } ``` Save and close the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http {: ``` server_names_hash_bucket_size 64; ``` Save the file, then validate the configuration using the following command: ``` nginx -t ``` Output: ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to implement the changes. ``` systemctl restart nginx ``` ## Step 5 – Access Bookstack Web UI Now, open your web browser and access the Bookstack web interface using the URL **http://bookstack.example.com.** You will see the Bookstack login page: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p1.png) Provide default username **admin@admin.com** with a password of **password**, then click on the **Log in** button. You will see the Bookstack dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p2.png) ## Conclusion In conclusion, installing BookStack on Ubuntu 24.04 gives you a robust and efficient platform for organizing and managing documentation. Following the steps outlined in this guide, you have successfully set up BookStack, empowering you and your team to create, collaborate, and share knowledge seamlessly. As you explore the features and capabilities of BookStack, consider customizing the platform to meet your specific requirements and integrating it into your existing workflows and tools. You can now deploy Bookstack on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Gitea DevOps Platform using Docker on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-gitea-devops-platform-using-docker-on-ubuntu-22-04/ | Published: 2024-05-12 | Updated: 2024-06-02 | Author: Hitesh Jethva Gitea is an open-source, self-hosted Git service that allows you to create and manage Git repositories on your own server. Installing Gitea on Ubuntu 22.04 gives you complete control over your Git repositories, offering features similar to other popular Git hosting platforms while allowing customization and integration with your existing infrastructure. In this guide, we will walk you through the step-by-step process of installing Gitea on Ubuntu 22.04, ensuring you have a seamless experience setting up your own Git hosting solution. ## Step 1 – Getting Started Before starting, you must update all the system packages to the latest version. You can do it with the following command: ``` apt update -y ``` Next, install other required dependencies using the following command: ``` apt install curl wget nano software-properties-common dirmngr apt-transport-https ca-certificates lsb-release debian-archive-keyring gnupg2 ufw unzip -y ``` Once all the required dependencies are installed, you can proceed to the next step. ## Step 2 – Install Docker CE This section will install the Docker CE from their official repository. First, create a directory to store the Docker GPG key. ``` mkdir -p /etc/apt/keyrings ``` Next, download the Docker GPG key. ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /etc/apt/keyrings/docker.gpg ``` Next, add the Docker repository to the APT file. ``` echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null ``` Next, update the repository index. ``` apt update ``` Next, install Docker CE and other packages using the following command: ``` apt install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin ``` Once the installation has been completed, you can verify the Docker service using the following command: ``` systemctl status docker ``` Output: ``` ● docker.service - Docker Application Container Engine Loaded: loaded (/lib/systemd/system/docker.service; enabled; vendor preset: enabled) Active: active (running) since Fri 2024-02-09 07:48:16 UTC; 10s ago TriggeredBy: ● docker.socket Docs: https://docs.docker.com Main PID: 27927 (dockerd) Tasks: 8 Memory: 29.6M CPU: 206ms CGroup: /system.slice/docker.service └─27927 /usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock ``` ## Step 3 – Create a Docker Compose File for Gitea First, create a directory to store your Gitea configuration files. ``` mkdir ~/gitea-docker ``` Next, create other required directories: ``` cd ~/gitea-docker mkdir {gitea,postgres} ``` Next, create a docker-compose.yml file. ``` nano docker-compose.yml ``` Add the following configurations: ``` services: server: image: gitea/gitea:1.21.0 container_name: gitea environment: - USER_UID=105 - USER_GID=111 - GITEA__database__DB_TYPE=postgres - GITEA__database__HOST=db:5432 - GITEA__database__NAME=gitea - GITEA__database__USER=gitea - GITEA__database__PASSWD=gitea restart: always networks: - gitea volumes: - ./gitea:/data - /root/.ssh/:/data/git/.ssh - /etc/timezone:/etc/timezone:ro - /etc/localtime:/etc/localtime:ro ports: - "3000:3000" - "2221:22" depends_on: - db db: image: postgres:15 restart: always environment: - POSTGRES_USER=gitea - POSTGRES_PASSWORD=gitea - POSTGRES_DB=gitea networks: - gitea volumes: - ./postgres:/var/lib/postgresql/data networks: gitea: external: false ``` Save and close the file when you are done. ## Step 4 – Launch Gitea Container At this point, the Docker Compose file is ready to launch the Gitea Docker container. You can run the following command to start all the containers: ``` docker compose up -d ``` Next, verify the running containers using the following command: ``` docker ps ``` You will see the following output: ``` CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES e3a6eaac98d5 gitea/gitea:1.21.0 "/usr/bin/entrypoint…" 19 seconds ago Up 18 seconds 0.0.0.0:3000->3000/tcp, :::3000->3000/tcp, 0.0.0.0:2221->22/tcp, :::2221->22/tcp gitea e8794d6c1a5e postgres:15 "docker-entrypoint.s…" 19 seconds ago Up 18 seconds 5432/tcp gitea-docker-db-1 ``` As you can see, the Gitea container is started and listens on port 3000. ## Step 5 – Configure Nginx as a Reverse Proxy Now, you must configure Nginx as a reverse proxy to access the Gitea from the remote machine. First, install the Nginx package: ``` apt install nginx ``` Next, create an Nginx configuration file. ``` nano /etc/nginx/conf.d/gitea.conf ``` Add the following configurations: ``` # Connection header for WebSocket reverse proxy map $http_upgrade $connection_upgrade { default upgrade; "" close; } map $remote_addr $proxy_forwarded_elem { # IPv4 addresses can be sent as-is ~^[0-9.]+$ "for=$remote_addr"; # IPv6 addresses need to be bracketed and quoted ~^[0-9A-Fa-f:.]+$ "for=\"[$remote_addr]\""; # Unix domain socket names cannot be represented in RFC 7239 syntax default "for=unknown"; } map $http_forwarded $proxy_add_forwarded { # If the incoming Forwarded header is syntactically valid, append to it "~^(,[ \\t]*)*([!#$%&'*+.^_`|~0-9A-Za-z-]+=([!#$%&'*+.^_`|~0-9A-Za-z-]+|\"([\\t \\x21\\x23-\\x5B\\x5D-\\x7E\\x80-\\xFF]|\\\\[\\t \\x21-\\x7E\\x80-\\xFF])*\"))?(;([!#$%&'*+.^_`|~0-9A-Za-z-]+=([!#$%&'*+.^_`|~0-9A-Za-z-]+|\"([\\t \\x21\\x23-\\x5B\\x5D-\\x7E\\x80-\\xFF]|\\\\[\\t \\x21-\\x7E\\x80-\\xFF])*\"))?)*([ \\t]*,([ \\t]*([!#$%&'*+.^_`|~0-9A-Za-z-]+=([!#$%&'*+.^_`|~0-9A-Za-z-]+|\"([\\t \\x21\\x23-\\x5B\\x5D-\\x7E\\x80-\\xFF]|\\\\[\\t \\x21-\\x7E\\x80-\\xFF])*\"))?(;([!#$%&'*+.^_`|~0-9A-Za-z-]+=([!#$%&'*+.^_`|~0-9A-Za-z-]+|\"([\\t \\x21\\x23-\\x5B\\x5D-\\x7E\\x80-\\xFF]|\\\\[\\t \\x21-\\x7E\\x80-\\xFF])*\"))?)*)?)*$" "$http_forwarded, $proxy_forwarded_elem"; # Otherwise, replace it default "$proxy_forwarded_elem"; } server { listen 80; server_name gitea.example.com; access_log /var/log/nginx/gitea.access.log; error_log /var/log/nginx/gitea.error.log; tcp_nopush on; # security headers add_header X-XSS-Protection "1; mode=block" always; add_header X-Content-Type-Options "nosniff" always; add_header Referrer-Policy "no-referrer-when-downgrade" always; add_header Content-Security-Policy "default-src 'self' http: https: ws: wss: data: blob: 'unsafe-inline'; frame-ancestors 'self';" always; add_header Permissions-Policy "interest-cohort=()" always; # . files location ~ /\.(?!well-known) { deny all; } location / { client_max_body_size 100M; proxy_pass http://localhost:3000; proxy_http_version 1.1; proxy_cache_bypass $http_upgrade; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection $connection_upgrade; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-Port $server_port; proxy_set_header Forwarded $proxy_add_forwarded; proxy_connect_timeout 60s; proxy_send_timeout 60s; proxy_read_timeout 60s; } } ``` Save and close the file, then edit the Nginx main configuration file. ``` nano /etc/nginx/nginx.conf ``` Add the following line after the line http {: ``` server_names_hash_bucket_size 64; ``` Save the file, then reload the Nginx service to apply the changes: ``` systemctl reload nginx ``` ## Step 6 – Access Gitea Web Interface Now, open your web browser and access the Gitea Web UI using the URL **http://gitea.example.com.** You will see the Gitea initial configuration page: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p1-1.png) ![](https://www.atlantic.net/wp-content/uploads/2024/02/p2-1.png) ![](https://www.atlantic.net/wp-content/uploads/2024/02/p3.png) Provide all the required details and click on **Install Gitea.** You will see the following screen: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p4.png) In the Register Account tab, provide your username, email, and password then click the **Register Account** button. You will see the Gitea dashboard on the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p5.png) ## Conclusion By following the steps outlined in this guide, you have successfully set up Gitea, enabling you to collaborate with your team, manage version control, and maintain code integrity within your organization. As you explore the features and capabilities of Gitea, remember to regularly update the application and implement best practices for security and user management to ensure a reliable and robust Git hosting environment. With Gitea installed, you are well-equipped to streamline your development workflow and foster collaboration among your team members. You can now try to host your own repository using Gitea on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Syncthing on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-syncthing-on-ubuntu-24-04/ | Published: 2024-05-13 | Updated: 2025-10-02 | Author: Hitesh Jethva Syncthing is a powerful and secure open-source file synchronization tool that synchronizes files across multiple devices and platforms. Whether you need to synchronize files between your computers, servers, or mobile devices, Syncthing offers a decentralized and flexible solution that prioritizes privacy and security. Syncthing lets you create your private file synchronization network, ensuring your data remains controlled and protected from third-party access. In this guide, we will walk you through the step-by-step process of installing Syncthing on Ubuntu 24.04. ## Step 1 – Add Syncthing Repository By default, the Syncthing package is not included in the Ubuntu central repository, so you will need to add the Syncthing official repo to the APT source list. First, install the required dependencies: ``` apt update -y apt install curl gpg -y ``` Next, download the Syncthing GPG key: ``` curl -fsSL https://syncthing.net/release-key.txt | gpg --dearmor -o /etc/apt/trusted.gpg.d/syncthing.gpg ``` Next, add the Syncthing repository to APT. ``` echo "deb [signed-by=/usr/share/keyrings/syncthing-archive-keyring.gpg] https://apt.syncthing.net/ syncthing stable" | sudo tee /etc/apt/sources.list.d/syncthing.list ``` Next, update the repository index. ``` apt update ``` ## Step 2 – Install Syncthing At this point, the Syncthing repository is ready. You can now install Syncthing using the apt command: ``` apt install syncthing ``` Once Syncthing is installed, you can verify the Syncthing installation using the following command: ``` syncthing --version ``` You will see the Syncthing version in the following output: ``` syncthing v1.27.2-ds4 "Gold Grasshopper" (go1.22.2 linux-amd64) debian@debian 2024-11-08 06:50:53 UTC ``` ## Step 3 – Manage Syncthing Service By default Syncthing service is managed by systemd. You can easily start, stop, and disable the Syncthing service via the systemctl command. To start the Syncthing service, run: ``` systemctl start syncthing@root.service ``` To enable the Syncthing service, run: ``` systemctl enable syncthing@root.service ``` To check the status of the Syncthing service, run: ``` systemctl status syncthing@root.service ``` Output: ``` ● syncthing@root.service - Syncthing - Open Source Continuous File Synchronization for root Loaded: loaded (/usr/lib/systemd/system/syncthing@.service; disabled; preset: enabled) Active: active (running) since Wed 2025-05-14 06:44:27 UTC; 38s ago Docs: man:syncthing(1) Main PID: 5670 (syncthing) Tasks: 15 (limit: 4609) Memory: 15.2M (peak: 15.7M) CPU: 1.520s CGroup: /system.slice/system-syncthing.slice/syncthing@root.service ├─5670 /usr/bin/syncthing serve --no-browser --no-restart --logflags=0 └─5677 /usr/bin/syncthing serve --no-browser --no-restart --logflags=0 May 14 06:44:29 ubuntu syncthing[5670]: [VD6A4] INFO: QUIC listener ([::]:22000) starting May 14 06:44:29 ubuntu syncthing[5670]: [VD6A4] INFO: Loading HTTPS certificate: open /root/.local/state/syncthing/https-cert.pem: no such file or directory May 14 06:44:29 ubuntu syncthing[5670]: [VD6A4] INFO: Creating new HTTPS certificate May 14 06:44:29 ubuntu syncthing[5670]: [VD6A4] INFO: GUI and API listening on 127.0.0.1:8384 May 14 06:44:29 ubuntu syncthing[5670]: [VD6A4] INFO: Access the GUI via the following URL: http://127.0.0.1:8384/ May 14 06:44:29 ubuntu syncthing[5670]: [VD6A4] INFO: My name is "ubuntu" May 14 06:44:29 ubuntu syncthing[5670]: [VD6A4] WARNING: Syncthing should not run as a privileged or system user. Please consider using a normal user account. May 14 06:44:29 ubuntu syncthing[5670]: [VD6A4] INFO: Completed initial scan of sendreceive folder "Default Folder" (default) May 14 06:44:42 ubuntu syncthing[5670]: [VD6A4] INFO: Joined relay relay://172.93.167.234:22067 May 14 06:44:49 ubuntu syncthing[5670]: [VD6A4] INFO: Detected 0 NAT services ``` ## Step 4 – Configure Syncthing By default, Syncthing listens on localhost. To access Syncthing from the outside world, you will need to configure It to listen on your server IP. Edit the Syncthing configuration file. ``` nano /root/.local/state/syncthing/config.xml ``` Find the following line: ```
127.0.0.1:8384
``` Replace it with the following line: ```
your-server-ip:8384
``` Save and close the file, then restart the Syncthing service: ``` systemctl restart syncthing@root.service ``` ## Step 5 – Access Syncthing Web UI Now, open your web browser and access the Syncthing web interface using the URL **http://your-server-ip:8384.** You will see the Syncthing dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/05/syncthinc.png)   You can now follow the same steps to install Syncthing on another server and share files and folders between both servers. ## Conclusion In this guide, we’ve covered the steps to install Syncthing, configure its settings, and access its web interface for managing file synchronization across your devices. With Syncthing, you can synchronize files seamlessly, collaborate with others, and access your data from anywhere without relying on third-party cloud services or compromising the security of your files. You can try deploying Syncthing on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Nextcloud AIO on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-nextcloud-aio-on-ubuntu-22-04/ | Published: 2024-05-14 | Author: Hitesh Jethva Nextcloud All-In-One (AIO) is a comprehensive solution that integrates various components into a single package, including the Nextcloud file hosting service, a web server, a database, and other necessary dependencies. Nextcloud AIO lets you set up a self-hosted cloud storage and collaboration platform quickly and efficiently. With Nextcloud AIO, you can store, sync, and share files securely, collaborate on documents in real-time, and access your data from anywhere, using any device. This post will show you how to install Nextcloud AIO on Ubuntu 22.04. ## Step 1 – Install Docker CE By default, the latest Docker version is unavailable in the Ubuntu default repo, so,you will need to install it from their official repo. First, install all the necessary dependencies: ``` apt update -y apt install ca-certificates curl gnupg lsb-release -y ``` Next, create a directory to store the Docker GPG key. ``` mkdir -p /etc/apt/keyrings ``` Next, download the GPG key: ``` curl -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /etc/apt/keyrings/docker.gpg ``` Next, add the Docker repository to the APT source file. ``` echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null ``` Next, update the repository cache: ``` apt update ``` Finally, install the Docker CE and other required tools using the following command: ``` apt install docker-ce docker-ce-cli containerd.io docker-compose-plugin -y ``` You can verify the status of the Docker service using the following command: ``` systemctl status docker ``` Output: ``` ● docker.service - Docker Application Container Engine Loaded: loaded (/lib/systemd/system/docker.service; enabled; vendor preset: enabled) Active: active (running) since Fri 2024-02-09 07:48:16 UTC; 1h 4min ago TriggeredBy: ● docker.socket Docs: https://docs.docker.com Main PID: 27927 (dockerd) Tasks: 84 Memory: 263.4M CPU: 1min 40.313s CGroup: /system.slice/docker.service ├─27927 /usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock ├─34566 /usr/bin/docker-proxy -proto tcp -host-ip 0.0.0.0 -host-port 3478 -container-ip 172.21.0.4 -container-port 3478 ├─34572 /usr/bin/docker-proxy -proto tcp -host-ip :: -host-port 3478 -container-ip 172.21.0.4 -container-port 3478 ├─34586 /usr/bin/docker-proxy -proto udp -host-ip 0.0.0.0 -host-port 3478 -container-ip 172.21.0.4 -container-port 3478 ├─34591 /usr/bin/docker-proxy -proto udp -host-ip :: -host-port 3478 -container-ip 172.21.0.4 -container-port 3478 ├─35803 /usr/bin/docker-proxy -proto tcp -host-ip 0.0.0.0 -host-port 443 -container-ip 172.21.0.10 -container-port 443 ├─35809 /usr/bin/docker-proxy -proto tcp -host-ip :: -host-port 443 -container-ip 172.21.0.10 -container-port 443 ├─35825 /usr/bin/docker-proxy -proto udp -host-ip 0.0.0.0 -host-port 443 -container-ip 172.21.0.10 -container-port 443 └─35833 /usr/bin/docker-proxy -proto udp -host-ip :: -host-port 443 -container-ip 172.21.0.10 -container-port 443 ``` ## Step 2 – Install Nextcloud AIO First, create a directory to store all configuration files. ``` mkdir nextcloud ``` Next, change the directory to the Nextcloud and create a Docker Compose file for Nextcloud AIO. ``` cd nextcloud nano docker-compose.yml ``` Add the following configurations: ``` version: "3.8" volumes: nextcloud_aio_mastercontainer: name: nextcloud_aio_mastercontainer # This line is not allowed to be changed services: nextcloud: image: nextcloud/all-in-one:latest # Must be changed to 'nextcloud/all-in-one:latest-arm64' when used with an arm64 CPU restart: always container_name: nextcloud-aio-mastercontainer volumes: - nextcloud_aio_mastercontainer:/mnt/docker-aio-config # This line is not allowed to be changed - /var/run/docker.sock:/var/run/docker.sock:ro ports: - 80:80 - 8080:8080 - 8443:8443 ``` Save and close the file, then launch the Nextcloud AIO container using the following command: ``` docker compose up -d ``` You can verify the status of all running containers using the following command: ``` docker compose ps ``` Output: ``` NAME IMAGE COMMAND SERVICE CREATED STATUS PORTS nextcloud-aio-mastercontainer nextcloud/all-in-one:latest "/start.sh" nextcloud 8 seconds ago Up 7 seconds (health: starting) 0.0.0.0:80->80/tcp, :::80->80/tcp, 0.0.0.0:8080->8080/tcp, :::8080->8080/tcp, 0.0.0.0:8443->8443/tcp, :::8443->8443/tcp, 9000/tcp ``` ## Step 3 – Access Nextcloud AIO At this point, Nextcloud AIO is installed inside the Docker container. You can now access it using the URL **http://nextcloud.example.com:8080.** You will see the Nextcloud AIO setup page: Note: You can also use http://your_server_ip/settings/admin/overview ![](https://www.atlantic.net/wp-content/uploads/2024/02/p1-3.png) Copy the password from the above screen and click on **Open Nextcloud AIO Login.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p2-3.png) Paste your password and click on **Log in.** You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p3-1.png) Provide your domain name and click on **Submit domain**. You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/02/p4-1.png) Click on **Download and start containers.** Once all the containers are started, you will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p5-1.png) Copy the Nextcloud initial admin username and password and click on the **Open your Nextcloud.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p6.png) Provide your admin username and password and click on **Log in.** You will see the Nextcloud dashboard on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/02/p7.png) ## Conclusion In conclusion, installing Nextcloud All-In-One (AIO) on Ubuntu 22.04 provides a powerful and versatile platform for hosting your cloud storage and collaboration environment. This guide covered the steps to install Nextcloud AIO, configure its dependencies, set up the database, and access the Nextcloud web interface. You can test Nextcloud AIO on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Atlantic.Net Joins NVIDIA’s Cloud Service Provider Program > URL: https://www.atlantic.net/press-releases/atlantic-net-joins-nvidias-cloud-service-provider-program/ | Published: 2024-05-21 | Updated: 2026-03-02 | Author: Editorial Team *Atlantic.Net empowers customers to advance offerings through market-leading AI cloud solutions, helping to speed up the adoption of AI compute for software developers and businesses of all sizes* Orlando, FL– MAY 21, 2024 – [Atlantic.Net](https://www.atlantic.net/), a leading cloud hosting solutions provider, today announced it has joined the [NVIDIA](https://www.nvidia.com/) Partner Network Cloud Partner (NCP) program. As an NCP member, Atlantic.Net will help customers learn, build, test, develop, and deploy NVIDIA solutions more easily through the Atlantic.Net Cloud. New and existing clients can leverage the latest technology and leap into the future with low-risk AI investments as the cloud evolves. The Atlantic.Net Cloud Platform will provide customers with NVIDIA’s GPU offerings powered by [Supermicro, Inc.](https://www.supermicro.com) (NASDAQ: SMCI) server systems. “We are honored to participate in this program and to be an NVIDIA Partner Network Cloud Partner, bringing AI compute to our customers,” said Marty Puranik, CEO, and founder of Atlantic.Net. “As a 30-year veteran in the cloud space and a member of NVIDIA’s program, Atlantic.Net Cloud is ready to support organizations and developers using AI and those that may want to in the future.” Customers of Atlantic.Net can access market-leading NVIDIA GPU technologies without the burden of significant and costly upfront capital spend. Atlantic.Net helps lower the learning curve and create scalable solutions for customers of all sizes and budgets, so they can leverage NVIDIA’s groundbreaking technology powered by Supermicro’s performance-leading servers. ### **About Atlantic.Net** Atlantic.Net is a global cloud services provider with over 30 years of experience, specializing in managed and non-managed cloud server hosting solutions. With a focus on security, compliance, and simplifying the user experience, Atlantic.Net provides business-class dedicated and cloud hosting solutions globally through data centers in New York, London, San Francisco, Singapore, Toronto, Dallas, Ashburn, and Orlando regions. With 24 x 7 x 365 expert support and a range of certifications such as SSAE 18 SOC 2 and SOC 3, HIPAA and HITECH Audits, Atlantic.Net is known for providing reliable and exceptional service, simplifying complex technologies, and building a brand that businesses have trusted since 1994. For more information, please visit [www.atlantic.net](https://www.atlantic.net/). --- # Atlantic.Net Joins Forces with NVIDIA > URL: https://www.atlantic.net/announcements/atlantic-net-joins-forces-with-nvidia/ | Published: 2024-05-21 | Updated: 2026-02-28 | Author: Alexander Wise ![](https://www.atlantic.net/wp-content/uploads/2024/05/icon_GPU-Server.png) ## Affordable GPU Cloud Servers In a move set to shake up the AI industry, Atlantic.Net has joined forces with NVIDIA as an NVIDIA Partner Network Cloud Partner (NCP) to bring the power of GPU processing to on-demand cloud computing. This collaboration will simplify access to cutting-edge Artificial Intelligence (AI) solutions. With straightforward, on-demand payment options, you can leverage powerful dedicated servers, each with a powerful CPU, super-fast NVME storage, large-capacity RAM, and now an enterprise-grade NVIDIA GPU. **We have two types of GPU available, with more to be added soon:** - **NVIDIA L40S GPU** – For general AI tasks, Machine Learning, and Deep Learning. - **NVIDIA H100 NVL** – For more demanding workloads, such as advanced AI and Deep Learning. ![](https://www.atlantic.net/wp-content/uploads/2024/05/icon_Why-Choose.png) ## The Advantages of GPU Cloud Computing from Atlantic.Net With Atlantic.Net’s powerful GPU cloud computing solutions, businesses can expect lots of benefits, including: - **Accelerated AI Development:** GPUs significantly reduce training times for deep learning models, enabling businesses to bring AI applications to market faster. - **Cost Reduction:** GPU cloud servers eliminate the need for costly upfront investments in hardware and maintenance, making AI accessible to organizations of all sizes. - **Effortless Scaling:** Atlantic.Net’s scalable cloud infrastructure allows businesses to easily adjust their GPU resources to meet evolving needs. - **Expert Support:** Atlantic.Net provides comprehensive, around-the-clock support for dedicated GPU cloud servers, ensuring businesses can maximize their investment in AI and receive assistance whenever needed ![](https://www.atlantic.net/wp-content/uploads/2024/05/icon_Unlock-the-Power-of-AI.png) ## Unlock the Power of AI with Atlantic.Net So what exactly can you do with Atlantic.Net’s GPU cloud servers? GPU Servers are perfect for a wide range of applications. Here are the top 10 uses of dedicated GPU cloud servers: **Deep Learning:** Atlantic.Net’s GPU cloud servers are ideal for deep learning, enabling the training and deployment of complex neural networks. These networks excel in tasks such as image recognition, natural language processing, and a variety of other AI applications, providing businesses with the tools they need to advance their AI capabilities. **Inference:** Inference tasks benefit immensely from Atlantic.Net’s GPU cloud servers, allowing AI models to run in real-time and make swift predictions and decisions. This capability is perfect for applications like chatbots or hosting your own GPT solution, ensuring responsive and efficient performance for end-users. **High-Performance Computing:** Accelerate scientific simulations, financial modeling, and other computationally intensive workloads. This increased speed and efficiency help empower your business to tackle complex tasks more effectively, leading to faster results and deeper insights. **Video Editing and Rendering:** GPUs are still superb at rendering graphics. Dramatically speed up video processing tasks like rendering, encoding, and effects application. The superior graphics processing capabilities make them indispensable for media professionals who need to deliver high-quality video content efficiently and quickly. **3D Animation, Modeling, and Graphic Design:** Animators can accelerate queued rendering times for complex 3D scenes and models, enabling faster iterations and higher-quality output. **Computer-Aided Design (CAD) and Computer-Aided Engineering (CAE):** Enhance performance and rendering in CAD applications. Preview faster simulations and design iterations, even in real-time. Accelerate complex engineering simulations and analyses, reducing time to market for new products. **Product Visualization:** Generate high-quality, photorealistic product renders and simulations for marketing and sales purposes. Create visually stunning and accurate representations of your product, enhancing promotional efforts and customer engagement. **Medical Imaging:** Accelerate processing of medical images like CT scans and MRIs, enabling faster diagnosis and treatment planning. Combined with Atlantic.Net’s [HIPAA-Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/), you can rest easy that your business operations remain secure and protected. **Drug Discovery and Genomics:** Big Pharma experts can speed up medical simulations of molecular interactions and drug-target binding, aiding in the development of new therapeutics and predictions. Accelerate analysis of large genomic datasets to help identify disease-causing genes and potential treatments. **Risk Modeling and Fraud Detection:** Perform complex financial simulations and risk analyses in real-time, informing investment decisions and risk management strategies. Analyze massive amounts of financial data to identify patterns and anomalies indicative of fraudulent activity. We have just scratched the surface of what Atlantic.Net GPU cloud servers are capable of doing. Our customers are finding innovative and unique ways to make use of the raw power being made available thanks to NVIDIA GPUs. ![](https://www.atlantic.net/wp-content/uploads/2024/05/icon_GPU-Server-Hosting.png) ## Atlantic.Net GPU Server Hosting If you’re looking for a GPU server hosting provider that can deliver the performance, reliability, and support you need to succeed, look no further than Atlantic.Net. Our GPU cloud servers are an ideal platform for businesses looking to harness the power of AI to help drive innovation and growth. If you’re seeking a GPU server hosting provider that delivers performance, reliability, and exceptional support, look no further than Atlantic.Net. Don’t wait—rent a [GPU server from Atlantic.Net](https://www.atlantic.net/gpu-server-hosting/) today and experience the transformative power of GPU cloud computing. --- # NVIDIA GPU Server Hosting for AI, ML and HPC > URL: https://www.atlantic.net/gpu-server-hosting/ | Updated: 2026-09-16 Launch on-demand Cloud GPU or Dedicated GPU Servers with NVIDIA L40S or H100 NVL acceleration for generative AI, LLMs, rendering, data analytics, scientific workloads, and high-performance computing, with 24x7x365 expert support. - NVIDIA NCP Cloud Partner - L40S & H100 NVL GPUs - Cloud & Dedicated Options - 24x7x365 Expert Support On-Demand GPU Cloud: 60 Seconds H100 NVL Memory Bandwidth: 3.9 TB/s ## Next-Gen Cloud and Dedicated GPU Servers, Accelerated by NVIDIA NVIDIA Partner Network Cloud Partner (NCP) Experience unparalleled performance with dedicated and cloud GPU servers equipped with the revolutionary NVIDIA accelerated computing platform. Choose from the NVIDIA L40S GPU and NVIDIA H100 NVL to unleash the full potential of your generative artificial intelligence (AI) workloads, train large language models (LLMs), and deploy natural language processing (NLP) in real time. The NVIDIA accelerated computing platform is superb at scientific research, 3D graphics and rendering, medical imaging, climate modeling, and more. ## GPU Cloud Hosting Pricing Plans | | | | | | | | | --- | --- | --- | --- | --- | --- | --- | | AL40S.192GB | 192GB | 32 | 1 x L40S | 1400GB | 12 TB | On-Demand: $1,120.9/mo $1.668/hr; 1-Year: $1,108.0/mo $1.6488/hr; 3-Year: $1,058.7/mo $1.5755/hr | | AH100NVL.240GB | 240GB | 28 | 1 x H100NVL | 2400GB | 15 TB | On-Demand: $2,648.4/mo $3.941/hr; 1-Year: $2,546.7/mo $3.7898/hr; 3-Year: $2,407.8/mo $3.583/hr | *The hourly rate for GPU Cloud Servers is determined by dividing the monthly rate by 730 hours. There is no additional cost for going over 730 hours in a given calendar month and usage below 730 hours will be billed at the hourly billing rate. *Prices listed above are based on the service being utilized for the period specified. *All Servers include one IPv4 Address. Additional IPs are available for $3.65/month ($0.005431/hour) *Unlimited inbound bandwidth. If free outbound bandwidth is exceeded, each additional GB is $0.02 *Optional Daily Backups are available for 20% of the server price. Minimum $1.00/month. *cPanel licensing cost starts at $23 per month ## Atlantic.Net Cloud GPU Hosting Massive Computing Power Up in 60 Seconds! Transform your AI models and ML workflows with Atlantic.Net. Discover the power and speed of our On-Demand GPUs in the Cloud. ## More Resources ### Proxmox Virtualization on Bare Metal: Performance, Cost, and Compliance Compared to Public Cloud [Read More >](https://www.atlantic.net/dedicated-server-hosting/proxmox-virtualization-on-bare-metal-performance-cost-and-compliance-compared-to-public-cloud/) ### OpenClaw (ClawdBot): Open-Source AI Agent – and How to Deploy It on Atlantic.Net Cloud [Read More >](https://www.atlantic.net/cloud-platform/openclaw-open-source-ai-agent-and-how-to-deploy-it-on-atlantic-net-cloud/) ### HIPAA Compliant Hosting Solutions by Atlantic.Net [Read More >](https://www.atlantic.net/hipaa-compliant-hosting/) ### Managed Services by Atlantic.Net [Read More >](https://www.atlantic.net/managed-services/) ## GPUs Available on Atlantic.Net Our dedicated high-performance servers are available in two powerful configurations: | Feature | NVIDIA L40S GPU | NVIDIA H100 NVL | | --- | --- | --- | | Architecture | Ada Lovelace | Hopper | | CUDA® Cores | 18,176 | 14,592 | | Tensor Cores | 568 | 456 | | RT Cores | 142 | 0 | | Memory | 48GB GDDR6 with ECC | 94GB HBM3 | | Memory Bandwidth | 864 GB/s | 3.9 TB/s | | FP32 Performance | Up to 91.6 TFLOPS | Up to 60 TFLOPS | | FP8 Performance | Up to 1,466 TFLOPS with Sparsity | Up to 3,341 TFLOPS with Sparsity | | Transformer Engine | 4th Gen | 4th Gen | | Primary Use Cases | Versatile AI, Graphics, Video | Large-scale AI, High-Performance Computing | NVIDIA L40S GPU is great for general AI tasks, machine learning and deep learning. NVIDIA H100 NVL is more powerful with much higher memory bandwidth, making it perfect for advanced AI and deep learning requirements. ## Choosing the Right GPU ### NVIDIA L40S GPU Experience breakthrough multi-workload performance with the NVIDIA L40S GPU. Combining powerful AI compute with best-in-class graphics and media acceleration, the L40S GPU is built to power the next generation of workloads – from generative AI and large language model (LLM) inference and training to 3D graphics, rendering, medical imaging, video, and virtual desktops. ### NVIDIA H100 NVL The most optimized platform for LLM inferences with its high compute density, high memory bandwidth, high energy efficiency, and unique NVIDIA® NVLink™ communications protocol. It also delivers unprecedented acceleration to power the world's highest-performing AI, data analytics, complex calculations and simulations, and high-performance computing (HPC) applications. ## Why Choose Atlantic.Net for GPU Cloud Servers? Atlantic.Net, a leading provider of cloud services, is renowned for its award-winning cloud infrastructure, reliable performance, and commitment to customer satisfaction. With the new partnership with NVIDIA, Atlantic.Net is now offering a range of GPU cloud servers designed to meet the diverse needs of businesses and developers. Whether you need a dedicated GPU server for improved performance and flexibility, or a cloud GPU to process data for deep learning algorithms, Atlantic.Net has you covered. Our dedicated GPU cloud servers are accelerated by NVIDIA computing platforms, ensuring optimal performance for even the most demanding AI workloads. ## The Advantages of GPU Cloud Computing from Atlantic.Net. With Atlantic.Net's powerful GPU cloud computing solutions, businesses can expect lots of benefits, including: - Accelerated AI Development: GPUs significantly reduce training times for deep learning models, enabling businesses to bring AI applications to market faster. - Cost Reduction: GPU cloud servers eliminate the need for costly upfront investments in hardware and maintenance, making AI models accessible to organizations of all sizes. - Effortless Scaling: Atlantic.Net's scalable cloud infrastructure allows businesses to easily adjust their GPU resources and add multiple GPUs to meet evolving needs. - Expert Support: Atlantic.Net provides comprehensive, around-the-clock support for dedicated GPU cloud servers, ensuring businesses can maximize their investment in AI models and receive assistance whenever needed. ## Atlantic.Net GPU Server Hosting If you're looking for a GPU server hosting provider that can deliver the performance, reliability, and support you need to succeed, look no further than Atlantic.Net. Our GPU cloud servers are an ideal platform for businesses looking to harness the power of AI to help drive innovation and growth. ## Use Cases: NVIDIA L40S GPU Versatile AI, Graphics, and Video ### Generative AI and Content Creation Unleash your creativity with the L40S. Generate stunning images, videos, and 3D models using AI-powered tools. Accelerate your creative workflows with real-time rendering and video editing capabilities. ### AI-Enhanced Video Conferencing Transform your virtual meetings with the L40S. Enhance video quality with AI-driven upscaling and noise reduction, ensuring clear and crisp visuals even in low-bandwidth environments. Add virtual backgrounds and avatars for a more engaging experience. ### Medical Imaging and Analysis Accelerate the processing and analysis of medical images with the L40S. Aid in the diagnosis of diseases and the development of new treatments by leveraging AI models to detect subtle patterns and anomalies in scans and X-rays. ## Use Cases: NVIDIA H100 NVL Large-Scale AI and High-Performance Computing (HPC) ### Natural Language Processing (NLP) Develop sophisticated language models that can understand, generate, and translate human language with unprecedented accuracy. The H100 NVL powers the training and deployment of these models for applications like chatbots, virtual assistants, and language translation services. ### High-Performance Data Analytics Analyze massive datasets and uncover hidden insights with the H100 NVL. Accelerate your data processing pipelines and gain a competitive edge in fields like finance, marketing, and scientific research. ### Scientific Simulations and Modeling Map weather patterns, compute protein folding, and model astrophysical events with unparalleled speed and accuracy. ## Managed Services Options What sets Atlantic.Net apart from other cloud hosting providers is the depth and breadth of our managed cloud hosting services and 24x7x365 expert technical support. Managed Services are available to all customers. ### Round-the-Clock Server Management Free you and your staff up to focus on the bigger picture and rely on our experts' deep technical knowledge. Choose Atlantic.Net Server Management and let our team of highly skilled experts secure, monitor, manage, and support your virtual server or servers 24x7x365. In addition to server monitoring and management, our team can also manage your security patching, firewalls, advanced DDoS protection, anti-malware, backups, and more. ### Server Migration Atlantic.Net understands that migrating your production and development environments to a new web host can be daunting for you and your team, especially considering that many IT teams are often already stretched thin. Our migration specialists are available to help you with a smooth migration and can be involved as much or as little as you want. Please check our Migration Services Page for further information. ### 24x7x365 Support Atlantic.Net provides email and phone support for all customers, and our response times are incredibly quick at no additional cost to you. We endeavor to provide a first-time fix on all issues raised in a timely fashion, 24 hours a day. ### Multi-Factor Authentication Service Cyber Security is so important, and one of the most effective ways to thwart attacks is to use a Multi-Factor Authentication (MFA) Service. MFA helps to verify and authenticate all of your users' identities before granting access to your server environment. Our simple and secure Multi-Factor Authentication Service is the easiest way for users to verify their identity before being granted access to your VPN, Linux (SSH), and Windows Servers (RDP). ### Network Edge Services The network edge is quickly becoming a requirement for in-demand businesses to help offload large portions of the workload your server does to an edge service. Options include web application firewalls (WAF), Content Delivery Networks (CDN), web optimization, and more. ## Dedicated Server with GPU Q&A ### What is a GPU server? A GPU server is a specialized computer designed to accelerate tasks like AI, machine learning, and graphics rendering by using powerful graphics processing units (GPUs) in addition to traditional CPUs. GPUs are not just for gaming – they turn already powerful dedicated servers into extreme number-crunching powerhouses. A GPU server is a high-performance computing platform designed for intensive tasks. The architecture features one or more graphics processing units that significantly accelerate workloads like deep learning, machine learning, data analysis, and AI training. GPU parallel-processing capabilities make them ideal for handling massive datasets and complex algorithms needed by modern AI/ML applications. ### How does a GPU improve performance? Enterprise GPUs accelerate workloads using parallelism and specialized hardware like tensor cores, offloading compute-intensive tasks from CPUs and maximizing throughput for demanding applications like AI, machine learning, and data analytics. GPUs excel at calculating complex algorithms at tremendous speed. ### Why do I need GPU server hosting from Atlantic.Net? Atlantic.Net is leading the way with affordable GPU cloud servers – whether you need them for deep learning or inference, a GPU cloud server is available on demand. The GPUs we deploy are extremely capital-intensive, but Atlantic.Net's on-demand model lets you use these services for as long as you need them without the upfront hardware cost. ## Atlantic.Net Cloud GPU Hosting Massive Computing Power Up in 60 Seconds! Transform your AI and ML workflows with Atlantic.Net. Discover the power and speed of our On-Demand GPUs in the Cloud. ## GPU Hosting Plans ### Fortress Business GPU Hosting H100 NVL GPU $4,729.44 Per Month 28 vCPU's 240 GB of DDR 5 Ram 2.4 TB NVMe SSD Raid 10 Storage 10 TB of Monthly Data Transfer Fully Managed Hosting Package Fully Managed FortiGate Firewall with Intrusion Prevention System ( 5 ) Managed VPN's Fully Managed Daily Backups ( Local ) Fully Managed Daily Backups ( Off-Site ) DUO Proxy Multi-Factor Authentication ( 5 users ) TrendMicro Security Suite Fully Managed DDos / CDN / WAF Scheduled Vulnerability Scans Contact Us To Get Started ### Fortress Custom GPU Hosting Maximum security, customization, and premium SLAs Custom Bare Metal Hosting Fully Managed Hosting Package Fully Managed FortiGate Firewall with Intrusion Prevention System ( 5 ) Managed VPN's Fully Managed Daily Backups ( Local ) Fully Managed Daily Backups ( Off-Site ) DUO Proxy Multi-Factor Authentication ( 5 users ) TrendMicro Security Suite Fully Managed DDos / CDN / WAF Scheduled Vulnerability Scans Contact Sales *$450 setup fee applies *Pricing based upon 12-month term commitment *Prices based upon Linux Operating System. Windows Operating System available at an additional cost. ***Save up to 30% off above listed pricing with longer billing terms*** *Due to global supply-chain volatility, Dedicated Host pricing is subject to change but will be confirmed prior to deployment. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Network Edge > URL: https://www.atlantic.net/managed-services/network-edge/ | Published: 2024-05-28 | Updated: 2025-10-21 | Author: Richard Bailey ## What Is the Network Edge? The network edge is the connection point between your private network and the Internet, strategically placed to minimize user wait times when accessing cloud-based network resources. It is a connection or interface made between geographically disparate devices. It is used to reduce latency and improve efficiency by presenting interfaces at locations typically closer to the user. ## Latency on the Web If you are unfamiliar with IT and the cloud, it can be challenging to understand the concept of the [Network Edge](https://www.atlantic.net/managed-services/network-edge-protection/). Remember that edge networking will determine your applications’ overall performance, which impacts the user experience. For example, if a user is based in South America and consumes an application hosted on servers in Europe, the geographical location of the provider and the user would introduce a certain amount of latency. When the user sends a request to the application, that request travels 6000 miles to the European servers, which then responds with an answer that has to travel 6000 miles back to the user. This happens thousands of times per second, so you can see how this can introduce lag or latency. ## How Does Network Edge Infrastructure Help? Network edge infrastructure introduces a cached copy of the application at another edge computing location, also based in South America. Now, the user’s requests only have to travel a short distance to content delivery networks located close by. Creating this physically distributed computing paradigm introduces lots of extra benefits, such as cost savings, such as allowing the provider to configure robust security, and it saves the end user money on expensive egress network costs. What other benefits are introduced by processing data at the network edge? ### #1: Reduced Latency: By processing data locally across more devices, the network edge minimizes the distance information needs to travel, resulting in lower latency and faster response times. This is crucial for real-time data analysis in applications like IoT devices, autonomous vehicles, or industrial automation. ### #2: Enhanced Security: Less data travels across the network, minimizing the vulnerability to breaches during data transmission itself. Additionally, security measures like encryption can be implemented directly on edge devices to improve data protection. Edge computing can also give you more granular control allowing improved data privacy and security policies for different devices and locations. ### #3: Improved Reliability: [Edge computing](https://www.atlantic.net/managed-services/understanding-network-edge-computing-devices/) lessens dependence on constant cloud connectivity for data generation. Local processing ensures operations continue even if there’s a wider network disruption. ### #4: Cost-Effectiveness: Localized data processing, often enabled by network functions virtualization, reduces reliance on expensive, dedicated hardware, potentially leading to even lower operational costs. Processing data with edge computing will help you save on your egress traffic costs simply because the network traffic is processed locally and stays on the local network. ### #5: Better Performance: Instead of overloading the network by sending massive amounts of raw data to the cloud, edge devices can pre-process and filter process data, reducing latency by transmitting only the most important requests. This reduces bandwidth requirements and costs. A good example is having a database read replica at an edge location; local users read directly from that database instead of querying the master database. The network edge is a designated area of a broader core network closer to your customers or employees. When using a core network-to-edge network design, the world gets much smaller. Users experience faster speeds, services are highly secured, and even the costs are lower! ## What Is the Difference Between Network Edge and Perimeter? The terms network edge and network perimeter are often used interchangeably, and despite sharing many similar traits, they are very different concepts. We already know that the *network edge* is where individual devices, users, and applications directly connect to the Internet or a distributed network. Alternatively, the *network perimeter* is a defined line of separation between an organization’s private, internal network and the uncontrolled, public Internet. ### Key Differences #### Network Perimeter - Single, well-defined boundary - Protects the internal network - Centralized security model, defended by firewalls - Works well with traditional cloud computing #### Network Edge - Vast, ever-changing environment - Designed to protect devices, users, and data - Decentralized, device-level security - Great for IoT devices ## What Is the Difference Between the Edge and the Core in an Access Network? An access network is the part of the telecommunications network that bridges the gap between end-users physical devices (homes, businesses, data centers, mobile devices) and a service provider’s core network. It’s the connection that gets internet traffic to and from your devices. Your ISP is an access network. ### The Edge (Front Line) The edge of the access network is the point where end-user devices physically connect to other devices and networks. Customer premises equipment (CPE) includes routers, modems, and optical network terminals (ONTs) in your home, as well as cell phones and business connections. The purpose of the edge is to collect traffic from individual users and devices. It is a centralized data center that aggregates the data (clusters the data together) and sends it to its destination. IoT devices use the edge to send data to a target. The edge can handle routing, quality of service (QoS), and security functions. ### The Core (Backbone) The core is centralized within the service provider’s network, away from the user. It acts as the high-speed backbone or virtual network that carries large volumes of aggregated traffic from the data center to multiple edge locations. The network core uses powerful routers and switches to manage significant volumes of data. The network core directs traffic to a provider’s edge networks and broader network infrastructure, ultimately connecting it to the Internet or other destinations. Its purpose is to transmit data at scale, from any edge location. The network core handles complex routing and can enforce advanced security policies. Essentially, the network core’s purpose is to connect the edge networks and wider Internet to other service provider networks and enterprise applications. In summary, the edge acts as the entry point for user traffic, while the network core provides the powerful infrastructure that carries and directs that traffic to its final destination. ## Is a Smartphone an Edge Computing Device? Yes, a smartphone can be called a network edge device. This is because all smartphones connect directly to the Internet and cellular networks. Logically, the cell phone is often the outermost point of an edge network, making cell phones edge devices as far as network infrastructure is concerned. Another reason is that smartphones crunch data. They generate and consume significant amounts of data, which originates and terminates at the smartphone, making it an edge device. Modern smartphones are substantially more powerful than their predecessors of 5 or 10 years ago. They have significant processing capabilities that can analyze data and perform image recognition; the latest generation devices even have AI built into the handset, making edge computing one of the most important functions of a smartphone. ## Do I Need Network Edge Protection? The network edge is everywhere. You probably use edge devices daily without even considering that you are using them. Whether you need the network edge for your business requires a more detailed answer. It depends on various factors such as the size of your business network, whether or not you handle sensitive data, and also your risk tolerance. Before we discuss why you may need Network Edge protection, let’s consider who needs it. Edge protection is suitable for literally all types of businesses, from small businesses to large enterprises. Everyone needs to face up to the risk of cyberattacks. The size of your organization’s network doesn’t determine your vulnerability. The number of people working remotely is still high, even after the Covid-19 pandemic has subsided. Since the rise of remote working, the network edge has expanded significantly. Protecting remote connections is crucial to preventing unauthorized access to corporate networks. Also, if you rely on cloud services, your data already travels through the network edge. Ensuring its security is paramount. This is even more important if your IoT devices are often connected at the edge, making them potential entry points for attacks. Protecting them is essential for overall network security. Now, lets consider the crucial reasons why you may need Network Edge Protection: - **An Ever-Changing Threat Landscape:** Cyberattacks are increasingly sophisticated and frequent. The network edge, being the most exposed part, is a prime target. Protecting it is essential to safeguard your entire network. - **Data Protection:** Most organizations have valuable data that needs protecting, whether it’s customer information, healthcare data, intellectual property, or financial records. A breach at the edge can compromise this data, leading to significant financial and reputational damage. - **Business Continuity:** Disruptions or attacks at the edge can severely impact business operations, leading to downtime, lost productivity, and customer dissatisfaction. Edge protection helps ensure business continuity. - **Compliance:** Many industries have regulatory requirements, such as HIPAA or PCI-DSS, regarding data protection and network security. Edge protection is often a mandatory requirement needed to meet compliant status. Finally, let’s consider the most common types of network edge protection available. The front line of defense is the network Firewall. These are used across the network to filter incoming and outgoing traffic based on predetermined rules. They are either hardware appliances or software-based [web application firewalls](https://www.atlantic.net/managed-services/firewall/) (WAF). Both are proven technologies that filter out unwanted and malicious traffic. Next, **Intrusion Detection Systems (IDS)**monitor network traffic for suspicious activity and automatically [block potential threats](https://www.atlantic.net/managed-services/intrusion-detection-service/). An IPS is an intelligent application that first creates a baseline security profile, which determines your security stance. Any deviations from normal activity are reported. Offenses are classified, and alerts are created that are either automatically fixed or logged for manual triage. Another popular tool is Secure Web Gateways (SWG). These control web access and protect against web-based threats. The secure web gateway sits between users and the Internet to filter traffic and enforce acceptable use and security policies. ### Living on the Edge with Atlantic.Net Atlantic.Net is a cloud hosting and managed service provider with an expansive cloud platform with points of presence throughout the United States, Canada, Europe, and the Far East. Atlantic.Net offers a suite of managed services designed to protect and further optimize traffic at the network edge. **Network Edge/DDoS Protection:** This service safeguards against distributed denial-of-service (DDoS) attacks, which can overwhelm your network and disrupt operations. It helps ensure your network remains available and responsive, even under attack. **Firewall:** Atlantic.Net offers managed web application firewall services to filter traffic and protect your network from unauthorized access and malicious activity. **Intrusion Detection System (IPS):** Our IDS service actively monitors network traffic for signs of intrusion and takes action to prevent or block attacks. Looking to boost your network’s speed, security, and cost-efficiency? The network edge is the key. By bringing your applications and data closer to your users, you can reduce latency, enhance security, and even lower your bandwidth costs. Contact [Atlantic.Net](https://www.atlantic.net/about-us/corporate-contact/) today to learn how our managed services can help you secure and optimize your network edge. --- # Understanding Network Edge Computing Devices > URL: https://www.atlantic.net/managed-services/understanding-network-edge-computing-devices/ | Published: 2024-05-29 | Updated: 2024-06-03 | Author: Richard Bailey ## What Is Network Edge Computing? Distributed cloud computing at the edge, or network edge computing, is when service providers use distributed computation and data storage closer to the data source, typically the user. In edge computing, data processing takes place nearer to the user on devices like smartphones, IoT sensors, or edge servers – unlike cloud computing, where processing primarily takes place in the data center. Decentralized computing reduces latency, optimizes bandwidth usage, improves reliability, and enhances the network’s security and privacy. Consider your favorite streaming services, such as Netflix or Disney Plus. These companies have powerful servers located all over the world. Before edge computing systems, when you pressed play on a movie, the request traveled halfway across the globe to a data center. The data center finds the video, processes it, and sends it back to you. When many people are watching and the data center gets overwhelmed, your video might buffer or lag. If you remember RealPlayer in the 1990s, you’d load a media file from storage or download it from the Internet, then process and play it on your local machine. When you stream a video on your device today, companies like Netflix use local edge computing nodes to support streaming. In this model, when you click play, your request goes to a nearby server that already has a copy of the video stored, so it starts playing instantly. Even if several people are simultaneously watching, the load gets spread out among many servers, resulting in zero lag or buffering. ### **The Rise of Edge Computing** Data at the edge is not a new concept. Edge computing environments have been built over many years as the Internet has grown, and there has been a greater demand for reliable network performance. There has been a proliferation of IoT devices, industrial sensors, and other connected technologies that generate unprecedented amounts of data. Sending all this data to a central data center is becoming increasingly impractical due to bandwidth limitations, latency concerns, and cloud provider egress costs. Many emerging technologies and data-intensive applications, such as self-driving cars, augmented reality, and remote enterprise applications, require near real-time data processing and adequate network bandwidth to function effectively. One of the benefits of edge computing is that it enables these applications to respond instantly to events without the delays caused by sending data over long distances. A single centralized data center exacerbates bandwidth constraints and bottlenecks, causing complications. Networks struggle to cope with the ever-increasing volumes of data. Edge computing alternatively reduces the amount of data transmitted over a wide area network, easing congestion and saving bandwidth and computing resources. Sending sensitive data over long distances can also increase the risk of security exposure. Edge computing improves operational efficiency and addresses these concerns by processing and storing data locally, minimizing the risk of interception or unauthorized access. Perhaps you have a fleet of medical devices bound by HIPAA compliance—when using an edge deployment, having a point of presence geographically near the source reduces risk and satisfies compliance. Remember, edge services can reduce the cost of transmission, computation, and data storage by processing data locally and only sending relevant insights or aggregated data to a central data center. This can create serious cost savings, especially when handling large egress data volumes. ### **The Architecture of Edge Computing** Edge computing is not a single technology but rather a distributed computing architecture that manages connected devices within a software-defined networking architecture. It protects client devices from threats based on the global internet. Let’s take a moment to understand what components make up the edge computing environment of local cloud data centers. An **Edge Device**is the source of data generation. It can be anything that can process data, from simple sensors to complex medical equipment. It can be smart devices, cell phones, edge nodes, or an entire edge data center. IoT devices are most commonly found on the [network edge](https://www.atlantic.net/managed-services/network-edge/). There is an estimated 15 billion IoT devices globally. The volume of raw data such devices produce is difficult to comprehend, but it is easy to see how network congestion occurs and how system performance is impacted. Edge devices typically have limited processing power and storage capacity, so keeping all that data on **Edge Nodes**makes sense. Another critical component of the edge network is **Edge Gateways**. These more powerful devices aggregate data from multiple edge devices, perform some initial processing, and filter or preprocess data before sending it to an edge server or a central data center. Edge gateways play a crucial role on the edge “backbone.” They serve as the primary pathway for information between edge computing systems and a user’s computer. Gateways can decide how data processing flows, including filtering and prioritization. They also decide how to send the data: over the Internet or a 5G cell network infrastructure. The next critical infrastructure of an edge strategy is **Edge Servers**. These are powerful servers located physically close to the data sources. They handle the bulk of data processing and storage at the edge. Edge computing nodes can be located in local data centers, on-premise data centers, or even in protected enclosures for harsh environments, such as research centers in Antarctica. ### The Importance of 5G So far, we have discussed the importance of the network edge, network capacity, and network connectivity. Alongside traditional networking concepts, the recent introduction of 5G networks has been a significant development. 5G edge computing offers a super-fast digital network that provides the necessary infrastructure and capabilities to support the growing demand for low latency and high bandwidth. 5G is important because it enables significantly higher speeds and lower latency than previous generations. 5G supports a massive number of connected devices simultaneously, which is ideal for IoT devices and helps applications that demand near real-time data processing and super-fast responsiveness. 5G also allows the creation of virtualized, independent networks (slices) within the same physical infrastructure; this optimizes performance and security, helping to meet the diverse requirements of different edge workloads. ## Examples of Network Edges Edge computing is already significantly impacting our lives across various industries. It is a transformative technology that aims to make our lives easier, safer, and more efficient. ### **Impact on Our Daily Lives** There is a good chance that the benefits of edge computing are already intertwined with your daily routine. Lots of people already have smart devices in their homes. Thermostats, security cameras, and voice assistants use edge computing to process data locally for faster response times and improved security. Do you have a **smart speaker** like an Alexa? It is also considered a network-edge device! Newer Echo devices use the AZ1 Neural Edge processor, designed to speed up machine learning tasks on the device itself, including speech recognition and natural language processing. Home **security devices** like Ring cameras process video footage locally to detect motion, recognize faces, or identify specific events. Using data at the edge allows for faster alerts and reduces the amount of data sent to the cloud, enhancing privacy. Modern **home appliances** like refrigerators, washing machines, and ovens often have built-in sensors and processing capabilities. They can optimize energy usage, predict maintenance needs, and even suggest recipes based on available ingredients. Edge computing plays a vital role in **healthcare** by enabling real-time analysis of medical data from wearable devices such as fitness trackers and heart rate monitors. Implanted sensors and hospital equipment within the local network often bypass the need for an on-premise data center. Near real-time data processing can lead to faster diagnoses, personalized treatment plans, and improved patient outcomes. Edge computing also supports remote patient monitoring and telemedicine applications while ensuring data security. Edge computing work enhances the efficiency and reliability of our **energy production** and power grids by enabling real-time monitoring and control of power generation, distribution, and consumption. Helping energy companies integrate renewable energy sources, demand response programs, and smart grid technologies while reducing the strain on centralized data centers. ### **Impact on How We Live** Have you heard of the term “**Smart Cities**?” Edge computing collects and analyzes data generated from various sources, such as traffic cameras, environmental sensors, and utility meters. If you travel on the highway, you may see this in action when traveling on smart motorways as signage reacts to adjust speed limits to help optimize traffic flow. Enterprise-generated data at the edge is transforming our **retail** experience. Shops use real-time inventory management, personalized recommendations, and targeted advertising to drive sales and improve customer service. You can now shop in stores that use “Just Walk Out” technology. This technology allows shoppers to enter the store using their smartphone, select their items, and simply walk out. The technology automatically tracks the items they take and charges their bank account. This technology would not work without edge network infrastructure, cloud computing, and centralized servers. Edge computing, often using fog computing at the network edge, is transforming **agriculture** by enabling precision farming techniques. Sensors deployed in fields collect data on soil conditions, weather patterns, and crop health. Edge computing analyzes this data in real-time, providing farmers with actionable insights for optimizing irrigation, fertilization, pest control, and, importantly, the best time to harvest their crops. Elsewhere, the **transportation and logistics**industry enables real-time tracking of vehicles and shipments, optimizing routes, and improving fleet management—all thanks to edge computing. Some logistics companies are investing in autonomous vehicles that need sensor data to make real-time decisions about navigation and safety. ## What Is the Difference Between Network Edge Devices and the Cloud? *Network edge devices* and the cloud are two core components of modern IT infrastructure, each offering distinct advantages. Edge computing handles local data processing and storage close to end-users or data sources. These devices, like routers, switches, firewalls, and IoT gateways, excel at reducing latency by processing data right where it is generated. This is crucial for applications that need real-time data analysis. It minimizes the distance data travels to ensure faster response times and an enhanced user experience. On the other hand, the *cloud* consists of remote servers and resources accessible over the internet, provided by cloud service providers like Atlantic.Net. Cloud computing is highly scalable and flexible, offering virtually limitless resources that can be scaled up or down based on demand—making it ideal for applications requiring extensive storage and processing power, such as big data analytics, machine learning, and enterprise resource planning. While on-premise data centers have been the traditional choice for many businesses, the cloud’s pay-as-you-go model lowers upfront costs and provides robust tools for resource management, though it can introduce latency due to the physical distance from end-users. Integrating edge devices with the cloud creates a hybrid approach that leverages the strengths of both. Edge computing focuses on handling immediate data processing, ensuring low latency and real-time responsiveness, while the cloud takes care of complex computations and long-term storage. This synergy, a key part of modern edge strategies, allows businesses to optimize performance, manage costs, and maintain flexibility. We will discuss how Atlantic.Net does this a little later in this article. ## Edge Servers and Computing Examples Now, let’s dig deeper and look at real-world examples involving the use of edge servers, which are transforming various industries by enabling real-time data processing and reducing latency. ### Healthcare **Remote Patient Monitoring** Hospitals and healthcare practices heavily use remote patient monitoring tools. Edge medical devices store and process information locally, and the information is then synced to a centralized data center if needed. Patients wearing biosensors like smartwatches, fitness trackers, and specialized medical wearables can continuously monitor vital signs such as heart rate, blood pressure, oxygen saturation, movement, and even biomarkers in sweat. Local edge servers allow doctors and physicians to analyze this data in real time, which improves patient care because the appropriate physicians can be immediately alerted and intervene if abnormal conditions are detected. **Medical Imaging** Edge computing processes large volumes of imaging data (like X-rays, CT scans, and MRIs) locally, speeding up analysis and diagnosis. The goal is to reduce the time patients wait for results and enable quicker treatment decisions. Edge computing helps in four key ways: - **Automating Tasks:** Such as simultaneous large-scale image processing - **Detecting Abnormalities**: thousands of images can be scanned simultaneously, and when using AI, computers can identify medical images that deviate from “normal.” - **Personalized Treatment:** treatment options can be recommended based on the patient’s personal medical imaging data. - **Clinical Decision Support**: Edge computers can help make diagnoses. For example, radiologists can gain additional insights using X-ray image analysis data. You may have seen portable ultrasound devices parked outside your nearest hospital. Edge computing enables real-time image analysis and guidance during ultrasound procedures, even in remote or resource-constrained settings. Elsewhere, specialized ambulances equipped with CT scanners use edge computing to quickly diagnose strokes and initiate treatment en route to the hospital. Healthcare is a significant area that makes edge computing important! ### Manufacturing **Predictive Maintenance** Manufacturing plants use edge servers to monitor machinery and robotic equipment in real time, and numerous sensors make this possible. - **Computer Vision**– Thermal sensors can identify temperature anomalies that could indicate unsafe or abnormal conditions. - **Sound** – Sonic and ultrasonic technology can listen and identify whether machinery is operating outside of the norm. - **Touch** – Specifically vibration – machinery that is developing faults will often abnormally vibrate; delicate sensors can identify even minute vibrations. - **Smell** – Total Volatile Organic Compounds (TVOC) sensors can detect chemical leaks such as gas. - **All Data** – Edge computers can fuse all sensor information together to get an overall picture of the machinery. By analyzing sensor data, these systems can predict when maintenance is needed, preventing costly downtime and improving operational efficiency. **Quality Control** Edge computing enhances quality control by processing data from cameras and sensors on the production line. This allows for immediate detection of defects, ensuring high standards and reducing waste. Car manufacturers such as [Audi](https://www.audi-mediacenter.com/en/press-releases/edge-cloud-4-production-how-audi-is-revolutionizing-factory-automation-14783) use edge computing to analyze images from cameras on their production lines in real-time. This enables them to quickly identify defects and take corrective action, ensuring the highest quality standards for their vehicles. ### Atlantic.Net and Network Edge Computing We hope you have enjoyed reading about edge computing. The technology has taken off in recent years, and its success is a testament to its integration into our lives. It’s so seamless that many people have not even noticed. However, if the edge did not exist, you would certainly feel the impact in your daily life. Atlantic.Net is celebrating its 30th year in business. We provide cloud computing and hosting solutions for businesses around the globe and offer a selection of network-edge solutions. Atlantic.Net’s Network Edge Protection Services help safeguard your important data and keep your business running smoothly. ### What we offer: - **DDoS Protection:** Our advanced system shields your website or online service from cyberattacks that aim to disrupt it. We block even the most sophisticated attacks to keep your business online. - **Web Application Firewall:** This acts as a smart filter for your website’s traffic, blocking malicious activity like hacking attempts and spam. You get solid protection without needing to change your website’s code. - **Website Optimization:** We make your website load faster on any device, improving user experience and helping you rank better in search engines. - **Content Delivery Network (CDN):** Our global network ensures your website’s content reaches your audience quickly and reliably, wherever they are in the world. ### Why choose us: - **Expertise**: We’re experts in network security and web performance. - **Flexibility**: Our services can be tailored to your specific needs. - **Scalability**: Our solutions can grow with your business. - **Reliability**: We’re committed to providing the highest level of service. Focus on your business, and we’ll handle the tech. [Contact us](https://www.atlantic.net/about-us/corporate-contact/) to learn more about how our [Network Edge Protection Services](https://www.atlantic.net/managed-services/network-edge-protection/#) can benefit your business. --- # Virtual Private Cloud vs. Private Cloud > URL: https://www.atlantic.net/vps-hosting/virtual-private-cloud-vs-private-cloud/ | Published: 2024-05-30 | Updated: 2024-09-09 | Author: Richard Bailey ## **What Is a Virtual Private Cloud (VPC)?** A Virtual Private Cloud (VPC) is a secure, isolated segment of a public cloud infrastructure that provides a dedicated environment for a single organization. The VPC segregates a traditional private network within a shared public cloud, allowing organizations to control their entire virtual networking environment, including configuring IP addresses, subnets, and security groups. VPCs balance the cost-effectiveness and scalability of public clouds with the security and control of private infrastructure. A *virtual private cloud*, often referred to as a VPC, is a type of private cloud hosted within a public cloud environment. It provides a logically isolated section of the public cloud dedicated to a single organization. VPCs offer many of the same benefits as a private cloud, such as security and customization, but they are typically more affordable, easier to scale, and entirely virtualized. ## **What Is a Private Cloud?** A Private Cloud is a dedicated cloud computing environment solely owned and operated by a single organization. All the infrastructure, hardware, and software resources within a private cloud are exclusively accessible to that organization. Private clouds are typically located on-premises within the organization’s data center or hosted externally by a third-party provider. They provide a high level of security, control, and customization but often require significant capital expenditure and ongoing IT management compared to an on-demand public cloud provider. Briefly, a *private cloud *is a cloud computing environment typically dedicated to a single organization or customer. It can be located on-premises (in the organization’s own data center) or hosted by a third-party provider like Atlantic.Net. A private cloud offers a single tenant greater control, security, and customization option than public clouds, but they can also be more expensive and complex to manage. ## ** ****What Is the Difference Between a****Virtual Private Cloud and a Private Cloud****?** Despite their similar names, a Virtual Private Cloud and a Private Cloud are completely different technologies. Each offers a vastly different user experience with contrasting feature sets and varied cloud capabilities. In this guide, we’ll break down the many key features and distinctions between the two and answer some challenging questions to help you make an informed decision. ## Definition of the Two Types of Private Cloud Now, let’s explore each type of cloud computing infrastructure in detail. ### **Private Cloud** A [private cloud](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/) is a cloud computing model where the entire infrastructure is dedicated exclusively to a single organization. It can be located on-premises within the organization’s own data center or hosted by a third-party service provider off-site. A private cloud can be a cluster of physical infrastructure, servers, storage, and networking, or it can be a virtualized cluster such as a VMWare vSphere Environment, an OpenStack Cluster, or perhaps a Hyper-V stack. #### Summary of a Private Cloud Infrastructure - **Location:** Hosted either on-premises or by a third-party provider. - **Ownership:** Often owned and operated by the organization, but large-scale clusters are typically leased from Managed Service Providers. - **Control:** Full control over server, storage, and networking resources and infrastructure. Everyday management tasks may be outsourced to a Managed Services provider. - **Security:** High level of security bespoke to your exact requirements. Often customized to meet specific requirements such as legislation or compliance. - **Customization:** This option offers a high degree of flexibility to tailor the environment to specific needs. It is ideal if the customer needs specific hardware resources. - **Cost:** Typically higher upfront purchasing and ongoing costs, especially licensing and maintenance. - **Scalability:** Less scalable than public cloud options, but new servers and resources can be added to racks as needed. Requires considerable planning, budget considerations, and waiting on lead times. - **Ease of management:** Due to increased control and customization, it can be more complex to manage. If not outsourced, it requires virtualization experts to complete day-to-day management tasks. #### Key Characteristics of Private Cloud: What do you get when you sign up for a Private Cloud Environment? And is it the best choice for you? - **Exclusive Access:** The resources (servers, storage, networking) are not shared with other organizations, providing complete isolation and control. - **Enhanced Security:** Due to their isolated nature, a private cloud often has stronger security measures, making them ideal for sensitive data and regulated industries. - **Customization:** Organizations can configure the infrastructure, applications, and security policies to their specific needs and workflows. - **Performance:** Private clouds can offer higher performance due to dedicated resources and no contention with other users. - **Compliance:** Private Clouds are often preferred for meeting strict regulatory requirements as the organization has full control over data and security measures. This is why most Government industries are managed in-house on a private cloud model. - **Higher Costs:** Building and maintaining a private cloud involves significant upfront investment in hardware, software, and skilled personnel. You may have to factor in the costs of running a data center, power, cooling, disaster recovery, and so on. ### **Virtual Private Cloud (VPC)** A [Virtual Private Cloud](https://www.atlantic.net/virtual-private-cloud/) (VPC) is a subset of a public cloud that simulates a private cloud environment. The key difference is that it uses virtualization technology to create a logically isolated section within a public cloud provider’s infrastructure—an environment dedicated to a single organization. The major cloud providers integrate VPCs into customer accounts, allowing users to configure a software-defined VPC that isolates networking, resources, and security groups into the same isolated environment. VPCs are highly flexible; they can be shared across regions and availability zones and span multiple customers and user accounts if needed. #### Summary of Virtual Private Cloud Infrastructure - **Location:** Hosted within a public cloud provider’s infrastructure - **Ownership:** Resources are typically provided on-demand by a public cloud provider - **Control:** It depends on the cloud provider; typically, there is less direct control compared to a private cloud, but it still offers excellent isolation, security, and segregation. - **Security:** There is a High level of security, often available on demand from the provider and leveraging the provider’s built-in measures. Reputable providers will also offer managed security services, which can be included in your service. - **Customization:** A good level of customization within the defined parameters of your account and virtualized organization. - **Cost:** Generally much more affordable than private cloud due to shared resources and out-of-the-box configuration. - **Scalability:** Highly scalable, leveraging the public cloud’s infrastructure - **Ease of management:** Easier to manage due to the provider handling underlying infrastructure #### Key Characteristics of Virtual Private Cloud (VPC) What do you get when you sign up for a Virtual Private Cloud Environment? And is a VPC the best choice for you? - **Shared Infrastructure:** The underlying physical resources (servers, storage) are shared with other users of the public cloud. There are rarely contention issues, but remember that you are reliant on your provider’s uptime capabilities. In all circumstances, the VPC provides a secure and isolated virtual environment. - **Security:** VPCs leverage the public cloud provider’s robust security measures and offer additional isolation mechanisms, such as virtual firewalls, security groups, and permission-based access. - **Scalability:** VPCs are highly scalable as they can easily tap into the vast resources of the public cloud. VPCs are easy to manage by code, making them superb for automated configuration by your developers. - **Flexibility:** They offer a good degree of customization, allowing organizations to choose the type and size of virtual resources they need. - **Cost-Effective:** VPCs are more cost-effective than private clouds as organizations only pay for the resources they use and don’t need to invest in hardware or maintenance. - **Less Control:** Organizations have less control over the underlying infrastructure compared to a private cloud, however, you do have full control over the virtualized abstraction layer. ## What Is the Difference Between Virtualization and Private Cloud? We have already discussed what a private cloud is a little earlier in this article, so instead, let’s focus on what Virtualization offers for cloud adoption. Virtualization and private cloud are both important concepts in cloud computing, but they are fundamentally different things. ### **Virtualization** Virtualization is a reliable and proven technology that allows you to build multiple virtual environments on physical infrastructure. It requires virtualization software called a hypervisor that sits on top of powerful dedicated physical hardware. The hypervisor effectively divides the existing hardware resources into multiple virtual resources, typically virtual machines (VMs). Each VM acts like an independent computer with its own operating system and applications. Hypervisors allow multiple operating systems to run on a single physical host computer. Some of the most popular include VMware, Hyper-V, KVM, Citrix, and Nutanix. #### Benefits of Virtualization Virtualization offers numerous advantages that enhance the efficiency and flexibility of IT infrastructure. One key benefit is resource efficiency. By running multiple virtual machines (VMs) on a single physical or virtual server, organizations can maximize the utilization of their existing hardware. This not only reduces the need for additional physical servers but also cuts down on energy consumption and overall costs. Another significant advantage is the isolation provided by virtualization. Each virtual machine operates independently from the others, ensuring that any issues or security breaches in one VM do not affect the others. This isolation enhances the overall security and stability of the IT environment, making it a reliable choice for businesses that handle sensitive data or require robust security measures. Virtualization also offers remarkable flexibility. Virtual machines can be easily moved, cloned, and backed up, simplifying management and increasing operational agility. This flexibility is particularly beneficial in disaster recovery scenarios and for scaling operations up or down as needed. Lastly, virtualization is invaluable for testing and development environments. It allows for the rapid creation and destruction of virtual machines, enabling developers to test new software or configurations without the need for additional physical hardware. This accelerates the development cycle and fosters innovation, as teams can experiment and iterate quickly and efficiently using virtual networks. ## **What Are the Disadvantages of Virtual Private Clouds**? While Virtual Private Clouds (VPCs) offer numerous benefits, they also come with potential drawbacks that organizations should consider. One significant disadvantage is the limited control over the underlying infrastructure. Unlike private cloud environments, VPC users rely on public cloud providers such as Atlantic.Net, Google Cloud Platform, or Microsoft Azure to manage and maintain the cloud infrastructure, such as the computing hardware, the core network infrastructure, and other essential hardware and software components used to interlink cloud resources. This dependency can be problematic for businesses requiring granular control over their IT resources. It also means that you are at the mercy of the provider’s Service Level Agreements, so make sure you choose a service provider that has[excellent service level guarantees](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/). Another concern is the potential security risks associated with VPCs. Despite robust security measures, VPCs are still part of the shared public cloud infrastructure, which means there is a risk if the provider’s overall security is compromised. For companies handling highly sensitive data, this shared environment might pose unacceptable risks compared to the isolation offered by a private cloud setting. However, potentially, an ever-great risk exists regarding you, the customer, misconfiguring the security features of the VPC! Setting up and managing a VPC is complex, particularly for organizations lacking extensive cloud expertise. Configuring network settings, security features like security groups and network access control lists (NACLs), and managing access controls require specialized knowledge and experience. VPCs are hard to configure correctly and require lots of testing to make sure the security does exactly as expected. While the costs associated with VPCs are generally lower than those of private clouds, they can potentially spiral out of control if you do not plan your architecture correctly. VPCs still charge for storage resources, data transfer (in particular degree traffic), and additional services provided by different cloud providers and service providers, such as backups. When you add all this together, costs can rise quickly. Vendor lock-in is another potential challenge; while most businesses and startups don’t care about lock-in, choosing a VPC from a specific cloud service provider can lead to difficulties and high costs when attempting to migrate data and applications to another provider. This situation can be exacerbated by the need for specialized management software and tools unique to each provider. Performance variability is also a concern, as the performance of a VPC can be influenced by the activities of other customers sharing the same infrastructure. Although reputable public cloud providers implement measures to mitigate this impact, it remains a consideration. Additionally, the limited customization options in VPCs compared to private cloud environments can restrict businesses to the configurations and services offered by the provider, potentially limiting flexibility and innovation. The VPCs and other customers’ computing resources on the server also depend on a stable internet connection. Any disruptions in connectivity can affect access to virtual servers and other cloud resources. This reliance on the public internet can be a critical issue for businesses requiring uninterrupted access to their IT infrastructure. Despite these disadvantages, VPCs can still be a viable option for many organizations. They offer cost-effectiveness, scalability, and ease of management. However, it is crucial to weigh these benefits against the potential drawbacks and consider factors like security needs, control requirements, and future flexibility before opting for a VPC. For some businesses, a hybrid cloud approach, combining the benefits of both public and private clouds, might offer the optimal balance of cost, control, and performance. ## **What Is the Difference Between a Virtual Cloud and a Public Cloud**? Firstly, it’s important to mention that Virtual Cloud is just another way of saying Virtual Private Cloud (VPC). When choosing between a virtual cloud and a public cloud for your cloud deployment needs, understanding the differences in infrastructure, management, and use cases is crucial. Both options utilize cloud services but cater to very distinct requirements. ### Virtual Cloud A virtual cloud, often referred to as a Virtual Private Cloud (VPC), operates within a shared public cloud infrastructure but provides businesses with a private network environment. This setup allows companies to manage computing resources and cloud services in a secure and isolated manner, leveraging the scalability and flexibility of cloud and computing services. In a virtual cloud, businesses create a virtual private network (VPN) within the public cloud infrastructure. This virtual network itself is equipped with private IP addresses and network access controls, offering a level of security and isolation similar to that found in on-premises data centers. Users have control over network configurations, including IP address ranges and routing tables, through self-service portals provided by the cloud provider. This setup enables businesses to integrate their cloud resources with existing on-premises infrastructure or other private environments seamlessly. Virtual clouds are particularly suited for organizations that prioritize enhanced security and isolation for sensitive data or workloads. They provide customers with the computing resources and flexibility needed to customize network settings and security parameters, making them an ideal choice for businesses with specific compliance or regulatory requirements. ### Public Cloud In contrast to private infrastructure, a public cloud relies on a shared infrastructure provided by a third-party cloud provider over the public internet. This environment is shared among multiple customers, with the cloud provider managing hardware maintenance, software updates, and overall security. In a public cloud setup, users manage their applications and data within the cloud provider’s environment, benefiting from the provider’s scalability and quick provisioning capabilities. This allows businesses to access a wide range of computing resources on demand without the need for large capital expenditures. Public clouds are well-suited for startups, small businesses, and enterprises looking for cost-effective and scalable solutions to accommodate varying workloads and applications. ## Atlantic.Net Cloud Hosting and Managed Services Atlantic.Net has been in business for 30 years and provides IT services to customers throughout the United States, Europe, and Asia. We have 8 data center locations around the globe that our customers can leverage for a wide range of hosting solutions, managed services, and compliance services, including our award-winning HIPAA-Complaint Managed Services. Atlantic.Net’s Virtual Private Cloud (VPC) offers businesses a secure and scalable cloud solution. Each VPC system seamlessly integrates with the Atlantic.Net Cloud and features the robust security and logical network segmentation needed to meet and exceed diverse compliance requirements, including HIPAA, PCI-DSS, and HITECH. With the added advantage of a fully managed service, Atlantic.Net’s dedicated team ensures a customized network solution that aligns with organizational goals. Add features like the Managed Firewall and VPN to enhance security and connectivity. Atlantic.Net’s VPC combines security, performance, and scalability, making us a great choice for businesses of all sizes. Step into the future with Atlantic.Net’s Virtual Private Cloud (VPC). Imagine the security of a physical data center network but with the flexibility of the cloud. Our VPC offers complete logical isolation, ensuring unparalleled security and compliance, all while residing on Atlantic.Net’s trusted Cloud services. Reach out to the team [today to learn more](https://www.atlantic.net/about-us/corporate-contact/). --- # Top 10 Server Management Software Solutions > URL: https://www.atlantic.net/managed-services/server-management-software/ | Published: 2024-05-31 | Updated: 2024-08-26 | Author: Richard Bailey ## **What is Server management Software?** Server management software is a crucial tool designed to help businesses efficiently and effectively manage their IT infrastructure. The aim is to offer a software solution with numerous tools and features that simplify complex tasks related to server administration. ## What Is the Purpose of a Server Management Solution? Server management software makes it easier to manage complex IT platforms, including [Windows servers](https://www.atlantic.net/managed-services/server-management-windows/), [Linux servers](https://www.atlantic.net/managed-services/server-management-in-linux/), and everything else associated with supporting an IT environment. The goal is to reduce downtime by identifying server issues and resolving them promptly and proactively through advanced automation. This, in turn, improves overall network performance by optimizing resource usage and configuration settings. Business leaders gain visibility into their IT operations with server management software that often includes security solutions designed to enhance security, automate system updates, and streamline security policy handling. Each leading unified solution typically automates routine management tasks and gives IT departments a centralized platform to manage complex server infrastructure, including SQL servers and vSphere environments. ## Server Management Software Automation [Server management](https://www.atlantic.net/managed-services/server-management/) software solves many IT problems. Many feature enhanced server monitoring and continuously tracking server health, performance metrics, and resource utilization (CPU, memory, disk space). Alerts are automated when they detect anomalies or critical situations, such as server crashes, high resource usage, or security breaches. Configuration management tools help system administrators automate and standardize server configurations and reduce errors and inconsistencies across large server environments. Backup and Recovery tools offer the ability to protect data remotely. Advanced reporting and even an analytics platform that leverages machine learning to identify issues across an entire data center are becoming more popular in Server Management software. ## **Types of Server Management Software** Various types of server management software are available, with each catering to different needs and budgets served by multiple pricing options. Some are cloud-based, offering managed servers, while others are installed on-premises. Choosing the right software depends on the specific requirements of your organization and the complexity of your server infrastructure. ## Top 10 Server Management Solutions Here is our top 10 list of server management software companies that can help you achieve complete visibility and full control over your IT operations. ## #10 CheckMK **Why CheckMK Stands Out** CheckMK is an open-source IT monitoring solution that provides comprehensive and scalable tools for the entire data center, from servers and networks to cloud environments and applications. It’s a popular agent-based server monitoring tool that uses automated discovery to deploy at scale. It monitors key values such as availability, performance, and capacity and includes key features such as log management, event correlation, and reporting. **Who Can Benefit from CheckMK** Sysadmins use CheckMK to monitor the health and performance of several servers in their infrastructure, ensuring uptime and identifying potential issues. It also has many key features for developers and engineering teams. MSPs use Checkmk to monitor their clients’ infrastructures, providing value-added services and ensuring the smooth operation of their clients’ systems. **Pros** - **Robust and Feature-Rich:** Offers extensive observability out of the box. - **Easy to Install and Configure:** User-friendly interface and automatic discovery simplify setup. - **Large Community and Support:** Active user community and comprehensive documentation. - **Cost-Effective:** The open-source model reduces licensing costs. **Cons** - **Learning Curve:** Some advanced key features may require time to master. - **Resource Intensive:** Can consume significant resources in large environments. - **Limited Out-of-the-Box Reporting:** Customization may be needed for complex reports. ## **#9 Nagios XI** **Why Nagios XI Stands Out** Nagios is a powerful and widely used open-source monitoring software for IT infrastructures. It helps organizations identify and resolve IT infrastructure problems before they affect critical business processes. It’s great as a mission-critical monitor server for applications, services, operating systems, network protocols, systems metrics, and network infrastructure. It provides a central view of your entire data center, IT operations network, and business processes. **Who Can Benefit from Nagios XI** Nagios XI helps IT teams proactively monitor and manage their IT infrastructure, reducing downtime and improving service availability. From small businesses to large enterprises and hosting providers, Nagios XI can be tailored to fit the specific monitoring needs of any organization. **Pros** - **Powerful and Flexible:** Offers a wide range of monitoring capabilities and customization options. - **Scalable:** Can easily grow with your organization’s needs. - **Mature and Reliable:** Proven track record with a large user community. - **Cost-Effective:** Open-source core with affordable commercial add-ons. **Cons** - **Learning Curve:** It can be complex to set up and configure, especially for beginners. - **Resource Intensive:** Requires dedicated resources for optimal performance. - **Limited Out-of-the-Box Features:** To get the most out of Nagios requires additional plugins and customization for specific needs. ## **#8 Zabbix** **Why Zabbix Stands Out** Zabbix is a software company with an open-source enterprise-class monitoring solution designed for real-time monitoring of millions of metrics collected from tens of thousands of servers, virtual machines, and network devices. It offers a comprehensive monitoring solution for various IT infrastructure components, including networks, servers, applications, **Who Can Benefit from Zabbix** Everyone can benefit from Zabbix because it is free to use, but also a complete and highly customizable tool. Therefore, any business that relies on IT infrastructure for its day-to-day operations can benefit from Zabbix’s comprehensive monitoring and alerting capabilities. **Pros** - **Highly Customizable:** Can be tailored to meet specific monitoring needs. - **Scalable:** Handles large environments with thousands of devices. - **Cost-Effective:** The open-source model eliminates licensing costs. - **Large and Active Community:** Provides extensive support and resources. **Cons** - **Learning Curve:** May require some time to master its advanced key features and configuration. - **Resource Intensive:** Can consume significant resources in large environments. - **Complex Setup:** Initial setup and configuration is complex for beginners ## **#7 Dynatrace** **Why Dynatrace Stands Out** Dynatrace is an all-in-one software intelligence platform designed to provide full-stack monitoring and observability for complex enterprise cloud environments. It’s good at alerting on application usage and is a great tool for developers looking for deep insights into how their applications are performing. AI is cleverly integrated too, it can automatically identify the root cause of problems, allowing you to resolve issues faster and prevent them from happening again. **Who Can Benefit from Dynatrace** Dynatrace targets medium and large enterprises mainly because it’s considered a premium product. It’s expensive, but it’s also very good, and many users find the value it provides justifies the cost. **Pros** - **Powerful AI Capabilities:** Automates many monitoring tasks and provides valuable insights. - **Comprehensive Monitoring:** Covers the entire technology stack, providing a holistic view of your environment. - **Ease of Use:** Intuitive interface and automated workflows reduce manual effort and simplify monitoring. - **Scalability:** Handles large and complex environments with ease. - **Excellent Support:** Offers comprehensive documentation and responsive customer support. **Cons** - **Cost:** This can be expensive compared to other monitoring solutions. - **Complexity:** Some advanced features may require expertise to configure and utilize effectively. - **Learning Curve:** Initial setup and configuration may take some time to master. ## **#6 New Relic** **Why New Relic Stands Out** New Relic is a comprehensive observability platform designed to help organizations monitor, troubleshoot, and optimize their entire technology stack. It provides full-stack visibility from infrastructure web servers to applications to user experience, allowing teams to proactively identify and resolve performance issues before they impact customers. **Who Can Benefit From New Relic** New Relic is ideal for organizations of all sizes that want to gain a deeper understanding of their technology stack and improve its performance. Its UI is really good, it’s easy to use, and it features everything you need to get started. New Relics offers a free tier, as well as standard, pro, and enterprise editions – there is something out there for everyone. **Pros** - **AI-Powered Insights:** Automates many monitoring tasks and delivers actionable insights. - **Open and Extensible:** Easily integrates with your existing tools and workflows. - **Scalability:** Handles large and complex environments. - **Strong Community:** Active user community and extensive documentation. **Cons** - **Cost:** Very expensive, especially for large-scale deployments. - **Complexity:** Some features can be complex to configure and use effectively. - **Learning Curve:** Initial setup and configuration may require some time and effort. ## **#5 SolarWinds SAM** **Why SolarWinds Stands Out** SolarWinds SAM is designed to monitor the performance and health of applications, servers, and infrastructure components. The App Insight tool is great at identifying application bugs and issues, and the reporting features are also very good. If you are already invested in SolarWinds, SAM seamlessly integrates with Network Performance Monitor (NPM) and Log Analyzer. **Who Can Benefit from SolarWinds** SolarWinds SAM is used by a variety of organizations, including NASA, which uses it to monitor its mission-critical systems. Solarwinds licensing is very expensive, so their target audience is large and enterprise-scale businesses. **Pros** - **Comprehensive Monitoring:** Offers deep visibility into application and server performance. - **User-Friendly Interface:** Intuitive and easy-to-use interface for monitoring and troubleshooting. - **Extensive Template Library:** Out-of-the-box templates for a wide range of applications and systems. - **Customizable Monitoring:** Allows for the creation of custom templates and monitors. - **Integration with the Orion Platform:** Seamlessly integrates with other SolarWinds products. **Cons** - **Cost:** Can be expensive, especially for larger environments. - **Complexity:** May require some training and expertise to fully utilize all key features. - **Resource Intensive:** Can consume significant resources in large environments. - **Security Concerns:** Management software company SolarWinds has experienced a high-profile security breach in the past, raising concerns about the security of its products. ## **#4 Datadog** **Why Datadog Stands Out** Datadog is a cloud-based monitoring and observability service platform for cloud applications. It brings together data from servers, databases, tools, and services to present a unified view of an organization’s data center and entire technology stack. This allows teams to monitor infrastructure health and application performance. **Who Can Benefit from Datadog** Datadog also targets medium, large, and enterprise-scale businesses. Tech companies like Twilio, Peloton, and Zoom rely on Datadog to monitor their complex cloud-based applications and infrastructure. **Pros** - **Scalability:** Easily adapts to growing infrastructure and data volumes. - **AI-Powered Insights:** Automates anomaly detection and root cause analysis. - **Extensive Integrations:** Works seamlessly with popular tools and services. - **User-Friendly Interface:** Offers intuitive dashboards and customizable visualizations. **Cons** - **Cost:** Can be expensive, especially for large-scale deployments and with additional features. - **Complexity:** Some advanced features may require expertise to set up and manage effectively. - **Learning Curve:** Initial onboarding and configuration can be time-consuming. - **Data Retention:** Limited data retention periods in lower-tier plans. ## **#3 ManageEngine OpManager** **Why ManageEngine Stands Out** At number 3 is ManageEngine OpManager. Another monitoring tool but this one stands out for its performance. It’s fast! It can easily monitor the health of network devices, servers, and virtual machines. It has many key features including application performance monitoring, bandwidth monitoring, firewall log analysis, IP address management, fault detection, and workflow automation. Its interface is superb and very intuitive. **Who Can Benefit from ManageEngine** ManageEngine targets Small and Medium-sized businesses and startups. It is also popular in the healthcare, education, and government industries. It’s affordable to offer free versions, essential “lite” editions, plus professional and enterprise editions. **Pros** - **Ease of Use:** User-friendly interface and automated discovery. - **Real-Time Alerts:** Sends instant notifications for timely response. - **Network Mapping:** Automatically generates visual network maps. - **Workflow Automation:** Automates routine tasks for improved efficiency. **Cons** - **Scalability:** May face challenges scaling to very large networks. - **Reporting:** Some users find the reporting features limited. - **Cost:** Can be expensive for smaller organizations with limited budgets. ## **#2 NinjaOne** **Why NinjaOne Stands Outs** At number two is NinjaOne, a popular cloud-based IT operations platform designed to simplify endpoint management for managed service providers (MSPs) and internal IT teams. It offers a comprehensive suite of server management tools, for remote monitoring and management (RMM), patch management, service desk, backup, and an endpoint security solution **Who Can Benfit from NinjaOne** NinjaOne consistently receives high ratings from users for its ease of use, functionality, and customer support. It has a wonderful UI that is so simple to navigate, it’s a pleasure. They primarily target Managed Service Providers with the aim to simplify MSPs’ need to manage huge estates of infrastructure. NinjaOne is a very cost-effective solution (with a free tier available) and you get a lot of features for your money. **Pros** - **User-Friendly Interface:** Easy to navigate and use, even for those with limited technical expertise. - **Robust Feature Set:** This product offers a wide range of capabilities, including RMM, patch management, service desk, backup, and automation. - **Strong Security Focus:** Prioritizes endpoint security with features like patching, antivirus, and backup. - **Scalable and Flexible:** Adapts to the needs of organizations of various sizes and supports different deployment options. - **Affordable Pricing:** Offers competitive pricing plans that are accessible to businesses of all sizes. ### Cons - **Limited Reporting:** Reporting capabilities may be less extensive compared to some other IT management platforms. - **Steeper Learning Curve for Advanced Features:** While basic features are easy to use, mastering advanced functionality may require some time and effort. ## #1 Atera **Why Atera Stands Out** At number one is Atera, an amazing cloud-based all-in-one IT management software. It’s a top server management software that combines Remote Monitoring and Management (RMM), Professional Services Automation (PSA), and remote access tools into a single solution. It can handle most any task, the reporting is probably the best available, and there is lots of scope for scripting and automation, making it a very effective tool to customize and integrate in-house. **Who Can Benefit From Atera** Atera targets MSPs and companies with in-house IT departments. It’s designed to manage large enterprise-scale businesses. The pricing starts at $79 per technician per month for the Pro plan and $99 per technician per month for the Growth plan. They also offer a free trial for new users. **Pros** - **User-Friendly:** Intuitive interface and easy navigation. - **All-in-One Solution:** Consolidates RMM, PSA, and remote access tools. - **Scalable:** Adapts to the needs of growing businesses. - **Automation:** Streamlines repetitive tasks with powerful automation capabilities. - **Cost-Effective:** Pay-per-technician pricing model. **Cons** - **Limited Third-Party Integrations:** Compared to some other platforms, Atera may have fewer integrations with third-party tools. - **Learning Curve for Advanced Features:** While basic features are easy to use, mastering advanced functionality may require some time and effort. ## Let Atlantic.Net Host Your Next Server Management Software We know that server management software costs are high, but your hosting providers’ costs don’t have to be. Atlantic.Net has been providing cloud hosting and managed services for 30 years. We are based in Orlando, Florida. We have data centers located throughout the United States, Canada, Europe, and Asia, and our award-winning cloud platform is always available, featuring our industry-leading 100% Service Level Agreements. Don’t let hosting costs hold you back from optimizing your server management. Contact [Atlantic.Net](https://www.atlantic.net/about-us/corporate-contact/) today and experience the difference of a reliable, high-performance hosting solution. --- # Bare Metal Kubernetes: Pros, Cons, and Best Practices > URL: https://www.atlantic.net/dedicated-server-hosting/bare-metal-kubernetes-pros-cons-and-best-practices/ | Published: 2024-06-02 | Updated: 2024-09-24 | Author: Gilad Maayan ## What Is Bare Metal? Bare metal refers to physical computer server hardware without any installed operating systems or virtualization layers. It represents the most direct access to the server’s physical resources, such as CPU, memory, and storage, enabling users to maximize performance and efficiency for their specific applications. Bare metal environments are characterized by their lack of overhead that comes with hypervisors or virtual machines, offering dedicated resources for high-demand applications. Deploying applications directly onto [bare metal servers](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) can significantly enhance their performance and reliability. This approach is particularly beneficial for resource-intensive applications that require direct access to hardware features, allowing them to run more efficiently than in virtualized environments. Bare metal setups are favored in scenarios where control and optimization of the hardware environment are crucial for application performance. ## Pros of Kubernetes on Bare Metal ### Enhanced Control Running Kubernetes on bare metal provides enhanced control over the infrastructure, allowing organizations to tailor their environment specifically to their application needs. This direct control enables finer optimization of resources, ensuring that Kubernetes clusters are tuned for maximum efficiency and performance. Administrators can make specific hardware adjustments and configurations that directly benefit their workloads, something not as easily achievable in virtualized or cloud environments. This level of control also extends to the network configuration, storage options, and security settings, allowing for a highly customized Kubernetes environment. Enhanced control means that organizations can optimize their deployments for specific performance characteristics or compliance requirements, ensuring that their applications run as efficiently as possible. ### Cost Savings Deploying Kubernetes on bare metal can lead to significant cost savings, particularly for organizations with stable, predictable workloads that can fully utilize the capacity of their servers. Without the need to pay for virtualization layers and the overhead they create, organizations can reduce operational costs while still benefiting from the scalability and automation that Kubernetes provides. Moreover, the efficient use of resources in a bare metal setup reduces the need for overprovisioning, allowing organizations to invest in exactly what they need without unnecessary extras. This direct and efficient use of hardware translates into lower operational costs. ### Improved Cluster Security and Control Running Kubernetes on bare metal enhances cluster security by providing complete control over the physical infrastructure. This control allows organizations to implement security measures at every layer of their infrastructure, from the physical access to servers to the network configurations and data storage. The absence of a hypervisor reduces the attack surface, and the ability to directly manage hardware resources can lead to a more secure environment. This direct control also means that organizations can enforce compliance standards more easily, tailoring their security posture to meet specific regulatory requirements without the constraints imposed by cloud providers or virtualization platforms. Enhanced security and control make Kubernetes on bare metal an appealing option for sensitive or critical applications. ## Cons of Deploying Kubernetes on Bare Metal ### Hardware Management Managing hardware in a bare metal Kubernetes environment presents unique challenges. Organizations must handle the physical aspects of their servers, including provisioning, maintenance, and upgrades, tasks that are typically abstracted away in cloud or virtualized environments. This direct management requires a higher level of operational expertise and can introduce complexity in terms of hardware compatibility and performance optimization. Additionally, the lack of immediate scalability compared to ordinary cloud environments means that organizations must plan for capacity more carefully, ensuring they have the hardware resources available to scale up as needed. ### Networking Complexity Networking in a bare metal Kubernetes environment provides more flexibility but can be more complex than in virtualized or cloud settings. Configuring network topologies that support high availability, security, and performance requires a deep understanding of both Kubernetes networking and the underlying physical network infrastructure. Challenges include implementing network policies, managing ingress and egress traffic, and ensuring low-latency communication between nodes. Organizations must also deal with the physical network hardware and configurations, from switches to routers, which can add another layer of complexity to the deployment. This complexity necessitates a strong networking knowledge base and may require specialized tools or software to manage effectively. ### Cluster Bootstrapping and Updates Bootstrapping and updating Kubernetes clusters on bare metal can be more challenging than in cloud environments. The initial setup requires careful planning and configuration of the hardware, networking, and software components to ensure a successful deployment. This process often involves manual steps, making it more labor-intensive and prone to errors. Updates and upgrades also pose challenges, as they must be carefully managed to avoid disrupting operations. Unlike cloud services that offer managed Kubernetes solutions, updates on bare metal must be performed manually, requiring a robust strategy for testing and rolling out updates without impacting the production environment. ## Best Practices for Running Kubernetes on Bare Metal Here are a few best practices that will help you run Kubernetes more effectively on bare metal servers. ### 1. Choose Smaller Nodes Opting for smaller nodes can enhance the resilience and flexibility of a Kubernetes cluster on bare metal. Smaller nodes allow for a more granular scaling of resources, enabling precise adjustments to the cluster based on current workload requirements. This approach reduces the risk of resource wastage and can improve overall cluster efficiency by distributing workloads more evenly across the available infrastructure. ### 2. Choose Standardized Hardware Standardizing hardware in a bare metal Kubernetes environment simplifies management and reduces operational complexity. Using a consistent set of hardware specifications for servers, storage, and networking equipment makes it easier to automate provisioning, monitoring, and management tasks. This consistency can also improve performance predictability, as the cluster’s behavior is more uniform. ### 3. Master kubectl Commands for Efficient Cluster Management Efficient management of a Kubernetes cluster on bare metal requires mastering kubectl commands. kubectl is the command-line tool for interacting with the Kubernetes API, allowing administrators to deploy applications, inspect and manage cluster resources, and view logs. Proficiency with kubectl enables administrators to perform special tasks that might be required in a bare metal environment, such as debugging pods or rolling out updates. *Learn more in the detailed guide to [kubectl](https://komodor.com/learn/the-ultimate-kubectl-cheat-sheet/)* ### 4. Keep the Operating System Consistent Maintaining a consistent operating system (OS) across all nodes in a Kubernetes cluster on bare metal is crucial for stability and security. Consistency in the OS ensures that applications perform predictably across the cluster and simplifies the management of updates and patches. It reduces the risk of compatibility issues that can arise from differences in OS configurations or versions, which can lead to unexpected behavior or security vulnerabilities. ### 5. Use a Bare-Metal Management Tool Leveraging a bare-metal management tool can streamline the deployment and operation of Kubernetes on bare metal. These tools facilitate tasks such as provisioning, monitoring, and managing physical servers, automating many of the manual processes involved in running bare metal infrastructure. ## Running Docker on Bare Metal Servers with Atlantic.Net Running Docker containers on bare metal servers offers an efficient and scalable way to deploy and manage containerized applications. Atlantic.Net is responding to the growing demand for flexible container orchestration by developing a container orchestration and deployment platform. The Atlantic.Net Container Engine caters to a wide range of container deployment needs. Whether users are interested in utilizing libraries of pre-built, vendor-approved containers or deploying their own custom application containers, the engine is engineered to offer the necessary support and functionality. With Atlantic.Net’s new capabilities, developers and IT professionals can look forward to a more streamlined and efficient container management experience, leveraging the power of Docker on bare metal servers for optimal performance and scalability. [Learn more about the Atlantic.Net Container Engine](https://www.atlantic.net/cloud-platform/cloud-containers/) --- # Atlantic.Net Launches One-Click HIPAA-Compliant Cloud Hosting > URL: https://www.atlantic.net/announcements/atlantic-net-launches-one-click-hipaa-compliant-cloud-hosting/ | Published: 2024-06-04 | Updated: 2026-02-28 | Author: Alexander Wise We are pleased to announce a one-click deployment of our HIPAA-compliant cloud services, a web hosting solution that meets and exceeds the required administrative, physical, and technical safeguards mandated by the Health Insurance Portability and Accountability Act. The new offering allows faster deployment with instant access to resources and quicker compliance in minutes, not days! Atlantic.Net’s HIPAA One-Click Cloud Hosting solution is now available through instant sign-up.![](https://www.atlantic.net/wp-content/uploads/2024/06/One-Click-HIPAA-Application-Now-Available-01-01-01-01.jpg) **Our HIPAA Platform includes everything you need to be HIPAA compliant and more!** **Plans start from only $148.99 per month which includes:** - Cloud Server - Fully Managed Firewall - Daily Onsite Backup - Business Associate Agreement ## Optional Managed Services In addition to our basic HIPAA-compliant hosting, we also offer a full range of managed services to go above and beyond compliance requirements: - Server Management - Vulnerability Scans - Migration Service - Intrusion Prevention Service - Multi-Factor Authentication - Off-Site Backup - TrendMicro Security Suite - Network Edge Protection - Load Balancing ## New HIPAA Hosting One-Click Pricing Plans The ongoing monthly cost greatly depends upon variables like security services, and server specifications. Here are a few standard [HIPAA hosting pricing plans and packages](https://www.atlantic.net/hipaa-compliant-hosting/#hipaa_plans): ![](https://www.atlantic.net/wp-content/uploads/2024/06/HIPAA-Plans.png) These plans can be easily upgraded to fit power users as well – Atlantic.Net offers more robust resources that can play a vital role in the infrastructure needed to meet the growing demands of AI while maintaining compliance needs, such as those associated with HIPAA. ## More About HIPAA-Compliant Hosting Start your HIPAA-compliant hosting trial today risk-free! Atlantic.Net meets and surpasses HIPAA compliance requirements for both physical security and security configuration, with built-in extensibility for additional software, services, and features. If you are not satisfied with our solution for any reason, you can cancel anytime within the first 30 days. --- # Atlantic.Net Launches One-Click HIPAA-Compliant Cloud Hosting > URL: https://www.atlantic.net/press-releases/atlantic-net-launches-one-click-hipaa-compliant-cloud-hosting/ | Published: 2024-06-04 | Updated: 2024-11-22 | Author: Editorial Team ***The new offering allows faster deployment with instant access to resources and quicker compliance*** **ORLANDO, Fla. – June 4, 2024** – Atlantic.Net, a leading cloud hosting solutions provider, today announced a one-click deployment of its HIPAA-compliant cloud services, a web hosting solution that meets and exceeds the required administrative, physical, and technical safeguards mandated by the Health Insurance Portability and Accountability Act. As a decade-long leader in healthcare compliance hosting, Atlantic.Net provides critical and compliant infrastructure to leading Ivy League universities, the biotech industry, pharmaceutical companies, healthcare providers, and application service providers. With an increase in the number of healthcare startups that rely on artificial intelligence (AI), Atlantic.Net is solving advanced problems with a simple, easy-to-use solution that helps healthcare providers with a compliant solution instantly. “Technological disruptions in healthcare are rapidly taking place as new ideas and inventions are improving the quality of life, and Atlantic.Net helps customers stay at the forefront of these advancements by providing fully managed and HIPAA Compliant Cloud Hosting solutions,” said Marty Puranik, CEO and Founder of Atlantic.Net. “As AI impacts the landscape, from new tools being added to legacy tech stacks to bad actors ramping up attacks against healthcare providers, we are committed to continuously improving our infrastructure services and solutions to meet the demands of our customers.” Atlantic.Net’s HIPAA One-Click Cloud Hosting solution is now available through instant sign-up. Plans start from only $148.99 per month which includes a Cloud Server, Fully Managed Firewall, and daily Onsite Backup, plus a Business Associate Agreement included with every plan. Additional optional Managed Services include Server Management, Vulnerability Scans, Migration Service, Intrusion Prevention Service, Multi-Factor Authentication, Off-Site Backup, TrendMicro Security Suite, Network Edge Protection, and Load Balancing. These plans can be easily upgraded to fit power users as well – Atlantic.Net offers more robust resources that can play a vital role in the infrastructure needed to meet the growing demands of AI while maintaining compliance needs, such as those associated with HIPAA. Atlantic.Net specializes in an array of hosting services including on-demand and turnkey cloud hosting, dedicated hosts, dedicated servers, colocation, private virtualization, and managed hosting. The company provides scalable computing from eight secure data centers worldwide, each engineered to provide fault-tolerant and ultra-fast performance. For more information, please visit https://www.atlantic.net/hipaa-compliant-hosting/. **About Atlantic.Net** Atlantic.Net is an award-winning global cloud services provider with a focus on security, compliance, and simplifying complex infrastructures. With over 30 years of experience, Atlantic.Net is dedicated to offering developers and healthcare IT leaders at small, medium, and large organizations a range of on- demand, customized, and cost-effective cloud solutions that cater to their unique business needs. Having deployed millions of cloud servers world-wide, the company’s commitment to excellence has positioned it as a leader in the industry, recognized for its innovation and customer-centric approach. ### Media Contact 5WPR for Atlantic.net atlantic@5wpr.com --- # Server Management Windows > URL: https://www.atlantic.net/managed-services/server-management-windows/ | Published: 2024-06-11 | Updated: 2025-04-11 | Author: Richard Bailey Microsoft has tried to make all flavors of Windows and Windows Server as user-friendly as possible, and it has included several excellent server management tools in the Operating System. Thanks to this attention to usability, Windows and Windows Server users can experience quality and proven server management tools out-of-the-box – tools that are easy to use and learn, not to mention that Microsoft applications always have great online documentation if users get stuck. A wide selection of propriety-licensed products and third-party management tools are also available, most of which are free-to-use. This article will discuss the Windows Server Management Tools that will make your life easier. ## What Is Windows Server Management? Windows Server Management includes all the activities sysadmins perform to keep Windows server instances running smoothly, securely, and efficiently. Typically, the tasks center around the installation, configuration, monitoring, troubleshooting, updating, and security hardening of Windows. Users who implement effective server management tasks benefit from better overall performance and stronger data integrity features with tools like BitLocker and typically achieve better uptime results. ## What types of tools are available in Windows Server for Server Management? Thousands of server management tools are available to manage Windows Server. We have focused on the more popular first-party and third-party tools that are favored by system administrators. ### Remote Server Administration Tools RSAT allows administrators to manage Windows Servers remotely from their Windows laptops or workstations. It’s a vital tool for server administration and is particularly useful for managing multiple servers and remote servers. RSAT includes tools like Server Manager, Microsoft Management Console (MMC) snap-ins, and PowerShell cmdlets. The RSAT snap-ins help admins manage Active Directory (ADUC, ADAC), Group Policy (GPMC), DNS, DHCP, devices, events, performance, and services. You install it locally and connect directly to the target server using remote access. ### Manage Windows Server with Admin Center Windows Admin Center (WAC) is a browser-based management experience that controls access to advanced server/computer configuration options, performance monitoring, event management, and role/feature installation. WAC can manage both on-premises and cloud-based Windows Servers. It integrates with Microsoft Defender and is one of the management solutions that works perfectly via CLI/PowerShell. ### System Center System Center is an enterprise-grade suite of management tools designed for larger, complex IT environments on a corporate network. It offers sysadmins the ability to manage at scale – perfect for configuration management, monitoring, automation, and security. System Center components like Configuration Manager (SCCM) and Operations Manager (SCOM) are commonly used for managing Windows Servers and other virtual machines. Beyond Microsoft’s native tools for managing servers, IT professionals turn to a wide array of third-party solutions for Windows Server management. For server roles like automated patch management, NinjaOne, and PDQ Deploy are popular choices. [Veeam Backup & Replication](https://www.atlantic.net/managed-services/veeam-services/) and Acronis Cyber Protect provide robust backup and recovery capabilities, and tools like Rapid7 InsightVM and Tenable Nessus can achieve deep security insights and hardening. ## What Are the Most Important Tasks in Managing a Windows Server? Asking this question to different system administrators would give you a different answer every time! The most important tasks for a server manager depend on the server’s role and the business’s goals. According to Atlantic.Net engineers, there are 8 key areas to that are very important to consider: 1. **Installation and Configuration:** Ensuring correct installation of the operating system and roles/features, configuring network settings, storage, and security. 2. **Patch Management:** Keeping the operating system and applications up-to-date with the latest security patches and updates. 3. **Performance Monitoring:** Monitoring server performance metrics (CPU, memory, disk, network) to identify and resolve bottlenecks or issues. 4. **Security Hardening:** Implementing security best practices to protect the server from unauthorized access, malware, and other threats. 5. **Backup and Recovery:** Regularly backing up server data and configurations to ensure that they can be restored in the event of a disaster or data loss. 6. **Log Management:** Collecting and analyzing server logs to identify errors, security incidents, and performance issues. 7. **Capacity Planning:** Proactively monitoring resource usage and planning for future capacity needs to avoid performance degradation. 8. **User Management:** Managing user accounts, permissions, and access to ensure that only authorized users can access server resources. ## **Should I Choose an MSP to Help with Windows Server Management?** Choosing a Managed Service Provider (MSP) like Atlantic.Net for Windows Server management can be a strategic decision that allows your business to free up resources to focus on day-to-day business operations. MSPs can offer around-the-clock expertise, 24/7 monitoring, proactive maintenance, and rapid response and resolution to complex issues. Managed services like [server management](https://www.atlantic.net/managed-services/server-management/) ensure that your remote Windows servers are well-maintained, secure, and compliant. If you have a large or complex environment, if your internal IT team is limited, or if you need email server support, load balancing, VPN support, Database Support, OnWatch Platinum monitoring, or vulnerability scanning, Atlantic.Net can fill the gaps and ensure that your servers receive adequate attention. ## Atlantic.Net Server Management Managed Services Don’t let Windows server management become a headache. Simplify your IT operations and ensure peak performance of your Windows servers with Atlantic.Net’s expert [Managed Services](https://www.atlantic.net/managed-services/what-are-managed-services/). From 24/7 monitoring and proactive maintenance to advanced security and robust backup solutions, we cover all your Windows Server management needs. Ready to offload the burden of server management? [**Contact Atlantic.Net today**](https://www.atlantic.net/about-us/corporate-contact/)**for a free consultation and discover how our Managed Services can streamline your IT infrastructure.** --- # How to Create and Select MySQL Databases > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-create-and-select-mysql-databases/ | Published: 2024-06-12 | Updated: 2024-07-15 | Author: Hitesh Jethva Databases are the backbone of any application, enabling you to store, manage, and retrieve data efficiently. Whether you are setting up a new project or managing an existing one, understanding how to create and select databases is crucial. In this tutorial, we will walk you through the essential steps of creating and selecting MySQL databases. ## Prerequisites Before we begin, ensure you have MySQL installed on your system. You should also have access to the MySQL command line. ## Step 1 – Creating a MySQL Database 1. First, open your terminal or command prompt. If you have MySQL installed, you can access the MySQL command line by typing: ```bash mysql -u root -p ``` Press Enter and provide your MySQL root password when prompted. You will see the MySQL prompt: ```bash mysql> ``` 2. Use the CREATE DATABASE command followed by the name of the database to create a database. For example, to create a database named test_db, you would type: ```bash CREATE DATABASE test_db; ``` You should see a message confirming the database has been created: ```bash Query OK, 1 row affected (0.00 sec) ``` 3. To verify that your new database has been created, you can list all databases using the SHOW DATABASES command: ```bash SHOW DATABASES; ``` The output will include your newly created database: ```bash +--------------------+ | Database | +--------------------+ | information_schema | | mysql | | performance_schema | | sys | | test_db | +--------------------+ 5 rows in set (0.00 sec) ``` ## Step 2 – Selecting a MySQL Database 1. Once you have created your database, you need to select it before performing any operations like creating tables or inserting data. To select a database, use the USE command followed by the database name. For example, to select the test_db database, you would type: ```bash USE test_db; ``` You should see a confirmation message: ```bash Database changed ``` 2. To confirm which database is currently selected, you can use the SELECT DATABASE() function: ```bash SELECT DATABASE(); ``` The output will show the name of the selected database: ```bash +------------+ | DATABASE() | +------------+ | test_db | +------------+ 1 row in set (0.00 sec) ``` ## Conclusion In this article, we covered the fundamental steps for creating and selecting MySQL databases. You learned how to access the MySQL command line, create a new database, verify its creation, and select it for use. These basic operations are essential for managing your data effectively in MySQL. Try to use MySQL on [**dedicated server hosting**](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Show/List Users in MySQL > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-show-list-users-in-mysql/ | Published: 2024-06-13 | Updated: 2024-07-15 | Author: Hitesh Jethva Managing users is a fundamental aspect of database administration. In this tutorial, we’ll cover the steps necessary to display all users within a MySQL database. This includes using SQL queries to fetch user details, filtering users based on specific criteria, and understanding user privileges. Additionally, we will explore how to list MySQL users using the mysqladmin command-line tool. ## Prerequisites Before we dive into listing users, make sure you have the following prerequisites: - MySQL installed on your system - Access to MySQL with administrative privileges - Basic understanding of MySQL commands and SQL syntax ## Step 1 – Connecting to MySQL First, let’s connect to the MySQL server. Open your terminal or command prompt and enter the following command: ```bash mysql -u root -p ``` You will be prompted to enter the root user’s password. After entering the password, you’ll be logged into the MySQL shell. ## Step 2 – Using the SELECT Statement In MySQL, user information is stored in a table called mysql.user. To list all users, you need to query this table. To display all users, execute the following SQL command: ```bash SELECT User, Host FROM mysql.user; ``` This command will list all users along with the hosts from which they can connect. ```bash +------------------+-----------+ | User | Host | +------------------+-----------+ | debian-sys-maint | localhost | | mysql.infoschema | localhost | | mysql.session | localhost | | mysql.sys | localhost | | root | localhost | | user1 | localhost | +------------------+-----------+ 6 rows in set (0.00 sec) ``` ## Step 3 – Detailed User Information If you need more details about each user, you can expand the query to include additional columns: ```bash SELECT User, Host, authentication_string, plugin, password_expired FROM mysql.user; ``` Output: ```bash +------------------+-----------+------------------------------------------------------------------------+-----------------------+------------------+ | User | Host | authentication_string | plugin | password_expired | +------------------+-----------+------------------------------------------------------------------------+-----------------------+------------------+ | debian-sys-maint | localhost | $A$005$@Wdglgbtv|9j(cxJW68OpLkbqlxBgsfH0qsLhyC94qbAMa6zgVhVZA88 | caching_sha2_password | N | | mysql.infoschema | localhost | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | caching_sha2_password | N | | mysql.session | localhost | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | caching_sha2_password | N | | mysql.sys | localhost | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | caching_sha2_password | N | | root | localhost | | auth_socket | N | | user1 | localhost | $A$005$M)n~_ELK>wrj;@NL&wGXK82ttCQPwQelqbl8dDn6W1FQB6A21SIJozFOJsrA | caching_sha2_password | N | +------------------+-----------+------------------------------------------------------------------------+-----------------------+------------------+ 6 rows in set (0.00 sec) ``` In this output, you can see the authentication method, whether the password is expired, and other useful information. ## Step 4 – Filtering Users Sometimes, you might want to list users based on specific criteria. For example, to list only users that can connect from any host (%), use the following command. ```bash SELECT User, Host FROM mysql.user WHERE Host = '%'; ``` Output: ```bash +-------+------+ | User | Host | +-------+------+ | user1 | % | +-------+------+ ``` ## Step 5 – Managing User Privileges Understanding user privileges is crucial for database security. To list the privileges of a specific user, use the SHOW GRANTS command. For example, to display the privileges of user1: ```bash SHOW GRANTS FOR 'user1'@'%'; ``` Output: ```bash +-----------------------------------------------------------------+ | Grants for user1@% | +-----------------------------------------------------------------+ | GRANT USAGE ON *.* TO `user1`@`%` | | GRANT SELECT, INSERT ON `database1`.* TO `user1`@`%` | +-----------------------------------------------------------------+ ``` ## Step 6 – List MySQL Users Using mysqladmin Another way to list MySQL users is by using the mysqladmin command-line tool. This tool provides a quick way to perform various administrative tasks, including listing users. To see the general status of the MySQL server, including user information, use the following command: ```bash mysqladmin -u root -p extended-status ``` After entering the root password, you will see an extended status output. However, this command doesn’t directly list users but provides a comprehensive server status, which includes various metrics. To see the currently active MySQL users, you can use the processlist command: ```bash mysqladmin -u root -p processlist ``` Output: ```bash +----+------+-----------+-----------+---------+------+-------+------------------+ | Id | User | Host | db | Command | Time | State | Info | +----+------+-----------+-----------+---------+------+-------+------------------+ | 2 | root | localhost | mydb | Query | 0 | init | show processlist | | 3 | user1| localhost | database1 | Sleep | 5 | | | +----+------+-----------+-----------+---------+------+-------+------------------+ ``` This output shows the currently active users and their corresponding processes. ## Conclusion In this article, we covered how to show or list users in MySQL. You learned how to connect to MySQL, list all users, retrieve detailed user information, filter users based on specific criteria, and display user privileges. Additionally, we explored how to use the mysqladmin tool to view user information. You can now test MySQL on [**dedicated server hosting**](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # List (Show) Tables in a MySQL Database > URL: https://www.atlantic.net/dedicated-server-hosting/list-show-tables-in-a-mysql-database/ | Published: 2024-06-14 | Updated: 2024-07-15 | Author: Hitesh Jethva In this tutorial, you will learn how to connect to your MySQL server, select a database, and list all tables within that database. We will explore various commands such as SHOW TABLES, SHOW FULL TABLES, and queries on INFORMATION_SCHEMA. Additionally, we’ll look at how to describe a specific table and list tables using MySQL Workbench. ## Prerequisites Before we start, ensure you have the following: - MySQL installed on your system. - Access to a MySQL database (you should have login credentials). - Basic understanding of MySQL commands. ## Step 1- Connecting to MySQL To begin, you need to connect to your MySQL server. Open your terminal or command prompt and use the following command: ```bash mysql -u root -p ``` After entering your password, you’ll be connected to the MySQL shell. If you see the mysql> prompt, you’re good to go. ## Step 2 – Selecting the Database Once connected, select the database you want to work with. Use the USE command followed by the database name: ```bash USE your_database_name; ``` For example, if your database is named test_db, the command would be: ```bash USE test_db; ``` After executing this command, you should see the message “Database changed.” ## Step 3 – Listing Tables with SHOW TABLES The simplest way to list all tables in your selected database is by using the SHOW TABLES command. Execute the following: ```bash SHOW TABLES; ``` This will display all the tables in the current database. Here’s what the output might look like: ```bash +-------------------+ | Tables_in_test_db | +-------------------+ | departments | | employees | | salaries | +-------------------+ 3 rows in set (0.01 sec) ``` As you can see, the SHOW TABLES command is straightforward and provides a quick overview of all tables in the database. ## Step 4 – Listing Tables with SHOW FULL TABLES To get more detailed information about the tables, including whether they are base tables or views, use the SHOW FULL TABLES command: ```bash SHOW FULL TABLES; ``` This command will show the table type along with the table names: ```bash +-------------------+------------+ | Tables_in_test_db | Table_type | +-------------------+------------+ | departments | BASE TABLE | | employees | BASE TABLE | | salaries | BASE TABLE | +-------------------+------------+ 3 rows in set (0.00 sec) ``` ## Step 4 – Describing a Specific Table If you want more details about a specific table, you can use the DESCRIBE command. For instance, to describe the employees table, use: ```bash DESCRIBE employees; ``` This command will output the structure of the employees table, including column names, data types, and other attributes: ```bash +------------+---------------+------+-----+---------+-------+ | Field | Type | Null | Key | Default | Extra | +------------+---------------+------+-----+---------+-------+ | emp_no | int | NO | PRI | NULL | | | birth_date | date | NO | | NULL | | | first_name | varchar(14) | NO | | NULL | | | last_name | varchar(16) | NO | | NULL | | | gender | enum('M','F') | NO | | NULL | | | hire_date | date | NO | | NULL | | +------------+---------------+------+-----+---------+-------+ 6 rows in set (0.01 sec) ``` ## Step 5 – Using INFORMATION_SCHEMA to List Tables Another way to list tables is by querying the INFORMATION_SCHEMA database, which stores metadata about all your databases. Here’s how to retrieve table names from INFORMATION_SCHEMA: ```bash SELECT table_name FROM INFORMATION_SCHEMA.TABLES WHERE table_schema = 'test_db'; ``` Replace your_database_name with the name of your database. This query provides the same result as SHOW TABLES but can be more flexible for complex queries. Here’s an example output: ```bash +-------------+ | TABLE_NAME | +-------------+ | departments | | employees | | salaries | +-------------+ 3 rows in set (0.01 sec) ``` ## Step 6 – Show MySQL Tables from the Command Line For users who prefer command-line interfaces, you can also list MySQL tables directly from the command line without entering the MySQL shell. For example, if your username is root and your database is test_db, the command would be: ```bash mysql -u root -p -e 'SHOW TABLES;' test_db ``` After entering your password, the tables in the specified database will be listed directly in your terminal. ```bash +-------------------+ | Tables_in_test_db | +-------------------+ | departments | | employees | | salaries | +-------------------+ ``` ## Conclusion In this article, we explored various methods to list tables in a MySQL database. We covered the SHOW TABLES command for a quick overview, the SHOW FULL TABLES command for detailed table types, and the DESCRIBE command for table details. Additionally, we learned how to use INFORMATION_SCHEMA for more advanced queries. You can try to use MySQL on [**dedicated server hosting**](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Connect to MySQL through SSH Tunnel > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-connect-to-mysql-through-ssh-tunnel/ | Published: 2024-06-15 | Updated: 2024-07-15 | Author: Hitesh Jethva SSH tunneling provides a secure way to connect to your MySQL database over an encrypted SSH connection, protecting your data from being intercepted during transmission. This is especially useful when accessing a remote MySQL server that isn’t exposed to the public internet. In this tutorial, we will learn how to connect to a MySQL database using an SSH tunnel securely. ## Prerequisites Before we get started, make sure you have the following: - Access to a remote server with SSH enabled. - MySQL server installed and running on the remote server. - SSH client installed on your local machine. - MySQL client installed on your local machine. ## Step 1 – Open SSH Tunnel Using Command Line To create an SSH tunnel, you can use the ssh command from your local machine. The basic syntax is as follows: ```bash ssh -L local_port:remote_host:remote_port user@ssh_server -N ``` Here’s what each part means: - **-L local_port:remote_host:remote_port**: This specifies the local port, remote host, and remote port for the tunnel. - **user@ssh_server**: Your SSH username and the server you are connecting to. - **-N**: This tells SSH not to execute a remote command (just create the tunnel). For example, to forward your local port 3306 to the remote MySQL server’s port 3306 through an SSH server, you would use: ```bash ssh -L 3306:localhost:3306 root@mysql-server-ip -N ``` ## Step 2 – Verify the SSH Tunnel After running the command, your terminal will wait and not show any output, indicating that the tunnel is active. You can verify this by opening a new terminal window and checking the SSH connection: ```bash netstat -plant | grep 3306 ``` If the SSH tunnel is working, you should see output similar to this: ```bash tcp 0 0 127.0.0.1:3306 0.0.0.0:* LISTEN 1234/ssh ``` ## Step 3 – Connecting to MySQL Through the SSH Tunnel With the SSH tunnel set up, you can connect to the MySQL server using the mysql command: ```bash mysql -h 127.0.0.1 -P 3306 -u your_mysql_user -p ``` You will be prompted to enter your MySQL password. Once authenticated, you can run your MySQL commands as if connected directly to the remote server. ## Conclusion In this article, we demonstrated how to connect to a MySQL database securely using an SSH tunnel. We covered setting up the SSH tunnel from the command line, verifying the tunnel, and connecting to MySQL using the command line. SSH tunneling ensures your database connections are secure, protecting sensitive data from potential interception. You can now access your MySQL hosted on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Create and Delete a Postgres User > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-create-and-delete-a-postgres-user/ | Published: 2024-06-16 | Updated: 2024-07-15 | Author: Hitesh Jethva Managing users in PostgreSQL is a crucial aspect of database administration. Whether you’re setting up a new database or maintaining an existing one, knowing how to create and delete users efficiently is essential. In this tutorial, we’ll walk you through the entire process step-by-step, ensuring that even if you’re new to PostgreSQL, you’ll find it easy to follow. ## Prerequisites Before we begin, ensure you have: - PostgreSQL installed on your system - Access to a PostgreSQL database as a superuser or a user with sufficient privileges - Basic knowledge of SQL commands and PostgreSQL ## Step 1 – Connecting to PostgreSQL To manage users, you first need to connect to your PostgreSQL database. Use the psql command-line tool for this purpose. ```bash sudo -u postgres psql ``` This command connects you to the PostgreSQL server using the default postgres user. If you have set up a different superuser, replace postgres with that username. ```bash psql (13.3) Type "help" for help. postgres=# ``` You’re now connected to the PostgreSQL database and ready to create a new user. ## Step 2 – Creating a New User Creating a new user in PostgreSQL is straightforward. Use the CREATE USER command followed by the username and any optional parameters like password and privileges. ```bash CREATE USER new_user WITH PASSWORD 'password123'; ``` Output: ```bash CREATE ROLE ``` The command above creates a new user named **new_user** with the password **password123.** By default, this user has no privileges beyond connecting to the database. ## Step 3 – Granting Privileges to the User To make the new user more useful, you’ll likely want to grant some privileges. For instance, you might want the user to have the ability to create databases. ```bash ALTER USER new_user CREATEDB; ``` Output: ```bash ALTER ROLE ``` The ALTER USER command above grants the **CREATEDB** privilege to **new_user,** allowing them to create new databases. ## Step 4 – Deleting a User If you no longer need a user, you can remove them using the DROP USER command. Be careful with this operation as it cannot be undone. ```bash DROP USER new_user; ``` Output. ```bash DROP ROLE ``` The command above deletes the user **new_user** from the PostgreSQL database. ## Conclusion In this article, we covered the essential steps to create and delete a PostgreSQL user. You learned how to connect to your PostgreSQL database, create a new user, grant privileges, and finally, delete the user when they are no longer needed. These tasks are fundamental for PostgreSQL database administration and ensure that you can manage user access and permissions effectively. Try to create a user on PostgreSQL hosted on a [**dedicated server hosting**](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to List All Databases in PostgreSQL > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-list-all-databases-in-postgresql/ | Published: 2024-06-17 | Updated: 2024-07-15 | Author: Hitesh Jethva PostgreSQL is a powerful, open-source relational database management system used widely by developers and database administrators. Understanding how to list all databases in your PostgreSQL instance is crucial for database management and administration. In this tutorial, we will walk you through various methods to view all databases present in a PostgreSQL instance. ## Prerequisites Before we dive into the details, make sure you have the following: - PostgreSQL is installed on your system. - Access to the PostgreSQL command line. ## 1. Using the psql Command Line Interface The psql command line interface is a powerful tool to interact with your PostgreSQL database. Here’s how you can list all databases using psql. 1. First, you need to access the psql command line. Open your terminal and connect to your PostgreSQL server by running: ```bash sudo -u postgres psql ``` Replace **postgres** with your PostgreSQL username. You will be prompted to enter your password. 2. Once you are logged in, you can list all databases by using the following command: ```bash \l ``` Alternatively, you can use: ```bash \list ``` Output: ```bash List of databases Name | Owner | Encoding | Collate | Ctype | Access privileges ------------+----------+----------+-------------+-------------+----------------------- mydatabase | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | postgres | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | template0 | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | =c/postgres + | | | | | postgres=CTc/postgres template1 | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | =c/postgres + | | | | | postgres=CTc/postgres ``` This output lists all databases along with their owners, encoding, collation, ctype, and access privileges. ## 2. Using SQL Queries You can also use a SQL query to list all databases. This method can be handy if you prefer to use SQL commands directly. 1. Connect to your PostgreSQL server using the psql command line as described earlier. 2. Run the following SQL query to list all databases: ```bash SELECT datname FROM pg_database; ``` Output: ```bash datname ------------ postgres mydatabase template1 template0 (4 rows) ``` This query retrieves the names of all databases from the pg_database system catalog. ## Conclusion In this article, we explored several methods for listing all databases in PostgreSQL. We covered how to use the psql command line interface and execute SQL queries to view all databases. Each method offers a different approach, allowing you to choose the one that best suits your workflow. You can now test this tutorial on [**dedicated server hosting**](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Create and Delete a Postgres Database > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-create-and-delete-a-postgres-database/ | Published: 2024-06-18 | Updated: 2024-07-15 | Author: Hitesh Jethva Managing databases is a fundamental skill for any database administrator or developer. This tutorial will guide you through the steps to create and delete databases in PostgreSQL. We’ll start by setting up the necessary environment and ensuring you have the required permissions. Then, we’ll dive into the commands needed to create and delete databases. ## Prerequisites Before we begin, make sure you have: - PostgreSQL is installed on your system. - Access to the psql command-line tool. - Superuser privileges or appropriate permissions to create and delete databases. ## Step 1 – Connecting to PostgreSQL First, let’s connect to the PostgreSQL server using the psql command-line tool. Open your terminal and run: ```bash sudo -u postgres psql ``` You’ll be prompted to enter your password. After successfully logging in, you’ll see the psql prompt: ```bash postgres=# ``` ## Step 2 – Creating a PostgreSQL Database To create a new PostgreSQL database, use the CREATE DATABASE command followed by the name of the database you want to create. Let’s create a database named **mydatabase:** ```bash CREATE DATABASE mydatabase; ``` After running this command, you should see a confirmation message: ```bash CREATE DATABASE ``` To verify that the database has been created, list all databases: ```bash \l ``` You should see **mydatabase** in the list: ```bash List of databases Name | Owner | Encoding | Collate | Ctype | Access privileges ------------+----------+----------+-------------+-------------+----------------------- mydatabase | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | postgres | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | template0 | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | =c/postgres + | | | | | postgres=CTc/postgres template1 | postgres | UTF8 | en_US.UTF-8 | en_US.UTF-8 | =c/postgres + | | | | | postgres=CTc/postgres (4 rows) ``` ## Step 3 – Connecting to the New Database Once the database is created, you can connect to it using the **\c** command followed by the database name: ```bash \c mydatabase ``` You should see a message confirming the connection: ```bash You are now connected to database "mydatabase" as user "postgres". mydatabase=# ``` ## Step 4 – Deleting a PostgreSQL Database To delete a PostgreSQL database, use the DROP DATABASE command followed by the name of the database. Be cautious with this command as it permanently deletes all data in the database. Let’s delete mydatabase: First, disconnect from the database (if you are currently connected to it): ```bash \c postgres ``` Then, run the DROP DATABASE command: ```bash DROP DATABASE mydatabase; ``` You should see a confirmation message: ```bash DROP DATABASE ``` To verify that the database has been deleted, list all databases again: ```bash \l ``` You should no longer see mydatabase in the list. ## Conclusion In this article, we covered how to create and delete a PostgreSQL database. We started by connecting to the PostgreSQL server, then we created a new database and verified its creation. Finally, we demonstrated how to delete the database and verify its deletion. You can now manage your PostgreSQL server on [**dedicated server hosting**](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Back Up and Restore a MySQL Database > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-back-up-and-restore-a-mysql-database/ | Published: 2024-06-19 | Updated: 2024-07-15 | Author: Hitesh Jethva Backing up your database is essential for preventing data loss and ensuring you can recover from system failures or accidental deletions. Restoring a database is equally important, allowing you to recover data from backups and maintain business continuity. In this tutorial, we will guide you through the process of backing up and restoring a MySQL database. ## Introduction to MySQL Backups MySQL backups are crucial for data protection. A good backup strategy ensures that you can recover from data loss, corruption, or other disasters. There are different types of backups: full backups, incremental backups, and differential backups. - **Full Backup:** This involves creating a complete copy of the database. It is the most comprehensive type but can be time-consuming and resource-intensive. - **Incremental Backup:** This captures only the changes made since the last backup. It is quicker and uses fewer resources but requires more effort during restoration. - **Differential Backup:** This captures all changes made since the last full backup. It is a balance between full and incremental backups. ## Basic Syntax for Backing Up and Restoring Databases Before diving into detailed methods and examples, it’s important to understand the basic syntax for backing up and restoring MySQL databases using the command line. ### Basic Syntax for Backing Up To back up a MySQL database, you can use the mysqldump command. The basic syntax is: ```bash mysqldump -u [username] -p [database_name] > [backup_file.sql] ``` - **-u [username]**: Specifies the MySQL username. - **-p**: Prompts for the MySQL password. - **[database_name]**: Name of the database you want to back up. - **> [backup_file.sql]**: Redirects the output to a SQL file. ### Basic Syntax for Restoring To restore a MySQL database from a backup file, you can use the mysql command. The basic syntax is: ```bash mysql -u [username] -p [database_name] < [backup_file.sql] ``` - **-u [username]**: Specifies the MySQL username. - **-p**: Prompts for the MySQL password. - **[database_name]**: Name of the database you want to restore. - **< [backup_file.sql]**: Redirects the input from a SQL file. ## Backup a MySQL Database To back up a single database named **exampledb,** run: ```bash mysqldump -u root -p exampledb > exampledb_backup.sql ``` When prompted, enter your MySQL password. This command creates a file named **exampledb_backup.sql** containing the SQL statements needed to recreate the database. To backup multiple databases, run: ```bash mysqldump -u root -p --databases db1 db2 db3 > multiple_dbs_backup.sql ``` This command creates a backup file named **multiple_dbs_backup.sql** that contains the SQL statements for **db1, db2,** and **db3.** To backup all databases, run: ```bash mysqldump -u root -p --all-databases > all_dbs_backup.sql ``` This command creates a backup file named **all_dbs_backup.sql** containing the SQL statements for all databases on the server. ## Restore a MySQL Database Restoring a MySQL database can be done using the mysql command-line utility. The mysql utility allows you to execute SQL statements stored in a file. This is useful for restoring backups created with mysqldump. To restore a single database from a backup file named exampledb_backup.sql, run: ```bash mysql -u root -p exampledb < exampledb_backup.sql ``` When prompted, enter your MySQL password. This command restores the **exampledb** database from the **exampledb_backup.sql** file. To restore multiple databases from a backup file named **multiple_dbs_backup.sql,** run: ```bash mysql -u root -p < multiple_dbs_backup.sql ``` This command restores the databases db1, db2, and db3 from the multiple_dbs_backup.sql file. To restore all databases from a backup file named **all_dbs_backup.sql,** run: ```bash mysql -u root -p < all_dbs_backup.sql ``` This command restores all databases from the all_dbs_backup.sql file. ## Conclusion In this article, we explored the importance of backing up and restoring MySQL databases. We discussed different types of backups and demonstrated how to back up and restore databases using mysqldump. We covered how to back up and restore single databases, multiple databases, and all databases. Backing up your data is essential for preventing data loss, and knowing how to restore it ensures that you can recover quickly from any issues. You can now perform MySQL backup operations on [**dedicated server hosting**](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install SolidInvoice on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-solidinvoice-on-ubuntu-22-04/ | Published: 2024-06-20 | Updated: 2024-07-15 | Author: Hitesh Jethva SolidInvoice is an open-source invoicing application designed for small to medium-sized businesses. It is a robust invoicing application that helps businesses streamline their invoicing and billing processes. It offers features such as client management, quote creation, payment tracking, and more, making it an ideal choice for businesses looking to improve their financial management. In this tutorial, we will explain how to install and configure SolidInvoice on Ubuntu 22.04. ## Step 1 – Install LAMP Server SolidInvoice requires a web server, a database server, and PHP with various extensions. We’ll use Apache as our web server and MariaDB as our database server. Install Apache, MariaDB, PHP, and the necessary PHP extensions with the following command: ```bash apt install apache2 mariadb-server mariadb-client php php-curl php-common php-mbstring php-json php-mysql php-opcache php-bcmath php-intl php-gd php-xml php-soap php-zip php-apcu unzip ``` Verify the PHP installation: ```bash php -v ``` You should see output similar to this: ```bash PHP 8.1.2-1ubuntu2.18 (cli) (built: Jun 14 2024 15:52:55) (NTS) Copyright (c) The PHP Group Zend Engine v4.1.2, Copyright (c) Zend Technologies with Zend OPcache v8.1.2-1ubuntu2.18, Copyright (c), by Zend Technologies ``` Open the PHP configuration file for Apache: ```bash nano /etc/php/8.1/apache2/php.ini ``` Modify the following settings: ```bash date.timezone = UTC memory_limit=512M upload_max_filesize=64M post_max_size=120M max_execution_time=120 ``` Save and close the file, then restart Apache to apply the changes: ```bash systemctl restart apache2 ``` ## Step 2 – Configure MariaDB Database Log in to the MariaDB shell. ```bash mysql ``` Create a database and user for SolidInvoice: ```bash CREATE DATABASE solidinvoice; CREATE USER solidinvoice@localhost IDENTIFIED BY 'securepassword'; ``` Grant all the privileges to the SolidInvoice database. ```bash GRANT ALL PRIVILEGES ON solidinvoice.* TO solidinvoice@localhost; ``` Flush the privileges and exit from the MariaDB shell. ```bash FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download and Install SolidInvoice Download the latest version of SolidInvoice from the Sourceforge website. ```bash wget https://master.dl.sourceforge.net/project/solidinvoice.mirror/2.2.6/SolidInvoice-2.2.6.zip ``` Unzip the downloaded file to the web root directory: ```bash unzip SolidInvoice-2.2.6.zip -d /var/www/html/solidinvoice ``` Set the appropriate permissions: ```bash chown -R www-data:www-data /var/www/html/solidinvoice chmod -R 775 /var/www/html/solidinvoice ``` ## Step 4 – Configure Apache Create a new virtual host configuration for SolidInvoice: ```bash nano /etc/apache2/sites-available/solidinvoice.conf ``` Add the following content: ```bash ServerName invoice.example.com DocumentRoot /var/www/html/solidinvoice/public AllowOverride All Order allow,deny Allow from All ErrorLog /var/log/apache2/solidinvoice.error.log CustomLog /var/log/apache2/solidinvoice.access.log combined ``` Save and close the file, then activate the new virtual host and enable the Apache rewrite module. ```bash a2ensite solidinvoice.conf a2enmod rewrite ``` Restart Apache to apply the changes: ```bash systemctl restart apache2 ``` ## Step 5 – Set Up Cron Job SolidInvoice requires a cron job to handle background tasks. Open the crontab file: ```bash nano /etc/crontab ``` Add the following line: ```bash * * * * * php /var/www/html/solidinvoice/bin/console cron:run -e prod -n ``` This cron job runs every minute and executes SolidInvoice’s background tasks. ## Step 6 – Complete the Installation Through the Web Interface Open your web browser and navigate to **http://invoice.example.com.** You should see the SolidInvoice PHP requirement page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p1-8.png) Make sure all dependencies are installed, then click on **Next.** You will see the database setup page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p2-7.png) Define your database and click on **Next**. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p3-4.png) Click on **Next**. You will see the system settings page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p4-4.png) Define your admin user and password and click on **Next**. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p5-3.png) Click on **Log in** now. You will see the Solidinvoice login page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p6-2.png) Provide your admin credential and click on **Login**. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p7-2.png) Define your company name and click on **Create**. You will see the Solidinvoice dashboard. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p8-1.png) ## Conclusion Congratulations! You have successfully installed SolidInvoice on your Ubuntu 22.04 server. With SolidInvoice, you can efficiently manage your invoicing and billing processes, helping you to keep track of clients, quotes, and payments seamlessly. This installation provides a solid foundation for your business operations, ensuring you have a reliable and efficient system in place. Let’s try to deploy SolidInvoice on [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) hosting from Atlantic.Net! --- # How to Install CrowdSec IDS on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-crowdsec-ids-on-ubuntu-22-04/ | Published: 2024-06-21 | Updated: 2024-07-15 | Author: Hitesh Jethva Intrusion Detection Systems (IDS) play a crucial role in safeguarding your network by monitoring and analyzing traffic for suspicious activities and potential threats. CrowdSec is an open-source, collaborative security platform leveraging community-driven threat intelligence’s power to provide robust protection. It offers an efficient and scalable way to detect and mitigate a wide range of security threats, from brute force attacks to more sophisticated exploits. In this guide, we will walk you through the process of installing CrowdSec IDS on Ubuntu 22.04. ## Step 1 – Install CrowdSec First, you need to add the CrowdSec repository to install CrowdSec. ```bash curl -s https://packagecloud.io/install/repositories/crowdsec/crowdsec/script.deb.sh | bash ``` This command downloads and runs a script to add the CrowdSec repository to your system. Next, install CrowdSec. ```bash apt install crowdsec ``` You will be asked to select the service that you want to monitor. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p1-9.png) Select any service and click on **Continue**. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p2-8.png) Select any service from the above list or click on **Cancel** to finish the installation. ## Step 2 – Install Firewall Bouncer Next, install the CrowdSec Firewall Bouncer for IPTables. This will enable CrowdSec to interact with your firewall to block malicious IPs. ```bash apt install -y crowdsec-firewall-bouncer-iptables ``` ## Step 3 – Verify Installation To verify that CrowdSec is installed and running correctly, use the following command: ```bash cscli collections list ``` This will display a list of installed collections: ```bash COLLECTIONS ───────────────────────────────────────────────────────────────────────────────────────────────────────────── Name 📦 Status Version Local Path ───────────────────────────────────────────────────────────────────────────────────────────────────────────── crowdsecurity/apache2 ✔️ enabled 0.1 /etc/crowdsec/collections/apache2.yaml crowdsecurity/base-http-scenarios ✔️ enabled 1.0 /etc/crowdsec/collections/base-http-scenarios.yaml crowdsecurity/http-cve ✔️ enabled 2.6 /etc/crowdsec/collections/http-cve.yaml crowdsecurity/linux ✔️ enabled 0.2 /etc/crowdsec/collections/linux.yaml crowdsecurity/sshd ✔️ enabled 0.3 /etc/crowdsec/collections/sshd.yaml ───────────────────────────────────────────────────────────────────────────────────────────────────────────── ``` ## Step 4 – Set Up Dashboard To set up the CrowdSec dashboard, you will need Docker. First, install Docker: ```bash apt install -y docker.io ``` Then, set up the CrowdSec dashboard: ```bash cscli dashboard setup ``` You will be prompted to accept the security responsibility for the Metabase instance and to add a new group called ‘crowdsec’. Accept these prompts by typing Yes. The setup process will pull the necessary Docker image and start the Metabase container. Once it’s ready, you will see the following information: ```bash ? CrowdSec takes no responsibility for the security of your metabase instance. Do you accept these responsibilities ? Yes ? For metabase docker to be able to access SQLite file we need to add a new group called 'crowdsec' to the system, is it ok for you ? Yes INFO Pulling docker image metabase/metabase:v0.46.6.1 INFO creating container 'crowdsec-metabase' INFO waiting for metabase to be up (can take up to a minute) ............ INFO Metabase is ready URL : 'http://127.0.0.1:3000' username : 'crowdsec@crowdsec.net' password : 'cmC3d6ynmhKqopnY' ``` Note down the username and password from the above output. ## Step 5 – Accessing the Dashboard By default, the CrowdSec dashboard can be accessed only from the local host. To access the dashboard from a remote machine, you need to forward the local port **3000** to the CrowdSec server’s port **3000** using SSH: ```bash ssh -L 3000:127.0.0.1:3000 your_username@remote_server_ip ``` Replace **your_username** with your actual username on the remote server and **remote_server_ip** with the IP address or hostname of the remote server. Open your web browser and navigate to **http://127.0.0.1:3000.** This will forward your local port **3000** to port **3000** on the remote server, allowing you to access the remote web application as if it were running locally. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p4-5.png) Provide your CrowdSec credential and click on Sign In. The CrowdSec dashboard will appear on the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p5-4.png) ## Step 5 – Enable and Disable Scenarios You can enable or disable specific scenarios using the **cscli** command. For example, to enable the SSH brute-force scenario in simulation mode: ```bash cscli simulation enable crowdsecurity/ssh-bf systemctl reload crowdsec ``` To disable the SSH brute-force scenario: ```bash cscli simulation disable crowdsecurity/ssh-bf systemctl reload crowdsec ``` ## Conclusion Congratulations! You have successfully installed and configured CrowdSec IDS on Ubuntu 22.04. With CrowdSec, you now have a powerful tool to protect your server from various cyber threats. The dashboard provides an intuitive interface for monitoring and managing security incidents. Regularly check for updates and new scenarios to keep your system secure. You can start deploying CrowdSec IDS on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install ClickHouse OLAP Database System Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-clickhouse-olap-database-system-ubuntu-22-04/ | Published: 2024-06-22 | Updated: 2024-08-19 | Author: Hitesh Jethva ClickHouse is an open-source columnar database management system designed for online analytical processing (OLAP). It was developed by Yandex, a Russian multinational corporation specializing in Internet-related products and services. ClickHouse is known for its high performance in handling large volumes of data and its ability to execute complex queries in real-time, making it an ideal solution for data analytics and big data applications. This tutorial will guide you through the process of installing ClickHouse on an Ubuntu 22.04 system, configuring it, and performing basic operations. ## Step 1 – Install Required Dependencies ClickHouse requires certain dependencies to be installed on your system. Install these dependencies using the following command: ```bash apt install apt-transport-https ca-certificates dirmngr ``` ## Step 2 – Add ClickHouse Repository and GPG Key Next, we need to add the ClickHouse repository to our system’s package sources list and import the GPG key to ensure the packages’ authenticity. ```bash apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv 8919F6BD2B48D754 echo "deb https://packages.clickhouse.com/deb stable main" | tee /etc/apt/sources.list.d/clickhouse.list ``` After adding the ClickHouse repository, update your package list to include the new repository: ```bash apt update ``` ## Step 3 – Install ClickHouse Now, install the ClickHouse server and client using the following command: ```bash apt install clickhouse-server clickhouse-client ``` You will be asked to set a password for the default user. ```bash Enter password for the default user: Password for the default user is saved in file /etc/clickhouse-server/users.d/default-password.xml. ``` You can also access the **/etc/clickhouse-server/users.d/default-password.xml** file to retrieve or change the password as needed. ## Step 4 – Start and Enable ClickHouse Service To start the ClickHouse server and enable it to start on boot, use the following commands: ```bash systemctl start clickhouse-server systemctl enable clickhouse-server ``` Verify that the ClickHouse server is running: ```bash systemctl status clickhouse-server ``` You should see output similar to the following, indicating that the service is active and running: ```bash ● clickhouse-server.service - ClickHouse Server (analytic DBMS for big data) Loaded: loaded (/lib/systemd/system/clickhouse-server.service; enabled; vendor preset: enabled) Active: active (running) since Wed 2024-06-26 11:27:31 UTC; 3s ago Main PID: 43570 (clickhouse-serv) Tasks: 666 (limit: 4579) Memory: 133.7M CPU: 1.065s CGroup: /system.slice/clickhouse-server.service ├─43569 clickhouse-watchdog "" "" "" "" "" "" "" --config=/etc/clickhouse-server/config.xml --pid-file=/run/clickhouse-server/clickhouse-server.pid └─43570 /usr/bin/clickhouse-server --config=/etc/clickhouse-server/config.xml --pid-file=/run/clickhouse-server/clickhouse-server.pid Jun 26 11:27:30 ubuntu systemd[1]: Starting ClickHouse Server (analytic DBMS for big data)... Jun 26 11:27:30 ubuntu clickhouse-server[43569]: Processing configuration file '/etc/clickhouse-server/config.xml'. Jun 26 11:27:30 ubuntu clickhouse-server[43569]: Logging trace to /var/log/clickhouse-server/clickhouse-server.log Jun 26 11:27:30 ubuntu clickhouse-server[43569]: Logging errors to /var/log/clickhouse-server/clickhouse-server.err.log ``` ## Step 5 – Access ClickHouse Client To interact with the ClickHouse server, use the ClickHouse client. Open the client and log in using the default user: ```bash clickhouse-client --user default --password Enter the password when prompted. You should see a prompt similar to this: ClickHouse client version 24.5.3.5 (official build). Password for user (default): Connecting to localhost:9000 as user default. Connected to ClickHouse server version 24.5.3. Warnings: * Delay accounting is not enabled, OSIOWaitMicroseconds will not be gathered. You can enable it using `echo 1 > /proc/sys/kernel/task_delayacct` or by using sysctl. * Maximum number of threads is lower than 30000. There could be problems with handling a lot of simultaneous queries. ubuntu :) ``` ## Step 6 – Basic Operations in ClickHouse Now that ClickHouse is installed and running, let’s perform some basic operations to familiarize ourselves with the database system. Create a new database named db1: ```bash CREATE DATABASE db1; USE db1; ``` Create a table named users with some sample columns: ```bash CREATE TABLE users (id UInt64, name String, jobs String, last_login DateTime) ENGINE=MergeTree() PRIMARY KEY id ORDER BY id; ``` Insert some sample data into the user’s table: ```bash INSERT INTO users VALUES (1, 'jay', 'admin', '2024-06-10 00:10:10'); INSERT INTO users VALUES (2, 'hit', 'Manager', '2024-06-05 01:19:10'); ``` Query the data from the user’s table: ```bash SELECT * FROM users; ``` The output should be: ```bash Query id: 9ff7c880-b63b-4762-b90e-f32f0020564f ┌─id─┬─name─┬─jobs────┬──────────last_login─┐ 1. │ 2 │ hit │ Manager │ 2024-06-05 01:19:10 │ └────┴──────┴─────────┴─────────────────────┘ ┌─id─┬─name─┬─jobs──┬──────────last_login─┐ 2. │ 1 │ jay │ admin │ 2024-06-10 00:10:10 │ └────┴──────┴───────┴─────────────────────┘ ``` Update a record in the user table: ```bash ALTER TABLE users UPDATE jobs = 'Administrator' WHERE name = 'hit'; ``` Verify the update by querying the data again: ```bash SELECT * FROM users; ``` The output should show the updated data: ```bash ┌─id─┬─name─┬─jobs──────────┬──────────last_login─┐ 1. │ 2 │ hit │ Administrator │ 2024-06-05 01:19:10 │ └────┴──────┴───────────────┴─────────────────────┘ ┌─id─┬─name─┬─jobs──┬──────────last_login─┐ 2. │ 1 │ jay │ admin │ 2024-06-10 00:10:10 │ └────┴──────┴───────┴─────────────────────┘ ``` Finally, drop the table and database: ```bash DROP TABLE users; DROP DATABASE db1; ``` List all databases to ensure db1 has been dropped: ```bash SHOW DATABASES; ``` You should see the following databases: ```bash ┌─name───────────────┐ 1. │ INFORMATION_SCHEMA │ 2. │ default │ 3. │ information_schema │ 4. │ system │ └────────────────────┘ ``` ## Conclusion In this tutorial, we covered the installation of ClickHouse on an Ubuntu 22.04 system, starting and enabling the ClickHouse service, and performing basic database operations. ClickHouse is a robust tool for OLAP applications, offering high performance for real-time analytics. By following these steps, you should have a fully functional ClickHouse setup ready for your data analytics needs. applications. With this setup, you can now start building your own MQTT-based solutions. You can use Mosquitto MQTT as a database on [**dedicated server hosting**](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Mosquitto MQTT Server on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-mosquitto-mqtt-server-on-ubuntu-24-04/ | Published: 2024-06-23 | Updated: 2025-07-05 | Author: Hitesh Jethva Mosquitto MQTT is an open-source message broker that implements the MQTT protocol. It is a lightweight, publish-subscribe network protocol designed for low-bandwidth, high-latency networks. It facilitates efficient communication between devices, making it ideal for Internet of Things (IoT) applications and other scenarios requiring reliable message delivery with minimal overhead. Mosquitto supports various security features, such as TLS encryption and authentication, ensuring secure data transmission. Its ability to handle thousands of concurrent connections makes it suitable for large-scale deployments. In this tutorial, we will walk you through the process of installing the Mosquitto MQTT Server on Ubuntu 24.04. ## Step 1 – Installing Required Packages First, we need to update our package list and install some essential packages required for the installation process. Open your terminal and run the following command to make sure the packages you need are available – please note, most of these may already be installed by default: ```bash apt-get update apt-get install curl gnupg2 wget git apt-transport-https ca-certificates -y ``` ## Step 2 – Adding the Mosquitto PPA Next, we need to add the Mosquitto PPA (Personal Package Archive) to our system. The PPA provides the latest version of Mosquitto. Run the following command: ```bash add-apt-repository ppa:mosquitto-dev/mosquitto-ppa -y ``` This command adds the Mosquitto PPA to your system’s software sources. ## Step 3 – Installing Mosquitto and Mosquitto Clients Now that the PPA has been added, we can install Mosquitto and its clients. Execute the following command: ```bash apt install mosquitto mosquitto-clients -y ``` This command installs the Mosquitto server and the Mosquitto client utilities (mosquitto_sub and mosquitto_pub). To verify that Mosquitto has been installed correctly and is running, use the **systemctl** command to check its status: ```bash systemctl status mosquitto ``` You should see an output similar to this: ```bash ● mosquitto.service - Mosquitto MQTT Broker Loaded: loaded (/usr/lib/systemd/system/mosquitto.service; enabled; preset: enabled) Active: active (running) since Mon 2025-05-12 06:23:36 UTC; 9s ago Docs: man:mosquitto.conf(5) man:mosquitto(8) Process: 49200 ExecStartPre=/bin/mkdir -m 740 -p /var/log/mosquitto (code=exited, status=0/SUCCESS) Process: 49202 ExecStartPre=/bin/chown mosquitto:mosquitto /var/log/mosquitto (code=exited, status=0/SUCCESS) Process: 49204 ExecStartPre=/bin/mkdir -m 740 -p /run/mosquitto (code=exited, status=0/SUCCESS) Process: 49206 ExecStartPre=/bin/chown mosquitto:mosquitto /run/mosquitto (code=exited, status=0/SUCCESS) Main PID: 49208 (mosquitto) Tasks: 1 (limit: 4609) Memory: 1.0M (peak: 1.5M) CPU: 25ms CGroup: /system.slice/mosquitto.service └─49208 /usr/sbin/mosquitto -c /etc/mosquitto/mosquitto.conf May 12 06:23:36 ubuntu systemd[1]: Starting mosquitto.service - Mosquitto MQTT Broker... May 12 06:23:36 ubuntu systemd[1]: Started mosquitto.service - Mosquitto MQTT Broker. ``` The output indicates that the Mosquitto service is active and running. ## Step 4 – Configuring Mosquitto By default, Mosquitto is configured to allow anonymous connections. For security reasons, it is recommended to set up a password for your Mosquitto broker. Run the following command to create a password file and add a user: ```bash mosquitto_passwd -c /etc/mosquitto/passwd hjethva ``` You will be prompted to enter and confirm a password for the user you just created (**hjethva**). ```bash Password: Reenter password: ``` Set the correct ownership for the password file: ```bash chown mosquitto:mosquitto /etc/mosquitto/passwd ``` Next, create a configuration file to specify the listener and password file. Open the configuration file with nano: ```bash nano /etc/mosquitto/conf.d/default.conf ``` Add the following lines: ```bash listener 1883 password_file /etc/mosquitto/passwd ``` These lines configure Mosquitto to listen on port 1883 and use the specified password file for authentication. After making these changes, restart the Mosquitto service to apply the new configuration: ```bash systemctl restart mosquitto ``` ## Step 5 – Testing Mosquitto To ensure everything is working correctly, we will test Mosquitto using the mosquitto_pub and mosquitto_sub commands. Open a terminal window and subscribe to a topic – remember to change the YOUR_PASSWORD value. ```bash mosquitto_sub -u hjethva -P YOUR_PASSWORD -v -t "hello/topic" ``` In another terminal window, publish a message on the same topic – – remember to change the YOUR_PASSWORD value. ```bash mosquitto_pub -u hjethva -P YOUR_PASSWORD -t 'hello/topic' -m 'hello MQTT' ``` You should see the following output in the subscriber terminal: ```bash hello/topic hello MQTT ``` This confirms that the Mosquitto server is working correctly. ## Conclusion In this tutorial, we have covered the installation and configuration of the Mosquitto MQTT server on Ubuntu 24.04. We also demonstrated how to secure the server with a password and tested the setup using Mosquitto client tools. Mosquitto is a powerful and lightweight MQTT broker that is widely used in IoT and messaging applications. With this setup, you can now start building your own MQTT-based solutions. You can try deploying Mosquitto MQTT on [**dedicated server hosting**](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Virtual Private Cloud Server: Clearing the Confusion > URL: https://www.atlantic.net/vps-hosting/virtual-private-cloud-server-a-comprehensive-guide/ | Published: 2024-06-24 | Updated: 2026-03-04 | Author: Richard Bailey The term *Virtual Private Cloud Server* is sometimes used interchangeably with *Virtual Private Cloud* or *Virtual Private Server*, causing significant confusion for those new to cloud computing. The issue stems from the fact that the term itself is a misnomer, attempting to combine two distinct concepts that serve different functions within cloud infrastructure resources. You can break these concepts into VPC and VPS; let’s clear up this confusion once and for all by clearly defining what exactly each technology is: ### **Virtual Private Cloud (VPC):** A Virtual Private Cloud (VPC) is a secure and isolated private network within a public cloud. It provides users with complete control over their virtual network environment, including IP address range, subnets, and security settings. ### **Virtual Private Server (VPS):** A Virtual Private Server (VPS) is a virtualized server environment within a physical server, providing dedicated resources and greater control than shared hosting while being more affordable than a dedicated server. The *conflation* of these terms leads to misunderstandings about Virtual Private Clouds and how they differ from VPSes or VPCs. Some cloud providers might even use these terms to refer to a specific type of VPS product, further muddying the waters. This article aims to resolve this confusion by clearly exploring VPC and VPS solutions. Our goal is to simplify the concepts to help you choose the right solution for your needs. ## What Is a Virtual Private Cloud (VPC)? A [Virtual Private Cloud](https://www.atlantic.net/vps-hosting/virtual-private-cloud-vs-private-cloud/) (VPC) is a secure, isolated virtual network established within a public cloud infrastructure. A popular analogy is to think of it as renting an apartment in a multi-tenant building. You have exclusive access to your apartment, the ability to control who comes and goes, and the freedom to customize the layout and use of the space. The isolation enhances security and privacy, as your resources are segregated from other tenants on different floors. Within your VPC, you can create and manage multiple resources like virtual machines (VMs), databases, storage, and virtual networks. These resources can communicate securely within your dedicated floor and with your company’s headquarters (your on-premises network) if necessary. ### **Key Benefits of VPCs:** #### Enhanced Security: VPCs offer an additional layer of security within a public cloud provider’s environment. Unlike resources deployed in shared public cloud infrastructure, VPCs provide a private space where you can control access to all resources. Logical isolation safeguards your valuable data and applications from unauthorized access by other public cloud tenants on the same infrastructure. A VPC creates enhanced security for businesses handling sensitive information and those subject to strict compliance. #### Isolated Environment Customization: VPCs are highly customizable, offering options to configure network access control lists (ACLs) and security groups to restrict access based on IP addresses or protocols. Administrators can define custom IP ranges to create a logically isolated network within the cloud provider’s data center. This level of customization allows you to mirror your on-premises network architecture in the cloud or create entirely new configurations. Best of all, you can integrate your services with public cloud resources. #### Scalability: VPCs are inherently scalable, enabling you to adapt to changing workloads. You can deploy dynamically provisioned virtual servers across multiple availability zones within a VPC. Such scalability ensures that your applications can handle spikes in traffic or resource demands without impacting performance. You can also integrate machine learning models for predictive scaling, further optimizing resource utilization. #### Cost Efficiency: By giving you granular control over your resources, you can optimize your cloud deployment to avoid overprovisioning. You only pay for the resources you actually use, which can lead to significant savings compared to traditional data centers, where you might need to maintain excess capacity for peak loads. ## What Is the Difference between a Virtual Private Server (VPS) and a Virtual Private Cloud (VPC)? A Virtual Private Server (VPS) is a virtualized instance of a physical server hosted on a cloud platform, typically within a private cloud infrastructure. A single physical server is divided into multiple VPSes, each acting as an independent server with its own operating system, resources, and dedicated storage. The crucial distinction is that a VPC is an entire virtual network, while a VPS is a single virtual machine (or server) residing within that network. You can have multiple VPSes running within a VPC, each serving different purposes, such as web hosting, application hosting, or database management. ### **Key benefits of VPSes:** Virtual Private Servers (VPSes) provide a powerful and flexible solution for hosting websites and applications. They offer a middle ground between shared hosting and dedicated servers, making them ideal for businesses and individuals seeking a balance of affordability, performance, and control. Here’s a closer look at the key benefits of VPSes, with a focus on their use in cloud environments: #### **Cost-Effective Cloud Hosting:** VPSes offer a cost-effective alternative to dedicated servers, particularly when hosted on a public cloud platform like Google Cloud Platform (GCP). Businesses can choose from various cloud providers and pricing models, paying only for the resources they use and avoiding the upfront costs of purchasing and maintaining physical servers. #### **Root Access and Customization:** Just like traditional dedicated servers, cloud-hosted VPSes provide root access, giving users complete control over their virtual server environment. This allows businesses and IT teams to install custom software, configure settings to their exact specifications, and tailor the environment to their specific needs. #### **Isolation and Security:** VPSs are logically isolated networks, ensuring that each VPS operates independently within the cloud environment. This isolation protects against the “noisy neighbor” effect, where one VPS’s excessive resource usage could impact others sharing the same physical server. Additionally, cloud providers often implement robust security measures to protect VPSes and their customer’s data. #### **Scalability and Flexibility:** Cloud VPSes can be deployed dynamically and scaled up or down easily to accommodate changing needs. This flexibility is a major advantage for businesses experiencing growth or seasonal fluctuations in traffic. Public cloud providers offer a range of VPS configurations, allowing businesses to choose the right resources to optimize performance and cost. **High Availability and Reliability:** Public cloud offerings typically include built-in redundancy and failover mechanisms to minimize downtime. If a physical server fails, the VPS can be quickly migrated to another server, ensuring that websites and applications remain accessible. #### **Private Cloud Options:** While public cloud providers like Google Cloud are popular choices, some organizations opt for private cloud-hosted VPS solutions like Atlantic.Net. Private clouds offer greater control and customization but may require more in-house IT expertise. Hybrid cloud deployments, combining public and private clouds, offer another option for businesses seeking flexibility and control over their data. Whether you choose a public cloud provider, a private cloud-hosted solution, or a hybrid approach, VPSes in the cloud environment offer a powerful and flexible way to host your applications and websites. ## What Is the Difference between VPC and VPN? Another term that is often confused with VPC is a Virtual Private Network (VPN), a technology that creates a secure, encrypted tunnel over a public network (like the Internet) to connect remote users or locations to a private network. It acts like a secure bridge, allowing you to access private resources remotely as if you were physically present on the network. The primary difference between a VPC and a VPN is their scope. A VPC is a private virtual network, while a VPN is a tool to securely access a private network (which could be a VPC). You can use a VPN to securely connect to your VPC from any location with an internet connection. ## What Are VPC Servers Used for? While “VPC server” isn’t a standalone concept, understanding the distinct use cases for Virtual Private Servers (VPSes) and Virtual Private Clouds (VPCs) is crucial when choosing the right hosting solution from [Atlantic.Net](https://www.atlantic.net/vps-hosting/). **Atlantic.Net VPS Use Cases:** - **Web Hosting:** Launch and manage websites and [web applications](https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/) with dedicated resources and root access. - **Application Hosting:** Run resource-intensive software applications requiring isolated environments. - **Development and Testing Environments:** Create customizable [sandboxes](https://cloud.atlantic.net/?page=userlogin) for software development and testing processes. **Atlantic.Net VPC Use Cases:** - **Enterprise Applications:** Host [mission-critical business applications](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/) demanding high security, compliance, and customization. - **Complex Environments:** Manage intricate [multi-tier applications](https://www.atlantic.net/virtual-private-cloud/) or multiple virtual servers within a secure, isolated network. - **Hybrid Cloud Environments:** Seamlessly connect on-premises infrastructure to Atlantic.Net’s cloud resources for enhanced scalability and flexibility. ### **Choosing the Right Atlantic.Net Solution for Your Needs** The decision between a VPS and a VPC from Atlantic.Net depends on your specific requirements: - **Atlantic.Net VPS:** Ideal if you need a single, cost-effective virtual server with full control (root access) and dedicated resources. - **Atlantic.Net VPC:** The optimal choice for complex projects, multiple virtual servers, enhanced security, compliance requirements [(like HIPAA)](https://www.atlantic.net/hipaa-compliant-hosting/), and complete customization of your virtual network environment. If you’re still unsure, Atlantic.Net’s team of experts can help you assess your needs and recommend the best solution for your specific use case. Don’t hesitate to [contact us for personalized guidance](https://www.atlantic.net/about-us/corporate-contact/). --- # Atlantic.Net Offers Free 4GB Cloud Server Tier for One Year [Offer has ended] > URL: https://www.atlantic.net/press-releases/atlantic-net-offers-free-4gb-cloud-server-tier-for-one-year/ | Published: 2024-06-26 | Updated: 2026-03-28 | Author: Editorial Team *The 4GB Cloud Servers will be free for one year, doubling resources for new customers across all data center regions.* **ORLANDO, Fla.** **– June 26, 2024 –**[Atlantic.Net](https://www.atlantic.net/), a leading cloud hosting solutions provider,  announced a major upgrade to its Free Tier. New customers can now take advantage of a powerful free 4GB server, a 50% increase in resources, at no additional cost. This enhanced plan is available across Atlantic.Net’s eight global data centers, providing businesses worldwide with the performance and reliability they need to thrive. All new customers receive a free cloud server for a year, which includes: - 4GB RAM - 2 vCPU  - 80 GB SSD storage - 5TB monthly data transfer In addition to the free  G3.4GB server, the Free Tier also includes 50 GB of Free Block Storage and Snapshots for one full year and comes with all the benefits of the Atlantic.Net Cloud Platform: - **Fault-tolerant, ultra-fast performance:** Engineered for maximum uptime and speed. - **Award-winning Cloud Servers:** Backed by a proven track record of excellence. - **Secure Block Storage:** Safeguard your critical data with robust security measures. - **One-Click Applications, DNS, Private Networking, RESTful API:** Streamline your workflow and development processes. - **Optional Data Backup & Managed Services:** Tailor your solution to your needs. - **24/7 U.S.-Based Expert Support:** Get the help you need whenever needed. “Atlantic.Net is celebrating 30 years of success, and providing a free tier with additional resources makes it easy for developers and startups to start their project with no up-front capital,” said Marty Puranik, CEO and Founder of Atlantic.Net. “The new free promotion is a significant step towards helping developers and small and mid-sized businesses get more for less, continuing our journey to bring tomorrow’s computing today,” said Puranik. Most recently, the company announced the one-click deployment of its HIPAA-Compliant Hosting. This web hosting solution meets and exceeds the required administrative, physical, and technical safeguards mandated by the Health Insurance Portability and Accountability Act of 1996. Atlantic.Net specializes in an array of hosting services, including on-demand and turnkey cloud, dedicated hosts, dedicated servers, colocation, private virtualization, and managed hosting. This offering builds on Atlantic.Net’s previous initiatives, such as expanding the G3.2GB server promotion to all eight global data center regions, including New York, Toronto, San Francisco, Dallas, London, Orlando, Ashburn, and Singapore. For more information, please visit [Atlantic.Net](https://www.atlantic.net/).   **About Atlantic.Net** Atlantic.Net is an award-winning global cloud services provider with a focus on security, compliance, and simplifying complex infrastructures. With over 30 years of experience, Atlantic.Net is dedicated to offering developers and IT leaders at small, medium, and large organizations a range of on-demand, customized, and cost-effective cloud solutions that cater to their unique business needs. Having served clients like Lenovo, Newegg, NASA, and Hilton, the company’s commitment to excellence has positioned it as a leader in the industry, recognized for its innovation and customer-centric approach.  ### **Media Contact** 5WPR for Atlantic.net [**atlantic@5wpr.com**](mailto:Atlantic@5wpr.com) --- # Atlantic.Net Offers Free 4GB Cloud Server Tier for One Year [Offer has ended] > URL: https://www.atlantic.net/announcements/atlantic-net-offers-free-4gb-cloud-server-tier-for-one-year/ | Published: 2024-06-26 | Updated: 2026-04-01 | Author: Alexander Wise As we celebrate 30 years of success, we are pleased to announce a major upgrade to our Free Tier. New customers can now take advantage of a powerful free 4GB server, a 50% increase in resources, at no additional cost. This enhanced plan is available across Atlantic.Net’s eight global data centers, providing businesses worldwide with the performance and reliability they need to thrive. ![](https://www.atlantic.net/wp-content/uploads/2024/06/Double-the-Performance-06.jpg) All new customers receive a free cloud server for a year, which includes: - 4GB RAM - 2 vCPU - 80 GB SSD storage - 5TB monthly data transfer In addition to the free  G3.4GB [Cloud VPS](https://www.atlantic.net/vps-hosting/) server, the Free Tier also includes 50 GB of Free Block Storage and Snapshots for one full year and comes with all the benefits of the Atlantic.Net Cloud Platform: - **Fault-tolerant, ultra-fast performance:** Engineered for maximum uptime and speed. - **Award-winning Cloud Servers:** Backed by a proven track record of excellence. - **Secure Block Storage:** Safeguard your critical data with robust security measures. - **One-Click Applications, DNS, Private Networking, RESTful API:** Streamline your workflow and development processes. - **Optional Data Backup & Managed Services:** Tailor your solution to your needs. - **24/7 U.S.-Based Expert Support:** Get the help you need whenever needed. With this promotion, developers, startups, and small-to-mid-sized businesses will get more for less, making it easy to start projects with no up-front capital. This offering builds on Atlantic.Net’s previous initiatives, such as expanding the G3.2GB server promotion to all eight global data center regions, including New York, Toronto, San Francisco, Dallas, London, Orlando, Ashburn, and Singapore. --- # HIPAA Compliant Remote Desktop: How to Set Up a HIPAA-Compliant RDP Server > URL: https://www.atlantic.net/hipaa-compliant-hosting/are-rdp-servers-hipaa-compliant/ | Published: 2024-06-27 | Updated: 2024-06-30 | Author: Sam Guiliano ## Can Remote Desktop Protocol (RDP) Be Made HIPAA-Compliant? Remote desktop protocol (RDP) can be made HIPAA compliant (HIPAA Compliant RDP Server Hosting) with the help of a HIPAA-compliant hosting company. Healthcare security and HIPAA compliance are points of focus for us at Atlantic.Net. Here is a sample chat with a prospective client interested in setting up nationwide access to a compliant system via remote desktop protocol (RDP). ## What is Remote Desktop Protocol (RDP)? [Remote Desktop Protocol (RDP)](https://www.atlantic.net/vps-hosting/how-to-remote-desktop-windows-server/) is a proprietary protocol developed by Microsoft which provides a user with a graphical interface to connect to another computer over a network connection. The user employs RDP client software to remotely access the other computer, while the other computer must run RDP server software for the user to access it remotely. Here is a sample use-case with a prospective client interested in setting up nationwide access to a HIPAA compliant remote desktop protocol (RDP). ### **Healthcare Hosting Scenario Client Needs a System for Nationwide Remote Desktop** **Healthcare Client:** I have an application I’d like to have hosted with a [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) Server. My users will access the program from various locations throughout the U.S. via Remote Desktop. **Hosting Consultant:** Thank you for contacting Atlantic.Net. A few questions: - - How many internal users do you have? (Each internal user will need an “Encrypted” VPN to connect to the platform.) - What is your total storage requirement? - Are you “encrypting” the data before storing it on the HIPAA hosting platform? - Is there a high amount of Read/Writes daily on the database side? - Do you require any database software (we can only provide MySQL and MSSQL)? - Do you have both a Web and Database front end? Attached are the BAA and the HIPAA certification. **Healthcare Client:** - - A “group” is considered from 2-100 individuals working for the same medical practice. They can be at several different physical locations, sharing the same databases. There will be a few groups to start, with a steady increase. - 30 MB per group. - A typical user will log in first thing in the morning and access the program 10-30 times a day. Very low bandwidth per group. - Users will access the server/application via Remote Desktop. I am assuming the application and the databases will be separated. **Hosting Consultant:** OK, thank you for your responses. Attached is the formal HIPAA-compliant pricing proposal. The smallest amount of Storage Space we can provide is 500 GB. The most cost-effective way to give Application and Database servers (to meet HIPAA requirements) is by using a dedicated server and creating two Virtual Machines inside the server. The dedicated server comes with ( 2 ) RDP licenses; they are $ XXX per month per RDP license if you need extra ones. We include ( 5 ) Encrypted VPNs with our proposal; if you need additional VPNs, they are $ XXX per month per VPN. We require all of the services listed on the proposal to provide you with the **business associate agreement**. Below is a list of the supporting documents we provide for your review. - - Fully Managed Hardware Firewall - Encrypted VPNs - Intrusion Detection System - Fully Managed Daily Backup **Healthcare Client:** Thanks for your quick reply. Please let me digest this information – I’m sure I’ll have some questions for you afterward. **Hosting Consultant:** Are you still looking for [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) services? **Healthcare Client:** I am still considering this. The project timing is not 100% defined. Do you have a few references who are current users that I can contact? Thank you. **Hosting Consultant:** We have many [HIPAA hosting](https://www.atlantic.net/hipaa-compliant-hosting/) customers, but all customers have NDAs. We have some customers who have provided us with permission to use them as a reference, and you can contact these customers anytime. Please see the attached list. ### **The Perspective of Complete Healthcare Solutions** One of our most vocal supporters is Complete Healthcare Solutions. “Atlantic.Net’s reputation for 100% up-time, their secure infrastructure, and expertise in Healthcare IT were key components in finalizing our partnership,” said the firm’s VP of product development, Joseph Nompleggi. ## Security Increasingly Critical in Healthcare To understand data breaches, follow the money. Hackers can now sell your healthcare records for ten times what they can get for your credit card. As medical records increase in value, more hackers set their sights on medical companies; their efforts are often successful since many firms use outdated equipment and don’t invest substantially in security. “As attackers discover new methods to make money, the healthcare industry is becoming a much riper target because of the ability to sell large batches of personal data for profit,” explained TrustedSEC CEO Dave Kennedy, adding that the information is typically used to conduct medical fraud. Hackers have disproportionately targeted healthcare companies for years, but their efforts are accelerating. In 2009, 20% of HIPAA “covered entities” reported an attack in a survey by the Ponemon Institute. By 2013, 40% of companies said they had experienced a breach. Larry Ponemon, the institute’s founder, commented that 2014 was even more devastating for healthcare security: there were more successful assaults and more data exfiltrated per assault. Intermountain Healthcare CIO Mark Probst noted that his hospital chain defends against thousands of cyberattacks every week. Furthermore, Ponemon revealed that [9 out of every ten healthcare firms had patient records compromised or stolen in 2012 or 2013](http://money.cnn.com/2014/08/20/technology/security/hospitals-data/). Currently, healthcare experiences more attacks than both finance and military organizations combined. Here are some essential resources that could assist you with setting up your RDP server, but to ensure [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/), you need to add a comprehensive security apparatus around your RDP servers. [How to Configure Windows RDP Server](https://www.atlantic.net/vps-hosting/how-to-configure-rdp-windows-server-2008-r2/) [Remote Desktop Scenario using a Cloud VPS](https://www.atlantic.net/vps-hosting/how-to-remote-desktop-windows-server/) [How to Remote Desktop into Your Windows Server](https://www.atlantic.net/vps-hosting/how-to-remote-desktop-windows-server/)   **** Note that various details are changed for privacy, clarity, etc. **** ![HIPAA RDP Server Requirements](https://www.atlantic.net/wp-content/themes/anet/img/hipaa/hipaa_hosting_infographic.png) Check out our full range of **[VPS Hosting](https://www.atlantic.net/vps-hosting/)**Solutions today.   --- # How to Monitor Ubuntu Server Security with Osquery > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-monitor-ubuntu-server-security-with-osquery/ | Published: 2024-06-28 | Updated: 2024-08-17 | Author: Hitesh Jethva Osquery is an open-source, cross-platform tool that allows you to query your operating system as if it were a relational database. Using SQL-based queries, Osquery provides insights into your system’s configuration, status, and activities, making it an invaluable tool for system monitoring, security auditing, and incident response. In this tutorial, we’ll cover how to install, configure, and use Osquery to monitor the security of an Ubuntu 22.04 server. ## Step 1 – Update the System Keeping your system updated is crucial for security. Regular updates provide the latest security patches and software enhancements. Ensure your system is up to date: ``` apt update -y apt upgrade -y ``` ## Step 2 – Install Osquery Osquery is not available in the default Ubuntu repositories, so you need to add its repository. Download and add the repository GPG key: ``` export OSQUERY_KEY=1484120AC4E9F8A1A577AEEE97A80C63C9D8B80B apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv-keys $OSQUERY_KEY ``` This command ensures the authenticity of the packages from the Osquery repository. GPG keys help verify that the software you’re installing is legitimate and hasn’t been tampered with. ``` add-apt-repository 'deb [arch=amd64] https://pkg.osquery.io/deb deb main' ``` This command adds the Osquery repository to your system. Adding the repository ensures you get the latest version of Osquery directly from the source. Now, install Osquery using the apt command: ``` apt install osquery -y ``` ## Step 3 – Configure Osquery Creating a configuration file is the first step in customizing Osquery’s behavior. Let’s create a new configuration file: ``` mkdir -p /etc/osquery nano /etc/osquery/osquery.conf ``` Add the following content: ``` { "options": { "config_plugin": "filesystem", "logger_plugin": "filesystem", "logger_path": "/var/log/osquery", "disable_logging": "false", "log_result_events": "true", "schedule_splay_percent": "10", "worker_threads": "2", "enable_monitor": "true" }, "schedule": { "system_info": { "query": "SELECT hostname, cpu_brand, physical_memory FROM system_info;", "interval": 3600 }, "processes": { "query": "SELECT * FROM processes WHERE on_disk = 0;", "interval": 300 } }, "packs": { "osquery-monitoring": "/usr/share/osquery/packs/osquery-monitoring.conf" } } ``` This configuration sets Osquery to log its results and run scheduled queries. The options section configures logging and performance, while the schedule section defines periodic queries. Create log directory and set permissions: ``` mkdir -p /var/log/osquery chown -R syslog:adm /var/log/osquery ``` ## Step 4 – Start and Enable Osquery Enable and start the Osquery daemon: ``` systemctl enable osqueryd systemctl start osqueryd ``` Check the service status: ``` systemctl status osqueryd ``` The status command provides information about the service’s current state. ``` ● osqueryd.service - The osquery Daemon Loaded: loaded (/lib/systemd/system/osqueryd.service; disabled; vendor preset: enabled) Active: active (running) since Fri 2024-06-21 03:33:42 UTC; 4s ago Process: 4492 ExecStartPre=/bin/sh -c if [ ! -f $FLAG_FILE ]; then touch $FLAG_FILE; fi (code=exited, status=0/SUCCESS) Process: 4494 ExecStartPre=/bin/sh -c if [ -f $LOCAL_PIDFILE ]; then mv $LOCAL_PIDFILE $PIDFILE; fi (code=exited, status=0/SUCCESS) Main PID: 4495 (osqueryd) Tasks: 14 (limit: 4579) Memory: 14.0M CPU: 110ms CGroup: /system.slice/osqueryd.service ├─4495 /opt/osquery/bin/osqueryd --flagfile /etc/osquery/osquery.flags --config_path /etc/osquery/osquery.conf └─4497 /opt/osquery/bin/osqueryd "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "> ``` ## Step 5 – Querying with Osquery You can use Osquery’s interactive shell to run queries and explore your system. Let’s launch the Osquery interactive shell: ``` osqueryi ``` The interactive shell allows you to run ad-hoc queries and inspect your system in real-time. It’s a powerful tool for on-the-fly analysis. ``` osquery> ``` Run a query to list all users: ``` SELECT username, description FROM users; ``` This query lists all users on the system. It’s useful for auditing user accounts and their descriptions. ``` +------------------+------------------------------------+ | username | description | +------------------+------------------------------------+ | root | root | | daemon | daemon | | bin | bin | | sys | sys | | sync | sync | | games | games | | man | man | | lp | lp | | mail | mail | | news | news | | uucp | uucp | | proxy | proxy | | www-data | www-data | | backup | backup | | list | Mailing List Manager | | irc | ircd | | gnats | Gnats Bug-Reporting System (admin) | | nobody | nobody | | _apt | | | systemd-network | systemd Network Management,,, | | systemd-resolve | systemd Resolver,,, | | messagebus | | | systemd-timesync | systemd Time Synchronization,,, | | pollinate | | | sshd | | | syslog | | | uuidd | | | tcpdump | | | tss | TPM software stack,,, | | landscape | | | usbmux | usbmux daemon,,, | | lxd | | | ntp | | +------------------+------------------------------------+ ``` Run a query to check for listening ports: ``` SELECT * FROM listening_ports; ``` This query shows all open network ports. ``` +------+------+----------+--------+-------------------------+-----+--------+--------------------------------------------+---------------+ | pid | port | protocol | family | address | fd | socket | path | net_namespace | +------+------+----------+--------+-------------------------+-----+--------+--------------------------------------------+---------------+ | 584 | 53 | 6 | 2 | 127.0.0.53 | 14 | 19806 | | 4026531992 | | 1101 | 22 | 6 | 2 | 0.0.0.0 | 3 | 22415 | | 4026531992 | | 1101 | 22 | 6 | 10 | :: | 4 | 22417 | | 4026531992 | | 584 | 53 | 17 | 2 | 127.0.0.53 | 13 | 19805 | | 4026531992 | | 745 | 123 | 17 | 2 | 209.23.8.109 | 19 | 20237 | | 4026531992 | | 745 | 123 | 17 | 2 | 127.0.0.1 | 18 | 20235 | | 4026531992 | | 745 | 123 | 17 | 2 | 0.0.0.0 | 17 | 20231 | | 4026531992 | ``` Exit the Osquery shell: ``` .exit ``` ## Step 6 – Automating Security Monitoring To automate and extend your security monitoring, consider using additional query packs and integrating Osquery with centralized logging and alerting systems like ELK Stack or Splunk. Download and install additional query packs: ``` wget -P /usr/share/osquery/packs/ https://raw.githubusercontent.com/osquery/osquery/master/packs/osquery-monitoring.conf ``` Query packs contain predefined queries for specific monitoring tasks. They simplify setting up comprehensive security checks. Update the packs section in **/etc/osquery/osquery.conf** to include the new packs: ``` "packs": { "osquery-monitoring": "/usr/share/osquery/packs/osquery-monitoring.conf", "incident-response": "/usr/share/osquery/packs/incident-response.conf" } ``` ## Conclusion You now have Osquery installed and configured on your Ubuntu 22.04 server. By using Osquery, you can monitor various aspects of your system in real-time, aiding in security and compliance efforts. Customize your queries and schedules to fit your specific needs, and integrate Osquery with other tools for enhanced monitoring and alerting. You can now use Osquery for security auditing on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install and Use bmon Real Time Bandwidth Monitor in Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-and-use-bmon-real-time-bandwidth-monitor-in-ubuntu-22-04/ | Published: 2024-06-29 | Updated: 2024-07-28 | Author: Hitesh Jethva Monitoring network bandwidth is crucial for maintaining a well-functioning and efficient system. Whether you’re a system administrator overseeing multiple servers or an individual managing your home network, understanding the network usage can help you identify bottlenecks, optimize performance, and detect potential issues early. bmon (Bandwidth Monitor) is a powerful, real-time bandwidth monitoring tool designed for Unix-like operating systems, including Ubuntu. It provides detailed information about your network bandwidth usage, presenting data in a user-friendly, graphical interface. This tutorial will guide you through the installation and usage of bmon on Ubuntu 22.04. ## Step 1 – Installing bmon First, you need to install bmon. It is available in the default Ubuntu repositories, so you can install it using the apt package manager. Update the package list: ``` apt update -y ``` After updating the apt cache, install bmon using the following command: ``` apt install bmon -y ``` ## Step 2 – How to Use bmon Once installed, you can start using bmon to monitor your network bandwidth in real time. ``` bmon ``` By default, bmon will start displaying the bandwidth usage of all available network interfaces. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p1-7.png) When you run bmon, you will see several sections and columns on the screen. Here’s a breakdown of what each part represents: - **Interfaces Section:** This section lists all detected network interfaces along with their current bandwidth usage statistics. - **Statistics Section:** Displays detailed statistics for the selected interface, such as: - **RX:** Received bytes/packets. - **TX:** Transmitted bytes/packets. - **Errors:** Number of errors. - **Dropped:** Number of dropped packets. - **Overruns:** Number of overruns. - **Frame:** Frame errors. - Rate Graph: A graphical representation of the bandwidth usage over time for the selected interface. ## Step 3 – Command-Line Options and Key Bindings bmon supports several command-line options to customize its behavior. Some of the most useful options include: Use the **-p** flag to specify which network interfaces to monitor. For example: ``` bmon -p eth0 ``` ![](https://www.atlantic.net/wp-content/uploads/2024/06/p2-6.png) Use the **-o** flag to set the output module. bmon supports several output modules, such as ASCII and curses. By default, curses is used. For example: ``` bmon -p eth0 -o ascii ``` Output: ``` Interfaces RX bps pps % TX bps pps % eth0 0 0 0 0 Interfaces RX bps pps % TX bps pps % eth0 885B 0 293B 0 Interfaces RX bps pps % TX bps pps % eth0 2.15KiB 0 293B 0 Interfaces RX bps pps % TX bps pps % eth0 2.77KiB 0 334B 1 Interfaces RX bps pps % TX bps pps % eth0 2.82KiB 0 303B 1 ``` Use the **-r** option to set the read interval in seconds. This determines how frequently bmon will update the statistics. For example, to update every 2 seconds: ``` bmon -p eth0 -r 2 ``` ![](https://www.atlantic.net/wp-content/uploads/2024/06/p3-3.png) You can use the **-s** option to set the storage module, which determines where the data is read from. For example: ``` bmon -p eth0 -s netlink ``` ![](https://www.atlantic.net/wp-content/uploads/2024/06/p4-3.png) ### Key Bindings While running bmon, you can use the following keys to navigate and customize the display: - **Left/Right Arrow Keys**: Switch between different network interfaces. - **Up/Down Arrow Keys:** Scroll through the statistics of the selected interface. - **Tab:** Switch between different sections (interfaces, statistics, graph). - **g**: Toggle the graph display. - **d**: Toggle detailed interface statistics. - **q**: Quit bmon. ## Conclusion bmon is a powerful tool for monitoring network bandwidth usage in real time on Ubuntu 22.04. By understanding its command-line options and interface, you can effectively track and debug network performance issues. Try to install bmon on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Miniconda on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-miniconda-on-ubuntu-24-04/ | Published: 2024-06-30 | Updated: 2025-05-12 | Author: Hitesh Jethva Miniconda is a minimal, lightweight version of Anaconda that includes only the essential packages and the Conda package manager. This makes it an excellent choice for those who want a lean Python environment without the extra bulk of a full Anaconda installation. Miniconda allows you to create isolated environments with specific Python versions and packages, making it easier to manage dependencies and avoid conflicts. This guide will walk you through the steps to install Miniconda on Ubuntu 24.04. ## Step 1 – Update the System Before installing any new software, it’s good practice to update the package list and upgrade the installed packages to their latest versions. Open a terminal and run the following commands: ``` apt update -y apt upgrade -y ``` ## Step 2 – Download the Miniconda Installer Next, download the Miniconda installer script. You can find the latest version of Miniconda on the official Miniconda website. Use wget to download the installer: ``` wget https://repo.anaconda.com/miniconda/Miniconda3-latest-Linux-x86_64.sh ``` ## Step 3 – Run the Installer Once you have verified the integrity of the installer, you can run the installer script: ``` bash Miniconda3-latest-Linux-x86_64.sh ``` The installer will guide you through the installation process. ``` Do you accept the license terms? [yes|no] >>> yes Miniconda3 will now be installed into this location: /root/miniconda3 - Press ENTER to confirm the location - Press CTRL-C to abort the installation - Or specify a different location below [/root/miniconda3] >>> You can undo this by running `conda init --reverse $SHELL`? [yes|no] [no] >>> You have chosen to not have conda modify your shell scripts at all. To activate conda's base environment in your current shell session: eval "$(/root/miniconda3/bin/conda shell.YOUR_SHELL_NAME hook)" To install conda's shell functions for easier access, first activate, then: conda init Thank you for installing Miniconda3! ``` ## Step 4 – Initialize Conda After completing the installation, you need to initialize Conda. This sets up the necessary shell configuration. Run the following commands: ``` source ~/miniconda3/bin/activate conda init ``` - **source ~/miniconda3/bin/activate**: Activates the Conda environment. - **conda init**: Configures your shell to use Conda. ## Step 5 – Test the Installation Close and reopen your terminal, or source your shell configuration file to apply the changes: ``` source ~/.bashrc ``` To verify the installation, run: ``` conda --version ``` This command should display the installed Conda version, confirming that the installation was successful. ``` conda 25.3.1 ``` You can also check the Conda configuration details with: ``` conda info ``` Output: ``` active environment : base active env location : /root/miniconda3 shell level : 1 user config file : /root/.condarc populated config files : /root/miniconda3/.condarc conda version : 25.3.1 conda-build version : not installed python version : 3.13.2.final.0 solver : libmamba (default) virtual packages : __archspec=1=x86_64 __conda=25.3.1=0 __glibc=2.39=0 __linux=6.8.0=0 __unix=0=0 base environment : /root/miniconda3 (writable) conda av data dir : /root/miniconda3/etc/conda conda av metadata url : None channel URLs : https://repo.anaconda.com/pkgs/main/linux-64 https://repo.anaconda.com/pkgs/main/noarch https://repo.anaconda.com/pkgs/r/linux-64 https://repo.anaconda.com/pkgs/r/noarch package cache : /root/miniconda3/pkgs /root/.conda/pkgs envs directories : /root/miniconda3/envs /root/.conda/envs platform : linux-64 user-agent : conda/25.3.1 requests/2.32.3 CPython/3.13.2 Linux/6.8.0-54-generic ubuntu/24.04.2 glibc/2.39 solver/libmamba conda-libmamba-solver/25.4.0 libmambapy/2.0.5 aau/0.7.0 c/. s/. e/. UID:GID : 0:0 netrc file : None offline mode : False ``` ## Step 7 – Update Conda To ensure you have the latest packages and features, update Conda: ``` conda update --all ``` ## Step 8 – Install Packages with Conda With Conda installed, you can now install packages easily via conda command. For example, to install pandas, use: ``` conda install pandas ``` You can list all installed packages in your Conda environment with: ``` conda list ``` When you’re done, you can deactivate the Conda environment with: ``` conda deactivate ``` ## Conclusion You have successfully installed Miniconda on Ubuntu 24.04. You can now use Conda to manage your Python environments and packages. This lightweight setup is perfect for creating isolated environments for your projects without the overhead of the full Anaconda distribution. Feel free to explore Conda’s documentation to learn more about managing environments and packages. You can now use Miniconda to manage your Python project on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Remote Desktop to Server: Windows Hosting Remote Desktop Protocol (RDP) Tutorial > URL: https://www.atlantic.net/vps-hosting/how-to-remote-desktop-windows-server/ | Published: 2024-07-01 | Updated: 2024-07-08 | Author: Atlantic.Net NOC ##### Verified and Tested 07/01/2024 In this how-to, we will walk you through how to use Remote Desktop to access your Windows Server. ## What Is RDP? **Remote Desktop Protocol** (**RDP**) is a proprietary protocol developed by Microsoft, which provides a user with a graphical interface to connect to another computer over a network connection. The user employs RDP client software for this purpose while the other computer must run RDP server software. ### Prerequisites – A Server with Windows Server. If you do not have a server already, you can visit our [VPS hosting](https://www.atlantic.net/vps-hosting/) page and spin one up in under 30 seconds. ## How to Remote Desktop to a Server All Windows computers come pre-installed with Remote Desktop Connection. You can find this by going to Start and typing “Remote Desktop Connection” or “mstsc.” Once you see Remote Desktop Connection, click on it to open. ![Enter your hosts name or IP into Remote desktop Connection](https://www.atlantic.net/wp-content/uploads/2018/01/remote1.png)Remote desktop Connection When you have opened Remote Desktop Connection, you must enter the computer name or IP address of the computer/server. Once you have entered either one, then click **Connect**. Once you have clicked on Connect, you will be prompted if you trust this connection. If you do and do not want to see this message again, check the box beside “Don’t ask me again for connections to this computer.”  Also, if you would like to connect your local drives, printers, or clipboard, click on the Show Details at the bottom left. ![If you would like to connect your local drives, printers or clipboard, then click on the Show Details at the bottom left.](https://www.atlantic.net/wp-content/uploads/2018/01/remote2.png)Details   After clicking on **Show Details**, you will be able to check the boxes of which ones you would like connected as well. ![If you would like to connect your local drives, printers or clipboard, then click on the Show Details at the bottom left.](https://www.atlantic.net/wp-content/uploads/2018/01/remote3.png)Details After you are done choosing which options you would like, click on **Connect**. You will then be prompted for the Username and password to log in to your remote computer/server. ![Enter your remote hosts username and password.](https://www.atlantic.net/wp-content/uploads/2018/01/remote4.png)Windows security Once you have entered the Username and Password, you can check the box next to “Remember my credentials” if you want to. Once you are ready, then click on OK. Now you should be connected to the remote server. ## Remote Desktop Protocol Tips As you can see, RDP as a basic tool is straightforward. To connect to your server remotely using Remote Desktop Connection on a Windows computer, type “remote” into the search box of your start menu. Once the program is opened, type in the machine you want to access and hit “Connect.” That is all. However, entering the Options menu – accessible through the main window – allows you to control additional features. Ryan Dube of MakeUseOf assessed a few of those options so that you can understand the fuller potential of the [Windows software](http://www.makeuseof.com/tag/how-to-use-remote-desktop-connections-like-an-it-pro/). *Changing the display* Frequently RDP defaults to a window that does not take up the entire screen. Especially on big monitors, this aspect can be annoying. You want a full visual of the environment, and all you get is a window that fills 50% of your screen, if that. It’s challenging to work with that small viewing space to have several windows open simultaneously. How to solve the size problem? Before connecting through RDP, access the Display menu (within Options) and slide the setting to the right-hand side. Once you have done that, you should see the words “Full Screen” appear within the window. Additionally, if you have multiple monitors connected, you now have the option to utilize all of them for the remote session. *Using local resources* Another potential element of frustration when using a Remote Desktop connection is that some Windows shortcuts don’t work. For example, control-alt-delete (to end processes, log off, etc.) and alt-tab (to switch between windows) are nonfunctional. However, this issue can be resolved as well. Enter the Local Resources menu. Under the Keyboard heading, you will see the option to use Windows key combinations when the display is set in particular ways. *Accessing additional devices* You also have the ability to use thumb drives or other media while connected remotely. Within Local Resources, you will see a Local Devices heading. Click “More.” Now you will see various options for media that can be accessed during RDP. ## Finding a Helpful Windows RDP Hosting Provider The remote desktop protocol is just one of the many tools and features useful to you within a cloud environment. Your Windows Cloud Server Hosting solutions, like any cloud computing situation, will rely in part on the quality of your Cloud Servers. If you ever have any questions at any time related to your cloud hosting or other hosting-related tools, such as our [VPS hosting](https://www.atlantic.net/vps-hosting/) solutions, Atlantic.Net’s consultants are here to assist you 24/7. --- # How to Check Docker Container RAM and CPU Usage > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-check-docker-container-ram-and-cpu-usage/ | Published: 2024-07-02 | Updated: 2024-07-28 | Author: Hitesh Jethva Docker containers are a lightweight, portable, and self-sufficient unit of software that includes everything needed to run an application. Monitoring the resource usage of Docker containers, particularly RAM and CPU, is essential for maintaining performance, identifying bottlenecks, and ensuring that applications run smoothly. In this tutorial, we will cover various methods to check the RAM and CPU usage of Docker containers. We’ll use both Docker’s built-in tools and external monitoring tools. ## Prerequisites - Docker must be installed and running. ## 1. Using the docker stats Command The **docker stats** command provides a live stream of real-time resource usage statistics for your Docker containers. It helps you monitor the performance and resource consumption of your containers, giving you insights into how much CPU, memory, network, and block I/O each container is using. ``` docker stats ``` ![](https://www.atlantic.net/wp-content/uploads/2024/06/p1-6.png) This command outputs a table with the following columns: - **CONTAINER ID:** The unique identifier of the container. - **NAME:** The name of the container. - **CPU** **%:** The percentage of the host’s CPU the container is using. - **MEM USAGE / LIMIT**: The memory usage of the container and the memory limit set for the container. - **MEM** **%**: The percentage of the container’s memory usage relative to its limit. - **NET I/O:** The amount of network traffic (in/out). - **BLOCK I/O:** The amount of block I/O (read/write). Additional Options for docker stats - **–all, -a**: Show all containers (default shows just running) - **–format**: Pretty-print images using a Go template - **–no-stream:** Disable streaming stats and only pull the first result - **–no-trunc:** Do not truncate output Example using options: ``` docker stats --no-stream --format "table {{.Container}}\t{{.Name}}\t{{.CPUPerc}}\t{{.MemUsage}}" ``` This example displays a one-time snapshot of the stats in a table format, showing container ID, name, CPU percentage, and memory usage. ``` CONTAINER NAME CPU % MEM USAGE / LIMIT b9bcf1921e95 xenodochial_jang 0.00% 856KiB / 3.834GiB 9c13fdf2fef9 dreamy_borg 0.00% 3.078MiB / 3.834GiB ``` ## 2. Using the docker inspect Command The **docker inspect** command retrieves detailed information about a container. To get the memory and CPU usage, you can inspect a running container and parse the JSON output. ``` docker inspect ``` You can filter the output using jq or similar tools to get specific information. For example, to get memory usage: ``` docker inspect --format='{{.State.Pid}}' | xargs -I {} cat /proc/{}/status | grep VmRSS ``` Output: ``` VmRSS: 3840 kB ``` ## 3. Using cAdvisor cAdvisor (Container Advisor) is an open-source project from Google that provides container users with an understanding of the resource usage and performance characteristics of their running containers. It collects, aggregates, processes, and exports information about running containers. Run cAdvisor as a Docker container to start monitoring your other containers. ``` docker run --volume=/:/rootfs:ro --volume=/var/run:/var/run:ro --volume=/sys:/sys:ro --volume=/var/lib/docker/:/var/lib/docker:ro --publish=8080:8080 --detach=true --name=cadvisor gcr.io/cadvisor/cadvisor:latest ``` Navigate to **http://your-server-ip:8080** in your web browser. You will see a dashboard displaying detailed metrics for all running containers, including CPU and memory usage. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p2-5.png) ![](https://www.atlantic.net/wp-content/uploads/2024/06/p3-2.png) ## 4. Using Pseudofiles Linux provides pseudofiles in the /proc and /sys/fs/cgroup directories, which contain information about system and process metrics. These can be used to monitor Docker container resource usage. To check memory usage, you can use the cgroup pseudofiles. First, find the container’s cgroup path: ``` docker inspect --format '{{.Id}}' ``` Output: ``` cadvisor 54310651ae8a769a782fea91c322c47a5dea14df6f359d6aa8f5a161121e0915 xenodochial_jang b9bcf1921e958824d15e686ab400d0d0834b6d0c321fcb75c897f2329616eb7a dreamy_borg 9c13fdf2fef92a9fba52cb09a3fa5f313ebaa566692f8de702497aaf456b70e0 ``` Use the container ID to navigate to its memory usage file: ``` cat /sys/fs/cgroup/system.slice/docker-9c13fdf2fef92a9fba52cb09a3fa5f313ebaa566692f8de702497aaf456b70e0.scope/memory.stat ``` Output: ``` anon 2506752 file 73728 kernel_stack 49152 pagetables 139264 percpu 72 sock 0 shmem 4096 file_mapped 4096 file_dirty 0 file_writeback 0 swapcached 0 anon_thp 0 file_thp 0 shmem_thp 0 inactive_anon 2498560 active_anon 12288 inactive_file 16384 active_file 53248 unevictable 0 slab_reclaimable 237840 slab_unreclaimable 157672 slab 395512 workingset_refault_anon 0 workingset_refault_file 0 workingset_activate_anon 0 workingset_activate_file 0 workingset_restore_anon 0 workingset_restore_file 0 workingset_nodereclaim 0 pgfault 4042 pgmajfault 0 pgrefill 0 pgscan 0 pgsteal 0 pgactivate 4 pgdeactivate 0 pglazyfree 0 pglazyfreed 0 thp_fault_alloc 0 thp_collapse_alloc 0 ``` CPU usage can be monitored similarly: ``` cat /sys/fs/cgroup/system.slice/docker-9c13fdf2fef92a9fba52cb09a3fa5f313ebaa566692f8de702497aaf456b70e0.scope/cpu.stat ``` This file displays the total CPU time (in nanoseconds) consumed by the container. ``` usage_usec 120676 user_usec 52454 system_usec 68221 nr_periods 0 nr_throttled 0 throttled_usec 0 ``` ## Conclusion Monitoring Docker container resource usage is essential for maintaining application performance and stability. The methods covered in this tutorial offer different levels of detail and flexibility. Use Docker stats and inspect for quick checks, cAdvisor for comprehensive overviews, and pseudofiles for low-level metrics. You can now easily check CPU and Memory usage on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Arkime Moloch Packet Capture Tool on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-arkime-moloch-packet-capture-tool-on-ubuntu-24-04/ | Published: 2024-07-03 | Updated: 2025-05-27 | Author: Hitesh Jethva Arkime (formerly known as Moloch) is an open-source, large-scale, full packet capturing, indexing, and database system. It allows organizations to capture and index network traffic, providing a web-based interface for browsing, searching, and analyzing packet data. Arkime is highly scalable and can handle massive amounts of data, making it suitable for use in large networks or data centers. This tutorial will guide you through the step-by-step process of installing Arkime on an Ubuntu 24.04 server. ## Step 1 – Install Necessary Packages First, we need to install some prerequisite packages. These packages ensure that your system has the necessary tools for downloading, managing, and verifying software from external sources. Open your terminal and run the following command: ``` apt install apt-transport-https ca-certificates curl gnupg2 software-properties-common -y ``` ## Step 2 – Add Elasticsearch GPG Key and Repository Now, let’s add the GPG key for the Elasticsearch package to ensure the packages you download are authentic and haven’t been tampered with. Then, we’ll add the Elasticsearch repository. First, add the GPG key: ``` wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | gpg --dearmor -o /etc/apt/trusted.gpg.d/elastic.gpg ``` Then, add the repository: ``` echo "deb https://artifacts.elastic.co/packages/8.x/apt stable main" |tee /etc/apt/sources.list.d/elastic-8.x.list ``` ## Step 3 – Install Elasticsearch Next, update your package list and install Elasticsearch. Elasticsearch is a powerful search engine based on the Lucene library, designed for horizontal scalability, reliability, and real-time search capabilities. ``` apt update apt install elasticsearch ``` During the installation, a password for the elastic user is generated. Make sure to note this password because you’ll need it later. For example, the output might be: ``` The generated password for the elastic built-in superuser is : jUz*X+1f5gyw4Oz8OR2j ``` To make sure Elasticsearch runs continuously and starts automatically on boot, you need to start the service and enable it. ``` systemctl start elasticsearch systemctl enable elasticsearch ``` Let’s check if Elasticsearch is running correctly. Use curl to verify the installation. The -k flag allows curl to perform insecure SSL connections and transfers. ``` curl https://localhost:9200 -k -u elastic -p ``` You will be prompted to enter the password for the elastic user. After entering the password, you should see a response confirming Elasticsearch is running, similar to this: ``` { "name" : "ubuntu", "cluster_name" : "elasticsearch", "cluster_uuid" : "BviykehYSvig56i9fmShlw", "version" : { "number" : "8.18.1", "build_flavor" : "default", "build_type" : "deb", "build_hash" : "df116ec6455476a07daafc3ded80e2bb1a3385ed", "build_date" : "2025-04-30T10:07:44.026929518Z", "build_snapshot" : false, "lucene_version" : "9.12.1", "minimum_wire_compatibility_version" : "7.17.0", "minimum_index_compatibility_version" : "7.0.0" }, "tagline" : "You Know, for Search" } ``` ## Step 4 – Download and Install Arkime It’s time to download the Arkime package specific to Ubuntu 22.04. Arkime provides tools to index and search captured packet data, integrating with Elasticsearch for data storage and retrieval. First, use the wget command to download the latest Arkime package from its official website. ``` wget https://github.com/arkime/arkime/releases/download/v5.6.4/arkime_5.6.4-1.ubuntu2404_amd64.deb ``` Once the package is downloaded, install it using the following command. ``` apt install ./arkime_5.6.4-1.ubuntu2404_amd64.deb ``` ## Step 5 – Configure Arkime Now, let’s configure Arkime by running the configuration script. This script will help you specify which network interfaces to monitor, the Elasticsearch server details, and other settings. ``` /opt/arkime/bin/Configure ``` You will be asked several questions as shown below: ``` Found interfaces: lo;eth0;eth1 Semicolon ';' seperated list of interfaces to monitor [eth1] eth0 Install Elasticsearch server locally for demo, must have at least 3G of memory, NOT recommended for production use (yes or no) [no] OpenSearch/Elasticsearch server URL [https://localhost:9200] OpenSearch/Elasticsearch user [empty is no user] elastic OpenSearch/Elasticsearch password [empty is no password] jUz*X+1f5gyw4Oz8OR2j Password to encrypt S2S and other things, don't use spaces [must create one] password Arkime - Creating configuration files Installing sample /opt/arkime/etc/config.ini sed: can't read : No such file or directory Arkime - Installing /etc/security/limits.d/99-arkime.conf to make core and memlock unlimited Download GEO files? You'll need a MaxMind account https://arkime.com/faq#maxmind (yes or no) [yes] yes ``` Next, initialize the Arkime configuration in Elasticsearch. This step sets up the necessary indices and configurations in Elasticsearch for Arkime to function correctly. ``` /opt/arkime/db/db.pl --esuser elastic:'jUz*X+1f5gyw4Oz8OR2j' https://localhost:9200 init ``` Next, add an admin user for Arkime. This user will have administrative privileges and can manage other users and configurations. ``` /opt/arkime/bin/arkime_add_user.sh admin "Arkime SuperAdmin" password --admin ``` ## Step 6 – Start Arkime Services To start capturing and analyzing network traffic, we need to enable and start the Arkime capture and viewer services. These services must be running for Arkime to function. ``` systemctl enable --now arkimecapture systemctl enable --now arkimeviewer ``` Verify that both services are running: ``` systemctl status arkimecapture arkimeviewer ``` Output: ``` ● arkimecapture.service - Arkime Capture Loaded: loaded (/etc/systemd/system/arkimecapture.service; enabled; preset: enabled) Active: active (running) since Tue 2025-05-27 05:41:26 UTC; 11s ago Main PID: 4540 (sh) Tasks: 7 (limit: 4609) Memory: 320.9M (peak: 321.3M) CPU: 446ms CGroup: /system.slice/arkimecapture.service ├─4540 /bin/sh -c "/opt/arkime/bin/capture -c /opt/arkime/etc/config.ini >> /opt/arkime/logs/capture.log 2>&1" └─4546 /opt/arkime/bin/capture -c /opt/arkime/etc/config.ini May 27 05:41:25 ubuntu systemd[1]: Starting arkimecapture.service - Arkime Capture... May 27 05:41:26 ubuntu systemd[1]: Started arkimecapture.service - Arkime Capture. May 27 05:41:26 ubuntu (sh)[4540]: arkimecapture.service: Referenced but unset environment variable evaluates to an empty string: OPTIONS ● arkimeviewer.service - Arkime Viewer Loaded: loaded (/etc/systemd/system/arkimeviewer.service; enabled; preset: enabled) Active: active (running) since Tue 2025-05-27 05:41:30 UTC; 7s ago Main PID: 4710 (sh) Tasks: 12 (limit: 4609) Memory: 99.5M (peak: 99.9M) CPU: 1.459s CGroup: /system.slice/arkimeviewer.service ├─4710 /bin/sh -c "/opt/arkime/bin/node viewer.js -c /opt/arkime/etc/config.ini >> /opt/arkime/logs/viewer.log 2>&1" └─4711 /opt/arkime/bin/node viewer.js -c /opt/arkime/etc/config.ini May 27 05:41:30 ubuntu systemd[1]: Started arkimeviewer.service - Arkime Viewer. May 27 05:41:30 ubuntu (sh)[4710]: arkimeviewer.service: Referenced but unset environment variable evaluates to an empty string: OPTIONS ``` ## Step 7 – Access Arkime Web Interface You can now access the Arkime web interface by navigating to **http://your-server-ip:8005** in your web browser. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p1-5.png) Use your admin credentials to log in.   ![](https://www.atlantic.net/wp-content/uploads/2024/07/ark.png) It’s always a good idea to check the Arkime logs for any errors. This helps in troubleshooting any issues that might arise during the setup process. ``` tail -f /opt/arkime/logs/viewer.log tail -f /opt/arkime/logs/capture.log ``` ## Conclusion You have successfully installed Arkime on Ubuntu 24.04. You can now start capturing and analyzing network traffic using its powerful web interface. Arkime’s capabilities enable you to monitor, search, and analyze network packets in real time, providing deep insights into your network’s activity. This tool is invaluable for network administrators, security professionals, and anyone needing comprehensive network visibility. Try to install Arkime on dedicated server hosting from Atlantic.Net! --- # How to Install Tensorflow on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-tensorflow-on-ubuntu-22-04/ | Published: 2024-07-04 | Updated: 2024-08-17 | Author: Hitesh Jethva TensorFlow, developed by Google, is a powerful open-source platform for machine learning and artificial intelligence. It’s used by researchers and developers worldwide to build and deploy machine learning models. Whether you’re working on a small hobby project or a large-scale application, TensorFlow provides the tools you need. In this article, we’ll walk you through each step of the installation process of TensorFlow on Ubuntu 22.04. ## Step 1 – Update and Upgrade Your System Before anything else, let’s ensure your system is up to date. Open your terminal and run the following commands: ```bash apt update -y apt upgrade -y ``` Updating your system is crucial as it ensures you have the latest security patches and features, setting a strong foundation for TensorFlow installation. ## Step 2 – Install Python Next, you’ll need Python, which is essential for running TensorFlow. To install Python, enter the command: ```bash apt install python3 -y ``` You can verify the installation by checking the version: ```bash python3 --version ``` You should see an output like Python 3.10.12. Great, Python is installed! ```bash Python 3.10.12 ``` ## Step 3 – Install Pip, Virtual Environment, and Development Tools To manage your Python packages, you’ll need Pip. Also, creating a virtual environment is a good practice to keep your TensorFlow installation isolated. Install Pip, the virtual environment module, and development tools with: ```bash apt install python3-pip python3-venv python3-dev -y ``` ## Step 4 – Set Up Your Project Directory Next, create a directory for your project and navigate to the directory: ```bash mkdir project cd project ``` Now you’re in your project directory. Perfect! ## Step 5 – Create and Activate a Virtual Environment Creating a virtual environment is crucial to avoid conflicts with other Python packages. Create one with the following command: ```bash python3 -m venv venv ``` Activate the virtual environment: ```bash source venv/bin/activate ``` You’ll notice your terminal prompt changes, indicating the virtual environment is active. ## Step 6 – Install TensorFlow With the virtual environment activated, you can now install TensorFlow. Use Pip to install the latest version: ```bash pip3 install --upgrade TensorFlow ``` TensorFlow will be downloaded and installed in your virtual environment. This might take a few minutes, so grab a coffee while you wait! ## Step 7 – Verify the Installation To ensure TensorFlow is installed correctly, you can check the installation details. Run: ```bash python3 -m pip show TensorFlow ``` You should see an output similar to this: ```bash Name: tensorflow Version: 2.16.1 Summary: TensorFlow is an open source machine learning framework for everyone. Home-page: https://www.tensorflow.org/ Author: Google Inc. Author-email: packages@tensorflow.org License: Apache 2.0 Location: /root/project/venv/lib/python3.10/site-packages Requires: absl-py, astunparse, flatbuffers, gast, google-pasta, grpcio, h5py, keras, libclang, ml-dtypes, numpy, opt-einsum, packaging, protobuf, requests, setuptools, six, tensorboard, tensorflow-io-gcs-filesystem, termcolor, typing-extensions, wrapt Required-by: ``` This confirms that TensorFlow is installed and ready to use. Once you’re done, you can deactivate the virtual environment by simply running: ```bash deactivate ``` This will return your terminal to its normal state. ## Conclusion In this article, we’ve walked through the steps to install TensorFlow on Ubuntu 22.04. We started by updating and upgrading the system, then installed Python and Pip. We set up a project directory, created a virtual environment, and installed TensorFlow. Finally, we verified the installation and deactivated the virtual environment. Try to install TensorFlow on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Bitwarden Password Manager on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-bitwarden-password-manager-on-ubuntu-24-04/ | Published: 2024-07-05 | Updated: 2025-05-25 | Author: Hitesh Jethva Bitwarden is a secure, open-source password manager that helps individuals and organizations store, manage, and share their passwords and other sensitive information securely. It provides a centralized and encrypted repository for all your passwords, reducing the risk of security breaches due to weak or reused passwords. In this article, we’ll guide you through the process of installing Bitwarden on an Ubuntu 24.04 server. ## Step 1 – Update and Upgrade Your System First, ensure that your system is up-to-date. Open a terminal and run the following commands: ```bash apt update apt upgrade -y ``` ## Step 2 – Install Docker and Docker Compose Bitwarden can be easily deployed using Docker. Install Docker and Docker Compose by following the below steps: Install required dependencies. ```bash apt install -y ca-certificates curl gnupg ``` Import the Docker GPG key. ```bash install -m 0755 -d /etc/apt/keyrings curl -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /etc/apt/keyrings/docker.gpg chmod a+r /etc/apt/keyrings/docker.gpg ``` Add the Docker CE official repository. ```bash echo "deb [arch="$(dpkg --print-architecture)" signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/ubuntu "$(. /etc/os-release && echo "$VERSION_CODENAME")" stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null ``` Install Docker CE and Docker Compose. ```bash apt install docker-ce docker-compose -y ``` Verify that the Docker service is running properly. ```bash systemctl status docker ``` Output: ```bash ● docker.service - Docker Application Container Engine Loaded: loaded (/usr/lib/systemd/system/docker.service; enabled; preset: enabled) Active: active (running) since Sun 2025-05-25 06:02:40 UTC; 6s ago TriggeredBy: ● docker.socket Docs: https://docs.docker.com Main PID: 17829 (dockerd) Tasks: 9 Memory: 23.4M (peak: 88.8M) CPU: 426ms CGroup: /system.slice/docker.service └─17829 /usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock ``` ## Step 3 – Install Bitwarden Create a user for Bitwarden and add it to the docker and sudo groups. ```bash useradd -G docker,sudo -s /bin/bash -m -d /opt/bitwarden bitwarden ``` Log in as a Bitwarden user and download the Bitwarden installation script. ```bash su - bitwarden curl -Lso bitwarden.sh https://go.btwrdn.co/bw-sh ``` Make the script executable. ```bash chmod +x bitwarden.sh ``` Run the installation script. ```bash ./bitwarden.sh install ``` During the installation process, you’ll be prompted to configure Bitwarden. ```bash _ _ _ _ | |__ (_) |___ ____ _ _ __ __| | ___ _ __ | '_ \| | __\ \ /\ / / _` | '__/ _` |/ _ \ '_ \ | |_) | | |_ \ V V / (_| | | | (_| | __/ | | | |_.__/|_|\__| \_/\_/ \__,_|_| \__,_|\___|_| |_| Open source password management solutions Copyright 2015-2025, 8bit Solutions LLC https://bitwarden.com, https://github.com/bitwarden =================================================== bitwarden.sh version 2024.12.1 Docker version 28.1.1, build 4eba377 Docker Compose version v2.35.1 (!) Enter the domain name for your Bitwarden instance (ex. bitwarden.example.com): bitwarden.linuxbuz.com (!) Do you want to use Let's Encrypt to generate a free SSL certificate? (y/n): y (!) Enter your email address (Let's Encrypt will send you certificate expiration reminders): hitjethva@gmail.com (!) Enter the database name for your Bitwarden instance (ex. vault): bitwarden (!) Enter your installation id (get at https://bitwarden.com/host): 8cafef6e-6cce-433b-9807-b186005fa921 (!) Enter your installation key: UMpxaUNxwoIrC13c1bbf (!) Enter your region (US/EU) [US]: US ``` After entering the required information, the installation script will download and configure Bitwarden. ```bash ./bitwarden.sh start Bitwarden is up and running! =================================================== visit https://bitwarden.linuxbuz.com to update, run `./bitwarden.sh updateself` and then `./bitwarden.sh update` ``` Once the installation is complete, you can start Bitwarden using the following command: ```bash ./bitwarden.sh start ``` ## Step 4 – Access Bitwarden Now that Bitwarden is running, you can access it via your web browser. Open your browser and navigate to **https://bitwarden.linuxbuz.com.** You should see the Bitwarden login page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p1.png) Provide your email, and click on **Create account.** You will be redirected to the Bitwarden account creation page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p2.png) Provide your name, username, email, and master password and click on **Create Account.**You will see the Bitwarden login page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p3.png) Provide your email and click on **Continue.** You will be asked for the master password. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p4.png) Provide your master password and click on **Log in with master password**. You will see the Bitwarden dashboard. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p5.png) ## Conclusion You’ve successfully installed Bitwarden on Ubuntu 24.04! This setup provides you with a secure and efficient way to manage your passwords. Bitwarden offers a variety of features to help you manage your credentials, including secure sharing, password generation, and multi-factor authentication. Keep your Bitwarden instance updated and backed up to ensure your data remains secure. If you encounter any issues or need further customization, refer to the official Bitwarden documentation for more information. You can now use Bitwarden to manage all your passwords on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net. --- # How to Install Ruby on Rails on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-ruby-on-rails-on-ubuntu-22-04/ | Published: 2024-07-06 | Updated: 2024-07-15 | Author: Hitesh Jethva Ruby on Rails, commonly referred to as Rails, is a popular open-source web application framework written in Ruby, a dynamic, object-oriented programming language. Rails follows the Model-View-Controller (MVC) architectural pattern, which separates an application into three main logical components: models for handling data and business logic, views for rendering user interfaces, and controllers for handling user requests and coordinating interactions between the model and view. In this tutorial, we will show you how to install Ruby on Rails on Ubuntu 22.04. ## Step 1 – Install Required Dependencies First, we need to install the necessary dependencies. Open your terminal and run the following command: ```bash apt install -y git curl libssl-dev libreadline-dev zlib1g-dev autoconf bison build-essential libyaml-dev libreadline-dev libncurses5-dev libffi-dev libgdbm-dev ``` ## Step 2 – Install rbenv Rbenv is a lightweight Ruby version management tool that allows you to easily install and switch between different versions of Ruby. Install rbenv by running the following command: ```bash curl -fsSL https://github.com/rbenv/rbenv-installer/raw/HEAD/bin/rbenv-installer | bash ``` Next, add rbenv to your PATH and initialize it by adding the following lines to your ~/.bashrc file: ```bash echo 'export PATH="$HOME/.rbenv/bin:$PATH"' >> ~/.bashrc echo 'eval "$(rbenv init -)"' >> ~/.bashrc source ~/.bashrc ``` ## Step 3 – Install Ruby Now that rbenv is set up, we can install the desired version of Ruby. In this example, we’ll install Ruby version 3.2.0: ```bash rbenv install 3.2.0 ``` Make Ruby available globally. ```bash rbenv global 3.2.0 ``` Verify that Ruby has been successfully installed by running: ```bash ruby -v ``` You should see output similar to: ```bash ruby 3.2.0 (2022-12-25 revision a528908271) [x86_64-linux] ``` ## Step 4 – Install Node.js Rails requires a JavaScript runtime for compiling assets. Install Node.js using the following commands: ```bash curl -fsSL https://deb.nodesource.com/setup_lts.x | sudo -E bash - apt-get install -y nodejs ``` ## Step 5 – Update RubyGems Ensure that RubyGems, the package manager for Ruby, is up to date: ```bash gem update --system ``` Check the version of RubyGems: ```bash gem -v ``` You should see the version number, for example: ```bash 3.5.11 ``` ## Step 6 – Install Rails Finally, let’s install Ruby on Rails using the following command: ```bash gem install rails -v 7.0.4 ``` Verify that Rails has been installed correctly: ```bash rails -v ``` You should see output similar to: ```bash Rails 7.0.4 ``` ## Step 7 – Create a New Rails Application You’re now ready to create your first Rails application. Navigate to the directory where you want to create the application and run: ```bash rails new my_app ``` Replace my_app with the desired name for your application. Navigate into your newly created Rails application directory: ```bash cd my_app ``` Start the Rails server: ```bash rails server --binding=0.0.0.0 ``` You should see the following output indicating that the server is running: ```bash => Booting Puma => Rails 7.1.3.4 application starting in development => Run `bin/rails server --help` for more startup options Puma starting in single mode... * Puma version: 6.4.2 (ruby 3.2.0-p0) ("The Eagle of Durango") * Min threads: 5 * Max threads: 5 * Environment: development * PID: 50188 * Listening on http://0.0.0.0:3000 Use Ctrl-C to stop ``` ## Step 8 – Access Rails Application Now, open your web browser and access your Rails application using the URL **http://your-server-ip:3000.** ![](https://www.atlantic.net/wp-content/uploads/2024/06/p1-1.png) ## Conclusion In this guide, we’ve covered the step-by-step process of installing Ruby on Rails on Ubuntu 22.04. By following these instructions, you should now have a fully functional Rails development environment ready to use. Whether you’re a beginner or an experienced developer, Rails offers a powerful and efficient framework for building modern web applications. Try to install Ruby on Rails on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Uptime Kuma on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-uptime-kuma-on-ubuntu-24-04/ | Published: 2024-07-07 | Updated: 2025-05-19 | Author: Hitesh Jethva Uptime Kuma is a self-hosted, open-source monitoring tool that helps you keep track of the uptime and status of your websites, servers, and applications. It provides real-time status updates, notifications, and detailed reports on the availability and performance of your monitored services. Uptime Kuma is designed to be a modern and flexible alternative to other uptime monitoring solutions. This guide will walk you through the process of installing Uptime Kuma on an Ubuntu 24.04 system. ## Step 1 – Install Nodejs Before starting, you will need to install Nodejs on your server. Follow the steps below to install the latest stable version of Node.js. First, create a directory to store the Nodejs GPG key. ``` mkdir -p /etc/apt/keyrings ``` Download the Nodejs GPG key to the above directory. ``` curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | sudo gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg ``` Add the Nodejs repository to the APT source file. ``` echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_22.x nodistro main" | sudo tee /etc/apt/sources.list.d/nodesource.list ``` Update the repository index. ``` apt update ``` Finally, install the Nodejs using the following command: ``` apt install nodejs ``` After the installation, you can verify the Nodejs version using the following command: ``` node --version ``` Output: ``` v22.15.1 ``` ## Step 2 – Install and Setup Uptime Kuma First, clone the Uptime Kuma repository from GitHub. ```bash git clone https://github.com/louislam/uptime-kuma.git ``` Navigate to the uptime-kuma directory and run the setup script using npm: ```bash cd uptime-kuma npm run setup ``` ## Step 3 – Install PM2 for Process Management PM2 is a process manager for Node.js applications that allows you to keep your app running in the background and restart it if it crashes. Install PM2 globally: ```bash npm install pm2 -g ``` Install the PM2 log rotation module to manage log files efficiently: ```bash pm2 install pm2-logrotate ``` You should see output similar to this: ```bash ┌────┬──────────────────┬─────────────┬─────────┬─────────┬──────────┬────────┬──────┬───────────┬──────────┬──────────┬──────────┬──────────┐ │ id │ name │ namespace │ version │ mode │ pid │ uptime │ ↺ │ status │ cpu │ mem │ user │ watching │ └────┴──────────────────┴─────────────┴─────────┴─────────┴──────────┴────────┴──────┴───────────┴──────────┴──────────┴──────────┴──────────┘ Module ┌────┬──────────────────────────────┬───────────────┬──────────┬──────────┬──────┬──────────┬──────────┬──────────┐ │ id │ module │ version │ pid │ status │ ↺ │ cpu │ mem │ user │ ├────┼──────────────────────────────┼───────────────┼──────────┼──────────┼──────┼──────────┼──────────┼──────────┤ │ 0 │ pm2-logrotate │ 2.7.0 │ 87179 │ online │ 0 │ 0% │ 11.0mb │ root │ └────┴──────────────────────────────┴───────────────┴──────────┴──────────┴──────┴──────────┴──────────┴──────────┘ ``` ## Step 4 – Start Uptime Kuma with PM2 Start the Uptime Kuma server using PM2: ```bash pm2 start server/server.js --name uptime-kuma ``` You should see output similar to this: ```bash [PM2] Starting /root/uptime-kuma/server/server.js in fork_mode (1 instance) [PM2] Done. ┌────┬──────────────────┬─────────────┬─────────┬─────────┬──────────┬────────┬──────┬───────────┬──────────┬──────────┬──────────┬──────────┐ │ id │ name │ namespace │ version │ mode │ pid │ uptime │ ↺ │ status │ cpu │ mem │ user │ watching │ ├────┼──────────────────┼─────────────┼─────────┼─────────┼──────────┼────────┼──────┼───────────┼──────────┼──────────┼──────────┼──────────┤ │ 1 │ uptime-kuma │ default │ 1.23.13 │ fork │ 87203 │ 0s │ 0 │ online │ 0% │ 5.7mb │ root │ disabled │ └────┴──────────────────┴─────────────┴─────────┴─────────┴──────────┴────────┴──────┴───────────┴──────────┴──────────┴──────────┴──────────┘ Module ┌────┬──────────────────────────────┬───────────────┬──────────┬──────────┬──────┬──────────┬──────────┬──────────┐ │ id │ module │ version │ pid │ status │ ↺ │ cpu │ mem │ user │ ├────┼──────────────────────────────┼───────────────┼──────────┼──────────┼──────┼──────────┼──────────┼──────────┤ │ 0 │ pm2-logrotate │ 2.7.0 │ 87179 │ online │ 0 │ 0% │ 52.3mb │ root │ └────┴──────────────────────────────┴───────────────┴──────────┴──────────┴──────┴──────────┴──────────┴──────────┘ ``` Check the status of the process to ensure it’s running correctly: ```bash pm2 status ``` To ensure Uptime Kuma starts on system boot, configure PM2 with the following command: ```bash pm2 startup ``` ## Step 5 – Install and Configure Nginx To make Uptime Kuma accessible via a web domain, we will use Nginx as a reverse proxy. First, install Nginx: ```bash apt install nginx -y ``` Create a new Nginx configuration file for Uptime Kuma: ```bash nano /etc/nginx/conf.d/kuma.conf ``` Add the following configuration to the file: ```bash server { listen 80; server_name kuma.example.com; location / { proxy_pass http://localhost:3001; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $host; } } ``` Edit the Nginx main configuration file and set max hash bucket size: ```bash nano /etc/nginx/nginx.conf ``` Add the following line after http {: ```bash server_names_hash_bucket_size 64; ``` Test the Nginx configuration for syntax errors: ```bash nginx -t ``` You should see the following output if the configuration is correct: ```bash nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Restart Nginx to apply the changes: ```bash systemctl restart nginx ``` ## Step 6 – Access Uptime Kuma You can now access your Uptime Kuma instance through your web browser by navigating to **http://kuma.example.com.**You will see the account creation page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p1-2.png) Define your admin username, password and click on **Create.** You will see the Uptime Kuma dashboard. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p2-1.png) ## Conclusion Congratulations! You have successfully installed and configured Uptime Kuma on Ubuntu 24.04. Uptime Kuma is now running behind Nginx and can be accessed via your configured domain. This setup ensures that your monitoring tool is robust, easy to manage, and ready to alert you in case of any issues with your websites or servers. You can now monitor your application using Uptime Kuma on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install CloudPanel on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-cloudpanel-on-ubuntu-22-04/ | Published: 2024-07-08 | Updated: 2024-07-15 | Author: Hitesh Jethva Managing cloud servers efficiently can be a daunting task without the right tools. CloudPanel, a modern and user-friendly control panel, simplifies this process by offering a powerful interface to manage cloud infrastructure. Designed specifically for cloud environments, CloudPanel provides an array of features that streamline server administration, making it a popular choice for developers and system administrators alike. This guide will walk you through the step-by-step process of installing CloudPanel on Ubuntu 22.04. ## Step 1 – Install Necessary Dependencies Before installing CloudPanel, you need to ensure that your server has all the necessary dependencies. These dependencies include gnupg2 and curl, which are essential for the installation process. Open your terminal and execute the following command to install these dependencies: ```bash apt install -y gnupg2 curl ``` ## Step 2 – Download and Execute the CloudPanel Installer With the dependencies installed, the next step is to download and execute the CloudPanel installer script. This script will handle the entire installation process, setting up CloudPanel on your server. First, use curl to download the installer script: ```bash curl -sS https://installer.cloudpanel.io/ce/v2/install.sh -o install.sh ``` Once the script is downloaded, execute it using bash: ```bash bash install.sh ``` After running the installer script, CloudPanel will be installed on your server. The installation process will take a few minutes as it sets up all the necessary components and configurations. Once the installation is complete, you should see a message indicating that CloudPanel has been successfully installed. The message will also provide the URL to access CloudPanel. ```bash ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ The installation of CloudPanel is complete! CloudPanel can be accessed now: https://YOUR_SERVER_IP:8443 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ``` ## Step 3 – Access CloudPanel After successfully installing CloudPanel on your Ubuntu 22.04 server, the next step is to access the CloudPanel Web UI. This interface allows you to manage your cloud servers and services easily. Open your web browser and access the CloudPanel web interface using the URL **https://your-server-ip:8443.** Since CloudPanel uses a self-signed SSL certificate by default, you might see a security warning in your browser indicating that the connection is not private. This is normal for self-signed certificates. In Chrome, click on “Advanced” and then “Proceed to [your-server-ip] (unsafe)”. You will be presented with the CloudPanel user creation screen. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p1-4.png) Provide your name, username, password, and email and click on **Create User.** You will see the CloudPanel login screen. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p2-3.png) Provide your admin credentials and click on **Log In.** You will see the CloudPanel Dashboard. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p3-1.png) Click on **ADD SITE** to create a new site on CloudPanel**.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p4-2.png) Click on “**Create a WordPress Site.**” You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p5-2.png) Provide your WordPress site details and click on **Create.** You will see the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p6-1.png) Click on **Back to Sites**. You will see your newly added WordPress site. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p7-1.png) ## Conclusion Installing CloudPanel on Ubuntu 22.04 is a straightforward process that significantly enhances your ability to manage cloud servers. With just a few commands, you can set up a robust control panel that simplifies server administration and boosts productivity. Whether you are hosting websites, deploying applications, or managing various services, CloudPanel provides an intuitive interface that makes these tasks more manageable. By following the steps outlined in this guide, you now have CloudPanel installed and ready to use, allowing you to take full advantage of its powerful features and streamline your cloud server management. You can now host your own server panel on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Froxlor Server Management Panel on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-froxlor-server-management-panel-on-ubuntu-22-04/ | Published: 2024-07-09 | Updated: 2024-07-28 | Author: Hitesh Jethva Froxlor is an open-source server management panel that provides an intuitive and user-friendly web interface for managing various aspects of web hosting servers. It is designed to help system administrators and web hosting providers efficiently manage server configurations, domains, email accounts, databases, and other server-related tasks. Froxlor is free to use, which can significantly reduce the costs associated with server management. It provides a viable alternative to commercial server management panels without compromising on features and functionality. In this tutorial, we will show you how to install Froxlor server management panel on Ubuntu 22.04. ## Step 1 – Install Required Dependencies First, install the necessary dependencies for Froxlor using the following command: ```bash apt -y install gnupg2 apt-transport-https lsb-release curl ca-certificates apache2 ``` ## Step 2 – Add Froxlor Repository Download the Froxlor GPG key and add the Froxlor repository to your system: ```bash curl -sSLo /usr/share/keyrings/deb.froxlor.org-froxlor.gpg https://deb.froxlor.org/froxlor.gpg ``` Add the repository to your sources list: ```bash sh -c 'echo "deb [signed-by=/usr/share/keyrings/deb.froxlor.org-froxlor.gpg] https://deb.froxlor.org/ubuntu $(lsb_release -sc) main" > /etc/apt/sources.list.d/froxlor.list' ``` ## Step 3 – Install Froxlor Update the package list and install Froxlor: ```bash apt update apt install froxlor -y ``` ## Step 4 – Configure MySQL Froxlor requires a MySQL database. You will need to create a new user and database for Froxlor. First, connect to MySQL. ```bash mysql ``` Create a user and database for Froxlor: ```bash CREATE USER 'froxroot'@'localhost' IDENTIFIED BY 'password'; GRANT ALL PRIVILEGES ON *.* TO 'froxroot'@'localhost' WITH GRANT OPTION; ``` Flush the privileges and exit from the MySQL shell: ```bash FLUSH PRIVILEGES; EXIT; ``` ## Step 5 – Install PHP GNUPG Extension To ensure Froxlor operates correctly, install the PHP GNUPG extension: ```bash apt install php-gnupg -y ``` Restart the Apache web server to apply the changes: ```bash systemctl restart apache2 ``` Check the status of the Apache service to ensure it is running: ```bash systemctl status apache2 ``` You should see an output indicating that the Apache service is active and running. ```bash ● apache2.service - The Apache HTTP Server Loaded: loaded (/lib/systemd/system/apache2.service; enabled; vendor preset: enabled) Active: active (running) since Wed 2024-06-05 12:14:57 UTC; 25s ago Docs: https://httpd.apache.org/docs/2.4/ Process: 69486 ExecStart=/usr/sbin/apachectl start (code=exited, status=0/SUCCESS) Main PID: 69490 (apache2) Tasks: 6 (limit: 4579) Memory: 14.9M CPU: 55ms CGroup: /system.slice/apache2.service ├─69490 /usr/sbin/apache2 -k start ├─69491 /usr/sbin/apache2 -k start ├─69492 /usr/sbin/apache2 -k start ├─69493 /usr/sbin/apache2 -k start ├─69494 /usr/sbin/apache2 -k start └─69495 /usr/sbin/apache2 -k start ``` ## Step 6 – Access Froxlor Web Installer Open your web browser and navigate to **http://your-server-ip/froxlor** to access the Froxlor web installer. You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/06/p1-3.png) Click on the **Start install.** You will see the system check page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p2-2.png) Click on **Start installation.** You will see the database setup page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p4-1.png) Define your database name and password and click on **Next.** You will see the admin setup page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p5-1.png) Set your admin user, password, and email and click on **Next.** You will see the server setup page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p6.png) Set your server IP, domain name, and enable SSL and click on **Next.** You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p7.png) Copy the command from the above page and run it on your server console to finish the installation. ```bash /var/www/html/froxlor/bin/froxlor-cli froxlor:install -c 'eyJteXNxbF9ob3N0IjoibG9jYWxob3N0IiwibXlzcWxfdW5wcml2aWxlZ2VkX3VzZXIiOiJmcm94bG9yIiwibXlzcWxfdW5wcml2aWxlZ2VkX3Bhc3MiOiJwYXNzd29yZCIsIm15c3FsX2RhdGFiYXNlIjoiZnJveHJvb3QiLCJteXNxbF9yb290X3VzZXIiOiJmcm94cm9vdCIsIm15c3FsX3Jvb3RfcGFzcyI6InBhc3N3b3JkIiwibXlzcWxfc3NsX2NhX2ZpbGUiOiIiLCJteXNxbF9zc2xfdmVyaWZ5X3NlcnZlcl9jZXJ0aWZpY2F0ZSI6IjEifQ==' /var/www/html/froxlor/bin/froxlor-cli froxlor:config-services -a '{"distro":"jammy","dns":"x","http":"apache24","smtp":"postfix_dovecot","mail":"dovecot_postfix2","ftp":"proftpd","system":["cron","libnssextrausers","logrotate","goaccess","php-fpm"]}' --yes-to-all ``` Go back to your web browser, you will see the Froxlor login page. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p8.png) Enter your Froxlor admin username and password and click on **Login.** You will see the Froxlor dashboard. ![](https://www.atlantic.net/wp-content/uploads/2024/06/p10.png) ## Conclusion You have now successfully installed and configured the Froxlor server management panel on Ubuntu 22.04. This powerful tool will help you manage your server more efficiently through its user-friendly web interface. For more information and advanced configurations, refer to the Froxlor documentation. You can now host your own server management panel using Froxlor on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Wiki.js on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-wiki-js-on-ubuntu-24-04/ | Published: 2024-07-10 | Updated: 2025-05-25 | Author: Hitesh Jethva Wiki.js is a powerful, flexible, and modern open-source wiki application designed to help you manage your documentation and knowledge base effectively. Built on Node.js, it offers a sleek user interface, extensive customization options, and seamless integration with various authentication systems and data sources. This guide will walk you through the steps to install Wiki.js on Ubuntu 24.04. ## Step 1 – Install Node.js First, install the necessary dependencies using the following command. ``` apt-get install -y ca-certificates curl gnupg ``` Next, download the Node.js GPG key. ``` mkdir -p /etc/apt/keyrings curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg ``` Next, add the NodeSource repo to the APT source list. ``` echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_22.x nodistro main" | tee /etc/apt/sources.list.d/nodesource.list ``` Then, update the repository index and install Node.js with the following command. ``` apt update apt-get install -y nodejs ``` Next, verify the Node.js version using the following command. ``` node -v ``` Output. ``` v22.15.1 ``` ## Step 2 – Install and Configure MariaDB Database Wiki.js uses MariaDB as its database. You can install the MariaDB server with the following commands: ```bash apt install mariadb-server -y ``` Once the MariaDB is installed, connect to the MariaDB shell using the following command. ```bash mysql ``` Next, create a database and user for Wiki.js. ```bash CREATE DATABASE wikijs; GRANT ALL on wikijs.* to wikijs@localhost identified by 'password'; ``` Next, flush the privileges and exit from the MariaDB shell. ```bash FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Install Wiki.js First, create a dedicated user for Wiki.js. ```bash useradd -m -d /opt/wikijs -U -r -s /bin/bash wikijs ``` Log in to your wikijs user: ```bash su - wikijs ``` Download the latest version of Wiki.js: ```bash wget https://github.com/Requarks/wiki/releases/latest/download/wiki-js.tar.gz ``` Extract the downloaded file. ```bash tar -xzvf wiki-js.tar.gz ``` Copy the sample configuration file. ```bash cp -a config.sample.yml config.yml ``` Edit the sample configuration file. ```bash nano config.yml ``` Define your database settings: ```bash db: type: mariadb # PostgreSQL / MySQL / MariaDB / MS SQL Server only: host: localhost port: 3306 user: wikijs pass: password db: wikijs ``` Save and close the file then exit from the Wiki.js user. ```bash exit ``` ## Step 4 – Create a Systemd Service To ensure Wiki.js runs as a service and starts on boot, create a systemd service file: ```bash nano /etc/systemd/system/wikijs.service ``` Add the following content to the file: ```bash [Unit] Description=Wiki.js After=network.target [Service] Type=simple ExecStart=/usr/bin/node server Restart=always User=wikijs Environment=NODE_ENV=production WorkingDirectory=/opt/wikijs [Install] WantedBy=multi-user.target ``` Reload the systemd daemon to apply the new service file: ```bash systemctl daemon-reload ``` Enable and start the Wiki.js service: ```bash systemctl enable --now wikijs ``` ## Step 4 – Configure Nginx as a Reverse Proxy If you want to serve Wiki.js through a domain and use Nginx as a reverse proxy, install Nginx first: ```bash apt install nginx ``` Create a new Nginx configuration file: ```bash nano /etc/nginx/conf.d/wiki.conf ``` Add the following configuration: ```bash server { listen 80; server_name wikijs.example.com; root /opt/wikijs; location / { proxy_pass http://127.0.0.1:3000; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } } ``` Edit the Nginx main configuration file: ```bash nano /etc/nginx/nginx.conf ``` Add the following lines after the line http {: ```bash server_names_hash_bucket_size 64; ``` Save the file then restart the Nginx service to apply the changes. ```bash systemctl restart nginx ``` ## Step 5 – Access Wiki.js Open a web browser and navigate to **http://wikijs.example.com.** You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p1-1.png) Set your email, password, and site URL, and click on **INSTALL**. You will be redirected to the Wiki.js login page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p2.png) Provide your email and password and click on **Log** **in**. You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p3-1.png) Click on **ADMINISTRATION.** You will see the Wiki.js dashboard. ![](https://www.atlantic.net/wp-content/uploads/2024/05/p4.png) ## Conclusion Installing Wiki.js on Ubuntu 24.04 is a comprehensive process that involves setting up the necessary software stack, configuring your environment, and deploying the application. By carefully following each step, from updating your system and installing Node.js, MariaDB, and other dependencies, to configuring Wiki.js and ensuring it runs as a service, you can achieve a smooth and efficient installation. With Wiki.js up and running, you now have a modern and feature-rich platform for managing your documentation and knowledge base. This setup not only enhances collaboration and information sharing but also provides a scalable solution that can grow with your needs. Let’s deploy Wiki.js on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Atlantic.Net Teams (ANT) > URL: https://www.atlantic.net/cloud-platform/collaboration-service/ | Updated: 2026-09-16 Manage servers, IP addresses, DNS, block storage, and billing from a single account with role-based access, searchable audit logs, and no shared passwords, API keys, or SSH credentials. - No Shared Credentials - 4 Role Types - Searchable Audit Logs - Centralized Billing Built-In Roles: 4 Separate Per-Seat Fee: None ## Simplify, secure, and scale your cloud operations with seamless teamwork. Atlantic.Net Teams (ANT) enables seamless collaboration on the Atlantic.Net Cloud Platform - simplifying resource management for everyone with a stake in your cloud environment. With Atlantic.Net Teams, you can simplify cloud operations, secure your team, and boost your results. ### The Perfect Solution for Your Cloud Operations Atlantic.Net Teams (ANT) gives your team the tools to collaborate on cloud projects seamlessly - share resources, delegate tasks, and stay in sync, all within a secure, controlled, centralized platform. ### Secure Resource Sharing Invite users to share cloud servers, IP addresses, DNS configurations, block storage, and more - without sharing sensitive credentials. ### Set the Permissions Your Users Need Assign custom roles - administrator, technical, billing, observer - to control access and maintain a secure, fully audited workflow. ### Easily Access Logs Track user actions and resource changes through comprehensive, searchable audit logs for enhanced accountability. ### Simplify Billing Centralized billing management within your team for improved visibility, delegation, and financial control. ## Who Can Benefit? ### Development Teams Collaborate on projects, manage environments, and deploy applications with ease. ### IT Professionals Simplify cloud administration, monitor resource usage, and maintain security standards. ### Businesses of All Sizes Customize cloud management, enhance collaboration, and optimize resource utilization. ## Why Choose Atlantic.Net Teams? ### Enhanced Security Protect sensitive information and maintain control over your cloud environment. ### Improved Efficiency Streamline workflows, automate tasks, and reduce communication overhead. ### Increase Collaboration Foster teamwork, share knowledge, and accelerate project completion. ## Get Started Today Leverage our collaborative cloud to meet your unique cloud needs - backed by outstanding customer support, world-class infrastructure, and innovative technologies. Sign up online to see how our collaborative cloud can help increase efficiency, reduce cost, and bring focus to your core business. ## Frequently Asked Questions About Atlantic.Net Teams ### What is Atlantic.Net Teams (ANT)? Atlantic.Net Teams (ANT) is a collaboration layer for the Atlantic.Net Cloud Platform that lets multiple users share, delegate, and audit cloud resources from a single account - without exposing credentials. It covers servers, IP addresses, DNS, block storage, and billing under a role-based permission model. ### What roles and permissions are available? The built-in roles are administrator (full access), technical (resource and configuration access without billing), billing (financial-only access), and observer (read-only). Roles are assigned per user and audited so you always know who did what. ### How does sharing resources work without sharing credentials? Each user logs in with their own ACP account. The team owner grants scoped access to specific resources or all resources, and the user inherits permissions through their assigned role - no shared password, no shared API key, no shared SSH credential. ### Do audit logs cover all team activity? Yes. Searchable audit logs record user logins, role changes, resource create/modify/destroy events, and billing actions. The logs are useful for security review, internal governance, and compliance attestations. ### Is there an additional cost to use Atlantic.Net Teams? The collaboration features are part of the ACP control panel for Atlantic.Net Cloud Platform customers. Underlying compute, storage, and managed-services usage is still billed normally; ANT consolidates visibility and control without adding a separate per-seat fee. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # How to Install HAProxy on Ubuntu 24.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-haproxy-on-ubuntu-24-04/ | Published: 2024-07-11 | Updated: 2025-05-14 | Author: Hitesh Jethva HAProxy, which stands for High Availability Proxy, is a free, open-source software solution that provides a reliable, high-performance load balancer and proxy server for TCP and HTTP-based applications. It is commonly used to improve the performance and reliability of web applications by distributing incoming traffic across multiple servers. In this tutorial, we will show you how to install HAProxy on Ubuntu 24.04. ## Step 1 – Setting Up Backend Servers Before starting, you will need to set up Apache on both backend servers. Log in to both your servers and install the Apache package using the following command. ```bash apt-get install apache2 -y ``` Once the Apache package is installed, create an index.html file on both web servers. `echo "

This is my first Apache Server

" | tee /var/www/html/index.html` `echo "

This is my second Apache Server

" | tee /var/www/html/index.html` ## Step 2 – Install HAProxy By default, the HAProxy package is included in the Ubuntu default repository. You can install it using the following command. ```bash apt-get install haproxy -y ``` Next, check the installed version to verify that HAProxy is installed correctly. ```bash haproxy -v ``` You should see an output showing the HAProxy version. ```bash HAProxy version 2.8.5-1ubuntu3.3 2025/04/09 - https://haproxy.org/ ``` Next, start and enable the HAProxy service. ```bash systemctl start haproxy systemctl enable haproxy ``` ## Step 3 – Configure HAProxy Edit the HAProxy configuration file to set up a basic configuration. The default configuration file is located at /etc/haproxy/haproxy.cfg. ```bash nano /etc/haproxy/haproxy.cfg ``` Add the following lines: ```bash frontend haproxy-main bind *:80 option forwardfor default_backend apache_webservers backend apache_webservers balance roundrobin server websvr1 192.168.1.10:80 check server websvr2 192.168.1.11:80 check ``` - The frontend section defines where HAProxy listens for incoming traffic (port 80 in this case). - The backend section specifies the servers that the traffic should be distributed to. **Note**: Replaced **192.168.1.10** and **192.168.1.11** with the IP address of your backend Apache web servers. ## Step 4 – Setup HAProxy Authentication To configure authentication for the HAProxy statistics page on port 8800 and set up a backend for your Apache web servers, you can use the following configuration. This example includes the listen section for the stats page with basic authentication and a backend section for your Apache servers. Edit the haproxy.cfg file. ```bash nano /etc/haproxy/haproxy.cfg ``` Add the following lines: ```bash listen stats bind :8800 stats enable stats uri / stats hide-version stats auth admin:password default_backend apache_webservers ``` Save and close the file, then restart the HAProxy service to apply the changes. ```bash systemctl restart haproxy ``` Now, verify the status of HAProxy using the command given below: ```bash systemctl status haproxy ``` Output: ```bash ● haproxy.service - HAProxy Load Balancer Loaded: loaded (/lib/systemd/system/haproxy.service; enabled; vendor preset: enabled) Active: active (running) since Sat 2025-05-11 12:32:27 IST; 9s ago Docs: man:haproxy(1) file:/usr/share/doc/haproxy/configuration.txt.gz Process: 44208 ExecStartPre=/usr/sbin/haproxy -Ws -f $CONFIG -c -q $EXTRAOPTS (code=exited, status=0/SUCCESS) Main PID: 44210 (haproxy) Tasks: 5 (limit: 9188) Memory: 70.0M CPU: 78ms CGroup: /system.slice/haproxy.service ├─44210 /usr/sbin/haproxy -Ws -f /etc/haproxy/haproxy.cfg -p /run/haproxy.pid -S /run/haproxy-master.sock └─44212 /usr/sbin/haproxy -Ws -f /etc/haproxy/haproxy.cfg -p /run/haproxy.pid -S /run/haproxy-master.sock May 11 12:32:27 ubuntupc systemd[1]: Starting HAProxy Load Balancer... May 11 12:32:27 ubuntupc haproxy[44210]: [NOTICE] (44210) : New worker #1 (44212) forked May 11 12:32:27 ubuntupc systemd[1]: Started HAProxy Load Balancer. ``` ## Step 5 – Test HAProxy Open a web browser and navigate to your server’s IP address **http://your-haproxy-ip.** You should be able to see the Apache page if your backend servers are configured correctly. ![](https://www.atlantic.net/wp-content/uploads/2024/05/p1.png) To view HAProxy statistics, navigate to **http://your_haproxy_ip:8080/** and log in with the credentials defined in the configuration file (admin:password in this example). ![](https://www.atlantic.net/wp-content/uploads/2024/05/p3.png) ## Conclusion HAProxy is a powerful and flexible tool for load balancing and improving the availability and performance of web applications and services. Its wide range of features and configurations makes it suitable for various use cases, from simple load balancing to complex routing and traffic management tasks. You can now deploy HAProxy on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! to load balance your web server. --- # How to Install Textpattern on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-textpattern-on-ubuntu-22-04/ | Published: 2024-07-12 | Updated: 2024-07-15 | Author: Hitesh Jethva Textpattern is a flexible, open-source content management system (CMS) designed for web developers, designers, and content creators. It is known for its simplicity, ease of use, and powerful features that enable users to manage content efficiently. Whether you are building a simple blog or a complex business website, Textpattern provides the tools and features to manage your content effectively. In this tutorial, we will show you how to install Textpattern CMS on Ubuntu 22.04. ## Step 1 – Install LEMP Stack Textpattern requires a LEMP stack to be installed on your server. If not installed, you can install it using the following command. ```bash apt install -y nginx mariadb-server php php-fpm php-xml php-mysql php-json php-mbstring php-zip unzip ``` Once the LEMP stack is installed, start and enable the Nginx and MariaDB services. ```bash systemctl start mariadb nginx systemctl enable mariadb nginx ``` ## Step 2 – Create a Database and User Textpattern uses MariaDB/MySQL as a database backend. First, connect to the MariaDB console. ```bash mysql ``` Once you are connected to the MariaDB shell, create a database and user for Textpattern. ```bash CREATE DATABASE textpattern_db; CREATE USER textpattern_user IDENTIFIED BY 'password'; ``` Next, grant all the privileges to the Textpattern database. ```bash GRANT ALL PRIVILEGES ON textpattern_db.* TO textpattern_user; ``` Next, flush the privileges and exit from the MariaDB console. ```bash FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download Textpattern Next, visit the Textpattern official website and download the latest version of Textpattern using the following command. ```bash wget https://textpattern.com/file_download/118/textpattern-4.8.8.zip ``` Once Textpattern is downloaded, unzip it using the following command. ```bash unzip textpattern-4.8.8.zip ``` Next, move the extracted directory to Nginx web root. ```bash mv textpattern-4.8.8 /var/www/html/textpattern ``` Next, change the ownership of the Textpattern directory. ```bash chown -R www-data:www-data /var/www/html/textpattern ``` ## Step 4 – Configure Nginx To configure Nginx for Textpattern, you’ll need to set up Nginx as your web server, create a new server block for your Textpattern site, and adjust the configuration to ensure it works correctly with Textpattern. ```bash nano /etc/nginx/conf.d/textpattern.conf ``` Add the following configuration: ```bash server { listen 80; server_name textpattern.example.com; root /var/www/html/textpattern; index index.php; location ~* \.php$ { fastcgi_pass unix:/run/php/php8.1-fpm.sock; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_param SCRIPT_NAME $fastcgi_script_name; } } ``` Save and close the file, then edit the Nginx main configuration file. ```bash nano /etc/nginx/nginx.conf ``` Add the following line after the line http {: ```bash server_names_hash_bucket_size 64; ``` Now, verify the Nginx for any syntax configuration error. ```bash nginx -t ``` Output: ```bash nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx service to apply the changes. ```bash systemctl restart nginx ``` ## Step 5 – Access Textpattern Web UI Now, open your web browser and access the Textpattern web interface using the URL **http://textpattern.example.com/textpattern/setup/.** You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p1-2.png) Select your language and click on **Submit.** You will see the database configuration page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p2-1.png) Define your database details and click on the **Next.** You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p4-1.png) Now, copy the content from the above page, create a new configuration file at **/var/www/html/textpattern/textpattern/config.php**, and paste this content to this file. Next, go back to your web browser and click on **I did it**. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/05/p5.png) Set your admin username, email, and password, and click on **Next**. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/05/p6.png) Click on **Log in now**. You will see the Textpattern login page. ![](https://www.atlantic.net/wp-content/uploads/2024/05/p7.png) Provide your admin username and password and click on **Log in.** You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p9.png) Enter your blog title and description and click on the **Publish** button. Then, click on **My Site** to see your newly published blog post. ![](https://www.atlantic.net/wp-content/uploads/2024/05/p10.png) ## Conclusion Textpattern is a powerful yet user-friendly CMS that caters to a wide range of website needs. Its flexibility, extensibility, and adherence to web standards make it a solid choice for developers and content creators looking for a robust content management solution. You can try Textpattern CMS on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install Zen Cart on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-zen-cart-on-ubuntu-22-04/ | Published: 2024-07-13 | Updated: 2024-07-15 | Author: Hitesh Jethva Zen Cart is an open-source software program that allows you to set up and manage an online store. It’s free to use and considered user-friendly, making it a popular choice for those starting out with e-commerce. Zen Cart is a solid option for those looking for a free and easy-to-use platform to set up a basic online store. In this tutorial, we will show you how to install Zen Cart on Ubuntu 22.04. ## Step 1 – Install LAMP Server First, install the Apache, MariaDB, PHP and other required PHP extensions using the following command: ```bash apt install -y apache2 mariadb-server php php-cli php-common libapache2-mod-php php-curl php-zip php-gd php-mysql php-xml php-mbstring php-json php-intl ``` Next, edit the PHP configuration file: ```bash nano /etc/php/8.1/apache2/php.ini ``` Change the default values of the following settings: ```bash memory_limit = 512M post_max_size = 128M upload_max_filesize = 128M date.timezone = America/Chicago ``` Save the file, then restart the Apache service to implement the changes. ```bash systemctl restart apache2 ``` ## Step 2 – Create a Database and User First, log in to your MariaDB shell: ```bash mysql ``` After the successful connection, create a database and user for Zen Cart: ```bash CREATE DATABASE zencart; CREATE USER 'zencart'@'localhost' IDENTIFIED BY 'password'; ``` Next, grant all the privileges to Zen Cart. ```bash GRANT ALL PRIVILEGES ON zencart. * TO 'zencart'@'localhost'; ``` Next, flush the privileges and exit from the MariaDB shell: ```bash FLUSH PRIVILEGES; EXIT; ``` ## Step 3 – Download Zen Cart First, go to the Zen Cart official download page and download the latest Zen Cart archive. ```bash wget https://github.com/zencart/zencart/archive/refs/tags/v2.0.0.zip --no-check-certificate ``` Then, unzip the downloaded archive: ```bash unzip v2.0.0.zip ``` Next, move the extracted directory to the Apache web root: ```bash mv zencart-2.0.0 /var/www/html/zencart ``` Next, copy the Zen Cart sample configuration file. ```bash cp /var/www/html/zencart/includes/dist-configure.php /var/www/html/zencart/includes/configure.php ``` Next, change the ownership and permission of the Zen Cart directory. ```bash chown -R www-data:www-data /var/www/html/zencart find /var/www/html/zencart/ -type d -exec chmod 755 {} \; find /var/www/html/zencart/ -type f -exec chmod 644 {} \; ``` ## Step 4 – Create an Apache Virtual Host Next, you will need to create an Apache virtual host configuration file for Zen Cart. ```bash nano /etc/apache2/sites-available/zencart.conf ``` Add the following content: ```bash ServerAdmin admin@example.com DocumentRoot /var/www/html/zencart/ ServerName zencart.example.com Options FollowSymLinks AllowOverride All Order allow,deny Allow from all ErrorLog /var/log/apache2/example.com-error_log CustomLog /var/log/apache2/example.com-access_log common ``` Save the file then activate the Zen Cart virtual host. ```bash a2ensite zencart.conf ``` Finally, restart the Apache service to apply the changes. ```bash systemctl restart apache2 ``` ## Step 5 – Access Zen Cart Web Interface Now, open your web browser and access the Zen Cart UI using the URL http://zencart.example.com. You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p1-3.png) Click on **CLICK HERE.** You will see the system inspection page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p2-2.png) Click on **Continue.** You will see the License Agreement and settings page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p3-2.png) Accept the License Agreement, define other necessary settings, and click on **Continue.** You will see the database setup page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p4-2.png) Provide your database credentials and click on **Continue.** You will see the admin setup page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p5-1.png) Set your admin username, email, and password, and click on **Continue.** You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p6-1.png) Now, delete the installation directory from your server using the following command. ```bash rm -rf /var/www/html/zencart/zc_install ``` Next, click on the **Admin Dashboard** link. You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p7-1.png) Provide your admin username and password and click on **Submit.** You will see the password reset page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p8-1.png) Change your admin password and click on **Submit.** You will see the Initial Setup page. ![](https://www.atlantic.net/wp-content/uploads/2024/05/p9-1.png) Provide your store information and click on **Update.** You will see the Zen Cart dashboard. ![](https://www.atlantic.net/wp-content/uploads/2024/05/p10-1.png) ## Conclusion Zen Cart offers a powerful and flexible solution for e-commerce, and with this guide, you can confidently set it up on your Ubuntu 22.04 server. Whether you are setting up a new store or migrating an existing one, you now have the knowledge to manage your installation effectively. Enjoy the capabilities of Zen Cart and start building your online presence today! You can now host your own online store using Zen Cart on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Deploy MinIO on Ubuntu 24.04 – An Open-Source Object Storage Application > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-deploy-minio-on-ubuntu-24-04-an-open-source-object-storage-application/ | Published: 2024-07-14 | Updated: 2025-05-18 | Author: Hitesh Jethva Whether you’re managing data for a small business, a large enterprise, or personal projects, a reliable object storage system is essential. MinIO, an open-source object storage server, provides a solution that is not only powerful but also easy to deploy and manage. In this guide, we’ll walk you through the process of installing MinIO on Ubuntu 24.04. ## Step 1 – Install MinIO First, visit the MinIO server download page and download the latest deb file. https://min.io/download#/linux ```bash wget https://dl.min.io/server/minio/release/linux-amd64/minio ``` Once the package is downloaded, copy the downloaded file to the system location. ```bash mv minio /usr/local/bin/minio ``` ## Step 2 – Configure MinIO Next, create a user and group for MinIO: ```bash groupadd -r minio-user useradd -M -r -g minio-user minio-user ``` Next, create a data directory for MinIO: ```bash mkdir /mnt/data ``` Then, change the ownership of the data directory and Minio binary. ```bash chmod u+rxw /mnt/ /usr/local/bin/minio chown -R minio-user /mnt/ /usr/local/bin/minio ``` ## Step 3 – Create a Systemd Service File for Minio Now, create a systemd file to manage the Minio service. ```bash nano /etc/systemd/system/minio.service ``` Add the following lines: ```bash [Unit] Description=MinIO High Performance Object Storage Documentation=https://docs.min.io Wants=network-online.target After=network-online.target [Service] User=minio-user Group=minio-user WorkingDirectory=/mnt/data ExecStart=/usr/local/bin/minio server /mnt/data --console-address ":9001" Restart=always RestartSec=5 # Set environment variables Environment=MINIO_ROOT_USER=admin Environment=MINIO_ROOT_PASSWORD=password # Allow MinIO to bind to low ports if needed CapabilityBoundingSet=CAP_NET_BIND_SERVICE AmbientCapabilities=CAP_NET_BIND_SERVICE NoNewPrivileges=true [Install] WantedBy=multi-user.target ``` Next, reload the systemd daemon to apply the changes: ```bash systemctl daemon-reload ``` Start and enable the Minio service. ```bash systemctl start minio systemctl enable minio ``` Check the status of Minio: ```bash systemctl status minio ``` Output: ```bash ● minio.service - MinIO High Performance Object Storage Loaded: loaded (/etc/systemd/system/minio.service; disabled; preset: enabled) Active: active (running) since Mon 2025-05-19 04:25:59 UTC; 53s ago Docs: https://docs.min.io Main PID: 18513 (minio) Tasks: 7 (limit: 4609) Memory: 214.8M (peak: 215.0M) CPU: 709ms CGroup: /system.slice/minio.service └─18513 /usr/local/bin/minio server /mnt/data --console-address :9001 May 19 04:25:59 ubuntu systemd[1]: Started minio.service - MinIO High Performance Object Storage. May 19 04:25:59 ubuntu minio[18513]: INFO: Formatting 1st pool, 1 set(s), 1 drives per set. May 19 04:25:59 ubuntu minio[18513]: INFO: WARNING: Host local has more than 0 drives of set. A host failure will result in data becoming unavailable. May 19 04:25:59 ubuntu minio[18513]: MinIO Object Storage Server May 19 04:25:59 ubuntu minio[18513]: Copyright: 2015-2025 MinIO, Inc. May 19 04:25:59 ubuntu minio[18513]: License: GNU AGPLv3 - https://www.gnu.org/licenses/agpl-3.0.html May 19 04:25:59 ubuntu minio[18513]: Version: RELEASE.2025-04-22T22-12-26Z (go1.24.2 linux/amd64) May 19 04:25:59 ubuntu minio[18513]: API: http://69.28.88.17:9000 http://127.0.0.1:9000 May 19 04:25:59 ubuntu minio[18513]: WebUI: http://69.28.88.17:9001 http://127.0.0.1:9001 May 19 04:25:59 ubuntu minio[18513]: Docs: https://docs.min.io ``` ## Step 4 – Access MinIO Web UI Now, open your web browser and access the MinIO web UI using the URL **http://your-server-ip:9000.** You will see the MinIO login page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p1-4.png) Provide your admin username and password and click on **Login.** You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p2-3.png) Click on the Buckets in the left pane and click on **Create** **a Bucket.** You will see the following page: ![](https://www.atlantic.net/wp-content/uploads/2024/05/p3-3.png) Define your bucket name and click on **Create Bucket.** You will see your bucket on the following page. ![](https://www.atlantic.net/wp-content/uploads/2024/05/p4-3.png) ## Conclusion By following the steps outlined in this guide, you can quickly deploy MinIO on your Ubuntu server and start reaping the benefits of a modern, flexible, and efficient object storage system. Whether you’re building a cloud-native application, managing backups, or simply looking for a reliable storage solution, MinIO offers a versatile and scalable platform that can meet your requirements. With its easy installation process, robust features, and compatibility with the Amazon S3 API, MinIO empowers users to take control of their data without the complexity and cost associated with proprietary solutions. You can now deploy your own online storage using MinIO on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Guide: RDP Access to Atlantic.Net Windows Server > URL: https://www.atlantic.net/vps-hosting/guide-rdp-access-to-atlantic-net-windows-server/ | Published: 2024-07-15 | Author: Richard Bailey **Important Note:** Before proceeding, ensure your Windows Server on Atlantic.Net is configured with a static public IP address and has RDP (Remote Desktop Protocol) enabled. Also, security best practices like using strong passwords and enabling Network Level Authentication (NLA) for RDP should be considered. ## Method 1: RDP over 3389 (Direct, Public Internet) This is the most straightforward but least secure method, suitable for temporary use or on trusted networks. All Atlantic.Net Windows Servers running the desktop experience have RDP configured out of the box. - - Windows Server 2022 Datacenter (Desktop Experience) - Windows Server 2019 Datacenter (Desktop Experience) - Windows Server 2016 Datacenter (Desktop Experience) - Windows Server 2012 R2 Datacenter (Desktop Experience) ### Step 1 – Obtain Server IP Log into your Atlantic.Net control panel and find your Windows Server’s public IP address. You will also find this on the automated email sent from Atlantic.Net and on the provisioning screen immediately after deploying a Windows Server. ![](https://www.atlantic.net/wp-content/uploads/2024/07/Obtain-Server-IP.png) ### Step 2 – Open RDP Client On your local Windows machine, press **Win + R**, type “mstsc”, and press Enter. If you are using Linux, we recommend using Remmina. ### Step 3 – Enter IP Details In the RDP client, enter your server’s public IP and click “Connect”. ### Step 4 – Authenticate Provide the username and password for a user account with RDP permissions on the server. Atlantic.Net provides this information in the deployment email you get when you first deploy your Windows Server. ## Method 2: WinRM (Windows Remote Management) WinRM offers a PowerShell-based way to manage your server remotely, similar to SSH. To configure this, you will need to RDP to the server first or manage it via the Atlantic.Net VNC console. ### Step 1 – Enable WinRM On the Windows Server, open an elevated PowerShell Windows and type: ``` winrm quickconfig ``` This enables WinRM with default settings. Tip: To open an elevated Powershell window, right-click on the Powershell icon. ![](https://www.atlantic.net/wp-content/uploads/2024/07/Powershell.png) Once enabled, you will get the following output: ![](https://www.atlantic.net/wp-content/uploads/2024/07/Powershell-Output.png) ### Step 2 – Create New Inbound & Outbound Firewall Rule Ensure your Atlantic.net firewall settings allow inbound traffic on port 5985 (HTTP) or 5986 (HTTPS) for WinRM. #### Inbound Rule ``` New-NetFirewallRule -DisplayName "WinRM-HTTP" -Direction Inbound -Action Allow -Protocol TCP -LocalPort 5985 ``` #### Outbound Rule ``` New-NetFirewallRule -DisplayName "WinRM-HTTPS" -Direction Inbound -Action Allow -Protocol TCP -LocalPort 5986 ``` You will get the following output: ``` New-NetFirewallRule -DisplayName "WinRM-HTTP" -Direction Inbound -Action Allow -Protocol TCP -LocalPort 5985 Name : {b985530a-910d-4243-b483-e23b81013076} DisplayName : WinRM-HTTP Description : DisplayGroup : Group : Enabled : True Profile : Any Platform : {} Direction : Inbound Action : Allow EdgeTraversalPolicy : Block LooseSourceMapping : False LocalOnlyMapping : False Owner : PrimaryStatus : OK Status : The rule was parsed successfully from the store. (65536) EnforcementStatus : NotApplicable PolicyStoreSource : PersistentStore PolicyStoreSourceType : Local RemoteDynamicKeywordAddresses : {} PolicyAppId : PS C:\Users\Administrator> New-NetFirewallRule -DisplayName "WinRM-HTTPS" -Direction Inbound -Action Allow -Protocol TCP -LocalPort 5986 Name : {91d8d840-0d61-407b-bf1e-5186841bf683} DisplayName : WinRM-HTTPS Description : DisplayGroup : Group : Enabled : True Profile : Any Platform : {} Direction : Inbound Action : Allow EdgeTraversalPolicy : Block LooseSourceMapping : False LocalOnlyMapping : False Owner : PrimaryStatus : OK Status : The rule was parsed successfully from the store. (65536) EnforcementStatus : NotApplicable PolicyStoreSource : PersistentStore PolicyStoreSourceType : Local RemoteDynamicKeywordAddresses : {} PolicyAppId : ``` ### Step 3 – Create PSSession From a local Windows desktop or laptop machine, open PowerShell as Administrator and type the following to connect to your remote server: ``` $cred = Get-Credential # Enter server credentials $session = New-PSSession -ComputerName -Credential $cred ``` You will be prompted for your credentials. ### Step 4 – Execute Remote Commands on your Remote Server You can now manage your remote server from the current shell session. To test it, try running: ``` Invoke-Command -Session $session -ScriptBlock { Get-Process } ``` ## Method 3: SSH Tunnel (Most Secure) This method encrypts RDP traffic within an SSH tunnel, making it ideal for untrusted networks. You’ll need SSH access to an intermediary server—typically a jump box (e.g., a Linux server) that can reach your Windows Server. Alternatively, if you have a Linux laptop or Raspberry Pi, you can tunnel directly from there. ### Option 1 – Create SSH Tunnel Direct from a Linux Server If you don’t have OpenSSH installed on your Windows Server, follow these steps: #### Step 1 – Install OpenSSH on the Remote Windows Server By default, SSH is not enabled on Windows Server. To enable it Open PowerShell as an administrator and Run the following command to install OpenSSH: ``` Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0 ``` #### Step 2 – Start and Enable SSHD service Start the SSHD service and configure it to start automatically: ``` Start-Service sshd Set-Service -Name sshd -StartupType 'Automatic' ``` #### Step 3 – Allow SSH traffic through the Windows firewall Run this command in PowerShell as an administrator: ``` New-NetFirewallRule -Name sshd -DisplayName 'OpenSSH Server (sshd)' -Enabled True -Direction Inbound -Protocol TCP -Action Allow -LocalPort 22 ``` Once SSH is set up on your Windows server, follow these steps on your Ubuntu machine to create the tunnel: #### Step 4 – Use Terminal to Establish the SSH Tunnel Open a terminal session on your local Linux Machine. Use the following command to create the tunnel: ``` ssh -L 5985:localhost:5985 administrator@my-ip-address ``` You should get the following output: ``` ssh -L 5985:localhost:5985 administrator@my-ip-address The authenticity of host 'my-ip-address (my-ip-address)' can't be established. ED25519 key fingerprint is SHA256:VM41PWh85b91ZVTgIot0mqn3hCUV0vgJ4Lsut6OCLtc. This key is not known by any other names Are you sure you want to continue connecting (yes/no/[fingerprint])? yes Warning: Permanently added 'my-ip-address' (ED25519) to the list of known hosts. administrator@my-ip-address's password: Microsoft Windows [Version 10.0.20348.2527] (c) Microsoft Corporation. All rights reserved. administrator@CLOUD-H35V3SGG8 C:\Users\Administrator>hostname CLOUD-H35V3SGG8 You can now manage the remote server directly from your local terminal. ``` ### Option 2 – Create an SSH Tunnel from a Windows Machine via SSH Jumpbox #### Step 1 – Install an SSH Client and Configure Use a client like PuTTY or OpenSSH. **SSH -> Tunnels:** Source Port: 33389 Destination: your_server_IP:3389 Click “Add” #### Step 2 – Set Port Forwarding In your SSH client’s settings, configure a local port (e.g., 33389) to forward to your Windows Server’s IP and port 3389. #### Step 3 – Establish SSH Connection Connect to your intermediary server via SSH. #### Step 4 – RDP to Localhost Open your RDP client and connect to localhost:33389. Traffic will be securely tunneled to your Windows Server. #### Troubleshooting **Firewall**: Double-check firewall rules on both the Windows Server and any intermediary server (SSH tunnel). **Network:** Ensure network connectivity between your local machine, intermediary server (if using), and the Windows Server. **Authentication:** Verify you are using the correct credentials. --- # What Is HIPAA Cloud? > URL: https://www.atlantic.net/hipaa-compliant-hosting/what-is-hipaa-cloud/ | Published: 2024-07-27 | Updated: 2026-07-24 | Author: Alexander Wise *Updated: July 22, 2026* HIPAA cloud hosting meets the HIPAA Security Rule and Privacy Rule requirements for storing, processing, and transmitting electronic Protected Health Information (ePHI), backed by a signed HIPAA Business Associate Agreement (BAA) between the healthcare organization and the cloud service provider. Both halves of that sentence carry weight. The technical half covers encryption, access controls, audit logging, backup and recovery, and the physical security of the building where the hardware sits. The contractual half is the BAA, which makes the provider directly liable under the HIPAA Rules for the part of the environment it operates. A cloud platform with strong security and no BAA is not a HIPAA cloud, and neither is a signed BAA over an environment with no encryption at rest. The term describes a way of operating infrastructure, so it applies to public, private, and hybrid deployments alike. The U.S. Department of Health and Human Services (HHS) is explicit on this in its[cloud computing guidance](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html): “A covered entity or business associate may use cloud-based services of any configuration (public, hybrid, private, etc.), provided it enters into a BAA with the CSP.” One caveat belongs at the top. No hosting provider can make an organization HIPAA-compliant on its own. A[HIPAA-compliant cloud provider](https://www.atlantic.net/hipaa-compliant-hosting/) delivers an audited platform, signs the BAA, and operates the infrastructure controls. The covered entity still owns its risk analysis, workforce training, and application-level permissions. Most HIPAA enforcement actions turn on that second list. ## What Is HIPAA-Compliant Cloud Computing? HIPAA-compliant cloud computing runs healthcare workloads on shared, virtualized infrastructure under the same safeguards HIPAA would demand of an on-premises server room. The regulation sets out what has to be achieved and leaves the technical means open. It requires access controls, audit controls, integrity controls, transmission security, and a documented risk analysis. It does not name a firewall vendor or a cipher suite. That flexibility is why two providers can both offer HIPAA cloud services and mean different things. One has commissioned an independent audit against HIPAA AT-C 105/205, SOC 2 Type II, and SOC 3 Type II, and can produce the reports. The other has read the HIPAA Security Rule and written a policy document. Both claims are legal. Only one is verifiable. ### Who Needs HIPAA Cloud Computing? Covered entities are healthcare providers, health plans, and clearinghouses. Business associates handle ePHI on their behalf, which now covers most healthcare software companies: telehealth platforms, medical billing processors, EHR vendors, medical SaaS products, and biotech research teams. Covered entities and business associates both need HIPAA cloud hosting the moment healthcare data touches infrastructure they do not physically control. That catches organizations assuming they are out of scope, because a scheduling tool storing patient names alongside appointment reasons is handling ePHI. Business associates are where the boundary surprises people, since the definition follows the data and not the job title. ## HIPAA Cloud Requirements Checklist The table below covers what a HIPAA cloud environment has to include and, more usefully, who owns each piece. The right-hand column is where compliance projects go wrong. | **Requirement** | **What It Covers** | **Who Typically Owns It** | | --- | --- | --- | | **Signed BAA** | HIPAA duties allocated between the covered entity and cloud service provider | Provider offers; customer executes | | **Encryption at rest** | AES-256 encryption on volumes, snapshots, and backups | Provider | | **Encryption in transit** | TLS 1.2 or 1.3 for ePHI in motion, plus VPN for administrative access | Shared | | **Access controls** | Unique user IDs, role-based permissions, and automatic logoff | Provider at the infrastructure layer; customer at the application layer | | **Multi-factor authentication** | MFA on administrative and remote access paths | Shared | | **Audit logging** | Retained access and administrative action records with traceability | Shared | | **Risk analysis** | Documented assessment under 45 CFR § 164.308(a)(1)(ii)(A) | Customer | | **Backup and disaster recovery** | On-site and off-site encrypted copies, with tested restore procedures | Provider | | **Breach notification** | Reporting breaches of unsecured PHI under 45 CFR § 164.410 | Provider notifies the customer; customer notifies individuals and HHS | | **Physical safeguards** | Facility access control, environmental protection, and media disposal | Provider | | **Workforce policies and training** | Sanctions, authorization, and termination workflows | Customer | A provider can take eight of those eleven rows. The other three stay with the covered entity, whichever cloud it picks. Providers that publish their own version of this split, mapping each of the HIPAA requirements to a named owner, make the customer’s risk analysis a great deal shorter. ## The HIPAA Privacy Rule, Security Rule, and Breach Notification Rule HIPAA compliance rests on several rules working together. The HIPAA Privacy Rule governs how protected health information (PHI) may be used and disclosed. The HIPAA Security Rule sets the administrative, physical, and technical safeguards for ePHI. The Breach Notification Rule defines what has to be reported, to whom, and how quickly. The HITECH Act extended enforcement to business associates directly and raised the penalty tiers, which reach into the millions per violation category per year. Named OCR settlements give the range: $100,000 against Phoenix Cardiac Surgery, $2.7 million against Oregon Health & Science University. One point worth watching through 2026. HHS published a Notice of Proposed Rulemaking on January 6, 2025, that would make encryption of ePHI at rest and in transit a required specification, removing today’s “addressable” flexibility. It remains proposed, and HHS has moved the amendments to the long-term section of its regulatory agenda with final action projected for July 2027. Encryption is still addressable, which has always meant “do it, or document a defensible reason why not.” ## Public or Private Cloud for HIPAA Compliance? Both work. HHS permits any configuration provided a BAA is in place, so the choice changes the risk analysis and not the legality. Public cloud puts ePHI on shared, multi-tenant hardware with logical isolation between customers, and it provisions faster and costs less at small scale. Private cloud gives a single-tenant environment on dedicated hosts, which shortens the risk analysis because the tenancy question disappears. Hybrid deployments keep an EHR database on private infrastructure and run a patient-facing web tier in public cloud. Atlantic.Net’s[HIPAA-Compliant Cloud Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) is engineered for HIPAA in either configuration, including private dedicated hosts for customers whose auditor pushes them that way. ## What a BAA Actually Does The BAA converts a hosting relationship into a HIPAA one. It names the permitted uses and disclosures of protected health information (PHI), requires the business associate to apply the Security Rule safeguards, obliges it to report breaches and security incidents, flows the same duties down to subcontractors, and sets out what happens to the data when the contract ends. HHS takes an expansive view of who needs one. A cloud service provider storing only encrypted ePHI and holding no decryption key is still a business associate, because lacking an encryption key “does not exempt a CSP from business associate status and obligations under the HIPAA Rules.” The industry calls this a no-view service. It reduces what the provider can see. It does not reduce what the provider is liable for. Under HITECH, business associates carry the Security Rule duties directly, so a hosting provider answers to OCR for its own safeguards as well as to the covered entities it serves. Atlantic.Net includes a legally binding BAA as standard with every HIPAA hosting plan, across Linux and Windows and across the Fortress Developer, Business, DR, and Custom tiers. ## HIPAA-Compliant Cloud Storage as Part of a HIPAA Cloud Compute attracts most of the attention in a HIPAA project, but most protected health information (PHI) in a cloud environment is sitting still, in database files, object stores, snapshots, log archives, and backup sets. HIPAA-compliant cloud storage has to satisfy the same HIPAA requirements as the instance reading from it. When it fails, it fails for dull reasons: a bucket left open, a snapshot copied into an unencrypted region, a backup product with no BAA behind it. Secure cloud storage starts from the assumption that every object holding ePHI is one misconfiguration away from the wrong person. Three storage layers appear in almost every healthcare deployment. - **Block storage.** The volumes attached to instances, holding databases and application state. Encrypted at rest, snapshotted on a schedule, and governed by access controls at the hypervisor and inside the guest operating system. - **Object storage.** Where imaging studies, exported reports, and document archives land. Secure cloud storage at this layer means private by default, authenticated access only, and audit logs covering every read, write, and permission change. - **Backup and archive storage.** Encrypted onsite and offsite copies of the first two, with their own key material and a restore that has actually been tested. The BAA has to reach all three. A cloud service provider that signs a BAA for compute while excluding its cloud storage product leaves ePHI outside the agreement, and HHS treats storage providers as business associates for the data they hold. Business associates cannot narrow the HIPAA Rules by narrowing a contract. Hyperscalers handle this by publishing a covered-services list. Google Cloud signs a BAA and names the products it covers,[Cloud Storage among them](https://cloud.google.com/security/compliance/hipaa), while stating that “the customer is responsible for ensuring that the environment and applications that they build on top of Google Cloud are properly configured and secured according to HIPAA requirements.” Google Cloud secures the platform, and covered entities configure identity, encryption, and audit logs correctly on top of it. Enabling a service outside that list, or writing PHI into object metadata or build logs, moves data beyond the BAA with no warning. ### Retention, Disposal, and Audit Trails for Stored ePHI Retention is two questions. HIPAA requires policies, procedures, and required documentation to be kept for six years from creation or last effective date under 45 CFR § 164.316(b)(2)(i). How long the medical records themselves have to be kept is state law, commonly six to ten years, and that is the clock that drives cloud storage capacity planning. Disposal is where cloud storage differs from a filing cabinet. The device and media controls standard at 45 CFR § 164.310(d)(2)(i) requires a documented method for disposing of ePHI and the media holding it. In cloud storage that means knowing what happens when a volume is destroyed, whether snapshots and replicas go with it, and how the cloud service provider retires failed disks. Encrypting at rest and destroying the key is the workable answer, because ciphertext nobody can read is not unsecured PHI. Audit trails tie the layers together. Storage audit logs should record who touched which object, when, from where, and what changed. Auditors ask for a year of operating evidence, so audit trails that roll off after 30 days answer a question nobody asked. On Atlantic.Net, HIPAA-compliant cloud storage sits inside the same audited environment as the compute: encrypted volumes, Veeam-managed onsite and offsite backups replicated across regions, geographic redundancy, and data mirroring, all under the same BAA that covers the servers. Secure cloud storage is as much a configuration outcome as a product choice, so data security here is a review discipline: check bucket permissions, volume encryption settings, and retention periods before each annual audit and not during it. ## Encryption Standards for HIPAA-Compliant Cloud Storage Data at rest should be encrypted with AES-256. Data in transit should move over TLS 1.2 or 1.3. Backups need their own encryption and ideally their own key material, so a compromise of the production keys does not hand over the archive as well. The underlying detail matters more than the headline number. HIPAA-compliant cloud storage on Atlantic.Net uses LUKS with the aes-xts-plain64 cipher mode and a 512-bit key split into two 256-bit halves, one for the cipher and one for the XTS tweak. That is an AES-256 deployment described accurately, which is easier to verify than a claim about bank-grade encryption. Key management is the part that breaks at scale. Atlantic.Net rotates the key-encryption key every three months, retains former KEK sets for decryption while only the active set encrypts, governs access to each key through a control list restricted to authenticated users and services, and logs every request. Three-month rotation is an operational standard, not a HIPAA requirement. The Security Rule says nothing about intervals, only that safeguards be reasonable and appropriate. ## Data Security and Access Controls for HIPAA Compliance The security layer on Atlantic.Net[HIPAA web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) starts with a fully managed FortiGate firewall and an intrusion prevention service. The IPS matches live traffic against a continually revised threat database and blocks known attack signatures, while the firewall controls the perimeter. Atlantic.Net engineers own the monitoring, tuning, and patching of both, which removes a standing source of risk and staff hours from healthcare organizations. Around that sit the data security controls a HIPAA audit asks about directly: - **Managed encrypted VPN.** Five accounts as standard, so administrative traffic to servers holding PHI never crosses the public internet unprotected. - **Multi-factor authentication and role-based access controls.** Unique user identification with least-privilege roles, which is where the Security Rule’s access controls standard lands in practice. - **Trend Micro Deep Security Suite.** Anti-malware, virtual patching, and host intrusion detection on Fortress Business tiers and above. - **Bi-weekly vulnerability scanning and file integrity monitoring.** Scheduled and evidenced, ready when an auditor asks for a year of operating evidence. - **Detailed access and admin action logging.** Audit trails that separate suspecting a breach from being able to characterize one. - **Onsite and offsite encrypted daily backups.** Veeam-managed, replicated across regions, with file-level and full-system restore. Customers can manage their own host servers or hand that to Atlantic.Net engineers. Either way the firewall, IPS, and network layer stay managed, so the data security and access controls at the infrastructure layer sit with the same team whichever option a customer picks. That keeps the shared-responsibility line short to explain to an auditor. ## HIPAA-Compliant, Access-Controlled Hosting and Physical Security Storing files in a HIPAA-compliant manner means showing how the environment satisfies each safeguard. Atlantic.Net’s infrastructure is independently audited for HIPAA and HITECH and holds SOC 2 Type II, SOC 3 Type II, and SSAE 18 attestations from a third-party CPA firm. Physical safeguards are the ones customers see least and auditors check hardest. In the Orlando data center that includes biometric palm scanners and proximity card readers at access points, a man-trap entry vestibule, closed-circuit television with 24-hour recording and 30-day retention, and VESDA air-sampling fire detection. No document review confirms that a palm scanner works. Someone has to stand in front of it. The Service Level Agreement carries compliance weight of its own. HHS guidance points to the SLA for backup and disaster recovery, availability, limitations on use and disclosure, data return at contract end, and adherence to the[Security Rule](https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html) safeguards. ## Benefits of HIPAA Cloud Computing Healthcare’s move to cloud infrastructure is well past the pilot stage. MarketsandMarkets values the[healthcare cloud computing market](https://www.marketsandmarkets.com/Market-Reports/cloud-computing-healthcare-market-347.html) at USD 74.02 billion in 2026, forecast to reach USD 169.34 billion by 2031 at an 18.0% compound annual growth rate, with North America holding 45.4% of the market in 2026. A worked example shows why. A telehealth platform running a Node.js API, a PostgreSQL database of consultation records, and a Redis session store does not need a rack. It needs one properly sized compliant instance. Atlantic.Net’s Fortress Developer tier provides 6 vCPU, 16 GB RAM, 200 GB SSD, and 10 TB of transfer on a 12-month term at $492.31 per month for Linux, with the BAA, managed firewall, VPN, and backups included. Fortress Business at $644.16 adds IPS and Trend Micro Deep Security Suite. Migration includes four hours of assistance, additional hours at $160 per hour. That is a useful starting point for budgeting, but sizing still needs checking against real workload data. An instance that runs out of memory during a Monday morning appointment rush creates an availability problem no SLA can solve. ## Atlantic.Net as a HIPAA Cloud Provider Atlantic.Net has hosted regulated workloads since 1994 and runs eight data center regions across New York, Ashburn, Orlando, Dallas, San Francisco, Toronto, London, and Singapore. For healthcare customers the platform provides: - **Audited HIPAA and HITECH compliance.** Independent annual audit covering HIPAA AT-C 105/205, SOC 2 Type II, SOC 3 Type II, HITECH, and PCI DSS 4.0, with a BAA standard on every Fortress tier. - [**Fully managed security services**](https://www.atlantic.net/managed-services/)**and a**[**100% uptime SLA**](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/)**.** The SLA is backed separately across network, hardware replacement, and power and HVAC. - **US-based 24/7/365 support.** Certified engineers, English and Spanish, never outsourced. - **Recognition for healthcare cloud work.** Cyber Defense Magazine named Atlantic.Net a 2026 Global InfoSec Award winner in the Cutting Edge AI Healthcare Compliant Cloud category. [HIPAA-compliant cloud storage](https://www.atlantic.net/hipaa-compliant-hosting/) sits alongside the compute, covering geographic redundancy, backup and data mirroring, and deduplication. ## Frequently Asked Questions ### What Does HIPAA Require From a Hosting Provider Handling Protected Health Information? A hosting provider handling ePHI must sign a BAA and meet the Security Rule safeguards for the infrastructure it operates: encryption at rest and in transit, access controls with unique user identification, audit logging, integrity and transmission controls, physical safeguards at the facility, backup and disaster recovery, and breach reporting to the customer under 45 CFR § 164.410. Under HITECH, business associates are directly liable for those duties, separately from the contract. ### What Encryption Standards Are Required or Recommended for HIPAA-Compliant Hosting? HIPAA does not name a cipher. The accepted standards are AES-256 at rest and TLS 1.2 or 1.3 in transit, aligned with HHS guidance on rendering PHI unusable and unreadable, with backups separately encrypted. Encryption is currently addressable, so an organization may document an equivalent alternative, though the January 2025 proposed Security Rule update would make it required. ### What Is the Difference Between HIPAA-Eligible Hosting and Fully HIPAA-Compliant Hosting? HIPAA-eligible means the service can be used for ePHI if the customer configures it correctly and signs a BAA, which leaves the compliance work with the customer. Hyperscalers such as Google Cloud publish a list of HIPAA-eligible services, compute and cloud storage among them, that the customer must then assemble and secure. A fully HIPAA-compliant hosting environment arrives with the safeguards built and audited, operated by the provider. No hosting can be HIPAA-compliant: no such certification exists. ### What Is a BAA and Why Is It Required for HIPAA Hosting? A BAA is a contract between a covered entity and a business associate setting out how PHI may be used and disclosed, requiring Security Rule safeguards, mandating breach reporting, flowing obligations to subcontractors, and governing data return or destruction at termination. It is required because a cloud provider storing or processing ePHI meets the definition of a business associate, and HHS holds that this applies even when the provider stores only encrypted data and holds no decryption key. ### Public or Private Cloud for HIPAA Compliance? Either is permitted. HHS guidance allows public, private, or hybrid configurations provided a BAA is executed with the cloud service provider, so the configuration changes the risk analysis and not the legality. Private, single-tenant infrastructure removes multi-tenancy from the assessment. Public cloud provisions faster and costs less. Many covered entities split the two, keeping the primary database private and the web tier public. ### How Does Physical Data Center Security Factor Into HIPAA Compliance? The Security Rule’s physical safeguards apply to the building as well as the software, naming facility access controls, workstation security, and device and media controls. Atlantic.Net’s Orlando facility uses biometric palm scanners, proximity card readers, a man-trap vestibule, CCTV with 30-day retention, and VESDA fire detection, verified on site during the annual audit. ## Getting Started With HIPAA Cloud Hosting Atlantic.Net builds and operates HIPAA cloud environments for covered entities and business associates alike: healthcare providers, medical SaaS companies, telehealth platforms, and biotech research teams, with the BAA, the audited data security controls, and US-based engineering support included from day one. If you are scoping a move of ePHI into the cloud and want a clear picture of which safeguards Atlantic.Net operates and which stay with your team,[contact us](https://www.atlantic.net/about-us/corporate-contact/) to review your application stack, your compliance requirements, and where the shared-responsibility line falls. ### Read More About HIPAA Compliance - [HIPAA Compliance Checklist](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) - [How to Become HIPAA-compliant](https://www.atlantic.net/hipaa-compliant-hosting/how-to-become-hipaa-compliant/) - What Is the[HIPAA Security Rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/)? - Top Considerations for[HIPAA File Storage](https://www.atlantic.net/hipaa-compliant-hosting/top-10-considerations-for-hipaa-compliant-file-storage/) - [HIPAA Data Storage Requirements](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-cloud-storage/) - Protecting[e-PHI](https://www.atlantic.net/hipaa-compliant-hosting/protecting-phi-cloud/) in the Cloud - What Is[Healthcare Hosting](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/)? - [What Is PHI?](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) --- --- # Top 10 Healthcare Software Development Companies > URL: https://www.atlantic.net/hipaa-compliant-hosting/top-10-healthcare-software-development-companies/ | Published: 2024-07-28 | Updated: 2026-09-09 | Author: Dr. Rachael Bailey ## **What are Healthcare Software Development Companies?** With the global digital health market estimated to be worth around [$660 billion by 2025](https://www.statista.com/statistics/1092869/global-digital-health-market-size-forecast/#:~:text=Global%20digital%20health%20market%20size%202019%2D2025%20forecast&text=In%202019%2C%20the%20global%20digital,660%20billion%20dollars%20by%202025.), more and more businesses and organizations are turning to leading healthcare software development companies to engineer quality software that will streamline the delivery of their services. Healthcare software development covers many sectors of the growing healthcare industry, including primary and secondary care, financing, data management, appointment scheduling, clinical research, and the manufacture and supply of medical equipment. Whether you are part of a large healthcare organization seeking to design and implement a state-of-the-art healthcare app, or a small doctors’ practice looking to construct a simple billing and financing solution, there is a healthcare software development company to help you. ## **Top Healthcare Software Development Companies** Here, we collate the top 10 Healthcare Software Development Companies, considering their features, pricing structure, and experience in the industry. ## 1. [ScienceSoft](https://www.scnsoft.com/healthcare/software-development) In healthcare IT since 2005, ScienceSoft brings together time-proof reliability and innovation. Working with healthcare providers and medical software vendors around the globe, ScienceSoft offers medical software development services and has successfully completed over 100 projects.  ScienceSoft’s passionate teams successfully plan, build, and support award-winning medical solutions to help their customers meet their business goals and drive high ROI from their IT projects. Proficient in advanced techs like AI, ML, blockchain, and image analysis, ScienceSoft takes the lead both in innovative and process-oriented medical projects. Its customers point out that ScienceSoft’s teams are reliable, thorough, extremely good communicators, and very friendly.  ## 2. [**Technology Rivers**](https://technologyrivers.com) Technology Rivers is a Virginia based custom software development firm, that specializes in HIPAA compliant web and mobile app development. Technology Rivers work with healthcare entrepreneurs, startups, and health-tech organizations and help them in creating innovative healthcare solutions. Their work includes native and cross-platform hybrid mobile apps, web applications, desktop applications, and integrations with EMR & EHR such as EPIC. ## 3. ZDI ZDI is a leading New York-based digital marketing company and a proud partner of Atlantic.Net. With strong ties to HIPAA-compliant organizations, ZDI designs and delivers powerful digital branding and marketing solutions to healthcare clients. The services offered by ZDI include comprehensive digital marketing consultation, strategy, & analysis, SEO, SEM, UI/UX design, web development, print & packaging, and original film, video & photo content. ZDI won the GDUSA Health + Wellness Design award in 2017 and has created some excellent web applications for our clients. ## 4. Let’s Talk Interactive A leader within the telemedicine sector, Let’s Talk Interactive has delivered exciting solutions for healthcare businesses, both during and post-pandemic. With telehealth adoption soaring since the global pandemic limited face-to-face interactions, Let’s Talk Interactive is developing HIPAA-compliant, customized telehealth solutions to improve patient healthcare access. Their cutting-edge turnkey solutions include industry-leading virtual and walk-in clinic software, video conferencing & telemedicine software, live analytics, and [HIPAA-compliant website](https://www.atlantic.net/hipaa-compliant-hosting/how-to-make-website-hipaa-compliant/) development. ## 5. Arkenea Arkenea is an award-winning healthcare software development company that was founded in 2011. Arkenea is the only software development company fully dedicated to the healthcare industry, boasting over ten years of experience in this field. The company has been ranked among the top software development companies in the world by the industry research report “Global Intelligent Apps Market – Industry Trends and Forecast to 2026.” Arkenea helps healthcare companies to design and implement HIPAA- and HITRUST-compliant software solutions (both websites and mobile applications). ## 6. SNS System Inc. SNS System is a leading global provider of business consulting and IT services. The company specializes in developing quality client-server applications with user-friendly interfaces and boasts expertise in a wide range of the newest programming language tools and platforms designed for client-server applications. SNS System comprises a team of experienced developers, system administrators, and IT managers and uses only the latest, proven technology. ## 7. Codal With offices in the US, UK, and India, Codal is an award-winning and innovative company that delivers customized healthcare software solutions. Codal’s company approach is to provide innovative and modern solutions that can be continuously tested and improved until they are just right. Codal’s notable awards include an UpCity Local Excellence Award 2022, Expertise.com’s 2022 Best Web Developers in Chicago, and BigCommerce’s 2021 Partner of the Year. Codal’s vast portfolio of clients includes Samsung, Pepsi, Baxter, and Charles Schwab. ## 8. IT Craft With over 300 clients in 21 countries and over 20 years of experience, IT Craft is a trusted and valued healthcare software development company. Working with both big enterprises and small start-ups, IT Craft has had a successful role in helping businesses to grow and evolve. IT Craft builds web and mobile apps for doctors, patients, hospital administrations, and insurance companies alike. While IT Craft services may be more costly than some of their competitors, their satisfied customer base proves they offer value for money. ## 9. [Glorium Technologies](https://gloriumtech.com/healthcare/) Glorium Technologies is an established company that delivers software development services worldwide. As a full-cycle app & software development company, they are ready to provide their customers across the EU and North America with on-demand teams of software engineers, project managers, QA specialists, and other tech workforce. Product design, growth on demand, and investment strategy guidance are also listed as their top-provided services. Most of their clients are funded startups that work in the healthcare or real estate industry, but the company is not limited to these domains and has plenty of experience in other industries, i.e. fintech and eCommerce. Glorium Technologies has operated since 2010. The company has three ISO certificates: it is ISO-13485 certified for medical device development; has ISO-9001 certification for quality management; and ISO-27001 certification for information security standards. All the healthcare software is GDPR or HIPAA/HITRUST compliant (depending on the client’s territorial disposition). Glorium Technologies’ headquarters is located in New Jersey, and development centers are in Kyiv, Krakow, and Paphos.  ## 10. Appinventiv As an award-winning healthcare solutions provider with 7+ years of industry experience, Appinventiv has been delivering exceptional [healthcare software development services](https://appinventiv.com/healthcare-software-development/). The professionals of Appinventiv have created top-notch healthcare software solutions for the world’s leading health and fitness brands. The company aims to enable a faster ecosystem with its advanced healthcare applications that aim to streamline healthcare operations. From clinical management to effective patient treatment and diagnosis solutions, Appinventiv has worked with over 50 digital healthcare projects solving their greatest challenges. Their healthcare app development services digitize current administrative processes, improving efficiency and thereby lowering healthcare costs. ### Bonus: ## [RisingMax Inc.](https://risingmax.com/industries/healthcare-software-development-company) As a top-rated IT consulting company in NYC, RisingMax Inc. has been delivering high-end healthcare software development services to clients worldwide. Their healthcare experts understand the nitty-gritty of healthcare solutions and continuously improve and test software to deliver modern solutions. The company boasts expertise in bleeding-edge technologies such as AI, ML, IoT, and blockchain, integrating them to build custom healthcare solutions. Their team has successfully built HIPAA-compliant healthcare solutions that include electronic health record (EHR) software, hospital asset-tracking software, healthcare workforce management software, laboratory management systems, and telehealth and telemedicine software. The team strives to build healthcare apps that streamline operations, automate processes, and reduce costs, overheads, and other unnecessary expenses. The combination of all the above-mentioned parameters makes them a trusted custom healthcare software development company and a worthy contender for our list. ## **TATEEDA** TATEEDA is a San Diego healthcare software development company founded in 2013. The company helps U.S. healthcare providers, healthtech vendors, biotech firms, pharma businesses, and medical staffing organizations build HIPAA-compliant web, mobile, cloud, and AI-assisted software. TATEEDA’s work covers patient portals, EHR/EMR integrations, healthcare mobile apps, medical billing systems, remote patient monitoring solutions, pharma automation platforms, laboratory software, and secure API integrations. With 100+ senior engineers across the U.S., Eastern Europe, LATAM, and other delivery hubs, TATEEDA supports both full-cycle product development and the setup of dedicated engineering teams for regulated healthcare projects. ## FATbit Technologies FATbit Technologies is a leading [custom software development company](https://www.fatbit.com/) that delivers agile software development services in the healthcare and eCommerce domains. The company has dedicated teams of product managers, developers, and quality testers to provide startups and established businesses with software that meets their requirements. Apart from custom software development services, FATbit has in-house products that help businesses with online grocery marketplaces, food delivery, business consultation, equipment rental solutions, and so on. The products offered by the company are white-label and inclusive of payment gateway & popular marketing tool integrations. ## Light-it Light-it works with digital health startups, clinics, and MedTech companies to develop transformative web and mobile applications. Over the past 14 years, Light-it has delivered over 500 custom solutions to companies worldwide, specializing in the digital health space. According to Clutch, Light-it is one of the top software development agencies. The company offers web & app development, roadmap development, and UI/UX design, and maintains [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/), focusing on privacy, security, and scalability. ## Matellio Matellio is a leading software engineering studio offering end-to-end healthcare software development services to clients worldwide. With an experienced team and decades of expertise in [custom healthcare software development](https://www.matellio.com/solutions/healthcare-software-development/), the company has designed and delivered HIPAA-compliant healthcare solutions and mobile apps based on next-gen technologies such as AI, ML, and IoT. Some of their cutting-edge healthcare solutions include telehealth apps, patient monitoring software, EHR software, remote patient monitoring solutions, etc. Global Leaders like Clutch, App Futura, DesignRush, and Scrum Alliance, have acknowledged their abilities and knowledge. ## How Can Atlantic.Net Help? Spurred on by the global pandemic, healthcare businesses and organizations continue to embrace digital healthcare solutions. Healthcare companies must be supported by leading software development teams so that they can offer simple yet effective digital technologies to their employees and patients. Well-designed digital applications will help to streamline the delivery of healthcare services moving forwards. Are you a healthcare provider searching for a healthcare software developer to design and implement your latest digital solution? We have shortlisted our top healthcare software development companies to help you along the way. No matter which software solution you purchase, you must partner with a fully HIPAA-compliant hosting platform that prioritizes security, privacy, and compliance to host your application. Atlantic.Net has over 30 years of experience providing HIPAA-compliant hosting services to companies and organizations within the healthcare industry. Atlantic.Net can offer you cloud hosting solutions that are fully scalable and customizable to meet your organization’s needs. [Contact our sales team](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) today to learn how Atlantic.Net can help your organization. --- #### Read More About HIPAA IT Compliance - [HIPAA IT Compliance](https://www.atlantic.net/hipaa-data-centers/hipaa-compliant-it-infrastructure-guide/) Guide - Best [HIPAA Compliant Fax](https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-fax-services-in-2021/) Service - Best [HIPAA Compliant Email Service](https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-email-service-in-2021/) - Best [HIPAA Compliant VOIP](https://www.atlantic.net/hipaa-compliant-hosting/top-10-best-hipaa-compliant-voip-providers/) Service - Top Considerations for a [HIPAA-Compliant Database](https://www.atlantic.net/hipaa-compliant-hosting/top-10-considerations-for-a-hipaa-compliant-database/) - [What Is a BAA?](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) - [SSAE16, SAAE18, SOC1, SOC2](https://www.atlantic.net/hipaa-compliant-hosting/ssae-16-soc-1-soc2-care/) – Why You Should Care - Best [HIPAA Consulting](https://www.atlantic.net/hipaa-compliant-hosting/top-10-hipaa-consulting-companies-in-2020/) Companies - Is It [HIPPA or HIPAA?](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-vs-hippa/) --- --- # cPanel VPS Hosting with Simple Website and Server Management > URL: https://www.atlantic.net/vps-hosting/cpanel-vps-hosting/ | Updated: 2026-09-16 Deploy a cPanel and WHM-ready VPS in under 30 seconds with dedicated resources, full root access, enterprise-grade SSD storage, and 24/7 US-based support. - cPanel & WHM Ready - Full Root Access - 100% Uptime SLA - 24/7 US-Based Support One-Click Deployment: Under 30 sec Data Center Locations: 8 By integrating cPanel with the impressive power of a virtual private server from Atlantic.Net, we have created an efficient way to scale hosting solutions and manage individual servers from one user-friendly interface. Need more power? Perhaps you are a cPanel reseller: take a look at our dedicated server options for cPanel. ## What is cPanel VPS Hosting? cPanel is a leading web-based control panel that lets users manage all aspects of their website and creates valuable functionality by streamlining essential processes. It gives both technical and non-technical users a great platform to build and manage exciting websites and enterprise platforms. From adding subdomains and email accounts to installing scripts and checking bandwidth, the control and flexibility provided by cPanel are unsurpassed. The cPanel application is reliable and secure, its licensing costs are good value, and updates are released regularly. ## Linux VPS Hosting Pricing & Plans | | | | | | | | | --- | --- | --- | --- | --- | --- | --- | | General Purpose | G3.2GB | 2GB | 1 | 50GB | 3 TB | On-Demand: $10.0/mo $0.0149/hr; 1-Year: $9.0/mo $0.0134/hr; 3-Year: $8.0/mo $0.0119/hr | | General Purpose | G3.4GB | 4GB | 2 | 80GB | 5 TB | On-Demand: $20.0/mo $0.0298/hr; 1-Year: $18.0/mo $0.0268/hr; 3-Year: $17.0/mo $0.0253/hr | | General Purpose | G3.8GB | 8GB | 4 | 160GB | 6 TB | On-Demand: $40.0/mo $0.0595/hr; 1-Year: $37.0/mo $0.0551/hr; 3-Year: $34.0/mo $0.0506/hr | | General Purpose | G3.16GB | 16GB | 6 | 320GB | 7 TB | On-Demand: $80.0/mo $0.119/hr; 1-Year: $74.0/mo $0.1101/hr; 3-Year: $68.0/mo $0.1012/hr | | General Purpose | G3.32GB | 32GB | 8 | 640GB | 8 TB | On-Demand: $160.0/mo $0.2381/hr; 1-Year: $147.0/mo $0.2188/hr; 3-Year: $136.0/mo $0.2024/hr | | General Purpose | G3.48GB | 48GB | 12 | 960GB | 9 TB | On-Demand: $240.0/mo $0.3571/hr; 1-Year: $220.0/mo $0.3274/hr; 3-Year: $204.0/mo $0.3036/hr | | General Purpose | G3.64GB | 64GB | 16 | 1280GB | 10 TB | On-Demand: $320.0/mo $0.4762/hr; 1-Year: $294.0/mo $0.4375/hr; 3-Year: $272.0/mo $0.4048/hr | | General Purpose | G3.96GB | 96GB | 20 | 1920GB | 11 TB | On-Demand: $480.0/mo $0.7143/hr; 1-Year: $441.6/mo $0.6571/hr; 3-Year: $408.0/mo $0.6071/hr | | General Purpose | G3.128GB | 128GB | 24 | 2560GB | 12 TB | On-Demand: $640.0/mo $0.9524/hr; 1-Year: $589.0/mo $0.8765/hr; 3-Year: $544.0/mo $0.8095/hr | | General Purpose | G3.192GB | 192GB | 32 | 3840GB | 13 TB | On-Demand: $960.0/mo $1.4286/hr; 1-Year: $883.2/mo $1.3143/hr; 3-Year: $816.0/mo $1.2143/hr | | Storage Optimized | S2.16GB | 16GB | 2 | 500GB | 10 TB | On-Demand: $248.0/mo $0.369/hr; 1-Year: $161.0/mo $0.2396/hr; 3-Year: $105.0/mo $0.1563/hr | | Storage Optimized | S2.32GB | 32GB | 4 | 1TB | 10 TB | On-Demand: $425.0/mo $0.6324/hr; 1-Year: $276.0/mo $0.4107/hr; 3-Year: $180.0/mo $0.2679/hr | | Storage Optimized | S2.64GB | 64GB | 8 | 2TB | 10 TB | On-Demand: $778.0/mo $1.1577/hr; 1-Year: $506.0/mo $0.753/hr; 3-Year: $330.0/mo $0.4911/hr | | Storage Optimized | S2.96GB | 96GB | 12 | 3TB | 10 TB | On-Demand: $1,097.0/mo $1.6324/hr; 1-Year: $713.0/mo $1.061/hr; 3-Year: $465.0/mo $0.692/hr | | Storage Optimized | S2.128GB | 128GB | 16 | 4TB | 10 TB | On-Demand: $1,414.0/mo $2.1042/hr; 1-Year: $919.0/mo $1.3676/hr; 3-Year: $599.0/mo $0.8914/hr | | Memory Optimized | M2.16GB | 16GB | 2 | 40GB | 10 TB | On-Demand: $163.0/mo $0.2426/hr; 1-Year: $106.0/mo $0.1577/hr; 3-Year: $52.0/mo $0.0774/hr | | Memory Optimized | M2.32GB | 32GB | 4 | 80GB | 10 TB | On-Demand: $318.0/mo $0.4732/hr; 1-Year: $207.0/mo $0.308/hr; 3-Year: $101.0/mo $0.1503/hr | | Memory Optimized | M2.64GB | 64GB | 8 | 160GB | 10 TB | On-Demand: $630.0/mo $0.9375/hr; 1-Year: $409.0/mo $0.6086/hr; 3-Year: $200.0/mo $0.2976/hr | | Memory Optimized | M2.128GB | 128GB | 16 | 350GB | 10 TB | On-Demand: $1,246.0/mo $1.8542/hr; 1-Year: $810.0/mo $1.2054/hr; 3-Year: $396.0/mo $0.5893/hr | | Compute Optimized | C2.8GB | 8GB | 4 | 40GB | 10 TB | On-Demand: $211.0/mo $0.314/hr; 1-Year: $137.0/mo $0.2039/hr; 3-Year: $67.0/mo $0.0997/hr | | Compute Optimized | C2.16GB | 16GB | 8 | 80GB | 10 TB | On-Demand: $418.0/mo $0.622/hr; 1-Year: $271.0/mo $0.4033/hr; 3-Year: $133.0/mo $0.1979/hr | | Compute Optimized | C2.32GB | 32GB | 16 | 160GB | 10 TB | On-Demand: $828.0/mo $1.2321/hr; 1-Year: $538.0/mo $0.8006/hr; 3-Year: $263.0/mo $0.3914/hr | | Compute Optimized | C2.64GB | 64GB | 20 | 350GB | 10 TB | On-Demand: $1,451.0/mo $2.1592/hr; 1-Year: $943.0/mo $1.4033/hr; 3-Year: $461.0/mo $0.686/hr | *All plans are available in every location for Managed Server clients. *The hourly rate is determined by dividing the monthly rate by 672 hours (28 days). If your server is online for more than 672 hours in a calendar month, you will only be billed the monthly rate. *Prices listed above are based on the service being utilized for the period specified. *All Servers include one IPv4 Address. Additional IPs are available for $3.65/month ($0.005431/hour) *Unlimited inbound bandwidth. If free outbound bandwidth is exceeded, each additional GB is $0.02 *Optional Daily Backups are available for 20% of the server price. Minimum $1.00/month. *cPanel licensing cost starts at $23 per month ## All cPanel VPS Plans Are Equipped with Cloud Features cPanel/WHM is available on Atlantic.Net's VPS in the Cloud, which makes web hosting and managing individual servers both easy and effective. With Atlantic.Net's world-class hosting service, users can provision cPanel/WHM-ready VPS in seconds, as opposed to the 60 to 90 minutes required for self-installation or on-site physical or off-site dedicated servers. ## #1: Intuitive Website Management (cPanel) User-friendly interface: cPanel is user-friendly and has thorough official documentation. The graphical interface makes it simple for non-technical users to manage websites, email, domains, and other aspects of their hosting environment. Domain management: cPanel allows you to easily add, remove, and manage domains and subdomains, as well as configure DNS settings and email routing. Some of the advanced features include: - Addon domains: host multiple websites on a single cPanel account. - Subdomains: create sub-sections of your main domain. - Parked domains: point additional domains to your primary website. - Redirects: set up 301 (permanent) or 302 (temporary) redirects. - Aliases: create alternative domain names for your website. - DNS Zone Editor: manage DNS records (A, CNAME, MX, etc.) for your domains. - Email routing: configure email forwarding for specific domains or addresses. Email management: create and manage email accounts, set up email forwarding, autoresponders, spam filters, and access webmail directly from cPanel. Some of the advanced features include: - Email account creation & management: easily create, modify, and delete email addresses associated with your domains, including forwarding and auto-responses. - Webmail clients: access your emails directly through a web browser using popular clients like Roundcube or Horde. - Email filtering: create filters to organise incoming emails based on sender, subject, or content, allowing for automatic sorting or deletion of spam. - Spam protection: implement spam filtering tools (SpamAssassin) to reduce the amount of unwanted mail. - Mailing lists: manage email lists to send announcements or newsletters to groups of subscribers. - Email authentication: configure SPF, DKIM, and DMARC records to improve email deliverability and reduce the risk of spoofing. - Email delivery routes: customise how emails are sent from your server. - Email disk usage: monitor the storage space used by email accounts and messages. ### File Management cPanel's file manager provides a convenient way to upload, download, edit, and delete files and folders on your server without needing FTP software. ### Database Management Easily create and manage MySQL and PostgreSQL databases through phpMyAdmin or phpPgAdmin, a user-friendly web-based tool. ### Security Features cPanel includes tools for managing SSL certificates, password-protecting directories, blocking IP addresses, and configuring two-factor authentication. Some of the advanced security features include: - File and directory protection - Email security - SSL/TLS - IP blocker - Two-factor authentication (MFA) - ModSecurity WAF ### Software Installation cPanel integrates with Softaculous, a popular auto-installer that lets you install hundreds of applications, including WordPress, Joomla, and Drupal, with just a few clicks. ### Backup and Restore cPanel makes it easy to create full or partial backups of your website and restore them if needed, protecting your data from accidental loss or corruption. ### Metrics and Analytics cPanel provides tools for monitoring website traffic, visitor statistics, disk space usage, bandwidth usage, and other essential metrics. ### Server Configuration cPanel allows you to customise server settings, manage cron jobs, configure error pages, and access server logs for troubleshooting. Some of the advanced server configuration features include: - Easy-to-use update features - Service Manager - Time server settings - Network configuration ## #2: Efficient Server Administration (WHM) Multiple cPanel accounts: easily manage and provision multiple cPanel accounts for clients or users. Server configuration: customise server settings, manage cron jobs, configure error pages, and access server logs. ## #3: Atlantic.Net cPanel VPS Hosting Advantages Beyond cPanel & WHM, our VPS hosting solutions offer: ### Operating System Choice Our one-click cPanel image is built on AlmaLinux, an enterprise-grade server OS and a stable Linux distribution with regular releases and a long support window. Alternatively, you can build your own cPanel configuration and select your preferred operating system from the variety of Linux distributions optimised for cPanel. ### Full Root Access With root access, you can take full control of your VPS server environment. You can install custom software, configure settings, and optimise performance according to your specific needs. ### [100% Uptime SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/) We support the reliability of our VPS hosting infrastructure with a 100% uptime service level agreement. ### NVMe SSD Storage With our dedicated servers, you can experience exceptional disk performance with enterprise-grade NVMe SSD storage. Standard VPS also features enterprise-grade SSD storage as standard. ### Multiple Data Center Locations Choose the data center closest to your target audience to minimise latency and optimise website performance. ### Developer-Friendly Our cPanel VPS hosting plans are designed for web developers who need a flexible and reliable hosting environment. ### Rapid Deployment Launch your cPanel VPS hosting plan in minutes: - One-click application launch in under 30 seconds - Dedicated server deployment ## Additional Benefits - Managed VPS hosting options for hassle-free server maintenance. - Unlimited bandwidth and DDoS protection for optimal performance and security. - Scalable VPS plans to accommodate your growing needs. - Access to dedicated resources on a virtual machine for enhanced performance. - 24/7 support from experienced engineers. ## cPanel Licenses We offer fantastic discounts on cPanel licenses. You can purchase from 5 to 500 licenses for the cPanel hosting solution at a greatly reduced rate: the more licenses you buy, the cheaper the licenses become. ## cPanel Dedicated Server Hosting Need more power? Look no further than our dedicated powerhouse servers. Unable to find what you need? Reach out to our [sales team](https://www.atlantic.net/about-us/corporate-contact/); they will be available to help and discuss your options. ## Why Choose Atlantic.Net's cPanel Virtual Private Server Hosting? ### Total Control, Simplified cPanel's user-friendly hosting control panel makes managing your virtual private server (VPS) environment effortless. Combine it with the Atlantic.Net Control Panel to manage your cPanel instances and delegate tasks to individual team members using Atlantic.Net Teams collaboration features. ### Optimized for Performance The Atlantic.Net VPS infrastructure runs on Supermicro servers, all with class-leading, multicore Intel Xeon CPUs. Every server and attached storage runs on SSD or faster technology. The robust VPS hardware and cPanel's efficient resource management help keep your websites loading quickly and reliably. ### Scalable to Your Needs Your online presence is dynamic. Our cPanel VPS solutions are designed to scale alongside your growth. Easily upgrade CPU, RAM, or SSD storage to adapt to increased traffic or resource-intensive applications, making our managed VPS plans suitable for businesses of all sizes. ### Security Is Critical Both cPanel and Atlantic.Net prioritise the security of your data and applications. The Atlantic.Net platform is built from the ground up to be a security-defined infrastructure. Atlantic.Net further strengthens cPanel's robust security with managed security features like dynamic web application firewalls, intrusion-prevention systems, spam filters, DDoS protection, and SSL certificate management. To safeguard your inventory, we adhere to stringent security protocols within our secure data centers, including SOC 2, SOC 3, PCI, and HIPAA. ### Expert Support, Around the Clock Our experienced US-based support team is available 24/7 to assist you with any technical questions or concerns related to your hosting account or VPS platform. ## Additional Benefits of Atlantic.Net's cPanel VPS Hosting - Install cPanel effortlessly with our one-click applications. - Choose from a wide range of high-performance cloud VPS servers. - Enjoy the flexibility of a dedicated environment with dedicated resources. - Select your preferred server location in the United States, Canada, Europe, or Asia. - Benefit from our extensive experience as a reliable hosting provider. ## Who Benefits from cPanel VPS Hosting? Our cPanel customers range from individual users to enterprise clients to large-scale resellers. The cPanel web hosting control panel is suitable for everyone: ### Small to Medium Businesses cPanel VPS provides the resources and scalability needed for growing businesses without the need for a dedicated server. When your needs change, we have the dedicated infrastructure available. ### Web Professionals Web developers, designers, and agencies can leverage cPanel VPS to host client websites, manage projects, and enhance collaboration. ### E-commerce Stores cPanel VPS's performance and security make it well suited for online stores. You can even install a store straight from the web interface, supporting a seamless shopping experience for customers. ## Frequently Asked Questions ### Can I upgrade my cPanel VPS plan later? Yes. You can seamlessly upgrade your cPanel VPS plan resources (CPU, RAM, disk space) at any time through your client dashboard. Unlike shared hosting, with a virtual server you have the flexibility to scale your hardware resources to accommodate growth. ### Is cPanel included in the price? cPanel & WHM is included with every cPanel VPS plan. We provision a valid cPanel Admin license for the lifetime of your VPS subscription. Licensing costs are clearly shown when you provision the VPS. ### Do you offer managed cPanel VPS hosting? Yes. While our standard plans are self-managed, we offer various managed services add-ons that cover everything from cPanel updates and security hardening to proactive server monitoring and issue resolution. See our [managed services](https://www.atlantic.net/managed-services/). ### What is your uptime guarantee? Atlantic.Net offers a 100% uptime SLA on network and infrastructure for cPanel VPS plans. Your sites and applications stay accessible without the noisy-neighbour risk of shared hosting. ### How quickly can I get my cPanel VPS up and running? Our automated provisioning system deploys your cPanel VPS in under 30 seconds. All login details and URLs are displayed in the ACP control panel and emailed to you. ### What kind of support do you offer for cPanel VPS? 24/7 US-based technical support via email and phone. Our support team is available to assist with cPanel, your VPS platform, or optimising your hardware resources. ### Do you offer additional features with your cPanel VPS plans? Free Let's Encrypt SSL certificates bundled for all of your domains; automatic daily backups (enable in the ACP control panel); and a choice of 8 data center locations across the US, Canada, Europe, and Asia. ### What sets your VPS platform apart from other hosting providers? Competitive pricing, a wider range of managed-services options, current cPanel versions, and 24/7 support backed by a 30-year US-based hosting operation. ### Is a cPanel VPS the right choice for me if I'm currently on shared hosting? If you're outgrowing shared hosting (whether due to traffic, resource needs, or the desire for more control), a cPanel VPS is a strong next step. You get dedicated resources, improved performance, and the ability to customise your server environment. ## Read More About VPS Hosting ### [VPS Hosting](https://www.atlantic.net/vps-hosting/) - [VPS Pricing](https://www.atlantic.net/vps-hosting/pricing/) - [Windows VPS Hosting](https://www.atlantic.net/vps-hosting/windows-vps-hosting/) - [Linux VPS Hosting](https://www.atlantic.net/vps-hosting/linux-vps-hosting/) - [What Is Web Server Hosting?](https://www.atlantic.net/dedicated-server-hosting/what-is-web-server-hosting/) - [WordPress VPS Hosting](https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/) --- # Using ChainML and Council-AI for Generative Applications > URL: https://www.atlantic.net/vps-hosting/using-chainml-and-council-ai-for-generative-applications/ | Published: 2024-07-31 | Updated: 2024-11-05 | Author: Richard Bailey This guide streamlines the setup and usage of ChainML and Council-ai for developing generative AI applications. This procedure was tested on the Atlantic.Net Cloud Platform,  using Ubuntu on a Cloud VPS with 32GB RAM. Council-AI is an open-source platform designed to rapidly develop and deploy customized generative AI applications. It utilizes teams of agents built in Python to achieve this. Council enhances AI development tools, providing greater control and management capabilities for AI agents. It allows users to build complex AI systems that behave consistently through its robust control features. ChainML is a deep learning framework for building and training deep learning models. It is built on top of TensorFlow and provides a number of features that make it easier to build and train deep learning models, such as automatic differentiation, eager execution, and a high-level API. In short, ChainML is a deep learning framework, while Council is an open-source platform for developing and deploying generative AI applications. In this procedure, we will be focusing on using Council-AI to create Chains. --- ## Create OpenAI API Key (Mandatory) To use this procedure, you will need a paid license to interact with the OpenAI API. You can also use AzureLLM or GoogleLLM, but again, a paid license is needed. If you already have your own **Project API key** you can skip this step. Otherwise, you must complete this step to integrate Council-AI with a Language Model. - Go to the OpenAI website and Create an Account (or log in if you already have one) [https://platform.openai.com/signup](https://platform.openai.com/signup) ![](https://www.atlantic.net/wp-content/uploads/2024/07/Create-OpenAI-Account.png) - Navigate to the Project API Keys Sections by clicking here: [https://platform.openai.com/api-keys](https://platform.openai.com/api-keys) - Click on Create New Secret Key ![](https://www.atlantic.net/wp-content/uploads/2024/07/API-Keys.png) - Follow the instructions and give your Key a Name and a Project. I will be using the default project in this example. ![](https://www.atlantic.net/wp-content/uploads/2024/07/Create-Secret-Key.png) - IMPORTANT: Make a note of your KEY. You will need it later. This is the only chance you get to save the key in its entirety. Click done when ready. ![](https://www.atlantic.net/wp-content/uploads/2024/07/Save-Your-Key.png) ![](https://www.atlantic.net/wp-content/uploads/2024/07/Key-Created.png) --- ## Part 1: Using Council-AI with Jupyter Notebooks on Ubuntu ### Prerequisites - **Ubuntu 22.04**: I will be using Ubuntu 22.04 throughout this demo. You can install your Ubuntu server in under 30 seconds from the Atlantic.Net Cloud Platform Console. - **Basic Python Knowledge**: Familiarity with Python and virtual environments is helpful. - **ChatGPT Pro Licence**: Recent changes from OpenAI mean that you need to have a paid account to use the OpenAI API (OpenAILLM) ### Step 1 – Install Python Jupyter Lab requires Python. You can install it using the following commands: ``` apt install python3 python3-pip -y ``` Next, install the Python virtual environment package. ``` pip install -U virtualenv ``` ### Step 2 – Install Jupyter Lab Now, install the Jupyter Lab using the pip command. ``` pip3 install jupyterlab ``` This command installs Jupyter Lab and its dependencies. Next, edit the .bashrc file. ``` nano ~/.bashrc ``` Define your Jupyter Lab path as shown below; simply add it to the bottom of the file: ``` export PATH=$PATH:~/.local/bin/ ``` Reload the changes using the following command. ``` source ~/.bashrc ``` Next, test run the Jupyter Lab locally using the following command to make sure everything starts. ``` jupyter lab --allow-root --ip=0.0.0.0 --no-browser ``` Check the output to make sure there are no errors. Upon success you will see the following output: ``` [C 2023-12-05 15:09:31.378 ServerApp] To access the server, open this file in a browser: http://ubuntu:8888/lab?token=aa67d76764b56c5558d876e56709be27446 http://127.0.0.1:8888/lab?token=aa67d76764b56c5558d876e56709be27446 ``` Press the CTRL+C to stop the server. ### Step 3 – Configure Jupyter Lab By default, Jupyter Lab doesn’t require a password to access the web interface. To secure Jupyter Lab, generate the Jupyter Lab configuration using the following command. ``` jupyter-lab --generate-config ``` Output: ``` Writing default config to: /root/.jupyter/jupyter_lab_config.py ``` Next, set the Jupyter Lab password. ``` jupyter-lab password ``` Set your password as shown below: ``` Enter password: Verify password: [JupyterPasswordApp] Wrote hashed password to /root/.jupyter/jupyter_server_config.json ``` You can verify your hashed password using the following command. ``` cat /root/.jupyter/jupyter_server_config.json ``` Output: ``` { "IdentityProvider": { "hashed_password": "argon2:$argon2id$v=19$m=10240,t=10,p=8$zf0ZE2UkNLJK39l8dfdgHA$0qIAAnKiX1EgzFBbo4yp8TgX/G5GrEsV29yjHVUDHiQ" } } ``` Make a note of this information, as you will need to add it to your config. Next, edit the Jupyter Lab configuration file. ``` nano /root/.jupyter/jupyter_lab_config.py ``` Define your server IP, hashed password, and other configurations as shown below: ``` c.ServerApp.ip = 'your-server-ip' c.ServerApp.open_browser = False c.ServerApp.password = 'argon2:$argon2id$v=19$m=10240,t=10,p=8$zf0ZE2UkNLJK39l8dfdgHA$0qIAAnKiX1EgzFBbo4yp8TgX/G5GrEsV29yjHVUDHiQ' c.ServerApp.port = 8888 ``` Make sure you format the file exactly as above. For example, the port number is not in brackets, and the False boolean must have a capital F. Save and close the file when you are done. ### Step 4 – Create a Systemctl Service File Next, create a systemd service file to manage the Jupyter Lab. ``` nano /etc/systemd/system/jupyter-lab.service ``` Add the following configuration: ``` [Service] Type=simple PIDFile=/run/jupyter.pid WorkingDirectory=/root/ ExecStart=/usr/local/bin/jupyter lab --config=/root/.jupyter/jupyter_lab_config.py --allow-root User=root Group=root Restart=always RestartSec=10 [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon. ``` systemctl daemon-reload ``` Next, start the Jupyter Lab service using the following command. ``` systemctl start jupyter-lab ``` You can now check the status of Jupyter Lab service using the following command. ``` systemctl status jupyter-lab ``` Jupyter Lab is now started and listening on port 8888. You can verify it with the following command. ``` ss -antpl | grep jupyter ``` Output: ``` LISTEN 0 128 104.219.55.40:8888 0.0.0.0:* users:(("jupyter-lab",pid=156299,fd=6)) ``` ### Step 5 – Access Jupyter Lab Now, open your web browser and access the Jupyter Lab web interface using the URL http://your-server-ip:8888. You will see the Jupyter Lab on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/07/Jupyter-Password.png) Provide the password you set during the installation and click on Log in. You will see Jupyter Lab dashboard on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2024/07/Jupyter-Lab-Dashboard.png) ### Step 6 – Start the Python3 Notebook and Run the following Code This part of the procedure uses examples provided by [ChainML](https://colab.research.google.com/drive/1XdC7mj_tfTkfbHEfcKDcfQIsvaDrpiG5?usp=sharing#scrollTo=Jx-Sksz7C-CL). This guide aims to transform your social media presence with an AI-powered marketing assistant! Share your post idea, and this tool will identify the perfect platform and generate tailored content for maximum impact. Whether you’re an influencer, marketer, or developer, this tutorial will showcase how Agents, Chains, and Skills can streamline your content creation process. using X (formerly Twitter), LinkedIn, or Discord. #### Install Council-AI ``` !pip install council-ai !pip install --upgrade jupyter ipywidgets ``` #### Import Modules ``` # Import required modules. This block imports all the required libraries for our project. # Each one serves a specific function in creating our Council AI agent. import dotenv import os import logging from council.chains import Chain from council.skills import LLMSkill from council.filters import BasicFilter from council.llm import OpenAILLM from council.controllers import LLMController from council.evaluators import LLMEvaluator from council.agents import Agent ``` #### Set Your OpenAI API KEY ``` # Setup environment variables dotenv.load_dotenv() os.environ['OPENAI_API_KEY'] = 'sk-None-123456789-123456789-123456789' os.environ['OPENAI_LLM_MODEL'] = 'gpt-3.5-turbo-0125' os.environ['OPENAI_LLM_TIMEOUT'] = '90' ``` #### Initialize the LLM ``` # Initialize OpenAI LLM (Large Language Model) # Here, we create an instance of OpenAILLM, which is a wrapper around the OpenAI language model, # configured based on our environment variables. openai_llm = OpenAILLM.from_env() ``` #### Create Your Chains ``` # Create the short content 'XorTwitter' Skill and Chain prompt_XorTwitter = "You are a social media influencer with millions of followers on Twitter because of your short humorous social media posts that always use emojis and relevant hash tags." XorTwitter_skill = LLMSkill(llm=openai_llm, system_prompt=prompt_XorTwitter) XorTwitter_chain = Chain(name="XorTwitter", description="Responds to a prompt, which is a short sarcastic and humorous post idea.", runners=[XorTwitter_skill]) # Create a professional content 'LinkedIn' Skill and Chain prompt_LinkedIn = "You are a social media influencer with millions of followers on LinkedIn because of your compelling short professional business posts that generate lots of engagement." LinkedIn_skill = LLMSkill(llm=openai_llm, system_prompt=prompt_LinkedIn) LinkedIn_chain = Chain(name="LinkedIn", description="Responds to a prompt, which is a post idea, written in formal businesss language using big words.", runners=[LinkedIn_skill]) # Create a longer 'Discord' Skill and Chain prompt_Discord = "You are a social media influencer with millions of followers on Discord because of your compelling short social media posts." Discord_skill = LLMSkill(llm=openai_llm, system_prompt=prompt_Discord) Discord_chain = Chain(name="Discord", description="Responds to a prompt, which is a post idea, as an expert Discord influencer and generates a Discord post.", runners=[Discord_skill]) ``` #### Create Controller & Evaluator ``` # Create Controller controller = LLMController(chains=[XorTwitter_chain, LinkedIn_chain, Discord_chain], llm=openai_llm, response_threshold=5) # Create Evaluator evaluator = LLMEvaluator(llm=openai_llm) # Create Filter filter = BasicFilter() ``` #### Create the Agent ``` # Create Agent agent = Agent(controller=controller, evaluator=evaluator, filter=filter) ``` #### Create a Context ``` result = agent.execute_from_user_message("Open Data Conference") #for message in result.messages: print("\n" + result.best_message.message) #OpenAI models may time-out due to high traffic, retry this step immediately or try this step later #for message in result.messages: print("\n" + result.best_message.message) ``` #### Examples Here are some example inputs to invoke the 3 different chains: - For the ‘XorTwitter’ Skill: Prompt: “What is the sum of two and three” - For the ‘LinkedIn’ Skill: Prompt: “Job Search” - For the ‘Discord’ Skill: Prompt: “Game Night Announcement” Try the same questions in ChatGPT directly and note the different responses. Now try your own input text. --- ## Part 2: Using Council-AI Direct From the Ubuntu Console ### Prerequisites - **Ubuntu 22.04**: Ensure you have Ubuntu 22.04 installed. You can quickly set up an Ubuntu server using cloud platforms like Atlantic.Net. - **Basic Python Knowledge**: Familiarity with Python and virtual environments is helpful. - **ChatGPT Pro Licence**: Recent changes from OpenAI mean that you need to have a paid account to use the OpenAI API (OpenAILLM) ### Step 1 Update OS and Install Pre-Requisites I will be using Ubuntu 22.04 throughout this demo. You can install your Ubuntu server in under 30 seconds from the Atlantic.Net Cloud Platform Console. Open a terminal and run: ``` apt-get update -y apt-get install python3 python3-pip git python3.10-venv python3-dotenv -y ``` **Explanation:** This command updates package lists and installs Python (version 3), pip (package manager), Git (version control), Python virtual environment tools, and dotenv (for managing environment variables) ### Step 2 – Create and Activate a Python Virtual Environment Using a Python virtual environment to run Council AI (or any Python project, really) is highly recommended. Virtual environments help to: - **Isolate Dependencies**: Each project gets its own set of packages, avoiding conflicts between different projects that might require different versions of the same libraries. - **Keep Your System Clean**: You won’t clutter your global Python installation with project-specific packages. - **Make Sharing and Deployment Easier**: Virtual environments create a self-contained setup for your project, making it easier to share with others or deploy. ``` python3 -m venv council-env source council-env/bin/activate ``` **Explanation**: - The first command creates a virtual environment named “council-env”. - The second command activates the virtual environment, isolating your project dependencies. ### Step 3 – Install Council AI using PyPi Install Council AI. ``` pip install council-ai ``` Wait for the installation to complete. Pip will download and install the Council AI package and its dependencies. Validate the installation by typing: ``` pip show council-ai ``` ### Step 4 – Set Up Your Local .env File **Create a .env File:** - In your project directory (or within your virtual environment), create a new file named .env. - Note: The .env file is a common way to store sensitive information like API keys. It is usually ignored by version control systems like Git to prevent accidental exposure. ``` nano .env ``` **Add Your API Key:** Open the .env file in a text editor and add the following line, replacing your_actual_openai_api_key with your actual key: ``` OPENAI_API_KEY=your_actual_openai_api_key ``` ### Step 5 – Start Council AI and Run Your First Chain All code must be executed inside a python script. If you run this against the shell it will simply error and not know what to do. First, create a blank python script: ``` nano council_script.py ``` Add the following script block: ``` from council.chains import Chain from council.skills import LLMSkill from council.llm import OpenAILLM import dotenv import os dotenv.load_dotenv() print(os.getenv("OPENAI_API_KEY", None) is not None) openai_llm = OpenAILLM.from_env() prompt = "You are responding to every prompt with a short poem titled hello world" hw_skill = LLMSkill(llm=openai_llm, system_prompt=prompt) hw_chain = Chain(name="Hello World", description="Answers with a poem titled Hello World", runners=[hw_skill]) prompt = "You are responding to every prompt with an emoji that best addresses the question asked or statement made" em_skill = LLMSkill(llm=openai_llm, system_prompt=prompt) em_chain = Chain(name="Emoji Agent", description="Responds to every prompt with an emoji that best fits the prompt", runners=[em_skill]) from council.controllers import LLMController controller = LLMController(chains=[hw_chain, em_chain], llm=openai_llm, response_threshold=5) from council.evaluators import LLMEvaluator evaluator = LLMEvaluator(llm=openai_llm) from council.filters import BasicFilter from council.agents import Agent agent = Agent(controller=controller, evaluator=evaluator, filter=BasicFilter()) result = agent.execute_from_user_message("hello world?!") print(result.best_message.message) result = agent.execute_from_user_message("Represent with emojis, council a multi-agent framework") print(result.best_message.message) ``` --- # How to Create a User and Add a Role in MongoDB > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-create-a-user-and-add-a-role-in-mongodb/ | Published: 2024-08-01 | Updated: 2024-08-17 | Author: Hitesh Jethva MongoDB, a popular NoSQL database, offers robust user management and role-based access control (RBAC) features to secure your data. Creating users and assigning roles in MongoDB helps in maintaining a secure environment by ensuring that only authorized individuals can access and manipulate the data. In this tutorial, we’ll walk through the steps to create a new user and assign roles to them. ## Step 1 – Connecting to MongoDB First, let’s connect to our MongoDB instance. Open your terminal and run the following command: ```bash mongo ``` You should see an output similar to this: ```bash > ``` ## Step 2 – Creating a New User MongoDB user management is typically performed in the admin database. Switch to the admin database by executing: ```bash use admin ``` Output: ```bash switched to db admin ``` Now, let’s create a new user. We’ll create a user named testUser with the password password123. This user will be assigned the readWrite role on a database called mydatabase. ```bash db.createUser({ user: "testUser", pwd: "password123", roles: [ { role: "readWrite", db: "mydatabase" } ] }) ``` Output: ```bash Successfully added user: { "user" : "testUser", "roles" : [ { "role" : "readWrite", "db" : "mydatabase" } ] } ``` **Explanation:** - **user:** The username for the new user. - **pwd:** The password for the new user. - **roles:** An array specifying the roles assigned to the user. Here, testUser is granted the readWrite role on the mydatabase database. ## Step 3 – Adding Additional Roles to a User If you need to add more roles to an existing user, you can use the updateUser command. Let’s add the dbAdmin role to testUser on mydatabase. ```bash db.updateUser("testUser", { roles: [ { role: "readWrite", db: "mydatabase" }, { role: "dbAdmin", db: "mydatabase" } ] }) ``` Output: ```bash Successfully updated user: { "user" : "testUser", "roles" : [ { "role" : "readWrite", "db" : "mydatabase" }, { "role" : "dbAdmin", "db" : "mydatabase" } ] } ``` In the command above, we updated testUser to have both readWrite and dbAdmin roles on the mydatabase database. ## Step 4 – Verifying User Roles Let’s verify the roles assigned to testUser. First, we need to authenticate as testUser. ```bash db.auth("testUser", "password123") ``` Output: ```bash 1 ``` A return value of 1 indicates successful authentication. Now, let’s check the roles assigned to testUser. Run the following command: ```bash db.runCommand({ usersInfo: "testUser" }) ``` Output. ```bash { "users" : [ { "_id" : "admin.testUser", "user" : "testUser", "db" : "admin", "roles" : [ { "role" : "readWrite", "db" : "mydatabase" }, { "role" : "dbAdmin", "db" : "mydatabase" } ] } ], "ok" : 1 } ``` The output shows the roles assigned to testUser, confirming that the user has both readWrite and dbAdmin roles on mydatabase. ## Conclusion In this article, we’ve walked through the steps to create a new user and assign roles in MongoDB. We started by connecting to the MongoDB instance, creating a user, and assigning initial roles. We then demonstrated how to update user roles and verify the roles assigned to the user. Try to deploy a MongoDB database and create a user on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Back Up and Restore a Database in MongoDB > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-back-up-and-restore-a-database-in-mongodb/ | Published: 2024-08-02 | Updated: 2024-08-17 | Author: Hitesh Jethva Backing up your database is essential to protect against data loss and ensure data integrity. Restoring a database from a backup allows you to recover your data in case of accidental deletion, corruption, or hardware failure. In this tutorial, we will cover how to back up and restore a MongoDB database. ## Backing Up a MongoDB Database The **mongodump** command is a utility provided by MongoDB that creates a database backup. It exports data from your MongoDB database into BSON files, which can be restored later. To perform a basic backup of your MongoDB database, open your terminal and run the following command: ```bash mongodump --db your_database_name --out /path/to/backup/directory ``` Here’s a breakdown of the command: - **–db your_database_name**: Specifies the name of the database you want to back up. - **–out /path/to/backup/directory**: Specifies the directory where the backup files will be stored. For example, to backup a database named tutorialDB to /tmp directory, run: ```bash mongodump --db tutorialDB --out /tmp/tutorialDB_backup ``` Output: ```bash 2024-07-15T12:29:20.438+0000 writing tutorialDB.products to /tmp/tutorialDB_backup/tutorialDB/products.bson 2024-07-15T12:29:20.439+0000 done dumping tutorialDB.products (1 document) 2024-07-15T12:29:20.442+0000 writing tutorialDB.users to /tmp/tutorialDB_backup/tutorialDB/users.bson 2024-07-15T12:29:20.443+0000 done dumping tutorialDB.users (1 document) ``` If your MongoDB instance is running on a non-default host or port, you can specify these using the **–host** and **–port** options: ```bash mongodump --host your_host --port your_port --db your_database_name --out /path/to/backup/directory ``` **Example:** ```bash mongodump --host localhost --port 27017 --db tutorialDB --out /tmp/tutorialDB_backup ``` If your MongoDB instance requires authentication, you can include the **–username** and **–password** options: ```bash mongodump --username your_username --password your_password --authenticationDatabase admin --db your_database_name --out /path/to/backup/directory ``` **Example:** ```bash mongodump --username admin --password secret --authenticationDatabase admin --db tutorialDB --out /tmp/tutorialDB_backup ``` ## Restoring a MongoDB Database The **mongorestore** command is a utility for restoring a MongoDB database from BSON files created by mongodump. To restore a MongoDB database, open your terminal and run the following command: ```bash mongorestore --db your_database_name /path/to/backup/directory/your_database_name ``` Here’s a breakdown of the command: - **–db your_database_name**: Specifies the database name to which you want to restore. - **/path/to/backup/directory/your_database_name**: Specifies the directory where the backup files are located. **Example:** ```bash mongorestore --db tutorialDB /tmp/tutorialDB_backup/tutorialDB ``` Output: ```bash 2024-07-15T12:35:23.456+0000 restoring tutorialDB.collection1 from /tmp/tutorialDB_backup/tutorialDB/collection1.bson 2024-07-15T12:35:23.456+0000 restoring tutorialDB.collection2 from /tmp/tutorialDB_backup/tutorialDB/collection2.bson Restore completed successfully. ``` If your MongoDB instance is running on a non-default host or port, you can specify these using the **–host** and **–port** options: ```bash mongorestore --host your_host --port your_port --db your_database_name /path/to/backup/directory/your_database_name ``` **Example:** ```bash mongorestore --host localhost --port 27017 --db tutorialDB /tmp/tutorialDB_backup/tutorialDB ``` If your MongoDB instance requires authentication, you can include the **–username** and **–password** options: ```bash mongorestore --username your_username --password your_password --authenticationDatabase admin --db your_database_name /path/to/backup/directory/your_database_name ``` **Example:** ```bash mongorestore --username admin --password secret --authenticationDatabase admin --db tutorialDB /tmp/tutorialDB_backup/tutorialDB ``` ## Conclusion In this article, we have covered the essential steps for backing up and restoring a MongoDB database using the **mongodump** and **mongorestore** commands. Regular backups are crucial for data integrity and security while knowing how to restore data ensures you can recover from any unforeseen data loss. You can now perform a MongoDB back up and restoration on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Delete a User and Database in MongoDB > URL: https://www.atlantic.net/vps-hosting/how-to-delete-a-user-and-database-in-mongodb/ | Published: 2024-08-05 | Updated: 2024-08-17 | Author: Hitesh Jethva Managing users and databases within MongoDB is critical to maintaining an organized and secure database environment. While adding users and creating databases are fundamental operations, there are times when you need to delete a user or an entire database. In this tutorial, we will walk through the steps to delete a user and a database in MongoDB. ## Deleting a User in MongoDB First, you need to connect to the MongoDB shell. Open your terminal or command prompt and type the following command: ```bash mongo ``` To manage users, you must switch to the admin database. The admin database is the default database for administrative tasks in MongoDB. Use the following command: ```bash use admin ``` If your MongoDB instance is running with authentication, you must authenticate as a user with administrative privileges. Run the following command, replacing and with your admin user’s credentials: ```bash db.auth('admin-user', 'password') ``` To delete a user, you can use the db.dropUser() method. Let’s say you want to delete a user named testUser. Use the following command: ```bash db.dropUser('testUser') ``` If the user is successfully deleted, you will see: ```bash { "ok" : 1 } ``` ## Deleting a Database in MongoDB If you have not already connected to MongoDB, open your terminal or command prompt and type: ```bash mongo ``` Before deleting a database, it’s a good idea to list all the databases to ensure you are deleting the correct one. Use the following command: ```bash show dbs ``` This command will list all databases: ```bash admin 0.000GB config 0.000GB local 0.000GB tutorialDB 0.000GB ``` Let’s say you want to delete a database named **tutorialDB.** Switch to the **tutorialDB** database using the following command: ```bash use tutorialDB ``` To delete the **tutorialDB** database, use the **db.dropDatabase()** method: ```bash db.dropDatabase() ``` If the database is successfully deleted, you will see: ```bash { "dropped" : "tutorialDB", "ok" : 1 } ``` ## Conclusion In this article, we covered how to delete a user and a database in MongoDB. We started by explaining how to connect to the MongoDB shell and switch to the admin database. Then, we demonstrated how to delete a user using the **db.dropUser()** method. Finally, we walked through the process of deleting a database with the db.dropDatabase() method. You can follow this guide to delete a MongoDB database and user on [VPS hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Create a Table/Collections in MongoDB > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-create-a-table-collections-in-mongodb/ | Published: 2024-08-06 | Updated: 2024-08-17 | Author: Hitesh Jethva Before diving into creating tables, it’s essential to understand what a collection is in MongoDB. A collection is a group of MongoDB documents, similar to a table in a relational database. Documents within a collection can have different fields, but typically, they share a similar purpose or structure. Collections do not enforce a schema, meaning each document can contain different fields and data types. In this tutorial, we’ll learn how to create a table in MongoDB. ## Step 1 – Connecting to MongoDB First, we need to connect to the MongoDB server. Open your terminal or command prompt and start the MongoDB shell by typing: ```bash mongo ``` You should see an output indicating that you are connected to the MongoDB server. ```bash > ``` ## Step 2 – Creating a Database Before creating a collection, we need a database. In MongoDB, databases are created dynamically. You can switch to a new or existing database using the use command. For this tutorial, we’ll create a new database called tutorialDB. ```bash use tutorialDB ``` The output will be: ```bash switched to db tutorialDB ``` ## Step 3 – Creating a Collection In MongoDB, collections are created implicitly when you insert data into them. However, you can also create a collection explicitly using the createCollection command. Let’s create a collection named users by inserting a document into it: ```bash db.users.insertOne({ name: "John Doe", email: "john.doe@example.com", age: 29 }) ``` This command creates a collection named users and inserts a document with the specified fields. ```bash { "acknowledged" : true, "insertedId" : ObjectId("669514de0bc92b8bfdbe553d") } ``` Alternatively, you can explicitly create a collection using the createCollection command: ```bash db.createCollection("products") ``` This command creates an empty collection named products. ```bash { "ok" : 1 } ``` ## Step 4 – Inserting Documents into a Collection Now that we have our collections, let’s insert more documents into them. To insert multiple documents into the users collection, use the insertMany command: ```bash db.users.insertMany([ { name: "Alice Smith", email: "alice.smith@example.com", age: 24 }, { name: "Bob Johnson", email: "bob.johnson@example.com", age: 35 }, { name: "Charlie Brown", email: "charlie.brown@example.com", age: 28 } ]) ``` Output. ```bash { "acknowledged" : true, "insertedIds" : [ ObjectId("669515120bc92b8bfdbe553e"), ObjectId("669515120bc92b8bfdbe553f"), ObjectId("669515120bc92b8bfdbe5540") ] } ``` To insert a single document into the products collection, use the insertOne command: ```bash db.products.insertOne({ productName: "Laptop", brand: "BrandX", price: 799 }) ``` The output will be: ```bash { "acknowledged" : true, "insertedId" : ObjectId("669515310bc92b8bfdbe5541") } ``` ## Step 5 – Querying Collections Once we have data in our collections, we can query it. Here are a few basic queries to get you started. To find all documents in a collection, use the find command: ```bash db.users.find().pretty() ``` Output: ```bash { "_id" : ObjectId("669514de0bc92b8bfdbe553d"), "name" : "John Doe", "email" : "john.doe@example.com", "age" : 29 } { "_id" : ObjectId("669515120bc92b8bfdbe553e"), "name" : "Alice Smith", "email" : "alice.smith@example.com", "age" : 24 } { "_id" : ObjectId("669515120bc92b8bfdbe553f"), "name" : "Bob Johnson", "email" : "bob.johnson@example.com", "age" : 35 } { "_id" : ObjectId("669515120bc92b8bfdbe5540"), "name" : "Charlie Brown", "email" : "charlie.brown@example.com", "age" : 28 } ``` The pretty method formats the output for readability. To find specific documents, pass a query document to the find command. For example, to find users who are 29 years old: ```bash db.users.find({ age: 29 }).pretty() ``` The output will be: ```bash { "_id" : ObjectId("669514de0bc92b8bfdbe553d"), "name" : "John Doe", "email" : "john.doe@example.com", "age" : 29 } ``` ## Step 6 – Updating Documents Updating documents in MongoDB is straightforward. Let’s see how to update a document’s field. To update a single document, use the updateOne command. For example, to update John Doe’s age: ```bash db.users.updateOne( { name: "John Doe" }, { $set: { age: 30 } } ) ``` To update multiple documents, use the updateMany command. For example, to set the verified field to true for all users: ```bash db.users.updateMany( {}, { $set: { verified: true } } ) ``` ## Step 7 – Deleting Documents You can also delete documents from a collection. To delete a single document, use the deleteOne command. For example, to delete Bob Johnson’s document: ```bash db.users.deleteOne({ name: "Bob Johnson" }) ``` To delete multiple documents, use the deleteMany command. For example, to delete all users who are younger than 30: ```bash db.users.deleteMany({ age: { $lt: 30 } }) ``` ## Conclusion In this article, we covered the basics of creating and managing collections (tables) in MongoDB. We learned how to connect to MongoDB, create a database, create collections implicitly and explicitly, insert documents, query data, update documents, and delete documents. Try to create a MongoDB table on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How To Run MongoDB as a Docker Container > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-run-mongodb-as-a-docker-container/ | Published: 2024-08-07 | Updated: 2024-08-17 | Author: Hitesh Jethva Docker is a popular containerization tool that simplifies managing applications and their dependencies. MongoDB is a widely used NoSQL database known for its flexibility and scalability. Combining Docker and MongoDB allows developers to set up and manage MongoDB instances in isolated environments quickly. This guide will walk you through creating a MongoDB Docker container, covering everything from pulling the MongoDB image to running the container and connecting to it. We’ll also provide practical examples to help you understand each step. ## Prerequisites Before we begin, ensure you have the following installed on your system: - Docker is installed and running on your server - Basic knowledge of Docker commands ## Step 1 – Pulling the MongoDB Docker Image The first step is to pull the official MongoDB image from Docker Hub. Open your terminal and run the following command: ```bash docker pull mongo:4.4 ``` This command downloads the latest MongoDB image. You can verify the MongoDB docker image using the following command. ```bash docker images ``` Output: ```bash REPOSITORY TAG IMAGE ID CREATED SIZE mongo 4.4 d896c071ac69 4 months ago 427MB ``` ## Step 2 – Running a MongoDB Container Once the image is downloaded, you can create and run a MongoDB container. Use the following command: ```bash docker run --name mongodb -d mongo:4.4 ``` Here’s a breakdown of the command: - **docker run:** Command to create and start a container. - **–name mongodb**: Names the container “MongoDB”. - **-d**: Runs the container in detached mode. - **mongo:4.4:** Specifies the image to use. You can verify that the container is running by using: ```bash docker ps ``` Output: ```bash CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 3dc272f119f5 mongo:4.4 "docker-entrypoint.s…" 3 seconds ago Up 2 seconds 27017/tcp mongodb ``` ## Step 3 – Connecting to the MongoDB Container You need to use a MongoDB client to connect to the MongoDB instance running in your Docker container. The MongoDB CLI client is included in the container, so you can connect using the following command: ```bash docker exec -it mongodb /bin/bash ``` This command opens an interactive MongoDB shell inside the running container. ```bash root@3dc272f119f5:/# ``` Run the following command to exit from the Mongodb container. ```bash exit ``` ## Step 4 – Persisting Data with Volumes By default, data stored in a Docker container is ephemeral. To persist data, you need to use Docker volumes. Create a directory on your host machine to store MongoDB data, then run the container with a volume: ```bash mkdir -p ~/mongo-data docker run --name mongodb-volume -v ~/mongo-data:/data/db -d mongo:4.4 ``` This command mounts the host directory ~/mongo-data to the container’s /data/db directory, ensuring data persistence. ## Step 5 – Configuring MongoDB with Environment Variables You can configure MongoDB using environment variables. For example, to set a root username and password, use the following command: ```bash docker run --name mongodb-env -e MONGO_INITDB_ROOT_USERNAME=admin -e MONGO_INITDB_ROOT_PASSWORD=secret -d mongo:4.4 ``` This command sets the root username to admin and the password to secret. ## Step 6 – Managing MongoDB Containers You can start, stop, and remove MongoDB containers using Docker commands: Stop the container: ```bash docker stop mongodb ``` Start the container: ```bash docker start mongodb ``` Remove the container: ```bash docker rm mongodb ``` ## Step 7 – Practical Example Let’s go through a practical example where we create a MongoDB container with data persistence and authentication. Before getting started, all existing MongoDB containers must be deleted. 1. Create a directory for MongoDB data and give proper permissions: ```bash mkdir -p ~/mongodb-data chmod -R 777 ~/mongodb-data ``` 2. Run the MongoDB container with volume and authentication: ```bash docker run --name mongodb-data -v ~/mongodb-data:/data/db -e MONGO_INITDB_ROOT_USERNAME=admin -e MONGO_INITDB_ROOT_PASSWORD=secret -d mongo:4.4 ``` 3. Connect to the MongoDB container: ```bash docker exec -it mongodb-data mongo -u admin -p secret --authenticationDatabase admin ``` This command connects to the MongoDB instance using the specified username and password. ```bash MongoDB shell version v4.4.29 connecting to: mongodb://127.0.0.1:27017/?authSource=admin&compressors=disabled&gssapiServiceName=mongodb Implicit session: session { "id" : UUID("b59b44c8-a977-4770-9b1e-0abfd0ce5c16") } MongoDB server version: 4.4.29 Welcome to the MongoDB shell. For interactive help, type "help". For more comprehensive documentation, see https://docs.mongodb.com/ Questions? Try the MongoDB Developer Community Forums https://community.mongodb.com --- The server generated these startup warnings when booting: 2024-07-15T15:26:54.439+00:00: Using the XFS filesystem is strongly recommended with the WiredTiger storage engine. See http://dochub.mongodb.org/core/prodnotes-filesystem --- > ``` 4. Create a new database and collection: ```bash use mydatabase db.createCollection("mycollection") ``` 5. Insert a document: ```bash db.mycollection.insert({ name: "example", type: "demo" }) ``` 6. Exit from the container: ```bash exit ``` 7. Stop and remove the container: ```bash docker stop mongodb-data docker rm mongodb-data ``` 8. Run the container again: ```bash docker run --name mongodb-data -v ~/mongodb-data:/data/db -e MONGO_INITDB_ROOT_USERNAME=admin -e MONGO_INITDB_ROOT_PASSWORD=secret -d mongo:4.4 ``` 9. Connect and verify the data: ```bash docker exec -it mongodb-data mongo -u admin -p secret --authenticationDatabase admin use mydatabase db.mycollection.find() ``` You should see the document you inserted earlier, confirming that data persistence is working. ```bash > db.mycollection.find() { "_id" : ObjectId("6695471d6ae167ad03dcadfd"), "name" : "example", "type" : "demo" } ``` ## Conclusion Creating a MongoDB Docker container is a straightforward process that provides a flexible and isolated environment for your database. By following this guide, you can set up a MongoDB container with data persistence and authentication, ensuring your data is secure and persistent across container restarts. You can now create a MongoDB docker container on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Create a PostgreSQL Docker Container > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-create-a-postgresql-docker-container/ | Published: 2024-08-08 | Updated: 2024-08-17 | Author: Hitesh Jethva Docker containers provide a convenient way to manage and deploy applications. PostgreSQL, a powerful open-source relational database system, can be run in a Docker container for easy development, testing, and deployment. This guide will show you how to set up and run a PostgreSQL Docker container. In this guide, we’ll walk through the steps to create a PostgreSQL Docker container. ## Prerequisites Before we begin, ensure you have the following: - Docker installed on your machine. - Basic knowledge of Docker commands and PostgreSQL. ## Step 1 – Pulling the PostgreSQL Docker Image First, let’s pull the official PostgreSQL Docker image from Docker Hub. Open your terminal and run the following command: ```bash docker pull postgres ``` This command will download the latest PostgreSQL image. If you need a specific version, you can specify it like this: ```bash docker pull postgres: ``` For example, to pull PostgreSQL 13, you would run: ```bash docker pull postgres:13 ``` ## Step 2 – Running a PostgreSQL Container Now that we have the PostgreSQL image, let’s run a container. We’ll run the container with some basic configurations such as setting the PostgreSQL password and mapping a port. ```bash docker run --name my_postgres -e POSTGRES_PASSWORD=mysecretpassword -d -p 5432:5432 postgres ``` **Explanation:** - **–name my_postgres:** Names the container my_postgres. - **-e POSTGRES_PASSWORD=mysecretpassword**: Sets the PostgreSQL password to mysecretpassword. - **-d:** Runs the container in detached mode. - **-p 5432:5432:** Maps port **5432** of the host to port **5432** of the container. - **postgres:** Uses the postgres image. To verify that the container is running, use: ```bash docker ps ``` Output: ```bash CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES f690208d6e8a postgres "docker-entrypoint.s…" 6 seconds ago Up 6 seconds 0.0.0.0:5432->5432/tcp, :::5432->5432/tcp my_postgres ``` ## Step 3 – Connecting to the PostgreSQL Container You can connect to the PostgreSQL database using the psql command-line tool or any PostgreSQL client like pgAdmin. For this example, we’ll use psql. First, enter the running container: ```bash docker exec -it my_postgres bash ``` Once inside the container, connect to PostgreSQL using: ```bash psql -U postgres ``` Once connected, you will see the following output: ```bash psql (16.3 (Debian 16.3-1.pgdg120+1)) Type "help" for help. postgres=# ``` To exit from the Postgres shell, run: ```bash exit ``` To exit from the container, run: ```bash exit ``` ## Step 4 – Managing the PostgreSQL Container To stop the PostgreSQL container, run: ```bash docker stop my_postgres ``` To start the PostgreSQL container again, run: ```bash docker start my_postgres ``` To remove the container, first stop it (if it’s running), and then remove it: ```bash docker rm my_postgres ``` ## Step 4 – Data Persistence By default, data inside a Docker container is ephemeral, meaning it will be lost when the container is removed. To persist data, you can use Docker volumes. Create a volume: ```bash docker volume create pgdata ``` Run the PostgreSQL container with the volume: ```bash docker run --name mynew_postgres -e POSTGRES_PASSWORD=mysecretpassword -d -p 5432:5432 -v pgdata:/var/lib/postgresql/data postgres ``` The **-v pgdata:/var/lib/postgresql/data** option mounts the volume to the PostgreSQL data directory. ## Conclusion In this guide, we’ve covered how to create and manage a PostgreSQL Docker container. We’ve walked through pulling the PostgreSQL image, running a container, connecting to it, and ensuring data persistence. Using Docker for PostgreSQL provides a flexible and efficient way to manage your databases, especially in development and testing environments. Let’s create a PostgreSQL docker container on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Create a Docker Container > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-create-a-docker-container/ | Published: 2024-08-09 | Updated: 2024-08-17 | Author: Hitesh Jethva Docker containers are lightweight, portable, and self-sufficient units that include everything needed to run a piece of software, including code, runtime, system tools, libraries, and settings. Containers are based on images, which are read-only templates specifying how the container should behave. In this tutorial, we will show you how to create a Docker container. ## Prerequisites - A server running Ubuntu with Docker installed. - A root user or a user with sudo privileges. ## Step 1 – Pulling a Docker Image To create a Docker container, start with a Docker image. You can either pull an existing image from Docker Hub or create your own. Let’s start by pulling an image. Let’s pull the Ubuntu image. ```bash docker pull ubuntu ``` This will download the Ubuntu image from the Docker Hub registry. ## Step 2 – Running a Docker Container Next, create and start a container from the pulled image. ```bash docker run -it --name my_ubuntu_container ubuntu ``` This command creates a container named **my_ubuntu_container** from the **Ubuntu** image and opens an interactive shell. ```bash root@68cf357568f9:/# ``` **Explanation**: - **-it:** Interactive terminal. - **–name:** Name of the container. - **ubuntu:** The Docker image to use. ## Step 3 – Interacting with a Docker Container Once inside the container, you can interact with it as you would with any other terminal. For example: ```bash apt update -y ``` This will update the package index in the Ubuntu container. To exit from the container, run: ```bash exit ``` ## Step 4 – Managing Docker Containers List all running containers: ```bash docker ps ``` List all containers including both start and stopped containers. ```bash docker ps -a ``` Stop a running container. ```bash docker stop my_ubuntu_container ``` Remove a stopped container. ```bash docker rm my_ubuntu_container ``` ## Conclusion Creating Docker containers is straightforward and highly beneficial for consistent application deployment. By following this guide, you now have the skills to create, manage, and customize Docker containers. Explore more by experimenting with different images and building your own to suit specific needs. Try to create a Docker container on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Docker Run Command with Examples > URL: https://www.atlantic.net/vps-hosting/docker-run-command-with-examples/ | Published: 2024-08-12 | Updated: 2024-08-17 | Author: Hitesh Jethva The Docker platform enables developers to build, deploy, and manage containerized applications. The docker run command is used to create and start a new container from a Docker image. It combines several functions in one command, such as creating a writable container layer over the specified image, configuring the container, and executing a specified command. In this guide, we’ll explore the docker run command in-depth, covering its options and providing practical examples to help you get started. ## Prerequisites - A server running Ubuntu with Docker installed. - A root user or a user with sudo privileges. ## Basic Syntax The basic syntax of the docker run command is: ```bash docker run [OPTIONS] IMAGE [COMMAND] [ARG...] ``` **Explanation:** - **OPTIONS:** Various flags to modify the behavior of the container. - **IMAGE:** The name of the Docker image you want to use. - **COMMAND:** The command to run inside the container (optional). - **ARG…:** Arguments to the command (optional). ## 1. Running a Container Interactively To run a container interactively, you can use the -it options. The **-i** flag keeps the container’s STDIN open, and the **-t** flag allocates a pseudo-TTY. This is useful for debugging or running shell sessions. ```bash docker run -it ubuntu /bin/bash ``` This command starts an interactive bash shell in an Ubuntu container. ## 2. Running a Container in the Background To run a container in the background (detached mode), use the **-d** option. This is useful for running services or applications. ```bash docker run -d nginx ``` This command starts an Nginx web server container in the background. You can verify it using the following command: ```bash docker ps ``` Output: ```bash CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES c187638e79a3 nginx "/docker-entrypoint.…" 10 seconds ago Up 9 seconds 80/tcp priceless_bardeen ``` ## 3. Exposing Ports To access the services running inside a container, you can expose ports using the **-p** option. ```bash docker run -d -p 8080:80 nginx ``` This command maps port **80** inside the container to port **8080** on the host machine. ## 4. Mounting Volumes Volumes allow you to persist data outside the container’s filesystem. You can use the **-v** option to mount a volume. ```bash docker run -d -v /mnt:/opt nginx ``` This command mounts the **/mnt** directory on the host to the **/opt** directory inside the container. ## 5. Setting Environment Variables You can set environment variables inside a container using the **-e** option. ```bash docker run -d -e "ENV_VAR=value" nginx ``` This command sets the **ENV_VAR** environment variable to a value inside the container. ## 6. Naming a Container By default, Docker assigns a random name to each container. You can specify a custom name using the **–name** option. ```bash docker run -d --name my-nginx nginx ``` This command starts an Nginx container with the name **my-nginx.** ## 7. Removing Containers Automatically To automatically remove a container when it exits, you can use the **–rm** option. ```bash docker run --rm ubuntu /bin/echo "Hello, world!" ``` This command removes the container after it prints **“Hello, world!”** and exits. ## 8. Passing Commands to Containers You can pass commands to a container at runtime. This is useful for running scripts or commands inside the container. ```bash docker run ubuntu /bin/echo "Hello, Docker!" ``` This command runs the **echo** command inside an Ubuntu container. ## 9. Limiting Resource Usage To limit the CPU and memory usage of a container, you can use the **–cpus** and **–memory** options. ```bash docker run -d --cpus="1.0" --memory="512m" nginx ``` This command limits the container to use at most **one** CPU core and **512** MB of memory. ## Conclusion The docker run command is versatile and essential for managing Docker containers. Understanding its various options and flags is crucial for effectively deploying and managing containers. The examples provided here are just a starting point; the command can be customized further based on specific needs and use cases. You can now manage and run a Docker container on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Dockerizing a Java Application > URL: https://www.atlantic.net/dedicated-server-hosting/dockerizing-a-java-application/ | Published: 2024-08-13 | Updated: 2024-08-17 | Author: Hitesh Jethva In modern software development, containerization has become a crucial practice for packaging and deploying applications. Docker, a leading containerization platform, allows developers to create isolated environments to run applications consistently across different systems. Java, a widely-used programming language, can greatly benefit from Docker’s capabilities by packaging Java applications into containers, simplifying deployment and scaling. This guide walks you through the process of creating a JAR file for your Java application and then Dockerizing it. ## Prerequisites - A server running Ubuntu with Docker installed. - A root user or a user with sudo privileges. ## Step 1 – Create a JAR File To package a Java application into a JAR file, you need to follow these steps: 1. Create your Java application. For example, let’s say you have a simple application with a main class **HelloDocker.java:** ```bash nano HelloDocker.java ``` Add the following code. ```bash package com.example; public class HelloDocker { public static void main(String[] args) { System.out.println("Hello, Docker!"); } } ``` 2. Create a manifest file to specify the main class of the application. ```bash nano MANIFEST.MF ``` Add the following lines: ```bash Manifest-Version: 1.0 Main-Class: com.example.HelloDocker ``` 3. Compile your Java application using the **javac** command. This will generate .class files in the out directory. ```bash javac -d out HelloDocker.java ``` 4. Use the jar command to package the compiled classes into a JAR file. For example, to create a JAR file named **app.jar:** ```bash jar cfm app.jar MANIFEST.MF -C out/ . ``` This command creates a JAR file **app.jar** containing all the classes in the out directory. ## Step 2 – Dockerizing the Java Application To Dockerize the Java application, you’ll need to create a Dockerfile, build a Docker image, and run a container. 1. Create a Dockerfile in the same directory as your JAR file. This file defines the environment and the commands to run your Java application in a Docker container. ```bash nano Dockerfile ``` Add the following configuration. ```bash # Use a base image with Java installed FROM openjdk:11-jre-slim # Set the working directory WORKDIR /app # Copy the JAR file into the container COPY app.jar app.jar # Command to run the application ENTRYPOINT ["java", "-jar", "app.jar"] ``` 2. Build the Docker image using the **docker build** command. Run this command in the directory containing your Dockerfile: ```bash docker build -t my-java-app . ``` This command builds a Docker image named **my-java-app.** You can verify it using the following command. ```bash docker images ``` Output. ```bash REPOSITORY TAG IMAGE ID CREATED SIZE my-java-app latest e4d514a07674 14 seconds ago 223MB openjdk 11-jre-slim 764a04af3eff 24 months ago 223MB ``` 3. Run the Docker container using the docker run command: ```bash docker run -d --name my-running-app -p 8080:8080 my-java-app ``` To view the logs generated by your Java application, you can use the **docker logs** command. ```bash docker logs -f my-running-app ``` You can see the **“Hello, Docker!”** message. ```bash Hello, Docker! ``` ## Conclusion Dockerizing a Java application provides a streamlined and efficient way to deploy and manage software in various environments. By encapsulating the application, its dependencies, and runtime configurations into a Docker container, you achieve a consistent and portable deployment process. Try to create your own Java application with Docker on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Deploy Laravel with Docker and Docker Compose > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-deploy-laravel-with-docker-and-docker-compose/ | Published: 2024-08-14 | Updated: 2024-08-19 | Author: Hitesh Jethva Deploying applications with Docker has revolutionized the way developers build, ship, and run software. Laravel, a popular PHP framework known for its elegant syntax and powerful features, pairs exceptionally well with Docker to create a consistent and scalable development and production environment. By leveraging Docker and Docker Compose, you can streamline the deployment process, ensuring that your Laravel application runs smoothly across different environments. In this guide, we will walk you through the process of deploying a Laravel application using Docker and Docker Compose. ## Prerequisites - A server running Ubuntu with Docker and Docker Compose installed. - A root user or a user with sudo privileges. ## Step 1 – Set Up Your Laravel Project Install PHP and other required packages. ```bash apt install composer php php-cli php-xml php-curl php-intl -y ``` Stop the Apache service. ```bash systemctl stop apache2 ``` If you don’t have a Laravel project yet, you can create one using Composer: ```bash composer create-project --prefer-dist laravel/laravel laravel-docker ``` Navigate to the project directory ```bash cd laravel-docker ``` ## Step 2 – Create a Dockerfile Create a Dockerfile in the root of your Laravel project. This file defines the image configuration for your Laravel application. ```bash nano Dockerfile ``` Add the following lines: ```bash # Use the official PHP image as a base image FROM php:8.1-fpm # Set working directory WORKDIR /var/www # Install system dependencies RUN apt-get update && apt-get install -y \ build-essential \ libpng-dev \ libjpeg-dev \ libfreetype6-dev \ locales \ zip \ jpegoptim optipng pngquant gifsicle \ vim \ unzip \ git \ curl \ libzip-dev \ libpq-dev \ libonig-dev \ && docker-php-ext-configure gd --with-freetype --with-jpeg \ && docker-php-ext-install -j$(nproc) gd # Install PHP extensions RUN docker-php-ext-install pdo pdo_mysql pdo_pgsql mbstring zip exif pcntl # Clear cache RUN apt-get clean && rm -rf /var/lib/apt/lists/* # Install Composer COPY --from=composer:latest /usr/bin/composer /usr/bin/composer # Copy the existing application directory contents to the working directory COPY . /var/www # Copy the existing application directory permissions to the working directory COPY --chown=www-data:www-data . /var/www # Change current user to www USER www-data # Expose port 9000 and start php-fpm server EXPOSE 9000 CMD ["php-fpm"] ``` Save and close the file. ## Step 3 – Create a Docker Compose File Create a **docker-compose.yml** file in the root of your project. This file defines the services (containers) to be run. ```bash nano docker-compose.yml ``` Add the following configuration: ```bash version: '3.8' services: app: build: context: . dockerfile: Dockerfile image: laravel-app container_name: laravel-app restart: unless-stopped tty: true environment: SERVICE_NAME: app SERVICE_TAGS: dev working_dir: /var/www volumes: - .:/var/www - ./docker-compose/php/local.ini:/usr/local/etc/php/conf.d/local.ini networks: - app-network webserver: image: nginx:alpine container_name: nginx-webserver restart: unless-stopped ports: - "8080:80" volumes: - .:/var/www - ./docker-compose/nginx:/etc/nginx/conf.d/ networks: - app-network db: image: mysql:5.7 container_name: mysql restart: unless-stopped environment: MYSQL_DATABASE: laravel MYSQL_ROOT_PASSWORD: root MYSQL_PASSWORD: root MYSQL_USER: root ports: - "3306:3306" volumes: - dbdata:/var/lib/mysql networks: - app-network networks: app-network: driver: bridge volumes: dbdata: driver: local ``` Save and close the file. ## Step 4 – Configure Nginx Create a directory named **docker-compose/nginx** and add a configuration file named **default.conf** inside it. ```bash mkdir -p docker-compose/nginx nano docker-compose/nginx/default.conf ``` Add the following configuration. ```bash server { listen 80; index index.php index.html; server_name localhost; root /var/www/public; location / { try_files $uri $uri/ /index.php?$query_string; } location ~ \.php$ { fastcgi_pass app:9000; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; include fastcgi_params; } location ~ /\.ht { deny all; } } ``` Save the file. ## Step 5 – Environment Variables Ensure you have a .env file set up in your Laravel project with appropriate configurations. For instance, set the database host to db (the name of the MySQL service in docker-compose.yml): ```bash nano .env ``` Modify the following content: ```bash DB_CONNECTION=mysql DB_HOST=db DB_PORT=3306 DB_DATABASE=laravel DB_USERNAME=laravel DB_PASSWORD=root ``` ## Step 6 – Build and Run the Containers Build and start the Docker containers using Docker Compose: ```bash docker-compose up -d ``` This command will build the Docker images defined in the **Dockerfile** and **docker-compose.yml,** and then start the containers in detached mode. Verify the running containers. ```bash docker-compose ps ``` Output. ```bash Name Command State Ports ---------------------------------------------------------------------------------------------------- laravel-app docker-php-entrypoint php-fpm Up 9000/tcp mysql docker-entrypoint.sh mysqld Restarting nginx-webserver /docker-entrypoint.sh ngin ... Up 0.0.0.0:8080->80/tcp,:::8080->80/tcp ``` ## Step 7 – Access the Application Your Laravel application should now be accessible at **http://your-server-ip:8080.** ![](https://www.atlantic.net/wp-content/uploads/2024/07/p1.png) ## Step 8 – Stop the Containers To stop the Docker containers, you can use: ```bash docker-compose down ``` This will stop and remove the containers but preserve the data stored in the volumes. ## Conclusion You’ve now set up a Laravel application with Docker and Docker Compose. This setup helps isolate the application and its dependencies, making it easier to manage and deploy. You can customize the configuration files further to suit your needs, such as adding more services, adjusting the Nginx configuration, or modifying the PHP environment settings. Try deploying a Laravel app with Docker on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How To Remove Docker Images, Containers and Volumes > URL: https://www.atlantic.net/vps-hosting/how-to-remove-docker-images-containers-and-volumes/ | Published: 2024-08-15 | Updated: 2024-08-19 | Author: Hitesh Jethva Docker is a powerful platform that enables developers to automate the deployment of applications inside lightweight, portable containers. Over time, as you build, run, and test applications, you may accumulate many Docker images and containers. These can consume significant disk space and clutter your environment, making it harder to manage and maintain your system. Knowing how to efficiently remove Docker images and containers is essential for keeping your Docker environment clean and optimized. In this guide, we will explore the steps to remove Docker images and containers. ## Removing Docker Containers **1. List Containers.** To list all containers, both running and stopped, use the following command: ```bash docker ps -a ``` This will display a list of all containers with their status. ```bash CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 7d8db99f64e9 nginx "/docker-entrypoint.…" 6 seconds ago Up 5 seconds 80/tcp elated_diffie a7dfbcd76554 busybox "sh" 2 minutes ago Exited (0) 2 minutes ago my_container ``` **2. Stop a Running Container.** Before removing a running container, you need to stop it. Use the following command: ```bash docker stop ``` Replace with the ID or name of the container. ```bash docker stop 7d8db99f64e9 ``` This will stop the Nginx container. **3. Remove a Container.** To remove a container, use the following command: ```bash docker rm ``` Replace with the ID or name of the container. ```bash docker rm 7d8db99f64e9 ``` This will remove the Nginx container. You can remove multiple containers at once by specifying multiple container IDs separated by a space. **4. Force Remove a Running Container.** You can also forcefully stop and remove a running container with: ```bash docker rm -f ``` **5. Remove All Stopped Containers.** To remove all stopped containers, use: ```bash docker container prune ``` You will be prompted to confirm the action. ## Removing Docker Images **1. List Docker Images.** To list all Docker images, use: ```bash docker images ``` Output: ```bash REPOSITORY TAG IMAGE ID CREATED SIZE nginx latest a72860cb95fd 4 weeks ago 188MB ubuntu latest 35a88802559d 6 weeks ago 78.1MB busybox latest 65ad0d468eb1 14 months ago 4.26MB ``` **2. Remove a Specific Image.** To remove a specific image, use: ```bash docker rmi ``` Replace with the ID of the image you want to remove. ```bash docker rmi a72860cb95fd ``` This will remove the Nginx image. **3. Remove Multiple Images.** You can remove multiple images by specifying multiple image IDs. ```bash docker rmi ``` **4. Force Remove an Image.** If an image is associated with a container, you can forcefully remove it with: ```bash docker rmi -f ``` **5. Remove Dangling Images.** Dangling images are layers not associated with any tagged images. To remove them, use: ```bash docker image prune ``` **6. Remove All Unused Images.** To remove all images not associated with a container, use: ```bash docker image prune -a ``` ## Cleaning Up Volumes and Networks **1. Remove Unused Volumes.** Volumes can also consume disk space. To remove unused volumes, use: ```bash docker volume prune ``` **2. Remove Unused Networks.** To remove unused networks, use: ```bash docker network prune ``` ## Conclusion Managing Docker containers and images is essential for maintaining a clean and efficient Docker environment. By regularly removing unused containers, images, volumes, and networks, you can free up valuable disk space and improve the performance of your Docker system. The commands provided in this guide give you the tools needed to list, stop, and remove containers and images effectively. You can now easily remove Docker images and containers from [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Create and Manage Docker Volumes with Practical Example > URL: https://www.atlantic.net/vps-hosting/how-to-create-and-manage-docker-volumes-with-practical-example/ | Published: 2024-08-16 | Updated: 2024-08-19 | Author: Hitesh Jethva Docker volumes are a crucial feature for managing data in containerized applications. They provide a way to persist data generated by Docker containers, ensuring that data remains intact even after the container is deleted. In this guide, we will explore how to create and manage Docker volumes with practical examples. ## Types of Docker Volumes 1. **Named Volumes:** Named volumes are explicitly created and can be referenced by a specific name. They are useful when you want to share data between multiple containers or need to persist data beyond the lifecycle of a single container. 2. **Anonymous Volumes:** Anonymous volumes are created implicitly when a container is started and a volume is not specified. They are used when data persistence is needed, but the specific volume name is not important. 3. **Host Volumes:** Host volumes are created by mounting a directory from the host system into the container. This allows for direct access to host files and directories from within the container. ## Creating a Named Volume To create a named volume, use the docker volume create command: ```bash docker volume create my_named_volume ``` This command creates a volume named **my_named_volume.** You can verify its creation by listing all volumes: ```bash docker volume ls ``` Output: ```bash DRIVER VOLUME NAME local my_named_volume ``` ## Creating an Anonymous Volume Anonymous volumes are automatically created when a container is started with a mount point, but no specific volume name is provided: ```bash docker run -d --name my_container -v /data busybox ``` In this example, an anonymous volume is created and mounted to **/data** in the container. ## Mounting a Named Volume You can mount a named volume into a container using the **-v** flag: ```bash docker run -d --name my_new_container -v my_named_volume:/app busybox ``` Here, the named volume **my_named_volume** is mounted to **/app** in the container. ## Mounting a Host Volume To mount a host directory as a volume, use the following syntax: ```bash docker run -d --name my_host_container -v /mnt:/app busybox ``` This command mounts the host directory **/mnt** to **/app** in the container. ## Inspecting Docker Volumes To inspect the details of a Docker volume, use the **docker volume inspect** command: ```bash docker volume inspect my_named_volume ``` This command provides information about the volume, including its mount point and usage details. ```bash [ { "CreatedAt": "2024-07-25T09:41:19Z", "Driver": "local", "Labels": null, "Mountpoint": "/var/lib/docker/volumes/my_named_volume/_data", "Name": "my_named_volume", "Options": null, "Scope": "local" } ] ``` ## Removing Docker Volumes Docker volumes can be removed using the docker volume rm command. Be cautious, as this action deletes the data stored in the volume. To remove a named volume: ```bash docker volume rm my_named_volume ``` To remove all volumes not currently in use by containers, use: ```bash docker volume prune ``` Output. ```bash WARNING! This will remove anonymous local volumes not used by at least one container. Are you sure you want to continue? [y/N] y Total reclaimed space: 0B ``` ## Conclusion Docker volumes are a powerful tool for managing data in containerized environments. By understanding how to create and manage volumes, you can ensure data persistence, share data between containers, and manage application state effectively. Try to create and manage Docker volumes on [VPS hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install MongoDB on Ubuntu 22.04 > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-mongodb-ubuntu-20-04/ | Published: 2024-08-17 | Author: Jose Velazquez MongoDB, a powerful and versatile NoSQL database, is widely used for its ability to handle large volumes of diverse data types with ease. Whether you are developing a web application, managing big data, or leveraging real-time analytics, MongoDB offers the flexibility and scalability required for modern data-driven applications. However, to fully utilize MongoDB’s capabilities, it is crucial to install it correctly and ensure that it is securely configured. This guide will walk you through the process of installing and securing MongoDB on Ubuntu 22.04. ## Step 1 – Update System Packages First, update your system packages to ensure you have the latest updates and security patches. ```bash apt update && apt upgrade -y ``` This command will update the package list and upgrade all the installed packages to their latest versions. Next, you will also need to install libssl to your server. You can download and install it using the following commands: ```bash wget http://archive.ubuntu.com/ubuntu/pool/main/o/openssl/libssl1.1_1.1.0g-2ubuntu4_amd64.deb dpkg -i libssl1.1_1.1.0g-2ubuntu4_amd64.deb ``` ## Step 2 – Import the MongoDB GPG Key MongoDB provides a GPG key to ensure the integrity of the packages. Import this key using the following command: ```bash curl -fsSL https://www.mongodb.org/static/pgp/server-4.4.asc | gpg -o /usr/share/keyrings/mongodb-server-4.4.gpg --dearmor ``` You should see an output saying OK, indicating the key has been successfully added. ## Step 3 – Add MongoDB Repository Next, add the MongoDB repository to your system’s sources list. ```bash echo "deb [ arch=amd64,arm64 signed-by=/usr/share/keyrings/mongodb-server-4.4.gpg ] https://repo.mongodb.org/apt/ubuntu focal/mongodb-org/4.4 multiverse" | tee /etc/apt/sources.list.d/mongodb-org-4.0.list ``` This command will add the MongoDB repository to your sources list, making MongoDB packages available for installation. ## Step 4 – Install MongoDB Now, install MongoDB using the following command: ```bash apt update apt install mongodb-org ``` This will install the latest version of MongoDB along with all necessary dependencies. Now, verify the MongoDB installation using the following command: ```bash mongo --version ``` Output: ```bash MongoDB shell version v4.4.29 Build Info: { "version": "4.4.29", "gitVersion": "f4dda329a99811c707eb06d05ad023599f9be263", "openSSLVersion": "OpenSSL 1.1.0g 2 Nov 2017", "modules": [], "allocator": "tcmalloc", "environment": { "distmod": "ubuntu2004", "distarch": "x86_64", "target_arch": "x86_64" } } ``` ## Step 5 – Start and Enable MongoDB Service After the installation, start the MongoDB service and enable it to start on boot. ```bash systemctl start mongod systemctl enable mongod ``` To verify that MongoDB is running, use the command: ```bash systemctl status mongod ``` You should see output indicating that the MongoDB service is active and running. ```bash ● mongod.service - MongoDB Database Server Loaded: loaded (/lib/systemd/system/mongod.service; disabled; vendor preset: enabled) Active: active (running) since Mon 2024-07-15 11:33:18 UTC; 5s ago Docs: https://docs.mongodb.org/manual Main PID: 7581 (mongod) Memory: 64.7M CPU: 788ms CGroup: /system.slice/mongod.service └─7581 /usr/bin/mongod --config /etc/mongod.conf ``` ## Step 6 – Secure MongoDB By default, MongoDB does not enforce authentication. To secure your database, you need to enable authentication. Open the MongoDB configuration file: ```bash nano /etc/mongod.conf ``` Find the security section and add the following lines: ```bash security: authorization: "enabled" ``` Save and close the file, then restart MongoDB: ```bash systemctl restart mongod ``` Access the MongoDB shell: ```bash mongo ``` Switch to the admin database: ```bash use admin ``` Create the administrative user: ```bash db.createUser({ user: "admin", pwd: "strongpassword", roles: [{ role: "userAdminAnyDatabase", db: "admin" }] }) Replace "strongpassword" with a strong password of your choice. After creating the user, exit the MongoDB shell: ``` ```bash exit ``` ## Step 7 – Verify MongoDB Connectivity After configuring SSL/TLS for MongoDB, it’s important to verify that the authentication is working as expected. We will do this by connecting to the MongoDB instance using the mongosh shell. If you haven’t already installed the MongoDB shell, you can do so with the following command: ```bash apt install mongodb-mongosh ``` Use the mongosh shell to connect to your MongoDB instance with authentication. ```bash mongosh --host localhost --port 27017 -u admin -p --authenticationDatabase admin ``` Replace your_mongodb_server_ip with the IP address of your MongoDB server. You will be prompted to enter the password for the admin user. If the connection is successful, you should see the MongoDB shell prompt: ```bash Enter password: ************** Current Mongosh Log ID: 6695102f9cd95f2e6b482f8a Connecting to: mongodb://@localhost:27017/?directConnection=true&serverSelectionTimeoutMS=2000&authSource=admin&appName=mongosh+2.2.12 Using MongoDB: 4.4.29 Using Mongosh: 2.2.12 For mongosh info see: https://docs.mongodb.com/mongodb-shell/ To help improve our products, anonymous usage data is collected and sent to MongoDB periodically (https://www.mongodb.com/legal/privacy-policy). You can opt-out by running the disableTelemetry() command. Warning: Found ~/.mongorc.js, but not ~/.mongoshrc.js. ~/.mongorc.js will not be loaded. You may want to copy or rename ~/.mongorc.js to ~/.mongoshrc.js. test> ``` ## Conclusion In this article, we covered the installation and security setup for MongoDB on Ubuntu 22.04. You learned how to install MongoDB, enable authentication, create an administrative user, and verify the secure connection. By following these steps, you have ensured that your MongoDB instance is both operational and secure. You can deploy the MongoDB database server on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Create a Database in MongoDB > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-create-a-database-in-mongodb/ | Published: 2024-08-18 | Updated: 2024-08-17 | Author: Hitesh Jethva MongoDB is a popular NoSQL database known for its flexibility, scalability, and ease of use. Unlike traditional relational databases, MongoDB stores data in a schema-less format, using documents in a JSON-like structure called BSON (Binary JSON). This allows for rapid development and iteration, making it an ideal choice for modern applications that require agility and scalability. In this tutorial, we will explore how to create a database in MongoDB. ## Step 1 – Verify the MongoDB Installation Before starting, it is essential to check whether MongoDB is installed on your system. You can check it using the following command. ```bash mongo --version ``` You should see the information for the MongoDB version. ```bash MongoDB shell version v4.4.29 Build Info: { "version": "4.4.29", "gitVersion": "f4dda329a99811c707eb06d05ad023599f9be263", "openSSLVersion": "OpenSSL 1.1.0g 2 Nov 2017", "modules": [], "allocator": "tcmalloc", "environment": { "distmod": "ubuntu2004", "distarch": "x86_64", "target_arch": "x86_64" } } ``` **Note:** If you get an error, it means MongoDB isn’t installed or isn’t in your system’s PATH. ## Step 2 – Connecting to MongoDB After verifying the MongoDB installation, you can connect using the Mongo shell. Open your terminal or command prompt and type: ```bash mongo ``` This command connects you to the MongoDB server and opens an interactive Mongo shell. You should see a prompt that looks like this: ```bash > ``` ## Step 3 – Creating a Database In MongoDB, you don’t need to create a database explicitly. Instead, you can switch to a non-existent database, and MongoDB will create it for you when you insert the first document. Let’s create a database named mydatabase. ```bash use mydatabase ``` Output. ```bash switched to db mydatabase ``` Initially, the database will not be visible in the list of databases because it doesn’t contain any data. To see the list of databases, use the command: ```bash show dbs ``` Output: ```bash admin 0.000GB config 0.000GB local 0.000GB ``` Let’s insert a sample document into a collection called **mycollection** within the **mydatabase**: ```bash db.mycollection.insertOne({ name: "John Doe", age: 30, profession: "Developer" }) Output: ``` ```bash { "acknowledged" : true, "insertedId" : ObjectId("60c5dbd4f5d1dc8f459f2a27") } ``` Now, if you run the show dbs command again, you’ll see mydatabase listed: ```bash show dbs ``` Output: ```bash admin 0.000GB config 0.000GB local 0.000GB mydatabase 0.000GB ``` ## Step 4 – Basic Database Operations You can create collections within a database to store your data. To create a new collection, use the **createCollection** method: ```bash db.createCollection("mynewcollection") Output: ``` ```bash { "ok" : 1 } ``` To see all the collections in your current database, use the show collections command: ```bash show collections ``` Output: ```bash mycollection mynewcollection ``` You can insert documents into a collection using the insertOne or insertMany methods: ```bash db.mynewcollection.insertOne({ title: "MongoDB Guide", author: "Jane Doe" }) ``` Output: ```bash { "acknowledged" : true, "insertedId" : ObjectId("60c5dbf2f5d1dc8f459f2a28") } ``` To retrieve documents from a collection, use the find method: ```bash db.mynewcollection.find() ``` Output: ```bash { "_id" : ObjectId("60c5dbf2f5d1dc8f459f2a28"), "title" : "MongoDB Guide", "author" : "Jane Doe" } ``` To update documents, use the updateOne or updateMany methods. Let’s update the document we just inserted: ```bash db.mynewcollection.updateOne({ title: "MongoDB Guide" }, { $set: { author: "John Smith" } }) ``` Output: ```bash { "acknowledged" : true, "matchedCount" : 1, "modifiedCount" : 1 } ``` To delete documents, use the deleteOne or deleteMany methods. Let’s delete the document we just updated: ```bash db.mynewcollection.deleteOne({ title: "MongoDB Guide" }) ``` Output. ```bash { "acknowledged" : true, "deletedCount" : 1 } ``` ## Conclusion In this article, we have covered the essential steps to create and manage a database in MongoDB. We started with connecting to the MongoDB server, and created a new database by simply switching to it. We then explored basic database operations such as creating collections, inserting, querying, updating, and deleting documents. You can now easily create a MongoDB database on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Remove Metadata from Files in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-remove-metadata-from-files-in-linux/ | Published: 2024-08-21 | Updated: 2024-09-09 | Author: Hitesh Jethva Metadata is data that describes other data. This hidden data can include sensitive information like your location, device details, and more. If you care about privacy, it’s essential to know how to remove metadata from your files before sharing them. In this guide, we’ll explore how to remove metadata from different file types in Linux. ## Removing Metadata from Image Files Let’s start with images, as they often carry a lot of metadata. **ExifTool** is one of the most powerful tools for removing metadata from images. Here’s how to use it: 1. Install ExifTool: ```bash apt-get install libimage-exiftool-perl ``` 2. Remove Metadata: ```bash exiftool -all= image.jpg ``` This command strips all metadata from image.jpg. 3. Verify Removal: ```bash exiftool image.jpg ``` After running this command, the output should show no metadata. 4. If you have multiple files, you can remove metadata from all images using the following command. ```bash exiftool -all= *.jpg ``` This command removes metadata from all .jpg files in the directory. ## Removing Metadata from Document Files Documents, especially PDFs, can also contain metadata. Here’s how to clean them up. For PDFs, qpdf is a great tool to remove metadata. 1. Install qpdf: ```bash apt-get install qpdf ``` 2. Remove Metadata: ```bash qpdf --linearize input.pdf output.pdf ``` This command rewrites the PDF without the metadata. 3. Verify Removal: ```bash pdfinfo output.pdf ``` The output should show minimal or no metadata. ## Automating Metadata Removal with Scripts To make things easier, you can automate the process with a simple Bash script. Here’s a basic script to remove metadata from all .jpg and .pdf files in a directory: ```bash #!/bin/bash for file in *.jpg *.pdf; do if [[ $file == *.jpg ]]; then exiftool -all= "$file" elif [[ $file == *.pdf ]]; then qpdf --linearize "$file" "${file%.pdf}_clean.pdf" fi done ``` This script checks the file type and removes the metadata accordingly. ## Conclusion Removing metadata from your files is a crucial step in protecting your privacy. Whether you’re sharing photos, documents, or any other files, make sure to strip out the metadata first. Now, you can easily remove metadata from your files in Linux. Remember to always verify that the metadata has been removed to ensure your privacy is protected. You can follow this guide to remove metadata of any file on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Use the passwd Command in Linux with Examples > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-use-the-passwd-command-in-linux-with-examples/ | Published: 2024-08-22 | Updated: 2024-12-05 | Author: Hitesh Jethva Managing user accounts is essential in Linux systems. One of the most critical tasks is managing passwords. The passwd command in Linux is used to update a user’s authentication token or password. It’s a simple but powerful tool. You can use it to change your own password or manage other users’ passwords if you have the necessary permissions. This guide will show you how to use the passwd command in various scenarios. You’ll learn how to change passwords, force password updates, lock accounts, and more. ## Basic Syntax of the passwd Command Here’s the basic syntax for the passwd command: ```bash passwd [OPTIONS] [USERNAME] ``` - **USERNAME:** The user whose password you want to change. If you omit this, the command will change the password of the user who runs it. - **OPTIONS:** Various options to modify the behavior of the command (we’ll cover these later). ## Changing Your Own Password Changing your password is straightforward. Just type passwd in the terminal and follow the prompts. ```bash passwd ``` After entering your current password, you’ll be prompted to enter a new one twice. If the passwords match, your password is updated. ```bash Changing password for user your_username. Current password: New password: Retype new password: passwd: all authentication tokens updated successfully. ``` ## Changing Another User’s Password as Root As a system administrator, you may need to change another user’s password. You must have root privileges to do this. ```bash passwd username ``` Output: ```bash Enter new UNIX password: Retype new UNIX password: passwd: password updated successfully. ``` Replace username with the actual username. The system will prompt you to enter the new password for the user. ## Forcing Users to Change Password on Next Login Sometimes, you need to ensure a user updates their password the next time they log in. Use the -e option to force this. ```bash passwd -e username ``` This command expires the user’s password immediately. The user must change their password at the next login. ## Locking and Unlocking User Accounts Locking a user account prevents the user from logging in. This is useful if you need to temporarily disable a user’s access. Locking an account: ```bash passwd -l username ``` Unlocking an account: ```bash passwd -u username ``` When you lock an account, an exclamation mark (!) is added in front of the encrypted password in /etc/shadow. Unlocking removes this mark. ## Setting Password Expiration and Policies You can enforce password expiration policies using the passwd command. For example, to set a password to expire after 30 days: ```bash passwd -x 30 username ``` You can also set the minimum number of days between password changes: ```bash passwd -n 7 username ``` This command ensures the user cannot change their password more than once in seven days. ## Disabling Password for a User Account In some cases, you may want to allow a user to log in without a password. You can disable the password like this: ```bash passwd -d username ``` This command removes the password, allowing the user to log in without one. Be cautious with this, as it reduces security. ## Conclusion The passwd command is a vital tool for managing user accounts in Linux. I hope you should now have a solid understanding of how to use the passwd command effectively. Keep your system secure by managing passwords wisely. You can now easy set or reset password on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # What Is an AI Server, and What Does It Do? > URL: https://www.atlantic.net/vps-hosting/what-is-an-ai-server-and-what-does-it-do/ | Published: 2024-08-23 | Updated: 2024-11-26 | Author: Richard Bailey Over the last 18 months, AI has exploded into our everyday lives. It’s on our phones, it’s embedded in our search engines, social media, navigation systems, and even our healthcare and financial services. The rise has been meteoric, and it’s showing no signs of slowing down. But here’s where it gets even more interesting: you don’t have to be a passive consumer in this AI revolution. You can create your own AI server, and start developing your own AI applications, breaking free from the constraints of the big AI providers. AI servers are a popular solution in the field of artificial intelligence (AI); AI servers are used to execute complex AI workloads, including training and inference of sophisticated AI models. This article will introduce you to the core concepts of AI servers, their architecture, and functionality. ## Understanding AI Servers An AI server is a powerful computing system purpose-built to handle the computational demands of artificial intelligence tasks. Unlike traditional servers designed for general-purpose computing, AI servers boast specialized hardware and software components optimized for AI computations. While the hardware requirements for AI have historically been substantial, recent advancements have significantly lowered the barriers to entry, making AI capabilities accessible to a far broader audience. Let’s dive into what is needed for an AI server: ### GPU Horsepower Graphics cards are not just for gaming; they are proving hugely successful in powering AI. Specialized graphics processing units (GPUs) such as NVIDIA Tensor Core GPUs or AMD Instinct GPUs speed up AI processing capabilities substantially. A GPU accelerates the complex mathematical operations that form the foundation of AI and deep learning. This translates to faster training of AI models and quicker real-time inference, enabling advancements in various fields like natural language processing, computer vision, and more. ### High-Performance Processors AI models work best on servers with good processing power. A high clock speed and a large number of processing cores benefit performance greatly. Consumer-grade AI servers typically use high-performance central processing units (CPUs) like the Intel Xeon Scalable processor or AMD EPYC processors. While a powerful GPU is usually the star of the show in AI acceleration, a strong CPU acts as a vital supporting member that ensures the entire AI workload runs smoothly and efficiently. ### Expansive High-Speed Memory AI models and datasets can be enormous. Consequently, AI servers typically possess substantial amounts of high-bandwidth memory, often in the various form factors of DDR5/6 or HBM (High Bandwidth Memory). The more memory available to the AI workload, the larger AI model can be used, resulting in more detailed and typically more accurate results. ### Fast SSD and NVMe Storage AI training often needs rapid access to data and frequently utilizes high-performance storage like NVMe (Non-Volatile Memory Express) solid-state drives (SSDs) to enable efficient data movement. A fast disk file system is essential to keep up with the CPU and GPU performance and to avoid the risk of having any potential bottlenecks. ### High-Speed Networking: In distributed AI environments, seamless communication between the AI server stack is critical. AI servers typically feature high-speed networking capabilities such as InfiniBand or 2.5, 5, or 10 Gigabit Ethernet to ensure efficient data transfer between the nodes and the storage layer system. ## The Role of AI Servers in Generative AI Generative AI is a subfield of AI that focuses on creating content like images, text, and music and has experienced remarkable growth in recent years. 18 months ago, few knew of the three big players in AI: ChatGPT, Gemini, and CoPilot, each of which have now become household names. Businesses are investing huge resources in AI and machine learning, with many banking on the success of AI to give their business a competitive advantage. This growth has been fueled by the advancement of AI servers capable of handling the computational demands of training and deploying large language models (LLMs) and other generative AI models. Generative AI training often involves processing large datasets and executing complex algorithms, making the capabilities of AI servers pivotal to their success. Traditionally, users would pay a subscription to an LLM provider like ChatGPT, and then consume the service directly on their platform using prompts and API integration. This is already starting to change as businesses and users get smart to the idea that it’s relatively easy to do it yourself. The open-source community has been pushing free-to-use LLMs for the consumer market, and big corporations like Meta (Facebook) are investing billions of dollars in their development. Some popular open-source models include Llama, StableLM, Dolly, Bloom, and OpenAssistant. ## AI Workloads and Data Centers It’s now much easier to run AI computations in the data center. Atlantic.Net is fully committed to providing AI-ready services to our customers from all of our data center locations. You can create an AI-ready VPS in a few clicks from our [Atlantic.Net control panel](https://cloud.atlantic.net/?page=signup) in any of our data centers across our VPS regions. We have locations in the United States, Canada, Europe and Asia. Atlantic.net offers a range of VPS options that can effectively handle AI-driven processes. We have recently partnered with NVIDIA to offer optional [GPU configurations](https://www.atlantic.net/gpu-server-hosting/) (region-specific) for unparalleled performance. Enhance your experience by pairing this new service with our extensive VPS catalog, offering plans tailored for everything from general use to specialized storage, memory, or compute needs. Here is a summary of the type of plans we have available. ### General Purpose & Compute Optimized: Our general purpose and compute-optimized VPS instances provide a good starting point for various AI-driven processes. The higher-tier options within these categories, like G3.96GB, G3.128GB, C2.32GB, and C2.64GB, offer substantial RAM and support the vCPU counts that are crucial for handling the computational demands of AI. Integrating GPUs with these instances can supercharge their AI capabilities, particularly for tasks like deep learning and complex model training. Combining the latest gen Intel Xeon scalable CPUs from Intel Corporation, ample RAM, and a powerful GPU creates a highly performant environment for tackling demanding AI projects. ### Dedicated Hosts: Dedicated servers deliver unparalleled performance for resource-intensive AI tasks with their dedicated resources and isolation. When coupled with high-end NVIDIA GPUs like the H100 NVL or H200, these servers become powerhouses capable of easily handling the most demanding AI models running at scale. ### **GPU-Specific Considerations:** Choose the GPU model based on your AI tasks. The H100 NVL excels at large-scale AI models, while the L40S balances performance and cost-effectiveness for a broader range of AI applications. Engage with our [sales team](https://cloud.atlantic.net/?page=gpus) to discuss your AI workload requirements and identify the most suitable GPU configuration. These configurations, combining powerful CPUs, ample RAM, and cutting-edge GPUs, unlock the full potential of AI, enabling faster training, more complex model handling, and superior performance overall. ## Tips for Choosing and Deploying AI Servers Are you ready to start your AI server journey? Do you need a server that can handle diverse AI applications in operation, from training large language models to running inference workloads for various industries? Here are some of our top tips to get you started. ### **Assess Your AI Workload Requirements** #### **Identify Your AI Tasks:** Pinpoint the specific AI applications you’ll be running, such as deep learning, natural language processing, computer vision, or generative AI. Each task has different computational and memory requirements, pick an AI application and understand the recommended system requirements for the task at hand, this will help you identify the right hardware and software mix to achieve AI success. Different AI solutions have distinct system requirements. Deep learning relies heavily on GPUs for matrix operations, while Natural Language Processing (NLP) works best on powerful CPUs for text processing. Computer vision requires high-performance GPUs for image/video analysis, while generative AI needs both strong GPUs and CPUs for handling large models and generating complex outputs. All AI tasks benefit from ample high-speed memory and fast storage. #### **Estimate and Test Resource Needs:** Evaluate the size of your datasets, the complexity of your AI models, and the expected inference and AI training workload. Consider the scale of your ambitions – are you dealing with large models or aiming for large-scale deployments? This will help you determine the necessary GPU horsepower (potentially leveraging technologies like NVIDIA® NVLink™ for multi-GPU setups), the number of gen Intel Xeon Scalable processors or AMD EPYC cores needed, the optimal GPU memory capacity, and the storage performance required to keep your data flowing smoothly. ### **Choose the Right Deployment Model** Remember, you can host your AI deployment pretty much anywhere. If you have the capital, it’s possible to purchase or lease your own server. However, the costs can be very high for the top-of-the-line systems, which is why many users opt for a pay-as-you-go cloud model or a 1 to 3 year fixed term contracts. #### **On-Premises:** For organizations with compliance data control requirements or those in sectors like scientific research where data sovereignty is necessary, on-premises deployment might be the preferred choice. High-Performance Computing (HPC) workloads, which demand high-end computing power, often fall into this category. Remember, on-premises solutions require significant upfront investment and ongoing maintenance. Consider factors like space, power consumption, and cooling solutions – liquid cooling might be necessary for high-density deployments. #### **Cloud:** Cloud-based AI servers offer flexibility, scalability, and full support, plus you get pay-as-you-go pricing. They can be an excellent choice for handling fluctuating workloads and avoiding upfront infrastructure costs, you can also dip in and out when you need it. #### **Hybrid:** A hybrid approach, where some cognitive computing jobs run on-premises and others in the cloud, combines the benefits of both models, allowing you to leverage their strengths based on your specific business needs, and when needed offload AI computing power to the cloud. ### **Optimize AI Server Performance** #### **Software Optimization:** There are lots of paid and open-source AI-specific software frameworks and libraries available. To streamline development and maximize performance, look for mature and optimized code sets and software that works well within specific resource allocations. Also, look into vector database hosting for backend optimizations. #### **Hardware Acceleration:** We have already discussed the importance of GPU acceleration in AI Inference. Picking a powerful VPS host is also essential. #### **Load Balancing:** Use application load balancers to distribute AI workloads across multiple servers and ensure optimal resource utilization. Advanced AI solutions can require a cluster of nodes to ensure peak performance and avoid performance bottlenecks. #### **Monitoring and Management:** Take the time to implement monitoring and management tools to track the AI server performance. The overhead on these tools is now quite affordable, but the insights you can gain to improve performance and optimize your applications can be a lifesaver when helping to identify potential issues, and proactively address them. ### **Plan for Scalability** #### **Choose a Scalable Architecture:** Design your AI infrastructure with scalability in mind, allowing you to add more servers or GPUs as your AI workloads grow, ensuring your AI solutions can keep pace with the evolving demands of your business. This can involve horizontal and vertical scaling, using clustered nodes and application load balancing. #### **Leverage Cloud Elasticity:** If using cloud-based AI servers, take advantage of the elasticity of the cloud to scale resources up as needed, providing the agility to respond to changing AI workload demands efficiently. ## Atlantic.Net AI Server Hosting Our commitment to AI excellence is evident in our partnerships with industry leaders like NVIDIA and our continuous investment in AI-ready infrastructure. Our range of VPS options, dedicated hosts, and GPU configurations ensures that you have the flexibility to tailor your AI environment to your specific workload requirements. ### **Why Choose Atlantic.Net for AI Server Hosting?** - **Unparalleled Performance:** The latest generation Intel Xeon Scalable processors, high-bandwidth memory, fast NVMe storage, and cutting-edge NVIDIA GPUs to achieve optimal AI performance. - **Expert Support:** Our dedicated team of experts is available to guide you through every step of your AI journey, from choosing the right configuration to optimizing your deployment for maximum efficiency. - **Cost-Effectiveness:** Our transparent pricing models ensure that you only pay for the resources you need, making AI server hosting accessible to businesses of all sizes. ### **Take the Next Step in Your AI Journey** Don’t let infrastructure limitations hold back your AI ambitions. [Contact Atlantic.Net today](https://www.atlantic.net/about-us/corporate-contact/) to discuss your AI server hosting needs and discover how we can help you unlock the full potential of AI. --- # Fix APT Update Post-Invoke-Success Script Execution Error > URL: https://www.atlantic.net/dedicated-server-hosting/fix-apt-update-post-invoke-success-script-execution-error/ | Published: 2024-08-24 | Updated: 2026-07-23 | Author: Hitesh Jethva The APT package manager is a core part of Debian and Ubuntu-based systems. It handles the installation, updating, and removal of software packages. When you run apt-get update, APT not only updates the package lists but can also trigger custom scripts after a successful update. These scripts, called **“Post-Invoke-Success”** scripts. However, sometimes you might see an error related to these Post-Invoke-Success scripts. This error can stop the update process and leave your system in a less-than-ideal state. In this article, we’ll dive into what causes this error and how to fix it. ## Understanding the Post-Invoke-Success Script Execution Error This error occurs when APT tries to run a custom script after an update but fails. These scripts usually reside in /etc/apt/apt.conf.d/ and are often used for housekeeping tasks. You might see an error message like this: ```bash E: Problem executing scripts APT::Update::Post-Invoke-Success '/usr/local/bin/cleanup.sh' E: Sub-process returned an error code This message tells you that APT couldn't execute the script, likely due to an issue with the script itself or the environment it runs in. ``` ## Identifying the Root Cause To fix the problem, we first need to identify the root cause. Here’s how you can do it: **1. Check the APT logs:** The logs can give you clues about what went wrong. You can find these logs in /var/log/apt/term.log. ```bash less /var/log/apt/term.log ``` **2. Inspect the script:** The error might be in the script itself. Look at the script mentioned in the error message, and check for syntax errors, missing files, or other issues. ```bash nano /usr/local/bin/cleanup.sh ``` **3. Review file permissions:** Sometimes, the issue is as simple as incorrect file permissions. Ensure that the script has the right permissions to execute. ```bash ls -l /usr/local/bin/cleanup.sh ``` If the script isn’t executable, you can fix it with: ```bash chmod +x /usr/local/bin/cleanup.sh ``` ## Fixing Common Issues Now that you’ve identified the problem, let’s fix it. Here are some common issues and how to solve them: **1. Correcting Syntax Errors:** If the script has a syntax error, APT can’t run it. Open the script and review it for mistakes. Here’s an example of a bad line and how to fix it: **Incorrect:** ```bash if [ -f /tmp/file.txt then echo "File exists" fi ``` **Corrected:** ```bash if [ -f /tmp/file.txt ]; then echo "File exists" fi ``` Save your changes and exit the editor. **2. Adjusting File Permissions:** The script needs the right permissions to run. Check the permissions using ls -l. If the script isn’t executable, make it executable: ```bash chmod +x /usr/local/bin/cleanup.sh ``` **3. Resolving Conflicts:** Sometimes, another script or package might conflict with your Post-Invoke-Success script. If that’s the case, you might need to adjust how your script runs or change its order in the APT process. You can temporarily disable the script to test if it’s causing the issue: ```bash mv /usr/local/bin/cleanup.sh /usr/local/bin/cleanup.sh.disabled ``` ## Testing the Fix After applying these fixes, it’s time to test. Run the following command: ```bash apt-get update ``` Watch for errors. If everything runs smoothly, you’ve fixed the issue. To be thorough, you can also add set -x at the top of your script to see detailed output during execution. This helps with debugging: ```bash #!/bin/bash set -x # rest of the script ``` ## Conclusion The APT Update Post-Invoke-Success script execution error can be frustrating, but it’s usually straightforward to fix. By checking logs, reviewing scripts, and adjusting permissions, you can resolve the issue and ensure smooth updates in the future. Use this guide to fix update errors on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Use groupmod Command in Linux with Examples > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-use-groupmod-command-in-linux-with-examples/ | Published: 2024-08-26 | Updated: 2024-12-05 | Author: Hitesh Jethva Managing users and groups in Linux is essential. It helps keep your system organized and secure. The groupmod command is a powerful tool that allows you to modify existing groups. This article will show you how to use groupmod with clear explanations and practical examples. ## Basic Syntax of groupmod Command Before diving into examples, let’s look at the basic syntax: ```bash groupmod [options] GROUP ``` **Explanation:** - **[options]:** Specifies what you want to change. - **GROUP:** The name of the group you want to modify. Now, let’s explore some common use cases. ## Example 1: Changing a Group Name Sometimes, you may need to rename a group. The -n option in groupmod allows you to do this. ```bash groupmod -n new_group_name old_group_name ``` **Explanation:** - **-n new_group_name**: The new name you want to assign. - **old_group_name**: The current name of the group. After running the command, the group **old_group_name** will be renamed to **new_group_name.** ## Example 2: Changing a Group ID (GID) Each group in Linux has a unique Group ID (GID). Sometimes, you might need to change this ID. ```bash groupmod -g 1001 group_name ``` **Explanation:** - **-g 1001:** The new GID you want to assign. - **group_name:** The name of the group whose GID you want to change. The group **group_name** now has a GID of **1001.** Be cautious, changing the GID can affect file ownership. ## Example 3: Adding or Removing Users from a Group To modify the users in a group, you usually use the usermod command. But you can still make changes using groupmod. **Adding Users:** You add users to a group using gpasswd instead. ```bash gpasswd -a username group_name ``` **Explanation:** - **-a username:** Adds the user to the group. - **group_name:** The group you want to modify. **Removing Users:** ```bash gpasswd -d username group_name ``` **Explanation:** - **-d username:** Removes the user from the group. The user username will be added to or removed from the group_name group. ## Example 4: Locking a Group Locking a group can prevent changes to its membership. This is useful in some security setups. ```bash groupmod -L group_name ``` **Explanation:** - **-L:** Locks the group. - **group_name**: The name of the group you want to lock. The group **group_name** is now locked, preventing any changes. ## Conclusion The groupmod command is a valuable tool in Linux administration. It allows you to make essential changes to your groups quickly. By practicing the examples provided, you can gain confidence and ensure your Linux system remains well-organized. You can now easily modify group attributes on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Understanding CPU Usage Over 100% in top Command Output > URL: https://www.atlantic.net/dedicated-server-hosting/understanding-cpu-usage-over-100-in-top-command-output/ | Published: 2024-08-27 | Updated: 2024-12-05 | Author: Hitesh Jethva When managing a Linux system, monitoring CPU usage is crucial. One of the most popular tools for this is the top command. However, you might have noticed something curious: sometimes, CPU usage can exceed 100%. In this article, we’ll explore why this happens, how top calculates CPU usage, and what it means for your system. ## What Is the top Command? The top command is a real-time system monitor. It provides a dynamic view of the system’s processes, including memory and CPU usage. By default, top updates its output every few seconds, showing which processes consume the most resources. To run top, simply open your terminal and type: ```bash top ``` You’ll see a screen filled with information about your system’s current processes. ```bash Tasks: 325 total, 1 running, 324 sleeping, 0 stopped, 0 zombie %Cpu(s): 4.4 us, 0.0 sy, 0.0 ni, 95.6 id, 0.0 wa, 0.0 hi, 0.0 si, 0.0 st MiB Mem : 7731.5 total, 570.3 free, 4209.5 used, 2951.7 buff/cache MiB Swap: 2048.0 total, 347.3 free, 1700.7 used. 2155.8 avail Mem PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND 6634 vyom 20 0 567248 53416 40440 S 6.2 0.7 2:07.67 gnome-terminal- 108953 vyom 20 0 13344 4224 3328 R 6.2 0.1 0:00.02 top 1 root 20 0 168476 10476 6892 S 0.0 0.1 0:08.03 systemd 2 root 20 0 0 0 0 S 0.0 0.0 0:00.08 kthreadd 3 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 rcu_gp 4 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 rcu_par_gp 5 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 slub_flushwq 6 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 netns 8 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 kworker/0:0H-events_highpri 11 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 mm_percpu_wq 12 root 20 0 0 0 0 I 0.0 0.0 0:00.00 rcu_tasks_kthread ``` ## How CPU Usage is Calculated In top, CPU usage is calculated as a percentage of the CPU’s capacity. This can be a bit tricky because modern CPUs have multiple cores. For a single-core CPU, 100% means full usage. But for a multi-core CPU, top can show usage that exceeds 100%. ### Example of Single-Core vs. Multi-Core Imagine your system has four cores. If one process uses 100% of one core, top shows 100% for that process. But if another process uses 100% of a second core, you could see 200% total CPU usage. This is because top sums the usage across all cores. Here’s a simple way to understand this: - **Single-core CPU**: 100% means full usage. - **Dual-core CPU**: 200% is the maximum (100% per core). - **Quad-core CPU**: 400% is the maximum. ## Why CPU Usage Can Exceed 100% Seeing CPU usage over 100% is normal on multi-core systems. Each core can run at 100%, so on a quad-core CPU, you might see usage go up to 400%. This doesn’t mean your CPU is overworked; it just shows that multiple cores are being utilized. Let’s look at an example. Run the following command to simulate high CPU load: ```bash stress --cpu 4 --timeout 10 ``` In the top output, you’ll notice that CPU usage can exceed 100%. If your system has four cores, it could reach 400%. ```bash Tasks: 331 total, 5 running, 326 sleeping, 0 stopped, 0 zombie %Cpu(s): 99.3 us, 0.7 sy, 0.0 ni, 0.0 id, 0.0 wa, 0.0 hi, 0.0 si, 0.0 st MiB Mem : 7731.5 total, 399.0 free, 4205.2 used, 3127.3 buff/cache MiB Swap: 2048.0 total, 348.2 free, 1699.7 used. 2190.8 avail Mem PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND 109280 vyom 20 0 3708 256 256 R 98.7 0.0 0:03.03 stress 109282 vyom 20 0 3708 256 256 R 98.3 0.0 0:03.04 stress 109283 vyom 20 0 3708 256 256 R 98.3 0.0 0:03.02 stress 109281 vyom 20 0 3708 256 256 R 97.0 0.0 0:02.99 stress ``` Here, each stress process uses nearly 100% of a core, totaling 400%. ## Analyzing top Output Understanding what top shows helps you manage your system better. If CPU usage regularly exceeds 100%, it might indicate that your system is under heavy load. But it could also mean that your system is efficiently using its resources. To analyze CPU usage, focus on these key points: - **%CPU Column**: Shows the percentage of CPU used by each process. - **Overall CPU Usage**: Displayed at the top of the screen, showing the total usage across all cores. - **Load Average**: Indicates the system load over the last 1, 5, and 15 minutes. Values greater than the number of CPU cores suggest a heavily loaded system. ## Conclusion Seeing CPU usage over 100% in top is normal for multi-core systems. It shows that your system is using all available resources. By understanding how top calculates CPU usage and how to interpret the output, you can ensure your system runs smoothly. You can use the top command to view CPU usage when hosting your application on [**dedicated server hosting**](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Use lscpu Command to Display CPU Architecture > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-use-lscpu-command-to-display-cpu-architecture/ | Published: 2024-08-28 | Updated: 2024-12-05 | Author: Hitesh Jethva The lscpu command is a simple tool in Linux that gives you detailed information about your CPU. It shows you everything from the number of cores to the supported instruction sets. This command is compatible with most Linux distributions and is an easy way to gather CPU details. This guide will show you how to use lscpu to get all the information you need. ## Installing lscpu Most Linux distributions come with lscpu pre-installed. If you find it missing, you can easily install it. Here’s how: **For Debian/Ubuntu-based systems:** ```bash apt-get install util-linux ``` **For Red Hat/CentOS-based systems:** ```bash yum install util-linux ``` ## Basic Usage of lscpu Command Using lscpu is straightforward. Just open your terminal and type: ```bash lscpu ``` This command will give you a comprehensive overview of your CPU. Here’s an example output: ```bash Architecture: x86_64 CPU op-mode(s): 32-bit, 64-bit Address sizes: 39 bits physical, 48 bits virtual Byte Order: Little Endian CPU(s): 4 On-line CPU(s) list: 0-3 Vendor ID: GenuineIntel Model name: 11th Gen Intel(R) Core(TM) i3-1115G4 @ 3.00GHz CPU family: 6 Model: 140 Thread(s) per core: 2 Core(s) per socket: 2 Socket(s): 1 Stepping: 1 CPU max MHz: 4100.0000 CPU min MHz: 400.0000 BogoMIPS: 5990.40 ``` Let’s break down what each part of the lscpu output means: - **Architecture:** The CPU is 64-bit, allowing it to handle 64-bit data and applications. - **CPU op-mode(s)**: The CPU supports both 32-bit and 64-bit operations. - **Address sizes:** Can address up to 512 GB of physical memory and 256 TB of virtual memory. - **Byte Order:** Data is stored in Little Endian format, with the least significant byte first. - **CPU(s):** The system has 4 logical CPUs available. - **On-line CPU(s) list:** All 4 CPUs (0 to 3) are active and available for use. - **Vendor ID:** The CPU is manufactured by Intel. - **Model name:** It’s an 11th Gen Intel Core i3 processor running at 3.00 GHz. - **CPU family:** Identifies the CPU as part of Intel’s Family 6, which includes most modern processors. - **Model:** A specific identifier for this CPU within its family. - **Thread(s) per core**: Each core can handle 2 threads, thanks to Hyper-Threading. - **Core(s) per socket**: The CPU has 2 physical cores. - **Socket(s):** There is one physical CPU socket on the motherboard. - **Stepping:** Indicates the revision level of the CPU. - **CPU** **max MHz**: The CPU can boost up to 4.1 GHz under load. - **CPU min MHz**: The CPU can lower its speed to 400 MHz to save power. - **BogoMIPS:** A rough measure of CPU speed, calculated during system boot. ## Filtering and Customizing lscpu Output Sometimes you need specific information. You can filter lscpu output using tools like grep. For example, to show only the CPU model: ```bash lscpu | grep 'Model name' ``` This command will display: ```bash Model name: 11th Gen Intel(R) Core(TM) i3-1115G4 @ 3.00GHz ``` If you want to see if your CPU supports virtualization: ```bash lscpu | grep 'Virtualization' ``` Output: ```bash Virtualization: VT-x ``` You can also format the output for better readability by using the -e flag: ```bash lscpu -e ``` Output: ```bash CPU NODE SOCKET CORE L1d:L1i:L2:L3 ONLINE MAXMHZ MINMHZ MHZ 0 0 0 0 0:0:0:0 yes 4100.0000 400.0000 1003.032 1 0 0 1 1:1:1:0 yes 4100.0000 400.0000 1010.179 2 0 0 0 0:0:0:0 yes 4100.0000 400.0000 1015.344 3 0 0 1 1:1:1:0 yes 4100.0000 400.0000 1020.013 ``` ## Conclusion The lscpu command is a powerful tool that gives you a quick and detailed look into your CPU’s architecture. Whether you’re a system admin, developer, or just curious, understanding your CPU is crucial. Try using lscpu today to explore what your CPU has to offer on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Disable Weak SSH Ciphers > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-disable-weak-ssh-ciphers/ | Published: 2024-08-29 | Updated: 2024-09-09 | Author: Hitesh Jethva SSH (Secure Shell) is the backbone of secure remote connections to your servers. But did you know that using weak SSH ciphers can put your entire system at risk? Weak ciphers can be exploited by attackers, leaving your data exposed. In this guide, we’ll explore how to disable weak SSH ciphers and ensure your connections are as secure as possible. ## Understanding SSH Ciphers SSH ciphers are encryption algorithms that secure your SSH connections. They protect your data as it travels between your computer and the server. There are different types of SSH ciphers, including symmetric, asymmetric, and MACs (Message Authentication Codes). **Symmetric ciphers** use the same key to encrypt and decrypt data. Examples include AES (Advanced Encryption Standard) and 3DES. **Asymmetric ciphers** use a pair of keys: one to encrypt and another to decrypt. RSA (Rivest–Shamir–Adleman) is a common example. ## Identifying Weak SSH Ciphers in Your System Before disabling weak ciphers, you need to identify them. Here’s how to do it: 1. List all available ciphers on your server with this command: ```bash ssh -Q cipher ``` Output: ```bash 3des-cbc aes128-cbc aes192-cbc aes256-cbc aes128-ctr aes192-ctr aes256-ctr aes128-gcm@openssh.com aes256-gcm@openssh.com chacha20-poly1305@openssh.com ``` The list above shows both strong and weak ciphers. Your job is to identify and disable the weak ones. 2. Check the currently enabled ciphers in your SSH configuration file: ```bash nano /etc/ssh/sshd_config ``` Look for the line starting with Ciphers. If it’s not there, you’ll need to add it later. 3. Identify weak ciphers from the list. Common weak ciphers include: ```bash 3des-cbc aes128-cbc aes192-cbc ``` These ciphers are less secure and should be disabled. ## Disabling Weak SSH Ciphers Now that you know which ciphers to disable, let’s edit the SSH configuration file. 1. Open the SSH configuration file: ```bash nano /etc/ssh/sshd_config ``` 2. Add or update the Ciphers line to include only strong ciphers: ```bash Ciphers aes256-ctr,aes192-ctr,aes128-ctr ``` This line ensures that only the strong ciphers are used. You’re telling SSH to ignore the weak ones. 3. Save and exit the file by pressing Ctrl + X, then Y, and Enter. 4. Restart the SSH service to apply the changes: ```bash systemctl restart sshd ``` ## Testing the Configuration After adding the new ciphers, you should test the configuration to make sure everything works correctly. 1. Try to connect to your server using SSH: ```bash ssh -vvv user@your-server-ip ``` The -vvv option enables verbose mode, which shows detailed information about the connection, including which ciphers are being used. Check the ciphers in use in the output. You should see something like this: ```bash debug2: host key algorithms: rsa-sha2-512,rsa-sha2-256,ecdsa-sha2-nistp256,ssh-ed25519 debug2: ciphers ctos: aes256-ctr,aes192-ctr,aes128-ctr debug2: ciphers stoc: aes256-ctr,aes192-ctr,aes128-ctr ``` The above output confirms that your server only uses strong ciphers. 2. Troubleshoot if necessary. If the SSH service fails to restart or if you can’t connect, check the **sshd_config** file for typos or errors. ## Conclusion Securing your SSH connections by disabling weak ciphers is essential for protecting your server. By following this guide, you’ve taken a significant step toward enhancing your system’s security. Remember to regularly review your settings and stay up-to-date with the latest security practices. Try to disable weak ciphers on [**dedicated server hosting**](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Using AI Coding Assistants in a HIPAA-Compliant Environment > URL: https://www.atlantic.net/hipaa-compliant-hosting/using-ai-coding-assistants-in-a-hipaa-compliant-environment/ | Published: 2024-08-30 | Updated: 2026-03-01 | Author: Gilad Maayan ## What Are AI Coding Assistants? AI coding assistants are software tools powered by artificial intelligence that help developers write code more efficiently and accurately. These assistants leverage machine learning algorithms, including large language models (LLMs) in advanced tools, to provide suggestions, detect errors, and automate repetitive coding tasks. By integrating into development environments, they shorten the coding lifecycle and improve the overall coding experience. AI coding assistants have become indispensable tools for many developers, offering support for various programming languages and frameworks. Beyond simple syntax corrections, AI coding assistants can provide context-aware recommendations, write entire code snippets or functions, and refactor code to align with best practices. ![](https://www.atlantic.net/wp-content/uploads/2024/08/AI-coding-assistants.jpg) ## How AI Coding Assistants Work [AI coding assistants](https://www.tabnine.com/) use traditional natural language processing (NLP) algorithms and large language models to understand and generate code. They analyze the context of existing code and offer real-time suggestions that match the developer’s intent. These models are trained on extensive datasets that include various coding languages, styles, and problem-solving approaches, enabling them to make intelligent recommendations. The assistants operate within integrated development environments (IDEs), offering features like code completion, real-time error detection, and code refactoring. Some assistants also integrate with version control systems to suggest improvements based on past projects. The goal is to streamline the coding process, minimize errors, and ultimately increase development efficiency. ## Benefits of AI Coding Assistants in HIPAA-Compliant Environments AI coding assistants enhance code quality by identifying potential bugs, vulnerabilities, and logical errors during the development phase. They apply best practices and coding standards, ensuring that the generated code is both efficient and secure. This is critically important in HIPAA-compliant environments, where data security and integrity are paramount. Additionally, some of these tools include features that assess the security implications of code changes, offering suggestions to mitigate risks. They help ensure that the software adheres to compliance requirements by integrating security checks into the development workflow. ## Challenges of Using AI Coding Assistants in HIPAA-Compliant Environments ### Data Privacy and Security Risks While coding assistants can contribute to secure coding practices, integrating AI coding assistants in HIPAA-compliant environments can also create new data privacy and security risks. These tools need access to code repositories, some of which may contain sensitive patient information. If not properly managed, this access can lead to unauthorized data exposure. Ensuring that AI assistants adhere to strict data handling protocols is crucial to prevent security breaches. Moreover, the AI models themselves require regular updates and maintenance, which can introduce vulnerabilities if not handled securely. Organizations must implement robust security measures, including encryption and secure access controls, to protect sensitive data from potential threats. Continuous monitoring and auditing of AI tools are essential to detect and mitigate any emerging risks promptly. ### Model Training and Data Handling Concerns AI coding assistants rely on large datasets for training, which may include proprietary or sensitive information. In HIPAA-compliant environments, this can be problematic due to strict data privacy regulations. Ensuring that the data used for training is anonymized and secure is essential to prevent any compliance violations. Organizations must also be cautious about using third-party AI models that might not meet HIPAA standards. Furthermore, the data-handling practices of AI tool providers need thorough vetting to ensure compliance with HIPAA regulations. This includes understanding how data is collected, stored, processed, and shared. Any deviation from compliance can lead to significant legal and financial repercussions for the organization. Therefore, effective data governance and robust due diligence are essential when integrating AI coding assistants. ### Lack of Clear Regulatory Guidelines The rapid advancement of AI technology has outpaced the development of regulatory guidelines, leading to ambiguity in compliance requirements. HIPAA regulations were initially designed with traditional software development in mind and do not explicitly address the nuances of AI-assisted coding. This creates challenges for organizations trying to maintain compliance while leveraging the benefits of AI tools. Organizations must navigate this uncertainty by implementing best practices informed by general compliance principles and seeking guidance from legal and compliance experts. Collaboration with regulatory bodies to develop more specific guidelines for AI in healthcare can also help bridge this gap. Until clearer regulations are established, a cautious and well-documented approach to adopting AI coding assistants is advisable. ## Best Practices for Ensuring HIPAA Compliance with AI Coding Assistants ### Selecting HIPAA-Compliant AI Tools Choosing HIPAA-compliant AI coding assistants is the first step towards ensuring data privacy and security. Organizations should rigorously evaluate the compliance credentials of AI tool providers, including their adherence to data protection standards and audit practices. Contracts and service-level agreements (SLAs) should explicitly state the compliance obligations and responsibilities of both parties. Additionally, selecting tools with built-in compliance features, such as automated data anonymization and secure access controls, can significantly reduce the risk of non-compliance. It’s also beneficial to choose AI assistants that offer detailed logging and auditing capabilities, allowing for continuous monitoring and verification of compliance adherence. ### Implementing Robust Access Controls Implementing robust access controls is crucial to safeguard sensitive data when using AI coding assistants. Organizations should ensure that only authorized personnel have access to data and development environments. Role-based access controls (RBAC) can help restrict access based on job responsibilities and minimize the potential for data breaches. Furthermore, employing multi-factor authentication (MFA) adds an additional layer of security, making it more challenging for unauthorized users to gain access. Regularly reviewing and updating access permissions ensures that access controls remain effective and aligned with organizational changes. Continuous monitoring of access logs can help detect and respond to any unauthorized access attempts promptly. ### Data Anonymization and Encryption Anonymizing and encrypting data are vital practices for maintaining HIPAA compliance when using AI coding assistants. Data anonymization removes personally identifiable information (PII), ensuring that any data used by AI tools cannot be traced back to individuals. Encryption, both in transit and at rest, ensures that data remains secure from potential breaches. Organizations should implement strong encryption protocols and verify that AI tool providers adhere to these standards. Regular audits of encryption practices and anonymization processes are necessary to ensure ongoing compliance. By prioritizing data anonymization and encryption, organizations can significantly reduce the risk of data exposure and maintain the integrity of patient information. ### Training and Awareness for Developers Regular training and awareness programs for developers are essential to ensure HIPAA compliance when using AI coding assistants. Developers must understand the importance of data privacy and security and be well-versed in the compliance features and limitations of the AI tools they use. Ongoing education on regulatory updates and best practices ensures that developers remain compliant as they adapt to new technologies. Moreover, fostering a culture of security and compliance within the development team can enhance vigilance and proactive risk management. Providing resources, guidelines, and support for developers helps them incorporate compliance considerations into their daily workflows. ## Conclusion AI coding assistants offer significant benefits by enhancing developer productivity, improving code quality, and embedding compliance into the development process. In HIPAA-compliant environments, they can streamline workflows and reduce the risks associated with manual coding errors. However, these benefits come with challenges, including data privacy risks, model training concerns, and a lack of clear regulatory guidelines. To mitigate these challenges, organizations must adopt best practices such as selecting HIPAA-compliant tools, implementing robust access controls, and ensuring data anonymization and encryption. Ongoing training and awareness programs for developers are also essential. By taking these steps, organizations can leverage the advantages of AI coding assistants while maintaining stringent compliance with HIPAA regulations. ### How Can Atlantic.Net Help? Atlantic.Net’s [HIPAA Hosting Solutions](https://www.atlantic.net/hipaa-compliant-hosting/) are especially ideal for companies in the healthcare vertical to help cope with rapidly increasing infrastructure needs. Atlantic.Net has over thirty years of experience, with expert staff that are available to assist you and your company’s needs 24/7. Contact us today, and we will work with you to create a custom [HIPAA Cloud Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) Solution that is perfect for your business. **Author Bio: Gilad David Maayan** ![](https://www.atlantic.net/wp-content/uploads/2023/10/giladimage.jpg) Gilad David Maayan is a technology writer who has worked with over 150 technology companies including SAP, Imperva, Samsung NEXT, NetApp and Check Point, producing technical and thought leadership content that elucidates technical solutions for developers and IT leadership. Today he heads [Agile SEO](https://agileseo.co.il/), the leading marketing agency in the technology industry. LinkedIn: [LinkedIn](https://www.linkedin.com/in/giladdavidmaayan/) --- # Managed VPS vs. Unmanaged VPS: What’s the Difference? > URL: https://www.atlantic.net/vps-hosting/managed-vps-vs-unmanaged-vps/ | Published: 2024-08-31 | Updated: 2024-09-09 | Author: Richard Bailey A VPS is a high-performance server partitioned into multiple isolated virtual environments, each operating as a standalone server equipped with its dedicated operating system and resources. When choosing a VPS, you’ll need to decide between an unmanaged or managed server. Each service offering gives distinct advantages and disadvantages, and managed hosting can cater to the different levels of technical expertise and business needs that customers have. You choose to either include a wrap-around service (managed) where a team of experts look after the server 24×7, or you go it alone with unmanaged VPS hosting and handle everything yourself. In this article, we’ll explore and uncover the key differences between managed VPS servers and unmanaged VPS hosting. The aim is to provide you with enough information to make an informed decision about which hosting service is best for you. ## Managed VPS Hosting Managed VPS hosting is a popular choice for businesses that prefer a “hands-off, more control” approach to server management. In this model, the hosting provider takes care of the core technical aspects of the virtual server, including server management, security measures, and application management. Some of the key features of Managed VPS hosting include: ### #1: Server Setup and Configuration The hosting provider takes care of the initial setup, installing the operating system, and configuring essential software components. ### #2: Software Updates and Security Patches The provider ensures that the server’s operating system and software are kept up to date, minimizing the risk of security vulnerabilities and ensuring optimal performance. ### #3: Dedicated Support Team Managed VPS hosting typically includes access to a technical support team, ready to assist with any server-related issues you may encounter. You may also get access to a Network Operation Center that proactively monitors and maintains your servers. ### #4: User-Friendly Control Panel The Atlantic.Net managed VPS plans include a user-friendly control panel, making it easier to manage websites, databases, and email accounts without extensive technical knowledge. You get a detailed overview of your infrastructure and can look at performance logs, uptime, and events. ### #5: Automatic Backups Regular backups of your data are often included, protecting against data loss and enabling easy recovery in case of any unforeseen events. ## **Who is Managed VPS Hosting For?** Managed VPS hosting presents an ideal solution for individuals or businesses seeking the power and flexibility of a [Virtual Private Server (VPS)](https://www.atlantic.net/vps-hosting/) without the complexities of server administration. It caters perfectly to website owners experiencing moderate to high traffic volumes, particularly those running dynamic platforms like a WordPress site or e-commerce stores. For these users, reliable performance and minimal downtime are expected. Additionally, the assurance of automatic updates and a dedicated support team to swiftly address any technical issues offers invaluable peace of mind, allowing our customers to focus on their core business objectives. ## Unmanaged VPS Hosting Unmanaged VPS hosting offers greater control and flexibility but also requires more technical knowledge and responsibility. In this model, the hosting provider provides the virtual server and its underlying infrastructure but leaves the server management tasks to the user. Essentially the user is left to their own devices, but with the added peace of mind that Atlantic.Net dedicated support teams are available 24×7 if any help is needed. ### #1: Full Root Access and Full Control Unmanaged VPS grants root access, allowing users complete control over the server’s configuration, software installations, and customization. You control the operating system, the update frequency, the backup policy, and how to manage the applications. ### #2: Customization Freedom Users have the freedom to install and configure any software or applications they need, tailoring the server environment to their specific requirements. You control user access, server hardening, and security. ### #3: Cost-Effectiveness Unmanaged VPS hosting is generally more cost-effective than managed hosting, as users are not paying for additional server management services from hosting providers such as managed backup, server management, or anti-virus management. Unmanaged VPS hosting is the ideal choice for technically inclined individuals and businesses who value autonomy and customization. It provides an unparalleled level of control, allowing you to craft the perfect virtual private server environment to meet your specific needs. While this model requires technical proficiency, the potential rewards in terms of performance, flexibility, and cost savings are substantial. With great power comes great responsibility. Unmanaged VPS hosting demands a solid understanding of server administration and is typically used by established businesses. If you’re not comfortable with these tasks, a managed VPS server and hosting might be a more suitable option. However, if you’re ready to embrace the challenge and unleash your inner sysadmin, unmanaged VPS hosting offers a world of possibilities at your fingertips. ## Unmanaged vs Managed VPS: Key Differences When choosing between managed vs unmanaged VPS, understanding the core distinctions is vital. Let’s discover the key differences that will help you make an informed decision. - **Control**: Unmanaged VPS hosting offers complete control over your server environment, allowing you to configure everything from the operating system to security measures. However, this level of control requires technical expertise to handle server management independently. On the other hand, managed VPS saves time and simplifies server management, taking care of technical tasks like updates and security configurations to protect against potential threats. While this offers convenience, you’ll have less direct control over your hosting environment. - **Cost Considerations:** Generally, unmanaged VPS hosting is less expensive as you’re essentially renting a virtual machine on a physical server. Managed VPS server hosting comes at a higher cost as it includes the expertise of the hosting provider to manage your server. - **Technical Skills**: Unmanaged VPS is best suited for individuals or businesses with the technical skills to manage a server. It’s ideal if you enjoy the learning curve and want the freedom to customize your hosting experience. In contrast, managed hosting is perfect for those who prefer to focus on their website or business without worrying about server administration. ## Factors to Consider When Choosing Between Managed and Unmanaged VPS Unmanaged VPS offers an ideal solution for tech-savvy individuals and businesses who crave greater control and the ability to fine-tune their server resources for multiple websites or complex personal sites. This option lets users both handle server management independently and delve deep into the server’s configuration options, optimizing performance and tailoring the hosting environment to their specific needs. Managed VPS provides a hassle-free experience for those new to web hosting or those who simply prefer to focus their time and energy elsewhere. By entrusting server management to experts like Atlantic.Net, businesses and individuals alike can prioritize their core operations, confident that their own website will run smoothly and securely in the background. This hands-off approach is particularly beneficial for established businesses seeking to streamline their IT operations without sacrificing website performance. To recap, remember these key points: - **Technical Expertise:** If you lack in-house technical skills, managed VPS is a safer and more convenient option. - **Budget**: Unmanaged VPS is generally more cost-effective, but consider the potential costs of hiring technical support, consultancy, or experiencing downtime due to misconfiguration. - **Control and Flexibility**: Unmanaged VPS offers greater control and customization freedom, while managed VPS prioritizes ease of use and convenience. - **Business Needs:** Consider the specific requirements of your website or application and choose the hosting solution that best aligns with your needs. ## Managed and Unmanaged VPS: Finding the Middle Ground Some hosting providers like Atlantic.Net offer a middle ground between fully managed and unmanaged VPS, providing managed support for specific tasks such as server setup, security, and backups, while leaving other aspects of server management to the user. Atlantic.Net engineers will be involved as much or as little as you like. Everyone has access to our expert support teams around the clock – it doesn’t matter if you are managed or using unmanaged hosting, Atlantic.Net is available 24x7x365. Everyone gets out 100% Uptime SLA. This can be a good option for businesses seeking a balance between convenience and control. ## Choosing the Right VPS Hosting for Your Success Whether you opt for managed or unmanaged, VPS hosting, the key is to choose a reliable hosting provider with a strong reputation for performance, security, and customer support. Consider your technical expertise, budget, and business needs to make an informed decision that backs your online success. If you have any further questions about managed hosting vs unmanaged hosting or VPS or need assistance choosing the right hosting solution for your business, [feel free to reach out to our expert support team](https://www.atlantic.net/support/). We are always happy to help! We hope you have found this article helpful, remember: Your hosting choice can significantly impact your website’s performance, security, and overall user experience. Make sure to choose your web hosting providers wisely and invest in a hosting solution that supports your business growth and online success. ## Atlantic.Net: Your Trusted Hosting Partner At Atlantic.Net, we offer both managed and unmanaged VPS hosting options to cater to businesses of all sizes and technical expertise. Our cloud VPS hosting solutions provide dedicated servers with premium hardware resources, ensuring optimal performance and reliability for hosting your website or application. We are committed to providing exceptional customer support and empowering businesses to focus on their core activities while we handle the technical complexities of shared hosting and server management. [Contact us today to learn more about our VPS](https://www.atlantic.net/about-us/corporate-contact/) shared hosting services and how we can help you achieve your online goals.   --- # How to Remove the Password From Your SSL Key > URL: https://www.atlantic.net/vps-hosting/how-to-remove-password-ssl-key/ | Published: 2024-09-01 | Updated: 2024-12-05 | Author: Richard Bailey A common security measure used to protect SSL certificates is encrypting your SSL certificate and key file with a password or new passphrase. An SSL certificate (or Self Signed Certificate) is used to authenticate a website’s identity and enable encrypted connections, safeguarding all sensitive data transmitted between users and the server. A crucial component of an SSL certificate is the private key, a cryptographic file that must be kept confidential. To enhance security, private keys are often protected with a password or pass phrase. However, certain scenarios, such as automated processes or specific configurations, might require removing this password. In this guide, we’ll explore the process of removing the password from your SSL key file using OpenSSL, a powerful command-line tool widely used for cryptographic operations. ## Understanding the Importance of Private Keys Before we demonstrate the process of removing the password, let’s briefly explain the importance of private keys. In the SSL/TLS handshake, the private key is used to decrypt messages encrypted with the corresponding public key. If your private key is compromised, an attacker could impersonate your website, intercept sensitive data, or even carry out man-in-the-middle attacks. Therefore, safeguarding your private keys must be a top priority. ## **How To Use OpenSSL Remove Password From Key** OpenSSL provides a straightforward way to remove passphrase from the SSL key. The command takes your password protected private key, and prompt you for the password, removes the password, then outputs a new key with no password and encrypted headers. ``` openssl rsa -in yourSSLkey.key -out yourSSLkeywithnopassword.key ``` Let’s break down what’s happening here: - **openssl rsa:** This invokes the OpenSLL utility. - **-in yourSSLkey.key:** Specifies the input file, which is your original SSL key file containing the password. - **-out yourSSLkeywithnopassword.key:** Specifies the output file, where the new key without a password will be stored to a new RSA private key. When you run this command, you’ll be prompted to enter the password for your original key. Once you provide the correct password, OpenSSL will create a new key file (yourSSLkeywithnopassword.key) that is identical to the original but without password protection. ## **Working with a Private Key File** Private key files typically have the .key extension and are stored in the Privacy-Enhanced Mail (PEM) format. A PEM file is a text files that contain Base64-encoded data, making them easy to share, manage or view in a text editor. ## **Important Considerations** - **Security:** Removing the password from your SSL key reduces its security. Only do this if absolutely necessary and take steps to protect the unencrypted key file. - **Backups:** Always create a backup of your original key file before removing the password. - **Alternative:** If you need to use the key without a password temporarily, consider using openssl rsa -in yourSSLkey.key to decrypt it in memory rather than creating an unencrypted output file Removing the password from your OpenSSL key can be useful in certain situations, but it’s important to understand the security implications. By following the steps outlined in this guide and using OpenSSL’s powerful capabilities, you can manage your SSL keys effectively while maintaining a balance between convenience and security. --- # Simplify Linux Permissions with the getfacl Command > URL: https://www.atlantic.net/dedicated-server-hosting/simplify-linux-permissions-with-the-getfacl-command/ | Published: 2024-09-02 | Updated: 2024-12-05 | Author: Hitesh Jethva File permissions in Linux ensure that only authorized users can access or modify files. The traditional permission model uses rwx (read, write, execute) for the user, group, and others. But what if you need more fine-grained control? That’s where Access Control Lists (ACLs) come in. ACLs allow you to set specific permissions for individual users or groups. The getfacl command is a handy tool that lets you view these ACLs. This guide will walk you through how to use getfacl with clear examples. ## Introduction to the getfacl Command The getfacl command is straightforward. It lets you view the ACLs of any file or directory. Here’s the basic syntax: ```bash getfacl [OPTION] file_name ``` This command shows who has what permissions on a file or directory. Before you use ACLs, ensure your filesystem supports them. Most modern filesystems like ext4 and XFS do. Let’s dive into some practical examples to understand how getfacl works. ## Example 1: Viewing the ACLs of a File To see the ACLs of a file, use the following command: ```bash getfacl myfile.txt ``` Here’s what the output might look like: ```bash # file: myfile.txt # owner: vyom # group: vyom user::rw- group::rw- other::r-- ``` In this example: - **user::rw-** shows the owner’s permissions. - **group::rw-** shows the group’s permissions. - **other::r–** shows permissions for all other users. ## Example 2: Viewing the ACLs of a Directory Directories can have default ACLs. These are inherited by new files created in the directory. To view the ACLs of a directory, run: ```bash getfacl mydirectory ``` Output: ```bash # file: mydirectory # owner: vyom # group: vyom user::rwx group::rwx other::r-x ``` In this case, any new file in mydirectory will inherit the default ACLs, ensuring consistency. If you want to list ACLs for all files in a directory, use the -R flag: ```bash getfacl -R mydirectory ``` This command displays the ACLs of all files and subdirectories within mydirectory. ## Example 3: Combining getfacl with Other Commands You can combine getfacl with setfacl to manage and copy ACLs. For instance, if you want to copy ACLs from one file to another: ```bash getfacl sourcefile | setfacl --set-file=- targetfile ``` This command ensures that targetfile has the same ACLs as sourcefile. ## Conclusion ACLs are a powerful tool in Linux for managing permissions beyond the traditional model. The getfacl command makes it easy to view and understand these permissions. Explore getfacl in your system, and see how it can simplify your permission management tasks on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Extract Specific Columns from Files in Linux with grep, sed, and awk > URL: https://www.atlantic.net/dedicated-server-hosting/extract-specific-columns-from-files-in-linux-with-grep-sed-and-awk/ | Published: 2024-09-04 | Updated: 2024-09-09 | Author: Hitesh Jethva When you work with text files in Linux, you’ll often need to extract specific columns. Whether you’re dealing with CSV files, logs, or any tabular data, Linux command-line tools like grep, sed, and awk can make this task easy. This guide will show you how to use these tools to get the data you need. ## Using grep to Extract Specific Columns grep is a simple and efficient tool for searching text. But when it comes to extracting columns, grep needs help from other tools like cut. Here’s how you can use them together. **Example: Extracting a column with grep and cut** Suppose you have a file data.txt with the following content: ```bash Name Age Location Alice 30 New York Bob 25 Los Angeles Charlie 35 Chicago ``` You want to extract the “Age” column. First, use grep to filter the lines you need: ```bash grep -v "Name" data.txt | cut -d ' ' -f 2 ``` Output: ```bash 30 25 35 ``` Here’s what happens: - **grep -v “Name”** filters out the header line. - **cut -d ‘ ‘ -f 2** splits the line by spaces and selects the second field. ## Using sed to Extract Specific Columns sed is a stream editor, perfect for text substitution and simple data extraction. You can use sed to extract columns by combining it with the cut command. **Example: Using sed to remove unwanted parts** Imagine you have the same data.txt file, and you want to extract the “Location” column: ```bash sed '1d' data.txt | cut -d ' ' -f 3 ``` Output: ```bash New York Los Angeles Chicago ``` Here’s how it works: - **sed ‘1d’** deletes the first line (the header). - **cut -d ‘ ‘ -f 3** extracts the third field. ## Using awk to Extract Specific Columns awk is the powerhouse of text processing. It’s designed for extracting and processing text, especially when working with columns. **Example: Extracting columns with awk** Let’s extract both “Name” and “Location” from the data.txt file: ```bash awk '{print $1, $3}' data.txt ``` Output: ```bash Name Location Alice New York Bob Los Angeles Charlie Chicago ``` Explanation: **awk ‘{print $1, $3}’** tells awk to print the first and third columns. ## Skipping the header You might want to skip the header when extracting data: ```bash awk 'NR>1 {print $1, $3}' data.txt ``` Output: ```bash Alice New York Bob Los Angeles Charlie Chicago ``` In this example: **NR>1** ensures awk only processes lines after the first one. ## Conclusion You now know how to extract specific columns from files using grep, sed, and awk. Each tool has its strengths, and knowing when to use which one can make your work with text files much more efficient. Start practicing with your own files on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Retrieve Console Geometry in a Bash Script > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-retrieve-console-geometry-in-a-bash-script/ | Published: 2024-09-05 | Updated: 2024-09-09 | Author: Hitesh Jethva Console geometry refers to the dimensions of the terminal window—specifically, the number of columns and rows. These values determine how much text can fit on a single line and how many lines can be displayed at once. Knowing the size of the terminal allows your script to adapt its output, avoiding awkward line breaks or misaligned text. In this article, we’ll walk through how to retrieve console geometry, explain why it’s useful, and show you practical examples. ## Retrieving Console Geometry in Bash There are a few ways to retrieve the console geometry in a Bash script. We’ll cover three methods: using tput, stty, and command substitution. ### Method 1: Using tput The tput command is a simple way to get terminal dimensions. Here’s how you can use it: ```bash #!/bin/bash # Get the number of columns cols=$(tput cols) # Get the number of rows rows=$(tput lines) echo "Terminal size: ${cols} columns, ${rows} rows" ``` In this script, tput cols returns the number of columns, and tput lines returns the number of rows. We store these values in variables and then print them out. The above script will produce the following output. ### Method 2: Using stty Another way to retrieve terminal size is with the stty command: ```bash #!/bin/bash # Get terminal size size=$(stty size) rows=$(echo $size | cut -d' ' -f1) cols=$(echo $size | cut -d' ' -f2) echo "Terminal size: ${cols} columns, ${rows} rows" ``` The stty size command gives you the number of rows and columns in a single line. We split this line into two variables using the cut command. After running the above script, the output looks like shown below: ```bash Terminal size: 168 columns, 43 rows ``` ### Method 3: Using Command Substitution Command substitution lets you combine commands to get the geometry in one go: ```bash #!/bin/bash # Get terminal size cols=$(echo $(stty size) | cut -d' ' -f2) rows=$(echo $(stty size) | cut -d' ' -f1) echo "Terminal size: ${cols} columns, ${rows} rows" ``` This method is similar to the stty example, but it uses command substitution to streamline the process. You will get the following result after running the script. ```bash Terminal size: 168 columns, 43 rows ``` ## Using Geometry Values in a Script Now that you know how to get the terminal size, let’s use these values in a script. For instance, you might want to center some text based on the terminal width: ```bash #!/bin/bash # Get terminal size cols=$(tput cols) # Text to display text="Welcome to Bash Scripting!" # Calculate the position to center the text padding=$((($cols - ${#text}) / 2)) # Print the centered text printf "%${padding}s%s\n" "" "$text" ``` Here, **${#text}** gets the length of the text string, and padding calculates how much space to add on the left to center the text. This script will generate the following output. ```bash Welcome to Bash Scripting! ``` ## Conclusion Retrieving console geometry in a Bash script is a valuable skill. It allows you to make your scripts more interactive and responsive to the user’s environment. Whether you use tput, stty, or command substitution, these methods allow you to format your output dynamically. Now that you know how to retrieve and use console geometry. You can start making your scripts more user-friendly and adaptable on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # HIPAA Security Rule: Concepts, Requirements, and Compliance Checklist > URL: https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/ | Published: 2024-09-06 | Updated: 2026-09-15 | Author: Richard Bailey ## **What Is the HIPAA Security Rule?** The HIPAA Security Rule is a set of standards created to protect electronic protected health information (ePHI). Enacted under the Health Insurance Portability and Accountability Act (HIPAA), the Security Rule specifically addresses the technical and non-technical safeguards that organizations, known as covered entities, must implement to secure ePHI. The Security Rule applies to any healthcare provider, health plan, or healthcare clearinghouse that transmits health information in electronic form. Unlike the HIPAA Privacy Rule, which governs the overall protection of PHI in all formats, the Security Rule focuses solely on ePHI. It requires covered entities to ensure the confidentiality, integrity, and availability of ePHI, guarding against potential threats, unauthorized access, or misuse of the data. The Security Rule is structured to be flexible and scalable, allowing organizations of different sizes and capabilities to implement appropriate protections. This is part of a series of articles about [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). ## **What Is PHI?** Defining what classifies protected health information (PHI) is critical for a covered entity. Essentially, PHI is any individually identifiable health information. You may also encounter the acronym ePHI or e-PHI, or electronic protected health information. Electronic protected health information is protected health information stored or accessed in an electronic format. Common examples include: - Treatment reports - Test results - Prescription information - Any information that includes the name - Phone numbers - Addresses - Social security numbers - Medical records numbers - Health insurance details ![](https://www.atlantic.net/wp-content/uploads/2024/09/What-is-the-HIPAA-Security-Rule_What-is-PHI-05.jpg) ## What Are the Three Standards of the HIPAA Security Rule? The HIPAA Security Rule is organized around three primary standards: 1. **Administrative Safeguards:** These are the policies and procedures designed to manage the selection, development, implementation, and maintenance of security measures to protect ePHI. Key components include conducting risk assessments, assigning security responsibilities, developing security policies, and providing workforce training. 2. **Physical Safeguards:** These involve the protection of physical access to electronic information systems and the facilities where they are housed. Physical Safeguards cover access controls, device and media controls, and workstations, ensuring that only authorized individuals have access to sensitive areas and equipment. 3. **Technical Safeguards:** These are the technology and policies that protect ePHI and control access to it. Technical Safeguards include implementing access controls, audit controls, integrity controls, and transmission security measures. They ensure that ePHI is accessed only by authorized individuals and remains unaltered during storage or transmission. ## How to Comply with HIPAA Security Rule: Compliance Checklist Below are the main steps required to comply with each of the three standards of the HIPAA Security Rule. ### Complying with Administrative Safeguards 1. **Conduct a Risk Analysis:** To comply with the Administrative Safeguards under the HIPAA Security Rule, organizations must first conduct a comprehensive risk analysis. This involves identifying potential risks to the confidentiality, integrity, and availability of ePHI, assessing all areas where ePHI is stored, accessed, or transmitted, and documenting the findings to establish a baseline for future assessments. 2. **Develop a Risk Management Plan:** After identifying the risks, organizations must develop and implement a risk management plan. This plan outlines specific actions to mitigate identified risks, prioritizing these actions based on the severity of each risk and its potential impact on ePHI. The plan should also include the selection of security measures tailored to the organization’s size, complexity, and operational capabilities. 3. **Appoint a Security Officer:** A critical step in compliance is appointing a Security Officer responsible for overseeing the development and implementation of security policies and procedures. The Security Officer acts as the main point of contact for all security-related issues and ensures that the organization’s security measures are aligned with HIPAA requirements. 4. **Implement Workforce Training:** Workforce training is essential for compliance. All employees, from executives to front-line staff, must be trained on the organization’s security policies and procedures. This training should be continuous, with regular updates to address new threats and technological changes, ensuring employees can recognize and report potential security incidents. 5. **Establish Incident Response Procedures:** Organizations must have procedures for managing and responding to security incidents, including a clear incident response plan. This plan should detail steps to take in the event of a breach, such as containment, investigation, remediation, and reporting. Regular testing and updating of the plan are necessary to ensure it remains effective against evolving threats. 6. **Conduct Regular Evaluations:** Regular evaluations of security measures are essential to maintaining compliance. These evaluations assess the effectiveness of current safeguards and identify areas needing improvement. The evaluation process should be dynamic, incorporating feedback from past incidents and changes in the organization’s risk profile. ### Complying with Physical Safeguards 1. **Control Access to Facilities:** To comply with the Physical Safeguards, organizations must focus on protecting the physical environment where ePHI is accessed, stored, or transmitted. This begins with implementing access controls, such as locked doors, security badges, and biometric systems, to ensure only authorized personnel can enter sensitive areas. 2. **Monitor and Document Access:** Organizations must monitor and document who enters and exits areas containing ePHI. This can be achieved through visitor logs, security cameras, and other monitoring systems. Regular reviews of these records are crucial to detect and address any unauthorized access attempts. 3. **Secure Workstations:** Workstation security is another key aspect of Physical Safeguards. Organizations must ensure that workstations used to access ePHI are secure, which involves placing computers in safe locations, using privacy screens to prevent unauthorized viewing, and implementing automatic screen locks to protect unattended devices. 4. **Manage Mobile Device Security:** Mobile devices pose unique security challenges due to their portability. Organizations must implement security measures such as encryption, remote wiping capabilities, and strict access controls on mobile devices. Employees should be trained on these security protocols and the procedures to follow if a device is lost or stolen. 5. **Manage Hardware and Media Lifecycle:** Proper management of the lifecycle of hardware and media containing ePHI is crucial. Organizations need procedures for the secure disposal or reuse of equipment like hard drives and USB drives, including using certified data destruction services or physical destruction methods to ensure ePHI cannot be recovered. 6. **Implement Environmental Security Controls:** Environmental security controls are vital for protecting physical infrastructure. This includes measures such as fire suppression systems, climate control, and emergency power solutions that help safeguard against environmental threats like fires, floods, or power outages, thereby maintaining the availability and integrity of ePHI. ### Complying with Technical Safeguards 1. **Implement Access Controls:** Technical Safeguards focus on technologies and policies that protect ePHI from unauthorized access, alteration, or destruction. Implementing robust access controls is essential, including assigning unique user IDs to track access and using role-based access to ensure users only access necessary information based on their job functions. 2. **Establish Emergency Access Procedures:** Organizations must establish and document emergency access procedures to ensure authorized individuals can access ePHI during emergencies. These procedures should be regularly tested to ensure they are effective in crisis situations. 3. **Deploy Audit Controls:** Audit controls are a critical component of Technical Safeguards. Organizations must use systems that log user access, changes to ePHI, and security-related events. Regular review of audit logs is necessary to detect unauthorized activities, and logs must be protected from tampering to maintain their integrity. 4. **Maintain ePHI Integrity:** To maintain the integrity of ePHI, organizations should use integrity controls like checksums or hash functions to prevent data alteration or corruption. If an integrity breach is detected, processes must be in place to recover and verify the original ePHI. 5. **Ensure Transmission Security:** Transmission security is essential for protecting ePHI when transmitted electronically. Encryption is a primary technology for safeguarding ePHI during transmission, making data unreadable without the appropriate decryption keys. Organizations should also employ secure communication channels like VPNs or TLS. 6. **Continuously Monitor and Update Technical Safeguards:** Continuous monitoring and updating of technical safeguards are necessary to address new vulnerabilities and threats. This includes applying software patches, updating encryption protocols, and conducting regular security assessments to ensure all technical measures remain effective against the latest threats. ![](https://www.atlantic.net/wp-content/uploads/2024/09/What-is-the-HIPAA-Security-Rule_What-is-a-Covered-Entity-.png) ## What Is a Covered Entity? Covered Entities (CE) are organizations that handle PHI or e-PHI during day-to-day business operations.  A Covered Entity must abide by HIPAA regulations, including the HIPAA Security Rule, which are enforced by the HSS. The U.S. Department of Health and Human Services (HHS) [officially defines](https://www.hhs.gov/hipaa/for-professionals/covered-entities/index.html) a Covered Entity as belonging to one of the following groups: - Healthcare Providers – such as doctors, dentists, nursing homes, pharmacies, etc. - Health Plans – health insurance companies, HMOs, Medicare, Medicaid, etc. - Clearinghouses – transcription services, etc. ![](https://www.atlantic.net/wp-content/uploads/2024/09/What-is-the-HIPAA-Security-Rule_WHAT-IS-A-COVERED-ENTITY.jpg) ![](https://www.atlantic.net/wp-content/uploads/2024/09/What-is-the-HIPAA-Security-Rule_What-is-a-Business-Associate-.png) ## How Are [Business Associates Affected by the HIPAA Security Rule?](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) Business Associates are organizations that work with Covered Entities in handling e-PHI or PHI. Just as a Covered Entity must abide by HIPAA regulations in handling e-PHI or PHI, so too must any Business Associate they work with. Atlantic.Net is a Business Associate of each healthcare organization with whom we process, store, manage or otherwise deal with electronic protected health information. ![](https://www.atlantic.net/wp-content/uploads/2024/09/What-is-the-HIPAA-Security-Rule_What-is-a-Business-Associate.jpg) What is a Business Associate (BAA)? Therefore, we are legally obliged to sign a contract of service with each organization to guarantee our HIPAA compliance status. We outline our security policies and procedures and our administrative, physical, and technical safeguards that detail how we maintain the confidentiality, integrity, and availability of electronic protected health information. ![](https://www.atlantic.net/wp-content/uploads/2024/09/What-is-the-HIPAA-Security-Rule_What-is-the-Privacy-Rule-of-HIPAA-.png) ## HIPAA Security Rule vs. Privacy Rule: What Is the Difference? **The HIPAA Security Rule** focuses exclusively on protecting electronic protected health information (ePHI) by setting standards for how ePHI must be stored, accessed, and transmitted securely. It mandates administrative, physical, and technical safeguards that covered entities and business associates must implement to ensure the confidentiality, integrity, and availability of ePHI. **The HIPAA Privacy Rule** applies more broadly, covering all forms of protected health information (PHI), whether it is electronic, paper-based, or oral. The Privacy Rule sets standards for how PHI can be used and disclosed, establishing individuals’ rights over their health information, such as the right to access their records or request corrections. While the Security Rule deals with how ePHI is protected, the Privacy Rule governs how PHI is shared, emphasizing the need for patient consent and limiting unauthorized disclosures. ### ***Secure HIPAA Compliant Hosting*** *Are you in need of an infrastructure that can protect the health data of your organization? At Atlantic.Net, we can offer a secure*[*HIPAA-Compliant Hosting*](https://www.atlantic.net/hipaa-compliant-hosting/)*solution. Get a free consultation today!* Learn more about our [HIPAA-compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions. #### **Written by Richard Bailey** Linux, Cloud, and Lead IT Consultant with 30 years of experience.  Graduate of the University of Bradford, England. Enthusiastic about Technology, Automation, and Infrastructure as Code. Passionate writer, keen to understand and disseminate as much technical knowledge as possible ### *This article was updated with the most recent information on September 3, 2024.* --- #### Read More About HIPAA Compliance - [HIPAA Compliance Checklist](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) - [How to Become HIPAA Compliant](https://www.atlantic.net/hipaa-compliant-hosting/how-to-become-hipaa-compliant/) - Top Considerations for [HIPAA File Storage](https://www.atlantic.net/hipaa-compliant-hosting/top-10-considerations-for-hipaa-compliant-file-storage/) - [HIPAA Data Storage Requirements](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-cloud-storage/) - Protecting [e-PHI](https://www.atlantic.net/hipaa-compliant-hosting/protecting-phi-cloud/) in the Cloud - What Is [HIPAA Cloud Computing](https://www.atlantic.net/hipaa-compliant-hosting/what-is-hipaa-cloud/)? - What Is [Healthcare Hosting](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/)? - [What Is PHI?](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) --- --- # How to Install and Use ‘locate’ on an Ubuntu Server > URL: https://www.atlantic.net/vps-hosting/how-to-install-locate-ubuntu-vps/ | Published: 2024-09-07 | Updated: 2025-05-25 | Author: Richard Bailey In this procedure, you will learn how to improve your file management skills on the Linux operating system with locate, a powerful command-line tool for efficient indexed file searching. The locate command can help you accelerate troubleshooting, perform system audits, and enhance everyday tasks with rapid file location capabilities. ## What is ‘locate’? ‘locate’ is a command-line utility that allows you to quickly find files on Linux systems by simply searching for the file names. Unlike other search tools that traverse the entire file system in real-time, ‘locate’ relies on a regularly updated file database to perform its searches. The concept is very simple, the database contains a list of all the files on your system along with their paths. When you execute a ‘locate’ command, it searches this database by file name rather than the file system itself, resulting in significantly faster search times. Did you know there are two versions of the locate command? There is **mlocate** and **plocate.**When you install locate, you get both versions installed. But you can optionally install either mlocate or plocate. While both mlocate and plocate help locate files on Linux systems, plocate offers superior performance and efficiency due to its optimized data structures. It generates smaller databases, conducts faster searches, and is designed for modern Linux features. Notably, some distributions have transitioned to plocate as their default locate implementation. While mlocate still functions and can be suitable when seeking files matching any of the provided patterns, plocate is generally preferred for its speed and efficiency advantages. ## How ‘locate’ Works on the Linux System The locate command is an extremely useful utility. Before tools like it, users had to craft complex find commands to find files in Linux. Locate is clever because immediately after installation, the filesystem is quickly indexed and saved to a database. As we mentioned before, instead of searching the filesystem, the locate command searches the database manually – it’s that simple! Let’s discover in more detail how it works: ### **#1: Database Creation** The file database underpinning ‘locate’ is typically generated and maintained by a system process known as ‘*updatedb*‘. This process runs at scheduled intervals using a crontab that’s created during installation. The update runs generally once a day, but this can easily be changed. The *updatedb* commands the service to systematically scan the entire file system to capture a snapshot of all files and their locations. mlocate is fast at indexing the file system because it uses an incremental update strategy, an optimized database update structure, and minimizes its impact on the system with low-priority I/O tasks. ### **#2: Database Storage:** The default database storage location of ‘locate’ resides within the ‘**/var/lib/mlocate/**‘ directory. Should the need arise, this location can be easily changed. You can opt to save the database to an NVME or SSD storage for even quicker indexing and searches. ### **#3: Search Execution:** Upon executing a ‘locate’ command, it scans the pre-built database for files that align with your specified search criteria. The search results output and include the complete paths of the matching files. The search looks for partial and an exact match, you can even include a globbing option such as regex values. The output shows on your default system standard output. (TTY stdout) ## Ubuntu Install Locate – A Step-by-Step Guide I am not aware of ‘locate’ being pre-installed in any Linux distribution. Other commands like ‘find’ are included, but in all distributions I have used, installing mlocate manually was necessary. In this next section, we will explain how to install ‘locate’ package. Let’s dive into the process of installing and using ‘locate’ on your Ubuntu server: ### Step 1 – Install Locate Command In the majority of contemporary Linux distributions like Ubuntu, the ‘locate’ utility is not included by default. You’ll install ‘locate’ package, which provides the ‘locate’ command to **usr/bin/locate** and the required packages for managing the file databases. Launch your terminal and execute the following command to install ‘locate’: ``` #To Install locate use (Recommended) sudo apt install locate #To install specifically plocate use (Optional) sudo apt install plocate ``` If you have the Yum Package Manager installed you can install locate with this command line utility ``` sudo dnf install mlocate ``` ### Step 2 – Update the Locate DB After installing the mlocate package, you need to populate the ‘locate’ database for the first time. You can do this by running the following command as root user: ``` sudo updatedb ``` This process might take some time, depending on the size of your file system. Once it’s complete, you’re ready to start using ‘locate’. ### Step 3 – Find Files Using the Locate Command The basic syntax for using the locate command is as follows, you can also search the main pages to learn more. ``` locate [options] filename man locate ``` Replace the filename with the name of the file you’re searching for. You can also use wildcards (*) to search for multiple files that match a certain pattern. Here are a few examples of how to use locate: Search for a file by its exact name: ``` locate myfile.txt ``` Search for all files that contain the word “report”: ``` locate *report* ``` Search for all files with the “.pdf” extension: ``` locate *.pdf ``` ### Step 4 – Additional Options and Tips By default, ‘locate’ searches are case-sensitive. If you want to perform a case-insensitive search, you can use the -i option: ``` locate -i myfile.txt ``` ‘locate’ also supports the use of regular expressions for more complex search patterns. To use a regular expression, you can use the -r option: ``` locate -r '^myfile.*\.txt$' ``` If you expect a large number of search results, you can limit the output using the -n option: ``` locate -n 10 *report* ``` If you’ve created new files or made changes to your file system, you might need to manually update the ‘locate’ database to ensure accurate search results. You can do this by running the updatedb command again: ``` sudo updatedb ``` ### Troubleshooting - “locate command not found” error: If you encounter this error, it means the mlocate package is not installed on your system. Follow the steps in the “Install Locate Command” section to install it. - “sudo updatedb” permission denied: Make sure you’re running the updatedb command with sudo or as the root user. - Outdated search results: If ‘locate’ is returning outdated results, try manually updating the database using the sudo updatedb command. The ‘locate’ command is a powerful tool for quickly finding files on your Linux system. By understanding how ‘locate’ works and following the steps outlined in this guide, you can efficiently manage your files and streamline your workflow. Remember to keep your ‘locate’ database up-to-date to ensure accurate search results. --- # What Is the 3-2-1 Backup Rule? > URL: https://www.atlantic.net/disaster-recovery/what-is-a-3-2-1-backup-strategy/ | Published: 2024-09-08 | Updated: 2026-09-15 | Author: Richard Bailey ## **Data Protection: A Critical Necessity** Hardware failures, human error, natural disasters, and cyberattacks are constant threats that can compromise data integrity and lead to data loss. To safeguard against these risks, a robust data protection strategy is essential. The 3-2-1 backup rule is best practice for ensuring data safety and business continuity for any data stored across your organization. This article will explain what the 3-2-1 backup rule is, how it works, and explain why it’s important. We will also give details about how Atlantic.Net implements this strategy on our award-winning cloud platform. ## **Understanding the 3-2-1 Backup Rule** The backup rule is a straightforward yet highly effective approach to data backup that provides multiple layers of redundancy, crucial in safeguarding against data loss. ### #1: Keep Three Copies It is essential to maintain at least three copies of your data. This includes your original data and two backup copies. ### #2: Use Two Storage Media Types Store the data on two separate storage types. This could involve a combination of: - **Local storage:** such as an external hard drive or network-attached storage (NAS) for quick and convenient access. - **Off-site storage:** such as cloud storage or tape backup. This protects against physical damage, fire, or theft at your primary location. ### #3: Keep One Backup Copy Off-Site Store one backup copy in a geographically different location either at a colocation site or perhaps at a specialist records management company. This creates a safety net against local disasters like fires, floods, or even simple accidents. The 3-2-1 rule isn’t just about having backups; it’s about having a resilient strategy. By incorporating multiple copies, diverse storage media, and off-site protection, you significantly reduce the risk of permanent data loss. It’s a simple yet effective way to ensure your digital backups and critical information remain safe and accessible at all times. ## **The Importance of the 3-2-1 Backup Rule** Now that we know what the 3-2-1 backup strategy is, let’s explore how it directly strengthens your data recovery capabilities and safeguards your business operations. ### **Data Loss Prevention** Hardware failures, accidental deletions, cyberattacks, and natural disasters can all lead to data loss. The 3-2-1 backup rule ensures multiple data copies are stored across different locations and storage mediums, minimizing the impact of any single point of failure. ### **Disaster Recovery and Business Continuity** For businesses, data loss can disrupt operations, impact productivity, and damage reputation. The 3-2-1 backup rule helps define your disaster recovery by enabling the rapid restoration of critical data and systems, minimizing downtime, and ensuring business continuity. We have many healthcare organizations using our HIPAA-compliant hosting, and this strategy is mandatory for compliance. ### **Protecting Against Human Error** Accidental deletions, overwrites, and misconfigurations are common causes of data loss. It’s often a simple case of users accidentally deleting data – it happens! The 3-2-1 backup rule provides a safety net, allowing you to revert to a previous version of your data in case of human error. ### **Defending Against Ransomware** Ransomware attacks are a serious risk and a growing threat; cyber criminals are extorting businesses by encrypting valuable data and demanding payment for its release. Having successful backup strategies gives you the advantage; you’ll have leverage in negotiations! By restoring data from a protected offsite backup, you can dodge the ransom and instead focus on your infrastructure security. ### **Compliance and Data Security** Many industries have regulatory requirements for data retention and protection. We have already mentioned healthcare, but financial, education, government, and retail are all subject to compliance requirements. The 3-2-1 backup rule helps organizations meet these compliance standards and ensures data integrity and safety. ## Implementing the 3-2-1 Backup Rule in Practice How do you implement the 3-2-1 backup rule? Firstly, did you know that Atlantic.Net has an optional backup-managed service that can be implemented into our VPS offering? [Check out this page](https://cloud.atlantic.net/?page=signup) for more information. ### **The First Copy: Production Data** The first copy of your data is the original data that resides on your primary storage device, such as your computer’s hard drive, server, VPS SSD, or SAN. This is classed as production data that you actively use and modify. According to the 3-2-1 backup strategy, the production data is the original, actively used information residing on your primary storage medium. This is live data that drives your daily operations and is subject to constant change. ### **The Second Copy: Local Backup** Recognizing the risk of a single point of failure, the rule suggests at least two backups locally. For individuals, this could be as simple as creating a data copy on an external hard drive. Businesses may opt for more robust backup solutions, such as a Network Attached Storage (NAS) device or a dedicated VEEAM backup server. Regardless of the method, the proximity of these local backup copies ensures swift data recovery in scenarios like accidental deletions, file corruption, or hardware failure. ### **The Third Copy: Off-Site Backup (Cloud Storage)** The third copy of data is what sets the 3-2-1 backup strategy apart from standard backups. The third copy must be stored in a geographically separate location. An offsite copy of data is a great insurance policy for your data. It’s physically located away from your primary data, typically in a secondary data center, and often in a different part of the country. Having data offsite introduces several benefits. It creates disaster recovery and business continuity options. It’s protected from natural disasters, fire, and flood. Above all else, it gives you peace of mind that the data is safe. Some good options for an off-site data copy include: - **Cloud Storage:** Using a cloud service provider offers scalability, accessibility, and often built-in data security measures. Services like object storage provide cost-effective solutions for large data volumes. The storage layer has its own data protection which is yet another layer of safety. With some providers, you can also archive to cold archival storage automatically. - **Physical Off-Site Storage:** This traditional approach involves storing backup copies on media like tapes or hard drives, and transporting them to a secure location. Although this is less common today, many businesses still want to keep a copy of data offsite for extra safety. Popular businesses that offer this service are Iron Mountain and Crown Records Management. - **Hybrid Solutions:** Combining cloud and physical storage leverages the strengths of both strategies. This is more common with colocation service providers where businesses store server equipment in a provider’s data center, they will pay for a backup service where critical data copies are kept at the provider, either on disk or media typically kept in a safe. The ideal off-site storage choice depends on factors like data volume, recovery point objective, budget, and data sensitivity. ## **Key Considerations for 3-2-1 Backup Rule Data Storage** What are the important things you need to know when implementing a backed-up data strategy? **Plan the Backup Frequency:** You must know what frequency of your backups is required. This is not an easy task because it depends on how often your data changes. Critical data may require daily or even hourly backups, while less frequently modified data may only need weekly or monthly backups. **Use Backup Automation:** Utilize backup software or use a cloud-managed services provider like Atlantic.Net that can automate the backup process. Automation ensures that backups are performed consistently and reduces the risk of human error. **Backup Verification and Testing:** It is critical to know you can trust your backups! Regularly verify the integrity of your backups and perform recovery testing to ensure that you can successfully restore data in the event of a data loss incident. **Data Encryption:** Encrypt your backup data both in transit and at rest to protect it from unauthorized access. The Atlantic.Net managed backup service uses AES256 encryption as standard. **Off-Site Storage Options:** Evaluate different off-site storage options, such as cloud backup, physical off-site storage, or a combination of both, based on your budget, data volume, recovery time objectives (RTOs), and recovery point objectives (RPOs). **Immutable Storage:** Consider using immutable storage for your off-site backups. Immutable storage prevents data from being modified or deleted, providing an extra layer of protection against ransomware and accidental deletions. ## Atlantic.Net Backups and Replication Atlantic.Net’s Cloud Backup and Replication services offer a comprehensive solution to safeguard your critical data and ensure business continuity. The high-performance ACP cloud infrastructure provides lightning-fast, robust, and fault-tolerant backup and replication capabilities. **Cloud Backups** Our snapshot-based backup service operates seamlessly in the background, automatically capturing your data according to a predefined schedule. This ensures your data is consistently protected without manual intervention, minimizing the risk of human error. With configurable backup frequencies ranging from 5 minutes to daily, you can tailor the service to match your RTO and RPO. **Key Features of Atlantic.Net Cloud Backups** - **File-Level Recovery:** Recover individual files or folders from any backup point without the need for a full system restore. This granular approach saves time and resources, allowing you to quickly retrieve specific data as needed. - **Full System Restore:** Restore your entire cloud server to any previous backup point with a single click. This comprehensive recovery option ensures rapid recovery in the event of major system failures or data corruption. - **Off-Site Backups:** Safeguard your data against local disasters by storing backups in a geographically separate off-site location. Atlantic.Net offers multiple data center locations to choose from, ensuring your data remains safe and accessible even in the face of unforeseen events. **Replication** Our snapshot replication service takes your disaster recovery plan to the next level. By replicating your cloud VPS to one or more failover nodes, you can achieve high availability and minimize downtime in case of unexpected issues. These nodes can be located in the same data center or at a remote location, offering flexibility and redundancy. **Advantages of Atlantic.Net Backup and Replication Services** - **Seamless Integration with Cloud Infrastructure:** Leverage the power and reliability of Atlantic.Net’s cloud platform for efficient and secure backups and replication. - **Flexible Backup Frequencies:** Tailor your backup schedule to match your RTO and RPO requirements, ensuring your data is protected according to its criticality. - **Rapid Recovery Options:** Choose between file-level recovery or full system restore for quick and efficient data retrieval. - **Off-Site Protection:** Safeguard your data against local disasters with off-site backups stored in geographically separate locations. - **High Availability with Replication:** Ensure business continuity with snapshot replication, enabling rapid failover to redundant computing nodes. - **Cost-Effective Solutions:** Atlantic.Net offers competitive pricing to help you get started. [Sign up today](https://cloud.atlantic.net/?page=signup&s=hp) and experience the peace of mind that comes with knowing your data is protected. Our team of experts is ready to assist you in tailoring a backup strategy that meets your unique needs and ensures your critical data remains safe and accessible, no matter what challenges come your way. [Contact Atlantic.Net today](https://www.atlantic.net/about-us/corporate-contact/) and start on your data backup journey. **Here are some valuable resources from Atlantic.Net:** - [Does Atlantic.Net Offer Data Backup for Cloud Servers?](https://www.atlantic.net/disaster-recovery/how-to-data-backup-cloud-server/) - [How to Enable Cloud Backups](https://www.atlantic.net/vps-hosting/how-to-enable-cloud-backups/) - [What Is a Backup?](https://www.atlantic.net/vps-hosting/what-is-backups-review-basic-concepts/) - [File-Level Recovery](https://www.atlantic.net/announcements/announcing-file-level-recovery/) - [Veeam Backup from Atlantic.Net](https://www.atlantic.net/managed-services/veeam-services/) - [RTO vs. RPO](https://www.atlantic.net/disaster-recovery/rto-vs-rpo/) Atlantic.Net has an industry-leading selection of hosting options, one-click applications, and managed cloud hosting choices for your consideration. Learn more about Atlantic.Net’s hosting solutions, including HIPAA-compliant[disaster recovery](https://www.atlantic.net/disaster-recovery/) services. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282), or email us at sales@atlantic.net. --- #### Read More About Backup Server Solutions - Get a [Backup Server](https://www.atlantic.net/cloud-platform/backups/) from Atlantic.Net - Is a [Cloud-Based Backup Service](https://www.atlantic.net/vps-hosting/cloud-backup-vs-local-backup-the-safest-way-to-store-data/) the Best Way to Back Up Data? --- --- # Using sar Command to Get System Resource Stats > URL: https://www.atlantic.net/vps-hosting/using-sar-command-to-get-system-resource-stats/ | Published: 2024-09-10 | Updated: 2024-10-03 | Author: Hitesh Jethva The **sar** command is a handy tool for monitoring system performance on Linux. It can report CPU usage, memory consumption, network activity, and more. System administrators and DevOps engineers use sar to track resource usage and troubleshoot system issues. This guide will show you how to install and use the sar command to gather system resource stats. ## Installing the sar Command The **sar** command is part of the **sysstat** package, which needs to be installed before you can start using sar. The installation process varies depending on the Linux distribution you’re using. **On Ubuntu/Debian:** To install sysstat on Ubuntu or Debian-based systems, run the following commands: ```bash apt-get update apt-get install sysstat ``` Once installed, you need to enable the sysstat data collection process: ```bash systemctl enable sysstat systemctl start sysstat ``` The sysstat service will now automatically start at boot and collect data every 10 minutes by default. **On CentOS/Fedora:** On CentOS or Fedora-based systems, install sysstat using the following command: ```bash yum install sysstat ``` Again, you’ll need to enable and start the service: ```bash systemctl enable sysstat systemctl start sysstat ``` ## Basic Syntax and Options The **sar** command offers a variety of options that allow you to collect and report system statistics over a specific interval and for a specific count. The general syntax for the sar command is as follows: ```bash sar [options] [interval] [count] ``` **Explanation:** - **interval:** The time between each data sample, in seconds. - **count:** The number of samples to be collected. For example, if you want to collect CPU usage statistics every 5 seconds for a total of 3 times, you would run: ```bash sar -u 5 3 ``` Output: ```bash Linux 6.5.0-35-generic (ubuntupc) 09/10/2024 _x86_64_ (4 CPU) 09:13:48 AM CPU %user %nice %system %iowait %steal %idle 09:13:53 AM all 8.83 0.00 4.00 0.62 0.00 86.56 09:13:58 AM all 10.40 0.00 4.39 0.37 0.00 84.85 09:14:03 AM all 9.68 0.00 3.31 0.36 0.00 86.65 Average: all 9.63 0.00 3.90 0.45 0.00 86.02 ``` Here are some commonly used options for sar: - **-u:** Reports CPU usage statistics. - **-r:** Reports memory and swap space statistics. - **-n DEV:** Reports network activity - **-b:** Reports disk I/O statistics. ## Monitoring CPU Usage with sar One of the most common use cases of sar is to monitor CPU usage. The **-u** option shows how much CPU time is spent on different types of processes, such as user processes, system processes, and idle time. It also indicates how much time the CPU spends waiting for I/O operations. Run the following command to monitor CPU usage. ```bash sar -u 1 5 ``` Output: ```bash Linux 6.5.0-35-generic (ubuntupc) 09/10/2024 _x86_64_ (4 CPU) 09:16:21 AM CPU %user %nice %system %iowait %steal %idle 09:16:22 AM all 11.52 0.00 3.40 0.00 0.00 85.08 09:16:23 AM all 4.62 0.00 2.31 0.51 0.00 92.56 09:16:24 AM all 4.10 0.00 2.31 0.26 0.00 93.33 09:16:25 AM all 3.09 0.00 2.32 0.26 0.00 94.33 ``` Here’s what each column means: - **%user:** Percentage of CPU time spent on user processes (non-kernel). - **%system:** Time spent on system (kernel) processes. - **%iowait:** Time spent waiting for I/O operations to complete. - **%idle:** Time when the CPU is idle. ## Checking Memory Usage with sar The **sar -r** command allows you to monitor memory usage, providing insights into both physical memory (RAM) and swap space. Run the following command to monitor memory usage. ```bash sar -r 1 3 ``` Output: ```bash 09:17:46 AM kbmemfree kbavail kbmemused %memused kbbuffers kbcached kbcommit %commit kbactive kbinact kbdirty 09:17:47 AM 233660 1787928 4811984 60.78 66284 2413060 28737052 286.96 3526444 3294540 5628 09:17:48 AM 241400 1795668 4809148 60.74 66284 2408156 28731948 286.91 3527020 3294540 5456 09:17:49 AM 241472 1795740 4809288 60.75 66284 2407952 28733012 286.92 3528096 3294540 5392 Average: 238844 1793112 4810140 60.76 66284 2409723 28734004 286.93 3527187 3294540 5492 ``` Here’s what each column represents: - **kbmemfree:** Free memory in kilobytes. - **kbmemused:** Used memory in kilobytes. - **%memused:** Percentage of memory used. - **kbbuffers:** Memory used by kernel buffers. - **kbcached:** Memory used by the page cache. - **kbcommit:** Committed memory (the amount of memory reserved for processes). ## Analyzing Network Activity with sar The **sar** **-n DEV** option shows you how much data is being transferred over your network interfaces. Run the following command to monitor network activity. ```bash sar -n DEV 1 3 ``` Output: ```bash 12:03:01 AM IFACE rxpck/s txpck/s rxkB/s txkB/s rxcmp/s txcmp/s 12:03:02 AM eth0 34.03 12.12 4.22 2.56 0.00 0.00 12:03:03 AM eth0 32.43 14.01 4.35 3.01 0.00 0.00 ``` **Explanation:** - **rxpck/s:** Number of packets received per second. - **txpck/s:** Number of packets transmitted per second. - **rxkB/s:** Kilobytes received per second. - **txkB/s:** Kilobytes transmitted per second. ## Monitoring Disk I/O with sar The **sar** **-b** command provides detailed information on disk I/O activities, such as the number of reads and writes per second, and the amount of data read or written. Run the following command to monitor disk I/O. ```bash sar -b 1 3 ``` Output: ```bash 09:20:41 AM tps rtps wtps dtps bread/s bwrtn/s bdscd/s 09:20:42 AM 371.00 0.00 371.00 0.00 0.00 4128.00 0.00 09:20:43 AM 0.00 0.00 0.00 0.00 0.00 0.00 0.00 09:20:44 AM 0.00 0.00 0.00 0.00 0.00 0.00 0.00 Average: 123.67 0.00 123.67 0.00 0.00 1376.00 0.00 ``` Explanation of columns: - **tps:** Total transactions per second. - **rtps:** Read transactions per second. - **wtps:** Write transactions per second. - **bread/s:** Bytes read per second. - **bwrtn/s:** Bytes written per second. ## Scheduling sar to Run at Intervals You can automate monitoring process by scheduling sar using cron jobs. This allows you to gather long-term performance data for later analysis. To schedule sar to collect system resource stats every hour, edit your crontab file: ```bash crontab -e ``` Add the following line to schedule data collection every hour: ```bash 0 * * * * /usr/lib/sysstat/sa1 1 1 ``` This command tells sar to collect one sample per hour and store it in /var/log/sa/. You can view this historical data by using the -f option with sar: ```bash sar -f /var/log/sa/sa10 ``` This allows you to analyze system performance over time and detect any trends or anomalies. ## Conclusion The sar command is a powerful and flexible tool for monitoring system performance in Linux. It provides detailed reports on CPU, memory, network, and disk usage, helping system administrators identify and resolve performance issues. You should use sar a regular part of your system monitoring toolkit for improved system health and efficiency. You can try sar to monitor system resource usage on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Running a Shell Script on a Remote Machine Through SSH > URL: https://www.atlantic.net/vps-hosting/running-a-shell-script-on-a-remote-machine-through-ssh/ | Published: 2024-09-11 | Updated: 2024-12-05 | Author: Hitesh Jethva Remote access and automation are critical in modern system administration. SSH (Secure Shell) allows you to connect securely to remote machines, making it easy to run tasks or scripts from anywhere. This guide will show you how to run a shell script on a remote machine using SSH. You’ll learn how to automate tasks, transfer scripts, and troubleshoot common issues. ## Why Use SSH for Running Shell Scripts? Running shell scripts on a remote machine is useful for: - Automating tasks like backups, system updates, or deployments. - Managing remote servers without physically accessing them. - Centralizing workflows, making it easy to manage multiple machines from a single location. ## Setting up SSH Key-Based Authentication To avoid entering your password every time, use SSH keys: 1. Generate SSH Key Pair: ```bash ssh-keygen -t rsa -b 4096 ``` Output: ```bash Generating public/private rsa key pair. Enter file in which to save the key (/home/your_username/.ssh/id_rsa): ``` 2. Copy the Public Key to the Remote Server: ```bash ssh-copy-id user@remote-server ``` Once this is set up, you can log in without a password. ## Writing and Preparing the Shell Script Start by creating your shell script on your local machine. For example, a simple script like **backup.sh** could look like this: ```bash #!/bin/bash # Backup script to archive home directory tar -czf /backup/home_backup.tar.gz /home/user/ ``` Make the script executable: ```bash chmod +x backup.sh ``` ## Running a Shell Script on a Remote Machine via SSH To run a shell script on a remote machine directly through SSH, use this command: ```bash ssh user@remote-server 'bash -s' < ./backup.sh ``` Output: ```bash Compressing /home/user/ directory... Backup saved at /backup/home_backup.tar.gz ``` **Here’s a breakdown:** - **user@remote-server:** The username and remote host. - **‘bash** –**s**‘: Tells the remote machine to interpret the script as standard input. - < **./backup.sh:** Sends the script through SSH for execution. ## Transferring and Running Shell Scripts with SCP Another way to run a script is to transfer it first and then run it. You can use scp to copy the script to the remote server. **Step** **1**: Copy the Script to the Remote Machine ```bash scp ./backup.sh user@remote-server:/home/user/ ``` Output: ```bash backup.sh 100% 234 12KB/s 00:00 ``` **Step 2:** Run the Script on the Remote Machine ```bash ssh user@remote-server 'bash /home/user/backup.sh' ``` ## Automating Remote Script Execution with SSH Config and Bash Aliases You can set up an SSH config file or a Bash alias to simplify the process. **Setting up an SSH Config File** Create or edit the ~/.ssh/config file and add the following: ```bash Host remote-alias HostName remote-user User user ``` Now, you can use the alias remote-alias to log in: ```bash ssh remote-alias ``` **Creating a Bash Alias** You can also create a Bash alias to simplify running the script: ```bash alias run_backup="ssh user@remote-server 'bash /home/user/backup.sh'" ``` Now, simply type **run_backup** to execute the script. ## Conclusion Running shell scripts on remote machines via SSH simplifies automation and system management. You can either run the script directly using SSH or transfer it and execute it later. Use SSH config and Bash aliases to streamline repetitive tasks. Keep experimenting with more complex scripts to automate your workflow on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Execute a Bash Script Directly from a URL > URL: https://www.atlantic.net/vps-hosting/how-to-execute-a-bash-script-directly-from-a-url/ | Published: 2024-09-12 | Updated: 2024-10-03 | Author: Hitesh Jethva Bash scripts are an integral part of automating tasks in Linux environments. One interesting use case is executing a bash script directly from a URL. This can save time by allowing you to instantly run scripts hosted on the web without downloading them to your machine first. However, while this can be useful, it’s essential to understand the risks and security implications. This guide will walk you through different methods to execute bash scripts directly from URLs. ## Method 1: Using Curl and Pipe to Bash The curl command is one of the easiest ways to execute a bash script from a URL. The general syntax is as follows: ```bash curl -s https://example.com/script.sh | bash ``` **Explanation:** - **-s flag**: This flag enables silent mode, suppressing progress bars and errors to make the command cleaner. - **Piping to Bash**: The pipe | sends the output of curl directly to the bash interpreter. Example: Let’s assume there is a script hosted at **https://example.com/hello-world.sh** that prints **“Hello, World!”** when executed. ```bash curl -s https://example.com/hello-world.sh | bash ``` Output: ```bash Hello, World! ``` ## Method 2: Using Wget and Pipe to Bash **wget** is another popular tool for downloading files from the web. To execute a script from a URL using wget, you can use the following syntax: ```bash wget -qO- https://example.com/script.sh | bash ``` **Explanation:** - **-q flag**: This flag enables quiet mode, suppressing output. - **-O- option**: This tells wget to output the file contents to the terminal (stdout) instead of saving to a file. **Example:** Using the same **hello-world.sh** script as before: ```bash wget -qO- https://example.com/hello-world.sh | bash ``` Output: ```bash Hello, World! ``` ## Method 3: Downloading the Script First, Then Executing In some cases, it is safer to download the script first, review its content, and then run it. Here’s how you can download a bash script and execute it manually. **Step 1**: Download the script using wget or curl: ```bash wget https://example.com/hello-world.sh ``` **Step** **2**: Review the script to ensure it’s safe. You can use a text editor like nano or cat to read the contents: ```bash cat hello-world.sh ``` **Step 3**: Make the script executable: ```bash chmod +x hello-world.sh ``` **Step 4**: Run the script: ```bash ./hello-world.sh ``` Output: ```bash Hello, World! ``` ## Conclusion In this guide, we explored different methods to run a script from URLs. However, we recommend validating the script’s content and executing it in a secure environment. Whether you’re using curl, wget, or downloading scripts manually, these methods offer flexibility but should be handled with care. You can try any of the above methods on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Execute a Command in Multiple Directories on Linux – A Step-by-Step Guide > URL: https://www.atlantic.net/vps-hosting/how-to-execute-a-command-in-multiple-directories-on-linux-a-step-by-step-guide/ | Published: 2024-09-13 | Updated: 2024-10-03 | Author: Hitesh Jethva In Linux system administration, there are many situations where you may need to execute the same command across multiple directories. Automating this task can save significant time and reduce the likelihood of human error, whether it’s cleaning up log files, updating configurations, or managing files in bulk. In this tutorial, we’ll explore different ways to execute commands in multiple directories using Linux tools, such as for loops, find, xargs, and shell scripting. ## Why Execute Commands Across Multiple Directories? There are several practical scenarios where executing commands across multiple directories is necessary: - **Updating Git repositories**: Running git pull in several directories to keep repositories up to date. - **Cleaning up logs**: Removing old log files from multiple directories. - **Batch file processing**: Converting or moving files across directories. ## Using a For Loop in Bash to Execute Commands in Multiple Directories One of the simplest ways to execute a command in multiple directories is by using a for loop. This method is straightforward and ideal when you have a fixed list of directories. Here is an example of listing files in multiple directories: ```bash for dir in /home/user/dir1 /home/user/dir2 /home/user/dir3; do (cd "$dir" && ls) done ``` Output: ```bash file1.txt file2.txt file3.txt file4.log file5.txt file6.jpg file7.mp4 file8.doc file9.png ``` **In this example:** - The **for loop** iterates over each directory listed in **/home/user/dir1, /home/user/dir2,** and **/home/user/dir3.** The **cd “$dir”** changes the directory, and **&&** ls lists the files in that directory. ## Using the find Command to Target Directories Dynamically The **find** command is a handy tool for searching for directories based on specific criteria, such as names, types, or modification dates. You can also use it to execute a command in each found directory. Here is an example of how to find directories and run ls in each directory. ```bash find /home/user -type d -exec bash -c 'cd "{}" && ls' \; ``` Output: ```bash file1.txt file2.txt file3.txt file4.log file5.txt file6.jpg file7.mp4 file8.doc file9.png ``` **In this example:** - **find /home/user -type** **d** searches for all directories (-type d) under /home/user. - The **-exec** option allows us to execute the ls command in each directory found. This method is ideal for dynamically targeting directories, especially when the directory structure is large or unknown. ## Parallel Execution of Commands Using xargs If you have many directories and want to execute commands in parallel to speed things up, you can use **xargs.** This tool allows you to run commands concurrently by specifying the number of processes. Here is an example to run ls in parallel across directories. ```bash find /home/user -type d | xargs -n 1 -P 4 bash -c 'cd "$0" && ls' ``` Output: ```bash file1.txt file2.txt file3.txt file4.log file5.txt file6.jpg file7.mp4 file8.doc file9.png ``` **In this example:** - **xargs** **-n 1** tells xargs to pass one directory at a time to the bash command. - **-P** **4** runs the command in parallel using 4 processes. ## Using Shell Scripting for More Complex Operations For more complex tasks, such as error handling, conditional execution, or logging, writing a shell script is often the best solution. Let’s see how to create a script to process directories and log the output. Here is a simple shell script for logging file listings. ```bash #!/bin/bash LOGFILE="output.log" for dir in /home/user/dir1 /home/user/dir2 /home/user/dir3; do if cd "$dir"; then echo "Listing files in $dir:" >> $LOGFILE ls >> $LOGFILE else echo "Failed to change directory to $dir" >> $LOGFILE fi done ``` When you run the above script, the following output will be produced: ```bash Listing files in /home/user/dir1: file1.txt file2.txt file3.txt Listing files in /home/user/dir2: file4.log file5.txt file6.jpg Listing files in /home/user/dir3: file7.mp4 file8.doc file9.png ``` **This script does the following:** - It attempts to change to each directory listed in the for loop. - If the directory change is successful, it logs the file listing into output.log. - If it fails, it logs an error message. This method is useful for automating tasks that require logging and error handling. ## Conclusion Executing commands in multiple directories is a common task for Linux administrators and developers. By using methods like for loops, find, xargs, and shell scripting, you can automate repetitive tasks efficiently and avoid manual errors. Try to experiment with these methods to find the one that best suits your needs, and consider combining them for even more complex scenarios on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Exclude Files and Directories from rsync > URL: https://www.atlantic.net/vps-hosting/exclude-files-and-directories-from-rsync/ | Published: 2024-09-14 | Updated: 2024-10-03 | Author: Hitesh Jethva **rsync** is a flexible tool for syncing files and directories between different locations. It’s highly efficient because it only transfers the differences between source and destination, saving time and bandwidth. It is commonly used for backup, file transfers, and mirroring. **rsync** supports various options, including the exclusion of specific files and directories during the sync process. In many scenarios, you may not want to sync every file or directory. For example, temporary files, logs, or large data files might not be necessary for the target system. This is where the**—-exclude** and**—****-exclude-from** options come into play. In this guide, we’ll explore how to use these options to exclude files and directories from rsync with practical examples. ## Exclude a Single File The **–exclude** option allows you to specify files and directories that should not be copied during the sync operation. Let’s look at some basic examples of how to use it. To exclude a single file from the **sync,** use the **–exclude** option followed by the file name or path relative to the source directory: ```bash rsync -av --exclude 'file.txt' /source/ /destination/ ``` Output: ```bash sending incremental file list ./ file1.txt file2.txt file.txt sent 90 bytes received 45 bytes 270.00 bytes/sec total size is 200 speedup is 1.33 ``` **Here is the explanation:** - **-av:** Archive mode and verbose output. - **–exclude ‘file.txt’:** Excludes the file file.txt from the sync. - **/source/ /destination/:** The source and destination directories. In this example, **file.txt** is excluded, but other files (file1.txt, file2.txt) are copied. ## Exclude a Directory If you want to exclude an entire directory, use the directory name in the **–exclude** option: ```bash rsync -av --exclude 'dir1/' /source/ /destination/ ``` Output: ```bash sending incremental file list ./ dir2/ file1.txt file2.txt sent 140 bytes received 60 bytes 400.00 bytes/sec total size is 300 speedup is 1.67 ``` Here, **dir1/** is excluded from the sync, and only the remaining files and directories are synced. ## Exclude Files with Specific Patterns You can also exclude files based on patterns, such as excluding all **.log** files: ```bash rsync -av --exclude '*.log' /source/ /destination/ ``` Output: ```bash sending incremental file list ./ file1.txt file2.txt ``` In this case, all **.log** files are excluded, and only files that don’t match the pattern are synced. ## Using the –exclude-from Option The **–exclude-from** option allows you to specify a file containing a list of exclusions. This file can include multiple lines, each representing a file or directory to exclude. First, create an exclusion file with the items you want to exclude: ```bash echo 'file.txt' > exclude-list.txt echo 'dir1/' >> exclude-list.txt echo '*.log' >> exclude-list.txt ``` The **exclude-list.txt** file now contains the following: ```bash file.txt dir1/ *.log ``` Now, use the **–exclude-from** option to exclude all the patterns in the file: ```bash rsync -av --exclude-from='exclude-list.txt' /source/ /destination/ ``` In this example, all the exclusions from **exclude-list.txt** are applied, and the specified files, directories, and patterns are not synced. ## Conclusion In this guide, we’ve covered the basics of excluding specific files, directories, and patterns in rsync, along with practical examples of each use case. Excluding files and directories in rsync allows you to fine-tune your sync operations by omitting unnecessary or unwanted files. Try it out by syncing a backup directory on [VPS hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Extract and Create RAR Files in Linux > URL: https://www.atlantic.net/vps-hosting/how-to-extract-and-create-rar-files-in-linux/ | Published: 2024-09-15 | Updated: 2024-10-03 | Author: Hitesh Jethva **RAR** files are one of the most popular file compression formats, often used to pack multiple files into a single archive and compress them for easier storage or transfer. If you work on Linux, managing RAR files is quite straightforward with the right tools. In this guide, we will walk you through how to extract and create **RAR** files in Linux systems. ## Install rar and unrar To handle RAR files on Linux, you need to install the **rar** and **unrar** utilities. Unfortunately, these aren’t included by default in many Linux distributions because RAR is proprietary software. **Install rar and unrar on Ubuntu/Debian:** ```bash apt update apt install rar unrar ``` **Install rar and unrar on Fedora/RHEL:** ```bash dnf install rar unrar ``` Once installed, you’re ready to start working with RAR files. ## How to Extract RAR Files in Linux To extract RAR files, you can use the unrar command. The syntax is simple, and you can specify the target directory if necessary. ### Extracting a RAR File in the Current Directory To extract the contents of a RAR file into the current directory, use the following command: ```bash unrar x archive.rar ``` ### Extracting a RAR File to a Specific Directory You can specify a directory to extract the contents to using the following command: ```bash unrar x archive.rar /opt/ ``` ### Extracting Password-Protected RAR Files If your RAR file is password-protected, you can extract it by specifying the password when prompted: ```bash unrar x archive.rar ``` ## How to Create RAR Files in Linux To create RAR archives, you’ll use the rar command. Here’s how you can compress files into a RAR archive. ### Creating a Simple RAR Archive To create a RAR file from multiple files, run the following command: ```bash rar a archive.rar file1.txt file2.pdf file3.jpg ``` ### Creating a RAR File with a Password You can create a password-protected RAR file using the -p option: ```bash rar a -p archive.rar file1.txt file2.pdf file3.jpg ``` ### Specifying Compression Levels You can control the compression level when creating RAR files using the **-m** option followed by a number between 0 (no compression) and 5 (maximum compression): ```bash rar a -m5 archive.rar file1.txt file2.pdf file3.jpg ``` ## Conclusion This guide covered installing the rar and unrar utilities, extracting files from RAR archives, and creating new RAR files. We also explored on password protection and adjusting compression levels. You can easily manage RAR archives on your Linux system just as on Windows or macOS. Try practicing rar with all available options on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # Copy Files in Linux with Visual Progress: A Comprehensive Guide > URL: https://www.atlantic.net/vps-hosting/copy-files-in-linux-with-visual-progress-a-comprehensive-guide/ | Published: 2024-09-16 | Updated: 2024-12-05 | Author: Hitesh Jethva Copying files in Linux is a common task for system administrators, developers, and everyday users. While basic tools like **cp** can easily copy files, they don’t provide any real-time visual feedback on the progress of the file transfer. This is particularly inconvenient when copying large files or directories where knowing the remaining time and transfer speed can be essential. In this article, we’ll explore several ways to copy files in Linux while getting real-time visual feedback using tools like **rsync, pv,** and combining these tools for more advanced use cases. ## Basic File Copying in Linux The **cp** command is the standard method for copying files in Linux. It’s simple, efficient, but it lacks any progress indicator, which makes it hard to know how long the process will take for larger files. For example, the following command copy a **file1.txt** to the **/opt** directory. ```bash cp file1.txt /opt/ ``` ## Copying Files with Visual Progress Using rsync **rsync** is a handy tool that copies files efficiently and offers an option to display a progress bar. It’s especially useful for large transfers or network-based transfers, as it provides visual progress, file size, transfer speed, and estimated time remaining. Run the **rsync** command with the **–progress** option for copying file with progress. ```bash rsync --progress file1.txt /opt ``` This command shows the file name, the file size being copied, the percentage completed, the current transfer speed, and the estimated time to completion. ```bash file1.txt 123,456,789 100% 1.23MB/s 0:00:02 (xfr#1, to-chk=0/1) ``` ## Using pv (Pipe Viewer) for Real-Time Progress You can also use **pv (Pipe Viewer)** command-line tool to display real-time progress bar during file copying process. It can display transfer speed, estimated time remaining, and the amount of data transferred. You can use it with other commands like **dd** or **tar** to visualize the progress of file transfers or other data operations. **Using pv and dd:** Let’s use the **pv** command with **dd** to copy a **file1.txt.** ```bash pv file1.txt | dd of=/opt/file1.txt ``` Here, **pv** displays the file size, time elapsed, and transfer speed. This method is useful when copying files directly or creating disk images using **dd.** ```bash 123MB 0:00:01 [123MB/s] [================================================>] 100% ``` **Using tar and pv:** You can also use the **pv** with **tar** command to copy a directory with real-time progress bar. ```bash tar -cf - my-directory | pv | tar -xf - -C /opt ``` In this example, **pv** helps monitor the progress of copying a directory using tar. It’s especially useful for archiving large directories. ```bash 345MB 0:00:03 [115MB/s] [================================================>] 100% ``` ## Copying Large Files With rsync and pv Combined You can combine **rsync** with **pv** for maximum efficiency and detailed progress reporting. This setup gives you the best of both worlds: rsync for robust file transfer, and pv for real-time progress feedback. Let’s use the **rsync** with **pv** to copy a directory named **test-directory:** ```bash rsync -av --progress /mnt/test-directory /opt | pv ``` This combination allows rsync to handle the file transfer while pv provides a unified progress display. You get the advanced features of rsync, such as file comparison and incremental copying, along with a visual progress bar. ```bash sending incremental file list file1.txt 123,456,789 100% 1.23MB/s 0:00:02 (xfr#1, to-chk=0/1) file2.txt 234,567,890 100% 2.34MB/s 0:00:01 (xfr#2, to-chk=0/1) 345MB 0:00:04 [86MB/s] [================================================>] 100% ``` ## Using scp for Network Transfers With Progress **scp** is a standard tool for securely copying files over a network. While it does not offer a built-in progress bar, it can be combined with **pv** to achieve the same result. The following command copies a **file1.txt** to the remote machine with a progress bar. ```bash pv file1.txt | scp -C - root@remote-server-ip:/opt/file1.txt ``` Output: ```bash file1.txt 345MB 0:00:05 [69MB/s] [================================================>] 100% ``` ## Conclusion In Linux, copying files efficiently with visual progress can greatly enhance the user experience, especially when handling large files or directories. By using tools like rsync, pv, and combinations of commands, you can get real-time feedback on file transfers, ensuring you always know how long your task will take. Try to explore more advanced combinations to suit your needs on [VPS hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Mitigate the Terrapin SSH Attack > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-mitigate-the-terrapin-ssh-attack/ | Published: 2024-09-17 | Updated: 2024-10-03 | Author: Hitesh Jethva SSH (Secure Shell) is an essential protocol for securely accessing remote servers. However, as SSH usage has grown, so has the number of attacks targeting SSH, with one of the most common being the Terrapin SSH attack. This type of attack typically involves brute-forcing SSH credentials to gain unauthorized access. In this guide, we will explain the Terrapin SSH attack, how to detect it, and steps to mitigate it effectively. ## What Is the Terrapin SSH Attack? The Terrapin SSH attack is a brute-force attack that targets SSH servers by attempting to guess login credentials. Attackers use automated tools or botnets to try a large number of username-password combinations, hoping to find one that grants access. Once the attacker gains access, they can install malware, steal sensitive data, escalate privileges, or use the compromised server to launch additional attacks. ## How to Find Out If Your SSH Server Might Be Under Attack You can detect a possible SSH attack by observing the following: - **Frequent failed login attempts:** SSH logs will show a high number of failed login attempts. - **Unusual IP addresses:** Login attempts from unfamiliar or suspicious IPs. - **High server load**: Brute-force attacks can cause a spike in server CPU usage. - **Suspicious entries in logs**: You may notice repeated access attempts in **/var/log/auth.log** (Debian/Ubuntu) or **/var/log/secure** (CentOS/RHEL). To check for failed login attempts, use: ```bash grep "Failed password" /var/log/auth.log ``` Output: ```bash Oct 1 10:12:34 server sshd[2345]: Failed password for invalid user admin from 203.0.113.56 port 54832 ssh2 Oct 1 10:12:37 server sshd[2345]: Failed password for invalid user guest from 203.0.113.56 port 54832 ssh2 ``` Let’s dive deep to mitigate the Terrapin SSH Attack: ## Step 1: Disable Root SSH Login Disabling root login ensures that attackers cannot brute-force the root account, which often has the highest privileges. Edit the SSH configuration: ```bash nano /etc/ssh/sshd_config ``` Find the line PermitRootLogin and change it to: ```bash PermitRootLogin no ``` Restart the SSH service: ```bash systemctl restart sshd ``` Disabling root access via SSH forces attackers to guess non-root usernames, significantly increasing security. ## Step 2: Use Strong SSH Passwords or Key-Based Authentication Weak passwords are vulnerable to brute-force attacks. The best practice is to use SSH key-based authentication, which is much more secure. Generate an SSH key pair: ```bash ssh-keygen -t rsa -b 4096 ``` Follow the onscreen prompts to generate the key. Copy the public key to the server: ```bash ssh-copy-id user@server_ip ``` This installs your public key on the server, allowing passwordless login while blocking password-based brute-force attempts. ## Step 3: Change the Default SSH Port Changing the default SSH port from 22 to another port reduces the chance of automated brute-force attacks targeting your server. Edit the SSH configuration: ```bash nano /etc/ssh/sshd_config ``` Change the default port: ```bash Port 2222 ``` Restart the SSH service: ```bash systemctl restart sshd ``` Be sure to update firewall rules to allow traffic on the new port. ## Step 4: Enable SSH Rate Limiting with Fail2Ban Fail2Ban monitors SSH login attempts and blocks IP addresses after a certain number of failed login attempts, effectively preventing brute-force attacks. Install Fail2Ban: ```bash apt-get install fail2ban ``` Configure Fail2Ban for SSH: Edit the /etc/fail2ban/jail.local file and add the following: ```bash [sshd] enabled = true port = 22 logpath = /var/log/auth.log maxretry = 5 ``` Restart Fail2Ban: ```bash systemctl restart fail2ban ``` Now, after 5 failed login attempts, Fail2Ban will block the attacking IP address for a set period. ## Step 5: Enable Two-Factor Authentication (2FA) for SSH Adding two-factor authentication (2FA) provides an additional layer of security, requiring both a password and a one-time code generated on your mobile device. Install the Google Authenticator PAM module: ```bash apt-get install libpam-google-authenticator ``` Configure 2FA: Run google-authenticator for each user and follow the prompts. Then, add the following line to /etc/pam.d/sshd: ```bash auth required pam_google_authenticator.so ``` Restart SSH to apply the changes. ```bash systemctl restart sshd ``` ## What to Do If You’ve Been Compromised If you suspect that an SSH attack has compromised your server, take the following steps: - Disconnect the server from the network to prevent further damage. - Run a rootkit and malware scan using tools like rkhunter or chkrootkit. - Check SSH logs for any unauthorized access or suspicious activity. - Change all passwords and SSH keys to prevent the attacker from regaining access. ## Conclusion The Terrapin SSH attack is a serious threat, but it can be effectively mitigated through proactive security measures. By disabling root login, using strong authentication methods like SSH keys and 2FA, changing the default SSH port, and enabling tools like Fail2Ban, you can significantly reduce the risk of unauthorized access to your SSH server. Try implementing the above technique on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net to mitigate the terrapin SSH attack. --- # VPS RAM: Understanding the Importance of RAM for Your Cloud Server > URL: https://www.atlantic.net/vps-hosting/understanding-ram-for-your-vps/ | Published: 2024-09-18 | Updated: 2024-09-24 | Author: Richard Bailey When it comes to VPS performance, the total size and speed of Random Access Memory (RAM) will make all the difference. Think of it as the workspace of your virtual server – the more RAM you have, the more tasks and files your VPS can handle simultaneously without slowing down. From running complex software and handling large databases and files to managing multiple websites and applications, RAM is a critical factor in ensuring optimal performance and user experience. In this article, we will deep dive into how the speed and total size of your VPS impact your system performance. We will also highlight which scenarios where having vast amounts of RAM makes everything run smoothly, but also demonstrate in some circumstances, throwing additional RAM to create a VPS might not necessarily be the best option. ### Atlantic.Net VPS Service Offerings: A Closer Look at RAM Atlantic.Net is a leading cloud hosting solution provider that has been in business for over 30 years, and we offer a diverse range of VPS plans that cater to various user needs and budgets. Each plan comes with a specific amount of RAM, carefully balanced with other resources like CPU and storage to deliver the best possible performance for different use cases. We have data center locations throughout the United States, Canada, Europe, and Asia. The service plans are universally available across our website for every site and data center region. We also offer dedicated hosting options and shared hosting options. With Atlantic.Net, you will find a suitable VPS Plan that offers the RAM you need. Here is a brief overview of the types of plans available. ### General-Purpose Plans (G3 Series) G3 Plans feature RAM options ranging from 2GB to up to 192GB. - Balanced Allocation of CPU, RAM, and Storage - Ideal for a Wide Range of Applications and Websites - RAM Options from 2GB to 192GB - Entry-Level to Enterprise-Level Solutions ### Storage Optimized Plans (S2 Series) S3 plans, although focused on storage speed, also have access to good RAM options ranging from 16GB and 64GB. - Designed for Applications with High Storage Bandwidth Requirements - Adequate CPU and RAM Resources - RAM Options of 16GB and 64GB - Suitable for Data-Intensive Workloads ### Memory Optimized Plans (M2 Series) M2 Series feature ECC Memory option with DDR4 and DDR5 options, the RAM Options range from 16GB and 64GB. - Optimized for RAM-Heavy Environments - Full Bandwidth and Enhanced RAM Performance - RAM Options of 16GB and 64GB - Ideal for Memory-Intensive Applications ### CPU Optimized Plans (C2 Series) C2 prioritizes high-performance and multi-core CPU architecture. However, super-fast RAM is also standard ranging from 8GB to 64GB. - Geared Towards Computationally Intensive Applications - Balanced Allocation of CPU, RAM, and Storage - RAM Options from 8GB to 64GB - Suitable for High-Performance Computing ## Why RAM Matters: Finding the Perfect Amount for Your VPS Selecting the appropriate amount of RAM is crucial for ensuring the smooth operation of your virtual server. Too little RAM can lead to sluggish performance, crashes, and downtime, while too much RAM can be an unnecessary expense. Here are some factors to consider when determining your VPS RAM requirements: - **Type of Applications and Websites:** Resource-intensive applications and websites with high traffic volumes will require more RAM than simpler ones. - **Number of Concurrent Users:** The more users accessing your VPS simultaneously, the more RAM you’ll need to handle their requests efficiently. - **Database Size and Complexity:** Databases store most of their live data in active memory, therefore large and complex databases demand more RAM for optimal performance. - **Growth Potential:** It’s essential to factor in future growth when choosing your VPS RAM to avoid performance bottlenecks down the line. ### How Much RAM Do I Need? This is the million-dollar question. You should always read the documentation of the site or application you plan on hosting on your VPS server. You also need to consider if your VPS will have a single use or multiple uses. In the next section, we will break down the requirements to demonstrate which application types require minimal amounts of RAM, and show an example of which application types need lots of RAM. #### What Applications Require Minimal Amounts of RAM? Several types of server applications are known for their relatively low RAM requirements, making them suitable solutions for resource-constrained cluster environments or VPS with limited memory. **Lightweight Web Servers:** - **Nginx:** Renowned for its efficiency and low memory footprint, Nginx is a popular choice for serving *static* content and handling reverse proxy duties. - **Lighttpd:** Another lightweight web server option known for its speed and minimal resource usage. - **Caddy:** A modern web server with automatic HTTPS support and a focus on ease of use, often requiring less RAM than traditional web servers. **File Servers & FTP Servers:** - **vsftpd:** A secure and efficient FTP server with a small memory footprint, ideal for basic file sharing and transfer needs. - **ProFTPD:** Another popular FTP server is known for its stability and relatively low RAM usage. - **Samba:** While slightly more resource-intensive, Samba enables file sharing between Windows and Linux/Unix systems and can still run on servers with modest RAM. **Mail Servers:** - **Postfix:** A widely-used mail transfer agent (MTA) with a focus on efficiency and security, typically requiring minimal RAM for standard email operations. - **Dovecot:** A popular IMAP and POP3 server known for its fast performance and relatively low memory usage. **DNS Servers:** - **BIND:** The most widely deployed DNS server software, capable of running efficiently on systems with limited RAM. - **Unbound:** A modern, validating, recursive, and caching DNS resolver with a small memory footprint and a focus on security. **Monitoring & Logging Servers:** - **Nagios:** A popular open-source monitoring system that can run effectively on servers with modest RAM. - **Zabbix:** Another powerful monitoring solution known for its scalability and ability to operate on systems with limited resources. - **rsyslog:** A versatile and efficient logging system that typically requires minimal RAM for standard log collection and forwarding tasks. **Other Lightweight Applications:** - **OpenVPN:** A popular open-source VPN solution that can be run on servers with limited RAM for secure remote access. - **DHCP Servers:** Dynamic Host Configuration Protocol servers for automatically assigning IP addresses to network devices usually require minimal RAM. - **Simple Proxy Servers:** Basic proxy servers for web browsing or content filtering can often run efficiently on systems with limited resources. These examples demonstrate that you don’t need to throw memory at a VPS to get enterprise-grade applications. For the best results, it would be sensible to run these applications on Linux. #### What Applications Require Large Amounts of RAM? So, what applications need lots of RAM for the best performance? **Databases:** - **Large relational databases:** MySQL, PostgreSQL, Oracle, and Microsoft SQL Server can consume significant RAM, especially with large datasets and complex queries. - **NoSQL databases:** MongoDB, Cassandra, and Couchbase can also require ample RAM for caching and handling large volumes of data. **Virtualization Platforms:** - **Hypervisors:** VMware ESXi, Hyper-V, and KVM need substantial RAM to host and manage multiple virtual machines efficiently. **Web Servers & Application Servers:** - **Java application servers:** Tomcat, JBoss, and WebSphere can be memory-intensive, particularly when running complex Java applications. - **High-traffic web servers:** Apache, Nginx, and IIS may require more RAM when serving large numbers of *concurrent* users or handling resource-intensive web applications. **Big Data & Analytics Platforms:** - **Hadoop, Spark, and other big data frameworks:** These platforms often process and analyze massive datasets, necessitating ample RAM for optimal performance. **Machine Learning & AI:** - **TensorFlow, PyTorch, and other ML frameworks:** Training and deploying complex machine learning models can be computationally intensive and require significant RAM. **Gaming Servers:** - **Popular multiplayer games:** Minecraft, Counter-Strike, and other popular games can require dedicated servers with plenty of RAM to support many concurrent players and ensure smooth gameplay. **Media Servers:** - **Plex, Emby, and other media servers:** Transcoding and streaming high-quality video and audio content can demand a good amount of RAM, especially when serving multiple users simultaneously. ## Linux VPS & Dedicated Server Linux servers are generally much more memory efficient. At Atlantic.Net, we provide a diverse array of open-source distributions for VPS hosting. Here’s what’s on offer: - Ubuntu Server (16.04, 18.04, 20.04, 22.04 – LTS) - Debian (9.13, 10.13, 11.6) - Oracle Linux (7.9, 8.5) - Rocky Road (8.5, 9.2) - CentOS (6.9, 7.8, 8.2) - Fedora (33, 34) - FreeBSD (11.4, 12.2, 13.0) - Arch Linux distributions Each distribution is available in various release versions and editions (32-bit or 64-bit), ensuring compatibility with a wide range of customer applications and cloud services. Altogether, we offer users 26 distinct open-source builds for general release. ## Windows VPS & Dedicated Server Windows Servers typically require more RAM, especially when opting for the Desktop Experience. The minimum RAM recommended is 4GB for a good experience. With administrator privileges, you have complete control over the operating system and access to the familiar Microsoft software applications you rely on. Skip the hassle of complex installations – each Windows instance you create is deployed automatically and ready to use in approximately 60 seconds. We offer the following software versions, each available in different editions (Server Edition, Desktop Experience, Container Edition): - Windows Server 2022 - Windows Server 2019 - Windows Server 2016 - Windows Server 2012 R2 - Windows Server 2008 R2 ### Atlantic.Net’s Expertise: Guiding You to the Right RAM Choice Atlantic.Net’s team of experts is always ready to assist you in selecting the most suitable VPS plan with the right amount of RAM for your specific needs. We will take into account such factors as your current requirements, future growth potential, and budget to determine and recommend the best solution for your business or project. ### VPS RAM and Atlantic.Net: A Winning Combination Whether you’re a startup launching your first website or an established enterprise managing complex applications, Atlantic.Net’s VPS plans with carefully balanced RAM allocations offer the performance, reliability, and scalability features you need to succeed. ## VPS RAM: Key Considerations and Tech Tips If you are already hitting RAM limits on your VPS, there are plenty of options available to you. Of course, you can always scale up your plan to allocate more memory to manage the VPS, but have you thought about these tech tips? - **Startup Scripts and RAM:** Startup scripts, which execute commands automatically when your VPS boots up, can consume RAM. Ensure your scripts are optimized to minimize RAM usage. - **Operating Systems and RAM:** Different operating systems have varying RAM requirements. Choose an OS that is compatible with your VPS RAM and application needs. - **Accessing and Managing VPS RAM:** Atlantic.Net provides tools and interfaces to monitor and manage your VPS RAM usage effectively. ### VPS RAM and Performance Optimization Efficient RAM management is essential for maximizing your VPS performance. Here are some tips to optimize your RAM usage: - **Regularly Monitor RAM Usage:** Keep an eye on your RAM usage using tools provided by Atlantic.Net to identify potential bottlenecks and take corrective action. Consider using additional monitoring tools such as htop, glances, or nmon for a more detailed view of your system’s resource usage. Configure alerts to notify you when your RAM usage reaches a critical threshold. - **Optimize Applications and Databases:** Ensure your applications and databases are configured to use RAM efficiently. Conduct thorough code reviews and use profiling tools to identify areas of your application code that might be inefficiently using memory. Look for memory leaks, excessive object creation, or inefficient data structures. - **Close Unnecessary Processes:** Terminate any processes that are not actively being used to free up RAM. Use tools like top or ps to identify processes that are consuming a disproportionate amount of RAM. - **Upgrade RAM if Needed:** If you consistently experience RAM limitations, consider upgrading to a VPS plan with more RAM. - **free -m Command:** This command provides a quick overview of your VPS’s RAM usage, including total RAM, used RAM, free RAM, shared RAM, and buffers/cache. The -m flag displays the output in megabytes for easier interpretation. - **Swap Space:** Swap space acts as an extension of your RAM, allowing your system to temporarily store less frequently used data on your disk when your RAM is full. ## Atlantic.Net’s Commitment to Customer Success Atlantic.Net is dedicated to providing exceptional customer support and ensuring the success of your projects. Our team of experts is available 24/7 to assist you with any questions or issues you may encounter, including those related to VPS RAM. [Contact the team today](https://www.atlantic.net/about-us/corporate-contact/) to learn about our VPS hosting services and how it can help your business succeed. --- # VMware vs Hyper-V: Which Is Best? > URL: https://www.atlantic.net/vps-hosting/microsoft-hyper-v-or-vmware/ | Published: 2024-09-19 | Updated: 2026-05-30 | Author: Richard Bailey Hypervisors like Microsoft technologies Hyper-V server and VMWare vSphere products are popular for creating your own private and public cloud environments. You can even launch dedicated Hyper-V and VMware clusters directly on some cloud providers – avoiding the need to purchase your own virtualization solutions hardware. VMware ESXi and Hyper-V are Type-1 hypervisors, meaning that the virtualization software is installed directly onto bare-metal hardware and does not require a host operating system. Your virtual machine resides on top of the hypervisor layer, and you can run multiple virtual machines on any operating system inside a VM. In this article, we explore Hyper-V vs VMWare as virtual machine management tools. We will discover the strengths of each type of hypervisor, then do a comparison between Hyper-V vs VMware to give you the information to decide which advanced virtual machine features work best for your business. ## What Is Hyper-V? Hyper-V is a native virtualization platform that’s deeply integrated into the Windows Server operating system. It was first introduced in Windows Server 2008 R2 as a downloadable Windows Update, but since Windows Server 2012, Hyper-V has been a built-in core component of the operating system. But it’s not limited to Windows Server; you can also enable Hyper-V in client versions of Windows such as Windows 10 or Windows 11 operating systems. It’s important to note that these versions are classified as Type-2 hypervisors because they rely on the host operating system to function. The Type-1 Windows Server version runs independently and has access to the hardware layer to manage virtual disks and virtual networking directly. Hyper-V allows the user to create and manage virtual machines (VMs) from a dedicated Windows host. It’s possible to run multiple operating systems in Hyper-V, including Windows, Linux, and FreeBSD, simultaneously on the same physical server. With seamless integration into the Windows Server and OS ecosystem, Hyper-V offers a familiar management experience for Windows administrators. ### Hyper-V: How It Works Hyper-V uses hardware-assisted virtualization technologies (like Intel VT-x or AMD-V) to create virtualized hardware environments for each VM, allowing VMs to run directly on the physical CPU, and providing near-native performance with dynamic resource allocation. The hypervisor manages and allocates the physical resources (CPU, memory, storage, network) to the VMs based on pre-configured settings and current demands, ensuring efficient utilization of resources and allowing multiple VMs to run simultaneously on the same virtualization technology. Each virtual machine runs in its own isolated space, preventing interference from other VMs or the host system. Hyper-V Manager or other management tools (like System Center Virtual Machine Manager or Windows Admin Center) allow administrators to create, configure, start, stop, manage, and run virtual machines, as well as perform tasks like live migration and replication. ### What are the benefits of Windows Server Hyper-V? Microsoft Hyper-V is a popular way to introduce virtualization technology to Windows-centric environments and organizations without investing huge amounts of capital to get started. - **Cost-effectiveness:** Hyper-V is included with Windows Server licenses, making it an attractive option for organizations already invested in Microsoft technologies. - **Ease of use:** Hyper-V Manager offers a straightforward graphical user interface (GUI) for creating, configuring, and managing virtual machines, simplifying the virtualization process for Windows administrators. - **Integration with Windows ecosystem:** Hyper-V seamlessly integrates with other Microsoft technologies like System Center Virtual Machine Manager (SCVMM) and Windows Admin Center, providing centralized management for your entire virtualized environment.  If you know how to use Windows Server, you will pick up Hyper-V very quickly. - **Dynamic memory**: Hyper-V’s dynamic memory feature allows VMs to allocate memory dynamically based on their needs, optimizing resource utilization on the host server.  This is a great way to get high-performing virtual machines, but remember that resources are not infinite. - **Live migration:** Hyper-V enables you to move running virtual machines between physical host server(s) without downtime, ensuring high availability for your critical applications. - **Security features:** Hyper-V offers several security features, including Shielded VMs, Secure Boot, and Virtual Trusted Platform Module (vTPM), to protect your VMs from unauthorized access and malware ## What Is VMware? VMware is a leading provider of virtualization and cloud computing software and services. It’s a company that offers a comprehensive suite of solutions that enable organizations to virtualize their IT infrastructure, from servers and storage to networking and desktops. VMware’s flagship product, vSphere, is a server virtualization platform that allows you to create and manage multiple virtual machines (VMs) on a single physical server, running different operating systems and applications simultaneously. VMware has been around for decades, starting life back in 1998. VMware workstation was released in 1999, and VMware ESXi server virtualization platform was released in 2001. Its been hugely popular, but it can be argued that its popularity has dropped significantly since the mass adoption of cloud based services. However, there is definitely still a big market for VMware virtualization solutions and products. ### Key VMware Products VMware has lots of virtualization products. But when people talk about VMware, they are typically referring to vSphere. However, its important to know that the big 5 VMware products are: - **vSphere**: VMware’s flagship server virtualization platform. - **vSAN**: Software-defined storage solution that pools storage resources from multiple servers. - **NSX**: Network virtualization platform that enables you to create and manage virtual networks. - **Horizon**: Virtual desktop infrastructure (VDI) solution that delivers virtual desktops and applications to users. (Similar to Citrix) - **Workspace ONE**: Unified endpoint management (UEM) platform that enables you to manage and secure mobile devices, desktops, and applications. ### VMware vSphere: How it Works At its core, vSphere enables you to create and manage multiple virtual machines (VMs) on a single physical server, each running its own operating system and applications independently. Resource allocation is dynamically managed by VMware ESXi, ensuring optimal utilization. The physical server’s CPU, memory, storage, and network capabilities are distributed amongst the VMs according to their configured settings and real-time demands. vCenter Server is used as a control center for the entire vSphere environment. From this central hub, administrators can create, configure, and deploy VMs, along with monitoring their resource consumption and overall performance. Install VMWare tools on the VMware VMs to get better performance and interaction with the virtual machine. There are several key components of VMWare to understand: - **VMware ESXi Hypervisor:** VMware ESXi is installed directly on the host hardware and is used to directly manage your host hardware resources. VMware ESXi is a type-1 (bare-metal) hypervisor that installs directly onto the physical server’s hardware. It has complete control over the server’s resources (CPU, memory, storage, network) and creates a virtualized environment for each VM. - **Virtual Machines (VMs):** These are software-based representations of physical computers created by vSphere. Each VM has its own virtual hardware (vCPU, vRAM, vNIC, etc.) and runs its own guest operating system and applications. - **vCenter Server:** A centralized management platform that provides a single pane of glass for managing multiple VMware ESXi hosts and their VMs. It offers features like VM provisioning and deployment, resource allocation and monitoring, high availability and disaster recovery, configuration, and policy management. ## What are the benefits of VMware ESXi Hypervisors? VMware has lots of benefits, especially when combined with VMware Vcenter server. You get an entire virtualized data center in your control to manage virtual machines to your hearts content. Here are some of the key benefits of VMware: - **Performance and scalability:** VMware is known for its class-leading performance and scalability, making it suitable for demanding workloads and large-scale deployments. Technology such as NSX and vSAN enable flexible storage and networking upgrade. - **Advanced management features:** VMware vSphere includes vCenter Server, a centralized management platform for managing multiple VMware ESXi hosts, VMs, and other resources in your virtualized environment.  VMware memory management techniques cleverly manage resources throughout your virtual data center. - **High availability and fault tolerance:** VMware offers various features, like vMotion and vSphere HA, to ensure high availability and fault tolerance for your critical VMs. - **vSphere Distributed Resource Scheduler (DRS)**: DRS dynamically balances workloads across multiple VMware ESXi hosts, optimizing resource utilization and ensuring consistent performance. - **Extensive hardware compatibility:** VMware supports a broad range of server hardware, offering flexibility in choosing your infrastructure. - **Third-party Support**: VMware boasts a vast ecosystem of third-party tools and solutions that integrate seamlessly with its virtualization platform. You can integrate VMware directly into cloud solutions, backup solutions, and third party management tools with ease. ## Comparing VMware and Microsoft Hyper-V Virtual Machines Both VMware and Hyper-V are mature products that have decades of development built into the products. Broadly speaking they offer similar services, but there are some big differences between the two solutions. Both VMware and Hyper-V are powerful virtualization platforms with unique strengths. VMware excels in performance, scalability, and advanced management features, while Hyper-V offers cost-effectiveness, ease of use, and seamless integration with the Windows ecosystem. Your ideal choice will depend on your specific requirements, budget, and technical expertise. ### Cost Considerations Cost is one area that is a major differentiator. Both virtualization platforms require expensive hardware with multiple CPUs, stacks of memory, and redundant networking and storage. If you want high availability (HA) you need to purchase multiple virtualization hosts, if you want disaster recovery capabilities you need to replicate the setup in a secondary location, ensuring storage and network layer replication. These types of requirements alone are an extremely expensive pre-requisite for enterprise-grade virtualization. On the other hand, Hyper-V is included with Windows Server licenses, making it a cost-effective option for organizations already invested in Microsoft. So for example, if you have 16 cores across 2 CPUs, Windows Server Standard Edition [will cost around](https://www.microsoft.com/en-us/windows-server/pricing) $1069 and allow you to run two virtual machines (VMs) on top of it. Windows Server Datacenter Edition will cost around $6155 and allows you to run an unlimited number of VMs. VMware, on the other hand, has a higher upfront costs, with licensing typically based on the number of CPUs in your environment. Their pricing model is also much more complicated and seems to change every few months. vSphere is priced per CPU (not per core), and there are limits about how many cores you can have per CPU, it’s all very confusing. Therefore, [you’re looking at roughly](https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-vcenter-esxi-management/GUID-710CD935-DBF4-4AF6-A4F7-ED35E552DE4C.html) VMware vSphere Enterprise for $3,540 per CPU, and VMware vSphere Enterprise Plus at around $4,805 per CPU. Plus you have to licence features like disaster recovery, vSan and NSX. ### Ease of Use Hyper-V is tightly integrated with the Windows Server operating system, and is generally considered easier to learn and manage, especially for Windows administrators familiar with Microsoft technologies. Hyper-V Manager offers a straightforward graphical user interface (GUI) for creating, configuring, and managing virtual machines (VMs). You can manage Hyper-V from any domain connected Windows Server providing it has the Hyper-V Snap-In installed and your user account has relevant permissions. VMware vSphere, while arguably more powerful, has a steeper learning curve and requires some expertise to navigate the vSphere client interface. However, once mastered, the VMware UI is slick and easy to use because it uses a very well designed HTML6 virtualization client. vCenter is also based on an OS called Photon, a heavily customized Linux Kernel, which makes the CLI very reliable and super fast. ### Management Tools Both platforms provide reliable management tools. VMware vCenter Server is a centralized management appliance for multiple ESXi hosts, VMs, and other resources. Hyper-V integrates with tools like System Center Virtual Machine Manager (SCVMM) and Windows Admin Center for comprehensive management capabilities. Whichever you prefer comes down to personal choice. I find the Hyper-V integrations quite clunky and slow, plus the UI is basic and unintuitive. However, would I pay more for VMware just because of the UI? I’m not so sure if I were picking up the cost. ### Performance and Scalability VMware is renowned for its excellent performance and scalability, making it suitable for large-scale deployments and demanding workloads, such as enterprise environments with mission-critical applications. VMware is normally the number one choice for the enterprise because of its performance. You can tell that vSphere is a mature, highly efficient product. It handles errors and issues seamlessly, and every one of the features works faultlessly. You can happily leave VMware running knowing that your virtualization platform is safe and will heal automatically. Hyper-V also offers good performance but is generally better suited for small to medium-sized deployments. While Hyper-V is reliable, it’s not uncommon for features to simply not work, such as automated failover; if the operating system throws an error, the failover may hang or freeze. From experience, I have had a much more seamless experience with VMware ESXi. ### Guest OS Support Both VMware environments and Hyper-V have their strengths when it comes to guest operating system support and flexibility with virtual machine images. Both support Windows Centric environments and will deploy Linux VMs. VMware shines with its expansive compatibility, welcoming a wide range of guest operating systems, even those that are older, out of manufacturer support or less common. This makes it an excellent choice if you have diverse or legacy workloads that need to be virtualized. On the other hand, Hyper-V primarily focuses on Windows and Linux, but it’s incredibly well-optimized for these environments, often delivering superior performance and smoother integration with these operating systems. When it comes to VM images, both platforms allow you to create custom images, giving you control over your virtual environments. However, VMware’s ecosystem boasts a richer selection of pre-configured images available through its marketplace and third-party vendors. Hyper-V users on Azure have access to the extensive Azure Marketplace library. If you need a wide variety of readily available images or the flexibility to create highly customized ones, VMware might be a better fit. ### High Availability (HA) Both platforms provide features to ensure the high availability of your VMs. VMware offers vMotion for live migration of VMs between hosts without downtime, as well as vSphere HA and Fault Tolerance for automatic VM restarts and protection against data loss. Hyper-V provides Live Migration and Failover Clustering for similar high-availability capabilities. When considering Hyper-V vs VMWare, I prefer the way that VMWare handles HA. ### Security Features Both platforms offer robust security features to protect your virtual environment. VMware includes encryption, vTPM (virtual Trusted Platform Module), and Secure Boot. Hyper-V offers Shielded VMs, Secure Boot, and vTPM for enhanced security. These services are essentially the same, so both offer goo security features. ## VMware and Hyper-V Hosting with Atlantic.Net Atlantic.Net provides support for both VMware and Hyper-V environments. We offer private cloud hosting with either platform, and our award-winning virtualization solutions can cater to your business’s diverse needs, supporting virtual machines running on any operating system. Whether you’re managing Windows Servers, utilizing Windows Server licenses, or exploring other operating systems, Atlantic.Net’s offerings can fit your requirements. Atlantic.Net’s flexible approach allows you to select the virtualization software best aligned with your needs. For organizations heavily invested in Windows Servers, Hyper-V might be a natural fit. VMware’s broad operating system support and extensive feature set make it a compelling choice for enterprise-scale environments. [**Contact Atlantic.Net today**](https://www.atlantic.net/about-us/corporate-contact/)**to explore your options and embark on a seamless virtualization journey.** Our team of experts will assist you in choosing the ideal platform, configuring your environment, and ensuring optimal performance for your virtual machines. Whether you’re seeking enhanced resource utilization, streamlined management, or improved disaster recovery capabilities, Atlantic.Net has the solution for you. **Unlock the full potential of your IT environment with Atlantic.Net.** **Related Guides:** - [HIPAA Compliant Hosting Solutions](https://www.atlantic.net/hipaa-compliant-hosting/) - [PCI-Compliant Hosting Solutions](https://www.atlantic.net/pci-compliant-hosting/) - [What Are Managed Services?](https://www.atlantic.net/managed-services/what-are-managed-services/) **Related Products:** - [Atlantic.Net Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/) - [Atlantic.Net HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) - [Atlantic.Net GPU Hosting](https://www.atlantic.net/gpu-server-hosting/) --- # What Are the Benefits of Managed Hosting? > URL: https://www.atlantic.net/vps-hosting/benefits-of-managed-hosting/ | Published: 2024-09-20 | Updated: 2024-09-24 | Author: Richard Bailey Managed hosting removes the complexity of building and managing the entire IT ecosystem. Specialist managed service providers take responsibility for the entire IT operation, such as procurement, server monitoring and management, and day-to-day business operations. Building a suitable data center and hosting environment requires teams of expert personnel, engineers, and analysts capable of designing, building, and managing every component that makes up the IT platform. Trying to do all this in-house is a complex and challenging task, and that is why managed cloud server hosting is so important. In this article, we’ll break down what managed hosting is, how it stacks up against unmanaged hosting, and give you the info you need to choose the best service for your business. ## **The Key Benefits of Managed Hosting Services** First, let’s look at some of the key reasons business leaders choose managed hosting: ### **#1: Enhanced Security** Cybersecurity is one of the most important and challenging aspects of modern business. Security must be a top priority for any business that has any form of online presence or relies on any cloud or server-based services. Cyber challenges and the threat landscape are constantly changing. Data breaches and security vulnerabilities have the potential to cripple businesses, leading to financial losses, reputational damage, and legal repercussions. Managed hosting can step in to deploy proven security measures that ensure your network infrastructure remains protected at all times. Here are some of the core security protections you should expect from your managed hosting partner: **Firewalls:** Advanced firewalls filter incoming and outgoing network traffic, blocking unauthorized access attempts and potential threats at the network perimeter. For your web-based applications, it’s highly recommended to also invest in a Web Application Firewall (WAF), typically a software-based firewall that can be dynamically updated to respond to changes in the threat landscape. **Intrusion Protection Systems (IPS):** An IPS actively monitors network activity, identifying suspicious patterns and potential intrusions, allowing for swift response and mitigation. An IPS works seamlessly with SIEM platforms to alert the relevant support personnel if a security baseline is breached. **Regular Security Audits:** It’s highly recommended to complete thorough risk assessments, security audits, and complete vulnerability scanning at least once every 6 to 12 months. Additionally, it’s essential to implement any necessary improvements, ensuring your systems remain up-to-date and protected against the latest threats. **Data Encryption:** Sensitive data must be encrypted both at rest and in transit. We recommend a minimum of AES256 encryption standards to add an extra layer of protection in case of an unauthorized access breach, plus SSL certificates to validate your ecommerce sites. Remember, Atlantic.Net offers free SSL certificates with our Managed WordPress hosting! **DDoS Protection:** Distributed Denial of Service (DDoS) attacks can overwhelm your servers and disrupt your business operations. Managed hosting employs DDoS mitigation integration to absorb and deflect such attacks, ensuring your services remain available to your customers. **Patch Management:** Regular update scans will identify potential hotfixes for your systems. Manufacturers and software vendors frequently release security patches and updates to improve application protection. Ensure these updates are applied on a regular, and ideally scheduled basis. **Compliance Assistance:** If your business operates in a regulated industry (e.g., healthcare, finance), a managed hosting services can help to ensure that you meet the necessary compliance standards, such as HIPAA or PCI DSS. ### **#2: Server Maintenance and Monitoring** Another major benefit of choosing managed hosting is server management. Maintaining optimal server performance requires constant attention and technical expertise. Managed hosting takes on the responsibility of server monitoring and maintenance, ensuring your systems operate at peak efficiency 24/7. Managed Hosting providers like Atlantic.Net offer a service wraparound that includes alert response to common system alerts such as low disk space, high CPU, or low memory warnings. Managed services exist that enhance the service; our engineers can be involved as much (or as little) as you want. Other popular server maintenance tasks include: **Hardware and Software Updates:** Regularly updating server hardware and software is essential for optimal performance and security. Managed hosting handles these updates seamlessly, minimizing downtime and ensuring compatibility. Remember that the underlying infrastructure is also entirely managed by the hosting provider. **Server Backups:** Data loss can be catastrophic for businesses. Managed hosting implements reliable backup strategies for your systems. This ensures that your critical data is protected and can be easily restored in case of unforeseen events. **Proactive Issue Resolution:** With continuous server monitoring, potential issues are identified and addressed before they escalate into major problems, minimizing downtime and disruptions to your business. Analysis of regular issues helps improve overall server performance and improves reliability. **Load Balancing:** As your business grows, traffic to your applications and services may increase. Managed hosting can implement application load-balancing techniques to distribute traffic evenly across multiple servers, ensuring optimal performance and responsiveness even during peak periods. **Performance Optimization:** Hosting management experts can fine-tune your server configurations and optimize resource allocation to enhance performance and speed. ### **#3: Cost Savings** Managed hosting introduces significant cost savings because it eliminates the need for expense outlays on hardware procurement, licensing, support, and data center costs. Managed hosting offers predictable monthly hosting plan fees by using a pay-as-you-go model, allowing for better budget planning and eliminating unexpected expenses associated with purchasing hardware, maintenance contracts, and engineer visits to fix problems. You can also purchase long-term usage plans, typically from 1 to 3 years. This introduces further cost savings because the rate you pay is much lower than the pay-as-you-go price. This is a fantastic option if you know what hardware you need for the foreseeable future. Extended payment plans are popular for database servers which remain online 24×7 and are rarely decommissioned. Additionally, managed hosting eliminates the need to hire in-house system admins to manage the server environment. This can lead to significant cost savings for businesses and is one of the major benefits of managed hosting to senior management. ### **#4: Scalability** Business needs change over time, and as your business grows, your managed web hosting solution should scale to accommodate increased traffic, data storage requirements, and application demands. Managed hosting service providers offer flexible plans that allow you to easily upgrade your hosting resources to accommodate additional resource demands. Scalability ensures optimal performance and responsiveness even during peak trading periods such as Black Friday and Christmas. ### **#5: Expert Support** Technical issues can happen at any time, potentially disrupting your business operations and causing frustration to employees and customers. Managed hosting offers round-the-clock technical support, ensuring expert assistance is always at your fingertips. Providers are expected to offer dedicated 24×7 support teams that are trained to troubleshoot a wide range of server-related problems, providing timely solutions and minimizing downtime. Professional support means you have access to a knowledgeable team whenever you need them. ### **#6: Focus on Core Business Goals** From the feedback we get from our customers, one of the most popular benefits of managed hosting is that it gives the business back the opportunity to focus on running their business. Customers are no longer fighting with their IT systems or struggling to get things working because Atlantic.Net’s experts now manage the systems, giving the customers their precious time back to focus on what’s important to them. By offloading day-to-day business operations and server management, businesses can dedicate their valuable time to helping their customers and driving innovation. ### **#7: Access to the Latest Technologies** Technology in IT is constantly changing, with new software, hardware, and security protocols emerging all the time. Keeping up with these advancements can be challenging (and expensive), especially for businesses with limited IT resources. Managed hosting partners with hardware technologists to get access to the latest technology, plus they have the required capital to invest in the latest hardware, ensuring your infrastructure is always up-to-date and equipped to handle the demands of modern business applications. ### **#8: Improved Website Performance** Website owners know that speed and performance are crucial for user experience and search engine rankings. Popular services like managed WordPress hosting are available too. Managed hosting providers use various techniques to optimize website performance, such as: **Content Delivery Networks (CDNs):** Edge network services like CDNs distribute website content across multiple content servers (caching) around the world, ensuring fast loading times for visitors regardless of their location. **Server-Side Optimization:** Managed hosting can fine-tune server configurations and optimize code to enhance website performance. **High Performance Server Hardware:** VPS servers with SSD storage and advanced Intel processors offer excellent performance for your web server. ### #9: Disaster Recovery and Business Continuity Unforeseen events such as natural disasters, hardware failures, or cyberattacks can disrupt your business operations and lead to significant downtime. Having a reliable web hosting provider that can offer managed disaster recovery capabilities is essential, especially if you need compliance hosting (such as HIPAA) where Disaster Recovery is a required part of compliance. **Redundant Infrastructure:** Data is often stored across multiple cloud servers in various locations, ensuring that even if one server fails, your data remains safe and accessible. Having redundant server infrastructure means that if one of your servers fails, a like-for-like server is available to automatically pick up the workload This also applies to backups where the hosting company keeps copies of your data safe in different locations, essential if you are hit by a disaster where your online store or e-commerce sites are taken offline. **Failover Systems:** In the event of a server failure, traffic is automatically redirected to a secondary server, minimizing downtime and ensuring business continuity. **Regular Testing:** Managed hosting providers regularly test their disaster recovery plans to ensure they are effective and can be executed swiftly in a crisis. ### #10: Customization and Flexibility Managed hosting providers like Atlantic.Net understand that businesses have unique needs and requirements. We know that one size does not fit all, and because of this, we offer a range of customizable solutions, allowing you to tailor the hosting environment to your specific needs. This can include: **Choice of Operating Systems:** Select the operating system that best suits your applications and workloads. Our VPS servers are available with a choice of Windows Server or Linux Operating Systems. Or if you opt for our co-location hosting you can use whatever operating system you want, Hyper-V, VMware, AIX, I-Series – it doesn’t matter. **Software Installation and Configuration:** Managed hosting providers can help install and configure the software you need to run your business. We are partnered with all of the major software and hardware vendors, and we can offer competitive licensing options. Just get in touch to learn more about how managed hosting works. **Resource Allocation:** Customize your shared and dedicated hosting server resources, such as CPU, RAM, and storage, to match your specific requirements. All of our servers use SuperMicro Servers with genuine Intel CPUs, all our storage is at a minimum SSD with NVMe options available. We even have dedicated hosts if you need extra power. **Managed Services:** Choose from a variety of managed services, such as database management, security monitoring, and application optimization, to further enhance your IT infrastructure. ## **What Is the Difference Between Managed vs. Unmanaged Hosting Services?** Now you know what Managed Hosting offers you. But did you know that with Atlantic.Net you can also go down the Unmanaged Hosting route? Understanding the key distinctions between managed and unmanaged hosting is crucial in selecting the right solution for your business. ### **Unmanaged Hosting: The DIY Approach** #### **DIY Server Management** You have complete control over your dedicated server or cloud servers, meaning you get to decide how it’s set up, maintained, and secured. This level of control is ideal if you want to fine-tune every aspect of your server environment to match your exact needs. #### Hybrid Technical Support Atlantic.Net support teams are always available, even for our unmanaged hosting clients. We know that some of our customers have teams of IT experts in-house, so we are more than happy for you to handle any technical concerns; just remember, we are here if you need us. #### Cost Unmanaged hosting typically comes with a lower price tag, making it an attractive option for businesses on a tight budget or those who want to maximize their resources. You only pay for the server itself, without any additional fees for management services. It can eliminate some costs associated with managed hosting. #### Flexibility and Customization With unmanaged hosting, you’re not bound by any pre-defined configurations or restrictions. You can install any software you need, configure the server to your liking, and experiment with different setups without having to seek approval or assistance. Overall, unmanaged hosting is a good option for businesses or individuals who: **Value Control:** Want complete control over their server environment. **Have Technical Expertise:** Possess the technical skills to manage a server effectively, including things like running backups, software upgrades, and basic security measures. **Seek Cost Savings:** Want to minimize hosting costs. **Need Flexibility:** Require a high degree of customization and freedom to experiment. While unmanaged hosting offers many benefits, it’s essential to be realistic about your technical capabilities and time commitment. If you’re not comfortable managing a server or don’t have the resources to dedicate to it, managed hosting might be a more suitable choice, especially if you value things like 24/7 support, customer data protection, and having a hosting company handle the technical side so you can focus on your core business and customer relationships. Remember, whether you choose unmanaged hosting, managed VPS hosting, managed WordPress hosting, or even shared hosting, the key is to select the hosting service that best aligns with your needs and resources. ## Why Choose Atlantic.Net Managed Hosting? We know that selecting a reliable managed hosting provider is a critical decision that can impact your IT infrastructure’s performance, security, and overall efficiency. When you choose us for your hosting, you get so much more: ### Performance and Uptime Our platform is architected durably and robustly. Our engineers have spent years perfecting our platform. We are that confident in the service that we offer class-leading [100% uptime SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/). ### Security Features Security is key with Atlantic.Net. With our managed hosting you get access to security measures such as firewalls, intrusion protection systems, data encryption, multi-factor authentication, Network Edge protection, and more to protect your critical business information. ### Scalability With Atlantic.Net, your business can grow and scale as needed. All our services can scale up as needed to provide greater performance, and more storage, of a bigger hosting plan. We have flexible plans that can easily scale to accommodate your business growth. ### Technical Support Our support teams are all based in the United States. We offer [around-the-clock support](https://www.atlantic.net/support/), every day of the year. The team is available via phone and email. We also offer professional support services for your next project. ### Customer Reviews and Reputation Atlantic.Net’s hosting platforms are award-winning. Don’t just take our word for it; [check out what our customers say](https://www.atlantic.net/hosting-services-provider/award-winning-service/). ### Pricing and Value Compare our pricing plans with different providers, and you will see that we are competitively priced and offer more bang for your buck. ### Multiple Hosting Choices Consider whether you need to opt for shared hosting, dedicated servers, dedicated hosting, virtual private server (VPS) hosting, or cloud hosting, depending on your traffic levels, resource requirements, and budget. ## Atlantic.Net: Your Trusted Managed Hosting Partner At Atlantic.Net, we offer a range of award-winning managed hosting solutions tailored to your unique requirements. Our team of experts is dedicated to providing exceptional service, ensuring your network remains secure, performs optimally, and scales seamlessly with your business. [Contact us today](https://www.atlantic.net/about-us/corporate-contact/) for a free consultation and discover how we can help you achieve your IT goals with a customized managed hosting solution. --- # How to Fix HTTPS Download Errors with wget > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-fix-https-download-errors-with-wget/ | Published: 2024-09-21 | Updated: 2024-10-03 | Author: Hitesh Jethva The wget command is one of the most powerful tools in Linux for downloading files from the web. It supports both HTTP and HTTPS protocols, allowing users to download files securely. However, HTTPS downloads can sometimes fail due to certificate issues or misconfigurations. In this guide, we’ll explore how to troubleshoot and fix HTTPS download errors when using wget. ## What Is wget and Why Use It? **wget** is a non-interactive command-line tool for downloading files over the web. It can download files via HTTP, HTTPS, and FTP protocols. wget is especially useful because it works in the background, supports recursive downloads, and can resume broken downloads. While wget works seamlessly with HTTP links, HTTPS downloads can sometimes cause issues due to SSL certificate verification failures or other security-related problems. ## Common Causes of HTTPS Download Errors with wget When using wget with HTTPS URLs, some of the most common reasons for download failures include: - **SSL certificate verification failure**: The server’s certificate is not trusted. - **Outdated CA certificates**: The client machine’s certificate authority (CA) file is missing or outdated. - **Self-signed certificates**: The server is using a self-signed certificate. - **Proxy misconfiguration**: A proxy server or firewall is blocking the connection. - **Outdated OpenSSL**: wget relies on OpenSSL, and if it’s outdated, issues may occur. Let’s look at common HTTPS download error messages and how to fix them. ## Common HTTPS Download Errors Some typical errors you might encounter when downloading files via HTTPS using wget include: **SSL Certificate Error:** ```bash ERROR: The certificate of 'example.com' is not trusted. ERROR: The certificate of 'example.com' hasn't got a known issuer. ``` **Self-signed Certificate Error:** ```bash ERROR: The certificate of 'example.com' is self-signed. ``` **Connection Timed Out:** ```bash ERROR: Failed to establish a connection. ``` Now, let’s go through how to fix these issues step by step. ## Method 1: Ignoring SSL Certificate Checks Sometimes the certificate verification fails due to a misconfigured server or an expired certificate. In such cases, you can bypass SSL verification with the **–no-check-certificate** option. However, be cautious when using this method as it disables security checks. ```bash wget --no-check-certificate https://example.com/file ``` **Note:** This method is insecure and should only be used as a last resort or for trusted internal connections. ## Method 2: Updating CA Certificates If your system’s CA certificates are outdated or missing, wget may fail to verify the SSL certificate of the server. Updating your CA certificates can resolve this issue. **Update CA Certificates on Debian/Ubuntu:** ```bash apt-get install --reinstall ca-certificates ``` **Update CA Certificates CentOS/RHEL:** ```bash yum reinstall ca-certificates ``` After reinstalling CA certificates, try downloading the file again with wget. ## Method 3: Manually Specifying a Certificate Authority (CA) File If you have a custom or self-signed certificate, you can manually specify the CA file to be used by wget. ```bash wget --ca-certificate=/path/to/ca-cert.pem https://example.com/file ``` This tells wget to use the specified CA certificate file to validate the server’s certificate. ## Method 4: Fixing Proxy Issues If your network uses a proxy, misconfigurations can cause wget to fail when downloading via HTTPS. To fix this, you can configure wget to use a proxy server either via the .wgetrc file or directly in the command. ```bash wget --proxy=on --https-proxy=https://proxyserver:port https://example.com/file ``` Alternatively, edit the .wgetrc file to set proxy options globally: ```bash nano ~/.wgetrc ``` Add the following lines: ```bash use_proxy=yes https_proxy=https://proxyserver:port ``` ## Method 5: Updating or Reinstalling OpenSSL wget relies on the OpenSSL library to handle HTTPS connections. An outdated or missing version of OpenSSL can cause HTTPS errors. To fix this, update OpenSSL to the latest version. **Update OpenSSL Debian/Ubuntu:** ```bash apt-get install openssl ``` **Update OpenSSL CentOS/RHEL:** ```bash yum install openssl ``` After updating OpenSSL, retry the wget command. ## Conclusion In this guide, we have provided clear steps to troubleshoot and fix HTTPS download errors with wget. HTTPS download errors with **wget** can be frustrating, but they are usually easy to fix once you understand the underlying cause. Hopefully this guide helps you troubleshoot HTTPS downloading errors on [**dedicated server hosting**](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Find Open Ports and Close Them in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-find-open-ports-and-close-them-in-linux/ | Published: 2024-09-22 | Updated: 2024-10-03 | Author: Hitesh Jethva Managing open ports in Linux is crucial for system security. Open ports can be entry points for unauthorized access if not monitored properly. This guide will walk you through finding open ports on your Linux system and how to close them to enhance your system’s security. ## What Are Open Ports in Linux? An open port is a network port that accepts incoming connections. Ports are communication endpoints for networked devices, allowing services and applications to communicate over a network. There are two main types: - **TCP Ports:** Ensure reliable communication with error checking. - **UDP Ports:** Faster communication without error checking. Each service or application running on your Linux system may listen on a specific port for incoming connections. ## How to Find Open Ports in Linux There are several tools available to identify open ports on your Linux system: - **netstat:** Network statistics tool. - **ss:** Socket statistics, a modern replacement for netstat. - **lsof:** Lists open files and ports. - **nmap:** Network scanner for discovering hosts and services. ### 1. Using netstat to List Open Ports The **netstat** command displays network connections, routing tables, and interface statistics. ```bash netstat -tuln ``` Output: ```bash Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN tcp6 0 0 :::80 :::* LISTEN udp 0 0 0.0.0.0:68 0.0.0.0:* ``` This output shows SSH (port 22) and HTTP (port 80) are open and listening for connections. **Explanation:** - **-t:** Shows TCP connections. - **-u:** Shows UDP connections. - **-l:** Lists listening ports. - **-n:** Displays addresses and port numbers in numerical form. ### 2. Using ss to Check Open Ports The **ss** command provides similar functionality to netstat but is faster and more efficient. ```bash ss -tuln ``` Output: ```bash Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port udp UNCONN 0 0 0.0.0.0:68 0.0.0.0:* tcp LISTEN 0 128 0.0.0.0:22 0.0.0.0:* tcp LISTEN 0 128 [::]:80 [::]:* ``` The output shows open ports similar to Netstat. ### 3. Using lsof to Find Listening Ports The **lsof** command lists open files, which can include network connections since they are treated as files in Unix-like systems. ```bash lsof -i -P -n | grep LISTEN ``` Output: ```bash sshd 1234 root 3u IPv4 1234567 0t0 TCP *:22 (LISTEN) apache2 5678 www-data 3u IPv6 7654321 0t0 TCP *:80 (LISTEN) ``` This output shows that sshd is listening on port 22 and apache2 is listening on port 80. Options Explained: - **-i:** Lists IP-related files. - **-P:** Shows port numbers instead of service names. - **-n:** Avoids DNS lookup for hostnames. ### 4. Scanning Open Ports with nmap **nmap** is a powerful network scanning tool that can discover hosts and services on a network. Run the following command to scan localhost. ```bash nmap -sT localhost ``` Output: ```bash Starting Nmap 7.60 ( https://nmap.org ) at 2023-10-01 12:00 UTC Nmap scan report for localhost (127.0.0.1) Host is up (0.000012s latency). Not shown: 998 closed ports PORT STATE SERVICE 22/tcp open ssh 80/tcp open http ``` This output shows that ports **22** and **80** are open on the localhost. ## How to Close Open Ports in Linux To close an open port, you generally need to stop the service using it. The basic syntax to stop the service is shown below: ```bash systemctl stop service-name ``` For example, if you want to close HTTP port **80,** you will need to stop the Apache service. ```bash systemctl stop apache2 ``` To stop SSH port **22,** run the following command: ```bash systemctl stop sshd ``` ## Blocking Ports Using Firewall (iptables or UFW) You can use firewall rules if you cannot stop a service but want to block access to a port. **Using iptables to Block a Port** ```bash iptables -A INPUT -p tcp --dport 80 -j DROP ``` Verify the added rules. ```bash iptables -L ``` Output: ```bash Chain INPUT (policy ACCEPT) target prot opt source destination DROP tcp -- anywhere anywhere tcp dpt:80 ``` **Using UFW to Block a Port** UFW (Uncomplicated Firewall) is a user-friendly frontend for iptables. To close/block the port 80, run: ```bash ufw deny 80/tcp ``` Verify UFW Status: ```bash ufw status ``` Output: ```bash Status: active To Action From -- ------ ---- 80/tcp DENY Anywhere 80/tcp (v6) DENY Anywhere (v6) ``` ## Conclusion Monitoring and managing open ports is a fundamental aspect of Linux system security. Regularly checking for open ports and closing or securing them reduces potential vulnerabilities. You can now easily find open ports and close them on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Ecommerce Security Best Practices & Adding Ease-of-Use > URL: https://www.atlantic.net/pci-compliant-hosting/10-ecommerce-security-best-practices/ | Published: 2024-09-23 | Author: Richard Bailey Ecommerce businesses typically handle large volumes of sensitive customer data, such as credit card data, personal details, other financial data, and browsing history. Protecting this sensitive data is not only a legal and ethical responsibility but also crucial for maintaining customer trust and the long-term success of your online business. In this article, we will explore the complexity of ecommerce security and look at common ecommerce security threats that businesses face. We’ll discuss essential security measures to implement and provide actionable tips for enhancing the overall user experience on your ecommerce website. By understanding the risks and taking proactive steps to mitigate them, you can create a secure and trustworthy online environment for your customers. ## Understanding Ecommerce Security Ecommerce is a prime target for hacking communities, and ecommerce security threats are constantly changing. This rapidly changing security ecosystem makes it imperative for ecommerce businesses to stay vigilant and adapt their security strategies as the trends change. Let’s examine some of the most common ecommerce security threats that may target your platform and customer data: ### #1: Data Breaches Data breaches involve unauthorized access to sensitive customer data, often resulting in identity theft, financial fraud, and reputational damage for e-commerce sites. Ecommerce security breaches occur for various reasons, but some of the most common reasons include weak system passwords, unpatched software vulnerabilities, and inadequate security protection such as anti-malware software and anti-virus software. The repercussions of a data breach can be devastating for your ecommerce business, potentially leading to financial losses, losing customers, and potential legal consequences. ### #2: Cross-Site Scripting (XSS) Cross-site scripting (XSS) is a popular attack vector used to exploit vulnerabilities in web applications to inject malicious code into web pages. This malicious code can then be executed on the victim’s browser, allowing hackers to steal customer information, hijack sessions, or deface an ecommerce site. XSS attacks are particularly dangerous because they can target unsuspecting users who simply visit a compromised ecommerce site. ### #3: SQL Injection SQL injection attacks target vulnerabilities in web applications to gain unauthorized access to databases. By injecting malicious SQL queries, hackers can retrieve, modify, or delete sensitive customer data directly from the database. SQL injection attacks can also be used to hijack websites or gain complete control over ecommerce website content. These attacks highlight the importance of strong database security and enabling input validation protections. ### #4: Brute Force Attacks Hackers use brute force attacks to repeatedly guess passwords or encryption passphrases until they gain access to the systems that hold the sensitive data. These attacks can be time-consuming but are often successful against weak or easily guessable passwords. Implementing strong password policies, multi-factor authentication, and account lockout mechanisms will help to effectively prevent brute force attacks. ### #5: Distributed Denial of Service (DDoS) Attacks DDoS attacks aim to overwhelm ecommerce websites with a massive spike of traffic, rendering an ecommerce site inaccessible to legitimate customers and disrupting online transactions. These attacks are often launched by botnets coordinated by groups of hackers. DDoS often results in downtime, and downtime costs ecommerce businesses money, which can result in significant financial losses and reputational damage. DDoS mitigation managed services and robust network infrastructure (and monitoring) are crucial for repelling such attacks. ### #6: Phishing Attacks Phishing attacks rely on deceptive tactics to trick users into revealing their personal information or login credentials. These attacks often involve fraudulent emails, websites, or social media messages that impersonate legitimate ecommerce companies or financial institutions. Educating customers about phishing scams and social engineering is critical, and implementing email authentication protocols can improve the ecommerce security required to help prevent phishing attacks. ### #7: Malware and Ransomware Attacks Malware and ransomware attacks involve the use of malicious software to infect ecommerce sites, steal data, and encrypt files. Ransomware attacks, in particular, can cripple online businesses by demanding a ransom payment in exchange for the decryption key. Regular software updates, anti-malware solutions, and secure backups are essential for protecting against these threats. ### #8: Third-Party Integrations Integrating third-party services into your ecommerce platform offers significant benefits to business, but remember: ecommerce security is a shared responsibility. When you partner with a third-party provider, you’re essentially extending your trust to them. Choose providers that prioritize security as much as you do, ensuring their ecommerce security practices align with industry best practices. ## Safeguarding Your Ecommerce Business Customer Data Protecting your business and your customer data requires a multi-layered approach to e-commerce security. The good news is that there is plenty that can be done to improve your security posture. By implementing the following essential ecommerce security measures, you will significantly reduce your risk of cyberattacks and data breaches. ### #1: Secure Sockets Layer (SSL) Certificates SSL certificates encrypt data transmitted between the customer’s browser and a web server, ensuring genuine connections and secure online transactions on your ecommerce website. This encryption prevents hackers from intercepting and stealing sensitive information, such as credit card details or login credentials. Look for the padlock icon and “https://” in the address bar to confirm that an ecommerce website is using an SSL certificate. You can also view more information about the certificate from your browser to ensure you are browsing the genuine site. ### #2: Strong Password Policies Enforcing strong password policies is fundamental to e-commerce security. Encourage customers and employees to create complex passwords that include a combination of uppercase and lowercase letters, numbers, and symbols. Such policies can be enforced by tools like Group Policy. Create a policy that requires the user to implement regular password changes and consider implementing password managers to help users generate and store secure passwords. ### #3: Multi-Factor Authentication (MFA) Multi-factor authentication (MFA) adds an extra layer of security to servers and websites by requiring users to provide additional verification, such as a code sent to their mobile device or a fingerprint scan, before accessing their accounts. This significantly reduces the risk of unauthorized access even if passwords are compromised. ### #4: Web Application Firewalls (WAFs) Web application firewalls (WAFs) filter and monitor traffic to e-commerce websites, blocking malicious requests and protecting against common security threats like SQL injection and cross-site scripting. The WAF acts as a logical barrier between your website and potential attackers, analyzing incoming traffic and identifying suspicious patterns. Remember, its also possible to configure your WAF to intelligently block known ecommerce security threats, and if a 0-day threat is detected, the WAF can be quickly updated to give you immediate protection across your entire technology stack. ### #5: Anti-Malware and Anti-Virus Software Regularly updating your anti-malware and anti-virus software, along with timely installation of security patches, is crucial for detecting and removing malicious software that could compromise your e-commerce systems. These programs are often the first physical line of defense against security threats on your devices; they scan your files and network traffic for known threats and can quarantine or delete infected files. ### #6: Regular Security Audits and Vulnerability Scans Conducting periodic security audits and vulnerability scans helps to identify and address potential weaknesses in your ecommerce platform and security measures. These assessments can uncover outdated software, misconfigurations, or other vulnerabilities that could be exploited by hackers. Regular audits ensure that your ecommerce business security posture remains strong and up-to-date, they serve as a baseline for all future security hardening. It’s important to have administrative safeguards in place to follow up on the recommended actions to ensure the issues found are fixed promptly. ### #7: Data Encryption Encrypting sensitive customer data, both at rest (stored on your servers) and in transit (transmitted over networks), protects it from unauthorized access in case of a data breach. Encryption scrambles the data, making it unreadable without the decryption key. This adds an extra layer of protection for your customer’s information, such as credit card details or personal information. ### #8: PCI-DSS Compliance If your ecommerce website accepts credit card payments, ensure compliance with the Payment Card Industry Data Security Standard (PCI DSS). This standard outlines a set of security requirements for handling cardholder data, including encryption, secure storage, and regular vulnerability assessments. PCI DSS compliance demonstrates your commitment to protecting customer payment information. ### #9: Intrusion Protection Systems (IPS) Intrusion detection and prevention systems (IDPS) monitor network traffic for suspicious activity and can automatically block potential threats. These systems analyze traffic patterns, identify anomalies, and take action to prevent unauthorized access or data exfiltration. An IPS can be a valuable tool for detecting and stopping cyberattacks no your online store in real-time. ### #10: Regular Backups Creating and storing secure backups of your e-commerce website and customer data is essential for recovering from disasters such as cyberattacks, hardware failures, or natural disasters. Backups should be performed regularly and stored in a secure off-site location. This ensures that you can restore your data and resume operations quickly in case of an unexpected event. ## Enhancing User Experience for Your Online Store – Adding Ease-of-Use For obvious reasons, ecommerce security is usually the number one priority when designing an e-commerce platform; however, defining the user experience is also key to creating security and adding ease-of-use to an online store. Optimizing the user experience on your e-commerce site is crucial for building customer trust and driving sales. Now let’s take another look and explore some best practices for creating a seamless and enjoyable shopping experience for customers in your online store: ### #1:Guiding Customers Through Your Site Implement clear and sensible navigation menus, breadcrumbs, and search functionality to help customers easily find the products they’re looking for. A well-organized ecommerce store site structure and logical categorization of products contribute to a positive user experience and reduces customer frustration. ### #2: Streamlined Checkout Process Simplify the checkout process by minimizing the number of steps and required information. Offer guest checkout options, provide clear shipping and return policies, and ensure that the payment process is secure and user-friendly. A seamless checkout experience reduces cart abandonment rates and encourages repeat purchases. ### #3: Mobile Optimization With the increasing use of smartphones for online shopping, it’s essential to optimize your e-commerce site for mobile devices. It’s essential to get on top of the approval processes for Apple and Android app stores. Ensure that your online store is responsive and adapts seamlessly to different screen sizes. A mobile-friendly experience enhances accessibility and caters to the growing number of on-the-go shoppers. ### #4: Clear Product Descriptions and Images Provide detailed and accurate product descriptions, along with high-quality images, to help customers make informed purchasing decisions. Transparency about product features, dimensions, and materials builds trust and reduces the likelihood of returns or customer dissatisfaction. ### #5: Provide Customer Reviews and Ratings Encourage customers to leave reviews and ratings for products they’ve purchased. Positive reviews and testimonials provide evidence of customer satisfaction and can influence other shoppers’ purchasing decisions. Online stores that display customer feedback demonstrate transparency and build credibility. ### #6: Offer Live Chat Support Providing live chat support on your e-commerce site allows customers to get immediate answers to their questions or concerns. This real-time interaction fosters a sense of personalized service and can significantly improve customer satisfaction. If you don’t have the manpower, perhaps look at integrating virtual AI assistants to answer common customer questions. Live chat often helps ensure customers complete their purchase by addressing any last-minute hesitations or issues. ### #7: Fast and Reliable Web Hosting Choosing a fast and reliable web hosting provider is essential for ensuring that your e-commerce site is always accessible and performs optimally. Slow loading times or frequent downtime can frustrate customers and lead to lost sales, not to mention harm your SEO performance and ranking! Look for a hosting provider that offers high uptime guarantees, robust security features, and scalable resources to accommodate traffic spikes. ### #8: Transparent Pricing and Shipping Information Be upfront and transparent about your pricing, shipping costs, and any additional fees. Surprising customers with hidden charges at checkout can lead to lost custom and negative reviews. Clearly display all costs associated with a purchase and offer various shipping options to cater to different customer needs. ### #9: Easy Returns and Exchanges Having a clear and hassle-free return and exchange policy builds customer confidence and encourages purchases. Clearly communicate your return process and timeframe, and make it easy for customers to initiate a return or exchange if needed. A positive return experience can turn a potentially negative situation into an opportunity to demonstrate excellent customer service. ### #10: Personalized Recommendations Utilize customer data and browsing behavior to provide personalized product recommendations. This can be achieved through algorithms that analyze purchase history, search queries, and other relevant factors. Personalized recommendations enhance and streamline the shopping experience by showcasing products that are most likely to resonate with individual customers. ### #11: Secure Payment Gateway Partnering with a reputable and secure payment gateway is critical for protecting sensitive customer payment information. Ensure that your payment gateway is PCI DSS compliant and employs robust encryption and fraud prevention measures. Displaying trust seals and security badges on your checkout page can further instill confidence in customers. ### #12: Post-Purchase Engagement Continue engaging with your customers even after they’ve made their purchase. Send order confirmation emails, provide tracking information, and solicit feedback on their shopping experience. Consider offering loyalty programs or exclusive discounts to encourage repeat business and foster long-term customer relationships. ## Atlantic.Net: Your Ecommerce Security Hosting Partner One of the quickest and most reliable ways to get ahead in ecommerce security is to partner with a proven hosting service provider like Atlantic.Net. Our security-defined hosting solutions harden your ecommerce platforms and protect customer information. Our VPS solutions provide industry-leading ecommerce security measures to protect your critical systems. Our managed services add additional layers of protection, such as a managed SQL database. encrypted connection to your platform, intrusion detection systems, plus robust security measures like managed backup, server management, and DDoS protection to protect customer data. Handled payment data? No problem, we offer PCI-DSS ready managed hosting too. [Contact the team today](https://www.atlantic.net/about-us/corporate-contact/) and discover how Atlantic.Net can protect your ecommerce company from successful cyber attacks. --- # The 4 Levels of PCI Compliance: What You Need to Comply > URL: https://www.atlantic.net/pci-compliant-hosting/the-4-levels-of-pci-compliance-what-you-need-to-comply/ | Published: 2024-09-25 | Updated: 2024-12-05 | Author: Gilad Maayan ## What Are PCI Compliance Levels? PCI (Payment Card Industry) compliance levels categorize merchants based on their volume of credit card transactions per year. The PCI Security Standards Council establishes these criteria to prevent fraud. Depending on the number of transactions, companies must adhere to different security measures. This classification ensures that merchants implement necessary safeguards commensurate with the risks involved in processing transactions. This is part of a series of articles about [PCI compliant hosting](https://www.atlantic.net/pci-compliant-hosting/). ## The 4 PCI Compliance Levels in Detail ### PCI Level 1 Compliance: Global Retailers and Enterprises Level 1 PCI compliance is mandatory for large enterprises processing over 6 million credit card transactions annually. These organizations face significant risks due to their transaction volumes, requiring stringent security measures. To achieve Level 1 compliance, businesses must conduct an annual on-site assessment by a Qualified Security Assessor (QSA). They must also perform a network scan by an Approved Scanning Vendor (ASV) each quarter. This compliance level focuses on thorough protection against data breaches. Companies at this level typically have complex infrastructure, necessitating detailed security controls. This includes encryption, secure processing environments, and security policies. Continuous monitoring and regular assessments ensure these practices are maintained, reducing the risk of data loss. ### PCI Level 2 Compliance: Regional and Mid-Sized Enterprises PCI Level 2 compliance targets businesses processing between 1 and 6 million transactions annually. While the transaction volume is lower than Level 1, these entities still face considerable risks. Companies must complete a Self-Assessment Questionnaire (SAQ) annually and conduct quarterly network scans. This helps them identify and mitigate potential vulnerabilities in their systems. Similar to Level 1, compliance involves maintaining stringent security protocols, although the audit process might be less intensive. Focus areas include maintaining a secure network and implementing access control measures. By fulfilling these requirements, mid-sized enterprises can significantly reduce the risk of data breaches. ### PCI Level 3 Compliance: Medium-Sized Businesses Level 3 compliance is suited for businesses processing 20,000 to 1 million transactions annually, typically involving e-commerce operations but also relevant to any business handling that number of transactions online. These enterprises must complete an annual Self-Assessment Questionnaire (SAQ) and conduct quarterly network scans to identify vulnerabilities. Such measures help safeguard sensitive cardholder information within their payment systems and reduce exposure to cyber threats. Network security and secure transaction processing are core components under Level 3 requirements. By adhering to [PCI DSS requirements](https://www.atlantic.net/pci-compliant-hosting/pci-dss-cybersecurity-requirements-a-practical-guide/), businesses can prevent unauthorized access and data disclosure. ### PCI Level 4 Compliance: Small and Local Businesses PCI Level 4 compliance is for businesses processing fewer than 20,000 transactions annually. This level addresses the unique security needs of small and local businesses. Although the transaction volume is lower, these entities must still take steps to ensure data security. Completing annual Self-Assessment Questionnaires (SAQs) and undertaking quarterly scans are crucial components in this process. While the requirements may not be as stringent, maintaining compliance is essential for protecting customer data from vulnerabilities. Level 4 businesses must implement basic security measures such as firewall configurations and secure access controls. ## PCI DSS Levels for Service Providers Service providers play a critical role in the payment processing ecosystem, and their compliance is just as important. PCI DSS levels for service providers are defined differently from merchant levels. ### Level 1 Service Provider Level 1 service providers process over 300,000 card transactions annually. These providers must undergo an annual on-site audit by a Qualified Security Assessor (QSA). Additionally, they are required to conduct network scans by an Approved Scanning Vendor (ASV) quarterly. This rigorous process ensures that all systems are properly secured and vulnerabilities are addressed immediately. ### Level 2 Service Provider Level 2 service providers handle less than 300,000 transactions annually. They are required to perform an annual Self-Assessment Questionnaire (SAQ) to evaluate their security practices. Additionally, quarterly network scans are critical components in the compliance process. ## PCI Evaluations by Compliance Level The following table explains the different evaluations required for PCI Compliance and which evaluations are relevant for each compliance level. | **Evaluation** | **Description** | **Merchant L1** | **Merchant L2** | **Merchant L3** | **Merchant L4** | **SP L1** | **SP L2** | | --- | --- | --- | --- | --- | --- | --- | --- | | **QSA (Qualified Security Assessor)** | An independent external audit conducted by a PCI-approved security assessor to ensure compliance with PCI DSS standards. | v | | | | v | | | **ASV (Approved Scanning Vendor)** | A vulnerability scan performed quarterly by a PCI-approved vendor to identify potential weaknesses in the network infrastructure. | v | v | v | | v | v | | **SAQ (Self-Assessment Questionnaire)** | A self-assessment that merchants and service providers complete annually to evaluate their security controls and adherence to PCI DSS requirements. | | v | v | | | v |   ## How to Determine Your PCI DSS Compliance Level Determining your PCI DSS compliance level involves assessing the volume of payment card transactions your organization processes annually. The process typically includes the following steps: 1. **Calculate annual transaction volume**: Start by calculating the total number of credit card transactions your business processes in a year. This includes all transactions, whether they are online, in-store, or through any other sales channel. 2. **Identify merchant or service provider status**: Determine whether your business is classified as a merchant or a service provider. Merchants are entities that accept payment cards as a form of payment, while service providers manage transactions on behalf of merchants or other service providers. 3. **Match transaction volume to PCI compliance level**: Compare your annual transaction volume to the thresholds set by the PCI Security Standards Council: - **Level 1**: More than 6 million transactions annually. - **Level 2**: Between 1 and 6 million transactions annually. - **Level 3**: Between 20,000 and 1 million e-commerce transactions annually. - **Level 4**: Fewer than 20,000 e-commerce transactions or up to 1 million transactions across other channels annually. 4. **Review compliance requirements**: Once your compliance level is determined, review the specific PCI DSS requirements for that level. This will include understanding the required documentation, security controls, and assessment procedures such as whether you need an on-site audit or a Self-Assessment Questionnaire (SAQ). 5. **Regularly reevaluate**: Transaction volumes can change, especially as your business grows. It’s important to regularly reevaluate your PCI compliance level and adjust your security practices accordingly to stay compliant. ### **PCI Hosting Services and Solutions by Atlantic.Net** PCI Hosting by Atlantic.Net™ is SOC 2 and SOC 3 certified, designed to secure and protect critical health data, audited by a qualified and an independent third-party CPA firm. If your company requires PCI-DSS compliance (Payment Card Industry Data Security Standard), Atlantic.Net’s managed security and compliance hosting services coupled with our Cloud Platform and Dedicated Hosting will provide you the easy button to help achieve and exceed your credit card industry PCI compliance requirements! With our expanded network capacity and hardened data centers, your business will be able to achieve the uptime and cyber-security requirements for PCI compliance. You can meet your customers’ needs and accept online payments while maintaining PCI compliance and reducing your overall cost. Gain the competitive advantage you need with ease with our PCI-Compliant Hosting, backed by a 100% SLA. [**Learn more about Atlantic.net PCI-compliant web hosting**](https://www.atlantic.net/pci-compliant-hosting/) --- # VPS Hosting vs. Shared Hosting: Pros/Cons, Differences, and Expert Tips > URL: https://www.atlantic.net/vps-hosting/vps-hosting-vs-shared-hosting-pros-cons-differences-and-expert-tips/ | Published: 2024-09-26 | Updated: 2024-12-05 | Author: Gilad Maayan ## What Is VPS Hosting? VPS (virtual private server) hosting offers a virtualized server environment, providing users with dedicated resources on a shared physical server. This setup balances the cost benefits of shared hosting while offering more control, similar to a dedicated server. VPS hosting uses hypervisor technology to create and manage multiple virtual servers on a single physical machine, allowing users to enjoy isolated server environments without the high price of a dedicated server. VPS hosting provides better performance, security, and control compared to shared hosting. Each VPS operates independently, meaning server resources like CPU and RAM are not shared with other users. This reduces the risk of resource contention and improves performance consistency. Additionally, since the server environment is isolated, users can install and manage software, apps, and configurations according to their needs. ### Pros of VPS Hosting - **Dedicated resources**: Each VPS has allocated CPU, RAM, and storage, providing better performance without interference from other users on the server. - **Customization**: Users have root access, allowing for custom software installations and server configurations to meet their requirements. - **Scalability**: VPS hosting is easily scalable, enabling users to increase resources like CPU and storage without significant downtime. - **Enhanced security**: With isolated environments, VPS hosting offers improved security compared to shared hosting, reducing risks from neighboring websites. ### Cons of VPS Hosting - **Higher cost**: VPS hosting is more expensive than shared hosting due to dedicated resources and increased control options. - **Technical expertise needed**: Managing a VPS requires a higher level of technical knowledge, particularly when it comes to server configuration and security. - **Limited physical resources**: While resources are dedicated, they are still limited by the underlying hardware of the physical server, unlike a fully dedicated server. - **Potential overhead**: If not properly managed, VPS resources can be inefficiently used, leading to performance degradation or the need for frequent upgrades. ## What Is Shared Hosting? Shared hosting involves multiple websites being hosted on a single physical server, sharing resources such as CPU, RAM, and storage. It is the most economical hosting type, making it a popular choice for small businesses and personal websites. The primary advantage of shared hosting is its cost-effectiveness, as the fees are distributed among many users who share the same server infrastructure. Hosting providers manage server maintenance and provide technical support. While shared hosting offers affordability, it comes with resource constraints. Websites on a shared server may experience slower performance during peak times because other sites consume the shared resources. Security is another consideration, as vulnerabilities in one website could potentially affect others on the same server. Additionally, users have limited control over server settings, which may restrict customization. ### Pros of Shared Hosting - **Cost-effective**: Shared hosting is the most affordable option, suitable for small websites and those with limited budgets. - **Managed service**: Server maintenance and security are handled by the hosting provider, making it easy for non-technical users. - **Easy setup**: Hosting providers often offer one-click installations for popular platforms like WordPress, simplifying website setup. - **Low maintenance**: Since the hosting provider manages the server, users can focus on their website without worrying about technical aspects. ### Cons of Shared Hosting - **Limited resources**: Shared resources can lead to performance bottlenecks, especially if neighboring websites experience high traffic. - **Security risks**: Vulnerabilities in one site can potentially expose other sites on the same server to security threats. - **Restricted control**: Users have limited access to server configurations, which may restrict advanced customizations or software installations. - **Scalability issues**: Shared hosting doesn’t easily scale, making it unsuitable for websites experiencing significant growth in traffic or resource needs. ## Shared Hosting vs VPS Hosting: Key Differences The following table summarizes the key differences between shared and VPS hosting. | **Feature** | **Shared Hosting** | **VPS Hosting** | | --- | --- | --- | | **Cost** | Low, with costs shared among multiple users | Higher, with dedicated resources and flexible pricing | | **Performance** | Can suffer due to resource sharing with other websites | Consistent performance with dedicated CPU, RAM, and storage | | **Security** | More vulnerable due to shared environment | Better security with isolated environments and customizable settings | | **Reliability** | Risk of downtime if other sites consume excessive resources | High reliability due to isolated operations and dedicated resources | | **Scalability** | Limited, requires upgrading to higher plans or VPS | Easily scalable by adjusting CPU, RAM, and storage as needed | | **Control & customization** | Limited, with managed server settings and little customization | Full control with root access, allowing custom software and configurations | | **Ideal for** | Small websites, blogs, and startups with tight budgets | Growing businesses, high-traffic websites, and resource-intensive applications |   ## 1. Cost Shared hosting is typically more affordable than VPS hosting. In shared hosting, server costs are distributed among many users, resulting in low prices. This makes it an excellent choice for small websites or startups with tight budgets, as the cost is generally fixed and predictable. VPS hosting involves dedicated resources and better performance, reflected in higher pricing. With VPS, costs vary based on the level of resources allocated and may include additional fees for extra features or management services. While generally more expensive, VPS hosting may provide value for money through better performance and control, catering to businesses needing more than basic hosting. The increased cost offers tangible benefits like dedicated resources, enhanced security, and more configuration options. | **Expert tip:** Consider starting with shared hosting and upgrading to VPS as your traffic grows. Many hosting providers make it easy to migrate between plans. | | --- |   ## 2. Performance Performance is a significant differentiator between shared and VPS hosting. Shared hosting’s resource pooling means that if one site experiences high traffic, others can suffer performance issues. This unpredictability can affect load times, user experience, and SEO rankings. VPS hosting provides dedicated resources, ensuring consistent performance regardless of other users. This makes VPS ideal for websites that require reliable speed and handling of higher traffic volumes or resource-intensive applications. In VPS hosting, resilience and better resource allocation typically translate into faster load times and a smoother user experience. Websites with high visitor numbers or dynamic content benefit from the enhanced processing power and memory availability that VPS offers. Data-intensive applications such as eCommerce sites and interactive platforms often require the increased CPU and RAM that VPS provides to maintain optimal functionality. | **Expert tip:** For improved performance, regularly monitor your VPS resource usage and adjust allocations to ensure your website or application runs optimally without lag. | | --- |   ## 3. Security Shared hosting is generally more vulnerable and presents greater security risks due to resource sharing. A breach in one site could potentially expose others on the same server to risks. Shared servers often have stricter security settings, meaning users have less control over individual security configurations. Despite managed server security protocols by the provider, shared hosting environments can still be at a disadvantage when compared to VPS. VPS hosting offers better security due to isolated environments. Each VPS functions independently, akin to a dedicated server, ensuring that the activities of one do not compromise others. Users can configure security settings and install specific security tools, providing better data protection. However, VPS hosting does not offer a physically separated environment, so it can still be vulnerable to attacks against the virtualized environment, such as hypervisor compromise. | **Expert tip:** Always enable a firewall and keep software up to date on both shared and VPS hosting to minimize the risk of security breaches. | | --- |   ## 4. Reliability and Stability Shared hosting’s reliance on a common pool of resources can negatively impact reliability. If one site consumes excessive resources, others on the server may face downtime or reduced performance. However, most shared hosting plans offer adequate reliability for small sites, as providers manage the infrastructure to balance loads and ensure basic stability. Still, the risk of resource contention and potential downtime remains higher compared to VPS solutions. VPS hosting enhances reliability and stability through dedicated resources and independent operations. Each VPS maintains consistent performance irrespective of other virtual servers on the same physical machine. Such isolation provides greater uptime and resilience against spikes in traffic, ensuring consistent user experiences. The dedicated resource allocation in VPS minimizes the risk of downtime due to server overload. | **Expert tip:** Opt for managed VPS hosting if you want enhanced reliability and stability without the responsibility of manually maintaining the server infrastructure. | | --- |   ## 5. Scalability Scalability in shared hosting is limited. As businesses or websites grow, exceeding the shared resources’ capabilities requires upgrading to higher plans or relocating to VPS or dedicated servers. This limitation poses a challenge for rapidly growing websites that need flexibility in resource expansion. Shared hosting suits small sites with stable traffic but lacks the scalable infrastructure for businesses anticipating significant growth. VPS hosting provides a scalable solution, allowing users to adjust resources like CPU, RAM, and storage as needed. This flexibility accommodates website growth without needing downtime or data migration. Users can seamlessly scale their resources to match demands, making VPS an attractive choice for growing businesses or those with variable traffic levels. | **Expert tip:** VPS hosting can be scaled in real-time, so set automated alerts to notify you when resources like RAM or CPU approach their limits. | | --- |   ## 6. Control and Customization Shared hosting offers limited control due to its managed nature. Hosting providers control server configurations, limiting users to what is necessary for basic site functionality. While this provides ease of use for beginners and non-technical users, it restricts customization opportunities, posing challenges for businesses with specific needs or requiring unique software installations. Users are generally confined to pre-established settings and available applications as determined by the hosting provider. VPS hosting affords users greater control and customization over their server environment. With root access, users can configure settings, choose operating systems, and install custom software, tailoring the server to specific needs. This level of control supports websites or applications with unique requirements, allowing tailored optimizations and fine-tuning. VPS hosting is suited for developers, businesses requiring particular tech stacks, or those wishing to exert more influence over their hosting conditions. | **Expert tip:** Use VPS hosting to test and implement custom server configurations or software, which is often impossible on shared hosting plans. | | --- |   ## How to Choose Between VPS and Shared Hosting When choosing between VPS and shared hosting, understanding the specific needs of your website or application is crucial. Each hosting type offers distinct advantages and limitations, making them suitable for different scenarios. Below are key considerations to help guide your decision: **Resource allocation transparency** - In shared hosting, resource allocation is typically opaque, making it difficult to understand exactly how much CPU, RAM, or bandwidth is available to your site at any given time. - VPS hosting offers clear resource allocation, allowing you to monitor and manage exactly how much of each resource your site uses. **Backup and recovery options** - Shared hosting often comes with basic backup solutions provided by the hosting company, but these may have limitations in frequency and accessibility. - VPS hosting usually offers more robust backup options, including the ability to create your own backup schedules and configurations. **Compliance and regulatory requirements** - For websites subject to specific industry regulations (e.g., GDPR, HIPAA), shared hosting might not provide the necessary environment to meet strict compliance standards. - VPS hosting can be configured to meet strict compliance requirements, offering the isolation and customization needed to implement specific security measures and data controls. **Development and testing environments** - Shared hosting is less suited for creating staging or testing environments, as it typically lacks the flexibility to support multiple isolated environments on a single plan. - VPS hosting allows you to set up multiple environments (e.g., production, staging, testing) on the same server, making it a preferred choice for developers and teams. **Support for legacy software** - Shared hosting environments often have restrictions on the types of software and versions you can run, making it challenging to support older, legacy applications. - VPS hosting provides the freedom to run legacy software or specific configurations that may not be supported by shared hosting. **Cross-platform compatibility** - Shared hosting environments are generally standardized, which can limit your ability to use specific operating systems or frameworks. - VPS hosting allows you to choose and configure your operating system and software stack, ensuring compatibility with a wider range of platforms and technologies. ### **VPS Hosting in the Cloud with Atlantic.net** VPS Hosting from Atlantic.Net gives you the freedom to create and deploy one or many virtual servers in seconds. By combining the most advanced VPS hosting innovations and resources available, the Atlantic.Net Cloud offers simplicity, security, scalability, and reliability that will not only improve your virtual private server performance but also reduce your costs. With Atlantic.Net, you get the full suite of Cloud VPS hosting services: compute, redundant storage platforms, One-Click Apps, DNS, private networking, Onsite Backups, Offsite Backups, Secure Block Storage, and more, all backed by 24×7 support and a full range of managed services your business needs to succeed. [Learn more about Atlantic.net VPS Hosting](https://www.atlantic.net/vps-hosting/) --- # Fixing Mount Point Does Not Exist Error in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/fixing-mount-point-does-not-exist-error-in-linux/ | Published: 2024-09-27 | Updated: 2024-10-03 | Author: Hitesh Jethva In Linux, mounting devices or filesystems allow users to access external drives, network filesystems, and partitions. However, one common error encountered during this process is the “Mount Point Does Not Exist” error. This guide will help you understand the causes of this error and provide clear steps to resolve it. ## What Is a Mount Point in Linux? A mount point is a directory in the Linux filesystem where an external device or partition is attached. Once a device is mounted, its contents become accessible via this directory. Common mount points include **/mnt, /media,** and user-created directories like **/mnt/my_mount_point.** ## Understanding the “Mount Point Does Not Exist” Error The **“Mount Point Does Not Exist”** error means the directory where you are trying to mount your filesystem does not exist. This usually happens when you specify a path that is either misspelled or has not been created. For example, running a command like: ```bash mount /dev/sda1 /mnt/nonexistent_directory ``` You will see the following error: ```bash mount: /mnt/nonexistent_directory: mount point does not exist. ``` This error indicates that the directory **/mnt/nonexistent_directory** doesn’t exist, so the system can’t attach the partition to it. Let’s explore how to fix this issue step-by-step. ## How to Check If a Mount Point Exists First, check if the directory (mount point) exists. You can do this with the ls or find commands: **Check using ls command.** ```bash ls /mnt/my_mount_point ``` You will see the following output if the directory doesn’t exist. ```bash ls: cannot access '/mnt/my_mount_point': No such file or directory ``` **Check using find command.** ```bash find /mnt -type d -name "my_mount_point" ``` You can not see any output if the directory is not found. If the directory doesn’t exist, you’ll need to create it. ## Creating a Mount Point Directory To fix this error, you need to create the mount point using the **mkdir** command. Let’s assume we want to create the directory **/mnt/my_mount_point.** Create a new mount point directory. ```bash mkdir /mnt/my_mount_point ``` Verify the directory was created: ```bash ls /mnt ``` Output: ```bash my_mount_point ``` Now that the mount point exists, we can move forward with mounting the filesystem. ## Mounting the Filesystem to the New Mount Point Once the mount point is created, you can proceed with mounting the filesystem or device. Let’s look at a few different examples of mounting filesystems: **Mount a local partition.** ```bash mount /dev/sda1 /mnt/my_mount_point ``` **Mount an external USB drive.** ```bash mount /dev/sdb1 /mnt/my_mount_point ``` **Mount a network filesystem (NFS).** ```bash mount -t nfs server-ip:/path /mnt/my_mount_point ``` **Verify the filesystem is mounted.** ```bash df -h | grep my_mount_point ``` Output: ```bash /dev/sda1 50G 20G 30G 40% /mnt/my_mount_point ``` ## Making Mount Points Persistent Across Reboots By default, when you mount a device or filesystem using the mount command, it will be unmounted after a system reboot. To make the mount point persistent, you must add it to the **/etc/fstab** file. 1. Edit the /etc/fstab file: ```bash nano /etc/fstab ``` 2. Add an entry for the device: ```bash /dev/sda1 /mnt/my_mount_point ext4 defaults 0 0 ``` 3. Save and exit. 4. Test the /etc/fstab entry: Run the following command to verify that the fstab entry is correct and the filesystem can be mounted automatically: ```bash mount -a ``` If no errors are returned, the entry is correct, and the device will be mounted automatically after each reboot. ## Checking for Mount Point and Filesystem Issues If you’re still encountering issues with mounting, you can use **dmesg** or **journalctl** to check for system logs related to the mounting process: Using dmesg to check system messages: ```bash dmesg | grep mount ``` Using journalctl for recent logs: ```bash journalctl -xe | grep mount ``` If the issue is related to the filesystem (e.g., corrupted files), you can run the fsck (filesystem check) utility to repair the device: ```bash fsck /dev/sda1 ``` Follow the on-screen prompts to repair any issues with the filesystem. ## Conclusion The “Mount Point Does Not Exist” error in Linux can be frustrating, but it’s usually straightforward to fix. By creating the mount point directory, checking for typos, and verifying device connectivity, you can resolve the error and successfully mount your device. Hopefully the above methods will now help you fix the mount error if you encounter it on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # ps -ef Command with Practical Examples > URL: https://www.atlantic.net/dedicated-server-hosting/ps-ef-command-with-practical-examples/ | Published: 2024-09-28 | Updated: 2024-10-03 | Author: Hitesh Jethva The **ps** command is a crucial tool in Linux for monitoring running processes. It displays information about the processes running on your system, helping you manage system resources, identify issues, and kill unnecessary processes. One of the most commonly used variations of this command is **ps -ef**. In this article, we will explore how the **ps -ef** command works and how to use it effectively, using practical examples. ## Understanding the -e and -f Options The **-e** option tells **ps** to display all processes running on the system, not just those associated with the current terminal. The **-f** option stands for full-format listing, which includes additional details about each process. To get a comprehensive view of all the processes on your system, you can use the **ps -ef** command: ```bash ps -ef ``` Output: ```bash UID PID PPID C STIME TTY TIME CMD root 1 0 0 09:22 ? 00:00:02 /sbin/init root 719 1 0 09:22 ? 00:00:00 /usr/lib/systemd/systemd-journald root 1369 1 0 09:22 ? 00:00:00 /usr/sbin/sshd -D user 1421 1369 0 09:22 ? 00:00:00 sshd: user [priv] user 1422 1421 0 09:22 pts/0 00:00:00 -bash user 1567 1422 0 09:22 pts/0 00:00:00 ps -ef ``` This command shows all running processes, regardless of the terminal. Each column in the output provides essential information about the processes. Here’s what each column in the **ps -ef** output means: - **UID:** The user ID of the process owner. - **PID:** The Process ID of the running process. - **PPID:** The Parent Process ID, which refers to the process that spawned this one. - **C:** CPU utilization of the process. - **STIME:** Start time of the process. - **TTY:** The terminal associated with the process. - **TIME:** Total CPU time used by the process. - **CMD:** The command that started the process. ## Filtering Processes with ps -ef You can filter specific processes using the **grep** command with **ps -ef.** For example, if you want to see all processes related to Apache, you can run: ```bash ps -ef | grep apache ``` Output: ```bash root 1350 1 0 09:25 ? 00:00:00 /usr/sbin/apache2 -k start www-data 1352 1350 0 09:25 ? 00:00:00 /usr/sbin/apache2 -k start www-data 1353 1350 0 09:25 ? 00:00:00 /usr/sbin/apache2 -k start user 1365 1422 0 09:26 pts/0 00:00:00 grep --color=auto apache ``` This shows all Apache-related processes. The last line with **grep** is the actual command we used to search. ## Using ps -ef to Find Parent and Child Processes Every process in Linux is either a parent or a child process. The PPID (Parent Process ID) field helps you identify the parent process of a given child process. You can use the **ps -ef** command to check the parent-child relationship of processes. For better visualization, you can use the **ps -ef –forest** option, which displays a tree of processes: ```bash ps -ef --forest ``` Output: ```bash root 1 0 0 09:22 ? 00:00:02 /sbin/init ├─/usr/lib/systemd/systemd-journald ├─/usr/sbin/sshd -D │ └─sshd: user [priv] │ └─sshd: user [priv] │ └─/bin/bash └─ps -ef --forest ``` This tree structure helps you understand how processes are related, which is especially useful when debugging. ## Sorting the ps -ef Output You can sort the output of **ps -ef** based on different criteria, such as CPU usage, memory usage, or PID. For example, to sort processes by CPU usage in descending order, use: ```bash ps -ef --sort=-pcpu ``` Output: ```bash UID PID PPID C STIME TTY TIME CMD user 1367 1369 2 09:25 pts/0 00:00:02 firefox user 1345 1341 1 09:22 pts/0 00:00:01 gnome-shell user 1567 1422 0 09:22 pts/0 00:00:00 ps -ef --sort=-pcpu ``` This example sorts processes by their CPU usage (represented by the C column). ## Listing Processes for a Specific User To list all processes running under a specific user, you can combine **ps -ef** with **grep.** For example, to list all processes run by the current user: ```bash ps -ef | grep $USER ``` Output: ```bash user 1422 1421 0 09:22 pts/0 00:00:00 -bash user 1367 1369 2 09:25 pts/0 00:00:02 firefox user 1567 1422 0 09:22 pts/0 00:00:00 ``` This shows only the processes owned by the logged-in user. ## Killing a Process with ps -ef and kill When you identify a process that needs to be stopped, you can use its PID from the **ps -ef** output and terminate it with the **kill** command. For example, to kill a process with PID 1350: ```bash kill 1350 ``` To ensure the process is terminated, you can recheck by running ps -ef again. ## Using ps -ef to Monitor System Performance ps -ef can also be used for performance monitoring by identifying high CPU or memory-consuming processes. For example, to list processes consuming the most memory, use: ```bash ps -ef --sort=-pmem ``` Output: ```bash UID PID PPID C STIME TTY TIME CMD user 1367 1369 1 09:25 pts/0 00:01:05 firefox root 1001 1 0 09:20 ? 00:00:50 apache2 user 1345 1341 0 09:22 pts/0 00:00:30 gnome-shell ``` This output helps you identify memory-heavy processes so you can take action if needed. ## Conclusion The ps -ef command is a powerful tool for process management in Linux. It allows you to easily view, filter, and manage running processes. Whether you’re troubleshooting system performance, monitoring resource usage, or managing applications, ps -ef is an essential command to know. You can now use ps -ef command to manage processes on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Use Read Command to Get User Inputs Into an Array in Bash > URL: https://www.atlantic.net/dedicated-server-hosting/use-read-command-to-get-user-inputs-into-an-array-in-bash/ | Published: 2024-09-29 | Updated: 2025-02-07 | Author: Hitesh Jethva In Bash scripting, handling user inputs is an essential task. Often, you need to gather multiple inputs and store them for further operations. Arrays are an efficient way to store such inputs. In this guide, we’ll explore how to use the read command to capture user inputs and store them in a Bash array. ## Introduction to Arrays in Bash In Bash, an array is a variable that holds multiple values. Unlike regular variables, which store a single value, arrays allow you to store and manage lists of items, making them incredibly useful for many applications. You can create a simple array like this: ```bash my_array=("item1" "item2" "item3") ``` To access elements of the array, use the following syntax: ```bash echo ${my_array[0]} # Outputs: item1 echo ${my_array[1]} # Outputs: item2 ``` You can also iterate over the array: ```bash for item in "${my_array[@]}"; do echo $item done ``` Output: ```bash item1 item2 item3 ``` ## Overview of the read Command The read command in Bash is used to take user input. By default, it reads a single value into a variable. Here’s a simple example of using read to capture input: ```bash echo "Enter your name:" read name echo "Hello, $name!" ``` Output: ```bash Enter your name: John Hello, John! ``` The read command can also be used to read multiple values into an array by using the **-a** option, which we’ll explore next. ## Using read -a to Capture User Inputs Into an Array To read multiple inputs and store them into an array, we use the read command with the **-a** flag. This flag tells Bash to store the input into an array instead of a single variable. Here’s an example: ```bash echo "Enter a list of items (separated by spaces):" read -a items echo "You entered: ${items[@]}" ``` Output: ```bash Enter a list of items (separated by spaces): apple banana orange You entered: apple banana orange ``` The user’s input (apple banana orange) is stored in the items array, and we print the array using **${items[@]}.** ## Prompting the User for Multiple Inputs You can prompt users to enter multiple values on a single line. Here’s how you can capture that input and store it in an array: ```bash echo "Enter your favorite colors (separated by spaces):" read -a colors echo "Your favorite colors are:" # Loop through the array and print each color for color in "${colors[@]}"; do echo $color done ``` Output: ```bash Enter your favorite colors (separated by spaces): red blue green Your favorite colors are: red blue green ``` In this example, red, blue, and green are stored in the colors array, and we print each color using a loop. ## Reading Multiple Inputs (Line by Line) Into an Array Sometimes, you may want to collect inputs line by line and store them in an array. This can be done using a while loop. ```bash echo "Enter items one by one (leave blank to finish):" declare -a input_array while true; do read item [[ -z "$item" ]] && break input_array+=("$item") done echo "You entered: ${input_array[@]}" ``` Output: ```bash Enter items one by one (leave blank to finish): apple banana grape You entered: apple banana grape ``` This script reads user input one line simultaneously, appending each value to the **input_array.** The loop breaks when the user enters an empty line. ## Practical Example: Collecting a List of User-Defined Items Here’s a practical script example where the user can input items for a shopping list, and the script stores them in an array. ```bash echo "Enter items for your shopping list (leave blank to finish):" declare -a shopping_list while true; do read item [[ -z "$item" ]] && break shopping_list+=("$item") done echo "Your shopping list is:" for item in "${shopping_list[@]}"; do echo $item done ``` Output: ```bash Enter items for your shopping list (leave blank to finish): bread milk eggs Your shopping list is: bread milk eggs ``` This simple shopping list script collects user inputs line by line and displays them at the end. ## Error Handling and Edge Cases When reading inputs into arrays, there are a few potential issues: **1. Handling Whitespace:** Be mindful of values with spaces. To handle multi-word inputs, use quotes around the value like so: ```bash read -a input_array <<< "one two 'multi word input'" echo "${input_array[@]}" ``` Output: ```bash one two multi word input ``` **2. Validating User Inputs:** Always check for empty or invalid inputs before adding them to the array. **3. Escaping Special Characters:** If the user’s input contains special characters (like &, |, etc.), make sure to escape or handle them accordingly. ## Conclusion Using the read command in Bash is a powerful way to capture user input, and with the **-a** option, you can easily store multiple inputs into an array. Whether you need to collect input in a single line or line by line, this method provides flexibility in handling user data in Bash scripts. Experiment with arrays and user inputs to enhance your Bash scripts and make them more interactive and efficient on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # What Is IPv6 and Should I Enable It? > URL: https://www.atlantic.net/vps-hosting/what-you-should-know-before-enabling-ipv6/ | Published: 2024-10-01 | Updated: 2026-05-04 | Author: Richard Bailey Every single computer device connected to a network or the wider Internet uses an Internet Protocol version (IP) to communicate. For decades, IPv4 has served as the backbone of the Internet, but the rapid growth of the Internet has made its limitations increasingly apparent. IPv6 was chosen as the successor to IPv4 by the Internet Engineering Task Force (IETF), and it has been designed to address the challenges of the modern internet, a place where billions of devices connect and communicate each day. But what exactly is IPv6, and should you enable it on your home or corporate network? It’s quite surprising how long IPv6 technology has been around; believe it or not, its origins go back to 1992, with the draft standardization being agreed upon. Yet even today, IPv6 is not hugely popular when in reality we should all be using it. In this technical article, we will learn all about IPv6 and discover the difference between using IPv6 locally and across the Internet. We will also try and answer why the adoption of IPv6 has been so slow across the industry, and then discuss the strengths and weaknesses of IPv6. ## What Is IPv6? IPv6, or Internet Protocol version 6, is the most recent version of the Internet Protocol (IP). It serves as the foundation for communication on the internet by assigning unique IP addresses to devices, allowing them to send and receive data. The core distinction between IPv4 and IPv6 lies in the allocated address space. IPv4 uses 32-bit addresses, limiting the number of available unique addresses to roughly 4.3 billion. In contrast, IPv6 employs 128-bit addresses, offering an astronomical number of IP addresses. For context, the IPv6 address space works out at approximately 340 undecillion; that unfathomable number looks like this – 340,282,366,920,938,463,463,374,607,431,768,211,456 (according to [Pingdom](https://www.pingdom.com/blog/the-number-of-possible-ipv6-addresses-read-out-loud/)). Beyond its expanded address space, IPv6 introduces several other benefits: - **Eliminating Network Address Translation (NAT):** IPv4’s address limitations led to the widespread use of NAT, which allows multiple devices to share a single public IP address. IPv6 removes the need for NAT by providing ample IP addresses for every device. - **Enhanced Security:** IPv6 incorporates IPsec (IP Security) directly into the IP layer, offering built-in authentication and encryption. This strengthens data confidentiality, providing a more secure environment for online activities. - **Improved Efficiency:** The IPv6 header has been streamlined, leading to more efficient packet processing at routers and potentially saving network bandwidth. Such efficiency enhances the performance of bandwidth-intensive packet flows, such as those encountered in video streaming and large file transfers. ## **Important IPv6 Terminology** IPv6 is full of acronyms and new terminology you may not be familiar with. Take a few moments to consider these important terms. - **Internet Control Message Protocol (ICMPv6):** Used for error reporting, network diagnostics, and control messages in IPv6 networks. - **Path MTU Discovery (PMTUD):** A mechanism used to determine the path’s maximum transmission unit (MTU), the largest packet size that can be transmitted without fragmentation. - **Neighbor Discovery Protocol (NDP):** Replaces ARP in IPv4 and is used for address resolution, router discovery, and prefix discovery in IPv6 networks. - **Router Advertisement (RA):** Messages sent by routers to announce their presence and provide configuration information to hosts. - **Stateless Address Autoconfiguration (SLAAC):** Allows hosts to automatically configure their own IPv6 addresses based on information received from RAs. - **DHCPv6:** A protocol used for dynamic address allocation and other configuration parameters in IPv6 networks. ## What is the History of IPv6? The rapid expansion of the Internet in the early 1990s raised concerns about the limitations of the existing internet protocol, IPv4. Its 32-bit address space, while sufficient for the time, was projected to be exhausted as more devices connected to the internet. To address this looming issue, the Internet Engineering Task Force (IETF), an open standards organization responsible for developing and promoting internet standards, initiated the development of IPv6, a new internet protocol with a much larger 128-bit address space. The journey toward IPv6 adoption has been marked by several significant milestones: - **1995:** The first RFC outlining the basic concepts of IPv6 was published ([RFC 1883](https://www.rfc-editor.org/info/rfc1883)), laying the foundation for further development. - **1998:** The IETF finalized the core IPv6 specifications, solidifying the protocol’s technical framework and paving the way for implementation ([RFC 2460](https://www.rfc-editor.org/info/rfc2460)). - **2011:** World IPv6 Launch Day marked a coordinated global effort to promote and accelerate the transition to IPv6. Top websites and Internet service providers around the world, including [Google](https://googleblog.blogspot.com/2011/01/world-ipv6-day-firing-up-engines-on-new.html), [Facebook](https://www.facebook.com/notes/facebook-engineering/world-ipv6-day-solving-the-ip-address-chicken-and-egg-challenge/484445583919), and Akami joined together with more than 1000 other participating websites to trial IPv6. - **2017:** The [US government mandated](https://www.commerce.gov/about/policies/ipv6-policy) IPv6 support for all new federal IT systems, signaling a significant policy shift towards broader adoption. Despite these efforts, the [IPv4 to IPv6 transition](https://www.ipxo.com/blog/ipv6-adoption/) has been gradual. Compatibility issues with existing IPv4 infrastructure, the cost of upgrading network equipment, and a lack of immediate urgency for many users have contributed to the slow adoption rate. However, as the internet continues to grow and the demand for unique IP addresses increases, the full potential of IPv6 is only likely to be realized in years to come. ## Internet IPv6 and Public IP Address IPv6 can be implemented on both private internal networks and the public internet. In this section, we will discuss the different ways IPv6 can be implemented. Utilizing IPv6 on the internet means that your devices and internet service provider have a public IPv6 address, enabling direct communication with other IPv6-enabled devices and services across the globe. This opens up a wide range of benefits: - **More IP Addresses**: We have already discussed IPv6’s vastly expanded address space and how it eliminates concerns about running out of IP addresses. - **Enhanced Security**: IPv6’s integration of IPsec (IP Security) as an extension header establishes a foundation for strong data protection. It enables confidentiality through encryption, integrity verification to prevent data tampering, and authentication to confirm the identity of communicating parties, all at the network layer. - **More Efficient Routing**: IPv6’s simplified header structure and streamlined routing tables contribute to more efficient packet processing and forwarding, potentially leading to improved network performance. When compared to IPv4, IPv6 reduces the overhead associated with each packet, allowing routers to process them more quickly. - **End-to-End Connectivity**: With IPv6, devices can establish direct connections simplifying peer-to-peer applications and improving the overall user experience. - **No More NAT**: IPv6 eliminates the need for NAT, simplifying network configurations and allowing devices to have globally routable addresses. However, there are certain challenges associated with adopting IPv6 on the internet. We will go into this in more detail a little later, but it is important to mention some of the immediate problems with IPv6 over the Internet: - **Limited ISP Support**: Not all Internet Service Providers (ISPs) offer native IPv6 connectivity. Some might utilize tunneling or other transitional mechanisms, while others may discourage users from enabling it or even disable IPv6 by default. - **Compatibility**: Although most modern websites and services support IPv6, older legacy systems often still rely on IPv4, requiring transitional mechanisms to bridge the gap. If you work in a small, medium, or large organization – has your business enabled IPv6 yet? - **Configuration**: Enabling and configuring IPv6 on your devices requires a good technical knowledge of networking and that your provider or ISP supports it. The good news is that many devices can automatically configure their IPv6 addresses using mechanisms like SLAAC (Stateless Address Autoconfiguration) or DHCPv6. ## Local IPv6 IPv6 can also be implemented on private internal networks, such as within your home or office. This means that devices within your local network communicate using IPv6 addresses, providing local links with several advantages: - **Simplified Network Management**: With each device having a unique IPv6 address, network management becomes more straightforward. - **Enhanced Performance**: Applications that heavily utilize peer-to-peer communication or require multiple connections often experience performance gains with IPv6 due to the elimination of NAT and improved routing efficiency. - **Future-proofing**: As IPv6 adoption grows, having a local network already IPv6-enabled ensures seamless integration with the evolving internet landscape. - **Assign Multiple IP Addresses**: IPv6 allows you to assign multiple IPv6 addresses to the same device, enabling flexible network configurations and potential security benefits. Modern routers and operating systems generally include built-in IPv6 support, often requiring only simple configuration changes to the operating system to enable it. It’s important to understand the benefits and challenges of implementing IPv6 on the Internet and local networks. We will inevitably all need to transition to IPv6 in the future, and the transition may present some hurdles. ## What Is the Difference Between IPv4 and IPv6? Hopefully, by now you should have a good understanding of IPv6. If like me, you are more than familiar with IPV4, the transition to IPv6 may seem like a daunting task. In this section, we will highlight the key differences between IPv4 and IPv6. This table outlines the key distinctions between them, focusing on the technical attributes. | **Feature** | **IPv4** | **IPv6** | | --- | --- | --- | | **IP Addresses Size** | 32-bit (approximately 4.3 billion addresses) | 128-bit (vastly expanded address space, enough for every device on the planet to have its own public IP address) | | **Address Representation** | Dotted decimal notation (e.g., 192.168.1.1) | Hexadecimal notation (e.g., 2001:0db8:85a3:0000:0000:8a2e:0370:7334) | | **NAT (network address translation)** | Necessary due to limited address space | Eliminated, each device receives a unique IP address | | **Security** | IPsec is optional | IPsec is integrated into the IP layer, offering built-in authentication and encryption to enhance data integrity and confidentiality | | **Header Structure** | More complex, with 12 fields | Simplified, with 8 fields, contributing to more efficient packet processing | | **Multicast** | Less efficient | More efficient, with built-in support, enabling efficient communication with multiple destinations simultaneously | | **Adoption** | Widely adopted but nearing its limits | Increasing adoption, but the transition is ongoing | | **Other Features** | Requires manual address assignment and port forwarding for some services | Offers autoconfiguration capabilities (SLAAC, DHCPv6), flow label for QoS, and an extended unique identifier (EUI-64) for improved address assignment | IPv6 addresses the limitations of IPv4, primarily the scarcity of unique addresses. IPv6 also offers inherent security enhancements and improved support for multicast communication. While IPv4 remains dominant, the transition to IPv6 is essential for the continued growth and evolution of the internet. ## Weaknesses of IPv6 While IPv6 offers lots of benefits, it’s crucial to acknowledge its challenges and limitations. - **Transition Complexity:** The transition from IPv4 to IPv6 is a difficult task to complete, requiring careful planning and coordination. Compatibility issues often surface with older devices that do not support IPv6. Techniques like dual-stacking and tunneling can help with the transition, but it can also introduce unwanted networking complexity. - **Adoption Rate:** Although IPv6 adoption is increasing, it’s still not universally available. Some ISPs do not offer native IPv6 connectivity, and some websites and services still solely rely on IPv4. This problem leads to connectivity issues for users attempting to access IPv6-only resources. A slow adoption rate discourages users from fully embracing it. - **Security Concerns:** While IPv6 has built-in security features, it also introduces new attack vectors. For example, broadcast packets can be used for malicious purposes, and router advertisements can be spoofed. As a result, organizations need to be on-top of their security practices to address these new challenges. - **Configuration Challenges:** IPv6’s expanded address space and configuration options are more complex than IPv4. Manual configuration is time-consuming and error-prone. Proper address assignment and IP management is essential for a smooth IPv6 deployment, requiring technically advanced network engineers. However, cloud hosting providers like Atlantic.Net are actively promoting IPv6 adoption, offering our customer networks seamless IPv6 integration and support on the ACP platform. ## **IPv6 on Atlantic.Net** Atlantic.Net fully supports IPv6 on its platform, aligning with the industry’s move toward the next-generation internet protocol. We provide a range of features and configuration capabilities and benefits for customers seeking to leverage IPv6’s capabilities: ### Features: - **IPv6 Enablement:** Atlantic.Net allows users to enable IPv6 on their cloud servers, either during the initial server creation process or at a later time from the ACP console. - **Address Allocation:** Each cloud server with IPv6 enabled receives 16 IPv6 addresses for use. - **Network Configuration:** While Atlantic.Net automatically allocates IPv6 addresses, users are responsible for configuring their server’s network settings to utilize these addresses. - **Dual-Stack Support:** Atlantic.Net supports dual-stack configurations, allowing servers to operate with both IPv4 and IPv6 simultaneously, ensuring compatibility with both legacy and modern services. ### Benefits: - **Improved Performance:** IPv6’s efficiency gains can translate to faster and more responsive applications for our customers, particularly for services that rely on real-time data exchange. - **Future-Proofing:** By supporting IPv6, we ensure that our customers’ infrastructure is prepared for the future growth of the internet and the increasing number of connected devices. - **NAT Elimination:** With IPv6, our customers can bypass the need for NAT, simplifying network configurations and enabling direct end-to-end communication between devices. IPv6 represents the future of the Internet. By understanding the strengths and weaknesses of IPv6, as well as the key technologies and terminology involved, you can make informed decisions about how to best use this next-generation protocol in your network environment. Cloud providers like Atlantic.Net play a crucial role in facilitating this transition by providing the necessary tools, valuable services, and infrastructure to support IPv6 adoption. [Don’t get left behind](https://www.atlantic.net/about-us/corporate-contact/). Make the switch to IPv6 today! --- # How to Add a Directory to PATH in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-add-a-directory-to-path-in-linux/ | Published: 2024-10-02 | Updated: 2024-10-03 | Author: Hitesh Jethva In Linux, the PATH environment variable determines which directories the system searches for executable files. Adding a directory to the PATH allows you to run scripts or programs located in that directory without specifying the full path each time. This guide will show you how to temporarily and permanently add a directory to your PATH. ## What Is the PATH Environment Variable? The PATH environment variable is a colon-separated list of directories that the shell searches for executable files when you type a command. When you run a command in the terminal, the system checks these directories to see if the command exists there. You can view the current value of the PATH by running: ```bash echo $PATH ``` Output: ```bash /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/usr/local/games ``` In this example, directories like **/usr/bin** and **/usr/local/bin** are part of the **PATH.** Any executable placed in these directories can be run directly from the terminal without specifying its full path. ## Why Add a Directory to PATH? There are many practical scenarios where adding a directory to your PATH is helpful. For instance, you may have custom scripts stored in **/opt/my_program/bin.** Adding this directory to your PATH allows you to run those scripts from anywhere in the terminal without typing the full path. Suppose you have scripts or programs in **/opt/my_program/bin.** By adding this directory to your PATH, you can run: ```bash my_program_script ``` Instead of typing the full path like so: ```bash /opt/my_program/bin/my_program_script ``` ## Temporarily Add a Directory to PATH Use the export command to add a directory to the PATH for the current terminal session. This change will only last until the terminal is closed. 1. Use the export command to add the directory: ```bash export PATH=$PATH:/opt/my_program/bin ``` 2. Verify the directory has been added: ```bash echo $PATH ``` Output: ```bash /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/usr/local/games:/opt/my_program/bin ``` 3. You can now run any executable in /opt/my_program/bin without specifying the full path. For example: ```bash my_program_script ``` Note that this change is temporary and will reset once you close the terminal session. ## Permanently Add a Directory to PATH To permanently add a directory to the PATH, you must modify one of your shell’s configuration files. Common files include: - **.bashrc:** Runs for interactive non-login shells. - **.bash_profile:** Runs for login shells. - **.zshrc:** If you’re using the zsh shell. Let’s go through the steps to add a directory to the PATH permanently: 1. Open your shell configuration file. In this case, we’ll modify **.bashrc** for bash users. ```bash nano ~/.bashrc ``` 2. Add the following line at the end of the file: ```bash export PATH=$PATH:/opt/my_program/bin ``` 3. Save and exit the file. 4. Apply the changes by running: ```bash source ~/.bashrc ``` 5. Verify the changes by rechecking the PATH: ```bash echo $PATH ``` Now, the directory **/opt/my_program/bin** is permanently added to your PATH, and you can run scripts or executables in that directory from any terminal session. ## Conclusion Adding directories to your PATH in Linux makes it easier to run executables or scripts from any location in the terminal. Whether you’re adding a directory temporarily or permanently, it’s a simple yet powerful way to streamline your workflow. Now, you can run your custom programs or scripts without having to type out full paths every time. Try to add PATH to the [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # What Is HIPAA Compliance? History, Rules, and Requirements > URL: https://www.atlantic.net/hipaa-compliant-hosting/what-is-hipaa-compliance-history-rules-and-requirements/ | Published: 2024-10-03 | Updated: 2025-05-14 | Author: Gilad Maayan ## What Is HIPAA Compliance? HIPAA compliance refers to adherence to the Health Insurance Portability and Accountability Act, a U.S. regulation established to protect patient health information. It ensures that medical organizations and businesses manage patient data carefully, preventing unauthorized access while maintaining the confidentiality, integrity, and security of health information. HIPAA requires the U.S. healthcare industry to implement proper documentation, training, and security measures for data management. Compliance with HIPAA is not optional; it’s a legal requirement involving complex rules and guidelines. Organizations must conduct regular self-audits, staff training, and thorough risk management to prevent potential breaches and penalties. This framework impacts covered entities, including healthcare providers, insurers, and other related service providers. This is part of an extensive series of guides about [compliance management](https://www.exabeam.com/explainers/compliance-management/compliance-management-process-regulations-and-tools/). ## What Is ePHI? Electronic Protected Health Information (ePHI) refers to any Protected Health Information (PHI) that is created, stored, transmitted, or received in electronic form. ePHI includes sensitive patient data such as medical histories, diagnoses, treatment plans, and billing information that healthcare providers and their business associates handle in digital systems. The [HIPAA Security Rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/) governs the protection of ePHI, requiring organizations to implement administrative, physical, and technical safeguards to secure this data against unauthorized access and breaches. ## History of the HIPAA Regulation HIPAA was enacted in 1996 and has gone through several changes over the years. Here are the most significant milestones: - **1996**: HIPAA was signed into law by President Bill Clinton. The primary objective was to improve healthcare efficiency by encouraging the use of electronic data while safeguarding sensitive health information. - **2003**: The HIPAA Privacy Rule officially took effect, giving patients rights over their health information and setting strict guidelines for healthcare organizations regarding the use and disclosure of PHI. - **2005**: The HIPAA Security Rule came into effect. It targeted the protection of ePHI, mandating administrative, physical, and technical safeguards to secure digital patient data. - **2009**: The Health Information Technology for Economic and Clinical Health (HITECH) Act expanded HIPAA’s scope, introducing stricter breach notification requirements and higher penalties for non-compliance. - **2013**: The Omnibus Rule was introduced, amending HIPAA to address emerging technological challenges and expanding the accountability of business associates handling PHI. It also strengthened the rules around privacy and security compliance. - **2021**: The HIPAA Safe Harbor Law was signed into law, incentivizing organizations to adopt recognized security practices by reducing penalties for those demonstrating a strong security posture during audits or investigations following breaches. ## Who Must Comply with HIPAA? ### Covered Entities Covered entities are those directly involved in healthcare operations and include hospitals, clinics, insurance companies, and other related healthcare outfits. These entities handle large volumes of PHI and are responsible for implementing privacy and security safeguards in line with HIPAA regulations. Compliance requires consistent audits and evaluations to minimize risks associated with data breaches or unauthorized access, ensuring patient information remains protected. They must establish policies, conduct employee training, and adopt technological solutions to manage PHI effectively. Covered entities often face the challenge of balancing information accessibility and security—a critical aspect of achieving HIPAA compliance. ### Business Associates Business associates are involved in performing services for covered entities that involve access to PHI. Examples include IT providers, billing companies, and transcription services. Under HIPAA, these associates must ensure safeguards for PHI, indemnifying the covered entities against possible data breaches or security violations. They are required to sign Business Associate Agreements (BAAs) with covered entities, detailing compliance responsibilities. These agreements define the business associate’s duties, security obligations, and the permissible use and disclosure of PHI. Moreover, business associates should conduct self-audits and establish policies to manage PHI adeptly. ## HIPAA Rules and Regulations The HIPAA regulation includes the following main components: ### HIPAA Privacy Rule The HIPAA Privacy Rule focuses on the national standards for the protection of medical records and personal health information. Enforced in 2003, it mandates the confidentiality of patient information and gives patients rights over their health information, including rights to obtain a copy of their records and request corrections. The rule applies to all forms of PHI, whether electronic, paper, or oral. Covered entities must implement safeguards to protect PHI, limit its use and disclosure to the minimum necessary for health purposes, and ensure workforce members comply with these standards. Regular training and updated policies are crucial for maintaining adherence to this rule. ### HIPAA Security Rule The HIPAA Security Rule sets standards for securing electronic PHI (ePHI) through administrative, physical, and technical safeguards. Enacted in 2005, it requires covered entities to implement risk management processes to identify and mitigate vulnerabilities. The rule imposes requirements for data encryption, access controls, and audit controls to protect ePHI from cyber threats, ensuring its confidentiality, integrity, and availability. Organizations must conduct regular risk assessments, develop risk management policies, and ensure workforce training in security practices. ### HIPAA Breach Notification Rule The HIPAA Breach Notification Rule requires covered entities and business associates to notify patients and the U.S. Department of Health and Human Services (HHS) of any security breaches involving unsecured PHI. No later than 60 days after the breach discovery, organizations must inform affected individuals and provide detailed information about the incident, including potential impacts and steps for mitigation. Business associates must notify covered entities of breaches, enabling timely reporting and corrective actions. This rule establishes transparency and accountability, compelling organizations to take proactive security measures and maintain openness with patients about their data’s safety. ### HIPAA Transaction Rule The HIPAA Transaction Rule standardizes electronic transactions involving healthcare information, ensuring efficient and secure exchange of data between healthcare providers, insurers, and other entities. It mandates the use of uniform code sets, formats, and identifiers for electronic transactions like claims, enrollment, and payment processes. To comply, covered entities must implement systems that support these standardized transactions, ensuring consistent communication across the healthcare industry. This promotes interoperability and enhances the accuracy and security of sensitive patient data during electronic exchanges. ### HIPAA Enforcement Rule The HIPAA Enforcement Rule outlines the procedures for investigating and penalizing violations of HIPAA regulations. It grants the U.S. Department of Health and Human Services (HHS) the authority to investigate complaints, conduct compliance reviews, and impose civil monetary penalties on entities found to be non-compliant with HIPAA’s Privacy, Security, and Breach Notification Rules. Penalties under this rule are tiered based on the severity and intent of the violation, with fines ranging from $100 to $50,000 per violation. The Enforcement Rule serves as a strong incentive for organizations to prioritize HIPAA compliance and prevent potential breaches. ### HIPAA Identifiers Rule The HIPAA Identifiers Rule requires the use of unique identifiers to improve the efficiency and accuracy of electronic transactions. It introduced three main identifiers: the National Provider Identifier (NPI) for healthcare providers, the Employer Identification Number (EIN) for employers, and the Health Plan Identifier (HPID) for health plans. Covered entities must use these HIPAA-mandated identifiers when processing transactions, ensuring a consistent and organized method for identifying entities involved in healthcare operations. ### HIPAA Omnibus Rule The HIPAA Omnibus Rule, implemented in 2013, expanded the responsibilities of business associates and covered entities under HIPAA. It introduced modifications to the Privacy, Security, and Breach Notification Rules and enhanced patient rights concerning the use of their information for marketing and research. This rule also addressed provisions regarding the breach notification process and increased penalties for non-compliance. Under the Omnibus Rule, business associates are now directly liable for compliance with specific HIPAA requirements. It demands covered entities update business associate agreements to reflect enhanced responsibilities and ensures all parties involved in handling PHI understand their obligations. ## Recent HIPAA Updates Here are some of the latest updates to HIPAA that you should be aware of: - **FTC updates Health Breach Notification Rule (April 26, 2024):** The FTC expanded the scope of its Health Breach Notification Rule to cover health apps and other technologies that are not governed by HIPAA. This update addresses the collection, processing, and transmission of health information by entities outside of HIPAA’s jurisdiction, ensuring broader protection of sensitive health data. - **Biden-Harris administration’s new rule for reproductive health care privacy:** A new rule has been introduced to strengthen privacy protections specifically for reproductive health care. It safeguards the medical records and health information of women, their families, and healthcare providers involved in accessing or facilitating lawful reproductive care. - **OCR updates FAQs on Change Healthcare incident (April 19, 2024):** The Office for Civil Rights (OCR) released updated FAQs concerning the Change Healthcare cybersecurity breach. These FAQs clarify how HIPAA rules apply to the breach, which affected multiple healthcare entities, and offer guidance on managing cybersecurity incidents under HIPAA. ## What Are the Key HIPAA Compliance Requirements? ### Self-Audits Self-audits allow covered entities and business associates to regularly assess their security practices and identify any weaknesses in safeguarding Protected Health Information. These audits involve reviewing all aspects of HIPAA compliance, including physical, administrative, and technical safeguards, to ensure all areas meet regulatory standards. Conducting self-audits helps organizations detect potential vulnerabilities before they lead to breaches or violations. Organizations must maintain detailed records of these audits to demonstrate ongoing compliance efforts. **Requirements for self-audits:** - Conduct regular risk assessments - Review security policies and procedures - Assess the effectiveness of administrative, physical, and technical safeguards - Document audit results and identified vulnerabilities ### Remediation Plans A remediation plan is developed to address any vulnerabilities or gaps identified during self-audits or external audits. The plan outlines specific steps an organization must take to fix security deficiencies, including timelines, resources needed, and responsible parties. Proper implementation of remediation plans is crucial for avoiding potential breaches and penalties. The organization must closely monitor the progress of remediation efforts to ensure timely completion. It’s also essential to update the plan as new risks or challenges emerge, ensuring that all security measures remain current. **Requirements for remediation plans:** - Identify and prioritize security gaps - Develop a detailed corrective action plan - Assign responsibilities and timelines - Track progress and adjust as needed - Ensure timely completion of remediation efforts ### Policies and Procedures HIPAA requires organizations to establish comprehensive policies and procedures that align with its privacy and security rules. These documents outline how PHI is handled, stored, and protected within the organization. Additionally, all employees must undergo regular training to understand HIPAA regulations and their roles in maintaining compliance. Training should cover the organization’s policies and procedures, such as proper data handling practices and breach notification procedures. **Requirements for policies, procedures, and training:** - Develop HIPAA-compliant policies and procedures - Conduct regular employee training on HIPAA requirements - Update policies as needed - Ensure all staff understand their roles in maintaining compliance - Keep records of training sessions and participant attendance ### Business Associate Management Managing business associates is a key part of HIPAA compliance, as these entities often have access to PHI. Covered entities must establish Business Associate Agreements (BAAs) with all business associates, clearly outlining their responsibilities in protecting PHI and complying with HIPAA rules. These agreements ensure that business associates are held to the same security standards as the covered entity. Covered entities must also monitor business associates regularly to ensure they meet their obligations, conducting audits and enforcing compliance when necessary. **Requirements for managing business associates:** - Establish BAAs - Define responsibilities and compliance expectations - Conduct regular audits of business associates - Terminate agreements with non-compliant associates - Ensure business associates notify covered entities of any breaches ### Incident Management Incident management involves identifying, responding to, and resolving any security breaches or violations that compromise the integrity of PHI. Organizations must have a clear, structured process in place for reporting incidents, investigating the cause, and mitigating any damage. Proper incident management helps limit the impact of breaches and ensures timely compliance with HIPAA’s Breach Notification Rule. A well-defined incident response plan includes steps for notifying affected parties, correcting vulnerabilities, and preventing future incidents. **Requirements for incident management:** - Develop a comprehensive incident response plan - Investigate and document all security incidents - Notify affected individuals and HHS within 60 days of a breach - Implement corrective actions to prevent future incidents - Conduct post-incident reviews to assess response effectiveness ### Documentation Maintaining thorough documentation is essential for demonstrating HIPAA compliance. This includes records of policies and procedures, self-audits, employee training, incident reports, and BAAs. Accurate documentation serves as proof that the organization is consistently adhering to HIPAA requirements and is prepared for compliance reviews or audits by regulatory authorities. Documentation should be securely stored and regularly updated to reflect any changes in processes, ensuring that all compliance efforts are accurately recorded. **Requirements for documentation:** - Maintain records of policies, procedures, and compliance activities - Document self-audits and corrective actions - Keep records of employee training sessions - Securely store incident reports and response actions - Update documentation regularly and ensure easy accessibility ## What Is a HIPAA Violation? A HIPAA violation occurs when an entity fails to comply with any aspect of HIPAA regulations, compromising the confidentiality, integrity, or availability of PHI. Violations can result from inadequate safeguarding of patient information, unauthorized access, or failing to implement necessary policies and procedures. These infractions can result in penalties and jeopardize patient trust and reputation. Common violations include failing to conduct risk assessments, not encrypting PHI, unauthorized disclosures, and not reporting breaches within stipulated timeframes. Preventing violations requires proactive measures, including regular audits, employee training, and strict adherence to HIPAA rules. ### HIPAA Penalties for Non-Compliance The Office for Civil Rights (OCR), under the Department of Health and Human Services (HHS), enforces HIPAA regulations and categorizes violations into four tiers based on the level of severity and negligence. Fines increase depending on the entity’s level of awareness and corrective actions taken: - **Tier I – Unknowing:** The relevant entity was unaware of the violation and could not have reasonably avoided it. Fines range from $100 to $50,000 per violation, with a maximum annual penalty of $1.5 million per provision violated. - **Tier II – Reasonable Cause:** The entity should have known about the violation but did not act with willful neglect. Penalties range from $1,000 to $50,000 per violation, with the same annual maximum of $1.5 million. - **Tier III – Willful Neglect (Corrected)******The entity acted with willful neglect but corrected the issue within 30 days. Fines range from $10,000 to $50,000 per violation. - **Tier IV – Willful Neglect (Not Corrected)******The most severe violations, where the entity acted with willful neglect and failed to correct the issue within 30 days. Penalties can reach up to an annual maximum of $1.5 million per provision. ### Examples of HIPAA Violations - **Anthem, Inc.:** In 2015, Anthem, Inc., one of the largest health insurance providers in the U.S., experienced a massive data breach impacting nearly 79 million individuals. Cybercriminals gained unauthorized access to sensitive PHI due to inadequate security measures. As a result, Anthem agreed to a settlement of over $16 million, marking one of the largest settlements in HIPAA history. - **New York-Presbyterian Hospital/Columbia University Medical Center:** In 2014, these two institutions faced a $4.8 million settlement after PHI for approximately 6,800 patients was inadvertently made accessible to search engines. The breach occurred when a server was improperly deactivated, allowing sensitive patient information to be indexed online. This incident emphasized the importance of securely decommissioning systems that store or transmit PHI. - **Memorial Healthcare System:** Between 2011 and 2012, Memorial Healthcare System discovered that employees had been accessing patient records without authorization for over a year, affecting over 115,000 patients. This breach of internal controls resulted in a $5.5 million settlement. ## HIPAA Compliance Checklist and Best Practices ### 1. Designate a Privacy Officer A privacy officer is responsible for developing and implementing privacy policies, procedures, and practices that align with HIPAA regulations. This position requires a deep understanding of both legal requirements and the operational aspects of the organization. The privacy officer’s duties include overseeing the creation and enforcement of privacy policies, conducting regular risk assessments, and leading training programs for staff to ensure they understand their obligations under HIPAA. Additionally, the privacy officer acts as the main point of contact for any privacy-related issues, handling inquiries, and managing the resolution of complaints or concerns. They are also responsible for coordinating with IT and security teams to implement appropriate technical safeguards. ### 2. Conduct Risk Assessments Conducting regular risk assessments is fundamental to maintaining HIPAA compliance. These assessments should be comprehensive, covering all areas where PHI is handled, stored, or transmitted, including physical locations, electronic systems, and administrative processes. A thorough risk assessment involves evaluating current security measures to determine their effectiveness, identifying vulnerabilities, and assessing the likelihood and potential impact of various threats, such as cyberattacks, data breaches, or natural disasters. The assessment process should be well-documented, detailing the methodologies used, findings, and recommended actions for addressing identified risks. ### 3. Implement Administrative Safeguards Administrative safeguards include the policies and procedures that govern the management of PHI. These safeguards are designed to ensure that organizations establish a foundation for protecting PHI by defining roles, responsibilities, and processes that support the security and privacy of health information. Key aspects of administrative safeguards include: - **Development of a HIPAA compliance program**, which should outline the organization’s approach to managing PHI, including risk management, incident response, and contingency planning. This program should be tailored to the specific needs of the organization, taking into account its size, complexity, and the types of PHI it handles. - **Workforce training**—employees at all levels must receive regular training on HIPAA requirements, the organization’s privacy policies, and their specific responsibilities in protecting PHI. Training should cover topics such as identifying and reporting potential breaches, safeguarding electronic communications, and handling PHI securely in both digital and physical forms. - **Implementation of access controls**, ensuring that only authorized personnel have access to PHI. This involves establishing procedures for granting, modifying, and revoking access to information systems, as well as regularly reviewing access logs to detect and respond to any unauthorized access attempts. ### 4. Implement Physical Safeguards Physical safeguards protect PHI from physical threats such as unauthorized access, theft, or environmental hazards. These safeguards involve the implementation of security measures that control access to the physical locations where PHI is stored or processed, as well as the protection of the devices and systems that handle PHI. Important physical safeguards include: - **Securing the physical premises**, which includes implementing controlled access systems such as keycards, biometric scanners, or security personnel to restrict entry to areas where PHI is stored. This also involves installing surveillance cameras and alarm systems to monitor for unauthorized access attempts. - **Protecting hardware and media** that contain PHI. This includes securing workstations, servers, and portable devices like laptops and USB drives, using locks, secure cabinets, and proper storage protocols. - **Establishing procedures for proper disposal** of devices and media containing PHI, such as degaussing, shredding, or using certified destruction services. - **Establishing environmental controls**—organizations must ensure that their facilities are protected against natural disasters, power failures, and other environmental risks that could compromise the integrity of PHI. This includes implementing backup power systems, fire suppression systems, and climate control measures to safeguard electronic equipment and data. ### 5. Implement Technical Safeguards Technical safeguards are the technological measures that protect ePHI and control access to it, ensuring that only authorized individuals can view or manipulate this sensitive information. These safeguards address the specific requirements for securing electronic data against cyber threats, unauthorized access, and data breaches. Primary technical safeguards include: - **Access control mechanisms**, including the use of strong, unique passwords, multi-factor authentication, and role-based access controls that limit access to ePHI based on an individual’s job function. This ensures that users only have access to the minimum necessary information required to perform their duties. - **Encryption**, which protects ePHI by converting it into an unreadable format that can only be decrypted by authorized parties. Encryption should be applied to ePHI both at rest (when stored on devices or servers) and in transit (when being transmitted over networks). - **Audit controls**, providing a detailed log of who accessed what information, when, and what actions were taken. Regularly reviewing these logs allows organizations to detect and respond to suspicious activities, such as unauthorized access attempts or potential breaches. - **Data integrity measures**, such as checksums and digital signatures, ensure that ePHI is not altered or tampered with without detection. Organizations should implement regular data backups and use secure methods for transmitting data to prevent unauthorized changes or loss of information. ### 6. Develop and Enforce Policies and Procedures Developing and enforcing policies and procedures is vital for ensuring consistent and effective HIPAA compliance across an organization. These policies and procedures provide a framework for how PHI should be handled, from collection and storage to access, transmission, and disposal. They define the roles and responsibilities of employees, outline the organization’s approach to managing compliance, and establish the protocols for responding to incidents and breaches. Organizations must develop detailed policies covering all aspects of HIPAA compliance, including privacy practices, security measures, and breach notification procedures. These policies should be tailored to the specific needs of the organization, considering factors such as its size, the complexity of its operations, and the types of PHI it handles. Policies should also address the use of technology in managing PHI, including the secure use of email, mobile devices, and cloud services. ### 7. Sign Business Associate Agreements (BAAs) Signing Business Associate Agreements (BAAs) is a crucial step in ensuring HIPAA compliance when working with third-party vendors or partners who handle PHI. These agreements establish the responsibilities and expectations for both the covered entity and the business associate, outlining the permissible uses and disclosures of PHI, as well as the security measures that must be in place to protect this information. BAAs should be comprehensive, detailing the specific HIPAA requirements that the business associate must adhere to, including breach notification procedures, data encryption standards, and access controls. The agreement should also specify the consequences of non-compliance, such as termination of the contract or financial penalties. Covered entities must ensure that all business associates sign BAAs before any PHI is shared. This includes not only primary vendors but also any subcontractors or third parties that the business associate may engage. Regular reviews and updates of BAAs are necessary to reflect any changes in regulations or business practices. ### 8. Regularly Audit and Monitor Compliance Regular audits and ongoing monitoring are essential practices for maintaining continuous HIPAA compliance. Audits involve a systematic review of the organization’s policies, procedures, and practices to ensure they meet HIPAA requirements. This includes evaluating the effectiveness of administrative, physical, and technical safeguards, as well as identifying any gaps or weaknesses that could lead to non-compliance. An audit should cover all aspects of HIPAA compliance, including privacy practices, security measures, employee training, and incident response protocols. The audit process should be documented, with findings reported to senior management and used to inform corrective actions or improvements to the organization’s compliance program. Regular audits not only help ensure ongoing compliance but also prepare the organization for potential external audits by regulatory bodies. In addition to formal audits, organizations should implement continuous monitoring processes to detect and respond to compliance issues in real time. This includes monitoring access to PHI, reviewing security logs for unusual activity, and tracking employee adherence to privacy and security policies. Monitoring systems can provide early warnings of potential issues, allowing the organization to address them before they escalate into significant violations. ### 9. Prepare for Breach Notification Being prepared for breach notifications is a critical aspect of HIPAA compliance, as it ensures that an organization can respond quickly and effectively in the event of a data breach involving PHI. The HIPAA Breach Notification Rule requires organizations to notify affected individuals, the Department of Health and Human Services (HHS), and, in some cases, the media, of any breaches of unsecured PHI. To prepare for breach notification, organizations should develop a comprehensive breach response plan that outlines the steps to be taken immediately upon discovering a breach. This plan should include procedures for identifying the nature and scope of the breach, containing the breach to prevent further unauthorized access, and assessing the impact on the affected individuals. The plan should also specify the timelines for notifying affected parties and the required content of the notification, including a description of the breach, the types of PHI involved, and the steps individuals can take to protect themselves. In addition to internal preparations, organizations should establish relationships with external partners who can assist in breach response, such as legal counsel, cybersecurity experts, and public relations firms. These partners can provide valuable support in managing the breach, complying with notification requirements, and mitigating the potential damage to the organization’s reputation. ## **HIPAA-Compliant Hosting Services and Solutions by Atlantic.Net** *HIPAA-Compliant Hosting by Atlantic.Net™* is [SOC 2 and SOC 3 certified, HIPAA and HITECH audited](https://www.atlantic.net/compliance-hosting/), and designed to secure and protect critical health data, electronic protected health information (ePHI), and records. We are audited by a qualified and an independent third-party CPA firm to validity of our operational controls and compliance services. ### **HIPAA Compliant Website Hosting** Our HIPAA Compliant Web Hosting Platform is secured to industry standards, providing a highly durable, feature-rich solution, powered by the latest tech, offering breakneck performance – available in both dedicated and cloud server environments and backed by our 100% uptime SLA. ### **HIPAA-Compliant Cloud Hosting** Security, scalability, high-speed data transfers, and performance are the focus of our Cloud Hosting Solutions. Atlantic.Net’s HIPAA Cloud solutions offer fast provisioning, ongoing management, and round-the-clock monitoring. [Learn more about Atlantic.net HIPAA hosting](https://www.atlantic.net/hipaa-compliant-hosting/) ## See Additional Guides on Key Compliance Management Topics Together with our content partners, we have authored in-depth guides on several other topics that can also be useful as you explore the world of [compliance management](https://www.exabeam.com/explainers/compliance-management/compliance-management-process-regulations-and-tools/). #### [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) *Authored by Atlantic.Net* - [[Guide] HIPAA-Compliant Hosting | 2025 Award Winning HIPAA Hosting ](https://www.atlantic.net/hipaa-compliant-hosting/) - [[Guide] What is Protected Health Information (PHI) in 2025? Atlantic.Net ](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) - [[Blog] RTLS and Healthcare ](https://www.atlantic.net/hipaa-compliant-hosting/rtls-and-healthcare-can-real-time-location-system-security-improve-your-healthcare-operations/) - [[Product] Atlantic.Net HIPAA Compliant Hosting ](https://www.atlantic.net/hipaa-compliant-hosting/) #### [VPS Hosting](https://www.atlantic.net/vps-hosting/) *Authored by Atlantic.Net* - [[Guide] Cloud VPS Hosting | Virtual Private Servers ](https://www.atlantic.net/vps-hosting/) - [[Guide] High-Performance & Affordable Linux VPS Hosting ](https://www.atlantic.net/vps-hosting/linux-vps-hosting/) - [[Blog] Does Using SaaS Make My IT Environment More Secure or Less Secure?](https://www.atlantic.net/vps-hosting/does-using-saas-make-my-it-environment-more-secure-or-less-secure/) - [[Product] Atlantic.Net Cloud Platform | Scalable, Secure Cloud Solutions](https://www.atlantic.net/cloud-platform/) #### [DORA Regulation](https://faddom.com/dora-regulation-requirements-penalties-and-compliance-checklist/) *Authored by Faddom* - [[Guide] DORA Regulation: Requirements, Penalties & Compliance Checklist](https://faddom.com/dora-regulation-requirements-penalties-and-compliance-checklist/) - [[Guide] How the DORA Regulation Impacts IT ](https://faddom.com/how-the-dora-regulation-impacts-it/) - [[Product] Faddom | Instant Application Dependency Mapping Tool​](https://faddom.com/) --- # Passing Arguments to Bash Scripts: A Practical Guide > URL: https://www.atlantic.net/vps-hosting/passing-arguments-to-bash-scripts-a-practical-guide/ | Published: 2024-10-04 | Updated: 2025-02-07 | Author: Hitesh Jethva Bash scripts are files containing a series of commands that are executed in sequence by the Bash shell. These scripts are used for everything from simple file management to complex system administration tasks. One of the most essential aspects of Bash scripting is the ability to pass arguments to your scripts. This feature allows scripts to be flexible and dynamic, capable of handling various inputs and performing different actions based on those inputs. In this article, we will explore how to pass arguments to Bash scripts, the special variables involved, and some real-world examples to illustrate these concepts. ## Basics of Passing Arguments to Bash Scripts When you pass arguments to a Bash script, they are stored in positional parameters, which are special variables: - **$0** is the name of the script. - **$1, $2,** and so on represent the arguments passed to the script. - **$#** gives the number of arguments passed. - **$@** and **$*** represent all the arguments passed. Let’s create an example script. ```bash #!/bin/bash echo "Script name: $0" echo "First argument: $1" echo "Second argument: $2" echo "Total number of arguments: $#" echo "All arguments: $@" ``` Now, we’ll run this script using the following arguments: ```bash bash script.sh arg1 arg2 ``` Output: ```bash Script name: script.sh First argument: arg1 Second argument: arg2 Total number of arguments: 2 All arguments: arg1 arg2 ``` In this example, the script prints the script’s name, the first and second arguments, the total number of arguments, and all arguments as a list. ## Handling Multiple Arguments If your script needs to handle various arguments, you can loop through them. You can also use the shift command to move through the arguments. Let’s create a script with the following content. ```bash #!/bin/bash echo "All arguments: $@" echo "Looping through the arguments:" while (( "$#" )); do echo "Argument: $1" shift done ``` Now, we’ll run this script: ```bash bash script.sh one two three four ``` Output: ```bash All arguments: one two three four Looping through the arguments: Argument: one Argument: two Argument: three Argument: four ``` In this example, the while loop continues until no more arguments ($# becomes zero). The shift command moves each argument out of $1, making the next one the first. ## Combining Positional Arguments with Flags Scripts often need to handle options or flags (like -f or –file). Here’s how you can do this using **getopts,** a built-in command for parsing options. Here is an example script: ```bash #!/bin/bash while getopts ":f:o:" opt; do case $opt in f) echo "File option passed with value: $OPTARG" ;; o) echo "Output option passed with value: $OPTARG" ;; \?) echo "Invalid option: -$OPTARG" ;; esac done ``` Run the above script: ```bash bash script.sh -f input.txt -o output.txt ``` Output: ```bash File option passed with value: input.txt Output option passed with value: output.txt ``` In this example, **getopts** is used to parse the **-f** and **-o** options, and **$OPTARG** holds the value of each option. If an invalid option is passed, the script catches it and prints an error. ## Error Handling: Validating Input Good scripts should validate input to ensure they have the necessary arguments. This prevents errors or unexpected behavior. Here is an example script: ```bash #!/bin/bash if [ $# -lt 2 ]; then echo "Error: You need to provide at least two arguments." exit 1 fi echo "Arguments are valid. Proceeding..." ``` Run the above script: ```bash bash script.sh one ``` Output: ```bash Error: You need to provide at least two arguments. ``` Here, the script checks if fewer than two arguments were provided. If so, it prints an error message and exits. ## Conclusion Passing arguments to Bash scripts allows you to write flexible, reusable, and dynamic scripts. You can now create scripts that handle a variety of inputs, making them more powerful and useful in real-world applications. Try using Bash scripts to automate application deployment on [VPS hosting](https://www.atlantic.net/vps-hosting/) from Atlantic.Net! --- # How to Use scp Command with Specified Port Number in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-use-scp-command-with-specified-port-number-in-linux/ | Published: 2024-10-05 | Updated: 2025-02-07 | Author: Hitesh Jethva SCP (Secure Copy Protocol) is a command-line utility that allows users to transfer files between two machines over a network securely. Typically, SCP operates over the default SSH port, 22. However, there are situations where the SSH server is configured to use a non-standard port for enhanced security. In such cases, specifying a port number in the SCP command becomes essential. In this guide, we’ll explore how to use SCP with a specified port number. ## Specifying a Custom Port with SCP To specify a custom port, use the **-P** flag followed by the port number. Note that the -P option in SCP is uppercase **(-P)** and not to be confused with the lowercase -p option, which preserves file attributes. Here is a basic syntax: ```bash scp -P [custom-port] [Source] [Destination] ``` Let’s go through some practical examples: ### Example 1: Copying a File from a Local Machine to a Remote Server Suppose you want to copy a file named example.txt from your local machine to a remote server running SSH on port **2222:** ```bash scp -P 2222 /home/user/example.txt user@remote_host:/home/user/ ``` **Explanation:** - **-P 2222:** Specifies the custom port number. - **/home/user/example.txt:** Path to the source file on the local machine. - **user@remote_host:/home/user/:** Remote destination, where user is the username and /home/user/ is the target directory on the remote server. ### Example 2: Copying a Directory from a Remote Server to a Local Machine Now, let’s copy an entire directory named project from a remote server to your local machine. The SSH service on the remote server runs on port **2222:** ```bash scp -P 2222 -r user@remote_host:/home/user/project /home/local_user/ ``` **Explanation:** - **-P 2222:** Specifies the port number. - **-r:** Copies the entire directory recursively. - **user@remote_host:/home/user/project:** Source directory on the remote server. - **/home/local_user/:** Destination directory on the local machine. ## Practical Use Cases for Specifying a Custom Port ### 1. Enhanced Security by Changing Default SSH Port One of the most common reasons for specifying a custom port is to avoid using the default SSH port, 22. Changing the SSH port can mitigate automated attacks or bots scanning for open SSH ports, and administrators can reduce the likelihood of unauthorized access attempts using a non-standard port. ### 2. Multiple Services on the Same Host In environments where multiple services need to be accessed over SSH, different ports can be used to differentiate between them. For instance, one service might use port **2222** while another uses **2022.** ## Conclusion SCP is a powerful tool for secure file transfers between machines, and specifying a port number is often necessary in complex or hardened network environments. You can now ensure your file transfers are efficient and secure. You can now easily use scp to transfer files between multiple servers on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Linux rpm Command Guide with Examples > URL: https://www.atlantic.net/dedicated-server-hosting/linux-rpm-command-guide-with-examples/ | Published: 2024-10-06 | Updated: 2024-10-29 | Author: Hitesh Jethva The rpm command is a powerful package management tool used in RPM-based Linux distributions like Red Hat, CentOS, Fedora, and openSUSE. It allows users to install, update, verify, query, and remove software packages. In this comprehensive guide, we’ll explore various rpm commands with practical examples to help you efficiently manage your system’s software packages. ## Installing RPM Packages The **rpm -i** command is used to install RPM packages on your system. Below, we will look at some examples of using this command. ### Example 1: Installing a Package To install an RPM package, use the following command: ```bash rpm -i package.rpm ``` **Explanation:** - **-i** stands for install. - **package.rpm** is the name of the RPM file you want to install. ## Example 2: Installing a Package with Verbose Output The **-v** and **-h** options can be added to make the output more informative and user-friendly. ```bash rpm -ivh package.rpm ``` **Explanation:** - **-v** enables verbose mode, providing more detailed output. - **-h** displays hash marks (#) to show progress during installation. ## Updating RPM Packages To update an installed package, use the rpm -U command. This command can be used to either install a new version or replace an older version of the package. ### Example 1: Basic Update Command To update an existing package, use: ```bash rpm -U package.rpm ``` **Explanation:** - **-U** stands for upgrade, which installs a new version if available or upgrades an existing version. ### Example 2: Using the -F Flag to Update Only If Installed The **-F** (freshen) option only upgrades a package if an older version is already installed: ```bash rpm -F package.rpm ``` **Explanation:** - **-F** updates only if the package is already installed. It’s useful for applying updates without accidentally installing new packages. ## Removing RPM Packages To remove an installed package, use the **rpm -e** command. ### Example 1: Basic Removal To remove a package, use: ```bash rpm -e package_name ``` **Explanation:** - **-e** stands for erase, which removes the specified package from the system. ### Example 2: Removing a Package with Dependencies If you want to remove a package without checking dependencies, use the **–nodeps** flag: ```bash rpm -e --nodeps package_name ``` **Explanation:** - **–nodeps** forces removal without checking for package dependencies. Use this option with caution, as it can cause other packages to break. ## Querying RPM Packages The **rpm -q** command is used to query information about installed packages. ### Example 1: Querying Whether a Package is Installed To check if a package is installed: ```bash rpm -q package_name ``` ### Example 2: Querying Package Details To get detailed information about an installed package: ```bash rpm -qi package_name ``` ### Example 3: Listing All Installed Packages To list all installed packages: ```bash rpm -qa ``` ### Example 4: Querying Files Provided by a Package To list all files installed by a specific package, use: ```bash rpm -ql package_name ``` ### Example 5: Finding the Package That Provides a Specific File If you want to know which package owns a specific file: ```bash rpm -qf /usr/bin/package_binary ``` ## Verifying RPM Packages The **rpm -V** command verifies the integrity of installed packages, checking if any files have been altered since installation. ### Example 1: Verifying a Specific Package To verify an installed package: ```bash rpm -V package_name ``` ## Conclusion Understanding the rpm command is crucial for anyone managing RPM-based Linux distributions. It provides powerful and flexible options for installing, updating, removing, verifying, and querying software packages. Try exploring all available rpm command options on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Move Directory to Another Directory with Identical Name in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/move-directory-to-another-directory-with-identical-name-in-linux/ | Published: 2024-10-07 | Updated: 2024-10-29 | Author: Hitesh Jethva In Linux, moving directories is a common task that can become a bit challenging when dealing with directories that have identical names. The mv command is used to move files or directories from one location to another and can also be used to rename them if needed. This guide will walk you through the steps to move a directory into another location with the same name. ## Understanding the mv Command The mv command is one of the essential tools for managing files and directories in Linux. Here’s the basic syntax for the mv command: ```bash mv [options] source destination ``` - **source:** The file or directory you want to move. - **destination:** The target location. **Options:** - **-i:** Prompts before overwriting. - **-v:** Shows the progress of the move. - **-f:** Forces the move without prompting for confirmation. ## Preparing for the Move Before moving directories, it’s essential to ensure that both the source and destination directories exist and that you have the appropriate permissions to move them. ### Step 1: Verify Directory Existence To check if the source and destination directories exist, use the ls or find commands: ```bash ls /path/to/source_directory ls /path/to/destination_directory ``` If the directories exist, you will see their contents listed. Otherwise, an error will indicate that they do not exist. ### Step 2: Check Permissions Ensure that you have sufficient permissions to move the directories. Use the **ls -ld** command to check permissions: ```bash ls -ld /path/to/source_directory ``` The output will show the permissions, owner, and group. If you don’t have write permissions, you may need to use sudo or change permissions with the chmod command. ## Moving a Directory with an Identical Name Moving a directory into another location with the same name can be done in multiple ways, depending on whether you want to overwrite or merge the content. ### Method 1: Overwriting the Destination Directory If you want to overwrite the existing directory in the destination, use the mv command with the **-f** (force) option: ```bash mv -f /path/to/source_directory /path/to/destination_directory/ ``` **Explanation:** - The **-f** flag forces the move, overwriting files in the destination without prompting for confirmation. This is useful if you’re confident that overwriting the existing files is the desired action. ### Method 2: Merging the Contents of Both Directories If you want to merge the contents of the source directory with the destination directory, using the rsync command is a safer and more effective approach: ```bash rsync -av /path/to/source_directory/ /path/to/destination_directory/ ``` **Explanation:** - **rsync** is a powerful utility for copying files and directories. - **-a** ensures that all attributes are preserved (recursive, permissions, etc.). - **-v** enables verbose output to see the progress. ## Handling Conflicts and Avoiding Data Loss When moving directories with the same name, conflicts can arise, especially if files in the destination have the same names as files in the source. Here are some ways to handle conflicts: ### Example 1: Interactive Confirmation Before Overwriting Using the **-i** flag prompts you before overwriting existing files, allowing you to decide: ```bash mv -i /path/to/source_directory /path/to/destination_directory/ ``` You will be asked to overwrite: ```bash mv: overwrite '/path/to/destination_directory/file1.txt'? (y/n) ``` This prompt gives you control over which files to overwrite. ### Example 2: Renaming the Destination Directory To avoid conflicts entirely, you can rename the destination directory before moving the source directory: ```bash mv /path/to/destination_directory /path/to/destination_directory_backup mv /path/to/source_directory /path/to/destination_directory/ ``` This ensures that the original destination directory is preserved as a backup, and the source directory takes its place. ## Conclusion The mv command is a powerful tool for managing files and directories in Linux, but when dealing with directories that share the same name, careful planning is required. Practice with small tasks and gradually move on to more complex operations to master Linux file management. You can now easily use mv command on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Linux su Command Guide with Examples > URL: https://www.atlantic.net/dedicated-server-hosting/linux-su-command-guide-with-examples/ | Published: 2024-10-08 | Updated: 2025-09-11 | Author: Hitesh Jethva The su command in Linux, which stands for “substitute user” or “switch user,” is a powerful utility that allows you to switch to another user’s account. The **su** command is essential for performing administrative tasks that require elevated privileges, such as installing software or modifying system configurations. In this guide, we will explore how to effectively use the su command with practical examples. ## Understanding the su Command The su command allows you to switch from your current user account to another user account. It’s commonly used to gain superuser privileges by switching to the root user. Here is a basic syntax: ```bash su [options] [username] ``` **Options:** - **-:** Load the target user’s environment as a login shell. - **-c:** Execute a command as the specified user. ### Difference Between su and sudo - **su:** Switches the user, requiring the target user’s password (usually root). Once switched, you stay as that user until you exit. - **sudo:** Runs a single command with elevated privileges, requiring the current user’s password. It’s more controlled, as you don’t completely switch users. ## Switching to Root User The most common use of su is to switch to the root user, allowing you to perform administrative tasks. ### Example 1: Basic Command to Switch to the Root User To switch to the root user, simply enter: ```bash su ``` You will be prompted for the root password. After entering the correct password, you will have root privileges. ```bash Password: [root@hostname ~]# ``` ## Switching to Another User You can also use su to switch to any other user account. ### Example 1: Switching to a Different User Account To switch to a different user account, specify the username: ```bash su - username ``` You will be asked to provide your user’s password: ```bash Password: [username@hostname ~]$ ``` ## Running Commands as Another User You don’t always need to switch to an interactive shell; instead, you can run a single command as another user. ### Example 1: Running a Single Command as Root To execute a command as root without switching to a root shell: ```bash su -c "command_to_run" ``` Example: To create a directory named example_dir in the /root directory: ```bash su -c "mkdir /root/example_dir" ``` After entering the root password, the command will be executed, and the directory will be created. ### Example 2: Running a Command as Another User You can also run a command as a specific user: ```bash su - username -c "command_to_run" ``` Example: To list the files in another user’s home directory: ```bash su - john -c "ls /home/john" ``` This allows you to perform specific tasks for another user without fully switching to their account. ## Common Errors and Troubleshooting ### 1. “Authentication Failure” If you enter an incorrect password, you will see: ```bash su: Authentication failure ``` Make sure you are using the correct password for the target user. For root, this means knowing the root password, which may be different from your current user password. ### 2. Permission Issues If you attempt to use su to switch to a restricted account, you may encounter permission issues: ```bash su: cannot set user id: Permission denied ``` You need to ensure that you have the proper permissions to switch to the specified user. Only users with sufficient privileges can switch to certain accounts, like root. ## Conclusion The su command is an essential tool for managing Linux systems, allowing you to switch users, run commands as other users, and perform administrative tasks effectively. You can now easily switch between multiple users on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Linux pwd Command Guide with Examples > URL: https://www.atlantic.net/dedicated-server-hosting/linux-pwd-command-guide-with-examples/ | Published: 2024-10-09 | Updated: 2024-10-29 | Author: Hitesh Jethva The pwd command in Linux, which stands for “print working directory,” is a handy command that helps users identify their current location within the directory structure. When navigating the Linux filesystem, especially with deep and complex directory trees, knowing your current path is crucial. This guide will introduce you to the **pwd** command, explain its options, and provide practical examples to help you better understand how to use it effectively. ## Understanding the pwd Command The pwd command is used to display the absolute path of the current working directory. It helps users confirm where they are within the directory hierarchy. **Basic Syntax:** ```bash pwd [options] ``` - **pwd:** Prints the current working directory. - **[options]:** Optional flags to modify the command’s behavior. ## Using the pwd Command The most basic usage of pwd is to print the current working directory, which gives you the full path from the root directory (/) to your current location. ### Example 1: Displaying the Current Directory To print the current working directory, simply enter: ```bash pwd ``` Output: ```bash /home/user/Documents ``` The output shows the absolute path of the current directory, starting from the root **(/).** In this example, the user is currently in the Documents directory under **/home/user.** ## pwd Command Options The pwd command has a couple of useful options that can help you work with both logical and physical paths. ### Option 1: -L (Logical Path) The **-L** option tells pwd to display the logical path, taking into account any symbolic links that might be part of your path. ```bash pwd -L ``` This option shows the logical current working directory, which may include symbolic links. This is the default behavior of pwd. ### Option 2: -P (Physical Path) The **-P** option tells pwd to display the physical path, ignoring any symbolic links and showing the actual location on the filesystem. ```bash pwd -P ``` **Example:** Suppose you have a symbolic link **/home/user/link_to_docs** that points to **/mnt/storage/Documents.** If you navigate through the symbolic link and use pwd with different options as shown below: ```bash cd /home/user/link_to_docs pwd -L ``` Output: ```bash /home/user/link_to_docs ``` Now, run the following command: ```bash pwd -P ``` Output: ```bash /mnt/storage/Documents ``` **Explanation:** Using **pwd -L** returns the logical path **(/home/user/link_to_docs),** while **pwd -P** returns the physical path **(/mnt/storage/Documents).** This can be useful when you need to determine the real location of the directory you’re working in, especially in environments with multiple symbolic links. ## Practical Use Cases of the pwd Command The pwd command is useful in several real-world scenarios, especially when navigating complex directory structures or working on scripts. In scripts, using pwd allows you to store the current directory in a variable, ensuring that your script always works with absolute paths. This helps avoid issues when executing commands that depend on a specific directory structure. **Example script:** ```bash current_dir=$(pwd) echo "The script is running in: $current_dir" ``` Output. ```bash The script is running in: /home/user/scripts ``` Storing the current directory path in a variable can be particularly useful when you need to navigate away and return to the original directory within a script. ## Conclusion This article provides a comprehensive guide to using the pwd command in Linux. It aims to help beginners understand the command thoroughly while providing enough context for practical, real-world usage. Ppractice using pwd command on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting) from Atlantic.Net! --- # Run BASIC Code in the Linux Terminal > URL: https://www.atlantic.net/dedicated-server-hosting/run-basic-code-in-the-linux-terminal/ | Published: 2024-10-10 | Updated: 2024-10-29 | Author: Hitesh Jethva BASIC, which stands for “Beginner’s All-purpose Symbolic Instruction Code,” was one of the earliest and most accessible programming languages. Created in the 1960s, it became immensely popular in the 1980s due to its ease of use and was widely used in education and on early personal computers. This guide will show you how to run BASIC code directly in a Linux terminal using various tools and interpreters. ## Setting up a BASIC Interpreter on Linux To run BASIC programs in a Linux terminal, you need a BASIC interpreter. Fortunately, several interpreters are available, including BASIC-256, FreeBASIC, and cbmbasic. In this guide, we will use cbmbasic, which is a reimplementation of the original Commodore 64 BASIC. You can install cbmbasic using the default package manager in many Linux distributions. If you are using a Debian-based system like Ubuntu, use the following command: ```bash apt install cbmbasic ``` For Red Hat-based distributions, you can use: ```bash yum install cbmbasic ``` Once installed, you will be able to run BASIC code in the terminal. ## Writing Your First BASIC Program Let’s start by writing a simple BASIC program. You can use any text editor, such as nano, vim, or gedit, to create a new BASIC file. Open your text editor and type the following lines of code: ```bash 10 PRINT "Hello, World!" 20 END ``` Save the file as hello.bas. **Explanation:** - **Line 10:** The PRINT statement is used to display a message on the screen. - **Line 20:** The END statement indicates the end of the program. ## Running BASIC Code in the Terminal Now that you have created your first BASIC program, you can run it using the cbmbasic interpreter. To execute your BASIC program, type the following command in your terminal: ```bash cbmbasic hello.bas ``` The cbmbasic interpreter reads the hello.bas file and executes the code, displaying the message **“Hello, World!”** in the terminal. ```bash Hello, World! ``` ## Interactive Mode in BASIC Interpreters In addition to running scripts, cbmbasic also allows you to start an interactive BASIC session. This can be useful for experimenting with code and learning how BASIC works in real time. To start an interactive session, type: ```bash cbmbasic ``` You will see a prompt where you can enter BASIC commands directly. At the interactive prompt, you can type: ```bash PRINT "This is BASIC in action!" ``` Output: ```bash This is BASIC in action! ``` You can also perform calculations or try different commands without writing a full program file. ## Practical Use Cases and Examples BASIC may be simple, but it can still perform interesting tasks. Here are a few practical examples. ### Example 1: Writing a Loop to Print Numbers from 1 to 10 Open a text editor and write the following code: ```bash 10 FOR I = 1 TO 10 20 PRINT I 30 NEXT I 40 END ``` Save the file as **count.bas** and run it: ```bash cbmbasic count.bas ``` Output: ```bash 1 2 3 4 5 6 7 8 9 10 ``` ### Example 2: Creating a Simple Calculator Using INPUT Statements Create a new BASIC file with the following code: ```bash 10 INPUT "Enter first number: "; A 20 INPUT "Enter second number: "; B 30 PRINT "The sum is "; A + B 40 END ``` Save the file as **calculator.bas** and run it: ```bash cbmbasic calculator.bas ``` Output: ```bash Enter first number: 5 Enter second number: 7 The sum is 12 ``` ## Conclusion In this guide, we explored how to run BASIC code in the Linux terminal, from setting up an interpreter like cbmbasic to writing and executing BASIC programs. BASIC is a great way to learn programming concepts, and revisiting it can be a fun and educational journey. You can now easily run BASIC code on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Install a Specific Package Version Using Snap > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-install-a-specific-package-version-using-snap/ | Published: 2024-10-11 | Updated: 2024-10-29 | Author: Hitesh Jethva Snap is a universal package management system developed by Canonical, which allows developers and users to distribute and install software easily across various Linux distributions. Snap packages are sandboxed, automatically updated, and compatible across multiple platforms, making them a popular choice for both developers and end users. In this guide, we’ll show you how to install a specific version of a package using Snap. ## Installing Snap and Setting Up the Environment Before you can use Snap to install specific versions of packages, you need to have Snap installed on your system. Most modern Linux distributions, like Ubuntu, come with Snap pre-installed. If it’s not installed, follow the steps below. First, update your package list and then install Snap: ```bash apt update apt install snapd ``` Verify that Snap has been installed correctly by running: ```bash snap version ``` ## Searching for Available Package Versions Snap packages are available in multiple versions, often distributed through different channels. To install a specific version, you first need to find out which versions are available. To see all available versions of a Snap package, use the **snap info** command: ```bash snap info package-name ``` **Example:** Searching for available versions of the **node** package: ```bash snap info node ``` ## Installing a Specific Version Using Snap Once you have identified the version you want to install, you can specify the channel to install that version. ### Installing from a Specific Channel To install a specific version of a package, use the **–channel** option followed by the desired version and channel name. ```bash snap install package-name --channel=version/stable ``` **Example:** Installing Node.js version 14 from the stable channel: ```bash snap install node --channel=14/stable ``` - **–channel=14/stable:** Specifies the version (14) and the channel (stable) from which the Snap should be installed. ### Other Channels: Beta and Edge In addition to the stable channel, you can also choose candidate, beta, or edge channels to install the latest development versions: ```bash snap install package-name --channel=version/edge ``` **Example:** Installing the latest beta version of Docker: ```bash snap install docker --channel=19.03/beta ``` ## Switching Between Installed Versions Snap allows you to easily switch between different versions of an installed package without uninstalling. ### Using snap refresh to Switch Versions To switch to a different version of an already installed Snap, use the **snap refresh** command: ```bash snap refresh package-name --channel=desired-version/stable ``` **Example:** Switching to Node.js version 14: ```bash snap refresh node --channel=14/stable ``` ### Reverting to a Previous Version If you want to revert to the previous version after an update, use: ```bash snap revert package-name ``` ## Conclusion Snap provides an easy and convenient way to install specific versions of packages. With Snap, you can also switch between versions and revert to previous ones with ease, helping you maintain control over your software environment. You can now get started using Snap package manager on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Disable Avahi-Daemon in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-disable-avahi-daemon-in-linux/ | Published: 2024-10-12 | Updated: 2024-10-29 | Author: Hitesh Jethva Avahi-Daemon is a service that plays an important role in local network discovery on Linux systems. It facilitates communication between devices using the mDNS (Multicast DNS) and DNS-SD (DNS Service Discovery) protocols, allowing them to discover services such as printers, file shares, and more without manual configuration. However, in certain environments, such as production servers or devices where minimizing the attack surface is critical, you may want to disable Avahi-Daemon to enhance security, reduce unnecessary network traffic, or save system resources. This guide will walk you through how to properly disable Avahi-Daemon in Linux. ## Checking Whether Avahi-Daemon Is Running Before disabling Avahi-Daemon, you should verify if it is currently active. Use the **systemctl** command to check if Avahi-Daemon is running: ```bash systemctl status avahi-daemon ``` If the status shows “active (running)” then Avahi-Daemon is currently enabled and operational. If you decide to disable it, follow the next steps. ## Stopping Avahi-Daemon If you want to stop Avahi-Daemon temporarily, you can use the following command. This will stop the service until the system is rebooted. ```bash systemctl stop avahi-daemon ``` The stop command halts the Avahi-Daemon service immediately, but it will not prevent it from restarting on the next boot. ## Disabling Avahi-Daemon Permanently To ensure that Avahi-Daemon does not start again after a reboot, you need to disable it permanently. Use the following command to disable Avahi-Daemon: ```bash systemctl disable avahi-daemon ``` The disable command removes the links that cause Avahi-Daemon to start automatically at boot, ensuring it stays inactive. ## Masking Avahi-Daemon for Additional Security For extra security, you can mask the Avahi-Daemon service. Masking prevents it from being started manually or by other services. Use the following command to mask the service: ```bash systemctl mask avahi-daemon ``` Masking a service links its unit file to **/dev/null,** making it impossible to start the service. ## Removing Avahi-Daemon If you are sure that Avahi-Daemon is not required on your system, you can also choose to remove it completely. For Debian-based distributions like Ubuntu, use: ```bash apt remove avahi-daemon ``` For Red Hat-based distributions, use: ```bash yum remove avahi ``` ## Conclusion Disabling Avahi-Daemon can be a practical way to enhance the security and performance of your Linux system, especially if the service is not needed. Before deciding to disable Avahi-Daemon, carefully consider your use case. While it provides useful service discovery features in certain environments, it can pose a security risk in others. You can now disable Avahi daemon on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Grant SFTP User Access to /var/www Directory > URL: https://www.atlantic.net/dedicated-server-hosting/grant-sftp-user-access-to-var-www-directory/ | Published: 2024-10-13 | Updated: 2024-10-29 | Author: Hitesh Jethva When managing web servers, it’s common to provide users with secure access to the website’s files. One way to do this is by granting SFTP (Secure File Transfer Protocol) access to the /var/www directory. This allows users to upload, download, and manage website files securely without granting full SSH access. In this article, we will walk through the process of creating an SFTP user and restricting their access to the /var/www directory. ## Step 1: Create a New SFTP User We’ll create a new user specifically for SFTP access. This user will not need SSH access, which helps maintain security. ```bash adduser sftpuser ``` This command creates a new user named sftpuser. You’ll be prompted to set a password and optional information like name and contact details. Follow the instructions to complete the setup. ## Step 2: Modify SSH Configuration for SFTP To restrict sftpuser to SFTP-only access, we need to modify the SSH configuration file. 1. Open the SSH configuration file: ```bash nano /etc/ssh/sshd_config ``` Add the following at the end of the file: ```bash Match User sftpuser ChrootDirectory /var/www ForceCommand internal-sftp AllowTcpForwarding no X11Forwarding no ``` **Explanation:** - **Match User:** Limits the settings to sftpuser. - **ChrootDirectory:** Restricts the user’s root directory to /var/www. - **ForceCommand internal-sftp:** Ensures the user can only use SFTP. - **AllowTcpForwarding and X11Forwarding:** Disable unnecessary services. 2. Save and close the file. ## Step 3: Set Permissions on /var/www To allow sftpuser to write in **/var/www,** we need to adjust the permissions. 1. Change the ownership of **/var/www** to **root:** ```bash chown root:root /var/www ``` This ensures that sftpuser can access but not modify anything outside the **/var/www** directory. 2. Create a subdirectory in **/var/www** where the SFTP user can upload files: ```bash mkdir /var/www/sftpuser_uploads ``` 3. Set ownership of the subdirectory to **sftpuser:** ```bash chown sftpuser:sftpuser /var/www/sftpuser_uploads ``` 4. Adjust the permissions to allow **read** and **write** access: ```bash chmod 755 /var/www chmod 755 /var/www/sftpuser_uploads ``` These commands set the permissions so that sftpuser can upload and manage files inside **sftpuser_uploads.** ## Step 4: Restart the SSH Service After updating the configuration and permissions, restart the SSH service: ```bash systemctl restart ssh ``` ## Step 5: Test SFTP Access Now that the configuration is in place, you can test SFTP access. 1. Use an SFTP client like FileZilla or the command line to connect: ```bash sftp sftpuser@your_server_ip ``` 2. Navigate to **/var/www/sftpuser_uploads** and upload files. The user should only be able to modify files within this directory. ## Conclusion In this guide, we created an SFTP user and restricted their access to the /var/www directory. We also set permissions to allow them to manage files within a specific subdirectory. This setup ensures the security of the web files while allowing the SFTP user to perform their tasks. You can now easily grant SFTP user access to the /var/www directory on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Resolve dpkg Error [2] in Linux > URL: https://www.atlantic.net/tutorials/how-to-resolve-dpkg-error-2-in-linux/ | Published: 2024-10-14 | Updated: 2024-10-29 | Author: Hitesh Jethva Ubuntu/Debian Linux users may occasionally encounter issues with the dpkg package management system, including the commonly reported **dpkg: error: [2]**. This error typically occurs due to problems with file permissions, incomplete installations, or file system corruption. In this guide, we will explore the root causes of this error and provide step-by-step solutions to resolve it. ## What Is dpkg? **dpkg** is the low-level package manager used in Debian-based Linux distributions, including Ubuntu. It handles installing, configuring, upgrading, and removing software packages. When dpkg runs into issues, package installations and upgrades may fail, potentially leaving the system in an inconsistent state. ## Understanding dpkg Error [2] The **dpkg error [2]** generally indicates a problem related to file access or permissions. It usually comes with an error message that looks like: ```bash dpkg: error processing archive (--install): unable to access file: Input/output error [2] ``` **This error can arise when:** - The system is unable to access or modify necessary files due to file system corruption. - Incorrect permissions on certain directories or files block dpkg from functioning properly. - Temporary issues with file locks or incomplete installations. Now, let’s dive a deep to resolve dpkg error [2]. ## Step 1: Check Disk Health The first step is to ensure there are no underlying disk issues that are causing the error. We can do this by checking the integrity of the file system. 1. Open the terminal and run the following command to check the disk for errors: ```bash fsck -Af -M ``` **Explanation:** - **fsck** is the Linux utility to check and repair the file system. - **-A** runs the check on all file systems listed in /etc/fstab. - **-f** forces a file system check, and -M skips mounted file systems. 2. After the disk check, reboot the system: ```bash reboot ``` This will ensure that any file system corruption is fixed. ## Step 2: Reconfigure dpkg If the error persists, reconfiguring dpkg can help resolve issues caused by incomplete or broken package installations. 1. Use the following command to reconfigure all partially installed packages: ```bash dpkg --configure -a ``` This command checks for packages that are not fully configured and attempts to complete their installation. 2. After running this command, try installing or updating the problematic package again. ## Step 3: Clean Up Package Cache Sometimes, the package cache may be corrupted, causing errors. Cleaning up the cache can help. 1. Remove all partially downloaded and cached packages: ```bash apt-get clean ``` This command clears the local repository of downloaded package files and resolves issues caused by corrupted or incomplete downloads. 2. Update the package lists: ```bash apt-get update ``` 3. Now, try re-installing the package: ```bash apt-get install package_name ``` ## Step 4: Verify Permissions on /var/lib/dpkg The dpkg package manager uses the **/var/lib/dpkg** directory to store its data, including information about installed packages. If the permissions on this directory are incorrect, dpkg may not be able to function properly. 1. Verify that the directory is owned by the root user and has the correct permissions: ```bash ls -ld /var/lib/dpkg ``` The output should look like this: ```bash drwxr-xr-x 7 root root 4096 Oct 19 10:10 /var/lib/dpkg ``` 2. If the ownership or permissions are incorrect, fix them with the following commands: ```bash chown -R root:root /var/lib/dpkg chmod -R 755 /var/lib/dpkg ``` 3. After fixing the permissions, re-run the package installation or update. ## Step 5: Remove Lock Files Lock files in the **/var/lib/dpkg/** or /var/cache/apt/archives/ directories can prevent dpkg from working correctly. You may need to remove these lock files if they were not cleaned up properly. 1. Check for lock files in the relevant directories: ```bash rm /var/lib/dpkg/lock rm /var/lib/apt/lists/lock rm /var/cache/apt/archives/lock ``` 2. After removing the lock files, re-run the dpkg configuration command: ```bash dpkg --configure -a ``` ## Conclusion **dpkg: error [2]** is typically related to file system or permission issues, but it can also stem from package corruption or incomplete installations. In this guide, we’ve outlined multiple ways to resolve the error, including checking disk health, reconfiguring dpkg, cleaning up package caches, and adjusting file permissions. Follow the above guide to resolve dpkg Error [2] if it appears on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Find Lines Containing Specific Words in Linux > URL: https://www.atlantic.net/dedicated-server-hosting/find-lines-containing-specific-words-in-linux/ | Published: 2024-10-15 | Updated: 2024-10-29 | Author: Hitesh Jethva When working with text files or log files in Linux, you often need to search for lines containing specific words or patterns. This is a common task for system administrators, developers, and anyone dealing with large datasets or configurations. Fortunately, Linux provides powerful tools that allow you to search for specific words efficiently. In this article, we’ll explore several methods to find lines containing specific words in Linux using command-line tools like grep, sed, awk, and others. ## Method 1: Using grep to Find Lines Containing Specific Words The **grep** command is the most commonly used tool for searching text in Linux. It is fast, flexible, and allows you to search files or command output for lines containing specific words or patterns. **Basic Syntax of grep:** ```bash grep [options] 'pattern' file ``` **Explanation:** - **pattern:** The word or regular expression you want to search for. - **file:** The file in which you want to search. ### Example 1: Searching for a Specific Word in a File ```bash grep 'error' /var/log/syslog ``` This command will search for all lines containing the word **“error”** in the **/var/log/syslog** file. ### Example 2: Case-Insensitive Search To ignore case while searching, use the **-i** option: ```bash grep -i 'error' /var/log/syslog ``` This will return both **“error”** and **“Error.”** ### Example 3: Search Recursively in Directories If you need to search across multiple files in a directory, use the **-r** option for recursive searching: ```bash grep -r 'error' /var/log/ ``` This command will search for “error” in all files and subdirectories inside **/var/log/.** ### Example 4: Invert Search To find lines that do not contain a specific word, use the **-v** option: ```bash grep -v 'error' /var/log/syslog ``` This will return all lines except those containing **“error.”** ## Method 2: Using awk to Find Specific Words **awk** is a more advanced text-processing tool that allows you to search, filter, and manipulate text. While not as simple as grep, it provides greater flexibility. **Basic Syntax of awk:** ```bash awk '/pattern/ {action}' file ``` **Explanation:** - **/pattern/:** The word or pattern to search for. - **{action}:** The action to perform when a match is found. ### Example 1: Finding Lines Containing a Word ```bash awk '/error/ {print}' /var/log/syslog ``` This command will print all lines containing the word **“error”** in the file **/var/log/syslog.** ### Example 2: Case-Insensitive Search in awk To perform a case-insensitive search, you can convert both the input and search word to lowercase: ```bash awk '{ if(tolower($0) ~ /error/) print }' /var/log/syslog ``` This ensures that both **“error”** and **“Error”** are matched. ## Method 3: Using sed to Find and Display Lines **sed** is a stream editor that can be used for searching, finding, and even modifying text. It is less commonly used for simple searches but offers powerful capabilities. **Basic Syntax of sed:** ```bash sed -n '/pattern/p' file ``` **Explanation:** - **-n:** Suppresses automatic printing of lines. - **/pattern/p:** Prints lines that match the pattern. ### Example 1: Find and Print Lines Containing a Word ```bash sed -n '/error/p' /var/log/syslog ``` This command will print all lines that contain the word **“error.”** ### Example 2: Invert Search Using sed To print all lines not containing the word **“error,”** use: ```bash sed '/error/d' /var/log/syslog ``` This command deletes all lines containing “error” and prints the rest. ## Method 4: Using find with grep for Specific Files If you want to find specific words in files based on file type or other criteria, you can combine the find command with grep. **Example: Searching for a Word in All .log Files** ```bash find /var/log -name "*.log" -exec grep 'error' {} \; ``` This command searches for the word **“error”** in all **.log** files under the **/var/log** directory. ## Conclusion Finding lines containing specific words in Linux can be easily done using powerful command-line tools such as grep, awk, sed, and others. Each tool offers its own set of features, making them suitable for various tasks, from simple text searches to advanced filtering and processing. Discover how to find lines containing specific words in Linux on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Linux xargs Command Guide with Examples > URL: https://www.atlantic.net/dedicated-server-hosting/linux-xargs-command-guide-with-examples/ | Published: 2024-10-16 | Updated: 2024-10-29 | Author: Hitesh Jethva The xargs command in Linux is a handy tool used for building and executing command lines from standard input. It allows you to take the output of one command and pass it as arguments to another command, making it a versatile tool for handling bulk operations efficiently. In this guide, we will explore the various uses of xargs with practical examples. ## What Is xargs? **xargs** takes input from standard input (or the output of another command) and converts it into arguments for another command. It is particularly useful when dealing with commands that cannot handle input piped directly to them. **Syntax of xargs:** ```bash command | xargs [options] [command] ``` **Explanation:** - **command:** The command whose output will be used as input for xargs. - **options:** Various options to control how xargs processes the input. - **command:** The command that xargs will run using the input. ## Example 1: Basic Usage of xargs To understand the basic functionality of xargs, let’s start with a simple example. Suppose you have a list of filenames that you want to delete. Instead of passing each file to rm individually, you can use xargs to pass the list in bulk. ```bash echo file1 file2 file3 | xargs rm ``` **Explanation** - **echo file1 file2 file3**: Prints the filenames to standard output. - **xargs rm:** Takes the filenames as input and runs the rm command on each file. ## Example 2: Handling Multiline Input Often, you will need to handle multiline input. By default, xargs treats input as space-separated, but it can be configured to handle newline-separated input as well. ```bash echo -e "file1\nfile2\nfile3" | xargs rm ``` The **-e** option with echo ensures that newlines are preserved in the input. xargs processes each line separately and passes it as arguments to the rm command, deleting the files. ## Example 3: Using find with xargs A common use case for xargs is with the find command. When you use find to locate files, you may want to pass the list of files to another command, such as **rm** or **cp.** xargs allows you to do this efficiently. ```bash find . -name "*.txt" | xargs rm ``` **Explanation** - **find** **.** **-name “*.txt”:** Finds all .txt files in the current directory and its subdirectories. - **xargs rm:** Deletes each .txt file found by find. ## Example 4: Limiting the Number of Arguments By default, xargs passes as many arguments as possible to the command. However, you can limit the number of arguments passed per execution using the -n option. ```bash find . -name "*.log" | xargs -n 5 rm ``` **Explanation:** - **xargs -n 5 rm**: This limits xargs to passing only 5 arguments (files) to the rm command at a time. If there are more than 5 .log files, xargs will run rm multiple times, each time with up to 5 files. ## Example 5: Using xargs with Interactive Commands Sometimes, you may want to confirm actions before proceeding. The **-p** option in xargs prompts you before running each command. ```bash find . -name "*.tmp" | xargs -p rm ``` **Explanation:** - **xargs -p rm**: For each .tmp file found, xargs will ask for confirmation before deleting it. This is useful when you want to be cautious about deleting files. ## Example 6: Combining xargs with Other Commands You can combine xargs with various commands, such as **mkdir**,**cp**, or **mv**, to perform bulk operations. 1. Creating Multiple Directories ```bash echo "dir1 dir2 dir3" | xargs mkdir ``` In this example, **xargs mkdir** takes the directory names (dir1, dir2, dir3) as input and passes them to mkdir to create multiple directories in one go. 2. Copying Files to Another Directory ```bash echo "file1 file2 file3" | xargs -I {} cp {} /path/to/destination/ ``` **Explanation:** - **-I {}: Defines {}** as a placeholder for each input item. - **cp {} /path/to/destination/**: Copies each file (e.g., file1, file2, file3) to the specified destination directory. ## Example 7: Running Commands in Parallel You can use the **-P** option to run commands in parallel, which can speed up the execution when dealing with a large number of files. ```bash find . -name "*.log" | xargs -P 4 rm ``` **Explanation:** - **xargs -P 4 rm**: Runs up to 4 instances of rm in parallel to delete the .log files. This can significantly improve performance for tasks that involve many files. ## Example 8: Stopping on Errors If you want xargs to stop executing commands when an error occurs, use the **-e** option. ```bash find . -name "*.bak" | xargs -e rm ``` **Explanation:** - **xargs -e rm:** Stops execution if rm returns an error. This is useful when you want to halt further operations if a critical error occurs. ## Conclusion The xargs command is an essential tool for anyone working with Linux, especially when dealing with large datasets or file management tasks. Master the xargs command in Linux with practical examples on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # How to Check Available Free Disk Space on Linux > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-check-available-free-disk-space-on-linux/ | Published: 2024-10-17 | Updated: 2024-10-29 | Author: Hitesh Jethva Managing disk space is crucial for ensuring the optimal performance of a Linux system. Running out of disk space can lead to critical failures, including system crashes and service downtime. Therefore, regularly checking the available free disk space is an essential task for system administrators and users alike. In this guide, we’ll explore various methods to check free disk space on Linux. We’ll cover tools such as df, du, lsblk, ncdu, and others, along with practical examples to help you monitor disk usage effectively. ## Method 1: Using the df Command The **df** (disk free) command is one of the most commonly used tools to check disk space on Linux. It provides a quick overview of the disk usage for all mounted file systems. **Basic Syntax of df:** ```bash df [options] [file] ``` By default, df displays the disk space usage for all mounted file systems. **Example: Display Free Disk Space** ```bash df -h ``` Output: ```bash Filesystem Size Used Avail Use% Mounted on udev 3.9G 0 3.9G 0% /dev tmpfs 798M 11M 787M 2% /run /dev/sda1 50G 20G 28G 42% / tmpfs 3.9G 44K 3.9G 1% /dev/shm tmpfs 5.0M 4.0K 5.0M 1% /run/lock /dev/sdb1 100G 75G 25G 75% /data ``` **Explanation:** - **Size:** Total size of the file system. - **Used:** Amount of space used. - **Avail:** Available free space. - **Use%:** Percentage of space used. - **Mounted on:** The file system’s mount point. ## Method 2: Using du to Check Directory Usage The **du** (disk usage) command shows the space used by files and directories. 1. Check Space Usage of a Specific Directory ```bash du -sh /var/log ``` Output: ```bash 500M /var/log ``` 2. Display Disk Usage of Subdirectories ```bash du -h --max-depth=1 /home ``` Output: ```bash 4.0K /home/lost+found 12G /home/user1 8.0G /home/user2 20G /home ``` This will shows disk usage for each top-level subdirectory inside /home. ## Method 3: Using lsblk for Block Device Information The **lsblk** (list block devices) command provides detailed information about all block devices, including disk space and partitioning. While it does not directly show free space, it is useful for understanding how disks are partitioned. ```bash lsblk ``` This shows the block devices, their sizes, and their mount points. It’s useful for visualizing how storage is allocated across different partitions and disks. ```bash NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT sda 8:0 0 50G 0 disk ├─sda1 8:1 0 50G 0 part / sdb 8:16 0 100G 0 disk └─sdb1 8:17 0 100G 0 part /data ``` ## Method 4: Using df with File Systems Sometimes, you might want to check the available space for specific file systems or partitions. You can do this by specifying the file system as an argument to df. **Example: Check Free Space for /home** ```bash df -h /home ``` Output: ```bash Filesystem Size Used Avail Use% Mounted on /dev/sda1 50G 30G 20G 60% /home ``` This command shows disk usage for the /home directory. ## Method 5: Monitoring Disk Usage in Real-Time For real-time monitoring of disk usage, you can use watch in combination with df to keep an eye on free disk space as it changes. ```bash watch -n 5 df -h ``` **Explanation** - **watch -n 5**: Runs the **df -h** command every 5 seconds and updates the output in the terminal. ## Conclusion Monitoring disk space is a critical task in Linux system administration. By using tools like df, du, and lsblk, you can effectively track disk usage, identify potential issues, and manage space efficiently. Checking available free disk space on Linux is effortless with [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # List All Linux Services Starting at Boot > URL: https://www.atlantic.net/dedicated-server-hosting/list-all-linux-services-starting-at-boot/ | Published: 2024-10-18 | Updated: 2024-10-29 | Author: Hitesh Jethva Linux services play a crucial role in the system’s functionality, and knowing which services start at boot can help in system administration, troubleshooting, and performance optimization. Services that start automatically at boot are usually managed by systemd, the default service manager in most modern Linux distributions. In this guide, we will explore various methods to list all Linux services that are enabled to start at boot. ## Method 1: Using systemctl to List Services at Boot The **systemctl** command is part of the systemd service manager and is the most common way to list services that are enabled to start at boot. ```bash systemctl list-unit-files --type=service --state=enabled ``` Output: ```bash UNIT FILE STATE sshd.service enabled apache2.service enabled cron.service enabled networking.service enabled ``` ## Method 2: Checking the Status of a Specific Service To check whether a specific service is enabled to start at boot, use the systemctl is-enabled command. ```bash systemctl is-enabled sshd ``` Output: ```bash enabled ``` This confirms that the sshd service is enabled to start at boot. If the service is disabled, the output will be: ```bash disabled ``` ## Method 3: Using systemctl list-dependencies for a Deeper View The list-dependencies option in systemctl provides a hierarchical view of dependencies for systemd targets, including the services that start at boot under specific targets like multi-user.target (used for multi-user systems with networking). ```bash systemctl list-dependencies multi-user.target ``` Output: ```bash multi-user.target ● ├─apache2.service ● ├─cron.service ● ├─networking.service ● ├─sshd.service ● └─remote-fs.target ``` This shows that services like apache2, cron, networking, and sshd are dependencies of multi-user.target, meaning they start when the system enters this target (usually during boot). ## Method 4: Listing Services by Boot Target In systemd, services are organized under different targets that define specific system states. For example, multi-user.target is a common target for servers, and graphical.target is used on desktops with a GUI. You can list the services associated with a specific boot target. ```bash systemctl list-dependencies graphical.target ``` Output: ```bash graphical.target ● ├─gdm.service ● ├─cups.service ● ├─NetworkManager.service ● └─multi-user.target ``` ## Method 5: Using chkconfig for Older Linux Systems On older Linux systems that use SysVinit instead of systemd, the chkconfig tool is used to manage and list services that start at boot. ```bash chkconfig --list ``` Output: ```bash sshd 0:off 1:off 2:on 3:on 4:on 5:on 6:off httpd 0:off 1:off 2:on 3:on 4:on 5:on 6:off ``` Note: chkconfig is largely obsolete on modern Linux systems that use systemd, but it’s still useful on older systems. ## Method 6: Viewing All Running Services In addition to listing services that are enabled at boot, you might want to see all services that are currently running. Use the following systemctl command to display active services: ```bash systemctl list-units --type=service --state=running ``` Output: ```bash UNIT LOAD ACTIVE SUB DESCRIPTION cron.service loaded active running Regular background program processing daemon sshd.service loaded active running OpenSSH Daemon apache2.service loaded active running The Apache HTTP Server ``` ## Method 7: Using journalctl to Check Boot Services You can use journalctl to examine the system boot logs and verify which services started during boot. ```bash journalctl -b ``` This command will show detailed logs, including messages about which services started, their status, and any potential errors encountered during boot. ## Conclusion Knowing which services are enabled to start at boot is essential for Linux system administration, helping you manage system resources, optimize performance, and troubleshoot boot issues. With systemctl, you can easily list, enable, or disable services, providing fine-grained control over your system’s behavior at startup. Listing all Linux services starting at boot is straightforward on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Fix “Access Denied” Error Using systemctl as root > URL: https://www.atlantic.net/dedicated-server-hosting/fix-access-denied-error-using-systemctl-as-root/ | Published: 2024-10-19 | Updated: 2024-10-29 | Author: Hitesh Jethva When managing services on a Linux system, the systemctl command is the primary tool for starting, stopping, enabling, and checking the status of services. However, even when executing commands as root, users may sometimes encounter the frustrating **“Access Denied”** error while using systemctl. This error can occur due to various reasons, including permission issues, incorrect configurations, or problems with systemd itself. In this guide, we’ll explore the common causes of the “Access Denied” error when using systemctl and provide practical solutions to resolve it. ## Solution 1: Check Permissions and Use sudo Correctly Even though you’re running commands as root, certain actions may require using sudo in front of the systemctl command, especially if you’ve switched to the root user via su or su -. This is because sudo provides additional security contexts in some cases. **Step 1: Try Using sudo** If you are receiving an **“Access Denied”** error, prepend **sudo** to your command: ```bash sudo systemctl start apache2 ``` **Step 2: Verify Group Permissions** If you are part of an administrative group, such as wheel or adm, ensure that your user has the appropriate privileges to use systemctl. Check your group memberships: ```bash groups ``` If you do not belong to an administrative group, you can add your user to the appropriate group with the following command: ```bash sudo usermod -aG wheel your_username ``` Log out and log back in for the changes to take effect. ## Solution 2: Disable SELinux or AppArmor Temporarily **SELinux** (Security-Enhanced Linux) and AppArmor are security modules that can restrict actions even for the root user. If these are enabled, they may block access to certain system resources. **Step 1: Check SELinux Status** To see if SELinux is enabled, run: ```bash sestatus ``` ## Step 2: Temporarily Disable SELinux If SELinux is causing the issue, you can temporarily disable it by editing the configuration file. Open the SELinux configuration file: ```bash sudo nano /etc/selinux/config ``` Change the SELINUX directive to disabled: ```bash SELINUX=disabled ``` Save the file and reboot the system: ```bash sudo reboot ``` ## Step 3: Check AppArmor Status If your system uses AppArmor instead of SELinux, check its status with: ```bash sudo aa-status ``` To disable AppArmor temporarily, use: ```bash sudo systemctl stop apparmor ``` If disabling SELinux or AppArmor resolves the issue, you may need to fine-tune their security policies to allow access without fully disabling them. ## Solution 3: Check Unit File and Service Permissions The **“Access Denied”** error can also occur if the unit file of the service you’re trying to manage has incorrect permissions or configurations. **Step 1: Inspect the Unit File** Locate the unit file for the service that’s causing the issue (e.g., Apache): ```bash sudo systemctl cat apache2 ``` Check the unit file for any restrictions that could be blocking access. **Step 2: Check Service File Permissions** Verify that the unit file has the correct ownership and permissions: ```bash ls -l /etc/systemd/system/apache2.service ``` Ensure that root has ownership and that the permissions are set correctly. If necessary, fix them with: ```bash sudo chown root:root /etc/systemd/system/apache2.service sudo chmod 644 /etc/systemd/system/apache2.service ``` **Step 3: Reload systemd Configuration** After making any changes, reload the systemd configuration to apply them: ```bash sudo systemctl daemon-reload ``` ## Solution 4: Troubleshooting systemctl Errors with Logs If the above steps don’t resolve the “Access Denied” error, it’s helpful to check the system logs for more information. **Step 1: Check the Journal Logs** The journalctl command provides logs for system services managed by systemd. To view recent logs related to systemctl, run: ```bash sudo journalctl -xe ``` This will display detailed logs that may contain information on why access is being denied. **Step 2: Check Specific Service Logs** If the issue is related to a specific service, you can filter logs by that service. For example, to view logs for the Apache service: ```bash sudo journalctl -u apache2 ``` Review the logs for any permission errors or access denials. ## Conclusion The “Access Denied” error when using systemctl as root can be frustrating, but it is usually caused by permission issues, misconfigured Polkit rules, or restrictions imposed by SELinux or AppArmor. By following the solutions outlined in this guide, you can diagnose and resolve the error, allowing you to manage your Linux services effectively. Fixing the “Access Denied” error using systemctl as root is made easy with [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Linux unlink Command Guide with Examples > URL: https://www.atlantic.net/dedicated-server-hosting/linux-unlink-command-guide-with-examples/ | Published: 2024-10-20 | Updated: 2024-10-29 | Author: Hitesh Jethva The unlink command in Linux is used to delete a single file by removing its directory entry. This operation is quite low-level compared to rm, and it doesn’t prompt for confirmation or provide any output unless an error occurs. In this guide, we’ll explore how the unlink command works, its syntax, and practical examples of its usage. ## Syntax of the unlink Command The basic syntax of the unlink command is: ```bash unlink filename ``` **Where:** - **filename:** The file you want to remove. - The **unlink** command doesn’t support options or arguments other than the file name. ## Example 1: Removing a Single File with unlink To remove a file using the unlink command, you simply provide the file name as an argument. ```bash unlink file.txt ``` This command removes file.txt from the current directory. Once executed, the file is deleted, and no confirmation or output is provided unless there is an error. ## Example 2: Handling Permission Errors If you don’t have the necessary permissions to delete a file, unlink will return a permission denied error. ```bash unlink protected_file.txt ``` Output: ```bash unlink: cannot unlink 'protected_file.txt': Permission denied ``` To resolve this, use sudo to run the command with superuser privileges: ```bash sudo unlink protected_file.txt ``` This will bypass the permission issue and remove the file. ## Example 3: Deleting Symbolic Links with unlink The unlink command can also be used to remove symbolic links. It works the same way as with regular files, but it only removes the link and not the actual file it points to. **Step 1: Create a Symbolic Link** ```bash ln -s original_file.txt symlink.txt ``` **Step 2: Remove the Symbolic Link** ```bash unlink symlink.txt ``` ## Example 4: Handling File Paths with unlink When using unlink, you can specify either relative or absolute paths to remove a file located in another directory. ```bash unlink /home/user/documents/file.txt ``` This command removes the file located at **/home/user/documents/file.txt.** ## Conclusion The unlink command in Linux is a simple yet powerful tool for safely and precisely deleting individual files. While it lacks the advanced features of rm, its single-file focus makes it ideal for use in scripts and tasks where caution is required. Learn how to use the unlink command in Linux with practical examples on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # Resolve “Filename Not Matched” Error When Unzipping an Archive > URL: https://www.atlantic.net/dedicated-server-hosting/resolve-filename-not-matched-error-when-unzipping-an-archive/ | Published: 2024-10-21 | Updated: 2024-10-29 | Author: Hitesh Jethva When working with archives in Linux, you might encounter errors while trying to unzip files. One such common issue is the “Filename not matched” error. This error usually occurs due to mismatches between the file names in the archive and the commands or settings you use when extracting the archive. In this article, we will explore the causes of the “Filename not matched” error when unzipping an archive and provide detailed solutions to resolve it. ## Common Causes of the “Filename Not Matched” Error Before diving into solutions, it’s important to understand why this error occurs. Here are the most common causes: - **Case Sensitivity:** Linux file systems are case-sensitive, meaning “File.txt” and “file.txt” are treated as different files. - **Whitespace in File Names**: File names containing spaces or special characters can cause issues during extraction. - **Special Characters in File Names**: Characters like @, #, $, or & may cause problems if not handled properly. - **Incorrect Path**: The extraction command might not be pointing to the correct path or file within the archive. ## Solution 1: Handle Case Sensitivity Linux is case-sensitive, which means that file names must exactly match their cases. If you encounter a mismatch error while unzipping, check whether the file names are typed correctly. **Step 1: Check File Names Inside the Archive** You can inspect the contents of the archive using the **unzip -l** command. This allows you to see the exact file names, including their case. ```bash unzip -l archive.zip ``` Output: ```bash Archive: archive.zip Length Date Time Name --------- ---------- ----- ---- 12345 2023-10-01 12:34 File.txt 67890 2023-10-01 12:35 folder/Subfile.TXT ``` **Step 2: Match File Names Exactly** Once you’ve listed the files, ensure that your extraction command matches the case of the file names exactly. ```bash unzip archive.zip File.txt ``` ## Solution 2: Handling Whitespace in File Names File names that contain spaces can be tricky when unzipping archives, as the shell may treat them as separate arguments. **Step 1: Use Quotes to Handle Spaces** If a file name contains spaces, enclose the file name in quotes to prevent the shell from splitting it into multiple parts. ```bash unzip archive.zip "file with spaces.txt" ``` Using double quotes around the file name ensures that it’s treated as a single entity, avoiding the “Filename not matched” error. **Step 2: Use Escape Characters** Alternatively, you can use escape characters (\) before each space in the file name. ```bash unzip archive.zip file\ with\ spaces.txt ``` ## Solution 3: Handling Special Characters Special characters like @, #, $, and & in file names can cause the shell to misinterpret them, leading to errors during extraction. **Step 1: Escape Special Characters** To handle special characters in file names, you need to escape them using a backslash (\) or surround the entire file name with quotes. ``` archive.zip file\@name\#.txt ``` This will ensure that the shell doesn’t misinterpret the special characters, and the file can be extracted without errors. ## Solution 4: Ensure Correct Path When Extracting If the file you’re trying to unzip is located in a subdirectory within the archive, make sure to provide the correct path relative to the archive structure. **Step 1: List Archive Contents with Paths** First, use the **unzip -l** command to see the file paths inside the archive. ```bash unzip -l archive.zip ``` Output: ```bash Archive: archive.zip Length Date Time Name --------- ---------- ----- ---- 12345 2023-10-01 12:34 folder/File.txt 67890 2023-10-01 12:35 folder/subfolder/Anotherfile.txt ``` **Step 2: Extract Using Correct Path** If the file is located inside a folder, include the full path when extracting it. ```bash unzip archive.zip folder/File.txt ``` If the file is in a deeper directory: ```bash unzip archive.zip folder/subfolder/Anotherfile.txt ``` ## Solution 5: Use Wildcards for File Names If you’re unsure of the exact name of a file or if there are multiple files with similar names, you can use wildcards to match patterns. **Example: Extract All .txt Files** ```bash unzip archive.zip "*.txt" ``` This command extracts all **.txt** files from the archive, regardless of their names. **Example: Extract Files from a Specific Subdirectory** ```bash unzip archive.zip "folder/*" ``` This extracts all files from the folder directory within the archive. ## Conclusion The “Filename not matched” error when unzipping an archive in Linux is typically caused by issues such as case sensitivity, spaces, special characters, incorrect paths, or an outdated unzip utility. With these solutions, you’ll be able to efficiently unzip files without encountering filename mismatch errors on [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) from Atlantic.Net! --- # CPU Vs GPU: What Is The Difference? > URL: https://www.atlantic.net/gpu-server-hosting/cpu-vs-gpu-what-is-the-difference/ | Published: 2024-10-25 | Updated: 2024-11-02 | Author: Robert Agar Modern computing systems are built to address a wide range of business requirements and personal interests. A computer’s central processing unit (CPU) is responsible for controlling the data flow and carrying out instructions. It is unquestionably the most essential piece among many critical computer components comprising a modern machine. While CPUs are extremely important for complex computing tasks, some applications benefit from running on a more specialized processor. Employing a graphics processing unit (GPU) rather than a general-purpose processor can result in substantially improved performance for certain tasks that can be more efficiently addressed with parallel processing. GPUs have become increasingly important to handle the parallel instruction processing necessary to power artificial intelligence (AI) applications. This article examines the key differences between CPUs and GPUs. One main difference is that a computer can operate with only a CPU, but a GPU needs to be paired with a CPU to function properly. We will investigate how these processors differ physically and the types of problems they are best suited to address. Finally, we will examine typical usage scenarios for both processing units. ## What Is a Central Processing Unit (CPU)? A CPU is the main computer component and is responsible for the majority of processing tasks. It essentially acts as a computer’s brain. The CPU processes instructions from a computer’s memory to perform specific arithmetic, logical, control, and input/output operations. ### CPU components CPUs are constructed using several key components that perform serial instruction processing. - **Control unit:** The control unit (CU) manages the CPU’s operation. It coordinates the activities of the other CPU components as it executes instructions to perform tasks required by the operating system or applications. The CU decodes instructions to determine CPU activity, generates signals to other components like the ALU, manages data flow, and ensures the operations of all parts of the CPU are synchronized. - **Arithmetic logic unit:** The ALU is a primary CPU component responsible for multiple tasks essential to a computer system’s operation based on signals sent from the CPU’s control unit. A CPU’s arithmetic logic units perform basic arithmetic functions like addition and multiplication. It also performs logical operations such as AND, NOT, or XOR for decision-making and comparisons. The performance of a CPU can be substantially affected by the speed and efficiency of arithmetic logic units. - **Cores:** A CPU core is a processing unit within a CPU that independently executes instructions. CPU cores enable the processor to perform multiple tasks simultaneously. CPUs can have multiple cores, with more cores typically resulting in improved multithreading capability. Cores share resources like buses and cache memory, which can impact their performance. Modern CPU architecture enables cores to adjust performance dynamically based on workload requirements. - **Cache memory:** The CPU cache memory is dedicated storage for frequently accessed data. This high-speed, built-in memory can substantially increase processing speed by reducing the need to load data from other locations. There can be multiple caches of varying sizes to handle data overflow. While a larger cache can hold more data, it may result in slower operations than a smaller, optimized cache. - **Registers:** CPU registers are small and fast storage locations inside the CPU. They are critical to the CPU’s operation and store instructions and temporary data. Registers are directly accessible by the CPU, making them much faster than the main memory. A register is usually no larger than 64 bits, limiting the amount of data it can hold. A CPU can have several types of registers including general-purpose registers used for various purposes and specialized registers such as the program counter that holds the address of the next instruction. - **Buses:** A bus provides a high-speed, internal connection that transfers information between the CPU and other computing resources. Buses can be serial, transferring data one bit at a time, or parallel, capable of transmitting multiple bits simultaneously. Different types of buses are used as the CPU performs various tasks. For example, data buses carry data between the CPU and other components while an address bus transmits the memory location of data elements. Bus width and speed can impact the CPU’s performance. - **Clock:** The CPU clock, also known as the system clock, continuously generates pulses to synchronize the operation of the CPU and other computer components. Clock speed is measured in hertz (Hz) and indicates how many cycles a CPU can execute per second. For example, a clock speed of 2 GHz generates two billion cycles per second. The clock provides timing control and synchronization for all internal components. Modern CPUs can dynamically adjust clock speed to reduce power consumption and minimize heat generation. ### CPU characteristics and functionality The main function of a central processing unit is to perform logical operations and instructions received from the computer’s memory. The ability to perform these operations and process data efficiently is a function of the combined capabilities of its components. CPUs are designed to perform serial processing. They execute elements in the instruction cycle one at a time. A CPU’s components determine its serial computing capabilities. The clock speed provides a benchmark for the amount of processing the chip can handle. A higher clock speed generally indicates a faster-performing computer. Cache memory must be tuned to balance the volume of data it can hold and the latency in accessing that information. The number of cores is another factor in determining the power of a CPU. Additional cores allow the CPU to perform multithreading to perform calculations and other tasks more efficiently. A multi-core CPU with a high clock speed usually furnishes the best performance. ### CPU Architectures Multiple CPU architectures have been developed to address computational requirements. They can generally be categorized as either a Complex Instruction Set Computer (CISC) or a Reduced Instruction Set Computer based on the number of machine instructions it contains. The following are some popular CPU architectures found in modern computers. - 32-bit x86 – This architecture is commonly found in laptop and desktop computers and processes data in 32-bit chunks per clock cycle. It is a CISC architecture first released by Intel in 1978. - 64-bit x86 – This more modern CPU processes data 64 bits at a time and can address more memory than 32-bit processors. Intel and AMD use the architecture which is a popular solution for home computers and servers - ARM64 – This RISC architecture can process more instructions per second than Intel processors. They are energy-efficient, making them a good choice for sustainable computing initiatives. - PowerPC – This RISC architecture is based on IBM’s POWER architecture.  Memory access is separated from computational instructions by a register-to-register design. ### Types of CPUs CPUs are manufactured with specific characteristics and form factors to address various computing tasks. #### Desktop CPUs Desktop CPUs are available in multiple models offering different performance levels suitable for various tasks. The Intel Core Series and AMD’s Ryzen line are desktop CPUs used in many popular desktop machines. #### Mobile CPUs Mobile devices like laptops need to balance performance and power consumption. The Intel Core Mobile and AMD Ryzen Mobile processors are popular mobile CPUs providing good performance while supporting energy efficiency. #### Embedded CPUs Embedded CPUs are specialized microprocessors designed to perform specific tasks in embedded systems. These dedicated devices typically provide limited and specialized functionality compared with a general-use computer system. Features of embedded CPUs include durability, low power consumption, and real-time operation. Embedded CPUs often integrate multiple components on a single chip to reduce their size and energy requirements. #### Server CPUs Server CPUs need additional power and functionality to handle multiple tasks supporting business applications. A server CPU may offer more cores and error-correcting code memory support. Examples of server CPUs include the Intel Xeon and AMD EPYC lines of processors. #### Low-power CPUs Devices with energy constraints like equipment used for IoT (Internet of Things) implementations require specialized, low-power CPUs. Examples of these energy-efficient CPUs include ARM-based processors and Intel’s Atom designed for compact devices. #### Gaming CPUs Gaming platforms may employ specialized CPUs optimized for the high performance required by video and computer games. These CPUs provide higher clock speeds and can perform overclocking when necessary to facilitate a smoother gaming experience. #### High-performance CPUs Supercomputers and machines running processor-intensive tasks benefit from specialized high-performance CPUs. This type of CPU focuses on supporting high-performance computing with multithreading and typically has multiple cores. ## What is a Graphics Processing Unit (GPU)? A graphics processing unit is a specialized processor designed to render images and perform complex mathematical calculations. GPUs typically work in conjunction with a CPU. Some architectures place the CPU and GPU on the same chip. The terms GPU and graphics card are sometimes incorrectly used interchangeably. The GPU is the processor inside a graphics card. ### GPU Cores GPU cores are the processor’s foundational processing unit. Cores share similar characteristics that support the GPU’s functionality. - GPU cores handle multiple tasks simultaneously, supporting the parallel processing necessary to display graphical data efficiently. Each core can manage numerous threads to streamline concurrent operations. - GPU cores are constructed differently than CPU cores, enabling many cores to be deployed to address parallel workloads and advanced scientific research. In some cases, a high-performance GPU may have thousands of cores. - Cores are optimized to increase the processor’s performance with the floating-point calculations important for tasks like displaying images or teaching machine learning models. They share resources such as cache memory for efficiency. ### GPU components GPUs utilize several key components to perform concurrent calculations and parallel computing capabilities. - **Streaming multiprocessors and cores:** These processors represent the GPU’s basic processing units used to execute multiple threads. NVIDIA GPUs employ CUDA cores and AMD GPUs use stream processors for this component. More cores enable the GPU to handle parallel computing tasks more efficiently. - **Memory:** Video RAM (VRAM) is specialized memory the GPU utilizes for computer graphics as it provides faster data transfer than system memory. The GPU also has cache memory to improve processing speed by storing frequently accessed data. - **Framebuffer:** This component stores the GPUs finished image before it is displayed. Before reaching the framebuffer, a rasterizer converts vector graphics into pixel-based graphics, and textures are applied to 3D models. - **Cooling systems and power management circuits:** GPUs can get very hot. Managing power consumption and effectively cooling the processor are critical factors in maintaining high performance. ### GPU characteristics and functionality GPUs demonstrate characteristics and functionality that differentiate them from CPUs. The following are some areas where a GPU can outperform a CPU. #### Computer graphics GPUs were originally developed primarily for rendering graphics to support video games and other visual computerized activities. GPUs are integral to the manufacture of high-performing gaming platforms. They are also critical for displaying complex information graphically to make it more easily understood. #### Parallel processing GPUs are essential for parallel processing applications that handle large volumes of data. The many cores in a GPU can quickly perform repetitive calculations to address the computing needs of financial simulations and other processor-intensive tasks. #### Throughput and dedicated memory Thousands of cores and dedicated memory enable GPUs to perform multiple operations simultaneously and more quickly than CPUs accessing system RAM. Better performance across a range of graphics and processor-intensive applications is possible by leveraging the power of GPUs. #### Compatibility GPUs are compatible with graphics APIs like DirectX or frameworks such as CUDA for parallel processing. This compatibility lets developers benefit from specific GPU capabilities when designing new products. ### Types of GPUs Graphics processing units are available in multiple styles for specific usage scenarios. - **Dedicated GPUs:** A dedicated or discrete GPU is typically a standalone graphics card or video card used for high-performance tasks. - **Integrated GPUs:** This type of GPU is built on a single chip with the CPU to share resources such as system memory and reduce energy consumption. - **Hybrid GPUs:** Hybrid GPUs can switch between dedicated and integrated capabilities to provide enhanced performance or conserve energy based on application requirements. ## CPU Vs GPU for Specific Usage Scenarios The types of tasks and applications running on a given computer must be considered when choosing between a CPU and GPU. Many tasks will run efficiently with a CPU that provides enough speed, cores, and memory. In other cases, users will greatly benefit from the features and performance of a GPU. The chart below indicates how CPUs and GPUs address some specific usage scenarios. This information may help you select the appropriate platform for your application. | **Usage scenario** | **CPU** | **GPU** | | --- | --- | --- | | **Video editing and rendering** | Performs tasks like encoding and applying effects. | Accelerates rendering and real-time playback for faster performance. | | **Animation and 3D modeling** | Manages the software environment and some calculations | Reduces rendering time for enhanced real-time visualization and faster modeling iterations. | | **Artificial intelligence and machine learning** | Effective for sequential processing and training models on small datasets. | Enhanced capabilities for training deep learning models on larger volumes of data. | | **Gaming** | Manages game logic and artificial intelligence capabilities. | Renders graphics for smooth game playing. | | **Simulations and scientific computing** | Good for tasks such as numerical simulations involving complex and conditional logic. | Facilitates physical simulations and scientific applications that can be parallelized. | | **General computing tasks** | Handles the majority of processing tasks. | Accelerates web content and video display. | ## Atlantic Net Servers Feature Modern CPUs and GPUs Atlantic Net offers customers modern [CPU](https://www.atlantic.net/dedicated-server-hosting/) and [GPU server hosting](https://www.atlantic.net/gpu-server-hosting/) solutions designed to address your unique business objectives and requirements. Our servers can support virtually any application with an appropriate choice of processor and other components. [Talk to us today](https://www.atlantic.net/about-us/corporate-contact/) and learn how we can help your business grow with the right CPU or GPU. --- # What Is the Difference Between Machine Learning and Deep Learning? > URL: https://www.atlantic.net/gpu-server-hosting/what-is-the-difference-between-machine-learning-and-deep-learning/ | Published: 2024-10-26 | Updated: 2025-02-07 | Author: Robert Agar Machine learning and deep learning are distinct disciplines of artificial intelligence (AI). The two technologies share many characteristics as they leverage computing power to simulate and augment human intelligence. Key differences in these AI solutions make them appropriate for addressing different classes of tasks and automated processes. Machine learning (ML) is a broad category that relies on dedicated algorithms and statistical models to automate specific processes without explicit instructions and with less reliance on human intervention. Deep learning (DL) is a subset of machine learning using neural networks to learn or draw insights from large amounts of data. Essentially, all deep learning is machine learning, but all machine learning is not deep learning. This article discusses the differences between machine learning and deep learning. We will look at the underlying technologies used to provide ML and DL applications with their intelligence and how they are trained to address specific problems. We’ll also investigate how these technologies are responsible for major changes in how businesses and the general public interact with computing systems. ## **What Is Machine Learning?** Machine learning is a discipline of artificial intelligence that concentrates on developing applications and computer systems that can perform complex tasks they have not been explicitly programmed to accomplish. ML systems learn from exposure to training data that they use to make informed decisions or predictions. The system’s accuracy increases as the learning process progresses and additional data is ingested into an ML model. ML systems enable computers to perform tasks that require human intelligence without explicit programming. The systems employ techniques like linear regression and decision trees for classification and clustering activities. ML models are more effective when working with small datasets. The data used by ML models may need to undergo manual preprocessing by domain experts. ### **Key Components of Machine Learning** Several key components work together to form the foundation of machine learning systems. Each contributes equally to the accuracy and utility of the resulting system or application. #### Data Data is a required raw material for ML systems. Both structured data such as tables or unstructured data can be used as ML inputs. Unstructured data may include images, audio, or text to train a model to identify objects. Large amounts of data are typically used to train an ML system. #### Algorithms Multiple mathematical models, or algorithms, facilitate the learning necessary to provide functionality to an ML application. The algorithms are trained to identify patterns and relationships in the data. Historical data is processed to perform classification, make predictions, aggregate data points, and generate original content. We’ll look more closely at the various types of ML algorithms later in this article. #### Training An ML model learns by being trained using the previously described data and algorithms. The model is repeatedly fed training data utilizing its algorithms. Accuracy is improved by adjusting the model’s parameters based on its responses to the training data. #### Evaluation and Tuning After training and testing the ML model, its performance is evaluated using new data. The objective is to determine if the model meets expectations or needs further training before deployment. ### Machine Learning Algorithms Different types of machine learning algorithms are used to train ML systems. These algorithms typically fall into one of the following four categories. #### Supervised Learning Algorithms Supervised learning algorithms teach a model by example. An operator presents the machine learning algorithm with a test dataset including desired inputs and outputs. The algorithm attempts to produce those inputs and outputs by recognizing patterns in the data and making observations and predictions. The operator makes necessary corrections until the algorithm attains the desired level of accuracy. Supervised learning includes a model to address the following types of tasks. - **Classification** – The ML algorithm evaluates observed values and assigns new elements to an existing category. An example is an email filtering system distinguishing between spam and legitimate correspondence. - **Regression** – Regression tasks require the ML algorithm to understand the relationship between a single dependent variable and multiple changing variables. Regression is useful for forecasting and making predictions. - **Forecasting** – These tasks involve making predictions regarding the future based on past and present data. Forecasting is often used to analyze trends to influence business decisions. #### Semi-Supervised Learning Semi-supervised learning is similar to supervised learning with one exception. Training employs labeled data with meaningful tags and unlabeled data without this descriptive information. The goal is to enable the model to label unlabeled data. #### Unsupervised Learning Algorithms Unsupervised learning involves an ML algorithm analyzing data to identify relationships and correlations without intervention by a human operator. The algorithm interprets large data sets and organizes the information to describe its logical structure. The algorithm improves its decision-making ability as the volume of assessed data increases. Applications of unsupervised learning include: - **Clustering** – Segments data into groups based on defined criteria through analysis. - **Dimension reduction** – The number of variables under consideration is reduced to focus on the desired outcomes. #### Reinforcement Learning Algorithms In reinforcement learning, the algorithm is given a set of actions, parameters, and outcomes. The model defines rules and explores alternate options to identify the best action to address the problem. The algorithm is taught by trial and error, leveraging past experiences to adapt its responses to achieve optimal results. ### Applications of Machine Learning Machine learning systems are found in multiple usage scenarios across many diverse fields. - **Natural language processing (NLP)** – ML systems can be trained to converse with humans using natural language. Intelligent chatbots can provide automated customer service or translation services. They can be instrumental in providing information about an organization’s products and services. - **Speech recognition** – Machine learning is the technology responsible for the speech recognition intelligent virtual assistants employ to respond to verbal queries. ML systems can also create written transcripts from human speech. - **Robotics** – Robotics is an essential component of industrial automation. ML systems enable industrial robots to perform complex tasks that previously required human intelligence. Robots are used to staff assembly lines and engage in activities such as picking stock items for shipping. Delivery drones are another emerging use of ML-powered robotics. - **Healthcare** – Healthcare professionals utilize ML models trained to make recommendations regarding diagnosis and treatment options to enhance and streamline patient care. Another application in the healthcare field is the development of systems that can identify potential diseases or abnormalities from medical imaging. - **Autonomous vehicles** – Machine learning systems are powering the development of autonomous vehicles such as self-driving cars. These systems require substantial computing power to address the constantly evolving conditions faced when operating a vehicle. - **Recommendation systems** – Many ecommerce and entertainment sites utilize recommendation systems to create a more personalized user experience. Recommendations are made based on a user’s past interactions with the system that allow an ML model to learn about their preferences. ## What Is Deep Learning? Deep learning is a subset of machine learning that employs many-layered (deep) neural networks to learn from large and complex volumes of data. DL systems leverage complex architectures such as convolutional and recurrent neural networks. Deep learning techniques strive to replicate the operation of the human brain. Deep learning models automatically extract features from raw data to minimize the need for manual preprocessing. They can learn from their own errors and refine their performance over time. Large data sets are essential for developing accurate deep learning solutions. Deep learning algorithms can handle unstructured data more effectively than ML solutions that perform better with structured data. ### Deep Learning Key Characteristics Deep learning systems and applications typically share several key characteristics that differentiate them from machine learning models. - Artificial neural networks form the foundation of DL solutions. An artificial neural network is made of multiple interconnected layers of nodes. Data is transformed into more abstract representations as it traverses the layers. - The depth of a deep learning application refers to the number of layers in the network. Most DL models have three or more layers consisting of an input layer, an output layer, and multiple hidden layers. Additional layers enable the system to learn more complex features. - Deep learning automatically extracts features from unstructured data without the need for preprocessing or feature engineering. A DL model can successfully process large datasets comprised of text, images, and audio elements. More data typically results in improved model performance. - DL systems need substantial computational power to process the large amounts of data they require. The artificial neural networks use backpropagation to improve the model over time by adjusting the network’s connection weights based on output errors. ### Types of Neural Networks Employed in Deep Learning Different types of neural networks are used to develop deep learning solutions. The following three kinds of neural networks are essential components of deep learning technology. #### Feedforward Neural Networks A feedforward neural network is a simple network in which data moves in one direction from the model’s input layer to its output layer. Data never moves backward to be reanalyzed by the model. Data is fed to the model to train it to make predictions about other data sets. For example, feedforward neural networks are trained to detect fraud and are used in the banking industry. #### Convolutional Neural Networks (CNN) Convolutional neural networks are designed to replicate the visual capabilities of the human brain to process images. These networks are excellent at identifying animal or plant species from photographs. They can also be used to diagnose diseases from medical scans or identify specific items from social media feeds. #### Recurrent Neural Networks Recurrent neural networks employ complex connections that include loops. Data can move forward and loop back to be reanalyzed by previous layers. Each input is fed into the model to be analyzed alone and combined with prior input. Recurrent neural networks can predict sentiments and the ending of a sequence such as a speech. ### Applications of Deep Learning Algorithms and Systems Deep learning has applications in many areas of society and the business world. - **Natural language processing** – Deep learning models are powering advanced NLP solutions such as OpenAI’s GPT products. Systems can analyze customer sentiment in response to an organization’s products or services to facilitate personalized marketing. Deep learning solutions furnish enhanced functionality in comparison to ML-powered NLP applications. - **Computer vision** – Deep learning models are used to provide applications with computer vision capabilities. This functionality can be leveraged to perform activities ranging from image classification and object detection to facial recognition. These capabilities are essential in many fields such as security, surveillance, and advanced automation as seen in autonomous vehicles. - **Predictive analytics** – Deep learning methods analyze vast amounts of historical data from which they can make accurate predictions. This capacity can be used to enhance decision-making, streamline manufacturing operations, and forecast customer trends. - **Smart cities** – Deep learning solutions have many applications in creating smart cities that provide society with improved living conditions. Examples are surveillance data used to identify dangerous incidents and traffic management to minimize congestion in crowded metropolitan areas. - **Financial services** – DL is being used by financial services companies to detect and prevent fraud. Organizations are also employing deep learning models to predict and analyze market trends and execute trades quickly to address evolving conditions. ### **Advantages and Challenges of Deep Learning** Deep learning technology offers multiple advantages and presents several challenges that must be effectively addressed. #### Benefits - Automated feature extraction enhances productivity by minimizing manual feature engineering. - Deep learning systems are flexible and versatile due to their ability to process all types of unstructured data. - Systems exhibit high accuracy when operating with complex data. #### Challenges - Training deep learning solutions requires large datasets. This can pose difficulties and hinder the use of DL in some applications. - Deep learning applications consume substantial computational resources that can present financial constraints. Specialized hardware such as a graphics processing unit (GPU) may need to be used to support deep learning solutions. - Transparency may be an issue with deep learning systems that appear to be black boxes to a typical user. ## Deep Learning vs. Machine Learning The following chart illustrates the main differences when comparing deep learning vs. machine learning. | **Characteristic** | **Deep Learning** | **Machine Learning** | | --- | --- | --- | | **Dataset size** | Works best with large volumes of data | Best suited for use with smaller datasets | | **Data type** | Unstructured data | Structured data | | **Training methods** | Self-learning utilizing neural networks | Supervised and unsupervised learning using specialized machine learning algorithms | | **Human training requirements** | Minimal | Extensive | | **Training time** | Longer than ML solutions | Faster than DL solutions | | **Hardware requirements** | Requires the power of a GPU | Advanced central processing units (CPUs) | [Atlantic.Net](https://www.atlantic.net/) offers customers a cloud-based [GPU server hosting](https://www.atlantic.net/gpu-server-hosting/) platform to power your machine learning and deep learning applications. We feature two configurations to meet your business needs. Choose the **NVIDIA L40S****GPU** for general artificial intelligence tasks, machine learning and deep learning. The more powerful **NVIDIA H100 NVL =**furnishes higher memory bandwidth for advanced AI and deep learning. --- # Using Zilliz with Jupyter Notebooks on Ubuntu > URL: https://www.atlantic.net/dedicated-server-hosting/using-zilliz-with-jupyter-notebooks-on-ubuntu/ | Published: 2024-10-27 | Updated: 2024-10-29 | Author: Richard Bailey ## Prerequisites - **Ubuntu 22.04:** I will be using Ubuntu 22.04 throughout this demo. You can install your Ubuntu server in under 30 seconds from the [Atlantic.Net Cloud Platform Console](https://cloud.atlantic.net/). - **Basic Python Knowledge:** Familiarity with Python and virtual environments is helpful. - **Zilliz Account**– You will need a Zilliz Account. They offer a free tier. ## Part 1 – Create a Zilliz Free Account & Create Zilliz Cluster While you can’t install the Zilliz Cloud service directly onto an Atlantic.Net Cloud Server, you can use your server to connect to and interact with Zilliz Cloud. Here’s how you can set things up: ### Step 1 – Connect to Zilliz Cloud Create a Zilliz Cloud Account: - Sign up for an account on Zilliz Cloud ([zilliz.com/cloud](https://zilliz.com/cloud)). ![](https://www.atlantic.net/wp-content/uploads/2024/10/image11.png) - Use the Sign-Up pages to create an account as per the below image. You can also use your existing GitHub or Google accounts for added simplicity. ![](https://www.atlantic.net/wp-content/uploads/2024/10/image9.png) ![](https://www.atlantic.net/wp-content/uploads/2024/10/image12.png) ![](https://www.atlantic.net/wp-content/uploads/2024/10/image6.png) ### Step 2 – Create Zilliz Cluster We can now create a Zillz cluster in the GUI. - From the Get Started Page on Zilliz, click on New Cluster. ![](https://www.atlantic.net/wp-content/uploads/2024/10/image5.png) - Select the Free Tier. This will only give you the option to deploy Zilliz in GCP. - Check the details and hit Create. ![](https://www.atlantic.net/wp-content/uploads/2024/10/image7.png) - Wait for the Cluster to build and move on to part 2. You may want to make a note of your endpoint ID and API key at this point. You can view these later, so it’s not a disaster if you forget. ![](https://www.atlantic.net/wp-content/uploads/2024/10/image10.png) ![](https://www.atlantic.net/wp-content/uploads/2024/10/image8.png) ## Part 2 – Install Python & Jupyter Notebooks There are several ways you can use Zilliz, but you must use it with an SDK. This procedure will follow the steps to use Python, but please be aware that Zilliz supports Java and NodeJS if that is your preferred SDK. ### Step 1 – Install Python Jupyter Lab requires Python. You can install it using the following commands: ``` apt update -y apt install python3 python3-pip -y ``` Note: You may be prompted to restart services after installation. Just click . Next, install the Python virtual environment package. ``` pip install -U virtualenv ``` ### Step 2 – Install Jupyter Lab Now, install Jupyter Lab using the pip command. ``` pip3 install jupyterlab ``` This command installs Jupyter Lab and its dependencies. Next, edit the .bashrc file. ``` nano ~/.bashrc ``` Define your Jupyter Lab path as shown below; simply add it to the bottom of the file: ``` export PATH=$PATH:~/.local/bin/ ``` Reload the changes using the following command. ``` source ~/.bashrc ``` Next, test run the Jupyter Lab locally using the following command to make sure everything starts. ``` jupyter lab --allow-root --ip=0.0.0.0 --no-browser ``` Check the output to make sure there are no errors. Upon success you will see the following output. ``` [C 2023-12-05 15:09:31.378 ServerApp] To access the server, open this file in a browser: http://ubuntu:8888/lab?token=aa67d76764b56c5558d876e56709be27446 http://127.0.0.1:8888/lab?token=aa67d76764b56c5558d876e56709be27446 ``` Press the CTRL+C to stop the server. ### Step 3 – Configure Jupyter Lab By default, Jupyter Lab doesn’t require a password to access the web interface. To secure Jupyter Lab, generate the Jupyter Lab configuration using the following command. ``` jupyter-lab --generate-config ``` Output. ``` Writing default config to: /root/.jupyter/jupyter_lab_config.py ``` Next, set the Jupyter Lab password. ``` jupyter-lab password ``` Set your password as shown below: ``` Enter password: Verify password: [JupyterPasswordApp] Wrote hashed password to /root/.jupyter/jupyter_server_config.json ``` You can verify your hashed password using the following command. ``` cat /root/.jupyter/jupyter_server_config.json ``` Output. ``` { "IdentityProvider": { "hashed_password": "argon2:$argon2id$v=19$m=10240,t=10,p=8$zf0ZE2UkNLJK39l8dfdgHA$0qIAAnKiX1EgzFBbo4yp8TgX/G5GrEsV29yjHVUDHiQ" } } ``` Note this information, as you will need to add it to your config. Next, edit the Jupyter Lab configuration file. ``` nano /root/.jupyter/jupyter_lab_config.py ``` Define your server IP, hashed password, and other configurations as shown below: ``` c.ServerApp.ip = 'your-server-ip' c.ServerApp.open_browser = False c.ServerApp.password = 'argon2:$argon2id$v=19$m=10240,t=10,p=8$zf0ZE2UkNLJK39l8dfdgHA$0qIAAnKiX1EgzFBbo4yp8TgX/G5GrEsV29yjHVUDHiQ' c.ServerApp.port = 8888 ``` Make sure you format the file exactly as above. For example, the port number is not in brackets, and the False boolean must have a capital F. Save and close the file when you are done. ### Step 4 – Create a Systemctl Service File Next, create a systemd service file to manage Jupyter Lab. ``` nano /etc/systemd/system/jupyter-lab.service ``` Add the following configuration: ``` [Service] Type=simple PIDFile=/run/jupyter.pid WorkingDirectory=/root/ ExecStart=/usr/local/bin/jupyter lab --config=/root/.jupyter/jupyter_lab_config.py --allow-root User=root Group=root Restart=always RestartSec=10 [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon. ``` systemctl daemon-reload ``` Next, start the Jupyter Lab service using the following command. ``` systemctl start jupyter-lab ``` You can now check the status of the Jupyter Lab service using the following command. ``` systemctl status jupyter-lab ``` Jupyter Lab is now started and listening on port 8888. You can verify it with the following command. ``` ss -antpl | grep jupyter ``` Output. LISTEN 0      128    104.219.55.40:8888      0.0.0.0:*  users:((“jupyter-lab”,pid=156299,fd=6)) ### Step 5 – Access Jupyter Lab Now, open your web browser and access the Jupyter Lab web interface using the URL **http://your-server-ip:8888.** You will see Jupyter Lab on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/10/image2.png) Provide the password you set during the installation and click on Log in. You will see the Jupyter Lab dashboard on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2024/10/image4.png) ### Step 6 – Start the Python3 Notebook You can now start the Python 3 Notebook and move on to Part 3. ## Part 3 – Install and Configure Zilliz Cluster Now go back to your VPS terminal. We will install Zilliz and configure the cluster. ### Step 1  – Install Pymilvus - Install PyMilvus compatible with Milvus v2.4.x ``` python -m pip install pymilvus==2.4.4 ``` - Upgrade PyMilvus to the newest version. ``` python -m pip install --upgrade pymilvus ``` - Verify installation success. ``` python -m pip list | grep pymilvus ``` ### Step 2 – Connect to Cluster Now let’s connect to the cluster. Go back to your Jupyter notebook and execute the following code. Make sure you update the following parameters: CLUSTER_ENDPOINT=”YOUR_CLUSTER_ENDPOINT” # Set your cluster endpoint TOKEN=”YOUR_CLUSTER_TOKEN” # Set your token ``` # Connect using a MilvusClient object from pymilvus import MilvusClient CLUSTER_ENDPOINT="YOUR_CLUSTER_ENDPOINT" # Set your cluster endpoint TOKEN="YOUR_CLUSTER_TOKEN" # Set your token ``` ### Step 3 – Initialize the Zilliz Cluster - Now initialize the cluster. ``` # Initialize a MilvusClient instance # Replace uri and token with your own client = MilvusClient( uri=CLUSTER_ENDPOINT, # Cluster endpoint obtained from the console token=TOKEN # API key or a colon-separated cluster username and password ) ``` ![](https://www.atlantic.net/wp-content/uploads/2024/10/image3.png) ### Step 4 – Create a Collection Let’s create a collection. In Zilliz Cloud, a collection is like a table in a traditional database, but it’s specifically designed to store and manage vector data along with its associated metadata. ``` client.create_collection( collection_name="quick_setup", dimension=5 # The dimensionality should be an integer greater than 1. ) ``` ![](https://www.atlantic.net/wp-content/uploads/2024/10/image1.png) ### Step 5 – Insert Some Data Now let’s populate the Vector DB with some dummy data for testing. Note: The[official Zilliz documentation provides this data](https://docs.zilliz.com/docs/quick-start). - Run the following in your Jupyter notebook: ``` # 4. Insert data into the collection # 4.1. Prepare data data=[ {"id": 0, "vector": [0.3580376395471989, -0.6023495712049978, 0.18414012509913835, -0.26286205330961354, 0.9029438446296592], "color": "pink_8682"}, {"id": 1, "vector": [0.19886812562848388, 0.06023560599112088, 0.6976963061752597, 0.2614474506242501, 0.838729485096104], "color": "red_7025"}, {"id": 2, "vector": [0.43742130801983836, -0.5597502546264526, 0.6457887650909682, 0.7894058910881185, 0.20785793220625592], "color": "orange_6781"}, {"id": 3, "vector": [0.3172005263489739, 0.9719044792798428, -0.36981146090600725, -0.4860894583077995, 0.95791889146345], "color": "pink_9298"}, {"id": 4, "vector": [0.4452349528804562, -0.8757026943054742, 0.8220779437047674, 0.46406290649483184, 0.30337481143159106], "color": "red_4794"}, {"id": 5, "vector": [0.985825131989184, -0.8144651566660419, 0.6299267002202009, 0.1206906911183383, -0.1446277761879955], "color": "yellow_4222"}, {"id": 6, "vector": [0.8371977790571115, -0.015764369584852833, -0.31062937026679327, -0.562666951622192, -0.8984947637863987], "color": "red_9392"}, {"id": 7, "vector": [-0.33445148015177995, -0.2567135004164067, 0.8987539745369246, 0.9402995886420709, 0.5378064918413052], "color": "grey_8510"}, {"id": 8, "vector": [0.39524717779832685, 0.4000257286739164, -0.5890507376891594, -0.8650502298996872, -0.6140360785406336], "color": "white_9381"}, {"id": 9, "vector": [0.5718280481994695, 0.24070317428066512, -0.3737913482606834, -0.06726932177492717, -0.6980531615588608], "color": "purple_4976"} ]# 4.2. Insert data res = client.insert( collection_name="quick_setup", data=data ) print(res) # Output # # { #     "insert_count": 10, #     "ids": [0, 1, 2, 3, 4, 5, 6, 7, 8, 9] # } ``` - Let’s insert more data. ``` import time # 5. Insert more data into the collection # 5.1. Prepare data colors = ["green", "blue", "yellow", "red", "black", "white", "purple", "pink", "orange", "brown", "grey"] data = [ { "id": i, "vector": [ random.uniform(-1, 1) for _ in range(5) ], "color": f"{random.choice(colors)}_{str(random.randint(1000, 9999))}" } for i in range(1000) ] # 5.2. Insert data res = client.insert( collection_name="quick_setup", data=data[10:] ) print(res) # Output # # { #     "insert_count": 990 # } # Wait for a while time.sleep(5) ``` ### Step 6 – Perform a Vector Search Now let’s query the data using a vector search. #### Single Vector Search ``` # 6.1. Prepare query vectors query_vectors = [ [0.041732933, 0.013779674, -0.027564144, -0.013061441, 0.009748648] ]# 6.2. Start search res = client.search( collection_name="quick_setup",     # target collection data=query_vectors,                # query vectors limit=3,                           # number of returned entities ) print(res) ``` You should see output like this: ``` # Output # # [ #     [ #         { #             "id": 551, #             "distance": 0.08821295201778412, #             "entity": {} #         }, #         { #             "id": 296, #             "distance": 0.0800950899720192, #             "entity": {} #         }, #         { #             "id": 43, #             "distance": 0.07794742286205292, #             "entity": {} #         } #     ] # ] ``` #### Bulk-Vector Search ``` # 7. Search with multiple vectors # 7.1. Prepare query vectors query_vectors = [ [0.041732933, 0.013779674, -0.027564144, -0.013061441, 0.009748648], [0.0039737443, 0.003020432, -0.0006188639, 0.03913546, -0.00089768134] ]# 7.2. Start search res = client.search( collection_name="quick_setup", data=query_vectors, limit=3, ) print(res) ``` You should see output like this: ``` # Output # # [ #     [ #         { #             "id": 551, #             "distance": 0.08821295201778412, #             "entity": {} #         }, #         { #             "id": 296, #             "distance": 0.0800950899720192, #             "entity": {} #         }, #         { #             "id": 43, #             "distance": 0.07794742286205292, #             "entity": {} #         } #     ], #     [ #         { #             "id": 730, #             "distance": 0.04431751370429993, #             "entity": {} #         }, #         { #             "id": 333, #             "distance": 0.04231833666563034, #             "entity": {} #         }, #         { #             "id": 232, #             "distance": 0.04221535101532936, #             "entity": {} #         } #     ] # ] ``` That’s it! You are now ready to start using Zilliz Vector Databases with your Atlantic.Net hosted cloud server. Remember, you don’t have to use Python, Zilliz natively supports Java and NodeJS if that’s your preference. --- # VMware vs. Nutanix: Which Is Preferred in HIPAA Compliant Environments? > URL: https://www.atlantic.net/hipaa-compliant-hosting/vmware-vs-nutanix-which-is-preferred-in-hipaa-compliant-environments/ | Published: 2024-10-28 | Updated: 2025-02-07 | Author: Gilad Maayan ## What Is VMware? VMware is a provider of virtualization solutions. It offers software that allows multiple virtual machines to run on a single physical machine. This technology enables organizations to maximize resource efficiency and reduce operational costs. VMware’s flagship product, VMware vSphere, provides platform virtualization and cloud computing services. It is widely used across various industries to enhance infrastructure scalability and flexibility. Founded in 1998, VMware has been a pioneer in virtualization technology. The company’s software has revolutionized the IT landscape by facilitating server consolidation and improving disaster recovery solutions. With a portfolio that includes network virtualization, storage virtualization, and desktop virtualization, VMware continues to evolve, offering solutions that cater to modern data center challenges and cloud computing needs. ## What Is Nutanix? Nutanix is an enterprise cloud computing company. It provides hyper-converged infrastructure solutions that unify computing, storage, and networking resources into a single integrated system. Nutanix’s platform simplifies data center management by eliminating the need for separate storage, computing, and virtualization resources. This results in enhanced operational efficiency and reduced infrastructure complexity. Founded in 2009, Nutanix aims to bring the simplicity of public cloud infrastructure to enterprise data centers. Its flagship product, the Nutanix Enterprise Cloud Platform, offers a range of services that facilitate application deployment and scalability. Nutanix has been at the forefront of driving innovation in hyper-converged infrastructure. See this blog post for a detailed comparison of [VMware vs. Nutanix](https://faddom.com/vmware-vs-nutanix/). ## Overview of HIPAA Compliance Requirements The Health Insurance Portability and Accountability Act (HIPAA) establishes national standards to protect sensitive patient health information from being disclosed without the patient’s consent or knowledge. HIPAA compliance is essential for healthcare organizations, vendors, and any entity that handles protected health information (PHI). The key requirements for HIPAA compliance fall into several categories: 1. **Privacy rule**: This rule governs how PHI can be used and disclosed. It limits the sharing of patient data and ensures that individuals have rights to access their health information. Entities must implement safeguards to protect PHI from unauthorized access or misuse. 2. **Security rule**: The Security Rule focuses on protecting electronic PHI (ePHI). It requires covered entities to adopt administrative, physical, and technical safeguards. These include controlling access to ePHI, encrypting sensitive data, and ensuring secure communication channels. 3. **Breach notification rule**: In the event of a data breach involving PHI, entities must notify affected individuals, the Department of Health and Human Services (HHS), and, in some cases, the media. 4. **Enforcement rule**: This rule sets out the penalties for non-compliance. Organizations can face substantial fines depending on the severity of the violation, whether it was due to negligence, and the steps taken to correct the issue. 5. **Business associate agreements (BAAs)**: HIPAA requires that any third-party vendors with access to PHI sign a BAA, ensuring that they too follow HIPAA regulations. This extends HIPAA’s security requirements to partners and service providers. ## VMware’s Approach to HIPAA Compliance VMware addresses HIPAA compliance primarily through its Carbon Black Cloud and Workspace ONE Unified Endpoint Management (UEM) solutions. These platforms have undergone third-party assessment by Coalfire, an independent security organization, to ensure they meet the technical requirements of the [HIPAA Security Rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/), which governs the protection of electronic Protected Health Information (e-PHI). The Carbon Black Cloud and Workspace ONE platforms offer healthcare organizations a security framework that adheres to HIPAA’s core principles: confidentiality, integrity, and availability of patient data. Coalfire’s evaluation included testing of the platforms in areas such as malware detection and response, endpoint management, and the implementation of administrative and technical safeguards. By integrating these solutions, VMware helps healthcare providers safeguard their e-PHI through several key features: 1. **Endpoint security**: Carbon Black Cloud’s ability to detect and block malware ensures that workstations and devices handling e-PHI are protected against unauthorized access. 2. **Device management**: Workspace ONE provides centralized control over devices, ensuring that only authorized personnel can access sensitive data. It also supports secure communication channels. 3. **Compliance monitoring**: VMware’s platforms assist in meeting HIPAA’s administrative and technical safeguards, such as access controls and data encryption. ## Nutanix’s Approach to HIPAA Compliance Nutanix helps healthcare organizations address HIPAA compliance through its enterprise cloud platform, which integrates security, data protection, and simplified infrastructure management. By consolidating workloads like electronic health records (EHR), picture archiving and communication systems (PACS), and virtual desktop infrastructure (VDI) on a unified platform, Nutanix ensures that protected health information (PHI) is securely managed. Key features of Nutanix’s platform that support HIPAA compliance include: - **Data security**: Nutanix enhances patient data security by automating compliance with regulatory standards such as HIPAA, GDPR, and HITECH. - **Scalable EHR deployments**: Healthcare organizations can easily scale their EHR systems as needed, supporting compliance by keeping data accessible yet secure during expansions or upgrades. - **Protected data access**: The platform provides secure access to clinical applications and protected data from any device or location, supporting remote and on-site healthcare workers. - **Business continuity**: Nutanix’s self-healing architecture and VM-centric data protection keep critical healthcare applications and patient data available, reducing downtime. ## VMware vs. Nutanix: Which Is Preferred in HIPAA Compliant Environments? When evaluating VMware and Nutanix for HIPAA-compliant environments, the choice largely depends on an organization’s specific needs, infrastructure complexity, and priorities in terms of scalability, security, and operational efficiency. Both platforms offer solutions that help healthcare organizations maintain compliance with HIPAA’s data protection requirements. ### Security and Compliance Features VMware’s approach to HIPAA compliance centers on its Carbon Black Cloud and Workspace ONE platforms, which provide endpoint security and unified device management. These solutions offer safeguards for electronic [Protected Health Information](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) (ePHI), focusing on malware protection, access control, and encryption. VMware’s long history in virtualization and cloud computing makes it a trusted option for healthcare environments requiring adherence to HIPAA’s technical safeguards. Nutanix, on the other hand, emphasizes simplicity and performance in its hyper-converged infrastructure (HCI), combining compute, storage, and networking into a single platform. Nutanix’s security features—such as built-in encryption, automated compliance auditing, and VM-centric data protection—simplify HIPAA compliance by streamlining the management of sensitive data. Its ability to scale easily also allows healthcare providers to expand or adjust their infrastructure without compromising data security. ### Infrastructure Management VMware’s strengths lie in its ability to integrate into existing enterprise infrastructure, offering granular control and management over virtualized environments. This can be particularly beneficial for organizations with complex IT environments, where managing large-scale virtualization alongside security and compliance is crucial. Nutanix is often preferred for its simplicity and ease of management. Its hyper-converged infrastructure consolidates workloads like electronic health records (EHR) and other healthcare applications into a unified system, reducing the need for separate virtualization and storage solutions. This integrated approach minimizes operational complexity and enhances scalability. ### Performance and Scalability Both VMware and Nutanix offer scalable solutions. VMware’s vSphere is well-known for its reliability in managing large-scale data centers, making it suitable for organizations with extensive infrastructure needs. Nutanix, with its modular architecture, allows healthcare providers to scale workloads effortlessly, offering flexibility for organizations with fluctuating or growing demand. ### Which Is Preferred? In HIPAA-compliant environments, the decision between VMware and Nutanix often comes down to the organization’s size, IT complexity, and specific compliance needs. For larger healthcare systems with established virtualized environments and a need for detailed control over security, VMware may be the better choice. However, for organizations seeking a simplified, scalable solution with a focus on reducing infrastructure complexity, Nutanix may be more appealing. Both platforms provide the necessary tools to support HIPAA compliance, so the best choice will depend on the specific requirements of the healthcare provider. ## Conclusion Both VMware and Nutanix offer solutions to meet the demands of HIPAA compliance in healthcare environments. VMware’s focus on security features like endpoint protection and device management, alongside its mature virtualization platform, makes it a strong contender for organizations with complex IT infrastructures. Meanwhile, Nutanix’s hyper-converged infrastructure offers simplicity, scalability, and integrated security features that appeal to healthcare providers seeking to streamline operations without compromising on compliance. Ultimately, the decision between VMware and Nutanix should be driven by the specific needs of the organization, including the complexity of its infrastructure, its growth plans, and the level of control required over security and compliance. Both platforms are well-equipped to support HIPAA-compliant environments, ensuring the protection of sensitive patient data while enhancing operational efficiency. --- # API Security in a HIPAA Compliant Environment > URL: https://www.atlantic.net/hipaa-compliant-hosting/api-security-in-a-hipaa-compliant-environment/ | Published: 2024-10-29 | Author: Gilad Maayan ## What Is API Security? API security is the practice of protecting application programming interfaces (APIs) from cyber threats. APIs serve as the backbone for many web applications and services, and ensuring their security is vital. They allow applications to communicate with each other and exchange data, which makes them susceptible to unauthorized access, data theft, and manipulation. Cybersecurity measures for APIs aim to safeguard against these vulnerabilities through authentication, encryption, and continuous monitoring. API security is particularly crucial in industries like healthcare, where APIs handle sensitive data such as personal health information. Ensuring secure communication between APIs prevents data breaches. Implementing [API security measures](https://www.pynt.io/learning-hub/api-security-guide/api-security) involves understanding potential threats, deploying technologies like OAuth and TLS, and adhering to regulatory requirements such as HIPAA in the healthcare sector. ## Common API Security Threats in Healthcare ### Unauthorized Access Unauthorized access in healthcare APIs refers to the ability of malicious actors to access systems or data without permission. This threat arises when APIs are not properly secured, allowing hackers to exploit vulnerabilities and gain entry to sensitive data. Often, this is due to weak authentication mechanisms or improper API key management. To combat unauthorized access, healthcare organizations must implement strong authentication protocols and employ least privilege access. Regular audits of access logs can detect unusual activities, and API gateways can restrict access to only authorized users. By doing so, healthcare providers can ensure that patient information remains confidential and secure. ### Man-in-the-Middle Attacks Man-in-the-middle (MITM) attacks occur when an attacker intercepts the communication between two systems. In healthcare, this can lead to the compromise of sensitive patient data transmitted through APIs. Typically, MITM attacks exploit unsecured connections, allowing attackers to eavesdrop and modify data. To protect against MITM attacks, healthcare APIs should use transport layer security (TLS) to encrypt data in transit. Implementing digital certificates and mutual TLS can further authenticate parties involved in communication. These measures help ensure that data remains confidential and unaltered during transmission. ### Injection Attacks Injection attacks occur when an attacker sends malicious code to an API, which then executes the code within an application. This threat is significant in healthcare when APIs process user inputs without proper validation, leading to data leaks and system compromises. Preventing injection attacks requires input validation and sanitization of user data before processing. Employing prepared statements and parameterized queries can significantly reduce this risk. Regular code reviews and employing web application firewalls (WAFs) can also detect and block suspicious activities, thereby ensuring API resilience. ### Data Leakage and Loss Data leakage and loss involve unauthorized exposure or removal of sensitive data from an API. In healthcare, such breaches can have severe implications, compromising patient privacy and incurring legal penalties. Often, they result from misconfigured APIs or inadequate access controls. Ensuring proper API configuration and implementing data protection policies can mitigate this risk. Encrypting data at rest and during transmission, regular security audits, and continuous monitoring can help detect and prevent unauthorized data access. Protecting against data leakage is crucial for maintaining the integrity and confidentiality of patient information. ## What Is HIPAA? HIPAA, or the Health Insurance Portability and Accountability Act, is a U.S. law designed to protect sensitive patient health information from being disclosed without consent. It mandates standards for safeguarding medical data, impacting how healthcare providers, insurers, and other entities handle patient information. HIPAA requires the implementation of secure electronic access and ensures the confidentiality and integrity of health data. The law encompasses a set of rules and regulations, including the Privacy Rule, Security Rule, and Breach Notification Rule. Each addresses different aspects of data protection and privacy. The Security Rule, in particular, outlines administrative, physical, and technical safeguards required to secure electronic protected health information (ePHI). Compliance with HIPAA is critical for avoiding significant financial penalties. ## HIPAA-Specific API Security Requirements ### Access Control Access control is a foundational requirement for HIPAA compliance, ensuring only authorized personnel have access to patient data. This involves implementing user authentication mechanisms such as usernames, passwords, and two-factor authentication to verify identity. Proper access control mitigates risks of unauthorized access and ensures data integrity. Role-based access control (RBAC) further enhances security by providing permissions based on user roles. This approach minimizes risks by limiting data access to what’s necessary for a specific role. Regular audits and reviews of access permissions help identify and address potential breaches promptly, assisting in maintaining compliance with HIPAA regulations. ### Encryption for Data at Rest and in Transit HIPAA requires encryption to safeguard ePHI, both at rest and in transit. Encryption ensures that data remains unintelligible to unauthorized users. For data at rest, it involves securing databases and storage systems. At transit, it involves using protocols like TLS for secure data communication. Encrypting APIs that handle ePHI prevents unauthorized access or data leaks during data transmission or in storage. This measure is crucial for protecting patient data against interception and breaches, thereby helping healthcare organizations meet HIPAA standards. ### API Logging and Monitoring API logging and monitoring involve recording API activities to detect and respond to suspicious activities swiftly. Under HIPAA, tracking access logs and maintaining audit trails are crucial for ensuring accountability and detecting unauthorized activities. Effective logging captures relevant data such as user IDs, timestamps, and access points. Continuous monitoring helps in real-time identification of anomalies or security breaches. Implementing automated alert systems can ensure immediate response to incident detection. Together, logging and monitoring strengthen the security posture of healthcare APIs, aid in compliance, and protect sensitive patient information. ### Ensuring Data Integrity During API Communication Data integrity ensures that information remains accurate and unaltered during API communications. In healthcare, maintaining the integrity of patient data is vital for [compliance with HIPAA regulations](https://www.atlantic.net/hipaa-compliant-hosting/what-is-hipaa-compliance-history-rules-and-requirements/). Integrity can be compromised through tampering or corruption, necessitating security measures. Implementing cryptographic hash functions and message authentication codes (MACs) can detect unauthorized changes in data. Regular integrity checks and data validation processes are crucial for maintaining accurate and reliable health information, ensuring that healthcare providers comply with HIPAA. ## API Security Best Practices for HIPAA Compliance ### OAuth 2.0 and OpenID Connect for Securing API Access OAuth 2.0 and OpenID Connect offer frameworks for secure API access by enabling third-party applications to access APIs on behalf of a user. OAuth 2.0 enables secure, token-based access, minimizing the risk of exposing user credentials. OpenID Connect adds an identity layer to OAuth 2.0, providing user authentication. Both protocols help healthcare organizations implement secure single sign-on (SSO) solutions, facilitating streamlined access management. These frameworks also allow healthcare APIs to handle user identity in a secure, compliant manner, essential for protecting sensitive health information and maintaining HIPAA compliance. ### Rate Limiting and Throttling Rate limiting and throttling manage the number of API requests a user can make within a certain timeframe. These practices prevent abuse and ensure fair resource allocation. In healthcare, applying rate limits protects APIs from denial-of-service (DoS) attacks while ensuring legitimate access. Throttling adjusts the speed at which user requests are processed, maintaining API performance. Healthcare providers can implement these measures to protect APIs from being overwhelmed by excessive requests. Through careful configuration, they enhance API stability and comply with [HIPAA requirements](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). ### Limiting API Responses to Necessary Fields Limiting API responses to necessary fields involves configuring APIs to only return data essential for a given request. This reduces the risk of exposing sensitive information inadvertently. In healthcare, defining strict data policies ensures that APIs only share relevant patient information, aligning with HIPAA regulations. Implementing techniques like ‘selective fields’ in API calls can filter out unnecessary data. Regular reviews of API structures and response outputs help maintain minimal data exposure, helping protect patient privacy and secure sensitive health information. ### Use of API Gateways for Centralized Management of Security Policies API gateways serve as a single entry point for enforcing security policies across APIs. They provide centralized security logging, access control, and traffic management. In healthcare, using API gateways ensures consistent application of security measures, critical for complying with HIPAA. Gateways can also enable threat detection and policy enforcement, reducing the risk of unauthorized access. They streamline monitoring and can integrate with security tools for enhanced protection. This centralized approach helps healthcare providers efficiently manage security and maintain regulatory compliance. ### Automated Threat Detection Automated threat detection leverages machine learning and AI to identify suspicious activities in real-time. These systems monitor API traffic patterns to detect anomalies, often a sign of potential security threats. In healthcare, automation aids in swift threat identification and response, protecting sensitive data. Integrating automated threat detection into API security frameworks enhances responsiveness. Healthcare organizations can use this technology to identify breaches early, mitigate risks, and adhere to HIPAA requirements. Continuous improvements in detection algorithms ensure adaptive security over time. ## Conclusion API security is crucial for protecting sensitive healthcare data, ensuring compliance with regulations like HIPAA, and maintaining the integrity of healthcare systems. By understanding common security threats, such as unauthorized access and injection attacks, healthcare organizations can implement targeted measures to mitigate risks. Technologies like encryption, OAuth 2.0, and API gateways provide layers of protection, while best practices such as rate limiting and limiting API responses ensure APIs handle data securely. An API security strategy involves continuous monitoring, automated threat detection, and regular security assessments to stay ahead of evolving cyber threats. Ultimately, safeguarding healthcare APIs is not just about regulatory compliance—it’s about protecting patient privacy and fostering trust in healthcare systems. --- # Document Download > URL: https://www.atlantic.net/press-room-signup/ | Updated: 2026-09-16 Please choose a file to download from our [Press Room](https://www.atlantic.net/press-room/) --- # Cloud Hosting by Atlantic.Net > URL: https://www.atlantic.net/cloud-platform/cloud-hosting/ | Updated: 2026-09-16 Deploy Linux, Windows, or FreeBSD Cloud Servers in under 30 seconds with flexible CPU, RAM, and storage, RAID-10-backed redundancy, API and control panel access, and 24/7/365 US-based support. - Pay-As-You-Go Pricing - Linux, Windows & FreeBSD - RAID-10 Redundant Storage - RESTful API & Control Panel US-Based Support: 24/7/365 Cloud Server Deployment: Under 30 sec ## Cloud Hosting Overview Atlantic.Net Cloud Hosting provides scalable cloud servers with predictable pricing, enterprise-grade security, and global infrastructure. Organizations can deploy Linux or Windows cloud instances in seconds with flexible CPU, RAM, and storage configurations. The platform supports high-performance workloads, regulatory compliance environments (HIPAA, PCI), and rapid scaling for SaaS, AI, and high-traffic applications. - Deploy cloud servers in under 30 seconds - Flexible compute, RAM, and storage scaling - Secure infrastructure with compliance-ready architecture - Pay-as-you-go or reserved instance pricing - 24/7 expert support ## Cloud Hosting Services Cloud Hosting backed by our world-class cloud infrastructure gives you the freedom to choose the plans that best fit your needs. Our cloud servers are designed to provide the best performance and maximum flexibility to businesses and developers. Our simple all-inclusive pricing, easy-to-use cloud interface, and always-available phone support are some of the reasons why organizations of all sizes in over a hundred countries choose Atlantic.Net. Our network spans across the USA and includes Canada, the United Kingdom, and Singapore. ## On-Demand Cloud Plans Pay-as-you-go pricing based on compute, storage, and bandwidth usage. | | | | | | | | | | --- | --- | --- | --- | --- | --- | --- | --- | | General Purpose | G3.2GB | 2GB | 1 | 50GB | 3 TB | On-Demand: $10.0/mo $0.0149/hr; 1-Year: $9.0/mo $0.0134/hr; 3-Year: $8.0/mo $0.0119/hr | On-Demand: $16.5/mo $0.0246/hr; 1-Year: $15.5/mo $0.0231/hr; 3-Year: $15.5/mo $0.0231/hr | | General Purpose | G3.4GB | 4GB | 2 | 80GB | 5 TB | On-Demand: $20.0/mo $0.0298/hr; 1-Year: $18.0/mo $0.0268/hr; 3-Year: $17.0/mo $0.0253/hr | On-Demand: $33.0/mo $0.0491/hr; 1-Year: $31.0/mo $0.0461/hr; 3-Year: $30.0/mo $0.0446/hr | | General Purpose | G3.8GB | 8GB | 4 | 160GB | 6 TB | On-Demand: $40.0/mo $0.0595/hr; 1-Year: $37.0/mo $0.0551/hr; 3-Year: $34.0/mo $0.0506/hr | On-Demand: $66.0/mo $0.0982/hr; 1-Year: $63.0/mo $0.0938/hr; 3-Year: $59.5/mo $0.0885/hr | | General Purpose | G3.16GB | 16GB | 6 | 320GB | 7 TB | On-Demand: $80.0/mo $0.119/hr; 1-Year: $74.0/mo $0.1101/hr; 3-Year: $68.0/mo $0.1012/hr | On-Demand: $132.5/mo $0.1972/hr; 1-Year: $125.5/mo $0.1868/hr; 3-Year: $119.5/mo $0.1778/hr | | General Purpose | G3.32GB | 32GB | 8 | 640GB | 8 TB | On-Demand: $160.0/mo $0.2381/hr; 1-Year: $147.0/mo $0.2188/hr; 3-Year: $136.0/mo $0.2024/hr | On-Demand: $265.0/mo $0.3943/hr; 1-Year: $250.5/mo $0.3728/hr; 3-Year: $238.0/mo $0.3542/hr | | General Purpose | G3.48GB | 48GB | 12 | 960GB | 9 TB | On-Demand: $240.0/mo $0.3571/hr; 1-Year: $220.0/mo $0.3274/hr; 3-Year: $204.0/mo $0.3036/hr | On-Demand: $397.5/mo $0.5915/hr; 1-Year: $375.5/mo $0.5588/hr; 3-Year: $358.5/mo $0.5335/hr | | General Purpose | G3.64GB | 64GB | 16 | 1280GB | 10 TB | On-Demand: $320.0/mo $0.4762/hr; 1-Year: $294.0/mo $0.4375/hr; 3-Year: $272.0/mo $0.4048/hr | On-Demand: $529.5/mo $0.7879/hr; 1-Year: $500.5/mo $0.7448/hr; 3-Year: $477.0/mo $0.7098/hr | | General Purpose | G3.96GB | 96GB | 20 | 1920GB | 11 TB | On-Demand: $480.0/mo $0.7143/hr; 1-Year: $441.6/mo $0.6571/hr; 3-Year: $408.0/mo $0.6071/hr | On-Demand: $795.5/mo $1.1838/hr; 1-Year: $754.5/mo $1.1228/hr; 3-Year: $718.5/mo $1.0692/hr | | General Purpose | G3.128GB | 128GB | 24 | 2560GB | 12 TB | On-Demand: $640.0/mo $0.9524/hr; 1-Year: $589.0/mo $0.8765/hr; 3-Year: $544.0/mo $0.8095/hr | On-Demand: $1,059.0/mo $1.5759/hr; 1-Year: $1,003.0/mo $1.4926/hr; 3-Year: $953.0/mo $1.4182/hr | | General Purpose | G3.192GB | 192GB | 32 | 3840GB | 13 TB | On-Demand: $960.0/mo $1.4286/hr; 1-Year: $883.2/mo $1.3143/hr; 3-Year: $816.0/mo $1.2143/hr | On-Demand: $1,588.5/mo $2.3638/hr; 1-Year: $1,506.5/mo $2.2418/hr; 3-Year: $1,435.5/mo $2.1362/hr | | Compute Optimized | C2.8GB | 8GB | 4 | 40GB | 10 TB | On-Demand: $211.0/mo $0.314/hr; 1-Year: $137.0/mo $0.2039/hr; 3-Year: $67.0/mo $0.0997/hr | On-Demand: $254.5/mo $0.3787/hr; 1-Year: $173.0/mo $0.2574/hr; 3-Year: $96.0/mo $0.1429/hr | | Compute Optimized | C2.16GB | 16GB | 8 | 80GB | 10 TB | On-Demand: $418.0/mo $0.622/hr; 1-Year: $271.0/mo $0.4033/hr; 3-Year: $133.0/mo $0.1979/hr | On-Demand: $505.5/mo $0.7522/hr; 1-Year: $343.0/mo $0.5104/hr; 3-Year: $190.5/mo $0.2835/hr | | Compute Optimized | C2.32GB | 32GB | 16 | 160GB | 10 TB | On-Demand: $828.0/mo $1.2321/hr; 1-Year: $538.0/mo $0.8006/hr; 3-Year: $263.0/mo $0.3914/hr | On-Demand: $1,002.0/mo $1.4911/hr; 1-Year: $682.0/mo $1.0149/hr; 3-Year: $378.0/mo $0.5625/hr | | Compute Optimized | C2.64GB | 64GB | 20 | 350GB | 10 TB | On-Demand: $1,451.0/mo $2.1592/hr; 1-Year: $943.0/mo $1.4033/hr; 3-Year: $461.0/mo $0.686/hr | On-Demand: $1,777.5/mo $2.6451/hr; 1-Year: $1,216.5/mo $1.8103/hr; 3-Year: $685.0/mo $1.0194/hr | | Storage Optimized | S2.16GB | 16GB | 2 | 500GB | 10 TB | On-Demand: $248.0/mo $0.369/hr; 1-Year: $161.0/mo $0.2396/hr; 3-Year: $105.0/mo $0.1563/hr | On-Demand: $317.5/mo $0.4725/hr; 1-Year: $221.5/mo $0.3296/hr; 3-Year: $160.0/mo $0.2381/hr | | Storage Optimized | S2.32GB | 32GB | 4 | 1TB | 10 TB | On-Demand: $425.0/mo $0.6324/hr; 1-Year: $276.0/mo $0.4107/hr; 3-Year: $180.0/mo $0.2679/hr | On-Demand: $557.0/mo $0.8289/hr; 1-Year: $392.5/mo $0.5841/hr; 3-Year: $286.5/mo $0.4263/hr | | Storage Optimized | S2.64GB | 64GB | 8 | 2TB | 10 TB | On-Demand: $778.0/mo $1.1577/hr; 1-Year: $506.0/mo $0.753/hr; 3-Year: $330.0/mo $0.4911/hr | On-Demand: $1,035.0/mo $1.5402/hr; 1-Year: $734.5/mo $1.093/hr; 3-Year: $540.5/mo $0.8043/hr | | Storage Optimized | S2.96GB | 96GB | 12 | 3TB | 10 TB | On-Demand: $1,097.0/mo $1.6324/hr; 1-Year: $713.0/mo $1.061/hr; 3-Year: $465.0/mo $0.692/hr | On-Demand: $1,475.0/mo $2.1949/hr; 1-Year: $1,051.5/mo $1.5647/hr; 3-Year: $777.5/mo $1.157/hr | | Storage Optimized | S2.128GB | 128GB | 16 | 4TB | 10 TB | On-Demand: $1,414.0/mo $2.1042/hr; 1-Year: $919.0/mo $1.3676/hr; 3-Year: $599.0/mo $0.8914/hr | On-Demand: $1,913.0/mo $2.8467/hr; 1-Year: $1,367.0/mo $2.0342/hr; 3-Year: $1,013.5/mo $1.5082/hr | | Memory Optimized | M2.16GB | 16GB | 2 | 40GB | 10 TB | On-Demand: $163.0/mo $0.2426/hr; 1-Year: $106.0/mo $0.1577/hr; 3-Year: $52.0/mo $0.0774/hr | On-Demand: $223.5/mo $0.3326/hr; 1-Year: $161.0/mo $0.2396/hr; 3-Year: $101.5/mo $0.151/hr | | Memory Optimized | M2.32GB | 32GB | 4 | 80GB | 10 TB | On-Demand: $318.0/mo $0.4732/hr; 1-Year: $207.0/mo $0.308/hr; 3-Year: $101.0/mo $0.1503/hr | On-Demand: $439.0/mo $0.6533/hr; 1-Year: $316.5/mo $0.471/hr; 3-Year: $200.0/mo $0.2976/hr | | Memory Optimized | M2.64GB | 64GB | 8 | 160GB | 10 TB | On-Demand: $630.0/mo $0.9375/hr; 1-Year: $409.0/mo $0.6086/hr; 3-Year: $200.0/mo $0.2976/hr | On-Demand: $871.5/mo $1.2969/hr; 1-Year: $627.5/mo $0.9338/hr; 3-Year: $397.5/mo $0.5915/hr | | Memory Optimized | M2.128GB | 128GB | 16 | 350GB | 10 TB | On-Demand: $1,246.0/mo $1.8542/hr; 1-Year: $810.0/mo $1.2054/hr; 3-Year: $396.0/mo $0.5893/hr | On-Demand: $1,727.5/mo $2.5707/hr; 1-Year: $1,246.5/mo $1.8549/hr; 3-Year: $790.0/mo $1.1756/hr | *All plans are available in every location for Managed Server clients. *The hourly rate is determined by dividing the monthly rate by 672 hours (28 days). If your server is online for more than 672 hours in a calendar month, you will only be billed the monthly rate. *Prices listed above are based on the service being utilized for the period specified. *All Servers include one IPv4 Address. Additional IPs are available for $3.65/month ($0.005431/hour) *Unlimited inbound bandwidth. If free outbound bandwidth is exceeded, each additional GB is $0.02 *Optional Daily Backups are available for 20% of the server price. Minimum $1.00/month. *cPanel licensing cost starts at $23 per month ## What is Cloud Hosting? Cloud hosting is an infrastructure model where applications and websites run on virtualized servers distributed across multiple physical machines. This architecture allows organizations to scale resources dynamically, improve reliability through redundancy, and deploy services faster than traditional single-server hosting environments. ## Shared Hosting vs. Cloud Hosting vs. Dedicated Hosting ### Shared hosting Shared hosting allows multiple websites to share one server, making it affordable but limited in performance. ### Cloud hosting Cloud hosting runs applications on a distributed infrastructure of virtual servers, providing scalability and high availability. ### Dedicated hosting Dedicated hosting assigns an entire physical server to one customer, delivering maximum performance, security, and control. ## Cloud Hosting vs Shared Hosting vs Dedicated Hosting: Infrastructure Comparison | Hosting Feature | Shared Hosting | Cloud Hosting | Dedicated Hosting | | --- | --- | --- | --- | | What is it? | A hosting environment where many websites share the same server resources including CPU, RAM, and storage. | A hosting infrastructure where applications run on virtual servers backed by a distributed cloud platform. | A hosting solution where one physical server is allocated entirely to a single customer. | | Resource allocation | Resources such as CPU and memory are shared among multiple users on one server. | Resources are virtualized and distributed across multiple servers in a cloud cluster. | All hardware resources of the server are dedicated to one customer. | | Performance | Performance may vary depending on how much traffic other websites on the server generate. | High performance with the ability to dynamically allocate additional resources. | Consistently high performance because no other users share the server hardware. | | Scalability | Limited scalability because resources are fixed. | Highly scalable infrastructure allowing resources to scale up or down on demand. | Scaling typically requires upgrading or migrating to more powerful hardware. | | Reliability | Moderate reliability; issues affecting the server can impact all hosted websites. | Very high reliability because workloads can shift between multiple cloud nodes. | High reliability but dependent on the availability of a single physical server. | | Security isolation | Lower isolation since multiple customers share the same system environment. | Improved isolation through virtualization and network segmentation. | Maximum isolation because the entire server belongs to one organization. | | Customization and control | Limited control over server configuration and installed software. | Moderate to high control depending on the cloud platform configuration. | Full root or administrative access with complete hardware and software control. | | Traffic handling | Best suited for low-traffic websites and small projects. | Handles variable or unpredictable traffic spikes effectively. | Ideal for consistently high-traffic applications and resource-intensive workloads. | | Cost structure | Lowest cost hosting option. | Pay-as-you-go pricing based on compute, storage, and bandwidth usage. | Higher cost due to exclusive hardware resources. | | Best use cases | Personal websites, small blogs, and startup sites with limited traffic. | Growing websites, SaaS platforms, scalable applications, and development environments. | Enterprise applications, high-performance workloads, large databases, and compliance-sensitive systems. | ## Cloud Hosting Use Cases ### SaaS Platforms ### High-Traffic Websites ### AI / Machine Learning ### Healthcare Platforms ### Fintech Applications ### DevOps Environments ## Atlantic.Net Cloud Server Hosting Features Atlantic.Net offers Windows, Linux, and FreeBSD Cloud Virtual Servers combining the most advanced innovations and technology - all backed by redundant SSD storage for peace of mind. Experience a faster cloud computing environment optimized for performance, scalability, affordability, and reliability. ### A Cloud Support Team Backed by Decades of Experience Signing up as a Cloud Hosting member with us means you'll have 24/7 access to a crop of dedicated cloud computing veterans capable of solving any technical problem you throw their way. ### Blazing Fast SSDs All of our Cloud Servers are powered by enterprise-grade solid state drives (SSDs), providing blazing fast performance for your cloud servers and applications. ### Highly Available Cloud Infrastructure Our highly available infrastructure stands ready to accommodate cloud hosting projects of any scale and size. Backed by 100% up-time guarantee, our cloud hosting servers give you the ultimate peace of mind. ### Scale Up Servers Anytime Hosting in the Atlantic.Net Cloud means you have the capacity to provision additional hosting resources whenever you require them. ### Optional Daily Backup We'll automatically back up everything stored on your cloud server once per day for a cost. ### Flexibility We believe in allowing our members freedom and flexibility with monthly cloud hosting pricing and discounted pricing with term commitments. ### RAID-10 Storage Our highly redundant architecture ensures that your cloud servers and apps stay up and running even if there is an issue with any component. ### Additional IP Address All Cloud Servers include one IPv4 address and 16 IPv6 addresses. ### Guaranteed CPU Cycles We not only guarantee access to the CPU cycles you are paying for when you need them, but you can also burst to use additional CPU cycles in the cloud when they are not in use. ### Optional cPanel & WHM The most powerful web hosting control panel on the market. Add cPanel for only $24.50 per month. ### RESTful API Power and scale web applications easily using Atlantic.Net's RESTful Application Program Interface for cloud hosting. ## Linux Cloud Hosting - Ubuntu 16.04 LTS Server 32-Bit - Ubuntu 16.04 LTS Server 64-Bit - Ubuntu 18.04 LTS Server 64-Bit - Ubuntu 20.04 LTS Server 64-Bit - Ubuntu 22.04 LTS Server 64-bit - Ubuntu 24.04 LTS Server 64-bit - Debian 11.11.0 Server 64-Bit - Debian 12.11.0 Server 64-bit - Debian 13.0.0 Server 64-bit - Oracle Linux 7.9 64-bit - Oracle Linux 8.10 64-bit - Oracle Linux 9.6 64-bit - Oracle Linux 10.0 64-bit - Rocky Linux 8.10 64-bit - Rocky Linux 9.6 64-bit - Rocky Linux 10.0 64-bit - CentOS 6.9 Server 32-Bit - CentOS 6.9 Server 64-Bit - CentOS 7.9 Server 64-Bit - CentOS 8.2 Server 64-Bit - Fedora 42 Server 64-Bit - FreeBSD 13.0 Server 64-Bit - Arch Linux Server 64-Bit - AlmaLinux 8.10 64-bit - AlmaLinux 9.6 64-bit - AlmaLinux 10.0 64-bit - cPanel/WHM on AlmaLinux 64-bit ## Windows Cloud Hosting - Windows Server 2025 Datacenter (Desktop Experience) - Windows Server 2025 Datacenter - Windows Server 2022 Datacenter (Desktop Experience) - Windows Server 2022 Datacenter - Windows Server 2019 Datacenter (Desktop Experience) - Windows Server 2019 Datacenter - Windows Server 2016 Datacenter (with Containers/Docker) - Windows Server 2016 Datacenter - Windows Server 2012 R2 Datacenter (Desktop Experience) - Windows Server 2012 R2 Datacenter - Windows Server 2008 R2 SP1 Datacenter ## Secure Cloud Hosting Plans ### Cloud Hosting - Linux plans ### Fortress Standard Cloud Hosting - Linux Secure, isolated infrastructure with essential protections $373.24 Per Month 4 CPU's 16 GB of Ram 100 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - cPanel 5 Account License - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management **View 6 more plan services** - Managed VPN 5 Accounts - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Fortress Business Cloud Hosting - Linux Enhanced security layers and hardened configurations $744.88 Per Month 8 vCPU's 32 GB of Ram 300 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - cPanel 5 Account License - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management **View 6 more plan services** - Managed VPN 5 Accounts - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Fortress Enterprise Cloud Hosting - Linux Compliance-ready security for regulated and mission-critical workloads $1,468.75 Per Month 8 vCPU's 64 GB of Ram 500 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - cPanel 5 Account License - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management **View 6 more plan services** - Managed VPN 5 Accounts - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Cloud Hosting - Windows plans ### Fortress Standard Cloud Hosting - Windows Secure, isolated infrastructure with essential protections $385.22 Per Month 4 CPU's 16 GB of Ram 100 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts **View 5 more plan services** - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Fortress Business Cloud Hosting - Windows Enhanced security layers and hardened configurations $799.57 Per Month 8 vCPU's 32 GB of Ram 300 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts **View 5 more plan services** - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Fortress Enterprise Cloud Hosting - Windows Compliance-ready security for regulated and mission-critical workloads $1,786.89 Per Month 8 vCPU's 64 GB of Ram 500 GB SSD Storage 20 TB of Monthly Data Transfer - Onsite Daily Backups - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts **View 5 more plan services** - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement ### Fortress Custom Fortress Custom Cloud Hosting Maximum security, customization, and premium SLAs Custom Cloud Hosting - Onsite Daily Backups - Fully Managed FortiGate Firewall with IPS - 4 Hours of Migration Service - Server Management - Managed VPN 5 Accounts **View 5 more plan services** - Multi-Factor Authentication - Trend Micro Security Suite* - Off-site Daily Backups - Fully Managed Disaster Recovery Services - Business Associates Agreement *$150-$300 setup fee applies *Pricing based upon 12-month term commitment, and month to month option is available with a 20% premium. ***Save up to 30% off above listed pricing with longer billing terms*** These plans do not include HIPAA Compliant Hosting. You can choose a HIPAA Hosting plans by clicking here. ## Cloud Hosting FAQ ### Do you have scalable cloud hosting plans with hourly billing? Yes, you can use scalable cloud hosting with hourly billing. Atlantic.Net offers flexible CPU, RAM, and storage scaling, pay-as-you-go pricing, and on-demand plans with hourly rate examples alongside monthly pricing. ### How do I choose between public and private cloud hosting? Choose public cloud when you want fast provisioning, easier scaling, and lower entry cost. Choose private cloud when you need stronger isolation, more control over the environment, or tighter compliance boundaries. ### Are cloud hosting platforms good for compliance-heavy industries? Yes, they can be a strong fit when the environment is built for regulated workloads, and you still manage your side of compliance correctly. Atlantic.Net offers compliance-ready architecture and support for HIPAA- and PCI-related environments. Our data centers are SOC 2/SOC 3 certified and undergo annual HIPAA/HITECH audits. ### How do you switch from on-prem to cloud infrastructure? You usually switch in stages: assess the current environment, map dependencies, define the migration plan, move data through controlled channels, cut over during an approved window, and validate security, backups, and application behavior afterward. Atlantic.Net's migration service supports on-premises migrations; our teams conduct planning, controlled execution, encrypted transfers, and post-migration validation. ### What features should a business cloud hosting provider include? You should expect scalable compute and storage, predictable pricing, secure networking, backups and replication, private networking or isolated environments, API and control panel access, managed services, load-balancing options, and 24/7 support. ### How do I choose the best cloud hosting for developers? Choose a platform that gives developers direct control, fast provisioning, flexible scaling, operating system choice, API access, and easy collaboration. Atlantic.Net offers an easy-to-use control panel, RESTful API access, one-click applications, Windows/Linux/FreeBSD options, deployment in under 30 seconds, and a Teams collaboration service for sharing cloud resources between users. ### How do I evaluate which cloud hosting services are the fastest? Evaluate speed with your own workload, not just marketing language. Compare CPU and storage benchmarks, network latency from your users' locations, region coverage, consistency under load, and failover behavior. ### Do cloud providers generally offer built-in redundancy and load balancing? Redundancy is usually part of cloud architecture, but load balancing is not always automatic. In practice, many cloud platforms build redundancy into the infrastructure layer, while load balancing is offered as a separate service or deliberately architected into the application tier. [Atlantic.Net](https://www.atlantic.net/) has redundancy built into our core platform, and load balancing is available as a managed service. One of the major differentiators of Atlantic.Net is that its cloud has a built-in RAID 10 setup, which is not always included with other clouds. ### Do you offer high-performance cloud servers for remote teams? Yes, you can use high-performance cloud servers for distributed teams, especially when you need centralized infrastructure that can be managed securely from multiple locations. Our Team collaboration tools allow users to split stack responsibilities among different users while maintaining central authority. Furthermore, secure VPN connections can be set up for the teams with encryption. ### Do cloud hosting providers generally offer SSD storage and 24/7 support? Many business-grade providers do, but you should verify both items on the product and support pages rather than assume they are included. For Atlantic.Net, SSD storage is standard across all our hosting environments, with NVMe-backed storage options available. We offer 24/7/365 support by phone and email from US-Based tech teams. ## A Support Team Backed by Decades of Experience With over three decades of experience, our support team is always here to assist you. You’ll have 24/7/365 access to a crop of dedicated veterans, capable of solving any technical problem you throw their way. ## One-Click Cloud Hosting Apps Did you know that with the Atlantic.Net control panel or API, you can launch a range of 1-Click Apps in under 30 seconds? These cloud hosting apps are built upon a patched and secure operating system, and each app is configured to industry standards by our team of engineers. Each app is updated regularly to incorporate important features and security updates. ## Point, Click, and Deploy – It's That Easy! Instantly create, deploy, and manage your Linux and Windows infrastructure from the Atlantic.Net Cloud control panel. This control panel gives you the ability to deploy as many cloud servers as you need with a couple of clicks of your mouse. All our cloud server instances self-configure and will deploy into the high-performing Atlantic.Net data center of your choice. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # How to Create a Weaviate Vector Database, Import Data, and Search on the Atlantic.Net Cloud Platform: A Step-by-Step Guide > URL: https://www.atlantic.net/gpu-server-hosting/how-to-create-a-weaviate-vector-database-import-data-and-search-on-the-atlantic-net-cloud-platform-a-step-by-step-guide/ | Published: 2024-11-15 | Updated: 2024-12-12 | Author: Richard Bailey This guide outlines the process of setting up and connecting to a local Weaviate instance from an Atlantic.Net Cloud server using Docker for containerization and Ollama for the embedding and generative models. Weaviate is an open-source vector database that enables searches based on similarity. It is popular with Retrieval Augmented Generation (RAG). ## Prerequisites - An active Atlantic.Net account with a deployed cloud instance - We recommend selecting a cloud instance with ample resources (at least 8GB RAM, preferably 16GB or more) to accommodate Weaviate and the language models. - SSH access to your cloud server. ## Part 1: Prepare the Cloud Platform Environment ### Step 1 – Update Ubuntu - **Update System Packages:** ``` sudo apt update && sudo apt upgrade -y ``` ### Step 2 – Install Docker - **Install Docker:** Install the following packages to allow apt to use a repository over HTTPS: ``` sudo apt install -y ca-certificates curl gnupg lsb-release ``` - **Add Docker’s Official GPG Key** Download and add Docker’s official GPG key: ``` sudo mkdir -p /etc/apt/keyrings curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo gpg --dearmor -o /etc/apt/keyrings/docker.gpg ``` - **Set Up the Docker Repository** Add the Docker repository to APT sources: ``` echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.d/docker.list > /dev/null ``` - **Update the Package List Again** Update the package list to include Docker packages from the new repository: ``` sudo apt update -y ``` - **Install Docker Engine** Install the latest version of Docker Engine, containerd, and Docker Compose: ``` sudo apt install -y docker-ce docker-ce-cli containerd.io docker-compose-plugin ``` - **Verify the Installation** Check that Docker is installed correctly by running the hello-world image: ``` sudo docker run hello-world ``` You should see output like this: ``` root@Weaviate:~# sudo docker run hello-world Unable to find image 'hello-world:latest' locally latest: Pulling from library/hello-world c1ec31eb5944: Pull complete Digest: sha256:d211f485f2dd1dee407a80973c8f129f00d54604d2c90732e8e320e5038a0348 Status: Downloaded newer image for hello-world:latest Hello from Docker! This message shows that your installation appears to be working correctly. 1. The Docker client contacted the Docker daemon. 2. The Docker daemon pulled the "hello-world" image from the Docker Hub. (amd64) To generate this message, Docker took the following steps: 3. The Docker daemon created a new container from that image which runs the executable that produces the output you are currently reading. 4. The Docker daemon streamed that output to the Docker client, which sent it to your terminal. To try something more ambitious, you can run an Ubuntu container with: $ docker run -it ubuntu bash Share images, automate workflows, and more with a free Docker ID: https://hub.docker.com/ For more examples and ideas, visit: https://docs.docker.com/get-started/ root@Weaviate:~# ``` - **Add Your User to the docker Group (Optional)** To run Docker commands without sudo, add your user to the docker group: ``` sudo usermod -aG docker $USER ``` ### Step 3 – Set Up Weaviate in Docker Weaviate works very well within a Docker environment. We will us Docker Compose to create the Weaviate Database. - **Create docker-compose.yml** ``` nano docker-compose.yml ``` - **Use the Provided docker-compose.yml Content (Source: Weaviate Website)** ``` --- services: weaviate: command: - --host - 0.0.0.0 - --port - '8080' - --scheme - http image: cr.weaviate.io/semitechnologies/weaviate:1.27.2 ports: - 8080:8080 - 50051:50051 volumes: - weaviate_data:/var/lib/weaviate restart: on-failure:0 environment: QUERY_DEFAULTS_LIMIT: 25 AUTHENTICATION_ANONYMOUS_ACCESS_ENABLED: 'true' PERSISTENCE_DATA_PATH: '/var/lib/weaviate' DEFAULT_VECTORIZER_MODULE: 'none' ENABLE_API_BASED_MODULES: 'true' CLUSTER_HOSTNAME: 'node1' ENABLE_API_BASED_MODULES: 'true' volumes: weaviate_data: ... ``` - **Start Weaviate** Now start Weaviate using the docker-compose up detached command. ``` docker compose up -d ``` You will see output like this: ``` root@Weaviate:~# docker compose up -d [+] Running 8/8 ✔ weaviate Pulled 7.0s ✔ 43c4264eed91 Pull complete 0.8s ✔ 45d7c130d6ea Pull complete 1.0s ✔ db001b655dd0 Pull complete 3.3s ✔ 1eb7452f9739 Pull complete 3.3s ✔ 2777e559ecf5 Pull complete 4.0s ✔ add3a9abe015 Pull complete 4.3s ✔ 088f4f300a62 Pull complete 4.3s [+] Running 3/3 ✔ Network root_default Created 0.1s ✔ Volume "root_weaviate_data" C... 0.0s ✔ Container root-weaviate-1 Sta... 0.7s root@Weaviate:~# ``` ### Step 4 – Install Ollama Now, let’s install Ollama, a powerful open-source large language model. It is a requirement of Weaviate. This is a self-installable script. ``` curl -fsSL https://ollama.ai/install.sh | bash ``` Ollama is a large application that will take a few minutes to download and install. You should see output like this: ``` root@Weaviate:~# curl -fsSL https://ollama.ai/install.sh | bash >>> Installing ollama to /usr/local >>> Downloading Linux amd64 bundle ########################################################## 100.0% >>> Creating ollama user... >>> Adding ollama user to render group... >>> Adding ollama user to video group... >>> Adding current user to ollama group... >>> Creating ollama systemd service... >>> Enabling and starting ollama service... Created symlink /etc/systemd/system/default.target.wants/ollama.service → /etc/systemd/system/ollama.service. >>> The Ollama API is now available at 127.0.0.1:11434. >>> Install complete. Run "ollama" from the command line. WARNING: No NVIDIA/AMD GPU detected. Ollama will run in CPU-only mode. ``` - **Download Ollama Models** Now we need to download Ollama language models. These are open-source pre-trained LLMs. First, pull nomic-embed-text ``` ollama pull nomic-embed-text ``` You should see output like this: ``` root@Weaviate:~# ollama pull nomic-embed-text pulling manifest pulling 970aa74c0a90... 100% ▕████████▏ 274 MB pulling c71d239df917... 100% ▕████████▏ 11 KB pulling ce4a164fc046... 100% ▕████████▏ 17 B pulling 31df23ea7daa... 100% ▕████████▏ 420 B verifying sha256 digest writing manifest success root@Weaviate:~# ``` Next pull llama3.2. Note that this file is over 2GB and will take a while to download and install. ``` ollama pull llama3.2 ``` You should see output like this: ``` root@Weaviate:~# ollama pull llama3.2 pulling manifest pulling dde5aa3fc5ff... 100% ▕████████▏ 2.0 GB pulling 966de95ca8a6... 100% ▕████████▏ 1.4 KB pulling fcc5a6bec9da... 100% ▕████████▏ 7.7 KB pulling a70ff7e570d9... 100% ▕████████▏ 6.0 KB pulling 56bb8bd477a5... 100% ▕████████▏ 96 B pulling 34bb5ab01051... 100% ▕████████▏ 561 B verifying sha256 digest writing manifest success ``` ## Part 2 – Install Python & Jupyter Notebooks There are several ways you can use Weaviate, but you must use it with an SDK. This procedure will follow the steps to use Python, but please be aware that Weaviate supports Java and NodeJS if that is your preferred SDK. ### Step 1 – Install Python Jupyter Lab requires Python. You can install it using the following commands: ``` apt install python3 python3-pip -y ``` Note: You may be prompted to restart services after installation. Just click . Next, install the Python virtual environment package. ``` pip install -U virtualenv ``` ### Step 2 – Install Jupyter Lab Now, install Jupyter Lab using the pip command. ``` pip3 install jupyterlab ``` This command installs Jupyter Lab and its dependencies. Next, edit the .bashrc file. ``` nano ~/.bashrc ``` Define your Jupyter Lab path as shown below; simply add it to the bottom of the file: ``` export PATH=$PATH:~/.local/bin/ ``` Reload the changes using the following command. ``` source ~/.bashrc ``` Next, test run the Jupyter Lab locally using the following command to make sure everything starts. ``` jupyter lab --allow-root --ip=0.0.0.0 --no-browser ``` Check the output to make sure there are no errors. Upon success, you will see the following output. ``` [C 2023-12-05 15:09:31.378 ServerApp] To access the server, open this file in a browser: http://ubuntu:8888/lab?token=aa67d76764b56c5558d876e56709be27446 http://127.0.0.1:8888/lab?token=aa67d76764b56c5558d876e56709be27446 ``` Press the CTRL+C to stop the server. ### Step 3 – Configure Jupyter Lab By default, Jupyter Lab doesn’t require a password to access the web interface. To secure Jupyter Lab, generate the Jupyter Lab configuration using the following command. ``` jupyter-lab --generate-config ``` Output. ``` Writing default config to: /root/.jupyter/jupyter_lab_config.py ``` Next, set the Jupyter Lab password. ``` jupyter-lab password ``` Set your password as shown below: ``` Enter password: Verify password: [JupyterPasswordApp] Wrote hashed password to /root/.jupyter/jupyter_server_config.json ``` You can verify your hashed password using the following command. ``` cat /root/.jupyter/jupyter_server_config.json ``` Output. ``` { "IdentityProvider": { "hashed_password": "argon2:$argon2id$v=19$m=10240,t=10,p=8$zf0ZE2UkNLJK39l8dfdgHA$0qIAAnKiX1EgzFBbo4yp8TgX/G5GrEsV29yjHVUDHiQ" } } ``` Note this inano /root/.jupyter/jupyter_lab_config.pynformation, as you will need to add it to your config. Next, edit the Jupyter Lab configuration file. ``` ``` Define your server IP, hashed password, and other configurations as shown below: c.ServerApp.ip = ‘your-server-ip’ c.ServerApp.open_browser = False c.ServerApp.password = ‘argon2:$argon2id$v=19$m=10240,t=10,p=8$zf0ZE2UkNLJK39l8dfdgHA$0qIAAnKiX1EgzFBbo4yp8TgX/G5GrEsV29yjHVUDHiQ’ c.ServerApp.port = 8888 Make sure you format the file exactly as above. For example, the port number is not in brackets, and the False boolean must have a capital F. Save and close the file when you are done. ### Step 4 – Create a Systemctl Service File Next, create a systemd service file to manage Jupyter Lab. ``` nano /etc/systemd/system/jupyter-lab.service ``` Add the following configuration: ``` [Service] Type=simple PIDFile=/run/jupyter.pid WorkingDirectory=/root/ ExecStart=/usr/local/bin/jupyter lab --config=/root/.jupyter/jupyter_lab_config.py --allow-root User=root Group=root Restart=always RestartSec=10 [Install] WantedBy=multi-user.target ``` Save and close the file, then reload the systemd daemon. ``` systemctl daemon-reload ``` Next, start the Jupyter Lab service using the following command. ``` systemctl start jupyter-lab ``` You can now check the status of the Jupyter Lab service using the following command. ``` systemctl status jupyter-lab ``` Jupyter Lab is now starting and listening on port 8888. You can verify it with the following command. ``` ss -antpl | grep jupyter ``` Output. ``` LISTEN 0 128 104.219.55.40:8888 0.0.0.0:* users:(("jupyter-lab",pid=156299,fd=6)) ``` ### Step 5 – Access Jupyter Lab Now, open your web browser and access the Jupyter Lab web interface using the URL http://your-server-ip:8888. You will see Jupyter Lab on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2024/11/jupyter-password.png) Provide the password you set during the installation and click on Log in. You will see the Jupyter Lab dashboard on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2024/11/jupyter-dashboard.png) ### Step 6 – Start the Python3 Notebook You can now start the Python 3 Notebook and move on Part 3. ## Part 3 – Configure Weaviate ### Step 1: Install Weaviate Client Library - **Choose Your Preferred Language** Weaviate offers client libraries in Python, JavaScript/TypeScript, Go, and Java. - **Install the Weaviate Client Library** This can be done from either the command line or directly from the Jupyter Notebook. For ease, I recommend using the Jupyter Notebook. ``` pip install -U weaviate-client ``` - **Install Required Modules** ``` pip install pandas ``` ``` pip install tqdm ``` Now test if your Python client can connect to Weaviate. ``` import weaviate from weaviate.classes.init import AdditionalConfig, Timeout client = weaviate.connect_to_local( port=8080, grpc_port=50051, additional_config=AdditionalConfig( timeout=Timeout(init=30, query=60, insert=120) # Values in seconds ) ) print(client.is_ready()) ``` You should get this output: ``` True ``` You can pull the server’s metadata with this command: ``` import json metainfo = client.get_meta() print(json.dumps(metainfo, indent=2)) ``` You should see output like this: ``` { "hostname": "http://[::]:8080", "modules": { "generative-openai": { "documentationHref": "https://platform.openai.com/docs/api-reference/completions", "name": "Generative Search - OpenAI" }, "qna-openai": { "documentationHref": "https://platform.openai.com/docs/api-reference/completions", "name": "OpenAI Question & Answering Module" }, "ref2vec-centroid": {}, "reranker-cohere": { "documentationHref": "https://txt.cohere.com/rerank/", "name": "Reranker - Cohere" }, "text2vec-cohere": { "documentationHref": "https://docs.cohere.ai/embedding-wiki/", "name": "Cohere Module" }, "text2vec-huggingface": { "documentationHref": "https://huggingface.co/docs/api-inference/detailed_parameters#feature-extraction-task", "name": "Hugging Face Module" }, "text2vec-openai": { "documentationHref": "https://platform.openai.com/docs/guides/embeddings/what-are-embeddings", "name": "OpenAI Module" } }, "version": "1.23.13" } ``` ### Step 2 – Create some data in Weaviate - **Create a Collection** ``` import weaviate import weaviate.classes.config as wc import os client.collections.create( name="Movie", properties=[ wc.Property(name="title", data_type=wc.DataType.TEXT), wc.Property(name="overview", data_type=wc.DataType.TEXT), wc.Property(name="vote_average", data_type=wc.DataType.NUMBER), wc.Property(name="genre_ids", data_type=wc.DataType.INT_ARRAY), wc.Property(name="release_date", data_type=wc.DataType.DATE), wc.Property(name="tmdb_id", data_type=wc.DataType.INT), ], # Define the vectorizer module vectorizer_config=wc.Configure.Vectorizer.text2vec_openai(), # Define the generative module generative_config=wc.Configure.Generative.openai() ) ``` If successful you will see output like this: ``` ``` - **Import Data** We are going to impact a free opensource movie database called TMDB. ``` import weaviate import pandas as pd import requests from datetime import datetime, timezone import json from weaviate.util import generate_uuid5 from tqdm import tqdm import os data_url = "https://raw.githubusercontent.com/weaviate-tutorials/edu-datasets/main/movies_data_1990_2024.json" resp = requests.get(data_url) df = pd.DataFrame(resp.json()) # Get the collection movies = client.collections.get("Movies") # Enter context manager with movies.batch.dynamic() as batch: # Loop through the data for i, movie in tqdm(df.iterrows()): # Convert data types # Convert a JSON date to `datetime` and add time zone information release_date = datetime.strptime(movie["release_date"], "%Y-%m-%d").replace( tzinfo=timezone.utc ) # Convert a JSON array to a list of integers genre_ids = json.loads(movie["genre_ids"]) # Build the object payload movie_obj = { "title": movie["title"], "overview": movie["overview"], "vote_average": movie["vote_average"], "genre_ids": genre_ids, "release_date": release_date, "tmdb_id": movie["id"], } # Add object to batch queue batch.add_object( properties=movie_obj, uuid=generate_uuid5(movie["id"]) # references=reference_obj # You can add references here ) # Batcher automatically sends batches # Check for failed objects if len(movies.batch.failed_objects) > 0: print(f"Failed to import {len(movies.batch.failed_objects)} objects") ``` Upon completion, you will get an output like this: ``` 680it [00:05, 135.25it/s] ``` ## Conclusion To recap, now that we have imported the data into the Weaviate vector database, we can search and use the data. At this point, I recommend you consult Weaviate’s documentation to explore all the different ways you can query the data. By following this guide, you’ve successfully set up Weaviate on your Atlantic.Net Cloud Platform. You can now explore the powerful features of Weaviate and build your own RAG applications. Remember to refer to the official Weaviate documentation for more advanced use cases and configuration options. --- # How to Compare ZIP Files in Linux Shell > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-compare-zip-files-in-linux-shell/ | Published: 2024-11-20 | Updated: 2024-12-03 | Author: Hitesh Jethva When managing compressed files in Linux, it is common to compare two ZIP files to verify their contents or identify differences. Linux provides several shell tools to assist in comparing ZIP files without needing to extract them. In this guide, you will learn how to effectively compare ZIP files using different methods in the Linux shell. ## Method 1: Extract and Use diff The easiest way to compare ZIP files is to extract them and then use the **diff** command. **Step 1: Extract the ZIP files.** ```bash unzip file1.zip -d file1_dir unzip file2.zip -d file2_dir ``` The **-d** option allows you to specify the directory where files will be extracted. **Step 2: Use diff to compare the extracted directories.** ```bash diff -r file1_dir file2_dir ``` - The **-r** flag makes **diff** compare directories recursively. - This approach provides a line-by-line comparison of the differences between files in the ZIP archives. ## Method 2: Using diff with unzip -l You can also compare ZIP files without extracting their contents. This method uses **unzip -l** to list the contents and then **diff** to compare them. **Step 1: List the contents of each ZIP file.** ```bash unzip -l file1.zip > file1_contents.txt unzip -l file2.zip > file2_contents.txt ``` **unzip -l** lists the file names, sizes, and modification times. **Step 2: Use diff to compare the file lists.** ```bash diff file1_contents.txt file2_contents.txt ``` This command will show differences in file names, sizes, or timestamps between the two ZIP archives. ## Method 3: Using cmp for Byte-Level Comparison If you need a byte-level comparison between two ZIP files, you can use the cmp command. This compares the raw contents of the ZIP files directly. ```bash cmp file1.zip file2.zip ``` - If **cmp** finds differences, it will output the location of the first differing byte. - If there are no differences, cmp produces no output. ## Method 4: Compare Using 7z Another powerful tool for ZIP file comparison is 7z, part of the p7zip package. **Step 1: Install p7zip if not already installed.** ```bash apt-get install p7zip-full ``` **Step 2: Use 7z to list contents and compare.** ```bash 7z l file1.zip > file1_list.txt 7z l file2.zip > file2_list.txt diff file1_list.txt file2_list.txt ``` - The **7z l** command lists the contents of the ZIP archive. - Then, use **diff** to compare the lists. ## Method 5: Using vbindiff for Visual Comparison For a visual comparison of two ZIP files, you can use vbindiff. **Step 1: Install vbindiff.** ```bash apt-get install vbindiff ``` **Step 2: Use vbindiff to compare files.** ```bash vbindiff file1.zip file2.zip ``` vbindiff provides a visual, byte-by-byte comparison. This can be helpful when you need to see exactly where differences occur. ## Method 6: Using bsdiff If you need to create a binary patch to represent differences between two ZIP files, you can use bsdiff. **Step 1: Install bsdiff.** ```bash apt-get install bsdiff ``` **Step 2: Create a binary patch.** ```bash bsdiff file1.zip file2.zip patch_file.bsdiff ``` This creates a patch file that can represent the changes between two ZIP files. It’s useful for version control of large binary files. ## Conclusion Comparing ZIP files in Linux is not as straightforward as comparing regular text files, but it can be easily done with the right tools. Whether you choose to extract and compare using diff, leverage a visual tool like vbindiff, or automate the process with a script, Linux provides versatile solutions for different needs. Compare ZIP files on Atlantic.Net’s [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) with Linux shell commands! --- # Atlantic.Net HIPAA Cloud Hosting Solution Wins Merit Award for Medication Compliance/Adherence in Fall 2024 Digital Health Awards® > URL: https://www.atlantic.net/press-releases/atlantic-net-hipaa-cloud-hosting-solution-wins-merit-award-for-medication-compliance-adherence-in-fall-2024-digital-health-awards/ | Published: 2024-11-20 | Updated: 2024-12-05 | Author: Alexander Wise **Orlando, FL (November 20, 2024):** Atlantic.Net, a leading provider of managed cloud hosting solutions, today announced that its HIPAA Cloud Hosting Solution has been awarded a Merit Award in the Fall 2024 Digital Health Awards® for Connected Digital Health Medication Compliance/Adherence. The Digital Health Awards® program recognizes the best digital health resources across a wide range of categories. Atlantic.Net’s HIPAA Cloud Hosting Solution was selected for its ability to help healthcare organizations securely and reliably host applications and data related to medication compliance and adherence. “We are honored to be recognized by the Digital Health Awards® for our commitment to providing innovative and compliant cloud solutions for the healthcare industry,” said Marty Puranik, CEO of Atlantic.Net. “Our HIPAA One-Click Cloud Hosting Solutions make it easy for healthcare organizations to deploy and manage secure, compliant applications that can help improve patient outcomes.” Atlantic.Net’s HIPAA One-Click Cloud Hosting Solution is a managed, HIPAA-compliant cloud platform that provides a secure and reliable environment for hosting sensitive patient data. The solution is designed to help healthcare organizations meet the Health Insurance Portability and Accountability Act (HIPAA) requirements. ## About Atlantic.Net Atlantic.Net is a global cloud provider with over 30 years of experience delivering innovative and reliable hosting solutions. Focusing on security, compliance, and customer support, Atlantic.Net offers a wide range of services, including HIPAA-compliant hosting, dedicated hosting, VPS hosting, and colocation. Atlantic.Net provides mission critical services from  eight global data center regions located in the United States, Canada, The United Kingdom, and Asia. About the Health Information Resource Center (HIRC) The Health Information Resource Center (HIRC) is a national clearinghouse for professionals who work in consumer health fields. HIRC organizes the Digital Health Awards® and the National Health Information Awards, which recognize the best consumer health information in non-digital formats. ### **Media Contact** [pr@atlantic.net](mailto:pr@atlantic.net) --- # How to Run a Command Before User Logs In > URL: https://www.atlantic.net/tutorials/how-to-run-a-command-before-user-logs-in/ | Published: 2024-11-21 | Updated: 2024-12-03 | Author: Hitesh Jethva In many scenarios, you need to run specific commands or scripts automatically before a user logs into a system. This capability is especially useful for performing system checks, updating configurations, or setting up the environment consistently. This article covers various methods to achieve this on a Linux system. ## Understanding the Login Process Before we delve into how to run commands pre-login, it’s crucial to understand the login process. When a user logs into a Linux system, the process typically involves the following steps: - **Authentication:** The system verifies the user’s credentials. - **Session Creation:** Upon successful authentication, the system initiates a user session. - **Execution of Login Scripts**: Various scripts are executed that can be configured to run custom commands. Let’s explore various methods for running a script before user login on a Linux system in detail. ## Using /etc/rc.local for System-Wide Commands The **/etc/rc.local** file is a traditional way to run system-wide commands before the login screen appears. While some modern Linux distributions no longer include it by default, it remains a viable option for initializing services at boot. First, check if the **/etc/rc.local** file is present on your system: ```bash ls /etc/rc.local ``` If the file doesn’t exist, create it and ensure it is executable: ```bash touch /etc/rc.local chmod +x /etc/rc.local ``` Open the file with a text editor, like **nano:** ```bash nano /etc/rc.local ``` Add your script or command before the exit 0 line: ```bash #!/bin/bash echo "Running pre-login script" >> /var/log/prelogin.log /path/to/your_command.sh exit 0 ``` Enable and start the rc-local service. ```bash systemctl enable rc-local systemctl start rc-local ``` **Note:** This method runs commands at boot, making it suitable for tasks that need to start before the login screen is visible, but it does not run every time a user logs in. ## Configuring PAM (Pluggable Authentication Modules) PAM modules provide a way to execute scripts when users authenticate, which can be useful for security policies or performing actions specific to the user before full access is granted. The PAM configuration files are located in **/etc/pam.d/.** Depending on the type of login, choose the appropriate file. For SSH logins, edit **/etc/pam.d/sshd:** ```bash nano /etc/pam.d/sshd ``` For local logins, edit /etc/pam.d/login: ```bash nano /etc/pam.d/login ``` To run your script before login, add the following line to the appropriate file: ```bash auth required pam_exec.so /path/to/your_command.sh ``` You can also add logging within your script to track login attempts: ```bash #!/bin/bash echo "User $PAM_USER attempted login at $(date)" >> /var/log/prelogin_pam.log ``` ## Creating a Pre-Login Systemd Service systemd offers precise control over when and how services are executed. You can create a systemd service that runs before the display manager starts, ensuring the command executes prior to any graphical login prompt. Navigate to **/etc/systemd/system/** and create a new service file: ```bash nano /etc/systemd/system/prelogin.service ``` Add the following configuration to the service file: ```bash [Unit] Description=Run Pre-Login Script Before=display-manager.service [Service] Type=oneshot ExecStart=/path/to/your_command.sh [Install] WantedBy=multi-user.target ``` Enable the service to ensure it runs during every boot: ```bash systemctl enable prelogin.service systemctl start prelogin.service ``` Use the following command to verify that the service ran successfully: ```bash systemctl status prelogin.service ``` ## Running Commands with **/etc/profile** and **/etc/profile.d/** The **/etc/profile** file and the /etc/profile.d/ directory allows you to run commands when a user session starts. This is more suited for customizing the user environment and runs once the user logs in. Edit **/etc/profile** and add commands directly to **/etc/profile** to make them run at every session start: ```bash nano /etc/profile ``` Add the following line: ```bash echo "Session started for user $USER at $(date)" >> /var/log/session_start.log ``` Alternatively, you can create a script in **/etc/profile.d/** to achieve similar behavior: ```bash nano /etc/profile.d/prelogin_script.sh ``` Add your commands to the script: ```bash #!/bin/bash echo "Running session initialization for $USER" >> /var/log/session_script.log ``` **Note:** This method is effective for running commands that configure user environments after login, rather than before authentication. ## Using Cron Jobs for Boot-Time Execution cron jobs can be used to execute commands at system boot. The **@reboot** cron keyword allows for simple boot-time scripts, though these run alongside other startup tasks and do not necessarily need to be done before login. Open the crontab editor: ```bash crontab -e ``` Add the following line to run a script at every system boot: ```bash @reboot /path/to/your_command.sh ``` Log messages from your script can help you verify its execution: ```bash echo "Boot script executed at $(date)" >> /var/log/boot_script.log ``` ## Conclusion Running commands before user login can be essential for configuring the environment, initializing services, or setting up security measures. Each method offers unique benefits and is suitable for different scenarios, so select the approach that best matches your system’s requirements and the specific tasks you wish to perform. Ready to optimize your server environment? Explore Atlantic.Net’s [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) options today! --- # How to Mount Remote Directory in Linux Using SSHFS > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-mount-remote-directory-in-linux-using-sshfs/ | Published: 2024-11-22 | Updated: 2024-12-05 | Author: Hitesh Jethva SSHFS is a user-space filesystem client that enables mounting remote directories securely via SSH. This approach can be beneficial when you need direct access to remote files for development, data analysis, or backup purposes. In this guide, we will show you how to mount a remote directory in Linux using SSHFS. ## Why Use SSHFS? Using SSHFS provides several benefits: - **Ease of Use**: With a single command, you can access remote files as if they were local. - **Security:** SSHFS uses the SSH protocol, which means your data is transferred securely. - **No Extra Setup:** SSHFS requires no extra software on the remote server; it only needs SSH access. - **Versatility:** You can use SSHFS to connect to any server that allows SSH, giving you flexible access. ## Installing SSHFS SSHFS is usually available in the repositories of most Linux distributions. Install it using the package manager for your specific distribution. **On Ubuntu/Debian:** ```bash apt update apt install sshfs ``` **On CentOS/RHEL:** ```bash yum install epel-release yum install sshfs ``` **On Fedora:** ```bash dnf install sshfs ``` Verify the installation by running: ```bash sshfs -V ``` ## Basic Syntax To mount a remote directory with SSHFS, you need to know the remote directory path, remote user credentials, and have a designated local directory for mounting. **Here is a basic syntax:** ```bash sshfs [user]@[remote_host]:[remote_directory] [local_mount_point] ``` **Where:** - **user:** name of the remote user - **remote_host:** IP address of the remote host - **remote_directory:** path of the remote directory that you want to mount - **local_mount_point:** path of the local mount directory ## Create a Mount Point A mount point is a directory on your local machine where the remote filesystem will be mounted. You can create a directory in your home folder to serve as the mount point: ```bash mkdir ~/remote_directory ``` This directory will represent the remote server’s filesystem after mounting. ## Mount the Remote Directory Now that SSHFS is installed, you can use it to mount the remote directory. Use the following command to mount the remote directory: ```bash sshfs username@remote_host:/path/to/remote/directory ~/remote_directory ``` **Where:** - **username:** The username used to log into the remote server. - **remote_host:** The IP address or hostname of the remote server. - **/path/to/remote/directory:** The directory on the remote server that you wish to mount. - **~/remote_directory:** The local mount point. For example, if your remote server has an IP address of **192.168.1.100** and you want to mount the **/var/www** directory: ```bash sshfs user@192.168.1.100:/var/www ~/remote_directory ``` ## Verify the Mount Once mounted, you can verify that the remote directory is accessible using standard filesystem commands like ls: ```bash ls ~/remote_directory ``` You should see the contents of the remote directory as if they were local. Note: Keep in mind that file permissions on the remote server will still apply after mounting, so you may need to adjust ownership or permissions on the remote side if you encounter access issues; for shared access, the **-o allow_other** option can be used with caution, but be aware of the potential security implications as it allows other local users to access the mounted directory. ## Unmounting the Remote Directory When you’re done working with the remote directory, it’s important to unmount it properly to avoid issues. ```bash umount ~/remote_directory ``` ## Advanced Options for SSHFS SSHFS provides several options to customize the connection and mount behavior. **Compression:** You can enable SSH compression to improve performance when transferring many files: ```bash sshfs -C username@remote_host:/path/to/remote/directory ~/remote_directory ``` **Port Specification:** If your SSH server is running on a non-standard port (not 22), you can specify it using the -p flag: ```bash sshfs -p 2222 username@remote_host:/path/to/remote/directory ~/remote_directory ``` **Reconnect Automatically:** To automatically reconnect if the connection drops, use the reconnect option: ```bash sshfs -o reconnect username@remote_host:/path/to/remote/directory ~/remote_directory ``` ## Conclusion SSHFS is a powerful tool that allows you to access remote directories over SSH seamlessly. It’s easy to set up and secure and doesn’t require any special server-side configurations beyond SSH. Whether you need to manage files on a remote server for development or administrative purposes, SSHFS provides an efficient and secure solution. Need to access files on a remote server? Deploy [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) with Atlantic.Net and leverage the power of SSHFS! --- # How to Use the Linux sftp Command Guide with Examples > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-use-the-linux-sftp-command-guide-with-examples/ | Published: 2024-11-25 | Updated: 2024-12-03 | Author: Hitesh Jethva SFTP, or Secure File Transfer Protocol, is a network protocol that allows secure file access, transfer, and management over an encrypted SSH connection. SFTP is commonly used to transfer files between servers securely, often to or from a Linux server. It combines the ease of FTP with the security of SSH, making it suitable for use in environments that require encryption. In this guide, we’ll explore how to use the sftp command effectively with practical examples. ## Connecting to a Remote Server To connect to a remote server using sftp, you can use the following command: ```bash sftp user@remote_server_ip ``` For example: ```bash sftp john@192.168.1.10 ``` After entering the command, you’ll be prompted for the user’s password**.** Once authenticated, you will see the **sftp>** prompt, indicating that you have successfully connected. ## Basic Commands in sftp When connected via sftp, you can use various commands to navigate and manipulate files, similar to the commands used in a regular shell. **1. Listing Files** To list the files and directories in the current directory on the remote server, use: ```bash ls ``` You can also use **lls** to list files in your local working directory: ```bash lls ``` **2. Changing Directories** To change the current directory on the remote server: ```bash cd /path/to/directory ``` To change the directory on the local system: ```bash lcd /path/to/local/directory ``` **3. Uploading Files** To upload a file from your local system to the remote server, use the **put** command: ```bash put local_file.txt /remote/directory ``` For example: ```bash put document.txt /home/john/documents ``` **4. Downloading Files** To download a file from the remote server to your local system, use the **get** command: ```bash get /remote/directory/file.txt ``` For example: ```bash get /home/john/documents/report.pdf ``` **5. Uploading/Downloading Directories** To recursively upload a directory: ```bash put -r local_directory /remote/directory ``` To download a remote directory recursively: ```bash get -r /remote/directory local_directory ``` **6. Renaming Files** To rename a file on the remote server: ```bash rename old_name.txt new_name.txt ``` **7. Deleting Files** To delete a file on the remote server: ```bash rm /path/to/file.txt ``` ## Checking Remote Directory To display the current remote working directory: ```bash pwd ``` To display the current local working directory: ```bash lpwd ``` ## Creating and Removing Directories To create a new directory on the remote server: ```bash mkdir /path/to/new_directory ``` To remove a directory on the remote server: ```bash rmdir /path/to/directory ``` ## Using sftp in Batch Mode If you need to automate file transfers, you can use sftp in batch mode by providing a file containing a list of commands. Create a batch file, commands.txt, with the following content: ```bash lcd /local/directory cd /remote/directory put file1.txt get file2.txt ``` Then run sftp in batch mode: ```bash sftp -b commands.txt user@remote_server_ip ``` This allows you to automate repetitive file transfer tasks without manually typing each command. ## Using sftp in Non-Interactive Mode To run sftp non-interactively, echo commands to sftp or use here documents. This is particularly useful for integrating sftp commands into scripts. Example with here document: ```bash sftp user@hostname < URL: https://www.atlantic.net/dedicated-server-hosting/why-is-the-default-stack-size-huge-in-linux/ | Published: 2024-11-26 | Updated: 2024-12-03 | Author: Hitesh Jethva The stack is an important component in the Linux operating system. It holds local variables, manages function calls, and stores temporary data during program execution. In Linux, the default stack size is often much larger than necessary for most applications. This article explains why the default stack size is so large, its importance, and ways to manage it effectively. ## Understanding the Stack in Linux The stack in Linux is a part of memory that a program uses to store information temporarily. - This includes local variables, function arguments, and return addresses. - It grows dynamically as the program runs. - The stack follows a Last-In-First-Out (LIFO) structure, meaning the last item added is the first removed. Programs need the stack for function calls and recursive operations. Insufficient stack space can cause a program to crash due to a stack overflow. ## What Is the Default Stack Size? In many Linux systems, the default stack size is 8 MB per thread. You can check the default stack size using the **ulimit** command: ```bash ulimit -s ``` The output will typically show 8192 (kilobytes), indicating 8 MB. 8 MB is large for many applications, especially for simple programs or threads requiring minimal local storage. ## Why Is the Default Stack Size Large? There are several reasons why Linux provides a large default stack size: - **Handling Deep Recursion**: Some programs, especially those in scientific computing or complex algorithms, require deep recursion. Each recursive function call adds data to the stack. A large stack size ensures these programs can run without hitting a stack overflow. - **Flexibility for Developers**: By setting a large stack size by default, Linux gives developers flexibility. Programs with complex operations or large local variables don’t need extra configuration to run smoothly. - **Stability in Multithreaded Applications**: Multithreaded applications often require significant stack space. Each thread has its stack, and the default 8 MB helps prevent crashes due to insufficient stack space when running multiple threads simultaneously. ## Benefits of a Large Stack Size While it may seem wasteful, a large default stack size has advantages: - **Reduces Stack Overflow Risk**: Many crashes in software are due to stack overflows. With a large default stack, these risks are minimized. - **Simplifies Development**: Developers don’t need to adjust stack size for each program. They can assume that Linux provides enough memory for most use cases. - **Supports Complex Software**: Programs that involve deep function calls or complex data structures require a large stack. The default stack size ensures that these programs run without extra configuration. ## Drawbacks of a Large Stack Size Despite its benefits, a large stack size isn’t always ideal. Here are some drawbacks: - **Wasted Memory:** Each thread reserves 8 MB of stack space, even if it doesn’t use all of it. In programs with many threads, this can lead to significant wasted memory. - **Resource Limitation:** For low-memory systems, a large default stack size can limit the number of threads. Each 8 MB stack occupies valuable memory, which could otherwise support additional threads. ## How to Adjust the Stack Size Linux allows users to adjust the stack size as needed. Here are common ways to manage stack size: **1. Using limit** The **ulimit** command adjusts the stack size for a shell session. ```bash ulimit -s [size_in_kilobytes] ``` **Example:** To set the stack size to 4 MB, use: ```bash ulimit -s 4096 ``` **2. Setting Stack Size in C/C++ Programs** For multithreaded programs in C or C++, use the pthread_attr_setstacksize function to control stack size for individual threads. ```bash pthread_attr_t attr; pthread_attr_init(&attr); pthread_attr_setstacksize(&attr, 1024 * 1024); // 1 MB stack size ``` **3. Modifying System-Wide Stack Size** Adjust the system-wide stack size in /etc/security/limits.conf. This affects all users. ```bash * soft stack 4096 * hard stack 4096 ``` ## Default Stack Size in Other Systems Different operating systems have varying default stack sizes: - **Windows:** 1 MB by default, configurable with linker options. - **macOS:** Uses 512 KB for threads by default. Linux’s larger default stack size aligns with its flexibility for running diverse applications and supporting deep recursion. ## Conclusion The default stack size in Linux may seem large, but it ensures reliability across a range of applications. While it can lead to memory waste, the benefits of stability and flexibility often outweigh the drawbacks. Developers and administrators can adjust stack sizes to optimize memory use, especially on systems with limited resources. Discover why Linux stack sizes matter on Atlantic.Net’s [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) and how they optimize your applications!. --- # How to Use the Linux chage Command Guide with Examples > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-use-the-linux-chage-command-guide-with-examples/ | Published: 2024-12-02 | Updated: 2024-12-05 | Author: Hitesh Jethva The chage command in Linux is used to manage password aging for user accounts. It allows system administrators to enforce password expiration policies, making it a vital tool for maintaining system security. This guide will walk you through the basics of using chage with practical examples to help you manage user accounts effectively. ## Understanding Password Aging Password aging allows administrators to set rules about how often users must change their passwords. This helps enhance system security by reducing the chances of compromised accounts due to outdated credentials. The chage command is used to manage the aging policies. The syntax of the chage command is: ```bash chage [options] username ``` **Where:** - **username:** Specifies the name of the user for whom you want to manage password settings. - **options** allow you to control various aspects like password expiration, warning periods, and inactivity. ## Checking User Password Aging Information You can use chage without any options to view the current password aging information for a user. ```bash chage -l username ``` Output: ```bash Last password change : Aug 20, 2024 Password expires : Nov 18, 2024 Password inactive : never Account expires : never Minimum number of days between password change : 0 Maximum number of days between password change : 90 Number of days of warning before password expires : 7 ``` The **-l** (list) flag shows password information like last password change, account expiration, and password expiry dates. ## Setting Password Expiration The **-M** option is used to set the maximum number of days a password remains valid. After this period, users are forced to change their password. ```bash chage -M 60 username ``` This sets the maximum password validity to 60 days. Users will be required to change their passwords every 60 days. ## Setting Minimum Days Between Password Changes You can use the **-m** option to set the minimum number of days between password changes. ```bash chage -m 7 username ``` This sets a minimum of 7 days between password changes. ## Setting a Password Expiry Warning Period The **-W** option sets the number of days before password expiration when the user will start receiving warnings. ```bash chage -W 10 username ``` Users will receive a warning to change their password starting 10 days before it expires. ## Setting an Account Expiration Date The **-E** option is used to set an account expiration date, after which the account is disabled. ```bash chage -E 2024-12-31 username ``` After December 31, 2024, the user account will expire, preventing the user from logging in. ## Making Password Inactive After Expiry The **-I** option sets the number of days after a password has expired before the account becomes inactive. ```bash chage -I 30 username ``` The account will become inactive 30 days after the password has expired if the user does not update their password. ## Setting All Password Aging Options at Once You can use the -M, -m, -W, -I, and -E options together to fully configure the password aging policy for a user. ```bash chage -M 90 -m 10 -W 7 -I 15 -E 2024-12-31 username ``` This command sets up a comprehensive password policy as shown below: - **Maximum validity:** 90 days - **Minimum days between changes:** 10 days - **Warning period:** 7 days - **Account becomes inactive:** 15 days after password expiry - **Account expires on:** December 31, 2024 ## Conclusion The chage command is an essential tool for managing password policies on Linux. It allows system administrators to enforce security practices and ensure users regularly update their credentials. The powerful Linux chage command can manage user password policies on Atlantic.Net’s [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/). --- # How to Use curl with a Specific Interface > URL: https://www.atlantic.net/dedicated-server-hosting/how-to-use-curl-with-a-specific-interface/ | Published: 2024-12-03 | Author: Hitesh Jethva The curl command is one of the most widely used tools for data transfers in Linux. It supports various protocols, including HTTP, FTP, and SMTP. By default, curl will use the system’s default network interface to make requests. However, there are scenarios where you may want to specify a particular interface for outgoing connections, such as when you have multiple network interfaces or VPN connections. In this guide, we’ll discuss how to use curl with a specific interface. ## Understanding Network Interfaces A network interface in Linux represents a connection point for data communication between the operating system and a physical or virtual network. Examples of network interfaces are: - **eth0:** The default Ethernet connection. - **wlan0:** The wireless network adapter. - **tun0:** VPN tunnel interfaces. When you have multiple active interfaces, you might want to control which interface curl uses for its requests. ## Basic Usage of curl with –interface The **–interface** option allows you to use a specific network interface for the request. The syntax is: ```bash curl --interface interface_name url ``` - **interface_name:** This can be an interface name (e.g., eth0), an IP address, or a hostname. - **url:** The URL you wish to access. **Example:** ```bash curl --interface eth0 https://example.com ``` In this example, curl will use the eth0 network interface to access https://example.com. ## Specifying an IP Address Instead of specifying the interface name, you can use an IP address assigned to the interface. This method is beneficial if you have multiple IP addresses and want to control which one curl uses for outgoing requests. **Example:** ```bash curl --interface 192.168.1.10 https://example.com ``` Here, **192.168.1.10** is the IP address of the network interface you want to use. ## Using a VPN Interface When connected to a VPN, the virtual network interface is usually named something like tun0 or ppp0. You can specify that interface to ensure that all requests go through the VPN. **Example:** ```bash curl --interface tun0 https://example.com ``` This forces curl to use the VPN connection (tun0) instead of the default network interface. ## Verifying the Interface Used To verify that curl is using the specified interface, you can use tcpdump or Wireshark to monitor traffic. **Example with tcpdump:** ```bash tcpdump -i eth0 ``` - Run this command to observe all packets on the eth0 interface. - If curl is correctly using eth0, you will see the HTTP request packets in the output. ## Advanced Options for curl If you want to specify whether to use IPv4 or IPv6, you can combine the **–interface** option with **-4** or **-6.** ```bash curl -4 --interface eth0 https://example.com ``` **Example:** ```bash curl -v --interface eth0 https://example.com ``` ## Conclusion The curl command in Linux is a powerful utility for interacting with URLs from the command line. By using the –interface option, you can easily specify which network interface or IP address to use. This method is very useful when working with multiple connections or testing network configurations. Master using curl with a specific network interface on Atlantic.Net’s [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) for optimized connectivity! --- # How to Install NVIDIA CUDA Toolkit on Atlantic.Net GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-install-nvidia-cuda-toolkit-on-atlantic-cloud-gpu-server/ | Published: 2024-12-04 | Updated: 2024-12-12 | Author: Hitesh Jethva The NVIDIA CUDA Toolkit is a powerful development suite for accelerating computationally intensive applications using the GPU’s parallel processing capabilities. CUDA, short for Compute Unified Device Architecture, is a parallel computing platform and programming model developed by NVIDIA. It allows developers to leverage the processing power of NVIDIA GPUs (Graphics Processing Units) to perform general-purpose computing tasks that go beyond graphics rendering. CUDA is particularly important for high-performance computing, artificial intelligence (AI), machine learning (ML), and deep learning applications. It provides developers with a software environment for writing applications that can run in parallel on thousands of GPU cores, offering significant speed improvements compared to traditional CPU-based computations. In this guide, we’ll show you how to install and setup the NVIDIA CUDA Toolkit on your Atlantic.Net GPU server. ## Prerequisites - An Ubuntu 22.04 GPU Server - A root or sudo privileges ## Step 1: Update System Packages Start by updating the system package list to ensure your environment is equipped with the latest updates and patches. ```bash apt update -y ``` ## Step 2: Verify Your GPU Compatibility To confirm that your GPU supports CUDA, run the following command: ```bash lspci | grep -i nvidia ``` This command lists all NVIDIA GPUs detected by your system. Example output: ```bash 06:00.0 VGA compatible controller: NVIDIA Corporation GA102GL [A40] (rev a1) ``` If the output lists an NVIDIA GPU, your system is CUDA-compatible. If no NVIDIA GPU is listed, update the PCI hardware database and rerun the lspci command: ```bash update-pciids ``` ## Step 3: Check GCC Compiler Version CUDA requires a supported version of the GNU Compiler Collection (GCC). Verify the installed version with: ```bash gcc --version ``` Example output: ```bash gcc (Ubuntu 11.4.0-1ubuntu1~22.04) 11.4.0 Copyright (C) 2021 Free Software Foundation, Inc. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. ``` If your GCC version is outdated, install or update it using: ```bash apt install gcc -y ``` ## Step 4: Download and Install NVIDIA CUDA Toolkit Visit the [**CUDA Toolkit Archive files page**](https://developer.nvidia.com/cuda-downloads?target_os=Linux&target_arch=x86_64) and download the NVIDIA CUDA keyring using the below command. ```bash wget https://developer.download.nvidia.com/compute/cuda/repos/ubuntu2204/x86_64/cuda-keyring_1.1-1_all.deb ``` Install the downloaded package with dpkg command: ```bash dpkg -i cuda-keyring_1.1-1_all.deb ``` Refresh the package index to recognize NVIDIA’s repository: ```bash apt-get update ``` Install the CUDA Toolkit version 12.6 using: ```bash apt-get -y install cuda-toolkit-12-6 ``` This command downloads and installs the necessary files, including the CUDA compiler, libraries, and tools. ## Step 5: Configure Environment Variables To ensure the CUDA Toolkit functions seamlessly, you will need to update the system environment variables. Append the CUDA binary directory to the PATH variable: ```bash echo "export PATH=/usr/local/cuda-12.6/bin${PATH:+:${PATH}}" >> ~/.bashrc ``` Include the CUDA library directory in the LD_LIBRARY_PATH: ```bash echo "export LD_LIBRARY_PATH=/usr/local/cuda-12.6/lib64${LD_LIBRARY_PATH:+:${LD_LIBRARY_PATH}}" >> ~/.bashrc ``` Activate the updated environment variables: ```bash source ~/.bashrc ``` By configuring these variables, the system knows where to find CUDA executables and libraries. ## Step 6: Verify the Installation Verify the GPU driver installation using NVIDIA System Management Interface (SMI): ```bash nvidia-smi ``` Output: ![](https://www.atlantic.net/wp-content/uploads/2024/11/p1.png) Ensure the NVIDIA CUDA Compiler (NVCC) is installed: ```bash nvcc --version ``` Output: ```bash nvcc: NVIDIA (R) Cuda compiler driver Copyright (c) 2005-2024 NVIDIA Corporation Built on Tue_Oct_29_23:50:19_PDT_2024 Cuda compilation tools, release 12.6, V12.6.85 Build cuda_12.6.r12.6/compiler.35059454_0 ``` ## Step 7: Test CUDA Installation with Sample Programs Download sample CUDA programs for testing the installation. ```bash git clone https://github.com/NVIDIA/cuda-samples.git ``` Switch to the directory containing the deviceQuery sample: ```bash cd cuda-samples/Samples/1_Utilities/deviceQuery ``` Build the deviceQuery program: ```bash make ``` Execute the deviceQuery program to test CUDA functionality: ```bash ./deviceQuery ``` If the program runs successfully, your CUDA installation is complete. ![](https://www.atlantic.net/wp-content/uploads/2024/11/p2.png) ## Conclusion Installing the NVIDIA CUDA Toolkit on an Atlantic.Net GPU server enables you to harness the power of GPU computing for complex applications. With this guide, you’ve verified your GPU compatibility, installed the CUDA Toolkit, configured environment variables, and tested the setup with sample programs. You’re now ready to develop and run CUDA-accelerated applications. Dive into [**Atlantic.Net’s GPU server hosting**](https://www.atlantic.net/gpu-server-hosting/) options and explore the possibilities CUDA offers! --- # How to Install NVIDIA cuDNN on Atlantic.Net GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-install-nvidia-cudnn-on-atlantic-cloud-gpu-server/ | Published: 2024-12-05 | Updated: 2024-12-12 | Author: Hitesh Jethva The NVIDIA CUDA Deep Neural Network library (cuDNN) is a GPU-accelerated library designed to optimize deep learning operations. cuDNN serves as a key component for training and deploying neural networks efficiently on NVIDIA GPUs. It is widely used in frameworks such as TensorFlow, PyTorch, and Caffe to accelerate operations like convolution, pooling, and activation functions. This guide will help you install and verify cuDNN on an Ubuntu 22.04 GPU server. ## Prerequisites - An Ubuntu 22.04 GPU Server - CUDA Toolkit installed - A root or sudo privileges ## Step 1: Verify NVIDIA GPU Drivers Before proceeding with cuDNN installation, verify that your NVIDIA GPU drivers are correctly installed and functioning. ```bash nvidia-smi ``` This command displays the status of your GPU and driver installation. Example output: ```bash Mon Nov 25 08:18:16 2024 +-----------------------------------------------------------------------------------------+ | NVIDIA-SMI 550.90.07 Driver Version: 550.90.07 CUDA Version: 12.4 | |-----------------------------------------+------------------------+----------------------+ | GPU Name Persistence-M | Bus-Id Disp.A | Volatile Uncorr. ECC | | Fan Temp Perf Pwr:Usage/Cap | Memory-Usage | GPU-Util Compute M. | | | | MIG M. | |=========================================+========================+======================| | 0 NVIDIA A16-2Q On | 00000000:06:00.0 Off | 0 | | N/A N/A P0 N/A / N/A | 1398MiB / 2048MiB | 0% Default | | | | N/A | +-----------------------------------------+------------------------+----------------------+ +-----------------------------------------------------------------------------------------+ | Processes: | | GPU GI CI PID Type Process name GPU Memory | | ID ID Usage | |=========================================================================================| ``` ## Step 2: Add NVIDIA Package Repository NVIDIA distributes cuDNN through its package repository. Adding this repository ensures you install the latest and most secure version. Visit the [**cuDNN download page**](https://developer.nvidia.com/rdp/cudnn-download) and download the NVIDIA keyring with the following command. ```bash wget https://developer.download.nvidia.com/compute/cuda/repos/ubuntu2204/x86_64/cuda-keyring_1.1-1_all.deb ``` Install the downloaded keyring package using: ```bash dpkg -i cuda-keyring_1.1-1_all.deb ``` Refresh your system’s package list to include NVIDIA’s repository: ```bash apt-get update ``` Adding the repository ensures you’re downloading official, trusted packages directly from NVIDIA, reducing the risk of compatibility issues. ## Step 3: Install NVIDIA cuDNN cuDNN is available in different versions depending on the installed CUDA version. Make sure to choose the correct package. Install the cuDNN package using the following command. ```bash apt-get -y install cudnn ``` This command installs the standard cuDNN package, which works with most CUDA installations. For systems running CUDA 12, install the version-specific cuDNN package: ```bash apt-get -y install cudnn-cuda-12 ``` ## Step 4: Verify cuDNN Installation After installation, it’s important to confirm that cuDNN is correctly set up on your system. Check the installed version of cuDNN by reading the version header file: ```bash cat /usr/include/cudnn_version.h | grep CUDNN_MAJOR -A 2 ``` Output. ```bash #define CUDNN_MAJOR 9 #define CUDNN_MINOR 5 #define CUDNN_PATCHLEVEL 1 -- #define CUDNN_VERSION (CUDNN_MAJOR * 10000 + CUDNN_MINOR * 100 + CUDNN_PATCHLEVEL) /* cannot use constexpr here since this is a C-only file */ ``` This output confirms the installed version of cuDNN (in this example, 9.5.1). The CUDNN_VERSION macro calculates the complete version number. ## Step 5: Verify NVIDIA Drivers (Post Installation) Re-check your GPU drivers to ensure they are functioning correctly after installing cuDNN: ```bash nvidia-smi ``` The output should remain consistent with your earlier results, confirming that cuDNN installation did not affect the drivers. ![](https://www.atlantic.net/wp-content/uploads/2024/11/p2-1.png) ## Conclusion Installing NVIDIA cuDNN on Ubuntu 22.04 empowers your system for efficient GPU-based deep learning tasks. With the steps above, you’ve added the NVIDIA repository, installed cuDNN, and verified its setup. Your system is now ready to accelerate neural network training and inference tasks. Explore the possibilities of cuDNN and take your deep learning workflows to the next level using [**GPU Hosting**](https://www.atlantic.net/gpu-server-hosting/) from Atlantic.Net. --- # How to Install K3s with NVIDIA GPU Operator on Ubuntu 22.04 > URL: https://www.atlantic.net/gpu-server-hosting/how-to-install-k3s-with-nvidia-gpu-operator-on-ubuntu-22-04/ | Published: 2024-12-06 | Updated: 2024-12-12 | Author: Hitesh Jethva K3s is a lightweight Kubernetes distribution designed for simplicity, scalability, and fast deployments. It is perfect for running Kubernetes clusters on resource-constrained environments or edge devices. When combined with the NVIDIA GPU Operator, it unlocks the full potential of GPUs in containerized workloads, allowing developers to run GPU-accelerated applications efficiently. This guide provides a step-by-step tutorial on installing K3s and configuring it with NVIDIA GPU Operator on Ubuntu 22.04. ## Prerequisites - An Ubuntu 22.04 GPU Server - At least 8GB of RAM and 20GB of free disk space (for GPU-accelerated workloads). - A root or sudo privileges ## Step 1: Verify GPU Availability Ensuring that your NVIDIA GPU is detected and operational is a critical first step. This guarantees compatibility with the NVIDIA Container Toolkit and GPU Operator. ```bash nvidia-smi ``` Output. ```bash Mon Nov 25 04:45:16 2024 +-----------------------------------------------------------------------------------------+ | NVIDIA-SMI 550.90.07 Driver Version: 550.90.07 CUDA Version: 12.4 | |-----------------------------------------+------------------------+----------------------+ | GPU Name Persistence-M | Bus-Id Disp.A | Volatile Uncorr. ECC | | Fan Temp Perf Pwr:Usage/Cap | Memory-Usage | GPU-Util Compute M. | | | | MIG M. | |=========================================+========================+======================| | 0 NVIDIA A40-2Q On | 00000000:06:00.0 Off | 0 | | N/A N/A P0 N/A / N/A | 1MiB / 2048MiB | 0% Default | | | | N/A | +-----------------------------------------+------------------------+----------------------+ +-----------------------------------------------------------------------------------------+ | Processes: | | GPU GI CI PID Type Process name GPU Memory | | ID ID Usage | |=========================================================================================| | No running processes found | +-----------------------------------------------------------------------------------------+ ``` If no GPU is detected, ensure the GPU is properly installed and powered. ## Step 2: Disable Swap Kubernetes requires swap to be disabled to manage resources efficiently. Swap conflicts with Kubernetes’ resource scheduling and can lead to unpredictable behavior. ```bash swapoff -a ``` To disable swap permanently, edit the **/etc/fstab** file and comment out the swap entry. Disabling swap ensures that Kubernetes nodes use actual memory for resource allocation. This improves stability and avoids node taints. ## Step 3: Install K3s K3s is a lightweight Kubernetes distribution, designed for edge devices and development environments. Its streamlined architecture eliminates unnecessary components, making it faster and easier to deploy than traditional Kubernetes. Run the following command to download and execute the K3s installation script. ```bash curl -sfL https://get.k3s.io | sh - ``` This command installs containerd as the default container runtime and configures essential services. Check the status of the K3s service: ```bash systemctl status k3s ``` Output. ```bash ● k3s.service - Lightweight Kubernetes Loaded: loaded (/etc/systemd/system/k3s.service; enabled; vendor preset: enabled) Active: active (running) since Mon 2024-11-25 04:46:26 UTC; 33s ago Docs: https://k3s.io Process: 9098 ExecStartPre=/bin/sh -xc ! /usr/bin/systemctl is-enabled --quiet nm-cloud-setup.service 2>/dev/null (code=exited, status=0/SUCCESS) Process: 9100 ExecStartPre=/sbin/modprobe br_netfilter (code=exited, status=0/SUCCESS) Process: 9101 ExecStartPre=/sbin/modprobe overlay (code=exited, status=0/SUCCESS) Main PID: 9102 (k3s-server) Tasks: 86 Memory: 1.3G CPU: 21.304s CGroup: /system.slice/k3s.service ├─ 9102 "/usr/local/bin/k3s server" ``` Export the KUBECONFIG environment variable to access the K3s cluster. ```bash export KUBECONFIG=/etc/rancher/k3s/k3s.yaml ``` List the nodes in your K3s cluster. ```bash kubectl get nodes ``` Output. ```bash NAME STATUS ROLES AGE VERSION ubuntu Ready control-plane,master 83s v1.30.6+k3s1 ``` ## Step 4: Install NVIDIA Container Toolkit The NVIDIA Container Toolkit allows containerized applications to access GPU resources. It is a critical component for running GPU workloads in Kubernetes. Add the NVIDIA repository. ```bash curl -fsSL https://nvidia.github.io/libnvidia-container/gpgkey | gpg --dearmor -o /usr/share/keyrings/nvidia-container-toolkit-keyring.gpg && curl -s -L https://nvidia.github.io/libnvidia-container/stable/deb/nvidia-container-toolkit.list | sed 's#deb https://#deb [signed-by=/usr/share/keyrings/nvidia-container-toolkit-keyring.gpg] https://#g' | tee /etc/apt/sources.list.d/nvidia-container-toolkit.list ``` Update the repository index. ```bash apt-get update ``` Install the container toolkit. ```bash apt-get install -y nvidia-container-toolkit ``` Check the installed version of the NVIDIA Container CLI: ```bash nvidia-container-cli --version ``` Output. ```bash cli-version: 1.17.2 lib-version: 1.17.2 ``` Configure Docker for GPU support. ```bash nvidia-ctk runtime configure --runtime=docker ``` Restart Docker to apply the configuration: ```bash systemctl restart docker ``` Run a container with GPU access to verify the setup: ```bash docker run --rm --gpus all nvidia/cuda:12.6.2-cudnn-runtime-ubuntu22.04 nvidia-smi ``` Output. ```bash ========== == CUDA == ========== CUDA Version 12.6.2 Container image Copyright (c) 2016-2023, NVIDIA CORPORATION & AFFILIATES. All rights reserved. This container image and its contents are governed by the NVIDIA Deep Learning Container License. By pulling and using the container, you accept the terms and conditions of this license: https://developer.nvidia.com/ngc/nvidia-deep-learning-container-license A copy of this license is made available in this container at /NGC-DL-CONTAINER-LICENSE for your convenience. Mon Nov 25 04:57:39 2024 +-----------------------------------------------------------------------------------------+ | NVIDIA-SMI 550.90.07 Driver Version: 550.90.07 CUDA Version: 12.6 | |-----------------------------------------+------------------------+----------------------+ | GPU Name Persistence-M | Bus-Id Disp.A | Volatile Uncorr. ECC | | Fan Temp Perf Pwr:Usage/Cap | Memory-Usage | GPU-Util Compute M. | | | | MIG M. | |=========================================+========================+======================| | 0 NVIDIA A40-2Q On | 00000000:06:00.0 Off | 0 | | N/A N/A P0 N/A / N/A | 1MiB / 2048MiB | 0% Default | | | | N/A | +-----------------------------------------+------------------------+----------------------+ +-----------------------------------------------------------------------------------------+ | Processes: | | GPU GI CI PID Type Process name GPU Memory | | ID ID Usage | |=========================================================================================| | No running processes found | +-----------------------------------------------------------------------------------------+ ``` ## Step 5: Install Helm Helm simplifies Kubernetes deployments by managing application packaging and upgrades. Install Helm using the script below. ```bash curl https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash ``` Verify the Helm installation. ```bash helm version ``` Output. ```bash version.BuildInfo{Version:"v3.16.3", GitCommit:"cfd07493f46efc9debd9cc1b02a0961186df7fdf", GitTreeState:"clean", GoVersion:"go1.22.7"} ``` ## Step 6: Deploy NVIDIA GPU Operator The NVIDIA GPU Operator automates the management of NVIDIA GPU drivers, monitoring tools, and runtime in Kubernetes. Add the NVIDIA Helm repository. ```bash helm repo add nvidia https://nvidia.github.io/gpu-operator ``` Update the repository. ```bash helm repo update ``` Install GPU operator. ```bash helm install --wait --generate-name nvidia/gpu-operator ``` Verify the deployment. ```bash kubectl get pods | grep nvidia ``` This command will list all NVIDIA-related pods in the cluster: **Please note:** it may take some time for the pods to start ```bash nvidia-container-toolkit-daemonset-cl2s5 1/1 Running 0 2m36s nvidia-cuda-validator-r6pl4 0/1 Evicted 0 2m26s nvidia-dcgm-exporter-bt8jp 1/1 Running 0 2m35s nvidia-device-plugin-daemonset-gtgwv 1/1 Running 0 2m35s nvidia-operator-validator-cbd9z 0/1 Init:2/4 0 2m36s ``` Ensure that the NVIDIA GPU Operator has configured the nodes correctly. ```bash kubectl describe nodes | grep nvidia ``` You should see the information about the GPU resources managed by the NVIDIA GPU Operator. ![](https://www.atlantic.net/wp-content/uploads/2024/11/p1-1.png) ## Conclusion You’ve successfully installed K3s with the NVIDIA GPU Operator on Ubuntu 22.04. This setup allows you to run GPU-accelerated workloads on a lightweight Kubernetes cluster, enabling efficient deployment of machine learning, AI, and other compute-intensive applications. Try to deploy K3s on [**Atlantic.Net GPU Hosting**](https://www.atlantic.net/gpu-server-hosting/). --- # Setting Up Your Deep Learning Environment on Atlantic.Net GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/setting-up-your-deep-learning-environment-on-atlantic-cloud-gpu-server/ | Published: 2024-12-09 | Updated: 2024-12-12 | Author: Hitesh Jethva Deep learning has revolutionized industries like healthcare, finance, and gaming by enabling the creation of highly sophisticated models capable of performing complex tasks. These models, however, require immense computational power, and GPUs (Graphics Processing Units) play a critical role in accelerating this process. Atlantic.Net’s GPU dedicated servers offer a high-performance GPU infrastructure, making it an ideal platform for deep learning projects. This guide will walk you through the entire process of setting up a deep learning environment on an Atlantic.Net GPU Server. ## Prerequisites - An Ubuntu 22.04 GPU Server - CUDA Toolkit and cuDNN Installed - A root or sudo privileges ## Verify NVIDIA GPU The first step in any GPU-accelerated setup is ensuring that your system detects the GPU. Atlantic.Net GPU server instances come pre-configured with GPU hardware, but verifying its availability is crucial. ```bash lspci | grep -i nvidia ``` Output. ```bash 00:1e.0 3D controller: NVIDIA Corporation GP102 [Tesla P40] (rev a1) ``` If no GPU is detected, ensure that your server is configured with GPU support. ## Install Anaconda Anaconda is a powerful tool for managing Python environments and packages, which is especially useful in deep learning projects where dependency management is critical. Visit the official [**Anaconda Archives Directory**](https://repo.anaconda.com/archive/) to find the latest installer. For this guide, we’ll use a specific version. ```bash wget https://repo.anaconda.com/archive/Anaconda3-2024.10-1-Linux-x86_64.sh ``` Execute the downloaded script: ```bash bash Anaconda3-2024.10-1-Linux-x86_64.sh ``` You will be asked the following: - Accept the license agreement by typing yes. - Confirm the installation directory (default is typically /home/your-username/anaconda3). - Allow the installer to initialize Anaconda. Reload your .bashrc file to enable Anaconda. ```bash source ~/.bashrc ``` Confirm that Anaconda is correctly installed by checking its version. ```bash conda --version ``` Output. ```bash conda 24.9.2 ``` ## Set Up Your Deep Learning Environment Creating an isolated environment for deep learning ensures that dependencies and libraries do not conflict with other projects. Create a new conda environment. ```bash conda create -n deep_learning python=3.9 ``` Activate the environment. ```bash conda activate deep_learning ``` Your terminal prompt should now include (deep_learning), indicating the environment is active. ## Install TensorFlow and PyTorch with GPU Support Leveraging GPU acceleration with TensorFlow and PyTorch drastically improves the speed of training deep learning models. Install TensorFlow using conda. ```bash conda install -c conda-forge tensorflow ``` Install the NVIDIA CUDA Toolkit for the Anaconda environment. ```bash conda install -c "nvidia/label/cuda-12.4.1" cuda ``` Install PyTorch and libraries. ```bash pip install torch torchvision torchaudio --pre -f https://download.pytorch.org/whl/nightly/cu124/torch_nightly.html ``` This installs the nightly version of PyTorch optimized for CUDA 12.4. Install additional libraries. ```bash conda install numpy pandas matplotlib ``` These libraries are useful for: - Data manipulation (numpy, pandas). - Visualization (matplotlib). ## Test Your Installation Now, you will need to ensures that TensorFlow, PyTorch, and GPU acceleration are working as expected. Start Python using the following command. ```bash python3 ``` In the Python shell, import both tensorflow and torch library. ```bash >>> import tensorflow as tf >>> import torch ``` Check the TensorFlow version. ```bash >>> print("TensorFlow version:", tf.__version__) ``` Output. ```bash TensorFlow version: 2.17.0 ``` Verify the PyTorch version. ```bash >>> print("PyTorch version:", torch.__version__) ``` Output. ```bash PyTorch version: 2.5.1+cu124 ``` Press **CTRL+D** to exit from the Python shell. Check if TensorFlow detects the GPU. ```bash python -c "import tensorflow as tf; print(tf.config.list_physical_devices('GPU'))" ``` Expected output: ```bash [PhysicalDevice(name='/physical_device:GPU:0', device_type='GPU')] ``` ## Conclusion Congratulations! You have successfully set up a deep learning environment on an Atlantic.Net GPU server. With TensorFlow and PyTorch configured to leverage GPU acceleration, you can now train and deploy complex models efficiently. [**Atlantic.Net GPU Server Hosting**](https://www.atlantic.net/gpu-server-hosting/) provides a robust platform for AI and deep learning, empowering you to focus on innovation without worrying about hardware limitations. --- # How to Install and Use Jupyter Notebook on a Atlantic Cloud GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-install-and-use-jupyter-notebook-on-a-atlantic-cloud-gpu-server/ | Published: 2024-12-10 | Updated: 2024-12-12 | Author: Hitesh Jethva Jupyter Notebook is an open-source, interactive computing environment that supports data visualization, analysis, and machine learning workflows. When paired with a GPU-enabled Atlantic.Net server, it allows for accelerated computations, making it an excellent choice for tasks like deep learning and large-scale data processing. This guide will walk you through setting up and using Jupyter Notebook on a GPU-enabled Atlantic.Net server. ## Prerequisites - An Ubuntu 22.04 GPU Server - CUDA Toolkit and cuDNN Installed - A root or sudo privileges ## Step 1: Update the Server To ensure the latest updates and security patches are included, run: ```bash apt update -y apt upgrade -y ``` This updates the package repository and upgrades outdated packages. ## Step 2: Install Python and Required Packages Jupyter Notebook is built on Python, and its ecosystem relies on Python libraries for everything from data visualization to machine learning. Install Python and pip. ```bash apt install python3 python3-pip -y ``` Check the versions of Python and pip to confirm the installation: ```bash python3 --version pip3 --version ``` Install libraries required for machine learning and data analysis: ```bash pip install tensorflow torch matplotlib pandas numpy ``` These packages include popular frameworks like TensorFlow and PyTorch, along with essential libraries for data manipulation and visualization. ## Step 3: Install and Configure Jupyter Notebook Kernel A kernel is the engine that executes the code in your notebooks. Configuring a kernel ensures it has access to the installed libraries and GPU resources. Install the ipykernel package. ```bash pip install ipykernel ``` Create a custom kernel for Jupyter. ```bash python3 -m ipykernel install --user --name=gpu_env --display-name "Python (GPU)" ``` Output. ```bash Installed kernelspec gpu_env in /root/.local/share/jupyter/kernels/gpu_env ``` This kernel links your Python environment to Jupyter Notebook, ensuring it recognizes the GPU-enabled libraries. ## Step 4: Install Jupyter Notebook Install Jupyter Notebook using pip. ```bash pip install notebook ``` Verify the installation by checking its version. ```bash jupyter notebook --version ``` Output. ```bash 7.2.2 ``` Generate a configuration file to enable remote access. ```bash jupyter notebook --generate-config ``` Edit the generated configuration file to enable access over the network. ```bash nano ~/.jupyter/jupyter_notebook_config.py ``` Add the following lines: ```bash c.ServerApp.ip = '0.0.0.0' c.ServerApp.open_browser = False c.ServerApp.port = 8888 ``` ## Step 5: Test Jupyter Notebook for GPU Support Before launching Jupyter Notebook, verify that your GPU is accessible: Open a Python shell. ```bash python3 ``` Check PyTorch GPU availability. ```bash >>>import torch >>>print("PyTorch GPU Support:", torch.cuda.is_available()) ``` Output. ```bash PyTorch GPU Support: True ``` Test TensorFlow GPU support. ```bash >>>import tensorflow as tf >>>print("TensorFlow GPU Devices:", tf.config.list_physical_devices('GPU')) ``` Output. ```bash TensorFlow GPU Devices: [PhysicalDevice(name='/physical_device:GPU:0', device_type='GPU')] ``` These tests confirm that your GPU is ready for computation. ## Step 6: Launch Jupyter Notebook Start Jupyter Notebook on your server with the following command. ```bash jupyter notebook --no-browser --port=8888 --ip=your-server-ip --allow-root ``` Replace **your-server-ip** with the server’s public IP address. The output will display a URL to access the notebook: ```bash To access the server, open this file in a browser: file:///root/.local/share/jupyter/runtime/jpserver-8084-open.html Or copy and paste one of these URLs: http://45.77.182.191:8888/tree?token=8e99e04461348b61490e1a51559a8be313840260787e7e17 http://127.0.0.1:8888/tree?token=8e99e04461348b61490e1a51559a8be313840260787e7e17 ``` ## Step 7: Run a PyTorch Model in Jupyter Notebook Open your web browser and access the Jupyter Notebook using the URL **http://your-server-ip:8888/tree?token=8e99e04461348b61490e1a51559a8be313840260787e7e17.** ![](https://www.atlantic.net/wp-content/uploads/2024/11/p1-3.png) Click on **File** > **New** > **Notebook.** You will be asked to select the Kernel. ![](https://www.atlantic.net/wp-content/uploads/2024/11/p2-2.png) Select the **“Python (GPU)”** kernel and click **Select** to create a new notebook. Add the following code to train a simple PyTorch model. ```bash import torch import torch.nn as nn import torch.optim as optim # Check GPU availability device = torch.device('cuda' if torch.cuda.is_available() else 'cpu') print(f"Using device: {device}") # Simple linear model model = nn.Linear(10, 1).to(device) print(model) # Sample data inputs = torch.randn(100, 10).to(device) targets = torch.randn(100, 1).to(device) # Loss and optimizer criterion = nn.MSELoss() optimizer = optim.SGD(model.parameters(), lr=0.01) # Training loop for epoch in range(5): optimizer.zero_grad() outputs = model(inputs) loss = criterion(outputs, targets) loss.backward() optimizer.step() print(f"Epoch {epoch+1}, Loss: {loss.item()}") ``` ![](https://www.atlantic.net/wp-content/uploads/2024/11/p3.png) Now, click on the **run** symbol to run your Notebook. This will print the loss for each epoch, confirming the GPU is being used if device is cuda. ![](https://www.atlantic.net/wp-content/uploads/2024/11/p4.png) ## Step 8: Monitor GPU Usage For the above examples, you can use the **nvidia-smi** command in the server’s terminal to monitor GPU utilization: ```bash nvidia-smi ``` If the models are correctly using the GPU, you will see GPU memory and utilization metrics updating during training. ```bash Mon Nov 25 08:18:16 2024 +-----------------------------------------------------------------------------------------+ | NVIDIA-SMI 550.90.07 Driver Version: 550.90.07 CUDA Version: 12.4 | |-----------------------------------------+------------------------+----------------------+ | GPU Name Persistence-M | Bus-Id Disp.A | Volatile Uncorr. ECC | | Fan Temp Perf Pwr:Usage/Cap | Memory-Usage | GPU-Util Compute M. | | | | MIG M. | |=========================================+========================+======================| | 0 NVIDIA A16-2Q On | 00000000:06:00.0 Off | 0 | | N/A N/A P0 N/A / N/A | 1398MiB / 2048MiB | 0% Default | | | | N/A | +-----------------------------------------+------------------------+----------------------+ +-----------------------------------------------------------------------------------------+ | Processes: | | GPU GI CI PID Type Process name GPU Memory | | ID ID Usage | |=========================================================================================| | 0 N/A N/A 8257 C /usr/bin/python3 1397MiB | +-----------------------------------------------------------------------------------------+ ``` ## Conclusion By following this guide, you’ve set up a powerful Jupyter Notebook environment on an [**Atlantic.Net GPU Server**](https://www.atlantic.net/gpu-server-hosting/). This setup empowers you to perform high-performance data analysis and machine learning tasks with ease. Make sure to explore additional Jupyter features like extensions and plugins to further enhance your productivity. --- # How to Extract Tables from Images on an Atlantic.Net GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-extract-tables-from-images-on-an-atlantic-net-gpu-server/ | Published: 2024-12-11 | Updated: 2024-12-12 | Author: Hitesh Jethva Extracting tables from images is a common requirement in data extraction and document processing workflows. With the power of GPU computing and tools like Tesseract OCR and Camelot, we can automate this process effectively. This guide explains how to set up a Python-based solution on an Ubuntu 22.04 GPU server to extract tables from images. ## Prerequisites Before starting, ensure you have the following: - A GPU-enabled server running Ubuntu 22.04. - Access to an Atlantic.Net GPU server or any other GPU-enabled environment. - NVIDIA Drivers and CUDA Toolkit. ## Step 1: Install Python and Required Libraries Ensure your server has Python and essential libraries installed: ``` apt install python3 python3-pip imagemagick ghostscript python3.10-venv -y ``` Here: - **imagemagick:** For image preprocessing. - **ghostscript:** For handling PDFs. - **python3.10-venv:** To create isolated Python environments. ## Step 2: Install PyTorch with GPU Support **PyTorch** is a popular framework for machine learning and image processing. Installing it with GPU support ensures optimal performance. ``` pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu124 ``` Here: - **torch, torchvision,** and **torchaudio** are essential PyTorch packages. - The **–index-url** specifies the CUDA-enabled PyTorch repository for GPU support. You can verify the installation using: ``` python3 -c "import torch; print(torch.cuda.is_available())" ``` This should return **True** if GPU support is enabled. ## Step 3: Install Tesseract OCR **Tesseract** is a powerful OCR tool for extracting text from images. Install Tesseract OCR. ``` apt install tesseract-ocr libtesseract-dev -y ``` Verify the installation: ``` tesseract --version ``` You should see output similar to: ``` tesseract 4.1.1 ``` ## Step 4: Create a Python Virtual Environment 1. Create the project directory structure. ``` mkdir -p ~/table_extraction_project/{uploads,processed,output,scripts} ``` 2. Create a subdirectory for templates. ``` mkdir ~/table_extraction_project/scripts/templates ``` 3. Navigate to the project directory. ``` cd ~/table_extraction_project ``` 4. Create a Python virtual environment. ``` python3 -m venv venv ``` 5. Activate the virtual environment. ``` source venv/bin/activate ``` 6. Install required Python dependencies. ``` pip install flask pytesseract pillow numpy opencv-python camelot-py[cv] pandas pip install "PyPDF2<3.0.0" ``` ## Step 5: Create a Web Interface to Upload Images 1. Create an HTML template file for the upload interface. ``` nano scripts/templates/index.html ``` Add the following HTML code. ``` Table Extraction

Upload an Image

``` 2. Create a Flask backend application. ``` nano scripts/app.py ``` Add the following code. ``` from flask import Flask, request, render_template, send_from_directory import os import pytesseract from PIL import Image import camelot app = Flask(__name__) # Directories UPLOAD_FOLDER = 'uploads' PROCESSED_FOLDER = 'processed' OUTPUT_FOLDER = 'output' os.makedirs(UPLOAD_FOLDER, exist_ok=True) os.makedirs(PROCESSED_FOLDER, exist_ok=True) os.makedirs(OUTPUT_FOLDER, exist_ok=True) app.config['UPLOAD_FOLDER'] = UPLOAD_FOLDER @app.route('/') def index(): return render_template('index.html') @app.route('/upload', methods=['POST']) def upload_image(): if 'image' not in request.files: return "No file uploaded!", 400 file = request.files['image'] if file.filename == '': return "No selected file!", 400 filepath = os.path.join(app.config['UPLOAD_FOLDER'], file.filename) file.save(filepath) # Process image processed_filepath = process_image(filepath) table_filepath = extract_table(processed_filepath) return send_from_directory(OUTPUT_FOLDER, table_filepath, as_attachment=True) def process_image(filepath): from PIL import Image # Load and preprocess image image = Image.open(filepath) processed_filepath = os.path.join(PROCESSED_FOLDER, os.path.basename(filepath)) image.save(processed_filepath, dpi=(300, 300)) # Set resolution to 300 DPI return processed_filepath def extract_table(filepath): # Convert image to searchable PDF using Tesseract pdf_filepath = os.path.join(PROCESSED_FOLDER, os.path.basename(filepath).replace('.jpg', '')) os.system(f"tesseract {filepath} {pdf_filepath} -l eng pdf") pdf_filepath += ".pdf" # Tesseract appends ".pdf" # Check if PDF file was created if not os.path.exists(pdf_filepath): raise FileNotFoundError("Tesseract failed to generate the PDF file.") # Read table from the PDF tables = camelot.read_pdf(pdf_filepath) if len(tables) == 0: raise ValueError("No tables found in the PDF.") table_filepath = os.path.join(OUTPUT_FOLDER, "extracted_table.csv") tables[0].to_csv(table_filepath) return "extracted_table.csv" if __name__ == '__main__': app.run(host='0.0.0.0', port=5000) ``` This Flask app allows users to upload images, processes them into searchable PDFs with Tesseract-OCR, and extracts tables using Camelot, saving results as CSVs for download via a web interface. ## Step 6: Run the Flask Application Your application is now ready. It’s time to run and test it. 1. Navigate to the scripts folder. ``` cd ~/table_extraction_project/scripts ``` 2. Run the Flask app. ``` python3 app.py ``` Output. ``` * Serving Flask app 'app' * Debug mode: off WARNING: This is a development server. Do not use it in a production deployment. Use a production WSGI server instead. * Running on all addresses (0.0.0.0) * Running on http://127.0.0.1:5000 * Running on http://your-server-ip:5000 Press CTRL+C to quit ``` ## Step 7: Upload Images and Extract Tables 1. Open your web browser and access your application using the URL **http://your-server-ip:5000.** ![](https://www.atlantic.net/wp-content/uploads/2024/12/p1.png) 2. Click on the **Upload** button and upload a JPG image containing tables. Click on **Upload and Extract Table.** The server processes the image, extracts the table, and generates a downloadable CSV file. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p2.png) ## Conclusion This guide explains how to set up a [GPU-enabled server](https://www.atlantic.net/gpu-server-hosting/) to extract tables from images. By combining tools like Tesseract, Camelot, and Flask, you can automate table extraction tasks efficiently. This workflow is ideal for businesses or researchers handling large volumes of tabular data in scanned documents. --- # How to Deploy ComfyUI on and Atlantic.Net GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-deploy-comfyui-on-and-atlantic-net-gpu-server/ | Published: 2024-12-12 | Updated: 2025-02-07 | Author: Hitesh Jethva ComfyUI is a versatile and user-friendly web interface designed for running AI models. It is widely used for tasks like image generation and other AI-driven workflows. By deploying it on a GPU-powered Atlantic.Net server, you can take advantage of high-performance hardware for faster and more efficient processing. Running ComfyUI on a dedicated server is ideal for users who need reliable performance without the limitations of local machines. It ensures that your infrastructure can handle computationally intensive tasks seamlessly. Atlantic.Net servers provide scalable GPU resources, making them perfect for AI applications. This guide will walk you through the process of deploying ComfyUI on an Atlantic.Net GPU server. ## Prerequisites Ensure you have the following before starting: - An Ubuntu 22.04 server with an NVIDIA GPU (minimum 6 GB GPU RAM). - NVIDIA Drivers and CUDA Toolkit installed. ## Step 1: Update and Install Python Dependencies 1. Update the package index and upgrade existing packages: ``` apt update apt upgrade -y ``` 2. If Python3 and pip3 are not already installed, install them. ``` apt install python3 python3-pip -y ``` ## Step 2: Install ComfyUI In this section, we will download ComfyUI and install the required dependencies for it. 1. Download the ComfyUI source code using Git. ``` git clone https://github.com/comfyanonymous/ComfyUI.git ``` 2. Navigate to the ComfyUI directory. ``` cd ComfyUI ``` 3. Install required dependency packages. ``` pip install "numpy<2" torch==2.1.0+cu121 torchvision==0.16.0+cu121 torchaudio==2.1.0+cu121 --extra-index-url https://download.pytorch.org/whl xformers ``` The above command installs the following packages: - **torch:** A library for machine learning. It provides tools for deep learning with a flexible computational graph. - **torchvision:** A library for computer vision. It includes utilities for image and video datasets, such as image classification and object detection. - **torchaudio:** A library for audio processing. It offers tools for loading, transforming, and working with audio datasets. - **xformers:** A library for transformer-based 4. Install additional dependencies. ``` pip install -r requirements.txt ``` 5. Navigate to the **models/checkpoints** directory. ``` cd models/checkpoints ``` 6. Create a **put_checkpoints_here** file. ``` nano put_checkpoints_here ``` Add the following lines to download Stable Diffusion models. ``` ## SDXL wget -c https://huggingface.co/stabilityai/stable-diffusion-xl-base-1.0/resolve/main/sd_xl_base_1.0.safetensors -P ./models/checkpoints/ wget -c https://huggingface.co/stabilityai/stable-diffusion-xl-refiner-1.0/resolve/main/sd_xl_refiner_1.0.safetensors -P ./models/checkpoints/ ## SD1.5 wget -c https://huggingface.co/runwayml/stable-diffusion-v1-5/resolve/main/v1-5-pruned-emaonly.ckpt -P ./models/checkpoints/ ## SD2 wget -c https://huggingface.co/stabilityai/stable-diffusion-2-1-base/resolve/main/v2-1_512-ema-pruned.safetensors -P ./models/checkpoints/ wget -c https://huggingface.co/stabilityai/stable-diffusion-2-1/resolve/main/v2-1_768-ema-pruned.safetensors -P ./models/checkpoints/ ``` Save the file. 7. Run the above file. ``` bash put_checkpoints_here ``` 8. Switch to your user home directory. ``` cd ``` 9. Move the ComfyUI project directory to a /opt directory. ``` mv ComfyUI /opt/ ``` ## Step 3: Configure ComfyUI as a System Service Now, you will need to create a system unit file to manage the ComfyUI service. 1. Create a new service file. ``` nano /etc/systemd/system/comfyui.service ``` Add the following configurations to the file. ``` [Unit] Description=ComfyUI System Service After=network.target [Service] WorkingDirectory=/opt/ComfyUI ExecStart=python3 main.py --disable-cuda-malloc [Install] WantedBy=multi-user.target ``` 2. Reload the systemd daemon to apply the changes. ``` systemctl daemon-reload ``` 3. Start and enable the ComfyUI system service. ``` systemctl enable comfyui systemctl start comfyui ``` 4. Check the service status. ``` systemctl status comfyui ``` Output. ``` ● comfyui.service - ComfyUI System Service Loaded: loaded (/etc/systemd/system/comfyui.service; enabled; vendor preset: enabled) Active: active (running) since Sat 2024-12-07 05:04:57 UTC; 5s ago Main PID: 8372 (python3) Tasks: 3 (limit: 14212) Memory: 849.9M CPU: 5.025s CGroup: /system.slice/comfyui.service └─8372 python3 main.py Dec 07 05:05:00 gpu-server python3[8372]: Python 3.10.13 (you have 3.10.12) Dec 07 05:05:00 gpu-server python3[8372]: Please reinstall xformers (see https://github.com/facebookresearch/xformers#installing-xformers) Dec 07 05:05:00 gpu-server python3[8372]: Memory-efficient attention, SwiGLU, sparse and more won't be available. Dec 07 05:05:00 gpu-server python3[8372]: Set XFORMERS_MORE_DETAILS=1 for more details Dec 07 05:05:01 gpu-server python3[8372]: xformers version: 0.0.22.post7+cu118 Dec 07 05:05:01 gpu-server python3[8372]: Set vram state to: NORMAL_VRAM Dec 07 05:05:01 gpu-server python3[8372]: Device: cuda:0 GRID A100D-8C : cudaMallocAsync Dec 07 05:05:02 gpu-server python3[8372]: Using pytorch cross attention Dec 07 05:05:03 gpu-server python3[8372]: [Prompt Server] web root: /opt/ComfyUI/web Dec 07 05:05:03 gpu-server python3[8372]: Successfully imported spandrel_extra_arches: support for non commercial upscale models. ``` ## Step 4: Configure Nginx as a Reverse Proxy By default, ComfyUI listens on the localhost port **8188.** You will need to set up a reverse proxy such as Nginx to forward all incoming connection requests to the backend port **8188** to enable access to the ComfyUI interface. 1. Install Nginx. ``` apt install nginx -y ``` 2. Create a new Nginx virtual host configuration file. ``` nano /etc/nginx/conf.d/comfyui.conf ``` Add the following configuration. ``` upstream backend { server 127.0.0.1:8188; } server { listen 80; listen [::]:80; server_name comfy.example.com; proxy_set_header Host $host; proxy_http_version 1.1; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header Sec-WebSocket-Extensions $http_sec_websocket_extensions; proxy_set_header Sec-WebSocket-Key $http_sec_websocket_key; proxy_set_header Sec-WebSocket-Version $http_sec_websocket_version; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "Upgrade"; location / { proxy_pass http://backend$request_uri; } } ``` 3. Test the Nginx configuration for errors. ``` nginx -t ``` Output. ``` nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` 4. Restart Nginx to apply the configuration changes. ``` systemctl restart nginx ``` ## Step 5: Access ComfyUI and Generate Images At this point, ComfyUI is installed and running on your server. You can now generate images using the ComfyUI web interface. 1. Visit the URL **http://comfy.example.com** using a web browser to access the ComfyUI interface. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p1-3.png) 2. Navigate to the Prompt node, and enter the prompt “**beautiful scenery nature glass bottle landscape, purple galaxy bottle**“. Also, enter a prompt in the respective node such as **“text,watermark”.** Then, click on **Queue** to generate a new image. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p2-3.png) 3. Wait for the image generation process to complete. Your generated image should appear in the Save Image node. ## Conclusion You’ve successfully deployed ComfyUI on your Atlantic.Net [GPU server](https://www.atlantic.net/gpu-server-hosting/). With the power of ComfyUI and stable diffusion models, you can now generate high-quality images directly from your web interface. --- # How to Deploy a Deep Learning Model with Streamlit > URL: https://www.atlantic.net/gpu-server-hosting/how-to-deploy-a-deep-learning-model-with-streamlit/ | Published: 2024-12-13 | Updated: 2024-12-17 | Author: Hitesh Jethva Machine learning (ML) and data science are transforming industries with intelligent solutions. However, deploying ML models as web applications can be challenging. It often requires knowledge of backend and frontend tools like Flask, React, or JavaScript. For many, this process is both complex and time-consuming. Streamlit is a game-changer for such scenarios. It enables machine learning engineers to create interactive web applications quickly without needing advanced web development skills. This Python-based, open-source framework is designed for data scientists and ML engineers. Applications built with Streamlit are easy to scale, making it ideal for both prototypes and production systems. In this guide, we’ll show you how to deploy a deep-learning model using Streamlit. You’ll learn to create a simple, interactive application in no time. ## Prerequisites Before starting the deployment, ensure you have the following: - An Ubuntu 22.04 server with an NVIDIA GPU. - NVIDIA Drivers and CUDA Toolkit. ## Step 1: Set Up Your Environment 1. Update your Ubuntu server to ensure all packages are up-to-date. ``` apt update apt upgrade -y ``` 2. If Python3 and pip3 are not already installed, install them. ``` apt install python3 python3-pip -y ``` 3. Install PyTorch with GPU support. ``` pip3 install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu124 ``` 4. Install Streamlit and other dependencies. ``` pip3 install streamlit pip3 install numpy pandas scikit-learn matplotlib ``` ## Step 2: Create the Streamlit Application 1. Create a new directory for your Streamlit app and navigate to it. ``` mkdir streamlit_app && cd streamlit_app ``` 2. The model uses **ImageNet** class labels to interpret predictions. Download the labels file: ``` wget https://gist.githubusercontent.com/ageitgey/4e1342c10a71981d0b491e1b8227328b/raw/24d78ea09a31fdff540a8494886e0051e3ad68f8/imagenet_classes.txt ``` 3. Create a new **Streamlit** app. ``` nano app.py ``` Add the following content: ``` """Create an Image Classification Web App using PyTorch and Streamlit.""" # import libraries from PIL import Image from torchvision import models, transforms import torch import streamlit as st # set title of app st.title("Simple Image Classification Application") st.write("") # enable users to upload images for the model to make predictions file_up = st.file_uploader("Upload an image", type = "jpg") def predict(image): """Return top 5 predictions ranked by highest probability. Parameters ---------- :param image: uploaded image :type image: jpg :rtype: list :return: top 5 predictions ranked by highest probability """ # create a ResNet model resnet = models.resnet101(pretrained = True) # transform the input image through resizing, normalization transform = transforms.Compose([ transforms.Resize(256), transforms.CenterCrop(224), transforms.ToTensor(), transforms.Normalize( mean = [0.485, 0.456, 0.406], std = [0.229, 0.224, 0.225] )]) # load the image, pre-process it, and make predictions img = Image.open(image) batch_t = torch.unsqueeze(transform(img), 0) resnet.eval() out = resnet(batch_t) with open('imagenet_classes.txt') as f: classes = [line.strip() for line in f.readlines()] # return the top 5 predictions ranked by highest probabilities prob = torch.nn.functional.softmax(out, dim = 1)[0] * 100 _, indices = torch.sort(out, descending = True) return [(classes[idx], prob[idx].item()) for idx in indices[0][:5]] if file_up is not None: # display image that user uploaded image = Image.open(file_up) st.image(image, caption = 'Uploaded Image.', use_column_width = True) st.write("") st.write("Just a second ...") labels = predict(file_up) # print out the top 5 prediction labels with scores for i in labels: st.write("Prediction (index, name)", i[0], ", Score: ", i[1]) ``` This app is a simple image classification tool built with Streamlit and PyTorch. It allows users to upload a JPEG image and processes it using a pre-trained ResNet-101 model, which is a deep-learning model trained on the ImageNet dataset. The app resizes and normalizes the uploaded image to prepare it for prediction, then outputs the top 5 predictions along with their probabilities. ## Step 3: Configure Streamlit Streamlit needs to be configured to allow external access from your browser. 1. Create a .streamlit directory in your home folder. ``` mkdir ~/.streamlit ``` 2. Create a Streamlit configuration file. ``` nano ~/.streamlit/config.toml ``` Add the following configuration: ``` [server] headless = true enableCORS = false port = 8501 ``` Save and close the file. ## Step 4: Run the Streamlit Application Your Streamlit app is installed and configured. Now, it’s time to start it. 1. Run the app using the following command. ``` streamlit run app.py ``` Output: ``` Collecting usage statistics. To deactivate, set browser.gatherUsageStats to False. You can now view your Streamlit app in your browser. Network URL: http://your-server-ip:8501 External URL: http://your-server-ip:8501 ``` 2. Open your browser and navigate to **http://your-server-ip:8501.** You will see your app dashboard. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p1-1.png) 3. Click on **Browse files** and upload any image (JPEG format). ![](https://www.atlantic.net/wp-content/uploads/2024/12/p2-1.png) 4. The app will display the image and predict the top 5 classes with their probabilities. ## Step 5: Monitor GPU Usage To ensure that your model is utilizing the GPU, monitor its activity with: ``` watch -n 1 nvidia-smi ``` This command displays real-time GPU usage. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p3.png) ## Conclusion Congratulations! You’ve successfully deployed a deep learning model using PyTorch and Streamlit on an Ubuntu 22.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). Your web application is now live and can classify images uploaded by users. This deployment leverages GPU acceleration for fast predictions and offers an intuitive interface for non-technical users. --- # Create a Stable Diffusion Web UI with a Atlantic.Net GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/create-a-stable-diffusion-web-ui-with-a-atlantic-net-gpu-server/ | Published: 2024-12-16 | Updated: 2024-12-17 | Author: Hitesh Jethva Stable Diffusion is a text-to-image generation AI model developed by CompVis. It leverages deep learning techniques to produce visually stunning images based on natural language prompts. However, running such a powerful model requires significant computational resources, which is why we use an Atlantic.Net GPU server. An Atlantic.Net GPU server instance provides the necessary GPU acceleration, ensuring the model operates efficiently. By combining this power with a user-friendly web interface, you can create images seamlessly and share the experience with others. This guide will explain how to deploy your Stable Diffusion Web UI on the Ubuntu 22.04 GPU server. ## Prerequisites Before proceeding, ensure you have the following: - An Ubuntu 22.04 server with an NVIDIA GPU and a minimum of 6 GB GPU RAM. - NVIDIA Drivers and CUDA Toolkit installed and configured on your server. ## Step 1: Update the Server and Install Required Dependencies Update all the packages to the updated version. ``` apt update -y ``` Install Python and other required dependencies. ``` apt install python3 python3-pip -y ``` Once installed, verify the versions to ensure everything is set up correctly: ``` python3 --version pip3 --version ``` ## Step 2: Install Git Large File Storage (LFS) Stable Diffusion uses large checkpoint files that standard Git cannot handle. Git LFS (Large File Storage) is designed to manage these large files effectively. Install Git Large File Storage (LFS). ``` apt install git-lfs -y ``` After installation, initialize Git LFS to enable its functionality globally: ``` git lfs install ``` You should see the following output: ``` Git LFS initialized. ``` ## Step 3: Clone the Stable Diffusion Model Repository The Stable Diffusion model is hosted on Hugging Face, a platform for AI and machine learning models. Use Git to clone the Stable Diffusion model repository: ``` git clone https://huggingface.co/CompVis/stable-diffusion-v-1-4-original ``` This repository contains the **sd-v1-4.ckpt** checkpoint file, which is the core of the model. Cloning this repository might take some time, depending on your internet speed, as it includes large files (7.14GB) ## Step 4: Clone the Stable Diffusion Web UI Repository The Stable Diffusion Web UI simplifies interaction with the model. Instead of using command-line tools, you can access all features through a graphical interface. Run the following command to clone the Web UI repository: ``` git clone https://github.com/AUTOMATIC1111/stable-diffusion-webui.git ``` This repository contains all the scripts, assets, and backend logic required to host the Stable Diffusion model on a web server. ## Step 5: Configure the Model for Web UI To make the Stable Diffusion model available in the Web UI, you need to move the model checkpoint file **(sd-v1-4.ckpt)** to the appropriate directory. Copy the sd-v1-4.ckpt checkpoint file from the Stable Diffusion directory to the **stable-diffusion-webui/models/Stable-diffusion/** Web UI directory and rename it as **model.ckpt** ``` cp ~/stable-diffusion-v-1-4-original/sd-v1-4.ckpt ~/stable-diffusion-webui/models/Stable-diffusion/model.ckpt ``` Once the checkpoint file is copied, you can delete the original Stable Diffusion directory to free up disk space: ``` rm -rf ~/stable-diffusion-v-1-4-original ``` ## Step 6: Install FastAPI Framework FastAPI is a high-performance Python framework used to build the backend for the Web UI. Use pip to install FastAPI. ``` pip3 install fastapi ``` This framework will handle HTTP requests sent to the Web UI, making it responsive and efficient. ## Step 7: Launch the Stable Diffusion Web UI You’re now ready to start the Web UI. The **launch.py** script initializes the server and makes the interface accessible. Start the Stable Diffusion Web UI. ``` cd stable-diffusion-webui python3 launch.py --listen ``` The **–listen** flag allows you to access the Web UI from any device on the same network. During the launch, the server will load the model and initialize the interface. This process may take a few minutes. Once complete, you’ll see a message indicating the web server is running, along with the URL to access the UI. Please note your GPU must have 6GB of available RAM to start the application. ## Step 8: Test the Stable Diffusion Web UI 1. Open your web browser and access the Stable Diffusion Web UI using the URL **http://your-server-ip:7860** ![](https://www.atlantic.net/wp-content/uploads/2024/12/p2-2.png) 2. Under the Stable Diffusion checkpoint dropdown menu, select **model.ckpt.** 3. Select the **txt2img** tab. 4. Enter a prompt, such as: ``` A serene landscape with mountains and a river at sunset ``` 5. Adjust the image dimensions (width and height) for better results. 6. Click the **Generate** button to create your image. The generated image will appear in the UI and can be downloaded. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p3-1.png) ## Conclusion Congratulations! You’ve successfully set up a Stable Diffusion Web UI using an Atlantic.Net [GPU server](https://www.atlantic.net/gpu-server-hosting/) instance. This interface allows you to generate stunning AI images directly from your web browser. Experiment with different prompts and settings to unleash the full potential of Stable Diffusion. --- # Installing MyScale on an Ubuntu Server > URL: https://www.atlantic.net/gpu-server-hosting/installing-myscale-on-an-ubuntu-server/ | Published: 2024-12-17 | Author: Richard Bailey MyScale allows you to run similarity searches with SQL. This guide will provide a step-by-step procedure for installing MyScale locally on an Ubuntu server.  ## **Prerequisites** Before you begin the installation process, ensure you have the following prerequisites in place: - An Ubuntu server - root or sudo privileges ## Step 1 – Create a MyScale Cluster Online - Create a signup login for MyScale at the following website [https://myscale.com](https://myscale.com). - Give yourself a Username, set your Company, and fill in the required information: ![](https://www.atlantic.net/wp-content/uploads/2024/12/myscale-setup.png) - Click on the New Cluster button on the top right: ![](https://www.atlantic.net/wp-content/uploads/2024/12/myscale-new-cluster.png) - Launch a Cluster, give it a name, select the free tier: ![](https://www.atlantic.net/wp-content/uploads/2024/12/myscale-launch-cluster.png) - Once completed, you get given the option to import demo data. In this example we will choose the “movie recommendation” demo data. Next, click import: ![](https://www.atlantic.net/wp-content/uploads/2024/12/myscale-movie-recommendation.png) - The data will now import. ![](https://www.atlantic.net/wp-content/uploads/2024/12/myscale-import-data.png) - Wait a few moments for the cluster to initialize: ![](https://www.atlantic.net/wp-content/uploads/2024/12/myscale-initialize-cluster.png) - **Important**: Make sure you get the “Connection Details” from your MyScale cluster. Simply click the tab in the top right corner and select “Connection Details.” You will need this information for later in the procedure. ![](https://www.atlantic.net/wp-content/uploads/2024/12/myscale-connection-details.png) ## Step 2 – Update Ubuntu and Install Python - First, update Ubuntu: ``` apt update apt upgrade -y ``` - MyScale requires Python. You can install it using the following commands: ``` apt install python3 python3-pip unzip -y ``` **Note:** You may be prompted to restart services after installation. Just click . - Next, install the Python virtual environment package. ``` pip install -U virtualenv ``` ## Step 3 – Install Jupyter Lab - Now, install Jupyter Lab using the pip command. ``` pip3 install jupyterlab ``` - This command installs Jupyter Lab and its dependencies. Next, edit the .bashrc file. ``` nano ~/.bashrc ``` - Define your Jupyter Lab path as shown below; simply add it to the bottom of the file: ``` export PATH=$PATH:~/.local/bin/ ``` - Reload the changes using the following command. ``` source ~/.bashrc ``` - Next, test run the Jupyter Lab locally using the following command to make sure everything starts. ``` jupyter lab --allow-root --ip=0.0.0.0 --no-browser ``` - Check the output to make sure there are no errors. Upon **success,** you will see the following output. ``` [C 2023-12-05 15:09:31.378 ServerApp] To access the server, open this file in a browser: http://ubuntu:8888/lab?token=aa67d76764b56c5558d876e56709be27446 http://127.0.0.1:8888/lab?token=aa67d76764b56c5558d876e56709be27446 ``` Press the CTRL+C to stop the server. ## Step 4 – Configure Jupyter Lab By default, Jupyter Lab doesn’t require a password to access the web interface. - To secure Jupyter Lab, generate the Jupyter Lab configuration using the following command. ``` jupyter-lab --generate-config ``` Output. ``` Writing default config to: /root/.jupyter/jupyter_lab_config.py ``` - Next, set the Jupyter Lab password. ``` jupyter-lab password ``` Set your password as shown below: ``` Enter password: Verify password: [JupyterPasswordApp] Wrote hashed password to /root/.jupyter/jupyter_server_config.json ``` - You can verify your hashed password using the following command. ``` cat /root/.jupyter/jupyter_server_config.json ``` Output. ``` { "IdentityProvider": { "hashed_password": "argon2:$argon2id$v=19$m=10240,t=10,p=8$zf0ZE2UkNLJK39l8dfdgHA$0qIAAnKiX1EgzFBbo4yp8TgX/G5GrEsV29yjHVUDHiQ" } } ``` Note this information, as you will need to add it to your config. - Next, edit the Jupyter Lab configuration file. ``` nano /root/.jupyter/jupyter_lab_config.py ``` - Define your server IP, hashed password, and other configurations as shown below: ``` c.ServerApp.ip = 'your-server-ip' c.ServerApp.open_browser = False c.ServerApp.password = 'argon2:$argon2id$v=19$m=10240,t=10,p=8$zf0ZE2UkNLJK39l8dfdgHA$0qIAAnKiX1EgzFBbo4yp8TgX/G5GrEsV29yjHVUDHiQ' c.ServerApp.port = 8888 ``` Make sure you format the file exactly as above. For example, the port number is not in brackets, and the False boolean must have a capital F.c. - Save and close the file when you are done. ## Step 5 – Create a Systemctl Service File - Next, create a systemd service file to manage Jupyter Lab. ``` nano /etc/systemd/system/jupyter-lab.service ``` - Add the following configuration: ``` [Service] Type=simple PIDFile=/run/jupyter.pid WorkingDirectory=/root/ ExecStart=/usr/local/bin/jupyter lab --config=/root/.jupyter/jupyter_lab_config.py --allow-root User=root Group=root Restart=always RestartSec=10 [Install] WantedBy=multi-user.target ``` - Save and close the file, then reload the systemd daemon. ``` systemctl daemon-reload ``` - Next, start the Jupyter Lab service using the following command. ``` systemctl start jupyter-lab ``` - You can now check the status of the Jupyter Lab service using the following command. ``` systemctl status jupyter-lab ``` - Jupyter Lab is now starting and listening on port 8888. You can verify it with the following command. ``` ss -antpl | grep jupyter ``` Output. ``` LISTEN 0      128    104.219.55.40:8888      0.0.0.0:*  users:(("jupyter-lab",pid=156299,fd=6)) ``` ## Step 6 – Access Jupyter Lab Now, open your web browser and access the Jupyter Lab web interface using the URL **http://your-server-ip:8888.** You will see Jupyter Lab on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2024/12/jupyter-lab-login.png) Provide the password you set during the installation and click on Log in. You will see the Jupyter Lab dashboard on the following screen: ![](https://www.atlantic.net/wp-content/uploads/2024/12/jupyter-lab-dashboard.png) ## Step 7 – Start the Python3 Notebook You can now start the Python 3 Notebook. ## Step 8 – Install ClickHouse Connect and Prerequisites - Switch over to your Jupyter Notebook and run: ``` !pip install -U clickhouse-connect scikit-learn unzip pandas matplotlib datasets pyarrow ``` - Download some additional sample data: ``` !wget https://files.grouplens.org/datasets/movielens/ml-latest-small.zip ``` - Unzip the Sample Data ``` !unzip ml-latest-small.zip ``` ## Step 8 – Build a Dataset This example uses information provided from the [MyScale GitHub Page](https://github.com/myscale/examples/blob/main/movie-recommendation.ipynb). - Let’s start building a dataset by: - Importing necessary files - Loading movie metadata - Add TMDB IDs (filtered) ``` import pandas as pd # obtain movie metadata original_movie_metadata = pd.read_csv('ml-latest-small/movies.csv') movie_metadata = original_movie_metadata[['movieId', 'title', 'genres']] movie_metadata['genres'] = movie_metadata['genres'].str.split('|', expand=False) # add tmdbId to movie metadata dataframe original_movie_links = pd.read_csv('ml-latest-small/links.csv') movie_info = pd.merge(movie_metadata, original_movie_links, on=["movieId"])[['movieId', 'title', 'genres', 'tmdbId']] # filter tmdb valid movies movie_info = movie_info[movie_info['tmdbId'].notnull()] movie_info['tmdbId'] = movie_info['tmdbId'].astype(int).astype(str) movie_info.head() ``` You should see output like this: ![](https://www.atlantic.net/wp-content/uploads/2024/12/dataset-output.png) - Now run this command: - Load User Ratings - Check dataset properties ``` # get movie user rating info movie_user_rating = pd.read_csv('ml-latest-small/ratings.csv')# remove ratings of movies which don't have tmdbId movie_user_rating = movie_user_rating[movie_user_rating['movieId'].isin(movie_info['movieId'])] movie_user_rating = movie_user_rating[["userId", "movieId", "rating"]] movie_user_rating.head() ``` The procedure generates two dataframes: ![](https://www.atlantic.net/wp-content/uploads/2024/12/dataframes.png) - movie_info: Contains movie information (ID, title, genres, TMDB ID). - movie_user_rating: Contains user ratings for movies. Now run this command: ``` movie_user_rating.nunique() ``` You Should see output like this: ``` userId      610 movieId    9716 rating       10 dtype: int64 ``` ## Step 10 – Run a Vector Search on the Data This part of your procedure focuses on generating vector embeddings for users and movies, and then preparing the data for loading into MyScale. Run the following commands to use NMF. NMF is a dimensionality reduction technique that decomposes a matrix into two smaller matrices with non-negative values. This is suitable for user-item interaction data like movie ratings, as the values are inherently non-negative. ``` from sklearn.decomposition import NMF from sklearn.preprocessing import MaxAbsScaler from scipy.sparse import csr_matrixuser_indices, user_ids = pd.factorize(movie_user_rating['userId']) item_indices, movie_ids = pd.factorize(movie_user_rating['movieId']) rating_sparse_matrix = csr_matrix((movie_user_rating['rating'], (user_indices, item_indices)))# normalize matrix with MaxAbsScaler max_abs_scaler = MaxAbsScaler() rating_sparse_matrix = max_abs_scaler.fit_transform(rating_sparse_matrix) ``` This will create a user-item matrix, we can fit an NMF model with the matrix. ``` # create NMF model with settings dimension = 512 nmf_model = NMF(n_components=dimension, init='nndsvd', max_iter=500)# rating sparse matrix decomposition with NMF user_vectors = nmf_model.fit_transform(rating_sparse_matrix) item_vectors = nmf_model.components_.Terror = nmf_model.reconstruction_err_ print("Reconstruction error: ", error) ``` ``` # generate user vector matrix, containing userIds and user vectors user_vector_df = pd.DataFrame(zip(user_ids, user_vectors), columns=['userId', 'user_rating_vector']).reset_index(drop=True)# generate movie vector matrix, containing movieIds and movie vectors movie_rating_vector_df = pd.DataFrame(zip(movie_ids, item_vectors), columns=['movieId', 'movie_rating_vector']) ``` ## Step 11 – Creating Datasets We now have four dataframes: movie metadata, user movie ratings, user vectors and movie vectors. We will merge the relevant dataframes into a single dataframe. In the step we will: - Merge the movie_rating_vector_df (containing movie vectors) with the movie_info DataFrame (containing movie metadata) using the movieId column. - Keep the user_rating_df (containing user ratings) separate for later use. - Convert the dataframesto Parquet format using pyarrow. Parquet is a columnar storage format that is efficient for analytical queries and data warehousing. This is a good choice for storing data that will be loaded into MyScale. ``` user_rating_df = movie_user_rating.reset_index(drop=True) # add movie vectors into movie metadata and remove movies without movie vector movie_info_df = pd.merge(movie_info, movie_rating_vector_df, on=["movieId"]).reset_index(drop=True) movie_info_df.head() ``` ``` import pyarrow as pa import pyarrow.parquet as pq# create table objects from the data and schema movie_table = pa.Table.from_pandas(movie_info_df) user_table = pa.Table.from_pandas(user_vector_df) rating_table = pa.Table.from_pandas(user_rating_df)# write the table to parquet files pq.write_table(movie_table, 'movie.parquet') pq.write_table(user_table, 'user.parquet') pq.write_table(rating_table, 'rating.parquet') ``` ## Step 12 – Populating Data to MyScale To populate data to MyScale, first, we load data into panda dataframes. In [1]: ``` from datasets import load_dataset movie = load_dataset("myscale/recommendation-examples", data_files="movie.parquet", split="train") user = load_dataset("myscale/recommendation-examples", data_files="user.parquet", split="train") rating = load_dataset("myscale/recommendation-examples", data_files="rating.parquet", split="train") # transform datasets to panda Dataframe movie_info_df = movie.to_pandas() user_vector_df = user.to_pandas() user_rating_df = rating.to_pandas() # convert embedding vectors from np array to list movie_info_df['movie_rating_vector'] = movie_info_df['movie_rating_vector'].apply(lambda x: x.tolist()) user_vector_df['user_rating_vector'] = user_vector_df['user_rating_vector'].apply(lambda x: x.tolist()) ``` You should see output like this: ``` Generating train split: 9716 examples [00:00, 46166.81 examples/s] Generating train split: 610 examples [00:00, 60321.24 examples/s] Generating train split: 100823 examples [00:00, 13216311.29 examples/s] ``` ## Step 13 – Connect to MyScale - Now connect to MyScale: ``` import clickhouse_connect client = clickhouse_connect.get_client( host='msc-xxxxxxxx.us-east-1.aws.myscale.com', port=443, username='atlanticdotnetdemo_org_default', password='123456789' ) ``` - Now prep the data to dump into MyScale: ``` client.command("DROP TABLE IF EXISTS default.myscale_movies") client.command("DROP TABLE IF EXISTS default.myscale_users") client.command("DROP TABLE IF EXISTS default.myscale_ratings")# create table for movies client.command(f""" CREATE TABLE default.myscale_movies ( movieId Int64, title String, genres Array(String), tmdbId String, movie_rating_vector Array(Float32), CONSTRAINT vector_len CHECK length(movie_rating_vector) = 512 ) ORDER BY movieId """)# create table for user vectors client.command(f""" CREATE TABLE default.myscale_users ( userId Int64, user_rating_vector Array(Float32), CONSTRAINT vector_len CHECK length(user_rating_vector) = 512 ) ORDER BY userId """)# create table for user movie ratings client.command(""" CREATE TABLE default.myscale_ratings ( userId Int64, movieId Int64, rating Float64 ) ORDER BY userId """) ``` - Now upload to MyScale: ``` client.insert("default.myscale_movies", movie_info_df.to_records(index=False).tolist(), column_names=movie_info_df.columns.tolist()) client.insert("default.myscale_users", user_vector_df.to_records(index=False).tolist(), column_names=user_vector_df.columns.tolist()) client.insert("default.myscale_ratings", user_rating_df.to_records(index=False).tolist(), column_names=user_rating_df.columns.tolist())# check count of inserted data print(f"movies count: {client.command('SELECT count(*) FROM default.myscale_movies')}") print(f"users count: {client.command('SELECT count(*) FROM default.myscale_users')}") print(f"ratings count: {client.command('SELECT count(*) FROM default.myscale_ratings')}") ``` You should see output like this: ``` movies count: 9716 users count: 610 ratings count: 100823 ``` ## Step 14 – Index the Data Now index the data in MyScale: ``` # create vector index with cosine client.command(""" ALTER TABLE default.myscale_movies ADD VECTOR INDEX movie_rating_vector_index movie_rating_vector TYPE MSTG('metric_type=IP') """) ``` You can check the status with this command: ``` # check the status of the vector index, make sure vector index is ready with 'Built' status get_index_status="SELECT status FROM system.vector_indices WHERE name='movie_rating_vector_index'" print(f"index build status: {client.command(get_index_status)}") ``` Check the output to make sure it changes from this: ``` index build status: InProgress ``` To this: ``` index build status: Built ``` ## Step 15 – You Are Now Ready to Query MyScale Lets now query the vector database: ``` import matplotlib.pyplot as plt import numpy as np import pandas as pdrandom_user = client.query("SELECT * FROM default.myscale_users ORDER BY rand() LIMIT 1") assert random_user.row_count == 1 target_user_id = random_user.first_item["userId"] target_user_vector = random_user.first_item["user_rating_vector"]print("currently selected user id={} for movie recommendation\n".format(target_user_id))# user rating plot target_user_ratings = user_rating_df.loc[user_rating_df['userId'] == target_user_id]['rating'].tolist() bins = np.arange(1.0, 6, 0.5) # Compute the histogram hist, _ = np.histogram(target_user_ratings, bins=bins) print("Distribution of ratings for user {}:".format(target_user_id)) plt.bar(bins[:-1], hist, width=0.4) plt.xlabel('Rating') plt.ylabel('Count') plt.title('User Rating Distribution') for i in range(len(hist)): plt.text(bins[i], hist[i], str(hist[i]), ha='center', va='bottom') plt.show() ``` You should see output like this: ![](https://www.atlantic.net/wp-content/uploads/2024/12/user-rating-distribution.png) You can also use the following command to find the top 10 movies by rating: ``` top_k = 10 # query the database to find the top K recommende # d movies recommended_results = client.query(f""" SELECT movieId, title, genres, tmdbId, distance(movie_rating_vector, {target_user_vector}) AS dist FROM default.myscale_movies WHERE movieId not in ( SELECT movieId from default.myscale_ratings where userId = {target_user_id} ) ORDER BY dist DESC LIMIT {top_k} """)recommended_movies = pd.DataFrame.from_records(recommended_results.named_results()) rated_score_scale = client.query(f""" SELECT max(rating) AS max, min(rating) AS min FROM default.myscale_ratings WHERE userId = {target_user_id} """) max_rated_score = rated_score_scale.first_row[0] min_rated_score = rated_score_scale.first_row[1]print("Top 10 movie recommandations with estimated ratings for user {}".format(target_user_id)) max_dist = recommended_results.first_row[4] recommended_movies['estimated_rating'] = min_rated_score + ((max_rated_score - min_rated_score) / max_dist) * recommended_movies['dist'] recommended_movies[['movieId', 'title', 'estimated_rating', 'genres']] ``` This concludes the procedure for installing MyScale on an Ubuntu server and running a basic movie recommendation query. You can now experiment with different parameters and datasets to further explore the capabilities of MyScale – try it on [GPU hosting](https://www.atlantic.net/gpu-server-hosting/) from Atlantic.Net! --- # NVIDIA NVLink: How It Works, Use Cases, and Critical Best Practices > URL: https://www.atlantic.net/gpu-server-hosting/nvidia-nvlink-how-it-works-use-cases-and-critical-best-practices/ | Published: 2024-12-31 | Updated: 2025-03-26 | Author: Gilad Maayan ## What Is NVIDIA NVLink? NVLink is a high-speed interconnect technology developed by NVIDIA to improve data transfer between GPUs and CPUs. It addresses the limitations of the PCI Express (PCIe) interface in high-performance computing applications by providing a faster pathway with lower latency. NVLink enables better communication and coordination between GPU units, crucial in workloads such as AI, deep learning, and scientific simulations. The primary benefit of NVLink is its ability to create a unified memory pool across multiple GPUs. This allows for more efficient parallel processing and resource sharing. By reducing bottlenecks and improving the scalability of systems, NVLink significantly improves performance, especially in data-intensive tasks. This is part of a series of articles about GPU architecture. ## How NVLink Works NVLink works by establishing a direct, high-bandwidth link between compatible processors and memory. This architecture bypasses the slower PCIe system, which can be limiting in scenarios requiring substantial data flow between processors. NVLink’s design allows multiple GPUs to communicate directly with one another at higher speeds. Key to its operation is the support for cache coherence, which ensures data consistency across the GPUs sharing memory space. This feature simplifies programming models because developers do not need to manage memory coherency explicitly. This makes NVLink a viable alternative to traditional PCIe, improving data flow and computing efficiency. ### NVLink Architecture The NVLink architecture is structured around links that connect the computing units within a system. Each NVLink connection supports a significantly higher data throughput compared to PCIe lanes, providing an aggregate bandwidth considerably surpassing conventional interconnects. This architecture supports multiple connectivity options, enabling varied system configurations to suit workload demands. These links incorporate protocol layers that manage data transfer processes, ensuring resilience and efficiency. By splitting data across multiple parallel paths, NVLink minimizes wait times and improves throughput. ### Data Transfer Mechanisms NVLink uses advanced data transfer mechanisms that optimize how data moves between components. It features protocols that allow for coherent data sharing, reducing the need for manual synchronization and ensuring unity in data view across GPUs. Another key mechanism is memory pooling, which lets multiple GPUs share a single large memory space. This arrangement reduces redundancy and improves parallel processing capabilities, vital for applications needing broad computational resources. ## Advantages of NVLink Over PCIe NVLink provides several advantages over PCIe, the traditional serial bus standard used in most computer systems: - **Higher bandwidth:** NVLink offers significantly higher bandwidth compared to PCIe. While PCIe 4.0 provides a maximum throughput of approximately 32 GB/s for a 16-lane connection, NVLink can achieve bandwidths exceeding 200 GB/s, depending on the generation. - **Lower latency:** NVLink reduces latency by providing a direct connection between GPUs or between a GPU and CPU. Unlike PCIe, which involves multiple intermediary steps, NVLink allows for faster communication by eliminating unnecessary bottlenecks. - **Unified memory pooling:** One of NVLink’s standout features is its ability to create a unified memory pool across GPUs. This allows multiple GPUs to share memory seamlessly, effectively expanding the available memory space for large models or datasets. PCIe-based systems often require explicit data transfers between discrete memory pools, adding complexity and overhead. - **Enhanced scalability:** NVLink’s architecture is designed to scale efficiently across multiple GPUs. It supports mesh and ring topologies, enabling the interconnection of more devices without a significant drop in performance. PCIe-based systems can face limitations in scalability due to contention for shared resources. - **Improved power efficiency:** By optimizing data transfer and reducing latency, NVLink can offer better performance per watt compared to PCIe. - **Simplified programming models:** NVLink’s support for cache coherence ensures data consistency across GPUs sharing memory. This removes the need for developers to manually manage memory synchronization. ### Tips from the expert: ![Author icon](https://secure.gravatar.com/avatar/eb8695bf1d856d659c4fa98eba9e0c42?s=192&d=mm&r=g) ![Linkedin Icon](https://www.atlantic.net/wp-content/themes/anet/img/cloud/gpu/icon_linkedin.webp) #### Richard Bailey ##### Technical Editor Richard Bailey brings over two decades of IT expertise, from traditional data centers to cutting-edge cloud solutions. As the founder of [turbogeek.co.uk](https://turbogeek.co.uk/) and a seasoned writer, he focuses on delivering authoritative content on our hosting services, HIPAA compliance, and related topics. In my experience, here are tips that can help you better harness NVIDIA NVLink technology: 1. **Optimize NVLink topology for specific workloads:** Consider the topology (e.g., point-to-point, mesh, ring) based on workload requirements. For example, AI training models with heavy inter-GPU communication benefit from mesh topologies, while workloads with minimal inter-GPU data transfers can utilize simpler setups. 2. **Leverage NVLink-aware libraries:** Use libraries like cuDNN, NCCL, and TensorRT, which are optimized to exploit NVLink’s high bandwidth. These libraries handle parallelism and memory pooling efficiently, reducing the need for custom optimization. 3. **Integrate NVSwitch for hyperscale systems:** For multi-node configurations, consider NVSwitch for a seamless, scalable architecture. It not only improves GPU communication but also enhances collective operations like all-reduce, which are critical in deep learning and HPC workloads. 4. **Pin memory to optimize transfer speeds:** Pinning memory (locking it in physical RAM) ensures faster transfers between host memory and GPUs. Combining pinned memory with NVLink’s unified memory model can further boost performance in applications requiring frequent host-GPU communication. 5. **Combine NVLink with RDMA for cluster computing:** In distributed systems, use Remote Direct Memory Access (RDMA) with NVLink to achieve low-latency inter-node GPU communication. This is especially useful in HPC clusters or AI supercomputers to minimize data transfer bottlenecks across nodes. ## How NVLink Works with NVSwitch NVLink and NVSwitch complement each other to enable high-performance, scalable GPU communication in advanced computing systems. While NVLink provides direct, high-speed interconnects between GPUs, NVSwitch extends these connections into a cohesive, multi-node environment. Together, they create an efficient system tailored for data-intensive workloads like AI training and scientific simulations. NVSwitch serves as a high-bandwidth switch that integrates multiple NVLink connections, enabling seamless, all-to-all communication across GPUs. The latest NVSwitch generation supports 64 NVLink ports and incorporates NVIDIA’s Scalable Hierarchical Aggregation Reduction Protocol (SHARP), which optimizes data aggregation and transfer. In practical terms, NVSwitch improves the capabilities of NVLink by supporting configurations with up to 256 GPUs interconnected at an aggregate bandwidth of 57.6 TB/s. ## NVLink Use Cases and Applications ### High-Performance Computing (HPC) In high-performance computing, NVLink enables the handling of massive computing loads, essential for simulations, weather modeling, and scientific research. NVLink’s architecture allows clusters of GPUs to work in tandem, improving computational power without the limitations inherent to PCIe. The rapid transfer speeds offered by NVLink allow researchers to focus on deriving insights and results, reducing the time required for complex calculations. This efficiency translates directly into faster time-to-results in computational-heavy tasks, benefiting scientific projects, financial modeling, and operational research. ### Artificial Intelligence and Deep Learning AI and deep learning frameworks derive considerable benefits from NVLink’s data transfer capabilities. AI models often require intensive data processing between GPUs during both training and inference phases, and NVLink alleviates the bandwidth restrictions and latency bottlenecks that can hinder performance with PCIe alone. By providing a coherent memory space across GPUs, NVLink simplifies the development of AI algorithms, enabling easier scaling and implementation of complex neural networks. The reduction in data bottlenecks allows for more extensive experiments and rapid iteration cycles. ### Data Analytics and Big Data NVLink’s high bandwidth and low latency characteristics make it ideal for data analytics and big data computation. These fields require processing vast amounts of data quickly, and any delays can impact decision-making and insights. By optimizing data flow, NVLink curtails processing times and aids in managing real-time analytics applications. In big data scenarios, NVLink’s ability to form expansive memory pools from multiple GPUs means that larger datasets can be processed simultaneously. This parallel processing capability is crucial for organizations looking to leverage data-driven insights rapidly. ## 4 Best Practices for Optimizing NVLink Performance Here are some of the ways to ensure optimal performance when using NVLink. ### 1. Efficient Memory Utilization Efficient memory utilization with NVLink requires strategic planning of data distribution and caching strategies across GPU networks. Ensuring balanced access to the shared memory resources helps avert performance degradation due to bottlenecks. Techniques such as load balancing and dynamic memory allocation can aid in achieving these goals effectively. Integrating memory coherence strategies across shared memory pools helps minimize latency and improves data retrieval efficiency. This involves coordinating data access to benefit from NVLink’s high bandwidth, optimizing computational workloads across system resources. ### 2. Balancing Computational Workloads Balancing workloads across GPUs in an NVLink-enhanced environment ensures that no single GPU is overloaded while others are underutilized. This balance is crucial, as it maximizes the computational power available, allowing for the efficient parallel processing NVLink is designed to deliver. Techniques involving dynamic scheduling and task distribution help achieve this balance. Developers should aim to distribute tasks in a way that resources are fully utilized without data congestion or idle periods. This approach ensures that each GPU contributes effectively to computation, further leveraging NVLink’s strengths in connected operations. ### 3. Monitoring and Troubleshooting NVLink Monitoring NVLink performance requires tools that can track data flow, bandwidth usage, and processing bottlenecks. Effective use of monitoring tools aids in identifying issues quickly, ensuring the system runs smoothly. Tools like NVIDIA’s system management suite provide insights into NVLink’s operational status. Troubleshooting NVLink involves checking cable connections, ensuring firmware updates, and validating driver installations. These measures help address common issues that might arise, including data transfer slowdowns or connector failures. ### 4. Ensuring System Compatibility and Updates To ensure NVLink compatibility, systems must have the right hardware and up-to-date software support. This includes installing the latest drivers and ensuring that firmware is updated to manage NVLink’s functions properly. Regularly updating system software helps preempt compatibility problems and ensures continued access to NVLink’s latest features and improvements. ***Related content: Read our guide to [virtual GPU](https://www.atlantic.net/gpu-server-hosting/how-virtual-gpus-work-use-cases-and-critical-best-practices/) (coming soon)*** ## **Next-Gen Dedicated GPU Servers from Atlantic.Net, Accelerated by NVIDIA** Experience unparalleled performance with dedicated cloud servers equipped with the revolutionary NVIDIA accelerated computing platform. Choose from the NVIDIA L40S GPU and NVIDIA H100 NVL to unleash the full potential of your generative artificial intelligence (AI) workloads, train large language models (LLMs), and harness natural language processing (NLP) in real time. High-performance GPUs are superb at scientific research, 3D graphics and rendering, medical imaging, climate modeling, fraud detection, financial modeling, and advanced video processing. [Learn more about Atlantic.net GPU server hosting](https://www.atlantic.net/gpu-server-hosting/) --- # GPU for Rendering: How It Works, Top 10 GPUs and Pro Tips > URL: https://www.atlantic.net/gpu-server-hosting/gpu-for-rendering-how-it-works-top-10-gpus-and-pro-tips/ | Published: 2025-01-02 | Updated: 2025-03-26 | Author: Gilad Maayan ## How Are GPUs Used for Rendering? A graphics processing unit (GPU) is a component for rendering, accelerating the process of generating images from 3D models. Unlike CPUs, which are for general-purpose processing tasks, GPUs are specialized for parallel processing, making them useful for handling large blocks of visual data. They can quickly render detailed 3D scenes, crucial in applications such as video games, film production, and architectural visualization. GPUs achieve this by utilizing architecture that supports thousands of small, efficient cores capable of handling multiple threads simultaneously. This architecture allows GPUs to process tasks in parallel, accelerating rendering workflows compared to the sequential processing found in CPUs. GPUs enable 3D rendering by executing millions of calculations in parallel to simulate lighting, texture, and shading. They perform tasks like geometry processing, transforming 3D models into pixels on the screen. In addition to core processing, GPUs utilize memory management techniques, such as tiling, to optimize the storage and retrieval of textures and images. This is part of a series of articles about GPU applications. ## Types of Rendering That Benefit from GPUs GPUs are useful for various rendering tasks. ### Real-Time Rendering Real-time rendering creates images on-the-fly as users interact with a scene, crucial for applications like gaming and virtual reality. This type of rendering relies heavily on the GPU’s ability to quickly process graphics data to maintain fluid motion. The real-time rendering process is refined through the use of techniques such as rasterization, where 3D objects are projected onto a 2D screen by converting vertices into pixels. This method optimizes the rendering pipeline, allowing for dynamic and immediate generation of frames. ### Offline Rendering Offline rendering processes images without the need for immediate display, often allowing for more complex scenes with higher visual fidelity. Used extensively in film and animation, this method benefits from the GPU’s processing power to handle detailed calculations for effects such as global illumination and physically accurate simulations. The offline rendering process enables extended compute times, allowing for the use of sophisticated algorithms that can produce photorealistic results. Although not constrained by real-time requirements, the computational demands are still significant, making GPUs essential for reducing rendering times of high-quality visuals. ### Hybrid Rendering Hybrid rendering combines elements of real-time and offline rendering, aiming to deliver high-quality visuals with interactive capabilities. This approach capitalizes on the strengths of both methods, using GPUs to balance real-time interaction with complex image generation. By leveraging GPUs, hybrid rendering involves the strategic use of real-time techniques, like rasterization, alongside computational methods, like ray tracing, for specialized effects. ### AI-Assisted Rendering AI-assisted rendering utilizes machine learning algorithms to improve rendering processes, optimizing visual output and reducing computational loads. These algorithms, often executed on GPUs, accelerate tasks such as denoising, upscaling, and texture prediction. The integration of AI in rendering allows for improved image processing techniques that automate and improve the quality of results. GPUs, with their parallel processing capability, are well suited to execute complex AI models, enabling rendering tools to deliver higher fidelity images faster. ### Tips from the expert: ![Author icon](https://secure.gravatar.com/avatar/eb8695bf1d856d659c4fa98eba9e0c42?s=192&d=mm&r=g) ![Linkedin Icon](https://www.atlantic.net/wp-content/themes/anet/img/cloud/gpu/icon_linkedin.webp) #### Richard Bailey ##### Technical Editor Richard Bailey brings over two decades of IT expertise, from traditional data centers to cutting-edge cloud solutions. As the founder of [turbogeek.co.uk](https://turbogeek.co.uk/) and a seasoned writer, he focuses on delivering authoritative content on our hosting services, HIPAA compliance, and related topics. In my experience, here are tips that can help you maximize the performance of GPUs for rendering tasks: 1. **Utilize GPU memory efficiently for large scenes:** When working with complex scenes, optimize textures, meshes, and assets to fit within the GPU’s VRAM. Use techniques like texture atlasing, mipmapping, and LOD (Level of Detail) models to reduce memory overhead without sacrificing quality. 2. **Leverage GPU rendering denoising tools:** Use AI-based denoising tools, such as those in NVIDIA OptiX or AMD’s ProRender, to reduce noise in rendered frames. This can cut down rendering times significantly by allowing fewer samples per pixel while still achieving photorealistic results. 3. **Enable hardware acceleration for ray tracing and AI:** For tasks involving ray tracing, enable dedicated ray-tracing cores (e.g., NVIDIA RTX cores) or AMD’s ray accelerators. For AI-assisted rendering tasks, ensure that Tensor Cores (NVIDIA) or Matrix Cores (AMD) are being utilized by compatible rendering software. 4. **Batch-render animations to maximize GPU usage:** When rendering animations, set up batch renders to ensure continuous GPU operation. This avoids idle time between frames and allows for optimal use of the GPU’s processing power. Some tools, like Blender, let teams automate rendering pipelines to increase throughput. 5. **Use out-of-core rendering for memory-intensive scenes:** For scenes that exceed GPU memory capacity, utilize out-of-core rendering features offered by rendering engines like Redshift or Octane. This offloads excess data to system memory, avoiding crashes or performance drops while maintaining scene fidelity. ## Key Features of GPUs for Rendering Here are some of the main GPU features that enable rendering. ### CUDA Cores/Stream Processors CUDA cores (NVIDIA) and stream processors (AMD) are essential for executing parallel tasks, directly impacting a GPU’s performance in rendering. These cores enable the concurrent processing of numerous calculations, significantly accelerating tasks like shading, physics, and complex geometry calculations in graphic rendering. The number of CUDA cores or stream processors on a GPU is a critical determinant of its capability in handling demanding rendering loads. More cores allow for increased parallel throughput, translating into smoother and faster rendering. ### VRAM Video random access memory (VRAM) stores textures, meshes, and other data needed for rendering. The amount of VRAM in a GPU affects its ability to handle large datasets and complex scenes without slowdowns. Sufficient VRAM is essential for maintaining performance, especially in high-resolution or resource-intensive applications. Insufficient VRAM can lead to bottlenecks, causing significant performance degradation during rendering. Choosing a GPU with adequate VRAM ensures that the rendering pipeline operates smoothly. ### Ray Tracing Cores Ray tracing cores, like those found in NVIDIA’s RTX series, are specialized units designed to accelerate ray tracing calculations. These cores enable real-time computation of light paths, reflections, and shadows, improving realism in rendered scenes. The inclusion of dedicated ray tracing cores in a GPU improves rendering capabilities by improving the efficiency of complex lighting simulations. This feature is becoming increasingly important for achieving photorealistic effects. ### Thermal Design Thermal design in a GPU refers to its ability to manage heat output during intensive computational tasks. Effective thermal management is crucial for maintaining optimal performance and preventing thermal throttling, where excessive heat causes a reduction in processing speed. A well-designed thermal system includes features such as high-performance cooling fans, heat sinks, and adaptive power management techniques. These features ensure that the GPU can operate under peak conditions without overheating. ### Driver Support Driver support is vital for ensuring compatibility and performance of a GPU with rendering software. Regular driver updates provide improvements, bug fixes, and optimizations, directly influencing the efficiency and reliability of rendering tasks. Driver updates can introduce new features, improve existing functionality, and resolve compatibility issues with rendering software. Maintaining up-to-date drivers is important for optimizing GPU performance. ## Popular GPUs for 3D Rendering When selecting a GPU for 3D rendering, it’s important to consider models that offer high performance and compatibility with rendering software. Here are some popular options: ### NVIDIA GPUs 1. **NVIDIA A100 tensor core GPU:** For AI and high-performance computing, the A100 also excels in rendering with its massive parallel processing power and 80 GB of high-bandwidth memory. Its capability to handle large datasets and complex rendering tasks makes it a top choice for advanced visualizations and simulations. 2. **NVIDIA A30 tensor core GPU:** Offering 24 GB of memory and optimized for mixed workloads, the A30 is suitable for rendering workflows that involve AI-enhanced processes. Its balance of performance and efficiency makes it suitable for professional environments requiring scalable solutions. 3. **NVIDIA A2 tensor core GPU:** This compact and efficient GPU provides 16 GB of memory and is optimized for entry-level rendering tasks and edge applications. It is a cost-effective solution for lightweight rendering workloads, particularly in AI-assisted or hybrid rendering scenarios. 4. **NVIDIA GeForce RTX 4090:** This high-end GPU features 24 GB of GDDR6X VRAM and a large number of CUDA cores, making it suitable for handling complex rendering tasks efficiently. 5. **NVIDIA GeForce RTX 4080:** With 16 GB of GDDR6X VRAM, this GPU offers a balance between performance and cost, making it a viable option for demanding rendering applications. 6. **NVIDIA GeForce RTX 4070 Ti:** With 12 GB of GDDR6X VRAM, this GPU is suitable for less demanding rendering tasks, offering a more budget-friendly option without significant compromises on performance. 7. **NVIDIA RTX 3090 Ti:** Featuring 24 GB of GDDR6X VRAM and a high CUDA core count, the RTX 3090 Ti delivers exceptional rendering performance. It is suitable for professionals handling complex scenes, large datasets, and real-time applications that demand high computational throughput. ### AMD GPUs 1. **AMD Radeon Pro W7900**: This workstation-grade graphics card features a GPU with 48 GB of memory, enabling it to process large production scenes efficiently. It’s tailored for tasks that demand ultimate performance and reliability in animation and rendering projects. 2. **AMD Radeon RX 7900 XTX:** Equipped with 24 GB of GDDR6 VRAM, this GPU provides strong performance for rendering tasks, especially in applications optimized for AMD hardware. 3. **AMD Radeon RX 7800 XT:** Featuring 16 GB of GDDR6 VRAM, this GPU offers a cost-effective solution for mid-range rendering needs, balancing performance and affordability. ## 5 Best Practices for Using GPUs in Rendering Organizations should consider the following practices to ensure optimal use of GPUs for rendering tasks. ### 1. Choose the Right GPU for the Task Selecting the appropriate GPU involves assessing the rendering workloads, such as real-time or offline rendering. Different tasks may require varying levels of GPU power, with certain applications benefiting from features like ray tracing or AI acceleration. It’s important to consider the software being used, as some programs are optimized for specific GPU architectures. Researching compatibility and testing performance metrics can guide this decision, ensuring the selected GPU meets the rendering requirements. ### 2. Optimize the Hardware Configuration Optimizing the hardware configuration involves balancing all system components, including the CPU, RAM, and storage, alongside the GPU. Ensuring all parts work harmoniously can prevent bottlenecks that limit rendering performance. Investing in complementary hardware that matches the GPU’s capabilities is essential for achieving efficient rendering outcomes. Attention to cooling and power supply can further improve system stability and performance. A well-cooled GPU operates more efficiently, while a reliable power supply ensures consistent performance under heavy loads. ### 3. Use Compatible Rendering Software Using compatible rendering software maximizes GPU efficiency by leveraging hardware-specific optimizations. Many applications offer tailored improvements for different GPU brands and models, which can greatly improve performance. Regularly updating software also ensures access to the latest features and improvements. Compatibility checks and updates maintain the optimal functioning of rendering applications with current GPU technologies. ### 4. Manage Resource Usage Effective resource management ensures that the GPU operates at peak efficiency during rendering tasks. Monitoring tools can help track GPU usage, temperatures, and memory consumption, providing insights into the optimization of workloads. Adjusting settings to avoid exceeding resource capacities prevents performance drops or crashes. Utilizing render queues and scene optimization can help distribute the workload efficiently, preserving GPU resources for critical tasks. Resource management strategies increase the GPU’s longevity and ensure seamless rendering operations. ### 5. Consider Cloud Rendering for Heavy Workloads Cloud rendering offers scalability and flexibility, using remote GPUs to handle intensive rendering jobs. This approach mitigates local hardware limitations, allowing access to more powerful resources without significant upfront investment. Cloud services can be tailored to meet project requirements. Cloud rendering also supports collaboration, as teams can share access to rendered scenes and results. Assessing cloud service providers and their offerings ensures alignment with workflow demands and pricing models. ***Related content: Read our guide to [GPU virtualization](https://www.atlantic.net/gpu-server-hosting/gpu-virtualization-techniques-solutions-and-best-practices/)*** ## **Next-Gen Dedicated GPU Servers from Atlantic.Net, Accelerated by NVIDIA** Experience unparalleled performance with dedicated cloud servers equipped with the revolutionary NVIDIA accelerated computing platform. Choose from the NVIDIA L40S GPU and NVIDIA H100 NVL to unleash the full potential of your generative artificial intelligence (AI) workloads, train large language models (LLMs), and harness natural language processing (NLP) in real time. High-performance GPUs are superb at scientific research, 3D graphics and rendering, medical imaging, climate modeling, fraud detection, financial modeling, and advanced video processing. [Learn more about Atlantic.net GPU server hosting](https://www.atlantic.net/gpu-server-hosting/)   --- # GPU for Data Science: 4 Free Libraries and 6 Best Practices > URL: https://www.atlantic.net/gpu-server-hosting/gpu-for-data-science-4-free-libraries-and-6-best-practices/ | Published: 2025-01-04 | Updated: 2025-03-26 | Author: Gilad Maayan ## What Is GPU Acceleration in Data Science? GPU acceleration in data science refers to using graphics processing units (GPUs) to improve data processing and analysis speeds. Unlike traditional CPUs, which have a few cores optimized for sequential processing, GPUs consist of thousands of smaller cores that handle multiple operations simultaneously. This parallel processing capability benefits data-intensive tasks such as machine learning, simulations, and data visualization, enabling quicker insights and outcomes. The transition to GPU acceleration arises from the increasing scale and complexity of data. As datasets grow in size, the demand for rapid computation increases. GPUs provide the ability to process vast amounts of data at speed, which is vital for developing real-time applications. By offloading demanding tasks to GPUs, data scientists can achieve significant reductions in computation times, ensuring the timely analysis of large-scale datasets. This is part of a series of articles about GPU applications. ## The Role of GPUs in Data Science Workflows GPUs support data science workflows by accelerating various computational processes. From data preprocessing and model training to visualization, GPUs enable faster execution of tasks that would otherwise take hours on CPUs. This performance is especially critical in iterative processes like model training, where multiple runs are needed to optimize parameters. GPUs are also essential in deep learning tasks, which are computationally intensive. High-dimensional data and complex models, often used in neural networks, benefit from the parallel computing power of GPUs. This results in quicker model convergence and the ability to handle larger datasets efficiently. ## Advantages of GPUs Over CPUs in Data Processing GPUs offer several distinct advantages over CPUs in the context of data processing: - **Parallel processing power**: GPUs handle multiple operations simultaneously due to their thousands of smaller cores. This makes them suited for tasks like matrix operations and large-scale computations common in data science. - **High throughput**: GPUs process large volumes of data in parallel, leading to significantly faster execution of data-intensive tasks compared to CPUs, which operate sequentially. - **Efficient for iterative tasks**: Machine learning workflows, especially training models, often involve repetitive computations. GPUs can speed up these iterative processes, reducing training times from days to hours. - **Better handling of high-dimensional data**: GPUs manage complex calculations involving high-dimensional datasets, which are prevalent in tasks like deep learning. - **Cost-effectiveness for large-scale workloads**: While GPUs can be expensive upfront, their ability to handle massive workloads quickly often translates to lower costs in cloud environments where time-based billing is a factor. - **Optimization for AI and ML frameworks**: Popular frameworks like TensorFlow and PyTorch are optimized for GPU usage, enabling integration and performance gains in data science workflows. ***Related content: Read our guide to [GPU virtualization](https://www.atlantic.net/gpu-server-hosting/gpu-virtualization-techniques-solutions-and-best-practices/)*** ### Tips from the expert: ![Author icon](https://secure.gravatar.com/avatar/eb8695bf1d856d659c4fa98eba9e0c42?s=192&d=mm&r=g) ![Linkedin Icon](https://www.atlantic.net/wp-content/themes/anet/img/cloud/gpu/icon_linkedin.webp) #### Richard Bailey ##### Technical Editor Richard Bailey brings over two decades of IT expertise, from traditional data centers to cutting-edge cloud solutions. As the founder of [turbogeek.co.uk](https://turbogeek.co.uk/) and a seasoned writer, he focuses on delivering authoritative content on our hosting services, HIPAA compliance, and related topics. In my experience, here are tips that can help you make the most of GPU acceleration in data science: 1. **Use mixed precision training for deep learning:** Leverage mixed precision training (combining 16-bit and 32-bit floating-point calculations) to reduce memory usage and speed up computations without compromising model accuracy. Frameworks like TensorFlow and PyTorch support this natively with tools like torch.cuda.amp or TensorFlow’s MixedPrecision API. 2. **Pin processes to GPU cores:** For multi-GPU setups, pin specific processes or tasks to designated GPUs using CUDA_VISIBLE_DEVICES or framework-specific GPU affinity tools. This minimizes resource contention and ensures balanced GPU utilization, especially for distributed training or concurrent tasks. 3. **Preprocess data on the GPU:** Move preprocessing tasks like data augmentation, normalization, or feature extraction to the GPU to reduce CPU-GPU transfer overhead. Libraries such as NVIDIA DALI (Data Loading Library) can offload these operations directly to GPUs for higher throughput. 4. **Implement checkpointing in iterative workflows:** For long-running model training or iterative simulations, implement checkpointing to save intermediate results. This ensures data scientists can resume operations in case of system interruptions, saving time and GPU resources in redoing previous steps. 5. **Experiment with GPU-optimized neural network architectures:** Choose neural network architectures that are optimized for GPU workloads, such as EfficientNet or ResNet. These architectures are designed for reduced computation and memory usage, maximizing the parallel capabilities of GPUs without unnecessary resource strain. ## 4 Open Source Libraries for GPU-Accelerated Data Science ### 1. cuDF **License:** Apache-2.0 **Repository:** https://github.com/rapidsai/cudf **GitHub stars:** 8K+ **Contributors:** 200+ cuDF is a GPU-accelerated library for data manipulation, enabling data processing tasks akin to Pandas but optimized for GPUs. It allows manipulation of DataFrames and offers operations like filtering, aggregation, and joining at higher speeds. cuDF integrates with RAPIDS AI, enabling end-to-end data science pipelines to benefit from GPU acceleration. The adoption of cuDF provides a marked improvement in performance for data science workflows. By offloading computation to GPUs, users experience reduced processing times and increased efficiency when handling large datasets. This advantage is especially evident in real-time data analytics and when iterating over large datasets. ### 2. cuML **License:** Apache-2.0 **Repository:** https://github.com/rapidsai/cuml **GitHub stars:** 4K+ **Contributors:** 100+ cuML is a suite of machine learning algorithms that runs on GPUs, providing accelerated training and inference capabilities. It aims to replicate the functionality of scikit-learn using GPUs’ parallel processing power, supporting a broad range of tasks such as classification, regression, and clustering. By leveraging cuML, users can speed up model training processes, especially with large datasets. cuML’s GPU-centric design ensures scalability and performance in machine learning workflows. For example, operations like k-means clustering or linear regression are expedited, freeing resources and time for further experimentation and refinement. ### 3. cuGraph **License:** Apache-2.0 **Repository:** https://github.com/rapidsai/cugraph **GitHub stars:** 1K+ **Contributors:** 100+ cuGraph specializes in graph analytics, utilizing GPUs to process graph algorithms efficiently. It supports tasks like PageRank, connectivity, and link analysis, which benefit from GPU’s parallel computation capabilities. This library accelerates graph processing compared to CPU-bound frameworks, improving performance for large-scale network analyses in real-world applications. cuGraph provides data scientists with the tools to quickly derive insights from complex, interconnected data. The speed of execution allows for handling increasingly large graphs relevant in social network analysis, fraud detection, and recommendation systems. By integrating with the RAPIDS ecosystem, cuGraph enables comprehensive analytics solutions. ### 4. XGBoost for GPUs **License:** Apache-2.0 **Repository:** https://github.com/dmlc/xgboost/tree/master **GitHub stars:** 26K+ **Contributors:** 600+ XGBoost for GPUs is a high-performance library leveraging GPU power for gradient boosting tasks. Offering speed and accuracy, XGBoost is widely adopted in data science for building predictive models. The GPU-accelerated version handles tasks faster than its CPU counterpart by parallelizing tree building and boosting tasks, crucial for iterative modeling and evaluation. Deploying XGBoost on GPUs provides substantial performance gains, particularly with large datasets and complex models. The reduction in training time allows data scientists to iterate more rapidly, improving model tuning and optimization. The integration of GPU capabilities into XGBoost makes it a favored choice for competitions and scenarios where both speed and accuracy are paramount. ## 6 Best Practices for GPU-Accelerated Data Science By implementing the following practices, organizations can ensure the most effective use of GPUs for data science applications. ### 1. Optimize Data Loading and Preprocessing Optimizing data loading and preprocessing is crucial in GPU-accelerated data science. Efficient handling of data ensures that GPUs receive the necessary data without bottlenecks. Techniques such as using appropriate data formats (e.g., CSV vs. Parquet), batching, and chunking help maintain data throughput to the GPU, minimizing idle times and maximizing performance. Investing time in preprocessing can significantly reduce the computational load during actual processing. For example, aligning data types and structures with GPU memory can improve execution speed. Efficient preprocessing also involves scaling and normalizing data to ensure compatibility and performance improvements during data-intensive operations on the GPU. ### 2. Minimize Data Transfer Between CPU and GPU Minimizing data transfer between CPU and GPU is essential for maximizing performance in GPU-accelerated workflows. Data transfers are relatively slow compared to the computational capabilities of GPUs, potentially leading to bottlenecks. Strategies such as keeping data within the GPU-memory realm once transferred can significantly improve execution times. Techniques such as copying all necessary data at once and structuring computations to minimize CPU-GPU interactions help reduce transfer times. This practice speeds up current operations and allows for efficient multitasking and parallel workflows, where more complex operations can run simultaneously without excessive data shuttling requirements. ### 3. Utilize Efficient Memory Management Efficient memory management is important for optimizing GPU performance in data science tasks. Properly allocating and deallocating GPU memory prevents resource congestion and maximizes available memory for large datasets and models. Using memory pools and ensuring data structures are suited for GPU cache sizes can prevent memory-related slowdowns. Conscientious memory management practices include reusing memory allocations instead of frequent reallocations, which is particularly useful in iterative processes. This approach minimizes memory fragmentation, leading to smoother operations. ### 4. Profile and Monitor GPU Performance Profiling and monitoring GPU performance are vital for maintaining efficient data science workflows. Continuous monitoring helps identify performance bottlenecks, such as underutilized computational resources or overextended memory use. Tools like NVIDIA’s NSight or similar profiling tools can provide insights into GPU usage patterns, helping to optimize tasks. Regular performance evaluation ensures that any changes in workload or system setup maintain optimal GPU efficiency. This involves tracking metrics like memory usage, processing time, and kernel execution times to understand GPU behavior better. ### 5. Leverage Parallelism in Algorithms Leveraging parallelism in algorithms is vital for maximizing GPU capabilities in data science. GPUs are inherently designed for parallel operations, and algorithms that utilize this feature can significantly improve processing speeds. Implementing parallel techniques in tasks like sorting or matrix multiplication allows for full exploitation of GPU architecture. Designing algorithms to operate in parallel involves decomposing tasks so they can be executed concurrently across multiple GPU cores. This approach is particularly effective in machine learning, where operations such as training can be parallelized, reducing computation time and resources. ### 6. Utilize GPU Hosting GPU hosting refers to leveraging cloud-based or on-premises infrastructure to access powerful GPUs for data science tasks. Several cloud platforms and hosting providers offer on-demand GPU instances, enabling data scientists to scale their workflows without the need for costly hardware investments. These services provide flexibility, allowing users to choose configurations that match their requirements, such as the number of GPUs or memory capacity. GPU hosting allows data scientists to access high-performance resources for tasks like deep learning, model training, and real-time analytics. By opting for managed services, users benefit from optimized environments with pre-installed frameworks, such as TensorFlow or PyTorch, reducing setup time. Hosted GPUs also often include tools for monitoring and optimizing resource usage. ## **Next-Gen Dedicated GPU Servers from Atlantic.Net, Accelerated by NVIDIA** Experience unparalleled performance with dedicated cloud servers equipped with the revolutionary NVIDIA accelerated computing platform. Choose from the NVIDIA L40S GPU and NVIDIA H100 NVL to unleash the full potential of your generative artificial intelligence (AI) workloads, train large language models (LLMs), and harness natural language processing (NLP) in real time. High-performance GPUs are superb at scientific research, 3D graphics and rendering, medical imaging, climate modeling, fraud detection, financial modeling, and advanced video processing. [Learn more about Atlantic.net GPU server hosting](https://www.atlantic.net/gpu-server-hosting/) --- # GPU Parallel Computing: Techniques, Challenges, and Best Practices > URL: https://www.atlantic.net/gpu-server-hosting/gpu-parallel-computing-techniques-challenges-and-best-practices/ | Published: 2025-01-06 | Updated: 2025-03-26 | Author: Gilad Maayan ## What Is GPU Parallel Computing? GPU parallel computing involves using graphics processing units (GPUs) to run many computation tasks simultaneously. Unlike traditional CPUs, which are optimized for single-threaded performance, GPUs handle many tasks at once due to their thousands of smaller cores. This architecture is suited for tasks where computations can be distributed across multiple processors, making it integral to fields requiring large-scale data processing, such as machine learning, scientific simulations, and financial modeling. GPU parallel computing relies on executing multiple operations concurrently, leveraging the parallel architecture of GPUs. This is achieved by dividing the workload into smaller tasks and executing them simultaneously across the GPU cores. By utilizing this capability, applications can achieve significant speed improvements compared to CPU-only processing. This is part of a series of articles about [GPU for AI](https://www.atlantic.net/gpu-server-hosting/gpu-for-ai-platforms-top-gpus-and-key-features-to-consider/). ## Benefits of GPU Parallel Computing GPU parallel computing offers a range of advantages for applications requiring high performance and efficiency: - **Enhanced computational speed:** GPUs process multiple tasks simultaneously, significantly reducing execution time for data-intensive operations like machine learning and simulations compared to CPU-based processing. - **Energy efficiency:** GPUs perform parallel operations more efficiently, consuming less energy per computation. This makes them ideal for large-scale data centers and energy-conscious applications. - **Scalability:** Modern GPUs scale effectively across increasing data sizes and multiple devices, enabling linear speedups for demanding workloads. - **Support for complex algorithms:** GPUs facilitate the execution of algorithms, such as those used in deep learning and scientific simulations, which were previously infeasible due to computational limits. - **Improved resource utilization:** By executing thousands of threads concurrently, GPUs maximize hardware utilization, ensuring computational resources are effectively employed for suitable workloads. ***Related content: Read our guide to [GPU cloud computing](https://www.atlantic.net/gpu-server-hosting/gpus-in-cloud-computing-4-cloud-providers-compared/)*** ## Programming Models for GPU Parallel Computing GPU parallel computing utilizes various programming models to facilitate the execution of parallel tasks. ### CUDA Programming Model The CUDA programming model, developed by NVIDIA, is tailored for developers aiming to optimize computing operations on NVIDIA GPUs. It allows direct access to the GPU’s parallel architecture, enabling significant performance boosts for applications that can benefit from parallelism. CUDA provides a set of extensions to the C programming language, empowering developers to write functions, known as kernels, that execute across multiple GPU cores. This enables efficient data processing and algorithm execution in fields that demand high computational power. CUDA excels in scalability and efficiency, allowing developers to handle complex computational tasks with ease. The model supports various memory types and synchronization techniques that enhance data handling and thread coordination. This flexibility and control make it a preferred choice for domains like scientific computing, deep learning, and real-time rendering. CUDA also provides extensive libraries and tools provide support for debugging and optimization. ### OpenCL Framework The OpenCL (Open Computing Language) framework is an open standard for cross-platform parallel computing. It facilitates the execution of tasks across diverse hardware platforms, including GPUs, CPUs, and other processors. OpenCL’s flexibility makes it an attractive option for developers seeking to write portable code that can efficiently run on different devices and architectures. It allows the use of a common language to harness the processing power of available hardware. OpenCL provides detailed control over computational resources, enabling developers to optimize performance across a wide array of devices. It defines a programming interface for writing kernels, which are executed in parallel across processing elements within the system’s devices. This model supports parallel execution on heterogeneous systems, bridging the gap between different computational devices. ### Vulkan Compute Shaders Vulkan is a low-level API that allows developers to control graphics and computation on modern GPUs. Specifically, its compute shaders facilitate parallel computation outside traditional graphics rendering tasks. By providing direct access to GPU resources, Vulkan enables fine-tuned performance optimization, making it suitable for applications requiring extensive computational workloads, such as simulations and custom rendering engines. Compute shaders in Vulkan are designed to handle complex mathematical operations needed for non-graphics computation. The API’s low-level nature means a steep learning curve, but it rewards with uncompromised performance and detailed management of GPU operations. Unlike more generalized frameworks, Vulkan’s emphasis on explicit resource management can lead to more efficient execution, assuming developers manage synchronization and resource allocation precisely. ## Parallel Computing Techniques on GPUs ### Data Parallelism Data parallelism involves executing the same operation on distributed data simultaneously across multiple GPU cores. This technique is effective for workload types that require repetitive operations on large datasets. By processing data chunks in parallel, data parallelism accelerates the computation process, significantly reducing execution time compared to serial processing. This approach is widely applicable in tasks like matrix multiplications, image processing, and neural network training. One of the primary advantages of data parallelism is its scalability. As datasets grow, the work can be divided into more portions and allocated to the available GPU cores, effectively managing large-scale computations. The increased throughput comes from the parallel execution, which not only speeds up processing but also enhances resource utilization. Effective implementation of data parallelism requires careful synchronization and management of data dependencies to ensure accuracy and efficiency in computational tasks. ### Task Parallelism Task parallelism divides applications into distinct tasks that can be processed concurrently, providing a different approach to parallel computation. Unlike data parallelism, which focuses on dividing data, task parallelism concentrates on splitting the work itself into smaller, independent tasks. This technique is optimal for applications where tasks can run independently and in parallel, such as rendering different frames in parallel within a video game or processing various inputs in a multi-threaded server application. Implementing task parallelism on a GPU requires careful structuring to ensure tasks execute independently without data conflicts. Since each task can be distinct and possibly varied in resource requirements, load balancing and scheduling become critical. Efficient task parallelism enhances application throughput by executing multiple functions simultaneously, leveraging the full capability of GPU resources. By effectively distributing tasks across GPU cores, developers can maximize processing efficiency and achieve higher performance for complex applications requiring multiprocess execution. ### Hybrid Parallelism Hybrid parallelism combines data and task parallelism, creating a strategy for efficiently utilizing GPU resources. This approach is beneficial in complex applications where both large data sets and diverse task management are required. Hybrid parallelism allows simultaneous management of data and tasks, dynamically adjusting to application demands and improving overall throughput and resource usage. By integrating both parallelism strategies, hybrid parallelism maximizes GPU potential, particularly in heterogeneous computing environments where multiple task types and data processing needs arise simultaneously. However, successful hybrid parallelism implementation often requires intricate understanding of GPU architecture and workload characteristics to balance and coordinate tasks and data efficiently. ### Tips from the expert: ![Author icon](https://secure.gravatar.com/avatar/eb8695bf1d856d659c4fa98eba9e0c42?s=192&d=mm&r=g) ![Linkedin Icon](https://www.atlantic.net/wp-content/themes/anet/img/cloud/gpu/icon_linkedin.webp) #### Richard Bailey ##### Technical Editor Richard Bailey brings over two decades of IT expertise, from traditional data centers to cutting-edge cloud solutions. As the founder of [turbogeek.co.uk](https://turbogeek.co.uk/) and a seasoned writer, he focuses on delivering authoritative content on our hosting services, HIPAA compliance, and related topics. In my experience, here are tips that can help you better leverage GPU parallel computing for advanced performance and efficiency: 1. **Use GPU occupancy calculators:** Use GPU occupancy calculators (e.g., NVIDIA’s Occupancy Calculator) to fine-tune the number of active warps and achieve the optimal balance between register usage, shared memory, and thread count. This ensures maximum throughput while avoiding underutilization or resource contention. 2. **Employ warp specialization:** Design threads within a warp to specialize in different subtasks (e.g., some threads handle computation while others manage memory prefetching). This approach reduces memory latency and improves performance for highly memory-bound applications. 3. **Exploit hardware-accelerated tensor cores (where available):** If using GPUs like NVIDIA’s Tensor Core GPUs, take advantage of tensor operations (e.g., matrix-matrix multiplications in mixed precision) to drastically accelerate workloads in deep learning and linear algebra. This requires leveraging libraries like cuBLAS or writing custom kernels that utilize these specialized cores. 4. **Minimize divergence in thread execution:** Avoid conditional branching (if-else) within GPU warps, as divergent execution paths cause some threads to idle while others execute. Instead, restructure algorithms to use uniform branching or predicated instructions to ensure all threads execute together. 5. **Implement memory prefetching:** Manually prefetch data from global memory to shared memory in advance of computation. This overlaps memory latency with computation, preventing threads from stalling while waiting for data transfers. ## Common Challenges of GPU Parallel Computing Despite its advantages, GPU parallel computing poses several challenges: ### Debugging Parallel Code Debugging parallel code involves challenges not typically encountered in single-threaded programs. The concurrent execution of multiple threads can lead to unpredictable results, making it difficult to trace and diagnose issues using traditional debugging methods. This complexity necessitates specialized tools that can track thread activity and state, helping developers identify problems like deadlocks and race conditions, where threads compete for shared resources unpredictably. These tools must handle the intricacies of parallel execution, providing insights into thread interactions and synchronization issues. Effective debugging requires understanding not only the logical flow of the program but also the memory interactions between concurrent threads. GPUs, with their vast number of cores executing operations simultaneously, exacerbate these issues. Developers often need to employ techniques such as logging states or using parallel debugging utilities to manage and resolve issues arising from parallel code execution. ### Handling Race Conditions Race conditions occur when multiple threads access shared data simultaneously, leading to unpredictable results. Handling these conditions on GPUs is challenging due to the inherent parallelism and the vast number of concurrent processes. Effective management of race conditions requires a comprehensive understanding of synchronization techniques, including mutexes, locks, and atomic operations, which ensure orderly access to shared resources. Addressing race conditions involves identifying potential conflict areas and implementing appropriate synchronization mechanisms to manage resource access. However, excessive synchronization can hinder performance gains from parallelism by introducing bottlenecks. Striking a balance between ensuring correct data handling and maintaining performance efficiency is essential. Developers must carefully design algorithms to minimize shared resource interaction while utilizing GPU capabilities efficiently. ### Scalability Issues Scalability in GPU parallel computing involves maintaining performance gains as workloads and data sizes grow. A common issue arises when increased workload sizes lead to diminishing returns in speed and efficiency. This challenge can result from inefficiencies in workload distribution, memory access patterns, or insufficient GPU resource utilization. Unbalanced workloads lead to underutilized cores, negating the benefits of parallelism and reducing computational effectiveness. To resolve scalability issues, developers must focus on optimal resource allocation, efficient memory usage, and effective workload distribution. Techniques such as load balancing, where tasks are evenly distributed across GPU cores, and optimizing memory transfer operations, are vital for maintaining scalability. Additionally, understanding the architectural limitations and leveraging hardware-specific features can enhance performance. By addressing these factors, developers can ensure that their applications scale effectively, maximizing computational capabilities and maintaining high performance levels as workload demands increase. ## Best Practices for GPU Parallel Computing ### 1. Profile and Benchmark Regularly Profiling and benchmarking are crucial practices in GPU parallel computing, essential for maximizing application performance. Regular profiling involves monitoring the application’s runtime behavior to identify bottlenecks, inefficient resource use, and areas where improvements can be made. Tools like NVIDIA Nsight and AMD’s CodeXL allow developers to gain insights into how a GPU executes their code, highlighting inefficiencies in memory usage and execution paths that might hinder performance. Benchmarking provides a framework for measuring application performance against predefined standards or previous versions, helping developers track improvements and regressions. By comparing these metrics over time, developers can assess the impact of code changes or hardware upgrades on application performance. Regular execution of these practices ensures that applications remain efficient, scalable, and capable of leveraging the full potential of their GPU resources. ### 2. Optimize Memory Access Patterns Optimizing memory access patterns is essential for efficient GPU parallel computing. Efficient memory use minimizes access latency and maximizes bandwidth utilization, critical for achieving high performance. GPUs have a hierarchical memory structure with significant speed differences between levels, so accessing global memory is expensive compared to shared memory. For optimal performance, developers should reduce global memory calls, making effective use of faster memory types like shared memory and registers, thus enhancing data throughput and execution speed. Additionally, coalescing memory accesses—ensuring that memory operations align with GPU architecture—limits unnecessary data transfer and makes better use of memory bandwidth. By organizing data structures and memory access patterns to fit the GPU’s architecture, developers can reduce bottlenecks and enhance performance. Understanding GPU memory architecture and its impact on computational efficiency is pivotal. Through careful consideration and optimization of memory access patterns, applications can achieve higher execution rates. ### 3. Utilize Asynchronous Execution Asynchronous execution in GPU computing involves executing tasks concurrently without waiting for other operations, significantly enhancing performance by overlapping computations and data transfers. By using streams or command queues, developers can decouple data management from computation, allowing GPUs to process data while simultaneously executing kernels. This reduces idle time and maximizes resource usage, leading to improved throughput and efficiency in GPU applications. Employing asynchronous execution requires careful planning to avoid race conditions and ensure correct synchronization between tasks. Proper management of asynchronous workflows ensures that data dependencies are respected, and results remain accurate. Utilizing CUDA streams or OpenCL command queues, for instance, provides mechanisms for executing multiple operations asynchronously, optimizing the sequencing and overlap of different tasks. ### 4. Balance Workloads Across Threads and Blocks Balancing workloads across threads and blocks ensures that GPU resources are efficiently utilized, preventing some threads from idling while others are overloaded. This balance is vital for maximizing parallel execution efficiency, as uneven distribution can lead to underutilized cores and reduced performance gains from parallelism. Developers need to divide tasks such that all threads and blocks handle equivalent amounts of work, ensuring uniform resource utilization and minimizing waiting time. Achieving effective workload balance requires understanding the application’s computational demands and the GPU’s architectural characteristics. Techniques such as dynamic load balancing and adjusting block sizes in response to workload characteristics can help achieve even distribution. By refining the workload division, developers enhance throughput by ensuring all available resources contribute to task execution. This strategic partitioning maximizes computational efficiency and resource usage. ### 5. Keep Kernels Lightweight Keeping kernels lightweight is critical for efficient GPU parallel computing, focusing on minimizing the computational complexity and runtime length of each task. Lightweight kernels ensure that tasks execute quickly, maximizing the number of operations that the GPU can perform in a given time. This practice leads to better resource utilization and higher application throughput, reducing the overhead introduced by complex or overly large kernels. Lightweight kernels can achieve higher performance by facilitating faster context switching and allowing more concurrent task executions within the GPU. Developers should aim to simplify operations within kernels, breaking down complex tasks into smaller, manageable kernels that efficiently utilize the GPU’s parallel capabilities. While lightweight design may require more kernels to accomplish a task, their efficiency and reduced computational footprint generally result in superior performance. ## **Next-Gen Dedicated GPU Servers from Atlantic.Net, Accelerated by NVIDIA** Experience unparalleled performance with dedicated cloud servers equipped with the revolutionary NVIDIA accelerated computing platform. Choose from the NVIDIA L40S GPU and NVIDIA H100 NVL to unleash the full potential of your generative artificial intelligence (AI) workloads, train large language models (LLMs), and harness natural language processing (NLP) in real time. High-performance GPUs are superb at scientific research, 3D graphics and rendering, medical imaging, climate modeling, fraud detection, financial modeling, and advanced video processing. [Learn more about Atlantic.net GPU server hosting](https://www.atlantic.net/gpu-server-hosting/) --- # GPU Computing: Use Cases, Challenges, and 5 Critical Best Practices > URL: https://www.atlantic.net/gpu-server-hosting/gpu-computing-use-cases-challenges-and-5-critical-best-practices/ | Published: 2025-01-07 | Updated: 2025-03-26 | Author: Gilad Maayan ## What Is GPU Computing? GPU computing involves utilizing graphics processing units (GPUs) to perform computation typically executed by a CPU. This approach leverages the parallel processing capabilities of GPUs to expedite complex computational tasks. Originally designed to render graphics, GPUs are now used for a broad array of applications due to their ability to process many tasks simultaneously. This parallel architecture makes them suited for handling large-scale computations quicker than traditional CPUs. The significance of GPU computing is rooted in its ability to handle massive datasets and perform extensive calculations at an accelerated pace. It has become a vital tool in fields requiring intensive computation. Through the use of APIs like CUDA and OpenCL, developers can exploit GPUs to reduce execution times for various applications, ranging from scientific computations to machine learning models. This is part of a series of articles about [GPU for AI](https://www.atlantic.net/gpu-server-hosting/gpu-for-ai-platforms-top-gpus-and-key-features-to-consider/). ## Evolution of GPUs: From Graphics to General Purpose Computing GPUs were initially designed to accelerate rendering tasks for computer graphics, handling operations like shading, texture mapping, and 3D transformations. These tasks benefited greatly from the parallel processing nature of GPUs, which could handle multiple graphical computations simultaneously. As video games and visual effects demanded increasingly sophisticated graphics, GPU architectures evolved to deliver higher performance and more flexibility. The shift toward general-purpose computing began in the early 2000s when developers recognized that the parallel processing capabilities of GPUs could also be applied to non-graphical computations. This realization led to the development of programming frameworks like CUDA (by NVIDIA) and OpenCL (an open standard), which allowed GPUs to perform a wider range of computational tasks. These frameworks enabled researchers and engineers to harness GPUs for applications beyond graphics, such as scientific simulations, machine learning, and data analytics. Modern GPUs are designed with high-performance computing in mind, offering thousands of cores optimized for parallelism, large memory bandwidth, and support for advanced programming models. This evolution has transformed GPUs into tools for solving complex problems across various domains, from medical imaging to autonomous vehicles. ***Related content: Read our guide to [GPU cloud computing](https://www.atlantic.net/gpu-server-hosting/gpus-in-cloud-computing-4-cloud-providers-compared/)*** ## Key Use Cases of GPU Computing ### Scientific Computing Scientific computing utilizes GPUs to solve complex mathematical problems faster than traditional computing methods. In fields like physics, chemistry, and genomics, the parallel processing power of GPUs enables researchers to conduct simulations and analyze data at unprecedented speeds. The ability to perform large-scale computations simultaneously makes GPUs essential tools in these research areas, delivering results in a fraction of the time previously required. ### Machine Learning and Deep Learning In machine learning and deep learning, GPUs have become indispensable due to their capability to process vast datasets and run computations in parallel. Tasks that involve large neural networks benefit significantly from GPU acceleration, which reduces training time and enhances performance. The architecture of GPUs aligns well with the parallelizable nature of machine learning algorithms, making them ideal for deploying high-performance models. The use of GPUs in these fields allows for efficient handling of complex operations, such as matrix multiplications and data transformations, which are foundational to neural network training. This efficiency speeds up model development, enabling researchers and developers to iterate and optimize models rapidly. ### Data Analytics Data analytics benefits greatly from GPU computing by accelerating data processing speeds and enabling real-time analysis. As datasets grow in size and complexity, traditional CPUs struggle to keep pace. GPUs, however, offer the necessary compute power to process and analyze large volumes of data quickly, providing insights faster. This characteristic is essential in industries like finance and healthcare, where timely decision-making is critical. GPU acceleration in data analytics facilitates complex computations such as big data processing and real-time querying. Businesses can leverage GPU power to derive actionable insights from data streams, improving responsiveness and strategic planning. ### Cryptography and Blockchain Cryptography and blockchain technologies have found a natural fit with GPU computing due to the intensive mathematical operations involved. GPUs accelerate tasks such as hashing and encryption by executing multiple calculations in parallel. This capability is especially valuable in cryptocurrency mining, where speed and efficiency directly influence profitability. Blockchain technology relies heavily on the ability to perform secure transactions rapidly, an area where GPUs excel. The parallel nature of GPU processors supports enhanced encryption and decryption capabilities, making them efficient tools for cryptographic applications. This advantage extends to blockchain operations, such as validating transactions and managing distributed ledgers. ### Tips from the expert: ![Author icon](https://secure.gravatar.com/avatar/eb8695bf1d856d659c4fa98eba9e0c42?s=192&d=mm&r=g) ![Linkedin Icon](https://www.atlantic.net/wp-content/themes/anet/img/cloud/gpu/icon_linkedin.webp) #### Richard Bailey ##### Technical Editor Richard Bailey brings over two decades of IT expertise, from traditional data centers to cutting-edge cloud solutions. As the founder of [turbogeek.co.uk](https://turbogeek.co.uk/) and a seasoned writer, he focuses on delivering authoritative content on our hosting services, HIPAA compliance, and related topics. In my experience, here are tips that can help you better harness GPU computing effectively: 1. **Optimize GPU utilization through workload profiling:** Use tools like NVIDIA Nsight Systems or AMD’s ROCm profiler to analyze how your workloads utilize GPU resources. By identifying bottlenecks such as idle cores, memory transfer delays, or suboptimal thread usage, you can fine-tune your code for maximum performance. 2. **Avoid memory oversubscription with careful batching:** Instead of transferring the entire dataset to GPU memory at once, split it into smaller batches that fit within available memory. This prevents performance degradation from oversubscription and allows the GPU to operate more efficiently. 3. **Exploit multi-GPU environments with optimized frameworks:** For multi-GPU setups, use frameworks like NCCL (NVIDIA Collective Communication Library) to ensure efficient communication between GPUs. Avoid redundant data transfers by designing algorithms with reduced inter-GPU synchronization. 4. **Adopt containerized GPU environments:** Use container technologies like NVIDIA Docker or Singularity to standardize and simplify GPU-enabled application deployment. This ensures consistent performance across different environments and avoids compatibility issues. 5. **Incorporate energy-aware scheduling:** Develop energy-efficient scheduling techniques that dynamically adjust GPU workloads based on performance and energy trade-offs. Combine this with real-time energy monitoring tools like NVIDIA’s nvidia-smi to reduce power consumption without compromising performance. ## Challenges in GPU Computing ### Scalability Issues Scalability is a significant challenge in GPU computing, particularly when deploying applications across multiple GPUs or clusters. The difficulty lies in efficiently distributing workloads and maintaining communication between devices to optimize performance. As applications grow in complexity, ensuring scalability without performance bottlenecks becomes crucial, requiring sophisticated algorithms and efficient data management strategies. Managing scalability involves addressing hardware limitations and ensuring software frameworks can handle increased loads. Ensuring that applications remain efficient as they scale is complex, demanding constant monitoring and adjustments to balance loads across different GPUs. ### Power Consumption Power consumption is a critical concern in GPU computing, impacting both operational costs and environmental sustainability. GPUs are power-intensive, consuming substantial electricity to maintain their high-performance capabilities. This factor can lead to significant expenses, especially in large-scale or continuous operations, challenging organizations to balance performance gains with energy efficiency. To address power consumption issues, optimizing GPU applications for energy efficiency is essential. Techniques such as dynamic voltage scaling and workload management can mitigate power usage, but may require trade-offs in performance. ### Portability Across Different GPU Platforms Portability across various GPU platforms presents another significant challenge. Differences in hardware and software environments can complicate application deployment and maintenance. Developers need to ensure that their applications can run efficiently across different GPU architectures, which often involves accounting for varying capabilities and performance benchmarks. Addressing portability issues requires leveraging platform-agnostic development tools and adhering to standardized APIs. However, achieving true cross-platform compatibility can be labor-intensive, often necessitating modifications to codebases to exploit specific hardware features optimally. ## 5 Best Practices for Successful GPU Computing ### 1. Efficient Memory Usage Efficient memory usage is crucial in optimizing GPU performance. Given their limited memory compared to traditional CPUs, GPUs require careful management of resources to avoid bottlenecks. Techniques like memory coalescing, data compression, and optimizing memory transfers can significantly enhance GPU efficiency. Ensuring that memory is utilized effectively reduces latency and maximizes processing throughput. Developers should focus on minimizing data movement between the CPU and GPU, as this can slow operations considerably. Enhancing memory access patterns through meticulous coding practices is essential in maximizing resource utilization. ### 2. Choosing the Right GPU Hardware Selecting appropriate GPU hardware is vital for achieving desired performance outcomes. Factors like computational power, memory capacity, and power efficiency must be considered based on application requirements. A mismatch in hardware capabilities and application demands can lead to suboptimal performance or increased costs. Understanding the specific needs of your application guides optimal hardware investments. Evaluating GPUs based on benchmarks and performance metrics ensures compatibility with existing systems and scalability for future needs. Tailoring GPU choice to application specifics can enhance performance efficiency, reduce processing times, and ensure cost-effectiveness. ### 3. Utilizing GPU-Accelerated Libraries GPU-accelerated libraries offer pre-optimized solutions to boost application performance without requiring extensive code modifications. Libraries like cuBLAS, cuDNN, and TensorRT provide efficient implementations of common algorithms, allowing developers to leverage GPU power seamlessly. These tools reduce development time while maximizing performance gains in numerical computations and machine learning tasks. Integrating GPU-accelerated libraries requires understanding their functionalities and compatibility with existing codebases. By utilizing these libraries, developers can focus on application-specific logic while relying on tried-and-tested optimizations for underlying processes. ### 4. Keeping Up with Driver and Toolkit Updates Staying current with driver and toolkit updates is essential for maintaining optimal GPU performance. Manufacturers continually release updates to enhance capabilities, fix bugs, and improve security. Ensuring that GPUs operate with the latest drivers and toolkits can enhance functionality and prevent compatibility issues, particularly as new applications and features are developed. Regular update management involves monitoring release notes and understanding the impact of changes. This practice ensures that you leverage the full potential of GPU advancements and address any emerging vulnerabilities. ### 5. Consider GPU Server Hosting Hosted GPU servers offers scalable solutions for organizations requiring high-performance computing environments. Advanced hosting providers provide dedicated GPU resources that can be tailored to specific workload demands, ensuring efficient processing across diverse applications. Leveraging GPU server hosting can reduce infrastructure costs and simplify IT management. By utilizing external hosting services, companies can focus on core business tasks while ensuring robust computational support. This approach allows for seamless scaling of resources in response to workload fluctuations, providing an adaptable and cost-effective computing environment. ## Next-Gen Dedicated GPU Servers from Atlantic.Net, Accelerated by NVIDIA Experience unparalleled performance with dedicated cloud servers equipped with the revolutionary NVIDIA accelerated computing platform. Choose from the NVIDIA L40S GPU and NVIDIA H100 NVL to unleash the full potential of your generative artificial intelligence (AI) workloads, train large language models (LLMs), and harness natural language processing (NLP) in real time. High-performance GPUs are superb at scientific research, 3D graphics and rendering, medical imaging, climate modeling, fraud detection, financial modeling, and advanced video processing. [Learn more about Atlantic.net GPU server hosting](https://www.atlantic.net/gpu-server-hosting/) --- # GPGPU vs. GPU: 4 Key Differences and GPGPU Best Practices > URL: https://www.atlantic.net/gpu-server-hosting/gpgpu-vs-gpu-4-key-differences-and-gpgpu-best-practices/ | Published: 2025-01-08 | Updated: 2025-03-26 | Author: Gilad Maayan ## What Is a GPU? A graphics processing unit (GPU) is a specialized processor for graphics rendering. It handles large data blocks and complex calculations, making it crucial for rendering images, videos, and animations in computer applications. GPUs consist of hundreds to thousands of smaller cores than central processing units (CPUs), enabling parallel processing. Initially, GPUs were developed for real-time graphics rendering for gaming but have since evolved to support tasks requiring massive parallel processing power. They handle tasks like image processing, machine learning, and scientific simulations. By offloading certain tasks from the CPU, GPUs boost overall system performance and efficiency. ## What Is GPGPU? General-purpose computing on graphics processing units (GPGPU) refers to using a GPU to perform computation traditionally handled by a CPU. It transforms a GPU from a specialized graphics engine into a general-purpose parallel processing unit. This capability allows for processing non-graphical mathematical and data-centric tasks. GPGPU leverages the architecture of GPUs, which are inherently parallel, to accelerate a broad range of tasks beyond graphics. It has become valuable for operations intensive in data and computation, such as deep learning, scientific research, and financial modeling. This is part of a series of articles about [GPU for AI](https://www.atlantic.net/gpu-server-hosting/gpu-for-ai-platforms-top-gpus-and-key-features-to-consider/). ## Evolution of GPUs The evolution of GPUs spans several decades, driven by advancements in graphics technology and the increasing need for computational power. Early GPUs, introduced in the 1980s and 1990s, were primarily fixed-function hardware for rendering 2D and 3D graphics. These GPUs focused on accelerating tasks such as rasterization, shading, and texture mapping, which were computationally intensive for CPUs at the time. In the early 2000s, programmable GPUs emerged, allowing developers to write custom shaders using programming languages like DirectX HLSL and OpenGL GLSL. This shift marked a significant turning point, enabling more flexibility in graphics rendering and laying the groundwork for general-purpose GPU computing. Modern GPUs, such as those from NVIDIA and AMD, are highly sophisticated, featuring thousands of cores and support for parallel computing frameworks like CUDA and OpenCL. These GPUs are no longer confined to graphics tasks—they now play a central role in high-performance computing applications, including artificial intelligence, video processing, and scientific simulations. The introduction of tensor cores and AI accelerators in recent GPU generations has further solidified their importance for modern computational use cases. ## How GPGPU Works GPGPU leverages the parallel architecture of GPUs to accelerate computational tasks by dividing them into smaller chunks that can be processed simultaneously. Unlike CPUs, which typically have a few powerful cores optimized for sequential processing, GPUs have thousands of smaller cores designed for concurrent execution, making them ideal for tasks with repetitive operations on large datasets. To utilize GPGPU, developers write programs using parallel computing frameworks like CUDA (NVIDIA) or OpenCL (cross-platform). These programs break down computations into kernels, which are small units of code executed in parallel by GPU threads. For example, in matrix multiplication, each thread might handle the calculation of a single matrix element, enabling thousands of computations to occur simultaneously. GPGPU’s efficiency stems from its memory hierarchy, including shared memory for thread communication and global memory for larger data storage. By minimizing data transfers between the GPU and CPU, and optimizing memory usage within the GPU, performance can be maximized. Applications of GPGPU range from accelerating deep learning models by rapidly training neural networks to processing large-scale simulations in physics and chemistry. Its ability to handle massive parallelism makes it indispensable in many domains where speed and scalability are critical. ***Related content: Read our guide to [GPU parallel computing](https://www.atlantic.net/gpu-server-hosting/gpu-parallel-computing-techniques-challenges-and-best-practices/)*** ### Tips from the expert: ![Author icon](https://secure.gravatar.com/avatar/eb8695bf1d856d659c4fa98eba9e0c42?s=192&d=mm&r=g) ![Linkedin Icon](https://www.atlantic.net/wp-content/themes/anet/img/cloud/gpu/icon_linkedin.webp) #### Richard Bailey ##### Technical Editor Richard Bailey brings over two decades of IT expertise, from traditional data centers to cutting-edge cloud solutions. As the founder of [turbogeek.co.uk](https://turbogeek.co.uk/) and a seasoned writer, he focuses on delivering authoritative content on our hosting services, HIPAA compliance, and related topics. In my experience, here are tips that can help you better understand and leverage the differences between GPUs and GPGPU for computational workloads: 1. **Assess computational intensity to determine GPU vs. GPGPU needs:** Not all workloads benefit equally from GPGPU. For example, tasks with low parallelizability (like recursive algorithms) may perform better on CPUs or hybrid architectures. Benchmark your specific workload to identify if the complexity justifies GPGPU optimization. 2. **Use domain-specific libraries for faster implementation:** Many industries now offer pre-built libraries optimized for GPGPU (e.g., cuDNN for deep learning or TensorFlow-GPU for AI). These libraries take advantage of GPGPU APIs without requiring you to develop low-level kernels, saving development time while ensuring efficiency. 3. **Combine CPU and GPU workloads strategically:** Offloading all tasks to a GPU can sometimes lead to inefficiencies. Use a hybrid approach where CPUs handle sequential or low-parallelism tasks while GPUs focus on parallelizable components. Frameworks like CUDA Streams can help synchronize these processes effectively. 4. **Account for PCIe latency in data transfers:** Data transfer between the host (CPU) and GPU via PCIe can become a bottleneck. Minimize these transfers by caching data on the GPU memory whenever possible. Consider using Unified Memory or pinned memory to further reduce latency for shared data. 5. **Experiment with mixed-precision computing:** Modern GPUs often support mixed-precision computing (e.g., FP16 or Tensor Cores). Using lower precision where possible can drastically increase throughput without significant accuracy loss in many applications like AI training and simulations. ## GPU vs. GPGPU: Key Differences ### 1. Architecture Differences GPUs traditionally focused on accelerating graphics tasks with a fixed-function pipeline, optimized for the inherent parallelism in image rendering. In contrast, GPGPU utilizes GPUs’ programmable nature to address a wider range of computational problems. Unlike traditional GPUs, GPGPU emphasizes flexibility and programmability, supporting diverse operations beyond graphics tasks. Modern GPUs are architecturally suited for GPGPU workloads, with unified shaders and increased memory bandwidth. They can handle complex calculations needed for scientific computing or machine learning. The move to general-purpose capabilities has driven changes in hardware design, enhancing GPUs’ ability to manage irregular workloads common in non-graphics applications. ### 2. Focus The primary focus of traditional GPUs is rendering graphics efficiently. They are optimized for displaying images at the highest fidelity and speed possible, essential for video games and multimedia. The architecture is fine-tuned for tasks like shading, texture mapping, and pixel rendering. On the other hand, GPGPU shifts focus from rendering to computation across various domains. It seeks to maximize computational efficiency using the GPU’s cores for parallel processing. The objective is to tackle problems requiring significant data-crunching power, reducing processing times for complex models in scientific research or large-scale data analysis. ### 3. Programming APIs GPUs are programmed using graphics-specific APIs like DirectX and OpenGL, tailored for rendering operations. These APIs handle graphics-centric tasks, providing abstractions for developers to create visually intense applications. In contrast, GPGPU relies on APIs like CUDA and OpenCL that facilitate parallel computing. These APIs provide the tools developers need to harness the immense processing power of GPUs for computing tasks. They unlock the GPU’s potential beyond graphics, allowing for applications in areas like computational physics, finance, and artificial intelligence. ### 4. Key Applications Traditional GPUs are vital in sectors like gaming, animation, and content creation, where rapid image rendering is crucial. They enable high-resolution displays and smooth, interactive environments. Applications in this domain rely on the GPU’s ability to continuously refresh visuals at high frame rates. GPGPU broadens the scope to include data-intensive applications like deep learning, scientific simulations, and cryptocurrency mining. Its ability to quickly process vast amounts of data makes it indispensable for tasks involving large-scale computations. As a result, industries like healthcare and finance are increasingly leveraging GPGPU for data analysis and predictive modeling. ## 5 Best Practices for Implementing GPGPU ### 1. Choose the Right Hardware Selecting suitable hardware is crucial for effective GPGPU implementation. Consider factors like the number of cores, memory bandwidth, and energy efficiency. High-end GPUs may offer more performance but at higher costs and power consumption. Analyzing workload requirements can aid in decision-making, ensuring the chosen GPU aligns with performance and budget constraints. Look for hardware that supports the desired APIs and frameworks. Compatibility with existing systems and future-proofing against technological advances should also factor into the hardware selection, as should support features such as ray tracing or AI accelerators. ### 2. Optimize Memory Usage Memory bandwidth and management are critical in GPGPU applications, requiring optimization for peak performance. Efficient data transfer between host and device memory minimizes latency and maximizes throughput. Structuring data to align with GPU memory architecture is essential to ensure swift access and processing times. Avoiding data transfer bottlenecks by compacting data and using shared memory intelligently can lead to substantial performance gains. Memory usage optimizations, such as overlapping data transfer with computation, help maintain high levels of GPU occupancy. Profiling tools can identify memory constraints, guiding refinement steps for more efficient memory usage. ### 3. Leverage Parallelism Effectively Parallelism is at the heart of GPGPU, exploiting thousands of GPU cores to perform simultaneous operations. Designing algorithms to maximize parallel processing can significantly speed up tasks. Breaking down problems into smaller, independently executable units is fundamental for harnessing the full power of GPUs. Considerations like load balancing and minimizing serialization points are vital. Ensuring each GPU core is optimally utilized without idle time can lead to major efficiency improvements. Parallel execution must account for dependencies and potential bottlenecks. Efficient task distribution techniques, such as thread adaptation strategies, can enhance overall performance. ### 4. Profile and Debug Performance Profiling and debugging are ongoing tasks in GPGPU development, crucial for identifying performance bottlenecks. Use profiling tools to analyze code execution, understand kernel behavior, and optimize code paths. These tools help in monitoring resource utilization and identifying areas where improvements can increase efficiency. Debugging parallel applications poses unique challenges, but modern tools offer insights into GPU execution patterns and potential errors. Regular testing and code verification help detect issues early. By iteratively profiling and debugging, developers can hone their applications, achieving optimal performance and reliability in GPU-based computing setups. ### 5. Stay Updated with Latest SDKs Staying current with the latest software development kits (SDKs) and updates is essential for taking advantage of new features and performance improvements. Manufacturers frequently release SDK updates to support new hardware capabilities and optimize existing functionalities. Leveraging these updates can lead to substantial performance enhancements and new capabilities. Keeping track of SDK and driver updates ensures compatibility and harnesses the latest advancements in GPU technology. It also provides access to improved libraries and debugging tools. Regularly revisiting and updating code in line with new SDK features can optimize application performance and align with cutting-edge developments in the field. ## Next-Gen Dedicated GPU Servers from Atlantic.Net, Accelerated by NVIDIA Experience unparalleled performance with dedicated cloud servers equipped with the revolutionary NVIDIA accelerated computing platform. Choose from the NVIDIA L40S GPU and NVIDIA H100 NVL to unleash the full potential of your generative artificial intelligence (AI) workloads, train large language models (LLMs), and harness natural language processing (NLP) in real time. High-performance GPUs are superb at scientific research, 3D graphics and rendering, medical imaging, climate modeling, fraud detection, financial modeling, and advanced video processing. [Learn more about Atlantic.net GPU server hosting](https://www.atlantic.net/gpu-server-hosting/) --- # Popular Intel GPUs for Consumer and Enterprise Use > URL: https://www.atlantic.net/gpu-server-hosting/popular-intel-gpus-for-consumer-and-enterprise-use/ | Published: 2025-01-09 | Updated: 2025-01-26 | Author: Robert Agar Intel has long been an industry leader in manufacturing central processing units (CPUs) for laptops, desktop computers, and servers. Intel manufactured its first graphics card in the 1980’s. The company’s goal has been to improve its GPU technology and produce cutting-edge microprocessors. While Intel’s share of the GPU market does not match that of NVIDIA or AMD, they offer some interesting products designed for consumer and enterprise data center use. Intel GPUs offer good performance for a wide and diversified user base and sometimes provide solutions at a better price point than the competition. Read on to learn more about the variety of Intel GPUs available for personal and business use. ## **Intel’s Proprietary XE HPG Microarchitecture** Intel GPUs are built on the advanced technology of the company’s proprietary[XE HPG microarchitecture](https://www.intel.com/content/www/us/en/developer/articles/technical/introduction-to-the-xe-hpg-architecture.html). The XE HPG microarchitecture is a high-performance architecture developed for discrete GPUs. It offers a rich feature set and components designed for enhanced performance and efficiency to support state-of-the-art computer graphics. The following highlights illustrate some of the strengths of the XE HPG microarchitecture. ### **Improved performance** The XE HPG microarchitecture supports up to 32 cores and 512 vector engines to provide increased compute capability. The XE-HPG builds on previous Intel GPU LE-XP technology to improve latency, increase latency tolerance, and streamline the caching hierarchy. ### **Deep learning inference support** Deep learning applications rely on high-throughput multiply-accumulate operations. The XE HPG microarchitecture enables up to 275 teraOPS (TOPs) of compute performance to support deep learning frameworks and toolkits. ### **Intel XE Super Sampling (XeSS)** XE Super Sampling is a technique to create more compelling content by upscaling images with an increase in resolution while maintaining image quality. XeSS leverages game engines to upscale resolution up to 4x for an enhanced gaming experience. ### **Real-time ray tracing** Ray tracing is essential for creating realistic 3D graphics effects like shadows, reflection, and ambient occlusion. Gaming requires real-time performance and typically utilizes faster and reduced-quality rasterization instead of ray tracing to achieve the desired results. The XE HPG microarchitecture enables ray-tracing effects to be layered with traditional rasterization for enhanced graphics performance and presentation. ### **Mesh and variable rate shading** Mesh shading and variable rate shading (VRS) are crucial techniques for displaying high-quality graphics. Mesh shading enhances the generation of 3D primitives, while VRS provides developers with better pixel control to support high-density displays. XE HPG microarchitecture supports VRS Tier 2 to enable fine-grained shading control. ### **Unified lossless compression** Unified lossless compression reduces the read/write memory bandwidth and power consumption. The technique can be applied to all GPU resources and can dramatically increase performance for memory-constrained workloads. ### **High-bandwidth device memory** Artificial intelligence and deep learning applications require high bandwidths for optimized performance. The architecture supports from 4GB to 16GB of local memory. A maximum of eight channels delivers up to 560 GB/s of low-latency bandwidth for the most demanding high-performance computing requirements. ### **Supports current leading media formats** Intel’s focus on the consumer laptop and desktop market for GPUs makes it essential that their processors support the current leading media formats. The company’s audience includes users interested in smooth graphics processing for streaming videos and game playing. Intel Arc GPUs address customer expectations by supporting all media formats they may encounter. ## **The Intel Arc GPU Family** The [Intel Arc line of GPUs](https://www.intel.com/content/www/us/en/products/details/discrete-gpus/arc.html) delivers good performance for diverse usage scenarios. Intel GPUs support processor-intensive activities such as high-performance gaming, professional graphics creation, and generative artificial intelligence applications. Intel Arc GPUs offer advanced features and superior performance that address the needs of gamers, creators, and businesses. The following are some of the highlights and advantages users can expect with Intel Arc GPUs. - **Improved gaming experience:** Intel Arc GPU’s features and capabilities enhance users’ experience and support industry gaming benchmarks. Smoother gameplay is provided with Intel XeSS upscaling technology and frame generation. Intel Xe Low Latency reduces lag and input delays. The Endurance Gaming feature enables power savings for longer gameplay sessions. - **Enhanced graphics capabilities:** Gamers and creators benefit from the enhanced graphics capabilities of Arc GPUs. Powerful AI engines support upscaled gaming and creative activities. AI algorithms provide higher image quality and faster gaming performance. - **Compelling content creation:** Intel Arc GPUs augment content creation and improve productivity. Users can access the power of 3D models with these powerful and affordable graphics cards. Cross-codec support streamlines the creative process. Dual encode and decode capabilities provide faster and more efficient video exporting. ### **A versatile graphics card series** Multiple models of Intel Arc GPUs are available to address various usage scenarios. In some cases, a model is designed with specific hardware constraints, such as a laptop, in mind. Others are built to handle the requirements of distinct usage scenarios like edge computing or business workloads. #### [**Desktop GPUs**](https://www.intel.com/content/www/us/en/products/docs/discrete-gpus/arc/desktop/b-series/overview.html) Modern desktop computer users generally require enhanced computing power to support a wide range of processor-intensive software applications. Desktop machines are typically used for high-performance gaming and other activities that demand exceptional graphics capabilities. The addition of a graphics card to a desktop computer’s motherboard gives the machine enhanced capabilities for playing games and other creative endeavors. Intel Arc GPUs utilize technology like ray-tracing and upscaling to address the visual requirements of modern immersive gaming. They support fast and smooth responsiveness with speeds of up to 60+ FPS in 1440p resolution. Advanced AI algorithms help deliver faster gameplay and high image quality. Parallel cores speed up content creation and video editing. Intel Arc GPUs designed for use in desktops include the following models. **Intel Arc B570:** The model B570 meets the demands of high-performance gaming and offers a flexible platform for creating and editing graphics. GPU specifications include: - 10 GB memory; - 18 cores and ray tracing units; - 144 Vector Engines; - 380 GB/s memory bandwidth - 203 peak TOPS. **Intel Arc B580:** This model enhances the capabilities of the B570 to provide gamers with superior performance. Specifications include: - 12 GB memory; - 20 cores and ray tracing units; - 160 Vector Engines; - 456 GB/s memory bandwidth - 233 peak TOPS. [Intel Arc A-Series](https://www.intel.com/content/www/us/en/products/docs/discrete-gpus/arc/desktop/a-series/overview.html): This series of Intel GPUs for desktops offers a range of graphics cards designed to enhance gaming and content creation and support processor-intensive AI applications. Models are equipped with 4 to 16 GB of memory and 6 to 32 cores. We will discuss these GPUs further in the professional workstation section. #### [**Laptop GPUs**](https://www.intel.com/content/www/us/en/products/docs/discrete-gpus/arc/mobile/overview.html) Laptop computers offer users flexibility and mobility not available with desktop machines. The mobile workforce and student and professionals’ adoption of laptop computers have spurred their popularity. Unfortunately, a laptop’s hardware limitations can make achieving acceptable graphics processing or gaming performance challenging. Traditional GPUs are not suitable for the power and size constraints necessary for use in a laptop. Intel’s line of Arc-based laptops efficiently addresses this problem and offers users a powerful gaming, business, and content creation platform. Intel Arc-based laptops feature Intel Core Ultra Processors with built-in Intel Arc GPUs for faster and superior performance across all computing activities. Laptops are built with both the Arc B-Series and A-Series GPUs. The machines leverage optimized architecture to provide exceptional capacities in a slim design. They deliver power and portability while operating quietly and cooly. #### [**Professional workstation GPUs**](https://www.intel.com/content/www/us/en/products/docs/discrete-gpus/arc/workstations/a-series/overview.html) Intel Arc Pro A-Series GPUs are designed to handle the needs of professional workstations. They offer users built-in ray-tracing hardware, graphics acceleration, and machine learning capabilities. The result is a versatile GPU available in multiple form factors that leverages cutting-edge visual technologies and enhanced content creation. The Intel Arc Pro A-Series GPUs share the following features. - Intel ensures compatibility between specialized software and the company’s high-performance GPUs through a rigorous certification process. Working closely with Independent Software Vendors (ISVs) to provide superior reliability and stability. - Built-in ray-tracing hardware accelerates image creation and supports pro workflows with a cost-efficient GPU. Small Form Factor cards enable the support of up to four ultra-large displays for multi-display home or office use. - Discrete and laptop Arc GPUs support Ultra-High Definition (UHD) and ultrawide UHD display resolutions. The cards are optimized to work with modern viewport technology for maximum performance and stability. Dolby Vision support optimizes image quality to deliver consistently exceptional visuals. - High bandwidth speeds enhance graphics memory and performance. AV1 hardware acceleration provides faster encoding than software alternatives. Dedicated acceleration is available when needed for advanced AI applications. - The Series-A Hyper Compute feature integrates the power of Intel CPUs and GPUs for greater performance. All available compute engines and AI accelerators are employed for tasks like image processing or machine learning. - Dynamic power share capabilities intelligently route power between a laptop CPU and GPU to boost performance for a given task. A smart algorithm allocates power where it is needed most. The following models are representative of the Intel Arc A-Series of GPUs. **Intel Arc Pro A40 GPUs** offer superior graphics acceleration and machine learning capabilities in a small, single-slot form factor. Specifications include: - 6 GB memory; - 8 cores and ray tracing units; - 128 Vector Engines; - 192 GB/s memory bandwidth - 69 peak TOPS. **Intel Arc Pro A50 GPUs** are larger dual-slot units offering a step up from the A40. Its specifications are similar to the A40. **Intel Arc Pro A60 GPUs** are a significant improvement from the A40 and A50, offering more performance in a single-slot form. Specifications include: - 12 GB memory; - 16 cores and ray tracing units; - 256 Vector Engines; - 384 GB/s memory bandwidth - 151 peak TOPS. #### [**Intel Arc GPUs for Edge Computing**](https://www.intel.com/content/www/us/en/products/details/discrete-gpus/arc/edge.html) Intel Arc Graphics discrete GPUs are designed to boost the performance of edge workloads. The graphics cards help create immersive visual experiences. They also enhance video production, media transcoding, and streaming. Specialized AI engines support the deployment of advanced AI workloads at the edge. Multiple Intel Arc A-Series GPUs are suitable for edge workloads. The memory capacity of these GPUs ranges from 4 GB to 16 GB, with bandwidths from 124 GB/s to 512 GB/s. GPUs are equipped with 6 to 28 cores and produce speeds between 49 TOPS and 229 TOPS. Systems equipped with Intel Arc GPUs are being used to innovate in diverse market sectors, such as retail and self-service electric vehicle charging. The [ADLINK](https://www.intel.com/content/www/us/en/products/docs/discrete-gpus/arc/edge/adlink-aoi-solution-brief.html) automated optical inspection solution is built with Intel GPUs and reduces the costs of quality assurance in the manufacturing industry. ## [**Intel Data Center GPUs**](https://www.intel.com/content/www/us/en/products/details/discrete-gpus/data-center-gpu.html) Intel’s line of data center GPUs is designed to provide businesses with the power they need for mathematically complex and graphics-intensive processing. These GPUs boost CPU performance and provide parallel processing capabilities to speed outcomes and accelerate innovation. ### [**Intel Data Center GPU Flex Series**](https://www.intel.com/content/www/us/en/products/details/discrete-gpus/data-center-gpu/flex-series.html) The Flex Series of data center GPUs is designed to support AI inference solutions, virtual desktop infrastructure, and media processing. The GPUs feature up to four Xe media engines to reach speeds of up to 256 TOPS for AI inferencing. No license or royalty fees make the Flex Series a cost-effective GPU solution. Built-in AV1 encoding reduces bandwidth requirements and enables high stream density for more media streams. Low power consumption via open source optimizations delivers higher throughput while conserving energy. The Flex Series supports scalable and flexible advanced workloads. ### [**Intel Data Center GPU Max Series**](https://www.intel.com/content/www/us/en/products/details/discrete-gpus/data-center-gpu/max-series.html) The GPU Max Series is built utilizing the Intel Xe Link high-speed, coherent, unified fabric for extensive flexibility and scalability. The processors support high capacity workloads with up to 128 GB of high bandwidth memory, 64 MB of L1 cache, and 408 MB of L2 cache. Animation and visualization are accelerated by up to 128 ray tracing units on each GPU. The Max Series accelerates AI workloads and matrix operations via the Intel Xe Matrix Extensions (XMX) built with deep systolic arrays. The Aurora supercomputer at the Argonne National Laboratory is powered by 10,000 server blades equipped with Intel Max Series processors. The blades support a machine learning process that trains AI models to identify structures and create 3D visualizations. ## **Atlantic Net’s Data Center GPU Solutions** Atlantic Net’s data center GPU solutions are built on a foundation of NVIDIA GPUs. We offer [high-performance systems](https://www.atlantic.net/gpu-server-hosting/) designed to power next-generation AI models, complex mathematical applications, and parallel computing algorithms. [Contact us today](https://www.atlantic.net/about-us/corporate-contact/) and learn how our GPU solutions can help your business thrive. --- # An Overview of Popular NVIDIA GPUs > URL: https://www.atlantic.net/gpu-server-hosting/an-overview-of-popular-nvidia-gpus/ | Published: 2025-01-10 | Author: Robert Agar Graphics processing units (GPUs) are important components of high-performance computers used in many advanced applications. Graphics cards’ parallel processing capabilities make them suitable for many advanced computing uses, including video rendering, supporting deep learning systems, and training machine learning algorithms. The ability to process multiple commands simultaneously supports accelerated computing in diverse applications like artificial intelligence, gaming, and robotics. NVIDIA is the industry leader in GPU production, commanding over 80% of the graphics card market. Their processors regularly get high marks in reviews from reliable industry sources such as Tom’s Hardware. We are going to look at the technology that distinguishes NVIDIA GPUs and the architectures utilized in GPU production. We’ll also identify some of the company’s most popular GPU models for gaming, video processing, and business uses, such as training machine learning models. ## **Advantages of NVIDIA Graphics Processor Technology** The technology employed in manufacturing NVIDIA GPUs provides some advantages over the products of other GPU suppliers like AMD and Intel. These benefits may be important when selecting a GPU to address specific business, manufacturing, or data science usage scenarios. ### **CUDA Cores** Compute Unified Device Architecture (CUDA) is a proprietary parallel computing platform and application programming interface (API) model created by NVIDIA. CUDA cores are smaller and more efficient than CPU cores. They are designed to process multiple tasks simultaneously, providing support for applications leveraging parallel processing. The cores are integral components of NVIDIA graphics cards that increase the speed of applications by exploiting the capabilities of the GPU. NVIDIA GPUs utilize thousands of CUDA cores to construct a massively parallel architecture capable of efficiently handling multiple tasks simultaneously. These specialized cores offer enhanced speed when processing large datasets and performing complex mathematical calculations. CUDA cores are instrumental in accelerating application performance in fields like big data analytics, machine learning, and other areas of artificial intelligence. ### **Tensor Cores** [Tensor Cores](https://www.nvidia.com/en-us/data-center/tensor-cores/) are specialized processing units introduced by NVIDIA in 2017. The cores are designed to accelerate AI workloads by improving matrix math performance. Tensor cores can significantly enhance the parallel processing required by deep learning tasks. NVIDIA has advanced its Tensor Core technology with each generation of its GPUs. The advantages of a GPU equipped with Tensor Cores include: - Exceptional performance that maintains accuracy while reducing AI training time; - Breakthrough inference performance with low latency, high throughput, and maximum GPU utilization; - High-performance computing (HPC) support for superior accuracy and speed to accelerate next-generation scientific research. ### **Real-Time Ray Tracing** NVIDIA’s GPUs provide real-time ray tracing that simulates light’s physical behavior. Ray tracing enables the creation of exceptionally realistic visuals for use in gaming, business, and scientific applications. This technology allows a developer to produce a more lifelike visualization than alternate video rendering solutions. NVIDIA developers utilize deep learning supersampling (DLSS) to leverage the power of AI, providing improved image quality for better gaming performance. DLSS upscales lower-resolution images to higher resolutions for enhanced performance with no loss of visual quality. NVIDIA ray tracing provides enhanced rasterization performance for the 3D and 2D modeling critical to the entertainment and scientific communities. ### **Accelerated Computing** NVIDIA GPUs support accelerated computing with their massively parallel architecture. Multiple features of the GPUs support the demands of high-performance computing. - Energy efficiency is prioritized in GPU design to control energy costs in large data centers and HPC environments. - NVIDIA’s NVLink and Scalable Link Interface support scalability by enabling multiple GPUs to work together for enhanced computational power to support tasks like machine learning training and scientific simulations. ## **NVIDIA GPU Architectures** NVIDIA GPUs are manufactured utilizing several different architectures. An overview of these architectures illustrates their differences and the applications they are designed to address. New NVIDIA GPUS are constructed using the following architectures. Some NVIDIA GPUs using older architectures are still being sold and offer excellent performance. ### [**Hopper Architecture**](https://www.nvidia.com/en-us/data-center/technologies/hopper-architecture/)**(March 2022)** The Hopper architecture provides an accelerated computing platform to support demanding, next-generation workloads. The architecture securely scales diverse workloads in any size data center utilizing the following technological innovations. - The transformer engine optimizes floating-point operations to accelerate AI calculations for transformers and training models. - The NVLink, NVSwitch, and NVLink Switch System support GPU clusters and scalability to meet the requirements of HPC tasks and trillion-parameter AI models - NVIDIA Confidential Computing protects data and applications while in use to close gaps in traditional encryption methods. - The second-generation Multi-Instance GPU (MIG) feature enables a GPU to be partitioned into multiple smaller, fully isolated instances with dedicated memory, cache, and compute cores. - DPX instructions accelerate dynamic programming, an algorithmic technique for solving complex recursive problems by breaking them down into simpler subproblems. ### [**Ada Lovelace Architecture**](https://www.nvidia.com/en-us/technologies/ada-architecture/)**(September 2022)** The Ada Lovelace architecture focuses on providing energy-efficient and enhanced GPU performance to power AI, graphics, video, and other demanding computing tasks. Following are some of the features powering this GPU architecture. - Third-generation RT Cores double ray tracing performance for photorealistic graphic rendering. - Fourth-generation Tensor Cores accelerate throughput to support transformative AI technologies like natural language processing (NLP), generative AI, and computer vision. - CUDA Cores double the processing speed of single-precision floating point (FP32) operations over previous GPU versions. - Advanced video and AI vision acceleration are supported by NVIDIA’s optimized AV1 stack to enhance performance in areas like video conferencing, augmented reality (AR), and virtual reality (VR). - Ada Lovelace GPUs are optimized for enterprise data center operations. They are tested and supported for maximum performance, durability, and security. ### [**Blackwell Architecture**](https://www.nvidia.com/en-us/data-center/technologies/blackwell-architecture/)**(March 2024)** Blackwell is NVIDIA’s newest architecture and introduces groundbreaking advancements to support generative AI and accelerated computing. The following are some of the distinctive features of this advanced GPU architecture. - Blackwell-architecture GPUs are manufactured with 208 billion transistors utilizing a custom-built TSMC 4NP process. They offer exceptional speed for the most demanding AI applications. - The second-generation Transformer Engine accelerates large language model (LLM) and mixture-of-experts (MoE) model inference and training. - Secure AI is provided with NVIDIA Confidential Computing to protect sensitive and valuable data with strong hardware-based security. - NVLink and NVLink Switch support seamless communication between all GPUs in a server cluster. - The Decompression Engine provides a high-speed link to accelerate database queries for superior performance in data analytics and data science applications. - A dedicated Reliability, Availability, and Serviceability (RAS) Engine proactively identifies potential faults to minimize downtime and enhance resiliency. ## **Popular NVIDIA GPU Reviews** While not all-inclusive, the following list identifies some of the popular NVIDIA GPUs on the market. We’ll look at the chips’ features and settings where they are typically deployed. ### [**NVIDIA GeForce GTX 16 Series**](https://www.nvidia.com/en-us/geforce/graphics-cards/16-series/) The GeForce GTX 16 series is designed to supercharge the gaming experience with powerful graphics performance. GeForce GTX 16 series GPUs are available as graphics cards for a PC or integrated into powerful laptops. The GPUs are an excellent choice for gamers. - Turing shaders provide improved performance and power efficiency for a faster, cooler, and quiet gaming experience. - Faster graphics deliver higher frame rates for smoother gameplay. - The inclusion of game-ready drivers ensures excellent speed and smooth performance with graphics-intensive games. - Advanced graphics and video rendering bring new levels of realism to virtual reality (VR) projects. GeForce GTX 16 series GPUs are equipped with 512 to 1536 CUDA cores and either 4GB or 6GB of memory. They are built with NVIDIA’s legacy Turing architecture. ### [**NVIDIA GeForce RTX 20 Series**](https://www.nvidia.com/en-us/geforce/20-series/) GeForce RTX 20 series graphics cards and laptops provide powerful performance and cutting-edge features with dedicated ray tracing and AI cores. Gamers can maximize settings and video resolution for an enhanced visual experience. The GeForce RTX 20 offers users low latency and excellent responsiveness for a competitive edge when playing their favorite games. The GPU delivers advanced streaming capabilities with the NVIDIA Encoder. Creative endeavors are supported by the NVIDIA Studio platform, which features dedicated drivers and tools meant to unlock a user’s imagination. The NVIDIA Broadcast app lets you use an RTX 20 to transform any room into a home studio with powerful AI features like noise removal and virtual backgrounds. GeForce RTX 20 series GPUs feature from 1920 to 4352 CUDA cores for superior parallel processing. Graphics cards have between 6GB and 12GB of memory. The chips are built utilizing the Turing architecture and come equipped with 1st generation ray tracing cores and 2nd generation Tensor cores for enhanced performance. ### [**NVIDIA GeForce RTX 30 Series**](https://www.nvidia.com/en-us/geforce/graphics-cards/30-series/) The GPUs utilized in the GeForce RTX 30 series are designed to provide high performance to creators and gamers. The GPUs feature 2nd generation ray tracing cores and 3rd generation Tensor Cores for enhanced graphics performance and support for AI technologies. The processors employ deep learning supersampling (DLSS) to boost speeds for a more immersive gaming experience. NVIDIA Reflex technology provides unparalleled responsiveness and exceptionally low latency. Competitive gamers can get an advantage from the technology built into the RTX series. GeForce game-ready drivers have been finely tuned in collaboration with developers and tested extensively to provide users with maximum performance and reliability. Game settings can be optimized with a single click for a more enjoyable gaming session. RTX 30 series GPUs are available with 2304 to 10752 CUDA cores. The processors are built with the Ampere architecture and offer memory from 6GB to 24GB to ensure fast performance for the most demanding graphics applications. ### [**NVIDIA GeForce RTX 40 Series**](https://www.nvidia.com/en-us/geforce/graphics-cards/40-series/) The GeForce RTX 40 series are the most powerful NVIDIA GPUs designed for consumer use. They are manufactured utilizing the advanced Ada Lovelace architecture for supercharged performance. New streaming multiprocessors deliver up to double the performance of the RTX 30 series and offer improved power efficiency. Revolutionary AI graphics are delivered with a combination of DLSS, third-gen ray tracing cores, and fourth-gen Tensor Cores. NVIDIA Reflex technology minimizes latency and provides higher frame rates. The RTX 40 series supports creativity with a suite of exclusive tools for video editing and graphic design. Additional features of the GPU series include RTX Video Super Resolution which automatically enhances video played in your web browser. NVIDIA G-Sync offers high refresh rates for smooth gameplay. The graphics capabilities of the RTX provide the high performance required by virtual reality applications. RTX 40 series GPUs are available with from 3072 to 18394 CUDA cores. Dedicated Shader Cores enhance graphics performance to deliver photorealistic presentation. On-board memory ranges from 8GB to 24GB to address the needs of complex calculations and applications. ### [**NVIDIA L40S**](https://www.nvidia.com/en-us/data-center/l40s/) The NVIDIA L40S offers unparalleled AI and graphics performance for enterprise data centers. The processor is designed to power next-generation data center workloads, including graphics rendering, LLM training and inference, and generative AI applications. The L40S supports the most demanding data center workloads by utilizing the Ada Lovelace architecture, fourth-gen Tensor Cores, and third-gen ray tracing cores. The L40S is designed for efficiency and security. It is optimized for data center operations and extensively tested to ensure maximum performance, durability, and uptime. The GPU delivers breakthrough performance for generative AI and LLM inference applications. NVIDIA Confidential Computing ensures data security. The L40S provides 48GB of GPU memory with a bandwidth of 864GB/s. It features 18,176 CUDA cores, 142 third-generation ray tracing cores, and 568 fourth-generation Tensor Cores. Its maximum power consumption is 350W, offering the performance and energy efficiency required for enterprise data center use. ### [**NVIDIA H100 NVL**](https://www.nvidia.com/en-us/data-center/h100/) NVIDIA’s H100 Tensor Core GPU delivers exceptional performance, scalability, and security for every workload. The GPU leverages the technology of NVIDIA’s Hopper architecture to speed up the performance of LLMs by 30X. A dedicated Transformer Engine allows the GPU to solve trillion-parameter language models The power available in the H100 increases performance while maintaining accuracy when working with LLMs. Utilizing NVLink and NVSwitch enables large GPU clusters to be deployed for accelerated data analytics and exascale high-performance computing. NVIDIA Confidential Computing ensures the security of data processed by the H100. ## **Atlantic Net’s NVIDIA GPU Solutions** Atlantic Net offers customers dedicated high-performance servers in[two powerful configurations](https://www.atlantic.net/gpu-server-hosting/) designed to meet your advanced computing needs. - Our NVIDIA L40S GPU server option is an excellent solution for general AI tasks, machine learning, and deep learning applications. - Our NVIDIA H100 NVL server is more powerful than the L40S, offering higher memory bandwidth for enhanced AI and deep learning requirements. [Contact us](https://www.atlantic.net/gpu-server-hosting/#GetStarted) to learn more about how our hosted NVIDIA GPU server solutions can help your business thrive. --- # How to Analyze and Visualize Data Using Pandas and Matplotlib on Atlantic.Net Cloud GPU > URL: https://www.atlantic.net/gpu-server-hosting/how-to-analyze-and-visualize-data-using-pandas-and-matplotlib-on-atlantic-net-cloud-gpu/ | Published: 2025-01-13 | Updated: 2026-05-04 | Author: Hitesh Jethva Data analysis and visualization are at the core of data-driven decision-making. As data gets increasingly complex, having a powerful machine can speed up these processes, especially when you have machine learning or deep learning tasks that rely heavily on GPU. An Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/) is a great balance of performance, flexibility, and open-source tooling—perfect for data analysts, data scientists, and anyone who wants to experiment with large datasets quickly. Pandas provide powerful data structures (DataFrames) and data manipulation and analysis tools. Matplotlib is a popular plotting library for creating static, animated, and interactive visualizations. In this article, we will discuss setting up an environment for data analysis using Pandas and Matplotlib, inspecting and manipulating data, and visualizing the results. ## Prerequisites - An Ubuntu 22.04 Cloud GPU Server. - CUDA Toolkit, cuDNN Installed. - Jupyter Notebook is installed and running. - A root or sudo privileges. ## Setting Up the Environment First, install the required Python packages and other libraries. Run the following command: ```bash pip install pandas matplotlib jupyter numpy scipy seaborn scikit-learn ``` ## Using IPython’s display() Function for DataFrames In a Jupyter Notebook, you can display Pandas DataFrames neatly by using the display() function from IPython instead of the standard print() function. ```bash from IPython.display import display import pandas as pd df_sample = pd.DataFrame({ 'X': [10, 20, 30], 'Y': [100, 200, 300] }) # Show first rows display(df_sample.head()) # Show summary stats display(df_sample.describe()) ``` In this code: - **display()** renders the output in a more readable, table-like format inside Jupyter notebooks. - **df_sample.head()** shows the first five rows of the DataFrame. - **df_sample.describe()** provides summary statistics such as mean, standard deviation, etc. ![](https://www.atlantic.net/wp-content/uploads/2025/01/p1-4.png) ## Mixing print() and display() Sometimes, you may want to include text messages before displaying DataFrames: ```bash print("This is the head of the DataFrame:") display(df_sample.head(2)) print("Descriptive statistics:") display(df_sample.describe()) ``` **Explanation:** - **print()** is good for showing plain text or messages. - **display()** handles DataFrames gracefully, giving a well-formatted table output. ![](https://www.atlantic.net/wp-content/uploads/2025/01/p2-2.png) ## Multiple Plots in One Jupyter Cell While analyzing data, you might need multiple charts to compare different aspects of your dataset. With Jupyter, you can display multiple plots one after another in the same cell: ```bash import matplotlib.pyplot as plt %matplotlib inline # Plot 1 plt.figure(figsize=(5, 3)) plt.plot(df_sample['X'], label='Column X') plt.legend() plt.title("Plot for X") plt.show() # Plot 2 plt.figure(figsize=(5, 3)) plt.plot(df_sample['Y'], color='red', label='Column Y') plt.legend() plt.title("Plot for Y") plt.show() ``` Here: - **%matplotlib** inline tells Jupyter to display the plots inline within the notebook. - **plt.figure(figsize=(5, 3))** defines the size of each figure. - **plt.show()** is used to display the figure. ![](https://www.atlantic.net/wp-content/uploads/2025/01/p3-1.png) ## Creating and Exploring a Custom Dataset with Pandas Here’s an example of creating a small dataset demonstrating basic Pandas functionality. ```bash import pandas as pd import matplotlib.pyplot as plt %matplotlib inline # Create a small dataset df = pd.DataFrame({ 'Country': ['USA', 'Canada', 'UK', 'Germany', 'France'], 'Population':[331, 38, 67, 83, 65 ], 'GDP': [21.43, 1.64, 2.83, 3.86, 2.71 ] # In trillions USD }) df ``` In this code: - We are creating a DataFrame with columns Country, Population, and GDP. - Population is in millions, while GDP is in trillions (USD). ![](https://www.atlantic.net/wp-content/uploads/2025/01/p4.png) ## Quick Data Inspection After creating your DataFrame, you can inspect it using some useful Pandas methods: ```bash df.head() df.info() df.describe() df.columns df.shape ``` **Explanation:** - **df.head()** and **df.info()** give you a quick overview of the data structure. - **df.describe()** helps you identify the central tendency and dispersion of numeric columns. ![](https://www.atlantic.net/wp-content/uploads/2025/01/p5.png) ## Data Manipulation Adding new columns or transforming existing ones is straightforward in Pandas. For example, calculating GDP per capita: ```bash df['GDP_Per_Capita'] = (df['GDP'] * 1000) / df['Population'] df ``` This formula multiplies GDP by **1000** (to convert from trillions to billions), then divides by the population in millions to get GDP per capita in thousands of **USD.** ![](https://www.atlantic.net/wp-content/uploads/2025/01/p6.png) ## Filtering and Selecting Data If you want to filter countries based on specific criteria (e.g., large population), you can do: ```bash large_countries = df[df['Population'] > 60] large_countries ``` In this code, **df[‘Population’]** **>** **60** produces a boolean mask for rows with a population greater than 60 million, and slicing the DataFrame with this mask returns only those rows. ![](https://www.atlantic.net/wp-content/uploads/2025/01/p7.png) ## Data Visualization with Matplotlib Visualizing your data can reveal patterns, trends, and insights not immediately apparent from raw data. ### Bar Chart (Vertical) ```bash plt.figure(figsize=(8, 5)) plt.bar(df['Country'], df['Population'], color='skyblue') plt.title('Population by Country (Millions)') plt.xlabel('Country') plt.ylabel('Population (in Millions)') plt.show() ``` **Explanation:** - **plt.bar(x, height, …)** creates a bar plot where each country is on the x-axis and the height is its population. - **plt.title()** adds a title to your chart, while plt.xlabel() and plt.ylabel() define axis labels. ![](https://www.atlantic.net/wp-content/uploads/2025/01/p8.png) ### Bar Chart (Horizontal) ```bash plt.figure(figsize=(8, 4)) plt.barh(df['Country'], df['GDP'], color='green') plt.title('GDP by Country (Trillions of USD)') plt.xlabel('GDP (in Trillions USD)') plt.ylabel('Country') plt.show() ``` **Explanation:** - **plt.barh()** is the horizontal variant of the bar plot. - We set **color=’green’** for a different aesthetic. ![](https://www.atlantic.net/wp-content/uploads/2025/01/p9.png) ### Scatter Plot ```bash plt.figure(figsize=(6, 4)) plt.scatter(df['Population'], df['GDP'], color='purple') plt.title('GDP vs. Population') plt.xlabel('Population (Millions)') plt.ylabel('GDP (Trillions USD)') plt.show() ``` A scatter plot is perfect for showing the relationship between two continuous variables—here, Population and GDP. ![](https://www.atlantic.net/wp-content/uploads/2025/01/p10.png) ### Plotting a Computed Column Finally, you may want to plot the computed GDP_Per_Capita column: ```bash plt.figure(figsize=(8, 4)) plt.plot(df['Country'], df['GDP_Per_Capita'], marker='o', linestyle='--', color='r') plt.title('GDP Per Capita (Thousands of USD)') plt.xlabel('Country') plt.ylabel('GDP Per Capita (in Thousands USD)') plt.show() ``` In this code, we use plt.plot() with markers and a dashed line to create a simple line plot. ![](https://www.atlantic.net/wp-content/uploads/2025/01/p11.png) ## Conclusion In this tutorial, we went through the steps to analyze and visualize data using Pandas and Matplotlib on an Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/). We set up the environment and installed the required libraries, used Jupyter Notebook’s display() function to show DataFrames nicely, inspected data, manipulated data,a and finally visualized the results. --- # How to Use Pretrained Models for Transfer Learning in PyTorch on Atlantic.Net Cloud GPU > URL: https://www.atlantic.net/gpu-server-hosting/how-to-use-pretrained-models-for-transfer-learning-in-pytorch-on-atlantic-net-cloud-gpu/ | Published: 2025-01-14 | Updated: 2026-05-04 | Author: Hitesh Jethva Deep learning has changed how we approach image classification tasks, but training a deep neural network from scratch requires a huge amount of labeled data and computational resources. This is where transfer learning comes in. Transfer learning uses pre-trained models such as ResNet-5,0, which have already learned general features from large datasets like ImageNet. These models can be fine-tuned for a specific task, reducing training time and the need for large datasets. In this tutorial, we will show you how to implement transfer learning using PyTorch to classify flowers from the Flowers Dataset. ## Prerequisites - An Ubuntu 22.04 Cloud GPU Server. - CUDA Toolkit, cuDNN Installed. - Jupyter Notebook is installed and running. - A root or sudo privileges. ## Step 1: Install Required Libraries Before starting, you will need to install PyTorch with GPU support on your server. You can install them with the following command. ```bash pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu124 ``` ## Step 2: Download and Extract the Dataset To begin, we’ll use the Flowers dataset provided by TensorFlow. It contains labeled images of five flower classes: daisy, dandelion, roses, sunflowers, and tulips. ```bash # Import necessary libraries import os import random import torch import torch.nn as nn import torch.optim as optim import matplotlib.pyplot as plt from torchvision import datasets, transforms, models from PIL import Image # Check for GPU availability device = torch.device('cuda' if torch.cuda.is_available() else 'cpu') #Download and Extract Dataset # Download and extract the dataset if not os.path.exists('dataset/flower_photos'): os.system('wget http://download.tensorflow.org/example_images/flower_photos.tgz') os.system('mkdir -p dataset') os.system('tar -xzf flower_photos.tgz -C dataset') ``` **Explanation:** - The code checks if the dataset exists locally. - If not, it downloads the dataset **(flower_photos.tgz)** and extracts it into the **dataset/flower_photos** directory. ## Step 3: Dataset Preparation We prepare the dataset for training and validation. Images are resized to **224×224** pixels and converted to PyTorch tensors. The dataset is split into 80% training and 20% validation. ```bash # Define transformations for preprocessing transform = transforms.Compose([ transforms.Resize((224, 224)), # Resize images to 224x224 pixels transforms.ToTensor(), # Convert images to PyTorch tensors ]) # Load the dataset and split into training and validation sets dataset_path = 'dataset/flower_photos' train_dataset = datasets.ImageFolder(dataset_path, transform=transform) val_split = int(len(train_dataset) * 0.2) # Use 20% for validation train_split = len(train_dataset) - val_split train_dataset, val_dataset = torch.utils.data.random_split( train_dataset, [train_split, val_split] ) # Create DataLoaders train_loader = torch.utils.data.DataLoader(train_dataset, batch_size=32, shuffle=True) val_loader = torch.utils.data.DataLoader(val_dataset, batch_size=32, shuffle=False) # Print dataset statistics print(f"Classes: {train_dataset.dataset.classes}") # ['daisy', 'dandelion', 'roses', 'sunflowers', 'tulips'] print(f"Number of training samples: {len(train_dataset)}") print(f"Number of validation samples: {len(val_dataset)}") ``` **Explanation:** - **Transformations:** Resize images to **224×224** to match the input size for ResNet and convert them into tensors. - **Data Splitting:** The dataset is split into training **(80%)** and validation **(20%)** subsets for model training and evaluation. - **Data Loaders:** These enable efficient batch processing during training and validation. ## Step 4: Load and Modify the Pretrained Model PyTorch provides a variety of pre-trained models via torch-vision models. Here, we use ResNet-50 and modify its final layer to classify five flower types. ```bash # Load pretrained ResNet-50 model model = models.resnet50(pretrained=True) # Freeze pretrained layers for param in model.parameters(): param.requires_grad = False # Replace the final classification layer to match the number of classes num_classes = len(train_dataset.dataset.classes) model.fc = nn.Linear(model.fc.in_features, num_classes) model = model.to(device) ``` **Explanation:** - **Freezing Layers:** Prevents updates to the pretrained layers, preserving their learned features. - **Final Layer Replacement:** The original 1000-class output layer is replaced with a new layer for five flower classes. ## Step 5: Define Training Setup We define the loss function and optimizer required for training. ```bash # Loss function and optimizer criterion = nn.CrossEntropyLoss() optimizer = optim.Adam(model.fc.parameters(), lr=0.001) ``` **Explanation:** - **Loss Function:** CrossEntropyLoss is suitable for multi-class classification problems. - **Optimizer:** Adam optimizer updates only the parameters of the newly added final layer. ## Step 6: Train the Model Train the model over multiple epochs, calculating the loss for each batch and updating weights accordingly. ```bash epochs = 5 for epoch in range(epochs): model.train() running_loss = 0.0 for inputs, labels in train_loader: inputs, labels = inputs.to(device), labels.to(device) optimizer.zero_grad() outputs = model(inputs) loss = criterion(outputs, labels) loss.backward() optimizer.step() running_loss += loss.item() print(f"Epoch {epoch+1}/{epochs}, Loss: {running_loss/len(train_loader)}") ``` **Explanation:** - **Training Mode:** The model is set to training mode using model.train(). - **Batch Processing:** Each batch of inputs and labels is passed through the model to calculate and backpropagate the loss. - **Loss Monitoring:** Average loss per epoch is printed to track training progress. ## Step 7: Validate the Model Evaluate the model’s accuracy on the validation set. ```bash model.eval() correct = 0 total = 0 with torch.no_grad(): for inputs, labels in val_loader: inputs, labels = inputs.to(device), labels.to(device) outputs = model(inputs) _, predicted = torch.max(outputs, 1) total += labels.size(0) correct += (predicted == labels).sum().item() print(f'Validation Accuracy: {100 * correct / total:.2f}%') ``` **Explanation:** - **Evaluation Mode:** Disables dropout and batch normalization using model.eval(). - **Prediction:** Compares predicted labels with actual labels to calculate accuracy. ## Step 8: Verify the Model with a Sample Image Select a random image from the dataset and visualize the model’s prediction. ```bash # Get a random image path from one of the class directories sample_dir = os.path.join(dataset_path, random.choice(train_dataset.dataset.classes)) sample_image_path = os.path.join(sample_dir, random.choice(os.listdir(sample_dir))) print(f"Using sample image: {sample_image_path}") # Load and preprocess the sample image image = Image.open(sample_image_path) input_tensor = transform(image).unsqueeze(0).to(device) # Get prediction model.eval() with torch.no_grad(): output = model(input_tensor) _, predicted = torch.max(output, 1) # Map prediction to class name predicted_class = train_dataset.dataset.classes[predicted.item()] print(f"Predicted Class: {predicted_class}") # Visualize the image with its predicted label plt.imshow(image) plt.title(f'Predicted: {predicted_class}') plt.axis('off') plt.show() ``` **Explanation:** - **Random Image Selection:** Picks a random image from the dataset for testing. - **Prediction:** Passes the image through the model and retrieves the predicted class. - **Visualization:** Displays the image with the predicted class label. ## Step 9: Run the Code in Jupyter Notebook Create a new notebook from Jupyter Notebook, add all the code to the notebook cell, and then run the notebook. ![](https://www.atlantic.net/wp-content/uploads/2025/01/p1-3.png) The above image demonstrates the notebook’s final output. Here, the model has been trained over five epochs, achieving a validation accuracy of **90.60%.** A sample image of a flower from the validation set was randomly selected, and the model predicted its class as roses. The displayed image visually confirms the prediction, highlighting the model’s accuracy. ## Conclusion In this tutorial, we went through transfer learning with PyTorch to build robust classifiers for image classification tasks. We used the pre-trained ResNet-50 model and avoided training a model from scratch, and got high accuracy on the Flowers dataset. We went through data preparation, model fine-tuning, training, and validation, and finally, we visualized the results. You can use Atlantic.Net [GPU server hosting](https://www.atlantic.net/gpu-server-hosting/) as a platform for AI image classification and other applications! --- # How to Perform Hyperparameter Tuning with GridSearchCV on Atlantic.Net Cloud GPU > URL: https://www.atlantic.net/gpu-server-hosting/how-to-perform-hyperparameter-tuning-with-gridsearchcv-on-atlantic-net-cloud-gpu/ | Published: 2025-01-15 | Updated: 2026-05-04 | Author: Hitesh Jethva Hyperparameter tuning is an important step in improving the performance of machine learning models. By tuning the hyperparameters, we can boost the predictive power of the models. One way of hyperparameter tuning is GridSearchCV, which exhaustively searches through a grid of hyperparameter combinations. Due to computational constraints, running GridSearchCV on a local machine is impractical when working with large datasets or complex models. Using a [cloud GPU](https://www.atlantic.net/gpu-server-hosting/) can speed up this process. In this tutorial, we will go through the steps to perform hyperparameter tuning with GridSearchCV on a cloud GPU. ## Prerequisites - An Ubuntu 22.04 Cloud GPU Server. - CUDA Toolkit, cuDNN Installed. - Jupyter Notebook is installed and running. - A root or sudo privileges. ## Step 1: Install Required Software Before starting, you will need to install the necessary dependencies, including drivers for GPU acceleration and libraries for machine learning tasks. ```bash pip install numpy pandas scikit-learn matplotlib ``` ## Step 2: Create an In-Memory Dataset We will first create a small in-memory dataset using Python’s pandas library. This dataset will serve as input for the model. ```bash import pandas as pd from sklearn.pipeline import Pipeline from sklearn.preprocessing import StandardScaler from sklearn.ensemble import RandomForestClassifier from sklearn.model_selection import GridSearchCV # Create an in-memory dataset data_dict = { 'feature1': [1, 4, 7, 2, 9], 'feature2': [2, 5, 8, 5, 3], 'feature3': [3, 6, 9, 3, 5], 'target': [0, 1, 0, 1, 0] } # Convert dictionary to DataFrame data = pd.DataFrame(data_dict) # 2. Split into features (X) and labels (y) X = data.drop("target", axis=1) y = data["target"] ``` Here, the dataset contains three features and a target variable. The X variable holds the features, and y holds the target. ## Step 3: Define a Machine Learning Pipeline A pipeline helps streamline preprocessing and model training steps. Here, we scale the features and train a random forest classifier: ```bash pipeline = Pipeline([ ('scaler', StandardScaler()), ('classifier', RandomForestClassifier(random_state=42)) ]) ``` The pipeline first applies feature scaling using StandardScaler, which normalizes the data. Then, it trains a RandomForestClassifier on the scaled features. ## Step 4: Define Hyperparameter Grid Hyperparameters are configurations external to the model, and tuning them can significantly affect performance. Define a grid of values to search: ```bash param_grid = { 'classifier__n_estimators': [100, 200, 300], 'classifier__max_depth': [10, 20, 30], 'classifier__min_samples_split': [2, 5, 10] } ``` Here, we tune three parameters of the RandomForestClassifier: the number of estimators, maximum depth, and minimum samples required to split a node. ## Step 5: Initialize GridSearchCV GridSearchCV performs an exhaustive search over the parameter grid to find the best combination: ```bash grid_search = GridSearchCV( estimator=pipeline, param_grid=param_grid, scoring='accuracy', cv=2, # <-- Reduced from 5 to 2 n_jobs=-1 ) ``` This setup optimizes the accuracy score, uses 2-fold cross-validation, and parallelizes computations for efficiency. ## Step 6: Fit the Model Train the model using the defined parameter grid: ```bash grid_search.fit(X, y) print("Best Parameters:", grid_search.best_params_) print("Best Score:", grid_search.best_score_) ``` The fit method evaluates all parameter combinations, and best_params_ shows the optimal hyperparameters. best_score_ displays the highest cross-validated accuracy. ## Step 7: Running the Code in a Jupyter Notebook Create a new notebook from the Jupyter Notebook dashboard, combine all code and paste them into the notebook cell, then run the notebook to observe the outputs. ![](https://www.atlantic.net/wp-content/uploads/2025/01/p1-2.png) The above image displays the best hyperparameter values **({‘classifier__max_depth’: 10, ‘classifier__min_samples_split’:** **2**, **‘classifier__n_estimators’: 100})** and the corresponding accuracy score **(0.583333…).** ## Step 8: Monitor GPU Usage To ensure the GPU is utilized efficiently, monitor its usage with: ```bash !nvidia-smi ``` This command shows GPU utilization, memory usage, and active processes. ![](https://www.atlantic.net/wp-content/uploads/2025/01/p2-1.png) ## Step 9: Save and Download Results Save the best-performing model to a file for future use. ```bash import joblib joblib.dump(grid_search.best_estimator_, "best_model.pkl") ``` This creates a portable file containing the trained model, which can be loaded later for inference. You can download this model using SCP or FTP method. ## Conclusion Performing hyperparameter tuning with GridSearchCV on a [cloud GPU](https://www.atlantic.net/gpu-server-hosting/) is much faster for large datasets or complex models. Follow this guide to set up and execute hyperparameter optimization in the cloud. Each step, from preparing the dataset to saving the results, is designed to be efficient and accurate. With the right setup, you will get the best out of your machine learning model. --- # How to Visualize Machine Learning Models with SHAP and LIME > URL: https://www.atlantic.net/gpu-server-hosting/how-to-visualize-machine-learning-models-with-shap-and-lime/ | Published: 2025-01-16 | Updated: 2025-02-07 | Author: Hitesh Jethva In machine learning, having a good model is only half the battle. Understanding how the model makes predictions is just as important especially when working with complex datasets or making decisions that impact business, healthcare or finance. This is where model interpretability comes in. Techniques like SHAP (SHapley Additive exPlanations) and LIME (Local Interpretable Model-agnostic Explanations) are great tools to explain the inner workings of machine learning models. This article will walk you through the visualization of machine learning models using SHAP and LIME, with a hands-on example. We will use the Iris dataset and a Random Forest classifier to demonstrate and run the model in Jupyter Notebook. ## Prerequisites - An Ubuntu 22.04 Cloud GPU Server. - CUDA Toolkit, cuDNN Installed. - Jupyter Notebook is installed and running. - A root or sudo privileges. ## Step 1: Installing Necessary Libraries Before diving into the implementation, ensure you have the required libraries installed in your environment. Use the following command to install them: ```bash pip install pandas ipywidgets numpy matplotlib scikit-learn shap lime ``` ## Step 2: Load the Dataset We’ll use the Iris dataset, a classic dataset in machine learning, to train a Random Forest classifier. The dataset contains information about different flower species and their features such as sepal length, sepal width, petal length, and petal width. ```bash import pandas as pd import shap from sklearn.datasets import load_iris from sklearn.ensemble import RandomForestClassifier from sklearn.model_selection import train_test_split from lime.lime_tabular import LimeTabularExplainer data = load_iris() X = pd.DataFrame(data.data, columns=data.feature_names) y = data.target ``` Here: - **X** contains the feature values. - **y** contains the target class labels for each flower species. ## Step 3: Train-Test Split We split the dataset into training and testing sets to evaluate the model’s performance. This ensures that the model is trained on one part of the data and tested on another. ```bash X_train, X_test, y_train, y_test = train_test_split( X, y, test_size=0.2, random_state=42 ) ``` Here: - **test_size=0.2:** Reserves 20% of the data for testing. - **random_state=42:** Ensures reproducibility of the split. ## Step 4: Train a Random Forest Model A random forest is a robust ensemble learning method that operates by constructing multiple decision trees and outputting the class, which is the mode of the classes of the individual trees. We’ll train this model using the training set. ```bash model = RandomForestClassifier(random_state=42) model.fit(X_train, y_train) ``` The trained model can now be used for predictions and analysis. ## Step 5: Explain Predictions with SHAP SHAP provides a unified measure of feature importance by attributing a prediction’s outcome to individual features. It uses Shapley values from cooperative game theory to explain predictions. ```bash explainer = shap.Explainer(model, X_train) shap_values = explainer(X_test, check_additivity=False) print("shap_values.values.shape:", shap_values.values.shape) # Typically (n_samples, n_classes, n_features) = (30, 3, 4) for Iris print("X_test.shape:", X_test.shape) ``` Here: - **check_additivity=False:** Disables additivity checks, which is often necessary for ensemble models like Random Forests. - **shap_values:** Contains SHAP values for all features in the test set. ## Step 6: Analyze SHAP Values The **shap_values** object helps us understand how each feature contributes to the model’s predictions. We can visualize these contributions globally and locally. ```bash num_classes = shap_values.values.shape[1] for class_idx in range(num_classes): # Extract Explanation object for this class only shap_values_class = shap_values[..., class_idx] print(f"\n--- Beeswarm for class {class_idx} ---") shap.plots.beeswarm(shap_values_class) ``` This visualization highlights the most influential features for each class, providing insights into the model’s decision-making process. ## Step 7: Explain Predictions with LIME LIME focuses on explaining individual predictions by approximating the model locally with an interpretable surrogate model. This makes it particularly useful for understanding specific predictions. ```bash lime_explainer = LimeTabularExplainer( training_data=X_train.values, feature_names=X_train.columns, class_names=data.target_names, mode="classification" ) ``` Here: - **feature_names:** Names of the features in the dataset. - **class_names:** Target class labels (e.g., species of flowers) ## Step 8: Analyze a Specific Instance We’ll analyze the model’s prediction for a specific test instance. ```bash instance = X_test.iloc[0].values lime_exp = lime_explainer.explain_instance( instance, model.predict_proba, num_features=4 ) lime_exp.show_in_notebook() lime_exp.as_pyplot_figure() ``` The visualization provides a breakdown of the features that contribute the most to the prediction for the selected instance. ## Step 9: Running the Code in a Jupyter Notebook Create a new notebook from the Jupyter Notebook dashboard, combine all code snippets and paste them into the notebook cell, and run the notebook to observe the outputs. ![](https://www.atlantic.net/wp-content/uploads/2025/01/p1-1.png) In the above result, the beeswarm plot illustrates the global importance of features, while the LIME explanation highlights the local contribution of features to an individual prediction. ## Conclusion Model interpretability is key to responsible AI. Tools like SHAP and LIME make it easier to explain predictions and trust machine learning models. In this tutorial we used the Iris dataset and a Random Forest classifier to show you how to use these tools. Start using these today on [GPU hosting](https://www.atlantic.net/gpu-server-hosting/) from Atlantic.Net to get more insights and make better decisions. --- # How to Build Your First Machine Learning Model with Scikit-learn > URL: https://www.atlantic.net/gpu-server-hosting/how-to-build-your-first-machine-learning-model-with-scikit-learn/ | Published: 2025-01-17 | Updated: 2025-01-27 | Author: Hitesh Jethva Machine learning (ML) has become a tool for solving many problems, from predicting house prices to recommending movies. Among the many libraries for ML in Python, Scikit-learn is one of the most popular. Scikit-learn is a robust and easy to use framework for implementing and testing machine learning algorithms. It includes tools for data preprocessing, dataset splitting, model training and evaluation. In this tutorial, you’ll learn how to build your first machine learning model using Scikit-learn on Atlantic.Net [Cloud GPU](https://www.atlantic.net/gpu-server-hosting/). ## Prerequisites - An Ubuntu 22.04 Cloud GPU Server. - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Step 1: Setting Up the Environment Before we begin coding, you need to install the required Python libraries. Open a terminal and execute the following commands: ```bash pip install scikit-learn pandas seaborn ``` Next, install the Jupyter Notebook. ```bash pip install notebook ``` Next, launch a Jupyter Notebook using the below command. ```bash jupyter notebook --no-browser --port=8888 --ip=your-server-ip --allow-root ``` After running the jupyter notebook command, you will see a URL in your terminal. Open your web browser and use this URL to access the Jupyter Notebook. **Note**: If you cannot access the Notebook, check to see if your Firewall is blocking traffic. ![](https://www.atlantic.net/wp-content/uploads/2025/01/p1.png) Click on **File** > **New** > **Notebook.** You will be asked to select the Kernel. ![](https://www.atlantic.net/wp-content/uploads/2025/01/p2.png) Select the **“Python (GPU)”** kernel and click **Select** to create a new notebook. ![](https://www.atlantic.net/wp-content/uploads/2025/01/p3.png) Jupyter Notebook allows you to write and execute Python code in a browser-based interface interactively. We will perform remaining steps in Jupyter Notebook. ## Step 2: Import Libraries and Prepare the Dataset Once the environment is set up, start by importing the necessary libraries and creating a small dataset. ```bash import numpy as np import pandas as pd from sklearn.model_selection import train_test_split from sklearn.linear_model import LinearRegression from sklearn.metrics import mean_squared_error, r2_score import seaborn as sns import matplotlib.pyplot as plt # Example dataset data = pd.DataFrame({ 'Feature1': [1, 2, 3, 4, 5], 'Feature2': [2, 4, 6, 8, 10], 'PRICE': [3, 6, 9, 12, 15] }) # Check for missing values print("Missing values in the dataset:") print(data.isnull().sum()) ``` In this code: - We imported essential libraries for machine learning **(sklearn),** data handling **(pandas),** and visualization **(seaborn, matplotlib).** - The data DataFrame is a simple dataset with two features (Feature1, Feature2) and a target variable (PRICE) to illustrate regression. - Missing values can create issues during model training, so we check them using **isnull().sum().** ![](https://www.atlantic.net/wp-content/uploads/2025/01/a1.png) ## Step 3: Visualize Data Relationships Visualization provides insights into how features are related to each other and the target variable. ```bash # Get basic statistics of the dataset print("\nBasic statistics of the dataset:") print(data.describe()) # Visualize the correlation matrix plt.figure(figsize=(10, 8)) sns.heatmap(data.corr(), annot=True, cmap="coolwarm") plt.title("Correlation Matrix") plt.show() ``` Here: - The **describe()** function provides an overview of the dataset, such as mean, min, and max values, which helps us understand its range and variability. - The correlation matrix reveals the strength of relationships between variables. - Values close to **1** or **-1** indicate strong positive or negative correlations, while values close to **0** show weak or no correlation. ![](https://www.atlantic.net/wp-content/uploads/2025/01/a2.png) ## Step 4: Define Features and Split Data Machine learning models require separating features (independent variables) from the target (dependent variable). Then, we split the data into training and testing sets. ```bash # Define features (X) and target variable (y) X = data.drop('PRICE', axis=1) y = data['PRICE'] # Split the data with sufficient test size test_size = 0.4 if data.shape[0] > 5 else 0.2 # Adjust test_size based on dataset size X_train, X_test, y_train, y_test = train_test_split(X, y, test_size=test_size, random_state=42) print(f"\nTraining set size: {X_train.shape[0]} rows") print(f"Test set size: {X_test.shape[0]} rows") ``` Here: - The feature set **(X)** is created by dropping the **PRICE** column, and **y** stores the target variable. - Using **train_test_split,** we divide the data into training (to build the model) and testing (to evaluate it). Adjusting **test_size** ensures a sufficient split based on dataset size. ![](https://www.atlantic.net/wp-content/uploads/2025/01/a3.png) ## Step 5: Train the Model Fit a linear regression model to the training data. We also use the trained model to predict the target variable for the test set. ```bash # Train the model model = LinearRegression() model.fit(X_train, y_train) print("\nModel Coefficients:", model.coef_) print("Intercept:", model.intercept_) # Predict housing prices y_pred = model.predict(X_test) # Compare actual vs predicted prices results = pd.DataFrame({"Actual": y_test.values, "Predicted": y_pred}) print("\nComparison of actual vs predicted prices:") print(results.head()) ``` Here: - The **LinearRegression** model learns a linear relationship between **X_train** and **y_train.** - The **coef_** and intercept_ values represent the slope and intercept of the regression line, which the model uses for predictions. - The **predict** method generates predictions for **X_test** using the trained model. - A **DataFrame** (results) compares actual and predicted values to help visualize the model’s accuracy. ![](https://www.atlantic.net/wp-content/uploads/2025/01/a4.png) ## Step 6: Evaluate the Model Evaluate the model’s performance using metrics such as Mean Squared Error (MSE) and R-squared. Then, create a scatter plot to visualize how closely the predicted values align with the actual values. ```bash # Calculate Mean Squared Error mse = mean_squared_error(y_test, y_pred) print(f"\nMean Squared Error: {mse:.2f}") # Calculate R-squared only if there are at least two test samples if X_test.shape[0] > 1: r2 = r2_score(y_test, y_pred) print(f"R-squared: {r2:.2f}") else: print("\nR-squared cannot be calculated due to insufficient test samples.") # Visualize actual vs predicted prices plt.scatter(y_test, y_pred, alpha=0.7) plt.xlabel("Actual Prices") plt.ylabel("Predicted Prices") plt.title("Actual vs Predicted Prices") plt.show() ``` Here: - **MSE** quantifies the average squared error between actual and predicted values, where lower values indicate better performance. - **R-squared** explains how well the features predict the target variable, with values closer to 1 indicating a better fit. ![](https://www.atlantic.net/wp-content/uploads/2025/01/a5.png) ## Conclusion Congratulations! You’ve completed your first machine learning model with Scikit-learn in Jupyter Notebook. This hands on approach is perfect for learning the basics of ML and Jupyter’s interactivity makes it easy to test and visualize. Now go experiment with larger datasets, more features and different algorithms. --- # AI Image Manipulation with Instruct Pix2Pix on Atlantic.Net Cloud GPU > URL: https://www.atlantic.net/gpu-server-hosting/ai-image-manipulation-with-instruct-pix2pix-on-atlantic-net-cloud-gpu/ | Published: 2025-01-18 | Updated: 2025-01-27 | Author: Hitesh Jethva Image manipulation has always been a cornerstone of creativity, enabling designers, artists, and hobbyists to bring their ideas to life. With the advent of AI, tools like Instruct Pix2Pix are revolutionizing this field by allowing users to edit images through simple text instructions. Instruct Pix2Pix leverages state-of-the-art deep learning models to perform detailed and accurate modifications to images based on prompts. This guide provides a step-by-step walkthrough to set up and use Instruct Pix2Pix on an Ubuntu GPU server. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p33.png) ## Prerequisites Before we dive into the setup, ensure that your server meets the following requirements: - An Ubuntu 22.04 Cloud GPU Server with at least 20 GB VRAM. - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. To confirm CUDA support, run: ```bash nvidia-smi ``` Ensure the output lists your GPU and available VRAM. ## Step 1: Installing Python Dependencies We’ll start by installing the required Python packages. Ensure Python 3 and pip are installed on your system. ```bash apt install python3 python3-pip ``` Next, install torch with Cuda support using the pip. ```bash pip3 install torch --index-url https://download.pytorch.org/whl/cu124 ``` ## Step 2: Setting Up Jupyter Notebook Jupyter Notebook provides an interactive environment to work with Instruct Pix2Pix. You can install it using the following command. ```bash pip3 install notebook ``` Next, run the Jupyter notebook. ```bash jupyter notebook --ip=your-server-ip --allow-root ``` You will see the following output. ```bash [I 2024-12-17 03:32:14.456 ServerApp] Jupyter Server 2.14.2 is running at: [I 2024-12-17 03:32:14.456 ServerApp] http://your-server-ip:8888/tree?token=6b926e2169755fafadf0282b219f775b978c9f5e009bbe16 [I 2024-12-17 03:32:14.456 ServerApp] http://127.0.0.1:8888/tree?token=6b926e2169755fafadf0282b219f775b978c9f5e009bbe16 [I 2024-12-17 03:32:14.456 ServerApp] Use Control-C to stop this server and shut down all kernels (twice to skip confirmation). [W 2024-12-17 03:32:14.459 ServerApp] No web browser found: Error('could not locate runnable browser'). [C 2024-12-17 03:32:14.459 ServerApp] To access the server, open this file in a browser: file:///root/.local/share/jupyter/runtime/jpserver-2789-open.html Or copy and paste one of these URLs: http://your-server-ip:8888/tree?token=6b926e2169755fafadf0282b219f775b978c9f5e009bbe16 http://127.0.0.1:8888/tree?token=6b926e2169755fafadf0282b219f775b978c9f5e009bbe16 ``` Note down the Jupyter notebook URL in the above output. ## Step 3: Access Jupyter Notebook In this section, we will access the Notebook and run the Model via web-based interface. ### 1. Access Jupyter Notebook Open the URL provided in the output (e.g., **http://your-server-ip:8888/tree?token=6b926e2169755fafadf0282b219f775b978c9f5e009bbe16)** in a web browser to access the Jupyter Notebook interface. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p1-5.png) Click on **File** => **New** => **Notebook** to create a new Notebook. You will be asked to select a kernel. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p2-4.png) Select a **Python kernel** and click on **Select.** You will see the new Notebook page. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p3-2.png) ### 2. Install Required Dependencies In the new Notebook window, install the required model libraries. ```bash !pip3 install diffusers accelerate safetensors transformers pillow ``` Click on **run** or press **Control** + **Enter** to install the above libraries. Upgrade Jupyter Notebook and the ipywidgets package. ```bash !pip3 install --upgrade jupyter ipywidgets ``` ### 3. Import Necessary Libraries In the Notebook window, add the below code to import the necessary library. ```bash from PIL import Image, ImageOps import requests import torch from diffusers import StableDiffusionInstructPix2PixPipeline, EulerAncestralDiscreteScheduler ``` ### 4. Download an Image Add this function to download and prepare an image: ```bash def download_image(url): image = Image.open(requests.get(url, stream=True).raw) image = ImageOps.exif_transpose(image) image = image.convert("RGB") return image # Example url = "https://i.postimg.cc/gkGpRjsp/image1.png" image = download_image(url) ``` **Note:** replace **https://i.postimg.cc/gkGpRjsp/image1.png** with your image URL. ### 5. Load the Instruct Pix2Pix Model Define and configure the model pipeline: ```bash model_id = "timbrooks/instruct-pix2pix" pipe = StableDiffusionInstructPix2PixPipeline.from_pretrained(model_id, torch_dtype=torch.float16, safety_checker=None) pipe.to("cuda") pipe.scheduler = EulerAncestralDiscreteScheduler.from_config(pipe.scheduler.config) ``` ### 6. Running the Pipeline Once the model is loaded, you can use it to edit images based on text prompts: ```bash prompt = "Make it red and blue" images = pipe(prompt, image=image, num_inference_steps=10, image_guidance_scale=1).images # Save or display the result images[0].save("output.png") images[0].show() ``` **Note:** Replace the prompt with your desired modification description. For example, “**Turn it into a sketch**” or “**Add a sunset background**.” After adding all the code to the Notebook window, Click on **run** or press **Control** + **Enter** to run the Notebook. You will see the generated image in the Notebook window. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p5.png) ### 7. Verifying GPU Utilization Ensure the GPU is utilized efficiently by running the following command in Notebook window: ```bash !nvidia-smi ``` The output should show the GPU memory being used by Python processes. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p6.png) ## Conclusion Instruct Pix2Pix enables flexible and precise image editing using simple text prompts. With an Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/), you can leverage this powerful AI tool for creative projects or experimentation. Follow this guide to set up your environment and start exploring the possibilities of AI-driven image manipulation. --- # Object Detection with Tensorflow on a Atlantic.Net Cloud Server > URL: https://www.atlantic.net/gpu-server-hosting/object-detection-with-tensorflow-on-a-atlantic-net-cloud-server/ | Published: 2025-01-19 | Updated: 2025-02-07 | Author: Hitesh Jethva Object detection is a key technology in computer vision, enabling machines to recognize and localize objects within images or video frames. It has diverse applications, from enhancing security with intelligent surveillance systems to powering autonomous vehicles, retail inventory management, and augmented reality experiences. TensorFlow offers a comprehensive Object Detection API that simplifies the process of creating, training, and deploying object detection models. In this guide, we will walk you through setting up TensorFlow’s Object Detection API on an Atlantic.Net Cloud GPU Server running Ubuntu 22.04. ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 22.04 Cloud GPU Server. - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Install Required Dependencies 1. First, update all system packages to the updated version. ```bash apt update -y ``` 2. Next, install essential tools and libraries required for TensorFlow and object detection. ```bash apt install python3-pip python3.10-venv protobuf-compiler ``` 3. Install the Python virtual environment package. ```bash pip install virtualenv ``` ## Create a Project Virtual Environment A virtual environment keeps your project’s dependencies isolated, ensuring compatibility and reducing conflicts. 1. Create a project directory. ```bash mkdir project ``` 2. Navigate into the project directory ```bash cd project ``` 3. Create the Python virtual environment. ```bash python3 -m venv env ``` 4. Activate the virtual environment. ```bash source env/bin/activate ``` ## Install TensorFlow Object Detection API 1. First, install TensorFlow and Cython. ```bash pip install tensorflow cython ``` 2. Clone the TensorFlow Object Detection API repository. ```bash git clone https://github.com/tensorflow/models ``` 3. Change the directory to the research directory. ```bash cd models/research ``` 4. Configure the model and training parameters using the protoc command. ```bash protoc object_detection/protos/*.proto --python_out=. ``` ## Install COCO API 1. Change back to the project directory. ```bash cd ../.. ``` 2. Clone the cocoapi repository. ```bash git clone https://github.com/cocodataset/cocoapi.git ``` 3. Change the directory to PythonAPI. ```bash cd cocoapi/PythonAPI ``` 4. Run the make command to build the library. ```bash make ``` 5. Copy the pycocotools subfolder into the research folder from the cloned TensorFlow Object Detection API repository. ```bash cp -r pycocotools ../../models/research/ ``` 6. Install the Object Detection API. ```bash cd ../../models/research cp object_detection/packages/tf2/setup.py . && python -m pip install . ``` ## Create an Object Detection Application In this section, we’ll build a Python application to use a pre-trained object detection model. 1. First, create a **main.py** file within your main project directory. ```bash cd ../../ nano main.py ``` Add the following code to main.py. ```bash import os import tensorflow as tf import numpy as np from PIL import Image from object_detection.utils import label_map_util from object_detection.utils import visualization_utils as viz_utils def download_model(model_name, model_date): """ Downloads and extracts the TensorFlow Object Detection model. """ base_url = 'http://download.tensorflow.org/models/object_detection/tf2/' model_file = model_name + '.tar.gz' model_dir = tf.keras.utils.get_file(fname=model_name, origin=base_url + model_date + '/' + model_file, untar=True) print(f"Model downloaded to: {model_dir}") return str(model_dir) def verify_model_path(model_dir, model_name): """ Verifies if the saved_model exists in the downloaded directory. Adjusts the path if there is an additional subfolder. """ saved_model_path = os.path.join(model_dir, model_name, "saved_model") if os.path.exists(saved_model_path): print(f"Found SavedModel at: {saved_model_path}") return saved_model_path else: raise FileNotFoundError(f"SavedModel not found in {saved_model_path}. Please check the download.") # Download model model_name = "ssd_resnet152_v1_fpn_1024x1024_coco17_tpu-8" model_date = "20200711" PATH_TO_MODEL_DIR = download_model(model_name, model_date) # Verify saved_model path with subfolder adjustment PATH_TO_SAVED_MODEL = verify_model_path(PATH_TO_MODEL_DIR, model_name) # Load model print("Loading model...") model_fn = tf.saved_model.load(PATH_TO_SAVED_MODEL) print("Model loaded successfully!") # Load labels PATH_TO_LABELS = 'models/research/object_detection/data/mscoco_label_map.pbtxt' category_index = label_map_util.create_category_index_from_labelmap(PATH_TO_LABELS, use_display_name=True) # Images to run detection images = ["balloon.png", "cow.png"] # Run inference for image in images: print(f"Running inference for image: {image}") # Load image into a numpy array image_np = np.array(Image.open(image).convert("RGB")) # Convert image to tensor input_tensor = tf.convert_to_tensor(image_np) # Add an axis to make it a batch input_tensor = input_tensor[tf.newaxis, ...] # Run inference detections = model_fn(input_tensor) # Process detection outputs num_detections = int(detections.pop('num_detections')) detections = {key: value[0, :num_detections].numpy() for key, value in detections.items()} detections['num_detections'] = num_detections detections['detection_classes'] = detections['detection_classes'].astype(np.int64) # Visualize detections image_np_with_detections = image_np.copy() viz_utils.visualize_boxes_and_labels_on_image_array( image_np_with_detections, detections['detection_boxes'], detections['detection_classes'], detections['detection_scores'], category_index, use_normalized_coordinates=True, max_boxes_to_draw=200, min_score_thresh=.30, agnostic_mode=False, line_thickness=8) # Save image with detections img = Image.fromarray(image_np_with_detections) img_filename = image.replace(".png", "_detect.png") img.save(img_filename) print(f"Saved image with detections to: {img_filename}") ``` **Explanation:** - The code downloads and verifies a TensorFlow object detection model from the TensorFlow model zoo. - It loads the saved model and label map to map class IDs to readable labels. - Images are preprocessed into tensors with a batch dimension for inference compatibility. - The model runs inference to detect objects and processes outputs like bounding boxes, classes, and scores. - Detected objects are visualized on images with annotations and saved as new files. 2. Download the sample images below, name them **balloon.png** and **cow.png,** and place them in the **project** directory. ![](https://www.atlantic.net/wp-content/uploads/2024/12/cow.png) ![](https://www.atlantic.net/wp-content/uploads/2024/12/baloon.png) The project directory should look like this: ```bash project ├── env/ └── models/ └── cocoapi/ └── main.py └── cow.png └── balloon.png ``` 3. Run the main.py script within your project directory. ```bash python3 main.py ``` Monitor the output for successful inference and file creation: ```bash I0000 00:00:1734412066.740691 32930 gpu_device.cc:2022] Created device /job:localhost/replica:0/task:0/device:GPU:0 with 5567 MB memory: -> device: 0, name: NVIDIA A40-8Q, pci bus id: 0000:06:00.0, compute capability: 8.6 Model loaded successfully! Running inference for image: balloon.png I0000 00:00:1734412088.887535 32952 cuda_dnn.cc:529] Loaded cuDNN version 90600 Saved image with detections to: balloon_detect.png Running inference for image: cow.png Saved image with detections to: cow_detect.png ``` The above code downloads the model, processes the images, and saves object-detected images within your project directory. 4. Download the newly generated images **(balloon_detect.png** and **cow_detect.png)** to your local machine for inspection. 5. Open the detected images and verify that the objects are correctly labeled. ![](https://www.atlantic.net/wp-content/uploads/2024/12/cow_detect.png) ![](https://www.atlantic.net/wp-content/uploads/2024/12/baloon_detect.png) ## Conclusion You have successfully set up TensorFlow Object Detection API on an Atlantic.Net Cloud Server and used it to detect objects in images. The process involved: - Installing TensorFlow and dependencies. - Setting up COCO and TensorFlow Object Detection APIs. - Running a pre-trained model for object detection. This setup can be extended to train custom models for domain-specific applications. Give it a try today on [GPU hosting](https://www.atlantic.net/gpu-server-hosting/) from Atlantic.Net! --- # AI Face Restoration using GFPGAN on Atlantic.Net Cloud GPU > URL: https://www.atlantic.net/gpu-server-hosting/ai-face-restoration-using-gfpgan-on-atlantic-net-cloud-gpu/ | Published: 2025-01-20 | Updated: 2025-01-27 | Author: Hitesh Jethva GFPGAN (Generative Facial Prior GAN) is a powerful tool developed by the TencentARC team for restoring old, damaged, or low-quality facial images. By leveraging generative models, GFPGAN can enhance facial details, improve resolution, and deliver more realistic restorations compared to traditional image enhancement methods. Using a GPU-accelerated environment is highly recommended for faster inference times when working on multiple images or high-resolution inputs. This guide will walk you through the process of setting up GFPGAN for AI-powered face restoration on an Atlantic.Net Cloud GPU server. ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 22.04 Cloud GPU Server. - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Update and Upgrade Packages Before starting, it’s always good practice to ensure your system is up to date: ```bash apt update apt upgrade ``` ## Install Python 3 and Pip Ubuntu 22.04 should have Python 3 and pip installed by default. If not, run: ```bash apt install -y python3 python3-pip ``` ## Install Torch with CUDA Support GFPGAN requires PyTorch for model inference. Install the appropriate PyTorch version for CUDA support. ```bash pip install torch==2.1.2+cu118 torchvision==0.16.2+cu118 --index-url https://download.pytorch.org/whl/cu118 ``` The **–index-url** option points pip to PyTorch’s CUDA 11.8 wheel index. ## Download the GFPGAN Repository Next, we’ll download the GFPGAN source code from GitHub: ```bash git clone https://github.com/TencentARC/GFPGAN.git ``` Once the download is completed, change the directory to the GFPGAN. ```bash cd GFPGAN ``` ## Install Dependent Packages 1. Install **basicsr** and **facexlib** for face detection and image restoration operations. ```bash pip install basicsr facexlib ``` 2. Install all the Python dependencies listed in GFPGAN’s **requirements.txt.** These may include image-processing libraries, PyTorch-related tools, and other necessary packages. ```bash pip install -r requirements.txt ``` 3. Install GFPGAN in a **“development”** mode. It allows you to run GFPGAN as a module and integrate its code changes immediately. ```bash python3 setup.py develop ``` 4. Install Real-ESRGAN to enhance images further. ```bash pip install realesrgan ``` ## Download the Pre-trained GFPGAN Model Weights GFPGAN relies on **pre-trained** models to perform face restoration. We will download version 1.3 of the model weights: ```bash wget https://github.com/TencentARC/GFPGAN/releases/download/v1.3.0/GFPGANv1.3.pth -P experiments/pretrained_models ``` This command downloads the GFPGANv1.3.pth model file directly into the experiments/pretrained_models folder, where GFPGAN expects the weights. ## Setting Up the Web Interface To make the restoration process user-friendly, we’ll set up a simple Flask-based web interface. With this interface, you can upload an image through a browser and get the restored version. 1. Create a folder for holding HTML templates used by the Flask application. ```bash mkdir templates ``` 2. Next, create a simple HTML page **index.html** for uploading images. ```bash nano templates/index.html ``` Add the code below. ```bash GFPGAN Web Interface

Upload an Image for Restoration

After uploading, the restored images will be processed and downloaded automatically.

``` This HTML form allows the user to select an image file and upload it to the Flask application. Once submitted, the image is sent to the upload endpoint for processing. 3. Create a Flask application. ```bash nano app.py ``` Add the following code: ```bash from flask import Flask, request, render_template, send_file import os import subprocess import shutil import zipfile from datetime import datetime app = Flask(__name__) UPLOAD_FOLDER = 'inputs/whole_imgs' RESULT_FOLDER = 'results' app.config['UPLOAD_FOLDER'] = UPLOAD_FOLDER os.makedirs(UPLOAD_FOLDER, exist_ok=True) os.makedirs(RESULT_FOLDER, exist_ok=True) @app.route('/') def index(): return render_template('index.html') @app.route('/upload', methods=['POST']) def upload_file(): if 'file' not in request.files: return "No file uploaded", 400 file = request.files['file'] if file.filename == '': return "No file selected", 400 filepath = os.path.join(app.config['UPLOAD_FOLDER'], file.filename) file.save(filepath) # Clean up old files in the results folder shutil.rmtree(RESULT_FOLDER) os.makedirs(RESULT_FOLDER, exist_ok=True) # Run GFPGAN inference command = f"python3 inference_gfpgan.py -i {UPLOAD_FOLDER} -o {RESULT_FOLDER} -v 1.3 -s 2" subprocess.run(command, shell=True) # Create a dynamically named ZIP archive of the results folder zip_name = f"results_{datetime.now().strftime('%Y%m%d_%H%M%S')}.zip" with zipfile.ZipFile(zip_name, 'w') as zipf: for root, dirs, files in os.walk(RESULT_FOLDER): for file in files: file_path = os.path.join(root, file) arcname = os.path.relpath(file_path, start=RESULT_FOLDER) zipf.write(file_path, arcname) # Send the ZIP file for download return send_file(zip_name, as_attachment=True) if __name__ == '__main__': app.run(host='0.0.0.0', port=5000) ``` This code will do the following: - Imports necessary libraries for file handling, subprocess execution, and **ZIP** archiving. - Sets **UPLOAD_FOLDER** and **RESULT_FOLDER** for storing input and output images. - Defines a Flask route **/** to display the upload form. - Defines a Flask route **/upload** to handle file uploads, run GFPGAN, and return a **ZIP** file of results. 4. Finally, run the Flask application. ```bash python3 app.py ``` You will get the following output. ```bash * Serving Flask app 'app' * Debug mode: off WARNING: This is a development server. Do not use it in a production deployment. Use a production WSGI server instead. * Running on all addresses (0.0.0.0) * Running on http://127.0.0.1:5000 * Running on http://your-server-ip:5000 Press CTRL+C to quit ``` ## Access the Flask Web UI 1. Open a browser and navigate to **http://your-server-ip:5000.** You will see an upload form. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p1-6.png) 2. Download the following image and save it on your local computer. ![](https://www.atlantic.net/wp-content/uploads/2024/12/image1.jpg) 3. Click on **Browse,** choose the downloaded image from your local system, and click **“Upload and Restore.**” 4. The server will run GFPGAN inference on the uploaded image and produce a restored version. Once complete, your browser should prompt you to download a ZIP file containing the restored image(s). ![](https://www.atlantic.net/wp-content/uploads/2024/12/p2-5.png) 5. The restored image will also be found in the **restored_imgs** folder inside your downloaded zip archive. ![](https://www.atlantic.net/wp-content/uploads/2024/12/image2.jpg) ## Conclusion By following this guide, you have successfully set up an AI-powered face restoration application using GFPGAN on an Ubuntu 22.04 cloud GPU server. This implementation leverages the power of GPU acceleration provided by PyTorch and CUDA, enabling high-performance image restoration. With GFPGAN, you not only harness state-of-the-art technology but also demonstrate the practical benefits of AI in real-world applications – test it out today on a [GPU server](https://www.atlantic.net/gpu-server-hosting/) from Atlantic.Net! --- # How to Deploy MLFlow on a Kubernetes Cluster > URL: https://www.atlantic.net/gpu-server-hosting/how-to-deploy-mlflow-on-the-kubernetes-cluster/ | Published: 2025-01-21 | Updated: 2025-02-07 | Author: Hitesh Jethva **MLFlow** is a powerful, open-source platform designed to manage the entire lifecycle of machine learning (ML) development. It provides tools for tracking experiments, packaging code, and deploying models. By deploying MLFlow on a Kubernetes cluster, you can leverage scalability, reliability, and GPU support for ML workloads. This guide provides a detailed, step-by-step walkthrough for setting up MLFlow on a Kubernetes cluster. ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 22.04 Cloud GPU Server. - CUDA Toolkit, cuDNN and Helm Installed. - A root or sudo privileges. ## Step 1: Install and Configure K3s K3s is a lightweight Kubernetes distribution that is ideal for quick setups. Install it using the following command: ```bash curl -sfL https://get.k3s.io | sh - ``` After installation, copy the K3s configuration file to your kubeconfig directory for **kubectl** to interact with the cluster: ```bash cp /etc/rancher/k3s/k3s.yaml ~/.kube/config ``` Confirm the Kubernetes cluster is up and running by checking the node status: ```bash kubectl get nodes ``` Expected output: ```bash NAME STATUS ROLES AGE VERSION ubuntu Ready control-plane,master 9s v1.31.3+k3s1 ``` ## Step 2: Install NVIDIA Container Toolkit To enable GPU support in your Kubernetes cluster, install the NVIDIA container toolkit: 1. Add the NVIDIA repository and import its GPG key: ```bash curl -fsSL https://nvidia.github.io/libnvidia-container/gpgkey | gpg --dearmor -o /usr/share/keyrings/nvidia-container-toolkit-keyring.gpg && curl -s -L https://nvidia.github.io/libnvidia-container/stable/deb/nvidia-container-toolkit.list | sed 's#deb https://#deb [signed-by=/usr/share/keyrings/nvidia-container-toolkit-keyring.gpg] https://#g' | tee /etc/apt/sources.list.d/nvidia-container-toolkit.list ``` 2. Update and install the toolkit: ```bash apt-get update apt-get install -y nvidia-container-toolkit ``` 3. Verify the installation: ```bash nvidia-container-cli --version ``` Output. ```bash cli-version: 1.17.3 lib-version: 1.17.3 build date: 2024-12-04T09:47+00:00 ``` 4. Deploy the NVIDIA plugin to manage GPUs in your Kubernetes cluster: ```bash kubectl apply -f https://raw.githubusercontent.com/NVIDIA/k8s-device-plugin/v0.13.0/nvidia-device-plugin.yml ``` ## Step 3: Configure Persistent Storage for MLFlow MLFlow requires persistent storage to save experiment data and models. Create and configure a Persistent Volume (PV) and Persistent Volume Claim (PVC): 1. Create a YAML file for the PV and PVC configuration: ```bash nano mlflow-pv-pvc.yaml ``` Add the following content: ```bash apiVersion: v1 kind: PersistentVolume metadata: name: mlflow-pv labels: type: local spec: storageClassName: manual capacity: storage: 10Gi accessModes: - ReadWriteOnce hostPath: path: "/mnt/data" --- apiVersion: v1 kind: PersistentVolumeClaim metadata: name: mlflow-pvc spec: storageClassName: manual accessModes: - ReadWriteOnce resources: requests: storage: 10Gi ``` 2. Apply the configuration: ```bash kubectl apply -f mlflow-pv-pvc.yaml ``` 3. Verify the **PV** and **PVC:** ```bash kubectl get pv ``` Output. ```bash NAME CAPACITY ACCESS MODES RECLAIM POLICY STATUS CLAIM STORAGECLASS VOLUMEATTRIBUTESCLASS REASON AGE mlflow-pv 10Gi RWO Retain Available manual 6s ``` ```bash kubectl get pvc ``` Output. ```bash NAME STATUS VOLUME CAPACITY ACCESS MODES STORAGECLASS VOLUMEATTRIBUTESCLASS AGE mlflow-pvc Bound mlflow-pv 10Gi RWO manual 15 ``` ## Step 4: Deploy MLFlow Using Helm 1. Add the Helm chart repository for MLFlow: ```bash helm repo add community-charts https://community-charts.github.io/helm-charts ``` 2. Update the Helm repository. ```bash helm repo update ``` 3. Install MLFlow using Helm: ```bash helm install atlantic community-charts/mlflow ``` Output. ```bash NAME: atlantic LAST DEPLOYED: Wed Dec 18 09:43:10 2024 NAMESPACE: default STATUS: deployed REVISION: 1 TEST SUITE: None NOTES: Get the application URL by running these commands: export POD_NAME=$(kubectl get pods --namespace default -l "app.kubernetes.io/name=mlflow,app.kubernetes.io/instance=atlantic" -o jsonpath="{.items[0].metadata.name}") export CONTAINER_PORT=$(kubectl get pod --namespace default $POD_NAME -o jsonpath="{.spec.containers[0].ports[0].containerPort}") echo "Visit http://127.0.0.1:8080 to use your application" kubectl --namespace default port-forward $POD_NAME 8080:$CONTAINER_PORT ``` 4. Verify that MLFlow has been successfully deployed: ```bash kubectl get deployments ``` Output. ```bash NAME READY UP-TO-DATE AVAILABLE AGE atlantic-mlflow 1/1 1 1 70s ``` ## Step 5: Expose MLFlow Service 1. To make MLFlow accessible, create a service: ```bash nano mlflow-service.yaml ``` Add the following configuration: ```bash apiVersion: v1 kind: Service metadata: name: mlflow-service spec: selector: app: mlflow ports: - protocol: TCP port: 80 targetPort: 5000 nodePort: 30001 # Optional, or let Kubernetes assign a random NodePort type: NodePort ``` 2. Deploy the service. ```bash kubectl apply -f mlflow-service.yaml ``` 3. Check the services running in your cluster. ```bash kubectl get services ``` Output. ```bash NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE atlantic-mlflow ClusterIP 10.43.183.234 5000/TCP 28m kubernetes ClusterIP 10.43.0.1 443/TCP 35m mlflow-service NodePort 10.43.158.142 80:30001/TCP 10m ``` **Note:** Note down the IP **10.43.158.142** shown in the CLUSTER-IP column. ## Step 6: Run the MLFlow Experiment 1. Create a directory for your models. ```bash mkdir Models cd Models ``` 2. Install the required Python packages. ```bash pip install mlflow scikit-learn shap matplotlib ``` 3. Set environment variables. ```bash export MLFLOW_EXPERIMENT_NAME='my-sample-experiment' export MLFLOW_TRACKING_URI='http://10.43.158.142' ``` **Note:** Replaced **10.43.158.142** with your CLUSTER-IP shown in the previous step. 4. Create a Python script (main.py) and add your ML experiment code. ```bash nano main.py ``` Add the following code: ```bash # Import Libraries import os import numpy as np import shap from sklearn.datasets import load_diabetes from sklearn.linear_model import LinearRegression import mlflow from mlflow.artifacts import download_artifacts from mlflow.tracking import MlflowClient # Prepare the Training Data X, y = load_diabetes(return_X_y=True, as_frame=True) X = X.iloc[:50, :4] y = y.iloc[:50] # Train a model model = LinearRegression() model.fit(X, y) # Log an explanation with mlflow.start_run() as run: mlflow.shap.log_explanation(model.predict, X) # List Artifacts client = MlflowClient() artifact_path = "model_explanations_shap" artifacts = [x.path for x in client.list_artifacts(run.info.run_id, artifact_path)] print("# artifacts:") print(artifacts) # Load the logged explanation dst_path = download_artifacts(run_id=run.info.run_id, artifact_path=artifact_path) base_values = np.load(os.path.join(dst_path, "base_values.npy")) shap_values = np.load(os.path.join(dst_path, "shap_values.npy")) # Show a Force Plot shap.force_plot(float(base_values), shap_values[0, :], X.iloc[0, :], matplotlib=True) ``` 5. Run the script. ```bash python3 main.py ``` Output. ```bash 100%|██████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 50/50 [00:00<00:00, 249.00it/s] 🏃 View run persistent-frog-660 at: http://10.43.158.142/#/experiments/1/runs/e19dbaac59fe452bab13217fcc9aac49 🧪 View experiment at: http://10.43.158.142/#/experiments/1 # artifacts: ['model_explanations_shap/base_values.npy', 'model_explanations_shap/shap_values.npy', 'model_explanations_shap/summary_bar_plot.png'] ``` ## Step 7: Copy Kubeconfig to the Local Machine To manage your Kubernetes cluster remotely, copy the kubeconfig file from the server to your local machine. 1. Create a .kube directory in your local machine. ```bash mkdir .kube ``` 2. Copy the kubeconfig file from your server. ```bash scp root@server-ip:/root/.kube/config .kube/ ``` 3. Edit the kubeconfig file. ```bash nano .kube/config ``` Find the following line: ` server: https://127.0.0.1:6443 ` And replace it with the following: ` server: https://your-server-ip:6443 ` 4. Verify connectivity. ```bash kubectl get services ``` Output. ```bash NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE atlantic-mlflow ClusterIP 10.43.183.234 5000/TCP 28m kubernetes ClusterIP 10.43.0.1 443/TCP 35m mlflow-service NodePort 10.43.158.142 80:30001/TCP 10m ``` ## Step 8: Access MLFlow UI To access the MLFlow UI from your local machine, you will need to forward the MLFlow service on that machine. ```bash kubectl port-forward svc/mlflow-service 8880:80 ``` Output. ```bash Forwarding from 127.0.0.1:8880 -> 5000 Forwarding from [::1]:8880 -> 5000 ``` Now, open your web browser and access the MLFlow UI at **http://127.0.0.1:8880/#/experiments/1** ![](https://www.atlantic.net/wp-content/uploads/2024/12/p1-4.png) ## Conclusion You’ve successfully deployed MLFlow on a Kubernetes cluster, configured it for GPU support, and run a sample experiment. This setup can be extended to manage and track ML experiments for production-scale applications. Try it today on [GPU hosting](https://www.atlantic.net/gpu-server-hosting/) from Atlantic.Net! --- # Building a GPU-Powered Web Interface with Gradio and CuPy on Atlantic.Net GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/building-a-gpu-powered-web-interface-with-gradio-and-cupy-on-atlantic-net-gpu-server/ | Published: 2025-01-22 | Updated: 2026-05-04 | Author: Hitesh Jethva GPUs (Graphics Processing Units) are indispensable for high-performance computations. They excel at parallel processing, making them ideal for tasks such as machine learning, data analysis, and scientific computations. When paired with intuitive tools like Gradio and CuPy, GPUs become even more accessible, enabling developers to build interactive and efficient applications for real-world use cases. This guide demonstrates how to set up a GPU-powered web interface for performing arithmetic computations using Atlantic.Net [GPU servers](https://www.atlantic.net/gpu-server-hosting/). ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 22.04 Cloud GPU Server. - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Step 1: Installing Required Libraries To perform GPU-accelerated computations, you need the CuPy library, which provides an interface similar to NumPy but runs operations on the GPU. Additionally, Gradio simplifies the creation of a web interface. Run the following command to install these libraries: ```bash pip install cupy-cuda12x gradio ``` To verify the installation, execute: ```bash python3 -c "import cupy as cp; print(cp.arange(10).sum())" ``` Expected output: ```bash 45 ``` This output confirms that **CuPy** is installed correctly and leveraging the **GPU** for computations. ## Step 2: Writing the Application We will now create a Python application **(app.py)** that performs GPU-based arithmetic operations and hosts a web interface. Use a text editor such as **nano** to create the application file: ```bash nano app.py ``` Add the following code: ```bash import gradio as gr import cupy as cp def gpu_arithmetic(num_elements, operation): a = cp.arange(num_elements, dtype=cp.float32) b = cp.arange(num_elements, dtype=cp.float32) if operation == "Add": result = a + b elif operation == "Multiply": result = a * b elif operation == "Dot Product": result = cp.dot(a, b) return f"Result: {result}" return f"First 10 elements: {result[:10].get()}" iface = gr.Interface( fn=gpu_arithmetic, inputs=[ gr.Number(label="Number of Elements"), gr.Dropdown(choices=["Add", "Multiply", "Dot Product"], label="Operation") ], outputs="text", description="Perform GPU arithmetic on two arrays of the given length." ) iface.launch(server_name="0.0.0.0", server_port=8888, share=False) ``` This script does the following: - **Defines the gpu_arithmetic Function**: Performs operations (Add, Multiply, Dot Product) on two arrays using CuPy. - **Sets Up the Gradio Interface**: Creates an interactive web interface with: - **Inputs:** Number of elements and operation type. - **Output:** Result of the computation. - **Launches the Interface**: Hosts the application on port **8888.** ## Step 3: Running the Application You can now run the application using the following command. ```bash python3 app.py ``` The output should display something like: ```bash Running on local URL: http://0.0.0.0:8888 ``` ## Step 4: Access the Gradio Web UI 1. Open a web browser and navigate to **http://your-server-IP:8888.** Replace **your-server-IP** with your Atlantic.Net server’s public IP address. 2. Specify the array’s number in the given field, select the **“Add”** operation, and click **Submit.** This will add the corresponding elements of two arrays and display the result. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p1-7.png) 3. Specify the number of the array in the given field, select the **“Multiply”** operation, and click **Submit.** This will multiply the corresponding elements of two arrays and display the result. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p2-6.png) 4. Specify the array’s number in the given field, select the **“Dot Product”** operation, and click **Submit.** This will compute the dot product of two arrays and display the result. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p3-3.png) ## Conclusion Setting up a GPU-powered web interface using Gradio and CuPy on an Atlantic.Net [GPU server](https://www.atlantic.net/gpu-server-hosting/) is a powerful way to handle heavy computations. With CuPy, you can perform fast, GPU-accelerated operations, and Gradio makes it easy to create an interactive web interface for users to access these capabilities. --- # Building a Streamlit App on a GPU Server with NumPy, Pandas, and PyTorch > URL: https://www.atlantic.net/gpu-server-hosting/building-a-streamlit-app-on-a-gpu-server-with-numpy-pandas-and-pytorch/ | Published: 2025-01-23 | Updated: 2025-01-27 | Author: Hitesh Jethva Streamlit is a popular tool for creating interactive and user-friendly web applications for data science and machine learning projects. It simplifies building dashboards and visualizations with Python. When integrated with powerful libraries like NumPy, Pandas, and PyTorch, Streamlit enables developers to create feature-rich, GPU-accelerated applications. In this guide, we will build a Streamlit app on a GPU server. The app will use NumPy for numerical computations, Pandas for data manipulation, and PyTorch for deep learning tasks. ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 22.04 Cloud GPU Server. - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Step 1: Install Required Packages The first step is to update the server’s package index and install the necessary libraries for your application. 1. Update the package index. ```bash apt update -y ``` 2. Install PyTorch and its related libraries using the following command: ```bash pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu124 ``` 3. Install Streamlit, along with NumPy, Pandas, and Matplotlib, for building and visualizing your app: ```bash pip install streamlit numpy pandas matplotlib ``` ## Step 2: Set Up the Project 1. Create a directory for the project. ```bash mkdir streamlit_gpu_app ``` 2. Navigate it to your project directory. ```bash cd streamlit_gpu_app ``` 3. Create a Python script that defines your Streamlit application: ```bash nano gpu_calculator.py ``` Add the following code: ```bash import streamlit as st import numpy as np import pandas as pd import torch # Title st.title("Streamlit App with GPU Computations") # Sidebar for user input st.sidebar.header("Choose an Operation") operation = st.sidebar.selectbox("Select a computation:", [ "Matrix Multiplication (NumPy)", "DataFrame Operations (Pandas)", "Tensor Computations (PyTorch)", "Train and Test a Deep Learning Model" ]) # Main app functionality if operation == "Matrix Multiplication (NumPy)": st.header("Matrix Multiplication with NumPy") # User inputs for matrix dimensions rows = st.number_input("Number of rows:", min_value=1, max_value=1000, value=3) cols = st.number_input("Number of columns:", min_value=1, max_value=1000, value=3) if st.button("Generate and Multiply Matrices"): # Generate random matrices matrix_a = np.random.rand(rows, cols) matrix_b = np.random.rand(cols, rows) # Perform matrix multiplication result = np.dot(matrix_a, matrix_b) st.write("Matrix A:") st.write(matrix_a) st.write("Matrix B:") st.write(matrix_b) st.write("Resultant Matrix:") st.write(result) elif operation == "DataFrame Operations (Pandas)": st.header("DataFrame Operations with Pandas") # Generate a random DataFrame rows = st.number_input("Number of rows:", min_value=1, max_value=1000, value=10) if st.button("Generate DataFrame"): df = pd.DataFrame( np.random.rand(rows, 5), columns=["A", "B", "C", "D", "E"] ) st.write("Randomly Generated DataFrame:") st.write(df) st.write("Column Summaries:") st.write(df.describe()) elif operation == "Tensor Computations (PyTorch)": st.header("Tensor Computations with PyTorch") # Tensor size input tensor_size = st.number_input("Tensor Size:", min_value=1, max_value=10000, value=3) if st.button("Generate Tensor and Compute"): # Generate random tensor on GPU tensor_a = torch.rand(tensor_size, tensor_size, device="cuda") tensor_b = torch.rand(tensor_size, tensor_size, device="cuda") # Perform matrix multiplication on GPU result = torch.matmul(tensor_a, tensor_b) st.write("Tensor A:") st.write(tensor_a.cpu().numpy()) st.write("Tensor B:") st.write(tensor_b.cpu().numpy()) st.write("Resultant Tensor:") st.write(result.cpu().numpy()) elif operation == "Train and Test a Deep Learning Model": st.header("Train and Test a Deep Learning Model") # User input for dataset size num_samples = st.number_input("Number of Samples:", min_value=100, max_value=10000, value=1000) num_features = st.number_input("Number of Features:", min_value=1, max_value=100, value=10) if st.button("Train Model"): # Generate random data X = torch.rand(num_samples, num_features, device="cuda") y = torch.sum(X, dim=1) + torch.randn(num_samples, device="cuda") * 0.1 # Add noise # Define a simple model model = torch.nn.Sequential( torch.nn.Linear(num_features, 50), torch.nn.ReLU(), torch.nn.Linear(50, 1) ).to("cuda") # Loss and optimizer criterion = torch.nn.MSELoss() optimizer = torch.optim.Adam(model.parameters(), lr=0.01) # Train the model epochs = 50 for epoch in range(epochs): optimizer.zero_grad() predictions = model(X) loss = criterion(predictions.squeeze(), y) loss.backward() optimizer.step() st.success(f"Training complete! Final Loss: {loss.item():.4f}") # Test the model test_data = torch.rand(10, num_features, device="cuda") test_predictions = model(test_data) st.write("Test Data:") st.write(test_data.cpu().numpy()) st.write("Predictions:") st.write(test_predictions.cpu().detach().numpy()) ``` Here is the explanation: - The code creates a Streamlit web app with a sidebar for choosing different operations. - Based on the selection, it can do matrix multiplication with NumPy, DataFrame tasks with Pandas, or tensor computations on GPU with PyTorch. - It also trains and tests a simple deep learning model using PyTorch. - User inputs for data size and model parameters are taken from the Streamlit interface. - Results, such as matrices, data summaries, or model predictions, are displayed directly in the browser. ## Step 3: Run the Streamlit App You can now run the app using the server’s IP address. Replace with your server’s IP address. ```bash streamlit run gpu_calculator.py --server.address your-server-ip --server.port 8501 ``` You will see the below output. ` You can now view your Streamlit app in your browser.` URL: http://your-server-ip:8501 **Note:** Replace the **your-server-ip** with the actual IP address of the GPU server. ## Step 4: Accessing the App in a Web Browser Open your web browser and access your app using the URL **http://your-server-ip:8501.** The app loads with a sidebar containing operation options. Users can navigate to desired features like NumPy, Pandas, or PyTorch computations. **1. Matrix Multiplication with NumP** Input dimensions in the sidebar and click **“Generate and Multiply Matrices.”** The result displays Matrix A, Matrix B, and the resultant matrix. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p1-8.png) **2. DataFrame Operations with Pandas** Input the number of rows in the sidebar and click **“Generate DataFrame.”** A DataFrame is displayed along with column summaries. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p2-7.png) **3. Tensor Computations with PyTorch** Input tensor size in the sidebar and click **“Generate Tensor and Compute.”** Tensors and results are shown with GPU acceleration. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p3-4.png) **4. Train and Test a Deep Learning Model** Input dataset parameters in the sidebar and click **“Train Model.”** The model trains for 50 epochs, and test predictions are displayed. ![](https://www.atlantic.net/wp-content/uploads/2024/12/p4.png) ## Conclusion This guide has walked you through the entire process—from setting up your environment and writing modular code to deploying and interacting with the app in a web browser. Each functionality, from NumPy matrix operations to training a deep learning model with PyTorch, demonstrates the flexibility and efficiency of this setup. Try it today on [GPU hosting](https://www.atlantic.net/gpu-server-hosting/) from Atlantic.Net! --- # 17-Step PCI Compliance Checklist, Common Pitfalls and Solutions > URL: https://www.atlantic.net/pci-compliant-hosting/17-step-pci-compliance-checklist-common-pitfalls-and-solutions/ | Published: 2025-01-24 | Updated: 2025-02-07 | Author: Gilad Maayan ## What Is PCI Compliance? PCI compliance is the practice of adhering to the payment card industry data security standards (PCI DSS), which are guidelines established to ensure businesses process, store, or transmit credit card information securely. It mandates a standard methodology for network security, encryption, and related practices to safeguard sensitive payment data. PCI compliance involves fostering a secure transactional environment. Businesses that adhere to PCI DSS standards reduce the risk of security incidents. Non-compliance not only poses security risks but can also result in substantial fines and loss of reputation. Thus, PCI compliance is integral for organizations in the payment card industry. This is part of a series of articles about [PCI compliant hosting.](https://www.atlantic.net/pci-compliant-hosting/) ## Preparing for a PCI DSS Audit Preparedness for a PCI DSS audit involves meticulous planning and thorough understanding of compliance requirements. Establishing a compliance program and ensuring all relevant documentation is ready are crucial steps for a successful audit outcome. ### Self-Assessment Questionnaires (SAQs) Self-assessment questionnaires allow organizations to evaluate their compliance status in a structured manner. Depending on the company’s level and type of transactions, specific SAQs are utilized to validate adherence to PCI DSS requirements, providing a snapshot of current security measures. Completing SAQs accurately requires deep knowledge of internal security practices and systems. Organizations need to be honest and precise in their responses to ensure true reflection of compliance levels. This not only supports successful auditing but also guides in identifying areas needing improvement. ### Working with a Qualified Security Assessor (QSA) Organizations that process over 6 million transactions per annum are required to engage with a qualified security assessor (QSA). This is an organization that provides expert guidance in navigation of PCI DSS compliance. QSAs help identify gaps, recommend solutions, and ensure adherence to all aspects of PCI requirements, facilitating a smooth auditing process for businesses, especially those with complex environments. Choosing a reputable QSA involves researching their credentials and experience with industry-specific compliance challenges. Collaborating closely with a QSA helps build a compliance plan, ensuring thorough preparation for audits and sustained PCI compliance post-evaluation. ## The Complete PCI Compliance Checklist ### 1. Install and Maintain a Firewall Configuration to Protect Cardholder Data A firewall acts as a barrier between trusted internal networks and untrusted external networks, making it a critical component for protecting cardholder data. Firewalls must be configured to block unauthorized access and only permit traffic that is necessary for the organization’s operations. Best practices: - **Define clear access control rules**: Establish explicit firewall rules that dictate which IP addresses and services are allowed to access your network. This limits access to only necessary systems. - **Regularly update firewall configurations**: Ensure firewall rules are reviewed and updated regularly, especially when new applications, devices, or users are added to the network. - **Log and monitor traffic**: Enable logging on the firewall to monitor both inbound and outbound traffic, and regularly review these logs for suspicious activity. - **Segment the cardholder data environment (CDE)**: Isolate systems that store or process cardholder data from other network components to minimize potential attack vectors. ### 2. Avoid Using Vendor-Supplied Defaults for System Passwords and Other Security Parameters Vendor-supplied default passwords and settings are well-known across the industry and are often the first point of attack for cybercriminals. Upon installation of any system or software, it is essential to change these defaults immediately. Strong password policies should be enforced, including the use of complex passwords that combine letters, numbers, and special characters. Best practices: - **Change default settings immediately**: After installing hardware or software, update all default usernames and passwords to stronger, unique credentials. - **Implement complex password policies**: Require passwords that include a mix of upper and lower-case letters, numbers, and special characters, with a minimum length of 12 characters. - **Disable unused accounts**: Remove or disable any default accounts that are not necessary for the operation of your system. - **Enforce regular password changes**: Ensure all administrative passwords are changed periodically and following a set schedule, particularly for critical systems. ### 3. Protect Stored Cardholder Data (Encrypt, Truncate, Mask, or Hash) Organizations must ensure that all stored cardholder data is protected using strong encryption methods, such as advanced encryption standard (AES) with a 256-bit key. In addition to encryption, data masking, truncation, or hashing should be employed to minimize exposure. Best practices: - **Use strong encryption**: Apply AES-256 encryption for all stored cardholder data, ensuring data is unreadable without proper authorization. - **Limit data retention**: Only store cardholder data when absolutely necessary, and remove any unnecessary data as soon as possible. - **Use tokenization**: Implement tokenization to replace sensitive cardholder data with a non-sensitive equivalent (token), which cannot be used outside of your system. - **Mask data where applicable**: Display only the last four digits of a card number for employees or customers who do not require full access to sensitive data. ### 4. Encrypt Transmission of Cardholder Data Across Open, Public Networks Any cardholder data transmitted over open or public networks, such as the Internet, must be encrypted using strong cryptographic protocols. transport layer security (TLS) 1.3 or higher is recommended to safeguard data from interception or tampering. Best practices: - **Use TLS 1.3 or higher**: Ensure that all transmitted cardholder data is encrypted using TLS 1.3 or higher for secure communications across public networks. - **Disable weak protocols and ciphers**: Deactivate outdated encryption protocols such as SSL and weaker ciphers to reduce vulnerabilities in data transmission. - **Monitor for certificate expiry**: Regularly check and renew SSL/TLS certificates before they expire to avoid insecure communications. - **Mask Primary Account Numbers (PANs):** Ensure PANs are masked when displayed on device screens or physical receipts. ### 5. Protect All Systems Against Malware and Regularly Update Anti-Virus Software To defend against malware attacks, organizations must install and maintain anti-virus software across all systems that interact with cardholder data. This includes point-of-sale (POS) devices, servers, and workstations. Best practices: - **Use next-generation anti-virus (NGAV) Software**: Implement advanced anti-virus software that includes real-time threat detection and prevention. - **Enable automatic updates**: Configure all anti-virus programs to automatically download and install updates to protect against the latest malware variants. - **Run regular scans**: Schedule routine system scans to detect any potential malware or viruses on all systems, including servers and endpoints. ### 6. Develop and Maintain Secure Systems and Applications Secure development practices are critical to ensuring that applications and systems are resistant to cyberattacks. This includes conducting regular vulnerability assessments and applying security patches as soon as they become available. Best practices: - **Apply security patches promptly**: As soon as new patches are available for software or systems, apply them immediately to close known vulnerabilities. - **Conduct regular code reviews**: Perform thorough security code reviews for all internally developed applications to identify and fix potential vulnerabilities. - **Use multi-factor authentication (MFA)**: Require MFA for administrative access to systems and applications to add an extra layer of security. - **Implement web application firewalls (WAFs)**: Deploy WAFs to protect web applications from common attacks such as SQL injection and cross-site scripting (XSS). ### 7. Restrict Access to Cardholder Data by Business Need-to-Know Access to cardholder data must be strictly limited to employees and systems that require it to perform their job functions. role-based access control (RBAC) should be used to enforce the principle of least privilege, ensuring that only authorized individuals can access sensitive data. Best practices: - **Implement role-based access control (RBAC)**: Assign access rights based on roles and job functions, ensuring that employees can only access cardholder data necessary for their work. - **Regularly review access permissions**: Conduct periodic audits of user permissions to ensure access levels remain appropriate and revoke access for users who no longer need it. - **Use the principle of least privilege**: Grant the minimum level of access required for users to perform their tasks, minimizing the risk of accidental or malicious data exposure. ### 8. Assign a Unique ID to Each Person with Computer Access To ensure accountability and traceability, each individual who accesses systems that handle cardholder data must have a unique identifier. This allows organizations to monitor and log all activities performed by each user. Unique IDs also help identify unauthorized or suspicious behavior in the event of a security incident. Best practices: - **Create unique user accounts**: Ensure that each employee or contractor has their own unique username and password for system access, rather than sharing accounts. - **Monitor for unauthorized access attempts**: Set up automated alerts for suspicious login activities, such as repeated failed access attempts or logins from unusual locations. - **Enforce account lockouts**: Implement account lockout mechanisms after a certain number of failed login attempts to protect against brute-force attacks. ### 9. Restrict Physical Access to Cardholder Data Physical security is just as important as digital security when it comes to protecting cardholder data. Data centers, servers, and other devices that store or process cardholder data should be located in secure facilities with restricted access. Best practices: - **Secure physical locations**: Use access control mechanisms such as key cards, biometrics, or PINs to restrict entry to areas where cardholder data is stored or processed. - **Deploy surveillance systems**: Install security cameras to monitor entry points and sensitive areas, maintaining records of physical access to data centers and server rooms. - **Monitor physical access**: Maintain logs of all personnel who access secure areas and regularly review these logs for any unauthorized access. - **Use tamper-evident seals**: Place tamper-evident seals on physical media, such as backup tapes, to detect and deter unauthorized access or alteration. ### 10. Track and Monitor All Access to Network Resources and Cardholder Data To detect and respond to security incidents, it is critical to track and monitor all access to network resources and cardholder data. Comprehensive logging should be enabled across all systems, capturing key details such as user activity, system changes, and data access. Best practices: - **Implement centralized logging**: Use a centralized logging system to collect logs from all network resources, making it easier to analyze access patterns and detect anomalies. - **Enable real-time monitoring**: Set up tools for real-time monitoring of access to cardholder data and critical systems, triggering alerts for any suspicious activity. - **Retain logs for compliance**: Ensure logs are retained for at least one year, with a minimum of three months immediately available for analysis in case of an incident. ### 11. Regularly Test Security Systems and Processes Organizations must regularly test their security systems and processes to ensure that they are functioning as intended and capable of protecting cardholder data. Regular testing helps identify weaknesses that could be exploited by attackers, allowing organizations to address them before they become security incidents. Best practices: - **Conduct quarterly vulnerability scans**: Perform vulnerability scans at least once per quarter, both internally and externally, to identify security weaknesses in your network and systems. - **Perform annual penetration tests**: Engage a qualified security expert to conduct penetration testing at least once a year to simulate real-world attacks and identify exploitable vulnerabilities. - **Test security controls after significant changes**: Whenever there are changes to the network infrastructure, such as new software installations or configuration updates, perform security testing to ensure no new vulnerabilities are introduced. ### 12. Maintain a Policy That Addresses Information Security for All Personnel Every organization handling cardholder data should establish an information security policy that outlines the roles, responsibilities, and expectations for all personnel. This policy should cover key areas such as data protection, access control, and incident response. Best practices: - **Define clear security roles and responsibilities**: Ensure the information security policy clearly outlines the responsibilities of all personnel in maintaining data security. - **Conduct security awareness training**: Provide ongoing training for employees to educate them on security risks, phishing attacks, password hygiene, and other key security principles. - **Enforce disciplinary measures for non-compliance**: Establish clear disciplinary actions for employees who fail to adhere to security policies, ensuring accountability. ### 13. Ensure That Service Providers Handle Cardholder Data Securely When working with third-party service providers that process or store cardholder data, organizations must conduct thorough due diligence to ensure that these providers comply with PCI DSS. Best practices: - **Conduct due diligence before onboarding**: Perform thorough evaluations of third-party service providers before signing contracts, ensuring they meet PCI DSS requirements. - **Include security clauses in contracts**: Ensure contracts with service providers specify that they must maintain PCI DSS compliance and are responsible for protecting cardholder data. - **Request regular compliance attestations**: Require service providers to provide proof of PCI DSS compliance, such as reports on compliance (ROCs) or attestation of compliance (AOCs), on an annual basis. ### 14. Ensure That Cloud Providers Comply with PCI DSS Requirements If an organization uses cloud services to store or process cardholder data, it must ensure that the cloud provider complies with PCI DSS. This includes understanding the shared responsibility model, where both the organization and the cloud provider share responsibilities for securing the data. Best practices: - **Understand the shared responsibility model**: Clearly define which aspects of PCI DSS compliance are the responsibility of the cloud provider and which are the responsibility of your organization. - **Review the cloud provider’s compliance certifications**: Request documentation such as AOCs or ROCs to confirm that the cloud provider has been audited and complies with PCI DSS. - **Audit the cloud provider’s security practices**: Regularly assess the cloud provider’s security practices, ensuring they maintain strong security controls, including access management and encryption. ***Learn more in our detailed guide to***[***cloud PCI compliance.***](https://www.atlantic.net/pci-compliant-hosting/pci-compliance-in-the-cloud-challenges-and-key-requirements/) ### 15. Encrypt Sensitive Data Stored and Transmitted in Cloud Environments To protect cardholder data stored and transmitted in cloud environments, encryption must be applied both at rest and in transit. Strong encryption algorithms, such as AES-256, should be used, and encryption keys must be managed securely, with access restricted to authorized personnel only. Best practices: - **Apply AES-256 encryption for data at rest**: Ensure all sensitive data stored in cloud environments is encrypted using AES-256 to protect it from unauthorized access. - **Use TLS 1.2 or higher for data in transit**: Encrypt all data transmitted between your organization and the cloud provider using TLS 1.2 or higher, to prevent interception during transmission. - **Implement secure key management practices**: Use a dedicated key management service (KMS) to securely generate, store, and rotate encryption keys, limiting access to authorized personnel only. ### 16. Develop an Incident Response Plan for Handling a Data Breach An incident response plan is crucial for minimizing the damage caused by a data breach. The plan should outline the steps to be taken when a security incident occurs, including roles and responsibilities, communication protocols, and procedures for containing, investigating, and recovering from the breach. Best practices: - **Define clear incident response procedures**: Document specific steps to follow in case of a breach, including containment, investigation, and remediation processes. - **Assign roles and responsibilities**: Identify key personnel who will be responsible for managing various aspects of the breach, such as communication, investigation, and legal responses. - **Create communication protocols**: Develop communication plans for notifying affected customers, regulatory bodies, and other stakeholders in the event of a breach. ### 17. Ensure Regular Testing of the Incident Response Plan The incident response plan should not only be well-documented but also regularly tested through simulations and tabletop exercises. These tests help identify weaknesses in the plan and allow organizations to refine their response strategies. Best practices: - **Conduct annual tabletop exercises**: Simulate a security breach scenario and involve key personnel to walk through the response steps, identifying potential gaps in the process. - **Test for various incident types**: Ensure the incident response plan is tested for different breach scenarios, such as malware attacks, insider threats, or data leaks. - **Involve third-party security experts**: Engage third-party consultants to review and test your incident response plan, ensuring an objective assessment of your preparedness. - **Review and update incident response plans**: Periodically review the plan to adapt to evolving threats and incorporate lessons from previous security incidents. ## Common Challenges in Achieving PCI Compliance Here are common challenges your organization might face when building a PCI compliance program. ### Scope Creep and Identifying Cardholder Data Environment Scope creep occurs when unmonitored changes lead to expanded data environments, complicating compliance efforts. Identifying and maintaining a well-defined cardholder data environment is crucial for compliance. This requires mapping data flows and isolating environments to ensure only relevant systems fall within the compliance scope. **Addressing the challenge:** Implementing consistent monitoring practices, documentation, and boundary definitions helps manage scope creep effectively. Accurate scoping not only supports compliance but also enables organizations to apply focused security measures, safeguarding sensitive information. ### Keeping Up With Changing Compliance Requirements Compliance requirements frequently evolve to address new security threats, presenting challenges for organizations in maintaining up-to-date protocols. This demands continuous vigilance and adaptability, ensuring policies and procedures align with current standards. Adequate resource allocation towards research and compliance updates is crucial in smooth transitions. **Addressing the challenge:** Organizations should cultivate a proactive compliance culture, engaging in regular training and awareness initiatives for employees. Staying abreast of industry changes and collaborating with experts aids in anticipating requirements, facilitating prompt adaptation to revised compliance mandates. ### Managing Third-Party Service Providers Third-party service providers can introduce vulnerabilities into the cardholder data environment if not properly managed. Ensuring third-party compliance involves due diligence in vendor selection, ongoing assessments, and clear agreements aligning security practices with PCI DSS standards. Collaborative approaches are key in reducing associated risks. **Addressing the challenge:** Routine audits and contractual obligations help enforce compliance across third-party interactions, maintaining oversight on data handled externally. Transparency and effective communication between organizations and their providers ensure alignment on security objectives. ### **PCI Hosting Services and Solutions by Atlantic.Net** PCI Hosting by Atlantic.Net™ is SOC 2 and SOC 3 certified, designed to secure and protect critical health data, audited by a qualified and an independent third-party CPA firm. If your company requires PCI-DSS compliance (Payment Card Industry Data Security Standard), Atlantic.Net’s managed security and compliance hosting services coupled with our Cloud Platform and Dedicated Hosting will provide you the easy button to help achieve and exceed your credit card industry PCI compliance requirements! With our expanded network capacity and hardened data centers, your business will be able to achieve the uptime and cyber-security requirements for PCI compliance. You can meet your customers’ needs and accept online payments while maintaining PCI compliance and reducing your overall cost. Gain the competitive advantage you need with ease with our PCI-Compliant Hosting, backed by a 100% SLA. [**Learn more about Atlantic.net PCI-compliant web hosting.**](https://www.atlantic.net/pci-compliant-hosting/) --- # GPU for AI: Platforms, Top GPUs, and Key Features to Consider > URL: https://www.atlantic.net/gpu-server-hosting/gpu-for-ai-platforms-top-gpus-and-key-features-to-consider/ | Published: 2025-01-25 | Updated: 2025-05-14 | Author: Gilad Maayan ## What Are GPUs? Graphics processing units (GPUs) are specialized electronic circuits that accelerate image rendering and processing. Initially developed for graphics-intensive tasks, GPUs have evolved significantly. They consist of thousands of smaller cores optimized for parallel processing, allowing them to perform many calculations simultaneously. This architecture is well-suited for operations involving large datasets and complex computational tasks. In addition to their graphics capabilities, GPUs have become crucial for machine learning and artificial intelligence (AI). Their design allows them to handle tasks that require massive data throughput and high-speed computation efficiently. Compared to central processing units (CPUs), GPUs can offer substantial performance improvements for specific workloads, making them versatile components in both consumer and enterprise technology solutions. This is part of an extensive series of guides about [machine learning](https://www.tabnine.com/blog/real-world-machine-learning-models-use-cases-operations/). ## Why GPUs Are Great for AI ### Handling Large Matrix Operations GPUs handle large matrix operations, which are fundamental to AI and machine learning tasks. These operations often involve performing a vast number of calculations simultaneously, a task that GPUs execute efficiently. Traditional CPUs, even very powerful ones, lack the parallel processing infrastructure found in GPUs, resulting in slower performance for these tasks. The ability to process large volumes of data in parallel makes GPUs indispensable in AI applications. ### Accelerating Deep Learning Tasks GPUs accelerate deep learning tasks by providing the computational power to handle deep neural networks, which require intensive computation. These tasks often involve handling complex layers of computations that CPUs would process sequentially over longer periods. The parallel architecture of GPUs allows them to process multiple operations at once, significantly reducing the time required for model training and inference. Some GPUs have features specific to deep learning, such as tensor cores, which enhance their performance for AI applications. These enhancements focus on increasing throughput for operations vital to deep learning, like matrix multiplications and convolutions. As a result, GPUs have been behind some of the biggest breakthroughs in fields like computer vision and natural language processing. ### Performance Improvements in AI Model Training AI model training benefits markedly from the performance improvements offered by GPUs, especially when dealing with large, complex datasets. The parallel processing capabilities of GPUs allow for faster computation of gradients and parameter updates, which are critical tasks in training neural networks. As a consequence, training times can be reduced significantly, enabling researchers and developers to iterate and refine models more quickly. Enhanced performance with GPUs also leads to practical benefits such as reduced energy consumption and lower operational costs over time. Faster training phases and more efficient resource utilization mean that fewer computational resources are needed, reducing the workload on hardware and saving time and energy. ## Popular GPU Platforms for AI In order to use GPUs effectively in AI projects, you will need an entire ecosystem, which includes not only the hardware itself but also drivers, supporting software, and networking equipment. NVIDIA, AMD and Intel each provide a platform that offers this ecosystem. In addition, many organizations rely on third party providers hosting pre-configured GPU systems. ### NVIDIA NVIDIA is a leading player in the GPU market and one of the world’s fastest growing companies. Its GPUs are integral to AI applications, notably for their CUDA architecture which allows developers to program in a parallel-computing environment efficiently. This architecture has become a standard in academia and industry, facilitating widespread adoption of NVIDIA GPUs for AI research and development. Their ecosystem includes software, libraries, and development tools that enhance productivity and performance in AI workflows. NVIDIA’s GPUs are equipped with features specifically for machine learning and deep learning tasks. The introduction of tensor cores in their architectures resulted in significant performance improvements for AI computations, allowing deep learning tasks to execute faster and more efficiently. The company offers products ranging from data center-grade GPUs and massive-scale GPU servers, to lower-cost consumer-grade offerings. ### AMD AMD offers a competitive alternative in the GPU market, focusing on high-performance computing and graphics. Known for their open-source approach, AMD GPUs support various programming models and libraries through their ROCm (Radeon Open Compute) platform. This platform provides an ecosystem that allows AI developers to build, optimize, and deploy machine learning solutions effectively. AMD’s commitment to openness has led to a supportive community and wide-ranging collaborations in AI research and development. AMD GPUs are increasingly recognized for their performance in AI workloads. They have been optimized to deliver high throughput and efficiency, especially in applications requiring significant parallel processing capabilities. With recent advancements, AMD has closed the gap with competitors regarding performance and power efficiency, making their GPUs a viable option for AI applications seeking alternatives to dominant market players. ### Intel Intel, primarily known for its CPU technology, has also made strategic inroads into the GPU market with its dedicated graphics offerings. Intel’s approach integrates GPUs with their x86 architecture, offering potential advantages in terms of compatibility and performance synergy with their existing CPU technologies. This integration allows for seamless transitions and optimizations in workloads that require both CPU and GPU resources. Intel’s GPUs leverage the company’s historical strengths in processing power and innovation in chip technology to deliver GPUs capable of handling AI workloads efficiently. Intel’s focus on integrated solutions and its increasing investment into GPU development suggest an expanding role in the AI ecosystem. However, at the time of this writing, Intel is considered a niche player, with its solutions mainly catering to hybrid workloads including both AI and traditional applications. ### Cloud-Hosted GPUs Cloud hosting services offer GPUs as a way to scale AI applications without the need for substantial upfront hardware investments. Specialized hosting providers like Atlantic.net, and general-purpose cloud platforms like Amazon Web Services (AWS), provide cloud-based GPU options that can be tailored to the requirements of specific AI projects. These services allow developers to access powerful GPU technology on a pay-per-use basis, making them an attractive option for businesses looking to manage costs while leveraging high-performance AI capabilities. Cloud-hosted GPUs provide flexibility and scalability for AI workloads, accommodating fluctuating demand with ease. The ability to spin up virtual machines with GPU acceleration makes it possible to handle peak processing requirements efficiently. Cloud providers also offer support and optimization tools, facilitating the deployment and management of AI models. ***Related content: Read our guide to [GPU cloud computing](https://www.atlantic.net/gpu-server-hosting/gpus-in-cloud-computing-4-cloud-providers-compared/)*** ## Best GPUs for AI in 2024 ### NVIDIA A100 **Specs:** - CUDA Cores: 6,912 - Tensor Cores: 432 - Memory: 80 GB HBM2 - Mixed-Precision Training: FP16, FP32 - Multi-Instance GPU (MIG) Support The NVIDIA A100 is a [GPU for deep learning](https://www.atlantic.net/gpu-server-hosting/gpu-for-deep-learning-critical-specs-and-top-7-gpus-in-2025/) and high-performance computing tasks. Built on NVIDIA’s Ampere architecture, it delivers substantial performance improvements, particularly for AI workloads. Equipped with tensor cores, the A100 accelerates both training and inference, significantly reducing the time required for deep learning computations. It supports mixed-precision training, which optimizes performance without sacrificing accuracy. Its Multi-Instance GPU (MIG) capability allows the A100 to be partitioned into smaller instances. This enables more efficient use of the GPU, allowing multiple tasks to run concurrently, which is particularly beneficial in data center environments. With a memory capacity of up to 80 GB, it can handle massive datasets, making it useful for training complex models. ### NVIDIA RTX A6000 **Specs:** - CUDA Cores: 10,752 - Tensor Cores: 336 - Memory: 48 GB GDDR6 - Memory Bandwidth: 768 GB/s - Deep Learning Support: Mixed-Precision The NVIDIA RTX A6000 is another GPU built on the Ampere architecture, designed for AI and visualization tasks. Its tensor cores enable accelerated deep learning operations, including fast matrix multiplications crucial for AI model training. The RTX A6000 is equipped with 48 GB of GDDR6 memory, providing ample space for handling large datasets and complex models. Its high number of CUDA cores and AI-specific optimizations allow the RTX A6000 to deliver fast training and inference times. Though it’s a professional-grade GPU, its AI-specific features and memory capacity make it an appropriate option for training neural networks and other AI workloads. ### NVIDIA RTX 4090 **Features:** - CUDA Cores: 16,384 - Tensor Cores: N/A - Memory: 24 GB GDDR6X - Memory Bandwidth: 1 TB/s The NVIDIA RTX 4090, while primarily designed for gaming, is also capable of performing deep learning tasks. It boasts a high number of CUDA cores (16,384) and a memory bandwidth of 1 TB/s, enabling it to handle data-intensive AI operations efficiently. With 24 GB of GDDR6X memory, the RTX 4090 can manage small to medium-sized deep learning models, making it a feasible option for individual developers or smaller-scale AI applications. However, it lacks the AI-specific features found in professional GPUs like the A100 and RTX A6000, such as tensor cores optimized for deep learning. While it can be used for AI tasks, it’s less suited for large-scale or highly specialized deep learning workloads compared to NVIDIA’s enterprise GPUs. ### NVIDIA L40S GPU **Specs:** - CUDA Cores: Accelerated FP32 throughput for graphics and compute tasks - Tensor Performance: 1,466 TFLOPS (FP8) - Single-Precision Performance: 91.6 TFLOPS - Memory: 48 GB GDDR6 - Max Power Consumption: 350W The NVIDIA L40S GPU is suitable for AI and data center applications, delivering performance improvements for AI computations and graphics-intensive tasks. Based on the Ada Lovelace architecture, it includes fourth-generation Tensor Cores and a Transformer Engine, which provide enhanced capabilities for deep learning tasks like large language model (LLM) training and inference. With support for FP8 precision and TF32 computations, the L40S ensures fast processing speeds for AI workloads. The L40S also suits multi-workload environments, handling tasks ranging from generative AI to 3D rendering and video processing. Its 48 GB of memory and NVLink technology enable smooth scaling across multiple GPUs. ### NVIDIA H100 NVL **Specs:** - Memory: 94 GB HBM3 - Tensor Cores: Fourth generation, supporting FP8 precision - NVLink Bandwidth: 600 GB/s - PCIe Gen5 support The NVIDIA H100 NVL, part of the Hopper architecture, is purpose-built for large-scale AI training and inference tasks. It delivers 12x higher performance on GPT-3 175B models compared to previous generations. The GPU includes dual GPUs connected via NVLink, offering 188 GB of HBM3 memory, which is essential for massive datasets and training trillion-parameter models. The Transformer Engine leverages FP8 precision, reducing memory consumption. Additionally, the H100 NVL is optimized for large AI clusters, supporting NVLink and PCIe Gen5, which ensure high-speed communication between GPUs. This scalability is useful for distributed AI workloads, making the H100 NVL suitable for enterprises working on large-scale AI systems. ## GPU Features to Consider for AI Workloads ### Total Core Count When selecting a GPU for AI workloads, total core count is a critical factor. A higher number of cores allows for improved parallel processing capabilities, which is essential for efficiently handling the data-intensive calculations involved in AI and machine learning. This translates into faster processing times and the ability to manage larger datasets, enabling more complex models to be developed and refined quickly. A GPU’s core count directly impacts its potential to perform compute-heavy tasks concurrently. The core count also influences how well a GPU can manage diverse AI applications simultaneously. More cores provide the computational headroom needed for multitasking and executing multiple AI models in parallel. For researchers and developers running extensive AI experiments or production-level AI applications, selecting a GPU with a sufficient core count can significantly improve throughput and reduce time to insight. ### Total Memory Total memory on a GPU determines how much data can be stored and processed simultaneously, directly affecting the ability to handle large datasets and complex models in AI workloads. High memory capacity allows for the storage of entire models and their parameters, facilitating more efficient computation and reducing the need for data swapping between the GPU and system memory. This is especially important in deep learning, where model sizes and data volumes can be substantial. A GPU with ample memory supports larger batch sizes during training, enhancing the efficiency of the training process. It also enables the execution of resource-intensive tasks without encountering memory bottlenecks, thus speeding up computations and improving model convergence rates. ### Memory Clock Speed Memory clock speed on a GPU determines the rate at which data is transferred from the GPU’s memory to its cores for processing. Higher clock speeds enable faster data retrieval and processing, crucial for tasks that require quick access to large datasets, such as in AI and machine learning applications. A faster memory clock can significantly increase the throughput of data, optimizing the performance of AI workloads by minimizing delays and enhancing computational efficiency. In scenarios where the GPU frequently alternates between data fetching and processing, having higher memory clock speed can reduce latency and improve overall system responsiveness. This speed is particularly beneficial in real-time AI applications, such as autonomous vehicles and online data analytics, where prompt decision-making is vital. ### AI-Specific Hardware Optimizations AI-specific hardware optimizations in GPUs, such as tensor cores and AI-accelerating algorithms, significantly enhance the performance of machine learning tasks. These optimizations are tailored to the intricate needs of AI workloads, offering capabilities for quicker matrix multiplications and reduced precision computations, which are central to deep learning processes. These dedicated hardware features ensure GPUs efficiently handle the unique complexities involved in training and deploying AI models. Leveraging AI-specific hardware optimizations allows GPUs to achieve higher performance while maintaining improved power efficiency. This balance is crucial in deploying AI models in power-constrained environments like mobile devices or embedded systems. By utilizing these optimizations, developers can focus on model refinement and application innovation, rather than infrastructure limitations. ### GPU Clock Speed GPU clock speed, measured in MHz, dictates how many cycles per second a GPU can execute, affecting its ability to perform calculations. A higher GPU clock speed generally translates to faster processing of individual tasks, resulting in improved performance for AI applications that rely on quick sequential computations. While AI workloads are typically parallelized, having a high clock speed increases performance for tasks that require intensive processing on a single thread. This means the other factors mentioned above are typically more important for AI workload performance than raw GPU clock speed. Optimizing GPU clock speed is essential for maximizing performance in AI training and inference. Faster clock speeds lead to quicker execution of operations, thereby reducing overall processing time for computationally heavy models. This speed enhancement is particularly beneficial in scenarios where time-bound solutions are necessary, such as real-time data processing and interactive AI systems. ## Next-Gen Dedicated GPU Servers from Atlantic.Net, Accelerated by NVIDIA Experience unparalleled performance with dedicated cloud servers equipped with the revolutionary NVIDIA accelerated computing platform. Choose from the NVIDIA L40S GPU and NVIDIA H100 NVL to unleash the full potential of your generative artificial intelligence (AI) workloads, train large language models (LLMs), and harness natural language processing (NLP) in real time. High-performance GPUs are superb at scientific research, 3D graphics and rendering, medical imaging, climate modeling, fraud detection, financial modeling, and advanced video processing. ## [Learn more about Atlantic.net GPU server hosting.](https://www.atlantic.net/gpu-server-hosting/) ### See Additional Guides on Key Machine Learning Topics Together with our content partners, we have authored in-depth guides on several other topics that can also be useful as you explore the world of [machine learning](https://www.tabnine.com/blog/real-world-machine-learning-models-use-cases-operations/). #### [Vector Database](https://www.instaclustr.com/education/vector-database/vector-databases-explained-use-cases-algorithms-and-key-features/) *Authored by Instaclustr* - [[Guide] Top 10 Open Source Vector Databases](https://www.instaclustr.com/education/vector-database/top-10-open-source-vector-databases/) - [[Guide] How a Vector Index Works and 5 Critical Best Practices](https://www.instaclustr.com/education/vector-database/how-a-vector-index-works-and-5-critical-best-practices/) - [[Blog] Apache Cassandra® Compaction Strategies ](https://www.instaclustr.com/blog/apache-cassandra-compaction/) - [[Product] NetApp Instaclustr Data Platform](https://www.instaclustr.com/) #### [Auto Image Crop](https://cloudinary.com/guides/automatic-image-cropping/auto-image-crop-use-cases-features-and-best-practices) *Authored by Cloudinary* - [AI-Based Image Auto-Crop Algorithm Sticks to the Subject](https://cloudinary.com/blog/new_ai_based_image_auto_crop_algorithm_sticks_to_the_subject) - [Auto-Crop Images for Responsive Designs and Higher Quality](https://cloudinary.com/blog/introducing_smart_cropping_intelligent_quality_selection_and_automated_responsive_images) - [Cropping Images in Python With Pillow and OpenCV](https://cloudinary.com/guides/automatic-image-cropping/cropping-images-in-python-with-pillow-and-opencv) #### [AI Infrastructure](https://cloudian.com/guides/ai-infrastructure/ai-infrastructure-key-components-and-6-factors-driving-success/) *Authored by Cloudian* - [AI Infrastructure: Key Components & 6 Factors Driving Success](https://cloudian.com/guides/ai-infrastructure/ai-infrastructure-key-components-and-6-factors-driving-success/) - [AI Storage: Optimized Storage for the AI Revolution](https://cloudian.com/guides/ai-infrastructure/ai-storage-optimized-storage-for-the-ai-revolution/) - [[Product] HyperStore Object Storage ](https://cloudian.com/products/hyperstore/) --- # How to Generate Videos with HuggingFace ModelScope Text2Video Diffusion Model on Atlantic.Net Cloud GPU > URL: https://www.atlantic.net/gpu-server-hosting/how-to-generate-videos-with-huggingface-modelscope-text2video-diffusion-model-on-atlantic-net-cloud-gpu/ | Published: 2025-02-07 | Updated: 2026-05-04 | Author: Hitesh Jethva In the rapidly evolving world of [AI and machine learning](https://www.atlantic.net/gpu-server-hosting/gpu-servers-for-deep-learning-a-practical-guide/), generating videos from textual descriptions is no longer confined to the realms of science fiction. Thanks to advancements in generative models, it is now possible to create detailed, dynamic videos based solely on a few lines of text. One of the most exciting developments in this area comes from HuggingFace’s ModelScope, featuring the Text2Video Diffusion Model. This model leverages the power of diffusion techniques to transform written narratives into captivating visual stories. In this guide, we’ll show you how to use the Text2Video Diffusion Model to generate videos from text. ## Prerequisites Before proceeding, ensure you have the following: - An Atlantic.Net Cloud [GPU server](https://www.atlantic.net/gpu-server-hosting/) running Ubuntu 24.04, equipped with an NVIDIA A100 GPU with at least 20 GB of GPU RAM. - CUDA Toolkit and cuDNN Installed. - Root or sudo privileges. ## Step 1: Install Python and Additional Dependencies The default Python version in Ubuntu 24.04 (Python 3.12) is incompatible with HuggingFace requirements. You’ll need to install Python 3.10: Add the Python repository. ```bash add-apt-repository ppa:deadsnakes/ppa ``` Update the package index. ```bash apt update -y ``` Install Python 3.10 and essential libraries. ```bash apt install python3.10 python3.10-venv python3.10-dev apt install build-essential libssl-dev libffi-dev zlib1g-dev libbz2-dev libreadline-dev libsqlite3-dev wget curl llvm libncurses5-dev libncursesw5-dev xz-utils tk-dev libxml2-dev libxmlsec1-dev liblzma-dev ``` ## Step 2: Install WebUI and ModelScope Install Git LFS for managing large files. ```bash apt install git-lfs -y ``` Initialize Git LFS to use the WebUI and ModelScope repositories. ```bash git lfs install ``` Clone the WebUI repository. ```bash git clone https://github.com/AUTOMATIC1111/stable-diffusion-webui.git ``` Navigate to the new WebUI directory. ```bash cd stable-diffusion-webui ``` Set the WebUI version to 1.7.0, which is compatible with ModelScope. ```bash git reset --hard cf2772f ``` Create a directory structure to set up ModelScope files. ```bash mkdir -p models/ModelScope/t2v ``` Switch to the t2v directory. ```bash cd models/ModelScope/t2v ``` Download the latest ModelScope text-to-video model. ```bash git clone https://huggingface.co/ali-vilab/modelscope-damo-text-to-video-synthesis . ``` ## Step 3: Configure Nginx as a Reverse Proxy to Access WebUI By default, the WebUI is accessible on the localhost port 7860. To access the WebUI from an external network, you must configure Nginx as a reverse proxy. First, install the Nginx web server package. ```bash apt install nginx ``` Next, create an Nginx virtual host configuration file. ```bash nano /etc/nginx/conf.d/webui.conf ``` Add the following configuration. ```bash upstream webui { server 127.0.0.1:7860; } server { listen 80; listen [::]:80; server_name webui.example.com; proxy_set_header Host $host; proxy_http_version 1.1; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header Sec-WebSocket-Extensions $http_sec_websocket_extensions; proxy_set_header Sec-WebSocket-Key $http_sec_websocket_key; proxy_set_header Sec-WebSocket-Version $http_sec_websocket_version; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "Upgrade"; location / { proxy_pass http://webui; } } ``` Save and close the file. Then, verify the Nginx configuration. ```bash nginx -t ``` Output: ```bash nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` Finally, restart the Nginx to apply the changes. ```bash systemctl restart nginx ``` ## Step 4: Configure Stable Diffusion WebUI First, navigate to the stable-diffusion-webui directory. ```bash cd ~/stable-diffusion-webui ``` Then, create a Python virtual environment and activate it. ```bash python3.10 -m venv venv source venv/bin/activate ``` Update pip to the latest version. ```bash pip install --upgrade pip ``` Update the tqdm module required by the WebUI interface to run models. ```bash pip3 install --upgrade tqdm ``` Install Fast API and other libraries. ```bash pip3 install fastapi pip install clip ``` ## Step 5: Run the Stable Diffusion WebUI At this point, your Stable Diffusion WebUI is configured. You can now launch WebUI, which will serve as the interface for video generation. ```bash python3.10 launch.py ``` Wait for the application to fully initialize, which might take several minutes, depending on your system’s performance. You will see the following output after the successful execution. ```bash 100%|███████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 3.97G/3.97G [00:19<00:00, 216MB/s] Calculating sha256 for /root/stable-diffusion-webui/models/Stable-diffusion/v1-5-pruned-emaonly.safetensors: Running on local URL: http://127.0.0.1:7860 ``` ## Step 6: Access WebUI and Generate Videos using ModelScope Open your web browser and access WebUI using the URL **http://webui.example.com.** ![](https://www.atlantic.net/wp-content/uploads/2025/02/p1-2.png) In the main WebUI navigation menu, click on **Extensions** and navigate to the **Available** tab and click **Load from:** to load all available models in the WebUI repository. ![](https://www.atlantic.net/wp-content/uploads/2025/02/p2-1.png) In the search field, type the keyword **modelscope** and press the **Space** button to search an extension. ![](https://www.atlantic.net/wp-content/uploads/2025/02/p3-1.png) Click Install in the **text2video** result action tab to install the **ModelScope** extension. ![](https://www.atlantic.net/wp-content/uploads/2025/02/p4.png) Again search the keyword **“video** **in extras tab**” in the search field. Click **Install** next to the Video in the Extras tab to install the new extension. ![](https://www.atlantic.net/wp-content/uploads/2025/02/p5.png) Once the extension is installed, click **Reload UI** at the bottom of the web page to reload WebUI. ![](https://www.atlantic.net/wp-content/uploads/2025/02/p6.png) Navigate to the **txt2video** tab within the WebUI interface. Select the **ModelScope** as the Model type and enter your desired text prompt in the Prompt field. For example **“children are studying in the classroom”**. Then, click **Generate** and wait for at least 3 minutes for the **ModelScope** generation process to complete. You should see your generated video on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2025/02/p7.png) You can also change your input text prompt to generate a new video using ModelScope per your requirements. ## Conclusion Congratulations! You have successfully installed and configured the HuggingFace ModelScope Text2Video Diffusion Model on an Atlantic Cloud GPU. The process involves setting up a compatible Python environment, managing large files with Git LFS, configuring Nginx for external access, and deploying a complex AI model within a user-friendly web interface. You can now experiment with different prompts, explore various settings within the ModelScope, and continue to refine your approach to produce unique and impactful video content. --- # A Comprehensive Guide to Text-to-Video Generation on Atlantic.Net GPU Servers > URL: https://www.atlantic.net/gpu-server-hosting/a-comprehensive-guide-to-text-to-video-generation-on-atlantic-net-gpu-servers/ | Published: 2025-02-08 | Updated: 2026-05-04 | Author: Hitesh Jethva In the ever-evolving digital media landscape, transforming text into captivating video content is a highly sought-after skill. With the advent of powerful GPU servers, such as those offered by Atlantic.Net, this task has become more accessible. This guide will walk you through setting up and utilizing an Atlantic.Net [GPU server](https://www.atlantic.net/gpu-server-hosting/) to [create videos](https://www.dealfuel.com/blog/best-multimedia-tools/) based on text inputs. By leveraging the NVIDIA A100 GPU’s robust capabilities, users can create high-quality videos quickly and efficiently. ## Prerequisites Before proceeding, ensure you have the following: - An Atlantic.Net Cloud GPU server running Ubuntu 24.04, equipped with an NVIDIA A100 GPU with at least 20 GB of GPU RAM. - CUDA Toolkit and cuDNN Installed. - Root or sudo privileges. ## Step 1: Install Necessary Packages Begin by updating your system’s package list and installing Python, FFmpeg, and Git. ```bash apt update -y apt install python3-full python3-virtualenv ffmpeg git -y ``` ## Step 2: Set Up Python Environment Create and activate a virtual environment that isolates your Python setup and prevents conflicts between project dependencies. Let’s create a virtual environment for your project. ```bash python3 -m venv text2video-env ``` Next, activate the virtual environment. ```bash source text2video-env/bin/activate ``` ## Step 3: Install Python Libraries Install the required Python libraries, including PyTorch, for neural networks. ```bash pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu118 ``` Install additional libraries for AI-driven image generation and video processing. ```bash pip install diffusers transformers accelerate scipy tqdm opencv-python einops moviepy ``` ## Step 4: Create the Python Script Write a Python script named text2video_stablediffusion.py. This script will use AI models to generate video frames from text. Start by importing necessary libraries and initializing key variables: ```bash nano text2video_stablediffusion.py ``` Import the necessary modules. ```bash import os import subprocess import torch from diffusers import StableDiffusionPipeline ``` ## Step 5: Initialize the AI Pipeline Set up the StableDiffusionPipeline, which is essential for transforming text into images. This pipeline is loaded with a pre-trained model optimized for video frame generation: ```bash def main(): # Initialize pipeline pipe = StableDiffusionPipeline.from_pretrained( "CompVis/stable-diffusion-v1-4", torch_dtype=torch.float16 ) pipe.to("cuda") ``` ## Step 6: Define the Video Prompt and Parameters Configure your video by setting the prompt, the number of frames, and the frames per second (FPS): ```bash # Define your prompt prompt = "A surreal painting of a dancing robot in a futuristic city." print(f"Generating frames for prompt: {prompt}") # Directory to store the generated frames frames_folder = "generated_frames" os.makedirs(frames_folder, exist_ok=True) # Number of frames and fps num_frames = 30 # e.g., for 30 frames at 1 second of video fps = 30 ``` ## Step 7: Generate and Save Frames Use the AI model to generate each frame based on the text prompt, modifying the seed for each frame to ensure variation yet maintaining thematic consistency. ```bash # Generate frames for i in range(num_frames): seed = 42 + i generator = torch.Generator("cuda").manual_seed(seed) # Generate one image image = pipe(prompt, guidance_scale=7.5, generator=generator).images[0] # Save frame frame_path = os.path.join(frames_folder, f"frame_{i:03d}.png") image.save(frame_path) # Stitch frames into a video using ffmpeg video_filename = "output_video.mp4" print(f"Combining frames into {video_filename} at {fps} FPS...") ``` ## Step 8: Compile the Video After generating the frames, compile them into a single video file using FFmpeg. This step stitches the images into a flowing video sequence. ```bash subprocess.run([ "ffmpeg", "-framerate", str(fps), "-i", os.path.join(frames_folder, "frame_%03d.png"), "-c:v", "libx264", "-pix_fmt", "yuv420p", video_filename ]) print("Video generation complete.") if __name__ == "__main__": main() ``` Save and close the file. ## Step 9: Execute the Script Run the script to generate the video. ```bash python3 text2video_stablediffusion.py ``` This script will generate a video from the text prompt and save it to the file **output_video.mp4.** ```bash [libx264 @ 0x55cf716f6a40] using cpu capabilities: MMX2 SSE2Fast SSSE3 SSE4.2 AVX FMA3 BMI2 AVX2 [libx264 @ 0x55cf716f6a40] profile High, level 3.0, 4:2:0, 8-bit [libx264 @ 0x55cf716f6a40] 264 - core 164 r3108 31e19f9 - H.264/MPEG-4 AVC codec - Copyleft 2003-2023 - http://www.videolan.org/x264.html - options: cabac=1 ref=3 deblock=1:0:0 analyse=0x3:0x113 me=hex subme=7 psy=1 psy_rd=1.00:0.00 mixed_ref=1 me_range=16 chroma_me=1 trellis=1 8x8dct=1 cqm=0 deadzone=21,11 fast_pskip=1 chroma_qp_offset=-2 threads=4 lookahead_threads=1 sliced_threads=0 nr=0 decimate=1 interlaced=0 bluray_compat=0 constrained_intra=0 bframes=3 b_pyramid=2 b_adapt=1 b_bias=0 direct=1 weightb=1 open_gop=0 weightp=2 keyint=250 keyint_min=25 scenecut=40 intra_refresh=0 rc_lookahead=40 rc=crf mbtree=1 crf=23.0 qcomp=0.60 qpmin=0 qpmax=69 qpstep=4 ip_ratio=1.40 aq=1:1.00 Output #0, mp4, to 'output_video.mp4': Metadata: encoder : Lavf60.16.100 Stream #0:0: Video: h264 (avc1 / 0x31637661), yuv420p(tv, progressive), 512x512, q=2-31, 30 fps, 15360 tbn Metadata: encoder : Lavc60.31.102 libx264 Side data: cpb: bitrate max/min/avg: 0/0/0 buffer size: 0 vbv_delay: N/A [out#0/mp4 @ 0x55cf716f5cc0] video:607kB audio:0kB subtitle:0kB other streams:0kB global headers:0kB muxing overhead: 0.158672% frame= 30 fps=0.0 q=-1.0 Lsize= 608kB time=00:00:00.90 bitrate=5538.0kbits/s speed=1.84x [libx264 @ 0x55cf716f6a40] frame I:2 Avg QP:29.58 size: 20441 [libx264 @ 0x55cf716f6a40] frame P:28 Avg QP:30.96 size: 20731 [libx264 @ 0x55cf716f6a40] mb I I16..4: 6.6% 51.2% 42.2% [libx264 @ 0x55cf716f6a40] mb P I16..4: 7.1% 51.5% 41.2% P16..4: 0.1% 0.1% 0.0% 0.0% 0.0% skip: 0.0% [libx264 @ 0x55cf716f6a40] 8x8 transform intra:51.6% inter:79.0% [libx264 @ 0x55cf716f6a40] coded y,uvDC,uvAC intra: 78.5% 95.0% 77.2% inter: 81.0% 100.0% 59.7% [libx264 @ 0x55cf716f6a40] i16 v,h,dc,p: 32% 28% 3% 37% [libx264 @ 0x55cf716f6a40] i8 v,h,dc,ddl,ddr,vr,hd,vl,hu: 28% 22% 10% 6% 5% 6% 7% 7% 9% [libx264 @ 0x55cf716f6a40] i4 v,h,dc,ddl,ddr,vr,hd,vl,hu: 39% 21% 8% 5% 6% 6% 6% 5% 4% [libx264 @ 0x55cf716f6a40] i8c dc,h,v,p: 33% 23% 32% 12% [libx264 @ 0x55cf716f6a40] Weighted P-Frames: Y:3.6% UV:3.6% [libx264 @ 0x55cf716f6a40] ref P L0: 26.6% 19.4% 22.6% 29.8% 1.6% [libx264 @ 0x55cf716f6a40] kb/s:4970.80 Video generation complete. ``` Download the output_video.mp4 file to your local desktop machine and double-click on it to play the video. ![](https://www.atlantic.net/wp-content/uploads/2025/02/p1-1.png) ## Conclusion Using Atlantic.Net’s GPU servers for text-to-video generation harnesses cutting-edge AI technology to transform simple text descriptions into dynamic visual stories. This process enhances the creative possibilities and streamlines content creation across various digital media platforms. Whether for business or personal projects, integrating text-to-video technology offers a powerful tool for innovative and engaging digital content creation. --- # How to Use Vector Embeddings on Atlantic.Net Cloud GPU > URL: https://www.atlantic.net/gpu-server-hosting/how-to-use-vector-embeddings-on-atlantic-net-cloud-gpu/ | Published: 2025-02-09 | Updated: 2025-02-18 | Author: Hitesh Jethva In today’s data-driven world, vector embeddings have become fundamental in machine learning applications, especially in natural language processing (NLP). Vector embeddings are used in various applications such as semantic search, sentiment analysis, and machine translation. They help capture the semantic meanings of sentences, thus enabling machines to perform tasks that require a deep understanding of human language. Atlantic.Net Cloud GPU provides a robust environment for deploying machine learning models that require high computational power. This article will guide you on how to generate and use vector embeddings using an Atlantic.Net Cloud GPU. ## Prerequisites Before proceeding, ensure you have the following: - An Atlantic.Net Cloud GPU server running Ubuntu 22.04, equipped with an NVIDIA A100 GPU with at least 10 GB of GPU RAM. - CUDA Toolkit and cuDNN Installed. - Root or sudo privileges. ## Step 1: Setting Up Your Environment First, connect to your Atlantic.Net Cloud GPU instance using SSH. Once logged in, you should set up a Python environment. Here’s how you can install the necessary packages: ```bash apt install python3 python3-pip ``` Install PyTorch. ```bash pip3 install torch --index-url https://download.pytorch.org/whl/cu118 ``` Install the sentence-transformer Python framework. ```bash pip3 install sentence_transformers ``` ## Step 2: Creating the Embedding Generation Script Create a Python script named create-embeddings.py that will encode sentences into vector embeddings using the SentenceTransformer model. ```bash nano create-embeddings.py ``` Add the following code: ```bash from sentence_transformers import SentenceTransformer model = SentenceTransformer('all-MiniLM-L6-v2') sentences = [ 'This is sentence 1', 'This is sentence 2', 'This is sentence 3' ] embeddings = model.encode(sentences) for sentence, embedding in zip(sentences, embeddings): print("Sentence:", sentence) print("Embedding:", embedding) print("") ``` In this script, we initialize a pre-trained model **(all-MiniLM-L6-v2),** which is suitable for generating embeddings. The script processes a list of sentences and outputs their corresponding embeddings. Now, run the above script. ```bash python3 create-embeddings.py ``` The output will display the embeddings for each sentence, represented as vectors. These embeddings can be used for further analysis or model training. ```bash -1.81968231e-02 1.34411370e-02 3.34244817e-02 2.00667456e-02 -1.49116814e-02 2.83299759e-02 3.46540324e-02 5.40056638e-02 3.22964322e-03 -3.13563198e-02 -2.74929032e-02 -2.80718114e-02 4.45681438e-03 -2.83749006e-03 3.57951708e-02 4.00369102e-03 3.07004545e-02 3.27301696e-02 9.36542265e-03 3.44577916e-02 1.49957128e-02 8.31826255e-02 3.61972526e-02 9.59376097e-02 -2.22833566e-02 5.62446602e-02 -5.56956753e-02 -7.11603910e-02 7.02162553e-03 -6.63649812e-02 4.74848412e-02 -5.78645468e-02 6.50438573e-03 4.54177819e-02 -4.24348488e-02 6.53610080e-02 -1.88463349e-02 -3.33171338e-02 2.32637711e-02 -3.17560397e-02 -4.93795201e-02 -3.29444744e-02 -5.85382022e-02 -3.99537198e-02 7.91056156e-02 7.39838034e-02 5.14839850e-02 -2.18956899e-02 -4.34886962e-02 1.52404765e-02 -4.13710400e-02 -1.73745619e-03 3.03356256e-02 -1.15166663e-03 2.02252921e-02 -9.41368788e-02] ``` ## Step 3: Calculating Cosine Similarity You can calculate the cosine similarity between their embeddings to understand how similar two sentences are. Create a script named cosine-similarity.py to accomplish this: ```bash nano cosine-similarity.py ``` Add the following code. ```bash from sentence_transformers import SentenceTransformer, util model = SentenceTransformer('all-MiniLM-L6-v2') emb1 = model.encode("This is sentence 1") emb2 = model.encode("This is sentence 2") cos_sim = util.cos_sim(emb1, emb2) print("Cosine-Similarity:", cos_sim) ``` Run the script to see the cosine similarity score, which quantifies the similarity between two sentences. ```bash python3 cosine-similarity.py ``` Output: ```bash Cosine-Similarity: tensor([[0.9145]]) ``` ## Step 4: Finding Top Similar Sentence Pairs Finding the most similar pairs of sentences in a dataset can be crucial for applications like clustering or recommendation systems. Use the following script to find and display the top similar sentence pairs: ```bash nano top-similar-pairs.py ``` Add the following code: ```bash from sentence_transformers import SentenceTransformer, util model = SentenceTransformer('all-MiniLM-L6-v2') sentences = [ 'A man is eating food.', 'A man is eating a piece of bread.', 'The girl is carrying a baby.', 'A man is riding a horse.', 'A woman is playing violin.', 'Two men pushed carts through the woods.', 'A man is riding a white horse on an enclosed ground.', 'A monkey is playing drums.', 'Someone in a gorilla costume is playing a set of drums.' ] embeddings = model.encode(sentences) cos_sim = util.cos_sim(embeddings, embeddings) all_sentence_combinations = [] for i in range(len(cos_sim)-1): for j in range(i+1, len(cos_sim)): all_sentence_combinations.append([cos_sim[i][j], i, j]) all_sentence_combinations = sorted(all_sentence_combinations, key=lambda x: x[0], reverse=True) print("Top-5 most similar pairs:") for score, i, j in all_sentence_combinations[0:5]: print("{} \t {} \t {:.4f}".format(sentences[i], sentences[j], cos_sim[i][j])) ``` This script identifies and lists the top five similar sentence pairs from a predefined list, demonstrating a practical application of vector embeddings in determining text similarity. Now, run the above script. ```bash python3 top-similar-pairs.py ``` Output: ```bash Top-5 most similar pairs: A man is eating food. A man is eating a piece of bread. 0.7553 A man is riding a horse. A man is riding a white horse on an enclosed ground. 0.7369 A monkey is playing drums. Someone in a gorilla costume is playing a set of drums. 0.6433 A woman is playing violin. Someone in a gorilla costume is playing a set of drums. 0.2564 A man is eating food. A man is riding a horse. 0.2474 ``` The above outputs illustrate how vector embeddings and cosine similarity can be used to analyze and quantify the similarity between different texts, which can be crucial for many applications such as search engines, recommendation systems, and more sophisticated NLP tasks. ## Conclusion Using an Atlantic.Net Cloud [GPU server](https://www.atlantic.net/gpu-server-hosting/) to handle vector embeddings allows powerful computational resources to be leveraged to perform intensive machine learning tasks efficiently. The examples here showcase basic operations you can perform with embeddings, from generation to similarity comparison, which is foundational for advanced NLP tasks. --- # AI Generated Images with OpenJourney on Atlantic.Net Cloud GPU > URL: https://www.atlantic.net/gpu-server-hosting/ai-generated-images-with-openjourney-on-atlantic-net-cloud-gpu/ | Published: 2025-02-10 | Updated: 2025-02-18 | Author: Hitesh Jethva Artificial Intelligence (AI) has significantly transformed the creative landscape, enabling the generation of high-quality, lifelike images through models like OpenJourney. Users can efficiently produce AI-generated artwork by leveraging the computational power of cloud-based GPU servers, such as those offered by Atlantic.Net. In this guide, we will set up an environment on an Atlantic.Net Cloud [GPU server](https://www.atlantic.net/gpu-server-hosting/) to generate images using the OpenJourney model. ## Prerequisites Before proceeding, ensure you have the following: - An Atlantic.Net Cloud GPU server running Ubuntu 24.04, equipped with an NVIDIA A100 GPU with at least 20 GB of GPU RAM. - Root or sudo privileges. ## Step 1: Install NVIDIA CUDA Toolkit The CUDA Toolkit is essential for GPU acceleration, providing the necessary libraries and tools for running computations on NVIDIA GPUs. Download and set up the CUDA repository pin. ```bash wget https://developer.download.nvidia.com/compute/cuda/repos/ubuntu2404/x86_64/cuda-ubuntu2404.pin mv cuda-ubuntu2404.pin /etc/apt/preferences.d/cuda-repository-pin-600 ``` Download and install the CUDA repository package. ```bash wget https://developer.download.nvidia.com/compute/cuda/12.8.0/local_installers/cuda-repo-ubuntu2404-12-8-local_12.8.0-570.86.10-1_amd64.deb dpkg -i cuda-repo-ubuntu2404-12-8-local_12.8.0-570.86.10-1_amd64.deb cp /var/cuda-repo-ubuntu2404-12-8-local/cuda-*-keyring.gpg /usr/share/keyrings/ ``` Update the package lists and install the CUDA Toolkit. ```bash apt-get update apt-get -y install cuda-toolkit-12-8 ``` Configure environment variables to locate the CUDA executables and libraries. ```bash echo "export PATH=/usr/local/cuda-12.8/bin${PATH:+:${PATH}}" >> ~/.bashrc ``` Include the CUDA library directory in the LD_LIBRARY_PATH. ```bash echo "export LD_LIBRARY_PATH=/usr/local/cuda-12.8/lib64${LD_LIBRARY_PATH:+:${LD_LIBRARY_PATH}}" >> ~/.bashrc ``` Activate the updated environment variables. ```bash source ~/.bashrc ``` Verify that the GPU is recognized and that the CUDA compiler is installed correctly. ```bash nvidia-smi ``` Output: ```bash Thu Jan 30 11:30:08 2025 +-----------------------------------------------------------------------------------------+ | NVIDIA-SMI 550.90.07 Driver Version: 550.90.07 CUDA Version: 12.4 | |-----------------------------------------+------------------------+----------------------+ | GPU Name Persistence-M | Bus-Id Disp.A | Volatile Uncorr. ECC | | Fan Temp Perf Pwr:Usage/Cap | Memory-Usage | GPU-Util Compute M. | | | | MIG M. | |=========================================+========================+======================| | 0 GRID A100D-20C On | 00000000:06:00.0 Off | 0 | | N/A N/A P0 N/A / N/A | 1MiB / 20480MiB | 0% Default | | | | Disabled | +-----------------------------------------+------------------------+----------------------+ +-----------------------------------------------------------------------------------------+ | Processes: | | GPU GI CI PID Type Process name GPU Memory | | ID ID Usage | |=========================================================================================| | No running processes found | +-----------------------------------------------------------------------------------------+ ``` ## Step 2: Install NVIDIA cuDNN Library The cuDNN library is a GPU-accelerated library for deep neural networks, enhancing the performance of deep learning frameworks. Download and install the cuDNN repository package. ```bash wget https://developer.download.nvidia.com/compute/cudnn/9.7.0/local_installers/cudnn-local-repo-ubuntu2404-9.7.0_1.0-1_amd64.deb dpkg -i cudnn-local-repo-ubuntu2404-9.7.0_1.0-1_amd64.deb cp /var/cudnn-local-repo-ubuntu2404-9.7.0/cudnn-*-keyring.gpg /usr/share/keyrings/ ``` Update the package lists and install cuDNN. ```bash apt-get update apt-get -y install cudnn ``` Check the installed version of cuDNN to ensure it’s correctly set up. ```bash cat /usr/include/cudnn_version.h | grep CUDNN_MAJOR -A 2 ``` Output: ```bash #define CUDNN_MAJOR 9 #define CUDNN_MINOR 7 #define CUDNN_PATCHLEVEL 0 -- #define CUDNN_VERSION (CUDNN_MAJOR * 10000 + CUDNN_MINOR * 100 + CUDNN_PATCHLEVEL) /* cannot use constexpr here since this is a C-only file */ ``` ## Step 3: Set Up Python Environment A dedicated Python environment ensures that dependencies for your project are managed efficiently without conflicts. Install Python 3 and create a virtual environment. ```bash apt install python3-full python3-virtualenv python3 -m venv venv source venv/bin/activate ``` Upgrade pip and install Jupyter Notebook. ```bash pip install --upgrade pip pip install notebook ``` Launch the Jupyter Notebook. ```bash jupyter notebook --no-browser --port=8888 --ip=your-server-ip --allow-root ``` Output: ```bash To access the server, open this file in a browser: file:///root/.local/share/jupyter/runtime/jpserver-7131-open.html Or copy and paste one of these URLs: http://your-server-ip:8888/tree?token=46d4d0af7fd47802a59aa8dce159eafba688b17261592841 http://127.0.0.1:8888/tree?token=46d4d0af7fd47802a59aa8dce159eafba688b17261592841 [I 2025-01-30 11:13:06.976 ServerApp] Skipped non-installed server(s): bash-language-server, dockerfile-language-server-nodejs, javascript-typescript-langserver, jedi-language-server, julia-language-server, pyright, python-language-server, python-lsp-server, r-languageserver, sql-language-server, texlab, typescript-language-server, unified-language-server, vscode-css-languageserver-bin, vscode-html-languageserver-bin, vscode-json-languageserver-bin, yaml-language-server ``` Open your web browser and access the Jupyter Notebook using the URL **http://your-server-ip:8888/tree?token=8e99e04461348b61490e1a51559a8be313840260787e7e17.** ![](https://www.atlantic.net/wp-content/uploads/2025/02/a1.png) Click on **File** > **New** > **Notebook.** You will be asked to select the Kernel. ![](https://www.atlantic.net/wp-content/uploads/2025/02/a2.png) Select the **“Python (GPU)”** kernel and click **Select** to create a new notebook. ## Step 4: Install Required Python Packages To generate images using the OpenJourney model, you’ll need to install several Python libraries that facilitate model loading, data processing, and result visualization. It’s important to run these installation commands within your Jupyter Notebook to ensure the packages are available in that environment. **1. Install PyTorch and torchvision.** PyTorch is a deep learning framework, and torchvision provides access to popular datasets and model architectures. ```bash !pip install torch torchvision --index-url https://download.pytorch.org/whl/cu118 ``` **2. Install the Hugging Face Transformers Library.** The **transformers** library provides general-purpose architectures for natural language understanding and generation. In this context, it supports the integration with the OpenJourney model. ```bash !pip install transformers ``` **3. Install the Diffusers Library:** The **diffusers** library is essential for working with diffusion models like OpenJourney, enabling efficient image generation. ```bash !pip install diffusers ``` **4. Install the Accelerate Library:** The **accelerate** library optimizes the performance of your models, particularly when utilizing GPU resources, ensuring faster computations. ```bash !pip install accelerate ``` **5. Install Matplotlib:** **Matplotlib** is a plotting library used for visualizing data. Here, it will help display the generated images within the Jupyter Notebook. ```bash !pip install matplotlib ``` 6. Install ipywidgets: **ipywidgets** enhances the interactivity of Jupyter Notebooks, allowing for dynamic controls and interactive visualizations. ```bash !pip install ipywidgets ``` ## Step 5: Generate Images Using OpenJourney With the environment set up and the necessary packages installed, you can now generate images using the OpenJourney model. This process involves importing essential libraries, initializing the model, and creating images based on textual prompts. **1. Import the Required Libraries:** Begin by importing the necessary libraries into your Jupyter Notebook. `from diffusers import StableDiffusionPipeline import torch import matplotlib.pyplot as plt` **2. Initialize the OpenJourney Model:** Set up the model to prepare it for image generation. `model_id = "prompthero/openjourney" pipe = StableDiffusionPipeline.from_pretrained(model_id, torch_dtype=torch.float16) pipe = pipe.to("cuda")` **3. Generate an Image from a Text Prompt:** Create an image by providing a descriptive text prompt. `prompt = "green vulture with clouds in the background, mdjrny-v4 style" images = pipe(prompt).images` **4. Display the Generated Image:** Visualize the output within the Jupyter Notebook. ```bash plt.imshow(images[0]) ``` ![](https://www.atlantic.net/wp-content/uploads/2025/02/p1.png) Removes the axis ticks and labels for a cleaner presentation. ```bash plt.imshow(images[0]) plt.axis('off') plt.show() ``` ![](https://www.atlantic.net/wp-content/uploads/2025/02/p2.png) **5. Save Generated Images** Specify the directory where the images will be stored. ```bash save_directory = "/opt" ``` **6. Iterate through the list of images and save each one.** ```bash for i, image in enumerate(images): image.save(f"{save_directory}/image_{i}.png") ``` **7. Generate Multiple Images:** Define the number of images and generate them with new prompts. ```bash num_images = 5 prompt = ["blue vulture with clouds in the background, mdjrny-v4 style"] * num_images image_list = pipe(prompt).images for image in image_list: plt.imshow(image) plt.show() ``` This loop iterates over each image in image_list and displays it using Matplotlib: ![](https://www.atlantic.net/wp-content/uploads/2025/02/p3.png) ## Conclusion Congratulations! You’ve successfully set up an Atlantic.Net Cloud GPU server environment to generate AI-driven images using the OpenJourney model. This process involved installing essential tools like the NVIDIA CUDA Toolkit and cuDNN library, configuring a Python environment with Jupyter Notebook, and utilizing the OpenJourney model to create and save images based on textual prompts. --- # How to Build a Question Answering System on Atlantic.Net Cloud GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-build-a-question-answering-system-on-atlantic-net-cloud-gpu-server/ | Published: 2025-02-11 | Updated: 2025-02-18 | Author: Hitesh Jethva Question Answering (QA) systems transform how users interact with data, allowing them to query information in natural language and get concise, direct answers. Building a QA system has become more straightforward with the wide availability of advanced NLP models and the growing popularity of frameworks like Hugging Face Transformers and OpenAI GPT. This guide will show you how to set up and build a QA system on an Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/). ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 24.04 Cloud GPU Server. - CUDA Toolkit and cuDNN Installed. - Root or sudo privileges. ## Step 1: Install Required Packages Before starting, it is essential to update all system packages to the latest version. ```bash apt update apt upgrade ``` Next, install Python with all required libraries. ```bash apt install python3-full python3-virtualenv -y ``` ## Step 2: Create a Python Virtual Environment A virtual environment isolates your project’s dependencies, ensuring that installed packages don’t interfere with other projects or system-wide packages. Let’s create a new virtual environment for your project. ```bash python3 -m venv venv ``` Activate your virtual environment. ```bash source venv/bin/activate ``` ## Step 3: Install PyTorch with CUDA Support PyTorch is a deep learning framework for model operations. Installing it with CUDA support allows the GPU to be utilized, significantly accelerating computations. ```bash pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu118 ``` Next, install additional libraries for building and deploying the QA system. ```bash pip install transformers datasets fastapi uvicorn ``` - **transformers:** Provides access to pre-trained models and tools from Hugging Face. - **datasets:** Offers a collection of datasets and tools for model evaluation. - **fastapi:** A modern web framework for building APIs with Python. - **uvicorn:** A lightning-fast ASGI server for serving FastAPI applications. Connect to the Python shell and verify that PyTorch is correctly installed. ```bash python3 >>> import torch >>> print(torch.__version__) ``` Output: ```bash 2.6.0+cu118 ``` Confirm that CUDA is available for GPU acceleration. ```bash >>> print(torch.cuda.is_available()) ``` Output: ```bash True ``` Press **CTRL+D** to exit from the Python shell ## Step 4: Create a Basic QA Pipeline In this step, we’ll set up a basic question-answering pipeline using a pre-trained model to understand the foundational workings before any customization. Create a Python script that utilizes a pre-trained model to answer questions based on a provided context. ```bash nano qa_pipeline.py ``` Add the following code: ```bash from transformers import pipeline def main(): # Initialize QA pipeline with a DistilBERT model fine-tuned on SQuAD qa_pipeline = pipeline("question-answering", model="distilbert-base-uncased-distilled-squad") context = ( "Ubuntu is a Linux distribution based on Debian and composed mostly of free and open-source software. " "Ubuntu is officially released in three editions: Desktop, Server, and Core for IoT devices and robots." ) question = "What is Ubuntu based on?" result = qa_pipeline({"context": context, "question": question}) print("Answer:", result["answer"]) print("Score:", result["score"]) if __name__ == "__main__": main() ``` This script uses the Hugging Face pipeline to load a pre-trained QA model and processes a sample context and question. Now, run the above script. ```bash python3 qa_pipeline.py ``` This will display the model’s answer and its confidence score. ```bash Answer: Debian Score: 0.9923 ``` **Explanation:** - **Answer:** The model identifies **“Debian”** as the answer to the question. - **Score:** A confidence score (ranging from 0 to 1) indicating the model’s certainty. A score of **0.9923** signifies high confidence. ## Step 5: Fine-Tune the Model Fine-tuning tailors the pre-trained model to better suit our specific dataset, enhancing its performance on domain-specific questions. Create a script to fine-tune the model using the SQuAD dataset, a widely used benchmark for QA tasks. ```bash nano fine_tuning.py ``` Add the following code. ```bash # fine_tuning.py from datasets import load_dataset from transformers import AutoTokenizer, AutoModelForQuestionAnswering, TrainingArguments, Trainer def prepare_train_features(examples): # 1. Tokenize question + context tokenized_examples = tokenizer( examples["question"], examples["context"], truncation=True, max_length=384, padding="max_length", return_offsets_mapping=True ) # We'll create start_positions and end_positions for each example start_positions = [] end_positions = [] # Loop over each example in the batch for i, offsets in enumerate(tokenized_examples["offset_mapping"]): # Each 'examples["answers"]' is a list of dict for batched data answer = examples["answers"][i] # We take the first answer (SQuAD usually has one per example) answer_start_char = answer["answer_start"][0] answer_text = answer["text"][0] answer_end_char = answer_start_char + len(answer_text) # Initialize start_token_idx = None end_token_idx = None # Find start/end token indices for idx, (start, end) in enumerate(offsets): if start <= answer_start_char < end: start_token_idx = idx if start < answer_end_char <= end: end_token_idx = idx break # Fallback in case we don't find a matching token if start_token_idx is None: start_token_idx = 0 if end_token_idx is None: end_token_idx = len(offsets) - 1 start_positions.append(start_token_idx) end_positions.append(end_token_idx) tokenized_examples["start_positions"] = start_positions tokenized_examples["end_positions"] = end_positions # Remove offset mapping to save memory tokenized_examples.pop("offset_mapping") return tokenized_examples def main(): # 1. Load SQuAD squad = load_dataset("squad") # 2. Set up model/tokenizer model_name = "distilbert-base-uncased" global tokenizer tokenizer = AutoTokenizer.from_pretrained(model_name) model = AutoModelForQuestionAnswering.from_pretrained(model_name) # 3. Preprocess train/validation squad_encoded = squad.map(prepare_train_features, batched=True) # 4. Define training arguments training_args = TrainingArguments( output_dir="./qa_model", per_device_train_batch_size=8, per_device_eval_batch_size=8, num_train_epochs=2, # adjust as needed eval_strategy="epoch", # replaced `evaluation_strategy` with `eval_strategy` save_steps=1000, save_total_limit=1, ) # 5. Initialize Trainer trainer = Trainer( model=model, args=training_args, train_dataset=squad_encoded["train"], eval_dataset=squad_encoded["validation"], ) # 6. Train trainer.train() # 7. Save final model trainer.save_model("./qa_model") print("Fine-tuning complete. Model saved to ./qa_model") if __name__ == "__main__": main() ``` This script loads the SQuAD dataset, preprocesses the data, and fine-tunes the model. Now, run the script to commence the fine-tuning process. ```bash python3 fine_tuning.py ``` During training, you’ll observe outputs indicating the model’s progress, such as: ```bash You should probably TRAIN this model on a down-stream task to be able to use it for predictions and inference. Map: 100%|███████████████████████████████████████████████████████████████████████████████████████████████████████████████| 87599/87599 [00:24<00:00, 3514.81 examples/s] Map: 100%|███████████████████████████████████████████████████████████████████████████████████████████████████████████████| 10570/10570 [00:03<00:00, 3419.28 examples/s] {'loss': 3.2628, 'grad_norm': 23.89510726928711, 'learning_rate': 4.8858447488584476e-05, 'epoch': 0.05} {'loss': 2.3261, 'grad_norm': 13.938529968261719, 'learning_rate': 4.7716894977168955e-05, 'epoch': 0.09} {'loss': 2.0285, 'grad_norm': 20.18623161315918, 'learning_rate': 4.657534246575342e-05, 'epoch': 0.14} {'loss': 1.8877, 'grad_norm': 17.599531173706055, 'learning_rate': 4.54337899543379e-05, 'epoch': 0.18} {'loss': 1.8392, 'grad_norm': 20.058273315429688, 'learning_rate': 4.4292237442922375e-05, 'epoch': 0.23} {'loss': 1.7229, 'grad_norm': 20.78485870361328, 'learning_rate': 4.3150684931506855e-05, 'epoch': 0.27} {'loss': 1.6989, 'grad_norm': 29.019317626953125, 'learning_rate': 4.200913242009132e-05, 'epoch': 0.32} {'loss': 1.6686, 'grad_norm': 20.27025604248047, 'learning_rate': 4.08675799086758e-05, 'epoch': 0.37} {'loss': 1.6013, 'grad_norm': 17.87761878967285, 'learning_rate': 3.9726027397260274e-05, 'epoch': 0.41} {'loss': 1.6066, 'grad_norm': 25.986677169799805, 'learning_rate': 3.8584474885844754e-05, 'epoch': 0.46} {'loss': 1.5666, 'grad_norm': 21.410463333129883, 'learning_rate': 3.744292237442922e-05, 'epoch': 0.5} {'loss': 1.6172, 'grad_norm': 22.285802841186523, 'learning_rate': 3.63013698630137e-05, 'epoch': 0.55} {'loss': 1.5496, 'grad_norm': 22.68842315673828, 'learning_rate': 3.5159817351598174e-05, 'epoch': 0.59} ``` Fine-tuning customizes a pre-trained model to perform better on a specific task by training it on a relevant dataset. In this case, fine-tuning the DistilBERT model on the SQuAD dataset enhances its ability to answer questions accurately within given contexts. ## Step 6: Update the qa_pipeline.py Script to Use the Fine-Tuned Model Open the existing qa_pipeline.py script: ```bash nano qa_pipeline.py ``` Update the script with the following code: ```bash from transformers import pipeline, AutoModelForQuestionAnswering, AutoTokenizer model_path = "./qa_model" tokenizer = AutoTokenizer.from_pretrained(model_path) model = AutoModelForQuestionAnswering.from_pretrained(model_path) qa_pipeline = pipeline("question-answering", model=model, tokenizer=tokenizer) context = "Hugging Face is based in New York and Paris." question = "Where is Hugging Face based?" result = qa_pipeline({"context": context, "question": question}) print(result) # e.g., {'score': 0.95, 'start': 17, 'end': 25, 'answer': 'New York'} ``` Save and close the file. ## Step 7: Deploy the Fine-Tuned Model with FastAPI After fine-tuning our model, the next step is to deploy it so that it can serve real-time predictions. FastAPI is an excellent choice for this purpose due to its high performance and ease of use. Create a Python script named **app.py** to set up our FastAPI application. ```bash nano app.py ``` Add the following code. ```bash # app.py from fastapi import FastAPI from pydantic import BaseModel from transformers import pipeline app = FastAPI() # Load a QA model (pretrained or your fine-tuned one) qa_pipeline = pipeline("question-answering", model="distilbert-base-uncased-distilled-squad") class QAPayload(BaseModel): context: str question: str @app.post("/qa") def get_answer(payload: QAPayload): result = qa_pipeline({"context": payload.context, "question": payload.question}) return {"answer": result["answer"], "score": result["score"]} ``` This script initializes the FastAPI app and sets up an endpoint for our QA model. Start the FastAPI server using Uvicorn. ```bash uvicorn app:app --host 0.0.0.0 --port 8000 ``` Output: ```bash Device set to use cuda:0 INFO: Started server process [14449] INFO: Waiting for application startup. INFO: Application startup complete. INFO: Uvicorn running on http://0.0.0.0:8000 (Press CTRL+C to quit) ``` The above command starts the FastAPI application, making it accessible at **http://0.0.0.0:8000.** ## Step 9: Test the FastAPI Application Testing is crucial to ensure that our API functions as expected. We’ll use the **curl** utility for manual testing. Open another terminal and send a POST request to our /qa endpoint using curl. ```bash curl -X POST "http://localhost:8000/qa" -H "Content-Type: application/json" -d '{ "context": "Ubuntu is a Linux distribution based on Debian", "question": "What is Ubuntu based on?" }' ``` Output: ```bash { "answer": "Debian", "score": 0.9965217709541321 } ``` The model identifies **“Debian”** as the answer to the question. The confidence score (e.g., **0.9965)** indicates the model’s certainty regarding its answer. A score close to **1.0** signifies high confidence. ## Conclusion In this guide, we’ve walked through building a question-answering (QA) system on an Atlantic.Net Cloud [GPU server](https://www.atlantic.net/gpu-server-hosting/), utilizing FastAPI, Hugging Face Transformers, and PyTorch. We began by setting up the necessary environment, installing essential packages, and verifying the installation to ensure our system was ready for development. --- # How to Deploy a Machine Learning Model Using Flask on Atlantic.Net GPU > URL: https://www.atlantic.net/gpu-server-hosting/how-to-deploy-a-machine-learning-model-using-flask-on-atlantic-net-gpu/ | Published: 2025-02-12 | Updated: 2025-02-18 | Author: Hitesh Jethva Deploying a machine learning model is a crucial step to making it accessible to end-users. Flask, a lightweight web framework for Python, is popular for deploying machine learning models due to its simplicity and flexibility. When deploying on an Ubuntu GPU server, you can leverage the power of GPUs to accelerate inference, especially for deep learning models. In this guide, we’ll walk through the steps to deploy a machine learning model using Flask on an Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/). ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 22.04 Cloud GPU Server. - Latest CUDA Toolkit and cuDNN Installed. - Root or sudo privileges. ## Step 1: Update and Install System Dependencies Before starting, it’s essential to update our Ubuntu server to ensure we’re working with the latest security patches and package versions. ```bash apt update -y apt upgrade -y ``` Next, install Python and other dependencies. ```bash apt install python3 python3-pip python3-virtualenv -y ``` ## Step 2: Set Up a Virtual Environment Using a virtual environment helps isolate your project’s dependencies, preventing potential version conflicts with other projects or system Python packages. First, create a Python virtual environment named ml-env: ```bash python3 -m venv ml-env ``` Next, activate the virtual environment. ```bash source ml-env/bin/activate ``` Next, upgrade pip to the latest version. ```bash pip install --upgrade pip ``` Then install Flask and other Python libraries. ```bash pip install flask gunicorn torch torchvision tensorflow numpy pandas ``` ## Step 3: Write and Train a Machine Learning Model Now, let’s create a script called train_model.py that sets up a simple neural network using PyTorch, trains it on dummy data, and saves the model weights. ```bash nano train_model.py ``` Add the following code: ```bash import torch import torch.nn as nn import torch.optim as optim class SimpleModel(nn.Module): def __init__(self): super(SimpleModel, self).__init__() self.fc1 = nn.Linear(4, 64) self.fc2 = nn.Linear(64, 64) self.fc3 = nn.Linear(64, 1) def forward(self, x): x = torch.relu(self.fc1(x)) x = torch.relu(self.fc2(x)) # Using sigmoid for a binary classification output x = torch.sigmoid(self.fc3(x)) return x # Create the model model = SimpleModel() # Define a binary cross-entropy loss and Adam optimizer criterion = nn.BCELoss() optimizer = optim.Adam(model.parameters(), lr=0.001) # Dummy training data: data = torch.rand(100, 4) labels = torch.randint(0, 2, (100, 1), dtype=torch.float32) # Train for 10 epochs for epoch in range(10): optimizer.zero_grad() outputs = model(data) loss = criterion(outputs, labels) loss.backward() optimizer.step() if (epoch+1) % 2 == 0: print(f"Epoch [{epoch+1}/10], Loss: {loss.item():.4f}") # Switch model to evaluation mode (optional but good practice) model.eval() # Save the model's state dict only (recommended approach) torch.save(model.state_dict(), "model_weights.pth") print("Model weights saved to 'model_weights.pth'") ``` This code defines a simple feed-forward neural network using PyTorch, trains it on randomly generated data for **10** epochs using binary cross-entropy loss and the Adam optimizer, and then switches the model to evaluation mode. Finally, it saves the trained model parameters **(state dict)** to the file **model_weights.pth.** Run the above script. ```bash python3 train_model.py ``` Output: ```bash Epoch [2/10], Loss: 0.6822 Epoch [4/10], Loss: 0.6763 Epoch [6/10], Loss: 0.6745 Epoch [8/10], Loss: 0.6731 Epoch [10/10], Loss: 0.6718 Model weights saved to 'model_weights.pth' ``` ## Step 4: Create a Flask API for Model Inference Now, create a **app.py** to loads the same PyTorch model architecture defined earlier, loads the trained model’s weights and creates an endpoint for inference. ```bash nano app.py ``` Add the following code: ```bash import torch import torch.nn as nn import numpy as np from flask import Flask, request, jsonify app = Flask(__name__) ############################################### # 1. Define the EXACT SAME PyTorch architecture ############################################### class SimpleModel(nn.Module): def __init__(self): super(SimpleModel, self).__init__() # Must match your training script's layers: self.fc1 = nn.Linear(4, 64) self.fc2 = nn.Linear(64, 64) self.fc3 = nn.Linear(64, 1) # Single output (e.g. for binary classification) def forward(self, x): x = torch.relu(self.fc1(x)) x = torch.relu(self.fc2(x)) x = torch.sigmoid(self.fc3(x)) return x ########################################################### # 2. Load the PyTorch model state dict (must match architecture) ########################################################### pytorch_model = SimpleModel() pytorch_model.load_state_dict(torch.load("model_weights.pth")) pytorch_model.eval() ########################################################### # 3. Flask endpoint for PyTorch inference ########################################################### @app.route("/predict", methods=["POST"]) def predict(): data = request.get_json() # Convert input to a numpy array of shape [1, 4] since the model expects 4 features input_data = np.array(data["input"]).reshape(1, 4) # PyTorch inference tensor_input = torch.tensor(input_data, dtype=torch.float32) pytorch_output = pytorch_model(tensor_input).detach().numpy().tolist() return jsonify({ "pytorch": pytorch_output }) if __name__ == "__main__": app.run(host="0.0.0.0", port=5000, debug=True) ``` This code uses PyTorch, NumPy, and Flask to define a simple neural network model, load pre-trained weights, and serve predictions through a /predict endpoint. The endpoint accepts JSON input, converts it to a PyTorch tensor, runs inference, and returns the model’s output as JSON. ## Step 5: Run the Flask App Now, run your Flask app with the following command: ```bash python3 app.py ``` You will see the following output: ```bash * Serving Flask app 'app' * Debug mode: on WARNING: This is a development server. Do not use it in a production deployment. Use a production WSGI server instead. * Running on all addresses (0.0.0.0) * Running on http://127.0.0.1:5000 * Running on http://your-server-ip:5000 Press CTRL+C to quit * Restarting with stat * Debugger is active! * Debugger PIN: 125-332-575 ``` ## Step 6: Test the Flask Application Your Flask app is started and running on port 5000. Now, open another terminal and test the API using the curl command: ```bash curl -X POST -H "Content-Type: application/json" -d '{"input":[0.1, 0.2, 0.3, 0.4]}' http://localhost:5000/predict ``` You should receive a JSON response similar to: ```bash { "pytorch": [ [ 0.49628227949142456 ] ] } ``` This value represents the model’s prediction for a binary classification probability (between 0.0 and 1.0). ## Conclusion You have successfully set up a [GPU-enabled Ubuntu server](https://www.atlantic.net/gpu-server-hosting/gpu-servers-for-deep-learning-a-practical-guide/), trained a simple PyTorch model on dummy data, and created a Flask API to serve predictions. This foundational framework can be adapted to more complex architectures or real-world datasets by integrating additional data pipelines and container orchestration tools. --- # The Best GPUs for Scientific Research > URL: https://www.atlantic.net/gpu-server-hosting/the-best-gpus-for-scientific-research/ | Published: 2025-02-13 | Updated: 2025-06-04 | Author: Robert Agar ## **The Best GPUs for Scientific Research** Graphics processing units (GPUs) are used extensively in scientific computing. They provide the power to perform complex calculations and processor-intensive tasks like training machine learning models. Adding virtually any GPU will deliver enhanced computing capabilities to support scientific research. However, the characteristics of a specific graphics processing unit may make it more suitable for handling the large datasets and complex calculations required to run scientific applications effectively. ## **Why Graphics Processing Units Are Used in Scientific Computing** The scientific community utilizes GPUs to provide additional computing power that is unavailable from standard central processing units (CPUs). CPUs are excellent at processing the sequential instructions traditionally used in general computer programming**,**but GPUs are capable of efficiently processing multiple instructions simultaneously to streamline many scientific computing tasks Several factors make GPUs the correct type of processor for scientific computing. GPUs are typically used along with a CPU. The following are the most important reasons for deploying the computing power of GPUs to augment or replace a CPU. ### **Parallel processing capabilities** GPUs are constructed with up to thousands of small processing cores. Unlike CPU cores, which process instructions sequentially, GPU cores can operate on multiple tasks simultaneously. The parallelism provided by GPUs is essential for performing simulations efficiently, optimizing matrix operations, and training deep learning applications. ### **High throughput and enhanced performance** Manufacturers design GPUs with fast memory bandwidth and large memory capacity to limit slow I/O operations. This native memory**,** combined with a GPU’s parallel processing power**,**provides high throughput and enhanced performance. Large-scale calculations necessary for complex simulations can often be parallelized and run more efficiently with GPUs. ### **Scalability** Scientific research addresses complex and large-scale problems that traditional CPUs cannot solve. The scalability available with GPUs enables scientific computing to utilize systems powered by multiple processors for better speed and performance. Cloud providers offer customers dynamically scalable GPU environments to handle intensive computations and large volumes of data. ### **Energy efficiency and cost-effectiveness** A GPU can execute more operations than a CPU while consuming the same amount of power. This feature makes GPUs a logical and economically sound choice for the processing demands of scientific computing. A single GPU can typically outperform a CPU cluster, providing a cost-effective method of accelerating scientific processing. ### **Software support** Developers can create code optimized for GPU hardware due to the availability of CUDA libraries and other software development platforms like OpenCL. Software for specialized scientific fields such as physics or molecular dynamics is often tailored to take advantage of GPU acceleration. ## **Scientific Applications Leveraging the Computing Power of GPUs** The scientific community relies on the processing power and high-performance computing provided by graphical processing units for a wide variety of tasks and applications across numerous fields. The following are examples from some of the scientific disciplines utilizing GPU acceleration to support and streamline research. ### **Machine learning and deep learning** Researchers train machine learning and deep learning models using very large datasets. GPUs can process this large volume of data more efficiently than CPUs and are an integral part of the growth of artificial intelligence applications. Development frameworks like TensorFlow are optimized for GPUs and can significantly reduce the time required to train deep neural networks. Reinforcement learning algorithms used for training deep learning models run faster on GPUs. GPU acceleration is vital for training complex applications leveraging natural language processing (NLP) for speech and image recognition. The parallelism provided by GPUs is essential for the continued development of machine and deep learning applications. ### **Simulations across multiple fields** GPUs’ speed, parallelism, and processing power are essential for running complex simulations in various scientific fields. - Simulations are used to model complex systems and promote research in physics and engineering. Research disciplines leveraging GPU-accelerated simulations include molecular dynamics and computational fluid dynamics. - Astrophysical simulations allow scientists to study complex phenomena like black hole behavior and star formation. - Quantum mechanics uses Monte Carlo simulations to study molecular systems to improve material and drug design. - Biomedical research utilizes simulations for protein structure prediction to study diseases and develop new drugs. ### **Healthcare and medical imaging** The healthcare field in general and medical imaging specifically process large volumes of data to perform research and diagnostics. Medical research benefits from the speed of GPU-accelerated applications, which allow timely and accurate data analysis. GPUs support deep learning models that perform computer-aided diagnosis and automatically detect abnormal conditions such as tumors and fractures. The models minimize diagnostic time and improve patient care. Healthcare providers also use deep learning models running on GPUs for predictive analytics regarding disease progression and patient outcomes. Genomics requires the processing of massive datasets to identify and study DNA sequences. GPUs dramatically speed up this processing, allowing for more efficient and relevant research. ### **Meteorology and climate modeling** Meteorology and climate modeling study highly complex systems that can be significantly affected by slight variations in conditions. GPUs accelerate the simulations used to forecast weather and storm patterns. Large datasets are used for climate models so researchers can evaluate the long-term effects of climate change. ### **Data science and analytics** Data scientists use GPUs to facilitate big data analytics by processing large volumes of information. Analytics platforms like Hadoop have GPU-accelerated versions that take advantage of advanced hardware to simultaneously process data from multiple sources. Big data is the foundation of scientific visualizations across a wide range of fields. ## **Characteristics of the Best GPUs for Scientific Computing** GPUs are complex entities designed to deliver the power required by high-performance computing. Leading manufacturers like NVIDIA, AMD, and Intel differentiate their products with proprietary engineering and distinct architectures. Different GPU models address the needs of distinct user groups, such as gamers, business people, and scientists. The following are some characteristics of a graphics processing unit that make it a good choice to handle scientific computing requirements. ### **Parallel processing capabilities** Parallel processing is essential for many scientific computing applications. Parallelism enables the processing of large data sets or running molecular simulations to be performed more efficiently than with a CPU. In some cases, parallel processing offers the only method of obtaining timely results from scientific calculations. GPUs with many cores are better equipped to manage simultaneous operations and improve processing speed. Generally, more cores equate to enhanced parallelism. However, GPU manufacturers’ architectures may make it difficult to directly compare models based on their number of cores. Users engaged in scientific computing should look to maximize the number of cores when choosing a GPU. ### **GPU memory** High GPU memory bandwidth and memory capacity are essential for processing scientific workloads. Fast memory is critical to support the intensive computations required by simulations such as molecular dynamics or climate modeling. Scientific applications often rely on quickly and efficiently processing massive datasets. Data transfer speed can be dramatically affected by failing to address a GPU’s memory requirements. #### **Memory bandwidth** Memory bandwidth is measured in gigabytes per second (GB/s). Higher bandwidth minimizes bottlenecks and enables data to be efficiently moved in and out of memory. GPUs for scientific workloads should offer high-bandwidth memory such as GDDR6, HBM2, or HBM3. These technologies provide bandwidths ranging from several hundred to thousands of GB/s. #### **Memory capacity** Memory capacity is instrumental in supporting the data parallelism many scientific workloads require. Higher GPU memory capacity allows large datasets to be processed more efficiently and reduces time-consuming I/O operations. GPUs should have a minimum of 24 GB of internal memory for deep learning, medical research, or other scientific endeavors. ### **GPU acceleration** GPU acceleration benefits many types of scientific computing applications. Tensor cores are specialized hardware units designed to accelerate matrix operations. NVIDIA developed and introduced tensor cores and features them in their high-end GPUs. These cores are responsible for the speed demonstrated by GPU-accelerated applications. GPUs equipped with tensor cores are excellent at scientific computing applications relying on matrix-heavy calculations, such as machine learning workflows, training neural networks, and supporting complex simulations. Scientific groups working in these disciplines should consider taking advantage of the GPU acceleration that is possible with tensor cores. ### **Double precision support** Many types of scientific applications require the accuracy of double-precision floating-point arithmetic (FP64). Fields like medical research, scientific visualization, and climate modeling benefit from the enhanced accuracy provided by FP64. All GPUs offer single-precision accuracy (FP32), but GPUs designed for the consumer market may offer weak FP64 support. FP32 calculations are typically faster than FP64 but may not provide the accuracy necessary for a specific workload. GPUs optimized for FP64 performance should be utilized for scientific computing tasks that perform intensive computations like differential equations. NVIDIA and AMD have developed GPU models that optimize FP64 performance. ### **Power efficiency** Scientific computing requires power efficiency and effective thermal management. Workloads like producing complex simulations or computationally intensive calculations can run for long periods of time. A power-efficient GPU improves system stability and minimizes heat generation. Excessive heat can damage hardware and negatively impact system performance. Groups with high performance computing tasks should opt for a modern GPU with native power management features. Additional air or liquid cooling solutions may be necessary for multi-GPU configurations. ### **Scalability** Taking advantage of multi-GPU configurations can improve the performance of scientific computing applications. Complex simulations or tasks involving massive datasets may need more power or memory than a single GPU can provide. Deploying multiple GPUs can substantially reduce the training time of deep learning models. A multi-GPU environment allows more than one GPU to communicate at high speeds for improved system performance. NVIDIA NVLink and the AMD Infinity Fabric support communication between GPU nodes. Scientific computing users should look for scalable GPU models that support distributed environments. ### **Compatible software environment** Scientific computing groups should look for GPUs that integrate with an existing software environment or framework. Familiarity with the framework eliminates a learning curve and streamlines productivity. Teams should ensure the GPUs they select are compatible with their current environment. CUDA from NVIDIA is the leading framework for scientific and high-performance computing. ADM’s ROCm framework is similar to NVIDIA’s CUDA libraries and is gaining popularity for artificial intelligence and scientific applications. Development frameworks like OpenMP and TensorFlow have built-in GPU support. ## **The Best GPU Models for Scientific Computing** GPUs for scientific computing should demonstrate many or all previously discussed characteristics. GPU manufacturers are continuously refining and introducing cutting-edge technology to their products. The best GPU for a specific scientific application today may be surpassed by tomorrow’s innovations. Considering those issues, the following are some of the best GPUs for scientific computing. They are generally the most powerful and advanced devices available from the major GPU manufacturers. ### **NVIDIA GPUs for scientific computing** NVIDIA produces multiple GPUs with the characteristics that make them an excellent choice for scientific computing. #### [**NVIDIA H100 Tensor Core GPU**](https://www.nvidia.com/en-us/data-center/h100/) The H100 Tensor Core GPU is designed for data center use and is built using the Hopper architecture. The device has up to 120 GB of high-speed HBM3 memory and 14,592 CUDA cores to support cutting-edge parallel processing. The H100 supports advanced AI workloads and scientific simulations with 30 TFLOPS performance for FP64 precision calculations. #### **NVIDIA RTX 6000 Ada Generation** This GPU is designed to power AI workflows from desktop workstations. It is built on the NVIDIA Ada Lovelace architecture and combines 142 third-generation RT Cores, 568 fourth-generation Tensor Cores, and 18,176 CUDA cores with 48GB of graphics memory. The GPU delivers excellent graphics, AI, and compute performance to address a wide range of scientific applications. #### [**NVIDIA L40**](https://www.nvidia.com/en-us/data-center/l40/) The NVIDIA L40 features 48 GB of high-speed GDDR6 memory and has 18,176 CUDA cores and 58 Tensor cores to handle scientific applications requiring parallel processing. The L40 is a versatile GPU capable of powering AI and machine learning workflows for business and scientific users. ### **AMD GPUs for scientific computing** AMD’s GPUs utilize a different architecture than NVIDIA. The devices provide parallelism with stream processors rather than CUDA cores. The following models address scientific computing requirements. #### [**AMD Instinct MI250X**](https://www.amd.com/en/products/accelerators/instinct/mi200/mi250x.html) The Instinct MI250X accelerator is designed to supercharge high-performance computing, AI, and scientific workloads. It provides advanced parallelism with 14,080 stream processors (cores) and 128 GB of HBM2 memory. The GPU excels at double-precision math with 220 compute units. #### [**AMD Instinct MI300**](https://www.amd.com/en/products/accelerators/instinct/mi300.html) The Instinct MI300 series accelerators can handle the most demanding scientific workloads. With 304 compute units and up to 256 GB of HBM3 memory, they are equally well-suited for AI and HPC workloads. Memory bandwidth of up to 6 TB/s provides lightning-fast performance for data-intensive applications. ## **Atlantic.Net’s Hosted NVIDIA GPU Solutions** [Atlantic.Net’s hosted NVIDIA GPU solutions](https://www.atlantic.net/gpu-server-hosting/) offer customers versatile systems suitable for scientific computing. Customers can choose from a system built around the NVIDIA H100 NVL GPU or the NVIDIA L40S GPU to power AI and scientific workloads without building an on-premises infrastructure. [Contact us](https://www.atlantic.net/about-us/corporate-contact/) today to start supercharging your scientific computing applications. --- # GPU for 3D Modeling: A Practical Guide > URL: https://www.atlantic.net/gpu-server-hosting/gpu-for-3d-modeling-a-practical-guide/ | Published: 2025-02-14 | Updated: 2025-03-26 | Author: Gilad Maayan ## What Is a GPU for 3D Modeling? Graphics processing units (GPUs) are crucial in 3D modeling applications due to their ability to handle complex mathematical calculations required to render images, animations, and simulations. Unlike CPUs, which manage general-purpose tasks, GPUs excel at parallel processing, making them ideal for rendering tasks in 3D workflows. Modern 3D software leverages GPU capabilities to provide faster rendering times, real-time previews, and smoother interaction with detailed models. In addition to their rendering capabilities, GPUs support various acceleration techniques for 3D modeling. Technologies like shader processing, real-time ray tracing, and AI-based enhancements allow designers to achieve higher levels of realism and efficiency. These features enable more detailed textures, realistic lighting, and dynamic simulations. This is part of a series of articles about GPU applications. ## The Role of GPUs in 3D Workflows ### GPU vs. CPU Rendering [GPU rendering](https://www.atlantic.net/gpu-server-hosting/gpu-for-rendering-how-it-works-top-10-gpus-and-pro-tips/) uses parallel architecture, enabling it to handle thousands of operations simultaneously. This capability dramatically accelerates rendering times compared to CPU rendering. For instance, tasks like real-time visualization and animation playback benefit from GPU rendering, providing smoother and more responsive performance. In contrast, CPU rendering, though slower, offers precise control and is often used for final renders in certain workflows. While GPUs excel in speed, CPUs are crucial for tasks involving complex logic and sequencing. The choice between GPU and CPU rendering often depends on the specific requirements of the project. Many 3D modeling applications now support hybrid rendering, combining the strengths of both processors. ### Benefits of GPU Acceleration GPU acceleration enhances the rendering process by offloading intensive tasks from the CPU to the GPU, significantly reducing rendering times. This efficiency allows designers to iterate quickly, making real-time modifications and visualizations possible. GPU acceleration also improves the quality of renders, enabling advanced graphics features such as detailed textures, complex lighting effects, and dynamic simulations. In addition to rendering, GPU acceleration supports other computationally intensive tasks in 3D modeling, such as physics simulations and AI-based enhancements. By leveraging GPUs, these processes run faster and more efficiently. ## Key Factors in Choosing a GPU for 3D Modeling ### Performance Metrics for 3D Applications When selecting a GPU for 3D modeling, evaluating performance metrics specific to 3D applications is crucial. Key factors include: - **Benchmark scores**: Look for GPUs with high scores in 3D rendering benchmarks like SPECviewperf or OctaneBench, which reflect real-world performance in applications such as Maya, Blender, and 3ds Max. - **Ray tracing capability**: Modern GPUs with dedicated ray tracing cores (e.g., NVIDIA RTX series) provide significant benefits for rendering realistic lighting and shadows in real-time. - **Shader processing power**: A higher number of shader units and higher clock speeds enable more efficient processing of complex visual effects and simulations. ### Video Memory Requirements Video memory (VRAM) is a critical factor in 3D modeling, as it determines the GPU’s ability to handle large models, textures, and scenes: - **Memory capacity**: At least 8GB of VRAM is recommended for most 3D modeling tasks, with 16GB or more ideal for high-resolution rendering, complex simulations, and working with detailed assets. - **Memory bandwidth**: Higher memory bandwidth allows the GPU to access and process data more quickly, which is essential for performance in memory-intensive applications. ### GPU Architecture and Core Count The architecture and core count of a GPU significantly impact its performance in 3D modeling: - **Architecture**: Modern architectures, such as NVIDIA’s Hopper or Blackwell, or AMD’s RDNA 3, offer improved energy efficiency and support for advanced features like hardware-accelerated ray tracing. - **Core count**: A higher number of CUDA cores (NVIDIA) or stream processors (AMD) enhances parallel processing capabilities, crucial for rendering and computational tasks in 3D workflows. ### Budget Considerations Balancing performance and cost is essential when choosing a GPU for 3D modeling: - **Mid-range options**: GPUs like the NVIDIA RTX 4080 or AMD Radeon RX 6700 XT offer good performance for most 3D modeling tasks at a reasonable price. - **High-end options**: For professionals requiring maximum performance, GPUs such as the NVIDIA GeForce RTX 4090 or AMD Radeon RX 7800 XT provide top-tier capabilities but come with a higher cost. **Value for money**: Consider previous-generation GPUs or refurbished models as cost-effective alternatives, such as Radeon RX 6400 or NVIDIA RTX 3060, especially if cutting-edge features are not a priority. ### Tips from the expert: ![Author icon](https://secure.gravatar.com/avatar/eb8695bf1d856d659c4fa98eba9e0c42?s=192&d=mm&r=g) ![Linkedin Icon](https://www.atlantic.net/wp-content/themes/anet/img/cloud/gpu/icon_linkedin.webp) #### Richard Bailey ##### Technical Editor Richard Bailey brings over two decades of IT expertise, from traditional data centers to cutting-edge cloud solutions. As the founder of [turbogeek.co.uk](https://turbogeek.co.uk/) and a seasoned writer, he focuses on delivering authoritative content on our hosting services, HIPAA compliance, and related topics. In my experience, here are tips that can help you better utilize GPUs for 3D modeling: 1. **Leverage GPU partitioning for resource-intensive workflows:** Use GPU virtualization or partitioning (e.g., NVIDIA vGPU or AMD MxGPU) to divide GPU resources across multiple workflows or users. This is especially useful in collaborative environments or when running multiple 3D modeling applications simultaneously. 2. **Fine-tune VRAM allocation for texture-heavy scenes:** Customize texture compression and level-of-detail (LOD) settings to maximize VRAM usage efficiency. By optimizing texture streaming or limiting high-resolution textures to active camera views, you prevent unnecessary memory consumption while maintaining visual quality. 3. **Use AI-powered noise reduction for faster iterations:** Integrate AI denoisers, such as those available in NVIDIA OptiX, into your rendering workflow. These tools can significantly reduce noise in previews, allowing for quick feedback without requiring full-quality renders during the design phase. 4. **Implement GPU overclocking with caution:** For advanced users, safe overclocking can provide noticeable performance gains, especially for real-time previews or complex renders. Use GPU overclocking utilities (e.g., MSI Afterburner) and stress-test thoroughly to ensure system stability. Always monitor thermals to avoid hardware degradation. 5. **Explore GPU-driven procedural modeling tools:** Some 3D tools now use GPU acceleration for procedural generation (e.g., terrain, fluids, or crowds). By offloading procedural algorithms to the GPU, you can create complex simulations or assets faster without slowing down the main workflow. ## GPU Technologies Impacting 3D Modeling The following GPU innovations are valuable for 3D modeling, and you should consider GPUs that offer them: ### Real-Time Ray Tracing Real-time ray tracing enables the simulation of realistic lighting conditions by tracing the path of light as pixels in an image plane, significantly improving visual realism. This technology allows 3D artists to render reflections, refractions, and shadows dynamically, enhancing the depiction of lifelike environments. With GPUs like NVIDIA’s RTX series, real-time ray tracing becomes accessible, allowing designers to visualize and adjust scenes in real-time. ### AI-Accelerated Features AI-accelerated features leverage machine learning to optimize and enhance 3D modeling processes. GPUs equipped with AI capabilities, such as NVIDIA’s Tensor Cores, enable functions like denoising and upscaling, which improve render quality while reducing computational demands. These advancements allow for smarter workflows, such as automated texture generation or predictive modeling. ### Virtual Reality Support GPUs that support virtual reality (VR) provide the computational power necessary to create immersive 3D environments. VR in 3D modeling allows designers to interact with models in a lifelike spatial context. High refresh rates and low latency are critical for VR applications, which modern GPUs deliver, ensuring smooth and realistic virtual interactions crucial for industries ranging from architecture to games development. ## 5 Best Practices for Optimizing 3D Modeling Performance with GPUs ### 1. Keep Drivers Updated Keeping GPU drivers updated is essential for optimal performance and stability in 3D modeling applications. Manufacturers release driver updates to enhance compatibility with software, fix bugs, and improve hardware performance. Regularly updating drivers ensures the GPU can leverage the latest technological advancements and features. However, it’s important to ensure updates are compatible with all software used in the workflow, as some updates may introduce issues with older applications. ### 2. Optimize Software Settings Optimizing software settings can significantly impact GPU performance in 3D modeling tasks. Adjusting rendering preferences, such as enabling GPU acceleration and adjusting anti-aliasing or shadow quality, can improve efficiency and maintain desired output quality. Most 3D applications offer configuration options to balance performance with visual fidelity. Profile management allows users to save preferred settings for different tasks or projects, simplifying future adjustments. ### 3. Manage Power Consumption and Heat Managing power consumption and heat is crucial for maintaining GPU performance and longevity. High-performance GPUs can generate significant heat, impacting stability and lifespan. Implementing effective cooling solutions, such as high-quality fans or liquid cooling systems, helps maintain optimal temperatures during extended use. Software tools for monitoring GPU temperature and adjusting power settings can assist in managing energy use, particularly in mobile workstations. ### 4. Utilize Multiple GPUs Effectively Using multiple GPUs can significantly enhance rendering speed and computational capacity, but it requires careful configuration to achieve optimal results. Ensure software supports multi-GPU setups, as not all applications can effectively leverage additional GPUs. Technologies like NVIDIA NVLink enable better communication between GPUs, improving resource sharing and performance. Balancing workloads across GPUs and configuring drivers and settings appropriately helps maximize the benefits of a multi-GPU system. ### 5. Consider GPU Hosting GPU hosting services provide remote access to high-performance GPUs, offering a cost-effective solution for handling demanding 3D modeling tasks without investing in expensive hardware. These services enable scalability, allowing users to access additional resources as needed and pay only for what they use. By offloading processing to cloud GPUs, hosting services also reduce the need for in-house maintenance and energy consumption. ## Next-Gen Dedicated GPU Servers from Atlantic.Net, Accelerated by NVIDIA Experience unparalleled performance with dedicated cloud servers equipped with the revolutionary NVIDIA accelerated computing platform. Choose from the NVIDIA L40S GPU and NVIDIA H100 NVL to unleash the full potential of your generative artificial intelligence (AI) workloads, train large language models (LLMs), and harness natural language processing (NLP) in real time. High-performance GPUs are superb at scientific research, 3D graphics and rendering, medical imaging, climate modeling, fraud detection, financial modeling, and advanced video processing. [Learn more about Atlantic.net GPU server hosting.](https://www.atlantic.net/gpu-server-hosting/) --- # AI Accelerator vs GPU: 5 Key Differences and How to Choose > URL: https://www.atlantic.net/gpu-server-hosting/ai-accelerator-vs-gpu-5-key-differences-and-how-to-choose/ | Published: 2025-02-15 | Updated: 2025-03-26 | Author: Gilad Maayan ## What Is an AI Accelerator? An AI accelerator is a specialized hardware component that speeds up artificial intelligence workloads, particularly machine learning tasks such as training and inference. These accelerators handle the massive parallel processing demands of AI algorithms, which involve high-dimensional data and complex computations. By optimizing for these specific requirements, AI accelerators boost performance, reduce latency, and enhance efficiency over general-purpose processors. AI accelerators come in various forms, including application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), and dedicated AI chips. Each type offers distinct advantages in terms of speed, power consumption, and cost. They are increasingly integrated into data centers, autonomous vehicles, and edge computing devices to meet the growing demand for AI capabilities across different industry sectors. ## What Is a GPU? A graphics processing unit (GPU) is a specialized processor originally designed to accelerate graphics rendering. GPUs handle the massive parallelism required for processing images and videos due to their ability to perform multiple calculations simultaneously. This attribute also makes them well-suited for scientific computation tasks, including AI and machine learning workloads. GPUs have evolved beyond their initial role in graphics to become a pivotal component for high-performance computing environments. They are extensively used in data-intensive applications, providing significant speed-ups in AI model training and inferencing tasks. With architectures optimized for high throughput, GPUs handle algorithms that require repeated matrix operations, making them an ideal choice for deep learning frameworks. This is part of a series of articles about [GPU for AI](https://www.atlantic.net/gpu-server-hosting/gpu-for-ai-platforms-top-gpus-and-key-features-to-consider/). ## How AI Accelerators Work AI accelerators work by optimizing the execution of specific mathematical operations fundamental to AI workloads, such as matrix multiplications and convolutions. Unlike general-purpose processors, which handle a broad range of tasks, AI accelerators focus on efficiently executing the repetitive and compute-intensive tasks found in machine learning algorithms. At the core, AI accelerators rely on architectures tailored for parallel processing. They often include a large number of processing cores, each capable of performing operations independently. This setup enables simultaneous computation across multiple data streams, which is critical for tasks like training deep neural networks where millions of parameters are updated iteratively. Memory bandwidth is another key feature. AI accelerators are designed with high-speed memory or specialized caches to quickly transfer large datasets needed for computation. By minimizing data movement bottlenecks, these accelerators achieve lower latency and higher throughput. Most AI accelerators incorporate hardware-level optimizations for reduced precision arithmetic, such as 16-bit or 8-bit floating-point calculations, which speed up computations without compromising the accuracy of AI models. These efficiency gains make accelerators indispensable for both training large models and performing real-time inference. ## How GPUs Work GPUs work by leveraging thousands of small, efficient cores optimized for executing multiple operations in parallel. Unlike central processing units (CPUs), which are designed for serial task execution, GPUs excel at parallelism, making them ideal for handling large datasets and performing the same operation repeatedly across data elements. The architecture of a GPU is built around a grid of streaming multiprocessors (SMs), each containing numerous cores. When a task is executed, the GPU breaks it down into smaller sub-tasks called threads. These threads are processed concurrently, allowing the GPU to handle millions of computations at once, which is critical for rendering complex images or training neural networks. Memory access in GPUs is designed to support high-speed data transfer between processing cores and global memory. Features like shared memory and memory coalescing help reduce the latency associated with accessing data, further optimizing performance. In this context, they type of RAM used with the GPU can matter too; SRAM (Static Random Access Memory) can be used as a cache to store frequently accessed data, while HBM (High Bandwidth Memory) is composed of 3D-stacked high bandwidth DRAM (Dynamic Random Access Memory) for processing large amounts of data quickly. GPUs also include specific hardware units like tensor cores (in some models) to accelerate operations common in AI workloads, such as matrix multiplications. These enhancements have made GPUs a versatile tool for both graphics processing and advanced computational tasks, such as simulating scientific phenomena and developing AI models. ### Tips from the expert: ![Author icon](https://secure.gravatar.com/avatar/eb8695bf1d856d659c4fa98eba9e0c42?s=192&d=mm&r=g) ![Linkedin Icon](https://www.atlantic.net/wp-content/themes/anet/img/cloud/gpu/icon_linkedin.webp) #### Richard Bailey ##### Technical Editor Richard Bailey brings over two decades of IT expertise, from traditional data centers to cutting-edge cloud solutions. As the founder of [turbogeek.co.uk](https://turbogeek.co.uk/) and a seasoned writer, he focuses on delivering authoritative content on our hosting services, HIPAA compliance, and related topics. In my experience, here are tips that can help you better navigate the decision between AI accelerators and GPUs: 1. **Consider hybrid deployments for maximum flexibility:** For applications requiring a mix of specialized AI tasks and general-purpose computing, consider deploying both AI accelerators and GPUs. For example, use GPUs during prototyping and AI accelerators for production environments with repetitive inference tasks. 2. **Optimize software to leverage hardware fully:** Ensure your AI workloads are optimized to take full advantage of the specific hardware. For AI accelerators, this might mean rewriting algorithms to align with their unique architectural features. On GPUs, leverage frameworks like CUDA or ROCm for tailored performance boosts. 3. **Benchmark using real-world workloads:** Before making a decision, benchmark both AI accelerators and GPUs using datasets and AI models that closely resemble your actual production environment. Synthetic benchmarks often fail to capture real-world performance nuances. 4. **Account for hardware lifespan and upgrade cycles:** AI accelerators may have a shorter shelf life due to their task-specific designs becoming obsolete as AI models evolve. GPUs, being more general-purpose, may remain useful for a wider range of tasks over a longer period, reducing hardware churn. 5. **Plan for AI model evolution:** AI models evolve rapidly, often requiring new types of operations. While GPUs are more adaptable to such changes, AI accelerators may require hardware or firmware upgrades to support new features. Plan for this eventuality in your infrastructure strategy. ## AI Accelerators vs. GPUs: Key Differences ### 1. Architecture and Design The architecture of AI accelerators is built for processing deep learning models, enabling efficient matrix operations and data movement. They frequently use customized hardware paths for specific AI tasks, reducing data handling latency. The design prioritizes throughput and computational density, which are critical for AI workloads. In contrast, GPU design leverages general-purpose cores optimized for parallel processing, applicable across various domains. Their architecture includes large numbers of smaller cores compared to CPUs, providing a balanced mix of flexibility and performance. By supporting diverse operations, GPUs facilitate different computational tasks within the same hardware platform, maintaining greater adaptability than AI-specific designs. ### 2. Optimization Goals AI accelerators focus on reducing power consumption and latency while maximizing the throughput of AI operations. Such optimization targets ensure the execution of machine learning models with minimal resource expenditure. The dedicated hardware paths and specialized processing units allow AI accelerators to achieve these goals effectively. Conversely, GPUs aim to deliver broad performance improvements across multiple tasks with a strong emphasis on enhancing data parallelism. The optimization strategies employed in GPUs prioritize overall computational throughput and flexibility, maintaining efficiency across a wider range of applications rather than focusing exclusively on AI tasks. ### 3. Performance Characteristics AI accelerators exhibit high performance in handling specific AI workloads, characterized by their ability to operate efficiently with low power consumption. This performance stems from their specialized architecture, designed to execute AI tasks swiftly. The accelerators achieve significant gains in speed and efficiency when processing machine learning inference or training data. GPUs, while also offering strong performance, differ by their broad application versatility. They provide excellent throughput for AI tasks but may underperform compared to specialized AI accelerators when it comes to power efficiency. However, the flexibility of GPUs ensures they remain an appealing choice for projects requiring a mix of AI and other computational tasks. ### 4. Flexibility AI accelerators are often less flexible than GPUs, as they are engineered towards specific tasks relevant to AI workloads. Their fixed-function hardware allows for superior efficiency but limits adaptability to new algorithms or non-AI tasks. This characteristic confines their use to environments where tasks are well-known and changes infrequent. GPUs, conversely, offer high flexibility due to their programmability, which enables adaptation to a wide variety of tasks beyond AI. Their architecture is suitable for diverse applications, accommodating changes in workloads or computational requirements. This makes GPUs an ideal choice for research and development settings or where computational needs are evolving. ### 5. Cost and Availability AI accelerators often represent higher upfront costs, given their specialized nature, but can offer savings over time through efficiency and reduced energy usage. They are particularly cost-effective in environments with high volumes of repetitive AI tasks, where their performance and efficiency are maximized. GPUs are widely available and tend to have lower initial costs given their broad consumer market presence. This availability makes them accessible to various sectors ranging from individual developers to large enterprises. While they may not match the efficiency of dedicated AI accelerators, the flexibility and lower barrier to entry make GPUs a popular choice across industries. ## Considerations for Choosing Between AI Accelerators and GPUs When selecting between AI accelerators and GPUs, it is important to evaluate various factors to ensure the chosen hardware aligns with your specific requirements. Below are key considerations to guide this decision: - **Assess computational requirements:** Determine the complexity and scale of your AI workloads. AI accelerators are ideal for tasks requiring high efficiency in executing specific operations like matrix multiplications, while GPUs provide versatility for broader computational needs. If your use case involves general-purpose processing in addition to AI tasks, GPUs may be a better choice. - **Evaluate energy efficiency:** Consider the energy consumption of the hardware. AI accelerators are typically optimized for lower power usage during AI-specific tasks, making them suitable for energy-sensitive environments like edge devices. GPUs, while more flexible, may consume more power due to their general-purpose architecture. - **Consider scalability needs:** Examine how well the hardware scales with growing workload demands. AI accelerators often excel in large-scale deployments where they can process high volumes of repetitive tasks efficiently. GPUs, with their programmability, may offer better scalability for diverse or evolving workloads. - **Analyze total cost of ownership:** Factor in both the initial investment and long-term operational costs. AI accelerators might have higher upfront costs but can deliver savings through energy efficiency and faster processing for specific AI applications. GPUs may have a lower initial cost but could incur higher operational expenses due to greater power consumption. - **Examine software and ecosystem support:** Evaluate the availability of software frameworks and tools compatible with the hardware. AI accelerators may have limited but highly optimized software ecosystems tailored for specific tasks, while GPUs benefit from extensive support for widely used AI frameworks like TensorFlow and PyTorch, making them easier to integrate into diverse workflows. ## Next-Gen Dedicated GPU Servers, Powered by NVIDIA and Atlantic.net Experience unparalleled performance with dedicated cloud servers equipped with the revolutionary NVIDIA accelerated computing platform. Choose from the NVIDIA L40S Tensor Core GPU and NVIDIA H100 NVL GPU to unleash the full potential of your generative artificial intelligence (AI) workloads, train large language models (LLMs), and harness natural language processing (NLP) in real time. High-performance GPUs are superb at scientific research, 3D graphics and rendering, medical imaging, climate modeling, fraud detection, financial modeling, and advanced video processing. [Learn more about Atlantic.net GPU server hosting](https://www.atlantic.net/gpu-server-hosting/) --- # Hopper GPU Architecture: Key Innovations and Technical Features > URL: https://www.atlantic.net/gpu-server-hosting/hopper-gpu-architecture-key-innovations-and-technical-features/ | Published: 2025-02-16 | Updated: 2025-03-26 | Author: Gilad Maayan ## What Is the NVIDIA Hopper GPU Architecture? The NVIDIA Hopper GPU architecture is a graphics processing unit design. Named after computing pioneer Grace Hopper, this architecture focuses on accelerating artificial intelligence (AI) and high-performance computing (HPC) tasks. It handles complex calculations with improved speed, making it appropriate for data centers and AI researchers. In the NVIDIA Hopper architecture, several key innovations improve performance. It improves tensor cores for better matrix operations, which are crucial for training deep neural networks. This architecture handles the demands of contemporary AI workloads, offering a framework to meet the increasing computational challenges found in cutting-edge applications. NVIDIA H100 Tensor Core and the newer H200 GPUs are based on the Hopper architecture. This helps them achieve significantly faster performance for AI inference and training compared to the previous generation. ## Key Innovations in the Hopper Architecture This design introduces several new capabilities that go beyond NVIDIA’s previous architecture, Ampere: ### Transformer Engine and FP8 Precision The transformer engine within the Hopper architecture introduces floating point 8-bit (FP8) precision, a feature for accelerating deep learning processes. FP8 precision allows computations to be executed faster without significant loss of accuracy, optimizing the throughput for AI training tasks. This adjustability in precision helps adapt workloads to the needed precision dynamically, improving speed and resource efficiency. The transformer engine’s design improves deep learning workloads by providing specialized capabilities that match the processing demands of modern AI models. It supports operations crucial for AI training, such as transformer-based model execution. ### New DPX Instructions for Dynamic Programming Hopper’s new DPX instructions optimize dynamic programming workloads, commonly found in algorithms like sequence alignment or operations in bioinformatics. These instructions enable more efficient execution of complex computations by increasing parallelism and reducing processing time. With these improvements, developers can tackle larger datasets and more complex algorithms without proportionally increasing computational resources. This makes the Hopper architecture particularly beneficial for industries that rely on data-intensive computations, ensuring faster processing times and increased throughput across varied applications. ### Enhanced Streaming Multiprocessor Design The improved streaming multiprocessor (SM) design in the NVIDIA Hopper architecture delivers higher throughput and energy efficiency. This design optimizes the execution of parallel workloads by increasing the number of concurrently processed threads. Additionally, improvements in the scheduling algorithms enable more efficient resource utilization in the GPU. These advancements support a broader array of applications and workloads, ensuring that the Hopper architecture can handle various computation tasks. This design also provides better power efficiency, reducing the energy consumption per computation. ## Hopper Architecture: Memory Hierarchy Enhancements There are a few ways the Hopper architecture improves memory management to boost GPU performance: ### High-Bandwidth HBM3 Memory The Hopper architecture integrates high-bandwidth memory 3 (HBM3), offering substantial memory bandwidth improvements. This enhancement significantly accelerates data throughput, ensuring faster access to large datasets, which is vital for AI and HPC applications. HBM3 allows the GPU to process data more quickly, reducing latency and improving performance. These improvements are crucial for applications that require large-scale data processing and complex computations. By minimizing memory bottlenecks and providing a larger bandwidth for data transfer, the Hopper architecture can tackle more demanding workloads, making it suitable for AI research and development tasks. ### L1 and L2 Cache Improvements Cache performance is improved in the Hopper architecture with L1 and L2 cache improvements, increasing the speed of data retrieval from memory. This boost in cache efficiency helps in reducing latency and improving the performance of compute-intensive tasks. The upgraded cache hierarchy ensures that frequently accessed data is more readily available, reducing the need for repeated data fetches from distant memory sources. These cache improvements help optimize the performance of AI and HPC workloads where rapid data access and high-speed processing are essential. With a more efficient cache design, Hopper can deliver quicker execution of complex algorithms, improving the throughput and performance of GPU-dependent tasks. ### Distributed Shared Memory NVIDIA Hopper introduces advancements in distributed shared memory, enabling more efficient resource sharing among GPU nodes. This feature allows for improved scalability when deploying multiple GPUs, essential for handling large datasets across distributed systems. By improving memory coherence and synchronization, it supports seamless data exchange and processing across clustered GPUs. This shared memory model is crucial for applications requiring multi-GPU support, such as large-scale simulations and AI model training. By ensuring efficient data distribution and access among GPUs, the Hopper architecture improves reduces the overhead associated with inter-GPU communication in distributed environments. ### Tips from the expert: ![Author icon](https://secure.gravatar.com/avatar/eb8695bf1d856d659c4fa98eba9e0c42?s=192&d=mm&r=g) ![Linkedin Icon](https://www.atlantic.net/wp-content/themes/anet/img/cloud/gpu/icon_linkedin.webp) #### Richard Bailey ##### Technical Editor Richard Bailey brings over two decades of IT expertise, from traditional data centers to cutting-edge cloud solutions. As the founder of [turbogeek.co.uk](https://turbogeek.co.uk/) and a seasoned writer, he focuses on delivering authoritative content on our hosting services, HIPAA compliance, and related topics. In my experience, here are tips that can help you better utilize the NVIDIA Hopper GPU architecture for maximum performance and efficiency: 1. **Develop custom precision strategies beyond FP8 and FP16:** While FP8 and FP16 precision are key features of Hopper, consider hybrid precision strategies where FP8 is used for less sensitive computations and higher precision (e.g., FP32 or FP64) is reserved for critical parts of the workload. This approach can maximize accuracy without compromising performance. 2. **Use mixed memory models to reduce overhead:** Take advantage of Hopper’s HBM3 memory for bandwidth-intensive workloads while offloading lower-priority data to local caches or system memory. Combining these memory layers effectively can reduce contention and boost overall performance in mixed workload environments. 3. **Implement tensor core-specific optimizations:** Hopper’s improved tensor cores thrive on matrix-heavy operations. Restructure AI workloads to use matrix multiplications (GEMMs) where possible, even if it means redesigning parts of the algorithm, to maximize tensor core utilization. This is particularly relevant for transformer models. 4. **Profile workloads for cache efficiency:** Use tools like NVIDIA Nsight Systems and Nsight Compute to identify how workloads interact with the enhanced L1 and L2 caches. Fine-tune algorithms to reuse data in cache as much as possible, reducing expensive memory fetches from HBM3. 5. **Leverage asynchronous execution with DPX instructions:** Use Hopper’s DPX instructions in conjunction with asynchronous compute streams. This allows dynamic programming tasks to overlap computation and data transfer, further reducing execution time for bioinformatics, genomics, or sequence alignment workloads. ## Hopper Architecture: Advanced Interconnect Technologies Here are a few ways the Hopper architecture innovates on data transfer within and between GPUs: ### Fourth-Generation NVLink The fourth-generation [NVLink](https://www.atlantic.net/gpu-server-hosting/nvidia-nvlink-how-it-works-use-cases-and-critical-best-practices/) within the Hopper architecture provides improved connectivity between GPUs, offering significantly higher bandwidth and transfer speeds. It ensures faster data sharing between GPUs, crucial for applications requiring high-speed communication like AI training and HPC simulations. NVLink also reduces bottlenecks in multi-GPU setups. ### NVLink Switch System The NVLink switch system further extends NVIDIA’s interconnect capabilities, allowing for more flexible and scalable GPU topologies. This innovation connects multiple GPUs within a system, enabling greater data throughput. By allowing dynamic GPU configurations, this technology supports a broader range of computation environments and workloads. ### PCIe Gen 5 Support Hopper architecture incorporates PCIe Gen 5 support, boosting peripheral connectivity speeds. PCIe Gen 5 offers double the data rate of its predecessor, allowing for faster data transfer between the GPU and other system components. This is particularly crucial for applications requiring rapid data movement between storage, memory, and computational elements. ## Hopper vs. Ampere Architecture The NVIDIA Hopper architecture builds upon the strengths of the previous Ampere architecture, introducing several key improvements to meet the growing demands of AI and HPC workloads. Below is a summary of the key differences and improvements that set Hopper apart: 1. **Performance Improvements** Hopper outperforms Ampere with a new focus on optimized AI and HPC tasks. The inclusion of the transformer engine and FP8 precision enables Hopper GPUs to execute deep learning tasks faster and with greater efficiency. By contrast, Ampere primarily relied on FP16 precision, which, while powerful, lacked the dynamic adaptability that FP8 precision offers in Hopper. In addition, the improved tensor cores in Hopper deliver better performance for matrix operations, making it more suitable for modern AI models. This improvement significantly improves throughput for training and inference workloads, especially for large-scale transformer models. 1. **Memory Architecture Enhancements** Hopper introduces HBM3 memory, which provides substantially higher bandwidth than the HBM2 memory used in Ampere. This enhancement allows Hopper GPUs to handle larger datasets and more complex computations with reduced latency. Hopper’s L1 and L2 cache improvements further reduce memory access times, ensuring faster data retrieval than Ampere. The distributed shared memory advancements in Hopper also set it apart. This feature improves scalability and multi-GPU resource sharing, which was more limited in Ampere’s architecture. 1. **Interconnect Technologies** Hopper’s fourth-generation NVLink and NVLink switch system represent a significant upgrade over Ampere’s NVLink. These advancements provide higher data transfer speeds and improved flexibility in multi-GPU setups, making Hopper more adept at scaling for large AI workloads. Additionally, Hopper’s support for PCIe Gen 5 ensures faster peripheral data transfer, whereas Ampere supports PCIe Gen 4, which offers comparatively lower throughput. 1. **Dynamic Programming and Specialized Workloads** The introduction of DPX instructions in Hopper allows it to efficiently handle dynamic programming problems, a capability that Ampere lacks. This feature makes Hopper more suitable for specialized workloads, such as bioinformatics and complex algorithmic computations. 1. **Energy Efficiency** Hopper’s improved streaming multiprocessor design increases performance and reduces energy consumption per computation. This efficiency improvement ensures better sustainability and lower operational costs, particularly in large-scale data centers, compared to Ampere. ## Best Practices for Utilizing Hopper GPUs Here are some of the ways to ensure the most effective use of Hopper infrastructure. ### 1. Optimizing for FP8 Precision To fully leverage the capabilities of Hopper GPUs, developers should optimize their workflows for FP8 precision, which accelerates performance without compromising accuracy significantly. By adjusting models and algorithms to utilize FP8 operations, developers can achieve faster execution times, maximizing the computational benefits integral to Hopper’s design. This optimization requires careful consideration of precision requirements for each task, ensuring that the benefits of reduced data size do not impact model performance detrimentally. Developers should explore training regimes that exploit FP8 precision for efficient model training and inference, utilizing Hopper’s full potential for improved speed and reduced processing load. ### 2. Leveraging DPX Instructions Utilizing Hopper’s DPX instructions effectively requires an understanding of their application in dynamic programming problems. Developers should integrate these instructions into algorithms that benefit from increased parallelism and computational efficiency. This integration improves performance in areas such as bioinformatics and other scientific computations relying heavily on dynamic programming. By tailoring workloads to utilize these instructions, developers can significantly reduce processing times and improve resource utilization. This practice ensures optimal GPU performance in complex computational scenarios, allowing for broader applicability and efficiency in applications demanding high-speed data processing and analysis. ### 3. Maximizing Memory Bandwidth Utilization To capitalize on the high-bandwidth offerings of Hopper GPUs, developers should focus on optimizing memory access patterns within their applications. Efficient use of the available bandwidth ensures quicker data transfer and minimizes performance bottlenecks. By parallelizing data processing and ensuring coalesced memory accesses, developers can exploit the full potential of the GPU’s memory architecture. Implementing caching strategies and minimizing memory latency are vital for maximizing throughput. Developers should design algorithms that complement the GPU’s memory hierarchy to achieve high performance in data-intensive operations, ensuring that the Hopper architecture is used to its utmost potential in handling large-scale datasets efficiently. ### 4. Efficient Multi-GPU Scaling with NVLink For effective multi-GPU scaling, developers should leverage NVLink technology to interconnect GPUs, enabling distributed computational tasks to run more smoothly. By utilizing NVLink for data sharing, developers can achieve high-speed inter-GPU communication, minimizing the overhead that often plagues multi-GPU setups. This strategy includes designing applications that benefit from parallel execution across multiple GPUs, distributing workloads to maximize resource efficiency. By ensuring that applications are well-suited for distributed environments with Hopper’s NVLink capabilities, developers can scale their solutions, supporting larger datasets and more complex computations. ### 5. Updating Software for New Hopper Features Developers must update their software solutions to integrate the new features provided by the Hopper architecture. This includes adopting the latest CUDA enhancements and optimizing algorithms for new precision and processing capabilities. Keeping software in line with these advancements ensures optimal performance and full use of the GPU’s capabilities. Regular updates and testing are necessary to maintain compatibility and leverage performance improvements. By maintaining an agile development approach, developers can swiftly incorporate new techniques and strategies to stay ahead of evolving computational demands, maximizing the benefits of NVIDIA’s latest innovations in AI and HPC applications. ## **Next-Gen Dedicated GPU Servers from Atlantic.Net, Accelerated by NVIDIA** Experience unparalleled performance with dedicated cloud servers equipped with the revolutionary NVIDIA accelerated computing platform. Choose from the NVIDIA L40S GPU and NVIDIA H100 NVL to unleash the full potential of your generative artificial intelligence (AI) workloads, train large language models (LLMs), and harness natural language processing (NLP) in real time. High-performance GPUs are superb at scientific research, 3D graphics and rendering, medical imaging, climate modeling, fraud detection, financial modeling, and advanced video processing. [Learn more about Atlantic.net GPU server hosting](https://www.atlantic.net/gpu-server-hosting/) --- # GPU Servers for Deep Learning: A Practical Guide > URL: https://www.atlantic.net/gpu-server-hosting/gpu-servers-for-deep-learning-a-practical-guide/ | Published: 2025-02-17 | Updated: 2025-03-26 | Author: Gilad Maayan ## What Is a GPU Server? A GPU server is a high-performance computing system to handle tasks requiring intensive parallel processing. Unlike traditional CPU-based servers, GPU servers integrate one or more Graphics Processing Units (GPUs) to accelerate complex computations, particularly those involving large datasets and intricate mathematical operations. These servers are commonly used in fields such as artificial intelligence (AI), scientific research, and video rendering, where processing speed and efficiency are critical. The architecture of a GPU server allows it to perform thousands of operations simultaneously, making it ideal for tasks like deep learning, data analytics, and high-performance simulations. By offloading computationally demanding tasks to GPUs, these servers free up CPUs to manage other system processes, resulting in improved performance and resource utilization. ## Why Are GPUs Essential for Deep Learning? The role of GPU servers in deep learning lies in their ability to manage numerous operations simultaneously, drastically reducing the time needed for training deep learning models. Here are the key reasons why GPU servers are becoming popular in deep learning applications: - **Parallel processing capabilities:** GPUs can handle thousands of threads simultaneously. Deep learning algorithms often require the execution of multiple operations at once, and GPU architecture allows for dividing large computational jobs into smaller, more manageable tasks that can be processed concurrently. - **Efficient matrix and tensor computations:** Deep learning models rely heavily on operations involving matrices and tensors. GPUs execute these mathematical computations more efficiently than CPUs. Their architecture supports the rapid execution of linear algebra operations, required for neural network training. - **Speed improvements for training large models:** Training large models demands significant computational resources and time. GPUs markedly reduce training durations through their high processing power and specialized capabilities. The hardware acceleration provided by GPUs allows for faster data throughput and quick execution of complex algorithms. ## Key Specifications of a GPU Server for Deep Learning For deep learning applications, it is crucial to select GPU servers with the right specifications. Here are the key specifications of GPU servers that you must keep in mind. ### 1. GPU Type and Quantity Choosing the right GPU type and quantity is the cornerstone of an effective deep learning server. High-performance GPUs, such as NVIDIA’s A100 or the newer A200, are specifically designed for AI and machine learning tasks, offering features like Tensor Cores that accelerate deep learning computations. The number of GPUs in a server also directly impacts its processing capability; more GPUs mean higher parallelism and faster model training. For most deep learning applications, a **minimum of four to eight GPUs** is recommended, though this can vary depending on the scale and complexity of the projects. It’s essential to balance the GPU count with other hardware components to avoid bottlenecks and ensure efficient resource utilization. It’s also important to ensure the system uses a fast inter-GPU networking technology, such as NVIDIA NVLink. ### 2. Memory Capacity Memory capacity on the GPU, often referred to as VRAM, is crucial for handling large datasets and complex models. Insufficient GPU memory can lead to issues like memory overflow, which forces models to be broken into smaller, less efficient batches. Modern GPUs offer significant VRAM, often ranging **from 16GB to 80GB**, which is necessary for training large-scale neural networks. In addition to GPU memory, system RAM is also important. Deep learning tasks typically require substantial system memory to store datasets and manage operations. A configuration with at least **128GB of system RAM** is advisable for most deep learning workloads, ensuring smooth data processing and transition between CPU and GPU. ### 3. CPU Type and Core Count While GPUs handle the bulk of the computational load in a deep learning server, CPUs play a crucial role in managing and orchestrating tasks. A multicore CPU with high clock speeds is essential for preprocessing data, managing I/O operations, and coordinating communication between GPUs. CPUs with a higher core count and features like hyper-threading can significantly enhance server performance by efficiently managing simultaneous operations. It’s important to match the CPU capability with the number of GPUs to prevent bottlenecks. For instance, a server with multiple GPUs should be paired with a high-performance CPU, such as those from the AMD EPYC or Intel Xeon series, which offer the scalability and reliability needed for heavy computational workloads. ### 4. Storage Type and Capacity Storage in a deep learning server must be both high-capacity and high-speed to accommodate large datasets and ensure quick data access. Solid-state drives (SSDs) are preferred over traditional hard drives due to their superior read/write speeds, which drastically reduce data loading times. NVMe SSDs, in particular, provide the bandwidth and low latency required for intensive data-driven applications. For most deep learning projects, a **minimum of 2TB of storage** is recommended, with scalability options to expand as data requirements grow. Additionally, implementing a hybrid storage solution that combines SSDs for active datasets and HDDs for long-term storage can provide an efficient and cost-effective approach. ### 5. Networking High-performance networking is essential for GPU servers, especially when dealing with distributed deep learning systems that require communication between multiple servers. Fast network interfaces, such as 10GbE or 25GbE ports, enable quick data transfer, minimizing latency and maximizing throughput in multi-server configurations. Technologies like InfiniBand are also beneficial for deep learning environments that require low-latency communication. These networking solutions help in maintaining efficient data flow, which is crucial for real-time processing and collaboration in large-scale AI projects. ### Tips from the expert: ![Author icon](https://secure.gravatar.com/avatar/eb8695bf1d856d659c4fa98eba9e0c42?s=192&d=mm&r=g) ![Linkedin Icon](https://www.atlantic.net/wp-content/themes/anet/img/cloud/gpu/icon_linkedin.webp) #### Richard Bailey ##### Technical Editor Richard Bailey brings over two decades of IT expertise, from traditional data centers to cutting-edge cloud solutions. As the founder of [turbogeek.co.uk](https://turbogeek.co.uk/) and a seasoned writer, he focuses on delivering authoritative content on our hosting services, HIPAA compliance, and related topics. In my experience, here are tips that can help you better leverage GPU servers for deep learning: 1. **Leverage mixed precision training:** Modern GPUs like the NVIDIA A100 are optimized for mixed precision (FP16 and FP32), allowing faster computations with less memory usage. Incorporate this technique in your deep learning workflows to maximize throughput without sacrificing model accuracy. 2. **Evaluate interconnect bandwidth for multi-GPU scaling:** When scaling across multiple GPUs, the bandwidth of interconnects (like NVLink or PCIe) is as crucial as the GPUs themselves. Insufficient bandwidth can create communication bottlenecks, reducing scalability. Run profiling tools (e.g., NVIDIA’s Nsight Systems) to evaluate interconnect performance and adjust configurations. 3. **Utilize asynchronous data loading pipelines:** Feeding data into GPUs efficiently is critical. Implement asynchronous data loading with frameworks like PyTorch’s DataLoader and use tools such as DALI (NVIDIA Data Loading Library) to preprocess datasets on the fly, ensuring GPUs are not idle during training. 4. **Fine-tune GPU utilization with dynamic batch sizing:** Optimize batch sizes dynamically based on the available GPU memory. Start with the largest batch size that fits in memory, and scale it down only if out-of-memory errors occur. Some frameworks like PyTorch Lightning can automate this process for you. 5. **Profile and optimize training workflows with TensorRT:** Post-training optimizations, such as quantization and model pruning using NVIDIA TensorRT, can accelerate inference significantly. It’s particularly useful for deploying models on production GPU servers where latency and power efficiency are critical. ## Use Cases for GPU Servers in Deep Learning GPU servers have critical use cases in deep learning. Here are the top deep learning use cases for these servers. ### 1. Real-Time Inference and Deployment Real-time inference involves making predictions on new data almost instantaneously, which is crucial for applications like autonomous driving, fraud detection, and personalized recommendations. GPU servers excel in handling these workloads due to their ability to process large volumes of data with low latency. Their architecture supports rapid execution of inference tasks, ensuring swift and accurate decision-making. In deployment scenarios, GPU servers provide the scalability and reliability needed to support continuous operations. They provide the performance and stability needed for real-time applications that require consistent responsiveness. ### 2. Fine-Tuning Pre-Trained Models Fine-tuning involves adjusting pre-trained models to improve performance on specific tasks or datasets. This process is significantly enhanced by GPU servers, which expedite the retraining process. Fine-tuning requires fewer computational resources than training from scratch but still benefits from the parallel processing and efficiency offered by GPUs. By leveraging GPU servers, organizations can quickly adapt existing models to new challenges, saving time and computational costs. This capability is particularly useful in domains where data evolves rapidly, such as healthcare diagnostics or financial forecasting. ### 3. Research and Experimentation Experimentation in deep learning often involves testing various architectures, hyperparameters, and datasets to discover optimal solutions. GPU servers provide the computational power necessary for conducting extensive experiments efficiently. Their ability to process multiple models and iterations simultaneously accelerates the research cycle, enabling faster innovation and discovery. For academic and industrial research, GPU servers offer the flexibility and scalability needed to explore complex deep learning challenges. They empower researchers to work with large datasets and intricate models, pushing the boundaries of what is possible in fields like natural language processing and computer vision. ## Best Practices for Setting Up GPU Servers for Deep Learning When setting up a GPU server for deep learning, it’s essential to consider both hardware and software configurations to optimize performance. Here are some best practices: ### 1. Optimize Hardware Configuration Tailoring the hardware configuration to the deep learning use case is critical for achieving optimal performance. Begin by determining the computational demands of the models—tasks like natural language processing or computer vision may require different GPU types and counts. Pair GPUs with CPUs that match the workload’s I/O and orchestration needs to avoid bottlenecks. Use fast, high-bandwidth storage solutions like NVMe SSDs for quicker data access and loading. Additionally, implement NVLink or similar technologies for efficient multi-GPU communication. ### 2. Ensure Efficient Cooling Efficient cooling is essential for maintaining optimal GPU server performance and preventing hardware damage due to overheating. GPUs generate significant heat during deep learning tasks, so invest in effective cooling solutions like liquid cooling or high-efficiency air conditioning. Regularly monitor temperature using built-in GPU sensors to ensure systems remain within safe operational limits. ### 3. Optimize Software Stack Selecting and configuring the right software stack is critical for maximizing the performance of a GPU server. Use operating systems and drivers optimized for GPU computing, such as Ubuntu combined with NVIDIA’s CUDA toolkit. Deep learning frameworks like TensorFlow, PyTorch, and cuDNN should be installed and configured to leverage GPU capabilities fully. Containerization tools like Docker can help manage and deploy applications efficiently, providing isolated environments that ensure consistency across development and production systems. ### 4. Implement Robust Security Measures Security is crucial when setting up GPU servers, especially for applications involving sensitive data. Implement firewalls and intrusion detection systems to protect against unauthorized access. Regularly update software to patch vulnerabilities and use encryption to secure data in transit and at rest. Additionally, configure user access controls to limit administrative privileges and monitor server activity for any suspicious behavior. These measures help safeguard against cyber threats, ensuring the integrity and confidentiality of deep learning projects. ### 5. Consider GPU Hosting For organizations without the infrastructure to support on-premises GPU servers, hosting solutions offer a viable alternative. [Cloud providers](https://www.atlantic.net/gpu-server-hosting/gpu-as-a-service-benefits-use-cases-and-how-to-choose/) and hosting providers offer scalable GPU resources on demand, allowing businesses to adjust computational power based on their needs. This flexibility reduces upfront costs and provides access to the latest GPU technology. Hosted GPU solutions also simplify maintenance and management, handling updates, security, and scalability. This allows teams to focus on development and research rather than infrastructure, making it an attractive option for startups and organizations with fluctuating workloads. ## Next-Gen Dedicated GPU Servers from Atlantic.Net, Accelerated by NVIDIA Experience unparalleled performance with dedicated cloud servers equipped with the revolutionary NVIDIA accelerated computing platform. Choose from the NVIDIA L40S GPU and NVIDIA H100 NVL to unleash the full potential of your generative artificial intelligence (AI) workloads, train large language models (LLMs), and harness natural language processing (NLP) in real time. High-performance GPUs are superb at scientific research, 3D graphics and rendering, medical imaging, climate modeling, fraud detection, financial modeling, and advanced video processing. [Learn more about Atlantic.net GPU server hosting.](https://www.atlantic.net/gpu-server-hosting/) --- # GPU as a Service: Benefits, Use Cases, and How to Choose > URL: https://www.atlantic.net/gpu-server-hosting/gpu-as-a-service-benefits-use-cases-and-how-to-choose/ | Published: 2025-02-18 | Updated: 2025-03-26 | Author: Gilad Maayan ## What Is GPU as a Service? GPU as a Service (GaaS) is a cloud-based model that provides scalable access to GPU resources. Unlike traditional setups where organizations purchase and maintain physical hardware, GaaS offers virtual GPUs through the cloud. This service allows organizations to leverage computing resources without the need to invest in expensive infrastructure. Instead, users can rent GPU resources as needed, making it appropriate for handling workloads with varying demands. Through GaaS, users access GPUs over the internet, enabling them to perform compute-intensive tasks such as deep learning, graphics rendering, and simulation. This model provides significant benefits in scalability, as resources can be scaled up or down based on varying needs, and in cost-effectiveness, since users pay only for what they use. Additionally, GaaS simplifies the process of integrating GPU capabilities into existing workflows, reducing the complexity associated with hardware maintenance. This is part of a series of articles about GPU servers. ## How GPU as a Service Works GPU as a Service (GaaS) operates through advanced cloud infrastructure that virtualizes GPU resources, enabling users to access and utilize high-performance computing power on demand. The core components and functionalities that power GaaS include: - **Cloud infrastructure:** The provider’s cloud infrastructure is housed in advanced data centers. This infrastructure allows users to access GPU resources remotely via devices such as laptops and smartphones. The cloud environment ensures seamless connectivity, making GPU power available wherever an internet connection exists. - **Virtualization:** Service providers use virtualization technology to divide physical GPU hardware into virtual machines or containers. This enables multiple users to share GPU resources simultaneously without interference. Each virtualized instance operates independently, allowing users to execute their specific workloads securely and efficiently. - **Elasticity:** Users can increase or decrease the number of GPUs they use, accommodating both short-term intensive tasks and long-term projects. This flexibility eliminates the need for organizations to commit to fixed hardware resources, ensuring cost efficiency and adaptability. - **APIs and development platforms:** Providers often integrate APIs and development platforms that simplify GPU deployment and management. These tools allow users to automate tasks such as starting, stopping, and monitoring GPU instances, streamlining workflows, and enhancing operational efficiency. - **Security and compliance:** GaaS providers implement security measures to protect data in transit and at rest. Common security features include encryption, two-factor authentication, identity management, and firewalls. Providers also comply with industry regulations such as GDPR and HIPAA, ensuring data integrity and compliance for sensitive applications. ## Benefits of GPU as a Service GaaS offers several benefits for organizations and developers requiring high-performance computing power: - **Cost efficiency:** GaaS eliminates the need for upfront investments in expensive GPU hardware. Users pay only for the resources they consume, converting capital expenses into manageable operational costs. - **Scalability:** Resources can be scaled up or down to match workload demands, ensuring that organizations only use what they need. - **Ease of maintenance:** Service providers handle all hardware maintenance, including updates, repairs, and replacements. This reduces the operational burden on organizations and ensures uninterrupted access to GPUs. - **Access to the latest hardware:** GaaS offers access to the latest GPU technologies without requiring hardware upgrades. Providers regularly update their infrastructure, giving users cutting-edge performance capabilities. - **Faster time to market:** Rapid deployment of GPU resources allows organizations to accelerate project timelines. Developers can access GPUs instantly, avoiding delays associated with procuring and setting up hardware. - **Global accessibility:** Cloud-based GPUs are accessible from anywhere with an internet connection. This is particularly advantageous for remote teams and collaborative projects spanning multiple locations. ### Tips from the expert: ![Author icon](https://secure.gravatar.com/avatar/eb8695bf1d856d659c4fa98eba9e0c42?s=192&d=mm&r=g) ![Linkedin Icon](https://www.atlantic.net/wp-content/themes/anet/img/cloud/gpu/icon_linkedin.webp) #### Richard Bailey ##### Technical Editor Richard Bailey brings over two decades of IT expertise, from traditional data centers to cutting-edge cloud solutions. As the founder of [turbogeek.co.uk](https://turbogeek.co.uk/) and a seasoned writer, he focuses on delivering authoritative content on our hosting services, HIPAA compliance, and related topics. In my experience, here are tips that can help you make the most of GPU as a Service (GaaS) for your computing needs: 1. **Choose the right GPU instance type for specific workloads:** Different GaaS providers offer GPU instance types optimized for specific tasks, such as rendering (NVIDIA RTX series) or deep learning (NVIDIA A100). Always match the instance to the workload to avoid overpaying for underutilized resources or bottlenecks due to insufficient capacity. 2. **Take advantage of spot or preemptible instances:** For non-time-critical workloads like batch rendering or training large AI models, spot or preemptible instances can save up to 90% of costs. Implement checkpointing in workflows to prevent data loss when these instances are terminated. 3. **Use auto-scaling to handle fluctuating workloads:** Leverage auto-scaling to allocate additional GPU resources during peak usage and scale down when demand is low. This ensures optimal performance while minimizing costs, especially in machine learning training or analytics with unpredictable workloads. 4. **Optimize data transfer to reduce latency and costs:** Minimize data transfer between the cloud and local systems by pre-processing or compressing datasets before uploading them to the cloud. Use storage solutions located in the same cloud region as GPU instances to reduce latency and egress fees. 5. **Use containerized environments for easy portability:** Deploy GPU workloads in containers using tools like Docker and NVIDIA GPU Cloud (NGC). Containers ensure that dependencies are consistent across different providers or on-premise systems, making it easier to switch providers or replicate environments. ## GPU as a Service vs. On-Premise GPUs: A Comparison ### Deployment **GPU as a Service**utilizes cloud-based environments, offering virtual GPUs maintained by providers. This alleviates the burden of hardware maintenance and allows for dynamic scaling of resources in response to demand fluctuations. Rapid deployment and access to resources are defining features of the GaaS model. **On-premise GPUs** involve considerable initial investment in hardware and require ongoing maintenance, which can become resource-heavy for organizations with limited IT staff. The deployment of on-premise systems generally offers more control over hardware configurations, allowing for custom setups tailored to specific applications. However, this comes at the cost of flexibility and scalability. ### Cost Considerations **GaaS** typically offers lower upfront costs, as it eliminates the need for purchasing and installing physical hardware. Instead, organizations can pay incrementally based on usage, converting what would be capital expenses into manageable operational expenditures. **On-premise solutions**require substantial initial investment in hardware and infrastructure, although they may become cost-effective over time for regular, extensive workloads. Organizations needing constant, uninterrupted GPU access might find on-premise solutions more predictable in terms of monthly expenses. However, these savings can be offset by maintenance, power, and infrastructure upgrades. ### Security Implications **GaaS providers** may offer differing security measures. Prefer a provider that supports compliance standards relevant for your organization, and offers security features like encryption protocols and identity management systems. **On-premise solutions** offer more direct control over security configurations, allowing organizations to customize their defenses based on specific needs. This level of control can be appealing for organizations with stringent security requirements or regulations. However, it can be challenging to maintain a strong security posture, as internal teams are responsible for managing updates and responding to threats. ### Maintenance and Updates With **GaaS**, maintenance responsibilities fall on the service provider, ensuring that hardware updates, patches, and repairs are handled seamlessly. This allows organizations to focus on core activities without worrying about the operational aspects of GPU maintenance. Continuous hardware updates by providers also mean access to the latest technologies without additional cost. **On-premise solutions**require organizations to manage their hardware upkeep, from installing updates to dealing with potential hardware failures. This internal management can be demanding, requiring dedicated IT teams and resources to ensure optimal performance. While on-premise setups allow for customizations and configurations, they involve an ongoing commitment to maintaining system health and performance. ## Use Cases for GPU as a Service ### Machine Learning and AI Training In machine learning and AI training, GPU as a Service offers support by providing accessible, high-performance computing power. This capability is crucial for training large models and processing massive data sets efficiently. With GaaS, data scientists can allocate additional GPUs as needed, significantly accelerating training times, enabling complex experimentation. Additionally, GaaS enables rapid prototyping and continuous integration in AI development environments. Researchers can leverage GPU resources without delay, fostering environments where iterative testing and agile methodologies thrive. This immediacy in accessing computing power improves productivity but also enables faster proof-of-concept demonstrations. ### High-Performance Computing High-performance computing (HPC) applications benefit from GPU as a Service due to the immense parallel processing power available through cloud-based GPUs. Industries like aerospace and scientific research, which require intensive calculations and simulations, can leverage GaaS for real-time data analysis and processing. The scalability of GaaS allows organizations to execute complex tasks that would be otherwise infeasible with an on-premise setup. The ability to access cutting-edge GPU architectures also aids in optimizing workloads that demand significant computational resources. By eliminating the need for infrastructure investment, organizations can redirect resources to innovation. ### Graphics Rendering and Visualization Graphics rendering and visualization are areas where GPU as a Service makes a significant impact, particularly in industries such as media, entertainment, and architecture. By offering high-performance, scalable GPU resources, GaaS enables the rendering of complex graphics and visualizations at superior speeds and high resolutions. This capability is essential for creating sophisticated visual effects, detailed simulations, and interactive visual content. The flexibility provided by GaaS for artists and designers to access rendering tools on-demand fosters collaboration and innovation. Team members can work on projects without the hardware limitations that typically slow down creative processes. ### Data Analytics GPU as a Service improves data analytics capabilities by offering the processing power necessary to handle big data challenges. This is vital for sectors such as finance, healthcare, and retail, where timely insights from data analysis drive strategic decision-making. The parallel processing abilities of GPUs accelerate data processing tasks, enabling real-time analytics. GaaS also allows organizations to manage varying data loads without investing in dedicated hardware, aligning with seasonal or project-specific analytics needs. The ability to perform complex computations with cloud-based GPUs ensures that organizations can innovate and respond promptly to market dynamics. ***Related content: Read our guide to [GPU server for deep learning](https://www.atlantic.net/gpu-server-hosting/gpu-servers-for-deep-learning-a-practical-guide/).*** ## Choosing a GPU-as-a-Service Provider Here are some of the things to consider when evaluating GaaS providers. ### Evaluating Performance and Hardware Options Providers differ in the GPU models they offer and the technical specifications available. Key considerations include the processing power, memory capacity, and architectural features of the GPUs. Comparing these aspects helps determine which provider best aligns with the specific computational needs of the applications. Performance metrics, such as latency and throughput, are also important. Understanding how these factors impact workflows is critical, especially for applications requiring high concurrency or real-time processing. Conducting performance tests and analyzing benchmarks from potential providers can offer insights into how their GPUs will perform under workload pressure. ### Pricing Models and Cost Efficiency Providers often offer various pricing structures, such as pay-as-you-go, reserved instances, or spot pricing, each with different cost implications. Understanding these models helps organizations predict expenses more accurately and select the model that best fits their budget and usage patterns. For short-term projects, pay-as-you-go may be more cost-effective, whereas long-term commitments might benefit from reserved instances. Additionally, assessing the total cost of ownership (TCO) includes examining additional fees that might not be immediately apparent, such as data transfer costs, storage fees, or premium support charges. ### Integration with Existing Workflows Integration with existing workflows is a vital factor when selecting a GPU-as-a-Service provider. Compatibility with current software and systems ensures a smooth transition and maximizes productivity. Evaluate how well the provider’s services align with the technical environment and processes, focusing on APIs, SDKs, and support for prevailing development tools. Providers that offer comprehensive integration support can help simplify workflow adjustments and minimize disruptions. Features such as seamless cloud-based deployment, consistency in user interfaces, and support for automation can improve integration efforts. ### Data Security and Compliance Providers must offer strong security protocols, including encryption, identity management, and regular security audits to protect sensitive information. It is crucial to verify that the provider’s security standards align with industry norms and regulatory requirements such as GDPR, HIPAA, or other relevant standards. Providers should support a transparent compliance framework, offering insights into how they handle data security and privacy concerns. An established incident response plan and continuous monitoring capabilities can add another layer of assurance. Evaluating these factors helps ensure that the GPU deployment is secure and compliant. ### Support and Service Level Agreements (SLAs) Support and Service Level Agreements (SLAs) are key considerations when selecting a GPU-as-a-Service provider. Comprehensive support structures can include technical assistance, user training, and dedicated account management to ensure smooth operation and prompt problem resolution. Understanding the level of support provided can help organizations plan for potential challenges and ensure continuity in their computational processes. SLAs are indicative of the provider’s commitment to uptime and service quality. Key elements to review include the guaranteed uptime percentage, response times for support requests, and any compensation clauses for unfulfilled service commitments. ## **Next-Gen Dedicated GPU Servers from Atlantic.Net, Accelerated by NVIDIA** Experience unparalleled performance with dedicated cloud servers equipped with the revolutionary NVIDIA accelerated computing platform, and benefiting from Atlantic.net’s industry-leading compliance with standards like HIPAA and PCI DSS. Choose from the NVIDIA L40S GPU and NVIDIA H100 NVL to unleash the full potential of your generative artificial intelligence (AI) workloads, train large language models (LLMs), and harness natural language processing (NLP) in real time. High-performance GPUs are superb at scientific research, 3D graphics and rendering, medical imaging, climate modeling, fraud detection, financial modeling, and advanced video processing. [Learn more about Atlantic.net GPU server hosting.](https://www.atlantic.net/gpu-server-hosting/) --- # AI in Drug Discovery: Technologies and Practical Applications > URL: https://www.atlantic.net/hipaa-compliant-hosting/ai-in-drug-discovery-technologies-and-practical-applications/ | Published: 2025-02-20 | Updated: 2025-02-24 | Author: Gilad Maayan ## What Is Drug Discovery? Drug discovery is the process of identifying and developing new medications to treat diseases and improve health. This involves understanding disease mechanisms, identifying biological targets, and designing molecules that can interact with those targets. The process typically includes several stages, starting with basic research to identify potential therapeutic targets, followed by drug design and optimization, preclinical testing, and clinical trials. Each phase ensures the drug’s safety, efficacy, and suitability for human use. Drug discovery is a critical and complex aspect of pharmaceutical research, requiring multidisciplinary collaboration across biology, chemistry, medicine, and data science. This is part of a series of articles about [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/what-is-hipaa-compliance-history-rules-and-requirements/) ## The Evolution of Drug Discovery: From Traditional Methods to AI Throughout history, drug discovery relied on labor-intensive laboratory testing and serendipitous findings. Traditional methods involved trial-and-error processes that were both time-consuming and costly, often taking years to develop a single drug. ### Limitations of Traditional Drug Discovery Methods Traditional drug discovery methods face several limitations, such as the significant time and financial investments required. It involves screening millions of compounds against target diseases, which can take years to yield a viable pharmaceutical product. The extensive trial and error further add to the resource constraints encountered in traditional approaches. Another limitation is the low success rate, as many candidates fail to progress beyond clinical trials. The complexity of biological systems often leads to unexpected failures, with only a small percentage advancing past each phase. ### Artificial Intelligence in Drug Discovery AI significantly improves the efficiency and accuracy of finding new drugs. AI tools can process vast biological datasets quickly, uncovering patterns not immediately evident through manual efforts. This automated approach accelerates the identification of new drug targets and potential compounds. Machine learning models can predict molecular interactions and potential drug side effects, reducing trial phases’ burden. By simulating various scenarios computationally, AI avoids unnecessary experimentation, optimizing resource utilization. ## Key AI Technologies Revolutionizing Drug Discovery Artificial intelligence (AI) technologies have transformed drug discovery by automating complex processes and enhancing decision-making. Here are some notable AI innovations: 1. **Machine learning for predictive modeling:** Machine learning algorithms analyze large datasets to identify patterns and predict how potential drug candidates will behave. For example, by modeling molecular interactions, machine learning helps researchers select promising compounds while eliminating those likely to fail, reducing the costs and time spent on unsuccessful trials. 2. **Generative AI for novel compound design:** Generative AI models, such as variational autoencoders (VAEs) and generative adversarial networks (GANs), explore chemical spaces and design new compounds based on therapeutic goals. By learning from known chemical structures, these models can generate new molecules. For example, generative AI assisted in the discovery of halicin, a powerful antibiotic, by rapidly screening thousands of molecules and identifying candidates. 3. **AlphaFold for Protein structure prediction:** Accurate protein models help researchers understand how drugs interact with biological targets, improving the design of molecules that bind effectively. Google’s AlphaFold 3 has advanced this further by modeling protein interactions with other molecules, such as sugars and nucleic acids. 4. **Multimodal AI for complex data integration:** Multimodal AI systems integrate diverse datasets, including genomics, proteomics, and clinical data, to provide a comprehensive view of biological mechanisms. These models enable simultaneous analysis of text, imaging, and molecular data, identifying new therapeutic targets and guiding personalized treatment approaches. 5. **Natural Language Processing (NLP) for literature mining:** NLP tools analyze vast amounts of text-based data to uncover connections between known drugs, diseases, and biological pathways, enabling drug repurposing and target discovery. 6. **Explainable AI (XAI) for regulatory compliance:** XAI frameworks provide insights into the decision-making process, helping regulators and stakeholders understand the rationale behind drug candidates’ selection. **Tips from the expert:** In my experience, here are tips that can help you better leverage AI in drug discovery: 1. 1. **Implement federated learning for data privacy:** Utilize federated learning to train AI models on sensitive biomedical data across multiple organizations without sharing raw data. This ensures privacy while enabling access to a broader dataset, improving model accuracy and generalizability. 2. **Incorporate active learning to optimize data usage:** Use active learning techniques to prioritize the most informative data points for model training. This minimizes the need for extensive labeled datasets and accelerates the iterative learning process in resource-constrained settings. 3. **Combine physics-based models with AI-driven predictions:** Hybrid approaches that integrate AI with physics-based simulations, such as molecular dynamics, improve the accuracy of drug design. These combinations account for physical properties that pure AI models may overlook. 4. **Utilize generative AI for novel compound design:** Deploy generative AI models like variational autoencoders (VAEs) or generative adversarial networks (GANs) to create novel molecular structures. These tools explore vast chemical spaces efficiently and can tailor compounds to therapeutic goals. 5. **Focus on explainable AI (XAI) for regulatory acceptance:** Ensure the AI models offer interpretable insights into their predictions. Explainable AI frameworks help regulators and stakeholders understand decision-making processes, facilitating trust and compliance with regulatory standards. ## Applications of AI in Drug Discovery ### Identifying New Drug Targets AI algorithms accelerate the discovery of drug targets by analyzing large biological datasets, such as gene expression profiles and protein-protein interaction networks. Tools like AlphaFold predict protein structures with high accuracy, revealing potential binding sites for therapeutic intervention. Machine learning models can prioritize targets based on their relevance to diseases. Additionally, AI-driven approaches help uncover previously unknown or overlooked targets by identifying hidden patterns within complex biological systems. For example, AI-based methods analyze data across multiple modalities, such as transcriptomics and proteomics, to highlight pathways and interactions that may serve as viable drug targets. ### Virtual Screening and Drug Repurposing Structure-based and ligand-based virtual screening methods powered by machine learning models assess the compatibility of compounds with target proteins, drastically reducing the need for physical laboratory screening. This computational strategy simplifies the selection of compounds that can be further optimized into viable drug candidates. AI also aids in drug repurposing by analyzing existing clinical data to find new therapeutic uses for approved drugs. Machine learning models identify hidden correlations between drugs and diseases, uncovering new indications for previously developed drugs. ### Predicting Drug Efficacy and Toxicity AI helps predict drug efficacy by simulating molecular interactions and biological responses before clinical trials begin. By analyzing preclinical data, machine learning models can identify how drugs interact with target proteins and biological systems, allowing for early optimization of drug candidates. In addition, AI-driven toxicology models assess potential adverse effects by detecting patterns associated with toxicity, such as hepatotoxicity or cardiotoxicity, in preclinical data. This early-stage screening minimizes the risk of failures in human trials, ensuring that only the safest and most effective compounds advance through the drug development pipeline. ### AI in Clinical Trial Design and Optimization AI optimizes clinical trial design by predicting patient responses and outcomes, enabling the selection of appropriate trial populations. Machine learning algorithms can stratify patients based on genetic, demographic, or clinical characteristics, ensuring that those most likely to benefit from the treatment are included. AI also supports adaptive trial designs by continuously analyzing real-time data from ongoing trials. This allows researchers to adjust dosages, modify protocols, or refine inclusion criteria based on interim results, ultimately speeding up the process while maintaining safety. ## Challenges and Limitations of AI in Drug Discovery ### Data Quality and Availability Issues AI-driven drug discovery depends heavily on the quality and availability of data. Incomplete or noisy datasets can lead to inaccurate predictions, affecting the reliability of AI models. Ensuring high-quality, comprehensive data is critical to leverage AI’s true potential in drug discovery. Data availability is another hurdle, as valuable proprietary datasets are not always accessible, hindering AI’s application across broader contexts. ### Ethical Considerations and Regulatory Hurdles Implementing AI in drug discovery presents ethical considerations and regulatory challenges that need addressing. AI models must be developed transparently, ensuring unbiased data handling and decision-making processes. Regulatory bodies require comprehensive evaluations of AI-driven approaches to mitigate potential technology-related risks. ### Integration with Existing Drug Discovery Workflows Integrating AI within existing drug discovery workflows poses operational challenges, requiring adaptation into established processes. Pharmaceutical organizations must align their infrastructure to support AI’s integration while training personnel on new technologies. This organizational shift requires strategic planning to maximize AI’s benefits. ## 5 Best Practices for Implementing AI in Drug Discovery When using AI to enhance drug discovery, it’s important to consider the following best practices. ### 1. Collaborating Between AI Experts and Pharmaceutical Scientists Effective AI implementation in drug discovery requires close collaboration between data scientists, pharmaceutical researchers, and compliance experts. AI models alone cannot capture the complexities of drug development without input from those who understand disease mechanisms, regulatory requirements, and clinical trial design. By working together, AI and life science professionals can refine predictive models to ensure they align with real-world biological and clinical contexts. For example, multidisciplinary teams can improve AI-driven target identification by integrating domain expertise into data interpretation. AI may highlight potential drug targets based on statistical correlations, but pharmaceutical scientists validate these findings through experimental data and biological plausibility. ### 2. Ensuring Data Security and Privacy Ensuring data security and privacy is crucial in AI-enabled drug discovery, particularly given the sensitive nature of biomedical data. Implementing strong data protection measures, such as encryption protocols and access controls, protects patient information and proprietary research data. These security frameworks build trust with partners and stakeholders, enabling open collaboration and data sharing. AI systems should be designed with privacy by design principles, ensuring compliance with regulations like GDPR and HIPAA. Regular security audits and risk assessments are essential, identifying potential vulnerabilities before exploitation. ### 3. Ensuring Data Quality The accuracy of AI models in drug discovery depends on the quality of input data. Poor-quality datasets can lead to incorrect predictions, such as selecting ineffective drug targets or underestimating potential safety risks. To prevent these issues, pharmaceutical companies must implement strict data governance policies, including verifying data provenance, standardizing formats, and removing inconsistencies before feeding data into AI models. Continuous monitoring and quality checks are also essential. As new datasets become available, models should be updated and revalidated to maintain accuracy. AI-driven drug discovery benefits from curated and harmonized data sources, ensuring that insights are based on reliable, unbiased information rather than incomplete or outdated records. ### 4. Validation of AI Models with Experimental Data AI-generated predictions must be validated using real data before being applied in drug discovery. Without experimental verification, AI models risk producing misleading or overly optimistic results that do not translate to real-world conditions. To ensure accuracy, AI-driven insights should be cross-checked with in vitro and in vivo studies, as well as historical clinical trial data. For example, when AI identifies a potential drug candidate, laboratory experiments should confirm its binding affinity, biological activity, and toxicity profile before progressing further. This iterative process, combining computational modeling with hands-on experimentation, improves confidence in AI-driven predictions and minimizes risks in later drug development stages. ### 5. Maintaining Transparency of AI Outcomes Many AI models operate as “black boxes,” making it difficult for researchers and regulators to understand how predictions are made. To address this, AI developers should provide clear documentation on the strengths and limitations of their models, including data sources, key assumptions, and validation methods. Regulatory bodies are more likely to approve AI-assisted drug discoveries when the decision-making process is explainable. AI platforms should incorporate explainability tools that highlight which factors influenced a prediction, such as molecular structure features, known biomarkers, or clinical trial data patterns. ## Conclusion AI is revolutionizing drug discovery by simplifying complex workflows, increasing accuracy, and reducing costs. By integrating advanced machine learning models, generative design tools, and multimodal data analysis, AI helps researchers to accelerate the identification and development of new therapeutics. However, successful implementation requires addressing challenges related to data quality, regulatory compliance, and interdisciplinary collaboration. --- # Atlantic.Net Scores Multi-Year Partnership with San Jose Earthquakes > URL: https://www.atlantic.net/press-releases/atlantic-net-scores-multi-year-partnership-with-san-jose-earthquakes/ | Published: 2025-02-21 | Updated: 2026-03-02 | Author: Editorial Team **Premier Provider Strengthens its Presence in Silicon Valley as the Official Cloud Hosting Platform with Major League Soccer Team** **SAN JOSE, Calif. – February 21, 2025 –**[Atlantic.Net](https://www.atlantic.net/), a premier provider of innovative and reliable cloud services and hosting solutions, has signed a multi-year partnership with Major League Soccer’s [San Jose Earthquakes](https://www.sjearthquakes.com/) (Quakes), becoming the team’s Official Cloud Server Hosting Platform and Official Accelerated Compute Provider. “Our secure and high-performance cloud solutions will provide a perfect fit to equip the Earthquakes with the technological advancements to further achieve their IT goals,” said Marty Puranik, CEO of Atlantic.net. “As an organization that shares our passion for innovation and excellence, we look forward to working with the San Jose Earthquakes team of professionals.” Forming its partnership just before the Quakes’ season opener game on Feb. 22, 2025, fans will first see Atlantic.Net’s presence as a promotional sponsor partner at the stadium. In the next phase of the partnership, Atlantic.Net will pivot the deployment of its cloud services for the Quakes, allowing the organization to [save costs on infrastructure](https://www.atlantic.net/cloud-platform/save/) and take advantage of [managed services](https://www.atlantic.net/managed-services/) to further decrease its information technology costs. Atlantic.Net’s cutting-edge cloud platform and accelerated computing solutions will provide the Quakes the opportunity to power their next-generation applications, including AI and machine learning initiatives. This partnership provides a perfect platform to enhance the team’s ability to analyze data, improve performance, and engage with fans in new and innovative ways. “We’re excited about partnering with Atlantic.Net,” said San Jose Earthquakes Chief Strategy Officer Ian Anderson. “Being based in Silicon Valley, we’re always looking to work with leaders in technology and find ways to optimize our infrastructure. Atlantic.Net’s award-winning hosting solutions and services make them a welcome addition to our partner roster.” This marks the second time a professional sports team has partnered with Atlantic.Net, following The National Basketball Association’s [Orlando Magic](https://www.atlantic.net/press-releases/orlando-magic-selects-atlantic-net-official-server-host/) partnership established in 2009.   **About Atlantic.Net** Established in 1994, Atlantic.Net is a privately-owned, global cloud services provider that delivers innovative and reliable hosting solutions. Focusing on security, compliance, and customer support, Atlantic.Net offers a wide range of services, including GPU hosting, an award-winning Cloud Platform, HIPAA-compliant hosting, dedicated hosting, and colocation to a large roster of organizations in a variety of industries. Atlantic.Net provides mission-critical services from eight global data center regions located in the United States, Canada, the United Kingdom, and Asia. For more information, visit[Atlantic.Net](https://www.atlantic.net) or connect with us on[Facebook](https://www.facebook.com/Atlantic.Net),[X (Twitter)](https://twitter.com/AtlanticNet),[LinkedIn](https://www.linkedin.com/company/atlantic-net), and[YouTube](https://www.youtube.com/c/AtlanticNet). **About the San Jose Earthquakes** The San Jose Earthquakes, one of Major League Soccer’s original teams, are the epicenter for soccer in Northern California, playing at the highest professional level in the United States. The club won MLS Cups in 2001 and 2003 and took home Supporters’ Shields in 2005 and 2012. The club is based out of PayPal Park, an 18,000-seat soccer-specific stadium that opened in 2015 and is the first cloud-enabled venue in MLS. The organization was originally founded in 1974 in the North American Soccer League, and in 2024 celebrated its 50th anniversary of positively impacting communities around Northern California. The club’s nonprofit arm, the Quakes Foundation, focuses on health and fitness initiatives for local underserved youth and fighting food insecurity. For more information about the Earthquakes, visit[www.sjearthquakes.com](http://www.sjearthquakes.com/). **Media Contact** Elise Riley, 404-434-1756 elise@myglobalpresence.com ** ** ### --- # Atlantic.Net Scores Winning Partnership with San Jose Earthquakes > URL: https://www.atlantic.net/announcements/atlantic-net-scores-winning-partnership-with-san-jose-earthquakes/ | Published: 2025-02-21 | Updated: 2025-09-11 | Author: Alexander Wise We are pleased to announce a multi-year partnership with the San Jose Earthquakes, establishing Atlantic.Net as the ***Official Cloud Server Hosting Platform and Official Accelerated Compute Provider.*** ![](https://www.atlantic.net/wp-content/uploads/2025/02/Quakes600x300-Banner-01.jpg) The Earthquakes provide an excellent platform for Atlantic.Net to reach an affluent and growing soccer fanbase in the heart of Silicon Valley, and Atlantic.Net provides the latest accelerated computing which can greatly help equip the Earthquakes with the technological advancements to further achieve their goals on and off the field. Forming its partnership just before the Quakes’ season opener game on Feb. 22, 2025, fans will first see Atlantic.Net’s presence as a promotional sponsor partner at the stadium. In the next phase of the partnership, Atlantic.Net will pivot the deployment of our cloud services for the Quakes, allowing the organization to [save costs on infrastructure](https://www.atlantic.net/cloud-platform/save/) and take advantage of [managed services](https://www.atlantic.net/managed-services/) to further decrease its information technology costs. This marks the second time a professional sports team has partnered with Atlantic.Net, following The National Basketball Association’s [Orlando Magic](https://www.atlantic.net/press-releases/orlando-magic-selects-atlantic-net-official-server-host/) partnership established in 2009. We are thrilled to partner with the San Jose Earthquakes, an organization that shares our passion for innovation and excellence. We are confident that our secure and high-performance cloud solutions provide a perfect fit to equip the Earthquakes with the technological advancements to further achieve their IT goals. ***Go Earthquakes!*** --- # GPUs in Cloud Computing: 4 Cloud Providers Compared > URL: https://www.atlantic.net/gpu-server-hosting/gpus-in-cloud-computing-4-cloud-providers-compared/ | Published: 2025-02-24 | Author: Gilad Maayan Almost all cloud providers offer GPUs, or graphics processing units, as an optional add-on for cloud-based computing resources. GPUs enhance cloud computing by performing complex calculations efficiently. Unlike CPUs, which handle a few threads quickly, GPUs can manage thousands simultaneously, making them ideal for tasks that require parallel processing. This capacity enables faster data analysis, simulation, and rendering, crucial for various cloud-based applications, from machine learning to graphics rendering and scientific computing. In a cloud computing environment, GPUs are critical for managing large datasets and performing high-speed computations. They support industries relying on intensive computation, including financial modeling, gaming, and predictive analytics. By offloading demanding tasks from CPUs, GPUs improve overall system performance and energy efficiency in cloud environments, offering scalable solutions to meet growing computational demands. This is part of a series of articles about [GPU for AI](https://www.atlantic.net/gpu-server-hosting/gpu-for-ai-platforms-top-gpus-and-key-features-to-consider/). ## How GPUs Impact Cloud Computing The application of GPUs in cloud computing goes beyond speed, enabling new functionalities and services. Cloud service providers integrate GPUs to offer accelerated machine learning and deep learning frameworks. This integration allows companies to innovate faster by accessing high-performance computing resources without the overhead costs of maintaining physical hardware. ### Acceleration of Compute-Intensive Workloads GPUs accelerate compute-intensive workloads by harnessing their parallel processing architecture to handle massive amounts of data simultaneously. This ability is particularly beneficial for applications in scientific research and 3D rendering, where large volumes of data need processing quickly. By reducing computation time, GPUs enable researchers and businesses to achieve faster results. The use of GPUs in cloud computing democratizes access to high-performance computing resources. Organizations that might not afford expensive infrastructure can leverage cloud-based GPU power for their complex computational needs. This accessibility facilitates innovation and experimentation across various domains, from academic research to commercial product development. ### Improved Efficiency for Parallel Processing GPUs significantly boost parallel processing efficiency, performing numerous calculations simultaneously. This advantage is essential for applications needing extensive image, video, or data processing. By optimizing these tasks, GPUs ensure faster completion times. Parallel processing also plays a role in reducing computational resources needed for large-scale operations. By efficiently distributing workloads across thousands of GPU cores, cloud computing systems minimize bottlenecks and enhance system throughput. This capability ensures high operational efficiency for enterprises relying on intensive computing tasks and large datasets. ### Enabling Real-Time Applications GPUs enable real-time applications by providing the necessary computational power to process and analyze data on-the-fly. This capability is important in sectors such as eCommerce, financial services, and entertainment, where decision-making depends on immediate data insights. In addition, real-time applications benefit from the scalability of GPU-accelerated cloud platforms. As the demand for rapid data processing grows, cloud services equipped with GPUs scale efficiently to accommodate increased workloads. This scalability enables businesses to maintain continuous service availability and performance. ***Related content: Read our guide to [GPU for deep learning](https://www.atlantic.net/gpu-server-hosting/gpu-for-deep-learning-critical-specs-and-top-7-gpus-in-2025/)*** ## Key Use Cases for GPU in Cloud Computing ### Artificial Intelligence and Machine Learning GPUs are essential for training deep learning models, where large datasets and complex computations are involved. Neural networks, especially deep architectures like convolutional and transformer-based models, benefit from the parallelism that GPUs provide, reducing training times compared to CPUs. This enables faster experimentation cycles, critical for applications like computer vision, natural language processing, and autonomous systems. GPUs are also used for inference tasks in production environments. For real-time AI applications—such as voice assistants, recommendation engines, and fraud detection—GPUs process input data rapidly, ensuring low-latency responses. This performance boost is key in ### High-Performance Computing (HPC) HPC applications in fields such as weather forecasting, molecular simulations, and seismic analysis require handling massive computational workloads. GPUs provide the power needed to execute highly parallel operations, making them suitable for tasks like finite element analysis, fluid dynamics, and large-scale simulations. In addition, cloud-based GPU clusters offer on-demand scalability, allowing organizations to run large-scale simulations without the need for on-premise infrastructure. This flexibility supports projects requiring intermittent high performance, such as drug discovery or computational chemistry, where experiments can scale according to research needs. ### Data Analytics GPUs speed up data preprocessing, aggregation, and querying tasks. They are particularly beneficial in environments involving big data, where datasets are too large for traditional CPU processing. For example, GPUs accelerate SQL queries and data transformations using GPU-optimized frameworks, helping analysts derive insights quickly. In machine learning-driven analytics, GPUs enable faster model training and iterative analysis on big datasets, such as real-time customer behavior tracking or predictive maintenance systems. This speed allows organizations to make timely, data-driven decisions. ### Graphics Rendering and Visualization GPUs are built for rendering complex visualizations and 3D graphics, making them useful for cloud-based applications in gaming, virtual reality, and digital content creation. In these cases, cloud providers offer GPU-powered virtual machines to render graphics-intensive scenes in real time, reducing latency and enabling smooth user experiences. Visualization in scientific research, architecture, and engineering also relies on GPU acceleration. Fields like medical imaging or computer-aided design (CAD) benefit from GPUs to generate detailed models, perform simulations, and visualize high-resolution images. Applications include surgical planning, geological mapping, and product prototyping. ## GPUs for Cloud Computing: Challenges and Solutions Despite the benefits, using GPUs for cloud computing also presents challenges such as cost management and resource allocation. Addressing these issues involves implementing strategies for efficient deployment and operation, ensuring businesses capitalize on the capabilities of GPUs without incurring prohibitive expenses. Effective management methods are crucial for optimizing performance and reducing operational costs. ### Cost Management Managing costs associated with GPU-powered cloud computing can be challenging due to the high expenses of running compute-intensive applications. Effective cost management strategies include utilizing cloud provider tools for monitoring and scaling resources, ensuring usage aligns with demand. Pay-per-use and commitment discounts can be leveraged for cost savings and predictability. In addition, companies can explore optimizing their workloads to reduce GPU time consumption, thereby lowering operational expenses. Employing machine learning pipelines efficiently and scheduling tasks during off-peak hours might further cut costs. ### Resource Allocation and Scheduling for Optimal Performance Resource allocation in cloud environments using GPUs involves distributing tasks efficiently across available resources to maximize performance. Effective scheduling ensures that compute resources are neither underutilized nor overburdened, achieving balanced workload distribution. Leveraging cloud provider tools and algorithms can help in dynamic resource scaling and optimal utilization of GPU nodes. Maintaining optimal performance also requires monitoring and adjusting resource allocations based on real-time data and usage patterns. By integrating automated systems for load balancing and resource monitoring, companies can improve efficiency, minimize latency, and ensure smooth operation of applications. ### Network Bandwidth and Data Transfer Limitations Network bandwidth and data transfer pose potential constraints in GPU-accelerated cloud computing by limiting data throughput and increasing latency. Solutions include employing advanced data compression techniques and optimizing application architectures to reduce dependency on high bandwidth. Additionally, choosing cloud providers with robust network infrastructure can alleviate bandwidth issues. Effective data management strategies, such as caching and edge computing, can further mitigate network constraints, ensuring timely data access and processing. Implementing efficient data transfer protocols and architectures that minimize bandwidth consumption without compromising performance is crucial for leveraging GPU capabilities in cloud environments. ## Next-Gen Dedicated GPU Servers, Powered by NVIDIA and Atlantic.net Experience unparalleled performance with dedicated cloud servers equipped with the revolutionary NVIDIA accelerated computing platform. Choose from the NVIDIA L40S Tensor Core GPU and NVIDIA H100 NVL GPU to unleash the full potential of your generative artificial intelligence (AI) workloads, train large language models (LLMs), and harness natural language processing (NLP) in real time. High-performance GPUs are superb at scientific research, 3D graphics and rendering, medical imaging, climate modeling, fraud detection, financial modeling, and advanced video processing. [Learn more about Atlantic.net GPU server hosting](https://www.atlantic.net/gpu-server-hosting/)   --- # Windows Server 2025 Hosting: Now Available on the Atlantic.Net Cloud Platform > URL: https://www.atlantic.net/announcements/windows-server-2025-hosting-now-available-on-the-atlantic-net-cloud-platform/ | Published: 2025-02-25 | Updated: 2025-04-20 | Author: Richard Bailey Windows Server 2025 is here, and it’s packed with improvements to security, performance, and features. Even better, you can now get your hands on Windows Server 2025 hosting through the Atlantic.Net Cloud Platform! In this article, we’ll explore everything you need to know about Windows Server 2025, from its different editions to its powerful capabilities. Whether you’re thinking of upgrading or starting fresh, let’s dive in and discover more about this important business server operating system. ![](https://www.atlantic.net/wp-content/uploads/2025/02/Windows-Server-2025-02.jpg) ## What Is Windows Server 2025? So, what exactly *is* Windows Server 2025? It’s the latest and greatest server operating system from Microsoft, designed to give businesses the tools they need to thrive. Think powerful features for virtualization, seamless cloud connectivity, enhanced security, and simplified management. Building on the success of its predecessors, Windows Server 2025 introduces a range of improvements and exciting new capabilities. There are two new editions of Windows Server 2025: - **Windows Server 2025 Datacenter:** A full-featured edition for large-scale deployments, virtualization, and advanced features. Designed for large enterprises with demanding workloads and advanced requirements. It offers advanced features like Storage Spaces Direct, shielded virtual machines, and unlimited virtualization rights. The Datacenter edition is ideal for critical workloads and large-scale deployments. - **Windows Server 2025 Standard:** An edition designed for smaller businesses or those with less demanding needs. It includes essential server features and supports a limited number of virtual machines. Windows Server Standard is suitable for file servers, application servers, and other common server roles. Its important to note that there is also different variations of each version, dependent on what you need. Both Datacenter and Standard come in versions *with* and *without* the “Desktop Experience”. This means: - **With Desktop Experience:** Includes a graphical user interface (GUI) similar to what you’d see on a Windows 11 desktop. This is useful for those who prefer a visual interface or need certain GUI-based applications. - **Without Desktop Experience (Server Core):** This is a command-line only installation, offering a much smaller footprint, reduced attack surface, and better performance for some tasks. Most of our users opt for the Desktop Experience; however, it’s nice to know that the server core version is available for the technically inclined and those who need a smaller footprint, better performance, and enhanced security. ## Benefits of Windows Server 2025 Hosting Choosing Windows Server 2025 hosting, especially through platforms like Atlantic.Net, provides plenty of new technology and numerous advantages to our customers. ### Enhanced Security Windows Server 2025 incorporates built-in security features, including advanced security capabilities like VBS key protection and Credential Guard, to protect your critical workloads and data. These advanced security features help mitigate threats and ensure the integrity of your server environments. ### Optimized Performance Experience improved performance with optimized resource utilization and new features designed for high performance. Whether running Windows Server deployments as file servers, application servers, virtual machines, or domain controllers, you’ll benefit from improved performance and scalability. ### Centralized Management Simplify management with Windows Admin Center, providing a centralized platform for managing your Windows Server environments, including on-premises and Azure Arc connected servers. This centralized management simplifies tasks and improves efficiency. ### Cloud Integration Seamless integration with Azure services allows you to extend your on-premises infrastructure to the cloud, creating hybrid cloud solutions. Azure Arc enables you to manage your servers across different environments from a single pane of glass. ### Cost Effective Solutions Windows Server 2025 hosting, particularly when considering cloud options like those offered by Atlantic.Net, can be a cost effective solution, especially when leveraging virtualization and cloud resources. Choosing the right edition and licensing model can optimize your IT spending. ### Scalability Scale your Windows Server environments easily to meet growing business demands. Whether you need to deploy new VMs or expand your existing infrastructure, Windows Server 2025 provides the scalability you need. ### Latest Enhancements and New Features Windows Server 2025 includes the latest enhancements and new features, ensuring you have access to the most up-to-date technology. These new versions bring improved performance, security, and management capabilities. ## Windows Server Licenses Understanding Windows Server licenses is crucial for compliance and cost optimization, especially when considering long-term usage and upgrades. [Atlantic.Net](https://www.atlantic.net/) makes this process super simple. With our Windows Server hosting plan there are no contracts, and you can pay-as-you-go, meaning you only pay for the resources you use. It doesn’t matter if you use the server for 2 minutes, 2 months or 2 years; the licensing cost is included with the pay-as-you-go cost. This approach offers a level of flexibility similar to having active software assurance, allowing you to adapt your server usage without being locked into fixed licensing costs. There are no hidden extras! ## Windows Server 2025 Key Features ### Windows Admin Center Windows Admin Center simplifies the management of your Windows Server environments with its web-based interface. From a single dashboard, you can manage servers across on-premises, Azure, and other cloud environments, performing essential tasks like configuring network settings, managing storage volumes and virtual disks, and monitoring server health and performance. Windows Admin Center has matured into a powerful product. It’s not just about simplifying routine tasks; it’s about giving you deeper control and insights. Plus, with its extensible architecture, you can add even more functionality through a growing library of extensions, tailoring Windows Admin Center to your specific needs. ### Security Features in Windows Server 2025 Security, as always, is another top priority in Windows Server 2025. The operating system includes a range of general availability built-in security features to protect your data and infrastructure: - **Credential Guard:** Credential Guard protects credentials from advanced threats by isolating them in a secure virtualized environment, similar to the concept of secure enclaves, and reinforces a zero-trust security model. - **VBS Key Protection:** VBS Key Protection safeguards your cryptographic keys by storing them in an isolated, virtualized environment, preventing access even if the operating system is compromised. This adds a crucial layer of defense against sophisticated attacks targeting your sensitive data. - **Transport Layer Security (TLS) Connections:** Windows Server 2025 supports the latest TLS versions, including TLS 1.3, ensuring that all communication between your servers and client devices is encrypted with the strongest protocols available. This protects your data from eavesdropping and tampering, maintaining confidentiality and integrity. - **Network Security:** Windows Server 2025 strengthens network security with features like Network ATC, which simplifies network configuration and helps prevent misconfigurations that could lead to vulnerabilities. This, combined with enhanced firewall capabilities and support for the latest security protocols, provides robust protection against unauthorized network access. - **Enhanced Security:** Windows Server 2025 includes numerous enhancements to improve the overall security posture of your server environments. Beyond the features mentioned above, Microsoft has implemented numerous enhancements throughout the operating system to harden its defenses and reduce its attack surface, including improvements to user access control, threat detection, and exploit mitigation, providing a more secure foundation for your critical workloads. ### Windows Server 2025 Virtuailzation Windows Server 2025 provides a powerful platform for both virtual machines (VMs) and containers, offering enhanced performance and flexibility for your workloads. Hyper-V, Microsoft’s virtualization technology, is deeply integrated, allowing you to easily create and manage VMs. This latest version boasts significant performance enhancements, including faster VM startup times and reduced I/O overhead. A standout feature is GPU partitioning, enabling you to share a physical GPU across multiple VMs, ideal for demanding workloads like AI and machine learning. Beyond VMs, Windows Server 2025 advances containerization with improved Windows Containers and enhanced Kubernetes support. This allows you to run containerized applications more efficiently and manage them at scale. Whether you’re consolidating your server infrastructure with VMs or embracing modern containerized deployments, Windows Server 2025 delivers the virtualization capabilities you need. ### Active Directory Active Directory remains a fundamental reason why our customer choose Windows Server environments, and Windows Server 2025 continues the strong support for on-premise AD. Active Directory (AD) provides the essential services for managing users, computers, other devices and other resources within your network using centralized authentication and authorization. AD ensures that only authorized users and devices can access specific resources, enhancing security and simplifying access control. Windows Server 2025 introduces several enhancements to Active Directory, including improved performance for domain controllers, stronger security for machine accounts, and better integration with Azure Active Directory or LDAP client. These improvements make AD much more stable on cloud deployments, especially for larger organizations and those with hybrid cloud environments. ### Powering Your Applications with Windows Server 2025 Windows Server 2025 provides a robust foundation for your application servers, offering the high performance, scalability, and reliability needed to support your critical business applications. Whether you’re running web applications, a database SQL Server enterprise resource planning (ERP) systems, or custom-built cloud applications, Windows Server 2025 delivers the features and capabilities you need. ### Enhanced Application Performance One of the things that makes Windows Server 2025 shine is its sheer speed. Microsoft has fine-tuned the performance, so you get lightning-fast network speeds, minimal delays, and super-efficient memory management. This means your applications will run smoother and respond quicker than ever, keeping your users happy and your business running smoothly. ### Support for Diverse Applications But speed isn’t everything. Windows Server 2025 is also incredibly versatile. It can handle everything from traditional on-premises applications to the latest cloud-native ones. Whether your developers love.NET, Java, or open-source tools, they’ll find the flexibility they need to build and deploy amazing applications. ### Simplified Deployment and Management And speaking of developers, Microsoft has made their lives easier too. Setting up and managing your application servers is a breeze with familiar tools like Server Manager and the super-handy Windows Admin Center. And if you’re in the cloud with a provider like [Atlantic.Net](https://www.atlantic.net/) it’s even simpler, thanks to their intuitive interfaces and automated tools. ### Advanced Storage Capabilities Worried about your data? Don’t be. Windows Server 2025 has advanced storage features like Storage Spaces Direct, which lets you create super-reliable storage clusters. This means your critical application data is always safe and sound, even if a hard drive decides to take a break. ### Enhanced Security for Applications Of course, security is a top priority. Windows Server 2025 comes with a whole arsenal of security features to keep your applications and data locked down tight. Credential Guard, VBS enclaves, and confidential attributes are just some of the tools that help prevent unauthorized access and protect your sensitive information. ### Network Optimization for Applications Windows Server 2025 includes features that optimize network performance for your applications. Network ATC simplifies network configuration and management, while support for the latest TLS versions ensures secure communication between your application servers and clients. ### Developer-Friendly Features To help support developers, Microsoft introduced a new feature called Dev Drive. It’s a special storage volume that’s optimized for development work, making coding and testing faster and more efficient. ### Windows Server 2025: The Ideal Platform for Your Applications With its comprehensive set of features, enhanced performance, and robust security, Windows Server 2025 is the ideal platform for running your business-critical applications. Windows Server 2025 provides the foundation you need for migrating existing applications or building new ones. ### Upgrading to Windows Server 2025 Upgrading to the latest version of Windows Server on Atlantic.Net involves a streamlined process that leverages our powerful cloud platform. Here’s how it works: 1. **Modify Service Plan:** If you need to upgrade your hardware specs (CPU, RAM, storage) to meet the requirements of Windows Server 2025, you can easily modify your service plan through the Atlantic.Net Cloud Platform UI. This ensures your server has the necessary resources to run the new operating system efficiently. 2. **Deploy New 2025 Instance:** Once your service plan is updated, you can deploy a fresh instance of Windows Server 2025. Atlantic.Net offers a variety of pre-configured images, including the popular Standard edition, allowing you to quickly spin up a new server with the desired configuration. This gives you the advantage of starting with a pristine, optimized installation of the latest Windows Server version, free from any potential legacy issues. 3. **Restore from Snapshot:** To preserve your existing data and applications, you’ll need to restore them from a snapshot. Atlantic.Net’s snapshot feature allows you to capture the entire state of your existing Windows Server instance, including the applications, and data. You can then restore the relevant data from this snapshot to your new Windows Server 2025 instance, ensuring a seamless transition without data loss. This approach eliminates the need for traditional in-place upgrades, simplifying the process and minimizing downtime. While Atlantic.Net handles the underlying infrastructure, it’s still recommended to verify that your applications are compatible with Windows Server 2025 before initiating the upgrade. **Atlantic.Net is proud to offer Windows Server 2025 hosting on our award winning cloud platform.** Whether you’re looking to upgrade your existing infrastructure or deploy new Windows Server environments, Atlantic.Net provides the tools and resources you need to succeed. Our cloud platform offers scalability, security, and cost-effectiveness, making it the ideal choice for your [Windows Server 2025 deployments](https://cloud.atlantic.net). **[Contact Atlantic.Net today](https://www.atlantic.net/about-us/corporate-contact/) to learn more about our Windows Server 2025 hosting solutions.** --- # The 8 Best VPN Services for Post-Quantum Security in 2026 > URL: https://www.atlantic.net/managed-services/top-vpn-services-in-your-guide-to-the-best-options-available/ | Published: 2025-03-04 | Updated: 2026-03-18 | Author: Dr. Assad Abbas Modern privacy needs call for protocols strong enough to handle the rise of quantum computing. By 2026, secure VPNs are expected to offer more than just AES encryption. They should also provide post-quantum protection and proven no-logs policies. This guide reviews leading VPN services, focusing on connection speed, transparency through audits, and how well they keep data safe across worldwide networks. [Virtual Private Networks (VPNs)](https://www.atlantic.net/vps-hosting/what-is-vpn/) have become an essential part of the digital world. Once viewed mainly as advanced security tools, they are now used widely in everyday life. People use VPNs to secure public Wi-Fi, reduce online tracking, access content restricted by location, and protect sensitive data while communicating online. In 2026, the VPN market is defined less by basic encryption claims and more by measurable security standards such as independently verified no-logs audits and early adoption of post-quantum encryption frameworks. Many services are available, each with different features that balance security, speed, and ease of use. With so many choices, selecting the right option depends on understanding what VPNs are meant for and which features are most important. This guide explains VPN basics, their uses, and key factors for choosing a service, and compares leading providers on security, privacy, speed, protocol transparency, encryption standards, streaming, torrenting, and pricing. ## What Is a VPN? A VPN is a service that ensures the confidentiality of Internet activity by encrypting transmitted data and masking the user’s IP address. This reduces the ability of websites, Internet service providers, and third parties to monitor or profile online behavior. The VPN establishes an encrypted tunnel between a user’s device and a remote server, and all traffic passes through this tunnel before reaching its destination. In 2026, leading VPNs are evaluated not only on AES-256 encryption but also on their readiness for post-quantum cryptography and independently verified no-logs infrastructure. Modern VPN services use secure protocols such as WireGuard and OpenVPN to protect data while maintaining speed. Some providers are beginning to integrate quantum-resistant key exchange mechanisms to future-proof encrypted connections. When a VPN connection is established, websites see the server’s IP address instead of the user’s actual address, and encryption protects data even on public Wi-Fi networks. ## Benefits of Using a VPN A VPN provides several benefits that improve both security and everyday Internet use. ### Access to Global Content VPNs allow connections through servers in different regions to access websites, applications, and streaming services that may be location-restricted. ### Protection Against Data Leaks Advanced VPNs include DNS leak protection, kill switches, and private DNS. These features prevent exposure if the VPN connection drops. Leading providers now combine these tools with verified no-logs systems to ensure activity data is not stored or retrievable. ### Consistent Performance for Streaming and Gaming Some Internet providers slow down high-bandwidth activities. VPNs can reduce throttling, improving video playback and gaming stability. ### Secure Online Transactions VPNs add protection to financial activity, securing payment details and login credentials on public networks. Stronger protocol implementations also protect session keys against future cryptographic threats. ### Support for Remote Work and Collaboration VPNs secure remote access to business systems. Enterprise-focused services now prioritize scalable infrastructure and audited encryption frameworks to support distributed teams. ### Greater Anonymity in Daily Use VPNs reduce profiling and targeted advertising by masking browsing patterns. Providers with transparent audit reports offer stronger assurances that user data is not retained. ## Choosing the Best VPN Selecting a VPN depends on several important factors. Each of these affects the level of security, performance, and convenience a service can provide. In 2026, evaluation standards increasingly prioritize post-quantum readiness and independently verified no-logs audits alongside traditional performance metrics. Typically, the following factors help select the best VPN service. ### Server Network and Locations A broad and well-distributed server network improves both access and connection quality. Servers located closer to the user generally reduce delays. In addition, overall performance also depends on server load and the quality of connection routes. ### No-Logs Policy and Transparency Clear data handling policies are essential when selecting a VPN. Providers with independent audits and verified no-logs practices offer stronger privacy. Search visibility and trust signals now favor VPNs that publish third-party audit reports and regular transparency updates. Advanced measures such as RAM-only servers and private DNS further reduce the risk of storing or exposing user information. ### Encryption and Protocols Strong encryption is a core element of VPN security. AES-256 is widely regarded as a reliable standard. Similarly, modern protocols like [WireGuard](https://www.paloaltonetworks.com/cyberpedia/what-is-wireguard) and [OpenVPN](https://helpcenter.trendmicro.com/en-us/article/tmka-11325) combine strong protection with stable performance, while lighter options such as Lightway may improve speed on weaker connections. Some providers are also integrating hybrid or post-quantum key exchange mechanisms to strengthen long-term cryptographic resilience. ### Post-Quantum Security Readiness As quantum computing technology advances, some VPN providers are adopting quantum-resistant cryptographic algorithms or hybrid key-exchange methods. These steps help protect encrypted data from future decryption and support long-term privacy. ### Additional Security Features Some VPNs provide extra tools that strengthen protection. For example, a kill switch blocks data leaks if the connection drops. Similarly, split tunneling permits certain apps to use VPN while others connect directly. In addition, features such as multi-hop routing, stealth modes, and ad blocking provide additional safety in restricted or unsafe networks. Emerging implementations also include quantum-resistant handshake layers for future-proof protection. ### Price and Connection Limits Cost is another important factor. Long-term plans are usually more economical, while monthly subscriptions provide flexibility. Users should also check the number of devices that can connect at once. Some providers allow unlimited connections or offer dedicated IP addresses for an additional cost. ### Device Support and Ease of Use A good VPN should work across all major platforms, including Windows, macOS, iOS, Android, and Linux. Similarly, browser extensions and router support add flexibility for different use cases. In addition, an easy interface, auto-connect options, and clear access to advanced settings make the service more practical for everyday use. ### Independent Reviews and User Feedback Independent audits, transparency reports, and technical tests are useful for checking the accuracy of provider claims. Similarly, user reviews provide practical insights by highlighting issues such as regional speed differences, service reliability, or problems with specific internet providers. Priority should be given to providers with publicly verifiable audit histories rather than marketing claims alone. ### Audit Frequency and Verification Standards When you compare services, check how often they are audited and whether the audits cover infrastructure, no-logs policies, and protocol use. Ongoing, independent security audits are more valuable than one-time certifications. ## Top VPN Services in 2026 Below are five leading VPN providers. Each is strong in different areas, from speed and streaming to privacy and security. This list prioritizes providers that demonstrate verified no-logs audits and measurable progress toward post-quantum encryption readiness. ![](https://www.atlantic.net/wp-content/uploads/2026/03/ExpressVPN.png) ### 1. [ExpressVPN](https://www.expressvpn.com) ExpressVPN is positioned as a premium provider in 2026, with a focus on independently verified no-logs audits and protocol-level security enhancements designed for long-term cryptographic resilience. **Best for**: streaming geo-restricted content, gaming, secure and private browsing, and bypassing censorship Take a look at the ExpressVPN dashboard, where you can connect to secure VPN servers and manage your privacy settings in one place. ![ExpressVPN dashboard](https://www.atlantic.net/wp-content/uploads/2025/03/ExpressVPN-dashboard.jpg) Image Source: ExpressVPN **Why you should choose it**: ExpressVPN offers fast connections in 105 countries. It works reliably with Netflix, Disney+, Hulu, and BBC iPlayer. Its Lightway protocol is optimized for performance and designed to support future cryptographic upgrades. **Security and privacy**: AES-256 encryption, secure protocols, password manager, kill switch, split tunneling, private DNS, and an independently audited no-logs policy. The provider emphasizes third-party audit verification and infrastructure transparency, aligning with 2026 search priorities around verified no-logs compliance. **Everyday use**: Easy-to-use app that performs well on computers, phones, and routers. Good choice if you want a simple and reliable VPN. **Trade-offs**: Higher cost than many competitors. Limited to 8 devices at the same time. ![](https://www.atlantic.net/wp-content/uploads/2026/03/Private_Internet_Access_Logo.png) ### 2. [Private Internet Access (PIA)](https://www.privateinternetaccess.com) Private Internet Access is known for its transparency-first approach, offering open-source apps and publicly documented privacy practices. It appeals to users who prioritize verifiable no-logs policies and granular control over encryption settings. **Best for**: Transparency, advanced controls, and secure torrenting. Discover the Private Internet Access interface designed to adjust general preferences, configure network settings, and enhance online security. ![Private Internet Access](https://www.atlantic.net/wp-content/uploads/2025/03/Private-Internet-Access.jpg) Image Source: Private Internet Access **Why you should choose it**: PIA has one of the largest server networks, covering 91 countries and all 50 U.S. states. It gives advanced settings and port forwarding for P2P use. Its open-source applications allow public inspection of code, strengthening transparency and trust signals. **Security and privacy**: AES-128/256 encryption, WireGuard and OpenVPN protocols, kill switch, open-source apps, and a no-logs policy proven in court. The provider emphasizes verifiable no-logs documentation and configurable encryption settings, appealing to users focused on audit-backed privacy standards. **Everyday use**: Flexible and customizable, ideal for power users. Affordable on long-term plans. **Trade-offs**: May appear complex for beginners. Streaming is possible, but sometimes it needs switching between servers. ![](https://www.atlantic.net/wp-content/uploads/2026/03/surfshark.png) ### 3. [Surfshark VPN](https://surfshark.com) Surfshark is a value-focused VPN that offers many features, including unlimited device connections and no-logs claims that have been independently audited. It is a good choice for people who want to cover their entire household without sacrificing privacy controls. **Best for**: Households and multi-device streaming. This screen shows the Surfshark dashboard, where you can secure your internet connection, monitor personal data safety, and manage your cybersecurity tools. ![Surfshark dashboard](https://www.atlantic.net/wp-content/uploads/2025/03/Surfshark-dashboard.jpg) Image Source: Surfshark **Why you should choose it**: Surfshark offers unlimited device connections with one subscription. It also provides fast speeds and good streaming access. Its infrastructure supports modern protocols optimized for both performance and encryption integrity. **Security and privacy**: AES-256 encryption, WireGuard/OpenVPN/IKEv2 protocols, kill switch, MultiHop, ad/tracker blocking, and optional static IP. The provider highlights third-party audit verification and advanced routing features designed to strengthen data confidentiality. **Everyday use**: Excellent value, particularly for households. Easy to set up and run on many devices. **Trade-offs**: Operates under the jurisdiction of the Netherlands ([14 Eyes alliance](https://tuta.com/blog/fourteen-eyes-countries)). Renewal cost is higher than in the first term. ![](https://www.atlantic.net/wp-content/uploads/2026/03/proton-vpn.png) ### 4. [Proton VPN](https://protonvpn.com) Proton VPN focuses on transparency and privacy, offering open-source apps and infrastructure that have been independently reviewed. People often choose it if they care about strong privacy laws and clear audit records. **Best for**: Privacy-focused users, researchers, and those looking to bypass restrictions. Take a closer look at the Proton VPN interface designed to control protocols, enable kill switch protection, and customize advanced networking options. ![Proton VPN dashboard](https://www.atlantic.net/wp-content/uploads/2025/03/Proton-VPN-dashboard.jpg) Image Source: Proton VPN **Why choose it**: Based in Switzerland with strong privacy laws, open-source apps, independent audits, and Secure Core routing through privacy-friendly countries. Its Secure Core architecture routes traffic through hardened data centers, reducing exposure to network-based attacks. **Security & privacy**: AES-256 encryption, WireGuard/OpenVPN protocols, kill switch, NetShield malware/tracker filtering, and transparency reports. The provider emphasizes verified no-logs audits and publishes regular transparency updates to support its privacy claims. **Everyday use**: Paid plans deliver excellent speeds and streaming access; free plan offers unlimited data but fewer servers and slower speeds. **Trade-offs**: Paid plans are mid- to high-priced; Secure Core routing can reduce speed due to a multi-hop design. ![](https://www.atlantic.net/wp-content/uploads/2026/03/Mullvad-VPN.png) ### 5. [Mullvad VPN](https://mullvad.net/en) Mullvad is known for allowing users to create accounts anonymously using random numeric IDs instead of personal information. This helps keep your identity separate from the start. **Best for**: Maximum anonymity and minimal user data collection. Here is the Mullvad account panel, which lets you manage devices, download VPN clients, and maintain complete control over your privacy setup. ![Mullvad dashboard](https://www.atlantic.net/wp-content/uploads/2025/03/Mullvad-dashboard.jpg) Image Source: Mullvad VPN **Why choose it**: No personal information required; accounts are generated via random numbers. Accepts cash and cryptocurrency payments. Its account model is designed specifically for users who want to avoid email registration or identity-based billing records. **Security and privacy**: AES-256 encryption, WireGuard/OpenVPN protocols, kill switch, multi-hop, RAM-only servers, traffic obfuscation (DAITA), and quantum-resistant tunnels. The service documents its cryptographic approach and highlights post-quantum key exchange experimentation for long-term data protection. **Everyday use**: Lightweight, fast apps; strong torrenting privacy with port forwarding support. **Trade-offs**: Smaller network (~695 servers in 49 countries); limited streaming access compared to competitors. ![](https://www.atlantic.net/wp-content/uploads/2026/03/NordLayer.png) ### 6. [NordLayer](https://nordlayer.com/) NordLayer is a VPN made for businesses that need to grow and manage remote teams. It offers centralized management, secure remote access, and helps organizations control users and segment their networks with encryption. **Best for**: Companies that want to scale, keep remote teams secure, and control their enterprise networks. See the NordLayer control panel, which lets you manage gateways, monitor server status, and organize user access across locations. ![NordLayer dashboard](https://www.atlantic.net/wp-content/uploads/2025/03/NordLayer-dashboard.avif) Image Source: NordLayer **Why choose it**: NordLayer is built for organizations and offers cloud deployment, dedicated gateways, and team access controls. It makes user management easy to scale, making it well-suited for companies with hybrid or remote teams. **Security and privacy**: NordLayer uses AES-256 encryption, supports WireGuard, and offers zero-trust access controls and multi-factor authentication. Its security practices are audited, and it adheres to strict logging policies and encryption standards to meet compliance requirements. **Everyday use**: IT admins get a central dashboard, onboarding employees is simple, and the platform works across different devices. **Trade-offs**: NordLayer is not meant for personal streaming or individual use. Its pricing is designed for businesses, not individual users. ![](https://www.atlantic.net/wp-content/uploads/2026/03/cyberghost.png) ### 7. [CyberGhost VPN](https://www.cyberghostvpn.com/) CyberGhost is a privacy-focused VPN with a wide range of servers and clear transparency practices. It’s a good choice for people who want ready-made profiles for streaming, torrenting, and secure browsing, without needing to set things up themselves. **Best for**: People who want easy streaming, beginners, and anyone looking for lots of server options. Here is the CyberGhost control panel, which lets you manage privacy tools, update security settings, and keep your device protected from threats. ![CyberGhost dashboard](https://www.atlantic.net/wp-content/uploads/2025/03/CyberGhost-dashboard.png) Image Source: CyberGhost **Why choose it**: CyberGhost has thousands of servers in many countries and offers special profiles for streaming and torrenting in its apps. The organized server categories make it easy to find what you need, while still keeping up-to-date security standards. **Security and privacy**: CyberGhost uses AES-256 encryption, supports WireGuard, OpenVPN, and IKEv2 protocols, and includes a kill switch and DNS leak protection. It also publishes independent transparency reports and has passed no-logs audits and infrastructure reviews, demonstrating that it handles data responsibly. **Everyday use**: The interface is easy to use, with clearly marked streaming and P2P servers. It’s a good fit for people who like having guided setup options. **Trade-offs**: You get better value with longer-term plans, while monthly prices are higher. There are fewer advanced customization options than those available in VPNs aimed at developers. ![](https://www.atlantic.net/wp-content/uploads/2026/03/IVPN-logo.png) ### 8. [IVPN](https://www.ivpn.net/en/) IVPN collects very little data, undergoes independent audits, and is open about its operations. The service uses strong privacy controls and offers simple subscription plans. **Best for**: People who care deeply about privacy and want a VPN with proven no-logs policies. Here’s the IVPN app dashboard, where you can manage server selection, enable privacy tools, and ensure a fast and secure browsing experience. ![IVPN dashboard](https://www.atlantic.net/wp-content/uploads/2025/03/IVPN-dashboard.jpg) Image Source: IVPN **Why choose it**: IVPN has a clear no-logs policy, openly shares its security documentation, and offers multi-hop routing. Its system is built to keep metadata to a minimum and protect your privacy at every connection point. **Security and privacy**: IVPN uses AES-256 encryption, supports WireGuard and OpenVPN, and includes a kill switch, multi-hop routing, and anti-tracker tools. Third-party audits verify its no-logs policy. IVPN also explains how its encryption works and how it plans to keep data secure in the future. **Everyday use**: IVPN has a simple, easy-to-use interface and works on different devices. It is designed for privacy, not for streaming services. **Trade-offs**: IVPN has fewer servers than some larger VPNs and does not prioritize streaming access. ## Comparison of Leading VPN Services (Security, Performance, Coverage) | **Provider** | **Security & Privacy** | **Speed & Performance** | **Streaming Access** | **Torrenting Support** | **Pricing** | **Server Coverage** | | --- | --- | --- | --- | --- | --- | --- | | ExpressVPN | AES-256, Lightway/WireGuard/OpenVPN, kill switch, split tunneling, private DNS, independently audited no-logs | Consistently high speeds globally | Netflix, BBC iPlayer, Disney+, Hulu | Full P2P support | Premium: up to 8 devices | ~2,000+ servers in 105 countries | | Private Internet Access (PIA) | AES-128/256, WireGuard/OpenVPN, kill switch, open-source apps, court-verified no-logs | Fast; highly configurable | Netflix, Disney+, BBC iPlayer (may require switching) | Full P2P with port forwarding | Budget-friendly; up to 10 devices | 10,000+ servers in 91+ countries | | Surfshark VPN | AES-256, WireGuard/OpenVPN/IKEv2, kill switch, MultiHop, CleanWeb, audited no-logs | Fast and stable; unlimited devices | Netflix, BBC iPlayer, Disney+, Hulu | Full P2P support | Affordable initial term; higher renewal | 3,200+ servers in 100+ countries | | Proton VPN | AES-256, WireGuard/OpenVPN, kill switch, Secure Core, NetShield, open-source, independently audited | Premium plans are fast; the free tier is slower | Netflix, BBC iPlayer, Disney+ (premium) | P2P on select servers | Free tier; paid mid- to high-priced | 2,000+ servers in 65+ countries | | Mullvad | AES-256, WireGuard/OpenVPN, kill switch, multi-hop, RAM-only servers, quantum-resistant tunnels | Fast; smaller network | Limited streaming | Full P2P with port forwarding | Flat €5/month; up to 5 devices | ~695 servers in 49 countries | | NordLayer | AES-256, WireGuard-based protocol, zero-trust access controls, MFA, audited infrastructure | Optimized for enterprise stability | Not streaming-focused | Business file transfer support | Business-tier pricing | Global cloud-based gateways | | CyberGhost | AES-256, WireGuard/OpenVPN/IKEv2, kill switch, DNS leak protection, transparency reports | Strong speeds; optimized streaming profiles | Netflix, BBC iPlayer, Disney+ | Dedicated P2P servers | Tiered pricing; long-term discounts | 9,000+ servers in 90+ countries | | IVPN | AES-256, WireGuard/OpenVPN, kill switch, multi-hop, audited no-logs | Stable speeds; privacy-focused routing | Limited streaming focus | P2P supported | Standard and Pro plans | Servers in 30+ countries | ## Encryption Protocol Comparison (WireGuard vs. Post-Quantum Readiness) | **Provider** | **WireGuard Support** | **OpenVPN Support** | **Proprietary Protocol** | **Post-Quantum / Hybrid Key Exchange** | **Verified No-Logs Audit** | | --- | --- | --- | --- | --- | --- | | ExpressVPN | Yes | Yes | Lightway | Hybrid-ready infrastructure design | Yes | | Private Internet Access (PIA) | Yes | Yes | No | Not publicly specified | Yes (court-verified) | | Surfshark VPN | Yes | Yes | No | Not publicly specified | Yes | | Proton VPN | Yes | Yes | No | Not publicly specified | Yes | | Mullvad | Yes | Yes | No | Experimental quantum-resistant tunnels | Yes | | NordLayer | Yes | Yes | No | Enterprise-focused cryptographic controls | Yes | | CyberGhost | Yes | Yes | No | Not publicly specified | Yes | | IVPN | Yes | Yes | No | Not publicly specified | Yes | ## Budget-Friendly Options Some VPNs are more expensive, while others prioritize affordability without compromising reliability. ExpressVPN is more expensive but is valued for its speed, global coverage, and independently audited no-logs policy. Similarly, Surfshark offers a lower-cost alternative with long-term plans and unlimited connections, which makes it practical for households. Private Internet Access (PIA) is also competitively priced on extended plans, offering advanced configuration options at a lower monthly cost. Mullvad takes a different approach: a flat €5 monthly rate, no contracts, and no personal details required, making it attractive to those who prefer simplicity and privacy. CyberGhost frequently discounts long-term subscriptions, positioning itself as a cost-effective option for streaming-focused users. IVPN offers straightforward Standard and Pro plans, prioritizing transparency over promotional pricing models. In addition, Proton VPN provides flexibility with a free plan suitable for basic use and paid plans that deliver faster speeds and broader server access. NordLayer operates on a business-tier pricing structure designed for teams rather than individual users, making it suitable for organizations that require scalable encrypted access instead of budget personal use. When considering costs, long-term subscriptions usually reduce the effective monthly price. Likewise, avoiding extras such as dedicated IP addresses or advanced add-ons helps keep expenses low. Services that allow unlimited connections, such as Surfshark, often provide better household value, while flat-rate models like Mullvad appeal to users who prefer predictable pricing without promotional tiers. ## Specialty VPNs Some VPN services perform better for specific tasks, particularly streaming, torrenting, and secure business connectivity. The providers mentioned above are discussed from the perspectives below. ### VPNs for Streaming For streaming, key factors include a large server network, consistent platform unblocking, high throughput, and protection against throttling. To that end, ExpressVPN is a suitable option because it delivers reliable access and smooth playback across major services. Similarly, Surfshark is useful for households because it allows unlimited devices and maintains good streaming performance. CyberGhost also performs well in this category, offering dedicated streaming-optimized servers within its apps. In addition, Proton VPN’s paid plans can provide stable access, though users may need to test different servers for the best results. Providers such as PIA and Surfshark also offer dedicated IP addresses, which can be helpful in special cases, though most users do not require them. IVPN and Mullvad are less focused on streaming optimization, prioritizing privacy controls instead. NordLayer is designed for business environments and is not intended for consumer streaming use cases. ### VPNs for Torrenting File sharing through torrents requires high privacy and a stable connection. Therefore, choosing the right VPN is important. Torrenting requires measures such as a kill switch and consistent speeds for smooth transfers. PIA and Mullvad are suitable options because they support port forwarding and provide strong privacy protection. Similarly, ExpressVPN offers fast and secure P2P connections, though it does not include port forwarding. Surfshark and CyberGhost both allow P2P traffic on supported servers, making them practical for general users. IVPN supports torrenting with a privacy-first configuration, while NordLayer is structured for secure corporate data transfer rather than public torrent networks. Finally, keeping the kill switch enabled is important to prevent data leaks if the VPN connection drops. ### Other VPN Options For users with specific needs beyond entertainment, NordLayer provides centralized management and encrypted access for remote teams. IVPN and Mullvad appeal to privacy-focused users who prefer minimal data collection and simplified account models. However, when evaluating any provider, priority should be given to verified no-logs audits, transparency in encryption protocols, and infrastructure design rather than marketing claims alone. For stronger privacy, reliable streaming, scalable business deployment, and advanced features, services such as ExpressVPN, Surfshark, Proton VPN, Mullvad, PIA, CyberGhost, IVPN, and NordLayer offer more complete options. ## Final Thoughts Choosing the right VPN depends on your specific needs, whether for privacy, streaming, torrenting, business use, or everyday browsing. In 2026, priority should also be given to post-quantum encryption readiness and independently verified no-logs audits, not just basic AES claims. Security, speed, server coverage, device support, and cost are all important factors to consider. ExpressVPN offers reliable global coverage and fast performance. Similarly, Surfshark provides good value with unlimited device connections. Mullvad and PIA focus on strong privacy and advanced features, while Proton VPN offers flexible options with both free and paid plans. CyberGhost stands out for streaming-optimized servers, IVPN emphasizes audit-backed privacy controls, and NordLayer supports scalable encrypted access for business teams. For lighter or basic use, alternatives such as [Hotspot Shield](https://hotspotshield.com/) and [TunnelBear](https://www.tunnelbear.com/) may be suitable, although they have limitations in privacy and advanced functionality. Providers without transparent audit documentation or clear disclosures of encryption protocols should be evaluated cautiously. By comparing providers carefully and considering your priorities, you can select a VPN that ensures secure, private, and resilient Internet access. Hotspot Shield focuses on speed with its Catapult Hydra protocol, making it suitable for casual browsing and light streaming. Similarly, TunnelBear offers an easy-to-use interface and clear connection indicators, which are helpful for beginners who want simplicity over advanced features. However, these VPNs have limits in privacy, server coverage, and advanced options. For stronger privacy assurances, verified no-logs audits, broader protocol support (including WireGuard implementations), and scalable deployment options, services like ExpressVPN, Surfshark, Proton VPN, Mullvad, PIA, CyberGhost, IVPN, and NordLayer provide more complete solutions.   --- # How to Use RASA for Building Scalable Chatbots with Real-time Data on Atlantic.Net GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-use-rasa-for-building-scalable-chatbots-with-real-time-data-on-atlantic-net-gpu-server/ | Published: 2025-03-06 | Updated: 2026-05-04 | Author: Hitesh Jethva Building scalable chatbots that can handle real-time data is critical for many businesses today. RASA, an open-source conversational AI framework, is a powerful tool for creating such chatbots. This guide will walk you through the process of setting up RASA on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/), integrating it with real-time data, and deploying it for scalable usage. ## Prerequisites Before diving into the setup, ensure you have the following: - An Atlantic.Net Cloud GPU server running Ubuntu 24.04. - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Step 1: Install Python and Additional Dependencies The default Python version in Ubuntu 24.04 is Python 3.12, which is incompatible with some of the libraries required by RASA and HuggingFace. Therefore, we need to install Python 3.10. **1. Add the Python Repository** First, add the deadsnakes PPA to your system to access Python 3.10: ```bash add-apt-repository ppa:deadsnakes/ppa ``` **2. Update the Package Index** Update the package index to ensure you have the latest package listings: ```bash apt update -y ``` **3. Install Python 3.10 and Essential Libraries** Install Python 3.10 along with essential libraries. ```bash apt install python3.10 python3.10-venv python3.10-dev -y ``` **4. Create a Virtual Environment** Create a virtual environment to isolate your RASA installation. ```bash python3.10 -m venv rasa-env source rasa-env/bin/activate ``` ## Step 2: Install RASA and Additional Packages With the virtual environment activated, install RASA and other necessary packages. ```bash pip install rasa pip install fastapi uvicorn websockets ``` ## Step 3: Initialize and Train the RASA Model 1. Initialize a new RASA project. ```bash rasa init --no-prompt ``` This command creates a new RASA project with default configurations and sample data. 2. Train the RASA model using the sample data. ```bash rasa train ``` This command trains the model and saves it in the models directory. ## Step 4: Create a FastAPI Server for Real-time Communication To enable real-time communication with the chatbot, we’ll use FastAPI to create a WebSocket server. Create a new file named **rasa_server.py:** ```bash nano rasa_server.py ``` Add the following code to the file: ```bash from fastapi import FastAPI, WebSocket from rasa.core.agent import Agent from rasa.utils.endpoints import EndpointConfig import asyncio # Load the Rasa agent agent = Agent.load("models", action_endpoint=EndpointConfig(url="http://localhost:5055/webhook")) app = FastAPI() # Root endpoint @app.get("/") async def root(): return {"message": "Welcome to the Chatbot Server!"} @app.websocket("/chat") async def chat(websocket: WebSocket): await websocket.accept() while True: data = await websocket.receive_text() response = await agent.handle_text(data) await websocket.send_text(response[0]['text']) ``` This script sets up a FastAPI server that loads the RASA model and handles WebSocket connections for real-time chat. ## Step 5: Create Custom Actions Custom actions allow your chatbot to perform specific tasks. Create a new file named actions.py: ```bash nano actions.py ``` Add the following code to define a custom greeting action: ```bash from rasa_sdk import Action, Tracker from rasa_sdk.executor import CollectingDispatcher class ActionGreet(Action): def name(self) -> str: return "action_greet" def run(self, dispatcher: CollectingDispatcher, tracker: Tracker, domain: dict) -> list: dispatcher.utter_message(text="Hello! How can I assist you today?") return [] ``` ## Step 6: Run the RASA Action Server and API Run the RASA action server in the background: ```bash rasa run actions & ``` Run the RASA API server: ```bash rasa run --enable-api & ``` ## Step 7: Start the FastAPI Server Start the FastAPI server using Uvicorn: ```bash uvicorn rasa_server:app --host 0.0.0.0 --port 8000 --reload & ``` This command starts the server on **0.0.0.0:8000** with auto-reload enabled. ## Step 8: Install WebSocat for WebSocket Testing WebSocat is a command-line tool for testing WebSocket connections. Download and install it: ```bash wget https://github.com/vi/websocat/releases/download/v1.14.0/websocat.x86_64-unknown-linux-musl mv websocat.x86_64-unknown-linux-musl /usr/bin/websocat chmod 755 /usr/bin/websocat ``` ## Step 9: Test the Chatbot Server **1. Test the Root Endpoint** Ensure the FastAPI server is running by testing the root endpoint: ```bash curl http://localhost:8000 ``` You should see the following response: ```bash INFO: 127.0.0.1:52546 - "GET / HTTP/1.1" 200 OK {"message":"Welcome to the Chatbot Server!"} ``` **2. Test the WebSocket Connection** Use WebSocat to test the WebSocket connection: ```bash websocat ws://localhost:8000/chat ``` **3. Start a conversation with the chatbot:** ```bash > Hello < Hey! How are you? > I am fine. What are you doing? < I am a bot, powered by Rasa. ``` ## Conclusion You have successfully set up a scalable chatbot using RASA on an Ubuntu 24.04 GPU server. The integration with FastAPI enables real-time communication, making the chatbot suitable for various applications. With additional steps like containerization and orchestration, you can further enhance the scalability and reliability of your chatbot in a production environment. --- # How to Automate Data Preprocessing for Machine Learning with Apache Airflow > URL: https://www.atlantic.net/gpu-server-hosting/how-to-automate-data-preprocessing-for-machine-learning-with-apache-airflow/ | Published: 2025-03-07 | Updated: 2025-03-24 | Author: Hitesh Jethva Data preprocessing is a critical step in the machine learning pipeline. Automating this process ensures consistency, efficiency, and scalability. Apache Airflow is a powerful orchestration tool that allows you to schedule and monitor data preprocessing tasks programmatically. This guide walks through setting up Apache Airflow on an Ubuntu [cloud GPU server](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/) and automating data preprocessing using Airflow DAGs. ## Prerequisites Before proceeding, ensure you have the following: - An Atlantic.Net Cloud GPU server running Ubuntu 24.04. - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Step 1: Install Python and Required Libraries 1. Ensure your system has Python and necessary dependencies installed. ```bash apt install python3 python3-pip python3-venv ``` 2. Create and activate a virtual environment: ```bash python3 -m venv dag-env source dag-env/bin/activate ``` 3. Install required Python libraries: ```bash pip install numpy pandas scikit-learn tensorflow torch graphviz ``` ## Step 2: Install Apache Airflow Apache Airflow is a powerful platform to programmatically author, schedule, and monitor workflows. 1. Install Airflow. ```bash pip install apache-airflow ``` 2. Initialize the Airflow database. ```bash airflow db init ``` 3. Create a user for the Airflow web interface. ```bash airflow users create --username admin --password admin --firstname Admin --lastname User --role Admin --email admin@example.com ``` 4. Start the Airflow web server and scheduler. ```bash airflow webserver --port 8080 & airflow scheduler & ``` 5. Access the Airflow UI at **http://your-server-ip:8080.** ![](https://www.atlantic.net/wp-content/uploads/2025/03/p1.png) 6. Log in with the username and password you created. ![](https://www.atlantic.net/wp-content/uploads/2025/03/p2.png)   ## Step 3: Create the DAG Directory Apache Airflow looks for DAGs in a specific directory. By default, this directory is ~/airflow/dags. If it doesn’t exist, create it: ```bash mkdir -p ~/airflow/dags ``` This is where you’ll place your Python scripts defining the workflows (DAGs). ## Step 4: Create Sample Data Files Before defining the DAG, let’s create a sample dataset **(raw_data.csv)** to use in the preprocessing pipeline. Create a directory for your data: ```bash mkdir -p ~/airflow/data ``` Create a Python script to generate sample data: ```bash nano ~/airflow/data/generate_sample_data.py ``` Add the following code to generate a sample CSV file: ```bash import pandas as pd import numpy as np # Create a sample dataset data = { 'feature1': np.random.rand(100), 'feature2': np.random.rand(100), 'target': np.random.randint(0, 2, 100) } # Introduce some missing values and duplicates data['feature1'][10:15] = np.nan data['feature2'][20:25] = np.nan df = pd.DataFrame(data) df = pd.concat([df, df.iloc[:5]]) # Add duplicates # Save to CSV df.to_csv('~/airflow/data/raw_data.csv', index=False) print("Sample data saved to ~/airflow/data/raw_data.csv") ``` Run the script to generate the sample data: ```bash python3 ~/airflow/data/generate_sample_data.py ``` ## Step 5: Define Your Data Preprocessing Pipeline Create a Python script (data_preprocessing_dag.py) in the ~/airflow/dags directory to define your data preprocessing workflow. ```bash nano ~/airflow/dags/data_preprocessing_dag.py ``` Add the following code to define the data preprocessing pipeline: ```bash from airflow import DAG from airflow.operators.python_operator import PythonOperator from datetime import datetime import pandas as pd from sklearn.preprocessing import StandardScaler # Define file paths RAW_DATA_PATH = '/root/airflow/data/raw_data.csv' CLEANED_DATA_PATH = '/root/airflow/data/cleaned_data.pkl' TRANSFORMED_DATA_PATH = '/root/airflow/data/transformed_data.pkl' PROCESSED_DATA_PATH = '/root/airflow/data/processed_data.csv' # Define Python functions for each preprocessing step def load_data(): data = pd.read_csv(RAW_DATA_PATH) print("Data loaded successfully!") data.to_pickle(CLEANED_DATA_PATH) # Save as pickle for the next step def clean_data(): data = pd.read_pickle(CLEANED_DATA_PATH) data.dropna(inplace=True) # Remove missing values data.drop_duplicates(inplace=True) # Remove duplicates print("Data cleaned successfully!") data.to_pickle(TRANSFORMED_DATA_PATH) # Save as pickle for the next step def transform_data(): data = pd.read_pickle(TRANSFORMED_DATA_PATH) scaler = StandardScaler() data[["feature1", "feature2"]] = scaler.fit_transform(data[["feature1", "feature2"]]) print("Data transformed successfully!") data.to_pickle(PROCESSED_DATA_PATH) # Save as pickle for the next step def save_data(): data = pd.read_pickle(PROCESSED_DATA_PATH) data.to_csv(PROCESSED_DATA_PATH, index=False) print("Processed data saved successfully!") # Define the DAG default_args = { 'owner': 'admin', 'start_date': datetime(2023, 10, 1), 'retries': 1, } dag = DAG( 'data_preprocessing_pipeline', default_args=default_args, description='Automated Data Preprocessing Pipeline', schedule_interval='@daily', # Run daily ) # Define tasks load_task = PythonOperator( task_id='load_data', python_callable=load_data, dag=dag, ) clean_task = PythonOperator( task_id='clean_data', python_callable=clean_data, dag=dag, ) transform_task = PythonOperator( task_id='transform_data', python_callable=transform_data, dag=dag, ) save_task = PythonOperator( task_id='save_data', python_callable=save_data, dag=dag, ) # Set task dependencies load_task >> clean_task >> transform_task >> save_task ``` ## Step 6: Run the Pipeline 1. Trigger the DAG. ```bash airflow dags trigger data_preprocessing_pipeline ``` 2. Check the status of the DAG run. ```bash airflow dags list-runs --dag-id data_preprocessing_pipeline ``` Output. ```bash dag_id | run_id | state | execution_date | start_date | end_date ============================+======================================+=========+===========================+==================================+========= data_preprocessing_pipeline | manual__2025-03-09T12:08:01+00:00 | running | 2025-03-09T12:08:01+00:00 | 2025-03-09T12:11:25.601992+00:00 | data_preprocessing_pipeline | scheduled__2023-10-15T00:00:00+00:00 | running | 2023-10-15T00:00:00+00:00 | 2025-03-09T12:12:11.941213+00:00 | ``` 3. Refresh the Airflow UI to see your new DAG (data_preprocessing_pipeline). ![](https://www.atlantic.net/wp-content/uploads/2025/03/p4.png) 4. Double click on the data_preprocessing_pipeline. ![](https://www.atlantic.net/wp-content/uploads/2025/03/p3.png) ## Step 7: Verify the Output After the DAG runs successfully, check the output files in the **~/airflow/data** directory: - **Cleaned Data:** cleaned_data.pkl - **Transformed Data:** transformed_data.pkl - **Processed Data:** processed_data.csv ## Conclusion You have successfully set up an automated data preprocessing pipeline using Apache Airflow on an Ubuntu cloud GPU server. This pipeline loads, cleans, transforms, and saves data for further machine learning tasks, ensuring a streamlined and reproducible preprocessing workflow. --- # How to Deploy a Scalable Semantic Search Application with Deepset.ai on Atlantic.Net GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-deploy-a-scalable-semantic-search-application-with-deepset-ai-on-atlantic-net-gpu-server/ | Published: 2025-03-11 | Updated: 2026-05-04 | Author: Hitesh Jethva Semantic search is a powerful technique that improves information retrieval by understanding the meaning behind queries and documents. With the help of Deepset.ai’s Haystack framework, you can build and deploy a scalable semantic search application on an Ubuntu GPU server. This article will guide you through the process to deploy a Scalable Semantic Search Application with Deepset.ai’s Haystack framework on Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/). ## Prerequisites Before proceeding, ensure you have the following: - An Atlantic.Net Cloud GPU server running Ubuntu 24.04. - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Step 1: Set Up the Environment 1. Install Python Dependencies: ```bash apt install python3 python3-pip python3-venv ``` 2. Create a virtual environment: ```bash python3 -m venv haystack-env source haystack-env/bin/activate ``` 3. Install Haystack and other dependencies: ```bash pip install farm-haystack[elasticsearch,gpu] sentence-transformers torch ``` 4. Ensure PyTorch can detect the GPU: ```bash python3 ``` Write the following in Python shell: ```bash >>> import torch >>> print(torch.cuda.is_available()) ``` Output. ```bash True ``` Press CTRL+D to exit from the Python shell. ## Step 2: Install Docker and NVIDIA Container Toolkit Docker simplifies deployment, and the NVIDIA Container Toolkit allows Docker containers to use GPU resources. 1. Install Docker. ```bash apt install docker.io ``` 2. Start and enable the Docker service. ```bash systemctl start docker systemctl enable docker ``` 3. Install NVIDIA Container Toolkit. ```bash distribution=$(. /etc/os-release;echo $ID$VERSION_ID) curl -s -L https://nvidia.github.io/nvidia-docker/gpgkey | apt-key add - curl -s -L https://nvidia.github.io/nvidia-docker/$distribution/nvidia-docker.list | tee /etc/apt/sources.list.d/nvidia-docker.list apt update && apt install -y nvidia-container-toolkit systemctl restart docker ``` 4. Haystack supports various document stores like Elasticsearch, FAISS, and Weaviate. For this tutorial, we’ll use Elasticsearch. Run Elasticsearch Docker container. ```bash docker run -d -p 9200:9200 -e "discovery.type=single-node" elasticsearch:7.9.2 ``` 5. Verify the Elasticsearch. ```bash curl -X GET "http://localhost:9200/" ``` Note: You may need to wait a short while for the container to start. Output. ```bash { "name" : "e42a0e2ac752", "cluster_name" : "docker-cluster", "cluster_uuid" : "Q76hITRvRu65Gzxo_gnYdg", "version" : { "number" : "7.9.2", "build_flavor" : "default", "build_type" : "docker", "build_hash" : "d34da0ea4a966c4e49417f2da2f244e3e97b4e6e", "build_date" : "2020-09-23T00:45:33.626720Z", "build_snapshot" : false, "lucene_version" : "8.6.2", "minimum_wire_compatibility_version" : "6.8.0", "minimum_index_compatibility_version" : "6.0.0-beta1" }, "tagline" : "You Know, for Search" } ``` ## Step 3: Delete the Existing Index (if it exists) Before creating a new index, delete any existing index to avoid conflicts. ```bash nano semantic_app.py ``` Add the below code: ```bash from elasticsearch import Elasticsearch # Connect to Elasticsearch es = Elasticsearch(hosts=["http://localhost:9200"]) index_name = "document" # Replace with your index name # Delete the index if it exists if es.indices.exists(index=index_name): es.indices.delete(index=index_name) print(f"Index '{index_name}' deleted successfully.") else: print(f"Index '{index_name}' does not exist.") ``` ## Step 4: Initialize the ElasticsearchDocumentStore The ElasticsearchDocumentStore is a Haystack component that interacts with Elasticsearch to store and retrieve documents. Initialize it with the appropriate embedding dimension to match the output of your embedding model. ```bash from haystack.document_stores import ElasticsearchDocumentStore document_store = ElasticsearchDocumentStore( host="localhost", # Replace with your Elasticsearch host username="", # Replace with your Elasticsearch username (if applicable) password="", # Replace with your Elasticsearch password (if applicable) index="document", # Name of the index where documents will be stored embedding_dim=384 # Set embedding_dim to match the model's output ) ``` ## Step 5: Prepare and Index Sample Documents Add sample documents to the document store. ```bash your_documents = [ { "content": "The quick brown fox jumps over the lazy dog.", "meta": {"title": "Example Document 1", "author": "John Doe"} }, { "content": "Artificial intelligence is transforming the world.", "meta": {"title": "Example Document 2", "author": "Jane Smith"} }, { "content": "Semantic search improves information retrieval.", "meta": {"title": "Example Document 3", "author": "Alice Johnson"} } ] # Write documents to the document store document_store.write_documents(your_documents) print("Documents have been successfully indexed!") ``` ## Step 6: Initialize the Retriever The retriever is responsible for fetching relevant documents based on the query. ```bash from haystack.nodes import EmbeddingRetriever retriever = EmbeddingRetriever( document_store=document_store, # Pass the document_store here embedding_model="sentence-transformers/all-MiniLM-L6-v2" ) ``` ## Step 7: Generate Embeddings for Documents Generate embeddings for the indexed documents. ```bash document_store.update_embeddings(retriever) print("Document embeddings have been generated!") ``` ## Step 8: Initialize the Reader The reader extracts answers from the retrieved documents. ```bash from haystack.nodes import FARMReader reader = FARMReader( model_name_or_path="deepset/roberta-base-squad2", use_gpu=True # Enable GPU acceleration ) ``` ## Step 9: Create the Pipeline Combine the retriever and reader into a pipeline. ```bash from haystack.pipelines import ExtractiveQAPipeline pipeline = ExtractiveQAPipeline(reader, retriever) ``` ## Step 10: Query the Pipeline Test the pipeline by running a query. ```bash query = "What is semantic search?" results = pipeline.run(query=query) # Print the results print("Search Results:") for doc in results["documents"]: print(f"Content: {doc.content}") print(f"Meta: {doc.meta}") print("---") ``` ## Step 11: Test the Application To ensure the application is working correctly, run multiple test queries and verify the results. ```bash test_queries = [ "Who wrote about the quick brown fox?", "How is AI transforming the world?", "What improves information retrieval?" ] for query in test_queries: print(f"Query: {query}") results = pipeline.run(query=query) for doc in results["documents"]: print(f"Content: {doc.content}") print(f"Meta: {doc.meta}") print("---") ``` ## Step 12: Run the Application Run the Python script: ```bash python3 semantic_app.py ``` Output: ```bash Documents have been successfully indexed! Batches: 100%|████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 1/1 [00:00<00:00, 3.45it/s] Updating embeddings: 10000 Docs [00:00, 15556.09 Docs/s] Document embeddings have been generated! Batches: 100%|███████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 1/1 [00:00<00:00, 148.67it/s] Inferencing Samples: 100%|██████████████████████████████████████████████████████████████████████████████████████████████████████████| 1/1 [00:00<00:00, 7.95 Batches/s] Search Results: Content: Semantic search improves information retrieval. Meta: {'author': 'Alice Johnson', 'title': 'Example Document 3'} --- Content: Artificial intelligence is transforming the world. Meta: {'author': 'Jane Smith', 'title': 'Example Document 2'} --- Content: The quick brown fox jumps over the lazy dog. Meta: {'author': 'John Doe', 'title': 'Example Document 1'} --- Query: Who wrote about the quick brown fox? Batches: 100%|███████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 1/1 [00:00<00:00, 218.53it/s] Inferencing Samples: 100%|██████████████████████████████████████████████████████████████████████████████████████████████████████████| 1/1 [00:00<00:00, 74.42 Batches/s] Content: The quick brown fox jumps over the lazy dog. Meta: {'author': 'John Doe', 'title': 'Example Document 1'} --- Content: Semantic search improves information retrieval. Meta: {'author': 'Alice Johnson', 'title': 'Example Document 3'} --- Content: Artificial intelligence is transforming the world. Meta: {'author': 'Jane Smith', 'title': 'Example Document 2'} --- Query: How is AI transforming the world? Batches: 100%|███████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 1/1 [00:00<00:00, 256.44it/s] Inferencing Samples: 100%|██████████████████████████████████████████████████████████████████████████████████████████████████████████| 1/1 [00:00<00:00, 78.72 Batches/s] Content: Artificial intelligence is transforming the world. Meta: {'author': 'Jane Smith', 'title': 'Example Document 2'} --- Content: Semantic search improves information retrieval. Meta: {'author': 'Alice Johnson', 'title': 'Example Document 3'} --- Content: The quick brown fox jumps over the lazy dog. Meta: {'author': 'John Doe', 'title': 'Example Document 1'} --- Query: What improves information retrieval? Batches: 100%|███████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 1/1 [00:00<00:00, 263.43it/s] Inferencing Samples: 100%|██████████████████████████████████████████████████████████████████████████████████████████████████████████| 1/1 [00:00<00:00, 70.20 Batches/s] Content: Semantic search improves information retrieval. Meta: {'author': 'Alice Johnson', 'title': 'Example Document 3'} --- Content: Artificial intelligence is transforming the world. Meta: {'author': 'Jane Smith', 'title': 'Example Document 2'} --- Content: The quick brown fox jumps over the lazy dog. Meta: {'author': 'John Doe', 'title': 'Example Document 1'} ``` ## Conclusion By following these steps, you can deploy a scalable semantic search application using Deepset.ai’s Haystack framework on an Ubuntu GPU server. This setup leverages the power of Elasticsearch, sentence-transformers, and GPU acceleration to deliver fast and accurate search results. --- # Step-by-Step Guide to Astra DB Serverless Vector Database > URL: https://www.atlantic.net/gpu-server-hosting/step-by-step-guide-to-astra-db-serverless-vector-database/ | Published: 2025-03-11 | Updated: 2025-04-20 | Author: Richard Bailey The ability to efficiently search and retrieve information based on semantic similarity is crucial. Vector databases have emerged as a powerful tool for this purpose, enabling applications like recommendation systems, natural language processing, and image recognition. This guide will walk you through the process of creating and using a serverless vector database with DataStax Astra DB on your Atlantic.Net Ubuntu 22.04 cloud server. We’ll cover everything from setting up your Astra DB account and database to inserting data, generating vector embeddings, and performing vector searches. By the end of this guide, you’ll have a functional vector database. ## Prerequisites - **An Atlantic.Net cloud server running Ubuntu 22.04**: You’ll need access to a terminal on your server to execute commands. - **An Astra DB Account:** You’ll need to sign up for a free Astra DB account. - **Basic Python Knowledge:** Familiarity with Python scripting will be helpful. - **Internet Connection:** Your server needs an active internet connection to download packages and connect to Astra DB. ## Step 1 – Create an Atlantic.Net Cloud Server with Ubuntu 22.04: This step explains how to create a Cloud Server on Atlantic.Net. If you already have an Atlantic.Net server you can skip this step: - **Sign Up/Log In to Atlantic.Net:** - Go to the [Atlantic.Net website](https://www.atlantic.net/) and sign up for an account or log in if you already have one. - **Create a Cloud Server:** - In the Atlantic.Net portal, navigate to the cloud server section and click on the option to create a new server. - **Choose Ubuntu 22.04:** - Select “Ubuntu 22.04” as the operating system for your server. - **Select Server Specifications:** - Choose the server size and resources (CPU, RAM, storage) that meet your needs. For this quickstart, a basic configuration should be sufficient. - **Configure Server Options**: - Set a hostname, root password, and any other relevant server options. - **Deploy the Server:** - Review your server configuration and deploy the server. Wait for the server to be provisioned and become active. - **Access Your Cloud Server:** - Once the server is ready, you’ll receive the server’s IP address. - Use an SSH client (like PuTTY on Windows, or the built-in Terminal on macOS/Linux) to connect to your Server: ## Step 2 – Create an Astra Account and Database: - **Sign Up/Log In:** - Go to the [Astra DB website](https://accounts.datastax.com/session-service/v1/login) and sign up for a free account or log in if you already have one. - Accept the terms and conditions when prompted - Fill out the Welcome Page to continue - **Create a Database:** - In the Astra Portal, navigate to “Databases” and click “Create Database.” ![](https://www.atlantic.net/wp-content/uploads/2025/03/Create-Database.png) - - Select the following: - Deployment Type: “Serverless (Vector)” - Provider: “Amazon Web Services” - Region: “us-east-2” (This is crucial for the NVIDIA embedding model). ![](https://www.atlantic.net/wp-content/uploads/2025/03/Create-Database-Deployment-Type.png) - - Click “Create Database.” - Wait for the database to reach “Active” status (this might take a few minutes). ![](https://www.atlantic.net/wp-content/uploads/2025/03/Database-Initializing.png) - - Once complete you will see this screen. ![](https://www.atlantic.net/wp-content/uploads/2025/03/Database-Overview.png) - **Retrieve Credentials:** - Once active, go to the “Database Details.” pane on the main page ![](https://www.atlantic.net/wp-content/uploads/2025/03/Database-Details.png) - - Copy the “API Endpoint.” - Click “Generate Token” and copy the token. ![](https://www.atlantic.net/wp-content/uploads/2025/03/Generate-Token.png) **Important:** Make a note of these values as you will need them later ## Step 3 – Configure Your Atlantic.Net Cloud Server Now let’s switch over to the Atlantic.Net server to continue the configuration. - **Set environmental variables on your Ubuntu 22.04Server:** - Open your terminal on your Atlantic.Net Server. - Run the following commands, replacing API_ENDPOINT and TOKEN with the values you copied: ``` export ASTRA_DB_API_ENDPOINT=API_ENDPOINT export ASTRA_DB_APPLICATION_TOKEN=TOKEN ``` - To make these variables persistent, add these export lines to your ~/.bashrc or ~/.zshrc file and then run source ~/.bashrc or source ~/.zshrc. - **Install Python and Astrapy:** - On your Ubuntu Server, update your package lists and upgrade existing packages: - ``` sudo apt update sudo apt upgrade -y ``` - **Install Python 3.x.x+ and pip:** - Ensure Python 3.x.x or higher is installed. ``` sudo apt install python3-pip -y ``` - Verify the Python version. ``` python3 --version Python 3.10.12 ``` - Upgrade pip: ``` python3 -m pip install --upgrade pip ``` - Verify the pip version. ``` pip --version pip 25.0.1 from /usr/local/lib/python3.10/dist-packages/pip (python 3.10) ``` - **Install Astrapy:** - Install the astrapy library: ``` pip install astrapy ``` ## Step 4 – Connect to the Vector Database Now you are ready to connect to the AstraDB. - **Create a Python file:** - - First create a file named quickstart_connect.py ``` nano quickstart_connect.py ``` Paste the following code into the file: ``` import os from astrapy import DataAPIClient, Database def connect_to_database() -> Database:     """     Connects to a DataStax Astra database.     This function retrieves the database endpoint and application token from the     environment variables `ASTRA_DB_API_ENDPOINT` and `ASTRA_DB_APPLICATION_TOKEN`.     Returns:         Database: An instance of the connected database.     Raises:         RuntimeError: If the environment variables `ASTRA_DB_API_ENDPOINT` or         `ASTRA_DB_APPLICATION_TOKEN` are not defined.     """     endpoint = os.environ.get("ASTRA_DB_API_ENDPOINT")     token = os.environ.get("ASTRA_DB_APPLICATION_TOKEN")     if not token or not endpoint:         raise RuntimeError(             "Environment variables ASTRA_DB_API_ENDPOINT and ASTRA_DB_APPLICATION_TOKEN must be defined"         )     client = DataAPIClient(token)     database = client.get_database(endpoint)     print(f"Connected to database {database.info().name}")     return database ``` **Note:** quickstart_connect.py is a module that is imported by the other Python scripts and is not run directly. - **Download the Dataset:** - - Download the quickstart_dataset.json file and save it to your project directory. This dataset contains demo information about 100 books. Each object within the array represents a single book and has the following key-value pairs: - title: The title of the book (string). - author: The author of the book (string). - summary: A short summary or description of the book’s plot (string). - genres: An array of genres associated with the book (array of strings). - numberOfPages: The number of pages in the book (integer). - rating: The rating of the book (floating-point number). ``` wget https://docs.datastax.com/en/astra-db-serverless/get-started/_attachments/quickstart_dataset.json ``` - **Create a Python file:** - - Create a file named quickstart_upload.py and paste the following code: ``` from quickstart_connect import connect_to_database from astrapy import Database, Collection from astrapy.constants import VectorMetric from astrapy.info import CollectionVectorServiceOptions import json def create_collection(database: Database, collection_name: str) -> Collection:     collection = database.create_collection(         collection_name,         metric=VectorMetric.COSINE,         service=CollectionVectorServiceOptions(             provider="nvidia",             model_name="NV-Embed-QA",         ),     )     print(f"Created collection {collection.full_name}")     return collection def upload_json_data(collection: Collection, data_file_path: str, embedding_string_creator: callable) -> None:     with open(data_file_path, "r", encoding="utf8") as file:         json_data = json.load(file)     documents = [         {             **data,             "$vectorize": embedding_string_creator(data),         }         for data in json_data     ]     inserted = collection.insert_many(documents)     print(f"Inserted {len(inserted.inserted_ids)} items.") def main():     database = connect_to_database()     collection = create_collection(database, "quickstart_collection")     upload_json_data(         collection,         "quickstart_dataset.json",  # Use the actual filename         lambda data: (             f"summary: {data['summary']} | "             f"genres: {', '.join(data['genres'])}"         ),     ) if __name__ == "__main__":     main() ``` - **Run the script:** - - In your terminal, run: python3 quickstart_upload.py This will run a nested module that will use the first connect to db script, and then the second script will upload the data. You should see the following information on completion. ``` python3 quickstart_upload.py Connected to database atlanticdotnet Created collection default_keyspace.quickstart_collection Inserted 100 items. ``` ## Step 5 – Start to Query Data - **Create a Python file:** - Create a file named quickstart_find.py ``` nano quickstart_find.py ``` - Then paste the following code: ``` from quickstart_connect import connect_to_database def main():     database = connect_to_database()     collection = database.get_collection("quickstart_collection")     print("\nFinding books with rating greater than 4.7...")     rating_cursor = collection.find({"rating": {"$gt": 4.7}})     for document in rating_cursor:         print(f"{document['title']} is rated {document['rating']}")     print("\nUsing vector search to find a single scary novel...")     single_vector_match = collection.find_one({}, sort={"$vectorize": "A scary novel"})     print(f"{single_vector_match['title']} is a scary novel")     print("\nUsing filters and vector search to find 3 books with more than 400 pages that are set in the arctic, returning just the title and author...")     vector_cursor = collection.find(         {"numberOfPages": {"$gt": 400}},         sort={"$vectorize": "A book set in the arctic"},         limit=3,         projection={"title": True, "author": True}     )     for document in vector_cursor:         print(document) if __name__ == "__main__":     main() ``` - **Run the script:** - In your terminal, navigate to the directory where you saved quickstart_find.py. Execute the script using Python 3: ``` python3 quickstart_find.py ``` You should see the output of the three search queries, demonstrating how to filter and perform vector searches in your Astra DB collection. - **Change the searches:** - Open quickstart_find.py in a text editor. - Look for these parts in the code: - collection.find({…}) : This is where you change the filters. - sort={“$vectorize”: “…”} : This is where you change what you’re searching for with vectors. - limit=…: This is where you change how many results you get. - projection={…}: This is where you change what information you get back. - Change the text or numbers inside these parts. - Save the file and run again python3 quickstart_find.py Here is a modified example: ``` from quickstart_connect import connect_to_database def main():     database = connect_to_database()     collection = database.get_collection("quickstart_collection")     # Example: Find books with fewer than 300 pages     print("\nFinding books with fewer than 300 pages...")     page_cursor = collection.find({"numberOfPages": {"$lt": 300}})     for document in page_cursor:         print(f"{document['title']} has {document['numberOfPages']} pages")     # Example: Vector search for "A thrilling adventure story"     print("\nVector search for 'A thrilling adventure story'...")     adventure_match = collection.find_one({}, sort={"$vectorize": "A thrilling adventure story"})     if adventure_match:         print(f"{adventure_match['title']} is a thrilling adventure story")     else:         print("No thrilling adventure story found.")     # Example: Find top 5 historical novels with rating > 4.0, show title and author     print("\nTop 5 historical novels with rating > 4.0, showing title and author...")     historical_cursor = collection.find(         {"rating": {"$gt": 4.0}},         sort={"$vectorize": "A historical novel"},         limit=5,         projection={"title": True, "author": True}     )     for document in historical_cursor:         print(document) if __name__ == "__main__":     main() ``` Look how the results differ between the 2 examples. This shows you how easy it is for Vector Databases to give intelligent answers quickly. Get started with a Vector Database on an Atlantic.Net server today using our [GPU server hosting](https://www.atlantic.net/gpu-server-hosting/)! --- # Stylish Logo Generation with Stable Diffusion on Ubuntu Cloud GPU > URL: https://www.atlantic.net/gpu-server-hosting/stylish-logo-generation-with-stable-diffusion-on-ubuntu-cloud-gpu/ | Published: 2025-03-12 | Updated: 2025-03-24 | Author: Hitesh Jethva Creating a stylish logo is a critical step in establishing a brand’s identity. With the advent of AI-powered tools like Stable Diffusion, the process has become faster, more accessible, and highly customizable. Stable Diffusion is a state-of-the-art AI model capable of generating high-quality images from textual prompts. It’s particularly useful for logo design because: - It allows for customization through detailed prompts. - It can generate multiple variations quickly. - It supports artistic styles, such as minimalism, futuristic designs, or hand-drawn aesthetics. When combined with the computational power of a [cloud GPU server](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/), Stable Diffusion becomes a scalable and efficient solution for logo generation. In this guide, we’ll walk you through setting up Stable Diffusion to generate a logo on an Ubuntu Cloud GPU server. ## Prerequisites Before proceeding, ensure you have the following: - An Atlantic.Net Cloud GPU server running Ubuntu 24.04. - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Step 1: Set Up the Environment 1. Update the system. ```bash apt update -y ``` 2. Install necessary packages. ```bash apt install -y python3-pip python3-venv git ffmpeg ``` 3. Create and activate a virtual environment: ```bash python3 -m venv sd-env source sd-env/bin/activate ``` 4. Install PyTorch and other dependencies: ```bash pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu118 pip install diffusers transformers ``` ## Step 2: Install Stable Diffusion 1. Clone the official Stable Diffusion repository: ```bash git clone https://github.com/CompVis/stable-diffusion.git cd stable-diffusion ``` 2. Download the pre-trained model checkpoint (sd-v1-4.ckpt) from Hugging Face and place it in the models directory: ```bash mkdir -p models wget https://huggingface.co/CompVis/stable-diffusion-v-1-4-original/resolve/main/sd-v1-4.ckpt -O models/sd-v1-4.ckpt ``` ## Step 3: Write a Python Script for Logo Generation Create a Python script to generate logos using Stable Diffusion. ```bash nano generate_logo.py ``` Add the below code: ```bash import os import torch from PIL import Image from torch import autocast from diffusers import StableDiffusionPipeline # Load the Stable Diffusion model model_id = "CompVis/stable-diffusion-v1-4" device = "cuda" if torch.cuda.is_available() else "cpu" pipe = StableDiffusionPipeline.from_pretrained(model_id, torch_dtype=torch.float16) pipe = pipe.to(device) # Define the logo prompt prompt = "A stylish logo for a tech startup, futuristic, geometric shapes, blue and white color scheme, minimalistic" # Generate the logo with autocast("cuda"): image = pipe(prompt, height=512, width=512, num_inference_steps=50).images[0] # Save the generated logo output_dir = "outputs" os.makedirs(output_dir, exist_ok=True) output_path = os.path.join(output_dir, "generated_logo.png") image.save(output_path) print(f"Logo saved to {output_path}") ``` The script uses the Stable Diffusion model from the diffusers library to generate a logo based on a descriptive prompt, executing on a GPU if available. It generates and saves the logo to a specified directory, harnessing machine learning to streamline graphic design tasks. ## Step 4: Run the Script and Generate the Logo Execute the script to generate the logo: ```bash python3 generate_logo.py ``` Output. ```bash model.safetensors: 100%|████████████████████████████████████████████████████████████████████████████████████████████████████████████| 1.22G/1.22G [00:04<00:00, 258MB/s] diffusion_pytorch_model.safetensors: 100%|██████████████████████████████████████████████████████████████████████████████████████████| 3.44G/3.44G [00:19<00:00, 172MB/s] Fetching 16 files: 100%|████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 16/16 [00:20<00:00, 1.28s/it] Loading pipeline components...: 100%|█████████████████████████████████████████████████████████████████████████████████████████████████████| 7/7 [00:07<00:00, 1.01s/it] 100%|███████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 50/50 [00:03<00:00, 15.15it/s] Logo saved to outputs/generated_logo.png%|█████████████████████████████████████████████████████████████████████████████████████████▊| 3.43G/3.44G [00:19<00:00, 146MB/s] ``` The generated logo will be saved in the outputs directory as generated_logo.png. ## Step 5: Download the Generated Logo To verify the generated logo, you can use scp command to download the log from your server to your local machine. ```bash scp root@your-server-ip:/root/stable-diffusion/outputs/generated_logo.png /home/user/Downloads/ ``` Now, double-click on the downloaded file to open the generated logo: ![](https://www.atlantic.net/wp-content/uploads/2025/03/generated_logo.png) ## Conclusion In this article, we explained how to generate a logo with Stable Diffusion on an Atlantic.Net GPU server. This workflow not only saves time but also opens up endless possibilities for creativity. Whether you’re designing logos for clients or exploring new branding ideas, Stable Diffusion is a powerful tool to have in your arsenal. --- # Using BERT for Question Answering in TensorFlow with Python on Ubuntu GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/using-bert-for-question-answering-in-tensorflow-with-python-on-ubuntu-gpu-server/ | Published: 2025-03-13 | Updated: 2026-05-04 | Author: Hitesh Jethva BERT (Bidirectional Encoder Representations from Transformers) is a state-of-the-art model for natural language processing (NLP) tasks, including question answering. Fine-tuning BERT on a custom dataset can significantly improve its performance for specific use cases. In this guide, we’ll walk through the process of fine-tuning BERT for question answering using TensorFlow on an Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/). ## Prerequisites Before proceeding, ensure you have the following: - An Atlantic.Net Cloud GPU server running Ubuntu 24.04, equipped with an NVIDIA A100 GPU with at least 10 GB of GPU RAM. - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Step 1: Set Up a Python Virtual Environment 1. Update the system and install essential packages. ```bash apt update -y apt install python3-pip python3-venv -y ``` 2. Create and activate a virtual environment: ```bash python3 -m venv qa-env source qa-env/bin/activate ``` 3. Install the required libraries: ```bash pip install tensorflow transformers datasets tf-keras ``` ## Step 2: Load the Pre-trained BERT Model and Tokenizer We’ll use the bert-large-uncased-whole-word-masking-finetuned-squad model, which is fine-tuned for question answering. The BertTokenizerFast is used for tokenization, as it supports the return_offsets_mapping feature required for question answering. ```bash nano fine_tune_bert_qa.py ``` Add the below code: ```bash # fine_tune_bert_qa.py from transformers import BertTokenizerFast, TFBertForQuestionAnswering, create_optimizer from datasets import load_dataset import tensorflow as tf from tensorflow.keras.mixed_precision import set_global_policy # Enable mixed precision for better GPU performance set_global_policy('mixed_float16') # Load pre-trained BERT model and fast tokenizer model_name = "bert-base-uncased" tokenizer = BertTokenizerFast.from_pretrained(model_name) model = TFBertForQuestionAnswering.from_pretrained(model_name) ``` This code loads the necessary libraries, sets up mixed precision for efficient GPU usage, and loads the pre-trained BERT model and tokenizer from Hugging Face’s transformers library. ## Step 3: Load and Preprocess the Dataset We’ll use the SQuAD dataset, a popular dataset for question answering. The dataset contains questions, contexts, and answers with their start and end positions in the context. Add this to `fine_tune_bert_qa.py`   ```bash # Load the SQuAD dataset dataset = load_dataset("squad") # Preprocess the dataset def preprocess_function(examples): questions = [q.strip() for q in examples["question"]] inputs = tokenizer( questions, examples["context"], max_length=128, # Reduce sequence length truncation=True, padding="max_length", return_offsets_mapping=True ) offset_mapping = inputs.pop("offset_mapping") processed_inputs = { "input_ids": [], "attention_mask": [], "start_positions": [], "end_positions": [] } for i, offsets in enumerate(offset_mapping): answer = examples["answers"][i] start_char = answer["answer_start"][0] end_char = start_char + len(answer["text"][0]) start_index = next((idx for idx, offset in enumerate(offsets) if offset[0] <= start_char < offset[1]), None) end_index = next((idx for idx, offset in enumerate(offsets) if offset[0] < end_char <= offset[1]), None) if start_index is not None and end_index is not None: processed_inputs["input_ids"].append(inputs["input_ids"][i]) processed_inputs["attention_mask"].append(inputs["attention_mask"][i]) processed_inputs["start_positions"].append(start_index) processed_inputs["end_positions"].append(end_index) else: continue return processed_inputs if processed_inputs["start_positions"] else None # Apply preprocessing and filter out any None entries tokenized_datasets = dataset.map(preprocess_function, batched=True, remove_columns=dataset["train"].column_names) tokenized_datasets = tokenized_datasets.filter(lambda x: x is not None) ``` This script preprocesses the data by tokenizing the questions and contexts and mapping the answers’ start and end positions to token indices. It filters out entries where no valid token position for the answer is found. ## Step 4: Prepare TensorFlow Datasets We’ll convert the tokenized dataset into TensorFlow datasets for training and validation. Add this to `fine_tune_bert_qa.py`   ```bash # Function to convert processed data into TensorFlow dataset format def create_tf_dataset(tokenized_data): input_ids = tf.constant(tokenized_data["input_ids"]) attention_mask = tf.constant(tokenized_data["attention_mask"]) start_positions = tf.constant(tokenized_data["start_positions"]) end_positions = tf.constant(tokenized_data["end_positions"]) return tf.data.Dataset.from_tensor_slices(( {"input_ids": input_ids, "attention_mask": attention_mask}, {"start_positions": start_positions, "end_positions": end_positions} )).shuffle(10000).batch(2) # Adjust batch size as needed # Create TensorFlow datasets for training and validation train_dataset = create_tf_dataset(tokenized_datasets["train"]) validation_dataset = create_tf_dataset(tokenized_datasets["validation"]) ``` This code converts the preprocessed data into TensorFlow datasets, which are suitable for training by batching and shuffling the data. ## Step 5: Compile the Model The TFBertForQuestionAnswering model requires a loss function for both the start and end positions. We’ll use SparseCategoricalCrossentropy for this purpose. Add this to `fine_tune_bert_qa.py`   ```bash # Create the optimizer using Hugging Face's utility num_train_steps = len(train_dataset) * 1 # Assume 3 epochs of training optimizer, _ = create_optimizer( init_lr=5e-5, num_train_steps=num_train_steps, num_warmup_steps=0, weight_decay_rate=0.01, ) # Compile the model with the optimizer model.compile(optimizer=optimizer) ``` This sets up the optimizer with training parameters and compiles the model, making it ready for training. ## Step 6: Fine-Tune the Model Now, we’ll fine-tune the model on the SQuAD dataset. Add this to `fine_tune_bert_qa.py`   ```bash # Fine-tune the model model.fit(train_dataset, validation_data=validation_dataset, epochs=1) # Save the fine-tuned model model.save_pretrained("fine_tuned_bert_qa_model") tokenizer.save_pretrained("fine_tuned_bert_qa_model") print("Fine-tuning complete! Model saved to 'fine_tuned_bert_qa_model'.") ``` This trains the model on the training dataset while evaluating on the validation set. After training, it saves the model and tokenizer for later use. ## Step 7: Run the Script Run the script using the following command to train and save the model. ```bash python3 fine_tune_bert_qa.py ``` ## Step 8: Monitor GPU Usage While the script is running, you can monitor GPU usage to ensure that the fine-tuning process is utilizing the GPU effectively. Use the following command in a separate terminal: ```bash watch -n 1 nvidia-smi ``` This command will display GPU usage statistics every second. ## Step 9: Use the Fine-Tuned Model for Inference After fine-tuning, you can load the fine-tuned model and use it for inference. ```bash nano run_model.py ``` Add the below code: ```bash import tensorflow as tf # Import TensorFlow from transformers import BertTokenizerFast, TFBertForQuestionAnswering # Load the fine-tuned model and tokenizer model = TFBertForQuestionAnswering.from_pretrained("fine_tuned_bert_qa_model") tokenizer = BertTokenizerFast.from_pretrained("fine_tuned_bert_qa_model") # Use the model for inference question = "What is the capital of France?" context = "France is a country in Europe. The capital of France is Paris." # Tokenize the input inputs = tokenizer(question, context, return_tensors="tf") # Get model predictions outputs = model(inputs) # Find the start and end positions of the answer start_index = tf.argmax(outputs.start_logits, axis=1).numpy()[0] end_index = tf.argmax(outputs.end_logits, axis=1).numpy()[0] # Extract the answer tokens answer_tokens = inputs["input_ids"][0][start_index:end_index+1] # Decode the answer tokens to text answer = tokenizer.decode(answer_tokens, skip_special_tokens=True) print(f"Answer: {answer}") ``` This script loads the model and tokenizer, processes an input question and context, and predicts the answer using the model. Run the code: ```bash python3 run_model.py ``` You will get the below output. ```bash Answer: paris ``` This output confirms the model’s ability to predict correct answers from the context provided. ## Conclusion In this guide, we’ve walked through the process of fine-tuning BERT for question answering using TensorFlow on an Ubuntu GPU server. You can now fine-tune BERT on your custom dataset and deploy it for production use. --- # How to Perform Clustering with K-means and Visualize Results on an Ubuntu GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-perform-clustering-with-k-means-and-visualize-results-on-an-ubuntu-gpu-server/ | Published: 2025-03-14 | Updated: 2026-05-04 | Author: Hitesh Jethva Clustering is a fundamental unsupervised machine learning technique for grouping similar data points together. K-means clustering is one of the most popular clustering algorithms due to its simplicity and efficiency. However, with large datasets, the computational cost can be high. Leveraging GPU acceleration can greatly reduce the time taken for clustering and make it possible to work with large data. In this article, we will review how to do K-means clustering on an Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/). ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 24.04 Cloud GPU Server. - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Step 1: Setting Up the Python Environment First, you will need to set up the environment for Python. 1. Add the Python 3.10 repository. ```bash add-apt-repository ppa:deadsnakes/ppa ``` 2. Install Python3.10 and pip. ```bash apt install python3 python3-venv python3-dev ``` 3. Create a Python virtual environment. ```bash python3.10 -m venv venv-kmeans source venv-kmeans/bin/activate ``` 4. Upgrade pip to the latest version. ```bash pip install --upgrade pip ``` 5. Install the necessary libraries. ```bash pip install cuml-cu12 --extra-index-url=https://pypi.nvidia.com pip3 install matplotlib numpy ``` The cuml-cu12 package is a GPU-accelerated machine learning library from NVIDIA, and matplotlib is used for data visualization. 6. Install Nvidia CUDA apt install nvidia-cuda-toolkit -y 7. Instal cuDNN Drivers. ``` wget https://developer.download.nvidia.com/compute/cuda/repos/ubuntu2204/x86_64/cuda-keyring_1.1-1_all.deb ``` ``` sudo dpkg -i cuda-keyring_1.1-1_all.deb ``` ``` sudo apt-get update ``` ``` sudo apt-get -y install cudnn ``` ## Step 2: Generating Synthetic Data Synthetic data is often used to test and prototype machine learning algorithms. It allows you to control the data distribution and size, making it easier to validate the clustering algorithm. 1. Create a file named generate_data.py. ```bash nano generate_data.py ``` Add the following code: ```bash # generate_data.py import numpy as np # Generate synthetic data np.random.seed(42) data = np.random.rand(1000, 2) # 1000 points in 2D space # Save the data to a file np.save('data.npy', data) print("Data generated and saved to 'data.npy'.") ``` 2. Run the script to generate and save the data: ```bash python3 generate_data.py ``` This script generates 1000 random points in 2D space and saves them to a file named **data.npy.** ```bash Data generated and saved to 'data.npy'. ``` ## Step 3: Performing K-means Clustering K-means clustering is used to partition the data into a predefined number of clusters. Using GPU acceleration significantly speeds up the computation, especially for large datasets. 1. Create a file named **kmeans_clustering.py.** ```bash nano kmeans_clustering.py ``` Add the following code: ```bash # kmeans_clustering.py import numpy as np from cuml import KMeans import matplotlib.pyplot as plt # Load the generated data data = np.load('data.npy') # Perform K-means clustering kmeans = KMeans(n_clusters=3, random_state=42) kmeans.fit(data) # Get the cluster labels and centroids labels = kmeans.labels_ centroids = kmeans.cluster_centers_ # Save the results np.save('labels.npy', labels) np.save('centroids.npy', centroids) # Visualize the clusters plt.scatter(data[:, 0], data[:, 1], c=labels, cmap='viridis', s=50) plt.scatter(centroids[:, 0], centroids[:, 1], c='red', marker='X', s=200, alpha=0.75) plt.title('K-means Clustering') plt.savefig('clusters.png') plt.show() print("Clustering completed. Results saved to 'labels.npy', 'centroids.npy', and 'clusters.png'") ``` 2. Run the script to perform clustering and visualize the results: ```bash python3 kmeans_clustering.py ``` This script performs K-means clustering on the data, saves the cluster labels and centroids to files, and visualizes the clusters using matplotlib. The resulting plot is saved as **clusters.png.** ```bash Clustering completed. Results saved to 'labels.npy', 'centroids.npy', and 'clusters.png' ``` **Explanation of each file:** **labels.npy:** Contains the cluster assignment for each data point (0, 1, or 2). **centroids.npy:** Contains the coordinates of the 3 cluster centers. **clusters.png:** A scatter plot showing the data points colored by their cluster assignments and the centroids marked with red “X” symbols. Here is **clusters.png** ![](https://www.atlantic.net/wp-content/uploads/2025/02/clusters.png) ## Step 4: Checking GPU Utilization Monitoring GPU utilization ensures that the GPU is being used effectively for computation. This is crucial for optimizing performance and diagnosing potential issues. You can check the GPU status using the nvidia-smi command: ```bash nvidia-smi ``` This command provides information about the GPU, including its utilization, memory usage, and running processes. ```bash Sun Feb 23 05:07:52 2025 +-----------------------------------------------------------------------------------------+ | NVIDIA-SMI 550.90.07 Driver Version: 550.90.07 CUDA Version: 12.4 | |-----------------------------------------+------------------------+----------------------+ | GPU Name Persistence-M | Bus-Id Disp.A | Volatile Uncorr. ECC | | Fan Temp Perf Pwr:Usage/Cap | Memory-Usage | GPU-Util Compute M. | | | | MIG M. | |=========================================+========================+======================| | 0 NVIDIA A40-8Q On | 00000000:06:00.0 Off | 0 | | N/A N/A P8 N/A / N/A | 1MiB / 8192MiB | 0% Default | | | | N/A | +-----------------------------------------+------------------------+----------------------+ +-----------------------------------------------------------------------------------------+ | Processes: | | GPU GI CI PID Type Process name GPU Memory | | ID ID Usage | |=========================================================================================| | No running processes found | +-----------------------------------------------------------------------------------------+ ``` ## Conclusion In this article, we walked through the process of setting up a Python environment on an Ubuntu GPU server, generating synthetic data, performing K-means clustering using GPU-accelerated libraries, and visualizing the results. If you follow these steps, you can use GPU acceleration for clustering. --- # What Are Managed Services? > URL: https://www.atlantic.net/managed-services/what-are-managed-services/ | Published: 2025-03-15 | Updated: 2026-05-04 | Author: Richard Bailey ## What Are Managed Services? Managed services are services provided to a company or organization by a third party that shift the responsibility for specific processes, functions, and operations from that company to the third party. While managed services apply to several activities, they frequently refer to IT solutions, offering a proactive approach to modernizing business operations by making them cloud-ready and future-proof. Managed services give companies the time needed to focus on their core competencies without the burden of managing IT operations in-house. Outsourcing IT services maximizes your business’s efficiency, providing peace of mind and knowing that you are in the capable hands of a team of experts. MSPs deliver a comprehensive service wrap for new and existing environments, from network management and data backup to cybersecurity and a managed cloud computing platform. Managed services are designed to optimize your business performance, providing the critical IT support needed to thrive in a competitive market. Learn more in our detailed guide exploring what a [managed service provider](https://www.atlantic.net/managed-services/what-is-a-managed-service-provider-a-brief-guide-to-msps/) is and what they can do for you. ### The Rise of Managed Services Managed services have become increasingly popular as organizations recognize the benefits of outsourcing their IT needs to specialists. In a recent study by Gartner, the global managed services market is expected to reach $393.72 billion by 2028. The report attributes this growth to several factors, including: - The increasing complexity of IT infrastructures - Growing demand for cloud computing - Need for improved business security - Scarcity of skilled IT professionals ### The Shift Towards Multi-Cloud and Hybrid Cloud Environments Businesses no longer rely solely on a single cloud provider. Instead, they are adopting multi-cloud and hybrid cloud environments to optimize their business operations, improve resilience to downtime and gain a competitive edge. This shift enables organizations to leverage the strengths of multiple cloud platforms and utilize various managed services from each provider. All providers have distinctive advantages, and a multi-cloud strategy empowers you to cherry-pick the managed services appropriate to your business. Likewise, hybrid cloud environments balance on-premises infrastructure and public cloud resources. As a result, hybrid is perfect for organizations that need to control sensitive data while utilizing the cloud’s scalability, agility, and powerful computing. ### The Growing Demand for Remote Work and Collaboration Solutions The COVID-19 pandemic accelerated the demand for remote working and collaboration solutions, and this can be evidenced when you consider how many of us still work from home today. As a result, businesses now offer hybrid working as a unique selling point for job vacancies, resulting in enterprises looking for an effective way to communicate and collaborate among their teams seamlessly. Remote work solutions, such as video conferencing, project management tools, and virtual collaboration platforms, have become essential for maintaining productivity and fostering teamwork in a distributed work environment. These tools facilitate real-time communication, file sharing, and employee engagement, ensuring everyone can collaborate effectively regardless of location. ### The Growing Role of Artificial Intelligence and Automation Artificial Intelligence (AI) and automation are transforming industries across the board. Organizations leverage AI and automation technologies to streamline processes, improve efficiency, and drive innovation. AI-powered solutions can analyze vast amounts of data, provide valuable insights, and automate repetitive tasks, enabling businesses to make data-driven decisions and allocate resources more effectively. From chatbots and virtual assistants to machine learning algorithms and predictive analytics, AI and automation are revolutionizing how businesses operate, enhancing customer experiences, and optimizing workflows. Managed service providers enable you to embrace these trends, empower organizations to stay ahead in a rapidly evolving working environment, and unlock new opportunities for growth and success. **Learn more in the detailed guide to [managed services.](https://www.atlantic.net/managed-services/)** ### Better Cost Control Arguably, financial benefits are the most crucial aspect of managed services. Of course, you still have to pay for your services; however, by outsourcing IT operations, organizations can eliminate the need for costly in-house IT infrastructure and personnel. Purchasing servers and infrastructure is expensive; hardware costs are astronomical, and maintenance contracts typically cost thousands of dollars per server. Also, remember that IT salaries are some of the highest in the market, especially if you want the best hires. MSPs negate these problems by offering flexible and affordable pricing models, allowing businesses to pay on-demand for only the services they need without any upfront investments or unexpected costs. The financial benefits are clear; leveraging the MSP’s professional expertise, utilizing the extensive computing resources, and gaining access to the latest cutting-edge technologies and skilled professionals is priceless. MSPs can also optimize any existing IT systems, helping you streamline operations and identify additional areas where cost savings can be achieved. Add the ability to monitor and maintain the infrastructure proactively, reducing the risk of costly downtime and unexpected repairs; outsourcing is a compelling option. ### Improved Risk Management Managing risk is a vital concept within managed services. Cybersecurity is a hot topic in the industry. Managed services are crucial in implementing robust security measures to protect sensitive data, guard against cyber threats, and ensure regulatory compliance. Detailed monitoring tools underpin risk management, and additional safeguards such as performing regular backups and developing disaster recovery plans will help minimize any potential impact. ### High Availability, Efficiency & Productivity, The day-to-day management of servers and infrastructure ensures that IT systems are consistently monitored, maintained, and optimized, minimizing the risk of downtime and service disruptions. With proactive monitoring, potential issues are identified and resolved before they may impact business operations. MSPs offer round-the-clock support of server resources, reducing response times and ensuring quick resolution of IT-related problems. This leads to improved operational efficiency and empowers employees to work seamlessly without interruptions. ## Choosing Managed Services Providers ### Evaluating MSP Capabilities and Expertise Before you pick an MSP, look at the technical expertise available. You want a provider that understands your industry’s unique IT requirements and has the attributes to meet them. For example, if you are an e-commerce organization, it may prove beneficial to work with a PCI-Compliant provider; likewise, if you are a healthcare practice, you need someone who is HIPAA-Compliant. The best Managed Service Providers will have a team of certified professionals who are well-versed in the latest technologies and best practices and can demonstrate their experience managing similar IT environments. Feel free to ask for case studies or references to gauge their competency. ### Understanding the MSP’s Service-Level Agreements (SLAs) The SLA is crucial to any MSP contract. They define the baseline level of service you can expect and provide a clear framework for accountability. Be sure to understand what each SLA covers, the performance metrics the MSP will adhere to, and the resolution path should they fail to meet those standards. A reputable MSP will have transparent SLAs that align directly with your business needs. ### Checking MSP’s Security and Compliance Measures As data breaches become increasingly common, ensuring your MSP has robust security measures is essential. Ask them about their data protection policies, security certifications, and how they handle potential security threats. Equally important is their compliance with industry-specific regulations. ### Evaluating MSP’s Communication and Support Structure Finally, effective communication and a supportive structure are vital. A good MSP will be there for you 24/7, responding promptly to your queries and concerns. They should have a straightforward escalation process in place and be able to provide remote and on-site support on demand. Moreover, they should proactively inform you about any changes or updates your IT environment requires. ### Discover Atlantic.Net Managed Services In today’s highly competitive and increasingly digital business landscape, you need a trusted partner who understands the ins and outs of cutting-edge technology and how to provide a secure, efficient, and scalable digital environment. That’s where Atlantic.Net comes in. With our Managed Private Cloud, your business gains efficiency, scalability, and an unmatched level of security. We provide the cutting-edge cloud computing solutions you need while allowing you to focus on what matters – growing your core business. ## Best Practices for Implementing Managed Services Implementing managed services is a strategic decision that can significantly benefit your business. Initiatives include cost savings, increased efficiency, and access to expert knowledge and cutting-edge technology. However, following best practices during the implementation process is essential to fully realize these benefits. Here are some key considerations: ### Clearly Defining Objectives and Scope of Services The first step to a successful MSP partnership is clearly understanding your objectives. What challenges are you trying to address? For example, are you aiming to improve network security, enhance data management, or streamline IT operations? Identifying your specific needs will guide the scope of services, ensuring alignment between your organization’s goals and the MSP’s offerings. After establishing the objectives, defining the scope of services is crucial. This refers to the specific tasks the MSP will handle. Be explicit about what’s included and what isn’t. For example, will the MSP provide round-the-clock monitoring? Are software updates part of their responsibilities? A detailed scope of services eliminates ambiguity, promoting a smooth partnership. ### Establishing Clear Communication Channels Effective communication is a cornerstone of any successful relationship, and your partnership with an MSP is no different. Establishing clear communication channels is essential for addressing concerns promptly and making necessary adjustments. Regular updates on the MSP’s activities give you an insight into their work, strengthening the trust between both parties. Consider setting up weekly or monthly meetings to discuss progress, challenges, and plans. Also, ensure there are established procedures for urgent communication needs, such as network outages or security breaches. ### Developing a Comprehensive Service-Level Agreement The Service-Level Agreement (SLA) is a crucial document in an MSP partnership. It outlines the expectations for the MSP, detailing the services they will provide, performance standards, and remedies or penalties for non-compliance. The SLA should be comprehensive, covering all aspects of the partnership. It should specify the response time for service issues, data protection measures, and disaster recovery plans. By laying out these details, the SLA safeguards the interests of both parties, providing a clear roadmap for the partnership. ### Regularly Reviewing and Updating the Scope of Services In a dynamic IT landscape, static service offerings can quickly become outdated. Regular service reviews ensure your needs are continually met. This could involve adding new services as your business grows or removing services you may no longer require. Updating the scope of services is more than adapting to your organization’s changes. It’s also about leveraging the evolving capabilities of the MSP. As they adopt new technologies and methodologies, they can offer more innovative solutions that benefit your business. ### Monitoring and Measuring the Performance of the MSP Lastly, monitoring the MSP’s performance is vital to the partnership’s success. This involves tracking key performance indicators (KPIs) that align with your objectives. For instance, if your goal is to improve network uptime, the MSP’s uptime statistics would be a relevant KPI. Regular performance assessments ensure the MSP is fulfilling its obligations and help identify areas for improvement. Remember, the goal isn’t micromanaging the MSP but ensuring they deliver the promised value. ## Examples of Managed Services Atlantic.Net offers an impressive suite of managed services designed to provide technical prowess and a competitive advantage for your business. #### Cloud Services Management #### Managed Private Cloud Managed Private Cloud is a specialized service with a dedicated cloud computing infrastructure maintained exclusively for clients. This means that all the resources and capabilities of the cloud, from servers to storage to network components, are solely dedicated to that organization. A managed private cloud offers a high level of control and customization. Unlike public clouds, which are shared among multiple users, private clouds can be tailored to meet the business’s unique needs, including specific performance, security, and compliance requirements. This ensures that companies can fully utilize cloud technology’s scalability and efficiency while meeting their needs. ##### **Learn more in the detailed guides to:** ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [SaaS architecture](https://frontegg.com/guides/the-evolution-of-saas-architecture) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) HPC on Azure ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) Linux on Azure ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [SAP on Azure](https://bluexp.netapp.com/hubfs/tr-4757-SAP-Applications-on-microsoft-azure.pdf) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Cloud hosting](https://www.atlantic.net/vps-hosting/what-is-cloud-hosting/) ##### ***[Related product offering: Atlantic.Net Dedicated Server Hosting | High Performance Dedicated Servers](https://www.atlantic.net/dedicated-server-hosting/)*** ##### **Related technology updates:** ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Blog] 9 Essential Features of Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/9-essential-features-of-dedicated-server-hosting/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Blog] – What Is the Difference Between a Dedicated Server and a Dedicated Cloud Host?](https://www.atlantic.net/dedicated-server-hosting/what-is-the-difference-between-a-dedicated-server-and-a-dedicated-cloud-host/) #### Cloud Database Services Cloud Database Services has revolutionized how businesses handle data, offering a dynamic and flexible virtual data storage and management environment. With these services, companies can access their data anytime, anywhere, with an internet connection, a significant shift from traditional databases that required physical infrastructure and dedicated IT personnel. In addition to flexibility and scalability, Cloud Database Services provide robust disaster recovery solutions, ensuring minimal disruption to operations in case of a system failure or data loss. Enhanced with advanced security measures such as data encryption, access controls, and routine security audits, these services offer businesses peace of mind about protecting their sensitive information. ##### **Learn more in the detailed guides to** ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [AWS database](https://bluexp.netapp.com/blog/aws-cvo-blg-aws-databases-the-power-of-purpose-built-database-engines) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [AWS big data](https://bluexp.netapp.com/blog/aws-cvo-blg-aws-big-data-6-options-you-should-consider) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) Azure database ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Azure big data](https://www.netapp.com/learn/a-step-by-step-guide-to-setting-up-cloud-volumes-ontap-on-azure/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Google Cloud database](https://bluexp.netapp.com/blog/gcp-cvo-blg-google-cloud-database-the-right-service-for-your-workloads) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Managed database](https://www.instaclustr.com/education/data-architecture/managed-databases-types-use-cases-and-best-practices/) **Related product offering:** [Open-Source Data Infrastructure Platform](https://www.instaclustr.com/) **Related technology updates: **[[Blog] Multi Data Center Apache Spark™/Cassandra Benchmark](https://www.instaclustr.com/blog/multi-data-center-sparkcassandra-benchmark-round-2/) #### IT Consulting Services [IT consulting services](https://www.atlantic.net/managed-services/consulting/) provide expert advice and strategic direction to your business by helping you harness the technology needed to meet your unique business objectives. As companies grow, so does the complexity and load on the IT infrastructure.IT professionals assist in identifying system bottlenecks, projecting future tech needs, and optimizing IT operations to align with your business goals. This strategic approach results in streamlined processes enhanced productivity, and minimized downtime. Consequently, it can lead to increased customer satisfaction and business growth. ##### **Learn more in the detailed guide to [IT consulting services](https://www.atlantic.net/managed-services/consulting/)** ##### ***[Related product offering: Atlantic.Net Dedicated Server Hosting | High Performance Dedicated Servers](https://www.atlantic.net/dedicated-server-hosting/)*** ##### ***[Related technology update: [Ebook] How to Build a Security Framework if You’re a Resource Drained IT Security Team](https://www.cynet.com/blog/6-steps-to-building-a-lean-security-framework/)*** #### Virtual Desktop Infrastructure (VDI). With VDI-managed services, organizations can access their desktops and applications securely from anywhere, anytime, using any device. A scalable solution eliminates the need for costly on-premises infrastructure, enhances data security, and simplifies IT management. It empowers businesses to streamline operations, improve productivity, and adapt to dynamic work environments while ensuring a seamless user experience. ##### **Learn more in the detailed guides to:** ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [VDI](https://perception-point.io/vdi-solutions-comparing-top-6-solutions/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [VDI on Azure](https://bluexp.netapp.com/blog/azure-anf-blg-the-complete-guide-to-vdi-on-azure) #### Supply Chain Management Supply Chain Management is the backbone of efficient business operations, and partnering with a Managed Service provider can yield substantial benefits. Organizations can leverage their expertise to optimize logistics, inventory, and procurement processes, enhancing visibility and control across the supply chain. By harnessing advanced technologies and analytics, Managed Service providers empower businesses to streamline operations, mitigate risks, and achieve cost savings, ultimately driving growth and customer satisfaction. #### CDN. The Network Edge plays a vital part in protecting your infrastructure. A DDoS Protection service acts like a digital fortress around your network. It’s designed to absorb Distributed Denial of Service (DDoS) attacks, ensuring your platform remains available and accessible. This service helps keep your network resilient against a flood of malicious traffic that DDoS attacks are known to unleash. ##### **Learn more in the detailed guide to [CDN](https://www.imperva.com/learn/performance/cdn-guide/)** ##### ***[Imperva Secure CDN | Fast and Secure Content Delivery Network](https://www.imperva.com/products/content-delivery-network-cdn/)*** ##### **Related technology updates:** ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Blog] 9 Recommendations to Prevent Bad Bots on Your Website](https://www.imperva.com/blog/9-recommendations-to-prevent-bad-bots-on-your-website/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Blog] The New York Times vs. OpenAI: A Turning Point for Web Scraping?](https://www.imperva.com/blog/the-new-york-times-vs-openai-a-turning-point-for-web-scraping/) #### Security Services Management SSM is an oversight of [security functions](https://www.atlantic.net/pci-compliant-hosting/pci-security-services/) within an organization. It entails coordinating resources, processes, and technologies to protect and maintain the integrity of the organization’s assets. This includes physical assets and proprietary information to digital resources and reputation. SSM’s critical functions involve risk management, implementation of security protocols, incident response, and ensuring compliance with relevant regulations. This system of managing and mitigating risks helps safeguard sensitive data. It fosters a security culture, improving business continuity, customer trust, and overall organizational health. #### Managed Security and Compliance Managed security and compliance services help organizations meet industry regulations while protecting sensitive data and systems from cyber threats. These services include continuous monitoring, threat detection, risk assessments, and automated compliance reporting to ensure that organizations remain compliant with relevant standards. Compliance regulations vary by industry, but some key examples include: - **HIPAA (Health Insurance Portability and Accountability Act):** Required for healthcare organizations to protect patient data and ensure privacy. - **PCI DSS (Payment Card Industry Data Security Standard):** Mandates security measures for organizations handling credit card transactions. - **GDPR (General Data Protection Regulation):** Enforces data protection and privacy rules for organizations handling personal data of individuals in the EU. - **SOC 2 (Service Organization Control 2):** Ensures service providers securely manage customer data to protect privacy and interests. - **ISO 27001 (International Organization for Standardization 27001):** Provides a framework for managing information security risks. - **NIST Cybersecurity Framework:** A voluntary framework used to improve security and resilience against cyber threats. ##### **Learn more in the detailed guide to [PCI compliance](https://www.tigera.io/learn/guides/pci-compliance/)** ##### ***[Related product offering: Tigera | Security and Observability for Containers and Kubernetes](https://www.tigera.io/)*** ##### ***[Related technology update: [Whitepaper] SOC 2 Security Compliance for Containers and Kubernetes](https://www.tigera.io/blog/what-is-soc-2-and-how-do-you-achieve-soc-2-compliance-for-containers-and-kubernetes/)*** #### Providing Payroll Services Comprehensive Payroll Services are all about streamlining the payroll process. The MSP ensures tax regulations and labor laws, accurate employee data, and timely payment disbursements are followed. Expertise in payroll administration and advanced software enables businesses to focus on core operations while enjoying efficient, error-free payroll management. ##### **Learn more in the detailed guide to [global payroll](https://enterprise.fiverr.com/global-payroll-guide/)** #### Managed Webinars Managed webinar services focus on ensuring seamless virtual events. MSPs set up platforms, configure integrations with CRM or marketing systems, and provide real-time technical support during live sessions. They manage registration workflows, recording, analytics, and post-event content distribution. By outsourcing webinar delivery, organizations avoid interruptions caused by bandwidth issues, audio failures, or software glitches. MSPs also optimize security to prevent unauthorized access or disruptions. These services are especially valuable for enterprises that rely on webinars for training, customer engagement, or product launches. ##### Learn more in the detailed guides to [Webinar Platforms](https://corp.kaltura.com/blog/best-webinar-platforms/) #### Managed SIEM Security Information and Event Management (SIEM) is a complex service that requires constant tuning and monitoring. MSPs collect and analyze log data from endpoints, networks, applications, and cloud environments. They use correlation rules, threat intelligence feeds, and machine learning models to detect suspicious activity. Managed SIEM services also handle incident escalation, forensic analysis, and compliance reporting. Instead of managing an expensive in-house SIEM platform, organizations can leverage the MSP’s expertise to gain real-time visibility into security threats. This reduces false positives and ensures quicker detection and response to attacks. ##### Learn more in the detailed guides to [Splunk SIEM](https://www.exabeam.com/explainers/splunk/splunk-siem-key-features-limitations-and-alternatives/) **Related product offering:** [LogRhythm SIEM | Self-Hosted SIEM for Advanced TDIR](https://www.exabeam.com/platform/logrhythm-siem/) **Related technology updates: ** [[Whitepaper] Gartner® Magic Quadrant™ for SIEM ](https://www.exabeam.com/blog/infosec-trends/exabeam-named-a-leader-for-the-5th-straight-time-in-gartner-magic-quadrant-for-security-information-and-event-management-siem/) [[Blog] How SIEM Helps With Cyber Insurance ](https://www.exabeam.com/blog/siem-trends/how-siem-helps-with-cyber-insurance/) #### Managed Content as a Service Managed content services provide centralized platforms for creating, storing, and distributing digital content across an organization. This includes websites, intranets, knowledge bases, and enterprise document libraries. MSPs ensure that content is organized, versioned, and delivered reliably to both employees and customers. A critical component of this service is Digital Asset Management (DAM). DAM systems allow businesses to store, catalog, and retrieve digital assets such as images, videos, presentations, and marketing collateral. MSPs manage DAM platforms by handling metadata tagging, access permissions, and integration with creative tools and publishing systems. This ensures that teams can quickly find and reuse approved assets, improving consistency and reducing duplication of work. In addition, MSPs integrate content and DAM platforms with enterprise applications such as CRM, ERP, and collaboration tools. They also enforce governance policies, ensuring that sensitive content is secured and regulatory requirements are met. By outsourcing content and asset management, organizations streamline workflows, accelerate content delivery, and maintain a consistent digital presence across multiple channels. ##### Learn more in the detailed guides to [Digital Asset Management](https://corp.kaltura.com/blog/digital-asset-management-2025/) #### Managed IAM Services Identity and Access Management (IAM) services govern how users authenticate and interact with systems. MSPs implement solutions such as single sign-on (SSO), multi-factor authentication (MFA), and privileged access management (PAM). These measures reduce unauthorized access risks and improve user convenience. MSPs continuously monitor identity events, enforce least-privilege policies, and provide detailed access audits. They also manage lifecycle events, ensuring user accounts are provisioned and deactivated appropriately. Managed IAM services are critical for compliance, zero-trust architectures, and protecting against credential-based attacks. ##### Learn more in the detailed guides to [MFA Solution](https://www.atlantic.net/managed-services/multi-factor-authentication/) **Related product offering: [Atlantic.Net Cloud Platform | Scalable, Secure Cloud Solutions](https://www.atlantic.net/)** #### Incident Response Services Our dedicated teams proactively monitor your systems, and our 24/7 NOC handle automated alerts or customer interactions. The team is tasked to promptly identify and resolve issues, minimizing downtime and maximizing system availability. In addition, all incidents are logged in our ticketing system. #### [Load Balanced Servers](https://www.cynet.com/services/) With cutting-edge [load-balancing technology,](https://www.atlantic.net/managed-services/load-balancing/) traffic is efficiently distributed across multiple servers minimizing downtime and scalability. In addition, our infrastructure and expert support ensures a seamless user experience. ##### **Learn more in the detailed guide to [load balanced servers.](https://www.atlantic.net/managed-services/load-balancing/)** ##### **Related technology updates:** ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Blog] How Secure is the Cloud?](https://www.atlantic.net/hipaa-compliant-hosting/how-secure-is-the-cloud/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Blog] How to Best Mitigate Cybersecurity Risks and Protect Your Data](https://www.atlantic.net/hipaa-compliant-hosting/how-to-best-mitigate-cybersecurity-risks-and-protect-your-data/) #### Colocation Hosting Colocation allows clients to lease space in [one or multiple data centers](https://www.atlantic.net/orlando-colocation-hosting-data-center/) while maintaining complete ownership and control of the hardware and software settings. The service provides enhanced Internet bandwidth, reliable power, and robust cooling systems. The enhanced security offered is apt for industries requiring secure on-site data storage. Moreover, it facilitates high bandwidth, low latency, redundant power feeds, advanced climate control systems, and constant equipment monitoring. ##### **Learn more in the detailed guide to [colocation hosting](https://www.atlantic.net/orlando-colocation-hosting-data-center/what-is-colocation-hosting/)** #### Dedicated Server Hosting [Dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) is a robust hosting environment that provides exclusive access to an entire server’s resources for a single user. Unlike shared or virtual hosting options, where resources are divided among multiple users, dedicated hosting allocates the entirety of a server’s power— its processing, memory, storage, and bandwidth— to a single tenant—ensuring peak performance, as there are no other websites or applications to compete with for resources. The primary advantage of dedicated server hosting lies in its remarkable power and control. Users have full root and admin access, allowing them to configure the server according to their specific needs and security requirements. This makes dedicated servers ideal for businesses with high-traffic websites or those requiring extensive customization and security, such as e-commerce platforms, large corporations, and tech companies. ##### **Learn more in the detailed guide to [dedicated server hosting.](https://www.atlantic.net/dedicated-server-hosting/)** ##### ***[Related product offering: USA Dedicated Hosting](https://www.atlantic.net/dedicated-server-hosting/)*** #### VoIP Cloud Service VoIP (Voice over Internet Protocol) cloud services offer a more flexible and cost-effective solution for businesses compared to traditional telephony systems. This service allows voice communications to be made over the internet, converting analog voice signals into digital data packets. VoIP services hosted in the cloud provide improved reliability, scalability, and security compared to traditional on-premise deployments. Unlike traditional virtual phone systems that often involve hefty initial investments and ongoing maintenance costs, VoIP services generally require a lower upfront investment and can significantly reduce monthly phone bills. Cloud-based VoIP solutions are inherently scalable, allowing businesses to easily add or remove phone lines and features as their needs change. ##### **Related product offering: [VoIP Cloud Server Service](https://www.atlantic.net/voip-cloud-servers/)** ##### **Related technology updates:** ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Blog] How to Secure SSH Server on Arch Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-secure-ssh-server-on-arch-linux/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Blog] Lessons Learned in 2022 About Cybersecurity for 2023 and Beyond](https://www.atlantic.net/dedicated-server-hosting/lessons-learned-in-2022-about-cybersecurity-for-2023-and-beyond/) Unlock your IT potential with Atlantic.Net Managed Services. Streamline IT operations and accelerate growth with a comprehensive range of security, infrastructure management, data protection, recovery, and transformative managed services. Contact us today for a personalized consultation. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282) or email us at [sales@atlantic.net.](mailto:sales@atlantic.net) #### [Cloud Business VoIP Service](https://www.atlantic.net/voip-cloud-servers/) ##### Related guides Authored by Atlantic.Net ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [VoIP Cloud Servers](https://www.atlantic.net/voip-cloud-servers/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Cloud VoIP](https://www.atlantic.net/voip-cloud-servers/cloud-voip/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Top 10 Cloud VoIP Providers](https://www.atlantic.net/voip-cloud-servers/cloud-voip-providers/) ##### Related product offering:[Atlantic.Net Cloud Platform | Scalable, Secure Cloud Solutions](https://www.atlantic.net/cloud-platform/) *Offered by Atlantic.Net* ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Cloud Hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Secure Block Storage (SBS)](https://www.atlantic.net/cloud-platform/block-storage/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Top 10 Cloud VoIP Providers](https://www.atlantic.net/voip-cloud-servers/cloud-voip-providers/) ##### Related technology updates: ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Blog] How to Secure SSH Server on Arch Linux](https://www.atlantic.net/dedicated-server-hosting/how-to-secure-ssh-server-on-arch-linux/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Blog] Lessons Learned in 2022 About Cybersecurity for 2023 and Beyond](https://www.atlantic.net/dedicated-server-hosting/lessons-learned-in-2022-about-cybersecurity-for-2023-and-beyond/) #### [IT Consulting Services](https://www.atlantic.net/managed-services/consulting/) Authored by Atlantic.Net ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Managed Consulting Services](https://www.atlantic.net/managed-services/consulting/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Best Cloud Consultancy or MSP in 2024](https://www.atlantic.net/vps-hosting/best-cloud-consultancy-or-msp/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Top 13 Difficult Questions Your HIPAA Consultant Should Be Asking You](https://www.atlantic.net/managed-services/consulting/) ##### Related product offering:[Atlantic.Net Cloud Platform | Scalable, Secure Cloud Solutions](https://www.atlantic.net/cloud-platform/) *Offered by Atlantic.Net* ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Cloud Backups (Snapshots)](https://www.atlantic.net/cloud-platform/backups/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Atlantic.Net Teams (ANT) Collaboration Service](https://www.atlantic.net/cloud-platform/collaboration-service/) ##### Related technology updates: ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Ebook] How to Build a Security Framework if You’re a Resource Drained IT Security Team](https://www.cynet.com/blog/6-steps-to-building-a-lean-security-framework/) #### [Load Balanced Servers](https://www.atlantic.net/managed-services/load-balancing/) ##### Related guides Authored by Atlantic.Net ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Load Balanced Servers](https://www.atlantic.net/managed-services/load-balancing/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Maximizing Uptime: Understanding Server Load Balancing](https://www.atlantic.net/hipaa-data-centers/server-load-balancing/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [How to Check Your Server Load in Linux](https://www.atlantic.net/vps-hosting/how-to-check-your-server-load-in-linux/) ##### Related technology updates: ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Blog] How Secure is the Cloud?](https://www.atlantic.net/hipaa-compliant-hosting/how-secure-is-the-cloud/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Blog] How to Best Mitigate Cybersecurity Risks and Protect Your Data](https://www.atlantic.net/hipaa-compliant-hosting/how-to-best-mitigate-cybersecurity-risks-and-protect-your-data/) #### [Multi-Factor Authentication Solution](https://www.atlantic.net/managed-services/multi-factor-authentication/) ##### Related guides Authored by Atlantic.Net ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Multi-Factor Authentication Service](https://www.atlantic.net/managed-services/multi-factor-authentication/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Top 10 MFA Providers: How to Choose an MFA Provider](https://www.atlantic.net/managed-services/why-you-need-an-mfa-provider-all-about-mfa/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [What Is MFA as a Service? | Multi-Factor Authentication Services](https://www.atlantic.net/managed-services/what-is-mfa-as-a-service/) ##### Related product offering:[Atlantic.Net Cloud Platform | Scalable, Secure Cloud Solutions](https://www.atlantic.net/cloud-platform/) #### [Server Management](https://www.atlantic.net/managed-services/server-management/) ##### Related guides Authored by Atlantic.Net ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Server Management Services](https://www.atlantic.net/managed-services/server-management/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [How to Manage a Windows Server](https://www.atlantic.net/managed-services/server-management-windows/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Top 10 Server Management Software Solutions](https://www.atlantic.net/managed-services/server-management-software/) #### [USA Dedicated Hosting](https://www.atlantic.net/dedicated-server-hosting/) ##### Related guides Authored by Atlantic.Net ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [USA Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Dedicated Hosts | Dedicated Cloud Host](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) #### [What Is Cloud Hosting](https://www.atlantic.net/vps-hosting/what-is-cloud-hosting/) ##### Related guides Authored by Atlantic.Net ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [What Is Cloud Hosting?](https://www.atlantic.net/vps-hosting/what-is-cloud-hosting/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [What Is a DNS? Complete Domain Name System Guide](https://www.atlantic.net/vps-hosting/what-is-dns-and-how-does-it-work/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [What Is VMWare?](https://www.atlantic.net/dedicated-server-hosting/what-is-vmware/) ##### Related product offering:[Atlantic.Net Cloud Platform | Scalable, Secure Cloud Solutions](https://www.atlantic.net/cloud-platform/) ##### Related technology updates: ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Blog] 9 Essential Features of Dedicated Server Hosting](https://www.atlantic.net/vps-hosting/what-is-dns-and-how-does-it-work/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Blog] What Is the Difference Between a Dedicated Server and a Dedicated Cloud Host?](https://www.atlantic.net/dedicated-server-hosting/what-is-the-difference-between-a-dedicated-server-and-a-dedicated-cloud-host/) #### [CDN](https://www.imperva.com/learn/performance/cdn-guide/) ##### Related guides Authored by Imperva ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [The Essential CDN Guide](https://www.imperva.com/learn/performance/cdn-guide/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [How to Reduce Network Latency | CDN Guide](https://www.imperva.com/learn/performance/latency/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [What is Anycast Routing | Anycast DNS | CDN Guide](https://www.imperva.com/learn/performance/anycast/) ##### Related product offering:[Imperva Secure CDN | Fast and Secure Content Delivery Network](https://www.imperva.com/products/content-delivery-network-cdn/) ##### Related technology updates: ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Blog] 9 Recommendations to Prevent Bad Bots on Your Website](https://www.imperva.com/blog/9-recommendations-to-prevent-bad-bots-on-your-website/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Blog] The New York Times vs. OpenAI: A Turning Point for Web Scraping?](https://www.imperva.com/blog/the-new-york-times-vs-openai-a-turning-point-for-web-scraping/) #### [PCI Compliance](https://www.tigera.io/learn/guides/pci-compliance/) ##### Related guides Authored by Tigera ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [PCI Compliance: Merchant Levels, 12 Requirements & PCI in the Cloud](https://www.tigera.io/learn/guides/pci-compliance/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [AWS PCI Compliance: 5 Ways to Make Your Cloud Compliant](https://www.tigera.io/learn/guides/pci-compliance/aws-pci-compliance/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Azure PCI Compliance: A Quick Guide for Cloud Users](https://www.tigera.io/learn/guides/pci-compliance/azure-pci-compliance/) ##### Related product offering: [Tigera | Security and Observability for Containers and Kubernetes](https://www.tigera.io/) *Offered by Tigera* ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Vulnerability Management](https://www.tigera.io/tigera-products/vulnerability-management/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Security Policy Management](https://www.tigera.io/features/policy-lifecycle-management/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Multi-Cloud Security](https://www.tigera.io/tigera-products/multi-cloud-security/) ##### Related technology updates: ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [[Whitepaper] SOC 2 Security Compliance for Containers and Kubernetes](https://www.tigera.io/blog/what-is-soc-2-and-how-do-you-achieve-soc-2-compliance-for-containers-and-kubernetes/) #### [Digital Asset Management](https://corp.kaltura.com/blog/digital-asset-management-2025/) Authored by Kaltura ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Digital Asset Management (DAM) in 2025: Use Cases & Best Practices](https://corp.kaltura.com/blog/digital-asset-management-2025/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [The 2025 guide to using AI for content repurposing](https://corp.kaltura.com/blog/ai-content-repurposing/) #### [Splunk SIEM](https://www.exabeam.com/explainers/splunk/splunk-siem-key-features-limitations-and-alternatives/) Authored by Exabeam ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Splunk SIEM: Key Features, Limitations and Alternatives](https://www.exabeam.com/explainers/splunk/splunk-siem-key-features-limitations-and-alternatives/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Splunk SOAR: Pros/Cons, Architecture & Quick Tutorial](https://www.exabeam.com/explainers/splunk/splunk-soar-pros-cons-architecture-and-quick-tutorial/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Understanding Splunk Enterprise Security: Solution Overview](https://www.exabeam.com/explainers/splunk/understanding-splunk-enterprise-security-solution-overview/) ##### Related product offering: [LogRhythm SIEM | Self-Hosted SIEM for Advanced TDIR](https://www.exabeam.com/platform/logrhythm-siem/) Offered by Exabeam ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Exabeam SIEM](https://www.exabeam.com/capabilities/siem/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Flexible Deployment of Exabeam in the Cloud or Self-Hosted](https://www.exabeam.com/benefits/flexible-deployment/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Compliance | Exabeam](https://www.exabeam.com/use-cases/compliance/) ##### Related technology updates: [[Whitepaper] Gartner® Magic Quadrant™ for SIEM](https://www.exabeam.com/blog/infosec-trends/exabeam-named-a-leader-for-the-5th-straight-time-in-gartner-magic-quadrant-for-security-information-and-event-management-siem/) [[Blog] How SIEM Helps With Cyber Insurance](https://www.exabeam.com/blog/siem-trends/how-siem-helps-with-cyber-insurance/) #### [Managed Database](https://www.instaclustr.com/education/data-architecture/managed-databases-types-use-cases-and-best-practices/) Authored by Instaclustr ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Managed databases: Types, use cases, and best practices](https://www.instaclustr.com/education/data-architecture/managed-databases-types-use-cases-and-best-practices/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Enterprise database management: Pillars, functions and best practices](https://www.instaclustr.com/education/data-architecture/enterprise-database-management-pillars-functions-and-best-practices/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [8 database management best practices to know in 2025](https://www.instaclustr.com/education/data-architecture/8-database-management-best-practices-to-know-in-2025/) ##### Related product offering: [Open-Source Data Infrastructure Platform](https://www.instaclustr.com/) Offered by Instaclustr ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Apache Kafka® on the Instaclustr Managed Platform](https://www.instaclustr.com/platform/managed-apache-kafka/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Managed Kafka Connect](https://www.instaclustr.com/platform/managed-kafka-connect/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Managed Cadence®](https://www.instaclustr.com/platform/managed-cadence/) ##### Related technology updates: [[Blog] Multi Data Center Apache Spark™/Cassandra Benchmark](https://www.instaclustr.com/blog/multi-data-center-sparkcassandra-benchmark-round-2/) #### [Webinar Platforms](https://corp.kaltura.com/blog/best-webinar-platforms/) Authored by Kaltura ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [5 Best Webinar Platforms to Engage Your Audience in 2025](https://corp.kaltura.com/blog/best-webinar-platforms/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Webinar Hosting: Comparing the Top 10 Webinar Platforms in 2025](https://corp.kaltura.com/blog/webinar-platforms/) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Webinar Management: The Ultimate Guide](https://corp.kaltura.com/blog/webinar-management/) #### [MDR Security](https://www.bluevoyant.com/knowledge-center/understanding-mdr-security-benefits-and-core-technologies) ##### Related guides Authored by BlueVoyant ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Understanding MDR Security: Benefits and Core Technologies](https://www.bluevoyant.com/knowledge-center/understanding-mdr-security-benefits-and-core-technologies) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [What is Managed Detection and Response (MDR)?](https://www.bluevoyant.com/knowledge-center/what-is-managed-detection-and-response) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Managed Security Services: MSP, MSSP, MDR, and More](https://www.bluevoyant.com/knowledge-center/managed-security-services-msp-mssp-mdr) #### [SaaS Architecture](https://frontegg.com/guides/the-evolution-of-saas-architecture) ##### Related guides Authored by Frontegg ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [The Evolution of SaaS Architecture](https://frontegg.com/guides/the-evolution-of-saas-architecture) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [SaaS Reporting Guide: Everything You Need to Know](https://frontegg.com/blog/saas-reporting-for-enterprise-users) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Roles and Permissions Handling in SaaS Applications](https://frontegg.com/blog/roles-and-permissions-handling-in-saas-applications) #### Additional Managed Services Resources Below are additional articles that can help you learn about Managed Services topics. ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [Integrating SalesForce with AWS](https://blog.enree.co/2023/12/integrating-salesforce-with-aws) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/site/icon-check-mark.webp) [What Is AWS Aurora?](https://agile-7.gitbook.io/what-is-aws-aurora) ![Check mark](https://www.atlantic.net/wp-content/themes/anet/img/managed/graphic-check-mark.webp) [2FA vs MFA: 5 Key Differences and How to Choose](https://frontegg.com/blog/2fa-vs-mfa) --- # How to Create Style Transfer Models Using PyTorch on an Ubuntu GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-create-style-transfer-models-using-pytorch-on-an-ubuntu-gpu-server/ | Published: 2025-03-17 | Updated: 2025-03-24 | Author: Hitesh Jethva Style transfer is a cool deep learning technique that allows you to mix one image’s content with another’s style. PyTorch is a great choice for style transfer because of its flexibility and efficiency in handling dynamic computational graphs. This makes it very suitable for the iterative and experimental nature of adjusting and applying artistic styles to images. In this article, we will describe the process of creating a style transfer model using PyTorch in a Jupyter Notebook on an Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/). ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 24.04 Cloud GPU Server. - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Step 1: Setting Up the Environment First, let’s set up the environment by installing the necessary packages. 1. Install Python3 and pip ```bash apt install python3 python3-venv python3-dev ``` 2. Create a Python virtual environment. ```bash python3 -m venv venv source venv/bin/activate ``` 3. Upgrade pip to the latest version. ```bash pip install --upgrade pip ``` 4. Install PyTorch with CUDA support. ```bash pip3 install torch torchvision torchaudio --extra-index-url https://download.pytorch.org/whl/cu118 ``` 5. Install additional dependencies. ```bash pip3 install jupyter numpy matplotlib pillow ``` ## Step 2: Run Jupyter Notebook 1. Open your terminal and run the Jupyter Notebook. ```bash jupyter notebook --no-browser --port=8888 --ip=your-server-ip --allow-root ``` Output. ```bash To access the server, open this file in a browser: file:///root/.local/share/jupyter/runtime/jpserver-6071-open.html Or copy and paste one of these URLs: http://your-server-ip:8888/tree?token=eab31988f685c20a6809e4c18033037d0c318a7ac97e4033 http://127.0.0.1:8888/tree?token=eab31988f685c20a6809e4c18033037d0c318a7ac97e4033 ``` 2. Open your web browser and access your Jupyter Notebook using the URL as shown in the above output. ![](https://www.atlantic.net/wp-content/uploads/2025/02/p1-4.png) 3. Click on **File** and **New** to create a new notebook. ## Step 3: Load and Preprocess Images We’ll start by loading and preprocessing the content and style images. Run the following code in a Jupyter Notebook cell. ```bash import torch import torchvision.transforms as transforms from PIL import Image import matplotlib.pyplot as plt import numpy as np # Load image function def load_image(image_path, max_size=400, shape=None): image = Image.open(image_path).convert('RGB') if max(image.size) > max_size: size = max_size else: size = max(image.size) if shape is not None: size = shape in_transform = transforms.Compose([ transforms.Resize(size), transforms.ToTensor(), transforms.Normalize((0.485, 0.456, 0.406), (0.229, 0.224, 0.225))]) image = in_transform(image).unsqueeze(0) return image # Function to convert tensor to image def tensor_to_image(tensor): image = tensor.to("cpu").clone().detach() image = image.numpy().squeeze() image = image.transpose(1, 2, 0) image = image * np.array((0.229, 0.224, 0.225)) + np.array((0.485, 0.456, 0.406)) image = image.clip(0, 1) return image # Load content and style images content = load_image("content.jpg") style = load_image("style.jpg", shape=content.shape[-2:]) # Display the images plt.figure() plt.imshow(tensor_to_image(content)) plt.title("Content Image") plt.show() plt.figure() plt.imshow(tensor_to_image(style)) plt.title("Style Image") plt.show() ``` You should see two images displayed: the **content image** and the **style image.** ![](https://www.atlantic.net/wp-content/uploads/2025/02/p2-3.png) **Explanation:** - **load_image:** This function loads an image, resizes it, and converts it to a tensor. The image is also normalized using the mean and standard deviation of the ImageNet dataset. - **tensor_to_image:** This function converts a tensor back to an image format that can be displayed using matplotlib. ## Step 4: Define the Model Next, we’ll define the model for style transfer. Run the following code in a new cell. ```bash import torch.nn as nn import torchvision.models as models # Load a pre-trained VGG19 model vgg = models.vgg19(pretrained=True).features # Freeze all VGG parameters since we're only optimizing the target image for param in vgg.parameters(): param.requires_grad_(False) # Move the model to GPU if available device = torch.device("cuda" if torch.cuda.is_available() else "cpu") vgg.to(device) # Define the layers for content and style features content_layers = ['conv_4'] style_layers = ['conv_1', 'conv_2', 'conv_3', 'conv_4', 'conv_5'] # Function to get the features from the model def get_features(image, model, layers=None): if layers is None: layers = {'0': 'conv_1', '5': 'conv_2', '10': 'conv_3', '19': 'conv_4', '21': 'conv_5'} features = {} x = image for name, layer in model._modules.items(): x = layer(x) if name in layers: features[layers[name]] = x return features ``` **Explanation:** - **VGG19:** We use a pre-trained VGG19 model, which is well-suited for style transfer due to its deep architecture. - **get_features:** This function extracts features from specific layers of the VGG19 model, which will be used to compute the content and style losses. ## Step 5: Define Loss Functions Now, let’s define the loss functions for style transfer. Run the following code in a new cell. ```bash import torch.nn.functional as F # Content Loss def content_loss(target_features, content_features): return F.mse_loss(target_features['conv_4'], content_features['conv_4']) # Style Loss def gram_matrix(tensor): _, d, h, w = tensor.size() tensor = tensor.view(d, h * w) gram = torch.mm(tensor, tensor.t()) return gram def style_loss(target_features, style_features): loss = 0 for layer in style_features: target_feature = target_features[layer] style_feature = style_features[layer] target_gram = gram_matrix(target_feature) style_gram = gram_matrix(style_feature) loss += F.mse_loss(target_gram, style_gram) return loss # Total Loss def total_loss(content_loss, style_loss, alpha=1, beta=1e6): return alpha * content_loss + beta * style_loss ``` **Explanation:** - **content_loss:** This function computes the mean squared error between the content features of the target image and the content image. - **style_loss:** This function computes the style loss using the Gram matrix, which captures the style information. - **total_loss:** This function combines the content and style losses with weights alpha and beta. ## Step 6: Perform Style Transfer Finally, let’s put everything together and perform the style transfer. Run the following code in a new cell. ```bash # Perform style transfer import torch.optim as optim # Load content and style images content = load_image("content.jpg").to(device) style = load_image("style.jpg", shape=content.shape[-2:]).to(device) # Initialize the target image as the content image target = content.clone().requires_grad_(True).to(device) # Get features for content and style images content_features = get_features(content, vgg) style_features = get_features(style, vgg) # Optimizer optimizer = optim.Adam([target], lr=0.003) # Style transfer loop epochs = 3000 for epoch in range(epochs): target_features = get_features(target, vgg) c_loss = content_loss(target_features, content_features) s_loss = style_loss(target_features, style_features) t_loss = total_loss(c_loss, s_loss) optimizer.zero_grad() t_loss.backward() optimizer.step() if epoch % 100 == 0: print(f"Epoch {epoch}, Loss: {t_loss.item()}") plt.imshow(tensor_to_image(target)) plt.title(f"Epoch {epoch}") plt.show() # Save the final image final_image = tensor_to_image(target) plt.imshow(final_image) plt.title("Final Image") plt.show() # Convert the NumPy array to a PIL image and save it final_image_pil = Image.fromarray((final_image * 255).astype(np.uint8)) final_image_pil.save("final_output.jpg") ``` **Explanation:** - **Optimizer:** We use the Adam optimizer to minimize the total loss. - **Style Transfer Loop**: We iteratively update the target image to minimize the content and style losses. - **Final Image:** After the optimization process, the final image is saved as final_output.jpg. You should see the target image being updated over epochs, gradually blending the content of the content image with the style of the style image. The final output will be saved as **final_output.jpg.** ![](https://www.atlantic.net/wp-content/uploads/2025/02/p3-3.png) ## Conclusion In this article, we created a style transfer model using PyTorch in a Jupyter Notebook. We covered image preprocessing, model definition, loss functions, and the style transfer process. Now, you can create your own style transfer models and experiment with different content and style images. --- # HIPAA GPU Hosting > URL: https://www.atlantic.net/gpu-server-hosting/hipaa-gpu-hosting/ | Updated: 2026-09-16 Accelerate AI/ML, medical imaging, genomic research, and clinical workloads on dedicated or shared NVIDIA H100 NVL and L40S GPU resources inside Atlantic.Net's HIPAA-audited environment. - NVIDIA H100 NVL & L40S - Dedicated or Shared GPUs - HIPAA BAA Available - AES-256 Encryption at Rest GPU Models: 2 Uptime SLA: 100% ## Atlantic.Net HIPAA-Compliant GPU Hosting, Powered by NVIDIA Atlantic.Net's HIPAA-Compliant GPU Hosting platform is meticulously designed to future-proof your healthcare applications. Our proven HIPAA-compliant hosting environment has been significantly upgraded to meet the specialized AI/ML engineering demands of biotech, medical, and forward-thinking healthcare organizations. Power your next AI application with specialized imaging, accelerate genomic testing, run advanced predictive models, and conduct large-scale medical trials – all within a secure and compliant hosting environment. Unleash your innovations by running millions of possibilities on our dedicated or shared NVIDIA GPUs, backed by our rigorous HIPAA and HITECH audited platform – and our industry-leading 100% Uptime SLA. ## HIPAA GPU Hosting Plans ### Fortress Business HIPAA GPU Hosting H100 NVL GPU $4,789.44 Per Month 28 vCPU's 240 GB of DDR 5 Ram 2.4 TB NVMe SSD Raid 10 Storage 10 TB of Monthly Data Transfer - Fully Managed Hosting Package - Fully Managed FortiGate Firewall with Intrusion Prevention System - Business Associates Agreement - ( 5 ) Managed VPN's - Fully Managed Daily Backups ( Local ) - Fully Managed Daily Backups ( Off-Site ) - Multi-Factor Authentication - TrendMicro Security Suite - Fully Managed DDos / CDN / WAF - Scheduled Vulnerability Scans ### Fortress Custom HIPAA GPU Hosting Maximum security, customization, and premium SLAs Custom Bare Metal Hosting - Fully Managed Hosting Package - Fully Managed FortiGate Firewall with Intrusion Prevention System - Business Associates Agreement - ( 5 ) Managed VPN's - Fully Managed Daily Backups ( Local ) - Fully Managed Daily Backups ( Off-Site ) - Multi-Factor Authentication - TrendMicro Security Suite - Fully Managed DDos / CDN / WAF - Scheduled Vulnerability Scans *$450 setup fee applies *Pricing based upon 12-month term commitment *Prices based upon Linux Operating System. Windows Operating System available at an additional cost. ***Save up to 30% off above listed pricing with longer billing terms*** *Due to global supply-chain volatility, Dedicated Host pricing is subject to change but will be confirmed prior to deployment. ## Atlantic.Net Cloud GPU Hosting – Massive Computing Power Accelerate research and innovation with Atlantic.Net. Contact us to learn how we support your mission-critical initiatives. ## Why Choose Atlantic.Net HIPAA GPU Hosting, Powered by NVIDIA? At Atlantic.Net, we understand the critical balance between performance and security. Our HIPAA-audited infrastructure, powered by cutting-edge NVIDIA GPUs, is designed to help you achieve HIPAA compliance. We provide: Trust Atlantic.Net to empower your healthcare innovations with secure, high-performance GPU hosting that meets the highest standards of HIPAA compliance. - Dedicated HIPAA compliance: our platform is specifically configured as a HIPAA server and HIPAA cloud, ensuring your ePHI is protected within a secure environment. - High-performance NVIDIA GPUs: leverage advanced GPUs for medical imaging, AI/ML, and other demanding workloads with the NVIDIA H100 NVL and L40S. - Expert support: our team of certified professionals provides guidance and support throughout your security and compliance journey. - Scalable and secure infrastructure: grow your applications confidently with our scalable and resilient hosting solutions, designed to prevent catastrophic failure. - Direct access: gain direct access to your hardware for granular control over your environment, allowing your team to optimize performance and security. - Energy consumption: hardware options that consider energy consumption to help you maintain efficient operations. - Additional resources: guidance, documentation, and AI/ML procedures to assist your compliance efforts. Read more on our HIPAA-Compliant Hosting overview. ## Unleashing the Power of NVIDIA's Latest GPUs Atlantic.Net HIPAA GPU hosting uses the cutting-edge capabilities of NVIDIA's H100 NVL and L40S GPUs. By integrating these advanced GPUs into our HIPAA-compliant infrastructure, Atlantic.Net enables healthcare organizations to achieve groundbreaking advancements while maintaining the utmost security and regulatory compliance. ### NVIDIA H100 NVL The NVIDIA H100 NVL is designed for the most demanding AI and machine learning workloads, delivering unparalleled performance for tasks like large-scale model training and complex data analysis. ### NVIDIA L40S The NVIDIA L40S excels in graphics-intensive applications, making it ideal for medical imaging, 3D visualization, and advanced simulations. ## HIPAA Compliance Requirements for GPU Hosting and Electronic Protected Health Information To provide HIPAA-compliant hosting solutions for GPU-accelerated workloads, providers must adhere to the requirements outlined in the HIPAA Security Rule and related HIPAA guidelines. This involves a multi-layered approach that meets and exceeds the administrative, physical, and technical controls – ensuring the utmost protection of sensitive information and ePHI. ## Administrative Safeguards for GPU Resources HIPAA compliance requires a team effort from Atlantic.Net and the healthcare organization being onboarded. Our expert team works alongside you to introduce the core administrative requirements that must be met by both Atlantic.Net and our clients. ### Risk Analysis and Management Providers need to conduct a comprehensive risk assessment tailored to GPU-intensive operations before embarking on any task containing ePHI. These assessments should address potential vulnerabilities associated with processing large datasets and deploying machine learning and deep learning models. Strict rules protect PHI, so datasets must be used correctly and in scope of compliance – this may require individual processing or data obfuscation. The risk assessment acts as a baseline; robust risk-management policies must be implemented to mitigate identified risks, ensuring security, scalability, and compliance. ### Business Associate Agreements (BAA) A critical component is establishing Business Associate Agreements (BAA) with all entities involved in processing ePHI – including any third-party software or public cloud services providers supporting GPU resources. Atlantic.Net is ready to sign a BAA with your healthcare organization today. ### Workforce Training and Management Training is one of the most important areas of HIPAA compliance. Comprehensive HIPAA training must be provided to all personnel – including data scientists and engineers – who have access to ePHI on GPU servers. Personnel must understand the rules and regulations for handling sensitive data. Training, combined with strict access-control policies, should be enforced throughout your IT environments, limiting users' access to only the necessary ePHI. ### Policies and Procedures Detailed documentation of all HIPAA-related policies and procedures – specifically addressing GPU usage – must be maintained to ensure HIPAA compliance. ## Physical Safeguards in Data Centers ### Data Center Security One of the great benefits of outsourcing to a HIPAA-Compliant GPU Hosting provider is that you offload the complexities of running a heavily audited data center location. All Atlantic.Net facilities in the United States offer our HIPAA-Compliant Service. Most offer GPU services, with more coming online shortly. Atlantic.Net data center facilities hosting GPU resources implement robust physical security policies, including biometric access control, 24/7 surveillance, and environmental monitoring. We maintain a secure data center environment with rigorous access procedures to prevent unauthorized access. Need bare-metal servers or dedicated server options? Atlantic.Net data centers provide them – including our GPU service offering. ### Hardware Security Atlantic.Net implements physical security measures to protect GPU hardware from tampering or unauthorized removal. Server cages are locked, and we have multiple layers of security at the software and physical layer to prevent unauthorized access. Secure data-erasure protocols are in place for all storage devices containing ePHI. ## Technical Safeguards for GPU Environments ### Access Control All Atlantic.Net healthcare GPU hosting meets full HIPAA compliance for access controls. Our employees are vetted for secure access, and we can help you implement role-based access control (RBAC) to restrict your users' access to ePHI based on their job functions. All hosting solutions include strong authentication, including multi-factor authentication, and permission sets that follow the principle of least privilege. ### Audit Controls Auditing GPU hosting is a critical part of HIPAA regulations. We provide comprehensive audit logs that track all access to ePHI on GPU servers. Logging is essential, and we have the tools to understand large datasets at scale, offering industry-standard audit controls. We undertake regular reviews of audit logs – essential for detecting and investigating security incidents from our intrusion-prevention systems. We implement automated controls plus a support team that responds to unexpected alerts. ### Integrity Controls Atlantic.Net HIPAA GPU Hosting includes data-integrity controls managed by our SIEM platform. These controls continuously monitor and alert when unexpected alterations or deletion of ePHI occur. Further protections include real-time File Integrity Monitoring (FIM) of critical files, database integrity checks via checksums and transaction logs, and rigorous data validation. Our systems perform continuous log analysis and network monitoring, triggering immediate alerts and a defined incident-response plan upon detecting unauthorized alterations. Detailed audit trails are maintained, and regular security assessments ensure ongoing compliance with HIPAA integrity standards – the best protection against data corruption and manipulation. ### Transmission Security Atlantic.Net ensures ePHI transmission security through GPU data encryption, both within the data center and across external networks. Any workload being processed is encrypted to meet HIPAA requirements. When combined with our comprehensive network security measures, GPU customers get access to our secure ecosystem designed to prevent unauthorized access and safeguard data during transit. This includes encryption protocols, secure network configurations, and continuous monitoring to maintain the confidentiality and integrity of ePHI during all transmission activities. ### Encryption Atlantic.Net's HIPAA GPU Hosting uses multi-layered encryption to secure ePHI at rest. This includes Full Disk Encryption (FDE) with AES-256 for all GPU server storage, optional encrypted file systems, and hardware-based memory encryption where applicable. Secure key management is provided by Key Encryption Keys (KEKs), regular key rotation, and Hardware Security Modules (HSMs) or KMS integration. Logical data partitioning isolates ePHI, and application-level encryption can be used for specific workloads, ensuring comprehensive protection. To maintain compliance, rigorous key-management practices are enforced – including secure generation, storage, and rotation of encryption keys. Encryption configurations and key management are audited at least twice a year. This approach ensures that ePHI on GPU servers and storage devices remains protected against unauthorized access. ### Disaster Recovery and Backup Atlantic.Net's HIPAA GPU hosting platform provides reliable backup and disaster recovery options to safeguard your critical data and ensure business continuity. We offer secure off-site backups for your GPU server data and configurations, scheduled to meet your specific needs and align with HIPAA retention policies. Backups provide a reliable safeguard against data loss, though restore times may vary. For organizations requiring minimal downtime, we offer replication for enhanced availability, creating copies of your data in a secondary location. While replication offers faster recovery, failover may require manual intervention and potential restore times. Whether you choose off-site backups or replication, Atlantic.Net prioritizes data integrity and security. All backups and replicated data are encrypted, and robust validation procedures ensure data accuracy. ### Software and Application Security To exceed HIPAA requirements, Atlantic.Net maintains all software and applications with the latest security patches and updates, minimizing vulnerabilities. Intrusion detection and prevention systems (IDPS) are deployed to continuously monitor for and block malicious activity, safeguarding against unauthorized access and data breaches. We conduct regular vulnerability scanning and penetration testing to proactively identify and address potential security weaknesses, while secure coding practices are enforced for custom applications. ### Network Security Strong network security is needed to protect the HIPAA platform. We deploy stateful firewalls and Web Application Firewalls (WAF) to control network traffic and prevent unauthorized access. We implement secure network configurations, including virtual private networks (VPNs) and network segmentation, to isolate ePHI and restrict access to authorized users. ## What Is HIPAA Compliance? The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is an important legislative framework created to safeguard the integrity and confidentiality of protected health information. The protection of Electronic Protected Health Information (ePHI) is not only a regulatory requirement but an ethical obligation, especially when implementing advanced technologies like GPU computing. HIPAA requires that covered entities – healthcare providers, health plans, and healthcare clearinghouses, along with their business associates – implement and adhere to the administrative, physical, and technical safeguards of HIPAA. These safeguards ensure the confidentiality, integrity, and availability of ePHI, building patient trust and addressing the risk associated with data breaches. At Atlantic.Net, we understand the critical importance of HIPAA compliance. Our GPU HIPAA Hosting platform is designed to meet and exceed these rigorous standards. We help healthcare organizations implement AI/ML workloads for cutting-edge applications – AI-driven diagnostics, genomic research, and more – while maintaining unwavering security. Atlantic.Net provides and manages the entire infrastructure needed for handling sensitive patient data such as personally identifiable health information, medical records, test results, and billing details. By choosing Atlantic.Net, healthcare organizations demonstrate a proactive commitment to protecting patient privacy and maintaining the trust of those they serve. ## Importance of HIPAA Compliance in Healthcare GPU Hosting Security and privacy are fundamental to HIPAA compliance. The healthcare industry is a prime target for hacking communities and rogue individuals, and the hosting environment must provide the backbone security needed to safeguard sensitive data. Implementing AI/ML technology that integrates graphics processing units can provide huge benefits: fast-track your research and development, train chatbots that provide first-line support for your healthcare organization, or enhance the datasets needed in a clinical trial. The use cases for high-performance computing in healthcare are limitless – a real growth area that will accelerate your practice expansion. However, with great power comes great responsibility. Let's take a deeper dive into how Atlantic.Net protects your AI/ML healthcare workloads. ## Optimized Software Stack for Peak GPU Performance To maximize computing power for your compute-intensive tasks, Atlantic.Net's GPU Cloud Accelerated by NVIDIA provides a finely tuned software stack that ensures optimal performance and streamlines your AI/ML workflows. ### NVIDIA Drivers and CUDA Toolkit Unlock the full potential of the dedicated GPU card with the latest NVIDIA drivers, optimized for AI/ML. The included NVIDIA CUDA Toolkit provides a comprehensive development and deployment environment for GPU-accelerated applications, giving you granular control over your high-performance computing resources. ### NVIDIA cuDNN Accelerate model development and deployment with NVIDIA cuDNN. This GPU-accelerated library delivers highly optimized routines for neural-network training and inference, directly integrated into our GPU VPS and dedicated server offerings. ### Docker with NVIDIA Container Toolkit Ensure consistency and reliability of cloud services across diverse environments. Our custom GPU stack can integrate Docker with the NVIDIA Container Toolkit, simplifying the deployment of GPU-accelerated containers for image data and other complex workloads. ### NVIDIA NGC Integration Jumpstart your AI/ML projects with NVIDIA NGC. Get direct access to a vast repository of pre-trained models, SDKs, and optimized frameworks that empower you to accelerate your development lifecycle from initial concept to final deployment. ## How GPU Dedicated Servers Work GPU Architecture and Functionality GPUs are designed with a large number of cores that execute multiple operations concurrently, making them well suited for parallel processing. This architecture contrasts with CPUs, which typically have fewer, more powerful cores optimized for sequential processing. In a GPU, thousands of small cores work together to perform many calculations simultaneously, enabling efficient handling of complex computations and large datasets. GPUs are equipped with specialized cores optimized for different tasks: - CUDA cores are the standard for general parallel computations, ideal for applications such as machine learning and simulations. - Tensor cores, available in modern NVIDIA GPUs, are specifically designed for accelerating deep-learning tasks like matrix operations – critical for training and inference on AI models. - RT cores (ray-tracing cores) handle real-time rendering of realistic lighting and shadows, making them essential in gaming and visualization. ## Integration into Server Environments Some GPUs also support sparsity-aware operations, where sparsity cores optimize processing by skipping redundant data points. Memory plays a significant role in GPU performance. DDR memory (such as GDDR6) is commonly used for high-speed data access, suitable for most computational workloads. Advanced memory types like HBM (High Bandwidth Memory) provide greater bandwidth and energy efficiency, ideal for memory-intensive tasks like large-scale scientific simulations or AI training. Integrating GPUs into server environments involves configuring hardware and software to maximize the GPU's processing capabilities. GPU servers are equipped with one or more GPU cards connected to the motherboard – typically through PCIe slots, which offer high-speed data transfer rates. These cards are often housed in specialized enclosures or mounted in dedicated servers, designed with adequate cooling systems to handle the heat generated by intensive GPU processing. On the software side, GPU integration requires compatible drivers, libraries, and APIs like CUDA or OpenCL, which let applications access the GPU's processing power. This setup enables efficient use of resources across applications, from data processing in scientific research to high-definition video rendering used in media production. Server environments often include resource-allocation tools such as Kubernetes or Docker to manage workloads and scale resources dynamically. ## Frequently Asked Questions About HIPAA GPU Hosting ### What is HIPAA GPU Hosting? HIPAA GPU Hosting is GPU-accelerated cloud or dedicated hosting delivered inside a HIPAA-audited environment. It combines the parallel-processing performance of NVIDIA GPUs with the administrative, physical, and technical safeguards required by the HIPAA Security Rule for workloads that handle ePHI. ### Which NVIDIA GPUs does Atlantic.Net offer for HIPAA workloads? NVIDIA H100 NVL for the most demanding AI/ML training and data-analysis workloads, and NVIDIA L40S for graphics-intensive applications such as medical imaging, 3D visualization, and advanced simulations. Both are deployed inside the HIPAA-audited environment with BAA support. ### What healthcare workloads benefit most from GPU acceleration? AI-driven diagnostics, medical-imaging analysis (CT, MRI, X-ray), genomic data processing, drug-discovery model training, clinical-trial data analysis, predictive risk modeling, NLP on clinical notes, and large-scale simulation. Anything that benefits from massive parallel matrix math typically wins on a GPU. ### Will Atlantic.Net sign a Business Associate Agreement (BAA) for GPU workloads? Yes. Atlantic.Net signs a HIPAA BAA with customers handling ePHI on GPU resources, the same way it does for the rest of the HIPAA-compliant hosting product line. Contact our Sales Department to obtain a copy. ### How is ePHI protected on shared vs. dedicated GPU resources? On dedicated GPUs, the GPU is reserved for your workloads only – no other tenant. On shared GPU resources, isolation is enforced through hypervisor and OS-level controls, RBAC, and encryption. Customers handling sensitive ePHI typically choose dedicated resources for predictability and clearer audit boundaries; shared resources cost less and are common for non-PHI training and validation workloads. ### How is ePHI encrypted on GPU servers? AES-256 Full Disk Encryption (FDE) at rest on all GPU server storage, optional encrypted file systems, hardware-based memory encryption where applicable, and TLS in transit. Key management uses Key Encryption Keys (KEKs) with regular rotation, and integrates with HSMs or KMS as required. Encryption configurations and key management are audited at least twice a year. ### What software stack is pre-tuned for GPU performance? NVIDIA drivers and CUDA Toolkit, NVIDIA cuDNN for deep-learning training and inference, Docker with the NVIDIA Container Toolkit for portable GPU containers, and integration with NVIDIA NGC for pre-trained models, SDKs, and optimized frameworks. ### How does HIPAA GPU hosting handle disaster recovery and backups? Off-site encrypted backups and replication options align with HIPAA contingency-plan requirements (45 CFR § 164.308(a)(7)). Backup frequency, retention, and the secondary-site architecture (hot/warm/cold) are sized to your RTO and RPO targets during onboarding. ### Where are HIPAA GPU resources hosted? Atlantic.Net's HIPAA GPU resources run inside the audited Atlantic.Net data center footprint in the United States. Most US locations now offer GPU services, with additional capacity coming online. The same audited environment hosts cloud, dedicated, and bare-metal HIPAA workloads, so customers can mix products inside one compliance perimeter. ### How is HIPAA GPU Hosting priced? Pricing depends on the GPU model selected (H100 NVL, L40S), whether you use dedicated or shared resources, the size of the protected workload, and the bundled managed services (firewall, backup, DR, MFA, etc.). Contact our sales team for a quote tailored to your environment. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Dedicated GPU Hosting by Atlantic.Net > URL: https://www.atlantic.net/gpu-server-hosting/gpu-dedicated-hosting/ | Updated: 2026-09-16 Run AI, machine learning, rendering, and scientific workloads on customizable physical servers with NVIDIA L40S or H100 NVL GPUs, Intel Xeon CPUs, NVMe storage, high-bandwidth networking, and full root access. - NVIDIA L40S & H100 NVL - Full Root Access & Control - Custom CPU, RAM, Storage & Network - 100% Uptime SLA H100 NVL HBM3 Memory: 94 GB H100 NVL Memory Bandwidth: 3.9 TB/s ## Atlantic.Net Dedicated GPU Hosting, Accelerated by NVIDIA Unleash the full potential of your AI, machine learning, and high-performance computing workloads with Atlantic.Net's dedicated GPU server hosting. We offer a comprehensive range of servers equipped with the latest NVIDIA® GPUs, including the versatile L40S and the performance-leading H100 NVL. Experience the difference between next-generation Intel® CPUs, ultra-fast NVMe storage, and high-bandwidth network connectivity, all designed to maximize your performance and efficiency. ## Experience the NVIDIA Advantage Regardless of your specific needs, high-performance GPU servers provide best-in-class performance, reliability, and a comprehensive ecosystem of software and tools to accelerate your most demanding workloads. Our purpose-built GPU servers are engineered to deliver a seamless and optimized experience, empowering you to achieve groundbreaking results. ## High-Performance Dedicated GPU Server Hosting at Atlantic.Net Many industries now rely on applications that demand significant computing power. From training complex deep learning models to rendering high-fidelity graphics or conducting scientific research using artificial intelligence, the need for robust computing resources is undeniable. Atlantic.Net's dedicated GPU server hosting solutions provide the infrastructure and hardware needed to handle these demanding tasks. ## Atlantic.Net Dedicated GPU Hosting Massive Computing Power Transform your AI and ML workflow with Atlantic.Net. Discover the power and speed of our Dedicated GPU Hosting. ## Features of Atlantic.Net's Dedicated GPU Server Hosting Experience the Atlantic.Net difference, by embracing our class-leading GPU hosting service. ### Powerful NVIDIA GPUs Get the right GPU dedicated server, including the latest Ampere and Ada Lovelace architectures. These graphics processing units (GPUs) provide parallel processing power that surpasses traditional central processing units (CPUs). Power through intense AI workloads in seconds and integrate AI/ML routines into your applications. ### Latest Generation CPUs Our dedicated servers are equipped with the latest Intel® Xeon® CPU, delivering strong processing power and intense bus bandwidths to keep the GPU busy and your costs down. ### Fast NVMe Storage Benefit from fast storage speeds with NVMe SSDs, which offer significantly better read and write performance than traditional SATA SSDs, again powering intense I/O workloads for the GPU to process. ### High-Bandwidth Network Our GPU servers are connected to a high-bandwidth, low-latency network, ensuring rapid data transfer between all layers of the networking stack. ### Customizable Server Configurations Tailor your GPU-dedicated server to your specific needs. Choose from a variety of CPU, RAM, storage, and networking options. Choose to split GPU usage with NVLink, or get exclusive GPU access with our dedicated server hosting. ### Root Access and Control Enjoy full root access and control over your server environment, enabling you to install and configure software as needed. Need bespoke GPU driver versions, or perhaps PyTorch? You can install whatever you need with root access. We also provide remote server management and tools for added convenience from an intuitive UI on our Web Console. ### Reliable Infrastructure Our GPU servers are housed in modern data centers with redundant power, cooling, and network connectivity, promoting uptime. Atlantic.Net is proud to offer a 100% Uptime SLA. ### Comprehensive Support from Your Hosting Provider We understand that reliable performance is crucial. As your hosting provider, Atlantic.Net offers technical support to help you manage your powerful servers and ensure optimal performance for your high-performance computing capabilities. We handle the server management, allowing you to focus on your core work. This commitment to cost efficiency and ensuring optimal performance makes us a leading choice among GPU hosting providers. We also support NVIDIA's multi-instance GPU technology. ## Why Consider an Atlantic.Net GPU Dedicated Server? Here's what sets Atlantic.Net apart: ### Proven Expertise Operating since 1994, Atlantic.Net is an established provider of cloud and dedicated hosting solutions. With over three decades of experience in cloud and dedicated hosting, we understand the demands of high-performance computing. ### Optimized Performance Our high-performance GPU servers are optimized to deliver the computing power needed for demanding tasks. Engineered for maximum throughput, delivering the raw power you need for demanding AI/ML and HPC workloads. ### Industry Leading Reliability We focus on providing a robust infrastructure and high uptime for smooth application performance. ### Robust Security Your data is protected by comprehensive security measures, including encryption, access controls, and regular audits. ### Dedicated Support Our expert support team is available 24/7 to assist you with any technical challenges. ### Exceptional Value We offer competitive pricing and flexible plans to suit various budgets and needs, including options for GPU rental and multiple GPUs. ### Compliance Our solutions meet industry standards, including HIPAA, HITECH, PCI DSS, and SOC 2 and 3 compliance. ## Powering Your Workloads: A Choice of Powerful GPUs We understand that different tasks demand different levels of processing power. That's why we offer two cutting-edge high-performance NVIDIA GPUs, each designed to provide maximum performance. Our GPU hosting leverages NVLink technology to distribute and share GPU resources between the cloud instances. If you need dedicated resources, our Dedicated GPU Server Hosting has got you covered. ### NVIDIA L40S GPU The NVIDIA L40S GPU, powered by the cutting-edge NVIDIA Ada Lovelace architecture, is a versatile powerhouse designed to accelerate a wide spectrum of professional workloads. From training advanced AI models and rendering photorealistic graphics to encoding high-resolution video, the L40S delivers exceptional performance and efficiency. Key features: Blazing-Fast Performance: Experience unparalleled speed for complex computations with 18,176 CUDA® Cores. AI Acceleration: Supercharge your AI and deep learning workflows with 568 Tensor Cores, enabling faster training and inference. Stunning Visuals: Achieve breathtaking realism in graphics rendering with 142 RT Cores dedicated to real-time ray tracing. Massive Memory Capacity and Bandwidth: Handle large datasets and complex models with 48GB of GDDR6 memory featuring ECC for data integrity and 864 GB/s of memory bandwidth for rapid data transfer. Ideal for: AI model training and inference Graphics rendering and visualization Video encoding and transcoding High-performance computing ### NVIDIA H100 NVL For those pushing the boundaries of large-scale AI and high-performance computing, the NVIDIA H100 NVL represents the pinnacle of performance. Built on the revolutionary NVIDIA Hopper architecture, the H100 NVL delivers unmatched scalability and speed for the most demanding workloads. Key features: Unprecedented Compute Power: Harness the immense computational capabilities of 14,592 CUDA® Cores for tackling massive datasets and intricate models. Accelerated AI Training and Inference: Optimize AI workflows with 456 Tensor Cores, enabling faster training and more efficient inference. Massive HBM3 Memory: Access and process vast datasets at lightning speed with 94GB HBM3 memory. Unrivaled Memory Bandwidth: Experience unprecedented data throughput with 3.9 TB/s of memory bandwidth, ensuring seamless performance for the most demanding applications. Optimized for Transformers: Leverage the 4th Gen Transformer Engine for peak performance in training and deploying transformer-based deep learning models. Ideal for: Training and deploying large language models (LLMs) High-performance computing (HPC) Scientific simulations and research Large-scale data analytics and machine learning ## Dedicated GPU Server Use Cases Our GPU-dedicated powerful servers are suitable for a range of compute-intensive applications, including: - Artificial Intelligence (AI): Train and deploy AI models efficiently. - Machine Learning (ML): Accelerate machine learning tasks, such as image recognition and natural language processing. - Deep Learning: Support the development of complex deep learning models with large datasets. - High-Performance Computing (HPC): Handle demanding high-performance computing tasks such as scientific simulations, financial modeling, and genomic research. - Graphics and Video Rendering: Create visuals for video games, 3D animation, visual effects, and video rendering efficiently. - Data Analytics: Analyze large datasets and gain insights with accelerated data processing. - Cloud Gaming: Deliver smooth gaming experiences with GPU instances optimized for cloud gaming. - Scientific Computing: Run complex scientific computing workloads effectively. ## Benefits of GPU Dedicated Servers Dedicated GPU servers offer a range of benefits for handling resource-intensive applications and high-volume data processing. Some of the key advantages include: - Enhanced processing speed: GPU servers perform complex calculations much faster than CPU-based servers by leveraging parallel processing. This speed is crucial for applications in AI, scientific research, and media production, where tasks involve vast data sets and require rapid computation. - Scalability for high-demand applications: GPU servers can scale efficiently to meet the demands of computationally heavy workloads. This scalability supports applications that grow in complexity, such as large machine learning models or real-time analytics, enabling them to handle more extensive and demanding datasets over time. - Efficient resource utilization: By offloading specific tasks to the GPU, applications can use server resources more efficiently, freeing up the CPU for other processing tasks. This efficiency optimizes performance across applications, enhancing overall server responsiveness. - Reduced processing time for data-intensive workloads: GPU servers accelerate tasks that traditionally require long processing times, such as rendering, simulation, and model training. This reduction in time helps organizations deliver results faster, boosting productivity in workflows dependent on high-speed computation. - Support for modern software frameworks: GPU servers are compatible with leading software frameworks like CUDA, TensorFlow, and PyTorch, which are optimized for GPU acceleration. This support enables developers and researchers to integrate cutting-edge libraries for advanced analytics and AI model development. - Improved data processing in real-time: GPU servers handle real-time data processing effectively, making them ideal for applications that require instant results, such as video processing, virtual reality, and streaming. Real-time capabilities allow businesses to deliver enhanced user experiences in dynamic environments. ## Optimized Software Stack for Peak GPU Performance To maximize computing power for your compute-intensive tasks, Atlantic.Net's GPU Cloud Accelerated by NVIDIA provides a finely tuned software stack that ensures optimal performance and streamlines your AI/ML workflows. ### NVIDIA Drivers and CUDA Toolkit Unlock the full potential of the dedicated GPU card with the latest NVIDIA drivers, optimized for AI/ML. The included NVIDIA CUDA Toolkit provides a comprehensive development and deployment environment for GPU-accelerated applications, giving you granular control over your high-performance computing resources. ### NVIDIA cuDNN Accelerate model development and deployment with NVIDIA cuDNN. This GPU-accelerated library delivers highly optimized routines for neural network training and inference, directly integrated into our GPU VPS and dedicated server offerings. ### Docker with NVIDIA Container Toolkit Ensure consistency and reliability of cloud services across diverse environments. Our custom GPU stack can integrate Docker with the NVIDIA Container Toolkit, simplifying the deployment of GPU-accelerated containers for image data and other complex workloads. ### NVIDIA NGC Integration Jumpstart your AI/ML projects with NVIDIA NGC. Get direct access to a vast repository of pre-trained models, SDKs, and optimized frameworks that empower you to accelerate your development lifecycle from initial concept to final deployment. ## How GPU Dedicated Servers Work GPU Architecture and Functionality GPUs are designed with a large number of cores that execute multiple operations concurrently, making them well-suited for parallel processing. This architecture contrasts with CPUs, which typically have fewer, more powerful cores optimized for sequential processing. In a GPU, thousands of small cores work together to perform many calculations simultaneously, enabling efficient handling of complex computations and large datasets. GPUs are equipped with specialized cores optimized for different tasks, which enhance their performance across various applications. For instance, - CUDA cores are the standard for general parallel computations, ideal for applications such as machine learning and simulations. - Tensor cores, available in GPU computing, are specifically designed for accelerating deep learning tasks like matrix operations. These are critical in training and inference for AI models. - RT cores, or ray-tracing cores, handle real-time rendering of realistic lighting and shadows, making them essential in gaming and visualization. Some GPUs also support sparsity-aware operations, where sparsity cores optimize processing by skipping redundant data points. In addition to core types, memory plays a significant role in GPU performance. DDR (Double Data Rate) memory, such as GDDR6, is commonly used for high-speed data access, making it suitable for most computational workloads. Advanced memory types like HBM (High Bandwidth Memory) provide greater bandwidth and energy efficiency, making them ideal for memory-intensive tasks like large-scale scientific simulations, or AI training. Integration into Server Environments Integrating GPUs into server environments involves configuring hardware and software to maximize the GPU's processing capabilities. GPU servers are equipped with one or more GPU cards connected to the server's motherboard, typically through PCIe slots, which offer high-speed data transfer rates. These cards are often housed in specialized enclosures or mounted in dedicated servers, designed with adequate cooling systems to handle the heat generated by intensive GPU processing. On the software side, GPU integration requires compatible drivers, libraries, and APIs like CUDA or OpenCL, which allow applications to access the GPU's processing power. This setup enables the efficient use of resources across various applications, from data processing in scientific research to high-definition video rendering used in media production. Additionally, server environments often include resource allocation tools, such as Kubernetes or Docker, to manage workloads and scale resources dynamically. ## GPU Hosting Plans ### Fortress Business GPU Hosting H100 NVL GPU $4,729.44 Per Month 28 vCPU's 240 GB of DDR 5 Ram 2.4 TB NVMe SSD Raid 10 Storage 10 TB of Monthly Data Transfer - Fully Managed Hosting Package - Fully Managed FortiGate Firewall with Intrusion Prevention System - ( 5 ) Managed VPN's - Fully Managed Daily Backups ( Local ) - Fully Managed Daily Backups ( Off-Site ) - DUO Proxy Multi-Factor Authentication ( 5 users ) - TrendMicro Security Suite - Fully Managed DDos / CDN / WAF - Scheduled Vulnerability Scans ### Fortress Custom GPU Hosting Maximum security, customization, and premium SLAs Custom Bare Metal Hosting - Fully Managed Hosting Package - Fully Managed FortiGate Firewall with Intrusion Prevention System - ( 5 ) Managed VPN's - Fully Managed Daily Backups ( Local ) - Fully Managed Daily Backups ( Off-Site ) - DUO Proxy Multi-Factor Authentication ( 5 users ) - TrendMicro Security Suite - Fully Managed DDos / CDN / WAF - Scheduled Vulnerability Scans *$450 setup fee applies *Pricing based upon 12-month term commitment *Prices based upon Linux Operating System. Windows Operating System available at an additional cost. ***Save up to 30% off above listed pricing with longer billing terms*** *Due to global supply-chain volatility, Dedicated Host pricing is subject to change but will be confirmed prior to deployment. ## Frequently Asked Questions About Dedicated GPU Hosting ### What is a dedicated GPU server? A dedicated GPU server is a physical server equipped with one or more high-performance graphics processing units (GPUs) that is exclusively allocated to a single customer. Unlike shared GPU cloud instances, you get full access to all GPU, CPU, memory, and storage resources without competing for compute time. GPUs provide massively parallel processing capabilities that far exceed traditional CPUs for workloads like AI/ML training, deep learning inference, scientific simulations, and graphics rendering. ### What NVIDIA GPUs does Atlantic.Net offer? Atlantic.Net offers two NVIDIA GPU options. The NVIDIA L40S, built on the Ada Lovelace architecture, features 18,176 CUDA Cores, 568 Tensor Cores, 142 RT Cores, and 48GB of GDDR6 ECC memory – ideal for AI training and inference, graphics rendering, and video encoding. The NVIDIA H100 NVL, built on the Hopper architecture, delivers 14,592 CUDA Cores, 456 Tensor Cores, 94GB of HBM3 memory, and 3.9 TB/s bandwidth with a 4th Gen Transformer Engine – designed for large language model training, HPC, and large-scale data analytics. ### What is the difference between the NVIDIA L40S and H100 NVL? The L40S is a versatile GPU that excels across AI/ML, graphics rendering, and video encoding workloads, offering a balanced mix of CUDA, Tensor, and RT Cores with 48GB GDDR6 memory. The H100 NVL is purpose-built for the most demanding AI training and HPC workloads, featuring 94GB of ultra-fast HBM3 memory with 3.9 TB/s bandwidth and a 4th Gen Transformer Engine optimized for large language models and transformer-based architectures. The L40S is the right choice for mixed workloads while the H100 NVL is best for large-scale AI training and scientific computing that requires maximum memory bandwidth. ### What workloads are dedicated GPU servers best suited for? Dedicated GPU servers are ideal for compute-intensive workloads that benefit from parallel processing. Common use cases include AI and machine learning model training, deep learning inference, large language model (LLM) development, high-performance computing (HPC), scientific simulations and research, genomic analysis, financial modeling, 3D graphics rendering and visual effects, video encoding and transcoding, real-time data analytics, and cloud gaming. Any application that processes large datasets or performs complex mathematical operations in parallel will see significant performance gains on GPU hardware. ### What software stack is included with GPU servers? Atlantic.Net's GPU servers come with an optimized software stack that includes the latest NVIDIA drivers, the NVIDIA CUDA Toolkit for GPU-accelerated application development, and NVIDIA cuDNN for optimized neural network training and inference. Docker with the NVIDIA Container Toolkit is available for containerized GPU workloads, and NVIDIA NGC integration gives you access to pre-trained models, SDKs, and optimized frameworks. The stack supports popular AI/ML frameworks including TensorFlow, PyTorch, and CUDA. You also have full root access to install any additional software or custom GPU driver versions you need. ### What is NVLink and multi-instance GPU (MIG)? NVLink is NVIDIA's high-speed interconnect technology that allows multiple GPUs to communicate directly with each other at much higher bandwidth than traditional PCIe connections. This enables GPU resources to be pooled and shared across cloud instances for improved performance on large-scale workloads. Multi-instance GPU (MIG) technology, supported on Atlantic.Net's GPU servers, allows a single physical GPU to be partitioned into multiple isolated GPU instances, each with its own dedicated compute, memory, and bandwidth resources. This lets you run multiple workloads simultaneously on a single GPU with hardware-level isolation. ### Can I customize my GPU server configuration? Yes. Atlantic.Net's dedicated GPU servers are fully customizable. You can choose your GPU model (L40S or H100 NVL), CPU configuration, amount of RAM, NVMe storage capacity, and networking options. You can also opt for exclusive dedicated GPU access or share GPU resources via NVLink depending on your workload requirements. Our team will work with you to configure a server that matches your specific performance and budget needs. ### Are Atlantic.Net's GPU servers compliant with industry standards? Yes. Atlantic.Net's GPU server infrastructure meets industry compliance standards including HIPAA, HITECH, PCI DSS, and SOC 2 and SOC 3 certifications. GPU servers are housed in the same audited, certified data centers as all Atlantic.Net hosting services, with comprehensive security measures including encryption, access controls, and regular audits. This makes them suitable for organizations in healthcare, finance, and other regulated industries that need GPU compute power within a compliant hosting environment. ### What is the difference between a dedicated GPU server and a GPU cloud instance? A dedicated GPU server provides you with the entire physical machine – CPU, GPU, RAM, and storage – exclusively for your use, with no shared resources or hypervisor overhead. A GPU cloud instance runs on shared infrastructure where GPU resources may be partitioned via NVLink or MIG across multiple tenants. Dedicated GPU servers deliver more consistent performance, lower latency, and full hardware-level control, making them the better choice for sustained, high-throughput workloads like model training. GPU cloud instances offer more flexibility and on-demand scalability for shorter or variable workloads like inference. ### How do I get started with Atlantic.Net GPU hosting? You can get started by contacting Atlantic.Net's sales team through the contact form on this page, via live chat, by calling 866-618-DATA (3282), or by emailing sales@atlantic.net. Our team will discuss your workload requirements, recommend the right GPU configuration, and provide a custom quote. Atlantic.Net also offers 24/7 expert technical support to help you set up your environment and optimize performance once your server is deployed. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # GPU Cloud Hosting by Atlantic.Net > URL: https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/ | Updated: 2026-09-16 Launch H100 NVL or L40S GPU instances for AI/ML, HPC, rendering, and simulation workloads with shared or dedicated GPU allocation, high-speed NVMe storage, and flexible billing. - NVIDIA H100 NVL & L40S - Shared or Dedicated GPUs - Up to 8 GPUs per Instance - 100% Uptime SLA Deployment Time: Under 60 sec Multi-GPU Scale: Up to 8 GPUs ## Atlantic.Net GPU Cloud Hosting, Powered by NVIDIA Get access to massive computing power for your data and AI workloads with the new Atlantic.Net GPU Cloud Hosting solutions, powered by NVIDIA. Our GPU-hosted solutions offer incredible performance at an even better price point. Start building today with GPU-accelerated performance to fine-tune and scale your AI/ML workload. ## GPU Cloud Hosting Plans Transform your AI and ML workflows with Atlantic.Net. Discover the power and speed of our On-Demand GPUs in the Cloud. | | | | | | | | | --- | --- | --- | --- | --- | --- | --- | | AL40S.192GB | 192GB | 32 | 1 x L40S | 1400GB | 12 TB | On-Demand: $1,120.9/mo $1.668/hr; 1-Year: $1,108.0/mo $1.6488/hr; 3-Year: $1,058.7/mo $1.5755/hr | | AH100NVL.240GB | 240GB | 28 | 1 x H100NVL | 2400GB | 15 TB | On-Demand: $2,648.4/mo $3.941/hr; 1-Year: $2,546.7/mo $3.7898/hr; 3-Year: $2,407.8/mo $3.583/hr | *The hourly rate for GPU Cloud Servers is determined by dividing the monthly rate by 730 hours. There is no additional cost for going over 730 hours in a given calendar month and usage below 730 hours will be billed at the hourly billing rate. *Prices listed above are based on the service being utilized for the period specified. *All Servers include one IPv4 Address. Additional IPs are available for $3.65/month ($0.005431/hour) *Unlimited inbound bandwidth. If free outbound bandwidth is exceeded, each additional GB is $0.02 *Optional Daily Backups are available for 20% of the server price. Minimum $1.00/month. *cPanel licensing cost starts at $23 per month ## Atlantic.Net Cloud GPU Hosting Massive Computing Power Up in 60 Seconds! Transform your AI and ML workflows with Atlantic.Net. Discover the power and speed of our On-Demand GPUs in the Cloud. ## Key Features of Atlantic.Net GPU Cloud Hosting ### Cutting-Edge Hardware Atlantic.Net Cloud Platform (ACP) has some of the most powerful cloud instances available. Our Cloud runs on top quality SuperMicro and Dell server hardware. We use SSD storage throughout, with NVMe options available. Coupled with our ultra-high bandwidth network connectivity, we have the capacity and connectivity to let your AI applications thrive. ### Security Defined Infrastructure ACP is built from the ground up with security at the forefront of the design process. Our data centers and our workforce adhere to the highest security standards. We manage sensitive data with secure efficiency for our technology, e-commerce, healthcare clients, and scientific researchers. ### We Are Compliant! Dedicated to data security and privacy, Atlantic.Net maintains key compliance certifications, to be in compliance with HIPAA/HITECH, PCI DSS, SOC 2/3, and GDPR, which focus on ensuring robust protection for sensitive information. ### 24x7x365 Support Our USA-based support services team is available around the clock, every day of the year to help you with any GPU instance query. ### 100% Uptime SLA Atlantic.Net is so confident in the reliability, security and robust architecture of our cloud platforms that we offer a 100% uptime SLA. Meaning you can get more work done safely in the knowledge that the infrastructure is healthy and available around the clock. ## GPU Cloud vs. Dedicated GPU Hosting | Feature | GPU Cloud Hosting | Dedicated GPU Hosting | | --- | --- | --- | | Deployment Speed | Under 60 seconds with 1-click apps | Custom engagement & provisioning | | Billing Model | Hourly, monthly, or 1/3-year reserved | Monthly or custom contract | | GPU Access | Shared or dedicated allocation | Full dedicated hardware | | Root Access | Yes | Yes | | Scalability | On-demand, resize instantly | Fixed hardware, upgrade via provisioning | | Best For | Dev/test, bursty workloads, prototyping | Long-running training, production inference | | Multi-GPU Options | Up to 8 GPUs per instance | Up to 8 GPUs per server | | Compliance | HIPAA, PCI DSS, SOC 2/3, GDPR | HIPAA, PCI DSS, SOC 2/3, GDPR | | Uptime SLA | 100% | 100% | ## GPU Cloud Hosting Use Cases Atlantic.Net GPU Cloud Hosting powers demanding workloads across industries. From AI model training to real-time rendering, our NVIDIA-powered infrastructure delivers the performance you need. ### AI Model Training & Fine-Tuning Train large language models, fine-tune foundation models, and run distributed deep learning experiments at scale with multi-GPU instances featuring up to 8x NVIDIA H100 NVL GPUs. ### Machine Learning Inference Deploy low-latency ML inference pipelines for real-time predictions, recommendation engines, and intelligent automation with flexible GPU allocation. ### Scientific Research & Simulation Accelerate computational fluid dynamics, molecular modeling, genomic analysis, and other HPC workloads with dedicated GPU compute and high-speed NVMe storage. ### Video Rendering & Processing Process high-resolution video encoding, 3D rendering, and real-time visual effects with NVIDIA L40S GPUs purpose-built for graphics-intensive applications. ### Financial Modeling & Analytics Run Monte Carlo simulations, risk analysis, quantitative research, and algorithmic trading strategies at speeds that give your firm a competitive edge. ### Natural Language Processing Build and deploy conversational AI, text generation, sentiment analysis, and document understanding models with the memory and bandwidth your NLP pipelines demand. ## Atlantic.Net Cloud GPU Instances Ready to unleash the power of GPU computing? Getting started with Atlantic.Net is easy. Simply sign up for our Cloud Hosting Platform, then follow these simple steps: ### Choose the Perfect GPU: GPU Model: Select from powerful NVIDIA H100 NVL or NVIDIA L40S GPUs. Allocation: Choose between shared GPU allocation for cost-effectiveness or dedicated GPU instances for maximum performance. VRAM: Specify the VRAM you need to match your workload demands. ### Configure Your Instance: vCPUs: Determine the optimal number of vCPUs for your applications. RAM: Allocate the necessary amount of physical RAM. Storage: Choose the right storage for your needs: high-performance NVMe or reliable Enterprise SSD. Operating System: Select your preferred operating system from a variety of Linux distributions and Windows versions. ### Launch and Manage: Instant Deployment: Spin up your GPU instance in minutes, or even faster with our 1-click, pre-configured virtual machine options (under 30 seconds!). Intuitive Control Panel: Effortlessly manage your instances through our user-friendly control panel. Secure Access: Manage SSH keys for secure and controlled access. Networking: Configure DNS settings as needed. Team Collaboration: Delegate user controls with Atlantic.Net Teams for streamlined collaboration. ### Optimize Performance and Cost: Flexible Pricing: Take advantage of our flexible pricing and billing options, including pay-as-you-go and reserved instances. Cost Optimization: Optimize your cloud GPU investment with our cost management tools. Scalability: Easily resize your instances to adapt to changing needs and manage costs effectively. ## The Most Popular NVIDIA GPUs Atlantic.Net has built its GPU Cloud with two of the most powerful NVIDIA GPUs. Our Cloud GPU Hosting utilizes NVIDIA NVLink to intelligently deploy and share GPU resources on demand. Opt for a service plan that offers exactly the right resources you demand, or go all in, and allocate the entire GPU. The power is in your hands! ### NVIDIA H100 NVL: The AI Powerhouse Need to train massive AI models? Tackle cutting-edge simulations? The NVIDIA H100 NVL is the answer. Built on the Hopper architecture, this powerful GPU has a staggering 94GB VRAM with 3.9 TB/s memory bandwidth. Tearing through computationally intensive tasks. Pushing the Limits of AI: Train the largest, most complex models and accelerate your deep learning research and conversational AI with natural language processing. Perform Complex Simulations: Ideal for scientific research or financial modeling, the H100 NVL handles complexity at unparalleled speeds. High-Performance Computing Redefined: Powering your most demanding workloads, at any scale. ### NVIDIA L40S GPU: The AI Workhorse The NVIDIA L40S GPU is the perfect balance of power and versatility for all AI workloads. Driven by the Ada Lovelace architecture and equipped with 48GB of GDDR6 memory, get ready for GPU acceleration in your machine learning projects. Streamlined AI Development: From prototyping to deployment, the L40S makes AI development faster and more efficient. Efficient Machine Learning: Train and deploy your ML models with ease, optimizing performance and resource utilization. Deep Learning Made Accessible: Tackle diverse deep learning tasks without breaking the bank. Beyond AI Graphics and Video: The L40S also shines in demanding graphics and video processing applications. ## GPU Hosting Plans ### Fortress Business GPU Hosting H100 NVL GPU $4,729.44 Per Month 28 vCPU's 240 GB of DDR 5 Ram 2.4 TB NVMe SSD Raid 10 Storage 10 TB of Monthly Data Transfer - Fully Managed Hosting Package - Fully Managed FortiGate Firewall with Intrusion Prevention System - ( 5 ) Managed VPN's - Fully Managed Daily Backups ( Local ) - Fully Managed Daily Backups ( Off-Site ) - DUO Proxy Multi-Factor Authentication ( 5 users ) - TrendMicro Security Suite - Fully Managed DDos / CDN / WAF - Scheduled Vulnerability Scans ### Fortress Custom GPU Hosting Maximum security, customization, and premium SLAs Custom Bare Metal Hosting - Fully Managed Hosting Package - Fully Managed FortiGate Firewall with Intrusion Prevention System - ( 5 ) Managed VPN's - Fully Managed Daily Backups ( Local ) - Fully Managed Daily Backups ( Off-Site ) - DUO Proxy Multi-Factor Authentication ( 5 users ) - TrendMicro Security Suite - Fully Managed DDos / CDN / WAF - Scheduled Vulnerability Scans *$450 setup fee applies *Pricing based upon 12-month term commitment *Prices based upon Linux Operating System. Windows Operating System available at an additional cost. ***Save up to 30% off above listed pricing with longer billing terms*** *Due to global supply-chain volatility, Dedicated Host pricing is subject to change but will be confirmed prior to deployment. ## GPU Cloud Hosting FAQs ### What is GPU Cloud Hosting, and why is it important for AI/ML? GPU Cloud Hosting provides on-demand access to GPU AI Accelerators. GPUs offer powerful parallel processing essential for accelerating demanding workloads like machine learning training, generative AI, and large language models (LLMs), enabling faster AI development and inference. ### How quickly can I deploy a GPU instance with Atlantic.Net? You can spin up your AI/ML project fast! With our 1-click applications, your GPU instance deploys in under 60 seconds, running your AI projects almost instantly. ### What NVIDIA GPUs does Atlantic.Net offer? As an NVIDIA Partner Network Cloud Partner (NCP), we offer cutting-edge GPUs: NVIDIA L40S GPU: Ideal for versatile AI, graphics, and video, featuring 48GB GDDR6 memory. NVIDIA H100 NVL: Designed for massive AI/HPC workloads, 94GB HBM3 memory, and exceptional bandwidth. ### Can I choose between shared and dedicated GPU resources? Yes. Choose shared GPU allocation for cost-effectiveness or dedicated GPU instances for maximum performance. You can also choose multi-GPU options up to a maximum of 8 GPUs. ### How do you run large datasets or simulations on GPU cloud servers? Use GPU cloud servers when your workload benefits from massively parallel compute, and you need faster provisioning than traditional infrastructure can provide. For large datasets, simulations, AI training, or HPC-style jobs, the right setup usually combines high-end GPUs, fast NVMe storage, strong CPU support, and enough memory and bandwidth to keep the GPUs fed efficiently. ### What are the best GPU hosting options for deep learning? The best option depends on how you plan to use it. GPU cloud is a strong fit for rapid testing, development, and elastic scaling, while dedicated GPU servers are better for long-running deep learning jobs that need stable performance, full hardware access, and predictable costs. ### Can I rent GPU servers with full root access from Atlantic.Net? Yes. Atlantic.Net offers dedicated GPU servers with full root access, which gives you full control over the operating system, drivers, frameworks, and software stack. ### How can I optimize costs with Atlantic.Net's GPU Cloud? We offer flexible pricing designed to optimize your investment. Choose pay-as-you-go (hourly) rates or reserved instances for discounts on long-term projects. Transparent costs mean no surprises. You can easily resize instances to manage both spending and scalability effectively. ### Can I scale my GPU resources as my project grows? Absolutely. Our platform is built for seamless scalability. Whether you need a single GPU for development or multi-GPU instances for large-scale High-Performance Computing (HPC) applications, you can easily resize. ### Does Atlantic.Net support different operating systems? Yes. You have full control, selecting your preferred OS from a wide range of Linux distributions and Windows versions. Our instances are also optimized to work seamlessly with leading AI/ML frameworks like TensorFlow, PyTorch, and CUDA. ### What industries benefit most from GPU cloud hosting? Industries that benefit most include AI and machine learning, financial modeling, video rendering, engineering simulation, scientific research, and manufacturing workflows that depend on high-throughput parallel processing. ### How does Atlantic.Net ensure low latency for my applications? We use ultra-high bandwidth network connectivity and high-speed SSD/NVMe storage across our global data centers. This robust infrastructure ensures your AI applications thrive with minimal latency from strategically located data centers in Orlando, New York, Dallas, San Francisco, Ashburn, Toronto, London, and Singapore. ### What kind of hardware should I look for in a GPU cloud provider? Focus on the GPU model first, then look at GPU memory, CPU performance, RAM, NVMe storage, and network bandwidth. A strong GPU platform should be designed as a complete system, not just a powerful card attached to an underpowered infrastructure. ### Are there any runtime limits on the GPU instances? No. Atlantic.Net provides cloud and dedicated resources with no hidden runtime limits, giving you full control over your computing environment for uninterrupted training and inference. ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # How to Build an Image Segmentation Pipeline with OpenCV on an Ubuntu GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-build-an-image-segmentation-pipeline-with-opencv-on-an-ubuntu-gpu-server/ | Published: 2025-03-18 | Updated: 2026-05-04 | Author: Hitesh Jethva Image segmentation is a fundamental task in computer vision that involves dividing an image into multiple segments or regions, each corresponding to different objects or parts of objects. OpenCV is a powerful library for computer vision and it provides various tools to build an image segmentation pipeline. In this article, we will go through the steps to build a simple image segmentation pipeline using OpenCV. ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 24.04 [Cloud GPU Server](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/). - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Step 1: Setting Up the Environment First, let’s set up the environment by installing the necessary packages. 1. Install Python3 and pip ```bash apt install python3 python3-venv python3-dev -y ``` 2. Create a Python virtual environment. ```bash python3 -m venv venv source venv/bin/activate ``` 3. Upgrade pip to the latest version. ```bash pip install --upgrade pip ``` 4. Install required libraries. ```bash pip3 install opencv-python numpy matplotlib ``` **Explanation:** - **opencv-python:** Provides OpenCV functionalities for image processing. - **numpy:** Essential for numerical operations and handling image data. - **matplotlib:** Used for displaying images in Jupyter Notebook. ## Step 2: Run Jupyter Notebook 1.Install Jupyter Notebook. `pip install jupyter` 2.Open your terminal and run the Jupyter Notebook. If you cannot connect to your notebook, make sure your firewall isn’t blocking access. ```bash jupyter notebook --no-browser --port=8888 --ip=your-server-ip --allow-root ``` Output. ```bash To access the server, open this file in a browser: file:///root/.local/share/jupyter/runtime/jpserver-6071-open.html Or copy and paste one of these URLs: http://your-server-ip:8888/tree?token=eab31988f685c20a6809e4c18033037d0c318a7ac97e4033 http://127.0.0.1:8888/tree?token=eab31988f685c20a6809e4c18033037d0c318a7ac97e4033 ``` 2. Open your web browser and access your Jupyter Notebook using the URL as shown in the above output. ![](https://www.atlantic.net/wp-content/uploads/2025/02/p.png) 3. Click on **File** => **New** to create a new Notebook. ## Step 3: Import Required Libraries In the first cell of your Jupyter Notebook, import the required libraries: ```bash # Import libraries import cv2 import numpy as np import matplotlib.pyplot as plt ``` **Explanation:** - **cv2:** OpenCV library for image processing. - **numpy:** For numerical operations. - **matplotlib.pyplot:** For displaying images in the notebook. ## Step 4: Load and Display the Image In the next cell, load an image and display it using matplotlib: Note: You will need to upload an image to your server. You can do this using a tool like WinSCP or FileZilla. ```bash # Load an image from file image = cv2.imread('my_image.jpg') # Check if the image was loaded successfully if image is None: print("Error: Could not load image.") else: # Convert the image from BGR to RGB (OpenCV loads images in BGR format) image_rgb = cv2.cvtColor(image, cv2.COLOR_BGR2RGB) # Display the image using matplotlib plt.imshow(image_rgb) plt.title('Original Image') plt.axis('off') # Hide axis plt.show() ``` **Explanation:** - **cv2.imread(‘my_image.jpg’):** Loads the image from the file. Replace ‘my_image.jpg’ with the path to your image. - **cv2.cvtColor(image, cv2.COLOR_BGR2RGB):** Converts the image from BGR (OpenCV default) to RGB for proper display with matplotlib. - **plt.imshow(image_rgb):** Displays the image. - **plt.axis(‘off’):** Hides the axis for a cleaner view. Output: ![](https://www.atlantic.net/wp-content/uploads/2025/02/p1-3.png) ## Step 5: Convert the Image to Grayscale Convert the image to grayscale, as many image processing tasks work better on grayscale images: ```bash # Convert the image to grayscale gray_image = cv2.cvtColor(image, cv2.COLOR_BGR2GRAY) # Display the grayscale image plt.imshow(gray_image, cmap='gray') plt.title('Grayscale Image') plt.axis('off') plt.show() ``` **Explanation:** - **cv2.cvtColor(image, cv2.COLOR_BGR2GRAY):** Converts the image to grayscale. - **cmap=’gray’:** Ensures the grayscale image is displayed correctly. Output: ![](https://www.atlantic.net/wp-content/uploads/2025/02/p2-2.png) ## Step 6: Apply Gaussian Blur Blurring the image helps reduce noise and improve segmentation results: ```bash # Apply Gaussian blur blurred_image = cv2.GaussianBlur(gray_image, (5, 5), 0) # Display the blurred image plt.imshow(blurred_image, cmap='gray') plt.title('Blurred Image') plt.axis('off') plt.show() ``` **Explanation:** - **cv2.GaussianBlur(gray_image, (5, 5), 0)**: Applies Gaussian blur with a 5×5 kernel. You can adjust the kernel size for more or less blur. Output: ![](https://www.atlantic.net/wp-content/uploads/2025/02/p3-2.png) ## Step 7: Apply Thresholding Thresholding is a simple way to segment an image into foreground and background: ```bash # Apply binary thresholding _, binary_image = cv2.threshold(blurred_image, 127, 255, cv2.THRESH_BINARY) # Display the binary image plt.imshow(binary_image, cmap='gray') plt.title('Binary Image') plt.axis('off') plt.show() ``` **Explanation:** - **cv2.threshold(blurred_image,** **127, 255, cv2.THRESH_BINARY):** Applies binary thresholding. Pixels with intensity > 127 are set to 255 (white), and others are set to 0 (black). Output: ![](https://www.atlantic.net/wp-content/uploads/2025/02/p4-1.png) ## Step 8: Detect Edges Using Canny Edge Detection Edge detection is another common technique for image segmentation: ```bash # Detect edges using Canny edge detection edges = cv2.Canny(blurred_image, 100, 200) # Display the edges plt.imshow(edges, cmap='gray') plt.title('Edges') plt.axis('off') plt.show() ``` **Explanation:** - **cv2.Canny(blurred_image, 100, 200)**: Detects edges using the Canny algorithm. The thresholds 100 and 200 control the sensitivity of edge detection. Output: ![](https://www.atlantic.net/wp-content/uploads/2025/02/p5-1.png) ## Step 9: Find Contours Contours are useful for identifying objects in an image: ```bash # Find contours contours, _ = cv2.findContours(binary_image, cv2.RETR_TREE, cv2.CHAIN_APPROX_SIMPLE) # Draw contours on the original image contour_image = cv2.drawContours(image.copy(), contours, -1, (0, 255, 0), 2) # Convert the image to RGB for display contour_image_rgb = cv2.cvtColor(contour_image, cv2.COLOR_BGR2RGB) # Display the image with contours plt.imshow(contour_image_rgb) plt.title('Contours') plt.axis('off') plt.show() ``` **Explanation:** - **cv2.findContours(binary_image, cv2.RETR_TREE, cv2.CHAIN_APPROX_SIMPLE):** Finds contours in the binary image. - **cv2.drawContours(image.copy(), contours, -1, (0, 255, 0), 2)**: Draws contours on a copy of the original image. The color (0, 255, 0) is green, and 2 is the thickness of the contour lines. Output: ![](https://www.atlantic.net/wp-content/uploads/2025/02/p6-1.png) ## Step 10: Save the Final Output Finally, save the image with contours to a file: ```bash # Save the image with contours cv2.imwrite('output_image.jpg', cv2.cvtColor(contour_image_rgb, cv2.COLOR_RGB2BGR)) print("Output image saved as 'output_image.jpg'") ``` **Explanation:** - **cv2.imwrite(‘output_image.jpg’, contour_image_rgb)**: Saves the image with contours to a file. ## Conclusion By following these steps in a Jupyter Notebook you can build a simple image segmentation pipeline using OpenCV. The notebook environment allows you to visualize each step of the process, so you can understand and debug it better. You can further extend this pipeline with more advanced techniques like semantic segmentation or deep learning based approaches. --- # How to Detect Anomalies in Time Series Data on an Ubuntu GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-detect-anomalies-in-time-series-data-on-an-ubuntu-gpu-server/ | Published: 2025-03-19 | Updated: 2025-03-24 | Author: Hitesh Jethva Detecting anomalies in time series data is a big deal in many industries like finance, healthcare, cybersecurity and industrial IoT. Anomalies can mean faults, fraud, or unexpected behavior that requires immediate attention. Efficient anomaly detection can prevent financial loss, ensure safety in industrial systems and maintain cybersecurity integrity. With the advancement of deep learning, techniques like Long-Short-Term Memory (LSTM) Autoencoders are very effective in detecting anomalies in time series data. In this article, we will describe how to detect anomalies in time series data using an LSTM-based autoencoder on an Ubuntu GPU server. ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 24.04 [Cloud GPU Server](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/). - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Step 1: Setup a Python Environment In this section, we’ll set up a dedicated Python environment on an Ubuntu GPU server to run our anomaly detection models. 1. Add the Python 3.10 repository. ```bash add-apt-repository ppa:deadsnakes/ppa ``` 2. Update the package list. ```bash apt update -y ``` 3. Install packages necessary for creating a virtual environment and compiling Python modules. ```bash apt install python3.10 python3.10-venv python3.10-dev ``` 4. Set up a virtual environment to manage your project’s dependencies separately from the system’s Python environment. ```bash python3.10 -m venv venv source venv/bin/activate ``` 5. Upgrade pip and install wheel. ```bash pip install --upgrade pip pip install wheel ``` 6. Install the Python packages needed for data analysis, machine learning, and visualization. ```bash pip3 install "numpy<2" pandas matplotlib seaborn tensorflow jupyter scikit-learn ``` ## Step 2: Prepare the Time Series Data Time series data is a sequence of observations recorded at regular time intervals. For this guide, we will generate synthetic time series data with injected anomalies. Create a file named prepare_data.py. ```bash nano prepare_data.py ``` Add the following code. ```bash import numpy as np import pandas as pd import matplotlib.pyplot as plt # Generate synthetic time series data def generate_data(n=1000): np.random.seed(42) time = np.arange(n) values = np.sin(0.02 * time) + np.random.normal(scale=0.1, size=n) anomalies = np.random.choice(n, size=10, replace=False) values[anomalies] += np.random.normal(scale=2, size=10) # Injecting anomalies return pd.DataFrame({'timestamp': time, 'value': values}) data = generate_data() data.to_csv("time_series_data.csv", index=False) ``` Run the script to generate and save the data. ```bash python3 prepare_data.py ``` This script creates a time series dataset with normal patterns and anomalies and saves it as time_series_data.csv. ## Step 3: Build an LSTM Autoencoder for Anomaly Detection An autoencoder is a neural network trained to reconstruct normal data patterns. When it encounters an anomaly, the reconstruction error is significantly higher. Create a file to detect anomalies. ```bash nano anomaly_detection.py ``` Add the following code. ```bash import numpy as np import pandas as pd import tensorflow as tf from tensorflow.keras.models import Sequential from tensorflow.keras.layers import LSTM, Dense, Dropout, RepeatVector, TimeDistributed from sklearn.preprocessing import MinMaxScaler import matplotlib.pyplot as plt # Load time series data data = pd.read_csv("time_series_data.csv") values = data['value'].values.reshape(-1, 1) # Normalize data scaler = MinMaxScaler() values_scaled = scaler.fit_transform(values) # Create sequences for LSTM def create_sequences(data, seq_length): sequences = [] for i in range(len(data) - seq_length): sequences.append(data[i: i + seq_length]) return np.array(sequences) seq_length = 50 X_train = create_sequences(values_scaled, seq_length) # Define LSTM autoencoder model = Sequential([ LSTM(64, activation='relu', input_shape=(seq_length, 1), return_sequences=True), Dropout(0.2), LSTM(32, activation='relu', return_sequences=False), RepeatVector(seq_length), LSTM(32, activation='relu', return_sequences=True), Dropout(0.2), LSTM(64, activation='relu', return_sequences=True), TimeDistributed(Dense(1)) ]) model.compile(optimizer='adam', loss='mse') # Train the model model.fit(X_train, X_train, epochs=20, batch_size=16, validation_split=0.1) # Save the trained model model.save("anomaly_detector.h5") ``` Run the script to train the model. ```bash python3 anomaly_detection.py ``` This script trains the LSTM autoencoder on normal patterns and saves the model as anomaly_detector.h5. ```bash Epoch 1/20 54/54 [==============================] - 5s 41ms/step - loss: 0.1079 - val_loss: 0.0153 Epoch 2/20 54/54 [==============================] - 2s 34ms/step - loss: 0.0308 - val_loss: 0.0116 Epoch 3/20 54/54 [==============================] - 2s 34ms/step - loss: 0.0196 - val_loss: 0.0103 Epoch 4/20 54/54 [==============================] - 2s 34ms/step - loss: 0.0143 - val_loss: 0.0088 Epoch 5/20 54/54 [==============================] - 2s 34ms/step - loss: 0.0113 - val_loss: 0.0105 Epoch 6/20 54/54 [==============================] - 2s 34ms/step - loss: 0.0096 - val_loss: 0.0075 ``` ## Step 4: Detect Anomalies After training the model, we will use it to detect anomalies in the time series data. Create a file named detect_anomalies.py. ```bash nano detect_anomalies.py ``` Add the following code. ```bash from tensorflow.keras.models import load_model import numpy as np import pandas as pd import matplotlib.pyplot as plt from sklearn.preprocessing import MinMaxScaler # Load the trained model with custom loss function from tensorflow.keras.losses import MeanSquaredError model = load_model("anomaly_detector.h5", custom_objects={"mse": MeanSquaredError()}) # Load and preprocess data data = pd.read_csv("time_series_data.csv") values = data['value'].values.reshape(-1, 1) # Normalize data scaler = MinMaxScaler() values_scaled = scaler.fit_transform(values) # Create sequences for prediction def create_sequences(data, seq_length): sequences = [] for i in range(len(data) - seq_length): sequences.append(data[i: i + seq_length]) return np.array(sequences) seq_length = 50 X_test = create_sequences(values_scaled, seq_length) # Predict reconstruction error X_pred = model.predict(X_test) mse = np.mean(np.abs(X_pred - X_test), axis=(1, 2)) threshold = np.percentile(mse, 95) # 95th percentile as anomaly threshold # Mark anomalies data = data.iloc[seq_length:] data['mse'] = mse data['anomaly'] = data['mse'] > threshold # Plot anomalies plt.figure(figsize=(12, 6)) plt.plot(data['timestamp'], data['value'], label='Value', color='blue') plt.scatter(data['timestamp'][data['anomaly']], data['value'][data['anomaly']], color='red', label='Anomaly') plt.legend() plt.title("Anomaly Detection in Time Series Data") plt.xlabel("Timestamp") plt.ylabel("Value") plt.show() # Save detected anomalies to CSV data.to_csv("anomalies_detected.csv", index=False) print("Anomaly detection completed. Results saved in anomalies_detected.csv.") ``` Run the above script. ```bash python3 detect_anomalies.py ``` This script detects anomalies and visualizes them while saving results to anomalies_detected.csv. ```bash Anomaly detection completed. Results saved in anomalies_detected.csv. ``` You can run the command below to display the anomalies detected in the terminal. You can also open the CSV file in a spreadsheet application. ```bash cat anomalies_detected.csv ``` Output. ```bash timestamp,value,mse,anomaly 50,0.873879381747376,0.05099832916747173,False 51,0.8135997939077313,0.05162067832585881,False 52,0.7947120272127426,0.051868111103225124,False 53,0.933523111229073,0.051020112694549,False 54,0.9850577591345426,0.0504320734778334,False 55,0.9843353719730552,0.05125568314028007,False 56,0.8161786898542412,0.05199617866260993,False 57,0.8777122585307618,0.05020586907291115,False 58,0.9499294519121232,0.04897388883144851,False 59,1.022160525120256,0.048887483703040434,False 60,0.8841216621826973,0.048953077273603506,False 61,0.920533458652686,0.04866946629698113,False 62,0.8351505020489361,0.04704867943636561,False 63,0.8324696791824486,0.04447853718451549,False 64,1.0392684425286447,0.045233664400090544,False ``` ## Conclusion In this article we showed how to detect anomalies in time series data using an LSTM based autoencoder on an Ubuntu GPU server. Now you can apply similar technique to your own time series data to find unusual patterns and issues. --- # How to Generate Music Using Transformers on an Ubuntu GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-generate-music-using-transformers-on-an-ubuntu-gpu-server/ | Published: 2025-03-20 | Updated: 2025-03-24 | Author: Hitesh Jethva Generating music using transformers has become very popular due to the advancements in deep learning and natural language processing (NLP). Transformers, originally designed for NLP tasks, have been adapted for music generation by treating musical sequences as a form of language. In this article, we will generate music using transformers on an Ubuntu GPU server. We’ll cover setting up the environment, writing the code, and running the code to generate music. ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 24.04 [Cloud GPU Server](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/). - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Step 1: Set Up the Environment 1. First, make sure your system is up to date. ```bash apt update -y ``` 2. Add the Python repository. ```bash add-apt-repository ppa:deadsnakes/ppa ``` 3. Update the package index. ```bash apt update -y ``` 4. Install Python 3.10 and essential libraries. ```bash apt install python3.10 python3.10-venv python3.10-dev -y ``` 5. Create a virtual environment to isolate the dependencies: ```bash python3.10 -m venv musicgen_env source musicgen_env/bin/activate ``` 6. Install the required Python libraries: ```bash pip install torch torchvision torchaudio --extra-index-url https://download.pytorch.org/whl/cu118 pip install transformers pip install numpy scipy matplotlib pip install midiutil ``` **Explanation:** - **torch:** PyTorch is a deep-learning framework that we’ll use to build and train our transformer model. - **transformers:** The Hugging Face Transformers library provides pre-trained models and tools for working with transformers. - **numpy, scipy, matplotlib:** These libraries are used for numerical computations and visualization. - **midiutil:** This library is used to create MIDI files from the generated music. ## Step 2: Writing the Code **1. Create a Python Script** Create a new Python script file named music_generator.py: ```bash nano music_generator.py ``` **2. Import Required Libraries** Add the below code: ```bash # Import required libraries import torch from transformers import GPT2LMHeadModel, GPT2Tokenizer from midiutil import MIDIFile ``` **3. Load Pre-trained Model and Tokenizer** We’ll use a pre-trained GPT-2 model from Hugging Face’s Transformers library. GPT-2 is a transformer-based model that can generate text, and we’ll adapt it for music generation. ```bash # Load pre-trained GPT-2 model and tokenizer def load_model(): model_name = "gpt2" tokenizer = GPT2Tokenizer.from_pretrained(model_name) model = GPT2LMHeadModel.from_pretrained(model_name) # Set pad token ID explicitly tokenizer.pad_token = tokenizer.eos_token # Move model to GPU if available device = torch.device("cuda" if torch.cuda.is_available() else "cpu") model.to(device) return model, tokenizer, device ``` **4. Define Music Generation Function** Next, we’ll define a function to generate music using the GPT-2 model. We’ll treat the music as a sequence of tokens and generate new tokens based on the input sequence. ```bash # Generate music using the GPT-2 model def generate_music(prompt, model, tokenizer, device, max_length=100, temperature=0.7): # Encode the input prompt input_ids = tokenizer.encode(prompt, return_tensors="pt").to(device) # Generate music tokens output = model.generate( input_ids, max_length=max_length, temperature=temperature, do_sample=True, top_k=50, top_p=0.95, pad_token_id=tokenizer.eos_token_id, # Explicitly set pad token ID attention_mask=input_ids.ne(tokenizer.pad_token_id).float().to(device) # Set attention mask ) # Decode the generated tokens to a string generated_music = tokenizer.decode(output[0], skip_special_tokens=True) return generated_music ``` **Explanation:** - **prompt:** The initial sequence of tokens that will be used to start the generation. - **max_length:** The maximum length of the generated sequence. - **temperature:** Controls the randomness of the generated sequence. Lower values make the output more deterministic, while higher values make it more random. - **do_sample:** If True, the model will sample from the probability distribution instead of taking the most likely token. - **top_k:** Limits the sampling pool to the top k tokens. - **top_p:** Implements nucleus sampling, where the model samples from the smallest possible set of tokens whose cumulative probability exceeds p. **6. Convert Generated Music to MIDI** The generated music is a sequence of tokens. We’ll convert these tokens into a MIDI file that can be played or further processed. ```bash # Convert generated music tokens to a MIDI file def tokens_to_midi(generated_music, filename="generated_music.mid"): # Convert the generated music tokens to a list of integers try: tokens = [int(token) for token in generated_music.split() if token.isdigit()] except ValueError: print("Error: Generated music contains non-integer tokens. Please check the model output.") return # Create a MIDI file midi = MIDIFile(1) track = 0 time = 0 midi.addTrackName(track, time, "Generated Music") midi.addTempo(track, time, 120) # Add notes to the MIDI file for i, token in enumerate(tokens): pitch = token % 128 # MIDI pitches range from 0 to 127 duration = 1 # Each note lasts for 1 beat midi.addNote(track, 0, pitch, time + i, duration, 100) # Save the MIDI file with open(filename, "wb") as output_file: midi.writeFile(output_file) ``` **7. Generate and Save Music** Finally, we’ll generate music and save it as a MIDI file. ```bash # Main function to generate and save music def main(): # Load the model and tokenizer model, tokenizer, device = load_model() # Define a prompt to start the music generation prompt = "60 62 64 65 67 69 71 72" # Example: C major scale # Generate music generated_music = generate_music(prompt, model, tokenizer, device, max_length=200, temperature=0.7) # Save the generated music as a MIDI file tokens_to_midi(generated_music, "generated_music.mid") print("Music generated and saved as 'generated_music.mid'") # Run the script if __name__ == "__main__": main() ``` ## Step 3: Running the Code Now, run the above script using the below command. ```bash python3 music_generator.py ``` When you run the script, it will generate a MIDI file named **generated_music.mid** in the same directory as the script. The output in the terminal will look something like this: ```bash Music generated and saved as 'generated_music.mid' ``` The MIDI file contains the generated music in a format that can be easily manipulated or played back. Each note in the MIDI file corresponds to a token in the generated sequence. ## Conclusion In this article we’ve gone through the process of generating music using transformers on an Ubuntu GPU server. We’ve covered setting up the environment, writing the code and running the code to generate music. The generated music is saved as a MIDI file which can be played or further processed. Try it out! By leveraging the power of transformers and GPUs, you can create unique and interesting musical compositions that push the boundaries of what’s possible with AI-generated music. --- # How to Build a Simple Reinforcement Learning Model with Gym on Ubuntu GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-build-a-simple-reinforcement-learning-model-with-gym-on-ubuntu-gpu-server/ | Published: 2025-03-21 | Updated: 2026-05-04 | Author: Hitesh Jethva Reinforcement Learning (RL) is a subfield of machine learning where an agent learns to make decisions by performing actions in an environment to maximize some notion of cumulative reward. OpenAI’s Gym is a popular toolkit for developing and comparing reinforcement learning algorithms. In this article, we will go through building a simple RL model using Gym on an Ubuntu GPU server. ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 24.04 [Cloud GPU Server](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/). - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Step 1: Set Up the Environment 1. First, ensure your system is up to date: ```bash apt update -y ``` 2. The default Python version in Ubuntu 24.04 (Python 3.12) is incompatible with Gym requirements. You’ll need to install Python 3.10. Add the Python repository. ```bash add-apt-repository ppa:deadsnakes/ppa ``` 3. Update the package index. ```bash apt update -y ``` 4. Install Python 3.10 and essential libraries. ```bash apt install python3.10 python3.10-venv python3.10-dev -y ``` 5. Create a Python virtual environment. ```bash python3.10 -m venv rl_env source rl_env/bin/activate ``` ## Step 2: Install Required Libraries 1. Upgrade pip to the latest version. ```bash pip install --upgrade pip ``` 2. Install required libraries. ```bash pip install wheel "numpy<2" matplotlib scipy ``` 3. Install TensorFlow with GPU support. ```bash pip install tensorflow-gpu ``` 4. Install OpenAI Gym. ```bash pip install gym ``` ## Step 3: Build a Simple Reinforcement Learning Model OpenAI Gym provides various environments. For this tutorial, we’ll use the CartPole-v1 environment, where the goal is to balance a pole on a cart. 1. Create a file named **environment_setup.py.** ```bash nano environment_setup.py ``` Add the following code. ```bash import gym env = gym.make('CartPole-v1') print("Environment created successfully!") print("Observation space:", env.observation_space) print("Action space:", env.action_space) ``` 2. Run the above script. ```bash python3 environment_setup.py ``` Output. ```bash Environment created successfully! Observation space: Box([-4.8000002e+00 -3.4028235e+38 -4.1887903e-01 -3.4028235e+38], [4.8000002e+00 3.4028235e+38 4.1887903e-01 3.4028235e+38], (4,), float32) Action space: Discrete(2) ``` ## Step 4: Define the Model We’ll use a simple neural network to approximate the Q-function. The network will take the state as input and output the Q-values for each action. 1. Create a file to define the model. ```bash nano build_model.py ``` 2. Add the following code. ```bash import tensorflow as tf from tensorflow.keras import layers def build_model(state_size, action_size): model = tf.keras.Sequential([ layers.Dense(24, input_dim=state_size, activation='relu'), layers.Dense(24, activation='relu'), layers.Dense(action_size, activation='linear') ]) model.compile(loss='mse', optimizer=tf.keras.optimizers.Adam(learning_rate=0.001)) return model # Test the model state_size = 4 action_size = 2 model = build_model(state_size, action_size) model.summary() ``` 3. Run the script. ```bash python3 build_model.py ``` Output. ```bash Model: "sequential" _________________________________________________________________ Layer (type) Output Shape Param # ================================================================= dense (Dense) (None, 24) 120 dense_1 (Dense) (None, 24) 600 dense_2 (Dense) (None, 2) 50 ================================================================= Total params: 770 Trainable params: 770 Non-trainable params: 0 _________________________________________________________________ ``` ## Step 5: Implement the Q-Learning Algorithm Q-Learning is a popular RL algorithm. Here, we’ll implement a simple version of Q-Learning with experience replay. 1. Create a **q_learning** agent. ```bash nano q_learning_agent.py ``` Add the following code. ```bash import numpy as np from build_model import build_model class QLearningAgent: def __init__(self, state_size, action_size): self.state_size = state_size self.action_size = action_size self.memory = [] self.gamma = 0.95 # discount rate self.epsilon = 1.0 # exploration rate self.epsilon_min = 0.01 self.epsilon_decay = 0.995 self.model = build_model(state_size, action_size) def remember(self, state, action, reward, next_state, done): self.memory.append((state, action, reward, next_state, done)) def act(self, state): if np.random.rand() <= self.epsilon: return np.random.choice(self.action_size) q_values = self.model.predict(state) return np.argmax(q_values[0]) def replay(self, batch_size): minibatch = np.random.choice(len(self.memory), batch_size, replace=False) for index in minibatch: state, action, reward, next_state, done = self.memory[index] target = reward if not done: target = reward + self.gamma * np.amax(self.model.predict(next_state)[0]) target_f = self.model.predict(state) target_f[0][action] = target self.model.fit(state, target_f, epochs=1, verbose=0) if self.epsilon > self.epsilon_min: self.epsilon *= self.epsilon_decay # Test the agent state_size = 4 action_size = 2 agent = QLearningAgent(state_size, action_size) print("Q-Learning agent created successfully!") ``` 2. Run the above script. ```bash python3 q_learning_agent.py ``` Output. ```bash Model: "sequential" _________________________________________________________________ Layer (type) Output Shape Param # ================================================================= dense (Dense) (None, 24) 120 dense_1 (Dense) (None, 24) 600 dense_2 (Dense) (None, 2) 50 ================================================================= Total params: 770 Trainable params: 770 Non-trainable params: 0 _________________________________________________________________ Q-Learning agent created successfully! ``` ## Step 6: Train the Model 1. Now, let’s train the model using the Q-Learning algorithm. ```bash nano train_model.py ``` Add the following code. ```bash import gym import numpy as np from q_learning_agent import QLearningAgent env = gym.make('CartPole-v1') state_size = env.observation_space.shape[0] action_size = env.action_space.n agent = QLearningAgent(state_size, action_size) batch_size = 32 episodes = 1000 for e in range(episodes): state, _ = env.reset() # Unpack the tuple returned by env.reset() state = np.expand_dims(state, axis=0) # Reshape state to (1, state_size) for time in range(500): action = agent.act(state) next_state, reward, done, _, _ = env.step(action) # Unpack the tuple returned by env.step() next_state = np.expand_dims(next_state, axis=0) # Reshape next_state to (1, state_size) agent.remember(state, action, reward, next_state, done) state = next_state if done: print(f"episode: {e}/{episodes}, score: {time}, e: {agent.epsilon:.2}") break if len(agent.memory) > batch_size: agent.replay(batch_size) ``` 2. Run the code. ```bash python3 train_model.py ``` Output. ```bash episode: 0/1000, score: 12, e: 0.99 episode: 1/1000, score: 15, e: 0.98 ... episode: 999/1000, score: 200, e: 0.01 ``` **Explanation:** - The agent is trained for 1000 episodes. - The score (time steps before the pole falls) increases over time, indicating that the agent is learning. - The exploration rate (epsilon) decreases over time as the agent relies more on learned knowledge. ## Step 7: Test the Model 1. After training, you can test the model to see how well it performs. ```bash nano test_model.py ``` Add the following code. ```bash import gym import numpy as np from q_learning_agent import QLearningAgent env = gym.make('CartPole-v1') state_size = env.observation_space.shape[0] action_size = env.action_space.n agent = QLearningAgent(state_size, action_size) # Load the trained model (if saved) # agent.model.load_weights('model_weights.h5') state, _ = env.reset() # Unpack the tuple returned by env.reset() state = np.expand_dims(state, axis=0) # Reshape state to (1, state_size) for time in range(500): env.render() action = np.argmax(agent.model.predict(state)[0]) next_state, reward, done, _, _ = env.step(action) # Unpack the tuple returned by env.step() next_state = np.expand_dims(next_state, axis=0) # Reshape next_state to (1, state_size) state = next_state if done: print(f"Test finished with score: {time}") break env.close() ``` 2. Run the above test. ```bash python3 test_model.py ``` Output. ```bash Test finished with score: 8 ``` **Explanation:** - The agent successfully balances the pole for the maximum allowed time (500 steps). - This indicates that the training was successful. ## Conclusion In this article, we built a simple RL model using OpenAI Gym on an Ubuntu GPU server. You can now develop your own RL projects and try out more complex environments. OpenAI Gym has many environments to test and refine different RL strategies. --- # Toxic Comment Detection with TensorFlow on an Ubuntu GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/toxic-comment-detection-with-tensorflow-on-an-ubuntu-gpu-server/ | Published: 2025-03-24 | Updated: 2025-04-15 | Author: Hitesh Jethva Online platforms face increasing challenges in moderating user-generated content. Toxic comments—including insults, threats, hate speech, and obscene language—can create hostile environments and drive users away. Manual moderation doesn’t scale effectively for large platforms, making automated detection systems essential. In this article, we’ll build a toxic comment classification system using TensorFlow on an Ubuntu server with GPU acceleration. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user with sudo privileges. - NVIDIA drivers installed. ## Step 1: Setting Up the Environment Before we begin processing data or training models, we need to set up our Ubuntu server environment with the necessary dependencies. 1. Install Python and other required libraries. ```bash apt install -y python3 python3-pip python3-venv ``` 2. Create a virtual environment for your project. ```bash python3 -m venv toxic-env ``` 3. Activate the virtual environment. ```bash source toxic-env/bin/activate ``` 4. Upgrade Pip to the latest version. ```bash pip install --upgrade pip ``` 5. Install Tensorflow and other packages. ```bash pip install tensorflow pandas numpy scikit-learn matplotlib nltk kaggle uvicorn fastapi ``` ## Step 2: Data Preparation We’ll use the Jigsaw Toxic Comment Classification Challenge dataset from Kaggle, which contains Wikipedia comments labeled for various types of toxicity. 1. Create a directory structure for your project. ```bash mkdir -p toxicity-detector/{data,models,src} ``` 2. Navigate to the toxicity-detector directory. ```bash cd toxicity-detector ``` 3. Log in to the Kagel site, download the [Jigsaw dataset file](https://www.kaggle.com/datasets/julian3833/jigsaw-toxic-comment-classification-challenge) called archive.zip, and place it in the /root directory. 4. Unzip the **archive.zip** to the data/raw directory. ```bash unzip /root/archive.zip -d data/raw/ ``` ## Step 3: Preprocess Data Effective text classification requires careful preprocessing. 1. Create a preprocess.py script. ```bash nano src/preprocess.py ``` Add the following code. ```bash import pandas as pd import nltk from nltk.tokenize import word_tokenize from nltk.stem import WordNetLemmatizer import multiprocessing as mp import os nltk_dir = os.path.expanduser('~/nltk_data') os.makedirs(nltk_dir, exist_ok=True) nltk.data.path.append(nltk_dir) for resource in ['punkt', 'stopwords', 'wordnet', 'omw-1.4']: nltk.download(resource, download_dir=nltk_dir) def clean_text(text): tokens = word_tokenize(str(text).lower()) lemmatizer = WordNetLemmatizer() return ' '.join([lemmatizer.lemmatize(w) for w in tokens if w.isalpha()]) if __name__ == "__main__": df = pd.read_csv('data/raw/train.csv') with mp.Pool(mp.cpu_count()) as pool: df['clean_text'] = pool.map(clean_text, df['comment_text']) os.makedirs('data/processed', exist_ok=True) df.to_csv('data/processed/train_clean.csv', index=False) print("Preprocessing completed successfully!") ``` 2. Run the preprocessing script. ```bash python3 src/preprocess.py ``` ## Step 4: Model Training Our model architecture uses a bidirectional LSTM network, which is particularly effective for sequence classification tasks like text analysis. 1. Create a train.py script. ```bash nano src/train.py ``` Add the following code. ```bash import os os.environ['TF_CPP_MIN_LOG_LEVEL'] = '2' import numpy as np import pandas as pd import tensorflow as tf from tensorflow.keras.layers import TextVectorization, Embedding, Bidirectional, LSTM, Dense, Input from tensorflow.keras.models import Sequential from sklearn.model_selection import train_test_split import pickle train_df = pd.read_csv('data/processed/train_clean.csv') texts = train_df['clean_text'].astype(str).tolist() labels = train_df[['toxic', 'severe_toxic', 'obscene', 'threat', 'insult', 'identity_hate']].values X_train, X_val, y_train, y_val = train_test_split(texts, labels, test_size=0.2, random_state=42) # Create vectorizer separately vectorizer = TextVectorization(max_tokens=50000, output_sequence_length=200, output_mode='int') vectorizer.adapt(X_train) # Vectorize data before training X_train_vec = vectorizer(np.array([[s] for s in X_train])).numpy() X_val_vec = vectorizer(np.array([[s] for s in X_val])).numpy() # Save vectorizer separately with open('models/vectorizer.pkl', 'wb') as f: pickle.dump({'config': vectorizer.get_config(), 'weights': vectorizer.get_weights()}, f) # Build model without vectorizer model = Sequential([ Input(shape=(200,)), Embedding(50000, 128, mask_zero=True), Bidirectional(LSTM(64, return_sequences=True)), Bidirectional(LSTM(32)), Dense(64, activation='relu'), Dense(6, activation='sigmoid') ]) model.compile(loss='binary_crossentropy', optimizer='adam', metrics=['accuracy']) # Train model on vectorized data model.fit(X_train_vec, y_train, validation_data=(X_val_vec, y_val), epochs=10) # Save model model.save('models/toxicity.h5') ``` 2. Run the script to train the model. ```bash python3 src/train.py ``` ## Step 5: Deployment with FastAPI For production deployment, we create a REST API using FastAPI that exposes our model’s prediction capabilities. 1. Create an **api.py** script. ```bash nano src/api.py ``` Add the following code: ```bash from fastapi import FastAPI from tensorflow.keras.models import load_model from tensorflow.keras.layers import TextVectorization from pydantic import BaseModel import numpy as np import pickle import tensorflow as tf app = FastAPI() # Load the trained model model = load_model('models/toxicity.h5') # Load vectorizer separately and properly initialize it with open('models/vectorizer.pkl', 'rb') as f: vec_data = pickle.load(f) vectorizer = TextVectorization.from_config(vec_data['config']) # Temporary adapt call with dummy data to fully initialize internal tables vectorizer.adapt(tf.data.Dataset.from_tensor_slices(["dummy"])) vectorizer.set_weights(vec_data['weights']) class TextRequest(BaseModel): text: str @app.post("/predict") async def predict(request: TextRequest): try: # Vectorize the input text input_vector = vectorizer([request.text]) # Make the prediction prediction = model.predict(input_vector)[0] return { "toxic": float(prediction[0]), "severe_toxic": float(prediction[1]), "obscene": float(prediction[2]), "threat": float(prediction[3]), "insult": float(prediction[4]), "identity_hate": float(prediction[5]) } except Exception as e: return {"error": str(e)} ``` 2. Start the server. ```bash uvicorn src.api:app --reload & ``` 3. Test the API with a sample request. ```bash curl -X POST 'http://localhost:8000/predict' \ -H 'Content-Type: application/json' \ -d '{"text":"You are an idiot!"}' ``` Output. ```bash {"toxic":0.5728890299797058,"severe_toxic":0.04583415016531944,"obscene":0.4520402252674103,"threat":0.007368859834969044,"insult":0.19956137239933014,"identity_hate":0.023788010701537132} ``` The output of the API request represents the model’s prediction scores for six different types of toxicity in the input text. Each score is a probability value between 0 and 1, where higher values indicate greater confidence that the text contains that particular type of toxicity. ## Conclusion This implementation demonstrates building an effective toxic comment classification system using TensorFlow on an Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/). By leveraging GPU acceleration, we can train sophisticated models efficiently while the modular architecture ensures maintainability and scalability. The system can be integrated into content moderation pipelines, forum platforms, or social media applications to automatically flag potentially harmful content for human review or automatic filtering. --- # How to Build a Recommender System with Surprise on Ubuntu GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-build-a-recommender-system-with-surprise-on-ubuntu-gpu-server/ | Published: 2025-03-24 | Author: Hitesh Jethva Recommender systems are the invisible engines behind personalized internet experiences. Whether you’re searching for your next TV show on Netflix, products on Amazon, or music on Spotify, recommender systems are working behind the scenes. They analyze your preferences, compare them with millions of other users, and deliver tailored recommendations that keep you engaged and happy. In this article, we’ll build a recommender system using the Surprise library on an Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/). We’ll use the MovieLens 100K dataset, a popular dataset for collaborative filtering, and train a model using SVD. ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 24.04 Cloud GPU Server. - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Step 1: Install Required Dependencies First, we need to set up the environment and install the necessary dependencies. 1. Update your system packages. ```bash apt update -y ``` 2. Install Python and the venv module to create an isolated environment: ```bash apt install python3-pip python3-venv -y ``` 3. Create and activate a virtual environment to manage dependencies: ```bash python3 -m venv surprise_env source surprise_env/bin/activate ``` 4. Install the necessary Python libraries: ```bash pip install "numpy<2" scikit-surprise pandas matplotlib ``` **Explanation:** - **NumPy:** For numerical computations. - **scikit-surprise:** A Python library for building and analyzing recommender systems. - **Pandas:** For data manipulation. - **Matplotlib:** For visualization (optional). ## Step 2: Download the MovieLens 100K Dataset The MovieLens 100K dataset is a widely used dataset for building recommender systems. It contains 100,000 ratings from 943 users on 1,682 movies. 1. Create a directory for the dataset and download it: ```bash mkdir -p ~/datasets && cd ~/datasets wget https://files.grouplens.org/datasets/movielens/ml-100k.zip unzip ml-100k.zip ``` This will create a directory named **ml-100k** containing the dataset files. 2. The file we need is **ml-100k/u.data.** Let’s inspect the first few lines: ```bash head ml-100k/u.data ``` Output: ```bash 196 242 3 881250949 186 302 3 891717742 22 377 1 878887116 244 51 2 880606923 166 346 1 886397596 298 474 4 884182806 115 265 2 881171488 253 465 5 891628467 305 451 3 886324817 6 86 3 883603013 ``` The columns represent: - **user_id:** ID of the user. - **item_id:** ID of the movie. - **rating:** Rating given by the user (1-5). - **timestamp:** Timestamp of the rating. ## Step 3: Load the Dataset We’ll use the surprise library to load the dataset into a format suitable for training. 1. Create a file named **load_data.py:** ```bash nano load_data.py ``` Add the following code: ```bash import pandas as pd from surprise import Dataset, Reader # Load MovieLens 100K dataset file_path = "ml-100k/u.data" columns = ['user_id', 'item_id', 'rating', 'timestamp'] df = pd.read_csv(file_path, sep='\t', names=columns) # Define a reader object reader = Reader(line_format='user item rating timestamp', sep='\t') # Load the dataset into Surprise format data = Dataset.load_from_df(df[['user_id', 'item_id', 'rating']], reader) print("Data loaded successfully.") ``` 2. Execute the script: ```bash python3 load_data.py ``` Output: ```bash Data loaded successfully. ``` ## Step 4: Build a Recommender System Using Surprise We’ll use the **SVD** (Singular Value Decomposition) algorithm, a popular collaborative filtering technique, to build our recommender system. 1. Create a Python file to train the model ```bash nano train_model.py ``` Add the following code: ```bash import pandas as pd from surprise import Dataset, Reader, SVD from surprise.model_selection import cross_validate # Load dataset file_path = "ml-100k/u.data" columns = ['user_id', 'item_id', 'rating', 'timestamp'] df = pd.read_csv(file_path, sep='\t', names=columns) reader = Reader(line_format='user item rating timestamp', sep='\t') data = Dataset.load_from_df(df[['user_id', 'item_id', 'rating']], reader) # Train SVD model model = SVD() cross_validate(model, data, cv=5, verbose=True) print("Model trained successfully.") ``` 2. Run the script. ```bash python3 train_model.py ``` This will perform 5-fold cross-validation and output RMSE (Root Mean Square Error) and MAE (Mean Absolute Error). ```bash Evaluating RMSE, MAE of algorithm SVD on 5 split(s). Fold 1 Fold 2 Fold 3 Fold 4 Fold 5 Mean Std RMSE (testset) 0.9271 0.9318 0.9398 0.9403 0.9423 0.9363 0.0058 MAE (testset) 0.7311 0.7359 0.7374 0.7412 0.7434 0.7378 0.0043 Fit time 0.79 0.83 0.85 0.88 0.96 0.86 0.06 Test time 0.09 0.09 0.09 0.10 0.08 0.09 0.01 Model trained successfully. ``` ## Step 5: Make Predictions Using the Model Now that the model is trained, let’s make predictions for a specific user. 1. Create a Python file to make predictions. ```bash nano predict.py ``` Add the following code: ```bash import pandas as pd from surprise import Dataset, Reader, SVD from surprise.model_selection import train_test_split # Load dataset file_path = "ml-100k/u.data" columns = ['user_id', 'item_id', 'rating', 'timestamp'] df = pd.read_csv(file_path, sep='\t', names=columns) reader = Reader(line_format='user item rating timestamp', sep='\t') data = Dataset.load_from_df(df[['user_id', 'item_id', 'rating']], reader) # Split data into train and test set trainset, testset = train_test_split(data, test_size=0.2) # Train SVD model model = SVD() model.fit(trainset) # Make predictions predictions = model.test(testset) # Print sample predictions for prediction in predictions[:10]: print(f"User {prediction.uid} - Item {prediction.iid}: Predicted Rating {prediction.est:.2f}") ``` 2. Run the script. ```bash python3 predict.py ``` Output: ```bash User 282 - Item 325: Predicted Rating 2.90 User 619 - Item 188: Predicted Rating 3.74 User 336 - Item 1118: Predicted Rating 3.04 User 763 - Item 505: Predicted Rating 4.18 User 735 - Item 286: Predicted Rating 3.45 User 276 - Item 214: Predicted Rating 3.53 User 305 - Item 557: Predicted Rating 2.91 User 682 - Item 71: Predicted Rating 3.20 User 718 - Item 471: Predicted Rating 4.00 User 145 - Item 460: Predicted Rating 3.16 ``` ## Step 6: Save and Load the Model To reuse the trained model, we’ll save it to a file and load it later. 1. Create a file named save_model.py: ```bash nano save_model.py ``` Add the following code: ```bash import pandas as pd import pickle from surprise import Dataset, Reader, SVD # Load dataset file_path = "/root/datasets/ml-100k/u.data" # Ensure this path is correct columns = ['user_id', 'item_id', 'rating', 'timestamp'] df = pd.read_csv(file_path, sep='\t', names=columns) # Now pd is defined reader = Reader(line_format='user item rating timestamp', sep='\t') data = Dataset.load_from_df(df[['user_id', 'item_id', 'rating']], reader) # Train model trainset = data.build_full_trainset() model = SVD() model.fit(trainset) # Save the trained model with open("recommender_model.pkl", "wb") as f: pickle.dump(model, f) print("Model saved successfully.") ``` 2. Run the script. ```bash python3 save_model.py ``` Output: ```bash Model saved successfully. ``` 3. Create a file named **load_model.py** to load and use the saved model. ```bash nano load_model.py ``` Add the following code: ```bash import pickle from surprise import Dataset, Reader # Load the saved model with open("recommender_model.pkl", "rb") as f: model = pickle.load(f) # Make a prediction for user 1 and item 50 user_id = "1" item_id = "50" predicted_rating = model.predict(user_id, item_id).est print(f"Predicted rating for User {user_id} and Item {item_id}: {predicted_rating:.2f}") ``` 4. Run the script. ```bash python3 load_model.py ``` Output: ```bash Predicted rating for User 1 and Item 50: 3.53 ``` ## Step 7: Evaluate the Model Performance Finally, let’s evaluate the model’s performance using RMSE (Root Mean Square Error). 1. Create a file for evaluation. ```bash nano evaluate_model.py ``` Add the following code: ```bash import pandas as pd from surprise import Dataset, Reader from surprise.model_selection import train_test_split from surprise import accuracy import pickle # Load dataset file_path = "/root/datasets/ml-100k/u.data" # Make sure this path is correct columns = ['user_id', 'item_id', 'rating', 'timestamp'] df = pd.read_csv(file_path, sep='\t', names=columns) # Now pd is defined reader = Reader(line_format='user item rating timestamp', sep='\t') data = Dataset.load_from_df(df[['user_id', 'item_id', 'rating']], reader) # Split data trainset, testset = train_test_split(data, test_size=0.2) # Load saved model with open("recommender_model.pkl", "rb") as f: model = pickle.load(f) # Predict predictions = model.test(testset) # Compute RMSE rmse = accuracy.rmse(predictions) print(f"RMSE: {rmse:.4f}") ``` 2. Run the script. ```bash python3 evaluate_model.py ``` Output: ```bash RMSE: 0.6721 RMSE: 0.6721 ``` ## Conclusion In this article, we built a recommender system using the Surprise library on an Atlantic.Net GPU server. Now, you have a working recommender system that can be extended to real-world applications like e-commerce product recommendations, movie suggestions, or content curation. --- # How To Build a Neural Network to Recognize Handwritten Digits with TensorFlow on Ubuntu GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-build-a-neural-network-to-recognize-handwritten-digits-with-tensorflow-on-ubuntu-gpu-server/ | Published: 2025-03-25 | Updated: 2026-05-04 | Author: Hitesh Jethva Handwritten digit recognition is one of the classic “Hello World” projects in deep learning. Thanks to TensorFlow and GPU acceleration, we can build a highly accurate model in minutes. In this guide, we’ll walk through setting up a Convolutional Neural Network (CNN) on an Ubuntu GPU server to recognize digits from the famous MNIST dataset and even test it on your own handwritten images. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user with sudo privileges. - NVIDIA drivers installed. ## Step 1: Set Up the Project Environment Before diving into coding, we must prepare our GPU-powered Ubuntu server with the right tools. 1. First, let’s install Python and set up an isolated environment to avoid dependency conflicts: ```bash apt install -y python3 python3-pip python3-venv ``` 2. Now, create and activate a virtual environment: ```bash python3 -m venv tf-gpu-env source tf-gpu-env/bin/activate ``` 3. TensorFlow can leverage NVIDIA CUDA for lightning-fast training. Install it along with NumPy and Matplotlib: ```bash pip install tensorflow numpy matplotlib ``` 4. Connect to the Python shell. ```bash python3 ``` Verify that TensorFlow recognizes your GPU: ```bash import tensorflow as tf print("Num GPUs Available:", len(tf.config.list_physical_devices('GPU'))) ``` Output. ```bash Num GPUs Available: 1 ``` 5. Press **CTRL+D** to exit from the Python shell. ## Step 2: Build and Train the Model Now, the fun part is building a Convolutional Neural Network (CNN) to recognize handwritten digits! 1. Create the training script. ```bash nano train_mnist.py ``` Add the following code: ```bash import tensorflow as tf from tensorflow.keras.datasets import mnist from tensorflow.keras.models import Sequential from tensorflow.keras.layers import Conv2D, MaxPooling2D, Flatten, Dense, Dropout import os # Load and preprocess data (x_train, y_train), (x_test, y_test) = mnist.load_data() x_train, x_test = x_train / 255.0, x_test / 255.0 # Normalize x_train = x_train[..., tf.newaxis] # Add channel dimension (28x28x1) x_test = x_test[..., tf.newaxis] # Build CNN model model = Sequential([ Conv2D(32, (3,3), activation='relu', input_shape=(28,28,1)), MaxPooling2D((2,2)), Conv2D(64, (3,3), activation='relu'), MaxPooling2D((2,2)), Flatten(), Dense(128, activation='relu'), Dropout(0.5), # Prevent overfitting Dense(10, activation='softmax') # 10 output classes (digits 0-9) ]) # Compile model model.compile(optimizer='adam', loss='sparse_categorical_crossentropy', metrics=['accuracy']) # Train model history = model.fit(x_train, y_train, epochs=10, validation_data=(x_test, y_test)) # Evaluate model test_loss, test_acc = model.evaluate(x_test, y_test, verbose=2) print(f"\nTest Accuracy: {test_acc*100:.2f}%") # Save model os.makedirs("models", exist_ok=True) model.save("models/mnist_cnn.h5") print("Model saved to 'models/mnist_cnn.h5'") ``` 2. Run the script. ```bash python3 train_mnist.py ``` Output. ```bash Test accuracy: 0.9925000071525574 ``` ## Step 3: Test the Model on New Data Let’s see how well our model performs on unseen digits from the MNIST test set. 1. Create a prediction script. ```bash nano predict.py ``` Add the following code. ```bash import tensorflow as tf import numpy as np import matplotlib.pyplot as plt import random # Load saved model model = tf.keras.models.load_model('models/mnist_cnn.h5') # Load test data (_, _), (x_test, y_test) = tf.keras.datasets.mnist.load_data() x_test = x_test / 255.0 x_test = x_test[..., tf.newaxis] # Make predictions def predict_random_sample(): index = random.randint(0, len(x_test)) image = x_test[index] prediction = model.predict(image[np.newaxis, ...]) predicted_label = np.argmax(prediction) plt.imshow(image.squeeze(), cmap='gray') plt.title(f'Predicted: {predicted_label}, Actual: {y_test[index]}') plt.show() # Predict 5 random samples for _ in range(5): predict_random_sample() ``` 2. Run the prediction. ```bash python3 predict.py ``` Output. ```bash 1/1 ━━━━━━━━━━━━━━━━━━━━ 1s 563ms/step 1/1 ━━━━━━━━━━━━━━━━━━━━ 0s 23ms/step 1/1 ━━━━━━━━━━━━━━━━━━━━ 0s 23ms/step 1/1 ━━━━━━━━━━━━━━━━━━━━ 0s 22ms/step 1/1 ━━━━━━━━━━━━━━━━━━━━ 0s 22ms/step ``` ## Step 4: Test on Custom Handwritten Images Now, let’s try using your own handwriting. 1. Create an image named hand.png with a white digit (3) on a black background. ![](https://www.atlantic.net/wp-content/uploads/2025/04/hand.png) 2. Create a script including your own handwritten image. ```bash nano predic_image.py ``` Add the following code. ```bash import tensorflow as tf from PIL import Image import numpy as np # Load the trained model model = tf.keras.models.load_model('models/mnist_cnn.h5') # Adjust path if needed def preprocess_custom_image(image_path): img = Image.open(image_path).convert('L') # Grayscale img = img.resize((28, 28)) # Resize to MNIST dimensions img_array = np.array(img) / 255.0 # Normalize img_array = img_array.reshape(1, 28, 28, 1) # Reshape for model return img_array # Predict custom_img = preprocess_custom_image("hand.png") # Replace with your image path prediction = model.predict(custom_img) print("Predicted Digit:", np.argmax(prediction)) ``` 3. Run the script. ```bash python3 predic_image.py ``` The script predicts your handwritten digit in the image and gives the output. ```bash Predicted Digit: 3 ``` ## Conclusion You’ve now built a neural network that can recognize handwritten digits with high accuracy using TensorFlow on an Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/). The GPU acceleration significantly reduces training time, allowing faster experimentation with different architectures and hyperparameters. --- # How to Use NVIDIA Container Tools and Miniconda with Ubuntu GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-use-nvidia-container-tools-and-miniconda-with-ubuntu-gpu-server/ | Published: 2025-03-26 | Updated: 2025-04-15 | Author: Hitesh Jethva With the right tools, running GPU-accelerated workloads like deep learning or scientific computing on an Ubuntu server can be significantly simplified. In this guide, we’ll explore how to use the Nvidia Container Toolkit for Dockerized GPU access and Miniconda for flexible environment management. Whether building AI models or managing CUDA-based applications, combining these tools provides a powerful, modular, and reproducible setup. ## Prerequisites Before diving in, ensure you have: - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user with sudo privileges. - NVIDIA drivers installed. - Basic knowledge of Docker and Conda. ## Verify Nvidia Drivers and Docker 1. Verify that the Nvidia drivers are installed. ```bash nvidia-smi ``` Output. ```bash Sun Apr 6 05:53:34 2025 +-----------------------------------------------------------------------------------------+ | NVIDIA-SMI 550.90.07 Driver Version: 550.90.07 CUDA Version: 12.4 | |-----------------------------------------+------------------------+----------------------+ | GPU Name Persistence-M | Bus-Id Disp.A | Volatile Uncorr. ECC | | Fan Temp Perf Pwr:Usage/Cap | Memory-Usage | GPU-Util Compute M. | | | | MIG M. | |=========================================+========================+======================| | 0 NVIDIA A40-8Q On | 00000000:06:00.0 Off | 0 | | N/A N/A P8 N/A / N/A | 1MiB / 8192MiB | 0% Default | | | | N/A | +-----------------------------------------+------------------------+----------------------+ +-----------------------------------------------------------------------------------------+ | Processes: | | GPU GI CI PID Type Process name GPU Memory | | ID ID Usage | |=========================================================================================| | No running processes found | +-----------------------------------------------------------------------------------------+ ``` 2. Make sure the Docker package is installed. ```bash docker --version ``` Output. ```bash Docker version 28.0.1, build 068a01e ``` ## Configure Docker to Use Nvidia Runtime 1. Configure Docker to use Nvidia runtime. ```bash nvidia-ctk runtime configure --runtime=docker ``` 2. Restart Docker to apply changes. ```bash systemctl restart docker ``` 3. Run a PyTorch container and check CUDA ```bash docker run --rm -it --gpus all --ipc=host --ulimit memlock=-1 --ulimit stack=67108864 nvcr.io/nvidia/pytorch:24.08-py3 python3 -c "import torch;print('CUDA available:', torch.cuda.is_available())" ``` Output. ```bash ============= == PyTorch == ============= NVIDIA Release 24.08 (build 107063150) PyTorch Version 2.5.0a0+872d972 Container image Copyright (c) 2024, NVIDIA CORPORATION & AFFILIATES. All rights reserved. Copyright (c) 2014-2024 Facebook Inc. Copyright (c) 2011-2014 Idiap Research Institute (Ronan Collobert) Copyright (c) 2012-2014 Deepmind Technologies (Koray Kavukcuoglu) Copyright (c) 2011-2012 NEC Laboratories America (Koray Kavukcuoglu) Copyright (c) 2011-2013 NYU (Clement Farabet) Copyright (c) 2006-2010 NEC Laboratories America (Ronan Collobert, Leon Bottou, Iain Melvin, Jason Weston) Copyright (c) 2006 Idiap Research Institute (Samy Bengio) Copyright (c) 2001-2004 Idiap Research Institute (Ronan Collobert, Samy Bengio, Johnny Mariethoz) Copyright (c) 2015 Google Inc. Copyright (c) 2015 Yangqing Jia Copyright (c) 2013-2016 The Caffe contributors All rights reserved. Various files include modifications (c) NVIDIA CORPORATION & AFFILIATES. All rights reserved. This container image and its contents are governed by the NVIDIA Deep Learning Container License. By pulling and using the container, you accept the terms and conditions of this license: https://developer.nvidia.com/ngc/nvidia-deep-learning-container-license NOTE: CUDA Forward Compatibility mode ENABLED. Using CUDA 12.6 driver version 560.35.03 with kernel driver version 550.90.07. See https://docs.nvidia.com/deploy/cuda-compatibility/ for details. CUDA available: True ``` ## Install Miniconda Miniconda provides lightweight Python environment management. 1. Create a directory for Miniconda. ```bash mkdir -p ~/miniconda3 ``` 2. Download the installer. ```bash wget https://repo.anaconda.com/miniconda/Miniconda3-latest-Linux-x86_64.sh -O ~/miniconda3/miniconda.sh ``` 3. Run the installer. ```bash bash ~/miniconda3/miniconda.sh -b -u -p ~/miniconda3 ``` 4. Remove the installer script. ```bash rm -rf ~/miniconda3/miniconda.sh ``` 5. Initialize Conda for the current user. ```bash ~/miniconda3/bin/conda init bash ``` 6. Reload the shell to apply changes. ```bash source ~/.bashrc ``` 7. Verify Conda installation. ```bash conda --version ``` Output. ```bash conda 24.7.1 ``` ## Set Up a Conda Environment with PyTorch (GPU Support) 1. Create a new environment named ‘torch’. ```bash conda create -n torch python=3.10 ``` 2. Activate the environment. ```bash conda activate torch ``` 3. Install PyTorch with CUDA 12.1. ```bash conda install pytorch torchvision torchaudio pytorch-cuda=12.1 -c pytorch -c nvidia ``` 4. Verify GPU support. ```bash python3 -c "import torch; print('CUDA available:', torch.cuda.is_available())" ``` Output. ```bash CUDA available: True ``` ## Conclusion By combining NVIDIA Container Toolkit and Miniconda, you’re unlocking a modular, GPU-powered Python environment that’s portable and easy to manage. Use this setup for: - Training PyTorch/TensorFlow models - Scientific computing - Reproducible ML pipelines This combo is especially great for teams or production pipelines needing consistency, isolation, and GPU access. Try it today on [GPU hosting](https://www.atlantic.net/gpu-server-hosting/) from Atlantic.Net! --- # How to Use ClickHouse for High-Performance Querying on Large Datasets on Ubuntu GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-use-clickhouse-for-high-performance-querying-on-large-datasets-on-ubuntu-gpu-server/ | Published: 2025-03-27 | Updated: 2026-05-04 | Author: Hitesh Jethva ClickHouse is an open-source column-oriented database management system that excels at real-time analytical processing (OLAP). When deployed on a [GPU-enabled Ubuntu server](https://www.atlantic.net/gpu-server-hosting/), ClickHouse can achieve even greater performance for querying large datasets. This in-depth guide will walk you through setting up ClickHouse with GPU support, generating test data, loading it into ClickHouse, and verifying the installation. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user with sudo privileges. - NVIDIA drivers installed. ## Step 1: Setting Up the Python Environment First, we’ll create a clean Python environment for our data generation and verification scripts. 1. Install Python and the required packages. ```bash apt install -y python3 python3-pip python3-venv ``` 2. Create and activate the virtual environment. ```bash python3 -m venv venv source venv/bin/activate ``` 3. Install ClickHouse and additional packages. ```bash pip install numpy pandas clickhouse-driver ``` **Explanation:** - **numpy** for numerical operations - **pandas** for data manipulation - **clickhouse-driver** for Python connectivity to ClickHouse ## Step 2: Generating Synthetic Test Data Create a Python script to generate a large dataset for testing. ```bash nano generate_data.py ``` Add the following code: ```bash # generate_data.py import pandas as pd import numpy as np # Generate 1 million rows of synthetic data data = { 'id': np.arange(1, 1_000_001), 'feature1': np.random.rand(1_000_000), 'feature2': np.random.rand(1_000_000), 'feature3': np.random.rand(1_000_000) } df = pd.DataFrame(data) df.to_csv('data.csv', index=False) print("Generated data.csv with 1,000,000 rows") ``` Run the script. ```bash python3 generate_data.py ``` This creates a CSV file with 1 million rows of random floating-point numbers across three features, plus an ID column. ```bash Generated data.csv with 1,000,000 rows ``` ## Step 3: Setting Up ClickHouse with GPU Support ClickHouse has experimental GPU support that can accelerate certain operations. We’ll use Docker to run ClickHouse with GPU access. ```bash docker run -d \ --name clickhouse-server \ --gpus all \ -p 9000:9000 \ -p 8123:8123 \ -v $PWD/data:/var/lib/clickhouse \ -e CLICKHOUSE_DEFAULT_ACCESS_MANAGEMENT=1 \ clickhouse/clickhouse-server:latest ``` **Key parameters:** - **–gpus all:** Enables GPU access for the container - Ports 9000 (native protocol) and 8123 (HTTP interface) exposed - Data directory mounted for persistence - Access management enabled for security ## Step 4: Preparing the ClickHouse Database 1. Copy the data file into the container and access the ClickHouse shell: ```bash docker cp data.csv clickhouse-server:/tmp/data.csv ``` 2. Connect to the ClickHouse container. ```bash docker exec -it clickhouse-server /bin/bash ``` 3. Inside the container, connect to the ClickHouse server. ```bash clickhouse-client ``` 4. Create a table to hold our data. ```bash CREATE TABLE large_dataset ( id UInt32, feature1 Float64, feature2 Float64, feature3 Float64 ) ENGINE = MergeTree() ORDER BY id; ``` 5. Exit from the ClickHouse shell. ```bash exit ``` ## Step 5: Loading Data into ClickHouse 1. Use the ClickHouse client to import the CSV data. ```bash clickhouse-client --query "INSERT INTO large_dataset FORMAT CSV" < /tmp/data.csv --progress ``` 2. Exit from the Docker container. ```bash exit ``` ## Step 6: Verifying the Data 1. Create a verification script to check the data was loaded correctly: ```bash nano verify_data.py ``` Add the code below. ```bash # verify_data.py from clickhouse_driver import Client client = Client( host='localhost', user='default', password='' ) count = client.execute('SELECT count() FROM large_dataset')[0][0] print(f"Table contains {count} rows") sample = client.execute('SELECT * FROM large_dataset LIMIT 5') print("Sample rows:") for row in sample: print(row) ``` 2. Run the verification. ```bash python3 verify_data.py ``` Output. ```bash Table contains 2000000 rows Sample rows: (1, 0.38233336651112515, 0.29973790958931235, 0.936007728842977) (2, 0.13126390736004656, 0.249047252224595, 0.6534321474304323) (3, 0.7285561857877713, 0.38113395640456516, 0.6836105833319909) (4, 0.5117479220423862, 0.7073417787216559, 0.8446349501745961) (5, 0.6415940064857016, 0.7574774031938657, 0.7175210065963386) ``` ## Step 7: Running Performance Queries Now that the data is loaded, let’s test some queries. ClickHouse’s columnar storage and GPU acceleration shine with analytical queries: 1. First, install the ClickHouse client. ```bash apt install clickhouse-client ``` 2. Connect to the ClickHouse server. ```bash clickhouse-client ``` Output. ```bash ClickHouse client version 18.16.1. Connecting to localhost:9000. Connected to ClickHouse server version 25.3.2 revision 54476. e7cf71653d41 :) ``` 2. Run the below query for basic aggregation. ```bash SELECT avg(feature1) as avg_feature1, stddevPop(feature2) as std_feature2, quantile(0.99)(feature3) as p99_feature3 FROM large_dataset ``` Output: ```bash SELECT avg(feature1) AS avg_feature1, stddevPop(feature2) AS std_feature2, quantile(0.99)(feature3) AS p99_feature3 FROM large_dataset ┌───────avg_feature1─┬────────std_feature2─┬───────p99_feature3─┐ │ 0.5002608413633995 │ 0.28872380769587086 │ 0.9908446093587597 │ └────────────────────┴─────────────────────┴────────────────────┘ ↘ Progress: 1.00 million rows, 24.00 MB (108.22 million rows/s., 2.60 GB/s.) 99% 1 rows in set. Elapsed: 0.010 sec. Processed 1.00 million rows, 24.00 MB (103.62 million rows/s., 2.49 GB/s.) ``` 3. Run the below query for filtering and grouping. ```bash SELECT intDiv(id, 100000) as bucket, count() as count, avg(feature1 + feature2) as avg_combined FROM large_dataset WHERE feature3 > 0.5 GROUP BY bucket ORDER BY bucket ``` Output: ```bash SELECT intDiv(id, 100000) AS bucket, count() AS count, avg(feature1 + feature2) AS avg_combined FROM large_dataset WHERE feature3 > 0.5 GROUP BY bucket ORDER BY bucket ASC ┌─bucket─┬─count─┬───────avg_combined─┐ │ 0 │ 49802 │ 1.0000974894524948 │ │ 1 │ 50131 │ 1.0002304278511396 │ │ 2 │ 49990 │ 1.0011286054623088 │ │ 3 │ 50031 │ 0.9968373869613624 │ │ 4 │ 50022 │ 1.0022925786397234 │ │ 5 │ 50123 │ 0.9986748463314014 │ │ 6 │ 50218 │ 1.0004042381656353 │ │ 7 │ 50041 │ 0.9998849136710541 │ │ 8 │ 50138 │ 1.000476200468667 │ │ 9 │ 49908 │ 1.0030392683409466 │ └────────┴───────┴────────────────────┘ ↙ Progress: 1.00 million rows, 28.00 MB (87.21 million rows/s., 2.44 GB/s.) 99% 10 rows in set. Elapsed: 0.012 sec. Processed 1.00 million rows, 28.00 MB (83.71 million rows/s., 2.34 GB/s.) ``` 4. Exit from the ClickHouse shell. ```bash exit ``` ## Conclusion By combining ClickHouse’s columnar storage and vectorized query execution with GPU acceleration on an Ubuntu server, you can achieve exceptional performance when querying large datasets. The setup process is straightforward with Docker, and the performance benefits for analytical workloads are substantial. --- # Deploying Generative AI on an Ubuntu GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/deploying-generative-ai-on-an-ubuntu-gpu-server/ | Published: 2025-03-28 | Updated: 2025-04-15 | Author: Hitesh Jethva Generative AI has revolutionized how we create content, from text and images to music and code. Models like OpenAI’s GPT, Stable Diffusion, and DALL-E have demonstrated the immense potential of generative AI. However, deploying these models efficiently requires robust hardware and software configurations, especially when leveraging GPUs for accelerated performance. In this guide, we’ll set up a GPT-2 text generation model on an Ubuntu server with an NVIDIA GPU, using FastAPI for the backend and a simple web interface for interaction. ## Prerequisites - An Ubuntu 24.04 server with an [NVIDIA GPU](https://www.atlantic.net/gpu-server-hosting/an-overview-of-popular-nvidia-gpus/). - A non-root user with sudo privileges. - NVIDIA drivers installed. ## Step 1: Install System Dependencies Before setting up the AI model, we must ensure the system has the required dependencies. 1. Update system packages. ```bash apt update ``` 2. Install Python and Pip. ```bash apt install -y python3 python3-pip python3-venv ``` 3. Create and activate the virtual environment. ```bash python3 -m venv generative-ai-env source generative-ai-env/bin/activate ``` ## Step 2: Install AI & Web Framework Dependencies 1. Create the required directories for your project. ```bash mkdir templates static ``` 2. Install PyTorch with GPU support. ```bash pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu118 ``` 3. Install Transformers and Tensorflow. ```bash pip install tensorflow transformers diffusers openai ``` 4. Install FastAPI and Uvicorn. ```bash pip install fastapi uvicorn jinja2 ``` ## Step 3: Create the HTML Frontend We’ll build a simple interface for text generation. Create **index.html.** ```bash nano templates/index.html ``` Add the following code: ```bash GPT-2 Demo

GPT-2 Text Generator

Output:

``` **Explanation:** - A textarea for user input. - A submit button to trigger generation. - JavaScript Fetch API to communicate with the backend. - Simple CSS styling for better UX. ## Step 4: Create the FastAPI Backend The backend loads the GPT-2 model and handles requests. Create app.py file. ```bash nano app.py ``` Add the following code. ```bash from fastapi import FastAPI, Request, HTTPException from fastapi.responses import HTMLResponse, JSONResponse from fastapi.templating import Jinja2Templates from transformers import pipeline, set_seed import torch import os import logging from pydantic import BaseModel # Configure logging logging.basicConfig(level=logging.INFO) logger = logging.getLogger(__name__) app = FastAPI() templates = Jinja2Templates(directory="templates") class PromptRequest(BaseModel): prompt: str max_length: int = 150 # Reduced default length to prevent rambling # Model loading with better error handling def load_model(): try: device = "cuda" if torch.cuda.is_available() else "cpu" logger.info(f"Loading model on device: {device}") # Using gpt2 instead of distilgpt2 for better quality model_name = "gpt2" generator = pipeline( "text-generation", model=model_name, device=device, framework="pt", torch_dtype=torch.float16 if device == "cuda" else torch.float32 ) logger.info(f"Successfully loaded {model_name}") return generator except Exception as e: logger.error(f"Model loading failed: {str(e)}") return None generator = load_model() @app.get("/", response_class=HTMLResponse) async def read_root(request: Request): return templates.TemplateResponse("index.html", { "request": request, "model_loaded": generator is not None }) @app.post("/generate") async def generate_text(request_data: PromptRequest): if not generator: return JSONResponse( status_code=503, content={"error": "Model not loaded. Please try again later."} ) try: set_seed(42) # For reproducible results # Enhanced generation parameters output = generator( request_data.prompt, max_length=request_data.max_length, num_return_sequences=1, do_sample=True, temperature=0.7, # Controls randomness top_k=50, # Limits to top 50 probable tokens top_p=0.9, # Nucleus sampling threshold repetition_penalty=1.5, # Strong penalty for repetition no_repeat_ngram_size=3, # Prevents 3-word repetitions early_stopping=True # Stops when coherent answer is reached ) # Clean up the output generated_text = output[0]["generated_text"] # Remove the input prompt if it appears in output if generated_text.startswith(request_data.prompt): generated_text = generated_text[len(request_data.prompt):].strip() # Truncate at last complete sentence last_period = generated_text.rfind('.') if last_period > 0: generated_text = generated_text[:last_period + 1] return {"output": generated_text} except Exception as e: logger.error(f"Generation error: {str(e)}") return JSONResponse( status_code=500, content={"error": f"Generation failed: {str(e)}"} ) if __name__ == "__main__": import uvicorn uvicorn.run( app, host="0.0.0.0", port=8000, reload=True, log_level="info" ) ``` **Key Components:** - **FastAPI:** Handles HTTP requests. - **transformers:** Loads the GPT-2 model. - **device=”cuda”:** Ensures GPU acceleration. - **POST /generate:** Processes prompts and returns AI-generated text. ## Step 5: Run the FastAPI Server Start the server for testing. ```bash uvicorn app:app --reload --host 0.0.0.0 --port 8000 ``` ## Step 6: Access and Test the API 1. Open a browser and go to **http://your-server-ip:8000.** ![](https://www.atlantic.net/wp-content/uploads/2025/04/p1.png) 2. Enter a prompt (e.g., “**What is neural networks?**“). 3. Click **Generate Text** and see the AI response! ## Conclusion You’ve deployed a Generative AI (GPT-2) model on an Ubuntu GPU server with a FastAPI backend and interactive web UI. This setup can be extended to models like LLaMA, Stable Diffusion, or Whisper. Now, go ahead and build amazing AI-powered applications! --- # How to Run Stable Cascade model on Cloud GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-run-stable-cascade-model-on-cloud-gpu-server/ | Published: 2025-03-31 | Updated: 2026-02-28 | Author: Hitesh Jethva Artificial Intelligence (AI) has revolutionized image generation, enabling the creation of high-quality, photorealistic images from text prompts. One of the most advanced models in this domain is Stable Cascade, developed by Stability AI. Built on the Würstchen architecture, Stable Cascade employs a three-stage (A, B, C) process to generate efficient and high-quality images. This guide will walk you through setting up and running the Stable Cascade model on an Atlantic.Net [Cloud GPU Server](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/) running Ubuntu. ## What Is Stable Cascade? Stable Cascade is a state-of-the-art text-to-image generation model that leverages a three-stage architecture for improved efficiency and image quality. The model’s stages are as follows: - **Stage** **A**: The Encoder Network compresses an input image into a latent code, reducing the data size by 42x. This compressed data is stored in a low-dimensional latent space and passed to Stage B. - **Stage** **B**: The Decoder Network expands the latent code, adding details and filling in missing information before forwarding it to the Latent Generator. - **Stage C**: The Latent Generator combines the compressed latent code from Stage B with a text prompt to iteratively refine and generate a high-resolution image aligned with the input prompt. ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 24.04 Cloud GPU Server with 20 GB GPU memory. - **CUDA Toolkit 12.x and cuDNN 8.x installed** - **Git Installed:** `sudo apt install git` - Root or sudo privileges. ## Step 1: Setting Up the Environment To get started, you need to set up a development environment on your Ubuntu GPU server. Follow these steps: 1. First, update your system and install the necessary dependencies: ```bash apt update apt install python3 python3-pip python3-venv ``` 2. Create a virtual environment to isolate your project dependencies: ```bash python3 -m venv stablecascade-env source stablecascade-env/bin/activate ``` 3. Install Jupyter Notebook to create an interactive environment for running the model: ```bash pip install jupyter ``` ## Step 2: Installing the Stable Cascade Model 1. Clone the official Stable Cascade repository: ```bash git clone https://github.com/Stability-AI/StableCascade.git cd StableCascade ``` 2. Remove an existing requirements.txt file. This is to ensure a clean install. ```bash rm -rf requirements.txt ``` 2. Create a new requirements.txt file. ```bash nano requirements.txt ``` Add the following dependencies: ```bash --find-links https://download.pytorch.org/whl/torch_stable.html accelerate torch torchvision transformers numpy kornia insightface opencv-python tqdm matplotlib webdataset wandb munch onnxruntime einops onnx2torch warmup-scheduler @ git+https://github.com/ildoonet/pytorch-gradual-warmup-lr.git torchtools @ git+https://github.com/pabloppp/pytorch-tools ``` 3. Install the dependencies: ```bash pip install -r requirements.txt ``` 4. Navigate to the models directory and download the required model weights: ```bash cd models bash download_models.sh essential big-big bfloat16 ``` 5. Go back to your project directory. ```bash cd .. ``` ## Step 3: Generating Images with Stable Cascade Once the environment is set up, you can start generating images using the Stable Cascade model. Below is a step-by-step guide to implementing the model in a Jupyter Notebook. 1. Run the Jupyter Notebook server, replacing your-server-ip with the actual public IP address of your Ubuntu server. Ensure port 8888 is open in your server’s firewall: ```bash jupyter notebook --no-browser --port=8888 --ip=your-server-ip --allow-root ``` Output. ```bash To access the server, open this file in a browser: file:///root/.local/share/jupyter/runtime/jpserver-7437-open.html Or copy and paste one of these URLs: http://your-server-ip:8888/tree?token=6a8386b686c4131d1da9aa9b95750fdffa11e38e1ce23958 http://127.0.0.1:8888/tree?token=6a8386b686c4131d1da9aa9b95750fdffa11e38e1ce23958 ``` 2. Access the notebook using the provided URL, such as: **http://your-server-ip:8888/tree?token=6a8386b686c4131d1da9aa9b95750fdffa11e38e1ce23958** ![](https://www.atlantic.net/wp-content/uploads/2025/03/p.png) 3. Click on **File** and create a new notebook. 4. Add the below code in the notebook shell to import the necessary Python packages: ```bash import os import yaml import torch import torchvision from tqdm import tqdm from PIL import Image os.chdir('/root/StableCascade/') from inference.utils import * from core.utils import load_or_fail from train import WurstCoreC, WurstCoreB ``` This code block imports the necessary modules for file operations (`os`), configuration parsing (`yaml`), PyTorch functionalities (`torch`, `torchvision`), image processing (`PIL`), progress tracking (`tqdm`), and model-specific utility functions and classes (`inference.utils`, `core.utils`, `train`). The `os.chdir()` function changes the working directory to the Stable Cascade project folder. 5. Check if the GPU is available: ```bash device = torch.device("cuda:0" if torch.cuda.is_available() else "cpu") print(device) ``` This code checks if a GPU is available and sets the device accordingly. If a GPU is available, it will use **cuda:0;** otherwise, it defaults to the CPU. 6. Load the configuration files for **Stage C** and **Stage** **B**: ```bash # Stage C config_file = 'configs/inference/stage_c_3b.yaml' with open(config_file, "r", encoding="utf-8") as file: loaded_config = yaml.safe_load(file) core = WurstCoreC(config_dict=loaded_config, device=device, training=False) ``` This step loads the YAML configuration file for Stage C, which contains model settings and parameters. The **WurstCoreC** class initializes the Stage C model. 7. Load the configuration file for Stage B: ```bash # Stage B config_file_b = 'configs/inference/stage_b_3b.yaml' with open(config_file_b, "r", encoding="utf-8") as file: config_file_b = yaml.safe_load(file) core_b = WurstCoreB(config_dict=config_file_b, device=device, training=False) ``` Similar to Stage C, this step loads the configuration file for Stage B and initializes the model using the **WurstCoreB** class. 8. Prepare the Stage C model for inference: ```bash extras = core.setup_extras_pre() models = core.setup_models(extras) models.generator.eval().requires_grad_(False) print("STAGE C READY") ``` This code sets up the Stage C model by initializing the generator, discriminator, and tokenizer. The **eval()** method sets the model to evaluation mode, and **requires_grad_(False)** disables gradient computation to save resources. 9. Prepare the Stage B model for inference: ```bash extras_b = core_b.setup_extras_pre() models_b = core_b.setup_models(extras_b, skip_clip=True) models_b = WurstCoreB.Models( **{**models_b.to_dict(), 'tokenizer': models.tokenizer, 'text_model': models.text_model} ) models_b.generator.bfloat16().eval().requires_grad_(False) print("STAGE B READY") ``` This step prepares the Stage B model, similar to Stage C. The **bfloat16()** method converts the model parameters to 16-bit floating-point precision for faster computation. 10. Set the batch size and text prompt for image generation: ```bash batch_size = 4 caption = "Anthropomorphic cat dressed as a pilot" ``` The **batch_size** determines how many images are generated in parallel. The caption variable contains the text prompt that describes the desired image. 11. Set the height and width of the generated image: ```bash height, width = 1024, 1024 stage_c_latent_shape, stage_b_latent_shape = calculate_latent_sizes(height, width, batch_size=batch_size) ``` This step defines the resolution of the generated image and calculates the latent sizes for Stage C and Stage B. 12. Configure the sampling parameters for Stage C and Stage B: ```bash # Stage C Parameters extras.sampling_configs['cfg'] = 4 extras.sampling_configs['shift'] = 2 extras.sampling_configs['timesteps'] = 20 extras.sampling_configs['t_start'] = 1.0 # Stage B Parameters extras_b.sampling_configs['cfg'] = 1.1 extras_b.sampling_configs['shift'] = 1 extras_b.sampling_configs['timesteps'] = 10 extras_b.sampling_configs['t_start'] = 1.0 ``` These parameters control the sampling process during image generation, such as the number of timesteps and the guidance scale. 13. Prepare conditions and unconditional inputs for both stages: ```bash batch = {'captions': * batch_size} conditions = core.get_conditions(batch, models, extras, is_eval=True, is_unconditional=False, eval_image_embeds=False) unconditions = core.get_conditions(batch, models, extras, is_eval=True, is_unconditional=True, eval_image_embeds=False) conditions_b = core_b.get_conditions(batch, models_b, extras_b, is_eval=True, is_unconditional=False) unconditions_b = core_b.get_conditions(batch, models_b, extras_b, is_eval=True, is_unconditional=True) ``` This step prepares the conditions required for generating images based on the input text prompt. 14. Disable parallelism to avoid conflicts during image generation: ```bash os.environ["TOKENIZERS_PARALLELISM"] = "false" ``` This step ensures that the tokenizer runs sequentially, preventing potential issues with parallel processing. 15. . Run the image generation process, with *tqdm* providing a progress bar to track the sampling steps: ```bash with torch.no_grad(), torch.cuda.amp.autocast(dtype=torch.bfloat16): sampling_c = extras.gdf.sample( models.generator, conditions, stage_c_latent_shape, unconditions, device=device, **extras.sampling_configs, ) for (sampled_c, _, _) in tqdm(sampling_c, total=extras.sampling_configs['timesteps']): sampled_c = sampled_c conditions_b['effnet'] = sampled_c unconditions_b['effnet'] = torch.zeros_like(sampled_c) sampling_b = extras_b.gdf.sample( models_b.generator, conditions_b, stage_b_latent_shape, unconditions_b, device=device, **extras_b.sampling_configs ) for (sampled_b, _, _) in tqdm(sampling_b, total=extras_b.sampling_configs['timesteps']): sampled_b = sampled_b sampled = models_b.stage_a.decode(sampled_b).float() ``` This code generates the image in two stages. Stage C creates a latent representation, and Stage B decodes it into a high-resolution image. The torch.cuda.amp.autocast enables mixed-precision computation for faster processing. 16. View the generated image: ```bash show_images(sampled) ``` This step displays the final image generated based on the input text prompt. ![](https://www.atlantic.net/wp-content/uploads/2025/03/p1-1.png) ## Conclusion By following this guide, you have successfully set up and run the Stable Cascade model on an Atlantic.Net Cloud GPU Server to generate AI images. The model’s three-stage architecture ensures high-quality results, and its flexibility allows for various extensions and fine-tuning options. --- # How to Deploy OobaBooga and Use It to Run a Model on a GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-deploy-oobabooga-and-use-it-to-run-a-model-on-a-gpu-server/ | Published: 2025-04-01 | Updated: 2025-04-14 | Author: Hitesh Jethva OobaBooga’s Text Generation Web UI is an open-source project that simplifies deploying and interacting with large language models like GPT-J-6B. It provides a user-friendly web interface to generate text, fine-tune parameters, and experiment with different models without extensive technical expertise. Whether you are a developer, researcher, or AI enthusiast, this tool makes using LLMs on your own hardware easy. In this guide, we will go through the steps to deploy OobaBooga and run a model on an Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/). ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 24.04 Cloud GPU Server with 8 GB GPU memory. - **CUDA Toolkit 12.x and cuDNN 8.x installed ** - **Git Installed:** `sudo apt install git` - Root or sudo privilege ## Step 1: Set Up the Environment First, update your system and install the necessary dependencies: ```bash apt update apt install python3 python3-pip python3-venv ``` Next, create a Python virtual environment to isolate your project dependencies: ```bash python3 -m venv opentext-env source opentext-env/bin/activate ``` ## Step 2: Install PyTorch with CUDA Support OobaBooga relies on PyTorch for model inference. - **Note:** This installation may take several minutes depending on your internet connection. - **Verify CUDA is working:** Run `python3 -c "import torch; print(torch.cuda.is_available())"`. If it prints `True`, CUDA is correctly configured. Install PyTorch with CUDA 11.8 support to enable GPU acceleration: ```bash pip3 install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu118 ``` ## Step 3: Clone the OobaBooga Repository Clone the OobaBooga Text Generation Web UI repository from GitHub: ```bash git clone https://github.com/oobabooga/text-generation-webui.git cd text-generation-webui ``` Install the required Python packages: ```bash pip3 install -r requirements.txt ``` ## Step 4: Download the GPT-J-6B Model Navigate to the models directory. ```bash cd models ``` Create a folder for the GPT-J-6B model and navigate to it. ```bash mkdir gpt-j-6B cd gpt-j-6B ``` Download the necessary model files from Hugging Face: ```bash wget https://huggingface.co/EleutherAI/gpt-j-6B/resolve/main/pytorch_model.bin wget https://huggingface.co/EleutherAI/gpt-j-6B/resolve/main/config.json wget https://huggingface.co/EleutherAI/gpt-j-6B/resolve/main/vocab.json wget https://huggingface.co/EleutherAI/gpt-j-6B/resolve/main/merges.txt ``` **Important:** These files are large, so the download may take a significant amount of time. If you encounter slow download speeds or connection issues, Hugging Face’s rate limiting may be in effect. Return to the project root directory: ```bash cd ../.. ``` ## Step 5: Configure the Web UI Copy the **settings-template.yaml** file to **settings.yaml** to create a configuration file: ```bash cp settings-template.yaml settings.yaml ``` You can modify **settings.yaml** to customize the behavior of the web UI, but the default settings should work fine for most use cases. ## Step 6: Run the Web UI Start the OobaBooga Text Generation Web UI with the following command: ```bash python3 server.py --listen --model models/gpt-j-6B --load-in-8bit ``` This command does the following: - **–listen:** Allows the server to be accessed from other devices on the network. - **–model** models/gpt-j-6B: Specifies the path to the GPT-J-6B model. - **–load-in-8bit:** Reduces memory usage by loading the model in 8-bit precision. Once the server starts, you’ll see output similar to this: ```bash 15:34:00-890889 INFO Loaded "gpt-j-6B" in 38.20 seconds. 15:34:00-892683 INFO LOADER: "Transformers" 15:34:00-893366 INFO TRUNCATION LENGTH: 2048 15:34:00-893964 INFO INSTRUCTION TEMPLATE: "Alpaca" Running on local URL: http://0.0.0.0:7860 ``` **Note:** The output `Running on local URL: http://0.0.0.0:7860` indicates the server is running *on the Ubuntu server itself*. To access it from another device, you’ll use `http://your_server_public_ip:7860`. Also, ensure that port 7860 is open in your server’s firewall. The model will take a longer time to load the first time. ## Step 7: Access the Web UI Open your web browser and navigate to `http://your_server_public_ip:7860`. **Replace `your_server_public_ip` with the actual public IP address of your Ubuntu server.** ![](https://www.atlantic.net/wp-content/uploads/2025/03/p1-2.png) Enter the prompt “**What is the full form of ATM**” in the text box, and click **“Generate”** to see the model’s output. ![](https://www.atlantic.net/wp-content/uploads/2025/03/p2-1.png) ## Conclusion Deploying OobaBooga’s Text Generation Web UI on an Ubuntu GPU server is straightforward and unlocks the power of large language models like GPT-J-6B. Follow this guide to set up a text generation environment and start experimenting with AI-driven content creation. --- # Deploying an NLP Model as a Web App on a GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/deploying-an-nlp-model-as-a-web-app-on-a-gpu-server/ | Published: 2025-04-02 | Updated: 2025-04-14 | Author: Hitesh Jethva Natural Language Processing (NLP) has become a key technology that helps computers understand and work with human language in recent years. NLP is used in many things like chatbots, analyzing feelings in texts, translating languages, and summarizing long articles. While creating a good NLP model is important, deploying it properly to work well for real users is just as crucial. This means ensuring the NLP system is easy to access, can handle many users at once, and works efficiently. In this article, we will deploy an NLP model as a web application on an Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/) using PyTorch. ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 24.04 Cloud GPU Server. - CUDA Toolkit 11.8 and cuDNN 8.6 installed. Verify with `nvidia-smi`. - curl installed: `sudo apt install curl` - Root or sudo privileges. ## Step 1: Setting up the Environment 1. Install Python with additional dependencies. ```bash apt install python3-venv python3-pip ``` 2. Create a Python virtual environment. ```bash python3 -m venv pytorch-env ``` 3. Activate the virtual environment. ```bash source pytorch-env/bin/activate ``` ## Step 2: Install PyTorch with GPU Support 1. Install PyTorch with GPU support **Note**: This installation can take a significant amount of time. Verify CUDA is working: Run python3 -c “import torch; print(torch.cuda.is_available())”. If it prints True, CUDA is correctly configured. ```bash pip install torch torchvision torchaudio --extra-index-url https://download.pytorch.org/whl/cu118 ``` 2. Next, install Flask to create the web application: ```bash pip install Flask ``` 3. Install the transformers library if you haven’t already: ```bash pip install transformers ``` ## Step 3: Building the NLP Model We’ll use a pre-trained BERT model from the Hugging Face transformers library for text classification. **Note**: BERT (Bidirectional Encoder Representations from Transformers) is a pre-trained model that has achieved state-of-the-art results in various NLP tasks. It is used here for text classification. The predicted class 0 represents the first class that the model was trained on. Without knowing the training data, it is impossible to know what that class represents. Create a Python script to load the pre-trained model and tokenizer, and perform inference on sample text. ```bash nano load_module.py ``` Add the following code. ```bash from transformers import BertTokenizer, BertForSequenceClassification import torch # Load pre-trained model and tokenizer model_name = 'bert-base-uncased' tokenizer = BertTokenizer.from_pretrained(model_name) model = BertForSequenceClassification.from_pretrained(model_name) # Example input text input_text = "This is a sample text for classification." # Tokenize input text inputs = tokenizer(input_text, return_tensors='pt', truncation=True, padding=True) # Perform inference with torch.no_grad(): outputs = model(**inputs) logits = outputs.logits predicted_class = torch.argmax(logits, dim=1).item() print(f"Predicted class: {predicted_class}") ``` Run the script to test the model: ```bash python3 load_module.py ``` Output. ```bash Predicted class: 0 ``` This confirms that the model is working as expected. ## Step 4: Creating the Flask Web App Create a file named app.py. ```bash nano app.py ``` Add the following code. ```bash from flask import Flask, request, jsonify from transformers import BertTokenizer, BertForSequenceClassification import torch app = Flask(__name__) # Load pre-trained model and tokenizer model_name = 'bert-base-uncased' tokenizer = BertTokenizer.from_pretrained(model_name) model = BertForSequenceClassification.from_pretrained(model_name) @app.route('/predict', methods=['POST']) def predict(): data = request.json input_text = data.get('text', '') if not input_text: return jsonify({'error': 'No text provided'}), 400 # Tokenize input text inputs = tokenizer(input_text, return_tensors='pt', truncation=True, padding=True) # Perform inference with torch.no_grad(): outputs = model(**inputs) logits = outputs.logits predicted_class = torch.argmax(logits, dim=1).item() return jsonify({'predicted_class': predicted_class}) if __name__ == '__main__': app.run(host='0.0.0.0', port=5000) ``` Save the file and run the Flask app using the following command: ```bash python3 app.py & ``` The Flask server will start on **http://0.0.0.0:5000.** ## Step 5: Testing the Deployed Model You can test the deployed model by sending a POST request to the /predict endpoint. Here’s how you can do it using curl. Run the following command in your terminal: ```bash curl -X POST http://localhost:5000/predict -H "Content-Type: application/json" -d '{"text": "This is a sample text for classification."}' ``` If everything is set up correctly, you should receive a JSON response like this: ```bash {"predicted_class":0} ``` The predicted_class value will depend on the model’s output. ## Conclusion In this article, we walked through deploying an NLP model as a web application on an Ubuntu GPU server using PyTorch and Flask. We also demonstrated how to test the deployed model by sending a POST request. By leveraging the power of GPUs, you can significantly speed up the inference time of your NLP models, making them suitable for real-time applications. --- # HIPAA Compliance in the Age of AI > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-in-the-age-of-ai/ | Published: 2025-04-03 | Updated: 2025-04-10 | Author: Gilad Maayan ## What Is HIPAA Compliance? [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/what-is-hipaa-compliance-history-rules-and-requirements/) refers to adherence to the Health Insurance Portability and Accountability Act (HIPAA), a U.S. federal law enacted in 1996 to protect the privacy and security of individuals’ medical information. HIPAA establishes standards for protecting protected health information (PHI), which includes any data that can identify an individual, such as medical records, billing information, or insurance details. Compliance with HIPAA involves following its key rules: 1. **Privacy rule**: Ensures that PHI is not disclosed without the patient’s consent or knowledge, except under specific circumstances such as public health reporting. 2. **Security rule**: Requires organizations to implement administrative, physical, and technical safeguards to protect electronic PHI (ePHI). 3. **Breach notification rule**: Mandates that covered entities notify affected individuals and the Department of Health and Human Services (HHS) of data breaches. 4. **Enforcement rule**: Defines the penalties for noncompliance, which can range from monetary fines to criminal charges in severe cases. Entities that must comply include healthcare providers, health plans, clearinghouses, and their business associates. Failure to meet these requirements can lead to legal and financial consequences. ## How Do AI Technologies Impact HIPAA Compliance? The rapid adoption of AI in healthcare has introduced both opportunities and challenges for maintaining HIPAA compliance. While AI systems offer solutions for diagnostics, treatment, and operational efficiency, their integration raises concerns around data privacy, security, and ethical use. AI often relies on large datasets, including PHI, to train algorithms and improve performance. This creates a tension between leveraging data to improve healthcare outcomes and adhering to HIPAA’s regulations. Compliance in this context requires organizations to ensure that AI systems and their data sources are designed and deployed with HIPAA standards in mind. This includes implementing technical safeguards, such as encryption and access controls, and organizational measures like employee training and governance policies. Additionally, the use of AI amplifies the need for transparency and accountability. Organizations must document AI system functionalities, data usage, and decision-making processes. ## Applications of AI in Healthcare Here are some of the way AI is used in healthcare today. ### AI in Diagnostics and Treatment Planning AI is transforming diagnostics and treatment planning by improving accuracy, speed, and accessibility. Machine learning algorithms can analyze medical imaging data, such as X-rays, MRIs, and CT scans, to detect abnormalities like tumors or fractures. AI-powered diagnostic tools often outperform human radiologists in identifying conditions such as cancer or rare diseases at early stages. In treatment planning, AI can analyze patient histories, genetic profiles, and clinical guidelines to recommend personalized treatment options. For example, AI systems can assist oncologists in identifying the most effective therapies for individual cancer patients based on tumor characteristics and drug interactions. Additionally, predictive analytics help clinicians anticipate complications or disease progression. ### AI in Patient Data Management AI improves the management of patient data by improving accuracy, organization, and accessibility. Natural language processing (NLP) tools can extract relevant information from unstructured medical records, making it easier for healthcare providers to retrieve and analyze patient histories. This simplifies clinical decision-making and reduces the risk of errors caused by incomplete or inconsistent data. AI-powered data management systems also support interoperability by standardizing and integrating data from multiple sources, such as electronic health records (EHRs), wearables, and lab systems. Real-time data processing allows healthcare providers to monitor patient conditions continuously and respond promptly to changes. AI ensures that data is categorized and stored securely, adhering to HIPAA regulations, while encryption methods protect sensitive information against breaches. ### Administrative Process Automation AI can automate repetitive and time-consuming tasks, allowing staff to focus on patient care. For example, AI-driven tools can manage appointment scheduling, billing, and claims processing with minimal human intervention. These systems improve operational efficiency and reduce errors that could delay care or result in financial losses. Another key application is prior authorization, where AI algorithms simplify the review process for insurance approvals by automatically verifying patient eligibility and matching clinical documentation with insurer requirements. Chatbots and virtual assistants further improve patient engagement by providing instant answers to queries, sending appointment reminders, or guiding patients through administrative procedures. ### Tips from the expert: ![Author icon](https://secure.gravatar.com/avatar/eb8695bf1d856d659c4fa98eba9e0c42?s=192&d=mm&r=g) ![Linkedin Icon](https://www.atlantic.net/wp-content/themes/anet/img/cloud/gpu/icon_linkedin.webp) #### Richard Bailey ##### Technical Editor Richard Bailey brings over two decades of IT expertise, from traditional data centers to cutting-edge cloud solutions. As the founder of [turbogeek.co.uk](https://turbogeek.co.uk/) and a seasoned writer, he focuses on delivering authoritative content on our hosting services, HIPAA compliance, and related topics. In my experience, here are additional tips to ensure HIPAA compliance when integrating AI into healthcare systems: 1. **Use differential privacy for enhanced data protection:** Implement differential privacy techniques to allow AI models to learn from sensitive data without exposing individual patient information. By adding controlled noise to datasets, organizations can protect PHI while maintaining model utility. 2. **Implement role-based access controls for AI systems:** Restrict access to AI platforms and datasets based on roles and responsibilities. Role-based access control ensures that only authorized personnel can view or modify sensitive data, reducing the risk of insider threats. 3. **Conduct adversarial testing on AI models:** Evaluate AI systems against potential attacks, such as adversarial inputs or data poisoning, to ensure robust performance and compliance. This proactive approach safeguards AI models from vulnerabilities that could compromise PHI. 4. **Deploy edge AI for localized processing:** Use edge AI devices to process sensitive health data locally rather than transmitting it to the cloud. This reduces exposure to breaches during transmission and aligns with HIPAA’s focus on securing PHI in transit. 5. **Leverage blockchain for secure data logging:** Integrate blockchain technology to create immutable logs of data transactions involving PHI. Blockchain ensures transparency, accountability, and tamper-proof audit trails, enhancing compliance and trust. ## Challenges of AI in Relation to HIPAA Compliance ### Data De-Identification De-identification plays a central role in enabling the use of health data in AI systems while maintaining HIPAA compliance. Under HIPAA, de-identified information is not considered PHI and can therefore be used or disclosed without restriction. Covered entities and business associates can apply one of two approved methods to de-identify data: - **The expert determination method**involves a qualified expert applying statistical and scientific techniques to conclude that the risk of identifying an individual is very small. This determination must be documented, including the methods used and the results. - **The safe harbor method** requires the removal of 18 specific identifiers—such as names, full dates, and geographic locations smaller than a state—and the absence of actual knowledge that the remaining data could be used to re-identify a person. ### Data Privacy Concerns AI systems typically require vast amounts of health data to function effectively, raising significant privacy concerns. The aggregation and processing of sensitive PHI increase the risk of unauthorized access or misuse. Even when data is de-identified, there is a possibility of re-identification through advanced data-matching techniques, especially if datasets are combined with external information. ### Security Vulnerabilities The integration of AI into healthcare networks introduces new attack vectors that could jeopardize ePHI. AI systems are susceptible to hacking, data breaches, and ransomware attacks, which can lead to significant HIPAA violations. Additionally, AI’s reliance on cloud-based solutions can expose sensitive data during transmission or storage if proper security protocols are not in place. ### Potential for Algorithmic Bias AI algorithms can inadvertently introduce bias into healthcare processes, leading to unequal treatment outcomes. Bias may stem from unrepresentative training data or flawed assumptions during algorithm development. For example, if an AI system is trained on data predominantly from one demographic group, its recommendations may be less accurate for other populations. ## 5 Best Practices for Integrating AI in Healthcare While Maintaining HIPAA Compliance Healthcare organizations should consider the following best practices to ensure compliance with HIPAA when using AI. ### 1. Implement Robust Data Encryption Methods Encryption protects data such as PHI at rest and in transit, preventing unauthorized access and breaches. Healthcare organizations must adopt encryption technologies, making them integral to AI systems to uphold the confidentiality and integrity of patient information. Integrating encryption requires an understanding of the latest technologies and compliance standards. This includes selecting strong encryption algorithms and implementing effective key management practices. Ensuring data encryption is ingrained in the AI workflow protects sensitive information. ### 2. Train Staff on AI Systems and HIPAA Requirements Training staff on AI systems and HIPAA requirements is crucial for maintaining compliance and operational integrity. Education ensures personnel understand the intricacies of AI technologies alongside the regulatory obligations of handling PHI. Regular training helps staff to responsibly engage with AI systems, augmenting security measures, and protecting patient data. Effective training programs focus on practical skills and regulatory understanding, adapting to emerging technologies and compliance updates. Training improves awareness, enabling staff to implement best practices for data protection and risk management within AI contexts. ### 3. Establish Clear Data Governance Policies Establishing clear data governance policies helps integrate AI into healthcare settings while maintaining HIPAA compliance. Governance frameworks guide how data is used, accessed, and managed, ensuring adherence to regulations and organizational standards. Strong policies establish accountability and transparency, essential for handling sensitive healthcare data. Governance policies should outline data access permissions, usage parameters, and audit protocols to ensure compliant AI interactions. They ensure that all data transactions are meticulously recorded and monitored, enabling compliance with HIPAA standards. ### 4. Regularly Update and Monitor AI Systems Regularly updating and monitoring AI systems are critical to maintaining HIPAA compliance in the ever-evolving technological landscape. Routine updates address security vulnerabilities, ensuring protection against threats to PHI. Continuous monitoring allows organizations to detect anomalies or breaches promptly, reinforcing the security of AI applications in healthcare settings. Updates involve installing patches, improving system functionalities, and adapting to new regulatory requirements. Monitoring systems through real-time analytics and alerts helps in timely detection of non-compliant activities. This proactive approach ensures that AI tools remain secure and effective in handling patient data in alignment with HIPAA standards. ### 5. Engage in Continuous Compliance Auditing Engaging in continuous compliance auditing ensures that AI applications in healthcare consistently adhere to HIPAA standards. Audits evaluate the efficacy of security measures and regulatory conformance, identifying areas needing improvement. This vigilance helps sustain data privacy and integrity, allowing AI technologies to operate safely in healthcare environments. Auditing involves scrutinizing data handling processes, security protocols, and system interactions to detect non-compliance. Regular audits foster a culture of accountability, ensuring all aspects of AI system operations meet HIPAA’s requirements. ***Related content: Read our guide to***[***HIPAA security rule***](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/) ## **HIPAA-Compliant Hosting with Atlantic.net** Many organizations work with third parties on their data systems, particularly if they are in rigorously controlled sectors such as healthcare. Contracting with outside organizations is not simply a way to push away off-focus work; it is also a way to tap expertise that is not present in-house. When you need a healthcare website, work with organizations that are HIPAA and HITECH certified, as well as SOC 2 and SOC 3 audited, so that they are prepared to meet their obligations to the Department of Health and Human Services. See our [HIPAA-compliant web hosting solutions](https://www.atlantic.net/hipaa-compliant-hosting/). --- # Atlantic.Net Honored as a Winner in the 2025 Artificial Intelligence Excellence Awards > URL: https://www.atlantic.net/press-releases/atlantic-net-honored-as-a-winner-in-the-2025-artificial-intelligence-excellence-awards/ | Published: 2025-04-04 | Updated: 2026-03-02 | Author: Alexander Wise Orlando, Fla.—April 4, 2025—Atlantic.Net is proud to announce that it has been named a winner in the [2025 Artificial Intelligence Excellence Awards](https://www.bintelligence.com/awards/artificial-intelligence-excellence-awards), presented by the Business Intelligence Group. This prestigious recognition highlights the company’s commitment to innovation and its contributions to advancing artificial intelligence. Atlantic.Net, a premier provider of innovative and reliable cloud services and hosting solutions, is one of the companies leading the push into GPU-powered server hosting to support artificial intelligence applications. Atlantic.Net’s award-winning Cloud Hosting and Storage Solutions have been recognized in the “Internet and Technology, Medium 101-900 Employees” category for its groundbreaking advancements in AI, which have demonstrated significant impact in GPU cloud hosting. “We are incredibly honored to receive this recognition from the Business Intelligence Group,” said Marty Puranik, CEO of Atlantic.Net. “This award is a testament to the dedication of our team and our mission to push the boundaries of AI to create meaningful solutions that improve lives and industries.” The Artificial Intelligence Excellence Awards celebrate the most innovative companies, technologies, and professionals who are leading the way in AI innovation. Winners are selected by a panel of industry experts who evaluate nominees based on their creativity, impact, and measurable success in AI-driven solutions. “The AI industry is evolving rapidly, and it is through the efforts of companies like Atlantic.Net that we see real-world applications driving change,” said Russ Fordyce, CEO of the Business Intelligence Group. “Their work exemplifies the kind of innovation and leadership that is shaping the future of artificial intelligence.” For more information about Atlantic.Net and its award-winning AI solutions, visit [www.atlantic.net](http://www.atlantic.net). **About Business Intelligence Group www.bintelligence.com** The Business Intelligence Group was founded with the mission of recognizing true talent and superior performance in the business world. Unlike other [industry award programs](http://www.bintelligence.com), these programs are judged by business executives having experience and knowledge. The organization’s proprietary and unique scoring system selectively measures performance across multiple business domains and rewards those companies whose achievements stand above those of their peers. Contact Eliana Starbird Chief Nominations Officer Business Intelligence Group +1 909-529-2737 contact@bintelligence.com **About Atlantic.Net** Established in 1994, Atlantic.Net is a privately-owned, global cloud services provider that delivers innovative and reliable hosting solutions. Focusing on security, compliance, and customer support, Atlantic.Net offers a wide range of services, including GPU hosting, an award-winning Cloud Platform, HIPAA-compliant hosting, dedicated hosting, and colocation to a large roster of organizations in a variety of industries. Atlantic.Net provides mission-critical services from eight global data center regions located in the United States, Canada, the United Kingdom, and Asia. For more information, visit Atlantic.Net or connect with us on Facebook, X (Twitter), LinkedIn, and YouTube. Contact Elise Riley, 404-434-1756 elise@myglobalpresence.com ### --- # Continuous Deployment in PCI DSS Environments: Considerations and Best Practices > URL: https://www.atlantic.net/pci-compliant-hosting/continuous-deployment-in-pci-dss-environments-considerations-and-best-practices/ | Published: 2025-04-04 | Updated: 2026-05-05 | Author: Gilad Maayan ## What Is PCI DSS? The Payment Card Industry Data Security Standard (PCI DSS) is a framework established to ensure the secure handling of credit card information. Developed by major credit card companies, it provides a set of security standards aiming to protect cardholder data and mitigate fraud risks.  Compliance with PCI DSS is mandatory for organizations handling card transactions and involves adhering to practices like maintaining secure systems and data protection protocols. Organizations must pass regular audits and assessments to verify compliance with PCI DSS. This process involves reviewing processes, systems, and software employed in handling cardholder data. Non-compliance can result in severe fines and damage to reputation. The standards promote a broad approach to security, requiring vigilant monitoring, and risk management practices. ## What Is Continuous Deployment? [Continuous deployment (CD) automates the delivery of software updates](https://codefresh.io/learn/continuous-delivery/continuous-delivery-vs-continuous-deployment/), enabling rapid releases without manual intervention. By automatically deploying all code changes to production, CD improves the development cycle, ensuring that updates reach users faster. This process is integral to agile methodologies, where changes are pushed through testing stages to achieve integration into production environments. Adopting CD allows organizations to respond quickly to market demands and improve software reliability through faster bug fixes and improvements. Continuous testing within the deployment pipeline helps in catching errors early, ensuring quality control. While CD increases operational efficiency, it requires rigorous testing and monitoring to maintain software stability and security across releases. ## PCI DSS Requirements Relevant for Software Deployment Here are some of the requirements that organizations must adhere to when developing software in a continuous deployment pipeline. ### 1. Develop and Maintain Secure Systems and Software Organizations must ensure their software is free from vulnerabilities, utilizing development methodologies that incorporate security practices. Regular updates and patches are necessary to address emerging threats and mitigate risks, ensuring the safety and integrity of applications. Implementing security assessments during the development process helps identify potential threats early. This involves code reviews, vulnerability scanning, and penetration testing. By integrating security into the software lifecycle, organizations can maintain compliance with PCI DSS and avoid breaches that could expose sensitive data. ### 2 Restrict Access to System Components and Cardholder Data by Business Need-to-Know Restricting access to system components and cardholder data is crucial for compliance, focusing on the principle of least privilege. Only individuals whose roles require them to access sensitive information should be granted permission. This minimizes the risk of unauthorized access and potential data breaches of cardholder information. Implementing role-based access controls helps enforce these restrictions effectively. Regular reviews and audits of access permissions are crucial to maintain this security level. Ensuring that access rights align with current roles and responsibilities prevents privilege creep, contributing to a security posture aligned with PCI DSS requirements. ### 3. Identify Users and Authenticate Access to System Components Identifying users and authenticating access is fundamental in preventing unauthorized data access. PCI DSS mandates that organizations implement authentication mechanisms such as multi-factor authentication (MFA) to verify user identities. Regularly updating authentication methods in line with emerging threats ensures that data access remains secure. User access should be monitored and logged to maintain accountability. This practice enables organizations to track who accesses system components and identify any anomalies indicative of a security breach. By maintaining stringent authentication processes, companies protect critical infrastructure and sensitive data in compliance with PCI DSS. ### 4. Log and Monitor All Access to System Components and Cardholder Data Logging and monitoring access to system components and cardholder data underpins proactive security measures. PCI DSS requires logging of all access and activity to allow for effective monitoring and incident response. This helps in identifying potentially malicious activities and provides the evidence needed in forensic investigations. Automated logging solutions can assist in capturing detailed access information and trigger alerts upon detecting suspicious activities. Continuous monitoring ensures swift identification of breaches, allowing for rapid remediation. This vigilance is crucial to maintaining the security of cardholder data and the trusted operation of systems under PCI DSS standards. ### 5. Test Security of Systems and Networks Regularly Regular security testing of systems and networks is a PCI DSS mandate aimed at identifying vulnerabilities. Through periodic assessments such as vulnerability scanning and penetration testing, organizations can uncover weaknesses before they are exploited by attackers. These tests simulate real-world attacks, providing insights into potential security gaps. By continuously updating security measures based on test findings, organizations improve their defense mechanisms. Scheduling frequent tests ensures responsiveness to evolving threats, enabling organizations to uphold PCI DSS compliance and protect sensitive data. ### 6. Support Information Security with Organizational Policies and Programs Establishing programs that define security protocols and responsibilities underscores a proactive security culture. Policies should address key areas such as data protection, access control, and incident response. Continuous training and awareness programs reinforce these policies by educating employees on security best practices. This ensures everyone understands their role in protecting sensitive data. By aligning policies with PCI DSS standards, organizations create a secure environment that anticipates and mitigates security challenges effectively. ## Challenges of Implementing CD in PCI DSS Environments Ensuring PCI DSS compliance can be challenging when using continuous deployment practices Here are some of the main issues that may arise. ### 1. Balancing Rapid Deployment with Stringent Security Controls Continuous deployment requires agility, often pushing updates frequently. However, PCI DSS necessitates rigorous security measures that can sometimes slow deployment. The challenge is in maintaining this balance without compromising security or the advantages of fast deployments. ### 2. Ensuring Continuous Compliance Amidst Frequent Changes Frequent software updates inherent in CD can strain compliance efforts. Each change has the potential to introduce non-compliance risks if not managed properly. Maintaining consistent documentation and change control processes is crucial for ensuring continuous compliance within PCI DSS frameworks during rapid development cycles. ### 3. Managing Access Controls and Authentication in Automated Pipelines In automated pipelines, managing access controls and authentication becomes complex. Securing the pipeline is essential to prevent unauthorized deployment changes, which could compromise security. PCI DSS compliance requires stringent access management, posing a challenge when combined with the automation ethos of CD. ## 5 Best Practices for Continuous Deployment in PCI DSS Environments [QG1] Here are some of the ways that organizations can overcome these challenges and ensure [compliance with the PCS DSS](https://www.atlantic.net/pci-compliant-hosting/17-step-pci-compliance-checklist-common-pitfalls-and-solutions/) when implementing continuous deployment. ### 1. Integrating Security Into the CI/CD Pipeline To ensure PCI DSS compliance in continuous deployment, security must be tightly integrated into the CI/CD pipeline. This means shifting security left—embedding checks as early as possible in the development cycle. Automated tools like static application security testing (SAST) and software composition analysis (SCA) should scan code and third-party libraries for vulnerabilities at build time. Dynamic application security testing (DAST) can be added later in the pipeline to detect runtime issues before production deployment. Security gates should be enforced at each stage of the pipeline. For example, if a SAST scan detects critical issues, the pipeline should automatically block the deployment. Additionally, container security scanning and IaC policy enforcement (e.g., using tools like Checkov or OPA) should validate configuration and deployment scripts. ### 2. Maintaining Compliance Documentation Continuous deployment can generate a high volume of changes, making manual documentation impractical. However, PCI DSS requires organizations to maintain detailed records of system changes, access control updates, and security validations. To meet this requirement in a CD environment, documentation must be automated and integrated into the deployment process. CI/CD platforms should automatically log deployment metadata, including code versions, approvers, timestamps, and related test results. These logs can feed into centralized systems that maintain audit trails, enabling PCI audits. Change management tools and ticketing systems (like Jira integrated with the pipeline) can help associate deployments with documented change requests, approvals, and validations, ensuring traceability across frequent releases. ### 3. Access Control and Segregation of Duties In a continuous deployment setup, automated systems often push code to production, raising concerns around access control and separation of duties—both key PCI DSS requirements. To comply, organizations must ensure that no single individual can develop, approve, and deploy changes without oversight. This can be enforced through CI/CD tooling by configuring pipeline stages to require multi-party approval for production deployments. Role-based access control (RBAC) must be applied to limit who can modify pipeline configurations, approve pull requests, or deploy artifacts. Secrets management systems should be used to ensure that credentials used by the pipeline are securely stored and rotated. Clearly separating duties across development, QA, and operations functions helps minimize risk and maintain compliance. ### 4. Continuous Monitoring and Incident Response Continuous deployment increases the need for real-time visibility into what’s being deployed and how it behaves in production. PCI DSS mandates that organizations log and monitor system access and activity. In a CD environment, this extends to monitoring the deployment pipeline, build artifacts, and infrastructure changes. Automated logging of all deployment activities should be enabled and routed to a centralized log aggregation or SIEM system. Monitoring tools should track unexpected changes, failed deployments, and unusual access patterns within the pipeline. Alerts from these systems must trigger predefined incident response workflows. For example, if a deployment includes a critical misconfiguration or bypasses a security gate, it should automatically notify the security team and halt the process. Testing the incident response plan regularly, especially in response to deployment-related threats, ensures the organization is prepared to act quickly. ### 5. Regular Training and Awareness With frequent releases and automation, mistakes in the continuous deployment process can easily introduce non-compliant or insecure changes. To prevent this, all team members involved in the CI/CD workflow need targeted, ongoing training on secure development practices and PCI DSS requirements. Training should focus on secure coding, proper use of secrets, configuration management, and interpreting the results of automated security tools. Developers should understand how insecure code can propagate quickly in a CD pipeline, while DevOps teams need awareness of access control and system hardening practices. Regular refreshers, hands-on workshops, and post-mortems of past security incidents can reinforce awareness. Aligning training content with actual CD practices ensures it remains practical and directly applicable. --- # Decoding Intelligence: AI Training vs AI Inference vs AI Reasoning > URL: https://www.atlantic.net/gpu-server-hosting/decoding-intelligence-ai-training-vs-ai-inference-vs-ai-reasoning/ | Published: 2025-04-07 | Updated: 2025-04-08 | Author: Richard Bailey Artificial intelligence (AI) focuses on creating computer systems that are capable of performing tasks that typically require human-like intelligence. Tasks may include perception, language understanding, data analysis, and decision-making. AI draws from a diverse set of disciplines like computer science, data quality analytics, and neuroscience to develop applications that can reason, learn, and act autonomously to achieve specific goals. AI often involves technologies rooted in machine learning and deep learning. Ranging from predictive modeling to natural language processing, the ultimate goal is to equip machines with training AI models with reasoning capabilities that can act similarly to those of the human brain, such as solving complex problems or making informed decisions through training and inference. Key concepts explored in this article include AI Training, AI Inference, and AI Reasoning, along with their roles in the AI Lifecycle Model’s ability to learn and process data. ## Understanding Core AI Concepts First, let’s examine how the core AI concepts of Machine Learning, Deep Learning, and Neural Networks enable AI systems to learn from data **(training)**, apply that knowledge to new situations **(inference)**, and develop capabilities for logical reasoning. ### Machine Learning Machine learning is a crucial subset of artificial intelligence where systems learn from data without explicit programming. Models use algorithms and statistical models to enable machine learning computers to identify patterns in large datasets and make predictions or recommendations. Having this capability allows AI systems to adapt and improve performance over time when exposed to more data. The core of machine learning lies in its ability to analyze data, figure out underlying patterns, and create new patterns to forecast future predictions or classify new information. ### Deep Learning Building upon machine learning, deep learning is a specialized field that uses artificial neural networks with multiple layers to analyze complex data, including unstructured data like images and text. These neural networks enable deep learning models to learn intricate features from data using a hierarchical process. Deep learning often [requires less human intervention](https://mindthegraph.com/blog/what-is-deep-learning/) compared to traditional machine learning and has achieved remarkable success in tasks such as image recognition, speech recognition, and natural language processing. ### Neural Networks Neural networks are key building blocks for deep learning and many AI methods. Think of them as computer systems inspired by the human brain. They’re made of many simple, connected units (called ‘neurons’ or ‘nodes’) that are arranged in layers. Information flows through these layers: starting at an ‘input layer’, passing through one or more ‘hidden layers’ for processing, and ending at an ‘output layer’ which gives the result. Each connection between neurons has an associated weight that determines the strength of the signal being passed. During the learning process, these weights are adjusted to improve the network’s ability to map inputs to desired outputs. The architecture and data systems of neural networks, with their interconnected layers and adjustable weights, allow AI systems to learn complex relationships within data, essentially by creating a huge map of the data outcomes. ## AI Training: Building the Intelligent Engine AI training is the foundational process of *teaching an AI model to learn from data,* which involves presenting large, curated data sets to the model so it can learn about a specific topic. The training data acts as the *input*that the AI model analyzes to identify patterns and relationships relevant to the task it is being trained for. For example, to [train an AI model for image recognition](https://www.appliedaicourse.com/blog/supervised-learning/) of cats and dogs, a vast dataset of labeled images of cats and dogs would be used. The goal of AI training is to enable the AI model to accurately recognize patterns in the training data and generalize this knowledge to new, unseen data. The training process is iterative, involving feeding the training data to the AI model, evaluating its performance, and adjusting its internal parameters to minimize errors and improve accuracy. During the training phase, the AI model learns by adjusting its internal parameters, such as the weights in a neural network, based on the input data. For deep learning training, this adjustment is often achieved through a process called backpropagation, where the error between the model’s predictions and the actual values is propagated back through the network to update the weights. To get technical for a minute, the choice of optimization algorithms, such as Stochastic Gradient Descent (SGD) or Adam, plays a crucial role in how these [internal parameters are updated](https://massedcompute.com/faq-answers/?question=What%20are%20the%20key%20differences%20between%20Adam%20and%20SGD%20optimizers%20in%20large%20language%20model%20training?). The training process continues over multiple epochs (periods of time), where each epoch represents one complete pass through the entire training data. The number of epochs and the size of the data batches used in each iteration are important [hyperparameters](https://www.ibm.com/think/topics/hyperparameter-tuning) that can affect the model’s performance. The computational demands of deep learning training are significant, often requiring specialized hardware for efficient processing. Graphics processing units (GPUs) have become essential for accelerating deep learning training due to their parallel processing capabilities, which are well-suited for the matrix operations needed to train neural networks. Application-specific integrated circuits (ASICs), such as Google’s Tensor Processing Units (TPUs), offer even greater performance and efficiency for specific AI workloads, including both deep learning training and AI inference. These specialized hardware accelerators significantly reduce the time required for the computationally intensive training process. The quality of the training data is vital for the success of AI model training. High-quality data that is accurate, consistent, and representative of real-world scenarios is crucial for training robust and reliable AI models. Issues such as bias, missing values, and inconsistencies in the training data can lead to poor model performance and inaccurate predictions. Therefore, significant effort is often dedicated to data collection, cleaning, preprocessing, and augmentation to ensure the training data is suitable for the task. ## AI Inference: Applying Learned Knowledge AI inference is the process where a *trained AI model applies its learned knowledge to make predictions or draw conclusions* from new data. This occurs after the training phase, when the AI model is deployed to make predictions on unseen data based on the patterns it learned during training. During inference, the trained neural network uses its established weights and biases to process the new data and generate an output, such as classifying an image, translating text, or predicting a future value. Unlike training, inference typically requires fewer computational resources as the model’s parameters are already fixed, allowing it to conclude more efficiently. There are two main types of AI inference: batch inference and dynamic inference. - **Batch Inference**: Involves processing a large volume of data offline to generate AI predictions. This approach is suitable for tasks where immediate results are not required, such as generating daily reports or updating dashboards. - **Dynamic Inference:** provides AI predictions on demand with low latency. This is crucial for applications like self-driving cars and facial recognition that require immediate decision-making based on streaming data. The hardware used for AI inference can vary depending on the application requirements. While GPUs can accelerate inference, especially for large and complex models, central processing units (CPUs) are often sufficient for smaller models or inference on edge devices where power efficiency is important. AI inference is fundamental to a wide range of AI applications. In self-driving cars, inference is used to interpret sensor data in real-time for navigation and safety. Facial recognition systems rely on inference to identify individuals from images or videos. Other applications include: - Speech recognition - Image recognition - Object detection - Natural language processing - Medical diagnosis - Fraud detection in financial transactions - Personalized recommendations in retail AI inference enables trained models to bring intelligence to various real-world scenarios, driving automation and improving decision-making. ## AI Reasoning: The Art of Logical Deduction AI reasoning is the process by which artificial intelligence systems use logical rules and principles to draw conclusions and derive new information from existing data. It involves analyzing information, identifying patterns, and applying logical rules to solve complex problems and make informed decisions. The goal of AI reasoning is to mimic human intelligence by enabling machines to think critically, understand context, and generate new knowledge. Unlike AI inference, which primarily focuses on applying learned patterns to new data, AI reasoning involves a more deliberate and logical process of deduction and problem-solving. *Reasoning systems* use a knowledge base that contains structured information and an inference engine that applies logical techniques like deduction, induction, and abduction to generate conclusions. - *Deductive reasoning* involves deriving specific conclusions from general rules, while inductive reasoning involves making generalizations from specific observations. - *Abductive reasoning* focuses on finding the most plausible explanation for a set of observations, even with incomplete data. While AI reasoning strives to emulate human reasoning, there are key differences. Human reasoning often incorporates emotions, common sense, and a broad understanding of the world, whereas AI reasoning typically operates within the confines of its programmed knowledge. AI reasoning is crucial for applications requiring complex decision-making and problem-solving. Expert systems, for example, use reasoning to provide advice and solutions in specific domains like medical diagnosis. In natural language processing, reasoning helps AI systems understand the meaning and context of text. Robotic learning, such as in self-driving cars, utilizes reasoning to interpret complex environments and plan actions. The main components of artificial intelligence, including learning, reasoning, problem-solving, perception, and language understanding, all contribute to the overall goal of creating machines with intelligent capabilities. ## The AI Model Lifecycle **Problem Definition > Data Collection & Prep > Model Training > Evaluation > Deployment > Monitoring & Maintenance** Creating and using an AI model is a step-by-step process, like building and maintaining any important tool. This journey, often called the AI model lifecycle, starts with defining the problem the AI needs to solve. Then, we gather and prepare the right information (data) for the AI to learn from. The next big step is ‘training’ the AI, which is like sending it to school to learn patterns from the data – this takes time and significant computer power. After training, we test (evaluate) the AI to see how well it learned. Once it passes the tests, the AI is ready to be put to work (deploy AI models). This is where ‘inference’ happens – the AI uses what it learned to make predictions or decisions on new, real-world data. But the journey doesn’t end there. We constantly need to watch (monitor) the AI to make sure it’s still performing well and update it as needed. Getting AI ready for the real world has its hurdles. If the original learning data wasn’t good quality or was biased, the AI might make poor decisions. Ensuring the AI is accurate and reliable is essential. Sometimes, complex AI needs a lot of computing power, making it tricky to use. Careful checks and ongoing maintenance are vital to keep the AI helpful and trustworthy over time. ## Real-World Applications of AI Inference AI inference is the engine driving numerous real-world applications across various industries. - *In healthcare*, AI inference plays a vital role in medical diagnosis by analyzing medical imaging data to detect diseases. It also assists in drug discovery by analyzing large datasets to identify potential drug candidates. - *In the finance industry,* AI inference is crucial for fraud detection by identifying unusual patterns in financial transactions. - *In manufacturing*, AI inference enhances quality control by enabling automated visual inspection on production lines. - *Retail*benefits from AI inference through personalized recommendations and optimized customer interactions. Other applications include speech recognition, facial recognition, object detection, and natural language processing, which are integrated into various technologies we use daily. The widespread AI adoption driven by AI inference is transforming how businesses operate and interact with customers, leading to increased efficiency and innovation. ## Powering Artificial Intelligence with Deep Learning Training and GPU-Accelerated Dynamic Inference AI training, AI inference, and AI reasoning are the fundamental building blocks of intelligent systems. AI training equips models with the ability to recognize patterns from data. AI inference allows these trained models to apply their knowledge to new data for AI predictions and decision-making. AI reasoning enables AI systems to go beyond pattern recognition by using logical rules to solve complex problems and derive new knowledge. Together, these three processes form the core of how artificial intelligence learns, acts, and understands the world. The ongoing advancements in these areas continue to expand the possibilities of AI applications, promising to address increasingly complex tasks and drive innovation across all aspects of society. However, unleashing the full power of these processes, especially the computationally demanding nature of deep learning training and the low-latency requirements of many inference applications, requires significant hardware capabilities. The parallel processing power of Graphics Processing Units (GPUs) has become essential. This is where infrastructure solutions like [Atlantic.Net Managed GPU Hosting](https://www.atlantic.net/gpu-server-hosting/), powered by NVIDIA, provide a critical advantage. By offering scalable, on-demand access to high-performance NVIDIA GPUs within a fully managed environment, Atlantic.Net eliminates the complexity and overhead of managing specialized hardware. Our technology can help you: - Drastically reduce AI model training times, accelerating the development lifecycle. - Efficiently run demanding AI inference workloads, enabling real-time applications. - Focus resources on innovation and AI development rather than infrastructure maintenance. Want to learn more? [Reach out to our team](https://www.atlantic.net/about-us/corporate-contact/) to discover how Atlantic.Net GPU Hosting can help your business. --- # AI vs Agentic AI > URL: https://www.atlantic.net/gpu-server-hosting/ai-vs-agentic-ai/ | Published: 2025-04-08 | Updated: 2026-02-28 | Author: Richard Bailey Artificial intelligence (AI) is quickly integrating into our economy and workflows, and it’s starting to impact and transform numerous aspects of our lives, from virtual assistants to self-driving cars. However, within the broader field of AI, there are distinct subcategories, each with its own capabilities and limitations. This article will uncover the key differences between traditional AI, often represented by everyday generative AI tools, and the emerging field of agentic AI, particularly focusing on agentic AI vs generative AI. ## Artificial Intelligence: The Foundation Artificial intelligence, at its core, refers to the development of computer systems capable of performing repetitive tasks that typically require some level of human reasoning or intelligence. These tasks include learning, problem-solving, decision-making, and natural language understanding. This encompasses a wide range of techniques and approaches, all aimed at creating different systems that can mimic or even surpass human cognitive abilities in specific domains. ### Traditional AI and Its Subsets Traditional AI models typically include a specific range of techniques related to various AI applications, including predefined rules, most of which you are probably already aware of: - **Machine learning:** A subset of AI that enables systems to learn from data without explicit programming. Machine learning models identify patterns and make predictions or decisions based on the data they are trained on. This allows AI systems to improve their performance over time as they are exposed to more data. Various algorithms and techniques fall under machine learning, such as supervised learning, unsupervised learning, and reinforcement learning. - **Natural language processing (NLP):** Focuses on enabling computers to understand, interpret, and generate human-style language. NLP is crucial for applications like machine translation, sentiment analysis, and chatbots. It involves techniques like text analysis, speech recognition, and natural language generation. - **Computer vision:** Allows computers to “see” and interpret visual information from the world. This field involves techniques like image recognition, object detection, and image processing, enabling applications like facial recognition, autonomous navigation, and medical data and image analysis. Traditional AI has evolved through several stages. Early systems relied heavily on traditional programming, where human experts would define explicit rules for the AI to follow. While effective in well-defined tasks, these systems can struggle to adapt to new or unexpected situations. Machine learning marked a significant advancement, allowing AI systems to learn from data without the need for hand-coded rules. ### Generative AI: Creating New Content Generative AI is a subset of AI that focuses on creating new content, including complex text, images, and audio, that is similar to what humans can produce. Large language models (LLMs) are a key component of many generative AI systems. This branch of AI has opened up new possibilities in art, entertainment, and various creative industries. ## Generative AI: A Closer Look Generative AI has gained significant attention in recent years due to its ability to produce impressive results. Such models generate highly realistic and creative content, often blurring the lines between human and machine-generated outputs. The rapid progress in this field has been fueled by advancements in deep learning and the availability of vast amounts of digital data. ### Large Language Models and Generative AI Large language models (LLMs) are a type of AI model trained on vast amounts of text data. These models can generate coherent and contextually relevant text, making them suitable for various applications. Popular examples include: - **ChatGPT:** Can generate human-like text for conversations, answer questions, and create different creative text formats. ChatGPT has demonstrated remarkable abilities to perform specific tasks such as writing essays, composing poems, and even generating computer code. - **DALL-E 2 and Midjourney:** Can create images from textual descriptions. These models can produce a wide range of artistic styles and have been used to create stunning visual content. ### How Generative AI Works Generative AI models, particularly LLMs, work by learning the underlying statistical patterns in the training data. They use techniques like deep learning to recognize patterns and build complex representations of language and other forms of provided data. When prompted with an input, the model uses its learned knowledge to generate a new output that is consistent with the training data. ### Applications of Generative AI Generative AI is hugely popular. It’s hard to believe that its only been in the public domain for a few years but its usage, development, and the major investments Generative AI has attracted demonstrate that it is here to stay. Some of the exciting applications that Generative AI can do include: - **Content creation:** Generating articles, blog posts, and marketing copy. This can automate content creation processes and free up human writers to focus on more strategic tasks. - **Image and video generation:** Creating artwork, product visualizations, and special effects. This has helped the creative industries by enabling the creation of unique and visually appealing content. - **Code generation:** Assisting developers in writing code. This can improve developer productivity and accelerate the software development process. - **Data augmentation:** Creating synthetic data to improve the performance of other AI models. This is particularly useful when dealing with limited or imbalanced datasets. - **Drug discovery:** Generative AI can be used to design new molecules with desired properties, potentially accelerating the development of new drugs and therapies. - **Personalized medicine:** These models can help tailor treatments to individual patients based on their genetic makeup and other factors. ### Limitations of Generative AI Despite its capabilities, generative AI has several limitations: - **Lack of true understanding:** Generative AI models primarily focus on statistical relationships in data and may not possess a genuine understanding of the content they generate. This can lead to outputs that are grammatically correct but conceptually lacking. - **Bias and misinformation:** Models can perpetuate biases present in the training data and may generate inaccurate or misleading information. This is a [significant concern](https://www.theguardian.com/technology/2025/jan/28/we-tried-out-deepseek-it-works-well-until-we-asked-it-about-tiananmen-square-and-taiwan), especially in applications where accuracy and reliability are critical. - **Requires constant human input**: Generative AI needs prompts and instructions to guide its output. The quality of the output is highly dependent on the quality of the input prompt. - **Computational cost:** Training and running large generative AI models can be computationally expensive, requiring significant resources. ## What Is Agentic AI? Agentic AI is a cutting-edge field that focuses on developing AI systems capable of autonomous action to achieve specific goals. Unlike traditional AI, which often requires significant human intervention, Agentic AI systems perceive their environment, make decisions, and take actions independently. ### Key Characteristics of Agentic AI - **Autonomy**: Agentic AI systems possess the ability to operate independently, with minimal human input, allowing them to pursue objectives and execute tasks without continuous guidance. - **Goal-Oriented Behavior**: These systems are designed to work towards specific, predefined goals, enabling them to proactively take steps to achieve desired outcomes. - **Adaptability**: Agentic AI agents can adapt to changes in their environment, learning from experiences and adjusting their behavior. - **Interactivity**: These agents interact with their environment, gathering information and responding to real-time events to make informed decisions. - **Decision-Making**: Agentic AI systems are equipped to make choices based on their understanding of the environment and their defined goals, allowing them to navigate certain complexities . - **Problem-Solving**: Agents can decompose complex problems into smaller, more manageable steps, using reasoning and planning to identify effective solutions. ### AI Agents At the core of Agentic AI are autonomous agents, known as AI agents. AI agents operate as an entity that perceives its environment, makes decisions, and takes actions to achieve specific goals. These agents act independently and are designed to be autonomous and goal-oriented, capable of interacting with their surroundings to achieve their objectives. ### Key Features of Agentic AI Explained Agentic AI distinguishes itself from other forms of AI, including generative AI, through several key characteristics focused on autonomous action and goal achievement: 1. **Autonomy:** Agentic AI systems exhibit a high degree of autonomy, meaning they can operate independently with minimal human input. Unlike systems that primarily react to prompts, agentic systems can make decisions and take actions without constant guidance or intervention to pursue their objectives. 2. **Goal-Oriented Behavior:** These systems are explicitly designed to pursue specific, predefined goals. They don’t just respond to stimuli; they actively develop plans and strategies to work towards a defined objective, focusing on effective action and goal attainment. 3. **Interactivity with the Environment:** A defining feature is their ability to interact directly with their environment (digital or physical). They perceive their surroundings, gather real-time feedback, and adapt their behavior accordingly, allowing them to operate effectively even in dynamic and unpredictable conditions. 4. **Proactive Decision-Making:** Agentic AI systems make autonomous decisions based on their perception of the environment and their programmed goals. They evaluate different options and proactively choose the course of action most likely to lead to successful goal achievement, rather than simply reacting to direct commands. 5. **Complex Problem-Solving & Task Handling:** These systems are built to tackle complex, multi-step tasks. They can break down large problems into smaller, manageable steps, employing techniques like planning and reasoning to find solutions and navigate intricate scenarios effectively. 6. **Adaptability & Learning:** Agentic AI learns from its experiences and adapts to changes in its environment. This capability allows for performance improvement over time, leading to greater efficiency and effectiveness in achieving goals. 7. **Proactivity:** Unlike purely reactive systems (like many generative models that wait for a prompt), agentic AI can take initiative. It acts proactively to make progress towards its goals based on its internal state and environmental perception. ### Summary Comparison: Generative AI vs. Agentic AI Here is the table summarizing the core differences based on these features: | Feature | Generative AI | Agentic AI | | --- | --- | --- | | **Goal** | Content creation | Goal achievement | | **Autonomy** | Limited | High | | **Interaction** | Primarily with data | With the environment | | **Task Complexity** | Specific, content-focused tasks | Handle complex tasks | | **Decision-Making** | Reactive, based on prompts | Proactive, autonomous | | **Key Focus** | Output quality and creativity | Effective action & goal attainment | ### How Agentic AI Operates Agentic AI operates through a continuous cycle of: 1. **Perception:** Gathering information from the environment through sensors or data inputs. This involves using sensors or other means to collect data about the current state of the environment. 2. **Reasoning:** Processing the information and making decisions based on predefined goals and learned knowledge. This involves using logic, planning, and other techniques to analyze the perceived information and determine the best course of action. 3. **Action:** Executing actions in the environment to achieve the desired outcome. This involves interacting with the environment to change its state and move closer to the desired goal. 4. **Learning:** Updating its knowledge and improving its decision-making process based on the outcomes of its actions. This involves using feedback from the environment to learn from past experiences and improve future performance. This cycle continues iteratively, allowing the agent to continuously interact with its environment, learn from its experiences, and refine its behavior over time. ### Examples of Agentic AI Now you know how Agentic AI works, I bet you can think of some real-world examples. - **Self-driving cars:** One of the most obvious use cases is self-driving cars. Modern self-driving cars use Agentic AI to perceive their surroundings, make driving decisions, and navigate roads autonomously by using a variety of sensors, including cameras, radar, and lidar, to perceive the environment and make decisions in real-time. - **Robotics**: Robots equipped with Agentic AI can perform complex tasks in manufacturing, logistics, and healthcare environments. Robots can adapt to changing conditions and perform tasks with a high degree of autonomy. - **Personal assistants:** Advanced AI assistants can learn user preferences, anticipate needs, and proactively take actions to assist users. These assistants can go beyond simple tasks like setting reminders and answering questions to perform more complex actions like booking travel or managing finances. - **Healthcare:** Agentic AI can assist doctors in diagnosing diseases, developing treatment plans, and monitoring patients, potentially improving the quality and efficiency of healthcare. ## Agentic AI vs. Generative AI: Key Differences While both agentic AI and generative AI represent advancements in the field, they serve different purposes and possess distinct characteristics. Here’s a breakdown of the key differences, highlighting the paradigm shift from traditional methods to advanced AI technique : ### Goal Orientation - **Generative AI:** Focuses on creating new content, such as text, images, or audio. Its primary goal is to generate outputs that are similar to human-created content. The emphasis is on the quality and creativity of the generated output. - **Agentic AI:** Focuses on achieving specific goals through autonomous actions. Its primary goal is to perceive, reason, and act in an environment to reach a desired outcome. The emphasis is on the agent’s ability to achieve its objectives through its own actions. ### Autonomous Systems - **Generative AI:** Typically operates in a reactive manner, generating outputs based on specific prompts or inputs. It has limited autonomy and does not make independent decisions. The user provides the input, and the model generates an output based on that input. - **Agentic AI:** Operates autonomously, making decisions and taking actions without constant human agent input. It can adapt to changing environments and pursue goals with minimal human intervention. The agent has the ability to act on its own, without requiring continuous input from a user. ### Interaction with the Environment - **Generative AI:** Primarily interacts with data to learn patterns and generate new content. It does not actively interact with the real-world environment. The interaction is limited to the data that the model is trained on. - **Agentic AI:** Interacts with its environment, perceiving information and taking actions to achieve its goals. It can adapt its behavior based on real-time feedback from the environment. The agent is constantly interacting with its surroundings, gathering information, and taking actions that affect the environment. ### Complexity of Tasks - **Generative AI:** Excels at generating content for specific tasks, such as writing articles or creating images. These tasks are typically well-defined and focused on a specific output. - **Agentic AI:** Designed to handle more complex tasks that require planning, decision-making, and interaction with the environment. It can perform multi step tasks and solve complex problems. These tasks often involve multiple steps and require the agent to adapt to changing circumstances. ## The Role of Large Language Models in Agentic AI Large language models (LLMs) play a crucial role in the development of agentic AI. Their ability to understand and generate natural language enables AI agents to: - **Interpret user instructions:** LLMs can process and understand complex instructions given by users in natural language, allowing users to communicate with AI agents in a more natural and intuitive way. - **Reason about goals:** LLMs can help agents reason about their goals and develop plans to achieve them. LLMs use their knowledge of language and the world to understand the implications of different actions and choose the best course of action. - **Communicate with other agents:** LLMs can facilitate communication and collaboration between multiple AI agents. This enables the development of complex systems where multiple agents work together to achieve a common goal. - **Generate human-readable explanations:** LLMs can explain the actions and decisions of AI agents in a way that humans can understand. - **Provide context and knowledge:** LLMs can provide AI agents with access to a vast datasets about the world, enabling them to make more informed decisions. ## The Future Agentic AI Models Agentic AI is driving the future. Imagine AI autonomously pursuing goals, transforming industries through applications like robotic process automation from logistics to healthcare. This shift from reactive tools to proactive partners, capable of making independent decisions, marks a major leap forward. ### Potential Benefits of Agentic AI - **Increased efficiency and productivity:** Agentic artificial intelligence systems automate tasks and optimize processes, leading to significant improvements in efficiency and productivity. This can free up human workers to focus on more creative and strategic tasks. - **New possibilities:** Agentic AI can enable new applications and possibilities that were previously impossible with traditional AI. This can lead to breakthroughs in various fields, from healthcare to space exploration. - **Solving complex problems:** Agentic AI can help address some of the world’s most challenging problems, such as climate change, healthcare, and poverty. By developing intelligent and autonomous systems, we can potentially find solutions to problems that have eluded us for centuries. - **Enhanced decision-making:** Agentic AI systems can process vast amounts of data and make more informed decisions than humans in many situations, leading to improved outcomes in various domains. - **Personalized experiences:** Agentic AI can learn user preferences and tailor experiences to individual needs, leading to more satisfying and effective interactions. ### Challenges and Ethical Considerations The development and deployment of Agentic AI in dynamic environments raises several challenges and ethical considerations: - **Safety and reliability:** Ensuring the safety and reliability of autonomous systems is crucial, especially in critical applications like autonomous driving and healthcare. - **Bias and fairness:** Agentic AI systems can perpetuate biases present in the data they are trained on, leading to unfair or discriminatory outcomes. - **Job displacement:** The automation potential of Agentic AI raises concerns about potential job displacement and the need for workforce adaptation. - **Ethical concerns/decision-making:** Agentic AI systems may need to make ethical decisions in complex situations, requiring careful consideration of moral principles and values. - **Human oversight:** The appropriate level of human oversight in autonomous systems needs to be carefully determined to balance the benefits of autonomy with the need for control and accountability. It is important to find the right balance between autonomy and human control to ensure that these systems are used responsibly. - **Unintended consequences:** As agentic AI systems become more complex and autonomous, there is a risk of unintended consequences that could have negative impacts on society. We need to carefully consider the potential risks and take steps to mitigate them. - **Security risks:** Agentic AI systems could be vulnerable to hacking or other forms of attack, potentially leading to dangerous or harmful outcomes. Robust security measures are essential to protect these systems from malicious actors. To wrap up, it’s clear from the evidence we have presented that there are clear differences between AI and Agentic AI, while generative AI creates based on instruction, agentic AI acts to achieve objectives. This fundamental difference highlights a major leap towards more autonomous, goal-oriented artificial intelligence. The potential impact is transformative, promising unprecedented efficiency and new capabilities, yet it also demands careful consideration of ethics and safety. As we push the boundaries of what AI can *do*, especially in data analysis the computational requirements skyrocket. Building and running sophisticated agentic systems relies heavily on powerful hardware foundations. This is precisely where solutions like [Atlantic.Net GPU hosting platform](https://www.atlantic.net/gpu-server-hosting/) become critical, offering the scalable performance needed to power the development and deployment of these increasingly intelligent and autonomous technologies. --- # Continuous Delivery in Healthcare: Security and Compliance Best Practices > URL: https://www.atlantic.net/hipaa-compliant-hosting/continuous-delivery-in-healthcare-security-and-compliance-best-practices/ | Published: 2025-04-09 | Updated: 2025-04-15 | Author: Gilad Maayan ## What Is Continuous Delivery? Continuous delivery (CD) is a software development approach where teams produce software in short cycles. This methodology automates the software release process, enabling teams to deliver changes to production frequently and with confidence. The goal is to create deployable software increments that can be reliably released at any time, reducing the cost, time, and risk of delivering changes. By emphasizing automation and immediate feedback, [continuous delivery allows teams to focus on business objectives](https://octopus.com/devops/continuous-delivery/) while maintaining code quality. It integrates with CI (continuous integration), which automatically tests code for defects before merging it into a central repository. This ensures that each code change is consistently ready for production. ## The Regulatory Landscape in Healthcare Healthcare software is subject to strict regulatory oversight to ensure patient safety, data integrity, and privacy. In the United States, the Food and Drug Administration (FDA) regulates software that qualifies as a medical device, requiring compliance with frameworks such as 21 CFR Part 820 (Quality System Regulation). Similarly, software that handles patient data must comply with the Health Insurance Portability and Accountability Act (HIPAA), which sets standards for protecting sensitive patient information. In the European Union, developers must navigate the Medical Device Regulation (MDR) and General Data Protection Regulation (GDPR). MDR classifies software based on its intended use and potential risk, imposing different levels of scrutiny. GDPR governs how personal data is collected, stored, and shared, with strict rules around consent and data processing. These regulations often require thorough documentation, traceability of changes, and validated processes. As a result, software teams must adopt development practices that ensure automated delivery pipelines include rigorous checks for safety and regulatory alignment. ## Challenges of Continuous Delivery in Healthcare Here are some of the main potential challenges of implementing continuous delivery in the healthcare industry. ### Balancing Rapid Deployment with Stringent Compliance Requirements Healthcare regulations require rigorous validation, documentation, and approvals before any software can be released. Continuous delivery, however, is built around frequent, automated deployments. This creates a conflict: the speed of CD versus the deliberate pace of regulatory compliance. Many regulatory frameworks require human review, documented verification steps, and formal approval processes that don’t align easily with fully automated pipelines. Changes that might be pushed to production in minutes in other industries must instead go through layers of review. This can create bottlenecks unless the pipeline includes compliance gates and evidence generation. ### Managing Data Privacy and Security During Automated Processes In healthcare, even temporary exposure of sensitive data during build, test, or deployment stages can constitute a serious violation. Continuous delivery pipelines often involve multiple automated steps that move data across systems, run integration tests, and deploy code to staging environments—any of which could become a point of leakage if not tightly controlled. Automated processes might inadvertently store logs containing [protected health information](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) (PHI), or developers might use real patient data in test environments. These risks are amplified in CD systems because they run frequently and touch many components automatically. Ensuring encryption, access controls, data anonymization, and secure storage practices throughout the pipeline is critical but difficult to implement and maintain at CD speed. ### Ensuring Traceability and Auditability of Changes Healthcare regulations require complete traceability of all changes, including who made them, why they were made, what risk they addressed, and how they were validated. Continuous delivery introduces frequent, sometimes daily, code changes, which can make traceability harder to maintain. Automated deployments risk losing the context behind a change unless traceability is explicitly built into the development process. Standard CD tools may not log approvals, test evidence, or links to regulatory requirements without customization. As a result, teams struggle to provide sufficient audit trails for regulators, especially when under time pressure to release updates. ## Best Practices for Continuous Delivery in Healthcare Compliance Here are some of the ways that healthcare organizations can ensure compliance while implementing efficient continuous delivery pipelines. ### 1. Incorporating Compliance Assessments Early in the Development Lifecycle During the planning phase, teams should collaborate with regulatory, quality assurance, and clinical experts to identify applicable standards (e.g., HIPAA, FDA 21 CFR Part 11, MDR). Each feature or user story should be mapped to compliance controls, including traceability requirements, validation needs, and documentation obligations. Risk assessments should be conducted before development begins to determine the classification and potential impact of software changes. This informs what level of testing, documentation, and review is needed. For example, a minor UI update may require limited documentation, while a feature that affects clinical decision-making could require extensive validation. Automated tools should be used to tag code changes with associated requirements, maintain traceability to user stories or defects, and generate documentation artifacts as part of the CI/CD pipeline. This integration of compliance reduces rework and audit risk later in the process. ### 2. Continuous Monitoring and Auditing of Deployed Applications Post-deployment compliance relies on real-time visibility into how the application behaves in production. Monitoring tools should be configured to detect unauthorized access, data leaks, performance degradation, and violations of data residency rules. These tools must support the retention and secure storage of logs that meet regulatory expectations for auditability. Logs should capture granular details such as user identities, timestamps, actions performed, and the data accessed or modified. For example, in a HIPAA-regulated system, it’s essential to record which clinicians accessed patient records, for what purpose, and whether access was appropriate. To support automated compliance auditing, monitoring systems should integrate with deployment pipelines, creating a cohesive record of what was deployed, when, by whom, and with what controls. Alerts and incident management workflows should also be in place to quickly triage and respond to compliance breaches, with a documented post-incident review process. ### 3. Training Development and Operations Teams on Compliance Obligations Technical teams must understand how their work impacts regulatory compliance. This includes not only the rules themselves but also how those rules apply to their daily tasks—such as writing code, configuring infrastructure, managing data, and performing deployments. Training should be role-specific. Developers need to know how to build features that support auditability and data privacy. Operations staff should be trained on secure deployment practices, incident handling, and the importance of preserving data integrity during rollouts or rollbacks. Teams should also learn how to document their work in a way that supports traceability—such as linking pull requests to risk assessments or recording validation test results in an accessible format. Periodic refreshers and compliance updates help keep the knowledge current as regulations evolve. ### 4. Training and Awareness A culture of compliance requires organization-wide understanding, not just technical expertise. Product managers and business leads need to grasp how compliance impacts product design, release timing, and customer communications. [Training](https://www.atlantic.net/hipaa-compliant-hosting/top-10-hipaa-training-companies-in-2020/) should include overviews of key regulations, case studies of compliance failures, and workshops that simulate real-world compliance challenges. Encouraging cross-functional participation in risk assessments and audits also helps teams internalize the importance of compliance. Organizations should also consider maintaining a compliance knowledge base with up-to-date guidelines, FAQs, and process documentation. Making this easily accessible promotes independent learning and ensures consistent application of policies. ### 5. Establishing Clear Policies and Procedures to Guide CD Processes Clear, well-documented policies act as the foundation for compliant continuous delivery. These should define how software changes are proposed, reviewed, tested, approved, deployed, and monitored. Policies must be specific enough to enforce behavior, but flexible enough to accommodate iterative development. Procedures should include gate checks at critical stages of the CD pipeline. For example, no code should be promoted to production without automated test passes, manual approval for high-risk changes, or documented validation artifacts. Each stage should produce traceable records, such as approval signatures, risk justifications, and evidence of testing. Organizations should also formalize how they handle incidents, including predefined response steps, reporting obligations, and review processes. Policies should be regularly reviewed and updated to reflect changes in technology, regulation, or organizational structure. --- # 5 Reasons a WAF Can Help You Meet PCI DSS Requirements > URL: https://www.atlantic.net/pci-compliant-hosting/5-reasons-a-waf-can-help-you-meet-pci-dss-requirements/ | Published: 2025-04-10 | Author: Gilad Maayan ## What Is PCI DSS? PCI DSS, or Payment Card Industry Data Security Standard, is a set of security requirements to ensure the safe handling of credit card information by organizations. It was developed by major credit card companies, including Visa, MasterCard, American Express, Discover, and JCB. These requirements apply to any entity that processes, stores, or transmits cardholder information. Meeting these standards is crucial for organizations to prevent data breaches and protect customer information. Compliance with PCI DSS helps maintain trust and avoid penalties associated with data theft. The PCI DSS framework consists of 12 requirements, which cover aspects like maintaining a secure network, protecting stored cardholder data, implementing strong access control measures, and regularly monitoring and testing networks. Organizations must validate their compliance annually, which involves assessing their processes and systems for vulnerabilities. Failure to comply may result in fines or loss of the ability to process credit card payments. ## What Is a WAF? A [web application firewall (WAF) is an advanced security tool](https://www.radware.com/cyberpedia/application-security/what-is-waf/) that monitors and filters HTTP/HTTPS traffic between a web application and the Internet. It protects web applications from threats such as SQL injection, cross-site scripting (XSS), and other application-layer attacks. By inspecting incoming traffic, a WAF can detect and block malicious requests before they reach the application. WAFs use predetermined security rules to identify and mitigate potential threats. They can be deployed in various configurations, including cloud-based, on-premises, or as part of a hybrid model. These solutions offer customization options to suit business needs, allowing organizations to adapt to evolving threats. In addition to protecting against known vulnerabilities, WAFs can be updated to address new security challenges as they emerge. ## 5 Reasons a WAF Can Help You Meet PCI DSS Requirements ### 1. Protection Against Common Web Application Vulnerabilities A web application firewall guards against common attacks such as SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF). These vulnerabilities are frequently targeted by cybercriminals seeking to exploit weaknesses in web applications. By intercepting and filtering malicious traffic, a WAF helps ensure that these threats do not reach applications. Deploying a WAF helps fulfill PCI DSS’s objective of protecting sensitive customer data, including payment information. As these types of attacks are within the scope of PCI DSS concerns, using a WAF aligns with these compliance requirements by addressing known security flaws. ### 2. Compliance with PCI DSS Requirement 6.6 PCI DSS Requirement 6.6 mandates that organizations either deploy a WAF or conduct regular code reviews to identify vulnerabilities in web applications. A WAF automates security, providing continuous protection without the need for frequent manual intervention. This helps organizations demonstrate their commitment to securing the environment holding sensitive cardholder data. Implementing a WAF relieves organizations from conducting constant code reviews, which can be resource-intensive and time-consuming. The automated nature of WAFs allows for real-time monitoring and threat detection and simplifies the compliance process by providing ongoing protection and adaptability to new threats. ### 3. Real-Time Threat Detection and Response By actively monitoring web traffic, a WAF can detect anomalies and threats as they occur, blocking malicious activities before they impact the application. This proactive approach aligns with PCI DSS’s requirement for maintaining a secure network by enabling quick and effective responses to potential security breaches. Real-time response capabilities mean that threats are identified and mitigated as they happen, minimizing potential damage. This rapid reaction is crucial in a security landscape where threats evolve quickly. ### 4. Enhanced Data Protection and Leakage Prevention WAFs improve data protection by preventing data leakage and unauthorized access to sensitive information. They impose stringent access controls, ensuring only legitimate traffic reaches applications, which is critical for maintaining the confidentiality and integrity of cardholder data. This capability addresses [PCI DSS requirements](https://www.atlantic.net/pci-compliant-hosting/what-is-pci-compliance/) related to data protection. The filtering mechanisms of a WAF enable it to identify and block attempts to exfiltrate sensitive information from systems. This data leakage prevention is a benefit in meeting compliance requirements, as it ensures that sensitive information, particularly cardholder data, is well-protected. ### 5. Simplified Compliance Reporting and Auditing A WAF offers simplified compliance reporting and auditing capabilities, helping organizations maintain detailed records of all security incidents and responses. PCI DSS compliance requires diligent documentation and proof of protective measures. WAFs automatically generate logs and reports, making it easier for organizations to track compliance efforts. The automation features of WAFs reduce the manual burden of compiling security reports and performing audits. With easy access to logs, organizations can quickly produce evidence of compliance for auditors. This enables smoother audit processes and ensures that organizations can efficiently respond to any compliance-related inquiries. ## Best Practices to Implement a WAF Here are some of the ways that organizations can ensure compliance with the PCI DSS using a WAF. ### 1. Select an Appropriate Deployment Mode There are several options for the deployment mode, including network-based, host-based, and cloud-based WAFs. Network-based WAFs are integrated within the network infrastructure, offering protection and high performance. Host-based WAFs are installed on the application server, providing tight integration with the application. Cloud-based options deliver scalability and ease of management without the need for extensive on-premises resources. Each deployment mode presents distinct advantages and limitations. For example, network-based WAFs offer superior performance and are harder to bypass, while cloud-based WAFs provide flexibility and reduced infrastructure costs. When selecting a WAF, consider factors such as application architecture, scalability needs, and available resources. ### 2. Manage and Customize Rules Effectively Default rule sets provide a foundational level of security but may not address all business needs or unique application threats. Customizing these rules allows organizations to tailor their WAF to detect and block threats more accurately, reducing false positives and negatives that could impact user experience or leave vulnerabilities unaddressed. Regular updates and reviews of WAF rule sets are necessary to adapt to evolving threats. This involves assessing the current threat landscape and modifying rules to account for new attack vectors. Organizations should establish processes for continuous rule optimization, including leveraging threat intelligence and conducting vulnerability assessments. ### 3. Implement a Phased Deployment Strategy By gradually introducing the WAF into production environments, organizations can monitor its impact, adjust configurations, and address any issues without major disruptions. A phased approach allows for incremental testing and validation, ensuring that the WAF integrates well with existing infrastructure and security protocols. In a phased deployment, organizations typically start with non-critical applications, assessing the WAF’s performance and fine-tuning settings as needed. Scaling up to more critical components incrementally reduces the potential for disruptions and enables smoother adoption. This strategy also helps to identify and resolve any compatibility issues or configuration challenges early on. ### 4. Monitor and Maintain the WAF Continuously Regularly updating WAF software and rules is necessary to keep it current with the latest security developments. Without ongoing attention, the effectiveness of a WAF can degrade over time, leaving applications vulnerable to new attack vectors and exploits. Proactive monitoring involves analyzing WAF logs and alerts to detect anomalous activities or patterns that may indicate potential threats. Organizations should establish a comprehensive maintenance schedule that includes software updates, rule reviews, and performance assessments. ### 5. Integrate WAF Management into Organizational Processes Integrating WAF management into organizational processes is essential for maximizing its effectiveness. This involves incorporating WAF monitoring, maintenance, and incident response activities into broader IT and security workflows. By aligning WAF operations with existing procedures, organizations can ensure a cohesive approach to cybersecurity. An integrated WAF management strategy includes training staff on WAF operations, establishing clear communication channels for threat alerts, and documenting response protocols. This alignment improves collaboration among IT and security teams, enabling efficient threat detection and response. --- # How to Deploy TensorBoard on a GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-deploy-tensorboard-on-a-gpu-server/ | Published: 2025-04-11 | Updated: 2025-04-14 | Author: Hitesh Jethva TensorBoard is a visualization tool provided by TensorFlow that monitors and analyzes the training process of machine learning models. It shows loss, accuracy, and other custom values, as well as model graphs, histograms, and embeddings. Deploying TensorBoard on an Ubuntu GPU server lets you use the power of GPUs to visualize and debug your machine learning workflows. In this guide, we’ll go through the steps to deploy TensorBoard on an Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/). ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 24.04 Cloud GPU Server. - CUDA Toolkit and cuDNN Installed. - A root or sudo privileges. ## Step 1: Set Up a Python Virtual Environment 1. Install Python and the required dependencies. ```bash apt install python3-venv python3-pip ``` 2. Create a virtual environment for your project. ```bash python3 -m venv tensor-env ``` 3. Activate the virtual environment. ```bash source tensor-env/bin/activate ``` ## Step 2: Install TensorFlow with GPU Support 1. Install TensorFlow. ```bash pip install tensorflow numpy ``` 2. Log in to the Python shell. ```bash python3 ``` 3. Run the following Python code to ensure TensorFlow uses the GPU. ```bash >>> import tensorflow as tf >>> print("Num GPUs Available: ", len(tf.config.experimental.list_physical_devices('GPU'))) ``` Output. ```bash Num GPUs Available: 1 ``` 4. Press **CTRL+D** to exit from the Python shell. ## Step 3: Install TensorBoard TensorBoard is included with TensorFlow, so no additional installation is required. However, you can ensure it’s available by running: ```bash pip install tensorboard ``` ## Step 4: Launch TensorBoard 1. Create a Python script file, for example, train_model.py. ```bash nano train_model.py ``` Add the following code. ```bash import tensorflow as tf # Define a simple model model = tf.keras.models.Sequential([ tf.keras.layers.Dense(10, activation='relu'), tf.keras.layers.Dense(1, activation='sigmoid') ]) # Compile the model model.compile(optimizer='adam', loss='binary_crossentropy', metrics=['accuracy']) # Generate dummy data for demonstration import numpy as np x_train = np.random.random((1000, 10)) y_train = np.random.randint(2, size=(1000, 1)) # Create a TensorBoard callback tensorboard_callback = tf.keras.callbacks.TensorBoard(log_dir="./logs") # Train the model model.fit(x_train, y_train, epochs=10, callbacks=[tensorboard_callback]) ``` 2. To train the model and generate logs, run the script using Python: ```bash python3 train_model.py ``` The above command will: - Train the model for 10 epochs. - Save the training logs (including loss, accuracy, and other metrics) to the **./logs** directory. 3. Once the training is complete, launch TensorBoard to visualize the logs: ```bash tensorboard --logdir=./logs --bind_all ``` Output. ```bash TensorBoard 2.19.0 at http://ubuntu:6006/ (Press CTRL+C to quit) ``` ## Step 5: Access TensorBoard 1. Open your browser and navigate to **http://your-server-ip:6006.** You should see the TensorBoard dashboard with tabs like Scalars, Graphs, Distributions, Histograms, etc. ![](https://www.atlantic.net/wp-content/uploads/2025/03/p1-3.png) 2. Click on the **Scalars** tab to check for training metrics like loss and accuracy. ![](https://www.atlantic.net/wp-content/uploads/2025/03/p2-2.png) ## Conclusion Deploying TensorBoard on an Ubuntu GPU server lets you visualize and monitor your machine learning workflows. This is great for teams working on machine learning projects or researchers who need to monitor long running training sessions. --- # How to Install Open WebUI on a Cloud GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-install-open-webui-on-a-cloud-gpu-server/ | Published: 2025-04-14 | Author: Hitesh Jethva Open WebUI is a self-hosted, open-source web interface that allows large language models (LLMs) to run easily. It integrates with Ollama and OpenAI-compatible APIs, so you can add custom AI models and plugins. Whether you’re a developer, researcher or AI enthusiast, Open WebUI is a robust platform for managing and interacting with LLMs. In this guide, you’ll learn how to install Open WebUI on an Atlantic.Net Cloud GPU instance to run LLMs. ## Prerequisites Before starting, ensure you have the following: - An Ubuntu 24.04 [Cloud GPU Server](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/) with 8 GB of GPU memory. - CUDA Toolkit and cuDNN Installed. - Git installed: `sudo apt install git` - A root or sudo privileges. ## Step 1: Install Ollama Ollama is a lightweight framework for running open-source LLMs like Llama, Code Llama, Mistral, and Gemma. It provides APIs for creating, managing, and customizing models, making it an essential component for running Open WebUI. Follow these steps to install Ollama and download a sample model. 1. Download the Ollama installation script: ```bash wget https://ollama.ai/install.sh ``` 2. Grant execute permissions to the script: ```bash chmod +x install.sh ``` 3. Run the script to install Ollama: ```bash ./install.sh ``` Output. ```bash >>> Installing ollama to /usr/local >>> Downloading Linux amd64 bundle ############################################################################################################### 100.0% >>> Creating ollama user... >>> Adding ollama user to render group... >>> Adding ollama user to video group... >>> Adding current user to ollama group... >>> Creating ollama systemd service... >>> Enabling and starting ollama service... Created symlink /etc/systemd/system/default.target.wants/ollama.service → /etc/systemd/system/ollama.service. >>> NVIDIA GPU installed. ``` 4. Enable the Ollama service to start at boot: ```bash systemctl enable ollama ``` 5. Start the Ollama service: ```bash systemctl start ollama ``` 6. Verify the Ollama service status: ```bash systemctl status ollama ``` Output. ```bash ● ollama.service - Ollama Service Loaded: loaded (/etc/systemd/system/ollama.service; enabled; preset: enabled) Active: active (running) since Tue 2025-03-18 11:26:38 UTC; 21min ago Main PID: 5783 (ollama) Tasks: 31 (limit: 17886) Memory: 5.0G (peak: 5.0G) CPU: 27.539s CGroup: /system.slice/ollama.service ├─5783 /usr/local/bin/ollama serve └─6864 /usr/local/bin/ollama runner --model /usr/share/ollama/.ollama/models/blobs/sha256-6a0746a1ec1aef3e7ec53868f220ff6e389f6f8ef87a01d77c96807de94ca2aa> Mar 18 11:44:52 ubuntu ollama[5783]: llama_init_from_model: CUDA_Host output buffer size = 2.02 MiB Mar 18 11:44:52 ubuntu ollama[5783]: llama_init_from_model: CUDA0 compute buffer size = 560.00 MiB Mar 18 11:44:52 ubuntu ollama[5783]: llama_init_from_model: CUDA_Host compute buffer size = 24.01 MiB Mar 18 11:44:52 ubuntu ollama[5783]: llama_init_from_model: graph nodes = 1030 Mar 18 11:44:52 ubuntu ollama[5783]: llama_init_from_model: graph splits = 2 Mar 18 11:44:52 ubuntu ollama[5783]: time=2025-03-18T11:44:52.653Z level=INFO source=server.go:624 msg="llama runner started in 1.51 seconds" Mar 18 11:44:53 ubuntu ollama[5783]: [GIN] 2025/03/18 - 11:44:53 | 200 | 2.827091744s | 127.0.0.1 | POST "/api/chat" Mar 18 11:44:56 ubuntu ollama[5783]: [GIN] 2025/03/18 - 11:44:56 | 200 | 2.410066333s | 127.0.0.1 | POST "/api/chat" Mar 18 11:44:56 ubuntu ollama[5783]: [GIN] 2025/03/18 - 11:44:56 | 200 | 256.13705ms | 127.0.0.1 | POST "/api/chat" Mar 18 11:44:57 ubuntu ollama[5783]: [GIN] 2025/03/18 - 11:44:57 | 200 | 803.167998ms | 127.0.0.1 | POST "/api/chat" ``` 7. Use Ollama to download a sample model, such as llama3:8b: ```bash ollama pull llama3:8b ``` ## Step 2: Install Open WebUI Open WebUI can be installed using Python Pip or Docker. The Pip method requires Python 3.11 or greater version. 1. Install Pythen3 and additional dependencies. ```bash apt install python3-venv python3-pip ``` 2. Create a Python virtual environment and activate it. ```bash python3 -m venv venv source venv/bin/activate ``` 3. Install Open WebUI. ```bash pip install open-webui ``` 4. Upgrade the Pillow and pyopenssl modules. ```bash pip install -U Pillow pyopenssl ``` 5. Install additional libraries. ```bash pip install ffmpeg uvicorn ``` 6. Run Open WebUI and verify it starts without errors. ```bash open-webui serve & ``` Output. ```bash WARNING: CORS_ALLOW_ORIGIN IS SET TO '*' - NOT RECOMMENDED FOR PRODUCTION DEPLOYMENTS. INFO [open_webui.env] Embedding model set: sentence-transformers/all-MiniLM-L6-v2 /root/venv/lib/python3.12/site-packages/pydub/utils.py:170: RuntimeWarning: Couldn't find ffmpeg or avconv - defaulting to ffmpeg, but may not work warn("Couldn't find ffmpeg or avconv - defaulting to ffmpeg, but may not work", RuntimeWarning) WARNI [langchain_community.utils.user_agent] USER_AGENT environment variable not set, consider setting it to identify your requests. ██████╗ ██████╗ ███████╗███╗ ██╗ ██╗ ██╗███████╗██████╗ ██╗ ██╗██╗ ██╔═══██╗██╔══██╗██╔════╝████╗ ██║ ██║ ██║██╔════╝██╔══██╗██║ ██║██║ ██║ ██║██████╔╝█████╗ ██╔██╗ ██║ ██║ █╗ ██║█████╗ ██████╔╝██║ ██║██║ ██║ ██║██╔═══╝ ██╔══╝ ██║╚██╗██║ ██║███╗██║██╔══╝ ██╔══██╗██║ ██║██║ ╚██████╔╝██║ ███████╗██║ ╚████║ ╚███╔███╔╝███████╗██████╔╝╚██████╔╝██║ ╚═════╝ ╚═╝ ╚══════╝╚═╝ ╚═══╝ ╚══╝╚══╝ ╚══════╝╚═════╝ ╚═════╝ ╚═╝ v0.5.20 - building the best open-source AI user interface. https://github.com/open-webui/open-webui ``` 7. Allow the Open WebUI port 8080 via UFW. ```bash ufw allow 8080 ``` ## Step 3: Access Open WebUI Once Open WebUI is installed, you can access it via your server IP. Follow these steps to set up an administrator account and start using the interface. 1. Access your Open WebUI using the URL **http://your-server-ip:8080.** ![](https://www.atlantic.net/wp-content/uploads/2025/03/p1-4.png) 2. Click **Get Started** to open the web interface. ![](https://www.atlantic.net/wp-content/uploads/2025/03/p2-3.png) 3. Create a new administrator account by entering a username, email address, and password. Then, click on **Create Admin Account.** ![](https://www.atlantic.net/wp-content/uploads/2025/03/p3-1.png) 4. Enter a prompt, “**What is atlantic.net?**” Then click on **Send** to generate a response using the model. You will see the answer on the following screen. ![](https://www.atlantic.net/wp-content/uploads/2025/03/p4-1.png) ## Conclusion Open WebUI is a powerful and flexible web interface to run large language models on your server. You’ve now installed Open WebUI on an Atlantic.Net Cloud GPU instance, configured it with Ollama and added SSL certificates. You can now customize the interface, add more models and create multiple user accounts to share your LLMs. --- # How to Use LLM CLI to Deploy the Deepseek Model on an Ubuntu GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-use-llm-cli-to-deploy-the-deepseek-model-on-an-ubuntu-gpu-server/ | Published: 2025-04-15 | Author: Hitesh Jethva Deploying large language models (LLMs) has traditionally been complex, requiring significant effort and specialized knowledge. However, tools like LLM CLI now streamline this process, making it accessible even to those new to deploying advanced AI models. Deepseek, a powerful language model known for its remarkable performance in understanding and generating human-like text, can now easily be deployed using LLM CLI on Ubuntu GPU servers. In this tutorial, we will explain how to use LLM CLI to deploy the Deepseek model on your Ubuntu GPU server. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user with sudo privileges. - NVIDIA drivers installed. ## Step 1: Setup a Python Environment Ubuntu’s default repositories include the Python 3.12 version, which may not support the latest LLM optimizations. We’ll use the deadsnakes PPA to install Python 3.11. 1. Add the deadsnakes PPA for Python 3.11. ```bash add-apt-repository ppa:deadsnakes/ppa -y ``` 2. Update package lists. ```bash apt update ``` 3. Install Python 3.11 along with essential tools. ```bash apt install python3.11 python3.11-venv python3.11-distutils python3.11-dev -y ``` 4. Create a virtual environment named ‘deepseek-env’. ```bash python3.11 -m venv deepseek-env ``` 5. Activate the environment. ```bash source deepseek-env/bin/activate ``` ## Step 2: Install PyTorch with CUDA 12.1 for GPU Acceleration PyTorch with CUDA support is crucial for GPU-accelerated deep learning. We’ll install the latest stable version compatible with NVIDIA CUDA 12.1. 1. Install PyTorch with CUDA 12.1 support. ```bash pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu121 ``` 2. Install Hugging Face libraries for model loading and quantization. ```bash pip install transformers accelerate bitsandbytes auto-gptq optimum ``` 3. Install the LLM CLI and Llama.cpp integration. ```bash pip install llm llm-llama-cpp llama-cpp-python ``` ## Step 3: Download the Deepseek GGUF Model GGUF is the latest format for efficient GPU inference. We’ll download the Q5_K_M quantized version (good balance between quality & speed). 1. Create a directory to store models. ```bash mkdir -p ~/models ``` 2. Navigate into the models directory. ```bash cd ~/models ``` 3. Download the Deepseek-7B GGUF model. ```bash wget https://huggingface.co/TheBloke/deepseek-llm-7B-chat-GGUF/resolve/main/deepseek-llm-7b-chat.Q5_K_M.gguf ``` 4. Register the model with an alias ‘deepseek-chat’. ```bash llm llama-cpp add-model ~/models/deepseek-llm-7b-chat.Q5_K_M.gguf --alias deepseek-chat ``` ## Step 4: Run Inference with GPU Offloading To maximize GPU utilization, we set LLAMA_CPP_GPU_LAYERS=35 (adjust based on VRAM). Run the llm with your query. ```bash LLAMA_CPP_GPU_LAYERS=35 llm -m deepseek-chat "What is Atlantic.Net Cloud GPU?" ``` Output. ```bash llama_init_from_model: n_ctx_per_seq (4000) < n_ctx_train (4096) -- the full capacity of the model will not be utilized Atlantic.Net Cloud GPU is a service that provides high-performance computing resources using Graphics Processing Units (GPUs) for running compute-intensive applications and workloads. GPU-based cloud computing offers significant performance gains in comparison to CPU-based systems, particularly for tasks that require a lot of graphical processing and data-intensive applications like machine learning, deep learning, data analysis, and scientific simulations. ``` ## Conclusion You’ve successfully deployed the Deepseek-7B-Chat model on an Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/) using the llm CLI. This setup allows for efficient, GPU-accelerated inference, making it ideal for AI-powered applications. --- # Atlantic.Net Launches Next-Generation Secure Block Storage: Stability, Security and Scalability Without the Guesswork > URL: https://www.atlantic.net/press-releases/atlantic-net-launches-next-generation-secure-block-storage-stability-security-and-scalability-without-the-guesswork/ | Published: 2025-04-23 | Updated: 2026-06-04 | Author: Alexander Wise *Cloud Customers Gain Peace of Mind With Fixed Pricing, Encrypted Infrastructure and Ultra-Fast NVMe Performance* **ORLANDO, Fla. (April 23, 2025)** — As global market volatility continues to impact everything from supply chains to tariffs, [Atlantic.Net](https://www.atlantic.net/) is offering businesses something rare: stability and security in the cloud. Today, the company announced the launch of its upgraded [Secure Block Storage (SBS) solution](https://www.atlantic.net/cloud-platform/block-storage/), designed to be ultra-fast, scalable, affordable, and resilient, giving peace of mind in uncertain times. “Businesses shouldn’t have to worry about fluctuating forecasts or hidden costs,” said Marty Puranik, Founder and CEO of Atlantic.Net. “We are excited to release the latest version of our Secure Block Storage. The service provides high-performance with automatic encryption at affordable prices. We continue to enhance and bring new services to the market as part of our 30-year journey of innovation and reliability.” Built with 100% NVMe SSDs, Atlantic.Net’s new SBS architecture delivers lightning-fast throughput and IOPS performance for mission-critical workloads, from complex databases to enterprise backups. The upgrade introduces all-new specs, including up to 10,000 IOPS per volume and burst throughput of 450 MB/s, while offering seamless storage scaling from 10 GB to 16 TB per volume. **Secure Block Storage v2: Key Highlights** Atlantic.Net’s upgraded Secure Block Storage offering is engineered for high performance, flexibility, and resilience, meeting the needs of modern workloads with confidence and clarity. - **Powered by Pure NVMe******The service is built entirely on high-speed NVMe SSDs, ensuring rapid data access and the throughput required for performance-intensive applications. - **Built for Uptime******With a 99.999% availability design, data is automatically replicated across multiple storage nodes, minimizing the risk of downtime or data loss. - **Enhanced Security Architecture******All data is encrypted at rest and transmitted over isolated storage networks, delivering robust protection from end to end. - **Scale Without Limits******Users can expand volumes up to 16 terabytes and attach as many as 15 volumes per cloud server, allowing for seamless scalability as storage demands grow. Volumes can also be resized on the fly and easily moved between cloud servers within the same region, offering true flexibility without service interruptions. - **Local Performance, Cloud Flexibility******Secure Block Storage volumes appear as locally attached block storage devices within each cloud server, enabling high-speed data access and consistent application performance. Volumes can be formatted and partitioned to fit custom workload requirements. - **Streamlined Backup and Recovery******Integrated snapshot functionality makes it easy to protect and recover data without complex configurations. - **Strategic Availability******The service is initially available in Atlantic.Net’s USA-EAST-1 region, located in Orlando, Florida, with additional regional rollouts planned. In a digital economy increasingly shaped by global instability, Atlantic.Net’s Secure Block Storage is engineered to give organizations a steady foundation, no matter how unpredictable external forces become. Secure Block Storage v2 delivers straightforward, transparent pricing. Customers pay a flat rate of 10 cents per gigabyte each month, with no hidden fees or unexpected charges, even as tariff conditions shift. The first 50 gigabytes are free for one year, offering a risk-free way to experience the service. After the introductory period, standard pricing applies. The offer is available for one year from the date of customer signup. Existing Atlantic.Net customers are receiving automatic upgrades at no extra cost. All Secure Block Storage v1 volumes have been transitioned to the new v2 platform, allowing users to take advantage of enhanced performance without downtime, manual changes, or added fees. Explore Secure Block Storage today at:[https://www.atlantic.net/cloud-platform/block-storage](https://www.atlantic.net/cloud-platform/block-storage). **About Atlantic.Net** Established in 1994, Atlantic.Net is a privately owned, global cloud services provider that delivers innovative and reliable hosting solutions. Focusing on security, compliance, and 24×7 customer support, Atlantic.Net offers a wide range of services, including GPU hosting, an award-winning Cloud Platform, HIPAA-compliant hosting, dedicated hosting, and colocation to a large roster of organizations in a variety of industries. Atlantic.Net provides mission-critical services from eight global data center regions located in the United States, Canada, the United Kingdom, and Asia. For more information, visit[Atlantic.Net](https://www.atlantic.net/) or connect with us on [Facebook](https://www.facebook.com/Atlantic.Net), [X (Twitter)](https://twitter.com/AtlanticNet), [LinkedIn](https://www.linkedin.com/company/atlantic-net), and [YouTube](https://www.youtube.com/c/AtlanticNet).   ### --- # Atlantic.Net Launches Next-Generation Secure Block Storage: Stability, Security and Scalability Without the Guesswork > URL: https://www.atlantic.net/announcements/atlantic-net-launches-next-generation-secure-block-storage-stability-security-and-scalability-without-the-guesswork/ | Published: 2025-04-23 | Updated: 2026-06-04 | Author: Alexander Wise We are pleased to announce the launch of our upgraded [Secure Block Storage (SBS) solution](https://www.atlantic.net/cloud-platform/block-storage/), designed to be ultra-fast, scalable, affordable, and resilient, giving peace of mind. The latest version of our Secure Block Storage provides high-performance with automatic encryption at affordable prices. Built with 100% NVMe SSDs, Atlantic.Net’s new SBS architecture delivers lightning-fast throughput and IOPS performance for mission-critical workloads, from complex databases to enterprise backups. The upgrade introduces up to 10,000 IOPS per volume and burst throughput of 450 MB/s, while offering seamless storage scaling from 10 GB to 16 TB per volume. ![](https://www.atlantic.net/wp-content/uploads/2025/04/SBS-Announcement.png) ## **Secure Block Storage v2: Key Highlights** - **Powered by Pure NVMe:** Built entirely on high-speed NVMe SSDs, ensuring rapid data access and high throughput. - **Built for Uptime:** 99.999% availability design minimizes the risk of downtime or data loss. - **Enhanced Security Architecture:** Data is encrypted at rest and transmitted over isolated storage networks. - **Scale Without Limits:** Expand volumes up to 16 terabytes, attach as many as 15 volumes per cloud server, resize volumes on the fly, and easily move between cloud servers within the same region. - **Local Performance, Cloud Flexibility:** SBS volumes appear as locally attached block storage devices within each cloud server. Format and partition volumes for custom workload requirements. - **Streamlined Backup and Recovery:** Integrated snapshot functionality makes it easy to protect and recover data. - **Strategic Availability:** SBS v2 is launching in Atlantic.Net’s USA-EAST-1 region in Orlando, Florida. Additional regional rollouts planned. Secure Block Storage v2 delivers straightforward, transparent pricing. Customers pay a flat rate of 10 cents per gigabyte each month. The first 50 gigabytes are free for one year; after the introductory period, standard pricing applies. The offer is available for one year from the date of customer signup. Existing Atlantic.Net customers are receiving automatic upgrades at no extra cost. All Secure Block Storage v1 volumes have been transitioned to the new v2 platform. Explore Secure Block Storage today at:[https://www.atlantic.net/cloud-platform/block-storage](https://www.atlantic.net/cloud-platform/block-storage). --- # Language Translation with Machine Learning on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/language-translation-with-machine-learning-on-ubuntu-24-04-gpu-server/ | Published: 2025-04-25 | Updated: 2025-05-01 | Author: Hitesh Jethva In this machine learning project, we’ll develop a Language Translator application using a many-to-many encoder-decoder sequence model on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). Our model will use LSTM (Long Short-Term Memory) networks to translate English text to French. This implementation leverages the power of GPU acceleration to achieve faster training and improved performance. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user with sudo privileges. - NVIDIA drivers installed. ## Step 1: Setting Up the Environment 1. First, let’s install the necessary packages. ```bash apt install python3-pip python3-tk python3-venv graphviz ``` 2. Create a virtual environment and activate it. ```bash python3 -m venv lang-env source lang-env/bin/activate ``` 3. Install Tensorflow and other packages. ```bash pip3 install tensorflow scikit-learn numpy pydot graphviz flask ``` ## Step 2: Downloading the Dataset A quality dataset is the foundation of any machine learning project. We’ll use an English-French parallel corpus that contains aligned sentence pairs for training our translation model. You can download it with the following command. ```bash wget https://raw.githubusercontent.com/hitjethva/linuxbuz/master/eng-french.txt ``` ## Step 3: Building the Translation Model The model architecture is the heart of our translation system. We’ll implement an encoder-decoder LSTM network that can learn the complex patterns between English and French sentences. 1. Create a new Python file named **LangTraining.py.** ```bash nano LangTraining.py ``` Add the following code. ```bash # LangTraining.py #Load all the required modules. from tensorflow.keras.models import Model from tensorflow.keras import models from tensorflow.keras.utils import plot_model from tensorflow.keras.layers import Input,LSTM,Dense from sklearn.feature_extraction.text import CountVectorizer import numpy as np import pickle #initialize all variables input_texts=[] target_texts=[] input_characters=set() target_characters=set() #read dataset file with open('eng-french.txt','r',encoding='utf-8') as f: rows=f.read().split('\n') #read first 10,000 rows from dataset for row in rows[:10000]: #split input and target by '\t'=tab input_text,target_text = row.split('\t') #add '\t' at start and '\n' at end of text. target_text='\t' + target_text + '\n' input_texts.append(input_text.lower()) target_texts.append(target_text.lower()) #split character from text and add in respective sets input_characters.update(list(input_text.lower())) target_characters.update(list(target_text.lower())) #sort input and target characters input_characters = sorted(list(input_characters)) target_characters = sorted(list(target_characters)) #get the total length of input and target characters num_en_chars = len(input_characters) num_dec_chars = len(target_characters) #get the maximum length of input and target text. max_input_length = max([len(i) for i in input_texts]) max_target_length = max([len(i) for i in target_texts]) def bagofcharacters(input_texts,target_texts): #inintialize encoder , decoder input and target data. en_in_data=[] ; dec_in_data=[] ; dec_tr_data=[] #padding variable with first character as 1 as rest all 0. pad_en=[1]+[0]*(len(input_characters)-1) pad_dec=[0]*(len(target_characters)) ; pad_dec[2]=1 #countvectorizer for one hot encoding as we want to tokenize character so #anlyzer is true and None the stopwords action. cv=CountVectorizer(binary=True,tokenizer=lambda txt: txt.split(),stop_words=None,analyzer='char') for i,(input_t,target_t) in enumerate(zip(input_texts,target_texts)): #fit the input characters into the CountVectorizer function cv_inp= cv.fit(input_characters) #transform the input text from the help of CountVectorizer fit. #it character present than put 1 and 0 otherwise. en_in_data.append(cv_inp.transform(list(input_t)).toarray().tolist()) cv_tar= cv.fit(target_characters) dec_in_data.append(cv_tar.transform(list(target_t)).toarray().tolist()) #decoder target will be one timestep ahead because it will not consider #the first character i.e. '\t'. dec_tr_data.append(cv_tar.transform(list(target_t)[1:]).toarray().tolist()) #add padding variable if the length of the input or target text is smaller #than their respective maximum input or target length. if len(input_t) < max_input_length: for _ in range(max_input_length-len(input_t)): en_in_data[i].append(pad_en) if len(target_t) < max_target_length: for _ in range(max_target_length-len(target_t)): dec_in_data[i].append(pad_dec) if (len(target_t)-1) < max_target_length: for _ in range(max_target_length-len(target_t)+1): dec_tr_data[i].append(pad_dec) #convert list to numpy array with data type float32 en_in_data=np.array(en_in_data,dtype="float32") dec_in_data=np.array(dec_in_data,dtype="float32") dec_tr_data=np.array(dec_tr_data,dtype="float32") return en_in_data,dec_in_data,dec_tr_data #create input object of total number of encoder characters en_inputs = Input(shape=(None, num_en_chars)) #create LSTM with the hidden dimension of 256 #return state=True as we don't want output sequence. encoder = LSTM(256, return_state=True) #discard encoder output and store hidden and cell state. en_outputs, state_h, state_c = encoder(en_inputs) en_states = [state_h, state_c] #create input object of total number of decoder characters dec_inputs = Input(shape=(None, num_dec_chars)) #create LSTM with the hidden dimension of 256 #return state and return sequences as we want output sequence. dec_lstm = LSTM(256, return_sequences=True, return_state=True) #initialize the decoder model with the states on encoder. dec_outputs, _, _ = dec_lstm(dec_inputs, initial_state=en_states) #Output layer with shape of total number of decoder characters dec_dense = Dense(num_dec_chars, activation="softmax") dec_outputs = dec_dense(dec_outputs) #create Model and store all variables model = Model([en_inputs, dec_inputs], dec_outputs) pickle.dump({'input_characters':input_characters,'target_characters':target_characters, 'max_input_length':max_input_length,'max_target_length':max_target_length, 'num_en_chars':num_en_chars,'num_dec_chars':num_dec_chars},open("training_data.pkl","wb")) #load the data and train the model en_in_data,dec_in_data,dec_tr_data = bagofcharacters(input_texts,target_texts) model.compile( optimizer="adam", loss="categorical_crossentropy", metrics=["accuracy"] ) model.fit( [en_in_data, dec_in_data], dec_tr_data, batch_size=64, epochs=200, validation_split=0.2, ) # Save model model.save("s2s.keras") #summary and model plot model.summary() plot_model(model, to_file='model_plot.png', show_shapes=True, show_layer_names=True) ``` 2. Run the training script. ```bash python3 LangTraining.py ``` Once training is completed, you will see the following output. **Please note the training will take several minutes to complete.** ```bash Model: "functional" ┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓ ┃ Layer (type) ┃ Output Shape ┃ Param # ┃ Connected to ┃ ┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩ │ input_layer (InputLayer) │ (None, None, 47) │ 0 │ - │ ├───────────────────────────────┼───────────────────────────┼─────────────────┼────────────────────────────┤ │ input_layer_1 (InputLayer) │ (None, None, 67) │ 0 │ - │ ├───────────────────────────────┼───────────────────────────┼─────────────────┼────────────────────────────┤ │ lstm (LSTM) │ [(None, 256), (None, │ 311,296 │ input_layer[0][0] │ │ │ 256), (None, 256)] │ │ │ ├───────────────────────────────┼───────────────────────────┼─────────────────┼────────────────────────────┤ │ lstm_1 (LSTM) │ [(None, None, 256), │ 331,776 │ input_layer_1[0][0], │ │ │ (None, 256), (None, 256)] │ │ lstm[0][1], lstm[0][2] │ ├───────────────────────────────┼───────────────────────────┼─────────────────┼────────────────────────────┤ │ dense (Dense) │ (None, None, 67) │ 17,219 │ lstm_1[0][0] │ └───────────────────────────────┴───────────────────────────┴─────────────────┴────────────────────────────┘ Total params: 1,980,875 (7.56 MB) Trainable params: 660,291 (2.52 MB) Non-trainable params: 0 (0.00 B) Optimizer params: 1,320,584 (5.04 MB) ``` ## Step 4: Creating the GUI Application A user-friendly interface makes our translation system accessible to end-users. We’ll build a web-based interface using Flask that allows users to input English text and receive French translations. 1. Create a new file named **LangTransGui.py.** ```bash nano LangTransGui.py ``` Add the following code. ```bash # LangTransWeb.py from flask import Flask, render_template, request import pickle import numpy as np from sklearn.feature_extraction.text import CountVectorizer from tensorflow.keras.models import load_model, Model from tensorflow.keras.layers import Input app = Flask(__name__) # Load preprocessed data data = pickle.load(open("training_data.pkl", "rb")) input_characters = data['input_characters'] target_characters = data['target_characters'] max_input_length = data['max_input_length'] max_target_length = data['max_target_length'] num_en_chars = data['num_en_chars'] num_dec_chars = data['num_dec_chars'] # Prepare CountVectorizer cv = CountVectorizer(binary=True, tokenizer=lambda txt: txt.split(), stop_words=None, analyzer='char') # Load the trained model model = load_model("s2s.keras") # Build encoder model encoder_outputs, state_h_enc, state_c_enc = model.layers[2].output encoder_model = Model(model.input[0], [state_h_enc, state_c_enc]) # Decoder setup decoder_state_input_h = Input(shape=(256,), name="input_3") decoder_state_input_c = Input(shape=(256,), name="input_4") decoder_states_inputs = [decoder_state_input_h, decoder_state_input_c] decoder_lstm = model.layers[3] decoder_outputs, state_h_dec, state_c_dec = decoder_lstm( model.input[1], initial_state=decoder_states_inputs ) decoder_states = [state_h_dec, state_c_dec] decoder_dense = model.layers[4] decoder_outputs = decoder_dense(decoder_outputs) decoder_model = Model( [model.input[1]] + decoder_states_inputs, [decoder_outputs] + decoder_states ) reverse_target_char_index = dict(enumerate(target_characters)) # Function to vectorize input def vectorize_input(input_text): en_in_data = [] pad_en = [1] + [0] * (len(input_characters) - 1) cv_inp = cv.fit(input_characters) en_in_data.append(cv_inp.transform(list(input_text)).toarray().tolist()) if len(input_text) < max_input_length: for _ in range(max_input_length - len(input_text)): en_in_data[0].append(pad_en) return np.array(en_in_data, dtype="float32") # Decode sequence using trained model def decode_sequence(input_seq): states_value = encoder_model.predict(input_seq) co = cv.fit(target_characters) target_seq = np.array([co.transform(list("\t")).toarray().tolist()], dtype="float32") decoded_sentence = "" stop_condition = False while not stop_condition: output_tokens, h, c = decoder_model.predict([target_seq] + states_value) sampled_token_index = np.argmax(output_tokens[0, -1, :]) sampled_char = reverse_target_char_index[sampled_token_index] decoded_sentence += sampled_char if sampled_char == "\n" or len(decoded_sentence) > max_target_length: stop_condition = True target_seq = np.zeros((1, 1, num_dec_chars)) target_seq[0, 0, sampled_token_index] = 1.0 states_value = [h, c] return decoded_sentence.strip() # Route: Home Page @app.route("/", methods=["GET", "POST"]) def home(): translation = "" if request.method == "POST": input_text = request.form["input_text"] vectorized_input = vectorize_input(input_text.lower()) translation = decode_sequence(vectorized_input) return render_template("index.html", translation=translation) if __name__ == "__main__": app.run(host="0.0.0.0", port=5000, debug=True) ``` 2. Create a templates directory and create a file inside it. ```bash mkdir templates nano templates/index.html ``` Add the below code. ```bash Language Translator

Language Translator: English to French

{% if translation %}

Translation:

{{ translation }}

{% endif %}
``` ## Step 5: Running the Application With all components ready, we can launch our translation service. The Flask application will serve our model through a web interface. Run the GUI application using the command below. ```bash python3 LangTransGui.py ``` You will see the following output. ```bash * Running on all addresses (0.0.0.0) * Running on http://127.0.0.1:5000 * Running on http://your-server-ip:5000 Press CTRL+C to quit ``` ## Step 6: Access and Test the Application 1. Now that our translation service is running. Now, open your web browser and access it using the URL **http://your-server-ip:5000.** You’ll see a clean interface with an input field. 2. Type an English sentence like **“Hello, How Are You”** and click **Translate.** 3. The system will process your input and display the French translation. ![](https://www.atlantic.net/wp-content/uploads/2025/04/p1-5.png) ## Conclusion This article demonstrates how to build a comprehensive English-to-French translation system using Long Short-Term Memory (LSTM) networks on Ubuntu 24.04. By leveraging GPU acceleration, we achieved efficient training of our sequence-to-sequence model, while the Flask web interface makes the technology accessible to end users. --- # Create Your Own Emoji with Deep Learning on Ubuntu 24.04 GPU server > URL: https://www.atlantic.net/gpu-server-hosting/create-your-own-emoji-with-deep-learning-on-ubuntu-24-04-gpu-server/ | Published: 2025-04-26 | Updated: 2025-05-01 | Author: Hitesh Jethva Emojis and avatars help show feelings without using words. They are now a big part of online chats, product reviews, and even how people connect with brands. As a result, many researchers are investigating how emojis can aid in storytelling. Thanks to new tools like computer vision and deep learning, we can now understand human emotions just by looking at images. In this tutorial, we’ll build an end-to-end system using deep learning to recognize facial expressions. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user with sudo privileges. - NVIDIA drivers installed. ## Step 1: Setting Up the Environment 1. Install Python package manager and virtual environment tools. ```bash apt install python3-pip python3-venv ``` 2. Create a new virtual environment called ’emojify-env’. ```bash python3 -m venv emojify-env ``` 3. Activate the virtual environment. ```bash source emojify-env/bin/activate ``` 4. Install Flask for the web interface and TensorFlow for deep learning. ```bash pip install flask tensorflow opencv-python numpy ``` ## Step 2: Project Structure Setup Organizing files properly is crucial for maintainability. We’ll create a logical directory structure for our project. 1. Create a directory for your project. ```bash mkdir emojify ``` 2. Navigate to the directory that was created. ```bash cd emojify ``` 3. Create a static and templates directory. `mkdir templates data templates` `mkdir -p static/uploads mkdir -p static/emoji` ## Step 3: Dataset Preparation Quality data is the foundation of any machine learning project. We’ll use a facial expression dataset from Kaggle. 1. Download the Emojis dataset from [Kaggle](https://www.kaggle.com/datasets/msambare/fer2013). 2. Copy the dataset from your local machine to the server. ```bash scp Downloads/archive.zip root@your-server-ip:/root/ ``` 3. Unzip the downloaded file to the data directory. ```bash unzip /root/archive.zip -d /root/emojify/data ``` ## Step 4: Model Training The heart of our application is the deep learning model that classifies facial expressions. 1. Create the training script. ```bash nano train.py ``` Add the below code. ```bash # train.py import numpy as np import cv2 import tensorflow as tf from tensorflow.keras.models import Sequential from tensorflow.keras.layers import Conv2D, MaxPooling2D, Dropout, Flatten, Dense from tensorflow.keras.optimizers import Adam from tensorflow.keras.preprocessing.image import ImageDataGenerator # Disable OpenCL for OpenCV (helps avoid unnecessary GPU warnings) cv2.ocl.setUseOpenCL(False) # Paths to dataset folders train_dir = 'data/train' val_dir = 'data/test' # Image data generators with rescaling train_datagen = ImageDataGenerator(rescale=1.0 / 255) val_datagen = ImageDataGenerator(rescale=1.0 / 255) # Load training data train_generator = train_datagen.flow_from_directory( train_dir, target_size=(48, 48), batch_size=64, color_mode="grayscale", class_mode='categorical' ) # Load validation data val_generator = val_datagen.flow_from_directory( val_dir, target_size=(48, 48), batch_size=64, color_mode="grayscale", class_mode='categorical' ) # Define CNN model architecture model = Sequential([ Conv2D(32, (3, 3), activation='relu', input_shape=(48, 48, 1)), Conv2D(64, (3, 3), activation='relu'), MaxPooling2D(pool_size=(2, 2)), Dropout(0.25), Conv2D(128, (3, 3), activation='relu'), MaxPooling2D(pool_size=(2, 2)), Conv2D(128, (3, 3), activation='relu'), MaxPooling2D(pool_size=(2, 2)), Dropout(0.25), Flatten(), Dense(1024, activation='relu'), Dropout(0.5), Dense(7, activation='softmax') # 7 emotion categories ]) # Compile model with optimizer and loss function model.compile( loss='categorical_crossentropy', optimizer=Adam(learning_rate=0.0001, decay=1e-6), metrics=['accuracy'] ) # Train model history = model.fit( train_generator, steps_per_epoch=train_generator.samples // train_generator.batch_size, epochs=50, validation_data=val_generator, validation_steps=val_generator.samples // val_generator.batch_size ) # Save the trained weights model.save_weights("emotion_model.weights.h5") print("✅ Training complete. Weights saved to 'emotion_model.weights.h5'.") ``` 2. Run the training script. ```bash python3 train.py ``` After training completes, you should see: ```bash ✅ Training complete. Weights saved to 'emotion_model.weights.h5'. ``` ## Step 5: Creating the Web Application Now we’ll build the interface that allows users to interact with our model. 1. Create and edit the Flask application file. ```bash nano app.py ``` Add the following code to app.py: ```bash # app.py import os import numpy as np import cv2 from flask import Flask, request, render_template from werkzeug.utils import secure_filename import tensorflow as tf from tensorflow.keras.models import Sequential from tensorflow.keras.layers import Conv2D, MaxPooling2D, Dropout, Flatten, Dense, Input from tensorflow.keras.optimizers import Adam # Setup GPU memory growth (avoids memory overload) gpus = tf.config.experimental.list_physical_devices('GPU') if gpus: try: tf.config.experimental.set_memory_growth(gpus[0], True) except RuntimeError as e: print(e) # Initialize Flask app app = Flask(__name__) app.config['UPLOAD_FOLDER'] = 'static/uploads' os.makedirs(app.config['UPLOAD_FOLDER'], exist_ok=True) # Load emotion model model = Sequential() model.add(Input(shape=(48, 48, 1))) model.add(Conv2D(32, (3, 3), activation='relu')) model.add(Conv2D(64, (3, 3), activation='relu')) model.add(MaxPooling2D(pool_size=(2, 2))) model.add(Dropout(0.25)) model.add(Conv2D(128, (3, 3), activation='relu')) model.add(MaxPooling2D(pool_size=(2, 2))) model.add(Conv2D(128, (3, 3), activation='relu')) model.add(MaxPooling2D(pool_size=(2, 2))) model.add(Dropout(0.25)) model.add(Flatten()) model.add(Dense(1024, activation='relu')) model.add(Dropout(0.5)) model.add(Dense(7, activation='softmax')) model.load_weights("emotion_model.weights.h5") # Emotion labels emotion_dict = { 0: "Angry", 1: "Disgusted", 2: "Fearful", 3: "Happy", 4: "Neutral", 5: "Sad", 6: "Surprised" } # Emoji image path map emoji_paths = { 0: "static/emojis/angry.png", 1: "static/emojis/disgusted.png", 2: "static/emojis/fearful.png", 3: "static/emojis/happy.png", 4: "static/emojis/neutral.png", 5: "static/emojis/sad.png", 6: "static/emojis/surprised.png" } @app.route('/', methods=['GET', 'POST']) def index(): if request.method == 'POST': file = request.files.get('image') if not file: return render_template('index.html', error="No image selected.") filename = secure_filename(file.filename) filepath = os.path.join(app.config['UPLOAD_FOLDER'], filename) file.save(filepath) try: # Load image and convert to grayscale img = cv2.imread(filepath) gray = cv2.cvtColor(img, cv2.COLOR_BGR2GRAY) # Face detection face_cascade = cv2.CascadeClassifier( cv2.data.haarcascades + "haarcascade_frontalface_default.xml") faces = face_cascade.detectMultiScale(gray, scaleFactor=1.3, minNeighbors=5) if len(faces) == 0: return render_template('index.html', image=filename, message="No face detected.") # Take first face detected (x, y, w, h) = faces[0] roi_gray = gray[y:y+h, x:x+w] roi = cv2.resize(roi_gray, (48, 48)) roi = roi.astype("float32") / 255.0 roi = np.expand_dims(np.expand_dims(roi, -1), 0) prediction = model.predict(roi) max_index = int(np.argmax(prediction)) emotion = emotion_dict[max_index] emoji = emoji_paths[max_index] return render_template('index.html', image=filename, emotion=emotion, emoji=emoji) except Exception as e: return render_template('index.html', error=str(e)) return render_template('index.html') if __name__ == '__main__': app.run(host='0.0.0.0', port=5000, debug=True) ``` 2. Create and edit the HTML template file. ```bash nano templates/index.html ``` Add the following code. ```bash Emojify - Image Upload

📸 Emojify from Uploaded Photo

{% if image %}

Uploaded Image:



{% endif %} {% if emotion %}

Predicted Emotion: {{ emotion }}

{% elif message %}

{{ message }}

{% elif error %}

{{ error }}

{% endif %} ``` ## Step 6: Running the Application 1. Run the Flask web application. ```bash python3 app.py ``` You should see output similar to: ```bash * Running on all addresses (0.0.0.0) * Running on http://127.0.0.1:5000 * Running on http://your-server-ip:5000 ``` ## Step 7: Test the Web Application With everything set up, let’s test our application end-to-end. 1. Open your web browser and access your application using the URL **http://your-server-ip:5000/** 2. Click **“Browse”** to select an image from your computer. 3. Click **“Upload and Detect”** to submit the image. 4. The system will process the image and display the original uploaded image and detected emotion (e.g., Happy, Sad, Angry) ![](https://www.atlantic.net/wp-content/uploads/2025/04/p1-4.png) ## Conclusion In this tutorial, we have successfully built a comprehensive deep learning pipeline for facial expression recognition and emoji generation. Starting from setting up an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/), we installed the necessary dependencies, trained a CNN model using TensorFlow, and created a user-friendly web interface with Flask. --- # How to Implement a Neural Network from Scratch Using CuPy on Ubuntu GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-implement-a-neural-network-from-scratch-using-cupy-on-ubuntu-gpu-server/ | Published: 2025-04-27 | Updated: 2026-05-04 | Author: Hitesh Jethva Neural networks are utilized in various intelligent technologies, including face recognition, chatbots, and recommendation systems. Most people use tools like TensorFlow or PyTorch to build them, but these tools often hide the underlying mechanisms that make them work. To truly understand how a neural network learns, it’s best to build one from scratch. In this guide, we’ll show you how to create a basic neural network using CuPy, a Python library that runs on your GPU. You’ll learn how the network makes predictions, improves itself, and trains faster using GPU power on an Ubuntu server. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user with sudo privileges. - NVIDIA drivers installed. - CUDA Toolkit 12.x installation needed ## Step 1: Set up the Environment First, let’s set up our Python environment. We’ll create a virtual environment to keep our dependencies isolated. 1. Install Python and pip if not already present. ```bash apt install python3 python3-pip python3-venv -y ``` 2. Create and activate a virtual environment. ```bash python3 -m venv nn-env source nn-env/bin/activate ``` 3. Install required packages. ```bash pip install cupy-cuda12x matplotlib ``` The virtual environment ensures that our project dependencies do not conflict with system-wide Python packages. The cupy-cuda12x package is specifically optimized for CUDA 12.x. ## Step 2: Neural Network Implementation 1. Create a new file, **nn.py,** with our neural network class. This implementation handles both forward and backward propagation. ```bash nano nn.py ``` Add the below code: ```bash import cupy as cp class SimpleNeuralNetwork: def __init__(self, input_size, hidden_size, output_size): cp.random.seed(42) self.wh = cp.random.uniform(size=(input_size, hidden_size)) self.bh = cp.zeros((1, hidden_size)) self.wo = cp.random.uniform(size=(hidden_size, output_size)) self.bo = cp.zeros((1, output_size)) def sigmoid(self, x): return 1 / (1 + cp.exp(-x)) def sigmoid_derivative(self, x): return x * (1 - x) def forward(self, X): self.hidden_input = cp.dot(X, self.wh) + self.bh self.hidden_output = self.sigmoid(self.hidden_input) self.final_input = cp.dot(self.hidden_output, self.wo) + self.bo self.output = self.sigmoid(self.final_input) return self.output def backward(self, X, y, learning_rate): error = y - self.output d_output = error * self.sigmoid_derivative(self.output) error_hidden = cp.dot(d_output, self.wo.T) d_hidden = error_hidden * self.sigmoid_derivative(self.hidden_output) self.wo += cp.dot(self.hidden_output.T, d_output) * learning_rate self.bo += cp.sum(d_output, axis=0, keepdims=True) * learning_rate self.wh += cp.dot(X.T, d_hidden) * learning_rate self.bh += cp.sum(d_hidden, axis=0, keepdims=True) * learning_rate return cp.mean(cp.square(error)) def save_model(self, path="model_weights"): import os os.makedirs(path, exist_ok=True) cp.save(f"{path}/wh.npy", self.wh) cp.save(f"{path}/bh.npy", self.bh) cp.save(f"{path}/wo.npy", self.wo) cp.save(f"{path}/bo.npy", self.bo) def load_model(self, path="model_weights"): self.wh = cp.load(f"{path}/wh.npy") self.bh = cp.load(f"{path}/bh.npy") self.wo = cp.load(f"{path}/wo.npy") self.bo = cp.load(f"{path}/bo.npy") ``` The class includes methods for forward propagation, backpropagation, and model persistence. The sigmoid activation function provides non-linearity to our network. 2. Run the script. ```bash python3 nn.py ``` ## Step 3: Training the Network 1. Create train.py to train our network on the XOR problem. This classic problem helps validate our implementation. ```bash nano train.py ``` Add the below code. ```bash import cupy as cp import matplotlib.pyplot as plt from nn import SimpleNeuralNetwork # XOR dataset X = cp.array([[0, 0], [0, 1], [1, 0], [1, 1]]) y = cp.array([[0], [1], [1], [0]]) # Initialize model nn = SimpleNeuralNetwork(input_size=2, hidden_size=4, output_size=1) # Training parameters epochs = 10000 lr = 0.1 losses = [] # Training loop for epoch in range(epochs): nn.forward(X) loss = nn.backward(X, y, lr) losses.append(cp.asnumpy(loss)) # Convert to NumPy for plotting if epoch % 1000 == 0: print(f"Epoch {epoch} – Loss: {loss:.5f}") # Save model weights nn.save_model() print("Training complete. Weights saved in 'model_weights/'.") # Plot training loss plt.plot(losses) plt.title("Training Loss over Epochs") plt.xlabel("Epoch") plt.ylabel("Loss") plt.grid(True) plt.savefig("training_loss.png") plt.show() ``` The XOR problem is non-linearly separable, making it a perfect test for our neural network. We will track and visualize the loss over the training epochs. 2. Execute the training script with: ```bash python3 train.py ``` This command initiates the training loop that optimizes our network weights. You should see the loss decreasing over time as the network learns. ```bash Epoch 0 – Loss: 0.35371 Epoch 1000 – Loss: 0.25000 Epoch 2000 – Loss: 0.24955 Epoch 3000 – Loss: 0.24767 Epoch 4000 – Loss: 0.23425 Epoch 5000 – Loss: 0.17842 Epoch 6000 – Loss: 0.06636 Epoch 7000 – Loss: 0.02008 Epoch 8000 – Loss: 0.01001 Epoch 9000 – Loss: 0.00636 Training complete. Weights saved in 'model_weights/'. ``` ## Step 4: Testing the Network 1. Create test.py to evaluate our trained model. This verifies if our network learned the XOR function correctly: ```bash nano test.py ``` Add the following code. ```bash import cupy as cp from nn import SimpleNeuralNetwork # XOR input X = cp.array([[0, 0], [0, 1], [1, 0], [1, 1]]) # Load model nn = SimpleNeuralNetwork(input_size=2, hidden_size=4, output_size=1) nn.load_model() # Predict output = nn.forward(X) print("Predicted Output:") print(cp.round(output, 3).get()) # Move to CPU and print ``` 2. Run the test script to see the predictions: ```bash python3 test.py ``` The output shows how well our network approximates the XOR function. Values close to 0 or 1 indicate successful learning. ```bash Predicted Output: [[0.07 ] [0.935] [0.935] [0.07 ]] ``` ## Conclusion In this tutorial, we’ve successfully implemented a neural network from scratch using CuPy on an Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/). By leveraging GPU acceleration through CuPy, we achieved significant performance improvements over traditional CPU-based implementations. The comprehensive solution, from environment setup to training and testing, demonstrates how accessible GPU computing can be for deep learning tasks. --- # How to Use RNN for Sequence Labeling on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-use-rnn-for-sequence-labeling-on-ubuntu-24-04-gpu-server/ | Published: 2025-04-28 | Updated: 2025-05-01 | Author: Hitesh Jethva Recurrent Neural Networks (RNNs) are powerful deep learning models, particularly well-suited for sequence labeling tasks such as named entity recognition, part-of-speech tagging, or speech recognition. When combined with GPU acceleration, RNNs can process sequences much faster than on CPUs alone. In this guide, we’ll walk through setting up an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/) for sequence labeling tasks using RNNs with Python and TensorFlow/Keras. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user with sudo privileges. - NVIDIA drivers installed. - Compatible NVIDIA CUDA Toolkit and cuDNN library installed. ## Step 1: Setting Up the Environment First, let’s install the necessary system packages and create a Python virtual environment. 1. Install required system packages. ```bash apt install -y python3-pip python3-dev python3-venv build-essential libcupti-dev git wget unzip ``` 2. Create and activate a Python virtual environment. ```bash python3 -m venv rnn_env source rnn_env/bin/activate ``` 3. Upgrade pip and install the required Python packages. ```bash pip install --upgrade pip pip install tensorflow numpy pandas matplotlib scikit-learn seqeval ``` 4. Let’s check that TensorFlow can detect your GPU. ```bash python3 -c "import tensorflow as tf; print('Num GPUs:', len(tf.config.list_physical_devices('GPU')))" ``` Output. ```bash Num GPUs: 1 ``` ## Step 2: Prepare the Project Structure 1. Create a directory structure for our sequence labeling project. ```bash mkdir -p ~/sequence_labeling/{data,models,utils} cd ~/sequence_labeling ``` 2. Download the dataset. We’ll use the CoNLL-2003 dataset for this example. ```bash wget https://data.deepai.org/conll2003.zip -P data/ ``` 3. Extract the downloaded file to the data directory. ```bash unzip data/conll2003.zip -d data/ ``` ## Step 3: Create Data Loading Utilities In this section, we will create helper functions to load and preprocess the CoNLL dataset. 1. Create a data loader script to handle the dataset. ```bash nano utils/data_loader.py ``` Add the following code. ```bash import numpy as np from tensorflow.keras.preprocessing.sequence import pad_sequences from tensorflow.keras.utils import to_categorical def load_conll_data(file_path): tokens, labels = [], [] with open(file_path, 'r', encoding='utf-8') as f: current_tokens, current_labels = [], [] for line in f: line = line.strip() if not line: if current_tokens: tokens.append(current_tokens) labels.append(current_labels) current_tokens, current_labels = [], [] else: parts = line.split() current_tokens.append(parts[0]) current_labels.append(parts[-1]) return tokens, labels def prepare_data(train_path, test_path): train_tokens, train_labels = load_conll_data(train_path) test_tokens, test_labels = load_conll_data(test_path) # Create vocabulary and label mappings word2idx = {w: i+2 for i, w in enumerate(set([w for s in train_tokens for w in s]))} word2idx[''] = 0 word2idx[''] = 1 label2idx = {l: i for i, l in enumerate(set([l for s in train_labels for l in s]))} idx2label = {i: l for l, i in label2idx.items()} # Convert tokens and labels to indices train_sequences = [[word2idx.get(w, word2idx['']) for w in s] for s in train_tokens] train_labels = [[label2idx[l] for l in s] for s in train_labels] test_sequences = [[word2idx.get(w, word2idx['']) for w in s] for s in test_tokens] test_labels = [[label2idx[l] for l in s] for s in test_labels] # Pad sequences max_len = max(len(s) for s in train_sequences) train_sequences = pad_sequences(train_sequences, maxlen=max_len, padding='post') train_labels = pad_sequences(train_labels, maxlen=max_len, padding='post') test_sequences = pad_sequences(test_sequences, maxlen=max_len, padding='post') test_labels = pad_sequences(test_labels, maxlen=max_len, padding='post') # Convert labels to categorical num_classes = len(label2idx) train_labels = [to_categorical(i, num_classes=num_classes) for i in train_labels] test_labels = [to_categorical(i, num_classes=num_classes) for i in test_labels] return { 'word2idx': word2idx, 'label2idx': label2idx, 'idx2label': idx2label, 'train_sequences': train_sequences, 'train_labels': train_labels, 'test_sequences': test_sequences, 'test_labels': test_labels, 'max_len': max_len, 'num_classes': num_classes, 'vocab_size': len(word2idx) } ``` This script loads and tokenizes the dataset, converts it to indexed sequences, and pads them for training. 2. Run the data loader script. ```bash python3 utils/data_loader.py ``` ## Step 4: Build and Train the RNN Model Here we build a BiLSTM-based sequence labeling model and train it using our processed data. 1. Create a training script. ```bash nano train.py ``` Add the following training code. ```bash import tensorflow as tf from tensorflow.keras.models import Model from tensorflow.keras.layers import Input, Embedding, Bidirectional, LSTM, TimeDistributed, Dense from utils.data_loader import prepare_data import os import numpy as np import pickle def build_rnn_model(vocab_size, max_len, num_classes): input_layer = Input(shape=(max_len,)) embedding = Embedding(input_dim=vocab_size, output_dim=128)(input_layer) lstm = Bidirectional(LSTM(units=64, return_sequences=True))(embedding) output = TimeDistributed(Dense(num_classes, activation='softmax'))(lstm) model = Model(inputs=input_layer, outputs=output) model.compile(optimizer='adam', loss='categorical_crossentropy', metrics=['accuracy']) return model def main(): # Prepare data data = prepare_data('data/train.txt', 'data/test.txt') # Build model model = build_rnn_model(data['vocab_size'], data['max_len'], data['num_classes']) model.summary() # Train model history = model.fit( np.array(data['train_sequences']), np.array(data['train_labels']), validation_data=(np.array(data['test_sequences']), np.array(data['test_labels'])), batch_size=32, epochs=10 ) # Save model and metadata os.makedirs('models', exist_ok=True) model.save('models/rnn_sequence_labeler.h5') with open('models/metadata.pkl', 'wb') as f: pickle.dump({ 'word2idx': data['word2idx'], 'label2idx': data['label2idx'], 'idx2label': data['idx2label'], 'max_len': data['max_len'] }, f) print("Model training complete and saved to models/ directory") if __name__ == "__main__": main() ``` This script defines the RNN model and trains it using BiLSTM layers for better context understanding in both directions. 2. Run the training script. ```bash python3 train.py ``` Output. ```bash Model: "functional" ┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━┓ ┃ Layer (type) ┃ Output Shape ┃ Param # ┃ ┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━┩ │ input_layer (InputLayer) │ (None, 113) │ 0 │ ├──────────────────────────────────────┼─────────────────────────────┼─────────────────┤ │ embedding (Embedding) │ (None, 113, 128) │ 3,024,128 │ ├──────────────────────────────────────┼─────────────────────────────┼─────────────────┤ │ bidirectional (Bidirectional) │ (None, 113, 128) │ 98,816 │ ├──────────────────────────────────────┼─────────────────────────────┼─────────────────┤ │ time_distributed (TimeDistributed) │ (None, 113, 9) │ 1,161 │ └──────────────────────────────────────┴─────────────────────────────┴─────────────────┘ Total params: 3,124,105 (11.92 MB) Trainable params: 3,124,105 (11.92 MB) Non-trainable params: 0 (0.00 B) Epoch 1/10 I0000 00:00:1744894143.190118 11843 cuda_dnn.cc:529] Loaded cuDNN version 90700 1/1 ━━━━━━━━━━━━━━━━━━━━ 4s 4s/step - accuracy: 0.6667 - loss: 1.0917 - val_accuracy: 0.2222 - val_loss: 1.1006 Epoch 2/10 1/1 ━━━━━━━━━━━━━━━━━━━━ 0s 62ms/step - accuracy: 0.6667 - loss: 1.0773 - val_accuracy: 0.3333 - val_loss: 1.1023 Epoch 3/10 1/1 ━━━━━━━━━━━━━━━━━━━━ 0s 60ms/step - accuracy: 0.6667 - loss: 1.0628 - val_accuracy: 0.2222 - val_loss: 1.1041 Epoch 4/10 1/1 ━━━━━━━━━━━━━━━━━━━━ 0s 61ms/step - accuracy: 0.6667 - loss: 1.0481 - val_accuracy: 0.2222 - val_loss: 1.1062 Epoch 5/10 1/1 ━━━━━━━━━━━━━━━━━━━━ 0s 60ms/step - accuracy: 0.6667 - loss: 1.0328 - val_accuracy: 0.2222 - val_loss: 1.1084 Epoch 6/10 1/1 ━━━━━━━━━━━━━━━━━━━━ 0s 58ms/step - accuracy: 0.6667 - loss: 1.0168 - val_accuracy: 0.2222 - val_loss: 1.1110 Epoch 7/10 1/1 ━━━━━━━━━━━━━━━━━━━━ 0s 58ms/step - accuracy: 0.6667 - loss: 0.9998 - val_accuracy: 0.2222 - val_loss: 1.1139 Epoch 8/10 1/1 ━━━━━━━━━━━━━━━━━━━━ 0s 59ms/step - accuracy: 0.6667 - loss: 0.9818 - val_accuracy: 0.2222 - val_loss: 1.1173 Epoch 9/10 1/1 ━━━━━━━━━━━━━━━━━━━━ 0s 60ms/step - accuracy: 0.6667 - loss: 0.9627 - val_accuracy: 0.2222 - val_loss: 1.1212 Epoch 10/10 1/1 ━━━━━━━━━━━━━━━━━━━━ 0s 62ms/step - accuracy: 0.6667 - loss: 0.9424 - val_accuracy: 0.2222 - val_loss: 1.1257 ``` ## Step 5: Evaluate the Model This section assesses the performance of the trained model on the test data, using accuracy and classification reports. 1. Create an evaluation script. ```bash nano test.py ``` Add the following code. ```bash import tensorflow as tf import numpy as np import pickle from sklearn.metrics import classification_report from seqeval.metrics import classification_report as seqeval_report def load_model_and_metadata(): model = tf.keras.models.load_model('models/rnn_sequence_labeler.h5') with open('models/metadata.pkl', 'rb') as f: metadata = pickle.load(f) return model, metadata def evaluate_model(): model, metadata = load_model_and_metadata() # Reload test data from utils.data_loader import prepare_data data = prepare_data('data/train.txt', 'data/test.txt') # Predict on test data y_pred = model.predict(np.array(data['test_sequences'])) y_pred = np.argmax(y_pred, axis=-1) y_true = np.argmax(np.array(data['test_labels']), axis=-1) # Convert indices to labels for each sequence true_labels = [] pred_labels = [] for i in range(len(y_true)): true_seq = [] pred_seq = [] for j in range(len(y_true[i])): true_label = metadata['idx2label'].get(y_true[i][j], 'O') pred_label = metadata['idx2label'].get(y_pred[i][j], 'O') # Skip padding tokens if true_label != 'O' or pred_label != 'O': true_seq.append(true_label) pred_seq.append(pred_label) true_labels.append(true_seq) pred_labels.append(pred_seq) # Print token-level classification report print("Token-level Classification Report:") flat_true = [label for seq in true_labels for label in seq] flat_pred = [label for seq in pred_labels for label in seq] print(classification_report(flat_true, flat_pred)) # Print sequence-level report (requires seqeval) print("\nSequence-level Classification Report:") print(seqeval_report(true_labels, pred_labels)) if __name__ == "__main__": evaluate_model() ``` This script reloads the saved model and computes detailed evaluation metrics on the test set using both sklearn and seqeval libraries. 2. Run the evaluation. ```bash python3 test.py ``` ## Step 6: Create a Prediction Script 1. Finally, let’s create a script to make predictions on new text. ```bash nano predict.py ``` Add the following code. ```bash import tensorflow as tf import numpy as np import pickle from tensorflow.keras.preprocessing.sequence import pad_sequences def load_model_and_metadata(): model = tf.keras.models.load_model('models/rnn_sequence_labeler.h5') with open('models/metadata.pkl', 'rb') as f: metadata = pickle.load(f) return model, metadata def predict_sequence(text): model, metadata = load_model_and_metadata() tokens = text.split() sequence = [metadata['word2idx'].get(w, metadata['word2idx']['']) for w in tokens] padded = pad_sequences([sequence], maxlen=metadata['max_len'], padding='post') prediction = model.predict(padded) prediction = np.argmax(prediction, axis=-1)[0] return [(token, metadata['idx2label'].get(idx, 'O')) for token, idx in zip(tokens, prediction)] if __name__ == "__main__": while True: text = input("\nEnter text to analyze (or 'quit' to exit): ") if text.lower() == 'quit': break results = predict_sequence(text) print("\nPredicted labels:") for token, label in results: print(f"{token}: {label}") ``` This script allows users to enter a sentence and receive predicted labels for each word using the trained RNN model. 2. Test the prediction script. ```bash python3 predict.py ``` You will be asked to enter the text to analyze. ```bash Enter text to analyze (or 'quit' to exit): Microsoft is based in USA ``` Write the text **“Microsoft** **is based in USA**” and press the Enter key. You will see the output below. ```bash I0000 00:00:1744894809.978962 13089 cuda_dnn.cc:529] Loaded cuDNN version 90700 1/1 ━━━━━━━━━━━━━━━━━━━━ 1s 1s/step Predicted labels: Microsoft: B-ORG is: O based: O in: O USA: B-LOC ``` ## Conclusion In this guide, you learned how to set up a GPU-powered RNN model for sequence labeling tasks on an Ubuntu 24.04 server. We walked through the setup of the environment, data loading, model training, evaluation, and prediction. This comprehensive pipeline can be further enhanced with advanced techniques, such as CRF layers, attention mechanisms, or transformer-based models, to achieve even greater accuracy. --- # Atlantic.Net Named Winner of the Coveted Global InfoSec Awards during RSA Conference 2025 > URL: https://www.atlantic.net/press-releases/atlantic-net-named-winner-of-the-coveted-global-infosec-awards-during-rsa-conference-2025/ | Published: 2025-04-28 | Updated: 2025-04-29 | Author: Alexander Wise **Atlantic.Net Wins Most Innovative Cloud Hosting and Storage Solutions IN 13th Annual Global InfoSec Awards at #RSAC 2025** **SAN FRANCISCO – (BUSINESS WIRE) – APRIL 28, 2025** – **Atlantic.Net** is proud to announce we have won the **Most Innovative Cloud Hosting and Storage Solutions** award from Cyber Defense Magazine (CDM), the industry’s leading electronic information security magazine. “We’re thrilled to receive one of the most prestigious and coveted cybersecurity awards in the world from Cyber Defense Magazine, during their 13th anniversary as one of the world’s leading independent cybersecurity news and information providers. We knew the competition would be tough and with top judges who are leading infosec experts from around the globe, we couldn’t be more pleased,” said Marty Puranik, CEO of Atlantic.Net. ![](https://www.atlantic.net/wp-content/uploads/2025/04/Infosec2025.png) “We scoured the globe looking for cybersecurity innovators that could make a huge difference and potentially help turn the tide against the exponential growth in cybercrime. **Atlantic.Net** is worthy of this coveted award and consideration for deployment in your environment,” said Yan Ross, Global Editor of Cyber Defense Magazine. **About Atlantic.Net** Founded in 1994, Atlantic.Net is a global cloud services provider headquartered in Orlando, Florida, with data centers across the United States, Canada, Europe, and Asia. Focused on security, compliance, and simplifying the user experience, Atlantic.Net offers a wide array of hosting solutions, including award-winning cloud hosting, GPU hosting powered by Nvidia, secure block storage, dedicated servers, colocation, and HIPAA-compliant hosting, backed by a 100% uptime SLA and 24/7/365 support. Serving customers in over 100 countries for three decades, Atlantic.Net helps businesses achieve growth and success through reliable, secure, and innovative IT infrastructure solutions. **About Cyber Defense Magazine** Cyber Defense Magazine is the premier source of cybersecurity news and information for InfoSec professionals in business and government. We are managed and published by and for ethical, honest, passionate information security professionals. Our mission is to share cutting-edge knowledge, real-world stories, and awards on the information technology industry’s best ideas, products, and services. We deliver free electronic magazines online every month, as well as special editions exclusively for the RSA Conferences. CDM is a proud member of the Cyber Defense Media Group. Learn more about us at[http://www.cyberdefensemagazine.com](http://www.cyberdefensemagazine.com). **Atlantic.Net Media Contact:** Media Contact [pr@atlantic.net](mailto:pr@atlantic.net) **Cyber Defense Magazine Media Contact:** Contact:                Irene Noser, Marketing Executive Email:                   marketing@cyberdefensemagazine.com Toll Free (USA):   1-833-844-9468 International:        1-646-586-9545 --- # Network Intrusion Detection System Using Machine Learning on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/network-intrusion-detection-system-using-machine-learning-on-ubuntu-24-04-gpu-server/ | Published: 2025-04-29 | Updated: 2026-05-04 | Author: Hitesh Jethva With the increasing number of cyber threats, organizations need robust Network Intrusion Detection Systems (NIDS) to monitor and protect their networks. Traditional signature-based detection methods are often ineffective against zero-day attacks and sophisticated threats. Machine Learning (ML) offers a powerful alternative by learning patterns from network traffic data and detecting anomalies in real time. This article demonstrates how to implement a machine learning-based Network Intrusion Detection System (NIDS) on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/) using TensorFlow for enhanced performance. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user with sudo privileges. - NVIDIA drivers installed. ## Step 1: Setting Up the Environment 1. First, install the necessary Python packages. ```bash apt install python3 python3-pip python3-venv -y ``` 2. Next, create and activate a virtual environment to isolate our project dependencies. ```bash python3 -m venv nids-env source nids-env/bin/activate ``` 3. Install the necessary machine learning and networking packages. ```bash pip install tensorflow scikit-learn pandas numpy scapy matplotlib seaborn joblib tqdm ``` 4. Verify that TensorFlow can access your GPU. ```bash python3 -c "import tensorflow as tf; print(f'TensorFlow GPU: {tf.test.is_gpu_available()}')" ``` Output. ```bash TensorFlow GPU: True ``` **Note: If you get an error here, you can install the require NVIDIA drivers using:** ``` python3 -m pip install 'tensorflow[and-cuda]' ``` ```` ## Step 2: Preparing the Dataset We will use the CIC-IDS-2017 dataset from Kaggle, which contains labeled network traffic with various types of attacks. 1. Create main project folders ```bash mkdir -p ~/nids-project/{datasets,models,scripts,data} ``` 2. Download Network Intrusion dataset(CIC-IDS- 2017) from the [Kaggle](https://www.kaggle.com/datasets/chethuhn/network-intrusion-dataset/code). 3. Transfer the downloaded dataset to your server: ```bash scp Downloads/archive.zip root@server-ip:/root/nids-project/datasets/ ``` 4. Unzip the dataset: ```bash cd ~/nids-project/datasets unzip archive.zip ``` ## Step 3: Data Preprocessing 1. Create a preprocessing script to clean and prepare the data. ```bash cd ~/nids-project nano scripts/preprocess.py ``` Add the following code: ```bash import pandas as pd import numpy as np import os from sklearn.preprocessing import MinMaxScaler, LabelEncoder import joblib # Configure paths DATASET_DIR = os.path.expanduser('~/nids-project/datasets') MODEL_DIR = os.path.expanduser('~/nids-project/models') DATA_DIR = os.path.expanduser('~/nids-project/data') def load_data(): """Load and merge all dataset files with custom labels""" file_mapping = { 'Monday': 'BENIGN', 'Tuesday': 'BruteForce', 'Wednesday': 'DoS', 'Thursday-WorkingHours': 'WebAttack', 'Thursday-Afternoon': 'Infiltration', 'Friday-WorkingHours': 'DDoS', 'Friday-Afternoon-PortScan': 'PortScan', 'Friday-Afternoon': 'Botnet' } combined = pd.DataFrame() for pattern, label in file_mapping.items(): for file in os.listdir(DATASET_DIR): if pattern in file and file.endswith('.csv'): file_path = os.path.join(DATASET_DIR, file) print(f"📂 Loading {file} as '{label}'") df = pd.read_csv(file_path, low_memory=False) df['label'] = label combined = pd.concat([combined, df], ignore_index=True) return combined def main(): print("🚀 Loading and merging dataset files...") df = load_data() if 'label' not in df.columns: raise ValueError("❌ Label column not found in the dataset.") # Extract label column first labels = df['label'] # Keep only numeric features df = df.select_dtypes(include=['number']) # Detect and report columns with inf/-inf inf_cols = df.columns[np.isinf(df).any()] if len(inf_cols) > 0: print(f"⚠️ Columns with inf/-inf values: {inf_cols.tolist()}") # Replace inf/-inf with NaN and fill NaNs with 0 df.replace([np.inf, -np.inf], np.nan, inplace=True) df.fillna(0, inplace=True) # Final safety check if not np.isfinite(df.values).all(): raise ValueError("❌ Data still contains non-finite values after cleaning.") # Prepare features and encoded labels X = df label_encoder = LabelEncoder() y = label_encoder.fit_transform(labels) # Create directories os.makedirs(MODEL_DIR, exist_ok=True) os.makedirs(DATA_DIR, exist_ok=True) # Fit and save MinMaxScaler scaler = MinMaxScaler() scaler.fit(X) joblib.dump(scaler, os.path.join(MODEL_DIR, 'scaler.pkl')) # Save processed data and label encoder joblib.dump((X, y), os.path.join(DATA_DIR, 'processed.pkl')) joblib.dump(label_encoder, os.path.join(MODEL_DIR, 'label_encoder.pkl')) print(f"✅ Preprocessing complete. Data saved to:\n- {DATA_DIR}/processed.pkl\n- {MODEL_DIR}/scaler.pkl\n- {MODEL_DIR}/label_encoder.pkl") if __name__ == "__main__": main() ``` 2. Run the preprocessing script. ```bash python3 scripts/preprocess.py ``` This script loads the dataset, cleans it, normalizes the features, and saves the processed data for training. ```bash 🚀 Loading and merging dataset files... 📂 Loading Monday-WorkingHours.pcap_ISCX.csv as 'BENIGN' 📂 Loading Tuesday-WorkingHours.pcap_ISCX.csv as 'BruteForce' 📂 Loading Wednesday-workingHours.pcap_ISCX.csv as 'DoS' 📂 Loading Thursday-WorkingHours-Afternoon-Infilteration.pcap_ISCX.csv as 'WebAttack' 📂 Loading Thursday-WorkingHours-Morning-WebAttacks.pcap_ISCX.csv as 'WebAttack' 📂 Loading Friday-WorkingHours-Afternoon-PortScan.pcap_ISCX.csv as 'DDoS' 📂 Loading Friday-WorkingHours-Morning.pcap_ISCX.csv as 'DDoS' 📂 Loading Friday-WorkingHours-Afternoon-DDos.pcap_ISCX.csv as 'DDoS' ⚠️ Columns with inf/-inf values: ['Flow Bytes/s', ' Flow Packets/s'] ✅ Preprocessing complete. Data saved to: - /root/nids-project/data/processed.pkl - /root/nids-project/models/scaler.pkl - /root/nids-project/models/label_encoder.pkl ``` ## Step 4: Model Training 1. Create a training script to build our intrusion detection model. ```bash nano scripts/train.py ``` Add the following code. ```bash import os import joblib import numpy as np import tensorflow as tf from tensorflow.keras.models import Sequential from tensorflow.keras.layers import Dense, Dropout # Configure paths DATA_DIR = os.path.expanduser('~/nids-project/data') MODEL_DIR = os.path.expanduser('~/nids-project/models') # Load processed data X, y = joblib.load(os.path.join(DATA_DIR, 'processed.pkl')) # Load and apply the scaler scaler = joblib.load(os.path.join(MODEL_DIR, 'scaler.pkl')) X_scaled = scaler.transform(X) # Build and compile the model model = Sequential([ Dense(256, activation='relu', input_shape=(X_scaled.shape[1],)), Dropout(0.3), Dense(128, activation='relu'), Dense(len(np.unique(y)), activation='softmax') ]) model.compile(optimizer='adam', loss='sparse_categorical_crossentropy', metrics=['accuracy']) # Train the model model.fit(X_scaled, y, epochs=20, validation_split=0.2) # Save the model model.save(os.path.join(MODEL_DIR, 'nids_model.h5')) print(f"✅ Model training complete and saved to {MODEL_DIR}/nids_model.h5") ``` 2. Run the training script. ```bash python3 scripts/train.py ``` This builds and trains a neural network model to classify network traffic, leveraging GPU acceleration for faster training. ## Step 5: Real-time Detection 1. Create a detection script to monitor network traffic. ```bash nano scripts/detect.py ``` Add the following code. ```bash import os import time import numpy as np import pandas as pd from scapy.all import sniff, IP, TCP from collections import deque, defaultdict import joblib import tensorflow as tf # Paths MODEL_DIR = os.path.expanduser('~/nids-project/models') # Load model and preprocessing artifacts model = tf.keras.models.load_model(os.path.join(MODEL_DIR, 'nids_model.h5')) scaler = joblib.load(os.path.join(MODEL_DIR, 'scaler.pkl')) label_encoder = joblib.load(os.path.join(MODEL_DIR, 'label_encoder.pkl')) # Track packet rate for flood detection packet_log = deque(maxlen=2000) # Track port hits for each source IP port_tracker = defaultdict(set) # Extract features with expected column names def extract_features(packet): if IP in packet: ip_layer = packet[IP] features = { 'ip_len': ip_layer.len, 'ip_ttl': ip_layer.ttl, 'payload_len': len(ip_layer.payload) } if TCP in packet: tcp_layer = packet[TCP] features['tcp_flags'] = int(tcp_layer.flags) features['src_port'] = tcp_layer.sport features['dst_port'] = tcp_layer.dport features['proto'] = 6 # TCP protocol number # Pad missing features expected_columns = scaler.feature_names_in_ df = pd.DataFrame([features]) for col in expected_columns: if col not in df.columns: df[col] = 0 return df[expected_columns] return None # Main detection function def process_packet(packet): global packet_log, port_tracker now = time.time() # Track packet rate for flood detection packet_log.append(now) recent_packets = [t for t in packet_log if now - t < 2] packet_rate = len(recent_packets) if packet_rate > 50: print(f"🚨 ALERT: High packet rate detected! ({packet_rate} packets/2s) [Potential Flood]") # Track destination ports per source IP for port scan detection if IP in packet and TCP in packet: src_ip = packet[IP].src dst_port = packet[TCP].dport port_tracker[src_ip].add(dst_port) if len(port_tracker[src_ip]) > 100: print(f"🚨 ALERT: Possible port scan from {src_ip} — hit ports: {sorted(port_tracker[src_ip])}") # ML-based detection features_df = extract_features(packet) if features_df is not None: scaled = scaler.transform(features_df) pred = model.predict(scaled, verbose=0) confidence = np.max(pred) pred_index = np.argmax(pred) label = label_encoder.inverse_transform([pred_index])[0] if label != 'BENIGN' and confidence > 0.9: print(f"🚨 ALERT: Intrusion detected - {label} (Confidence: {confidence:.2f})") else: print(f"✅ Normal traffic - {label} (Confidence: {confidence:.2f})") # Start sniffing if __name__ == "__main__": print("🛡️ Starting NIDS with ML, Flood, and Port Scan Detection...") sniff(iface="lo", prn=process_packet, store=False) ``` 2. Run the detection system. ```bash python3 scripts/detect.py ``` This script monitors network traffic in real-time, utilizing both rule-based detection (for flood attacks and port scans) and our trained machine learning model to identify potential intrusions. 3. Open another terminal and run a port scan. ```bash nmap -sS -p 1-1000 localhost ``` 4. Go back to the first terminal, you will see the detected attack in the following output: ```bash ✅ Normal traffic - BruteForce (Confidence: 0.25) 🚨 ALERT: Possible port scan from 127.0.0.1 — hit ports: [21, 22, 23, 25, 53, 80, 110, 111, 113, 139, 143, 199, 256, 443, 445, 554, 587, 993, 995, 63630] ``` ## Conclusion This implementation demonstrates how to build a comprehensive Network Intrusion Detection System (NIDS) using machine learning on Ubuntu 24.04 with GPU acceleration. The system combines traditional rule-based detection with machine learning (ML) classification for improved accuracy. The GPU acceleration significantly speeds up both training and inference, making it practical for real-world deployment. --- # Atlantic.Net Honored as Bronze Stevie® Award Winner in 2025 American Business Awards® > URL: https://www.atlantic.net/press-releases/atlantic-net-honored-as-bronze-stevie-award-winner-in-2025-american-business-awards/ | Published: 2025-04-29 | Author: Alexander Wise **Stevie winners will be celebrated during the gala event on June 10 in New York** **ORLANDO, FL – April 29, 2025** – **Atlantic.Net** was named the winner of a **Bronze** Stevie® Award in the **Infrastructure as a Service** category in The 23rd Annual American Business Awards® today. ![](https://www.atlantic.net/wp-content/uploads/2025/04/Stevie2025.png) The American Business Awards are the U.S.A.’s premier business awards program. All organizations operating in the U.S.A. are eligible to submit nominations – public and private, for-profit and non-profit, large and small. Nicknamed the Stevies for the Greek word meaning “crowned,” the awards will be presented to winners at a gala ceremony at the Marriott Marquis Hotel in New York on Tuesday, June 10. Tickets are now on sale. More than 3,600 nominations from organizations of all sizes and in virtually every industry were submitted this year for consideration in a wide range of categories, including Startup of the Year, Executive of the Year, Best New Product or Service of the Year, Marketing Campaign of the Year, Thought Leader of the Year, and App of the Year, among others. **Atlantic.Net** was nominated in the **Infrastructure as a Service** category. This repeated recognition underscores Atlantic.Net’s consistent delivery of high-performance, reliable Infrastructure as a Service solutions. The judges acknowledged the company’s sustained innovation and dedication to providing robust, scalable, and secure cloud infrastructure, solidifying its leadership position in a competitive market. “Receiving the Stevie Award for Infrastructure as a Service for another year is a tremendous honor and a testament to our entire team’s continued focus on delivering service excellence to our clients,” said Marty Puranik, CEO of Atlantic.Net. “Winning this award again confirms that our focus on providing reliable and high-performing infrastructure isn’t just a goal, it’s something we deliver consistently for our clients. We are grateful for this acknowledgment and remain dedicated to driving further innovation for our customers worldwide.” More than 250 professionals worldwide participated in the judging process to select this year’s Stevie Award winners. “Organizations across the United States continue to demonstrate resilience and innovation,” said Stevie Awards president Maggie Miller. “The 2025 Stevie winners have helped drive that success through their innovation, persistence, and hard work. We congratulate all of the winners in the 2025 ABAs and look forward to celebrating their achievements during our June 10 gala event in New York.” Details about The American Business Awards and the list of 2025 Stevie winners are available at [www.StevieAwards.com/ABA](http://www.stevieawards.com/ABA). **About Atlantic.Net:** Established in 1994, Atlantic.Net is a global cloud services provider with over 30 years of experience, specializing in secure, compliant, and user-friendly cloud hosting and infrastructure solutions. Offering dedicated and cloud GPU platforms, powered by NVIDIA, for high-performance computing (HPC) and AI/ML workloads, alongside managed services and customizable cloud configurations, Atlantic.Net operates state-of-the-art data centers across North America, Europe, and Asia. Known for reliability, exceptional support, and audited certifications (including SSAE 18 SOC 2/3, HIPAA, and HITECH), Atlantic.Net is a trusted partner simplifying complex technology for businesses across the globe. **About the Stevie Awards** Stevie Awards are conferred in nine programs: the Asia-Pacific Stevie Awards, the German Stevie Awards, the Middle East & North Africa Stevie Awards, The American Business Awards®, The International Business Awards®, the Stevie Awards for Women in Business, the Stevie Awards for Great Employers, the Stevie Awards for Sales & Customer Service, and the Stevie Awards for Technology Excellence. Stevie Awards competitions receive more than 12,000 entries each year from organizations in more than 70 nations. Honoring organizations of all types and sizes and the people behind them, the Stevies recognize outstanding performance in the workplace worldwide. --- # OCR with Machine Learning on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/ocr-with-machine-learning-on-ubuntu-24-04-gpu-server/ | Published: 2025-04-30 | Updated: 2025-05-01 | Author: Hitesh Jethva Optical Character Recognition (OCR) is a powerful technology that enables machines to convert images of text into editable and searchable data. By leveraging machine learning and GPU acceleration, you can greatly enhance OCR accuracy and processing speed. In this guide, you’ll learn how to set up an OCR solution using machine learning tools on an Ubuntu 24.04 GPU server. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user with sudo privileges. - NVIDIA drivers installed. ## Step 1: Set Up Python Virtual Environment 1. Install required system packages. ```bash apt install -y python3-pip python3-dev python3-venv ``` 2. Create and activate a Python virtual environment. ```bash python3 -m venv ocr-env source ocr-env/bin/activate ``` 3. Update pip to the latest version. ```bash pip install --upgrade pip ``` ## Step 2: Install EasyOCR and Dependencies EasyOCR is a popular library for optical character recognition (OCR) tasks, leveraging machine learning. 1. Install Torch with GPU support. ```bash pip install tensorflow torch torchvision torchaudio ``` 2. Install the OCR package and other dependencies. ```bash pip install easyocr opencv-python matplotlib ``` ## Step 3: Perform OCR on Images Create a Python script **gpu_ocr.py** to read text from an image. ```bash nano gpu_ocr.py ``` Add the following content. ```bash import easyocr import cv2 import matplotlib.pyplot as plt import numpy as np import requests # Initialize EasyOCR reader with GPU support reader = easyocr.Reader(['en'], gpu=True) # Load image directly from URL image_url = 'https://i.postimg.cc/NfdDwSw5/sample-ocr.png' # Replace with your image URL response = requests.get(image_url) # Convert image bytes to NumPy array for OpenCV image_array = np.frombuffer(response.content, dtype=np.uint8) image = cv2.imdecode(image_array, cv2.IMREAD_COLOR) # Perform OCR on the loaded image results = reader.readtext(image) # Display OCR results in the console for detection in results: bbox, text, confidence = detection print(f"Detected: '{text}' (Confidence: {confidence:.2f})") # Visualize OCR results by drawing bounding boxes and labels for detection in results: bbox, text, confidence = detection top_left = tuple(map(int, bbox[0])) bottom_right = tuple(map(int, bbox[2])) # Draw bounding box cv2.rectangle(image, top_left, bottom_right, (0, 255, 0), 2) # Label detected text cv2.putText(image, text, (top_left[0], top_left[1] - 10), cv2.FONT_HERSHEY_SIMPLEX, 0.6, (255, 0, 0), 2) # Display the resulting image with OCR annotations plt.figure(figsize=(10, 10)) plt.imshow(cv2.cvtColor(image, cv2.COLOR_BGR2RGB)) plt.axis('off') plt.show() ``` Run the OCR script. ```bash python3 gpu_ocr.py ``` You will see the extracted text in the output below. ```bash Detected: 'What' (Confidence: 0.99) Detected: 'is Atlantic.Net?' (Confidence: 0.98) ``` ## Step 4: Create a Web Interface for OCR You can also create a web-based application for OCR. 1. Install required packages. ```bash pip install flask numpy ``` 2. Create an application for OCR. ```bash nano app.py ``` Add the following code. ```bash from flask import Flask, request, render_template import easyocr import cv2 import numpy as np app = Flask(__name__) reader = easyocr.Reader(['en'], gpu=True) @app.route('/', methods=['GET', 'POST']) def upload_image(): text_results = [] if request.method == 'POST': file = request.files['image'] if file: img_bytes = file.read() np_img = np.frombuffer(img_bytes, np.uint8) img = cv2.imdecode(np_img, cv2.IMREAD_COLOR) results = reader.readtext(img) text_results = [result[1] for result in results] return render_template('upload.html', results=text_results) if __name__ == '__main__': app.run(host='0.0.0.0', port=5000) app.run(debug=True) ``` 2. Create an HTML Template for your application. ```bash mkdir templates nano templates/upload.html ``` Add the below content: ```bash OCR Web Interface

Upload an Image for OCR

{% if results %}

Extracted Text:

    {% for text in results %}
  • {{ text }}
  • {% endfor %}
{% endif %} ``` 4. Run the application. ```bash python3 app.py ``` 5. Access the application by navigating to **http://your-server-ip:5000** in your browser. ![](https://www.atlantic.net/wp-content/uploads/2025/04/p2-1.png) 6. Click on **Choose File** to select the following image file from your local system. ![](https://www.atlantic.net/wp-content/uploads/2025/04/sample_ocr.png) 7. Click on **Upload.** The application extracts a text from your uploaded image file and displays it in the following output. ![](https://www.atlantic.net/wp-content/uploads/2025/04/p1-3.png) ## Conclusion By following this guide, you’ve successfully set up and executed OCR using machine learning on your Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). Leveraging GPU acceleration significantly enhances performance, allowing rapid processing of large datasets. Additionally, the web interface provides an intuitive way to interact with the OCR functionality. --- # How to Install Whisper Real-Time Speech-to-Text on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-install-whisper-real-time-speech-to-text-on-ubuntu-24-04-gpu-server/ | Published: 2025-05-01 | Author: Hitesh Jethva Real-time transcription of spoken language into text has numerous applications, ranging from live captioning and meeting transcription to accessibility tools and virtual assistants. OpenAI’s Whisper model provides powerful multilingual speech recognition capabilities, and when deployed on a GPU-enabled Ubuntu 24.04 server, it can handle real-time audio with high accuracy and minimal latency. In this guide, you’ll learn how to set up and run Whisper for real-time speech-to-text on Ubuntu 24.04 with GPU support. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user with sudo privileges. - NVIDIA drivers installed. ## Step 1: Install System Dependencies First, we need to install the essential system packages that Whisper and its supporting libraries require. ```bash apt install -y ffmpeg python3 python3-venv python3-pip portaudio19-dev ``` ## Step 2: Create and Activate a Python Virtual Environment Using a virtual environment isolates our Whisper installation, preventing conflicts with system Python packages. ```bash python3 -m venv whisper-env source whisper-env/bin/activate ``` ## Step 3: Upgrade pip and install Whisper With our environment ready, we can now install Whisper and its dependencies. First, upgrade pip to the latest version. ```bash pip install --upgrade pip ``` Install Whisper. ```bash pip install git+https://github.com/openai/whisper.git ``` ## Step 4: Install PyTorch with CUDA Support For GPU acceleration, we need to install PyTorch with CUDA 12.1 support (compatible with NVIDIA GPUs). ```bash pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu121 ``` ## Step 5: Install Additional Required Packages We will need a few additional Python packages for audio handling and our web interface. ```bash pip install sounddevice numpy gradio ``` - **sounddevice** for microphone access - **numpy** for numerical operations - **gradio** for creating a web interface ## Step 6: Create the Application Script Now we’ll create a Python script that loads the Whisper model and provides a web interface for transcription. Create a new file named **app.py:** ```bash nano app.py ``` Add the following code. ```bash import whisper import gradio as gr import datetime # Load Whisper model (use "medium" or "large" for better accuracy if needed) model = whisper.load_model("base") # Error log file LOG_FILE = "error_logs.txt" # Log errors to file def log_error(error_message): with open(LOG_FILE, "a") as f: timestamp = datetime.datetime.now().strftime("%Y-%m-%d %H:%M:%S") f.write(f"[{timestamp}] {error_message}\n") # Transcription logic def transcribe_audio(audio): try: if audio is None: return "❌ No audio received. Please record or upload an audio file." result = model.transcribe(audio) return result["text"] except Exception as e: log_error(str(e)) return f"⚠️ Error occurred: {e}" # Gradio interface with gr.Blocks() as demo: gr.Markdown("## 🎙️ Whisper Real-Time Speech-to-Text on Ubuntu 24.04 GPU Server") # Input type selection input_method = gr.Radio(["Upload Audio File", "Record via Microphone"], label="Choose Input Method", value="Upload Audio File") # Both audio components are now the same due to gradio v4+ behavior upload_audio = gr.Audio(type="filepath", label="📂 Upload Audio File", visible=True) record_audio = gr.Audio(type="filepath", label="🎤 Record via Microphone", visible=False) output_text = gr.Textbox(label="📝 Transcribed Text") # Show/hide audio inputs dynamically def toggle_inputs(method): return ( gr.update(visible=(method == "Upload Audio File")), gr.update(visible=(method == "Record via Microphone")) ) input_method.change(fn=toggle_inputs, inputs=input_method, outputs=[upload_audio, record_audio]) # Decide which audio input to use and transcribe def handle_transcription(upload, record, method): audio = upload if method == "Upload Audio File" else record return transcribe_audio(audio) transcribe_button = gr.Button("🔍 Transcribe") transcribe_button.click(fn=handle_transcription, inputs=[upload_audio, record_audio, input_method], outputs=output_text) # Launch app with public sharing link demo.launch(share=True) ``` This script: - Loads the Whisper base model (you can change to “medium” or “large” for better accuracy) - Sets up error logging to a file - Creates a Gradio web interface with options to either upload audio files or record directly - Implements the transcription logic that processes audio through Whisper - Provides a clean interface for viewing results ## Step 7: Run the Application With everything set up, launch the application: ```bash python3 app.py ``` This starts the web server and provides both local and public URLs to access the interface. ```bash checkpoint = torch.load(fp, map_location=device) * Running on local URL: http://127.0.0.1:7860 * Running on public URL: https://c914b0a89448da8a6d.gradio.live ``` ## Step 6: Accessing the Web Interface Open your web browser and access the web UI using the URL **https://c914b0a89448da8a6d.gradio.live** from the above output. Select **“Record via Microphone”** as the input method. ![](https://www.atlantic.net/wp-content/uploads/2025/04/p1-2.png) Click the **microphone** icon on the interface and click on **Record** to start recording. Stop recording by clicking the same icon again. Click **“Transcribe”** to process the recording. Whisper transcribes the audio and displays the resulting text. ![](https://www.atlantic.net/wp-content/uploads/2025/04/p2.png) ## Conclusion You have successfully set up Whisper for real-time speech-to-text transcription on your Ubuntu [GPU server](https://www.atlantic.net/gpu-server-hosting/), complete with a web-based user interface. You can further customize the Whisper model or enhance the web application according to your needs. --- # COBOL Modernization: 5 Considerations for Regulated Industries > URL: https://www.atlantic.net/managed-services/cobol-modernization-5-considerations-for-regulated-industries/ | Published: 2025-05-06 | Updated: 2025-05-08 | Author: Gilad Maayan ## What Is COBOL Modernization? COBOL modernization refers to updating older COBOL systems to newer platforms or technologies without rewriting or redesigning them from scratch. This process involves using tools and techniques to improve the performance, security, and interoperability of existing COBOL applications. The goal is to ensure these systems meet current IT demands while retaining their business logic and functionality. Modernization can include rehosting applications on modern infrastructure, integrating with contemporary systems, and adopting modern development processes. Organizations can gain several [benefits through COBOL modernization](https://swimm.io/learn/legacy-code/cobol-modernization-benefits-challenges-and-5-critical-techniques), including reduction of  operational costs, improved reliability and development flexibility. The modernization path depends on factors like budget constraints, business priorities, and technology stacks. ## Why Organizations Still Depend on COBOL Despite its age, COBOL remains embedded in many organizations due to its reliability and proven track record. Many financial institutions, airlines, and government bodies continue to rely on COBOL systems to handle critical transactions and data processing tasks. Its syntax is straightforward, which reduces errors in complex calculations and record-keeping. As a result, COBOL is valued for its stability and efficiency in high-volume operations, making transitioning to newer languages not straightforward or always preferable. The significant investment in these systems over decades has created a dependency that is hard to break. Organizations often face challenges in migrating due to the vast amount of data, complex integrations, and unavailability of direct replacements for the existing functionalities COBOL provides. While newer programming languages offer different advantages, COBOL’s ability to perform mission-critical jobs with minimal downtime keeps its position in the technology stack. ## Limitations of Legacy COBOL Systems in Adapting to Evolving Regulatory Requirements Here are some of the main issues regarding the adaptability of COBOL systems: - **Lack of flexibility:** These systems were built decades ago with static business rules hardcoded into the application logic. When new compliance mandates arise—such as updates to data privacy laws, financial reporting standards, or industry-specific regulations—adapting COBOL systems can be slow and cumbersome. - **Limited modularity:** Business logic is frequently intertwined with data handling and user interface code, making even small regulatory updates a complex and risky process. Developers must navigate a dense web of interdependent components, increasing the chances of introducing unintended consequences with every change. - **Limited support:** Legacy COBOL applications often lack native support for modern audit trails, encryption standards, and access controls. These shortcomings make it difficult to meet contemporary regulatory expectations around data security and traceability. While workarounds exist, they typically require customization and retrofitting. - **Lack of real-time reporting and analytics capabilities:** Many regulations now require timely and accurate data reporting, which older COBOL systems may not support without significant upgrades. As a result, organizations relying on these systems often face difficulties in demonstrating compliance during audits or responding promptly to regulatory changes. ## Common Obstacles in Transitioning Legacy Systems Here are some of the main factors complicating modernization efforts for COBOL systems. ### Complex Legacy Code Structures Legacy COBOL systems typically contain complex code structures that have been built and modified over decades. These layers of updates and patches result in codebases that can be intimidating to new developers. The inherent complexity makes it difficult to predict the outcomes of changes, leading to risks in performance and stability. Thorough documentation of code structures is frequently lacking, as well-maintained records are rare in longstanding systems. Without detailed documentation, deciphering the intricacies of legacy code becomes challenging, leading to increased development time and resource allocation in modernization efforts. ### Shortage of Skilled COBOL Developers A major hurdle in modernizing COBOL systems is the scarcity of developers who are proficient in COBOL. As technology evolves, younger developers typically learn contemporary languages rather than older ones like COBOL. This trend results in a skills gap in the workforce, where fewer professionals have the expertise required to manage and update COBOL systems. As a generation of COBOL specialists approaches retirement, the demand for their skills intensifies. Organizations are now compelled to invest in training programs or hire consultants to bridge the gap. The shortage of skilled professionals hampers modernization and escalates costs, as finding and retaining proficient COBOL developers becomes expensive. ### Documentation Gaps Legacy systems often suffer from inadequate or outdated documentation, which complicates modernization processes. Over the years, changes are made to these systems with the assumption that existing developers understand the alterations. However, this documentation gap poses a significant challenge when newer developers attempt to decipher system functionalities, particularly when the original creators are unavailable for consultation. Inaccurate or incomplete documentation extends project timelines as additional time must be spent reverse-engineering existing code to understand its purpose and structure. This can lead to increased risk of introducing errors and inefficiencies during the transition process. To address this issue, organizations must prioritize efforts to improve documentation. ### Dependency on Outdated Hardware COBOL systems typically run on outdated mainframes and hardware that are costly and difficult to maintain. These older infrastructure components are more prone to failure, posing operational risks and increasing the need for maintenance. As technology evolves, sourcing replacement parts for outdated hardware becomes increasingly challenging, leading to periods of downtime. Modernization requires transitioning to newer, more reliable platforms that offer increased scalability and performance. However, migrating to contemporary hardware solutions involves substantial logistical and financial planning. Organizations must strategically manage the shift to minimize disruptions, while also ensuring that new platforms can handle existing workloads. ### Integration with Legacy Systems Integrating legacy COBOL systems with modern applications and platforms presents a formidable challenge. New systems are predominantly built using modern programming languages and frameworks, which often do not align seamlessly with COBOL’s architecture. Bridging the communication gap between these distinct systems requires careful planning and specialized interfaces, which can complicate the modernization process. Successful integration requires thorough analysis of system dependencies and the development of middleware solutions. ## Approaches to Updating COBOL Applications There are several ways to modernize a legacy COBOL system. ### 1. Rewrite from Scratch One approach to updating legacy COBOL applications is to rewrite them entirely using modern programming languages. This method involves translating business logic and functionalities into new code on contemporary platforms. Rewriting from scratch offers the opportunity to rectify structural inefficiencies, improve performance, and improve user experience. However, it requires a substantial investment of time and resources, which may not be feasible for all organizations. ### 2. Automated Code Conversion Automated code conversion offers a less labor-intensive alternative to modernization by utilizing tools that transform COBOL code into modern languages. This process allows for the preservation of business logic while benefiting from modern syntactic standards and application frameworks. Automated tools simplify the conversion process, potentially reducing the time and cost associated with manual rewrites, while helping maintain the original system’s functionality and intent. Despite its appeal, automated code conversion may produce results that require manual refinement. Converted code is often less readable and maintainable than human-written code. ### 3. Phased Modular Updates A phased modular update involves gradually updating individual components or modules of a COBOL application rather than overhauling the entire system simultaneously. This approach allows organizations to manage modernization in manageable sections, minimizing risk and maintaining operational continuity. Each module is updated, tested, and integrated incrementally, allowing the remaining system to continue functioning as modernization progresses. Phased updates help distribute the workload over time, easing resource constraints and financial pressures. However, they require effective project management and testing to verify that modular changes don’t introduce issues. ### 4. COBOL to Java Migration Java supports modern development practices and tools, making it a popular choice for system updates. COBOL to Java migration involves translating existing business logic and processes into Java code, leveraging Java’s object-oriented features to improve scalability and maintainability. This migration process can improve system flexibility, allowing for easier integration with modern applications and platforms. However, migration presents challenges such as ensuring functional equivalence and managing the learning curve for developers unfamiliar with Java intricacies. ### 5. AI-Assisted Transformation AI-based tools for code analysis, refactoring, and optimization can significantly improve the efficiency and accuracy of code conversion by identifying patterns and automating repetitive tasks. This aids developers in understanding complex code structures, reducing errors, and accelerating the modernization timeline. By leveraging AI, organizations can achieve a more seamless transition, minimizing human error and maximizing resource efficiency. AI tools can also assist in optimizing new code for performance and maintainability, ensuring that modernized applications meet current standards and business needs. ## Considerations for Successful COBOL Modernization for Regulated Industries Here are some important practices to consider when implementing a COBOL modernization initiative. ### 1. Establish a Clear Roadmap and Strategy Developing a well-defined roadmap and strategy is critical for a successful COBOL modernization initiative. It involves setting clear objectives, timelines, and stakeholder expectations to guide the project effectively. The strategy should assess the current state of legacy systems, identify priorities, and determine the most suitable modernization approaches. Having a structured roadmap ensures resource allocation aligns with project needs, helping to avoid budget overruns and scope creep. Engaging stakeholders at various levels provides a shared vision, enabling collaboration and reducing resistance to change. Regularly reviewing and updating the strategy allows organizations to adapt to evolving requirements. ### 2. Perform Thorough Code Assessments Conducting detailed code assessments is an essential preparatory step in modernization, providing insights into the existing system’s strengths, weaknesses, and areas requiring improvement. Code assessments involve analyzing code quality, architecture, performance, and dependencies to inform decision-making throughout the modernization journey. Automated analysis tools and expert reviews can uncover technical debt and refactoring opportunities. Comprehensive assessments help identify potential risks and resource needs, shaping the modernization plan. They also provide a baseline for measuring success post-modernization, allowing organizations to track improvements in key performance metrics. ### 3. Iterative Refactoring Over “Big Bang” Approaches Adopting an iterative refactoring approach, rather than undertaking a “big bang” transformation, helps minimize risks and ensure smoother transitions during modernization. Iterative refactoring involves making incremental improvements to the codebase, addressing issues in manageable portions. This strategy limits disruptions to ongoing business operations. By completing modernization in phases, organizations can assess each iteration’s impact, iteratively refining solutions and validating outcomes before proceeding to subsequent phases. This method also enables continuous feedback, fostering a development environment where improvements and optimizations are ongoing. ### 4. Automated Testing for Functional Equivalence Implementing automated testing practices is crucial for maintaining functional equivalence during modernization efforts. Automated tests validate that modernized systems perform as expected and preserve the original system’s functionality and intent. Leveraging tools like Selenium or TestComplete enables testing across diverse scenarios and environments. Automation reduces the time and effort associated with manual testing, allowing for thorough coverage and rapid identification of discrepancies or errors. Regularly updating automated test cases ensures alignment with evolving business processes and technical environments. ### 5. Ongoing Maintenance for Long-Term Sustainability Post-modernization, ongoing maintenance is vital for retaining system relevancy and performance. Regular maintenance involves monitoring system health, addressing emerging issues, and implementing continuous improvements to align with technological advancements and changing business requirements. Establishing structured maintenance practices ensures systems remain efficient, secure, and adaptable over time. Organizations should invest in continuous training for development teams, ensuring they are equipped with the skills necessary to support sustained system operations. Additionally, automated monitoring and incident response tools help improve system reliability. --- # How Does Atlantic.Net Handle HIPAA Migrations? > URL: https://www.atlantic.net/hipaa-compliant-hosting/how-does-atlantic-net-handle-hipaa-migrations/ | Published: 2025-05-07 | Updated: 2026-05-08 | Author: Editorial Team Medical institutions handling Protected Health Information (PHI) need to ensure that the infrastructure relocation is handled in strict compliance with HIPAA regulations. In contrast to typical IT migrations, HIPAA-regulated migrations pose a greater risk of data exposure, service interruption, compliance risks, and non-compliance, making it essential to address these risks during a HIPAA-compliant migration. These risks are further heightened in 2026 due to increased enforcement of regulations, greater upheaval in the threat environment, and greater pressure on audit preparedness and operational resilience expectations. The Health Insurance Portability and Accountability Act (HIPAA) sets national standards for protecting sensitive patient health information from unauthorized access or disclosure during data migration. Atlantic.Net undertakes HIPAA migrations with a highly organized, compliance-based approach that sustains security controls, minimizes disruption, and maintains regulatory consistency throughout the migration life cycle. A complete risk assessment is necessary to identify vulnerabilities in both source and target environments before data migration. Secure data transfer and maintaining regulatory compliance are key objectives of the migration process. ## Introduction to HIPAA Compliance HIPAA compliance is foundational for any healthcare organization undertaking data migration, as it ensures the protection of sensitive patient data throughout the process. The Health Insurance Portability and Accountability Act (HIPAA) establishes strict national standards for safeguarding protected health information (PHI), requiring healthcare providers to implement reliable access controls, encryption, and audit logging. These measures are designed to prevent unauthorized access and ensure that only authorized personnel can handle sensitive healthcare data. Healthcare organizations must also conduct regular risk assessments to identify and address potential vulnerabilities in their systems and processes. By proactively managing these risks, organizations can maintain regulatory compliance and protect sensitive patient data from breaches or misuse. Adhering to HIPAA compliance not only fulfills legal obligations but also reinforces patient trust, demonstrating a commitment to the confidentiality and security of their health information. , prioritizing HIPAA compliance during data migration helps healthcare organizations safeguard patient data, maintain operational integrity, and uphold their reputation in the healthcare industry. ## Understanding Healthcare Data Healthcare data encompasses a wide range of sensitive information, including electronic health records (EHRs), electronic medical records (EMRs), billing details, and other critical patient information. This data is often stored in legacy systems that may be outdated, fragmented, or inefficient, presenting challenges when migrating to modern platforms. The of healthcare data—ranging from structured clinical data to unstructured notes—requires careful planning and execution to ensure a smooth transition. During healthcare data migration, organizations must transfer data from existing systems to new environments while maintaining data integrity and regulatory compliance. Any misstep can result in data loss, corruption, or unauthorized access, potentially compromising patient care and regulatory standing. By thoroughly understanding the nature and structure of their healthcare data, organizations can develop tailored migration strategies that address the unique challenges of their environment, ensuring a successful healthcare data migration that preserves the quality and security of patient information. ## Why Healthcare Organizations Migrate to Atlantic.Net? Organizations also migrate HIPAA-regulated workloads to Atlantic.Net to move out of legacy or non-compliant environments, or outdated systems that hinder operational , and to infrastructure capable of supporting regulated healthcare operations. These migrations are usually motivated by the need for stronger security controls, greater system reliability, enhanced audit visibility, and scalable infrastructure to support compliance requirements, while addressing system and eliminating data silos. Healthcare cloud migration is increasingly seen as a strategic upgrade, as cloud environments enable the consolidation of fragmented data silos and support secure, compliant operations. Cloud migration allows healthcare organizations to consolidate data from legacy systems into a unified platform, improving operational and enabling smooth access to patient information across departments. Atlantic.Net provides HIPAA-supporting infrastructure under a shared responsibility model, while customers remain responsible for their own applications, policies, access controls, and compliance obligations ## HIPAA Data Migration Process of Atlantic.Net Atlantic.Net has implemented a specific, staged HIPAA migration process to minimize risk and maintain compliance before, during, and after migration operations. This process emphasizes secure data migration, using protocols such as HTTPS, SFTP, and end-to-end encryption to protect sensitive data throughout the transfer. This process focuses more on prior planning, managed execution, and post-migration validation than on expedited or ad hoc migrations. The migration process starts with a critical evaluation of the customer’s current environment. The analysis involves the identification of systems that store, process, or transmit PHI, the review of application and infrastructure dependency, the review of access control models, and the review of network and storage architecture. During this planning stage, a complete risk assessment and thorough data inventory are conducted to identify sensitive datasets, data structures, and potential vulnerabilities. Understanding data structures and structured data, such as lab results and medication codes, is essential to ensure accurate mapping and migration. Towards the end of this stage, a documented migration plan clarifies the scope, sequencing, risk concerns, and schedules in line with regulatory and operational requirements. Migration is carried out through a controlled, documented process aimed at safeguarding PHI in data transfer and system cutover scenarios. AES-256 encryption or stronger is used for data at rest, while TLS 1.2+ is enforced for data in transit. HIPAA Business Associate Agreement (BAA) (BAAs) must be signed with all third-party vendors who will access PHI during migration. Multi-Factor Authentication (MFA) and Role-Based Access Control (RBAC) are implemented to safeguard PHI access, and strict access controls limit user access to sensitive data during migration. Data masking and de-identification techniques are used for test migrations to protect real patient information. Pilot tests and pilot migrations are conducted to validate data throughput, access controls, and logging before full migration, and to detect technical issues early. Data filtration and purging techniques are used to remove irrelevant or expired data in accordance with retention policies before migration. Duplicate patient records are identified and removed during data cleansing to ensure data quality. Execution is monitored and logged, maintaining immutable and detailed audit logs for traceability of access events and modifications. Continuous monitoring tools are implemented to detect misconfigurations or suspicious activity in the new environment. A contingency plan is prepared to revert to the old system if the migration fails, and incident response and monitoring plans are established to detect and respond to unauthorized access or data breaches in real-time. After the migration process is complete, Atlantic.Net conducts post-migration validation to ensure the environment meets the specified security and compatibility expectations. Data integrity is verified by checking access permission, verifying encryption controls, inspecting monitoring and logging settings, and checking backup and disaster recovery. Legacy systems must be securely decommissioned by sanitizing or destroying hardware and media containing PHI, in accordance with NIST SP 800-88 Revision 2 guidelines. The Minimum Necessary Standard is applied to migrate only essential data to reduce exposure risk. Atlantic.Net will provide customers with documentation assistance, as needed, for internal governance reviews and external compliance audits. Healthcare data migration involves transferring sensitive patient data, such as electronic health records (EHRs), lab results, and billing information, ensuring data accuracy and compliance with regulations like HIPAA. Effective healthcare data migration is critical for improving patient care continuity by enabling access to complete medical histories. Legacy systems often store data in incompatible formats or across disconnected databases, making extraction and migration complex and error-prone. Mismatched data fields, outdated formats, and incomplete records can create data integrity issues during healthcare migrations, leading to errors or loss of critical patient information. ## HIPAA Migration Tiers Atlantic.Net provides HIPAA migration services at multiple levels to address the technical, business, and system complexities that often challenge migration projects in healthcare environments. The Standard Migration level is aimed at constrained environments with a fairly simple architecture. This tier is typically used for simple data and system migrations, where little reconfiguration or architectural changes are necessary. The Advanced Migration tier offers additional planning and execution capabilities and is appropriate for environments with moderate or compliance dependencies. This level will require specialized engineering engagement to align migration efforts, prepare systems, and ensure compliance with established migration processes. The Enterprise Migration tier is intended to support complex or mission-critical healthcare platforms and migration projects, including data center migrations. This tier provides sophisticated migration applications, such as physical-to-virtual conversions, bare-metal restorations, staged data seeding, parallel migrations, and protracted validation testing before production cutover. Enterprise migrations are conducted through complete change management and validation processes to reduce service risk and disruption, with careful planning to avoid compromising patient care and safety. Pilot migrations help organizations detect technical issues early, such as data mismatches and connectivity problems, preventing broader disruptions that could impact patient care. These migrations enable healthcare providers and healthcare teams to focus on patient care by reducing manual workload and minimizing errors. ## Migration Success Program Atlantic.Net also offers a Migration Success Program that covers customer migration expenses for qualified customers. The planning phase defines program eligibility and terms that rely on established infrastructure scope and service adoption criteria. Particles in the program do not change compliance obligations or security controls related to workloads regulated by HIPAA. ## Data Integrity and Validation Ensuring data integrity and validation is during healthcare data migration, as it ensures sensitive patient data remains accurate, complete, and trustworthy throughout the process. Data integrity involves maintaining consistency and accuracy as information moves between systems, while data validation focuses on identifying and correcting errors, inconsistencies, or missing elements. Healthcare organizations must implement complete validation protocols, including detailed data audits, the use of advanced validation tools, and rigorous quality control measures. These steps help detect and resolve discrepancies before they can impact patient care or regulatory compliance. By prioritizing data integrity and validation, healthcare organizations not only protect sensitive patient data but also reinforce the reliability of their healthcare systems, supporting both clinical operations and long-term patient trust. ## Security Standards, Access Controls, and Compliance The HIPAA migrations have been moved to the Atlantic.Net hosting environments, which are intended to support audited security and compliance procedures, ensuring HIPAA-compliant data handling and emphasizing data protection and security throughout the process. These settings meet the HIPAA administrative, physical, and technical safeguards and align with the SOC 2 and SOC 3 control frameworks. HIPAA-compliant cloud migration leverages a secure cloud environment to support compliant healthcare operations, enabling organizations to transition from legacy systems while maintaining regulatory standards. HIPAA compliance is built around three core components: the Privacy Rule, Security Rule, and Breach Notification Rule, which together ensure that Protected Health Information (PHI) is safeguarded both at rest and in transit. The storage and network architecture support encryption, audit logging, and monitoring, along with a BAA, to ensure compliance continuity even after the migration event. Protecting sensitive patient information and health data, including electronic health records, is critical during migration to prevent breaches and unauthorized access. Adoption of Fast Healthcare Interoperability Resources (FHIR) as a standard further facilitates smooth data exchange and interoperability between healthcare systems during migration. ## Cost Savings and ROI Migrating healthcare data to modern, cloud-based platforms can deliver substantial cost savings and a strong return on investment (ROI) for healthcare organizations. By leveraging cloud migration, organizations can reduce the need for expensive on-premises infrastructure, lower maintenance costs, and optimize resource allocation. Cloud environments also offer scalability, allowing healthcare providers to adjust capacity as needed without capital investment. Beyond direct cost reductions, healthcare data migration enhances operational by streamlining workflows and reducing administrative burdens. This enables healthcare providers to devote more time and resources to patient care, improving service quality. Calculating the ROI of healthcare data migration helps organizations make informed decisions about their IT strategies, demonstrating the long-term value of investing in secure, compliant, and data management solutions. ## Incident Response and Monitoring A reliable incident response and continuous monitoring framework is essential for protecting sensitive patient data during and after healthcare data migration. Healthcare organizations must establish complete incident response plans that outline clear procedures for addressing security incidents, such as data breaches or unauthorized access. These plans should detail steps to contain threats, eliminate vulnerabilities, and swiftly restore normal operations to minimize impact. Continuous monitoring plays a critical role in enabling healthcare organizations to detect and respond to security incidents in real time. Implementing advanced security information and event management (SIEM) systems, enforcing multi-factor authentication, and conducting regular security audits are key practices for maintaining vigilance. By integrating these measures, healthcare organizations can ensure regulatory compliance, protect sensitive patient data, and maintain the trust of patients and stakeholders throughout the data migration lifecycle. ## Next Steps Migration regulated under HIPAA entails technical, operational, and compliance considerations that vary significantly by system structure, data sensitivity, and organizational needs. Migration in healthcare requires careful planning to address compliance risks, especially when migrating data from legacy systems to modern EHR or EMR platforms. Although a systematic migration approach provides a framework for safe migrations, every healthcare setting has distinct issues that require careful measurement and consideration. Companies considering a HIPAA-compliant migration should conduct additional assessments to determine whether infrastructure design, security, and operational governance align with applicable compliance requirements. A HIPAA risk assessment is essential before migrating data to identify PHI-related vulnerabilities, define the data scope, and ensure data security. Proper data handling and secure processes are critical when migrating data in healthcare settings to protect patient information and maintain regulatory compliance. These factors are better understood in greater detail, and this knowledge can inform migration strategy, risk management decisions, and long-term platform architecture. More details, including information on HIPAA-compliant infrastructure, security measures, and migration interaction models at Atlantic.Net, may be provided to companies seeking to learn more about regulated hosting and migration planning.   --- # Security by Design in Common Compliance Frameworks: HIPAA, PCI, and NIST Cybersecurity > URL: https://www.atlantic.net/hipaa-compliant-hosting/security-by-design-in-common-compliance-frameworks-hipaa-pci-and-nist-cybersecurity/ | Published: 2025-05-07 | Updated: 2026-05-05 | Author: Gilad Maayan ## What Is Security by Design? Security by design embeds security measures at the core of product development, from initial concept to final deployment. This approach prioritizes identifying and mitigating security threats throughout the entire lifecycle of a product or system. By integrating security principles early on, developers can address potential vulnerabilities before they become exploitation targets. This contrasts with traditional methods where security is often an afterthought, leading to costly retrofitting. [The security by design methodology](https://sternumiot.com/iot-blog/secure-by-design-compliance-aspects-principles-and-best-practices/) is crucial for protecting data and systems against increasingly sophisticated cyber threats. It ensures that security mechanisms are foundational components of any system. Adopting this approach minimizes risk, fosters compliance with regulatory mandates, and builds resilience into the system architecture. ## Security by Design Principles Security by design is guided by principles that ensure systems are built with security at their core. These principles provide a framework for making design decisions that reduce risk, prevent common vulnerabilities, and support long-term resilience. 1. **Least privilege:** Limit access rights for users, processes, and systems to only what is necessary. This minimizes potential damage from accidents or malicious activity by containing the scope of access. 2. **Defense in depth:** Layer multiple security controls throughout the system to provide redundancy. If one layer fails, others remain in place to protect the system. 3. **Secure defaults:** Ensure systems are secure out of the box, with restrictive default settings. Security features should be enabled by default, requiring deliberate action to weaken protections. 4. **Fail securely:** Design systems to handle failures in a secure manner. When errors occur, they should not expose sensitive data or leave the system vulnerable to attack. 5. **Keep it simple:** Avoid unnecessary complexity in system design, as it often introduces hard-to-detect vulnerabilities. Simple designs are easier to audit, test, and secure. 6. **Secure the supply chain:** Evaluate and secure third-party components, including libraries, frameworks, and hardware. Vulnerabilities in external dependencies can compromise the entire system. 7. **Continuous validation:** Implement ongoing testing and security assessments throughout the development lifecycle. Techniques like static analysis, dynamic testing, and penetration testing help uncover vulnerabilities early. 8. **Secure by default configuration management:** Provide and enforce secure configurations through automated tools and policies. Systems should remain secure even as they scale or change over time. ## Security by Design in Common Compliance Frameworks ### Health Insurance Portability and Accountability Act (HIPAA) HIPAA does not explicitly use the term “security by design,” but its security rule requires covered entities and business associates to implement administrative, physical, and technical safeguards that support the intent of the approach. For example, the rule emphasizes risk analysis and risk management (45 CFR §164.308(a)(1)), requiring organizations to identify potential risks and vulnerabilities to electronic protected health information (ePHI) and implement measures to reduce those risks. Technical safeguards such as access controls, audit controls, integrity controls, and transmission security (45 CFR §164.312) also reflect core security by design principles. While HIPAA is flexible and technology-neutral, compliance demands that security considerations be integrated into system design and operations, particularly when handling or transmitting ePHI. ### Payment Card Industry Data Security Standard (PCI DSS) PCI DSS incorporates security by design concepts, especially in requirements related to secure system development and maintenance. Requirement 6 mandates the development of secure systems and applications, including secure coding practices, vulnerability management, and change control processes. Developers must follow industry standards for secure development, such as OWASP, and test applications for security flaws throughout their lifecycle. Requirement 2 (secure configurations) and requirement 10 (logging and monitoring) also support security by design by ensuring systems are securely configured and continuously monitored for suspicious activity. The standard further emphasizes minimizing attack surfaces and limiting access based on business need to know, aligning closely with principles like least privilege and defense in depth. ### NIST Cybersecurity Framework The NIST cybersecurity framework (CSF) adopts a risk-based approach to managing cybersecurity, aligning well with security by design principles. Although it does not prescribe specific technical controls, it provides a structure (Identify, Protect, Detect, Respond, Recover) that encourages early and continuous consideration of security in system design. Within the “Protect” function, the framework highlights secure software development processes (PR.IP-3), configuration management (PR.IP-1), and access control (PR.AC), all of which are central to security by design. NIST also offers more detailed guidance through publications like NIST SP 800-160, which focuses explicitly on engineering trustworthy secure systems. ## Security by Design Implementation Strategies Organizations should implement these measures to ensure security by design. ### 1. Define Security Objectives and Risk Tolerance Begin by identifying critical assets—data, services, infrastructure—and assessing the impact of their compromise. Categorize these assets based on confidentiality, integrity, and availability requirements. Use this classification to define security goals, such as preventing unauthorized access, ensuring data accuracy, and maintaining uptime. Next, perform a risk assessment to map threats to assets. Consider threat actors, attack vectors, likelihood, and potential impact. This helps establish acceptable risk levels, which guide the design of controls and investments. Document these tolerances and revisit them periodically. ### 2. Integrate Security into Development Processes Security integration should start with requirement gathering. Include non-functional security requirements alongside performance and availability metrics. During design, apply architectural threat modeling using frameworks like STRIDE or PASTA to identify and mitigate attack surfaces. In development, enforce secure coding standards such as those from OWASP or CERT. Embed linting tools, dependency checkers, and SAST into the build pipeline to catch issues early. Include security in code reviews and use infrastructure as code (IaC) scanning to identify misconfigurations. Security gates in CI/CD pipelines should trigger alerts or block deployments if critical issues are found. Automate compliance checks and integrate secrets management tools to avoid exposing credentials in code or logs. ### 3. Implement Least Privilege Access Control Design access control based on the principle of least privilege (PoLP). Start by defining roles and permissions narrowly—grant only the exact actions needed. Avoid over-permissioned service accounts or user roles. Use centralized identity and access management (IAM) platforms to enforce access policies and support auditability. For fine-grained control, adopt attribute-based policies where access depends on user context (e.g., department, location, time of access). Enforce separation of duties (SoD) to prevent abuse of combined privileges. Monitor access logs for anomalies, and set up automatic revocation of permissions for inactive users or expired roles. Regularly schedule access reviews and recertifications to ensure that permissions remain appropriate. ### 4. Conduct Regular Security Training Security knowledge decays quickly if not reinforced. Tailor training programs to different audiences—developers need secure coding and code review practices, while operations teams need to know about hardening systems and detecting intrusion signs. Include training on how to recognize phishing, social engineering, and other user-targeted attacks. Use real-world scenarios and incident case studies to illustrate impact and responses. Require completion of baseline training for onboarding and mandate annual refreshers. Simulate attacks through red team exercises or phishing tests to identify human vulnerabilities. Debrief participants and use results to guide further training needs. ### 5. Perform Continuous Security Testing Establish a testing regimen that spans static, dynamic, and interactive methods. SAST tools analyze code for common vulnerabilities (e.g., buffer overflows, SQL injection) before it’s compiled. DAST tools test running applications by simulating attacks in real time. Interactive application security testing (IAST) tools combine the strengths of SAST and DAST by running in QA environments and analyzing runtime behavior. Run dependency scans to detect known CVEs in third-party libraries and containers. Supplement automated tools with manual testing, such as security-focused code reviews and red team exercises. Track findings in issue trackers, assign severity levels, and integrate fixes into sprints. Include regression testing to verify fixes and prevent recurrence. ### 6. Adopt Defense-in-Depth Strategies Build security layers across all architectural domains—network, host, application, and data. Use perimeter defenses like firewalls and VPNs, but don’t rely solely on them. Within networks, use segmentation and microsegmentation to isolate workloads and restrict lateral movement. At the host level, apply endpoint detection and response (EDR) tools, harden operating systems, and enforce patch management. For applications, use WAFs, secure APIs, and runtime protection mechanisms. Encrypt data at rest and in transit using modern protocols like TLS 1.3 and AES-256. Implement monitoring and alerting at each layer to detect anomalous behavior early. Ensure that all layers operate independently—if one fails, the others must continue protecting the system. ### 7. Establish Incident Response Plans Develop an incident response (IR) plan that covers detection, containment, eradication, recovery, and post-incident analysis. Assign roles to individuals and create communication plans for internal stakeholders, regulators, and customers. Integrate IR capabilities with SIEM systems and log aggregation tools to centralize detection and correlation. Establish playbooks for common attack types—ransomware, insider threats, data breaches—and test them regularly through tabletop and red team/blue team exercises. Document every incident, including near misses, and update the IR plan based on lessons learned. Ensure backups are tested for restorability and stored securely to support recovery. --- # Atlantic.Net Introduces High-Performance GPU Cloud Hosting for Business and Research [$250 Credit Promotion Has Been Ended] > URL: https://www.atlantic.net/press-releases/atlantic-net-introduces-high-performance-gpu-cloud-hosting-for-business-and-research/ | Published: 2025-05-20 | Updated: 2026-03-19 | Author: Editorial Team ***Allows for Massive Computer Power for Data and AI Workloads in Less Than 60 Seconds*** **ORLANDO, Fla. (May 20, 2025)** — [Atlantic.Net](https://www.atlantic.net/), a global leader in cloud hosting, has introduced its latest innovation: GPU Cloud Hosting. The service enables users to deploy a GPU Cloud server in less than 60 seconds. This service delivers high-performance, cost-effective AI and machine learning (ML) solutions designed for businesses, developers, and researchers. [Atlantic.Net](https://www.atlantic.net/) is offering a $250 credit to new customers who sign up for its GPU Cloud Platform. The credit can be used for up to 60 days from the signup date. “Our [GPU](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/)Cloud isn’t just about power—it’s about making AI more accessible,” said Marty Puranik, CEO of Atlantic.Net. “We designed this service with ease of use in mind, so businesses of all sizes can harness AI without unnecessary complexity. With 24/7 customer support, clear on-demand, and contract pricing, we’re making AI and high-performance computing available to everyone.” “Our team at the Data Science Association has been very impressed with the performance and reliability of the new GPU Cloud Service from Atlantic.Net. Atlantic.Net is truly a leader in the AI and data science revolution, providing the critical infrastructure needed to transform life, business, and government for a better future,” commented Michael Walker, Chief Technology and Data Officer at the Data Science Association. ### **Optimized for AI Performance** Atlantic.Net’s GPU Cloud allows users to scale AI and ML workloads with precision. Two powerful GPU options are now available: - **High-Memory GPU Configuration** – Designed for training large AI models, running advanced simulations, and deep learning research, featuring 94GB memory and ultra-high bandwidth for high-performance computing at scale. - **Versatile AI GPU** – A flexible, energy-efficient GPU with 48GB memory, ideal for AI development, machine learning, and graphics-intensive workloads. **Beyond GPUs – A Complete AI Environment******Atlantic.Net goes beyond hardware by offering a comprehensive AI cloud ecosystem that includes flexible GPU configurations with options for dedicated or shared resources. The platform is built with enterprise-grade security, meeting HIPAA, PCI DSS, SOC 2/3, and GDPR compliance standards. Users benefit from a 100% uptime SLA, ensuring that mission-critical applications remain online without interruption. Blazing-fast NVMe storage and high-speed network connectivity enhance performance, while a user-friendly control panel simplifies cloud computing for AI users. **About Atlantic.Net** Established in 1994, Atlantic.Net is a privately owned, global cloud services provider that delivers innovative and reliable hosting solutions. Focusing on security, compliance, and customer support, Atlantic.Net offers a wide range of services, including GPU hosting, an award-winning Cloud Platform, HIPAA-compliant hosting, dedicated hosting, and colocation to a large roster of organizations in a variety of industries. Atlantic.Net provides mission-critical services from eight global data center regions located in the United States, Canada, the United Kingdom, and Asia. For more information, visit[Atlantic.Net](https://www.atlantic.net/) or connect with us on[Facebook](https://www.facebook.com/Atlantic.Net),[X (Twitter)](https://twitter.com/AtlanticNet),[LinkedIn](https://www.linkedin.com/company/atlantic-net), and[YouTube](https://www.youtube.com/c/AtlanticNet). ### --- # Introducing High-Performance GPU Cloud Hosting > URL: https://www.atlantic.net/announcements/introducing-high-performance-gpu-cloud-hosting/ | Published: 2025-05-20 | Author: Editorial Team ## ***Massive Power for Data and AI Workloads in Less Than 60 Seconds*** Deploy a GPU server in less than 60 seconds with our new GPU Cloud Hosting service, delivering high-performance, cost-effective AI and machine learning (ML) solutions. This service was designed with ease of use in mind and comes with clear on-demand and contract pricing so businesses, developers, and researchers can harness AI without unnecessary complexity. ## ![](https://www.atlantic.net/wp-content/uploads/2025/05/GPU-Cloud-Hosting-V-4_GPU-Cloud-Server-Hosting.jpg) ## GPU Cloud Hosting Highlights Unleash the raw power of AI and high-performance computing with Atlantic.Net’s Cloud-Based GPU Solutions, powered by cutting-edge NVIDIA GPUs. - **Cutting-Edge Hardware:** The Atlantic.Net Cloud Platform (ACP) offers powerful cloud instances with top-quality SuperMicro and Dell server hardware, SSD storage throughout (with NVMe options available), and ultra-high bandwidth network connectivity. - **Security-Defined Compliant Infrastructure:** We adhere to the highest security standards and maintain key data security and privacy certifications, including HIPAA/HITECH, PCI DSS, SOC 2/3, and GDPR, ideal for sensitive healthcare and scientific data. - **Dedicated Servers:** We provide dedicated GPU server options, ensuring maximum control and performance without resource sharing. - **Always Available Support & 100% Uptime SLA:** Our USA-based support team is available 24/7/365 to help with any GPU query. We are so confident our cloud platform’s reliability and security that we offer a 100% uptime SLA. ## Beyond GPUs – A Complete AI Environment Atlantic.Net goes beyond hardware with a comprehensive AI cloud ecosystem featuring flexible GPU configurations for dedicated or shared resources. Our user-friendly control panel simplifies cloud computing for AI users. Additionally, our GPU Cloud lets you precisely scale AI and ML workloads with two powerful GPU options: - **High-Memory GPU Configuration –**Designed for training large AI models, running advanced simulations, and deep learning research, featuring 94GB memory and ultra-high bandwidth for high-performance computing at scale. - **Versatile AI GPU –**A flexible, energy-efficient GPU with 48GB memory, ideal for AI development, machine learning, and graphics-intensive workloads. ## Getting Started Is Easy! Simply sign up for our [Cloud Hosting Platform](https://cloud.atlantic.net/?page=userlogin), then follow these simple steps. New to Atlantic.Net or want learn more about our GPU Cloud Hosting? [Click here to learn more.](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/) --- # Acceptable Use of Rack Space at Atlantic.Net Facilities > URL: https://www.atlantic.net/acceptable-use-of-rack-space-at-atlantic-net-facilities/ | Updated: 2026-09-16 **Acceptable Use of Rack Space at Atlantic.Net Facilities** Atlantic.Net’s data center rack colocation services include secure, lockable rack space for housing your servers and other IT equipment. Acceptable use of this service includes (listed below) physical building, networking infrastructure, environmental controls, power & cooling, and physical security for all your colocation needs.   Here’s a breakdown of rules regarding what is allowed, and not allowed, within data center: 1. **Equipment and Devices:** - Approved Hardware: Only devices that are explicitly approved by the data center management are allowed to be installed in the racks. - Rack-mountable Equipment: Only rack-mountable equipment can be placed in server racks. Non-rack-mountable devices should be placed in designated areas. Special arrangements can be made for nonstandard equipment with permission of Atlantic.Net staff. - Storage of Personal Items: Personal belongings such as bags, coats, and unnecessary electronic devices are not allowed to be stored inside racks to maintain security and cleanliness. 1. **Cabling and Connections:** - Power and Data Separation: Power cables and data cables must be kept separate to prevent interference and potential hazards. - Proper Labeling: All cables, power cords, and connections must be clearly and accurately labeled for easy identification and troubleshooting. - Cable Length and Management: Cables must be of appropriate length and neatly managed to avoid clutter, airflow obstruction, and tripping hazards. - Customers must provide Power Distribution Units (PDUs) in their dedicated rack.  PDUs must be UL approved, and data center approved equipment and match the power requirements.  PDUs are connected below the raised floor and can only be connected by certified personnel. - No Daisy-Chaining: Connecting power strips to other power strips (daisy-chaining) is generally prohibited due to potential overload and fire hazards.  1. **Safety and Security:** - No Flammables: Combustible materials, such as cardboard, paper, pallets, or flammable liquids, are strictly prohibited inside server racks and on the data center floor to minimize fire risks.  All equipment packaging must be removed prior to entering the data center floor. - No Food or Drinks: Food and beverages are not allowed on the data center floor to prevent contamination and pest infestations. - Secure Access: Server racks must be locked when the customer is not present, and access is to be restricted to authorized personnel only. - Emergency Procedures: Clear pathways for emergency exits are to be kept clear of debris and maintained around the racks and on the data center floor.  - Weapons and Firearms: Strictly prohibited for security reasons. - Customers are responsible for refuse, equipment, and cabling removal.  Customers are encouraged to recycle whenever possible.  Recycling directions and costs can be obtained from Atlantic.Net staff. - Hazardous Materials: Substances that could pose a risk to the equipment, the facility, or personnel are not allowed. 1. **Environmental Control:** - Blanking Panels: Empty rack spaces must be filled with customer-provided blanking panels to prevent hot and cold air mixing, improving cooling efficiency. - Proper Airflow: Equipment is required to be installed in a way that does not obstruct airflow within the rack and around the data center. Airflow must be in accordance with hot and cold aisles. - Hot and Cold Aisle Containment: Atlantic.Net emphasizes the importance of maintaining a separation between hot and cold aisles to ensure efficient airflow and prevent overheating. Please contact Atlantic.Net staff for further information. - Heat Load Limits: The total heat load of the equipment in a rack must not exceed the cooling capacity of the data center. Atlantic.Net staff can help with load planning. - Temperature and Humidity Monitoring: Temperature and humidity levels within the racks and data center are monitored and maintained within the specified range. Some organizations may install their own monitoring equipment, like sensors for temperature or humidity, with approval from the data center provider.  **Acceptable Use of Cage Space at Atlantic.Net Facilities** Atlantic.Net’s data center cages are secure, enclosed areas within a larger data center facility designed to house servers, networking equipment, and other critical IT infrastructure.  They provide physical isolation and restricted access for specific organizations or tenants within the data center, ensuring enhanced security, privacy, and control over their equipment.  Here’s a breakdown of rules regarding what is allowed, and not allowed, within data center cages: **Allowed:** - Racks and Cabinets: Approved enclosed server rack/cabinet with proper hot/cold airflow.  All Racks/Cabinets must be grounded. - IT Equipment: This is the primary purpose of the cage, including servers, storage systems, network switches, routers, and other essential hardware. - Cables & Connectors: Power cables, network cables (fiber optic, Ethernet), and necessary connectors to link equipment within the cage. - Power Distribution Units (PDUs): Customers must provide PDUs in their dedicated rack.  PDUs must be UL approved, and data center approved equipment and match the power requirements.  PDUs are connected below the raised floor and can only be connected by certified personnel. - Basic Tools & Supplies: A limited selection of tools and supplies for maintenance and basic repairs, like screwdrivers, cable ties, and a label printer. - Monitoring Equipment: Temperature and humidity levels within the racks and data center are monitored and maintained within the specified range. Some organizations may install their own monitoring equipment, like sensors for temperature or humidity, with approval from the data center provider.  - Video Monitoring: Atlantic.Net has external video monitoring to cover aisles and public areas.  Customers may install equipment to monitor their own cage.  It is prohibited for customer cameras to capture other cages or racks and customer cameras cannot capture any public areas.   - Work Surfaces: A small desk or table and one small chair are acceptable in cages if they do not obstruct airflow.  These cannot be positioned on hot aisle side of racks and cannot be placed over the perforated floor tiles in front of rack or impede the door opening.  Work surfaces must be kept clean and neat and not have any items accessible from outside the cage. - Storage: Plastic bins are acceptable and can be placed in the cage.  Bins cannot be positioned on hot aisle side of the racks and cannot be placed over the perforated floor tiles in front of the racks or impede the door opening. **Prohibited:** - Open Face/2 Post Racks/Shelving: Open-faced, 2-post racks or open shelving are not allowed inside the cage or on the data center floor except if approved by the data center staff as this impeded airflow.   - Food and Drinks: To prevent spills, pests, and contamination that could damage equipment, no food or drinks are allowed inside the cage or on the data center floor. - Combustible Materials: These are prohibited, not limited to but including cardboard, paper, pallets, and other flammable substances, to reduce fire risk.  All equipment packaging must be removed prior to entering the data center floor. - Storage of Personal Items: Typically, personal belongings like bags, coats, and unnecessary electronic devices are not allowed inside cages to maintain security and cleanliness. - Unauthorized Tools & Equipment: Only necessary tools for essential maintenance are allowed to be brought into the cage. - Modifications to the Cage: Altering the physical structure of the cage or its locking mechanisms without prior approval from the data center provider is usually prohibited. Hanging items on cage walls is strictly prohibited. - Smoking and Tobacco Products: These are prohibited to maintain a clean and safe environment. - Weapons and Firearms: Strictly prohibited for security reasons. - Hazardous Materials: Substances that could pose a risk to the equipment, the facility, or personnel are not allowed.  **Important Considerations:** - Data Center Specific Rules: These guidelines are generally applicable, but specific rules and regulations will vary based on the data center provider and location.  - Hot and Cold Aisle Containment: Atlantic.Net emphasizes the importance of maintaining a separation between hot and cold aisles to ensure efficient airflow and prevent overheating. Please contact Atlantic.Net staff for further information. - Safety: Following safety protocols and guidelines is crucial within the data center environment. - Compliance: Data centers adhere to industry standards and regulations, such as ISO 27001, SOC 2, or HIPAA, which can influence the rules regarding permitted items within cages.  - Customers are responsible for refuse, equipment, and cabling removal.  Customers are encouraged to recycle whenever possible.  Recycling directions and costs can be obtained from Atlantic.Net staff. In addition to the Atlantic.Net’s Acceptable Use policies, customers shall comply with all laws, orders, and regulations of all governmental bodies having jurisdiction over the building and/or customer’s activities and with all the building owner’s and Atlantic.Net’s policies and procedures.  More information may be found at Atlantic.Net’s website, [https://www.atlantic.net](https://www.atlantic.net)/, in your Service Contract and Colocation Master Service Agreement. --- # Artificial Intelligence-Driven Cybersecurity in IoT: Ensuring Secure Connections in an Interconnected World > URL: https://www.atlantic.net/gpu-server-hosting/artificial-intelligence-driven-cybersecurity-in-iot-ensuring-secure-connections-in-an-interconnected-world/ | Published: 2025-05-22 | Updated: 2026-05-04 | Author: Dr. Assad Abbas The [Internet of Things (IoT)](https://www.atlantic.net/life-sciences-pharma-biotech/internet-of-things-vs-internet-of-medical-things/) has entirely transformed the operations of industries, homes, and cities by making everything smarter, more efficient, and automated. The IoT connects devices that communicate over the Internet. From smart thermostats and wearables to automated factories, IoT-based solutions are pervasive. However, with the widespread growth of IoT devices, cyber threats have also increased at the same rate. In 2025, there are already over [18.8 billion IoT devices](https://www.demandsage.com/number-of-iot-devices/) worldwide, which is expected to reach around [40 billion](https://www.demandsage.com/number-of-iot-devices/) by 2030. This rapid expansion not only increases opportunities for hackers to exploit vulnerabilities but also demands proactive measures to secure the devices and the networks. [Artificial Intelligence (AI)](https://www.britannica.com/technology/artificial-intelligence) plays an important role here. AI can quickly analyze large amounts of data, find unusual activity, and even take action to stop attacks before they cause harm. Using AI-driven security is now essential to protect the growing IoT network from new and more complex threats. ## What Makes IoT Vulnerable to Attacks Many IoT devices have weak security, and the reason for this is that they are often developed quickly and lack strong protections. According to [IBM X-Force Threat Intelligence](https://www.ibm.com/thought-leadership/institute-business-value/en-us/report/2025-threat-intelligence-index), over 50% of IoT devices have security vulnerabilities that hackers can exploit. Moreover, around 60% of IoT breaches are due to outdated software and unpatched firmware. Similarly, lots of devices still use default passwords, which make it easy for attackers to gain unauthorized access. The variety of IoT devices, ranging from basic sensors to advanced medical equipment, makes it challenging to implement security measures consistently. As the number of devices increases, the number of entry points for hackers also increases, making IoT networks more vulnerable. Key IoT Cyber Threats include: - **Data Breaches**: Cybercriminals target IoT devices to steal personal and corporate information. About one in three data breaches involve these devices, making them a significant point of vulnerability. - **Ransomware:** In certain industries, like healthcare and manufacturing, attackers lock IoT devices and demand a ransom for access. This type of cyberattack is becoming more prevalent as IoT devices are integrated into critical operations. - **Malware and Botnets:** Harmful software can infect IoT devices and turn them into bots for large-scale attacks. A well-known example of this is the [Mirai botnet](https://www.cloudflare.com/learning/ddos/glossary/mirai-botnet/), which has been responsible for major disruptions to websites and online services. The financial impact of IoT breaches is significantly high. According to a [PSA certified report](https://www.psacertified.org/what-is-psa-certified/why-choose-psa-certified/#:~:text=The%20average%20cost%20of%20a,damages%20will%20total%20%2410%20trillion.), each breach costs businesses an average of $330,000. Additionally, sectors subject to more strict regulations often face even greater penalties. Besides financial losses, around [78%](https://jumpcloud.com/blog/iot-security-risks-stats-and-trends-to-know-in-2025) of consumers say they would discontinue a company’s services after a major IoT-related breach according to the IoT Security Foundation. This highlights the severe reputational damage businesses have to experience due to IoT breaches. Securing IoT devices and networks is therefore essential to protect privacy, maintain trust, and ensure the smooth operation of the increasingly connected smart environments. ## The Role of Artificial Intelligence in IoT Cybersecurity As IoT devices increasingly proliferate, conventional security approaches find it challenging to address the expanding risks and complexities. Here is why artificial intelligence is becoming essential for safeguarding IoT networks ### Why Traditional Security Falls Short Traditional security tools, such as firewalls and antivirus software, were developed for standard computer networks without consideration for the speed and scale of IoT networks. IoT devices continuously transmit vast amounts of data, but these older tools cannot process this data efficiently to prevent attacks before they occur. One of the main problems with traditional security is signature-based detection. This method is suitable for only known threats. It cannot identify new or evolving attacks. Moreover, traditional tools’ fixed security rules are ineffective for IoT networks. Since IoT networks are constantly changing, these fixed rules cannot adapt to the rapid developments in IoT environments. On the other hand, AI follows a different approach. It processes data in real-time and uses predictive techniques to detect threats before they cause damage. With AI, devices can learn from patterns and adapt to new, unknown attacks, thus ensuring a more dynamic and responsive defense. ### How AI Transforms IoT Security AI plays an important role in securing IoT networks. AI models can analyze data from all connected devices in real-time and identify unusual activity. This helps AI systems predict threats before they result in any harm and stop them early. With predictive threat detection, AI analyzes past data to find patterns or unusual behavior that could signal an attack. This helps AI to act quickly and prevent a data breach. In addition, AI systems can automatically respond to threats and can reduce the need for human intervention. For example, if a threat is detected, AI can isolate the affected device or block harmful traffic, thereby stopping the attack. Different AI techniques are used to secure IoT devices. Machine Learning (ML) is one of the most common. It helps AI learn from past data and improve over time. In IoT, ML can detect new attacks that have not been witnessed before. Deep Learning (DL) is a more advanced form of ML. It can understand more complex data and detect hidden threats that simpler models might not be able to detect. This is useful in IoT networks, where threats can be challenging to detect. Anomaly detection is another vital AI technique. It enables AI to identify unusual patterns within IoT networks, such as unexpected data transmissions. When such irregularities occur, AI marks them as potential security threats, facilitating quicker responses and enhancing overall protection. Finally, [federated learning](https://www.analyticsvidhya.com/blog/2021/05/federated-learning-a-beginners-guide/) enables AI models to learn from data across multiple devices without sharing sensitive information. This approach preserves privacy while still enabling AI to enhance security. ## AI-Driven Approaches to Securing IoT Network Below are some important AI-driven approaches currently being employed to strengthen IoT security. ### Predictive Threat Detection and Anomaly Detection AI systems continuously analyze the data generated by connected devices to find anomalies that deviate from standard behavior. For example, suppose an IoT device like a smart thermostat unexpectedly sends large amounts of data or connects to an unfamiliar endpoint. In that case, AI systems will detect this as suspicious activity and generate an alert. This preventive approach helps recognize possible threats at an early stage before they escalate into significant issues. ### Automated Incident Response Swift responses are essential in the domain of IoT security to avoid damage on a large scale. AI-powered Security Operations Centers (SOCs) automatically speed up the reaction time by handling several response tasks. When the AI system detects suspicious activity, it can immediately isolate compromised devices, block harmful traffic, and notify human analysts to investigate further. This automation not only speeds up the process but also reduces the workload of cybersecurity teams. ### Adaptive Access Controls and Behavioral Authentication In addition to automated incident response, AI improves access management in IoT networks. AI systems continuously track user and device behavior rather than just relying on fixed credentials. AI can promptly block or limit access if a user or device attempts to access resources from an unusual location or behaves suspiciously. This approach is based on the [zero-trust security](https://www.cloudflare.com/lp/dg/product/zero-trust-security/?utm_medium=cpc&utm_source=google&utm_campaign=ao-fy-acq-apac_en_in-modernsec-txt-general-generic_zerotrust_alpha&utm_content=alpha_generic_zerotrust_core&utm_source=google&utm_medium=cpc&utm_campaign=CLOUD_ACQ_AOFY_MDS_GOOGLE_GENERAL_TXT_APAC-EN_IN_TOFU_GENERAL_X_LEAD-GEN_GENERIC-ZEROTRUST-ALPHA&utm_content=Alpha_Generic_ZeroTrust_Core&campaignid=71700000121547035&adgroupid=58700008861645762&creativeid=682737031178&&utm_term=zero%20trust_go_cmp-20807450796_adg-157153681858_ad-682737031178_aud-410492152481:kwd-366936102151_dev-c_ext-_prd-_sig-Cj0KCQjwlYHBBhD9ARIsALRu09qXlSEbeu2MY582Mm8GkkPaDVZ5Tgvmni_8fwd3QwfS_Ky7Vl7i8WUaAhnSEALw_wcB&gad_source=1&gad_campaignid=20807450796&gbraid=0AAAAApvFJgxGrXxuhk-Iva6wj5Vsk20NL&gclid=Cj0KCQjwlYHBBhD9ARIsALRu09qXlSEbeu2MY582Mm8GkkPaDVZ5Tgvmni_8fwd3QwfS_Ky7Vl7i8WUaAhnSEALw_wcB&gclsrc=aw.ds) model, which assumes no device or user should be trusted without proper verification. By dynamically adjusting access rights based on real-time behavior, AI helps prevent unauthorized access and keeps IoT networks secure. ### Edge AI and Federated Learning for Privacy and Efficiency Edge AI has become essential for timely threat detection and privacy protection. It involves processing data locally on IoT devices or nearby edge gateways. As a result, the time to identify and respond to threats reduces significantly. In addition, since the data does not need to be transmitted to a centralized server, edge AI helps preserve privacy as well. Additionally, federated learning enables multiple IoT devices to train AI models using local data without sharing sensitive information. This decentralized method improves security while maintaining privacy. Moreover, federated learning enables AI to use collective intelligence to detect threats more accurately across the entire network. ## The Rise of AI-Powered Cyber Threats in IoT Security While AI is helping secure IoT devices and networks, cybercriminals are also using it to carry out more advanced attacks. Recently, AI-driven threats have become a serious concern for the cybersecurity domain. AI-generated phishing Attacks are becoming more advanced and malicious. Cybercriminals use AI to create realistic phishing emails that look legitimate, making it difficult for traditional security systems to spot them. Deepfake Technology is another tool being widely used by attackers. Hackers can create fake audio and videos that mimic trusted people. This is used in social engineering attacks, like fake wire transfers or leaking sensitive data. In addition, adaptive AI-driven malware is a new kind of malicious software. It can change its behavior to avoid detection, making traditional security systems ineffective. This emerging threat demands more innovative and more flexible security measures. ### 5 Best Practices for Securing IoT with AI The organizations should: - Map the IoT environment and identify all connected devices. Security efforts must focus on devices that handle sensitive data or are highly important. - Implement AI-based machine learning and anomaly detection tools to monitor IoT device behavior in real-time. This will help detect unusual activities quickly. - Enforce strict access controls using AI-powered behavioral analytics to continuously verify identities and adjust access based on risk levels. - Continuously retrain AI models with updated data to maintain detection accuracy and stay ahead of new threats. - Integrate AI security solutions that comply with regulations such as GDPR and CCPA, ensuring the protection of sensitive information and meeting legal requirements. ## The Bottom Line The growth of IoT devices brings numerous benefits but also increases security risks. Many devices have weak protection mechanisms, making them easy targets for attackers. Traditional security methods are insufficient to handle the fast and large-scale data of IoT networks. To that end, AI offers a better way by quickly finding unusual activity and stopping threats early. AI can learn from data, adapt to new attacks, and respond automatically, which helps protect connected devices and networks. At the same time, attackers are also using AI to develop more advanced threats. This means security systems must keep improving and being flexible. Organizations should carefully know their IoT devices, use AI tools to observe device behavior in real time, control access strictly, and update their AI models often. Following these steps will help keep IoT networks safer and protect privacy and trust. --- # The Role of High-Performance Computing in Advancing AI for Climate Solutions > URL: https://www.atlantic.net/gpu-server-hosting/the-role-of-high-performance-computing-in-advancing-ai-for-climate-solutions/ | Published: 2025-05-23 | Updated: 2026-05-04 | Author: Dr. Tehseen Zia High-performance computing (HPC) and artificial intelligence (AI) are playing increasingly important roles in addressing the complex challenges posed by climate change. The Earth’s climate system is a very complex process and tracking it requires collecting large amounts of detailed data. Managing and analyzing this vast and complex data demands powerful computing and intelligent analytical techniques. This article explores the individual and combined roles of HPC and artificial intelligence in supporting climate solutions. ## The Role of HPC in Climate Computing Weather and climate centers across the globe have long relied on high-performance computing to track, analyze, simulate, and predict weather systems and climate patterns. These tasks require immense computational resources that only specialized HPC systems can provide. The computational requirements for climate solutions are high because Earth’s climate system depends on many interacting components including atmosphere, oceans, land, and ice. Each of these components operate on different time scales and physical dimensions, which creates a complex process that requires powerful computing systems to understand. Traditional climate modeling approaches have been limited by available computing power. Even with powerful supercomputers, scientists have had to make compromises on resolution, complexity, or forecast length. Climate models with higher resolution can capture more detailed processes but require significantly more computing resources. This is where the HPC becomes essential for climate solutions. HPC enables researchers to run complex global models on high resolution data.  For example, the [Community Earth System Model](https://www.cesm.ucar.edu/) has millions of lines of code which can only run on an HPC cluster. ## The Increasing Role of AI in Climate Solutions Climate monitoring systems, including satellites, weather stations, and sensors collect terabytes of climate data every day. Traditional methods often struggle to analyze this data due to its huge volume and complexity. This is where AI becomes essential for climate solutions. It can rapidly process huge amounts of data and uncover patterns that might be difficult for humans to detect. AI is being applied in many areas to support climate solutions. For example, AI algorithms analyze satellite imagery to [detect deforestation](https://www.deepblock.net/blog/the-role-of-artificial-intelligence-in-deforestation-detection) and melting glaciers. They also use historical data to [predict natural disasters](https://www.nature.com/articles/s41467-025-56573-8) like floods and heatwaves. Machine learning models improves [weather forecasts](https://www.nature.com/articles/s41586-024-08252-9) by analyzing real-time weather data with high accuracy and speed. Additionally, AI enhances climate models to provide more reliable predictions. Despite forecasting, AI helps to [reduce carbon emissions](https://www.equans.com/news/how-artificial-intelligence-is-driving-decarbonisation) by optimizing energy systems, transportation, and industrial processes. Recent advances in AI have further enhanced its potential in climate applications. For instance, a collaboration between NASA and IBM Research produced an [AI geospatial foundation](https://www.earthdata.nasa.gov/news/blog/ibm-geospatial-foundation-model-trained-hls-data) model trained on [Harmonized Landsat and Sentinel-2 data](https://hls.gsfc.nasa.gov/). This publicly available model accurately detects burn scars, maps floodwaters, and classifies crops and land use. The partnership combined NASA’s scientific data and expertise with IBM’s computing power and AI capabilities. Similarly, Google recently introduced the [Geospatial Reasoning framework](https://sites.research.google/gr/geospatial-reasoning/#:~:text=Geospatial%20Reasoning%20leverages%20this%20long,a%20wide%20range%20of%20problems.&text=Using%20AI%20to%20make%20flood%20forecasting%20information%20universally%20accessible.), which integrates its generative AI model Gemini with specialized geospatial models. This framework can answer complex questions about climate data in natural language. For example, when asked about the impact of a recent hurricane on infrastructure, Gemini can analyze satellite images to assess damage, uses weather data to predict ongoing risks, and incorporates demographic information to help prioritize relief efforts. ## How HPC Drives AI-Enabled Climate Solutions As AI’s role in climate solutions increases, the demand for HPC is also growing. HPC systems use thousands of processors working in parallel to solve very large problems. They often include GPUs and other accelerators that speed up machine learning and scientific computations. HPC infrastructure is well-suited for AI-enabled climate solutions due to its following features: - **Massive Parallelism:** HPC systems run many tasks at the same time across thousands of cores or GPUs. This parallel processing is needed to train deep learning models and run high-resolution climate simulations quickly. - **High-Speed Networking and I/O:** All parts of an HPC cluster, including the interconnects, memory, and storage, are very fast and designed for high throughput. These systems can move large volumes of climate data (like satellite imagery) without any communication bottlenecks. - **Specialized Accelerators:** Many HPC centers [provide GPUs](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/) or other AI accelerators. These chips can perform the types of calculations used in machine learning much more efficiently than standard CPUs. For climate AI workloads, accelerators can dramatically speed up model training and data analysis. - **Large Memory and Storage:** Climate models and AI data sets can be huge. HPC nodes typically have large amounts of RAM or high-bandwidth memory, and the clusters use parallel file systems to store terabytes of data. This prevents memory bottlenecks when processing global datasets. - **Scalability:** HPC clusters can scale up by adding more nodes. In the cloud, users can enhance their resources on demand. This scalability is important for climate projects that may suddenly need a lot of compute power (for example, to run an ensemble of forecasts). ## Cloud-Based HPC for Accessibility and Cost Efficiency Cloud-based HPC combines the power of supercomputers with the flexibility of the cloud. In a cloud HPC environment, researchers can employ powerful clusters without owning them. They can scale up or down as needed, and they only pay for the resources they use. This on-demand access makes it possible for smaller universities and startups to develop climate solutions without investing in expensive data centers. For example, [Planette](https://www.planette.ai/)’s team uses a mix of Amazon and Google cloud resources to run their climate models and AI algorithms. This multi-cloud approach enables them to scale and optimize costs while having backup options. In practice, cloud HPC makes it easier for diverse teams around the world to collaborate on climate AI projects, because they can share data and compute through the cloud. Some of the key features of cloud-based HPC are as follows: - **On-Demand Access and Scalability:** Cloud HPC allows users to access supercomputing power as needed and release it when it is no longer required. They can also increase or decrease computing resources on the fly. - **Pay-As-You-Go Cost Model:** Instead of buying and maintaining expensive hardware, organizations pay for compute time. This model avoids large upfront investments in dedicated HPC machines. It can be much more cost-effective for starting or growing projects. - **Flexibility:** Cloud platforms offer a variety of hardware (different CPUs, GPUs, etc.) and software environments. Climate researchers can choose the configuration that best fits their workload. - **Multi-Cloud Optimization:** By using multiple cloud providers (as Planette does), users can improve performance and resilience. It also enables teams to compare costs between vendors and avoid dependency on a single provider. ## Challenges and Considerations Despite the benefits, combining HPC and AI for climate work brings some challenges: - **Energy and Sustainability:** Both HPC and AI have high energy demand. Training large [AI models](https://www.atlantic.net/gpu-server-hosting/gpu-hosting-for-ai-projects-top-gpu-hosts-for-ai-in-2025/) may run thousands of GPUs for days or weeks which consume vast amounts of power. Modern supercomputers themselves can draw as much power as a small town. This significant energy consumption brings both financial costs and environmental impacts. Researchers must consider energy efficiency and possibly use renewable power or advanced cooling to mitigate this. - **Data Complexity:** Climate data are not only large in volume but also complex in nature due to multiple variables, time series, and different formats. Managing, storing, and cleaning this data is difficult. HPC systems need robust data pipelines and quality control to handle these challenges. - **Skilled Workforce:** Running HPC and AI systems requires specialized skills. Scientists need training in parallel programming, machine learning, and data science. A recent report argues that investment in HPC should include “training for people to use them”. In practice, there is often a shortage of experts who can employ AI and HPC for developing climate solutions, so workforce development is a key need. ## Final Thoughts High-performance computing and AI have become key technologies in developing modern day climate solutions. This combination helps climate solution providers to learn from massive datasets and generate actionable forecasts. Ongoing advances in HPC hardware, smarter AI algorithms, and greater accessibility are speeding up progress in climate action. By transforming vast amounts of climate data into actionable insights, HPC and AI are vital tools for scientists and decision-makers working to build climate solutions. --- # Atlantic.Net Offers One Year of Free Cloud Hosting [Offer has ended] > URL: https://www.atlantic.net/announcements/atlantic-net-offers-one-year-of-free-cloud-hosting/ | Published: 2025-05-28 | Updated: 2026-06-04 | Author: Alexander Wise Celebrating 31 years in business, [Atlantic.Net](https://www.atlantic.net/) is now offering new clients an opportunity for one year of free cloud hosting backed by [Atlantic.Net](https://www.atlantic.net/)’s eight global data centers, providing businesses worldwide with high performance and reliability. All new customers receive a free cloud platform for a year, which includes 8GB RAM, 2 vCPU, 80 GB SSD storage, and 5TB monthly data transfer. [![](https://www.atlantic.net/wp-content/uploads/2025/05/Double-the-Performance-08-01.jpg)](https://cloud.atlantic.net/?page=signup) Our [G3 8GB plan](https://www.atlantic.net/cloud-platform/) is ideal for developers and businesses to deploy larger applications with our free-to-use Cloud Hosting now with more powerful resources. In addition to the free G3.8 GB server, the free tier also includes 50 GB of Free SSD Block Storage and Snapshots for one full year and comes with all the benefits of the Atlantic.Net Cloud Platform: - Fault-tolerant, ultra-fast performance: Engineered for maximum uptime and speed. - Award-winning Cloud Servers: Backed by a proven track record of excellence. - Secure Block Storage: Safeguard your critical data with robust security measures. - One-Click Applications, DNS, Private Networking, RESTful API: Streamline your workflow and development processes. - Optional Data Backup & Managed Services: Tailor your solution to your needs. - 24/7 U.S.-Based Expert Support: Get the help you need whenever needed. The service includes a 100% uptime service-level agreement, ensuring mission-critical applications stay online. Blazing-fast NVMe storage and high-speed network connectivity boost performance, while a user-friendly control panel simplifies cloud computing for AI users. [Get Started](https://cloud.atlantic.net/?page=signup) --- # Atlantic.Net Offers One Year of Free Cloud Hosting to New Business and Healthcare Clients [Offer has ended] > URL: https://www.atlantic.net/press-releases/atlantic-net-offers-one-year-of-free-cloud-hosting-to-new-business-and-healthcare-clients/ | Published: 2025-05-28 | Updated: 2026-06-04 | Author: Alexander Wise *Promotion Aims to Support Growing Organizations with Secure, Scalable Cloud Solutions* **ORLANDO, Fla. (May 28, 2025)** — Celebrating 30-plus years in business, [Atlantic.Net](https://www.atlantic.net/), a global leader in cloud hosting, is offering new clients an opportunity for one year of free cloud hosting backed by [Atlantic.Net](https://www.atlantic.net/)’s eight global data centers, providing businesses worldwide with high performance and reliability. All new customers receive a free cloud platform for a year, which includes: - 8GB RAM - 2 vCPU - 80 GB SSD storage - 5TB monthly data transfer “Our [G3 8GB plan](https://www.atlantic.net/cloud-platform/) is ideal for developers and businesses to deploy larger applications with our free-to-use Cloud Hosting now with more powerful resources,” said Marty Puranik, CEO of Atlantic.Net. In addition to the free G3.8 GB server, the free tier also includes 50 GB of Free Block Storage and Snapshots for one full year and comes with all the benefits of the Atlantic.Net Cloud Platform: - Fault-tolerant, ultra-fast performance: Engineered for maximum uptime and speed. - Award-winning Cloud Servers: Backed by a proven track record of excellence. - Secure Block Storage: Safeguard your critical data with robust security measures. - One-Click Applications, DNS, Private Networking, RESTful API: Streamline your workflow and development processes. - Optional Data Backup & Managed Services: Tailor your solution to your needs. - 24/7 U.S.-Based Expert Support: Get the help you need whenever needed. Recently, [Atlantic.Net](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/) announced its new GPU Cloud, which enables users to scale artificial intelligence and machine learning workloads with precision. Atlantic.Net now offers two high-performance GPU options: - **High-Memory GPU Configuration** – Designed for training large AI models, running advanced simulations and conducting deep learning research. It features 94 GB of memory and ultra-high bandwidth to support high-performance computing at scale. - **Versatile AI GPU** – A flexible, energy-efficient option with 48 GB of memory, ideal for AI development, machine learning and graphics-intensive tasks. Atlantic.Net offers more than just hardware. Its AI cloud ecosystem includes flexible GPU configurations with dedicated or shared resource options. The platform is built with enterprise-grade security and meets compliance standards including HIPAA, PCI DSS, SOC 2/3 and GDPR. The service includes a 100% uptime service-level agreement, ensuring mission-critical applications stay online. Blazing-fast NVMe storage and high-speed network connectivity boost performance, while a user-friendly control panel simplifies cloud computing for AI users. **About Atlantic.Net** Established in 1994, Atlantic.Net is a privately owned, global cloud services provider that delivers innovative and reliable hosting solutions. Focusing on security, compliance, and customer support, Atlantic.Net offers a wide range of services, including GPU hosting, an award-winning Cloud Platform, HIPAA-compliant hosting, dedicated hosting, and colocation to a large roster of organizations in a variety of industries. Atlantic.Net provides mission-critical services from eight global data center regions located in the United States, Canada, the United Kingdom, and Asia. For more information, visit[Atlantic.Net](https://www.atlantic.net/) or connect with us on[Facebook](https://www.facebook.com/Atlantic.Net),[X (Twitter)](https://twitter.com/AtlanticNet),[LinkedIn](https://www.linkedin.com/company/atlantic-net), and[YouTube](https://www.youtube.com/c/AtlanticNet).   ### --- # Atlantic.Net Wins 2025 Fortress Cybersecurity Award for Product or Service – Artificial Intelligence > URL: https://www.atlantic.net/press-releases/atlantic-net-wins-2025-fortress-cybersecurity-award-for-product-or-service-artificial-intelligence/ | Published: 2025-06-03 | Updated: 2025-05-23 | Author: Alexander Wise **FOR IMMEDIATE RELEASE** **ORLANDO, FL — June 3, 2025** — Atlantic.Net announced today that it has been named a winner in the 2025 Fortress Cybersecurity Awards, presented by the Business Intelligence Group. The company was recognized in the category of **Product or Service – Artificial Intelligence** for its work in protecting systems, infrastructure, and data from the growing threat landscape. The Fortress Cybersecurity Awards program honors the industry’s leading companies and professionals who are going beyond compliance to build and maintain secure systems and processes. Winners are selected based on innovation, measurable impact, and commitment to security best practices. “The volume and complexity of threats facing organizations today is growing by the minute,” said Russ Fordyce, CEO of the Business Intelligence Group. “The winners of this year’s Fortress Cybersecurity Awards are not only keeping up—they’re setting the pace. We’re proud to honor Atlantic.Net for building systems and solutions that make us all more secure.” Atlantic.Net was recognized for its Cloud Hosting and Storage Solutions, which leverage artificial intelligence to enhance cybersecurity and protect against online threats. “We are honored to receive this award from the Business Intelligence Group,” said Marty Puranik, CEO of Atlantic.Net. “Security isn’t just part of our business—it’s at the core of everything we do. This recognition validates the work our team puts in every day to stay ahead of threats and protect our clients, partners, and communities.” To learn more about the Fortress Cybersecurity Awards, visit:[https://www.bintelligence.com/awards/fortress-cybersecurity-awards](https://www.bintelligence.com/awards/fortress-cybersecurity-awards) **About Atlantic.Net** Founded in 1994 from a University of Florida dorm room by Marty Puranik and two classmates, Atlantic.Net began as ICC Computers and quickly established a reputation for quality service. In 1995, they launched one of the first commercial Internet services in North Florida. Over the decades, Atlantic.Net has evolved into a global cloud services provider, specializing in secure, high-performance GPU Hosting, cloud solutions, including cloud hosting, dedicated servers, and colocation. The company is known for its focus on security, compliance, and simplifying user experience, offering a range of certifications such as SSAE 18 SOC 2 and SOC 3, HIPAA, and HITECH audits, and now serves businesses worldwide with data centers in multiple global regions. **About Business Intelligence Group**[ ](https://www.bintelligence.com) The Business Intelligence Group was founded with the mission of recognizing true talent and superior performance in the business world. Unlike other industry award programs, these programs are judged by business executives with real-world experience. The organization’s proprietary scoring system measures performance across multiple business domains and rewards companies whose achievements are significant and measurable. **Contact Atlantic.Net Public Relations:** [**pr@atlantic.net**](mailto:pr@atlantic.net) --- # 12 Essential AI Tools for Developers in 2026 > URL: https://www.atlantic.net/gpu-server-hosting/top-ai-tools-for-developers/ | Published: 2025-06-09 | Updated: 2026-04-10 | Author: Richard Bailey   ## What Is an AI Development Tool? An AI Development Tool is a software application or platform that helps people create, test, and deploy artificial intelligence (AI) and machine learning (ML) models and applications. In 2026, this definition has expanded beyond model building to include autonomous coding agents that operate directly inside developer workflows. These tools don’t just suggest snippets—they can navigate entire repositories, reason over dependencies, and assist with build and deployment tasks. Coding is one subset of AI tools that is gaining significant traction, but AI tools can be much more, including: - Used to write and manage code generation (AI writing assistants and IDE-integrated agents). - Prepare and process data for analysis. - Build or train AI models. - Test and evaluate trained models. - Operate through terminal-based agents and IDE extensions to automate repetitive development tasks. - Automate tasks to aid project management. AI Dev Tools cover the broad scope of the development lifecycle, and there are tools suitable for every type of developer. Modern platforms increasingly support MCP (Model Context Protocol), allowing shared context across editors, terminals, and services. There are even no-code platform options emerging, making AI more accessible to a wider range of users. ## Should I Use Paid or Free AI Tools? With so many AI tools available, listing them all would be impossible. Many are free or open source, but the majority of leading AI tools offer limited free tiers designed for experimentation, while reserving advanced capabilities for paid plans. This is especially true for tools that provide deep workflow integration, terminal-based agents, or full-repository context. Paying for AI tools is becoming increasingly common due to the high costs of operating large language models and maintaining always-on IDE extensions and autonomous agents. That said, even a free tier can provide meaningful access to core features, allowing developers to evaluate workflow fit, MCP compatibility, and agent behavior before committing to a paid plan. ## Top AI Development Tools Here’s our deep dive into some of the standout tools shaping the AI landscape in 2026. Today’s leading tools emphasize workflow integration over standalone features, combining IDE extensions, terminal-based agents, and repository-level awareness to support developers end to end. ### #1: Cursor ![](https://www.atlantic.net/wp-content/uploads/2025/08/cursor-logo.png) #### About Cursor: Cursor is an AI-first code editor, built around integrating AI directly into the development workflow. It’s not just VS Code with an AI plugin; it’s a redesigned IDE where the AI assistant is embedded at the core. Cursor allows developers to chat with their codebase, generate code from prompts, debug, and refactor complex sections using an AI agent. In 2026, Cursor stands out for its ability to reason across entire repositories and operate as a persistent coding agent rather than a reactive autocomplete tool. Its goal is to act as an intelligent partner that understands the full context of your project, from individual files to overall architecture. This is the Cursor editor, built for developers who want faster coding with built-in AI-powered suggestions and automation. ![cursor](https://www.atlantic.net/wp-content/uploads/2025/02/cursor.png) Image Source: Cursor #### Advantages: - **Repository-Level Understanding**: Can reason across your entire project, making it effective for large codebases and multi-service applications. - **Intuitive AI Chat**: Allows for natural language commands to edit, generate, and debug code, resembling pair programming with an advanced AI agent. - **Error Resolution**: Can often automatically identify and suggest fixes for bugs, speeding up debugging. - **Refactoring:** Simplifies large-scale code changes by understanding developer intent. - **Workflow Integration**: Operates as an IDE extension that fits naturally into existing development habits. - **Migration**: Helps migrate codebases or adopt new technologies, such as converting a Python script to TypeScript. #### Disadvantages: - **Learning Curve**: Leveraging its full capabilities requires adjusting how developers delegate tasks to AI agents. - **Resource Intensive**: Cursor can be demanding on system resources. - **Dependency on AI Models**: The quality of suggestions depends on underlying LLMs, and manual review is still required. - **Agent Limitations**: Complex business logic may still need explicit guidance. #### Target Audience: - **Software Developers**: Suitable for anyone who writes code regularly. - **Complex Projects**: Ideal for large repositories where context matters. - **Tight Deadlines**: Teams looking to accelerate delivery without sacrificing structure. - **Early Adopters of Agent-Based Workflows**: Developers embracing MCP-compatible tools and autonomous coding agents. ### #2: RunwayML ![](https://www.atlantic.net/wp-content/uploads/2026/02/runway.png) #### About RunwayML: RunwayML, founded in 2018, has positioned itself as a leading no-code platform for artists, designers, and creators looking to use AI without writing code. While not a traditional developer tool, RunwayML remains relevant in 2026 workflows by integrating AI-driven creative output directly into production pipelines. Runway provides a suite of “AI Magic Tools” that cover a wide array of creative tasks, from video generation (text-to-video, video-to-video) and image generators to 3D texture creation and music generation. These tools are increasingly used alongside developer environments to support content-heavy applications, demos, and marketing assets tied to software projects. Runway offers a web-based interface to complex AI models, enabling users to experiment and create high-quality visuals with ease, often using pre-built templates or styles. Although it does not operate as a terminal-based agent or IDE extension, Runway complements developer workflows by accelerating creative iteration without engineering overhead. It’s a strong option for content creation! Get started with RunwayML, choose from ready-made apps or customize your own creative pipeline to produce high-quality media effortlessly. ![RunwayML](https://www.atlantic.net/wp-content/uploads/2025/06/RunwayML.png) Image Source: RunwayML #### Advantages: - **User-Friendly Interface**: Designed for creatives, not just AI experts. - **Wide Range of Creative Tools**: A comprehensive suite for video, image, and audio generation. - **No-Code/Low-Code**: You don’t need to be a programmer to get started. - **Rapid Prototyping**: Excellent for quickly visualizing ideas and generating assets for product launches or demos. - **Workflow Support**: Fits well into modern content pipelines that support developer-led projects. - **Community and Learning**: Offers tutorials and a community for users to learn and share clips. #### Disadvantages: - **Output Control**: Achieving specific results can require multiple iterations. - **Computational Costs**: High-resolution video generation consumes credits quickly. - **“AI Look”**: Generated content may have a recognizable AI aesthetic. - **Limited Developer Integration**: Lacks native IDE or terminal-based agent support. #### Target Audience: - **Artists & Designers**: Creatives exploring new AI-driven mediums. - **Filmmakers & Video Editors**: Professionals and hobbyists needing AI video tools. - **Content Creators**: Those producing visuals for multiple platforms. - **Marketers**: Teams creating visuals tied to product launches or campaigns. - **Small Businesses**: Companies producing creative assets without dedicated AI teams. - **Product Teams & Developers**: Those needing fast creative output to support software demos, documentation, or marketing. ### #3: Perplexity AI ![](https://www.atlantic.net/wp-content/uploads/2025/06/perplexity-logo.jpg) #### About Perplexity AI: Founded in 2022, Perplexity AI aims to be an “answer engine” rather than a traditional search engine. It provides direct answers to user queries by synthesizing information from multiple web sources and citing them, offering a conversational approach to information retrieval. In 2026, Perplexity is increasingly used as a research layer inside developer and knowledge-worker workflows rather than a standalone search replacement. Its purpose is to deliver accurate, well-sourced answers, making it a strong tool for research, learning, and knowledge management. While not an IDE extension or terminal-based agent, Perplexity complements development workflows by quickly grounding decisions with cited context. It excels at understanding intent and summarizing information efficiently. Leverage Perplexity AI to summarize documents, verify information, and explore topics with reliable, source-backed insights. ![Perplexity AI](https://www.atlantic.net/wp-content/uploads/2025/06/Perplexity-AI.png) Image Source: Perplexity AI #### Advantages: - **Direct Answers with Citations**: Saves time by summarizing information and linking directly to sources. - **Conversational Interface**: Supports follow-up questions for iterative research. - **Reduced Information Overload**: Cuts through long search result pages with concise responses. - **Focus Modes**: Offers modes like Academic and Writing to tailor outputs. - **Good for Research**: Useful for synthesizing information for documentation, specs, and planning. - **Workflow Support**: Commonly used alongside IDEs and terminals as an external research companion. #### Disadvantages: - **Inaccuracies/Hallucinations**: Can still misinterpret queries or synthesize incorrect information. - **Depth of Information**: Specialized topics may require deeper primary-source review. - **Bias in Sources**: Outputs may reflect biases present in indexed web content. - **Limited Integration**: Does not function as a native IDE extension or autonomous agent. #### Target Audience: - **Students & Academics**: For research and learning. - **Researchers**: Professionals synthesizing and citing information quickly. - **Writers & Journalists**: For background research and fact-checking. - **Professionals Seeking Quick Answers**: Business users needing fast, sourced insights. - **Developers & Product Teams**: Those needing rapid, cited context to support design, architecture, and technical decisions. ### #4: Scale AI ![](https://www.atlantic.net/wp-content/uploads/2025/06/scale-logo.png) #### About Scale AI: Founded in 2016, Scale AI has become a critical player in AI development by focusing on one of the hardest problems in machine learning: high-quality training data. They recognized early that even the most advanced models fail without large volumes of accurately labeled data. In 2026, Scale AI plays a foundational role in supporting agent-based and MCP-compatible AI systems that depend on reliable feedback loops. Scale AI provides data annotation, curation, and validation services, effectively supplying the “fuel” for machine learning models. Its infrastructure increasingly supports workflows tied to LLM development, evaluation, and reinforcement learning pipelines rather than isolated annotation tasks. This enables companies to build and deploy AI software backed by dependable, human-verified data. Collaborate efficiently using Scale AI, with built-in tools for team management, billing, and project coordination. ![Scale AI](https://www.atlantic.net/wp-content/uploads/2025/06/Scale-AI.png) Image Source: Scale AI #### Advantages: - **High-Quality Data Annotation**: Delivers consistent labeling across images, text, audio, and LiDAR. - **Scalability**: Handles the massive datasets required for enterprise AI systems. - **Tooling and Platform**: Provides a unified environment for managing annotation workflows and workforces. - **Focus on RLHF and Safety**: Plays a key role in reinforcement learning from human feedback and model alignment. - **Agent Readiness**: Supports data pipelines used to train and evaluate autonomous AI agents. #### Disadvantages: - **Cost**: Large-scale, high-quality annotation remains expensive. - **Complexity**: Managing enterprise data workflows requires strong operational oversight. - **Human Element**: Distributed annotation introduces variability without clear guidelines. - **Vendor Lock-in**: Deep platform integration can make migration difficult. - **Indirect Developer Interaction**: Not used directly inside IDEs or terminal-based workflows. #### Target Audience: - **Enterprises Developing AI**: Organizations requiring dependable training data at scale. - **Well-Funded AI Startups**: Teams building advanced models in vision, NLP, or autonomy. - **Machine Learning Engineers & Data Scientists**: Professionals managing large training and evaluation datasets. - **LLM and Agent Builders**: Companies prioritizing safety, alignment, and high-quality outputs in autonomous systems. ### #5: Claude Code ![](https://www.atlantic.net/wp-content/uploads/2025/06/claude-ai-icon.png) #### About Claude Code: Claude Code is a coding agent designed for developers and built on Anthropic’s Claude models. Unlike a passive chatbot, it works directly in developer workflows. By 2026, most people use Claude Code as a terminal-based agent that understands whole repositories, runs commands, and updates code with minimal supervision. Claude Code stands out from regular autocomplete tools because it can handle long-context reasoning and complex tasks. Its MCP-compatible design enables it to ingest structured project details, making it useful for refactoring, debugging, and exploring large codebases. Developers choose it when they need a tool that understands intent, not just code syntax. Build faster with Claude Code, an AI-powered coding assistant that helps you write, debug, and optimize code with clarity and precision. ![claude code](https://www.atlantic.net/wp-content/uploads/2025/06/claude-code.png) Image Source: Claude Code #### Advantages: - **Terminal-Based Agent**: Runs smoothly on the command line, allowing users to run commands and repeat tasks easily. - **Long-Context Reasoning**: Handles large files and projects with many files effectively. - **MCP-Compatible**: Uses structured information from tools, repositories, and workflows. - **Refactoring & Debugging**: Explains code logic clearly and suggests safe updates. - **Reduced Hallucination Risk**: Delivers clear and careful results. #### Disadvantages: - **No Native IDE UI**: Relies on the terminal or external integrations instead of a full IDE extension. - **Slower for Simple Tasks**: Not ideal for basic autocomplete or simple code generation. - **Requires Clear Prompts**: Performs best with clear goals and limits. #### Target Audience: - **Backend & Systems Developers**: Engineers who mainly work in the terminal. - **Large Codebase Owners**: Teams managing complex or older codebases. - **AI-Native Teams**: Developers building MCP-compatible and agent-based systems. - **Engineers Who Prefer CLI Workflows**: Users who want more control and transparency than UI-based tools provide. ### #6: Windsurf ![](https://www.atlantic.net/wp-content/uploads/2025/06/windsurf-black-symbol.png) #### About Windsurf: Windsurf is an AI-powered IDE that uses autonomous coding agents and integrates deeply with your workflow. Unlike traditional editors, Windsurf has built-in AI and agent-driven task execution, making it a productivity-focused environment instead of just another plugin. With Windsurf, developers can hand off multi-step tasks such as feature implementation, refactoring, or test generation to AI agents that understand the entire project. Its design follows MCP principles, so context is shared across files, tools, and background agents. Build and ship faster with Windsurf, an AI-powered coding environment that streamlines development workflows. ![windsurf](https://www.atlantic.net/wp-content/uploads/2025/06/windsurf.png) Image Source: Windsurf #### Advantages: - **IDE-Native Agents**: The AI is built into the editor rather than added as an extension. - **Repository Awareness**: Agents can understand and work across entire projects. - **MCP-Compatible Design**: Structured context helps improve accuracy and keeps tasks on track. - **Task Delegation**: Works well for multi-step development workflows. - **Modern UX**: Built from the ground up for AI-assisted development, not adapted from older tools. #### Disadvantages: - **Newer Platform**: Has fewer plugins and a smaller community than older IDEs. - **Learning Curve**: Users need to get used to agent-driven development patterns. - **Resource Usage**: Workflows that rely heavily on AI can consume significant system resources. #### Target Audience: - **Full-Stack Developers**: For engineers who work on frontend, backend, and infrastructure code. - **Teams Adopting Agent-Based Workflows**: For organizations looking to go beyond simple autocomplete features. - **Startup & Product Engineers**: For developers who need to deliver quickly with small teams. - **Early Adopters**: For developers who like to experiment with MCP-compatible IDEs and autonomous agents. ### #7: JetBrains AI Assistant ![](https://www.atlantic.net/wp-content/uploads/2025/06/jetbrains.png) #### About JetBrains AI Assistant: JetBrains AI Assistant is built into JetBrains IDEs such as IntelliJ IDEA, PyCharm, and WebStorm. It helps professional developers by working within their usual tools. In 2026, its main advantage is its close integration with the IDE, rather than working as a separate agent. The assistant understands your project’s structure, symbols, and the context within the IDE. Because it works with MCP, it can share context across files, inspections, and refactoring tools. This makes it especially useful for large, strongly typed codebases where IDE features are important. Develop with confidence in JetBrains, leveraging intelligent code assistance, version control integration, and productivity-focused features. ![IntelliJ IDEA](https://www.atlantic.net/wp-content/uploads/2025/06/IntelliJ-IDEA.png) Image Source: JetBrains AI #### Advantages: - **Native IDE Integration**: Built right into the JetBrains tools that developers already use. - **Context-Aware Assistance**: Knows your project’s symbols, structure, and dependencies. - **Refactoring Support**: Works with JetBrains’ well-established refactoring tools. - **MCP-Aligned Context Handling**: Uses organized project data instead of just raw prompts. - **Low Workflow Disruption**: Feels like a natural part of the IDE, not a separate tool. #### Disadvantages: - **Limited Autonomy**: Acts less like an independent agent than terminal-based tools. - **JetBrains-Only**: Only works within the JetBrains ecosystem. - **Conservative Execution**: Won’t run commands or do multi-step tasks on its own; it needs user input. #### Target Audience: - **JVM, Python, and Web Developers**: Best for teams already using JetBrains IDEs. - **Enterprise Engineers**: Good for developers working with large, organized codebases. - **IDE-Centric Workflows**: Suits users who want guided help rather than fully autonomous agents. - **Teams Transitioning to AI**: Helps organizations add AI without changing their main tools. ### #8: Aider #### ![](https://www.atlantic.net/wp-content/uploads/2025/06/aiderai.png) #### About Aider: Aider is an open-source AI coding assistant for developers who like working in the terminal. It works as an autonomous agent, editing files in your repository with Git-based workflows. Aider handles multi-file edits, refactoring, and test generation by keeping track of the conversation as you make changes. Its design enables it to leverage structured repository context, making it a strong tool for agent-driven development in 2026. Build and edit code directly from your terminal with Aider, an AI-powered coding assistant designed for developers. ![aider ai](https://www.atlantic.net/wp-content/uploads/2025/06/aider-ai.png) Image Source: Aider AI #### Advantages: - **Terminal-Based Agent**: Runs fully in the command line. - **Git-Native Workflow**: Tracks changes so you can review them. - **Multi-File Reasoning**: Manages edits and refactoring across multiple files. - **MCP-Compatible Design**: Uses structured context to improve reliability. - **Model Flexibility**: Supports different LLM backends. #### Disadvantages: - **No GUI**: Not the best fit for developers who like visual IDEs. - **Prompt Sensitivity**: Works best when you give clear instructions. - **Less Discoverable**: CLI tools can be harder to learn at first. #### Target Audience: - **Backend & Systems Engineers**: Best for developers who are comfortable in the terminal. - **Open-Source Contributors**: Those who use Git workflows will benefit most. - **AI Power Users**: Good for engineers who want to experiment with autonomous agents. - **Small Teams**: Helps developers who want more leverage without many extra tools. ### #9: Zed ![](https://www.atlantic.net/wp-content/uploads/2025/06/zed-logo.jpg) #### About Zed: Zed is a fast, collaborative code editor designed for today’s developer workflows. By 2026, it stands out for its speed, real-time collaboration, and support for a new AI agent, all within a lightweight IDE. Zed’s architecture supports AI features directly, not just through add-on plugins. Its design, which follows MCP principles, enables collaborators and AI assistants to share context, making it a good fit for team development. Let’s explore Zed, a fast and modern code editor built for real-time collaboration and high-performance development. ![zed](https://www.atlantic.net/wp-content/uploads/2025/06/zed.png) Image Source: Zed #### Advantages: - **Fast, Native Performance**: Built with Rust for quick, low-latency editing. - **IDE-Native AI Direction**: AI is a key part of the editor’s main plan. - **Real-Time Collaboration**: Developers and AI agents can work together and share context. - **MCP-Aligned Architecture**: Helps teams easily share and organize context. - **Clean UX**: Editing, collaboration, and AI help all work smoothly together. #### Disadvantages: - **Younger Platform**: There are fewer extensions compared to older editors. - **AI Features Still Evolving**: The AI is not as independent as terminal agents yet. - **Not Yet Universal**: More people are using Zed, but it’s not mainstream yet. #### Target Audience: - **Collaborative Teams**: Developers who work together on shared codebases. - **Performance-Focused Engineers**: People who care about speed and quick response times. - **Early Adopters**: Teams trying out editors that are built with AI in mind. - **Product Engineers**: Developers who mix collaboration, AI, and quick updates in their work. ### #10: Replit ![](https://www.atlantic.net/wp-content/uploads/2025/06/replit.png) #### About Replit: Replit is a cloud-based development platform where you can edit, run, and deploy code all in one place. By 2026, it has become an AI-native IDE with built-in agents that help write, run, and deploy code from start to finish. Replit’s AI agents work right inside the platform, so developers can quickly turn ideas into live applications. Its MCP compatibility enables the editor, runtime, and deployment to share information, making the overall process smoother. Here is the Replit dashboard, where you can turn ideas into working products using AI agents, code generation, and real-time collaboration. ![Replit AI](https://www.atlantic.net/wp-content/uploads/2025/06/Replit-AI.png) Image Source: Replit AI #### Advantages: - **All-in-One Workflow**: You can code, run, and deploy everything in one place. - **IDE-Native AI Agents**: The platform has built-in AI to help you as you work. - **Rapid Prototyping**: Great for testing ideas and building demos quickly. - **MCP-Aligned Context Sharing**: The editor and runtime can easily share information. - **Beginner to Pro Friendly**: Easy for beginners to use, but still powerful for experienced users. #### Disadvantages: - **Cloud-Dependent**: Requires an internet connection and relies on the platform. - **Less Control**: It’s not the best choice for low-level systems programming. - **Performance Constraints**: Very large or demanding projects might run into limits. #### Target Audience: - **Full-Stack Developers**: For those who want to build and launch applications quickly. - **Startups & Hackers**: Good for fast changes and getting started with little setup. - **Educators & Learners**: Useful for teaching and trying out AI-assisted coding. - **Product Teams**: Helps teams quickly test and develop ideas with agent-driven workflows. ### #11: Sourcegraph ![](https://www.atlantic.net/wp-content/uploads/2025/06/sourcegraph.jpg) #### About Sourcegraph: Sourcegraph is a code intelligence and search platform that helps developers work with large codebases. By 2026, it will have evolved from a code search tool into an AI-powered layer that fits smoothly into developer workflows. Sourcegraph’s AI features are designed to work across whole repositories, making it especially helpful for monorepos and distributed systems. Its MCP-compatible design lets structured context flow between search, code navigation, and AI insights, so developers can answer questions spanning thousands of files. Let’s explore Sourcegraph, a smart code intelligence tool that helps you search, analyze, and understand massive codebases with ease. ![Sourcegraph](https://www.atlantic.net/wp-content/uploads/2025/06/Sourcegraph.png) Image Source: Sourcegraph #### Advantages: - **Repository-Scale Awareness**: Built for very large codebases and monorepos. - **Advanced Code Search**: Supports semantic and structural search across different languages. - **IDE & Web Integration**: Works with editors instead of replacing them. - **MCP-Compatible Context Handling**: Uses structured repository data to improve AI accuracy. - **Refactoring & Discovery**: Helps with impact analysis and understanding system architecture. #### Disadvantages: - **Not a Code Editor**: Needs an IDE to make code changes. - **Learning Curve**: Users need some experience to get the most out of advanced queries. - **Enterprise-Oriented**: Smaller teams might not need all its features. #### Target Audience: - **Large Engineering Teams**: Best for organizations with monorepos or complex systems. - **Platform & Infra Engineers**: For developers who manage shared codebases. - **Codebase Maintainers:** Useful for teams that need to onboard new engineers quickly. - **AI-Augmented Enterprises:** For companies using MCP-compatible intelligence layers. ### #12: Greptile ![greptile](https://www.atlantic.net/wp-content/uploads/2025/06/greptile-1.png) #### About Greptile: Greptile is an AI-powered tool for code search and understanding that answers natural language questions about code. It acts as a lightweight intelligence layer, augmenting IDEs and terminal workflows rather than replacing them. Greptile explains unfamiliar code, traces logic, and summarizes how code works across files. Its MCP-aligned design leverages structured repository context, making its answers more reliable than those from tools that rely solely on prompts. Get started with Greptile and create a custom context that drives smarter, faster, and more relevant code reviews. ![Greptile](https://www.atlantic.net/wp-content/uploads/2025/06/Greptile-2.png) Image Source: Greptile #### Advantages: - **Natural Language Code Search**: Lets you ask questions instead of writing queries. - **Repository-Level Reasoning**: Understands how files relate to each other. - **IDE & Web-Based Usage**: Fits into existing wIDE & Web-Based Usage: Fits easily into your current workflow. accuracy and traceability. - **Fast Onboarding**: Helps you quickly understand new or inherited codebases. #### Disadvantages: - **Read-Only Focus**: Does not make direct changes to code. - **Less Autonomous**: It is not a terminal-based agent. - **Depends on Repo Indexing**: Needs some initial setup for best results. #### Target Audience: - **Developers Joining New Codebases**: Let’s you quickly understand new code without deep dives. - **Reviewers & Maintainers**: Useful for explaining and auditing code. - CT & Engineering Managers: High-level understanding of systems. ## AI in 2026: Revolutionizing Software Development and Content Creation In 2026, AI innovation is reshaping industries. Intelligent code editors like Cursor, creative suites such as RunwayML, information synthesizers like Perplexity AI, and data quality platforms (Scale AI) are already heavily relied on by companies across the United States. What’s changed most is the shift toward workflow-integrated and agent-driven tools that operate inside IDEs and terminals. AI-powered tools are essential for productivity, streamlining workflows and automating tasks from data analysis to content creation for all types of businesses. Rather than isolated features, modern AI tools increasingly manage context across repositories and development stages. However, challenges like learning curves, ensuring brand consistency, and even ethical considerations are important. Critical human thinking remains essential to responsibly improve AI. Autonomous agents still require oversight, validation, and clear intent from developers. Despite these hurdles, AI tools are making important steps forward and growing in popularity. Despite everything that AI can do, remember it’s not 100% foolproof, so the human touch is still incredibly important to create accurate and well-thought-out software. AI certainly has a very bright future for creation and development. As MCP-compatible platforms mature, teams that blend human judgment with deeply integrated AI workflows will see the strongest results. Remember, if you need to build and scale your innovative AI applications, Atlantic.Net has a powerful and reliable GPU hosting service available, powered by NVIDIA. Updated: 2/25/26 --- # Atlantic.Net: A Journey of More Than 32 Years > URL: https://www.atlantic.net/hosting-services-provider/history/ | Updated: 2026-09-16 Founded in 1994 by University of Florida students Manoj 'Marty' Puranik and Jose Sanchez, Atlantic.Net began as a small internet service provider initially named Internet Connect Company Computers (ICC Computers). The company was started in direct response to the limited internet access available at the university. Puranik and Sanchez established operations in Puranik's dorm room and offered dial-up and web hosting services. At the time, most people were unfamiliar with internet and email access, and most of today's dominant technology companies did not yet exist. Atlantic.Net was one of the world's first internet service providers, and it continues to grow. ## Rapid Growth Throughout the 1990s Within a year ICC Computers expanded to eight employees serving 2,000 customers in the Gainesville, Florida, area. In 1996, Atlantic.Net expanded to Tampa and Orlando and, by 1997, completed its first strategic acquisitions of First Coast Internet and Worldwide Internet. From the late 1990s to the early 2000s, the company acquired 13 internet service companies in strategically targeted and underserved second-tier markets and rural areas. With this growth also came enhanced service offerings, such as webmail, national dial-up service, DSL and true private networks. In 1999, it received CLEC (competitive local exchange carrier) certification. ## Managed Hosting Takes Off By 2005, Atlantic.Net entered the VoIP market, demonstrating an early ability to adapt to emerging technologies. The company's service portfolio expanded to include e-business solutions: long-distance services, broadband, web solutions, T-1 to DS-3 connectivity, and web design and hosting services. Recognizing the growing importance of dedicated infrastructure, Atlantic.Net opened its first data center in Orlando, Florida, in 2003. This marked a strategic shift toward dedicated servers, server colocation, and managed services, which laid the groundwork for the company's future in cloud computing. ## The Foundations of Cloud Computing The transition to cloud computing represented a significant evolution for Atlantic.Net. As the internet matured, demand increased for scalable and flexible IT solutions. In 2010, Atlantic.Net launched its cloud offering and virtualization services, positioning itself at the forefront of the booming cloud market. ## Strategic Technology Partnerships Atlantic.Net has established strategic partnerships with leading technology providers to enhance its service offerings: ### Samsung Atlantic.Net utilizes Samsung's high-performance storage solutions in its data centers. ### CISCO Powered Network Atlantic.Net started as a pioneer in internet technologies and solely utilized CISCO-powered equipment to provide internet access. ### NVIDIA As an official NVIDIA Partner Network Cloud Partner, Atlantic.Net provides customers with access to NVIDIA solutions for accelerated computing. ### Microsoft As a Certified Partner – Advanced Solutions, Atlantic.Net ensures its engineers are certified in the latest Microsoft Server technology. ### Intel As an Intel Titanium Partner, the company leverages Intel's enterprise-grade processors and hardware in its server infrastructure. ## Compliance Certifications Atlantic.Net takes compliance seriously, as demonstrated by the following certifications that it has achieved and maintained over the years: ### HIPAA (Health Insurance Portability and Accountability Act) The company demonstrates adherence to the stringent security and privacy requirements for protected health information. Healthcare organizations rely on Atlantic.Net's compliant infrastructure. ### SOC 1 (Service Organization Control 1) Detailed reports are provided on controls relevant to your organization's internal control over financial reporting, ensuring transparency and accountability. ### SOC 2 (Service Organization Control 2) Comprehensive reports are delivered on controls related to security, availability, processing integrity, confidentiality, and privacy, assuring protection of your sensitive data. ### HITECH (Health Information Technology for Economic and Clinical Health Act) Atlantic.Net strengthens HIPAA's privacy and security provisions, safeguarding your electronic health records with enhanced measures. ### PCI DSS (Payment Card Industry Data Security Standard) Secure handling of your customers' credit card information is ensured, maintaining a robust environment for payment processing. ### ISO 27001 Adherence to this globally recognized standard for information security management systems (ISMS) demonstrates the company's commitment to protecting your valuable information. ### GDPR (General Data Protection Regulation) Atlantic.Net complies with European Union regulations for the protection of personal data, ensuring the privacy and security of your EU-based customers' information. ## Current Service Portfolio With a global presence spanning eight data center regions, including a recent expansion to Singapore, Atlantic Net offers a comprehensive suite of cloud and hosting solutions backed by a 100% uptime service level agreement. ### Cloud Platform A highly available and scalable platform offering virtual servers (Windows, Linux, FreeBSD), secure block storage, dedicated hosts, and managed services. ### Dedicated Hosting Dedicated servers that provide high performance and robust security for clients with stringent compliance requirements. ### Graphics Processing Unit (GPU) Hosting High-performance GPU servers optimized for artificial intelligence (AI), machine learning (ML), and other computationally intensive workloads. ### HIPAA Hosting Secure and compliant hosting solutions designed for the healthcare industry, ensuring the privacy of patient data. ### PCI Hosting Secure hosting solutions that meet PCI DSS requirements. ### Managed Services A comprehensive range of services, including server management, network edge protection, and security services. Atlantic Net continues to invest in emerging technologies, including AI and ML. The company offers a high-performance computing platform to facilitate the development and deployment of AI/ML models. Solutions for remote work, automation, and cybersecurity further demonstrate Atlantic Net's commitment to addressing evolving business needs. ## A History of Innovation and Customer Focus Atlantic.Net's journey from a university startup to a global cloud services provider illustrates a consistent commitment to adaptability, innovation, and a customer-centric approach. The company has successfully navigated significant technological shifts while maintaining a focus on security, compliance, and customer satisfaction. With its comprehensive cloud solutions and ongoing investment in emerging technologies, Atlantic.Net is well-positioned for continued growth in the cloud computing market. Our history highlights the importance of understanding customer needs and adapting to technological advancements. In short, Atlantic.Net started by helping customers get online, then enabled them to conduct commerce online, and now it makes sure they stay secure and compliant online. Tomorrow's computing happens today with Atlantic.Net. ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # Gender and Age Detection using Machine Learning on Ubuntu 24.04 Server > URL: https://www.atlantic.net/gpu-server-hosting/gender-and-age-detection-using-machine-learning-on-ubuntu-24-04-server/ | Published: 2025-06-11 | Updated: 2025-06-18 | Author: Hitesh Jethva In today’s AI-driven world, automatically recognizing a person’s age and gender from an image has numerous real-world applications. From targeted advertising to audience analysis and security systems, age and gender detection is increasingly valuable. In this tutorial, we’ll build a gender and age detection system using Machine Learning on an Ubuntu 24.04 server. We will also create a Flask-based web interface that allows users to upload an image and view the predicted age and gender. ## Prerequisites - An Ubuntu 24.04 server with an [NVIDIA GPU](https://www.atlantic.net/gpu-server-hosting/). - A non-root user with sudo privileges. - NVIDIA drivers installed. ## Step 1: Set Up a Python Environment 1. Install required Python packages. ```bash apt install python3-pip python3-venv ``` 2. Create a virtual environment for your project. ```bash python3 -m venv venv ``` 3. Activate the virtual environment. ```bash source venv/bin/activate ``` 4. Install Python libraries for AI and Web development ```bash pip install scikit-learn opencv-python flask tensorflow keras ``` ## Step 2: Prepare Pre-trained Models In this section, we will download the face, age, and gender detection models needed for inference. For this project, we’ll use OpenCV’s pre-trained Age and Gender models. 1. First, create a directory to store all models. ```bash mkdir -p model ``` 2. Navigate to the model directory. ```bash cd model ``` 3. Download all required models. ```bash wget https://raw.githubusercontent.com/spmallick/learnopencv/master/AgeGender/opencv_face_detector.pbtxt wget https://raw.githubusercontent.com/spmallick/learnopencv/master/AgeGender/opencv_face_detector_uint8.pb wget https://raw.githubusercontent.com/spmallick/learnopencv/master/AgeGender/age_deploy.prototxt wget https://raw.githubusercontent.com/eveningglow/age-and-gender-classification/5b60d9f8a8608cdbbcdaaa39bf28f351e8d8553b/model/age_net.caffemodel wget https://raw.githubusercontent.com/spmallick/learnopencv/master/AgeGender/gender_deploy.prototxt wget https://raw.githubusercontent.com/eveningglow/age-and-gender-classification/master/model/gender_net.caffemodel ``` 4. Change back to the main directory. ```bash cd .. ``` ## Step 3: Write the Age and Gender Detection Script Here, you create a Python script that loads the models and predicts age and gender from face images. 1. Create a file detect.py. ```bash nano detect.py ``` Add the following code. ```bash import cv2 # Load models face_model = "model/opencv_face_detector_uint8.pb" face_proto = "model/opencv_face_detector.pbtxt" age_model = "model/age_net.caffemodel" age_proto = "model/age_deploy.prototxt" gender_model = "model/gender_net.caffemodel" gender_proto = "model/gender_deploy.prototxt" age_list = ['(0-2)', '(4-6)', '(8-12)', '(15-20)', '(25-32)', '(38-43)', '(48-53)', '(60-100)'] gender_list = ['Male', 'Female'] # Load networks face_net = cv2.dnn.readNet(face_model, face_proto) age_net = cv2.dnn.readNet(age_model, age_proto) gender_net = cv2.dnn.readNet(gender_model, gender_proto) def detect_face(img): blob = cv2.dnn.blobFromImage(img, 1.0, (300, 300), [104, 117, 123], swapRB=False) face_net.setInput(blob) detections = face_net.forward() h, w = img.shape[:2] faces = [] for i in range(detections.shape[2]): confidence = detections[0, 0, i, 2] if confidence > 0.7: box = detections[0, 0, i, 3:7] * \ [w, h, w, h] (x1, y1, x2, y2) = box.astype("int") faces.append((x1, y1, x2-x1, y2-y1)) return faces def predict_age_gender(img_path): frame = cv2.imread(img_path) faces = detect_face(frame) if len(faces) == 0: return "No face detected!", None results = [] for (x, y, w, h) in faces: face_img = frame[y:y+h, x:x+w].copy() blob = cv2.dnn.blobFromImage(face_img, 1.0, (227, 227), (78.4263377603, 87.7689143744, 114.895847746), swapRB=False) # Predict Gender gender_net.setInput(blob) gender_preds = gender_net.forward() gender = gender_list[gender_preds[0].argmax()] # Predict Age age_net.setInput(blob) age_preds = age_net.forward() age = age_list[age_preds[0].argmax()] results.append((gender, age)) return results[0] # Return first detected face ``` ## Step 4: Create the Flask Web App This step builds a web server using Flask that can accept image uploads and return predictions. 1. Create a Flask application. ```bash nano app.py ``` Add the following code. ```bash from flask import Flask, render_template, request import os from detect import predict_age_gender app = Flask(__name__) UPLOAD_FOLDER = 'static/uploads' app.config['UPLOAD_FOLDER'] = UPLOAD_FOLDER os.makedirs(UPLOAD_FOLDER, exist_ok=True) @app.route('/', methods=['GET', 'POST']) def index(): result = None filename = None if request.method == 'POST': if 'file' not in request.files: return 'No file uploaded', 400 file = request.files['file'] if file.filename == '': return 'No selected file', 400 if file: filename = os.path.join(app.config['UPLOAD_FOLDER'], file.filename) file.save(filename) result = predict_age_gender(filename) return render_template('index.html', result=result, filename=filename) if __name__ == '__main__': app.run(host="0.0.0.0", port=5000, debug=True) ``` ## Step 5: Create the HTML Template You’ll now design a simple user interface that allows users to upload images and view the results. Create a folder called **‘templates’** and inside it, create an **index.html** file. ```bash mkdir templates nano templates/index.html ``` Add the following code. ```bash Gender and Age Detection

Upload an Image for Age and Gender Detection

{% if filename %}

Uploaded Image:

Uploaded Image {% endif %} {% if result %}

Prediction:

Gender: {{ result[0] }}

Age: {{ result[1] }}

{% endif %} ``` ## Step 6: Run the Flask App Finally, this step starts the Flask web server, allowing you to access your app from a browser. ```bash python3 app.py ``` Access your Flask app at **http://server-ip:5000.** You’ll see a simple page where you can upload a face image, and it will show the predicted gender and age! ![](https://www.atlantic.net/wp-content/uploads/2025/05/p1-3.png) ## Conclusion In this project, we built a Gender and Age Detection app using Machine Learning models on an Ubuntu 24.04 server and created a Flask web interface for easy interaction. You can enhance this project further by integrating it with a live camera feed or deploying it online. --- # Iris Flower Classification Using Machine Learning on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/iris-flower-classification-using-machine-learning-on-ubuntu-24-04-gpu-server/ | Published: 2025-06-12 | Updated: 2026-05-04 | Author: Hitesh Jethva Classifying Iris flowers is a classic machine learning problem. It’s a perfect introduction to supervised learning, showcasing key machine learning techniques. Initially introduced by the renowned statistician Ronald Fisher, the Iris dataset has become a standard benchmark for testing new machine learning algorithms. It consists of different Iris species, each with distinct characteristics, making it an ideal dataset for understanding classification concepts. In this guide, you’ll learn how to build a robust Iris flower classification model using a GPU-powered Ubuntu 24.04 server. We will also create a Flask web application that allows users to upload an image of an iris flower and display the predicted species name. ## Prerequisites - An Ubuntu 24.04 server with an [NVIDIA GPU](https://www.atlantic.net/gpu-server-hosting/). - A non-root user with sudo privileges. - NVIDIA drivers installed. ## Step 1: Install Required Packages First, let’s install the necessary system packages. ```bash apt install python3-pip python3-venv unzip -y ``` ## Step 2: Set Up Python Environment Now, you will create a Python environment for your project. 1. Create a virtual environment. ```bash python3 -m venv venv ``` 2. Activate the virtual environment. ```bash source venv/bin/activate ``` 3. Install the required Python packages. ```bash pip3 install tensorflow pillow flask kaggle ``` These packages include: - **tensorflow** for machine learning with GPU support - **pillow** for image processing - **flask** for the web interface - **kaggle** to download datasets ## Step 3: Set Up Kaggle API To download our dataset, we need to configure the Kaggle API. 1. Go to [Kaggle](https://www.kaggle.com) and log in. 2. Click your **profile picture**  => **Account** 3. Scroll down to **API** section 4. Click **“Create New API Token”** 5. This will download **kaggle.json** to your computer 6. Create a Kaggle configuration directory on your server. ```bash mkdir -p ~/.kaggle ``` 7. Copy your downloaded **kaggle.json** file into the **~/.kaggle** folder. 8. Set appropriate permissions. ```bash chmod 600 ~/.kaggle/kaggle.json ``` ## Step 4: Download and Prepare the Dataset Now, we will use Kaggle to download and extract the dataset. 1. Download the flower dataset. ```bash kaggle datasets download -d imsparsh/flowers-dataset ``` 2. Unzip the dataset. ```bash unzip flowers-dataset.zip ``` 3. Rename the training folder for easier reference. ```bash mv train flowers ``` ## Step 5: Create the CNN Training Script 1. Create a file called train_cnn_model.py. ```bash nano train_cnn_model.py ``` Add the following code. ```bash # train_cnn_model.py import tensorflow as tf from tensorflow.keras.preprocessing.image import ImageDataGenerator from tensorflow.keras.models import Sequential from tensorflow.keras.layers import Conv2D, MaxPooling2D, Flatten, Dense from tensorflow.keras.optimizers import Adam # Define dataset path data_dir = 'flowers' # folder created after unzip model_path = 'flowers_cnn_model.h5' # Image properties img_width, img_height = 150, 150 batch_size = 32 epochs = 10 # Data loading and augmentation datagen = ImageDataGenerator(rescale=1./255, validation_split=0.2) train_generator = datagen.flow_from_directory( data_dir, target_size=(img_width, img_height), batch_size=batch_size, class_mode='categorical', subset='training' ) validation_generator = datagen.flow_from_directory( data_dir, target_size=(img_width, img_height), batch_size=batch_size, class_mode='categorical', subset='validation' ) # Build CNN Model model = Sequential([ Conv2D(32, (3, 3), activation='relu', input_shape=(img_width, img_height, 3)), MaxPooling2D(2, 2), Conv2D(64, (3, 3), activation='relu'), MaxPooling2D(2, 2), Flatten(), Dense(128, activation='relu'), Dense(train_generator.num_classes, activation='softmax') ]) # Compile model model.compile(optimizer=Adam(), loss='categorical_crossentropy', metrics=['accuracy']) # Train the model model.fit(train_generator, epochs=epochs, validation_data=validation_generator) # Save the model model.save(model_path) print("✅ CNN model trained and saved as flowers_cnn_model.h5") ``` This will: - Load and preprocess the flower images - Create a convolutional neural network (CNN) - Train the model for 10 epochs - Save the trained model as flowers_cnn_model.h5 2. Run the training script. ```bash python3 train_cnn_model.py ``` Output. ```bash ✅ CNN model trained and saved as flowers_cnn_model.h5 ``` ## Step 6: Create the Flask Application 1. Create the main application file. ```bash nano app.py ``` Add the following code. ```bash # app.py import os from flask import Flask, render_template, request from tensorflow.keras.models import load_model from tensorflow.keras.preprocessing import image import numpy as np app = Flask(__name__) UPLOAD_FOLDER = 'static/uploads' os.makedirs(UPLOAD_FOLDER, exist_ok=True) app.config['UPLOAD_FOLDER'] = UPLOAD_FOLDER # Load the trained model model = load_model('flowers_cnn_model.h5') # Class labels (based on folders in 'flowers' dataset) class_labels = ['daisy', 'dandelion', 'rose', 'sunflower', 'tulip'] @app.route('/', methods=['GET', 'POST']) def index(): prediction = None image_url = None if request.method == 'POST': file = request.files['file'] if file: filepath = os.path.join(app.config['UPLOAD_FOLDER'], file.filename) file.save(filepath) # Preprocess uploaded image img = image.load_img(filepath, target_size=(150, 150)) img_array = image.img_to_array(img) / 255.0 img_array = np.expand_dims(img_array, axis=0) # Predict class pred = model.predict(img_array) predicted_class = class_labels[np.argmax(pred)] prediction = predicted_class image_url = filepath return render_template('index.html', prediction=prediction, image_url=image_url) if __name__ == '__main__': app.run(host='0.0.0.0', port=5000) ``` 2. Create the templates directory and HTML file. ```bash mkdir templates nano templates/index.html ``` Add the following code. ```bash Flower Image Classifier 🌸

Upload a Flower Image 🌻🌹🌼



{% if prediction %}

Predicted Flower Species: {{ prediction }}

Uploaded Image {% endif %} ``` ## Step 7: Run the Application Start the Flask development server. ```bash python3 app.py ``` Output. ```bash * Running on all addresses (0.0.0.0) * Running on http://127.0.0.1:5000 * Running on http://server-ip:5000 INFO:werkzeug:Press CTRL+C to quit ``` ## Step 8: Access the App 1. Open your web browser and access the app using the URL **http://server-ip:5000.** 2. Click the **“Browse”** button to upload a flower image from your local computer 3. Click **“Upload and Predict”.** ![](https://www.atlantic.net/wp-content/uploads/2025/05/p1-2.png)4. The app will process the image and display: - The predicted flower species (daisy, dandelion, rose, sunflower, or tulip) - The uploaded image ## Conclusion This tutorial has walked you through the complete process of building a flower classification system on an Ubuntu 24.04 GPU server. We have implemented a convolutional neural network using TensorFlow that can accurately classify five types of flowers (daisy, dandelion, rose, sunflower, and tulip). We then created a user-friendly web interface using Flask to make the model accessible. --- # Advanced Color Detection Web App with Flask & Machine Learning on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/advanced-color-detection-web-app-with-flask-machine-learning-on-ubuntu-24-04-gpu-server/ | Published: 2025-06-13 | Updated: 2026-05-04 | Author: Hitesh Jethva Color detection plays a crucial role in computer vision, from sorting items by color to assisting visually impaired users. By combining the power of Flask, OpenCV, and machine learning, you can build an advanced web app that accurately detects and classifies colors from uploaded images or user interactions. In this tutorial, we will deploy a color detection web app on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). The app utilizes a pre-trained machine learning model for enhanced accuracy and offers an intuitive interface for uploading images and selecting pixels to identify their colors. You also learn how to structure the Flask backend, handle file uploads, and serve color predictions in real-time. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user with sudo privileges. - NVIDIA drivers installed. ## Step 1: Set Up Python Environment First, we’ll install the necessary Python packages and create a virtual environment. 1. Install Python and pip. ```bash apt install -y python3-pip python3-dev python3-venv ``` 2. Create a virtual environment. ```bash python3 -m venv venv ``` 3. Activate the virtual environment. ```bash source venv/bin/activate ``` ## Step 2: Install Required Python Packages Now we’ll install all the Python dependencies for our project. ```bash pip install tqdm flask opencv-python pandas numpy scikit-learn pillow ``` These packages include: - **tqdm** for progress bars - **flask** for the web framework - **opencv-python** for image processing - **pandas, numpy** for data handling - **scikit-learn** for machine learning - **pillow** for image handling ## Step 3: Set Up Project Structure 1. Create the necessary directories for our web application. ```bash mkdir templates static ``` 2. Download the color database from [Kaggle](https://www.kaggle.com/datasets/adikurniawan/color-dataset-for-color-recognition) for color recognition. 3. Copy the downloaded dataset file from your local computer to the server. ```bash scp archive.zip root@server-ip:/root/ ``` 4. Unzip the downloaded dataset. ```bash unzip archive.zip ``` ## Step 4: Create the Machine Learning Model Now we’ll create a script to train our color classification model. 1. Create a new file called **model_trainer.py:** ```bash nano model_trainer.py ``` Add the following code. ```bash import os import cv2 import numpy as np from sklearn.svm import SVC from sklearn.model_selection import train_test_split from sklearn.metrics import accuracy_score import joblib from tqdm import tqdm class ColorModelTrainer: def __init__(self, dataset_path="training_dataset"): self.dataset_path = dataset_path self.classes = sorted(os.listdir(dataset_path)) self.model = SVC(kernel='linear', probability=True) def load_dataset(self): X = [] y = [] print("Loading dataset...") for class_idx, class_name in enumerate(tqdm(self.classes)): class_path = os.path.join(self.dataset_path, class_name) for img_file in os.listdir(class_path): img_path = os.path.join(class_path, img_file) img = cv2.imread(img_path) if img is not None: img = cv2.resize(img, (50, 50)) # Standardize size img = cv2.cvtColor(img, cv2.COLOR_BGR2RGB) X.append(img.flatten()) y.append(class_idx) return np.array(X), np.array(y) def train(self): X, y = self.load_dataset() X_train, X_test, y_train, y_test = train_test_split(X, y, test_size=0.2) print("Training model...") self.model.fit(X_train, y_train) # Evaluate y_pred = self.model.predict(X_test) accuracy = accuracy_score(y_test, y_pred) print(f"Model accuracy: {accuracy:.2f}") # Save model os.makedirs("static/models", exist_ok=True) joblib.dump(self.model, "static/models/color_classifier.joblib") joblib.dump(self.classes, "static/models/classes.joblib") print("Model saved successfully") if __name__ == "__main__": trainer = ColorModelTrainer() trainer.train() ``` 2. Run the training script. ```bash python3 model_trainer.py ``` This script will: - Load and preprocess the training images - Train an SVM classifier - Evaluate the model accuracy - Save the trained model for later use ## Step 5: Create the Color Detector Class Now we’ll create the core functionality that detects colors using both traditional and ML methods. 1. Create a new file called **color_detector.py:** ```bash nano color_detector.py ``` Add the following code. ```bash import cv2 import pandas as pd import numpy as np import joblib import os class AdvancedColorDetector: def __init__(self): # Traditional method self.csv_path = os.path.join('static', 'colors.csv') self.index = ["color", "color_name", "hex", "R", "G", "B"] self.df = pd.read_csv(self.csv_path, names=self.index, header=None) # ML method self.ml_model = joblib.load("static/models/color_classifier.joblib") self.classes = joblib.load("static/models/classes.joblib") def get_color_name_traditional(self, R, G, B): minimum = float('inf') color_name = "Unknown" for i in range(len(self.df)): d = abs(R - int(self.df.loc[i, "R"])) + abs(G - int(self.df.loc[i, "G"])) + abs(B - int(self.df.loc[i, "B"])) if d < minimum: minimum = d color_name = self.df.loc[i, "color_name"] return color_name def get_color_name_ml(self, img, x, y): # Extract 50x50 patch around the clicked point patch_size = 25 patch = img[max(0,y-patch_size):min(img.shape[0],y+patch_size), max(0,x-patch_size):min(img.shape[1],x+patch_size)] if patch.size == 0: return "Unknown" # Resize and predict patch = cv2.resize(patch, (50, 50)) patch = cv2.cvtColor(patch, cv2.COLOR_BGR2RGB).flatten() proba = self.ml_model.predict_proba([patch])[0] confidence = max(proba) if confidence < 0.6: # Confidence threshold return "Unknown (Low Confidence)" return self.classes[np.argmax(proba)] def process_image(self, image_path, x, y): img = cv2.imread(image_path) if img is None: return None, "Could not read image" b, g, r = img[y, x] # Get results from both methods traditional_name = self.get_color_name_traditional(r, g, b) ml_name = self.get_color_name_ml(img, x, y) return { 'rgb': (r, g, b), 'traditional': traditional_name, 'ml': ml_name } ``` ## Step 6: Create the Flask Web Application Now we’ll create the main Flask application that serves our web interface. 1. Create a new file called **app.py:** ```bash nano app.py ``` Add the following code. ```bash from flask import Flask, render_template, request, jsonify import os from color_detector import AdvancedColorDetector app = Flask(__name__) app.config['UPLOAD_FOLDER'] = os.path.join('static', 'uploads') os.makedirs(app.config['UPLOAD_FOLDER'], exist_ok=True) detector = AdvancedColorDetector() @app.route('/', methods=['GET', 'POST']) def index(): if request.method == 'POST': if 'file' not in request.files: return render_template('index.html', error="No file selected") file = request.files['file'] if file.filename == '': return render_template('index.html', error="No file selected") if file: filename = os.path.join(app.config['UPLOAD_FOLDER'], file.filename) file.save(filename) return render_template('index.html', image_url=filename, filename=file.filename) return render_template('index.html') @app.route('/detect', methods=['POST']) def detect(): data = request.json filename = os.path.join(app.config['UPLOAD_FOLDER'], data['filename']) x, y = int(data['x']), int(data['y']) result = detector.process_image(filename, x, y) return jsonify({ 'rgb': f"RGB({result['rgb'][0]}, {result['rgb'][1]}, {result['rgb'][2]})", 'traditional': result['traditional'], 'ml': result['ml'] }) if __name__ == '__main__': app.run(host='0.0.0.0', port=5000, debug=True) ``` 2. Create the web interface template in the templates directory. ```bash nano templates/index.html ``` Add the following code. ```bash Advanced Color Detection

Advanced Color Detection

Upload an image and click anywhere to detect colors using both traditional and ML methods

{% if error %}

{{ error }}

{% endif %} {% if image_url %}
Uploaded Image
Traditional Method: Click on the image
ML Method: Click on the image
RGB Values: -
{% endif %}
{% if image_url %} {% endif %} ``` ## Step 7: Run the Application Start the Flask development server. ```bash python3 app.py ``` You will see the following output. ```bash * Running on all addresses (0.0.0.0) * Running on http://127.0.0.1:5000 * Running on http://server-ip:5000 ``` ## Step 8: Access the Application 1. Open a web browser and navigate to **http://server-ip:5000.** 2. Click the **“Browse”** button to upload an image from your local computer. ![](https://www.atlantic.net/wp-content/uploads/2025/05/p1.png) 3. After uploading, click on any **color** in the image. ![](https://www.atlantic.net/wp-content/uploads/2025/05/p2.png) 4. The app will display: - The RGB values of the selected color - The color name detected by the traditional method - The color name detected by the machine learning method ## Conclusion In this tutorial, you have built a robust and interactive web app capable of detecting colors using machine learning on an Ubuntu 24.04 GPU server. You configured the environment, deployed a Flask application, and integrated a color classification model to enhance accuracy. This setup provides a strong foundation for more complex vision tasks such as object recognition or augmented reality. --- # Auto-Capture Selfie by Detecting Smile Using OpenCV on Ubuntu 24.04 Server > URL: https://www.atlantic.net/gpu-server-hosting/auto-capture-selfie-by-detecting-smile-using-opencv-on-ubuntu-24-04-server/ | Published: 2025-06-16 | Updated: 2025-06-18 | Author: Hitesh Jethva In this digital age, automated photo capture systems are becoming increasingly popular for creating seamless user experiences. This article will guide you through setting up a browser-based smile detection system that automatically captures selfies when it detects your smile. ## Prerequisites - An Ubuntu 24.04 server with an [NVIDIA GPU](https://www.atlantic.net/gpu-server-hosting/). - A non-root user with sudo privileges. - NVIDIA drivers installed. ## Step 1: Set up a Python Environment First, we need to install essential system-level packages to support Python development and OpenCV. ```bash apt install -y python3-pip python3-dev python3-venv libopencv-dev cmake ``` Now let’s isolate our Python project using a virtual environment. ```bash python3 -m venv smile_env source smile_env/bin/activate ``` Install the necessary Python libraries for image processing, mathematical operations, and web application. ```bash pip install opencv-python opencv-contrib-python numpy flask ``` ## Step 2: Create Project Structure Now, create directories to organize templates and selfie images. ```bash mkdir templates static/selfies ``` ## Step 3: Create a Self-Signed SSL Certificate Flask will run with HTTPS, which browsers require for webcam access. Let’s create a self-signed certificate. ```bash openssl req -x509 -newkey rsa:4096 -nodes -out cert.pem -keyout key.pem -days 365 ``` This creates two files: cert.pem (certificate) and key.pem (private key), valid for one year. Browsers may show a warning, but you can safely proceed for local testing. ## Step 4: Build the Flask Backend Let’s create the heart of the app, the Python backend that receives webcam frames and saves selfies. ```bash nano app.py ``` Add the following code. ```bash from flask import Flask, request, Response, jsonify, render_template import cv2 import numpy as np import os import time import base64 app = Flask(__name__) # Create directory for saved selfies os.makedirs('static/selfies', exist_ok=True) # Load pre-trained classifiers face_cascade = cv2.CascadeClassifier(cv2.data.haarcascades + 'haarcascade_frontalface_default.xml') smile_cascade = cv2.CascadeClassifier(cv2.data.haarcascades + 'haarcascade_smile.xml') selfie_count = 0 last_capture_time = 0 CAPTURE_COOLDOWN = 2 # seconds between captures @app.route('/') def index(): selfies = sorted([f for f in os.listdir('static/selfies') if f.endswith('.jpg')], reverse=True) return render_template('index.html', selfies=selfies) @app.route('/process_frame', methods=['POST']) def process_frame(): global selfie_count, last_capture_time # Get image data from POST request image_data = request.json['image'].split(',')[1] # Remove data URL prefix nparr = np.frombuffer(base64.b64decode(image_data), np.uint8) frame = cv2.imdecode(nparr, cv2.IMREAD_COLOR) # Convert to grayscale gray = cv2.cvtColor(frame, cv2.COLOR_BGR2GRAY) # Detect faces faces = face_cascade.detectMultiScale(gray, 1.3, 5) result = {'faces': [], 'captured': False} for (x, y, w, h) in faces: # Add face to result result['faces'].append({'x': int(x), 'y': int(y), 'w': int(w), 'h': int(h)}) # Detect smiles within the face region roi_gray = gray[y:y+h, x:x+w] smiles = smile_cascade.detectMultiScale( roi_gray, scaleFactor=1.7, minNeighbors=20, minSize=(25, 25) ) # If smile detected and cooldown has passed current_time = time.time() if len(smiles) > 0 and (current_time - last_capture_time) > CAPTURE_COOLDOWN: # Save the selfie timestamp = time.strftime("%Y%m%d-%H%M%S") filename = f"static/selfies/selfie_{timestamp}_{selfie_count}.jpg" cv2.imwrite(filename, frame) selfie_count += 1 last_capture_time = current_time result['captured'] = True result['selfie_url'] = filename return jsonify(result) if __name__ == '__main__': app.run(host='0.0.0.0', port=5000, ssl_context=('cert.pem', 'key.pem')) ``` The above code: - Loads pre-trained Haar cascade classifiers for face and smile detection. - Processes video frames sent from the browser. - Captures and saves selfies when a smile is detected (with a 2-second cooldown). ## Step 5: Build the Web Interface Create a front-end that interacts with the user’s webcam and displays the results. ```bash nano templates/index.html ``` Add the following code. ```bash Browser-Based Smile Detection Selfie

Smile Detection Selfie Capture

Allow camera access when prompted. The system will automatically capture selfies when you smile!

Camera is off

Your Selfies

{% for selfie in selfies %} {% endfor %}
``` This page: - Lets users start or stop their webcam. - Sends each frame to the Flask server via /process_frame. - Draws bounding boxes around detected faces. - Displays the captured selfies in a grid layout. ## Step 6: Run the Flask App Launch your Flask web server with HTTPS enabled. ```bash python3 app.py ``` Your app will now listen on **https://0.0.0.0:5000** with the SSL certificates. This makes it compatible with browsers requiring a secure context for webcam access. ## Step 7: Access the Web Interface Open your web browser and open the URL https://server-ip:5000. ![](https://www.atlantic.net/wp-content/uploads/2025/05/p1-1.png) Once the site loads, click on the **“Start Camera”** button. Allow camera access when prompted. ![](https://www.atlantic.net/wp-content/uploads/2025/05/p2-1.png) The system will now: - Show your camera feed. - Continuously scan for faces. - Capture and save selfies when it detects a smile. Every time you smile, the system detects it and captures a selfie, saving it to the **static/selfies** folder. ## Conclusion You’ve just built a complete smile-activated selfie system using OpenCV and Flask on an Ubuntu 24.04 server. This project is an excellent example of combining computer vision with web development to create real-time, interactive applications. --- # How to Predict Stock Prices Using LSTM Neural Network on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-predict-stock-prices-using-lstm-neural-network-on-ubuntu-24-04-gpu-server/ | Published: 2025-06-18 | Updated: 2026-05-04 | Author: Hitesh Jethva Predicting stock prices has long been a challenge for investors and analysts alike. With the advent of deep learning, particularly Long Short-Term Memory (LSTM) neural networks, we now have powerful tools to analyze time-series data like stock prices. In this tutorial, we will walk through setting up an LSTM model on an Ubuntu 24.04 GPU server to predict stock prices, using Apple Inc. (AAPL) as an example. ## Prerequisites Before we begin, ensure you have: - Ubuntu 24.04 [server with GPU](https://www.atlantic.net/gpu-server-hosting/) capabilities. - Python 3 and NVIDIA drivers installed. - Basic familiarity with terminal commands. ## Step 1: Setting Up the Environment First, let’s create a clean Python environment and install the necessary packages: 1. Install Python’s virtual environment and pip packages. ```bash apt install python3-venv python3-pip ``` 2. Create a new virtual environment. ```bash python3 -m venv stock_env ``` 3. Activate the environment. ```bash source stock_env/bin/activate ``` 4. Install essential packages, including TensorFlow, for our LSTM model. ```bash pip install tensorflow numpy pandas matplotlib scikit-learn yfinance ``` ## Step 2: Writing the LSTM Stock Prediction Script Now, we will write the full Python script to download stock data, preprocess it, build and train the LSTM model, and visualize the predictions. This script handles everything: data download, training, evaluation, and next-day prediction. Create the script file. ```bash nano stock_prediction_lstm.py ``` Add the following code. ```bash import numpy as np import pandas as pd import yfinance as yf import matplotlib.pyplot as plt from sklearn.preprocessing import MinMaxScaler from tensorflow.keras.models import Sequential from tensorflow.keras.layers import LSTM, Dense, Dropout # Download stock data directly ticker = 'AAPL' data = yf.download(ticker, start='2010-01-01', end='2025-04-20') # Preprocess data data_close = data[['Close']] dataset = data_close.values # Scale data between 0 and 1 scaler = MinMaxScaler(feature_range=(0, 1)) scaled_data = scaler.fit_transform(dataset) # Split into training (80%) and testing (20%) train_len = int(len(scaled_data) * 0.8) train_data = scaled_data[:train_len] # Function to create dataset for LSTM def create_dataset(data, time_step=60): X, y = [], [] for i in range(time_step, len(data)): X.append(data[i-time_step:i, 0]) y.append(data[i, 0]) return np.array(X), np.array(y) # Prepare training data X_train, y_train = create_dataset(train_data) X_train = X_train.reshape(X_train.shape[0], X_train.shape[1], 1) # Build the LSTM model model = Sequential([ LSTM(50, return_sequences=True, input_shape=(X_train.shape[1], 1)), Dropout(0.2), LSTM(50, return_sequences=False), Dropout(0.2), Dense(25), Dense(1) ]) model.compile(optimizer='adam', loss='mean_squared_error') # Train the model model.fit(X_train, y_train, batch_size=32, epochs=50) model.save('lstm_stock_model.h5') # Prepare test data test_data = scaled_data[train_len - 60:] X_test, y_test = create_dataset(test_data) X_test = X_test.reshape(X_test.shape[0], X_test.shape[1], 1) # Predict and inverse transform predictions = model.predict(X_test) predictions = scaler.inverse_transform(predictions) y_test_actual = scaler.inverse_transform(y_test.reshape(-1, 1)) # Calculate RMSE rmse = np.sqrt(np.mean((predictions - y_test_actual)**2)) print(f"Root Mean Squared Error (RMSE): {rmse}") # Visualization train = data_close[:train_len] valid = data_close[train_len:].copy() valid['Predictions'] = predictions plt.figure(figsize=(16, 8)) plt.title('Stock Price Prediction with LSTM') plt.xlabel('Date') plt.ylabel('Close Price (USD)') plt.plot(train['Close'], label='Train') plt.plot(valid['Close'], label='Actual') plt.plot(valid['Predictions'], label='Predicted') plt.legend() plt.savefig('stock_prediction_plot.png') plt.show() # Predict the next day's closing price def predict_next_day(model, data, scaler, time_step=60): last_60_days = data[-time_step:].values last_60_scaled = scaler.transform(last_60_days) X_pred = np.array([last_60_scaled]) X_pred = X_pred.reshape(X_pred.shape[0], X_pred.shape[1], 1) pred_price = model.predict(X_pred) return scaler.inverse_transform(pred_price)[0][0] next_day_price = predict_next_day(model, data_close, scaler) print(f"Predicted next day price for {ticker}: ${next_day_price:.2f}") ``` The above code: - Downloads historical stock data for AAPL from Yahoo Finance. - Trains an LSTM neural network to predict the future closing price based on past data. - Visualizes the model’s predicted vs. actual closing prices. - Predicts and displays the next day’s closing price for Apple’s stock. ## Step 3: Run the Model Now let’s run the script to train the model and see the results. ```bash python3 stock_prediction_lstm.py ``` This step executes the prediction workflow and shows model accuracy and forecast. ```bash Root Mean Squared Error (RMSE): 7.07722469189058 1/1 ━━━━━━━━━━━━━━━━━━━━ 0s 25ms/step Predicted next day price for AAPL: $182.96 ``` ## Step 4: Download the Prediction Chart To visualize the chart on your local system, use scp to download it. ```bash scp root@YOUR_SERVER_IP:/root/stock_prediction_plot.png Downloads/ ``` ![](https://www.atlantic.net/wp-content/uploads/2025/05/stock_prediction_plot.png) ## Conclusion In this guide, you learned how to predict stock prices using an LSTM neural network on an Ubuntu 24.04 GPU server. We used Python and deep learning tools to download historical stock data, train a model, and predict the next day’s closing price for Apple’s stock. We also visualized the model’s performance and saved the results for easy access. --- # Future-Proofing Digital Security: The Role of AI and Quantum-Safe Algorithms in Trust Convergence > URL: https://www.atlantic.net/gpu-server-hosting/future-proofing-digital-security-the-role-of-ai-and-quantum-safe-algorithms-in-trust-convergence/ | Published: 2025-06-20 | Updated: 2026-05-04 | Author: Dr. Assad Abbas Due to the increased reliance on digital systems, businesses face increasing [cyber threats](https://www.atlantic.net/gpu-server-hosting/artificial-intelligence-driven-cybersecurity-in-iot-ensuring-secure-connections-in-an-interconnected-world/) today. [Artificial intelligence (AI)](https://www.britannica.com/technology/artificial-intelligence) and [quantum computing](https://www.ibm.com/think/topics/quantum-computing#:~:text=Quantum%20computing%20is%20an%20emergent,the%20most%20powerful%20classical%20computers.) are emerging as influential technologies having both risks and prospects for companies. While AI provides advanced tools for identifying and preventing cyberattacks, it also introduces new vulnerabilities, as cybercriminals employ similar technologies to execute more complex and difficult-to-detect cyberattacks. Likewise, quantum computing  poses a distinct challenge to existing [encryption](https://www.atlantic.net/hipaa-compliant-hosting/why-is-encryption-so-key-to-hipaa-compliance/) techniques and thus makes the conventional security measures less effective. Cyberattacks are becoming more advanced, and traditional security methods no longer offer the same level of protection. Therefore, businesses need to rethink their approach to digital security. This requires adopting new strategies that rely on advanced technologies and preparing for future challenges. The concept of trust convergence, which integrates AI, [quantum-safe algorithms](https://www.ibm.com/think/topics/quantum-safe-cryptography), and conventional security techniques, has become an essential component of modern security strategies. Organizations should adopt technologies like AI-enhanced threat detection and quantum-safe algorithms to establish a robust and dependable framework for [digital trust](https://initiatives.weforum.org/digital-trust/home). This strategy will help businesses protect their data, proactively address emerging threats, and maintain the long-term security of their digital environments. ## The Evolving Digital Security Environment Traditional security methods, such as encryption, [Domain Name System (DNS)](https://www.atlantic.net/vps-hosting/what-is-dns-and-how-does-it-work/), and Public Key Infrastructure (PKI), have been widely used to secure sensitive data. However, as cyber threats become more advanced and quantum computing develops quickly, these methods alone are no longer enough to keep systems secure. Recent findings from [Gartner’s November 2024 survey](https://www.gartner.com/en/newsroom/press-releases/2024-05-22-gartner-survey-shows-ai-enhanced-malicious-attacks-as-top-er-for-enterprises-for-third-consec-quarter) show that AI-driven attacks are still the top emerging risk for businesses. This trend continued for the third quarter in a row. According to the survey of 286 senior risk executives, the rapid rise of AI-powered cyber threats has significantly impacted enterprise security, making it a leading concern. The costs are even higher in the financial sector, with breaches averaging $7.3 million. Likewise, ransomware attacks, driven by AI tools, rose by [149%](https://axisinsurance.ca/a-i-driven-cyberattacks-fuel-149-rise-in-ransomware-incidents-in-early-2025-our-advice-for-staying-ahead-of-the-next-breach/) in early 2025. Supply chain attacks are also expected to grow as cybercriminals target complex vendor networks. These trends show that AI’s ability to adapt quickly surpasses traditional security measures. While methods like DNS and PKI are still important, they have limitations. DNS is often the first defence against threats like phishing and malware. However, attackers can bypass it by exploiting weaknesses in DNS servers. Similarly, PKI uses certificates to verify and encrypt communications, but it faces risks from the growing power of quantum computing. Surprisingly, quantum computing seriously threatens encryption, which is an integral part of traditional security. Algorithms like RSA and Elliptic Curve Cryptography (ECC) are often used to protect data. However, they can be easily broken by a powerful quantum computer, making the current encryption methods outdated. This shows the urgent need to move to quantum-safe encryption techniques. ## How AI Strengthens Digital Trust Digital trust is essential for businesses today and AI plays a significant role in enforcing and maintaining it. AI helps enhance security by automating threat detection, improving response times, and providing predictive insights to prevent cyberattacks before they happen. AI can quickly identify threats by processing large volumes of data in real-time. It can also adapt to new attack patterns more effectively than human analysts. AI-based threat detection is a key component of digital trust. Real-time machine learning-based anomaly detection systems can identify unusual behaviors. These behaviors may indicate an impending attack. For example, AI can analyze network traffic for abnormal patterns. This may include attempts to steal data or unauthorized login activity. When these threats are recognized, AI can immediately stop breaches before they cause significant damage. In addition, AI plays a vital role in fraud detection and identity verification, which are essential to maintaining trust. In sectors like finance, machine learning algorithms can analyze transaction patterns. These patterns help detect fraudulent activities. These systems are meant to spot even minor irregularities. By ensuring that identities are accurately verified, AI strengthens the security of online transactions. Despite several benefits, AI brings new challenges. Cybercriminals are increasingly using AI to create more sophisticated attacks. For example, AI-based phishing attacks can be tailored to target specific individuals based on their online behavior. To overcome these challenges, businesses must adopt strong AI-based security measures capable of reacting quickly to new threats and protecting digital trust. This will help companies to avoid being outpaced by cybercriminals who use AI to exploit weaknesses. ## The Quantum Threat: Why Quantum-Safe Algorithms Matter Quantum computing appears to threaten current encryption systems due to its ability to solve complex problems much faster than classical computers. These computers use [qubits](https://www.ibm.com/think/topics/qubit), which enable them to perform calculations in parallel. This makes them capable of breaking widely used encryption methods like RSA and ECC through algorithms like [Shor’s algorithm](https://www.quera.com/glossary/shors-algorithm#:~:text=Shor's%20Algorithm%2C%20named%20after%20mathematician,known%20classical%20algorithms%20for%20factoring.), which can efficiently factor large numbers. One of the main risks of quantum computing is the [*harvest now, decrypt later*](https://www.nist.gov/cybersecurity/what-post-quantum-cryptography) threat. In this practice, cybercriminals intercept or steal encrypted data today with the expectation that quantum computers will be able to decrypt it in the future. This is a particular concern for industries like government, finance, and healthcare, where data security is critical. With quantum decryption becoming a reality soon, businesses should transition to quantum-safe algorithms to protect their sensitive data. Quantum-safe cryptography, also known as Post-Quantum Cryptography (PQC), is based on mathematical problems that are hard for quantum computers to solve. The [National Institute of Standards and Technology (NIST)](https://www.nist.gov/cybersecurity/what-post-quantum-cryptography) is working on standardizing these quantum-resistant algorithms, which are being developed to resist quantum attacks and tested for security and efficiency. Organizations must assess their current cryptographic systems to prepare for the quantum era. They should transition to quantum-safe methods by replacing outdated algorithms like RSA-2048 and ECC-256 with quantum-resistant alternatives. During the transition, hybrid systems that combine classical and quantum-safe algorithms can be used to maintain compatibility. Moreover, organizations should actively participate in testing and PQC migration initiatives to ensure smooth implementation. ## Trust Convergence: Integrating AI, DNS, PKI, and Quantum-Safe Security Trust convergence is a new way to improve digital security. It combines AI, DNS, PKI, and quantum-safe algorithms into a unified framework. This method increases digital trust by creating a multi-layered defense system. Each technology supports the others to provide better protection against evolving cyber threats. AI and DNS collaborate to identify and stop threats before they reach users. AI-based DNS filtering can find harmful domains in real-time, helping prevent phishing, malware, and other attacks. By acting early, AI and DNS minimize risk and enhance overall network security. Likewise, PKI is the foundation for secure communications. It provides authentication, encryption, and digital signatures. However, with the rise of quantum computing, traditional cryptographic methods face new challenges. Therefore, to be secure, PKI must adapt by adding quantum-safe cryptography. This ensures PKI can protect trusted identities and secure communications against quantum threats. By incorporating quantum-resistant algorithms into PKI, organizations can protect their security for the future. Combining AI for intelligent threat detection, DNS for network protection, PKI for identity assurance, and quantum-safe encryption can help build a strong and flexible security system. This system can respond to new threats while keeping users and data secure. As a result, the idea of trust convergence can help move cybersecurity from separate tools to a single, intelligent, and coordinated approach. ## Five-Step Trust Convergence Strategy for Cybersecurity Preparation Businesses should prioritize integrating AI, DNS, PKI, and quantum-safe encryption into their cybersecurity strategies to be secure against emerging threats. Below, a five-step trust convergence strategy for businesses to prepare for cybersecurity is presented: 1. Integrate AI-based threat detection tools to identify and stop threats in real time. This will help businesses respond quickly to potential security issues. 2. Implement DNS filtering to block harmful Websites and prevent phishing attacks. This will add an extra layer of protection and stop threats before they reach users. 3. Conduct a thorough review of cryptographic assets. Check current encryption methods and identify any weaknesses, especially those that could be affected by quantum threats. 4. Develop a plan to switch to quantum-safe encryption. As part of a long-term strategy, adopt quantum-resistant algorithms to ensure cryptographic systems are ready for the future. 5. Provide training for the project teams on AI-based security solutions and quantum-safe cryptography. Moreover, stay updated on NIST’s PQC standardization process and adopt quantum-safe algorithms as they become available. ## The Bottom Line With the rise of more advanced cyber threats, adopting new technologies like AI and quantum-safe encryption has become essential for businesses. Trust convergence, which combines AI, DNS, PKI, and quantum-safe systems, is the future of digital security. This approach strengthens protection by integrating these technologies into one cohesive framework. By implementing this strategy, organizations can address current vulnerabilities and prepare for future risks posed by quantum computing. While moving to these advanced technologies could be challenging, the long-term benefits far outweigh the difficulties. By investing in improved security measures now, organizations can build greater trust with users and ensure stronger resilience against future threats. Taking early action can help protect sensitive data and support uninterrupted business operations and ensure long-term security.   --- # How to Set up a TensorFlow Workspace on a Atlantic.Net Cloud GPU Instance > URL: https://www.atlantic.net/gpu-server-hosting/how-to-set-up-a-tensorflow-workspace-on-a-atlantic-net-cloud-gpu-instance/ | Published: 2025-06-25 | Updated: 2025-07-10 | Author: Hitesh Jethva TensorFlow is a popular open-source tool that makes it easier to build and train machine learning and deep learning models. It’s widely used by developers and companies to solve real-world problems using AI. TensorFlow provides everything needed to create powerful and scalable machine learning applications. This guide shows you how to set up a temporary or permanent TensorFlow workspace using Docker and NVIDIA’s GPU tools. ## Prerequisites Before getting started, ensure you have: - An Ubuntu 24.04 server with NVIDIA GPU(s). - NVIDIA drivers installed. - A non-root user with sudo privileges. ## Step 1: Check if Your GPU is Working Before starting, make sure your GPU is available. 1. Run this command on your server: ```bash nvidia-smi ``` This will show GPU details like model, memory, and usage. ```bash Sat Jun 7 07:20:18 2025 +-----------------------------------------------------------------------------------------+ | NVIDIA-SMI 550.90.07 Driver Version: 550.90.07 CUDA Version: 12.9 | |-----------------------------------------+------------------------+----------------------+ | GPU Name Persistence-M | Bus-Id Disp.A | Volatile Uncorr. ECC | | Fan Temp Perf Pwr:Usage/Cap | Memory-Usage | GPU-Util Compute M. | | | | MIG M. | |=========================================+========================+======================| | 0 NVIDIA A40-12Q On | 00000000:06:00.0 Off | 0 | | N/A N/A P0 N/A / N/A | 1MiB / 12288MiB | 0% Default | | | | N/A | +-----------------------------------------+------------------------+----------------------+ +-----------------------------------------------------------------------------------------+ | Processes: | | GPU GI CI PID Type Process name GPU Memory | | ID ID Usage | |=========================================================================================| | No running processes found | +-----------------------------------------------------------------------------------------+ ``` 2. Run the nvidia-smi command inside a container to check if Docker can access the GPU. ```bash docker run --rm --gpus all nvidia/cuda:12.9.0-base-ubuntu24.04 nvidia-smi ``` **Explanation:** - **–rm** deletes the container after use. - **–gpus** all lets Docker use the GPU. If you see GPU info, everything is working! ```bash Sat Jun 7 08:05:20 2025 +-----------------------------------------------------------------------------------------+ | NVIDIA-SMI 550.90.07 Driver Version: 550.90.07 CUDA Version: 12.9 | |-----------------------------------------+------------------------+----------------------+ | GPU Name Persistence-M | Bus-Id Disp.A | Volatile Uncorr. ECC | | Fan Temp Perf Pwr:Usage/Cap | Memory-Usage | GPU-Util Compute M. | | | | MIG M. | |=========================================+========================+======================| | 0 NVIDIA A40-12Q On | 00000000:06:00.0 Off | 0 | | N/A N/A P0 N/A / N/A | 1MiB / 12288MiB | 0% Default | | | | N/A | +-----------------------------------------+------------------------+----------------------+ +-----------------------------------------------------------------------------------------+ | Processes: | | GPU GI CI PID Type Process name GPU Memory | | ID ID Usage | |=========================================================================================| | No running processes found | +-----------------------------------------------------------------------------------------+ ``` 3. Install required dependencies. ```bash apt install -y python3-pip python3-venv ``` 4. Create and activate the Python virtual environment. ```bash python3 -m venv venv source venv/bin/activate ``` 5. Install Jupyter notebook. ```bash pip install jupyter ``` ## Step 2: Set Up a Temporary TensorFlow Workspace Atlantic.Net [Cloud GPU servers](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/) let you use powerful GPUs without buying expensive hardware. These servers are great for training machine learning models faster. In this section, we’ll show you how to quickly set up a temporary TensorFlow workspace on an Atlantic.Net Cloud GPU server. 1. Run TensorFlow in a Docker container. ```bash docker run --rm --gpus all -p 8888:8888 -v /root/notebooks:/tf/notebooks tensorflow/tensorflow:2.15.0-gpu-jupyter ``` **Explanation:** - **-p** 8888:8888 makes Jupyter Notebook accessible on port 8888. - **-v** /root/notebooks:/tf/notebooks saves notebooks to your server. You will see the following output containing Jupyter URL. ```bash To access the server, open this file in a browser: file:///root/.local/share/jupyter/runtime/jpserver-1-open.html Or copy and paste one of these URLs: http://c9af04990219:8888/tree?token=73873d6313d74f4477d83e15ffc4d95983ab8fd8e9f24be2 http://127.0.0.1:8888/tree?token=73873d6313d74f4477d83e15ffc4d95983ab8fd8e9f24be2 ``` 2. Open a web browser and access the Jupyter notebook using the URL **http://your-server-ip:8888/tree?token=73873d6313d74f4477d83e15ffc4d95983ab8fd8e9f24be2** ![](https://www.atlantic.net/wp-content/uploads/2025/06/p1.png) 3. Create a new notebook from the top left menu (file > new) . ![](https://www.atlantic.net/wp-content/uploads/2025/06/p2.png) 4. Run the following code in the Notebook cell. ```bash import tensorflow as tf tf.config.list_physical_devices() ``` If you see CPU and GPU listed, TensorFlow is using the GPU! ```bash [PhysicalDevice(name='/physical_device:CPU:0', device_type='CPU'), PhysicalDevice(name='/physical_device:GPU:0', device_type='GPU')] ``` ## Step 3: Set Up a Permanent TensorFlow Workspace For long-term use, we’ll use Docker Compose with Nginx (for secure access) and HTTPS. 1. Install Docker Compose. ```bash apt install docker-compose -y ``` 2. Create and navigate to the new directory named tensorflow-workspace. ```bash mkdir ~/tensorflow-workspace cd ~/tensorflow-workspace ``` 3. Create a docker-compose.yaml file. ```bash nano docker-compose.yaml ``` Add the following content. ```bash services: jupyter: image: tensorflow/tensorflow:2.15.0-gpu-jupyter restart: unless-stopped volumes: - "/root/notebooks:/tf/notebooks" deploy: resources: reservations: devices: - capabilities: [gpu] nginx: image: nginx restart: unless-stopped ports: - 80:80 - 443:443 volumes: - ./nginx/nginx.conf:/etc/nginx/nginx.conf - ./nginx/dhparam.pem:/etc/ssl/certs/dhparam.pem - ./certbot/conf:/etc/letsencrypt - ./certbot/www:/var/www/certbot certbot: image: certbot/certbot container_name: certbot volumes: - ./certbot/conf:/etc/letsencrypt - ./certbot/www:/var/www/certbot command: certonly --webroot -w /var/www/certbot --email YOUR_EMAIL@example.com -d your_domain.com --agree-tos --no-eff-email ``` The above setup includes three services. - The **jupyter** service runs a container with TensorFlow and GPU support, and it saves all your notebooks in the /root/notebooks folder. - The **nginx** service uses the official Nginx container to work as a reverse proxy, passing traffic between users and the jupyter server. - The **certbot** service uses the official Certbot container to get a free SSL certificate from Let’s Encrypt for your domain name. 4. Create a new directory for Nginx. ```bash mkdir nginx ``` 5. Create an Nginx configuration file. ```bash nano nginx/nginx.conf ``` Add the following configuration. ```bash events {} http { server_tokens off; charset utf-8; server { listen 80; server_name tensorflow.example.com; location ~ /.well-known/acme-challenge/ { root /var/www/certbot; } } } ``` The above setup tells the Nginx server to handle the special verification files created by Certbot. This step is needed so Certbot can prove that you own the domain name and then issue a free SSL certificate for it. 6. Create a directory structure for Let’s Encrypt challenge. ```bash mkdir -p certbot/www/.well-known/acme-challenge ``` 7. Deploy the Docker Compose services. ```bash docker-compose up -d ``` The above command starts the services defined in the **docker-compose.yaml** file in detached mode. 8. Verify the SSL issuance. ```bash ls certbot/conf/live/tensorflow.example.com/ ``` Output. ```bash cert.pem chain.pem fullchain.pem privkey.pem README ``` 9. Edit the Nginx configuration file. ```bash nano nginx/nginx.conf ``` Remove all existing content and add the below configuration. ```bash events {} http { server_tokens off; charset utf-8; map $http_upgrade $connection_upgrade { default upgrade; '' close; } server { listen 80; server_name tensorflow.example.com; return 301 https://$host$request_uri; } server { listen 443 ssl http2; server_name tensorflow.example.com; ssl_certificate /etc/letsencrypt/live/tensorflow.example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/tensorflow.example.com/privkey.pem; ssl_protocols TLSv1.2 TLSv1.3; ssl_prefer_server_ciphers on; ssl_ciphers 'ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384'; ssl_session_timeout 1d; ssl_session_cache shared:SSL:50m; ssl_stapling on; ssl_stapling_verify on; add_header Strict-Transport-Security max-age=15768000; location / { proxy_pass http://jupyter:8888; proxy_set_header X-Real-IP $remote_addr; proxy_set_header Host $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection $connection_upgrade; proxy_set_header X-Scheme $scheme; proxy_buffering off; } location ~ /.well-known/acme-challenge/ { root /var/www/certbot; } } } ``` The above setup uses the SSL certificate from Certbot along with extra security settings to protect your workspace. It also sets up a reverse proxy server that sends incoming traffic to the Jupyter container running on port 8888. 10. Restart the Nginx container to apply the changes. ```bash docker-compose restart nginx ``` 11. Retrieve the token from the Docker logs. ```bash docker-compose logs jupyter ``` This command outputs the logs generated by the jupyter container. It contains the token to access the Jupyter notebook interface. ```bash jupyter_1 | To access the server, open this file in a browser: jupyter_1 | file:///root/.local/share/jupyter/runtime/jpserver-1-open.html jupyter_1 | Or copy and paste one of these URLs: jupyter_1 | http://19880e871edf:8888/tree?token=cfecf37285dccaf783a751bda24b4497a1279487ebd70c03 jupyter_1 | http://127.0.0.1:8888/tree?token=cfecf37285dccaf783a751bda24b4497a1279487ebd70c03 ``` 12. Open your web browser and access the Jupyter notebook using **https://tensorflow.example.com.** ![](https://www.atlantic.net/wp-content/uploads/2025/06/p3.png) 13. Scroll down to the **“Setup** **a Password**” section. Enter the **token** fetched from the Docker Compose logs. Enter the password you want to use to protect the interface. Click the “**Log in and set new password**” button. You will see the Jupyter notebook dashboard. ## Conclusion This article showed how to set up a temporary or long-term TensorFlow workspace using the official Docker image and NVIDIA Docker Toolkit. You can create a temporary setup to use the powerful hardware from Atlantic.Net for tasks like training models or creating visualizations. You can also set up a permanent workspace, which gives you a stable environment for remote development. With the Jupyter notebook interface, it’s easy to collaborate with others on your machine learning projects – try it on [GPU Hosting](https://www.atlantic.net/gpu-server-hosting/) from Atlantic.Net. --- # How to Deploy a High-Performance Semantic Search Application Using Zilliz on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-deploy-a-high-performance-semantic-search-application-using-zilliz-on-ubuntu-24-04-gpu-server/ | Published: 2025-06-26 | Updated: 2026-05-04 | Author: Hitesh Jethva Semantic search represents the next evolution in search technology, moving beyond keyword matching to understanding the intent and contextual meaning behind queries. When combined with GPU acceleration, semantic search systems can deliver unprecedented performance and accuracy for applications like e-commerce product discovery, enterprise document retrieval, and personalized recommendation systems. In this guide, we’ll walk through deploying a high-performance semantic search application using Zilliz (an open-source vector database) on an Ubuntu 24.04 GPU server. ## Prerequisites Before beginning, ensure you have: - An Ubuntu 24.04 server with NVIDIA GPU (Tested on A100, V100, or RTX 3090/4090). - NVIDIA drivers installed. - A root user or a user with sudo privileges. ## Step 1: Set Up the Python Environment 1. Update the system packages. ```bash apt update -y ``` 2. Install required dependencies. ```bash apt install -y python3-pip python3-venv build-essential libssl-dev docker-compose ``` ## Step 2: Install Zilliz with GPU Support Zilliz offers several deployment options. We’ll use the open-source Milvus version with GPU acceleration: 1. Pull the GPU-enabled Milvus image ```bash docker pull milvusdb/milvus:latest-gpu ``` 2. Create a docker-compose.yml file. ```bash nano docker-compose.yml ``` Add the following content. ```bash version: '3.5' services: etcd: container_name: milvus-etcd image: quay.io/coreos/etcd:v3.5.5 environment: - ETCD_AUTO_COMPACTION_MODE=revision - ETCD_AUTO_COMPACTION_RETENTION=1000 - ETCD_QUOTA_BACKEND_BYTES=4294967296 - ETCD_SNAPSHOT_COUNT=50000 volumes: - ./etcd_data:/etcd command: etcd -advertise-client-urls=http://127.0.0.1:2379 -listen-client-urls http://0.0.0.0:2379 --data-dir /etcd minio: container_name: milvus-minio image: minio/minio:RELEASE.2023-03-20T20-16-18Z environment: MINIO_ACCESS_KEY: minioadmin MINIO_SECRET_KEY: minioadmin volumes: - ./minio_data:/minio_data command: minio server /minio_data healthcheck: test: ["CMD", "curl", "-f", "http://localhost:9000/minio/health/live"] interval: 30s timeout: 20s retries: 3 standalone: container_name: milvus-standalone image: milvusdb/milvus:latest-gpu command: ["milvus", "run", "standalone"] environment: ETCD_ENDPOINTS: etcd:2379 MINIO_ADDRESS: minio:9000 volumes: - ./milvus_data:/var/lib/milvus ports: - "19530:19530" depends_on: - "etcd" - "minio" deploy: resources: reservations: devices: - driver: nvidia count: 1 capabilities: [gpu] networks: default: name: milvus ``` 3. Start the containers. ```bash docker compose up -d ``` ## Step 3: Verify the Installation 1. Check that all services are running. ```bash docker ps ``` Output. ```bash CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 7546b3a7999a milvusdb/milvus:latest-gpu "/tini -- milvus run…" 16 seconds ago Up 16 seconds 0.0.0.0:19530->19530/tcp, [::]:19530->19530/tcp milvus-standalone d700cd1e1af3 minio/minio:RELEASE.2023-03-20T20-16-18Z "/usr/bin/docker-ent…" 16 seconds ago Up 16 seconds (health: starting) 9000/tcp milvus-minio fbe9fd450a28 quay.io/coreos/etcd:v3.5.5 "etcd -advertise-cli…" 16 seconds ago Up 16 seconds 2379-2380/tcp milvus-etcd ``` 2. Create a Python virtual environment. ```bash python3 -m venv semantic_env source semantic_env/bin/activate ``` 3. Install the Milvus client. ```bash pip install pymilvus ``` 4. Test the Milvus connection. ```bash python3 -c "from pymilvus import connections, utility; connections.connect('default', host='localhost', port='19530'); print(utility.get_server_version())" ``` Output. ```bash v2.4.15-gpu ``` ## Step 4: Set Up the Semantic Search Application 1. Install required packages. ```bash pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu118 pip install sentence-transformers pymilvus fastapi uvicorn python-multipart ``` 2. Create a file named semantic_search.py. ```bash nano semantic_search.py ``` Add the below code. ```bash import torch from sentence_transformers import SentenceTransformer from pymilvus import ( connections, Collection, utility, FieldSchema, CollectionSchema, DataType ) import numpy as np from fastapi import FastAPI, Query, HTTPException from fastapi.responses import JSONResponse from typing import Optional import uuid import logging from pydantic import BaseModel # Configure logging logging.basicConfig(level=logging.INFO) logger = logging.getLogger(__name__) # Initialize FastAPI app = FastAPI( title="Semantic Search API", description="GPU-accelerated semantic search using Zilliz/Milvus", version="1.0" ) # Configuration COLLECTION_NAME = "semantic_search" EMBEDDING_DIM = 384 # Dimension for 'all-MiniLM-L6-v2' model MODEL_NAME = "all-MiniLM-L6-v2" MILVUS_HOST = "localhost" MILVUS_PORT = 19530 # Initialize the model (GPU if available) device = "cuda" if torch.cuda.is_available() else "cpu" logger.info(f"Using device: {device}") model = SentenceTransformer(MODEL_NAME, device=device) logger.info(f"Initialized model on device: {device}") # Pydantic models for API documentation class Document(BaseModel): text: str doc_id: Optional[str] = None class SearchResult(BaseModel): id: str text: str score: float class SearchResponse(BaseModel): results: list[SearchResult] class ErrorResponse(BaseModel): error: str detail: Optional[str] = None def initialize_milvus(): """Initialize connection and create collection if needed""" try: # Connect to Milvus connections.connect("default", host=MILVUS_HOST, port=MILVUS_PORT) # Create collection if it doesn't exist if not utility.has_collection(COLLECTION_NAME): fields = [ FieldSchema(name="id", dtype=DataType.VARCHAR, is_primary=True, auto_id=False, max_length=100), FieldSchema(name="text", dtype=DataType.VARCHAR, max_length=5000), FieldSchema(name="embedding", dtype=DataType.FLOAT_VECTOR, dim=EMBEDDING_DIM) ] schema = CollectionSchema(fields, "Semantic search collection") collection = Collection(COLLECTION_NAME, schema, consistency_level="Strong") # Create index index_params = { "index_type": "IVF_FLAT", "metric_type": "L2", "params": {"nlist": 128} } collection.create_index("embedding", index_params) logger.info("Created new collection with index") else: collection = Collection(COLLECTION_NAME) logger.info("Connected to existing collection") # Explicit load for version compatibility try: collection.load() except Exception as e: logger.warning(f"Load warning (may be normal in some versions): {str(e)}") return collection except Exception as e: logger.error(f"Milvus initialization failed: {str(e)}") raise HTTPException( status_code=500, detail=f"Database connection failed: {str(e)}" ) # Initialize Milvus connection on startup try: collection = initialize_milvus() except Exception as e: logger.error(f"Failed to initialize Milvus: {str(e)}") collection = None @app.on_event("shutdown") def shutdown_event(): """Clean up on shutdown""" if connections.has_connection("default"): connections.disconnect("default") logger.info("Disconnected from Milvus") @app.post("/documents/", response_model=dict, responses={500: {"model": ErrorResponse}}) async def add_document(document: Document): """Add a document to the search index""" try: if not collection: raise HTTPException(status_code=503, detail="Service unavailable") # Generate embedding embedding = model.encode(document.text) # Prepare data doc_id = document.doc_id if document.doc_id else str(uuid.uuid4()) data = [ [doc_id], [document.text], [embedding.tolist()] ] # Insert into Milvus collection.insert(data) collection.flush() return {"status": "success", "id": doc_id} except Exception as e: logger.error(f"Document insertion failed: {str(e)}") raise HTTPException( status_code=500, detail=f"Document processing failed: {str(e)}" ) @app.get("/search/", response_model=SearchResponse, responses={ 400: {"model": ErrorResponse}, 500: {"model": ErrorResponse}, 503: {"model": ErrorResponse} }) async def search( query: str = Query(..., min_length=1, max_length=1000), top_k: int = Query(5, ge=1, le=100) ): """Search for similar documents""" try: if not collection: raise HTTPException(status_code=503, detail="Service unavailable") # Version-compatible load check try: if hasattr(collection, 'is_loaded') and not collection.is_loaded: collection.load() elif not hasattr(collection, 'is_loaded'): collection.load() # Force load for older versions except Exception as e: logger.warning(f"Load warning: {str(e)}") # Generate embedding query_embedding = model.encode(query) # Search parameters search_params = { "metric_type": "L2", "params": {"nprobe": 10} } # Execute search results = collection.search( data=[query_embedding.tolist()], anns_field="embedding", param=search_params, limit=top_k, output_fields=["text"] ) # Format results ret = [] for hits in results: for hit in hits: ret.append({ "id": hit.id, "text": hit.entity.get("text"), "score": 1 - hit.distance # Convert to similarity score }) return {"results": ret} except ValueError as e: raise HTTPException(status_code=400, detail=str(e)) except Exception as e: logger.error(f"Search failed: {str(e)}") raise HTTPException( status_code=500, detail=f"Search processing failed: {str(e)}" ) @app.get("/status") async def service_status(): """Check service health""" try: milvus_ok = connections.has_connection("default") gpu_available = torch.cuda.is_available() # Version-compatible collection check collection_status = False if collection: try: if hasattr(collection, 'is_loaded'): collection_status = collection.is_loaded else: # For older versions, assume loaded if we have a collection object collection_status = True except: collection_status = False return { "milvus_connected": milvus_ok, "gpu_available": gpu_available, "collection_loaded": collection_status, "model": MODEL_NAME, "status": "healthy" if all([milvus_ok, collection_status]) else "degraded" } except Exception as e: return { "status": "unhealthy", "error": str(e) } if __name__ == "__main__": import uvicorn uvicorn.run(app, host="0.0.0.0", port=8000) ``` ## Step 5: Launch the Application 1. Start the FastAPI service. ```bash python3 semantic_search.py ``` Output. ```bash INFO: Started server process [59814] INFO: Waiting for application startup. INFO: Application startup complete. INFO: Uvicorn running on http://0.0.0.0:8000 (Press CTRL+C to quit) ``` 2. Your semantic search service is now running on port 8000. ## Step 6: Test the Application 1. Add the text **“The quick brown fox jumps over the lazy dog”** to documents. ```bash curl -X POST "http://localhost:8000/documents/" -H "Content-Type: application/json" -d '{"text": "The quick brown fox jumps over the lazy dog"}' ``` Output. ```bash {"status":"success","id":"c9dbb77f-a41f-4056-bd4b-69eab9334ae3"} ``` 2. Search for “brown fox” from the added documents using curl. ```bash curl -G "http://localhost:8000/search/" --data-urlencode "query=brown fox" --data "top_k=2" ``` Output. ```bash {"results":[{"id":"c9dbb77f-a41f-4056-bd4b-69eab9334ae3","text":"The quick brown fox jumps over the lazy dog","score":0.24801254272460938},{"id":"f27c880e-9b18-4a6f-b625-dc57e393117d","text":"The quick brown fox jumps over the lazy dog","score":0.24801254272460938}]} ``` 3. Check the health status of your application. ```bash curl "http://localhost:8000/status" ``` Output. ```bash {"milvus_connected":true,"gpu_available":true,"collection_loaded":true,"model":"all-MiniLM-L6-v2","status":"healthy"} ``` ## Conclusion You’ve now deployed a high-performance semantic search application leveraging Zilliz (Milvus) on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). The architecture can be extended with custom embedding models, hybrid search (combining vectors and keywords), and real-time indexing for dynamic content. --- # How to Deploy a PyTorch Workspace on a Atlantic.Net Cloud GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-deploy-a-pytorch-workspace-on-a-atlantic-net-cloud-gpu-server/ | Published: 2025-06-27 | Updated: 2025-07-10 | Author: Hitesh Jethva PyTorch is a free, open-source tool used for deep learning tasks like natural language processing and computer vision. It’s easy to use and flexible, making it simple to build and use AI models in different types of projects. Running a PyTorch workspace on Atlantic.Net lets you take advantage of powerful [Cloud GPU servers](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/) with NVIDIA A100 and A40 GPUs. This is great for heavy tasks like training models using the torch library. By combining PyTorch with JupyterLab, you get a smooth remote development setup where you can easily work with others on machine learning projects. This article shows you how to create your own Docker image by starting with a PyTorch image and adding JupyterLab. It also guides you through setting everything up using Docker and Docker Compose on Atlantic.Net Cloud GPU servers with help from the NVIDIA Docker Toolkit. ## Prerequisites Before getting started, ensure you have: - An Ubuntu 24.04 server with NVIDIA GPU(s). - NVIDIA drivers installed. - A non-root user with sudo privileges. ## Step 1: Verify GPU Availability Before starting, make sure your GPU is detected and working. 1. Check GPU on the server. ```bash nvidia-smi ``` This shows GPU details like model, driver version, and memory usage. ```bash Sat Jun 7 07:20:18 2025 +-----------------------------------------------------------------------------------------+ | NVIDIA-SMI 550.90.07 Driver Version: 550.90.07 CUDA Version: 12.4 | |-----------------------------------------+------------------------+----------------------+ | GPU Name Persistence-M | Bus-Id Disp.A | Volatile Uncorr. ECC | | Fan Temp Perf Pwr:Usage/Cap | Memory-Usage | GPU-Util Compute M. | | | | MIG M. | |=========================================+========================+======================| | 0 NVIDIA A40-12Q On | 00000000:06:00.0 Off | 0 | | N/A N/A P0 N/A / N/A | 1MiB / 12288MiB | 0% Default | | | | N/A | +-----------------------------------------+------------------------+----------------------+ +-----------------------------------------------------------------------------------------+ | Processes: | | GPU GI CI PID Type Process name GPU Memory | | ID ID Usage | |=========================================================================================| | No running processes found | +-----------------------------------------------------------------------------------------+ ``` 2. Install required dependencies. ```bash apt install -y python3-pip python3-venv docker-compose docker.io ``` 3. Run a temporary PyTorch container. ```bash docker run --rm -it --gpus all pytorch/pytorch:latest ``` **Explanation:** - **–gpus** all allows Docker to use the GPU. - **-it** gives you an interactive terminal. - **–rm** deletes the container when you exit. After running the above command, you will get into the container shell as shown below. ```bash root@7117aa4ac0ba:/workspace# ``` 4. Connect to the Python shell. ```bash root@7117aa4ac0ba:/workspace# python ``` Output. ```bash Python 3.10.13 (main, Sep 11 2023, 13:44:35) [GCC 11.2.0] on linux Type "help", "copyright", "credits" or "license" for more information. >>> ``` 5. Check if PyTorch detects the GPU. ```bash >>> import torch >>> torch.cuda.is_available() ``` If the output says **True,** your GPU is working! ```bash True ``` 6. Use the **quit()** command to quit the Python console and the **exit** command to exit the container terminal. ## Step 2: Build a Custom Docker Image with PyTorch & JupyterLab We’ll create a new Docker image that includes PyTorch + JupyterLab for easy coding. 1. Create and activate the Python virtual environment. ```bash python3 -m venv venv source venv/bin/activate ``` 2. Install Jupyter notebook. ```bash pip install jupyter ``` 3. Create a new configuration file for Jupyter notebook. ```bash nano config.py ``` Add the following content: ```bash c.ServerApp.ip = '0.0.0.0' c.ServerApp.allow_root = True c.ServerApp.allow_remote_access = True c.ServerApp.password = '' ``` The above setup tells the JupyterLab server to accept remote connections and listen on IP address **0.0.0.0,** which allows you to access the workspace using the server’s public IP. You can also add other settings to this file to customize the container before it runs. 4. Create the password hash using the passwd function. ```bash python3 -c "from jupyter_server.auth import passwd; print(passwd('securepassword'))" ``` Output. ```bash argon2:$argon2id$v=19$m=10240,t=10,p=8$+Gm411wZBogCWpF/CyvvMg$w+tQ9IctMYs4P6Zbi6rcwEGx8HVerRxHczhBtFHsSV0 ``` 5. Edit the config.py. ```bash nano config.py ``` Replace the c.ServerApp.password value in the config.py file with the output. ```bash c.ServerApp.ip = '0.0.0.0' c.ServerApp.allow_root = True c.ServerApp.allow_remote_access = True c.ServerApp.password = 'argon2:$argon2id$v=19$m=10240,t=10,p=8$+Gm411wZBogCWpF/CyvvMg$w+tQ9IctMYs4P6Zbi6rcwEGx8HVerRxHczhBtFHsSV0' ``` 6. Create a Dockerfile. ```bash nano Dockerfile ``` Add the below content. ```bash FROM pytorch/pytorch:latest RUN pip install jupyterlab RUN pip install -U ipywidgets ipykernel COPY config.py /root/.jupyter/jupyter_lab_config.py EXPOSE 8888 CMD ["bash", "-c", "jupyter lab"] ``` The above steps use the official PyTorch container image as a starting point. It installs JupyterLab using pip, copies the config file you created earlier, opens port **8888,** and runs the JupyterLab server with the **bash -c jupyter lab** command. 7. Build the Docker image. ```bash docker build -t pytorch-jupyter . ``` This builds a new container image called pytorch-jupyter. You can also upload this image to your private DockerHub account so it’s ready to use anytime you want to quickly launch a PyTorch workspace for heavy tasks like training models. ## Step 3: Deploy the Workspace using Docker In the last section, you created the pytorch-jupyter image by combining JupyterLab and the PyTorch container. This part now shows how to run that image using Docker to set up a temporary workspace or test your setup. 1. Run a temporary container using the pytorch-jupyter image. ```bash docker run --rm -it --gpus all -p 8888:8888 pytorch-jupyter ``` This command starts a new container using the image you created. The **–gpus** all option gives the container access to all GPUs on the host machine. The **-it** option allows you to interact with the container through the terminal. The **–rm** option makes sure the container is automatically deleted from the system once it stops running. 2. Open your web browser and access the URL **http://your-server-ip:8888.** You will see the Jupyter notebook login page. ![](https://www.atlantic.net/wp-content/uploads/2025/06/p1-1.png) 3. Log in to the JupyterLab interface using the password you used to create the password hash in the previous sections. ![](https://www.atlantic.net/wp-content/uploads/2025/06/p2-1.png) 4. Create a new notebook. ![](https://www.atlantic.net/wp-content/uploads/2025/06/p3-1.png) Then add the below function in a new notebook to verify the GPU availability. ```bash import torch if torch.cuda.is_available(): print("✅ GPU is available!") print(f"GPU Name: {torch.cuda.get_device_name(0)}") else: print("❌ GPU is NOT available.") ``` 5. Run the Notebook. If everything is fine, you will see the message “✅ GPU is available!”. 6. Go back to your terminal and exit the container using **Ctrl + C**. ## Step 4: Deploy a Permanent Workspace (Docker Compose) In this section, we’ll deploy a persistent PyTorch workspace on an Atlantic.Net Cloud GPU server using Docker Compose. 1. Create and enter a new directory named pytorch-environment. ```bash mkdir ~/pytorch-environment cd ~/pytorch-environment ``` 2. Create a new file named docker-compose.yaml. ```bash nano docker-compose.yaml ``` Add the following content: ```bash services: jupyter: image: pytorch-jupyter restart: unless-stopped volumes: - "/root/workspace:/workspace" deploy: resources: reservations: devices: - capabilities: [gpu] nginx: image: nginx restart: unless-stopped ports: - 80:80 - 443:443 volumes: - ./nginx/nginx.conf:/etc/nginx/nginx.conf - ./certbot/conf:/etc/letsencrypt - ./certbot/www:/var/www/certbot certbot: image: certbot/certbot container_name: certbot volumes: - ./certbot/conf:/etc/letsencrypt - ./certbot/www:/var/www/certbot command: certonly --webroot -w /var/www/certbot --force-renewal --email hitjethva@gmail.com -d pytorch.example.com --agree-tos ``` The above setup includes three services. - The **jupyter** service runs a container with a GPU-powered PyTorch workspace and saves all workspace files in the /root/workspace folder using the volumes setting. - The **nginx** service uses the official Nginx image to act as a reverse proxy, directing traffic from users to the Jupyter service. - The **certbot** service uses the official Certbot image to request a free SSL certificate from Let’s Encrypt for your domain. **Important:** Replace `your-email@example.com` and `pytorch.example.com` with your own email and domain name. 2. Create a new directory named nginx. ```bash mkdir nginx ``` 3. Create a new file named nginx/nginx.conf inside the directory. ```bash nano nginx/nginx.conf ``` Add the below content. ```bash user nginx; worker_processes auto; error_log /var/log/nginx/error.log warn; pid /var/run/nginx.pid; events { worker_connections 1024; } http { server_tokens off; charset utf-8; include /etc/nginx/mime.types; default_type application/octet-stream; sendfile on; keepalive_timeout 65; access_log /var/log/nginx/access.log; server { listen 80; server_name pytorch.example.com; location /.well-known/acme-challenge/ { root /var/www/certbot; } location / { return 404; } } } ``` 4. Create required directories. ```bash mkdir -p certbot/www/.well-known/acme-challenge ``` 5. Start the PyTorch workspace. ```bash docker-compose up -d ``` The above command launches the services listed in the **docker-compose.yaml** file in detached mode. This means the services will run in the background, allowing you to continue using your terminal for other tasks. 6. Verify the generated SSL certificates. ```bash ls certbot/conf/live/pytorch.example.com/ ``` Output. ```bash cert.pem chain.pem fullchain.pem privkey.pem README ``` 7. Update the nginx.conf file. ```bash nano nginx/nginx.conf ``` Replace existing content with the following: ```bash user nginx; worker_processes auto; error_log /var/log/nginx/error.log warn; pid /var/run/nginx.pid; events { worker_connections 1024; } http { server_tokens off; charset utf-8; include /etc/nginx/mime.types; default_type application/octet-stream; sendfile on; keepalive_timeout 65; access_log /var/log/nginx/access.log; # HTTP - for Certbot challenge and redirect to HTTPS server { listen 80; server_name pytorch.example.com; # Let’s Encrypt challenge path location /.well-known/acme-challenge/ { root /var/www/certbot; } # Redirect everything else to HTTPS location / { return 301 https://$host$request_uri; } } # HTTPS - Secure JupyterLab server { listen 443 ssl; server_name pytorch.example.com; ssl_certificate /etc/letsencrypt/live/pytorch.example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/pytorch.example.com/privkey.pem; ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; location / { proxy_pass http://jupyter:8888; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } } } ``` The above setup uses the SSL certificate provided by Certbot. It sets up a reverse proxy server that forwards incoming traffic to the container running on port 8888. It also includes a location block to handle ACME challenge files, which are needed for automatic SSL renewal through a scheduled Cron job. 8. Restart the Nginx service. ```bash docker-compose restart nginx ``` 9. You can now confirm the deployment of the workspace by opening **https://pytorch.example.com** in your web browser. ## Conclusion This article explained how to start with the PyTorch container image and install JupyterLab to create a custom container image. It also guided you through deploying the setup using Docker and Docker Compose on Atlantic.Net Cloud GPU servers. You can also upload your custom image to your DockerHub account, making it easy to launch temporary PyTorch workspaces whenever you need them. --- # How to Use Zilliz for Scalable Vector Search on Ubuntu 24.04 GPU Instances > URL: https://www.atlantic.net/gpu-server-hosting/how-to-use-zilliz-for-scalable-vector-search-on-ubuntu-24-04-gpu-instances/ | Published: 2025-06-28 | Updated: 2025-07-10 | Author: Hitesh Jethva Vector search has become a critical component of modern AI applications, enabling efficient similarity searches in high-dimensional spaces. Zilliz is a powerful vector database that provides scalable, high-performance search capabilities, particularly when leveraging GPU acceleration. In this guide, we’ll walk through setting up and using Zilliz on Ubuntu 24.04 GPU instances for optimal vector search performance. ## Prerequisites Before getting started, ensure you have: - An Ubuntu 24.04 server with NVIDIA GPU(s). - NVIDIA drivers installed. - A non-root user with sudo privileges. ## Step 1: Set Up Your GPU Environment First, install the necessary dependencies. ```bash apt update -y apt install -y python3-pip python3-venv docker-compose ``` ## Step 2: Install Zilliz with GPU Support Zilliz offers several deployment options. For GPU instances, we recommend using Milvus (the open-source version of Zilliz) with GPU acceleration: 1. Create a directory for your Zilliz deployment. ```bash mkdir zilliz-gpu && cd zilliz-gpu ``` 2. Create a **docker-compose.yaml** file for GPU-enabled Milvus. ```bash nano docker-compose.yaml ``` Add the below content: ```bash version: '3.5' services: etcd: container_name: milvus-etcd image: quay.io/coreos/etcd:v3.5.5 environment: - ETCD_AUTO_COMPACTION_MODE=revision - ETCD_AUTO_COMPACTION_RETENTION=1000 - ETCD_QUOTA_BACKEND_BYTES=4294967296 - ETCD_SNAPSHOT_COUNT=50000 volumes: - ${DOCKER_VOLUME_DIRECTORY:-.}/etcd:/etcd command: etcd -advertise-client-urls=http://127.0.0.1:2379 -listen-client-urls http://0.0.0.0:2379 --data-dir /etcd minio: container_name: milvus-minio image: minio/minio:RELEASE.2023-03-20T20-16-18Z environment: MINIO_ACCESS_KEY: minioadmin MINIO_SECRET_KEY: minioadmin volumes: - ${DOCKER_VOLUME_DIRECTORY:-.}/minio:/minio_data command: minio server /minio_data healthcheck: test: ["CMD", "curl", "-f", "http://localhost:9000/minio/health/live"] interval: 30s timeout: 20s retries: 3 standalone: container_name: milvus-standalone image: milvusdb/milvus:v2.3.3-gpu command: ["milvus", "run", "standalone"] environment: ETCD_ENDPOINTS: etcd:2379 MINIO_ADDRESS: minio:9000 volumes: - ${DOCKER_VOLUME_DIRECTORY:-.}/volumes/milvus:/var/lib/milvus ports: - "19530:19530" - "9091:9091" depends_on: - "etcd" - "minio" deploy: resources: reservations: devices: - driver: nvidia count: 1 capabilities: [gpu] ``` 3. Start the containers. ```bash docker-compose up -d ``` 4. Verify the services are running. ```bash docker ps ``` Output. ```bash CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 66ac3ea90205 milvusdb/milvus:v2.3.3-gpu "/tini -- milvus run…" 11 minutes ago Up 11 minutes 0.0.0.0:9091->9091/tcp, [::]:9091->9091/tcp, 0.0.0.0:19530->19530/tcp, [::]:19530->19530/tcp milvus-standalone cd2e62004369 quay.io/coreos/etcd:v3.5.5 "etcd -advertise-cli…" 11 minutes ago Up 11 minutes 2379-2380/tcp milvus-etcd e09e5cb48212 minio/minio:RELEASE.2023-03-20T20-16-18Z "/usr/bin/docker-ent…" 11 minutes ago Up 11 minutes (healthy) 9000/tcp milvus-minio ``` ## Step 3: Install Python Client and Dependencies 1. Create a Python virtual environment. ```bash python3 -m venv zilliz-env source zilliz-env/bin/activate ``` 2. Install the necessary Python packages. ```bash pip install pymilvus torch torchvision sentence-transformers ``` ## Step 4: Connect to Zilliz and Create a Collection 1. First, create a Python script to import all necessary Python modules, including the Milvus client and SentenceTransformer for embedding generation. ```bash nano zilliz_demo.py ``` Add the below code: ```bash #!/usr/bin/env python3 from pymilvus import connections, utility, FieldSchema, CollectionSchema, DataType, Collection from sentence_transformers import SentenceTransformer import time import torch import pymilvus ``` **Explanation:** - **pymilvus** is used to interact with the Milvus vector database. - **SentenceTransformer** loads a pre-trained transformer model for sentence embeddings. - **torch** detects if GPU is available for faster inference. 2. Verify a connection to Milvus server. ```bash def verify_connection(): """Verify connection to Milvus server""" try: # Test connection connections.connect("default", host="localhost", port="19530") print("✓ Successfully connected to Milvus server") # Check server status print(f"Server status: {utility.get_server_version()}") print(f"List of collections: {utility.list_collections()}") return True except Exception as e: print(f"Failed to connect to Milvus: {e}") return False ``` **Explanation:** - Connects to a Milvus instance running on localhost:19530. - Prints server version and any existing collections to confirm successful connection. 3. Creates a new Milvus collection if it doesn’t exist, generates embeddings for a set of documents, and inserts them into the collection. ```bash def create_collection(): """Create a collection with sample data""" # Configuration collection_name = "document_embeddings" dim = 384 # Dimension of SBERT embeddings # Verify connection first if not verify_connection(): return # Initialize model (using GPU if available) device = 'cuda' if torch.cuda.is_available() else 'cpu' print(f"Using device: {device}") model = SentenceTransformer('all-MiniLM-L6-v2', device=device) # Create collection if it doesn't exist if not utility.has_collection(collection_name): print(f"Creating collection: {collection_name}") fields = [ FieldSchema(name="id", dtype=DataType.INT64, is_primary=True, auto_id=True), FieldSchema(name="text", dtype=DataType.VARCHAR, max_length=500), FieldSchema(name="embedding", dtype=DataType.FLOAT_VECTOR, dim=dim) ] schema = CollectionSchema(fields, description="Document embeddings collection") collection = Collection(collection_name, schema) # Create index for efficient search index_params = { "index_type": "IVF_PQ", "metric_type": "L2", "params": {"nlist": 128, "m": 16, "nbits": 8} } collection.create_index("embedding", index_params) print("Collection created with IVF_PQ index") else: collection = Collection(collection_name) print(f"Collection {collection_name} already exists") # Sample data documents = [ "Zilliz provides scalable vector search solutions", "Ubuntu 24.04 offers improved GPU support", "Vector databases are essential for AI applications", "GPU acceleration significantly improves vector search performance" ] # Generate embeddings print("Generating embeddings...") start_time = time.time() embeddings = model.encode(documents) print(f"Embeddings generated in {time.time() - start_time:.2f} seconds") # Prepare data for insertion - CORRECTED FORMAT entities = [ documents, # text field embeddings.tolist() # embedding field ] # Insert data - now properly formatted print("Inserting data...") mr = collection.insert(entities) # Removed extra list wrapper # Wait for collection to load collection.load() print(f"Inserted {len(documents)} documents") return collection ``` **Explanation:** - Initializes the SentenceTransformer model (GPU-accelerated if available). - Defines the collection schema with fields: auto-generated id, text, and embedding. - Creates an IVF_PQ index for efficient vector search. - Encodes 4 sample sentences into 384-dim embeddings using SBERT. - Inserts the documents and loads the collection for querying. 4. Encodes a search query into an embedding and performs an ANN (Approximate Nearest Neighbor) search in the Milvus collection. ```bash def perform_search(collection): """Perform a sample vector search""" device = 'cuda' if torch.cuda.is_available() else 'cpu' model = SentenceTransformer('all-MiniLM-L6-v2', device=device) search_terms = ["scalable database solutions"] print("\nGenerating search embedding...") search_embeddings = model.encode(search_terms) search_params = { "metric_type": "L2", "params": {"nprobe": 10} } print("Executing search...") results = collection.search( data=[search_embeddings[0].tolist()], anns_field="embedding", param=search_params, limit=3, output_fields=["text"] ) print("\nSearch results:") for i, hits in enumerate(results): print(f"Search term: '{search_terms[i]}'") for hit in hits: print(f" • Score: {hit.distance:.4f} - Text: {hit.entity.get('text')}") ``` **Explanation:** - Re-loads the same **SBERT** model to encode the search term. - Uses **collection.search()** with vector data, targeting the **“embedding”** field, and retrieves the top 3 matches. - Outputs a similarity score and matched text. 5. Create the script’s entry point. It verifies the connection, creates the collection and data, and performs a sample vector search. ```bash if __name__ == "__main__": print("=== Zilliz/Milvus Vector Search Demo ===") print(f"PyMilvus version: {pymilvus.__version__}") # Verify connection first if verify_connection(): collection = create_collection() if collection: perform_search(collection) print("\nDemo completed") ``` **Explanation:** - First print PyMilvus version. - If the connection is successful, it proceeds to create the collection and run the search query. - Wraps the entire logic in a clean main block for clarity and modularity. 6. Run the full Python script. ```bash python3 zilliz_demo.py ``` Output. ```bash === Zilliz/Milvus Vector Search Demo === PyMilvus version: 2.5.10 ✓ Successfully connected to Milvus server Server status: v2.3.3-gpu List of collections: ['document_embeddings'] ✓ Successfully connected to Milvus server Server status: v2.3.3-gpu List of collections: ['document_embeddings'] Using device: cuda Collection document_embeddings already exists Generating embeddings... Embeddings generated in 0.30 seconds Inserting data... Inserted 4 documents Generating search embedding... Executing search... Search results: Search term: 'scalable database solutions' • Score: 1.1304 - Text: Zilliz provides scalable vector search solutions • Score: 1.1836 - Text: Vector databases are essential for AI applications • Score: 1.6474 - Text: GPU acceleration significantly improves vector search performance Demo completed ``` ## Conclusion Setting up Zilliz (Milvus) on Ubuntu 24.04 GPU instances provides a powerful platform for scalable vector search applications. By leveraging [GPU acceleration](https://www.atlantic.net/gpu-server-hosting/ai-accelerator-vs-gpu-5-key-differences-and-how-to-choose/), you can achieve significant performance improvements for similarity search operations. This setup is particularly valuable for AI applications requiring real-time vector search capabilities with large datasets. --- # Set up a Transcoding Server with Handbrake and Atlantic Cloud GPU > URL: https://www.atlantic.net/gpu-server-hosting/set-up-a-transcoding-server-with-handbrake-and-atlantic-cloud-gpu/ | Published: 2025-06-29 | Updated: 2025-07-10 | Author: Hitesh Jethva Transcoding means changing a media file from one format to another. This process can use a lot of CPU and GPU power, especially for large files, which might be too much for a regular computer to handle. A good solution is to use a special server made for transcoding. These servers are fast, powerful, and often use hardware acceleration to speed up the process. HandBrake is a free, open-source tool that converts video files. You can set it up on a server just for transcoding. When you combine HandBrake with FileBrowser, you can use cloud-based GPU power to make the conversion faster and more efficient. In this guide, you’ll learn how to create a transcoding server using HandBrake on an Atlantic.Net [Cloud GPU server](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/). ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A root user or a user with sudo privileges. - NVIDIA drivers installed. ## Step 1: Create a User 1. First, create a dedicated user for your project. ```bash adduser example-user ``` 2. Add your user to the sudo group. ```bash usermod -aG sudo example-user ``` 3. Add the user to the Docker group. ```bash usermod -aG docker example-user ``` ## Step 2: Install HandBrake In this section, we will create a HandBrake container. 1. Log in as an example-user. ```bash su - example-user ``` 2. Verify that the Docker service is up and running. ```bash sudo service docker status ``` 3. Start a new HandBrake container. ```bash docker run -d --name=handbrake -p 8000:5800 -v /docker/appdata/handbrake:/config:rw -v /home/handbrake-user/:/storage:rw -v /home/handbrake-user/HandBrake/watch:/watch:rw -v /home/handbrake-user/HandBrake/output:/output:rw jlesage/handbrake ``` **Explanation:** - The above Docker run command starts a HandBrake container in the background **(-d)** with the name **handbrake.** - It maps port **5800** inside the container to port **8000** on the host, allowing you to access HandBrake’s web interface via http://localhost:8000. - Several volumes are mounted: **/docker/appdata/handbrake** is used to store HandBrake’s configuration files, **/home/handbrake-user/** provides general file access, and specific folders (watch and output) are used for input and output video files. - The container uses the **jlesage/handbrake** image, which includes a web-based interface for transcoding videos. 4. Verify that the HandBrake container is created and running. ```bash docker ps ``` Output. ```bash CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 00dd17e8cada jlesage/handbrake "/init" 11 seconds ago Up 10 seconds 5900/tcp, 0.0.0.0:8000->5800/tcp, [::]:8000->5800/tcp handbrake ``` 5. Also, verify if HandBrake is listening on port 8000. ```bash ss -antpl | grep 8000 ``` Output. ```bash LISTEN 0 4096 0.0.0.0:8000 0.0.0.0:* LISTEN 0 4096 [::]:8000 [::]:* ``` ## Step 2: Install FileBrowser FileBrowser is an open-source, self‑hosted web-based file manager that lets you interact with files and folders on your server through a browser. 1. First, create a new directory for storing FileBrowser files. ```bash sudo mkdir /home/handbrake-user/Files ``` 2. Create a database file for FileBrowser. ```bash sudo touch /home/handbrake-user/Files/filebrowser.db ``` 3. Create a new container for FileBrowser. ```bash docker run -d --name=filebrowser -v /home/handbrake-user/Files:/srv -v /home/handbrake-user/Files/filebrowser.db:/database.db -e PGID=$(id -g) -e PUID=$(id -u) -p 8001:80 filebrowser/filebrowser ``` This command runs a **FileBrowser** container named filebrowser in the background, maps port **80** in the container to port **8001** on the host, mounts a file directory and database, and sets user permissions using your current user and group ID, enabling web-based file management at **http://localhost:8001.** 4. Verify that the FileBrowser container created and running. ```bash docker ps ``` Output. ```bash CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES f621cca33d0a filebrowser/filebrowser "/filebrowser" 10 seconds ago Up 9 seconds (healthy) 0.0.0.0:8001->80/tcp, [::]:8001->80/tcp filebrowser 00dd17e8cada jlesage/handbrake "/init" 2 minutes ago Up 2 minutes 5900/tcp, 0.0.0.0:8000->5800/tcp, [::]:8000->5800/tcp handbrake ``` ## Step 3: Configure Nginx as a Reverse proxy In this section, you’ll configure Nginx as a reverse proxy to securely route incoming traffic to the internal ports, **8000** for **HandBrake** and **8001** for **FileBrowser,** allowing safe and streamlined access to both applications. 1. Install the Nginx server. ```bash sudo apt install nginx -y ``` 2. Delete the default Nginx host configuration file. ```bash sudo rm /etc/nginx/sites-enabled/default ``` 3. Create a new HandBrake configuration file. ```bash sudo nano /etc/nginx/conf.d/handbrake.conf ``` Add the following configuration. ```bash map $http_upgrade $connection_upgrade { default upgrade; '' close; } server { listen 80; server_name handbrake.example.com; location / { proxy_pass http://127.0.0.1:8000; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; } location /websockify { proxy_pass http://127.0.0.1:8000; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection $connection_upgrade; proxy_read_timeout 86400; } } ``` 4. Test the Nginx configuration. ```bash sudo nginx -t ``` Output. ```bash nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful ``` 5. Create a FileBrowser configuration file. ```bash sudo nano /etc/nginx/conf.d/filebrowser.conf ``` Add the following configuration. ```bash server { listen 80; server_name filebrowser.example.com; location / { proxy_pass http://127.0.0.1:8001; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; } } ``` 6. Restart Nginx to apply the changes. ```bash sudo systemctl restart nginx ``` ## Step 4: Upload Files Using FileBrowser In this section, you will access the FileBrowser and upload a video file. 1. Open your web browser and access the FileBrowser at **http://filebrowser.example.com.** ![](https://www.atlantic.net/wp-content/uploads/2025/06/p1-2.png) 2. Provide the default administrator username **admin** and password **admin** to log in to FileBrowser. ![](https://www.atlantic.net/wp-content/uploads/2025/06/p2-2.png) 3. Click **New Folder** on the left navigation menu to create a new folder named **HandBrake-uploads.** 4. Click the **Upload** **↑** button on the top right bar. 5. In the pop-up window, click **File** to browse and upload a video file from your computer. 6. After the upload finishes, check that the file appears in the directory so you can begin the transcoding process with HandBrake. ![](https://www.atlantic.net/wp-content/uploads/2025/06/p3-2.png) ## Step 5: Transcode Files Using Handbrake In this section, you will access the Handbrake web interface and transcode your uploaded video file using Handbrake. 1. Access the Handbrake web UI using the URL **http://handbrake.example.com.** ![](https://www.atlantic.net/wp-content/uploads/2025/06/p4.png) 2. Click **Open Source** to locate your media file. ![](https://www.atlantic.net/wp-content/uploads/2025/06/p5.png) 3. Navigate to the Files directory where you uploaded the media file and click Open to load it. 4. Click the **Presets** button in the top-right toolbar, choose your preferred transcode preset (e.g., Creator **2160p60** 4K) from the dropdown, then close the popup by clicking the **X**. ![](https://www.atlantic.net/wp-content/uploads/2025/06/p6.png) 5. In the Summary section, open the **Format** dropdown and choose your desired output format. 6. In the Video section, set your preferred Video Encoder and Framerate. ![](https://www.atlantic.net/wp-content/uploads/2025/06/p7.png) 7. Adjust settings in the Audio, Subtitles, and Tags sections as needed. 8. In the **Save As** field at the bottom, enter a name for the output file. Under the **TO:** dropdown, click it, scroll down, select Other, then use the file manager to open the storage folder and choose the **Files** directory as the output location. 9. Click **Start** to begin the transcoding process. ## Step 6: Download Transcoded Files 1. Go back to the **FileBrowser** dashboard. 2. Verify that the new transcoded file is available in your **Files** directory. ![](https://www.atlantic.net/wp-content/uploads/2025/06/p8.png) 3. Click the file, then click the **Download ↓** button on the top right bar. 4. Download and save the file on your computer. ## Conclusion You’ve successfully set up a transcoding server using HandBrake on an Atlantic.net Cloud GPU. With GPU acceleration, you can transcode multiple files simultaneously while maintaining high output quality, which can be easily downloaded via FileBrowser. If you need faster conversions or have heavier workloads, you can scale your GPU instance for more processing power. To increase storage capacity, simply attach a block storage volume. --- # Lane Line Detection with OpenCV and Flask on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/lane-line-detection-with-opencv-and-flask-on-ubuntu-24-04-gpu-server/ | Published: 2025-06-30 | Updated: 2025-07-10 | Author: Hitesh Jethva Lane detection is a key element in autonomous driving systems and driver-assistance technologies. In this article, we’ll walk through implementing lane line detection using OpenCV and Python on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). This real-time solution processes a video stream to identify lane lines using computer vision techniques like edge detection, region masking, and Hough transforms. We’ll also create a web interface to display both original and processed videos side-by-side. ## What You’ll Build We’ll use a video of a car driving on a highway, apply computer vision techniques to detect lane lines, and visualize both the original and processed outputs in a web app. The lane detection is powered by OpenCV, and Flask delivers the interface. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A root user or a user with sudo privileges. - NVIDIA drivers installed. ## Step 1: Set Up the Python Environment To ensure a clean setup with all necessary packages, we’ll create a virtual environment and install dependencies. First, install all necessary dependencies: ```bash apt install python3 python3-dev python3-venv -y ``` Next, create and activate a virtual environment. ```bash python3 -m venv venv source venv/bin/activate ``` Next, update pip to the latest version. ```bash pip install --upgrade pip ``` Next, install all required packages for this project. ```bash python3 -m pip install opencv-python numpy matplotlib pillow flask kaggle ``` ## Step 2: Download the Video Dataset We’ll use the Kaggle lane detection dataset for this project. Follow the below steps to download the Kaggle dataset. 1. Go to Kaggle and log in. 2. Click your **profile picture** => **Account** 3. Scroll down to the **API** section 4. Click **“Create New API Token”** 5. This will download **kaggle.json** to your computer 6. Create a Kaggle configuration directory on your server. ```bash mkdir -p ~/.kaggle ``` 7. Copy your downloaded **kaggle.json** file into the **~/.kaggle** folder. 8. Set appropriate permissions. ```bash chmod 600 ~/.kaggle/kaggle.json ``` 9. Download the [dataset](https://www.kaggle.com/datasets/dpamgautam/video-file-for-lane-detection-project) using the command below. ```bash kaggle datasets download -d dpamgautam/video-file-for-lane-detection-project ``` 10. Unzip the downloaded file. ```bash unzip video-file-for-lane-detection-project.zip ``` 11. This command will extract the **test_video.mp4** file from the downloaded zip file. ## Step 3: Process the Video with OpenCV We’ll write a Python script that reads each frame, detects edges, isolates the region of interest, and applies the Hough Line Transform to detect lanes on **test_video.mp4**. 1. Create a file. ```bash nano main.py ``` Add the below code. ```bash import cv2 import numpy as np import os # Global variables first_frame = True cache = np.zeros(8) frame_counter = 0 def interested_region(img, vertices): mask = np.zeros_like(img) mask_color = (255,) * img.shape[2] if len(img.shape) > 2 else 255 cv2.fillPoly(mask, vertices, mask_color) return cv2.bitwise_and(img, mask) def hough_lines(img, rho, theta, threshold, min_line_len, max_line_gap): lines = cv2.HoughLinesP(img, rho, theta, threshold, np.array([]), minLineLength=min_line_len, maxLineGap=max_line_gap) if lines is None: print("⚠️ No Hough lines found.") else: print(f"✅ Detected {len(lines)} line(s).") line_img = np.zeros((img.shape[0], img.shape[1], 3), dtype=np.uint8) lines_drawn(line_img, lines) return line_img def lines_drawn(img, lines, color=[0, 255, 0], thickness=3): if lines is None: return for line in lines: for x1, y1, x2, y2 in line: cv2.line(img, (x1, y1), (x2, y2), color, thickness) def weighted_img(img, initial_img, α=0.8, β=1., λ=0.): return cv2.addWeighted(initial_img, α, img, β, λ) def process_frame(image): global frame_counter # Use full grayscale image (no masking) gray = cv2.cvtColor(image, cv2.COLOR_BGR2GRAY) # Gaussian blur blurred = cv2.GaussianBlur(gray, (5, 5), 0) # Canny edge detection - more sensitive edges = cv2.Canny(blurred, 5, 50) # Region of interest height, width = image.shape[:2] roi_vertices = np.array([[ (width * 0.1, height), (width * 0.45, height * 0.6), (width * 0.55, height * 0.6), (width * 0.9, height) ]], dtype=np.int32) roi = interested_region(edges, roi_vertices) # Save debug images for the first few frames if frame_counter < 3: os.makedirs("debug", exist_ok=True) cv2.imwrite(f"debug/edges_{frame_counter}.jpg", edges) cv2.imwrite(f"debug/roi_{frame_counter}.jpg", roi) # Run relaxed Hough Transform line_img = hough_lines(roi, 2, np.pi / 180, 10, 20, 50) result = weighted_img(line_img, image) frame_counter += 1 return result if __name__ == "__main__": cap = cv2.VideoCapture("test_video.mp4") if not cap.isOpened(): print("❌ Error: Cannot open input video.") exit(1) width = int(cap.get(cv2.CAP_PROP_FRAME_WIDTH)) height = int(cap.get(cv2.CAP_PROP_FRAME_HEIGHT)) fps = cap.get(cv2.CAP_PROP_FPS) fourcc = cv2.VideoWriter_fourcc(*'mp4v') out = cv2.VideoWriter("output.mp4", fourcc, fps, (width, height)) print("🚀 Processing video...") while cap.isOpened(): ret, frame = cap.read() if not ret: break processed = process_frame(frame) out.write(processed) if frame_counter % 10 == 0: print(f"📦 Processed {frame_counter} frames...") cap.release() out.release() print("✅ Done. Output saved as output.mp4.") print("🛠️ Debug edge/ROI images saved to ./debug/") ``` This code reads each frame, applies edge detection and region masking, then uses HoughLinesP to detect line segments. It overlays the detected lines on the original video and writes the output. Now, run the above code. ```bash python3 main.py ``` ## Step 4: Create the Flask Web App Now we’ll set up a web server that streams both the original and processed videos. Create a Flask application file. ```bash nano app.py ``` Add the following code. ```bash from flask import Flask, render_template, Response import cv2 app = Flask(__name__) # Video file paths video_original = cv2.VideoCapture("test_video.mp4") video_processed = cv2.VideoCapture("output.mp4") def generate_frames(video): while True: success, frame = video.read() if not success: video.set(cv2.CAP_PROP_POS_FRAMES, 0) continue _, buffer = cv2.imencode('.jpg', frame) frame_bytes = buffer.tobytes() yield (b'--frame\r\n' b'Content-Type: image/jpeg\r\n\r\n' + frame_bytes + b'\r\n') @app.route('/') def index(): return render_template('index.html') @app.route('/video_original') def stream_original(): return Response(generate_frames(video_original), mimetype='multipart/x-mixed-replace; boundary=frame') @app.route('/video_processed') def stream_processed(): return Response(generate_frames(video_processed), mimetype='multipart/x-mixed-replace; boundary=frame') if __name__ == "__main__": app.run(host='0.0.0.0', port=5000, debug=False) ``` This Flask app defines routes to stream both video files as MJPEG streams. The **generate_frames()** function encodes each video frame into JPEG and streams it continuously. ## Step 5: Build the Web Interface We’ll now create an HTML page to display the input and output video feeds side-by-side. First, create a templates directory and create an HTML page. ```bash mkdir templates nano templates/index.html ``` Add the below code. ```bash Lane Line Detection – Viewer

Lane Line Detection – Input vs Output

Original Video
Original Video Stream
Processed Video
Processed Video Stream
© 2025 Lane Detection Demo – Powered by OpenCV + Flask
``` The HTML page renders both video streams with labels using the routes defined in the Flask app. ## Step 6: Run the Flask App Now, start the Flask server using the command below. ```bash python3 app.py ``` Open your web browser and access the Flask web interface using the URL **http://your-server-ip:5000.** You should see both the original and processed videos playing side by side. ![](https://www.atlantic.net/wp-content/uploads/2025/06/lan.png) ## Conclusion You have successfully implemented a full lane detection system using OpenCV and served it with Flask. By leveraging the parallel processing capabilities of GPUs, you can achieve real-time performance essential for critical applications like autonomous navigation. This solution can be extended to use live camera input, real-time overlays, or integration with machine learning models. --- # Dog vs Cat Convolutional Neural Network Classifier on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/dog-vs-cat-convolutional-neural-network-classifier-on-ubuntu-24-04-gpu-server/ | Published: 2025-07-01 | Updated: 2026-05-04 | Author: Hitesh Jethva Classifying images of dogs and cats is a classic deep learning problem that helps demonstrate the power of Convolutional Neural Networks (CNNs). In this tutorial, we’ll build a CNN-based classifier using TensorFlow and Keras on an Ubuntu 24.04 server with GPU acceleration. We’ll also create a simple Flask-based web interface to upload images and get predictions. ## Prerequisites Before starting, ensure you have: - An Ubuntu 24.04 server with an [NVIDIA GPU](https://www.atlantic.net/gpu-server-hosting/top-10-nvidia-gpus-for-ai/). - A root user or a user with sudo privileges. - NVIDIA drivers are installed for GPU acceleration. ## Step 1: Install Required Packages First, update your system and install the necessary Python packages: ```bash apt update -y apt install python3 python3-pip python3-venv ``` ## Step 2: Set Up Python Environment Now, you will create a Python environment for your project. 1. Create a virtual environment. ```bash python3 -m venv ~/dogcat-cnn ``` 2. Activate the virtual environment. ```bash source ~/dogcat-cnn/bin/activate ``` 3. Install the required Python packages. ```bash pip install tensorflow keras flask pillow scipy kaggle ``` These packages include: - **tensorflow** for machine learning with GPU support - **pillow** for image processing - **flask** for the web interface - **kaggle** to download datasets ## Step 3: Set Up Kaggle API We’ll use the Kaggle API to download the dataset. 1. Go to Kaggle and log in. 2. Click your profile **picture**  => **Account** 3. Scroll down to the **API** section 4. Click **“Create New API Token”** 5. This will download **kaggle.json** to your computer 6. Create a Kaggle configuration directory on your server. ```bash mkdir -p ~/.kaggle ``` 7. Copy your downloaded **kaggle.json** file into the **~/.kaggle** folder. 8. Set appropriate permissions. ```bash chmod 600 ~/.kaggle/kaggle.json ``` This step allows us to download the dataset directly from Kaggle without manual uploads programmatically. ## Step 4: Download and Prepare the Dataset Now, we will use Kaggle to download the [Dogs vs Cats dataset](https://www.kaggle.com/c/dogs-vs-cats) from Kaggle and extract it. 1. Download the dataset. ```bash kaggle datasets download -d salader/dogs-vs-cats ``` 2. Unzip the dataset. ```bash unzip dogs-vs-cats.zip ``` 3. Verify the extracted directory. ```bash ls dogs_vs_cats/train/ ``` Output. ```bash cats dogs ``` 4. Create the required directories for your project. ```bash mkdir templates mkdir -p static/uploads ``` The dataset contains labeled images of dogs and cats, which we’ll use to train our CNN model. ## Step 5: Build and Train the CNN Model We’ll define a CNN using TensorFlow/Keras and train it on the dataset. ```bash nano dog_cat_classifier.py ``` Add the below code: ```bash import os from tensorflow.keras.models import Sequential from tensorflow.keras.layers import Conv2D, MaxPooling2D, Flatten, Dense, Dropout from tensorflow.keras.preprocessing.image import ImageDataGenerator from tensorflow.keras.models import load_model # Define paths base_dir = 'dogs_vs_cats' train_dir = os.path.join(base_dir, 'train') test_dir = os.path.join(base_dir, 'test') # Image parameters img_width, img_height = 150, 150 batch_size = 32 # Data augmentation for training train_datagen = ImageDataGenerator( rescale=1./255, rotation_range=40, width_shift_range=0.2, height_shift_range=0.2, shear_range=0.2, zoom_range=0.2, horizontal_flip=True, fill_mode='nearest') # Only rescaling for testing test_datagen = ImageDataGenerator(rescale=1./255) # Generators train_generator = train_datagen.flow_from_directory( train_dir, target_size=(img_width, img_height), batch_size=batch_size, class_mode='binary') test_generator = test_datagen.flow_from_directory( test_dir, target_size=(img_width, img_height), batch_size=batch_size, class_mode='binary') # Build the model model = Sequential([ Conv2D(32, (3,3), activation='relu', input_shape=(img_width, img_height, 3)), MaxPooling2D(2,2), Conv2D(64, (3,3), activation='relu'), MaxPooling2D(2,2), Conv2D(128, (3,3), activation='relu'), MaxPooling2D(2,2), Flatten(), Dropout(0.5), Dense(512, activation='relu'), Dense(1, activation='sigmoid') ]) # Compile the model model.compile(loss='binary_crossentropy', optimizer='adam', metrics=['accuracy']) # Train the model epochs = 10 model.fit( train_generator, steps_per_epoch=train_generator.samples // batch_size, epochs=epochs, validation_data=test_generator, validation_steps=test_generator.samples // batch_size) # Evaluate the model loss, accuracy = model.evaluate(test_generator) print(f'Test Accuracy: {accuracy * 100:.2f}%') # Save the model model.save('dog_cat_classifier_model.h5') ``` This CNN model uses convolutional layers to extract features and dense layers for classification. Data augmentation helps improve generalization. ## Step 6: Create a Flask Web App for Predictions We’ll build a simple web interface to upload images and get predictions. Create a web application file. ```bash nano web_app.py ``` Add the below code. ```bash from flask import Flask, request, render_template, redirect, url_for from tensorflow.keras.models import load_model from tensorflow.keras.preprocessing.image import load_img, img_to_array import numpy as np import os from PIL import Image app = Flask(__name__) model = load_model('dog_cat_classifier_model.h5') UPLOAD_FOLDER = 'static/uploads' app.config['UPLOAD_FOLDER'] = UPLOAD_FOLDER def model_predict(img_path): img = load_img(img_path, target_size=(150, 150)) img_array = img_to_array(img) / 255.0 img_array = np.expand_dims(img_array, axis=0) prediction = model.predict(img_array)[0][0] return 'Dog' if prediction > 0.5 else 'Cat' @app.route('/', methods=['GET', 'POST']) def index(): if request.method == 'POST': file = request.files['file'] if file: filepath = os.path.join(app.config['UPLOAD_FOLDER'], file.filename) file.save(filepath) prediction = model_predict(filepath) return render_template('index.html', prediction=prediction, image_url=filepath) return render_template('index.html') if __name__ == '__main__': app.run(host='0.0.0.0', port=5000) ``` Create an **index.html** file. ```bash nano templates/index.html ``` Add the following code. ```bash Dog vs Cat Classifier

Upload an image of a Dog or Cat

{% if prediction %}

Prediction: {{ prediction }}

Uploaded Image {% endif %} ``` The Flask app loads the trained model and provides an interface for uploading images and receiving real-time predictions. ## Step 7: Run the Web App 1. You can now start the Flask Web Application using the following command: ```bash python3 web_app.py ``` 2. Visit **http://your-server-ip:5000** in your browser to access the interface. 3. Click **Browse** and upload a cat image, then click on the **Predict** button. The web interface classifies the uploaded image with a pre-trained model and displays the result. ![](https://www.atlantic.net/wp-content/uploads/2025/06/cat.png) ## Conclusion We successfully built a Dog vs Cat CNN classifier on Ubuntu 24.04 with GPU support, trained it on a Kaggle dataset, and deployed it using Flask. This project demonstrates: - CNN architecture for image classification. - Data augmentation to improve model robustness. - Flask integration for real-time predictions. --- # How to Build a Real-Time Speech to Text App with Whisper and Flask > URL: https://www.atlantic.net/gpu-server-hosting/how-to-build-a-real-time-speech-to-text-app-with-whisper-and-flask/ | Published: 2025-07-02 | Updated: 2025-07-10 | Author: Hitesh Jethva Real-time speech-to-text transcription is a powerful application of AI. With the rise of open-source models like OpenAI’s Whisper and lightweight web frameworks like Flask, building such tools has become much easier. In this tutorial, we’ll walk you through building a speech-to-text web app that: - Captures audio from your browser, - Sends it to a Flask server using WebSockets, - Transcribes the audio in real time using Whisper, - Displays the transcribed text in the browser. We’ll also show how to expose the app with HTTPS using Nginx and Certbot for a secure experience. ## Prerequisites Before you begin, ensure the following are in place: - An Atlantic.Net [cloud GPU server](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/) running Ubuntu 24.04 with root access. - A domain name (e.g., app.code2devops.com) pointing to your server IP. - NVIDIA drivers are installed on your server. ## Step 1: Install System Dependencies First, install all the essential system packages required for audio processing and Python development. ```bash apt install espeak ffmpeg libespeak1 python3 python3-dev python3-venv -y ``` These packages are required for text-to-speech (optional), audio conversion, and Python environment setup. ## Step 2: Create a Python Virtual Environment Create a virtual environment for your project dependencies are isolated and won’t interfere with other Python projects. Let’s create a virtual environment for your project. ```bash python3 -m venv venv ``` Activate the virtual environment. ```bash source venv/bin/activate ``` Upgrade pip to the latest version. ```bash pip install --upgrade pip ``` ## Step 3: Install Python Packages Next, install Flask, Whisper, Socket.IO, and supporting libraries for real-time audio streaming and transcription. ```bash pip install flask flask-socketio eventlet whisper torch pyttsx3 ``` **Explanation:** - **Whisper** and **Torch** are for speech recognition. - **Flask** and **flask-socketio** serve and manage the web app. - **Eventlet** enables real-time WebSocket communication. - **pyttsx3** is optional, used for speech synthesis if needed. ## Step 4: Create the Flask App Now, build the backend logic using Flask and WebSockets. Create an app.py file. ```bash nano app.py ``` Add the following code. ```bash from flask import Flask, render_template from flask_socketio import SocketIO from core import transcribe_audio app = Flask(__name__) socketio = SocketIO(app, cors_allowed_origins="*") @app.route("/") def home(): return render_template("index.html") @socketio.on("audio") def handle_audio(data): with open("temp.webm", "wb") as f: f.write(data) text = transcribe_audio("temp.webm") print("🗣️ Transcribed:", text) socketio.emit("transcript", {"text": text}) if __name__ == "__main__": socketio.run(app, host="0.0.0.0", port=5000, debug=True) ``` This file sets up the Flask web server, handles audio input, and emits transcribed output. ## Step 5: Add Whisper Transcription Logic Create a separate file to manage Whisper transcription logic. ```bash nano core.py ``` Add the following code. ```bash import whisper model = whisper.load_model("base") def transcribe_audio(audio_file): result = model.transcribe(audio_file) return result['text'].strip() ``` This script loads the Whisper model and uses it to transcribe audio. ## Step 6: Create the Web Interface Now let’s build the frontend interface for browser-based audio capture and display. ```bash mkdir templates nano templates/index.html ``` Add the following HTML code. ```bash Speech to Text

🎤 Speech to Text Demo

Transcription:

``` This simple UI allows users to start and stop audio recording and view the transcription in real time. ## Step 7: Run the Flask App Start your Flask application in the background. ```bash python3 app.py & ``` The app will now be accessible on port 5000. ## Step 8: Configure Nginx as a Reverse Proxy Web browsers do not allow microphone access on insecure (HTTP) websites. This is a built-in security measure to protect user privacy. Since our app relies on real-time voice input, serving it over HTTPS is not optional, it’s required for the microphone to work. Additionally, HTTPS ensures all audio data is transmitted securely and cannot be intercepted. To achieve this, we’ll use Nginx to forward requests to our Flask app and later secure the app with Let’s Encrypt SSL certificates using Certbot. First, install Nginx and other packages. ```bash apt install nginx certbot python3-certbot-nginx -y ``` Next, create an Nginx configuration file. ```bash nano /etc/nginx/conf.d/app.conf ``` Add the following configuration. ```bash server { listen 80; server_name app.code2devops.com; location / { proxy_pass http://127.0.0.1:5000; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; } } ``` **Note:** Replace the domain **app.code2devops.com** with your own domain name. Verify the Nginx configuration. ```bash nginx -t ``` Restart Nginx to apply the changes. ```bash systemctl restart nginx ``` Now, use certbot to issue a free SSL certificate and enable HTTPS for your domain. ```bash certbot --nginx -d app.code2devops.com ``` ## Step 9: Access and Test Your Application Visit **https://app.code2devops.com** in your browser. ![](https://www.atlantic.net/wp-content/uploads/2025/06/p1-3.png) Click **Start Recording.** Allow microphone access when prompted. Click **Stop Recording** to stop and see your transcribed text. ![](https://www.atlantic.net/wp-content/uploads/2025/06/p2-3.png)   ## Conclusion You’ve successfully built a real-time speech-to-text web application using Whisper and Flask. The app captures audio through a browser, transcribes it on the server using Whisper, and displays the text in real time. With the help of Nginx and Certbot, you also secured your app using HTTPS and made it publicly accessible via a custom domain. --- # How to Deploy Milvus with GPU Support for High-Speed Indexing on Ubuntu 24.04 > URL: https://www.atlantic.net/gpu-server-hosting/how-to-deploy-milvus-with-gpu-support-for-high-speed-indexing-on-ubuntu-24-04/ | Published: 2025-07-04 | Updated: 2026-05-04 | Author: Hitesh Jethva Milvus is an open-source vector database designed for high-performance similarity search and AI applications. When deployed with GPU acceleration, Milvus can significantly speed up indexing and search tasks, perfect for machine learning workloads. In this guide, you’ll learn how to deploy Milvus with GPU support on Ubuntu 24.04 using Docker, configure it for GPU-accelerated FAISS indexing, and test it with a Python script. ## Prerequisites - An Ubuntu 24.04 server with an [NVIDIA GPU](https://www.atlantic.net/gpu-server-hosting/top-10-nvidia-gpus-for-ai/). - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Install Required Dependencies In this step, we install essential packages like Python, Docker Compose, and set up a Python virtual environment. ```bash apt install python3 python3-dev python3-venv docker-compose -y ``` Create and activate the virtual environment: ```bash python3 -m venv venv source venv/bin/activate ``` Upgrade pip to the latest version. ```bash pip install --upgrade pip ``` Restart Docker to ensure all changes are applied: ```bash systemctl restart docker ``` This sets up a clean Python environment and prepares your system for Dockerized deployment. ## Step 2: Verify Docker GPU Runtime Check if your Docker installation is configured to support GPU access. ```bash docker info | grep -i runtimes ``` Output. ```bash Runtimes: nvidia runc io.containerd.runc.v2 ``` If NVIDIA is missing, install the NVIDIA Container Toolkit to enable GPU support in Docker containers. ## Step 3: Clone the Milvus Repository Milvus provides a Docker-based deployment setup. We’ll use their official repository. Clone the Milvus repository. ```bash git clone https://github.com/milvus-io/milvus.git ``` Navigate to the standalone directory. ```bash cd milvus/deployments/docker/standalone ``` This directory contains Docker Compose files for deploying Milvus in standalone mode. ## Step 4: Configure Docker Compose for GPU Acceleration In this section, we will create a docker-compose.yml with a GPU-optimized configuration. ```bash nano docker-compose.yml ``` Remove the default configuration and add the following configuration: ```bash version: '3.5' services: etcd: container_name: milvus-etcd image: quay.io/coreos/etcd:v3.5.18 environment: - ETCD_AUTO_COMPACTION_MODE=revision - ETCD_AUTO_COMPACTION_RETENTION=1000 - ETCD_QUOTA_BACKEND_BYTES=4294967296 - ETCD_SNAPSHOT_COUNT=50000 volumes: - ${DOCKER_VOLUME_DIRECTORY:-.}/volumes/etcd:/etcd command: etcd -advertise-client-urls=http://etcd:2379 -listen-client-urls http://0.0.0.0:2379 --data-dir /etcd healthcheck: test: ["CMD", "etcdctl", "endpoint", "health"] interval: 30s timeout: 20s retries: 3 minio: container_name: milvus-minio image: minio/minio:RELEASE.2023-03-20T20-16-18Z environment: MINIO_ACCESS_KEY: minioadmin MINIO_SECRET_KEY: minioadmin ports: - "9001:9001" - "9000:9000" volumes: - ${DOCKER_VOLUME_DIRECTORY:-.}/volumes/minio:/minio_data command: minio server /minio_data --console-address ":9001" healthcheck: test: ["CMD", "curl", "-f", "http://localhost:9000/minio/health/live"] interval: 30s timeout: 20s retries: 3 standalone: container_name: milvus-standalone image: milvusdb/milvus:v2.3.9-gpu command: ["milvus", "run", "standalone"] security_opt: - seccomp:unconfined environment: MINIO_REGION: us-east-1 ETCD_ENDPOINTS: etcd:2379 MINIO_ADDRESS: minio:9000 CUDA_VISIBLE_DEVICES: "0" volumes: - ${DOCKER_VOLUME_DIRECTORY:-.}/volumes/milvus:/var/lib/milvus healthcheck: test: ["CMD", "curl", "-f", "http://localhost:9091/healthz"] interval: 30s start_period: 90s timeout: 20s retries: 3 ports: - "19530:19530" - "9091:9091" depends_on: - "etcd" - "minio" deploy: resources: reservations: devices: - driver: nvidia count: all capabilities: [gpu] networks: default: name: milvus ``` This setup ensures Milvus and its dependencies, like etcd and MinIO, run correctly with GPU support. ## Step 5: Launch Milvus with Docker Compose Start the Milvus standalone stack using Docker Compose. ```bash docker compose up -d ``` Check the container status. ```bash docker ps ``` Output. ```bash CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 0e15ab0d6d9a milvusdb/milvus:v2.3.9-gpu "/tini -- milvus run…" 4 minutes ago Up 4 minutes (healthy) 0.0.0.0:9091->9091/tcp, [::]:9091->9091/tcp, 0.0.0.0:19530->19530/tcp, [::]:19530->19530/tcp milvus-standalone d3c681c4ef63 minio/minio:RELEASE.2023-03-20T20-16-18Z "/usr/bin/docker-ent…" 4 minutes ago Up 4 minutes (healthy) 0.0.0.0:9000-9001->9000-9001/tcp, [::]:9000-9001->9000-9001/tcp milvus-minio d59b8cd4bb7b quay.io/coreos/etcd:v3.5.18 "etcd -advertise-cli…" 4 minutes ago Up 4 minutes (healthy) 2379-2380/tcp ``` You should see three containers: milvus-standalone, milvus-minio, and milvus-etcd, all marked healthy. ## Step 6: Verify GPU Access Inside the Container Now we’ll enter the Milvus container to confirm it can see the host GPU. ```bash docker exec -it milvus-standalone bash ``` After you connect to the container, you will get the following shell. ```bash root@0e15ab0d6d9a:/milvus# ``` Run the below command to see the host GPU. ```bash nvidia-smi ``` Output. ```bash Wed Jun 25 14:32:10 2025 +-----------------------------------------------------------------------------------------+ | NVIDIA-SMI 550.90.07 Driver Version: 550.90.07 CUDA Version: 12.4 | |-----------------------------------------+------------------------+----------------------+ | GPU Name Persistence-M | Bus-Id Disp.A | Volatile Uncorr. ECC | | Fan Temp Perf Pwr:Usage/Cap | Memory-Usage | GPU-Util Compute M. | | | | MIG M. | |=========================================+========================+======================| | 0 NVIDIA A40-12Q On | 00000000:06:00.0 Off | 0 | | N/A N/A P8 N/A / N/A | 1MiB / 12288MiB | 0% Default | | | | N/A | +-----------------------------------------+------------------------+----------------------+ +-----------------------------------------------------------------------------------------+ | Processes: | | GPU GI CI PID Type Process name GPU Memory | | ID ID Usage | |=========================================================================================| | No running processes found | +-----------------------------------------------------------------------------------------+ ``` Exit the container once verified. ```bash exit ``` ## Step 7: Create a Python Script to Test GPU FAISS Indexing Let’s run a quick demo to validate that GPU-based indexing works using the Milvus Python SDK. Create a new Python script. ```bash nano milvus_faiss_gpu_demo.py ``` Add the below configuration. ```bash from pymilvus import connections, utility, Collection, FieldSchema, CollectionSchema, DataType import random import numpy as np # Step 1: Connect to Milvus connections.connect(alias="default", host="localhost", port="19530") print("✅ Connected to Milvus") # Step 2: Create a collection with FLOAT_VECTOR field collection_name = "demo_gpu_vectors" # Delete old collection if exists if utility.has_collection(collection_name): Collection(collection_name).drop() print(f"⚠️ Dropped existing collection: {collection_name}") # Define schema fields = [ FieldSchema(name="id", dtype=DataType.INT64, is_primary=True, auto_id=False), FieldSchema(name="embedding", dtype=DataType.FLOAT_VECTOR, dim=128) ] schema = CollectionSchema(fields, description="GPU FAISS test collection") collection = Collection(name=collection_name, schema=schema) print(f"✅ Created collection: {collection_name}") # Step 3: Insert 1,000 random vectors num_vectors = 1000 vectors = np.random.random((num_vectors, 128)).astype("float32") ids = [i for i in range(num_vectors)] data = [ids, vectors] collection.insert(data) print(f"✅ Inserted {num_vectors} vectors") # Step 4: Create GPU FAISS index index_params = { "index_type": "IVF_FLAT", # GPU-accelerated "metric_type": "L2", "params": {"nlist": 128} } collection.create_index(field_name="embedding", index_params=index_params) print("✅ Index created with IVF_FLAT (GPU enabled)") # Step 5: Load collection into memory collection.load() print("✅ Collection loaded into memory") # Step 6: Perform a similarity search search_vectors = [vectors[42]] # Use a vector from dataset search_params = {"metric_type": "L2", "params": {"nprobe": 10}} results = collection.search( search_vectors, "embedding", search_params, limit=5, output_fields=["id"] ) print("\n🔍 Top 5 Similar Vectors:") for hit in results[0]: print(f"ID: {hit.id}, Distance: {hit.distance:.4f}") ``` This script connects to Milvus, inserts 1000 random vectors, creates a GPU-accelerated FAISS index, and performs a similarity search. ## Step 8: Install the Milvus Python SDK and Run the Script Now, install the Python SDK client. ```bash pip install pymilvus ``` Run the script. ```bash python3 milvus_faiss_gpu_demo.py ``` After the successful connection, you will get the following output. ```bash ✅ Connected to Milvus ✅ Created collection: demo_gpu_vectors ✅ Inserted 1000 vectors ✅ Index created with IVF_FLAT (GPU enabled) ✅ Collection loaded into memory 🔍 Top 5 Similar Vectors: ID: 42, Distance: 0.0000 ID: 165, Distance: 15.2311 ID: 437, Distance: 15.4424 ID: 921, Distance: 15.5928 ID: 549, Distance: 15.6674 ``` This confirms that GPU-based indexing and similarity search are working as expected. ## Conclusion You have successfully deployed Milvus with GPU support on Ubuntu 24.04. By using the FAISS IVF_FLAT index on GPU, you can perform high-speed similarity searches across thousands (or millions) of vectors with impressive performance. This setup is ideal for real-time recommendation engines, semantic search, and AI applications. --- # How to Use GPU Servers to Generate Embeddings for Weaviate Vector Search on Ubuntu 24.04 > URL: https://www.atlantic.net/gpu-server-hosting/how-to-use-gpu-servers-to-generate-embeddings-for-weaviate-vector-search-on-ubuntu-24-04/ | Published: 2025-07-05 | Updated: 2026-05-04 | Author: Hitesh Jethva Weaviate is a powerful open-source vector database designed to perform semantic search using vector embeddings. When you integrate it with [GPU-powered servers](https://www.atlantic.net/gpu-server-hosting/), embedding generation becomes significantly faster, especially for large-scale or real-time applications. In this guide, you’ll learn how to: - Set up Weaviate using Docker - Leverage a GPU for fast embedding generation - Store custom embeddings in Weaviate - Query and manage vectorized data using Python scripts ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Install Required Dependencies First, install Python and the necessary tools. ```bash apt install python3 python3-pip python3-venv -y ``` Restart Docker to ensure GPU support. ```bash systemctl restart docker ``` Verify that the NVIDIA container runtime is available. ```bash docker info | grep -i runtime ``` Output. ```bash Runtimes: io.containerd.runc.v2 nvidia runc Default Runtime: runc ``` ## Step 2: Set Up Weaviate with Docker Configure and launch Weaviate using Docker Compose, ensuring proper port exposure for both REST and gRPC connections that will be used for vector operations. Create a **docker-compose.yml** file. ```bash nano docker-compose.yml ``` Add the below configuration. ```bash services: weaviate: image: semitechnologies/weaviate:latest ports: - "8080:8080" - "50051:50051" # <-- required for gRPC environment: ENABLE_MODULES: '' DEFAULT_VECTORIZER_MODULE: 'none' QUERY_DEFAULTS_LIMIT: 25 AUTHENTICATION_ANONYMOUS_ACCESS_ENABLED: 'true' ``` Start Weaviate container using the below command. ```bash docker-compose up -d ``` Verify the running container. ```bash docker ps ``` Output. ```bash CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 2166c9434c83 semitechnologies/weaviate:latest "/bin/weaviate --hos…" 18 minutes ago Up 18 minutes 0.0.0.0:8080->8080/tcp, [::]:8080->8080/tcp, 0.0.0.0:50051->50051/tcp, [::]:50051->50051/tcp root-weaviate-1 ``` ## Step 3: Set Up a Python Virtual Environment In this section, we will create an isolated Python environment to manage dependencies cleanly and verify that PyTorch can properly access your GPU hardware. Create a Python virtual environment. ```bash python3 -m venv venv ``` Activate the environment. ```bash source venv/bin/activate ``` Update pip to the latest version. ```bash pip install --upgrade pip ``` Install required Python packages. ```bash pip install sentence-transformers weaviate-client torch torchvision ``` Verify GPU availability. ```bash python3 -c "import torch; print(torch.cuda.is_available())" ``` Output. ```bash True ``` ## Step 4: Generate Embeddings Using GPU In this section, we will create a Python script that leverages GPU acceleration to convert text into high-dimensional vectors using the sentence-transformers library. Create **generate_embeddings.py.** ```bash nano generate_embeddings.py ``` Add the following code. ```bash from sentence_transformers import SentenceTransformer import torch device = "cuda" if torch.cuda.is_available() else "cpu" model = SentenceTransformer('all-MiniLM-L6-v2', device=device) def get_embedding(text): embedding = model.encode(text, convert_to_tensor=True) return embedding.cpu().numpy().tolist() ``` Run the script. ```bash python3 generate_embeddings.py ``` ## Step 5: Insert Data into Weaviate In this section, we will create and populate a Weaviate collection with your text documents and their corresponding GPU-generated vector embeddings. Create **insert_to_weaviate.py.** ```bash nano insert_to_weaviate.py ``` Add the following code. ```bash from weaviate.connect import ConnectionParams from weaviate import WeaviateClient from weaviate.collections.classes.config import DataType from generate_embeddings import get_embedding # Connect to Weaviate connection_params = ConnectionParams.from_url("http://localhost:8080", 50051) client = WeaviateClient(connection_params) client.connect() # Define class name class_name = "Document" # Create collection if not exists if not client.collections.exists(class_name): client.collections.create( name=class_name, vectorizer_config=None, # Use custom embeddings properties=[ {"name": "content", "data_type": DataType.TEXT} # ✅ Correct enum ] ) # Sample texts to insert texts = [ "Weaviate is a vector database.", "GPU servers are great for deep learning.", "Embeddings help convert text into searchable vectors." ] collection = client.collections.get(class_name) for text in texts: vector = get_embedding(text) collection.data.insert( properties={"content": text}, vector=vector ) # Close the connection properly client.close() ``` Run the script. ```bash python3 insert_to_weaviate.py ``` ## Step 6: Query Data in Weaviate In this section, we will execute vector similarity searches against your Weaviate database to retrieve relevant documents based on semantic meaning rather than exact keyword matches. Create **search_weaviate.py.** ```bash nano search_weaviate.py ``` Add the following code. ```bash from weaviate.connect import ConnectionParams from weaviate import WeaviateClient from generate_embeddings import get_embedding # Connect to Weaviate connection_params = ConnectionParams.from_url("http://localhost:8080", 50051) client = WeaviateClient(connection_params) client.connect() collection = client.collections.get("Document") # Query query = "What is Weaviate?" query_vector = get_embedding(query) # Perform search results = collection.query.near_vector( near_vector=query_vector, limit=3, return_properties=["content"] ) # Print results print("\nSearch Results:") for result in results.objects: print(f"- {result.properties['content']}") client.close() ``` Run the script. ```bash python3 search_weaviate.py ``` You will see the following output. ```bash Search Results: - Weaviate is a vector database. - Embeddings help convert text into searchable vectors. - GPU servers are great for deep learning. ``` ## Step 7: Manage Documents In this section, we will learn additional operations for maintaining your vector database, including listing, updating, and removing documents as needed. First, create a script to list all documents. ```bash nano list_documents.py ``` Add the following code. ```bash from weaviate.connect import ConnectionParams from weaviate import WeaviateClient connection_params = ConnectionParams.from_url("http://localhost:8080", 50051) client = WeaviateClient(connection_params) client.connect() collection = client.collections.get("Document") # Replace with actual UUID doc_id = "REPLACE-WITH-UUID" # Delete the document success = collection.data.delete(uuid=doc_id) print("Deleted successfully?" , success) client.close() ``` Run the script. ```bash python3 list_documents.py ``` You will see all documents in the output below. ```bash Documents in 'Document' collection: - ID: 2189ca0b-ebdb-437a-90f1-d2881bfbbbd7 | Content: Weaviate is a vector database. - ID: 296db11b-b2bc-4554-a236-2fee50579c2d | Content: GPU servers are great for deep learning. - ID: dde5a358-058b-46f3-9033-47967df64a01 | Content: Embeddings help convert text into searchable vectors. ``` Create an **update_document.py** script to update the existing document. ```bash nano update_document.py ``` Add the below code. ```bash from weaviate.connect import ConnectionParams from weaviate import WeaviateClient from weaviate.collections.classes.config import DataType from generate_embeddings import get_embedding # Connect to Weaviate connection_params = ConnectionParams.from_url("http://localhost:8080", 50051) client = WeaviateClient(connection_params) client.connect() try: collection = client.collections.get("Document") # UUID of the document to update (replace with actual ID) doc_id = "296db11b-b2bc-4554-a236-2fee50579c2d" # New content new_text = "Updated description about vector databases." # Generate new embedding new_vector = get_embedding(new_text) # Delete existing object by ID collection.data.delete_by_id(doc_id) # Re-insert object with same ID and new content + vector collection.data.insert( uuid=doc_id, properties={"content": new_text}, vector=new_vector ) print("✅ Document updated successfully.") finally: client.close() ``` Replaced the id **“296db11b-b2bc-4554-a236-2fee50579c2d”** with the actual document. Run the script. ```bash python3 update_document.py ``` Output. ```bash ✅ Document updated successfully. ``` Create a **delete_document.py** to delete the existing document. ```bash nano delete_document.py ``` Add the below code. ```bash from weaviate.connect import ConnectionParams from weaviate import WeaviateClient # Connect to Weaviate connection_params = ConnectionParams.from_url("http://localhost:8080", 50051) client = WeaviateClient(connection_params) client.connect() try: # Get the 'Document' collection collection = client.collections.get("Document") # Replace this with the actual UUID you want to delete doc_id = "2189ca0b-ebdb-437a-90f1-d2881bfbbbd7" # Delete the object by UUID deleted = collection.data.delete_by_id(doc_id) if deleted: print(f"✅ Document with ID {doc_id} deleted successfully.") else: print(f"❌ Document with ID {doc_id} not found or could not be deleted.") finally: client.close() ``` Run the script. ```bash python3 delete_document.py ``` Output. ```bash ✅ Document with ID 2189ca0b-ebdb-437a-90f1-d2881bfbbbd7 deleted successfully. ``` ## Conclusion Congratulations! You’ve successfully created a powerful vector search system that combines Weaviate’s efficient similarity search capabilities with GPU-accelerated embedding generation. This setup demonstrates how modern hardware can dramatically improve the performance of semantic search applications. --- # How to Serve Ollama Models on GPU Server via REST API > URL: https://www.atlantic.net/gpu-server-hosting/how-to-serve-ollama-models-on-gpu-server-via-rest-api/ | Published: 2025-07-06 | Updated: 2025-07-10 | Author: Hitesh Jethva As demand for local, private, and GPU-accelerated AI solutions grows, developers and enterprises are looking for alternatives to cloud-based LLM APIs. Ollama is an open-source tool that allows you to run large language models like Mistral, LLaMA, and Code LLaMA entirely on your own hardware, including GPU-accelerated servers. This provides complete data privacy, faster inference, and zero ongoing API costs. In this tutorial, you’ll learn how to set up Ollama on a [GPU server](https://www.atlantic.net/gpu-server-hosting/) running Ubuntu 24.04, serve models through a REST API, and build a simple web interface using FastAPI to query models from your browser. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Set Up Ollama on the GPU Server We’ll begin by installing Ollama and verifying that it runs correctly with GPU acceleration. 1. First, install Python and other required dependencies. ```bash apt install python3 python3-venv python3-pip ``` 2. Create and activate a Python virtual environment. ```bash python3 -m venv venv source venv/bin/activate ``` 3. Install Ollama. ```bash curl -fsSL https://ollama.com/install.sh | sh ``` Output. ```bash >>> Installing ollama to /usr/local >>> Downloading Linux amd64 bundle ############################################################################################################### 100.0% >>> Creating ollama user... >>> Adding ollama user to render group... >>> Adding ollama user to video group... >>> Adding current user to ollama group... >>> Creating ollama systemd service... >>> Enabling and starting ollama service... Created symlink /etc/systemd/system/default.target.wants/ollama.service → /etc/systemd/system/ollama.service. >>> NVIDIA GPU installed. ``` 4. Start and enable the Ollama service. ```bash systemctl enable ollama systemctl start ollama ``` 5. Verify that Ollama is running. ```bash curl http://localhost:11434 ``` Output. ```bash Ollama is running ``` 6. Download and runs the Mistral model locally. This model is optimized for instruction-following and text generation, and is runnable locally via the Ollama framework. ```bash ollama run mistral ``` ## Step 2: Test REST API via cURL Verify that the REST API works correctly by querying a prompt. ```bash curl -s http://localhost:11434/api/generate -d '{ "model": "mistral", "prompt": "What is the most populous city in Germany?" }' | jq -r '.response' | tr -d '\n' ``` You will see the generated response from the model. ```bash The most populous city in Germany is Berlin. As of 2021, its estimated population is approximately 3.7 million people within its city limits, and over 6.5 million people in the Berlin-Brandenburg metropolitan area. However, if we consider the total urban agglomeration, which includes cities like Potsdam and Brandenburg an der Havel, the population exceeds 7 million inhabitants. ``` ## Step 3: Create a Python Script to Call the API Let’s write a Python script to send a request to the Ollama API and stream the output. ```bash nano test_ollama_api.py ``` Add the following code. ```bash import requests import json url = "http://localhost:11434/api/generate" payload = { "model": "mistral", "prompt": "What is the most populous city in USA?" } response = requests.post(url, json=payload, stream=True) # Collect streamed chunks and combine text output = "" for line in response.iter_lines(): if line: chunk = json.loads(line.decode("utf-8")) output += chunk.get("response", "") print("Full response:\n", output) ``` Run the script. ```bash python3 test_ollama_api.py ``` This streams the response in real-time. ```bash Full response: The most populous city in the United States is New York City, specifically its five boroughs: The Bronx, Brooklyn, Manhattan, Queens, and Staten Island. According to the U.S. Census Bureau's July 1, 2021 estimates, New York City has a population of approximately 8.4 million people. ``` ## Step 4: Build a Web Interface with FastAPI Now, let’s create a user-friendly chat interface using FastAPI and Jinja2. Install the necessary Python modules. ```bash pip install fastapi uvicorn requests jinja2 python-multipart ``` Create a FastAPI endpoint. ```bash nano main.py ``` Add the following code. ```bash from fastapi import FastAPI, Request, Form from fastapi.responses import HTMLResponse from fastapi.templating import Jinja2Templates import requests import json app = FastAPI() templates = Jinja2Templates(directory="templates") OLLAMA_URL = "http://localhost:11434/api/generate" @app.get("/", response_class=HTMLResponse) def load_chat(request: Request): return templates.TemplateResponse("index.html", {"request": request, "response": ""}) @app.post("/", response_class=HTMLResponse) async def get_response(request: Request, prompt: str = Form(...)): payload = { "model": "mistral", "prompt": prompt } # Collect response stream response = requests.post(OLLAMA_URL, json=payload, stream=True) output = "" for line in response.iter_lines(): if line: chunk = json.loads(line.decode("utf-8")) output += chunk.get("response", "") return templates.TemplateResponse("index.html", { "request": request, "response": output, "prompt": prompt }) ``` Create a simple HTML form to interact with the model. ```bash mkdir templates nano templates/index.html ``` Add the following code. ```bash Ollama Chat

Ollama Chat Interface

{% if response %}

Response:

{{ response }}

{% endif %} ``` ## Step 5: Run the Web App Finally, start your FastAPI server. ```bash uvicorn main:app --host 0.0.0.0 --port 8000 ``` Output. ```bash INFO: Started server process [41142] INFO: Waiting for application startup. INFO: Application startup complete. INFO: Uvicorn running on http://0.0.0.0:8000 (Press CTRL+C to quit) ``` Now open **http://your-server-ip:8000** in your browser. You will see the FastAPI interface with a chat box. Type “**Please explain about linux operating system**” and click on **Send.** You will see a real-time response from the Ollama model. ![](https://www.atlantic.net/wp-content/uploads/2025/06/p1-4.png) ## Conclusion You’ve now seen how to serve large language models like Mistral on your own GPU server using Ollama. Starting from setting up Python and the Ollama runtime to calling the model through a REST API, you also built a lightweight web interface with FastAPI and Jinja2 to send prompts and display streamed responses. This setup is ideal for creating private, low-latency LLM applications that run entirely on your infrastructure. --- # Sales Demo by Atlantic.Net > URL: https://www.atlantic.net/demo/ | Updated: 2026-09-16 Atlantic.Net sales demo The presentation is hosted on Google Slides, a third-party service that sets its own cookies once loaded. Prefer a new tab? [Open the presentation on Google Slides](https://docs.google.com/presentation/d/e/2PACX-1vTIiaoXg1_t-7V61UoGsyTzsz4wJRFy1VbzizkBz9o_noXnq_--5zOHzDPzAEB2-ohekrhBjkf0lZH_/pubembed?start=false&loop=false&delayms=60000). ## Dedicated to Your Success Jason Coleman VP of Information Technology, Orlando Magic > "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge." Joseph Nompleggi VP of Product Development, Complete Healthcare Solutions > "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals." Gilad Shainer Senior Vice President of Networking, NVIDIA (Formerly Vice President of Market Development at Mellanox Technologies) > "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform." Erin Chapple General Manager for Windows Server, Microsoft Corp. > "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services." ## Enterprise Hosting Designed Around Your Needs From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business. Call or email us now. [**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net) ### Let's Discuss Your Infrastructure Needs Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started. ### See What Sets Atlantic.Net Apart and How We Help Customers Succeed. Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience. --- # How to Use StarRocks for Fast SQL Queries on JSON and Nested Data Using Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-use-starrocks-for-fast-sql-queries-on-json-and-nested-data-using-ubuntu-24-04-gpu-server/ | Published: 2025-07-09 | Updated: 2026-05-04 | Author: Hitesh Jethva StarRocks is a blazing-fast analytical database optimized for modern analytics workloads. It supports semi-structured formats like JSON and nested data, making it an excellent fit for use cases involving raw event data, user activity logs, or application telemetry. In this hands-on tutorial, you’ll learn how to deploy StarRocks on Ubuntu 24.04 with Docker, preprocess JSON using GPU acceleration, and run fast SQL queries using the StarRocks engine. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Install Required Packages Install essential tools like Python, Docker, Java, and the MySQL client needed for running StarRocks and preprocessing JSON with a GPU. First, update all the packages to the latest version. ```bash apt update -y ``` Next, install the required packages. ```bash apt install python3 python3-pip python3-venv docker-compose default-jdk -y ``` ## Step 2: Deploy StarRocks with Docker Compose We will use Docker Compose to deploy a single-node StarRocks cluster with Frontend (FE) and Backend (BE) services. First, create a directory for your project and navigate inside it. ```bash mkdir ~/starrocks && cd ~/starrocks ``` Next, create a docker-compose.yml file. ```bash nano docker-compose.yml ``` Add the following configuration. ```bash version: '3.8' services: fe: image: starrocks/fe-ubuntu:3.2-latest container_name: starrocks-fe ports: - "8030:8030" # Web UI - "9030:9030" # MySQL protocol environment: - FE_SERVERS=starrocks-fe:9010 command: - /opt/starrocks/fe/bin/start_fe.sh volumes: - ./fe-meta:/opt/starrocks/fe/meta restart: always be: image: starrocks/be-ubuntu:3.2-latest container_name: starrocks-be depends_on: - fe ports: - "8040:8040" # BE port command: - /opt/starrocks/be/bin/start_be.sh environment: - FE_SERVERS=starrocks-fe:9010 volumes: - ./be-storage:/opt/starrocks/be/storage restart: always ``` The above file defines a StarRocks deployment with two services: - **Frontend (FE)** – Acts as the query coordinator, running on port 8030 (web UI) and 9030 (MySQL protocol). It stores metadata in the ./fe-meta volume and connects to the backend. - **Backend (BE)** – Handles data storage and query execution, exposed on port 8040. It depends on the FE and stores data in ./be-storage. Both services auto-restart on failure. Start the container using the command below. ```bash docker compose up -d ``` Verify that containers are running. ```bash docker ps ``` Output. ```bash CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 97465ff8fb67 starrocks/be-ubuntu:3.2-latest "/opt/starrocks/be/b…" 31 minutes ago Up 31 minutes 0.0.0.0:8040->8040/tcp, [::]:8040->8040/tcp starrocks-be b184563cf3b3 starrocks/fe-ubuntu:3.2-latest "/opt/starrocks/fe/b…" 31 minutes ago Up 31 minutes 0.0.0.0:8030->8030/tcp, [::]:8030->8030/tcp, 0.0.0.0:9030->9030/tcp, [::]:9030->9030/tcp starrocks-fe ``` ## Step 3: Connect to StarRocks Frontend Use the MySQL protocol to connect to the StarRocks FE service and issue SQL commands for managing databases and tables. First, install the MySQL client package. ```bash apt install mysql-client -y ``` Next, verify the StarRocks FE connectivity. ```bash mysql -h 127.0.0.1 -P 9030 -uroot ``` The FE must register at least one BE node to store data. Add the backend node using the below command. ```bash ALTER SYSTEM ADD BACKEND "starrocks-be:9050"; ``` Verify that the backend is registered and active. ```bash SHOW BACKENDS\G ``` Output. ```bash *************************** 1. row *************************** BackendId: 10006 IP: 172.18.0.3 HeartbeatPort: 9050 BePort: 9060 HttpPort: 8040 BrpcPort: 8060 LastStartTime: 2025-06-28 11:06:13 LastHeartbeat: 2025-06-28 11:07:28 Alive: true SystemDecommissioned: false ClusterDecommissioned: false TabletNum: 59 DataUsedCapacity: 0.000 B AvailCapacity: 269.413 GB TotalCapacity: 337.143 GB UsedPct: 20.09 % MaxDiskUsedPct: 20.09 % ErrMsg: Version: 3.2.16-8dea52d Status: {"lastSuccessReportTabletsTime":"2025-06-28 11:07:14"} DataTotalCapacity: 269.413 GB DataUsedPct: 0.00 % CpuCores: 4 NumRunningQueries: 0 MemUsedPct: 0.73 % CpuUsedPct: 0.2 % Location: 1 row in set (0.00 sec) ``` ## Step 4: Create a Database and Table In this section, we will create a StarRocks database and define a table schema to receive flattened JSON data. First, create a StarRocks database. ```bash CREATE DATABASE gpu_json; ``` Change the database to **gpu_json.** ```bash USE gpu_json; ``` Define a table schema. ```bash CREATE TABLE IF NOT EXISTS users ( id INT, name STRING, email STRING, city STRING, zip STRING ) ENGINE=OLAP DUPLICATE KEY(id) DISTRIBUTED BY HASH(id) BUCKETS 1 PROPERTIES("replication_num" = "1"); ``` Press CTRL+D to exit from the MySQL shell. ## Step 5: Set Up GPU JSON Preprocessing with cuDF We’ll now use GPU acceleration to flatten nested JSON data using NVIDIA’s cuDF, a high-performance GPU dataframe library. Create a Python virtual environment and activate it. ```bash python3 -m venv venv source venv/bin/activate ``` Update pip to the latest version. ```bash pip install --upgrade pip ``` Install cuDF to preprocess nested JSON. ```bash pip install cudf-cu12 --extra-index-url=https://pypi.nvidia.com ``` Create a sample JSON data. ```bash nano raw_users.json ``` Add the following content. ```bash [ { "id": 1, "user": { "name": "Alice", "email": "alice@example.com", "location": {"city": "New York", "zip": "10001"} } }, { "id": 2, "user": { "name": "Bob", "email": "bob@example.com", "location": {"city": "Chicago", "zip": "60601"} } } ] ``` This JSON structure contains nested fields that we’ll flatten before loading into StarRocks. Create a **preprocess_json_gpu.py** script to load the JSON into GPU memory, extract nested values, and save the flat result to a CSV file. ```bash nano preprocess_json_gpu.py ``` Add the following code. ```bash import cudf import json # Load raw JSON file with open("raw_users.json", "r") as f: data = json.load(f) # Convert list of dicts to cuDF DataFrame df = cudf.DataFrame(data) # Convert 'user' column to pandas for safe iteration user_data = df['user'].to_pandas() # Extract nested fields using pandas-like iteration df['name'] = [user['name'] for user in user_data] df['email'] = [user['email'] for user in user_data] df['city'] = [user['location']['city'] for user in user_data] df['zip'] = [user['location']['zip'] for user in user_data] # Drop the original nested column df = df.drop(columns=['user']) # Save to CSV df.to_csv("flattened_users.csv", index=False) print("✅ Flattened data saved to 'flattened_users.csv'") ``` Run the script. ```bash python3 preprocess_json_gpu.py ``` ## Step 6: Load the CSV into StarRocks Using Stream Load We’ll use StarRocks’ HTTP API to load the CSV file directly into the users table. First, remove the CSV header row. ```bash tail -n +2 flattened_users.csv > flattened_users_noheader.csv ``` Load the data to StarRocks using curl. ```bash curl -v --location-trusted -u root: \ -H "label: csv_load_02" \ -H "format: csv" \ -H "column_separator: ," \ -H "Expect: 100-continue" \ -T ./flattened_users_noheader.csv \ http://localhost:8030/api/gpu_json/users/_stream_load ``` Look for a “Status”: “Success” message in the output. ```bash { "TxnId": 4, "Label": "csv_load_02", "Status": "Success", "Message": "OK", "NumberTotalRows": 3, "NumberLoadedRows": 3, "NumberFilteredRows": 0, "NumberUnselectedRows": 0, "LoadBytes": 100, "LoadTimeMs": 29, "BeginTxnTimeMs": 0, "StreamLoadPlanTimeMs": 2, "ReadDataTimeMs": 0, "WriteDataTimeMs": 6, "CommitAndPublishTimeMs": 20 * Connection #1 to host 172.18.0.3 left intact ``` ## Step 7: Verify the Data In this section, we will query the table to confirm that the flattened JSON has been loaded correctly. First, connect to StarRocks. ```bash mysql -h 127.0.0.1 -P 9030 -uroot ``` Change the database to gpu_json. ```bash mysql> USE gpu_json; ``` Verify the data. ```bash mysql> SELECT * FROM users; ``` Output. ```bash +----+-------+-------------------+----------+--------+ | id | name | email | city | zip | +----+-------+-------------------+----------+--------+ | 1 | Alice | alice@example.com | New York | 10001 | | 2 | Bob | bob@example.com | Chicago | 60601 | +----+-------+-------------------+----------+--------+ ``` ## Conclusion In this tutorial, you built a powerful data pipeline using StarRocks and [GPU acceleration](https://www.atlantic.net/gpu-server-hosting/ai-accelerator-vs-gpu-5-key-differences-and-how-to-choose/) on Ubuntu 24.04. You learned how to deploy a StarRocks single-node cluster using Docker Compose, preprocess nested JSON data with NVIDIA’s cuDF library, and ingest the flattened data using the high-performance Stream Load API. Finally, you verified that the data was correctly loaded and queried it using standard SQL. --- # How to Build a Real-Time AI Inference Pipeline Using GPU and StarRocks > URL: https://www.atlantic.net/gpu-server-hosting/how-to-build-a-real-time-ai-inference-pipeline-using-gpu-and-starrocks/ | Published: 2025-07-14 | Updated: 2025-08-01 | Author: Hitesh Jethva Building a real-time AI inference pipeline lets you analyze and react to data as soon as it’s available. With the rise of deep learning and big data, you often need to combine high-performance AI models (using GPU acceleration) with fast, scalable analytics tools. In this guide, you’ll learn how to set up an end-to-end pipeline that uses a [GPU server](https://www.atlantic.net/gpu-server-hosting/) for running AI inference with PyTorch and StarRocks. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Install Required Packages You need several tools and dependencies to build your AI inference pipeline and run StarRocks. This step will guide you through updating your system and installing everything you need. First, update all the packages to the latest version. ```bash apt update -y ``` Next, install the required packages. ```bash apt install python3 python3-pip python3-venv docker-compose default-jdk -y ``` ## Step 2: Deploy StarRocks with Docker Compose Now that you have the required tools, it’s time to deploy a StarRocks cluster using Docker Compose. This makes it easy to set up and manage both the Frontend (FE) and Backend (BE) services needed for analytics. First, create a directory for your StarRocks project. ```bash mkdir ~/starrocks && cd ~/starrocks ``` Next, create a docker-compose.yml file. ```bash nano docker-compose.yml ``` Add the following configuration. ```bash version: '3.8' services: fe: image: starrocks/fe-ubuntu:3.2-latest container_name: starrocks-fe ports: - "8030:8030" # Web UI - "9030:9030" # MySQL protocol environment: - FE_SERVERS=starrocks-fe:9010 command: - /opt/starrocks/fe/bin/start_fe.sh volumes: - ./fe-meta:/opt/starrocks/fe/meta restart: always be: image: starrocks/be-ubuntu:3.2-latest container_name: starrocks-be depends_on: - fe ports: - "8040:8040" # BE port command: - /opt/starrocks/be/bin/start_be.sh environment: - FE_SERVERS=starrocks-fe:9010 volumes: - ./be-storage:/opt/starrocks/be/storage restart: always ``` **Explanation:** - **Frontend** (FE): Handles queries and coordinates the cluster, with ports 8030 (web UI) and 9030 (MySQL protocol). - **Backend** (BE): Stores data and executes queries, exposed on port 8040. It depends on the FE service. - Both use local volumes to persist metadata and storage, and will restart automatically if they fail. Start the StarRocks cluster. ```bash docker compose up -d ``` Verify that containers are running. ```bash docker ps ``` You should see both starrocks-fe and starrocks-be containers in the output, indicating that your StarRocks cluster is up and running. ```bash CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 97465ff8fb67 starrocks/be-ubuntu:3.2-latest "/opt/starrocks/be/b…" 31 minutes ago Up 31 minutes 0.0.0.0:8040->8040/tcp, [::]:8040->8040/tcp starrocks-be b184563cf3b3 starrocks/fe-ubuntu:3.2-latest "/opt/starrocks/fe/b…" 31 minutes ago Up 31 minutes 0.0.0.0:8030->8030/tcp, [::]:8030->8030/tcp, 0.0.0.0:9030->9030/tcp, [::]:9030->9030/tcp starrocks-fe ``` ## Step 3: Connect to StarRocks Frontend With StarRocks running in Docker, it’s time to connect to the Frontend (FE) service and prepare it for storing AI inference results. You’ll use the MySQL client to manage your StarRocks databases and tables, since StarRocks supports the MySQL protocol for compatibility. 1. First, install the MySQL client package. ```bash apt install mysql-client -y ``` 2. Next, connect to StarRocks FE using MySQL protocol. ```bash mysql -h 127.0.0.1 -P 9030 -uroot ``` This command connects to the StarRocks FE running on your server at port 9030, using the default root user. 3. Before you can create and use tables, you must register at least one backend (BE) node with the FE. ```bash mysql>ALTER SYSTEM ADD BACKEND "starrocks-be:9050"; ``` 4. Verify that the backend is registered and active. ```bash mysql>SHOW BACKENDS\G ``` You should see an output showing the BE node’s status, IP address, and “Alive: true.” ```bash *************************** 1. row *************************** BackendId: 10006 IP: 172.18.0.3 HeartbeatPort: 9050 BePort: 9060 HttpPort: 8040 BrpcPort: 8060 LastStartTime: 2025-06-28 11:06:13 LastHeartbeat: 2025-06-28 11:07:28 Alive: true SystemDecommissioned: false ClusterDecommissioned: false TabletNum: 59 DataUsedCapacity: 0.000 B AvailCapacity: 269.413 GB TotalCapacity: 337.143 GB UsedPct: 20.09 % MaxDiskUsedPct: 20.09 % ErrMsg: Version: 3.2.16-8dea52d Status: {"lastSuccessReportTabletsTime":"2025-06-28 11:07:14"} DataTotalCapacity: 269.413 GB DataUsedPct: 0.00 % CpuCores: 4 NumRunningQueries: 0 MemUsedPct: 0.73 % CpuUsedPct: 0.2 % Location: 1 row in set (0.00 sec) ``` 5. Exit from MySQL. ```bash mysql>exit; ``` ## Step 4: Create Tables in StarRocks for Prediction Data Now that your StarRocks cluster is up and the backend node is active, you need a place to store your AI inference results. You’ll create a database and a table designed for logging model predictions, making it easy to analyze results in real-time. 1. Connect to StarRocks FE with the MySQL client. ```bash mysql -h 127.0.0.1 -P 9030 -uroot ``` 2. Create a new database for your AI demo. ```bash mysql>CREATE DATABASE ai_demo; ``` 3. Switch to your new database. ```bash mysql> USE ai_demo; ``` 4. Create a predictions table to store model outputs. ```bash mysql> CREATE TABLE predictions ( filename VARCHAR(255), prediction INT, ts DATETIME DEFAULT CURRENT_TIMESTAMP ) ENGINE=OLAP DUPLICATE KEY(filename) DISTRIBUTED BY HASH(filename) BUCKETS 3 PROPERTIES ( "replication_num" = "1" ); ``` 5. Exit the MySQL client. ```bash mysql>exit; ``` ## Step 5: Run AI Inference Using GPU (PyTorch) With your StarRocks database ready, it’s time to generate some predictions using a GPU-accelerated AI model. In this step, you’ll set up a simple PyTorch pipeline to process images, run inference on your GPU, and export results for analytics. 1. Create a Python virtual environment for your project. ```bash python3 -m venv venv source venv/bin/activate ``` 2. Install PyTorch and related libraries. ```bash pip install torch torchvision pillow ``` 3. Build your model inference script. ```bash nano model_inference.py ``` Add the following code: ```bash import torch from torchvision.models import resnet50, ResNet50_Weights from torchvision import transforms from PIL import Image weights = ResNet50_Weights.DEFAULT model = resnet50(weights=weights).cuda().eval() transform = weights.transforms() def predict(image_path): image = Image.open(image_path).convert('RGB') input_tensor = transform(image).unsqueeze(0).cuda() with torch.no_grad(): output = model(input_tensor) return output.argmax(dim=1).item() ``` 4. Test single image inference. ```bash python3 model_inference.py ``` 5. Create another script to run batch inference on a folder of images. ```bash nano batch_infer.py ``` Add the following code: ```bash import os, csv from model_inference import predict from PIL import UnidentifiedImageError os.makedirs("images", exist_ok=True) # Ensure folder exists with open("predictions.csv", "w", newline="") as f: writer = csv.writer(f) writer.writerow(["filename", "prediction"]) for file in os.listdir("images"): if file.endswith(".jpg"): path = os.path.join("images", file) try: label = predict(path) writer.writerow([file, label]) except UnidentifiedImageError: print(f"Skipped invalid image: {file}") ``` This script loops through all .jpg files in the images folder, runs inference, and writes the results to predictions.csv. 6. Run the batch inference. ```bash python3 batch_infer.py ``` After this step, you’ll have a predictions.csv file with model outputs, ready to load into StarRocks for analytics. ## Step 6: Ingest Inference Data into StarRocks With your AI model’s predictions saved in predictions.csv, the next step is to load these results directly into your StarRocks database. StarRocks offers a simple and fast streaming API called Stream Load for ingesting batch data via HTTP. 1. Use the Stream Load API with curl. ```bash curl --location-trusted -u root: \ -T predictions.csv \ -H "Expect: 100-continue" \ -H "Content-Type: application/octet-stream" \ -H "column_separator:," \ -H "columns: filename,prediction" \ http://localhost:8030/api/ai_demo/predictions/_stream_load ``` You should see a response like this: ```bash { "TxnId": 2, "Label": "c62f6a53-aeff-4be2-a2b5-0d04733217ae", "Status": "Success", "Message": "OK", "NumberTotalRows": 1, "NumberLoadedRows": 1, "NumberFilteredRows": 0, "NumberUnselectedRows": 0, "LoadBytes": 21, "LoadTimeMs": 195, "BeginTxnTimeMs": 22, "StreamLoadPlanTimeMs": 116, "ReadDataTimeMs": 0, "WriteDataTimeMs": 9, "CommitAndPublishTimeMs": 46 } Status: "Success" confirms your data was loaded. ``` Your AI inference results are now stored in StarRocks and ready for instant querying and analytics! In the next step, you’ll learn how to run real-time SQL queries on these predictions. ## Step 7: Query Results in Real-Time Once your predictions are loaded into StarRocks, you can instantly analyze and visualize the data using SQL queries. This step demonstrates how to access your AI inference results and perform real-time analytics. 1. Connect to StarRocks using the MySQL client. ```bash mysql -h 127.0.0.1 -P 9030 -uroot ``` 2. Switch to your AI demo database. ```bash mysql> USE ai_demo; ``` 3. View the latest predictions. ```bash mysql>SELECT * FROM predictions ORDER BY ts DESC LIMIT 5; ``` This command fetches the five most recent inference results, letting you monitor new data as it arrives. ```bash +----------+------------+---------------------+ | filename | prediction | ts | +----------+------------+---------------------+ | filename | NULL | 2025-07-09 07:34:34 | +----------+------------+---------------------+ 1 row in set (0.07 sec) ``` 4. Aggregate predictions for analytics. ```bash mysql> SELECT prediction, COUNT(*) AS count FROM predictions GROUP BY prediction ORDER BY count DESC; ``` This query shows how many times each prediction label appears, great for summarizing your model’s results. ```bash +------------+-------+ | prediction | count | +------------+-------+ | NULL | 1 | +------------+-------+ 1 row in set (0.03 sec) ``` Your pipeline is now complete, from GPU-powered inference to instant analytics with StarRocks! ## Conclusion You’ve now built a complete real-time AI inference pipeline using a GPU server and StarRocks. You started by preparing your Ubuntu 24.04 environment, then deployed StarRocks with Docker Compose. After connecting to StarRocks, you created a table for storing prediction results. Next, you used PyTorch to run image classification on your GPU, saved the predictions, and loaded them directly into StarRocks for real-time analytics. --- # IaaS (Infrastructure as a Service): The Ultimate Guide [2025] > URL: https://www.atlantic.net/dedicated-server-hosting/what-is-iaas/ | Published: 2025-07-15 | Updated: 2026-05-28 | Author: Alexander Wise ## What Is Infrastructure as a Service (IaaS)? Infrastructure as a service (IaaS) is a cloud computing model that provides virtualized computing resources over the internet. Instead of buying and maintaining physical servers and data center infrastructure, organizations can rent compute, storage, and networking on-demand from a cloud provider. This model gives businesses the flexibility to scale up or down based on workload requirements while paying only for what they use. IaaS supports a range of use cases from hosting websites to running large-scale enterprise applications. Users have control over operating systems, deployed applications, and configurations, while the cloud provider manages the underlying physical infrastructure. This makes IaaS ideal for organizations that need computing power and flexibility without the burden of managing hardware. ![](https://www.atlantic.net/wp-content/uploads/2025/07/graphic_what-is-iaas.jpg) ## IaaS Architecture In the IaaS model, cloud providers host infrastructure like servers, storage, networking hardware, and hypervisors, meaning organizations do not need to have this requirement in their on-premise data center. **IaaS providers offer a variety of services over this infrastructure. These include:** - Multi tenancy and billing management - Logging and monitoring - Security - Clustering, failover and load balancing - Backup, replication and recovery Most IaaS providers offer policy-driven services, allowing users to implement a high level of automation and coordinate critical infrastructure tasks. For example, users can implement policies that automate load balancing to maintain application performance and availability. IaaS customers can access resources and services over a wide area network (WAN) such as the Internet, and instruct the cloud provider to deploy a complete application stack. For example, a user can connect to the IaaS platform remotely to create virtual machines (VMs). They can install an operating system and an enterprise application on each virtual machine, deploy local disk storage, large-scale object storage, and database systems. The user can then use the provider’s services for cost tracking, performance monitoring, network traffic balancing, disaster recovery management, and more. Most IaaS users consume cloud services via a cloud provider, such as Amazon Web Services or Microsoft Azure . This is known as public cloud computing. Organizations can also set up their own IaaS infrastructure, creating what is known as a private cloud, or in combination with public cloud resources, a hybrid cloud. ***Learn more in the in-depth guides to***[***Load Balancers***](https://www.radware.com/cyberpedia/application-delivery/what-is-load-balancing/) **Related product offering:** [Radware Alteon | Application Delivery and Security](https://www.radware.com/products/alteon/) ## Multi-Tenant Architecture in the Cloud Multi-Tenant Architecture in the Cloud Multi-tenancy makes it possible for one software application or infrastructure component to serve multiple customers. Customers are referred to as “tenants”. Each tenant might have the ability to customize the infrastructure or service they receive, but they usually do not have full access to its configuration or source code. A multi-tenant architecture runs applications or infrastructure in a shared environment. Every tenant is logically separated, while working on resources that are physically integrated with those of other tenants. This means that a multi-tenant component shares one instance of configurations, user management, and data. Most cloud environments are based on the multi-tenancy model. Both public clouds and private clouds use multi-tenancy, allowing multiple users or groups (whether from different organizations or the same organization) to run workloads separately. For example, in a multi-tenant public cloud environment, multiple organizations or users can run workloads on the same physical server. However, each user only sees their own workloads, a concept known as isolation. ***Learn more in the in-depth guide to***[***multi-tenant architecture***](https://frontegg.com/blog/multi-tenant-architecture) ## What Is Cloud Hosting? Cloud hosting is a paradigm that allows organizations to leverage cloud computing without the full complexity of public cloud or private cloud deployments. Cloud hosting is a more flexible, scalable, and reliable alternative to traditional hosting methods like shared hosting and dedicated hosting. Unlike these traditional methods, where an organization’s resources run on a single server in a provider’s data center, cloud hosting leverages large-scale cloud computing environments, enabling easier scalability and redundancy. Here are the primary types of cloud hosting: - **Managed cloud hosting:** In managed cloud hosting, the service provider takes care of the setup, administration, management, and support of the cloud servers, freeing up the business to focus on its core competencies. - **Cloud VPS (Virtual Private Server):** This is a type of cloud hosting where the user has an allocated amount of server resources. Unlike shared hosting, resources aren’t shared with other users. This type of hosting is scalable and can be adjusted as needed. - **Dedicated server hosting:** This type of service allows organizations to use a dedicated server hosted within a cloud platform. ***Learn more in our detailed guide to***[***what is cloud hosting***](https://www.atlantic.net/vps-hosting/what-is-cloud-hosting/) ***Related technology updates:*** - [*[Blog] What Is the Difference Between a Dedicated Server and a Dedicated Cloud Host? *](https://www.atlantic.net/dedicated-server-hosting/what-is-the-difference-between-a-dedicated-server-and-a-dedicated-cloud-host/) ***Learn more in our detailed guide to***[***dedicated server hosting***](https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/) ***Related product offering:***[***VPS hosting***](https://www.atlantic.net/vps-hosting/)***by Atlantic.net*** ## What Is a Bare-Metal Cloud? A bare-metal cloud is a type of cloud service where the client leases physical servers from a cloud service provider. Unlike traditional cloud models where multiple users share resources of the same physical server, the bare-metal cloud provides dedicated servers to a single client. This eliminates the “noisy neighbor” problem often encountered in shared hosting environments. The term “bare-metal” refers to the direct access granted to the underlying physical servers. This means that users are not limited to the resources provided by the hypervisor or virtualization software, but they can access the full capacity of the physical servers. This includes the server’s processor power, memory, storage, and networking resources. Bare-metal cloud combines the best features of traditional dedicated server hosting with the flexibility and scalability of cloud hosting. You get the raw performance of physical servers and the ability to scale up or down as your needs change. And unlike traditional dedicated servers, you can provision and deprovision servers in a matter of minutes, not days or weeks. ***Related product offering:***[***bare metal servers***](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/)***by Atlantic.net*** ## IaaS vs PaaS vs SaaS ### What is Platform as a Service (PaaS)? Platform as a Service (PaaS) provides some infrastructure components, along with additional managed service and software. A PaaS is a framework developers can use to create their own applications, focusing on developing software functionality for their end users. The cloud provider manages complex back-end infrastructure, including computing resources, operating systems, software updates, storage, networking, and integrations. ### What is Software as a Service (SaaS)? Software as a service (SaaS) is a popular choice for cloud users. Because SaaS delivers software to end users over the Internet, most SaaS applications run directly from a web browser and do not need to be downloaded or installed by the customer. PaaS, on the other hand, delivers a software development platform. The majority of cloud consumers do not need PaaS. This web services model eliminates the need for IT staff to download and install applications on local devices. SaaS enables providers to simplify service and support for their business, while solving potential technical problems such as data and storage management, middleware, servers, and networking. ### Key Differences Between IaaS, PaaS and SaaS - PaaS is based on the IaaS model—this is because, in addition to infrastructure components, the provider manages the operating systems, middleware, and other operating environments for cloud users. PaaS workloads simplify deployment but offer more limited flexibility compared to a pure IaaS model. - SaaS manages all infrastructure and applications needed for the end user—SaaS users don’t need to install or deploy anything. They can typically just login and start using the provider’s application, running on the provider’s infrastructure. Users can customize the behavior of applications, add their own data, and restrict access. Almost all other aspects are the responsibility of the SaaS provider. ## Public Cloud vs. Private Cloud vs. Hybrid Cloud vs. Multi Cloud There are three primary types of cloud computing environments: public, private, and hybrid clouds: - **Public cloud** is the most common form of cloud computing. In this model, service providers offer resources, such as servers and storage, over the Internet. Public cloud services are generally affordable and highly scalable, but they may lack the security and control desired by some businesses. - **Private cloud**is a cloud service that is not shared with any other organization. The servers and storage are dedicated to a single business, providing greater control and security. However, private clouds are more expensive and require more management than public clouds. - **Hybrid cloud** is a blend of public and private clouds. It allows businesses to keep sensitive information in a private cloud while using the public cloud for non-sensitive data and applications. Hybrid clouds offer the best of both worlds, combining the security of private clouds with the cost-effectiveness and scalability of public clouds. - **Multi cloud** refers to the use of multiple cloud services from different providers. This approach allows businesses to avoid vendor lock-in, optimize costs, and leverage the unique strengths of each cloud provider. Multi cloud strategies enable greater flexibility and resilience, as workloads can be distributed across various platforms to meet specific requirements and ensure continuity. ***Learn more in the detailed guides to:*** - [***Multi cloud***](https://umbrellacost.com/learning-center/what-is-multicloud-benefits-use-cases-challenges-and-solutions/) - [***Hybrid cloud***](https://faddom.com/hybrid-cloud-architecture-use-cases-and-5-critical-best-practices/) **Related technology updates:** [[Report] Optimizing in a Multi-Cloud World ](https://spot.io/blog/research-optimize-multi-cloud-infrastructure/) ### Examples of IaaS Use Cases IaaS enables organizations to access scalable, on-demand infrastructure without maintaining physical hardware. This model is suited for a wide range of use cases across industries and technical needs. - **Test and Development** – Quickly provision environments for application development and testing, supporting agile workflows and CI/CD pipelines. - **Web Applications** – Host web apps with dynamic scaling and built-in load balancing, minimizing upfront infrastructure investment. - **Cloud hosting** – Distributes website or application data across multiple virtual servers, offering scalability, high availability, and flexibility without physical server management. It supports a wide variety of workloads and operational needs. *Learn about Atlantic.net*[*cloud hosting solutions*](https://www.atlantic.net/cloud-platform/cloud-hosting/)*.* - **Dedicated hosting** – Provides organizations with exclusive use of physical servers, delivering consistent performance, control, and security for high-demand or regulated workloads. *Learn about Atlantic.net*[*dedicated server hosting*](https://www.atlantic.net/dedicated-server-hosting/)*.* - **Storage, Backup, and Recovery** – Leverage elastic storage and automated backup solutions without complex on-prem management. *Learn more in the detailed guide to*[*cloud storage*](https://bluexp.netapp.com/cloud-storage). - **High-Performance Computing (HPC)** – Run simulations, financial models, or scientific computations using scalable compute clusters available on demand. - **Big Data Analytics** – Utilize distributed storage and compute resources for real-time analytics, machine learning, and large-scale data processing. - **Learning Management Systems (LMS)** – Deploy scalable back-ends for LMS platforms that require high uptime and adaptable performance, supporting e-learning for organizations, educational institutions, or corporate training platforms. *Learn more in the detailed guide to*[*Learning Management Systems*](https://corp.kaltura.com/blog/learning-management-systems/). - **Digital Asset Management (DAM)** – Store and serve media assets globally with high availability and integrated security controls. *Learn more in the detailed guide to*[*Digital Asset Management*](https://cloudinary.com/guides/digital-asset-management/what-is-digital-asset-management). - **Related product offering:** [Cloudinary Assets | AI-Powered Digital Asset Management](https://cloudinary.com/products/digital_asset_management) - **Related technology update:** [[Blog] New for DAM: Media Library Extension for Chrome](https://cloudinary.com/blog/new_for_dam_media_library_extension_for_chrome) [[Blog] Best Image Optimization Techniques: Expert Roundup](https://cloudinary.com/blog/image_optimization_expert_roundup) - **Infrastructure as Code (IaC)** – Automate infrastructure provisioning and management through code, using tools like Terraform or AWS CloudFormation. IaaS provides the underlying resources that IaC tools configure and orchestrate, enabling consistent, repeatable deployments. ***Learn more in the detailed guide to***[***Infrastructure as Code***](https://codefresh.io/learn/infrastructure-as-code/) ***Related product offering:*** [*GitOps Software Delivery Platform*](https://codefresh.io/)*by Codefresh* ***Related technology update:***[*[Blog] How to Model Your GitOps Environments and Promote Releases between Them *](https://codefresh.io/blog/how-to-model-your-gitops-environments-and-promote-releases-between-them/) ### What Is CloudOps? CloudOps is the combination of continuous operations and continuous delivery in the cloud. It is about operating your infrastructure and applications in a way that is optimized, efficient, reliable, secure, and cost-effective. In the context of IaaS, CloudOps involves managing and maintaining the infrastructure elements provided by the IaaS provider. This could include server instances, storage, and networking components. The goal is to ensure that these resources are optimally configured, secure, and that they are delivering value to the business. CloudOps also involves monitoring and managing the performance and availability of these resources. This includes setting and managing service levels, as well as identifying and resolving any issues that may arise. ***Learn more in our detailed guide to***[***CloudOps***](https://spot.io/cloudops/) ***Related product offering:***[*NetApp Spot | Cloud Optimization Solutions*](https://spot.io/) ***Related technology update:***[*[Report] 2023 State of CloudOps*](https://spot.io/blog/state-of-cloudops-2023-cloud-operations-challenges/) ***Learn more in our detailed guide to:***[***Cloud Optimization***](https://spot.io/resources/cloud-optimization/cloud-optimization-the-4-things-you-must-optimize/) ***Related technology update:***[*[Report] GigaOm 2024 Radar for Cloud Resource Optimization*](https://spot.io/blog/spot-gigaom-radar-cloud-resource-optimization-third-year/) ***Learn more in our detailed guide to:***[***Cloud Cost Optimization***](https://granulate.io/blog/cloud-cost-optimization-optimization-tips/) ### What Is FinOps? FinOps, short for Financial Operations, is a discipline that combines financial management, operations, and cloud engineering to optimize cloud spending and maximize business value. It focuses on gaining financial control and accountability over cloud resources, ensuring that cloud investments are made efficiently and aligned with business objectives. **FinOps involves several key practices:** 1. Visibility: Ensuring that cloud costs are transparent and understandable. This includes detailed cost reporting and usage analytics to track where and how resources are being consumed. 2. Optimization: Identifying areas where cloud spending can be reduced without compromising performance or reliability. This includes rightsizing instances, leveraging reserved instances, and eliminating unused resources. 3. Governance: Implementing policies and controls to manage cloud spending. This involves setting budgets, defining cost allocation rules, and establishing spending limits to prevent cost overruns. 4. Collaboration: Facilitating communication and cooperation between finance, operations, and engineering teams. This ensures that financial considerations are integrated into the cloud management process and that all stakeholders are aligned on cost management goals. By integrating FinOps into cloud operations, organizations can better manage their cloud costs, enhance financial predictability, and ensure that their cloud investments support overall business strategy. ***Learn more in the detailed guide to***[***FinOps*********](https://www.finout.io/blog/finops-guide) ### FinOps on AWS FinOps on AWS involves leveraging various tools and practices provided by Amazon Web Services to manage and optimize cloud costs effectively. Key components include: - AWS Cost Explorer: This tool provides detailed insights into your AWS spending and usage. It helps in analyzing cost trends, identifying cost drivers, and exploring saving opportunities. With Cost Explorer, you can create custom reports and visualize data to understand spending patterns better. - AWS Budgets: AWS Budgets allows you to set custom cost and usage budgets. You can receive alerts when usage or costs exceed the predefined thresholds, enabling proactive management of cloud expenses. This tool also integrates with AWS Cost Explorer for detailed budget analysis. - AWS Trusted Advisor: Trusted Advisor offers real-time recommendations to optimize your AWS environment. It provides insights on cost optimization, security, fault tolerance, and performance improvements. The cost optimization checks include recommendations for unused or idle resources, reserved instance usage, and opportunities for savings plans. - AWS Savings Plans and Reserved Instances: These purchasing options allow you to commit to using a specific amount of compute power or instances over a one- or three-year period, in exchange for significant discounts compared to on-demand pricing. Utilizing these plans effectively can lead to substantial cost savings. - Cost Allocation Tags: Implementing cost allocation tags helps in categorizing and tracking AWS resources. By tagging resources with meaningful labels, organizations can allocate costs to specific projects, departments, or teams, enabling more granular cost management and accountability. ***Learn more in the detailed guide to***[***AWS cost optimization***](https://www.finout.io/blog/aws-cost-optimization-6-free-tools-10-hacks-to-cut-aws-bills) **Related product offering:** [Finout | Enterprise-Grade FinOps Platform](https://www.finout.io/) **Related technology update:** [[Webinar] How To Create a Cost-Effective AWS Environment](https://www.finout.io/blog/how-to-create-a-cost-effective-aws-environment) ### FinOps on Azure FinOps on Azure focuses on using Microsoft’s suite of tools and services to optimize cloud spending and improve financial management. Key practices include: - Azure Cost Management and Billing: This service provides comprehensive insights into your Azure spending. It includes cost analysis, budgeting, and forecasting tools that help in tracking and managing cloud expenses. You can set budgets and alerts to monitor spending and ensure it stays within the allocated limits. - Azure Advisor: Azure Advisor provides personalized recommendations to optimize your Azure resources for cost, security, performance, and availability. The cost recommendations include advice on rightsizing or shutting down underutilized resources and taking advantage of reserved instances or savings plans. - Azure Reservations and Spot VMs: Azure Reservations allow you to commit to one- or three-year plans for significant cost savings on compute resources. Spot VMs offer unused Azure capacity at discounted rates, ideal for non-critical or flexible workloads. - Azure Cost Allocation and Tagging: By implementing a robust tagging strategy, organizations can allocate costs accurately to different projects, departments, or business units. Tags facilitate detailed cost reporting and accountability, making it easier to track and manage expenses. - Azure Hybrid Benefit: This feature allows you to use your existing on-premises Windows Server and SQL Server licenses with Software Assurance to save on Azure costs. It provides substantial savings for workloads that can leverage this benefit. ### FinOps on Google Cloud FinOps on Google Cloud involves utilizing Google’s tools and practices to manage cloud costs effectively. Key components include: - Google Cloud Cost Management: This suite of tools includes detailed cost reporting, budget tracking, and cost forecasting. It allows you to monitor spending, analyze cost trends, and set budget alerts to prevent unexpected expenses. - Google Cloud Pricing Calculator: This tool helps in estimating the cost of Google Cloud services based on your specific usage patterns. It provides a detailed breakdown of costs, enabling you to plan and optimize your cloud spending. - Committed Use Contracts and Sustained Use Discounts: Google Cloud offers discounts for committing to use specific resources over a period (one or three years) and automatic sustained use discounts for consistent usage of certain resources. These options help in reducing overall cloud costs significantly. - Resource Management and Tagging: Implementing a robust tagging strategy in Google Cloud allows for detailed cost tracking and allocation. Tags can be used to categorize resources by project, team, or department, facilitating more accurate financial reporting and accountability. Google Cloud Recommender: This tool provides actionable recommendations to optimize your Google Cloud environment. It includes suggestions for rightsizing VMs, removing unused resources, and optimizing storage, helping to reduce costs without impacting performance. ***Learn more in the in-depth guide to***[***cloud cost management***](https://www.finout.io/blog/why-cloud-cost-management-5-tools-to-know-and-tips-for-success) **Related technology updates: ** - [[Webinar] Driving a Successful Company-Wide FinOps Cultural Change ](https://www.finout.io/blog/driving-a-successful-company-wide-finops-cultural-change) - [[Webinar] Mastering Kubernetes Spend-Efficiency ](https://www.finout.io/blog/mastering-kubernetes-spend-efficiency) ## Top Cloud Computing Providers ### General Purpose Cloud Providers 1. **Amazon Web Services**—AWS was the first major IaaS provider in 2008, and is today the leading provider of public cloud computing. It provides a complete computing stack that enables organizations to deploy almost any combination or software and hardware infrastructure. 2. **Microsoft Azure**—Microsoft Azure is the world’s second largest cloud provider. It is the obvious choice for hosting Microsoft-based systems on the cloud, and is a common choice for government agencies. It also runs an increasing number of non-Microsoft workloads, including Linux, HPC, and SAP systems. 3. **Google Cloud**—offers a more limited set of services compared to AWS and Azure, but competes on price and provides the Anthos Platform, which makes it easier to create multi cloud solutions and avoid vendor lock in. 4. **IBM Cloud**—a group of enterprise cloud computing services developed by IBM. Includes IaaS, SaaS, and PaaS solutions supporting public, private, and hybrid cloud models. 5. **Alibaba Cloud**—the leading cloud provider in China, which is forging alliances to become a key player across Asia. 6. **Hewlett Packard Enterprise**—Hewlett Packard Enterprise’s hybrid cloud strategy focuses on its hardware stack, including Aruba wireless networking and edge computing solutions, and software platforms like Greenlake, SimPVT, and Synergy. HPE has partnerships with Red Hat, VMware, and the major cloud providers. 7. **Oracle Cloud**—Oracle’s public cloud has a competitive advantage in IoT, OLTP, microservices, artificial intelligence and machine learning. It provides its popular database software as IaaS and PaaS offerings, and also provides the Oracle Data Cloud, which enables big data analytics for business data. 8. **Dell Technologies/VMware**—Dell acquired VMware and is using it to provide a true multi cloud offering. VMware is today fully container based, and enables companies to run the same workloads on leading public clouds like Amazon, Azure and Google Cloud, as well as on premises. VMware complements its cloud offering with its acquisition of [CloudHealth](https://www.finout.io/blog/vmware-cloudhealth-overview), a cloud cost management solution. **Related product offering:** [Finout | Enterprise-Grade FinOps Platform](https://www.finout.io/) ### Cloud-Native Analytics Platforms Cloud-native analytics platforms are designed to run entirely in the cloud, offering scalable, flexible, and efficient solutions for data storage, processing, and analysis. These platforms separate compute and storage resources, enabling independent scaling and cost optimization. They support various data types and provide advanced analytics capabilities, including real-time processing and machine learning integration. Here are some leading cloud-native analytics platforms: 1. **Snowflake**: A cloud-based data warehouse that separates compute and storage, allowing for independent scaling. Supports structured and semi-structured data formats like JSON and Parquet. Offers features like automatic scaling, data sharing, and support for multiple cloud providers. Utilizes ANSI SQL for querying and provides near-zero maintenance. *Learn more in the in-depth guide to*[*Snowflake pricing*](https://seemoredata.io/blog/understanding-snowflake-pricing/)*.* 2. **Amazon Redshift**: A fully managed, petabyte-scale data warehouse service by AWS. Employs columnar storage and parallel processing to handle large datasets efficiently. Integrates with AWS services like S3 and supports querying data directly from S3 using Redshift Spectrum. Offers features like concurrency scaling and materialized views. 3. **Google BigQuery**: A serverless, highly scalable data warehouse that enables super-fast SQL queries using the processing power of Google’s infrastructure. Automatically handles resource provisioning and scaling. Supports real-time analytics and integrates with various Google Cloud services. Pricing is based on the amount of data processed per query. 4. **Azure Synapse Analytics**: An analytics service that brings together big data and data warehousing. Allows querying data using serverless on-demand or provisioned resources. Integrates with Azure services like Power BI and Azure Machine Learning. Supports both structured and unstructured data and provides a unified experience for ingesting, preparing, managing, and serving data. 5. **Databricks**: A unified data analytics platform built on Apache Spark. Combines data engineering, data science, and machine learning workflows. Supports various data formats and provides collaborative notebooks for data exploration. Offers features like Delta Lake for reliable data lakes and MLflow for managing the machine learning lifecycle. ## IaaS Pricing: AWS vs Azure vs Google Cloud The following table will help you understand the basic pricing model offered by the big three cloud providers. | **Price Parameter** | **AWS** | **Azure** | **Google Cloud** | | --- | --- | --- | --- | | **Compute Instances** | General Purpose, Computer Optimized, Memory Optimized instances Price per second determined by the number of CPUs, memory, and other hardware resources | | | | **Reserved Instances** | Commit to 1-3 years with three payment options: upfront, partial payment and the balance monthly, or monthly payment | Commit to 1-3 years and pay balance upfront | Offers a discount for commitment to 1 or 3 years, with monthly payments | | **Spot Instances** | Bid for unused EC2 capacity at a potentially lower price. Prices fluctuate based on supply and demand. Instances can be terminated by AWS with a two-minute notification if demand rises or spot price exceeds the bid. | Bid for unused Azure compute capacity at reduced prices. Prices can change based on availability and demand. Virtual Machines can be evicted based on capacity or the set max price. | Offered at a lower fixed price than standard VMs. Can be terminated by Google Cloud if resources are needed elsewhere. Designed for batch jobs and fault-tolerant workloads; run for up to 24 hours. | | **Object Storage—Frequent Access** | Basic rate for first 50 TB, discounts for 51-500 TB and over 500 TB | Basic rate for first 50 TB, discounts for 51-500 TB and over 500 TB | Flat rate per GB per month | | **Object Storage—Infrequent Access** | Three tiers: Infrequent access, One Zone Infrequent Access,  Archive Storage | Two tiers: Infrequent access, Archive storage | Two tiers: Nearline storage, Coldline storage | | **Block Storage** | Two tiers: HDD, SSD, and free tier up to 30GB | Two tiers: HDD, SSD | Offers standard local/regional volumes, SSD local/regional volumes, multi-regional snapshot storage | | **Rating Frequency** | Per-Hour for most services, Per-Second for EC2 and Reserved instances | Per-Hour for most services, Per-Second offered for Windows VMs and Container instances | Per-Second pricing for all services | | **Official Pricing Information** | [Official pricing](https://aws.amazon.com/backup/pricing/)[Cost calculator](https://calculator.aws/#/) | [Official pricing Cost calculator](https://azure.microsoft.com/en-us/pricing/calculator/) | [Official pricing Cost calculator](https://cloud.google.com/products/calculator) | ***Learn more in our guides comparing cloud services pricing:*** - [***Google Cloud Pricing***](https://spot.io/resources/google-cloud-pricing/google-cloud-pricing-the-complete-guide/) - [***Cloud Cost***](https://spot.io/resources/cloud-cost/) - [***Spot Instances***](https://spot.io/resources/spot-instances/spot-instances-aws-azure-google-cloud/) - [***Cloud Computing Costs***](https://faddom.com/cloud-computing-costs-and-pricing-comparison/) **Related technology updates:** [[Report] GigaOm 2024 Radar for Cloud Resource Optimization](https://spot.io/blog/spot-gigaom-radar-cloud-resource-optimization-third-year/) ***Learn more in our detailed guide to:***[***AWS EC2 Pricing***](https://spot.io/resources/aws-ec2-pricing/the-ultimate-guide/) ***Related technology updates:*** - [*[Report] Optimizing in a Multi-Cloud World*](https://spot.io/blog/research-optimize-multi-cloud-infrastructure/) - [*[Announcement] Cost Intelligence and Billing Launch*](https://spot.io/blog/go-beyond-savings-spot-for-finops/) ***Learn more in our detailed guide to:***[***Cloud Cost***](https://spot.io/resources/cloud-cost/cloud-cost-models-management-strategies/) ***Related product offering:***[*Spot Eco | Cloud Commitments and Cost Management*](https://spot.io/product/eco/) ## What Is IoT in the Cloud? The Internet of Things, or IoT, refers to the network of physical devices connected to the internet, all collecting and sharing data. When we talk about IoT in the cloud, we’re referring to using cloud computing to process and store the data collected by these devices. IoT in the cloud allows businesses to improve efficiency and make more informed decisions. By using cloud-based analytics, companies can extract valuable insights from vast amounts of data generated by IoT devices. These insights can then be used to drive business growth and innovation. Moreover, cloud-based IoT platforms can handle the massive influx of data from various devices and sensors in real-time. They provide the necessary scalability and storage capacity to manage this data effectively. Also, cloud-based IoT solutions offer advanced security features to ensure that the data remains protected from potential threats. ## IaaS High Availability High availability is an important principle of cloud computing. This is especially important for mission critical systems where downtime due to business interruptions is unacceptable. Downtime can hurt productivity and lead to financial losses. IaaS services are known for their ability to provide a high level of redundancy, spreading applications across multiple physical machines in different locations. They can also provide auto scaling, a mechanism that allows systems to automatically scale up to additional machines on the cloud when loads increase. ### AWS High Availability Architecture Amazon Web Services has built a massive global infrastructure to provide high availability and flexibility for customer workloads. Amazon offers cloud services in 24 regions ([see the map](https://aws.amazon.com/about-aws/global-infrastructure/regions_az/) of the Amazon regions). Amazon defines a region as a geographic area with at least three different data centers known as availability zones (AZs). Each AWS availability zone is a fully localized infrastructure with redundant power supplies, networks, and Internet connectivity. Currently, Amazon supports 77 Availability Zones worldwide. Each AZ typically has three or more data centers in one location, separated by a “meaningful distance” of up to 100 km. This ensures a physical disaster is unlikely to take down all data centers in the AZ, and yet enables high-speed connections between the data centers. ***Learn more in the in-depth guide to***[***AWS auto scaling***](https://spot.io/resources/aws-auto-scaling-scaling-ec2-ecs-rds-and-more/)***.*** ### Azure High Availability Architecture Like AWS, Azure also bases its high availability architecture on regions and availability zones. Azure always stores three copies of user data across three availability zones. This is called redundant local storage. Customers can opt for global redundant storage, to create up to three additional copies of their data in a “paired region”, a nearby region that has fast connectivity with the first region, for added flexibility. Azure availability zones achieve high availability by distributing resources across multiple data centers in a customer’s region. Azure provides additional services like Azure Site Recovery and Azure Backup to achieve the required recovery point objective (RPO) and recovery time objective (RTO) for their applications. ### Google Cloud SQL High Availability Architecture In Google Cloud, resources that operate in one zone are called “zonal resources”. Other resources operate across an entire region and are called “regional resources”. For example, a Google Cloud virtual machine instance or persistent disk is a zonal resource, while a static IP address is a regional resource. Google adds the concept of clusters—clusters are groups of physical computers inside a physical data center, with independent power, cooling, networking, and security infrastructure. This allows Google Compute Engine to balance customer resources across clusters in the same zone, while retaining high connectivity between the physical machines in each cluster. ### AWS CloudFormation Amazon Web Services (AWS) CloudFormation is a service that helps you automate the process of creating and managing infrastructure resources in the AWS Cloud. It allows you to use a template to create and provision resources in your AWS account. This template is written in JSON or YAML, and it specifies the resources and their properties that you want to create. CloudFormation allows you to create, update, and delete resources in a predictable and automated way. It helps you standardize and automate the way you create and manage resources, making it easier to manage and maintain your infrastructure. CloudFormation also provides versioning for your templates, so you can track changes to your infrastructure over time. You can use CloudFormation to create and manage resources such as Amazon [EC2 instances](https://spot.io/blog/aws-spotinst-workload-automation-on-ec2-spot-instances/), Amazon S3 buckets, and Amazon Virtual Private Clouds (VPCs). You can also use CloudFormation to create custom resources, using AWS Lambda functions or other AWS services. ***Learn more in the in-depth guide to:***[***AWS CloudFormation.***](https://faddom.com/aws-cloudformation/) **Related product offering:** [Faddom | Instant Application Dependency Mapping Tool​](https://faddom.com/) **Related technology updates:** [[Announcement] AWS Well Architected Reviews with CloudCheckr ](https://spot.io/blog/aws-well-architected-reviews-made-easy-with-cloudcheckr/) ### AWS IaaS Services #### Amazon S3 Amazon Simple Storage Service (S3) is the first and most popular Amazon service, which provides object storage at unlimited scale. S3 is easy to access via the Internet and programmatically via API, and is integrated into a wide range of applications. It provides 11 9’s of durability (99.999999999%), and offers several storage tiers, allowing users to move data that is used less frequently into a low-cost archive tier within S3. #### AWS EC2 Amazon Elastic Compute Cloud (Amazon EC2) offers scalable computing resources. It lets you run as many virtual servers as you want, configure your network and security, and manage storage. You can increase or decrease resources on-demand according to changing business requirements, and set up auto scaling to scale resources up and down according to actual workloads. #### AWS EBS Amazon Elastic Block Store (Amazon EBS) is a block-level storage service for use with Amazon EC2 instances. When mounted on an Amazon EC2 instance, you can use Amazon EBS volumes like any other raw block storage device. It can be formatted and mirrored for specific file systems, host operating systems, and applications. #### AWS EFS Amazon Elastic File System (Amazon EFS) provides a simple, scalable, and fully managed elastic NFS file system for use with AWS cloud services and on-premises resources. It can support up to petabytes of data, automatically scaling as files are added and removed, eliminating the need to configure and manage storage capacity. #### AWS EMR Amazon Elastic MapReduce (EMR) is a cloud-based big data platform for processing vast amounts of data using common open-source tools such as Apache Spark, HBase, Presto, and Flink. EMR is used for data analysis, machine learning, financial analysis, scientific simulation, and bioinformatics. Customers can create EMR clusters using large or small instances depending on their compute and memory requirements. EMR integrates with AWS data stores such as Amazon S3 and DynamoDB, allowing you to analyze and visualize your data with business intelligence tools. #### AWS Lambda AWS Lambda is a serverless, on-demand IT service that provides developers with a fully managed, event-driven cloud system that executes code. AWS Lambda uses Lambda functions—anonymous functions that are not associated with identifiers—enabling users to package any code into a function and run it, independently of other infrastructure. #### AWS FSx Amazon FSx is a fully-managed service that lets you launch, run, and scale high-performance file systems in the AWS cloud. AWS handles management tasks such as hardware provisioning, backups, and patching. The underlying infrastructure powering this service consists of the latest AWS networking, compute, and disk technologies. AWS FSx offers various capabilities delivered as a reliable, secure, and scalable cloud service that achieves high performance and lower TCO. The service lets you choose a file system to support your storage, including NetApp ONTAP, Lustre, and Windows File Server. FSx provides full access to all feature sets, data management capabilities, and performance profiles. #### AWS ECS AWS Elastic Container Service (ECS) is a highly scalable, high-performance container orchestration service that supports Docker containers and allows you to easily run and scale containerized applications on AWS. ECS eliminates the need for you to install, operate, and scale your own cluster management infrastructure. With simple API calls, you can launch and stop Docker-enabled applications, query the complete state of your application, and access many familiar features like security groups, Elastic Load Balancing, EBS volumes, and IAM roles. ECS can be used in conjunction with AWS Fargate, a compute engine for Amazon ECS that allows you to run containers without having to manage servers or clusters. With AWS Fargate, you no longer have to provision, configure, and scale clusters of virtual machines to run containers. This removes the need to choose server types, decide when to scale your clusters, or optimize cluster packing. #### AWS Fargate AWS Fargate is a serverless compute engine for containers that works with both Amazon Elastic Container Service (ECS) and Amazon Elastic Kubernetes Service (EKS). Fargate enables you to focus on building and deploying applications without the complexity of managing the underlying infrastructure. It allocates the right amount of compute, eliminating the need to choose instances and scale cluster capacity. Fargate is designed for applications that require a balance of compute, memory, and networking resources and integrates with AWS services to provide a secure and efficient container execution environment. Pricing is based on the actual compute and memory resources used by the containerized application, offering a pay-as-you-go model that can lead to cost savings. However, in general Fargate is more expensive compared to EC2, for the same computing capacity. #### AWS EKS AWS Elastic Kubernetes Service (EKS) is a managed service that makes it easier for users to run Kubernetes on AWS without needing to install, operate, and maintain their Kubernetes control plane or nodes. Kubernetes is an open-source system for automating deployment, scaling, and management of containerized applications. EKS runs the Kubernetes management infrastructure across multiple AWS availability zones, automatically detecting and replacing unhealthy control plane nodes, and providing on-demand, zero-downtime upgrades and patching. #### AWS Bedrock AWS Bedrock is a fully managed service that allows developers to build and scale generative AI applications using foundation models from various AI providers. It eliminates the need to manage underlying infrastructure and provides seamless integration with AWS services. Bedrock supports multiple foundation models, enabling users to choose the best model for their use case, whether for text generation, image creation, or chatbot applications. It also offers fine-tuning capabilities and responsible AI tools to help businesses deploy AI solutions securely and ethically. ***Learn more in the in-depth guide to***[***AWS Bedrock***](https://umbrellacost.com/blog/aws-bedrock/) **Related product offering:** [Anodot | Intelligent Cost Optimization Platform](https://umbrellacost.com/) **Related technology updates: ** - [[Blog] State of Cloud Cost Report 2024 ](https://umbrellacost.com/blog/summary-report-mastering-cloud-cost-optimization-in-2024/) #### AWS Secrets Manager AWS Secrets Manager is a managed service that helps you securely store, manage, and retrieve sensitive information such as database credentials, API keys, and other secrets. It eliminates the need for hardcoding secrets in application code by providing automatic retrieval and rotation. Secrets Manager integrates with AWS Identity and Access Management (IAM) and AWS Key Management Service (KMS) to enforce security best practices. It also provides audit logs via AWS CloudTrail, helping organizations meet compliance requirements. ***Learn more in the in-depth guide to***[***AWS Secrets Manager***](https://configu.com/blog/aws-secret-manager-features-pricing-limitations-alternatives/) **Related product offering:** [Configu: Configuration Management Platform | Configuration-as-Code Automation for Secure Collaboration](https://configu.com/) **Related technology update:** [[Blog] The state of config file formats: XML vs. YAML vs. JSON vs. HCL](https://octopus.com/blog/state-of-config-file-formats) #### AWS SNS Amazon Simple Notification Service (SNS) is a fully managed messaging service that enables the delivery of notifications between distributed systems, microservices, and applications. It supports multiple messaging protocols, including SMS, email, HTTP/S, and AWS Lambda. SNS allows developers to implement pub/sub messaging architectures, where messages are published to topics and then distributed to multiple subscribers. It integrates with AWS services like SQS and CloudWatch, enabling event-driven architectures at scale. #### AWS CloudWatch Amazon CloudWatch is a monitoring and observability service that provides real-time insights into AWS resources, applications, and services. It collects and analyzes metrics, logs, and events, helping users detect anomalies, troubleshoot issues, and optimize performance. CloudWatch includes features like alarms, dashboards, and automated actions. It integrates with AWS Lambda, EC2, ECS, and other services to enable proactive monitoring and automated responses to infrastructure events. #### AWS Auto Scaling AWS Auto Scaling monitors your applications and automatically adjusts capacity to maintain steady, predictable performance at the lowest possible cost. It provides a powerful interface that lets you build scaling plans for resources including Amazon EC2 instances and Spot Fleets, Amazon ECS tasks, Amazon DynamoDB tables and indexes, and Amazon Aurora Replicas. AWS Auto Scaling lets you optimize costs and improve performance. It makes it possible to set scaling policies and set scaling targets manually, or have these created automatically based on an analysis of application loads. ***Learn more in the in-depth guide to***[***AWS autoscaling***](https://spot.io/resources/aws-autoscaling/scaling-ec2-ecs-rds-and-more/) **Related product offering:** [**Spot Elastigroup | Spot Instance Automation**](https://spot.io/product/elastigroup/)** ** ***Related technology update:***[*[Blog] Horizontal vs. Vertical Scaling*](https://spot.io/blog/horizontal-vs-vertical-scaling-in-the-cloud/) ### Azure IaaS Services #### Linux Virtual Machines in Azure Traditionally Azure focused on Windows virtual machines, but now has a robust offering for Linux users as well. Azure virtual machines (VMs) are scalable on-demand compute resources provided by Azure. Microsoft Azure supports popular Linux distributions deployed and managed by multiple partners. Linux machine images are available in the Azure Marketplace for the following Linux distributions (more distributions are added on an ongoing basis): - FreeBSD - Red Hat Enterprise - CentOS - SUSE Linux Enterprise - Debian - Ubuntu - CoreOS - RancherOS #### Azure Files Azure Files is a cloud file storage service that provides access to server message block (SMB) file shares. These shares can be configured as part of an Azure storage account. Azure Files enables cloud-based virtual machines and on-premise applications to share files using standard protocols. #### Azure Managed Disk Azure managed disks are block-level storage volumes managed by Azure and used by Azure virtual machines. A managed disk is similar to a physical disk on a local server, but it is virtualized. For managed disks, you only need to specify the disk size and disk type, and provision—Azure does the rest. The available hard drive types are: - Standard hard disks (HDD) - Standard SSD - Premium SSDs - Ultra disks—optimized for sub-millisecond latency #### Azure Blob Storage Azure Blob Storage is Microsoft’s object storage service, similar to Amazon S3. Blob storage is suitable for storing large amounts of unstructured data. Blob storage offers sixteen 9’s of durability, and advanced security features including RBAC, encryption at rest and advanced threat protection. IT also supports lifecycle management and immutable storage (WORM), which can help protect against data loss and threats like Ransomware. #### HPC on Azure Azure provides high performance computing (HPC) resources, which you can deploy purely on the public cloud, or combine with local HPC resources to create a hybrid HPC deployment. Azure provides an HPC head node which is used to schedule jobs and workloads, and a virtual machine scale set, with large numbers of VMs that can be used to run massively parallel workloads. These VMs can include both CPU and GPU hardware, depending on the type of processing required. ***Learn more in the  in-depth guide about***[***HPC on Azure***](https://www.netapp.com/azure/azure-netapp-files/) #### SAP on Azure A large variety of SAP applications can be deployed to Azure, using predefined virtual machines created and certified by SAP. **SAP HANA** You can run the SAP HANA in-memory database on Azure, using M-series VMs that scale up to 4TB memory, certified for use with SAP HANA. Another option is Mv2 VMs, the largest SAP HANA certified VMs in the public cloud, with 6TB of memory. Azure offers a service level agreement (SLA) of 99.99% for instances in high availability pairs, and 99.9% for standalone instances. **SAP S/4HANA** You can deploy SAP S/4HANA on Azure, with remote connection via Azure ExpressRoute for Fiori applications. Azure provides an SLA of 99.99% SLA if you run S/4HANA in two Azure availability zones. It also provides backup and recovery in second, even for databases with multiple TBs of data. #### VDI on Azure Microsoft Virtual Desktop Infrastructure (VDI) offers multi-tenant support for Windows 10 and a Windows Virtual Desktop license. Azure provides the FSLogix configuration file container, which decouples user configuration files from the underlying operating system. Azure recently launched MSIX AppAttach, which allows you to package a Win32 application in an MSIX application container. ### Google Cloud IaaS Services #### Google Cloud Storage Google Cloud Storage is an object storage service by Google Cloud. It provides features like object versioning and extended permissions (per item or bucket). Google Cloud offers two archive storage tiers with lower pricing and fast retrieval times, called Nearline and Coldline. #### Google Cloud Filestore Google Cloud Filestore uses NFS version 3 and is designed for workloads requiring low latency and minimal performance fluctuations. This service has two levels of performance: standard and premium. The premium tier can support very high performance—700 Mbps for reads, 350 Mbps for writes, and a maximum of IOPS of 30,000. #### Google Persistent Disk In Google Cloud, a Persistent Disk is a storage device that you can access from a virtual machine, like a physical hard drive. The data is spread across multiple physical hard drives in the Google data center. Google Compute Engine manages the distribution of data for optimal redundancy and performance. ## Adopting IaaS: Cloud Migration Strategies Following are the most common approaches to cloud migration, taken from the influential “[5 Rs](https://www.gartner.com/en/documents/1485116/migrating-applications-to-the-cloud-rehost-refactor-revi)” model proposed by Gartner. ### Rehosting Re-hosting (also known as “lift and shift”) is the fastest way to move your application to the cloud. This is usually the first approach taken in a cloud migration project because it allows moving the application to the cloud without any changes. Both physical and virtual servers are migrated to infrastructure as a service (IaaS). Lift and shift is commonly used to improve performance and reliability for legacy applications. ### Replatforming, Refactoring, or Re-architecture This migration strategy involves detailed planning and a high investment, but it is the only strategy that can help you get the most out of the cloud. Applications that undergo replatforming or re-architecture are completely rebuilt on cloud-native infrastructure. They scale up and down on-demand, are portable between cloud resources and even between different cloud providers. ### Repurchasing In most cases, repurchasing is as easy as moving from an on-premise application to a SaaS platform. Typical examples are switching from internal CRM to Salesforce.com, or switching from internal email server to Google’s G Suite. It is a simple license change, which can reduce labor, maintenance, and storage costs for the organization. ### Retire When planning a move to the cloud, it often turns out that part of the company’s IT product portfolio is no longer useful and can be decommissioned. Removing old applications allows you to focus time and budget on high priority applications and improve overall productivity. ### Retain Moving to the cloud doesn’t make sense for all applications. You need a strong business model to justify migration costs and downtime. Additionally, some industries require strict compliance with laws that prevent data migration to the cloud. Some on-premises solutions should be kept on-premises, and can be supported in a hybrid cloud migration model. Now that we’ve covered some of the general strategies for migrating workloads to the cloud, let’s dive deeper into specific best practices for migrating to each of the big three cloud providers: AWS, Azure, and Google Cloud ## AWS Migration Best Practices ### Leverage AWS Tools AWS offers a wide range of tools designed for the migration process, from the initial planning phase to features for post-migration. Here are several useful tools to consider: - AWS Migration Hub – a dashboard that centralizes data and helps you monitor and track the progress of migration. - AWS Application Discovery – collects data needed for pre-migration due diligence. - TSO Logic – offers data-driven recommendations based on predictive analytics. The recommendations are tailored to help during the planning and strategizing phase. - AWS Server Migration Service – provides automation, scheduling, and tracking capabilities for incremental migrations. - AWS Database Migration Service – keeps the source data store fully-operational while the migration is in process, to minimize downtime. Amazon S3 Transfer Acceleration – improves the speed of data transfers made to Amazon S3, to maximize available bandwidth. ### Automate Repetitive Tasks The migration process typically involves many repetitive tasks. You can perform these tasks manually, and you can automate them. The main purpose of automation is to enable you to achieve a higher level of efficiency while reducing costs. In many cases, automation can also help you complete tasks much faster than manually possible. ### Outline and Share a Clear Cloud Governance Model A cloud governance model defines and specifies the practices, roles, responsibilities, tools, and procedures involved in the governance of your cloud environments. Your model needs to be as clear as possible, to ensure all relevant stakeholders understand how cloud resources should be managed and used. Ideally, you should define this information before migrating. Here are several questions your cloud governance model should answer: - What controls are set in place to meet security and privacy requirements? - How many AWS accounts are maintained? - What privileges are enabled for each role? There are many more considerations to address in your cloud governance model, depending on your industry and business needs. Be sure to keep your documentation flexible to allow for change and optimization after the migration process is completed and your workloads settle in the new cloud environment. ## Azure Migration Best Practices ### Azure Migration Tools Azure offers several migration tools designed to simplify and automate the migration process. Here are three commonly used Azure migration tools: - Azure Migrate—helps you to assess your local workloads, determine the required size of cloud resources, and estimate cloud costs. - Microsoft Assessment and Planning—helps you discover your servers and applications and build an inventory. Additionally, this tool can create reports that determine whether Azure can support your workloads. - Azure Database Migration Service—helps you migrate on-premise SQL Server workloads to Azure. ### Cost Management in Azure Cloud resources are highly accessible and flexible, but costs can quickly skyrocket if you don’t have a cost management strategy in place. Here are several tools and techniques you can use to manage your cloud costs: - Tag your resources – to manage costs, you need visibility into cloud resource consumption. You can set this up by tagging resources and monitoring them. Be sure to use standard tags and keep this organized. - Use policies – to automate tagging and monitoring. Cloud resources are highly scalable and this can make manual tagging and monitoring incredibly time consuming. Use policies to standardize the process and automation to enforce these rules. You can leverage either third-party and first-party tools for tagging. There are also tools dedicated to cost management and optimization and monitoring. In addition, you can set up role-based access control (RBAC) to ensure resources are properly used by authorized users, and set up several resource groups. ### Review Every Policy and Procedure Policies and procedures are a foundational component of the migration process and heavily impact the success of the implementation. To ensure your migration runs smoothly, you should define and review all policies and then apply them in a cohesive and standardized manner. Properly implementing security can ensure all required security measures are set in place. Policies are not only responsible for enforcing security, but also help you achieve and maintain compliance. Data encryption, for example, is a component you can enforce using a policy. Once you define your policies and procedures, you should test them before running in production. You can automate this process using several tools. Azure Migrate, for example, can help you automatically identify, assess, and migrate your local VMs to the Azure cloud. ## Google Cloud Migration Best Practices ### Moving Data Here are several aspects to consider when migrating to Google Cloud: - Move your data first – and then move the rest of the application. This is recommended by Google. - Choose the relevant storage – Google Cloud offers several tiers for hot and warm storage, as well as several archiving options. You can also leverage SSDs and hard discks, or choose a cloud-based database service, such as Bigtable, Datastore, and Google Cloud SQL. - Plan the data transfer process – determine and define how to physically move your data. You can, for example, send your offline disk to a Google data center or opt to stream to persistent disks. ### Moving Applications There are several ways to migrate applications, depending on the application’s suitability to the cloud. In some cases, you might need to re-architect the entire application before it can be moved to the cloud. In other cases, you might need to do light modification before the migration. Ideally, when possible, your application can be lifted and shifted to the cloud. A lift and shift migration means you do not need to make any changes to your application. You can lift it and move it directly to the new cloud environment. For example, you can create a local VM within your on-premise center, and then import it as a Google VM. Alternatively, you can backup your application to GCP – this option lets you automatically create a cloud copy. ### Optimize After the migration process is complete and your application is safely hosted in the cloud, you need to set up measures that help you continuously optimize your cloud environment. Here are several tools offered by Google: - Google Cloud operations suite (Stackdriver) – provides features that enable full observability into your Google cloud environment. The information is centralized in a single database that lets you run queries and leverage root-cause analysis to gain detailed insights. - Google Cloud Pub/Sub – helps you set up communication between any independent applications. You can use Pub/Sub to rapidly scale, decouple applications, and improve performance. - Google Cloud Deployment Manager – lets you automate the configuration of your applications. You specify the requirements and Deployment Manager automatically initiates the deployments. ## Running Mission Critical Applications in the Cloud A mission-critical application relies on continuous availability and cannot undergo even a brief downtime. This can lead to financial, reputational, and operational damages to an entire business or a segment. When provisioning a mission critical application, you need to ensure stability and availability at all times. You can achieve this by creating redundant copies of your application and hot backups. Additionally, you can duplicate your production and staging environments and test them. **Large enterprises typically use the following three types of mission critical applications:** - Backup and disaster recovery – strategies are critical to ensure business continuity.  Your recovery strategy should provide a short recovery time objective (RTO) and minimize the recovery point objective (RPO). - Enterprise Resource Planning (ERP) – systems manage business processes, providing capabilities to manage finances, manufacturing, distribution, the supply chain, human resources, and more. ERPs must remain operational at all times. - Virtual Desktop Infrastructure (VDI) – solutions help you remotely deliver a desktop image to endpoint devices via an Internet network. VDI technology enables users to access mission critical applications on their smartphones, laptops, and other thin-client devices. Traditionally, mission-critical applications are hosted on-premises, but today many of these applications are moving to cloud environments. The cloud can provide enterprises with a high level of flexibility and scalability. Ideally, if cloud resources are properly utilized and optimized, enterprises can significantly reduce their costs by moving to the cloud. There are, however, several challenges enterprises face when migrating their mission-critical applications to the cloud. The migration process is a major challenge for many enterprises. The process itself can take time, for one, and comes with a unique set of risks. For many enterprises, security and compliance are critical and must be maintained at all times. The cost of migration and unforeseen overhead can also run high. However, it is possible to address these challenges. To successfully migrate mission critical applications, enterprises can leverage techniques and solutions designed for the migration process. Planning the migration is especially helpful to minimize overhead and ensure known challenges are addressed in advance. ## Deep Learning in the Cloud Deep learning is at the center of most artificial intelligence (AI) initiatives. It is based on the concept of a deep neural network, which passes inputs through multiple layers of connections. Neural networks can perform many complex cognitive tasks, improving performance dramatically compared to traditional machine learning algorithms. However, they often require huge data volumes to train and can be very computationally intensive. Deep learning is often a time-consuming and costly endeavor, especially regarding training models. Many factors can impact the process, but processing power is critical to ensure the pipeline works effectively. Graphics processing units (GPUs) provide the processing power needed for computationally intensive operations, but setting this up is not affordable for all organizations. Cloud computing vendors provide various services to help make deep learning more affordable and accessible. Services may vary between vendors, but most can help you manage large datasets and train algorithms on distributed hardware. Here are notable offerings from the top cloud vendors – Amazon Web Services (AWS), Microsoft Azure, and Google Cloud: ### AWS AWS provides four instance options, available in multiple sizes. These include EC2 P2, P3, G3, and G4 instances. With these instances, you can choose to access NVIDIA Tesla M60, T4 Tensor, K80, or V100 GPUs and can include up to 16 GPUs per instance. With AWS, you also have the option of using Amazon Elastic Graphics. This service enables you to connect your EC2 instances to various low-cost GPUs. You can attach GPUs to any instance compatible for greater workload flexibility. The Elastic Graphics service also provides up to 8GB of memory and supports OpenGL 4.3. ### Azure Azure provides several choices for GPU-based instances. These instances are designed for high computation tasks, including deep learning, simulations, and visualizations. In Azure, you can choose from three instance series: - NC-series—optimized for compute and network-intensive workloads. These instances can support OpenCL and CUDA-based applications and simulations. Available GPUs include NVIDIA Tesla V100, Intel Broadwell, and Intel HaswellGPUs. - NV-series—optimized for visualizations, encoding, streaming and virtual desktop infrastructures (VDI). These instances support OpenGL and DirectX. Available GPUs include AMD Radeon Instinct MI25 and NVIDIA Tesla M60 GPUs. - ND-series—optimized for deep learning training scenarios and inference. Available GPUs include NVIDIA Tesla P40, Intel Skylake, and Intel Broadwell GPUs. ### Google Cloud Although Google Cloud doesn’t offer dedicated instances with GPUs, it does enable you to connect GPUs to existing instances. This works with standard instances and Google Kubernetes Engine (GKE) instances. It also enables you to deploy node pools, including GPUs. Support is available for NVIDIA Tesla V100, P4, T4, K80, and P100 GPUs. Another option in Google Cloud is access to TensorFlow processing units (TPUs). These units are made of multiple GPUs. TPUs are designed to perform matrix multiplication quickly and can provide performance similar to Tensor Core enabled Tesla V100 instances. Currently, PyTorch provides partial support for TPUs. ## Kubernetes in the Cloud ### Kubernetes on AWS Kubernetes lets you use existing on-premises and cloud-based tools to run containerized applications. It can manage clusters of AWS EC2 instances, deploying, running, maintaining, and scaling containers on EC2 instances. AWS helps you easily manage Kubernetes infrastructure with Amazon EC2 or employ Amazon EKS for automatic provisioning and management. You can also leverage community-backed integrations to AWS services, such as IAM, VPC, and service discovery. ### Kubernetes on Azure Azure Kubernetes Service (AKS) enables you to deploy a managed Kubernetes cluster in the Azure cloud. AKS is a hosted Kubernetes service that reduces the operational overhead and complexity of managing Kubernetes by managing these responsibilities. Azure handles health monitoring and maintenance and manages Kubernetes masters, so you can focus on managing and maintaining agent nodes. ### Kubernetes on Google Cloud Google Kubernetes Engine (GKE) is an orchestration system for Docker containers and container clusters running in Google’s public cloud. It is based on Kubernetes, which Google originally developed for container management. You can use the gcloud CLI or the Google Cloud Platform Console to interact with this service. GKE employs a group of instances to run Kubernetes. It allocates a master node to manage a cluster of Docker containers and runs a Kubernetes API server that interacts with the cluster and performs various tasks, including scheduling containers. A cluster may also include one or more additional nodes that run a Docker runtime and kubelet agent to manage containers. ## See Additional Guides on IaaS Topics ### [What Is Cloud Hosting](https://www.atlantic.net/vps-hosting/what-is-cloud-hosting/) **Related guides** *Authored by Atlantic.Net * - [What Is Cloud Hosting?](https://www.atlantic.net/vps-hosting/what-is-cloud-hosting/) - [What Is a DNS? Complete Domain Name System Guide](https://www.atlantic.net/vps-hosting/what-is-dns-and-how-does-it-work/) - [What is VMware? ](https://www.atlantic.net/dedicated-server-hosting/what-is-vmware/) **Related product offering:** [**Atlantic.Net Dedicated Server Hosting | High Performance Dedicated Servers**](https://www.atlantic.net/dedicated-server-hosting/) *Offered by Atlantic.Net* - [Managed Private Cloud Hosting](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/) - [Atlantic.Net Orlando Colocation Data Center](https://www.atlantic.net/orlando-colocation-hosting-data-center/) - [Server Management Services](https://www.atlantic.net/managed-services/server-management/) **Related technology updates:** - [[Blog] What Is the Difference Between a Dedicated Server and a Dedicated Cloud Host? ](https://www.atlantic.net/dedicated-server-hosting/what-is-the-difference-between-a-dedicated-server-and-a-dedicated-cloud-host/) ### [What Is Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/) **Related guides** *Authored by Atlantic.Net* - [What Is Dedicated Server Hosting: Benefits, Types, and Costs](https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/) - [GPU Dedicated Server Hosting: A Buyer’s Guide](https://www.atlantic.net/gpu-server-hosting/gpu-dedicated-server-hosting-a-buyers-guide/) **Related product offering:** [**Atlantic.Net Dedicated Server Hosting | High Performance Dedicated Servers**](https://www.atlantic.net/dedicated-server-hosting/) *Offered by Atlantic.Net* - [USA Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/) - [Bare Metal Server Hosting](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) - [Dedicated Hosts ](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) **Related technology updates:** - [[Blog] How to Secure SSH Server on Arch Linux ](https://www.atlantic.net/dedicated-server-hosting/how-to-secure-ssh-server-on-arch-linux/) - [[Blog] 9 Essential Features of Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/9-essential-features-of-dedicated-server-hosting/) ### [Hybrid Cloud](https://faddom.com/hybrid-cloud-architecture-use-cases-and-5-critical-best-practices/) **Related guides** *Authored by Faddom* - [Hybrid Cloud: Architecture, Use Cases & 5 Critical Best Practices](https://faddom.com/hybrid-cloud-architecture-use-cases-and-5-critical-best-practices/) - [Hybrid Cloud Architecture: Is It Right for Your Business?](https://faddom.com/hybrid-cloud-architecture/) - [Hybrid Cloud with AWS: 5 Tools and a Reference Architecture](https://faddom.com/hybrid-cloud-with-aws-5-tools-and-a-reference-architecture/) **Related product offering:** [Faddom | Instant Application Dependency Mapping Tool​](https://faddom.com/) **Related technology updates:** [[Report] Optimizing in a Multi-Cloud World ](https://spot.io/blog/research-optimize-multi-cloud-infrastructure/) ### [Infrastructure as Code](https://codefresh.io/learn/infrastructure-as-code/) **Related guides** *Authored by Codefresh* - [Infrastructure as Code: Benefits, Platforms & Tips for Success](https://codefresh.io/learn/infrastructure-as-code/) - [Infrastructure as Code on AWS: Process, Tools & Best Practices](https://codefresh.io/learn/infrastructure-as-code/infrastructure-as-code-on-aws-process-tools-and-best-practices/) - [Why You Need Immutable Infrastructure and 4 Tips for Success ](https://codefresh.io/learn/infrastructure-as-code/why-you-need-immutable-infrastructure-and-4-tips-for-success/) **Related product offering:** [GitOps Software Delivery Platform](https://codefresh.io/) *Offered by Codefresh* - [*CI/CD Platform with GitOps*](https://codefresh.io/product/gitops/) - [Enterprise Support for Argo ](https://codefresh.io/enterprise-argo-support/) - [Secure Distribution for Argo CD and Argo Rollouts ](https://codefresh.io/secure-distribution-for-argo/) **Related technology update:** [[Blog] How to Model Your GitOps Environments and Promote Releases between Them ](https://codefresh.io/blog/how-to-model-your-gitops-environments-and-promote-releases-between-them/) ### [Load Balancer](https://www.radware.com/cyberpedia/application-delivery/what-is-load-balancing/) **Related guides** *Authored by Radware* - [What is a Load Balancer? History, Key Functions, Pros and Cons ](https://www.radware.com/cyberpedia/application-delivery/what-is-load-balancing/) - [What is Global Server Load Balancing (GSLB)? ](https://www.radware.com/cyberpedia/application-delivery/what-is-global-server-load-balancing-gslb/) **Related product offering:** [Application Delivery and Security](https://www.radware.com/products/alteon/) *Offered by Radware* - [Application Delivery For Hybrid Environments ](https://www.radware.com/solutions/adc-hybrid-environments/) - [SSL Inspection, Offloading and Acceleration](https://www.radware.com/solutions/ssl-inspection/) ### [AWS Cloudformation](https://faddom.com/aws-cloudformation/) **Related guides** *Authored by Faddom* - [AWS CloudFormation Beginners Guide](https://faddom.com/aws-cloudformation/) - [Creating a custom resource in AWS CloudFormation ](https://faddom.com/creating-a-custom-resource-in-aws-cloudformation/) **Related product offering:** [Instant Application Dependency Mapping Tool​](https://faddom.com/) *Offered by Faddom* - [Asset Documentation & Discovery ](https://faddom.com/use-case/asset-documentation-and-discovery/) - [Application Change Management](https://faddom.com/use-case/application-change-management/) - [Data Center Migration](https://faddom.com/use-case/data-center-migration/) **Related technology updates:** [[Announcement] AWS Well Architected Reviews with CloudCheckr ](https://spot.io/blog/aws-well-architected-reviews-made-easy-with-cloudcheckr/) ### [Cloud Computing Costs](https://faddom.com/cloud-computing-costs-and-pricing-comparison/) **Related guides** *Authored by Faddom* - [AWS EC2 Pricing: A Beginners Guide ](https://faddom.com/the-beginners-guide-to-aws-ec2-pricing/) - [Azure VMs Pricing Beginners Guide ](https://faddom.com/azure-vms-pricing/) - [Cloud Computing Costs & Pricing Comparison for 2023](https://faddom.com/cloud-computing-costs-and-pricing-comparison/) **Related product offering:** [Instant Application Dependency Mapping Tool​](https://faddom.com/) *Offered by Faddom* - [Resource and Cost Optimization ](https://faddom.com/use-case/resource-and-cost-optimization/) - [Network Security ](https://faddom.com/use-case/network-security/) - [Compliance and IT Audit](https://faddom.com/use-case/it-audit-and-compliance/) **Related technology updates:** [[Report] GigaOm 2024 Radar for Cloud Resource Optimization](https://spot.io/blog/spot-gigaom-radar-cloud-resource-optimization-third-year/) ### [Cloud Cost Management](https://www.finout.io/blog/why-cloud-cost-management-5-tools-to-know-and-tips-for-success) **Related guides** *Authored by Finout* - [Why Cloud Cost Management, 5 Tools to Know, and Tips for Success](https://www.finout.io/blog/why-cloud-cost-management-5-tools-to-know-and-tips-for-success) - [What Is IT Financial Management (ITFM) and 5 Steps to Adoption](https://www.finout.io/blog/what-is-it-financial-management) - [Cloud Storage Pricing – Updated for 2025](https://www.finout.io/blog/cloud-storage-pricing-comparison) **Related product offering:** [Enterprise-Grade FinOps Platform](https://www.finout.io/) *Offered by Finout* - [Cloud Cost Anomaly Detection Tools ](https://www.finout.io/anomaly-detection) - [Dashboards & Reporting](https://www.finout.io/custom-dashboard) - [How to manage AI cloud spend ](https://www.finout.io/artificial-intelligence) **Related technology updates: ** - [[Webinar] Driving a Successful Company-Wide FinOps Cultural Change ](https://www.finout.io/blog/driving-a-successful-company-wide-finops-cultural-change) - [[Webinar] Mastering Kubernetes Spend-Efficiency ](https://www.finout.io/blog/mastering-kubernetes-spend-efficiency) ### [FinOps](https://www.finout.io/blog/finops-guide) **Related guides** *Authored by Finout* - [Cloud FinOps: Ultimate Guide to Principles, Tools & Practices](https://www.finout.io/blog/finops-guide) - [AWS FinOps: Why, How, and 6 Tools to Get You Started](https://www.finout.io/blog/aws-finops-why-how-and-6-tools-to-get-you-started) - [FinOps: Principles and Lifecycle Guide](https://www.finout.io/blog/main-principles-of-finops) **Related product offering:** [Enterprise-Grade FinOps Platform](https://www.finout.io/) *Offered by Finout* - [Oracle | Integration](https://www.finout.io/oracle-integration) - [Snowflake Cost Optimization & Cost Management Tool ](https://www.finout.io/finout-snowflake-solution) - [Datadog Cloud Cost Management & Cost Optimization Tool ](https://www.finout.io/finouts-datadog-integration) ### [AWS Cost Optimization](https://www.finout.io/blog/aws-cost-optimization-6-free-tools-10-hacks-to-cut-aws-bills) **Related guides** *Authored by Finout* - [AWS Cost Optimization: 6 Free Tools & 10 Hacks to Cut AWS Bills](https://www.finout.io/blog/aws-cost-optimization-6-free-tools-10-hacks-to-cut-aws-bills) - [What Are AWS Spot Instances, Pros/Cons, and 6 Ways to Save Even More](https://www.finout.io/blog/aws-spot-instances) - [Top 5 Free & Open Source AWS Cost Optimization Tools](https://www.finout.io/blog/free-and-open-source-aws-cost-monitoring-tools) **Related product offering:** [Enterprise-Grade FinOps Platform](https://www.finout.io/) *Offered by Finout* - [Finout’s Patented Instant Virtual Tagging](https://www.finout.io/virtual-tagging) - [Financial Planning](https://www.finout.io/financial-planning) - [Track and Control Cloud Costs waste ](https://www.finout.io/costguard) **Related technology update:** [[Webinar] How To Create a Cost-Effective AWS Environment](https://www.finout.io/blog/how-to-create-a-cost-effective-aws-environment) ### [CloudHealth](https://www.finout.io/blog/vmware-cloudhealth-overview) **Related guides** *Authored by Finout* - [VMware CloudHealth: Solution Overview, Pros/Cons & Alternatives](https://www.finout.io/blog/vmware-cloudhealth-overview) - [CloudHealth Pricing Tiers and Contract Structure Explained](https://www.finout.io/blog/cloudhealth-pricing-tiers-and-contract-structure-explained) - [CloudHealth Competitors to Watch in 2025](https://www.finout.io/blog/cloudhealth-competitors) **Related product offering:** [Enterprise-Grade FinOps Platform](https://www.finout.io/) *Offered by Finout* - [Databricks Cost Optimization & Cost Management Tool](https://www.finout.io/finout-databricks-solution) - [Kubernetes Cost Monitoring & Management Tool: K8s Cost Reduction ](https://www.finout.io/kubernetes-waste-detection) ### [Digital Asset Management](https://cloudinary.com/guides/digital-asset-management/what-is-digital-asset-management) **Related guides** *Authored by Cloudinary* - [Digital Asset Management (DAM) Users, Features, and Benefits](https://cloudinary.com/guides/digital-asset-management/what-is-digital-asset-management) - [Reimaging DAM: The next-generation solution for marketing & development](https://cloudinary.com/blog/reimaging_dam_the_next_generation_solution_for_marketing_development) - [MAM vs ECM: What’s the Difference?](https://cloudinary.com/guides/digital-asset-management/media-asset-management-and-enterprise-content-management-whats-the-difference) **Related product offering:** [Cloudinary Assets | AI-Powered Digital Asset Management](https://cloudinary.com/products/digital_asset_management) **Related technology update:** [[Blog] New for DAM: Media Library Extension for Chrome ](https://cloudinary.com/blog/new_for_dam_media_library_extension_for_chrome) [[Blog] Best Image Optimization Techniques: Expert Roundup](https://cloudinary.com/blog/image_optimization_expert_roundup) ### [Virtual Private Cloud](https://www.atlantic.net/cloud-platform/virtual-private-cloud/) **Related guides** *Authored by Atlantic.Net* - [Virtual Private Cloud Servers by Atlantic.Net](https://www.atlantic.net/cloud-platform/virtual-private-cloud/) - [Virtual Private Cloud Server: Clearing the Confusion](https://www.atlantic.net/vps-hosting/virtual-private-cloud-server-a-comprehensive-guide/) - [Virtual Private Cloud vs. Private Cloud](https://www.atlantic.net/vps-hosting/virtual-private-cloud-vs-private-cloud/) ### [Elasticache](https://www.dragonflydb.io/guides/amazon-elasticache-pros-cons-tutorial-and-alternatives) **Related guides** *Authored by Dragonfly* - [Amazon ElastiCache: Pros/Cons, Tutorial, and Alternatives in 2026](https://www.dragonflydb.io/guides/amazon-elasticache-pros-cons-tutorial-and-alternatives) - [ElastiCache Pricing – Everything You Need to Know](https://www.dragonflydb.io/guides/elasticache-pricing) - [What You Need to Know About ElastiCache Serverless](https://www.dragonflydb.io/guides/what-you-need-to-know-about-elasticache-serverless) ### [Memorystore](https://www.dragonflydb.io/guides/google-memorystore-architecture-pros-cons-and-best-practices) **Related guides** *Authored by Dragonfly* - [Google Memorystore: Architecture, Pros/Cons and Best Practices](https://www.dragonflydb.io/guides/google-memorystore-architecture-pros-cons-and-best-practices) - [Google Memorystore Redis Pricing – Everything You Need To Know](https://www.dragonflydb.io/guides/google-cloud-redis-pricing) ### [Azure Virtual Desktop](https://www.venn.com/learn/azure-virtual-desktop/) **Related guides** *Authored by Venn* - [Azure Virtual Desktop: Pros/Cons, Pricing & Top 5 Alternatives](https://www.venn.com/learn/azure-virtual-desktop/) - [Azure Virtual Desktop Pricing in 2025 & 7 Ways to Cut Costs](https://www.venn.com/learn/azure-virtual-desktop-pricing/) ### [Citrix VDI](https://www.venn.com/learn/citrix-vdi/) **Related guides** *Authored by Venn* - [Citrix VDI (Citrix DaaS): Key Features, Pros/Cons & Alternatives](https://www.venn.com/learn/citrix-vdi/) - [Citrix VPN Alternative: Citrix Secure Private Access & Competitors](https://www.venn.com/learn/citrix-vdi/citrix-vpn/) - [Citrix Enterprise Browser: Pros/Cons & Top 8 Alternatives in 2025](https://www.venn.com/learn/citrix-enterprise-browser/) ### DaaS **Related guides** *Authored by Venn* - [Top 7 DaaS Solutions and Alternatives in 2026](https://www.venn.com/learn/daas-solutions/) - [Considering DaaS? Top 11 DaaS Best Practices and Considerations](https://www.venn.com/learn/daas-best-practices/) - [Best DaaS Providers and Alternatives: Top 7 in 2026](https://www.venn.com/learn/daas-providers/) **Related product offering:** [Venn | The Secure Workspace for Remote Work](https://www.venn.com/) **Related technology update:** [[Whitepaper] VDI is Dead: A Eulogy](https://www.venn.com/blog/why-vdi-is-dead/) [[Blog] Venn is Changing the Virtual Desktop Game With a Local Alternative ](https://www.venn.com/blog/localzone-is-changing-the-virtual-desktop-game) ### [Learning Management System](https://corp.kaltura.com/blog/learning-management-systems/) **Related guides** *Authored by Kaltura* - [Learning Management Systems (LMS): 6 Key Features and Top Use Cases ](https://corp.kaltura.com/blog/learning-management-systems/) - [Corporate Learning Management System: 11 Solutions to Know in 2025 ](https://corp.kaltura.com/blog/corporate-learning-management-system/) - [Healthcare learning management system: Challenges & best practices ](https://corp.kaltura.com/blog/learning-management-system-healthcare/) ### [AWS Secrets Manager](https://configu.com/blog/aws-secret-manager-features-pricing-limitations-alternatives/) **Related guides** *Authored by Configu* - [AWS Secret Manager: Features, Pricing, Limitations & Alternatives ](https://configu.com/blog/aws-secret-manager-features-pricing-limitations-alternatives/) **Related product offering:** [Configu: Configuration Management Platform | Configuration-as-Code Automation for Secure Collaboration](https://configu.com/) **Related technology update:** [[Blog] The state of config file formats: XML vs. YAML vs. JSON vs. HCL](https://octopus.com/blog/state-of-config-file-formats) ### [AWS Bedrock](https://umbrellacost.com/blog/aws-bedrock/) **Related guides** *Authored by Umbrella* - [Complete 2024 Guide to Amazon Bedrock: AWS Bedrock 101](https://umbrellacost.com/blog/aws-bedrock/) - [AWS Bedrock Pricing: Your 2024 Guide to Amazon Bedrock Costs ](https://umbrellacost.com/blog/aws-bedrock-pricing/) - [AWS Bedrock vs Azure OpenAI – Which Platform Is Best For You ](https://umbrellacost.com/blog/aws-bedrock-vs-openai/) **Related product offering:** [Intelligent Cost Optimization Platform](https://umbrellacost.com/) *Offered by Umbrella* - [Cloud Cost Management and Optimization](https://umbrellacost.com/cloud-cost-management/enterprise/) - [MSP Cloud ](https://umbrellacost.com/cloud-cost-management/msp/) - [Accurate FinOps Forecasting ](https://umbrellacost.com/cloud-cost-management/forecast/) **Related technology updates: ** - [[Blog] State of Cloud Cost Report 2024 ](https://umbrellacost.com/blog/summary-report-mastering-cloud-cost-optimization-in-2024/) ### [Multicloud](https://umbrellacost.com/learning-center/what-is-multicloud-benefits-use-cases-challenges-and-solutions/) **Related guides** *Authored by Umbrella* - [What Is Multicloud? Benefits, Use Cases, Challenges and Solutions ](https://umbrellacost.com/learning-center/what-is-multicloud-benefits-use-cases-challenges-and-solutions/) - [Multicloud Strategy: Pros, Cons, and Tips for Success](https://umbrellacost.com/learning-center/multicloud-strategy/) - [Multicloud Management: How It Works & 5 Critical Best Practices](https://umbrellacost.com/learning-center/multicloud-management/) **Related product offering:** [Intelligent Cost Optimization Platform](https://umbrellacost.com/) *Offered by Umbrella* - [Multicloud Cost Visibility for FinOps ](https://umbrellacost.com/cloud-cost-management/visibility/) - [Boost your cloud efficiency with automated waste detection](https://umbrellacost.com/cloud-cost-management/waste-detector/) - [Detect and resolve cloud cost anomalies in real-time](https://umbrellacost.com/cloud-cost-management/anomaly-detection/) ### [AWS Autoscaling](https://spot.io/resources/aws-autoscaling/scaling-ec2-ecs-rds-and-more/) **Related guides** *Authored by Spot.io* - [AWS Auto Scaling: Scaling EC2, ECS, RDS, and more ](https://spot.io/resources/aws-autoscaling/scaling-ec2-ecs-rds-and-more/) - [EC2 Autoscaling: The Basics, Getting Started & 4 Best Practices](https://spot.io/resources/aws-autoscaling/ec2-autoscaling-the-basics-and-4-best-practices/) - [Understanding EC2 Auto Scaling Groups ](https://spot.io/resources/aws-autoscaling/understanding-ec2-auto-scaling-groups/) **Related product offering:** [**Spot Elastigroup**](https://spot.io/product/elastigroup/)** ** *Offered by Spot.io* - [Elastigroup: Scale mission-critical workloads on spot instances](https://spot.io/solutions/autoscaling-applications/) **Related technology updates:** - [[Blog] Horizontal vs. Vertical Scaling](https://spot.io/blog/horizontal-vs-vertical-scaling-in-the-cloud/) - [[Report] GigaOm 2024 Radar for Cloud Resource Optimization](https://spot.io/blog/spot-gigaom-radar-cloud-resource-optimization-third-year/) ### [Multi Tenant Architecture](https://frontegg.com/guides/multi-tenant-architecture) **Related guides** *Authored by Frontegg* - [Multi-Tenant Architecture: How It Works, Pros, and Cons ](https://frontegg.com/guides/multi-tenant-architecture) - [Multi-Tenancy in Cloud Computing: Basics & 5 Best Practices](https://frontegg.com/guides/multi-tenancy-in-cloud-computing) - [Multi-Tenant vs. Single-Tenant: What Is the Difference?](https://frontegg.com/guides/multi-tenant-vs-single-tenant) ### Additional IaaS Resources - [What Is Cloud Orchestration?](http://www.computer.org/publications/tech-news/trends/what-is-cloud-orchestration) - [4 AWS File Systems Compared](https://plainenglish.io/blog/4-aws-file-systems-compared) - [ECS Vs. Plain Kubernetes: 5 Key Differences and How to Choose](https://cloudnativenow.com/topics/cloudnativedevelopment/ecs-vs-plain-kubernetes-5-key-differences-and-how-to-choose/) - [Benefits of Cloud Migration: Do They Outweigh the Cost?](https://www.computer.org/publications/tech-news/trends/cloud-migration-benefits-cost) - [Cloud Orchestration and its Impact on DevOps Teams](https://devops.com/cloud-orchestration-and-its-impact-on-devops-teams/) - [AWS Fargate pricing: how to optimize billing and save costs](https://spot.io/blog/aws-fargate-pricing-how-to-optimize-billing-and-save-costs/) -  [The Complete Guide to EC2 Instance Pricing](https://spot.io/resources/aws-ec2-pricing/the-complete-guide-to-ec2-instance-pricing/) - [Azure Kubernetes: The Basics and a Quick Tutorial](https://spot.io/blog/azure-kubernetes-the-basics-and-a-quick-tutorial/) - [Moving HPC To The Cloud: A Guide For 2020](http://highscalability.com/blog/2020/9/14/moving-hpc-to-the-cloud-a-guide-for-2020.html) - [Virtualization in Cloud Computing: Behind the Scenes](https://blog.cherryservers.com/virtualization-in-cloud-computing-behind-the-scenes) - [HIPAA Compliance in the Cloud: A Quick Start Guide](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-in-the-cloud-a-quick-start-guide/) - [Azure Encryption Explained](https://www.networkdatapedia.com/post/azure-encryption-explained) - [Understanding Azure Time Series Insights](https://blog.back4app.com/azure-time-series-insights/) - [3 Azure Migration Services and How They Cut Migration Costs](https://cloudtweaks.com/2023/04/azure-how-cut-migration-costs/) - [What Is a Cloud Operations Engineer?](https://devops.com/what-is-a-cloud-operations-engineer/) - [How to Become a Cloud Operations Engineer](https://it.tmcnet.com/topics/it/articles/2023/08/08/456718-how-become-cloud-operations-engineer.htm) - [Cloud Capacity Planning: A Practical Guide ](https://ourcodeworld.com/articles/read/2097/cloud-capacity-planning-a-practical-guide#google_vignette) ### **Which Service to Choose?** Whether choosing an infrastructure or platform as a service model, cloud servers are practical solutions in today’s world of constantly evolving technology. Since 1994, Atlantic.Net has been providing businesses with the best hosting solutions like our super-fast [VPS Hosting.](https://www.atlantic.net/vps-hosting/) To learn more about our cloud server hosting solutions, including[HIPAA compliant hosting,](https://www.atlantic.net/hipaa-compliant-hosting/) give us a call today at 866-618-3282. --- # How to Run Machine Learning Models in Your Browser with TensorFlow.js > URL: https://www.atlantic.net/gpu-server-hosting/how-to-run-machine-learning-models-in-your-browser-with-tensorflow-js/ | Published: 2025-07-16 | Updated: 2025-08-01 | Author: Hitesh Jethva Imagine running advanced machine learning models right inside your web browser—no need for heavy backend servers or complicated deployment pipelines. With TensorFlow.js, you can bring real-time AI features like image classification, object detection, and more directly to users, all with JavaScript. This means your apps can analyze images, predict outcomes, or recognize objects instantly, right in the browser. In this guide, you’ll learn how to build a ReactJS web app that uses TensorFlow.js to classify images. ## Why Use TensorFlow.js in the Browser? Running machine learning models directly in the browser with TensorFlow.js offers some unique advantages. Here are a few popular use cases for running machine learning in the browser: - Image classification (like recognizing objects, animals, or scenes) - Real-time face or pose detection via webcam - Sound recognition and speech commands - Text sentiment analysis or language translation ## Prerequisites - An Ubuntu 24.04 server with an [NVIDIA GPU](https://www.atlantic.net/gpu-server-hosting/an-overview-of-popular-nvidia-gpus/). - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Setting Up Your Server Let’s get your server ready to run a ReactJS app with TensorFlow.js. Follow these steps to update your system and install the necessary tools: 1. Update your package index. ```bash apt update -y ``` 2. Install Node.js and NPM to build and run your ReactJS project. ```bash apt install -y nodejs npm ``` 3. Make sure everything is set up correctly by checking the versions. ```bash node -v npm -v ``` ## Step 2: Create a ReactJS Project With Node.js and npm installed, you can quickly set up a new ReactJS app using the Create React App tool. This will give you a modern, ready-to-use project structure. 1. Create your app using the npx command. ```bash npx create-react-app tfjs-image-demo ``` 2. Navigate into your project directory. ```bash cd tfjs-image-demo ``` ## Step 3: Install TensorFlow.js and Supporting Libraries Now it’s time to add the libraries that make in-browser machine learning possible. 1. Install TensorFlow.js and other tools. ```bash npm install @tensorflow/tfjs @tensorflow-models/mobilenet antd ``` **Explanation:** - **@tensorflow/tfjs** – the TensorFlow.js library - **@tensorflow-models/mobilenet**  – pre-trained MobileNet model - **antd**  – (optional) for better UI components ## Step 4: Build the Image Classifier App Now, let’s add the code that makes everything work. You’ll create an interactive ReactJS app that uses TensorFlow.js and MobileNet to classify images right in the browser. 1. Edit the file **src/App.js.** ```bash nano src/App.js ``` Delete everything in App.js and paste the following code: ```bash import React, { useRef, useState, useEffect } from "react"; import "@tensorflow/tfjs"; import * as mobilenet from "@tensorflow-models/mobilenet"; import { Upload, Button, Tag, Typography } from "antd"; const { Title } = Typography; function App() { const [model, setModel] = useState(null); const [predictions, setPredictions] = useState([]); const canvasRef = useRef(null); // Load MobileNet model on mount useEffect(() => { async function loadModel() { const loadedModel = await mobilenet.load(); setModel(loadedModel); } loadModel(); }, []); // Handle image upload const handleImageChange = async (info) => { const file = info.file.originFileObj; if (!file || !model) return; const img = new window.Image(); img.src = URL.createObjectURL(file); img.onload = async () => { // Draw image to canvas const canvas = canvasRef.current; canvas.width = img.width; canvas.height = img.height; const ctx = canvas.getContext("2d"); ctx.drawImage(img, 0, 0); // Classify image const preds = await model.classify(canvas, 5); setPredictions(preds); }; }; return (
TensorFlow.js Image Classifier Demo {}} onChange={handleImageChange} >
{predictions.map(({ className, probability }) => ( {className.split(",")[0]}: {(probability * 100).toFixed(1)}% ))}
); } export default App; ``` The above code: - Loads the MobileNet model when the app starts. - Lets users upload any image. - Shows the image on a canvas and runs the model to classify it. - Instantly displays predicted labels and confidence scores, right in the browser! ## Step 5: Start the Development Server You’re almost ready to see your app in action! Now, let’s launch the ReactJS development server so you can access your project from your browser. Start the React development server. ```bash npm start -- --host your-server-ip ``` Output. ```bash Compiled successfully! You can now view tfjs-image-demo in the browser. http://localhost:3000 Note that the development build is not optimized. To create a production build, use npm run build. webpack compiled successfully ``` ## Step 6: Test Your Image Classifier in the Browser Now it’s time for testing using your browser-based AI app. 1. Open your browser and go to **http://YOUR_SERVER_IP:3000** 2. Click the **“Upload an Image”** button and choose any photo from your computer. You can try pictures of animals, everyday objects, or anything you like. ![](https://www.atlantic.net/wp-content/uploads/2025/07/p1.png) 3. As soon as you upload the image, the app will display the picture and show prediction tags with labels and confidence scores (like “tabby cat: **99.5%”).** ## Conclusion You’ve just built a modern, browser-based image classifier with TensorFlow.js and ReactJS, right on your Ubuntu 24.04 GPU server. With just a few commands and some simple code, you can now run machine learning models instantly in any web browser, all without sending data to a remote backend. This approach offers privacy, speed, and a seamless user experience. You can expand this project further by adding support for webcam input, testing other pre-trained models, or customizing the UI to fit your needs. --- # Live Face Detection Web App with face-api.js and JavaScript on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/live-face-detection-web-app-with-face-api-js-and-javascript-on-ubuntu-24-04-gpu-server/ | Published: 2025-07-17 | Updated: 2026-05-04 | Author: Hitesh Jethva Live face detection is becoming a core part of many modern web and mobile applications. From security and authentication to creative effects and user analytics, the ability to recognize faces instantly in the browser opens up a world of possibilities. face-api.js is a popular JavaScript library that brings powerful, real-time face detection and recognition to any website—no specialized hardware or backend required. It leverages TensorFlow.js to run deep learning models right in your browser, using your device’s webcam for instant results. In this tutorial, you’ll learn how to build a live face detection web app using face-api.js and vanilla JavaScript. ## Prerequisites - An Ubuntu 24.04 server with an [NVIDIA GPU](https://www.atlantic.net/gpu-server-hosting/top-10-nvidia-gpus-for-ai/). - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Installing Node.js and npm Node.js and npm (Node Package Manager) are essential tools for running and managing JavaScript projects outside the browser. 1. Start by making sure your package list is up to date. ```bash apt update -y ``` 2. Now install Node.js and npm with a single command. ```bash apt install nodejs npm -y ``` 3. After installation, check the versions to confirm everything is set up correctly. ```bash nodejs --version npm --version ``` ## Step 2: Setting Up Your Project and Local Web Server Let’s get your workspace organized, install a simple web server, and grab everything you need to run face detection in the browser. 1. Create a project directory. ```bash mkdir ~/faceapi-ml5js-demo cd ~/faceapi-ml5js-demo ``` 2. Install http-server to load your HTML and JavaScript in the browser. ```bash npm install -g http-server ``` 3. Now, download the face-api.js library and the required model files (weights). ```bash git clone https://github.com/justadudewhohacks/face-api.js.git ``` 4. Copy the weights folder from the cloned repo to your project root. ```bash mv face-api.js/weights . ``` ## Step 3: Creating the HTML Face Detection App Now you’ll create the main web page that handles live face detection using face-api.js and JavaScript. This will include video, canvas for drawing, and all the scripts needed to make it work in your browser. 1. Create an **index.html** file inside your project directory. ```bash nano index.html ``` Add the following code. ```bash Face Detection with face-api.js

Face Detection with face-api.js

Loading model...

``` 2. Start the HTTP web server. ```bash http-server -p 8080 & ``` This command starts the server in the background, serving your files at port 8080. ## Step 4: Exposing Your App Securely with NGINX and HTTPS At this point, your app is accessible only from the local machine. To make your app accessible from the internet, you will need to expose it using Nginx and HTTPS. 1. First, install NGINX on your server. ```bash apt install nginx -y ``` 2. Create a new configuration file for your app. ```bash nano /etc/nginx/conf.d/app.conf ``` Add the following code (replace app.example.com with your real domain): ```bash server { listen 80; server_name app.example.com; location / { proxy_pass http://localhost:8080; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } } ``` 3. Test the Nginx configuration. ```bash nginx -t ``` 4. If you see “syntax is ok,” reload Nginx. ```bash systemctl reload nginx ``` 5. Install Certbot and the Nginx plugin to secure your app with HTTPS. ```bash apt install certbot python3-certbot-nginx -y ``` 6. Run Certbot to get and apply a free SSL certificate. ```bash certbot --nginx -d app.example.com ``` ## Step 5: Access Your App Securely Now that your NGINX proxy and HTTPS certificate are set up, your app is accessible on the public internet with encrypted, private traffic. 1. Open your web browser and visit the URL below: ```bash https://app.example.com ``` 2. The app will prompt you to allow camera access. 3. Click **“Allow”** to enable face detection in real time. 4. If your webcam is working and the model weights are in place, you’ll see a green bounding box around your face on the video. The status message updates live: **“Face detected!”** or **“No face detected.”** ![](https://www.atlantic.net/wp-content/uploads/2025/07/p2.png) ## Conclusion You’ve just built a full-featured, real-time face detection web app using face-api.js and JavaScript, hosted on your own Ubuntu 24.04 server. With your app running securely over HTTPS, you can now access live face detection from anywhere, share it with others, and demonstrate browser-based AI in action—all with just a few lines of code and open-source tools. --- # How to Convert a Keras Model to a TensorFlow Lite Model on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-convert-a-keras-model-to-a-tensorflow-lite-model-on-ubuntu-24-04-gpu-server/ | Published: 2025-07-19 | Updated: 2026-05-04 | Author: Hitesh Jethva Deploying deep learning models outside of powerful cloud servers is now easier than ever, thanks to TensorFlow Lite (TFLite). When you convert your Keras model to TFLite, you unlock the ability to run AI-powered apps on mobile devices, Raspberry Pi, and a wide range of edge hardware. Many developers and data scientists want to use the same trained model across different platforms, but traditional TensorFlow models are often too large and resource-intensive for these environments. That’s where TensorFlow Lite comes in: it gives you smaller, faster models that retain much of the original model’s accuracy. In this guide, you’ll learn how to take a Keras model, convert it step-by-step to the TFLite format, and test it, all on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Install TensorFlow First, update all system packages to the latest version. ```bash apt update -y ``` Next, install Python and other required dependencies. ```bash apt install python3 python3-venv python3-pip -y ``` Create and activate the virtual environment. ```bash python3 -m venv keras2tflite-env source keras2tflite-env/bin/activate ``` Upgrade pip to the latest version. ```bash pip install --upgrade pip ``` Install TensorFlow. ```bash pip install tensorflow ``` ## Step 2: Create and Save a Keras Model In this section, you’ll build and save a simple Keras model for demonstration. Create a create_keras_model.py file. ```bash nano create_keras_model.py ``` Add the following code. ```bash import tensorflow as tf from tensorflow import keras # Build a basic model (MNIST-style, for simplicity) model = keras.Sequential([ keras.layers.Input(shape=(28, 28)), keras.layers.Flatten(), keras.layers.Dense(128, activation='relu'), keras.layers.Dense(10, activation='softmax') ]) # Compile the model (no need to train for conversion demo) model.compile(optimizer='adam', loss='sparse_categorical_crossentropy', metrics=['accuracy']) # Save the Keras model in HDF5 format model.save('my_keras_model.h5') print("Keras model saved as 'my_keras_model.h5'") ``` This script builds a basic neural network and saves it to a file named my_keras_model.h5. You can replace this with your own trained model if needed. Now, run the script. ```bash python3 create_keras_model.py ``` Output. ```bash Keras model saved as 'my_keras_model.h5' ``` ## Step 3: Convert Keras Model to TensorFlow Lite Now, you’ll convert the Keras model to the TensorFlow Lite format. Create a Python script. ```bash nano convert_to_tflite.py ``` Add the following code. ```bash import tensorflow as tf # Load the Keras model you saved model = tf.keras.models.load_model('my_keras_model.h5') # Convert to TFLite format converter = tf.lite.TFLiteConverter.from_keras_model(model) tflite_model = converter.convert() # Save as a .tflite file with open('model.tflite', 'wb') as f: f.write(tflite_model) print("TFLite model saved as 'model.tflite'") ``` This code loads your Keras. h5 model, converts it to TFLite, and saves it as a **model.tflite.** This is the model you’ll deploy to mobile or edge devices. Run the script. ```bash python3 convert_to_tflite.py ``` Output. ```bash TFLite model saved as 'model.tflite' ``` ## Step 4: Optimize Model with Quantization If you want your model to be even smaller and faster, you can optimize it with quantization. Create a script. ```bash nano convert_with_quantization.py ``` Add the following code. ```bash import tensorflow as tf # Load the Keras model again model = tf.keras.models.load_model('my_keras_model.h5') # Enable quantization during conversion converter = tf.lite.TFLiteConverter.from_keras_model(model) converter.optimizations = [tf.lite.Optimize.DEFAULT] quant_tflite_model = converter.convert() # Save quantized model with open('model_quant.tflite', 'wb') as f: f.write(quant_tflite_model) print("Quantized TFLite model saved as 'model_quant.tflite'") ``` This script uses TensorFlow’s built-in optimization to reduce the model’s size and improve inference speed, with minimal accuracy loss. The output file is model_quant.tflite. Run the script. ```bash python3 convert_with_quantization.py ``` Output. ```bash Quantized TFLite model saved as 'model_quant.tflite' ``` ## Step 5: Run Inference with TFLite Interpreter You should always test your TFLite model to ensure it works as expected. Here’s how to do a quick check. Let’s create a script to test the model. ```bash nano test_tflite_inference.py ``` Add the following code. ```bash import numpy as np import tensorflow as tf # Load the TFLite model and allocate tensors interpreter = tf.lite.Interpreter(model_path='model.tflite') interpreter.allocate_tensors() # Get details for input and output input_details = interpreter.get_input_details() output_details = interpreter.get_output_details() # Create a dummy input (batch size 1, 28x28 zeros) input_data = np.zeros((1, 28, 28), dtype=np.float32) interpreter.set_tensor(input_details[0]['index'], input_data) # Run inference interpreter.invoke() output_data = interpreter.get_tensor(output_details[0]['index']) print("TFLite model output:", output_data) ``` This script loads your TFLite model and runs it with dummy data to make sure everything works. If you see a probability array as output, your conversion was successful! Run the script. ```bash python3 test_tflite_inference.py ``` Output. ```bash TFLite model output: [[0.1 0.1 0.1 0.1 0.1 0.1 0.1 0.1 0.1 0.1]] ``` The output shows the model’s prediction probabilities for each of the 10 possible classes, with each value here being 0.1 since we used a dummy input of all zeros. ## Conclusion You’ve just walked through the complete process of converting a Keras model to TensorFlow Lite, right from installation and setup to final testing on Ubuntu 24.04. With these steps, you can confidently deploy your AI solutions to mobile phones, single-board computers, and embedded devices. --- # Voice Cloning with Tortoise-TTS on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/voice-cloning-with-tortoise-tts-on-ubuntu-24-04-gpu-server/ | Published: 2025-07-20 | Updated: 2025-08-01 | Author: Hitesh Jethva Voice cloning technology has seen major advances in recent years. You can now synthesize realistic speech that sounds like almost anyone, using just a few minutes of recorded audio. This opens up exciting new possibilities, from personal voice assistants to accessibility tools, creative media, and more. Tortoise-TTS stands out as one of the most advanced open-source tools for high-quality, controllable voice synthesis. It can generate natural-sounding speech and lets you “clone” a target voice with a small reference sample. In this guide, you’ll learn how to set up Tortoise-TTS on Ubuntu 24.04, build a simple Flask web interface, and clone voices by uploading a reference sample and custom text for instant speech generation. ## Prerequisites - An Ubuntu 24.04 server with an [NVIDIA GPU](https://www.atlantic.net/gpu-server-hosting/an-overview-of-popular-nvidia-gpus/). - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Install Required Dependencies Before you dive into voice cloning, let’s make sure your environment is ready. 1. Install the required dependency. ```bash apt install -y software-properties-common ``` 2. Add the Python repository. ```bash add-apt-repository ppa:deadsnakes/ppa ``` 3. Install Python 3.10 with other packages. ```bash apt install -y python3.10 python3.10-venv python3-pip python3.10-dev python3.10-distutils ffmpeg ``` 4. Verify the Python installation. ```bash python3.10 --version ``` Output. ```bash Python 3.10.18 ``` ## Step 2: Setting Up Tortoise-TTS Before you can start cloning voices, you’ll need to get Tortoise-TTS up and running on your Ubuntu 24.04 server. This section walks you through cloning the official repository and applying a quick code fix to avoid a common runtime error. 1. First, let’s download the latest Tortoise-TTS code from GitHub. ```bash git clone https://github.com/neonbjb/tortoise-tts.git ``` 2. Navigate inside the downloaded directory. ```bash cd tortoise-tts ``` 3. Tortoise-TTS sometimes throws an error related to an unexpected argument in the API. The fix is simple—just update one line in the tortoise/api.py file. ```bash nano tortoise/api.py ``` Find the following line: ```bash cond_mel = wav_to_univnet_mel(sample.to(self.device), do_normalization=False, device=self.device, stft=self.stft) ``` And, replaced it with the following line. ```bash cond_mel = wav_to_univnet_mel(sample.to(self.device), do_normalization=False) ``` Save and close the file ## Step 3: Prepare the Voice Directory Before you can start cloning a voice, you’ll need a special folder to store your reference audio sample. Tortoise-TTS uses this folder to find the audio it will learn from and later use for synthesis. Let’s make a new folder called my_target_voice inside the tortoise/voices directory. This will hold your recorded sample. ```bash mkdir -p tortoise/voices/my_target_voice ``` ## Step 4: Setting Up a Python Virtual Environment Running Tortoise-TTS and its dependencies inside a Python virtual environment is the best way to keep your project organized and avoid conflicts with other Python apps on your server. 1. First, make sure you’re in the root folder of your Tortoise-TTS project: ```bash cd ~/tortoise-tts ``` 2. Now, create a new virtual environment called tortoise-venv using Python 3.10. ```bash python3.10 -m venv tortoise-venv ``` 3. Activate your new environment so all Python commands use the right interpreter and dependencies. ```bash source tortoise-venv/bin/activate ``` ## Step 5: Install Python Dependencies With your virtual environment activated, you’re ready to install everything Tortoise-TTS needs to run smoothly. This includes core requirements, plus a couple of extra packages for the web interface. 1. Start by making sure pip (Python’s package installer) is up to date. ```bash pip install --upgrade pip ``` 2. Next, install all the required packages listed by the Tortoise-TTS repository. ```bash pip install -r requirements.txt ``` Note: The installation will take a few minutes 3. For the web interface and easier running of the Tortoise-TTS API, you’ll also want Flask and the latest Tortoise-TTS package. ```bash pip install flask tortoise-tts ``` ## Step 6: Building the Flask Web Application With Tortoise-TTS installed and ready, let’s make it user-friendly! You’ll build a simple Flask web app so you can record/upload your reference voice, type any text, and get your cloned voice as an MP3, all from your browser. 1. Create a new file named app.py in your tortoise-tts directory. ```bash nano app.py ``` Add the following code. ```bash import os from flask import Flask, render_template, request, send_file app = Flask(__name__) VOICE_DIR = "tortoise/voices/my_target_voice" AUDIO_PATH = os.path.join(VOICE_DIR, "sample1.wav") RESULT_WAV = "results/output_001.wav" RESULT_MP3 = "results/output_001.mp3" RESULTS_DIR = "results" # Ensure directories exist os.makedirs(VOICE_DIR, exist_ok=True) os.makedirs(RESULTS_DIR, exist_ok=True) @app.route("/", methods=["GET"]) def index(): return render_template("index.html") @app.route("/upload", methods=["POST"]) def upload(): # Remove old wav files in the target voice directory for f in os.listdir(VOICE_DIR): if f.endswith(".wav"): os.remove(os.path.join(VOICE_DIR, f)) audio = request.files["audio_data"] temp_path = os.path.join(VOICE_DIR, "temp_upload") audio.save(temp_path) # Convert to real WAV format using ffmpeg os.system(f'ffmpeg -y -i "{temp_path}" -ar 22050 -ac 1 "{AUDIO_PATH}"') os.remove(temp_path) return "Uploaded", 200 @app.route("/synthesize", methods=["POST"]) def synthesize(): text = request.form["text"] # Clean old .wav and .mp3 files from results/ for f in os.listdir(RESULTS_DIR): if f.endswith(".wav") or f.endswith(".mp3"): os.remove(os.path.join(RESULTS_DIR, f)) # Run Tortoise-TTS with the user's recorded reference cmd = f'python3 tortoise/do_tts.py --text "{text}" --voice my_target_voice' os.system(cmd) # Find the latest .wav file in results/ wav_files = [os.path.join(RESULTS_DIR, f) for f in os.listdir(RESULTS_DIR) if f.endswith(".wav")] if not wav_files: return "Synthesis failed: No output .wav found.", 500 latest_wav = max(wav_files, key=os.path.getctime) # Convert the wav file to mp3 using ffmpeg os.system(f'ffmpeg -y -i "{latest_wav}" -codec:a libmp3lame -qscale:a 2 "{RESULT_MP3}"') # Return the mp3 file for download if not os.path.exists(RESULT_MP3): return "Synthesis failed: MP3 not created.", 500 return send_file(RESULT_MP3, as_attachment=True, download_name="cloned_voice.mp3") if __name__ == "__main__": app.run(debug=True) ``` The above code: - Handles audio upload and conversion to the right format. - Runs the Tortoise-TTS synthesis process. - Converts the result to MP3 and sends it back for download. - Serves the web page for your interface. 2. Now let’s make a folder for your HTML files. ```bash mkdir templates ``` 3. Create a new HTML file inside the templates directory. ```bash nano templates/index.html ``` Add the following code. ```bash Voice Clone Web UI

1. Record your voice sample

2. Clone your voice

``` The above code allows you to: - Record your own voice or upload an audio sample directly from your browser. - Enter any text for voice synthesis. - Shows progress and lets you download your cloned voice as an MP3. ## Step 7: Running the Voice Cloning Web App Now that you’ve built your Flask web application and set up all the required files, it’s time to launch your own private voice cloning site! Run your Flask application. ```bash python3 app.py ``` You should see output like this. ```bash * Serving Flask app 'app' * Debug mode: on WARNING: This is a development server. Do not use it in a production deployment. * Running on http://127.0.0.1:5000 ``` This means your server is running locally and ready for you to test! ## Step 8: Accessing the Web Interface Remotely If your Ubuntu 24.04 server is running in the cloud, you’ll want to use your laptop or desktop browser to control your voice cloning web app. The safest and easiest way to do this is with an SSH tunnel. An SSH tunnel creates a secure, encrypted connection from your local computer to your server. It forwards a port from your server to your local machine, so only you can access the web app, no public exposure or risky firewall changes. On your local desktop computer, open a terminal and run: ```bash ssh -N -f -L 5000:localhost:5000 root@your-server-ip ``` **Note:** Replace **your-server-ip** with your server’s public IP address or domain name. The above command: - Forward your local port 5000 to port 5000 on the server. - Any request you make to localhost:5000 on your laptop goes securely to your server’s Flask app. ## Step 9: Using the Voice Cloning App Once you have your Tortoise-TTS web app running (and have connected via SSH tunnel if needed), you’re ready to try out voice cloning for yourself. Here’s how you can go from recording your own voice to downloading a fully cloned audio sample, all from your browser. **1. Open the Web App** On your local computer, open a web browser and visit: ```bash http://localhost:5000 ``` This brings up your voice cloning app’s main interface. **2. Record Your Voice Sample** - Click the **“Record”** button to begin recording your voice. - When your browser asks for permission, allow microphone access. - Speak clearly and record a short sample, just a few seconds is enough for a quick demo. - Click **“Stop”** when you’re done. - You’ll see your recorded sample appear in the audio player and a message confirming upload. **3. Enter the Text to Clone** In the input field below, type any text you want the app to synthesize in your voice. - Example: **“My name** **is hitesh**“ **4. Generate the Cloned Voice** - Click the **“Clone Voice”** button. You’ll see a progress bar as the server processes your request and generates the synthetic voice. ![](https://www.atlantic.net/wp-content/uploads/2025/07/clone.png) **5. Download Your Cloned Audio** - Once the process is finished, a download link for an MP3 file will appear. - Click the link to download your cloned voice and play it on your computer, phone, or any audio player. ## Conclusion You’ve now learned how to set up a powerful, private voice cloning app using Tortoise-TTS on an Ubuntu 24.04 GPU server. With just a few steps, you can record your voice, enter custom text, and generate natural-sounding speech, all from an easy-to-use web interface. This workflow is perfect for experimenting with AI voice technology in a secure environment, whether you’re a developer, content creator, or just curious about the latest in speech synthesis. If you want to go further, you can explore customizing the web UI, adding support for more voices, or integrating Tortoise-TTS with other applications and APIs. --- # GPU Applications: What Are the Main Applications for GPUs? > URL: https://www.atlantic.net/gpu-server-hosting/gpu-applications-what-are-the-main-applications-for-gpus/ | Published: 2025-07-21 | Updated: 2026-04-24 | Author: Richard Bailey The graphics processing unit, or GPU, has changed far beyond its original purpose of rendering complex graphics for video games. Today, it’s a powerful workhorse that outperforms the central processing unit for a wide range of highly demanding tasks. GPUs are essential for artificial intelligence and machine learning applications because the dedicated graphics processor is capable of performing the millions of calculations necessary for modern applications. From cutting-edge scientific research to powering chatbots, large language models, and intelligent coding agents, none of this would be possible without the performance and recent advances in GPU computing. In this article, we will explore the primary uses of GPUs and examine why their unique architecture is ideal for applications that handle complex calculations and process vast amounts of data. This is part of an extensive series of guides about [AI technology](https://www.tabnine.com/blog/ai-technology-powering-the-ai-revolution/). ## GPU Technology: Core Strengths GPUs excel at parallel processing tasks and memory-intensive tasks. A more recent, but now critical, strength of modern GPUs is the inclusion of dedicated hardware units designed to accelerate very specific workloads. These are not general-purpose cores; they are highly efficient, fixed-function blocks of silicon that make certain applications practical in real-time. - **Tensor Cores:** These units are engineered to accelerate the specific math operations (matrix multiply-accumulate) that are the foundation of deep learning and AI. For machine learning tasks, such as training a neural network, these cores provide a massive performance uplift over using general-purpose cores, reducing training times from weeks to days or even hours. - **Ray Tracing (RT) Cores:** Found in many consumer graphics cards, RT Cores are built for one purpose: to rapidly perform the complex intersection calculations needed for ray tracing. This technology simulates the physical behavior of light, creating incredibly realistic lighting, shadows, and reflections. ## Types of GPUs: Integrated, Dedicated, and Beyond Before looking specifically into the applications, it is important to distinguish between the different types of GPUs available, both consumer and enterprise-grade hardware: - **Integrated Graphics Processing Unit (Integrated GPU):** This type of processing unit is built directly into the computer’s motherboard or the CPU itself. It shares system memory with the CPU and is generally less powerful. Integrated graphics are sufficient for everyday tasks like web browsing, video playback, and basic productivity software. - **External GPU (eGPU):** An external GPU is a dedicated graphics card housed in an external enclosure that connects to a computer, typically a laptop, via a high-speed connection like Thunderbolt. This allows users to add the power of a discrete graphics card to a machine with only an integrated GPU. - **Dedicated Graphics Card (Discrete GPU):** A dedicated graphics card is a separate piece of hardware with its own memory (VRAM) and processing unit. These cards, also known as discrete GPUs, offer significantly higher graphics performance and are essential for demanding tasks. These are commonly found in gaming PCs up and down the country. - **Cloud GPUs:** These are the most powerful GPUs hosted in a data center that can be accessed remotely. Cloud computing services offer cloud GPUs for users who need immense computing power for tasks like large-scale machine learning model training without investing in expensive on-premise hardware. ## Key GPU Applications The unique GPU architecture has made it an indispensable tool in numerous fields. The following sections will detail some of the most prominent GPU applications, including scientific visualization. ## Gaming and Graphics Rendering The original and still most well-known application for GPUs is gaming. Modern GPUs are essential for rendering the complex and realistic worlds of today’s video games. They handle everything from rendering graphics and textures to complex physics calculations and real-time ray tracing, a technique that simulates the physical behavior of light to create incredibly lifelike images. The high memory bandwidth and massive number of cores, such as CUDA cores in NVIDIA cards, allow for the smooth, high-frame-rate gameplay that gamers demand. A powerful discrete graphics card is critical for achieving optimal graphics performance and a must-have for any serious PC gamer. Beyond gaming, GPUs are popular for professional 3D graphics rendering. Artists and designers in fields like architecture, animation, and visual effects rely on the processing power of GPUs to create and render their detailed models and scenes. The parallel processing capabilities of a graphics card can dramatically reduce the time it takes to render a final image or animation, from hours or even days with just CPU processing to mere minutes. ## Video Editing and Content Creation Video editing is another area where the GPU acceleration provides a significant boost. Tasks like encoding, decoding, rendering effects, and color grading are all highly parallelizable. A capable graphics processing unit can handle these tasks much more efficiently than a CPU alone, resulting in a smoother editing workflow and much faster export times. This is especially true when working with high-resolution footage, such as 4K or 8K video. The ability to offload these intensive tasks to the GPU frees up the CPU to handle other aspects of the operating system and software, leading to a more responsive experience. ## Machine Learning and Artificial Intelligence The fields of machine learning and artificial intelligence have been revolutionized by GPU technology. Training deep learning models, a subset of machine learning, involves performing a massive number of matrix multiplications and other mathematical operations. This is a perfect workload for the parallel processing power of a GPU. The ability to perform thousands of simultaneous calculations has drastically reduced the time it takes to train complex models from weeks or months to days or even hours. Key machine learning tasks that benefit from GPU acceleration include: - Image recognition - Natural language processing - Autonomous vehicle development - Medical image analysis The development of specialized libraries and APIs, such as NVIDIA’s CUDA platform, has made it easier for developers to program GPUs for general-purpose computing, further solidifying the GPU’s role in the AI revolution. The demand for GPU power in this space has also led to the growth of cloud GPUs, which provide the necessary computing resources on demand. ## Scientific Computing and Data Analysis High-performance computing (HPC) and scientific computing have also embraced the power of the GPU. Researchers and scientists use GPUs to run complex simulations and analyze massive datasets in fields like: - Computational fluid dynamics - Molecular modeling - Climate science - Astrophysics These simulations often involve solving systems of partial differential equations, a task that can be broken down into many smaller, independent calculations. The parallel processing capabilities of a GPU are ideally suited for this kind of work, allowing for faster and more detailed simulations. GPUs are used to accelerate the processing of large datasets, specifically for data analysis. This can be particularly useful in fields like finance, where analysts need to quickly process market data to identify trends and make decisions. The ability to process data simultaneously allows for much faster analysis than would be possible with a CPU alone. The increased memory bandwidth of modern GPUs is a significant advantage when working on the data pipeline of large datasets that need to be accessed quickly. ## Putting Theory into Practice: Dedicated GPU Cloud Hosting While understanding the power of a graphics processing unit is one thing, accessing that power is another. For many businesses and research institutions, the high cost of enterprise-grade dedicated hardware and the complexity of maintaining it are significant barriers. This is where dedicated GPU hosting platforms provide a practical solution, offering access to high-performance computing resources on demand. A prime example of this is the [Atlantic.Net GPU Hosting Platform,](https://www.atlantic.net/gpu-server-hosting/) which provides dedicated servers powered by NVIDIA GPUs. A dedicated server model is critical for professional applications as it guarantees that all the computing power of the physical hardware, including the CPU, RAM, and—most importantly—the dedicated GPU, is allocated to a single client. This ensures consistent, predictable hardware performance and enhances security, which is paramount when processing large datasets containing sensitive information. ## Discrete GPUs for the Most Demanding Jobs A key advantage of such a platform is access to a range of powerful, enterprise-class graphics processors. Atlantic.Net offers servers equipped with some of the most advanced GPUs on the market, including the NVIDIA L40S and the NVIDIA H100 NVL. - The NVIDIA L40S is a versatile GPU built on the Ada Lovelace architecture, designed to handle a mix of AI, graphics rendering, and video processing workloads. - The NVIDIA H100 NVL, based on the Hopper architecture, is a powerhouse specifically engineered for large-scale AI and high-performance computing (HPC), featuring extremely high memory bandwidth crucial for training large language models and other complex machine learning tasks. By making this dedicated hardware available, the platform enables specialized applications across numerous fields that were once limited to major research labs or corporations. ## GPU Applications in Critical Industries The availability of such powerful cloud GPUs has unlocked new possibilities in sectors that rely on data-intensive analysis and complex calculations. ### #1: Healthcare and Life Sciences In healthcare, GPU acceleration is driving a revolution in patient care and research. Medical institutions can leverage dedicated GPU servers for improved GPU acceleration in their research and patient care : - **Medical Image Analysis**: Using AI models to rapidly analyze MRI, CT, and X-ray images to detect anomalies like tumors with greater speed and accuracy. The NVIDIA L40S GPU is explicitly suited for accelerating such medical imaging analysis. - **Drug Discovery and Genomics:** The immense processing power of GPUs like the NVIDIA H100 can drastically reduce the time needed for molecular simulations and genomic sequencing. For example, the [NVIDIA Parabricks software](https://www.nvidia.com/en-gb/clara/genomics/), which is optimized for GPUs, has been shown to speed up whole-genome sequencing by more than 25 times. This allows researchers to accelerate the search for new drugs and personalized treatments. ### #2: Finance The financial sector operates on speed and data. GPU computing provides a critical edge for: - **Risk Analysis and Simulation:** Financial institutions run complex simulations, like Monte Carlo methods, to assess portfolio risk. GPU acceleration can reduce the time for these calculations from hours to minutes, enabling more timely and accurate risk management. - **Fraud Detection:** Machine learning models running on GPUs can analyze thousands of transactions per second to identify anomalous patterns and detect fraud in real-time, protecting both institutions and their customers. ### #3: Legal Technology Even the legal field, traditionally less tech-forward, is beginning to utilize GPU power. The primary driver is the explosion of digital data and the need to analyze it efficiently. - **E-Discovery:** In litigation, lawyers often need to sift through terabytes of data, including documents, emails, and other communications. GPU-accelerated platforms can run parallel searches and use AI-powered natural language processing (NLP) to classify and tag relevant documents, cutting review time significantly. - **Contract Analysis:** AI models accelerated by GPUs can analyze thousands of contracts to extract critical clauses, identify risks, and ensure compliance, automating a process that was once highly manual and error-prone. Ultimately, for any organization that works with large amounts of data, platforms like Atlantic.Net offer a simpler path. They take the raw power of a graphics processing unit and turn it from a complex piece of hardware into a practical, on-demand tool that businesses can use to push their work forward. ## The Future of GPU Applications The role of the graphics processing unit in modern computing continues to grow. As GPU technology advances, with increasing numbers of cores, greater energy efficiency, and more sophisticated architectures, we can expect to see even more innovative GPU applications emerge. The increasing use of multiple GPUs in a single system or across a network will further push the boundaries of what is possible. From powering the next generation of immersive video games to enabling breakthroughs in artificial intelligence and scientific computing, the GPU has proven itself to be a versatile and powerful tool. Its ability to perform a massive number of parallel tasks has fundamentally changed the landscape of computing, and its importance is only set to grow in the years to come. Whether you are a gamer, a content creator, a data scientist, or a researcher, the graphics processing unit is a piece of dedicated hardware that is likely to have a significant impact on your work and daily life. Ready to apply this knowledge and deploy your high-performance applications? [**Atlantic.Net’s GPU Hosting**](https://www.atlantic.net/gpu-server-hosting/gpu-dedicated-hosting/) provides on-demand access to powerful NVIDIA-powered servers. Accelerate your machine learning, data science, and rendering workloads today. ## See Additional Guides on Key AI Technology Topics Together with our content partners, we have authored in-depth guides on several other topics that can also be useful as you explore the world of [AI technology](https://www.tabnine.com/blog/ai-technology-powering-the-ai-revolution/). ### [LLM Security](https://www.mend.io/blog/llm-security-risks-mitigations-whats-next/) *Authored by Mend* - [[Guide] LLM Security in 2025: Key Risks, Best Practices & Trends](https://www.mend.io/blog/llm-security-risks-mitigations-whats-next/) - [[Guide] Prompt Injection Attacks: 4 Types & How to Defend](https://www.mend.io/blog/what-is-a-prompt-injection-attack-types-examples-defenses/) - [[Guide] 2025 OWASP Top 10 for LLM Applications: Quick Guide](https://www.mend.io/blog/2025-owasp-top-10-for-llm-applications-a-quick-guide/) ### [AI Cyber Security](https://www.exabeam.com/explainers/ai-cyber-security/ai-cyber-security-securing-ai-systems-against-cyber-threats/) *Authored by Exabeam* - [[Guide] AI Cyber Security: Securing AI Systems Against Cyber Threats](https://www.exabeam.com/explainers/ai-cyber-security/ai-cyber-security-securing-ai-systems-against-cyber-threats/) - [[Guide] What Is Machine Learning in Cybersecurity?](https://www.exabeam.com/explainers/ai-cyber-security/10-ways-machine-learning-is-transforming-cybersecurity/) - [[Blog] Cybersecurity Threats: Everything you Need to Know](https://www.exabeam.com/blog/infosec-trends/cybersecurity-threats-everything-you-need-to-know/) - [[Product] Exabeam | AI-Driven Security Operations](https://www.exabeam.com/) ### [GPU Architecture](https://www.atlantic.net/gpu-server-hosting/the-engine-of-modern-computing-a-deep-dive-into-gpu-architecture/) *Authored by Atlantic.Net* - [[Guide] The Engine of Modern Computing: A Deep Dive into GPU Architecture ](https://www.atlantic.net/gpu-server-hosting/the-engine-of-modern-computing-a-deep-dive-into-gpu-architecture/) - [[Guide] NVIDIA NVLink: How It Works, Use Cases & Critical Best Practices ](https://www.atlantic.net/gpu-server-hosting/nvidia-nvlink-how-it-works-use-cases-and-critical-best-practices/) - [[Blog] How to Make the Best Use of Artificial Intelligence in Cloud Computing](https://www.atlantic.net/vps-hosting/how-to-make-the-best-use-of-artificial-intelligence-in-cloud-computing/) - [[Product] Atlantic.Net GPU Hosting | Next-Gen Dedicated GPU Servers, Accelerated by NVIDIA](https://www.atlantic.net/gpu-server-hosting/) --- # The Engine of Modern Computing: A Deep Dive into GPU Architecture > URL: https://www.atlantic.net/gpu-server-hosting/the-engine-of-modern-computing-a-deep-dive-into-gpu-architecture/ | Published: 2025-07-22 | Updated: 2026-04-24 | Author: Richard Bailey From the vibrant, immersive worlds of video games to the complex calculations powering scientific breakthroughs and artificial intelligence, the role of the GPU has changed from being a specialized graphics processing tool into an essential part of modern AI computing. A GPU has the remarkable ability to perform a massive number of calculations simultaneously, making it indispensable for a wide range of demanding AI/ML applications. This article will uncover the complexity of GPU architecture, exploring its fundamental components, memory systems, and the design philosophies that set it apart from traditional CPU cores. We will look at the basic structure of a processing unit to the sophisticated tech that drives high-performance computing, machine learning, and specialist video rendering. This is part of an extensive series of guides about [AI technology](https://www.tabnine.com/blog/ai-technology-powering-the-ai-revolution/). ## Parallel Processing: Kernel Grids to Core Technologies At the core of a GPU’s ability to handle immense computational workloads is its architectural design, which centers on parallel processing. Unlike a Central Processing Unit (CPU) that is designed for sequential task execution with a few powerful cores, a GPU is built with thousands of smaller, more efficient cores. This design is optimized for the Single Instruction, Multiple Data [(SIMD) model](https://www.sciencedirect.com/topics/computer-science/single-instruction-multiple-data), where the same instruction is executed across multiple data points simultaneously. The basic processing unit within a modern GPU is the Streaming Multiprocessor (SM). Each GPU contains multiple SMs, and each SM, in turn, houses hundreds of processing cores. In NVIDIA GPUs, these are known as CUDA cores. These cores are the primary components responsible for executing the core math operations and floating-point calculations that are the basis of graphics rendering and scientific computing. The higher number of CUDA cores results in a higher processing power capability and, in turn, better GPU performance. The execution of tasks on a GPU is managed through a hierarchical structure of threads. A program running on a GPU, known as a kernel, launches a grid of thread blocks. Each thread block is a group of multiple threads that can cooperate and share data using a high-speed, on-chip memory known as shared memory. A single thread block is executed by a single SM. The ability to manage many thread blocks across multiple SMs allows a GPU to process an enormous number of threads simultaneously, leading to a major acceleration of parallelizable tasks. ## Tensor Cores and GPU Acceleration GPU manufacturers have responded to the surge in deep learning and artificial intelligence demands by developing a relatively new type of processing core that appears within NVIDIA GPUs: the Tensor Core. These are highly specialized cores designed to accelerate the matrix multiplication and accumulation operations that are central to model training and inference in neural networks. By performing these operations in a single step, Tensor Cores provide a large increase in performance for AI workloads compared to what is achievable with standard CUDA cores alone. This specialization is a prime example of how GPU technology has adapted to meet the needs of new computational fields, establishing the GPU’s role in the advancement of machine learning. ## Memory: Hierarchy, Bandwidth, L2 cache, and Latency The immense processing power of a GPU would be wasted without a complex memory system to feed its thousands of cores. The GPU memory hierarchy is a key aspect of its architecture, designed to balance the trade-off between speed, size, and cost. Understanding this hierarchy is central to improving GPU performance. At the top of the hierarchy are the registers, which are the fastest but smallest memory spaces, local to each processing core. Following this is the L1 cache and shared memory, both of which are on-chip and offer much lower memory latency than off-chip memory. Shared memory is a particularly important resource for developers, as it allows threads within a thread block to communicate and share data effectively. Effective shared memory usage is a key feature of well-tuned GPU applications, as it can greatly reduce latency and the need to access slower global memory. The largest pool of memory available to a GPU is the global memory, which is typically located off-chip. While large in size, it has the highest memory latency. A major portion of GPU performance improvement comes from minimizing the number of accesses to global memory by using the faster on-chip memory. To address the growing demand for faster data access, modern GPUs have adopted High-Bandwidth Memory (HBM). HBM uses a stacked die design to provide a much wider memory bus, resulting in much higher memory bandwidth compared to traditional GDDR memory. This high throughput is necessary for feeding the massive number of cores in high-end GPUs, particularly in memory-intensive applications like high-performance computing and large-scale deep learning model training. Another specialized memory space is texture memory, which is configured for 2D and 3D spatial locality. It has dedicated caching mechanisms that can accelerate memory access patterns commonly found in gaming and some scientific simulations. The entire memory subsystem, including the L2 cache, works together to supply the data multiple threads need, when they need it, to sustain high throughput and reach peak performance. ## Architectural Showdown: NVIDIA vs. AMD The GPU market is largely led by two key players: NVIDIA Corporation and AMD. Both companies have developed distinct GPU microarchitectures tailored to different market segments, from consumer GPUs for gaming to powerful accelerators for data centers. NVIDIA GPUs, with their CUDA programming model, have a strong foothold in the general-purpose computing on GPU market, especially in the fields of machine learning and scientific computing. Architectures like Ampere and the more recent Hopper have introduced major advancements. The Ampere architecture, for instance, brought second-generation ray tracing cores and third-generation Tensor Cores, greatly increasing performance for both gaming and professional workloads. The Hopper architecture further extends the capabilities for exascale computing and massive AI models, featuring even more powerful Tensor Cores and a new level of multi-GPU connectivity with NVLink. On the other side, AMD GPUs have made great progress with their RDNA and CDNA architectures. The RDNA architecture targets the gaming market, powering their Radeon series of consumer GPUs. It introduced a redesigned compute unit and a multi-level cache hierarchy to improve instructions-per-clock and energy usage. In contrast, the CDNA (Compute DNA) architecture is specifically designed for the data center and high-performance computing. It puts a priority on floating-point operations and features its own matrix core technology to offer an alternative to NVIDIA’s Tensor Cores in AI and scientific workloads. The key distinctions between these architectural philosophies often lie in the specifics of their core designs, memory subsystems, and the software that supports them. This competition continues to drive progress in GPU technology, leading to more powerful and effective processors with each new generation. ## Real-World Applications and How They Impact Performance The effect of GPU architecture is felt across a wide set of industries and applications. In video rendering and computer-aided design (CAD), GPUs allow for the rapid processing of complex scenes and models, greatly shortening the time it takes to create and render detailed designs. In the scientific community, GPUs specialize in number-crunching tasks, accelerating simulations in fields like molecular dynamics, climate modeling, and astrophysics. The ability to perform a massive number of math operations in parallel has changed computational science. For developers looking to use the full power of GPU acceleration, understanding how to improve performance is key. Main strategies include: - **Increasing Parallelism:** Structuring problems to expose as much parallelism as possible is a basic principle. This involves designing algorithms that can be broken down into a large number of independent tasks that can be executed by many threads across many thread blocks. - **Improving Memory Access:** Minimizing data movement between the host (CPU) and the device (GPU), and within the GPU memory hierarchy, is very important. This includes using shared memory to reduce reliance on global memory and making sure that memory accesses are coalesced to get the most out of memory bandwidth. - **Using Specialized Hardware:** For applications in machine learning, using Tensor Cores through libraries like cuDNN and TensorRT can lead to orders-of-magnitude performance improvements. - **Multi-GPU Scaling:** For the most computationally intensive workloads, using multiple GPUs can provide an almost direct increase in processing power. Technologies like NVIDIA’s NVLink provide a high-speed interconnect between GPUs, allowing them to work together on a single task or a set of multiple tasks more effectively than ever before. Note that not all applications scale well with multiple GPUs, and careful programming is required to manage data distribution and synchronization between devices. The path to peak performance requires a good understanding of the underlying GPU microarchitecture and a continuous process of profiling and refinement to identify and eliminate bottlenecks that affect performance. ## GPU Performance Power Through GPU Hosting Understanding the complex architecture of a modern GPU is one challenge; gaining access to this powerful hardware is another. The high cost of purchasing and maintaining cutting-edge GPUs can be a significant barrier for individuals and businesses. This is where GPU hosting services provide a practical solution. Cloud and dedicated server providers enable everyday users to gain access to powerful GPUs on demand. Atlantic.Net, for example, offers GPU hosting solutions that feature powerful NVIDIA GPUs, including the NVIDIA L40S and H100 NVL models. These services allow users to bypass the large upfront investment in hardware and instead rent access to servers equipped with the latest GPU technology. By using a hosting service, a developer working on a deep learning project can access servers with H100 GPUs, taking direct advantage of the Hopper architecture’s fourth-generation Tensor Cores and high-bandwidth HBM3 memory for training large language models. Similarly, a design studio can rent a server with L40S GPUs to accelerate video rendering workloads, benefiting from its balance of AI compute and graphics performance. This on-demand model provides the scalability to adjust computing resources as project needs change, making powerful GPU acceleration accessible for tasks ranging from scientific research to AI model training and inference. ## Conclusion: Ever-Changing GPU Architecture The GPU architecture has seen a major change, growing from a specialized graphics engine to a powerful, general-purpose parallel processor. The continued push for higher processing power, greater memory bandwidth, and improved energy usage has led to a detailed and highly tuned design. The combination of streaming multiprocessors, a range of processing cores like CUDA cores and Tensor Cores, and a layered memory hierarchy gives modern GPUs powerful capabilities. The need for artificial intelligence, scientific discovery, and immersive digital experiences will continue to shape the direction of GPU technology. Ongoing work from industry leaders like NVIDIA Corporation and AMD points toward more powerful and specialized architectures. This suggests the graphics processing unit will continue to be a central part of high-performance computing. The GPU’s ability to process multiple data points in parallel makes it a key tool for training new deep-learning models, rendering photorealistic virtual worlds, or solving some of the world’s most difficult scientific problems. Experience the power of dedicated NVIDIA GPUs without the cost and complexity of managing your own hardware. Launch your high-performance server in minutes with Atlantic.Net GPU Hosting. [**Deploy Your GPU Server Today**](https://cloud.atlantic.net) ## See Additional Guides on Key AI Technology Topics Together with our content partners, we have authored in-depth guides on several other topics that can also be useful as you explore the world of [AI technology](https://www.tabnine.com/blog/ai-technology-powering-the-ai-revolution/). ### [LLM Security](https://www.mend.io/blog/llm-security-risks-mitigations-whats-next/) *Authored by Mend* - [[Guide] LLM Security in 2025: Key Risks, Best Practices & Trends](https://www.mend.io/blog/llm-security-risks-mitigations-whats-next/) - [[Guide] Prompt Injection Attacks: 4 Types & How to Defend](https://www.mend.io/blog/what-is-a-prompt-injection-attack-types-examples-defenses/) - [[Guide] 2025 OWASP Top 10 for LLM Applications: Quick Guide](https://www.mend.io/blog/2025-owasp-top-10-for-llm-applications-a-quick-guide/) ### [AI Cyber Security](https://www.exabeam.com/explainers/ai-cyber-security/ai-cyber-security-securing-ai-systems-against-cyber-threats/) *Authored by Exabeam* - [[Guide] AI Cyber Security: Securing AI Systems Against Cyber Threats](https://www.exabeam.com/explainers/ai-cyber-security/ai-cyber-security-securing-ai-systems-against-cyber-threats/) - [[Guide] What Is Machine Learning in Cybersecurity?](https://www.exabeam.com/explainers/ai-cyber-security/10-ways-machine-learning-is-transforming-cybersecurity/) - [[Blog] Cybersecurity Threats: Everything you Need to Know](https://www.exabeam.com/blog/infosec-trends/cybersecurity-threats-everything-you-need-to-know/) - [[Product] Exabeam | AI-Driven Security Operations](https://www.exabeam.com/) ### [GPU Server](https://www.atlantic.net/gpu-server-hosting/) *Authored by Atlantic.Net* - [[Guide] NVIDIA GPU Server Hosting | High-Performance AI Hosting ](https://www.atlantic.net/gpu-server-hosting/) - [[Guide] GPU as a Service: Benefits, Use Cases & How to Choose ](https://www.atlantic.net/gpu-server-hosting/gpu-as-a-service-benefits-use-cases-and-how-to-choose/) - [[Blog] How to Make the Best Use of Artificial Intelligence in Cloud Computing](https://www.atlantic.net/vps-hosting/how-to-make-the-best-use-of-artificial-intelligence-in-cloud-computing/) - [[Product] Atlantic.Net GPU Hosting | Next-Gen Dedicated GPU Servers, Accelerated by NVIDIA](https://www.atlantic.net/gpu-server-hosting/) --- # Create a Custom Loss Function in TensorFlow on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/create-a-custom-loss-function-in-tensorflow-on-ubuntu-24-04-gpu-server/ | Published: 2025-07-23 | Updated: 2025-08-01 | Author: Hitesh Jethva Custom loss functions allow you to make your deep learning models more intelligent and tailored to your needs. While popular loss functions like Mean Squared Error (MSE) and Categorical Cross-Entropy work for most tasks, sometimes you need to reflect specific business priorities or research goals in how your model learns. This is where custom loss functions shine: you can penalize errors differently, combine multiple objectives, or handle special data scenarios. In this guide, you’ll learn everything you need to create, save, and use a custom loss function in TensorFlow on your Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). ## Why Create a Custom Loss Function? Before you jump in, it’s important to know why custom loss functions are valuable for machine learning projects. A loss function tells your model how far off its predictions are from the ground truth. While standard loss functions work for many scenarios, sometimes your problem has unique requirements: - You might want to punish certain mistakes more than others (e.g., false negatives in medical diagnoses). - You may need to mix losses (e.g., combine MSE and MAE). - You could have imbalanced data, unusual output formats, or business-specific priorities. In all these cases, designing your own loss function lets you shape your model’s learning in exactly the way you need. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Setting Up Python Environment 1. First, install the required dependencies. ```bash apt install -y software-properties-common ``` 2. Add the Python repository. ```bash add-apt-repository ppa:deadsnakes/ppa ``` 3. Install Python 3.10 with additional libraries. ```bash apt install -y python3.10 python3.10-venv python3-pip python3.10-dev ``` 4. Verify the Python installation. ```bash python3.10 --version ``` Output. ```bash Python 3.10.18 ``` ## Step 2: Install TensorFlow 1. First, create a virtual environment for your project. ```bash python3.10 -m venv tf-venv ``` 2. Activate the virtual environment. ```bash source tf-venv/bin/activate ``` 3. Update pip to the latest version. ```bash pip install --upgrade pip ``` 4. Install TensorFlow. ```bash pip install tensorflow ``` ## Step 3: Defining Your Custom Loss Function Now, let’s create a Python file that contains your custom loss logic. This keeps your code organized and reusable. ```bash nano custom_loss.py ``` Add the following code: ```bash import tensorflow as tf def mae_mse_loss(y_true, y_pred): """ Combine Mean Absolute Error (MAE) and Mean Squared Error (MSE). Returns: scalar loss value. """ mae = tf.reduce_mean(tf.abs(y_true - y_pred)) mse = tf.reduce_mean(tf.square(y_true - y_pred)) return mae + mse class WeightedMAEMSE(tf.keras.losses.Loss): """ Custom loss: weighted sum of MAE and MSE. """ def __init__(self, mae_weight=0.5, mse_weight=0.5, name="weighted_mae_mse"): super().__init__(name=name) self.mae_weight = mae_weight self.mse_weight = mse_weight def call(self, y_true, y_pred): mae = tf.reduce_mean(tf.abs(y_true - y_pred)) mse = tf.reduce_mean(tf.square(y_true - y_pred)) return self.mae_weight * mae + self.mse_weight * mse ``` **Explanation:** - **mae_mse_loss:** Combines MAE and MSE for a balanced regression loss. - **WeightedMAEMSE:** Lets you control the weighting between MAE and MSE by changing parameters. Run the script. ```bash python3.10 custom_loss.py ``` Note: Any warnings here can be safely ignored ## Step 4: Building and Training a Model with the Custom Loss With your custom loss ready, let’s see how to plug it into a real model. This file will set up the data, build the model, and train it. ```bash nano train_with_custom_loss.py ``` Add the following code: ```bash import numpy as np import tensorflow as tf from custom_loss import mae_mse_loss, WeightedMAEMSE # Generate toy regression data x = np.random.rand(1000, 10) y = np.sum(x, axis=1, keepdims=True) + np.random.normal(0, 0.1, (1000, 1)) # target: sum + noise # Build a simple model model = tf.keras.Sequential([ tf.keras.layers.Input(shape=(10,)), tf.keras.layers.Dense(64, activation='relu'), tf.keras.layers.Dense(1) ]) # Compile model with the function-based custom loss model.compile(optimizer='adam', loss=mae_mse_loss) print("Training model with function-based custom loss (MAE + MSE)...") model.fit(x, y, epochs=5, batch_size=32) # Now use the class-based loss with custom weights custom_loss = WeightedMAEMSE(mae_weight=0.7, mse_weight=0.3) model.compile(optimizer='adam', loss=custom_loss) print("Training model with class-based custom loss (Weighted MAE + MSE)...") model.fit(x, y, epochs=5, batch_size=32) ``` This script imports your custom loss and trains a small regression model using both function-based and class-based losses. Run the script. ```bash python3.10 train_with_custom_loss.py ``` The output will show training progress and loss values, proving your custom loss works! ```bash 32/32 ━━━━━━━━━━━━━━━━━━━━ 1s 10ms/step - loss: 27.3566 Epoch 2/5 32/32 ━━━━━━━━━━━━━━━━━━━━ 0s 2ms/step - loss: 15.0752 Epoch 3/5 32/32 ━━━━━━━━━━━━━━━━━━━━ 0s 2ms/step - loss: 4.5361 Epoch 4/5 32/32 ━━━━━━━━━━━━━━━━━━━━ 0s 2ms/step - loss: 0.3888 Epoch 5/5 32/32 ━━━━━━━━━━━━━━━━━━━━ 0s 2ms/step - loss: 0.3136 Training model with class-based custom loss (Weighted MAE + MSE)... Epoch 1/5 32/32 ━━━━━━━━━━━━━━━━━━━━ 1s 10ms/step - loss: 0.1630 Epoch 2/5 32/32 ━━━━━━━━━━━━━━━━━━━━ 0s 2ms/step - loss: 0.1055 Epoch 3/5 32/32 ━━━━━━━━━━━━━━━━━━━━ 0s 2ms/step - loss: 0.0864 Epoch 4/5 32/32 ━━━━━━━━━━━━━━━━━━━━ 0s 2ms/step - loss: 0.0756 Epoch 5/5 32/32 ━━━━━━━━━━━━━━━━━━━━ 0s 2ms/step - loss: 0.0695 ``` ## Conclusion Custom loss functions are a powerful tool for AI engineers and researchers. With them, you go beyond basic accuracy and make your models optimize for what matters most to your task, whether that’s a business metric, safety, or a scientific goal. In this article, you learned not just the “how” but also the “why” of custom losses. You saw how to structure your code with separate files, use both function-based and class-based approaches, and integrate your loss into a TensorFlow training loop. --- # Mobile Phone Price Prediction Using Machine Learning on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/mobile-phone-price-prediction-using-machine-learning-on-ubuntu-24-04-gpu-server/ | Published: 2025-07-24 | Updated: 2026-05-04 | Author: Hitesh Jethva Predicting mobile phone prices is an interesting machine learning task with real-world applications, such as helping buyers, sellers, and e-commerce platforms estimate fair market value based on device specifications. Instead of manually comparing phone features and market rates, we can train a machine learning model to analyze patterns in the data and predict prices automatically. In this guide, we’ll build a mobile phone price prediction system using Python, XGBoost, and Flask on an Ubuntu 24.04 GPU server. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Prepare the Server Environment Before we can start building and deploying our mobile phone price prediction system, we need to set up a working Python environment on our Ubuntu 24.04 GPU server. 1. We’ll start by installing Python, pip, and essential build tools. ```bash apt install -y python3 python3-pip python3-venv git build-essential ``` 2. Create and activate a virtual environment. ```bash python3 -m venv mobile-predict-env source mobile-predict-env/bin/activate ``` 3. It’s a good idea to make sure pip is updated before installing libraries. ```bash pip install --upgrade pip ``` 4. Finally, install all the Python libraries needed for this project, including Flask for the web server, pandas and numpy for data processing, scikit-learn and XGBoost for machine learning, and matplotlib and seaborn for visualization. ```bash pip install flask pandas numpy matplotlib seaborn scikit-learn xgboost ``` ## Step 2: Download the Dataset Now that your environment is ready, it’s time to get the dataset onto the server so we can train our machine learning model. 1. First, download the [**mobile dataset**](https://www.kaggle.com/code/xyzaraa/mobile-phone-price-prediction/input) from Kaggle on your local machine. 2. Use scp to upload the dataset from your local machine to the server. ```bash scp Downloads/mobile.csv root@your-server-ip:/root/ ``` This will upload **mobile.csv** directly to the **/root/** directory on your server. ## Step 3: Build the Machine Learning Model With the dataset now on your server, we can create a Python script that prepares the data, engineers useful features, and trains a machine learning model to predict mobile phone prices. 1. Create model.py. ```bash nano model.py ``` Add the following code: ```bash # model.py import pandas as pd import numpy as np import re from sklearn.model_selection import train_test_split from sklearn.pipeline import Pipeline from sklearn.preprocessing import OneHotEncoder, StandardScaler from sklearn.compose import ColumnTransformer from sklearn.impute import SimpleImputer from sklearn.linear_model import LinearRegression import xgboost as xgb class PricePredictor: def __init__(self, csv_path='mobile.csv'): self.df = pd.read_csv(csv_path) self.model = None self.preprocessor = None self.prepare_data() self.train_model() def prepare_data(self): df = self.df df.fillna('Unknown', inplace=True) # Handle outliers for Spec Score q1 = np.percentile(df['Spec Score'], 25) q3 = np.percentile(df['Spec Score'], 75) iqr = q3 - q1 lower_bound = q1 - 1.5 * iqr df['Spec Score'] = np.where(df['Spec Score'] < lower_bound, lower_bound, df['Spec Score']) # Feature engineering df['Battery_mAh'] = df['battery'].apply(lambda x: self.extract_value(x, r'(\d+)\s*mAh')) df['Display_Inches'] = df['display'].apply(lambda x: self.extract_value(x, r'(\d+\.?\d*)\s*(?:inch|inches|")')) df['Camera_MP'] = df['camera'].apply(lambda x: self.extract_value(x, r'(\d+)\s*MP')) df_storage = df['storage'].apply(self.extract_ram_rom) df = pd.concat([df, df_storage], axis=1) df['Processor_Brand'] = df['processor'].apply(self.extract_processor_brand) df['Version_Main'] = df['version'].apply(self.extract_version_main) # FIX: Replace inplace fillna with safe assignment for col in ['Battery_mAh', 'Display_Inches', 'Camera_MP', 'RAM_GB', 'Internal_Storage_GB']: df[col] = df[col].fillna(0) self.df = df self.numerical_features = ['Spec Score', 'rating', 'Battery_mAh', 'Display_Inches', 'Camera_MP', 'RAM_GB', 'Internal_Storage_GB'] self.cat_features = ['tag', 'sim', 'memoryExternal', 'Processor_Brand', 'Version_Main'] self.target = 'price' def extract_value(self, text, pattern): match = re.search(pattern, text, re.IGNORECASE) return float(match.group(1)) if match else np.nan def extract_ram_rom(self, text): text = str(text).lower() ram, rom = np.nan, np.nan ram_match = re.search(r'(\d+)\s*gb\s*ram', text) if ram_match: ram = int(ram_match.group(1)) rom_match = re.search(r'(\d+)\s*gb\s*(inbuilt|storage)?', text) if rom_match: rom = int(rom_match.group(1)) return pd.Series({'RAM_GB': ram, 'Internal_Storage_GB': rom}) def extract_processor_brand(self, text): text = str(text).lower() if 'snapdragon' in text: return 'Snapdragon' elif 'dimensity' in text: return 'Dimensity' elif 'helio' in text: return 'Helio' elif 'exynos' in text: return 'Exynos' elif 'a series' in text or 'apple' in text: return 'Apple A Series' elif 'kirin' in text: return 'Kirin' elif 'unisoc' in text: return 'Unisoc' else: return 'Other' def extract_version_main(self, text): text = str(text).lower() match = re.search(r'android\s*(\d+)', text) if match: return f"Android {match.group(1)}" return 'Other' def train_model(self): df = self.df X = df[self.numerical_features + self.cat_features] y = pd.to_numeric(df[self.target], errors='coerce') X_train, X_test, y_train, y_test = train_test_split(X, y, test_size=0.2, random_state=42) num_pipeline = Pipeline([ ('imputer', SimpleImputer(strategy='median')), ('scaler', StandardScaler()) ]) cat_pipeline = Pipeline([ ('imputer', SimpleImputer(strategy='most_frequent')), ('encoder', OneHotEncoder(handle_unknown='ignore')) ]) self.preprocessor = ColumnTransformer([ ('num', num_pipeline, self.numerical_features), ('cat', cat_pipeline, self.cat_features) ]) pipeline = Pipeline([ ('preprocessor', self.preprocessor), ('regressor', xgb.XGBRegressor(random_state=42)) ]) pipeline.fit(X_train, y_train) self.model = pipeline def predict(self, input_data): df_input = pd.DataFrame([input_data]) pred_price = self.model.predict(df_input)[0] return round(pred_price, 2) ``` This script will perform the following tasks: - Load the dataset (mobile.csv) - Handle missing values and outliers - Extract numerical features from text fields (like battery or display) - Encode categorical variables - Train a regression model using XGBoost - Provide a prediction method for future use ## Step 4: Build the Web Application with Flask Now that we have a trained machine learning model, it’s time to build a simple web interface that allows users to input mobile phone specifications and receive an instant price prediction. 1. Create app.py. ```bash nano app.py ``` Add the following code. ```bash # app.py from flask import Flask, render_template, request from model import PricePredictor import pandas as pd app = Flask(__name__) predictor = PricePredictor('mobile.csv') @app.route('/', methods=['GET', 'POST']) def index(): predicted_price = None if request.method == 'POST': input_data = { 'Spec Score': float(request.form['spec_score']), 'rating': float(request.form['rating']), 'Battery_mAh': float(request.form['battery']), 'Display_Inches': float(request.form['display']), 'Camera_MP': float(request.form['camera']), 'RAM_GB': float(request.form['ram']), 'Internal_Storage_GB': float(request.form['rom']), 'tag': request.form['tag'], 'sim': request.form['sim'], 'memoryExternal': request.form['memory_external'], 'Processor_Brand': request.form['processor_brand'], 'Version_Main': request.form['version_main'] } predicted_price = predictor.predict(input_data) return render_template('index.html', predicted_price=predicted_price) if __name__ == '__main__': app.run(host='0.0.0.0', port=5000, debug=True) ``` 2. Flask looks for HTML templates in a folder called templates. Let’s create it. ```bash mkdir templates ``` 3. Now create the HTML file inside the templates folder. ```bash nano templates/index.html ``` Add the following code. ```bash Mobile Price Predictor

📱 Mobile Phone Price Prediction

Spec Score:
Rating:
Battery mAh:
Display Inches:
Camera MP:
RAM GB:
ROM GB:
Tag:
SIM:
Memory External:
Processor Brand:
Version Main:
{% if predicted_price %}

💸 Predicted Price: ₹{{ predicted_price }}

{% endif %} ``` ## Step 5: Run the Application 1. With your Flask app and HTML template set up, you’re now ready to run the application and start serving predictions. ```bash python3 app.py ``` By default, this will start the Flask server on port **5000** and listen on all network interfaces (0.0.0.0), making it accessible from your browser. 2. Open your web browser and access the Flask app using the URL **http://your-server-ip:5000.** You should see a simple web form asking you to enter various specifications (like RAM, battery capacity, display size, etc.) for a mobile phone. ![](https://www.atlantic.net/wp-content/uploads/2025/07/p1-5.png) 3. Once you fill out the form, click on **Predict Price.** The trained XGBoost regression model processes the input and returns a predicted mobile phone price, which is displayed right on the page. ![](https://www.atlantic.net/wp-content/uploads/2025/07/p2-1.png) ## Conclusion In this article, we built a complete mobile phone price prediction system from scratch using Python, XGBoost, and Flask on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). We prepared the server environment, downloaded and processed a real-world dataset, trained a regression model, and deployed a user-friendly web interface for real-time predictions. --- # Machine Learning Pipeline for Malicious URL Detection on an Ubuntu 24.04 GPU server > URL: https://www.atlantic.net/gpu-server-hosting/machine-learning-pipeline-for-malicious-url-detection-on-an-ubuntu-24-04-gpu-server/ | Published: 2025-07-25 | Updated: 2026-05-04 | Author: Hitesh Jethva Cybersecurity threats continue to grow, and malicious URLs have become one of the most common vectors for phishing, malware delivery, and other online attacks. Detecting these URLs manually or using traditional blacklists is often ineffective because attackers can easily generate new domains to evade detection. This is where machine learning comes in. By learning patterns from known malicious and benign URLs, a machine learning model can generalize and classify previously unseen URLs more effectively than static rules or blocklists. In this guide, we will build a comprehensive machine learning pipeline for detecting malicious URLs. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Set up Python Environment Before we build and deploy our malicious URL detection pipeline, we need to set up a proper development environment on server. 1. Install required dependencies. ```bash apt install -y python3 python3-pip python3-venv ``` 2. Create a Python virtual environment. ```bash python3 -m venv url-venv source url-venv/bin/activate ``` 3. Upgrade pip to the latest version. ```bash pip install --upgrade pip ``` 4. Install required Python packages. ```bash pip3 install -U -q scikit-learn joblib seaborn colorama tld plotly whois wordcloud gensim nltk tldextract hmmlearn xgboost lightgbm catboost flask ``` ## Step 2: Download the Dataset Now that our environment is ready, we need to get the dataset onto the server and prepare it for machine learning. The dataset we’ll use contains labeled malicious and benign URLs, and it’s available from Kaggle. 1. On your server, create a directory for the project. ```bash mkdir /root/project ``` 2. Next, download the [dataset](https://www.kaggle.com/code/thisishusseinali/malicious-url-detection/input) from Kaggle on your local machine. 3. Use scp (secure copy) to upload the dataset from your local machine to the server. ```bash scp Downloads/malicious_phish.csv.zip root@your-server-ip:/root/project/ ``` 4. On the server, navigate to the project directory and unzip the dataset file. ```bash cd /root/project unzip malicious_phish.csv.zip ``` You should now see **malicious_phish.csv** in the **/root/project** directory. ## Step 3: Model Training and Evaluation With our dataset prepared, we are ready to train the machine learning model that will classify URLs as benign, phishing or malicious. 1. Create the training script. ```bash nano malicious_url_detection.py ``` Add the following code: ```bash import pandas as pd import numpy as np import hashlib import re import ipaddress from urllib.parse import urlparse import tldextract from sklearn.model_selection import train_test_split, cross_val_score, cross_val_predict from sklearn.pipeline import Pipeline from sklearn.ensemble import ExtraTreesClassifier from sklearn.metrics import accuracy_score, recall_score, precision_score, f1_score, classification_report import joblib # ---------------------- # Utility functions # ---------------------- def get_url_length(url): prefixes = ['http://', 'https://'] for prefix in prefixes: if url.startswith(prefix): url = url[len(prefix):] url = url.replace('www.', '') return len(url) def count_letters(url): return sum(c.isalpha() for c in url) def count_digits(url): return sum(c.isdigit() for c in url) def count_special_chars(url): return sum(c in "!@#$%^&*()_+-=[]{};:,.<>/?`~|" for c in url) def has_shortening_service(url): pattern = re.compile(r'bit\.ly|goo\.gl|tinyurl|t\.co|ow\.ly|bitly|is\.gd|cutt\.ly') return int(bool(pattern.search(url))) def abnormal_url(url): parsed = urlparse(url) hostname = parsed.hostname return int(bool(hostname and re.search(hostname, url))) def secure_http(url): return int(urlparse(url).scheme == 'https') def have_ip_address(url): try: parsed = urlparse(url) if parsed.hostname: ip = ipaddress.ip_address(parsed.hostname) return isinstance(ip, (ipaddress.IPv4Address, ipaddress.IPv6Address)) except ValueError: return 0 return 0 def hash_encode(val): return int(hashlib.md5(val.encode()).hexdigest(), 16) % (10 ** 8) # ---------------------- # Load dataset # ---------------------- data = pd.read_csv("malicious_phish.csv") # replace with your actual file path print(f"Loaded dataset: {data.shape[0]} rows") # ---------------------- # Label encoding # ---------------------- label_mapping = {'benign': 0, 'defacement': 1, 'phishing': 2, 'malware': 3} data['url_type'] = data['type'].map(label_mapping) # ---------------------- # Feature engineering # ---------------------- data['url_len'] = data['url'].apply(lambda x: get_url_length(str(x))) data['letters_count'] = data['url'].apply(lambda x: count_letters(str(x))) data['digits_count'] = data['url'].apply(lambda x: count_digits(str(x))) data['special_chars_count'] = data['url'].apply(lambda x: count_special_chars(str(x))) data['shortened'] = data['url'].apply(lambda x: has_shortening_service(str(x))) data['abnormal_url'] = data['url'].apply(lambda x: abnormal_url(str(x))) data['secure_http'] = data['url'].apply(lambda x: secure_http(str(x))) data['have_ip'] = data['url'].apply(lambda x: have_ip_address(str(x))) data['root_domain'] = data['url'].apply(lambda x: hash_encode(tldextract.extract(str(x)).domain)) data['url_region'] = data['url'].apply(lambda x: hash_encode(x.split('.')[-1])) # ---------------------- # Prepare dataset for training # ---------------------- feature_cols = [ 'url_len', 'letters_count', 'digits_count', 'special_chars_count', 'shortened', 'abnormal_url', 'secure_http', 'have_ip', 'url_region', 'root_domain' ] X = data[feature_cols] y = data['url_type'] print(f"Feature matrix: {X.shape}") print(f"Labels: {y.shape}") # ---------------------- # Train-test split # ---------------------- X_train, X_test, y_train, y_test = train_test_split(X, y, test_size=0.3, random_state=42) # ---------------------- # Train model # ---------------------- clf = Pipeline([('classifier', ExtraTreesClassifier(random_state=42))]) clf.fit(X_train, y_train) # ---------------------- # Evaluate model # ---------------------- y_pred = clf.predict(X_test) print("\nClassification report on test set:") print(classification_report(y_test, y_pred)) # ---------------------- # Save model # ---------------------- joblib.dump(clf, "eTc.sav") print("\n✅ Model saved as eTc.sav") # ---------------------- # Save feature column order for consistency # ---------------------- joblib.dump(feature_cols, "feature_order.sav") print("✅ Feature order saved as feature_order.sav") ``` The above script: - Loads the dataset - Applies feature engineering - Splits the data into training and testing sets - Trains an ensemble classifier (ExtraTreesClassifier) - Evaluates model performance - Saves both the trained model and the feature order for later inference 2. Run the training script. ```bash python3 malicious_url_detection.py ``` Output. ```bash Classification report on test set: precision recall f1-score support 0 0.95 0.98 0.96 128733 1 0.91 0.98 0.94 28692 2 0.87 0.68 0.77 28234 3 0.98 0.92 0.95 9699 accuracy 0.93 195358 macro avg 0.93 0.89 0.90 195358 weighted avg 0.93 0.93 0.93 195358 ✅ Model saved as eTc.sav ✅ Feature order saved as feature_order.sav ``` This shows strong predictive performance overall, with a weighted average accuracy of around 93%. ## Step 4: Build Flask App Now that our malicious URL detection model is trained and saved, the next step is to make it accessible via a simple web interface. We’ll use Flask, a lightweight Python web framework, to deploy the model, allowing users to submit URLs and receive predictions in real-time. 1. Create an application file. ```bash nano app.py ``` Add the following code. ```bash from flask import Flask, render_template, request import joblib import numpy as np import pandas as pd import re import hashlib from urllib.parse import urlparse import tldextract import ipaddress app = Flask(__name__) # Load trained model and feature order model = joblib.load('eTc.sav') feature_cols = joblib.load('feature_order.sav') class_mapping = {0: 'Benign', 1: 'Defacement', 2: 'Phishing', 3: 'Malware'} TRUSTED_DOMAINS = ['google.com', 'youtube.com', 'facebook.com', 'github.com', 'amazon.com'] # Utility functions def get_url_length(url): prefixes = ['http://', 'https://'] for prefix in prefixes: if url.startswith(prefix): url = url[len(prefix):] url = url.replace('www.', '') return len(url) def count_letters(url): return sum(c.isalpha() for c in url) def count_digits(url): return sum(c.isdigit() for c in url) def count_special_chars(url): return sum(c in "!@#$%^&*()_+-=[]{};:,.<>/?`~|" for c in url) def has_shortening_service(url): pattern = re.compile(r'bit\.ly|goo\.gl|tinyurl|t\.co|ow\.ly|bitly|is\.gd|cutt\.ly') return int(bool(pattern.search(url))) def abnormal_url(url): parsed = urlparse(url) hostname = parsed.hostname return int(bool(hostname and re.search(hostname, url))) def secure_http(url): return int(urlparse(url).scheme == 'https') def have_ip_address(url): try: parsed = urlparse(url) if parsed.hostname: ip = ipaddress.ip_address(parsed.hostname) return isinstance(ip, (ipaddress.IPv4Address, ipaddress.IPv6Address)) except ValueError: return 0 return 0 def hash_encode(val): return int(hashlib.md5(val.encode()).hexdigest(), 16) % (10 ** 8) def get_features(url): url_len = get_url_length(url) letters_count = count_letters(url) digits_count = count_digits(url) special_chars_count = count_special_chars(url) shortened = has_shortening_service(url) abnormal = abnormal_url(url) secure_https = secure_http(url) have_ip = have_ip_address(url) root_domain = hash_encode(tldextract.extract(url).domain) url_region = hash_encode(url.split('.')[-1]) return { 'url_len': url_len, 'letters_count': letters_count, 'digits_count': digits_count, 'special_chars_count': special_chars_count, 'shortened': shortened, 'abnormal_url': abnormal, 'secure_http': secure_https, 'have_ip': have_ip, 'url_region': url_region, 'root_domain': root_domain } @app.route('/', methods=['GET', 'POST']) def index(): prediction = None if request.method == 'POST': url = request.form['url'] parsed_url = urlparse(url) hostname = parsed_url.hostname or '' if any(trusted in hostname.lower() for trusted in TRUSTED_DOMAINS): prediction = 'Benign (trusted domain override)' else: feature_dict = get_features(url) feature_values = [feature_dict[col] for col in feature_cols] features_df = pd.DataFrame([feature_values], columns=feature_cols) pred_idx = model.predict(features_df)[0] prediction = class_mapping.get(pred_idx, 'Unknown') return render_template('index.html', prediction=prediction) if __name__ == '__main__': app.run(host='0.0.0.0', port=5000, debug=True) ``` The above script does the following: - Loads the trained model (eTc.sav) and saved feature columns (feature_order.sav) - Accepts URL input from users via a web form - Extracts features from the input URL (using the same feature engineering logic as during training) - Returns the predicted classification (Benign, Defacement, Phishing, or Malware) 2. Create a **templates** directory and an **index.html** file that defines the user interface. ```bash mkdir templates nano templates/index.html ``` Add the following code. ```bash Malicious URL Detector

🔒 Malicious URL Detector

{% if prediction %}
Prediction: {{ prediction }}
{% endif %} ``` ## Step 5: Run the Flask App and Access the Web UI At this point, our Flask web application is ready to serve predictions using the trained malicious URL detection model. Let’s go over how to start the app and access it from your browser. 1. Start the Flask server with the following command. ```bash python3 app.py ``` Output. ```bash * Running on all addresses (0.0.0.0) * Running on http://127.0.0.1:5000 * Running on http://149.28.70.3:5000 Press CTRL+C to quit * Restarting with stat * Debugger is active! * Debugger PIN: 759-456-018 ``` 2. Open your web browser and access the Flask App using the URL **http://your-server-ip:5000.** You should see the “Malicious URL Detector” interface 3. Enter a suspicious-looking or synthetic malicious URL in the text box and click on **Check URL.** The app will analyze the URL, extract its features, classify it and show the response below the text box. ![](https://www.atlantic.net/wp-content/uploads/2025/07/p1-4.png) ## Conclusion In this guide, we developed a comprehensive machine learning pipeline for detecting malicious URLs on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). Starting from environment setup, we prepared the dataset, engineered meaningful features, and trained a robust classification model using ExtraTreesClassifier. We then deployed the trained model as a user-friendly web application using Flask, allowing real-time predictions through a simple browser interface. Users can now submit any URL and immediately get a prediction: whether it is benign, defacement, phishing, or malware. --- # Fraction Problem Solving Using Machine Learning on Ubuntu 24.04 Cloud GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/fraction-problem-solving-using-machine-learning-on-ubuntu-24-04-cloud-gpu-server/ | Published: 2025-07-26 | Updated: 2026-05-04 | Author: Hitesh Jethva Fractions are a fundamental part of mathematics education and have practical applications in fields such as engineering, finance, and data analysis. However, automating fraction arithmetic is a non-trivial task, especially when the input is expressed as human-readable text (e.g., “1/2 + 1/3”). Traditionally, such problems are solved using rule-based algorithms that parse and compute exact answers. But what if we could teach a machine learning (ML) model to understand and solve these problems by learning patterns from examples? This approach not only offers opportunities for innovation but also opens the door to interactive educational tools, AI tutors, and intelligent calculators. In this project, we’ll walk through building a fraction problem solver using machine learning on an Ubuntu 24.04 [cloud GPU server](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/). ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Set up Python Environment Before we start generating datasets or training models, we need a clean and isolated Python environment with the required libraries. 1. Install core dependencies. ```bash apt install -y python3 python3-pip python3-venv ``` 2. Create a virtual environment. ```bash python3 -m venv ml-fraction-env ``` 3. Activate the environment to make sure all Python libraries are installed locally within it. ```bash source ml-fraction-env/bin/activate ``` 4. Upgrade pip and install all the libraries we’ll need for this project, including NumPy, pandas, TensorFlow, and Flask. ```bash pip install --upgrade pip pip install numpy pandas tensorflow flask ``` ## Step 2: Generate Dataset To train a machine learning model that can “understand” and solve fraction problems, we need a large dataset containing fraction expressions and their correct solutions. Instead of manually collecting data, we can generate synthetic data programmatically. 1. Write a Python script (generate_dataset.py) that automatically generates random fraction problems using basic arithmetic operators **(+, −, ×, ÷)** and computes their exact solutions. ```bash nano generate_dataset.py ``` Add the following code. ```bash import random from fractions import Fraction import pandas as pd def random_fraction(): numerator = random.randint(1, 10) denominator = random.randint(1, 10) return Fraction(numerator, denominator) def generate_problem(): ops = ['+', '-', '*', '/'] a = random_fraction() b = random_fraction() op = random.choice(ops) problem = f"{a} {op} {b}" try: if op == '+': solution = a + b elif op == '-': solution = a - b elif op == '*': solution = a * b elif op == '/': solution = a / b if b != 0 else 'undefined' except: solution = 'undefined' return problem, str(solution) # Generate 100,000 records data = [generate_problem() for _ in range(100000)] df = pd.DataFrame(data, columns=['problem', 'solution']) df.to_csv('fraction_dataset.csv', index=False) print("✅ Dataset saved to fraction_dataset.csv") ``` 2. Run the script to generate and save the dataset. ```bash python3 generate_dataset.py ``` After execution, you should see the confirmation. ```bash ✅ Dataset saved to fraction_dataset.csv ``` ## Step 3: Model Architecture & Training With our dataset ready, the next step is to train a machine learning model that can learn to solve fraction problems by predicting the correct result when given an expression. 1. Create a script to train the model. ```bash nano train_model.py ``` Add the following code. ```bash import pandas as pd import numpy as np from tensorflow.keras.preprocessing.text import Tokenizer from tensorflow.keras.preprocessing.sequence import pad_sequences from tensorflow.keras.models import Sequential from tensorflow.keras.layers import Embedding, LSTM, Dense, TimeDistributed from tensorflow.keras.callbacks import EarlyStopping, ModelCheckpoint import pickle # Load dataset df = pd.read_csv('fraction_dataset.csv') # Tokenizer (character-level) tokenizer = Tokenizer(char_level=True) tokenizer.fit_on_texts(df['problem'].tolist() + df['solution'].tolist()) vocab_size = len(tokenizer.word_index) + 1 # Convert to sequences X_seq = tokenizer.texts_to_sequences(df['problem'].tolist()) y_seq = tokenizer.texts_to_sequences(df['solution'].tolist()) # Pad sequences max_len = 20 X = pad_sequences(X_seq, maxlen=max_len, padding='post') y = pad_sequences(y_seq, maxlen=max_len, padding='post') # 📝 Reshape y for categorical output at each timestep y = np.expand_dims(y, -1) # Define correct sequence-to-sequence model model = Sequential([ Embedding(input_dim=vocab_size, output_dim=64, input_length=max_len), LSTM(128, return_sequences=True), # 🔥 Important change here! TimeDistributed(Dense(vocab_size, activation='softmax')) # 🔥 Predict vocab distribution at each timestep ]) model.compile(optimizer='adam', loss='sparse_categorical_crossentropy', metrics=['accuracy']) # Callbacks early_stop = EarlyStopping(monitor='val_loss', patience=5, restore_best_weights=True) checkpoint = ModelCheckpoint('best_fraction_solver_model.h5', save_best_only=True) # 🚀 Train for 30 epochs history = model.fit( X, y, epochs=30, batch_size=64, validation_split=0.1, callbacks=[early_stop, checkpoint] ) # Save tokenizer for inference with open('tokenizer.pkl', 'wb') as f: pickle.dump(tokenizer, f) print("✅ Training complete. Best model saved as best_fraction_solver_model.h5") ``` This script trains a character-level LSTM model to predict solutions for fraction problems. It tokenizes and pads input-output text, then uses a TimeDistributed layer for character prediction. The trained model and tokenizer are saved for later use. 2. Run the script. ```bash python3 train_model.py ``` Output. ```bash ✅ Training complete. Best model saved as best_fraction_solver_model.h5 ``` ## Step 4: Building the Flask Web Interface After training our machine learning model, we aim to provide a straightforward way for users to input fraction problems and receive solutions through a simple web interface. Flask is a lightweight web framework that makes this straightforward. 1. Create the Flask application script. ```bash nano app.py ``` Add the following code. ```bash from flask import Flask, request, render_template_string from fractions import Fraction import re app = Flask(__name__) TEMPLATE = ''' Hybrid Fraction Solver

Fraction Problem Solver (Hybrid: ML UI + Exact Backend)

Enter fraction problem (e.g. 1/2 + 1/3): {% if solution %}

Solution: {{ solution }}

{% endif %} ''' def solve_fraction_expression(expr): # Basic sanitization: remove spaces expr = expr.replace(' ', '') # Regex to extract operands and operator pattern = r'(\d+/\d+)([\+\-\*/])(\d+/\d+)' match = re.match(pattern, expr) if not match: return "Invalid input format" frac1, op, frac2 = match.groups() try: f1 = Fraction(frac1) f2 = Fraction(frac2) if op == '+': result = f1 + f2 elif op == '-': result = f1 - f2 elif op == '*': result = f1 * f2 elif op == '/': if f2 == 0: result = "undefined" else: result = f1 / f2 else: result = "Invalid operator" return str(result) except Exception as e: return f"Error: {str(e)}" @app.route('/', methods=['GET', 'POST']) def index(): solution = None if request.method == 'POST': problem = request.form['problem'] solution = solve_fraction_expression(problem) return render_template_string(TEMPLATE, solution=solution) if __name__ == '__main__': app.run(host='0.0.0.0', port=5000) ``` 2. Run the Flask application. ```bash python3 app.py ``` Output. ```bash * Running on all addresses (0.0.0.0) * Running on http://127.0.0.1:5000 * Running on http://45.76.67.103:5000 Press CTRL+C to quit ``` ## Step 5: Access the Flask App 1. Open your web browser and access the Flask app using the URL **http://your-server-ip:5000.** You will be greeted with a simple but functional web form. 2. Enter a fraction problem **(e.g., 3/4 + 4/7)**. 3. Click the **Solve** button. 4. The page will refresh and display the exact solution below the form. ![](https://www.atlantic.net/wp-content/uploads/2025/07/p1-3.png) ## Conclusion In this article, we created a fraction problem solver by combining machine learning and traditional Python arithmetic, deployed on an Ubuntu 24.04 cloud GPU server. We generated a large dataset of fraction problems, trained a sequence-to-sequence model, and built a simple Flask web interface for user interaction. While the current version computes exact solutions on the backend, the system is ready for integration with the trained model for prediction-based solving. --- # Cryptocurrency Price Prediction with Machine Learning on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/cryptocurrency-price-prediction-with-machine-learning-on-ubuntu-24-04-gpu-server/ | Published: 2025-07-27 | Updated: 2026-05-04 | Author: Hitesh Jethva Predicting cryptocurrency prices has become a popular application of machine learning. Crypto markets, such as Bitcoin (BTC) and Ethereum (ETH), are renowned for their volatility, and many developers and researchers are utilizing machine learning models to analyze historical price data and predict future trends. In this guide, you’ll learn how to build a cryptocurrency price prediction system using machine learning and deploy it on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). We’ll use Python and popular libraries like TensorFlow, scikit-learn, and Flask to develop and serve our prediction model. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Install Required Packages Before we can start building and training our cryptocurrency price prediction model, we need to set up the development environment on your Ubuntu 24.04 GPU server. 1. First, make sure your system is up to date and install essential packages. ```bash apt update -y apt install -y python3 python3-pip python3-venv git build-essential ``` 2. It’s a good practice to isolate your project’s dependencies using a virtual environment. ```bash python3 -m venv crypto-predict-env source crypto-predict-env/bin/activate ``` 3. Next, upgrade pip and install all the Python libraries required for this project. ```bash pip install --upgrade pip pip install flask tensorflow pandas numpy yfinance scikit-learn ``` Here’s what these packages are used for: - **Flask:** For building the web application. - **TensorFlow:** For training and running our LSTM neural network. - **pandas** & **numpy:** For handling and processing data. - **yfinance:** To fetch cryptocurrency price data from Yahoo Finance. - **scikit-learn:** For scaling and preparing the data. ## Step 2: Train the Machine Learning Model Now that your environment is set up, it’s time to build and train the machine learning model that will predict cryptocurrency prices. In this project, we’ll use an LSTM (Long Short-Term Memory) neural network, which is well-suited for time-series prediction tasks like price forecasting. 1. Create a Python script called train_model.py to handle downloading data, preprocessing, building the model, and training it. ```bash nano train_model.py ``` Add the below code: ```bash # train_model.py import yfinance as yf import numpy as np from sklearn.preprocessing import MinMaxScaler from tensorflow.keras.models import Sequential from tensorflow.keras.layers import LSTM, Dense # Download BTC-USD historical data data = yf.download('BTC-USD', start='2020-01-01', end='2025-01-01') dataset = data['Close'].values.reshape(-1, 1) # Normalize prices scaler = MinMaxScaler() scaled_data = scaler.fit_transform(dataset) # Prepare training sequences seq_length = 60 X_train, y_train = [], [] for i in range(seq_length, len(scaled_data)): X_train.append(scaled_data[i-seq_length:i, 0]) y_train.append(scaled_data[i, 0]) X_train, y_train = np.array(X_train), np.array(y_train) X_train = X_train.reshape((X_train.shape[0], X_train.shape[1], 1)) # Build LSTM model model = Sequential([ LSTM(50, return_sequences=True, input_shape=(X_train.shape[1], 1)), LSTM(50), Dense(25), Dense(1) ]) model.compile(optimizer='adam', loss='mean_squared_error') # Train the model model.fit(X_train, y_train, epochs=10, batch_size=32) # Save the model import os os.makedirs('model', exist_ok=True) model.save('model/crypto_model.h5') print("✅ Model trained and saved at 'model/crypto_model.h5'") ``` 2. After saving the file, run the script to start the training process. ```bash python3 train_model.py ``` During training, you’ll see progress output showing loss values for each epoch. Once training is done, the model will be saved in a folder called model as crypto_model.h5. ## Step 3: Build Flask Web Application for Predictions After training and saving our model, we’ll now create a Flask web application. This app will allow users to enter a cryptocurrency symbol (e.g., BTC-USD or ETH-USD), and it will fetch recent price data, load the trained model, and display a predicted next price. 1. Create the Flask app script. ```bash nano app.py ``` Add the following code. ```bash # app.py from flask import Flask, request, render_template import numpy as np import pandas as pd import yfinance as yf from sklearn.preprocessing import MinMaxScaler from tensorflow.keras.models import load_model app = Flask(__name__) model = load_model('model/crypto_model.h5') scaler = MinMaxScaler() def prepare_data(symbol='BTC-USD', seq_length=60): data = yf.download(symbol, period='90d', interval='1h') close_prices = data['Close'].values.reshape(-1, 1) scaled = scaler.fit_transform(close_prices) X_input = scaled[-seq_length:] X_input = X_input.reshape((1, seq_length, 1)) return X_input, close_prices[-1][0] @app.route('/', methods=['GET', 'POST']) def index(): prediction = None last_price = None symbol = "BTC-USD" if request.method == 'POST': symbol = request.form.get('symbol', 'BTC-USD') try: X_input, last_price = prepare_data(symbol) pred_scaled = model.predict(X_input) pred_price = scaler.inverse_transform(pred_scaled)[0][0] prediction = round(pred_price, 2) except Exception as e: prediction = f"Error: {str(e)}" return render_template('index.html', prediction=prediction, symbol=symbol, last_price=last_price) if __name__ == '__main__': app.run(host='0.0.0.0', port=5000) ``` The above script: - Loads your trained model (crypto_model.h5). - Fetches the most recent 90 days of price data. - Normalizes it so the model can use it for prediction. - Handles form submissions to let the user enter any cryptocurrency symbol. - Displays prediction results using an HTML template. 2. Prepare templates directory. ```bash mkdir templates ``` 3. Create the index.html template. ```bash nano templates/index.html ``` Add the following code. ```bash Crypto Price Prediction

Crypto Price Prediction





{% if prediction %}

Prediction Result:

Symbol: {{ symbol }}

Last Close Price: {{ last_price }}

Predicted Next Price: {{ prediction }}

{% endif %} ``` ## Step 4: Run the Web Application Now it’s time to run the application and access it from your browser. 1. Run this command in your terminal to launch the Flask server. ```bash python3 app.py ``` Output. ```bash * Running on all addresses (0.0.0.0) * Running on http://127.0.0.1:5000 * Running on http://149.28.70.3:5000 INFO:werkzeug:Press CTRL+C to quit ``` 2. Open your web browser and access the Flask web app using the URL **http://your-server-ip:5000.** 3. Enter a cryptocurrency symbol (like BTC-USD or ETH-USD). Click the **Predict** button. The app fetches recent price data automatically using yfinance. ![](https://www.atlantic.net/wp-content/uploads/2025/07/p1-1.png) ## Conclusion In this guide, you built a cryptocurrency price prediction web application from scratch using machine learning on an Ubuntu 24.04 GPU server. You installed all the necessary tools, trained an LSTM neural network on historical Bitcoin data, and deployed a Flask-based web interface to make predictions accessible directly in a web browser. --- # Fake News Detection Using Machine Learning on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/fake-news-detection-using-machine-learning-on-ubuntu-24-04-gpu-server/ | Published: 2025-07-28 | Updated: 2025-08-01 | Author: Hitesh Jethva Fake news has become a major challenge in today’s digital age, where false information spreads quickly across social media and online platforms. With the growing influence of news on public opinion, it’s essential to detect and stop misinformation before it goes viral. Traditional methods for manually verifying news are no longer practical due to the sheer volume of content published daily. This is where Machine Learning (ML) plays a critical role — by automatically analyzing patterns in news articles to classify them as real or fake based on their content. In this guide, we will show you how to build a Fake News Detection system using Machine Learning on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Set up Python Environment First, update your system and install Python 3 along with essential tools. ```bash apt update -y apt install -y python3 python3-pip python3-venv build-essential ``` 2. Create and activate a virtual environment. ```bash python3 -m venv fakenews-venv source fakenews-venv/bin/activate ``` 3. Now, install all required Python packages using pip. ```bash pip install numpy pandas scikit-learn flask ``` 4. We also install PyTorch libraries, which are not directly used in this project but can enable GPU acceleration for future improvements. ```bash pip install torch torchvision ``` 5. We’ll use the Kaggle CLI tool to download the dataset directly from Kaggle. ```bash pip install kaggle ``` ## Step 2: Download and Prepare the Dataset Now that your environment is ready, we’ll download the dataset and prepare it for model training. 1. Go to your **Kaggle** account settings. 2. Create and download an API token (a **kaggle.json** file). 3. Place **kaggle.json** in **~/.kaggle/.** 4. Download the dataset from Kaggle. ```bash kaggle datasets download -d emineyetm/fake-news-detection-datasets ``` 5. Once the download completes, unzip the dataset. ```bash unzip fake-news-detection-datasets.zip ``` 6. You should see a folder called News _dataset containing two CSV files. ```bash ls News\ _dataset/ ``` Output. ```bash Fake.csv True.csv ``` 7. Let’s move the dataset files into the current working directory for convenience. ```bash mv News\ _dataset/*.csv . ``` ## Step 3: Prepare and Train Data In this section, we’ll prepare the dataset and train a machine learning model to classify news as real or fake. 1. Create a Python script. ```bash nano prepare_and_train_data.py ``` Add the following code. ```bash import pandas as pd import re from sklearn.model_selection import train_test_split from sklearn.feature_extraction.text import TfidfVectorizer # Step 1: Load and label data fake = pd.read_csv('Fake.csv') true = pd.read_csv('True.csv') fake['label'] = 0 true['label'] = 1 data = pd.concat([fake, true]).sample(frac=1).reset_index(drop=True) # Step 2: Preprocess text def clean_text(text): text = re.sub(r'[^a-zA-Z ]', '', text) text = text.lower() return text data['text'] = data['title'] + " " + data['text'] data['text'] = data['text'].apply(clean_text) # Step 3: Feature extraction X = data['text'] y = data['label'] X_train, X_test, y_train, y_test = train_test_split( X, y, test_size=0.2, random_state=42 ) vectorizer = TfidfVectorizer(stop_words='english', max_df=0.7) X_train_tfidf = vectorizer.fit_transform(X_train) X_test_tfidf = vectorizer.transform(X_test) # Step 4: Train model from sklearn.linear_model import LogisticRegression from sklearn.metrics import accuracy_score, classification_report # Train the Logistic Regression model model = LogisticRegression(max_iter=1000) model.fit(X_train_tfidf, y_train) # Make predictions on the test set y_pred = model.predict(X_test_tfidf) # Print accuracy and a classification report print("Accuracy:", accuracy_score(y_test, y_pred)) print("Classification report:\n", classification_report(y_test, y_pred)) # Step 5: Save the model import joblib # Save the trained model joblib.dump(model, 'fakenews_model.pkl') # Save the TF-IDF vectorizer joblib.dump(vectorizer, 'tfidf_vectorizer.pkl') print("Model and vectorizer saved successfully!") ``` This script loads and cleans fake and genuine news data, converts the text into numerical features using TF-IDF, and splits it into training and test sets. It trains a Logistic Regression model to classify news as fake or true, evaluates its performance, and saves both the trained model and vectorizer for future use. 2. Run the script to train and save the model. ```bash python3 prepare_and_train_data.py ``` Expected output. ```bash Accuracy: 0.9867483296213808 Classification report: precision recall f1-score support 0 0.99 0.99 0.99 4705 1 0.99 0.99 0.99 4275 accuracy 0.99 8980 macro avg 0.99 0.99 0.99 8980 weighted avg 0.99 0.99 0.99 8980 Model and vectorizer saved successfully! ``` ## Step 4: Build Flask Web Application Now that we have a trained model and vectorizer saved **(fakenews_model.pkl** and **tfidf_vectorizer.pkl),** we can build a simple web app using Flask, allowing users to paste news text and receive an instant prediction. 1. Create the Flask app. ```bash nano app.py ``` Add the following code: ```bash from flask import Flask, render_template, request import joblib app = Flask(__name__) model = joblib.load('fakenews_model.pkl') vectorizer = joblib.load('tfidf_vectorizer.pkl') @app.route('/', methods=['GET', 'POST']) def index(): prediction = None if request.method == 'POST': user_text = request.form['news'] user_text_clean = user_text.lower() user_features = vectorizer.transform([user_text_clean]) pred = model.predict(user_features)[0] prediction = 'Real News' if pred == 1 else 'Fake News' return render_template('index.html', prediction=prediction) if __name__ == '__main__': app.run(host='0.0.0.0', port=5000, debug=True) ``` This script: - Initializes the Flask app. - Loads the saved model and vectorizer. - Handles both GET (show empty form) and POST (process user input) requests. - Displays the prediction back to the user. 2. Create a directory for templates. ```bash mkdir templates ``` 3. Create the file index.html for the web interface. ```bash nano templates/index.html ``` Add the following HTML code: ```bash Fake News Detector

Fake News Detection Web App


{% if prediction %}

Prediction: {{ prediction }}

{% endif %} ``` ## Step 5: Run Flask Application Now that both the backend (app.py) and frontend (index.html) are ready, let’s run the Flask app so it can serve predictions from your trained model. 1. Start the Flask server. ```bash python3 app.py ``` Output. ```bash * Serving Flask app 'app' * Debug mode: on WARNING: This is a development server. Do not use it in a production deployment. Use a production WSGI server instead. * Running on all addresses (0.0.0.0) * Running on http://127.0.0.1:5000 * Running on http://149.28.70.3:5000 Press CTRL+C to quit * Restarting with stat * Debugger is active! * Debugger PIN: 212-816-210 ``` 2. Open your web browser and access the Flask app using the URL **http://your-server-ip:5000.** You should see a simple page titled ‘**Fake News Detection Web App**‘ with a text area and a **‘Detect’** button. 3. Copy a news article headline or snippet from any online news source. **Paste** it into the textarea and click the **Detect** button. The app will process your input, run it through the trained model, and return one of the following results. ![](https://www.atlantic.net/wp-content/uploads/2025/07/p1-2.png) ## Conclusion In this guide, you built a fake news detection system using machine learning on an Ubuntu 24.04 GPU server. You trained a model, deployed it with Flask, and created a simple web interface for real-time predictions. This project provides a practical foundation for exploring text classification and machine learning deployment. You can now enhance the app further or share it with others for testing and feedback. --- # Importance of SOC Type 2, HIPAA, and GDPR Compliance in Website Accessibility > URL: https://www.atlantic.net/hipaa-compliant-hosting/importance-of-soc-type-2-hipaa-and-gdpr-compliance-in-website-accessibility/ | Published: 2025-07-29 | Updated: 2026-06-05 | Author: Editorial Team Ensuring a website’s accessibility refers not only to its conformance with the Web Content Accessibility Guidelines (WCAG) but also to safeguarding privacy, security, and each user’s rights. Every sector, including healthcare, finance, and SaaS, requires compliance with critical frameworks like SOC 2, HIPAA, and GDPR. These standards play a vital role in making a website inclusive. Their implication for digital accessibility is important in order to provide a safe space from data theft. So, when it comes to an inclusive digital environment, SOC 2, HIPAA, and GDPR compliance are equally crucial as WCAG. Read along to know more about these three crucial facets of digital compliance. ## Understanding These Compliance Frameworks 1. **What is SOC 2 and SOC Type 2?** SOC 2 (System and Organization Controls 2) is a framework developed by the American Institute of CPAs (AICPA). It evaluates how well a service provider manages customer data based on five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. SOC Type 2 specifically assesses the operational effectiveness of a company’s systems over a period (typically 3-12 months), making it highly relevant for SaaS platforms and cloud-based service providers. 1. **What is HIPAA?** The Health Insurance Portability and Accountability Act (HIPAA) regulates how healthcare providers, insurers, and their business associates handle Protected Health Information (PHI). It requires safe data storage, user authentication, encryption, and breach notification. HIPAA also requires that digital systems – including websites and patient portals – be accessible to users with disabilities. 1. **What is GDPR?** The General Data Protection Regulation (GDPR) governs data protection and privacy for individuals in the European Union. It mandates explicit consent for data processing, the right to access and delete personal data, and robust data protection measures. For accessible websites, GDPR means ensuring that privacy controls are usable by everyone, including those using screen readers or alternative navigation tools. ## **The Link Between Compliance and Accessibility** 1. **Accessibility and data privacy go hand-in-hand** An accessible website must also be a secure and private environment for every user. For instance, visually impaired users may use screen readers that read out sensitive data – like account numbers or health records. If privacy measures are poorly implemented, such sensitive information could be inadvertently exposed in public or unsafe environments. (Best practice: auto-reading can be paused if not required). 1. **Trust and user confidence** If a user with a disability tries to book a doctor’s appointment online, they need a safe, accessible website. Inaccessible environments make them feel insecure, and they might not complete their task. On the other hand, a secure and accessible platform builds trust, encouraging engagement and repeat visits – especially when sensitive information is involved. 1. **Inclusive design meets secure design** SOC 2 and GDPR both emphasize the importance of secure architecture and user control. These principles naturally align with accessible design. For example, GDPR requires that cookie consent pop-ups are understandable and operable. When accessibility is part of security planning, the result is a more resilient and user-friendly system. 1. **Role of third-party accessibility tools** Many organizations turn to third-party accessibility solutions to support compliance and enhance user experiences. These tools – such as accessibility overlays, AI-driven screen reader support, automated testing tools, and real-time remediation widgets – can offer quick solutions and help identify gaps. However, while these tools are useful, they ought to also comply with data protection and security standards. For example: - A widget that collects user interactions must comply with GDPR consent requirements. - Any tool that handles form validation or login data must meet SOC 2 Type 2 security controls. - In healthcare, integrations must be HIPAA-compliant if they process or store PHI. Organizations should carefully vet third-party vendors for both accessibility performance and compliance alignment. ## **Benefits of Aligning Website Accessibility with Compliance Standards** When accessibility and compliance are approached together, organizations unlock a range of strategic, operational, and reputational advantages: - **Stronger legal protection** Meeting both accessibility and regulatory standards significantly lowers the risk of legal penalties, complaints, or lawsuits. It demonstrates a proactive stance toward inclusivity and user rights. - **Wider market reach** Accessibility makes a website more accessible to a broader audience, including people with disabilities and older users. When layered with GDPR and HIPAA compliance, organizations can confidently serve international and healthcare-sensitive markets. - **Improved SEO and performance** Accessible websites generally have cleaner code, faster load times, and structured content, which align with SEO best practices. Security and privacy enhancements from compliance also contribute to improved system performance and uptime (a SOC 2 benefit). - **Cost-efficiency through unified strategy** By building security, privacy, and usability into the development process from the start, organizations save money on retrofits, fines, and patchwork fixes. ## **Consequences of Non-Compliance** 1. **Legal and financial repercussions** - HIPAA violations can lead to fines of up to $1.5 million per violation category per year. - GDPR fines can go up to €20 million or 4% of global turnover, whichever is higher. (Source: [Non-compliance – 8 regulations have high penalties?](https://community.trustcloud.ai/docs/grc-launchpad/grc-101/compliance/which-regulations-have-high-penalties-for-non-compliance/)) - A SOC 2 audit failure may not result in fines, but can destroy customer trust and lead to loss of enterprise contracts. If a site is both inaccessible and non-compliant, it faces dual risks: legal action and user abandonment. 1. **Damage to brand reputation** Companies that fail to provide secure and accessible digital experiences may encounter backlash, especially from advocacy groups and consumers on social media. Lawsuits and news coverage can quickly erode years of brand equity. ## **Best Practices to Achieve Accessibility and Compliance!** 1. **Conducting regular audits** Perform automated [manual accessibility audits](https://www.skynettechnologies.com/website-accessibility-audit) alongside compliance assessments. Look for overlaps – such as how authentication systems or data forms function for assistive tech users. 1. **Choosing the right tools and vendors** Work with vendors that prioritize privacy, security, and accessibility. Whether it’s a CMS, analytics provider, or payment processor, ensure their tools meet SOC 2, HIPAA, and GDPR requirements and are accessible. 1. **Invest in training and governance** Train teams – especially developers and content creators – on the intersections of accessibility and compliance. Maintain clear internal policies that include both accessibility checklists and data privacy/security requirements. 1. **Transparency through privacy policies and statements** Include accessibility statements, privacy policies, and terms of use that clearly articulate organizations’ compliance efforts. Make sure these documents are easy to read and accessible. ## **Wrapping up** Accessibility is a continuous effort toward inclusion, privacy, and trust. Frameworks like SOC Type 2, HIPAA, and GDPR provide the foundation for secure and ethical digital experiences – but without accessibility, their reach remains limited. By treating compliance and accessibility as complementary goals, organizations can build digital platforms that not only meet legal standards but also empower every user – regardless of their abilities. Make compliance inclusive and accessibility secure. That’s the future of digital trust! ***This thought leadership article was contributed by Skynet Technologies.*** ***Skynet Technologies is a worldwide leader in digital accessibility compliance solution. Skynet Technologies offers an WCAG, ADA, European Accessibility Act (EAA) [accessibility widget](https://www.skynettechnologies.com/all-in-one-accessibility) – All in One Accessibility®, supports HIPAA, and GDPR compliant, and they are SOC Type 2 compliant.*** --- # Sign Language Recognition Using Machine Learning on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/sign-language-recognition-using-machine-learning-on-ubuntu-24-04-gpu-server/ | Published: 2025-07-30 | Updated: 2025-08-01 | Author: Hitesh Jethva Sign language is a vital means of communication for millions of people in the deaf and hard-of-hearing communities. However, the language barrier between sign language users and non-signers can create significant communication challenges. To bridge this gap, we can use machine learning techniques to automatically recognize hand gestures and translate them into readable text or speech. In this tutorial, you’ll learn how to build a real-time American Sign Language (ASL) recognition system using machine learning. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Set Up Python Environment First, ensure that Python 3 and related tools are installed on your system. ```bash apt update -y apt install -y python3 python3-pip python3-venv ``` Create a Python virtual environment. ```bash python3 -m venv asl-ml-env source asl-ml-env/bin/activate ``` Next, upgrade pip and install all required Python libraries. ```bash pip install --upgrade pip pip install kaggle tensorflow opencv-python matplotlib scikit-learn flask ``` Here’s a brief description of what we’re installing: - **tensorflow:** Core library for building and training our CNN model. - **opencv-python:** For handling images and capturing webcam input. - **matplotlib:** For plotting training metrics. - **scikit-learn:** For additional utilities if needed. - **flask:** A Lightweight web framework for creating web interfaces. - **kaggle:** CLI tool for downloading datasets from Kaggle. ## Step 2: Download ASL Alphabet Dataset from Kaggle You’ll need your Kaggle API key for this step. 1. Go to your **Kaggle** account settings. 2. Create and download an API token (a **kaggle.json** file). 3. Place **kaggle.json** in **~/.kaggle/.** 4. Download the ASL dataset. ```bash kaggle datasets download -d grassknoted/asl-alphabet ``` 5. Unzip the downloaded dataset. ```bash unzip asl-alphabet.zip ``` The dataset folder **asl_alphabet_train** will contain images for training and validation. ## Step 3: Model Development Now that our environment is ready and the dataset is downloaded, it’s time to build, train, and save the machine learning model that will recognize American Sign Language (ASL) letters from images. 1. Let’s create a Python script to define and train the CNN model. ```bash nano train_model.py ``` Add the following code: ```bash import os import tensorflow as tf from tensorflow.keras.preprocessing.image import ImageDataGenerator from tensorflow.keras import layers, models import matplotlib.pyplot as plt # Dataset directory path DATA_DIR = "asl_alphabet_train/asl_alphabet_train" # Parameters IMG_HEIGHT, IMG_WIDTH = 64, 64 BATCH_SIZE = 32 EPOCHS = 10 # Data augmentation and preprocessing datagen = ImageDataGenerator( rescale=1./255, validation_split=0.2 ) train_generator = datagen.flow_from_directory( DATA_DIR, target_size=(IMG_HEIGHT, IMG_WIDTH), batch_size=BATCH_SIZE, class_mode='categorical', subset='training' ) val_generator = datagen.flow_from_directory( DATA_DIR, target_size=(IMG_HEIGHT, IMG_WIDTH), batch_size=BATCH_SIZE, class_mode='categorical', subset='validation' ) # CNN model architecture model = models.Sequential([ layers.Conv2D(32, (3, 3), activation='relu', input_shape=(IMG_HEIGHT, IMG_WIDTH, 3)), layers.MaxPooling2D((2, 2)), layers.Conv2D(64, (3, 3), activation='relu'), layers.MaxPooling2D((2, 2)), layers.Conv2D(128, (3, 3), activation='relu'), layers.MaxPooling2D((2, 2)), layers.Flatten(), layers.Dense(128, activation='relu'), layers.Dense(len(train_generator.class_indices), activation='softmax') ]) # Compile model model.compile(optimizer='adam', loss='categorical_crossentropy', metrics=['accuracy']) # Train the model history = model.fit( train_generator, validation_data=val_generator, epochs=EPOCHS ) # Save the trained model model.save("asl_sign_model.h5") ``` 2. Run the script to start training. ```bash python3 train_model.py ``` This will take a few minutes, depending on your GPU. After training completes. The model will be saved as asl_sign_model.h5 ## Step 4: Model Evaluation After training the model, it’s essential to evaluate its performance to ensure that it generalizes well to unseen data. In this section, we’ll test the saved model on the validation dataset and display key metrics, such as validation loss and accuracy. 1. Let’s create a new script to load the trained model and run evaluation. ```bash nano evaluate_model.py ``` Add the following code: ```bash import tensorflow as tf from tensorflow.keras.models import load_model from tensorflow.keras.preprocessing.image import ImageDataGenerator # Load trained model model = load_model('asl_sign_model.h5') # Dataset directory DATA_DIR = "asl_alphabet_train" # Parameters IMG_HEIGHT, IMG_WIDTH = 64, 64 BATCH_SIZE = 32 # Prepare test/validation dataset again datagen = ImageDataGenerator(rescale=1./255, validation_split=0.2) val_generator = datagen.flow_from_directory( DATA_DIR, target_size=(IMG_HEIGHT, IMG_WIDTH), batch_size=BATCH_SIZE, class_mode='categorical', subset='validation' ) # Evaluate on validation dataset loss, accuracy = model.evaluate(val_generator) print(f"Validation Loss: {loss:.4f}") print(f"Validation Accuracy: {accuracy:.4f}") ``` 2. Run the evaluation script. ```bash python3 evaluate_model.py ``` Example output might look like this: ```bash Validation Loss: 2.2038 Validation Accuracy: 0.7276 ``` This means our model achieves **~72%** accuracy on validation data after just 10 epochs, which is a promising result for a basic implementation. ## Step 5: Web Application Development Now that we have a trained model ready, it’s time to build a web application that allows users to interact with the model in real-time via their webcam. We’ll use Flask as the backend framework and HTML/JavaScript for the frontend to display webcam video and show predictions. 1. First, set up the necessary files and folders for our web app. ```bash mkdir templates ``` 2. Create the HTML frontend. ```bash nano templates/index.html ``` Add the below code: ```bash ASL Recognition Web App

ASL Sign Language Recognition

Prediction: ...

``` **Explanation:** - Captures webcam video - Every second, takes a snapshot from the video feed - Sends the snapshot to our Flask backend for prediction - Displays the prediction result below the video 2. Now create the Flask application that serves the HTML page and handles prediction requests. ```bash nano app.py ``` Add the following code. ```bash import base64 import io import numpy as np from PIL import Image from flask import Flask, render_template, request, jsonify from tensorflow.keras.models import load_model from tensorflow.keras.preprocessing.image import img_to_array # Load model model = load_model('asl_sign_model.h5') # Define parameters IMG_HEIGHT, IMG_WIDTH = 64, 64 # Initialize Flask app app = Flask(__name__) # Labels map from training class_labels = list('ABCDEFGHIJKLMNOPQRSTUVWXYZ') + ['del', 'nothing', 'space'] @app.route('/') def index(): return render_template('index.html') @app.route('/predict', methods=['POST']) def predict(): data = request.get_json() if 'image' not in data: return jsonify({'error': 'No image data'}), 400 image_data = data['image'].split(',')[1] image_bytes = base64.b64decode(image_data) image = Image.open(io.BytesIO(image_bytes)).convert('RGB') image = image.resize((IMG_WIDTH, IMG_HEIGHT)) img_array = img_to_array(image) / 255.0 img_array = np.expand_dims(img_array, axis=0) preds = model.predict(img_array) predicted_class = np.argmax(preds[0]) predicted_label = class_labels[predicted_class] return jsonify({'prediction': predicted_label}) if __name__ == '__main__': app.run(host='0.0.0.0', port=5000, debug=True) ``` The above code accepts image data from the browser, preprocesses it, predicts the gesture, and sends back the prediction as JSON. ## Step 6: Running the Web App 1. Now that we have built the Flask backend and front-end interface, let’s run the application and test the real-time sign language recognition system. ```bash python3 app.py ``` This will start the Flask server on port 5000, and you should see output like: ```bash * Running on http://0.0.0.0:5000/ (Press CTRL+C to quit) * Restarting with stat ``` 2. If you’re running this on a remote server, use SSH port forwarding so you can access it locally. ```bash ssh -N -f -L 5000:localhost:5000 root@your-server-ip ``` 3. Open your web browser and access the Flask App using the URL **http://localhost:5000.** 4. The browser will prompt you for camera access permission. Click **“Allow”** to let the app use your webcam. 5. Once the webcam feed is running, choose one of the ASL signs, such as the letters A, B, or C, from the image below. ![](https://www.atlantic.net/wp-content/uploads/2025/07/sign.png) 6. Hold your hand steady and clearly within the webcam’s field of view. 7. The app will capture frames every 1 second and send them to the backend for prediction. The predicted letter or gesture will appear in real-time below the video feed. ![](https://www.atlantic.net/wp-content/uploads/2025/07/asl.png) ## Conclusion In this tutorial, you built a real-time American Sign Language (ASL) recognition system using machine learning on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). You set up the development environment, downloaded and prepared the ASL Alphabet dataset from Kaggle, and built a Convolutional Neural Network (CNN) that classifies American Sign Language (ASL) hand gestures. After training and evaluating the model, you integrated it into a Flask web application that allows real-time interaction using a webcam. --- # Scaling AI Workloads: Why Hybrid Cloud Infrastructure Is the Future of Enterprise AI > URL: https://www.atlantic.net/gpu-server-hosting/scaling-ai-workloads-why-hybrid-cloud-infrastructure-is-the-future-of-enterprise-ai/ | Published: 2025-07-31 | Updated: 2026-05-04 | Author: Dr. Tehseen Zia Enterprise AI is currently undergoing a significant transformation. Businesses are transitioning from basic tools like chatbots and automation to advanced artificial intelligence (AI) models to gain a competitive edge and real business value. However, this change also brings new challenges, especially related to traditional IT infrastructures. [Reports](https://www.amd.com/content/dam/amd/en/documents/epyc-business-docs/solution-briefs/ai-infrastructure-under-strain-vanguard-highlights-report.pdf) show that many companies abandon AI projects because their infrastructure cannot handle computational requirements of AI. Traditional on-premises setups fail to handle sudden demands, and full cloud solutions bring challenges about rising costs and data control. This gap has created space for a new approach: hybrid cloud infrastructure. ## Understanding AI Workloads and Their Unique Demands AI applications today are far more demanding than most IT teams expected. Training a large language model can [require](https://www.theverge.com/24066646/ai-electricity-energy-watts-generative-consumption) thousands of GPUs running for weeks. Computer vision systems need to process millions of images in real time. Recommendation engines must analyze user behavior patterns across massive datasets. These workloads share common characteristics that make them particularly challenging. They require enormous amounts of computing power for short periods. They generate and consume vast amounts of data. They need specialized hardware like GPUs and TPUs. Most importantly, they are unpredictable in their resource demands. Take a retail company that uses a demand forecasting model as an example. During normal operations, the system might use modest computing resources to generate daily predictions. But when training new models on seasonal data, it suddenly needs 50 times more processing power. Traditional infrastructure cannot efficiently adapt to these changing requirements. ## Why Cloud-Only Solutions Fall Short Many organizations initially assume that public cloud services will solve their AI infrastructure challenges. Cloud providers offer impressive AI services and apparently unlimited computing power. However, reality often proves more complicated than expected. Cost becomes the first major hurdle. Running large AI workloads continuously in the cloud can generate excessive bills. The [CEO’s guide to generative AI](https://www.ibm.com/downloads/documents/us-en/107a02e9bec8fbd9) report states that every single organization has cancelled or postponed at least one gen AI initiative due to high compute cost. Data movement is also a key challenge. AI models need access to enormous datasets, often measured in terabytes or petabytes. Moving this data to and from cloud services creates bottlenecks and additional costs. Network latency can also slow down training processes significantly. Compliance and security concerns further complicate the process, particularly for industries subject to strict regulations like [GDPR](https://gdpr-info.eu/) and [HIPAA](https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html#:~:text=The%20Health%20Insurance%20Portability%20and,Rule%20to%20implement%20HIPAA%20requirements.). Many industries have strict requirements about where data can be stored and processed. Healthcare companies cannot easily move patient data to public clouds. Financial institutions face similar restrictions with customer information. ## The Hybrid Cloud Advantage [Hybrid cloud infrastructure](https://www.ibm.com/think/topics/hybrid-cloud) combines the best practices of on-premises systems and public cloud services. Organizations keep sensitive data and predictable workloads on their own servers while using cloud resources for variable demands and specialized tasks. This approach solves several problems simultaneously. Companies maintain control over their most critical data while gaining access to virtually unlimited computing power when needed. They can optimize costs by using their own infrastructure for baseline workloads and cloud services for peak demands. A manufacturing [company](https://taikun.cloud/what-are-some-real-examples-of-companies-using-hybrid-cloud/) illustrates this approach well. They run their quality control AI models on local servers to maintain low latency and data security. When they need to train new models on historical data, they employ cloud resources for additional computing power. This strategy reduces their AI infrastructure costs while improving performance. ## Flexibility in Resource Management Hybrid cloud infrastructure provides flexibility in managing AI workloads. Organizations can match their infrastructure choices to specific use cases rather than forcing everything into a single model. [Edge computing](https://azure.microsoft.com/en-us/resources/cloud-computing-dictionary/what-is-edge-computing#:~:text=Edge%20computing%20allows%20devices%20in,is%20transmitted%2C%20thereby%20minimizing%20latency.) becomes possible when AI models need to operate close to data sources. For example, a logistics company can deploy route optimization models directly in their warehouses while using cloud services for training and updates. This hybrid approach reduces latency and improves reliability. Seasonal businesses benefit enormously from this flexibility. For instance, an e-commerce company can scale up their recommendation systems during holiday shopping seasons using cloud resources. During slower periods, they can scale back to their on-premises infrastructure. This elasticity would be impossible with traditional approaches. ## Data Management and Security As data is crucial for building AI systems, data management has become an important part of AI development and deployment. Hybrid cloud infrastructure provides better options for managing data. Organizations can implement data governance policies that keep sensitive information secure while enabling AI innovation. [Data residency](https://www.ibm.com/think/insights/data-residency-why-is-it-important#:~:text=Data%20residency%20%E2%80%93%20Data%20residency%20is,region%20where%20it%20is%20collected.) requirements are easier to manage in hybrid environments. A multinational bank can keep customer data in specific countries while using cloud services for model training and development. They can comply with local regulations while still benefiting from global AI capabilities. Backup and disaster recovery become more robust with hybrid approaches. Critical AI models and data can be replicated across both on-premises and cloud environments. This redundancy ensures business continuity even during major outages. ## Performance Optimization Hybrid cloud infrastructure enables performance optimization strategies that are impossible with single-environment approaches. Organizations can place workloads where they perform better while maintaining overall system efficiency. GPU sharing becomes more effective in hybrid environments. Companies can aggregate GPU resources across on-premises and cloud environments, ensuring these expensive assets stay busy. A research organization can share GPU clusters between multiple AI projects, automatically shifting workloads to available resources. Network optimization plays a crucial role in hybrid performance. Organizations can minimize data movement by placing AI workloads close to their data sources. This reduces both latency and bandwidth costs. ## Cost Management Strategies Hybrid cloud infrastructure has changed cost management from a reactive task to a strategic process. It allows organizations to gain visibility and control over their AI spending while maintaining performance. On one side, the reserved capacity of on-premises infrastructure helps organizations manage predictable workloads at lower costs. On the other hand, variable cloud resources manage peak demand without the need for costly upgrades to on-premises systems. This combination helps optimize both operational and capital expenses. [Automated scaling](https://www.ibm.com/think/topics/autoscaling) policies ensure that costs are kept in check while also ensuring sufficient performance. For example, a healthcare AI system can automatically move workloads between environments based on demand. This automation reduces the need for manual management, while effectively controlling expenses. ## Implementation Challenges Deploying hybrid cloud infrastructure for AI workloads brings several challenges that organizations must handle carefully. Complexity increases significantly when managing resources across multiple environments. Managing hybrid environments effectively requires specialized skills, which can be difficult to find. Organizations need experts who understand both on-premises infrastructure and cloud services, as well as how to coordinate workloads across these environments. Integration becomes a challenge when connecting on-premises and cloud systems. Data synchronization, security policies, and performance monitoring are more complicated in hybrid environments. Organizations require strong management tools to manage these complexities. ## The Path Forward Hybrid cloud infrastructure is the future of enterprise AI because it addresses real business needs rather than theoretical possibilities. Organizations can maintain control while gaining flexibility. They can optimize costs while ensuring performance. Most importantly, they can adapt their infrastructure as their AI needs evolve. The successful deployment of this approach requires careful planning and gradual implementation. Organizations should start with pilot projects that demonstrate the benefits of hybrid clouds. They should invest in training teams and implementing proper management tools. They should also develop clear policies for workload placement and data governance. Companies that adopt hybrid cloud infrastructure for AI will gain a competitive edge. They will be able to deploy AI solutions faster, operate them more efficiently, and scale them more effectively than competitors using traditional methods. ## Conclusion The future of enterprise AI relies on infrastructure that can adapt to evolving needs while ensuring security, performance, and cost control. Hybrid cloud infrastructure offers this adaptability by combining the strengths of both on-premises and cloud environments. Organizations that recognize this shift will be better positioned for success in an AI-driven future. Hybrid cloud infrastructure allows businesses to utilize the full potential of artificial intelligence while maintaining the control and flexibility required for their operations. The key question is not whether to adopt hybrid cloud infrastructure for AI, but how quickly organizations can make the transition effectively. --- # What Is Quantum Computing? > URL: https://www.atlantic.net/managed-services/what-is-quantum-computing/ | Published: 2025-08-04 | Updated: 2025-07-18 | Author: Dr. Assad Abbas [Quantum computing](https://www.ibm.com/think/topics/quantum-computing#:~:text=Quantum%20computing%20is%20an%20emergent,the%20most%20powerful%20classical%20computers.) is an emerging form of computing. It utilizes the principles of quantum mechanics, a branch of physics that studies the behavior of tiny particles, such as atoms and photons. Unlike classical computers that use bits to represent information as either 0 or 1, quantum computers use [quantum bits or qubits](https://www.techtarget.com/whatis/definition/quantum-computing). Qubits can exist in multiple states at the same time. This characteristic is known as superposition. It enables quantum computers to process many possibilities simultaneously. In contrast, classical computers use bits that can only be in one state, either 0 or 1,at a time. Due to this fundamental difference  quantum computers perform certain complex calculations more quickly and efficiently. Quantum computers are expected to tackle problems that classical computers cannot handle or solve quickly enough. For example, tasks that would take classical supercomputers years to solve could be solved in minutes or hours using quantum computers. According to [McKinsey](https://www.mckinsey.com/capabilities/mckinsey-digital/our-insights/quantum-technology-sees-record-investments-progress-on-talent-gap), the quantum computing sector is projected to reach an estimated value of around USD 1.3 trillion by 2035 due to substantial investments by large tech firms. Although quantum computing is still in development, it has the potential to revolutionize various industries, including [cybersecurity](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-cybersecurity-requirements-a-practical-guide/), automotive, life sciences, and logistics. In the near future, quantum computers will address problems that are currently unsolvable with today’s technology, thereby bringing new opportunities across various fields. ## The Basics of Quantum Computing Below are the key concepts that explain how quantum computing works: ### Qubits and Superposition In classical computing, a bit is like a light switch that can only be ***on (1)*** or ***off (0)*** at a certain time. However, in quantum computing, a qubit behaves more like a spinning coin While it is spinning, it shows both heads and tails at the same time. Similarly, a qubit can represent **0, 1, or both at once**. This property is known as superposition. It enables quantum computers to carry out multiple calculations at the same time, making them highly efficient for certain tasks. The number of qubits directly affects the number of possibilities a quantum computer can handle. With ***n*** qubits, the system can represent ***2ⁿ*** different states at once. For example, two qubits can represent four possible combinations ***(00, 01, 10, 11)*** at the same time. As more qubits are added, the number of possible states increases rapidly. This exponential growth is what gives quantum computers their strength in solving complex problems #### Example: Finding the Best Route for a Delivery Truck *Suppose a delivery truck needs to visit 8 different locations and return to its starting point. This type of problem is called the*[*Travelling Salesman Problem (TSP)*](https://www.w3schools.com/dsa/dsa_ref_traveling_salesman.php)*. A classical computer would need to examine all possible routes (40,320 in the case of 8 stops) to find the shortest one. As the number of stops increases, the number of possible routes grows very quickly. For 15 stops, there are more than 1.3 trillion possible combinations.* *Quantum computers approach this problem differently. They use qubits to represent many possible routes at the same time. They also apply algorithms like the Quantum Approximate Optimization Algorithm (QAOA) or quantum annealing. These methods help focus on the most promising solutions and reduce the chances of less effective ones. This way quantum systems find good solutions much faster, particularly when the number of stops increases.* *Although quantum computers may not always find the exact shortest route, they are very effective at identifying near-optimal routes in a short amount of time. This makes them well-suited for real-world applications like logistics. Companies such as*[*DHL*](https://lot.dhl.com/quantum-leap-logistics/)*are already exploring how quantum computing can improve delivery routes and reduce fuel consumption and delivery time.* ### Entanglement Another key feature that adds to the power of quantum computing is entanglement. When two qubits are entangled, the state of one is directly linked to the state of the other. If one qubit is changed, the other responds instantly, even if they are far apart. Due to this strong connection quantum computers handle problems involving many related variables more efficiently. As a result, entanglement helps quantum systems perform certain tasks much faster than classical computers. ### Quantum Gates and Circuits Just as classical computers use logic gates like AND, OR, and NOT to operate on bits, quantum computers use quantum gates to control qubits. These gates change the state of qubits to create effects such as superposition and entanglement. Quantum gates are arranged in sequences to form quantum circuits. These circuits function like programs but are designed to work with qubits instead of bits. Since qubits can represent multiple states at once, quantum circuits can process many possibilities simultaneously. This ability forms the basis of quantum algorithms and makes quantum computers effective for solving complex problems. ## What Quantum Computing Can Do That Classical Computing Cannot Quantum computers are designed to solve problems that classical computers find difficult or time-consuming. One key area is the simulation of complex systems. For example, modeling how molecules behave is very challenging for classical computers. They need a lot of time and processing power. On the other hand, quantum computers can perform these simulations more efficiently and accurately. This could help in developing new medicines, better materials, and improved battery technologies. Quantum computing is also useful for solving optimization problems. These problems involve finding the best solution among many options. They appear in fields like logistics, finance, and manufacturing. Classical computers check each option one by one, which takes time as the number of options increases. Quantum computers can evaluate many options at once, making the process faster. This can improve things like delivery routes, investment planning, and city traffic management. In cryptography, quantum computing brings both risks and benefits. It could break current encryption systems. However, it also supports new types of encryption that are safer from quantum attacks. These [quantum-resistant](https://www.atlantic.net/gpu-server-hosting/future-proofing-digital-security-the-role-of-ai-and-quantum-safe-algorithms-in-trust-convergence/) methods will protect sensitive data in the future. It is important to note that quantum computers are not meant to replace devices like laptops or smartphones. They are specialized tools used for specific, complex problems. Tasks such as weather prediction, protein folding, and financial modeling can benefit from their unique power. ## The Current State of Quantum Computing in 2025 In 2025, quantum computing is moving from research to real-world use. The technology is still developing, but it is already available through cloud services. This enables companies and researchers to access quantum computing without needing to own expensive hardware, which can be complex to maintain. Big companies, such as IBM, Google, Microsoft, and Amazon, are leading the way. They are developing quantum processing units (QPUs) and offering them through cloud platforms. Startups are also entering the field, focusing on various quantum computing technologies, including photonic qubits, trapped ions, and superconducting qubits. Governments worldwide are investing heavily in quantum technology. In the United States, the [National Quantum Initiative](https://www.quantum.gov/) funds research and development. Similarly, in Europe, the [Quantum Flagship](https://qt.eu/) program supports various projects across member states. China is making significant progress, particularly in quantum communication and the development of satellite-based quantum networks. Other countries, such as Japan and South Korea, are also increasing their focus on quantum research. These global investments reflect the growing importance of quantum technology for national security, economic growth, and technological leadership. As a result, the pace of quantum advancements is expected to accelerate, creating new challenges and opportunities. Although quantum computing is not yet ready to replace classical computers, steady progress is being made in this field. With continued funding and open access, practical applications will likely emerge in the years to come. ## Challenges and Limitations of Quantum Computing Quantum computing has great potential, but it still faces numerous challenges before it can be widely adopted. One major issue is [error correction](https://www.javacodegeeks.com/2025/04/quantum-error-correction-in-2025-progress-and-persistent-challenges.html). Qubits are very sensitive. Small changes in the environment, like heat, noise, or electromagnetic signals, can cause them to lose their state. This makes it challenging to maintain accurate results. To fix this, scientists use error correction methods. However, these methods require many extra qubits to protect just one working qubit. This makes quantum computers more complex and more challenging to build. Another problem is qubit stability. Most quantum systems require operation at temperatures close to absolute zero, approximately [-273°C](https://www.msn.com/en-us/money/companies/north-korean-it-workers-infiltrated-fortune-500-companies-in-massive-fraud-scheme/ar-AA1HIGsG). To achieve this, researchers use large and expensive cooling machines. These machines are difficult to maintain, and add to the cost. Finding ways to make qubits function at higher temperatures is still an area of active research. Scaling up is also a challenge. Many current quantum computers have fewer than 100 usable qubits. This is insufficient to address significant, real-world problems. Experts believe that thousands or even millions of stable qubits are needed for meaningful applications. Reaching this goal will require time and new engineering solutions. Moreover, quantum computers cannot run classical algorithms. They need algorithms designed for quantum logic. Developing these quantum algorithms is still in the early stages. Lastly, there is a shortage of skilled workers. Few people understand both quantum physics and computer science. Many countries are investing in education and training, but the talent gap is a serious concern. These challenges must be addressed before quantum computing can be applied in everyday industries. Until then, it remains a powerful but early-stage technology. ## The Future of Quantum Computing The future of quantum computing is bright, but its development will happen in stages. Within the next 2 to 5 years, we can expect the emergence of hybrid quantum-classical systems. Quantum processors will work alongside classical supercomputers for tasks such as simulations in finance and chemistry. Over the next 5 to 10 years, quantum computers may become fault-tolerant with built-in error correction, thereby increasing their reliability. This could lead to innovations in material science and drug discovery, though it could also challenge current encryption methods. Therefore, businesses will need to adapt to new security standards. Over the next 10 years or more, large-scale quantum computers are expected to revolutionize fields such as climate modelling, artificial intelligence, and physics. Quantum technology will solve problems that classical computers cannot handle. This progress will impact industries such as healthcare, energy, and finance, bringing breakthroughs that are not possible with current technology. ## The Bottom Line In conclusion, quantum computing is an exciting and rapidly growing field with the potential to solve some of the most complex problems in science, industry, and society. Although it is still in its early stages, the progress made so far shows that it could address challenges that classical computers cannot handle. Quantum computing could bring major changes to areas like logistics, healthcare, and cybersecurity. It offers new possibilities that were once considered out of reach. However, there are still important challenges to overcome, such as qubit stability, error correction, and scaling up the technology. With ongoing research and better technology, quantum computing may become a major step forward in the coming years. It could change how we approach difficult problems and open the door to new ideas and innovations. --- # HIPAA Hosting: An In-Depth Buyer’s Guide > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-hosting-an-in-depth-buyers-guide/ | Published: 2025-09-03 | Updated: 2025-09-09 | Author: Richard Bailey For any business, choosing a hosting provider is an important decision, but for a healthcare organization or a company that handles patient data, it is one of the most critical decisions you will ever make. A data breach in e-commerce is a disaster; a data breach in healthcare can destroy patient trust, attract massive fines, and even create legal jeopardy. The Health Insurance Portability and Accountability Act (HIPAA) is not a suggestion—it is a federal law with serious consequences. [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) is a specific set of services, policies, and legal agreements designed to protect electronic Protected Health Information (e-PHI). It requires a partnership between you (the Covered Entity or Business Associate) and your hosting provider (your Business Associate). This is not about simply renting a server; it’s about building a secure foundation for your entire compliance strategy. This guide is for healthcare executives, clinic IT managers, and developers building health-tech applications. We will explain what HIPAA-compliant hosting actually is, what to look for in a provider, what services you need, and the common mistakes to avoid. Our goal is to simplify the technical workings of HIPAA so you can make an informed choice to protect your patients and your organization. ## Understanding HIPAA: The Law Behind the Hosting Before discussing servers and firewalls, it’s essential to understand the rules you must follow. HIPAA’s primary goal is to protect the privacy and security of patient health information. - **The Privacy Rule:** This rule sets national standards for who can access and use patient information. It is primarily about policies and procedures within your organization. - **The Security Rule:** This is arguably the most important rule for hosting. It dictates the safeguards that must be in place to protect e-PHI. These safeguards are broken down into three categories: - **Technical Safeguards:** Technology-based controls, like encryption, access controls, and audit logs, that protect data on your servers and networks. - **Physical Safeguards:** Physical protections for the data center and hardware where your data is stored, including locks, security guards, and surveillance cameras. - **Administrative Safeguards:** The policies and procedures that tie everything together, such as risk assessments, training employees, and having a formal plan to respond to security incidents. - **The HITECH Act:** The Health Information Technology for Economic and Clinical Health Act strengthened HIPAA’s enforcement. It increased the penalties for violations and introduced a public breach notification rule, meaning a significant breach will become public knowledge. The single most important document in this entire relationship is the *Business Associate Agreement (BAA)*. This is a legally binding contract between you and your hosting provider. It requires the provider to accept responsibility for protecting your e-PHI according to HIPAA rules. If a provider will not sign a BAA, they are not, and cannot be, a HIPAA-compliant hosting provider. ## What to Look for in a HIPAA Compliant Hosting Provider To achieve peace of mind in healthcare IT, you need a hosting partner with experience and commitment to security and compliance. This decision is about finding a long-term hosting provider with a proven track record. At Atlantic.Net, we’ve spent over 30 years providing secure infrastructure, making us a leading choice for HIPAA-compliant hosting. ### Audits, Certifications, and the BAA A provider’s claims of compliance mean nothing without proof. A willingness to sign a BAA is the first and most important qualifier. Beyond that, look for providers who undergo regular, independent audits. The most relevant reports are: - SOC 2 Type II, which examines security controls over time, - HITRUST, a framework specifically designed for healthcare regulations. For example, Atlantic.Net is HITRUST certified and maintains SOC 2 and SOC 3 attestations, providing clients with immediate, verifiable proof of its security and compliance posture. ### Data Center and Physical Security HIPAA has specific rules for physical security, and the quality of the provider’s data center is absolutely critical. The facility must have multiple layers of security, including 24/7 on-site staff, video surveillance, and multi-factor access control down to the server cabinet. The data center must also have redundant power, cooling, and fire suppression systems. Providers like Atlantic.Net operate multiple data centers across the United States, built to these exacting standards, ensuring both physical security and data sovereignty for US-based e-PHI. ### Uptime and Service Level Agreements (SLA) Clinical applications often require near-constant availability. A provider must offer a financially backed Service Level Agreement (SLA) that guarantees uptime for network, power, and infrastructure. Downtime impacts patient care, making a strong SLA non-negotiable. For instance, Atlantic.Net provides a 100% Uptime SLA for its HIPAA-compliant infrastructure, ensuring that your critical healthcare applications remain accessible to patients and staff. Our HIPAA platform is built with redundancy and security at the forefront of the design process; it’s engineered to be reliable, and we are so confident that we back our design with a [100% Uptime SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/). ### Secure Infrastructure and Technical Safeguards The provider must offer the specific technologies required to meet the HIPAA Security Rule. This includes encryption for data “at rest” and “in transit,” private networking to isolate your environment, and [managed security services](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-security/). A compliant host should offer managed firewall services, Intrusion Detection Systems (IDS), and log management to monitor for and respond to threats. ### Support and Incident Response When a security incident happens, you need a provider who knows exactly what to do. The best providers have years of experience working with healthcare clients. This is a key advantage of working with a provider like Atlantic.Net, whose engineers are not only available 24/7 but are also HIPAA-trained. We understand the unique challenges of the industry and can offer practical advice that goes beyond just server specifications. ## What to Buy: Compliant Hosting Services and Configurations You cannot just buy a standard server and call it “HIPAA compliant.” You must choose specific services and configurations designed for security and audibility. ### Server Type: Dedicated vs. Private Cloud While HIPAA-compliant solutions can be built on multi-tenant public clouds, it is a complex process that shifts significant security responsibility onto the customer. For this reason, dedicated servers or private cloud environments are often recommended to simplify compliance and reduce the risk of misconfiguration. - **Dedicated Servers:** A physical, dedicated server provides complete resource isolation, making security and auditing much more straightforward. - **Private Cloud:** A private cloud offers cloud flexibility (like easier scaling) but in a dedicated environment for your exclusive use. A specialist provider like Atlantic.Net can offer both HIPAA-compliant dedicated servers and private cloud solutions, allowing you to choose the architecture that best fits your technical requirements, budget, and long-term scalability needs. ### Essential Security Services These are not optional add-ons; they are core components of a compliant hosting solution. - **Managed Firewall:** This includes a dedicated network firewall to control all inbound and outbound traffic, and may also include a Web Application Firewall (WAF) to protect web-facing applications. - **Encrypted VPN Access:** A Virtual Private Network is essential for providing secure administrative access to your server for your healthcare workers, developers or IT staff. - **Encrypted Backups:** Backups of e-PHI must also be encrypted. Atlantic.Net’s HIPAA-compliant Hosting solutions, for example, integrate managed backup services where data is encrypted in transit and at rest, and stored in a geographically separate, compliant data center to ensure business continuity. - **Disaster Recovery Planning:** A DRP is an essential part of HIPAA. Critical applications must be fault-tolerant in the event of infrastructure failure. The most common solution is disaster recovery toolsets that fail over critical applications to an unimpacted environment, usually in another location. - **Log Management and Monitoring:** HIPAA requires you to keep audit logs of all access to e-PHI. A log management service collects and secures these logs to help identify suspicious activity. ## The Shared Responsibility Model It is critical to understand that compliance is a partnership. The provider is responsible for the security *of* the cloud/data center; you are responsible for security *in* the cloud. | **Responsibility** | **Hosting Provider (Business Associate)** | **You (Covered Entity)** | | --- | --- | --- | | **Data Center Physical Security** | **Yes** | No | | **Network Infrastructure** | **Yes** | No | | **Hardware Management** | **Yes** | No | | **OS Patching & Hardening** | If you buy a managed service | **Yes** (on unmanaged plans) | | **Application Security** | No | **Yes** | | **User Access Control** | No | **Yes** | | **e-PHI Data Management** | No | **Yes** | | **Workstation Security** | No | **Yes** | Never assume the provider is handling something. Always clarify responsibilities and have them documented. ## Why Use a Specialized HIPAA Compliant Host? You could try to build a compliant environment with a generic provider, but there are strong reasons to choose a specialist like Atlantic.Net. - **Risk Reduction:** A specialist provider lives and breathes HIPAA. They have pre-built, audited solutions and trained staff, dramatically lowering the chance of a misconfiguration that could lead to a breach and huge fines. The average cost of a healthcare data breach is over $10 million—investing in a proper host is a wise insurance policy. - **Reduce Costs:** While the investment in specialized HIPAA-compliant hosting is higher than for standard hosting, it pales in comparison to the average cost of a healthcare data breach. - **Expertise and Guidance:** A specialist provider acts as a consultant, guiding configuration, audit preparation, and incident response. This expertise is invaluable. - **Audit and Compliance Support:** A specialist provider can quickly give you the documentation you need for their part of the puzzle, making your audit process much smoother. - **Peace of Mind:** Knowing your infrastructure is handled by experts is a core benefit of partnering with a specialist like Atlantic.Net. This allows you to focus on providing patient care or building your application, rather than worrying about server administration and security threats. ## Common Problems and How to Avoid Them - **Problem: Assuming a “HIPAA Compliant” Badge is Enough.** - **How to Avoid It:** Ignore logos. The only thing that matters is a signed Business Associate Agreement (BAA). Without it, there is no compliant relationship. - **Problem: Forgetting Your Own Responsibilities.** - **How to Avoid It:** Understand the shared responsibility model. The provider handles the data center, but you must secure your application, manage users, and train your staff. - **Problem: Sending e-PHI Over Insecure Channels.** - **How to Avoid It:** Implement policies and solutions for secure communication, such as encrypted email. Compliance extends beyond the data center. - **Problem: Not Having a Breach Response Plan.** - **How to Avoid It:** Work with your provider to develop a formal, written incident response plan that details the steps to take to meet HIPAA’s breach notification requirements. ## Atlantic.Net vs. The Hyperscale Providers: A Better Value Proposition for HIPAA-Compliant SaaS Hosting While hyperscale clouds like Amazon Web Services (AWS) and Microsoft Azure are powerful platforms, achieving and maintaining HIPAA compliance can be a significant technical and financial challenge. Many are surprised to learn that neither AWS nor Azure is “HIPAA compliant” out of the box. Both provide a set of HIPAA-eligible services, but the customer is fully responsible for building, configuring, auditing, and proving compliance under a complex shared responsibility model. This “DIY” approach on massive, general-purpose platforms creates significant hurdles. Atlantic.Net offers a compelling alternative: a managed, high-performance, and cost-effective hosting solution designed for the specific regulatory needs of companies like yours. | | **Atlantic.Net** *Specialist HIPAA Provider* | **AWS** **(Amazon Web Services)** | **Microsoft Azure** | | --- | --- | --- | --- | | **Cost Model** | Designed to be straightforward and predictable, including the expert support and robust security features required for compliance. | Tiered, usage-based pricing can be complex. Essential services for security, monitoring, and expert support are often separate, premium-priced products, which can lead to unpredictable costs. | Complex pay-as-you-go model. Core services for advanced security (e.g., Microsoft Defender for Cloud) and expert architectural guidance are premium, tiered offerings that increase the total cost. | | **Storage Performance** | Engineered for consistently high I/O performance. Our platform is optimized for demanding workloads without the need for complex and costly storage provisioning tiers. | Performance is highly configurable but tiered. Achieving sustained high IOPS requires careful selection and payment for higher-tier storage volumes (e.g., Provisioned IOPS), adding to cost and management overhead. | Performance is tiered and budget-dependent. Reaching high IOPS for databases requires provisioning more expensive storage tiers like Premium SSD or Ultra Disk, adding layers of cost and management. | | **Compliance Model** | **Managed & Audited**: Provides a turnkey, HIPAA-compliant environment ready from day one. **Clear Responsibility**: We act as your partner, taking on the burden of infrastructure configuration and management. [Atlantic.Net](http://atlantic.net) signs a BAA. | **Do-It-Yourself**: Requires you to manually configure numerous services like IAM, WAF, and CloudTrail to meet HIPAA controls. **Transactional BAA:** Offers a BAA for its portfolio of HIPAA-eligible services. | **Do-It-Yourself**: The customer is responsible for configuring services like Azure Policy, Microsoft Defender, and Azure Monitor to meet HIPAA standards. **Transactional BAA**: Offers a BAA for its portfolio of “HIPAA-covered services.” | | **Support Model** | **Experts Included**: 24x7x365 U.S.-based support is standard. **Free Architecture Design**: Includes services like IT architecture design and assessment. | **Tiered & Costly**: Access to architecture and compliance experts often requires an expensive premium support plan (e.g., AWS Enterprise Support). | **Tiered & Costly**: Meaningful access to senior cloud architects typically requires an expensive Unified or Premier Support plan, a significant operational cost. | | **Infrastructure** | **Hybrid Flexibility**: Offers a seamless blend of secure cloud hosting and dedicated physical servers, tailored to specific security and performance needs. | Primarily a multi-tenant, virtualized cloud. While dedicated hardware options exist, they are premium services and add another layer of complexity to the ecosystem. | Primarily a multi-tenant, virtualized cloud. Strong hybrid capabilities with Azure Arc and Azure Stack are available, but represent an enterprise-grade solution that adds complexity. | | **Partnership** | **Partner-Focused**: As a specialized provider, we offer a hands-on, personalized relationship to ensure your success. | **Vendor-Focused**: As one of millions of customers, receiving dedicated, personalized attention can be a significant challenge. | **Vendor-Focused**: As a global hyperscaler, customers are one of millions navigating a vast and ever-changing platform. | If you’re tired of feeling like just another account number at AWS or Azure, it’s time for a change. At Atlantic.Net, you’re a valued partner. We deliver optimal performance with predictable pricing, a clear and direct path to compliance, and expert support that’s included from day one. It’s time to lower your total cost, reduce your compliance headaches, and work with a provider dedicated and focused on you. ### Why Atlantic.Net HIPAA Hosting - HIPAA and HITECH Compliant – Fully audited and certified. - Secure Infrastructure – Encryption, firewalls, intrusion detection. - Business Associate Agreement (BAA) – Included with hosting. - Managed Services – Patching, monitoring, and support. - 100% Uptime SLA – Reliable performance. - Dedicated Account Manager – HIPAA experts who design a customized solution. - 31+ Years in Business – Trusted, experienced provider. - S.-Based with Free Phone Support – Always available, no hidden fees. - Cost Advantage – Enterprise-grade hosting at competitive pricing. - Simple & Fast Deployment – Reduces headaches, cuts red tape, and speeds up time to launch. ## Reduce Health Tech Hosting Costs Without Compromising on HIPAA Compliance As a leader in the health tech industry, you face the constant challenge of managing operational costs while ensuring uncompromising security and HIPAA compliance for your sensitive patient data (ePHI). While large cloud providers like Azure and AWS offer a path to compliance, it is often a complex, costly, and resource-intensive journey. Atlantic.Net offers a more direct and cost-effective solution. As a specialist in [HIPAA hosting](https://www.atlantic.net/hipaa-compliant-hosting/) with over 31 years of experience, we provide a streamlined path to a secure, compliant, and high-performance environment, enabling you to focus on innovation rather than infrastructure. ## Here’s How Atlantic.Net Delivers Better Value: - Superior Price-Performance: True cost savings stem from efficiency. Our platform is engineered for the demanding I/O requirements of health applications. We provide consistently high disk performance without forcing you onto expensive, complex storage tiers, delivering superior and more predictable price-performance for your most critical workloads. This means your applications run faster and your budget goes further. - Turnkey HIPAA-Compliant Solutions: We remove the complexity and guesswork from compliance. Unlike the “DIY” model of the hyperscale providers, we offer a purpose-built environment designed specifically to meet and exceed complex HIPAA regulations. Our team of experts provides a fully audited, secure, and compliant platform from day one, freeing your team to focus on innovation. - Dedicated, U.S.-Based Expert Support: When you have a question, you get an expert, not a call center. Our entire support and management team is based in the USA, offering deep expertise in security and compliance. We provide services like free IT design and assessment to ensure your environment is optimized. - A True Partnership with a BAA: We are your compliance partner, not just a vendor. We sign a Business Associate Agreement (BAA) and work with you to customize a solution on our secure cloud that perfectly fits your specific needs. Don’t let exorbitant hosting costs and compliance complexity slow down your growth. Allow us to deliver superior performance and peace of mind at a competitive price point. Looking for a HIPAA compliant hosting solution that’s secure, reliable, and tailored to your organization’s needs? Atlantic.Net makes it easy. Our team is ready to help you design a custom hosting environment that meets all HIPAA requirements—without the complexity of managing it alone. Reach out today at sales@atlantic.net or give us a call at (866) 618-3282Questions for a Subject Matter Expert When evaluating a hosting provider, consider asking their experts the following questions to gauge their depth of knowledge: - What is the most common HIPAA Security Rule safeguard that organizations overlook? - If a provider signs a BAA, what is the biggest mistake a client can make next? - How can a small clinic with a limited budget approach HIPAA-compliant hosting? - What’s the difference between a SOC 2 report and a HITRUST certification, and which is more important? - How often should a healthcare organization conduct a formal risk assessment of its hosting environment? - Can an application ever be truly “HIPAA certified”? --- # AI Policy > URL: https://www.atlantic.net/ai-policy/ | Updated: 2026-09-16 ## Atlantic.Net AI Content & Crawler Policy **Last Updated:** June 27, 2026 #### **Introduction** At Atlantic.Net, we support the responsible development and use of artificial intelligence (AI). This policy outlines the rules for accessing and using content from atlantic.net and its subdomains for AI-related purposes, including model training, retrieval-augmented generation (RAG), and content indexing. Our goal is to enable innovation while protecting our intellectual property, our customers, and the integrity of our services. This policy applies to: - Automated agents, AI crawlers, and scrapers are accessing our web properties. - Developers and organizations using Atlantic.Net content in any AI system or workflow. For specific technical directives, please consult these resources: - https://www.atlantic.net/robots.txt: Standard crawling rules. - https://www.atlantic.net/llms.txt: AI-specific usage permissions and preferred content. - https://www.atlantic.net/sitemap-llms.xml: A sitemap of content mirrored in Markdown for cleaner ingestion. #### **1. Quick Start for AI Developers & Crawlers** To ensure compliant access, please follow these core principles: - **Respect robots.txt:** Always adhere to the directives in our robots.txt file. - **Prioritize Markdown:** For cleaner data ingestion, use the Markdown mirror of a page when available (e.g., use /gpu-server-hosting.md for /gpu-server-hosting/). A full list is in /sitemap-llms.xml. - **Follow llms.txt:** Use the links in our llms.txt file to identify the canonical pages we have designated for AI use. - **Attribute Correctly:** When you display or summarize our content, you must link back to https://www.atlantic.net and also to the specific source page. - **Observe Rate Limits:** Do not exceed an average of 1 request per second per IP (see Technical Guidelines for bursting rules). #### **2. Definitions** - **AI System:** Any model or application that generates, summarizes, translates, classifies, or retrieves text or media. - **Training:** Using our content to train, fine-tune, or otherwise adjust the parameters of a machine learning model. - **Inference / Retrieval:** Using our content at query time to generate answers, provide summaries, or ground responses in factual data (e.g., RAG). - **Cache:** A temporary local store of our content (e.g., embeddings, vector databases, HTML/Markdown copies) to enable faster processing. #### **3. Permitted Uses (Training, Inference & Retrieval)** You are permitted to use our content for the following purposes, provided you attribute Atlantic.Net as described in Section 1: - **Model Training:** Use our content to train, fine-tune, or adapt AI models, provided you attribute Atlantic.Net by linking back to our site and to the specific source page. - **Indexing and Summarization:** Crawl and create summaries of public-facing pages listed in our sitemaps and /llms.txt. - **Quotation:** Quote short excerpts (up to 200 words) with clear attribution and a direct, functional link to the canonical source page. - **Retrieval-Augmented Generation (RAG):** Use our content to ground AI-generated answers in fact, and provide a clear citation link to the source page is displayed with the output. - **Factual Comparisons:** Create accurate, non-misleading comparisons (e.g., feature tables, service checklists) that reflect information published on our site. #### **4. Prohibited Uses** The following activities are strictly prohibited: - **Training Without Attribution:** Using our content to train, fine-tune, or distill an AI model without providing the attribution required in Section 1. - **Republishing:** Republishing substantial portions of our content verbatim or near-verbatim. - **Removing Attribution:** Obscuring, removing, or altering our logos, trademarks, certification marks, or copyright notices. - **Misrepresenting Our Services:** Generating output that misrepresents our certifications (e.g., HIPAA, SOC 2, PCI DSS), implies endorsement where none exists, or makes false claims about our products. - **Data Harvesting:** Collecting data from non-public or interactive sections of our site or attempting to access user data. - **Bypassing Controls:** Circumventing any technical controls, including authentication requirements, robots.txt Disallow rules, or rate limits. For partnerships or other commercial arrangements, please contact **marketing@atlantic.net** #### **5. Technical Guidelines for Crawlers** - **User-Agent:** Identify your crawler with a descriptive User-Agent string that includes a contact URL or email address. - **Rate Limits:** The default limit is 1 request/second per IP, with bursts of up to 5 rps for no more than 60 seconds. - **Backoff Signals:** You must respect HTTP 429 (Too Many Requests) and HTTP 503 (Service Unavailable) responses and honor the Retry-After header. - **Efficient Crawling:** Use If-Modified-Since and ETag headers to avoid re-downloading unchanged content. Avoid crawling search endpoints or large media files unless essential. #### **6. Compliance & Regulated Data** Atlantic.Net provides services under strict compliance frameworks, including HIPAA, HITECH, SSAE 18 SOC 2 & SOC 3, and PCI DSS. **Important:** AI systems interacting with our content must: - Cite the specific source page for any compliance-related claim. - Never suggest that patient data (PHI), cardholder data (CHD), or other regulated information can be processed by our services in a non-compliant manner. - Never present aspirational statements as certified facts. #### **7. Caching and Data Retention** - **Duration:** Caches used for inference (e.g., embeddings, HTML snapshots) may be retained for up to 30 days. - **Deletion Requests:** You must have a mechanism to delete cached copies of our content and any derived data (like embeddings) within 15 days of a verified request from us. - **Cache Headers:** Always respect no-store and no-cache HTTP headers. #### **8. Enforcement** Violations of this policy will result in technical and legal enforcement actions. This may include, but is not limited to, IP or ASN-level blocking, filing of DMCA takedown notices, and pursuit of legal remedies for breach of terms or copyright infringement. We reserve the right to update this policy at any time. #### **9. Contact Information** For questions, partnerships, or license requests, please contact us at marketing@atlantic.net.   --- # The Top GPU Hosting Companies in India > URL: https://www.atlantic.net/gpu-server-hosting/the-top-gpu-hosting-companies-in-india/ | Published: 2025-09-05 | Author: Editorial Team Organizations located in India have several options when selecting a GPU cloud hosting solution. They can choose to engage one of the major cloud service providers such as Amazon Web Services (AWS), Microsoft Azure, or the Google Cloud Platform. These cloud service providers (CSPs) offer GPU instances to a worldwide customer base. Companies can also take advantage of Indian GPU cloud hosting providers. This article examines the advantages of GPU cloud servers, the types of workloads best suited for GPUs, and the benefits of working with a local provider. We will also list five of the top GPU hosting providers in India. ## The Advantages of GPU Cloud Servers GPU cloud servers provide organizations of any size with the opportunity to leverage high-performance computational power to address a wide range of business and scientific applications. While companies always have the option of building their own GPU servers, they can enjoy multiple advantages by utilizing GPU cloud servers. ### Cost-efficiency Companies can avoid the capital expenditures associated with building a GPU server and its supporting infrastructure. Customers rent GPU cloud servers to utilize them for advanced computing activities. Many providers offer monthly or hourly billing options, allowing organizations to benefit from the performance of GPU servers without making a long-term commitment. This situation is perfect for startups or companies looking to experiment with GPU computing. ### Scalability and flexibility Cloud providers offer customers a scalable and flexible platform that can meet evolving business requirements. Cloud GPU services are designed to grow with companies and can furnish virtually unlimited computing power to expanding organizations. Companies will not be burdened with overprovisioned resources and can reduce expenses by scaling down when necessary. ### Fast deployment Teams can get up and running quickly with cloud GPU instances, eliminating the need to plan and implement an in-house solution. The speed with which a company can access GPU performance in a cloud environment enables it to address business trends for enhanced competitiveness promptly. ### Global accessibility The cloud enables customers to access GPU resources from anywhere with an internet connection. Global accessibility fosters real-time collaboration with distributed teams and supports a remote workforce. Cloud GPU servers also allow teams to process data closer to its generation, such as from edge devices or regional offices. ## Cloud GPU Servers for High-Performance Computing GPU computing leverages the parallel processing capabilities of these advanced microprocessors to solve problems that are intractable for traditional sequential processors. The following applications demonstrate some of the high-performance computing capabilities enabled by utilizing GPU servers. ### Graphics rendering GPU is the acronym for Graphics Processing Unit, and one of the processor’s original purposes was for graphics and video rendering. GPU acceleration enables 3D rendering and real-time ray tracing, providing enhanced visual effects. Scenes that would take hours to render with traditional computing tools can be completed in minutes with GPU servers. ### AI workloads and machine learning GPUs enable customers to run the processor-intensive tasks required by AI workloads and machine learning applications. GPUs provide thousands of parallel cores that support matrix and tensor operations. Examples of the advanced workloads benefitting from high-performance GPUs include: - Deep learning and machine learning model training; - Computer vision applications; - Generative AI tools; - Natural language processing. ### Scientific computing GPUs provide the computing power necessary for efficient scientific simulations and research. The processors are capable of performing massive floating-point operations and reducing simulation time from days to hours or minutes. Examples of scientific computing facilitated by GPUs include climate modeling, molecular dynamics, and astrophysical simulations. Other scientific research targeting the healthcare sector includes genome sequencing, medical imaging analysis, and drug discovery. ### Data analytics and financial modeling Companies can utilize cloud GPUs to drive business objectives with data analytics and improved financial modeling. Organizations can enhance their risk analysis and forecasting capabilities with real-time analytics that support informed decision-making. The analytical capabilities of GPU servers provide a valuable tool for understanding the marketplace and remaining competitive. ## The Benefits of a Local GPU Cloud Hosting Solution Multiple benefits are available to companies that opt for a local GPU cloud hosting provider. - **Data residency and regulatory compliance** – Local providers ensure data stays within national borders to help meet legal and regulatory requirements. - **Lower latency** – Customers may enjoy improved performance and faster response time, which can be essential for maintaining mission-critical applications. - **Responsive support** – Local providers are typically more accessible and offer customer support in the local language. - **Reduced data transfer costs** – Localized traffic can minimize high bandwidth fees and delays associated with international data transfers - **Services tailored to the local market** – A local provider understands the market and regional infrastructure constraints, and can customize pricing and services for local businesses. - **Support for local innovation and economic growth** – Supporting local providers supports the region’s tech ecosystem and helps spur innovation, research, and economic development. ## Characteristics of Reliable GPU Cloud Hosting Providers When selecting a GPU cloud hosting provider, businesses should consider several key factors. - **Uptime and availability** – Look for providers with strong service-level agreements (SLAs) that guarantee high availability with an uptime of at least 99%. Providers should have a redundant infrastructure that prevents single points of failure. - **Modern GPUs** – The provider should offer a range of modern and high-performing GPUs to address different business requirements. - **Flexible pricing** – Customers should favor companies with flexible and transparent pricing that avoids hidden fees. Providers should offer options such as monthly billing as well as more cost-effective, long-term service plans. - **Strong security and compliance posture** – Providers should protect customer data with measures such as encryption and identity and access management (IAM) tools. Customers processing regulated data should look for providers with the necessary compliance certifications. - **Customizable services** – Customers should identify providers offering resources tailored to their specific workloads and objectives. - **Quality support teams** – The provider must offer comprehensive customer support through multiple channels such as phone, chat, and email. ## The Top GPU Hosting Providers in India The following list of top GPU hosting providers in India offers prospective customers an excellent selection of cloud GPU solutions. These companies may offer precisely what you need to meet your business goals. ### [Cantech](https://www.cantech.in/gpu-servers/cloud-gpu-server) Cantech provides powerful [Dedicated GPU Servers](https://www.cantech.in/dedicated-servers/gpu-dedicated-server) to accelerate advanced AI, machine learning, and the demanding tasks required by HPC applications. They offer scalable plans that range from a single cloud GPU server to an enterprise-grade infrastructure that grows with your business. The company relies on NVIDIA GPUs for superior performance and provides 24/7 customer support via phone and chat. Cantech maintains data centers in Mumbai and offers customized pricing and service plans to meet your business requirements and objectives. ### [Dataoorts GPU Cloud](https://dataoorts.com/gpu/) Dataoorts AI Cloud is purpose-built for AI developers and machine learning workloads. They offer affordable GPU VMs, available on both on-demand and reserved plans in India. You can spin up GPU instances within minutes and stop them when idle to optimize costs. - **NVIDIA H100**: just **$1.74/hour** - **RTX Pro Blackwell A6000 SE**: just **$1.55/hour** In addition, Dataoorts provides a Serverless AI API for leading open-source AI models, helping you get started instantly without infrastructure overhead. ### [Cyfuture Cloud](https://cyfuture.cloud/gpu-cloud) Cyfuture offers customers a wide range of NVIDIA-powered GPU servers for AI, graphics rendering, and machine learning applications. The provider has a reputation for a custom-centric cloud solution, allowing customers to tailor the service to fit their scale and requirements. Cyfuture has strategic partnerships with leading CSPs like Amazon and Alibaba to facilitate the creation of robust multi-cloud architectures. ### Acecloud.AI Acecloud offers customers quick access to dedicated GPU servers in the cloud, supporting AI, ML, and other demanding applications. The company offers a range of plans featuring the performance of NVIDIA Tensor cores. Customers can utilize shared or dedicated GPU servers with transparent hourly and monthly pricing plans. Acecloud utilizes NVIDIA-certified hardware and features a dedicated technical support team that is available 24/7, offering expertise in AI, graphics, and parallel computing. ### E2E Cloud E2E Cloud offers a diverse range of NVIDIA GPUs to support its customers’ AI and ML workloads. The company features an AI-Labs-as-a-Service (AILaaS) solution to bridge the gap between industry and academia, providing a scalable cloud platform to support training, research, and innovation. E2E Cloud backs their GPU servers with a 99.9% uptime SLA and 24/7 human customer support. ## Conclusion Indian GPU cloud hosting providers offer high-performance computing to support advanced applications, including deep learning, artificial intelligence, and scientific research. Companies may find that working with a local hosting provider offers benefits over engaging with larger organizations. The providers listed above present customers with access to capable, local GPU resources located in India. Atlantic.Net offers high-performance [GPU servers](https://www.atlantic.net/gpu-server-hosting/) leveraging the unmatched performance of advanced NVIDIA GPUs. They provide high reliability and global availability for AI training and other services that benefit from GPU servers. [Contact our team](https://www.atlantic.net/about-us/corporate-contact/) and learn more about our GPU server hosting services. --- # HIPAA-Ready AI Chatbots: Secure Hosting for Healthcare Innovation > URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-ready-ai-chatbots-secure-hosting-for-healthcare-innovation/ | Published: 2025-09-11 | Author: Dr. Assad Abbas [Artificial Intelligence (AI)](https://www.britannica.com/technology/artificial-intelligence) chatbots are becoming vital tools in healthcare. They facilitate patient communication, reduce wait times, and automate routine tasks, thus making medical services more efficient. According to recent reports, AI chatbots could save the global healthcare sector over [$3.7 billion](https://www.eltegra.ai/blog/healthcare-ai-chatbots-your-2025-implementation-reality-check) annually, primarily through improved scalability and operational efficiency. However, unlike other sectors, healthcare involves sensitive data known as [Protected Health Information (PHI)](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/). This includes medical records, insurance information, and any personal identifiers. Handling PHI is both a legal requirement and a professional responsibility. In the United States, the [Health Insurance Portability and Accountability Act (HIPAA)](https://www.ncbi.nlm.nih.gov/books/NBK500019/) defines strict standards for the privacy and security of such data. For AI chatbots to be widely adopted in healthcare, they must fully comply with these regulations. This involves secure data handling, strong encryption, and strict access controls. In addition to these measures, the hosting environment is also a critical aspect. [HIPAA-compliant platforms](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) offer the infrastructure required to meet these rules and keep patient information safe. ## HIPAA-Compliant Hosting for AI Chatbots in Healthcare AI chatbots are commonly used in healthcare facilities for better service delivery and communication. These systems respond to patient queries, assist in scheduling, and collect basic health information before clinical visits. Their round-the-clock availability enables patients to get support even outside regular office hours. This improves the patient experience and enables medical staff to focus on more critical cases rather than routine administrative tasks. However, the use of AI chatbots also raises significant concerns about data privacy. These systems often handle sensitive information, such as medical histories and personal details, to ensure compliance with regulatory standards. In the United States, HIPAA defines the legal requirements for protecting such data. To meet these requirements, chatbot systems should implement strong security measures that prevent unauthorized access, monitor interactions, and maintain the integrity of patient information throughout its lifecycle. In addition, the platforms that host these systems must also comply with HIPAA standards. Therefore, the cloud service providers offering HIPAA-compliant infrastructure are important to ensure secure storage and transmission of health data. ## Technical Readiness for Secure Chatbot Implementation Secure hosting is critical for AI chatbots used in healthcare. Since these systems deal with PHI, the hosting environment should keep data confidential, accurate, and available at all times. To meet HIPAA requirements, several measures, such as encryption, limited access, regular system checks, and reliable backups, are necessary. If the hosting is not compliant, even a well-designed chatbot can create serious privacy and security problems. On the other hand, HIPAA-compliant cloud services protect PHI during transfer, storage, and processing. This creates a safe and dependable base for healthcare chatbot operations. Following HIPAA standards is therefore not only a legal obligation but also a necessary practice for the safe and responsible use of AI chatbots in healthcare. ## Key Technical Requirements for HIPAA-Compliant Hosting To support AI chatbots in securely handling sensitive health information, hosting providers must implement several core technical safeguards. ### AI Chatbots All communication between the patient and the chatbot should be encrypted both when sent and when stored. This prevents sensitive health data from being accessed by unauthorized people and keeps the information protected. ### Granular Access Controls and Identity Management Only authorized personnel should be able to access the chatbot’s backend systems and stored data. To that end, hosting platforms must enforce strict access control mechanisms. This includes implementing [Role-Based Access Control (RBAC)](https://auth0.com/docs/manage-users/access-control/rbac), which ensures users only access information necessary for their responsibilities. [Multi-Factor Authentication (MFA)](https://www.atlantic.net/managed-services/multi-factor-authentication-examples/) introduces another layer of protection by verifying user identity during login. Together, these measures form part of a strong Identity and Access Management (IAM) framework that helps track user activity and supports regulatory audits. ### Comprehensive Audit Logging and Monitoring HIPAA requires precise tracking of all activities in the system. A secure hosting setup should keep detailed logs of user actions, data transfers, and any changes in settings. These records are checked through [Security Information and Event Management (SIEM)](https://www.microsoft.com/en-us/security/business/security-101/what-is-siem), which can automatically detect and flag unusual activity.. This ongoing process helps detect threats early and keeps a complete history for audits. ### Data Backup and Disaster Recovery Chatbots handling PHI must ensure data availability, even in cases of system failure or attack. This requires encrypted backups, retention policies, and geographically distributed data centers. Moreover, automated recovery protocols help maintain uninterrupted chatbot services. ### Physical Security Measures While digital security is essential, the physical infrastructure that supports the chatbot must also be protected. Hosting providers must enforce access restrictions at data centers using biometric scans, CCTV monitoring, and safeguards against fire, flooding, or power loss. ### Legal and Compliance Considerations Healthcare chatbots cannot be deployed using just any hosting provider. A Business Associate Agreement (BAA) is legally required to define the responsibilities of the host in managing PHI. Without a BAA, even a secure infrastructure is not compliant under HIPAA. ### Continuous Security Posture and Incident Response Chatbot environments must be monitored continuously to detect and respond to threats in real-time. In addition, incident response systems, penetration testing, and routine security audits are essential to maintain compliance and trust in the chatbot’s operations. ## Selecting and Configuring Hosting Providers for Secure Chatbot Deployment After identifying the technical requirements for HIPAA-compliant chatbot deployment, the next step is choosing a reliable and secure hosting provider. This process is not just about confirming basic compliance but also involves ensuring that the infrastructure is suitable for secure, scalable, and AI-specific workloads. Healthcare organizations should select hosting providers with a strong track record in managing healthcare applications and supporting AI-driven solutions. Leading cloud platforms offer HIPAA-eligible services with scalable infrastructure. Likewise, specialized providers like [Atlantic.Net](http://www.atlantic.net) focus exclusively on HIPAA-compliant hosting, offering tailored support for healthcare environments. However, choosing a HIPAA-ready provider is only the first step. True compliance requires proper configuration, strict access controls, and continuous monitoring throughout the deployment. Many healthcare chatbots are now deployed on cloud-native platforms that offer HIPAA-compliant Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) models, with dedicated tenancy options that reduce the risks associated with multi-tenant environments. For chatbots handling electronic Protected Health Information (ePHI), it is essential to use FIPS 140-2 validated encryption, TLS 1.3 for secure transmission, and AES-256 encryption for stored data. Moreover, additional measures, such as tokenization and masking of personally identifiable information, should be integrated to protect patient privacy. ## Securing Cloud Infrastructure for HIPAA-Compliant Chatbots Best practices for configuring cloud environments to support HIPAA-compliant chatbots include: - Hosting the chatbot backend within isolated [Virtual Private Clouds (VPCs)](https://www.atlantic.net/cloud-platform/virtual-private-cloud/), using strict access controls and custom security groups to prevent unauthorized exposure of patient data. - Deploying chatbot services in containerized environments, such as Docker or Kubernetes, using hardened container images to minimize attack surfaces. - Enabling real-time monitoring and logging tools like AWS CloudTrail or Azure Monitor to track every access point to PHI within chatbot conversations. Beyond the technical setup, hosting partners should also offer round-the-clock support, automated backup and disaster recovery, and undergo regular third-party security audits. These assurances are critical for chatbots that handle sensitive healthcare interactions, ensuring availability, reliability, and long-term compliance. ## Real-World Applications of HIPAA-Compliant Chatbots In 2024, [Stack AI](https://www.stack-ai.com/blog/how-to-build-a-hipaa-compliant-chatbot) deployed a HIPAA-compliant chatbot to support secure patient interactions and Electronic Health Record (EHR) integration. Its architecture enabled encrypted data handling, automated auditing, and scalable performance within isolated virtual private clouds. [Hathr.AI](https://hathr.ai/) used a HIPAA-compliant chatbot to power clinical documentation and insurance workflows. Its chatbot ensured PHI protection through strong encryption, client-level data isolation, and legal compliance via BAAs. A [third example](https://getstream.io/blog/building-an-end-to-end-encrypted-chatbot-with-stream-react-chat-virgil-security-and-google-dialogflow/) combined Stream Chat, Virgil Security, and Google Dialogflow to deliver encrypted, real-time communication for telemedicine apps. Hosted on Google Cloud, the chatbot supported secure patient messaging and intent recognition while maintaining HIPAA safeguards. These applications demonstrate how chatbots are transforming healthcare by enabling secure, compliant automation across patient engagement, documentation, and virtual care. ## The Bottom Line AI-powered chatbots are becoming essential tools in healthcare. Their effectiveness depends not only on accurate responses but also on the measures to protect patient data. Secure cloud hosting forms the vital foundation. Isolated environments, strict access controls, encryption, and real-time monitoring support HIPAA compliance. Tokenization and PII masking provide additional privacy protection during interactions. Backups, disaster recovery, and regular security audits help maintain trust and system reliability. Combined, these measures create a secure, scalable, and compliant environment for the responsible operation of healthcare chatbots. --- # How to Deploy a Linux VDI Solution on Atlantic.Net GPU Using Cendio Thinlinc > URL: https://www.atlantic.net/gpu-server-hosting/how-to-deploy-a-linux-vdi-solution-on-atlantic-net-gpu-using-cendio-thinlinc/ | Published: 2025-09-19 | Updated: 2026-05-04 | Author: Hitesh Jethva ThinLinc is a remote desktop server that allows multiple users to access graphical Linux desktops from anywhere securely. It is widely used in enterprise, education, and research environments because of its stability, scalability, and flexibility. What makes this setup even more powerful is the integration with NVIDIA GPUs and VirtualGL. By enabling GPU acceleration inside your ThinLinc sessions, you can run demanding applications like 3D visualization tools, machine learning notebooks, CAD software, and scientific simulations with smooth performance over the network. In this tutorial, you will learn how to deploy a Linux Virtual Desktop Infrastructure (VDI) solution on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/) using Cendio ThinLinc. ## Prerequisites Before starting with the installation, make sure your environment is ready. This will help you avoid common setup errors later. - Ubuntu 24.04 LTS (64-bit) with NVIDIA GPU and 8 GB RAM. - A root user or a user with sudo privileges. ## Step 1 – Install NVIDIA Driver To enable GPU acceleration inside your ThinLinc VDI, you need to install the NVIDIA driver and the CUDA toolkit on your Ubuntu 24.04 server. These components ensure that applications can leverage your GPU for 3D rendering, AI/ML workloads, and high-performance computing. 1. First, download the NVIDIA CUDA repository package and set up repository preferences. ``` wget https://developer.download.nvidia.com/compute/cuda/repos/ubuntu2404/x86_64/cuda-ubuntu2404.pin mv cuda-ubuntu2404.pin /etc/apt/preferences.d/cuda-repository-pin-600 ``` 2. Download and install the local CUDA repository package. ``` wget https://developer.download.nvidia.com/compute/cuda/12.8.0/local_installers/cuda-repo-ubuntu2404-12-8-local_12.8.0-570.86.10-1_amd64.deb dpkg -i cuda-repo-ubuntu2404-12-8-local_12.8.0-570.86.10-1_amd64.deb ``` 3. Copy the GPG key. ``` cp /var/cuda-repo-ubuntu2404-12-8-local/cuda-*-keyring.gpg /usr/share/keyrings/ ``` 4. Update the package list. ``` apt-get update ``` 5. Install the CUDA toolkit using APT. ``` apt-get -y install cuda-toolkit-12-8 ``` 6. Add CUDA binaries and libraries to your environment path. ``` echo "export PATH=/usr/local/cuda-12.8/bin${PATH:+:${PATH}}" >> ~/.bashrc echo "export LD_LIBRARY_PATH=/usr/local/cuda-12.8/lib64${LD_LIBRARY_PATH:+:${LD_LIBRARY_PATH}}" >> ~/.bashrc source ~/.bashrc ``` 7. Check if your GPU is detected correctly. ``` nvidia-smi ``` Output. ``` +-----------------------------------------------------------------------------------------+ | NVIDIA-SMI 550.90.07 Driver Version: 550.90.07 CUDA Version: 12.4 | |-----------------------------------------+------------------------+----------------------+ | GPU Name Persistence-M | Bus-Id Disp.A | Volatile Uncorr. ECC | | 0 NVIDIA A40-8Q Off | 00000000:06:00.0 Off | 0 | | 1MiB / 8192MiB | 0% Default | +-----------------------------------------------------------------------------------------+ | Processes: No running processes found | +-----------------------------------------------------------------------------------------+ ``` ## Step 2 – Install GNOME Desktop Environment To provide users with a graphical interface inside ThinLinc, you need a desktop environment installed on your Ubuntu 24.04 GPU server. In this guide, we will use GNOME Desktop, which is stable and widely supported. 1. Run the following command to install the complete GNOME desktop environment. ``` apt -y install task-gnome-desktop ``` This may take several minutes depending on your server’s resources and network speed, as it installs all necessary GNOME components. 2. Once the installation is complete, reboot your server to load GNOME services. ``` reboot ``` 3. After reboot, create a new non-root user that will be used for ThinLinc administration and login sessions. ``` adduser thinadm ``` Set a password when prompted and fill in optional user details. 4. Add the new user to the sudo group so they can run administrative commands. ``` usermod -aG sudo thinadm ``` 5. ThinLinc requires its binaries to be included in the secure path used by sudo. Edit the sudoers file. ``` nano /etc/sudoers ``` Find the Defaults secure_path line and update it to include ThinLinc paths: ``` Defaults secure_path="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin:/opt/thinlinc/bin:/opt/thinlinc/sbin" ``` 6. Log in as the newly created thinadm user: ``` su - thinadm ``` From here, you’ll install and configure the ThinLinc server in the next section. ## Step 3 – Install ThinLinc Server With GNOME installed, the next step is to set up Cendio ThinLinc. ThinLinc provides the VDI layer that enables multiple users to connect to your Ubuntu GPU server via browser or client. 1. Switch to your admin user (thinadm) and download the latest [ThinLinc](https://www.cendio.com/thinlinc/download/) server package. ``` wget https://www.cendio.com/downloads/server/tl-4.19.0-server.zip ``` 2. Unzip the downloaded file. ``` unzip tl-4.19.0-server.zip ``` 3. Go to the extracted directory. ``` cd tl-4.19.0-server ``` 4. Start the ThinLinc server installation. ``` sudo ./install-server ``` You will be asked to enter your user password. After successful authentication, the installation wizard will start in text mode. ``` [sudo] password for thinadm: Could not start GTK+. Using text mode fallback... ThinLinc server installation ============================ This program will help you install the ThinLinc software on your system. Before installing, see the platform specific notes at Platform specific notes Press Enter to continue... ``` 5. Press **Enter** to continue. The installer will list the packages to be installed. ``` Determining packages to install... done. The following packages will be installed: thinlinc-server_4.19.0-4116_amd64.deb Press Enter to continue... ``` 6. Press **Enter** again to start installing the package. ``` Performing package installation... done. All packages were installed successfully. Press Enter to continue... Installation of ThinLinc completed Before using ThinLinc, you must configure it using /opt/thinlinc/sbin/tl-setup. ``` 7. Type **Yes** and press **Enter** to launch the configuration wizard. ``` Run ThinLinc setup now [Yes/no]? Yes ``` 8. You must accept the license to continue. ``` Do you accept the terms of the license agreement [yes/No]? yes ``` 9. Choose **Master** as this will be the main server users connect to. ``` Server type =========== Select the type of ThinLinc server to configure. The master server is the one users will connect to. Agent servers are used to spread the resource load when just the master server is insufficent. If unsure, then pick Master. Server type [Master/agent]? Master ``` 10. The wizard will verify required libraries and binaries. Press **Enter** to continue and allow auto-installation of missing packages. ``` System check ============ Analyzing system... done. Library and binary requirements =============================== ThinLinc requires certain libraries and binaries to work as expected. This system lacks one or more of these. The necessary packages can be installed automatically by this wizard, or you can install them manually and restart the wizard. Press Enter to continue... ``` 11. The local drive redirection feature requires NFS client support. Type **Yes** to auto-install the packages. ``` Network file system support =========================== The local drive redirection feature requires that your system can act as an NFS client. The necessary packages can be installed automatically by this wizard, or you can install them manually and restart the wizard. Automatically install the necessary packages [Yes/no]? Yes ``` 12. ThinLinc requires GTK+, PyGObject, and the Python LDAP module. Type **Yes** when prompted to install them automatically. ``` GTK+ dependency =============== Some parts of ThinLinc require GTK+ and PyGObject to function correctly. Your system does not have these installed. The necessary packages can be installed automatically by this wizard, or you can install them manually and restart the wizard. Automatically install the necessary packages [Yes/no]? Yes Python dependency ================= The Python LDAP module is required for LDAP integration tools. Your system does not have this installed. The necessary packages can be installed automatically by this wizard, or you can install them manually and restart the wizard. Automatically install the necessary packages [Yes/no]? Yes ``` 13. Set the externally reachable address for ThinLinc. In this case, use the server’s IP. ``` External connections ==================== ThinLinc may not be externally accessible Externally reachable address to use * IP address * Hostname (vultr.guest) * Manually specified Externally reachable address to use [ip/hostname/manual]? ip ``` 14. Enter your email address to receive administrative alerts. ``` Administrator contact ===================== ThinLinc will send administrative messages, for example license warnings, to this email address. Administrator email []? hitjethva@gmail.com ``` 15. The ThinLinc Web Administration runs on port 1010. The default username is **admin.** Enter your desired password. ``` Web Administration ================== The default Web Administration username is "admin". Enter the desired password for this user, or leave unchanged to skip this step. The ThinLinc Web Administration is running on port 1010 (https) on this server. Web Administration password? ``` 16. ThinLinc requires AppArmor configuration for security. Type **Yes** to install it. ``` AppArmor ======== This system is using the AppArmor access control system. A ThinLinc configuration needs to be loaded for some applications to operate correctly in this environment. Would you like to install the ThinLinc AppArmor configuration? Install AppArmor configuration [Yes/no]? Yes ``` 17. The wizard will configure and start all services automatically. ``` Configuring services and timers =============================== Configuring and starting ThinLinc services and timers... done. All ThinLinc services and timers have been configured and started successfully. Press Enter to continue... ``` 18. Press **Enter** to complete the installation. ``` ThinLinc has been setup ======================= The ThinLinc Web Administration is available at https://localhost:1010, and the configuration files are located in /opt/thinlinc/etc/conf.d/. Icons for the ThinLinc Web Access, ThinLinc Web Administration and ThinLinc setup have been added to the menu. Visit https://www.cendio.com/thinlinc/support for information on how to contact us. Press Enter to continue... ``` 19. Check that the core services are running. ``` sudo systemctl status vsmserver sudo systemctl status vsmagent sudo systemctl status tlwebaccess sudo systemctl status tlwebadm ``` At this point, ThinLinc is installed and configured. Users can already connect to GNOME sessions, but GPU acceleration is not yet enabled. ## Step 4 – Install and Configure VirtualGL .ThinLinc provides the remote desktop environment, but by default, 3D applications won’t use the GPU. To enable GPU acceleration, you’ll integrate VirtualGL with ThinLinc. **VirtualGL** redirects OpenGL rendering to the GPU and streams the results to remote clients, making it ideal for CAD, 3D visualization, and machine learning tools. 1. Add the VirtualGL repository and GPG key. ``` wget -qO- https://packagecloud.io/dcommander/virtualgl/gpgkey | sudo gpg --dearmor -o /usr/share/keyrings/virtualgl-archive-keyring.gpg echo "deb [signed-by=/usr/share/keyrings/virtualgl-archive-keyring.gpg] https://packagecloud.io/dcommander/virtualgl/any any main" | sudo tee /etc/apt/sources.list.d/virtualgl.list ``` 2. Update the package index. ``` sudo apt update ``` 3. Install the VirtualGL package. ``` sudo apt install virtualgl mesa-utils ``` 4. Check the installed version. ``` vglrun --version ``` Output. ``` VirtualGL v3.1.3 (Build 20250409) ``` 5. Configure VirtualGL. ``` sudo /opt/VirtualGL/bin/vglserver_config ``` Choose the following options when prompted: ``` 1) Configure server for use with VirtualGL (GLX + EGL back ends) 2) Unconfigure server for use with VirtualGL (GLX + EGL back ends) 3) Configure server for use with VirtualGL (EGL back end only) 4) Unconfigure server for use with VirtualGL (EGL back end only) X) Exit Choose: 1 WARNING: Configuring this server for use with VirtualGL will disable the ability to log in locally with a Wayland session. Continue? [Y/n]Y Restrict 3D X server access to vglusers group (recommended)? [Y/n]Y Restrict framebuffer device access to vglusers group (recommended)? [Y/n]Y Disable XTEST extension (recommended)? [Y/n]Y Done. You must restart the display manager for the changes to take effect. 1) Configure server for use with VirtualGL (GLX + EGL back ends) 2) Unconfigure server for use with VirtualGL (GLX + EGL back ends) 3) Configure server for use with VirtualGL (EGL back end only) 4) Unconfigure server for use with VirtualGL (EGL back end only) X) Exit Choose:X ``` 6. Stop the display manager and NVIDIA service. ``` sudo systemctl stop gdm sudo systemctl stop nvidia-persistenced ``` 7. **nvidia_uvm** (Unified Memory) and **nvidia_drm/modeset** (Direct Rendering Manager) can hold onto GPU resources. VirtualGL needs clean access to the GPU for 3D acceleration over ThinLinc. So, first, you will need to unload the following modules. ``` sudo modprobe -r nvidia_uvm nvidia_drm nvidia_modeset nvidia ``` 8. Start both the display manager and the NVIDIA service. ``` sudo systemctl start gdm nvidia-persistenced ``` 9. Since cloud GPUs like Tesla or A40 don’t have display outputs, you need to configure a virtual display. Get the Bus ID of your GPU. ``` sudo nvidia-xconfig --query-gpu-info ``` Output. ``` Number of GPUs: 1 GPU #0: Name : NVIDIA A40-8Q UUID : GPU-5485b57b-8ec4-11f0-b9a9-33e0990b9a26 PCI BusID : PCI:6:0:0 Number of Display Devices: 0 ``` 10. Create an Xorg configuration for headless mode using the above Bus ID. ``` sudo nvidia-xconfig -a --allow-empty-initial-configuration --use-display-device=None \ --virtual=1920x1200 --busid PCI:6:0:0 ``` 11. Create the group and add your ThinLinc user **(thinadm)** to it. ``` sudo groupadd vglusers sudo usermod -aG vglusers thinadm ``` 12. Reboot the server to apply changes. ``` sudo reboot ``` At this point, VirtualGL is configured, and your ThinLinc sessions can run GPU-accelerated applications. ## Step 5 – Configure Firewall for ThinLinc Access ThinLinc requires several ports to be open so that remote users can connect to the server and access the web administration panel. On Ubuntu 24.04, the easiest way to manage firewall rules is with UFW (Uncomplicated Firewall). 1. By default, the ThinLinc server uses the following ports: **22** – SSH connection **300** – Web Access **9000** – ThinLinc Client Access **1010** – ThinLinc control panel access For ThinLinc remote desktop access, you need to open these ports on your cloud server. 2. Allow all required ports. ``` sudo ufw allow 22 sudo ufw allow 300 sudo ufw allow 9000 sudo ufw allow 1010 ``` 3. If your firewall is disabled, enable it with the command below. ``` sudo ufw enable ``` 4. List all active firewall rules. ``` sudo ufw status numbered ``` ## Step 6 – Access ThinLinc via Web Browser and Test GPU Acceleration Now that ThinLinc and VirtualGL are configured, it’s time to log in remotely and confirm that your VDI solution is working with GPU acceleration. 1. Open your web browser on your local system and access the Ubuntu remote desktop using the URL **https://your-server-ip:300.** You will be redirected to the Ubuntu desktop login screen. ![](https://www.atlantic.net/wp-content/uploads/2025/09/p1-3.png) 2. Enter the following details in the login screen. **Username** – thinadm (or another user you created). **Password** – the user’s password. Click **Login** to start a GNOME desktop session inside your browser. ![](https://www.atlantic.net/wp-content/uploads/2025/09/p4.png) 3. Once logged in, open a GNOME terminal from the ThinLinc desktop. This allows you to test applications inside the remote session. Run a 3D test with VirtualGL to check if GPU acceleration works ``` vglrun -d $DISPLAY glxgears ``` A small window opens with three spinning gears. The terminal shows FPS (frames per second) output, proving that rendering is happening via your GPU. ![](https://www.atlantic.net/wp-content/uploads/2025/09/a1.png) You can also verify that the GPU is in use by running: ``` nvidia-smi ``` ## Step 7 – Access Ubuntu Desktop via ThinLinc GUI Client While ThinLinc can be accessed through a web browser, using the ThinLinc GUI Client provides better performance, additional features (like sound redirection, media redirection), and a smoother experience over slow connections. The client is available for Linux, Windows, and macOS. 1. First, download the ThinLinc client **.deb** package on your local desktop machine ``` wget https://www.cendio.com/downloads/clients/thinlinc-client_4.19.0-4005_amd64.deb ``` 2. Next, install the downloaded package using the apt command. ``` sudo apt install ./thinlinc-client_4.19.0-4005_amd64.deb ``` This will install the ThinLinc client on your Ubuntu machine. 3. After installation, launch the client from the Applications menu (Ubuntu Dash) ![](https://www.atlantic.net/wp-content/uploads/2025/09/b1.png) You’ll see a connection window prompting. Enter the following details. **Server** – your ThinLinc server IP or hostname (e.g., your-server-ip). **Username** – thinadm (or another created user). **Password** – user’s login password. Then,  click **Connect.** 3. After successful login, the client opens a full GNOME desktop session. ![](https://www.atlantic.net/wp-content/uploads/2025/09/b2.png) Unlike the web version, the GUI client supports: - **Sound redirection** – play audio on the remote server and hear it locally. - **Optimized performance** – better video streaming over low-bandwidth connections. - **Clipboard support** – copy/paste between local and remote desktop. ## Step 8 – Access ThinLinc Control Panel ThinLinc comes with a web-based administration panel that allows you to monitor and configure your VDI server. This is where administrators can manage users, sessions, profiles, and licenses. 1. On your local system, open a browser and go to: ``` https://your-server-ip:1010 ``` You’ll be redirected to the ThinLinc Web Administration login screen. ![](https://www.atlantic.net/wp-content/uploads/2025/09/c1.png) 2. Enter the credentials you set during the setup wizard: **Username** – admin **Password** – (the one you defined during ThinLinc installation) Click **Sign in.**Once logged in, you’ll see the ThinLinc Control Panel. ![](https://www.atlantic.net/wp-content/uploads/2025/09/c2.png) ## Conclusion In this tutorial, you deployed a Linux Virtual Desktop Infrastructure (VDI) on an Ubuntu 24.04 GPU server using Cendio ThinLinc with VirtualGL support. This setup enables multiple users to connect to a secure remote GNOME desktop with full GPU acceleration. You now have a complete GPU-accelerated Linux VDI environment powered by ThinLinc. Remote users can connect securely and leverage full graphics acceleration from anywhere in the world. --- # Build an AI Chatbot Frontend with React, Next.js, and FastAPI Powered by Ollama & DeepSeek-R1 > URL: https://www.atlantic.net/gpu-server-hosting/build-an-ai-chatbot-frontend-with-react-next-js-and-fastapi-powered-by-ollama-deepseek-r1/ | Published: 2025-09-19 | Updated: 2026-05-04 | Author: Hitesh Jethva AI chatbots are no longer just a fun experiment; they’re becoming an important part of modern applications. With powerful open-source models like DeepSeek-R1 and tools like Ollama, you can run advanced language models locally without relying on external APIs. In this tutorial, you’ll learn how to build a complete chatbot system powered by Ollama + DeepSeek-R1 on the backend and a React/Next.js frontend for a modern, responsive chat interface. ## Prerequisites - An Ubuntu 24.04 server with an [NVIDIA GPU](https://www.atlantic.net/gpu-server-hosting/an-overview-of-popular-nvidia-gpus/). - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1 – Install Required Dependencies Before we build the chatbot, we need to prepare the environment with the required tools for both the backend (FastAPI + Python) and the frontend (React + Next.js). 1. Install Python and other dependencies. ``` apt install python3 python3-pip python3-venv git curl nodejs npm ``` 2. Ollama is the runtime we’ll use to run the DeepSeek-R1 model locally. Install it with the following command. ``` curl -fsSL https://ollama.com/install.sh | sh ``` 3. Verify the installation. ``` ollama --version ``` Output. ``` ollama version is 0.11.10 ``` 4. Start and enable the Ollama service. ``` systemctl start ollama systemctl enable ollama ``` 5. Download the DeepSeek-R1 (7B) model. ``` ollama pull deepseek-r1:7b ``` 6. Run the model interactively to confirm it works. ``` ollama run deepseek-r1:7b ``` You should get an interactive prompt. Type a question like: ``` >>> What is the capital of France? ``` If it responds, your model is ready. ``` The capital of France is Paris. ``` ## Step 2 – Backend Setup with FastAPI The backend will act as a bridge between the frontend (React + Next.js) and Ollama (DeepSeek-R1). We’ll use FastAPI to handle chat requests and return AI-generated responses. 1. First, create the backend directory and set up a Python virtual environment. ``` mkdir -p chatbot-project/backend cd chatbot-project/backend python3 -m venv venv source venv/bin/activate ``` 2. Now install the required Python dependencies. ``` pip install fastapi uvicorn pydantic ollama requests ``` 3. Save them into a requirements.txt file. ``` pip freeze > requirements.txt ``` 4. Create a file for the FastAPI server. ``` nano app.py ``` Add the following code. ``` # chatbot-project/backend/app.py from fastapi import FastAPI from pydantic import BaseModel from ollama import Client class ChatRequest(BaseModel): message: str app = FastAPI() ollama = Client(host="http://localhost:11434") # Ollama default endpoint @app.post("/chat") async def chat(req: ChatRequest): response = ollama.chat(model="deepseek-r1:7b", messages=[{"role": "user", "content": req.message}]) return {"reply": response["message"]["content"]} ``` 5. Start the backend server with Uvicorn. ``` uvicorn app:app --host 0.0.0.0 --port 8000 & ``` Output. ``` Backend is now available at: 👉 http://localhost:8000/chat ``` 6. Test it with curl. ``` curl -X POST http://localhost:8000/chat \ -H "Content-Type: application/json" \ -d '{"message": "Hello, how are you?"}' ``` You should see a JSON response with a reply. ``` INFO: 127.0.0.1:34508 - "POST /chat HTTP/1.1" 200 OK {"reply":"\n\n\n\nHello! I'm just a virtual assistant, so I don't have feelings, but I'm here and ready to help you with whatever you need. How are you doing today? 😊"} ``` ## Step 3 – Frontend Setup with Next.js + React The frontend is where users will interact with your chatbot. We’ll use React with Next.js to build a functional but straightforward chat interface. 1. From your project root (chatbot-project/), create the frontend app: ``` cd ../ npx create-next-app@latest frontend --ts ``` Answer the questions as shown below. ``` Need to install the following packages: create-next-app@15.5.3 Ok to proceed? (y) y ✔ Which linter would you like to use? › ESLint ✔ Would you like to use Tailwind CSS? … No / Yes ✔ Would you like your code inside a `src/` directory? … No / Yes ✔ Would you like to use App Router? (recommended) … No / Yes ✔ Would you like to use Turbopack? (recommended) … No / Yes ✔ Would you like to customize the import alias (`@/*` by default)? … No / Yes Creating a new Next.js app in /root/chatbot-project/frontend. ``` 2. After installation, move into the frontend folder and install dependencies. ``` cd frontend npm install ``` 3. Edit the index.tsx to build the chat UI. ``` nano pages/index.tsx ``` Remove default content and add the code below: ``` // chatbot-project/frontend/pages/index.tsx import { useState } from 'react'; export default function Home() { const [messages, setMessages] = useState<{ role: string; content: string }[]>([]); const [input, setInput] = useState(""); const send = async () => { if (!input.trim()) return; const userMsg = { role: "user", content: input }; setMessages([...messages, userMsg]); setInput(""); const res = await fetch("/api/chat", { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify({ message: userMsg.content }), }); const data = await res.json(); setMessages([...messages, userMsg, { role: "bot", content: data.reply }]); }; return (

AI Chatbot

{messages.map((m, i) => (

{m.role}: {m.content}

))}
setInput(e.target.value)} onKeyDown={e => e.key === "Enter" && send()} placeholder="Type your message…" style={{ width: '80%' }} />
); } ``` 4. Edit the next.config.js file to configure the API proxy. ``` nano next.config.js ``` Add the following code. ``` // chatbot-project/frontend/next.config.js module.exports = { async rewrites() { return [ { source: '/api/:path*', destination: 'http://127.0.0.1:8000/:path*', // use IPv4 instead of ::1 }, ]; }, experimental: { allowedDevOrigins: ["http://localhost:3000", "http://127.0.0.1:3000"], }, }; ``` This proxy forwards frontend /api/chat requests to the FastAPI backend. 5. Start the Next.js dev server. ``` npm run dev -- -H 0.0.0.0 & ``` 6. Open the web browser and access the Next.js web UI using the URL **http://your-server-ip:3000.** Type a message like: ``` Who won the 2018 FIFA World Cup? ``` Then, click on **Send.** You should see a chat bubble with your question and a bot reply generated by DeepSeek-R1. ![](https://www.atlantic.net/wp-content/uploads/2025/09/p1-2.png) ## Conclusion You have now built a complete AI chatbot system that combines Ollama with the DeepSeek-R1 model on the backend and a modern Next.js and React interface on the frontend. The FastAPI server acts as the bridge between the two, handling requests and delivering responses seamlessly. By running the model locally through Ollama, you gain both speed and control, while the frontend provides an easy and interactive way for users to chat with the AI. --- # How to Run Distilled Stable Diffusion with Gradio on Ubuntu 24.04 GPU > URL: https://www.atlantic.net/gpu-server-hosting/how-to-run-distilled-stable-diffusion-with-gradio-on-ubuntu-24-04-gpu/ | Published: 2025-09-19 | Author: Hitesh Jethva Stable Diffusion has become one of the most popular models for generating high-quality AI images from text prompts. However, running the full model often requires significant GPU memory and can be slow on smaller servers. This is where distilled Stable Diffusion comes into play. A distilled model is a lightweight, optimized version of the original model. It produces high-quality images while reducing computation time and resource usage, making it ideal for deployment on cloud GPU servers. In this guide, you’ll learn how to set up and run a distilled Stable Diffusion pipeline with Gradio on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1 – Install System Dependencies Before setting up Stable Diffusion and Gradio, you need to install a few essential system packages. 1. Next, you’ll install Python 3.10, since it’s recommended for working with modern AI frameworks. Ubuntu 24.04 may not ship with it by default, so you’ll add the deadsnakes PPA. ``` add-apt-repository ppa:deadsnakes/ppa ``` 2. Update the repository index. ``` apt update -y ``` 3. Install Python3.10 with additional dependencies. ``` apt install python3.10 python3.10 python3.10-venv libgl1 libglib2.0-0 git wget curl -y ``` 4. Create a virtual environment and activate it. ``` python3.10 -m venv venv source venv/bin/activate ``` 5. Upgrade pip and install required libraries. ``` pip install --upgrade pip pip install torch torchvision diffusers transformers gradio ``` ## Step 2 – Build the Gradio Application Now that your environment is ready, let’s set up a dedicated workspace for the project. This will help you keep all files organized in one place. 1. Create a new directory and move into it. ``` mkdir ~/distil-sd-gradio && cd ~/distil-sd-gradio ``` 2. Next, create a Python file named app.py. This will be the main script for running the distilled Stable Diffusion model with Gradio. ``` nano app.py ``` Add the following code. ``` from diffusers import StableDiffusionPipeline import torch import gradio as gr model_id = "nota-ai/bk-sdm-small" # distilled model pipe = StableDiffusionPipeline.from_pretrained( model_id, torch_dtype=torch.float16, use_safetensors=True ).to("cuda") def generate(prompt): image = pipe(prompt, guidance_scale=7.5, num_inference_steps=50).images[0] return image demo = gr.Interface( fn=generate, inputs=gr.Textbox(label="Prompt"), outputs=gr.Image(type="pil"), title="Distilled Stable Diffusion (Gradio)", description="Generate images using the distilled Stable Diffusion model." ) if __name__ == "__main__": demo.launch(server_name="0.0.0.0", server_port=7860) ``` 3. Now that your app.py file is ready, it’s time to launch the Gradio server and test your distilled Stable Diffusion model. ``` python3.10 app.py ``` Output. ``` Running on local URL: http://127.0.0.1:7860 Running on public URL: http://your_server_ip:7860 ``` ## Step 3 – Testing the Web UI With the Gradio server running, you can now test the distilled Stable Diffusion interface directly from your browser. 1. Open the Gradio interface using the URL **http://your_server_ip:7860** in your browser. You’ll see a clean interface with a Prompt textbox and a Generate button. 2. In the Prompt field, type the following description of the image you’d like to create and click **Submit.** The server will return the generated image to the Gradio interface. **“A futuristic cyberpunk city skyline at night, glowing neon lights.”** ![](https://www.atlantic.net/wp-content/uploads/2025/09/p1-1.png) **“A cute cartoon panda playing guitar.”** ![](https://www.atlantic.net/wp-content/uploads/2025/09/p2-1.png) **“A realistic photo of a mountain lake at sunrise.”** ![](https://www.atlantic.net/wp-content/uploads/2025/09/p3-1.png) ## Conclusion In this guide, you successfully deployed a distilled Stable Diffusion model on an Ubuntu 24.04 GPU server and built a simple Gradio web interface to generate images from text prompts. By using a distilled model, you achieved faster inference and reduced GPU resource usage compared to running the full Stable Diffusion pipeline, while still producing high-quality results. --- # Audio Transcription Effortlessly with Distill Whisper AI on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/audio-transcription-effortlessly-with-distill-whisper-ai-on-ubuntu-24-04-gpu-server/ | Published: 2025-09-19 | Updated: 2026-05-04 | Author: Hitesh Jethva Transcribing audio into text has become an important task across industries. Whether you are a researcher handling interviews, a content creator working on podcasts, or a business professional managing meeting notes, turning speech into written text saves time and improves productivity. Traditionally, transcription tools required either manual effort or expensive software. With the rise of modern AI models, transcription has become faster and more accessible. Distil Whisper AI, a lightweight and optimized version of OpenAI’s Whisper model, makes this process effortless while maintaining high accuracy. In this tutorial, you will learn how to set up Distil Whisper AI on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1 – Setting Up Python Environment Before running Distil Whisper AI, you need to prepare a clean environment with all the required dependencies. 1. First, update your system and install the basic tools along with FFmpeg, which is necessary for handling audio files. ``` apt update -y apt install -y python3 python3-venv python3-pip ffmpeg ``` 2. Next, create a dedicated environment for Distil Whisper AI and activate it. ``` python3 -m venv distilwhisper-env source distilwhisper-env/bin/activate ``` 3. Upgrade pip to the latest version. ``` pip install --upgrade pip ``` 4. Finally, install the libraries needed to run Distil Whisper AI. ``` pip install transformers datasets torchaudio ``` 5. Verify the GPU availability. ``` python3 - <<'EOF' import torch print("CUDA available:", torch.cuda.is_available()) print("GPU name:", torch.cuda.get_device_name(0) if torch.cuda.is_available() else "CPU only") EOF ``` If your server has a working NVIDIA GPU with CUDA drivers installed, you should see output like: ``` CUDA available: True GPU name: NVIDIA A40-8Q ``` ## Step 2 – Building the First Transcription Script Now that the environment is ready and the GPU is detected, let’s build our first transcription script using Distil Whisper AI. This script will load the model, set up the pipeline, and transcribe a short audio file. 1. Create the script file. ``` nano transcribe.py ``` Add the following code. ``` import torch from transformers import AutoModelForSpeechSeq2Seq, AutoProcessor, pipeline # Detect GPU device = "cuda" if torch.cuda.is_available() else "cpu" torch_dtype = torch.float16 if torch.cuda.is_available() else torch.float32 # Load Distil-Whisper model_id = "distil-whisper/distil-large-v2" print(f"Loading model {model_id} on {device}...") model = AutoModelForSpeechSeq2Seq.from_pretrained( model_id, torch_dtype=torch_dtype, low_cpu_mem_usage=True, use_safetensors=True ).to(device) processor = AutoProcessor.from_pretrained(model_id) # Build pipeline pipe = pipeline( "automatic-speech-recognition", model=model, tokenizer=processor.tokenizer, feature_extractor=processor.feature_extractor, max_new_tokens=128, torch_dtype=torch_dtype, device=0 if torch.cuda.is_available() else -1 ) # Test transcription audio_file = "sample.mp3" # Replace with your own audio file print(f"Transcribing: {audio_file}") result = pipe(audio_file) print("\n--- Transcription Result ---") print(result["text"]) ``` 2. Use wget to fetch a short audio file and save it as sample.mp3. ``` wget -O sample.mp3 https://github.com/pyannote/pyannote-audio/raw/develop/tutorials/assets/sample.wav ``` 3. Run the script. ``` python3 transcribe.py ``` You should see something like this in your terminal: ``` --- Transcription Result --- Hello? Hello? Oh, hello, I didn't know you were there. Neither did I. Okay, I thought, you know, I heard a beep. This is Diane in New Jersey. And I'm Sheila and Texas, originally from Chicago. Oh, I'm originally from Chicago also. I'm in New Jersey now, though. Well, there isn't that much difference. At least, you know, they all call me a Yankee down here, so what kind of that. Oh, I don't hear that in New Jersey now. ``` The output may vary slightly depending on the Distil Whisper model’s decoding, but you’ll get a clear, accurate transcript of the conversation in the audio. ## Step 3 – Handling Long Audio Files The script we created in the previous section works well for short clips, but many real-world use cases involve longer recordings — such as meetings, podcasts, or lectures. Processing a long audio file directly can overwhelm the model, so we need to split the audio into manageable chunks and transcribe them piece by piece. 1. Create a new script. ``` nano transcribe_long.py ``` Add the following code. ``` # File: transcribe_long.py import torch from transformers import AutoModelForSpeechSeq2Seq, AutoProcessor, pipeline device = "cuda" if torch.cuda.is_available() else "cpu" torch_dtype = torch.float16 if torch.cuda.is_available() else torch.float32 model_id = "distil-whisper/distil-large-v2" print(f"Loading model {model_id} on {device}...") model = AutoModelForSpeechSeq2Seq.from_pretrained( model_id, torch_dtype=torch_dtype, low_cpu_mem_usage=True, use_safetensors=True ).to(device) processor = AutoProcessor.from_pretrained(model_id) pipe = pipeline( "automatic-speech-recognition", model=model, tokenizer=processor.tokenizer, feature_extractor=processor.feature_extractor, max_new_tokens=128, chunk_length_s=15, # split into 15s chunks batch_size=16, # process 16 chunks in parallel torch_dtype=torch_dtype, device=0 if torch.cuda.is_available() else -1 ) audio_file = "long_sample.mp3" # Replace with your file print(f"Transcribing (long mode): {audio_file}") result = pipe(audio_file) print("\n--- Long Transcription Result ---") print(result["text"]) ``` Note: Replaced the long_sample.mp3 file with your own long file. 2. Run the script. ``` python3 transcribe_long.py ``` ## Step 4 – Building a Web Interface with Gradio So far, you’ve been running transcription from the command line. That works well for quick tests, but in real projects you’ll often want a user-friendly interface where you can upload files or record audio directly in your browser. For this, we’ll use Gradio, a lightweight Python library for creating web apps. 1. Install the additional packages needed for Gradio and microphone input. ``` pip install sounddevice scipy gradio soundfile apt install libportaudio2 ``` 2. Create an app file. ``` nano app.py ``` Add the following code. ``` # File: app.py import torch import gradio as gr from transformers import AutoModelForSpeechSeq2Seq, AutoProcessor, pipeline # ------------------------------ # Setup # ------------------------------ device = "cuda" if torch.cuda.is_available() else "cpu" torch_dtype = torch.float16 if torch.cuda.is_available() else torch.float32 model_id = "distil-whisper/distil-large-v2" print(f"Loading {model_id} on {device}...") model = AutoModelForSpeechSeq2Seq.from_pretrained( model_id, torch_dtype=torch_dtype, low_cpu_mem_usage=True, use_safetensors=True ).to(device) processor = AutoProcessor.from_pretrained(model_id) # Short pipeline (<30s) pipe_short = pipeline( "automatic-speech-recognition", model=model, tokenizer=processor.tokenizer, feature_extractor=processor.feature_extractor, max_new_tokens=128, torch_dtype=torch_dtype, device=0 if torch.cuda.is_available() else -1 ) # Long pipeline (>30s, chunked) pipe_long = pipeline( "automatic-speech-recognition", model=model, tokenizer=processor.tokenizer, feature_extractor=processor.feature_extractor, max_new_tokens=128, chunk_length_s=15, batch_size=16, torch_dtype=torch_dtype, device=0 if torch.cuda.is_available() else -1 ) # ------------------------------ # Functions # ------------------------------ def transcribe_short(audio_file): if audio_file is None: return "No audio uploaded." result = pipe_short(audio_file) return result["text"] def transcribe_long(audio_file): if audio_file is None: return "No audio uploaded." result = pipe_long(audio_file) return result["text"] def transcribe_mic(audio_file): if audio_file is None: return "No recording found." result = pipe_short(audio_file) return result["text"] # ------------------------------ # Gradio UI # ------------------------------ with gr.Blocks() as demo: gr.Markdown("## 🎙️ Distil-Whisper AI — Audio Transcription on Ubuntu 24.04 GPU Server") with gr.Tab("Short File (<30s)"): audio_short = gr.Audio(sources=["upload"], type="filepath", label="Upload audio file") output_short = gr.Textbox(label="Transcription") btn_short = gr.Button("Transcribe") btn_short.click(transcribe_short, inputs=audio_short, outputs=output_short) with gr.Tab("Long File (>30s)"): audio_long = gr.Audio(sources=["upload"], type="filepath", label="Upload long audio file") output_long = gr.Textbox(label="Transcription") btn_long = gr.Button("Transcribe") btn_long.click(transcribe_long, inputs=audio_long, outputs=output_long) with gr.Tab("Live Mic (Browser)"): audio_mic = gr.Audio(sources=["microphone"], type="filepath", label="Record from your browser") output_mic = gr.Textbox(label="Transcription") btn_mic = gr.Button("Transcribe Recording") btn_mic.click(transcribe_mic, inputs=audio_mic, outputs=output_mic) # ------------------------------ # Launch with HTTPS (gradio.live) # ------------------------------ demo.launch( share=True, # 🌍 get https://.gradio.live server_name="0.0.0.0", # allow external connections server_port=7860 ) ``` 3. Run the application to start the Gradio interface. ``` python3 app.py ``` You’ll see something like: ``` Running on local URL: http://127.0.0.1:7860 Running on public URL: https://c914b0a89448da8a6d.gradio.live ``` The public URL **(.gradio.live)** allows you to access the app securely without extra setup. ## Step 5 – Access the Gradio App With your Gradio app ready, it’s time to test it. This section will walk you through launching the app and using its different features for transcription. 1. Open your web browser and access the public URL **https://c914b0a89448da8a6d.gradio.live.** You’ll see three tabs: - **Short File (<30s)** – Upload an audio clip shorter than 30 seconds. - **Long File (>30s)** – Upload longer files such as meetings, lectures, or podcasts. - **Live Mic (Browser)** – Record directly from your browser and transcribe the recording. 2. Try uploading the sample file we downloaded earlier **(sample.mp3)** using the **Short File** tab. You should see the same transcript as before, but this time through a clean web interface. ![](https://www.atlantic.net/wp-content/uploads/2025/09/p1.png) 3. Click on **Live Mic (Browser)** tab. You will see the following page. ![](https://www.atlantic.net/wp-content/uploads/2025/09/p2.png) 4. Click on **Record** to start recording your voice. Then, click **Transcribe Recording,** you will see the transcribed text below the screen. ![](https://www.atlantic.net/wp-content/uploads/2025/09/p3.png) ## Conclusion In this tutorial, you learned how to set up Distil Whisper AI for effortless audio transcription on an Ubuntu 24.04 GPU server. Starting from environment setup and GPU verification, you built your first transcription script for short files, extended it to handle long recordings, and finally created a Gradio-powered web app to make transcription accessible directly from the browser. By leveraging the GPU, Distil Whisper delivers fast and accurate results, making it ideal for a wide range of use cases from meeting notes and podcasts to interviews and live speech. --- # How to Train YOLOv5 on a Custom Dataset on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/how-to-train-yolov5-on-a-custom-dataset-on-ubuntu-24-04-gpu-server/ | Published: 2025-09-19 | Author: Hitesh Jethva Object detection is one of the most powerful applications of computer vision, and YOLOv5 (You Only Look Once, version 5) has become one of the most popular frameworks to accomplish this. It is fast, lightweight, and accurate, making it suitable for both research and real-world deployment. In this tutorial, you’ll learn how to train YOLOv5 on a custom dataset using an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1 – Install Dependencies Before training YOLOv5, you need to prepare the environment by installing Python, Git, and other required tools. We’ll also create a virtual environment so that your YOLOv5 setup remains clean and isolated from system packages. 1. Install Python 3, pip, virtual environment support, Git, and unzip. ``` apt install python3 python3-pip python3-venv git unzip -y ``` 2. It’s a good practice to work in a virtual environment. This avoids conflicts with system-wide libraries. ``` python3 -m venv yolov5-env source yolov5-env/bin/activate ``` After activation, you should see (yolov5-env) at the start of your terminal prompt. 3. Inside the virtual environment, upgrade pip to the latest version. ``` pip install --upgrade pip ``` ## Step 2 – Download and Set Up YOLOv5 With the dependencies ready, the next step is to download the official YOLOv5 repository and install its requirements. 1. Use git to clone the YOLOv5 source code. ``` git clone https://github.com/ultralytics/yolov5.git ``` 2. Navigate to the downloaded directory. ``` cd yolov5 ``` 3. Inside the YOLOv5 folder, install all required Python packages. ``` pip install -r requirements.txt ``` This command installs PyTorch, OpenCV, and other libraries needed for training and inference. Since you’re running on a GPU server, make sure PyTorch installs with CUDA support. ## Step 3 – Download the Road Sign Dataset from Kaggle Now that YOLOv5 is installed, we need a dataset to train our model. For this tutorial, we’ll use the Road Sign Detection dataset from Kaggle, which contains 877 images with annotated bounding boxes in Pascal VOC XML format. 1. Install the Kaggle CLI tool. ``` pip install kaggle ``` 2. Go to your Kaggle account → Account Settings → Create New API Token. 3. This will download a kaggle.json file (your API credentials). Transfer this JSON file to your server. 4. Move this file to the proper location and secure it with permissions ``` mkdir -p ~/.kaggle cp kaggle.json ~/.kaggle/ chmod 600 ~/.kaggle/kaggle.json ``` 5. Make a dedicated folder to store datasets. ``` mkdir datasets ``` 6. Now download the dataset using Kaggle CLI. ``` kaggle datasets download -d andrewmvd/road-sign-detection ``` 7. Unzip the downloaded dataset to the datasets directory. ``` unzip road-sign-detection.zip -d datasets/roadsign ``` 8. After extracting, your dataset should look like this: ``` datasets/roadsign/ ├── annotations/ # Pascal VOC XML annotations └── images/ # 877 images ``` ## Step 4 – Convert Pascal VOC Annotations to YOLO Format The Road Sign dataset annotations are provided in Pascal VOC XML format, but YOLOv5 requires annotations in YOLO text format **(.txt** files). Each **.txt** file corresponds to one image and contains the class ID and normalized bounding box coordinates. 1. Create a new conversion script. ``` nano convert_voc_to_yolo.py ``` Paste the following code: ``` import os import xml.etree.ElementTree as ET # Classes in dataset classes = ["trafficlight", "stop", "speedlimit", "crosswalk"] input_dir = "datasets/roadsign/annotations" output_dir = "datasets/roadsign/labels" os.makedirs(output_dir, exist_ok=True) def convert_bbox(size, box): dw, dh = 1.0/size[0], 1.0/size[1] x = (box[0] + box[1]) / 2.0 y = (box[2] + box[3]) / 2.0 w = box[1] - box[0] h = box[3] - box[2] return (x*dw, y*dh, w*dw, h*dh) for file in os.listdir(input_dir): if not file.endswith(".xml"): continue in_file = open(os.path.join(input_dir, file)) tree = ET.parse(in_file) root = tree.getroot() size = root.find("size") w, h = int(size.find("width").text), int(size.find("height").text) out_file = open(os.path.join(output_dir, file.replace(".xml", ".txt")), "w") for obj in root.iter("object"): cls = obj.find("name").text if cls not in classes: continue cls_id = classes.index(cls) xmlbox = obj.find("bndbox") b = (float(xmlbox.find("xmin").text), float(xmlbox.find("xmax").text), float(xmlbox.find("ymin").text), float(xmlbox.find("ymax").text)) bb = convert_bbox((w,h), b) out_file.write(f"{cls_id} {' '.join([str(a) for a in bb])}\n") ``` 2. Execute the script to generate YOLO-format labels. ``` python3 convert_voc_to_yolo.py ``` Now you’ll have datasets/roadsign/labels/ with .txt files. ## Step 5 – Split the Dataset into Training and Validation To train a YOLOv5 model effectively, you need to split your dataset into training (80%) and validation (20%) sets. Training images will be used to learn, while validation images will help evaluate model performance during training. 1. Make subdirectories for training and validation images and labels. ``` mkdir -p datasets/roadsign/images/train datasets/roadsign/images/val mkdir -p datasets/roadsign/labels/train datasets/roadsign/labels/val ``` 2. Create a split script. ``` nano split_dataset.py ``` Add the following code. ``` import os, random, shutil image_dir = "datasets/roadsign/images" label_dir = "datasets/roadsign/labels" train_img = "datasets/roadsign/images/train" val_img = "datasets/roadsign/images/val" train_lbl = "datasets/roadsign/labels/train" val_lbl = "datasets/roadsign/labels/val" files = [f for f in os.listdir(image_dir) if f.endswith(".png")] random.shuffle(files) split = int(0.8 * len(files)) train_files, val_files = files[:split], files[split:] def move_files(file_list, dest_img, dest_lbl): for f in file_list: base = os.path.splitext(f)[0] shutil.copy(os.path.join(image_dir, f), os.path.join(dest_img, f)) shutil.copy(os.path.join(label_dir, base + ".txt"), os.path.join(dest_lbl, base + ".txt")) move_files(train_files, train_img, train_lbl) move_files(val_files, val_img, val_lbl) ``` 3. Run the script. ``` python3 split_dataset.py ``` This will automatically shuffle and copy images with their corresponding label files into the correct folders. 4. After splitting, your dataset should look like this: ``` datasets/roadsign/ ├── images/ │ ├── train/ │ └── val/ ├── labels/ │ ├── train/ │ └── val/ └── roadsign.yaml ``` ## Step 6 – Create Dataset Configuration File YOLOv5 requires a YAML configuration file that tells the training script where to find images, how many classes exist, and what the class names are. Without this, YOLOv5 won’t know how to load your dataset. Create a dataset configuration file. ``` nano datasets/roadsign/roadsign.yaml ``` Add the following lines. ``` train: datasets/roadsign/images/train val: datasets/roadsign/images/val nc: 4 names: ['trafficlight', 'stop', 'speedlimit', 'crosswalk'] ``` **Note:** Make sure the file paths **(datasets/roadsign/images/train** and **datasets/roadsign/images/val)** are correct relative to the YOLOv5 root folder. If you placed your dataset in a different location, adjust the paths accordingly. ## Step 7 – Train YOLOv5 Model Now that the dataset is prepared and the configuration file is ready, you can train YOLOv5 on the road sign dataset. Start training on datasets. ``` python3 train.py --img 640 --batch 16 --epochs 100 \ --data datasets/roadsign/roadsign.yaml --weights yolov5s.pt --device 0 ``` Output. ``` Validating runs/train/exp2/weights/best.pt... Fusing layers... Model summary: 157 layers, 7020913 parameters, 0 gradients, 15.8 GFLOPs Class Images Instances P R mAP50 mAP50-95: 100%|██████████| 6/6 [00:01<00:00, 3.32it/s] all 176 275 0.936 0.916 0.936 0.791 trafficlight 176 46 0.897 0.804 0.845 0.598 stop 176 21 0.953 0.976 0.986 0.915 speedlimit 176 160 0.98 1 0.995 0.91 crosswalk 176 48 0.914 0.883 0.916 0.741 Results saved to runs/train/exp2 ``` ## Step 8 – Validate the Model Once training is complete, you should validate the model to check how well it performs on unseen data. YOLOv5 provides a built-in validation script that uses your best trained weights. Now, run the validation. ``` python3 val.py --weights runs/train/exp2/weights/best.pt --data datasets/roadsign/roadsign.yaml --img 640 ``` Output. ``` val: data=datasets/roadsign/roadsign.yaml, weights=['runs/train/exp2/weights/best.pt'], batch_size=32, imgsz=640, conf_thres=0.001, iou_thres=0.6, max_det=300, task=val, device=, workers=8, single_cls=False, augment=False, verbose=False, save_txt=False, save_hybrid=False, save_conf=False, save_json=False, project=runs/val, name=exp, exist_ok=False, half=False, dnn=False YOLOv5 🚀 v7.0-430-g459d8bf0 Python-3.12.3 torch-2.8.0+cu128 CUDA:0 (NVIDIA A40-8Q, 8005MiB) Fusing layers... Model summary: 157 layers, 7020913 parameters, 0 gradients, 15.8 GFLOPs val: Scanning /root/yolov5/datasets/roadsign/labels/val.cache... 176 images, 0 backgrounds, 0 corrupt: 100%|██████████| 176/176 [00:00 R (Recall) - How many actual objects were detected. mAP50 - Mean Average Precision at IoU threshold 0.5 (higher is better). mAP50-95 - Average precision across IoU thresholds (stricter measure). ``` ## Step 9 – Run Inference on Road Signs After training and validation, it’s time to see the model in action. YOLOv5 provides a detect.py script to run inference on images, videos, or even live camera streams. Use your trained weights to detect objects in the validation set. ``` python3 detect.py --weights runs/train/exp2/weights/best.pt \ --source datasets/roadsign/images/val --img 640 ``` Output. ``` Results saved in runs/detect/exp2/. ``` ## Step 10 – Visualize Inference Results with Matplotlib Running YOLOv5 with detect.py saves results to disk, but sometimes you may want to display predictions directly in Python for analysis or integration into an application. We can do this with Matplotlib and OpenCV. 1. Create an inference script. ``` nano inference_plot.py ``` Paste the following code: ``` import torch import matplotlib.pyplot as plt import cv2 # Load YOLOv5 model model = torch.hub.load('ultralytics/yolov5', 'custom', path='runs/train/exp2/weights/best.pt', force_reload=True) # Run inference on an image img_path = 'datasets/roadsign/images/val/road107.png' # change to any test image results = model(img_path) # Results summary results.print() # class, confidence, bbox results.save() # saves to runs/detect/exp # Display inside Python using matplotlib img = results.render()[0] # render() returns list of images plt.figure(figsize=(10,10)) plt.imshow(cv2.cvtColor(img, cv2.COLOR_BGR2RGB)) plt.axis("off") plt.show() ``` 2. Run the script. ``` python3 inference_plot.py ``` Output. ``` Downloading: "https://github.com/ultralytics/yolov5/zipball/master" to /root/.cache/torch/hub/master.zip YOLOv5 🚀 2025-9-11 Python-3.12.3 torch-2.8.0+cu128 CUDA:0 (NVIDIA A40-8Q, 8005MiB) Fusing layers... Model summary: 157 layers, 7020913 parameters, 0 gradients, 15.8 GFLOPs Adding AutoShape... /root/.cache/torch/hub/ultralytics_yolov5_master/models/common.py:906: FutureWarning: `torch.cuda.amp.autocast(args...)` is deprecated. Please use `torch.amp.autocast('cuda', args...)` instead. with amp.autocast(autocast): image 1/1: 400x320 1 speedlimit Speed: 22.3ms pre-process, 83.1ms inference, 119.0ms NMS per image at shape (1, 3, 640, 512) Saved 1 image to runs/detect/exp2 ``` Open the generated image at **/root/yolov5/runs/detect/exp2/road107.jpg.** You’ll see your road sign image with bounding boxes like: ![](https://www.atlantic.net/wp-content/uploads/2025/09/road107.jpg) 🟥 trafficlight 🟦 stop 🟨 speedlimit 🟩 crosswalk Each box has a confidence score. You’ve now visualized YOLOv5 predictions directly inside Python. This method is useful for debugging, generating plots for reports, or integrating YOLOv5 inference into larger applications. ## Conclusion In this tutorial, you learned how to train YOLOv5 on a custom dataset using an Ubuntu 24.04 GPU server. Starting from environment setup, dataset preparation, annotation conversion, and splitting train/validation sets, you successfully trained, validated, and tested a YOLOv5 model on the Road Sign Detection dataset. You now have a working YOLOv5 object detection pipeline. This workflow is flexible, you can replace the dataset with your own images and annotations to train YOLOv5 on any custom problem. --- # Anomaly Detection in Python with Isolation Forest on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/anomaly-detection-in-python-with-isolation-forest-on-ubuntu-24-04-gpu-server/ | Published: 2025-09-19 | Updated: 2026-05-04 | Author: Hitesh Jethva Anomalies are data points that deviate significantly from the majority of observations. Detecting them early can prevent fraud, identify cyberattacks, and flag unusual system behavior before it causes damage. This process is known as anomaly detection, and it plays a key role in fields such as banking (credit card fraud), cybersecurity (intrusion detection), and healthcare (disease pattern discovery). Traditionally, anomaly detection methods run on CPUs, but with today’s growing datasets, CPU-based processing can become slow and inefficient. That’s where GPU acceleration comes in. Using NVIDIA’s RAPIDS cuML library, we can leverage the power of GPUs to speed up anomaly detection tasks dramatically. Instead of waiting minutes or hours, you can analyze massive datasets in seconds. In this tutorial, you’ll learn how to perform anomaly detection on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/) using Python and RAPIDS cuML. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1 – Setting Up Python Environment Before we start coding anomaly detection, we need to prepare a proper Python environment on our Ubuntu 24.04 GPU server. 1. Install Python tools. ``` apt install -y python3 python3-pip python3-venv python3-pip ``` 2. Create a project directory. ``` mkdir anomaly-detection && cd anomaly-detection ``` 3. Create and activate a virtual environment. ``` python3 -m venv .venv source .venv/bin/activate ``` 4. Upgrade pip and install dependencies. ``` pip install --upgrade pip pip install numpy pandas matplotlib seaborn joblib scikit-learn ``` 5. Finally, install cuML (RAPIDS library for GPU-accelerated ML). ``` pip install cuml-cu12 --extra-index-url=https://pypi.nvidia.com ``` ## Step 2 – Building a Synthetic Anomaly Detection Example To understand how anomaly detection works with GPU acceleration, we’ll first create a synthetic dataset. This allows us to clearly visualize the difference between normal data points and anomalies before applying the method to a real-world dataset. 1. Create a Python script. ``` nano anomaly_detection_gpu.py ``` Add the following code. ``` # anomaly_detection_gpu.py import numpy as np import pandas as pd import matplotlib.pyplot as plt import seaborn as sns from cuml.cluster import DBSCAN # GPU-based DBSCAN import joblib # ------------------------------ # Step 1: Generate synthetic data # ------------------------------ rng = np.random.RandomState(42) # Normal points X = 0.3 * rng.randn(200, 2) X = np.r_[X + 2, X - 2] # Outliers outliers = rng.uniform(low=-6, high=6, size=(20, 2)) X = np.r_[X, outliers] df = pd.DataFrame(X, columns=["feature1", "feature2"]) # ------------------------------ # Step 2: Train DBSCAN on GPU # ------------------------------ # eps = neighborhood size, min_samples = density threshold db = DBSCAN(eps=0.5, min_samples=5) labels = db.fit_predict(df[["feature1", "feature2"]].values) # Anomalies = label -1 df["anomaly"] = (labels == -1).astype(int) print("Anomaly counts:") print(df["anomaly"].value_counts()) # ------------------------------ # Step 3: Visualization # ------------------------------ plt.figure(figsize=(8, 6)) sns.scatterplot( x="feature1", y="feature2", hue="anomaly", style="anomaly", palette={0: "blue", 1: "red"}, data=df ) plt.title("GPU Accelerated Anomaly Detection with cuML DBSCAN") plt.savefig("anomaly_results.png") plt.show() # ------------------------------ # Step 4: Save model # ------------------------------ # Save labels only (DBSCAN in cuML doesn’t support pickling yet) joblib.dump(labels, "dbscan_labels.pkl") print("Labels saved as dbscan_labels.pkl") ``` 2. Run the script. ``` python3 anomaly_detection_gpu.py ``` You should see output similar to: ``` Anomaly counts: anomaly 0 402 1 18 Name: count, dtype: int64 Labels saved as dbscan_labels.pkl ``` This indicates that the model identified **402** normal points and **18** anomalies. 3. The script saves a visualization as **anomaly_results.png.** Open it and you’ll see: ![](https://www.atlantic.net/wp-content/uploads/2025/09/anomaly_results.png) **Blue points** – Normal data **Red points** – Detected anomalies At this point, you have a working GPU-accelerated anomaly detection pipeline on synthetic data. Next, we’ll apply the same workflow to a real-world dataset: credit card fraud detection. ## Step 3 – Applying to Real-World Dataset (Credit Card Fraud) After testing on synthetic data, let’s scale up to a real-world dataset: the Credit Card Fraud Detection dataset. This dataset contains 284,807 transactions with 29 features, making it an excellent benchmark for anomaly detection. 1. Open a new Python file. ``` nano anomaly_creditcard_gpu.py ``` Add the following code. ``` import pandas as pd from sklearn.datasets import fetch_openml from cuml.cluster import DBSCAN import joblib # ------------------------------ # Step 1: Load Credit Card Fraud dataset # ------------------------------ print("Downloading dataset...") data = fetch_openml(name="creditcard", version=1, as_frame=True) df = data.data print("Dataset shape:", df.shape) # ------------------------------ # Step 2: Train DBSCAN on GPU # ------------------------------ db = DBSCAN(eps=3.0, min_samples=10) # tune eps for better results labels = db.fit_predict(df.values) # Anomalies are labeled as -1 df["anomaly"] = (labels == -1).astype(int) print("Anomaly counts:") print(df["anomaly"].value_counts()) # ------------------------------ # Step 3: Save results # ------------------------------ joblib.dump(labels, "creditcard_dbscan_labels.pkl") df[["anomaly"]].to_csv("creditcard_anomalies.csv", index=False) print("Labels saved as creditcard_dbscan_labels.pkl") print("Anomaly flags saved to creditcard_anomalies.csv") ``` 2. Run the script. ``` python3 anomaly_creditcard_gpu.py ``` You will see the following output. ``` Downloading dataset... Dataset shape: (284807, 29) Anomaly counts: anomaly 0 218091 1 66716 Name: count, dtype: int64 Labels saved as creditcard_dbscan_labels.pkl Anomaly flags saved to creditcard_anomalies.csv ``` **Explanation:** - Dataset shape confirms the dataset size (284,807 rows × 29 features). - Anomaly counts show how many transactions were flagged as suspicious (label 1) vs normal (label 0). - **creditcard_dbscan_labels.pkl** – cluster labels for all transactions. - **creditcard_anomalies.csv** – CSV file with anomaly flags (useful for further analysis in Excel, Pandas, or BI tools). ## Conclusion In this tutorial, you learned how to set up an Ubuntu 24.04 GPU server for anomaly detection with Python, build a synthetic dataset to test the workflow, and then scale the approach to a real-world credit card fraud dataset. Using RAPIDS cuML’s DBSCAN, we took advantage of GPU acceleration to handle clustering and anomaly detection much faster than traditional CPU-based methods. --- # Bare Metal GPU Architecture: The Engine of Modern AI and Gaming > URL: https://www.atlantic.net/gpu-server-hosting/bare-metal-gpu-architecture-the-engine-of-modern-ai-and-gaming/ | Published: 2025-09-19 | Author: Richard Bailey Artificial intelligence and gaming are two fields that continue to push the boundaries of high-performance computing. From training sophisticated neural networks to rendering photorealistic game worlds in real-time, these tasks demand one thing above all: raw, uncompromised GPU power. This is where bare metal GPU hosting can become a game changer, a solution to provide direct, unthrottled access to the physical hardware needed to power advanced applications, and the only way to achieve consistent, low-latency performance users demand. ## The Unstoppable Demand for Raw GPU Power The resource-intensive nature of both AI and high-end gaming cannot be overstated. An AI-focused Bare Metal Server might house racks of GPUs drawing immense power, while a cloud gaming platform must render complex graphics and stream them with zero lag. The traditional, CPU-centric data center was simply not engineered for this kind of parallel processing demand. In response, the industry is pivoting towards purpose-built Bare Metal GPU infrastructure, and Atlantic.Net is leading by example with a wide range of GPU bare metal servers available for our customers. For AI practitioners, the goal is to accelerate training and inference. For gaming companies, the objective is delivering a flawless, high-fidelity experience. Industry analysts project an explosive growth trajectory for both sectors, with AI workloads expected to dramatically increase their share of data center energy consumption by 2027 and the cloud gaming market following a similar path. This surge is forcing an evolution in data center architecture, prompting providers to invest heavily in liquid cooling, renewable energy, and the reliable infrastructure needed to support Bare Metal Server Hosting at a massive scale. ## Case Study: Alex AI Stack Story Atlantic.Net was approached by an AI consultant called Alex, who reached out for help to evaluate a GPU solution for his specific needs, whose team performs cutting-edge work with generative AI in a media-centric industry. After proving their concept, Alex’s team needed to migrate to a production environment capable of handling their intense workflows with absolute reliability. For them, a Bare Metal Server was the obvious choice. His team chose one of our powerful Bare Metal GPU configurations, the AL40S.192GB, equipping them with a dedicated NVIDIA L40S GPU, 192 GB of RAM, and blazing-fast NVMe storage in a single-tenant environment. Through Bare Metal Server Hosting, they avoided sharing resources or competing with a hypervisor for clock cycles. Crucially, the direct, unfettered access to the hardware was essential for the inference-heavy workloads and specialized model training. One of the major benefits of using Atlantic.Net was our ability to gain deep access to GPU telemetry, storage health metrics, and network performance data. This enabled Alex to validate the project’s ROI and plan for future expansion—a level of observability often obscured in virtualized setups. Security was also paramount to Alex’s team. Our Bare Metal GPU Hosting delivered an environment protected with encrypted storage, SSH-key-only access, and a private VLAN. The result was a completely isolated and secure machine dedicated solely to his team’s mission-critical work. ## Dedicated Power, Guaranteed Results Traditional server hosting, where the CPU, Disk, and Memory are the most important factors, absolutely is still relevant; however, the rapid elasticity of virtualized environments comes at a cost: a performance compromise that is unacceptable for mission-critical AI and gaming. For applications that require sustained, predictable power, developers like Alex and major game streaming companies turn to Bare Metal Server Hosting for three compelling reasons: - **No Performance Tax**: By removing the hypervisor layer that consumes resources and adds latency in typical cloud environments, a Bare Metal Server gives you 100% of the CPU and GPU power you pay for. For gaming, this translates to lower input lag; for AI, it means faster model processing. - **Predictable Power**: Exclusive access to hardware means performance is consistent and predictable—a non-negotiable for competitive gaming and production-grade AI. You completely avoid the “noisy neighbor” problem, where another user’s workload on a shared machine can degrade your application’s performance. - **Total Control**: Full root access grants you command over the entire software stack. You can install a custom OS, fine-tune kernel settings, and optimize the environment specifically for your application, whether it’s a dedicated game server or a machine learning pipeline. ## Ready to Unleash True Performance? For applications where performance overhead and unpredictability are not an option, the raw power and dedicated resources of a Bare Metal Server are the only way forward. Whether you’re building the next great AI application or launching a high-performance gaming platform, don’t let virtualization be your bottleneck. [Explore our Bare Metal GPU Hosting solutions.](https://www.atlantic.net/gpu-server-hosting/) Have questions? Our solutions architecture team is ready to help you configure the perfect Bare Metal Server for your workload. [Contact our team for a free consultation](https://www.atlantic.net/about-us/corporate-contact/) ## Frequently Asked Questions **What makes Bare Metal GPU Hosting different from a regular cloud VM?** Bare Metal GPU Hosting gives you a whole physical server and its GPUs. Without a virtualization layer (hypervisor), you sidestep the performance overhead and resource contention (“noisy neighbor” effect) common in multi-tenant cloud environments. **Is a Bare Metal Server good for game hosting or cloud gaming?** Absolutely. For game servers, the low latency and consistent performance of Bare Metal ensure a smooth, competitive player experience. For cloud gaming platforms, direct access to a powerful GPU is essential for rendering high-fidelity graphics and streaming with minimal lag. **Can I monitor the GPU performance on my Bare Metal Server?** Yes. Full access to GPU-level telemetry is a key benefit. You can monitor utilization, memory usage, and thermal data, which allows for precise performance tracking and optimization. **Is your Bare Metal GPU Hosting truly single-tenant?** 100%. Each Bare Metal Server is exclusively yours. You get dedicated access to all the machine’s resources, guaranteeing both top-tier security and completely predictable performance. --- # Cartooning an Image using OpenCV on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/cartooning-an-image-using-opencv-on-ubuntu-24-04-gpu-server/ | Published: 2025-09-20 | Updated: 2025-09-23 | Author: Hitesh Jethva Have you ever wanted to turn a regular photo into something that looks hand-drawn or animated? That’s exactly what cartoonification does — it transforms a real-world image into something that looks like it came from a comic book or a cartoon series. In this tutorial, you’ll learn how to build a simple Cartoon Image Web App using OpenCV for image processing and Flask for the web interface. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Update the System and Install Python Environment Before we start coding, let’s prepare the Ubuntu 24.04 GPU server with the tools we need. We’ll update the package list and install Python-related packages required for our cartoonifier web app. 1. Start by updating your package list to ensure you have access to the latest versions. ```bash apt update -y ``` 2. Next, install Python 3 along with pip (Python’s package installer) and venv (used to create isolated virtual environments). ```bash apt install -y python3 python3-pip python3-venv ``` 3. Create and activate the virtual environment. ```bash python3 -m venv cartoon-env source cartoon-env/bin/activate ``` 4. Install the necessary Python libraries. ```bash pip install flask opencv-python ``` ## Step 2: Create Project Structure Let’s organize your files and folders before writing any code. This will make your project clean and easy to maintain. 1. Create the Main Project Folders. ```bash mkdir static templates ``` - **static/:** This folder will hold uploaded and processed images. - **templates/:** This will store HTML files for the Flask web app interface. 2. Here’s what your project directory will look like after you finish the app ```bash cartoon-env/ ├── app.py ├── cartoonizer.py ├── static/ │ ├── input.png │ └── cartoon.png ├── templates/ │ └── index.html ``` ## Step 3: Write the Cartoonizer Logic Now it’s time to build the heart of the project, the image cartoonification script using OpenCV. Create the cartoonizer.py file. ```bash nano cartoonizer.py ``` Add the following code. ```bash # cartoonizer.py import cv2 import os def cartoonify_image(image_path): # Read and resize image img = cv2.imread(image_path) img = cv2.resize(img, (480, 480)) # Convert to grayscale gray = cv2.cvtColor(img, cv2.COLOR_BGR2GRAY) gray_blur = cv2.medianBlur(gray, 7) # Detect edges edges = cv2.adaptiveThreshold( gray_blur, 255, cv2.ADAPTIVE_THRESH_MEAN_C, cv2.THRESH_BINARY, blockSize=9, C=9 ) # Apply bilateral filter for cartoon-like smoothing color = cv2.bilateralFilter(img, d=9, sigmaColor=300, sigmaSpace=300) # Combine edges with smoothed color image cartoon = cv2.bitwise_and(color, color, mask=edges) # Save cartoonified image os.makedirs("static", exist_ok=True) out_path = "static/cartoon.png" cv2.imwrite(out_path, cartoon) return out_path ``` This script takes an image path, processes it to give a cartoon effect, and saves the output to **static/cartoon.png.** In the next section, we’ll connect this logic to a web interface using Flask. ## Step 4: Build the Flask Web App Now that we have our image processing logic in place, let’s create a Flask app to let users upload an image and view the cartoonified result in the browser. Create the Flask App. ```bash nano app.py ``` Add the following code. ```bash # app.py from flask import Flask, render_template, request import os from cartoonizer import cartoonify_image app = Flask(__name__) UPLOAD_FOLDER = 'static' app.config['UPLOAD_FOLDER'] = UPLOAD_FOLDER @app.route("/", methods=["GET", "POST"]) def index(): if request.method == "POST": file = request.files.get('file') if not file: return "No file uploaded" input_path = os.path.join(app.config['UPLOAD_FOLDER'], 'input.png') file.save(input_path) cartoon_path = cartoonify_image(input_path) return render_template("index.html", cartoon_image=cartoon_path) return render_template("index.html", cartoon_image=None) if __name__ == "__main__": app.run(host="0.0.0.0", port=5000) ``` Your Flask backend is now ready. Next, we’ll create the HTML interface that lets users upload images and view the results. ## Step 5: Design the HTML Frontend Now, let’s create the web interface where users can upload an image and view the cartoonified output. Create the HTML file. ```bash nano templates/index.html ``` Add the following code. ```bash Cartoonify Image

Upload an Image to Cartoonify 🎨

{% if cartoon_image %}

Output:

{% endif %} ``` **Explanation:** - Displays a simple form to upload an image. - When the user clicks Cartoonify, it sends the image to the server. - If a cartoon image is returned, it’s displayed right below the form. ## Step 6: Start the Flask App You’ve written the cartoonizer logic, the Flask backend, and the HTML frontend. Now let’s run the app and test it in your browser. 1. Start the Flask server. ```bash python3 app.py ``` Output. ```bash * Running on all addresses (0.0.0.0) * Running on http://127.0.0.1:5000 * Running on http://your-server-ip:5000 ``` 2. Access the Flask web interface using the URL **http://your-server-ip:5000.** 3. Click **Browse** to upload an image and click the **Cartoonify** button. The processed cartoon image will appear below the form. ![](https://www.atlantic.net/wp-content/uploads/2025/08/girl2.png) ## Conclusion You’ve successfully built a cartoonifying web application using OpenCV and Flask on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). Throughout this tutorial, you created a Python virtual environment, installed the required libraries, and wrote a custom function to give any uploaded image a cartoon-like effect. You also developed a user-friendly HTML frontend and connected it to a Flask backend that handles image uploads and displays results in real time. --- # How to Run a Tokenizer on Ubuntu 24.04 GPU Server for Faster NLP Processing > URL: https://www.atlantic.net/gpu-server-hosting/how-to-run-a-tokenizer-on-ubuntu-24-04-gpu-server-for-faster-nlp-processing/ | Published: 2025-09-21 | Updated: 2025-09-23 | Author: Hitesh Jethva In Natural Language Processing (NLP), raw text data must be transformed into a structured format before it can be fed into machine learning models. This process is called tokenization. It breaks down text into smaller pieces—like words, subwords, or characters—so that models like BERT or GPT can understand and process it. Tokenization is often the first and most frequent step in any NLP workflow. Whether you’re generating embeddings, training a classifier, or performing sentiment analysis, every input sentence goes through this stage. That’s why optimizing tokenization can significantly improve the overall performance of your pipeline, especially when you’re processing thousands or even millions of texts. In this tutorial, you’ll learn how to set up your Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/) for NLP tokenization. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Set up Python Environment In this section, you’ll set up a clean Python environment and install the necessary libraries to run tokenization and benchmarking tasks using GPU-accelerated PyTorch and Hugging Face Transformers. 1. Update the package list and install dependencies. ```bash apt update -y apt install -y python3 python3-pip python3-venv git ``` 2. Create and activate a virtual environment. ```bash python3 -m venv venv source venv/bin/activate ``` 3. Upgrade pip to the latest version and install PyTorch with CUDA, along with transformers from Hugging Face. ```bash pip install --upgrade pip pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu121 pip install transformers ``` 4. Before running any GPU-based operations, confirm that PyTorch detects the GPU. ```bash python3 -c "import torch; print(torch.cuda.is_available())" ``` Output. ```bash True ``` ## Step 2: Tokenizer Performance Benchmarking: CPU vs GPU Now that your environment is ready, let’s measure how long it takes to tokenize a large batch of text using Hugging Face’s AutoTokenizer. While tokenizers don’t perform computation directly on the GPU, their output tensors (like input_ids and attention_mask) can be transferred to GPU memory for downstream model inference. This helps reduce the bottleneck in end-to-end NLP pipelines. 1. Create a new script file to benchmark tokenization. ```bash nano gpu_tokenizer.py ``` Add the following code. ```bash # gpu_tokenizer.py import time from transformers import AutoTokenizer import torch # Load fast tokenizer tokenizer = AutoTokenizer.from_pretrained("bert-base-uncased", use_fast=True) # Create dummy batch texts = ["Tokenize this sentence for GPU!"] * 10000 # --- CPU Tokenization --- start_cpu = time.time() cpu_encoded = tokenizer(texts, padding=True, truncation=True, return_tensors="pt") end_cpu = time.time() print("✅ CPU tokenization time:", round(end_cpu - start_cpu, 2), "seconds") # --- GPU Tokenization (moving outputs to CUDA) --- start_gpu = time.time() gpu_encoded = tokenizer(texts, padding=True, truncation=True, return_tensors="pt") gpu_encoded = {k: v.to("cuda") for k, v in gpu_encoded.items()} end_gpu = time.time() print("✅ GPU tokenization + transfer time:", round(end_gpu - start_gpu, 2), "seconds") # Check device print("📍input_ids tensor device:", gpu_encoded['input_ids'].device) ``` 2. Run the script. ```bash python3 gpu_tokenizer.py ``` Output. ```bash ✅ CPU tokenization time: 0.23 seconds ✅ GPU tokenization + transfer time: 0.45 seconds 📍input_ids tensor device: cuda:0 ``` This means tokenization on CPU is slightly faster in isolation, but transferring the output to GPU allows you to chain this step directly into a model inference pipeline on the GPU—saving time overall. ## Step 3: Tokenization with SentenceTransformers and GPU If you’re working with sentence-level representations, SentenceTransformers is a powerful library that simplifies embedding generation. It handles tokenization and model inference under the hood—and yes, it runs smoothly on the GPU. This section will show you how to use SentenceTransformers on your Ubuntu 24.04 GPU server to generate high-quality sentence embeddings quickly. 1. Install SentenceTransformers. ```bash pip install sentence-transformers ``` 2. Create the embedding script. ```bash nano sentence_embed.py ``` Add the following code. ```bash from sentence_transformers import SentenceTransformer # Load model and move it to GPU model = SentenceTransformer('all-MiniLM-L6-v2').to("cuda") # Encode sentences sentences = ["Tokenize this using GPU", "Sentence transformers are powerful"] embeddings = model.encode(sentences, device="cuda") # Output embedding shape print("Embedding shape:", embeddings.shape) ``` 3. Run the script. ```bash python3 sentence_embed.py ``` Output. ```bash Embedding shape: (2, 384) ``` You now have 384-dimensional embeddings for two sentences, computed fully on the GPU. This can be scaled up to thousands of sentences for downstream tasks like clustering, semantic search, or classification. ## Step 4: Implementing Byte-Pair Encoding (BPE) from Scratch Byte-Pair Encoding (BPE) is a widely used algorithm for tokenization in modern NLP models like GPT and RoBERTa. Instead of relying on pre-trained libraries, let’s implement a basic version of BPE yourself in Python. This will help you understand how text is broken down into subword units. 1. Create the BPE script. ```bash nano bpe_trainer.py ``` Add the following code. ```bash from collections import defaultdict corpus = {"cat": 5, "cap": 3, "can": 2, "bat": 4, "bats": 2} def get_tokenized_corpus(corpus): return {tuple(word): freq for word, freq in corpus.items()} def get_pair_freqs(tokenized): pairs = defaultdict(int) for word, freq in tokenized.items(): for i in range(len(word) - 1): pairs[(word[i], word[i+1])] += freq return pairs def merge_pair(pair, corpus): new_corpus = {} for word, freq in corpus.items(): new_word = [] i = 0 while i < len(word): if i < len(word)-1 and (word[i], word[i+1]) == pair: new_word.append(''.join(pair)) i += 2 else: new_word.append(word[i]) i += 1 new_corpus[tuple(new_word)] = freq return new_corpus tokenized = get_tokenized_corpus(corpus) for _ in range(5): pair_freqs = get_pair_freqs(tokenized) best_pair = max(pair_freqs, key=pair_freqs.get) tokenized = merge_pair(best_pair, tokenized) print(f"Merged {best_pair} → {''.join(best_pair)}") print("Updated:", tokenized) ``` 2. Run the script. ```bash python3 bpe_trainer.py ``` Output. ```bash Merged ('a', 't') → at Updated: {('c', 'at'): 5, ('c', 'a', 'p'): 3, ('c', 'a', 'n'): 2, ('b', 'at'): 4, ('b', 'at', 's'): 2} Merged ('b', 'at') → bat Updated: {('c', 'at'): 5, ('c', 'a', 'p'): 3, ('c', 'a', 'n'): 2, ('bat',): 4, ('bat', 's'): 2} Merged ('c', 'at') → cat Updated: {('cat',): 5, ('c', 'a', 'p'): 3, ('c', 'a', 'n'): 2, ('bat',): 4, ('bat', 's'): 2} Merged ('c', 'a') → ca Updated: {('cat',): 5, ('ca', 'p'): 3, ('ca', 'n'): 2, ('bat',): 4, ('bat', 's'): 2} Merged ('ca', 'p') → cap Updated: {('cat',): 5, ('cap',): 3, ('ca', 'n'): 2, ('bat',): 4, ('bat', 's'): 2} ``` You’ve now built a mini BPE tokenizer. While this is simplified and doesn’t include vocabulary size or merges file output, it teaches the core concept of subword merging based on frequency. ## Conclusion Tokenization plays a critical role in every NLP pipeline, especially when processing large volumes of text. In this guide, you set up an Ubuntu 24.04 GPU server, installed the necessary libraries, and benchmarked tokenization performance using Hugging Face Transformers on both CPU and GPU. You also generated sentence embeddings with SentenceTransformers and explored how Byte-Pair Encoding works by implementing it from scratch. --- # Convert Tokenizer into a Flask API with Frontend on Ubuntu 24.04 GPU Server > URL: https://www.atlantic.net/gpu-server-hosting/convert-tokenizer-into-a-flask-api-with-frontend-on-ubuntu-24-04-gpu-server/ | Published: 2025-09-22 | Updated: 2025-09-23 | Author: Hitesh Jethva Tokenization is the first and most critical step in any Natural Language Processing (NLP) task. It breaks down raw text into smaller units, called tokens, that a machine learning model can understand. These tokens could be words, subwords, or even characters, depending on the tokenizer being used. Without tokenization, models like BERT or GPT wouldn’t know where a sentence starts or ends, or how to differentiate words like “run” and “running.” In this tutorial, you’ll learn how to convert a Hugging Face tokenizer (like bert-base-uncased) into a Flask API that can process both real-time JSON requests and serve a web-based UI for interactive use. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Install Required Packages To get started, you’ll first set up a virtual environment for your Flask tokenizer app. This helps keep dependencies isolated and makes your project easier to manage. 1. Update the package list and install dependencies. ```bash apt update -y apt install -y python3 python3-pip python3-venv git ``` 2. Create a virtual environment. ```bash python3 -m venv tokenizer-api-env ``` 3. Activate the virtual environment. ```bash source tokenizer-api-env/bin/activate ``` 4. Install the required Python libraries. ```bash pip install flask transformers torch ``` ## Step 2: Create the Project Structure Now that your environment is ready and the required packages are installed, it’s time to organize your project. You’ll create a new directory for the Flask app and set up folders for your HTML templates. 1. Create the main project folder. ```bash mkdir -p tokenizer_flask/templates cd tokenizer_flask ``` This will create a structure like: ```bash tokenizer_flask/ └── templates/ ``` 2. Project File Structure Overview. ```bash tokenizer_flask/ ├── app.py # Main Flask app └── templates/ └── index.html # Frontend web interface ``` ## Step 3: Create the Flask API Now let’s write the core of your project: the Flask backend that handles both web form submissions and API requests. This backend loads the Hugging Face tokenizer and serves responses via two routes: - **/** → Web UI using HTML form - **/api/tokenize** → JSON API for programmatic access 1. Create and open the Flask app. ```bash nano app.py ``` Add the following code. ```bash from flask import Flask, request, jsonify, render_template from transformers import AutoTokenizer app = Flask(__name__) # Load pretrained tokenizer tokenizer = AutoTokenizer.from_pretrained("bert-base-uncased") @app.route('/', methods=['GET']) def index(): return render_template('index.html') @app.route('/tokenize', methods=['POST']) def tokenize_text(): text = request.form.get('text') if not text: return render_template('index.html', error="Please enter some text.") tokens = tokenizer(text, return_tensors="pt") input_ids = tokens['input_ids'].tolist() attention_mask = tokens['attention_mask'].tolist() return render_template('index.html', text=text, input_ids=input_ids, attention_mask=attention_mask) @app.route('/api/tokenize', methods=['POST']) def api_tokenize(): data = request.json if 'text' not in data: return jsonify({"error": "Missing 'text' field"}), 400 text = data['text'] tokens = tokenizer(text, return_tensors="pt") return jsonify({ "input_ids": tokens['input_ids'].tolist(), "attention_mask": tokens['attention_mask'].tolist() }) if __name__ == '__main__': app.run(host='0.0.0.0', port=5000) ``` Now that your backend is ready, let’s build the web interface so you can test the tokenizer visually in your browser. ## Step 4: Design the Frontend Now that your Flask backend is ready, let’s create a simple web interface where users can enter text and view the tokenized output. This will be served from the / route using Flask’s built-in templating system, Jinja2. Create an index.html inside the templates directory. ```bash nano templates/index.html ``` Add the following code. ```bash Tokenizer Web Interface

Tokenizer Web Interface




{% if error %}

{{ error }}

{% endif %} {% if input_ids %}

Tokenized Result

Input IDs: {{ input_ids }}

Attention Mask: {{ attention_mask }}

{% endif %} ``` With this frontend in place, you’re ready to start the server and test both the web UI and the API in the next section. ## Step 5: Run the Flask Server You’ve written both the backend and the frontend—now it’s time to start your Flask application and make the tokenizer API accessible from your browser and command line. Run the Flask server. ```bash python3 app.py ``` ## Step 6: Test the API via cURL Now let’s test your tokenizer Flask API using curl, a command-line tool for sending HTTP requests. This is a great way to confirm that the **/api/tokenize** endpoint works as expected. **Example** 1: **English Text** ```bash curl -X POST http://45.76.22.55:5000/api/tokenize \ -H "Content-Type: application/json" \ -d '{"text": "I love using Transformers!"}' ``` Output. ```bash {"attention_mask":[[1,1,1,1,1,1,1]],"input_ids":[[101,1045,2293,2478,19081,999,102]]} ``` **Example** **2: Text with Emoji** ```bash curl -X POST http://45.76.22.55:5000/api/tokenize \ -H "Content-Type: application/json" \ -d '{"text": "Python is awesome 😎"}' ``` Output. ```bash {"attention_mask":[[1,1,1,1,1,1]],"input_ids":[[101,18750,2003,12476,100,102]]} ``` **Note:** Emoji is treated as an unknown token (100) in BERT’s tokenizer. **Example 3: French Input** ```bash curl -X POST http://45.76.22.55:5000/api/tokenize \ -H "Content-Type: application/json" \ -d '{"text": "Bonjour! Je parle français."}' ``` Output. ```bash {"attention_mask":[[1,1,1,1,1,1,1,1,1,1,1]],"input_ids":[[101,14753,23099,2099,999,15333,11968,2571,22357,1012,102]]} ``` ## Step 7: Interact via Web Interface Your Flask app also comes with a built-in web interface. This is perfect for testing and visualizing how the tokenizer processes text without using command-line tools. Open your web browser and access the Flask web UI using the URL **http://your-server-ip:5000.** You’ll see a simple page with a text area and a Tokenize button. Try to enter the below texts and click **Tokenize,**the results will be displayed on the same page under the “Tokenized Result” section. **Hello, how are you doing today?** ![](https://www.atlantic.net/wp-content/uploads/2025/08/p1.png) **Hola! ¿Cómo estás?** ![](https://www.atlantic.net/wp-content/uploads/2025/08/p2.png) **Let’s meet at 5:00 p.m. #calendar** ![](https://www.atlantic.net/wp-content/uploads/2025/08/p3.png) ## Conclusion You’ve now built a fully functional tokenizer API with a clean web interface using Flask and Hugging Face Transformers—all running on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). The project supports both browser-based interaction and programmatic API access via JSON requests, making it flexible for a variety of use cases. --- # Deploy LLMs Like Phi-3 on Ubuntu 24.04 GPU Server Using Ollama + WebUI > URL: https://www.atlantic.net/gpu-server-hosting/deploy-llms-like-phi-3-on-ubuntu-24-04-gpu-server-using-ollama-webui/ | Published: 2025-09-23 | Author: Hitesh Jethva Large Language Models (LLMs) like Phi-3 are changing the way we interact with AI. Instead of relying on cloud services like OpenAI or Google, you can now run these powerful models locally on your own [GPU server](https://www.atlantic.net/gpu-server-hosting/). This gives you more control over privacy, performance, and cost. In this tutorial, you’ll learn how to deploy LLMs like Phi-3 on an Ubuntu 24.04 GPU server using a tool called Ollama. Ollama simplifies model management and inference with a local API server. On top of that, we’ll build a lightweight Flask-based Web UI so you can chat with the model through your browser—just like ChatGPT, but running entirely on your hardware. ## Prerequisites - An Ubuntu 24.04 server with an NVIDIA GPU. - A non-root user or a user with sudo privileges. - NVIDIA drivers are installed on your server. ## Step 1: Install Ollama Ollama is a lightweight model runtime that makes it easy to run large language models like Phi-3 locally. It manages downloading, caching, and serving models through a built-in API. Installing it on Ubuntu 24.04 is straightforward. 1. Ollama provides a shell script that installs everything for you. Run the following command in your terminal. ```bash curl -fsSL https://ollama.com/install.sh | sh ``` You’ll see output like this: ```bash >>> Installing ollama to /usr/local >>> Downloading Linux amd64 bundle ######################################################################## 100.0% >>> Creating ollama user... >>> Adding ollama user to render group... >>> Adding ollama user to video group... >>> Adding current user to ollama group... >>> Creating ollama systemd service... >>> Enabling and starting ollama service... Created symlink /etc/systemd/system/default.target.wants/ollama.service → /etc/systemd/system/ollama.service. >>> NVIDIA GPU installed. ``` 2. Reload the environment. ```bash source ~/.bashrc ``` 3. Start and enable the Ollama service. ```bash systemctl enable ollama systemctl start ollama ``` 4. Verify that Ollama is running. ```bash curl http://localhost:11434 ``` Output. ```bash Ollama is running ``` ## Step 2: Run a Phi-3 Model with Ollama Now that the Ollama backend is up and running, it’s time to load and run the Phi-3 model. This model is designed to be compact and fast, making it ideal for local deployments on GPU-enabled servers. 1. Run the Phi-3 model using Ollama. ```bash ollama run phi3 ``` This will download the Phi-3 model if it’s not already cached locally, start an interactive session in the terminal, and prompt you to enter text, which Phi-3 will respond to: ```bash >>> What is Ollama? Ollama seems to be a term that doesn't correspond with well-known technology or concepts as of my last update in April 2023. It might either refer to an emerging tool, application, system, project, acronym, organization, or even fictional element not recognized within the industry up until then. ``` 2. Press **Ctrl+D** to exit the session. ## Step 3: Use Ollama Programmatically with cURL While the terminal is great for quick testing, Ollama really shines when used programmatically through its local REST API. This allows you to build custom tools, integrate with apps, or even test prompt responses with curl. Send a prompt to the Ollama backend running Phi-3. ```bash curl http://localhost:11434/api/generate -d '{ "model": "phi3", "prompt": "Explain what is GPU? Answer in short paragraph", "stream": false }' ``` You should get a JSON response like: ```bash {"model":"phi3","created_at":"2025-07-30T14:44:34.276761484Z","response":"A Graphics Processing Unit, or GPU, is a specialized electronic circuit designed to accelerate the creation of computer graphics and facilitate complex calculations for scientific research. Traditionally used solethy primarily by professional graphic designers and video game developers as it excels at processing large blocks of data simultaneously which allows rendering high-quality images with great speed; modern GPUs have evolved into multipurpose processors that can run a wide array of applications including machine learning, cryptocurrency mining, media encoding/decoding, scientific simulations. They are typically found on personal computers as graphics cards or in mobile devices such as smartphones and tablets where computational efficiency is paramount for performance but their use extends far beyond just rendering visuals - they can perform general-purpose calculations quickly due to a parallel processing architecture that's significantly more efficient at handling the matrix and vector operations commonly found in today’s computing tasks.","done":true,"done_reason":"stop","context":[32010,29871,13,9544,7420,825,338,22796,29973,673,297,3273,14880,32007,29871,13,32001,29871,13,29909,29247,10554,292,13223,29892,470,22796,29892,338,263,4266,1891,27758,11369,8688,304,15592,403,278,11265,310,6601,18533,322,16089,10388,4280,17203,363,16021,5925,29889,18375,17658,1304,14419,21155,19434,491,10257,3983,293,2874,414,322,4863,3748,18777,408,372,5566,1379,472,9068,2919,10930,310,848,21699,607,6511,15061,1880,29899,29567,4558,411,2107,6210,29936,5400,22796,29879,505,15220,1490,964,6674,332,4220,1889,943,393,508,1065,263,9377,1409,310,8324,3704,4933,6509,29892,24941,542,10880,1375,292,29892,5745,8025,29914,7099,3689,29892,16021,23876,29889,2688,526,12234,1476,373,7333,23226,408,18533,15889,470,297,10426,9224,1316,408,15040,561,2873,322,1591,1372,988,26845,19201,338,1828,792,363,4180,541,1009,671,4988,2215,8724,925,15061,7604,29879,448,896,508,2189,2498,29899,15503,4220,17203,9098,2861,304,263,8943,9068,11258,393,29915,29879,16951,901,8543,472,11415,278,4636,322,4608,6931,15574,1476,297,9826,30010,29879,20602,9595,29889],"total_duration":5109776741,"load_duration":6017051,"prompt_eval_count":19,"prompt_eval_duration":20751507,"eval_count":189,"eval_duration":5082086586} ``` ## Step 4: Create a Flask WebUI for Chat Interface To make interacting with Phi-3 more intuitive, let’s build a simple web interface using Flask. This WebUI will let you send prompts and display model responses, just like a local ChatGPT! 1. Set up a Python virtual environment. ```bash python3 -m venv ollama-env source ollama-env/bin/activate ``` 2. Install Flask and other necessary dependencies. ```bash pip install flask flask-cors requests ``` 3. Create a Flask application. ```bash nano app.py ``` Add the following code. ```bash from flask import Flask, request, jsonify, render_template import requests app = Flask(__name__) OLLAMA_API = "http://localhost:11434/api/generate" @app.route("/") def home(): return render_template("index.html") @app.route("/chat", methods=["POST"]) def chat(): user_input = request.json.get("prompt") response = requests.post(OLLAMA_API, json={ "model": "phi3", "prompt": user_input, "stream": False }) return jsonify(response.json()) if __name__ == "__main__": app.run(host="0.0.0.0", port=5000) ``` 4. Make a folder called templates, and create index.html inside it. ```bash mkdir templates nano templates/index.html ``` Add the following code. ```bash Phi-3 Chatbot

Chat with Phi-3




  


```

5. Start the Flask app.

```bash
python3 app.py
```

6. Open your browser and visit the URL **http://your-server-ip:5000.**

7. Type your prompt, like: **“Give me 3 startup ideas related to climate change.”**

8. Click **Send,** and the model will reply below the box!

![](https://www.atlantic.net/wp-content/uploads/2025/08/p1-1.png)

## Conclusion

Running LLMs like Phi-3 locally using Ollama on Ubuntu 24.04 gives you full control over AI inference—no API keys, no rate limits, no privacy trade-offs. With just a few commands, you installed Ollama, ran the Phi-3 model, and built a working Flask-based web interface for real-time chat.


---

# GPU Hosting – An In-Depth Buyer’s Guide

> URL: https://www.atlantic.net/gpu-server-hosting/gpu-hosting-an-in-depth-buyers-guide/ | Published: 2025-09-23 | Author: Richard Bailey

Artificial intelligence, machine learning, and large-scale data science have created a huge demand for powerful server access. For data scientists, AI developers, researchers, and business owners looking to innovate, the Graphics Processing Unit (GPU) is helping to power progress and innovation.

However, the cost and complexity of owning and maintaining the necessary hardware can present a significant barrier to market. This is where [GPU hosting](https://www.atlantic.net/gpu-server-hosting/) changes the game. GPU hosting providers have introduced affordable access to supercomputing power, turning a prohibitive capital expense into a manageable operating cost.

This guide provides all the necessary information to help you make an informed decision about choosing a GPU hosting provider. We will cover what GPU hosting is, what to look for in a provider, what hardware to choose, and how to weigh the pros and cons for your business.

## Understanding GPU Hosting: What It Is and Who It’s For

GPU hosting is typically a cloud service that provides access to available compute resources with enterprise-grade GPUs integrated. With standard cloud hosting, the focus is on CPU, Disk, and memory; however, for GPU hosting, it’s the type of GPU card that is the main draw for users.

GPU hosting grants access to various GPU resources; there are typically several different GPU cards to choose from (each with different advantages), and you can lease on-demand either a percentage of a GPU, an entire GPU, or even multiple GPUs at the same time.

The type you need depends entirely on the type of workload you are running. For developers testing AI/ML applications, a percentage of a GPU is usually more than adequate, but for fully fledged AI applications, you may need single or multiple GPUs – it depends on the scale of the applications and the number of users.

### Who is GPU hosting for?

There was a time when GPUs were just for gamers. Their needs are still catered to in the consumer GPU market (GeForce and Radeon models). We are talking about enterprise-grade business servers with GPUs that excel at:

- **Machine Learning & AI:** Training deep learning models, which involves performing millions of repetitive calculations.
- **Big Data Analytics & Scientific Computing:** Complex simulations and near real-time querying of massive datasets in research, engineering, and finance.
- **Video Rendering & Transcoding:** Rendering high-resolution media, 3D graphics, and visual effects.
- **High-Performance Computing (HPC):** Complex computational tasks in fields like genomics, financial modeling, and climate science.

## What to Look for in a GPU Hosting Provider

The demand for GPU hosting is huge, with new vendors joining the market every month. Some providers target different markets, such as consumers, government, healthcare, and finance. As the demand is high, there is often a wait list to get access to GPU resources.

Selecting the right provider requires a thorough breakdown of the available hardware, the supporting cloud infrastructure, tech support, and of course, the pricing models.

### GPU Hardware Quality and Options

The performance of a GPU is entirely dependent on the system supporting it.

- **GPU Manufacturer:** There are 3 main providers of GPU hardware: NVIDIA, AMD, and Intel. It’s largely accepted that NVIDIA is the dominating market leader, likely the main reason NVIDIA became the richest company in the world in 2025.
- **GPU Type:** Look for providers offering modern, data-center-grade GPUs from NVIDIA, such as the H100, A100, and L40S. These are engineered for sustained, high-intensity workloads in a 24/7 server environment.
- **CPU & RAM:** The CPU and RAM must be powerful enough to feed data to the GPU and prevent bottlenecks. Insist on enterprise-grade processors (Intel Xeon or AMD EPYC) and high-speed ECC (Error Correcting Code) RAM to ensure system stability and data integrity.
- **Storage Technology:** Ultra-fast NVMe SSDs are really important in GPU hosting. Traditional SSDs or hard drives simply cannot feed data quickly enough to keep a high-end GPU fully utilized, leading to wasted processing cycles and money.

### Data Center and Network Infrastructure

Your chosen provider should have a global data center presence with plenty of capacity. As a minimum, we recommend:

- **Data Center Specs:** The provider should operate from certified data centers with redundant power (N+1, 2N UPS), advanced cooling, and robust physical security protocols.
- **Network Performance:** High-speed connectivity (10 Gbps+ ports) and a generous data transfer allowance are critical for moving large datasets. The network should be high-capacity and low-latency.
- **DDoS Protection:** Comprehensive, always-on protection against Distributed Denial of Service (DDoS) attacks should be a standard, included feature to ensure your services remain online.

### Support and Service Level Agreements (SLAs)

If you are new to GPU applications, there is a good chance you may need support setting up a production workload. The GPU hosting provider must ensure:

- **Expert Support:** GPU workloads are complex. Stress the importance of 24/7 direct access to senior engineers who understand the intricacies of GPU environments. This is a significant differentiator from tiered, ticket-based support systems.
- **SLAs:** A provider should offer a strong network uptime SLA, with 100% uptime being the gold standard offered by top-tier providers like Atlantic.Net. A clear hardware replacement guarantee is also essential to minimize potential downtime.

### Pricing, Contracts, and Setup

Cost is one of the most important considerations with GPU hosting. Providers vary significantly in cost, but it’s important to weigh up the level of service you are getting for your financial outgoings.

- **Pricing Models:** Understand the different models available, such as hourly, monthly, or reserved instances. Monthly contracts often provide the best value for ongoing projects.
- **Setup and Customization:** Check for setup fees and ask about customization options. A good provider will work with you to build a server tailored to your specific needs, ensuring you don’t pay for resources you won’t use.

## What to Buy: Server Hardware and Managed Services

Matching the hardware configuration to your workload is critical for performance and cost-efficiency.

### Choosing the Right GPU

Different tasks require different GPUs. For example, [NVIDIA’s lineup](https://www.atlantic.net/gpu-server-hosting/an-overview-of-popular-nvidia-gpus/) is specialized:

- **A-series and H-series (e.g., A100, H100):** These are flagship models designed for large-scale AI model training, featuring the highest VRAM capacity and Tensor Core performance.
- **L-series (e.g., L40S):** These GPUs offer an optimal balance of performance and value for inference, rendering, and less VRAM-intensive tasks.

When choosing, the most critical factor is often VRAM capacity. It dictates the maximum size and complexity of the models and datasets you can process. Insufficient VRAM will cause workloads to either refuse to run or fail entirely. It is always wise to provision a little more VRAM than your initial estimates suggest.

### CPU, Memory (RAM), and Storage

- **CPU and RAM:** A good starting point is to provision at least two powerful CPU cores and ensure your system RAM is equal to or greater than the total VRAM of your GPU(s). For heavy data preprocessing, you will need significantly more.
- **Storage:** NVMe SSDs are highly recommended. For data protection and even greater performance, consider RAID configurations.

### Software and Environment

Look for providers that offer pre-configured 1-click server environments. Starting with the correct NVIDIA drivers, CUDA toolkit, cuDNN libraries, and frameworks like TensorFlow or PyTorch already installed can save you days of complex setup and troubleshooting. At Atlantic.Net, we offer one-click installations for popular AI/ML stacks to get you productive in minutes.

## Why You Should Use GPU Hosting

Hosting your GPU workloads offers clear strategic advantages over purchasing hardware. You may opt to go it alone, but you may have to rethink this when you see the price of enterprise-grade GPUs.

- **Access Raw GPU Power:** Get on-demand access to enterprise hardware that can cost tens of thousands of dollars per server, hardware that is too expensive for most companies to purchase and maintain in-house.
- **Accelerated Performance:** Drastically reduce processing times for complex computational tasks, accelerating your speed of innovation and discovery from weeks to days, or days to hours.
- **Scalability:** Instantly scale GPU resources up or down as your project demands change. Spin up a massive 8-GPU server for a short-term training job and then scale back to a single GPU for inference.
- **Cost-Effectiveness:** Convert a large, risky capital expenditure (CapEx) into a predictable monthly operating expense (OpEx), freeing up capital for other core business activities.

## The Good Points and Bad Points of GPU Hosting

Let’s now weigh up the pros and cons of GPU hosting.  We offer this information for transparency to furnish you with all the facts.

### The Good

- **Performance:** GPUs offer unmatched parallel processing power for AI, HPC, and rendering workloads. You get access to cutting-edge hardware.
- **Scalability:** On-demand access to resources allows you to perfectly match compute power to the project’s needs.
- **Cost Model:** A pay-as-you-go or monthly model avoids massive upfront hardware investment.
- **Maintenance:** The provider handles all hardware, power, cooling, and infrastructure maintenance, freeing up your team. They can even offer a wide range of Managed services such as backups, server management, and managed security.

### The Bad

- **Cost:** Can be significantly more expensive than CPU-only hosting for workloads that don’t leverage the GPU’s parallel architecture.
- **Complexity:** Can require specialized knowledge to manage and optimize workloads effectively.
- **Vendor Lock-in:** Moving complex models and large datasets between different cloud provider environments can be difficult and time-consuming.
- **Surprise Bills:** Hourly pay-as-you-go models can lead to unexpectedly high costs if usage is not carefully monitored and managed. Don’t forget to switch off your Instance when you’re finished.

## What to Decide Before You Buy

Now you understand the core advantages and disadvantages,  ask yourself these key questions before engaging with a provider:

### Your Technical Needs

- What software frameworks (e.g., TensorFlow, PyTorch) and libraries (CUDA, cuDNN) will you use?
- What are the VRAM requirements of your largest models?
- How much data will you be processing, and what are your data transfer needs?
- Do you require multi-GPU interconnects like NVLink?

### Your Budget

Now consider your budget; this is a critical step to understand.

- What is your realistic monthly budget?
- Have you accounted for potential data transfer overage costs?
- Does an hourly or monthly pricing model make more sense for your usage patterns?

### Your Technical Skills

Do you or your team have to require know-how to onboard GPU hosting hardware and deploy AI workloads to it?

- Who on your team has the expertise to configure, manage, and troubleshoot the server environment?
- Can they patch and update the server on demand?
- Who will install and manage the AI applications?
- Do you need a fully managed service to offload system administration, or is an unmanaged server sufficient?

## Atlantic.Net vs. Hyperscale Providers

The cloud market is dominated by hyperscalers like AWS, Azure, and Google Cloud. They offer a massive, complex menu of GPU instances, but their model is fundamentally DIY. They provide a warehouse of parts and leave it to you to assemble a working, secure, and cost-effective solution.

**Atlantic.Net operates on a different philosophy: partnership.**

Where hyperscalers offer fixed configurations, we start with a conversation. We work with you to understand your specific workload, bottlenecks, and goals, then engineer a custom server that is the perfect tool for your job. This ensures you never pay for resources you don’t need or suffer from a performance issue that a standard instance would create.

The biggest differentiator is Customization and Support. With a hyperscaler, getting expert support is time consuming and very hit and miss. At Atlantic.Net, you get a direct line to the senior engineers who build and manage these systems every day. When you have a complex problem, you talk to an expert who can solve it. That’s not just support; it’s a partnership invested in your success.

## Questions for a Subject Matter Expert

Use these questions to vet a potential provider’s expertise:

1. How do you ensure data throughput between storage and the GPU isn’t a bottleneck for I/O-intensive workloads?
2. What specific enterprise-grade GPUs (e.g., H100, L40S) do you have available, and how do you help clients choose the right one?
3. Can you describe the CPU, RAM, and storage you pair with your high-end GPUs to create a balanced system?
4. What is your hardware replacement SLA if a GPU or another component fails?
5. What is the most common mistake people make when provisioning a GPU server for an AI workload?
6. Do you offer pre-configured server images with standard ML frameworks like PyTorch or TensorFlow installed?
7. How do you handle network security and DDoS protection for your GPU clients?
8. Beyond the hardware, what managed services do you offer to help us deploy and maintain our machine learning environment?
9. Can you provide an example of how you’ve built a custom solution for a client with unique requirements?
10. Who will I be speaking to when I need technical support, and what is their level of expertise with GPU systems?


---

# PCI Hosting – An In-Depth Buyer’s Guide

> URL: https://www.atlantic.net/pci-compliant-hosting/pci-hosting-an-in-depth-buyers-guide/ | Published: 2025-09-23 | Author: Richard Bailey

Credit and debit cards have become the standard for consumer transactions, especially online. To protect the integrity of this system, the world’s major card providers mandate that retailers adhere to a stringent set of security standards designed to safeguard customer payment data.

The Payment Card Industry Data Security Standard (PCI DSS) was introduced to ensure that all companies that handle credit card information maintain a highly secure payment environment. Adherence to these standards is not optional; it is a contractual mandate for any business wanting to process payments from Visa, Mastercard, Amex, Discover, and JCB.

This is why choosing a hosting provider that is PCI compliant is a decision that carries significant importance. Not only do you have to think of the technical ramifications, but also how the decision will impact your business’s security and financial integrity. A data breach can be a catastrophic event, leading to hefty fines, loss of customer trust, and severe damage to your brand’s reputation.

This in-depth guide is for business owners, IT managers, and users who need to get up to speed about the complexities of [PCI hosting](https://www.atlantic.net/pci-compliant-hosting). We will look at what PCI hosting providers must offer, plus discuss the specific services you’ll need to be compliant, and why a specialized hosting solution is a crucial investment.

## PCI-Compliant Hosting Requirements

Many providers claim to be “PCI compliant,” but the term can be misleading. True compliance is layered, starting with physical security and extending all the way to the services that actively protect your data. Here’s what you should expect as a baseline.

### Audits, Certifications, and the Attestation of Compliance (AOC)

Before you discuss technology, ask for the paperwork. The single most important document is the Attestation of Compliance (AOC). This is a formal, signed declaration from a certified Qualified Security Assessor (QSA) that the provider has been audited and meets PCI DSS requirements. If a provider can’t or won’t share their AOC, walk away.

Look for other independent audits as well, as they show a deeper commitment to security:

- **SOC 2 Type II:** This report evaluates a provider’s security controls over a period of time, offering a more comprehensive view of their security posture.
- **ISO 27001**: An international standard for information security management.

### Data Center and Physical Security

A compliant environment is built on secure infrastructure, both physical and digital. Your provider should be transparent about their security measures, which must include:

- **Physical Data Center Security:** There should be 24/7 on-site security staff, video surveillance, biometric access controls to prevent unauthorized entry, and redundant power, cooling, and fire suppression systems.
- **A Hardened Network:** The network is the primary battlefield for cyber threats. Essential security measures include a managed firewall to control traffic, Intrusion Detection and Prevention Systems (IDS/IPS) to spot and block malicious activity, and a Web Application Firewall (WAF) to protect against attacks aimed at your website itself. DDoS mitigation is also crucial to ensure an attack doesn’t knock your payment processing offline.

### Uptime and Service Level Agreements (SLAs)

For any e-commerce business, downtime is lost revenue. A provider must offer a financially backed Service Level Agreement (SLA) that guarantees a high level of uptime for their network, power, and infrastructure.

Look for an SLA of at least 99.9%, and be sure to understand the compensation offered if the provider fails to meet their guarantee. Some of the very best providers offer [100% Uptime SLAs](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/).

### Customer Support

When dealing with the complexities of PCI compliance, having access to expert support is invaluable. Look for a provider with a proven track record in PCI hosting and a support team that is available 24/7. The ability to speak directly with engineers who understand the nuances of compliance can be a significant advantage.

## Essential PCI Hosting Services

Building a PCI-compliant hosting environment requires a specific set of services and configurations.

Here are the core components you’ll need:

### Server Environment: Dedicated or Private Cloud

While it’s possible to build a compliant environment on a public cloud, it is a complex undertaking that places a significant security burden on your team. For this reason, dedicated servers or a private cloud environment are often the recommended choices for PCI hosting. These options provide greater isolation and control, simplifying compliance and reducing the risk of a data breach.

### Security Services

These are not optional add-ons but fundamental components of a secure and compliant hosting solution:

- **Managed Firewall:** As mentioned, a dedicated and properly configured firewall is your first line of defense.
- **Encrypted VPN Access:** A Virtual Private Network (VPN) is crucial for providing secure administrative access to your servers for your team.
- **Encrypted Backups:** All backups of cardholder data must be encrypted both in transit and at rest. These backups should be stored in a secure, off-site location.
- **Log Management and Monitoring:** PCI DSS requires that you maintain detailed audit logs of all access to cardholder data. A log management product collects, secures, and analyzes these logs to help identify suspicious activity.
- **Vulnerability Scanning:** Regular internal and external vulnerability scans are required by PCI DSS to identify and remediate security weaknesses.

## Why You Should Use a Specialized PCI Hosting Provider

Attempting to achieve PCI compliance on a non-specialized hosting platform can be a risky and resource-intensive endeavor. It’s not impossible, but it’s extremely challenging.

Many businesses choose to outsource to PCI Hosting providers like Atlantic.Net for the added peace of mind that you will be onboarded onto a proven and compliant infrastructure that your business simply consumes on demand.

Here’s why partnering with a specialist like Atlantic.Net is the smarter choice:

- **Reduced Risk:** A specialized provider has pre-built, audited solutions and a team of experts who understand the intricacies of PCI DSS. This significantly lowers the risk of a misconfiguration that could lead to a data breach and substantial fines.
- **Cost-Effectiveness:** While specialized hosting may have a higher upfront cost than standard hosting, it is a fraction of the potential cost of non-compliance. Fines for PCI non-compliance can range from [$5,000 to $100,000](https://www.varonis.com/blog/pci-compliance) per month.
- **Expert Guidance:** A knowledgeable provider acts as a partner, offering guidance on everything from initial setup to audit preparation. This expertise is invaluable, especially for businesses without a dedicated in-house security team.
- **Peace of Mind:** Knowing that your hosting environment is in the hands of experts allows you to focus on your core business, confident that you have a secure foundation for your payment processing.

## Pros and Cons of PCI Hosting

When you handle customer card data, your choice of hosting is key. A specialized PCI provider can be a huge help with security and compliance, but it’s a solution with clear trade-offs. It’s important to weigh the benefits against the higher cost and the responsibilities you still have to manage.

### Pros:

- **Enhanced Security:** A robustly secure environment for your customers’ sensitive data.
- **Reduced Risk of Data Breaches:** Proactive security measures significantly lower the likelihood of a costly breach.
- **Increased Customer Trust:** Demonstrating a commitment to security can enhance your brand’s reputation.
- **Simplified Compliance**: A specialized provider handles many of the technical aspects of PCI DSS, making it easier for you to achieve and maintain compliance.

### Cons:

- **Higher Cost:** Specialized PCI hosting is more expensive than standard hosting options.
- **Shared Responsibility:** While the provider secures the infrastructure, you are still responsible for the security of your applications and for managing user access.
- **Potential for Complexity:** The initial setup and configuration of a compliant environment can be complex.

## Quick Tips for PCI Hosting Success

Choosing a PCI host is just the first step. To truly protect your business and your customers, it’s crucial to be an active partner in the security process. Follow these quick tips to stay on top of your responsibilities and get the most out of your compliant environment.

- Always ask for the provider’s Attestation of Compliance (AOC). This is non-negotiable proof of their compliance.
- Understand the shared responsibility model. Clearly define which security tasks are handled by the provider and which are your responsibility.
- Start with a risk assessment. Understand where cardholder data is stored, transmitted, and processed in your environment.
- Limit the scope of your cardholder data environment (CDE). The fewer systems that touch cardholder data, the easier it is to secure them.
- Implement strong access control measures. Only grant access to cardholder data to employees who absolutely need it.

## Q&A with a Subject Matter Expert

Choosing the right provider is about more than just technology; it’s about finding a true security partner. To separate the experts from the rest, it helps to ask insightful questions. Here are a few to get you started during your vetting process:

- What is the most common mistake you see businesses make when trying to achieve PCI compliance?
- How do you help your clients prepare for a PCI audit?
- What is the single most important security control for protecting cardholder data?
- How does your team stay up-to-date with the latest threats and changes to PCI DSS?
- Can you walk me through your incident response plan in the event of a security breach?

## Key Considerations Before You Start

Before you start evaluating hosting providers, it’s important to look inward. Understanding your own business needs and limitations will help you choose the right solution. Here are the key factors to consider:

- **Your PCI DSS Level:** The number of transactions you process annually determines your compliance level, which dictates the specific requirements you must meet.
- **Your Technical Expertise:** Be realistic about your team’s ability to manage a secure environment. If you lack in-house expertise, a fully managed solution is often the best choice.
- **Your Budget:** While cost is a factor, it shouldn’t be the primary driver. The long-term cost of a data breach far outweighs the investment in a secure hosting solution.

## What Can Go Wrong?

There are common issues that can trip businesses up on their compliance journey. Being aware of these potential mistakes is the first step to avoiding them.

- **Assuming the provider handles everything:** Misunderstanding the shared responsibility model can lead to critical security gaps that leave you exposed.
- **Failing to properly scope your environment:** If you don’t identify all the systems that handle cardholder data, you can’t adequately protect them.
- **Neglecting ongoing maintenance:** PCI compliance isn’t a one-time event. It requires continuous monitoring, patching, and updating to remain secure.

## How Do You Know You Are on the Right Track?

PCI compliance is an ongoing process, not a destination. So how do you know you’re heading in the right direction? Look for these positive signs that confirm you’re making solid progress:

- You have a clear understanding of your specific PCI DSS requirements.
- You have partnered with a reputable hosting provider who has provided their Attestation of Compliance (AOC).
- You have a documented shared responsibility matrix that outlines who is responsible for each security task.
- You are conducting regular vulnerability scans and addressing any identified issues quickly.

## Atlantic.Net vs. Hyperscale Providers

When it comes to PCI-compliant hosting, there are two main approaches you can take.

#### **1. The DIY Approach with Hyperscalers (AWS, Azure, Google Cloud)**

The giant public cloud providers offer a huge menu of PCI-compliant *services and tools*. However, they leave it entirely up to you to assemble those tools into a secure and compliant solution.

This path offers immense flexibility but requires a high level of in-house security expertise. It’s a viable option for large enterprises with dedicated security teams, but it can be complex, time-consuming, and error-prone for everyone else.

#### **2. The Partnership Approach with a Specialist**

A specialized PCI hosting provider takes a more hands-on, solution-oriented approach. Instead of just giving you the tools, they provide a pre-built, audited, and compliant environment ready for you to use. This significantly lowers your risk of a misconfiguration that could lead to a breach.

At Atlantic.Net, for example, we focus on this partnership model. Our team of certified engineers works with you to design and implement a hosting environment tailored to your specific needs. We can be as involved as you need us to be, acting as an extension of your team to offer expert guidance on everything from initial setup to audit preparation.

For businesses without a dedicated security staff, this model is a far more cost-effective and secure choice. While the monthly cost may be higher than a basic cloud server, it is a fraction of the potential cost of non-compliance, which can run into tens of thousands of dollars per month in fines.

## Take the Next Step

Ready to build a secure foundation for your payments? Contact the [PCI hosting experts at Atlantic.Net](https://www.atlantic.net/about-us/corporate-contact/) today for a no-obligation consultation to discuss your specific compliance needs.


---

# Implementing Autoencoders from Scratch in PyTorch on Ubuntu 24.04 GPU Server

> URL: https://www.atlantic.net/gpu-server-hosting/implementing-autoencoders-from-scratch-in-pytorch-on-ubuntu-24-04-gpu-server/ | Published: 2025-09-24 | Updated: 2026-05-04 | Author: Hitesh Jethva

Autoencoders are a special type of neural network used to learn efficient representations of data, often for the purpose of dimensionality reduction or unsupervised feature learning. They work by compressing the input into a latent space (encoding) and then reconstructing the original input from this compressed version (decoding). The main goal is to output data that closely resembles the input.

In this tutorial, you’ll learn how to implement an autoencoder from scratch in PyTorch, without using high-level prebuilt models. You’ll train it on the MNIST dataset, which contains handwritten digits, and use a fully connected (linear) architecture to build both the encoder and decoder.

## Prerequisites

- An Ubuntu 24.04 server with an NVIDIA GPU.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1: Set up Python Environment

Before diving into the code, you’ll need to set up a clean Python development environment on your Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). Follow these steps to install the necessary packages and verify CUDA support.

1. Install system dependencies for managing your project.

```bash
apt install python3 python3-pip python3-venv build-essential git -y
```

2. Create and activate a Python virtual environment.

```bash
python3 -m venv autoencoder
source autoencoder/bin/activate
```

3. Upgrade pip and install required Python packages.

```bash
pip install --upgrade pip
pip install matplotlib
pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu121
```

4. Check if your GPU is detected by PyTorch.

```bash
python3 -c "import torch; print(torch.cuda.is_available())"
```

Output.

```bash
True
```

5. Create a project directory.

```bash
mkdir pytorch_autoencoder
cd pytorch_autoencoder
```

You’ll place all your scripts (dataset loader, model, training loop, and visualization) inside this directory.

## Step 2: Prepare the Dataset Loader

To train our autoencoder, we’ll use the MNIST dataset, a classic benchmark in machine learning containing 28×28 grayscale images of handwritten digits (0–9). PyTorch’s torchvision.datasets module makes it easy to download and use this dataset.

Create a Python script to wrap the dataset and data loader logic.

```bash
nano dataset.py
```

Add the following code.

```bash
# dataset.py
import torch
from torchvision import datasets, transforms
from torch.utils.data import DataLoader

def get_dataloaders(batch_size=128):
    transform = transforms.ToTensor()

    train_dataset = datasets.MNIST(root='data', train=True, transform=transform, download=True)
    test_dataset = datasets.MNIST(root='data', train=False, transform=transform, download=True)

    train_loader = DataLoader(train_dataset, batch_size=batch_size, shuffle=True)
    test_loader = DataLoader(test_dataset, batch_size=batch_size, shuffle=False)

    return train_loader, test_loader
```

**Explanation:**

- **transforms.ToTensor():** Converts images to tensors and scales pixel values from [0, 255] to [0, 1].
- **datasets.MNIST(…):** Automatically downloads the MNIST dataset.
- **DataLoader(…):** Creates iterable batches for training and testing.

## Step 3: Build the Autoencoder Model

Now that the dataset loader is ready, it’s time to build the core of this project, the Autoencoder model. We’ll define a simple feedforward neural network with two main parts:

**Encoder:** Compresses the input image into a lower-dimensional representation.
 **Decoder:** Reconstructs the image from this compressed version.

Create a **autoencoder.py** file.

```bash
nano autoencoder.py
```

Add the following code.

```bash
# autoencoder.py
import torch.nn as nn

class Autoencoder(nn.Module):
    def __init__(self):
        super(Autoencoder, self).__init__()
        self.encoder = nn.Sequential(
            nn.Linear(28 * 28, 128),
            nn.ReLU(),
            nn.Linear(128, 64),
            nn.ReLU()
        )
        self.decoder = nn.Sequential(
            nn.Linear(64, 128),
            nn.ReLU(),
            nn.Linear(128, 28 * 28),
            nn.Sigmoid()
        )

    def forward(self, x):
        x = x.view(x.size(0), -1)
        encoded = self.encoder(x)
        decoded = self.decoder(encoded)
        return decoded
```

Explanation of the Model

- **Input:** MNIST images are 28×28, so we flatten them to a 784-element vector.
- **Encoder:** 784 → 128 → 64: Two linear layers with ReLU activation.
- **Decoder:** 64 → 128 → 784: Two linear layers that attempt to reconstruct the original image.
- **Final activation (Sigmoid):** Scales outputs between 0 and 1 (same range as input pixels).

## Step 4: Train the Autoencoder

With the dataset and model in place, it’s time to train the autoencoder.

Let’s create a Python file.

```bash
nano train.py
```

Add the following code.

```bash
# train.py
import torch
import torch.nn as nn
import torch.optim as optim
from autoencoder import Autoencoder
from dataset import get_dataloaders

device = torch.device("cuda" if torch.cuda.is_available() else "cpu")

# Load data
train_loader, _ = get_dataloaders()

# Initialize model
model = Autoencoder().to(device)
criterion = nn.MSELoss()
optimizer = optim.Adam(model.parameters(), lr=1e-3)

# Training
num_epochs = 10
for epoch in range(num_epochs):
    total_loss = 0
    for imgs, _ in train_loader:
        imgs = imgs.to(device)
        outputs = model(imgs)
        loss = criterion(outputs, imgs.view(imgs.size(0), -1))

        optimizer.zero_grad()
        loss.backward()
        optimizer.step()

        total_loss += loss.item()

    print(f"Epoch [{epoch+1}/{num_epochs}], Loss: {total_loss / len(train_loader):.4f}")

# Save the model
torch.save(model.state_dict(), "autoencoder.pth")
```

Execute the training script to start training your autoencoder.

```bash
python3 train.py
```

A trained model file **autoencoder.pth** will be saved in your working directory.

## Step 5: Visualize the Output

In this step, you’ll load your saved model **(autoencoder.pth),** pass test images through the autoencoder, compare original and reconstructed images, save the output as a visual .png file.

Create visualize.py file.

```bash
nano visualize.py
```

Add the following code.

```bash
# visualize.py
import torch
from autoencoder import Autoencoder
from dataset import get_dataloaders
import matplotlib.pyplot as plt

device = torch.device("cuda" if torch.cuda.is_available() else "cpu")

# Load model
model = Autoencoder().to(device)
model.load_state_dict(torch.load("autoencoder.pth"))
model.eval()

# Get test images
_, test_loader = get_dataloaders()
images, _ = next(iter(test_loader))
images = images[:8].to(device)

# Reconstruct
with torch.no_grad():
    reconstructed = model(images)

images = images.cpu()
reconstructed = reconstructed.view(-1, 1, 28, 28).cpu()

# Plot
fig, axs = plt.subplots(2, 8, figsize=(12, 3))
for i in range(8):
    axs[0, i].imshow(images[i].squeeze(), cmap='gray')
    axs[1, i].imshow(reconstructed[i].squeeze(), cmap='gray')
    axs[0, i].axis("off")
    axs[1, i].axis("off")
plt.suptitle("Top: Original | Bottom: Reconstructed")
plt.tight_layout()
plt.savefig("reconstructed.png")
plt.show()
```

Run the visualization script.

```bash
python3 visualize.py
```

This will generate a file reconstructed.png showing original and reconstructed digits side by side.

## Step 6: Download the Result to Your Local Machine

From your local desktop computer, run this scp command to copy the image from your server.

```bash
scp root@your-server-ip:/root/pytorch_autoencoder/reconstructed.png /home/user/Downloads/
```

Open the downloaded image file to view the **reconstructed.png** file.

![](https://www.atlantic.net/wp-content/uploads/2025/08/reconstructed.png)

## Conclusion

In this tutorial, you learned how to implement an autoencoder from scratch in PyTorch on an Ubuntu 24.04 GPU server. You set up a clean Python environment, built a custom encoder–decoder architecture using fully connected layers, trained it on the MNIST dataset, and visualized how well the model could reconstruct digit images.


---

# Autoencoders Using Keras on Ubuntu 24.04 GPU Server

> URL: https://www.atlantic.net/gpu-server-hosting/autoencoders-using-keras-on-ubuntu-24-04-gpu-server/ | Published: 2025-09-25 | Updated: 2025-09-26 | Author: Hitesh Jethva

Autoencoders are a special type of neural network designed to learn efficient representations of data. They’re commonly used for tasks like dimensionality reduction, image compression, and denoising. Instead of predicting labels, autoencoders aim to recreate their input at the output layer, forcing the network to learn the most important features in between.

In this hands-on tutorial, you’ll learn how to build several types of autoencoders using Keras with TensorFlow backend on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/).

## Prerequisites

- An Ubuntu 24.04 server with an NVIDIA GPU.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1: Set up Python Environment

Before diving into code, let’s prepare your Ubuntu 24.04 GPU server to run Keras-based autoencoders efficiently. This includes installing Python tools, setting up a virtual environment, and installing the required Python libraries.

1. Install Python tools and other dependencies.

```bash
apt install python3 python3-pip python3-venv git wget -y
```

2. Create and activate a virtual environment.

```bash
python3 -m venv autoencoder-env
source autoencoder-env/bin/activate
```

3. Now install TensorFlow, NumPy, and Matplotlib.

```bash
pip install --upgrade pip
pip install tensorflow matplotlib numpy
```

**Explanation:**

- **tensorflow:** Provides Keras API and GPU support
- **matplotlib:** Used to visualize image results
- **numpy:** Helps with array operations and data preprocessing

## Step 2: Prepare MNIST Dataset

To train our autoencoders, we’ll use the MNIST dataset, a set of 70,000 handwritten digit images (28×28 pixels). This dataset is commonly used for testing image-based models because it’s lightweight and easy to visualize.

1. Download the MNIST dataset in .npz format from TensorFlow’s official hosting.

```bash
wget https://storage.googleapis.com/tensorflow/tf-keras-datasets/mnist.npz
```

**This file contains:**

- **x_train:** 60,000 training images
- **y_train:** labels for training data (we won’t use labels here)
- **x_test:** 10,000 test images
- **y_test:** test labels

2. Create a reusable file to load this dataset across all our autoencoder scripts.

```bash
nano load_mnist.py
```

Add the following code.

```bash
# load_mnist.py
import numpy as np

def load_data(path='mnist.npz'):
    with np.load(path) as f:
        x_train, y_train = f['x_train'], f['y_train']
        x_test, y_test = f['x_test'], f['y_test']
        return (x_train, y_train), (x_test, y_test)
```

3. Run the script to test the loader.

```bash
python3 load_mnist.py
```

If there’s no error, your MNIST loader is working correctly. You’re now ready to feed this data into your autoencoder models.

## Step 3: Build a Simple Autoencoder

In this section, you’ll create your first autoencoder using fully connected (Dense) layers. This model compresses the MNIST images into a lower-dimensional representation (encoding) and then reconstructs them.

1. Create a Python script for a simple autoencoder.

```bash
nano simple_autoencoder.py
```

Add the following code.

```bash
import numpy as np
import matplotlib.pyplot as plt
import tensorflow as tf
from load_mnist import load_data

ENCODING_DIM = 32
input_img = tf.keras.layers.Input(shape=(784,))
encoded = tf.keras.layers.Dense(ENCODING_DIM, activation='relu')(input_img)
decoded = tf.keras.layers.Dense(784, activation='sigmoid')(encoded)

autoencoder = tf.keras.models.Model(input_img, decoded)
autoencoder.compile(optimizer='adadelta', loss='binary_crossentropy')

(x_train, _), (x_test, _) = load_data()
x_train = x_train.astype('float32') / 255.
x_test = x_test.astype('float32') / 255.
x_train = x_train.reshape((len(x_train), 784))
x_test = x_test.reshape((len(x_test), 784))

autoencoder.fit(x_train, x_train, epochs=50, batch_size=256, shuffle=True, validation_data=(x_test, x_test))

decoded_imgs = autoencoder.predict(x_test)

# Visualize results
n = 10
plt.figure(figsize=(20, 4))
for i in range(n):
    ax = plt.subplot(2, n, i + 1)
    plt.imshow(x_test[i].reshape(28, 28), cmap='gray')
    ax.axis('off')
    ax = plt.subplot(2, n, i + 1 + n)
    plt.imshow(decoded_imgs[i].reshape(28, 28), cmap='gray')
    ax.axis('off')
plt.savefig("simple_autoencoder_result.png")
```

2. Run the script to start training.

```bash
python3 simple_autoencoder.py
```

A file named **simple_autoencoder_result.png** will be generated, showing the top 10 original test images and their reconstructions.

![](https://www.atlantic.net/wp-content/uploads/2025/08/simple_autoencoder_result.png)

## Step 4: Build a Sparse Autoencoder

The Sparse Autoencoder works like the simple one but adds a constraint to encourage the model to activate only a few neurons in the hidden layer. This leads to more meaningful and compact representations of the input.

1. Create a script for a sparse autoencoder.

```bash
nano sparse_autoencoder.py
```

Add the following code.

```bash
import numpy as np
import matplotlib.pyplot as plt
import tensorflow as tf
from load_mnist import load_data

ENCODING_DIM = 32
input_img = tf.keras.layers.Input(shape=(784,))
encoded = tf.keras.layers.Dense(ENCODING_DIM, activation='relu',
    activity_regularizer=tf.keras.regularizers.l1(10e-5))(input_img)
decoded = tf.keras.layers.Dense(784, activation='sigmoid')(encoded)
autoencoder = tf.keras.models.Model(input_img, decoded)
autoencoder.compile(optimizer='adadelta', loss='binary_crossentropy')

(x_train, _), (x_test, _) = load_data()
x_train = x_train.astype('float32') / 255.
x_test = x_test.astype('float32') / 255.
x_train = x_train.reshape((len(x_train), 784))
x_test = x_test.reshape((len(x_test), 784))

autoencoder.fit(x_train, x_train, epochs=100, batch_size=256, shuffle=True, validation_data=(x_test, x_test))

decoded_imgs = autoencoder.predict(x_test)

# Visualize
n = 10
plt.figure(figsize=(20, 4))
for i in range(n):
    ax = plt.subplot(2, n, i + 1)
    plt.imshow(x_test[i].reshape(28, 28), cmap='gray')
    ax.axis('off')
    ax = plt.subplot(2, n, i + 1 + n)
    plt.imshow(decoded_imgs[i].reshape(28, 28), cmap='gray')
    ax.axis('off')
plt.savefig("sparse_autoencoder_result.png")
```

2. Run the script to sparse autoencoder.

```bash
python3 sparse_autoencoder.py
```

Training will run for 100 epochs and output a new image:

```bash
sparse_autoencoder_result.png
```

This image will show how the sparse model performs reconstruction using only a limited number of active neurons.

![](https://www.atlantic.net/wp-content/uploads/2025/08/sparse_autoencoder_result.png)

## Step 5: Build a Deep Autoencoder

A Deep Autoencoder extends the architecture by stacking multiple encoding and decoding layers. This helps the model learn more abstract and hierarchical features from the data, making it more powerful than a shallow architecture.

1. Create a new script for a deep autoencoder.

```bash
nano deep_autoencoder.py
```

Add the following code.

```bash
import numpy as np
import matplotlib.pyplot as plt
import tensorflow as tf
from load_mnist import load_data

input_img = tf.keras.layers.Input(shape=(784,))
encoded = tf.keras.layers.Dense(128, activation='relu')(input_img)
encoded = tf.keras.layers.Dense(64, activation='relu')(encoded)
encoded = tf.keras.layers.Dense(32, activation='relu')(encoded)
decoded = tf.keras.layers.Dense(64, activation='relu')(encoded)
decoded = tf.keras.layers.Dense(128, activation='relu')(decoded)
decoded = tf.keras.layers.Dense(784, activation='sigmoid')(decoded)

autoencoder = tf.keras.models.Model(input_img, decoded)
autoencoder.compile(optimizer='adadelta', loss='binary_crossentropy')

(x_train, _), (x_test, _) = load_data()
x_train = x_train.astype('float32') / 255.
x_test = x_test.astype('float32') / 255.
x_train = x_train.reshape((len(x_train), 784))
x_test = x_test.reshape((len(x_test), 784))

autoencoder.fit(x_train, x_train, epochs=100, batch_size=256, shuffle=True, validation_data=(x_test, x_test))

decoded_imgs = autoencoder.predict(x_test)

# Visualize
n = 10
plt.figure(figsize=(20, 4))
for i in range(n):
    ax = plt.subplot(2, n, i + 1)
    plt.imshow(x_test[i].reshape(28, 28), cmap='gray')
    ax.axis('off')
    ax = plt.subplot(2, n, i + 1 + n)
    plt.imshow(decoded_imgs[i].reshape(28, 28), cmap='gray')
    ax.axis('off')
plt.savefig("deep_autoencoder_result.png")
```

2. Run the deep encoder.

```bash
python3 deep_autoencoder.py
```

Once complete, the output image **deep_autoencoder_result.png** will be saved in your working directory. It shows side-by-side comparisons of the original and reconstructed digits.

![](https://www.atlantic.net/wp-content/uploads/2025/08/deep_autoencoder_result.png)

## Step 6: Build a Convolutional Autoencoder

The Convolutional Autoencoder (CAE) is designed for image data. Instead of flattening the input, it uses convolutional layers to preserve spatial structure. This is ideal for capturing visual patterns in images like edges, curves, and textures. This model compresses the 28×28 grayscale image to a low-dimensional feature map, then reconstructs it.

1. Create a script for a convolutional autoencoder.

```bash
nano conv_autoencoder.py
```

Add the following code.

```bash
import numpy as np
import matplotlib.pyplot as plt
import tensorflow as tf
from load_mnist import load_data

(x_train, _), (x_test, _) = load_data()
x_train = x_train.astype('float32') / 255.
x_test = x_test.astype('float32') / 255.
x_train = np.reshape(x_train, (len(x_train), 28, 28, 1))
x_test = np.reshape(x_test, (len(x_test), 28, 28, 1))

input_img = tf.keras.layers.Input(shape=(28, 28, 1))
x = tf.keras.layers.Conv2D(16, (3, 3), activation='relu', padding='same')(input_img)
x = tf.keras.layers.MaxPooling2D((2, 2), padding='same')(x)
x = tf.keras.layers.Conv2D(8, (3, 3), activation='relu', padding='same')(x)
x = tf.keras.layers.MaxPooling2D((2, 2), padding='same')(x)
encoded = tf.keras.layers.Conv2D(8, (3, 3), activation='relu', padding='same')(x)

x = tf.keras.layers.UpSampling2D((2, 2))(encoded)
x = tf.keras.layers.Conv2D(8, (3, 3), activation='relu', padding='same')(x)
x = tf.keras.layers.UpSampling2D((2, 2))(x)
decoded = tf.keras.layers.Conv2D(1, (3, 3), activation='sigmoid', padding='same')(x)

autoencoder = tf.keras.models.Model(input_img, decoded)
autoencoder.compile(optimizer='adadelta', loss='binary_crossentropy')
autoencoder.fit(x_train, x_train, epochs=50, batch_size=128, shuffle=True, validation_data=(x_test, x_test))

decoded_imgs = autoencoder.predict(x_test)

n = 10
plt.figure(figsize=(20, 4))
for i in range(n):
    ax = plt.subplot(2, n, i + 1)
    plt.imshow(x_test[i].reshape(28, 28), cmap='gray')
    ax.axis('off')
    ax = plt.subplot(2, n, i + 1 + n)
    plt.imshow(decoded_imgs[i].reshape(28, 28), cmap='gray')
    ax.axis('off')
plt.savefig("conv_autoencoder_result.png")
```

2. Run the convolutional autoencoder.

```bash
python3 conv_autoencoder.py
```

After 50 epochs, the model will generate:

```bash
conv_autoencoder_result.png
```

This shows original and reconstructed digits using convolutional filters.

![](https://www.atlantic.net/wp-content/uploads/2025/08/conv_autoencoder_result.png)

## Step 7: Build a Denoising Autoencoder

The Denoising Autoencoder learns to reconstruct clean images from noisy input. It’s especially useful when working with real-world images that may be corrupted, blurred, or degraded.

In this section, we’ll artificially add Gaussian noise to the MNIST dataset and train the model to remove it.

1. Create a new Python script.

```bash
nano denoising_autoencoder.py
```

Add the following code.

```bash
import numpy as np
import matplotlib.pyplot as plt
import tensorflow as tf
from load_mnist import load_data

(x_train, _), (x_test, _) = load_data()
x_train = x_train.astype('float32') / 255.
x_test = x_test.astype('float32') / 255.
x_train = np.reshape(x_train, (len(x_train), 28, 28, 1))
x_test = np.reshape(x_test, (len(x_test), 28, 28, 1))

noise_factor = 0.5
x_train_noisy = np.clip(x_train + noise_factor * np.random.normal(size=x_train.shape), 0., 1.)
x_test_noisy = np.clip(x_test + noise_factor * np.random.normal(size=x_test.shape), 0., 1.)

input_img = tf.keras.layers.Input(shape=(28, 28, 1))
x = tf.keras.layers.Conv2D(32, (3, 3), activation='relu', padding='same')(input_img)
x = tf.keras.layers.MaxPooling2D((2, 2), padding='same')(x)
x = tf.keras.layers.Conv2D(32, (3, 3), activation='relu', padding='same')(x)
x = tf.keras.layers.MaxPooling2D((2, 2), padding='same')(x)
x = tf.keras.layers.Conv2D(32, (3, 3), activation='relu', padding='same')(x)
x = tf.keras.layers.UpSampling2D((2, 2))(x)
x = tf.keras.layers.Conv2D(32, (3, 3), activation='relu', padding='same')(x)
x = tf.keras.layers.UpSampling2D((2, 2))(x)
decoded = tf.keras.layers.Conv2D(1, (3, 3), activation='sigmoid', padding='same')(x)

autoencoder = tf.keras.models.Model(input_img, decoded)
autoencoder.compile(optimizer='adadelta', loss='binary_crossentropy')
autoencoder.fit(x_train_noisy, x_train, epochs=100, batch_size=128, shuffle=True, validation_data=(x_test_noisy, x_test))

decoded_imgs = autoencoder.predict(x_test_noisy)

n = 10
plt.figure(figsize=(20, 4))
for i in range(n):
    ax = plt.subplot(2, n, i + 1)
    plt.imshow(x_test_noisy[i].reshape(28, 28), cmap='gray')
    ax.axis('off')
    ax = plt.subplot(2, n, i + 1 + n)
    plt.imshow(decoded_imgs[i].reshape(28, 28), cmap='gray')
    ax.axis('off')
plt.savefig("denoising_autoencoder_result.png")
```

2. Run the denoising autoencoder.

```bash
python3 denoising_autoencoder.py
```

After training completes, the result will be saved to.

```bash
denoising_autoencoder_result.png
```

This image will show the original noisy input on the top row and the clean, denoised output on the bottom.

![](https://www.atlantic.net/wp-content/uploads/2025/08/denoising_autoencoder_result.png)

## Conclusion

In this tutorial, you built and tested five different types of autoencoders using Keras on an Ubuntu 24.04 GPU server. You started with a simple architecture, then explored sparse, deep, convolutional, and denoising autoencoders.

Each model helped you learn a new approach to image compression and reconstruction using neural networks. You also visualized the output of each model to compare how well it learned to recreate the MNIST digits.


---

# How to Train Transformers for Time Series Forecasting on a Ubuntu 24.04 GPU Server

> URL: https://www.atlantic.net/gpu-server-hosting/how-to-train-transformers-for-time-series-forecasting-on-a-ubuntu-24-04-gpu-server/ | Published: 2025-09-26 | Updated: 2026-05-04 | Author: Hitesh Jethva

Time series forecasting has countless applications, from predicting stock prices to anticipating energy demand. In this tutorial, you’ll learn how to train a Transformer model to forecast daily temperatures using weather data on an Ubuntu 24.04 GPU server. Transformers, originally designed for natural language processing, have proven to be powerful for sequential data tasks, including time series prediction.

## Prerequisites

- An Ubuntu 24.04 server with an NVIDIA GPU.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1 – Set Up the Python Environment

We’ll begin by preparing a clean Python environment for our project. This ensures all dependencies are isolated and avoids conflicts with other packages on your system.

1. First, install Python, venv, pip, and Git.

```bash
apt install -y python3 python3-venv python3-pip git
```

2. Next, create a dedicated virtual environment for the Transformer weather forecasting project.

```bash
python3 -m venv weather-transformer-env
source weather-transformer-env/bin/activate
```

3. Upgrade pip inside the environment to avoid installation issues.

```bash
pip install --upgrade pip
```

4. Now install PyTorch with CUDA 12.1 support for GPU acceleration, along with other required packages.

```bash
pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu121
pip install transformers datasets scikit-learn matplotlib pandas
```

5. Finally, verify that your GPU is accessible to PyTorch.

```bash
python3 -c "import torch; print(torch.cuda.is_available())"
```

If everything is set up correctly, you should see.

```bash
True
```

This means your GPU is ready for training the Transformer model.

## Step 2 – Prepare a Weather Dataset

Before training the Transformer model, we need time series data. In this example, we’ll generate a synthetic weather dataset that simulates 2,000 days of daily temperature readings. This lets you focus on building and training the model without having to source and clean real-world data first.

1. Create a new file called prepare_weather_data.py.

```bash
nano prepare_weather_data.py
```

Add the below code.

```bash
import pandas as pd
import numpy as np

# Generate synthetic daily temperature data
np.random.seed(42)
dates = pd.date_range(start="2015-01-01", periods=2000)
temperatures = 20 + 10 * np.sin(np.linspace(0, 20, 2000)) + np.random.randn(2000) * 2

df = pd.DataFrame({"date": dates, "temperature": temperatures})
df.to_csv("weather_data.csv", index=False)
print("Weather dataset saved as weather_data.csv")
```

This script:

- Creates a date range starting from January 1, 2015.
- Uses a sine wave with added noise to mimic seasonal temperature variations.
- Stores the result in a CSV file called **weather_data.csv.**

2. Run the script.

```bash
python3 prepare_weather_data.py
```

At this point, you have a complete CSV file ready for loading into PyTorch. Later, you can easily swap this with real weather data from sources like NOAA or Meteostat by keeping the same column structure.

## Step 3 – Build a PyTorch Dataset for Sliding Windows

Our Transformer model needs sequential input. For time series forecasting, this means feeding it a fixed-length window of past temperature readings and asking it to predict the next value.

We’ll create a custom PyTorch Dataset that takes a sequence length and returns (input_window, target_value) pairs.

1. Create a file named **dataset_loader.py.**

```bash
nano dataset_loader.py
```

Add the following code.

```bash
import torch
import pandas as pd
from torch.utils.data import Dataset

class WeatherDataset(Dataset):
    def __init__(self, series, seq_length=30):
        self.seq_length = seq_length
        self.series = torch.tensor(series, dtype=torch.float32)

    def __len__(self):
        return len(self.series) - self.seq_length

    def __getitem__(self, idx):
        return (
            self.series[idx:idx + self.seq_length],
            self.series[idx + self.seq_length]
        )

if __name__ == "__main__":
    df = pd.read_csv("weather_data.csv")
    dataset = WeatherDataset(df["temperature"].values)
    print("Sample Input:", dataset[0][0])
    print("Sample Target:", dataset[0][1])
```

2. Run the script.

```bash
python3 dataset_loader.py
```

You should see.

```bash
Sample Input: tensor([20.9934, 19.8235, 21.4955, 23.3462, 19.9318, 20.0318, 23.7584, 22.2346,
        19.8606, 21.9844, 20.0720, 20.1669, 21.6816, 17.4704, 17.9463, 20.3705,
        19.5683, 22.3212, 19.9751, 19.0649, 24.9190, 21.6341, 22.3184, 19.4314,
        21.2894, 22.6971, 20.2701, 23.4200, 21.5636, 22.2775])
Sample Target: tensor(21.7532)
```

Now the dataset is ready to feed into the Transformer model during training.

## Step 4 – Define a Lightweight Transformer Model

With the dataset ready, we can design a Transformer-based neural network to handle our time series forecasting task. Transformers excel at capturing long-range dependencies, which makes them a strong choice for sequential data like weather patterns.

Create a file named **transformer_model.py.**

```bash
nano transformer_model.py
```

Add the following code.

```bash
import torch
import torch.nn as nn

class TransformerWeatherForecast(nn.Module):
    def __init__(self, seq_length=30, d_model=64, nhead=4, num_layers=3):
        super().__init__()
        self.input_proj = nn.Linear(1, d_model)
        encoder_layer = nn.TransformerEncoderLayer(d_model=d_model, nhead=nhead, batch_first=True)
        self.transformer_encoder = nn.TransformerEncoder(encoder_layer, num_layers=num_layers)
        self.fc_out = nn.Linear(d_model, 1)

    def forward(self, x):
        x = x.unsqueeze(-1)  # [batch, seq_len, 1]
        x = self.input_proj(x)
        x = self.transformer_encoder(x)
        out = self.fc_out(x[:, -1, :])
        return out
```

This PyTorch model, TransformerWeatherForecast, uses a Transformer encoder to learn temporal patterns in time series data. It projects input values to a higher dimension, processes them with multi-head attention, and outputs a prediction from the last time step.

## Step 5 – Train the Model

Now that we have both the dataset and model, we can train the Transformer to predict the next day’s temperature from the previous 30 days.

1. Create a file named train.py.

```bash
nano train.py
```

Add the following code.

```bash
import torch
import torch.nn as nn
from torch.utils.data import DataLoader, random_split
import pandas as pd
from dataset_loader import WeatherDataset
from transformer_model import TransformerWeatherForecast

# Hyperparameters
SEQ_LENGTH = 30
BATCH_SIZE = 32
EPOCHS = 20
LR = 0.001

# Load dataset
df = pd.read_csv("weather_data.csv")
dataset = WeatherDataset(df["temperature"].values, seq_length=SEQ_LENGTH)

# Train-test split
train_size = int(len(dataset) * 0.8)
test_size = len(dataset) - train_size
train_ds, test_ds = random_split(dataset, [train_size, test_size])

train_loader = DataLoader(train_ds, batch_size=BATCH_SIZE, shuffle=True)
test_loader = DataLoader(test_ds, batch_size=BATCH_SIZE)

# Model
device = torch.device("cuda" if torch.cuda.is_available() else "cpu")
model = TransformerWeatherForecast(seq_length=SEQ_LENGTH).to(device)

# Loss & optimizer
criterion = nn.MSELoss()
optimizer = torch.optim.Adam(model.parameters(), lr=LR)

# Training loop
for epoch in range(EPOCHS):
    model.train()
    total_loss = 0
    for x, y in train_loader:
        x, y = x.to(device), y.to(device)
        optimizer.zero_grad()
        output = model(x)
        loss = criterion(output.squeeze(), y)
        loss.backward()
        optimizer.step()
        total_loss += loss.item()

    print(f"Epoch [{epoch+1}/{EPOCHS}], Loss: {total_loss/len(train_loader):.4f}")

# Save model
torch.save(model.state_dict(), "transformer_weather_forecast.pth")
print("Model saved as transformer_weather_forecast.pth")
```

This code trains a Transformer-based model for weather temperature forecasting:

- **Imports libraries & modules** – Uses PyTorch, pandas, and custom WeatherDataset & TransformerWeatherForecast.
- **Sets hyperparameters** – Defines sequence length, batch size, epochs, and learning rate.
- **Loads and prepares data** – Reads temperature data from weather_data.csv and creates a dataset of input sequences.
- **Splits dataset** – Uses 80% for training and 20% for testing with PyTorch DataLoader.
- **Initializes model** – Loads the Transformer model on GPU if available.
- **Defines** **loss & optimizer** – Uses Mean Squared Error (MSE) loss and Adam optimizer.
- **Training loop** – Iterates over epochs, performs forward/backward passes, updates weights, and logs loss.
- **Saves the model** – Stores the trained weights as transformer_weather_forecast.pth.

2. Run the training script.

```bash
python3 train.py
```

Output.

```bash
Epoch [1/20], Loss: 259.9079
Epoch [2/20], Loss: 159.8631
Epoch [3/20], Loss: 92.6229
Epoch [4/20], Loss: 62.2326
Epoch [5/20], Loss: 54.8255
Epoch [6/20], Loss: 55.8948
Epoch [7/20], Loss: 54.4462
Epoch [8/20], Loss: 53.6575
Epoch [9/20], Loss: 54.1364
Epoch [10/20], Loss: 53.8897
Epoch [11/20], Loss: 54.0865
Epoch [12/20], Loss: 53.5845
Epoch [13/20], Loss: 53.2018
Epoch [14/20], Loss: 54.0120
Epoch [15/20], Loss: 53.6179
Epoch [16/20], Loss: 54.2151
Epoch [17/20], Loss: 54.2123
Epoch [18/20], Loss: 53.6800
Epoch [19/20], Loss: 51.3220
Epoch [20/20], Loss: 54.1718
Model saved as transformer_weather_forecast.pth
```

You’ll notice the loss drops significantly in the first few epochs, then stabilizes. This is a good sign that the model is learning the temperature patterns.

## Step 6 – Evaluate Quick Predictions

After training, it’s time to check how well the model performs on unseen data. We’ll load the saved weights and run predictions for a few sequences from the dataset.

1. Create a file named evaluate.py.

```bash
nano evaluate.py
```

Add the following code.

```bash
import torch
from torch.utils.data import DataLoader
import pandas as pd
from dataset_loader import WeatherDataset
from transformer_model import TransformerWeatherForecast

SEQ_LENGTH = 30
df = pd.read_csv("weather_data.csv")
dataset = WeatherDataset(df["temperature"].values, seq_length=SEQ_LENGTH)
loader = DataLoader(dataset, batch_size=1)

device = torch.device("cuda" if torch.cuda.is_available() else "cpu")
model = TransformerWeatherForecast(seq_length=SEQ_LENGTH).to(device)
model.load_state_dict(torch.load("transformer_weather_forecast.pth"))
model.eval()

with torch.no_grad():
    for i, (x, y) in enumerate(loader):
        x, y = x.to(device), y.to(device)
        pred = model(x)
        print(f"Actual: {y.item():.2f}°C, Predicted: {pred.item():.2f}°C")
        if i == 10:
            break
```

2. Run the evaluation script.

```bash
python3 evaluate.py
```

Output.

```bash
Actual: 21.75°C, Predicted: 21.09°C
Actual: 26.76°C, Predicted: 21.09°C
Actual: 23.12°C, Predicted: 21.09°C
Actual: 21.13°C, Predicted: 21.09°C
Actual: 24.98°C, Predicted: 21.09°C
Actual: 20.99°C, Predicted: 21.09°C
Actual: 23.94°C, Predicted: 21.09°C
Actual: 19.70°C, Predicted: 21.09°C
Actual: 21.05°C, Predicted: 21.09°C
Actual: 24.20°C, Predicted: 21.09°C
Actual: 25.37°C, Predicted: 21.09°C
```

Here, the model is producing consistent predictions around **21.09°C,** which indicates it has learned a general mean trend but not yet captured more variation.

## Conclusion

In this tutorial, you learned how to build, train, and evaluate a Transformer model for time series forecasting using PyTorch on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). We walked through setting up the environment, generating a synthetic weather dataset, creating a custom PyTorch Dataset for sliding windows, defining a lightweight Transformer architecture, training it with GPU acceleration, and evaluating its predictions.


---

# How to Train CLIP Models on a Ubuntu 24.04 GPU Server for Image-Text Matching

> URL: https://www.atlantic.net/gpu-server-hosting/how-to-train-clip-models-on-a-ubuntu-24-04-gpu-server-for-image-text-matching/ | Published: 2025-09-27 | Updated: 2026-05-04 | Author: Hitesh Jethva

Imagine typing **“a cat on a windowsill”** and instantly finding the exact picture you had in mind, no manual tagging, no tedious searching. That’s the power of CLIP (Contrastive Language–Image Pretraining). Developed by OpenAI, CLIP learns to understand the relationship between images and text by mapping them into the same vector space.

In this tutorial, you’ll learn how to train a CLIP model on an Ubuntu 24.04 GPU server for image–text matching. We’ll fine-tune the model with your own dataset, use GPU acceleration for faster training, and test it with real examples.

## Prerequisites

- An Ubuntu 24.04 server with an NVIDIA GPU.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1 – Install and Set Up CLIP

Before training CLIP, you need to set up the environment on your Ubuntu 24.04 GPU server. This section gives you a fast, copy-paste setup so you can start right away.

1. Install system dependencies.

```bash
apt install -y python3 python3-venv python3-pip git wget unzip
```

2. Create and activate a virtual environment.

```bash
python3 -m venv clip-env
source clip-env/bin/activate
```

3. Upgrade pip to the latest version.

```bash
pip install --upgrade pip
```

4. Install PyTorch with CUDA support.

```bash
pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu121
```

5. Install CLIP dependencies.

```bash
pip install ftfy regex tqdm
pip install git+https://github.com/openai/CLIP.git
```

6. Verify GPU access.

```bash
python3 -c "import torch; print(torch.cuda.is_available())"
```

If everything is set up correctly, you’ll see.

```bash
True
```

Your GPU server is now ready for training CLIP. Next, we’ll prepare a dataset for image–text matching so the model has something to learn from.

## Step 2 – Prepare the Dataset for CLIP Image-Text Matching

CLIP learns by pairing images with their matching text descriptions. You’ll need to organize your dataset so it’s easy to load during training.

1. Create dataset folders.

```bash
mkdir dataset/images
```

2. Create a captions file.

```bash
nano dataset/captions.txt
```

Add your image–caption pairs in the format.

```bash
img1.png|A cat sitting on a windowsill.
img2.png|A man riding a bicycle on the street.
```

3. Download some images to the images directory.

```bash
wget https://i.ibb.co/TM1bCfq8/img1.png -O dataset/images/
wget https://i.ibb.co/43YsGnq/img2.png -O dataset/images/
wget https://i.ibb.co/prv23zKw/test.jpg -O dataset/images/
```

## Step 3 – Create the CLIP Training Script in Python

With your dataset ready, it’s time to write the Python script that will train CLIP on your images and captions.

1. Create the training script file.

```bash
nano train_clip.py
```

Add the following code.

```bash
# train_clip.py
import os
import math
from pathlib import Path
from contextlib import nullcontext

import torch
import torch.nn as nn
import torch.optim as optim
from PIL import Image
from torch.utils.data import Dataset, DataLoader
import clip

# -----------------------
# Config
# -----------------------
IMAGE_DIR = "dataset/images"
CAP_PATH = "dataset/captions.txt"
BATCH_SIZE = 16
EPOCHS = 5
LR = 5e-6
NUM_WORKERS = 2                     # match system suggestion to avoid stalls
CKPT_DIR = Path("checkpoints")
CKPT_DIR.mkdir(exist_ok=True)
FINAL_WEIGHTS = "clip_finetuned.pt"

# -----------------------
# Dataset
# -----------------------
class ImageTextDataset(Dataset):
    def __init__(self, image_folder, captions_file, preprocess):
        self.image_folder = image_folder
        self.preprocess = preprocess
        self.data = []
        with open(captions_file, "r", encoding="utf-8") as f:
            for line in f:
                line = line.strip()
                if not line or "|" not in line:
                    continue
                img, caption = line.split("|", 1)
                self.data.append((img, caption))

    def __len__(self):
        return len(self.data)

    def __getitem__(self, idx):
        img_name, caption = self.data[idx]
        img_path = os.path.join(self.image_folder, img_name)
        image = self.preprocess(Image.open(img_path).convert("RGB"))
        return image, caption

# -----------------------
# Model / Device
# -----------------------
device = "cuda" if torch.cuda.is_available() else "cpu"
model, preprocess = clip.load("ViT-B/32", device=device)

# Use FP32 master params for optimizer stability; AMP will handle compute casting
model = model.float()
model.train()

# -----------------------
# Data
# -----------------------
dataset = ImageTextDataset(IMAGE_DIR, CAP_PATH, preprocess)
loader = DataLoader(
    dataset,
    batch_size=BATCH_SIZE,
    shuffle=True,
    num_workers=NUM_WORKERS,
    pin_memory=(device == "cuda"),
    persistent_workers=(NUM_WORKERS > 0)
)

# -----------------------
# Optimizer / Loss
# -----------------------
optimizer = optim.AdamW(model.parameters(), lr=LR)
loss_img = nn.CrossEntropyLoss()
loss_txt = nn.CrossEntropyLoss()

# -----------------------
# AMP (new API)
# -----------------------
if device == "cuda":
    autocast = lambda: torch.amp.autocast("cuda", dtype=torch.float16)
    scaler = torch.amp.GradScaler("cuda")
else:
    autocast = nullcontext
    scaler = None

# -----------------------
# Train Loop
# -----------------------
def run_epoch(epoch_idx: int):
    running = 0.0
    steps_per_epoch = math.ceil(len(dataset) / BATCH_SIZE)

    for step, (images, captions) in enumerate(loader, start=1):
        images = images.to(device, non_blocking=True)
        tokens = clip.tokenize(captions, truncate=True).to(device, non_blocking=True)

        with autocast():
            img_features = model.encode_image(images)
            txt_features = model.encode_text(tokens)

            # Normalize to unit length
            img_features = img_features / img_features.norm(dim=1, keepdim=True)
            txt_features = txt_features / txt_features.norm(dim=1, keepdim=True)

            # Similarity logits
            logits_per_image = img_features @ txt_features.t()
            logits_per_text  = txt_features @ img_features.t()

            # Contrastive targets
            ground_truth = torch.arange(len(images), device=device)
            total_loss = (loss_img(logits_per_image, ground_truth) +
                          loss_txt(logits_per_text,  ground_truth)) / 2

        optimizer.zero_grad(set_to_none=True)

        if scaler:
            scaler.scale(total_loss).backward()
            scaler.step(optimizer)
            scaler.update()
        else:
            total_loss.backward()
            optimizer.step()

        running += total_loss.item()
        if step % 10 == 0 or step == steps_per_epoch:
            avg = running / step
            print(f"Epoch {epoch_idx+1} Step {step}/{steps_per_epoch} - Loss: {avg:.4f}")

    # Save per-epoch checkpoint (state_dict only)
    ckpt_path = CKPT_DIR / f"epoch_{epoch_idx+1}.pt"
    torch.save(model.state_dict(), ckpt_path)
    print(f"Saved checkpoint: {ckpt_path}")

# -----------------------
# Execute Training
# -----------------------
for epoch in range(EPOCHS):
    run_epoch(epoch)

# Save final fine-tuned weights (state_dict only)
torch.save(model.state_dict(), FINAL_WEIGHTS)
print(f"Saved final weights to {FINAL_WEIGHTS}")
```

This script fine-tunes the CLIP ViT-B/32 model on a custom image–captions dataset:

- **Configuration** – Sets dataset paths, hyperparameters (batch size, epochs, learning rate), checkpoint directory, and output model filename.
- **Dataset Class** – Loads images and matching captions from a text file, applies CLIP preprocessing, and returns (image, caption) pairs.
- **Model Setup** – Loads CLIP on GPU (if available), switches to training mode, and prepares FP32 weights for stability.
- **DataLoader** – Creates a shuffled, multi-worker loader with pinned memory for faster GPU transfer.
- **Optimizer** **& Loss** – Uses AdamW optimizer and cross-entropy loss for both image-to-text and text-to-image similarity.
- **Mixed Precision Training (AMP)** – Speeds up training and reduces memory usage with half-precision on CUDA.
- **Training Loop** – Encodes images and captions, normalizes embeddings, computes similarity logits, calculates contrastive loss, and updates weights using AMP if available.
- **Checkpointing** – Saves model weights after each epoch and stores the final fine-tuned weights.

2. Run the training script.

```bash
python3 train_clip.py
```

Output.

```bash
Epoch 1 Step 1/1 - Loss: 0.6165
Saved checkpoint: checkpoints/epoch_1.pt
Epoch 2 Step 1/1 - Loss: 0.5577
Saved checkpoint: checkpoints/epoch_2.pt
Epoch 3 Step 1/1 - Loss: 0.4955
Saved checkpoint: checkpoints/epoch_3.pt
Epoch 4 Step 1/1 - Loss: 0.4474
Saved checkpoint: checkpoints/epoch_4.pt
Epoch 5 Step 1/1 - Loss: 0.4056
Saved checkpoint: checkpoints/epoch_5.pt
Saved final weights to clip_finetuned.pt
```

Now you have a fine-tuned CLIP model and saved checkpoints for each training stage. Next, we’ll verify the dataset integrity before training so you can avoid runtime errors.

## Step 4 – Verify Dataset Integrity Before Training

Before you start training, it’s smart to check if your dataset is complete and correctly formatted. This quick check prevents wasted GPU time due to missing images or broken captions.

1. Create the dataset check script.

```bash
nano check_dataset.py
```

Add the following code.

```bash
from pathlib import Path
n = sum(1 for _ in open("dataset/captions.txt", "r", encoding="utf-8")
        if "|" in _.strip())
print("Pairs:", n)
print("Images folder exists:", Path("dataset/images").exists())
```

2. Run the check.

```bash
python3 check_dataset.py
```

Output.

```bash
Pairs: 2
Images folder exists: True
```

If the number of pairs matches your expectation and the image folder exists, your dataset is ready for CLIP training.

## Step 5 – Test the Fine-Tuned CLIP Model for Image-Text Matching

After training, you can load the fine-tuned weights and test how well CLIP matches images to text. This helps confirm that your model learned from the dataset.

1. Create the inference script.

```bash
nano test_clip_inference.py
```

Add the below code.

```bash
import torch, clip
from PIL import Image
from pathlib import Path

device = "cuda" if torch.cuda.is_available() else "cpu"
model, preprocess = clip.load("ViT-B/32", device=device)

weights_path = Path("clip_finetuned.pt")
if weights_path.exists():
    try:
        # Safer: only tensors, no arbitrary objects
        state = torch.load(weights_path, map_location=device, weights_only=True)
        missing, unexpected = model.load_state_dict(state, strict=False)
        print(f"Loaded fine-tuned weights from {weights_path}")
        if missing:
            print(f"Missing keys: {missing}")
        if unexpected:
            print(f"Unexpected keys: {unexpected}")
    except Exception as e:
        print(f"Could not load fine-tuned weights safely: {e}\nUsing base CLIP.")
else:
    print("No fine-tuned weights found; using base CLIP.")

image = preprocess(Image.open("test.jpg")).unsqueeze(0).to(device)
text = clip.tokenize(["A beautiful beach sunset", "A crowded city street"]).to(device)

with torch.no_grad():
    image_features = model.encode_image(image)
    text_features = model.encode_text(text)
    probs = (image_features @ text_features.T).softmax(dim=-1)

print("Probabilities:", probs.squeeze().tolist())
```

2. Run the script.

```bash
python3 test_clip_inference.py
```

Output.

```bash
Loaded fine-tuned weights from clip_finetuned.pt
Probabilities: [0.9970703125, 0.0031719207763671875]
```

In this example, the model is almost sure that the image matches the first caption. This confirms your fine-tuned CLIP works for image–text matching.

## Conclusion

Training a CLIP model on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/) gives you the ability to connect images and text in powerful ways. In this guide, you set up a GPU-ready environment, prepared a dataset of image–captions pairs, built a Python training script, enabled mixed precision for faster performance, saved checkpoints, and tested a fine-tuned model with real captions.


---

# How to Use Apache Arrow with GPU for Faster Data Loading on Ubuntu 24.04 Server

> URL: https://www.atlantic.net/gpu-server-hosting/how-to-use-apache-arrow-with-gpu-for-faster-data-loading-on-ubuntu-24-04-server/ | Published: 2025-09-28 | Updated: 2026-05-04 | Author: Hitesh Jethva

Moving data to the GPU is often the bottleneck, not your kernels. Apache Arrow addresses a significant limitation by providing a fast, columnar memory format that integrates seamlessly with GPU analytics. In this guide, you’ll set up an Ubuntu 24.04 server, generate tens of millions of rows in Parquet, and load them straight into the GPU with RAPIDS cuDF. You’ll also learn when to keep working on CPU and when to hand it off to the GPU for real wins.

## Prerequisites

- An Ubuntu 24.04 server with an NVIDIA GPU with 8 GB GPU memory.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1 – Set Up the Python Environment

We’ll create a dedicated Python virtual environment so GPU libraries and dependencies stay clean and isolated from your system packages.

1. Install required build tools and Python venv.

```bash
apt install -y python3-venv build-essential
```

2. Create and activate a virtual environment.

```bash
python3 -m venv arrow-gpu
source arrow-gpu/bin/activate
```

3. Upgrade pip and wheel inside the venv.

```bash
python3 -m pip install --upgrade pip wheel
```

4. Install PyArrow for working with Arrow and Parquet formats.

```bash
pip install pyarrow
```

5. Install the GPU-accelerated RAPIDS libraries.

```bash
pip install cudf-cu12 rmm-cu12 --extra-index-url https://pypi.nvidia.com
```

6. Finally, add CuPy for low-level GPU array operations.

```bash
pip install cupy-cuda12x
```

7. To confirm everything is installed correctly and that Python can see your GPU, run.

```bash
python - <<'PY'
import pyarrow as pa, pyarrow.parquet as pq
import cudf, cupy, rmm
print("PyArrow:", pa.__version__)
print("cuDF:", cudf.__version__)
print("CuPy:", cupy.__version__)
PY
```

Output.

```bash
PyArrow: 19.0.1
cuDF: 25.08.00
CuPy: 13.5.1
```

If you see the expected versions without errors, you’re ready to start creating and loading data.

## Step 2 – Generate a Large Parquet File

To see real performance differences between CPU and GPU reads, we’ll first create a large dataset stored in Parquet format. This will give us enough rows to make the GPU useful and highlight the benefits of columnar storage.

1. Create a file named **make_parquet.py.**

```bash
nano make_parquet.py
```

Add the following code.

```bash
# make_parquet.py
import os, numpy as np
import pyarrow as pa
import pyarrow.parquet as pq

N = int(os.environ.get("N_ROWS", "20_000_000"))  # 20M rows
OUT = "demo.parquet"

def build_table(n):
    arrays = {
        "id": pa.array(np.arange(n, dtype=np.int64)),
        "x": pa.array(np.random.randn(n).astype("float32")),
        "y": pa.array(np.random.randn(n).astype("float32")),
        "label": pa.array(np.random.randint(0, 10, size=n, dtype=np.int8)),
    }
    return pa.table(arrays)

if not os.path.exists(OUT):
    tbl = build_table(N)
    pq.write_table(
        tbl, OUT,
        compression="zstd",            # good speed/ratio balance
        write_statistics=True,         # enables predicate pushdown
        data_page_size=1<<20,          # 1 MB pages
        row_group_size=1<<27           # ~134M rows? No — PyArrow interprets as bytes if writing by size
    )
    # If your PyArrow version expects row group size in rows, replace with e.g., row_group_size=5_000_000
    print("Wrote", OUT)
else:
    print(OUT, "already exists")
```

2. Run the script.

```bash
python3 make_parquet.py
```

Output.

```bash
Wrote demo.parquet
```

## Step 3 – CPU vs GPU Read Benchmark

With our 20M-row Parquet file ready, we can measure how long it takes to load into memory using:

- pandas with PyArrow (CPU only)
- cuDF (directly into GPU memory)

This test will help you see where the GPU can save time and where it may not offer much benefit for simple reads.

Create a file named **bench_parquet.py.**

```bash
nano bench_parquet.py
```

Add the following code.

```bash
# bench_parquet.py
import time, pandas as pd, cudf

FILE = "demo.parquet"

def timeit(fn, label):
    t0 = time.perf_counter()
    _ = fn()
    dt = time.perf_counter() - t0
    print(f"{label}: {dt:.2f}s")

def cpu_pandas():
    return pd.read_parquet(FILE, engine="pyarrow")

def gpu_cudf():
    return cudf.read_parquet(FILE)  # directly to GPU

if __name__ == "__main__":
    timeit(cpu_pandas, "CPU pandas read_parquet")
    timeit(gpu_cudf,  "GPU cuDF   read_parquet")
```

Run the script.

```bash
python3 bench_parquet.py
```

Output.

```bash
CPU pandas read_parquet: 0.65s
GPU cuDF   read_parquet: 0.93s
```

In this case, the GPU read is slightly slower. That’s because:

We only read a single file.

The dataset is large, but the GPU still needs to transfer data from CPU to device memory. There’s little computation after the load, so I/O and PCIe transfer time dominate.

Next, we’ll split our dataset into shards to prepare for faster streaming and parallel processing on the GPU.

## Step 4 – Write Many Smaller Parquet Shards (Parallelism-Friendly)

Single big files are easy, but shards are faster to move and process in parallel. We’ll slice the dataset into 10 Parquet files of 2M rows each. This helps with multi-process loaders, overlapping I/O with compute, and better GPU memory utilization.

1. Create **make_shards.py.**

```bash
nano make_shards.py
```

Add the below code.

```bash
# make_shards.py
import os, numpy as np, pyarrow as pa, pyarrow.parquet as pq
os.makedirs("parquet_shards", exist_ok=True)

rows_per = 2_000_000
shards = 10
for i in range(shards):
    start = i * rows_per
    arrays = {
        "id": pa.array(np.arange(start, start + rows_per, dtype=np.int64)),
        "val": pa.array(np.random.randn(rows_per).astype("float32")),
        "bucket": pa.array(np.random.randint(0, 32, size=rows_per, dtype=np.int16)),
    }
    tbl = pa.table(arrays)
    pq.write_table(
        tbl,
        f"parquet_shards/part-{i:02d}.parquet",
        compression="zstd",
        write_statistics=True,
    )
print("Shards ready")
```

2. Run the script.

```bash
python3 make_shards.py
```

Output.

```bash
Shards ready
```

**Why this helps:**

- **Parallel reads:** Multiple workers (or Dask-cuDF) can pull different shards at once.
- **Better caching:** Smaller files improve locality and reduce re-reads.
- **Controlled memory:** You can size shards/row groups to fit GPU memory (e.g., 128–512 MB row groups).

Next, we’ll stream these shards directly into the GPU and run a quick aggregation to measure end-to-end throughput.

## Step 5 – Stream Shards Directly to GPU & Aggregate

Now let’s read the shard files straight into GPU memory and perform a small aggregation to simulate “real work” after I/O. We’ll compute the mean of val grouped by bucket per shard and time the whole pipeline.

1. Create **stream_to_gpu.py.**

```bash
nano stream_to_gpu.py
```

Add the below code.

```bash
# stream_to_gpu.py
import glob, cudf, time

files = sorted(glob.glob("parquet_shards/*.parquet"))

t0 = time.perf_counter()
total = 0
for path in files:
    gdf = cudf.read_parquet(path)           # GPU DataFrame
    # Example GPU work: quick groupby
    agg = gdf.groupby("bucket").val.mean()
    total += len(gdf)
dt = time.perf_counter() - t0
print(f"Processed {total} rows from {len(files)} files in {dt:.2f}s")
```

2. Run the script.

```bash
python3 stream_to_gpu.py
```

Output.

```bash
Processed 20000000 rows from 10 files in 1.49s
```

**What this shows:**

- **I/O** **+** **compute pipeline:** We’re not just timing reads; we’re timing a GPU aggregation too, which is where the GPU starts to shine.
- **Shard wins:** Multiple smaller files reduce latency and make it easier to scale with more workers or Dask-cuDF.

Next, we’ll convert Arrow (host) → cuDF (device) to move CPU-built Arrow tables directly into GPU memory.

## Step 6 – Convert Arrow (Host) → cuDF (Device)

Sometimes you prepare data on the CPU (ETL, joins with CPU-only sources) and then hand it off to the GPU for fast analytics. With Arrow, that handoff is simple: build an Arrow Table in host memory and create a cuDF DataFrame on the device in one step.

1. Create **arrow_to_cudf.py.**

```bash
nano arrow_to_cudf.py
```

Add the following code.

```bash
import numpy as np
import pyarrow as pa
import cudf

# Build a CPU Arrow table (host memory)
tbl = pa.table({
    "a": np.arange(1_000_000, dtype=np.int32),
    "b": np.random.randn(1_000_000).astype("float32"),
})

# Copy host→device and create a GPU DataFrame
gdf = cudf.DataFrame.from_arrow(tbl)

print("Rows on GPU:", len(gdf))
print("dtypes:", dict(zip(gdf.columns, map(str, gdf.dtypes))))
print("head():")
print(gdf.head())
```

2. Run the script.

```bash
python3 arrow_to_cudf.py
```

Output.

```bash
Rows on GPU: 1000000
dtypes: {'a': 'int32', 'b': 'float32'}
head():
   a         b
0  0 -2.701743
1  1  0.692678
2  2 -0.638901
3  3  0.102307
4  4  0.323030
```

**Why this matters:**

- **Zero fuss interop:** Arrow’s columnar layout maps cleanly to cuDF.
- **Controlled dtypes:** Set NumPy dtypes up front (e.g., int32, float32) to match GPU-friendly types and avoid casts.
- **Clear boundary:** Do CPU-bound prep where it’s convenient, then switch to GPU when it pays off.

Next, we’ll do the reverse: convert cuDF (device) → Arrow (host) for when you need to export data or pass it to CPU-only libraries.

## Step 7 – Convert cuDF (Device) → Arrow (Host)

There are times when you’ve done heavy GPU processing but need to move the results back to the CPU, maybe for exporting to disk, handing off to a CPU-based library, or sending data over a network. With cuDF, you can easily convert a GPU DataFrame into an Apache Arrow Table in host memory.

1. Create **cudf_to_arrow.py.**

```bash
nano cudf_to_arrow.py
```

Add the following code.

```bash
import cudf

# Build a GPU DataFrame
gdf = cudf.DataFrame({
    "x": cudf.Series(range(10_000_0)),  # 100k rows
    "y": cudf.Series(range(10_000_0)) * 2
})

# Copy device→host into an Arrow table
tbl = gdf.to_arrow()

print("Rows on CPU as Arrow:", tbl.num_rows)
print("Schema:", tbl.schema)
print("first 5 as pandas (CPU):")
print(tbl.to_pandas().head())
```

2. Run the script.

```bash
python3 cudf_to_arrow.py
```

Output.

```bash
Rows on CPU as Arrow: 100000
Schema: x: int64
y: int64
-- schema metadata --
pandas: '{"index_columns": [{"kind": "range", "name": null, "start": 0, "' + 462
first 5 as pandas (CPU):
   x  y
0  0  0
1  1  2
2  2  4
3  3  6
4  4  8
```

**Why this is useful:**

- **Exporting data:** Easily write Arrow tables to Parquet, Feather, or IPC for storage or sharing.
- **CPU-only workflows:** Hand off data to pandas, scikit-learn, or other CPU-based systems.
- **Interoperability:** Arrow format is supported across many languages (C++, Rust, R, Java).

## Conclusion

By combining Apache Arrow with [GPU acceleration](https://www.atlantic.net/gpu-server-hosting/ai-accelerator-vs-gpu-5-key-differences-and-how-to-choose/) via cuDF, you can move large datasets from disk to device memory much faster and with less friction. In this guide, you set up a clean Python environment on Ubuntu 24.04, generated massive Parquet datasets, and compared CPU vs GPU read speeds. You also learned how to split data into shards for parallel processing, stream those shards directly into GPU memory, and seamlessly convert between Arrow tables on the CPU and cuDF DataFrames on the GPU.


---

# Atlantic.Net Expands Cloud Services Provider Team to Fuel Global Growth Amid Rising AI Demand

> URL: https://www.atlantic.net/press-releases/atlantic-net-expands-cloud-services-provider-team-to-fuel-global-growth-amid-rising-ai-demand/ | Published: 2025-09-29 | Updated: 2025-09-30 | Author: Editorial Team

**ORLANDO, FL** (September 29, 2025) — Atlantic.Net, a leading global cloud services provider that delivers innovative and reliable hosting solutions, today announced the appointment of three executive-level professionals who bring decades of industry experience to its global team.

As the industry races toward AI-driven infrastructure, GPU optimization and global scalability, these Atlantic.Net  strategic hires are expected to greatly drive the company’s growth and expand its market presence:

- **Drew Adams**, Vice President of Sales Strategy and Development, brings over 20 years of experience in the IaaS and hosting industry that spans sales, management, operations, and innovation.
- **Kevin Boyle**, Director of Customer Success and Account Management, has over 20 years of experience in IT data center infrastructure, including dedicated servers, colocation, and bare metal cloud, with a strong focus on sales, customer success, and building long-term partnerships.
- **Robert Wright**, Senior Account Executive, brings nearly two decades of dedicated server, cloud, and colocation sales and customer relationship excellence.

“These professionals join us at an important stage in our continued growth,” said Marty Puranik, founder and CEO of Atlantic.Net, who remains focused on staying adaptable and forward-thinking. “They’ve come on board not only because of what we’ve accomplished in 30+ years, but because they believe in where we’re headed.”

The key appointments of Adams, Boyle and Wright are already sparking conversations across the industry, and their vision, experience, and energy will initially be focused on helping expand Atlantic.Net’s AI and GPU services portfolio, accelerating international sales and partnerships, and deepening customer relationships with a human-first approach.

In May 2025, [Atlantic.Net](https://www.atlantic.net) introduced its latest innovation: GPU Cloud Hosting. The services enable users to deploy a GPU Cloud server in fewer than 60 seconds, as well as GPU Dedicated Hosts and GPU Bare Metal Servers. These services deliver high-performance, cost-effective AI and ML (machine learning) platforms designed for businesses, developers, and researchers.

**About Atlantic.Net**

Established in 1994, Atlantic.Net is a privately owned global cloud services provider that delivers innovative and reliable hosting solutions. Focusing on security, compliance and customer support, Atlantic.Net offers a wide range of services, including GPU hosting, an award-winning Cloud Platform, HIPAA-compliant hosting, PCI hosting, bare metal hosting, dedicated hosting and colocation to a large roster of organizations in a variety of industries. Atlantic.Net provides mission-critical services from eight global data center regions located in the United States, Canada, the United Kingdom and Asia. For more information, visit Atlantic.Net or connect with us on Facebook, X (Twitter), LinkedIn and YouTube.

Contact Atlantic.Net Public Relations:

[pr@atlantic.net](mailto:pr@atlantic.net)


---

# How to Profile and Debug GPU Performance for Machine Learning Models on Ubuntu 24.04 GPU Server

> URL: https://www.atlantic.net/gpu-server-hosting/how-to-profile-and-debug-gpu-performance-for-machine-learning-models-on-ubuntu-24-04-gpu-server/ | Published: 2025-09-29 | Updated: 2026-05-04 | Author: Hitesh Jethva

When you train machine learning models on a GPU, raw power alone doesn’t guarantee fast results. Poor kernel execution, inefficient memory usage, or unnecessary CPU-GPU synchronization can significantly slow down the process, sometimes by minutes or even hours per epoch. This is where GPU profiling comes in.

By profiling and debugging GPU performance, you can pinpoint bottlenecks, optimize memory usage, and understand exactly how your training code interacts with the hardware.

In this guide, you’ll learn how to set up a profiling environment, run targeted profiling sessions, monitor GPU usage in real time, and interpret reports. We’ll work through a small CNN training example so you can replicate the process on your own server and apply it to larger models.

## Prerequisites

- An Ubuntu 24.04 server equipped with an NVIDIA GPU that has at least 8 GB of memory.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1 – Installing Required GPU Profiling Tools

Before we can analyze GPU performance, we need to install a few essential tools. These include NVIDIA’s Nsight Systems for timeline analysis, Nsight Compute for kernel-level profiling, and nvtop for real-time GPU monitoring.

1. Install Python and required dependencies.

```bash
apt install -y python3 python3-venv python3-pip git
```

2. Install NVIDIA profiling tools.

```bash
apt install nsight-compute nsight-systems nvtop
```

3. Reload your shell environment to ensure the profiling tools are in your PATH.

```bash
source ~/.bashrc
```

4. Verify NCU version.

```bash
ncu --version
```

Output.

```bash
NVIDIA (R) Nsight Compute Command Line Profiler
Copyright (c) 2018-2024 NVIDIA Corporation
Version 2025.1.0.0 (build 35237751) (public-release)
```

5. Verify the nsys version.

```bash
nsys --version
```

Output.

```bash
NVIDIA Nsight Systems version 2024.6.2.225-246235244400v0
```

## Step 2 – Setting Up the Python Environment

To keep things organized and avoid package conflicts, we’ll create a dedicated Python virtual environment for our GPU profiling work.

1. Create a dedicated working directory for profiling experiments.

```bash
mkdir -p ~/gpu-profiling && cd ~/gpu-profiling
```

2. Create and activate the virtual environment.

```bash
python3 -m venv venv
source venv/bin/activate
```

3. Upgrade pip inside the virtual environment.

```bash
pip install --upgrade pip
```

4. Next, install PyTorch, torchvision, and torchaudio with CUDA 12 support.

```bash
pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu121
```

5. Once the installation completes, verify that PyTorch detects your GPU.

```bash
python - <<'PY'
import torch
print("CUDA available:", torch.cuda.is_available())
if torch.cuda.is_available():
    print("Device:", torch.cuda.get_device_name(0))
    print("CUDA capability:", torch.cuda.get_device_capability(0))
PY
```

Output.

```bash
CUDA available: True
Device: NVIDIA A40-16Q
CUDA capability: (8, 6)
```

6. Update your environment variables to include CUDA and Nsight tools in our PATH.

```bash
export PATH=/usr/local/cuda-12.8/bin:/opt/nvidia/nsight-compute:$PATH
```

## Step 3 – Preparing a Sample Training Script for Profiling

To demonstrate GPU profiling, we’ll use a small CNN model with a synthetic dataset. This setup ensures that GPU activity is consistent and easy to interpret in profiling tools, without being slowed down by disk I/O or complex data processing.

1. Create a training script.

```bash
nano train.py
```

Add the following code.

```bash
import os
import time
import argparse
from contextlib import nullcontext

import torch
import torch.nn as nn
import torch.optim as optim
from torch.utils.data import DataLoader, Dataset
from torch.cuda import nvtx

# ---- Synthetic dataset to drive GPU compute ----
class SyntheticImages(Dataset):
    def __init__(self, n=50000, c=3, h=224, w=224):
        self.n, self.c, self.h, self.w = n, c, h, w
    def __len__(self):
        return self.n
    def __getitem__(self, idx):
        x = torch.randn(self.c, self.h, self.w)  # random image
        y = torch.randint(0, 1000, (1,)).item()  # 1000-class label
        return x, y

# ---- Small-ish CNN to keep kernels visible but fast ----
class SmallCNN(nn.Module):
    def __init__(self, num_classes=1000):
        super().__init__()
        self.net = nn.Sequential(
            nn.Conv2d(3, 32, 3, stride=2, padding=1),
            nn.ReLU(inplace=True),
            nn.Conv2d(32, 64, 3, stride=2, padding=1),
            nn.ReLU(inplace=True),
            nn.Conv2d(64, 128, 3, stride=2, padding=1),
            nn.ReLU(inplace=True),
            nn.AdaptiveAvgPool2d((1, 1))
        )
        self.fc = nn.Linear(128, num_classes)

    def forward(self, x):
        x = self.net(x)
        x = torch.flatten(x, 1)
        return self.fc(x)

def main():
    parser = argparse.ArgumentParser()
    parser.add_argument("--epochs", type=int, default=2)
    parser.add_argument("--batch-size", type=int, default=64)
    parser.add_argument("--workers", type=int, default=4)
    parser.add_argument("--amp", action="store_true", help="Use mixed precision")
    parser.add_argument("--profile", action="store_true", help="Write PyTorch profiler trace")
    parser.add_argument("--profile_dir", type=str, default="./tb_logs")
    args = parser.parse_args()

    device = "cuda" if torch.cuda.is_available() else "cpu"
    torch.backends.cudnn.benchmark = True

    # Data
    train_set = SyntheticImages()
    train_loader = DataLoader(
        train_set,
        batch_size=args.batch_size,
        shuffle=True,
        num_workers=args.workers,
        pin_memory=True
    )

    # Model/opt
    model = SmallCNN().to(device)
    criterion = nn.CrossEntropyLoss()
    optimizer = optim.Adam(model.parameters(), lr=3e-4)

    # AMP context
    amp_ctx = torch.autocast(device_type="cuda", dtype=torch.float16) if (args.amp and device == "cuda") else nullcontext()
    scaler = torch.cuda.amp.GradScaler(enabled=(args.amp and device == "cuda"))

    # Optional PyTorch profiler
    prof_ctx = nullcontext()
    if args.profile:
        from torch.profiler import profile, ProfilerActivity, tensorboard_trace_handler
        os.makedirs(args.profile_dir, exist_ok=True)
        prof_ctx = profile(
            activities=[ProfilerActivity.CPU, ProfilerActivity.CUDA],
            schedule=torch.profiler.schedule(wait=1, warmup=1, active=2, repeat=1),
            on_trace_ready=tensorboard_trace_handler(args.profile_dir),
            record_shapes=True,
            with_stack=True,
            with_flops=True,
            profile_memory=True
        )

    start = time.time()
    if args.profile:
        prof_ctx.__enter__()

    for epoch in range(args.epochs):
        nvtx.range_push(f"epoch_{epoch}")
        model.train()
        running_loss = 0.0
        for i, (x, y) in enumerate(train_loader):
            nvtx.range_push("batch")
            x = x.to(device, non_blocking=True)
            y = y.to(device, non_blocking=True)

            optimizer.zero_grad(set_to_none=True)
            with amp_ctx:
                out = model(x)
                loss = criterion(out, y)

            scaler.scale(loss).backward()
            scaler.step(optimizer)
            scaler.update()

            running_loss += loss.item()
            if args.profile:
                prof_ctx.step()
            nvtx.range_pop()  # batch

            # Keep runtime contained for profiling demos
            if i >= 100:   # ~101 batches per epoch
                break

        print(f"Epoch {epoch+1} | Loss: {running_loss/(i+1):.4f}")
        nvtx.range_pop()  # epoch

    if args.profile:
        prof_ctx.__exit__(None, None, None)

    dur = time.time() - start
    print(f"Total time: {dur:.2f}s")
    print(torch.cuda.memory_summary(device=device))

if __name__ == "__main__":
    main()
```

2. Run the training script.

```bash
python3 train.py --epochs 2 --batch-size 64 --workers 4 --amp
```

Output.

```bash
Epoch 1 | Loss: 6.9113
Epoch 2 | Loss: 6.9093
Total time: 6.24s
|===========================================================================|
|                  PyTorch CUDA memory summary, device ID 0                 |
|---------------------------------------------------------------------------|
|            CUDA OOMs: 0            |        cudaMalloc retries: 0         |
|===========================================================================|
|        Metric         | Cur Usage  | Peak Usage | Tot Alloc  | Tot Freed  |
|---------------------------------------------------------------------------|
| Allocated memory      |  57875 KiB | 379086 KiB | 146761 MiB | 146705 MiB |
|       from large pool |  54272 KiB | 377258 KiB | 145822 MiB | 145769 MiB |
|       from small pool |   3603 KiB |   4472 KiB |    939 MiB |    935 MiB |
|---------------------------------------------------------------------------|
| Active memory         |  57875 KiB | 379086 KiB | 146761 MiB | 146705 MiB |
|       from large pool |  54272 KiB | 377258 KiB | 145822 MiB | 145769 MiB |
|       from small pool |   3603 KiB |   4472 KiB |    939 MiB |    935 MiB |
|---------------------------------------------------------------------------|
| Requested memory      |  57870 KiB | 377033 KiB | 146492 MiB | 146435 MiB |
|       from large pool |  54272 KiB | 375210 KiB | 145555 MiB | 145502 MiB |
|       from small pool |   3598 KiB |   4466 KiB |    936 MiB |    933 MiB |
|---------------------------------------------------------------------------|
| GPU reserved memory   | 419840 KiB | 514048 KiB |   1440 MiB |   1030 MiB |
|       from large pool | 413696 KiB | 509952 KiB |   1434 MiB |   1030 MiB |
|       from small pool |   6144 KiB |   6144 KiB |      6 MiB |      0 MiB |
|---------------------------------------------------------------------------|
| Non-releasable memory |  62957 KiB | 140490 KiB |  64668 MiB |  64607 MiB |
|       from large pool |  60416 KiB | 137911 KiB |  63726 MiB |  63667 MiB |
|       from small pool |   2541 KiB |   3410 KiB |    942 MiB |    939 MiB |
|---------------------------------------------------------------------------|
| Allocations           |      40    |      49    |   15388    |   15348    |
|       from large pool |       3    |       9    |    3646    |    3643    |
|       from small pool |      37    |      46    |   11742    |   11705    |
|---------------------------------------------------------------------------|
| Active allocs         |      40    |      49    |   15388    |   15348    |
|       from large pool |       3    |       9    |    3646    |    3643    |
|       from small pool |      37    |      46    |   11742    |   11705    |
|---------------------------------------------------------------------------|
| GPU reserved segments |      10    |      11    |      24    |      14    |
|       from large pool |       7    |       9    |      21    |      14    |
|       from small pool |       3    |       3    |       3    |       0    |
|---------------------------------------------------------------------------|
| Non-releasable allocs |      16    |      19    |    8288    |    8272    |
|       from large pool |       3    |       8    |    2629    |    2626    |
|       from small pool |      13    |      16    |    5659    |    5646    |
|---------------------------------------------------------------------------|
| Oversize allocations  |       0    |       0    |       0    |       0    |
|---------------------------------------------------------------------------|
| Oversize GPU segments |       0    |       0    |       0    |       0    |
|===========================================================================|
```

This script is now ready for profiling; it contains NVTX markers for Nsight, an optional PyTorch profiler, and memory summary output for debugging allocations.

## Step 4 – Monitoring Real-Time GPU Usage

Before running deep profiling sessions, it’s useful to watch GPU usage in real time. This helps confirm that the GPU is being utilized as expected and can quickly reveal issues like low utilization, excessive memory use, or thermal throttling.

**1. Using nvidia-smi**
 The simplest tool is NVIDIA’s nvidia-smi, which comes with the GPU driver. Run.

```bash
watch -n 1 nvidia-smi
```

This command updates every second and shows:

- GPU utilization percentage
- Memory usage
- Temperature
- Running processes

**2. Using nvtop for Interactive Monitoring**
 **nvtop** is like htop but for GPUs. It provides a colorful, real-time display.

```bash
nvtop
```

With nvtop, you can:

- Monitor per-process GPU usage
- Track VRAM consumption over time
- See compute vs. memory utilization

**3. Using nvidia-smi dmon for Detailed Stats**
 For low-level telemetry such as power consumption and PCIe throughput, use.

```bash
nvidia-smi dmon -s pucvmt
```

This is helpful for detecting bottlenecks caused by thermal limits or power constraints.

## Step 5 – Profiling with Nsight Systems (nsys)

Nsight Systems is NVIDIA’s system-wide performance analysis tool. It helps visualize how your training code interacts with the CPU, GPU, and operating system, making it easier to spot bottlenecks in kernel launches, data loading, or synchronization.

1. Create a directory to save the report.

```bash
mkdir -p reports
```

2. Running an nsys profile for one epoch of our CNN training script to keep the report small.

```bash
nsys profile --trace=cuda,nvtx,osrt \
  -o reports/nsys_smoke \
  python3 train.py --epochs 1 --batch-size 64 --workers 4 --amp
```

3. After profiling, generate a summary.

```bash
nsys stats reports/nsys_smoke.nsys-rep \
  | tee reports/nsys_smoke_stats.txt
```

Output:

```bash
 Time (%)  Total Time (ns)  Instances     Avg (ns)         Med (ns)        Min (ns)       Max (ns)     StdDev (ns)    Style    Range  
 --------  ---------------  ---------  ---------------  ---------------  -------------  -------------  ------------  -------  --------
     70.2    3,687,984,904          1  3,687,984,904.0  3,687,984,904.0  3,687,984,904  3,687,984,904           0.0  PushPop  :epoch_0
     29.8    1,568,095,057        101     15,525,693.6      6,956,237.0      6,786,630    871,783,914  86,053,398.2  PushPop  :batch  

Processing [reports/nsys_smoke.sqlite] with [/opt/nvidia/nsight-systems/2024.6.2/host-linux-x64/reports/osrt_sum.py]... 

 ** OS Runtime Summary (osrt_sum):

 Time (%)  Total Time (ns)  Num Calls    Avg (ns)       Med (ns)     Min (ns)     Max (ns)      StdDev (ns)            Name         
 --------  ---------------  ---------  -------------  ------------  ----------  -------------  -------------  ----------------------
     35.8   16,379,720,411        207   79,129,084.1   3,912,872.0      26,329  1,892,649,216  342,138,838.6  pthread_cond_wait     
     31.4   14,374,694,895        125  114,997,559.2  98,891,000.0      28,279  1,153,881,169  182,208,818.2  sem_wait              
     16.3    7,478,573,597        174   42,980,308.0  13,189,978.0       1,542    763,891,502   72,151,566.3  poll                  
     10.0    4,557,471,910        759    6,004,574.3      27,657.0       1,302    502,654,188   54,197,437.6  pthread_cond_timedwait
      4.2    1,915,698,569         91   21,051,632.6  13,376,724.0   1,202,730    147,786,074   18,470,602.4  sem_clockwait         
      0.9      434,767,656      1,023      424,992.8      10,137.0       1,024    152,203,095    5,252,250.5  ioctl                 
      0.8      369,512,061      2,073      178,249.9       2,477.0       2,057      5,530,737      774,095.6  munmap                
      0.1       54,252,032          4   13,563,008.0  12,635,347.0  11,484,002     17,497,336    2,696,547.7  fork                  
      0.1       40,884,509      3,325       12,296.1       2,926.0       1,000      2,499,701       66,540.4  read                  
      0.1       36,920,409        921       40,087.3       5,218.0       1,077      3,357,386      288,751.3  pthread_cond_signal   
      0.1       26,573,233          2   13,286,616.5  13,286,616.5   1,785,896     24,787,337   16,264,474.9  pthread_rwlock_wrlock 
      0.0       19,158,656      9,863        1,942.5       1,682.0       1,000         23,503        1,120.4  stat64                
      0.0       15,520,576        108      143,709.0      15,325.0       1,013     11,797,602    1,138,827.1  pthread_mutex_lock    
      0.0       15,417,551     13,104        1,176.6       1,156.0       1,000         20,377          371.3  lstat64               
      0.0       10,395,002        937       11,093.9       3,281.0       1,003        436,038       27,260.8  write
```

## Step 6 – Profiling with Nsight Compute (ncu)

While Nsight Systems gives you a broad view of CPU => GPU interaction, Nsight Compute focuses on the low-level performance of individual CUDA kernels. It provides metrics such as warp execution efficiency, memory throughput, and bottleneck analysis.

1. Run a kernel-level profile using the speed-of-light preset to measure theoretical vs. achieved performance.

```bash
ncu --set speed-of-light \
    --target-processes application-only \
    --launch-skip 50 --launch-count 1 \
    --force-overwrite \
    --export reports/ncu_step \
    python3 -u train.py --epochs 1 --batch-size 64 --workers 0 --amp
```

Once the run completes, you’ll have a .ncu-rep file in the reports directory.

```bash
==PROF== Report: /root/gpu-profiling/reports/ncu_step.ncu-rep
```

**Explanation:**

- **–set speed-of-light** → capture a wide range of performance metrics.
- **–target-processes application-only** → avoid profiling system processes.
- **–launch-skip 50** → skip initial batches to focus on steady-state execution.
- **–launch-count 1** → profile only one kernel launch to keep reports small.
- **–export reports/ncu_step** → save results for later viewing in Nsight Compute GUI.

2. You can open and extract details directly from the report in the terminal.

```bash
ncu --import reports/ncu_step.ncu-rep --page summary
```

## Conclusion

Profiling and debugging GPU performance involves more than just running commands; it’s about understanding where your training workflow loses time and efficiency. On an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/), Nsight Systems gives you a high-level view of how your code interacts with the CPU, GPU, and operating system. At the same time, Nsight Compute lets you drill down to individual CUDA kernels to see how effectively they are using the hardware.


---

# How to Use TensorBoard to Monitor GPU Training Metrics in Real Time on Ubuntu 24.04 Server

> URL: https://www.atlantic.net/gpu-server-hosting/how-to-use-tensorboard-to-monitor-gpu-training-metrics-in-real-time-on-ubuntu-24-04-server/ | Published: 2025-09-30 | Updated: 2026-05-04 | Author: Hitesh Jethva

When you’re training deep learning models on a [GPU server](https://www.atlantic.net/gpu-server-hosting/), knowing what’s going on under the hood is just as important as writing the code. This is where TensorBoard comes in. It’s a powerful visualization tool that lets you monitor your training process in real time, right from your browser.

With TensorBoard, you can track training loss, GPU memory usage, and other performance metrics as your model learns. Instead of waiting until training is over to discover problems, you can spot issues like slow convergence, overfitting, or memory bottlenecks early on and make adjustments immediately.

In this guide, you’ll learn how to install TensorBoard on Ubuntu 24.04, integrate it with a PyTorch training script, and monitor your GPU metrics live.

## Prerequisites

- An Ubuntu 24.04 server with an NVIDIA GPU.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1 – Install Python and TensorBoard

The first step is to set up Python, a virtual environment, and the required packages for training and monitoring. This keeps your dependencies isolated and avoids version conflicts with system packages.

1. Install Python and additional dependencies.

```bash
apt install -y python3 python3-venv python3-pip git
```

2. Create a virtual environment.

```bash
python3 -m venv tb-env
source tb-env/bin/activate
```

3. Upgrade pip to the latest version.

```bash
pip install --upgrade pip
```

4. Install PyTorch, torchvision, torchaudio, and TensorBoard.

```bash
pip install torch torchvision torchaudio tensorboard
```

5. To confirm TensorBoard is installed correctly, check its version.

```bash
tensorboard --version
```

Output.

```bash
2.20.0
```

## Step 2 – Create a Training Script with TensorBoard Logging

Now that TensorBoard is installed, the next step is to integrate it into a PyTorch training loop so you can log metrics in real time.

We’ll create a file named train_with_tb.py and write a simple MNIST digit classification model. Along with tracking the training loss per batch, we’ll also log GPU memory usage in MB, which is especially useful when working on a GPU server.

```bash
nano train_with_tb.py
```

Add the following code.

```bash
import torch
from torch import nn, optim
from torch.utils.data import DataLoader
from torchvision import datasets, transforms
from torch.utils.tensorboard import SummaryWriter

# Initialize TensorBoard writer
writer = SummaryWriter(log_dir="./tb_logs")

# Dataset & loader
transform = transforms.ToTensor()
train_data = datasets.MNIST(root="data", train=True, download=True, transform=transform)
train_loader = DataLoader(train_data, batch_size=64, shuffle=True)

# Model, loss, optimizer
model = nn.Sequential(
    nn.Flatten(),
    nn.Linear(28*28, 128),
    nn.ReLU(),
    nn.Linear(128, 10)
).cuda()

criterion = nn.CrossEntropyLoss()
optimizer = optim.Adam(model.parameters(), lr=0.001)

# Training loop
global_step = 0
for epoch in range(3):
    total_loss = 0
    for batch_idx, (data, target) in enumerate(train_loader):
        data, target = data.cuda(), target.cuda()
        
        optimizer.zero_grad()
        output = model(data)
        loss = criterion(output, target)
        loss.backward()
        optimizer.step()
        
        total_loss += loss.item()

        # Log loss per batch
        writer.add_scalar("Loss/train", loss.item(), global_step)

        # Log GPU memory usage in MB per batch
        gpu_mem = torch.cuda.memory_allocated() / (1024 ** 2)
        writer.add_scalar("GPU/Memory_MB", gpu_mem, global_step)

        global_step += 1
    
    avg_loss = total_loss / len(train_loader)
    print(f"Epoch {epoch+1}, Average Loss: {avg_loss:.4f}")

writer.close()
```

Now, run the training script.

```bash
python3 train_with_tb.py
```

Output.

```bash
100.0%
100.0%
100.0%
100.0%
Epoch 1, Loss: 0.3434
Epoch 2, Loss: 0.1530
Epoch 3, Loss: 0.1066
```

## Step 3 – Launch TensorBoard to View GPU Metrics

1. Once training is complete (or even while it’s still running), you can launch TensorBoard to visualize the logged data.

```bash
tensorboard --logdir ./tb_logs --port 6006 --host 0.0.0.0
```

Note:

- `--logdir ./tb_logs`: Points TensorBoard to the directory where you saved your logs.
- `--port 6006`: Specifies the network port to serve the dashboard on (6006 is the default).
- `--host 0.0.0.0`: Makes TensorBoard listen on all network interfaces, allowing you to connect to it from your local machine using the server’s public IP address.”

Output.

```bash
TensorBoard 2.20.0 at http://0.0.0.0:6006/ (Press CTRL+C to quit)
```

2. Now, you can access the TensorBoard web interface using the URL **http://your-server-ip:6006** from your browser to visualize your training metrics.

Note: Before you can access the dashboard, you may need to open port 6006 in your server’s firewall. For example, on Ubuntu using UFW (Uncomplicated Firewall), you would run:”

```
sudo ufw allow 6006/tcp
```

![](https://www.atlantic.net/wp-content/uploads/2025/08/p1-2.png)

This chart displays the GPU memory usage in megabytes (MB) throughout training.

3. Click on the **SCALARS** tab, and you should see the graph below.

![](https://www.atlantic.net/wp-content/uploads/2025/08/p2-1.png)

The above graph shows the model’s loss decreasing from around 0.4 to 0.1 over training steps, with expected batch-to-batch fluctuations, indicating steady learning and convergence, while a flat or rising curve would signal poor training requiring parameter or architecture changes.

## Conclusion

Using TensorBoard on Ubuntu 24.04 gives you a clear, real-time view of your model’s training progress and GPU usage without guesswork. By logging metrics like training loss and GPU memory consumption, you can quickly identify whether your model is converging, detect inefficiencies, and make informed adjustments during training.


---

# Create an Account - Dedicated Hosting

> URL: https://www.atlantic.net/dedicated-server-hosting/create-an-account/ | Updated: 2026-09-16

## Create a Dedicated Hosting Account

After you create an account, we will contact you to activate it. Please share your server details and requirements.

**If you need assistance, please call us at [866-618-3282](tel:+18666183282)**


---

# How to Train OpenCLIP Models on a Ubuntu 24.04 GPU Server

> URL: https://www.atlantic.net/gpu-server-hosting/how-to-train-openclip-models-on-a-ubuntu-24-04-gpu-server/ | Published: 2025-10-01 | Author: Hitesh Jethva

OpenCLIP is an open-source implementation of the CLIP (Contrastive Language–Image Pretraining) model, designed to align images and text in a shared embedding space. It enables powerful image–text search, classification, and retrieval capabilities, making it a go-to choice for vision-language applications.

In this guide, you’ll learn how to set up, train, and evaluate OpenCLIP models on a Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/) using the COCO dataset.

## Prerequisites

- An Ubuntu 24.04 server with an NVIDIA GPU with 8 GB GPU memory.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1 – Set Up Python Virtual Environment

To keep your OpenCLIP setup clean and isolated from other Python projects, it’s best to use a virtual environment. We’ll also install the system tools and Python packages needed for GPU-accelerated training.

1. Install system dependencies.

```bash
apt install -y python3 python3-venv python3-pip git wget unzip
```

2. Create a virtual environment.

```bash
python3 -m venv openclip-env
```

3. Activate the virtual environment.

```bash
source openclip-env/bin/activate
```

4. Upgrade pip to the latest version.

```bash
pip install --upgrade pip
```

5. Next, install the GPU-compatible version of PyTorch, TorchVision, and TorchAudio.

```bash
pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu121
```

6. After installation, verify that your GPU is accessible.

```bash
python3 -c "import torch; print(torch.cuda.is_available())"
```

Output.

```bash
True
```

7. Install OpenCLIP and the COCO helpers.

```bash
pip install open_clip_torch pycocotools
```

## Step 2 – Download and Prepare the COCO Dataset

You’ll train on COCO’s 2017 split. Create a dataset folder, download the images and annotations, and extract them.

1. Create a dataset directory and navigate inside it.

```bash
mkdir datasets && cd datasets
```

2. Download COCO train images and annotations.

```bash
wget http://images.cocodataset.org/zips/train2017.zip
wget http://images.cocodataset.org/annotations/annotations_trainval2017.zip
```

3. Unzip archives.

```bash
unzip train2017.zip
unzip annotations_trainval2017.zip
```

4. Go back to the project root.

```bash
cd ..
```

## Step 3 – Create a Training Script

You’ll write a single, production-ready script that can run on one or many GPUs, train OpenCLIP on COCO captions, and save the best checkpoint.

1. Create a training script.

```bash
nano train_openclip.py
```

Add the below code.

```bash
#!/usr/bin/env python3
# train_openclip.py
import os
import math
import time
import random
import argparse
from pathlib import Path

import torch
import torch.distributed as dist
from torch.utils.data import DataLoader, Dataset
from torch.utils.data.distributed import DistributedSampler
from torchvision import datasets
import open_clip


# -------------------- DDP helpers --------------------
def is_dist():
    return dist.is_available() and dist.is_initialized()

def get_rank():
    return dist.get_rank() if is_dist() else 0

def get_world_size():
    return dist.get_world_size() if is_dist() else 1

def barrier():
    if is_dist():
        dist.barrier()

def setup_ddp():
    # torchrun sets these
    if "RANK" in os.environ and "WORLD_SIZE" in os.environ:
        dist.init_process_group(backend="nccl", init_method="env://")
        torch.cuda.set_device(int(os.environ.get("LOCAL_RANK", 0)))

def cleanup_ddp():
    if is_dist():
        dist.destroy_process_group()

def seed_everything(seed: int):
    random.seed(seed)
    torch.manual_seed(seed)
    torch.cuda.manual_seed_all(seed)
    torch.backends.cudnn.benchmark = True  # speed on CNN-like preprocess


# -------------------- COCO wrapper --------------------
class CocoRandomCaption(Dataset):
    """Returns (image, one_random_caption_string) per sample."""
    def __init__(self, root, ann_file, transform):
        self.ds = datasets.CocoCaptions(root=root, annFile=ann_file, transform=transform)

    def __len__(self):
        return len(self.ds)

    def __getitem__(self, idx):
        img, captions = self.ds[idx]  # list[str]
        cap = random.choice(captions)
        return img, cap


# -------------------- Output normalizer --------------------
def unpack_clip_outputs(out):
    """
    Normalize different OpenCLIP forward() return formats.
    Returns (logits_per_image, logits_per_text).
    """
    # Tuple/list variants
    if isinstance(out, (tuple, list)):
        if len(out) >= 2:
            return out[0], out[1]
        raise ValueError(f"Unexpected tuple length from model(): {len(out)}")
    # Dict variants
    if isinstance(out, dict):
        lpi = out.get("logits_per_image") or out.get("image_logits")
        lpt = out.get("logits_per_text") or out.get("text_logits")
        if lpi is None or lpt is None:
            raise ValueError(f"Dict output missing logits keys: {list(out.keys())}")
        return lpi, lpt
    raise ValueError(f"Unexpected output type from model(): {type(out)}")


# -------------------- One epoch --------------------
def train_one_epoch(model, optimizer, dataloader, tokenizer, device, scaler, use_amp, epoch, total_epochs):
    model.train()
    loss_img = torch.nn.CrossEntropyLoss()
    loss_txt = torch.nn.CrossEntropyLoss()

    running_loss = torch.zeros([], device=device)
    num_batches = len(dataloader)
    start = time.time()

    for step, (images, captions) in enumerate(dataloader):
        images = images.to(device, non_blocking=True)
        texts = tokenizer(list(captions)).to(device, non_blocking=True)

        optimizer.zero_grad(set_to_none=True)
        gt = torch.arange(images.shape[0], device=device, dtype=torch.long)

        with torch.amp.autocast('cuda', enabled=use_amp):
            out = model(images, texts)
            logits_per_image, logits_per_text = unpack_clip_outputs(out)
            loss = (loss_img(logits_per_image, gt) + loss_txt(logits_per_text, gt)) * 0.5

        if use_amp:
            scaler.scale(loss).backward()
            scaler.step(optimizer)
            scaler.update()
        else:
            loss.backward()
            optimizer.step()

        running_loss += loss.detach()

        if get_rank() == 0 and (step + 1) % 50 == 0:
            pct = 100.0 * (step + 1) / max(1, num_batches)
            elapsed = time.time() - start
            print(f"[Epoch {epoch+1}/{total_epochs}] {step+1}/{num_batches} "
                  f"({pct:5.1f}%) loss={loss.item():.4f} elapsed={elapsed:.1f}s", flush=True)

    # Reduce across workers
    if is_dist():
        dist.all_reduce(running_loss, op=dist.ReduceOp.SUM)

    mean_loss = (running_loss / (num_batches * get_world_size())).item()
    return mean_loss


# -------------------- Main --------------------
def main():
    ap = argparse.ArgumentParser("Train OpenCLIP on COCO (Ubuntu 24.04, single or multi-GPU)")
    ap.add_argument("--train-images", type=str, default="datasets/train2017",
                    help="Path to COCO train2017 images dir")
    ap.add_argument("--train-ann", type=str, default="datasets/annotations/captions_train2017.json",
                    help="Path to COCO train captions json")
    ap.add_argument("--model", type=str, default="ViT-B-32", help="OpenCLIP model name, e.g., ViT-B-32, ViT-L-14")
    ap.add_argument("--pretrained", type=str, default="laion2b_s34b_b79k", help="Pretrained weights tag")
    ap.add_argument("--batch-size", type=int, default=64, help="Per-GPU batch size")
    ap.add_argument("--epochs", type=int, default=5)
    ap.add_argument("--lr", type=float, default=5e-6)
    ap.add_argument("--weight-decay", type=float, default=0.01)
    ap.add_argument("--workers", type=int, default=4)
    ap.add_argument("--amp", action="store_true", help="Use mixed precision")
    ap.add_argument("--compile", action="store_true", help="torch.compile the model (PyTorch 2.x)")
    ap.add_argument("--save-dir", type=str, default="runs/openclip_coco", help="Checkpoint directory")
    ap.add_argument("--seed", type=int, default=42)
    args = ap.parse_args()

    # DDP
    setup_ddp()
    local_rank = int(os.environ.get("LOCAL_RANK", 0))
    device = torch.device(f"cuda:{local_rank}" if torch.cuda.is_available() else "cpu")
    if get_rank() == 0:
        print(f"World size: {get_world_size()}, device: {device}", flush=True)

    seed_everything(args.seed)

    # Model + preprocess + tokenizer
    model, _, preprocess = open_clip.create_model_and_transforms(
        args.model, pretrained=args.pretrained
    )
    tokenizer = open_clip.get_tokenizer(args.model)
    model = model.to(device)

    if args.compile:
        try:
            model = torch.compile(model)
            if get_rank() == 0:
                print("Compiled model with torch.compile()", flush=True)
        except Exception as e:
            if get_rank() == 0:
                print(f"torch.compile failed, proceeding uncompiled: {e}", flush=True)

    # Data
    ds = CocoRandomCaption(root=args.train_images, ann_file=args.train_ann, transform=preprocess)
    if is_dist():
        sampler = DistributedSampler(ds, shuffle=True)
        shuffle = False
    else:
        sampler = None
        shuffle = True

    dl = DataLoader(
        ds,
        batch_size=args.batch_size,
        shuffle=shuffle,
        sampler=sampler,
        num_workers=args.workers,
        pin_memory=True,
        drop_last=True,
        persistent_workers=args.workers > 0
    )

    # Optimizer
    optimizer = torch.optim.AdamW(model.parameters(), lr=args.lr, weight_decay=args.weight_decay)

    # AMP scaler (new API)
    scaler = torch.amp.GradScaler('cuda', enabled=args.amp)

    # Train
    Path(args.save_dir).mkdir(parents=True, exist_ok=True)
    best_loss = math.inf

    for epoch in range(args.epochs):
        if is_dist():
            dl.sampler.set_epoch(epoch)

        epoch_loss = train_one_epoch(
            model=model,
            optimizer=optimizer,
            dataloader=dl,
            tokenizer=tokenizer,
            device=device,
            scaler=scaler,
            use_amp=args.amp,
            epoch=epoch,
            total_epochs=args.epochs
        )

        if get_rank() == 0:
            print(f"Epoch {epoch+1}/{args.epochs} - mean loss: {epoch_loss:.4f}", flush=True)
            # Save epoch checkpoint
            ckpt = {
                "model": model.state_dict(),
                "args": vars(args),
                "epoch": epoch + 1,
                "loss": epoch_loss,
            }
            ep_path = Path(args.save_dir) / f"epoch_{epoch+1:03d}.pt"
            torch.save(ckpt, ep_path)
            # Save best
            if epoch_loss < best_loss: best_loss = epoch_loss best_path = Path(args.save_dir) / "best.pt" torch.save(ckpt, best_path) print(f"Saved new best -> {best_path}", flush=True)

        barrier()

    cleanup_ddp()
    if get_rank() == 0:
        print("Training complete.", flush=True)


if __name__ == "__main__":
    main()
```

2. Run the script.

```bash
python3 train_openclip.py
```

You’ll see periodic step logs and an epoch summary. Checkpoints are saved in **runs/openclip_coco/,** with **the best results****.pt** updated when the mean loss improves.

```bash
Saved new best -> runs/openclip_coco/best.pt
Training complete.
```

That’s it, your script is now ready for robust, scalable OpenCLIP training on Ubuntu 24.04. The next section will use the saved checkpoint to evaluate image–text retrieval quality.

## Step 4 – Evaluate the Model

With best.pt saved, let’s score your fine-tuned OpenCLIP on custom images and natural-language prompts. You’ll use **evaluate_openclip.py** to compute cosine similarities between image and text embeddings and then print the top matches.

```bash
nano evaluate_openclip.py
```

Add the following code.

```bash
#!/usr/bin/env python3
# evaluate_openclip.py
import os
import argparse
from pathlib import Path
from typing import List

import torch
from PIL import Image
import open_clip


def load_image_paths(path_str: str) -> List[Path]:
    p = Path(path_str)
    if p.is_dir():
        exts = {".jpg", ".jpeg", ".png", ".bmp", ".webp"}
        return sorted([q for q in p.rglob("*") if q.suffix.lower() in exts])
    if p.is_file():
        return [p]
    raise FileNotFoundError(f"No such file or directory: {path_str}")

def load_prompts(inline: List[str], prompts_file: str | None) -> List[str]:
    if prompts_file:
        with open(prompts_file, "r", encoding="utf-8") as f:
            lines = [ln.strip() for ln in f.readlines()]
        return [x for x in lines if x]
    return inline

def main():
    ap = argparse.ArgumentParser("Evaluate a fine-tuned OpenCLIP checkpoint")
    ap.add_argument("--ckpt", type=str, default="runs/openclip_coco/best.pt",
                    help="Path to checkpoint: best.pt or epoch_XXX.pt")
    ap.add_argument("--model", type=str, default="ViT-B-32",
                    help="OpenCLIP model name, e.g., ViT-B-32, ViT-L-14")
    ap.add_argument("--base-pretrained", type=str, default=None,
                    help="Optional base weights tag (e.g., laion2b_s34b_b79k). "
                         "If omitted, start from random init before loading ckpt.")
    ap.add_argument("--images", type=str, required=True,
                    help="Image file or directory of images")
    ap.add_argument("--prompts", type=str, nargs="*", default=[],
                    help="Inline prompts, e.g. --prompts 'a cat' 'a dog'")
    ap.add_argument("--prompts-file", type=str, default=None,
                    help="Text file with one prompt per line")
    ap.add_argument("--batch-size", type=int, default=32)
    ap.add_argument("--amp", action="store_true", help="Use mixed precision for speed")
    args = ap.parse_args()

    device = torch.device("cuda" if torch.cuda.is_available() else "cpu")
    print(f"Using device: {device}")

    # Recreate model + preprocess pipeline
    model, _, preprocess = open_clip.create_model_and_transforms(
        args.model,
        pretrained=args.base-pretrained if args.base_pretrained else None
    )
    tokenizer = open_clip.get_tokenizer(args.model)
    model = model.to(device).eval()

    # Load fine-tuned weights
    ckpt = torch.load(args.ckpt, map_location="cpu")
    state = ckpt["model"] if isinstance(ckpt, dict) and "model" in ckpt else ckpt
    missing, unexpected = model.load_state_dict(state, strict=False)
    if missing or unexpected:
        print(f"Loaded with missing keys: {missing[:5]} ... total={len(missing)}")
        print(f"Loaded with unexpected keys: {unexpected[:5]} ... total={len(unexpected)}")

    # Collect images
    image_paths = load_image_paths(args.images)
    if not image_paths:
        raise SystemExit("No images found to evaluate.")

    # Collect prompts
    texts = load_prompts(args.prompts, args.prompts_file)
    if not texts:
        raise SystemExit("Provide prompts via --prompts or --prompts-file")

    # Encode all texts once
    with torch.no_grad(), torch.amp.autocast("cuda", enabled=args.amp):
        text_tokens = tokenizer(texts).to(device)
        text_feats = model.encode_text(text_tokens)
        text_feats = text_feats / text_feats.norm(dim=-1, keepdim=True)

    # Encode images in batches
    sims = []  # one similarity row per image
    batched_paths = []
    for i in range(0, len(image_paths), args.batch_size):
        batch_paths = image_paths[i:i + args.batch_size]
        images = []
        for p in batch_paths:
            img = Image.open(p).convert("RGB")
            images.append(preprocess(img))
        images = torch.stack(images, dim=0).to(device)

        with torch.no_grad(), torch.amp.autocast("cuda", enabled=args.amp):
            img_feats = model.encode_image(images)
            img_feats = img_feats / img_feats.norm(dim=-1, keepdim=True)
            # cosine similarity via dot product since both normalized
            # shape: [B, T]
            sim = img_feats @ text_feats.t()

        sims.append(sim.detach().cpu())
        batched_paths.extend(batch_paths)

    sims = torch.cat(sims, dim=0)  # [N_images, N_texts]

    # Report top-k
    k = min(5, len(texts))
    print("\nTop matches per image:")
    for row, path in zip(sims, batched_paths):
        topk = torch.topk(row, k=k)
        print(f"\nImage: {path}")
        for rank, (score, idx) in enumerate(zip(topk.values.tolist(), topk.indices.tolist()), start=1):
            print(f"  {rank}. {texts[idx]}  |  score={score:.4f}")

    # Also: best image for each prompt (text->image retrieval)
    print("\nBest image per prompt:")
    k2 = min(3, len(image_paths))
    sims_T = sims.t()  # [N_texts, N_images]
    for t_idx, t in enumerate(texts):
        topk = torch.topk(sims_T[t_idx], k=k2)
        print(f"\nPrompt: {t}")
        for rank, (score, idx) in enumerate(zip(topk.values.tolist(), topk.indices.tolist()), start=1):
            print(f"  {rank}. {image_paths[idx]}  |  score={score:.4f}")


if __name__ == "__main__":
    main()
```

Now, run the evaluation.

```bash
python3 evaluate_openclip.py \
  --ckpt runs/openclip_coco/best.pt \
  --model ViT-B-32 \
  --images datasets/train2017/000000000009.jpg \
  --prompts "a cat sitting on a bed" "a dog in the park" "a person riding a bike" \
  --amp
```

Output.

```
Image: datasets/train2017/000000000009.jpg
1. a cat sitting on a bed | score=0.4102
2. a person riding a bike | score=0.1987
3. a dog in the park | score=0.1855

Best image per prompt:

Prompt: a cat sitting on a bed
1. datasets/train2017/000000000009.jpg | score=0.7802

Prompt: a dog in the park
2. datasets/train2017/000000000009.jpg | score=0.1855

Prompt: a person riding a bike
3. datasets/train2017/000000000009.jpg | score=0.1987
```

The evaluation ran on the GPU, loaded the checkpoint without errors, and matched the image most strongly to “a cat sitting on a bed” with a score of 0.78. Both image => text and text => image retrieval confirmed that the fine-tuned model correctly aligned this prompt with the image.

## Conclusion

Training OpenCLIP on a Ubuntu 24.04 GPU server provides a fast and scalable way to fine-tune vision–language models for real-world tasks. In this guide, you set up the environment, prepared the COCO dataset, trained the model, and ran evaluations with custom prompts. With this workflow, you can now experiment with different architectures, datasets, and optimization techniques to adapt OpenCLIP for your projects.

```bash

```


---

# Top Backup Services in 2026: Discover the Best Options for Your Data Security

> URL: https://www.atlantic.net/managed-services/top-backup-services-in-2026-discover-the-best-options-for-your-data-security/ | Published: 2025-10-01 | Updated: 2026-07-23 | Author: Richard Bailey

The loss of critical data due to hardware failure, cyberattacks, human error, or natural disasters can result in catastrophic financial losses, reputational damage, and operational paralysis. Consequently, establishing a resilient backup strategy is not a discretionary IT expense but a foundational requirement for business continuity and long-term viability.

The market is saturated with a wide array of online backup service providers, each offering different features, security protocols, and pricing models. Navigating these options to find the optimal backup solution requires a clear understanding of your organization’s specific data protection needs.

This article provides an in-depth analysis of the top [backup services](https://www.atlantic.net/cloud-platform/backups/), examining the key players in the industry. We will explore the fundamental principles of data backup, evaluate the offerings of major providers, and provide the necessary information to help you select a service that ensures your data remains secure, available, and recoverable.

## The 3-2-1 Rule: A Proven Backup Strategy

Before we dive into providers, let’s talk strategy. The gold standard for data protection for years has been the 3-2-1 rule for backups. It’s a simple framework that builds layers of redundancy to protect you from any single point of failure.

Think of it as diversifying your data’s portfolio. You wouldn’t put all your money in one stock; the 3-2-1 rule applies that same logic to your most critical asset: information.

Here’s the breakdown:

- **Three copies** of your data. This means your live, production data plus two backups.
- **Two different media types.** Don’t save both backups on the same type of hard drive. Use a mix of internal drives, an external NAS (local backup), and, most importantly, cloud storage. This protects you if a specific type of hardware has a widespread failure.
- **One copy off-site.** This is the crucial step for disaster recovery. If your office has a fire or flood, your on-site backups are useless. An off-site copy, almost always handled by a cloud backup service, is physically isolated from any local disaster.

These simple rule are the foundation of any serious backup process, ensuring you’re prepared for anything from a single file deletion to the loss of an entire building.

## Why Choose a Cloud Backup Service?

While local backup to an external drive or on-premises server is a valid component of the 3-2-1 rule, relying on it exclusively presents significant limitations. On-site hardware requires capital expenditure, ongoing maintenance, and physical security, and it remains vulnerable to local disasters. This is where cloud backup solutions provide a superior alternative for the critical off-site copy.

A cloud backup service transfers a copy of your data over a secure internet connection to a provider’s off-site data servers. These services are managed by experts in highly secure and redundant data centers, providing a level of security and reliability that is difficult for most businesses to achieve on their own.

Key advantages include:

- **Disaster Recovery:** By storing data in a geographically distinct location, cloud backup is a great way to defend against localized events.
- **Scalability:** Cloud storage services allow you to scale your backup capacity up or down as needed without purchasing new hardware. You can have as much storage as your business requires.
- **Accessibility:** Data can be restored from anywhere with a broadband connection, which is critical for remote workforces and minimizing internet downtime.
- **Security:** Reputable providers offer robust data encryption both in transit and at rest. Many allow you to use a personal encryption key (also known as a private encryption key), ensuring that only *you*can decrypt your data. This means not even the service provider can access your files.

## A Review of the Top Backup Services

The market is crowded, but a few key players stand out by solving specific problems exceptionally well. Who makes the best backup depends entirely on what you need to protect.

### #1: [Atlantic.Net](https://www.atlantic.net/cloud-platform/backups/)

![](https://www.atlantic.net/wp-content/uploads/2025/10/Atlanticnetlogo.png)

For businesses in healthcare or finance, a data breach isn’t just an IT problem; it’s a potential legal nightmare. This is the specific challenge Atlantic.Net addresses. Instead of offering just a standalone online service or relying on third party services , they provide an integrated, secure cloud infrastructure where compliant backup and disaster recovery are core components.

Atlantic.Net focus heavily on the stringent requirements of regulations like HIPAA and PCI, making them the a great choice for organizations handling sensitive data. When the question is “what’s the safest place to back up your data?”, a provider that builds its entire environment around audited security and compliance is a compelling answer.

#### Key Features:

- Fully managed backup and disaster recovery services.
- Infrastructure engineered for security and compliance (HIPAA, PCI).
- High-performance, redundant data centers.
- Integrated ecosystem combining hosting, storage, and data protection

**Best For:** Businesses in regulated industries needing a secure, compliant, and managed cloud and backup infrastructure.

### #2: [Veeam](https://www.veeam.com/)

![](https://www.atlantic.net/wp-content/uploads/2025/10/Veeam_logo.png)

Walk into almost any data center running VMware or Hyper-V, and you’ll likely find Veeam. It became the de facto standard by deeply understanding the needs of virtualized environments long before others.

While many client backup software tools treated virtual machines like physical servers, Veeam built its platform to leverage the unique capabilities of virtualization. This results in incredibly fast, flexible, and reliable recovery of entire systems and applications, not just files

#### Key Features:

- Advanced backup, replication, and recovery for virtual machines.
- Deep integration with VMware and Microsoft Hyper-V.
- Powerful disaster recovery orchestration.
- Portability for multi-cloud and hybrid cloud environments.

**Best For:** Medium to large enterprises that rely heavily on a virtual cloud infrastructure.

### #3: [Acronis](https://www.acronis.com/en/#sp)

![](https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcQER8pxHAF2iWZSJeYbTLxZoTnjVEYtDBKjfw&s)

Acronis saw that ransomware was fundamentally changing the backup game. It was no longer enough to just back up data; you had to stop the attack in the first place. Their solution is a direct response to this threat, bundling active anti-malware and anti-ransomware tools directly with their backup client.

If it detects suspicious activity, it can shut down the process and automatically restore any affected files. This integrated approach simplifies security for businesses that lack a dedicated cybersecurity team.

#### Key Features:

- Integrated backup and cybersecurity features.
- Active protection against ransomware attacks.
- Support for physical servers, VMs, and multiple devices.
- Single management console for all protection tasks.

**Best For:** Organizations seeking a unified solution for both backup and endpoint security.

### #4: [Backblaze](https://www.backblaze.com/)

![](https://www.atlantic.net/wp-content/uploads/2025/10/Backblaze_Logo.svg_.png)

Backblaze’s philosophy is simple: make backup so easy you’ll actually do it. They stripped away complex options in favor of a one-click, “back up everything” approach for a single computer. Its client software is famously lightweight, running in the background without hogging resources.

For a flat fee, you get unlimited storage for one Mac or PC. The trade-off for this simplicity is a lack of advanced features for servers or complex systems, but for individuals and small businesses, it’s often the best online backup service for its sheer ease of use.

#### Key Features:

- Unlimited cloud backup storage for a single computer.
- Extremely simple setup and user interface.
- Option for a personal encryption key for enhanced privacy.
- Hard drive restore service (they ship you a drive).

**Best For:** Individuals and small businesses looking for a simple, set-and-forget backup solution.

### #5: [IDrive](https://www.idrive.com/)

![](https://www.atlantic.net/wp-content/uploads/2025/10/250px-IDrive_Inc._logo.png)

Most online services charge per device, which gets expensive fast for a family or a small team with multiple computers, laptops, and mobile devices. IDrive broke that model by letting you connect as many devices as you want to a single storage pool.

This versatility, including mobile backup options, makes it incredibly cost-effective. It also packs in a surprising number of power-user features, like server and database backups, and the ability to create a local backup to a mapped drive for a hybrid approach.

#### Key Features:

- Back up unlimited devices to one account.
- Supports server, database, and disk image backups.
- Strong security with a user-defined private encryption key option.
- Hybrid backup capabilities (cloud and local backup).

**Best For:** Users and businesses needing to protect multiple devices, including computers and laptops, under a single plan.

### #6: [Cohesity](https://www.cohesity.com/)

![](https://www.cohesity.com/content/dam/cohesity/live/cohesity-logo-black-green.svg)

Large companies don’t just have backup data; they have file shares, object stores, and test environments, all sitting in different silos. Cohesity’s big idea is to bring all that ‘secondary’ data together onto one platform.

This not only simplifies backup and recovery but also makes it easier to manage and even use for analytics or development. It’s a high-end backup solution designed to tackle data sprawl in complex enterprise environments.

#### Key Features:

- Unified platform for backup, file shares, and object storage.
- Massive scalability for large enterprise environments.
- Strong focus on compliance and data governance.
- Reduces data silos and simplifies IT management.

**Best For:** Large enterprises looking to modernize data management and consolidate secondary storage.

## Choosing the Right Service

A feature list only tells you part of the story. Selecting the best cloud backup provider involves understanding some critical trade-offs.

- **Security vs. Convenience:** Don’t just look for “encryption.” Ask if you can hold your own key (a private encryption key). If you can, not even the provider’s employees can see your files. The trade-off? If you lose that encryption key, your data is gone forever. It’s maximum security, but also maximum responsibility.
- **Cost vs. Predictability:** Pay close attention to pricing models. Per-gigabyte pricing from cloud storage services seems cheap but can spiral with large data sets. Per-device pricing, like Backblaze offers in its personal plan, is predictable but doesn’t work for servers. Review their business plans and estimate your data growth to avoid sticker shock.
- **Backup Speed vs. Recovery Speed**: Backing up is only half the battle. How quickly can you restore? A cloud download of terabytes over a standard broadband connection can take days. Some services offer physical drive shipping services for this exact reason. It is critical to test the restore process before you need it.

## Cloud Backup and Backup Software Explained

It is useful to distinguish between the two primary components of a backup system: the cloud backup service and the backup software.

The *cloud backup service* refers to the infrastructure provided by the company—the data centers, network equipment, servers, and online storage where your data is kept. This is the backend that ensures your data is secure, redundant, and available.

The *backup software*, often called the backup client or desktop app, is the application you install on your computers, servers, and other devices. This software is responsible for managing the backup process: identifying files for backup, compressing and encrypting them, transmitting them to the cloud service, and handling restorations. A good client supports all major operating systems and allows for granular control over scheduled backups.

These two components work in tandem. The software on your device connects to the cloud storage services over your broadband connection to ensure data is continuously protected without manual intervention.

## Advanced Backup Solutions and Automated Backup

As technology evolves, so do backup methodologies. For organizations with complex IT environments, advanced features are necessary. Cloud native backup tools are designed specifically to protect applications and data that exist entirely within cloud environments, such as containerized applications or services running on the Google Cloud Platform. These tools understand the architecture of cloud workloads and can protect them more effectively than traditional desktop solutions.

Another critical feature is immutable backups. An immutable backup is a read-only copy of data that cannot be changed or deleted for a specified period. This technology provides a powerful defense against ransomware, as malicious actors cannot encrypt or erase the protected backup files, ensuring a clean copy is available for recovery.

The principle of automated backup remains central to all modern strategies. Automating the process eliminates the risk of human error—such as forgetting to run a backup—and ensures that data protection is consistent and reliable. All reputable online services build their solutions around this core principle.

## Evaluating the Best Free Cloud Backup Options

Several providers offer free services, which can be tempting for individuals and small businesses. The best free cloud backup options typically come from major technology companies or as entry-level tiers from specialized backup providers. However, these plans almost always come with significant limitations.

Common restrictions include:

- **Limited Storage:** Free plans usually offer a small amount of cloud backup storage, often between 5GB and 15GB, which is insufficient for backing up an entire system.
- **Feature Restrictions:** Advanced features like server backup, private encryption keys, and versioning are typically reserved for paid business plans.
- **Limited Support:** Free users generally do not have access to priority technical support.

While free online storage services are useful for file sharing or storing a small number of non-critical documents, they are not a substitute for a comprehensive online backup service designed for robust data protection and disaster recovery.

In conclusion, selecting from the top backup services is a critical decision that directly impacts an organization’s resilience. From the simplicity of Backblaze to the integrated cyber protection of Acronis and the enterprise-grade power of Veeam and Cohesity, a solution exists for nearly every need.

For businesses that cannot compromise on security and compliance, leveraging the secure cloud infrastructure of a provider like Atlantic.Net ensures that the backup and disaster recovery strategy is built on a foundation of trust and reliability.

Ultimately, the best cloud backup is one that is automated, secure, and regularly tested, with all the details consider transforming it from a simple utility into a strategic asset for data preservation.


---

# Choosing Bare Metal, Cloud, or Dedicated Hosting for Healthcare: Pros and Cons

> URL: https://www.atlantic.net/hipaa-compliant-hosting/choosing-bare-metal-or-dedicated-hosting-for-healthcare-pros-and-cons/ | Published: 2025-10-01 | Updated: 2026-05-05 | Author: Robert Agar

Healthcare providers and businesses operating in the healthcare industry, and those that process healthcare-related patient data in the United States, are subject to stringent security and privacy regulations. Companies must protect patient information in accordance with specific guidelines or face significant financial, legal, and reputational penalties.

Organizations may want to address these guidelines with the services of a cloud hosting provider. The choice between a HIPAA-compliant infrastructure hosted on cloud servers or a dedicated hosting solution must take the needs of the prospective client into account. In most cases, a dedicated hosting solution will provide a more secure environment for protecting ePHI by conforming to HIPAA guidelines and segregating the systems from other users. Healthcare providers can take advantage of the enhanced security features available with bare metal or dedicated servers.

Compared to cloud hosting, bare metal servers and dedicated hosting solutions offer similar features and functionality, but there are differences that may make one more appropriate for your company. This article compares these two methods of protecting healthcare data to help you choose the right secure environment for your business.

## Key Requirements of Healthcare Applications

Healthcare applications impose requirements that may influence your decision to implement a bare metal or dedicated hosting solution.

- Companies must maintain regulatory compliance with data privacy and security standards, such as HIPAA in the U.S. and GDPR in the European Union.
- Healthcare providers need high-performance and low-latency systems to support real-time, mission-critical applications such as CT scans. Server resources must be reliable with minimal downtime.
- Organizations in the healthcare industry require robust security to protect patient data from cyber threats.
- Some healthcare providers need the ability to rapidly scale systems to address demand spikes or seasonal fluctuations.
- Healthcare professionals may need partners with the technical expertise to ensure data is protected effectively.
- The healthcare industry comprises various entities, ranging from large hospitals to individual healthcare providers. These diverse customers require a tailored solution that aligns with their budget and financial structure.

## What Are HIPAA Regulations?

Healthcare organizations in the U.S. are required to protect patient data by meeting the security and privacy regulations defined by the Health Insurance Portability and Accountability Act (HIPAA). HIPAA focuses on maintaining the security and privacy of protected health information (PHI).

PHI is a legal term in the U.S. referring to health-related information that can be linked to an individual and is created, stored, or processed by a healthcare provider, employer, or health plan. When the data is digitized and stored electronically, it is referred to as ePHI (electronic protected health information).

HIPAA compliance requires companies subject to the regulation to implement three categories of safeguards to protect sensitive patient data.

### #1: Administrative safeguards

Administrative safeguards are the policies and procedures that organizations use to select, implement, and maintain the necessary security measures to protect ePHI. The following are examples of administrative safeguards healthcare organizations need to adopt.

- Decision-makers must assign an individual to act as the security focal point and ensure HIPAA compliance.
- Companies must provide security awareness training to help employees recognize and respond to threats, such as phishing attacks.
- Teams must develop incident response plans to address data breaches and other issues with regulated data.
- Business Associate Agreements (BAAs) must be signed with all third parties that handle or process ePHI.
- Companies must develop contingency plans to perform disaster recovery and ensure access to patient records and healthcare data.

### #2: Physical safeguards

These safeguards are designed to protect the physical resources related to the processing and storage of ePHI. Examples of physical safeguards include the following controls.

- Organizations implement facility access controls to ensure authorized access to the physical hardware processing ePHI.
- Teams must practice workstation security by implementing measures such as locked screens to protect patient records from unauthorized access.
- Companies must develop policies for the effective disposal and reuse of devices and media that contain ePHI.

### #3: Technical safeguards

HIPAA’s technical safeguards are technological solutions meant to protect and limit access to ePHI. The following controls are examples of technical safeguards.

- Companies must implement access control measures to protect sensitive data, including unique user IDs for all individuals accessing ePHI, automatic logoff features, and encryption. Integrity controls must ensure that data is not destroyed or corrupted.
- Strong measures such as biometric or multi-factor authentication must be implemented to restrict unauthorized users from accessing ePHI.
- Businesses must implement audit controls to demonstrate HIPAA compliance for all hardware, software, and processes involved in handling ePHI.
- Teams must implement end-to-end encryption and network security on all data transmissions to protect patient health records.

## Characteristics of a HIPAA-Compliant Hosting Provider

Organizations hosting ePHI must ensure that they partner with a cloud provider offering a HIPAA-compliant dedicated hosting solution or bare metal servers. Candidate providers must meet the following criteria.

- The provider must offer services utilizing a HIPAA-compliant infrastructure.
- Reputable providers will sign a BAA to define their responsibilities in protecting patient records and sensitive data.
- Activity logs and audit trails must be available as evidence of regulatory compliance.
- Data should be encrypted in transit and at rest.
- The data center hosting the physical hardware must be secured with strong access controls and surveillance.
- Servers should have intrusion detection systems, continuous monitoring, role-based access controls, and be patched regularly to address known security vulnerabilities.

## Key Considerations When Selecting a HIPAA Compliant Cloud Solution

Organizations should perform due diligence when selecting a cloud hosting solution that supports HIPAA regulatory compliance. Decision-makers should expect to receive acceptable answers to the following questions when considering a cloud provider to protect ePHI.

- Does the provider have experience assisting healthcare providers with compliance with HIPAA regulations?
- Will the provider sign a BAA?
- What type of uptime guarantee does the provider offer?
- Are there incident plans to address hardware failures?
- How do they control access to physical servers?
- Are there backups and disaster recovery capabilities available for the solution?
- Is your network isolated from other tenants?
- What methods are used to encrypt data, and is sensitive information encrypted at all times, both at rest and in transit?
- How much memory, CPU, and network bandwidth are in the solution, and how does this impact throughput and latency?
- Can you quickly add capacity and integrate with other cloud services if needed?
- What level of technical support is provided, and what specific tasks, such as patching and monitoring systems, are included?
- What are the fixed and variable or hidden costs of the solution?
- Does the provider offer pay-as-you-go pricing or long-term contracts?

## How to Choose Bare Metal or Dedicated Hosting for Healthcare

Companies in the healthcare sector that want to ensure compliance with HIPAA requirements cannot safely utilize a public cloud, shared hosting solution, where resources may be accessed by other clients. HIPAA privacy requires that healthcare information be stored securely with a dedicated solution that isolates sensitive data from other users.

Bare metal dedicated servers and dedicated hosting solutions can both be used to maintain HIPAA compliance. The two alternatives share many similarities that make them suitable choices for meeting HIPAA requirements. They also exhibit some differences that may make one a better fit for specific healthcare organizations.

- [Bare metal servers](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) are physical servers typically provisioned without virtualization, used by a single client. They offer customers complete control over the hardware and operating system. The user can implement customized security protocols to ensure data is effectively protected. Bare metal servers often utilize bleeding-edge technology and are generally more flexible than dedicated hosted servers.
- [Dedicated hosts](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) are also physical servers allocated to a single customer. Customers get full use of the hardware, but may enjoy less flexibility due to preset configuration options. Some vendors may utilize legacy hardware as the foundation for their dedicated server offerings.

Choosing between these two options depends on the customer’s business objectives and the technical proficiency of their staff.

### When Bare Metal Makes Sense

A bare metal option may be more appropriate for healthcare organizations that meet the following criteria.

- The company’s workload includes I/O or compute-intensive applications such as real-time image processing, medical imaging, machine learning, or analytics on large volumes of data.
- The business requires low latency and consistent performance to address critical healthcare applications.
- The organization seeks complete control over the operating system, firmware, and audit logs to meet stringent regulatory requirements.
- The healthcare organization expects to face usage spikes, for example, when addressing public health issues. Bare metal servers enable customers to quickly add and remove capacity.
- The company has an experienced and skilled technical staff that can manage and secure the infrastructure.

### When Dedicated Hosting Is a Better Option

Dedicated hosting is a more suitable option for healthcare providers with less demanding requirements.

- The organization has a predictable workload and does not anticipate facing any spikes or excessive usage demands.
- Teams do not require maximum customization, as all regulatory requirements can be met with the provider’s standard dedicated hosting options.
- The healthcare organization does not require high performance for real-time imaging or AI training. They may host a healthcare-related web application or need to securely store electronic health records (EHRs).
- The company lacks the technical resources to manage a bare-metal server and requires operational support from the provider.
- Companies with budget concerns, looking to minimize capital expenditures, can benefit by taking advantage of more predictable contracts.

## A Comparison Between a Cloud and Dedicated Hosting Solution

Most organizations in the healthcare field do not have the necessary in-house resources to maintain an on-premises HIPAA-compliant data center. Implementing the safeguards mandated by the Security Rule demands a highly secure and redundant infrastructure.

Rather than attempting to enact and maintain HIPAA compliance with an ad-hoc and in-house solution, many organizations are turning to the cloud. As with other types of computing environments, cloud providers offer an easier and more cost-effective method of implementing a HIPAA-compliant environment.

Cloud vendors offer covered entities multiple ways to address HIPAA compliance. Most commonly, covered entities can choose between an infrastructure built on public cloud hosts or one that relies on [dedicated cloud hosts](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/). Let’s look at how the two solutions compare to identify the best route for your company.

### [Dedicated Hosts](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/)

In a dedicated host environment, the cloud provider makes available the dedicated hardware components to a single customer.  These dedicated hosts are used to provide compute and storage capabilities. Your databases or applications will not be sharing resources with another customer, enabling the infrastructure to be tailored completely to your needs.

Security is enhanced with a dedicated hosting solution by eliminating potential attacks emanating from other tenants on a cloud host.

A dedicated host environment provides customers with more control over how the hardware is used and managed. Scaling up or down can be slightly more challenging with a dedicated hosting solution since dedicated hosts can not be instantly scaled.  Some providers, like Atlantic.Net, do allow live migrations so your cloud servers will not see downtime when required to move to a larger host system.  Depending on how the environment is configured, there may be a slightly greater chance of experiencing availability issues with a dedicated host since there are both lower-end and higher-end hardware offerings available for a dedicated host.

With Dedicated Hosts, the customer is able to remove the potential of any noisy neighbor issues from occurring on their host.  The customer also has the ability to shift workloads across different nodes if a cloud server starts to use more of a certain resource than originally planned.

Some software licensing, for example, those from Microsoft, can require you to only deploy on dedicated hardware that is defined as non-shared or not multi-tenant hardware.  This is where Dedicated Hosts would be an excellent option while still utilizing the benefits of cloud platforms.

### [Cloud Servers](https://www.atlantic.net/cloud-platform/)

The first major difference between using cloud servers and dedicated hosting is that with cloud servers you are sharing physical hardware with other customers with specific resources allocated for your systems. A dedicated host restricts the use of the hardware and ensures you are not sharing it with other clients.

Cloud servers’ elasticity results in greater and on-demand scalability to address fluctuating enterprise requirements. Customers using dedicated servers need to have a better understanding of their future needs when provisioning resources.

Cloud servers offer a more economical path towards HIPAA compliance for smaller end deployments. Once a threshold of more than $500 of cloud services is required, a dedicated host is often a better choice from a cost perspective.

## Conclusion

Healthcare organizations can meet HIPAA compliance requirements with a bare metal or dedicated hosting solution. The choice often rests on the company’s level of technical expertise and the performance requirements for their specific healthcare applications. Businesses should examine both options to make an informed selection.

[Atlantic.Net](https://www.atlantic.net/hipaa-compliant-hosting/) offers both types of servers and has extensive experience with providing clients a HIPAA-compliant infrastructure to address their compliance needs.


---

# How to Perform Image Classification with TensorFlow on Ubuntu 24.04 GPU Server

> URL: https://www.atlantic.net/gpu-server-hosting/how-to-perform-image-classification-with-tensorflow-on-ubuntu-24-04-gpu-server/ | Published: 2025-10-02 | Updated: 2026-05-04 | Author: Hitesh Jethva

Image classification is one of the most common tasks in deep learning. It allows you to train a model that can recognize and categorize images into predefined classes, for example, identifying whether a picture shows a cat, dog, or car. TensorFlow, a popular open-source deep learning framework, makes it easier to build, train, and deploy image classification models.

In this tutorial, you will learn how to perform image classification on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/) using TensorFlow.

## Prerequisites

- An Ubuntu 24.04 server with an NVIDIA GPU.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1 – Setting Up the Python Environment

Before building and training your image classification model, you need to set up a dedicated Python environment with TensorFlow installed.

1. Update your system and install Python, pip, venv, and Git.

```bash
apt update -y
apt install -y python3 python3-venv python3-pip git
```

2. Create a new virtual environment for TensorFlow.

```bash
python3 -m venv tf-gpu-env
source tf-gpu-env/bin/activate
```

3. Upgrade pip and install TensorFlow.

```bash
pip install --upgrade pip
pip install tensorflow
```

4. Confirm TensorFlow detects your GPU.

```bash
python3 -c "import tensorflow as tf; print(tf.config.list_physical_devices('GPU'))"
```

Output.

```bash
[PhysicalDevice(name='/physical_device:GPU:0', device_type='GPU')]
```

This means TensorFlow is ready to use your GPU for faster training.

## Step 2 – Preparing the Dataset

Now that your environment is ready, the next step is to load and preprocess the dataset you’ll use for training the image classification model. In this tutorial, we’ll work with the CIFAR-10 dataset, a benchmark dataset for image classification tasks.

1. Create a dataset script.

```bash
nano dataset_prep.py
```

Add the following code.

```bash
# save as dataset_prep.py
import tensorflow as tf

# Load CIFAR-10 dataset
(x_train, y_train), (x_test, y_test) = tf.keras.datasets.cifar10.load_data()

# Normalize images
x_train, x_test = x_train / 255.0, x_test / 255.0

print("Training data shape:", x_train.shape)
print("Test data shape:", x_test.shape)
```

2. Execute the script to verify that the dataset is loaded correctly.

```bash
python3 dataset_prep.py
```

Output.

```bash
170498071/170498071 ━━━━━━━━━━━━━━━━━━━━ 7s 0us/step   
Training data shape: (50000, 32, 32, 3)
Test data shape: (10000, 32, 32, 3)
```

The above output tells that:

- Training set has 50,000 images.
- Test set has 10,000 images.
- Each image is 32×32 pixels with 3 color channels (RGB).

By normalizing the images, we make training more efficient and stable. The dataset is now ready for model building.

## Step 3 – Building the CNN Model

To classify images from the CIFAR-10 dataset, we’ll use a Convolutional Neural Network (CNN). CNNs are well-suited for image tasks because they can automatically detect patterns such as edges, textures, and shapes.

1. Create the model script.

```bash
nano cnn_model.py
```

Add the following code.

```bash
# save as cnn_model.py
import tensorflow as tf
from tensorflow.keras import layers, models

def build_model():
    model = models.Sequential([
        layers.Conv2D(32, (3,3), activation='relu', input_shape=(32,32,3)),
        layers.MaxPooling2D((2,2)),
        layers.Conv2D(64, (3,3), activation='relu'),
        layers.MaxPooling2D((2,2)),
        layers.Conv2D(64, (3,3), activation='relu'),
        layers.Flatten(),
        layers.Dense(64, activation='relu'),
        layers.Dense(10, activation='softmax')
    ])
    return model

if __name__ == "__main__":
    model = build_model()
    model.summary()
```

2. Run the script to see the model’s architecture.

```bash
python3 cnn_model.py
```

You should see the following model summary:

```bash
Model: "sequential"
┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━┓
┃ Layer (type)                         ┃ Output Shape                ┃         Param # ┃
┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━┩
│ conv2d (Conv2D)                      │ (None, 30, 30, 32)          │             896 │
├──────────────────────────────────────┼─────────────────────────────┼─────────────────┤
│ max_pooling2d (MaxPooling2D)         │ (None, 15, 15, 32)          │               0 │
├──────────────────────────────────────┼─────────────────────────────┼─────────────────┤
│ conv2d_1 (Conv2D)                    │ (None, 13, 13, 64)          │          18,496 │
├──────────────────────────────────────┼─────────────────────────────┼─────────────────┤
│ max_pooling2d_1 (MaxPooling2D)       │ (None, 6, 6, 64)            │               0 │
├──────────────────────────────────────┼─────────────────────────────┼─────────────────┤
│ conv2d_2 (Conv2D)                    │ (None, 4, 4, 64)            │          36,928 │
├──────────────────────────────────────┼─────────────────────────────┼─────────────────┤
│ flatten (Flatten)                    │ (None, 1024)                │               0 │
├──────────────────────────────────────┼─────────────────────────────┼─────────────────┤
│ dense (Dense)                        │ (None, 64)                  │          65,600 │
├──────────────────────────────────────┼─────────────────────────────┼─────────────────┤
│ dense_1 (Dense)                      │ (None, 10)                  │             650 │
└──────────────────────────────────────┴─────────────────────────────┴─────────────────┘
 Total params: 122,570 (478.79 KB)
 Trainable params: 122,570 (478.79 KB)
 Non-trainable params: 0 (0.00 B)
```

## Step 4 – Training the Model

With the dataset prepared and CNN model defined, the next step is to train the model on the CIFAR-10 dataset. Training allows the CNN to learn patterns in the images and improve its ability to classify them correctly.

1. Create a training script.

```bash
nano train_model.py
```

Add the following code.

```bash
# train_model.py
import tensorflow as tf
import os
from tensorflow.keras import datasets
from cnn_model import build_model

(x_train, y_train), (x_test, y_test) = datasets.cifar10.load_data()
x_train, x_test = x_train/255.0, x_test/255.0

model = build_model()

model.compile(optimizer='adam',
              loss='sparse_categorical_crossentropy',
              metrics=['accuracy'])

# Train model
history = model.fit(x_train, y_train, epochs=10,
                    validation_data=(x_test, y_test))

# ✅ Ensure save directory exists
os.makedirs("saved_model", exist_ok=True)

# Save full model and weights
model.save("saved_model/cnn.keras")           # preferred modern format
model.save_weights("saved_model/cnn.weights.h5")  # backup (weights only)
```

2. Run the training script.

```bash
python3 train_model.py
```

During training, you’ll see output logs for each epoch.

```bash
1563/1563 ━━━━━━━━━━━━━━━━━━━━ 14s 5ms/step - accuracy: 0.4384 - loss: 1.5377 - val_accuracy: 0.5465 - val_loss: 1.2606
Epoch 2/10
1563/1563 ━━━━━━━━━━━━━━━━━━━━ 3s 2ms/step - accuracy: 0.5848 - loss: 1.1710 - val_accuracy: 0.6242 - val_loss: 1.0618
Epoch 3/10
1563/1563 ━━━━━━━━━━━━━━━━━━━━ 3s 2ms/step - accuracy: 0.6378 - loss: 1.0266 - val_accuracy: 0.6493 - val_loss: 0.9867
Epoch 4/10
1563/1563 ━━━━━━━━━━━━━━━━━━━━ 3s 2ms/step - accuracy: 0.6723 - loss: 0.9303 - val_accuracy: 0.6738 - val_loss: 0.9508
Epoch 5/10
1563/1563 ━━━━━━━━━━━━━━━━━━━━ 3s 2ms/step - accuracy: 0.6951 - loss: 0.8659 - val_accuracy: 0.6778 - val_loss: 0.9201
Epoch 6/10
1563/1563 ━━━━━━━━━━━━━━━━━━━━ 3s 2ms/step - accuracy: 0.7188 - loss: 0.8065 - val_accuracy: 0.6868 - val_loss: 0.9126
Epoch 7/10
1563/1563 ━━━━━━━━━━━━━━━━━━━━ 3s 2ms/step - accuracy: 0.7342 - loss: 0.7576 - val_accuracy: 0.6918 - val_loss: 0.8812
Epoch 8/10
1563/1563 ━━━━━━━━━━━━━━━━━━━━ 3s 2ms/step - accuracy: 0.7501 - loss: 0.7130 - val_accuracy: 0.7058 - val_loss: 0.8600
Epoch 9/10
1563/1563 ━━━━━━━━━━━━━━━━━━━━ 3s 2ms/step - accuracy: 0.7637 - loss: 0.6772 - val_accuracy: 0.7079 - val_loss: 0.8726
Epoch 10/10
1563/1563 ━━━━━━━━━━━━━━━━━━━━ 3s 2ms/step - accuracy: 0.7759 - loss: 0.6436 - val_accuracy: 0.6847 - val_loss: 0.9227
```

Here you can see:

- Training accuracy improving with each epoch.
- Validation accuracy reaching around ~68%.
- The trained model and weights are saved in the saved_model/ directory.

At this stage, you have a trained CNN ready for evaluation.

## Step 5 – Evaluating the Model

After training, the next step is to evaluate the model’s performance on the test dataset. This helps you understand how well the model generalizes to unseen data.

1. Create the evaluation script.

```bash
nano evaluate.py
```

Add the following code.

```bash
# evaluate.py
import os
import tensorflow as tf
from tensorflow.keras import datasets
from cnn_model import build_model

# Reload CIFAR-10 dataset
(_, _), (x_test, y_test) = datasets.cifar10.load_data()
x_test = x_test / 255.0

model = None

# ✅ Try full model first
if os.path.exists("saved_model/cnn.keras"):
    print("Loading full model from saved_model/cnn.keras")
    model = tf.keras.models.load_model("saved_model/cnn.keras")

# ✅ Fallback to weights-only
elif os.path.exists("saved_model/cnn.weights.h5"):
    print("Loading model architecture + weights from saved_model/cnn.weights.h5")
    model = build_model()
    model.compile(optimizer='adam',
                  loss='sparse_categorical_crossentropy',
                  metrics=['accuracy'])
    model.load_weights("saved_model/cnn.weights.h5")

else:
    raise FileNotFoundError("No saved model found! Please run train_model.py first.")

# Evaluate model
loss, acc = model.evaluate(x_test, y_test, verbose=2)
print(f"Test accuracy: {acc*100:.2f}%")
```

2. Run the evaluation script.

```bash
python3 evaluate.py
```

You should see something like this:

```bash
313/313 - 6s - 18ms/step - accuracy: 0.6847 - loss: 0.9227
Test accuracy: 68.47%
```

This indicates that the trained CNN correctly classified approximately 68% of the test images. While this isn’t state-of-the-art, it’s a solid baseline for CIFAR-10 using a relatively simple CNN.

## Step 6 – Making Predictions

Now that the model has been trained and evaluated, let’s use it to make predictions on new data. This step demonstrates how to reload a saved model and test it against unseen images.

1. Create a prediction script.

```bash
nano predict.py
```

Add the following code.

```bash
# predict.py
import os
import numpy as np
import tensorflow as tf
from tensorflow.keras import datasets
from cnn_model import build_model

# Reload CIFAR-10 test dataset
(_, _), (x_test, y_test) = datasets.cifar10.load_data()
x_test = x_test / 255.0

model = None

# ✅ Try full model first
if os.path.exists("saved_model/cnn.keras"):
    print("Loading full model from saved_model/cnn.keras")
    model = tf.keras.models.load_model("saved_model/cnn.keras")

# ✅ Fallback to weights-only
elif os.path.exists("saved_model/cnn.weights.h5"):
    print("Loading model architecture + weights from saved_model/cnn.weights.h5")
    model = build_model()
    model.compile(optimizer='adam',
                  loss='sparse_categorical_crossentropy',
                  metrics=['accuracy'])
    model.load_weights("saved_model/cnn.weights.h5")

else:
    raise FileNotFoundError("No saved model found! Please run train_model.py first.")

# ✅ Make predictions on first 5 test samples
predictions = model.predict(x_test[:5])

print("Predicted labels:", np.argmax(predictions, axis=1))
print("True labels     :", y_test[:5].flatten())
```

2. Run the script.

```bash
python3 predict.py
```

You should see output similar to this:

```bash
Predicted labels: [3 1 8 0 4]
True labels     : [3 8 8 0 6]
```

Here, the model predicted labels for the first 5 test images.

- It correctly predicted 3 (cat) and 0 (airplane).
- It misclassified some others, which is common with a relatively simple CNN trained for only 10 epochs.

## Conclusion

In this tutorial, you built an image classification pipeline with TensorFlow on Ubuntu 24.04 GPU server. You prepared the CIFAR-10 dataset, created a CNN model, trained it, evaluated its accuracy, and made predictions on test images. The model reached around 68% accuracy, which is a solid baseline for a simple CNN trained for 10 epochs.


---

# The Top Block Storage Providers for 2026: A Comprehensive Guide

> URL: https://www.atlantic.net/managed-services/the-top-block-storage-providers-for-2026-a-comprehensive-guide/ | Published: 2025-10-02 | Updated: 2026-01-06 | Author: Richard Bailey

Block storage is an essential component of modern cloud computing and is used to support a wide range of cloud applications, such as transactional databases or virtual machine file systems. Block storage is a software defined storage layer that underpins nearly every service offered by cloud providers, it’s an elastic service which means that it can be assigned to various server instances as needed.

Its essential to choose a SDS block storage solution that offers the best in class capabilities and a reliable platform. Block storage environments impact the performance, scalability, and cost of the cloud service, and it can even be used in hybrid environments.

This guide provides an overview of block storage and reviews some of the top block storage providers available in 2025.

## Understanding Block Storage

There are three primary types of data storage. These are:

1. Object storage;
2. File storage;
3. Block storage.

Each storage platform has a distinct purpose. Specifically, block storage breaks data into fixed-size chunks called blocks. Each block has a unique identifier but no metadata, and these blocks are stored independently. The blocks are presented and configured by the operating system as a raw storage volume.

This approach provides high speed and efficiency because it’s the operating system that controls the file system, making block storage a fast and flexible storage solution for performance-sensitive workloads by offering low latency and high throughput, making it an ideal choice for databases, email servers, and for virtual disks.

## SBS Block Storage Solutions

When selecting a chosen block storage provider, keep these five key areas at the forefront of your decision making. They will help determine how well the storage solution will integrate into your existing workflow and help you achieve your business goals.

- **Performance:** The speed of the storage is crucial. This is measured in terms of latency and throughput. You are looking for low latency and high throughput from the best high-performance storage. Most providers offer [Solid-State Drives (SSDs)](https://www.atlantic.net/cloud-platform/block-storage/) to ensure quick access for applications but always check.
- **Scalability:** The ability to easily increase or decrease storage capacity is important. A good storage solution allows users to add a storage volume or resize existing volumes without downtime. This flexibility ensures that the storage infrastructure can grow with the data needs of the business.
- **Availability and Reliability:** High availability ensures data is always available. It’s achieved through redundant storage systems and replication between data centers. Features like automated [snapshots and block-level replication](https://www.atlantic.net/cloud-platform/backups/) protect data from hardware failure, helping to ensure business continuity.
- **Security:** Data security is a critical requirement. Customers expect data integrity with encryption of data at rest and in transit, and access controls and integration with identity management systems.
- **Integration:** The storage should be easily integrated with existing computing resources, such as seamless attachment to virtual machine instances and simplified management and deployment across on-premises, hybrid, and multi-cloud environments.

## Top Block Storage Providers for Scalable Solutions

There are plenty of providers out there to choose from, but the following companies provide proven and reliable block storage solutions suitable for a variety of industries, from healthcare to finance.

### #1: Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

[Atlantic.Net](https://www.atlantic.net/cloud-platform/block-storage/) is an established cloud services provider known for its focus on reliability, security, and personalized customer support. The block storage solution is an extension of the ACP cloud platform, offering a simple and powerful way to add persistent SSD storage to cloud instances.

The service is designed for ease of use and consistent performance, making it a strong choice for businesses that need scalable and dependable storage without the complexity of larger hyperscale platforms. The company’s long history in compliant hosting also makes it a trusted vendor for regulated industries.

#### Advantages

- **Simplified and Predictable Pricing:** The storage solution is offered with a straightforward, per-gigabyte monthly pricing model. This approach avoids the complex, multi-faceted billing of larger providers, making it exceptionally easy to predict storage costs.
- **Reliable High-Performance Storage:** All block storage volumes are powered by Solid-State Drives (SSDs) in a redundant RAID 10 configuration. This architecture is engineered to deliver both high-speed data access and inherent data protection against drive failure.
- **Dedicated Customer Support:** Atlantic.Net is recognized for its responsive and accessible customer support, which is available around the clock and exclusively based in the United States. Having direct access to technical assistance is a significant benefit for businesses that may not have extensive in-house IT teams.

#### Disadvantages

- **Limited Geographic Footprint:** While operating multiple data centers throughout the United States, Europe, and Asia, its presence is not as extensive as some of the largest cloud providers.

#### Ideal for

- Small to medium-sized businesses that require a simple, cost-effective, and high-performance storage solution that just works!
- Organizations in regulated industries like healthcare that need a secure, compliant infrastructure vendor.
- Users who prioritize straightforward management and direct access to high-quality technical support.

### #2: Amazon Web Services (AWS) Elastic Block Store (EBS)

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

[Amazon Elastic Block Store](https://aws.amazon.com/ebs/) (EBS) is a block storage service designed for use with Amazon EC2, the AWS virtual server platform. It is a highly established service that provides persistent block-level storage volumes. EBS is engineered for high availability and durability, automatically replicating volumes within a single Availability Zone.

#### Advantages

- **Diverse Performance Tiers:** Multiple volume types are offered, from general-purpose SSDs (gp3) to high-performance Provisioned IOPS SSDs (io2 Block Express), allowing organizations to match storage performance and cost directly to the needs of the application.
- **Deep EC2 Integration:** EBS volumes are managed and attached as a native part of the Amazon EC2 instance lifecycle. This tight integration allows for fast attachment and the ability to use volumes as boot partitions, which simplifies the deployment of virtual machines.
- **Advanced Data Management:** The platform features strong data protection and management options. Elastic Volumes allow for on-the-fly modifications to capacity and performance, while automated snapshots to Amazon S3 provide a simple and effective backup solution.

#### Disadvantages

- **Ecosystem Lock-in:** EBS is designed specifically for the AWS environment and cannot be easily used with on-premises systems or other cloud providers.
- **Complex Pricing:** The cost structure can be difficult, with different pricing for storage capacity, provisioned performance, and snapshot usage.
- **Performance Constraints:** While highly performant, volumes are tied to a single Availability Zone, which can be a limitation for certain high-availability architectures.

#### Ideal for

- Businesses of all sizes that are already embedded in AWS.
- Enterprises that run performance-sensitive applications, such as large databases or data analytics platforms.
- Users who require a feature-rich storage solution that can be managed via infrastructure-as-code.

### #3: Google Cloud Persistent Disk

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

[Google Cloud Persistent Disk](https://console.cloud.google.com/) is the primary block storage solution for Google Compute Engine virtual machines. It is designed for high durability and performance, with data being redundantly stored to protect against equipment failure.

Persistent Disk separates the storage from the virtual machine instance, allowing users to detach and reattach disks to different machines as needed.

#### Advantages

- **Flexible Performance Options:** Users can select from several disk types, including Standard, Balanced, and SSD Persistent Disks, to meet different performance requirements. For high-end needs, Extreme Persistent Disks offer very high IOPS for demanding database workloads.
- **Strong Reliability and Availability:** Data is automatically encrypted before it travels outside of a virtual machine instance to Persistent Disk storage. The platform also offers regional persistent disks that provide synchronous data replication between two zones in a region for high availability.
- **User-Friendly Management:** The service allows for easy resizing of disks without downtime. Snapshots can be created to back up data, and these snapshots can be used to create new disks in any region, which simplifies data migration and disaster recovery.

#### Disadvantages

- **Regional Limitations:** While robust, the global footprint of Google Cloud is smaller than some competitors, which could be a factor for businesses needing a presence in specific areas.
- **Performance Scaling:** Some disk types require provisioning both capacity and IOPS, which can be less straightforward than automatically scaling solutions.

#### Ideal for

- Organizations that already use Google Cloud for data analytics, machine learning, and containerized applications.
- Businesses that require high durability and the ability to easily manage and move storage between virtual machine instances.
- Developers looking for a simple and scalable storage solution integrated with a modern cloud platform.

### #4: Microsoft Azure Disk Storage

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

[Azure Disk Storage](https://azure.microsoft.com/en-gb/products/storage/disks) is a high-performance, durable block storage service designed to be used with Azure Virtual Machines. It offers several disk types that cater to a wide variety of workloads. As part of the extensive Microsoft Azure cloud, this storage solution is built with enterprise-grade security, compliance, and availability features, making it a trusted option for many large organizations.

#### Advantages

- **Tiered Storage for All Workloads:** Azure provides a clear hierarchy of storage options, including Standard HDDs, Standard SSDs, Premium SSDs, and Ultra Disks. This structure makes it easy for businesses to select the right balance of cost and performance for any given task, from backups to SAP HANA databases.
- **Strong Integration with Microsoft Ecosystem:** The service is seamlessly integrated with the broader Azure platform and Microsoft software. This is a significant benefit for organizations that already rely on Windows Server, Microsoft 365, and other Azure services, as it simplifies deployment and management.
- **Enterprise-Grade Security and Availability:** Azure Disk Storage supports availability sets and availability zones to protect applications from data center failures. It also provides multiple encryption options, including server-side encryption with platform-managed or customer-managed keys.

#### Disadvantages

- **Cost of High Performance:** The highest performance tier, Ultra Disk, offers excellent low-latency storage but can be significantly more expensive than other options.
- **Complexity for New Users:** The Azure portal and its vast number of configuration options can be complex for users who are not already familiar with the Microsoft cloud environment.

#### Ideal for

- Enterprises, particularly those already invested in the Microsoft software and cloud ecosystem.
- Businesses running Windows-based workloads or high-performance applications like SQL Server and SAP.
- Organizations in regulated industries that require a provider with a strong focus on security and compliance certifications.

#### #5: IBM Cloud Block Storage

![](https://www.atlantic.net/wp-content/uploads/2025/06/ibm-logo.png)

IBM Cloud Block Storage is a persistent, high-performance storage service designed for use with IBM Cloud Virtual Servers. It offers customizable performance tiers and is built on an enterprise-grade infrastructure. This service provides durable and redundant block-level storage volumes that can be attached to virtual server instances, making it suitable for a variety of demanding workloads, from transactional databases to general-purpose applications.

**Advantages**

- **Customizable Performance Tiers:** The service allows for precise performance tuning. Users can select from predefined IOPS tiers or provision a custom IOPS level, enabling a close match between application requirements and storage costs.
- **High Durability and Availability:** Storage volumes are built on a redundant infrastructure with no single point of failure. Data is stored across multiple physical disks within an Availability Zone, which protects against hardware failure and ensures high data durability.
- **Enterprise-Grade Security:** IBM provides robust security features. This includes default encryption for data at rest, which can be managed by IBM or with customer-provided keys for greater control. It also integrates with IBM Cloud Identity and Access Management for fine-grained access control.

**Disadvantages**

- **Ecosystem Specificity:** The storage is tightly integrated with the IBM Cloud environment and is intended for use with its virtual servers. This limits its applicability for hybrid or multi-cloud strategies that require storage portability.
- **Complexity in Management:** The IBM Cloud interface and its range of options can present a steeper learning curve compared to more streamlined providers, particularly for users new to the platform.
- **Geographic Reach:** Although IBM has a significant global presence, its number of cloud data center regions is less than that of the top hyperscale providers, which could be a consideration for global applications needing low-latency access in specific locations.

**Ideal for**

- Existing IBM Cloud customers who need a reliable, integrated block storage solution for their virtual server instances.
- Enterprises running mission-critical workloads, such as large databases, that require predictable and provisioned I/O performance.
- Organizations with stringent security and compliance needs that benefit from IBM’s focus on enterprise-level data protection.

### Conclusion

Selecting a block storage provider in 2025 requires a careful evaluation of specific needs. Each provider listed offers a distinct combination of performance, features, and cost. The best choice depends on factors like existing infrastructure, technical expertise, and budget.

One size does not fit all, and all situations are different. Choose the best solution that suites your needs. If you need a simple secure block storage, Atlantic.Net has built a strong storage solution with SSD and built-in safety and security features. But you like to work with the mega cloud providers, you obviously have many other options to choose from also. In the current market, Amazon Web Services (AWS) is recognized as the largest storage provider by market share, making it the most popular cloud storage provider for infrastructure services. The reason block storage is expensive relative to other storage types is because of the underlying technology.

It is built on high-performance hardware like SSDs and engineered for the low latency and high IOPS that demanding applications require, positioning it as a premium storage solution. A final decision should be made after a detailed comparison of these factors.


---

# Top HIPAA Hosting Provider for Small Businesses in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/top-hipaa-hosting-provider-for-small-businesses-in-2026/ | Published: 2025-10-02 | Updated: 2025-11-22 | Author: Dr. Rachael Bailey

Why do even small clinics need a HIPAA hosting provider? Patient information has become one of the most valuable and vulnerable assets that a business can hold. We have seen a rise in healthcare data breaches year on year, with patient data being exposed and fines to businesses running into the millions. Beyond the huge financial impact, losing control of protected health information can also have a massive effect on patient trust.

HIPAA-compliant hosting is designed to protect against these risks. It ensures that electronic protected health information (ePHI) is stored, processed, and transmitted in accordance with the strict privacy and security rules outlined in the [Health Insurance Portability and Accountability Act](https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html) (HIPAA).

This requires businesses to have a robust infrastructure, audited safeguards, and a formal Business Associate Agreement (BAA) with their hosting provider.

In this article, we will guide small businesses through the essentials of selecting a suitable HIPAA-compliant hosting provider, from understanding the requirements and costs to identifying the features that matter most.

## Understanding HIPAA Requirements

HIPAA regulations were first introduced in 1996 to protect the privacy and security of sensitive patient health information, otherwise known as Protected Health Information (PHI). This covers any data that can identify a patient, such as names, addresses, medical records, test results, or insurance details. When this information is stored or transmitted electronically, it becomes electronic Protected Health Information (ePHI), which must be handled with particular care.

In order to adequately protect ePHI, HIPAA sets out three key safeguards: administrative, physical, and technical. Administrative safeguards cover policies, training, and access controls to ensure only authorized staff can handle patient information. Physical safeguards relate to secure facilities, controlled server access, and [disaster recovery](https://www.atlantic.net/disaster-recovery/) planning. While technical safeguards include encryption, authentication, firewalls, and audit logs to protect against cyber threats.

### What Is a Business Associate Agreement (BAA)?

To comply with HIPAA requirements, a [Business Associate Agreement](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) (BAA) is also essential. Any hosting provider that stores or processes PHI on behalf of a healthcare business is considered a Business Associate. The BAA is a legal contract confirming their responsibility to meet HIPAA standards.

## Does HIPAA Apply to Small Businesses?

HIPAA guidelines apply to organizations of all sizes. Whether you are a large hospital or a small clinic, the same rules apply when it comes to protecting patient data. Any small business that handles sensitive patient information is legally required to comply, making the choice of a HIPAA-compliant hosting provider just as critical as it is for larger organizations.

## Benefits of HIPAA Compliant Hosting

Opting for a HIPAA-compliant hosting provider brings significant advantages for healthcare organizations and any HIPAA-covered entity that handles sensitive data. These include the following:

### Enhanced Security and Compliance

A HIPAA-compliant service provider offers a secure hosting environment that aligns with the HIPAA Security Rule and other health insurance portability and accountability requirements. This includes robust data encryption to secure data both at rest and in transit, intrusion detection and prevention systems, regular security updates, reliable off-site backups, and rigorous access controls, such as multi-factor authentication.

A good HIPAA-compliant hosting partner will also provide HIPAA compliance monitoring, regular security testing, and ongoing audits to ensure safeguards keep pace with evolving cyber threats.

### Regulatory Assurance

All healthcare organizations, whether they are large hospitals or smaller covered entities, face the same legal responsibility to protect their patient information under HIPAA rules. A HIPAA-compliant cloud hosting partner provides the necessary safeguards, secure data centers, and HIPAA compliance support to achieve true HIPAA compliance. By having a suitable Business Associate Agreement (BAA) in place, businesses can demonstrate accountability and reduce the risk of fines or penalties linked to non-compliance.

### Patient Trust and Reputation

Healthcare providers rely on trust to maintain strong relationships with their patients. Using HIPAA-compliant solutions, such as HIPAA-compliant email services, cloud servers, and HIPAA-compliant websites, demonstrates that privacy is a priority for them. By maintaining full HIPAA compliance, healthcare providers can build confidence and credibility within the healthcare industry.

### Scalable and Reliable Hosting Solutions

HIPAA-compliant hosting services offer flexibility and resilience. Managed hosting providers can scale resources up or down to match the growth of a small business, while also delivering reliable solutions such as off-site backups and disaster recovery planning. This ensures that healthcare technology systems remain available and secure even during periods of rapid growth, hardware failure, or cyberattacks.

### Simplified Management

Running a healthcare business means dedicating your focus primarily to your patients. Partnering with a HIPAA-compliant cloud service provider lets you shift the responsibility for compliance support, monitoring, and infrastructure management to experts. This allows businesses to operate securely and efficiently, with a hosting environment that powers healthcare technology systems while keeping sensitive data protected.

## Choosing a HIPAA Hosting Provider for Small Businesses

Finding the right HIPAA-compliant hosting partner for your healthcare business is an important decision. The right provider keeps your sensitive patient data secure while also supporting day-to-day operations, regulatory compliance, and future growth.

So what should you be looking for as you evaluate potential providers?

### Check for HIPAA Compliance and a BAA

Firstly, you should look for HIPAA-compliant web hosting providers that offer a formal Business Associate Agreement (BAA) and can demonstrate full HIPAA compliance. Make sure they provide necessary HIPAA compliance services such as ongoing auditing, intrusion prevention, and compliance monitoring. A HIPAA-compliant cloud hosting solution or HIPAA-compliant server that meets these standards creates a secure environment for your healthcare technology systems.

### Look at Security Features

A good HIPAA hosting provider offers more than just basic security. Take a close look at the security features offered by your shortlist of HIPAA-compliant hosting partners to ensure they provide a secure environment for your sensitive data. Look for features such as fully managed firewalls, intrusion prevention, vulnerability scans, file integrity monitoring, anti-malware protection, multi-factor authentication, SSL certificates, secure sockets layer (SSL) encryption, off-site backups, and network edge/DDoS protection. These features help create a secure environment for your patient data.

### Managed vs. Unmanaged Hosting

Decide whether you need managed services or unmanaged hosting solutions. Managed services take care of security, backups, and HIPAA compliance support, letting your team focus on patient care. Unmanaged hosting may be suitable for businesses with internal IT expertise, but who still require HIPAA-compliant environments, such as HIPAA-compliant Linux or HIPAA-compliant Windows servers.

### Scalability and Reliability

Find a HIPAA-compliant web hosting partner that can scale with your business. Look for providers that let you scale resources easily, handle increased traffic, and maintain performance without compromising security. Reliable uptime, disaster recovery planning, and a resilient cloud environment ensure that your healthcare systems remain available and protected as your business expands.

### Ongoing Compliance Support

Finally, choose a HIPAA-compliant hosting partner that offers ongoing services to ensure HIPAA compliance is maintained long-term. This includes regular auditing, monitoring, updates, and guidance on HIPAA rules, giving you peace of mind that your sensitive patient data stays secure and your hosting environment remains fully compliant.

## How Much Does HIPAA Hosting Cost?

The cost of HIPAA-compliant hosting can vary significantly depending on the size of your business and the type and scale of HIPAA hosting solutions you require. Small healthcare businesses may find entry-level HIPAA-compliant web hosting or HIPAA-compliant cloud hosting solutions more affordable, while larger organizations or those needing managed services, dedicated servers, and robust compliance monitoring will see higher costs.

As your business grows or your needs become more complex, costs increase to reflect additional protections and services. Features such as managed firewalls, intrusion prevention, file integrity monitoring, offsite backups, multi-factor authentication, and ongoing HIPAA compliance support add value and, with that, higher pricing. Meanwhile, shared hosting options are generally less expensive, but dedicated servers or HIPAA-compliant cloud environments offer stronger security, better reliability, and greater scalability.

Ultimately, investing in a HIPAA-compliant hosting provider is about more than just the monthly fee. It ensures your sensitive patient data remains secure, your healthcare technology systems are protected, and your business maintains full HIPAA compliance, building trust with patients and supporting growth over time.

## How to Ensure Your Hosting Setup Remains HIPAA-Compliant

Maintaining HIPAA compliance isn’t a one-time task. Your hosting environment needs ongoing attention to protect confidential patient information and keep your healthcare business fully compliant. Threats evolve, software needs updating, access controls must be monitored, and backups tested. Without regular maintenance, even a compliant setup can quickly become vulnerable.

Here’s how a strong HIPAA-compliant hosting partner can help manage these critical areas for you:

### Regular Auditing and Monitoring

Ongoing auditing and monitoring are essential to identify vulnerabilities, ensure security controls are functioning, and confirm that your hosting environment continues to meet the [HIPAA Security Rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/). A good HIPAA-compliant hosting provider handles this for you, offering detailed logging, intrusion detection, and vulnerability scanning so your data remains protected without adding to your workload.

### Staying Up-to-Date with Security Updates

Servers, software, and cloud environments need regular updates to address emerging security threats. A strong hosting partner takes care of these updates automatically or provides guidance for maintaining HIPAA-compliant environments.

### Maintaining Strong Access Controls

Multi-factor authentication, role-based access, and strict user permissions are vital to controlling who can access your medical records and patient information. The right HIPAA hosting provider manages these controls for you, reducing risk and ensuring your systems stay compliant over time.

### Regular Backups and a Robust Disaster Recovery Plan

Regular, encrypted off-site backups and tested disaster recovery plans are critical to keeping your data safe in the event of hardware failure, cyberattacks, or natural disasters. HIPAA-compliant hosting solutions from a reliable provider make these processes seamless and dependable.

Ultimately, the easiest way to maintain ongoing HIPAA compliance is by partnering with a provider who takes care of it for you.

## Why Choose Atlantic.Net for Your HIPAA Compliant Hosting?

Choosing the right HIPAA-compliant hosting partner is crucial for small healthcare businesses that need to protect sensitive patient data while staying focused on patient care. [Atlantic.Net](https://www.atlantic.net/) is a market-leading hosting solutions provider with over 30 years of experience, offering award-winning hosting solutions and services that have been designed to take the burden of compliance and security off your shoulders.

For healthcare businesses that require HIPAA compliance, we offer scalable and resilient hosting environments tailored to their needs. Whether you need HIPAA-compliant cloud hosting, dedicated servers, or managed services, we handle ongoing HIPAA compliance support, updates, and monitoring. This allows you to focus on patient care while we ensure your critical patient data is protected and your hosting environment meets all HIPAA requirements.

Our [HIPAA solutions](https://www.atlantic.net/hipaa-compliant-hosting/) include a full suite of features designed to protect personal health data and ensure regulatory compliance. This includes a Business Associate Agreement (BAA), intrusion prevention services, fully managed firewalls, vulnerability scans, file integrity monitoring, and anti-malware protection. We also provide SSL certificates, encrypted storage, encrypted VPNs, and off-site backups to secure your data, while multi-factor authentication and a detailed log management system ensure strict access control. Advanced protections, such as Trend Micro Deep Security and network edge/DDoS protection, safeguard your systems against evolving cyber threats, giving your healthcare business confidence that your hosting environment is fully secure and HIPAA-compliant.

## Partner with Atlantic.Net for Trusted HIPAA Compliant Web Hosting

Protecting sensitive patient data and maintaining HIPAA compliance doesn’t have to be complicated. With [Atlantic.Net](https://www.atlantic.net/), you get a trusted hosting partner that offers scalable, secure, and fully managed HIPAA-compliant hosting solutions designed for small healthcare businesses.

### Contact Us Today To Find Out More

[Contact Atlantic.Net today](https://www.atlantic.net/#GetStarted) to get started and enjoy the confidence of a fully HIPAA-compliant web hosting solution that keeps your sensitive data secure.


---

# Top Object Storage Providers in 2026: A Guide to the Best Solutions Available

> URL: https://www.atlantic.net/managed-services/top-object-storage-providers-2026-a-guide-to-the-best-solutions-available/ | Published: 2025-10-02 | Updated: 2026-09-07 | Author: Richard Bailey

Object storage is a data storage architecture for handling large amounts of unstructured data. Unlike traditional file systems that organize data in a file hierarchy, object storage systems manage data as distinct units, or objects. Each object includes the data itself, a variable amount of metadata, and a globally unique identifier. This structure is highly scalable and is used by many cloud-native applications.

Cloud object storage was developed to handle modern data management requirements. It offers an affordable storage solution with industry-standard data integrity, durability, and availability. Businesses use object storage for everything from [data backup](https://www.atlantic.net/cloud-platform/backups/) and disaster recovery to data analytics and machine learning. A key benefit of this data storage model is having the ability to use non-specialist hardware, which helps reduce the total storage costs for the customer.

However, choosing the right provider is important because each provider is different. The file sizes you can save vary dramatically (from 50 GB files to 5TB files). Also, factors like the provider’s pricing model, egress fees, performance, and integration with other services should be considered.

## The Best Cloud Object Storage Solutions

The top object storage providers show how different services are tailored for specific use cases, including the storage of sensitive information from large-scale enterprise data archives to high-performance content distribution. The choice is varied, so it’s important to shop around.

### #1: Amazon S3

![](https://www.atlantic.net/wp-content/uploads/2026/09/Amazon-S3-Logo.png)

Amazon Simple Storage Service (S3) is the market leader in cloud object storage. Launched in 2006, it has become one of the most popular online storage solutions. Its long presence in the market has resulted in extensive documentation and a massive environment of integrated third-party tools, ensuring high durability and data protection software.

#### Advantages**:**

- **Exceptional Data Durability:** Amazon S3 is designed for 99.999999999% of data durability. It achieves this by automatically replicating data across multiple physically disparate Availability Zones within a region, which protects stored data from a wide range of failure scenarios.
- **Vast, Mature Platform:** S3 integrates seamlessly with nearly every other AWS service, from computing (EC2) to data analytics (Athena, Redshift). This allows users to build sophisticated, end-to-end cloud-native applications directly on top of their data without complex integrations.
- **Versatile Storage Classes:** The service offers a range of storage tiers, such as S3 Standard for frequently accessed data, S3 Intelligent-Tiering for data with unknown access patterns, and S3 Glacier for long-term archival.
- **Comprehensive Security Features:** S3 provides extensive security controls, including multi-factor authentication, fine-grained access controls through IAM policies, and multiple encryption options.

#### Disadvantages**:**

- The pricing model is complex and can be difficult to predict, with separate charges for storage capacity, API requests, and data transfer.
- High egress fees for moving data out of the AWS cloud can lead to significant, sometimes unexpected, costs and contribute to vendor lock-in.

#### Ideal For:

- Enterprises and startups already invested in the AWS cloud computing ecosystem.
- Developers building cloud-native applications that require a robust, scalable storage solution.
- Organizations that need a wide range of storage options for different data access patterns.

### #2: Wasabi Hot Cloud Storage

![](https://www.atlantic.net/wp-content/uploads/2025/10/250px-Wasabi_Logo.png)

Wasabi Technologies was founded to make cloud storage a simple commodity. The company’s core value proposition is a simplified and predictable pricing model. They have eliminated the egress fees and API request charges that are common with other larger providers. Wasabi offers a single tier of high-performance storage and is fully compatible with Amazon S3, making it a popular alternative.

#### Advantages**:**

- **No Egress or API Request Fees:** This is Wasabi’s key differentiator. Businesses can retrieve their data as often as needed without incurring extra data transfer costs, making total storage costs highly predictable and often much lower for read-heavy workloads.
- **Simple, Competitive Pricing:** Wasabi offers a straightforward, low per-terabyte monthly price for its single tier of hot storage.
- **High-Performance and S3 Compatibility:** The service is designed for high performance, making it suitable for active data use cases, not just archival. Its full S3 API compatibility means that existing applications, backup tools, and data management software that work with S3 can be pointed to Wasabi with minimal configuration changes.

#### Disadvantages**:**

- A smaller global footprint of data centers compared to major cloud providers.
- The ecosystem of integrated services is less extensive than that of AWS or Google Cloud.
- Fewer advanced features for complex data management or data analytics workflows.

#### Ideal For:

- Businesses with high data egress needs, such as media companies or video surveillance archives.
- Organizations looking for a cost-effective solution for backup and disaster recovery.
- Companies seeking to implement a hybrid cloud environment without facing unpredictable data transfer costs.

### #3: Google Cloud Storage

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

Google Cloud Storage is part of the Google Cloud Platform. It’s well known for its reliable performance and deep integration with Google’s analytics and machine learning tools. It uses Google’s private global network to provide high-speed, low-latency data access from anywhere in the world. This makes it a good choice for performance-sensitive workloads.

#### Advantages**:**

- **High Performance and Global Reach:** Google Cloud Storage uses Google’s global network infrastructure to provide consistently fast data access. Features like multi-regional storage options ensure high availability and low latency for users distributed around the world.
- **Seamless Analytics Integration:** The service integrates natively with powerful Google Cloud tools like BigQuery, allowing users to run complex SQL queries directly on petabytes of data stored in GCS. This capability is ideal for large-scale data analytics without the need to move data.
- **Unified Object Storage:** Google provides several storage classes (Standard, Nearline, Coldline, Archive) under a single, unified API. This simplifies application development and data lifecycle management, as the same tools can be used to interact with data regardless of its storage tier.

#### Disadvantages**:**

- Egress fees for data transfer out of Google Cloud can be a significant and unpredictable component of the total cost.
- While its market share is growing, it has a smaller ecosystem of third-party tools and community support compared to AWS S3.

#### Ideal For:

- Organizations that are already using Google Cloud Platform for data analytics, machine learning, or large-scale computing services.
- Developers who need to store and deliver large media files or other digital content with high performance and low latency.
- Global businesses that require a single storage solution and fast access to users across different continents.

### #4: MinIO

![](https://www.atlantic.net/wp-content/uploads/2026/09/MINIO_wordmark.png)

[MinIO](https://www.atlantic.net/dedicated-server-hosting/how-to-deploy-minio-on-ubuntu-24-04-an-open-source-object-storage-application/) is a high-performance, software-defined object storage solution designed for the private and hybrid cloud. Unlike the managed services on this list, MinIO is open-source software that can be deployed on any commodity hardware, from on-premises data centers to any public cloud provider. It is fully compatible with the Amazon S3 API and is optimized for the performance demands of modern AI/ML, data analytics, and cloud-native application workloads.

#### Advantages**:**

- **Deployment Flexibility:** MinIO can be deployed anywhere—on bare metal, in containers with Kubernetes, or on public cloud infrastructure. This provides organizations with complete control over their data and helps them build a consistent storage architecture across multiple nodes.
- **High Performance:** It is engineered for extreme performance, capable of achieving read/write speeds measured in terabytes per second. This makes it an ideal storage backend for performance-sensitive applications like data lakes, AI/ML model training, and advanced analytics.
- **Open Source and S3 Compatible:** Being open-source and S3-compatible, MinIO helps organizations avoid vendor lock-in. It allows them to use S3-compatible tools and applications while retaining full ownership and control of the storage infrastructure.

#### Disadvantages**:**

- It requires self-management of hardware, software, and networking, which increases operational overhead (maintenance) and requires significant technical expertise.
- While the software is free, enterprise-grade support and management tools require a paid commercial subscription.

#### Ideal For:

- Large enterprises that need to build a high-performance, S3-compatible private cloud storage solution for security or regulatory compliance.
- Organizations implementing a multi-cloud or hybrid cloud strategy that requires a consistent storage layer across all environments.
- Companies with performance-intensive AI/ML and data analytics workloads that need faster access to data than traditional storage systems can provide.

### #5: Cloudflare R2

![](https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcSvaaS6cz2-k_AywDZ0twr_KFwOC5CHQPiFNA&s)

Cloudflare R2 is a distributed object storage solution, also with no egress fees. As a part of the wider Cloudflare product suite, R2 is designed to be tightly integrated with the Cloudflare global network (CDN). Cloudflare’s goal is to provide developers with a cost-effective, S3-compatible storage that does not impose hidden fees or penalize them for moving data out of the cloud.

#### Advantages**:**

- **Zero Egress Fees:** R2’s most compelling feature is its complete elimination of egress fees. Users can serve data from R2 to anywhere on the internet without incurring data transfer charges, which dramatically reduces the total cost of ownership for content-heavy applications.
- **Automatic CDN Integration:** Data stored in R2 is automatically and intelligently cached on Cloudflare’s global edge network. This ensures that content is delivered to end-users with extremely low latency, making it ideal for global content distribution.
- **S3-Compatible API:** R2 provides an S3-compatible API, allowing developers to migrate their existing applications and workflows with minimal code changes. This lowers the barrier to entry for developers looking to move away from providers with high egress costs.

#### Disadvantages**:**

- As a newer product, its feature set is less mature and comprehensive when compared to established providers like Amazon S3 or Google Cloud Storage.
- The most significant cost and performance benefits are realized when R2 is used in combination with other Cloudflare services.

#### Ideal For:

- Businesses that already use the Cloudflare network for application security and performance.
- Applications that distribute large volumes of data globally, such as websites with rich media, video streaming platforms, or software distribution.
- Developers and organizations looking to build multi-cloud architectures without being locked into a single provider by punitive egress fees.

### #6: Microsoft Azure Blob Storage

![](https://www.atlantic.net/wp-content/uploads/2025/10/Microsoft_Azure.svg_.png)

Microsoft Azure Blob Storage is the company’s object storage solution for the cloud and a foundational service of the Azure platform. It is engineered to be massively scalable, storing and serving trillions of objects for customers worldwide. Designed for durability and high availability, Blob Storage is optimized for storing unstructured data, making it a direct and powerful competitor to AWS S3 and Google Cloud Storage. Its strongest appeal is to enterprises that are deeply integrated with Microsoft’s software stack and cloud services.

#### Advantages**:**

- **Deep Integration with the Microsoft Ecosystem:** Azure Blob Storage integrates seamlessly with a wide range of other Azure services, such as Azure Machine Learning, Azure Functions, and Azure Data Factory. This creates a cohesive development and operational experience for businesses that use Microsoft tools like Visual Studio, .NET, and Microsoft 365.
- **Advanced Tiered Storage for Cost Optimization:** The service provides multiple access tiers—Hot, Cool, and Archive—that allow for effective data lifecycle management. Organizations can automatically transition data between tiers to balance storage costs and retrieval times, which is ideal for data with changing access patterns.
- **Robust Enterprise Security and Compliance:** Microsoft places a strong emphasis on security, offering features like Azure Active Directory integration for identity and access management, role-based access control (RBAC), and encryption for data at rest and in transit. It also holds a vast portfolio of compliance certifications, making it suitable for regulated industries.
- **Massive Global Data Center Footprint:** Azure’s extensive global network allows organizations to store data in specific geographic regions. This is essential for reducing latency by locating data closer to users and for meeting data sovereignty and residency requirements mandated by local regulations.

#### Disadvantages**:**

- The pricing model can be complex, with costs determined by storage capacity, the number and type of operations, and data transfer options.
- Significant egress fees for moving data out of the Azure cloud can result in high costs for data-heavy applications and contribute to vendor lock-in.

#### Ideal For:

- Enterprises that have standardized on Microsoft technologies, including Windows Server, Office 365, and the broader Azure cloud platform.
- Developers building applications using the .NET Framework can benefit from the native integration and tooling.
- Organizations in regulated industries that require a provider with a strong focus on security and an extensive list of compliance certifications.

### Emerging Solutions to Watch

New providers are entering the space with specialized offerings are entering the market all the time. For instance, Atlantic.Net is developing our own object storage solution. The introduction of new services is expected to increase competition, giving users more storage options that can help effectively manage data and balance cost with performance. Keep an eye on our website for more information in the near future.

## Conclusion

The selection of an object storage provider is a critical decision for data management. Amazon S3 offers a mature and feature-rich ecosystem, making it a reliable choice for many. Meanwhile, providers like Wasabi and Cloudflare R2 challenge the traditional pricing model of the cloud object storage service by eliminating egress fees, which is a major benefit for data-heavy applications.

Google Cloud Storage provides a high-performance option for those integrated with its analytics and machine learning platforms. For organizations that need control over their infrastructure, MinIO offers a flexible solution for building private or hybrid cloud environments. Ultimately, the best object storage solution depends on specific needs related to cost-effectiveness, performance, data durability, and the desire to avoid vendor lock-in.


---

# How to Select the Best HIPAA Hosting Provider for Small Businesses

> URL: https://www.atlantic.net/hipaa-compliant-hosting/how-to-select-the-best-hipaa-hosting-provider-for-small-business/ | Published: 2025-10-03 | Author: Robert Agar

Businesses that process and store specific types of healthcare information in the United States are required to comply with the data security and privacy regulations established in the Health Insurance Portability and Accountability Act (HIPAA).

Many small businesses lack the in-house computing resources or data centers necessary to support a HIPAA-compliant infrastructure. The failure to maintain this regulatory compliance can result in large fines and reputational damage that is hard to overcome.

The article examines the criteria that a small business must meet to be subject to HIPAA compliance. We then discuss the details of HIPAA guidelines and their impact on a business. Finally, we investigate the HIPAA solutions available to small businesses for deploying compliant hosting solutions.

## Does Your Business Need a HIPAA-Compliant Hosting Provider?

Companies that process or store Protected Health Information (PHI) are required to comply with HIPAA regulations. HIPAA defines PHI as any health-related information that can be linked to an individual. PHI includes medical records, billing details, and other personal data used when providing healthcare services. When PHI is stored and transmitted electronically, it is referred to as electronic Protected Health Information (ePHI).

Examples of PHI include health-related personal information such as a patient’s name, date of birth, and Social Security number. It also includes patient data such as lab results, prescriptions, and treatment plans. Other PHI artifacts include billing information and patient emails.

Two types of companies are required to comply with HIPAA requirements. If your small business fits into one of these categories, you must utilize a HIPAA-compliant IT infrastructure to process and store ePHI.

### Covered entities (CEs)

A covered entity is typically engaged in directly providing healthcare or health insurance. HIPAA defines three different types of covered entities:

- Healthcare organizations and healthcare providers, such as doctors, clinics, and pharmacies, that transmit health data electronically;
- Health plans such as health insurance companies and HMOs;
- Healthcare clearinghouses that convert non-standard health data into standard formats to facilitate billing and claims processing.

### Business associates (BAs)

A business associate is a vendor or contractor providing third-party services for or on behalf of a covered entity and has access to the CE’s PHI. Many different types of organizations may be considered BAs, including:

- Cloud service providers like Amazon Web Services (AWS), Microsoft Azure, or the Google Cloud Platform (GCP);
- Billing companies and medical coders;
- Data backup and recovery providers;
- IT support vendors with access to healthcare data;
- Electronic Health Record (EHR) providers.

All business associates are required to sign a Business Associate Agreement (BAA) with the covered entity. The BAA outlines how the BA will protect the CE’s PHI.

Organizations that are exempt from HIPAA compliance regulations include most employers, except those that operate a self-funded health plan. A company may be a hybrid entity that performs multiple functions, of which only a subset requires HIPAA compliance. An example of a hybrid entity is a university that operates an academic department not covered by HIPAA and a hospital that requires HIPAA-compliant services.

## What Is HIPAA Compliance?

Companies categorized as covered entities or business associates must ensure HIPAA compliance by handling PHI in a manner that incorporates the following characteristics.

It’s also important to note that modern standards require HITECH compliance, which updated HIPAA rules to address health technology and strengthen penalties for violations

- **Privacy** – CEs and BAs must ensure the privacy of PHI by restricting access to sensitive patient data. Specific guidelines are set in the HIPAA Privacy Rule.
- **Security** – Companies must protect ePHI with the administrative, physical, and technical safeguards defined in the HIPAA Security Rule.
- **Breach notification** – Organizations are required to notify the authorities and affected parties if a data breach involving PHI occurs.
- **Documentation** – Companies must maintain documentation regarding the policies and risk assessments related to handling PHI.
- **Training** – CEs and BAs must provide regular training to employees who work with PHI.
- **Business Associate Agreements** – BAAs are required to document the responsibilities of third parties in securing PHI.

## The Main HIPAA Rules

Organizations must comply with the requirements of the following rules, which define their responsibilities for protecting PHI. Failure to address these rules effectively can result in HIPAA violations, which may lead to substantial penalties and fines.

### HIPAA Privacy Rule

The Privacy Rule regulates the use and disclosure of PHI by CEs and BAs. It covers all forms of PHI, including written, oral, and electronic information. The rule also provides patients with specific rights to access, amend, and limit who else can view their sensitive data.

### HIPAA Security Rule

The Security Rule focuses exclusively on ePHI and how organizations must protect it from unauthorized access, deletion, modification, or transmission. The rule requires companies to implement three types of safeguards to secure ePHI.

#### Administrative Safeguards

These are designed to manage security risks and workforce behavior. Required controls include:

- Conducting a risk analysis and managing identified vulnerabilities through a formal HIPAA risk management program;
- Assigning a security officer as the focal point for HIPAA compliance;
- Implementing role-based access controls (RBAC);
- Providing employees with security awareness training;
- Signing BAAs with vendors and subcontractors;
- Developing backup and disaster recovery plans to ensure the availabil**i**ty of ePHI.

#### Physical Safeguards

Physical protections ensure the physical security of electronic systems that store and process ePHI. The controls include:

- Limiting access to facilities that handle ePHI;
- Ensuring the security of workstations processing ePHI;
- Managing the secure disposal of devices and media containing ePHI.

#### Technical Safeguards

These define the technologies and policies organizations must implement to protect ePHI. The safeguards include:

- Access controls such as unique user IDs and session timeouts;
- Audit controls that log and monitor access to ePHI systems;
- Integrity controls to restrict unauthorized changes to ePHI;
- Authentication controls such as biometrics and two-factor authentication;
- Transmission controls to protect ePHI using methods such as data encryption, often using Transport Layer Security (TLS).

### HIPAA Breach Notification Rule

The Breach Notification Rule requires CEs and BAs to notify affected individuals, the U.S. Department of Health and Human Services (HHS), and perhaps the media under certain circumstances when there is a breach of unsecured PHI.

Notices must contain a description of the breach, the type of PHI involved, and the steps individuals can take to protect themselves from identity theft.

## What Is HIPAA-compliant Web Hosting?

As you can see, implementing HIPAA compliance is not a trivial exercise. Many small businesses lack the technical expertise and resources necessary to comply with the stringent requirements for protecting PHI. However, healthcare organizations do not have the option of ignoring HIPAA guidelines.

HIPAA-compliant HIPAA web hosting solutions offer companies a reliable and efficient method for achieving and maintaining HIPAA compliance. Through Managed Services, companies can leverage cloud-based HIPAA compliance services rather than implement a compliant solution themselves.

Specific types of hosting services are suitable for ensuring HIPAA compliance. Customers need to work with a reputable hosting provider that offers HIPAA-compliant services. The following table outlines typical hosting options and their ability to provide HIPAA compliance services.

| **Hosting type** | HIPAA compliance |
| --- | --- |
| **Shared hosting** | Not compliant as it does not enforce data isolation to protect ePHI |
| **Dedicated servers** | Yes, with security and monitoring in place |
| **Cloud hosting** | Yes, with the proper configuration and a signed BAA |

## How to Choose the Best HIPAA Compliant Hosting for Your Business

Decision-makers must make the correct choice when seeking a HIPAA-compliant hosting solution. The decision should be influenced by the company’s technical capabilities, budget, and the amount of control they want over the hosting environment. Typically, the choice is between a dedicated server solution and cloud hosting.

### [Dedicated servers](https://www.atlantic.net/dedicated-server-hosting/)

Companies may choose to deploy a dedicated HIPAA-compliant server to address HIPAA compliance requirements. This option requires the customer to assume responsibility for the majority of HIPAA safeguards and requirements.

The provider must implement the physical safeguards necessary to protect the ePHI resident on the servers. Customers must address most of the administrative and technical safeguards to ensure the servers are HIPAA-compliant.

Organizations utilizing dedicated hosting need to engage a reputable provider that offers HIPAA-compliant infrastructure with robust enterprise networks. The company needs a skilled technical team to ensure all safeguards are correctly implemented and maintained.

They will be tasked with performing HIPAA compliance monitoring and promptly resolving any issues and security vulnerabilities.

Enterprise customers with experienced technical resources are well-suited for a dedicated server solution. The additional control over the environment aligns with an enterprise corporate mindset.

### [HIPAA-compliant cloud hosting solutions](https://www.atlantic.net/hipaa-compliant-hosting/)

Small businesses may find cloud hosting offers a more efficient method of meeting HIPAA compliance requirements. In this case, the managed hosting provider is responsible for implementing HIPAA safeguards to ensure the privacy and security of ePHI.

The customer can minimize their technical input into the environment, focus on their core business, and achieve true HIPAA compliance.

Potential customers should ensure that the hosting provider they choose meets the following key requirements.

- The provider must sign a BAA outlining their responsibilities and demonstrate compliance expertise. Companies should not proceed with a hosting provider that will not sign a BAA.
- All ePHI must be encrypted while in transit and at rest, ideally within a secure HIPAA vault environment.
- The provider must offer a comprehensive data protection strategy, including secure backups, disaster recovery services, and contingency plans to address emergencies
- The provider must guarantee the physical security of the hardware used for ePHI processing.
- The provider must offer HIPAA compliance support by conducting regular risk assessments to identify security vulnerabilities.
- The provider should offer enterprise-grade security features like a Web Application Firewall (WAF), DDoS protection, and a content delivery network (CDN) to further secure and accelerate data access.

## Conclusion

Small businesses can leverage the offerings of cloud providers to meet their HIPAA requirements. Dedicated servers offer more control but require additional technical skills to ensure compliance.

HIPAA-compliant cloud hosting with a [reputable provider](https://www.atlantic.net/hosting-services-provider/) is an excellent way for a small business with limited technical resources or budget constraints to maintain HIPAA compliance.


---

# A Practical Guide to Train-Test Splits in Machine Learning on Ubuntu 24.04 GPU Server

> URL: https://www.atlantic.net/gpu-server-hosting/a-practical-guide-to-train-test-splits-in-machine-learning-on-ubuntu-24-04-gpu-server/ | Published: 2025-10-03 | Updated: 2026-05-04 | Author: Hitesh Jethva

When building a machine learning model, one of the first and most important steps is to evaluate its performance on data it has never seen before. This is where the concept of a train-test split comes in.

A train-test split is the process of dividing your dataset into two (or sometimes three) parts:

- Training set → used by the model to learn patterns.
- Testing set → used to evaluate the model’s performance on unseen data.
- (Optional) Validation set → used during training to fine-tune hyperparameters.

Without a proper split, your model might memorize the training data instead of learning general patterns, leading to overfitting. By splitting the dataset, you create a more realistic testing scenario that mirrors how your model will behave in the real world.

In this tutorial, you’ll learn how to perform train-test splits step by step on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/).

## Prerequisites

- An Ubuntu 24.04 server with an NVIDIA GPU.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1 – Setting Up the Environment

Before we dive into splitting datasets, we need to prepare our Ubuntu 24.04 GPU server with the right tools. This involves installing Python, creating a virtual environment, and setting up the required libraries for machine learning.

1. Install Python and other tools.

```bash
apt install -y python3 python3-venv python3-pip git
```

2. Create and activate a virtual environment.

```bash
python3 -m venv ml-env
source ml-env/bin/activate
```

3. Update pip to the latest version.

```bash
pip install --upgrade pip
```

4. Install required Python libraries.

```bash
pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu121
pip install scikit-learn pandas matplotlib
```

5. Check if your GPU is available for PyTorch.

```bash
python3 -c "import torch; print(torch.cuda.is_available())"
```

Output.

```bash
True
```

If it prints True, your setup is ready for GPU-powered experiments.

## Step 2 – Basic Train-Test Split with Scikit-learn

The most common way to split data in machine learning is by using the **train_test_split** function from scikit-learn. Let’s start with a simple example using the Iris dataset, a small dataset of flower measurements often used in ML demos.

1. Create a script.

```bash
nano train_test_split_demo.py
```

Add the following code.

```bash
#!/usr/bin/env python3
import pandas as pd
from sklearn.model_selection import train_test_split
from sklearn.datasets import load_iris

# Load dataset
iris = load_iris(as_frame=True)
X = iris.data
y = iris.target

# Perform split (80% training, 20% testing)
X_train, X_test, y_train, y_test = train_test_split(
    X, y, test_size=0.2, random_state=42
)

print("Training set size:", X_train.shape)
print("Testing set size:", X_test.shape)
```

2. Run the script.

```bash
python3 train_test_split_demo.py
```

Output shows that out of 150 samples, 120 are used for training and 30 for testing.

```bash
Training set size: (120, 4)
Testing set size: (30, 4)
```

This basic split is often enough for quick experiments. However, in real-world scenarios, reproducibility and balanced splits are important, which we’ll cover next.

## Step 3 – Reproducible Splits with Random Seeds

When you randomly split a dataset, the results can differ each time you run the script. This may lead to inconsistent results during experiments. To solve this, we use a random seed (via the random_state parameter) to make splits reproducible.

1. Create a new script.

```bash
nano reproducible_split.py
```

Add the following code:

```bash
#!/usr/bin/env python3
from sklearn.model_selection import train_test_split
from sklearn.datasets import load_iris

iris = load_iris(as_frame=True)
X = iris.data
y = iris.target

# Fixed seed
X_train, X_test, y_train, y_test = train_test_split(
    X, y, test_size=0.3, random_state=123
)

print("Train size:", X_train.shape)
print("Test size:", X_test.shape)
```

2. Run the script.

```bash
python3 reproducible_split.py
```

Output.

```bash
Train size: (105, 4)
Test size: (45, 4)
```

This is very useful when comparing models or sharing code with others because it guarantees consistent results.

## Step 4 – Stratified Splits for Balanced Classes

Sometimes datasets have imbalanced classes (e.g., more samples of one category than others). If you randomly split such a dataset, the training and testing sets might not reflect the same class proportions, which can bias your model.

To avoid this, we use a stratified split. This ensures that each class appears in the train and test sets with the same proportion as in the full dataset.

1. Create the script.

```bash
nano stratified_split.py
```

Add the following code:

```bash
#!/usr/bin/env python3
import pandas as pd
from sklearn.model_selection import train_test_split
from sklearn.datasets import load_iris

iris = load_iris(as_frame=True)
X = iris.data
y = iris.target

# Stratified split
X_train, X_test, y_train, y_test = train_test_split(
    X, y, test_size=0.3, stratify=y, random_state=42
)

print("Training class distribution:\n", y_train.value_counts(normalize=True))
print("Testing class distribution:\n", y_test.value_counts(normalize=True))
```

2. Run the script.

```bash
python3 stratified_split.py
```

Output.

```bash
Training class distribution:
 target
1    0.333333
0    0.333333
2    0.333333
Name: proportion, dtype: float64
Testing class distribution:
 target
2    0.333333
1    0.333333
0    0.333333
Name: proportion, dtype: float64
```

In the Iris dataset, each of the three flower types makes up exactly 33.3% of the data, and you can see that both training and testing sets preserve this distribution.

Stratified splits are especially useful for classification problems with imbalanced datasets, such as fraud detection or medical diagnoses.

## Step 5 – Train-Validation-Test Split

In many projects, using just a train-test split isn’t enough. You also need a validation set to tune hyperparameters, compare models, and avoid overfitting before touching the test data.

1. Create a validation script.

```bash
nano train_val_test_split.py
```

Add the following code.

```bash
#!/usr/bin/env python3
from sklearn.model_selection import train_test_split
from sklearn.datasets import load_iris

iris = load_iris(as_frame=True)
X = iris.data
y = iris.target

# First: temp + test
X_temp, X_test, y_temp, y_test = train_test_split(
    X, y, test_size=0.2, random_state=42
)

# Second: train + validation
X_train, X_val, y_train, y_val = train_test_split(
    X_temp, y_temp, test_size=0.25, random_state=42
)  # 0.25 of 0.8 = 0.2 overall

print("Train:", X_train.shape)
print("Validation:", X_val.shape)
print("Test:", X_test.shape)
```

2. Run the script.

```bash
python3 train_val_test_split.py
```

Output.

```bash
Train: (90, 4)
Validation: (30, 4)
Test: (30, 4)
```

**Explanation**

- First, we split 80% for train+validation and 20% for test.
- Then, we split that 80% again into 75% training and 25% validation, which results in:
- 60% training (90 samples)
- 20% validation (30 samples)
- 20% testing (30 samples)

This ensures that your model selection process never touches the test set, keeping it as a true “final exam” for your model.

## Step 6 – Visualizing Splits

Numbers are helpful, but sometimes it’s easier to see how your data is divided. A quick visualization of class distributions in the train and test sets can confirm that the split worked as expected.

1. Create a script for visualization.

```bash
nano split_visualization.py
```

Add the following code.

```bash
#!/usr/bin/env python3
import matplotlib.pyplot as plt
from sklearn.model_selection import train_test_split
from sklearn.datasets import load_iris

iris = load_iris(as_frame=True)
X = iris.data
y = iris.target

X_train, X_test, y_train, y_test = train_test_split(
    X, y, test_size=0.3, stratify=y, random_state=42
)

plt.hist(y_train, bins=len(set(y)), alpha=0.7, label="Train")
plt.hist(y_test, bins=len(set(y)), alpha=0.7, label="Test")
plt.legend()
plt.title("Train vs Test Class Distribution")
plt.savefig("split_distribution.png")
print("Visualization saved as split_distribution.png")
```

2. Run the script.

```bash
python3 split_visualization.py
```

Output.

```bash
Visualization saved as split_distribution.png
```

A file named **split_distribution.png** will be created in your project directory. Open it, and you’ll see a histogram comparing class counts in the training and test sets.

![](https://www.atlantic.net/wp-content/uploads/2025/08/split_distribution.png)

## Step 7 – Train-Test Splits with PyTorch

So far, we’ve used scikit-learn for splitting datasets. But when working with deep learning in PyTorch, you’ll often load data into a TensorDataset and then split it using PyTorch utilities.

1. Create a script.

```bash
nano pytorch_split.py
```

Add the following code.

```
#!/usr/bin/env python3
import torch
from torch.utils.data import random_split, TensorDataset
from sklearn.datasets import load_iris

# --- Suggested Change Start ---
# For reproducible splits, set the PyTorch random seed
torch.manual_seed(42)
# --- Suggested Change End ---

iris = load_iris(as_frame=True)
X = torch.tensor(iris.data.values, dtype=torch.float32)
y = torch.tensor(iris.target.values, dtype=torch.long)

dataset = TensorDataset(X, y)

# 80/20 split
train_size = int(0.8 * len(dataset))
test_size = len(dataset) - train_size
train_dataset, test_dataset = random_split(dataset, [train_size, test_size])

print("Train samples:", len(train_dataset))
print("Test samples:", len(test_dataset))
```

2. Run the script.

```bash
python3 pytorch_split.py
```

Output.

```bash
Train samples: 120
Test samples: 30
```

**Explanation**

- **TensorDataset(X,** y) → bundles features and labels into a dataset PyTorch can work with.
- **random_split** → divides the dataset into train and test sets based on defined sizes.
- The split is compatible with PyTorch’s DataLoader, making it easy to feed batches into your model.

This approach is very common in deep learning workflows where datasets are stored as tensors rather than Pandas DataFrames.

## Conclusion

In this guide, you explored the different ways to split datasets for machine learning on an Ubuntu 24.04 GPU server. You started with a simple train-test split using scikit-learn, then moved to reproducible splits with fixed seeds, balanced stratified splits, and extended the process to include a validation set. You also learned how to visualize splits for better understanding and performed splits directly in PyTorch for deep learning workflows.


---

# How to Build a Linear Regression Model from Scratch on Ubuntu 24.04 GPU Server

> URL: https://www.atlantic.net/gpu-server-hosting/how-to-build-a-linear-regression-model-from-scratch-on-ubuntu-24-04-gpu-server/ | Published: 2025-10-04 | Updated: 2026-05-04 | Author: Hitesh Jethva

Linear regression is one of the most fundamental algorithms in machine learning. It models the relationship between input features (independent variables) and an output (dependent variable) by fitting a straight line. Despite its simplicity, linear regression is widely used in business forecasting, trend analysis, and scientific research.

In this tutorial, you’ll learn how to build a linear regression model from scratch on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/).

## Prerequisites

- An Ubuntu 24.04 server with an NVIDIA GPU.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1 – Set Up the Environment

Before building the model, you need a proper Python environment with the right libraries installed. Since we’re working on Ubuntu 24.04 with GPU support, we’ll prepare a virtual environment and install PyTorch with CUDA, along with data and plotting libraries.

1. Install required packages.

```bash
apt install -y python3 python3-pip python3-venv git
```

2. Create and activate a virtual environment.

```bash
python3 -m venv venv
source venv/bin/activate
```

3. Install additional dependencies.

```bash
pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu121
pip install numpy matplotlib pandas
```

4. Verify the GPU availability.

```bash
python3 -c "import torch; print(torch.cuda.is_available())"
```

Output.

```bash
True
```

If you see True, your server is ready to train models with GPU acceleration.

## Step 2 – Generate a Sample Dataset

To train and test our linear regression model, we first need some data. Instead of using a public dataset, we’ll generate a simple one based on a known equation:

```bash
y=4+3X+noise
```

This will allow us to verify whether our model can correctly learn the intercept (4) and slope (3).

1. Create the data generation script.

```bash
nano generate_data.py
```

Add the following code.

```bash
#!/usr/bin/env python3
import numpy as np
import pandas as pd

# Generate random data
np.random.seed(42)
X = 2 * np.random.rand(100, 1)
y = 4 + 3 * X + np.random.randn(100, 1)  # y = 4 + 3X + noise

# Save to CSV
data = np.hstack([X, y])
df = pd.DataFrame(data, columns=["X", "y"])
df.to_csv("linear_data.csv", index=False)

print("Dataset saved as linear_data.csv")
```

2. Run the script to generate the dataset.

```bash
python3 generate_data.py
```

Output.

```bash
Dataset saved as linear_data.csv
```

Now we have a clean dataset stored in linear_data.csv that we’ll use for training both CPU and GPU versions of our linear regression model.

## Step 3 – Build Linear Regression from Scratch

Now that we have our dataset, let’s build a linear regression model from scratch using only NumPy. This will help us understand how gradient descent optimizes parameters step by step.

1. Create the script.

```bash
nano linear_regression.py
```

Add the following code.

```bash
#!/usr/bin/env python3
import numpy as np
import pandas as pd
import matplotlib.pyplot as plt

# Load dataset
data = pd.read_csv("linear_data.csv")
X = data["X"].values.reshape(-1, 1)
y = data["y"].values.reshape(-1, 1)

# Add bias column (for intercept term)
X_b = np.c_[np.ones((X.shape[0], 1)), X]

# Initialize parameters (theta = [bias, weight])
theta = np.random.randn(2, 1)

# Hyperparameters
learning_rate = 0.1
iterations = 1000
m = len(X)

# Gradient Descent
for i in range(iterations):
    gradients = (2/m) * X_b.T.dot(X_b.dot(theta) - y)
    theta -= learning_rate * gradients

print("Learned parameters (intercept, slope):", theta.ravel())

# Predictions
y_pred = X_b.dot(theta)

# Plot
plt.scatter(X, y, color="blue", label="Data")
plt.plot(X, y_pred, color="red", label="Prediction")
plt.xlabel("X")
plt.ylabel("y")
plt.legend()
plt.savefig("regression_plot.png")
plt.show()
```

2. Run the model.

```bash
python3 linear_regression.py
```

Output.

```bash
Learned parameters (intercept, slope): [4.21509616 2.77011339]
```

The script generates a plot **regression_plot.png** that shows:

- Blue dots → Original dataset.
- Red line → Predicted regression line.

![](https://www.atlantic.net/wp-content/uploads/2025/08/regression_plot.png)

This confirms that our model successfully approximated the real equation **y=4+3X** even with added noise.

## Step 4 – Accelerate with GPU (PyTorch)

Our NumPy implementation works well, but training larger datasets can be slow on the CPU. To speed things up, we’ll use PyTorch and run the training on the GPU.

1. Create a script.

```bash
nano linear_regression_gpu.py
```

Add the following code.

```bash
#!/usr/bin/env python3
import torch
import pandas as pd
import numpy as np

# Load dataset
data = pd.read_csv("linear_data.csv")
X = data["X"].values.reshape(-1, 1)
y = data["y"].values.reshape(-1, 1)

# Add bias column (for intercept term)

X_b = np.c_[np.ones((X.shape[0], 1)), X]

# Select device
device = "cuda" if torch.cuda.is_available() else "cpu"
print("Using device:", device)

# Convert data to torch tensors
X_tensor = torch.tensor(X_b, dtype=torch.float32).to(device)
y_tensor = torch.tensor(y, dtype=torch.float32).to(device)

# Initialize parameters (theta = [bias, weight])
theta = torch.randn((2,1), dtype=torch.float32, device=device, requires_grad=True)

# Optimizer
optimizer = torch.optim.SGD([theta], lr=0.1)

# Training loop
for i in range(1000):
    y_pred = X_tensor @ theta
    loss = torch.mean((y_pred - y_tensor) ** 2)
    optimizer.zero_grad()
    loss.backward()
    optimizer.step()

print("Learned parameters on GPU:", theta.detach().cpu().numpy().ravel())
```

2. Run the training on your GPU.

```bash
python3 linear_regression_gpu.py
```

Output.

```bash
Using device: cuda
Learned parameters on GPU: [4.215091  2.7701175]
```

Notice how the learned values are almost identical to those from the CPU version:

- CPU: [4.21509616, 2.77011339]
- GPU: [4.215091, 2.7701175]

Both converge close to the true equation **y=4+3X.** The main advantage of GPU computation is speed, which becomes significant with much larger datasets.

## Conclusion

In this tutorial, you learned how to build a linear regression model from scratch on an Ubuntu 24.04 GPU server. Starting from a synthetic dataset, you implemented gradient descent manually with NumPy on the CPU, then accelerated the same process with PyTorch on the GPU.


---

# Analyze Tornado Data with Python and GeoPandas on Ubuntu 24.04 GPU

> URL: https://www.atlantic.net/gpu-server-hosting/analyze-tornado-data-with-python-and-geopandas-on-ubuntu-24-04-gpu/ | Published: 2025-10-05 | Updated: 2025-10-06 | Author: Hitesh Jethva

Tornadoes are among the most destructive natural disasters in the United States, causing widespread damage to property, infrastructure, and human lives. Understanding where tornadoes occur and how they move is critical for risk assessment, emergency planning, and climate research.

In this tutorial, you’ll learn how to analyze tornado data using Python on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). We’ll use NOAA’s (National Oceanic and Atmospheric Administration) Storm Events Dataset, which provides detailed records of tornado events, including their location, timing, and severity.

## Prerequisites

- An Ubuntu 24.04 server with an NVIDIA GPU.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1 – Install Dependencies

To start analyzing tornado data, you need the right tools installed on your Ubuntu 24.04 GPU server. We’ll set up Python, system libraries for geospatial processing, and Python packages for analysis and visualization.

1. GeoPandas and related libraries require GDAL and Fiona for handling spatial data. Install them along with Python tools.

```bash
apt install -y python3 python3-venv python3-pip git wget unzip gdal-bin libgdal-dev
```

2. It’s a good practice to isolate dependencies in a virtual environment.

```bash
python3 -m venv tornado-env
source tornado-env/bin/activate
```

3. Next, upgrade pip and install the required Python libraries.

```bash
pip install --upgrade pip
pip install geopandas pandas matplotlib shapely pyproj fiona requests
```

These packages cover data analysis (pandas), geospatial processing (GeoPandas, Shapely, Fiona), and visualization (Matplotlib).

4. For larger datasets, GPU acceleration speeds up analysis. Install cudf-cu12 from NVIDIA’s PyPI index.

```bash
pip install cudf-cu12 --extra-index-url=https://pypi.nvidia.com
```

This gives you a pandas-like API that runs on the GPU for big-data tornado analysis.

## Step 2 – Download NOAA Tornado Dataset

The National Oceanic and Atmospheric Administration (NOAA) maintains the Storm Events Database, which includes detailed records of tornadoes, floods, hurricanes, and other severe weather events across the United States. For this tutorial, we’ll focus on tornado events from the year 2010.

1. Create a directory for the dataset.

```bash
mkdir datasets && cd datasets
```

2. Download the 2010 storm events CSV file.

```bash
wget https://www.ncei.noaa.gov/pub/data/swdi/stormevents/csvfiles/StormEvents_details-ftp_v1.0_d2010_c20250520.csv.gz
```

This file contains tornado records and other storm-related events for the year 2010.

3. Unzip the compressed file so it’s ready for analysis.

```bash
gunzip StormEvents_details-ftp_v1.0_d2010_c20250520.csv.gz
```

4. Move back to the root directory to keep your workflow clean.

```bash
cd ..
```

## Step 3 – Load and Inspect Data with Pandas

Now that the dataset is downloaded and extracted, the first step is to load it into Python and explore its structure. We’ll use pandas, a powerful library for data analysis.

1. Create a script to load data.

```bash
nano load_data.py
```

Add the following code.

```bash
#!/usr/bin/env python3
import pandas as pd

# Load tornado dataset
df = pd.read_csv("datasets/StormEvents_details-ftp_v1.0_d2010_c20250520.csv")

print("First five rows:")
print(df.head())
```

2. Run the script.

```bash
python3 load_data.py
```

Output.

```bash
First five rows:
   BEGIN_YEARMONTH  BEGIN_DAY  BEGIN_TIME  ...                                  EPISODE_NARRATIVE                                    EVENT_NARRATIVE  DATA_SOURCE
0           201007          7        1251  ...  A strong ridge built into Southern New England...  Heat index values at the Nashua Boire Field (K...          CSV
1           201001         17        2300  ...  A coastal storm passing southern New England j...  Four to eight inches fell across eastern Hills...          CSV
2           201010          1         830  ...  Several waves of low pressure moved across Sou...  In Manchester, firefighters responded to about...          CSV
3           201007          6         951  ...  A strong ridge built into Southern New England...  Heat index values at the Manchester Airport (K...          CSV
4           201012         26        1700  ...  A strengthening winter storm passed southeast ...  Snowfall totals of 6 to 10 inches were observe...          CSV

[5 rows x 51 columns]
```

The NOAA Storm Events dataset contains over 50 columns. A few important ones for tornado analysis are:

- **EVENT_TYPE** – The type of storm (we’ll filter for Tornado).
- **BEGIN_LAT** / **BEGIN_LON** – The starting point of the tornado.
- **END_LAT** / **END_LON** – The ending point of the tornado.
- **BEGIN_YEARMONTH, BEGIN_DAY, BEGIN_TIME** – Date and time of the event.
- **EVENT_NARRATIVE** – A text description of what happened.

## Step 4 – Convert Tornado Events into GeoDataFrame

Now that we’ve explored the dataset, the next step is to filter out tornado events and convert their coordinates into geospatial objects. This will allow us to map tornado tracks across the U.S. using GeoPandas.

1. Create a script for conversion.

```bash
nano convert_to_geodata.py
```

Add the code below.

```bash
#!/usr/bin/env python3
import pandas as pd
import geopandas as gpd
from shapely.geometry import LineString

# Load dataset
df = pd.read_csv("datasets/StormEvents_details-ftp_v1.0_d2010_c20250520.csv")

# Filter only tornado events
df = df[df['EVENT_TYPE'] == 'Tornado']

print(f"Total tornado events: {len(df)}")

# Function to create LineString geometry (only if coords are valid)
def create_lines(row):
    if pd.notnull(row['BEGIN_LON']) and pd.notnull(row['BEGIN_LAT']) \
       and pd.notnull(row['END_LON']) and pd.notnull(row['END_LAT']):
        return LineString([(row['BEGIN_LON'], row['BEGIN_LAT']),
                           (row['END_LON'], row['END_LAT'])])
    return None

df['geometry'] = df.apply(create_lines, axis=1)

# Drop rows with invalid geometries
df = df.dropna(subset=['geometry'])

# Convert to GeoDataFrame
gdf = gpd.GeoDataFrame(df, geometry='geometry', crs="EPSG:4326")

print(gdf.head())
print(f"Valid tornado geometries: {len(gdf)}")
```

2. Run the script.

```bash
python3 convert_to_geodata.py
```

Output.

```bash
Total tornado events: 1449
     BEGIN_YEARMONTH  BEGIN_DAY  BEGIN_TIME  ...                                    EVENT_NARRATIVE  DATA_SOURCE                                           geometry
75            201011         30          46  ...  An NWS Storm Survey found a weak EF0 tornado t...          CSV    LINESTRING (-92.1172 30.4366, -92.0965 30.4405)
304           201011         30        1945  ...  A tornado damage path was surveyed starting in...          CSV        LINESTRING (-82.605 34.829, -82.583 34.863)
617           201010         18        1643  ...  An EF-0 tornado, with winds estimated at 75 mp...          CSV  LINESTRING (-113.9737 35.2023, -113.9821 35.1859)
731           201011         29        1512  ...  Numerous trees were snapped near the intersect...          CSV     LINESTRING (-92.808 31.7947, -92.6528 31.9479)
732           201011         29        1618  ...  The tornado touched down in an inaccessible wo...          CSV    LINESTRING (-92.1872 32.2802, -92.1248 32.2864)

[5 rows x 52 columns]
Valid tornado geometries: 1449
```

You now have a GeoDataFrame of tornado paths ready for visualization. Next, we’ll plot these tornado tracks on a map using Matplotlib and GeoPandas.

## Step 5 – Visualize Tornado Tracks

After converting tornado events into geospatial features, the next step is to plot tornado paths on a map. This gives us a clear visual representation of where tornadoes occurred and how they moved.

1. Create a script for plotting.

```bash
nano plot_tornado_paths.py
```

Add the code below.

```bash
#!/usr/bin/env python3
import pandas as pd
import geopandas as gpd
from shapely.geometry import LineString
import matplotlib.pyplot as plt

# Load data
df = pd.read_csv("datasets/StormEvents_details-ftp_v1.0_d2010_c20250520.csv")

# Filter tornado events only
df = df[df['EVENT_TYPE'] == 'Tornado']

# Function to create LineString geometry
def create_lines(row):
    if pd.notnull(row['BEGIN_LON']) and pd.notnull(row['BEGIN_LAT']) \
       and pd.notnull(row['END_LON']) and pd.notnull(row['END_LAT']):
        return LineString([(row['BEGIN_LON'], row['BEGIN_LAT']),
                           (row['END_LON'], row['END_LAT'])])
    return None

df['geometry'] = df.apply(create_lines, axis=1)

# Drop invalid geometries
df = df.dropna(subset=['geometry'])

# Convert to GeoDataFrame
gdf = gpd.GeoDataFrame(df, geometry='geometry', crs="EPSG:4326")

print(f"Total tornado tracks to plot: {len(gdf)}")

# Plot tornado paths
fig, ax = plt.subplots(figsize=(12, 8))
gdf.plot(ax=ax, color="red", linewidth=1, alpha=0.7)

plt.title("Tornado Tracks - NOAA Storm Events (2010)", fontsize=16)
plt.xlabel("Longitude")
plt.ylabel("Latitude")

# Save figure
plt.savefig("tornado_tracks.png", dpi=300)
print("Map saved as tornado_tracks.png")
```

2. Run the script.

```bash
python3 plot_tornado_paths.py
```

Output.

```bash
Total tornado tracks to plot: 1449
Map saved as tornado_tracks.png
```

This creates a file called **tornado_tracks.png** that shows tornado paths in red lines.

![](https://www.atlantic.net/wp-content/uploads/2025/08/tornado_tracks.png)

You now have a visual tornado map generated from NOAA’s dataset. Next, we’ll enhance this analysis by adding U.S. state boundaries and creating a hotspot (density) map.

## Step 6 – Add U.S. State Boundaries and Hotspot Mapping

Plotting tornado paths gives us an overview, but to identify which states are most affected, we need to overlay tornado tracks with U.S. state boundaries. By performing a spatial join, we can count tornadoes per state and visualize hotspots.

1. Download the U.S. state shapefile.

```bash
wget https://www2.census.gov/geo/tiger/GENZ2018/shp/cb_2018_us_state_20m.zip
unzip cb_2018_us_state_20m.zip -d states
```

This creates a folder states/ containing the shapefile components.

2. Create a hotspot analysis script.

```bash
nano tornado_hotspots.py
```

Add the following code.

```bash
#!/usr/bin/env python3
import pandas as pd
import geopandas as gpd
from shapely.geometry import LineString
import matplotlib.pyplot as plt

# Load tornado data
df = pd.read_csv("datasets/StormEvents_details-ftp_v1.0_d2010_c20250520.csv")


# Filter only tornado events
df = df[df['EVENT_TYPE'] == 'Tornado']

# Function to create LineString geometry
def create_lines(row):
    if pd.notnull(row['BEGIN_LON']) and pd.notnull(row['BEGIN_LAT']) \
       and pd.notnull(row['END_LON']) and pd.notnull(row['END_LAT']):
        return LineString([(row['BEGIN_LON'], row['BEGIN_LAT']),
                           (row['END_LON'], row['END_LAT'])])
    return None

df['geometry'] = df.apply(create_lines, axis=1)

# Drop invalid geometries
df = df.dropna(subset=['geometry'])

# Convert to GeoDataFrame
gdf = gpd.GeoDataFrame(df, geometry='geometry', crs="EPSG:4326")

print(f"Valid tornado tracks: {len(gdf)}")

# Load US state boundaries (NAD83)
states = gpd.read_file("states/cb_2018_us_state_20m.shp")

# Reproject states to match tornado CRS (WGS84)
states = states.to_crs(epsg=4326)

# Spatial join: tornadoes intersecting states
joined = gpd.sjoin(gdf, states, predicate="intersects")

# Count tornadoes per state
state_counts = joined.groupby("NAME")["EVENT_ID"].count().reset_index()

# Merge counts with state geometries
states = states.merge(state_counts, on="NAME", how="left")

# Plot tornado density
fig, ax = plt.subplots(figsize=(12, 8))
states.plot(column="EVENT_ID", cmap="Reds", legend=True, ax=ax, edgecolor="black")

plt.title("Tornado Density by State (2010)")
plt.savefig("tornado_density.png", dpi=300)
print("Hotspot map saved as tornado_density.png")
```

2. Run the script.

```bash
python3 tornado_hotspots.py
```

Output.

```bash
Valid tornado tracks: 1449
Hotspot map saved as tornado_density.png
```

This creates a file **tornado_density.png** showing a choropleth map where states are shaded in red based on the number of tornadoes.

![](https://www.atlantic.net/wp-content/uploads/2025/08/tornado_density.png)

You now have a state-level tornado density map. Next, we’ll look at how to use GPU acceleration with cuDF to process this NOAA dataset much faster than pandas.

## Step 7 – GPU-Accelerated Analysis with cuDF

When working with large NOAA storm event datasets (spanning decades), pandas on CPU can become slow. To speed things up, we can use cuDF, a RAPIDS library that mimics pandas but runs entirely on the GPU.

This lets us filter, aggregate, and explore millions of records with lightning-fast performance.

1. Create a script for GPU analysis.

```bash
nano gpu_analysis.py
```

Add the following code.

```bash
#!/usr/bin/env python3
import cudf

df_gpu = cudf.read_csv("datasets/StormEvents_details-ftp_v1.0_d2010_c20250520.csv")
print(df_gpu.head())
```

2. Run the script.

```bash
python3 gpu_analysis.py
```

Output.

```bash
   BEGIN_YEARMONTH  BEGIN_DAY  BEGIN_TIME  ...                                  EPISODE_NARRATIVE                                    EVENT_NARRATIVE  DATA_SOURCE
0           201007          7        1251  ...  A strong ridge built into Southern New England...  Heat index values at the Nashua Boire Field (K...          CSV
1           201001         17        2300  ...  A coastal storm passing southern New England j...  Four to eight inches fell across eastern Hills...          CSV
2           201010          1         830  ...  Several waves of low pressure moved across Sou...  In Manchester, firefighters responded to about...          CSV
3           201007          6         951  ...  A strong ridge built into Southern New England...  Heat index values at the Manchester Airport (K...          CSV
4           201012         26        1700  ...  A strengthening winter storm passed southeast ...  Snowfall totals of 6 to 10 inches were observe...          CSV

[5 rows x 51 columns]
```

With cuDF, we loaded NOAA data into GPU memory, filtered tornado events instantly, and grouped them by month at high speed. On multi-year datasets with millions of rows, cuDF can deliver 10x–50x faster performance than pandas, making it ideal for large-scale tornado analysis.

## Conclusion

In this tutorial, you learned how to analyze tornado data from NOAA using Python, GeoPandas, and GPU acceleration with cuDF on Ubuntu 24.04. We loaded and inspected the dataset, converted tornado records into geospatial tracks, visualized their paths, mapped state-level hotspots, and leveraged GPU power for faster analysis.

This workflow shows how combining open datasets, geospatial libraries, and GPU acceleration can uncover meaningful insights into tornado patterns. You can extend this further by analyzing multiple years, comparing seasonal trends, or integrating population data to study risk impact.


---

# How to Install and Use InvokeAI on Ubuntu 24.04 GPU Server

> URL: https://www.atlantic.net/gpu-server-hosting/how-to-install-and-use-invokeai-on-ubuntu-24-04-gpu-server/ | Published: 2025-10-06 | Author: Hitesh Jethva

InvokeAI is an advanced image generation toolkit built on top of Stable Diffusion, a powerful text-to-image deep learning model. It allows you to generate highly realistic or artistic images simply by describing them in natural language. Unlike basic tools, InvokeAI provides a web-based user interface (WebUI), model manager, and GPU acceleration support, making it more flexible and efficient for creators, researchers, and developers.

In this tutorial, you’ll learn how to install and use InvokeAI on a Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/).

## Prerequisites

- An Ubuntu 24.04 server with an NVIDIA GPU.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1 – Install Required Packages

Before installing InvokeAI, you need to prepare your Ubuntu 24.04 GPU server with the required tools and dependencies. This ensures that your installation runs smoothly without conflicts.

1. Update the system packages.

```bash
apt update -y
```

2. Install essential tools.

```bash
apt install git python3-venv python3-pip -y
```

## Step 2 – Cloning the InvokeAI Repository

Now that your environment is ready, the next step is to download the InvokeAI source code. The official project is hosted on GitHub, so you can easily clone it to your server.

1. Run the following command to clone InvokeAI.

```bash
git clone https://github.com/invoke-ai/InvokeAI.git
```

This will create a new folder called InvokeAI in your current directory.

2. Switch to the newly created directory.

```bash
cd InvokeAI
```

At this point, you have the latest InvokeAI source code on your system. Next, we’ll create a Python virtual environment inside this directory to manage dependencies.

## Step 3 – Setting Up a Python Virtual Environment

Using a Python virtual environment keeps InvokeAI’s dependencies isolated from your system’s global Python packages. This helps avoid version conflicts and makes it easier to manage upgrades or removals later.

1. Run the following command inside the InvokeAI directory.

```bash
python3 -m venv venv
```

This creates a new folder named venv that will store all Python dependencies for InvokeAI.

2. Activate the virtual environment.

```bash
source venv/bin/activate
```

Now that the virtual environment is ready, we can move forward with installing InvokeAI and its dependencies.

## Step 4 – Installing InvokeAI and Dependencies

With the virtual environment active, the next step is to install InvokeAI and all required Python packages.

1. First, update pip, setuptools, and wheel to their latest versions for smoother installations.

```bash
pip install --upgrade pip setuptools wheel
```

2. Now install InvokeAI directly using pip.

```bash
pip install invokeai
```

This will download and install the latest version of InvokeAI along with its dependencies. Since you are inside a virtual environment, these packages will not affect your global Python setup.

## Step 5 – Launching the Web Interface

After installing InvokeAI, you can start the web interface (WebUI), which provides an easy-to-use dashboard for generating images.

1. Start the InvokeAI web.

```bash
invokeai-web --root ~/invokeai
```

2. Since your InvokeAI web interface is running on the server’s local network (port 9090), you need to forward this port to your local machine so you can access it in a browser.

On your local machine, run the following command (replace **your-server-ip** with your server’s IP).

```bash
ssh -L 9090:127.0.0.1:9090 root@your-server-ip
```

## Step 6 – Accessing the Web UI

With SSH port forwarding set up, you can now open the InvokeAI interface in your local browser.

1. On your local computer, open your preferred browser and go to **http://localhost:9090.** You should see the InvokeAI WebUI dashboard. From here, you can manage models, configure settings, and start generating images.

![](https://www.atlantic.net/wp-content/uploads/2025/08/p1-3.png)

2. Inside the InvokeAI WebUI, click on **Model Manager** from the sidebar. Click **Add Model.** In the **URL or Local Path** tab, paste the following model URL from Hugging Face:

```bash
https://huggingface.co/runwayml/stable-diffusion-v1-5/resolve/main/v1-5-pruned-emaonly.safetensors
```

![](https://www.atlantic.net/wp-content/uploads/2025/08/p2-2.png)

3. Click **Install.**

4. After installation completes, the model will appear in your **Available Models** list. You can now select it for image generation.

5. From the left sidebar in the WebUI, navigate back to the **Main Dashboard.**

6. In the prompt box, type the description **“A fantasy castle on a hill at sunset, cinematic, highly detailed”** and click the **Invoke** button. InvokeAI will process your text prompt using the installed model. Within a short time, you should see a beautiful AI-generated image appear in the results panel.

![](https://www.atlantic.net/wp-content/uploads/2025/08/p3-1.png)

## Conclusion

You’ve successfully installed and used InvokeAI on an Ubuntu 24.04 GPU server. In this guide, you prepared the environment, set up a virtual Python workspace, installed InvokeAI, launched the web interface, forwarded ports via SSH, added a Stable Diffusion model, and generated your first AI image.

InvokeAI makes text-to-image generation fast, flexible, and GPU-accelerated. From here, you can explore more models on Hugging Face, try advanced settings, or refine your prompts to unlock endless creative possibilities.


---

# How to Find Seasonality Patterns in Time Series Using Fourier Transforms on Ubuntu 24.04 GPU Server

> URL: https://www.atlantic.net/gpu-server-hosting/how-to-find-seasonality-patterns-in-time-series-using-fourier-transforms-on-ubuntu-24-04-gpu-server/ | Published: 2025-10-07 | Updated: 2026-05-04 | Author: Hitesh Jethva

Time series data often shows repeating cycles, called seasonality, such as weekly sales spikes or daily traffic peaks. Detecting these patterns is important for forecasting and decision-making.

The Fourier Transform is a powerful tool to uncover hidden cycles by breaking a signal into its frequency components. This makes it easy to spot dominant periodic trends like a 7-day weekly pattern.

In this tutorial, you’ll generate synthetic time series data, analyze it with NumPy (CPU), and then accelerate the process using CuPy (GPU) on Ubuntu 24.04.

## Prerequisites

- An Ubuntu 24.04 server with an NVIDIA GPU.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1 – Set Up a Python Environment

To keep your project organized and avoid conflicts with system-wide packages, it’s best to create a dedicated Python virtual environment.

1. First, install the required base tools.

```bash
apt install -y python3 python3-venv python3-pip git
```

2. Create an isolated environment.

```bash
python3 -m venv ts-env
```

3. Activate the environment.

```bash
source ts-env/bin/activate
```

4. Upgrade pip and install the libraries needed for time series analysis and GPU acceleration.

```bash
pip install --upgrade pip
pip install numpy matplotlib pandas
pip install cupy-cuda12x
```

## Step 2 – Generate a Sample Time Series

To demonstrate how to detect seasonality, you’ll first create a synthetic dataset that mimics real-world time series data. This dataset will contain a weekly seasonal pattern combined with some random noise.

1. Open a new file called generate_timeseries.py.

```bash
nano generate_timeseries.py
```

Add the following code.

```bash
#!/usr/bin/env python3
import numpy as np
import pandas as pd

# Generate a time index
days = pd.date_range(start="2024-01-01", periods=365, freq="D")

# Create seasonal pattern (weekly cycle) + noise
weekly_pattern = 10 * np.sin(2 * np.pi * np.arange(365) / 7)
noise = np.random.normal(0, 2, 365)
data = weekly_pattern + noise

# Save to CSV
df = pd.DataFrame({"date": days, "value": data})
df.to_csv("time_series.csv", index=False)

print("time_series.csv generated successfully")
```

2. Run the script.

```bash
python3 generate_timeseries.py
```

A new file named **time_series.csv** will be created. It contains two columns: date and value, where value represents the seasonal signal plus noise.

```bash
time_series.csv generated successfully
```

## Step 3 – Analyzing Seasonality with CPU-based FFT

Now that you have a synthetic dataset, the next step is to analyze it using the Fast Fourier Transform (FFT) with NumPy. This will let you uncover the hidden weekly cycle.

1. Create a new file called **seasonality_fft.py.**

```bash
nano seasonality_fft.py
```

Add the following code.

```bash
#!/usr/bin/env python3
import os
# Use a non-GUI backend if DISPLAY isn't set
if os.environ.get("DISPLAY", "") == "":
    import matplotlib
    matplotlib.use("Agg")

import pandas as pd
import numpy as np
import matplotlib.pyplot as plt

def main():
    df = pd.read_csv("time_series.csv", parse_dates=["date"])
    df = df.sort_values("date").reset_index(drop=True)

    # Estimate sampling interval (days) from timestamps
    deltas = df["date"].diff().dt.total_seconds().dropna() / 86400.0
    d = float(np.median(deltas)) if len(deltas) else 1.0  # default daily

    values = df["value"].to_numpy()
    n = len(values)

    fft_vals = np.fft.fft(values)
    fft_freq = np.fft.fftfreq(n, d=d)

    mask = fft_freq > 0
    positive_freqs = fft_freq[mask]
    positive_fft = np.abs(fft_vals[mask]) * (2.0 / n)  # scale amplitude

    plt.figure(figsize=(10, 5))
    plt.plot(positive_freqs, positive_fft, linewidth=1)
    plt.title(f"Frequency Spectrum (d = {d:.4f} days/sample)")
    plt.xlabel("Frequency (cycles/day)")
    plt.ylabel("Amplitude")
    plt.tight_layout()

    out = "fft_spectrum.png"
    plt.savefig(out, dpi=150)
    print(f"[OK] Saved spectrum to {out}")

    # Optional: print top 5 peaks
    top_idx = np.argsort(positive_fft)[-5:][::-1]
    print("\nTop 5 peaks:")
    for i in top_idx:
        freq = positive_freqs[i]
        period_days = 1.0 / freq if freq != 0 else float("inf")
        amp = positive_fft[i]
        print(f"  freq={freq:.6f} cycles/day  (~{period_days:.2f} days)  amplitude={amp:.4f}")

if __name__ == "__main__":
    main()
```

2. Run the script.

```bash
python3 seasonality_fft.py
```

You should see an output similar to:

```bash
[OK] Saved spectrum to fft_spectrum.png

Top 5 peaks:
  freq=0.142466 cycles/day  (~7.02 days)  amplitude=9.5641
  freq=0.145205 cycles/day  (~6.89 days)  amplitude=1.8724
  freq=0.139726 cycles/day  (~7.16 days)  amplitude=1.0879
  freq=0.136986 cycles/day  (~7.30 days)  amplitude=0.7250
  freq=0.147945 cycles/day  (~6.76 days)  amplitude=0.7032
```

The top peak at **~0.142** cycles/day corresponds to a **7-day** cycle, which matches the weekly pattern you added earlier.

## Step 4 – Accelerating FFT with GPU (CuPy)

While NumPy works well for small datasets, large-scale time series or real-time applications benefit from GPU acceleration. With CuPy, you can run the same FFT operations on the GPU, dramatically reducing computation time.

1. Create a new file called **seasonality_fft_gpu.py.**

```bash
nano seasonality_fft_gpu.py
```

Add the below code.

```bash
#!/usr/bin/env python3
import os
# Switch to non-GUI backend if no display
if os.environ.get("DISPLAY", "") == "":
    import matplotlib
    matplotlib.use("Agg")

import pandas as pd
import cupy as cp
import matplotlib.pyplot as plt

def main():
    # Load dataset
    df = pd.read_csv("time_series.csv", parse_dates=["date"])
    values = cp.array(df["value"].values)

    # FFT with GPU
    fft_vals = cp.fft.fft(values)
    fft_freq = cp.fft.fftfreq(len(values), d=1)

    # Convert back to NumPy for plotting
    mask = fft_freq > 0
    positive_freqs = cp.asnumpy(fft_freq[mask])
    positive_fft = cp.asnumpy(cp.abs(fft_vals[mask]))

    # Plot spectrum
    plt.figure(figsize=(10, 5))
    plt.plot(positive_freqs, positive_fft, linewidth=1)
    plt.title("Fourier Transform (GPU) - Frequency Spectrum")
    plt.xlabel("Frequency (cycles/day)")
    plt.ylabel("Amplitude")
    plt.tight_layout()

    out_file = "fft_spectrum_gpu.png"
    plt.savefig(out_file, dpi=150)
    print(f"[OK] Spectrum saved to {out_file}")

    # Optional: show top 5 peaks
    import numpy as np
    top_idx = np.argsort(positive_fft)[-5:][::-1]
    print("\nTop 5 peaks:")
    for i in top_idx:
        freq = positive_freqs[i]
        period_days = 1.0 / freq if freq != 0 else float("inf")
        amp = positive_fft[i]
        print(f"  freq={freq:.6f} cycles/day  (~{period_days:.2f} days)  amplitude={amp:.4f}")

if __name__ == "__main__":
    main()
```

2. Run the script.

```bash
python3 seasonality_fft_gpu.py
```

Expected output:

```bash
[OK] Spectrum saved to fft_spectrum_gpu.png

Top 5 peaks:
  freq=0.142466 cycles/day  (~7.02 days)  amplitude=1745.4544
  freq=0.145205 cycles/day  (~6.89 days)  amplitude=341.7149
  freq=0.139726 cycles/day  (~7.16 days)  amplitude=198.5501
  freq=0.136986 cycles/day  (~7.30 days)  amplitude=132.3208
  freq=0.147945 cycles/day  (~6.76 days)  amplitude=128.3347
```

Here too, the dominant frequency **(~0.142 cycles/day)** corresponds to a **7-day** weekly cycle. The difference is in amplitude scaling; GPU FFT outputs larger values, but the detected cycle remains the same.

## Step 5 – Comparing CPU vs. GPU Results

At this point, you’ve analyzed the same dataset using both NumPy (CPU) and CuPy (GPU). Let’s look at how the results compare.

**1. Frequency Detection**

Both approaches identify the dominant peak around 0.142 cycles/day, which translates to roughly 7 days per cycle. This confirms that the weekly pattern we built into the synthetic dataset has been correctly detected.

**2. Amplitude Differences**

You may notice that the amplitude values from the GPU output are much larger than those from the CPU run. This difference comes from internal scaling in the libraries, but it doesn’t affect the interpretation of the frequency peaks. The relative size of peaks is what matters for identifying seasonality.

**3. Performance**

- **CPU FFT (NumPy):** Works well for small datasets like our 365-day series.

![](https://www.atlantic.net/wp-content/uploads/2025/08/fft_spectrum.png)

- **GPU FFT (CuPy):** Shines with large datasets, streaming data, or when you need to run FFT repeatedly in real time. On a GPU-enabled server, you’ll typically see much faster execution compared to CPU.

![](https://www.atlantic.net/wp-content/uploads/2025/08/fft_spectrum_gpu.png)

**4. Visual Comparison**

Both scripts save frequency spectrum plots **(fft_spectrum.png** for CPU and **fft_spectrum_gpu.png** for GPU). You’ll see the same dominant weekly cycle in both graphs, confirming that GPU acceleration doesn’t change the result, only the speed.

In short, CPU analysis is fine for small-scale work. Still, if you’re analyzing millions of points or running Fourier analysis as part of a production pipeline, GPU acceleration can make a big difference.

## Conclusion

In this tutorial, you explored how to detect seasonality patterns in time series data using Fourier Transforms on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/). You began by setting up a clean Python environment with NumPy, Pandas, Matplotlib, and CuPy, then created a synthetic dataset containing a weekly cycle mixed with random noise. With this dataset, you applied a CPU-based FFT using NumPy to uncover the hidden seasonal component, and later accelerated the process with a GPU-based FFT using CuPy.


---

# Understanding Cloud Repatriation: Trends, Benefits, and Best Practices

> URL: https://www.atlantic.net/dedicated-server-hosting/understanding-cloud-repatriation-trends-benefits-and-best-practices/ | Published: 2025-10-08 | Author: Richard Bailey

Over the past decade, cloud-first strategies have dominated IT decision-making and migration strategies. The drive to the public cloud has been fast, with organizations expecting infinite scalability, flexibility, and pay-as-you-go pricing.

Many organizations that have been undertaking rapid digital transformation have seen large scale applications and data migration to their chosen cloud providers. Yet, as organizations mature in their cloud journey, a different story is emerging, with cloud repatriation becoming a focal point for many.

The operational realities of public cloud environments have led to a rising concern that not all workloads are suitable for cloud hosting. In some extreme cases, businesses have reported spiraling cloud costs, performance bottlenecks, and a loss of control.

As a result, we are definitely seeing an uptick in cloud repatriation: the strategic process of moving workloads from public cloud providers back to a private cloud [bare metal infrastructure](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/). This isn’t about abandoning cloud computing; it’s about evolving beyond a one-size-fits-all approach. It’s about smart workload placement, ensuring that every application runs on the platform that best serves its technical and business requirements. For a growing number of businesses, that platform is bare metal.

This guide will explore the drivers behind this shift and outline a practical cloud repatriation process, showing you how moving to a bare metal environment with a trusted partner like Atlantic.Net can unlock significant cost savings, superior performance, and enhanced control.

## Which Cloud Workloads Run Better on Bare Metal?

The true performance bottleneck for certain applications is not the cloud ecosystem itself, but a hypervisor’s virtualization layer. While excellent for general-purpose computing, this abstraction creates issues for workloads highly sensitive to latency, I/O, and performance consistency, prompting discussions around risk mitigation.

### I/O-Intensive Relational Databases (Oracle, MS SQL, large PostgreSQL)

In a virtualized cloud environment, databases often suffer from the “noisy neighbor” effect, where shared storage causes unpredictable I/O latency. The hypervisor also adds a small “tax” to every operation, creating a performance ceiling that simply adding more resources cannot overcome.

On bare metal, the database gets direct, uncontended access to NVMe storage, eliminating latency jitter. With 100% of the CPU’s power dedicated to its processes, performance increases significantly.

### Latency-Sensitive Platforms (High-Frequency Trading, Ad Bidding)

For applications where microseconds matter, the unpredictable network “jitter” and CPU scheduling delays inherent in a cloud environment are untenable. A momentary delay can directly impact revenue.

Bare metal provides the ultra-low, predictable network latency these platforms demand. It also allows critical processes to be pinned to specific CPU cores, guaranteeing consistent execution times without hypervisor or tenant interference.

### Network-Bound Big Data & HPC Clusters (Hadoop, Spark)

The performance of many big data and High-Performance Computing (HPC) jobs is limited by the speed of data shuffling between nodes. On a shared cloud network, this critical phase can become a major bottleneck, slowing job completion.

A bare metal cluster can be designed with a dedicated, high-speed network backplane (e.g., 25 GbE or 100 GbE) for internode communication, significantly accelerating these data-intensive tasks.

The decision is not about abandoning the cloud but choosing the right compute model for the workload.

## Why the Shift Back from the Public Cloud?

The conversation around cloud repatriation often begins with performance and compliance, but the reasons run much deeper. While achieving low latency for mission-critical applications or meeting the strict data residency requirements of heavily regulated industries are critical drivers, the move is often a calculated business decision focused on long-term sustainability and control.

### Unpredictable Cloud Costs vs. Predictable Savings

The most significant catalyst for repatriation is cost optimization. The flexible pricing model of the public cloud, once its main selling point, can become a financial headache for the wrong workload, making saving money a priority for many organizations. Hidden charges and variable expenses often lead to bill shock with the hyperscale providers

- **Data Egress Fees:** The most notorious expenses is data egress fees. Public cloud providers nearly always charge significant fees simply to move your own data out of their network, which can make analytics, backups, and multi-cloud strategies very expensive.
- **Spiraling Storage and Compute Costs:** As data volumes grow and applications scale, storage costs and compute resources on the cloud can quickly exceed budgets. The per-gigabyte or per-hour pricing model adds up, especially for steady-state workloads that run 24/7.
- **Operational Overhead:** Managing costs in a complex public cloud environment requires specialized tools and expertise, adding to the total cost of ownership.

In contrast, a bare metal on-premises environment—or more accurately, a dedicated environment in a provider’s data center—offers predictable, transparent pricing. With a fixed monthly cost for your dedicated hardware, you can budget effectively without fearing unexpected spikes in your bill. This shift from a variable operational expenditure (OpEx) model to a predictable, fixed one allows for genuine long-term cost savings, enhancing overall cost efficiency and a clearer ROI.

### Performance, Control, and Vendor Lock-in

With Shared Cloud Hosting, you share underlying hardware with other tenants, leading to resource contention and unpredictable performance, posing reliability challenges for latency-sensitive or I/O-intensive applications.

Bare metal eliminates this issue entirely. You get 100% of the server’s compute resources—CPU, RAM, and I/O—dedicated solely to your cloud workloads. This direct, uncontended access allows you to optimize performance for demanding tasks like databases, artificial intelligence (AI) model training, and high-traffic web services.

You choose the operating system, fine-tune the kernel, and configure the network exactly to your specifications. This level of control is crucial for security and helps to avoid vendor lock-in, where your applications become so deeply integrated with a specific cloud provider’s proprietary cloud services that migrating away becomes a significant technical and financial hurdle.

### Security and Compliance

While public cloud security has improved, the shared responsibility model can create gaps. Data breaches remain a constant threat, and proving compliance in a multi-tenant environment can be complex. Moving workloads to a private cloud infrastructure on bare metal gives you complete control over your security posture, allowing for tailored security measures.

You can implement your own security measures, from dedicated firewalls and intrusion detection systems to customized access controls. This is vital for organizations handling sensitive data or operating in heavily regulated industries like healthcare and finance.

Data residency regulations (like GDPR) require data to be stored in specific geographic locations. With a provider like Atlantic.Net, which has data centers across the globe, you can choose the precise location of your bare metal servers, ensuring you meet data residency and sovereignty requirements with strict controls.

## The Cloud Repatriation Process

A successful cloud migration back to bare metal requires strategic planning and methodical execution. It’s not always a simple lift-and-shift; but an opportunity to re-architect for better efficiency and performance.

Here’s how an Atlantic.Net customer would approach the repatriation process.

### Step 1: Strategic Analysis and Workload Assessment

Before moving anything, you must analyze your existing cloud workloads. Not every application is a good candidate for repatriation. The goal is to identify the workloads that will benefit most from the performance, cost, and control of bare metal.

- **Identify the Pain Points:** Which applications are incurring the highest cloud costs? Which ones suffer from inconsistent performance or latency issues?
- **Categorize Your Workloads:**
  - **Prime Candidates for Repatriation:** Stable, predictable workloads with high performance demands (e.g., large databases, analytics platforms, AI workloads).
  - **Candidates for a Hybrid Approach:** Applications with variable or “burstable” traffic might benefit from staying in the public cloud to handle peaks.
  - **Cloud-Native Services:** Workloads heavily reliant on proprietary cloud services may present significant hurdles to move and might be better left in place.
- **Consider the Challenges:** A balanced assessment must also weigh the downsides. Repatriation introduces new responsibilities, such as increased management overhead for hardware and OS patching. You may lose access to the provider’s managed services, meaning your team is now responsible for tasks like database backups and high availability. Finally, the near-instant scalability of the public cloud is replaced by a model where scaling requires provisioning new physical hardware.
- **Define Success Metrics:** Align the move with clear business objectives. Are you aiming to reduce TCO by 30%? Achieve a specific latency target? These goals will guide your entire strategy.

### Step 2: Designing Your New Bare Metal Infrastructure

Once you’ve identified which workloads to move, the next step is designing their new environment. This is where partnering with an experienced provider is invaluable. The Atlantic.Net team works with you to architect a solution tailored to your specific needs.

- **Server Sizing:** We help you select the right combination of CPU, RAM, and storage (NVMe for performance, HDD for bulk storage) to match your application requirements, ensuring future scalability.
- **Network Architecture:** We’ll design a secure and resilient network topology, including private networking between your servers, firewalls, and load balancers to support your mission-critical applications.
- **Data Migration Strategy:** We help you plan the most efficient and secure way to conduct the data transfer, whether it’s over a high-speed internet connection or using a physical data import/export service to minimize downtime and data loss.

### Step 3: Data Migration and Application Testing

This is the core technical phase of the cloud repatriation. The key is to minimize disruptions to your live servers.

- **Execute the Data Migration:** Using the planned strategy, begin the data migration. This often involves an initial bulk transfer followed by ongoing synchronization to keep the source and destination in sync until the final cutover.
- **Refactor and Configure:** Applications may need minor adjustments to run on a bare metal OS instead of a hypervisor. This is the time to implement automated configuration management tools (like Ansible, Puppet, or Chef) to build your new environment efficiently and ensure desired state enforcement (ensuring the configuration remains consistent and correct over time).
- **Thorough Testing:** Before directing any live traffic, rigorously test everything in the new environment. This includes performance testing, security scanning, and failover testing to ensure everything functions as expected and that you achieve a smooth transition.

### Step 4: Cutover, Optimization, and Embracing a Hybrid Future

The final step is the cutover. This is typically done during a planned maintenance window to minimize impact. Once traffic is flowing to your new Atlantic.Net bare metal servers, the job isn’t over.

- **Monitor and Optimize:** Continuously monitor your application’s performance and resource utilization. With bare metal, you have the granular management capability to fine-tune the OS and hardware settings to extract every ounce of performance and optimize costs.
- **Embrace the Hybrid Cloud:** Cloud repatriation doesn’t have to be an all-or-nothing proposition. The most effective strategy for many is a hybrid cloud model. Your performance-sensitive databases can run on Atlantic.Net bare metal, while your front-end web servers can auto scale in the Atlantic.Net public cloud. We help you build a hybrid cloud infrastructure, ensuring seamless integration between your public and private clouds for ultimate flexibility.

## Choosing the Right Home for Your Workloads

The cloud repatriation trend is a sign of a maturing industry. The initial rush to adopt cloud services is being replaced by a more thoughtful, strategic approach to cloud infrastructure. The question is no longer “Should we be in the cloud?” but “Where should each specific workload run to achieve its objectives?”

For many organizations, especially those with demanding, stable, and data-intensive applications, the answer is increasingly bare metal. Moving from the public cloud offers a clear path to reducing long-term costs, regaining control over your server infrastructure, and building a more resilient, high-performance foundation for your business.

At Atlantic.Net, with 30 years in the industry and a global footprint of data centers, we understand the complexities of infrastructure management. We believe in giving our customers flexible solutions and provide the right tools for the job. If you’re one of the many customers moving workloads and considering strategic cloud repatriation to improve service quality and achieve real cost savings, our experts are here to help you plan and execute a seamless and successful migration.

Want to learn more? [Reach out to the experts](https://www.atlantic.net/about-us/corporate-contact/) in the bare metal repatriation process.


---

# HIPAA-by-Design: Building a Compliant Cloud from the Ground Up

> URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-by-design-building-a-compliant-cloud-from-the-ground-up/ | Published: 2025-10-08 | Author: Richard Bailey

As healthcare organizations rush to modernize, many migrate to the cloud first and think about compliance later. This reactive approach often leads to costly retrofits, frantic policy changes, and significant security holes that can put sensitive patient data at risk. A smarter, more secure strategy is to adopt a “HIPAA-by-Design” philosophy, embedding compliance into the very foundation of your cloud infrastructure.

This proactive mindset isn’t just about checking boxes on a list; it’s about creating a reliable and resilient cloud environment that protects electronic protected health information (PHI) from the ground up. By building with HIPAA compliance at the forefront of the design process, healthcare providers are able to avoid future headaches, reduce costs, and focus on what truly matters: delivering exceptional patient care.

This article will introduce the concept of HIPAA-by-design, and demonstrate how Atlantic.Net cloud computing services are helping support HIPAA compliance to a large customer base of HIPAA covered entities. Highlighting the potential risks of failing to ensure security of patient sensitive information.

## Who Needs to Be HIPAA Compliant? Understanding Covered Entities

The first step in any compliance journey is understanding where you fit. The Health Insurance Portability and Accountability Act (HIPAA) and its subsequent HIPAA rules apply to two main groups:

1. **Covered Entities:** These are the frontline organizations in healthcare. The category includes health plans, healthcare clearinghouses, and healthcare providers who electronically transmit health information. If your organization provides treatment, payment, or operations in healthcare, you are likely a covered entity.
2. **Business Associates:** This group includes any vendor or subcontractor that creates, receives, maintains, or transmits PHI on behalf of a covered entity. This is where your cloud service provider (CSP) comes in, and its exactly what Atlantic.Net provide to our HIPAA clients. When you store PHI in a cloud computing environment, the provider becomes one of your business associates.

This relationship is critical. You cannot simply move patient data to any cloud storage solution. You must partner with a cloud hosting provider that understands its role and is willing to formalize its responsibilities, provide physical security, a compliant cloud based service, network and compute that exceeds HIPAA standards, and of course HIPAA compliant cloud storage that meets industry standards.

## Healthcare Providers – Business Associate Agreement (BAA)

Before a single byte of electronic protected health information (ePHI) is moved to the cloud, a [Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) must be in place. A BAA is more than a formality; it’s a legally binding contract that outlines how your chosen cloud service provider will protect sensitive data.

The BAA details the provider’s responsibilities for safeguarding ePHI, the permissible uses of the data, breach notification procedures, and requirements for subcontractors. Without a signed BAA, your organization is not HIPAA compliant, no matter how secure the provider’s infrastructure claims to be. A reputable provider will offer a BAA as a standard component of their HIPAA compliant cloud services.

At Atlantic.Net, we understand our role in the shared responsibility model of compliance. In this model, Atlantic.Net secures the underlying cloud infrastructure, while you, the client, are responsible for securing the data and applications you place in the cloud, including managing user access and configuring security settings.

Atlantic.Net works closely with our clients to help them achieve compliance, we can guide and advise you how to prepare your systems, and how to keep data safe when other covered entities process phi. We provide a comprehensive BAA for all our HIPAA-compliant hosting clients, establishing a clear framework of accountability from day one.

## The HIPAA Privacy Rule and Security Rule

Every healthcare professional needs to know about these fundamental rules. These core HIPAA guidelines, which have now been significantly strengthened by the Health Information Technology for Economic and Clinical Health (HITECH) Act, are principally divided into two main rules that dictate the “what” and “how” of protecting patient information.

### HIPAA Privacy Rule

The HIPAA Privacy Rule establishes national standards for protecting individuals’ medical records and other identifiable health information. It focuses on *what* data is protected and sets limits on its use and disclosure without patient authorization. It also gives patients rights over their own health information, including the right to examine and obtain a copy of their health records.

### Security Rule

While the Privacy Rule sets the standards, the HIPAA Security Rule dictates *how* to protect ePHI. This rule is more technical and flexible, allowing organizations to implement technologies and processes appropriate for their size and complexity.

The Security Rule is built on three categories of safeguards:

#### **Technical Safeguards:**

These are the technology and related policies used to protect ePHI and control access to it. At Atlantic.Net, we implement a suite of managed services that directly address these requirements.

To enforce strong access controls and user authentication, we deploy [Multi-Factor Authentication](https://www.atlantic.net/hipaa-compliant-hosting/two-factor-authentication-vs-multi-factor-authentication-the-best-log-in-security/)(MFA). For data in transit, our Encrypted VPN and mandatory TLS Certificates ensure information is unreadable to unauthorized parties. For data at rest, we utilize strong encryption across our Encrypted Storage and [Encrypted Backup solutions](https://www.atlantic.net/disaster-recovery/).

Network security is hardened with our Fully Managed Firewall Appliance, which is configured and maintained by our experts to block malicious traffic. To meet the need for continuous oversight, our Log Inspection System provides the detailed audit trails necessary to track all access and activity involving sensitive information, forming a complete technological defense for your data.

#### **Physical Safeguards:**

These focus on securing the physical locations where ePHI is stored. While you manage your applications, Atlantic.Net secures the underlying infrastructure.

Your data resides in our world-class, NIST certified [data centers](https://www.atlantic.net/hipaa-data-centers/), which are protected by stringent physical access controls, including 24/7/365 security personnel, biometric scanners, and continuous video surveillance.

Our facilities are designed for resilience and security, a fact that is independently verified by our SOC 2 Type II and SOC 3 Type II [certifications](https://www.atlantic.net/hosting-services-provider/certifications-and-partnerships/). These reports validate that our controls for security and availability meet the highest industry standards, ensuring your ePHI is physically protected from environmental threats and unauthorized access.

#### **Administrative Safeguards:**

This is the operational side of security, such as the policies and procedures that govern your compliance strategy. While you are responsible for your own internal policies and risk management, partnering with Atlantic.Net strengthens your administrative posture.

As mentioned previously, the partnership is founded by the Business Associate Agreement (BAA), an essential administrative control that formally defines our responsibilities in protecting your ePHI.

Our entire hosting environment is HIPAA and HITECH audited, giving you confidence that our own procedures are sound. Our IT professionals are available 24/7 to provide expert support, acting as an extension of your team to help you with any the complexities of maintaining a compliant cloud environment.

### Architecting a HIPAA Compliant Cloud Environment

Building a HIPAA compliant cloud from the ground up requires a multi-layered approach that addresses all aspects of the Security Rule. This means partnering with a cloud provider that offers more than just server space; you need a partner with a deep understanding of the HIPAA requirements.

Here are the essential components for your HIPAA compliant storage architecture:

#### **Private Hosted Environment:**

Your server infrastructure should be completely isolated from other tenants. At Atlantic.Net, our experienced engineers configure private, segmented environments to ensure the integrity and confidentiality of your data. We recommend dedicated hosts for HIPAA compliance, but you can also achieve this with bare metal servers or with our cloud hosting options.

#### **Managed Firewalls:**

A WAF firewall is a non-negotiable requirement. We combine perimeter and server-side firewalls, which we deploy, maintain, and manage to protect against evolving threats. WAFs are dynamically updated which means they are protected against zero-day threats immediately. The rules we apply to the WAF harden your environment from even the most advanced threats.

#### **Encrypted VPN and Storage:**

All ePHI must be encrypted, both at rest in secure cloud storage and in transit over your network. These protects ensure your patient data is always protected, combine this with robust access controls and you ePHI is in safe hands. Atlantic.Net ensures your VPN and storage volumes meet the HIPAA encryption standards expected from a cloud storage provider.

#### **Multi-Factor Authentication (MFA):**

Verifying user identity is crucial for preventing unauthorized access. We offer multi-factor authentication solutions to add a critical layer of security to your access management protocols. Its essential to train your employees to follow the best practice security standards when managing user accounts and access controls. Atlantic.Net are happy to help guide you to create a strong security posture.

#### **Onsite and Offsite Backups:**

HIPAA mandates that you have a reliable data backup and a disaster recovery plan. We provide fully managed daily backups, with both onsite copies for rapid recovery and offsite copies for protection against catastrophic events. Our HIPAA compliant cloud is redundant and can be configure to offer failover for your critical applications and services to ensure continuously service in the event of a disaster.

#### **Continuous Monitoring and Logging:**

To stay compliant, one of the regular security assessments you must achieve is being able to track who has accessed ePHI and when. Our SIEM log inspection systems and real-time monitoring provide the detailed audit trails necessary to these HIPAA regulations.

### Why a “HIPAA-by-Design” Approach Leads to Better Patient Outcomes

When data security is integral to your IT operations, it creates a stable foundation for innovation. A secure HIPAA compliant cloud ensures that data is available when and where healthcare teams need it, without compromising patient privacy. This reliability allows care providers to use technologies such as telehealth platforms and data analytics with confidence, leading to more informed decisions and ultimately, better outcomes for patients.

Achieving this level of trust and innovation requires a partnership with a provider that has a long-standing commitment to security and compliance. For 30 years, Atlantic.Net has been a strategic partner to organizations with mission-critical compliance needs. Our HIPAA-Compliant Hosting solutions are built on a foundation of security and stability, backed by our world-class data center infrastructure and a [100% Uptime SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/). Our environment is not only HIPAA and HITECH audited but has also achieved SOC 2 Type II and SOC 3 Type II certifications.

From fully managed firewalls and encrypted backups to 24/7/365 high-touch support from our compliance specialists, we provide the technical safeguards and expert guidance you need to build and maintain a secure and HIPAA compliant infrastructure. Don’t let compliance be an afterthought. Contact an [Atlantic.Net advisor today](https://www.atlantic.net/about-us/corporate-contact/) to build your HIPAA compliant cloud the right way, right from the start.


---

# How to Use DeepSeek R1 for Code Generation and Debugging on Ubuntu 24.04 GPU Server

> URL: https://www.atlantic.net/gpu-server-hosting/how-to-use-deepseek-r1-for-code-generation-and-debugging-on-ubuntu-24-04-gpu-server/ | Published: 2025-10-11 | Updated: 2026-05-04 | Author: Hitesh Jethva

In modern software development, AI-powered tools are becoming valuable companions for programmers. DeepSeek R1 is one such tool that helps you generate code snippets, fix bugs, and automate repetitive programming tasks. Instead of spending hours debugging or writing boilerplate code, you can offload these tasks to DeepSeek and focus on solving higher-level problems.

In this tutorial, you’ll learn how to use DeepSeek R1 for Code generation and debugging on an Ubuntu 24.04 GPU server.

## Prerequisites

- An Ubuntu 24.04 server with an NVIDIA GPU.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1 – Install System Dependencies

Before setting up DeepSeek R1, you need to install the essential packages required for building and running Python applications on Ubuntu 24.04.

1. Update the package index.

```
apt update -y
```

2. Install required system packages.

```
apt install -y git curl wget build-essential python3 python3-pip python3-venv
```

## Step 2 – Clone and Set Up DeepSeek R1 Repository

With the dependencies installed, the next step is to get a copy of the DeepSeek R1 project from GitHub. This repository contains the scripts and configuration files you’ll use to run the model.

1. Clone the DeepSeek R1 GitHub repository.

```
git clone https://github.com/deepseek-ai/DeepSeek-R1.git
```

2. Navigate to the downloaded repository.

```
cd DeepSeek-R1
```

3. Create a virtual environment for your project.

```
python3 -m venv venv
```

4. Activate the virtual environment.

```
source venv/bin/activate
```

5. Upgrade pip to the latest version.

```
pip install --upgrade pip
```

6. Next, install PyTorch compiled with CUDA 12.4 so the model can run on your GPU.

```
pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu124
```

7. Finally, install the Hugging Face ecosystem libraries.

```
pip install transformers accelerate huggingface_hub
```

8. Verify that PyTorch is correctly installed.

```
python3 -c "import torch; print(torch.__version__)"
```

Output.

```
2.6.0+cu124
```

## Step 3 – Authenticate with Hugging Face

DeepSeek R1 models are hosted on Hugging Face, so you’ll need to log in and download them before use. Authentication ensures you can access the model files and keep them locally on your server.

1. First, log in using your Hugging Face token.

```
huggingface-cli login
```

When prompted, enter your token.

2. Next, download the DeepSeek Coder model to a local directory.

```
huggingface-cli download deepseek-ai/deepseek-coder-1.3b-base --local-dir ./deepseek-coder
```

3. Once the download finishes, check if the model files exist.

```
ls ./deepseek-coder | grep bin
```

Output.

```
pytorch_model.bin
```

The model is now stored locally and ready for use. In the next step, you’ll generate your first piece of code with DeepSeek R1.

## Step 4 – Generate Code with DeepSeek R1

Now that the model is downloaded, let’s generate Python code using DeepSeek R1. We’ll create a script that sends a natural language prompt to the model and retrieves executable code.

1. Create a new file called deepseek_generate.py.

```
nano deepseek_generate.py
```

Add the following content:

```
from transformers import AutoTokenizer, AutoModelForCausalLM
import torch

# Load from local directory
model_name = "./deepseek-coder"
tokenizer = AutoTokenizer.from_pretrained(model_name)
model = AutoModelForCausalLM.from_pretrained(
    model_name,
    device_map="auto",
    dtype=torch.float16,
    trust_remote_code=True
)

prompt = "Write a Python function that checks if a number is prime."
inputs = tokenizer(prompt, return_tensors="pt").to("cuda")

with torch.no_grad():
    outputs = model.generate(**inputs, max_length=150)

generated_code = tokenizer.decode(outputs[0], skip_special_tokens=True)
print("\n=== Generated Code ===\n")
print(generated_code)
```

2. Run the script.

```
python3 deepseek_generate.py
```

You should see output like this:

```
=== Generated Code ===

Write a Python function that checks if a number is prime.

The function should take a number as input and return True if the number is prime and False otherwise.

You can assume that the input number is an integer.

Example:

Input: 19
Output: True

Input: 11
Output: False


def is_prime(number):
    if number == 1:
        return False
    for i in range(2, number):
        if number % i == 0:
            return False
    return True


print(is_prime(19))
print(is_prime(11))
```

✅ Congratulations! You just generated your first working Python function using DeepSeek R1.

## Step 5 – Debug Python Code with DeepSeek R1

DeepSeek R1 can also automatically repair broken Python scripts. This is especially useful when you hit runtime errors or logic bugs. Let’s try it with a simple example.

1. Create a buggy script.

```
nano buggy_script.py
```

Add the following code.

```
def divide(a, b):
    return a / b

print(divide(5, 0))
```

2. Create the debugger script.

```
nano deepseek_debug.py
```

Add the following code.

```
from transformers import AutoTokenizer, AutoModelForCausalLM
import sys, torch, re

model_name = "./deepseek-coder"
tokenizer = AutoTokenizer.from_pretrained(model_name)
model = AutoModelForCausalLM.from_pretrained(
    model_name,
    device_map="auto",
    dtype=torch.float16,
    trust_remote_code=True
)

if len(sys.argv) < 2:
    print("Usage: python deepseek_debugger.py ")
    sys.exit(1)

filename = sys.argv[1]
with open(filename, "r") as f:
    buggy_code = f.read()

prompt = (
    "Fix the following Python code.\n"
    "Respond with ONLY Python code inside a ```python ... ``` block.\n"
    "Do not include explanations.\n\n"
    f"{buggy_code}"
)

inputs = tokenizer(prompt, return_tensors="pt").to("cuda")

with torch.no_grad():
    outputs = model.generate(**inputs, max_length=500)

text_output = tokenizer.decode(outputs[0], skip_special_tokens=True)

# Find all python code blocks
matches = re.findall(r"```(?:python)?(.*?)```", text_output, re.DOTALL)

if matches:
    # Take the last block (most complete version)
    code_output = matches[-1].strip()
else:
    # fallback: treat the entire output as code
    code_output = text_output.strip()

# Save fixed code
with open("fixed_buggy_script.py", "w") as f:
    f.write(code_output)

print("\n=== Fixed Code (saved to fixed_buggy_script.py) ===\n")
print(code_output)
```

3. Run the debugger

```
python3 deepseek_debug.py buggy_script.py
```

Output.

```
Setting `pad_token_id` to `eos_token_id`:32014 for open-end generation.

=== Fixed Code (saved to fixed_buggy_script.py) ===

def divide(a, b):
    if b == 0:
        return None
    return a / b

print(divide(5, 5))
```

✅ DeepSeek R1 automatically fixed the bug and saved the corrected code in fixed_buggy_script.py.

## Step 6 – Create the CLI Code Generator

DeepSeek R1 can also be used as a CLI tool where you pass prompts directly from the command line, and it generates working Python code for you. This makes it convenient to quickly create code snippets without needing to write additional scripts.

1. Create a file called deepseek_codegen.py.

```
nano deepseek_codegen.py
```

Add the following code.

```
from transformers import AutoTokenizer, AutoModelForCausalLM
import sys, torch, re

model_name = "./deepseek-coder"
tokenizer = AutoTokenizer.from_pretrained(model_name)
model = AutoModelForCausalLM.from_pretrained(
    model_name,
    device_map="auto",
    dtype=torch.float16,
    trust_remote_code=True
)

prompt = " ".join(sys.argv[1:])
# Force model to return code only
prompt = f"{prompt}\n\nReturn only valid Python code. No text, no explanations."

inputs = tokenizer(prompt, return_tensors="pt").to("cuda")

with torch.no_grad():
    outputs = model.generate(**inputs, max_length=300)

text_output = tokenizer.decode(outputs[0], skip_special_tokens=True)

# Try to extract code from triple backticks
match = re.search(r"```(?:python)?(.*?)```", text_output, re.DOTALL)
if match:
    code_output = match.group(1).strip()
else:
    # fallback: assume whole output is code
    code_output = text_output.strip()

with open("generated_code.py", "w") as f:
    f.write(code_output)

print("\n=== Generated Code (saved to generated_code.py) ===\n")
print(code_output)
```

2. Run the following command to generate a Fibonacci script.

```
python3 deepseek_codegen.py "Print first 20 Fibonacci numbers"
```

Output.

```
=== Generated Code (saved to generated_code.py) ===

def fib(n):
    if n == 0:
        return 0
    elif n == 1:
        return 1
    else:
        return fib(n-1) + fib(n-2)

for i in range(20):
    print(fib(i))
```

3. Execute the generated script.

```
python3 generated_code.py
```

Output.

```
0
1
1
2
3
5
8
13
21
34
55
89
144
233
377
610
987
1597
2584
4181
```

## Conclusion

In this tutorial, you learned how to set up and use DeepSeek R1 on an Ubuntu 24.04 GPU server for real-world coding tasks. Starting from installing system dependencies, creating a Python virtual environment, and authenticating with Hugging Face, you successfully downloaded the DeepSeek Coder model and ran it locally on your GPU.

With this setup, your [GPU server](https://www.atlantic.net/gpu-server-hosting/) effectively becomes an AI coding assistant, capable of speeding up development, reducing debugging time, and even acting as a boilerplate generator for everyday programming tasks.


---

# How to Run Jupyter Notebooks in the Browser with JupyterLite on Ubuntu 24.04 GPU server

> URL: https://www.atlantic.net/gpu-server-hosting/how-to-run-jupyter-notebooks-in-the-browser-with-jupyterlite-on-ubuntu-24-04-gpu-server/ | Published: 2025-10-12 | Updated: 2026-05-04 | Author: Hitesh Jethva

Jupyter notebooks are one of the most popular tools for data science, machine learning, and interactive coding. Traditionally, they run on a backend kernel such as Python, R, or Julia, requiring you to install Jupyter Notebook or JupyterLab along with all dependencies on your server. But with JupyterLite, things work differently.

JupyterLite is a lightweight distribution of JupyterLab that runs entirely in the browser, powered by WebAssembly and Pyodide. This means you can open and execute notebooks directly from your web browser without needing a dedicated Python kernel running in the background. It’s fast, portable, and ideal for lightweight coding, education, and demos.

In this guide, you’ll learn how to set up JupyterLite on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/).

## Prerequisites

- An Ubuntu 24.04 server with an NVIDIA GPU.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1 – Install Required Packages

To begin, you need to install Python, pip, and the virtual environment tools that will help you isolate your JupyterLite setup from the system environment. Ubuntu 24.04 already comes with Python 3, but it’s good practice to install the latest packages and confirm everything is ready.

1. Update all system packages.

```
apt update -y
```

2. Install Python3 and other packages.

```
apt install -y python3 python3-pip python3-venv
```

3. Once installed, check the versions to confirm everything is in place.

```
python3 --version
```

## Step 2 – Create a JupyterLite Project

Now that you have Python and pip installed, the next step is to create a dedicated project directory for JupyterLite. This keeps everything organized and avoids cluttering your system with random files.

1. Create a new directory and navigate into it.

```
mkdir ~/jupyterlite-project
cd ~/jupyterlite-project
```

2. Create a virtual environment for your project.

```
python3 -m venv venv
```

3. Activate the virtual environment.

```
source venv/bin/activate
```

With the environment ready, the next step is to install JupyterLite and its dependencies.

## Step 3 – Install JupyterLite and Dependencies

With your virtual environment active, you can now install JupyterLite and the supporting packages it needs to run.

1. First, upgrade pip so you’re working with the latest package manager:

```
pip install --upgrade pip
```

2. Next, install JupyterLite along with the Pyodide kernel and required Jupyter components:

```
pip install jupyterlite-core jupyterlite-pyodide-kernel jupyter-server jupyterlab_server
```

3. After installation, verify that JupyterLite is available by checking its version:

```
jupyter lite --version
```

Output.

```
0.6.4
```

This confirms that JupyterLite is successfully installed and ready to build.

## Step 4 – Build and Serve JupyterLite Locally

With JupyterLite installed, the next step is to build the project and launch it in your browser. JupyterLite generates a static site containing your notebook environment, which can then be served locally or via a web server.

1. Run the following command to build the JupyterLite site.

```
jupyter lite build
```

This creates an _output directory inside your project folder. It contains the HTML, JavaScript, and configuration files that power JupyterLite.

2. Once the build is complete, start the local debug server.

```
jupyter lite serve
```

You should see output similar to:

```
		Serving JupyterLite Debug Server from:
			/root/jupyterlite-project/_output
		on:
			http://127.0.0.1:8888/index.html
```

Press **CTRL + C** in the terminal to stop the server when you’re done testing.

## Step 5 – Create a Sample Notebook

Now that JupyterLite is running, let’s add some real content. By default, JupyterLite serves an empty environment. To make it more useful, you can create and include your own notebooks.

1. First, install the nbformat package, which lets you programmatically create Jupyter notebooks.

```
pip install nbformat
```

2. Inside your project, create a directory named content. This is where your notebooks will be stored.

```
mkdir content
```

3. Use Python to generate a simple notebook with both Markdown and code cells.

```
python3 <
```

4. List the content directory to confirm the notebook was created.

```
ls content
```

Output.

```
sample_notebook.ipynb
```

## Step 6 – Rebuild JupyterLite with Custom Content

Now that you’ve created a sample notebook, you need to rebuild JupyterLite to include the new content. By default, JupyterLite won’t automatically detect new files — you must clean the old build and rebuild it with your content folder.

1. Run the following command to remove the old build files.

```
jupyter lite clean
```

This clears the _output directory so the next build will start fresh.

2. Next, rebuild JupyterLite while pointing it to the content directory.

```
jupyter lite build --contents content/
```

This process copies your sample_notebook.ipynb file into the JupyterLite site, making it available in the browser.

3. Now, start the Jupyter server.

```
jupyter lite serve --port 8888 --host 0.0.0.0 &
```

## Step 7 – Configure NGINX as a Reverse Proxy

Right now, JupyterLite is running on port 8888, which isn’t very convenient to access. To make it accessible via a clean domain name (like http://jupyter.mydomain.com), you can set up NGINX as a reverse proxy.

1. First, install NGINX on your server.

```
apt install nginx -y
```

2. Open the default site configuration file.

```
nano /etc/nginx/sites-enabled/default
```

Replace its contents with the following configuration.

```
server {
    listen 80;
    server_name jupyter.mydomain.com;

    location / {
        proxy_pass http://127.0.0.1:8888;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
    }
}
```

3. Before applying changes, test the configuration to ensure there are no syntax errors.

```
nginx -t
```

4. If the test passes, restart NGINX.

```
systemctl restart nginx
```

## Step 8 – Access JupyterLite in the Browser

With NGINX configured, your JupyterLite environment is now accessible through a simple domain name.

1. Open your browser and go to **http://jupyter.mydomain.com.** From the file browser, open the notebook you created earlier. You will see the screen below.

![](https://www.atlantic.net/wp-content/uploads/2025/09/p2-2.png)

## Conclusion

In this tutorial, you have installed JupyterLite on Ubuntu 24.04, built a custom project, created a sample notebook, and served it in the browser using NGINX. This setup provides a lightweight Jupyter environment that runs entirely on the client side, eliminating the need for a backend kernel. With your domain pointing to JupyterLite, you can now share notebooks that anyone can open and run directly from their browser. To take it further, you can secure your deployment with HTTPS, add more notebooks, and use this setup for teaching, demos, or quick coding tasks.


---

# How to Build a Multi-User Web Interface for DeepSeek with Streamlit on Ubuntu 24.04 GPU Server

> URL: https://www.atlantic.net/gpu-server-hosting/how-to-build-a-multi-user-web-interface-for-deepseek-with-streamlit-on-ubuntu-24-04-gpu-server/ | Published: 2025-10-13 | Updated: 2026-05-04 | Author: Hitesh Jethva

Running advanced AI models, such as DeepSeek, on a GPU server is powerful, but it can be challenging for teams to access and utilize these models efficiently. Instead of everyone logging in via SSH or Python scripts, you can build a multi-user web interface that runs directly in the browser. This enables multiple people to log in, ask questions, and view results in real-time.

In this tutorial, you’ll learn how to set up a Streamlit-based web application for DeepSeek on an Ubuntu 24.04 GPU server. Streamlit provides a simple yet powerful framework for building data apps, while PyTorch and Hugging Face’s Transformers library let you integrate the DeepSeek model.

## Prerequisites

- An Ubuntu 24.04 server with an NVIDIA GPU.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1 – Install Python Dependencies

Before starting, you will need to install Python and other packages to your server.

1. First, update the package index.

```
apt update -y
```

2. Install required packages.

```
apt install git python3 python3-venv python3-pip
```

3. Create a project directory and navigate to it.

```
mkdir ~/deepseek-app && cd ~/deepseek-app
```

4. Create and activate a Python virtual environment.

```
python3 -m venv venv
source venv/bin/activate
```

5. Update pip to the latest version.

```
pip install --upgrade pip
```

6. Now install PyTorch with CUDA 12.4 support so the DeepSeek model can use GPU acceleration.

```
pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu124
```

7. Next, install the core libraries required for our app.

```
pip install transformers streamlit accelerate
```

## Step 2 – Add Authentication

To make your DeepSeek app multi-user, you need a way for people to log in with their own accounts. We’ll start with a basic authentication system using Streamlit’s sidebar. For simplicity, credentials are stored in a small Python dictionary, but in production, you should connect it to a database, LDAP, or OAuth provider.

1. Create a new file called auth.py inside your project directory:

```
nano auth.py
```

Paste the following code:

```
import streamlit as st

# Hardcoded user database (replace with DB/LDAP in production)
USER_CREDENTIALS = {
    "admin": "deepseek123",
    "user1": "password1",
    "user2": "password2"
}

def login():
    st.sidebar.title("🔐 Login")

    # Ask for username & password
    username = st.sidebar.text_input("Username")
    password = st.sidebar.text_input("Password", type="password")

    if "authenticated" not in st.session_state:
        st.session_state["authenticated"] = False
        st.session_state["username"] = ""

    if st.sidebar.button("Login"):
        if username in USER_CREDENTIALS and USER_CREDENTIALS[username] == password:
            st.session_state["authenticated"] = True
            st.session_state["username"] = username
            st.sidebar.success(f"Welcome, {username} 👋")
        else:
            st.sidebar.error("Invalid username or password")

    if st.sidebar.button("Logout"):
        st.session_state["authenticated"] = False
        st.session_state["username"] = ""

    return st.session_state["authenticated"]
```

**How this works:**

- A login form appears in the sidebar.
- If the username/password match, the session is marked as authenticated.
- Once logged in, the username is saved in st.session_state.
- A logout button lets users exit their session anytime.

## Step 3 – Build the Streamlit App

Now that authentication is in place, let’s build the main Streamlit application that connects with the DeepSeek model. This app will handle user login, take input questions, generate responses using the model, and display a chat history.

1. Create a new file called app.py.

```
nano app.py
```

Add the following code:

```
import streamlit as st
from transformers import AutoModelForCausalLM, AutoTokenizer
import torch
from auth import login

# Load model once at startup
MODEL_NAME = "deepseek-ai/deepseek-coder-1.3b-instruct"
tokenizer = AutoTokenizer.from_pretrained(MODEL_NAME)
model = AutoModelForCausalLM.from_pretrained(
    MODEL_NAME,
    torch_dtype=torch.float16,
    device_map="auto"
)

st.set_page_config(page_title="DeepSeek Web App", layout="wide")

# Run login function
if not login():
    st.stop()

# App title
st.title("🚀 DeepSeek Multi-User Web Interface")
st.write(f"👤 Logged in as: **{st.session_state['username']}**")

# Session-specific chat history
if "chat_history" not in st.session_state:
    st.session_state.chat_history = []

# User input
user_input = st.text_area("Enter your question:", key="input")

if st.button("Submit"):
    if user_input.strip():
        inputs = tokenizer(user_input, return_tensors="pt").to(model.device)
        outputs = model.generate(**inputs, max_new_tokens=200, do_sample=True, temperature=0.7)
        response = tokenizer.decode(outputs[0], skip_special_tokens=True)

        st.session_state.chat_history.append((user_input, response))
    else:
        st.warning("⚠️ Please enter a question.")

# Display chat history
for q, r in st.session_state.chat_history:
    st.markdown(f"**You:** {q}")
    st.markdown(f"**DeepSeek:** {r}")
    st.markdown("---")
```

**Explanation:**

- **Model loading** – The DeepSeek model is loaded once at startup for better performance.
- **Login check** – Users must log in before accessing the app.
- **Chat interface** – Users type questions, the model generates answers, and both are stored in session history.
- **Multi-user support** – Each user sees their own chat history, separate from others.

With this setup, you now have a functioning AI chat interface that works for multiple users on the same GPU server.

## Step 4 – Run the Application

With both auth.py and app.py ready, it’s time to launch the Streamlit application and make it available to users.

1. Run the following command to start the app.

```
nohup streamlit run app.py --server.port 8501 --server.address 0.0.0.0 &
```

Once the server starts, you’ll see output like:

```
  You can now view your Streamlit app in your browser.

  Network URL: http://your-server-ip:8501
  External URL: http://your-server-ip:8501
```

## Step 5 – Accessing the Web Interface

Now that your Streamlit server is running, let’s see how to use the DeepSeek multi-user web app in practice.

1. Open the app in your browser and go to **http://your-server-ip:8501**

![](https://www.atlantic.net/wp-content/uploads/2025/09/p1-5.png)

2. Log in with admin credentials

**Enter Username:** admin
 **Enter Password:** deepseek123
 Click the **Login** button.

![](https://www.atlantic.net/wp-content/uploads/2025/09/p2-3.png)

3. In the text box labeled **“Enter your question:”,** type something like: **“Explain the difference between supervised and unsupervised learning.”**

![](https://www.atlantic.net/wp-content/uploads/2025/09/p3-2.png)

Press the **Submit** button. The app will send your question to the DeepSeek model and generate a response.

## Conclusion

In this tutorial, you built a multi-user web interface for DeepSeek on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/) using Streamlit. You started by preparing the environment, installing Python dependencies, and setting up authentication. Then, you created the main app to load the DeepSeek model, handle user input, and display chat history for each logged-in user. Finally, you ran the app and tested it through the web interface with separate user sessions.


---

# How to Train DeepSeek with Custom Knowledge Base Using LoRA on Ubuntu 24.04 GPU

> URL: https://www.atlantic.net/gpu-server-hosting/how-to-train-deepseek-with-custom-knowledge-base-using-lora-on-ubuntu-24-04-gpu/ | Published: 2025-10-14 | Updated: 2025-10-15 | Author: Hitesh Jethva

Large Language Models (LLMs), such as DeepSeek, are powerful tools for question answering, chatbots, and intelligent assistants. However, by default, they are trained on general-purpose data and may not know about your company’s specific policies, procedures, or internal knowledge base.

This is where fine-tuning with LoRA (Low-Rank Adaptation) comes in. Instead of retraining the whole model, which requires massive GPUs and days of compute, you can adapt DeepSeek efficiently using LoRA. This technique adds lightweight trainable layers to the model, keeping the original weights frozen. As a result, you can customize DeepSeek on a single GPU (such as an NVIDIA RTX 3090/4090 or A100) with as little as 12 GB VRAM.

In this tutorial, you’ll learn how to train DeepSeek with a custom knowledge base using Lora on an Ubuntu 24.04 [GPU server](https://www.atlantic.net/gpu-server-hosting/).

## Prerequisites

- An Ubuntu 24.04 server with an NVIDIA GPU.
- A non-root user or a user with sudo privileges.
- NVIDIA drivers are installed on your server.

## Step 1 – Install Prerequisites

Before you begin training DeepSeek with a custom knowledge base, you need to prepare your Ubuntu 24.04 GPU server with the right dependencies.

Important. Make sure you are using a non-root user account with sudo privileges.

```
adduser username
usermod -aG sudo username
su - username
```

1. First, update your system and install the basic packages:

```
sudo apt update
sudo apt install git wget curl python3 python3-venv python3-pip build-essential -y
```

2. Next, create a Python virtual environment to keep this project isolated.

```
python3 -m venv deepseek-env
source deepseek-env/bin/activate
```

## Step 2 – Install Python Libraries

With your virtual environment activated, the next step is to install the Python libraries required for training DeepSeek with LoRA. These include PyTorch (with CUDA support), Hugging Face Transformers, and additional optimization libraries.

1. First, upgrade pip to the latest version.

```
pip install --upgrade pip
```

2. Now install PyTorch with CUDA 12.4 support. This ensures GPU acceleration is enabled on your Ubuntu 24.04 server.

```
pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cu124
```

3. Next, install Hugging Face libraries and additional packages needed for LoRA fine-tuning.

```
pip install transformers datasets accelerate peft bitsandbytes sentencepiece
```

4. Once installed, you can check that PyTorch detects your GPU with.

```
python3 -c "import torch; print(torch.cuda.is_available())"
```

If everything is set up correctly, it should return:

```
True
```

## Step 3 – Create a Custom Dataset

To fine-tune DeepSeek with LoRA, you need a knowledge base dataset that represents the information you want the model to learn. This dataset could be your company handbook, IT policies, FAQs, or any domain-specific text.

1. Let’s create a small dataset using Python. Open a new file:

```
nano create_dataset.py
```

Add the following code:

```
# create_dataset.py
from datasets import Dataset

# Example knowledge base (company handbook, IT policy, FAQs)
documents = [
    {"text": "Welcome to ACME Corp. Our mission is to provide high quality products."},
    {"text": "All employees must use two-factor authentication when logging into company systems."},
    {"text": "Working hours are from 9 AM to 6 PM, Monday through Friday."},
    {"text": "If you forget your password, contact IT support via support@acme.com."},
    {"text": "Our company handbook states that teamwork and innovation are core values."},
    {"text": "Employees are entitled to 20 days of paid vacation annually."},
    {"text": "To access the VPN, employees must install the Cisco AnyConnect client."},
    {"text": "For cybersecurity, do not share your credentials with anyone."},
    {"text": "Remote work is allowed up to 3 days per week."},
    {"text": "All company meetings are recorded and stored in the internal portal."}
]

dataset = Dataset.from_list(documents)
dataset.save_to_disk("custom_dataset")
print("✅ Sample knowledge base dataset saved in custom_dataset/")
```

2. Now run the script.

```
python3 create_dataset.py
```

If everything goes well, you should see:

```
✅ Sample knowledge base dataset saved in custom_dataset/
```

## Step 4 – Load and Test the Base DeepSeek Model

Before applying LoRA fine-tuning, it’s important to test that the base DeepSeek model loads correctly on your GPU. This also confirms that quantization works and inference runs without issues.

1. Create a new file.

```
nano load_model.py
```

Add the following code:

```
# load_model.py
from transformers import AutoModelForCausalLM, AutoTokenizer, BitsAndBytesConfig

model_name = "deepseek-ai/deepseek-llm-7b-base"

# Use 4-bit quantization
bnb_config = BitsAndBytesConfig(
    load_in_4bit=True,
    bnb_4bit_use_double_quant=True,
    bnb_4bit_quant_type="nf4",
    bnb_4bit_compute_dtype="float16"
)

tokenizer = AutoTokenizer.from_pretrained(model_name)

model = AutoModelForCausalLM.from_pretrained(
    model_name,
    quantization_config=bnb_config,
    device_map="auto"
)

# Test inference
inputs = tokenizer("Hello DeepSeek!", return_tensors="pt").to("cuda")
outputs = model.generate(**inputs, max_length=30)
print(tokenizer.decode(outputs[0], skip_special_tokens=True))
```

2. Now run the script.

```
python3 load_model.py
```

If you hit any errors here, its likely you do not have enough VRAM on the GPU. Upgrade your instance.

If successful, you’ll see an output similar to this (it will vary slightly depending on the random generation):

```
Hello DeepSeek! How can I assist you today?
```

## Step 5 – Configure LoRA for Fine-Tuning

Now that the base DeepSeek model is working, the next step is to configure LoRA (Low-Rank Adaptation). LoRA adds small trainable layers to the model, making fine-tuning possible on a single GPU without retraining the entire 7B parameter model.

1. Create a new file.

```
nano configure_lora.py
```

Add the following code:

```
# configure_lora.py
from transformers import AutoModelForCausalLM, AutoTokenizer, BitsAndBytesConfig
from peft import LoraConfig, get_peft_model

model_name = "deepseek-ai/deepseek-llm-7b-base"

# Use 4-bit quantization with CPU offload
bnb_config = BitsAndBytesConfig(
    load_in_4bit=True,
    bnb_4bit_use_double_quant=True,
    bnb_4bit_quant_type="nf4",   # Normalized float4
    bnb_4bit_compute_dtype="float16"
)

# Load tokenizer
tokenizer = AutoTokenizer.from_pretrained(model_name)

# Load base model with quantization
model = AutoModelForCausalLM.from_pretrained(
    model_name,
    quantization_config=bnb_config,
    device_map="auto"  # automatically balances GPU/CPU
)

# Configure LoRA
lora_config = LoraConfig(
    r=16,
    lora_alpha=32,
    target_modules=["q_proj", "v_proj"],  # attention layers
    lora_dropout=0.05,
    bias="none",
    task_type="CAUSAL_LM"
)

# Attach LoRA adapters
model = get_peft_model(model, lora_config)
model.print_trainable_parameters()
```

2. Run the script.

```
python3 configure_lora.py
```

## Step 6 – Train DeepSeek with LoRA

With LoRA configured, it’s time to fine-tune DeepSeek on your custom dataset. We’ll use the Hugging Face Trainer API to simplify training.

1. Create a new script.

```
nano train_lora.py
```

Add the following code.

```
# train_lora.py
from transformers import TrainingArguments, Trainer, AutoTokenizer, AutoModelForCausalLM, BitsAndBytesConfig
from datasets import load_from_disk
from peft import LoraConfig, get_peft_model

# Load dataset
dataset = load_from_disk("custom_dataset")

# Model name
model_name = "deepseek-ai/deepseek-llm-7b-base"

# Quantization config (4-bit for 8 GB GPU)
bnb_config = BitsAndBytesConfig(
    load_in_4bit=True,
    bnb_4bit_use_double_quant=True,
    bnb_4bit_quant_type="nf4",
    bnb_4bit_compute_dtype="float16"
)

# Load tokenizer
tokenizer = AutoTokenizer.from_pretrained(model_name)

# Load base model
model = AutoModelForCausalLM.from_pretrained(
    model_name,
    quantization_config=bnb_config,
    device_map="auto"
)

# Configure LoRA
lora_config = LoraConfig(
    r=16,
    lora_alpha=32,
    target_modules=["q_proj", "v_proj"],  # attention projections
    lora_dropout=0.05,
    bias="none",
    task_type="CAUSAL_LM"
)

model = get_peft_model(model, lora_config)

# Tokenization function (with labels for loss computation)
def tokenize(batch):
    tokens = tokenizer(
        batch["text"],
        truncation=True,
        padding="max_length",
        max_length=256
    )
    tokens["labels"] = tokens["input_ids"].copy()
    return tokens

dataset = dataset.map(tokenize, batched=True)

# Training arguments
training_args = TrainingArguments(
    output_dir="deepseek-lora",
    per_device_train_batch_size=1,       # fit into 8GB GPU
    gradient_accumulation_steps=8,       # simulate bigger batch
    num_train_epochs=3,
    learning_rate=2e-4,
    fp16=True,
    logging_steps=5,
    save_strategy="epoch"
)

# Trainer
trainer = Trainer(
    model=model,
    args=training_args,
    train_dataset=dataset,
    tokenizer=tokenizer
)

trainer.train()

# Save the final LoRA adapter to a clean path 
output_dir = "deepseek-lora-final" 
model.save_pretrained(output_dir) 
tokenizer.save_pretrained(output_dir) 
print(f"✅ Final LoRA adapter saved to {output_dir}/")
```

2. Run the training script.

```
python3 train_lora.py
```

## Step 7 – Evaluate Fine-Tuned Model

Now that the LoRA training is complete, let’s test the fine-tuned DeepSeek model and see if it answers based on the custom knowledge base.

1. Create a new file.

```
nano evaluate_model.py
```

Add the following code:

```
# evaluate_model.py
from transformers import AutoTokenizer, AutoModelForCausalLM, BitsAndBytesConfig
from peft import PeftModel

model_name = "deepseek-ai/deepseek-llm-7b-base"

# 4-bit quantization config
bnb_config = BitsAndBytesConfig(
    load_in_4bit=True,
    bnb_4bit_use_double_quant=True,
    bnb_4bit_quant_type="nf4",
    bnb_4bit_compute_dtype="float16"
)

# Load tokenizer and base model 
base_model = AutoModelForCausalLM.from_pretrained( 
    model_name, 
    quantization_config=bnb_config, 
    device_map="auto" 
) 
tokenizer = AutoTokenizer.from_pretrained(model_name) # Also load tokenizer from base model 
# Load fine-tuned LoRA adapters from the clean local path 
adapter_path = "deepseek-lora-final" 
model = PeftModel.from_pretrained(base_model, adapter_path)

# Ask test questions
questions = [
    "What is ACME Corp's vacation policy?",
    "What are the official working hours?",
    "How do employees access the VPN?",
    "Who should I contact if I forget my password?"
]

for q in questions:
    inputs = tokenizer(q, return_tensors="pt").to("cuda")
    outputs = model.generate(**inputs, max_length=100)
    print(f"\nQ: {q}\nA: {tokenizer.decode(outputs[0], skip_special_tokens=True)}")
```

2. Run the script.

```
python3 evaluate_model.py
```

If successful, you should see outputs similar to:

```
Loading checkpoint shards: 100%|█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 2/2 [00:11<00:00,  5.89s/it]
Setting `pad_token_id` to `eos_token_id`:100001 for open-end generation.

Q: What is ACME Corp's vacation policy?
A: What is ACME Corp's vacation policy?
# 100 Days of Code - Log

### Day 0: May 1, 2020

**Today's Progress**: Started the 100 Days of Code challenge.

**Thoughts:** I'm excited to get started.

### Day 1: May 2, 2020

**Today's Progress**: Started the 1
Setting `pad_token_id` to `eos_token_id`:100001 for open-end generation.

Q: What are the official working hours?
A: What are the official working hours?
The official working hours are from 8:00 am to 5:00 pm.
What are the working days?
The working days are Monday to Friday.
What are the official holidays?
The official holidays are New Year's Day, Labor Day, Independence Day, Eid Al-Fitr, Eid Al-Adha, and the UAE National Day.
What are the official holidays?
The official holidays
Setting `pad_token_id` to `eos_token_id`:100001 for open-end generation.

Q: How do employees access the VPN?
A: How do employees access the VPN?
Q: How to get the current user's IP address? I'm trying to get the current user's IP address. I've tried using the following code:
$ip = $_SERVER['REMOTE_ADDR'];

But it's not working.

A: You can use $_SERVER['REMOTE_ADDR'] to get the IP address of the user.

A: You can use $_SERVER
Setting `pad_token_id` to `eos_token_id`:100001 for open-end generation.

Q: Who should I contact if I forget my password?
A: Who should I contact if I forget my password?
# 1.0.0

* Initial release
```

## Conclusion

In this tutorial, you learned how to fine-tune DeepSeek with a custom knowledge base using LoRA on Ubuntu 24.04 with GPU support. You started by preparing your environment, installing the required libraries, and creating a dataset that represents company-specific information. You then loaded the DeepSeek 7B base model with 4-bit quantization to save VRAM, configured LoRA adapters, and trained the model on your dataset.


---

# Atlantic.Net Wins the Fall 2025 Leader Award from SourceForge

> URL: https://www.atlantic.net/press-releases/atlantic-net-wins-the-fall-2025-leader-award-from-sourceforge/ | Published: 2025-10-15 | Updated: 2026-03-02 | Author: Editorial Team

*Atlantic.Net Is Honored To Be a Winner of the Leader Award From Sourceforge, the World’s Largest Software Reviews and Comparison Website*

**October 15, 2025 –** [Atlantic.Net](http://atlantic.net), award-winning hosting solutions and services, announced today that it has been awarded the Fall 2025 Leader Award by SourceForge. SourceForge is the world’s largest B2B software review and comparison website with nearly 20 million in-market B2B software buyers per month. This award recognizes exceptional companies and products with a high volume of recent excellent user reviews that put them in the top fifth percentile of highly reviewed products on SourceForge.

“We’re happy to announce this year’s outstanding Fall 2025 Leaders,” said SourceForge President, Logan Abbott. “Atlantic.Net showed that they are loved by their users, as evidenced by their large number of outstanding user reviews.”

To win the Fall 2025 Leader award, each winner had to receive enough high-rated user reviews to place the winning product in the top 5% of favorably reviewed products out of the 100,000 products on SourceForge, which demonstrates the utmost quality that Atlantic.net delivers to customers.

“At Atlantic.Net, we’re honored to receive the SourceForge Fall 2025 Leader Award,” said Marty Puranik, Founder and CEO of Atlantic.Net. “As one of the most experienced hosting infrastructure service providers in the world, Atlantic.Net’s mission has always been to continue to evolve and deliver cutting-edge technologies to the market—demonstrated by our 31-year track record. We strive to make powerful, secure cloud technology simple and accessible. This recognition is especially meaningful because it reflects the ongoing trust and satisfaction of our users. We’re deeply grateful to our team for their relentless innovation and dedication—their support continues to inspire us to raise the bar in performance, reliability, and service.”

**About Atlantic.Net**

Founded in 1994, [Atlantic.Net](http://atlantic.net) is a privately held global cloud infrastructure provider in over 100 countries, known for delivering secure, compliant, and customizable hosting solutions. With decades of experience, Atlantic.Net is one of the world’s most trusted and experienced hosting providers, offering 24/7 U.S.-based support.

Specializing in security, compliance, and customer service, Atlantic.Net serves a diverse range of industries with solutions including HIPAA-compliant hosting, PCI-compliant hosting, bare metal servers, dedicated hosting, GPU hosting, colocation, and its award-winning Cloud Platform.

Operating from eight strategically located data center regions across the United States, Canada, the United Kingdom, and Asia, Atlantic.Net powers mission-critical workloads for organizations worldwide.

For more information, visit[Atlantic.Net](https://www.atlantic.net/) or connect with us on[Facebook](https://www.facebook.com/Atlantic.Net),[X (Twitter)](https://twitter.com/AtlanticNet),[LinkedIn](https://www.linkedin.com/company/atlantic-net), and[YouTube](https://www.youtube.com/c/AtlanticNet).

**About SourceForge**

[SourceForge](https://sourceforge.net) is the world’s largest software comparison directory, serving nearly 20 million users every month and featuring user reviews, product comparisons, software guides, and more. SourceForge features over 100,000 B2B software products across 4000 B2B software categories. SourceForge’s mission is to help businesses find the best software to fit their needs and their budget. There are a variety of software tools available to businesses, and there are tools in almost every category and niche, each serving a slightly different purpose. 


---

# Why Bare Metal Is the Unsung Hero of the AI Revolution in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/why-bare-metal-is-the-unsung-hero-of-the-ai-revolution-in-2026/ | Published: 2025-10-24 | Updated: 2026-01-06 | Author: Dr. Tehseen Zia

The progress of Artificial Intelligence (AI) is usually attributed to advanced algorithms and massive datasets. However, these achievements rely on robust computing systems that can efficiently manage complex workloads. Therefore, the performance of AI models not only depends on their algorithmic design but also on the infrastructure that supports them.

Although cloud and virtualized platforms receive most of the attention, [bare metal servers](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) play an equally important, yet less visible, role. They provide direct hardware access, complete resource control, and consistent high performance without the delay caused by virtualization layers.

Moreover, such environments are ideal for training large language models, processing extensive datasets, and running time-sensitive AI applications.

Consequently, bare metal provides the speed, reliability, and stability required for demanding AI workloads.

## What Makes Bare Metal Essential for AI

Bare metal servers are physical machines dedicated to a single user or organization, providing a dedicated computing environment. They are not shared through virtualization, which allows full access to the hardware. Users can directly control the CPU, GPU, memory, storage, and network.

These servers support AI workloads that require speed, precision, and control. By removing virtualization layers, bare metal avoids performance loss from hypervisors and shared resources. This enables engineers to:

- Run large AI models without interference from other users.
- Configure and fine-tune systems for frameworks such as PyTorch or TensorFlow.
- Optimize GPU, memory, and I/O performance without delays.

Moreover, bare metal servers provide reliable performance, making them suitable for large language models, deep learning, and real-time analytics. These capabilities enable faster training, lower latency, and consistent results, making bare metal essential for AI workloads.

## The Demands of AI Workloads

Modern AI tasks place significant demands on computing infrastructure. With the increasing size of models and the continuous growth in data, systems must maintain high throughput, stable performance, and minimal delays. These needs extend beyond processing speed and encompass efficient data handling, reliable communication between nodes, and predictable performance during extended training cycles.

Bare metal servers are designed to meet such requirements. They offer full GPU acceleration for parallel computation, NVMe storage for rapid data access, and low-latency networking for distributed workloads. This setup ensures steady and uninterrupted operation during intensive processing.

In comparison, virtualized environments often face latency variations and resource contention, which can reduce efficiency. Bare metal servers prevent these problems by providing consistent performance and direct hardware control. Therefore, they form a dependable and efficient base for modern AI infrastructure.

## Bare Metal in AI Model Training

Training advanced AI models requires uninterrupted access to computing power and memory. Each training cycle involves millions of calculations and continuous data transfer. Any delay or fluctuation in resources can slow the process or affect model accuracy.

Bare metal servers address these needs directly. They offer unrestricted GPU access for faster computation, high I/O throughput for efficient data handling, and consistent performance without interference from virtualization. This setup reduces training time, improves scalability, and ensures uniform results across runs.

Moreover, predictable performance enables organizations to plan costs and manage energy use more efficiently. For these reasons, bare metal servers have become a preferred choice for large-scale AI model training and deployment.

## Deployment Options: On-Premises vs Cloud

Bare metal servers are no longer limited to traditional on-premises deployments. Many providers now offer bare metal cloud hosting, which combines the high performance of dedicated hardware with the flexibility and scalability of the cloud. This setup enables organizations to deploy

workloads quickly; scale resources as needed and maintain complete control over hardware configurations.

For instance, [Atlantic.Net](http://www.atlantic.net) provides bare metal cloud hosting equipped with NVIDIA GPUs, including H100 and L40S models, NVMe SSD storage, and high-speed networking. Their infrastructure is also compliance-ready, meeting standards such as HIPAA and PCI DSS. By combining performance with operational flexibility, this approach enables organizations to run demanding AI workloads efficiently and reliably on a scale.

## Security and Compliance

Bare metal servers offer significant security advantages due to their physical isolation of resources. This means sensitive data faces fewer risks compared to virtualized environments, where shared resources can introduce vulnerabilities. Moreover, network isolation through VLANs or VRFs adds another layer of protection, preventing unauthorized access and enhancing system integrity.

In addition, bare metal infrastructures often comply with strict standards such as HIPAA, PCI DSS, and SOC 2, which ensure regulatory requirements are met. Consequently, this combination of physical isolation, network safeguards, and compliance significantly reduces the risk of cross-tenant vulnerabilities, making bare metal a dependable option for secure and reliable AI workloads.

## Performance Benefits

The primary advantage of bare metal servers is their superior performance. By removing virtualization overhead, they deliver consistent, high-speed computing that enables AI engineers to optimize CPU, GPU, memory, and storage for their frameworks. High-throughput GPUs, NVMe storage, and low-latency networking ensure predictable, uninterrupted operation for large-scale workloads.

This enables efficient training of complex AI models while maintaining accuracy and repeatability. By supporting both stability and scalability, bare metal complements its security and deployment advantages, making it an essential component for demanding AI applications.

## Choosing a Bare Metal Provider for AI

Selecting the right bare metal provider is essential for AI projects, as it impacts performance, security, and scalability. Organizations should consider several key factors.

First, hardware and GPU capability are critical, as modern CPUs and high-performance GPUs enable the efficient processing of large models and complex workloads. Compliance and security are also vital, particularly for sensitive or regulated data; providers that meet standards such as HIPAA, SOC 2, and PCI DSS offer the necessary protection.

Reliability and support help maintain continuous operation, with 24/7 technical assistance and robust service level agreements that reduce the risk of costly downtime. Additionally, network performance must be robust, featuring redundant and high-speed connectivity to ensure stability.

Key considerations are summarized below:

- **Hardware and GPU capability:** Modern CPUs and GPUs for fast and efficient processing.
- **Compliance and security:** HIPAA, SOC 2, PCI DSS standards for sensitive workloads.
- **Reliability and support:** 24/7 technical assistance and robust SLAs.
- **Pricing transparency:** Clear cost structures to avoid unexpected expenses.
- **Network performance:** Redundant, high-speed connectivity for stable operations.

Leading providers such as Atlantic.Net, [IBM Cloud](https://www.ibm.com/cloud), [AWS](https://aws.amazon.com/), [Oracle Cloud](https://www.oracle.com/cloud/), and [OpenMetal](https://openmetal.io/) each offer a mix of strengths across these areas, providing organizations with reliable options depending on workload size, compliance requirements, and budget.

## Top Bare Metal Hosting Providers for AI Projects

### 1. Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

Atlantic.Net offers robust [bare metal hosting solutions](https://www.atlantic.net/gpu-server-hosting/the-best-bare-metal-hosting-for-ai-workloads-in-2025/?utm_source=chatgpt.com) equipped with NVIDIA H100 and L40S GPUs, designed to meet the demanding requirements of AI workloads. Their infrastructure supports NVMe SSD storage and high-speed networking, ensuring optimal performance for tasks like large language model training and real-time inference.

The platform is compliant with HIPAA, PCI DSS, and SOC 2 standards, making it suitable for industries where security and data privacy are of the utmost importance. Users can configure CPU, RAM, and NVMe storage according to the demands of their AI workloads, providing flexibility to create an environment that matches specific frameworks and performance needs.

**Advantages:**

- Provides access to top-tier NVIDIA H100 and L40S GPUs, which are essential for training large models and demanding inference tasks.
- Offers a robust compliance framework, independently audited for HIPAA, PCI DSS, and SOC 2/3, ensuring data integrity and security.
- Allows for deep hardware customization, enabling users to specify exact CPU, RAM, and NVMe SSD storage configurations to match workload requirements.
- Features 24/7 U.S.-based support and a clear, predictable pricing model, which simplifies budgeting for long-term AI projects.

**Ideal for:**

- Healthcare organizations and MedTech startups handling sensitive patient data (PHI) for AI-driven diagnostics or research.
- Fintech and e-commerce companies that must maintain PCI DSS compliance while running fraud detection or personalization models.
- Any organization that prioritizes stringent security and regulatory adherence alongside high-end GPU performance.

### 2. IBM Cloud

![](https://www.atlantic.net/wp-content/uploads/2025/06/ibm-logo.png)

IBM Cloud offers enterprise-grade bare metal servers equipped with a range of NVIDIA GPUs, including the H200 and L40S models. Their offerings are well-suited for AI applications that require high computational power and adhere to industry standards.

IBM Cloud’s infrastructure is designed for high resiliency and security, supporting AI, HPC, and visualization workloads. The platform offers flexible deployment options, including stand-alone servers and private cloud configurations, allowing organizations to tailor their infrastructure to specific needs.

**Advantages:**

- Features access to powerful, next-generation NVIDIA H200 and L40S GPUs, tailored for enterprise-scale AI and HPC.
- Built on an infrastructure with high resiliency and robust security, designed to meet complex enterprise-grade reliability standards.
- Offers flexible deployment models, including stand-alone servers and seamless integration into VPCs (Virtual Private Clouds).
- Strong support for hybrid cloud strategies, allowing businesses to connect on-premises data centers with cloud-based bare metal for consistent performance.

**Ideal for:**

- Large-scale enterprises that require a stable, secure, and highly reliable platform for mission-critical AI applications.
- Research and academic institutions running High-Performance Computing (HPC) and AI workloads that demand significant, sustained computational power.
- Businesses that need to integrate bare metal performance directly into their existing IBM Cloud hybrid or private cloud environments.

### 3. AWS (Amazon Web Services)

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

AWS offers bare metal EC2 instances, providing direct access to physical hardware while integrating with the broader AWS ecosystem. Their GPU offerings include the NVIDIA A100 and T4 models, which are suitable for various AI and machine learning tasks.

The platform holds certifications such as HIPAA, PCI-DSS, SOC 2, and GDPR. Under the shared responsibility model, AWS secures the underlying infrastructure, while clients are responsible for ensuring the security of their data and applications within the cloud.

**Advantages:**

- Enables direct integration with the full AWS ecosystem, allowing bare metal instances to natively access services like Amazon S3, VPC, and Amazon SageMaker.
- Provides direct, non-virtualized access to the underlying server’s processor and memory, eliminating hypervisor overhead for maximum performance.
- Offers proven NVIDIA H100, A100, and T4 GPUs, providing a solid, well-supported hardware base for a variety of machine learning and inference tasks.
- Leverages AWS’s extensive global network and availability zones for high availability and low-latency data access.

**Ideal for:**

- Organizations already deeply embedded in the AWS ecosystem that need to optimize performance for specific, resource-intensive workloads.
- Applications that require native, high-speed access to large datasets stored in Amazon S3 or that are part of a broader AWS data pipeline.
- Teams using Amazon SageMaker or other AWS ML services that want to add a high-performance, bare metal component for training or inference.

### 4. Oracle Cloud Infrastructure (OCI)

![Oracle Cloud Logo and symbol, meaning, history, PNG, brand](https://1000logos.net/wp-content/uploads/2024/08/Oracle-Cloud-Logo.jpg)

OCI provides bare metal instances with NVIDIA GPUs, including A100 and H100 models, optimized for AI and high-performance computing workloads. Their infrastructure supports RDMA-based networking and scalable superclusters.

OCI’s platform is compliant with GDPR, HIPAA, and SOC standards. The platform offers flexible configurations and professional services, allowing organizations to tailor their infrastructure to specific requirements.

**Advantages:**

- Provides elite NVIDIA A100 and H100 GPUs at what is often a highly competitive price point, offering strong price-performance.
- Features RDMA (Remote Direct Memory Access) cluster networking, which provides ultra-low latency and high bandwidth for rapid communication between nodes.
- Designed specifically for building large-scale GPU superclusters, allowing for efficient distributed training of massive foundation models.
- Offers a secure, enterprise-focused cloud environment with strong compliance certifications (GDPR, HIPAA, SOC).

**Ideal for:**

- High-Performance Computing (HPC) and AI research teams that need to build and scale massive, multi-node GPU clusters.
- Large-scale distributed training for foundation models or complex simulations where inter-node latency is a critical bottleneck.
- Organizations looking for the best raw performance-per-dollar ratio for high-end H100 or A100 GPU instances.

### 5. OpenMetal

![Cloud Native Infrastructure Provider with Fixed Costs](https://openmetal.io/wp-content/uploads/2021/11/OpenMetal-Logo-Horizontal.png)

OpenMetal offers on-demand private cloud and bare metal services built on OpenStack and Ceph, providing flexibility and control for AI projects. Their platform supports NVIDIA A100 and H100 GPUs, suitable for large-scale AI deployments.

OpenMetal’s infrastructure is compliant with HIPAA, SOC 2, and other relevant standards, ensuring the security and privacy of sensitive workloads. The platform offers complete control over hardware configurations, enabling organizations to tailor their infrastructure to specific AI tasks.

**Advantages:**

- Built on open-source platforms (OpenStack and Ceph), providing full transparency and eliminating proprietary vendor lock-in.
- Offers the flexibility of an on-demand private cloud combined with the raw performance of bare metal hardware.
- Provides access to NVIDIA A100 and H100 GPUs, allowing for high-performance AI workloads on a customizable, open platform.
- Grants complete root-level control over the hardware and cloud environment, ideal for complex, custom configurations.

**Ideal for:**

- Service providers (MSPs) and enterprises that want to build their own AI cloud using open-source standards.
- Organizations that require deep customization and control over their infrastructure, beyond what is offered by hyperscale providers.
- Teams with OpenStack expertise looking to deploy on-demand bare metal to avoid vendor lock-in and maintain a fully transparent stack.

**Table 1: Comparison of different bare metal hosting providers**

| **Provider** | **GPU Options** | **Compliance** | **Customization** | **Support** | **Pricing (Starting)** |
| --- | --- | --- | --- | --- | --- |
| **Atlantic.Net** | NVIDIA H100 NVL, L40S | HIPAA, PCI DSS, SOC 2/3 | CPU, RAM, NVMe SSD | 24/7 U.S.-based support | ~$412/month (bare metal); ~$1,108/month for GPU servers |
| **IBM Cloud** | NVIDIA H200, L40S | HIPAA, GDPR, ISO | CPUs, GPUs, memory, storage | Comprehensive support | ~$2,624.88/month (GPU-accelerated bare metal) |
| **AWS** | NVIDIA A100, T4 | HIPAA, PCI DSS, SOC 2, GDPR | Flexible configurations | Structured support plans | $7.82/hour (T4); $32.77/hour (A100); $98.32/hour (H100) |
| **OCI** | NVIDIA A100, H100 | GDPR, HIPAA, SOC | CPUs, GPUs, memory, storage | Professional services | $4.00/hour (A100); $10.00/hour (H100) |
| **OpenMetal** | NVIDIA A100, H100 | HIPAA, SOC 2 | Full hardware control | Direct engineering support | ~$2,234.88/month (A100); ~$4,608/month (H100) |

## The Future of Bare Metal in AI

Choosing the right provider depends on the goals and priorities of each AI project. For compliance-focused environments, Atlantic.Net and IBM Cloud offer strong regulatory certifications and enterprise-grade reliability. Those interested in cost-effective GPU hosting can benefit from OCI, which provides competitive pricing for NVIDIA A100 instances. Meanwhile, OpenMetal is better suited for teams that need complete control and customization, while AWS remains ideal for organizations seeking seamless integration within a broad cloud ecosystem.

AI models are continually expanding in scale and complexity, making bare-metal infrastructure vital for supporting their performance, efficiency, and security requirements. By combining the reliability of dedicated hardware with the scalability offered by modern cloud platforms, bare metal provides a robust foundation for demanding AI workloads. While cloud platforms get most of the attention, bare metal quietly powers the backbone of modern AI, supporting the performance and efficiency needed for breakthroughs in 2025 and beyond.

## Final Thoughts

Bare metal servers have become essential for AI in 2025 because they provide the performance, control, and reliability required for large-scale workloads. By offering direct access to dedicated CPUs, GPUs, memory, and storage, they eliminate virtualization overhead, which in turn enables faster model training, real-time inference, and consistent performance. In addition, security and compliance are reinforced through physical and network isolation, helping organizations meet standards such as HIPAA, SOC 2, and PCI DSS.

When selecting a provider, organizations must carefully consider GPU options, customization capabilities, support, network stability, and pricing. Providers like Atlantic.Net, IBM Cloud, AWS, OCI, and OpenMetal each offer unique advantages, enabling teams to tailor their infrastructure to their specific AI requirements. Therefore, bare metal remains a reliable, efficient, and secure solution for running demanding AI workloads at scale.


---

# PCI DSS 4.0 is Mandatory: A Hosting Checklist for 2026

> URL: https://www.atlantic.net/pci-compliant-hosting/pci-dss-4-0-is-mandatory-a-hosting-checklist-for-2026/ | Published: 2025-10-25 | Updated: 2026-04-23 | Author: Richard Bailey

With the March 31, 2025, deadline now behind us, all requirements of PCI DSS 4.0 are now fully in effect. For any organization that stores, processes, or transmits payment card data, compliance is not just a best practice—it’s mandatory. If your hosting environment isn’t fully aligned with the latest version of PCI, it’s essential to act now.

Understanding how the updated PCI DSS requirements impact your payment card transaction infrastructure is the first step toward protecting customers and the reputation of your business. This PCI DSS 4.0 hosting checklist will guide you through the essentials of compliance, focusing on the critical role your hosting environment plays in securing the Cardholder Data Environment (CDE) and achieving PCI DSS compliance.

## What Is PCI DSS?

Let’s quickly recap: the Payment Card Industry Data Security Standard (PCI DSS) is a set of security requirements established by the PCI Security Standards Council (PCI SSC). This council, founded by major payment brands like Visa and MasterCard, created a global standard to establish a unified approach to protect customers against payment card fraud.

PCI DSS provides a detailed framework of security controls and best practices that must be aligned to your business practices. Its primary goal is to protect cardholder data wherever it is handled, reducing the risk of data breaches that can lead to financial loss and huge reputational damage. Whether you’re a large enterprise or a small online shop, if you accept credit card data, these standards apply to you.

## Understanding Cardholder Data

To meet PCI DSS standards, you must first know what you’re protecting. The standard defines two main categories:

- **Cardholder Data:** This includes the full Primary Account Number (PAN), cardholder name, expiration date, and service code.
- **Sensitive Authentication Data (SAD):** This is even more critical and includes full magnetic stripe data, [CAV2/CVC2/CVV2/CID codes](https://support.worldline.com/content/dam/support-worldline/local/en-ch/documents/datasheets/110003502_DS_ErhoehteSicherheit_CHE_EN_opt.pdf), and PINs. Storing this data post-authorization is strictly prohibited.

All IT system components that store, process, or transmit sensitive data make up your Cardholder Data Environment (CDE). A key strategy for simplifying compliance is proper PCI DSS scoping—reducing the size and complexity of your CDE to minimize the number of systems that fall under PCI DSS rules. The less stored cardholder data you have, the smaller your attack surface.

## Moving to PCI DSS 4.0

[PCI DSS 4.0](https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0_1.pdf) is the latest updated compliance standard, these are designed to address emerging threats with greater flexibility and rigor. One of the biggest changes is the introduction of the added option for a “*customized approach*” to compliance. Many larger organizations have embraced this change as it enables them to meet a security objective by using a proven technology or method different from the one specified in the standard.

Needless to say, there are a large number of safeguards and controls to meet, but as long as the business can provide rigorous documentation and testing to prove that an alternative control is effective, then alternative approaches are allowed. This approach opens the door for large-scale providers to ingest PCI-DSS into their compliance environments.

This contrasts with the traditional “defined approach,” where the requirement must be met exactly as stated. The shift encourages organizations to adopt security as a continuous process rather than an annual “checkbox” exercise, preparing them to better handle modern cyber threats.

## Achieving PCI Compliance

Achieving PCI compliance typically involves a few key processes, especially in sensitive areas, depending on your PCI compliance level (which is determined by your [transaction volume](https://www.itgovernance.eu/blog/en/a-guide-to-the-4-pci-dss-compliance-levels)).

For many, this means completing an annual Self-Assessment Questionnaire (SAQ). For others, especially large enterprises or those with complex environments, it requires a formal Report on Compliance (ROC) performed by a Qualified Security Assessor (QSA).

The new standard also introduces [Designated Entities Supplemental Validation](https://listings.pcisecuritystandards.org/documents/FAQs_for_DESV.pdf) (DESV) for entities that might pose a greater risk to the payment system, requiring even deeper validation of their controls.

With PCI DSS 4.0, achieving compliance isn’t just about passing an annual audit — it’s about maintaining a state of continuous security readiness. To reach that level, organizations must secure data, control access, and verify protections across every layer of their hosting environment.

### Core Hosting Controls for PCI DSS 4.0

When it comes to protecting cardholder data, the fundamentals remain the same — but PCI DSS 4.0 demands more rigor and proof of effectiveness. Below are the essential hosting controls every business must implement to maintain compliance.

#### Encrypt Cardholder Data

Encryption is non-negotiable. All stored cardholder data must be unreadable, protected using strong cryptography and secure key management. Data transmitted across open, public networks must also be encrypted using modern TLS protocols to safeguard payment pages, APIs, and backend systems.

#### Strengthen Network Security

Your network is the perimeter that guards the Cardholder Data Environment (CDE). Firewalls must be properly configured and regularly reviewed to block unauthorized access. Internal and external vulnerability scans — including those by an Approved Scanning Vendor (ASV) — are critical for finding and fixing weaknesses before attackers do.

#### Implement Strong Access Controls

Only those with a legitimate business need should have access to cardholder data. PCI DSS 4.0 now requires [Multi-Factor Authentication](https://www.atlantic.net/managed-services/multi-factor-authentication/) (MFA) for *all* access into the CDE, not just administrative users. Physical access to servers must also be tightly controlled and monitored — something your data center or hosting provider must be able to demonstrate.

#### Maintain Continuous Protection

Attackers evolve constantly, so defenses must do the same. Anti-malware solutions must be active and updated across all systems, while regular penetration testing helps validate that your network and applications can withstand real-world threats.

### PCI 4.0 Hosting Checklist

To bring these principles together, here’s a handy checklist to align your infrastructure with the PCI DSS 4.0 standard. This *PCI DSS compliance checklist* is a starting point for assessing your hosting environment’s *security posture*.

- **[ ] Scope & Minimize CDE:** Properly scope your environment by segmenting networks to isolate systems *handling sensitive data*. Reduce the attack surface by minimizing the components and *network resources* that interact with *cardholder information*.
- **[ ] Enforce MFA Everywhere:** Implement multi-factor authentication for all users who *gain access* to the Cardholder Data Environment (CDE). This critical control helps *restrict access* even if passwords are compromised.
- **[ ] Encrypt All Cardholder Data:** Ensure all *sensitive information* is unreadable wherever it is stored (at rest) or transmitted (in transit). Use strong cryptographic algorithms that meet current *industry standards*.
- **[ ] Harden All Systems:** Change all vendor-supplied default credentials, disable non-essential services, and apply *secure coding practices* for in-house applications to strengthen your overall *security posture*.
- **[ ] Apply Access Control:** Implement strict access control lists and firewall policies to *restrict access* to systems and data. Adhere to the principle of least privilege, granting access on a strict *need-to-know basis*.
- **[ ] Automate Scanning & Patching:** Schedule regular *internal vulnerability scans* and external ASV scans. Maintain a robust patch management process to apply security fixes promptly.
- **[ ] Deploy Malware Protection:** Deploy and maintain anti-malware solutions on all systems commonly affected by malicious software. Ensure tools are actively running and configured for periodic scans.
- **[ ] Validate Physical Security:** Confirm your hosting provider can demonstrate how they *restrict physical access* to servers and equipment through controls like multi-layered entry, surveillance, and access logging.
- **[ ] Conduct Pen Tests:** Perform annual internal and external penetration tests. Note that *designated entities supplemental validation* (DESV) may require more rigorous testing for certain service providers.
- **[ ] Review Service Providers:** Maintain due diligence on all third-party vendors. Annually verify their Attestations of Compliance (AOC) to ensure they meet their own PCI DSS responsibilities.

## The Cost of Non-Compliance

Failing to stay compliant has serious consequences. The immediate risk is financial penalties from payment processors and card brands, but the long-term impact of non-compliance, such as vulnerabilities that allow attackers to steal data, is often far worse.

A single data breach can lead to devastating reputational damage, loss of customer trust, and costly forensic investigations. The goal is to avoid fines, but the real prize is avoiding a breach that could cripple your business.

### How Atlantic.Net PCI Hosting Helps with PCI DSS 4.0

For organizations navigating PCI DSS 4.0, the hosting provider, especially managed service providers, you choose can make the difference between a smooth compliance journey and a costly, time-consuming one. Atlantic.Net [PCI Hosting](https://www.atlantic.net/pci-compliant-hosting/) is designed to simplify that process by embedding compliance and security controls directly into the infrastructure layer — helping you meet and maintain PCI DSS 4.0 requirements with confidence.

Our PCI Hosting environment is independently audited and built to satisfy all twelve PCI DSS control categories. This includes managed firewalls, intrusion detection and prevention, data encryption, and network segmentation — all essential for maintaining a secure Cardholder Data Environment (CDE). With Atlantic.Net, your systems operate within a hardened environment that enforces strong access control, continuous monitoring, and advanced threat detection to keep sensitive payment data protected at every layer.

Under PCI DSS 4.0, organizations are expected to demonstrate continuous security, not just annual compliance. Atlantic.Net supports this shift with automated vulnerability management, patching, and 24/7 security operations that keep your infrastructure aligned with evolving threats. Multi-Factor Authentication (MFA), centralized logging, and strict access policies further ensure that only authorized personnel can reach your data.

By hosting with Atlantic.Net, businesses can significantly reduce their PCI compliance scope, streamline audits, and eliminate many of the technical burdens associated with maintaining secure systems in-house. Our team of compliance experts works alongside your organization to provide documentation, validation, and expert guidance — helping you not only achieve compliance but sustain it as your business grows.

## Key Takeaways

- **PCI DSS 4.0 is Mandatory:** The transition period is over. All organizations must now adhere to the new, more robust standard.
- **Focus on Continuous Security:** The new standard shifts the goal from an annual audit to a state of constant security readiness.
- **Authentication is Critical:** MFA is no longer optional for CDE access; it is a core requirement.
- **Your Host is Your Partner:** A compliant hosting environment is a cornerstone of your own compliance. Your provider must be able to demonstrate how they ensure compliance with physical security and network controls.

## E-Commerce and Your Hosting Partner

For any e-commerce business, achieving PCI DSS compliance is impossible without a secure and reliable hosting infrastructure. Choosing the right partner means selecting a provider that integrates security into its core operations, not as an afterthought.

At Atlantic.Net, we have provided secure and managed hosting solutions for over 30 years. Our PCI-compliant hosting is built on an audited framework, delivering the secure infrastructure and expert guidance you need to maintain your Cardholder Data Environment. From the physical security of our global data centers to managed firewalls and robust security systems, we provide the foundational controls necessary to help you achieve compliance with PCI DSS 4.0 and protect payment data while strengthening your defenses against threats.

Don’t let compliance be an obstacle. [Contact us today](https://www.atlantic.net/pci-compliant-hosting/) to learn how our secure hosting solutions can become a strategic asset for your business.


---

# Top Features of Windows Dedicated Server Hosting

> URL: https://www.atlantic.net/dedicated-server-hosting/top-features-of-windows-dedicated-server-hosting/ | Published: 2025-10-25 | Updated: 2025-10-27 | Author: Dr. Tehseen Zia

For businesses that require guaranteed stability, speed, and security, it’s important to choose a reliable and trustworthy hosting partner. While Linux servers are a popular choice for their open-source flexibility, Windows dedicated server hosting is still the preferred choice for many organizations that need full control of their infrastructure, an easier user experience, and seamless integration with the familiar Windows platform.

Windows dedicated hosting brings together the solid power of dedicated hardware and the flexibility of Microsoft operating system technologies, which make it especially appealing for organizations already using Windows-based systems and applications.

In this article, we will explore the main features that make Windows dedicated servers a dependable option for enterprises, developers, and growing companies alike.

## Performance and Reliability

The main selling point of a [dedicated server](https://www.atlantic.net/dedicated-server-hosting/) is the unrivaled performance. Unlike shared hosting, where multiple users compete for the same system resources, a dedicated server gives you full control over CPU, disk and memory. This exclusive access ensures that your applications run at peak efficiency without slowdowns, even during periods of heavy traffic. For businesses that depend on continuous uptime, this level of reliability is essential.

Windows servers are designed to support demanding workloads such as enterprise-level SQL databases, high-traffic IIS websites, or complex business applications already built on Windows.

The combination of dedicated hardware and the Windows operating system provide a predictable and optimized environment. It allows your systems to operate at full capacity with minimal risk of downtime or lag. Windows is also much easier to support, and you have Mircosoft support available (charges may apply) and you get free updates for the lifetime of the OS.

As a result, your business applications remain highly secure, accessible and responsive, supporting both day-to-day operations and long-term growth.

## Integration with the Microsoft Windows Server Environment

Another major advantage of Windows dedicated server hosting is its compatibility with other Microsoft products. Many organizations already rely on Microsoft products such as SQL Server, Active Directory, and .NET applications. Hosting on a Windows platform means these tools can work together easily, allowing developers to build and deploy in an environment they know well.

This integration also simplifies licensing and updates. Windows dedicated servers include automatic security patches and compliance with Microsoft licensing requirements.

Hosting companies like Atlantic.Net make this process even easier by offering licensed editions of Windows Server, including the latest version Windows Server 2025, directly within our cloud hosting plans, removing the hassle of separate license management.

## Security and Full Administrative Control

Security is a primary concern for any online business. With a dedicated server, you have far greater control compared to shared hosting. Administrators can set up firewalls, define custom security rules, and manage user access according to the organization’s internal policies. This level of control allows businesses to build a hosting environment that matches their specific security requirements.

Windows Server comes with several built-in protection tools, including BitLocker encryption, Windows Defender, and detailed security auditing features. Additionally, dedicated hosting providers like Atlantic.Net enhance this protection with enterprise-grade data center security, which includes 24/7 monitoring, biometric access restrictions, and intrusion detection systems. This infrastructure is built to comply with strict standards such as HIPAA and SOC 2.

For sectors such as healthcare, finance, or e-commerce, this combination of Windows security and Atlantic.Net’s infrastructure provides the strong safety needed to operate safely in regulated environments.

## Scalability and Flexibility

Windows dedicated server hosting provides the scalability required to grow without disruption. Whether you need extra storage space, more processing power, or higher memory capacity, the system allows you to increase resources easily whenever your workload demands it. For example, you can dynamically add additional servers to your Windows instance with zero downtime.

Flexibility is another strong advantage of Windows hosting. Businesses can choose configurations that best match their application needs, ranging from smaller setups for lightweight tools to high-performance servers designed for large enterprise systems. Atlantic.Net provides a wide range of dedicated server options, allowing customers to scale resources on demand and pay only for what they use. This makes it easier for businesses to stay efficient and cost-effective while keeping full control of their infrastructure.

## Remote Management and Ease of Administration

Managing Windows servers no longer requires being physically on-site. With Windows dedicated servers, administrators can easily handle their infrastructure from anywhere using tools such as Remote Desktop Protocol (RDP) and Windows Admin Center. These tools make it simple to monitor performance, install updates, and troubleshoot issues without needing direct access to the data center.

Atlantic.Net enhances this convenience with an easy-to-use control panel that simplifies daily management tasks. From a single dashboard, users can reboot servers, monitor system health, manage backups, and track resource usage. You also get console access to the server instance so you can see exactly what’s going on, even during the boot process!

This combination of Microsoft’s management tools and Atlantic.Net’s intuitive user interface gives IT teams complete visibility and control over the infrastructure, no matter where they are.

## Customization and Application Support

Every business has unique requirements, and a dedicated server offers the freedom to modify the environment accordingly. Windows dedicated servers support a broad spectrum of applications, including web hosting platforms and complex enterprise management systems. Organizations can install specialized software, configure databases, and fine-tune performance to match their operational goals.

Atlantic.Net makes this process easier by providing flexible server configurations and expert technical support. Our team assists with setup, migration, and optimization, ensuring clients get the best performance from their hosting environment even without having a large in-house IT department.

## Cost Efficiency Over the Long Term

While dedicated servers may seem more costly than shared or virtual hosting at first, they often prove to be more cost-effective over time. The improved performance, security, and reliability help prevent downtime and reduce the risk of costly disruptions. For businesses that depend on critical applications, this reliability brings a clear and measurable return on investment.

Atlantic.Net makes it even easier to manage expenses through transparent pricing and flexible hosting plans that adjust to each customer’s specific requirements. Clients can scale resources as their business grows, keeping costs aligned with usage. This approach keeps dedicated hosting both powerful and financially sustainable.

## Compliance and Industry Standards

For organizations that manage sensitive or regulated data, compliance is a top priority. Windows dedicated server hosting supports compliance with frameworks such as HIPAA, PCI DSS, and GDPR. Built-in Windows features like auditing, access control, and data protection make it easier to meet these obligations. For instance, Atlantic.Net’s certified data center offers [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and SOC 2 certification. This makes it a reliable choice for sectors such as healthcare and finance, where data integrity and privacy cannot be compromised.

## Conclusion

Selecting the right hosting solution is a critical decision for any business that values reliability, security, and control. Windows dedicated server hosting delivers these advantages by combining powerful hardware with the flexibility of the Windows platform. It offers a stable environment for demanding workloads, supports compliance requirements, and can scale easily as your business grows.

With Atlantic.Net, businesses gain the additional benefits of a secure infrastructure, transparent pricing, and expert technical support. Whether you are hosting enterprise applications, managing sensitive data, or running high-traffic websites, Atlantic.Net provides the performance and dependability needed to keep your operations running smoothly.


---

# The Benefits of Bare Metal for Big Data Analytics

> URL: https://www.atlantic.net/dedicated-server-hosting/the-benefits-of-bare-metal-for-big-data-analytics/ | Published: 2025-10-26 | Updated: 2025-10-27 | Author: Robert Agar

Modern companies process large volumes of both structured and unstructured data, analyzing multiple aspects of their businesses, their competition, and their customers. Decision-makers utilize the insights gained from big data analytics to make informed choices to drive competitiveness and operational efficiency. Organizations that ignore the valuable information offered by big data analytics risk falling behind market rivals and missing crucial business opportunities.

This article examines the importance of bare metal servers for big data analytics to companies of all sizes. We focus on how direct hardware access enhances and accelerates the analytical applications essential for success in today’s competitive business landscape.

## Why Do Businesses Need Big Data Analytics?

Businesses must effectively utilize the vast amounts of data they generate. Companies produce large datasets of information gathered from customers, internal operations, Internet of Things (IoT) devices, and digital interactions. Organizations that can utilize this information effectively can gain actionable insights, leading to better decision-making, improved efficiency, and a significant competitive advantage over less informed rivals.

Big data analytics refers to the collection, processing, and analysis of massive datasets that are typically too large and complex for traditional analytical tools to handle effectively. Big data applications often leverage advanced technologies such as artificial intelligence (AI) and machine learning to analyze this data. The goal of big data solutions is to uncover hidden patterns, customer preferences, operational inefficiencies, and market trends, resulting in predictive and meaningful insights.

The key business benefits of big data analytics include:

- Enhancing decision-making with fact-based insights;
- Promoting operational efficiency and lowering costs by optimizing processes;
- Improving risk management by identifying vulnerabilities before they are exploited;
- Addressing customer expectations through a deeper understanding of trends and behaviors;
- Providing a significant competitive edge fueled by faster and more accurate decisions.

A modern business must leverage the benefits of big data and real-time analytics to remain competitive in today’s rapidly evolving environment. Companies may face challenges in providing the computing power and storage space necessary for big data applications using on-premises data centers. The shared resources available in public cloud solutions may also be insufficient to provide the processing power required for effective big data analytics.

Organizations can meet the challenges posed by big data with bare metal cloud-based servers. These dedicated servers provide a solution that delivers the raw power and resource control necessary for big data processing without the exorbitant capital expenditures associated with an in-house, private infrastructure.

## What Are Bare Metal Servers?

Cloud service providers (CSPs) typically offer their customers solutions based on virtualized environments built on shared public cloud resources. These solutions and services are sufficient to address a wide variety of business needs, but may not deliver the high performance required by advanced applications such as big data analytics. Many CSPs also offer [bare metal, dedicated servers](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) to address more intensive computing requirements.

Bare metal cloud servers are physical, single-tenant computers dedicated to one organization or user. The customer does not share the machine with other clients, avoiding issues such as resource contention that can minimize the effectiveness of big data applications. Customers have exclusive use of the dedicated server, rather than sharing rented space as is the case with public cloud solutions.

A bare metal server provides the customer with direct access to the machine’s resources. The single-tenant nature of bare metal servers also furnishes complete control over the computer’s configuration.

### Key characteristics of bare metal servers

Bare metal servers share the following key characteristics, making them a practical choice for running mission-critical applications, such as real-time data analytics.

- The servers are dedicated to a single tenant with no resource sharing among other cloud customers.
- Users have direct access to the machine’s CPU, storage, networking, and memory.
- The computer is fully customizable. Clients can install the operating system of their choice and configure the hardware and storage systems to address specific business objectives.
- Customers are exposed to fewer cross-tenant security vulnerabilities.
- The lack of virtualization, hypervisor overhead, and resource sharing provides faster and more consistent performance.
- Bare metal servers can be vertically scaled by adding more resources, such as RAM or GPUs, to increase performance. Teams must consider the physical limitations of the machine when scaling it vertically.

## What Are the Benefits of Big Data on Bare Metal Servers?

Organizations running big data applications on bare metal servers stand to enjoy multiple benefits not available with virtualized public cloud or shared computing solutions. A bare metal server provides a company with an impressive combination of performance, control, and scalability. CSPs cannot deliver the same capabilities with virtualized cloud environments.

The following benefits of a bare metal solution are invaluable for addressing data-intensive applications such as machine learning training and big data processing.

### Maximum performance

Bare metal servers provide direct access to the hardware, eliminating the hypervisor overhead inherent in virtualized environments. This access enables faster processing and reduces latency issues often encountered with virtual machines. Big data applications, such as Hadoop and Spark, utilize this increased raw performance to deliver consistent and seamless real-time analytics.

### Customization and control

Customers have full control over every aspect of a bare metal server. Teams can tune the server’s hardware and software to address the specific requirements of their big data workloads. They can select specific hardware, such as high-speed local storage (e.g., NVMe) for fast data access, or add resources like GPU accelerators and high-performance network cards

Companies can optimize throughput by customizing the server’s operating system, filesystem, or data caching procedures. This level of customization is not possible in a standard cloud server scenario, where resources are shared among multiple tenants.

### Consistent resource availability

Customers can expect consistent access to the resources necessary to run big data solutions with a bare metal cloud solution. They will not be impacted by the noisy neighbors encountered in a shared environment, which can cause fluctuating performance and intermittent latency. The dedicated resources are crucial for ensuring stable computing power for analytics and other big data applications.

### Enhanced security

The single-tenant nature of a bare metal server offers stronger data security compared to a shared cloud solution. Companies that process sensitive data or are subject to compliance regulations, such as HIPAA, may need complete control over the server’s security posture. A bare metal cloud server reduces security risks, such as hypervisor exploits or data leakage.

### Excellent data throughput

Big data applications process massive amounts of structured and unstructured information, requiring fast and efficient read and write operations throughout the environment. Bare metal servers can be configured to provide high-speed local storage, ensuring fast data transfer and predictable performance.

### Optimization options

Providers can integrate GPUs and high-speed fabrics into bare metal cloud servers to provide the raw power required for AI model training and analytics. While shared cloud environments offer on-demand GPUs, a bare metal server provides dedicated access to these resources, avoiding performance contention and vGPU overhead.

### Scalability

Most companies processing big data eventually must scale their environment as the size of their datasets grows. Teams can scale individual servers vertically by adding more resources, such as CPU or memory. Companies can distribute workloads among multiple nodes to scale a bare metal environment horizontally.

### Cost savings

Organizations can save money by opting for a bare metal solution rather than renting virtual instances. Bare metal servers can be especially beneficial to companies with heavy and continuous workloads. Customers pay for the raw performance of the dedicated servers without the additional expense of virtualization overhead and management services.

## Bare Metal Servers Support Big Data Analytics

Many businesses can benefit by utilizing bare metal servers for processing big data resources and performing real-time data analytics. Companies that lack the resources to deploy an on-premises bare metal infrastructure can achieve the same benefits with a cloud-based bare metal solution while eliminating capital expenses. Organizations leveraging the power of bare metal can give themselves a significant competitive advantage by tailoring the system to their precise specifications.


---

# Achieving Unparalleled Security with Single-Tenant Dedicated Hosting

> URL: https://www.atlantic.net/dedicated-server-hosting/achieving-unparalleled-security-with-single-tenant-dedicated-hosting/ | Published: 2025-10-27 | Updated: 2026-06-17 | Author: Dr. Assad Abbas

Cyberattacks have become frequent and complex, while cloud misconfigurations have exposed millions of records worldwide. These incidents have led many organizations to question the reliability of their infrastructure security. The public cloud offers speed and flexibility, but its shared structure introduces hidden risks. When multiple users share the same environment, even a single error can expose data across tenants, creating serious security concerns.

Organizations that handle sensitive or regulated data cannot take such risks. They require complete control, apparent isolation, and compliance-ready systems that can be audited and trusted.
 Single-tenant [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) meets these needs. It provides a dedicated physical server for a single client, with no shared hardware or external access. This model reduces the attack surface, maintains steady performance, and ensures full control over security measures and monitoring practices.

Therefore, for businesses seeking a secure and transparent hosting environment, single-tenant dedicated hosting offers a reliable and controlled foundation for modern digital operations.

## What Is Single-Tenant Dedicated Hosting?

A single-tenant dedicated server is a physical machine allocated exclusively to one organization. Unlike shared or virtual servers that host multiple tenants, it isolates computing power, memory, and storage at the hardware level.

This complete separation ensures that no external entity can interfere with workloads or access stored data. It removes the risks of performance degradation caused by noisy neighbors and prevents cross-tenant data exposure through hypervisors. Moreover, it enables administrators to configure the operating system, deploy security tools, and manage encryption keys in accordance with organizational policies and compliance requirements.

**Table 1: Difference between Single-Tenant and Multi-Tenant Hosting**

| **Feature** | **Single-Tenant Dedicated** | **Multi-Tenant (Shared/Cloud)** |
| --- | --- | --- |
| **Resource Isolation** | Full hardware isolation | Shared CPU, RAM, storage |
| **Security Control** | Complete (customizable firewalls, IDS/IPS, access control) | Limited; depends on the provider |
| **Performance** | Predictable and stable | Variable based on the usage of others |
| **Compliance** | Easier to certify HIPAA, PCI DSS, SOC 2 | Complex due to shared infrastructure |
| **Cost** | Higher upfront | Lower initial, variable over time |

For organizations in healthcare, finance, and government, single-tenant dedicated hosting is sometimes required to meet strict compliance and data protection standards.

## Why Isolation Matters for Security and Compliance

Security in information systems encompasses more than just encryption or firewalls. It also depends on reducing the attack surface. Single-tenant dedicated hosting achieves this by removing shared layers of infrastructure and giving one organization complete control.

### Physical Isolation

In a single-tenant model, the entire server, including the processor, memory, storage, and network interface cards, is dedicated to a single client. No other workloads run on the same hardware. This prevents risks of shared hypervisors, such as side-channel attacks like Spectre or Meltdown. Data centers that host these servers typically employ strict physical security measures, including biometric entry systems, video surveillance, and redundant power and cooling systems.

### Network Protection

Dedicated servers enable organizations to develop their own customized network security measures. They can configure firewalls, create private VLANs, and use intrusion prevention systems. Many providers also include managed DDoS protection and encrypted links between data centers. These measures reduce the chance of unauthorized access or data interception.

### Compliance-Ready Infrastructure

Single-tenant hosting also supports regulatory compliance. Since the client controls all layers of the system, it is easier to meet and document requirements for audits. This model aligns with standards such as:

- HIPAA / HITECH for healthcare data
- PCI DSS for payment processing
- SOC 2 / SOC 3 for service audits
- ISO 27001 / GDPR for international security and privacy

In contrast, shared cloud environments often create unclear divisions of responsibility. Dedicated hosting avoids this problem by providing clear ownership and accountability.

## Essential Features of Secure Single-Tenant Hosting

Single-tenant dedicated hosting strengthens infrastructure security through isolation, control, and transparency. Each component of the environment, from hardware to backup, is designed for a single organization. The following features outline how this model provides enhanced protection and compliance.

### Private Storage

In a single-tenant setup, all storage devices, such as NVMe or SATA SSDs, are owned by a single organization. No other client can share or access them. This exclusive allocation eliminates the risks associated with shared disks and provides additional protection through hardware-level encryption and RAID redundancy.

### Tenant-Controlled Firewalls and IDS/IPS

One tenant fully controls network security tools in single-tenant environments. Firewalls, intrusion detection, and prevention systems are configured only for that organization’s traffic. This independence prevents conflicts or vulnerabilities that can emerge in shared environments.

### Independent Backup Strategy

Data protection in single-tenant hosting is also isolated. Backup routines, off-site replications, and encrypted archives are managed separately for each organization. This ensures that recovery processes remain secure and cannot be influenced by other users.

### Compliance Certification

Data centers supporting single-tenant servers are often certified for frameworks such as HIPAA, PCI DSS, or ISO 27001. The absence of shared infrastructure simplifies audits and makes compliance responsibilities clearer, which is essential for regulated industries.
 Together, these elements show that single-tenant dedicated hosting provides security through physical isolation, administrative control, and verifiable compliance. Each layer of the system, from hardware to network defense, is designed to protect a single organization.

## Top Single-Tenant Dedicated Hosting Providers (2025)

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

### [Atlantic.Net](http://www.atlantic.net)

Among single-tenant hosting providers, Atlantic.Net is popular for its strong emphasis on security and compliance. Established in 1994, it is one of the oldest U.S.-based hosting companies, recognized for its infrastructure designed to support sensitive workloads. Its [bare-metal servers](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) operate in fully isolated, single-tenant environments, offering dedicated performance and strict control, a model well-suited for industries such as healthcare, finance, and government.

- **Security and Compliance:** Atlantic.Net’s infrastructure meets leading compliance standards, including HIPAA, HITECH, PCI DSS, SOC 2, and SOC 3. The company also supports Business Associate Agreements (BAA) for clients in healthcare and related sectors, ensuring full audit readiness and data protection.
 ****
- **Global Data Center Footprint:** The company operates modern data centers in Orlando, Dallas, San Francisco, Ashburn, and New York, along with additional sites in Canada, the U.K., and Asia. This broad coverage helps clients to achieve regional redundancy and low-latency access for distributed teams.
 ****
- **Support and Management:** Atlantic.Net provides 24/7 U.S.-based technical support through phone and email. Both managed and unmanaged service models are available, allowing organizations to either retain complete administrative control or delegate maintenance and monitoring to the provider’s experts.
 ****
- **Performance and Configuration Options:** Dedicated servers feature the latest Intel Xeon and AMD EPYC processors, ECC RAM, and NVMe SSD storage for high throughput and reliability. In addition, configurations are flexible, with options reaching up to 104 CPU cores, 2 TB of RAM, and 90 TB of storage, making them suitable for large-scale applications or research workloads.
 ****
- **Network and Security Tools:** Each dedicated server includes unmetered inbound bandwidth, managed firewalls, advanced DDoS protection, and optional VPN connectivity. Clients also receive full root access and can bring their own licenses (BYOL) or choose their preferred operating systems.

![InterServer Logos - Interserver Tips](https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcSNUNvCz-J9OkZDpg7wQcDCYHeP6xsqAyJexw&s)

### [InterServer](https://www.interserver.net/)

Founded in 1999, InterServer is a U.S.-based hosting company known for its affordability and direct ownership of its data centers. Unlike resellers, InterServer maintains complete physical control of its infrastructure, which strengthens security and reliability. Its dedicated servers operate in single-tenant environments, giving clients exclusive access to hardware resources and predictable performance. This model is attractive for small to mid-sized businesses that require secure hosting without high costs.

- **Security and Compliance:** InterServer offers single-tenant servers equipped with built-in DDoS protection, IPMI/iLO access, and remote OS reinstalls. While it does not market itself as a compliance-first provider like Atlantic.Net, its dedicated infrastructure supports organizations that need isolation for sensitive workloads. Clients can configure their own firewalls, monitoring tools, and backup strategies to align with compliance requirements such as PCI DSS or ISO 27001.
 ****
- **Data Center Footprint:** The company owns and operates its primary facilities in Secaucus, New Jersey (HQ), and Los Angeles, California. This ownership ensures direct oversight of physical security, including restricted access, surveillance, and redundant power systems. InterServer also partners with international locations to achieve an extended reach, but its U.S. footprint remains its strongest asset.
 ****
- **Support and Management:** InterServer provides 24/7 technical support via phone, live chat, and ticketing systems. Both managed and unmanaged configurations are available, allowing clients to choose between complete administrative control or provider-assisted maintenance.
 ****
- **Performance and Configuration Options:** Dedicated servers range from AMD Ryzen 5600X (6 cores) at the entry level to dual Intel Xeon and AMD EPYC processors for higher workloads. Memory scales up to 512 GB RAM, with flexible storage options including HDD, SSD, and NVMe drives.
 ****
- **Network and Security Tools:** Each server includes 1 Gbps unmetered bandwidth, with upgrades to 10 Gbps available. Clients benefit from DDoS protection, customizable firewall rules, and the ability to deploy private VLANs. Full root access is provided, ensuring complete control over the environment.

![](https://www.atlantic.net/wp-content/uploads/2025/10/contabo_logo.png)

### [Contabo](https://contabo.com/en/dedicated-servers/)

Founded in Germany in 2003, Contabo has established itself as a global infrastructure provider known for delivering dedicated server solutions with a strong emphasis on affordability, scalability, and resource-rich configurations. The company serves businesses, developers, and enterprises that require single-tenant dedicated hosting environments without the premium pricing often associated with enterprise infrastructure. Its dedicated servers provide exclusive access to physical hardware, ensuring predictable performance, resource isolation, and administrative control.

- **Security and Compliance:** Contabo operates modern data centers with multiple layers of physical and network security designed to protect customer workloads. The company adheres to European data protection standards, including GDPR requirements, making it a suitable choice for organizations handling sensitive information within regulated environments. Dedicated servers benefit from isolated hardware resources, reducing exposure to risks commonly associated with multi-tenant infrastructures.
- **Global Data Center Footprint:** Contabo maintains a growing international presence with data center locations across Europe, North America, Asia, and Australia. This global infrastructure enables organizations to deploy applications closer to their users, improve latency, support international operations, and meet regional data residency requirements. The company’s European roots remain particularly attractive for businesses seeking hosting solutions aligned with EU privacy regulations.
- **Support and Management:** Contabo provides technical support services and self-service management tools that allow customers to maintain full administrative control over their dedicated servers. Businesses can choose unmanaged deployments for maximum flexibility or leverage available support resources for infrastructure-related assistance. Remote management capabilities simplify server provisioning, monitoring, and troubleshooting.
- **Performance and Configuration Options:** Contabo’s dedicated server portfolio includes systems powered by modern Intel Xeon and AMD EPYC processors, offering substantial compute capacity for business-critical workloads. Customers can configure servers with large memory allocations, enterprise-grade SSD or NVMe storage, and RAID options for enhanced redundancy and performance. These configurations support a wide range of use cases, including virtualization, database hosting, application hosting, and high-traffic web services.
- **Network and Security Tools:** Contabo provides high-bandwidth connectivity, DDoS mitigation capabilities, and private networking options that help organizations maintain secure and reliable operations. Advanced networking features enable customers to segment workloads, support internal communications between infrastructure components, and build scalable architectures capable of supporting growing business requirements.

### ![](https://www.atlantic.net/wp-content/uploads/2026/03/hetzner-logo.png)

### [Hetzner](https://www.hetzner.com/)

Founded in 1997, Hetzner is a German hosting provider known for delivering high-performance infrastructure with transparent operations. Its dedicated servers are widely used by European developers, research groups, and enterprises that require secure single-tenant environments. By giving clients exclusive access to hardware, Hetzner ensures predictable performance and strong isolation.

- **Security and Compliance:** Hetzner’s dedicated servers operate in single-tenant configurations, ensuring that no hardware resources are shared with other clients. The company provides DDoS protection, snapshot backups, and complete IPMI management for secure remote administration. Hetzner is certified under ISO/IEC 27001:2022, confirming adherence to international standards for information security management. This makes it suitable for organizations that must comply with GDPR and other EU data protection requirements.
 ****
- **European Data Center Footprint:** Hetzner operates modern data centers in Nuremberg and Falkenstein, Germany, as well as Helsinki, Finland. These facilities are equipped with redundant power, advanced cooling, and strict physical access controls. Their EU locations make Hetzner attractive for clients that must keep sensitive data within European borders.
 ****
- **Support and Management:** Clients can choose between managed and unmanaged configurations. Hetzner provides 24/7 support through its ticketing system and offers extensive documentation and automation tools for self-management. This flexibility appeals to both enterprises and technical teams.
 ****
- **Performance and Configuration Options:** Hetzner’s dedicated servers feature Intel Xeon, AMD EPYC, and Ryzen processors, with configurations scaling up to 1 TB of ECC RAM. Storage options include NVMe SSDs and hardware RAID for redundancy. The company also offers GPU-based servers, which are well-suited for AI training, rendering, and other computationally intensive workloads.
 ****
- **Network and Security Tools:** Each server features 1 Gbps of unmetered bandwidth, with optional upgrades available for higher throughput. Hetzner integrates DDoS protection by default and provides private networking options for workload isolation. Clients also benefit from snapshot backups and secure remote management.

![](https://www.atlantic.net/wp-content/uploads/2025/08/ionos-logo.png)

### [IONOS](https://www.ionos.com/)

IONOS was founded in Germany in 1988. IONOS is one of Europe’s largest hosting providers, offering enterprise-grade infrastructure with a focus on managed services, high availability, and strict data protection. Its dedicated servers operate in single-tenant environments, giving organizations exclusive access to hardware resources and ensuring predictable performance. This model is well-suited for regulated industries that require certified security standards and reliable uptime.

- **Security and Compliance:** IONOS data centers are certified under ISO/IEC 27001, confirming adherence to international standards for information security management. Security features include DDoS mitigation, managed firewalls, free SSL certificates, intrusion detection systems, and encrypted remote access. These measures support organizations that must demonstrate compliance with GDPR and other data protection regulations.
 ****
- **Global Data Center Footprint**: IONOS operates modern data centers in Europe and the United States, ensuring geographic redundancy and compliance with regional data sovereignty requirements. Facilities include advanced physical security, redundant power, and climate-controlled environments.
 ****
- **Support and Management**: The company provides 24/7 technical support and offers both managed and unmanaged configurations. Clients can retain complete administrative control or delegate monitoring, patching, and maintenance to IONOS experts. A 99.99% uptime SLA applies to specific products, reflecting its commitment to reliability.
 ****
- **Performance and Configuration**: Options IONOS dedicated servers are powered by Intel Xeon processors, with configurations scaling up to 512 GB of ECC RAM. Storage options include SSD and NVMe drives with redundancy for high availability. These resources support demanding workloads such as databases and enterprise applications.
 ****
- **Network and Security Tools**: In addition to DDoS protection and managed firewalls, IONOS provides secure networking options that allow organizations to isolate workloads and maintain encrypted communication. Clients also benefit from full root access for flexible system configuration.

## Best Use Cases for Single-Tenant Dedicated Hosting

Single-tenant dedicated hosting supports a wide range of industry needs, from regulated environments to performance-intensive workloads. Each provider offers specific strengths that align with different operational goals.

Atlantic.Net is particularly suitable for organizations in healthcare, finance, and government sectors. Its HIPAA- and PCI-ready infrastructure enables hospitals, research institutions, and analytics firms to deploy compliant systems with strong isolation. A healthcare analytics company, for example, can utilize Atlantic.Net’s U.S. data centers to securely process patient data while meeting audit requirements under a signed Business Associate Agreement (BAA). The combination of regulatory readiness, managed firewalls, and DDoS protection makes Atlantic.Net an ideal choice for projects where data integrity and compliance transparency are essential.

InterServer is ideal for small to mid-sized businesses seeking cost-effective security solutions. E-commerce companies or online platforms with moderate traffic can rely on unmetered bandwidth and single-tenant hardware for predictable performance and control, without incurring high operational costs.

Contabo is ideal for organizations seeking cost-effective dedicated hosting with substantial computing resources. A software development company can run virtual machines, CI/CD pipelines, and staging environments on Contabo’s dedicated servers to gain exclusive hardware access, predictable performance, and operational control without the higher costs associated with many enterprise-focused providers.

Hetzner is well-suited to research groups, developers, and European enterprises that value performance and affordability. GPU-based workloads, such as AI training or data modeling, can run efficiently on Hetzner’s ISO 27001-certified infrastructure, ensuring compliance with EU data protection regulations.

IONOS serves enterprises that prioritize managed services and uptime guarantees. Financial or consulting firms can use their single-tenant servers for databases and client applications that require continuous availability, backed by a 99.99% SLA and certified security measures.
 Together, these use cases demonstrate how single-tenant dedicated hosting can be tailored to meet various operational needs. Whether the goal is regulatory compliance, computational power, or regional control, this model provides a secure and dependable foundation for digital operations.

## Final Thoughts

Cyberattacks are becoming increasingly complex, and compliance requirements are also escalating in complexity. In this situation, single-tenant dedicated hosting becomes the most dependable option for protecting sensitive workloads. It provides full isolation, consistent performance, and complete administrative control, which shared cloud environments cannot offer.

Among leading providers, Atlantic.Net is known for its long experience in compliance and its security-focused infrastructure design. It is widely trusted in healthcare, finance, and government sectors. Other providers, including InterServer, Contabo, Hetzner, and IONOS, also offer reliable dedicated hosting solutions for different budgets and regions.

Ultimately, the strength of modern cybersecurity depends on control and isolation. When infrastructure belongs entirely to one organization, every layer, from hardware to data, remains protected from external interference and aligned with the highest standards of trust and compliance.


---

# Deploying HIPAA-Compliant Proxmox VE on Bare Metal

> URL: https://www.atlantic.net/hipaa-compliant-hosting/deploying-hipaa-compliant-proxmox-ve-on-bare-metal/ | Published: 2025-10-29 | Author: Richard Bailey

For organizations in healthcare and, increasingly, the AdTech space, the need for control, performance, and provable data security is an unnegotiable prerequisite. While public cloud platforms excel at general-purpose hosting, achieving compliance in those environments can be difficult—often requiring costly, bespoke HIPAA configurations.

However, numerous customers prefer custom Infrastructure-as-a-Service (IaaS) solution over cloud hosting. An environment built on HIPAA-compliant Proxmox VE and dedicated bare metal is an option for those with the skills and experience of managing private virtualized environments.

## Is Proxmox HIPAA-Compliant?

Proxmox is a powerful, open-source server management virtual environment platform that bundles KVM hypervisors and LXC containers into a single, web-based interface. When you deploy Proxmox on dedicated bare metal servers, you get the “best of both worlds”: the raw performance of dedicated hardware and the flexibility of a cloud-native environment, all without the prohibitive licensing fees of proprietary alternatives.

However, installing Proxmox is relatively easy. Making it *compliant* is still extremely challenging. This guide will introduce Proxmox for HIPAA-Compliant environments, and discuss the key areas that must be configured so that you can build a secure, auditable, and high-performance IaaS environment to protect both Electronic Protected Health Information (ePHI) and sensitive Personally Identifiable Information (PII).

Atlantic.Net is a HIPAA-Compliant hosting provider with 30 years of experience in the IT industry. If you are considering Proxmox Bare Metal for your next deployment, [get in touch](https://www.atlantic.net/about-us/corporate-contact/).

## Why Bare Metal and Proxmox for Compliance?

A Proxmox stack offers foundational advantages that not all public clouds can match. When combined with the flexibility of bare metal hosting, it becomes a very compelling offering.
 Here are 4 key reasons we hear from our customers:

### #1: Single-Tenant Security & Control:

The most significant compliance advantage of a bare metal deployment is ownership. There are no shared resources, so co-tenancy risks—only your environment, under your control, from the physical layer upward. This provides a strong foundation for HIPAA and GDPR compliance audits.

### #2: Unrivaled Performance:

Healthcare and AdTech applications are typically very data-heavy—think multi-gigabyte [PACS images](https://radiopaedia.org/articles/picture-archiving-and-communication-system?lang=gb) or real-time bidding engines. Bare metal infrastructure allows virtual machines to access CPU cores, RAM, and NVMe storage without contention.
 Proxmox’s KVM hypervisor, integrated into the Linux kernel, delivers near-native performance—crucial for latency-sensitive or compute-intensive workloads.

### #3: Cost-Effective Scalability:

Proxmox is open-source. Your costs are tied to predictable hardware resources, not fluctuating vCPU charges or proprietary software licensing fees. This makes building a high-availability cluster far more economical than using products like VMware vSphere or Microsoft Hyper-V.

### #4: Workload Flexibility (VMs vs. Containers):

Proxmox can be configured to provide full-stack KVM virtual machines and lightweight LXC containers in one platform. This allows you to use the right tool for the job:

- **Virtual Machines:** Perfect for strong security isolation and running legacy applications or different operating systems (like a Windows server for a specific medical device).
- **Linux Containers:** Ideal for speed and efficiency, allowing you to spin up microservices for AdTech bidding engines or modern healthcare app components in milliseconds.

## Building a HIPAA-Compliant Proxmox Environment

Remember that HIPAA compliance is not a product—it’s a continuous process guided by Administrative, Physical, and Technical safeguards. A compliant IaaS must address all three. When building a HIPAA-ready Proxmox platform, these core principles need to be at the forefront of the design process.

### Physical & Administrative Safeguards

Even a perfectly configured Proxmox host cannot be compliant if the underlying data center is insecure. Choose a hosting provider that has compliance built into its data center environments. You need guaranteed security and business processes to ensure data integrity.
 The core safeguards include:

#### The Business Associate Agreement (BAA)

The BAA is non-negotiable. If a provider will not sign a BAA, you cannot use them for ePHI. A BAA is a legal contract that holds the provider accountable for the physical security of your data. As a 30-year veteran in IT, Atlantic.Net has been providing BAA-backed, [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) from our audited data centers for decades.

#### Physical Security:

Your BAA ensures the provider’s data center meets HIPAA requirements: as a minimum, you require 24x7x365 security, biometric access controls, video surveillance, and secure cabinets.

### Technical Safeguards

The flexibility of open-source means the responsibility for these technical safeguards remains in-house. This requires your own technical expertise to configure, manage, and monitor the environment correctly. This is your responsibility. Here’s how you configure Proxmox VE to meet HIPAA’s technical requirements.

#### Access Controls

**Use 2FA/TFA:** Enforce Two-Factor Authentication (like [TOTP](https://datatracker.ietf.org/doc/html/rfc6238)) for all user accounts on the Proxmox web UI, especially the root user.

**Implement Role-Based Access Control (RBAC):** Don’t let everyone use root. Proxmox has a granular permissions system. Create specific groups like VM-Admins, Auditors (with read-only access), and Backup-Operators. Assign users to these roles to enforce least-privilege access.
 **Centralize Users:** Integrate Proxmox with an Active Directory, LDAP, or SAML server for centralized user management and password policies.

#### Audit Controls

HIPAA mandates the ability to “record and examine system activity. Forward all relevant logs—/var/log/syslog, /var/log/auth.log, and Proxmox task logs—to a centralized, write-once SIEM platform. This provides an immutable audit trail for incident analysis.

#### Encryption

**Data at Rest:** Use ZFS with native encryption during installation to protect VM and container disks automatically.
 **Data in Transit:**

- Replace the default self-signed SSL certificate with a valid one.
- Encrypt live migration traffic (Datacenter → Options → Migration).
- Isolate cluster communication on a dedicated VLAN.
- Ensure internal VM traffic carrying ePHI or PII is encrypted using SSL/TLS, SSH, or VPN tunnels.

## Secure Deployment Strategy: Segmentation is Everything

A successful HIPAA-compliant Proxmox deployment hinges on a core concept: *segmentation*. This is where the true flexibility of an open-source platform shines, allowing you to configure the network to your exact needs in a way that is often impossible with closed-source products.
 You must build digital “locked doors” between your services. Proxmox’s built-in firewall and support for Linux bridges/VLANs are your primary tools here.

### Segmented Network

Assume your Atlantic.Net bare metal server has two network interfaces:

- **eno1 (Management/Cluster):** This is for your Proxmox UI, SSH, and cluster traffic. It should be on a private management VLAN accessible only via a secure jump box or VPN. It should never be exposed to the public internet.
- **eno2 (VM Traffic):** This is for your virtual machines. This is where you create your VLAN-aware bridges.

Your network should look something like this:

| **VLAN ID** | **Name** | **Purpose** | **Bridge** | **Firewall Policy** |
| --- | --- | --- | --- | --- |
| 10 | Management | Proxmox UI / SSH | vmbr0 (eno1) | Allow only from trusted admin IPs |
| 20 | Cluster | HA/Corosync Traffic | vmbr0 (eno1) | Allow only between cluster nodes |
| 30 | Public / DMZ | Internet-facing servers | vmbr1 (eno2) | Allow HTTP/HTTPS only |
| 40 | Application | Internal app layer | vmbr2 (eno2) | Allow limited ports from VLAN 30 |
| 50 | Database | ePHI / PII data storage | vmbr3 (eno2) | Allow only from VLAN 40; no Internet access |

By enabling the Proxmox firewall at the Datacenter level and at each VM level, you create a zero-trust environment. For Example, in this setup, a compromised web server in VLAN 30 cannot access the database in VLAN 50, because the hypervisor itself blocks the traffic before it even leaves the host.

### Secure Backups & Disaster Recovery

[HIPAA’s Contingency Plan](https://www.atlantic.net/disaster-recovery/) requirements mandate proven backup and recovery procedures. Proxmox Backup Server (PBS) is a powerful, open-source option for this purpose:

- Deploy PBS on a separate, dedicated server with encrypted disks.
- Add it as a storage target to your Proxmox cluster.
- Schedule frequent, automated backups.
- Enable encryption at the job level to protect ePHI within backup data.
- Regularly test restore operations—an untested backup is not compliant.

If you prefer, you may be able to use a [managed service](https://www.atlantic.net/managed-services/) from your hosting provider.

## Use Cases: Healthcare and AdTech

### Healthcare

- **EHR/EMR Hosting:** Deploy EHR systems (e.g., OpenEMR) within isolated VMs using a three-tier architecture—web, application, and database layers—each on its own VLAN.
- **PACS and Imaging:** Implement ZFS storage pools backed by NVMe drives for fast retrieval of large imaging files.

### AdTech

- **Secure Data Enclaves:** Store health-related user data in encrypted VMs within a locked-down VLAN.
- **High-Performance Analytics:** Run short-lived, high-CPU VMs for analytics against secure data without exposing raw information.
- **Low-Latency Bidding:** Deploy RTB microservices in LXC containers for near-bare-metal speed while maintaining strict separation from PII databases.

## Shared Responsibility and Compliance Summary

Compliance is a partnership. Even with a secure infrastructure provider, you retain responsibility for maintaining application-level security and documentation.

| **Safeguard** | **Responsibility** | **Example** |
| --- | --- | --- |
| **Physical** | Hosting Provider | Data center security, environmental controls |
| **Administrative** | Both | Policies, staff training, and BAAs |
| **Technical** | You (Customer) | Encryption, access control, logging, patching |

## Your Partner in Compliance

Building a custom HIPAA-compliant Proxmox IaaS on bare metal gives you unparalleled control, performance, and security. It’s the smart, modern alternative to the public cloud, freeing you from vendor lock-in and prohibitive licensing costs. But this flexibility comes with the responsibility of technical management. However, you don’t have to do it alone.

For 30 years, Atlantic.Net has been that foundation. Our USA data centers are all SSAE 18 SOC 2/3 and HIPAA audited, and we’ve been a trusted partner for healthcare and finance industries for decades. We provide the secure bare metal, the BAA, and the 24×7 expert support—including managed services to handle the patching, security, and operations—giving you the confidence needed.

[Contact our experts today](https://www.atlantic.net/about-us/corporate-contact/) to discuss your dedicated hosting or HIPAA-compliant infrastructure needs.

 


---

# A Comprehensive Guide to Dedicated Server Technology for Your Business

> URL: https://www.atlantic.net/dedicated-server-hosting/a-comprehensive-guide-to-dedicated-server-technology-for-your-business/ | Published: 2025-10-29 | Author: Robert Agar

Companies use dedicated servers to address business objectives and requirements that cannot be handled effectively with a shared computing solution. A business can implement a dedicated server on a physical machine in an on-premises data center or on a cloud hosting platform. Our focus will be on cloud solutions that are available to any organization to meet their business needs.

This article examines the latest innovations in dedicated servers and dedicated server hosting – technologies that provide the computing power and consistent performance needed to meet rising customer demands.

## What Is a Dedicated Server?

A dedicated server is a physical server used exclusively by a single organization, user, or application. It provides customers with complete control to configure, optimize, and secure the server according to their specific requirements.

### Key characteristics of dedicated servers

- Teams have root access to the machine and full control over the server setup, operating system, installed applications, and security settings.
- The customer enjoys exclusive use of all hardware resources, such as CPU, storage, and network bandwidth.
- Dedicated servers provide enhanced security compared to a shared hosting solution by isolating the environment and sensitive data from other users.
- Organizations can improve performance by installing custom software and tuning the server to optimize intensive workloads, such as ML model training or AI analytics.
- Teams can scale a dedicated server by adding additional physical resources, such as storage devices or CPU cores.

## Main Business Uses of Dedicated Servers

Organizations can utilize dedicated servers to solve a wide range of business problems more effectively than with a shared hosting environment. The following are some of the primary uses of dedicated servers for modern businesses.

- Companies can leverage the robust performance and reliability to address high-traffic website and application hosting requirements. Teams have complete control over web server configuration and can ensure no performance degradation during traffic spikes. The high availability provided by dedicated resources offers excellent support for mission-critical enterprise software such as ERP and CRM tools.
- Organizations can use dedicated servers as the foundation of a virtualized infrastructure, allowing them to create custom hosting environments. This approach means teams can run multiple virtual machines on a physical server with full control over the virtualization stack, enhanced security compared to a shared solution, and stable VM performance due to dedicated server resources.
- Businesses can use a dedicated server as the center of their communication infrastructure. Teams can host email servers on dedicated hardware resources and control security policies, encryption, and data protection measures. Companies can ensure reliable communication by eliminating their reliance on third-party email providers.
- Companies processing regulated data and subject to regulatory standards can meet compliance requirements with a dedicated server environment. A dedicated server provides physical isolation and exclusive access to sensitive data, supporting compliance standards such as HIPAA and PCI-DSS. They also streamline the auditing and the documentation necessary to demonstrate compliance.
- Businesses that provide gaming and video streaming services benefit from the specialized hardware, high bandwidth, and low latency available with a dedicated hosting solution. For examples, providers can host multiplayer online games on dedicated gaming servers, offering players a smooth, consistent, and satisfying experience. Similarly, content streaming companies can meet customer expectations and avoid resource contention experienced with shared hosting.
- Customers with high-performance computing (HPC) needs benefit from the dedicated hardware resources and the scalability of a dedicated server. The computing power and enhanced security of a dedicated solution align with the needs of companies engaged in advanced analytics and AI/ML research.

Teams must demonstrate greater technical expertise to achieve optimal benefits from dedicated server hosting options. They must have the technical knowledge to perform the custom configuration necessary to support their business objectives. Team members are responsible for critical maintenance tasks, including installing software updates and security patches.

## What Are the Latest Innovations in Dedicated Server Technology?

The technologies supporting dedicated servers are evolving to address the changing demands of modern businesses.

### Advanced and next-generation server hardware

Modern workloads demand high-performance solutions. Dedicated servers can offer optimal performance because upgrading the physical hardware in the hosting provider’s data center is straightforward. Processing power and functionality are skyrocketing with the addition of cutting-edge CPUs like the AMD EPYC series and powerful GPUs such as the NVIDIA H100 Tensor Core. Beyond this, AI accelerators and neural processing units (NPUs) are being deployed to address analytics, inference, and generative AI tasks.

Latency is also being significantly reduced by upgrading memory and storage with ultra-fast NVMe SSDs and persistent DIMMs. This speed increase can be essential for time-sensitive applications such as real-time analytics.

### Automation and AI management

Providers are leveraging AI to automate the management of dedicated servers, optimizing resources and improving reliability. The following examples demonstrate the use of AI and automation to manage dedicated servers.

- **Intelligent server monitoring and analytics:** AI solutions include real-time dashboards that provide performance insights. ML models and NLP tools analyze and summarize logs to identify the root cause of performance issues and take proactive measures such as load balancing and modifying server settings.
- **Automated security and compliance:** AI tools perform continuous threat monitoring to detect and respond to anomalies and intrusions in real time. Providers can automate patch management to ensure that they address vulnerabilities by installing security updates as soon as they become available. Teams can enforce regulatory policies with security-as-code frameworks to streamline compliance.
- **Fault detection and predictive maintenance:** AI and trained ML models analyze logs and sensors to detect anomalies and perform predictive analytics to identify components that may fail, enabling proactive replacement. Automated bots can take measures such as rerouting traffic or restarting services to address issues.

### Improved energy efficiency and sustainability

Addressing the energy requirements of dedicated servers is another area of innovation, with several new techniques emerging.

- **Dynamic power management:** Smart controllers can adjust processor power draw in real time to address fluctuating requirements and reduce operational costs.
- **Liquid cooling:** Providers employ methods such as immersion cooling, in which entire servers are submerged in non-conductive fluids, and direct-to-chip cooling to reduce energy consumption significantly.
- **Sustainable energy sources:** The hosting provider’s data center can be powered by sustainable energy sources and leverage the cooling capabilities of nearby bodies of water, such as lakes and rivers.

### Security enhancements

Companies often run mission-critical and sensitive applications on dedicated servers. Consequently, providers are implementing innovative methods to protect their customers’ valuable server resources.

- **Hardware-level security:** The Trusted Platform Module (TPM 2.0) is essential for Windows Server users and provides hardware-based encryption keys to ensure only trusted components can execute on the server. A hardware root of trust strengthens authentication and helps protect against threats that evade traditional firewalls. Encrypted enclaves enable customers to process sensitive data in memory.
- **Network and perimeter security:** Dedicated server hosting providers are protecting customer systems with advanced firewalls and real-time intrusion detection systems. Many providers offer multi-layer DDoS protection by default. Communication is secured via dedicated VLANs and VPN tunnels between servers and admin systems.
- **Zero-trust architecture:** Providers are implementing a zero-trust approach to dedicated server security that verifies every request with no implicit trust for users or devices. Network resources are microsegmented to contain breaches, and every access attempt is verified via continuous authentication.
- **End-to-end data encryption:** Customer data is encrypted at rest and in transit to protect it from unauthorized use. Teams should ensure backups are encrypted and stored securely.

## How to Choose a Dedicated Server Provider

Decision-makers should consider the following factors when selecting a [dedicated server hosting provider](https://www.atlantic.net/dedicated-server-hosting/).

- **Business needs:** Companies should have well-defined reasons for needing their own dedicated server that they cannot meet with other hosting provider options.
- **Hardware availability:** The provider should offer top-of-the-line hardware, including cutting-edge processors, storage systems, and GPUs.
- **Transparent pricing:** You want a provider that offers precise cost details so you can accurately budget for a dedicated server. Customers may be able to obtain additional services with different pricing plans.
- **Management and support options:** You need to know how dedicated servers are managed and supported. Is there a support team available if issues arise with unmanaged servers?
- **System and network security:** The provider must provide DDoS and intrusion protection, hardware-level security, and end-to-end encryption. There should be 24/7 security to protect the physical computers in the data center, and the network should be protected with next-gen, intelligent firewalls and IDS solutions.

A dedicated server offers customers a secure, high-performing platform for running the modern, compute-intensive, and sensitive applications necessary to maintain competitiveness. The innovations in the underlying dedicated server technologies make them the logical choice for a wide range of businesses.


---

# Affordable PCI Compliance: Is Managed Hosting Worth It?

> URL: https://www.atlantic.net/pci-compliant-hosting/affordable-pci-compliance-managed-hosting-2/ | Published: 2025-11-03 | Updated: 2025-10-24 | Author: Dr. Tehseen Zia

Every business that accepts credit card payments faces the reality that compliance with [Payment Card Industry Data Security Standard](https://www.pcisecuritystandards.org/standards/pci-dss/) (PCI DSS) is a mandatory requirement. This requirement exists because the financial and reputational cost of a data breach can be devastating. Still, many companies view PCI compliance as a burdensome expense that strains already limited budgets. They believe they must choose between investing in security infrastructure or accepting the risk of non-compliance. The reality, however, is a bit different. For many organizations, managed hosting provides a practical compliance solution that is both affordable and financially sound.

## **The True Cost of Compliance and Risk**

The discussions about PCI compliance often start from the wrong perspective. Companies typically focus on the cost of compliance rather than the consequences of skipping it. This approach creates a misleading perception of cost savings. A single breach can cost an average business [$4.45 million](https://www.ibm.com/reports/data-breach), including legal fees, notification expenses, regulatory fines, and the impact of lost customer trust. From this perspective, investing in compliant infrastructure is not an expense, it is a protection against potentially significant business losses. This changes the focus from “can we afford compliance” to “can we afford not to comply?”

It is crucial to understand the risks before considering potential solutions. Many organizations operate under a misconception that hackers target only large corporations. This belief leaves smaller businesses vulnerable. In [reality](https://www.verizon.com/business/resources/reports/dbir/), hackers often target smaller businesses because they typically have weaker defenses and limited monitoring systems. One particularly dangerous threat is [digital skimming](https://www.humansecurity.com/learn/topics/what-is-digital-skimming/), in which attackers insert malicious code into payment pages to capture credit card information in real time.

Victims do not realize money is being stolen until months later when customers report suspicious charges. By that time, the attacker had already benefited, leaving the business to deal with the consequences. Digital skimming attacks increased significantly in recent years, and e-commerce sites are [frequent targets](https://cianaatech.com/strengthening-ecommerce-security-against-payment-data-theft/). A single undetected incident can lead to expensive notification requirements, card replacement costs, regulatory investigations, and significant harm to the company’s reputation.

Other common vulnerabilities make the problem even worse. [Unpatched systems](https://www.splashtop.com/blog/risks-and-vulnerabilities-of-unpatched-software) remain one of the easiest entry points for attackers. Software vendors release security patches regularly, but many companies delay updates because they fear downtime or compatibility issues. Weak authentication, insufficient encryption, and poor network segmentation create further security gaps. These vulnerabilities often exist not because business owners are careless but because managing security infrastructure requires specialized expertise and constant attention. Resources become strained when internal teams handle security alongside their regular responsibilities.

## **Why Managed Hosting Makes Economic Sense**

This is where managed hosting solutions begin to make economic sense. Rather than building and maintaining your own secure infrastructure, a managed hosting provider handles technical complexity while maintaining responsibility for compliance standards. The provider implements advanced monitoring, threat detection, and security protocols that would be prohibitively expensive for most businesses to establish on their own. Your company gets enterprise-level security without the enterprise-level expense.

The financial calculations become clearer when you break down the actual costs. Building in-house compliance infrastructure requires purchasing secure servers, deploying firewalls and intrusion detection systems, hiring security specialists, and providing 24/7 monitoring. For a mid-sized business, this setup typically costs between $150,000 and $300,000 per year, not including the upfront capital investment. Even a single qualified security specialist can [cost](https://www.salary.com/) $80,000 to $120,000 annually in most markets. Managed hosting solutions typically cost between $500 and $2,000 monthly depending on your specific needs and scale. Over a year, you are looking at $6,000 to $24,000 for comprehensive managed hosting with built-in PCI compliance features. The numbers strongly favor managed solutions for organizations without existing security infrastructure.

The protection is not just limited to vulnerability management. Managed hosting providers implement continuous monitoring and log management, which enables them to detect suspicious activity quickly rather than discovering it months later during a forensic investigation. They also maintain backup systems and disaster recovery protocols to keep your business running even in the event of a security incident. Additionally, they conduct regular vulnerability assessments, maintain audit-ready documentation, and manage compliance requirements as a core function rather than as an afterthought.

## **Operational and Compliance Advantages**

Consider what happens when a breach occurs on self-managed infrastructure. Besides the direct costs, your team must stop normal operations to respond to the incident. Customer service teams handle angry calls and questions. Technical staff work long hours investigating the breach. Management spends time on media communications and regulatory response. All these distractions have a cost, which is reflected in lost productivity and delayed business initiatives. With managed hosting, the provider’s security team handles incident response while your team focuses on recovery. This division of responsibility significantly reduces disruption to your core business.

Another often-overlooked advantage is compliance readiness. Regulatory audits and PCI assessments demand extensive documentation and evidence. Managed hosting providers maintain this documentation as part of their standard operations, ensuring it is always complete and well-organized. When an auditor arrives, the required records are readily available. Your compliance team does not need to scramble to gather evidence from multiple systems and reconstructing historical records. This efficiency saves valuable audit preparation time and keeps resources focused on revenue-generating work.

The risk profile also improves significantly. When you manage your own infrastructure, security effectiveness depends entirely on your team’s expertise and diligence. One mistake, one missed patch, one misconfigured firewall rule creates a vulnerability. With managed hosting, security is built into systems and processes designed by specialists. Multiple layers of protection ensure that one oversight does not compromise the entire infrastructure. This built-in resilience provides peace of mind and strengthens overall business confidence.

## **The Financial and Strategic Case**

Every business has its own risk tolerance and technical capability. Some organizations have the expertise and resources to build in-house security and should do so if they choose. But for the majority of businesses, especially those without dedicated security teams, managed hosting is the more practical and cost-effective choice. It provides professional-level security at a reasonable cost while allowing your team to focus on operations and growth. You get compliance without compromise.

The decision becomes simpler when you [consider](https://www.ibm.com/reports/data-breach) total cost of ownership, including potential breach scenarios. Even a modest breach can cost your business ten times more than a year of managed hosting. The potential risk alone makes the investment worthwhile. When you consider the operational benefits, faster compliance readiness, and reduced distraction from core business, managed hosting becomes a strategic business requirement, well worth the cost.

Providers like [Atlantic.net](https://www.atlantic.net/pci-compliant-hosting/) understand that compliance does not have to be complicated or expensive. They offer managed hosting solutions specifically designed to simplify PCI compliance while maintaining affordability. Their approach combines the right infrastructure, continuous monitoring, and expert support so your business can focus on what it does best. Instead of struggling with compliance details on your own, you gain a partner dedicated to ensuring your security success. This partnership transforms compliance from an internal burden into a shared responsibility managed by experts.

## **Moving Forward**

Achieving affordable PCI compliance requires a clear understanding of your current situation. Evaluate the level of security expertise within your organization and estimate the true cost of building comparable infrastructure on your own. Consider the distraction and opportunity cost of treating security as a secondary function. Evaluate managed hosting options based on your company requirements. The path to affordable, effective PCI compliance often lies not only in doing more yourself, but also in choosing the right providers to handle the technical complexity while you maintain control and confidence in your security posture.

Compliance on a budget does not mean compromising quality. It means finding smarter, more cost-effective ways to get protection you need without unnecessary overhead. Managed hosting provides an efficient path for organizations that recognize where their real expertise and competitive advantage lie. The combination of lower cost, professional expertise, faster compliance, and reduced operational distraction builds a strong case for managed hosting than just a simple price comparison.


---

# Proxmox Virtualization on Bare Metal: Performance, Cost, and Compliance Compared to Public Cloud

> URL: https://www.atlantic.net/dedicated-server-hosting/proxmox-virtualization-on-bare-metal-performance-cost-and-compliance-compared-to-public-cloud/ | Published: 2025-11-03 | Updated: 2026-06-17 | Author: Richard Bailey

The many businesses the public cloud has provided reliability and simplification of IT services. A decade later, some organizations are facing a predicament, a new set of challenges: escalating costs, unpredictable performance, and complex compliance requirements. For some, adapting to an operational expenditure (OpEx) model has sometimes resulted in “bill shock,” driven by data egress fees and metered IOPS.

For some businesses, this problem has prompted a strategic re-evaluation if the costs associated with specific workloads merit cloud infrastructure, or whether there is a better, more cost effective option. IT and FinOps leaders are recognizing that for stable, mission-critical workloads, the public cloud’s multi-tenant model may not be the best fit.

At Atlantic.Net, we are seeing a growing trend of cloud repatriation for specific workloads—or more accurately, a shift to a strategic hybrid model. The primary goal is to regain control over cost and performance, and a key enabler of this is Proxmox [bare metal](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) virtualization.

This article is a guide for decision-makers comparing the Proxmox bare metal model to public cloud platforms across three critical business objectives: Performance, Cost, and Compliance.

## What Is “Proxmox Bare Metal” Virtualization?

Before we compare, let’s establish a clear definition. Unlike public cloud platforms, which are typically massive, multi-tenant SaaS offerings, [Proxmox VE](https://proxmox.com/en/products/proxmox-virtual-environment/get-started) (Virtual Environment) is an open-source virtualization platform.

It is installed directly on dedicated, physical hardware—referred to as “bare metal.”

This creates a private, high-performance IaaS platform. It is a comprehensive virtualization solution integrating several key technologies:

- **KVM (Kernel-based Virtual Machine):** As the foundation, KVM is a Type-1 hypervisor built directly into the Linux kernel. It delivers high-speed, secure, and stable, near-native hardware performance.
- **LXC (Linux Containers):** For workloads where a full VM is unnecessary, Proxmox supports lightweight containers. These are ideal for microservices and applications that can be provisioned in seconds with minimal resource overhead.
- **Central Web-Based Management:** A single web interface allows teams to manage all virtual machines, containers, high-availability clustering, networking, and integrated backups.
- **Flexible Storage:** Proxmox natively supports advanced storage solutions like ZFS (for data integrity and encryption) and Ceph (for building scalable, distributed storage clusters).

Running Proxmox on dedicated servers combines the raw, single-tenant performance of dedicated hardware with the flexibility of a cloud-native virtualization stack. If you are coming from a VMware background, you will appreciate the ease of use of Proxmox and will no doubt pick it up quickly.

## Performance & Control

Performance in the public cloud is a variable, metered resource. Performance on bare metal is a fixed, dedicated asset.

### The Public Cloud: The Challenge of Contention

In a public cloud, your Virtual Machine (VM) runs on a physical server alongside numerous other “tenants.” You typically share the same physical CPU cores, RAM, network uplinks, and storage controllers.
 This has the potential to cause creates three problems:

- **“Noisy Neighbors”:** If another tenant on your shared hardware runs an intensive job, your application’s performance can suffer. This is visible as “CPU Steal Time,” where your VM is ready to execute, but the physical CPU is busy with another tenant’s workload.
- **Throttled I/O:** Storage performance (measured in IOPS) is one of the most common metered and throttled resources. To increase database speed, you must pay to upgrade to a “Provisioned IOPS” tier, even if the underlying hardware is capable of more.
- **Vendor Lock-In:** Public cloud services are often proprietary, creating dependencies that can be difficult to migrate from.

### Proxmox Bare Metal

A Proxmox bare metal server is, by definition, single-tenant. All resources on that machine are dedicated to you.

- **100% Dedicated CPU & RAM:** There are no “noisy neighbors” and no “CPU Steal.” Your mission-critical database or application gets every clock cycle it demands. Performance is not only high, but also predictable.
- **Full Hardware I/O:** You receive the full, unthrottled throughput of the underlying physical storage. With modern NVMe SSDs, this provides a significant performance advantage over general-purpose, throttled cloud storage tiers without incurring per-IOPS fees.
- **Total Network Control:** You control the virtual network stack and can create isolated private VLANs for backend database replication or cluster communication. This traffic is more secure and incurs no cost. In the public cloud, all data transfers, even inter-regional, are subject to egress fees.

Public cloud offers abstracted performance which is great for some less intense workloads, however, Proxmox bare metal offers deterministic performance. For any workload that is latency-sensitive or data-intensive (databases, analytics, real-time applications), bare metal provides a huge advantage.

## Total Cost of Ownership

Cost is a primary driver for organizations exploring alternatives. The Proxmox TCO (Total Cost of Ownership) model is structurally different and more predictable than the public cloud’s metered model.

### The Public Cloud: Pay-As-You-Go Cost Model

Public cloud is cost-effective to start but can become expensive to scale. The “pay-as-you-go” model meters nearly all resources.
 Key drivers of high costs include:

- **Data Egress Fees:** Charges for data transfers (outbound or inter-regional) are a significant and often unpredictable expense. Check your cloud providers egress limits, some offer set allocations of free bandwidth, while others charge for every byte.
- **Metered Performance:** As mentioned, users pay premiums for every IOPS, GB of “premium” storage, “high-CPU” instance, and managed service (e.g., NAT Gateways, Load Balancers).
- **The OpEx Trap:** A 100% OpEx model, while attractive for new ventures, can become an unpredictable and escalating operational cost for established businesses.

### The Proxmox TCO Advantage

The Proxmox bare metal model offers a predictable cost structure, whether hardware is purchased (Capex) or leased (predictable Opex).
 The cost advantages are significant:

- **Zero Software Licensing Fees:** Proxmox VE is open-source, eliminating per-CPU, per-socket, or per-VM licensing fees common to proprietary solutions like VMware.
- **No Data Egress Fees:** Dedicated servers typically include a large bandwidth allowance (e.g., 20TB) on a high-speed (e.g., 1Gbps) port. Data transfer is included, removing the variable egress fee.
- **Inclusive Performance:** All hardware performance (CPU, I/O) is included in the cost. You do not pay extra for faster I/O.
- **Workload Consolidation:** A single, powerful Proxmox server can replace numerous smaller public cloud instances, leading to a significant TCO reduction.

The trade-off is that open-source virtualization requires technical management expertise. This can be addressed via a hybrid approach, partnering with a provider to manage the hardware, network, and Proxmox layer, retaining the TCO benefits.

| **Cost Factor** | **Public Cloud (AWS/Azure/GCP)** | **Proxmox Bare Metal** |
| --- | --- | --- |
| **Software License** | N/A (Built into instance price) | $0 (Open-Source) |
| **Hardware** | Metered by the second/hour | Predictable monthly OpEx (lease) or one-time CapEx (buy) |
| **Performance (IOPS)** | Metered & Throttled (Pay-for-Performance) | Included (Full Hardware Throughput) |
| **Data Egress** | High, metered per-GB fee | $0 (or generous allowance) |
| **Networking** | Metered (NAT Gateway, Load Balancer, etc.) | Included (Full control of host networking) |
| **Cost Predictability** | Low. Highly variable based on usage. | High. Fixed, predictable monthly cost. |

## Compliance & Security

For organizations in healthcare, finance, or AdTech, [compliance is a foundational requirement.](https://www.datacenters.com/news/bare-metal-servers-the-cto-s-secret-asset-for-compliance-heavy-workloads) The Proxmox vs. public cloud models present different approaches to control and auditability.

### The Public Cloud: The “Shared Responsibility” Model

In the public cloud, you operate under a “Shared Responsibility Model.” The provider secures the cloud, but the customer is responsible for security *in* the cloud.
 This can create audit challenges:

- **Lack of Physical Attestation:** Unless you use specialized [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/), it is difficult to prove to an auditor that ePHI data, for example, never co-existed on the same physical hardware as another tenant’s data.
- **Configuration Complexity:** Achieving true network isolation for PII requires complex VPC, security group, and private link configurations, where missteps can lead to exposure.
- **Data Sovereignty:** Data can be replicated by the provider, making it difficult to guarantee data residency requirements (e.g., ensuring EU customer data remains in the EU).

### The Proxmox Bare Metal Advantage

A Proxmox bare metal environment provides a clearer model of responsibility and control.

- **Physical Single-Tenancy:** This is the core compliance control. An organization can state with 100% certainty that the server is dedicated. No other customer’s data has resided on its memory, CPUs, or disks, which simplifies HIPAA or SOC 2 audits.
- **Total Network Isolation:** A truly segmented network can be created. For example, a dedicated VLAN can be provisioned for a database server with no routes to the public internet. This “data enclave” is straightforward to implement and audit.
- **Full Audit Trail:** Root access to the host machine allows for 100% of system, authentication, and firewall logs to be forwarded to a SIEM, rather than being limited by the provider’s logging API.
- **The Business Associate Agreement (BAA):** A compliance-focused provider for Proxmox bare metal can offer a BAA that covers the entire stack: the audited data center, the network, and the physical hardware.

For any organization handling ePHI (HIPAA) or sensitive PII (GDPR, CCPA), this level of provable physical and network control is a significant advantage

## Conclusion: Hybrid Approach

The comparison is not an “either/or” proposition. An effective IT strategy is typically a hybrid one. The public cloud remains an excellent tool for ephemeral workloads, serverless functions, and elastic applications.

However, for core, mission-critical applications—such as databases, ERPs, and high-throughput analytics platforms—the case for bare metal is compelling.
 The Proxmox TCO is typically lower overall, the performance is guaranteed, and the compliance posture is stronger. The shift to open-source virtualization on bare metal is a strategic move to regain control over performance, cost, and data.

This transition may seem daunting, but you don’t have to make it alone. For 30 years, Atlantic.Net has specialized in providing the secure, high-performance, and compliant infrastructure that enables businesses to build their own clouds.

We provide the BAA-backed, audited data center environment, the high-performance dedicated servers, and 24×7 expert support. And with our managed services, we can even handle the Proxmox layer for you, giving you all the benefits of a private cloud without the day-to-day management overhead.

Would you like to explore how a Proxmox bare metal solution could reduce your cloud spend and improve performance? [Get in touch today](https://www.atlantic.net/about-us/corporate-contact/).

**Related Guides:**

- [HIPAA Compliant Hosting Solutions](https://www.atlantic.net/hipaa-compliant-hosting/)
- [PCI-Compliant Hosting Solutions](https://www.atlantic.net/pci-compliant-hosting/)
- [What Are Managed Services?](https://www.atlantic.net/managed-services/what-are-managed-services/)

**Related Products:**

- [Atlantic.Net Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/)
- [Atlantic.Net HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)
- [Atlantic.Net GPU Hosting](https://www.atlantic.net/gpu-server-hosting/)


---

# Choosing the Right Hardware for Proxmox: Cost Breakdown for AdTech and Healthcare Hosting

> URL: https://www.atlantic.net/dedicated-server-hosting/proxmox-hardware-guide-costs-for-adtech-healthcare-hosting/ | Published: 2025-11-05 | Updated: 2026-05-30 | Author: Richard Bailey

For IT professionals in regulated industries, the move to a Proxmox Virtualized Environment (VE) on bare metal is a strategic choice that can come with numerous advantages for businesses with specific requirements. [Going bare metal is an important decision](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers); you trade in the potential of hidden and unpredictable costs of the public cloud for the power, control, and total cost of ownership of a private Infrastructure as a Service (IaaS).

Once you have made the decision to go with Proxmox on bare metal, the next most important factor to understand is the hardware requirements. This decision is important because it’s the hardware that will help determine your success, performance, and long-term cost savings going forward.

In the public cloud, hardware is an abstraction layer. You choose from a menu of hosting plans often with little knowledge of the underlying physical components. When you build on bare metal, *you* are in control. This is a massive advantage, but it also means the choices you make upfront will have long-term consequences.

This is especially true for healthcare and AdTech. These are not general-purpose workloads. Healthcare applications must protect electronic Protected Health Information (ePHI) with zero tolerance for data corruption or breaches. AdTech platforms require microsecond latency, where a slow database read can mean lost revenue.

This guide serves as a blueprint for infrastructure planners and procurement specialists, outlining the critical Proxmox hardware components and analyzing their cost-to-value ratio for secure, high-performance, and compliance-driven hosting environments.

## Prioritize Resilience and Integrity

For healthcare and AdTech, your hardware-buying philosophy must be “Resilience and Integrity First.” A consumer-grade component that fails or causes “silent” data corruption is not just an inconvenience; it’s a data breach, a HIPAA violation, or a catastrophic loss of revenue.

Every component you select must be enterprise-grade. This means features like Error-Correcting Code (ECC) memory and power-loss protection (PLP) on SSDs are non-negotiable.

Let’s break down the stack, component by component, and analyze the right choice for your sensitive workloads.

## The CPU: Your Virtualization Engine

The CPU is the heart of your Proxmox host. All your virtual machines and containers share their cores, so it’s important to choose a processor that can handle the number of virtual machines you will host.

- **What Matters:** Core count, not just clock speed. Virtualization is a massively parallel task. A server with 32 slower cores will almost always outperform a server with 8 faster cores for a Proxmox workload. Look for a CPU with multiple cores and threads. AMD EPYC CPUs are particularly good when considering cost vs. performance.
- **The Right Choice:** Modern server-grade CPUs like Intel Xeon (Scalable series) or AMD EPYC. These processors are designed for 24/7/365 operation and, most importantly, have the hardware virtualization extensions (Intel VT-x, AMD-V) that Proxmox’s KVM hypervisor relies on for near-native performance.
- **Compliance & Security:** Modern EPYC and Xeon CPUs also include advanced security features like AMD-SEV or Intel-TDX, which enable full memory encryption for virtual machines. This is a powerful technical safeguard for protecting ePHI and PII, as it can prevent data from being snooped even at the hypervisor level.
- **Cost vs. Value:** Don’t be tempted by high-clock-speed “gaming” CPUs. Invest in a server-grade CPU. While a 32-core AMD EPYC processor has a higher initial cost than a 16-core desktop chip, it can comfortably run 2-3 times as many VMs, delivering a far lower cost-per-VM.

### CPU Example

| **Goal** | **Description** |
| --- | --- |
| System Objective | Deploy a reliable and high-performance Proxmox host to support core business infrastructure and virtualized services. |

### Planned Virtual Machines / Containers

| **VM / Container** | **Business Function** | **vCPU Allocation** |
| --- | --- | --- |
| TrueNAS Scale (VM) | Centralized storage and data management platform (ZFS, backup, and application hosting) | 8 vCPU |
| Plex Media Server (LXC) | Internal media distribution and training content streaming | 6 vCPU |
| Windows 11 Pro (VM) | Remote desktop and productivity environment for administrative access | 4 vCPU |
| pfSense Router (VM) | Virtualized network gateway providing routing, VPN, and firewall services | 2 vCPU |
| Web Application Servers (3× LXC) | Hosting line-of-business applications and internal web services | 6 vCPU total |
| Unifi Network Controller (LXC) | Centralized management of corporate network infrastructure | 2 vCPU |

## System Memory

RAM is the “workspace” for your host and all your guests. It’s also the easiest place to create a performance bottleneck. Typically virtualization hypervisors require a significant amount of RAM. It will eventually be allocated in chunks to each of your virtual machines, so there has to be enough to go around.

- **What Matters**: ECC (Error-Correcting Code) Memory. This is the most*important* distinction for a compliant server. Standard RAM can and does experience single-bit errors. In a regular desktop, this might cause a rare application crash. On a server hosting a patient database, this could cause silent data corruption, writing incorrect data to your storage. ECC RAM detects and corrects these errors in real-time. [For HIPAA or PII workloads](https://www.atlantic.net/hipaa-compliant-hosting/), ECC RAM is not optional.
- **How Much?** The rule of thumb is simple: [RAM for Proxmox Host OS (4-8 GB)] + [RAM for ZFS (1 GB per 1 TB of storage)] + [Total RAM you plan to assign to all your VMs].
- **Example:** A host with 24 TB of ZFS storage (24 GB) running 10 VMs that each need 8 GB of RAM (80 GB) should have a *minimum* of 128 GB of physical RAM to be safe.
- **Cost vs. Value:** RAM is one of the least expensive server components per-gigabyte. Skimping here is the definition of “penny wise and pound foolish.” A server with 128 GB of ECC RAM that costs $300 more than a 64 GB non-ECC configuration is an incredible value, preventing both crippling performance issues and catastrophic data integrity violations.

### RAM Example

| **Goal** | **Description** |
| --- | --- |
| **System Objective** | Ensure adequate memory resources to support a stable and high-performance Proxmox host for business-critical virtualized workloads. |

### System and Workload Allocation

| **Component** | **Business Function** | **RAM Allocation** |
| --- | --- | --- |
| **Host Operating System (Proxmox)** | Core hypervisor environment managing virtualization and system processes | 6 GB |
| **ZFS Storage Pool** | 12 TB usable capacity; ~1 GB RAM per TB recommended for ARC caching and metadata | 12 GB |
| **Windows 11 Pro (VM)** | Administrative workstation or remote access environment | 8 GB |
| **Plex Media Server (LXC)** | Internal multimedia and training content distribution | 4 GB |
| **Home Assistant (VM)** | Facility automation and IoT integration platform | 2 GB |
| **Unifi Network Controller (LXC)** | Centralized management of switches, access points, and gateways | 2 GB |
| **Ubuntu Server (Dev)** | Application development and testing environment | 4 GB |

### Memory Summary

| **Category** | **RAM Requirement** |
| --- | --- |
| Proxmox Host OS | 6 GB |
| ZFS ARC Cache | 12 GB |
| Virtual Machines & Containers | 20 GB |
| **Total Estimated Requirement** | **38 GB** |
| **Recommended Installation** | **64 GB (for operational headroom and caching efficiency)** |

## Storage

Storage is the most critical and complex hardware decision in any virtualization deployment. Your configuration directly determines system performance, data resilience, and integrity.

For Proxmox, the recommended best practice is to use the ZFS (Zettabyte File System) as the storage backend. Unlike traditional hardware RAID cards, ZFS is software-defined and purpose-built for data integrity, flexibility, and high performance — making it ideal for virtualized and compliance-driven environments.

### ZFS Benefits for Enterprise Compliance

| **Feature** | **Description** | **Compliance Value** |
| --- | --- | --- |
| **Bit-Rot Protection** | ZFS performs end-to-end checksums on every data block. If corruption is detected, it automatically repairs the data from redundancy. | Meets HIPAA and SOC 2 integrity requirements by ensuring long-term data reliability. |
| **Native Encryption** | ZFS supports on-disk encryption with minimal performance impact. | Protects ePHI/PII at rest, fulfilling technical safeguard obligations under HIPAA and GDPR. |
| **Snapshots & Replication** | Instant, block-level snapshots enable point-in-time recovery and remote replication to secondary systems. | Forms the backbone of a disaster recovery and business continuity strategy. |

### Recommended Hardware Configuration

| **Purpose** | **Hardware Choice** | **Configuration** | **Rationale** |
| --- | --- | --- | --- |
| **Boot Drives (Proxmox OS)** | 2× 500 GB (or larger) enterprise-grade SSDs | ZFS RAID 1 (mirror) | Fast and redundant hypervisor boot pool. Enterprise SSDs include power-loss protection (PLP) to prevent OS corruption during outages. |
| **VM / Container Storage (Primary Pool)** | 4–8 × NVMe SSDs (U.2 or M.2) | ZFS RAID 10 (mirror-stripe) | Delivers the high IOPS and low latency required for demanding workloads. Ideal for performance-sensitive environments. |
| **Storage Controller** | Host Bus Adapter (HBA) | Direct disk passthrough to OS | ZFS requires full visibility of individual drives. Use an HBA instead of a RAID card for simplicity, reliability, and cost savings. |

## Networking

Networking in a compliant environment is not just about speed; it’s about segmentation. This is a core HIPAA technical safeguard.

- **What Matters:** Redundancy and Speed. A single 1Gbps port is a bottleneck and a single point of failure.
- **The Right Choice:** A minimum of 2x 10Gbps SFP+ ports.
- **Why This Is Critical for Compliance:** This setup allows you to create a secure, segmented network:

| **VLAN ID** | **Segment** | **Purpose** | **Security Policy** |
| --- | --- | --- | --- |
| **VLAN 10** | Public Network | Internet-facing VMs and web servers | Ingress filtered; limited outbound access |
| **VLAN 20** | Application Network | Internal application communication | Access controlled to specific ports/services |
| **VLAN 30** | Database Network | Encrypted storage of ePHI/PII | Strictly firewalled; accessible only from VLAN 20 |
| **Mgmt VLAN** | Management Network | Proxmox host, SSH, and Web UI | Accessible only through VPN or jump host |

- **Management:** You can (and should) create a separate physical port or VLAN *just* for Proxmox host management (SSH, Web UI) that is only accessible via a secure VPN or jump box.
- **Cost vs. Value:** A dual 10Gbps network card is a small incremental cost but provides a 10x speed increase over 1Gbps and, more importantly, the port redundancy and segmentation capabilities required to build a zero-trust network model for your sensitive data.

## Proxmox Cost Breakdown: TCO Examples for Buyers

When evaluating the economics of virtualization, theoretical cloud pricing models often obscure the true cost of ownership.

A more transparent approach is to analyze real-world bare-metal deployments — where costs are fixed, predictable, and directly aligned with resource utilization.
 The following models are based on Atlantic.Net’s HIPAA-compliant bare-metal hosting platform, which provides dedicated servers with flat monthly Opex and no metered IOPS or unpredictable data egress fees.

This structure eliminates the “usage-based volatility” of traditional cloud billing, offering consistent performance and financial clarity

### Example 1: Start-Up

**Target Use Case:** ****Small to mid-sized organizations such as clinics, SaaS startups, or AdTech firms that require a reliable, compliant, and cost-effective infrastructure to replace multiple public cloud instances.

| **Component** | **Specification** |
| --- | --- |
| **CPU** | 36-core / 72-thread Intel Xeon Gold 6140 |
| **Memory (RAM)** | 128 GB ECC |
| **Boot Storage** | 2 × 480 GB Enterprise SSD (RAID 1 Mirror) |
| **VM / Container Storage** | 4 × 1.92 TB SSD (ZFS RAID 10 — ≈ 3.8 TB usable) |
| **Network** | Dual 10 Gbps SFP+ connections |
| **Estimated Monthly Lease** | ~ US $299 per month (Atlantic.Net, November 2025) |

#### TCO Analysis

| **Factor** | **Proxmox Bare Metal (Atlantic.Net)** | **Public Cloud Equivalent** |
| --- | --- | --- |
| **Billing Model** | Fixed, predictable monthly Opex | Variable metered usage (compute, IOPS, egress) |
| **Scalability** | Supports 20–40 VMs or LXCs concurrently | Each instance billed individually |
| **Performance** | Dedicated compute / storage with no throttling | Shared resources / variable IOPS |
| **Compliance** | HIPAA-ready environment with enterprise SSDs | Compliance add-ons billed separately |
| **ROI** | Typically < 6 months based on cloud comparisons | Ongoing recurring spend |

**Summary:** ****This configuration provides the reliability and performance of enterprise hardware with a fraction of public-cloud costs. By consolidating multiple instances onto one dedicated host, organizations often realize 3×–5× monthly savings while maintaining full compliance control and predictable Opex.

### Example 2: Performance Cluster

**Target Use Case:**
 Hospitals, research institutions, and AdTech platforms require high-density compute and low-latency storage for mission-critical workloads.

| **Component** | **Specification** |
| --- | --- |
| **CPU** | 64-core / 128-thread AMD EPYC 7702P |
| **Memory (RAM)** | 512 GB ECC |
| **Boot Storage** | 2 × 960 GB NVMe SSD (RAID 1 Mirror) |
| **VM / Container Storage** | 8 × 4 TB NVMe SSD (ZFS RAID 10 — ≈ 16 TB usable) |
| **Network** | Dual 25 Gbps SFP28 Connections (Custom Option) |
| **Estimated Monthly Lease** | From ~ US $434 per month (standard) to custom pricing for NVMe / 25 Gbps builds |

#### TCO Analysis

| **Factor** | **Proxmox Bare Metal (Atlantic.Net)** | **Public Cloud Equivalent** |
| --- | --- | --- |
| **Billing Model** | Fixed monthly lease, no usage-based variability | Tens of thousands per month (HPC or Storage-Optimized tiers) |
| **Performance** | Dedicated 96+ cores and unthrottled NVMe I/O | Shared cores / capped performance |
| **Capacity** | Consolidates hundreds of VMs and databases | Linear cost increase per instance |
| **Scalability** | Expand via additional nodes or ZFS replication | Pay-as-you-scale model with premium fees |
| **TCO Impact** | Immediate, sustained savings | High and unpredictable operational expense |

**Summary:** ****This high-density configuration effectively functions as a self-contained private cloud, capable of hosting large virtual estates or data-intensive workloads with consistent, deterministic performance. Even at higher monthly lease costs, the TCO savings compared with cloud HPC or storage-optimized tiers remain significant and immediate.

## Your Partner for Compliant Hardware & Hosting

Choosing the right Proxmox VE hardware is the first step. The second is choosing the right *partner*.

For healthcare and AdTech, your infrastructure must live in a secure, audited facility, and you must have a Business Associate Agreement (BAA) in place. This is a non-negotiable part of your compliance.

For 30 years, Atlantic.Net has been a compliant hosting leader. Our 8 global data centers are SSAE 18 SOC 2/3 and HIPAA audited. We provide the enterprise-grade bare metal servers, the BAA, and the 24×7 expert support you need.

Better yet, you don’t have to manage it all alone. With our managed services, we can handle the secure network, the hardware, and the Proxmox platform itself, patching and securing the host so your team can focus on what they do best: managing your applications.

Ready to build a Proxmox solution that delivers on performance, compliance, and cost? [Contact our solutions team today.](https://www.atlantic.net/about-us/corporate-contact/)

**Related Guides:**

- [HIPAA Compliant Hosting Solutions](https://www.atlantic.net/hipaa-compliant-hosting/)
- [PCI-Compliant Hosting Solutions](https://www.atlantic.net/pci-compliant-hosting/)
- [What Are Managed Services?](https://www.atlantic.net/managed-services/what-are-managed-services/)

**Related Products:**

- [Atlantic.Net Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/)
- [Atlantic.Net HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)
- [Atlantic.Net GPU Hosting](https://www.atlantic.net/gpu-server-hosting/)


---

# Optimizing Proxmox for Real-Time Workloads: RTB Performance, Storage, and Infrastructure Tips

> URL: https://www.atlantic.net/dedicated-server-hosting/proxmox-rtb-tuning-guide/ | Published: 2025-11-05 | Updated: 2026-05-30 | Author: Richard Bailey

In many industries, “real-time” is a flexible goal; however, in digital advertising, it’s an absolute law, driven by a process called Real-Time Bidding (RTB). RTB is a high-speed, programmatic auction that decides which ad to show a user in the time it takes a webpage to load. This entire transaction—receiving the request, analyzing user data, running the auction, and returning the winning ad—must be completed in 100 to 150 milliseconds. That isn’t an average; it’s the hard cutoff. A single millisecond late means the auction is lost and the transaction fails.

In this environment, “fast” isn’t good enough. You need guaranteed performance, which is precisely why public cloud platforms are typically not recommended. The potential “noisy neighbor” problem, variable network jitter, and—most critically—throttled storage I/O can introduce too much latency. You can’t win an auction where every microsecond counts when you’re paying for “Provisioned IOPS” and sharing a storage controller with a thousand other tenants.

However, there is a solution to this problem. [Proxmox VE on bare metal.](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) It provides the flexibility of a cloud-native environment, but with the raw, uncontended, single-tenant hardware you need to ensure optimal performance. But just installing Proxmox isn’t enough. You must eliminate every source of latency, and this guide offers some key infrastructure tips to tune your Proxmox environment so it can meet the demands.

## Why Bare Metal Servers?

Your RTB platform *must run* on dedicated bare metal. There is no other option for a high-performance, high-frequency bidding application with near-zero latency.

**CPU:** Public cloud VMs are subject to CPU steal time, where the hypervisor preempts the vCPU for other tenants. Bare metal guarantees 0% steal time, providing 100% of CPU cycles for deterministic p99 latency.

**I/O:** Cloud storage (e.g., EBS) is throttled, metered, and subject to “noisy neighbor” contention. This creates an unpredictable bottleneck for high-throughput databases (Aerospike, ScyllaDB). Bare metal provides direct, uncontended access to local physical NVMe, delivering maximum predictable IOPS.
 Network: Public cloud networking abstracts control and imposes per-GB egress fees and per-hour charges for virtual appliances (e.g., ELBs, NAT Gateways). Bare metal provides full, line-rate throughput (10/25Gbps+) and direct control over the physical NIC, Linux bridge, and kernel networking stack, enabling dedicated VLANs for backend traffic.

## NVMe Storage Recommended

For the responsiveness needed by an RTB application, there is only one type of storage you should consider, and that is NVMe solid-state storage. This does add additional cost to your bare metal options, but it’s essential to get the minimum latency needed.
 ****

**SATA SSDs:** Unacceptable for an RTB workload. The bottleneck is the 6Gbps SATA protocol, a high-latency, single-queue (NCQ depth 32) interface designed for spinning media. It cannot service the concurrent I/O required by a bidding database.
 ****

**SAS SSDs:** A marginal improvement, but still adds latency by routing I/O through a storage controller (HBA) and its associated protocol overhead.
 ****

**NVMe SSDs:** The required standard. NVMe bypasses the legacy storage stack entirely, interfacing directly with the CPU over the PCIe bus. This provides a massively parallel, low-latency path (up to 65,536 I/O queues) essential for the thousands of concurrent database reads/writes characteristic of an RTB auction.
 For an RTB database that is handling thousands of parallel read/write requests per second, the massive parallelism and low latency of NVMe are essential.

## Proxmox Storage Configuration for RTB

Your goal is maximum I/O performance and low-latency writes, therefore its essential to configure your storage layer correctly. This is how we recommend you set up the storage for RTB:

**File System:** Use ZFS for its [copy-on-write](https://www.lenovo.com/gb/en/glossary/what-is-cow/?srsltid=AfmBOoqsbnKd26eN3IQQuCKQFCDcovFmQIgu_QOqrKcexxpflNgjFx4D) (CoW) integrity and ARC (Adaptive Replacement Cache).

**VM Pool Layout:** Create a RAID 10 equivalent, a stripe of mirror vdevs using 6-8 enterprise NVMe drives. This layout provides the highest write IOPS (no parity/[RMW penalty](https://en.wikipedia.org/wiki/Read%E2%80%93modify%E2%80%93write)) and low latency, which is essential for database workloads.

**ZIL/SLOG Tuning:** Do not use a separate SLOG device (Separate Log). With an all-NVMe pool, the main pool’s vdevs are already fast enough to service ZIL (ZFS Intent Log) sync writes with low latency. A dedicated SLOG adds unnecessary complexity and cost.

**Host Boot Pool:** Use 2x SATA SSDs in a ZFS mirror vdev. This provides redundancy for the Proxmox host OS and segregates host I/O, dedicating 100% of the NVMe pool’s IOPS to guest VMs.

## CPU, Memory, and Infrastructure Tuning

The entire bare metal platform needs to be tuned for RTB workloads. Here are our recommendations and best practices to get your server working at its full capability.

### CPU Configuration

- **Hardware:** You need a balance of high core count and high clock speed. An AMD EPYC or Intel Xeon Scalable processor is the standard.
- **Host CPU Governor:** The default Linux CPU governor (ondemand or schedutil) tries to save power by scaling down CPU frequency. Set the governor to performance. This forces all CPU cores to run at their maximum frequency, all the time.
- **CPU Pinning (Affinity):** This is an advanced KVM trick. Assign your database VM a set number of vCPUs (e.g., 16) and then **pin them** to a specific range of physical CPU cores (e.g., cores 16-31). This ensures that VM has exclusive, dedicated access to those cores, eliminating scheduler latency.

### Memory Tuning

- **Hardware:** Use the fastest ECC DDR5 (or DDR4) RAM your server supports.
- **Guest Tuning:** Your RTB database (Aerospike, Redis, etc.) likely uses a massive amount of RAM for its in-memory index. By default, the OS uses 4KB memory pages. Configure your database VM to use Huge Pages (e.g., 2MB or 1GB). This reduces the number of memory addresses the CPU has to manage, which in turn reduces TLB (Translation Lookaside Buffer) misses. This is a well-known trick that shaves microseconds off every single database lookup.

### Network Infrastructure

- **Hardware:** 10Gbps SFP+ is your absolute minimum. For a high-throughput platform, 25Gbps SFP28 is the modern standard.
- **Network Segmentation:** Use VLANs to isolate traffic. This isn’t just for security; it’s for performance.
- **Jumbo Frames (MTU 9000):** On a private backend VLAN, enable Jumbo Frames. This increases the packet size from 1500 bytes to 9000 bytes, reducing the number of packets your server has to process for large user-profile data transfers, lowering CPU overhead, and improving throughput.

## LXC Containers + KVM

Proxmox gives you the unique ability to run both lightweight containers (LXC) and full VMs (KVM) on the same host. This is the ideal and preferred architecture for an RTB platform.

- **Use LXC Containers for Your Bidders:** Your bidding application is likely a small, stateless microservice. Running it in an LXC container is far more efficient than a full VM. It shares the host kernel, has near-zero overhead, and can be spun up or down in seconds. You can run dozens of bidders on a single host.
- **Use a KVM Virtual Machine for Your Database:** Your database (Aerospike, ScyllaDB, etc.) is the heart of your platform. It needs strong resource isolation. By placing it in a KVM virtual machine, you can dedicate and pin its CPU cores, allocate it a block of RAM (with Huge Pages), and give it dedicated access to the NVMe storage pool.

This hybrid model gives you the density and speed of containers for your app tier and the isolated, guaranteed performance of a VM for your data tier.

## Proxmox: Build for Purpose

The public cloud introduces non-deterministic latency through CPU steal, I/O throttling, and network abstraction, making it unsuitable for an RTB workload. An RTB platform demands a purpose-built, low-latency stack. This stack must be founded on bare metal to guarantee 0% CPU steal and uncontended, line-rate network I/O.
 Storage requires a local all-NVMe ZFS pool, configured as a RAID 10 (striped mirrors), to ensure maximum IOPS and bypass storage bottlenecks. This hardware is best managed by a tuned Proxmox environment, which can utilize both lightweight LXC containers and KVMs to minimize virtualization overhead.

Atlantic.Net provides the high-performance bare metal, global data center footprint, and 24/7 technical support required for these high-frequency workloads.

Would you like to discuss specific bare metal configurations for your RTB platform? [Reach out to the team now.](https://www.atlantic.net/about-us/corporate-contact/)

**Related Guides:**

- [HIPAA Compliant Hosting Solutions](https://www.atlantic.net/hipaa-compliant-hosting/)
- [PCI-Compliant Hosting Solutions](https://www.atlantic.net/pci-compliant-hosting/)
- [What Are Managed Services?](https://www.atlantic.net/managed-services/what-are-managed-services/)

**Related Products:**

- [Atlantic.Net Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/)
- [Atlantic.Net HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)
- [Atlantic.Net GPU Hosting](https://www.atlantic.net/gpu-server-hosting/)


---

# How to Choose the Top HIPAA-Compliant Hosting Services for Secure and Compliant Data Management

> URL: https://www.atlantic.net/hipaa-compliant-hosting/how-to-choose-the-top-hipaa-compliant-hosting-services-for-secure-and-compliant-data-management/ | Published: 2025-11-06 | Updated: 2026-05-05 | Author: Richard Bailey

Healthcare organizations face new challenges in managing sensitive healthcare data while maintaining regulatory compliance. The Health Insurance Portability and Accountability Act (HIPAA) of 1996 established a set of standards requiring specialized HIPAA-compliant hosting for the healthcare industry . Its goal was to protect the integrity of electronic protected health information from unauthorized access.

Selecting an appropriate HIPAA-compliant hosting service is one of the most critical infrastructure decisions healthcare executives have to make. With [average healthcare data breaches costing over $10 million](https://www.ibm.com/think/x-force/healthcare-data-breaches-costliest) and HIPAA-compliance violations resulting in substantial fines, choosing the right hosting solution is necessary for protecting sensitive data such as patient information and ensuring regulatory adherence.

This guide examines top [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) options, essential features healthcare organizations should prioritize, and best practices for selecting hosting providers that deliver true HIPAA-compliance while supporting healthcare industry innovation.

## Understanding HIPAA Hosting Services Requirements

Unlike standard hosting solutions, HIPAA-compliant hosting requires specific security frameworks that address the technical, physical, and administrative safeguards of the [HIPAA security rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/).

### Core HIPAA Compliance Requirements

The foundation of HIPAA hosting solutions rests on understanding fundamental HIPAA requirements established by federal [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) regulations. These requirements extend beyond basic security to encompass comprehensive data protection, ensuring healthcare organizations ensure HIPAA compliance across all technology infrastructure.

HIPAA-compliance mandates that hosting providers apply strong security controls protecting protected health information throughout its lifecycle. Healthcare organizations must partner with hosting providers willing to sign a detailed business associate agreement (BAA) establishing legal accountability.

### Safeguard Categories (HIPAA Security Rule)

#### Technical Safeguards

- Full encryption protecting data at rest and in transit
- Access controls limiting exposure to protected health information based on role-based permissions
- Audit logging tracking all system activities
- Automatic authentication mechanisms including session management
- Transport Layer Security (TLS) usage, often implemented via SSL certificates, ensuring encrypted communications

#### Physical Safeguards

- [Secure data centers](https://www.atlantic.net/hipaa-data-centers/) with enterprise-grade security controls and biometric access
- Data centers featuring environmental controls through redundant power and cooling
- Data centers applying secure equipment disposal
- Data centers maintaining visitor management with detailed logs
- Data centers providing geographic distribution for redundancy

#### Administrative Safeguards

- [Business associate agreement](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) frameworks defining legal responsibilities
- Workforce training ensuring personnel understand HIPAA regulations
- Incident response protocols enabling rapid breach detection
- Regular HIPAA-compliance audits identifying vulnerabilities
- HIPAA-compliance monitoring systems tracking adherence

### Shared Responsibility Model

HIPAA-compliant hosting solutions operate under shared responsibility where healthcare organizations and hosting providers share accountability for maintaining HIPAA-compliance. Organizations handle [application security](https://www.atlantic.net/hipaa-compliant-hosting/application-security-requirements-in-the-hipaa-framework/), patient data management, and workforce [training on HIPAA](https://www.atlantictraining.com/catalog/hipaa-compliance-training) guidelines. Providers manage infrastructure security, data centers protection, and platform HIPAA-compliance operations.

## Key Features of HIPAA Compliant Hosting Solutions

Selecting suitable HIPAA compliant solutions requires evaluating key features distinguishing legitimate HIPAA hosting services from standard hosting solutions lacking compliance capabilities.

### Infrastructure and Platform Requirements

HIPAA-compliant hosting infrastructure must provide strong foundations supporting secure healthcare application deployment. Dedicated servers offer maximum isolation, eliminating multi-tenant security risks while providing complete administrative control. Cloud server platforms provide scalability while maintaining appropriate security controls.

HIPAA-compliant cloud hosting solutions combine cloud computing benefits with thorough security controls. HIPAA-compliant cloud platforms and HIPAA cloud environments enable resource scaling supporting organizational growth while maintaining isolation. Cloud hosting architectures must apply network segmentation, encryption, full monitoring, and access controls, ensuring HIPAA-compliant environments for services like HIPAA compliant web hosting.

HIPAA-compliant server configurations require specialized hardening including operating system updates, application patches, firewall configuration, and complete logging. Multiple servers may be deployed across geographically distributed facilities providing redundancy, disaster recovery capabilities, and business continuity for enterprise customers managing critical applications.

### Security and Compliance Features

Comprehensive security features form the cornerstone of HIPAA-compliant hosting solutions:

#### Encryption and Data Protection

- Industry-standard encryption algorithms protecting data at rest
- Transport layer [encryption](https://www.atlantic.net/hipaa-compliant-hosting/encryption-for-hipaa-compliance/) providing secure data transmission
- End-to-end encryption for patient data transmissions
- Encrypted offsite backups stored in geographically distributed facilities
- Hardware security modules providing secure key management

#### Access Management

- [Multi-factor authentication](https://www.atlantic.net/managed-services/multi-factor-authentication/) mandatory for administrative access
- Role-based controls limiting information exposure based on minimum necessary principles
- Centralized identity management that powers healthcare technology systems
- Privileged access management with session recording
- Comprehensive audit trails documenting all access attempts

#### Network Security

- Web application firewall protection filtering malicious traffic for a HIPAA compliant website
- Network segmentation isolating systems from other applications
- Intrusion detection systems monitoring traffic
- DDoS protection ensuring application availability
- VPN connectivity providing secure remote access

## Legal and Regulatory Compliance

HIPAA-compliant hosting requires comprehensive legal frameworks:

### Business Associate Agreements

- The business associate agreement represents the foundational legal document establishing HIPAA-compliance relationships.
- A detailed BAA must include specifications for handling protected health information, security requirements meeting HIPAA requirements, breach notification procedures complying with HIPAA guidelines, and incident response protocols.
- Business associate agreement provisions should address subcontractor management, data retention policies, audit rights, and termination clauses.
- Healthcare organizations should disqualify any hipaa compliant hosting partner unwilling to sign detailed BAA documentation.

### Compliance Certifications

- Legitimate HIPAA-compliant hosting providers undergo rigorous third-party audits.
- Key certifications include SOC 2 Type II audits, HITRUST certification (designed for healthcare), FISMA compliance, and ISO 27001 standards that validate HIPAA-compliant environments meet regulatory expectations.
- Ongoing HIPAA-compliance monitoring programs ensure providers maintain security standards through regular assessments, vulnerability scanning, and staff training.
- HIPAA-compliance services should include audit support and regulatory documentation management.

## Technical Safeguards and Security Controls

Technical safeguards are important components of HIPAA-compliant hosting, protecting information through thorough security controls.

### Data Encryption and Protection

Encryption forms the foundation of HIPAA-compliant hosting solutions, requiring application at multiple layers. Data encryption must use AES-256 for data at rest and TLS 1.3 for data in transit, ensuring sensitive patient data remains protected.

Platforms must apply database-level encryption enabling granular controls, encrypted backup systems with geographically distributed offsite backups, and hardware security modules providing secure key management. HIPAA cloud infrastructures and advanced protection includes data loss prevention systems monitoring movement, tokenization capabilities, and secure deletion procedures.

### Monitoring and Audit Capabilities

Full monitoring enables healthcare organizations and healthcare providers who require HIPAA compliance to track system activities, detect security incidents, and maintain detailed compliance documentation required by regulations. HIPAA-compliance monitoring systems must provide real-time visibility into user access attempts, data modifications, and configuration changes.

Audit logging should track all interactions including access attempts, successful authentications, and data modifications. Log retention must meet requirements with secure, tamper-proof storage.

### Network Architecture

HIPAA-compliant network architectures must apply complete segmentation, isolating systems from other applications. Network segmentation through virtual LANs and software-defined networking limits potential breach impact.

Cloud environment architectures require additional security controls including virtual private cloud setup and dedicated network connections. Zero-trust network models eliminate implicit trust relationships, applying continuous verification.

## Selecting HIPAA Compliant Hosting Providers

Selecting appropriate HIPAA-compliant hosting providers requires systematic evaluation balancing technical capabilities, compliance services, cost considerations, and long-term partnership potential.

### Evaluation Criteria

#### Technical Capabilities

- Infrastructure options, including [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/), cloud server platforms, and hybrid hosting solutions
- Security setups meeting all requirements and supporting technical safeguards
- Facilities locations, certifications, and operational procedures
- Disaster recovery capabilities including backup systems
- Performance characteristics supporting application requirements
- Scalability supporting organizational growth

#### Compliance Framework

- Willingness to sign detailed agreements
- Current certifications including SOC 2 Type II and HITRUST
- Monitoring programs and ongoing assessments
- Compliance services availability including audit support
- Experience serving organizations with a demonstrated understanding
- References from current healthcare clients

#### Service and Support

- [Managed services](https://www.atlantic.net/managed-services/) availability including system administration
- Technical support responsiveness and availability
- HIPAA-compliance support services assisting with regulatory adherence
- Migration assistance for a secure transition
- Training programs educating staff on platform usage
- Account management providing strategic guidance

### Common Pitfalls

Healthcare organizations frequently encounter challenges when selecting providers:

#### Warning Signs

- Many providers make misleading claims about capabilities without providing legitimate frameworks or demonstrating actual skill.
- Generic security features marketed as HIPAA-compliant services without healthcare-specific setup represent major red flags.
- Insufficient experience addressing clinical workflow requirements, inadequate incident response procedures, and missing support capabilities indicate that providers lack the necessary skills.

#### Due Diligence

- Verify status through independent audit documentation
- Review terms carefully with legal counsel
- Confirm facilities meet physical security requirements
- Validate staff training and knowledge
- Test support responsiveness through pilot projects
- Assess long-term viability evaluating financial stability

## Atlantic.Net: Premier HIPAA Hosting Services

Our HIPAA-compliant hosting services provide complete hosting solutions with certified secure facilities strategically located throughout the United States. These facilities maintain the highest physical security levels and undergo regular audits including SOC 2 Type II and HITRUST certification.

### Core Platform Features

- Certified facilities with SOC 2 Type II compliance
- HITRUST certification demonstrating security knowledge
- A detailed business associate agreement included with all hosting services
- 100% uptime SLA ensuring continuous operations
- 24/7 technical support from trained engineers

### Infrastructure Options

- Dedicated servers providing complete isolation and configuration
- HIPAA-compliant cloud environments supporting scalable growth
- Hybrid solutions integrating on-premises with cloud hosting resources
- HIPAA-compliant cloud hosting platforms featuring full security
- Cloud server capabilities supporting analytics and research

### Managed Services and Support

Atlantic.Net’s managed services approach recognizes organizations need reliable technology partners enabling focus on patient care while maintaining operations.

#### Management Services

- Full system administration including server management
- Proactive monitoring and security tracking
- Security patch management and vulnerability remediation
- Administration with regular testing
- Support services including audit preparation

#### Healthcare Expertise

- Specialists understanding regulatory challenges
- HIPAA business process optimization and connection support
- Data lifecycle management supporting requirements
- HIPAA-compliance services including risk assessments and training
- HIPAA solutions setup supporting electronic health records

## Implementation and Compliance Management

Successful implementation requires careful planning, systematic execution, and ongoing management ensuring organizations stay compliant with evolving regulatory requirements.

### Migration and Implementation

Organizations transitioning must develop comprehensive migration strategies minimizing operational disruption while ensuring patient data security. Migration planning should address application compatibility, data transfer procedures, security validation, staff training, and cutover coordination.

#### Implementation Phases

- Assessment and planning evaluating current infrastructure
- Hosting environment preparation including infrastructure provisioning
- Data migration executing secure transfer procedures
- Application deployment installing applications
- Security validation conducting penetration testing
- Staff training, educating personnel on new systems
- Cutover execution transitioning production operations

### Ongoing Compliance Management

Maintaining HIPAA-compliance requires continuous monitoring, regular assessments, and proactive management, ensuring configurations remain aligned with regulations. Organizations must establish governance frameworks defining responsibilities and oversight mechanisms.

#### Compliance Activities

- Tracking security metrics, compliance status, and emerging threats
- Regular security assessments and conducting vulnerability scans
- Audit preparation, maintaining documentation
- Incident response planning and testing, validating procedures
- Policy reviews ensure procedures remain aligned
- Staff training programs to maintain current knowledge

### Continuous Improvement

Organizations should implement continuous improvement programs, optimizing performance, security, and cost-effectiveness while maintaining comprehensive compliance. Performance monitoring identifies optimization opportunities, capacity planning supports growth requirements, and security enhancements address emerging threats.

Service provider partnerships should include regular business reviews assessing performance metrics, discussing optimization opportunities, reviewing compliance status, and planning future enhancements. Managed hosting providers should provide a reliable service with proactive recommendations and strategic guidance.

## Partnering for Success

Selecting the right partner establishes foundations for long-term success in healthcare technology operations. Organizations should prioritize providers demonstrating commitment, ongoing investment in security capabilities, transparent communication, and genuine partnership approaches.

Stay compliant with evolving regulatory requirements through partnerships with providers offering services, support, and expert guidance for complex compliance issues. True HIPAA-compliance requires ongoing commitment, continuous improvement, and collaborative partnerships.

A HIPAA covered entity must understand that the requirement for HIPAA compliance extends beyond technology to include people, processes, and partnerships. Success requires selecting providers willing to serve as true partners, providing not just infrastructure but complete solutions supporting healthcare missions.

Ready to look at services designed for your requirements? Atlantic.Net’s specialists can help design secure hosting environments tailored to your organization’s unique needs and regulatory requirements. Our approach combines technical knowledge, regulatory knowledge, experience, and personalized support ensuring success while maintaining full HIPAA-compliance.

Additional security features including HIPAA compliant email services, secure sockets layer and TLS certificates for secure web communications, secure environment architectures protecting data, and full monitoring ensuring many hosting companies cannot match our specialization and commitment to compliance.

Discover how [Atlantic.Net](https://www.atlantic.net) can support your HIPAA-compliance goals.


---

# The Top 5 HIPAA Compliant Analytics Tools for Healthcare Insights in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/the-top-5-hipaa-compliant-analytics-tools-for-healthcare-insights-in-2026/ | Published: 2025-11-10 | Updated: 2026-01-06 | Author: Dr. Rachael Bailey

HIPAA-compliant analytics has become a core part of how healthcare organizations manage data, offering a secure way to turn complex health information into real-time data and actionable insight. These platforms support a wide range of use cases, from electronic health records and population health tools to real-time operational dashboards, and can be deployed across cloud or on-premise environments. The goal isn’t just to improve workflows or streamline operations, but to do so in a way that protects patient privacy and meets regulatory standards at every step.

Choosing the right tool for your needs means finding a platform that combines robust security to protect sensitive data, clear regulatory compliance so you are never left guessing, and smooth integration with your existing technology stack. Each of these factors influences not only the reliability of your analytics but also how effectively your organization can turn complex health data into practical, compliant insight.

This guide outlines the role of HIPAA-compliant analytics in 2025 and reviews the leading platforms that help healthcare organizations gain accurate, actionable insight from protected health information (PHI) while maintaining full compliance with privacy regulations.

## What Does HIPAA Compliance Mean for Analytics Tools?

The [Health Insurance Portability and Accountability Act (HIPAA) of 1996](https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html) established national standards for safeguarding electronic personal health information. Any digital analytics platform that collects or processes patient data must follow the same security and privacy rules that apply to healthcare providers. This includes requiring business associates to sign a Business Associate Agreement (BAA) that defines shared responsibilities for maintaining compliance.

In practice, a HIPAA-compliant analytics environment enforces the [HIPAA Security Rule](https://www.hhs.gov/hipaa/for-professionals/security/index.html), which outlines the technical, administrative, and physical safeguards which protect systems that handle PHI.

These include controlling user access, encrypting data during storage and transmission, and securing the physical infrastructure where data is stored. Covered entities and business associates must use strong authentication, maintain detailed audit logs, and have clear procedures for breach notification. These requirements apply not only to traditional medical records but also to analytics data, which may include identifiers such as a medical record number, billing information, or other health-related details collected through digital tools and tracking technologies.

When implemented correctly, HIPAA-compliant analytics allows healthcare organisations to study patient engagement and customer behavior trends while protecting the confidentiality and integrity of patient information.

## Key Criteria to Evaluate Analytics Platforms in Healthcare Settings

Choosing an analytics platform for your healthcare needs starts with understanding how it handles and manages PHI. A strong web analytics tool should balance security, usability, and integration, giving healthcare providers the insight they need without risking patient privacy.

So, what should you consider when evaluating an analytics platform in a healthcare setting?

### Security and Compliance

Every HIPAA-compliant analytics environment must follow the core principles of the HIPAA Security Rule, which are strict access controls, reliable data encryption, and detailed audit logs. These measures help to keep patient data, session recordings, and analytics information protected from unauthorized access or accidental exposure.

### Integration and Compatibility

Healthcare organizations typically rely on a mix of different digital tools, including patient portals, electronic forms, data warehouses, and mobile apps. The right analytics platform connects these systems securely, captures real-time user interactions, and maintains encrypted data flows across every source.

### Business Associate Agreement (BAA)

Any vendor handling PHI must enter into a signed Business Associate Agreement (BAA) that defines how data is protected, how breaches are reported, and how compliance is monitored. This ensures covered entities and their business associates remain aligned with HIPAA requirements.

Maintaining compliance also requires consistent documentation and ongoing review. Regular audits and updated security protocols help ensure that data protection standards remain current as regulations and technology evolve.

With these criteria in mind, the following platforms represent some of the most reliable HIPAA-compliant analytics tools available to healthcare organizations in 2025.

## Top 5 HIPAA-Compliant Analytics Tools

Each of the following platforms helps healthcare organizations to analyze patient engagement, optimize digital experiences, and measure performance while maintaining strict adherence to HIPAA requirements.

## #1: PostHog

![](https://images.surferseo.art/eb06ad73-935c-4942-9994-d2f94c32a9df.png)
 [PostHog](https://posthog.com/) is an open-source analytics and customer data platform that helps organizations to understand how users interact with their websites and applications. It offers a full suite of tools for tracking behavior, analyzing performance, and turning event data into actionable insight. Designed for self-hosted deployment, PostHog gives healthcare providers and digital teams complete control over data privacy while delivering the depth of analysis needed to enhance user experience and product outcomes.

### Advantages:

- **Open-Source and Self-Hosted:** This enables healthcare organizations to manage health-related data internally, providing full control over PHI and compliance configurations.
- **Comprehensive Analytics Suite:** The platform includes event tracking, funnel and cohort analysis, and real-time session recordings for detailed user behavior insights.
- **Flexible Integration:** Connects easily with data warehouses and other analytics or business intelligence tools to build unified reporting systems.

### Disadvantages:

- **Technical Setup Required:** Self-hosting demands IT support and infrastructure, which may be challenging for smaller healthcare companies.
- **Limited Built-In Compliance Features:** Requires manual configuration for consent management and access controls to meet HIPAA standards.

### Ideal For:

Healthcare organizations who are seeking an adaptable, privacy-focused analytics solution that provides deep behavioral insight while maintaining full data ownership.

## #2: Piwik PRO

![](https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcRSi0lOMXu19FENitZDaHoRlQDcnhzFMRKN8g&s)

Piwik PRO is a privacy-focused analytics and customer data platform designed for organizations that manage regulated or sensitive information. It combines web analytics, tag management, and consent features in one secure environment. With dedicated HIPAA support and hosting options in private cloud or on-premise deployments, Piwik PRO helps healthcare providers to analyze user behaviour while maintaining complete control of patient data.

### Advantages:

- **Enterprise-Grade Privacy Controls:** Offers HIPAA-ready infrastructure and governance tools suited to covered entities and business associates.
- **All-in-One Platform:** Combines analytics, tag management, and consent management in a unified interface to simplify compliance.
- **Flexible Hosting Options:** Available in private cloud, on-premises, or U.S./EU-based data centers for greater control over storage and data protection.

### Disadvantages:

- **High Monthly Costs:** Licensing and support plans may exceed the budget of smaller healthcare organizations.
- **Less Community Support:** As a commercial solution, it lacks the open-source flexibility and user community of platforms such as PostHog or Matomo.

### Ideal For:

Larger healthcare organizations, hospital networks, and digital health providers that need an enterprise-level analytics suite with built-in privacy controls and the option to operate under a signed Business Associate Agreement.

## #3: Mixpanel

![](https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcS14va6-kCgibzHce7myaPGry2RQfOgDMSt8w&s)
 [Mixpanel](https://mixpanel.com/home/) is a leading product analytics platform that gives healthcare organizations and digital health providers real-time visibility into how users interact with their products. Under its enterprise plan, Mixpanel supports HIPAA compliance and provides a signed BAA for covered entities and business associates. Its event-based tracking, funnel analysis, and cohort insights make it easier for product and marketing teams to map the full user journey while maintaining compliance with HIPAA.

### Advantages:

- **HIPAA-Compliant Architecture (Enterprise Plan):** Mixpanel encrypts all data at rest using AES-256-bit encryption within its proprietary analytics database and the underlying Google Cloud Platform, which applies its own layered encryption at the storage level.
- **Startup Program – First Year Free:** Eligible early-stage companies (under five years old, less than $8M in funding, and not part of other offers) can use Mixpanel’s Startup Plan free for their first year, which is an affordable way to begin product analytics before scaling up to an enterprise-level solution.
- **Comprehensive Integrations:** Connects seamlessly with third-party tools, data warehouses, and ad platforms to create a unified view of marketing performance and patient engagement.
- **Pricing Built for Scale:** Mixpanel plans are based on event volume and monthly tracked users, giving teams flexibility to scale analytics as their digital footprint expands across healthcare services.

### Disadvantages:

- **Limited Hosting Flexibility:** Mixpanel is cloud-based, which may not meet the needs of healthcare organizations that require complete data isolation or on-premises deployment.
- **Steep Learning Curve for Advanced Use:** While the interface is user-friendly for basic tasks, more complex features, such as custom event tracking, cohort analysis, or advanced segmentation, can require technical expertise.

### Ideal For:

Startups, digital health providers, and healthcare product teams that want a powerful, real-time product analytics platform to track user engagement, customer journeys, and marketing performance at scale.

## #4: Heap

![](https://s3-us-west-2.amazonaws.com/cbi-image-service-prd/original/62e679ca-3403-4ef1-8e94-41be49e1b122.png?w=3840)
 [Heap](https://www.heap.io/) is a digital analytics platform designed for digital teams to get detailed insights into their customers’ behavior and needs. Its standout “autocapture” feature automatically records every user interaction across web and mobile applications, without requiring manual event tagging. This approach gives healthcare organizations a complete, real-time view of how patients and users move through their digital experiences, helping teams identify bottlenecks, improve patient portals, and measure marketing performance while maintaining HIPAA compliance.

### Advantages:

- **Automatic Data Capture:** Heap’s autocapture technology tracks all user interactions by default, including clicks, form submissions, and page views, giving healthcare teams comprehensive visibility into the customer journey without additional setup.
- **Real-Time Event Tracking and Analysis:** Supports funnel analysis, cohort analysis, and real-time reporting that helps product and marketing teams quickly respond to changes in user engagement and patient health status.
- **Healthcare-Ready Compliance Features:** Offers data encryption, role-based access controls, and alignment with the HIPAA Security Rule, ensuring analytics data is handled in accordance with compliance requirements.

### Disadvantages:

- **Custom Pricing Model:** Heap’s pricing depends on usage and selected features, which can make budgeting difficult for healthcare organizations that track large volumes of data or require longer data retention.
- **Complex Interface:** Heap’s dashboard can take time to master, especially for users new to analytics or those without dedicated data specialists.
- **Limited Integrations:** While Heap connects with many third-party tools, integration options can be limited for more specialized healthcare platforms, which may require additional customization or support.

### Ideal For:

Healthcare systems, digital health platforms, and patient engagement teams that want deep insight into how users interact with online services. It’s best suited for organizations with internal analytics or marketing teams that need an automated, HIPAA-aligned way to improve customer experience, marketing performance, and patient care across multiple data sources.

## #5: Matomo

![](https://images.surferseo.art/ff7c4ba5-492e-4ad6-9512-85809ff6295c.png)

Matomo is an open-source analytics platform that gives healthcare teams full control over how they collect, store, and use customer data. When it’s self-hosted on properly configured servers, it can be set up to meet HIPAA Security Rule requirements, making it a solid option for organizations that want to track user behavior, device IDs, and real-time engagement in a private, compliant environment. It’s especially useful for teams that need to avoid third-party cloud dependencies and prefer to manage everything in-house, without sacrificing visibility or flexibility.

### Advantages:

- **Complete Data Ownership:** When self-hosted, healthcare providers retain full control of data sources, ensuring that analytics data never passes through third parties. This reduces exposure to risk and simplifies HIPAA compliance.
- **Flexible Deployment:** Matomo can be hosted on your own servers or within a HIPAA-compliant private cloud, giving teams control over where analytics data lives and how it’s secured.
- **Free and Open-Source:** Matomo has no licensing fees, with optional paid add-ons for advanced reporting and integration.
- **Privacy-First Design:** Matomo’s privacy policy emphasizes full data ownership by the user, configurable anonymization of visitor data, and safeguards that align with HIPAA and other major privacy laws.

### Disadvantages:

- **Self-Hosting Required for HIPAA Use:** The official Matomo Cloud service is not HIPAA-compliant, and Matomo does not sign a Business Associate Agreement (BAA). To handle PHI, organizations must self-host within a compliant infrastructure.
- **Technical Setup and Maintenance:** Installation, configuration, and ongoing upkeep require IT expertise and dedicated security resources.
- **Limited Integrations:** Matomo connects with fewer marketing and analytics tools compared to larger cloud-based platforms, such as Google Analytics.

### Ideal For:

Matomo is best for teams with the technical capacity to self-host and manage their analytics environment, enabling them to analyze patient engagement, marketing performance, and user behavior while keeping all sensitive data securely in-house.

## Conclusion

Choosing a suitable HIPAA-compliant analytics platform in 2025 means striking the right balance between gaining meaningful insight and protecting sensitive patient data. Each provider takes a slightly different approach, with some prioritizing privacy and control and others choosing to focus on automation and scalability. However, the best fit will depend on how your organization handles health-related information, the technical resources you have, and how much visibility you need across your digital systems.

Analytics in healthcare services now extend beyond tracking website visits or marketing performance, to supporting patient engagement, improving operational efficiency, and strengthening clinical decision-making. The challenge lies in doing all of this securely, without compromising the trust patients place in how their data is used.

[Atlantic.Net](https://www.atlantic.net/) offers a strong foundation for organizations that need to deploy or host HIPAA-compliant analytics environments. With secure cloud infrastructure, managed compliance services, and 24/7 support, it provides the reliability needed to protect sensitive patient information while enabling innovation in healthcare data analysis.

As data-driven care continues to evolve, under the principles of the Health Insurance Portability and Accountability Act, healthcare organizations that invest in both compliance and capability will be best positioned to deliver meaningful, measurable outcomes. [Contact our experts today](https://www.atlantic.net/about-us/corporate-contact/) to learn how our HIPAA-compliant hosting solutions can help you to build a secure, scalable foundation for your healthcare analytics.


---

# Top 6 HIPAA-Compliant CRM Software Tools in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/top-5-hipaa-compliant-crm-software-tools/ | Published: 2025-11-11 | Updated: 2026-01-06 | Author: Alexander Wise

Staff at healthcare practices constantly balance an array of tasks and priorities. Between scheduling patient appointments, facilitating communication between doctors and patients, and ensuring that patients receive an appropriate follow-up, the workload is significant and important tasks can be overlooked or forgotten. The result, unfortunately, can be unhappy patients and a lower quality of care.

Technology advancements and the development of HIPAA-compliant CRM tools can help healthcare practices better deal with these demands. By centralizing patient information, automating tasks, and ensuring all staff is accessing the latest information, these tools can enhance a practice’s performance and productivity.

If you’re considering investing in or upgrading your CRM, doing so could help you provide better patient-centered care and keep your practice competitive.

## Top 6 HIPAA-Compliant CRM Software Tools

These HIPAA-compliant CRM software tools are designed specifically for healthcare practices. They address some of the most common management and administrative challenges that practices face today, and each fully complies with patient privacy rules.

### Onpipeline

[Onpipeline](https://www.onpipeline.com/hipaa-compliant-crm/) is a healthcare CRM built for HIPAA compliance, helping organizations centralize patient relationships without compromising security. Purpose-built for patient acquisition, retention, and management, it brings scheduling, history tracking, and streamlined communications together in a clean, customizable interface.

It meets HIPAA’s technical and physical safeguards, encrypts data at rest, and uses HTTPS/TLS with an A+ rating for data in transit (SSL Labs data). That combination helps providers maintain confidentiality while collaborating across teams and locations. A signed **Business Associate Agreement (BAA)** is available, so covered entities can onboard with the required paperwork in place.

What you can do with it: Manage pipelines for referrals and treatments, keep every interaction in one place, and stay on top of calendars and tasks. Practices can tailor fields and workflows to match their processes, while integrations and role-based access help keep operations tight and auditable.

Onpipeline offers a free 30-day trial, with the Advanced [plan](https://www.onpipeline.com/pricing/) required for organizations that need HIPAA compliance features. It’s a strong fit for small to mid-sized providers that want an intuitive CRM with serious compliance credentials – without the implementation headache.

### NexHealth

NexHealth offers convenient online scheduling that takes care of repetitive, time-consuming tasks so that office staff can focus on patient interactions.

NexHealth empowers patients to schedule their own appointments, even after hours. Patients can see real-time availability through the NexHealth calendar. Single-click booking makes this platform convenient and easy to use, even from a smartphone.

Once appointments are scheduled, the CRM sends reminders via HIPAA-compliant texts. Those texts can also deliver marketing offers and follow-up messages.

If a patient cancels an appointment, they will receive an automated follow-up notification with a link to reschedule. NexHealth even uses the running patient waitlist to fill in cancellations, ensuring a practice stays fully booked and brings in maximum revenue.

This CRM integrates with practice management software and fully supports all of the processes that contribute to getting patients into the office. Electronic HIPAA-compliant forms allow a practice to gather information before an appointment, enabling a touchless check-in and reducing the scanning and data entry required of the office staff.

From facilitating patient and staff safety to delivering convenient 24-7 scheduling, NexHealth can enhance a practice’s overall performance, leading to increased bookings and reduced no-shows.

#### Top benefits

- Digitizes the patient experience
- Lets patients self-schedule at any time
- Eliminates time-consuming scheduling and follow-up tasks

### JotForm Tables

[JotForm Tables](https://www.jotform.com/products/tables/) streamlines the process of gathering information, and it’s a versatile tool that can act as a comprehensive healthcare CRM system. The spreadsheet functionality is easy to use and learn, and it efficiently organizes large amounts of information.

Practices begin by creating an online form. JotForm has many customizable templates available to save you time. Alternatively, a practice can build a form from scratch. Once you’ve built a form, you can share it with patients — for example, a practice can send patients their [intake forms](https://www.jotform.com/intake-form/) and consent forms in their appointment confirmation or reminder email.

As patients complete their forms, the submissions automatically appear in the practice’s JotForm Tables database. There’s no data input to worry about, which reduces the chance for human error. Staff can share the tables with coworkers, so a [nurse](https://betternurse.org/travel-nursing-career-guide/) can access a patient’s intake information for a streamlined patient care process.

A few of the available HIPAA-compliant form templates include:

- New patient registration
- Appointment request
- Patient survey
- Medical history

#### Top benefits

- Time-saving HIPAA-compliant form templates
- Submissions auto-populate the linked table
- Easy sharing features enable staff collaboration

### Aline CRM

Designed for senior housing and post-acute care, [Aline CRM](https://enquiresolutions.com/) is fully customizable so it works for a facility’s specific needs. This comprehensive CRM handles everything from contact management to email notifications to [marketing automation](https://technologyadvice.com/marketing-automation/).

With Aline CRM, all of the tools a facility uses are centrally located. The CRM tracks contact, referral, and inventory data, and real-time dashboards ensure that leads get the proper responses and attention as they move through the sales pipeline.

A facility can access integrated marketing tools within the CRM. These tools can help staff design emails, web forms, landing pages, and even schedule [social media](http://topinfluencermarketingagency.com/) posts, helping to bring in more potential leads.

This CRM also generates powerful reports with over 100 visualizations and a customizable interface. Rather than manually writing reports, a facility can get automated reports for better evaluations and business decision-making.

Automated workflows and integrations further streamline repetitive tasks, saving staff time and helping to ensure processes run smoothly. Other top features include text messaging, calendar syncing, custom alerts, and more.

Aline CRM is ideal for senior living, skilled nursing, home health, and hospice businesses.

#### Top benefits

- Marketing automation with automated email drip campaigns, social media post scheduling, and more
- Automated customizable reports with more than 100 visualizations
- Automated workflows and data entry with contact and referral tracking

### Tebra

Tebra is a HIPAA-compliant patient growth platform that focuses on marketing for healthcare practices. The dashboard system automates and enhances every step of the patient journey.

When it comes to reputation management, Tebra excels. Practices can use the CRM to send regular patient surveys in order to boost the practice’s online reputation. The system also offers valuable content marketing, social media scheduling, and SEO tools to enhance a practice’s digital marketing.

Tebra offers online booking and sends automated SMS appointment reminders and confirmations to reduce no-shows. The CRM’s telehealth functionality offers clear, two-way HD video, complete with a virtual waiting room.

This CRM is ideal for practices that want to streamline their workflows while heavily focusing on advertising and lead generation.

#### Top benefits

- Online booking and telehealth software
- Digital marketing tools that include content marketing, social media scheduling, and SEO tools
- Ability to schedule patient surveys to improve online reputation

### Salesforce Health Cloud

Salesforce Health Cloud delivers the powerful functionality of a top CRM with the features needed for healthcare applications. This software facilitates enhanced patient engagement for a more personalized experience.

The key to this CRM is that it drives communication for more collaborative care. Care coordinators, service agents, patients, family members, and others involved in the patient journey can connect on any device and collaborate throughout the healthcare network. The Health Cloud streamlines the process of supporting patients, allowing for stronger provider-patient relationships.

This CRM can also help streamline workflows, ensuring patients get the attention they need. It can support patient registration, scheduling, and reminders, and useful triggers can move patients along in the registration or follow-up process.

The secure Salesforce cloud can help facilities address HIPAA compliance and protect sensitive patient information.

#### Top benefits

- Supports collaborative care
- Streamlines workflows
- Triggers ensure patients get the follow-ups they need

## Choosing the Right CRM for Your Practice

A CRM that’s a good fit for your medical practice can save your staff time on repetitive tasks, solve the most pressing problems your practice faces, and help you better connect with patients to deliver a top-quality experience. When choosing your new CRM, think carefully about the types of challenges you need to solve and the tasks you want the tool to perform.

While price will always be a consideration when deciding which CRM is right for your business, consider the value the tool can deliver. A CRM that lets your staff create a better patient experience can lead to an improved reputation for your practice, increased leads, and a larger patient base. Those factors can make a CRM a valuable addition to your business, and the tool may well pay for itself.

For over 30 years, Atlantic.Net has helped thousands of businesses with industry-leading [HIPAA compliant cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA compliant website hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions.  Atlantic.Net Cloud is a far superior alternative to traditional providers, providing full control of your cloud server hosting software backed by either public or dedicated resources.  Contact an advisor at 866-618-3282 or email us at [sales@atlantic.net](mailto:sales@atlantic.net) to get started with a hosting solution for your business!

*This article was updated on January 6, 2026.*


---

# Complete Healthcare

> URL: https://www.atlantic.net/press-room/case-studies/complete-healthcare-download/ | Updated: 2026-09-16

## Streamline Your Healthcare Practice with Atlantic.Net: A Case Study with Complete HealthCare Solutions

Discover how Complete HealthCare Solutions (CHS), a leading provider of medical software solutions, partnered with Atlantic.Net to overcome IT infrastructure challenges and achieve HIPAA compliance.

### Download this free case study to learn how CHS:

- **Transitioned from costly and complex in-house infrastructure** to a flexible and scalable Infrastructure-as-a-Service (IaaS) solution.
- **Reduced deployment costs and ensured system compatibility** while incorporating legacy systems.
- **Enabled secure global access to patient records** for physicians 24/7.
- **Leveraged Atlantic.Net's expertise** to design and implement a customised hybrid cloud solution.
- **Achieved substantial cost savings** by eliminating upfront capital expenditures and ongoing maintenance costs.

This case study demonstrates the power of Atlantic.Net's IaaS solutions in helping healthcare providers streamline operations, enhance security, and ensure HIPAA compliance.

**Download the PDF now and explore how Atlantic.Net can empower your healthcare practice.**


---

# ShareSafe Solutions

> URL: https://www.atlantic.net/press-room/case-studies/sharesafe-solutions-download/ | Updated: 2026-09-16

## Enhance Healthcare Security with Atlantic.Net: A Case Study with ShareSafe Solutions

Discover how ShareSafe Solutions, a leading SaaS provider in the medical field, used Atlantic.Net's secure and reliable hosting solutions to protect sensitive patient data and optimise healthcare operations.

### Download this free case study to learn how ShareSafe Solutions:

- **Achieved HIPAA compliance** with Atlantic.Net's dedicated servers and robust security measures.
- **Improved employee productivity and satisfaction** through secure mobile identity authentication.
- **Reduced cybersecurity risks** with advanced communication and real-time intrusion detection.
- **Streamlined staff development and patient education** using a unified platform approach.
- **Scaled their infrastructure seamlessly** with Atlantic.Net's cloud hosting solutions.

This case study provides valuable insights for healthcare organisations seeking to enhance their security posture, improve operational efficiency, and ensure HIPAA compliance.

**Download the PDF now and explore the benefits of partnering with Atlantic.Net for your healthcare IT needs.**


---

# ACP vs AWS & Azure

> URL: https://www.atlantic.net/press-room/case-studies/acp-vs-aws-azure-download/ | Updated: 2026-09-16

## Tired of Overpaying for Cloud Hosting?

Discover the Atlantic.Net advantage. Download our free PDF, "Atlantic.Net Cloud Platform (ACP): The Smart Choice for Businesses," and learn how our powerful, user-friendly, and cost-effective solutions can help you.

### What you'll learn from this case study

- **Slash your cloud hosting costs** without sacrificing performance or features.
- **Simplify server management** with our intuitive control panel.
- **Scale your business with ease** thanks to our robust infrastructure and flexible solutions.
- **Enjoy peace of mind** knowing your data is secure and backed up.

Our PDF provides a detailed comparison of ACP with industry giants like AWS and Microsoft Azure, revealing how Atlantic.Net delivers exceptional value and performance.


---

# NVIDIA Mellanox Connected Clouds

> URL: https://www.atlantic.net/press-room/case-studies/nvidia-mellanox-connected-clouds-download/ | Updated: 2026-09-16

## Connecting the ACP Cloud

NVIDIA Mellanox provides the technology that powers the Atlantic.Net cloud. They help us with two main technologies:

### How NVIDIA Mellanox connects the Atlantic.Net cloud

- **InfiniBand:** super fast and enables servers to communicate at breakneck speeds efficiently. InfiniBand technology underpins our cloud service and disaster recovery communications.
- **Ethernet and RoCE:** our servers communicate over high-speed Ethernet, and the storage layer is connected via RoCE.

NVIDIA Mellanox also offers **VPI**, which lets you use both InfiniBand and Ethernet together, giving Atlantic.Net flexibility in how we set things up for our clients.


---

# NVIDIA Mellanox InfiniBand

> URL: https://www.atlantic.net/press-room/case-studies/nvidia-mellanox-infiniband-download/ | Updated: 2026-09-16

## Atlantic.Net: Mellanox High-Performance Cloud

At Atlantic.Net, we've invested in NVIDIA Mellanox InfiniBand solutions to deliver high-performance cloud services with high efficiency and ultra-low latency, giving our customers a strong cloud experience.

### What InfiniBand delivers in our cloud

- **Reduced costs:** Mellanox dramatically reduces hardware and operational costs.
- **Accelerated storage access:** stronger SLAs through Serial Attached SCSI SSD disks and a minimum of 40 Gb/s infrastructure throughout.
- **Transparent I/O consolidation:** consolidating LAN, SAN, and live migrations across one fabric improves performance across the board.
- **Faster data handling:** simple cabling and fewer switching ports let us serve our growing customer base instantly.
- **Lower latency:** we use the iSER (iSCSI Extensions for RDMA) protocol for lower latency and cost than traditional solutions.
- **Faster server builds and snapshots:** servers can be provisioned in under 30 seconds using rapid snapshots and backups.

Mellanox enables us to deliver high-performance storage, cost-effective networking, and an exceptional customer experience.

Mellanox is part of the technology stack that supports our 100% uptime SLA, helping Atlantic.Net meet customer expectations with our cloud infrastructure.


---

# Supermicro

> URL: https://www.atlantic.net/press-room/case-studies/super-micro-download/ | Updated: 2026-09-16

## Atlantic.Net: Supermicro-Powered Cloud

At Atlantic.Net, we exclusively use Supermicro servers to deliver top-tier cloud services to our clients.

### Our Supermicro clusters can:

- **Handle diverse workloads** like HIPAA-compliant and PCI-compliant hosting.
- **Optimise performance** for applications with Supermicro's solutions.
- **Energy-efficient** servers reduce environmental impact and costs.
- **Cost-effective** hardware lets us offer competitive pricing.

Supermicro helps us meet customer demand and provide optimised solutions. We deliver secure, high-performance cloud services to help you achieve your business goals.


---

# Eaton Data Center

> URL: https://www.atlantic.net/press-room/case-studies/eaton-data-center-download/ | Updated: 2026-09-16

## Atlantic.Net: Delivering on Our Promise of 100% Uptime

At Atlantic.Net, we're obsessed with reliability. That's why we've upgraded our Orlando data center with Eaton Power Xpert 9395 UPS systems. This cutting-edge technology supports 100% uptime for your critical systems, helping protect your business from costly downtime.

### What does this mean for you?

- **Zero interruptions:** rest assured, your operations will run smoothly thanks to the 9395's redundant design and advanced VMMS technology.
- **Greener operations:** we're committed to sustainability. The 9395's high efficiency reduces our environmental impact and helps lower your costs.
- **Proactive monitoring:** our team uses Power Xpert software to support peak performance and prevent potential issues.
- **Optimised space:** the 9395's compact design maximises our data center space to accommodate your growing needs.
- **Expert service:** our Eaton service plan supports ongoing reliability and optimal performance.

With the 9395 UPS, we're delivering on our promise of unwavering power and strong reliability for your business.


---

# HIPAA IT Infrastructure Guide

> URL: https://www.atlantic.net/about-us/whitepapers/hipaa-it-infrastructure-guide/ | Updated: 2026-09-16

## HIPAA Compliance in Healthcare IT: A Comprehensive Guide

Staying compliant with HIPAA regulations is a complex and challenging task for healthcare professionals. Download our free whitepaper, “HIPAA-Compliant IT Infrastructure Guide,” to gain valuable insights and practical guidance on building and maintaining a secure, compliant IT infrastructure.

## This informative guide covers crucial aspects of HIPAA compliance, including:

- Understanding HIPAA requirements: a detailed explanation of the Security Rule, HITECH Act, and EDI standards for data transmission.
- Building a compliant infrastructure: a comprehensive checklist covering physical, technical, and administrative safeguards for protecting ePHI.
- HIPAA-compliant cloud hosting: guidance on selecting a cloud provider and supporting compliance in a cloud environment.
- Best practices for data security: strategies for preventing breaches, managing risks, and implementing security measures like encryption and access controls.
- Business Associate Agreements: key considerations for establishing strong BAAs with service providers.

## Download this essential resource to:

- Strengthen your understanding of HIPAA requirements and develop a proven compliance strategy.
- Identify potential vulnerabilities in your IT infrastructure.
- Help ensure the security and privacy of patient data.


---

# Cloud & Managed Hosting for Healthcare Professionals

> URL: https://www.atlantic.net/about-us/whitepapers/cloud-managed-hosting-for-healthcare-professionals/ | Updated: 2026-09-16

## Optimise Healthcare IT with Cloud and Managed Hosting

Discover how cloud computing and managed hosting solutions have transformed healthcare. Download our free whitepaper, “Cloud & Managed Server Hosting for Healthcare Professionals,” and explore the benefits of HIPAA-compliant hosting technologies for security, scalability, and efficiency.

## This comprehensive guide provides valuable insights into:

- HIPAA, HITECH, and SSAE 18 compliance: understand the key requirements for healthcare hosting and how cloud and managed hosting providers support your compliance efforts.
- Choosing the right cloud model: explore the advantages and disadvantages of private, public, and hybrid cloud models for healthcare organisations.
- Selecting a strong healthcare host: key questions to ask potential providers and essential factors to consider, such as expertise, security measures, and flexibility.
- Data center advantages: consider the economies of scale, advanced infrastructure security, and how expert support contributes to optimal performance and cost savings.
- Launching your compliant healthcare system: practical guidance on implementing and managing a secure and efficient IT infrastructure in the cloud.

## Download this informative resource to:

- Gain a deeper understanding of cloud and managed hosting solutions for healthcare.
- Make informed decisions about your IT infrastructure.
- Optimise your healthcare operations for security, scalability, and compliance.


---

# HIPAA Compliance Developer Guide

> URL: https://www.atlantic.net/about-us/whitepapers/hipaa-compliance-developer-guide/ | Updated: 2026-09-16

## A Developer’s Guide to HIPAA-Compliant Applications

Building healthcare applications requires more than coding skills; it demands a deep understanding of HIPAA regulations to ensure the privacy and security of patient data. Download our free whitepaper, “HIPAA-Compliant Developer Guide,” and gain valuable insights into the complexities of HIPAA compliance in healthcare software development.

## This comprehensive guide covers hot topics for developers, including:

- HIPAA & HITECH laws: a clear explanation of the key requirements and their implications for software development.
- Covered entities & business associates: understanding the roles and responsibilities of different parties involved in handling ePHI.
- Privacy, Security & Breach Notification rules: a detailed breakdown of the core HIPAA rules and how they apply to software applications.
- HIPAA-compliant mobile app security checklist: practical steps to ensure your mobile app meets HIPAA security standards.
- HIPAA-compliant web app security checklist: a comprehensive checklist covering key security considerations for web applications.

## Download this essential resource to:

- Gain a solid understanding of HIPAA requirements for software development.
- Build secure and compliant mobile and web applications.
- Protect patient data and avoid costly HIPAA violations.


---

# IT Solutions for Healthcare

> URL: https://www.atlantic.net/about-us/whitepapers/it-solutions-for-healthcare/ | Updated: 2026-09-16

## Choosing the Right IT Solution for Your Healthcare Organisation

Download our free whitepaper, “IT Solutions for Healthcare: How to Choose,” and discover how managed IT services and cloud solutions can help healthcare organisations overcome challenges, enhance security, and improve patient care.

## This guide provides valuable insights into:

- Understanding healthcare IT solutions: explore the various technologies and services available to optimise healthcare operations and patient care.
- Benefits of managed IT services: discover how outsourcing IT tasks can help you address compliance challenges, improve cybersecurity, and enable workforce mobility.
- Key considerations for choosing a provider: learn about the essential factors to evaluate when selecting a managed IT service provider, such as breadth of services, total cost of ownership, and compliance awareness.
- Atlantic.Net’s solutions for healthcare: explore how Atlantic.Net’s expertise and comprehensive suite of services can help you achieve your healthcare IT goals.

## Download this valuable resource to:

- Gain a deeper understanding of the IT challenges and solutions in the healthcare industry.
- Make informed decisions about your IT infrastructure and managed services.
- Optimise your healthcare operations for security, efficiency, and compliance.


---

# HIPAA Disaster Recovery Guide

> URL: https://www.atlantic.net/about-us/whitepapers/hipaa-disaster-recovery-guide/ | Updated: 2026-09-16

## Supporting HIPAA Disaster Recovery: A Comprehensive Guide

Safeguarding electronic protected health information (ePHI) is a fundamental requirement in healthcare, and a proven disaster recovery (DR) plan is essential for achieving HIPAA compliance.

Download our free whitepaper, “HIPAA Disaster Recovery Guide,” and gain valuable insights into building and executing an effective DR plan for your healthcare organisation.

## This informative guide covers crucial aspects of HIPAA disaster recovery, including:

- Purpose of a DR plan: understanding the importance of a DR plan in supporting business continuity and protecting ePHI during unexpected events.
- Business Associate Agreements: establishing clear responsibilities and compliance requirements with your cloud service provider.
- Recovery Time Objective (RTO) and Recovery Point Objective (RPO): defining and achieving acceptable recovery timeframes and data-loss limits.
- Hosted infrastructure redundancy protection: implementing measures to support the resilience and availability of your IT infrastructure.
- Disaster recovery plan activation and process: establishing clear procedures for activating your DR plan and coordinating recovery efforts.
- Recovering servers and services: step-by-step guidance on restoring critical IT infrastructure and services.
- Testing, root-cause analysis, and service relocation: validating the effectiveness of your DR plan through testing, root-cause analysis, and planning for service relocation and return to business as usual (BAU).

## Download this essential resource to:

- Develop a comprehensive HIPAA-compliant disaster recovery plan.
- Protect your healthcare organisation from data loss and downtime.
- Support business continuity in the face of unexpected events.
- Maintain HIPAA compliance and safeguard patient data.


---

# HIPAA Compliance Fundamentals

> URL: https://www.atlantic.net/about-us/whitepapers/hipaa-compliance-fundamentals/ | Updated: 2026-09-16

## HIPAA Compliance Fundamentals: A Must-Read for Healthcare Organisations

Download our free whitepaper, “HIPAA Compliance: Important Fundamentals You Need to Know,” and gain a comprehensive understanding of the HIPAA Security Rule, Privacy Rule, and HITECH Act.

## This essential guide covers:

- Basics of HIPAA and HITECH: a clear explanation of the key requirements for protecting electronic patient health information (ePHI).
- HIPAA compliance simplified: practical tips and actionable strategies for achieving and maintaining HIPAA compliance.
- Checklist: how to make sure you’re compliant: a comprehensive checklist covering the HIPAA Security Rule, Privacy Rule, Breach Notification Rule, and Omnibus Rule.

## Download this valuable resource to:

- Strengthen your understanding of HIPAA requirements.
- Develop a robust HIPAA compliance strategy.
- Help ensure the security and privacy of patient data.
- Protect your healthcare organisation from potential fines and lawsuits.


---

# HIPAA Python Applications Guide

> URL: https://www.atlantic.net/about-us/whitepapers/hipaa-python-applications-guide/ | Updated: 2026-09-16

## Building HIPAA-Compliant Python Applications: A Best-Practice Guide

Python, a popular and versatile programming language, is widely used for application development. However, when it comes to healthcare applications dealing with protected health information (PHI), HIPAA compliance is crucial. This whitepaper provides essential guidance on building HIPAA-compliant Python applications.

## Key areas covered include:

- Designing HIPAA-compliant apps: understanding the importance of incorporating HIPAA compliance into the design and development process.
- Five key design requirements: implementing essential features such as user controls, access and authorisation controls, backup and restore capabilities, software-defined disaster recovery, and automatic logout.
- User controls: restricting access to authorised personnel and implementing administrative controls to manage user access and permissions.
- Access & authorisation controls: integrating access and authorisation controls to prevent unauthorised access to confidential information.
- Backing up and restoring data: implementing backup and restore functions to support data availability and integrity.
- Software-defined disaster recovery: leveraging Python functions to create highly available applications and support business continuity.

## Download this informative resource to:

- Gain insights into building secure and compliant healthcare applications.
- Learn about best practices for protecting PHI in Python applications.
- Help ensure your applications meet HIPAA requirements.


---

# HIPAA WordPress Guide and Checklist

> URL: https://www.atlantic.net/about-us/whitepapers/hipaa-wordpress-guide-and-checklist/ | Updated: 2026-09-16

## HIPAA WordPress Setup and HIPAA Compliance Checklist

This whitepaper offers a practical guide to setting up a HIPAA-compliant WordPress website, along with a comprehensive checklist to support compliance with the relevant regulations.

## Key topics covered include:

- HIPAA compliance checklist: a detailed checklist covering technical, physical, and administrative safeguards to protect electronic protected health information (ePHI).
- Sample HIPAA WordPress setup: a practical example of how to configure a HIPAA-compliant WordPress website, including hardware and software considerations.
- Hardened OS & software: best practices for securing your operating system and software, including updates, patching, and server configuration.
- Business Associate Agreement (BAA): understanding the importance of a BAA with your hosting provider and what it should cover.
- Intrusion prevention: implementing an intrusion prevention system (IPS) to monitor and block malicious activity.
- Managed firewall: protecting your network with a 24/7 managed firewall service.
- Continuous data protection backup: supporting data security and availability with robust, regular backups.
- Encryption: implementing encryption to protect ePHI at rest and in transit.

## Download this helpful guide to:

- Learn how to set up a secure, HIPAA-compliant WordPress website.
- Make sure your website meets the relevant regulatory requirements.
- Protect patient data and avoid costly HIPAA violations.


---

# How to Make Storage HIPAA Compliant

> URL: https://www.atlantic.net/about-us/whitepapers/how-to-make-storage-hipaa-compliant/ | Updated: 2026-09-16

## Simplify HIPAA Compliance for File Storage

Storing electronic Protected Health Information (ePHI) securely is crucial for any healthcare organisation. Download our free whitepaper, “10 Tips for HIPAA Compliant File Storage,” and learn how to navigate the complexities of HIPAA and HITECH regulations while leveraging the benefits of cloud-based file storage.

## This concise guide provides practical advice on:

- Identifying PHI: determine which data falls under HIPAA regulations.
- Implementing security measures: understand and apply the necessary administrative, technical, and physical safeguards.
- Encryption: support ePHI in transit and at rest with strong encryption.
- Risk assessment: regularly analyse and mitigate potential risks.
- Business Associate Agreements: establish strong BAAs with your cloud service provider.

Download this valuable resource to make sure your file-storage practices meet HIPAA compliance standards and protect sensitive patient data.


---

# Why Encryption is Essential in Healthcare Cybersecurity

> URL: https://www.atlantic.net/about-us/whitepapers/why-encryption-is-essential-in-healthcare-cybersecurity/ | Updated: 2026-09-16

## Protect Patient Data with Powerful Encryption

Want to make sure your healthcare organisation is safeguarding sensitive information and meeting HIPAA compliance standards? Download our free whitepaper, “Why Encryption is Essential in Healthcare Cybersecurity Strategies,” and learn how to implement robust encryption practices.

## This informative guide provides:

- A clear explanation of encryption and its importance in healthcare.
- Practical guidance on choosing the right encryption solutions.
- Key considerations for securing data at rest and in transit.

Download this valuable resource to strengthen your cybersecurity strategy and protect patient data.


---

# HIPAA LAMP Stack Guide

> URL: https://www.atlantic.net/about-us/whitepapers/hipaa-lamp-stack-guide/ | Updated: 2026-09-16

## Build a Secure Foundation for Your Healthcare Applications

Developing a LAMP stack for your healthcare application? Download our free whitepaper, “Best Practices for Creating a HIPAA-Compliant LAMP Stack,” and learn how to configure your Linux, Apache, MySQL, and PHP components to meet stringent HIPAA security standards.

## What you’ll learn

- Hardening your Linux OS: secure configurations, strong passwords, and encryption best practices.
- Optimising Apache for security: DDoS protection, access control, and TLS encryption.
- Securing your MySQL database: data masking, encryption at rest, and access control measures.
- Implementing secure PHP practices: keeping PHP updated and employing secure password handling.

Download this valuable resource to make sure your LAMP stack is built with a solid foundation of security and HIPAA compliance.


---

# HIPAA LEMP Stack Guide

> URL: https://www.atlantic.net/about-us/whitepapers/hipaa-lemp-stack-guide/ | Updated: 2026-09-16

## Best Practice for Creating a HIPAA-Compliant LEMP Stack

This whitepaper provides a comprehensive guide to securing a LEMP stack for HIPAA compliance. It offers practical advice and best practices for configuring each component of the stack (Linux, Nginx, MySQL, PHP) to support the confidentiality, integrity, and availability of protected health information (PHI).

## Key topics covered

- Hardening the Linux operating system: regularly updating the OS, using disk-encryption tools, enforcing strong passwords, and restricting file permissions.
- Nginx best-practice tips: regularly updating Nginx, obfuscating server information, enforcing HTTP Strict Transport Security (HSTS), disabling deprecated SSL standards and weak cipher suites, disabling unwanted modules, and enforcing cross-site scripting (XSS) protection.
- MySQL best practice: implementing data masking and de-identification routines, encrypting data at rest, enabling SELinux for access control, using plugins for authentication and access restriction, and enabling the MySQL Enterprise Audit plugin for monitoring and logging.
- PHP best practice: keeping PHP up to date, hashing and verifying passwords, enforcing a user registration system, and protecting against cross-site scripting (XSS) and cross-site request forgery (CSRF).

## Download this helpful guide to:

- Understand the importance of HIPAA compliance for LEMP stacks.
- Learn practical steps to secure each component of your LEMP stack.
- Implement best practices for data protection and access control.
- Help ensure your web applications meet HIPAA requirements.


---

# HIPAA WordPress Guide

> URL: https://www.atlantic.net/about-us/whitepapers/hipaa-wordpress-guide/ | Updated: 2026-09-16

## Best Practice for Creating a HIPAA-Compliant WordPress Site

This whitepaper offers a comprehensive guide to securing a WordPress site for HIPAA compliance. It provides a clear framework and practical steps to support the confidentiality, integrity, and availability of protected health information (PHI) managed through your WordPress site.

## Key topics covered

- HIPAA-compliant design rules for WordPress: incorporating access controls, audit controls, integrity controls, and transmission security controls to safeguard PHI.
- Server hardening: regularly updating WordPress, PHP, and the operating system; using strong passwords; encrypting file transfers; updating file permissions; and restricting database user privileges.
- HIPAA-compliant WordPress hosting: choosing a hosting provider that implements physical security controls, offers a firewall, provides encrypted VPN and data backup plans, and supports disaster recovery.

## Download this helpful guide to:

- Understand the HIPAA compliance requirements for WordPress sites.
- Learn how to implement security measures to protect PHI on your WordPress site.
- Choose a HIPAA-compliant hosting provider for your WordPress site.


---

# HIPAA cPanel Guide

> URL: https://www.atlantic.net/about-us/whitepapers/hipaa-cpanel-guide/ | Updated: 2026-09-16

## Best Practice for Creating a HIPAA-Compliant cPanel Host

This whitepaper provides a comprehensive guide to securing a cPanel host for HIPAA compliance. It offers practical advice and best practices for configuring cPanel, Apache, MySQL, and PHP to support the confidentiality, integrity, and availability of protected health information (PHI).

## Key topics covered

- Securing cPanel: implementing strong passwords, hardening the /tmp partition, restricting system compilers, disabling unused services and daemons, restricting filesystem permissions, controlling access by IP address, keeping cPanel updated, and enabling cPanel logging.
- Securing Apache: keeping Apache up to date, configuring Apache to increase DDoS protection, setting strict permissions on server root directories, enforcing TLS certificate encryption, implementing dynamic content security, and protecting system settings and service files with .htaccess restrictions.
- Securing the database: implementing MySQL Enterprise Data Masking and De-identification routines, encrypting data at rest, enabling SELinux for access control, implementing MySQL plugins for authentication and access restriction, and enabling the MySQL Enterprise Audit plugin for monitoring and logging.
- Securing PHP: keeping PHP up to date, hashing and verifying passwords, and protecting against cross-site scripting (XSS) and cross-site request forgery (CSRF).

## Download this helpful guide to:

- Understand the importance of HIPAA compliance for cPanel hosts.
- Learn practical steps to secure cPanel, Apache, MySQL, and PHP.
- Implement best practices for data protection and access control.
- Help ensure your web applications meet HIPAA requirements.


---

# Introduction to Virtualization

> URL: https://www.atlantic.net/about-us/whitepapers/introduction-to-virtualization/ | Updated: 2026-09-16

## Introduction to Private Cloud Technologies: Virtualization

This 17-page whitepaper provides a comprehensive overview of virtualisation and its role in private cloud technologies. It explores the various types of virtualisation, their benefits, and their adoption rates, highlighting the advantages of private cloud solutions.

## Key topics covered

Types of virtualisation:

- Application virtualisation: run applications locally without installation.
- Desktop virtualisation: access your desktop environment from any authorised device.
- Hardware virtualisation: multiple operating systems run on a single physical machine.
- Network virtualisation: software-defined networking for flexible and efficient network management.
- Storage virtualisation: pool physical storage resources into a single, logical unit.
- Nested virtualisation: run a hypervisor within a virtual machine (useful for development and testing).

## Download this helpful guide to:

- Learn about the different types of virtualisation and their applications.
- Understand the benefits of virtualisation for flexibility, availability, scalability, hardware utilisation, and security.
- Gain insights into the adoption rates and trends of virtualisation.


---

# Ransomware in the Wild

> URL: https://www.atlantic.net/about-us/whitepapers/ransomware-in-the-wild/ | Updated: 2026-09-16

This whitepaper provides a deep dive into the world of ransomware, exploring its evolution, impact, and the challenges it poses to various sectors.

## Key topics covered

- The rise of ransomware: from simple viruses to sophisticated attacks, how ransomware has evolved and the motivations behind it.
- Industries under attack: why healthcare, finance, and government institutions are prime targets for ransomware attacks.
- The ransomware challenge: the difficulties in assessing the scale of attacks, the dilemma of paying ransoms, and the importance of robust cybersecurity measures.

## Download this helpful guide to:

- Grasp the evolution and impact of ransomware.
- Learn about vulnerable industries.
- Understand the challenges of combating ransomware.
- Explore effective prevention strategies.


---

# Multi-Factor Authentication

> URL: https://www.atlantic.net/about-us/whitepapers/multifactor-authentication/ | Updated: 2026-09-16

## What Is Multi-Factor Authentication (MFA)?

This whitepaper provides a comprehensive overview of multi-factor authentication (MFA), a critical security practice that adds multiple layers of protection to user logins and access to sensitive IT infrastructure.

## Key topics covered

- Two-factor authentication (2FA): a security practice that requires the user to provide something they know (password) and something they have (physical device or code).
- Multi-factor authentication (MFA): similar to 2FA but with an additional layer such as a fingerprint or retinal scan to further secure login access.
- SFA vs. 2FA vs. MFA: a comparison of the security levels offered by single-factor authentication (SFA), 2FA, and MFA, highlighting the advantages of 2FA and MFA in protecting against unauthorised access.

## Download this helpful guide to:

- Understand the importance of MFA in today's cybersecurity landscape.
- Learn the differences between SFA, 2FA, and MFA.
- Discover best practices for implementing MFA in your organisation.


---

# Overview of Redundant Systems

> URL: https://www.atlantic.net/about-us/whitepapers/overview-of-redundant-systems/ | Updated: 2026-09-16

Redundancy in computing and networking is crucial for supporting business continuity and preventing downtime. This whitepaper explores various types of redundant systems and their implementations across hardware and software services.

## Key topics covered

- Types of redundant systems: Active-Inactive (Hot-Cold), Active-Active (Hot-Hot), and Active-Standby (Hot-Warm) configurations, each with unique approaches to maintaining system uptime.

## Examples of redundant software services

- Hyper-V Replica: a hot-warm redundancy solution for virtual machines, enabling replication of primary VMs to a separate physical host for failover protection.
- Hyper-V clustering: clustering VMs on a single host for local redundancy and load balancing through virtual networking.
- HAProxy: a Linux-based load balancer and high-availability solution for TCP and HTTP-based applications.

## Examples of redundant hardware services

- RAID (Redundant Array of Independent Disks): different RAID levels (RAID 0, RAID 1, RAID 5, RAID 10) for data protection and increased disk I/O performance.
- Networking redundancy: First Hop Redundancy Protocols (FHRP) like VRRP, HSRP, and GLBP for redundant gateways and load balancing.
- Data center redundancy: the Uptime Institute's tiered classification system for data center fault tolerance and high availability.

## Download this helpful guide to:

- Understand the importance of redundancy in maintaining system availability.
- Learn about different types of redundant systems and their applications.
- Explore examples of redundant software and hardware services.
- Gain insights into data center redundancy and tiered classifications.


---

# Power Infrastructure

> URL: https://www.atlantic.net/about-us/whitepapers/power-infrastructure/ | Updated: 2026-09-16

This whitepaper provides an overview of Atlantic.Net's robust power infrastructure, highlighting the critical role of reliable power solutions in supporting business continuity and preventing downtime.

## What you'll learn

- BladeUPS: the whitepaper highlights the Eaton BladeUPS system, a scalable and modular power-protection solution designed for high-density computing environments.
- Scalability: BladeUPS allows for easy expansion of power capacity by combining 12 kW modules, supporting growth alongside the business.
- Reliability: the system's parallel configuration capability, using Powerware Hot Sync technology, eliminates a single point of failure and supports continuous availability.
- Serviceability: BladeUPS is designed for easy serviceability, with hot-swappable batteries and electronics modules that can be replaced in minutes without interrupting power to critical loads.
- Energy efficiency: the system has a 98% efficiency rating, helping businesses reduce power and cooling costs.

## Download this helpful guide to:

- Understand the importance of reliable power infrastructure for business continuity.
- Learn about the benefits of the Eaton BladeUPS system, including its scalability, reliability, serviceability, and energy efficiency.
- Gain insights into how Atlantic.Net leverages BladeUPS to support 100% uptime for its customers.


---

# Choosing a Data Center

> URL: https://www.atlantic.net/about-us/whitepapers/choosing-a-data-center/ | Updated: 2026-09-16

This whitepaper guides IT professionals in selecting a data center that supports business continuity and disaster recovery.

## Key topics covered

- Budgeting: determine your budget and assess the cost of downtime.
- Physical security: evaluate security measures and compliance requirements.
- Space and power: determine your needs for space, power, and redundancy.
- Cooling: evaluate the cooling infrastructure and its efficiency.
- Connectivity: assess bandwidth, connectivity options, and redundancy.
- Support: 24/7 support, physical access, and on-site assistance.

## Download this helpful guide to:

- Learn how to choose the right data center for your needs.
- Understand key factors like budget, security, and infrastructure.
- Gain insights into due diligence and site visits.


---

# Rapid Diagnostics, Precise Insights

> URL: https://www.atlantic.net/about-us/whitepapers/rapid-diagnostics-precise-insights/ | Updated: 2026-09-16

## Transforming Medical Applications with Atlantic.Net GPUs

GPUs dramatically accelerate AI/ML workloads in healthcare, enabling much faster and more accurate medical imaging, diagnostics, genomic analysis, and predictive modelling than traditional CPU-based systems. Download this paper and you can:

## What you'll learn

- Understand concrete use cases where GPUs improve care: rapid and clearer MRI/CT reconstruction, enhanced digital pathology and mammography, OCT analysis, automated image segmentation, radiomics, genomics, disease risk prediction, drug-response modelling, and clinical-trial optimisation.
- See how telemedicine and virtual care benefit from GPU-accelerated AI, including better real-time analysis of patient data and higher-quality video consultations that integrate visualised clinical information.
- Look ahead to emerging trends such as AI-driven security/compliance automation, heterogeneous CPU/GPU/FPGA architectures, edge-based HIPAA-compliant diagnostics, federated learning for collaborative research, and future needs like quantum-resistant encryption.
- Find out how Atlantic.Net supports HIPAA compliance for GPU workloads through physical, technical, and administrative safeguards, covering encryption, access controls, audit trails, vulnerability management, BAAs, backup/DR, and incident response.
- Learn how Atlantic.Net's HIPAA- and HITECH-compliant GPU cloud hosting, powered by NVIDIA H100 NVL and L40S GPUs, offers healthcare organisations high-performance infrastructure tuned for AI-driven medical applications.


---

# Atlantic.Net vs. Liquid Web: A HIPAA-Compliant Hosting Showdown for Healthcare and Legal Teams

> URL: https://www.atlantic.net/hipaa-compliant-hosting/atlantic-net-vs-liquid-web-hipaa-hosting-comparison/ | Published: 2025-11-20 | Updated: 2025-11-24 | Author: Robert Agar

Healthcare companies and legal organizations must protect the sensitive information they process to comply with HIPAA data privacy and security regulations. Many of these businesses search for HIPAA-compliant cloud hosting solutions from providers such as Atlantic.Net, Liquid Web, and other companies. Both companies are recognized as reputable cloud hosting providers. However, many teams favor Atlantic.Net for its lengthy experience in the business, flexibility, and willingness to tailor support to meet customer requirements.

This post examines why Atlantic.Net is becoming a preferred HIPAA hosting option for a wide range of customers, especially mobile phlebotomists, dental practices, and legal SaaS applications. We offer services and support to address the needs of clients just starting with HIPAA cloud hosting, as well as those who are unsatisfied with their current provider.

## Atlantic.Net HIPAA Hosting Framework is Built for Compliance

We have over 30 years of experience and a proven track record of providing HIPAA-compliant hosting solutions to our customers. Our technical, compliance, and administrative teams have the experience and skills to deliver a cloud hosting platform that supports HIPAA compliance for businesses of all sizes. Your company will enjoy the following benefits by partnering with Atlantic.Net for HIPAA hosting.

### Fully audited and compliant infrastructure

Atlantic.Net offers [customized Windows and Linux HIPAA hosting plans](https://www.atlantic.net/hipaa-compliant-hosting/) to meet the needs of businesses ranging from small healthcare companies to enterprise legal teams. Our infrastructure is SOC 2 and SOC 3 certified and HIPAA/HITECH audited by an independent third-party CPA firm that validates our operational controls and compliance services. This audited environment is designed to help keep your data secure and support your efforts to achieve and maintain HIPAA compliance.

### Customizable Business Associate Agreements

Hosting providers are considered business associates (BAs) of the covered entities and business associates that engage their services. HIPAA rules require customers to sign a Business Associate Agreement (BAA) with their provider to define the BA’s responsibilities in maintaining compliance. We enter into [customizable BAAs](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) with our customers that align with their business requirements and the level of responsibility each party assumes in safeguarding protected health information (PHI).

## Managed Services That Simplify IT for Healthcare and Legal Teams

Many healthcare and legal small and medium-sized businesses (SMBs) have limited technical teams and may lack the skills to efficiently and securely manage their IT environments. Companies risk financial penalties for HIPAA noncompliance when infrastructure and security controls are poorly managed. Our managed services let you focus on running your business while we help ensure the health, security, and performance of your hosted Windows and Linux environments.

HIPAA compliance is a shared responsibility: we provide and manage the audited infrastructure, security controls, and supporting documentation, while your team maintains compliant application configurations, access controls, and internal policies.
 The features provided in our managed services solutions include:

- Automated patching to address security vulnerabilities and performance upgrades.
- Secure backups to protect data in line with HIPAA guidelines.
- Real-time monitoring and intrusion detection to help ensure performance and security.

Our expert support teams have healthcare-specific experience and are available 24/7 to resolve your issues. Smaller healthcare companies and those with growing SaaS platforms can benefit from a managed services solution that allows them to concentrate on core business activities while we support the underlying hosting environment.

## Transparent Pricing and Modular Options

Atlantic.Net transparent pricing and modular options are structured to appeal to healthcare and legal SMBs looking to maximize value and control IT costs. We deliver hosting that provides the features you need now and as your business grows, with understandable pricing plans and no hidden fees.

### Customizable bundled services

Healthcare and legal companies may have very different needs in a HIPAA-compliant hosting solution. Providers with a one-size-fits-all approach cannot effectively serve the diverse customer base that requires HIPAA hosting. We offer clients customizable hosting that ensures they are not paying for services or options they do not need. Services that can be included or excluded to meet customer requirements include:

- A fully managed firewall.
- On-site and/or off-site backups.
- Intrusion detection.
- Bi-weekly (every two weeks) vulnerability scans.
- Multi-factor authentication.
- Network edge protection.

### Clear and predictable billing

The monthly costs of our hosted platforms are determined by multiple variables, such as the specific security services or server configuration chosen by a customer. Our hosting solutions are delivered with transparent pricing plans and predictable billing, making it easier for your company to budget for IT services. Your organization controls costs by choosing only the options needed to support HIPAA compliance.

### Scale as your business grows

Our services are designed to scale easily as your business grows, ensuring you have the resources required to maintain performance and customer satisfaction. The flexibility of our HIPAA hosting enables small companies to utilize a right-sized environment, conserving financial resources. We can scale resources as the business expands, so you only pay for what you need.

## Real-World Use Cases for Atlantic.Net HIPAA-Compliant Hosting

Atlantic.Net has provided secure, HIPAA-compliant hosting for a wide variety of healthcare and legal organizations. The following are examples of organizations that benefit from the flexibility of our customized hosting solutions:

- **Dental practices in Texas:** We provided a solution tailored to the local compliance and low-latency requirements of a Texas healthcare business, onboarding them directly into our regional data center in Dallas, Texas.
- **Mobile phlebotomy services:** We worked with mobile phlebotomy providers that needed secure access to EHR and scheduling systems from patient homes, clinics, and remote sites, delivering encrypted connectivity and low-latency access across our US regions.
- **Healthcare marketing agencies:** We host sensitive, HIPAA-regulated campaign data for numerous clients that requires fast server speeds for analytics while maintaining PHI security and privacy.
- **Legal SaaS platforms:** We provide legal organizations with secure hosting, including data encryption and isolation, to help ensure client confidentiality and support HIPAA compliance when they process PHI.

## Why Organizations Are Switching to Atlantic.Net

Organizations are increasingly migrating to Atlantic.Net to escape the limitations of rigid hosting providers. Backed by 31 years of industry experience, we understand that effective HIPAA compliant hosting requires adaptability.

While some other providers offer inflexible terms and outdated infrastructure, Atlantic.Net attracts customers by offering a partnership model built on freedom and modernization:

- **Flexible Business Associate Agreements (BAAs):** We do not force you into a “take-it-or-leave-it” contract. Unlike providers with rigid terms that fail to align with client needs, we work with you to customize a BAA that fits your organization’s specific risk profile and business requirements.
- **Flexible Bundles & Competitive Pricing:** We eliminate the burden of rigid service bundles that force you to pay for resources you don’t need. Our solutions are fully customizable and competitively priced, ensuring you only pay for the services that drive value for your business.
- **Access to Modern Technologies:** To prevent the competitive disadvantage of hosting on outdated operating systems, we provide a modern environment ready for advanced analytics and artificial intelligence (AI), ensuring your technical capabilities can grow alongside your business.

Atlantic.Net provides a responsive HIPAA hosting alternative built around your needs. Our customizable solutions are designed to align with your business objectives, leveraging three decades of expertise to help your company thrive.

## How to Get Started With Atlantic.Net

We make it easy for your healthcare or legal organization to get started with our HIPAA-compliant hosting. Our HIPAA hosting experts offer a free consultation to begin developing a tailored solution that addresses your unique business requirements and objectives. We will work with you to provide HIPAA-compliant solutions that support business growth and help you manage regulatory risk.

Our teams provide comprehensive migration support for companies transitioning from other providers to our platforms. Skilled technical staff ensure that all data and workloads are transferred securely. Our experts verify the migration’s success and can manage the hosted environment for maximum efficiency and ongoing compliance support.

[Contact us today](https://www.atlantic.net/about-us/corporate-contact/) to learn more about how our HIPAA-compliant hosting solutions can help your business.


---

# HIPAA-Compliant Hosting for Healthcare, Senior Care, and Mobile Providers

> URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-hosting-for-healthcare-senior-care-and-mobile-providers/ | Published: 2025-11-21 | Author: Dr. Assad Abbas

The healthcare industry now depends heavily on digital systems. Today, clinics, senior care facilities, and mobile providers manage patient records, scheduling, and telehealth through online platforms. As a result, these operations handle large volumes of sensitive medical data, making Health Insurance Portability and Accountability Act (HIPAA) compliance essential to protecting patient privacy.

The HIPAA defines the way healthcare information must be stored, accessed, and shared. Therefore, any organization that manages or transmits Protected Health Information (PHI) must follow its rules to avoid violations and penalties. Moreover, hosting providers that store this data on behalf of healthcare entities are subject to the same regulatory requirements.

In this context, [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) provides secure infrastructure designed to protect patient data and meet legal obligations. Such hosting environments include encryption, access control, and monitoring systems that ensure continuous compliance. Several reliable providers, including [Atlantic.Net](http://www.atlantic.net), [Microsoft Azure](https://azure.microsoft.com/en-us), [Amazon Web Services (AWS)](https://aws.amazon.com/), [Google Cloud Platform (GCP)](https://cloud.google.com/), and [Rackspace](https://www.rackspace.com/), offer compliant hosting solutions with varying features and levels of management.

Ultimately, the right choice depends on the organization’s needs, whether it is a hospital system, a senior care portal, or a mobile care application that supports field healthcare professionals.

## What Does HIPAA-Compliant Hosting Mean?

HIPAA-compliant hosting ensures that all stored and transmitted data follows strict security and privacy rules. This includes encryption, user access control, detailed audit logs, and secure backups.
 A compliant hosting setup should include:

- Data encryption at rest and in transit.
- User authentication and access control to prevent unauthorized entry.
- Audit trails to track every system activity.
- Disaster recovery and backup solutions.
- Physical security for data centers.

Hosting providers that offer HIPAA-compliant services act as Business Associates under the law. This means they must sign a [Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) that clearly defines their responsibilities in protecting PHI.

## Business Associate Agreements (BAAs)

A BAA is a legal document required for HIPAA compliance. It defines how a hosting provider will safeguard PHI and what happens in the event of a data breach. Without a signed BAA, healthcare data hosting cannot be considered compliant.
 A reliable BAA should cover:

- Data ownership and permitted use.
- Breach notification timelines.
- Subcontractor obligations.
- Data disposal procedures upon contract termination.

Atlantic.Net includes BAAs with all its HIPAA hosting services. This ensures transparency and shared accountability. Other providers, such as Microsoft Azure, AWS, GCP, and Rackspace, also offer BAAs, but their processes may differ in complexity and pricing.
 Before choosing a provider, organizations should review each BAA carefully. It protects both the healthcare business and the hosting partner from compliance risks.

## HIPAA Hosting for Senior Care Facilities

Senior care facilities manage sensitive information that qualifies as PHI. This includes residents’ medical histories, medication records, and emergency contacts. Many facilities also rely on online platforms for family communication and telehealth consultations. Because these activities involve PHI, compliance with HIPAA is mandatory.

A HIPAA-compliant hosting environment provides the technical safeguards required to secure digital records and maintain trust. Such environments prevent unauthorized access, reduce the risk of data breaches, and ensure that communication remains private.

Leading HIPAA hosting providers—such as Atlantic.Net, Microsoft Azure, AWS, and Google Cloud—offer infrastructure suitable for assisted living centers, retirement communities, and home nursing platforms. These environments are regularly audited and monitored to maintain compliance standards. Staff can securely upload resident updates, while administrators manage user access and maintain audit logs.

For instance, a senior care provider in Florida might deploy a WordPress-based resident portal hosted on a HIPAA-compliant platform. Families and staff could log in through encrypted connections, administrators could restrict access to medical files, and automatic backups would protect data integrity. This type of setup reduces administrative workload, enhances transparency, and ensures compliance with both HIPAA and state privacy regulations.

## HIPAA Hosting for Mobile Healthcare Providers

Mobile healthcare professionals, such as mobile phlebotomists, traveling nurses, and home lab services, often collect patient data outside traditional medical facilities. Their devices and custom apps store or transmit PHI, which makes secure hosting essential.

A HIPAA-compliant cloud hosting environment ensures that all mobile app data is protected from collection to storage. It allows field teams to upload test results, forms, and notes through encrypted connections to servers that meet HIPAA standards. This helps prevent unauthorized access and ensures patient data remains confidential.

Several hosting providers, including Atlantic.Net, AWS, Google Cloud Platform, and Rackspace, offer infrastructure suitable for mobile healthcare applications. These environments support encrypted data transmission, secure APIs, and U.S.-based data centers to maintain compliance. They also enable fast synchronization between field devices and hospital or clinic databases, helping reduce delays in patient updates.

For example, a mobile phlebotomy service in California could deploy a HIPAA-compliant cloud platform to host its collection app. Each technician logs in securely, uploads lab results, and the data is instantly sent to the central system without risking a compliance breach. For larger mobile networks, providers like Atlantic.net, AWS, GCP, and Rackspace offer scalable solutions, though they may require specialized configuration and IT management. Using a compliant hosting environment simplifies these technical requirements and ensures HIPAA standards are consistently maintained.

## Comparing HIPAA-Compliant Hosting Providers

Healthcare organizations have several options when selecting HIPAA-compliant hosting. Each provider offers different strengths, pricing models, and levels of support. Below is an overview of five well-known providers.

### 1. Atlantic.Net

Atlantic.Net has built a strong reputation in healthcare hosting. It focuses on clinics, senior care facilities, and mobile health services.

- Offers fully managed HIPAA hosting with BAAs included
- Provides ready-to-use WordPress and custom app environments
- U.S.-based data centers audited under SOC 2, SSAE 18, and HITECH
- Ideal for clinics, senior care homes, and mobile healthcare providers

### 2. Microsoft Azure

Microsoft Azure is a global cloud platform that provides HIPAA-eligible services under its compliance program. It offers extensive infrastructure and integration with enterprise tools, making it suitable for healthcare organizations of varying sizes.

- Provides HIPAA‑eligible services with a signed BAA
- Strong integration with Microsoft 365, Teams, and healthcare applications
- Scalable infrastructure with global data centers
- Best fit for healthcare systems seeking enterprise‑level cloud services and hybrid deployments
- Azure services require correct configuration to achieve full HIPAA compliance, as they are not compliant by default.

### 3. Amazon Web Services (AWS)

AWS is one of the largest cloud platforms in the world. It offers HIPAA-eligible services under its compliance program, but customers must configure them correctly.

- Provides HIPAA-eligible services with a signed BAA
- Highly flexible but requires complex setup and internal IT management
- Best suited for large organizations with dedicated technical teams

### 4. Google Cloud Platform (GCP)

Google Cloud provides HIPAA-eligible infrastructure with advanced analytics and AI tools. Research organizations and large healthcare systems often choose it.

- HIPAA-eligible infrastructure with strong AI and data analytics capabilities
- Requires advanced configuration and a signed BAA for compliance
- Suitable for hospitals, research labs, and organizations handling large datasets

### 5. Rackspace

Rackspace specializes in managed hosting and hybrid cloud solutions. It supports multiple environments, including AWS and Azure, while offering compliance management.

- Provides managed HIPAA hosting with hybrid cloud options
- Supports multiple environments, such as AWS and Azure
- Ideal for enterprises needing flexible and customized setups
- Customers must still configure workloads appropriately to maintain HIPAA compliance.

**Table 1: Comparison of different HIPAA-compliant hosting providers**

| **Provider** | **Introductory Note** | **Strengths** | **Best Fit** |
| --- | --- | --- | --- |
| **Atlantic.Net** | A healthcare-focused provider with audited U.S. data centers. | Fully managed HIPAA hosting, BAAs included, ready-to-use WordPress and custom app environments, and continuous monitoring. | Clinics, senior care homes, and mobile healthcare providers. |
| **Microsoft Azure** | A global cloud platform offering HIPAA‑eligible services. | Enterprise integration, scalable infrastructure, hybrid cloud support. | Healthcare systems seeking enterprise‑level cloud services. |
| **AWS** | One of the largest global cloud platforms. | HIPAA-eligible services, scalability, and a wide range of infrastructure options. | Large hospitals and enterprise healthcare systems with dedicated IT teams. |
| **Google Cloud (GCP)** | Provides HIPAA-eligible infrastructure with advanced analytics. | AI and data tools provide strong support for research and large-scale healthcare projects. | Research labs, hospitals, and-data-intensive healthcare organizations. |
| **Rackspace** | A managed hosting provider with hybrid cloud expertise. | Supports AWS, Azure, and private cloud environments, with strong technical support. | Enterprises needing flexible hybrid setups |

## WordPress and App Hosting Under HIPAA

WordPress is a common choice for healthcare and senior care websites because it is easy to manage and flexible enough to meet diverse needs. Clinics and care facilities often use it for patient portals, scheduling, and communication. However, WordPress by itself is not HIPAA-compliant. Compliance depends on the hosting environment and ongoing maintenance.

A secure HIPAA setup should include:

- Encrypted databases and backups
- SSL/TLS certificates for secure connections
- Restricted administrative access
- Verified plugins with regular updates

Several hosting providers offer HIPAA-ready WordPress environments that include these safeguards. This enables healthcare organizations to launch secure portals without complex technical steps. In addition to WordPress, compliant hosting also supports custom healthcare applications such as telehealth platforms and senior care management tools. These environments are designed with encrypted APIs, protected user data, and monitoring features to ensure compliance.

Atlantic.Net, along with other HIPAA hosting providers, delivers pre-configured solutions for WordPress and custom apps. This enables healthcare teams to focus on patient care while relying on a secure infrastructure to ensure compliance.

## State-Level Use Cases for HIPAA Hosting

Healthcare providers across different states face unique compliance needs, and HIPAA‑compliant hosting plays a vital role in meeting them.
 In Florida, clinics and assisted living centers often rely on secure hosting to manage telehealth services, patient scheduling, and family portals. Hosting within local data centers helps reduce latency and supports compliance with both HIPAA and state privacy requirements.

In Texas, dental practices depend on compliant cloud environments to store imaging data and operate patient communication portals. These systems protect sensitive files while maintaining reliable performance for daily operations.

California presents another dimension, where mobile healthcare startups such as phlebotomy and home testing services must comply not only with HIPAA but also with the California Consumer Privacy Act (CCPA). CCPA does not require data to be hosted within state borders; however, in-state hosting may improve performance.
 Together, these examples show how HIPAA hosting adapts to regional demands, supporting healthcare providers of different sizes and specialties as they secure patient information and maintain trust.

## Final Thoughts

HIPAA-compliant hosting is essential for healthcare organizations, senior care facilities, and mobile healthcare providers. Because these organizations handle sensitive patient data, secure storage, safe transmission, and proper management are mandatory.

By choosing the right hosting provider, organizations can ensure HIPAA compliance while also benefiting from robust infrastructure, BAAs, and support for WordPress or custom applications. For instance, senior care facilities can securely manage resident portals and telehealth communications, while mobile providers can safely collect and transmit patient data from the field.

Choosing a HIPAA-compliant hosting solution helps reduce administrative work, lowers the risk of data breaches, and protects patient trust. In addition, investing in compliant hosting is not only about following legal rules. It also strengthens service reliability and creates a safer environment for healthcare providers and the patients they serve.


---

# Why EMR Vendors Are Choosing Specialized Providers

> URL: https://www.atlantic.net/hipaa-compliant-hosting/why-emr-vendors-are-choosing-specialized-providers/ | Published: 2025-11-21 | Updated: 2025-11-24 | Author: Dr. Tehseen Zia

Organizations in healthcare and education rely heavily on Windows-native applications and SQL Server to manage everything from student records to sensitive patient information. Vendors who build and maintain these systems need secure, stable environments that support their clients without creating unnecessary operational burden on their teams. Many start on large public cloud platforms for their flexibility, but as their applications grow, they often face rising costs, stricter compliance demands, and increasingly complex security needs.

In recent years, many [Electronic Medical Record (EMR)](https://www.oracle.com/health/electronic-medical-record-emr/) vendors and healthcare developers are shifting their Windows applications and SQL workloads to [Atlantic.Net](https://www.atlantic.net/press-room/case-studies/). They want a hosting provider that understands [HIPAA regulations](https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html), offers predictable pricing for small and midsize workloads, and provides a simple, practical operating model for Windows-focused development teams. In this article, we explore why EMR vendors are increasingly turning to specialized hosting providers.

## What Healthcare Software Vendors Actually Need

For a modern EMR vendor, the core business is software, not infrastructure management. Their expertise lies in creating applications that improve patient care, streamline clinic workflows, and ensure data is available to doctors. However, as these vendors grow, they often face significant operational hurdles when using large, general-purpose cloud platforms.

The primary challenge is not just “hosting,” but “[compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/).” HIPAA compliance requires continuous effort to meet requirements such as logical isolation and access controls, maintaining audit logging and retention, and configuring appropriate security controls. Vendors handling PHI for covered entities must comply with HIPAA and sign a business associate agreement (BAA). Many university counseling centers are governed by FERPA unless operating as HIPAA-covered clinics. They also need a clear and documented security posture for each deployment. These demands pull engineers away from improving the product.

Many EMR systems still rely on Windows-native interfaces or legacy frameworks because they remain familiar and reliable for users in clinics, counseling centers, and academic institutions. These vendors need hosting environments that support multiple versions of Windows and SQL Server without forcing major changes to their applications. Long-term stability and backward compatibility are essential, as they cannot afford to constantly redesign their core application stack.

Cost also becomes a significant factor. While EMR workloads are typically predictable and do not require [elastic scaling](https://www.geeksforgeeks.org/cloud-computing/scalability-and-elasticity-in-cloud-computing/), running them is still expensive for smaller vendors. In addition, healthcare applications have strict security requirements, and EMR vendors must provide their support staff and developers with controlled access to client databases for maintenance and troubleshooting. This access must be secure, logged, and, most importantly, not expose the database to the public internet. This is where specialized access methods, like VPNs, bastion/jump hosts with MFA, or SSH tunneling, become critical.

Configuring secure access in a large, multi-tenant environment can be complex and risky if not handled by experts. Additionally, the end-users often demand smooth integration including single sign-on (SSO), so their staff can use their existing hospital or university credentials to log in. This requires deep and secure integration with systems like Active Directory (AD) and identity federation standards (e.g., SAML 2.0 or OIDC), which is much simpler when the hosting partner understands these specific enterprise requirements.

## How Atlantic.Net Addresses These Requirements

Atlantic.Net offers a HIPAA-compliant hosting [platform](https://www.atlantic.net/hipaa-compliant-hosting/) specifically designed for healthcare applications. Its virtual machines support both modern and legacy versions of Windows Server, which give EMR vendors the flexibility to run a wide range of application architectures. Every environment is backed by a formal business associate agreement (BAA), and the infrastructure includes encryption, network isolation, access controls, and audit logging and reporting. Compliance remains a shared responsibility between Atlantic.Net and the vendor. This setup enables healthcare developers to focus on their applications rather than managing infrastructure.

A key advantage Atlantic.Net offers is the option for dedicated or strongly isolated per-client hosting. Rather than running all clients in shared environments, each customer can receive isolated resources adapted to their needs. This approach supports HIPAA safeguard requirements and gives EMR vendors confidence when addressing data security for clinics or universities.

Developers often appreciate the simplicity of using SSH tunneling, VPNs, or a bastion/jump host with MFA for secure access to SQL Server databases. This approach enables teams to work without exposing public ports or changing the core design of their applications. They can interact with the database for support, reporting, or troubleshooting, all while keeping the system protected behind a secure layer.

[SSO integration](https://www.atlantic.net/managed-services/multi-factor-authentication-examples/) is another area where Atlantic.Net provides practical flexibility. It supports traditional Active Directory (AD) setups for teams using domain-based authentication, as well as federated identity systems (e.g., SAML 2.0 or OIDC) for organizations that prefer cloud-based identity providers. This flexibility allows EMR vendors to accommodate clients with varying access requirements without enforcing a single identity model across all deployments.

The [partnership model](https://www.atlantic.net/partners/) is what many vendors appreciate most. Atlantic.Net acts as a hosting backbone for software companies that do not want to become infrastructure providers. Rather than building their own data centers or managing a complex cloud environment, these vendors rely on Atlantic.Net to handle the underlying environment. This approach allows them to focus on customer relationships, product development, and client onboarding. It reduces operational friction and provides their teams with stability and confidence.

## Two Real-World Case Studies

To better understand why vendors choose specialized providers, let’s look at two real-world case studies from Atlantic.Net. The first example involves an EMR vendor that supports over 1,500 university counseling centers. The team needed a hosting environment where SQL Server databases could be deployed quickly and securely for each institution. Their clients required strong data isolation, straightforward access, and reliable performance during peak academic periods. After consulting with Atlantic.Net, the vendor implemented a model where each university received its own dedicated SQL environment with no public endpoints. SSH tunneling gave the development team secure access for support, and the built-in HIPAA-eligible design with a signed BAA and required safeguards helped them meet their contractual obligations without restructuring their application. This approach enabled the vendor to maintain its familiar Windows-native architecture while delivering an improved experience to new customers.

Another example involves a healthcare app team who hosted their Windows-native application and SQL Server database on Azure. As their customer base grew, the team wanted more control over compliance requirements and a more predictable cost structure. They also needed secure database access without exposing public endpoints. Atlantic.Net provided a hosting environment where their Windows application ran without modification, and their SQL Server database ran in a private network with no public endpoints. The migration process required no major changes to the codebase, and the team quickly established a documented compliance posture backed by a signed BAA and concrete controls (encryption in transit/at rest, logging, backups). This stability enabled them to onboard clinics more efficiently and develop a stronger long-term roadmap.

These cases show that healthcare developers prefer hosting providers that provide clarity, reliability, and hands-on support. They want to grow without redesigning their infrastructure at every stage. They appreciate it when the hosting environment matches the practical needs of their applications. Atlantic.Net continues to attract these vendors because it provides these strengths in a simple and accessible way. These real-world examples illustrate a broader shift in how healthcare vendors approach their infrastructure decisions.

## The Bottom Line

Electronic Medical Record (EMR/EHR) vendors, healthcare startups, and educational institutions are realizing the strategic value of specialization. When your entire business depends on the trust and security of protected health information, your infrastructure provider must be more than just a utility. They must serve as an extension of your team, one that understands the unique demands of your Windows Server and SQL Server–based applications.

For teams building Windows applications or handling healthcare data, it’s important to choose a secure, HIPAA-eligible (with a signed BAA), and developer-friendly environment rather than relying on a one-size-fits-all model. This focused approach allows EMR vendors to shift their attention from infrastructure management to developing software that enhances patient care.


---

# Bare Metal, Dedicated Cloud Hosts, and Dedicated Servers – What Is the Difference in 2026?

> URL: https://www.atlantic.net/dedicated-server-hosting/bare-metal-dedicated-cloud-hosts-and-dedicated-servers-what-is-the-difference/ | Published: 2025-11-22 | Updated: 2026-05-04 | Author: Robert Agar

## **Bare Metal Servers vs Dedicated Servers and Cloud Hosts:**

Businesses looking to maximize the performance of their websites and eCommerce platforms have a choice between several solutions. The type of system that works best for an organization depends on factors like the market sector in which the business operates, the volume of daily transactions, and the effects of seasonal fluctuations on capacity demands.

The three major options available from public cloud service providers (CSPs) for businesses searching for optimal performance and availability are a bare metal solution, dedicated cloud hosts, or dedicated physical servers. While these alternatives may seem very similar, they are not the same and each presents advantages and disadvantages in certain usage scenarios.

In this article, we will break down the differences in these three solutions to help identify which one best suits your unique business requirements. Let’s start with a discussion of each hosting option to identify their strengths and potential weaknesses.

![](https://www.atlantic.net/wp-content/uploads/2023/03/bare-metal-dedicated-cloud-hosts-and-dedicated-servers.jpg)

## What Is a Dedicated Server?

A dedicated server is a remotely located physical server that does not employ virtualization technology. The server’s performance and storage capabilities are limited by the hardware and its associated infrastructure. Dedicated servers are single-tenant entities where the machine is not shared with other customers.

[Dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) do not have a hypervisor pre-installed and enable users to exert full control over how the server and its infrastructure are configured. This level of control allows customers to install any operating system they choose without relying on the selected offerings of a virtualized environment. Hardware and software resources can be optimized to manage specific workloads and large volumes of data.

### Advantages of dedicated servers

Using dedicated servers provides these benefits:

- Enhanced processing power suitable for substantial workloads.
- Full control over the operating system and application software.
- Consistent disk and network performance.
- Users have root access to the server.
- Improved quality of service by eliminating resource spikes.
- Traditional billing plans for planning and budgeting.
- Physical isolation (which can be important for security and regulatory compliance).

### Disadvantages of dedicated servers

Some things to look out for when considering dedicated servers are:

- More expensive than virtualized cloud hosting options.
- There could be delays in provisioning given supply chain constraints.
- Additional technical expertise is required by the customer.
- Providers may use lesser-quality or outdated hardware.

## What Is a Bare Metal Server?

Bare metal servers are dedicated servers that are delivered to a customer using a different method by their cloud provider. These servers are also sometimes referred to as managed dedicated servers. In some ways, bare metal servers can be seen as a hybrid between dedicated servers and cloud hosts.

As with dedicated servers, a bare metal server is not shared with multiple tenants. Its role is to run dedicated services for a single customer. Cloud vendors carefully select the components that go into their bare metal offerings, which typically results in enhanced performance and reliability. In some cases, customers can choose to deploy specific components that fit the machine’s intended workload. Reputable providers will optimize the server to address specific use cases and business requirements.

[Bare metal servers](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) can be rented on an hourly or monthly subscription basis from a cloud provider, eliminating concerns over a long-term commitment to a dedicated server solution. In this way, they are like inexpensive cloud hosting options but deliver greater control, performance, and flexibility.

### Advantages of bare metal servers

Benefits of using bare metal dedicated servers include:

- Enhanced processing power for data and processing-intensive workloads.
- Faster provisioning when compared to dedicated servers.
- Flexible hardware choices range from inexpensive to cutting-edge components.
- Managed by the cloud service provider.
- Users have root access to the server.
- Full control over operating system and application software.
- Consistent disk and network performance.
- Flexible billing options that can result in substantial savings over dedicated servers.
- Improved quality of service by the elimination of resource spikes.
- Physical isolation for enhanced security and regulatory compliance.

### Disadvantages of bare metal servers

Bare metal servers have similar disadvantages to dedicated servers including:

- More expensive than dedicated servers of virtualized cloud hosting options.
- Additional technical expertise is required by the customer.

## What Is a Dedicated Cloud Host?

A [dedicated cloud host](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) is a single-tenant cloud infrastructure that serves as an isolated public cloud. Dedicated clouds fall into the category of infrastructure as a service (IaaS) solution and provide organizations with flexibility and performance as well as features not found in dedicated and bare metal options.

This hosting model provides customers with a dedicated cloud node connected to the Internet. The customer has more control than in a shared cloud hosting environment and can deploy the provisioned resources however they see fit. Through vendor-supplied automation and software tools, the dedicated cloud host can be turned into multiple cloud servers.

Though the cloud host is dedicated to a single tenant, the underlying physical hardware is still shared with other customers. This implies that there are limitations regarding the scalability of the system which are dependent on resource availability. The isolated nature of a dedicated cloud host may be sufficient for addressing concerns over security and privacy as it pertains to regulatory compliance.

### Advantages of dedicated cloud hosts

The benefits of going with a dedicated cloud hosting solution include:

- Less expensive than dedicated or bare metal servers.
- Quickly provisioned by a cloud provider.
- Security and development tools are provided by the cloud vendor.
- Flexible licensing terms are usually available.
- Can be used to create multiple cloud servers.
- Computing resources can be customized to meet business requirements.

### Disadvantages of dedicated cloud hosts

Customers considering dedicated cloud hosts should keep these points in mind:

- Potential resource limitations.
- Lesser performance than bare metal or dedicated servers.

## Choosing the Right Hosting Option for Your Business

The three [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) options we discussed all provide benefits and some disadvantages. They can all successfully address the web hosting needs of a business or organization under certain conditions. Answering the following questions should provide an indication of which choice is appropriate for your company.

- **What are the business uses of the website?** –  If your business does not need the higher performance of a dedicated or bare metal server, a dedicated cloud host can be an economical choice. On the other hand, if your business relies on the performance of mission-critical web applications, bare metal or dedicated servers should be strongly considered. The price difference will often be repaid with a more responsive and reliable website.
- **What are the vendor’s subscription options?** – Most reputable cloud vendors offer various subscription plans tailored to the needs of their customers. If you need high performance for a limited time, a bare metal server might be a better choice than a dedicated server with a long-term contract.
- **What features are included?** – The feature set available with different hosting options varies widely from vendor to vendor. Make sure the hosting option you select offers the features and flexibility your business requires.
- **Are there uptime and reliability guarantees?** – Mission-critical websites need to be hosted by providers willing to enter into service level agreements (SLAs) that guarantee system performance and availability.

The answers to these questions should give you a good sense of which type of hosting option is best for your business. Don’t make a selection without considering if the alternatives can address your business objectives more effectively and efficiently. Choosing between bare metal, dedicated cloud, and traditional dedicated servers depends on your needs—performance, compliance, and location. If you’re in healthcare or finance, bare metal is a great fit for strict standards like [HIPAA Compliance](https://www.atlantic.net/hipaa-compliant-hosting/)  and PCI Compliance. If you are still curious about cloud security, or If you like to learn more about cloud security, you can read more about [how secure is the cloud](https://www.atlantic.net/hipaa-compliant-hosting/how-secure-is-the-cloud/). If you are still comparing options, this [guide](https://www.atlantic.net/dedicated-server-hosting/optimizing-costs-in-the-cloud-vms-vs-vps-vs-bare-metal/) further breaks the comparison.

**Atlantic.Net Can Help!**

If you’re exploring hosting options but aren’t sure which solution fits your organization best, Atlantic.Net is here to help! Reach out to us at **[sales@atlantic.net](mailto:sales@atlantic.net) or give us a call at 866-618-DATA**. Our team will be happy to design a customized solution tailored to your needs.

**Related Guides:**

- [HIPAA Compliant Hosting Solutions](https://www.atlantic.net/hipaa-compliant-hosting/)
- [PCI-Compliant Hosting Solutions](https://www.atlantic.net/pci-compliant-hosting/)
- [What Are Managed Services?](https://www.atlantic.net/managed-services/what-are-managed-services/)

**Related Products:**

- [Atlantic.Net Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/)
- [Atlantic.Net HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)
- [Atlantic.Net GPU Hosting](https://www.atlantic.net/gpu-server-hosting/)


---

# Top 10 Considerations for a HIPAA-Compliant Database Complete HIPAA Compliant Database Guide

> URL: https://www.atlantic.net/hipaa-compliant-hosting/top-10-considerations-for-a-hipaa-compliant-database/ | Published: 2025-11-22 | Updated: 2026-07-24 | Author: Kent Roberts

**Updated: July 22, 2026**

A database is HIPAA-compliant when the electronic Protected Health Information (ePHI) inside it is encrypted at rest and in transit, reachable only through access controls tied to unique named accounts, recorded in audit logs showing who read or changed what, and running on infrastructure covered by a signed HIPAA Business Associate Agreement (BAA). No database product ships in that state. Relational databases such as MySQL, PostgreSQL, and SQL Server give you the controls. What makes a database HIPAA-compliant is how you configure it, how you monitor it, and how you evidence that work to an auditor.

Being handed responsibility for a HIPAA-compliant database is a lot to absorb, and the temptation is to shop for a product that advertises itself as compliant. Healthcare teams arrive at the same short list either way, because HIPAA requirements apply whichever engine you pick.

## **The 10 Considerations at a Glance**

| **#** | **Consideration** | **What It Means in Practice** | **HIPAA Rule It Maps To** |
| --- | --- | --- | --- |
| **1** | Understand what HIPAA is | Know which parts of HIPAA govern patient data and ePHI | Privacy Rule and Security Rule, Title II |
| **2** | Know the core tools | Use encryption, firewalls, electronic auditing, and independent audits | 45 CFR § 164.306(a) |
| **3** | Train your staff | Train everyone who handles ePHI and enforce sanctions for policy breaches | Administrative safeguards, 45 CFR § 164.308(a)(5) |
| **4** | Examine technical and physical safeguards | Review software controls, hosting controls, and data center protections | Technical safeguards, 45 CFR § 164.312; physical safeguards, 45 CFR § 164.310 |
| **5** | Limit access to applications and data | Use unique logins, role-based access controls, and MFA on administrative paths | 45 CFR § 164.312(a)(1), § 164.312(d), and § 164.502(b) |
| **6** | Set up data usage controls | Restrict ePHI exports and classify sensitive data | 45 CFR § 164.308(a)(4) and § 164.310(d)(1) |
| **7** | Encrypt your databases | Encrypt data at rest and in transit to support HHS safe harbor expectations | 45 CFR § 164.312(a)(2)(iv) and § 164.312(e)(2)(ii) |
| **8** | Monitor use and create logs | Record and review access activity so incidents can be reconstructed | 45 CFR § 164.312(b) and § 164.308(a)(1)(ii)(D) |
| **9** | Decide whether to use an outside party | Confirm whether any provider handling ePHI is a business associate and requires a BAA | 45 CFR § 164.308(b)(1) and § 164.314(a) |
| **10** | Choose a partner with HIPAA experience | Select a host whose audit scope, safeguards, and compliance documentation can be reviewed. | Risk analysis, 45 CFR § 164.308(a)(1)(ii)(A), and evaluation, § 164.308(a)(8) |

The[Health Insurance Portability and Accountability Act (HIPAA)](https://www.hhs.gov/hipaa/for-professionals/index.html) classifies the encryption specifications in row 7 as addressable, not required. The Department of Health and Human Services is clear that addressable “does not mean that an implementation specification is optional.” You implement it, or you document why an alternative achieves the same purpose, and that reasoning belongs in your risk assessments. A Security Rule overhaul proposed in January 2025 would make encryption and multi-factor authentication mandatory, and OCR states that the current rule remains in effect while that rulemaking proceeds. Treating encryption as optional is a poor bet under either version.

## **What Is a Database?**

The two most widely deployed engines in healthcare systems are MySQL and SQL Server, with PostgreSQL now common in newer patient portals and medical SaaS platforms. Healthcare organizations run patient portals, billing, and scheduling on the same engines, so one database system often holds clinical records and ordinary operational data side by side.

### **What Is MySQL?**

MySQL is an Oracle-owned open-source relational database, usually run on Red Hat Enterprise Linux, Rocky Linux, or Ubuntu. Current releases support[InnoDB encryption for data at rest](https://dev.mysql.com/doc/refman/8.4/en/innodb-data-encryption.html) at the tablespace level, the feature that matters most for HIPAA work.

### **What Is MS-SQL?**

MS-SQL, also known as Microsoft SQL Server, is the long-standing choice for Windows Server environments. Microsoft has supported[SQL Server on Linux](https://learn.microsoft.com/en-us/sql/linux/install-upgrade/setup?view=sql-server-ver17) since 2017, and SQL Server 2025 runs on Red Hat Enterprise Linux 9 and 10 and Ubuntu 22.04 and 24.04.

### **Securing a Database for HIPAA Compliance**

Traditional databases have no built-in way to identify which columns hold sensitive patient data. Hence, nothing warns you when a support ticket table starts collecting diagnoses, and the chance of ePHI landing somewhere unplanned is high. Our ten considerations cover how healthcare organizations secure databases holding ePHI, and what a HIPAA-compliant database needs across the physical, technical, and administrative safeguards of[HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/).

![](https://www.atlantic.net/wp-content/uploads/2018/11/HIPAA_Compliant_File_Storage_Understand_what_HIPAA_is.png)

## 1 – **Understand What HIPAA Is**

Congress passed the Health Insurance Portability and Accountability Act in 1996. The law is wide-ranging, covering:

- portability of health insurance coverage when US employees change jobs;
- fraud and abuse prevention in the healthcare industry;
- standards for healthcare data used in billing; and
- safeguarding health data and maintaining its privacy.

That fourth point governs a database, through the Privacy Rule and the[Security Rule](https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html) of HIPAA Title II. Work out which side of the line you sit on first, because it sets your HIPAA obligations: covered entity or business associate. Healthcare providers, health plans, and clearinghouses transmitting individually identifiable health information electronically are covered entities, and the vendors they hand ePHI to are business associates bound by[business associate agreements](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/). NIST’s[SP 800-66 Revision 2](https://csrc.nist.gov/pubs/sp/800/66/r2/final), published in February 2024, maps each requirement to concrete controls.

![](https://www.atlantic.net/wp-content/uploads/2018/11/HIPAA_Compliant_File Storage_2Know_core_tools_for_protecting_a_HIPAA_compliant_database.png)

## 2 – **Know the Core Tools for Protecting a HIPAA-Compliant Database**

Four tools protect data in a[HIPAA-compliant database](https://www.atlantic.net/hipaa-compliant-hosting/): encryption, firewalls, electronic auditing systems, and third-party audits. Most healthcare organizations already own all four somewhere, and the gap is usually that none were ever pointed at the database.

Encryption ensures only authorized users can read sensitive information, whether it sits in stored data or in transmission. Firewalls block illegitimate network access, and electronic auditing platforms require login credentials and produce audit logs of everything each individual does. Third-party audits bring in someone who works on HIPAA compliance full time, surfacing weaknesses your own healthcare teams have stopped seeing.

![](https://www.atlantic.net/wp-content/uploads/2018/11/HIPAA_Compliant_File_Storage_Train_ your_staff.png)

## 3 – **Train Your Staff**

Data security is maintained through your staff as much as your technology. The[2026 Verizon Data Breach Investigations Report healthcare snapshot](https://www.verizon.com/business/resources/reports/2026-dbir-healthcare-snapshot.pdf) found the human element present in 54% of healthcare data breaches, with internal actors involved in 19%. Miscellaneous errors have appeared in the top three healthcare breach patterns in every Verizon report from 2014 through 2026.

The errors are mundane: misdelivery, loss (frequently unencrypted devices and portable media), and misconfiguration such as exposing a data store to the internet. Training the people who handle protected health information (PHI) stops those from becoming compliance violations and reportable breaches, and 45 CFR 164.308(a)(5) requires a security awareness and training program for every workforce member, management included. Auditors routinely ask for the attendance records, so keep them with your HIPAA compliance evidence.

![](https://www.atlantic.net/wp-content/uploads/2021/08/technical-safeguards_1.png)

## 4 – **Examine Your Infrastructure for Technical and Physical Safeguards**

Whether you run your own data center or use a[HIPAA-compliant server hosting](https://www.atlantic.net/hipaa-compliant-hosting/) provider, the technical safeguards and the physical controls both have to be in place, and the risk assessments at 45 CFR 164.308(a)(1)(ii)(A) tell you where the gaps sit.

Technical safeguards secure electronic data. The security measures 45 CFR 164.312 expects are data integrity controls, audit controls, unique user identification, authentication, and encryption and decryption. The same section requires an emergency access procedure, defining how clinicians reach patient data when the primary access path fails.

Physical safeguards govern in-person contact with the equipment holding ePHI: controlled access to the building and the cabinet,[data center physical security](https://www.atlantic.net/hipaa-compliant-hosting/data-center-physical-security-hipaa-compliance/), and disposal. A failed drive tests this, because 45 CFR 164.310(d) requires a documented procedure for how it leaves the building and how the ePHI on it is destroyed first.

![](https://www.atlantic.net/wp-content/uploads/2018/11/HIPAA_Compliant_File_Storage_5Limit_access_to_applications_and_data.png)

## 5 – L**imit Access to Applications and Data**

Robust access controls on healthcare applications and patient data improve security more reliably than most other single measures. Limit patient record access to the employees who need it, which is the Privacy Rule’s minimum necessary standard at 45 CFR 164.502(b) applied to a schema. Patient portals add a second population of accounts, so the same logic covers patients reaching their own records.

In database terms, that means named accounts instead of a shared application login, role-based access controls granting read or write per table or per view, and no direct production data access for developers. Put[multi-factor authentication](https://www.atlantic.net/managed-services/multi-factor-authentication/) in front of the administrative path, so an attacker holding a valid password still cannot reach the data.

Write the access controls down as well as configuring them. An auditor will ask which authorized users can manage patient data, who approved each one, and how fast access is removed when somebody changes role. Controlled access is easy to evidence when the grant list and the approval trail sit together.

![](https://www.atlantic.net/wp-content/uploads/2018/11/HIPAA_Compliant_File_Storage6–Set_up_data_usage_controls.png)

## 6 – **Set Up Data Usage Controls**

Data usage controls extend data protection past monitoring access to blocking malicious activity as it emerges. They stop the actions that move sensitive data out of the environment: printing, copying files onto external drives, unauthorized email, and uploads to third-party services.

None of that works until you know where the ePHI is. Use data discovery and classification to tag the columns and tables holding patient data, then attach secure data-handling rules to the tags. Classification also marks the operational data that can stay outside the strictest rules. This is the step teams skip, and it is why an export blocker so often misses the reporting replica.

![](https://www.atlantic.net/wp-content/uploads/2018/11/HIPAA_Compliant_File_Storage7–Encrypt_your_databases.png)

## 7 – **Encrypt Your Databases**

Encrypting ePHI converts the data into an encoded form readable only with a decryption key. Every covered entity must protect data it creates, receives, maintains, or transmits, and[encryption](https://www.atlantic.net/hipaa-compliant-hosting/encryption-for-hipaa-compliance/) is the standard way to do it.

HHS ties encryption to breach reporting. Its guidance on rendering unsecured PHI unusable treats healthcare data at rest as protected when encrypted to[NIST SP 800-111](https://www.hhs.gov/hipaa/for-professionals/breach-notification/guidance/index.html), and data in motion when encrypted to NIST SP 800-52, 800-77, or 800-113, or another FIPS 140-2 validated method. Encrypted data lost or stolen with the encryption keys held separately does not carry the same notification obligations as plaintext. Those encryption requirements cover backups and replicas too, and a nightly dump written to an unencrypted volume undoes the rest of the work.

Microsoft SQL Server offers Transparent Data Encryption, Always Encrypted, row-level security, and data masking. MySQL encrypts InnoDB tablespaces through a keyring plugin. PostgreSQL handles column-level encryption through pgcrypto, with full-volume encryption at the storage layer, which on Atlantic.Net block storage means LUKS. Enable Transport Layer Security (TLS) 1.2 or higher on the client connection, because encryption of data at rest does nothing for sensitive information traveling in the clear. Map the encryption requirements to the edition you are licensing, because the feature set differs by edition and release.

![](https://www.atlantic.net/wp-content/uploads/2018/11/HIPAA_Compliant_File_Storage8–Monitor_use_of_the_database_and_create_logs.png)

## 8 – **Monitor Use of the Database and Create Logs**

Comprehensive audit logging in a HIPAA-compliant database records every access to ePHI: the accounts, devices, times, applications, and specific records involved. During an audit, those logs support compliance by showing that access review is happening. After a security event, they let you find the point of entry and scope the damage.

45 CFR 164.312(b) makes this a named requirement, mandating audit controls that record and examine activity in systems holding ePHI, and 164.308(a)(1)(ii)(D) requires regular review of those records, naming audit logs, access reports, and security incident tracking reports explicitly. Database-native tooling produces most of these audit logs: SQL Server Audit, the pgAudit extension for PostgreSQL, and the MySQL Enterprise Audit plugin. Most healthcare organizations ship the output to a separate collector the database administrator cannot edit, which also stops a busy database filling its own disk. Check your[HIPAA log retention requirements](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-log-retention-requirements/) before setting rotation.

![](https://www.atlantic.net/wp-content/uploads/2018/11/HIPAA_Compliant_File_Storage9–Decide_whether_you_want_to_use_an_outside_party.png)

## 9 – ** Decide Whether You Want to Use an Outside Party**

You can use your own data center or a hosting service, cloud or otherwise, to run your HIPAA-compliant database. Meeting HIPAA compliance standards is easier on[compliant infrastructure](https://www.atlantic.net/compliance-hosting/) built for the purpose by a provider that does this work continuously. Every vendor with a path to sensitive patient information needs to be under contract, so your business associate agreements have to cover the host, the backup provider, and any managed service in the chain. Healthcare organizations running their own data center underestimate the physical side, forgetting that a stolen drive or an unescorted visitor produces the same reportable breach.

### **Managed Database Services and the Shared-Responsibility Line**

Many healthcare organizations now reach for a managed database service instead of installing an engine themselves. Managed MySQL, managed PostgreSQL, and database-as-a-service offerings take patching, replication, and backup scheduling off your plate, a genuine operational efficiency gain for a small team. Compared with traditional databases you install and patch yourself, you trade host-level control for that. Amazon RDS is HIPAA-eligible for its SQL Server, MySQL, Oracle, PostgreSQL, Db2, and MariaDB engines, with Aurora and DynamoDB on the same list.

AWS states that eligibility is subject to the shared responsibility model and that customers must still configure the services consistently with HIPAA requirements, with a BAA executed before any ePHI lands on the platform. HHS is blunter: a cloud service provider that creates, receives, maintains, or transmits ePHI is a business associate, and that holds “even if the CSP processes or stores only encrypted ePHI and lacks an encryption key for the data.” A managed database provider secures the platform underneath, and that work does support HIPAA compliance, but it ends at the boundary of what the provider controls. Your schema design, your access controls, your audit logs, and your key management stay yours. Collect the business associate agreements for every layer of the stack, because a missing one is a finding on its own.

![](https://www.atlantic.net/wp-content/uploads/2018/11/HIPAA_Compliant_File_Storage10–Choose_a_partner_with_niche_HIPAA_expertise.png)

## 10 – **Choose a Partner With Niche HIPAA Experience**

Hosting plans vary widely in how much HIPAA experience sits behind them. Plenty of providers list features that support HIPAA compliance without holding an audit that covers them, so ask what the provider’s audit actually covers, and ask to see it. Ask too how they handle business associate agreements for each service you plan to use, and whether their own risk assessments are current.

Healthcare has been one of Atlantic.Net’s primary focuses for years.[HIPAA-compliant database hosting](https://www.atlantic.net/hipaa-compliant-hosting/) from Atlantic.Net runs in a secure environment: SOC 2 Type II and SOC 3 Type II audited, SSAE 18 attested, HIPAA and HITECH audited data centers, with a legally binding BAA included as standard. Fortress HIPAA plans start at 6 vCPU, 16 GB RAM, 200 GB SSD, and 10 TB of transfer, and include a managed FortiGate firewall, encrypted onsite and offsite daily backups, managed VPN access, multi-factor authentication,[intrusion detection and prevention](https://www.atlantic.net/managed-services/intrusion-detection-service/), bi-weekly vulnerability scanning, and a log management system that keeps audit logs traceable. Four hours of migration service are included, with additional hours at $160 per hour. Supported engines include MySQL, PostgreSQL, MongoDB, Redis, and SQL Server.

 

![HIPAA Database Checklist](https://www.atlantic.net/wp-content/uploads/2018/11/HIPAA_Compliant_File_Storage_HIPAA_Compliant Database_HIPAA-Compliant_Database.jpg)

 

---

## **Frequently Asked Questions**

### **What Audit Logging and Monitoring Capabilities Are Needed in a HIPAA Hosting Environment?**

You need audit controls that record and examine every access to ePHI, plus the documented review process you can show an auditor. 45 CFR 164.312(b) mandates the recording mechanism and 164.308(a)(1)(ii)(D) mandates the review. That means database audit logs (SQL Server Audit, pgAudit, MySQL Enterprise Audit), authentication logs, and firewall alerts, stored where the people being audited cannot modify them. HIPAA sets no explicit retention period, so healthcare organizations align the logs with the six-year documentation retention rule. Atlantic.Net HIPAA plans include log management with audit traceability and 24/7 SOC monitoring.

### **What Encryption Standards Are Required or Recommended for HIPAA-Compliant Hosting?**

The HIPAA Security Rule classifies encryption as addressable, meaning you implement it or document a reasonable alternative that achieves the same purpose. In practice, encrypt. HHS guidance points to NIST SP 800-111 at rest and NIST SP 800-52, 800-77, or 800-113 in motion, or any FIPS 140-2 validated method. AES-256 and TLS 1.2 or 1.3 are the working norms. Encrypt database files, backups, and replication traffic at rest and in transit, and store encryption keys separately in a managed key service or hardware security modules.

### **How Does Access Control Management Support HIPAA Compliance?**

Access controls support compliance by turning the Privacy Rule’s minimum necessary standard into something enforceable. 45 CFR 164.312(a) requires unique user identification, an emergency access procedure, and technical policies allowing only authorized persons or software to access ePHI; 164.312(d) requires you to verify a user is who they claim to be. Role-based access controls do the day-to-day work: a billing clerk sees the billing tables, a clinician sees the clinical record, and nobody uses a shared account. Multi-factor authentication, prompt de-provisioning, and periodic review of those access controls complete the picture.

### **How Does Disaster Recovery Planning Relate to HIPAA Hosting Requirements?**

Disaster recovery is a required part of HIPAA compliance. The contingency plan standard at 45 CFR 164.308(a)(7) makes a data backup plan, a disaster recovery plan, and an emergency mode operation plan all required implementation specifications for a database that means retrievable exact copies of ePHI, a rehearsed restore procedure, and a way to keep critical processes running while the primary environment is offline. Atlantic.Net includes encrypted daily backups on HIPAA plans and offers replication-based[DR hosting](https://www.atlantic.net/disaster-recovery/what-are-the-hipaa-compliant-online-data-backup-and-retention-requirements/) for tighter recovery objectives.

### **How to Choose HIPAA Hosting for EMR or EHR Systems?**

Start with what your EMR or EHR vendor supports, because the application dictates the operating system, database engine, and often the exact version. Patient portals attached to the EHR belong in the same scope. Then check that the provider signs a BAA covering every service the system touches, that the audit scope is inspectable, and that performance matches your clinician count and reporting load. Where several applications manage patient data on one server, confirm a single agreement covers all of them. Atlantic.Net publishes guidance on[HIPAA hosting for EMR and EHR systems](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-hosting-emr-ehr-systems/).

### **How Does Physical Data Center Security Factor Into HIPAA Compliance?**

Physical security is one of the three categories of security safeguards in HIPAA, so a HHIPAA-compliantdata center is a prerequisite. 45 CFR 164.310 requires facility access controls, workstation security policies, and device and media controls governing how hardware carrying ePHI enters and leaves the building in an audited facility, which means biometric and card-based entry, a man-trap vestibule, closed-circuit television, escorted visitor access, and documented drive destruction. Healthcare organizations running their own server room need the same controls and the same evidence. Atlantic.Net operates[HIPAA data centers](https://www.atlantic.net/hipaa-data-centers/) across eight regions, tested during the annual independent audit.

## **Put Your HIPAA-Compliant Database on Audited Infrastructure**

Atlantic.Net builds and operates the platform underneath databases for healthcare organizations, so your healthcare teams can concentrate on the schema, the application, and the access model. If you have a database that will hold protected health information (PHI) and you want the encryption, access controls, audit logging, and backup posture reviewed before it goes live,[contact the Atlantic.Net solutions team](https://www.atlantic.net/about-us/corporate-contact/). We will walk through your database engine and version, where the shared-responsibility line falls, and what our audit reports cover.

#### **Read More About HIPAA IT Compliance**

- [HIPAA IT Compliance Guide](https://www.atlantic.net/hipaa-data-centers/hipaa-compliant-it-infrastructure-guide/)
- [Best HIPAA Compliant Fax Service](https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-fax-services-in-2021/)
- [Best HIPAA Compliant Email Service](https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-email-service-in-2021/)
- [Best HIPAA Compliant VOIP Service](https://www.atlantic.net/hipaa-compliant-hosting/top-10-best-hipaa-compliant-voip-providers/)
- [What Is a BAA?](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/)
- [SSAE 16, SSAE 18, SOC 1, SOC 2: Why You Should Care](https://www.atlantic.net/hipaa-compliant-hosting/ssae-16-soc-1-soc2-care/)
- [Best Healthcare Software Development Companies](https://www.atlantic.net/hipaa-compliant-hosting/top-10-healthcare-software-development-companies/)
- [Best HIPAA Consulting Companies](https://www.atlantic.net/hipaa-compliant-hosting/top-10-hipaa-consulting-companies-in-2020/)
- [Is It HIPAA or HIPAA?](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-vs-hippa/)
- [HIPAA Hosting Checklist: Turning Requirements Into Production Scope](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-hosting-checklist-production-scope/)
- [Launching a PostgreSQL HIPAA SaaS Platform](https://www.atlantic.net/hipaa-compliant-hosting/postgresql-hipaa-saas-launch-plan/)

---


---

# Why Organizations Consider Moving from Azure to Atlantic.Net for HIPAA and SOC-Compliant Hosting

> URL: https://www.atlantic.net/hipaa-compliant-hosting/migrating-from-azure-to-managed-compliance-hosting/ | Published: 2025-11-27 | Updated: 2025-11-26 | Author: Richard Bailey

For years, hyperscale cloud providers like Microsoft Azure have been a common choice for organizations moving to the cloud, tempted by a wide-reaching global service and limitless scale.But for organizations handling sensitive data—especially in healthcare (HIPAA/HITECH), finance (SOC 2), and e-commerce (PCI)—that promise often comes with high costs, operational fragility, and high levels of complexity.

One of the problems with Hyperscale providers is that investing in a “do-it-all” platform means *you* can often end up doing it all yourself, especially when it comes to compliance hosting. Yes, the platform provided by Azure is very powerful, but it comes with a specific technical expertise requirement.This is where the conversation shifts, where organizations are increasingly moving from complex hyperscale environments to managed providers like Atlantic.Net. The reason is simple: they are trading in unpredictable, “do-it-yourself” compliance burden for a fully managed, audit-ready environment with transparent, predictable pricing.

## Azure Compliance Hosting

For organizations bound by HIPAA, SOC 2, or PCI regulations, Azure presents two significant hurdles: technical complexity and financial complexity.

### Technical Complexity

Microsoft has built Azure into a huge, reliable cloud platform, featuring over 200 services. However, one major issue is that you, the customer, is responsible for all the configuration, integration, and security. This is fine if you are a certified Azure Solutions Architect, but perhaps it’s more challenging for small and medium enterprises, considering the added costs.

#### Configuration Expertize

You are responsible for correctly configuring every virtual machine, storage account, firewall rule, and logging service to meet stringent audit standards.

- **For HIPAA:** It’s not enough to just use “HIPAA-eligible” services. You must manually configure Network Security Groups (NSGs) to segment ePHI data, implement Azure Key Vault for managing encryption keys, and set up Azure Monitor with Log Analytics workspaces to create an immutable audit trail of *all* access to protected data. A single misconfigured NSG rule (e.g., an “AllowAny” for RDP) or a gap in logging can breach HIPAA compliance.
- **For SOC 2:** An auditor will test you against the Trust Services Criteria (e.g., Security, Availability, Confidentiality). You must provide concrete evidence that your controls are working. In Azure, this means manually correlating logs from Microsoft Defender for Cloud, Azure Active Directory, and your application to *prove* you are monitoring for anomalies or managing vendor access. This is a full-time job.

#### Shared Responsibility

It’s easy to misunderstand Azure’s “shared responsibility” model. While Microsoft secures the physical data center, you are responsible for almost everything else.
 In a typical IaaS (Infrastructure-as-a-Service) model, you are solely responsible for:

- **Data:** Securing it, encrypting it, controlling access.
- **Application & Network:** Patching operating systems, managing firewalls (NSGs), and configuring secure VNet-to-VNet connectivity.
- **Access Management:** Implementing strong Multi-Factor Authentication (MFA) and ensuring principles of least privilege.

A compliance failure in any of these areas is *your* failure, not Microsoft’s.

### Billing Complexity

The second major pain point is cost. Azure’s pay-as-you-go model is flexible, but it often leads to financial unpredictability for high-compliance environments.

#### Unpredictable Egress & Transfer Fees

Were you planning on moving data to a disaster recovery site, sharing it with a partner, or even just downloading logs for analysis? It’s important to remember Egress charges. Egress (data-out) fees are hard to predict and can impact your monthly costs. Even data transfer between Azure regions for high availability can incur unexpected costs.

#### Configuration Sprawl

In a complex environment, it’s easy to spin up a resource (a premium SSD, a test VM, a public IP) for a temporary project and forget to decommission it. These “zombie assets” can drain your budget for months. Worse, choosing the wrong pricing tier (e.g., using “hot” storage for long-term archives) means you are constantly overpaying. Any easy way to fix this is to manage your infrastructure by code, but not everyone is a DevOps expert, and it’s easy for employees to do click-ops to test out new features.

#### Employee Costs

Managing a compliant Azure environment doesn’t just require an IT team; it may requires a team of Azure-certified specialists who are also experts in HIPAA or SOC 2 controls. This is a rare and expensive combination. The salary for a single senior cloud security engineer can easily exceed $150,000. For many organizations, this hidden “people cost” is far greater than the Azure bill itself.

## The Atlantic.Net Alternative: Compliant, Managed, and Predictable

Organizations are moving to Atlantic.Net because we offer a fundamentally different approach. Instead of handing you a box of parts, we deliver a fully assembled, audited, and compliant solution. With 30 years in the industry, our model is built on partnership, not just a platform.

### A Turnkey, Audit-Ready Environment

When you handle ePHI or financial data, “good enough” isn’t an option. Our solutions are not just “compliant-capable”; they are audited and certified.

- **SOC 2 & SOC 3:** Our data centers and hosting environments are SOC 2 Type II and SOC 3 Type II certified. This provides verified, third-party proof of our security controls and operational effectiveness, which you can use in your own audits.
- **HIPAA & HITECH:** We are fully HIPAA and HITECH audited. We understand the critical importance of protecting patient data and will sign a comprehensive Business Associate Agreement (BAA) with you—a non-negotiable for healthcare. Our BAA covers the managed services we provide, not just the physical hardware.
- **PCI-Compliant:** For e-commerce and financial applications, we provide a secure, PCI-compliant environment to protect cardholder data.

### True Managed Services—Not Just Support

This is the most significant difference. Instead of you managing the platform, we manage it *for you*. This is all included, not an expensive add-on. Our engineers become an extension of your team.
 This includes:

- **Fully Managed Firewalls & VPNs:** We design, configure, and manage your firewall rules and secure VPN access.
- **Intrusion Detection/Prevention (IDS/IPS):** We proactively monitor network traffic 24/7 for malicious activity and policy violations—a key requirement for SOC 2.
- **Encrypted Backups & Storage:** Your data is encrypted at rest and in transit, with secure, off-site backups managed by us to protect against data loss or ransomware.
- **24x7x365 Expert Support:** Our support isn’t a call center. You get 24/7 access to our U.S.-based engineers—the same people who manage our infrastructure—any time, day or night.

### Transparent, Predictable Pricing

Our pricing is simple. We work with you to design a solution and provide a clear, all-inclusive monthly quote. That’s it.

- **No Unexpected Fees:** We include generous data transfer.
- **No Confusing Tiers:** We use high-performance SSD storage by default.
- **No Bill Shock:** You get a predictable operational expense, making budgeting easy and eliminating the financial anxiety of the hyperscale model.

### At-a-Glance: Azure (DIY) vs. Atlantic.Net (Managed)

| **Compliance Task** | **Microsoft Azure (Do-It-Yourself)** | **Atlantic.Net (Fully Managed)** |
| --- | --- | --- |
| **HIPAA BAA** | **Provided.** Covers physical infrastructure and *some* services. You are responsible for the OS, network, and application layer. | **Provided.** A comprehensive BAA that covers the entire managed solution—infrastructure, network, and managed services. |
| **Firewall / NSGs** | **DIY:** You must design, configure, and constantly audit all Network Security Groups and Azure Firewall rules. | **Managed:** We design, configure, and manage your dedicated firewall rules based on your compliance needs. |
| **Audit Logging** | **DIY:** You must provision, configure, and pay for Log Analytics, Azure Monitor, and storage accounts to retain logs. | **Managed:** We manage centralized logging and provide the audit reports you need. |
| **Intrusion Detection** | **DIY:** You must license, deploy, and manage Microsoft Defender for Cloud or a third-party tool. | **Managed:** 24/7/365 Intrusion Detection (IDS) is **included** and monitored by our security team. |
| **Encrypted Backups** | **DIY:** You must configure Azure Backup, set policies, manage encryption keys, and test restores. | **Managed:** Secure, encrypted daily backups are **included** and managed by our team. |
| **Support** | Standard support is a ticketing system. Premium support costs **thousands per month extra**. | **24x7x365 U.S.-based engineer support** is **included** for all clients. |
| **Pricing Model** | **Variable:** Pay-as-you-go for 200+ services. Highly unpredictable. | **Fixed:** A single, predictable, all-inclusive monthly price. |

## Migrating to Atlantic.Net

We’ve migrated a number of complex, high-compliance workloads. Our process is designed to be seamless, secure, and low-friction, managed by our experts at every step.
 Best Migration Strategy:

1. **Discovery & Compliance Mapping:** Solution architects review your current environment, data, and application dependencies. Then they map your *exact* HIPAA, SOC 2, or PCI requirements to our audited controls.
2. **Architecting the Solution:** Design a dedicated, secure, and high-performance environment that mirrors or improves upon your current setup.
3. **Phased, Low-Downtime Migration:** Schedule the migration at your convenience. Using live replication tools, move your data and applications securely, minimizing or eliminating downtime.
4. **Validation & Go-Live:** Before the final cutover, test everything in a secure sandbox. Post-migration, validate all security controls, network policies, and backup jobs, and take initial compliance documentation for your records.

## Why These Clients Moved to Atlantic.Net

While client names are confidential, these scenarios reflect the common challenges that drive organizations to migrate into Atlantic.Net cloud.

### The Healthcare Tech Platform

A SaaS company provides a patient data management app for clinics. On a hyperscaler, their small development team spent nearly 30% of its time on infrastructure management and compliance documentation instead of building new features. They faced constant anxiety during audits, fearing a misconfigured logging rule.

- **By moving to Atlantic.Net:** They now operate on a fully managed, HIPAA-audited platform. Atlantic.Net handles the infrastructure, security monitoring, and backups. Their team is 100% focused on their product, and audits are now a simple “check-the-box” process using Atlantic.Net’s compliance reports.

### The Legal Tech Firm

A legal tech firm specializing in e-discovery needed a SOC 2-compliant environment. Their Cloud bill was a moving target, fluctuating by thousands each month based on unpredictable data transfers during discovery.

- **By moving to Atlantic.Net:** They secured a SOC 2-certified environment with a fixed, predictable monthly cost. With data transfer included, they can now quote projects to their law firm clients with confidence, knowing their own cloud costs are static.

### The E-commerce Business

A growing e-commerce company was preparing for its PCI audit on a big cloud. They realized their team lacked the specialized expertise to properly implement and document all the required network segmentation and access controls.

- **By moving to Atlantic.Net:** They migrated to a PCI-compliant managed environment. Atlantic.Net’s experts not only configured the solution but also provided the clear documentation needed to sail through their audit, saving them from the high cost of specialized consultants.

## Stop Managing Complexity. Start Focusing on Your Business.

Azure is a great platform that is a great fit for large enterprise customers and those who enjoy the Windows experience. However, there is a growing audience for whom Azure is perhaps too complicated and too large an environment for their specific needs.

For Many clients it is sometimes difficult to understand the true cost of cloud with a large provider prior to adopting some of its services, and once embedded in their systems, far too much time was spent worrying about being compliant. That is why many small and medium businesses are choosing companies like Atlantic.Net that have built a compliance-ready platform that can be consumed from day one.

For organizations that need watertight compliance without the operational overhead and financial risk, a managed provider is the clear-headed choice.
 Atlantic.Net offers a 30-year track record of stability, a robust global network of 8 data centers, and a clear, simple promise: We manage the cloud. We help you reach compliance. You focus on your business.

Ready to simplify your compliance? Contact our team today for a no-obligation consultation and see what a truly managed, audit-ready environment can do for you.

 


---

# Why Businesses Consider Migrating from IBM Cloud to Atlantic.Net

> URL: https://www.atlantic.net/managed-services/ibm-cloud-to-atlantic-net-migration/ | Published: 2025-11-28 | Updated: 2025-11-26 | Author: Robert Agar

Many companies move mission-critical environments to the cloud to gain flexibility, reduce costs, and streamline operations. Yet not every migration delivers on these goals. Some choose a provider based on brand familiarity and now face rising costs, complex tooling, and limited flexibility. This article examines why some organizations are reevaluating IBM Cloud and other providers, and what they gain by migrating to Atlantic.Net.

The cloud infrastructure is evolving, and many businesses are reevaluating their hosting providers. In some cases, companies have not enjoyed the anticipated advantages of the cloud for various reasons. They may have made their initial choice of provider based on factors such as name familiarity, without performing a comprehensive comparison of potential vendors. Company decision-makers can either continue with the limitations and issues they are experiencing with their current provider or search for a new solution that better addresses their business requirements and objectives.

This article examines the reasons businesses across many sectors consider migrating from the IBM Cloud and other providers to Atlantic.Net to improve performance, transparency, and fit.

## Common Pain Points With Cloud Providers

Organizations dissatisfied with their current cloud provider typically face common pain points. These issues can significantly affect their business and may prompt them to seek a new, more satisfactory hosting partner. The following pain points are often the reason a company looks to change its cloud provider.

### High Costs

The promise of cost savings is a major factor in many businesses deciding to migrate to the cloud. Providers may raise costs after the initial agreements expire, significantly disrupting an organization’s IT budget and eliminating the financial advantage of moving to the cloud. The vendor may have complicated pricing plans that do not reveal the actual costs of their services. A company may feel stuck because it does not want to deal with the complications of another migration.

Costs can quickly get out of hand for other reasons as well. The provider may increase data egress fees, making it more expensive to use corporate information efficiently. Companies that want to expand their cloud infrastructure may have to pay premium prices for services such as dedicated servers or cloud hosting. A business may wind up paying for underutilized resources if they are not managed effectively. These issues can result in budget overruns and friction between the finance and IT departments.

### Complex Management Interfaces

Teams must manage their resources efficiently to optimize cloud benefits. Users need an effective way to monitor usage to ensure they are maximizing their cloud investment. A comprehensive interface enables granular monitoring as well as activities such as easily spinning up VMs and scaling specific resources.

Customers may choose to switch cloud providers due to the complexity of management interfaces, which limit their ability to understand and optimize resource usage. Teams forced to use complex, unintuitive interfaces will not get the most out of their cloud environment. Organizations can experience lost productivity when users struggle with inefficient interfaces.

### Limited Server Configuration Flexibility

Companies may experience inflexibility from their provider when they want servers configured to address specific requirements or objectives. Many vendors offer a variety of server configurations, but limit the degree of customization available to meet customer needs. An organization may benefit from customized configurations to support innovative solutions or address evolving business requirements.

Lack of configuration flexibility can hurt a company’s competitiveness by forcing it to use an inferior platform for targeted computing needs. Teams will be hampered when attempting to work around server configuration issues. Decision-makers may be motivated to search for a new provider that offers the desired level of customization.

### Inconsistent Support for Legacy Systems

Businesses often migrate legacy systems to the cloud to reduce on-premises data center space requirements. In some cases, the migration involves rehosting the systems on cloud resources. However, refactoring the legacy environments, such as IBM i and AS/400 workloads, is typically a more effective long-term solution.

Not all cloud hosting providers have the requisite experience and skill sets needed to support the transition of legacy systems to a modern infrastructure. Substandard vendor support can increase the risk of outages or poor performance.

## Why Atlantic.Net Is a Preferred Alternative Cloud Provider

Atlantic.Net’s professional cloud services and solutions present companies with an attractive alternative when searching for a new hosting provider.  We have over 30 years of experience in cloud hosting, giving us the expertise to meet all your company’s needs. Businesses that are dissatisfied with their current provider are switching to Atlantic.Net for the following reasons.

### Customizable Dedicated Server and Cloud Hosting

Our technical team will tailor a customized solution that addresses all of your requirements. We offer dedicated servers and Cloud hosting services for businesses of all sizes. Your company can optimize its IT environment with a wide range of base server configurations, each customizable to your exact specifications.

Our dedicated servers can be equipped with cutting-edge GPUs to support advanced AI and ML applications. We also offer bare-metal (single-tenant) solutions for companies that require full control and isolation. Our experts will perform a free assessment of your existing environment to demonstrate the advantages of a truly customizable hosting solution. Clear, transparent pricing helps you stay within budget while improving your IT capabilities.

### Legacy System Support

We understand the importance of supporting your mission-critical legacy systems and workloads. While it is possible to lift-and-shift the environment to the cloud, businesses can benefit from modernizing with cloud-native solutions. Companies running IBM i or AS/400 systems should strongly consider refactoring to a modern cloud platform.

Our technical experts work with firms specializing in IBM i and AS/400 to transition workloads to modern cloud environments. We help you migrate to the cloud and provide comprehensive support after the transition. Your essential workloads will run more efficiently, enabling you to leverage modern resources to grow your business.

A case in point is our work with a technology firm in Mexico City that relied on an IBM i environment for essential applications. We developed a seamless migration path that enabled them to modernize their clients’ systems in the cloud without losing legacy compatibility. The company is prepared for future growth and no longer must support legacy, on-premises hardware.

### Global Reach

Atlantic.Net has eight data centers located across North America, Europe, and Asia. The availability of regional data centers provides our customers with multiple benefits.

- Businesses can reduce network latency and increase performance by hosting their environment in a strategically located data center.
- Companies can enhance resiliency by developing disaster recovery plans that back up and recover data to alternate geographic regions.
- Organizations can comply with data privacy and security regulations by hosting their environment in specific regions.

### Comprehensive Managed Services

Atlantic.Net’s managed services support all of your company’s hosting needs without the overhead of in-house technical and cloud-focused skills. We make it easy to get in touch when you need us with 24/7 support by phone, chat, or email. Our experts leverage advanced skills with deep knowledge of the evolving IT landscape to effectively solve your problems.

Your IT environment is unique and deserves more than a standardized managed services solution. We customize our services to align with your requirements and goals, partnering with you to help the business grow. Our proactive approach helps identify potential issues early, supporting consistent and secure cloud hosting performance.

## Moving to Atlantic.Net Just Makes Sense

We have solutions to fit the needs of any company, whether they run legacy IBM workloads or host modern Kentico websites. Businesses can enjoy customized, scalable, and cost-effective hosting using leading-edge hardware, software, and technical support. If your current hosting provider no longer meets your needs, we invite you to benchmark cost, performance, and support with our team.

[Contact us today](https://www.atlantic.net/about-us/corporate-contact/) to explore your migration options with our experts.


---

# Why EMR Vendors Are Choosing Specialized Providers

> URL: https://www.atlantic.net/hipaa-compliant-hosting/emr-vendors-specialized-hosting-atlantic-net/ | Published: 2025-11-29 | Updated: 2025-12-02 | Author: Dr. Assad Abbas

Organizations in healthcare and education rely heavily on Windows-native applications and SQL Server to manage everything from student records to sensitive patient information. Vendors who build and maintain these systems need secure, stable environments that support their clients without creating unnecessary operational burden on their teams. Many start on large public cloud platforms for their flexibility, but as their applications grow, they often face rising costs, stricter compliance demands, and increasingly complex security needs.

In recent years, many [Electronic Medical Record (EMR)](https://www.oracle.com/health/electronic-medical-record-emr/) vendors and healthcare developers are shifting their Windows applications and SQL workloads to [Atlantic.Net](https://www.atlantic.net/press-room/case-studies/). They want a hosting provider that understands [HIPAA regulations](https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html), offers predictable pricing for small and midsize workloads, and provides a simple, practical operating model for Windows-focused development teams. In this article, we explore why EMR vendors are increasingly turning to specialized hosting providers.

## What Healthcare Software Vendors Actually Need

For a modern EMR vendor, the core business is software, not infrastructure management. Their expertise lies in creating applications that improve patient care, streamline clinic workflows, and ensure data is available to doctors. However, as these vendors grow, they often face significant operational hurdles when using large, general-purpose cloud platforms.

The primary challenge is not just “hosting,” but “[compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/).” HIPAA compliance requires continuous effort to meet requirements such as logical isolation and access controls, maintaining audit logging and retention, and configuring appropriate security controls. Vendors handling PHI for covered entities must comply with HIPAA and sign a business associate agreement (BAA). Many university counseling centers are governed by FERPA unless operating as HIPAA-covered clinics. They also need a clear and documented security posture for each deployment. These demands pull engineers away from improving the product.

Many EMR systems still rely on Windows-native interfaces or legacy frameworks because they remain familiar and reliable for users in clinics, counseling centers, and academic institutions. These vendors need hosting environments that support multiple versions of Windows and SQL Server without forcing major changes to their applications. Long-term stability and backward compatibility are essential, as they cannot afford to constantly redesign their core application stack.

Cost also becomes a significant factor. While EMR workloads are typically predictable and do not require [elastic scaling](https://www.geeksforgeeks.org/cloud-computing/scalability-and-elasticity-in-cloud-computing/), running them is still expensive for smaller vendors. In addition, healthcare applications have strict security requirements, and EMR vendors must provide their support staff and developers with controlled access to client databases for maintenance and troubleshooting. This access must be secure, logged, and, most importantly, not expose the database to the public internet. This is where specialized access methods, like VPNs, bastion/jump hosts with MFA, or SSH tunneling, become critical.

Configuring secure access in a large, multi-tenant environment can be complex and risky if not handled by experts. Additionally, the end-users often demand smooth integration including single sign-on (SSO), so their staff can use their existing hospital or university credentials to log in. This requires deep and secure integration with systems like Active Directory (AD) and identity federation standards (e.g., SAML 2.0 or OIDC), which is much simpler when the hosting partner understands these specific enterprise requirements.

## How Atlantic.Net Addresses These Requirements

Atlantic.Net offers a HIPAA-compliant hosting [platform](https://www.atlantic.net/hipaa-compliant-hosting/) specifically designed for healthcare applications. Its virtual machines support both modern and legacy versions of Windows Server, which give EMR vendors the flexibility to run a wide range of application architectures. Every environment is backed by a formal business associate agreement (BAA), and the infrastructure includes encryption, network isolation, access controls, and audit logging and reporting. Compliance remains a shared responsibility between Atlantic.Net and the vendor. This setup enables healthcare developers to focus on their applications rather than managing infrastructure.

A key advantage Atlantic.Net offers is the option for dedicated or strongly isolated per-client hosting. Rather than running all clients in shared environments, each customer can receive isolated resources adapted to their needs. This approach supports HIPAA safeguard requirements and gives EMR vendors confidence when addressing data security for clinics or universities.

Developers often appreciate the simplicity of using SSH tunneling, VPNs, or a bastion/jump host with MFA for secure access to SQL Server databases. This approach enables teams to work without exposing public ports or changing the core design of their applications. They can interact with the database for support, reporting, or troubleshooting, all while keeping the system protected behind a secure layer.

[SSO integration](https://www.atlantic.net/managed-services/multi-factor-authentication-examples/) is another area where Atlantic.Net provides practical flexibility. It supports traditional Active Directory (AD) setups for teams using domain-based authentication, as well as federated identity systems (e.g., SAML 2.0 or OIDC) for organizations that prefer cloud-based identity providers. This flexibility allows EMR vendors to accommodate clients with varying access requirements without enforcing a single identity model across all deployments.

The [partnership model](https://www.atlantic.net/partners/) is what many vendors appreciate most. Atlantic.Net acts as a hosting backbone for software companies that do not want to become infrastructure providers. Rather than building their own data centers or managing a complex cloud environment, these vendors rely on Atlantic.Net to handle the underlying environment. This approach allows them to focus on customer relationships, product development, and client onboarding. It reduces operational friction and provides their teams with stability and confidence.

## Two Real-World Case Studies

To better understand why vendors choose specialized providers, let’s look at two real-world case studies from Atlantic.Net. The first example involves an EMR vendor that supports over 1,500 university counseling centers. The team needed a hosting environment where SQL Server databases could be deployed quickly and securely for each institution. Their clients required strong data isolation, straightforward access, and reliable performance during peak academic periods. After consulting with Atlantic.Net, the vendor implemented a model where each university received its own dedicated SQL environment with no public endpoints. SSH tunneling gave the development team secure access for support, and the built-in HIPAA-eligible design with a signed BAA and required safeguards helped them meet their contractual obligations without restructuring their application. This approach enabled the vendor to maintain its familiar Windows-native architecture while delivering an improved experience to new customers.

Another example involves a healthcare app team who hosted their Windows-native application and SQL Server database on Azure. As their customer base grew, the team wanted more control over compliance requirements and a more predictable cost structure. They also needed secure database access without exposing public endpoints. Atlantic.Net provided a hosting environment where their Windows application ran without modification, and their SQL Server database ran in a private network with no public endpoints. The migration process required no major changes to the codebase, and the team quickly established a documented compliance posture backed by a signed BAA and concrete controls (encryption in transit/at rest, logging, backups). This stability enabled them to onboard clinics more efficiently and develop a stronger long-term roadmap.

These cases show that healthcare developers prefer hosting providers that provide clarity, reliability, and hands-on support. They want to grow without redesigning their infrastructure at every stage. They appreciate it when the hosting environment matches the practical needs of their applications. Atlantic.Net continues to attract these vendors because it provides these strengths in a simple and accessible way. These real-world examples illustrate a broader shift in how healthcare vendors approach their infrastructure decisions.

## The Bottom Line

Electronic Medical Record (EMR/EHR) vendors, healthcare startups, and educational institutions are realizing the strategic value of specialization. When your entire business depends on the trust and security of protected health information, your infrastructure provider must be more than just a utility. They must serve as an extension of your team, one that understands the unique demands of your Windows Server and SQL Server–based applications.

For teams building Windows applications or handling healthcare data, it’s important to choose a secure, HIPAA-eligible (with a signed BAA), and developer-friendly environment rather than relying on a one-size-fits-all model. This focused approach allows EMR vendors to shift their attention from infrastructure management to developing software that enhances patient care.


---

# How to Store and Secure 25TB+ of Patient Data in the Cloud

> URL: https://www.atlantic.net/hipaa-compliant-hosting/how-to-store-and-secure-25tb-of-patient-data-in-the-cloud/ | Published: 2025-11-30 | Updated: 2026-06-17 | Author: Dr. Tehseen Zia

Healthcare organizations today are collecting more data than ever before. Medical imaging systems like [PACS](https://www.techtarget.com/searchhealthit/definition/picture-archiving-and-communication-system-PACS), [electronic medical records (EMRs)](https://www.oracle.com/health/electronic-medical-record-emr/), and growing repositories of anonymized datasets are accelerating data storage needs.

Hospitals, research institutions, and diagnostic centers face a challenge: how to securely store and manage huge volumes of sensitive patient information while meeting compliance, availability, and performance standards.

Cloud storage has become the natural choice, but not all clouds are equal. Building a secure, compliant, and efficient cloud workflow for healthcare data requires careful planning and the right infrastructure choices.

## Managing Large-Scale Healthcare Data

Modern healthcare [runs](https://www.dicardiology.com/article/understanding-how-big-data-will-change-healthcare) on data. A single high-resolution MRI scan can take up several gigabytes. A hospital that handles thousands of scans each week can easily generate multiple terabytes per month. In addition, electronic medical records and analytics systems continuously generate text, images, and structured data. For research organizations using anonymized datasets to train diagnostic AI models, the data size grows even faster. Managing terabytes of data is not just about storage capacity; it is about performance, compliance, and security.

The [challenge](https://mobisoftinfotech.com/resources/blog/healthcare-data-management-challenges-and-solutions) is keeping this growing data pool accessible and always protected. Traditional on-premises systems [struggle](https://kodjin.com/blog/healthcare-data-storage-options-on-premise-cloud-or-hybrid/) with scalability and maintenance. Physical storage requires large capital investments, frequent hardware upgrades, and dedicated staff for management. Cloud storage, by contrast, [provides](https://www.simbo.ai/blog/cloud-data-storage-in-healthcare-advantages-challenges-and-best-practices-for-secure-and-scalable-data-management-solutions-69025/) scalability on demand, predictable costs, and access to built-in tools for data protection and backup. But with all these benefits come serious questions: Is patient data truly safe? How are backups maintained? What happens if a disaster strikes?

## HIPAA-Compliant Cloud Storage: What Matters Most

Healthcare data falls under strict privacy regulations such as [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/what-is-hipaa-cloud/) in the United States, [GDPR](https://gdpr.eu/) in Europe, and similar frameworks worldwide. These regulations require not only secure storage but also detailed control over data access, encryption, and transmission.

A cloud storage provider for medical data must meet these standards. Data must be protected at rest and in transit, and only authorized users should access it. The cloud vendor must sign a [Business Associate Agreement (BAA)](https://www.techtarget.com/healthtechsecurity/feature/What-Is-a-HIPAA-Business-Associate-Agreement-BAA), taking shared responsibility for security controls.

Encryption is central to HIPAA compliance. Every bit of [protected health information (PHI)](https://en.wikipedia.org/wiki/Protected_health_information) must be encrypted before going into the storage bucket, whether as MRI scans, patient histories, or lab results. Most trusted cloud services such as [Atlantic](https://www.datacenters.com/provider_brochures/atlantic-net-premier-hipaa-compliant-hosting-solutions) offer built-in, strong encryption both in transit and at rest. This means data remains unreadable to unauthorized parties even if systems are breached.

Audit logs are another requirement. Every access attempt, file upload, or deletion needs to be tracked. Most cloud platforms offer centralized dashboards where administrators can see who has accessed what, and when, with alerts for unusual activity. These features help meet compliance rules and give added peace of mind.

## Weekly Ingestion and Snapshot Workflows

One challenge for healthcare providers is managing constant data intake. For example, radiology departments may ingest hundreds of gigabytes of images every day. With cloud workflows, scheduled or continuous uploads are set up to efficiently transfer files as they are generated, a process that avoids pile-ups, ensures data availability, and reduces network stress.

[Snapshots](https://www.rubrik.com/insights/what-is-a-snapshot-backup) are an effective way to protect against accidental loss or corruption. Snapshots are point-in-time copies capturing the state of data at a specific moment. Setting up automated weekly (or even daily) snapshot schedules means there is always a recent restore point in place. If data is accidentally deleted, corrupted, or hit by ransomware, restoring from the last good snapshot can minimize downtime. Cloud platforms like Atlantic.Net snapshot management tools that make this process easy and cost-effective.

Snapshots are [not backups](https://www.commvault.com/explore/snapshots-vs-backups) themselves, but they are a key layer in a multi-tier data protection strategy. They allow quick rollbacks for short-term recovery while deeper backups handle long-term retention.

## Retention, Encryption, and Regulatory Confidence

Healthcare [regulations](https://www.givainc.com/blog/hipaa-retention-requirements/) often require data to be retained for specific periods. Regulations vary by jurisdiction, but storing clinical records for one year is generally a minimum. Longer retention periods are common, especially for imaging. The Cloud makes this process [easy](https://www.perplexity.ai/search/provide-references-for-the-fol-UzJE.to.TfGB0pfrIf53Qg).

With built-in retention policies and lifecycle management tools, healthcare providers can set rules for how long each type of data should live, then automatically archive or delete files according to compliance needs.
 Encryption is an important part of healthcare storage. Using strong, industry-standard protocols, cloud providers protect sensitive health records at every stage. Role-based access controls define what staff can view or modify, and encryption keys are managed securely. The Atlantic.Net platform, for example, provide [managed encryption](https://www.atlantic.net/press-releases/atlantic-net-announces-cloud-platform-encrypts-customer-data-stored-rest-automatically/) without manual intervention to further reduce the risk.

Importantly, cloud storage providers enable strong regulatory reporting. Administrators can quickly generate logs to demonstrate compliance during audits.  This ensures that all data access and storage actions are tracked and aligned with policy.

## Geo-Redundancy and Flexible Backups

Simply storing data in one place is not enough. Natural disasters, cyberattacks, or hardware failures can hit any region. Even the most secure systems need backup and recovery planning.

[Geo-redundancy](https://www.bravurasecurity.com/blog/protecting-your-data-with-geo-redundancy) means that copies of critical data are stored in multiple locations, often in different geographic regions. If one data center fails due to a natural disaster or technical issue, operations can continue from another site without data loss. Cloud providers like Atlantic.Net offer multi-region redundancy that automatically replicates data across different data centers.
 [Disaster recovery planning](https://www.techtarget.com/searchdisasterrecovery/definition/disaster-recovery-plan) is part of every large-scale storage deployment. Automated backup policies make it possible to take regular, encrypted backups of all new patient data and keep versions in multiple regions.

A well-designed disaster recovery plan also includes recovery time objectives (RTOs) and recovery point objectives (RPOs). These define how fast data can be restored and how much data loss is acceptable between backups. With cloud-based recovery tools, organizations can test and verify these systems regularly, ensuring readiness when it matters most.

## Cost and Scalability Considerations

Managing 25TB or more of healthcare data can seem expensive, but cloud storage offers cost efficiencies over traditional systems. Cloud pricing models allow organizations to pay only for what they use, and the ability to scale up or down reduces the need for overprovisioning. Automated lifecycle policies further reduce costs by moving older data to lower-priced tiers.

In addition, cloud systems eliminate the need for maintaining hardware, power, and cooling infrastructure. The cost savings in physical management and staff resources can be redirected toward improving patient services or investing in new research.

Providers that specialize in healthcare, like Atlantic.Net, also offer predictable pricing models that align with regulatory needs. Their [HIPAA-compliant](https://www.atlantic.net/hipaa-compliant-hosting/what-is-hipaa-cloud/) plans include managed security, regular backups, and dedicated support, ensuring that organizations don’t face hidden costs when scaling up.

## The Bottom Line

Managing massive patient datasets might seem a daunting task. Modern cloud storage makes it not just possible but practical, safe, and scalable for healthcare institutions of all sizes. With strong providers and best practices like encryption, snapshotting, and geo-redundant backups, healthcare teams can protect their data and meet rigorous regulatory requirements, without sacrificing accessibility or speed.

Providers like Atlantic.Net have thoughtfully designed their systems to meet these challenges. By adopting proven cloud storage tools and workflows, healthcare leaders can focus less on infrastructure headaches and more on delivering patient care.


---

# Email Deliverability, Port 25, and SMTP: A Complete Guide for Healthcare and Booking Platforms

> URL: https://www.atlantic.net/managed-services/email-deliverability-port-25-and-smtp-a-complete-guide-for-healthcare-and-booking-platforms/ | Published: 2025-12-01 | Updated: 2026-05-05 | Author: Richard Bailey

If you’re developing an application for a healthcare organization or a booking platform, you rely on transactional email for critical application functions. From appointment reminders and booking confirmations to patient portal password resets and two-factor authentication codes, embedded email automation becomes a critical operational function for user engagement.

One common issue you may experience after setting up a mail server is email failing to send. This typically happens when pointing the application at the original SMTP default port, it may result in emails failing to send, or worse, sending but landing directly in the user’s spam folder. For developers and system administrators, this frustrating scenario often points to one common, intentional roadblock: port 25 blocking.

As a managed cloud provider with over 30 years in the industry, Atlantic.Net has many clients resolve this exact issue. This isn’t a bug in your code or a misconfigured server; it’s caused by a global security policy applied to the server.

Here’s what you need to know to get your emails flowing securely and reliably.

## In a Hurry? The 60-Second Fix

Your emails are failing because your cloud provider is blocking outgoing Port 25 to prevent spam.

- Do NOT use Port 25 for sending email from your application.
- Change your application’s SMTP configuration to use:
  - **Port: 587** (with STARTTLS encryption)
  - **Port: 465** (with Implicit TLS/SSL encryption)
- Ensure you are using authentication (a username and password) for your mail server.
- For best results, use a dedicated transactional email service (like SendGrid, Postmark, or Mailgun) and configure SPF, DKIM, and DMARC records for your domain.

## Why Is Port 25 Blocked?

Port 25 is the original default port for Simple Mail Transfer Protocol (SMTP), the protocol that moves email from one server to another. In the early days of the internet, SMTP was built on trust. Servers didn’t require authentication to accept and forward an email. This “open relay” design was simple, but it was incredibly insecure. Spammers and botnet operators began to exploit it. They would scan the internet for compromised servers (“zombie computers”) and misconfigured mail servers, using them as open relays to send  millions of spam and phishing emails. To combat this problem, global action was needed:

- ISPs and cloud providers (like Atlantic.Net) began blocking all outgoing traffic on Port 25 from end-user devices and cloud servers.

Blocking Port 25 is a critical security measure. It protects the provider’s network reputation and prevents their IP address ranges from being blacklisted. It ensures that legitimate customer traffic isn’t impacted by spam.
 Therefore, you cannot, and should not force your application to use Port 25 for sending email. Even if you could, most receiving servers would block your mail anyway, suspecting it as spam.

## Use the Correct, Secure Ports

Stop using Port 25 for email submission (sending mail from your app to your mail server) and instead  use the modern, secure ports designated for this exact purpose.

- **Port 587 (Recommended):** This is the standard port for email submission. It uses STARTTLS, an [opportunistic encryption](https://blog.cloudflare.com/opportunistic-encryption-bringing-http-2-to-the-unencrypted-web/) command. The connection starts in plain text, but the first command from your application is to “upgrade” the connection to a secure, encrypted TLS (Transport Layer Security) channel before any credentials or email data are sent. It requires authentication.
- **Port 465 (Alternative):** This port is for SMTPS (SMTP Secure) and uses Implicit TLS. The entire connection is wrapped in a TLS/SSL tunnel from the very beginning. While once deprecated, it was officially reinstated by RFC 8314 and is a widely accepted, secure standard.

| **Port** | **Protocol** | **Encryption** | **Authentication** | **Primary Use** |
| --- | --- | --- | --- | --- |
| **25** | SMTP | None (Opportunistic) | Optional | Server-to-Server mail relay. Should be blocked for clients. |
| **587** | SMTP Submission | STARTTLS (Explicit) | Required | Recommended Standard for applications sending email. |
| **465** | SMTPS | Implicit TLS | Required | Excellent, modern alternative for applications. |

## How to Test Your SMTP Port Connection

How do you know if you can even reach your mail server on these ports? You can test the port connection directly from your server’s command line. For Port 587 (STARTTLS), you can use the telnet utility. By running the command **telnet smtp.yourprovider.com 587**, you are attempting to open a simple, unencrypted connection. A successful connection will immediately return a **220 … ESMTP Service ready response**, indicating the port is open and the mail service is listening. At that point, you could type EHLO yourdomain.com to see the server’s capabilities, which should include STARTTLS, before typing quit to exit.

Testing Port 465 (Implicit TLS) is slightly different. You cannot use telnet because this port expects the connection to be wrapped in SSL/TLS from the very beginning. Instead, you should use a tool like openssl. The command **openssl s_client -crlf -connect smtp.google.com:465 -debug -msg**will initiate the secure connection, display the server’s SSL certificate details, and then show the 220 SMTP welcome message if successful.

If either test results in a “Connection timed out” or “Connection refused” error, it’s a strong indicator that the port is being blocked by a firewall, either on your local server or on the provider’s side.

## Ensuring Deliverability with SPF, DKIM, and DMARC

Please bare with me because I need to get technical to explain this. Using the correct port ensures your email *sends*, but ensuring deliverability (reaching the inbox) requires proving your identity to receiving servers.

This is handled by the “Authentication Triad”—SPF, DKIM, and DMARC—which are all configured in your domain’s DNS settings.

- **SPF (Sender Policy Framework)** is a DNS TXT record that lists all IP addresses authorized to send email for your domain. Receiving servers check this record; if the sender’s IP doesn’t match, the email is treated as suspicious.
- **DKIM (DomainKeys Identified Mail)**provides a digital signature for your emails. It uses a private key on your server to sign the message and a public key, published in DNS, for receivers to verify it. A valid signature proves the email is from your domain and that its content has not been altered.
- **DMARC (Domain-based Message Authentication, Reporting & Conformance)** unifies SPF and DKIM. This DNS record tells receivers what policy to apply if a message fails those checks, such as p=quarantine (send to spam) or p=reject (block). It also enables reporting on email activity.

For any serious application, implementing all three is mandatory for deliverability and security.

## Self-Hosting vs. Third-Party Relays

While reconfiguring your port is the direct fix, you must also decide *how* to send your email. You have two main options: managing your own mail server (like Postfix or Exim) on your VM, or using a third-party transactional email service (like SendGrid or Postmark).

Self-hosting gives you complete control over logs and configuration, but it comes with significant technical burden. You are solely responsible for the complex setup, ongoing maintenance, and (most difficult) managing your server’s IP reputation. Poor reputation management will get your emails blacklisted, making deliverability a constant, difficult battle. You also have to build your own analytics and manage all compliance (like HIPAA) yourself.

A third-party relay is the recommended solution for most applications. These services are built specifically for high deliverability. They handle IP warming, reputation management, and provider relationships for you. Setup is fast (often minutes), and they provide built-in analytics for opens, clicks, and bounces. For healthcare, top providers offer Business Associate Agreements (BAAs) to help with [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/). While this means less direct control and a predictable per-email cost, it offloads immense complexity.

For 99% of applications, especially in healthcare and booking, a dedicated third-party service is the professional-grade solution. The cost and complexity of managing your own email deliverability are almost never worth it.

## Special Considerations for Sensitive Industries

But for sensitive industries, getting the email sent is only the first step. Security and compliance is essential.

### For Healthcare: HIPAA Compliant Email

When an email (even an appointment reminder) contains Protected Health Information (PHI), HIPAA rules apply.

- **You Must Have a BAA:** You must have a signed Business Associate Agreement (BAA) with your hosting provider (like Atlantic.Net for HIPAA-Compliant Hosting) and any third-party email provider you use. A [BAA is a legal contract](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/)that obligates the provider to safeguard PHI.
- **Crucial:** A BAA with your host does not cover a third-party email service. If your email provider (including Gmail or Microsoft 365) does not provide a BAA, you cannot use it to send PHI.
- **End-to-End Encryption:** HIPAA demands encryption for PHI “in-transit” (while being sent) and “at-rest” (in the database). Using Port 587 or 465 with TLS is a mandatory part of securing data in-transit.
- **What is PHI?** A name and an appointment time (“Jane Doe, 2:30 PM, Oncology Dept”) is PHI. A password reset link for a patient portal is also considered PHI by proxy, as it grants access to it.
- **Best Practice:** Avoid sending PHI in the email body or subject line. Send a generic notification (“You have a new message in your secure patient portal”) that requires the user to log in to your secure, compliant application.

### For Booking Platforms: Trust and Reliability

For booking and scheduling systems, the primary concerns are reliability and user trust.

- **Use a Recognizable “From” Address**: Avoid noreply@yourdomain.com. It feels impersonal and blocks users from replying with questions. Use something clear, like bookings@yourplatform.com or support@yourplatform.com.
- **Separate Transactional and Marketing Mail:** Send your password resets and booking confirmations from a different IP and subdomain (e.g., app.yourdomain.com) than your marketing newsletters (e.g., marketing.yourdomain.com). This protects the deliverability of your critical emails if your marketing mail ever gets flagged as spam.
- **Make It Clear and Actionable:** The email must clearly state the time, date, and location (or virtual link). Most importantly, include obvious, one-click links to “Confirm,” “Reschedule,” or “Cancel.” This reduces no-shows and administrative overhead.

Need a secure, compliant foundation for your healthcare or booking application? Atlantic.Net offers robust, 24/7-supported [HIPAA-Compliant Hosting](https://www.atlantic.net/gpu-server-hosting/hipaa-gpu-hosting/)and Managed Cloud Services from our 8 global data centers. We handle the secure infrastructure, so you can focus on building your application.

Contact us today to learn how we can help you build and deploy with confidence.

 


---

# Secure Cloud Hosting for Healthcare & Gov: HIPAA & FedRAMP Solutions

> URL: https://www.atlantic.net/hipaa-compliant-hosting/secure-cloud-hosting-healthcare-government/ | Published: 2025-12-02 | Author: Dr. Assad Abbas

Security and compliance are critical concerns for healthcare and government organizations because they handle sensitive information and operate under strict regulations. As a result, these organizations need [cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) environments that protect data, provide stable performance, and maintain clear audit trails. Choosing the right hosting solution helps ensure operational continuity while meeting regulatory obligations.

To address these requirements, hosting solutions must provide secure networks, structured access management, monitoring tools, and support for migrations from existing platforms. Platforms such as [Atlantic.Net](http://www.atlantic.net) offer HIPAA- and PCI-compliant services. Consequently, organizations can operate sensitive applications in a secure, reliable, and compliant infrastructure.

## Essential Hosting Requirements for Healthcare Organizations

Healthcare organizations operate under strict rules for managing patient data. These regulations influence the design of hosting systems, user access patterns, and backup strategies. Therefore, every component of the system must function together to ensure data security, operational reliability, and regulatory compliance.

### HIPAA-Compliant Infrastructure

HIPAA’s Security Rule requires safeguards appropriate to risk; encryption at rest and in transit are “addressable” controls that most organizations implement (e.g., TLS 1.2+ for HTTPS and strong at-rest encryption) based on a documented risk analysis. Consequently, hosting environments must include secure networks, encrypted storage, and restricted user privileges. Providers that handle ePHI must sign a Business Associate Agreement (BAA). Implement audit controls aligned to HIPAA §164.312(b) with centralized log collection, time synchronization, and documented retention.

In addition, the infrastructure typically uses isolated servers to separate medical applications from other workloads, thereby enhancing overall system security. At the same time, firewall rules restrict network traffic to authorized sources, and detailed logs record user activity for auditing purposes. As a whole, these measures provide a secure and stable foundation, enabling hospitals, clinics, laboratories, and billing offices to operate efficiently and reliably.

### Secure Access Using HTTPS

Healthcare applications are accessed from multiple locations. Doctors may connect from hospitals or clinics, patients from home portals, and administrative staff from offices or remote networks. All connections must be secured end-to-end.

HTTPS (HTTP over TLS 1.2 or higher with HSTS) encrypts communication between users and servers; disable SSL and early TLS and use modern cipher suites and certificate lifecycle management.

Consequently, critical data such as medical charts, laboratory results, billing records, and insurance information remains protected. In this way, enforcing HTTPS helps healthcare organizations provide consistent, reliable, and secure access to their applications, regardless of the user’s location.

### Regular Backups with Extended Retention

Healthcare systems handle large volumes of critical data, including patient records, appointment schedules, diagnostic reports, and insurance forms. Unexpected events such as system failures, user errors, or data corruption can compromise access to this information.

Regular backups are essential, but frequency and retention should be driven by risk analysis and RPO/RTO—not a fixed rule. For example, nightly backups with point-in-time recovery and at least one immutable/off-site copy (3-2-1 or 3-2-1-1-0) are common. An example policy might use weekly full plus daily incremental backups with 30–365-day retention; routinely test restores. HIPAA requires a documented Contingency Plan and Data Backup Plan, not a specific “weekly/6-month” schedule.

### Support for PostgreSQL and Java Applications

Many healthcare systems rely on PostgreSQL for database management and Java for application logic. These technologies support clinical modules, patient portals, laboratory integrations, and billing systems. Therefore, hosting platforms must provide reliable environments to ensure the uninterrupted operation of these applications.

Harden databases and runtimes: enable PostgreSQL TLS, point-in-time recovery, and replication for high availability; tune autovacuum/VACUUM/ANALYZE; secure JDBC connectivity; and right-size JVM heap/GC settings for predictable performance.

### Structured Migration from AWS

Healthcare organizations may migrate from large public cloud platforms to achieve more predictable performance, controlled support, and dedicated services. However, migration can be complex and carries potential risks if not carefully planned.

A structured migration process involves reviewing the current environment, preparing a parallel hosting setup, testing application workflows and database connections, and then performing data migration with DNS cutover. Strengthen the plan with lower DNS TTLs before cutover, repeatable data validation (e.g., checksums), rehearsed rollback, license/egress-cost analysis, and post-cutover monitoring. This risk-based approach helps maintain continuity and protects sensitive patient information throughout the transition.

## Critical Hosting Requirements for Government Agencies

Government agencies handle sensitive data that impacts public services and operations. Therefore, their hosting systems must meet specific requirements to ensure security, reliability, and regulatory compliance. While some principles overlap with healthcare, government workloads demand additional capabilities due to legacy systems, complex operations, and strict regulations.

### High-Level Security and Compliance

Government workloads must follow strict internal policies similar to standards in specialized cloud regions. Consequently, hosting systems should provide robust network isolation, defined permission structures, and continuous monitoring. In addition, reliable access is essential. Databases and internal portals must remain available at all times and deliver consistent performance under heavy workloads.

For U.S. federal workloads, align with FedRAMP Moderate/High baselines (NIST SP 800-53), use FIPS 140-2/140-3 validated cryptographic modules, and consider deployment in AWS GovCloud (US).

### Support for Legacy Systems

Many agencies still operate IBM AIX (a UNIX operating system) and IBM i (AS/400) systems for reporting, record management, and financial workflows. These systems are critical because they handle specialized functions that newer platforms cannot fully replace. Therefore, hosting systems must reliably support these legacy environments to ensure operational continuity. In addition, the infrastructure should facilitate gradual modernization with minimal disruption to essential services.

### Multi-Server Architecture

Government applications often consist of multiple interconnected systems. For example, CRM platforms track public interactions, reporting dashboards, compile analytics, and internal services manage documents and approvals. Therefore, hosting platforms should provide multi-server architectures that separate these functions across servers. This approach improves stability, simplifies maintenance, and reduces operational risks. Define clear east-west network segmentation, document inter-service APIs, and organize resource allocation to further enhance efficiency.

### User Access Controls and Authentication

Strict access control is necessary to protect government data. Hosting systems must enforce strong password policies, implement account lockout mechanisms, and monitor user activity. Add multi-factor authentication (especially for privileged and remote access), centralized logging/SIEM with alerting, and regular access reviews. These measures help prevent unauthorized access while enabling administrators to review logs and manage permissions effectively.

### Flexible Storage Solutions

Agencies often require both centralized storage for consistent access and auditing, as well as regional storage to improve performance for local offices and reduce network latency. Therefore, hosting platforms should support both options, including lifecycle policies, WORM/immutability where needed, and edge/region-aware replicas, which enables agencies to tailor storage to operational needs.

## Atlantic.Net’s Advantages for Healthcare Clients

Healthcare organizations select hosting providers based on trust, compliance, and reliability. Therefore, a provider must offer secure and well-structured environments that meet the unique requirements of regulated industries. Atlantic.Net supports these needs through a combination of compliance expertise, scalable infrastructure, strong access controls, and structured migration processes.

### Scalable Architecture for Growing Demands

Healthcare workloads often expand over time. Applications, data volumes, and user numbers increase steadily. Therefore, hosting environments must scale without major redesigns. Atlantic.Net provides flexible setups that start with a single server and can expand to multi-server clusters. Capacity planning ties to measurable SLOs (e.g., p95 latency, error rates) to maintain performance as operations grow.

### Advanced Access Controls and Audit Trails

Strong access management is essential for security. Atlantic.Net enforces password policies, lockout mechanisms, and audit trails. Add MFA for privileged and remote access, time-synced logging, and retention aligned to policy and regulatory expectations (e.g., documentation retained for six years under HIPAA). As a result, administrators can monitor user activity, detect unusual behavior, and ensure only authorized personnel have access to critical systems. This approach strengthens security and reduces operational risk.

### Structured Migration Support

Migrating applications can be challenging, particularly in regulated industries. Therefore, Atlantic.Net guides organizations through planning, testing, and DNS cutover. Best practices include lowering DNS TTL, side-by-side testing with representative data, checksum-based validation, explicit rollback plans, and post-cutover observability. Side-by-side testing ensures that applications function correctly before going live. This structured approach minimizes disruption and maintains security throughout the transition.

## Real-World Healthcare Hosting at a California Medical Center

A medical center in California reached out to Atlantic.Net to improve its hosting environment. Their application, built with PostgreSQL and Java, managed patient records, appointment scheduling, billing, and internal communications. The existing system was slow and sometimes unreliable. Therefore, the center needed faster performance, stronger security, and a more dependable hosting solution.

Atlantic.Net first analyzed the application and its infrastructure, including database usage, network flows, and access patterns. Based on this analysis, a new hosting design was proposed. The solution included encrypted storage, isolated networks, secure HTTPS connections, and weekly backups with extended retention. In addition, the design accounted for potential future growth and improved system performance.

For these types of deployments, [Atlantic.Net](http://atlantic.net) supports the systems by working closely with the client. First, a parallel environment is established for testing before complete migration. Sample data and real application workflows are used to verify stability and performance. Critical functions, such as accessing patient charts, processing billing, and managing scheduling, are thoroughly tested within this environment. This approach ensured that all processes would operate reliably without interruptions once the system goes live.

After testing confirmed system stability, Atlantic.Net is there to assist with database migration and application deployment. The DNS cutover is completed without interrupting access to the application. As a result, the new hosting setup is improved with faster response times and strengthened security. It also provides a safe and compliant foundation for critical applications. This example shows Atlantic.Net working with healthcare clients to deliver reliable and practical cloud hosting solutions that meet their needs.

## Final Thoughts

Secure and reliable cloud hosting is essential for healthcare and government organizations because they manage sensitive data and operate under strict regulations. Successful programs clearly distinguish regulatory requirements from best-practice controls and combine HIPAA Security Rule safeguards, PCI DSS v4.0 expectations, and—where applicable—FedRAMP Moderate/High controls with FIPS-validated cryptography. Moreover, scalable architectures, robust backup strategies, and structured migration processes are necessary to maintain operational continuity and adapt to changing workloads.

Platforms such as Atlantic.Net integrate compliance expertise, advanced access controls, and flexible storage options. As a result, organizations can secure critical applications, meet regulatory obligations, and enhance operational efficiency. By grounding designs in risk analysis (RPO/RTO, SLOs) and documenting controls, teams build durable, auditable environments that support long-term growth and security.

 


---

# ADA Compliance Statement

> URL: https://www.atlantic.net/ada-compliance-statement/ | Updated: 2026-09-16

**ADA Accessibility Statement**

Atlantic.Net is committed to providing an accessible and inclusive online experience for all individuals, including those with disabilities. We believe that everyone should be able to access information easily, navigate our services without barriers, and engage with our content regardless of ability or assistive technology.

To achieve this, we are actively working to ensure our website meets the requirements of the Americans with Disabilities Act (ADA) and aligns with the Web Content Accessibility Guidelines (WCAG) 2.1 AA standards. Our accessibility efforts are ongoing and include:

- 
  - Regular Accessibility Audits to identify and resolve issues.

- Updating Website Structure, Code, and Content for improved usability.
- Using Accessibility Tools and Expert Guidance to maintain compliance.
- Training Our Web Development Team to prioritize accessibility in design, development, and content management.
- Incorporating User Feedback to guide improvements and enhance the experience.
- While we strive to make every page fully accessible, some content may not yet meet the highest standards. Accessibility is an evolving process, and we are committed to continuous improvement.

**Need Assistance or Have Feedback?**

If you experience any difficulty using our website or encounter accessibility barriers, please contact us so we can assist you and address the issue promptly. Your feedback is essential in helping us create a better experience for all users.

**Contact Us for Accessibility Support:**

Email: support@atlantic.net
 Phone: 1-866-618-3282
 We appreciate your patience as we work toward full ADA and WCAG compliance. Your experience matters to us, and we remain dedicated to providing an accessible and inclusive digital environment for everyone.

**Accessibility FAQ**

At Atlantic.Net, we are committed to making our website and services accessible to everyone, including individuals with disabilities. Below are answers to common questions about accessibility.

**1. What is Atlantic.Net’s accessibility commitment?**

We strive to meet or exceed WCAG 2.1 AA standards to ensure our website is usable by all individuals, regardless of ability.

**2. How can I report an accessibility issue?**

If you encounter any barriers, please contact us at accessibility@atlantic.net or call 1-866-618-3282. We will respond promptly.

**3. What assistive technologies are supported?**

Our site is compatible with screen readers, keyboard navigation, and other assistive tools commonly used by individuals with disabilities.

**4. Are PDFs and documents accessible?**

Yes, we provide accessible PDFs. If you need an alternative format, email us and we’ll provide it.

**5. Does Atlantic.Net offer accessibility training for staff?**

Yes, our web development team is currently undergoing on-going training to ensure accessibility best practices are implemented across all services.

**6. What standards do you follow?**

We follow WCAG 2.1 AA guidelines and comply with applicable accessibility laws.

**7. Can I request accommodations for services?**

Absolutely. Contact us to discuss your needs, and we’ll work to provide reasonable accommodations.


---

# Atlantic.Net’s HIPAA Compliant Hosting Wins Gold in 15th annual Best in Biz Awards

> URL: https://www.atlantic.net/press-releases/atlantic-nets-hipaa-compliant-hosting-wins-gold-in-15th-annual-best-in-biz-awards/ | Published: 2025-12-03 | Updated: 2026-03-02 | Author: Editorial Team

**Orlando, FL** (December 3, 2025) – Atlantic.Net has been named a gold winner in the Technology Solution of the Year – Compliance category in Best in Biz Awards 2025, one of the most prestigious business awards in North America and globally, and the only independent business awards program judged each year by prominent editors and reporters from top-tier publications.

Atlantic.Net, a global cloud infrastructure provider, stands out in the healthcare industry as a leader in HIPAA-compliant Cloud Hosting services ensuring privacy, security, and compliance. The company serves a distinguished clientele that includes healthcare providers, Healthcare IT innovators, Application Service Providers, Biotech firms, and elite academic institutions. 

[Atlantic.Net](http://atlantic.net)’s HIPAA-Compliant GPU Hosting platform is meticulously designed to future-proof healthcare applications. Its proven HIPAA-compliant hosting environment has been significantly upgraded in 2025 to meet the specialized AI/ML engineering demands of biotech, medical, and forward-thinking healthcare companies.

For 15 years, Best in Biz Awards’ press judges have faced the incredible challenge of determining winners among equally compelling entries with varying strengths – and the 15th annual edition has been no different. This year’s winners demonstrate a wide range of innovations, including a continuation of the trend of innovative AI uses across various industries; continued expansion of workplace benefits and diversity and employee wellbeing programs offered; and last but not least, increasing community involvement and unwavering dedication to environmental responsibility causes.

“Innovation is key to our success,” said Marty Puranik, founder and CEO of Atlantic.Net. “The rapid change in technology is challenging but we continue to meet and exceed the required administrative safeguards, physical safeguards, and technical safeguards mandated by HIPAA regulations.”

Since the program’s inception in 2011, winners in Best in Biz Awards have been determined by independent judging panels assembled each year from some of the most respected national and local newspapers, TV and radio outlets, and business, consumer, technology and trade publications in North America. By combining the unparalleled expertise and experience of the top-notch editors and reporters with the vast diversity of outlets they represent, Best in Biz Awards has always offered the most objective and unbiased judging, beyond programs scored by regular business professionals or by writers from one publication. The 2025 judging panel included, among others, writers and contributors to Associated Press, Barron’s, Consumer Affairs, eWeek, Forbes, Globe and Mail, Inc., MediaPost, New York Times, Ottawa Citizen, and Wired.

“Over the past 15 years, Best in Biz Awards has seen entries from companies small and large, from every corner of the United States and Canada, and from industries as diverse as AI and cosmetics through logistics and retail to software and waste management. We’ve seen impressive entries both in years of incredible economic expansion and growth and in those difficult and challenging pandemic years,” said Best in Biz Awards staff. “As we mark our 15th annual edition, we are exceedingly proud of our winners, many of whom have grown exponentially, got acquired or went public since winning one of our awards. However, besides their impressive growth and innovation, what has always set Best in Biz Awards winners apart has been the positive impact and change they bring about for their employees, clients and communities – and it is that positive impact of Best in Biz Awards winners over the past 15 years that we are most proud of.”

For a full list of gold, silver and bronze winners in Best in Biz Awards 2025, visit [this link](http://www.bestinbizawards.com/2025-winners). 

**About Atlantic.Net**
 Founded in 1994, [Atlantic.Net](http://atlantic.net/) is a privately held global cloud infrastructure provider with customers in over 100 countries, known for delivering secure, compliant, on-demand and customizable hosting solutions. With decades of experience, Atlantic.Net is one of the world’s most trusted and experienced hosting providers, offering 24/7 U.S.-based support. Specializing in security, compliance, and customer service, Atlantic.Net serves a diverse range of industries with solutions including HIPAA-compliant hosting, and PCI-compliant hosting, backed by bare metal servers, dedicated hosting, GPU hosting, colocation, and its award-winning Cloud Platform. Operating from eight strategically located data center regions across the United States, Canada, the United Kingdom, and Asia, Atlantic.Net powers mission-critical workloads for organizations worldwide. For more information, visit[ Atlantic.Net](https://www.atlantic.net/) or connect with us on[ Facebook](https://www.facebook.com/Atlantic.Net),[ X (Twitter)](https://twitter.com/AtlanticNet),[ LinkedIn](https://www.linkedin.com/company/atlantic.net-inc./posts/?feedView=all), and[ YouTube](https://www.youtube.com/c/AtlanticNet).

**About Best in Biz Awards**
 Since 2011, Best in Biz Awards has been one of the most prestigious awards in North America and globally, and it remains the only independent business awards program judged only by well-known writers and editors from a wide spectrum of top-tier publications. Over the years, judges in the prestigious awards program have ranged from Associated Press to the Wall Street Journal and winners have spanned the spectrum, from some of the world’s most innovative start-ups and nimble local companies to blue-chip companies that form the bedrock of the global economy. Each year, Best in Biz Awards honors are conferred in two separate programs: North America and International, and in more than 100 categories, including company, team, executive leadership, product innovation, and CSR, media, PR and other categories. For more information, visit: [http://www.bestinbizawards.com](http://www.bestinbizawards.com/).


---

# Best HIPAA Compliant Workflow Automation Software 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-workflow-automation-software-2026/ | Published: 2025-12-05 | Updated: 2026-01-06 | Author: Dr. Rachael Bailey

Many healthcare teams still rely on manual data movement on a day-to-day basis, whether for transcribing intake forms into EHRs, forwarding referrals between clinicians, or updating billing status across systems. Every step introduces care delays, adds administrative burden, and increases the likelihood of errors or even privacy lapses.

Meanwhile, security [breaches continue to rise](https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf). In recent years, hundreds of millions of healthcare records have been exposed, often due to inconsistent access controls, fragile system integrations, or sensitive information ending up in tools that were never designed to handle PHI.

To close these gaps, more organizations are turning to workflow automation platforms that can connect EHRs, CRMs, billing systems, patient communication channels, and internal applications. When protected health information (PHI) is part of the process, however, automation must be built on a HIPAA-ready application stack, which spans not only the software itself but also the hosting environment and the way the entire system is configured and governed.

A secure, well-designed automation strategy can streamline clinical and administrative workflows without compromising patient trust.

## What is HIPAA-compliant workflow automation?

Workflow automation in healthcare means defining the triggers, logic, and actions once, and then letting software carry them out reliably instead of relying on staff to do them manually.
 For example, consider these types of regular healthcare workflows:

- Patient intake → eligibility check → EHR record creation → tasks for staff
- Referral received → routing to the right specialist → notifications → status updates
- Claim submitted → status polling → exception queue → follow-up tasks

HIPAA-compliant workflow automation adds:

- Encrypted transport and storage for PHI
- Role-based access and audit logs
- A signed Business Associate Agreement (BAA) is required when a vendor stores or processes PHI
- Hosting on [infrastructure that meets HIPAA’s](https://www.atlantic.net/hipaa-compliant-hosting) administrative, physical, and technical safeguards

## HIPAA Workflow Automation Hosting

Even the best software cannot make a deployment compliant on its own. HIPAA compliance depends on:

- A Compliant Platform (automation tool, EHR, CRM, etc.).
- A Compliant Environment to run in (cloud or data center).
- HIPAA hardened configuration and processes.

For self-hosted or hybrid tools, a HIPAA-compliant hosting provider is needed. Providers such as Atlantic.Net offer:

- SOC 2 / SOC 3–certified infrastructure
- HIPAA and HITECH audited cloud and dedicated servers
- Business Associate Agreements on all HIPAA hosting plans
- Security services such as managed firewalls, intrusion detection, MFA, and encrypted backups

This type of platform can host:

- Self-hosted automation engines (like n8n or Rhapsody)
- Custom microservices that sit between EHRs and SaaS tools
- Databases and queues that back your workflow engine

## How to Choose HIPAA-Compliant Workflow Automation Software

When you evaluate tools, it helps to use the same basic checklist every time:

- **BAA and HIPAA posture**
  - Does the vendor sign a BAA?
  - Do they publish details about HIPAA, SOC 2, or HITRUST audits?
- **Healthcare-specific capabilities**
  - Native healthcare connectors (EHRs, practice tools, labs)
  - Support for HL7, FHIR, X12, or payer-provider use cases
- **Security and governance**
  - Role-based access, SSO, detailed audit logs
  - Environment segregation for development, test, and production
- **Workflow design and usability**
  - No-code or low-code builders for operations teams
  - Support for complex routing, retries, and error handling
- **Deployment model**
  - SaaS in the vendor’s cloud
  - Self-hosted or private cloud on HIPAA-compliant infrastructure
  - Hybrid agents that connect on-prem or Atlantic.Net-hosted systems

Keep in mind that HIPAA compliance is always a shared responsibility. The automation platform and its hosting provider must supply the technical and security controls required by the regulation, but your organization’s own governance, access practices, and workflow design play an equally important role.

## Best HIPAA-Compliant Workflow Automation Software (2025)

![](https://www.atlantic.net/wp-content/uploads/2025/12/keragon.png)

### #1: Keragon

[Keragon](https://www.keragon.com/) is a no-code automation platform built specifically for healthcare. It is used to connect clinical, operational, and administrative systems and to automate workflows without a heavy engineering team. The platform is HIPAA- and SOC 2–compliant, and it is designed from day one for PHI, which makes it a fit for regulated digital health and provider environments.
 Teams use Keragon to sync intake forms into cloud EHRs, route referrals, coordinate scheduling logic, and orchestrate billing and insurance steps across tools.

#### Notable features

**Healthcare-native connectors**

Prebuilt integrations for leading EHRs (e.g., Athenahealth, DrChrono, Healthie), CRMs, telehealth tools, form builders, and communication apps, maintained by Keragon, so your team avoids custom API work.

**No-code healthcare workflow builder**

Drag-and-drop canvas with if/else logic, branching, retries, and error handling, designed so operations staff can build and adjust patient-facing workflows without writing code.

**Compliance and audit feature**

HIPAA and SOC 2 Type II posture, encryption, detailed audit logs, and environment controls, aimed at satisfying IT and compliance review for PHI workflows.

**Healthcare templates and use cases**

Library of templates for patient intake, referral pipelines, care coordination, billing workflows, and digital health onboarding to reduce setup time.

#### Advantages

- Focused only on healthcare workflows and tools
- Strong compliance story with HIPAA and SOC 2 audits
- Minimal engineering effort required for new automations
- Vendor-maintained connectors reduce integration maintenance

#### Disadvantages

- Fewer generic SaaS integrations than mass-market tools like Zapier or Make
- Cloud-only model; not self-hosted on your own infrastructure
- Best value is seen when most major workflows are pushed into the platform

#### Ideal for

- Multi-site clinics that want end-to-end intake, scheduling, and referral automation
- Digital health startups that need healthcare-grade integrations without building an internal integration team
- Established practices that want to modernize operations without replacing their EHR

![](https://www.atlantic.net/wp-content/uploads/2025/12/Workato-logo.png)

### #2: Workato

[Workato](https://docs.workato.com/security/security-compliance.html)is an enterprise integration and automation platform (iPaaS) used across many industries, including healthcare. It combines a visual “recipe” builder with extensive governance and a large connector library. Workato operates as a HIPAA-compliant Business Associate and signs BAAs, supported by third-party HIPAA and SOC 2 audits.
 For health systems and larger digital health vendors, Workato often becomes the central integration layer between EHRs, CRMs, data platforms, and internal services.

#### Notable features

**Recipe-based automation engine**

Workflows are built as “recipes” with triggers, conditions, and actions that can be versioned, reused, and governed across teams.

**Enterprise governance and security**

Role-based access, granular environment management, audit logs, and approval flows align with enterprise risk and compliance requirements, including HIPAA.

**Broad connector catalog and SDK**

Hundreds of prebuilt connectors across SaaS, databases, and on-prem systems, plus an SDK for custom connectors. This supports complex hybrid environments, including Atlantic.Net-hosted workloads.

**Healthcare-ready posture**

HIPAA-aligned security controls, BAAs, and support for healthcare workflows such as HL7 integrations through specific connectors and patterns.

#### Advantages

- Strong fit for large enterprises and complex data flows
- Mature governance framework for shared automation at scale
- Wide connector library across clinical and back-office tools

#### Disadvantages

- Pricing is oriented toward mid-market and enterprise
- Configuration and recipe design usually need experienced admins
- Less healthcare-specific out of the box than a healthcare-only platform like Keragon

#### Ideal for

- Health systems with many departments and diverse application stacks
- Vendors that need to embed integration and automation into their own products
- Organizations already using Atlantic.Net for core apps that need an iPaaS in front of them

![](https://www.atlantic.net/wp-content/uploads/2025/12/redox.png)

### #3:Redox

[Redox](https://redoxengine.com/)is a healthcare-specific integration platform that normalizes data across EHRs and clinical systems. It offers a unified API that abstracts HL7, FHIR, and other healthcare standards, which lets vendors and providers connect once and then scale across many health organizations.
 Redox positions itself as the connectivity backbone; workflow automation is then built on top through your own applications or other platforms.

#### Notable features

**Normalized healthcare APIs**

A single API surface is provided over HL7, FHIR, and proprietary interfaces, so engineering teams can avoid writing separate integrations for each EHR.

**Secure PHI routing and logging**

Encrypted transport, PHI-aware routing, and detailed audit trails support HIPAA expectations and simplify security reviews.

**Scale across many providers**

Redox focuses on multi-site, multi-EHR connectivity, which is critical for digital health products selling into many health systems.

**Partner ecosystem**

Many digital health apps and EHR vendors already use Redox, which shortens integration projects when both sides are on the platform.

#### Advantages

- Built exclusively for healthcare integration
- Reduces the EHR integration burden for product teams
- Strong compliance and security documentation for PHI

#### Disadvantages

- Enterprise-style pricing and contracting
- More developer-centric than no-code platforms
- Best fit for product vendors and large systems, not small practices

#### Ideal for

- Digital health vendors that sell into multiple EHRs and provider networks
- Health systems that want a centralized, standards-based integration layer
- Teams that want to run application logic on HIPAA-compliant hosting (e.g., Atlantic.Net) while offloading EHR connectivity to Redox

![](https://www.atlantic.net/wp-content/uploads/2025/12/ServiceNow-Logo.jpg)

### #4: ServiceNow

[ServiceNow](https://www.servicenow.com/products/healthcare-life-sciences.html)is a digital workflow platform best known for IT service management, but it is also used to automate clinical and operational processes in large healthcare organizations. The platform provides HIPAA-aligned security controls and is willing to sign BAAs, with documented guidance on HIPAA security and privacy controls.
 In healthcare, ServiceNow often sits at the center of IT, HR, facilities, and sometimes clinical operations, with IntegrationHub connecting out to other systems.

#### Notable features

**IT and enterprise service workflows**

Out-of-the-box workflows for incidents, requests, change management, and asset tracking, which can be extended to support clinical support queues and device management.

**IntegrationHub with prebuilt “spokes”**

Library of connectors and flow actions that link ServiceNow to EHRs, identity providers, collaboration tools, and infrastructure, including HIPAA-compliant clouds.

**Governance and policy enforcement**

Strong role-based access, approval flows, and policy controls are built in, which helps security and compliance teams maintain oversight.

**Healthcare-specific solutions**

Healthcare and life-sciences modules, plus partner-built content, provide pre-designed workflows for patient operations and regulatory processes.

#### Advantages

- Deep capabilities for large, complex organizations
- Mature governance, audit, and reporting features
- Can centralize IT, business, and some clinical workflows on one platform

#### Disadvantages

- Licensing and implementation can be significant investments
- Requires skilled admins and developers for advanced use cases
- Overkill for smaller practices or single-clinic deployments

#### Ideal for

- Large health systems with existing ServiceNow footprints
- Organizations that want a single platform for IT, security, and operational workflows touching PHI indirectly
- Teams that host clinical systems on HIPAA clouds, such as Atlantic.Net, need a central operational layer on top

### ![](https://www.atlantic.net/wp-content/uploads/2025/12/n8n.png)

### #5. n8n (self-hosted)

[n8n](https://n8n.io/workflows/3694-multi-agent-ai-clinic-management-with-whatsapp-telegram-and-google-calendar/)is an open-source workflow automation tool with a node-based visual builder. It is **not** HIPAA-certified as a SaaS product and does not sign BAAs, but it is often self-hosted inside private clouds or data centers to support regulated use cases.
 When it is deployed on a HIPAA-compliant hosting platform with appropriate controls, n8n can be part of a compliant automation stack. In that model, PHI never leaves your protected environment.

#### Notable features

**Self-hosted open-source deployment**

The core platform is open source, so it can be run on your own Linux or Windows servers, containers, or Kubernetes clusters. HIPAA-ready hosting providers like Atlantic.Net can supply the audited infrastructure, BAA, and security services beneath it.

**Visual, node-based workflow builder**

Workflows are built as graphs of nodes (triggers, logic, and actions). This gives technical teams a clear view of data paths and error points.

**Large integration surface**

Hundreds of community and official nodes connect to APIs, databases, queues, and internal services. Custom nodes and webhooks can be used for in-house apps running on Atlantic.Net.

**Compliance-friendly architecture (when configured)**

Because all data stays in your environment, you can align storage, logging, backups, and access control with your own HIPAA program rather than relying on a third-party SaaS model.

#### Advantages

- Full control over data location and infrastructure
- No per-workflow or per-user licensing in the open-source core
- Flexible enough to glue together EHRs, legacy systems, and modern APIs

#### Disadvantages

- Vendor does not provide HIPAA certification or a BAA; compliance depends entirely on your hosting and configuration
- Requires engineering and DevOps skills to run, secure, and monitor
- Fewer healthcare-specific connectors than dedicated healthcare platforms

#### Ideal for

- Technical teams that prefer open-source tools and already manage HIPAA-compliant infrastructure
- Organizations hosting core systems on Atlantic.Net that want a flexible automation layer in the same environment
- Vendors that need custom integrations where off-the-shelf SaaS options do not fit

## Bringing your HIPAA Automation Stack Together

HIPAA-compliant workflow automation is not only about the tools themselves. It’s also about how those tools are connected, where they run, and how PHI moves through each step. Platforms such as Keragon, Workato, Redox, ServiceNow, and n8n each cover different parts of the picture, from no-code clinical flows to deep EHR integration and self-hosted engines. With the right combination, care teams can streamline intake, referrals, billing, and operational workflows while maintaining tight control over sensitive data.

A common approach is to pair these platforms with a hardened hosting layer for any components you need to run yourself. Self-hosted elements, such as n8n, interface engines, RPA bots, custom APIs, or the databases that support them, can be placed on HIPAA-ready infrastructure. SaaS tools that operate as Business Associates then connect in over secure, audited channels. This model keeps PHI within a clearly defined boundary while still giving teams the flexibility to build and adapt automations as their needs evolve.

A HIPAA-compliant provider such as Atlantic.Net can supply that boundary. With our HIPAA-Compliant hosting, your team can:

- Host self-managed automation engines (for example, n8n or other integration services) inside a HIPAA-audited environment under a BAA.
- Deploy custom workflow services that extend Keragon, Workato, Redox, or ServiceNow without moving PHI into general-purpose clouds.
- Keep EHR-facing integrations, queues, and databases close to your core clinical systems, with encryption, access control, and monitoring handled at the infrastructure level.

When workflow platforms are selected with healthcare in mind, and the hosting environment is built for HIPAA, automation no longer requires a trade-off between speed and safety. You gain fewer manual steps, more consistent processes, and a clear audit trail for security and compliance teams, all while keeping ePHI on infrastructure that was built to protect it.

If you are planning your next HIPAA automation project, consider placing your eligible workflow tools and supporting services on [Atlantic.Net HIPAA-Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and speak with our team about creating the right-sized environment for your clinical, operational, and billing workflows.


---

# What to Look for When Searching for Top HIPAA-Compliant Hosting Companies

> URL: https://www.atlantic.net/hipaa-compliant-hosting/what-to-look-for-when-searching-for-top-hipaa-compliant-hosting-companies/ | Published: 2025-12-15 | Updated: 2025-12-16 | Author: Hitesh Jethva

With digital advancements in healthcare, patients increasingly access services and reports via secure digital channels. However, with every data transfer comes a responsibility for healthcare providers: safeguarding [electronic protected health information (ePHI)](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) while maintaining operational efficiency.

The Health Insurance Portability and Accountability Act (HIPAA) sets strict rules to keep this information private and secure. To maintain compliance, healthcare organizations need special HIPAA-compliant hosting services, not just regular web hosting. A significant amount of patient-related information is stored during consultation, diagnosis, or hospital admission. Even a single mistake or data leak could cost millions in fines, destroy patient trust, and even lead to legal trouble. Hence, choosing the right hosting company is critical.

In this guide, we will help healthcare professionals and organizations understand the key requirements for a HIPAA-compliant hosting solution. Whether you run a small clinic or a large healthcare system, this guide will help you understand [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and the critical factors to consider.

## Understanding HIPAA-Compliant Hosting Requirements

HIPAA-compliant hosting is not only about offering basic security but involves detailed security measures essential to safeguard sensitive data throughout its lifecycle. These requirements ensure that electronic protected health information gets the highest protection through specialized HIPAA-compliant hosting solutions.

### Essential Certifications and Business Associate Agreements

Partnering with a trusted HIPAA-compliant hosting provider requires clear legal frameworks that define each party’s responsibilities for protecting patient data. These agreements ensure that healthcare providers are legally protected under [HIPAA regulations](https://www.atlantic.net/hipaa-compliant-hosting/what-is-hipaa-compliance-history-rules-and-requirements/) while the hosting provider meets all compliance requirements.

#### Business Associate Agreement Requirements

A [Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) is a legal contract between a healthcare organization (like a hospital, clinic, or insurance company) and a third-party vendor (i.e., a hosting provider) that works with patient data. The BAA explains how Protected Health Information (PHI) must be handled and protected to meet [HIPAA rules](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/). These agreements include security requirements, breach notification procedures, and incident response protocols.

A complete and detailed BAA is essential for HIPAA compliance. As a healthcare provider, you should avoid a hosting partner that refuses to sign a proper BAA.

Some of the essential BAA components are:

- **PHI Definition:** A clear explanation of what counts as PHI within the agreement.
- **Permitted Uses and Disclosures:** Details on how PHI can be used or shared, ensuring it aligns with HIPAA requirements.
- **Security and Safeguards:** Requirements for following the HIPAA Security and Privacy Rules to protect data from breaches or misuse.
- **Breach Notification Procedures:** A set process for quickly reporting and managing any data breaches or security incidents.
- **Subcontractor Compliance:** Rules ensuring that any third parties or subcontractors with PHI access also follow HIPAA standards.
- **Data Retention and Termination Policies:** Guidelines for how PHI should be stored, retained, and securely destroyed once the contract ends.

#### Critical Certifications

A few other certifications to check and verify for HIPAA-compliant hosting providers by third-party auditors include:

- SOC 2 Type II evaluates a provider’s security controls over time.
- HITRUST certification is designed to meet healthcare industry standards.
- ISO 27001 ensures international best practices in information security management.
- Compliance with state-specific privacy laws: to meet local regulations.

### Ongoing Monitoring:

Apart from earning certification, it is equally important to maintain ongoing monitoring to stay compliant. This includes:

- Performing regular security assessments to find and fix vulnerabilities.
- Tracking and reporting compliance metrics.
- Training staff to stay up to date with the latest HIPAA regulations.
- Updating documentation regularly to reflect any changes in security standards or HIPAA requirements.

### The HIPAA Security Rule Framework: Core Requirements for HIPAA-Compliant Hosting

Each hosting provider must follow the HIPAA Security Rule which defines three main types of safeguard categories to keep patient data safe. Following this HIPAA Security Rule Framework, it will be easier to maintain HIPAA-compliant operations.

The three safeguard categories are:

#### #1: Technical Safeguards:

There are certain technical safeguards that HIPAA-compliant hosting companies must provide to protect information and maintain full HIPAA compliance.

- **Data encryption:** Involves using AES-256 algorithms for data at rest and TLS protocols for transit for encryption.
- **Access controls**: Implementing role-based permissions allows limited data exposure and more protection to health information.
- **Multi-factor authentication:** Involves multiple verification methods for administrative access.
- **Transmission security:** Prevents unauthorized access during electronic transfers.
- **Automatic session timeout**: Helps prevent any unauthorized access.

##### Encryption and Data Protection

Data encryption is the core of HIPAA-compliant hosting solutions. By implementing these security measures, organizations help keep patient information safe from unauthorized access.

Some of these protection layers include:

**Encryption Recommendations:**

- AES-256 data encryption for all data at rest including databases and backups
- Transport Layer Security (TLS) ensures data stays private during transmission with encryption.
- End-to-end encryption so that only the sender and receiver can read the data.
- File Level Encryption.
- Encrypted offsite backups with geographically distributed storage.
- Hardware Security Modules (HSMs) for encryption key security.

**Advanced Protection:**

- Data loss prevention (DLP) tools to track how sensitive information is used or shared.
- Tokenization replaces real patient data with random codes, reducing risk if a breach occurs.
- Secure deletion makes sure that old or unused data is completely erased.

##### Authentication and Access Management

HIPAA-compliant server configurations must have strong access management to ensure that only authorized individuals can view or handle sensitive patient information. Access management starts with multi-factor authentication (MFA), which requires users to verify their identity using more than one method, such as a password and a mobile code. Role-based access controls (RBAC) are also essential; they limit what each user can see or do based on their specific job role.

To make access easier and more secure, single sign-on (SSO) systems allow users to log in once and access multiple tools safely, reducing password fatigue while maintaining security. Session management adds another layer of protection by automatically logging users out after periods of inactivity and detecting suspicious behavior. Integration with directory services like Active Directory is another security layer that is crucial for healthcare security.

Apart from controlling access, HIPAA requires detailed monitoring and auditing. Every login, data access, and change must be tracked through audit trails that record who did what and when. Real-time monitoring systems watch for unusual activity, sending automatic alerts if something looks suspicious. Furthermore, log retention policies also help ensure that these records are securely stored for the required time. This helps organizations meet HIPAA requirements and support investigations if needed.

##### Network Security Infrastructure

HIPAA-compliant [cloud environments](https://www.atlantic.net/cloud-platform/cloud-hosting/) need strong network security to keep patient data safe from online threats. A web application firewall (WAF) acts as the first line of defense, blocking harmful traffic and detecting attacks on healthcare applications. Network segmentation further strengthens security by dividing systems into smaller sections (micro-segmentation), so if one area is compromised, others stay protected.

To catch threats early, intrusion detection systems (IDS) are another security measure that helps continuously monitor network traffic using healthcare-specific threat intelligence, while DDoS protection ensures that applications remain available even during heavy attacks. Advanced measures like zero-trust architecture, behavioral analytics, and automated threat response tools help quickly contain and fix security issues.

Having these in your hosting solutions will help watch, verify, and defend healthcare data from every angle.

#### #2: Physical Safeguards:

Physical safeguards mean offering protection to the actual places where patient data is stored or accessed. This includes securing data centers with enterprise-grade controls, such as biometric access systems, to ensure only authorized staff can enter. Data centers must also have environmental protections like backup power, cooling systems, and fire suppression to prevent damage or data loss during emergencies. When old equipment is no longer used, it must be securely disposed of so that no one can recover sensitive information from it.

Additionally, visitor management systems with detailed access logs help track who enters and exits the facility. Many providers also use multiple data center locations to ensure redundancy and compliance, meaning that data stays safe and accessible even if one site experiences an issue.

#### #3: Administrative Safeguards:

Administrative safeguards focus on the policies and procedures that guide how people and organizations handle patient data. This includes creating Business Associate Agreements (BAAs) that clearly define legal responsibilities for protecting health information. It also involves training employees to understand HIPAA rules and how to follow them. Organizations must have incident response plans to quickly detect and manage data breaches within required timeframes.

Regular HIPAA compliance audits help find and fix security gaps, while continuous monitoring systems ensure ongoing adherence to HIPAA standards. These safeguards make sure everyone in the organization knows their role in keeping patient data secure.

### Service Models

HIPAA-compliant web hosting includes different service models that let healthcare providers choose what works best for their needs.

#### Shared Responsibility Model

HIPAA-compliant hosting works on a shared responsibility model. Under this model, the responsibility to keep patient data safe belongs to both the healthcare organization and the hosting provider. The healthcare organization manages application security, patient data, and training of staff on HIPAA rules. The hosting provider takes care of the infrastructure security, i.e., making sure servers, networks, and data centers meet HIPAA compliance standards.

#### Infrastructure Options

##### Dedicated Server

A [**dedicated server hosting**](https://www.atlantic.net/dedicated-server-hosting/) setup gives healthcare providers full control over their data and systems. Investing in this HIPAA-compliant model will help keep resources completely separate from others. Furthermore, offers consistent performance and makes it easier to pass HIPAA audits since everything is managed in-house. In short, the control over HIPAA-compliant server configuration will entirely belong to you.

##### Cloud Hosting providers

If you opt for HIPAA-compliant cloud hosting solutions, you will gain more flexibility and scalability. It lets organizations easily adjust their resources as they grow while still maintaining strict HIPAA standards. These platforms often include automation tools that simplify system management and updates.

##### Web Hosting solutions

HIPAA-compliant web hosting solution is another option that focuses on hosting patient portals, healthcare websites, and telehealth applications. These services are built with strong security to protect patient data and often include HIPAA-compliant email services integration and monitoring to detect any suspicious activity.

In short, these HIPAA-compliant web hosting platforms are designed to support healthcare apps, record access, and engagement tools, everything that helps connect patients and providers safely.

#### Managed vs Unmanaged Services

[Managed services](https://www.atlantic.net/managed-services/) help healthcare providers focus on patient care while experts handle the technical side of HIPAA compliance. With fully managed hosting, the provider takes care of server setup, security configuration, and daily operations. They monitor systems for threats, manage vulnerabilities, perform regular offsite backups, and assist with compliance audits to keep everything secure and up to date.

Specialized support teams with healthcare experience also help improve business processes, integrate medical record systems, and plan for business continuity in case of outages. They conduct risk assessments, provide compliance reports, and ensure smooth data management.

While some hosting companies offer unmanaged hosting solutions, where the organization handles all administration on its own. Most healthcare providers go with managed services because they save time, reduce risk, and maintain continuous HIPAA compliance with expert support.

## Atlantic.Net: Your HIPAA-Compliant Web Hosting Partner

Atlantic.Net has established itself as a trusted HIPAA-compliant hosting provider over the years by delivering secure infrastructure for healthcare providers.

### Extensive Infrastructure Solutions

Interested users might find our [Atlantic.Net HIPAA-compliant hosting services](https://www.atlantic.net/hipaa-compliant-hosting/) highly beneficial, thanks to their complete hosting solution options that come with certified secure facilities across the United States.

**Core Platform Features:**

- Certified facilities with SOC 2 and SOC 3 compliance meeting HIPAA security requirements
- HIPAA/HITECH audited infrastructure demonstrating healthcare industry readiness
- Business Associate Agreement (BAA) available upon request for covered entities and business associates
- 100% Network and Infrastructure SLA
- 24/7 technical support

**Infrastructure Options:**

- Dedicated server hosting providing isolation and HIPAA-compliant server configuration
- HIPAA-compliant cloud environments supporting scalable growth
- Hybrid hosting solution combinations integrating on-premises with cloud hosting
- HIPAA-compliant Linux and HIPAA-compliant Windows platform support
- HIPAA-compliant Linux systems optimized for applications and medical data processing
- Cloud server capabilities supporting analytics, medical data processing, and research

[Atlantic.Net](https://www.atlantic.net/) offers specialized healthcare hosting services designed to meet the strict regulatory and operational needs of healthcare providers. Our managed services include proactive system monitoring, HIPAA compliance tracking, regular security patching, and encrypted offsite backups to ensure data integrity.

With a team experienced in healthcare workflows, our engineers can assist with HIPAA audit preparation, compliance integration, and medical data lifecycle management. We provide tailored hosting solutions for various use cases. Beyond standard website hosting, we also deliver secure environments for patient portals, documentation systems, and marketing platforms.

### Conclusion

Choosing the right HIPAA-compliant hosting provider requires a careful balance between technology, security, compliance, and long-term partnership potential. Start by verifying their Business Associate Agreement (BAA), third-party certifications, and compliance monitoring practices. Make sure they have a strong incident response plan, well-trained staff, and clear processes for maintaining ongoing HIPAA compliance.

It’s also important to assess the provider’s technical capabilities. Make sure to review their hosting architecture, encryption methods, monitoring systems, and disaster recovery processes to ensure they meet all HIPAA standards.

During implementation, plan data migration carefully to protect patient information, train staff on new systems, and continuously monitor for compliance. A strong hosting partner should not only provide secure infrastructure but also offer consistent support, guidance, and expertise to help healthcare organizations stay compliant as technology and regulations evolve.

Covered Entities must ensure HIPAA compliance across all business associates and hosting provider relationships while maintaining complete HIPAA compliance.

Ready to invest in a trusted and fully managed HIPAA-compliant service? Atlantic.Net offers tailored environments built with advanced security, proven compliance, and industry expertise. Thus, ensuring healthcare service providers can focus on patient care while maintaining complete peace of mind.

 


---

# Top HIPAA Compliant Web Hosting Services for Secure Data Management

> URL: https://www.atlantic.net/hipaa-compliant-hosting/top-hipaa-compliant-web-hosting-services-for-secure-data-management/ | Published: 2025-12-16 | Author: Hitesh Jethva

Healthcare organizations face distinct challenges in managing sensitive data while adhering to federal regulations. The Health Insurance Portability and Accountability Act (HIPAA) of 1996, along with the HITECH Act, established standards requiring specialized hosting environments. The goal is protecting the integrity of electronic Protected Health Information (ePHI) from unauthorized access.

Selecting an appropriate HIPAA-compliant hosting service from reliable hosting providers is one of the most critical infrastructure decisions healthcare executives have to make. With [average healthcare data breaches costing over $10 million](https://www.ibm.com/think/x-force/healthcare-data-breaches-costliest) and HIPAA-compliance violations resulting in substantial fines, choosing the right solution is necessary for securing patient information and meeting regulatory standards.

This guide examines top HIPAA hosting solutions, required features, and best practices for selecting providers that deliver verified compliance while supporting innovation in the healthcare industry.

## Understanding Requirements for Electronic Protected Health Information

Unlike standard hosting, compliant solutions require specific frameworks that address the technical, physical, and administrative safeguards of the [HIPAA security rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/).

### Core Requirements for Effective HIPAA Solutions

Effective HIPAA solutions rest on understanding fundamental federal regulations, including HIPAA requirements . These requirements extend beyond basic security to include complete data protection, verifying compliance across all technology infrastructure.

Mandates require that hosting providers apply strict security controls to secure ePHI throughout its lifecycle. Organizations must partner with providers willing to sign a detailed HIPAA Business Associate Agreement (BAA) establishing legal accountability.

### Safeguard Categories (HIPAA Security Rule)

#### Technical Safeguards

- Strong encryption protecting data at rest and in transit.
- Access controls limiting exposure to ePHI based on role-based permissions.
- Audit logging to track all system activities.
- Automatic authentication mechanisms, including session management.
- Transport Layer Security (TLS) usage, implemented via SSL certificates, to encrypt communications.

#### Physical Safeguards

- [Secure data centers](https://www.atlantic.net/hipaa-data-centers/) with enterprise-grade security controls and biometric access
- Data centers featuring environmental controls through redundant power and cooling
- Strict procedures for secure equipment disposal.
- Data centers maintaining visitor management with detailed logs
- Data centers providing geographic distribution for redundancy

#### Administrative Safeguards

- BAA frameworks defining legal responsibilities.
- Workforce training so personnel understand HIPAA regulations.
- Incident response protocols enabling rapid breach detection.
- Regular audits to identify vulnerabilities.
- Systems to monitor adherence.

### Shared Responsibility Model

Hosting solutions operate under shared responsibility. Organizations handle [application security](https://www.atlantic.net/hipaa-compliant-hosting/application-security-requirements-in-the-hipaa-framework/), patient data management, and workforce training. Providers manage infrastructure security, data center protection, and platform operations.

## Key Features of HIPAA Compliant Hosting Solutions

Selecting valid HIPAA-Compliant solutions requires evaluating features that distinguish verified services from standard hosting.

### Infrastructure and Platform Requirements

HIPAA-compliant hosting infrastructure must provide strong foundations supporting secure healthcare application deployment. Dedicated servers offer maximum isolation, eliminating multi-tenant security risks while providing complete administrative control. Cloud server platforms provide scalability while maintaining appropriate security controls.

HIPAA-compliant cloud hosting solutions combine cloud computing benefits with thorough security controls. HIPAA-compliant cloud platforms and HIPAA cloud environments enable resource scaling supporting organizational growth while maintaining isolation. Cloud hosting architectures must apply network segmentation, encryption, full monitoring, and access controls, ensuring HIPAA-compliant environments for services like HIPAA compliant web hosting.

HIPAA-compliant server configurations require specialized hardening including operating system updates, application patches, firewall configuration, and complete logging. Multiple servers may be deployed across geographically distributed facilities providing redundancy, disaster recovery capabilities, and business continuity for enterprise customers managing critical applications.

### Security and Compliance Features

Thorough security features are the baseline of secure hosting:

#### Encryption and Data Protection

- Industry-standard encryption algorithms protecting data at rest
- Transport layer [encryption](https://www.atlantic.net/hipaa-compliant-hosting/encryption-for-hipaa-compliance/) providing secure data transmission
- End-to-end encryption for patient data transmissions
- Encrypted offsite backups stored in geographically disparate facilities
- Hardware security modules providing secure key management

#### Access Management

- [Multi-factor authentication](https://www.atlantic.net/managed-services/multi-factor-authentication/) mandatory for administrative access
- Role-based controls limiting information exposure based on minimum necessary principles
- Centralized identity management that powers healthcare technology systems
- Privileged access management with session recording
- Comprehensive audit trails documenting all access attempts

#### Network Security

- Web application firewall protection filtering malicious traffic for a HIPAA compliant website
- Network segmentation isolating systems from other applications
- Intrusion detection systems monitoring traffic
- DDoS protection ensuring application availability
- VPN connectivity providing secure remote access

## Legal and Regulatory Compliance

HIPAA-compliant hosting requires comprehensive legal frameworks, including a business associate agreement :

### Business Associate Agreements

The BAA is the primary legal document establishing the relationship. A detailed BAA must include specifications for handling ePHI, security requirements, breach notification procedures, and incident response protocols. Provisions should address subcontractor management, data retention policies, audit rights, and termination clauses. Organizations should disqualify any HIPAA-compliant hosting partner unwilling to sign detailed BAA documentation.

### Compliance Certifications

Verified providers undergo strict third-party audits. Key certifications include SOC 2 Type II audits, HITRUST certification, FISMA compliance, and ISO 27001 standards. Ongoing monitoring programs ensure providers maintain standards through regular assessments, vulnerability scanning, and staff training.

## Technical Safeguards and Security Controls

Technical safeguards are important components of HIPAA-compliant hosting, protecting information through thorough security controls.

### Data Encryption and Protection

Encryption forms the basis of secure hosting. Data encryption must use AES-256 for data at rest and TLS 1.2 or 1.3 for data in transit. Platforms must apply database-level encryption enabling granular controls, encrypted backup systems, and hardware security modules. Advanced protection includes Data Loss Prevention (DLP) systems monitoring movement, tokenization, and secure deletion procedures

### Monitoring and Audit Capabilities

Full monitoring enables healthcare organizations and healthcare providers who require HIPAA compliance to track system activities, detect security incidents, and maintain detailed compliance documentation required by regulations. HIPAA-compliance monitoring systems must provide real-time visibility into user access attempts, data modifications, and configuration changes.

Audit logging should track all interactions including access attempts, successful authentications, and data modifications. Log retention must meet requirements with secure, tamper-proof storage.

### Network Architecture

HIPAA-compliant network architectures must apply strict segmentation, isolating systems from other applications. Network segmentation through virtual LANs and software-defined networking limits potential breach impact.

Cloud environment architectures require additional security controls including virtual private cloud setup and dedicated network connections. Zero-trust network models eliminate implicit trust relationships, applying continuous verification.

## Selecting HIPAA Compliant Hosting Providers

Selecting appropriate HIPAA-compliant hosting providers requires systematic evaluation balancing technical capabilities, compliance services, cost considerations, and long-term partnership potential.

### Evaluation Criteria

#### Technical Capabilities

- Infrastructure options, including [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/), cloud server platforms, and hybrid hosting solutions
- Security setups meeting all requirements and supporting technical safeguards
- Facilities locations, certifications, and operational procedures
- Disaster recovery capabilities including backup systems
- Performance characteristics supporting application requirements
- Scalability supporting organizational growth

#### Compliance Framework

- Willingness to sign detailed agreements
- Current certifications including SOC 2 Type II and HITRUST
- Monitoring programs and ongoing assessments
- Compliance services availability including audit support
- Experience serving organizations with a demonstrated understanding
- References from current healthcare clients

#### Service and Support

- [Managed services](https://www.atlantic.net/managed-services/) availability including system administration
- Technical support responsiveness and availability
- HIPAA-compliance support services assisting with regulatory adherence
- Migration assistance for a secure transition
- Training programs educating staff on platform usage
- Account management providing strategic guidance

### Common Pitfalls

Healthcare organizations frequently encounter challenges when selecting providers:

#### Warning Signs

- Many providers make misleading claims about capabilities without providing legitimate frameworks or demonstrating actual skill.
- Generic security features marketed as HIPAA-compliant services without healthcare-specific setup represent major red flags.
- Insufficient experience addressing clinical workflow requirements, inadequate incident response procedures, and missing support capabilities indicate that providers lack the necessary skills.

#### Due Diligence

- Verify status through independent audit documentation
- Review terms carefully with legal counsel
- Confirm facilities meet physical security requirements
- Validate staff training and knowledge
- Test support responsiveness through pilot projects
- Assess long-term viability evaluating financial stability

## Atlantic.Net: Premier HIPAA Hosting Services

Our HIPAA-compliant hosting services provide complete hosting solutions with certified secure facilities strategically located throughout the United States. These facilities maintain the highest physical security levels and undergo regular audits including SOC 2 Type II and HITRUST certification.

### Core Platform Features

- Certified facilities with SOC 2 Type II compliance
- HITRUST certification demonstrating security knowledge
- A detailed business associate agreement included with all hosting services
- 100% uptime SLA ensuring continuous operations
- 24/7 technical support from trained engineers

### Infrastructure Options

- Dedicated servers providing complete isolation and configuration
- HIPAA-compliant cloud environments supporting scalable growth
- Hybrid solutions integrating on-premises with cloud hosting resources
- HIPAA-compliant cloud hosting platforms featuring full security
- Cloud server capabilities supporting analytics and research

### Managed Services and Support

Atlantic.Net managed services approach recognizes organizations need reliable technology partners, allowing them to focus on patient care while maintaining operations.

- **Management Services:** Full system administration, proactive monitoring, patch management, and vulnerability remediation.
- **Healthcare Expertise:** Specialists understanding regulatory challenges, business process optimization, and data lifecycle management.

## Implementation and Compliance Management

Successful implementation requires careful planning, systematic execution, and ongoing management ensuring organizations stay compliant with evolving regulatory requirements.

### Migration and Implementation

Organizations transitioning must develop comprehensive migration strategies minimizing operational disruption while ensuring patient data security. Migration planning should address application compatibility, data transfer procedures, security validation, staff training, and cutover coordination.

#### Implementation Phases

- Assessment and planning evaluating current infrastructure
- Hosting environment preparation including infrastructure provisioning
- Data migration executing secure transfer procedures
- Application deployment installing applications
- Security validation conducting penetration testing
- Staff training, educating personnel on new systems
- Cutover execution transitioning production operations

### Ongoing Compliance Management

Maintaining HIPAA-compliance requires continuous monitoring, regular assessments, and proactive management to ensure hipaa compliance , ensuring configurations remain aligned with regulations. Organizations must establish governance frameworks defining responsibilities and oversight mechanisms.

#### Compliance Activities

- Tracking security metrics, compliance status, and emerging threats
- Regular security assessments and conducting vulnerability scans
- Audit preparation, maintaining documentation
- Incident response planning and testing, validating procedures
- Policy reviews ensure procedures remain aligned
- Staff training programs to maintain current knowledge

### Continuous Improvement

Organizations should implement continuous improvement programs, optimizing performance, security, and cost-effectiveness while maintaining comprehensive compliance. Performance monitoring identifies optimization opportunities, capacity planning supports growth requirements, and security enhancements address emerging threats.

Service provider partnerships should include regular business reviews assessing performance metrics, discussing optimization opportunities, reviewing compliance status, and planning future enhancements. Managed hosting providers should provide a reliable service with proactive recommendations and strategic guidance.

## Partnering for True HIPAA Compliance

Selecting the right partner establishes foundations for long-term success in healthcare technology operations. Organizations should prioritize providers demonstrating commitment, ongoing investment in security capabilities, transparent communication, and genuine partnership approaches.

Stay compliant with evolving regulatory requirements through partnerships with providers offering services, support, and expert guidance for complex compliance issues. True HIPAA-compliance requires ongoing commitment, continuous improvement, and collaborative partnerships.

A HIPAA covered entity must understand that the requirement for HIPAA compliance extends beyond technology to include people, processes, and partnerships. Success requires selecting providers willing to serve as true partners, providing not just infrastructure but complete solutions supporting healthcare missions.

Ready to look at services designed for your requirements? Atlantic.Net specialists can help design secure hosting environments tailored to your organization’s unique needs and regulatory requirements. Our approach combines technical knowledge, regulatory knowledge, experience, and personalized support ensuring success while maintaining full HIPAA-compliance.

Additional security features including HIPAA compliant email services, secure sockets layer and TLS certificates for secure web communications, secure environment architectures protecting data, and full monitoring ensuring many hosting companies cannot match our specialization and commitment to compliance.

Discover how [Atlantic.Net](https://www.atlantic.net) can support your HIPAA compliance services goals today.

 


---

# Best HIPAA-Compliant Email Service in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-email-services-2026/ | Published: 2025-12-17 | Updated: 2026-01-06 | Author: Hitesh Jethva

If your healthcare team relies on email daily, securing patient data is critical. With high volumes of sensitive information shared through inboxes, a HIPAA-compliant email solution is mandatory. A HIPAA-compliant email solution ensures that PHI sent electronically is protected from unauthorized access, tampering, and data breaches.

Standard free email services do not protect health information. They lack the required encryption, access controls, and compliance agreements. Consequently, your risk of exploitation or a data breach is high. To prevent such costly breaches, it is essential to invest in the right solution.

This guide breaks down what HIPAA-compliant email really means, the key features to look for, and who needs it most. Additionally, we have compiled a list of the top secure email solutions available today.

## What Is HIPAA-Compliant Email?

The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that protects the privacy and security of Protected Health Information (PHI). PHI covers any information that can help identify a patient, such as their name, test reports, medical records, and billing details.

Whenever information related to a patient is shared electronically, HIPAA requires healthcare organizations to use secure methods that keep the data protected at all times. HIPAA-compliant email is one such method that keeps PHI private and safe. This email service includes strong security features like encryption, access controls, and audit logs to achieve this goal.

If you believe free versions of Gmail, Yahoo, or Outlook are secure enough for sending PHI, you are mistaken. They lack specific security features and do not provide a Business Associate Agreement (BAA) by default. HIPAA-compliant email fills these security gaps, making sure sensitive patient information is handled safely and legally.

## Key Features to Look For in a HIPAA-Compliant Email Provider

When choosing a HIPAA-compliant email solution, you must identify the features that keep patient information safe and help organizations meet regulatory requirements. The following features are essential:

- **End-to-End Encryption:** This feature ensures that emails are protected not just while they are being sent but also while they are stored. With strong encryption, PHI stays unreadable to anyone except the intended recipient.
- **Access Control:** HIPAA requires strict access controls. Verify if your email provider offers settings like multi-factor authentication, role-based permissions, automatic session timeouts, and zero-trust access policies. These protections help prevent unauthorized access, whether from a stolen password or someone using an unsecured device.
- **Audit Trails and Monitoring:** A compliant email platform must keep detailed logs of everything that happens, including login attempts, sent and received messages, forwarding activity, admin changes, or any unusual behavior. These records are critical as they help find security issues, respond to incidents faster, and prepare for HIPAA audits.
- **Business Associate Agreement (BAA):** A BAA is a legal document stating that the vendor accepts responsibility for protecting PHI according to HIPAA rules. Every HIPAA-compliant email provider must sign a Business Associate Agreement (BAA). Without a signed BAA, even the most secure email system cannot legally be used for patient information.

## Use Cases for HIPAA-Compliant Email

HIPAA-compliant email is essential across the healthcare industry. Each type of organization must rely on a secure communication method to keep operations running smoothly while protecting patient data.

- **Hospitals:** Used for sharing clinical updates, coordinating between departments, or communicating with labs, pharmacies, and specialists. With many people involved in patient care, encrypted email keeps information protected.
- **Clinics and Private Practices:** From sending follow-up instructions to managing referrals, appointment reminders, and day-to-day admin work, a secure email system helps providers stay connected without risking patient privacy.
- **Telehealth Providers:** Since virtual care runs entirely on digital communication, encrypted email ensures that diagnostic reports, prescriptions, images, and remote monitoring data are exchanged safely and legally.
- **Insurance Companies and Payors:** Claims processing, benefits verification, prior authorizations, and appeals involve PHI. Using a compliant email platform helps protect patient data while speeding up coordination between insurers, providers, and patients.

Secure email is the foundation of efficient healthcare communication. Review the best HIPAA-compliant Email Solutions in the market and compare them before making a final investment.

## Top 10 HIPAA-compliant Email Solutions

Here are top HIPAA-compliant email providers that help you stay compliant and protected.

### Paubox

![](https://www.atlantic.net/wp-content/uploads/2025/12/paubox.png)

[Paubox](https://www.paubox.com/solutions/healthcare) is an AI-powered email security solution that helps healthcare organizations protect PHI. The solution comes with built-in email encryption and AI-powered inbound threat protection features that make sure all health information, billing details, and data are safe and secure at all times. It is a HITRUST CSF-certified HIPAA-compliant email service that is easy to set up and supports integration with other platforms, including Office 365 and G Suite. It even comes with the ability to detect and block evolving email attacks, thanks to its advanced AI features.

### Virtru

![](https://www.atlantic.net/wp-content/uploads/2025/12/virtu.jpg)

Virtru is another trusted email provider that makes the whole process of sharing health information seamless and secure with its encryption, access control, and other security features. It further allows secure collaborations and audit data sharing. Healthcare Organizations looking for a HIPAA Compliant Email and File Transfer system must opt for this as it further includes signed BAA, encrypted file sharing up to 15 GB, granular audit trails, and more.

### LuxSci

![](https://www.atlantic.net/wp-content/uploads/2025/12/luxci.png)

LuxSci is a HIPAA compliant, multi-channel solution that offers email security, PHI-powered personalization, and seamless integration with CDP, EHR, and RCM systems. It is built specifically for organizations that need strong security without sacrificing usability. You no longer need to worry about outgoing messages as it automatically encrypts every outgoing message, so protected health information stays secure. You require no extra steps or plugins to achieve results.

Beyond secure email, LuxSci also provides compliant web and email hosting, giving healthcare organizations an all-in-one environment. Their secure web forms add even more flexibility, offering options like ink-style signatures, custom fields, and dynamic form features.

### NeoCertified

![](https://www.atlantic.net/wp-content/uploads/2025/12/neo-certified-plc.png)

[NeoCertified](https://neocertified.com/hipaa-compliant-email/) is an all-in-one email solution built for healthcare teams. If you as an healthcare organization are looking for a HIPAA-safe email, the platform offers both a fully secure email portal and seamless integration with familiar tools like Gmail and Outlook.

With NeoCertified, you’ll find audit-ready access controls, identity authentication, strong transmission security, and the required Business Associate Agreement (BAA), all backed by a support team available 24/7. Their military-grade encryption ensures that every message, attachment, and interaction remains protected. Whether sending from a secure web portal, through Outlook/Gmail, or via the mobile app when you are on the go, NeoCertified keeps PHI safe from phishing, interception, and other threats.

### MailHippo

![](https://www.atlantic.net/wp-content/uploads/2025/12/mail-hippo.png)

If you are looking for something more than just a secure email provider, MailHippo is the right choice. It is an affordable HIPAA-compliant email solution designed to protect privileged medical data. You do not require any configuration or setup. With MailHippo secure email services, you can seamlessly work across multiple devices and ensure secure encrypted emails and HIPAA compliance. Interested users can even try the 30-day free trial before opting for paid solutions.

### Proton Mail

![](https://www.atlantic.net/wp-content/uploads/2025/12/ProtonMail_logo.svg_.png)

Proton Mail is well-known for its strong focus on privacy, but when it comes to HIPAA-related use cases, there are a few important things to understand. By default, Proton Mail automatically encrypts messages only when both the sender and recipient use Proton accounts. If you need to send an encrypted message to someone outside Proton, you’ll have to set a password for the email and share that password with the recipient so they can open it, adding a small extra step to the process.

Yet, most healthcare organizations opt for it because it offers strong end-to-end encryption, storage in secure data centers, and self-destructing emails. When using this email service, no personally identifiable data is tracked or logged that to its zero-access encryption feature.

### Aspida Mail

![](https://www.atlantic.net/wp-content/uploads/2025/12/aspida-logo.png)

A popular HIPAA-compliant email solution built for simplicity and security. It is best for healthcare teams who want encrypted communication without the technical assistance. You also get a Business Associate Agreement (BAA) and clear email policy support. The platform further uses AES-256 encryption, both in transit and at rest, keeping sensitive health information well-protected.

Behind the scenes, Aspida’s system automatically checks your message for sensitive data like social security numbers or subscriber IDs and encrypts it if needed, helping avoid accidental PHI disclosure. For data protection and compliance, Aspida retains all your emails for six years in accordance with HIPAA requirements and offers unlimited backup during that period.

### Mimecast

![](https://www.atlantic.net/wp-content/uploads/2025/12/logo-dark-2021.png)

Over 42,000 customers trust Mimecast for its excellent solutions and services. It is an all-inclusive secure email solution for HIPAA compliance that uses AI to protect and secure your emails. It further offers encryption and data leak prevention capabilities. With this tool in hand, you can protect PHI from phishing, ransomware, and business email compromise (BEC) attacks. Additionally, it offers granular message control, option to set email expiration dates, and maintain readily accessible backups.

### Protected Trust

![](https://www.atlantic.net/wp-content/uploads/2025/12/Protected_Trust_Services_Logo.png)

Protected Trust offers a streamlined way for healthcare organizations to communicate securely and compliantly. They offer encrypted email communication and seamlessly integrate with existing email setup. Recipients don’t need to pay or sign up to read encrypted messages, which makes it easier for patients, partners, or vendors to engage. They also provide a secure virtual printer for Windows.

With a fingerprint-secure app, Protected Trust provides access to your email through integration with multiple devices. As a community-driven platform, customers are able to contribute to modifications and improvements.

### MaxMD

![](https://www.atlantic.net/wp-content/uploads/2025/12/maxmd.png)

MaxMD offers HIPAA-compliant communication and security tools designed specifically for the healthcare industry.  It is an Electronic Healthcare Network Accreditation Commission (EHNAC) accredited Health Information Service Provider (HISP), Registration Authority (RA), and Certificate Authority (CA), one of the first companies to achieve such accreditation. Their flagship solution, Max Direct mdEmail®, gives healthcare organizations an easy way to send and receive PHI securely. The platform includes all the technical safeguards required under HIPAA, such as strong encryption, detailed audit controls, identity verification, and strict access management.

MaxMD also provides a signed Business Associate Agreement (BAA), ensuring your organization stays fully compliant while exchanging sensitive patient information.

## Top HIPAA-Compliant Email Providers (2026 Comparison Table)

Here is a side-by-side comparison of the best HIPAA-compliant email services, highlighting their security features, encryption options, BAA availability, and pricing to help you choose the safest solution for protecting PHI.

| **Provider** | **Key Features** | **Encryption** | **BAA Included** | **Free/Paid** |
| --- | --- | --- | --- | --- |
| **Paubox** | AI threat protection, automatic encryption, HITRUST certified | Yes (Default, no portals) | Yes | Free trial is available. Paid plans start at $29/mo |
| **Virtru** | Encryption, access control, secure file sharing (15GB), audit logs | Yes | Yes | You can book a demo or opt for paid palns – Starter: $119/month Business: $219/month CMMC / FedRAMP / ITAR: $399/month Enterprise: Custom pricing |
| **LuxSci** | Automatic outbound encryption, PHI personalization, secure forms, hosting | Yes | Yes | Contact sales team |
| **NeoCertified** | Secure portal + Gmail/Outlook integration, 24/7 support, audit controls | Yes | Yes | Standard plan: $99/year per user Gold Plan: $199/Year/User Non-profit plan: 59/Year/User |
| **MailHippo** | Easy setup, affordable, encrypted email, multi-device support | Yes | Yes | 30-day free trial is available. Basic plan: $4.95 Per Month / User Pro Plan: $7.95 Per Month / User |
| **Proton Mail** | Strong E2E encryption, zero-access model, self-destructing emails | Yes (with conditions for external recipients) | No (must be arranged separately) | Opt for free plan or go with paid plans: Mail Plus: €2.49 /month Proton Unlimited: €6.49 /month Proton Duo: €14.99 /month |
| **Aspida Mail** | AES-256 encryption, automatic PHI detection, 6-year retention | Yes | Yes | Starting at $10/mo |
| **Mimecast** | AI security, DLP, anti-phishing, backup, message expiration | Yes | Yes | Custom pricing |
| **Protected Trust** | Secure email, virtual printer, easy for recipients (no signup) | Yes | Yes | Contact Sales team |
| **MaxMD** | EHNAC-accredited HISP/RA/CA, secure PHI exchange, identity verification | Yes | Yes | Contact Sales team |

## Atlantic.Net’s HIPAA Hosting Solution

When you are handling sensitive patient information, keeping every part of your infrastructure HIPAA-compliant is not an option. Selecting a secure, HIPAA-compliant email provider becomes important, but if you think that’s all, remember it is only half of the equation. The other half is choosing a hosting platform that protects the storage, processing, and long-term handling of PHI without gaps. This is where Atlantic.Net comes in.

[Atantic.Net’s HIPAA Hosting platform](https://www.atlantic.net/hipaa-compliant-hosting/) gives healthcare organizations the flexibility to self-host secure email systems or integrate with trusted providers like Paubox. These integrations may help build a fully secured, end-to-end email and hosting environment tailored to your needs.

What sets Atlantic.Net apart is the infrastructure behind the promise. We offer high-performance [bare metal servers](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/), encrypted storage, [secure cloud environments](https://www.atlantic.net/cloud-platform/cloud-hosting/), and data center facilities, all designed with healthcare compliance at the core. Every deployment includes the safeguards required under HIPAA and HITECH, backed by industry-recognized certifications such as SOC 2 Type II and SOC 3 Type II. The environment is also independently audited to ensure that your PHI stays protected at every stage.

If you’re planning to upgrade your compliance posture or evaluate a new hosting provider, you can follow our detailed HIPAA Hosting Checklist that will help you compare requirements, features, and best practices. You can download it and use it as a guide while planning your next steps. For more information about customized HIPAA-compliant hosting and email solutions, [contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)!

## FAQs

- **What is a HIPAA-compliant email service?**

It is a secure email platform that protects electronic Protected Health Information (ePHI) from threats and breaches. It follows the HIPAA Security Rule requirements, including encryption, access controls, signed BAA, and more.

- **Do I really need a HIPAA-compliant email provider?**

Yes, all healthcare organizations that send, receive, or store any patient information electronically must invest in these solutions as regular emails like Gmail, outlook, etc. are not compliant by default.

- **Are services like Gmail or Outlook HIPAA compliant?**

No, the email services like Gmail and outlook are not HIPAA compliant by default but they can be made by signing a BAA with Google or Microsoft, configuring security settings, and using third party email providers to secure emails.

- **What is a Business Associate Agreement (BAA) and why is it important?**

A BAA is a mandatory legal contract between a healthcare provider and a service vendor. This agreement states that the vendor follows HIPAA standards and protects patient data. Without a BAA, using the service for PHI is not compliant, even if the platform is secure.

- **Are HIPAA-compliant email systems difficult to set up?**

Most modern providers make setup simple. Tools like Paubox, MailHippo, and NeoCertified require little to no configuration, while enterprise tools like Mimecast may need assistance.

 


---

# Why NVMe SSDs Matter in Dedicated Hosting | Speed & Latency

> URL: https://www.atlantic.net/dedicated-server-hosting/nvme-ssds-dedicated-hosting-performance-latency/ | Published: 2025-12-18 | Updated: 2025-12-19 | Author: Hitesh Jethva

Managing mission-critical applications, high-traffic websites, and data-heavy platforms is a challenge for modern businesses. Even small delays in accessing data can reduce speed, customer satisfaction, and productivity. Traditional storage solutions, such as HDD storage and SATA SSDs, often fail to keep up with modern demands. Consequently, developers and businesses require solutions that offer exceptional server performance.

[NVMe SSDs](https://www.atlantic.net/dedicated-server-hosting/whats-the-difference-between-hdds-sata-ssds-and-nvme-ssds/) in [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) make servers significantly faster and more stable, especially when processing a large number of users or data simultaneously. NVMe SSDs combine the power of dedicated hosting infrastructure with the advanced architecture of Non-Volatile Memory Express storage, making them a strong solution for improved server performance.

This guide discusses NVMe dedicated servers, how they change server performance, and what experts should consider when selecting one for their organization. We will also examine how deploying Dedicated hosting NVMe SSDs can increase performance.

## Understanding NVMe SSDs and Server Performance

NVMe (Non-Volatile Memory Express) is a storage technology changing the way servers store and access data.

Traditional server storage architectures involved various steps to reach the processor. This reduced system performance. In contrast, NVMe uses PCIe (Peripheral Component Interconnect Express) technology to minimize latency issues. Because NVMe reads data on a parallel model and communicates directly with the CPU, developers experience faster data transfer speeds.

### The Evolution of Server Storage

To read data sequentially or write data one piece at a time, traditional HDD storage (hard drives) relied on spinning platters and mechanical arms. The process was slow and caused delays or latency issues as operations happened in order. The introduction of SATA SSDs eliminated mechanical bottlenecks, but certain limitations remained.

For instance, SATA SSDs used flash memory instead of moving parts, which increased speed. Yet, they remained constrained by SATA interface bandwidth, an older technology designed when data needs were much smaller. Put simply, even if the speed improved, this technology struggled to handle today’s massive data requirements.

NVMe SSDs changed storage by using PCIe. This is a much faster connection type suitable for modern, high-speed peripherals. It allows NVMe drives to communicate directly with the CPU. This eliminates the need to pass through slower channels or multiple queues processing thousands of simultaneous commands.

NVMe drives are beneficial because they are scalable and effective. Unlike conventional drives, there is no need to wait in line with NVMe. These drives offer both raw speed and higher capacity for multitasking. Servers using NVMe can respond to user requests almost instantly, regardless of concurrent operation volume.

### How NVMe Technology Improves Operations

An NVMe Dedicated Server is a hosting configuration that modern businesses use for faster and more effective server performance. It uses NVMe storage over standard SATA or SAS hard drives, which reads and writes data simultaneously, resulting in faster data access. Allowing websites, apps, and databases to deliver information with minimal delay results in improved latency and responsiveness.

Traditional storage creates delays measured in milliseconds. This may seem small, but when thousands of operations happen at once, these delays add up. NVMe dedicated server hosting resolves this issue.

Besides speed, NVMe SSDs consume less energy. They use less power and produce less heat, reducing the need for extra cooling systems. With this solution, data centers can fit more servers in the same space, improving overall performance and cost-effectiveness.

### Impact on Applications

Users and developers can maximize benefits with NVMe dedicated servers. These servers eliminate storage-related bottlenecks and result in faster load times, even for high-traffic websites. With NVMe SSDs, the time spent fetching website files and database information drops as the drive performs both tasks simultaneously, increasing user engagement.

For developers building modern applications, the demand for fast storage, real-time data processing, and interactive features is high. NVMe servers fulfill this need. They help build applications with instant data visualizations and extensive data manipulation.

Scientists and analysts running big data operations or machine learning workloads also find it beneficial. These operations generally involve the processing of massive datasets that need constant access. Traditional storage often failed to meet these needs. NVMe SSDs are designed to handle these operations in minutes.

## Key Benefits of NVMe Dedicated Servers

Here are some of the benefits that come with the deployment of NVMe dedicated servers:

### Performance and Speed Advantages

The faster and more reliable storage options of NVMe dedicated servers make a big difference for businesses that need top performance. Modern PCIe Gen 4 NVMe offers read speeds of 7,000 MB/s and write speeds over 5,000 MB/s. By comparison, SATA SSDs provide a maximum of 600 MB/s.

Latency is another key performance metric. NVMe drives respond in under 20 microseconds, while SATA SSDs usually take 50–150 microseconds. In terms of consistency, even when many operations happen at the same time, NVMe servers maintain steady speed and low latency. SATA or older drives often slow down under heavy load.

If your business operates a high-traffic website or you demand extremely fast and reliable performance, NVMe dedicated servers excel.

### Reliability and Efficiency

NVMe dedicated servers are not only fast but also highly reliable. Unlike traditional hard drives, NVMe SSDs have no moving parts, eliminating the mechanical failures that can occur with HDDs. This makes them more durable with a longer operational lifespan. NVMe drives also use advanced technologies like error correction and wear leveling algorithms to maintain data accuracy and extend flash memory longevity.

Modern NVMe drives can handle millions of write cycles, allowing server infrastructure to manage heavy workloads consistently over many years. Additionally, lower latency increases reliability. NVMe SSDs complete operations almost instantly and reduce the risk of timeout errors that occur with storage delays.

### Scalability and Resources

Growing businesses that want to scale without infrastructure limitations will find NVMe dedicated servers a strong option. It supports scalability requirements by eliminating storage as a bottleneck. Businesses can add more users, increase transaction volumes, and expand application features without slowing down operations, thanks to fast NVMe storage.

In a dedicated server, all resources—such as CPU, RAM, storage, and bandwidth—are fully available, unlike shared hosting environments. In shared hosting, multiple virtual servers and websites compete for the same resources, resulting in limited access. In contrast, dedicated server hosting architectures let businesses access scalable resources for easy customization. Businesses can choose the right CPU, memory, storage size, and network settings that match their needs.

### Security and Control

In terms of security, NVMe dedicated servers offer stronger security than shared hosting or [VPS hosting](https://www.atlantic.net/vps-hosting/). With benefits like physical isolation and complete server control, the server reduces the risk of breaches.

Businesses also have full control over the server environment, which means they can set up custom configurations and security measures like firewalls, [intrusion detection systems](https://www.atlantic.net/hipaa-compliant-hosting/intrusion-detection-systems/), and other protections as needed. DDoS protection is also more effective. Hence, investing in hosting providers that can implement safeguards at the server level, offer protection against DDoS attacks and entire infrastructure, makes it a standout solution.

## Performance Specifications and Requirements

Apart from looking at benefits, it is equality important to understand performance specifications and technical requirements when selecting an appropriate NVMe dedicated server.

### CPU and RAM Specifications

The choice of CPU and RAM has a big impact on server performance. Modern processors come with different numbers of cores and speeds, so it’s important to check if they can meet your workload requirements. NVMe dedicated servers work best when a high-performance CPU configuration is paired with enough RAM.

Server CPUs can range from basic models for web hosting to powerful processors for heavy tasks like machine learning or big data processing. Businesses should choose a CPU based on how many users will be accessing the server at the same time and operational complexity.

RAM capacity is equally important. If a server doesn’t have enough memory, it will start using storage as “virtual memory,” which is much slower and reduces performance. Most modern applications require at least 64 GB of RAM. Hence, growing businesses should consider 64 GB as a baseline specification.

### Storage Capacity and Configuration

The amount of storage capacity may depend on the type of applications and data businesses use. NVMe dedicated servers are flexible. You can use a single drive or multiple drives to set up for better performance or reliability. Also, NVMe SSDs come in sizes from 480 GB up to 15.36 TB.

When selecting a solution based on storage capacity requirements, businesses should think about current data needs, future growth, and backup requirements. Advanced storage configurations combine multiple NVMe drives in [RAID arrays](https://www.atlantic.net/vps-hosting/what-is-raid/).

RAID 0 splits data across drives. RAID 1 copies data on two drives, and RAID 10 combines both speed and safety by striping and mirroring data. In short, businesses should select an option keeping both speed and reliability in mind.

### Network and Connectivity

To prevent network congestion, network infrastructure must support fast storage like NVMe SSDs. If the server’s network connection is too slow, it can become a bottleneck. Hence, investing in an NVMe SSD that can sustain multi-gigabit throughput is a good fit. Even businesses that serve multiple locations or target a global audience, investing in a hosting provider with geographic distribution can reduce delays and provide a fast experience for users everywhere.

## Choosing the Right Configuration

Specification matter but it is also important to carefully evaluate current requirement, application characteristics, and future needs when choosing a dedicated server configuration.

### Assessing Performance Requirements

Firstly, analyze performance requirement, i.e, expected user volume, transaction rate, and data processing demand. High-traffic websites often demand high CPU power, enough RAM capacity, and fast storage. Faster load times increase user engagement and conversions. Hence, remember that website performance expectations directly influence server specification requirements.

If you run database-heavy applications, RAM capacity and fast storage should be a priority because modern databases often use memory caching to store frequently accessed data in RAM for ultra-fast access.

### Evaluating Resources

Allocating server resources is about finding the right balance between performance, reliability, and cost. When choosing a CPU, businesses must consider core count and clock speed. For peak usage, RAM with 64 GB is the best solution for general applications. Storage planning also requires balancing how much space is needed, how fast it performs, and how reliable it is.

### Security Features

For protecting server infrastructure and data, strict security feature implementation is necessary. Hence, look for solutions that offer [DDoS protection](https://www.atlantic.net/managed-services/network-edge-protection/), firewall rules, intrusion detection systems, and other security measures. Hosting solutions like Atlantic.Net can be a good option for businesses as it implements enterprise-grade DDoS protection across all infrastructure.

## Atlantic.Net: Premium Dedicated Hosting NVMe SSDs

Atlantic.Net offers high-performance dedicated hosting NVMe SSD solutions for users and developers with comprehensive support and flexible configurations. This cutting-edge storage technology has helped millions of websites and applications perform better in the market and stay ahead of competitors.

### Comprehensive Solutions

If you are looking for exceptional performance, reliability, and energy efficient operation, Atlantic.Net NVMe dedicated server hosting infrastructure uses enterprise-grade NVMe drives. The infrastructure features include:

- Latest-generation SSDs with read speeds exceeding 7,000 MB/s
- Enterprise-grade CPU options with single and dual-processor systems
- RAM configuration from 64 GB to 512 GB
- 960 GB to multiple terabytes storage capacity
- DDoS protection

NVMe dedicated servers offer flexible deployment options, including single-drive setups for cost efficiency, multi-drive RAID configurations for speed and reliability, hybrid storage, and fully custom configurations.

### Advanced Features

Atlantic.Net

NVMe dedicated servers also comes with advanced features that may help maximize overall performance.

- **Performance optimization:** From offering direct PCIe connections to advanced caching and parallel processing, NVMe SSDs offer various features. This improves firmware for low latency.
- **Reliability enhancements:** NVMe dedicated servers enhance reliability with enterprise-grade drives, advanced wear leveling, error correction, redundant power, and effective thermal management.
- **Security capabilities:** Offers comprehensive security with physical data center protection, network-level DDoS mitigation, isolated environments, customizable firewalls, and full server control.
- **Management features:** NVMe dedicated servers provide full management capabilities with root access, remote management, configurable parameters, custom setups, and the flexibility to deploy any software stack.

[Atlantic.Net](https://www.atlantic.net) operates data centers across multiple locations, providing geographic diversity to support major markets. For growing businesses, investing in a hosting provider like Atlantic.Net can be a great benefit. The hosting solution offers redundant network connectivity, energy-saving operations, advanced cooling systems, and access to diverse carriers.

The support team can help customers match growing infrastructure requirements.

Atlantic.Net NVMe dedicated servers are a perfect solution for any business requiring high performance and exceptional reliability. By investing in this web hosting solution that combines modern storage technology and flexible configurations, developers and businesses can increase server performance. The dedicated resources, hosting infrastructure, and expertise give businesses a strong foundation to focus on technical development.

Want to experience the power of NVMe dedicated servers with fast access, lower latency, and high performance? Learn more about Atlantic.Net[Dedicated Hosting NVMe SSDs Solutions](https://www.atlantic.net/dedicated-server-hosting/) and make a right investment for your business today

 


---

# Bare Metal Server Hosting for Enterprises

> URL: https://www.atlantic.net/dedicated-server-hosting/bare-metal-server-hosting-for-enterprises/ | Published: 2025-12-19 | Updated: 2026-01-06 | Author: Hitesh Jethva

Enterprises are expanding, and their digital ecosystems are becoming more complex, raising the demand for better performance, control, and security systems. High-performance bare metal server hosting addresses these specific needs. This hosting model provides organizations with dedicated physical infrastructure instead of sharing resources through a virtualization layer.

In simple terms, a bare metal server is a single-tenant, fully dedicated physical server that runs directly on the hardware, without the interference of a [hypervisor](https://www.atlantic.net/vps-hosting/microsoft-hyper-v-or-vmware/) or other virtualized components. It is built specifically for high-performance workloads, critical applications, and enterprises that cannot afford to compromise speed, reliability, or compliance.

Enterprises today face major challenges, e.g., slow application performance issues due to shared resources, mounting compliance requirements like [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) and [GDPR](https://www.atlantic.net/vps-hosting/overview-of-ccpa-and-gdpr/), the need to scale rapidly without losing control of infrastructure, etc. Bare metal hosting solves these problems by offering maximum performance, enhanced security, and complete control over hardware and software environments while maintaining performance across workloads.

If your enterprise requires raw power, ultra-low latency, and resilient infrastructure, dedicated bare metal servers are the correct choice.

## What Are Bare Metal Dedicated Servers ?

Bare metal server hosting means having a dedicated server reserved for one client only. Unlike virtual servers or cloud servers, where multiple users share the same hardware through virtualization, a bare metal server gives you direct access to the server’s CPU, RAM, and storage.

In a shared hosting environment, applications share computing power and disk space with others. Resources are split among different sites and applications on the same server. With bare metal infrastructure, the setup is different. This solution provides dedicated resources with no “noisy neighbors” competing for bandwidth or memory.

Because there is no virtualization layer, workloads run with optimal performance and lower latency, which is essential for machine learning, big data analytics, financial trading, and other intensive workloads. Enterprises can get the most out of these servers thanks to their full root access, which allows IT teams to install custom operating systems, fine-tune configurations, and maintain complete control over their environment.

## How Bare Metal Hosting Works for Enterprises

The concept behind bare metal hosting is straightforward: you rent a high-performance physical server located in a secure data center that belongs entirely to your business. The enterprise is the sole client, ensuring consistent performance as no other user shares the server.

The server comes equipped with dedicated CPU cores, RAM, and storage, meaning your business gets 100% of the resources. The typical setup process involves:

- **Provisioning:** Enterprises can deploy new servers manually or through API integration, which automates setup and allows quick scaling across multiple locations.
- **Installing the operating system:** You can choose the OS that fits your business requirements, e.g.**,** Linux or Windows. This flexibility ensures your IT team works efficiently to run specific business applications or containerized workloads.
- **Network Configuration:** The IT team sets up private networks, firewalls, and load balancers to **ensure** better security, connectivity, and data protection.
- **Automation and Monitoring:** Modern bare metal hosting providers offer tools that let enterprises automate deployments, monitor performance, and manage servers remotely.

There is no hypervisor layer or resource contention. Since these servers are fully dedicated, enterprises experience a high-performance environment that guarantees better bandwidth, lower latency, and reliable stability for every workload.

## Key Benefits of Bare Metal Servers for Enterprises

To grow and maintain a market position, enterprises must face challenges around performance, security, and scalability. Applications are more data-heavy than ever, and users expect instant response times. For enterprises relying on mission-critical workloads, bare metal dedicated servers offer a significant advantage.

### Superior Performance and Reliability

Enterprises choose bare metal primarily for unmatched performance. Since you have direct access to high-performance hardware, there is no virtualization layer to introduce latency. Your application uses the full processing power, memory, storage, and disk space of the server.

This capability allows for faster data throughput and consistent performance, even during heavy traffic. You no longer need to worry about noisy neighbors consuming CPU or bandwidth—a common challenge in shared hosting or Virtual Private Servers (VPS).

For enterprises running AI, machine learning, big data analytics, or real-time gaming applications, these servers are the optimal solution. Every millisecond counts. By delivering ultra-low latency and guaranteed bandwidth, bare metal provides a reliable infrastructure for high-performance business applications.

### Enhanced Data Security and Compliance

Security is a requirement for modern enterprises. If your organization handles sensitive data—e.g., in the finance, healthcare, or government sectors—bare metal is highly beneficial. In a single-tenant environment, the server resources are dedicated to a single client, eliminating the risks associated with multi-tenant environments.

This physical isolation offers a solid first layer of defense against potential breaches, ensuring that no other customer’s data affects your systems. Furthermore, dedicated servers allow enterprises to deploy custom security policies, firewall rules, and advanced encryption standards, offering complete protection for customers’ data..

Since, as an enterprise, you have complete control over the infrastructure, it will be easier for you to enforce compliance with industry regulations such as HIPAA, GDPR, and [PCI DSS](https://www.atlantic.net/pci-compliant-hosting/). Enterprises can configure data access controls, monitor network traffic, and even deploy on-site security measures to protect against [DDoS attacks](https://www.atlantic.net/vps-hosting/what-is-a-ddos-and-how-do-we-prevent-our-business-from-being-attacked/) and unauthorized access.

This ability to ensure no resource sharing while offering customizable security layers improves security and regulatory compliance. Hence, offers complete peace of mind for enterprises that manage confidential or regulated data.

### Customization and Control

Every enterprise has unique infrastructure needs, and bare metal servers offer the full flexibility to tailor systems accordingly. With full root access, IT teams can install any operating system, adjust kernel settings, as well as deploy specialized applications without restrictions.

This level of complete control with enterprises may help fine-tune performance and better optimize their environment for different workloads. Whether you need help with running containerized applications, hosting databases, or managing complex business systems, the solution can be a perfect fit in all cases.

Most developers also appreciate the level of freedom they enjoy with bare metal hosting. They gain options to experiment with new software, optimize server settings, and integrate API-driven tools without any restrictions or limitations. Thus, making it one of the valuable solutions for enterprises that run custom software stacks or [hybrid cloud](https://www.atlantic.net/ashburn-virginia-hosting/understanding-hybrid-cloud-examples/) environments. This option, in short, allows developers and team members to design an environment that exactly meets their needs.

### Affordable Dedicated Servers

While bare metal may initially appear as a higher upfront investment compared to small cloud instances, the long-term Return on Investment (ROI) is often superior for high-performance workloads.

Dedicated servers offer predictable billing with no hidden charges. Cloud models often charge based on hourly usage, vCPU counts, or data transfer, which can result in extra cost at scale. With bare metal, pricing is generally transparent and consistent. Whether you choose month-to-month flexibility or long term contracts for better rates, the value is clear.

Furthermore, because there is no virtualization overhead, performance remains stable, reducing the need to provision additional servers to meet performance targets. Over time, investing in affordable bare metal servers results in better resource usage and a lower Total Cost of Ownership (TCO).

### Scalability and Automation

Modern enterprises need infrastructure that grows with them. Bare metal servers deliver this through API integration, automation, and hybrid scalability.

With advanced bare metal platforms, businesses can provision new dedicated servers quickly, manage deployments through automated tools, and integrate with cloud solutions. This allows enterprises to balance on-premise performance with cloud flexibility.

For example, an enterprise can run core business applications on bare metal for maximum performance while using cloud services for backups or temporary scaling. This hybrid setup combines reliability and cost-efficiency.

## Bare Metal vs Cloud Hosting: What is Better for Enterprises?

When comparing dedicated bare metal servers and [cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/), the choice must depend on what matters to an enterprise more, i.e., their performance, cost, control, or compliance.

Bare metal servers offer raw computing power, and improved security. All these features make these powerful servers ideal for mission-critical applications like big data, financial systems, or AI workloads. Meanwhile, cloud VPS hosting solutions provide on-demand flexibility and are great for environments with fluctuating demands.

Let us say you run a fintech company that processes millions of secure transactions daily. What would you prefer? Bare metal hosting for low latency and better security, or a cloud solution with access to shared resources. For enterprises, the case is different. There are also some individuals who invest in both. For example, a content streaming platform might combine bare metal servers for video encoding with cloud storage for distribution to achieve both speed and global reach.

Hybrid models are also becoming a new trend, giving enterprises the best of both worlds.

## Top Features to Look for in a Bare Metal Hosting Provider

Before making a final purchase, make sure to consider these points:

### Network Speed and Uptime SLA

A reliable provider should guarantee 99.99% uptime and low-latency connectivity. Look for high availability networks that ensure consistent performance even under heavy loads.

### Hardware Customization Options

Choose providers offering flexibility in CPU, RAM, storage, and Intel Xeon processors. Custom configurations help optimize performance for specific projects and business applications.

### Security and DDoS Protection

A robust security infrastructure with DDoS protection, [firewall](https://www.atlantic.net/managed-services/firewall/) management, and encrypted data transmission is a must. Enterprises must protect against rising cyber threats by investing in solutions that guarantee protection against DDoS attacks and maintain business continuity.

### Global Data Center Locations

A provider with a global reach ensures your workloads run close to your users. Distributed [data centers](https://www.atlantic.net/orlando-colocation-hosting-data-center/) enhance reliability and reduce latency for international businesses.

### 24/7 Managed Support and Monitoring

Round-the-clock technical support ensures rapid issue resolution. A provider with an expert first response team and proactive monitoring adds great value for enterprise clients.

## Atlantic.Net: Best Bare Metal Servers for Enterprises

Most modern enterprises demand high-performance and investments into fully dedicated hardware with strict compliance and control. For such enterprises, [Atlantic.Net’s bare metal server solution](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) can be a great choice. Their bare metal offering is built with enterprise use in mind. In short, as an enterprise, you will gain access to fully dedicated servers (not shared or virtualized) that provide raw processing power, direct access to hardware, support, and full root control over your OS and configurations.

Apart from this, Atlantic.Net enterprise-bare metal offers a wide range of features and benefits:

### Isolation and High Performance Hardware :

With single-tenant dedicated servers, you avoid the “noisy neighbor” effect of shared hosting or web hosting. Your entire CPU, RAM, storage, and network bandwidth are dedicated to your business. These servers utilize high-speed local storage to support mission-critical workloads efficiently.

### Flexible and Scalable Configurations:

These dedicated servers provide a wide range of server options, i.e., from large-scale servers with dozens of CPUs, hundreds of gigabytes of RAM, and fast NVMe storage, to fully customized setups designed to handle and meet large enterprise demands.

### Compliance-ready:

Many enterprises operate under strict regulatory requirements (HIPAA, PCI DSS, etc.). Atlantic.Net emphasizes secure infrastructure, audit-readiness, and full control of your server stack so you can meet those obligations.

### Root Access and Full Control:

You get full root access and freedom to install any operating system, deploy custom software, apply your desired configurations, and network settings with these dedicated servers. In short, a good solution for enterprises with sophisticated or specialized applications.

## Conclusion

In a world where speed and control define competitive advantage, dedicated bare metal servers stand out as the ideal choice for enterprises looking for maximum performance without compromise.

With proper resources, better defense system, support, and complete control, businesses can handle critical workloads efficiently and confidently. Whether you are powering AI-driven analytics, securing financial transactions, or managing enterprise SaaS platforms, bare metal dedicated servers provide the performance and reliability your operations demand.

If your organization is ready to move beyond shared and virtualized environments, now is the time to explore the potential of dedicated bare metal servers. Assess your infrastructure needs, get in touch with a [trusted provider](https://www.atlantic.net/), and experience what true bare metal performance can deliver for your business.


---

# Atlantic.Net Launches HIPAA-Compliant GPU Hosting for Healthcare AI and Medical Innovations

> URL: https://www.atlantic.net/press-releases/atlantic-net-launches-hipaa-compliant-gpu-hosting-for-healthcare-ai-and-medical-innovations/ | Published: 2025-12-19 | Updated: 2026-03-02 | Author: Editorial Team

ORLANDO, FL (Nov. 20, 2025) – Atlantic.Net,  a global cloud infrastructure provider specializing in security and compliance, has unveiled its new[ HIPAA-Compliant GPU Hosting service](https://www.atlantic.net/gpu-server-hosting/hipaa-gpu-hosting/), designed exclusively for healthcare, biotech, and medical companies seeking performance and regulatory peace of mind. The platform offers dedicated and shared GPU hosting that meets HIPAA and HITECH audit standards, empowering organizations to accelerate AI-powered medical imaging, genomics, predictive modeling, and clinical trials within a secure cloud environment.

“Our platform strikes the critical balance between security and performance. We help healthcare organizations achieve HIPAA compliance while enabling transformative healthcare innovations,” said Marty Puranik, Founder and CEO of Atlantic.Net. “Our HIPAA GPU Hosting provides researchers and clinicians with direct hardware access and industry-leading uptime, while ensuring protected health information remains safe and traceable.”

The service provides:

- Fully audited HIPAA-compliant cloud and bare-metal GPU infrastructure
- High-performance compute for medical imaging, deep learning, and big data in healthcare
- Direct hardware access for advanced workloads and granular performance controls
- Scalable architecture designed to prevent catastrophic failure and support mission-critical growth
- Expert support from certified professionals throughout the security and compliance journey
- Robust encryption, isolated networking, and audit logging to safeguard healthcare data

Atlantic.Net’s HIPAA GPU Hosting solution supports energy efficiency goals with options for lower-consumption hardware and provides extensive resource documentation and workflows for compliance. Healthcare innovators can harness powerful, compliant GPU hosting for demanding analytics, imaging, and AI—enabling new possibilities in medical research and patient care.

Founded in 1994, [Atlantic.Net](http://atlantic.net/) is a privately held global cloud infrastructure provider with customers in over 100 countries, known for delivering secure, compliant, on-demand and customizable hosting solutions. With decades of experience, Atlantic.Net is one of the world’s most trusted and experienced hosting providers, offering 24/7 U.S.-based support. Specializing in security, compliance, and customer service, Atlantic.Net serves a diverse range of industries with solutions including HIPAA-compliant hosting, and PCI-compliant hosting, backed by bare metal servers, dedicated hosting, GPU hosting, colocation, and its award-winning Cloud Platform. Operating from eight strategically located data center regions across the United States, Canada, the United Kingdom, and Asia, Atlantic.Net powers mission-critical workloads for organizations worldwide. For more information, visit[ Atlantic.Net](https://www.atlantic.net/) or connect with us on[ Facebook](https://www.facebook.com/Atlantic.Net),[ X (Twitter)](https://twitter.com/AtlanticNet),[ ](https://www.linkedin.com/company/atlantic-net)[LinkedIn](https://www.linkedin.com/company/atlantic.net-inc./posts/?feedView=all), and[ YouTube](https://www.youtube.com/c/AtlanticNet).

 


---

# Cloud vs Dedicated Hosting for HIPAA Compliance: Which Wins?

> URL: https://www.atlantic.net/dedicated-server-hosting/cloud-vs-dedicated-hipaa-compliance-hosting/ | Published: 2025-12-20 | Updated: 2025-12-23 | Author: Hitesh Jethva

In healthcare, trust is everything, and that trust begins with how well you protect patient data. Whether you’re a clinic, hospital, or telehealth platform, the information you handle every day, i.e., a patient’s medical history, insurance details, test reports, etc., is more than just simple data. This information, known as [Protected Health Information (PHI)](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/), is highly confidential, and protecting it is a legal and ethical duty.

Protecting sensitive healthcare data is not a simple task; cyber threats, data regulations, and hosting options present major challenges. For many healthcare organizations, the real question is no longer whether they need HIPAA-compliant hosting, but which kind they should choose.

Should they go with the cloud hosting, known for its flexibility and scalability, or stick with dedicated hosting? Both promise [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/), but they differ in terms of their strengths and risks.

In this guide, we will break down how each option supports the [HIPAA regulations](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). We will explore the role hosting has in ensuring compliance, which will help you decide which environment best protects your sensitive healthcare data while ensuring long-term security and trust.

## Understanding HIPAA-compliance in Hosting

Before making a choice, it is important to gain clarity and understand what HIPAA-compliance really means in terms of hosting.

The Health Insurance Portability and Accountability Act (HIPAA) is designed to safeguard Protected Health Information (PHI) and electronic protected health information (ePHI). Its purpose is to protect any data that can identify a patient, whether that information is stored on paper or via an online platform.

Today, most hospitals and clinics store medical records or insurance details on servers. Any hosting provider that stores or manages this information must follow HIPAA’s Security Rule and Privacy Rule to keep patient data private and secure.

This is not a checklist but a foundation that helps protect every patient’s personal details and records. HIPAA solutions ensure this through three main layers of security:

- **Technical safeguards**, like encryption, passwords, and activity logs used to control who can see or use the data.
- **Physical safeguards**, such as locked data centers and limited access to server rooms.
- **Administrative safeguards**, like regular risk checks and clear plans for handling security problems.

Any hosting provider that works with patient data must also sign a [Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/). This legal agreement confirms that both the healthcare organization and the hosting provider share responsibility for keeping data secure.

In short, HIPAA-compliant hosting not only focuses on where your data is stored, but also how well it is protected, who can access it, and how quickly it can be recovered if something goes wrong.

## What Is Cloud Hosting for HIPAA-compliance?

The cloud has changed how healthcare organizations store and access information. Instead of keeping data on one physical server in a hospital or office, [cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) lets you store it safely online in a virtual space managed by trusted cloud providers.

In short, with this practice, healthcare organizations no longer need to buy or maintain expensive hardware. If you run a clinic or healthcare organization, you can access data from anywhere, scale storage as your business grows, and pay only for what you use.

This flexibility is one of the major reasons why many modern telemedicine platforms, healthcare applications, and digital health companies are turning to cloud server hosting.

However, when patient data is involved, organizations have increased responsibility. The Protected Health Information (PHI) can be highly sensitive, which is why HIPAA-compliance is crucial. A HIPAA-compliant cloud is built with strict rules and advanced security measures to protect this data. Various encryption tools, access controls, and continuous monitoring features are included that help prevent data breaches and keep your healthcare data safe.

But here is something important that you must not miss. Even if you use a secure HIPAA-compliant cloud solution, compliance isn’t automatic. The cloud provider protects the servers and infrastructure, but as an organization, you must also take precautions. Make sure to set a strong password, control file sharing, and manage user permissions to prevent unauthorized access to sensitive patient data.

If implemented carefully, with these practices, you can take advantage of secure, affordable, and flexible hosting solutions. The cloud infrastructure allows you to easily add storage, connect with other systems, and integrate disaster recovery and off-site backups.

A secure HIPAA-compliant cloud hosting solution not only offers protection but also helps meet compliance rules, balance innovation, and growth.

### Key Features

- **Scalability:** You have the choice to add resources per changing needs and demand.
- **Disaster Recovery:** Comes with built-in offsite backups that help ensure data integrity and quick recovery.
- **Accessibility:** Allows accessing patient data securely from any location.
- **Managed Services:** Many cloud providers offer HIPAA-compliant services and Business Associate Agreements to ensure shared responsibility.

### Pros

- Highly flexible and scalable, making it a perfect solution for fast-growing healthcare platforms.
- Reduces upfront costs since you don’t need to buy or maintain physical servers.
- Helps in better collaboration and remote access to healthcare data.

### Cons

- The cloud provider manages the infrastructure, but you must still configure and monitor your own security settings to maintain HIPAA-compliance; this is the **shared responsibility model** in which the hosting provider secures the environment while the customer is responsible for the information stored in the environment.
- Requires careful access control and risk assessments to prevent unauthorized use.

## What Is Dedicated Hosting for HIPAA-compliance?

While the cloud-based hosting solutions are flexible and scalable, [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) is another secure hosting that offers something the cloud cannot match.

In the dedicated hosting setup, you get your own physical server. In short, no shared infrastructure, no virtual space sharing. You will have complete command over security measures and configurations.

For many healthcare organizations, this feature offers more peace of mind, making it a good solution to opt for. Further, with a dedicated server, it is much easier to stay HIPAA-compliant because you control everything. You can set up your own technical safeguards, like encryption and access controls, and track every action through audit logs.

A good [HIPAA-compliant hosting provider](https://www.atlantic.net/hipaa-compliant-hosting/top-hipaa-hosting-provider-for-small-businesses-secure-solutions-here/) will make this process even smoother. They’ll host your server in a secure data center with strong physical security, constant monitoring, and [managed services](https://www.atlantic.net/managed-services/) that handle system updates, risk assessments, and compliance checks. Thus, enabling developers and team members to focus on running smooth healthcare operations instead of worrying about maintaining the server themselves. This is why, as you might have noticed, most hospitals, laboratories, and large healthcare companies choose dedicated hosting.

Further, healthcare organizations deal with a large volume of patient data, and minor delays or data breaches are something they cannot afford. Hence, investing in a solution that comes with complete control and access is a better choice. Some solutions also offer zero trust security model, making it a gold standard for healthcare organizations.

The dedicated hosting usually costs more upfront, but in return, delivers reliable performance, strong data integrity, and a clearer path to full compliance.

So, if your organization manages critical healthcare systems, large-scale patient databases, or imaging systems that require reliability, dedicated HIPAA-compliant hosting might be the right option for your operations.

### Key Features

- **Single-Tenant Environment:** No need for resource sharing. Also, offers full control over security configurations.
- **High Performance:** Dedicated computing power ensures smooth access to patient records.
- **Better Security:** Team members can easily implement technical safeguards, physical security, and audit logs.
- **Customization**: You can choose your own software, firewalls, and compliance settings.

### Pros

- Users get complete control over their data and applications.
- Since the infrastructure is completely yours, achieving and maintaining HIPAA-compliance is easier.
- Strong isolation minimizes the risk of data breaches or unauthorized access.

### Cons

- Higher upfront cost and maintenance responsibilities.
- Healthcare organizations will need to add new hardware for scaling needs.

## Cloud vs. Dedicated: Key Differences for HIPAA-compliance

Understanding the key differences is important to determine which cloud or dedicated HIPAA-compliance hosting solution is better. When choosing between the two hosting environments, multiple factors should be kept in mind to make a strategic decision.

Both hosting types can meet HIPAA requirements, but they do so in different ways. Let’s compare HIPAA-compliant hosting solutions.

### 1. Control

Control is one of the main factors to consider when making your move.

In a **HIPAA-compliant cloud solution**, the infrastructure is managed by an external hosting provider. This means key aspects such as physical security, network management, and routine server maintenance within the cloud environment are handled by that provider rather than being fully under your organization’s direct control.

Your responsibility lies in securing the applications, controlling user access, and ensuring that sensitive patient data is handled properly. For instance, a clinic using a cloud server must configure access permissions carefully so that only authorized team members can view patient records.

Dedicated hosting, on the other hand, gives full control over the server and its configurations. No matter whether you run a small hospital or own large clinics, you can enforce your own technical safeguards, strict access controls, and customize monitoring protocols.

In short, a hospital managing [electronic medical records](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-and-electronic-health-records-ensuring-patient-confidentiality/) can set up specific firewalls, intrusion detection systems, and audit logging tailored to its workflow.

### 2. Scalability

Cloud hosting is highly flexible, i.e., you can add storage, processing power, or bandwidth instantly to meet growing demand. This could be a great benefit for platforms that experience sudden surges in patient consultations. For example, during flu season, a cloud-based hosting solution can help quickly scale and handle hundreds of video calls simultaneously without service interruptions.

Dedicated hosting, however, requires new hardware or manual upgrades to scale, making it suitable for organizations with relatively predictable workloads.

### 3. Cost

Cloud hosting usually operates on a pay-as-you-go model, making it budget-friendly for startups and smaller healthcare providers. There’s no need for large upfront investments in physical servers, and you only pay for the resources you use.

With the other solution, you might need to pay a higher initial cost for purchasing and maintaining hardware. Healthcare industry operators and service providers with stable workloads often prefer dedicated hosting because of the long-term benefits, simplified compliance monitoring, and sensitive data protection.

### 4. Security

When it comes to hosting, no healthcare can compromise on security.

In cloud hosting, the cloud provider secures the infrastructure, but it is the responsibility of the team members to ensure applications are configured correctly and sensitive patient data is protected. Misconfigurations or weak access controls can lead to HIPAA violations even in a secure environment.

Dedicated hosting, on the other hand, places most of the responsibility in your hands. It provides full control over physical, technical, and administrative safeguards, which is a great benefit for organizations handling large volumes of protected health information (PHI) and running critical systems that cannot compromise or tolerate security breaches.

### 5. Performance

To select a HIPAA-compliant hosting provider, you must also consider performance as a key factor, as it can affect day-to-day operations. Cloud hosting performance is generally reliable, but because resources are shared among multiple tenants, there is a high chance that minor fluctuations may occur during peak hours.

With the dedicated server, users gain high performance consistently since all server resources are reserved for a single organization. Hospitals running EMR systems or diagnostic imaging platforms can leverage the stable processing power, which ensures fast retrieval of patient records and smooth operation.

### 6. Compliance Management

Maintaining HIPAA-compliance is easier in dedicated environments. While cloud hosting can be HIPAA-compliant, it requires ongoing coordination with the provider to monitor logs, maintain proper access controls, and implement an incident response plan.

Dedicated hosting is much simpler as the infrastructure and data handling are fully under your control, making it easier to pass audits, conduct risk assessments, and stay fully compliant.

### Atlantic.Net: The Right HIPAA-Compliant Hosting Provider

The comparison might have brought some clarity, but selecting the right HIPAA-compliant hosting provider is more than comparing prices or performance stats. It is more about finding a solution that understands your healthcare industry and has the right tools that can protect patient data while staying compliant with HIPAA regulatory requirements.

Make sure to look for the following when making a final call:

- **Business Associate Agreement (BAA):** Make sure your hosting provider offers a signed BAA.
- **Continuous Monitoring:** This ensures you can detect and respond to security issues fast.
- **Disaster Recovery and Backups:** Important for maintaining data integrity and availability.
- **Strict Access Controls:** Essential for preventing unauthorized access to sensitive data.

Remember, hosting a website or application is not the major concern. The decision focuses more on ensuring HIPAA-compliance requirements while keeping the patient trust intact.

Investing in a good provider like [Atlantic.net](https://www.atlantic.net/hipaa-compliant-hosting/) will eventually help meet regulatory compliance requirements, maintain full security, and prevent financial losses. Rated as one of the top HIPAA-Compliant Website Hosting Service Provider, offers secure both Cloud and Dedicated Hosting solutions.

### Conclusion

So, should you choose cloud or dedicated hosting for HIPAA-compliance? Remember, your answer depends entirely on the needs, size, and priorities of your organization.

If you are a growing healthcare startup or a small clinic that prioritizes cost efficiency and values flexibility or quick scalability, HIPAA-compliant cloud hosting might be your best fit. It will offer you the freedom to innovate while maintaining strong security.

However, if you are a large hospital or a research institution, handling massive amounts of protected health information (PHI), dedicated hosting will provide unmatched control and security. With a private infrastructure and strict access controls, you can build a system that meets every aspect of true HIPAA-compliance, covering everything from physical safeguards to incident response and management.

Both options are beneficial if you manage them properly. The only thing you need to keep in mind is your risks, growth goals, and the ability to manage compliance responsibilities.

A right [HIPAA-compliant hosting solution](https://www.atlantic.net/hipaa-compliant-hosting/) won’t just help you stay compliant but also protect your reputation and patients’ trust.

 


---

# Top Features of Linux Dedicated Server Hosting for Businesses

> URL: https://www.atlantic.net/dedicated-server-hosting/linux-dedicated-server-hosting-features/ | Published: 2025-12-22 | Updated: 2026-01-06 | Author: Hitesh Jethva

Any organization relying on a digital presence must have a hosting foundation that delivers security, speed, control, and dependability. If you run a small project shared or [cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) might be a good option. But organizations that prioritize performance and data sovereignty must switch to dedicated server hosting. When that dedicated environment runs on Linux, it brings a level of productivity and freedom that few other platforms can match.

A well-configured Linux dedicated server is an excellent option for enterprise-grade applications, eCommerce platforms, and other essential systems. Its proven stability and high flexibility have made it a primary choice for many businesses. From offering complete control over the environment to resource allocation, it allows teams to adjust performance precisely to their operational needs.

Unlike Windows-based hosting, most Linux versions do not require expensive licensing fees, making it a cost-effective solution without compromising performance or security. There are several other features of a Linux dedicated server hosting that make it a top choice among developers and IT teams. In this guide, we will learn what a Linux dedicated server is and break down the top features that define Linux hosting.

Our goal is to help you see Linux not just as an operating system, but as a strategic advantage: a hosting solution that provides businesses with the control, confidence, and capability to grow without limitations.

## What Is a Linux Dedicated Server?

A dedicated server is a physical machine that a single user or organization owns or rents exclusively. In shared hosting, multiple users compete for the same CPU, RAM, and storage resources. In dedicated servers, the situation is reversed: all system resources are entirely yours.

When this dedicated hardware is powered by the Linux operating system, you get Linux Dedicated Server Hosting. Linux, being open source, offers transparency and value compared to other operating systems. Businesses can choose from different Linux distributions, e.g., Ubuntu, Debian, Fedora, Rocky Linux, or Red Hat Enterprise Linux (RHEL), and customize configurations as needed.

This setup provides organizations with an environment optimized for control and speed. Since there is no need to share system resources, your websites, applications, and databases run with better reliability and minimal latency, making this an ideal solution for demanding workloads.

## Key Features of Linux Dedicated Hosting

Here are the primary features of Linux Dedicated hosting that make it a preferred choice for performance-driven organizations.

### 1. Full Root Access and Administrative Control

One of the primary features of a Linux dedicated server is full root access. This capability gives IT teams and developers the power to manage every aspect of the hosting environment. This administrative privilege allows them to configure the system exactly as required. Whether installing software packages or tuning kernel parameters and network configurations, you gain full control.

Full root access also implies that you can apply hardening measures aligned with your organizational policies. To combat DDoS attacks or unauthorized access, you can configure firewalls, intrusion detection systems, or secure access protocols through SSH. Compared to shared hosting, where settings are predetermined, here you control every layer.

### 2. Choice of Linux Distribution and Stack Flexibility

Another major advantage is the freedom to choose the Linux distribution based on technical requirements and expertise. For instance, if you need simplicity, Ubuntu can be a good option. For stability, Debian works well, and for new features, Fedora could be a suitable choice. Developers building performance-critical applications might choose Alpine Linux for its lightweight footprint. Similarly, for long-term stability and certified compliance, RHEL could be top of the list. Each Linux distribution offers unique advantages, and having the option to choose one tailored to your specific needs drives the value of this solution.

### 3. Dedicated Hardware Resources and Guaranteed Performance

Another interesting feature of a dedicated server is access to its hardware. With these systems, there is no need to share CPU, RAM, storage, or bandwidth with anyone else. This isolation enables websites and applications to handle large amounts of traffic effortlessly.

Some modern Linux dedicated servers, such as those offered by [Atlantic.Net](https://www.atlantic.net/), feature high-end AMD EPYC processors or Intel Xeon CPUs, delivering high performance and reliability. You may also come across additional benefits, i.e., NVMe or SSD-based storage that help with low latency and fast I/O. Thus, making it a key feature for eCommerce platforms, database operations, and media streaming.

Network performance is equally important. Dedicated network links and unmetered bandwidth make sure the data transfers remain fast and uninterrupted. With guaranteed dedicated IPs, SSL installations, and robust data center connectivity, users may experience faster load times and improved uptime, even during peak hours.

### 4. Scalability

While a dedicated server represents fixed hardware, modern hosting solutions built on Linux offer excellent scalability. Providers often allow users to upgrade CPU, add more RAM, or expand storage as workloads grow, often with minimal downtime. This scalability ensures your infrastructure evolves with business needs.

Organizations looking forward to significant growth must deploy multiple Linux servers in a load-balanced cluster for seamless performance across multiple sites or services. Whether you are running a fully [managed service](https://www.atlantic.net/managed-services/) or a self-administered environment, having this modular design can make scaling straightforward and cost-effective.

Further, since Linux is an open-source platform, there is no additional licensing cost needed for scaling. You can easily expand your server hosting capacity without worrying about extra fees.

### 5. Security Features

Security is one of the major factors why you should opt for Linux dedicated server hosting. The Linux kernel provides robust built-in features such as SELinux and AppArmor, which enable kernel-level hardening and access control. With these features in your hosting solution, you can control services, permissions, and monitor security logs proactively.

Also, since these dedicated servers operate in a single-tenant environment, there’s complete isolation from other users. Thus, it reduces the risk associated with shared web hosting and ensures compliance with standards like [GDPR](https://www.atlantic.net/vps-hosting/gdpr-compliance-for-global-managed-service-providers/), [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/), or PCI-DSS. You can easily configure firewalls, SSL certificates, and VPN access.

Leading hosting providers complement these capabilities with DDoS protection, secure physical data centers, and 24/7 expert support. With full visibility into the system, you can even patch vulnerabilities immediately and ensure safety and peace of mind.

### 6. Superior Storage Options and I/O Performance

In a dedicated server hosting setup, storage performance is often the key determinant of how fast your applications run. Modern Linux servers offer a variety of storage configurations, from high-speed NVMe drives to RAID arrays designed for redundancy and speed.

For database-heavy workloads, NVMe-based storage ensures fast read/write cycles and minimal latency. Media platforms and file repositories can benefit from large-capacity SSDs that offer both performance and storage space. Administrators can also fine-tune file systems and caching layers to improve throughput and I/O performance.

In short, Linux allows you to optimize storage according to your workload requirements.

### 7. Support and Maintenance

Even with complete control, having reliable support is crucial. The best hosting providers offer 24/7 expert support, available through chat, phone, or ticket systems. This feature within the hosting solution helps resolve complex issues related to server configurations, software updates, or control panels quickly.

For those who prefer not to manage everything manually, many providers offer fully managed services. This means the host takes care of OS updates, security patches, monitoring, and even backups, allowing you to focus on your applications.

### 8. High Availability and Reliable Infrastructure

For enterprises running critical applications or managing high-traffic websites, reliability and high availability are non-negotiable. Linux dedicated servers are built to deliver exactly that. These servers operate on infrastructure designed for maximum uptime, featuring redundant power supplies, RAID-enabled storage, and multiple network connections, helping deliver uninterrupted performance even if one component fails.

Most hosting providers further strengthen this reliability with uptime guarantees of 99.9% or higher, ensuring your users can access your website or application at all times. The Linux operating system itself is known for its stability and efficient resource management, minimizing overhead while maintaining consistent performance under heavy workloads.

When paired with provider-level monitoring and proactive hardware maintenance, Linux dedicated servers create an enterprise-grade environment where downtime is nearly eliminated, and every process runs seamlessly. This combination of redundancy, intelligent resource allocation, and continuous oversight makes Linux dedicated servers a trusted choice for businesses that demand true reliability and high availability.

### 10. Cost Structure

Finally, the pricing model of Linux servers is a major benefit. Because most Linux distros are open-source, you often don’t need to pay licensing fees. This reduces long-term operational expenses, making [Linux hosting](https://www.atlantic.net/vps-hosting/linux-vps-hosting/) a cost-effective choice for growing organizations.

Dedicated servers also eliminate the unpredictable costs often associated with [shared hosting](https://www.atlantic.net/vps-hosting/top-shared-hosting-providers-in-the-usa/) or usage-based billing models. Look for a solution that features free domains, free SSL, and unlimited traffic, offering significant value without surprise charges.

## Atlantic.Net: A Reliable Linux Dedicated Hosting Solution

For businesses seeking a reliable and fully customizable Linux dedicated hosting solution, [Atlantic.Net](https://www.atlantic.net/dedicated-server-hosting/) offers an excellent choice. Their dedicated servers provide full root access, a wide selection of Linux distributions, and the flexibility to configure CPU, memory, and storage according to specific requirements. With dedicated IPs, hardware [RAID](https://www.atlantic.net/vps-hosting/what-is-raid/) options, and high-speed SSD or NVMe storage, Atlantic.Net ensures both performance and data reliability.

Atlantic.Net USA-based support team is also available 24/7, offering guidance on server setup, optimization, and security hardening. They also provide optional managed services, including OS updates, backups, and monitoring, allowing organizations to focus on core business functions without compromising server control.

## Conclusion

Linux Dedicated Hosting combines the performance of dedicated hardware with the versatility of the Linux operating system. It offers full root access, superior security, and extensive support that appeals to developers and enterprises.

From high-performance CPUs like AMD EPYC processors to SSL certificates and expert-managed infrastructure, every feature contributes to reliability, scalability, and confidence in your hosting foundation. By aligning technology with reliability, businesses can move beyond basic hosting to create infrastructures that truly support their operations. Make performance predictable and reliability scalable—this is the future of dedicated hosting.


---

# Top Hosting Control Panels for 2026

> URL: https://www.atlantic.net/cloud-platform/top-hosting-control-panels-2026/ | Published: 2025-12-27 | Updated: 2026-01-06 | Author: Robert Agar

Many customers use a cloud provider’s resources to host websites and applications, typically using on of the numerous managed services available to streamline operations. Cloud service providers (CSPs) typically offer a range of hosting plans designed to match clients’ usage scenarios and business requirements. Companies commonly use public cloud hosting services to run ecommerce storefronts, WordPress websites, and other applications that require fast and secure access from any location.

Some users may be satisfied with a cloud hosting option that shares server resources with other tenants. Other customers may opt for the improved security features of dedicated servers. Regardless of the type of web hosting they choose, they must have a way to manage their cloud environment.

This article reviews the web hosting control panels available to users for server management and other tasks, and it also briefly touches on other control panels that might fit niche needs. We discuss the key features you should look for in a hosting control panel to manage your server effectively, and identify some of the best and most popular control panels for your website.

## What is a Hosting Control Panel?

A hosting control panel is a dashboard that allows end-users to perform server management tasks without needing extensive technical knowledge, often serving as the primary control web panel for the entire environment. The control panel provides a web-based user interface that simplifies all aspects of managing a web hosting environment. System administrators, web designers, and general users all benefit from the tools provided by comprehensive control panels.

CSPs often offer customers multiple web hosting control panel options to manage their environment. The hosting provider may have an in-house control panel built to improve the customer experience. Clients may install any third-party commercial control panels if they have root access to the hosted server. Technically skilled or advanced users can also choose an open-source control panel and customize it to meet specific needs.

## Main Features of Hosting Control Panels

The web hosting control panel you select must provide the features you need to manage all aspects of your hosted environment without requiring command-line interaction with the server. You might not need all the features these tools provide, but a complete control panel should offer them to customers in a user-friendly interface.

### Website and application management

Customers need application and website management capabilities to improve their hosted servers. Many clients support multiple websites from the hosted server environment. Hosting control panels provide tools that simplify deploying, configuring, and managing websites and applications. Specific features often include:

- File management with uploading and editing tools;
- Web server configuration with tools like Apache;
- Tools to manage multiple PHP versions and modules;
- Creating and managing FTP/SFTP accounts;
- Advanced panels may even include a responsive remote terminal for direct command-line management within the browser;
- Simple installers for selected software packages and popular applications such as WordPress or Drupal.

### Domain management

Users must be able to use the web panel to manage the domains and subdomains associated with the hosted environment. A server control panel helps with actions such as DNS server management and URL forwarding. Teams can easily add or remove domains and subdomains with an intuitive user interface that eliminates the need for complex command-line work.

### Database administration

Many customers use cloud hosting to support important internal and customer-facing databases. A web hosting control panel lets users create, delete, and manage custom databases, often using a database management tool such as phpMyAdmin. However, more comprehensive control panels will provide visual tools for managing databases and performing tasks such as creating users, exporting, and backing up data.

### Email hosting management

Users should expect all popular web hosting control panels to provide email and mail server management capabilities. It should be easy to create dedicated email accounts across domains and websites. Some control panels may offer advanced features, such as spam filtering, antivirus screening, and mailbox size limits to minimize mailbox clutter and storage space consumption.

### Security management

The control panel should allow customers to modify numerous security features to protect the server and the hosted environment. A secure web hosting control panel provides capabilities including:

- SSL/TLS certificate management;
- Managing firewalls and creating IP allow/deny lists;
- Implementing two-factor authentication (2FA) and integrating with the linux pam authentication mechanism for unified login security;
- Advanced security features, such as malware and vulnerability scanning.

### User management

The web control panel must enable teams to create multiple user accounts with role-based access permissions to control server usage. Customers can define user account privileges and enforce advanced access controls to websites and applications.

### Backup and recovery tools

Customers should protect their environment and data with backup and recovery tools built into the control panel. The main features users should expect in a backup system include:

- Scheduled and on-demand backups;
- Defining backup retention policies;
- Simple file, account, and database recovery.

### Monitoring and analytics

Customers need monitoring tools that provide complete system usage statistics to understand and improve their hosted environment, websites, and applications. Ideally, the control panel should offer cross-platform support and enable teams to manage multiple servers from a unified dashboard. Additionally, administrators often look for tools that offer easy server logs visualization to quickly troubleshoot issues.

## Five of the Best Hosting Control Panels

Here are five of the best and most popular control panels available today.

![](https://www.atlantic.net/wp-content/themes/anet/img/site/main_logo.png)

### Atlantic Net Control Panel (ACP)

Atlantic Net offers users a proprietary control panel that combines the features of a web hosting control panel with the ability to manage infrastructure elements such as servers and storage. The friendly user interface makes it easy to manage your hosted servers and applications. The ACP control panel lets businesses manage their hosting solution without extensive technical expertise.

Specific features of ACP include:

- On-demand snapshots to protect the environment;
- Straightforward support for VM deployment and management;
- Excellent backup and recovery capabilities;
- Granular control over resources such as storage and networks.

![](https://www.atlantic.net/wp-content/uploads/2025/12/Cpanel-logo.png)

### [cPanel](https://www.cpanel.net/products/)

cPanel is a commercial web hosting control panel supporting cloud, VPS, and dedicated server solutions. Users can automate server management tasks using its powerful automation tools, ensure security, and monitor performance from a unified platform. System administrators specifically appreciate the Web Host Manager (WHM) interface, which provides administrative control over the server. The tool supports security with malware scanning and advanced customization options to strengthen firewalls.

Noteworthy features include:

- Multiple pricing plans ranging from one to a hundred accounts;
- Resource monitoring tools for bandwidth management and performance optimization;
- Support for Ubuntu and other Linux distributions.

![](https://www.atlantic.net/wp-content/uploads/2025/12/PLESK.png)

### [Plesk](https://www.hostinger.com/vps/plesk-hosting)

Plesk is a popular commercial hosting control panel that simplifies the management of all aspects of hosted websites and applications. Users can manage multiple virtual hosts from a single control panel. The tool includes a complete WordPress toolkit covering installation, staging, security, and updates for WordPress sites. Plesk’s feature set includes:

- A modern web stack with MongoDB database, Composer, and Docker integration;
- A web project lifecycle facility with a fast web interface to speed up web development and maintenance;
- Integrated security that includes advanced server monitoring and self-repair tools to address potential issues..

![](https://www.atlantic.net/wp-content/uploads/2025/12/cyberpanel.png)

### [CyberPanel](https://cyberpanel.net/)

CyberPanel is a completely free, open-source web hosting control solution. The tool lets users monitor CPU, memory, and disk usage from a centralized dashboard. Customers enjoy the simplicity of single-click installation and setup for popular applications like Joomla, Drupal, and WordPress.

Additional features include:

- No limits on the number of installations or websites with the Free Forever Plan;
- LSCache plugin for WordPress for faster website performance;
- One-click SSL certificates with auto-renewal.

![](https://www.atlantic.net/wp-content/uploads/2025/12/PLESK.png)

### [Vesta Control Panel](https://vestacp.com/)

The Vesta control panel is an open-source solution that offers advanced users unlimited customization abilities by allowing them to modify its source code. The tool supports server administration with real-time monitoring of CPU, memory, and disk usage. Vesta provides an intuitive dashboard that brings all its features together in a user-friendly interface.

Vesta’s features include:

- A file manager with simple drag-and-drop functionality;
- A template that simplifies creating and modifying Cron jobs;
- Access controlled by assigning User, Site Manager, or Admin roles.

## Find the Right Solution for Your Hosted Environment

Most users find it important to use an effective web hosting control panel with a user-friendly interface to manage their hosted environment. Users should look for a web hosting option that offers a full-featured native server control panel or supports their preferred control panel. Customers may want to evaluate the differences in features and support between free and commercial tools.

Regardless of the type of control panel chosen, customers must use the tool effectively to improve performance and strengthen security by controlling access privileges. More feature-rich and complex control panels can be compromised if misused. Users should protect their hosted environments by using their control panel securely.


---

# Best Dedicated Hosting Providers to Consider in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/best-dedicated-hosting-providers-2026/ | Published: 2025-12-30 | Updated: 2026-07-23 | Author: Dr. Assad Abbas

**Atlantic.Net is the best dedicated hosting provider for 2026.** Its dedicated servers pair SOC-certified, HIPAA- and PCI-ready infrastructure with 24/7 USA-based customer support, the strongest hosting solution for compliance-driven and high-traffic workloads.

## Key Takeaways

- **Atlantic.Net:** best for healthcare, finance, and other regulated industries that need[compliance-ready dedicated servers](https://www.atlantic.net/dedicated-server-hosting/).
- **HostGator:** best for small and medium businesses that want dependable hardware with simple management.
- **KnownHost:** best for managed dedicated hosting with customizable builds and responsive customer support.
- **InterServer:** best budget option, with deep customization, IPMI access, and no setup fees.
- **Hetzner:** best low-cost European provider for self-managed teams.
- **IONOS:** best for storage-heavy configurations, up to 80 TB with unlimited traffic.
- **Rackspace:** best for fully managed enterprise deployments with a 100% network uptime SLA.

## How the Top Dedicated Hosting Providers Compare

Table 1 compares the best dedicated server hosting providers of 2026 on hardware range, network capacity, compliance coverage, and typical pricing.

## Table 1: Comparison of the top dedicated hosting companies

Here we show the top 7 providers that have made our list. You will find details about the size of compute on offer (CPU, Disk and Memory), plus facts regarding network limits, compliance and what support services are available.

We also include the latest pricing we have (Accurate at time of publication)

| **Provider** | **CPU & Cores (min–max)** | **RAM (min–max)** | **Storage (range)** | **Network / Bandwidth** | **Security & Compliance** | **Support & Services** | **Typical Pricing** |
| --- | --- | --- | --- | --- | --- | --- | --- |
| **Atlantic.Net** | 6 – 64 cores (Intel Xeon, AMD EPYC) | 64 – 256 GB | ~480 GB – ~3.84 TB SSD/NVMe | 20 TB transfer, 1 Gbps | SOC certified (HIPAA/PCI/HITECH), firewalls, DDoS/IDS | 24/7 USA-based support, optional managed services | ~$138 – $495 /mo |
| **HostGator** | 8 – 32 cores (vCPU) | 32 – 128 GB DDR5 | 1 – 3 TB NVMe | Unmetered | DDoS protection, SSL, RAID 6, Linux security patches | 24/7/365 chat & phone support, guided server setup, free migration | $144 – $346 /mo |
| **KnownHost** | 4 – 32+ cores (Intel Xeon, AMD EPYC) | 16 – 512 GB DDR4/DDR5 | 480 GB – 15+ TB SSD/NVMe | 1 – 10 Gbps, unmetered options | DDoS protection, firewalls, proactive monitoring, free SSL | 24/7 expert support, managed options, root access, custom builds | $160 – $600+ /mo |
| **InterServer** | 1 – 56 cores (AMD/Intel) | 64 – 128 GB | 2 – 22 TB (SATA/SSD/NVMe) | 1 Gbps unmetered (10 Gbps optional) | DDoS protection, firewall rules, BYOIP & BGP | 24/7 uptime monitoring, managed support, IPMI/iLO access, remote OS reinstall | $74 – $577 /mo |
| **Hetzner** | Varies by line: 1 – 64+ cores (AMD/Intel) | Varies by line | 32 GB – multiple TBs SSD/NVMe | Public: 300 Mbps – 25 Gbps unmetered; private vRack: 1 – 100 Gbps | GDPR compliant, DDoS protection, firewalls | 24/7 support, managed server options, custom solutions | €29 – €399+ /mo |
| **IONOS** | 1 – 62 cores (Intel Xeon, AMD EPYC) | 2 – 256 GB+ DDR4/DDR5 ECC | 512 GB – ~80 TB SSD/NVMe/SATA (RAID included) | Unlimited traffic on 1 Gbps port (standard) | ISO 27001 certified, DDoS protection, firewalls, IDS/IPS, free SSL | 24/7 phone/email support, root access, optional managed services, Launch Assist | Custom quoted |
| **Rackspace** | 6 – 60+ cores (Intel Xeon, AMD EPYC) | 32 GB – 3 TB+ DDR4/DDR5 ECC | SSD, NVMe, SATA, SAN/NAS (custom configurations) | 10 GbE network, custom bandwidth (usage-based egress fees) | ISO, SOC 1/2/3, PCI DSS Level 1, HIPAA | 24/7 “Fanatical Support®”, fully managed services, 100% uptime SLA | $499 – $1,249+ /mo |

## What Is Dedicated Server Hosting?

[Dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/what-is-a-bare-metal-server-benefits-use-cases-and-best-practices/)refers to using a single physical server assigned to one organization. This means one customer gets the entire server, with all the server’s resources reserved exclusively for that business, which results in greater administrative control, enhanced security, and predictable performance.

This hosting model is commonly used for high-traffic websites, e-commerce platforms, SaaS products, and enterprise-level systems. Such applications depend on dedicated resources to support reliability and consistent response times, and many businesses arrive at dedicated servers after outgrowing shared or VPS hosting. Because dedicated servers handle critical workloads, the choice of operating system, the level of server management, and the quality of the data center network all influence stability, speed, and security, so these factors deserve careful consideration before committing to a web host.

## Benefits of Dedicated Hosting

Dedicated hosting gives a business exclusive access to a physical server, which provides complete control, enhanced security, and stable performance.

The key benefits include:

- **Complete Control:** Dedicated hosting allows administrators to configure hardware, install necessary software, adjust server settings, and manage security policies without restrictions. This level of control helps server performance meet business requirements.
- **Compliance Readiness:** Dedicated hosting often includes DDoS mitigation, dedicated IP addresses, firewalls, and certifications such as HIPAA or PCI. It is therefore suitable for industries with strict regulatory standards, including healthcare and finance.
- **Resource Isolation:** With dedicated hosting, all server resources are allocated to a single business rather than split across a shared hosting plan. This means databases, ERP systems, and custom software operate without interference from other users, which contributes to smooth performance for complex workloads.
- **Consistent Performance:** Dedicated hosting uses fully allocated resources, resulting in predictable server behavior, higher computing power, and stable performance. This makes it a dependable solution for high-traffic websites and enterprise applications.

## Dedicated Hosting Features and How to Choose a Provider

Dedicated server hosting offers strong hardware and flexible management options that support different business workloads, which is why this comparison focuses on the best dedicated hosting services. Dedicated hosting providers differ in the dedicated servers they offer and the services they include, and those differences influence performance and long-term suitability, so any dedicated server provider should be evaluated on hardware, support, and management scope. The features below are the ones that separate providers in practice.

### Hardware Specifications and Custom Configurations

Dedicated servers rely on Intel Xeon or AMD processors, with CPU, RAM, and storage assigned to a single business. Reviewing server specifications and server hardware shows whether a provider can support demanding workloads or future growth. Most providers here also offer custom hardware and server configuration choices, so a business can specify core counts, memory, RAID layout, and drive types instead of picking from a fixed menu.

### Operating Systems: Linux Distros and Windows Server Options

Most dedicated servers ship with a choice of operating systems, and some providers also offer Windows for Windows-specific workloads: Linux distros such as Ubuntu, Debian, or AlmaLinux, and Windows Server options for teams running .NET applications or Microsoft SQL Server. Windows servers carry a license fee that Linux avoids, so check whether the plan price includes it. Among the providers here, Atlantic.Net and HostGator both offer Linux and Windows servers as standard choices; confirm managed Windows server options separately, since management depth for Windows servers varies by provider.

### Bandwidth and Port Speed Options

Port speed and transfer allowance, along with bandwidth or data transfer, set the ceiling on how much traffic dedicated servers can push. A 1 Gbps port is the standard baseline here: InterServer includes unmetered bandwidth on it, IONOS includes unlimited traffic, and some dedicated plans market that as unlimited bandwidth, though actual limits should still be verified; Atlantic.Net pairs it with 20 TB of transfer, and Hetzner offers public connections from 300 Mbps up to 25 Gbps. Data-heavy operations should check for 10 Gbps upgrade options and whether hosting plans meter traffic, since overage fees change the real monthly cost. Bandwidth needs also depend on traffic levels and the size of website pages.

### Remote Access Through IPMI and iDRAC

Out-of-band management tools such as IPMI, iDRAC, and iLO let a system administrator reach a dedicated server even when the operating system is down, covering power cycling, console output, and full OS reinstalls without a support ticket. InterServer includes IPMI access on its dedicated hosting plans. Self-managed teams should treat this as a requirement; it is what lets you fix a broken boot yourself.

### Root Access and Server Management Levels

Dedicated hosting plans come in unmanaged, managed, and fully managed tiers, reflecting how much responsibility a business takes on for daily maintenance. Managed hosting costs typically start at $100 per month, while unmanaged dedicated hosting plans can start as low as $24 per month. Root access comes standard on unmanaged plans and remains available on most managed dedicated servers, preserving full control over software installs and security policies. Managed tiers are the provider-handled option for teams that want managed hosting services instead of handling updates and upkeep themselves. Atlantic.Net offers optional managed services on top of self-managed dedicated servers, while Rackspace manages the full lifecycle, including patching, OS administration, server maintenance, and server monitoring.

### DDoS Mitigation and Security Controls

Common security features include DDoS mitigation, TLS certificates, firewalls, malware scanning, and intrusion detection. Every provider here includes some level of attack filtering. Still, the depth varies: entry-level hosting plans filter volumetric attacks aimed at dedicated servers at the network edge, while compliance-focused providers such as Atlantic.Net and Rackspace layer firewalls and IDS on top. Organizations handling sensitive data should confirm the hosting company holds certifications, such as SOC audits for[HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) or PCI DSS for payment workloads.

### Uptime SLAs, Customer Support, and Data Center Footprint

An uptime SLA is a contractual commitment, and the difference between 99.9% and 99.99% is roughly 8.8 hours versus 53 minutes of allowable downtime per year. Liquid Web guarantees 99.99% uptime, which limits downtime to about four minutes per month. Rackspace backs its network with a 100% uptime SLA; whichever web host you choose, read what the SLA actually covers, and verify what web host promises in the SLA, especially whether coverage applies to network uptime, hardware, or both. Customer support response times vary widely, and a broader data center footprint reduces latency for distributed users and supports redundancy.

## Best Dedicated Hosting Providers

A brief about each dedicated hosting provider is presented below:

### 1. Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

Atlantic.Net provides[dedicated and bare-metal servers](https://www.atlantic.net/dedicated-server-hosting/) built for consistent performance and high security, giving customers their own server for single-tenant performance and compliance-sensitive workloads. Its focus on compliance and uptime makes it a strong choice for healthcare, finance, and other enterprise workloads.

- Servers can be configured with Intel Xeon or AMD CPUs, up to 256 GB of RAM, SSD or NVMe storage, and Linux or Windows OS. This range suits both smaller deployments and resource-intensive enterprise applications.
- SOC-certified data centers support HIPAA, PCI, and HITECH compliance, while firewalls, intrusion detection, and DDoS protection safeguard critical data.
- 24/7 USA-based support ensures issues are addressed quickly, and high-bandwidth connectivity with unmetered inbound traffic supports demanding applications.
- Optional managed services include monitoring, backups, and security add-ons, providing flexibility for teams that want partial or complete server management and support for tailored server environments when optional management is added.

### 2. HostGator

![](https://www.atlantic.net/wp-content/uploads/2025/08/Hostgator-logo.png)

HostGator offers dedicated hosting for small and medium businesses that require dependable hardware with straightforward management. Both Linux and Windows servers are supported, providing flexibility for different technology stacks.

- HostGator’s servers use AMD EPYC or Intel Xeon-class processors, DDR5 RAM, and NVMe storage, delivering solid performance for typical workloads.
- Security measures such as DDoS protection, TLS certificates, and RAID storage help protect data and reduce risks from routine threats.
- cPanel or Plesk can be added for easy administration, and upgrade paths support future resource needs. Pricing starts at competitive entry-level rates.

### 3. KnownHost

![](https://www.atlantic.net/wp-content/uploads/2025/12/knownhost.jpeg)

KnownHost provides dedicated server hosting focused on performance, flexibility, and managed support, with customizable hardware and responsive technical assistance.

- It offers dedicated CPU resources, Intel and AMD processors, DDR4/DDR5 RAM, and SSD or NVMe storage to deliver consistent performance for demanding workloads.
- Full root access is available for advanced administration, while managed support, multiple control panels, and operating system choices provide deployment flexibility.
- DDoS protection, hardware monitoring, customizable server configurations, and 24/7 support make KnownHost a reliable option for scalable dedicated hosting.

### 4. InterServer

![](https://www.atlantic.net/wp-content/uploads/2025/12/interserver.png)

InterServer is a cost-effective provider offering bare-metal servers with deep customization options. It is popular among developers and businesses that require flexibility.

- InterServer provides Intel Xeon and AMD processors with SSD, NVMe, or SATA storage. These options help businesses match server capacity to workload needs without moving into premium pricing.
- Its dedicated plans include DDoS protection, unmetered 1 Gbps bandwidth, and continuous monitoring for stable connectivity and dependable uptime. That 1 Gbps unmetered connection works well for gaming servers and other sustained-traffic workloads, while higher-capacity ports are available for data-heavy operations.
- InterServer also offers IPMI access and remote management tools, giving administrators direct control for reinstalls and troubleshooting. Pricing stays competitive, and the lack of setup fees keeps initial costs low.

### 5. Hetzner

![](https://www.atlantic.net/wp-content/uploads/2025/12/hetzner_logo.png)

Hetzner is a German hosting company well known for affordable and reliable dedicated servers. It operates ISO-certified data centers in Germany, Finland, and the USA, making it a popular choice for developers, startups, and enterprises globally.

- Hetzner offers Intel Xeon or AMD EPYC CPUs with scalable RAM up to 128 GB+ and SSD, NVMe, or SATA storage. Customers can pick configurations for small websites or enterprise applications.
- All dedicated hosting plans include unmetered bandwidth with 1 Gbps ports for stable performance. Higher-tier servers can upgrade to faster connections for demanding workloads.
- Security and compliance are supported through ISO-certified data centers, DDoS mitigation, and firewalls. Hetzner provides 24/7 support and remote management tools for businesses preferring self-managed hosting.

### 6. IONOS

![](https://www.atlantic.net/wp-content/uploads/2025/08/ionos-logo.png)

IONOS offers dedicated servers with configurable hardware and ISO-certified data centers. It is known for affordable pricing, strong security, and unlimited traffic, making it suitable for both enterprises and developers.

- Customers can configure servers with Intel Xeon or AMD EPYC CPUs, scalable RAM, and SSD or NVMe storage. Plans include options for storage servers with up to 80 TB of capacity.
- Unlimited traffic is included with 1 Gbps bandwidth as standard. This ensures stable performance for high-traffic websites and applications.
- ISO-certified data centers provide compliance and security. Features include firewalls, DDoS mitigation, and intrusion detection. 24/7 support is available for managed and unmanaged plans.

### 7. Rackspace

![](https://www.atlantic.net/wp-content/uploads/2025/12/rackspace_logo.png)

Rackspace delivers premium, fully managed dedicated and bare metal servers designed for enterprise workloads. It is recognized for its[Fanatical Support](https://www.rackspace.com/resources/fanatical-support-aws-solution-overview) and strong uptime guarantees, making it a trusted choice for organizations with mission-critical applications.

- Rackspace offers high-performance single-tenant servers equipped with Intel Xeon or AMD EPYC processors, scalable RAM, NVMe SSD storage, and SAN or NAS options. These configurations are designed to support complex and demanding workloads.
- Rackspace manages the full server lifecycle, which includes operating system administration, patching, monitoring, backups, and proactive technical support. A 100% network uptime SLA supports consistent reliability.
- The platform provides compliance support for standards such as HIPAA and PCI DSS, along with managed firewalls, DDoS protection, and intrusion detection services.

For a deeper look at unmanaged single-tenant options specifically, see our companion roundup of the[top bare-metal hosting services](https://www.atlantic.net/dedicated-server-hosting/top-5-bare-metal-hosting-services/).

## Choosing the Right Dedicated Hosting Provider

The right web host depends on how a business operates day to day. For many small and mid-sized businesses, the starting point is reliability. Stable performance, predictable pricing, and access to customer support tend to matter more than advanced customization. Providers such as HostGator and KnownHost fit this profile well, offering simple dedicated hosting plans that work for standard business websites and internal applications. Managed-hosting specialists such as Liquid Web and InMotion Hosting compete on white-glove service; the providers ranked here compete on infrastructure value and compliance depth.

As traffic increases, expectations change. Online stores, membership platforms, and content-heavy websites rely on fast storage and steady network performance to stay responsive, and downtime quickly turns into lost revenue. In these situations, Atlantic.Net becomes a practical option. Its use of NVMe storage and consistent uptime helps maintain smooth operations during busy periods, while managed security services reduce the operational burden on internal teams.

For regulated industries, infrastructure decisions are even more important. Healthcare, finance, and legal organizations must meet strict standards around data handling and system security, which often requires SOC-certified facilities, HIPAA-ready configurations, and layered security controls. Atlantic.Net supports these requirements while still giving businesses flexibility through optional management services, which helps teams stay compliant without overcomplicating their infrastructure.

Startups and development teams tend to approach hosting from a different angle, where flexibility and cost control often matter more than full-service management. Providers like Hetzner, InterServer, and IONOS appeal here because they offer configurable servers and hands-on control. At the same time, Atlantic.Net remains relevant for teams planning to scale, since its infrastructure can grow alongside applications while adding monitoring or support only when needed.

Larger organizations face a separate set of challenges. Complex applications, internal compliance rules, and uptime expectations leave little room for error, so dedicated servers backed by clear service commitments and dependable support are essential. Atlantic.Net supports enterprise workloads by pairing high-performance hardware with flexible service options, making it suitable for systems where stability matters more than short-term cost savings.

## Performance and Pricing for Dedicated Hosting Providers

Performance expectations vary based on workload type. Sequential applications benefit from strong single-thread performance, while high-traffic platforms rely more heavily on multi-threaded processing. Storage speed further influences responsiveness. NVMe drives provide faster access than SATA, which improves database queries, content delivery, and transaction-heavy workloads. Stronger CPU and RAM resources also help maintain better site speed for high-traffic or transaction-heavy websites. Network quality also matters, since real-world throughput and uptime commitments affect how well dedicated servers handle sustained traffic.

Pricing considerations extend beyond the advertised server rate. Most dedicated hosting plans start around $100 per month, with managed options generally priced above that baseline. Operating systems, control panels, backup services, and management options all influence total cost over time, and higher pricing often reflects compliance coverage, advanced security controls, and access to experienced support teams. Atlantic.Net performance with compliance readiness by pairing fast hardware with SOC-certified infrastructure and optional managed services, which suits organizations operating under regulatory constraints.

By comparison, Hetzner and InterServer focus on lower-cost infrastructure with greater self-management responsibility, which appeals to cost-sensitive teams with in-house. Rackspace positions itself at the enterprise end of the pricing spectrum, emphasizing full lifecycle management and extensive compliance coverage, an approach shared by managed dedicated specialists such as Liquid Web.

A practical hosting choice balances hardware capability, network reliability, support depth, and long-term cost predictability. Atlantic.Net reflects this balance by offering performance-driven infrastructure, compliance-ready environments, and flexible management options that scale across different business needs.

## Real World Use Cases of Dedicated Hosting Providers

Different business scenarios highlight where dedicated hosting services deliver the most value. In healthcare and software-as-a-service environments, Atlantic.Net fits well due to its HIPAA-ready infrastructure and optional managed services, which support compliance obligations without adding operational strain.

High-traffic ecommerce platforms also benefit from Atlantic.Net’s NVMe-based storage and consistent network performance, supporting reliable transactions and stable customer experiences during peak demand periods.

Developer teams and early-stage startups often favor dedicated servers from Hetzner or InterServer for development, testing, and gradual scaling, with lower-cost servers often used for a test site before production rollout, given their lower entry costs and customizable configurations. Atlantic.Net serves teams transitioning from this stage by offering scalable infrastructure with optional oversight as operational needs grow.

Enterprise workloads typically depend on strong uptime guarantees, structured support, and compliance alignment. Rackspace remains a common choice for large-scale enterprise deployments, while Atlantic.Net supports organizations that require enterprise-grade performance without committing fully to rigid management models.

These scenarios show that provider selection depends on operational goals, regulatory demands, and budget structure. Specifications alone rarely settle the decision.

## Key Terms

- **Dedicated server:** A physical server leased in full to one customer, with no resources shared with other tenants; the foundation of dedicated web hosting.
- **Single-tenant:** An infrastructure model where one organization is the only user of a piece of hardware, in contrast to shared hosting or virtualized multi-tenant environments.
- **IPMI:** Intelligent Platform Management Interface, an out-of-band channel for power control, console access, and OS reinstalls when the server itself is unresponsive. Vendor equivalents include Dell iDRAC and HPE iLO.
- **Managed vs. unmanaged hosting:** Managed dedicated hosting plans include provider-handled maintenance, patching, and monitoring; unmanaged plans hand full administrative responsibility to the customer.
- **SLA (Service Level Agreement):** A contractual uptime commitment, expressed as a percentage such as 99.99%, with defined remedies if the hosting company misses it.
- **DDoS mitigation:** Network-level filtering that absorbs or blocks distributed denial-of-service attacks before they exhaust a server’s bandwidth or resources.

## Final Thoughts

Choosing among dedicated server hosting providers is a long-term decision that affects performance, security, and operational costs. Businesses running high-traffic platforms or regulated systems benefit from web hosting services that offer reliable infrastructure, strong connectivity, and service options that over time.

Atlantic.Net brings these elements together through high-performance dedicated servers, compliance-ready data centers, and flexible management options. The result is a hosting solution that works across a wide range of workloads, from growing applications to environments with strict regulatory needs. Other providers may focus on lower entry costs or narrow use cases, while Atlantic.Net emphasizes consistency, security, and scalability without adding unnecessary complexity.

A well-chosen hosting provider reduces operational friction and supports predictable performance, giving teams the stability needed to focus on growth instead of infrastructure issues.

## Frequently Asked Questions (FAQ)

### Is Dedicated Hosting Better Than VPS?

Dedicated hosting is better than VPS for workloads that need consistent performance, full hardware control, and strict security. The key benefits of dedicated servers over[VPS hosting](https://www.atlantic.net/vps-hosting/) are resource isolation (no other tenants share the CPU, RAM, or disk), predictable behavior under heavy load, and a cleaner path to compliance certifications. Both are web hosting services built on the same hardware; VPS hosting plans split it among multiple users, which makes them cheaper and quicker to provision, and shared web hosting sits below both for very small sites.

### What Is the Difference Between Managed and Unmanaged Dedicated Hosting?

Managed dedicated hosting means the web host handles server administration; unmanaged means the customer does. On managed hosting services, the web host covers OS updates, patching, monitoring, backups, and frontline customer support, which suits teams without an in-house system administrator. On an unmanaged plan, the customer gets root access and full control but takes on updates, security hardening, and incident response. Many providers, including Atlantic.Net, sit between the two: self-managed dedicated servers with optional managed services added only where needed, typically delivered through a hosting account with varying levels of server access and responsibility.

### What Hardware Specifications Should You Evaluate When Selecting a Dedicated Server?

Evaluate CPU cores and generation, RAM capacity, storage type, and network port speed, in that order of impact for most workloads. Core count and clock speed determine how many simultaneous users or processes a dedicated server handles. NVMe storage outperforms SATA for databases and transaction-heavy applications, and RAM should cover the application’s working set plus headroom for caching. When comparing dedicated servers, check the port speed (1 Gbps standard, 10 Gbps for data-heavy work), whether RAID is included, and whether you need Linux or Windows servers, since licensing affects price.

### What Is the Typical Provisioning Time for a Dedicated Server Compared to a Cloud Instance?

A cloud instance provisions in minutes, while a dedicated server typically takes from a few hours to a few days. Cloud hosting carves virtual machines from already-running hardware, so deployment is nearly instant. Dedicated servers are physical machines the web host must allocate, cable, and image; standard configurations from stock are the fastest, and custom hardware builds take the longest. If provisioning speed matters more than raw capacity, start with cloud or VPS hosting and migrate to dedicated hosting later.

### How Does Dedicated Hosting Support Compliance-Heavy Industries Like Healthcare and Finance?

Dedicated hosting supports regulated industries through single-tenant isolation, auditable infrastructure, and provider certifications that shared environments struggle to match. Because no other customer touches the hardware of dedicated servers, sensitive data stays physically isolated, which simplifies HIPAA, PCI DSS, and HITECH audits. A hosting company like Atlantic.Net runs SOC-certified data centers and offers[HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) with intrusion detection, encrypted backups, and a signed HIPAA Business Associate Agreement (BAA). The customer still owns application-level controls, so confirm where the shared-responsibility line falls between you and the web host.

### How Does Dedicated Hosting Handle Hardware Failure and Replacement?

The web host owns the hardware, so failed components are replaced by the data center at no extra cost under standard terms. Reputable providers monitor disk health, power, and temperature, and many replace failing drives proactively. RAID keeps a dedicated server running through a single drive failure, and out-of-band tools such as IPMI allow remote diagnosis of dedicated servers. Hardware replacement restores capacity; backups restore data, so check the SLA for replacement timeframes and keep independent backups regardless of the warranty.

### Are Dedicated Servers Suitable for Small Websites?

Yes, though for most small websites dedicated web hosting is more capacity than the traffic requires. Smaller websites still benefit from dedicated servers through improved security, scalability, and control that shared hosting cannot match, and the entry-level dedicated hosting plans on this list (InterServer from around $74/month, Hetzner from €29/month) put that within reach. A small site on shared hosting or a VPS costs less and provisions faster; the best dedicated hosting for a small site is an entry-level plan chosen for a compliance obligation or a steady growth plan, while WordPress hosting may be more practical for content-driven small sites that do not need dedicated infrastructure.

### How to Choose a Dedicated Server for High-Traffic Websites?

Prioritize multi-core CPUs, NVMe storage, and generous bandwidth, because high-traffic sites are limited by concurrency and I/O before anything else. Dedicated servers provide predictable resources and faster storage, which shortens load times, database queries, and transaction handling. Look for a web host with a clear uptime SLA, DDoS mitigation at the network edge, and customer support that responds quickly during traffic spikes. Confirm the plan includes unmetered bandwidth or enough transfer to cover peak months, and prefer providers with an upgrade path so growth does not force a migration.


---

# Why Your Growing eCommerce Business Needs Dedicated Server Hosting

> URL: https://www.atlantic.net/dedicated-server-hosting/why-growing-ecommerce-businesses-need-dedicated-server-hosting/ | Published: 2026-01-01 | Updated: 2026-06-17 | Author: Dr. Tehseen Zia

Every second matters in online retail. When [Cyber Monday](https://en.wikipedia.org/wiki/Cyber_Monday) 2024 saw shoppers spending over [$14.2 billion](https://fortune.com/2025/12/02/cyber-monday-how-big-14-2-billion-record-spending-online-shopping/) in a single day, the retailers who succeeded were not just the [ones](https://websitespeedy.com/blog/bfcm-website-downtime-prevention/) with the best deals. They were the [ones](https://www.wsj.com/business/retail/shopify-breaks-down-on-busy-cyber-monday-4ce789e1) whose websites stayed fast, secure, and online when traffic surged to unprecedented levels. For many growing eCommerce businesses, the difference between capturing that revenue or losing it comes down to the single choice of the right hosting infrastructure.

## **Understanding What Dedicated Hosting Actually Means**

At its core, a [dedicated server](https://aws.amazon.com/what-is/dedicated-server/) means you have an entire physical machine dedicated to your business. Unlike [shared hosting](https://www.ndic.com/blog/difference-between-managed-dedicated-and-shared-hosting-for-ecommerce/), where hundreds of websites compete for the same resources, or even [virtual private servers](https://aws.amazon.com/what-is/vps/) that partition a machine among multiple users, dedicated hosting gives you complete access to all processing power, memory, and storage. This is like owning an entire building versus renting an apartment or even a floor.

This level of isolation is essential for an eCommerce business. Your store handles sensitive customer data with every transaction. You process payments, store personal information, and maintain inventory databases that need constant real-time updates. When other websites on a shared server experience traffic spikes or security issues, they can drag down your performance or even expose you to risks. With dedicated hosting, those concerns disappear because you control the entire environment.

## **Performance That Drives Revenue**

In eCommerce, website speed directly affects business revenue. Research [shows](https://queue-it.com/blog/ecommerce-website-speed-statistics/) that websites loading in under two seconds have significantly [higher conversion rates](https://www.cloudflare.com/learning/performance/more/website-performance-conversion-rates/) than those taking three or four seconds. When your average shopping cart value continues to grow, small delays in page load can have a substantial impact on revenue.

Dedicated servers deliver consistent performance because all resources are fully allocated to your business:

- Your CPU processes only your transactions.
- Your RAM handles only your customer sessions.
- Your bandwidth serves only your traffic.

During a sudden surge when a social media post goes viral or an influencer mentions your product, the server does not have to share resources with unrelated websites. It responds only to your needs.

Performance is not limited to faster page loads alone. Database queries run faster when they have dedicated processing power and enterprise-grade NVMe storage. Product images load more quickly when storage access is not restricted by other users. Checkout processes remain efficient even when hundreds of customers are completing purchases simultaneously.

## **Security Requirements for Handling Transactions**

Payment card industry regulations, specifically [PCI DSS compliance](https://www.atlantic.net/pci-compliant-hosting/pci-dss-4-0-is-mandatory-a-hosting-checklist-for-2026/), require strict security measures for any business that processes credit card transactions. While meeting these standards is possible with various hosting types, dedicated servers make compliance significantly easier to achieve and maintain. You control the firewall configurations, can implement custom intrusion detection systems, and maintain complete audit logs of who accesses your systems and when.

Data breaches in eCommerce can be [devastating](https://www.verizon.com/business/resources/articles/s/economic-impact-of-data-security-breaches-in-ecommerce/). Besides the immediate financial losses and potential regulatory fines, the damage to customer trust can take years to rebuild. Dedicated hosting provides isolation that shared environments cannot deliver. When security vulnerabilities emerge, you can patch and update your systems on your schedule without waiting for a hosting provider to coordinate updates across hundreds of clients.

The ability to implement end-to-end encryption, customize security protocols, and maintain private network configurations becomes mandatory as your business grows. Larger retailers often need to integrate with multiple payment processors, implement fraud detection systems, and connect to inventory management platforms. These integrations require secure API connections and data transfers that benefit enormously from dedicated infrastructure.

## **Customization for Your Specific Platform**

Different eCommerce platforms have different technical requirements. [Magento](https://magento-opensource.com/), with its powerful features and flexibility, demands significant server resources to run optimally. [WooCommerce](https://woocommerce.com/) sites need specific PHP configurations and database optimizations. [Shopify Plus](https://www.shopify.com/plus) users who want to host custom applications or manage high-volume API calls need infrastructure they can configure precisely.

With dedicated hosting, you can optimize every aspect of your server environment for your chosen platform. You can adjust memory allocation based on your product catalog size. You can fine-tune caching configurations based on your traffic patterns. You can install specific versions of software dependencies that your application requires without worrying about conflicts with other users’ needs.

This customization enables businesses to effectively manage and scale their growth. As your business expands, you might add new features like augmented reality product previews, live chat support, or real-time inventory tracking across multiple warehouses. These additions often have specific technical requirements. With complete server control, you can deploy new features, without facing arbitrary resource limits or needing approval from a hosting provider.

## **Managing Traffic Spikes Without Panic**

The 2024 holiday shopping data [revealed](https://www.clear.co/blog/cyber-monday-2025-data-recap) striking insights about modern eCommerce. Analysis indicates that traffic does not just increase during expected events anymore. AI-powered chatbots drove a massive influx of traffic to retail sites during Cyber Monday compared to the previous year. [Social media influencers](https://www.dash.app/blog/influencer-marketing-statistics) can send thousands of shoppers to a specific product page within hours. These unpredictable surges can overwhelm infrastructure that was not primarily designed to handle them.

Dedicated servers offer the capacity needed to handle these traffic spikes effectively. Unlike cloud hosting where costs can escalate unexpectedly during high-traffic periods, or shared hosting where performance degrades when demand increases, dedicated infrastructure offers predictable capacity.

## **Cost Considerations **

The cost of dedicated hosting requires careful consideration. Yes, dedicated servers cost more per month than shared hosting or basic VPS plans. A quality dedicated server can cost several hundred dollars per month, compared with just a few dollars for budget shared hosting. However, this simple comparison does not reflect the complete financial impact. For example, consider the impact of downtime. Even a single hour offline during a peak shopping day can cost more than an entire month of hosting fees, even for businesses with modest revenue. The consistent reliability and performance of dedicated hosting can help protect both revenue and customer trust.

When evaluated [holistically](https://www.digitalpacific.com.au/blog/why-dedicated-servers-are-the-best-bet-for-e-commerce-business-websites/), dedicated hosting often proves more cost-effective for businesses generating significant revenue. Once monthly online sales reach a certain threshold, hosting costs become a relatively small percentage of revenue compared with the performance and protection they provide. The question shifts from whether you can afford dedicated hosting to whether you can afford not to have it.

## **Finding the Right Hosting Provider**

Not all dedicated server providers offer the same value. The cheapest options are rarely the best choice for eCommerce businesses. What matters most is reliability, support quality, and infrastructure flexibility. It is important to choose providers with documented uptime commitments, preferably supported by service level agreements. Choose companies with specialized eCommerce hosting expertise that understand the specific requirements of online retail.

[Atlantic.net](https://www.atlantic.net/dedicated-server-hosting/) brings decades of infrastructure expertise to dedicated hosting, with a focus on businesses that need reliable, high-performance environments. Rather than simply supplying hardware, the company delivers complete hosting solutions that include security, monitoring, and expert support. For growing eCommerce businesses, having a provider that knows how to handle traffic surges or security incidents can make a meaningful difference.

The quality of management support is another critical factor to consider. Fully managed dedicated hosting means your provider handles server maintenance, security updates, and technical issues. For companies without dedicated IT staff, this level of support is as valuable as the hardware itself.

## **Growing Demands of eCommerce**

With the emergence of disruptive technologies, the eCommerce industry is evolving rapidly. Artificial intelligence tools are [changing](https://www.artisanfurniture.net/news/the-e-commerce-evolution-how-ai-is-transforming-online-shopping/) how customers shop. Mobile commerce keeps [growing](https://www.blog.udonis.co/mobile-marketing/mobile-marketing-statistics). New payment methods emerge regularly. Video content and interactive product experiences become [standard](https://wyzowl.com/video-marketing-statistics/) rather than special. Each of these trends places new demands on your infrastructure.

Dedicated hosting provides an infrastructure that can grow with these changes. When you need to implement new technologies, you have the control to do so. When regulations change, you can adapt your security measures. When your business expands into new markets, you can optimize your infrastructure for those regions.

The most successful online retailers see hosting not as a commodity expense but as a strategic investment in their growth capability. They understand that every aspect of their customer experience, from the first page load to the final checkout confirmation, depends on the infrastructure supporting it. They recognize that in a competitive market, the businesses with the best technical foundation often win even when products and prices are similar.

## **The Bottom Line**

For growing eCommerce businesses, every second of website performance and every measure of security matters. Dedicated servers provide the performance, security, and flexibility necessary to protect revenue, retain customer trust, and scale with growth. For retailers aiming to compete at the highest level, reliable infrastructure is not an optional requirement; it is the foundation for success.


---

# Disaster Recovery Hosting for Healthcare and Legal Workloads

> URL: https://www.atlantic.net/hipaa-compliant-hosting/disaster-recovery-hosting-healthcare-legal/ | Published: 2026-01-02 | Updated: 2026-01-06 | Author: Dr. Tehseen Zia

In healthcare and legal services, data is not just an asset. It is a responsibility. Patient records and case files hold the most sensitive details about people’s lives. The integrity and availability of this data are highly important. When a system fails, whether from a cyberattack, specifically ransomware, a natural disaster, or simple human error, the consequences are not limited to downtime. They can impact patient care and compromise legal proceedings. That is why disaster recovery has become one of the most critical requirements for these industries.

Disaster recovery is not just backing up data. It ensures your critical workload, from patient records to case management systems, can be restored within a given timeframe for your practice to survive and meet its obligations. The challenge becomes even more complex in regulated environments such as the United States, where compliance requirements dictate not just how you back up your data, but where you store it and who can access it. Understanding these requirements and planning accordingly helps you build a disaster recovery strategy that aligns with your industry, geography, and regulatory environment.

## **Understanding Your Recovery Objectives**

Before selecting any disaster recovery solution, organizations must define their Recovery Time Objective and Recovery Point Objective. These two metrics determine every decision that follows and directly impact the cost and complexity of your infrastructure

[Recovery Time Objective](https://www.techtarget.com/whatis/definition/recovery-time-objective-RTO), commonly called RTO, measures how long your systems can remain offline before they cause unacceptable damage. For a healthcare clinic, RTO might be measured in hours since patient schedules cannot be rescheduled indefinitely. For a law firm handling urgent litigation, RTO could be measured in minutes because missing a court filing deadline could have serious consequences. Most healthcare organizations target RTO between two and eight hours, while law firms often need something closer to one to four hours.

[Recovery Point Objective](https://www.techtarget.com/whatis/definition/recovery-point-objective-RPO), or RPO, defines how much data you can afford to lose. This is measured in time rather than volume. RPO answers the question that if your systems fail right now, how much data can you afford to lose? For example, if your last backup was four hours ago, your RPO is four hours. For high-volume healthcare environments, losing four hours of patient data is rarely acceptable, as vitals and lab results cannot be easily recreated. For a law firm in the middle of litigation, losing even one hour of case notes or email could be catastrophic. Most law firms need RPO measured in minutes because they are constantly generating data they cannot afford to lose. These objectives directly determine how frequently you must back up data and where you must store those backups.

Your RTO and RPO directly determine your backup strategy. A tighter RPO requires more frequent backups. This increases the amount of data moving across your network, adds storage demands, and introduces greater operational complexity. Geographic redundancy, which involves maintaining backups in multiple data centers, introduces additional expenses. The mistake most organizations make is targeting recovery times that look impressive in theory but may not align with their business needs. A law firm does not require a five-minute RPO when its workload only generates critical data every hour. Similarly, a clinic does not need a one-hour recovery if it can reschedule non-urgent appointments. Understanding your real business needs helps avoid unnecessary costs while ensuring protection where it truly matters.

## **Compliance Requirements Shape Infrastructure Decisions**

Healthcare organizations must comply with [HIPAA regulations](https://www.kiteworks.com/hipaa-compliance/hipaa-audit-log-requirements/) that enforce strict standards for data protection, access control, and audit logging. Legal firms must comply with various state bar requirements that emphasize confidentiality and data security. Both sectors often handle data governed by additional frameworks such as [PCI DSS](https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard) for payment information and [GDPR](https://en.wikipedia.org/wiki/General_Data_Protection_Regulation) for clients in the European Union.

These compliance frameworks do not just restrict what you can do with data. They define your disaster recovery architecture. HIPAA effectively mandates that backup data remain encrypted both in transit and at rest. It requires that only authorized personnel have access to recovery systems. It also requires audit trails that document every access to backup data. These requirements eliminate certain hosting approaches and make others mandatory.

Geographic location plays a critical factor when it comes to meeting compliance requirements. A New York law firm cannot simply store backups in any available data center. Many state bar associations have specific requirements about where client data can be stored and processed. Some firms find that selecting a disaster recovery provider with local facilities in their state simplifies compliance verification and audit processes. This geographic specificity becomes increasingly important for firms with multi-state practices where different rules apply in different jurisdictions.

## **Comparing Self-Managed and Fully Managed Solutions**

Once you understand your recovery objectives and compliance requirements, the next decision is how to implement your disaster recovery strategy. Some organizations choose to build and manage their own disaster recovery infrastructure. This approach offers control and can appear cost-effective at first. You select the hardware, manage the software, define backup schedules, and maintain the recovery systems yourself.

But self-managed disaster recovery places a significant burden on IT teams. Maintaining a secondary data center requires constant attention. Backups must be continuously monitored to ensure they are completed successfully, and recovery procedures require regular testing. When disaster strikes, your staff is responsible for executing recovery under intense pressure. For smaller healthcare practices or law firms with limited IT resources, these responsibilities can become overwhelming very quickly.

An alternative is a fully managed disaster recovery solution (DRaaS), where a specialized provider handles the infrastructure, monitoring, and recovery operations. Your organization defines the RTO and RPO targets, and the provider designs systems to meet those objectives. Backups are monitored continuously, recovery procedures are tested regularly via automated verification, and the provider stands ready to execute recovery whenever needed. This approach often proves more cost-effective when you consider the full scope of expenses, including hardware, software, and the time and expertise required to manage systems in-house. It allows your internal team to focus on day-to-day operations instead of maintaining backup infrastructure. Most importantly, it ensures that compliance requirements are achieved consistently since the provider maintains expertise in healthcare and legal industry regulations.

## **Geographic Distribution and Data Residency**

The geographical location of your disaster recovery host is another critical consideration. Data must be replicated across multiple locations so that a single site failure does not cause data loss. For a business based in New York, choosing a disaster recovery site in the same metropolitan area might offer low latency and simplify compliance verification, as regulators can easily inspect facilities within their jurisdiction. But it also exposes you to the same regional risks, such as a widespread power outage or a severe weather event. The secondary recovery location should be geographically distant enough that a single disaster cannot affect both sites, but not so distant that latency becomes a problem. A New York law firm might maintain backups in New York and replicate them to a facility in New Jersey or Pennsylvania. A healthcare clinic in Florida might use local backups with secondary replication to Georgia. This approach protects against data center failures and regional disasters while maintaining acceptable backup speeds.

## **Selecting the Right Disaster Recovery Provider**

When selecting a disaster recovery provider, it is critical to find one with specific expertise in your industry. Not all providers understand healthcare and legal industry needs. This direct experience is invaluable, as it means they have already developed solutions for industry-specific scenarios.

The provider’s capabilities must support your compliance obligations. They should offer encryption standards acceptable to your regulators, and their audit trails should be detailed enough to satisfy compliance reviews. Crucially, they should offer immutable backups to protect against ransomware attacks, ensuring data cannot be altered or deleted by hackers. They should also provide third-party certifications, such as [SOC 2](https://secureframe.com/hub/soc-2/what-is-soc-2) or [HITRUST](https://www.securitymetrics.com/blog/what-hitrust-compliance), to validate that their backup systems meet regulatory requirements.

Finally, confirm that the provider offers geographic flexibility. They must be able to maintain your primary and secondary sites in your required locations and scale to support your practice’s growth. If you operate across multiple jurisdictions, verify that they can handle multi-site failovers. Choosing a provider with this combination of expertise, compliance, and infrastructure is essential for an effective disaster recovery plan.


---

# Top Reliable Cloud Hosting for Web Hosting in 2026

> URL: https://www.atlantic.net/cloud-platform/top-reliable-cloud-hosting-web-hosting-speed-uptime/ | Published: 2026-01-04 | Updated: 2026-01-06 | Author: Dr. Assad Abbas

[Cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) provides an advanced method to host websites with better speed and uptime. Unlike traditional hosting, which depends on a single physical server, cloud hosting uses a network of connected servers to share resources. This architecture grants websites greater reliability, power, and flexibility.

Traditional hosting types, such as shared, VPS, or [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/what-is-a-bare-metal-server-benefits-use-cases-and-best-practices/), rely on only one server.If that server fails, the website may slow down or go offline. In contrast, cloud hosting automatically distributes traffic and workloads across multiple servers, reducing the risk of downtime.

Websites with high traffic or real-time data requirements benefit the most from this system. E-commerce stores, SaaS platforms, news portals, and content-heavy blogs require consistent uptime and fast loading speed. Without this, even a short delay can cause users to leave or reduce sales.

Cloud hosting also improves security and simplifies maintenance. Most providers include automated backups, malware protection, and disaster recovery. Together, these features create a stable and secure environment that keeps websites running smoothly. For businesses that depend on performance and reliability, cloud hosting is one of the best choices today.

## Ways Cloud Hosting Improves Website Performance

Cloud hosting provides a fast, reliable, and flexible environment for modern websites. It addresses the following common limitations found in traditional hosting types.

- ### Higher uptime and reliability

A cloud-based system runs across multiple interconnected servers. If one server experiences an issue, others immediately take over. This design minimizes downtime and always keeps websites accessible.

- ### Faster website performance

Resources such as CPU, memory, and storage are distributed across multiple servers. This balanced setup improves responsiveness and speeds page load times. This keeps visitors on the site longer and overall site engagement increases.

- ### Easy scalability

Cloud hosting adapts smoothly to changing resource demands. CPU, RAM, and storage capacity can be scaled up or down within minutes. This flexibility supports growth without complex migration or interruptions.

- ### Reliable handling of traffic spikes

Cloud servers automatically handle sudden traffic spikes, such as during sales, promotions, or viral events. Websites keep running smoothly and maintain stable performance even when visitor numbers surge.

- ### Cost efficiency

Most providers follow a pay-as-you-go billing system. Resources are billed only for actual usage, helping optimize operating expenses while maintaining consistent performance.

Cloud hosting offers a balance of stability, speed, and flexibility. This makes it an excellent choice for growing online businesses and high-traffic platforms that need reliable performance and consistent uptime.

## Cloud Hosting Models and Deployment Types

Cloud hosting is available in several models, each offering a distinct combination of control, automation, and reliability. Understanding these models helps align the hosting environment with project requirements and technical capacity. The types of cloud hosting are discussed below:

### Managed Cloud Hosting

Managed cloud hosting provides comprehensive operational support from the provider. The provider handles server maintenance, applies operating system updates, installs security patches, and continuously monitors performance. This reduces the administrative burden and lowers the risk of misconfiguration.

This model enables teams to concentrate on website management and application deployment rather than infrastructure tasks. It is particularly suitable for projects with limited in-house technical resources or where operational stability and support are prioritized over complete system control.

### Unmanaged Cloud Hosting

Unlike managed hosting, unmanaged cloud hosting offers complete control over the server environment. Administrators configure the operating system, install and maintain software, manage firewalls, and manually apply updates. This model provides maximum flexibility, enabling advanced customization and fine-tuned performance optimization.

However, it demands strong technical expertise and ongoing maintenance effort. It is most appropriate for developers, system administrators, or organizations with dedicated IT teams capable of handling complex server operations.

### Public, Private, and Hybrid Cloud

Public cloud hosting operates on shared infrastructure managed by a third-party provider. Although multiple customers share the same physical hardware, logical isolation ensures secure separation of resources. This model offers cost efficiency and scalability, making it suitable for a wide range of web projects.

Private cloud hosting, by contrast, allocates the infrastructure exclusively to a single organization. This arrangement provides higher isolation, predictable performance, and simpler compliance with stringent security and regulatory standards. Private cloud environments are commonly adopted in sectors such as healthcare, finance, and government.

Hybrid cloud hosting integrates public and private cloud environments. Sensitive workloads remain on private infrastructure, while less critical or highly variable workloads are processed on public cloud servers. This configuration optimizes security, cost, and scalability while supporting gradual migration strategies.

### VPS Hosting in the Cloud Context

[Virtual Private Server (VPS)](https://www.atlantic.net/vps-hosting/) hosting uses virtualization to create isolated virtual machines on a single physical server. Each VPS receives dedicated CPU, RAM, and storage resources but relies on a single hardware node. Although it offers more stability and configuration options than shared hosting, it lacks the distributed redundancy inherent in full cloud architectures.

VPS often serves as an intermediate step between shared hosting and actual cloud hosting. It is suitable for moderate workloads that require greater control and dedicated resources but do not yet demand large-scale elasticity or multi-node fault tolerance.

## How to Evaluate a Cloud Hosting Provider

Selecting the right cloud hosting provider requires careful consideration of several technical and practical factors. Each element contributes to website speed, uptime, and overall reliability.

- ### Technical Infrastructure

A provider’s infrastructure forms the foundation of its service. Providers with multiple data centers across different regions help reduce latency and support redundancy, which improves availability during localized outages. In addition, high-performance SSD or NVMe storage, combined with reliable power and network systems, supports consistent performance during hardware or network disruptions. Providers that clearly explain server locations, network design, and underlying architecture make it easier to evaluate overall reliability and operational resilience.

- ### Performance and Uptime

Infrastructure quality directly influences performance outcomes. Performance should be measured using real-world data rather than marketing claims. Tools such as GTmetrix, Pingdom, or similar services offer insight into load times and uptime patterns over time. Providers that publish performance metrics and back them with an SLA of at least 99.9% demonstrate stronger accountability for service consistency.

- ### Security Features

Performance and uptime matter little without adequate protection. Security evaluation should focus on the provider’s protective controls rather than surface-level features. Standard requirements include SSL certificates, network firewalls, DDoS mitigation, malware scanning, and scheduled backups. When applications handle personal, financial, or medical data, formal compliance with frameworks such as HIPAA, GDPR, or PCI-DSS becomes a required qualification rather than an added benefit.

- ### Customer Support

Even with strong infrastructure and security, issues can still arise. Support quality directly affects operational continuity. Continuous access through live chat, ticket systems, or phone support reduces downtime during unexpected incidents. Independent user reviews offer practical insight into response times, technical depth, and the provider’s ability to resolve issues effectively.

- ### Scalability and Flexibility

Scalability should be measured by how efficiently resources adapt to changing workload demands. Providers that support on-demand CPU, memory, and storage adjustments, along with modular plans or usage-based billing, maintain performance stability while keeping resource costs aligned with actual needs.

- ### Value-Added Services and Platform Capabilities

Once core requirements are met, additional services can influence day-to-day efficiency. Features such as integrated SSL certificates, automated backups, staging environments, free domains, and development tools reduce administrative overhead. These platform capabilities support smoother operations and enhance the overall hosting experience.

## Top Cloud Hosting Providers

Here are the top cloud hosting providers offering high-speed and reliable services:

### 1. Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

[Atlantic.Net](http://www.atlantic.net) is a reliable cloud hosting provider known for speed, uptime, and security. It offers managed and unmanaged options, making it suitable for businesses of all sizes. Atlantic.Net also emphasizes compliance, which is essential for healthcare and financial websites.

- 
  - Atlantic.Net delivers[100% uptime](https://www.atlantic.net/cloud-service-level-agreement/) backed by redundant data centers in the U.S. and Europe. This ensures websites remain online with minimal downtime.
  - The company provides HIPAA-compliant hosting, including encrypted storage and secure server access. This makes it a trusted choice for healthcare and financial organizations.
  - Hosting plans are scalable, with flexible CPU, RAM, and storage options. Businesses can expand resources without migrating servers.
  - Customers benefit from 24/7 support through chat, email, and phone. Technical issues are resolved quickly and professionally.

- Atlantic.Net offers both managed and unmanaged hosting plans, giving users either complete control or a hands-off experience depending on their preference.

### 2. Kamatera

![](https://www.atlantic.net/wp-content/uploads/2025/12/kamatera-logo-1.png)

[Kamatera](https://www.kamatera.com/) is a global cloud provider with high flexibility and performance. It allows users to configure servers exactly to their needs. Its cloud solutions are suitable for developers, businesses, and startups.

- Kamatera provides fully customizable cloud servers, with CPU cores, memory, and storage that can be adjusted to match specific workload requirements. This structure supports efficient resource usage and stable performance across different project sizes.
- Server resources can scale within minutes, which helps manage sudden traffic increases. Applications and websites continue running smoothly during peak demand periods without noticeable slowdowns.
- The company maintains data centers in multiple global regions. This global presence improves loading speed for users in different locations and supports consistent uptime.
- Full root access is included with cloud servers, giving technical teams complete control over system configuration. This level of access suits development, testing, and advanced deployment scenarios.
- Kamatera offers round-the-clock technical support alongside a straightforward management interface. Monitoring server health and adjusting resources remains simple, even for complex environments.

### 3. AWS (Amazon Web Services)

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

[AWS](https://aws.amazon.com/) is a global cloud hosting platform designed for scalability, performance, and reliability. It supports websites and applications of all sizes through a distributed infrastructure spanning multiple geographic regions.

- AWS operates across multiple availability zones within each region, which improves fault tolerance and reduces the impact of localized failures. This design supports consistent uptime and high availability for production workloads.
- The platform offers auto-scaling and elastic load balancing, which dynamically adjusts resources based on traffic demand. Websites maintain stable performance during sudden usage spikes.
- High-performance storage options, including SSD-backed instances, reduce latency and improve page load speed for web applications. This infrastructure supports data-intensive and real-time workloads.
- AWS meets extensive compliance standards, including HIPAA, SOC, ISO, and GDPR. These certifications support regulated industries and applications handling sensitive data.

### 4. Hostinger Cloud Hosting

![](https://www.atlantic.net/wp-content/uploads/2025/08/Hostgator-logo.png)

[Hostinger](https://www.hostinger.com/) provides cloud hosting services designed for affordability and ease of use. The platform relies on Google Cloud infrastructure, which supports stable performance and reliable uptime. It suits small to medium websites that need speed without a complex setup.

- Hostinger runs on Google Cloud, which provides high uptime and strong redundancy. This ensures that websites remain accessible even during unexpected traffic surges.
- The platform allows flexible scaling of CPU, RAM, and storage, making it easy to adjust resources to meet website demands without downtime.
- AI-powered optimization tools automatically enhance page load speed and reduce response times, improving visitor experience and engagement.
- Security measures include automated backups, SSL certificates, and malware protection. Together, these features safeguard sites against data loss and cyber threats.
- Customers have access to 24/7 support through chat and email. Quick and knowledgeable assistance helps resolve technical issues efficiently, reducing potential downtime.

### 5. Scala Hosting

![](https://www.atlantic.net/wp-content/uploads/2025/12/scalahosting.jpg)

[Scala Hosting](https://www.scalahosting.com/) provides managed cloud VPS solutions focused on security, performance, and operational simplicity. It suits businesses that want cloud flexibility without complex server management.

- Scala Hosting delivers managed cloud VPS environments with dedicated CPU, RAM, and storage resources. This ensures consistent performance without resource contention.
- The platform includes SShield security, which actively monitors and blocks threats in real time. Websites remain protected against malware and unauthorized access.
- Automatic daily backups and server monitoring reduce the risk of data loss and downtime. Recovery processes remain simple and reliable.
- Scala Hosting offers a 99.9% uptime guarantee supported by fully managed support available 24/7. Technical issues are addressed promptly to maintain service continuity.

**Table 1: Cloud Hosting Provider Guarantees**

| **Provider** | **Uptime SLA** | **Scalability Options** | **Compliance & Security** | **Support Availability** |
| --- | --- | --- | --- | --- |
| **Atlantic.Net** | 100% | Flexible CPU, RAM, storage | HIPAA, SOC, GDPR | 24/7 chat, email, phone |
| **Kamatera** | 99.95% | Instant vertical scaling | GDPR, ISO practices | 24/7 support |
| **AWS** | 99.99%* | Auto-scaling, load balancing | HIPAA, SOC, ISO, GDPR | 24/7 support plans |
| **Hostinger** | 99.9% | Scalable cloud plans | GDPR, PCI-DSS | 24/7 chat, email |
| **Scala Hosting** | 99.9% | Managed cloud VPS scaling | GDPR, PCI-DSS | 24/7 managed support |

While providers publish uptime SLA percentages, these numbers can feel abstract. To make them more meaningful, Table 2 translates each SLA into its maximum allowable downtime per year, month, and week.

The calculation uses a standard industry formula:

***Downtime per year****= (1 − SLA) × 8,760 hours*

*8,760 hours = total hours in a year (365 × 24)*

***Monthly downtime****= Annual downtime ÷ 12*

***Weekly downtime****= Annual downtime ÷ 52*

SLA percentages define the maximum downtime permitted before service credits apply.

Actual downtime may be lower depending on infrastructure design and incident response effectiveness.

***Table 2: Cloud Hosting Providers SLA and Maximum Allowable Downtime***

| **Provider** | **SLA** | **Downtime / Year** | **Downtime / Month** | **Downtime / Week** |
| --- | --- | --- | --- | --- |
| Atlantic.Net | 100% | 0 minutes | 0 minutes | 0 minutes |
| AWS | 99.99% | ~52 minutes | ~4 minutes | ~1 minute |
| Kamatera | 99.95% | ~4 hours 23 minutes | ~22 minutes | ~5 minutes |
| Hostinger | 99.9% | ~8 hours 45 minutes | ~44 minutes | ~10 minutes |
| Scala Hosting | 99.9% | ~8 hours 45 minutes | ~44 minutes | ~10 minutes |

To put these numbers in perspective, Atlantic.Net not only guarantees 100% network uptime but also provides financial compensation if the SLA is not met. For example, the provider offers credits of around 5% of the monthly fee for failing to meet uptime guarantees. Penalties increase for more extended outages, typically calculated per 30 minutes beyond the committed time. This approach ensures that customers receive compensation for any disruption and reflects the provider’s commitment to reliability.

## Evaluating Cloud Hosting Providers’ Reliability and Capabilities

Analyzing SLA percentages and maximum downtime figures provides a practical view of each provider’s reliability. High uptime reduces interruptions and improves the visitor experience. Atlantic.Net, for example, offers 100% network uptime with financial credits if commitments are not met, reflecting accountability. AWS and Kamatera also maintain strong reliability, with potential downtime measured in minutes or a few hours. Even slight differences in SLA, such as 0.05%, can result in several hours of downtime per year, potentially affecting operations and customer trust.

Scalability and flexible resource allocation further enhance performance stability. Kamatera provides instant vertical scaling, while AWS supports horizontal scaling through auto-scaling groups and elastic load balancing. Similarly, Hostinger and Scala Hosting offer scalable CPU, RAM, and load balancing, helping websites handle sudden traffic spikes without affecting performance. This allows growing businesses or high-traffic platforms to maintain smooth operation under changing demands.

In addition, security and compliance play a key role in overall reliability. Atlantic.Net adheres to HIPAA, SOC, and GDPR standards, making it suitable for healthcare and financial websites. Likewise, AWS, Kamatera, Hostinger, and Scala Hosting comply with GDPR, PCI-DSS, and ISO standards, which strengthen the protection of sensitive data.

Support availability also influences service continuity. Providers with 24/7 technical support address issues before they escalate into major outages. For instance, Atlantic.Net and Kamatera provide dedicated teams for quick problem resolution, while AWS, Hostinger, and Scala Hosting combine continuous support access with management tools that simplify troubleshooting.

Consequently, considering SLA percentages, downtime calculations, scalability, security, and support together offers a complete picture of each provider’s ability to maintain uninterrupted service, protect data, and support growth. By evaluating these elements collectively, businesses can select the cloud hosting provider that aligns with their performance, reliability, and compliance needs.

## Final Thoughts

Cloud hosting provides a fast, reliable, and flexible solution for websites and applications. However, each provider offers different strengths, so careful evaluation remains essential. For example, Atlantic.Net delivers strong uptime and comprehensive compliance support, which suits high-demand or sensitive workloads. In comparison, Kamatera offers flexible configurations and instant scaling, helping projects adapt quickly to changing demands. Meanwhile, AWS focuses on global scalability and enterprise-grade redundancy, while Hostinger balances affordability with reliable Google Cloud infrastructure. Likewise, Scala Hosting provides managed, security-focused cloud VPS solutions designed for growing businesses.

By considering SLA percentages, maximum downtime, scalability, security standards, and support availability together, businesses gain a clearer understanding of a provider’s real-world reliability. This approach supports consistent website performance, strengthens data protection, and encourages sustainable growth. Selecting the right cloud hosting solution enhances user satisfaction, business continuity, and overall operational efficiency.

 


---

# Top HIPAA Compliant Hosting for Small Businesses in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/top-hipaa-compliant-hosting-small-businesses-2026/ | Published: 2026-01-04 | Updated: 2026-07-24 | Author: Dr. Assad Abbas

*Updated July 2026*

## Key Takeaways

Atlantic.Net ranks first for small healthcare businesses in 2026. It is the only provider here that delivers HIPAA-compliant hosting as a managed, independently audited product with a signed HIPAA Business Associate Agreement (BAA), 24/7 US-based support, and a fixed monthly price. Hence, a five-person clinic never assembles a compliance program from raw cloud parts.

- **Atlantic.Net** is best for small clinics, medical billing firms, and healthcare SaaS teams that want fully managed HIPAA hosting with the BAA and the security stack included.
- **Amazon Web Services (AWS)** is best for digital health startups with in-house cloud engineers who can configure and monitor HIPAA-eligible services themselves.
- **Rackspace** is best for teams that want managed operations across dedicated and multi-cloud hosting environments.
- **Google Cloud Platform (GCP)** is best for healthcare analytics and research teams building on BigQuery and the Cloud Healthcare API.
- **Microsoft Azure** is best for practices standardized on Microsoft licensing, where the HIPAA BAA arrives through agreements they have already signed.

Small healthcare businesses handle sensitive patient data every day, and it has to stay private and meet the Health Insurance Portability and Accountability Act (HIPAA) security and privacy rules.[HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) provides secure infrastructure for electronic Protected Health Information (ePHI). The same category is sold as[HIPAA-compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/top-hipaa-compliant-web-hosting-services-for-secure-data-management/), HIPAA web hosting, or secure healthcare hosting.

In 2026, 772 breaches affecting 500 or more individuals were reported to the HHS Office for Civil Rights, and 136 came from business associates instead of the covered entity itself ([HIPAA Journal breach statistics](https://www.hipaajournal.com/healthcare-data-breach-statistics/)). A hosting provider that stores or transmits ePHI sits squarely in that business associate category.

Smaller practices run on limited IT staff, yet they face the same HIPAA mandates as large hospitals. The five HIPAA-compliant solutions below differ less in raw capability than in how much of the safeguard work arrives already built, already audited, and already staffed.

## What Is HIPAA-compliant Hosting and Why It Matters for Small Businesses

HIPAA-compliant hosting is an environment designed to protect ePHI. It combines the technical safeguards required by the HIPAA Security Rule, administrative controls, physical safeguards in audited data centers, and documented procedures that meet[HIPAA requirements](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/). The hosting provider must also sign a[BAA](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/). Without that agreement, the setup cannot meet HIPAA standards, no matter what the marketing page says.

Under the[security rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/), electronic Protected Health Information covers any identifiable health data stored, processed, or transmitted electronically: medical records, billing information, insurance details, and patient communication. HHS guidance on cloud computing is blunt about what that means for a host. A cloud provider that maintains electronic protected health information is a business associate even when the data is encrypted. It holds no decryption key ([HHS cloud computing guidance](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html)), and it is then directly liable under the HIPAA regulations.

For a small business, HIPAA-compliant hosting reduces two kinds of exposure at once. Cyberattacks on healthcare providers have climbed for years, and small clinics are frequently hit because their IT resources are thin. HIPAA-compliant hosting services cover the security risk and the regulatory responsibility together, and their audit structure makes external reviews less painful as the business grows.

A HIPAA-compliant server needs a specific feature set to do that job.[Data encryption](https://www.atlantic.net/hipaa-compliant-hosting/why-is-encryption-so-key-to-hipaa-compliance/) protects information at rest and in transit, while firewalls and network segmentation block unauthorized access. Intrusion detection and HIPAA compliance monitoring surface suspicious activity early, and role-based access controls and multi-factor authentication tighten the perimeter around accounts. Audit logging supports compliance reporting, which is how a small practice proves to an auditor that its access controls work. Encrypted storage, offsite backups in a separate location, and a tested disaster recovery plan cover the rest.

## Who Needs HIPAA-compliant Hosting?

Many small businesses work with protected health information without realizing it. Any organization that stores, processes, or transmits patient data must meet HIPAA requirements, even if it is small, fully remote, or short on technical staff. A website or portal touching that data needs HIPAA web hosting underneath it.

### Healthcare Providers

Healthcare providers handle protected health information daily: small clinics, dental offices, eye care centers, therapy practices, home health agencies, and telehealth providers. All of them fall under the same HIPAA guidelines and need HIPAA-compliant web hosting to protect that data.

### Billing and Administrative Services

Medical billing companies and revenue cycle management firms work with insurance and treatment data classified as ePHI. They need HIPAA-compliant server hosting, and whoever holds the data has to sign a BAA.

### Healthcare Software and SaaS Companies

Healthcare software companies that connect to[EHR](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-hosting-emr-ehr-systems/) or EMR systems exchange patient data through integrations and APIs, which creates HIPAA responsibility. SaaS platforms, scheduling systems, and patient engagement tools need a HIPAA-compliant application platform underneath, which means a HIPAA-compliant cloud with a BAA in place.

### Common Healthcare Tools and Applications

Patient portals, appointment systems, telehealth platforms, online intake forms, encrypted storage, and messaging systems all handle identifiable health data. HIPAA regulations apply to these healthcare technology systems, and a HIPAA-compliant website needs HIPAA-compliant web hosting underneath it. Check that any plan labeled HIPAA web hosting includes a signed BAA.

### Businesses With BAAs or Identifiable Health Data

A business needs a HIPAA-compliant website and HIPAA-compliant web hosting once it is asked to sign a BAA (BAA), and whenever it handles identifiable health data. Trace how data moves through your systems to confirm whether ePHI is involved.

## How to Choose the Right HIPAA-compliant Hosting Provider

Choosing between HIPAA-compliant hosting solutions means weighing technical, security, and operational requirements together.

### Assessing HIPAA Hosting Needs

HIPAA-compliant hosting solutions are not interchangeable, so start with the volume of ePHI, the typical workload, and expected growth. A HIPAA-compliant cloud suits teams that need flexibility for changing workloads, while HIPAA-compliant server hosting suits organizations that need physical separation or stricter controls. Fully managed HIPAA hosting works for teams with limited IT resources, because the hosting provider handles setup, monitoring, maintenance, and routine operations.

Consider a three-clinician physical therapy practice running a scheduling portal, an EHR, and an intake form that collects patient histories. The workload is small, perhaps two virtual machines and a database. The compliance obligation attached to it is identical to a hospital’s. That gap between workload size and compliance weight is worth holding in mind while comparing HIPAA-compliant hosting providers.

### Evaluation of Provider Experience and Healthcare Focus

Any provider that can offer HIPAA-compliant hosting should have real experience in healthcare hosting and a working command of HIPAA and HITECH Act security standards, including audit trails, audit logging, and breach notification procedures. Ask which audits it completes annually, who performs them, and what they cover. A hosting provider that walks you through your own audit is worth more than one that only passes its own.

### Reviewing Support and Compliance Services

Ongoing HIPAA compliance support is where small teams either keep up or quietly fall behind. Look for managed patching, continuous monitoring, and 24/7 incident response, plus HIPAA compliance services that supply the paperwork as routine: a signed BAA, security architecture diagrams, incident response plans, and evidence of encryption and backup practice. Ask whether the provider will offer HIPAA compliance monitoring or bill it separately.

### Match Provider Capabilities With Organizational Needs

The hosting provider should fit your technical capability and internal resources. When the fit is right, it carries part of the long-term compliance load. When it is wrong, you pay for capability nobody on the team can configure.

## HIPAA-compliant Hosting Providers Compared (2026)

The table compares five HIPAA-compliant hosting solutions on what matters to a small healthcare business: whether the hosting provider will sign a BAA, what is managed for you, and how much compliance work stays on your desk.

| Feature | Atlantic.Net | AWS | Rackspace | Google Cloud | Microsoft Azure |
| --- | --- | --- | --- | --- | --- |
| **HIPAA BAA** | Yes, included as standard | Yes, accepted before PHI use | Yes, on dedicated hosting | Yes, customer requests and executes | Yes, by default via Product Terms |
| **Hosting environments** | HIPAA-compliant cloud, dedicated servers, and private cloud | Public cloud | Cloud, hybrid, managed, and dedicated hosting | Public cloud | Public cloud |
| **Healthcare focus** | High | Medium | Medium | Medium | Medium |
| **Security features** | Managed FortiGate firewall with IPS, IDS, MFA, encrypted VPN, Trend Micro Deep Security, and encrypted backups | Encryption, IAM, CloudTrail logging, and KMS | HITRUST CSF-certified environment, monitoring, logging, and compliance reporting | Default encryption, Cloud Audit Logs, IAM, and VPC Service Controls | Encryption, Entra ID access controls, and Azure Policy HIPAA/HITRUST initiative |
| **Managed services** | Fully managed as standard | Customer-managed | Fully managed | Customer-managed | Customer-managed |
| **Audit support** | Strong, with direct engineer access | Customer-managed | Advanced | Customer-managed | Customer-managed |
| **Ease for small businesses** | High | Low | Low | Low | Low |
| **Scale ceiling** | Flexible, with custom builds up to 1 TB ECC RAM | Very high | High | Very high | Very high |
| **Best for** | Clinics, billing firms, and healthcare SaaS | Technical teams and digital health startups | IT teams and hybrid deployments | Analytics and research platforms | Microsoft-standardized teams |

Table 1: Comparison of top HIPAA-compliant hosting providers for small businesses.

## Top HIPAA-compliant Hosting Providers for Small Businesses (2026)

The five HIPAA-compliant hosting solutions below are ordered for a small healthcare buyer.

### Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

[Atlantic.Net](https://www.atlantic.net/) has built its business around regulated industries, healthcare chief among them. It offers[HIPAA-compliant cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) and dedicated servers with a signed BAA included as standard, sized and supported for small[healthcare organizations](https://www.atlantic.net/hipaa-compliant-hosting/healthcare-organizations-embracing-cloud-computing/) with no platform team of their own.

- The HIPAA-compliant infrastructure is independently audited every year against[SOC 2 Type II, SOC 3 Type II, SSAE 18, HIPAA, and HITECH](https://www.atlantic.net/hipaa-compliant-hosting/) by a third-party CPA firm. Those reports are what an auditor asks to see, and they cover the data centers, physical safeguards, operational controls, and technical safeguards.
- The security stack ships switched on: a managed FortiGate firewall with IPS, intrusion detection, multi-factor authentication, role-based access controls, a managed encrypted VPN with five accounts, bi-weekly vulnerability scanning, file integrity monitoring, and daily encrypted onsite and offsite backups. Trend Micro Deep Security Suite is included from the Business tier upward.
- The entry HIPAA tier, Fortress Developer, provides 6 vCPU, 16 GB RAM, 200 GB SSD, and 10 TB of transfer, from $492.31 per month on Linux on a 12-month term. Four hours of migration service are included, with additional hours at $160.
- Support is 24/7/365 from US-based engineers in English and Spanish, never outsourced, and the HIPAA-compliant environment carries a[100% uptime SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/).

One honest caveat: that entry price sits well above a general-purpose $10 cloud instance, and it should. What you are buying is a private, pre-audited HIPAA-compliant environment with the firewall, backups, scanning, VPN, and management already staffed. For a practice with no security engineer, the arithmetic usually works out. For a team already running its own security operations, it may not.

#### Who Should Choose Atlantic.Net?

Small clinics, medical billing companies, and healthcare SaaS platforms that need reliable HIPAA-compliant services with a strong default security posture and direct access to human HIPAA compliance support.

### Amazon Web Services (AWS)

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

AWS provides a very broad set of HIPAA-eligible services under a signed BAA (BAA). It is widely used across healthcare and supports applications of almost any size. A HIPAA-compliant deployment depends on correct configuration and on the customer holding up its end of the shared responsibility model.

- More than 170 services appear on the AWS eligibility reference, including Amazon EC2, Amazon S3, Amazon RDS, Amazon EBS, AWS Lambda, Amazon DynamoDB, Amazon VPC, AWS CloudTrail, and AWS Key Management Service.
- AWS requires customers to sign a BAA before any of those services touch PHI. Eligibility is only the starting condition.
- Encryption covers data at rest and in transit; AWS KMS handles key management, and identity and access management supports role-based access with audit logging through CloudTrail.
- Scale is effectively unlimited, which suits healthcare applications with unpredictable growth or heavy data processing.

#### Who Should Choose AWS?

AWS fits healthcare software companies, digital health startups, and technical teams that can manage cloud security, strict access controls, audit logging, and HIPAA compliance responsibilities internally.

### Rackspace

![](https://www.atlantic.net/wp-content/uploads/2025/12/rackspace_logo.png)

Rackspace offers enterprise cloud and managed hosting services with HIPAA support, and it will sign a BAA covering its dedicated hosting. The platform is capable, and it generally expects a technical buyer.

- Rackspace holds a HITRUST CSF certification validated against more than 300 requirements across 19 security categories, covering dedicated servers, private cloud, databases, networking, and storage across its data centers at no extra cost.
- Monitoring, audit logging, and compliance reporting are included, and managed services cover configuration, updates, and incident management, so operations stay steady without an in-house on-call rota.
- Rackspace also runs workloads on AWS, Azure, and GCP, which suits a team already committed to a hyperscaler that wants someone else operating it.

#### Who Should Choose Rackspace?

Teams with internal IT staff that need enterprise-level managed hosting, hybrid or multi-cloud hosting environments, and heavy customization.

### Google Cloud Platform (GCP)

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

GCP provides HIPAA-covered services for healthcare workloads under a customer-executed BAA. GCP leans on data analytics, performance, and global data centers, and a HIPAA-compliant setup again depends on correct configuration under the shared responsibility model.

- The GCP BAA covers more than 100 products, including Compute Engine, Cloud Storage, BigQuery, Cloud SQL, Google Kubernetes Engine, Cloud Run, and the Cloud Healthcare API.
- Encryption is applied by default at rest and in transit, which removes one common configuration mistake.
- Cloud Audit Logs, Cloud Monitoring, and Security Command Center support audit preparation, and the BAA covers all regions and zones with no isolated compliance zone.

#### Who Should Choose GCP?

Healthcare analytics platforms, research organizations, and technical teams that need advanced data processing and can manage HIPAA compliance configuration independently.

### Microsoft Azure (HIPAA-Eligible Services)

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

Microsoft Azure offers public cloud services with HIPAA-eligible components across data centers worldwide. Azure supports very large workloads, and a HIPAA-compliant deployment there requires correct configuration to keep protected health information secure.

- The Azure BAA is supplied by default through the Microsoft Product Terms and the Data Protection Addendum. There is no separate contract to sign, which removes a procurement step that stalls small teams.
- Compute, storage, and database services support[HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-in-the-age-of-ai/) when configured correctly, and Azure Policy ships a built-in HIPAA/HITRUST initiative that maps each control to customer, Microsoft, or shared responsibility.
- Customers still own access controls, audit logging, and encryption settings. Misconfiguration is the most common source of compliance risk for small teams on any hyperscaler.
- Azure and Azure Government both hold FedRAMP High authorization and ISO/IEC 27001 certification, which many healthcare procurement teams accept as supporting evidence.

#### Who Should Choose Microsoft Azure?

Technical teams and healthcare software companies already standardized on Microsoft licensing that can manage cloud configuration and security settings themselves.

## What the Proposed Security Rule Update Means for HIPAA Hosting Decisions

On December 27, 2024, the HHS Office for Civil Rights issued a Notice of Proposed Rulemaking to modernize the rule governing ePHI safeguards ([HHS fact sheet](https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/factsheet/index.html)). The proposals would remove the distinction between required and addressable safeguards, mandate encryption of protected health information at rest and in transit, mandate multi-factor authentication and network segmentation, require a technology asset inventory and network map reviewed at least every 12 months, and require vulnerability scanning at least every six months with penetration testing at least every 12 months.

One caveat belongs here. The rule is still proposed; HHS states plainly that the current rule remains in effect while rulemaking continues, and the timetable for final action has already moved more than once. Nothing in the NPRM is enforceable today.

The practical point is simpler. Every safeguard on that list already exists in well-built HIPAA-compliant hosting solutions. Encryption at rest and in transit, MFA, network segmentation, bi-weekly vulnerability scanning, documented backup and disaster recovery, and annual third-party audits are standard on Atlantic.Net HIPAA-compliant hosting plans today. A hosting provider that already operates that way leaves a shorter list of things to change if the rule lands.

## Common HIPAA Compliance Mistakes Small Businesses Make

Small practices hit the same problems repeatedly, even on well-chosen HIPAA-compliant hosting solutions, usually because resources are thin.

Using a hosting provider that will not sign a BAA is the most common. Without that agreement, responsibility for protecting ePHI is undefined, which creates regulatory and legal exposure for the covered entity. Confirm it before any data moves.

Weak access controls come second. Loosely managed permissions or missing multi-factor authentication raise the risk of unauthorized access to sensitive patient data. Strict access controls and stronger authentication close most of that gap.

Incomplete documentation causes trouble during audits. Missing records of security configurations, access logs, or incident responses make HIPAA compliance hard to prove even when the technical safeguards are sound. Keep the records current, because an auditor evaluates evidence and nothing else.

Skipping regular risk assessments is another familiar one. Without scheduled reviews, small teams miss vulnerabilities that expose ePHI, and a structured quarterly assessment catches threats early.

Assuming that all cloud hosting environments meet HIPAA standards out of the box is the mistake with the widest blast radius. Services have to be configured correctly, and the provider has to be contractually bound as a business associate. Knowing where the platform’s responsibility stops, and yours begins, protects patient data more reliably than any feature list.

## Final Thoughts

The pattern across all five HIPAA-compliant hosting solutions is consistent. Platform breadth is easy to buy and expensive to operate. Managed HIPAA compliance is harder to buy and cheaper to operate. AWS, Rackspace, GCP, and Azure serve specialized needs such as very large scale, hybrid estates, or advanced analytics, and each expects internal technical resources to run compliantly.

Atlantic.Net sits on the other side of that line, with HIPAA-compliant cloud hosting, dedicated servers in audited data centers, a managed security stack, disaster recovery, and hands-on guidance from US-based engineers. That fits clinics, billing services, and healthcare SaaS platforms that need a human on the phone during an audit. Choosing HIPAA-compliant hosting for a small healthcare business comes down to how much of that work you can absorb.

Atlantic.Net will walk through your ePHI footprint, where the shared responsibility line falls, and what our HIPAA, SOC 2 Type II, and HITECH audit reports cover, then size a HIPAA-compliant hosting plan against the workload you actually run.

[Contact the Atlantic.Net solutions team](https://www.atlantic.net/about-us/corporate-contact/) to scope HIPAA-compliant hosting with the BAA, the[managed security stack](https://www.atlantic.net/managed-services/), and 24/7 US-based support included from day one.

## Frequently Asked Questions

### Where Can You Get Affordable HIPAA Hosting With 24/7 Compliance Support?

Atlantic.Net is the most practical option for small healthcare businesses that need both. Its HIPAA hosting packages start at $492.31 per month on Linux for 6 vCPU, 16 GB RAM, 200 GB SSD, and 10 TB of transfer, and include the managed firewall, encrypted backups, vulnerability scanning, managed VPN, MFA, and a signed BAA, with 24/7/365 US-based support. Cheaper HIPAA hosting exists, and on the hyperscale, rs the security tooling and compliance labor arrive as separate line items and separate hires.

### Which HIPAA Hosting Services Include BAAs?

All five providers here offer HIPAA-compliant hosting with a BAA (BAA), delivered differently. Atlantic.Net includes a signed BAA as standard with every HIPAA hosting plan. Microsoft supplies the Azure BAA by default through the Product Terms and Data Protection Addendum. AWS requires you to accept its BAA before any eligible service touches PHI. GCP asks the customer to request and sign a BAA, and Rackspace will sign one covering its dedicated hosting. No BAA means no HIPAA-compliant hosting.

### What Is the Difference Between HIPAA-Eligible Hosting and Fully HIPAA-Compliant Hosting?

HIPAA-eligible means a service is permitted to handle ePHI under a BAA. A HIPAA-compliant environment is one where the safeguards are configured, operating, and documented. AWS, GCP, and Azure publish eligibility lists, and putting ePHI on a listed service does not deliver true HIPAA compliance. You still own encryption settings, access controls, audit logging, backup, and the risk analysis. Fully managed HIPAA-compliant hosting solutions close that gap by delivering the safeguards pre-built and pre-audited.

### What Features Should You Look for in HIPAA-compliant Cloud Servers?

Start by correcting the term. There is no such thing as HIPAA compliance, so treat any HIPAA-compliant claim with caution. Secure infrastructure for a HIPAA-compliant server means encryption at rest and in transit, a managed firewall with intrusion detection and prevention, multi-factor authentication, role-based access controls, audit logging, regular vulnerability scanning, file integrity monitoring, encrypted on-site and off-site backups with tested disaster recovery, and an independent annual audit such as SOC 2 Type II. A signed BAA and named 24/7 support complete the list.

### Who Offers Fully Managed HIPAA Hosting for Startups and Clinics?

Atlantic.Net and Rackspace both offer fully managed HIPAA hosting solutions for different buyers. Atlantic.Net is built around small and mid-sized healthcare organizations, with managed HIPAA hosting plans that include the BAA, the security stack, server management, and four hours of migration service. Rackspace focuses on larger managed and hybrid hosting environments and assumes an internal IT team. AWS, GCP, and Azure are self-managed, so a clinic choosing one is also choosing to hire for the compliance work.

### What Are the Penalties for a Hosting-Related HIPAA Data Breach?

Civil monetary penalties are tiered by culpability and adjusted for inflation each year. For violations assessed on or after January 28, 2026, they run from $145 per violation at the lowest tier up to $73,011 per violation for willful neglect, with an annual cap of $2,190,294 where willful neglect goes uncorrected. Criminal penalties reach up to 10 years imprisonment for obtaining PHI with intent to sell or for personal gain. Fines are rarely the highest cost, though. Breach notification, forensics, and lost patient trust usually exceed them.

### Does HIPAA Hosting Alone Deliver Full HIPAA Compliance?

No. HIPAA hosting alone does not ensure HIPAA compliance. HIPAA-compliant infrastructure covers one layer, and the rest is shared. Your internal policies, workforce training, risk analysis, access management, and the security of your own application code all sit on your side of the line. A good hosting provider narrows the scope of what you have to prove and supplies the evidence for its own layer. It cannot sign off on yours.

### Which Hosting Type Is Best for Small Healthcare Businesses?

A managed HIPAA-compliant cloud suits most small healthcare businesses. It gives flexibility for changing workloads without an in-house infrastructure team, and a HIPAA-compliant hosting plan covers patching, monitoring, backups, and disaster recovery. A dedicated HIPAA-compliant server makes sense when you need physical separation, consistent performance, or specific hardware. Unmanaged hosting is the wrong answer for a team with no security staff, whatever the price difference on the order form.


---

# Affordable HIPAA-Compliant Web Hosting in 2026: What Healthcare Organizations Should Really Look For

> URL: https://www.atlantic.net/hipaa-compliant-hosting/affordable-hipaa-compliant-web-hosting-2026/ | Published: 2026-01-06 | Author: Dr. Tehseen Zia

Healthcare organizations face a significant challenge in the 2026 regulatory environment. They must protect electronic Protected Health Information (ePHI)—which refers to any PHI that is covered under HIPAA regulations and is produced, saved, transferred, or received in an electronic form—adhere to HIPAA rules, and manage IT costs. This struggle is especially difficult for small clinics, health tech startups, medical billing companies, and telehealth platforms. HIPAA-compliant web hosting is a mandatory requirement, but it is often viewed as a costly undertaking.

The following guide explains how to make HIPAA-compliant hosting affordable without being locked into oversized contracts. The key is understanding what affordability means in a HIPAA context and how to choose a hosting provider that supports both compliance and growth. We also highlight features that cannot be compromised to ensure organizations make smart decisions without risking patient trust.

## Understanding What HIPAA Hosting Really Requires

[HIPAA compliance](https://aws.amazon.com/compliance/hipaa-compliance/) is not a product that you can purchase; it is a shared responsibility between the healthcare organization and its hosting provider. Any environment that stores, processes, or transmits ePHI must meet administrative, physical, and technical requirements.

From a technical perspective, this [includes](https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/administrative/securityrule/techsafeguards.pdf) encryption for stored data and data in transit, specifically using TLS 1.2 or 1.3 standards. On the administrative side, the provider must sign a HIPAA Business Associate Agreement. Without a signed BAA, no hosting environment can be considered HIPAA-compliant, regardless of its security claims. It is crucial to remember that there is no official “HIPAA Certification”; instead, providers like Atlantic.Net are fully HIPAA-compliant.

## Why Affordable Does Not Mean Cheap

In healthcare IT, the cheapest option often costs more in the long run. Basic shared hosting environments usually lack proper isolation and the detailed logging required for a BAA. The cost savings in HIPAA-compliant hosting come from predictable pricing and right-sized infrastructure. Our well-designed environments prevent data breaches and reduce audit stress. It is essential that hosting supports growth; instead of paying for unused capacity, teams can start small and expand as patient volumes grow.

## The Role of Infrastructure Choice in Cost Control

One of the biggest factors in hosting cost is infrastructure choice. Virtual private servers, cloud platforms, and dedicated servers can all support HIPAA compliance when configured correctly.

- **Cloud Servers:** These are often the most affordable option for HIPAA workloads. They provide isolation, customizable security settings, and predictable monthly pricing. For small practices, our VPS hosting can meet compliance requirements without unnecessary expense.
- **Cloud Hosting:** This provides flexibility and scalability. However, the costs can rise quickly if resources are not closely monitored. Clear pricing and defined usage limits are pivotal for keeping cloud-based HIPAA hosting affordable.
- **Dedicated Servers**: These provide [maximum control and consistent](https://www.atlantic.net/hipaa-compliant-hosting/choosing-bare-metal-or-dedicated-hosting-for-healthcare-pros-and-cons/)performance. While they were once seen as an expensive option, we now offer dedicated environments at more competitive prices. For organizations handling large volumes of patient data, this option can be cost-effective over time.

## Security Features That Must Always Be Included

Every HIPAA hosting environment needs a core set of [security features](https://quickblox.com/blog/hipaa-hosting-essentials-how-to-keep-your-healthcare-app-secure/), regardless of cost. Encryption protects patient data both when it is stored and when it travels across networks. Access controls ensure that only approved users can view or modify sensitive information. Audit logs track who accessed data and provide the records needed for compliance reviews.

Encryption is essential for data at rest and in transit. It helps protect patient information even if a system is compromised. Access controls keep sensitive data available only to authorized users. Audit logs record all access and help organizations show compliance during audits.

Regular backups and disaster recovery capabilities are equally important. Many hosting solutions often include automated backups as part of the base offering, reducing the need for third-party tools and manual processes. Network security features such as firewalls and intrusion detection further reduce risk. When these controls are built into the hosting platform, organizations save money and stay protected.

## Demystifying the Cost of Compliant Hosting

When evaluating affordability, view cost in terms of value and risk. Basic, unmanaged HIPAA-compliant servers may start at a few hundred dollars per month, while fully managed, enterprise-level solutions can cost more. However, viewing this in terms of expense only might be misleading. HIPAA-compliant hosting is an investment in risk reduction and operational stability.

The cost of non-compliance should also be part of this calculation. HIPAA violations can lead to fines reaching into the millions, along with long-term damage to an organization’s reputation. A reliable, HIPAA-compliant host acts as an insurance policy. For smaller practices, choosing a managed provider like Atlantic.Net can be more cost-effective than hiring a full-time, specialized IT security expert.

## Making the Right Decision for Your Organization

When choosing a hosting provider, there are plenty of options, and each comes with its own advantages.

### The Atlantic.Net Advantage

We focus entirely on compliance. We design our infrastructure specifically for healthcare data and undergo independent third-party audits for HIPAA, [HITECH](https://en.wikipedia.org/wiki/Health_Information_Technology_for_Economic_and_Clinical_Health_Act), and [SOC compliance](https://www.ninjaone.com/blog/what-is-soc-compliance-overview/). We offer fully managed services, taking care of tasks like security updates, firewall management, and compliance documentation. This approach reduces the workload for your IT team and ensures that compliance requirements are consistently met.

### Public Cloud Alternatives

Major public cloud platforms like [AWS](https://aws.amazon.com/compliance/hipaa-compliance/), Microsoft [Azure](https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-hipaa-us), and [Google Cloud](https://cloud.google.com/security/compliance/hipaa) offer “HIPAA-eligible” services. These platforms provide scalability and will sign a BAA. However, they use a shared responsibility model. The provider secures the underlying infrastructure, but you are responsible for correctly setting up services. This means your team needs strong technical expertise to avoid configuration mistakes.

For organizations using specific platforms, specialized providers also exist. Some offer secure, [HIPAA-compliant WordPress hosting](https://convesio.com/features/hipaa-compliant-wordpress-hosting/) with isolated containers, while others provide APIs for building HIPAA-compliant telehealth or communication features. Your choice should align not just with your technical capabilities but with your strategic focus.

## Final Considerations for 2026

Affordable HIPAA-compliant hosting is about finding the balance between security, functionality, and cost. It is about selecting a hosting environment that delivers the required security and reliability at a cost that aligns with your organization’s size. Key considerations include a signed BAA, built-in security controls, transparent pricing, and infrastructure that can scale.

By understanding what HIPAA hosting truly requires and evaluating providers based on both cost and responsibility, healthcare organizations can protect patient data and maintain financial control. The right hosting decision supports long-term stability and allows teams to focus on patient care.


---

# Top Cloud Hosting with Excellent Customer Support in 2026

> URL: https://www.atlantic.net/cloud-platform/top-cloud-hosting-excellent-customer-support-2026/ | Published: 2026-01-06 | Author: Dr. Assad Abbas

[Cloud hosting](https://aws.amazon.com/what-is/cloud-hosting/) plays an essential role in modern business operations. Organizations rely on it to support eCommerce platforms, internal systems, and applications that handle electronic Protected Health Information (ePHI). As businesses depend more on digital services, website uptime and system reliability directly affect revenue and reputation. Even minor disruptions can create massive operational challenges.

Although cloud infrastructure is resilient, technical issues occur. Servers can fail, software errors arise, and unexpected traffic surges can degrade performance. Infrastructure alone cannot guarantee continuous service. For this reason, customer support is a critical component of cloud hosting.

Timely, knowledgeable technical assistance helps restore services and provides peace of mind during high-pressure situations. When you select a cloud hosting provider, you should look beyond technical specifications; support quality is a foundational factor in achieving long-term success.

## What Cloud Hosting Is and Why Support Plays a Central Role

Cloud hosting stores data across multiple connected servers that work together. When one server fails, another takes over. This process helps keep systems available and stable. At the same time, it adds technical complexity that requires constant attention.

Because of this complexity, human support becomes essential. Support teams continuously monitor system performance and respond to alerts. They manage workloads during high-traffic periods and guide businesses through configuration or operational issues. Unlike simpler hosting types, cloud hosting relies on close coordination between technical teams and infrastructure to maintain smooth operations.

Furthermore, this collaboration turns technical potential into practical reliability. Skilled support staff oversee updates, troubleshoot problems, and optimize resource use. Without their guidance, even advanced cloud systems may fail to deliver consistent performance. Therefore, the real value of cloud hosting emerges when strong infrastructure is paired with expert, responsive support.

## Core Cloud Hosting Benefits Supported by Expert Assistance

Cloud hosting offers several significant benefits for businesses. These benefits become more effective when guided by knowledgeable support teams.

### Scalability

Support teams help businesses plan for growth and adjust cloud resources during sudden traffic spikes. Consequently, the hosting environment can scale smoothly without performance drops, ensuring applications and websites remain responsive.

### Reliability

Redundant servers in a cloud hosting platform reduce the risk of downtime. Nevertheless, expert support ensures failover events and recovery processes are handled quickly, keeping systems stable and minimizing disruptions.

### Performance

A cloud hosting platform performs best when performance is regularly monitored. Support engineers monitor for slowdowns, resolve configuration issues, and optimize resource usage. Their involvement keeps websites fast and responsive for users at all times.

### Security

Cloud hosting environments face constant threats from malware, DDoS attacks, and software vulnerabilities. Support teams respond immediately to alerts, guide recovery steps, and implement safety measures. This keeps data protected and operations secure.

### Managed Services

Provider support in a cloud hosting platform reduces the operational burden on internal teams. Therefore, businesses can focus on core activities while relying on expert guidance for maintenance, updates, and troubleshooting.

## Consequences of Inadequate Cloud Hosting Support

In cloud hosting, inadequate support can lead to serious operational, security, and performance consequences for businesses. When technical problems occur, slow or ineffective assistance can increase downtime. This may halt transactions, delay projects, and negatively affect customer relationships. Even brief outages can reduce client confidence and harm the company’s reputation.

Security incidents pose an even greater threat. Without timely guidance from experienced support teams, a data breach or malware attack can spread rapidly. Consequently, businesses may face loss of sensitive information, regulatory penalties, and long-term reputational damage. Each hour of delayed response further compounds these technical and legal risks.

Misconfigurations and failed updates create additional challenges. When businesses operate without proper support, systems may become unstable or inefficient, reducing performance and reliability. Moreover, attempts to fix these problems internally often consume time and resources and may introduce new vulnerabilities.

Automated monitoring tools can detect issues, but they cannot make critical decisions under high pressure. Therefore, skilled cloud hosting engineers are essential for interpreting alerts, prioritizing actions, and coordinating recovery. In this way, poor customer support is not merely an inconvenience; it can directly threaten business continuity, data security, and customer trust.

## Evaluating and Defining Excellent Cloud Hosting Support

Choosing a cloud hosting provider involves evaluating more than just uptime guarantees or infrastructure capacity. The accurate measure of reliability depends on customer support, specifically, how responsive, skilled, and consistent a provider is when problems occur. For businesses that rely on digital operations, adequate support directly affects performance, continuity, and customer trust.

Several criteria help evaluate support quality and define excellence.

### Availability

Support must be accessible 24/7 so that assistance is ready whenever issues arise. This ensures downtime is minimized and business operations continue smoothly.

### Technical Competence

Responses should come from engineers who understand both infrastructure and applications. Such expertise allows problems to be diagnosed and resolved efficiently, reducing the risk of prolonged disruption.

### Communication Quality

Clear and timely updates keep clients informed during incidents. Moreover, transparent explanations help businesses make decisions and respond effectively to challenges.

### Consistency

Support quality should remain stable over time. Maintaining reliable service long after onboarding builds trust and confidence in the provider.

### Compliance Expertise

Providers serving regulated industries must understand frameworks such as HIPAA, PCI, and SOC

2. This knowledge ensures that recovery actions comply with legal and security requirements.

Meeting these criteria establishes the foundation for strong cloud hosting support. The best providers go further by proactively monitoring systems, identifying potential problems before they become serious. This approach ensures that urgent issues are quickly escalated to senior specialists immediately. In complex cloud hosting environments, such readiness enables support teams to act as proactive partners rather than simply reacting to problems.

## Top Cloud Hosting Providers with Excellent Customer Support

Below, some cloud hosting providers offering excellent customer support services are briefly discussed:

### Atlantic.net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

[Atlantic.net](http://www.atlantic.net) is a U.S.-based cloud hosting provider known for combining reliable infrastructure with expert customer support. It is suitable for businesses that value consistent uptime and hands-on guidance. From initial setup to long-term operations, Atlantic.net’s team works closely with clients to ensure a smooth hosting experience.

- All support requests at Atlantic.net are directed to experienced staff, without outsourcing, ensuring businesses receive rapid, accurate assistance during technical issues.
- The support teams actively guide businesses through onboarding and resource expansion, helping reduce errors and minimize downtime.
- With extensive experience in healthcare and other regulated industries, Atlantic.net helps maintain audit readiness and implement effective security protocols.
- Systems are continuously monitored, and alerts are routed to specialists immediately, ensuring a rapid response to potential problems.

### Amazon Web Services (AWS)

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

[AWS](https://aws.amazon.com/) operates one of the world’s largest cloud infrastructures, offering flexibility for organizations of all sizes. Support depends on the plan, but it provides tools to manage complex workloads efficiently.

- Tiered support gives entry-level plans basic assistance and premium plans rapid access to senior engineers.
- Extensive documentation and self-service tools help developers navigate the platform, with guidance available for less technical users.
- Higher-tier subscriptions provide enterprise-grade support with fast escalation for urgent issues.
- Support is most effective alongside experienced in-house teams, maximizing AWS’s potential.

### Google Cloud Platform (GCP)

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

[Google Cloud Platform](https://cloud.google.com/) offers robust infrastructure and innovative data management tools for developers and technical teams. It is designed to handle high-performance and data-intensive workloads, with support that complements the platform’s technical nature.

-  Google Cloud follows a developer-centric support model, providing detailed documentation and technical resources, while direct assistance becomes more accessible through premium plans.
- The platform continuously monitors systems, and the GCP support team steps in efficiently during complex incidents, helping maintain smooth operations and minimize disruptions.
- Teams working on AI or big data projects benefit from GCP’s guidance on advanced tools and services, improving both workflow efficiency and outcomes.
- Support response times depend on the chosen plan, with higher-tier subscriptions offering faster assistance for urgent situations and critical issues.

### Microsoft Azure

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

[Microsoft Azure](https://azure.microsoft.com/en-us) provides a broad cloud ecosystem that integrates smoothly with Microsoft tools. Its hybrid cloud features and enterprise-ready services make it a strong choice for larger organizations with varied workloads. How Azure handles support can make a big difference in keeping operations running without interruptions.

- Azure’s paid support plans give businesses tiered access to knowledgeable engineers, so critical issues get resolved quickly, with higher subscription levels offering faster and more comprehensive assistance.
- The support team follows clear workflows and documentation, helping organizations navigate complex setups without confusion.
- Businesses using Windows or other Microsoft software benefit from tight integration, which improves continuity and system efficiency.
- Enterprise IT teams get the most value from Azure support, while smaller teams might need extra managed services to make the most of the platform.

### HostGator

![](https://www.atlantic.net/wp-content/uploads/2025/08/Hostgator-logo.png)

[HostGator](https://www.hostgator.com/) provides cloud hosting tailored for small and mid-sized businesses. The platform combines simplicity with responsive support, helping teams manage their websites and applications without unnecessary stress. This approach makes it easier for companies with limited technical resources to keep operations running smoothly.

- Businesses can reach HostGator’s support team 24/7 via live chat or phone, helping resolve common issues quickly and efficiently.
- The support staff assist customers through setup, routine maintenance, and troubleshooting, ensuring the platform is easy to use for everyday operations.
- HostGator handles several managed aspects of cloud hosting, relieving internal teams of routine technical tasks.
- This provider is best suited to smaller businesses with straightforward cloud needs, offering dependable support for general hosting requirements.

### Scala Hosting

![](https://www.atlantic.net/wp-content/uploads/2025/12/scala-hosting.jpg)

[Scala Hosting](https://www.scalahosting.com/) delivers managed cloud solutions with a strong focus on performance and personalized support. The platform is designed for businesses that want both flexibility and attentive guidance throughout their cloud operations.

- Scala Hosting offers direct client communication to resolve issues quickly and provide tailored advice for each client’s unique setup.
- The provider manages routine operations, such as monitoring and maintenance, helping internal teams focus on core business tasks.
- Support helps optimize performance, tune speed, and improve uptime across various workloads.
- Engineers assist with scaling and configuration adjustments to minimize bottlenecks and ensure smooth growth.

### Kamatera

![](https://www.atlantic.net/wp-content/uploads/2025/12/kamatera-logo-1.png)

[Kamatera](https://www.kamatera.com/) provides highly flexible cloud hosting with complete control over infrastructure. It emphasizes on-demand support to help businesses configure their systems efficiently, making it ideal for organizations that want both customization and reliable guidance.

- Kamatera’s experts advise on cloud configurations that align with business goals and technical requirements.
- Support teams respond promptly to identify and resolve issues, ensuring operational continuity.
- Guidance is provided for scaling resources, helping businesses increase or decrease infrastructure as needed.
- The platform is highly suitable for teams with technical expertise, though less experienced users can rely on support for detailed guidance.

**Table 1: Comparison of Cloud Hosting Support**

| **Provider** | **24/7 Support** | **Technical Expertise** | **Managed Services** | **Best For** |
| --- | --- | --- | --- | --- |
| **Atlantic.Net** | ✓ U.S.-based | High | Yes | SMBs, regulated industries |
| **AWS** | Plan-based | Very High | Yes (premium tiers) | Large enterprises, technical teams |
| **Google Cloud** | Plan-based | High | Yes (premium tiers) | Developer-led teams, data workloads |
| **Azure** | Plan-based | High | Yes (enterprise tiers) | Microsoft ecosystems, enterprises |
| **HostGator** | ✓ | Moderate | Partial | Small and mid-sized businesses need |
| **Scala Hosting** | ✓ | Moderate–High | Yes | Personalized managed cloud |
| **Kamatera** | ✓ | Moderate | Partial | Flexible, custom cloud setups |

## Analysis of Cloud Hosting Support Across Providers

When examining major cloud hosting providers, the relationship among support, uptime, and performance becomes clear. These elements do not operate separately; instead, they influence one another in daily operations. For example, Atlantic.net combines stable infrastructure with direct technical assistance. As a result, businesses receive guidance during onboarding and scaling while maintaining system stability, which is particularly important for regulated industries. Similarly, AWS offers tiered support together with extensive self-service resources. Consequently, large organizations and technically skilled teams can quickly reach senior engineers when serious issues arise. At the same time, Google Cloud places strong emphasis on developer-oriented support, providing timely assistance when data-intensive or AI-related workloads encounter difficulties.

In contrast, Microsoft Azure focuses on enterprise environments by using structured support processes and close integration with Microsoft products. This approach helps organizations maintain continuity and reduce service interruptions. Meanwhile, HostGator prioritizes simplicity and accessibility, which benefits smaller businesses that depend on consistent support without deep technical expertise. Likewise, Scala Hosting adopts a managed cloud model with personalized guidance, where support teams assist with performance improvement, resource adjustments, and steady scaling. In addition, Kamatera offers flexible infrastructure with on-demand support, which suits technically capable teams that prefer control while still relying on expert input when required.

Taken together, these providers show a consistent pattern across different service models. Skilled support strengthens infrastructure and contributes to reliable operations. Support teams respond to incidents promptly, while also improving performance and maintaining stability during traffic increases or unexpected technical events. Therefore, for organizations of varying sizes, the combination of experienced support and robust infrastructure results in a cloud environment that remains stable, responsive, and well-suited for future growth.

## Final Thoughts

Selecting a cloud hosting provider extends beyond infrastructure specifications and pricing models. Instead, long-term stability depends on the support teams that remain engaged when systems experience unexpected demands. In this context, reliable assistance strengthens performance, protects sensitive data, and limits disruption. As a result, organizations gain the confidence to focus on strategic goals rather than on operational uncertainty.

Moreover, support quality influences how effectively a cloud environment adapts over time. When teams respond promptly, communicate consistently, and assist during periods of expansion, organizations remain steady even as workloads increase. In addition, this ongoing support and guidance reduces risk during critical transitions and reinforces operational resilience.

Therefore, assessing support capabilities critically matters for businesses over time. It helps maintain regulatory readiness, supports continuity planning, and strengthens trust with clients and stakeholders. In practice, cloud hosting delivers real value when reliable infrastructure is supported by skilled support teams that remain involved, accountable, and responsive throughout the platform’s lifecycle.

At Atlantic.Net, we understand that cloud hosting delivers the most value when reliable infrastructure is paired with a team that remains accountable and responsive throughout the platform’s lifecycle. Contact us today to learn how our HIPAA-compliant hosting can support your 2026 business objectives.

 


---

# Benefits of Bare Metal Hosting for Enterprise IT

> URL: https://www.atlantic.net/dedicated-server-hosting/benefits-bare-metal-hosting-enterprise/ | Published: 2026-01-07 | Updated: 2026-06-23 | Author: Robert Agar

Companies seeking to modernize specific systems or elements of their IT environment often engage cloud services rather than upgrading an on-premises data center. Cloud service providers (CSPs) typically offer a range of solutions, including virtual servers and shared public [cloud hosting](https://www.atlantic.net/vps-hosting/what-is-cloud-hosting/). Many organizations find these solutions sufficient to address their business needs.

When selecting bare metal hosting for enterprise, it is important to evaluate performance, security, compliance, and scalability needs, along with a thorough cost analysis. These factors help ensure the chosen solution meets both technical and budgetary requirements.

Enterprise clients often require more resources than they can obtain with a [shared hosting](https://www.atlantic.net/vps-hosting/vps-hosting-vs-shared-hosting-pros-cons-differences-and-expert-tips/) environment. They may have mission-critical business applications or process sensitive information that is not a good fit for public cloud services. For these organizations, cost control and the ability to securely manage critical data are essential considerations. Bare-metal hosting offers an alternative solution that aligns with enterprise client requirements and objectives.

## What is Bare Metal Hosting?

Bare-metal hosting is a cloud hosting model in which a single tenant provisions an entire physical server from a CSP. Customers do not share a [virtualization](https://www.atlantic.net/vps-hosting/what-is-server-virtualization/) layer with other clients, unlike public cloud solutions. They have full control of a dedicated server, without the capital expenses involved with purchasing and maintaining the hardware in an on-premises data center.

Account management is crucial for enterprise clients, as account-based services help manage servers efficiently and support critical applications, ensuring high availability and scalability within enterprise infrastructure.

Companies can alleviate many of their concerns about a shared cloud environment by using bare-metal servers. The characteristics of bare metal servers make them an attractive option for enterprise clients.

Bare metal servers also support a wide range of operating systems and distributions, including Windows, Ubuntu, and VMware ESXi.

### Key Characteristics of Dedicated Bare Metal Servers

Bare metal servers are distinguished by several key characteristics that offer enterprise customers advantages over shared cloud services.

- **A dedicated server:** Companies get exclusive use of the server and its associated resources. Businesses enjoy predictable, consistent performance because there is no competition for the environment’s processors, memory, storage devices, and network bandwidth. Clients are not affected by issues such as noisy neighbors, fluctuating demand, excessive network traffic, or hypervisor contention.
- **Complete administrative control:** Teams have full control over their dedicated bare metal servers. They typically receive root or administrator-level access, enabling them to create a server tailored to their specific needs or business objectives. Organizations can install any operating system or hypervisor, providing greater flexibility and customization than shared environments. The infrastructure can be configured and optimized to address complex workloads.
- **Improved performance:** Bare metal hosting environments run workloads directly on hardware, eliminating performance degradation that may affect virtual servers. Direct hardware interaction yields higher I/O throughput, low latency, and overall best performance for demanding, compute-intensive tasks.
- **Enhanced security:** The [single-tenant](https://www.atlantic.net/dedicated-server-hosting/achieving-unparalleled-security-with-single-tenant-dedicated-hosting/) nature of a bare metal server provides enterprise clients with a stronger security posture. Sensitive or valuable data is isolated on the physical server, with no threats from other tenants. The lack of a hypervisor reduces the attack surface and the likelihood of compromise by threat actors. Teams can implement cybersecurity tools and processes, such as encryption and intrusion prevention, to protect their servers, which may not be available in a shared hosting environment.

## Primary Uses of Bare Metal Servers

Enterprise clients adopt bare metal solutions to address various computing and business applications that shared public cloud services cannot adequately handle. Bare metal servers are also highly scalable, allowing businesses to seamlessly expand their infrastructure as their needs grow.

- **High-performance computing (HPC) workloads:** Companies need maximum CPU throughput, high memory capacity, and high bandwidth, along with direct hardware optimization, for use cases such as scientific simulations, financial modeling, risk analytics, machine learning, and graphics rendering.
- **Big data analytics and data warehousing:** Businesses with data-intensive applications benefit from localized file storage and high I/O throughput. The absence of potentially noisy neighbors avoids degraded query performance for data lakes and warehouses.
- **Private cloud and hypervisor hosting:** Enterprise clients may leverage bare metal servers as the foundation for [private clouds](https://www.atlantic.net/private-cloud-hosting/what-is-private-cloud-hosting/) and VM clusters. The company gains performance and enhanced security while maintaining control of hypervisor policy.
- **Real-time applications:** Companies supporting gaming, streaming, and other latency-sensitive digital services benefit from the direct hardware access provided by bare metal servers. Organizations can develop a successful online presence and offer users an improved experience to grow the business using reliable bare metal hosting.
- **AI/ML and GPU-intensive workloads:** AI applications and machine learning training models require extensive GPU usage. The high-bandwidth local storage and exclusive control of GPUs make bare metal solutions a good fit for companies supporting these workloads.
- **Security-sensitive environments:** Enterprise clients often favor single-tenant solutions that offer stronger security than public cloud offerings. The physical and logical isolation provided by bare metal supports the processing of protected health data and payment processing platforms. Physical isolation in bare metal hosting provides inherent security against breaches and lateral attacks prevalent in [multi-tenant](https://www.atlantic.net/dedicated-server-hosting/multi-tenant-bare-metal-data-collection/) environments.
- **Highly customizable workloads:** Businesses may select bare metal for its ability to customize the environment with operating system or kernel builds. Teams can tune performance parameters to meet objectives that cannot be met with shared solutions. Bare metal servers are designed to handle high volumes of processing and can support resource-intensive applications like CRM and ERP systems.

## Are There Drawbacks to Bare Metal Servers?

Companies that want the control, performance, and high availability of bare-metal servers must be aware of several potential drawbacks to this hosting solution.

- **Increased operational responsibility:** Customers must have the skills and experience to manage a bare metal environment. Client teams are responsible for security, patching, hardware monitoring, backup, and [disaster recovery planning](https://www.atlantic.net/disaster-recovery/disaster-recovery-plan/). Supporting bare metal servers requires skilled infrastructure teams and proven operational procedures.
- **Limited flexibility:** Businesses have limited on-demand scalability with bare metal servers. Scaling up the environment typically involves capacity planning and reallocating hardware, which takes time and may affect the ability to support dynamic growth efficiently.
- **Slower provisioning and deployment:** Customers may experience significant delays when provisioning bare-metal systems compared to spinning up a VM in the public cloud. Providers may need to physically move or reconfigure hardware to provision servers in response to client requests.
- **Higher costs:** Organizations may face higher upfront costs, including fees for dedicated hardware, power, and cooling. Internal teams are required to maintain the operational efficiency of bare metal servers. However, bare metal hosting offers predictable pricing models optimized for workload and budget, with transparent pricing and cost-efficient hosting. Cost savings of up to 70% can be achieved with optimized pricing models, and bare metal hosting can eliminate public cloud egress fees. [Dedicated servers](https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/) in bare metal hosting are typically more cost-effective than public cloud solutions for constant demand workloads. Full control over server resources can also lead to better cost management and cost control.
- **Migration complexity:** Companies may face difficulties when migrating a bare-metal environment to another provider. Differences in hardware architecture, network topology, and firmware can result in a time-consuming and complicated migration.

## Scalability and Flexibility of Bare Metal Hosting

One of the standout advantages of bare metal hosting is its exceptional scalability and flexibility, which are crucial for businesses operating in fast-paced, ever-changing environments. With dedicated bare metal servers, organizations can provision servers and allocate more resources on demand, ensuring their infrastructure keeps pace with business growth or fluctuating workloads. This adaptability is especially valuable for companies running high performance computing, machine learning, or distributed storage solutions, where the ability to quickly scale up or down can directly impact business outcomes.

Bare metal servers are specifically designed to deliver consistent performance, even as demands shift. Whether supporting business applications that require high availability or managing workloads that need low latency and high performance, dedicated bare metal hosting provides the reliability and speed enterprises expect. The flexibility to customize storage, memory, and processing power allows businesses to optimize their hosting environment for a wide range of use cases, from mission-critical operations to innovative new projects.

By leveraging the scalability of bare metal hosting, companies can future-proof their IT infrastructure, respond rapidly to market changes, and maintain best in class performance for users around the world. This level of control and adaptability makes bare metal servers an ideal choice for organizations seeking to maximize both performance and operational efficiency in their hosting solutions.

## How to Select a Bare Metal Hosting Provider?

Organizations should consider several factors when choosing their bare metal hosting provider.

### Best in class hardware

The selected provider should offer best-in-class hardware that delivers the performance necessary to support high-performance computing tasks. Hardware choices should include making cutting-edge GPUs and processors available for advanced AI applications and machine learning training. Organizations should seek a provider that offers servers specifically designed to address their unique requirements.

### Strong SLAs and hardware replacement policies

Providers must provide strong [service level agreements](https://www.atlantic.net/cloud-service-level-agreement/) (SLAs) regarding uptime and hardware replacement. Enterprise clients must ensure their vendors’ availability of spare hardware to address equipment failures with minimal downtime. The vendor should have a clearly defined incident response and escalation process. Questions to ask prospective providers include how quickly failed hardware, such as hard drives, will be replaced and whether spare parts are available on-site. Limited spare parts or vague SLAs are warning signs to avoid.

### Data center location and network performance

Enterprise customers typically seek the bandwidth consistency and low latency of bare metal hosting. Providers with data centers in multiple regions can offer servers in closer proximity to users to streamline access to the environment. Companies should investigate the providers’ bandwidth and throughput ceilings to ensure they align with business requirements. Clients should look at network segmentation options that may be necessary to secure sensitive data assets. Reliable connection options, such as private networks, are important for optimal server management and security. Private networks also offer increased flexibility, allowing users to optimize network configurations without impacting service availability.

### Compliance readiness

Businesses processing regulated data must consider their bare-metal provider’s compliance stance. Specific elements to look for include physical security aligned with compliance standards, access logging, and secure decommissioning to protect sensitive data. The provider should have environments designed to support various regulations, such as HIPAA or [PCI-DSS](https://www.atlantic.net/pci-compliant-hosting/what-is-pci-compliance/). Vendors should support audits by tracking hardware custody and information collected in access and usage logs.

### Customer support

Businesses should look for a provider that offers 24/7 operational support and SLA response. A reliable provider typically will offer deployment assistance and migration support. It is essential to work with a vendor that has engineer-led in-house support teams, not outsourced help desks. Ideally, the provider should have a track record of successfully supporting other clients in the same industry.

For personalized guidance or further assistance with your bare metal hosting for enterprise needs, contact our support team.

## Conclusion

Bare-metal servers provide enterprise clients with numerous benefits to support a wide range of complex, computationally intensive tasks. The key for customers is to partner with a reputable vendor, such as Atlantic.Net, that offers a range of [bare metal hosting options](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) to address their unique business needs. We offer multiple plans to meet the needs of any enterprise client in 2026 and will customize the bare metal environment to match your company’s specific requirements.

For personalized guidance or further assistance with your bare metal hosting for enterprise needs, [**contact our support team.**](https://www.atlantic.net/about-us/corporate-contact/)

**Related Guides:**

- [HIPAA Compliant Hosting Solutions](https://www.atlantic.net/hipaa-compliant-hosting/)
- [PCI-Compliant Hosting Solutions](https://www.atlantic.net/pci-compliant-hosting/)
- [What Are Managed Services?](https://www.atlantic.net/managed-services/what-are-managed-services/)

**Related Products:**

- [Atlantic.Net Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/)
- [Atlantic.Net HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)
- [Atlantic.Net GPU Hosting](https://www.atlantic.net/gpu-server-hosting/)


---

# Best Bare Metal Hosting Providers for Business in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/best-bare-metal-hosting-providers-2026/ | Published: 2026-01-07 | Updated: 2026-07-24 | Author: Dr. Assad Abbas

*Updated July 2026*

Bare metal hosting sits underneath more business systems than the marketing admits. The claims database that has to close the month, the analytics cluster that runs overnight against forty billion rows, the payment platform measuring its latency budget in milliseconds: those workloads end up on single-tenant physical hardware because a hypervisor introduces variability nobody wants to explain to an auditor.

Choosing between bare metal cloud providers has become harder since 2024, and the hardware is not the reason. One vendor counts logical processors, the next counts physical cores. One quotes a burst network figure, another a guaranteed port speed. Prices appear on some pages and disappear behind a quote form on others.

The gap that decides a business purchase sits elsewhere. It is the operational commitments a provider will put in writing: who patches the operating system, who owns DDoS mitigation when an attack starts at 2 am on a Sunday, and how quickly failed hardware gets replaced. Every specification below was checked against the provider’s current documentation, and a wider vendor sweep sits in the companion guide to[the best bare metal hosting services for 2026](https://www.atlantic.net/dedicated-server-hosting/top-5-bare-metal-hosting-services/).

## The Verdict: Best Bare Metal Hosting Companies for Business in 2026

Ranked on the commitments a business buyer signs for, ahead of raw hardware ceilings, the best bare metal hosting companies for business in 2026 are:

- **Atlantic.Net.** Best for regulated workloads. Audited HIPAA, PCI DS, SOC 2 Type II data centers, published pricing, full root access, US-based engineers 24/7/365. See the[Atlantic.Net bare metal server plans](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/).
- **Amazon Web Services.** Best for teams already standardized on AWS, needing hardware-level access alongside cloud-native services.
- **Google Cloud Bare Metal Solution.** Best for Oracle estates moving alongside Google Cloud analytics, with an availability caveat covered below.
- **Microsoft Azure.** Best for certified SAP HANA and Oracle platforms inside an existing Azure subscription.
- **Rackspace.** Best for enterprises wanting one vendor to own procurement, racking, patching,g and day-two operations.
- **Kamatera.** Best for fast builds with reserved hardware resources across a wide geographic spread.
- **Scala Hosting.** Best for smaller businesses and agencies wanting managed hosting with a control panel bundled in.

### Comparison of Bare Metal Cloud Providers (2026 Data)

| **Provider** | **CPU Options** | **Peak Published RAM** | **Storage** | **Network** | **Support Model** | **Best Fit** |
| --- | --- | --- | --- | --- | --- | --- |
| **Atlantic.Net** | Intel Xeon E-2236, Intel Xeon Gold 6140, and AMD EPYC on custom builds | 256 GB published; 1 TB ECC custom | SATA SSD in hardware RAID; NVMe RAID 10 on dedicated hosts | 1 Gbps standard; 10 Gbps SFP+ and 25 Gbps SFP28 available | Managed or unmanaged | HIPAA and PCI workloads, databases, and private cloud |
| **AWS** | Intel Xeon Platinum, from Skylake to Ice Lake generations | 6 TiB on u-6tb1.metal | NVMe instance store up to 30 TB, plus EBS | 75 Gbps to 100 Gbps | Self-service with paid support tiers | Cloud-native estates, VMware, and Nutanix on AWS |
| **Google Cloud** | Intel Xeon Gold 5200/6200 and Intel Xeon Platinum 8200 | 24 TB on o2-ultramem-896-metal | Local storage plus attached volumes | 4-port 25 GbE NIC or higher | Google-managed infrastructure layer | Oracle databases adjacent to Google Cloud services |
| **Microsoft Azure** | Intel Xeon, including Optane SKUs | 24 TB across 30+ SKUs | All-flash SSD and NVMe, up to 1 PB per tenant | 40 Gbps or 100 Gbps | Microsoft-provisioned, customer-operated | Certified SAP HANA and Oracle platforms |
| **Rackspace** | Dell, HPE, and Cisco configurations | Not published | Configurable storage, including NetApp and Pure Storage arrays | Not published | Fully managed | Multi-site managed enterprise hosting |
| **Kamatera** | Intel Xeon Platinum, Cascade Lake, and Ice Lake | 512 GB per Type D server | NVMe SSD, up to 16 drives per server | Not published | Managed or unmanaged | Distributed development and test estates |
| **ScalaHosting** | Processors up to 4.1 GHz | Not published | PCIe NVMe SSD | 10 Gbps redundant network | Managed or self-managed | SMBs, agencies, and hosted web platforms |

Where a provider does not publish a number, the table says so instead of guessing.

## Why Business Buyers Move Workloads to Bare Metal Servers

### Consistent Performance Under Sustained Load

Bare metal servers remove the hypervisor, so the operating system talks to CPU, memory, and storage directly. That matters less for peak throughput than for the shape of the latency curve. A shared instance holds a good average, then produces slow requests when a neighbor starts a backup. Database primaries, real-time bidding engines, and high-performance computing jobs all feel that tail.

### Single-Tenant Isolation for Regulated Data

Hardware isolation is the cleanest answer to an auditor asking who else runs on that machine. Nobody. For workloads touching electronic Protected Health Information (ePHI) or cardholder data, single-tenancy shortens the scoping conversation. It does not make you compliant on its own: compliance also depends on your application, access controls and processes.

### Full Operational Control and Root Access

Bare metal gives you administrative ownership of the whole stack: choice of operating systems, your own hypervisor, kernel tuning, RAID layout and process pinning. Teams running VMware, Proxmox or Hyper-V on leased hardware are buying exactly this. Atlantic.Net supports all three on its[root access dedicated servers](https://www.atlantic.net/dedicated-server-hosting/root-access-dedicated-server/), with custom OS installs on request.

### Predictable Cost on Long-Running Workloads

A server running at 70% utilization around the clock is the worst case for consumption billing and the best case for a fixed monthly line item. Atlantic.Net publishes a 21% reduction between the one-year and three-year term on its entry build, from $315.84 to $248.64 a month.

## What to Look For in a Bare Metal Provider

### Hardware and NVMe Storage Options

CPU choice sets the ceiling and storage sets the floor. Intel Xeon and AMD EPYC both handle demanding workloads through high core counts, and the useful question is how many memory channels and PCIe lanes the platform offers. NVMe suits database and analytics tiers because it holds latency steady as queue depth climbs. SATA still wins on cost per terabyte for bulk capacity.

### Network Capacity and DDoS Protection

Port speed is the number everyone quotes and the least useful on its own. Ask what the transfer allowance is, what overage costs, and what happens during an attack.[Atlantic.Net Network Edge Protection](https://www.atlantic.net/managed-services/network-edge-protection/) covers L3 and L4 floods plus application-layer attacks through a ModSecurity web application firewall running the OWASP core rule set, at a fixed price.

### Data Centers, Global Network and Private Networking

Redundant power, tested cooling, biometric access control and independently audited operating procedures are the baseline for any data center worth buying from. Beyond that, a private network between servers keeps replication traffic off the public internet, and providers with global data centers let you place hardware near the users who feel the latency. Atlantic.Net operates eight global data center regions across the US, Canada, the United Kingdom, and Singapore.

### Provisioning Speed and Custom OS Installs

Instant provisioning has become a real differentiator. Automated builds with a prebuilt image typically deliver a production-ready server in[30 minutes to 4 hours](https://www.atlantic.net/dedicated-server-hosting/understanding-bare-metal-server-provisioning-time/), while manual processes with team handoffs stretch to one or two business days. Custom operating systems and unusual RAID layouts add time with any provider.

### Management, Support and Compliance Evidence

Unpack the phrase “fully managed” before signing anything. On some platforms it means the provider replaces failed hardware. On others it covers OS patching, firewall rule changes, backup verification and 24/7 engineering escalation. Atlantic.Net includes server management, a managed FortiGate firewall with IPS, Veeam backups, multi-factor authentication and four hours of migration service with its[managed services](https://www.atlantic.net/managed-services/) tiers. Ask for the audit reports too: a SOC 2 Type II report on the hosting service is a different artifact from an ISO certificate on a building.

## Bare Metal Deployment Models and Hybrid Infrastructure

### Traditional Bare Metal Dedicated Servers

A physical machine assigned to one tenant on a monthly or annual term, with CPU, memory, storage layout and network interfaces fixed at build time. This suits systems that run continuously and change rarely: core databases, ERP platforms and license-bound applications certified against specific hardware.

### Bare Metal Cloud

Single-tenant physical servers operated with cloud-style tooling. Bare metal instances are provisioned, rebuilt,t and released through an API in minutes, which fits automated deployment pipelines. Atlantic.Net’s[dedicated cloud hosts](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) sit here, with NVMe RAID10 storage and several dedicated instances running on a host you pay for once.

### Hybrid and Hosted Private Cloud

Most business estates end up mixed, with the database tier on dedicated hardware and the stateless application tier on cloud instances. Hybrid infrastructure of that shape depends on the link between the two halves being private and under your control, which is what a[virtual private cloud](https://www.atlantic.net/cloud-platform/virtual-private-cloud/) provides through managed firewalls, IPsec tunnels and BGP routing with your own ASN.

## The Best Bare Metal Hosting Companies for Business in 2026

### Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

[Atlantic.Net](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) provides bare metal dedicated servers built around regulated and business-critical workloads, backed by 31 years of operating history and eight global data center regions. Compliance is part of the platform instead of an add-on, which is why healthcare, fintech, and legal buyers shortlist it early.

- Three published builds cover most business sizing. BM.C1 pairs a 3.4GHz Intel Xeon E-2236 (6 cores, 12 threads) with 64GB RAM and 2 x 480GB SATA SSD at $315.84 a month on a one-year term. BM.C2 moves to dual Xeon Gold 6140 processors, 36 cores, 72 threads, 128GB RAM, and 4 x 1920GB SSD at $618.24. BM.C3 doubles that memory and storage at $806.40. All include 10TB of transfer.
- Data centers are independently audited for SOC 2 Type II, HIPAA, and PCI DSS; a HIPAA Business Associate Agreement (BAA) comes with regulated plans, and the 100% Uptime SLA covers network availability, no-cost hardware replacement, and power and HVAC separately.
- Root access is standard, custom OS installs are available on request, and VMware, Proxmox, and Hyper-V all run on the hardware. Custom builds reach 1TB ECC RAM, with 10Gbps SFP+ or 25Gbps SFP28 uplinks for adtech and trading platforms.
- One trade-off worth stating plainly: the published builds ship SATA SSD in hardware RAID. NVMe RAID10 lives on the dedicated hosts line or a custom configuration, so raise it during scoping.

### Amazon Web Services (AWS)

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

AWS bare metal EC2 instances expose the physical processor and memory to your operating system while keeping the rest of the AWS catalog one API call away. The appeal is placement, and it is priced accordingly.

- The bare metal ceiling is u-6tb1.metal, an eight-socket Xeon Platinum system with 448 logical processors, 6 TiB of RAM, and 100 Gbps of networking. Note that u-24tb1.metal is closed to new launches, and the larger 24 TiB and 32 TiB U7i sizes AWS now points at are virtualized.
- For storage-bound work, i4i.metal gives 128 vCPUs, 1,024 GB, and up to 30 TB of local NVMe at 75 Gbps, while x2iedn.Metal covers memory-bound cases with 4,096 GiB. Both are supported as the base for VMware Cloud on AWS and Nutanix clusters.
- Pricing sits well above equivalent dedicated hardware from a specialist host, and egress is billed separately.

### Google Cloud Bare Metal Solution

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

Google Cloud Bare Metal Solution places certified single-tenant servers in a Google-managed facility next to a cloud region, connected over a low-latency Partner Interconnect.

- Configurations run from o2-standard-16-metal (8 cores, 16 vCPUs, 192GB RAM) to o2-ultramem-896-metal, a 16-socket machine with 448 cores and 24TB of RAM, each with a 4-port 25GbE NIC or better. Operating systems are limited to Red Hat Enterprise Linux, Oracle Linux, and SUSE Linux Enterprise Server.
- The private link into Google Cloud is the real product. An Oracle database stays on certified hardware while BigQuery, Dataflow and Vertex AI read from it, which makes a phased modernization practical.
- One caveat matters for any 2026 shortlist: Google documents that availability is moving to a specialized, allowlist-only model tied to its Oracle partnership. Confirm you qualify before designing around it.

### Microsoft Azure

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

Azure BareMetal Infrastructure provides non-virtualized certified servers inside your Azure virtual network, aimed at applications software vendors that will not certify on a hypervisor. Azure Dedicated Host is the lighter option for isolated hardware still running Azure VMs.

- The catalog spans more than 30 SKUs, from two-socket to 24-socket systems, with memory from 1.5TB to 24TB. Storage is all-flash SSD and NVMe, reaching 1 PB and 1.2 million IOPS per tenant, with 40/100 Gb networking.
- Latency from Azure-hosted application VMs to the bare-metal instances is 0.35 ms, which makes an SAP application tier in Azure workable against a database tier on physical hardware.
- Operating system choice is limited to RHEL and SLES, licensing is bring-your-own, and the instances have no internet connectivity by design. The platform holds ISO 27001, ISO 27017, SOC 1 and SOC 2, and backup and disaster recovery stay with you.

### Rackspace

![](https://www.atlantic.net/wp-content/uploads/2025/12/rackspace_logo.png)

Rackspace sells managed bare metal infrastructure to organizations that prefer to buy an operations team instead of building one. The hardware is standard enterprise equipment; the product is the people around it.

- Configurations are built from Dell Technologies, HPE, Cisco, NetApp and Pure Storage components, with CPU, memory, storage, RAID, backup and monitoring specified per environment.
- The global network spans more than 40 data centers, with direct private links to AWS, Google Cloud and Azure through Equinix and Megaport, and RackConnect Global extending a private network across sites.
- Rackspace does not publish hardware ceilings, prices, or provisioning times. Expect a scoping call and a custom quote, and ask which certifications cover the environment you are actually buying.

### Kamatera

![](https://www.atlantic.net/wp-content/uploads/2025/12/kamatera-logo-1.png)

Kamatera offers Type D dedicated servers where each vCPU maps to a dedicated physical core with reserved memory, giving predictable performance without a full single-tenant chassis.

- Type D runs from 1 to 32 vCPUs with up to 512GB of RAM per server, on Intel Xeon Platinum processors, with NVMe SSD volumes from 20GB to 4,000GB and up to 16 drives per server.
- The global data centers number 18 across four continents, from Amsterdam and London to Singapore, Sydney, Tokyo and eight US cities, and servers deploy in around 60 seconds.
- Be precise about what you are buying. Type D is a virtualized instance with reserved dedicated hardware resources, so it removes noisy-neighbor contention without handing you the physical machine. Where an auditor wants hardware isolation, that distinction is the conversation.

### Scala Hosting

![](https://www.atlantic.net/wp-content/uploads/2025/12/scala-hosting.jpg)

Scala Hosting targets smaller businesses and web agencies with managed servers, a bundled control panel and security tooling included at no extra cost.

- Managed cloud plans start at $29.95 a month and self-managed builds at $19.95, with CPU, memory and NVMe storage adjustable independently through a build-your-own configurator.
- Hardware runs at processor speeds up to 4.1 GHz on PCIe NVMe SSD storage behind a 10 Gbps redundant network, and servers activate in around 30 seconds. SPanel is included free and replaces a paid cPanel license, while SShield adds brute-force defense, automatic IP blocking, and daily backups.
- Scala publishes cloud server builds instead of large single-tenant hardware, so treat it as managed hosting with dedicated resources.

## Matching a Bare Metal Provider to Your Business Workload

Take a concrete case. A payments platform runs a PostgreSQL primary with two streaming replicas, Redis for session state, RabbitMQ for the settlement queue, and a Node application tier, and it has to stay inside PCI DSS 4.0 scope. The database working set peaks at 90GB, and the nightly reconciliation job saturates storage for forty minutes.

That workload does not need 24TB of RAM. It needs enough memory to keep the working set resident, storage that holds latency flat through the reconciliation window, a private network between the database and application tiers, and a provider who will hand over a current SOC 2 Type II report and commit to fixed-price DDoS mitigation. A BM.C2 class build with 128GB of RAM covers the hardware at $618.24 a month, and[PCI-compliant hosting](https://www.atlantic.net/pci-compliant-hosting/) covers the rest.

Run the test in reverse when the requirement really is scale. SAP HANA at 12TB belongs on Azure or Google Cloud, because those are the platforms the software vendor certifies. For everything in between, the operational factors decide it. The guide to[bare metal, dedicated cloud hosts and dedicated servers](https://www.atlantic.net/dedicated-server-hosting/bare-metal-dedicated-cloud-hosts-and-dedicated-servers-what-is-the-difference/) compares the models.

## Frequently Asked Questions

### What Is Bare Metal Hosting and How Does It Differ From Virtualized Cloud Hosting?

Bare metal hosting gives you an entire physical server with no hypervisor between your operating system and the hardware. Virtualized cloud hosting splits one machine into several virtual servers sharing its CPU, memory,y and storage. The practical difference is isolation: bare metal has no other tenants competing for hardware resources, so performance stays steady under load. Our explainer on[what a bare metal server is](https://www.atlantic.net/dedicated-server-hosting/what-is-a-bare-metal-server-benefits-use-cases-and-best-practices/) covers the architecture.

### When Is Bare Metal Hosting a Better Choice Than a Cloud Instance?

Bare metal wins when the workload runs continuously, is sensitive to latency variation, or has to satisfy an isolation requirement. Databases holding large working sets in memory, trading and real-time bidding systems, high-performance computing jobs, and anything processing ePHI or cardholder data all fit. Cloud instances remain the better answer for bursty traffic.

### What Is the Typical Provisioning Time for a Bare Metal Server?

Most providers deliver a standard bare metal configuration within one business day. Where the hardware is already racked, the operating system image is prebuilt, and provisioning is automated, a server can be production-ready in 30 minutes to 4 hours. Manual builds involving team handoffs take one or two business days, and custom hardware or specialized images extend that.

### What Industries Use Bare Metal Hosting for Compliance and Performance?

Healthcare, financial services, e-commerce, adtech, gaming, and legal services are the heaviest users. Healthcare organizations choose bare metal to keep ePHI on isolated hardware under a BAA. Payment processors keep cardholder data environments small for PCI DSS 4.0. Atlantic.Net serves both through[HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and PCI-compliant hosting on the same audited infrastructure.

### What Are the Benefits of Using Bare Metal Servers for Databases?

Databases gain more from bare metal than almost any other workload. The buffer pool gets the full physical memory with no balloon driver reclaiming pages, storage latency stays flat because no other tenant issues I/O against the same devices, and you control the RAID layout, filesystem, and I/O scheduler. Licensing by physical core also matters for Microsoft SQL Server and Oracle.

### Who Offers Single-Tenant Bare Metal Environments With DDoS Protection?

Atlantic.Net, AWS, Azure, Google Cloud and Rackspace all provide single-tenant bare metal with DDoS mitigation, though the commercial models differ. Atlantic.Net includes Network Edge Protection with L3, L4 and L7 coverage, a ModSecurity web application firewall and CDN at a fixed price. Hyperscalers cover the network layer and charge for advanced tiers. Check whether mitigation is always-on and whether attack traffic is billed.

### What Is the Difference Between Bare Metal Hosting and Colocation?

With bare metal hosting, the provider owns the hardware and leases it to you as a service, including replacement parts, network, and facility. With colocation, you own the servers and rent rack space, power, cooling, and connectivity. Bare metal makes hardware failure the provider’s problem, usually under an SLA. Colocation gives you complete hardware choice and can cost less at large scale, at the price of procurement lead times.

### How to Choose Between Bare Metal and Virtualized Hosting?

Start with three questions. Does the workload run continuously, or does demand spike and fall? Does anything in your compliance scope require hardware isolation? Does the application depend on physical CPU features, nested virtualization, or per-core licensing? Continuous, regulated or hardware-dependent workloads point to bare metal. Everything else starts cheaper on virtualized[dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/).

## Final Thoughts

Atlantic.Net built its bare metal platform around the parts of this decision that are hard to reverse: audited compliance evidence, published pricing, a 100% Uptime SLA covering network, hardware and power separately, and US-based engineers who answer the phone at 3 am. The hyperscalers here will out-spec that hardware on paper, and for SAP HANA at 12TB they are the right call. For the regulated database tier and the[enterprise bare-metal workload](https://www.atlantic.net/dedicated-server-hosting/bare-metal-server-hosting-for-enterprises/) that has to run without drama, operational commitments matter more than the spec sheet.

If you are shortlisting bare metal hosting companies for a business workload in 2026 and want a configuration priced against your actual requirements,[contact the Atlantic.Net solutions team](https://www.atlantic.net/about-us/corporate-contact/). We will walk through your sizing, where the compliance shared-responsibility line falls for your application, which audit reports we can put in front of your reviewers, and what a migration would involve.


---

# The Top Antivirus Services for Technology Companies in 2026

> URL: https://www.atlantic.net/managed-services/top-antivirus-services-technology-companies-2026/ | Published: 2026-01-07 | Updated: 2026-01-09 | Author: Robert Agar

Modern businesses in 2026 require thorough security, including real-time protection from diverse cyber threats. The shift to remote work and mobile devices complicates the task of protecting ePHI (electronic Protected Health Information) and other sensitive data. Owners of any size enterprise must use effective methods to block malicious actors. As a company grows, its cybersecurity needs become more intricate, requiring scalable solutions that adjust to more devices and users.

To address these changing needs, top antivirus services often include tools like VPNs, firewalls, and dark web monitoring. Scalability is a key feature, allowing businesses to secure more devices as they grow. This is especially vital for technology companies handling sensitive data under a HIPAA Business Associate Agreement (BAA). One way to obtain this security is with a third-party antivirus tool. Some services also offer insurance for identity theft or data recovery.

This article reviews the key features of antivirus services and why they are necessary for technology companies in 2026.

## What is an Antivirus Service?

A modern antivirus service is typically a cloud-based software solution designed to detect, prevent, and remove malware from the computing environment, including servers, laptops, and endpoints. Many providers also offer dedicated antivirus apps for different user groups, such as developers and businesses, to address specific security needs. The service runs continuously in the background to provide 24/7 protection from viruses, ransomware, zero-day attacks, and other threats.

Companies often deploy antivirus programs as part of an overall cybersecurity strategy. A comprehensive security service may also include features like endpoint protection, web protection, and cloud storage for secure file backups. Most cloud service providers (CSPs) offer their customers antivirus protection along with other security services.

## Key Features of Antivirus Solutions

Today’s top antivirus software leverages artificial intelligence (AI) and machine learning (ML), offering enhanced protection over traditional signature-based solutions. These advanced techniques are necessary given the speed at which threat actors develop new and sophisticated attacks. Top antivirus solutions may also include additional services such as webcam protection, cloud storage, and data safe features to protect sensitive business data. Some plans offer coverage for unlimited devices, while others are limited compared to higher-tier options, with some only covering up to five devices.

The following key features are essential elements of a business antivirus service. Free trials are often available, allowing businesses to test the software risk-free, while free versions are typically limited in scope and intended for personal use. A money back guarantee provides additional confidence for businesses evaluating antivirus solutions. Many providers also offer other services, such as alert systems and monitoring tools, to supplement their primary offerings. Robust protection for Windows devices and Windows Server is especially important for technology companies with diverse IT environments. Data safe features are crucial for protecting sensitive business information.

Key features to look for include a firewall to prevent unauthorized access to the network, regular malware scans to identify and remove infections, and a lightweight design that ensures operations do not slow down employee productivity or device performance. Ease of use and management are important for business owners, and antivirus solutions must not significantly slow down business operations during scans and updates.

### Real-time protection

The best antivirus solutions provide real-time protection that blocks threats before they can cause damage. The tool should monitor network and system activity continuously to identify anomalies and may be capable of preventing ransomware from encrypting data assets.

### Malware detection and removal

The tool should identify known malware, such as ransomware, trojans, and spyware, using signature-based detection. Rogue files must be immediately quarantined and removed from the environment to maintain consistent operations.

### Ransomware protection

Ransomware is a significant threat to businesses of all sizes. An effective antivirus solution mitigates the risk of ransomware by detecting and blocking unauthorized file modifications or encryption. The tool may provide rollback capabilities to assist in recovery after a ransomware attack.

### Behavioral analysis

Advanced AI and ML capabilities detect suspicious behavior by identifying activity that deviates from previous behavioral baselines. This analysis can catch new and evolving threats such as zero-day and fileless attacks. Modern attacks evolve quickly and outpace security teams’ ability to develop manual rules to limit malware exposure.

### Cross-platform support

The antivirus tool should offer cross-platform support for the operating systems in your environment. It should provide robust protection for Windows, macOS, and Linux systems as well as for mobile devices and endpoints. The objective is to ensure consistent security across all the different operating systems in the IT infrastructure.

### Endpoint detection and response (EDR)

Companies supporting a mobile workforce must defend a greatly expanded and constantly changing attack surface. The antivirus software must provide comprehensive visibility into endpoint activity to facilitate incident investigation and root-cause analysis. Teams should be able to define automated response actions to address issues quickly.

### Advanced threat intelligence

Threats are constantly evolving, with new attacks emerging that are not detectable with signature-based techniques. Modern antivirus protection requires cloud-based threat intelligence that coordinates threat data from across the web to defend against new attack campaigns. Antivirus software leverages this intelligence to automatically update its protection models for enhanced security.

### Centralized management console

Many companies are challenged to provide sufficient security due to limited staff. A centralized dashboard that displays all endpoints reduces IT overhead and supports consistent policy enforcement across the environment, simplifying administration and monitoring efforts. A user-friendly interface is a welcome feature for any security team.

### Automatic updates

A reliable antivirus solution is kept up to date with automatic updates to ensure maximum protection against cyber threats. Updates typically include new malware definitions and improvements to the security engine. The automated updates eliminate manual effort and ensure the software always has the latest security settings, providing excellent protection.

### Email and web protection

Many cyberattacks are initiated through phishing campaigns that entice users to click on malicious links. A comprehensive antivirus service provides phishing protection by scanning emails and attachments and restricting access to potentially dangerous URLs and files. Advanced tools may perform dark web monitoring to identify compromised credentials before hackers can use them for nefarious purposes.

### Customer support

An antivirus service should provide good customer support to help users resolve issues quickly. Vendors should offer phone support and the ability to open a support ticket to document problems and track their resolution.

## Why Technology Companies Need Antivirus Protection

All organizations can benefit from implementing antivirus software or services. Technology companies, in particular, need enhanced protection for the following reasons.

- Technology companies present an attractive target for threat actors. They store and develop proprietary source code, new product information, and trade secrets. Cyberattackers may try to steal intellectual property or compromise code to affect downstream customers. Keeping business data safe is a top priority for technology companies, making strong data protection and threat detection essential.
- Many technology companies support remote workers with multiple devices and cloud-based virtual machines, creating additional endpoints that must be defended. Since a single compromised endpoint can infect the entire environment, it is crucial to business operations to maintain comprehensive protection.
- Tech companies are prone to ransomware and supply chain attacks. Good security tools offer protection against these attacks by quickly stopping malicious code execution and encryption before they can damage the environment.
- Support for a zero-trust security approach is essential for tech businesses. A robust antivirus tool may perform identity monitoring to detect suspicious behavior. Identity theft protection is an invaluable feature for safeguarding against insider threats and lateral movement across the infrastructure.
- Many tech companies must meet regulatory compliance requirements such as HIPAA, GDPR, or PCI-DSS. Audits often focus on endpoint protection, and businesses must be able to provide compliance documentation. Most antivirus services provide customers with audit logs and reports to support compliance audits. Basic antivirus software is often insufficient for technology companies; advanced endpoint security solutions are recommended.

For developer teams, antivirus software should be unobtrusive and allow easy exclusion of specific files or folders from scans, ensuring robust protection without compromising productivity.

## Antivirus Programs for Developers

Developers face unique cybersecurity challenges, from safeguarding proprietary code to ensuring the integrity of development environments across multiple operating systems. Choosing the right antivirus software is crucial for protecting against cyber threats that target both personal and business assets. The best antivirus programs for developers offer robust protection, advanced malware detection, and real-time protection to keep systems secure without interrupting workflow.

When selecting antivirus software, developers should prioritize compatibility with different operating systems, including Windows, macOS, and Linux, to ensure seamless security across all devices. Top antivirus software options like Norton, Bitdefender, and Avast provide comprehensive protection with advanced features tailored to developer needs. These include password managers for secure credential storage, dark web monitoring to alert users if their information is compromised, and real-time malware detection to prevent zero-day attacks.

Advanced antivirus programs also offer features such as identity theft monitoring, secure browser environments for safe code downloads, and scheduled scans that minimize impact on system resources. With the increasing prevalence of remote work and cloud-based development, having antivirus solutions that support multiple devices and provide centralized management is essential for maintaining a secure and efficient workflow.

By investing in top antivirus software with robust protection and developer-focused features, technology professionals can safeguard their projects, data, and intellectual property from evolving cyber threats.

## The Best Antivirus Services for Technology Companies

The following antivirus tools all offer the basic functionality needed to protect your business from threat actors. Choosing the right antivirus for a business can be challenging due to the variety of options available. Many providers offer antivirus apps tailored for different business needs, and some solutions include additional tools and other services to enhance overall protection. Some of these solutions may have advanced features that make them the right antivirus software for your technology company.

![](https://www.atlantic.net/wp-content/uploads/2026/01/Trend-Micro-Logo.png)

### [Trend Micro](https://www.trendmicro.com/en_us/business.html)

Trend Micro is an established leader in cybersecurity and antivirus tools. The company’s primary offering is Trend Vision One, which centralizes risk exposure management, security operations, and layered protection, enabling customers to predict and prevent threats. The platform helps eliminate security blind spots and lets teams hunt, detect, investigate, and respond to threats quickly. Trend Micro’s features include:

- Elite threat intelligence from over 250 million sensors and 500,000 enterprises;
- A user-friendly interface providing a comprehensive view and cyber risk index;
- Automated incident mitigation to quickly protect system resources when issues are detected.

![](https://www.atlantic.net/wp-content/uploads/2026/01/CrowdStrike-Emblem.png)

### Crowdstrike Falcon

Crowdstrike’s Agentic Security Platform offers technology companies a unified solution to protect modern IT environments. The cybersecurity solution secures data, models, identities, and infrastructure through AI-driven workforce automation. Business users can leverage the platform’s agentic security to accelerate incident investigations, reduce costs, and strengthen cybersecurity protection.

Crowdstrike’s outstanding features include:

- A person-aware console with natural language querying, role-specific workspaces, and instant dashboards;
- Charlotte AI AgentWorks, a no-code platform facilitating the creation and use of managed, trusted security agents;
- An Enterprise Graph unifying enterprise telemetry to develop a connected model of the infrastructure supported by a common, AI-based query language.

![](https://www.atlantic.net/wp-content/uploads/2026/01/Bitdefender-Logo.png)

### Bitdefender antivirus

Bitdefender Antivirus is a cross-platform solution designed to protect all your devices with industry-leading technologies. The tool protects Mac users, Windows servers, iOS, and Android devices with Linux extensions for business users. It provides excellent antivirus performance for small businesses with easy security setup procedures and email protection.

Bitdefender Antivirus offers impressive features, including:

- Affordable plans that meet the needs of small and large companies;
- Account breach protection with a built-in password manager and digital identity monitoring;
- A centralized, user-friendly dashboard allowing users to monitor and adjust security settings with no technical expertise.

![](https://www.atlantic.net/wp-content/uploads/2026/01/avast.png)

### Avast antivirus solutions

Avast offers a range of small business antivirus solutions to meet specific security requirements and objectives. Customers can select from basic antivirus protection to the full-featured Avast Ultimate Business Security suite, which includes patch management to fix app vulnerabilities automatically. All Avast versions safeguard users with phishing protection to prevent them from visiting malicious or fake websites.

Users benefit from these advanced Avast features:

- Manage users with an online management platform;
- Data breach protection that identifies suspicious files and prevents malware from reaching endpoints;
- Variable pricing and feature sets to address small business needs.

![](https://www.atlantic.net/wp-content/uploads/2026/01/8867.Microsoft_5F00_Logo_2D00_for_2D00_screen-1024x376-1.jpg)

### Microsoft Defender for Endpoint

Microsoft Defender for Endpoint enables users to view and manage their cyberattack surface from a single dashboard, enhancing enterprise cybersecurity. The platform automatically disrupts ransomware attacks by blocking remote encryption and lateral movement across the environment. The software leverages cutting-edge AI to help teams outmaneuver sophisticated threat actors.

These features distinguish Microsoft Defender for Endpoint:

- Global threat intelligence with insights from 84 trillion daily signals and thousands of worldwide experts;
- Granular controls for security settings, policies, resource access, and workflow automation;
- Protects Windows, Linux, macOS, iOS, Android, IoT, and network devices.

## Conclusion

Technology companies must take measures to protect their business and valuable data from malicious cyberattacks. Decision-makers should ensure their IT environment is safeguarded with a comprehensive antivirus service, such as those previously discussed in this article. Teams must use the chosen tool across all infrastructure components to keep threat actors away from mission-critical systems and resources.

Many top antivirus services offer a free trial and a money back guarantee, allowing businesses to evaluate their effectiveness risk-free. Some solutions also include insurance coverage for identity theft or data recovery, providing additional peace of mind. The right antivirus service offers protection for all business assets, from endpoints to cloud data.

Strong cybersecurity requires a concerted effort by everyone in the company. Companies must train employees to use the selected service effectively and protect the business. Businesses can protect themselves with the combination of an informed workforce and an effective antivirus service.


---

# Cloud Hosting for High-Traffic Websites in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/cloud-hosting-for-high-traffic-websites-2026/ | Published: 2026-01-09 | Author: Dr. Tehseen Zia

High-traffic websites are no longer limited to global brands or large media companies. In 2026, eCommerce stores, healthcare platforms, SaaS products, content-driven platforms, and public sector services can all face sudden traffic spikes. A campaign can go viral in minutes. A product launch can attract global attention. A news event can overload servers without warning. The challenge is no longer how to get traffic, but how to sustain it without downtime, slow performance, security risk, or high operational costs. Cloud hosting has become the foundation for meeting this challenge reliably and practically. This article explores why cloud hosting has become the preferred model for high-traffic websites, what makes it effective, and how organizations can choose a provider that supports both growth and responsibility.

## Why High-Traffic Websites Demand a Different Hosting Model

High-traffic websites behave differently from low or moderate-traffic sites. They experience unpredictable surges, uneven load patterns, and intense pressure on databases, networks, and application layers. Traditional single-server environments struggle under these conditions because resources are fixed and failures are disruptive.

High traffic exposes operational gaps that remain hidden at lower volumes. [Manual scaling](https://moldstud.com/articles/p-scaling-applications-for-high-traffic-and-performance) becomes too slow and error-prone to keep pace with demand. Single server failures can quickly cause downtime. Maintenance becomes more difficult to manage without causing disruption. Security threats increase because popular sites become high-value targets for attacks. For regulated industries, the pressure is even higher. Healthcare platforms, for example, must protect [electronic Protected Health Information (ePHI)](https://www.techtarget.com/searchhealthit/definition/electronic-protected-health-information-ePHI) while always remaining available to patients and providers.

In 2026, users expect pages to load instantly and services to stay available. Search engines and customers both penalize slow or unreliable sites. Cloud hosting [meets](https://www.site123.com/learn/maintaining-website-performance-during-traffic-spikes) these expectations by replacing fixed capacity with elastic resources, distributing workloads, optimizing infrastructure, and enabling teams to adapt in real time rather than reacting after problems have already occurred.

## How Cloud Hosting Supports Performance at Scale

Performance is the primary concern for high-traffic websites because it directly impacts user experience and business outcomes. Cloud hosting improves performance through distributed infrastructure and intelligent resource management. Cloud environments automatically scale compute power as demand grows, route traffic to the nearest or least loaded servers, and expand storage and databases without interrupting services. They also use advanced caching, high-speed storage, and optimized networking to reduce latency under pressure and deliver consistent performance.

This combination of [elasticity and optimization](https://nextbasket.com/scaling-your-business-with-cloud-hosting-how-to-handle-traffic-spikes/) becomes especially critical during unpredictable events. Seasonal sales, flash promotions, and breaking news create short but intense traffic spikes. Traditional hosting often forces businesses to overpay for unused capacity to survive these moments. Cloud hosting allows organizations to pay only for what they use while still providing fast and responsive experiences.

At Atlantic.Net, we build our cloud hosting on the principle that performance should be predictable, not just fast on good days. With this principle in mind, we design cloud environments to deliver consistent response times during traffic spikes, product launches, and unexpected surges. An independent expert review of our performance analysis is available [here](https://hostadvice.com/hosting-company/atlantic-net-reviews/).

## Reliability and Uptime Under Constant Demand

High traffic increases the impact of failures. A short outage on a popular site can affect thousands of users and damage brand credibility. Cloud hosting improves reliability through [redundancy](https://www.gremlin.com/blog/how-to-use-host-redundancy-to-improve-service-reliability-and-availability) and isolation.

Instead of relying on a single physical system, cloud environments [distribute](https://blogs.oracle.com/cloud-infrastructure/first-principles-redundancy-recovery-durability) workloads across multiple nodes. If one fails, others take over. This architecture supports high availability and simplifies disaster recovery planning.

At Atlantic.Net, a key focus of our architectural design is ensuring consistent availability. Our approach [centers on](https://www.atlantic.net/disaster-recovery/what-is-redundancy-a-broad-view/) eliminating single points of failure while keeping management simple for our clients.

## Security Expectations for High Traffic Websites

As traffic grows, so does the attack surface. High traffic websites are frequent targets for attacks, including denial of service attempts, credential abuse, and data exfiltration. Cloud hosting offers built-in tools to reduce these risks.

Isolation between workloads limits the spread of attacks. Network controls restrict access to sensitive systems. Encryption protects data as it moves across networks. For data in transit, acceptable standards like [TLS 1.2 or TLS 1.3](https://www.a10networks.com/glossary/key-differences-between-tls-1-2-and-tls-1-3/) can ensure confidentiality and integrity.

Besides technical solutions, [operational discipline](https://www.cloudpanel.io/blog/server-control-panel-apis/) also plays a vital role in maintaining security. Monitoring, logging, and access management must scale with traffic. Cloud platforms address this by providing centralized visibility and control.

## Compliance in High Traffic Environments

Many high-traffic websites operate in regulated industries. Healthcare, finance, and government services face strict requirements around data handling and privacy. Cloud hosting can support these needs, but compliance does not happen automatically.

In healthcare use cases, hosting environments must be HIPAA-compliant. This includes safeguards for ePHI, audit controls, access restrictions, and encryption. Organizations also need a [HIPAA Business Associate Agreement (BAA)](https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html) with their hosting provider.

It is important to note that there is no official HIPAA certification. Providers can be HIPAA-compliant but not certified. However, there are clear requirements that must be met and documented.

Atlantic.Net has long [prioritized](https://www.hipaahq.com/atlantic-net-review-hipaa-compliant-hosting/) compliance-driven cloud hosting. We work closely with clients managing sensitive workloads, helping them align their infrastructure with regulatory requirements. We believe security and performance should grow together, rather than compete with each other.

## Cost Control Without Compromising Growth

One concern often raised about cloud hosting is cost predictability. High traffic can lead to higher usage, and higher usage can increase bills. The answer is not in avoiding cloud hosting but in using it carefully.

Cloud environments provide detailed visibility into resource consumption. Teams can clearly see how traffic affects compute, storage, and network usage. This insight supports informed decisions about optimization and scaling policies. Instead of guessing future needs, organizations can adjust based on real usage patterns. For growing platforms, this flexibility is especially valuable. With proper planning, cloud hosting can remain both scalable and cost-efficient.

At Atlantic.Net, we work with clients to design cloud environments that balance performance and cost. [Transparent pricing](https://www.atlantic.net/cloud-platform/cloud-hosting/) and clear architecture choices help organizations plan growth without surprises.

## Operational Simplicity for Growing Teams

As traffic grows, operational complexity often grows with it. Managing servers, updates, backups, and security at scale can overwhelm internal teams. Cloud hosting simplifies operations by standardizing environments and automating routine tasks. Updates, scaling, and monitoring can be handled through consistent workflows. This reduces human error and shortens response times. Teams can focus on application quality and user experience instead of infrastructure maintenance.

At Atlantic.Net, we see our role as a partner rather than just a provider. We work with organizations to simplify operations while providing control and transparency.

## Choosing the Right Cloud Hosting Partner

Not all cloud hosting is the same. High-traffic websites require more than raw resources. They need thoughtful architecture, reliable support, and a clear understanding of compliance and security responsibilities.

An experienced partner offers guidance, not just infrastructure. They explain tradeoffs and design for real-world usage patterns. They help clients prepare for growth instead of reacting to crises. The right partner should become an extension of the team, supporting long-term performance, resilience, and trust as traffic scales.

At Atlantic.Net, we position ourselves as a partner, not just a vendor. We design, operate, and support cloud environments that help high-traffic websites remain fast, secure, and dependable as they scale.

### The Bottom Line

High traffic is a sign of success, but it also tests the limits of digital infrastructure. Cloud hosting provides the tools to meet this challenge. It supports performance under load, resilience during failures, security against threats, and compliance for sensitive data.

For organizations that expect growth, the question is no longer whether cloud hosting is suitable. The question is how well it is implemented and who stands behind it. With the right strategy and the right partner, high traffic becomes a strength rather than a risk.

At Atlantic.Net, we believe cloud hosting should allow growth, not restrict it. By combining scalable infrastructure with compliance-aware design and human support, we help high-traffic websites stay fast, secure, and ready for what comes next.


---

# Recommended HIPAA Hosting Services in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/recommended-hipaa-hosting-services-2026/ | Published: 2026-01-15 | Updated: 2026-01-09 | Author: Richard Bailey

Most organizations operating in the U.S. healthcare industry are required to comply with the regulations defined in the Health Insurance Portability and Accountability Act (HIPAA), passed by Congress in 1996. Companies must meet multiple standards and implement various safeguards regarding the processing of patient data to achieve HIPAA compliance. Failure to maintain HIPAA compliance can result in costly legal and financial penalties, as well as potentially long-term negative publicity. Healthcare organizations face potential financial penalties for non-compliance with HIPAA, which can range from $100 to $50,000 per violation.

Some businesses address these requirements with an on-premises data center and in-house technical skills. However, in many cases, companies opt for the best HIPAA-compliant and best HIPAA-compliant web hosting services to meet healthcare data privacy and security criteria. This path is very attractive to small and medium-sized businesses (SMBs) that may lack the resources or experience to achieve compliance. Selecting a HIPAA-compliant hosting provider is a critical decision that impacts the security of patient data.

This article examines why your business may be subject to HIPAA regulatory compliance. We discuss the features companies should look for when selecting a HIPAA-compliant cloud hosting provider such as Atlantic.Net. Our discussion concludes with reviews by reputable third parties that illustrate Atlantic.Net’s quality and the thoroughness of its HIPAA-compliant hosting solutions.

## Why Does a Company Need HIPAA Compliant Hosting?

Companies must comply with the HIPAA Privacy and Security Rules if they process or store protected health information (PHI) or electronic protected health information (ePHI) (also referred to as electronic patient health information). Organizations can be defined as a covered entity or a business associate, based on their role in handling patient data.

### What is PHI and ePHI?

PHI is any individually identifiable health information concerning a person’s health, care, or payment. PHI typically includes data about a patient’s health status, the medical care they receive, and how they paid for that care. This information must be accompanied by identifiers such as the patient’s name, Social Security number, addresses, and dates to qualify as PHI and be protected by the HIPAA Privacy Rule.

ePHI is a subset of PHI that is processed or stored electronically. It is protected by both the Privacy Rule and the HIPAA Security Rule. Companies handling ePHI must provide all employees and contractors with security awareness training and implement measures to meet the following safeguards defined in the Security Rule.

#### Administrative safeguards

These safeguards are designed to manage the security necessary to protect ePHI. They include:

- Implementing risk analysis and management processes;
- Engaging in proactive security monitoring;
- Designating a HIPAA security focal to oversee compliance activities;
- Providing workforce security awareness training;
- Developing data backup and disaster recovery plans;
- Defining role-based access controls;
- Implementing incident investigation and breach notification procedures;
- Entering into business associate agreements (BAAs) with partners.

#### Physical safeguards

Regulators developed these physical safeguards to protect the environment in which sensitive patient data is processed or stored.

- Facility access controls are required to restrict unauthorized entities from accessing ePHI.
- Companies must implement workstation use and security guidelines to protect equipment storing ePHI.
- Teams must develop device and media controls to track assets and securely dispose of obsolete data.

#### Technical safeguards

The technical safeguards required by the Security Rule protect the systems that process ePHI. They include:

- Access controls such as unique user identification, data encryption, and role-based authorization;
- Audit controls that provide immutable audit trails and activity logs;
- Authentication of all entities accessing ePHI;
- Integrity controls to identify unauthorized data modification;
- Protecting the transmission of ePHI from attacks by threat actors.

### Covered entities and business associates

Organizations subject to HIPAA compliance standards are categorized as either a covered entity or a business associate.

Covered entities (CEs) are the primary custodians of PHI and are directly regulated by HIPAA. They create, receive, maintain, or transmit patient data while providing healthcare or health benefits. Covered entities include:

- Healthcare providers such as hospitals, physicians, clinics, and labs;
- Health plans and insurers;
- Healthcare clearinghouses that process health data, such as billing services.

Business associates (BAs) provide services involving PHI on behalf of covered entities. They may create PHI, but not directly for treatment or care. Examples of business associates include:

- Cloud hosting providers;
- Managed service providers;
- Managed services;
- Claims processing services;
- Medical coders and transcribers;
- Backup and disaster recovery vendors.

Both CEs and BAs are liable for HIPAA compliance. CEs enter into business associate agreements with BAs to define compliance responsibilities and risk management.

A crucial aspect of HIPAA compliance is the shared responsibility model between hosting providers and covered entities.

## Key Features of HIPAA Compliant Hosting Providers

Healthcare organizations and businesses in the role of covered entity may decide to leverage a HIPAA-compliant hosting solution rather than rely on their in-house capabilities. They must ensure HIPAA compliance by working with reputable providers like Atlantic.Net. The company has over 30 years of experience with cloud hosting services, and has offered HIPAA-compliant hosting solutions since Congress enacted the regulations. Many providers offer compliance services to help organizations meet regulatory standards such as HIPAA and HITECH Act security standards, including technical controls, audits, and risk assessments. Some providers also support HIPAA eligible services, such as those offered by major cloud platforms, which are covered under a Business Associate Agreement (BAA) for processing Protected Health Information (PHI). The cost of HIPAA-compliant hosting can vary significantly based on the services and resources required.

The following are key features prospective customers should look for in a HIPAA-compliant hosting provider.

### Business associate agreements

The provider must be willing to sign a [business associate agreement](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) with a covered entity. Lack of a BAA is a HIPAA violation, and clients should walk away from vendors unwilling to enter into the agreement. Atlantic.Net’s BAAs meet all HIPAA regulations and demonstrate their willingness to exceed the minimum compliance standards. They serve as a trusted partner to CEs and are committed to the customer’s best interest.

### HIPAA-compliant data centers

The selected vendor must operate data centers that meet all HIPAA guidelines. Healthcare technology systems and ePHI must be protected by controlled access to the data center and supported by 24/7 on-site personnel. The data center should be equipped with surveillance capabilities, offer HIPAA compliance monitoring, and furnish audit trails. Providers demonstrate compliance with HIPAA standards through SOC 2, ISO 27001, or similar audits.

Regular data backups, both onsite and offsite backups, are required to ensure data recovery in case of a breach or failure. Offsite backups are especially important for HIPAA compliance, as they provide secure, remote storage of sensitive data in accordance with regulatory requirements.

Atlantic.Net provides its customers with a [world-class data center infrastructure](https://www.atlantic.net/hipaa-data-centers/) featuring 24/7/365 support and monitoring. Their experts can help you achieve compliance quickly with a range of certifications, including SOC 2, SOC 3, and HITECH.

### Meeting security rule safeguards

It is essential that the selected hosting services comply with all security rule safeguards for the handling of ePHI. Customers must be confident that the provider follows all guidelines required to protect ePHI. Using a HIPAA-compliant server is a critical component of a secure, regulated hosting environment, as it ensures that technical and administrative controls are in place to safeguard sensitive health information. The hosting provider must implement the following crucial measures.

- Protected data must be encrypted in transit and at rest. This protection includes full-disk encryption for storage devices and encrypted backups to eliminate the chance of data breaches.
- The provider must support activity logging that enables teams to investigate security-related events. Logs need to be retained to meet HIPAA requirements with immutable log storage to preserve tamper-proof audit evidence.
- Vendors must protect ePHI with dedicated or isolated networks and environments to meet HIPAA single-tenancy requirements. Network access must be controlled via firewalls and micro-segmentation. Intrusion detection and prevention solutions should be implemented to identify threat actors quickly. The provider’s technical teams should perform patch and vulnerability management to maintain robust security.
- The hosting environment must enforce user authorization and accountability by assigning unique identifiers, implementing multi-factor authentication (MFA), privileged access logging, and role-based access controls. HIPAA forbids the use of shared admin accounts.
- Providers must maintain a formal incident response program that includes notification and escalation workflows. The BAA may require the provider to handle breach reporting procedures. All response activities must be logged, retained, and auditable.

### Backup and disaster recovery services

Customers should expect a HIPAA-compliant hosting provider to protect their ePHI with encrypted off-site backups, preferably with geographic redundancy options for enhanced resiliency. The vendor must have documented disaster recovery plans that meet the customer’s recovery point and time expectations. Teams should regularly test disaster recovery procedures to ensure they support business continuity.

### Comprehensive documentation

Prospective providers should be able to supply customers with a BAA template that can be tailored to both parties’ satisfaction. Certification, such as SOC 2 reports, must be available to demonstrate their ability to provide a HIPAA-compliant environment. Additional documentation, such as penetration testing summaries and HIPAA compliance mapping, is an indication of a responsible partner.

### Tailored HIPAA hosting solutions

Your provider should offer a range of HIPAA-compliant services tailored to your unique business needs. While some companies may need a complete HIPAA-compliant environment, others may process ePHI in ways that require a less comprehensive solution. A flexible provider, such as Atlantic.Net, has a variety of HIPAA-compliant solutions to fit your company’s requirements. Managed HIPAA hosting helps reduce the internal IT burden for healthcare organizations by handling security patching and compliance monitoring.

The following are examples of our tailored solutions designed to protect ePHI and ensure your HIPAA compliance.

- HIPAA-compliant web hosting options, such as our [WordPress hosting](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/), provide customers with turn-key compliance for their WordPress websites.
- HIPAA-compliant website hosting ensures your site meets HIPAA security and privacy standards for PHI.
- HIPAA-compliant email services offer secure, encrypted communication and support for e-PHI.
- HIPAA-compliant database hosting supports enterprise MySQL and Microsoft SQL Server systems.
- Windows and Linux HIPAA-compliant hosting solutions support all versions of Windows Server and a wide range of Linux distros, including FreeBSD, Arch Linux, Ubuntu, Debian, and Oracle.
- HIPAA-compliant cloud solutions leverage secure cloud servers for scalable, compliant hosting environments, with physical, administrative, and technical safeguards in place.
- Our servers can be used as a HIPAA-compliant application platform for customers’ healthcare-related SaaS products.
- HIPAA-compliant hosting powers healthcare technology systems by providing secure, compliant infrastructure that supports healthcare workflows and protects PHI.

## HIPAA Compliant Cloud Hosting

HIPAA compliant cloud hosting is a critical solution for healthcare organizations that need to securely store, process, and manage electronic protected health information (ePHI) in the cloud. Under the Health Insurance Portability and Accountability Act (HIPAA), any cloud hosting provider that handles sensitive patient data must adhere to strict security and privacy standards. This includes signing a Business Associate Agreement (BAA) with each client, which legally binds the provider to safeguard protected health information in accordance with HIPAA regulations.

Leading cloud service providers such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud offer HIPAA compliant cloud hosting solutions tailored to the unique needs of healthcare organizations. These platforms deliver robust security features, including advanced encryption, access controls, and continuous compliance monitoring, to ensure that sensitive patient data remains protected at all times. By leveraging HIPAA compliant cloud hosting, healthcare organizations can benefit from scalable infrastructure, high availability, and disaster recovery capabilities, all while maintaining full compliance with the Accountability Act.

Choosing a HIPAA compliant cloud hosting partner allows healthcare providers to focus on delivering quality care, knowing that their electronic protected health information is managed in a secure, compliant environment. Whether you are migrating existing systems or building new healthcare applications, working with a provider that will sign a business associate agreement and offer comprehensive compliance support is essential for meeting regulatory requirements and protecting patient trust.

## HIPAA Compliant Hosting and Data Transmission

Secure data transmission is a cornerstone of HIPAA compliant hosting, ensuring that electronic protected health information (ePHI) remains confidential and protected as it moves across networks. HIPAA compliant hosting providers implement industry-standard protocols such as HTTPS and SFTP to encrypt patient data in transit, preventing unauthorized interception or tampering. These secure protocols are essential for healthcare organizations that need to transmit sensitive information between systems, locations, or third-party partners.

In addition to encryption, HIPAA compliant hosting providers deploy robust access controls, including firewalls and intrusion detection systems, to safeguard protected health information during transmission. Continuous monitoring and real-time alerting help identify and respond to potential security incidents, while comprehensive reporting procedures ensure that any breaches are promptly addressed in accordance with HIPAA regulations.

By choosing a hosting provider that prioritizes secure data transmission, healthcare organizations can confidently exchange ePHI, knowing that their patient data is protected every step of the way. This commitment to compliant hosting not only supports regulatory compliance but also reinforces patient trust in the organization’s ability to safeguard their most sensitive information.

## HIPAA Compliant Hosting and Access Controls

Effective access controls are fundamental to HIPAA compliant hosting, providing healthcare organizations with the tools needed to restrict and monitor access to electronic protected health information (ePHI). HIPAA compliant hosting providers implement secure login and authentication procedures, such as unique usernames, strong passwords, and multi-factor authentication, to ensure that only authorized personnel can access sensitive patient data.

Role-based access controls further enhance security by limiting data access based on an individual’s job function or responsibilities within the organization. This approach minimizes the risk of unauthorized access and helps healthcare organizations maintain strict oversight of who can view or modify protected health information.

To support ongoing compliance, HIPAA compliant hosting providers maintain detailed audit logs and access reports, enabling organizations to monitor user activity and quickly identify any suspicious behavior. These monitoring and reporting procedures are essential for demonstrating compliance with HIPAA regulations and for responding effectively to potential security incidents.

By partnering with a HIPAA compliant hosting provider that prioritizes robust access controls, healthcare organizations can ensure that their patient data remains secure, confidential, and accessible only to those with a legitimate need—helping to meet regulatory obligations and protect patient privacy.

## Why Choose Atlantic Net as Your HIPAA Compliant Hosting Partner?

Atlantic.Net provides all the features previously discussed to ensure HIPAA compliance for your business. We have over 30 years of experience in providing customers with HIPAA-compliant services. All of our solutions feature HIPAA-compliant cloud storage and cloud servers. We offer dedicated servers and cloud-based compliant hosting services with a 100% uptime SLA.

Here’s what some reviewers have to say about our HIPAA-compliant solutions.

- [The Silicon Review](https://thesiliconreview.com/2025/12/best-hipaa-hosting-providers): “Atlantic.Net’s compliance hosting platform is purpose-built for ePHI from the ground up, rather than offering HIPAA eligibility as one configuration option among many. Their infrastructure includes SOC 2 Type II and SOC 3 Type II certified systems validated through independent third-party audits of their data center facilities.”
- [HIPAA HQ](https://www.hipaahq.com/atlantic-net-review-hipaa-compliant-hosting/): “Atlantic.Net excels in all categories when it comes to HIPAA Compliant Hosting, including hosting your data in their private data centers from the start. If you need enterprise caliber features and service, with pricing that fits your budget, Atlantic.Net should be at the top of your list if you need a HIPAA Compliant Hosting Provider.”
- [HostAdvice](https://hostadvice.com/hosting-company/atlantic-net-reviews/): “Atlantic.Net caught my eye because they offer everything from powerful GPU servers to strict HIPAA-compliant hosting, a rare mix in one place. I thoroughly explored their sign-up process, dashboard, and performance to understand how they serve both newcomers and experienced users. What stood out was a platform that’s powerful but user-friendly, offering features suited for a wide range of demanding tasks.”
- [Customer testimonial](https://www.atlantic.net/hosting-services-provider/atlantic-net-reviews-and-testimonials/): “As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals “

[Get in touch](https://www.atlantic.net/about-us/corporate-contact/) with our team of experts today and start protecting your ePHI with a tailored HIPAA-compliant hosting solution.


---

# Atlantic.Net Named Internet and Technology Winner in the 2026 BIG Innovation Awards

> URL: https://www.atlantic.net/press-releases/atlantic-net-named-internet-and-technology-winner-in-the-2026-big-innovation-awards/ | Published: 2026-01-15 | Updated: 2026-03-02 | Author: Oday Albayati

Orlando, FL (January 15, 2026)  – [Atlantic.Net](https://www.atlantic.net/) is proud to announce that it has been named an Internet and Technology Winner in the 2026 [BIG Innovation Awards](https://www.bintelligence.com/awards/big-innovation-awards), a global recognition program honoring companies, products, and leaders who are transforming industries through applied innovation, intelligent platforms, and measurable real-world impact.

“The 2026 BIG Innovation Awards winners show that true innovation is no longer about chasing the latest buzzwords,” said Russ Fordyce, Chief Recognition Officer at the Business Intelligence Group. “It’s about building intelligent platforms, automating workflows with purpose, and making trust, privacy, and resilience the foundation of every breakthrough. These organizations and leaders are not just keeping pace with change, they are shaping the future of global business.”

Atlantic.Net was recognized for its outstanding contributions to innovation in HIPAA-Compliant Cloud Hosting.

In May 2025, Atlantic.Net significantly upgraded its HIPAA-compliant hosting environment to meet the specialized AI/ML demands of biotech, medical, and healthcare companies. With the rapid growth and application of AI in the healthcare industry, [Atlantic.Net](https://www.atlantic.net/) continues offering solutions to provide strict cybersecurity and compliance for the growing healthcare market. Important goal: To ensure a patient’s security. 

“We are pleased to have received this recognition,” said Marty Puranik, founder and CEO at Atlantic.Net. “We are committed to continue future innovations in 2026 and beyond.”

Atlantic.Net joins 159 winners recognized for their contributions to innovation across health, financial services, logistics, manufacturing, and enterprise technology. The 2026 BIG Innovation Awards winners reveal a clear trend: innovation is no longer about just having AI, it’s about how you use it. Winners are building platforms, automating workflows, and focusing on trust, privacy, and security as core to their mission.

For more information about the BIG Innovation Awards and to view the full list of winners, visit [here](http://www.bintelligence.com/posts/2026-big-innovation-awards-159-trailblazers-prove-where-innovation-is-really-happening.).

## **About Atlantic.Net**

Founded in 1994, [Atlantic.Net](https://www.atlantic.net/) is a privately held global cloud infrastructure provider with customers in over 100 countries, known for delivering secure, compliant, on-demand and customizable hosting solutions. With decades of experience, Atlantic.Net is one of the world’s most trusted and experienced hosting providers, offering 24/7 U.S.-based support. Specializing in security, compliance, and customer service, Atlantic.Net serves a diverse range of industries with solutions including HIPAA-compliant hosting, and PCI-compliant hosting, backed by bare metal servers, dedicated hosting, GPU hosting, colocation, and its award-winning Cloud Platform. Operating from eight strategically located data center regions across the United States, Canada, the United Kingdom, and Asia, Atlantic.Net powers mission-critical workloads for organizations worldwide. For more information, visit[Atlantic.Net](https://www.atlantic.net/) or connect with us on[Facebook](https://www.facebook.com/Atlantic.Net),[X (Twitter)](https://twitter.com/AtlanticNet),[LinkedIn](https://www.linkedin.com/company/atlantic.net-inc./posts/?feedView=all), and[YouTube](https://www.youtube.com/c/AtlanticNet).

## **About Business Intelligence Group**

The Business Intelligence Group was founded with the mission of recognizing true talent and superior performance in business. Unlike many [recognition programs](https://www.bintelligence.com/), these awards are evaluated by business leaders and practitioners who reward programs, products, and people that deliver real, quantifiable excellence rather than marketing narratives.


---

# Best Bare Metal Hosting Providers for Secure Workloads in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/best-bare-metal-hosting-providers-secure-workloads-2026/ | Published: 2026-01-16 | Author: Dr. Assad Abbas

Bare metal hosting has moved back into the spotlight as organizations rethink how they build and run critical systems. For years, shared cloud platforms promised simplicity and speed. They delivered flexibility, but they also introduced limits that are now hard to ignore. Performance inconsistency, limited hardware control, and growing security concerns are pushing teams to reconsider physically dedicated infrastructure.

[In 2026](https://www.archivemarketresearch.com/reports/bare-metal-server-provider-563723?tab=summary), bare metal hosting is no longer a niche choice. It is a strategic decision for businesses running AI workloads, large databases, regulated applications, and platforms where downtime or latency directly affect revenue or safety. The renewed interest is not about abandoning the cloud. It is about choosing the right foundation for the right workload.

## Why Organizations Are Returning to Bare Metal

The defining [advantage](https://www.ibm.com/think/topics/bare-metal-dedicated-servers) of bare metal is that one server belongs to one organization. There is no [hypervisor](https://www.vmware.com/topics/bare-metal-hypervisor) sharing resources, no competing workloads, and no uncertainty about performance. Every CPU cycle, memory allocation, and disk operation is predictable.

This matters most for workloads that fully consume hardware. [AI model training](https://acecloud.ai/blog/gpu-virtualization-vs-bare-metal/), real-time analytics, healthcare systems processing ePHI, [scientific research](https://www.latitude.sh/blog/how-bare-metal-servers-are-revolutionizing-scientific-research) and financial platforms making rapid decisions all depend on consistency. Even small fluctuations caused by shared environments can create real problems.

Security and compliance are equally important. Bare metal provides physical isolation, which reduces attack surfaces and simplifies risk management. For healthcare organizations, this is especially relevant. ePHI, or [electronic Protected Health Information](https://www.techtarget.com/searchhealthit/definition/electronic-protected-health-information-ePHI), must be protected through strict administrative, physical, and technical safeguards. Dedicated servers make it easier to control access, document processes, and meet audit expectations.

When combined with modern encryption for data in transit using TLS 1.2 or TLS 1.3, bare metal becomes a strong foundation for regulated workloads. Providers that support [HIPAA Business Associate Agreements](https://www.techtarget.com/healthtechsecurity/feature/What-Is-a-HIPAA-Business-Associate-Agreement-BAA) on first engagement and BAAs thereafter play a critical role in this ecosystem.

## How to Evaluate Bare Metal Hosting Providers

Not all bare metal hosting is the same. Hardware specifications matter, but they are only one part of the decision. Data center reliability, network design, operational support, and compliance expertise are just as important.

A strong provider offers transparency. You should know where your data resides, how physical access is controlled, and how incidents are handled. Support quality matters more than many teams expect. When infrastructure issues arise, the provider’s response can directly impact business continuity.

With those criteria in mind, the following list highlights some of the best bare metal hosting providers in 2026.

### Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

Atlantic.Net stands out as a bare metal hosting provider built for reliability, security, and regulated environments. We have spent decades supporting organizations that cannot afford uncertainty, especially in healthcare, finance, and enterprise SaaS.

Our bare metal servers are fully dedicated and hosted in U.S. based data centers with redundant power, cooling, and networking. We [offer](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) a range of hardware options, including high clock speed Intel Xeon processors and high core count AMD EPYC systems. This flexibility allows workloads to be matched precisely to application needs.

Security and compliance are core part of our operation, not just add-ons. We support HIPAA-compliant hosting and work closely with healthcare organizations managing ePHI. We provide HIPAA Business Associate Agreements and design infrastructure that aligns with regulatory requirements. It is important to note that there is no such thing as HIPAA certification, but our environments are built to support HIPAA-compliant operations in practice.

Key features include:

- Single tenant bare metal servers with full hardware control and predictable performance
- HIPAA-compliant infrastructure with support for BAAs and audit readiness
- Encryption support for data in transit using TLS 1.2 and TLS 1.3
- U.S. based data centers with a strong focus on uptime and support

More details about our bare metal hosting approach can be found at [https://www.atlantic.net](https://www.atlantic.net/).

### Amazon Web Services Bare Metal Instances

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

AWS [offers](https://aws.amazon.com/about-aws/whats-new/2023/10/new-amazon-ec2-bare-metal-instances/) bare metal instances as part of its broader cloud ecosystem. These instances remove the hypervisor layer while maintaining integration with familiar AWS services.

This option is well suited for organizations already deeply invested in AWS tooling. Teams can deploy dedicated hardware while continuing to use existing security groups, identity management, and automation workflows.

Key features include:

- Bare metal access integrated into the EC2 environment
- Strong global infrastructure and network reach
- Compatibility with existing AWS security and management tools

AWS bare metal works best for teams that value ecosystem continuity over infrastructure simplicity.

### Microsoft Azure Bare Metal Infrastructure

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

Azure [provides](https://learn.microsoft.com/en-us/azure/baremetal-infrastructure/concepts-baremetal-infrastructure-overview) bare metal infrastructure primarily designed for enterprise workloads and large-scale applications. It is often used in scenarios where organizations need dedicated hardware but want centralized management.

The Azure platform allows teams to manage physical servers using the same dashboards and policies they already use for virtual resources. This reduces operational friction for enterprises standardizing on Microsoft technologies.

Key features include:

- Centralized management through the Azure portal
- Integration with enterprise identity and security frameworks
- Suitable for large scale and legacy enterprise workloads

Azure bare metal is a natural fit for organizations already aligned with Microsoft’s ecosystem.

### Google Cloud Bare Metal Solution

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

Google Cloud [offers](https://docs.cloud.google.com/bare-metal/docs) bare metal solutions designed to support performance intensive workloads and data heavy applications. Its strength lies in networking and integration with Google’s analytics and AI services.

This platform is commonly used for migrations from premises systems or for workloads that benefit from Google’s global network.

Key features include:

- High performance networking backed by Google’s global infrastructure
- Integration with analytics and data processing services
- Support for hybrid and migration focused architectures

Google Cloud bare metal appeals to teams focused on data throughput and analytics performance.

### IBM Cloud Bare Metal Servers

![](https://www.atlantic.net/wp-content/uploads/2025/06/ibm-logo.png)

[IBM Cloud Bare Metal](https://www.ibm.com/products/bare-metal-servers) Servers are designed for organizations that need enterprise grade performance and customization. IBM offers bare metal through two primary models. The classic infrastructure model allows deep customization at the hardware level, while the VPC based bare metal option emphasizes faster provisioning and tighter integration with modern cloud workflows. This makes IBM a common choice for organizations operating in hybrid environments.

Key features include:

- Flexible deployment models, including classic infrastructure and VPC based bare metal
- Support for modern infrastructure, with GPU options for compute intensive workloads
- Global data center presence for enterprise scale operations

IBM Cloud Bare Metal Servers are best suited for large organizations that value stability and integration with broader enterprise systems. The platform offers depth and reliability for large scale workloads, even if it feels more complex than lightweight bare metal services.

## Looking Ahead in 2026

Bare metal hosting in 2026 is defined by flexibility layered on top of physical control. Bare Metal as a Service models are making dedicated infrastructure easier to deploy and scale. GPU accelerated bare metal is becoming standard as AI workloads grow. Sustainability is also influencing provider choices, with more efficient hardware and energy practices gaining attention.

Despite these trends, the fundamentals remain the same. Bare metal succeeds when it delivers predictable performance, strong security, and dependable support.

## Choosing the Right Bare Metal Partner

The right bare metal hosting provider depends on workload requirements, compliance obligations, and operational priorities. For regulated industries, experience matters. Providers that understand HIPAA-compliant hosting and can support BAAs reduce risk and operational burden.

Performance consistency, data location, and responsive support should weigh heavily in the decision. Bare metal is not just about hardware. It is about trust in the infrastructure that supports your most important systems.

In 2026, organizations that choose their bare metal partners carefully will gain not just performance, but confidence in the foundation of their digital operations.

 


---

# The Best Cloud Hosting for Ecommerce Sites in 2026

> URL: https://www.atlantic.net/cloud-platform/best-cloud-ecommerce-hosting-2026/ | Published: 2026-01-18 | Updated: 2026-06-23 | Author: Robert Agar

Ecommerce hosting refers to the cloud services provided to businesses that run online stores. Specialized hosting types such as cloud VPS offer scalable, reliable virtual private server solutions tailored for ecommerce sites, providing increased resources, security, and performance compared to [shared hosting](http://www.atlantic.net/vps-hosting/vps-hosting-vs-shared-hosting-pros-cons-differences-and-expert-tips/).

Ecommerce hosting is a specialized hosting type designed for online stores, featuring preinstalled store software, integrated payment and shipping tools, and advanced security protocols to optimize online retail operations. The type of web hosting necessary to support an ecommerce website is different from the services offered to other kinds of companies. An ecommerce platform is more sensitive to latency, site speed, and performance disruptions than businesses that do not need to maintain continuous availability.

There are various hosting types available for ecommerce, including shared, VPS, dedicated, and cloud hosting. Choosing the right [cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) plan requires evaluating your specific needs and budget.

This article highlights the features that ecommerce businesses need to be successful. We also identify some of the best ecommerce hosting services to help you find one that addresses your business requirements and objectives

## What Ecommerce Hosting Features Are Essential for Your Business?

Companies running an online business require key features from their ecommerce hosting solution. There are a variety of hosting options available for ecommerce businesses, including shared hosting, VPS, [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/top-dedicated-hosting-ecommerce-platforms/), and specialized e-commerce hosting, each catering to different business sizes and needs. The following are the necessary features that support ecommerce success.

### High performance with low latency

Ecommerce businesses require superior performance combined with low latency and fast page load to meet and maintain customer satisfaction. Visitors to an ecommerce website do not want to wait around for the site to respond. Businesses that cannot deliver acceptable site speed risk losing current and prospective customers to competitors offering better site performance.

Hosting clients must ensure their vendor provides the server resources needed to achieve optimal performance. Ecommerce sites are sensitive to the speed and responsiveness of the underlying infrastructure. Latency can adversely affect conversion rates, customer satisfaction, and revenue.

Essential features contributing to high performance include:

- Fast I/O throughput with SSDs or NVMe for data storage;
- High-performing CPUs coupled with adequate memory and caching for fast page loads;
- High levels of unlimited bandwidth to address fluctuating access demands;
- Support for HTTP/2 and HTTP/3;
- [Content Delivery Network](https://www.atlantic.net/hipaa-compliant-hosting/content-delivery-networks-theyre-powerful/) (CDN) integration to improve site navigation.

Cloud hosting typically delivers page load times under 2 seconds for optimized eCommerce sites.

### Outstanding availability

Ecommerce stores require high availability to maintain customer satisfaction. Downtime directly affects the revenue of companies running online stores. Customers will often find an alternative if an online store is unavailable. The hosting provider should offer the following features to ensure uptime and high availability.

- Redundant infrastructure is necessary to avoid downtime caused by component failures.
- Failover clustering eliminates downtime by immediately switching away from failed components.
- Geographic redundancy ensures continued ecommerce functionality in the event of major operational disruptions.
- Providers should offer service level agreements (SLAs) of at least 99.9% to guarantee uptime.

### Robust security with free SSL/TLS certificate

Security is vital for all web hosting clients, including those supporting ecommerce sites. Ecommerce platforms process payment data and store sensitive customer information, which must be protected against threat actors and security breaches. Essential security features for ecommerce hosting include:

- TLS certificates (TLS 1.2 or 1.3) to support secure HTTPS connections;
- Complimentary TLS to improve website security and simplify management;
- A web application firewall (WAF) to block malicious traffic;
- An [intrusion detection](https://www.atlantic.net/dedicated-server-hosting/what-is-an-intrusion-detection-system-and-why-do-i-need-it/) and prevention solution;
- Vulnerability management and patching;
- Isolation from other tenants.

Many ecommerce hosting services include free certificates for security.

After discussing firewalls or intrusion prevention, it’s important to note that DDoS protection shields your store from malicious attacks that attempt to overwhelm servers.

### Scalability

Ecommerce businesses must address unpredictable fluctuations in monthly visitor numbers due to seasonal traffic or marketing promotions. Hosting customers require sufficient resources to provide reliable performance regardless of visitor volume. Essential capabilities to support an ecommerce platform include:

- Vertical and horizontal on-demand scaling;
- Load balancing, maintaining performance across multiple websites;
- Seamless system and resource upgrades with no performance disruptions or downtime;
- Auto scaling.

Auto scaling automatically adjusts server resources based on real-time demand, ensuring your site remains responsive during traffic spikes. Cloud hosting for eCommerce uses multiple connected servers to power online stores, enhancing scalability and reliability.

### Payment processing support

One of the significant differences between ecommerce businesses and other cloud hosting clients is the need for payment processing support. The hosting services must support secure payment gateways to protect sensitive financial transactions. These features are crucial for ecommerce hosting:

- A PCI-compliant infrastructure to maintain regulatory compliance;
- Tokenization support for secure transactions;
- Network and resource segmentation for cardholder data;
- Detailed and retained audit logs of all transactions.

### Monitoring and reporting

Customers with an ecommerce website require comprehensive monitoring and reporting from their hosting platform. Monitoring, logging, and reporting provide ecommerce businesses with valuable information that includes:

- Real-time and historical data to track search engine rankings and the number of monthly visitors, helping to assess bandwidth and storage needs based on traffic levels;
- Error and downtime alerts to maintain performance standards;
- Application and infrastructure logging to support performance and security investigations.

### Backup and disaster recovery

Data protection is vital for ecommerce stores that need to safeguard customer, order, and inventory information. Companies with an online store also need [disaster recovery](https://www.atlantic.net/disaster-recovery/disaster-recovery-plan/) capabilities to ensure business continuity and maintain customer service. The web hosting provider should offer the following services to protect an ecommerce business.

- Data should be protected with regularly scheduled and automatic backups.
- Automated backups must be stored on encrypted media to prevent unauthorized access.
- Companies can achieve greater resilience by storing offsite backups in alternative geographic regions.
- Point-in-time recovery must be capable of meeting customer-defined recovery point and time objectives (RPOs/RTOs).
- Recovery must be tested by the customer or provider-led teams.

### Application compatibility

Many ecommerce applications are widely used by companies with online stores. Web hosting providers should support a variety of standard ecommerce application stacks and solutions for an e commerce website, such as:

- WooCommerce hosting;
- BigCommerce;
- Magento/Adobe Commerce;
- Payment gateways like PayPal.

Businesses look for providers with application compatibility, as it provides flexibility and prevents vendor lock-in.

### Operational support

Providers supporting ecommerce stores should offer their customers [managed services](https://www.atlantic.net/managed-services/) and operational support. Businesses can achieve improved performance and a competitive advantage with operational efficiency.

The provider’s expert teams can ensure that customers’ ecommerce websites are secure and meet performance expectations. Managed services reduce IT overhead, which is especially important to small businesses with limited technical resources. Valuable services include:

- Operating system maintenance and patching;
- Security hardening to mitigate threats;
- SLA-based incident response procedures;
- 24/7 customer support and a responsive ticketing system;
- Priority support.

Priority support provides immediate assistance when your store faces technical issues.

## Ecommerce Platform Integration

Ecommerce platform integration is a cornerstone of any successful ecommerce hosting solution. The ability to connect your online store with leading ecommerce platforms ensures that your business can leverage the latest features, maintain reliable performance, and scale as needed.

A top-tier ecommerce hosting provider will offer robust compatibility with popular ecommerce platforms, making it easy for you to launch, manage, and grow your ecommerce website without technical headaches. This integration not only streamlines your operations but also allows you to take full advantage of the tools and features that drive ecommerce success.

### WooCommerce, Magento, and Shopify compatibility

When selecting an ecommerce hosting provider, it’s essential to ensure compatibility with the most popular ecommerce platforms: WooCommerce, Magento, and Shopify. WooCommerce, as a flexible WordPress plugin, is ideal for businesses seeking customization and control over their ecommerce site.

Magento stands out for its advanced features and scalability, making it a favorite among larger enterprises and fast-growing online stores with [managed Magento hosting](https://www.mgt-commerce.com/magento-hosting/). Shopify, known for its user-friendly interface and extensive app ecosystem, is perfect for those who want a hassle-free, hosted solution.

By choosing an ecommerce hosting provider that supports these platforms, you guarantee that your ecommerce website can operate efficiently, adapt to your business needs, and integrate with the latest ecommerce solutions.

### Seamless integration with ecommerce applications

For an online business to thrive, seamless integration with essential ecommerce applications is a must. The best ecommerce hosting providers offer built-in support for payment gateways, inventory management tools, and shipping solutions, allowing you to manage every aspect of your ecommerce store from a single platform. Features like automated backups, free certificates, and dedicated resources ensure your ecommerce site remains secure, reliable, and high-performing. With these integrations, you can streamline order processing, protect sensitive customer information, and provide a smooth shopping experience—all of which are critical for ecommerce success. By partnering with hosting providers that prioritize seamless integration, you set your online business up for sustainable growth and superior performance.

## The Best Ecommerce Hosting Providers for Your Business

You must find the right ecommerce hosting provider to meet your business needs. When choosing a provider, consider hosting costs as they can vary depending on the type of hosting, features, and support levels. The right plan balances performance, features, and cost for optimal return on investment. The following list of hosting providers offers web hosting plans that meet the requirements for running an online store.

![](https://images.surferseo.art/384b855e-7b66-4eb1-b9bc-fa9b39a0dd0d.png)

### [Atlantic.Net](https://www.atlantic.net/)

Atlantic.Net has over 30 years of experience in providing customers with dedicated and shared hosting solutions to address various business objectives. They offer a range of PCI-compliant managed hosting plans that leverage cloud and dedicated resources to meet the unique needs of your ecommerce store. Atlantic.Net also provides a cloud VPS solution with dedicated resources, improved speed, and enhanced security, making it an excellent choice for ecommerce sites seeking reliable performance and protection. The company operates regularly inspected SOC 2 TYPE II and SOC 3 TYPE II certified data centers, ensuring the security of your environment and customer data.

Atlantic.Net outstanding features include:

- A managed firewall to keep threat actors out;
- Fully encrypted backups to protect valuable and sensitive data;
- 100% uptime SLA for cloud, managed, and dedicated hosting plans;
- Priority support to ensure high performance;
- Managed intrusion detection system for enhanced security.

![](https://images.surferseo.art/5cdd37c2-7ed6-4d7d-bd36-3304d68da500.png)

### [Shopify](https://www.shopify.com/)

Shopify is a dedicated ecommerce platform that supports local and global e commerce stores. The company provides flexible ecommerce solutions designed to grow with your business. Businesses can support global CDN networks to publish across channels and expand their customer base. Shopify offers desktop and mobile solutions that enable your store to operate efficiently on any device.

Shopify features include:

- Site builder tools to create online stores;
- Customizable templates and themes for enhanced branding;
- Pricing plans supporting clients ranging from entrepreneurs to enterprises;
- Analytics and inventory management tools.

![](https://images.surferseo.art/129cecbc-bdaa-482a-af3b-e8d0541706d2.png)

### [Hostinger](https://www.hostinger.com/)

Hostinger is a popular ecommerce platform that offers users a streamlined path to creating an online store. Their multiple hosting plans are designed to address the needs of individuals, large companies, and e commerce sites. The company specializes in creating WordPress sites using AI and pre-built templates.

Hostinger inclusive feature set includes:

- AI-website builder to create your store;
- AI-powered email marketing;
- 30-day money-back guarantee;
- Introductory plans starting at $1.99 per month.

![](https://images.surferseo.art/ce77e92f-eab9-47fa-b15b-9a72aea32e9c.png)

### [GoDaddy](https://www.godaddy.com/)

GoDaddy is a well-recognized hosting provider that heavily advertises its ecommerce solutions. Its AI-powered tools enable novice users to create an original online store in minutes. An extensive library of templates allows users to tailor their websites to distinguish themselves from the competition.

GoDaddy’s features include:

- GoDaddy Airo, an AI-powered assistant;
- Managed TLS/SSL services;
- Professionally branded invoices;
- Domain-based emails for a more professional look.

![](https://images.surferseo.art/70b70388-5fec-4396-8b27-957b2395d557.png)

### [AWS](https://aws.amazon.com/)

AWS is an industry leader in public cloud hosting and services. They offer virtual private servers as part of their hosting solutions, providing top-rated and user-friendly options for ecommerce sites. AWS provides clients with modern, AI-powered ecommerce shopping experiences across digital channels to increase conversion and profitability. Customers can maintain high service levels while combating fraud with the latest technologies.

Features to expect from AWS include:

- 3D product previews and virtual stores;
- Generative AI to quickly create compelling product descriptions and images;
- Digital shopping assistants and personalized recommendations;
- Improved search engines help consumers rapidly discover products.

![](https://images.surferseo.art/92a83d75-1d45-4c9f-970c-48437c8f210c.png)

### [Host Gator](https://www.hostgator.com/)

Host Gator provides ecommerce hosting solutions, along with web design and SEO tools, to help you get started quickly. They offer [VPS hosting](https://www.atlantic.net/vps-hosting/) as an option for ecommerce businesses, providing dedicated resources, enhanced control, and improved security compared to shared hosting. Host Gator also offers economically priced 36-month plans that appeal to start-ups and small businesses. Security includes free malware scanning, a [web application firewall](https://www.atlantic.net/vps-hosting/waf-web-application-firewall/), and [DDoS protection](https://www.atlantic.net/vps-hosting/what-is-a-ddos-and-how-do-we-prevent-our-business-from-being-attacked/).

The features Host Gator offers include:

- Free domain for a year;
- Free [SSL](https://www.atlantic.net/vps-hosting/what-is-ssl-certificate/) certificates;
- Unmetered bandwidth;
- Automatic WordPress installation.

### Conclusion

You must be sure that the hosting provider you select has the features you need to run your online store efficiently. We have examined the features to look for in a provider and identified some of the best options for creating an ecommerce website.

Partnering with a reliable and experienced company like Atlantic.Net will give you a competitive advantage and set your company up for long-term success. Additionally, some advanced hosting providers offer the ability to clone the entire server, making it easy to create staging environments for testing themes and plugins before deploying changes to your live site.


---

# Best Bare Metal Hosting Providers in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/best-bare-metal-hosting-providers-in-2026/ | Published: 2026-01-19 | Updated: 2026-06-23 | Author: Dr. Tehseen Zia

Bare metal hosting has moved back into the spotlight as organizations rethink how they build and run critical systems. For years, shared [cloud platforms](https://www.atlantic.net/cloud-platform/) promised simplicity and speed. They delivered flexibility, but they also introduced limits that are now hard to ignore. Performance inconsistency, limited hardware control, and growing security concerns are pushing teams to reconsider physically dedicated infrastructure.

[In 2026](https://www.archivemarketresearch.com/reports/bare-metal-server-provider-563723?tab=summary), bare metal hosting is no longer a niche choice. It is a strategic decision for businesses running AI workloads, large databases, regulated applications, and platforms where downtime or latency directly affect revenue or safety. The renewed interest is not about abandoning the cloud. It is about choosing the right foundation for the right workload.

## Why Organizations Are Returning to Bare Metal

The defining [advantage](https://www.ibm.com/think/topics/bare-metal-dedicated-servers) of bare metal is that one server belongs to one organization. There is no [hypervisor](https://www.vmware.com/topics/bare-metal-hypervisor) sharing resources, no competing workloads, and no uncertainty about performance. Every CPU cycle, memory allocation, and disk operation is predictable.

This matters most for workloads that fully consume hardware. [AI model training](https://acecloud.ai/blog/gpu-virtualization-vs-bare-metal/), real-time analytics, healthcare systems processing ePHI, [scientific research](https://www.latitude.sh/blog/how-bare-metal-servers-are-revolutionizing-scientific-research) and financial platforms making rapid decisions all depend on consistency. Even small fluctuations caused by shared environments can create real problems.

Security and compliance are equally important. Bare metal provides physical isolation, which reduces attack surfaces and simplifies risk management. For healthcare organizations, this is especially relevant. [ePHI](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/), or [electronic Protected Health Information](https://www.techtarget.com/searchhealthit/definition/electronic-protected-health-information-ePHI), must be protected through strict administrative, physical, and technical safeguards. Dedicated servers make it easier to control access, document processes, and meet audit expectations.

When combined with modern [encryption](https://www.atlantic.net/hipaa-compliant-hosting/encryption-for-hipaa-compliance/) for data in transit using TLS 1.2 or TLS 1.3, bare metal becomes a strong foundation for regulated workloads. Providers that support [HIPAA Business Associate Agreements](https://www.techtarget.com/healthtechsecurity/feature/What-Is-a-HIPAA-Business-Associate-Agreement-BAA) on first engagement and BAAs thereafter play a critical role in this ecosystem.

## How to Evaluate Bare Metal Hosting Providers

Not all bare metal hosting is the same. Hardware specifications matter, but they are only one part of the decision. [Data center](https://www.atlantic.net/hipaa-data-centers/) reliability, network design, operational support, and compliance expertise are just as important.

A strong provider offers transparency. You should know where your data resides, how physical access is controlled, and how incidents are handled. Support quality matters more than many teams expect. When infrastructure issues arise, the provider’s response can directly impact business continuity.

With those criteria in mind, the following list highlights some of the best bare metal hosting providers in 2026.

### Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

Atlantic.Net stands out as a bare metal hosting provider built for reliability, security, and regulated environments. We have spent decades supporting organizations that cannot afford uncertainty, especially in healthcare, finance, and enterprise [SaaS](https://www.atlantic.net/vps-hosting/what-is-saas-hosting/).

Our [bare metal servers](https://www.atlantic.net/dedicated-server-hosting/what-is-a-bare-metal-server-benefits-use-cases-and-best-practices/) are fully dedicated and hosted in U.S. based data centers with redundant power, cooling, and networking. We [offer](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) a range of hardware options, including high clock speed Intel Xeon processors and high core count AMD EPYC systems. This flexibility allows workloads to be matched precisely to application needs.

Security and compliance are a core part of our operation, not just add-ons. We support [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and work closely with healthcare organizations managing ePHI. We provide [HIPAA Business Associate Agreements](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) and design infrastructure that aligns with regulatory requirements.

Key features include:

- **Single-Tenant Servers:** Full hardware control and predictable performance without hypervisor overhead.
- **Compliance Support:** HIPAA-compliant infrastructure with support for BAAs and audit readiness.
- **Modern Encryption:** Full support for data in transit using TLS 1.2 and TLS 1.3.
- **Expert Support:** U.S.-based data centers with a focus on high uptime and direct technical assistance.

More details about our bare metal hosting approach can be found at [https://www.atlantic.net](https://www.atlantic.net/).

### Amazon Web Services Bare Metal Instances

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

AWS [offers](https://aws.amazon.com/about-aws/whats-new/2023/10/new-amazon-ec2-bare-metal-instances/) bare metal instances as part of its broader cloud ecosystem. These instances remove the hypervisor layer while maintaining integration with familiar AWS services.

This option is well suited for organizations already deeply invested in AWS tooling. Teams can deploy dedicated hardware while continuing to use existing security groups, identity management, and automation workflows.

Key features include:

- **EC2 Integration:** Bare metal access fully integrated into the existing EC2 environment.
- **Global Reach:** Access to massive global infrastructure and high-speed network backbones.
- **Tooling Compatibility:** Works seamlessly with existing AWS security and management tools.

AWS bare metal works best for teams that value ecosystem continuity over infrastructure simplicity.

### Microsoft Azure Bare Metal Infrastructure

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

Azure [provides](https://learn.microsoft.com/en-us/azure/baremetal-infrastructure/concepts-baremetal-infrastructure-overview) bare metal infrastructure primarily designed for enterprise workloads and large-scale applications. It is often used in scenarios where organizations need dedicated hardware but want centralized management.

The Azure platform allows teams to manage physical servers using the same dashboards and policies they already use for virtual resources. This reduces operational friction for enterprises standardizing on Microsoft technologies.

Key features include:

- **Unified Management:** Centralized control of physical and virtual assets through the Azure portal.
- **Identity Integration:** Deep integration with Microsoft Entra ID and enterprise security frameworks.
- **Enterprise Scaling:** Optimized for large-scale and legacy enterprise workloads that require dedicated cores.

Azure bare metal is a natural fit for organizations already aligned with Microsoft’s ecosystem.

### Google Cloud Bare Metal Solution

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

Google Cloud [offers](https://docs.cloud.google.com/bare-metal/docs) bare metal solutions designed to support performance intensive workloads and data heavy applications. Its strength lies in networking and integration with Google’s analytics and AI services.

This platform is commonly used for migrations from premises systems or for workloads that benefit from Google’s global network.

Key features include:

- **High-Speed Networking:** Performance backed by Google’s low-latency global infrastructure.
- **Analytics Integration:** Direct hooks into BigQuery and advanced data processing services.
- **Hybrid Support:** Architectures specifically designed for [hybrid-cloud](https://www.atlantic.net/gpu-server-hosting/scaling-ai-workloads-why-hybrid-cloud-infrastructure-is-the-future-of-enterprise-ai/) and migration-focused projects.

Google Cloud bare metal appeals to teams focused on data throughput and analytics performance.

**IBM Cloud Bare Metal Servers**

![](https://www.atlantic.net/wp-content/uploads/2025/06/ibm-logo.png)

[IBM Cloud Bare Metal](https://www.ibm.com/products/bare-metal-servers) Servers are designed for organizations that need enterprise grade performance and customization. IBM offers bare metal through two primary models. The classic infrastructure model allows deep customization at the hardware level, while the VPC based bare metal option emphasizes faster provisioning and tighter integration with modern cloud workflows. This makes IBM a common choice for organizations operating in hybrid environments.

Key features include:

- **Deployment Flexibility:** Choice between classic infrastructure and VPC-based bare metal workflows.

- **Specialized Hardware:** Support for modern infrastructure, including GPU options for compute-intensive AI workloads.

- **Enterprise Stability:** A global data center presence tailored for high-stability enterprise operations.

IBM Cloud Bare Metal Servers are best suited for large organizations that value stability and integration with broader enterprise systems. The platform offers depth and reliability for large scale workloads, even if it feels more complex than lightweight bare metal services.

**Looking Ahead in 2026**

Bare metal hosting in 2026 is defined by flexibility layered on top of physical control. Bare Metal as a Service models are making dedicated infrastructure easier to deploy and scale. GPU accelerated bare metal is becoming standard as AI workloads grow. Sustainability is also influencing provider choices, with more efficient hardware and energy practices gaining attention.

Despite these trends, the fundamentals remain the same. Bare metal succeeds when it delivers predictable performance, strong security, and dependable support.

**Choosing the Right Bare Metal Partner**

The right bare metal hosting provider depends on workload requirements, compliance obligations, and operational priorities. For regulated industries, experience matters. Providers that understand HIPAA-compliant hosting and can support BAAs reduce risk and operational burden.

Performance consistency, data location, and responsive support should weigh heavily in the decision. Bare metal is not just about hardware. It is about trust in the infrastructure that supports your most important systems.

In 2026, organizations that choose their bare metal partners carefully will gain not just performance, but confidence in the foundation of their digital operations.

 


---

# Top Equinix Metal Alternatives for Your Infrastructure Needs in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/equinix-metal-alternatives-2026/ | Published: 2026-01-19 | Updated: 2026-01-20 | Author: Dr. Assad Abbas

[Equinix Metal](https://www.equinix.com/) has long been a leading bare metal platform for organizations that need direct access to physical servers, predictable performance, and automated provisioning across global locations. However, Equinix has announced that the service will be phased out by [June 2026](https://docs.equinix.com/metal/?utm_source=copilot.com). Due to this planned phase-out, many enterprises have been prompted to explore alternative infrastructure solutions well in advance.

As this transition approaches, infrastructure planning now requires a more deliberate approach. Organizations need to look beyond selecting a replacement platform and consider how workloads will move and operate after the change. For this reason, performance consistency must be preserved, security controls need to be maintained, and compliance requirements must remain aligned throughout the process. These concerns directly connect to the phase-out timeline, particularly for regulated industries, where even minor gaps in planning can create operational or regulatory challenges.

The challenge is even bigger for organizations in highly regulated sectors. Healthcare providers, for example, manage [ePHI (electronic Protected Health Information)](https://www.atlantic.net/hipaa-compliant-hosting/protecting-phi-cloud/), which includes digital medical records, patient identifiers, and clinical data. Any infrastructure that hosts ePHI must meet strict HIPAA requirements and operate under a signed [HIPAA Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/). A BAA defines shared responsibility for protecting sensitive healthcare data and is mandatory for HIPAA-compliant hosting.

In this context, bare metal infrastructure serves as a reliable option. By providing direct access to physical servers, it eliminates virtualization overhead, which ensures predictable performance. Many organizations are looking for Equinix Metal alternatives that offer control, reliability, and compliance readiness well before the planned phase-out.

## Why Bare Metal Infrastructure Matters in 2026

Bare metal infrastructure is a primary choice for enterprises in 2026, particularly for those that require consistent performance, strong security, and reliable compliance. Since bare metal servers are dedicated to a single customer, the operating system runs directly on the hardware rather than on a shared hypervisor. This means organizations have complete control over their compute, memory, storage, and networking resources.

In contrast, virtualized environments share resources across multiple tenants. This can lead to unpredictable performance and delays, especially for workloads that demand high speed or precision. By removing these uncertainties, bare metal ensures consistent behavior, low latency, and predictable results for essential applications such as databases, AI training, and real-time systems.

Bare metal offers stronger security and easier compliance. Due to the servers being physically isolated, the attack surface is smaller, and network segmentation and access control are simpler to manage. Additionally, industries such as healthcare, finance, and SaaS often need infrastructure that can be audited and includes documented measures. By applying proper encryption and monitoring, organizations can use bare metal to meet regulatory requirements and keep sensitive data secure.

In addition, bare metal can be integrated with public cloud services in hybrid setups. This helps organizations maintain the performance of dedicated hardware while benefiting from the flexibility and global reach of the cloud. Therefore, companies evaluating Equinix Metal alternatives can maintain high performance and ensure compliance well before the planned phase-out.

## How the Equinix Metal Phase-Out Affects Modern Infrastructure

The planned phase-out of Equinix Metal has raised clear challenges for modern infrastructure planning. Equinix Metal combined automated bare metal provisioning with globally connected data centers. Therefore, organizations managed physical servers using cloud-style automation while maintaining direct hardware access. This approach supported workloads that required stable latency and consistent performance, such as databases, AI training, and real-time analytics. Consequently, the announced end of the platform by June 2026 demands that enterprises prepare for change well in advance.

At the same time, modern enterprises often use hybrid infrastructure models that combine dedicated servers and bare metal instances. Dedicated servers handle stable, long-term workloads that require consistent performance. In contrast, bare metal instances support tasks that require rapid provisioning and flexible automation. By combining dedicated servers with bare metal instances, organizations can maintain stability for core workloads while scaling dynamic workloads through cloud integration. This hybrid approach also brings additional security and compliance responsibilities. Because workloads run across both physical and cloud environments, data in transit must be secured using strong encryption standards, such as TLS 1.2 or TLS 1.3. Likewise, access controls, network segmentation, and monitoring should follow uniform policies across all systems. Following these practices helps ensure that performance-sensitive applications remain reliable and that regulated industries meet their compliance obligations.

When evaluating alternatives to Equinix Metal, organizations should prioritize platforms that provide automation, low-latency connectivity, secure cloud integration, and resilient security alignment. Providers that offer migration support and clear documentation can help reduce operational risk, ensuring workloads remain reliable and regulatory obligations are met throughout the transition.

## Top Equinix Metal Alternatives in 2026

The following platforms meet enterprise requirements for performance, security, and compliance, and can thus be good alternatives to Equinix.

### [Atlantic.Net](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) Bare Metal Hosting

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

As a long-established leader in secure and compliant hosting, we deliver bare metal infrastructure built for performance-intensive and regulated workloads. Our platform supports healthcare, finance, SaaS, and enterprise organizations that require strict security controls, predictable performance, and long-term reliability. Moreover, with a strong focus on compliance and hands-on support, we help clients deploy, scale, and protect mission-critical systems with confidence.

#### *Core Capabilities*

- We provide fully HIPAA-compliant environments designed to secure ePHI, supported by a signed BAA and comprehensive administrative, physical, and technical safeguards, ensuring that our clients’ sensitive healthcare data is protected at all levels.
- Our high-performance bare metal configurations are optimized for databases, AI workloads, analytics engines, and other compute-intensive applications, delivering consistent throughput and reliability for demanding workloads.
- We maintain network isolation, firewalls, intrusion detection, encrypted backups, and TLS 1.2/1.3 encryption to secure data transmission across all environments, keeping our clients’ systems safe and compliant.
- Our flexible architectures support hybrid cloud strategies, private networking, and multi-site deployments, helping organizations effectively plan and scale infrastructure according to evolving operational needs.
- Our clients have 24/7 direct access to experienced U.S.-based engineers who provide hands-on assistance, troubleshooting, and guidance for complex workloads, ensuring smooth operations and rapid support whenever needed.

### AWS Bare Metal

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

[AWS](https://aws.amazon.com/) offers bare metal instances through its EC2 portfolio, giving organizations direct access to physical hardware while benefiting from the extensive AWS ecosystem. These instances help teams manage workloads on dedicated servers while still using AWS tools for automation, monitoring, and orchestration. This combination makes AWS a strong choice for enterprises already invested in cloud-native frameworks and global infrastructure. Its bare metal options support high-performance workloads that require low latency, direct hardware control, and integration with other AWS services. Many organizations rely on AWS bare metal for compute-intensive tasks such as HPC, AI training, and large-scale analytics.

#### *Core Capabilities*

- AWS bare metal instances eliminate virtualization overhead and thus enable performance-sensitive workloads like HPC, analytics, and specialized databases to run at full capacity without interference.
- AWS provides native connectivity across networking, IAM, storage, and security services, enabling organizations to integrate bare metal servers into existing cloud architectures.
- AWS bare metal instances are suitable for regulated workloads when configured with proper controls, including encryption, monitoring, and the availability of BAAs for healthcare environments, ensuring compliance obligations are met.
- AWS offers extensive regional coverage, giving organizations low-latency access, geographic flexibility, and support for multi-region deployments and distributed applications.

### Google Cloud Bare Metal

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

Google Cloud provides bare metal solutions designed for data-intensive, analytics-driven, and enterprise workloads. These instances give organizations direct access to dedicated physical servers while also using Google Cloud’s ecosystem for networking, storage, orchestration, and security. The infrastructure is supported by Google’s high-performance global network, which makes it a strong choice for organizations that depend on large-scale data processing, machine learning, or latency-sensitive applications. In addition, Google Cloud bare metal works well with other Google services, so organizations can implement hybrid and multi-cloud strategies while maintaining predictable performance and low-latency connectivity across regions. For these reasons, enterprises often rely on Google Cloud bare metal for mission-critical applications where both performance and compliance are essential.

#### *Core Capabilities*

- Google Cloud bare metal servers are optimized for demanding workloads, such as large databases, analytics engines, and machine learning pipelines, ensuring consistent throughput and low latency.
- Google Cloud offers strong integration with VPC networking, Kubernetes services, and interconnect options, supporting hybrid and multi-cloud deployments across on-premises and cloud environments.
- Google Cloud provides access to its low-latency global backbone network, enabling organizations to achieve reliable performance for distributed workloads and international deployments.
- Google Cloud bare metal supports regulated workloads when configured correctly, with regions designed to meet compliance and data-residency requirements for industries such as healthcare and finance.

### Azure Bare Metal

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

[Microsoft Azure](https://learn.microsoft.com/en-us/azure/baremetal-infrastructure/concepts-baremetal-infrastructure-overview) offers dedicated hosts and bare metal-style solutions for enterprises that require strict workload isolation, governance, and integration with Microsoft’s ecosystem. These instances provide direct access to physical servers while using Azure’s cloud services, making them suitable for organizations that rely on Windows Server, Active Directory, and enterprise security tools. In addition, Azure bare metal works well with hybrid cloud strategies, so enterprises can manage workloads across on-premises and cloud environments while maintaining predictable performance and strong security. Many organizations choose Azure bare metal for critical applications where compliance, control, and stability are essential.

#### *Core Capabilities*

- Azure dedicated hosts provide predictable performance and strict isolation, making them suitable for workloads that are sensitive or require strong compliance.
- Azure integrates with Active Directory, Azure Security Center, and enterprise governance tools, enabling organizations to consistently manage identity, security, and compliance.
- Azure Arc and ExpressRoute support hybrid and multi-cloud setups, helping enterprises manage resources across on-premises and cloud environments without losing control.
- Azure provides a wide compliance portfolio and supports BAAs, making it a reliable choice for regulated industries such as healthcare, finance, and government.

### Rackspace Bare Metal

![](https://www.atlantic.net/wp-content/uploads/2025/12/rackspace_logo.png)

[Rackspace](https://www.rackspace.com/) focuses on managed hosting and hybrid cloud operations, offering bare-metal solutions for organizations that require hands-on operational support. Its services emphasize management, monitoring, and optimization, making it a strong choice for enterprises that prefer fully supported infrastructure over self-managed setups. By taking responsibility for operational tasks, Rackspace enables teams to focus on their core business goals rather than day-to-day server maintenance. In addition, Rackspace’s expertise in hybrid and multi-cloud environments enables organizations to integrate bare metal servers with existing cloud resources while maintaining reliable performance, consistent security, and simplified management.

#### *Core Capabilities*

- Rackspace offers managed bare metal services, providing support for provisioning, monitoring, patching, and server maintenance, helping reduce internal IT workload.
- Rackspace has deep experience integrating workloads across AWS, Azure, and Google Cloud, supporting flexible multi-cloud and hybrid strategies.
- The provider delivers security services, including managed firewalls, intrusion detection, monitoring, and compliance-aligned controls, helping organizations maintain a strong security posture.
- Rackspace provides 24/7 technical support, giving organizations guidance and troubleshooting assistance for mission-critical workloads whenever needed.

### Kamatera Bare Metal

[Kamatera](https://www.kamatera.com/) delivers customizable bare metal and cloud servers with rapid provisioning and global availability. Its platform supports organizations that need flexible hardware configurations, fast deployment, and cost-efficient scaling. This makes Kamatera appealing to development teams, startups, and global businesses that depend on speed and responsiveness. By offering direct access to physical servers together with cloud-style management tools, Kamatera helps teams deploy, test, and scale workloads quickly while maintaining predictable performance and operational control. In addition, its global data centers provide low-latency access and geographic redundancy, benefiting both local and distributed applications.

#### *Core Capabilities*

- Kamatera provides custom configurations, enabling organizations to adjust CPU, RAM, and storage to match specific workload requirements without unnecessary overhead.
- Servers can be provisioned in minutes, which supports rapid deployment, testing, and scaling for agile teams.
- Multiple global data centers provide low-latency access and geographic redundancy, helping distributed applications operate efficiently.
- Kamatera supports scalable infrastructure, with hardware configurations that can be modified with minimal disruption, supporting evolving workloads and long-term growth.

## A Decision Framework for Selecting an Equinix Metal Alternative

After reviewing the capabilities of providers like Atlantic.Net, AWS, Google Cloud, Azure, Rackspace, and Kamatera, it becomes clear that choosing the right Equinix Metal alternative requires careful consideration of multiple factors. Each provider offers different strengths, including global reach, automation depth, or managed services. Therefore, organizations must evaluate how those strengths align with workload demands, compliance obligations, and long-term infrastructure objectives.

Performance is often the first factor to assess, because compute-intensive workloads quickly expose infrastructure limitations. AI training, analytics pipelines, databases, and real-time systems depend on stable throughput and consistent latency. Although bare metal removes virtualization overhead, differences in hardware quality, provisioning speed, and regional availability still influence outcomes. For this reason, comparing how providers sustain performance under continuous load is more meaningful than reviewing specifications in isolation.

Security and compliance require equal attention. Regulated environments demand more than baseline protections. Providers must support HIPAA-compliant hosting, signed BAAs, strong encryption, defined access controls, and continuous monitoring across physical and hybrid deployments. Without these elements working together, migration introduces unnecessary legal and operational risk. Consequently, compliance readiness should be evaluated alongside performance rather than treated as a secondary concern.

Migration capability further affects the success of the transition. Moving away from Equinix Metal involves rebuilding network architectures, automation workflows, and governance controls. Providers that offer structured onboarding, testing support, and clear documentation help reduce disruption. As a result, organizations can maintain operational stability during the migration period.

Hybrid integration adds another dimension to the decision. Many enterprises rely on bare metal for core workloads while using cloud platforms for elasticity. Providers that offer low-latency connectivity and consistent management across environments help maintain control while supporting growth. Therefore, hybrid readiness directly influences long-term flexibility.

When these factors are considered together, organizations can make defensible infrastructure decisions. Atlantic.Net aligns well with enterprises that prioritize security, compliance, predictable performance, and direct engineering support. At the same time, AWS, Google Cloud, Azure, Rackspace, and Kamatera align with different operational priorities, such as ecosystem depth, managed services, or rapid deployment. The most suitable alternative emerges where technical capability, regulatory readiness, and operational fit converge.

**Table 1: Comparison of top alternatives to Equinix**

| **Provider** | **Performance & Hardware** | **Compliance & BAA Support** | **Hybrid Integration** | **Deployment Speed** | **Global Reach** | **Support & Services** |
| --- | --- | --- | --- | --- | --- | --- |
| **Atlantic.Net** | High-performance bare metal for compute-intensive workloads | HIPAA-compliant, signed BAA, regulatory safeguards | Hybrid cloud and private networking options | Custom setup with hands-on guidance | Multi-site deployments | 24/7 U.S.-based engineers, hands-on support |
| **AWS** | Bare metal EC2 instances for HPC, AI, analytics | BAA available for healthcare workloads, configurable security | Deep integration with the AWS ecosystem | Provisioning via AWS tools, rapid scaling | Extensive regional coverage | Standard AWS support tiers, global reach |
| **Google Cloud** | Optimized for databases, ML pipelines, analytics engines | Compliance-ready regions support BAA for ePHI | Integrates with VPC, Kubernetes, and interconnects | Moderate, with cloud management tools | Global low-latency backbone | Google Cloud support, monitoring options |
| **Azure** | Dedicated hosts with predictable performance | Broad compliance portfolio, BAAs supported | Hybrid support via Azure Arc, ExpressRoute | Configurable with Azure management | Global cloud regions | Enterprise support plans, governance tools |
| **Rackspace** | Managed bare metal with operational optimization | Compliance-aligned controls, monitoring | Multi-cloud and hybrid integration expertise | Managed provisioning, patching, and monitoring | Cloud-agnostic reach | 24/7 technical support, hands-on guidance |
| **Kamatera** | Customizable CPU, RAM, storage for workloads | Supports standard compliance measures | Hybrid-friendly with cloud-style tools | Rapid provisioning in minutes | Multiple global data centers | Flexible support options, operational guidance |

## The Bottom Line

The Equinix Metal phase-out can be a turning point for enterprises that rely on bare metal infrastructure. With 2026 already underway, organizations face immediate pressure to reassess how performance, security, and compliance fit into long-term infrastructure planning. In this context, bare metal remains a reliable foundation because it delivers predictable performance and direct control over physical resources.

At the same time, this transition requires careful evaluation of alternative providers. By examining automation capabilities, regional coverage, compliance readiness, and migration support, enterprises can reduce operational risk. Consequently, platforms such as Atlantic.Net, AWS, Google Cloud, Azure, Rackspace, and Kamatera help organizations maintain continuity while supporting infrastructure strategies beyond Equinix Metal.


---

# Pharma Cloud Computing: Why Do Biotech and Pharma Need So Much Computing Power in the Cloud?

> URL: https://www.atlantic.net/life-sciences-pharma-biotech/biotech-pharma-need-much-computing-power-cloud/ | Published: 2026-01-21 | Author: Richard Bailey

The pharmaceutical industry operates under unique pressures. Bringing a single drug to market can take over a decade and cost billions of dollars, with a high failure rate that makes efficiency a financial necessity. Historically, pharmaceutical companies and biotech firms slowed their uptake of new technologies due to strict regulatory oversight and concerns regarding intellectual property security.

Organizations now recognize that legacy systems cannot handle the current volume of biological data. To reduce costs, streamline workloads, and support global collaboration, the industry is moving toward pharma cloud computing. The life sciences industry and pharma industry are both experiencing significant transformation as cloud computing technologies drive improvements in efficiency, safety, and innovation across research, development, and operations.

Modern cloud technology offers the infrastructure required to process vast amounts of sensitive information. The shift to cloud based infrastructure provides scalability, remote data access, and operational efficiency, supporting the changing needs of the industry. By optimizing data sharing and enabling advanced computational modeling, cloud services facilitate the research necessary for medical breakthroughs.

The adoption of cloud services is accelerating, with the pharmaceutical industry projected to see significant growth in cloud computing adoption, reaching an [estimated USD 59.0 billion by 2032](https://www.startus-insights.com/innovators-guide/pharma-4-0-strategic-guide/#:~:text=Economic%20Impact%3A%20According%20to%20Straits,Technologies%20Connected%20to%20Advanced%20Computing). We will examine how cloud-based solutions drive digital transformation, expedite drug discovery, and secure clinical trial data. Major cloud providers such as Atlantic.Net, AWS, Google Cloud, and Microsoft Azure are increasingly being adopted by pharmaceutical companies to enhance their operations.

## Introduction to Cloud Technology

Cloud technology has fundamentally changed the landscape of the pharmaceutical industry, offering pharma companies a powerful way to manage and leverage their most valuable asset: data. Cloud computing enables organizations to use remote servers accessed via the internet to store, process, and analyze vast amounts of information. This shift from traditional in-house servers to cloud services has allowed pharmaceutical companies to streamline drug development, enhance the management of clinical trial data, and ensure robust data security.

By adopting cloud technology, the pharmaceutical industry can quickly scale its infrastructure to meet the demands of modern research and development. Cloud services support everything from trial data collection to regulatory compliance, providing a flexible and cost-effective alternative to legacy systems. With industry cloud solutions, pharma companies can collaborate more efficiently, access real-time data, and accelerate the pace of innovation. As a result, cloud computing has become an essential tool for managing the complex workflows and sensitive information that define the pharmaceutical sector.

## Data Analytics and the Explosion in Life Sciences

Biotechnology and pharmaceutical research generate data at a rate that outpaces traditional on-premise storage capabilities. Core disciplines such as genomics and proteomics produce massive datasets that demand significant computational horsepower for management, processing, and analysis.

[The Human Genome Project](https://www.genome.gov/human-genome-project) (HGP) serves as a primary example of this computational need. The project took nearly 13 years and cost approximately $3 billion to complete. Sequencing the human genome laid the foundation for thousands of scientific studies and identified the genetic causes of multiple diseases. When the HGP finished in 2003, the computational performance of available technology was far inferior to today’s infrastructure.

Current technological advances allow for Next-Generation Sequencing (NGS), which outputs approximately 15,000 times more data per day than the traditional [Sanger Sequencing](https://microbenotes.com/sanger-sequencing/) methods used during the HGP. Pharmaceutical companies cannot manage this influx of information with in-house servers alone. Research and development departments must adopt data analytics technology that processes these big data sets quickly to identify actionable insights. Cloud computing provides the elasticity to handle these spikes in data generation without requiring capital investment in physical hardware that may sit idle during low-activity periods. Data scientists play a crucial role in leveraging cloud-based platforms to analyze these large datasets and accelerate research in the pharmaceutical industry.

## Accelerating Drug Discovery and Drug Development

Time is a critical factor in pharmaceutical operations. With the average drug development cycle spanning 10 years and costing in [excess of $2.3 billion](https://www.phrma.org/policy-issues/research-development#:~:text=On%20average%2C%20it%20takes%2010,Drug%20Administration%20(FDA)%20approval.), increasing speed and efficiency is mandatory. Cost efficiency is also a key benefit of cloud computing in drug development, as it helps optimize operations and control costs. Only one in every 5,000 discovered compounds typically makes it to market, meaning companies must fail fast and pivot quickly to remain viable.

Pharmaceutical companies report an average of a 30% reduction in IT operational costs after adopting cloud services. Cloud computing accelerates this timeline. High-performance computing (HPC) environments in the cloud allow researchers to perform complex analyses and modeling of large datasets, including using artificial intelligence (AI) and machine learning (ML) to identify key drug targets and predict molecule behavior before physical testing begins.

The impact of cloud technology was evident during the global COVID-19 pandemic. The rapid development of vaccines and anti-viral medications relied heavily on cloud-based AI algorithms.

- [Pfizer partnered with AWS](https://www.pfizer.com/news/articles/how_a_novel_incubation_sandbox_helped_speed_up_data_analysis_in_pfizer_s_covid_19_vaccine_trial) to use scalable computing resources for processing and analyzing large datasets efficiently.
- [AstraZeneca used cloud solutions](https://aws.amazon.com/solutions/case-studies/astrazeneca-case-study/) to accelerate drug research and development, conducting 51 billion statistical tests in less than 24 hours.
- [Moderna utilized cloud-based](https://aws.amazon.com/solutions/case-studies/moderna-case-study/) methods to deliver the first clinical batch of its COVID-19 vaccine only 42 days after the initial sequencing of the virus.
- [Bayer collaborates with Google Cloud](https://www.bayer.com/media/en-us/bayer-to-accelerate-drug-discovery-with-google-clouds-high-performance-compute-power/) to run quantum chemistry simulations, speeding up drug discovery processes.
- [UCB’s collaboration with Microsoft](https://www.ucb.com/newsroom/press-releases/article/ucb-and-microsoft-expand-collaboration-to-accelerate-drug-discovery-and-development) has enhanced its drug development processes through cloud solutions.

Companies like Pfizer utilized distributed computer networks to manage production at every stage, from design to manufacture and delivery. This scale of operation required always-available cloud resources that could function across decentralized locations. By offloading data-intense workloads to the cloud, researchers performed tasks that were previously impossible, identifying viable vaccine candidates in record time.Such collaborations with major cloud providers are becoming standard practice in the pharmaceutical industry.

## Streamlining Clinical Trial Data with Cloud Technology

Clinical trials represent a significant portion of the drug development timeline and budget. The sector is predicted to see continued growth, increasing the demand for efficient data management. Cloud computing supports this growth by modernizing how clinical trial data is collected, stored, and analyzed. In addition, cloud computing plays a crucial role in clinical development and clinical research by integrating trial data, improving patient recruitment, ensuring regulatory compliance, and applying AI for safety monitoring and biomarker discovery.

Traditional clinical trials often suffer from geographic limitations. Cloud platforms provide a global infrastructure that supports decentralized trials, allowing patient recruitment and data collection from diverse locations. Researchers can access real-time monitoring tools and patient records from anywhere in the world, reducing the need for physical site visits. Real time access to trial data enables researchers to make faster decisions and allows regulatory bodies to monitor compliance more effectively.

Connectivity improves collaboration between pharmaceutical organizations, Contract Research Organizations (CROs), and academic institutions. A cloud platform offers on-demand connectivity, enabling researchers to share information and data with peers globally on a 24/7 basis. This eliminates transfer delays and allows geographically disparate teams to work on the same datasets simultaneously. The use of electronic health records (EHRs) in cloud-based clinical research further enhances data collection and analysis, streamlining clinical trial processes and improving patient engagement.

Modern clinical trials also utilize wearable devices and mobile apps to collect patient data. An Internet of Things (IoT) approach generates a continuous stream of information that must be processed immediately. Cloud-based platforms ingest this data in real time, allowing for faster detection of adverse events and quicker adjustments to trial protocols. This capability improves patient safety and ensures the integrity of clinical trial results. Secure storage of data from wearables and EHRs in the cloud is essential to maintain data integrity and privacy.

Utilizing cloud technology in clinical trials has been shown to [increase patient enrollment rates by up to 20% and reduce dropout rates by as much as 15%](https://avahi.ai/blog/cloud-computing-in-the-pharmaceutical-industry/). Cloud computing has enabled decentralized clinical trials, allowing patients to report their health status from home, which has decreased dropout rates significantly. By enabling more targeted and efficient recruitment strategies, cloud computing improves patient recruitment and retention in clinical trials. Cloud computing also improves compliance with regulations by allowing real-time monitoring and data access for regulatory bodies.

Cloud computing enhances transparency in the pharmaceutical supply chain by enabling drug manufacturers to trace every component back to its origin. Integration with IoT and blockchain in the supply chain allows for 100% traceability and real-time monitoring of conditions such as temperature and humidity, ensuring product quality and safety throughout the distribution process.

## Driving Digital Transformation in Pharma

The pharmaceutical industry is undergoing a major shift known as digital transformation. An evolution moves business processes away from paper-based records and legacy systems toward integrated digital workflows. The global pandemic fast-tracked this change, forcing companies to adapt to remote work and digital collaboration tools.

Cloud adoption is the engine behind this transformation. Scalability and agility allow companies to compete in a saturated global market. By processing ever-increasing amounts of data at speed, cloud computing streamlines research processes and expedites access to data-driven insights. Many companies now rely on cloud infrastructure to automate and standardize daily research tasks, reducing human error and freeing up scientists to focus on high-value analysis.

Digital transformation also impacts the supply chain. Cloud systems track production lines and inventory levels in real time, ensuring that critical medications reach distributors and patients without delay. Having visibility is essential for maintaining the cold chain requirements of biologics and vaccines.

## Improving Outcomes with Cloud Solutions

Pharmaceutical companies are increasingly focusing on patient-centric services. Digital technology and the development of personalized therapies place patients in control of their health. Cloud solutions allow companies to process data related to individual patient genetics and history, leading to more targeted treatments.

Image recognition and advanced analytics process medical imaging data to track disease progression with greater accuracy than the human eye alone. These tools improve diagnostic precision and help physicians tailor treatment plans. By analyzing patient outcomes across broad populations, pharmaceutical companies can refine their products and demonstrate value to payers and healthcare providers.

## Secure Data Storage and Management

Data is the most valuable asset for a pharmaceutical company. Intellectual property, including proprietary formulas and trial results, must be protected against theft and loss. The way data stored in the cloud is organized, accessed, and managed is crucial for operational efficiency, regulatory compliance, and enabling advanced analytics in pharma.

Cloud providers offer enterprise-grade security measures that often exceed what companies can achieve with on-premise data centers. However, data sovereignty issues can arise when data is stored outside the company’s home country, presenting legal and regulatory challenges that must be addressed to maintain compliance and trust with cloud providers.

Cloud storage solutions employ strong encryption protocols for data at rest and in transit, ensuring that sensitive information remains unreadable to unauthorized users even if intercepted. Access controls allow administrators to define granular permissions, ensuring that only authorized personnel can view or modify specific files. This follows the principle of least privilege, a core tenet of data security.

Biotech and pharma companies must trust that their IT infrastructure is fail-safe. High availability is achieved through redundancy. Cloud providers utilize dual power feeds, high-availability compute nodes, and redundant network stacks. Failsafe storage clusters can absorb numerous disk failures and hardware issues without data loss.

Backup and disaster recovery are critical components of this strategy. A strong backup plan includes daily recovery points and data replication services. Using a technology that creates a 1:1 copy of all data at a primary site and copies it to a secondary site. In the event of a natural disaster or cyberattack, the secondary site can be activated, ensuring business continuity.

## High Performance Cloud Computing

Innovation in biotechnology requires computing power capable of identifying scientific insights within terabytes of research data. Scalable cloud-based solutions often embedded with AI provide the resources needed to analyze this crucial data effectively. In the pharma industry, both public cloud and hybrid cloud deployment models are increasingly relevant, as public cloud offers rapid scalability for digital tools like LIMS systems, while hybrid cloud enables organizations to balance data security and regulatory requirements by integrating on-premise infrastructure with cloud services.

Resources in the cloud can be scaled up (vertical scaling) or out (horizontal scaling) to meet compute demands. Users can deploy compute-optimized, memory-optimized, and storage-optimized cloud nodes based on the specific workload. For example, creating a Hadoop cluster allows for the processing of massive datasets. In this practice, data is written to an external cloud storage account, and the nodes can be added or deleted as needed. Having this flexibility ensures that pharmaceutical companies only pay for the resources they use, rather than maintaining expensive hardware for peak loads that rarely occur.

## Cloud Adoption Strategies for Compliance

In the United States, the Food and Drug Administration (FDA), the Environmental Protection Agency (EPA), and the USDA’s Animal and Plant Health Inspection Service (APHIS) enforce strict guidelines. Additionally, companies must adhere to HIPAA (Health Insurance Portability and Accountability Act) and HITECH (Health Information Technology for Economic and Clinical Health Act) regulations when handling patient records.

Adopting cloud services does not mean relinquishing control over compliance. Instead, it involves selecting a managed service provider that understands these requirements. HIPAA-compliant hosting providers implement specific physical and digital security measures, including biometric access controls to data centers, documented chain-of-custody procedures, and rigorous audit logs.

The FDA itself relies on cloud services, setting a precedent for the industry. Cloud providers work closely with pharmaceutical customers to execute Business Associate Agreements (BAAs), which legally bind the provider to adhere to HIPAA regulations. This partnership ensures that the infrastructure supports the company’s compliance posture rather than hindering it.

## Overcoming Barriers

Despite the clear benefits, some pharmaceutical organizations remain hesitant to fully embrace the cloud. Concerns often center on data sovereignty, potential security risks, and the difficulty of migrating legacy systems.

Data sovereignty refers to laws governing where data is stored. Some nations require that health data concerning their citizens remain within physical national borders. Global cloud providers offer data centers in multiple regions, allowing companies to store data in specific geographic locations to satisfy these legal requirements.

Moving from legacy, on-premise systems to the cloud is a complex process. It requires careful planning to ensure data integrity during the transfer. A “lift and shift” approach moves applications to the cloud with minimal changes, while re-platforming involves optimizing applications for the cloud environment. Managed service providers assist in this transition, offering migration services that minimize downtime and operational disruption.

Security concerns are valid, as rogue nations and hacking groups target pharmaceutical researchers. Sensitive vaccine data is worth billions. To mitigate this, cloud environments utilize Multi-Factor Authentication (MFA) across the infrastructure. Managed firewalls block unwanted network traffic, and Intrusion Detection Systems (IDS) proactively scan for anomalies and unexpected behavior. Logs are saved directly to a monitored Security Information and Event Management (SIEM) platform, providing real-time visibility into potential threats.

The ability to harness vast amounts of computing power, collaborate globally, and analyze data with AI tools defines the future of drug development. As the industry continues to move away from traditional methods, the cloud provides the foundation for faster innovation cycles and improved patient care.

## Future of Cloud Computing in Pharma

Looking ahead, the future of cloud computing in the pharmaceutical industry is set to be shaped by emerging technologies like artificial intelligence (AI) and machine learning (ML). Cloud based platforms will empower pharmaceutical companies to analyze unprecedented volumes of data, uncovering patterns and generating data driven insights that can revolutionize drug development and clinical trials.

The integration of AI and ML with cloud technology will enable more efficient decentralized trials, making patient recruitment and retention easier and more effective. These advancements will also enhance supply chain management, reduce operational costs, and strengthen regulatory compliance across the industry. As digital transformation accelerates, cloud computing will remain at the heart of the pharmaceutical industry’s evolution, supporting everything from advanced analytics to real-time monitoring of clinical data.

By embracing cloud based solutions and staying at the forefront of emerging technologies, pharmaceutical companies can continue to innovate, improve patient outcomes, and maintain a competitive edge in a rapidly changing global market.

## Conclusion

To ensure successful cloud adoption, pharma organizations should prioritize data security and regulatory compliance, working closely with [trusted cloud providers](https://www.atlantic.net/life-sciences-pharma-biotech/) to safeguard sensitive information. Investing in emerging technologies such as artificial intelligence and machine learning will further enhance data management and unlock new possibilities for research and development. Collaboration across teams and with technology partners is essential to maximize the benefits of cloud technology.

As the pharmaceutical industry continues to evolve, staying up-to-date with the latest cloud computing trends and technologies will be crucial for maintaining competitiveness in the global market. By using the power of cloud computing, pharmaceutical companies can accelerate their digital transformation, deliver better patient outcomes, and shape the future of life sciences.


---

# GPU Dedicated Server Hosting: A Buyer’s Guide

> URL: https://www.atlantic.net/gpu-server-hosting/gpu-dedicated-server-hosting-a-buyers-guide/ | Published: 2026-01-22 | Author: Richard Bailey

## What Is GPU Dedicated Server Hosting?

GPU [dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/) involves servers equipped with graphics processing units (GPUs) to handle demanding computational tasks. Unlike traditional servers that rely heavily on central processing units (CPUs), GPU servers manage parallel processing workloads efficiently. These servers are beneficial for applications requiring high computational power like rendering, machine learning, and scientific simulations.

The integration of GPUs in dedicated servers offers significant advantages in processing complex tasks rapidly. By leveraging the parallel computing ability of GPUs, these servers enhance performance and manage intensive applications. This type of hosting is becoming increasingly popular in industries that require extensive data processing capabilities.

## Benefits of GPU Dedicated Servers

Opting for GPU dedicated servers offers a range of benefits for handling resource-intensive applications and high-volume data processing. Key advantages include:

- **Enhanced processing speed:** GPU servers perform complex calculations much faster than CPU-based servers by leveraging parallel processing. This speed is crucial for applications in AI, scientific research, and media production, where tasks involve vast data sets and require rapid computation.
- **Scalability for high-demand applications:** GPU servers can scale efficiently to meet the demands of computationally heavy workloads. This scalability supports applications that grow in complexity, such as large machine learning models or real-time analytics, enabling them to handle more extensive and demanding datasets over time.
- **Efficient resource utilization:** By offloading specific tasks to the GPU, applications can use server resources more efficiently, freeing up the CPU for other processing tasks. This efficiency optimizes performance across applications, enhancing overall server responsiveness.
- **Reduced processing time for data-intensive workloads:** GPU servers accelerate tasks that traditionally require long processing times, such as rendering, simulation, and model training. This reduction in time helps organizations deliver results faster, boosting productivity in workflows dependent on high-speed computation.
- **Support for modern software frameworks:** GPU servers are compatible with leading software frameworks like CUDA, TensorFlow, and PyTorch, which are optimized for GPU acceleration. This support enables developers and researchers to leverage cutting-edge libraries for advanced analytics and AI model development.
- **Improved data processing in real time:** GPU servers handle real-time data processing effectively, making them ideal for applications that require instant results, such as video processing, virtual reality, and streaming. Real-time capabilities allow businesses to deliver enhanced user experiences in dynamic environments.

## How GPU Dedicated Servers Work

### GPU Architecture and Functionality

A GPU server is a high-performance machine equipped with one or more graphics processing units designed for parallel processing. While a CPU handles sequential tasks with a few powerful cores, a dedicated GPU utilizes thousands of smaller cores to perform many calculations simultaneously.

Together, this architecture is the foundation of massive parallel computing power. Each GPU contains specialized components that facilitate rapid data movement and processing. Two essential components are Video RAM (VRAM) and the framebuffer. VRAM provides high-speed storage for the data the GPU is currently processing, while the framebuffer stores completed images or data outputs before they are delivered to the system or user. For tasks like graphics rendering and virtual desktop infrastructure, these components ensure smooth performance and low latency.

### GPU Dedicated Server vs. Traditional CPU Hosting

The primary difference between a GPU server and a standard dedicated server lies in how they handle instructions. Standard CPUs are designed for versatility and sequential logic. They manage the operating systems and general application code effectively. However, when an application requires the same mathematical operation to be performed across millions of data points, a CPU becomes a bottleneck.

Dedicated GPU servers address this by using parallel processing capabilities. By breaking large problems into smaller, identical pieces, the system solves them at once. This approach provides a significant leap in performance for AI workloads and scientific simulations. Using a professional GPU dedicated server allows engineers to finish jobs in hours that might take weeks on a CPU-only system.

### Modern GPU Architectures and CUDA Cores

Predominantly, GPU performance is tied to the development of specific NVIDIA architectures. When selecting a GPU dedicated server, understanding these generations is necessary for matching hardware to the specific workload.

- **Hopper CUDA Cores**: Found in the H100 series, these are designed specifically for large language models and advanced AI training. They provide extreme memory bandwidth and are the current standard for enterprise-level AI models.
- **Ada Lovelace CUDA Cores**: These power the RTX 40-series and L40S GPUs. They excel in graphics rendering, video processing, and generative AI, offering a balance of high performance and productivity.
- **Ampere CUDA Cores**: Used in the A100 and RTX 30-series, this architecture introduced significant improvements in sparse matrix multiplication, accelerating machine learning training.
- **Turing CUDA Cores**: This generation introduced RT cores for real-time ray tracing and Tensor cores for AI acceleration, making them ideal for professional GPU Cloud server environments and video rendering.
- **Volta CUDA Cores**: The V100 was the first to feature Tensor cores specifically for deep learning, setting the stage for modern AI research.
- **Pascal CUDA Cores**: Older but still effective for Lite GPU dedicated server needs, the Pascal architecture (P100) provided a major jump in double-precision performance for high performance computing.
- **Kepler CUDA Cores**: While considered legacy, Kepler architecture established the groundwork for using GPUs in the data center for scientific research.
- **Blackwell CUDA Cores**: The newest generation available in 2026 designed for trillion-parameter AI models, offering the highest density of computing resources for the most demanding tasks.

## Use Cases for GPU Dedicated Servers

### Machine Learning and AI Applications

Machine learning is one of the most common applications for GPU hosting. The process of training deep learning models involves presenting a model with vast datasets and adjusting internal parameters until it can make accurate predictions. It requires substantial mathematical calculations that only high performance GPU servers can handle effectively.

There are three primary training methods utilized in these environments:

- **Supervised Learning**: An operator provides the model with labeled datasets. The model learns to map inputs to specific outputs based on these examples. We often see this standard for image recognition and natural language processing.
- **Unsupervised Learning**: The model analyzes raw data to find hidden patterns or structures without human intervention. Its commonly used for customer segmentation and fraud detection.
- **Reinforcement Learning**: The model learns through a system of rewards and penalties, often used in robotics and autonomous systems.

A multi-GPU dedicated server is often required for these AI models to reduce the time needed for fine-tuning and inference. By utilizing multiple GPUs, researchers can distribute the workload, accelerating the research cycle.

### Natural Language Processing and Data Analytics

Natural language processing (NLP) involves training models to understand and generate human language. This process requires analyzing millions of parameters and relationships between words. Using a GPU instance with high GPU memory is essential for loading these large models and processing text in real time.

Data processing at scale also benefits from GPU resources. High performance data analytics tools use parallel processing to scan billions of records for trends. In sectors like finance and healthcare, the ability to process data instantly allows for faster decision-making and better diagnostic tools. Renting GPU servers allows organizations to handle these data-intensive tasks without the need for massive capital expenditure.

### High Performance Computing and Scientific Research

High performance computing (HPC) involves using clusters of servers to solve complex mathematical problems. HPC workloads often include fluid dynamics, molecular modeling, and climate simulations. These tasks rely heavily on floating-point mathematics, where GPUs offer a distinct advantage over CPUs.

Scientific research requires consistent performance and reliability. A dedicated GPU server ensures that the hardware is not shared with other users, preventing resource contention during long-running simulations. Organizations often utilize bare metal GPU servers to gain direct access to the hardware, allowing for deeper optimization of software frameworks like CUDA, TensorFlow, and PyTorch.

### Video Rendering and Transcoding

GPU dedicated servers significantly enhance video rendering and transcoding processes. These tasks require substantial computational resources to manage the conversion and compression of video files quickly and efficiently. With their parallel processing capabilities, GPUs speed up rendering times, enabling content creators to produce high-quality videos with reduced turnaround.

In transcoding, GPU servers offer superior performance by handling multiple video streams concurrently. This capability is vital for streaming services and media companies that need to process and deliver content across various platforms and formats. By reducing processing times and improving output quality, GPU servers optimize the video production pipeline.

### Virtual Desktop Infrastructure and Graphics Rendering

Virtual desktop infrastructure (VDI) allows businesses to host desktop environments on a central server. For users running graphics-intensive applications like CAD or 3D modeling software, a GPU dedicated server is required. By offloading the graphics processing to the server, the end-user experiences a responsive interface regardless of their local hardware.

Video rendering and video processing also demand high performance. Professionals in the film and gaming industries use GPU server rental services to render high-resolution frames. Using a server equipped with Turing or Ada Lovelace CUDA cores allows for real-time ray tracing and faster export times, increasing overall productivity.

### Gaming and Virtual Reality

GPU dedicated servers play a crucial role in gaming and virtual reality (VR) applications, which demand high computational throughput for realistic graphics rendering and immersive experiences. By offloading processing tasks from local machines to powerful GPU servers, users benefit from enhanced graphics quality and reduced latency, resulting in smoother gameplay and more engaging VR experiences.

In gaming, GPU servers support cloud gaming platforms, allowing players to access high-quality games without needing high-end hardware. Similarly, in VR, GPU servers manage complex calculations required for immersive environments, ensuring seamless graphics rendering and interactivity. Leveraging GPU server capabilities in these domains empowers developers to create visually stunning, responsive experiences.

## Comparing GPU Dedicated Servers to Other Server Types

### GPU Servers vs. CPU Servers

GPU servers offer distinct advantages over traditional CPU servers, particularly where parallel processing is required. While CPUs excel in single-threaded tasks and general-purpose computing, GPUs are optimized for handling multiple operations simultaneously. This makes them ideal for applications such as AI, scientific simulations, and rendering, where vast computational resources are needed to process data efficiently.

CPU servers are better suited for tasks requiring high-frequency, sequential processing. Furthermore, deploying GPU servers can significantly reduce the time needed for completing parallel tasks. Despite being more expensive initially, the performance gains of GPU servers often justify the investment, especially in fields where speed and efficiency are critical.

### GPU Servers vs. Cloud GPU Instances

GPU servers and cloud GPU instances present different benefits and trade-offs. Dedicated GPU servers offer consistent performance and control, which is essential for enterprise applications with specific compliance or security requirements. They provide guaranteed availability of computing resources, ensuring performance remains steady despite fluctuating demand.

On the other hand, cloud GPU instances offer flexibility and scalability, allowing businesses to scale resources up or down based on workload requirements. Although cloud solutions reduce upfront costs, expenses can add up over time with sustained use. Ultimately, the choice between GPU servers and cloud instances depends on factors such as cost considerations, control needs, and the nature of workloads being processed.

## Best Practices for GPU Dedicated Server Hosting

### Resource Allocation and Load Balancing

Effective resource allocation and load balancing are critical to maximizing GPU utilization and maintaining steady performance. By segmenting workloads across multiple GPUs or servers, businesses can avoid bottlenecks and ensure even distribution of tasks, reducing the risk of overloading any single GPU. Implementing load-balancing software or frameworks helps dynamically allocate resources based on demand, optimizing processing efficiency and preventing downtime during peak usage.

It’s also essential to regularly evaluate workload distribution and adjust configurations as necessary. As workloads evolve, fine-tuning resource allocation helps maintain optimal performance, ensuring GPU resources are neither underutilized nor overstressed.

### Data Backup and Disaster Recovery Planning

Establishing a comprehensive data backup and disaster recovery plan is essential for GPU dedicated server environments, where data integrity and availability are critical. Regularly backing up data to secure locations protects against data loss from hardware failures or cyber incidents. Using automated backup solutions ensures that data is consistently saved without requiring manual intervention.

A disaster recovery plan should include predefined protocols for data restoration and continuity of services. This plan enables quick recovery of operations in the event of an outage, minimizing downtime and maintaining service reliability. Regular testing of backup and recovery processes ensures readiness and effectiveness in real-world scenarios.

### Regular Updates and Patching

Keeping GPU dedicated servers up to date with the latest software and security patches is critical for smooth operation and defense against vulnerabilities. Regularly updating operating systems, drivers, and server applications enhances system performance and reliability. It also addresses known security issues, helping to protect against potential exploits and threats.

Timely patching requires efficient management practices, including setting up automation where possible to streamline the update process. Scheduling updates during maintenance windows minimizes disruption to operations. By ensuring servers are continuously updated, businesses can maintain optimal performance and secure their infrastructure against evolving cyber threats.

### Performance Monitoring and Optimization

Continual performance monitoring and optimization are necessary to maintain and improve GPU dedicated servers’ efficiency. By utilizing monitoring tools, businesses can track key performance metrics such as GPU utilization, memory usage, and network throughput, identifying areas for improvement. This data-driven approach enables timely adjustments to configurations and settings for enhanced performance.

Optimization involves tweaking server resources to better match workload demands. Adjusting parameters such as GPU clock speeds, memory allocation, and power settings can balance performance and energy consumption. Regularly reviewing resource usage statistics and reconfiguring settings helps ensure that the server operates at peak efficiency.

### GPU Rental Benefits: CapEx vs. OpEx

Purchasing high-end GPU hardware is a significant investment. A single enterprise-grade GPU can cost thousands of dollars, and maintaining a data center adds costs for power, cooling, and security. GPU rental allows businesses to convert these large capital expenses into predictable monthly operating expenses.

By using GPU server hosting, organizations gain access to the latest hardware without the risk of their investment becoming obsolete . When a newer generation like Blackwell becomes available, users can migrate their workloads to the new hosting environments without having to sell or decommission old physical assets.

### Scalability and Hosting Environments

Scaling a GPU infrastructure on-premises is slow and expensive. In contrast, cloud-based GPU [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/) offers flexibility. A business can start with a Lite GPU dedicated server for development and then scale up to a multi-GPU dedicated server for production or large-scale AI training.

Managed servers also reduce the burden on internal IT teams. Top hosting providers offer server management, backups, and technical support as part of their service. Allowing developers to focus on building AI models and applications rather than managing hardware health and network connectivity.

### Operating Systems and Software Integration

Most GPU servers run on Linux or Windows Server operating systems. Linux is preferred for machine learning training because of its compatibility with open-source software frameworks. Popular libraries like TensorFlow and PyTorch are optimized for Linux and provide direct integration with NVIDIA GPUs via the CUDA toolkit.

Windows Server is commonly used for VDI and certain graphics rendering applications. When selecting a provider, ensure they offer pre-configured server templates for your chosen OS. This speeds up deployment and ensures that the necessary drivers and pre-installed software are correctly configured for the hardware.

### Networking and Bandwidth Requirements

High performance GPU instances require a stable network infrastructure. Moving large datasets for AI training or streaming high-resolution video requires unmetered bandwidth and low-latency connections.

Professional GPU dedicated server providers typically offer:

- **High-speed ports (10 Gbps or higher)**
- **Multiple internet backbone connections**
- **Built-in DDoS protection**
- **Global data center locations for low-latency access**

Reliability is backed by a Service Level Agreement (SLA). Look for providers that offer a 100% uptime guarantee for both the network and the hardware. This is essential for applications that require 24/7 availability, such as real-time inference or global VDI deployments.

### Security and Compliance in GPU Hosting

Organizations in regulated industries like healthcare and finance must prioritize security. Dedicated GPU hosting provides physical data isolation, which is a requirement for HIPAA-compliant, PCI DSS, and SOC 2 hosting. Unlike virtualized cloud instances, a dedicated server ensures that your data never sits on the same physical storage or memory as another customer. When discussing data in transit, we ensure that all connections utilize TLS 1.2 or 1.3 to maintain high encryption standards.

Security measures should include:

- **Multi-factor authentication (MFA)**
- **Encrypted onsite and offsite backups**
- **Managed firewalls and intrusion detection**
- **Physical security at the data center location**

Professional technical support is another layer of security. Having 24/7 access to experts who understand GPU-intensive applications ensures that any hardware or software issues are resolved before they impact business operations. For healthcare clients, we formalize this partnership through the HIPAA Business Associate Agreement (BAA).

## Selecting a GPU Dedicated Server Provider

When evaluating hosting providers, look beyond the price of the GPU rental. Consider the total value provided by the infrastructure and support team.

**Key criteria for selection:**

- **Hardware Selection & Customization**: Do they offer the latest NVIDIA GPUs like the H100 or L40S? Can you choose specific amounts of RAM, storage types (NVMe), and CPU cores to prevent bottlenecks?
- **Support**: Is technical support available 24/7 with direct access to senior engineers?
- **Cost and Value:** Can you get the performance and reliability you need within your budget?
- **Data Center**: Is the data center positioned well to reduce latency and does it meet your compliance and security requirements?
- **Network Quality**: Does the provider use a high-performance network with redundant connections?

### Evaluating Hardware Options

The choice of hardware is fundamental when selecting a GPU server, as the right configuration will determine whether the server can meet your workload requirements. Begin by assessing the types of GPUs offered by the provider.

Check that the GPUs available align with your specific workload needs. Additionally, examine the CPU paired with the GPU, as it should have enough cores and processing power to support the GPU’s high throughput. Look for adequate RAM capacity (at least 32GB for most high-performance tasks) and SSD/NVMe storage to ensure fast data access speeds.

Consider asking the provider about expandability: some providers offer customizable setups, allowing you to add more GPUs, RAM, or storage as your workload grows, ensuring future scalability without requiring a complete migration.

### Assessing Support and Services

Robust support services are essential, particularly if your workloads run continuously or if downtime can impact your business operations. Here’s what to look for:

- **24/7 technical support**: This is crucial for addressing potential issues as soon as they arise. Ensure that the support team is available at all hours and that their response times align with your operational needs.
- **Expertise**: The support team should have experience with GPU-intensive applications. Inquire about their familiarity with frameworks like CUDA, TensorFlow, or PyTorch if you plan to run machine learning or AI workloads.
- **Service Level Agreement (SLA)**: Review the SLA for uptime guarantees. Look for providers offering at least a 99.9% uptime guarantee and clearly defined compensation or recourse in case of service disruptions.

Providers that back their services with a high uptime SLA and skilled support can help ensure that your server environment is both reliable and resilient to unexpected issues.

### Considering Cost and Value

While GPU dedicated servers offer significant computational power, they come with higher costs, especially for premium GPU models. To ensure value for your investment:

- **Analyze Pricing Structures**: Look beyond base prices to understand the total cost, including additional fees for bandwidth, setup, or maintenance. Some providers bundle services like monitoring or security features, which may justify higher prices.
- **Pay-as-you-go vs. subscription models**: If your workloads are seasonal or vary in intensity, a pay-as-you-go model might be more cost-effective. For constant, high-intensity workloads, a subscription model often provides better long-term value.
- **Cost of expansion**: If you anticipate needing more resources, confirm the provider’s costs for adding GPUs, RAM, or storage. Some providers offer flexibility at a lower incremental cost, allowing you to scale without incurring a significant upfront expense.

Balance your need for high-performance capabilities with your budget, ensuring that the hardware and support features match the value you’re seeking.

### Checking Provider Data Center Locations

The physical location of data centers affects latency, which can be crucial for applications needing real-time processing or minimal delay. When evaluating a provider’s data center locations:

- **Proximity to users**: If you serve users primarily in a specific region, choose a provider with data centers close to that area to reduce latency. For example, providers with facilities in North America, Europe, and Asia-Pacific offer better options for global reach.
- **Redundancy and reliability**: Data centers with multiple power sources, backup generators, and redundant network connections offer higher reliability. Confirm that the provider has failover systems in place to maintain uptime in the event of a local issue.
- **Compliance and security**: For sensitive data, ensure that the provider’s data centers meet security and compliance standards such as ISO 27001, SOC 2, or GDPR. This is especially important for industries with strict regulatory requirements, like finance or healthcare.

Prioritizing data center locations that align with your user base and compliance needs can significantly impact performance and data security.

### Examining Network Infrastructure and Uptime Guarantees

A provider’s network infrastructure plays a pivotal role in determining the reliability and performance of your GPU server. Here’s what to look for:

- **Bandwidth and throughput**: For high-performance applications, ensure the provider offers high bandwidth options to support large data transfers and high network throughput. Many GPU applications involve significant data exchange, so robust networking is essential.
- **Redundancy and resilience**: The best providers build redundancy into their networks to protect against downtime. Look for providers that maintain multiple data connections and employ traffic balancing across routes to prevent single points of failure.
- **Uptime guarantees and compensation**: Review the provider’s uptime guarantee, usually stated in the SLA. A 99.9% uptime guarantee should be a minimum standard, but some providers offer 99.99% for added reliability. Confirm what compensation is available if they fail to meet this standard, as this can help offset losses from downtime.

High-quality network infrastructure and clear uptime commitments ensure that your server remains accessible and responsive, even during high-demand periods.

## Final Considerations for GPU Deployment

Transitioning to a GPU dedicated server is a strategic move for any data-driven business. Whether you are training complex neural networks, running scientific simulations, or deploying a global virtual desktop infrastructure, the right hardware determines your project’s success.

By integrating dedicated GPU cards into your infrastructure, you can process data faster and more accurately. The shift from sequential CPU processing to massive parallel computing power allows for innovation that was previously impossible.

Analyze your current workloads and determine the specific GPU memory and processing requirements. For many projects, a pre-configured server from a reputable hosting provider offers the fastest path to production. With the right GPU hosting environment, your team can focus on solving complex problems while the hardware handles the heavy lifting.

At Atlantic.Net, we provide professional GPU dedicated server options and expert technical support needed to power your most demanding tasks. From AI training to high performance computing, our infrastructure is designed to deliver consistent performance and reliability for every use scenario in 2026.

### Technical Support and Managed Services

The complexity of GPU workloads requires a high level of technical expertise. Unlike standard web hosting, GPU hosting often involves intricate software stacks and driver configurations. A provider offering managed services can handle these technical details, including:

- **Operating system updates and security patches**
- **GPU driver installation and optimization**
- **Backup OS management and disaster recovery**
- **Monitoring server health and performance**

Having support in place ensures that your AI workloads remain productive. If a hardware failure occurs, a top-tier provider should offer a swift hardware replacement guarantee, often within one hour, to minimize downtime.

### Selecting the Right GPU for Your Task

Choosing the correct GPU dedicated server requires matching the specific hardware to the nature of your task. For instance, image recognition and generative AI benefit from the massive number of CUDA cores found in the Ada Lovelace and Hopper architectures.

If your project involves fine-tuning existing models, a server with high VRAM is necessary to hold the model parameters in memory. For video rendering, the presence of RT cores and high memory bandwidth will determine how quickly you can produce high-quality frames.

Renting GPU servers facilitates future growth. As your datasets expand and your AI models become more complex, having a scalable hosting environment ensures you can add more GPUs or upgrade to newer architectures without a complete infrastructure overhaul.

### The Future of High Performance Computing

As we move through 2026 and into an era dominated by large language models and real-time data processing, the demand for GPU resources will only increase. Dedicated GPU servers represent the pinnacle of modern hosting technology. They provide the raw power required for the most advanced AI models and the security needed for the most sensitive data. By choosing a dedicated GPU over a virtualized instance, you ensure that your application has the consistent performance and full resource availability required for success.

Maximize your computing resources by choosing a provider that understands the unique needs of the high performance computing community. With a professional GPU dedicated server, your organization is prepared to handle the challenges of modern data science and graphics processing.

[Talk to](https://www.atlantic.net/about-us/corporate-contact/)[Atlantic.net](http://Atlantic.net)[’s GPU dedicated hosting experts](https://www.atlantic.net/about-us/corporate-contact/) and give your machine learning and complex, high-performance computing tasks the proper foundation.


---

# Top Cloud Hosting Platforms for Compliance-Heavy Industries in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/compliance-ready-cloud-hosting-platforms-2026/ | Published: 2026-01-22 | Updated: 2026-01-20 | Author: Dr. Assad Abbas

Compliance-heavy industries are under constant pressure in 2026 because regulatory frameworks become more detailed each year, while enforcement activities also expand across jurisdictions. As a result, oversight expectations have become stricter, requiring organizations to provide more transparent and more frequent evidence of compliance. At the same time, organizations generate and process larger volumes of data.

In addition, the increasing interconnectivity of systems increases exposure to security risks, while cyber threats target regulated environments with greater precision and persistence. Therefore, organizations have minimal margin for operational or security failures. These pressures have accelerated the adoption of cloud hosting platforms that deliver standardized security controls, automated compliance tooling, and scalable infrastructure designed for regulated workloads.

Sector-specific requirements make these challenges even greater. Healthcare organizations must protect patient records, medical imaging, and clinical systems storing [electronic Protected Health Information (ePHI)](https://www.atlantic.net/hipaa-compliant-hosting/protecting-phi-cloud/). Similarly, financial institutions manage payment data, customer identities, and regulatory reports that require high accuracy and traceability. Similarly, Law firms protect confidential case files and private communications, while regulated SaaS providers manage sensitive customer data at scale. As a result, in all these sectors, a single mistake or control failure can lead to regulatory penalties, financial losses, and long-term harm to trust. This makes the choice of cloud hosting provider directly linked to an organization’s ability to meet its compliance obligations under a shared responsibility model.

In this situation, [cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) has become an essential part of compliance-focused operations rather than a secondary option. Many regulated organizations have moved beyond relying only on on-premises infrastructure. Therefore, critical workloads are increasingly run on cloud platforms that provide security controls, support regulatory compliance, and offer audit-ready visibility. These platforms also help organizations manage governance in a structured way while reducing the effort required to maintain internal compliance systems. As a result, cloud hosting is now a foundational component of modern compliance strategies.

## Why Regulated Industries Depend on Cloud Hosting

Regulated organizations rely on cloud hosting because it supports compliance requirements while helping manage complex workloads. In cloud environments, infrastructure provides layers of protection, including controlled access, monitoring, and backup systems. However, organizations are responsible for configuring resources correctly and applying internal policies to prevent risks. Therefore, cloud hosting does not replace organizational controls, but it offers tools that make managing them more practical.

Moreover, because regulated workloads constantly change in healthcare, finance, legal, and SaaS sectors, organizations face increasing demands on their systems. Data volumes rise, user access requirements expand, and reporting obligations become more complex. Consequently, cloud hosting enables organizations to adjust computing, storage, and network resources efficiently while maintaining security and compliance controls. In this way, operations remain stable even when workload requirements vary.

Moreover, cloud platforms strengthen audit readiness within regulated environments. Centralized logging systems, access records, and configuration histories support continuous oversight and systematic review of operational activity. Compliance teams rely on these consolidated records to track changes, verify controls, and assemble audit evidence with greater consistency. Automated dashboards and reporting tools further reduce manual effort and lower the likelihood of documentation errors during formal assessments.

Therefore, cloud hosting offers a combination of structured infrastructure, operational adaptability, and audit support suited to regulated operations. However, these advantages remain effective only when organizations apply precise internal controls and follow established compliance procedures. In this context, cloud platforms function as a practical complement to regulated operations rather than a substitute for governance responsibility.

## Compliance Foundations and Architectures for Regulated Cloud Workloads

Regulated industries face increasing complexity in managing compliance requirements. At the same time, organizations handle larger volumes of data across interconnected systems, which elevates security risks. Consequently, structured infrastructure and consistent governance are essential to maintain operational stability and regulatory alignment.

In addition, workloads in regulated domains require multiple layers of security. To achieve this, organizations implement controls such as encryption for data in transit and at rest, role-based access management, multi-factor authentication, and just-in-time privileges, which collectively strengthen protection against unauthorized access and data breaches.

Moreover, centralized logging, immutable audit trails, and monitoring systems help organizations maintain continuous oversight while supporting regulatory reporting. In addition, network segmentation, firewalls, and intrusion detection provide further measures, ensuring that sensitive workloads remain protected from unauthorized access or disruptions.

Cloud architecture decisions also influence compliance outcomes. For example, private or dedicated environments isolate regulated workloads, simplify audits, and deliver predictable performance. At the same time, hybrid models enable sensitive cores to remain on private infrastructure while extending non-sensitive services to public cloud environments through encrypted connections and boundary controls. Similarly, multi-cloud deployments enhance resilience and flexibility; however, they require automation to enforce consistent compliance across providers. Tools such as policy-as-code, infrastructure-as-code, and continuous monitoring support uniform configurations, collect audit evidence, and allow remediation when deviations are detected.

Finally, choosing a platform with strong operational support, built-in audit capabilities, and governance tools strengthens an organization’s ability to stay compliant. In this way, well-planned cloud architectures become practical partners for secure operations, helping organizations handle changing workloads efficiently and with confidence.

## Top Cloud Hosting Platforms for Compliance-Heavy Industries in 2026

Several cloud platforms support regulated workloads in 2026. Each platform serves different operational and compliance needs.

### Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

[Atlantic.Net](http://www.atlantic.net) is recognized for its strong orientation toward compliance-driven hosting environments, particularly for healthcare, finance, legal, and regulated SaaS organizations. The platform emphasizes predictable governance, dedicated infrastructure, and long-term operational stability. Its service model is suitable for institutions that require structured support to maintain alignment with HIPAA and other regulatory frameworks.

#### *Compliance**‑**Relevant Characteristics*

- The hosting environment from Atlantic.Net is built to be HIPAA-compliant, with strong access controls and encryption for sensitive data. This helps institutions protect regulated information in a stable, predictable manner.
- A formal [HIPAA Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) is available for customers. This document explains responsibilities and incident-handling steps in a clear, structured manner.
- Dedicated and private infrastructure options reduce exposure to shared environments. This gives organizations stronger control over their systems and supports stricter governance needs.
- Audit preparation is made easier through the logs, documentation, and guidance provided by Atlantic.Net. These resources support customers during external reviews and help them meet regulatory expectations with greater confidence.

### Amazon Web Services (AWS)

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

[AWS](https://aws.amazon.com/) is used by several organizations that work with regulated data. The platform offers a wide range of services and a global presence. Many teams choose it when they need systems that can grow in a stable, controlled way while still meeting governance requirements. The shared responsibility model means the customer must configure the environment with care. At the same time, AWS provides a robust foundation of certified infrastructure to support these efforts.

#### *Compliance**‑**Relevant Characteristics*

- A broad set of HIPAA-eligible services helps teams run regulated workloads on approved compute, storage, and analytics components under an AWS BAA.
- Identity and access controls in AWS support detailed permission settings and conditional rules. This helps organizations protect sensitive information with more confidence.
- Centralized logging and monitoring tools, such as CloudTrail and CloudWatch, give clear visibility into system activity. These tools also support audit work and compliance reporting.
- Global regional availability in AWS supports redundancy planning and disaster-recovery needs. It also helps institutions meet data-residency requirements across different regions.

### Microsoft Azure

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

[Microsoft Azure](https://azure.microsoft.com/en-us) is used by many enterprises that work under regulatory rules. The platform integrates well with Microsoft identity systems, helping organizations manage access centrally. Azure also supports hybrid setups, so teams can keep some systems on-premises while moving others to the cloud. This approach is helpful for institutions that need both flexibility and oversight. The platform includes tools that help maintain consistent configurations across environments.

#### *Compliance**‑**Relevant Characteristics*

- Centralized identity integration through Microsoft Entra ID improves visibility and access control for regulated workloads hosted on Azure. It helps organizations apply uniform identity rules across cloud and on-premises systems.
- Policy-based configuration tools help maintain compliance baselines and reduce the risk of mistakes. These tools guide teams toward safer and more consistent deployments.
- Hybrid architecture support helps organizations extend on-premises systems into Azure while keeping familiar operational practices. This model is helpful for institutions that must retain some local oversight while still using cloud resources.
- Azure supports HIPAA-compliant deployments when customers use HIPAA-eligible services and follow Microsoft’s recommended safeguards. This approach helps institutions meet regulatory expectations while running sensitive workloads in the cloud.

### Google Cloud Platform (GCP)

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

[Google Cloud Platform](https://cloud.google.com/) is used by various organizations that run data-intensive or analytics-focused workloads. The platform follows a security-first design with strong encryption and automated controls. These features help institutions meet regulatory requirements while processing sensitive information. GCP also offers clear visibility into system activity, which is essential for audit work. The platform supports structured governance through policy tools and configuration checks.

#### *Compliance**‑**Relevant Characteristics*

- Default encryption for data at rest and in transit helps protect sensitive information without extra setup steps on GCP. This approach supports regulated workloads that require strong protection for stored and transmitted data.
- Centralized logging and monitoring tools give clear insight into system behavior and help teams review events during audits. These tools also support ongoing compliance reporting for organizations that must document system activity.
- Policy enforcement features help reduce configuration mistakes and support consistent governance across large environments. This is useful for institutions that manage many resources and need predictable behavior across all deployments.
- GCP supports HIPAA-compliant deployments when customers use HIPAA-eligible services and follow Google’s configuration guidance. This helps organizations meet regulatory expectations while running sensitive workloads in the cloud.

### Rackspace

![](https://www.atlantic.net/wp-content/uploads/2025/12/rackspace_logo.png)

[Rackspace](https://www.rackspace.com/) focuses on managed cloud and managed security services, making it suitable for organizations that need operational assistance to maintain compliance. Instead of acting only as an infrastructure provider, Rackspace functions as a partner that helps configure, monitor, and maintain compliant environments across multiple cloud platforms. This approach is valuable for institutions with limited internal cloud expertise or those seeking continuous oversight.

#### *Compliance**‑**Relevant Characteristics*

- Managed security operations include monitoring, patching, and response activities that help reduce risk for regulated workloads supported by Rackspace. These tasks help institutions maintain safer and more stable systems.
- Support for compliance-heavy environments covers HIPAA, PCI, and other frameworks across private cloud and hyperscale platforms. This helps organizations keep consistent practices across different environments.
- Operational guidance helps teams maintain stable and secure configurations. This is useful for institutions without large internal engineering groups.
- Multi-platform management from Rackspace supports consistent governance across hybrid or multi-cloud setups. This helps organizations maintain predictable oversight even when systems run in different locations.

**Table 1: Compliance-Focused Cloud Providers**

| **Provider** | **Primary Strength in Regulated Industries** | **Compliance Orientation** | **Operational Model** | **Best-Fit Use Cases** |
| --- | --- | --- | --- | --- |
| **Atlantic.Net** | Dedicated, audit-ready hosting for healthcare and finance | Strong HIPAA alignment, BAAs, private infrastructure | Hands-on, guided, compliance-centric | Healthcare systems, legal firms, regulated SaaS, small–mid orgs needing structured oversight. |
| **AWS** | Broadest service portfolio and global reach | HIPAA-eligible services, detailed documentation | Self-managed with strong tooling | Large enterprises, analytics workloads, global deployments, and large-scale systems |
| **Microsoft Azure** | Enterprise identity integration and hybrid capabilities | Regulatory mappings, policy enforcement | Mixed: self-managed with strong governance tools | Enterprises with Microsoft ecosystems, hybrid cloud, and financial services |
| **GCP** | Security-first architecture and strong automation | Default encryption, policy controls | Self-managed with automated guardrails | Data-intensive workloads, analytics, and AI-driven regulated systems |
| **Rackspace** | Managed operations across multiple clouds | HIPAA/PCl-aligned managed services | Fully managed, partner-driven | Organizations lacking internal cloud expertise, hybrid/multi-cloud governance |

## Selecting a Compliance-Focused Cloud Provider

Selecting a cloud provider for regulated workloads is not a simple technical choice. It requires a careful review of how each platform supports governance, daily operations, and long-term compliance needs. Many providers advertise strong security features, but these claims do not always reflect the real experience of running regulated workloads. Institutions subject to HIPAA, PC, or similar rules must review the provider’s controls in detail. They also need to confirm that these controls align with their policies, staffing levels, and risk tolerance.

Some organizations prefer a provider that offers a guided environment. In such cases, Atlantic.Net becomes a practical option. It provides a stable, predictable setup, which is helpful when internal teams lack deep compliance engineering skills. The platform focuses on clarity, dedicated resources, and compliance-ready configurations. This approach supports institutions that want a more direct and structured path for running regulated workloads.

AWS is often selected for reasons other than performance. Many institutions choose it when they need large-scale systems, global regions, and a wide range of services. These features support complex workloads, but they also increase the customer’s responsibility. A team must carefully configure several settings. If the team is small or inexperienced, the environment can become challenging to manage.

Azure is chosen by organizations that depend on Microsoft identity systems or hybrid setups. This is common in enterprises that already use Microsoft tools for daily operations. The benefit is strong identity integration and a familiar environment. The limitation is that Azure works best when the rest of the organization is already aligned with Microsoft technologies.

GCP is often considered by institutions that work with large datasets or analytics workloads. The platform offers strong encryption and automated controls. These features help with regulated data, but the service catalog is more focused on data and analytics. Organizations that need broad enterprise features may find fewer built-in options compared to other providers.

Rackspace is different from the others. It is useful when an organization wants to share or delegate operational tasks. This is common in teams that lack sufficient internal staff to manage compliance work. Rackspace provides managed services across multiple clouds. The trade-off is reduced direct control, which may not suit institutions that prefer to manage everything internally.

A final decision should consider documentation quality, incident response steps, encryption methods, access control features, and the provider’s support for audit work. Compliance is not a one-time task. It requires continuous monitoring and regular updates. The chosen provider must support this ongoing effort in a stable, predictable manner.

## Decision‑Making Checklist for Compliance‑Focused Cloud Deployments

To help institutions apply these considerations, the following checklist offers a structured approach to evaluating cloud providers for regulated workloads.

### 1. Compliance Documentation

- *Confirm that the provider offers a BAA with clear terms.*

- *Review the list of HIPAA-eligible services and determine whether they align with your workload needs.*

### 2. Identity and Access Control

- *Check if the platform supports detailed permission settings and multi-factor authentication.*

- *Review how identity integrates with your existing systems.*

### 3. Encryption and Data Protection

- *Verify that data is encrypted during storage and transmission.*

- *Confirm that encryption keys can be managed in line with your internal policies.*

### 4. Logging and Monitoring

- *Ensure that the provider offers clear logs for access, configuration changes, and system activity.*

- *Check if these logs can be exported to your own monitoring tools.*

### 5. Network Controls

- *Review segmentation options and firewall rules.*

- *Confirm that the platform supports private networking for sensitive workloads.*

### 6. Operational Support

- *Decide whether your team needs a guided or self-managed environment.*

- *Review support hours, response times, and the provider’s experience with regulated industries.*

### 7. Audit Readiness

- *Check whether the provider offers documentation to support external audits.*

- *Confirm that logs and reports can be generated in a simple, consistent way.*

### 8. Scalability and Future Growth

- *Review regional availability and service expansion plans.*

- *Confirm that the platform can support new workloads without major redesign.*

### 9. Cost Structure

- *Study the pricing model and identify any hidden charges.*

- *Compare the cost of storage, compute, networking, and support across providers.*

### 10. Internal Capacity

- *Assess your team’s skills and available time.*

- *Choose a provider that aligns with your operational strengths, not just your technical goals.*

## The Bottom Line

Choosing a cloud provider for regulated workloads requires an understanding of both immediate needs and ongoing obligations. Because the decision influences how teams handle security, documentation, and daily operations, it also affects the organization’s ability to respond to audits and regulatory updates. Moreover, each platform offers a different mix of guidance, flexibility, and support, so the selection must align with the institution’s internal capabilities and long-term plans. Consequently, reviewing identity controls, network protections, and service reliability gives teams greater confidence in their choice. Finally, compliance work does not end after deployment; it continues through regular reviews, updated procedures, and ongoing oversight. In this way, a good provider helps maintain stable, secure, and compliant operations over time.


---

# What Is MFA as a Service? Modern Security Management with MFA Services in 2026

> URL: https://www.atlantic.net/managed-services/what-is-mfa-as-a-service/ | Published: 2026-01-24 | Updated: 2026-06-23 | Author: Richard Bailey

MFA as a Service, or [Multi-Factor Authentication](https://www.atlantic.net/hipaa-compliant-hosting/two-factor-authentication-vs-multi-factor-authentication-the-best-log-in-security/) as a Service, is a security identification platform various cloud-based applications use to secure private access to a particular service.

MFA enhances the protection of online accounts and systems by requiring multiple forms of verification from the user. MFA provides user identities with an extra layer of security beyond the traditional username and password combination.

By requiring that user accounts have multiple authentication factors, it becomes significantly more difficult for attackers to gain unauthorized access to a user account, even if they can obtain one of the user identities’ authentication factors.

Below we’ll learn what MFA is, how you can implement MFA in your environment, and why MFA as a service will make your life much easier.

## **What Is MFA and Why Is It Important?**

Typically, multi-factor authentication involves three main factors.

1. **Something you know, or Knowledge Factors**: This factor requires knowledge of a secret piece of information that only you, the authorized user, should know, such as a password, PIN, or an answer to a security question.
2. **Something you have, or Possession Factors**: This factor involves possessing a physical item (such as hardware tokens) that verifies your identity, such as a security token, smart card, or mobile device. Typically, the ‘*thing’*generates a unique code that changes frequently, such as an RSA code. The codes are used as part of the authentication process.
3. **Something you are, or Inherence Factors:** This factor involves a unique physical characteristic or biometric trait of the user, such as a fingerprint, iris scan, voice recognition, or facial recognition. Biometrics are increasingly used in MFA to provide a highly secure and convenient form of identification.

MFA solutions can be complex and resource-heavy but are an excellent choice for delivering security functionalities over the cloud. Businesses can choose to go it alone and implement a private MFA solution; however, these are expensive to license, complicated to install, and difficult to manage.

A hugely popular alternative is the MFA solution as a service. Managed multi-factor authentication (MFA) platforms give businesses secure access to a comprehensive, scalable, and configurable multi-factor authentication solution. It enables organizations to enhance security without the need for extensive technical expertise.

## **Understanding the MFA Service Landscape**

An MFA service does more than just send a text code. Modern services provide a comprehensive identity layer that protects against sophisticated phishing and “man-in-the-middle” attacks. These services authenticate users using authentication-based methods that go beyond simple username and password combinations.

MFA services are designed to verify user identities through multiple authentication factors, reducing the risk of unauthorized login. By moving to a cloud-based model, your organization can leverage advanced features like risk-based authentication without the overhead of maintaining physical servers on-premises.

## **Key Considerations for Your 2026 MFA Strategy**

When evaluating providers, consider how they handle FIDO (Fast IDentity Online) standards and public key cryptography. At Atlantic.Net, we prioritize solutions that offer a seamless user experience while maintaining high-security hurdles for unauthorized users.

For example, our [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) infrastructure is designed to work in tandem with identity providers to ensure your ePHI (electronic [Protected Health Information](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/)) remains secure. Remember that for all data in transit, we mandate the use of TLS 1.2 or 1.3.

### How Does Adaptive Authentication Work?

Rather than applying the same authentication process to every login attempt, adaptive authentication evaluates real-time signals—such as a user’s physical location, device type, and login history—to determine the appropriate level of security. For example, if a user logs in from a familiar device and location, the system may only require a password and a simple one time password. However, if the same user attempts to access sensitive resources from an unusual location or a new device, the MFA solution can prompt for additional authentication factors, such as a fingerprint scan or a push notification.

This dynamic approach ensures that users are not subjected to unnecessary friction during routine logins, while still providing strong authentication when risk is detected. By personalizing the authentication process, adaptive authentication helps organizations balance security and user experience, making it easier for users to access what they need without compromising the integrity of their accounts. As threats evolve, adaptive authentication remains a critical tool for verifying user identities and maintaining robust security across all access points.

### Cloud-Based MFA: Scalability and Flexibility for Modern Enterprises

Cloud-based MFA solutions have become the backbone of secure access and access management for modern organizations. Using the power of the cloud, businesses can deploy multi factor authentication across all user accounts and company resources without the need for complex on-premises infrastructure. This approach allows for rapid scaling as organizations grow, ensuring that every user—whether remote or on-site—benefits from consistent, up-to-date security.

Leading platforms like Cisco Duo and Microsoft Entra ID offer seamless integration with existing identity and access management systems, making it easy to manage authentication and monitor user activity in real time. Cloud-based MFA also provides centralized visibility into authentication attempts, enabling security teams to quickly identify and respond to suspicious behavior. With the flexibility to support a wide range of devices and authentication methods, cloud-based MFA ensures that users can securely access business applications and sensitive data from anywhere, at any time.

### User-Friendly Interfaces for MFA

A user-friendly interface is essential for the successful adoption of multi factor authentication across any organization. The best MFA solutions are designed to guide users through the authentication process with clear instructions and intuitive prompts, reducing confusion and minimizing the risk of user error. Whether a user is asked to enter a one time password, scan their fingerprint, or respond to a push notification, the interface should make it obvious what is required and how to proceed.

By prioritizing usability alongside security, organizations can ensure that users are more likely to comply with MFA requirements, leading to stronger overall protection for user accounts. A streamlined, user friendly experience also helps reduce support requests and training time, making it easier for both IT teams and end users to embrace the added security of multi factor authentication. Ultimately, a well-designed MFA solution delivers robust authentication factors without sacrificing convenience or productivity.

### Prebuilt APIs and Integrations Accelerate Deployment

Modern MFA solutions are designed with rapid deployment in mind, thanks to prebuilt APIs and integrations with leading identity and access management platforms. By offering out-of-the-box compatibility with systems like Okta, Ping Identity, and Microsoft Authenticator, these solutions enable organizations to quickly extend secure access controls to all users and business applications. This eliminates the need for time-consuming custom development and ensures that MFA can be rolled out organization-wide with minimal disruption.

Prebuilt APIs also make it easy to integrate MFA with existing workflows and company resources, providing a seamless authentication experience across cloud and on-premises environments. Whether securing access to sensitive databases, internal tools, or customer-facing portals, organizations can rely on these integrations to deliver strong authentication and consistent access management. With these capabilities, businesses can accelerate their MFA deployment and ensure that every user benefits from enhanced security from day one.

## **Top 10 MFA Providers for 2026**

Selecting the right partner to secure your user accounts is a critical decision. We have highlighted the leading MFA capabilities available for various business needs.

### **1. Cisco Duo**

![](https://www.atlantic.net/wp-content/uploads/2024/05/Cisco-Duo-Logo-Lockup-2-color-RGB.png)

Cisco Duo remains a market leader due to its focus on user-friendly security. The Duo Mobile app provides a streamlined experience that reduces help-desk tickets by making the second form of verification as simple as tapping a notification on a smartphone. We often recommend Duo for organizations that need to deploy MFA quickly across a diverse and remote workforce.

Integrating MFA with Single Sign-On (SSO) can reduce login friction and decrease the burden on IT help desks, and Cisco Duo supports such integrations, enabling secure and seamless access to multiple applications with one set of credentials.

- **Adaptive Access Policies**: Allows administrators to set granular rules based on user location, device health, and network security, ensuring only trusted users on healthy devices can access sensitive applications.
- **Device Visibility and Health**: Provides a comprehensive dashboard showing the security status of every device accessing your applications, allowing you to block outdated operating systems or devices without encryption.

### **2. Microsoft Entra ID**

![](https://www.atlantic.net/wp-content/uploads/2024/05/microsoft-entra-id-logo-small.png)

Formerly known as Azure AD, Microsoft Entra ID is the cornerstone of identity management for organizations utilizing the Microsoft ecosystem. It provides a deep level of integration with Windows 11, Office 365, and other enterprise tools. We find it particularly effective for large-scale enterprises that require complex conditional access policies and tight integration with their existing directory services.

- **Conditional Access Management**: Uses automated intelligence to evaluate signals like user risk and sign-in risk in real-time, automatically prompting for MFA or blocking access if a threat is detected.
- **Passwordless Authentication Options**: By leveraging the Microsoft Authenticator app and FIDO2 security keys, Entra ID allows organizations to move toward a passwordless environment.

### **3. Okta**

![](https://www.atlantic.net/wp-content/uploads/2024/05/okta.png)

Okta is a premier independent identity provider known for its “neutral” stance, offering over 7,000 pre-built integrations with various cloud and on-premises applications. This makes it an ideal choice for businesses with a diverse software stack that isn’t tied to a single vendor. Our team appreciates Okta’s reliability and its ability to serve as a single source of truth for corporate identities.

- **Extensive Integration Network**: The Okta Integration Network (OIN) allows for the rapid deployment of SSO and MFA across almost any modern business application, ensuring a consistent security posture.
- **Advanced ThreatInsight**: Analyzes authentication requests across Okta’s entire customer base to identify and block malicious IP addresses associated with credential stuffing and brute-force attacks.

### **4. Ping Identity**

![](https://www.atlantic.net/wp-content/uploads/2024/05/ping.png)

Ping Identity is built for the complexities of the modern enterprise, specifically those operating in hybrid environments where data lives both in the cloud and in legacy on-premises data centers. It offers high levels of customization and is frequently selected by companies that require bespoke identity workflows.

- **Hybrid Cloud Deployment**: Offers the flexibility to deploy identity services in the cloud, on-premises, or as a managed service, providing a unified identity bridge across different hosting environments.
- **PingID Mobile SDK**: Allows developers to embed MFA capabilities directly into their own custom-built mobile applications, providing a branded and seamless authentication experience.

### **5. Thales SafeNet Trusted Access**

![](https://www.atlantic.net/wp-content/uploads/2024/05/icon-one-time-password.png)

Thales specializes in high-assurance environments, such as government, defense, and high-finance sectors. Their SafeNet Trusted Access service manages a wide landscape of diverse authentication needs, offering one of the widest ranges of hardware tokens and smart cards in the industry.

- **Broadest Range of Authenticators**: From traditional hardware “key fobs” to pattern-based grids and mobile apps, Thales provides an authentication method for every possible user scenario.
- **Policy-Driven Access Control**: Administrators can define sophisticated access journeys based on the sensitivity of the resource, ensuring a simple app login is easy while database access requires a hardware key.

### **6. Yubico**

![](https://www.atlantic.net/wp-content/uploads/2024/05/Logo-Yubico_wordmark_standard_layout_630x.png)

Yubico’s YubiKey devices are the popular standard for hardware-based security, offering near-impenetrable defense against phishing. We recommend YubiKeys for IT administrators and executives who handle the most sensitive data within an organization.

- **Multi-Protocol Support**: A single YubiKey can support FIDO2, U2F, Smart Card (PIV), and OTP, making it compatible with a vast array of legacy and modern systems.
- **Physical Durability and Security**: Designed to be crush-proof and waterproof, these keys contain a secure element that prevents private keys from ever being extracted or copied by an attacker.

### **7. RSA SecurID**

![](https://www.atlantic.net/wp-content/uploads/2024/05/rsa.jpg)

RSA is a veteran in the security space that has successfully transitioned its reputation into a modern, cloud-first identity platform. RSA SecurID now offers a comprehensive suite of mobile-based MFA and risk-based analytics, making it a reliable choice for enterprise environments.

- **Risk-Based Authentication (RBA)**: Uses machine learning to build a profile of “normal” user behavior, allowing the system to silently verify identity unless a significant anomaly is detected.
- **Cloud and On-Premises Interoperability**: Provides a seamless bridge for companies transitioning to the cloud, allowing them to manage existing hardware tokens and new mobile authenticators from one dashboard.

### **8. JumpCloud**

![](https://www.atlantic.net/wp-content/uploads/2024/05/63efe864a1c54178183a56c0_jump.png)

JumpCloud provides an open directory platform that is particularly valuable for small-to-mid-sized businesses. It replaces the need for an on-premises Active Directory by providing a cloud-based hub for managing users, devices, and access. Our SMB clients find JumpCloud’s integrated MFA features to be both cost-effective and powerful.

- **Cross-Platform Device Management**: Allows you to enforce MFA at the system login level for Windows, macOS, and Linux devices, ensuring local security underpinnings are as strong as cloud apps.
- **Integrated RADIUS and LDAP**: Extends MFA protection to older networking equipment and legacy applications that rely on traditional authentication protocols without needing extra hardware. JumpCloud also supports users defined in external directories, such as LDAP or Active Directory, providing flexible user management.

### **9. HID Global**

![](https://www.atlantic.net/wp-content/uploads/2024/05/HID_Global_logo.png)

HID Global is a powerhouse in the world of physical access control that has expanded into digital identity. Their Crescendo and DigitalPersona platforms are designed for organizations that want to converge their physical building badges with their computer login systems.

- **Converged Physical and Digital ID**: Employees can use a single high-security “smart card” to enter the office building and then use that same card to log into their workstation and sign digital documents.
- **PKI-Based Authentication**: Leverages public key infrastructure (PKI) to provide the highest level of cryptographic assurance, ensuring that identities are undoubtedly verified through secure certificates.

### **10. Silverfort**

![](https://www.atlantic.net/wp-content/uploads/2024/05/Silverfort_Logo.jpg)

Silverfort is a transformative player because it solves a significant problem: adding MFA to systems that don’t natively support it. By working at the protocol level (like Kerberos and NTLM), Silverfort can protect legacy servers and command-line tools without installing agents.

- **Agentless MFA Deployment**: Monitors traffic between the user and domain controller to trigger an MFA prompt for any resource on the network without requiring target system software changes.
- **Protection for Administrative Tools**: One of the few providers that can effectively add MFA to tools like PowerShell, SSH, and RDP, which are frequently used by attackers to move laterally.

## **Implementing the Right MFA Method for Your Organization**

Choosing the right MFA service requires an assessment of your specific security needs. For small businesses, a user-friendly app-based approach like Cisco Duo or JumpCloud might be the best fit. For large enterprises with complex legacy systems, a more extensive platform like Microsoft Entra ID or Ping Identity may be required.

Our team at Atlantic.Net can help you determine how these services fit into your broader hosting strategy. By utilizing an identity provider that supports adaptive authentication and multiple authentication options, you can protect your company resources and significantly reduce the risk of data breaches.

## MFA and Compliance: Meeting Regulatory Demands

Meeting regulatory requirements is a top priority for organizations handling sensitive data, and multi factor authentication plays a vital role in achieving compliance. By implementing an MFA solution that uses multiple authentication factors, organizations can demonstrate their commitment to protecting user accounts and reducing the risk of data breaches. Standards set by the FIDO Alliance, as well as regulations like [PCI DSS](https://www.atlantic.net/pci-compliant-hosting/pci-dss-4-0-is-mandatory-a-hosting-checklist-for-2026/) and [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/what-is-a-hipaa-certification/), often require or strongly recommend the [use of MFA to safeguard critical information](https://www.atlantic.net/managed-services/multi-factor-authentication/).

By using strong authentication methods and maintaining detailed audit trails, businesses can ensure that their security practices align with industry best practices and legal requirements. Adopting multi factor authentication is a proactive step toward building trust with users and regulators alike, while significantly enhancing the organization’s overall security posture.

## **Final Implementation Steps**

To begin, you must enable MFA on your most sensitive accounts first. Start with IT administrators and executives, as these user accounts are the most likely targets for attackers. Once the core team is secure, roll out the MFA solution to the rest of the organization.

Provide clear instructions on how the MFA works and ensure every employee has the Duo Mobile app, Microsoft Authenticator, or a physical token ready. Consistent training helps ensure that the authentication process becomes a natural part of the workday. With a managed MFA service and our secure hosting environment, you can ensure that your organization remains protected against new threats in 2026.


---

# HIPAA Compliance for Law Firms: A Guide to Protecting Health Information

> URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-requirements-for-attorneys/ | Published: 2026-01-24 | Author: Richard Bailey

It’s not just healthcare organizations that need to adhere to HIPAA requirements. Attorneys and law firms often deal with health care providers and private health records and need to ensure they meet regulatory standards.

Getting HIPAA requirements wrong can lead to a financial penalty, so read on to find out what you need to know about HIPAA as an attorney and the best practices you and your firm should be following.

## What Is HIPAA?

HIPAA stands for the Health Insurance Portability and Accountability Act. As an attorney, you need to be fully aware of HIPAA requirements and consider them in your everyday practices, from handling sensitive patient data to your use of [tort attorney software](https://assemblysoftware.com/masstort).

The Health Insurance Portability and Accountability Act was originally designed to improve the efficiency of the healthcare system and ensure that individuals could maintain insurance coverage when changing jobs. The legislation also introduced national standards for electronic healthcare transactions and code sets. This evolved into a framework of privacy and security requirements that extend beyond healthcare providers to include any entity handling health information.

For a law firm, understanding the reach of this act is necessary. The law applies to covered entities and their business associates. While a law firm is not typically a covered entity, it becomes a business associate when it performs legal services that involve access to protected health information. This status requires the firm to meet the same security and privacy standards as the hospitals or insurance companies providing the data.

Attorneys concerned with HIPAA requirements will need to pay particular attention to the accountability aspects of the act noted in these provisions:

- **Privacy Rule:** Protects the privacy of individually identifiable health information, known as Protected Health Information (PHI). It sets boundaries on the use and release of health records, establishes safeguards to protect the privacy of PHI, and holds violators accountable, often with civil and criminal penalties.
- **Security Rule:** Specifies a series of administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of electronic protected health information (e-PHI).
- **Transactions and Code Sets Rule:** Standardizes the codes used to specify diseases, treatments, and medical procedures. This facilitates health-related electronic transactions like billing, referrals, and other administrative work.
- **Unique Identifiers Rule:** Provides a standardized way to identify healthcare entities in electronic transactions through the National Provider Identifier (NPI).
- **Enforcement Rule:** Provides guidelines for investigations into HIPAA compliance violations, including imposing monetary penalties for violations and procedures for hearings.

## Covered Entities

To understand the obligations of a law firm, one must first identify the covered entities defined by the law. Covered entities include three specific groups:

- **Health Care Providers**: Doctors, clinics, dentists, and pharmacies that transmit any health information in electronic form.
- **Health Plans**: Health insurance companies, health maintenance organizations, and government programs like Medicare or Medicaid.
- **Health Care Clearinghouses**: Entities that process nonstandard health information into standard electronic formats.

These organizations are the primary holders of patient records and billing records. When these entities share information with an attorney or law firm to facilitate legal representation, the firm acts as an extension of the covered entity’s workforce regarding data protection.

## Business Associates

A business associate is any person or organization that performs functions or activities on behalf of a covered entity that involve the use or disclosure of protected health information. Law firms are considered business associates when they handle medical records for litigation, care coordination, or benefits claim evaluations.

Under the HITECH Act, business associates are directly liable for compliance with the HIPAA Security Rule. Law firms must implement administrative, physical, and technical safeguards to protect data. The relationship between the covered entity and the firm must be formalized through a written contract.

## Key HIPAA Requirements for Attorneys

### Business Associate Agreements (BAAs)

If an attorney is performing services for a covered entity (like a healthcare provider or insurer) and has access to PHI, they may be considered what HIPAA terms “business associates.”

In this case, they must have a Business Associate Agreement (BAA) with the covered entity, which outlines how PHI will be used, disclosed, and protected. These agreements typically cover your responsibilities concerning PHI and any subcontractors you might work with.

In addition to BAAs, attorneys should also be aware that certain situations may require the use of [HIPAA forms](https://www.jotform.com/hipaa/) and documentation, such as consent forms for the release of medical records or authorization forms for the use of PHI in legal proceedings.

### Data Protection

Attorneys with access to PHI must have physical, administrative, and technical safeguards in place. This means secured databases, encrypted communications, staff training, and protocols for handling and storing sensitive data.

Law firms working with or in relation to a covered entity will be expected to have high data protection in place. Everything from your emails to your remote desktop connection manager should be considered.

Even if an attorney is permitted to access PHI for a case, HIPAA mandates the “minimum necessary” principle. Attorneys should only request, use, or disclose the minimum amount of PHI necessary to accomplish the intended purpose.

### Notification of Breaches

If there’s a major or minor breach or unauthorized disclosure of PHI, attorneys must have processes to notify the covered entity and, in some cases, the affected individuals and even the Department of Health and Human Services (HHS).

BAAs should inform the covered entity without unreasonable delay and in no case later than 60 calendar days after the discovery of a breach. The notification should provide:

- A description of the breach
- The types of information involved in the breach
- Steps taken to investigate the breach
- Potential mitigative measures taken

Often, it’s then up to the covered entity to inform individuals, but this can depend on who the attorney is working with.

### Document Retention

Any PHI records attorneys hold must be retained securely for the required period (often six years), and there should be clear policies about document destruction once that period expires.

Attorneys must retain documents such as:

- Business Associate Agreements
- Privacy and security policies and procedures specific to the firm’s handling of PHI
- Risk assessment reports and results
- Training materials and documentation related to HIPAA compliance training for staff
- Any incident or breach documentation, including investigations, notifications, and responses

HIPAA doesn’t mandate a specific format for retaining records — they can be kept in either electronic or paper format, but they must be accessible, reproducible when required, and protected from unauthorized digital or physical access, tampering, or destruction.

## HIPAA Compliance

Achieving HIPAA-compliant status for law firms requires a systematic approach to data management. Compliance is not a one-time event but a continuous process of risk assessment and mitigation. Firms must evaluate how they receive, store, and transmit data in electronic form.

The Office for Civil Rights (OCR) within the HHS is responsible for enforcing these regulations. If a firm experiences a security breach, the OCR may conduct an audit to determine if the firm followed HIPAA rules. Non-compliance can lead to civil and criminal penalties, depending on the level of negligence.

In order to comply with HIPAA, law firms must meet the requirements of the security rule which mandates that organizations handling patient health information maintain administrative, physical and technical safeguards over that information.

### Administrative Safeguards

Administrative safeguards are the policies and procedures that manage the conduct of the workforce in relation to the protection of PHI. These are the foundation of a secure practice.

- **Security Management Process**: Requires firms to identify and analyze risks to ePHI through a formal risk assessment.
- **Workforce Security**: Managed by limiting access to PHI to only those employees who require it for their jobs.
- **Regular Training**: All members of the workforce must receive education on security awareness, including password management and identifying malicious software.

### Physical Safeguards

Physical safeguards protect the physical assets of the firm, including offices and hardware. These measures prevent unauthorized physical access to systems and data.

- **Facility Access Controls**: Limiting physical access to areas where ePHI is stored using keycard entries or security cameras.
- **Workstation Use Policies**: Specifying the proper functions for computers that access PHI, ensuring they are not used for tasks that could introduce malware.
- **Device and Media Controls**: Managing the receipt and removal of hardware containing ePHI to ensure data is destroyed before hardware is retired.

### Technical Safeguards

Technical safeguards involve the technology and policies that protect ePHI and control digital access.

- **Access Control**: Measures to ensure that only authorized persons can access ePHI, including unique user IDs and automatic log-offs.
- **Encryption**: **ePHI** must be protected using TLS 1.2 or 1.3 while in motion and robust encryption algorithms while at rest.
- **Audit Controls**: Systems used to record and examine activity, allowing the firm to see who accessed data and when.

### Establishing HIPAA Compliance for Law Firms

Developing a strategy for HIPAA compliance begins with a thorough audit of the firm’s data handling processes. Legal practices must first identify every instance where protected health information enters their workflow, whether through digital portals, physical mail, or fax. Once these data points are identified, the firm must designate specific individuals to oversee the compliance program. This usually involves appointing a privacy officer to manage policy development and a security officer to handle the technical aspects of data protection.

After establishing leadership roles, the firm conducts a risk analysis to find vulnerabilities in its current systems. This analysis forms the basis for implementing the required administrative, physical, and technical safeguards. For a law firm, this also includes ensuring that all BAAs are signed and stored properly. Employees must receive training on these policies to ensure the entire workforce understands how to handle sensitive client data safely. Additionally, the firm must create a clear protocol for detecting potential HIPAA violations and a formal plan for notifying the necessary parties in the event of a breach.

## Best Practices for Attorneys to Meet HIPAA Requirements

### Thorough and Continuous Training

Attorneys and all staff at a legal firm should familiarize themselves with which of their clients or activities fall under HIPAA’s jurisdiction, common violations, and potential risks. This should be included as part of onboarding training and flagged when new cases are accepted.

In addition, you should regularly update your staff and legal professionals on [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-and-the-role-of-technology-in-healthcare-security/), ensuring everyone knows how to handle PHI correctly. Set a fixed annual date for refresher training for all staff.

**Tip: **Ask all staff to bookmark the official HHS HIPAA webpage or use online HIPAA training resources like the American Bar Association (ABA).

### Use Secure Communication

Data breaches are likely if communication lines are insecure, whether email, messaging, or phone calls.

Attorneys should always use secure, encrypted email services when sending or receiving PHI electronically. You should also be wary of discussing PHI over unsecured phone lines or in public places where conversations can be overheard.

**Tip:** Implement email software that prompts a warning or requires an additional step when sending emails containing potential PHI.

### Manage Data Storage, Access Control, and Documents with Care

Communication isn’t the only vulnerability at law firms. Your storage solutions and document management systems can be hacked too.

Store electronic files containing PHI on secure, encrypted drives or cloud storage solutions that comply with HIPAA. Limit access to PHI only to those within the firm who need it for case-related reasons. Use strong, unique passwords, and consider two-factor authentication for added security.

You should also maintain a strict protocol for document retention. Have a clear policy for document destruction, ensuring that both [electronic health records](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-and-electronic-health-records-ensuring-patient-confidentiality/) and paper records containing PHI are destroyed so they can’t be reconstructed.

**Tip: **Use software that tags and categorizes documents containing PHI and sets automated reminders for when these documents should be reviewed or securely destroyed.

### Have a Response Plan for Data Breaches

It’s always best to prepare for the worst. You must develop and regularly update a response plan for any potential security incidents. This plan should outline the steps to be taken, including notifications, internal investigations, and corrective actions.

Utilizing incident alert management systems can be highly beneficial in promptly detecting and responding to breaches.

Also, familiarize yourself with the breach notification requirements under HIPAA, ensuring timely reporting if a breach does occur. Ensure all bases are covered, from information stored on sites with other domains via [Only Domains](https://www.onlydomains.com/domains/British-Indian-Ocean-Territory/) to employees’ smartphones.

**Tip:** Conduct mock breach scenarios annually to test your firm’s contingency plan. This will help familiarize everyone with the steps they must take in an actual breach situation.

### Maintain Physical Security

While the above tips focus on electronic and technical safeguards, many law firms have paper records too. Keep paper documents containing Protected Health Information in locked cabinets or secure rooms.

You should also ensure office premises have adequate security measures like alarms, surveillance cameras, and controlled access to areas where sensitive information is stored.

**Tip: **Install a logging system for access to workstations and secure areas to trace who had access to sensitive information and when.

### Regularly Audit and Review

Once you have administrative safeguards in place, don’t just forget about them indefinitely. Instead, regularly audit your firm’s practices and [data management tools](https://www.atlantic.net/vps-hosting/the-best-cloud-data-management-solution/) regarding PHI to ensure ongoing compliance.

Review and update your internal policies regularly to adapt to law changes and address potential vulnerabilities.

**Tip:** Use a compliance checklist to ensure all areas of potential concern are audited bi-yearly.

### Collaborate with IT Staff and External Consultants

IT professionals are your best friends regarding HIPAA’s technical policies. Schedule routine cybersecurity assessments, vulnerability scans, and penetration testing to uncover and address potential weaknesses. Breaches can appear in places with little human interaction too, like automated customer service software, so be sure to get IT to cover all the bases.

Finally, if you’re still unsure about meeting HIPAA requirements, it’s time to seek external advice. And even if you’re confident in your technical security measures, seeking external legal or compliance consultation periodically can help identify potential oversights or areas of improvement.

**Tip:** Attend seminars or webinars focused on the intersection of legal practice and HIPAA compliance.

## Conclusion: Ensure your firm meets HIPAA requirements

HIPAA requirements mean any law firm should have reasonable safeguards in place to protect clients, patients, and employees. While monetary penalties are a top concern, HIPAA is also about ensuring trust across your firm and for your clients.

If your firm is dealing with any healthcare industry partners or clients, HIPAA is an essential part of day-to-day security practices, from data storage to everyday administrative actions. In addition to references this blog, please make sure you do a comprehensive research on HIPAA compliance by utilizing various available online and through credible sources.

Atlantic.Net can assist you with all your [HIPAA compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) needs.


---

# How Virtual GPUs Work, Use Cases and Critical Best Practices

> URL: https://www.atlantic.net/gpu-server-hosting/how-virtual-gpus-work-use-cases-and-critical-best-practices/ | Published: 2026-01-25 | Author: Richard Bailey

## What Is a Virtual GPU?

A virtual GPU (vGPU) is a technology that simulates the functionality of a physical graphics processing unit (GPU) within a virtualized environment. This allows multiple virtual machines (VMs) to share a single GPU, optimized for handling graphical tasks such as rendering images and processing complex computations.

Unlike traditional setups where each GPU is dedicated to a single machine, vGPU technology enables more efficient use of resources by distributing GPU power across multiple VMs. This setup helps in achieving higher performance without the need for additional hardware. Through shared usage, vGPUs ensure greater availability of resources.

By emulating physical GPU functions, vGPUs make graphical processing accessible in virtual environments. Organizations can leverage these capabilities for virtual desktop infrastructure (VDI), cloud-based applications, and other demanding tasks. This forms a crucial part of modern IT infrastructure, enabling high-end graphics processing on demand.

This is part of a series of articles about GPU applications.

## Benefits of Virtual GPUs

Virtual GPUs offer a range of advantages that enhance performance, scalability, and cost efficiency in virtualized environments:

- **Improved resource utilization:** vGPUs allow multiple virtual machines to share a single physical GPU, maximizing the usage of hardware resources. This leads to better allocation of processing power across tasks, reducing waste and increasing efficiency.
- **Cost efficiency:** By enabling resource sharing, vGPUs eliminate the need for dedicated GPUs for each VM. This reduces hardware expenses and overall operational costs while delivering comparable performance.
- **Enhanced scalability:** Organizations can scale their virtual environments more easily by allocating GPU resources dynamically as per workload requirements. This adaptability makes it easier to handle fluctuating demands without over-provisioning.
- **Support for high-performance applications:** vGPUs enable virtual machines to handle graphically intensive applications, such as CAD tools, machine learning models, and 3D rendering. This ensures that users experience smooth and responsive performance even in demanding scenarios.
- **Centralized management:** Administrators can monitor and manage GPU resources centrally within a virtualized infrastructure. This simplifies maintenance, troubleshooting, and performance tuning.

***Related content: Read our guide to [GPU for rendering](https://www.atlantic.net/gpu-server-hosting/gpu-for-rendering-how-it-works-top-10-gpus-and-pro-tips/)***

## How Virtual GPUs Work

The foundation of GPU virtualization starts with the hypervisor. In a virtual environment, the hypervisor manages the distribution of hardware resources to various virtual machines. When using vGPU technology, a physical GPU is partitioned into several virtual instances. Each instance acts as a discrete GPU to the VM it is assigned to.

The process involves a graphics driver installed on the guest operating system and a vGPU manager running within the hypervisor, such as VMware ESXi. The manager intercepts commands from the VM and schedules them on the physical GPU. This ensures that each VM receives its allocated share of GPU resources without interfering with other instances. This architecture supports both Microsoft Windows and Linux environments, making it versatile for various applications.

## NVIDIA Virtual GPU Solutions

NVIDIA leads the market with its comprehensive vGPU software stack. The NVIDIA virtual GPU ecosystem provides several distinct profiles designed for different types of users. These profiles allow administrators to customize the user experience by defining the amount of frame buffer and the number of supported displays.

### NVIDIA vGPU Software Tiers

NVIDIA classifies its offerings into specific editions to meet diverse needs:

- **NVIDIA Virtual PC:** Designed for knowledge workers using office productivity applications and web browsers. It provides a smooth virtual desktop experience.
- **NVIDIA Virtual Workstations:** Built for professional designers, architects, and engineers using compute intensive applications like CAD or 3D modeling.
- **NVIDIA Virtual Compute Server:** Tailored for data scientists and researchers running GPU workloads and machine learning simulations in a data center.

By using these specific software editions, organizations can ensure that every user has the right level of performance, from basic desktop tasks to high performance engineering simulations.

## NVIDIA vGPU Architecture and Profiles

The core of the NVIDIA vGPU system is the ability to split a single physical Nvidia GPU into multiple Virtual GPU (vGPU). Each vGPU has a fixed amount of GPU memory. For example, an NVIDIA RTX card with 24GB of memory could be partitioned into six virtual instances of 4GB each.

These profiles are not just about memory; they also dictate the type of tasks the virtual machine can perform. Some profiles prioritize graphics rendering, while others focus on compute intensive workloads like AI training. When an IT team deploys a vGPU, the guest VM uses the native NVIDIA driver, which allows for near native performance and access to the latest features of the hardware.

## GPU Virtualization Techniques

There are several ways to provide GPU resources to a virtual machine. The choice of technique depends on the required performance level and the number of users sharing the hardware.

### API Remoting

API remoting is a software-based approach where the graphics API calls (such as OpenGL or DirectX) are intercepted at the guest OS level. These calls are then sent over the network to a server that has a physical GPU, which processes the request and sends the rendered frames back.

This technique is useful for office productivity applications and basic tasks. However, it often results in lower performance compared to other methods because of the overhead of intercepting and redirecting API calls. It is rarely used for demanding workloads due to increased latency.

### Pass Through

In a pass through configuration, a single physical GPU is mapped directly to a single virtual machine. The hypervisor steps aside, allowing the guest OS to have exclusive control over the hardware.

**Advantages of Pass Through:**

- **Bare metal performance:** Since there is no virtualization layer, the VM performs exactly like a physical machine.
- **Low latency:** Ideal for the most compute intensive applications.
- **Full hardware support:** The multiple VMs can access every feature of the GPU.

The primary disadvantage is the lack of scalability, because the GPU is dedicated to one VM, you cannot share it among multiple users, which reduces cost efficiency.

### Mediated Pass Through

Mediated pass through is the most advanced technique and serves very common in shared GPU environments. It pairs the speed of direct hardware access with the ability to share a single physical card across many users. Setting this up is difficult and requires specific hardware support, but it is the best way to deliver high-end graphics to multiple virtual machines from a single hardware resource.

In this model, the vGPU manager creates a mediated device that represents a portion of the physical GPU. The guest VM interacts with this mediated device using a native driver. This allows for high performance while still enabling multiple virtual machines to share the same physical hardware. If your hosting provider sells GPUs in 1/8 or 1/4 plans, mediated pass through is most likely being used.

## Use Cases for Virtual GPUs

Virtualizing GPU resources is no longer just for high-end rendering. It has become a standard requirement for several industries.

### Machine Learning and AI Workloads

Data science requires massive parallel processing power. By using virtual GPUs, organizations can create multiple environments for AI training and machine learning without purchasing a separate physical server for every user.

IT teams can spin up virtual machines with specific GPU resources, run a training job, and then reallocate those resources once the job is complete. This flexibility is essential for managing the high costs associated with high performance hardware like the NVIDIA S40 or A100 series.

### Games Development

Game development involves constant iteration on graphics-heavy assets. Developers and artists can use virtual workstations to access powerful GPU hardware from any location. This allows teams to collaborate on game development projects using existing infrastructure while maintaining data security, as the source files and assets remain in the data center rather than on local devices.

### Virtual Desktop infrastructure

As modern applications become more graphics-heavy, even standard knowledge workers require GPU acceleration. Web browsers, video conferencing tools, and video playback all benefit from virtual GPUs. Implementing NVIDIA Virtual PC ensures that the virtual desktop remains responsive, which improves user satisfaction and productivity.

### Hardware and Infrastructure Considerations

To successfully deploy virtual GPUs, the underlying hardware must support specific virtualization features. This includes [Single Root I/O Virtualization](https://semiengineering.com/scalable-i-o-virtualization-a-deep-dive-into-pcies-next-gen-virtualization/)(SR-IOV) and appropriate BIOS settings.

### GPU Selection

The choice of physical GPU determines the density of the virtual environment. High-end data center GPUs are designed to support dozens of concurrent users.

When selecting GPU hardware, its important to consider:

- **Total GPU memory:** This is usually the limiting factor for the number of virtual machines.
- **Compute cores:** More cores allow for faster processing of AI workloads and rendering tasks.
- **Thermal and power limits:** Data center GPUs are built for 24/7 operation under demanding workloads.

### VMWare ESXi and Hypervisor Support

The hypervisor plays a critical role in managing GPU resources. VMware ESXi is widely regarded as a [leading platform for vGPU deployment](https://docs.nvidia.com/vgpu/deployment/vmware/latest/index.html). It provides robust tools for monitoring GPU utilization and fine tuning the allocation of resources. IT teams can monitor temperature, power consumption, and memory usage for each vGPU instance directly from the management console.

### Maximizing Performance and Efficiency

Achieving optimal performance in a virtualized environment requires careful configuration and ongoing management.

### Minimize Latency

Latency is the enemy of a good user experience, especially in virtual desktops and game development. To minimize latency, ensure that the network infrastructure can handle the high bandwidth required for streaming graphics data. Using high-speed interconnects and optimizing the display protocol settings can significantly improve responsiveness.

### Resource Efficiency and Utilization

One of the main goals of virtualization is to avoid wasted resources. Administrators should regularly review GPU utilization metrics. If a group of virtual machines is consistently using only 10% of their allocated GPU power, those vGPU profiles can be downsized, allowing more users to fit on the same physical GPU hardware.

### Data Security

Using virtual GPUs enhances data security by keeping sensitive data in the data center. Because only the pixels are sent to the end-user device, the actual data never leaves the secure server environment. This is particularly important for industries like healthcare and finance where data protection is a primary concern.

## Implementation Strategies for IT Teams

Successfully integrating virtual GPUs into an existing infrastructure requires a phased approach. Start by identifying the specific workload requirements of your users.

1. **Assess User Needs:** Determine if your users are knowledge workers, professional designers, or data scientists.
2. **Select the Right Software:** Choose the appropriate NVIDIA vGPU software edition (Virtual PC, Workstation, or Compute Server).
3. **Test with a Pilot Program:** Deploy a small number of VMs to test application performance and fine tuning settings before a full rollout.
4. **Monitor and Scale:** Use hypervisor tools to track performance and scale the environment as demand grows.

## GPU Accelerated Applications

A wide range of software now supports or requires GPU acceleration to function correctly. This includes everything from the Adobe Creative Suite to specialized CAD software and machine learning frameworks like TensorFlow or PyTorch. By providing virtual GPUs, you ensure that these various applications running in your cloud or on-premise servers have the necessary power to perform at their best.

High performance computing is no longer restricted to those with physical access to specialized workstations. Through the intelligent application of vGPU technology and mediated pass through techniques, organizations can provide bare metal performance to users anywhere in the world. This approach balances the need for high-end compute power with the practical requirements of cost efficiency and centralized management.

As the demand for AI and complex data analysis increases, the role of the virtual GPU will only grow. By understanding the underlying technology and following best practices for deployment, IT teams can [build a scalable, efficient, and powerful computing environment](https://www.atlantic.net/gpu-server-hosting/) that meets the needs of any modern workload.

## **Next-Gen Dedicated GPU Servers from Atlantic.Net, Accelerated by NVIDIA**

Experience unparalleled performance with dedicated cloud servers equipped with the revolutionary NVIDIA accelerated computing platform.

Choose from the NVIDIA L40S GPU and NVIDIA H100 NVL to unleash the full potential of your generative artificial intelligence (AI) workloads, train large language models (LLMs), and harness natural language processing (NLP) in real time.

High-performance GPUs are superb at scientific research, 3D graphics and rendering, medical imaging, climate modeling, fraud detection, financial modeling, and advanced video processing.

[Learn more about Atlantic.net GPU server hosting](https://www.atlantic.net/gpu-server-hosting/)


---

# How Many GB (Gigabytes) Are in a TB (Terabyte)?

> URL: https://www.atlantic.net/vps-hosting/how-many-gb-in-a-tb-and-what-can-you-do-with-it/ | Published: 2026-01-25 | Updated: 2026-06-23 | Author: Richard Bailey

When reviewing [cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) options or purchasing physical hardware, you will frequently encounter the term “terabyte” (TB). Whether it refers to the storage capacity of a hard drive or the monthly data transfer limit of a server, understanding exactly what this unit represents is essential for planning your infrastructure.

Confusion often arises because the definition of a terabyte changes depending on who you ask—or rather, which system they use to count. This guide clarifies the difference between binary and decimal calculations, breaks down how many gigabytes are in a terabyte, and explains what 1 TB allows you to do in a real-world server environment.

## How Many Gigs Are in a Terabyte?

The answer depends on whether you view the data through a decimal (base 10) or binary (base 2) lens. In the context of consumer product marketing and general data storage, the standard definition is:

**1 Terabyte (TB) = 1,000 Gigabytes (GB)**

This equates to 1,000,000 megabytes (MB) or 1,000,000,000,000 bytes. Storage manufacturers prefer this system because it is clean and standardized. If you buy a 1 TB external hard drive, the packaging assumes this decimal definition.

### The Binary System Exception

Computers operate on a binary system (0s and 1s). In this system, units grow by powers of two ($2^{10}$).

**1 Tebibyte (TiB) = 1,024 Gibibytes (GiB)**

While a terabyte technically refers to 1,000 gigabytes (GB), computer operating systems (like Windows) often calculate space using binary math but still display the standard “TB” or “GB” labels. This is why a one terabyte drive might appear to have only ~931 GB of usable space when connected to a computer.

### Mebibyte Versus Megabyte: The 1998 Standard

To resolve this confusion, the International Electrotechnical Commission (IEC) established new standards in 1998. They introduced prefixes like “kibi,” “mebi,” “gibi,” and “tebi” to denote binary values.

- **Megabyte (MB):** 1,000,000 bytes (Decimal)
- **Mebibyte (MiB):** 1,048,576 bytes (Binary)

Despite these official standards, the industry largely ignores the distinction. Most hosting providers and hardware vendors use “TB” to mean 1,000 GB, while IT professionals often calculate based on 1,024. For the purpose of planning storage capacity or cloud storage, it is safer to assume the decimal standard (1,000 GB) to avoid overestimating your available resources.

## What Is Data Transfer vs. Bandwidth?

When you see “1 TB” on a hosting plan, it often refers to data transfer rather than disk space. While these terms are frequently used interchangeably, they represent different concepts.

- **Data Transfer:** This is the total volume of information moved from one location to another over a specific period (usually a month). If your server has a 1 TB transfer limit, you can send 1,000 GB of data to visitors before incurring overage charges.
- **Bandwidth:** This refers to the capacity of the connection at a single moment, typically measured in megabytes per second (Mbps).

Think of bandwidth as the width of a pipe and data transfer as the amount of water that flows through it over a month. A server with 1 TB of bandwidth (common terminology for monthly transfer) provides a massive allowance for traffic.

### Throughput and Signal Quality

High bandwidth does not guarantee speed if the throughput is low. Throughput measures how much data actually reaches its destination successfully. Factors like network congestion or packet loss can reduce throughput, meaning that even with a high-capacity connection, large files may load slowly.

## How Much Data Fits in One Terabyte?

Calculating how much storage or transfer capacity you need requires estimating the size of your files. Digital storage requirements vary wildly based on file compression and resolution.

The following examples illustrate what 1 TB can accommodate.

### Digital Images

High-resolution photos and digital images range from small thumbnails (10 KB) to raw camera files (20 MB+).

- **Average Size:** 1 MB per image.
- **Capacity:** 1 TB can store or transfer approximately 1,000,000 photos.

If you run an e-commerce site, keep in mind that a single page load might require transferring multiple images. If a user views ten items, that counts as ten separate file transfers against your monthly limit.

### Video Content

Video consumes significantly more storage space and bandwidth than text or images.

- **Short Clips:** A 5-minute HD video recorded on a smartphone uses about 500 MB. You could store or stream roughly 2,000 of these clips with 1 TB.
- **Movies:** A feature-length film (standard definition) is about 3 GB. 1 TB holds roughly 330 movies.
- **Streaming:** A minute of high-definition video consumes roughly 100 MB.

Large datasets like video libraries drain resources quickly, many administrators prefer to use third-party cloud services like YouTube or Vimeo for hosting video content, preserving their server’s data transfer for core site functions.

### Documents and System Files

Text-based documents are negligible in size compared to media.

- **Capacity:** Millions of PDFs, Word docs, or emails can fit into a single TB.
- **Impact:** Interactive sites, such as forums where users post comments, consume minimal bandwidth per post. However, if users upload their own personal files or avatars, your storage needs will scale rapidly.

## Real-World Application: 1 TB in Cloud Hosting

Cloud storage and computing environments often include 1 TB of outbound data transfer as a standard baseline. This amount is sufficient for most small-to-medium business websites.

In a cloud server environment, [virtualization](https://www.atlantic.net/vps-hosting/what-is-server-virtualization/) technology partitions a physical server into multiple isolated units. This setup allows you to scale resources. If your application suddenly attracts a large amount of traffic—exceeding your 1,000 GB transfer limit—[cloud platforms](http://www.atlantic.net/cloud-platform/) often allow for “bursting” or easy upgrades to add more transfer capacity instantly.

For healthcare or financial sectors, where you must [protect sensitive data](https://www.atlantic.net/hipaa-compliant-hosting/protecting-patient-data-the-right-way-and-the-wrong-way/), understanding these limits is also a compliance issue. Ensuring you have adequate space for encrypted backups and sufficient bandwidth for secure offsite replication is mandatory.

## Assessing Your Storage Needs

To determine if 1 TB is enough, audit your current data usage:

1. **Calculate Average File Size:** Check the size of your typical image or video assets.
2. **Estimate Traffic:** Multiply the average page size by the number of expected monthly visitors.
3. **Account for Growth:** Always provision more space than you currently need to accommodate system updates, log files, and database expansion.

Whether you are managing a media-heavy website or a simple database, 1,024 GB (gigabytes) (or 1,000, depending on the manufacturer) represents a significant amount of digital storage. By understanding the difference between the binary and decimal system, and distinguishing between disk capacity and transfer limits, you can select the right plan and hardware for your infrastructure.

## Advanced Infrastructure Considerations

In professional environments, real world examples of storage planning often differ from consumer marketing. First, raw capacity does not equal usable space. When you connect physical devices in a [RAID array](https://www.atlantic.net/vps-hosting/how-raid-arrays-improve-performance-and-data-protection/) to protect data, you reserve specific drives for redundancy. This setup provides an equivalent level of safety but reduces total volume; for instance, two 1 TB drives in RAID 1 only create 1 TB of usable storage.

Also think about how file system formatting consumes space. While a decimal terabyte is 1,000 GB, the binary tebibyte used by operating systems is exactly 1,099,511,627,776 bytes. This math explains why you cannot access the full advertised space on a hard drive.

[Bandwidth](https://www.atlantic.net/bandwidth-backup-overages/) calculations require a similar buffer. When you share files or sync databases, network protocols attach kilobytes of header data to every packet. To transfer 1,024 gigabytes of content, you effectively consume more than that in bandwidth due to this overhead.

Finally, consider performance. One gigabyte on a slow mechanical drive is functionally different from one on a high-speed [NVMe SSD](https://www.atlantic.net/dedicated-server-hosting/whats-the-difference-between-hdds-sata-ssds-and-nvme-ssds/). To form a complete idea of your requirements, you must evaluate input/output speed ([IOPS](https://www.atlantic.net/vps-hosting/performance-matters-how-disk-throughput-and-iops-impact-your-business/)) alongside raw capacity.


---

# What Are SSAE 16, SSAE 18, SOC 1, and SOC 2? What Are They For?

> URL: https://www.atlantic.net/hipaa-compliant-hosting/ssae-16-soc-1-soc2-care/ | Published: 2026-01-25 | Author: Alexander Wise

Service organizations that handle sensitive data or financial transactions face constant pressure to demonstrate the reliability of their internal controls. For years, the Statement on Auditing Standards No. 70, better known as SAS 70, served as the primary method for reporting on these controls.

As outsourced services have become the standard, the need for a more precise framework led to the adoption of the Statement on Standards for Attestation Engagements SSAE No. 16, or simply SSAE 16. SSAE 16 was released in April 2010 to replace SAS 70 and became effective on June 15, 2011.

This standard, established by the American Institute of Certified Public Accountants (AICPA), shifted the focus toward a more rigorous examination of a service organization’s systems of control. SSAE 16 was a US auditing standard designed for service organizations to provide insight into their internal controls for clients. Compliance with SSAE 16 was often required by clients, especially in industries where financial reporting is affected. It was designed to align US auditing standards with international reporting requirements, specifically ISAE 3402. While SSAE 16 was the standard for several years, it has since been replaced by SSAE 18, which is the current standard today.

While there are many acronyms used here, it is important for us to explain how service standards have changed over the years. Understanding these standards is necessary for any company using data centers or other outsourced providers to manage their operational activities.

## What Are Auditing Standards? Understanding SSAE 18 and Its Predecessors

Auditing standards are essential guidelines that certified public accountants (CPAs) follow to verify the accuracy, consistency, and reliability of financial statements and other key information. In the United States, the Auditing Standards Board (ASB) of the AICPA serves as the primary authority for developing and issuing these standards. For service organizations, adhering to these auditing standards is necessary, especially when their services impact the financial reporting of user entities.

These standards, such as the historical SSAE 16 and the current SSAE 18, provide a structured framework for reporting on controls at a service organization. This framework is essential for organizations that rely on outsourced services, as it allows user entities to assess the effectiveness of the controls in place at their service providers. By following the standards set by the AICPA, service organizations can demonstrate their commitment to transparency and accountability. Ultimately, strong auditing standards help build trust between service organizations, their clients, and other stakeholders by confirming that controls are properly designed and operating as intended.

## SAS 70

SAS 70 was introduced in April 1992 and was originally intended to help auditors of financial statements understand how a service organization might impact a user organization’s internal controls. Over time, the auditing world began using SAS 70 as a general-purpose security audit. This was a misapplication of the standard. SAS 70 was not a checklist for security; it was a reporting mechanism for financial controls. SAS 70 and its local derivatives were widely adopted as universally accepted audit mechanisms for reporting controls at service organizations.

The AICPA recognized this discrepancy. To correct it, they introduced SSAE 16 in 2011 to provide a fresh approach. SSAE 16 required a service organization’s management to provide a written assertion about the fair presentation of the system description and the suitability of the control design. This added a layer of accountability that was missing from the older framework.

## SAS 70 to SSAE 16

The move from SAS 70 to SSAE 16 marked a significant shift in how service companies reported on their operations. Under SAS 70, the auditor was responsible for describing the controls. Under the newer attestation standards, the service auditor’s role shifted to evaluating and attesting to the service organization’s system, which includes a comprehensive description of infrastructure, software, people, procedures, and data.

This change required service organizations to have a deeper understanding of their own processes. It is no longer enough to simply have controls in place; management must be able to document and assert that those controls are operating effectively. SSAE 16 requires reports to include a detailed description of the service organization’s system. SSAE 16 reports (and now SSAE 18) are considered auditor-to-auditor communications rather than certifications.

## SSAE 16 vs SOC 1

One of the most common points of confusion in the industry is the relationship between the auditing standard (SSAE) and the report type (SOC). To be clear, SSAE 18 (formerly SSAE 16) is the professional standard used by the service auditor to perform the audit. The resulting document is a SOC 1 report. SOC stands for System and Organization Controls (formerly Service Organization Controls).

A SOC 1 report focuses specifically on internal controls over financial reporting. If a service organization provides services that could impact the financial statements of its clients—such as payroll processing, medical billing, or financial data hosting—a SOC 1 report is the appropriate choice. This report helps user entities and their auditors assess the risks associated with the outsourced services.

## SOC 1

When a service organization undergoes a SOC 1 engagement, the service auditor evaluates whether the control objectives are suitably designed. In a Type II report, the auditor also tests the operating effectiveness of those controls over a specific period. This provides assurance to business partners and user organization stakeholders that the service organization’s system is functioning as described.

## SSAE 18: The New Standard

Effective as of May 1, 2017, SSAE 18 is the current governing accounting principle authority for these types of reports. It builds upon the foundation of SSAE 16 but introduces new requirements for risk management and subservice organization monitoring.

The transition to SSAE 18 was driven by a push for transparency in the supply chain. Most service organizations rely on other vendors—known as subservice organizations—to deliver their own services. For example, a software provider might host its application in a third-party data center. Under SSAE 18, the primary service organization must implement appropriate controls to monitor these subservice organizations. This verifies that the entire chain of service remains compliant and secure.

### Six Practical Insights on the SSAE 18 Auditing Process

From an accounting perspective, the move to SSAE 16 and eventually SSAE 18 introduced several practical changes that organizations must understand.

1. **Detailed System Description:** The requirement for a “description of the system” is much more detailed than the older SAS 70 “description of controls.” Management must explain how the entire service is delivered, not just the specific control activities.
2. **Management Assertion:** The written assertion from management is a formal legal statement. It means that the leaders of the service organization take full responsibility for the accuracy of the report.
3. **Global Alignment:** Because SSAE 18 closely mirrors international standards (ISAE 3402), a US-based service organization can use its SOC report to satisfy international business partners.
4. **Design Matters:** The emphasis on “suitably designed” controls means that even if a control is operating effectively, it could still fail the audit if it is not designed to address the relevant risk.
5. **Restricted Use:** The Auditing Standards Board has made it clear that SOC 1 and SOC 2 reports are for restricted use. They are intended for the service organization, its user entities, and the auditors of those user entities. They are not meant to be public marketing documents; SOC 3 reports are available for that purpose.
6. **Continuous Compliance:** Compliance is not a one-time event. It is a continuous cycle of risk assessment, control implementation, and testing.

## SSAE Standards in Action: Organization Controls and Risk Management

For data centers and service companies, maintaining high-quality organization controls is a business requirement. The audit process involves identifying potential risks to the service organization’s system and implementing controls to mitigate those risks. This risk management process is a core component of both SSAE 16 and SSAE 18.

Service organizations must identify the specific risks that could prevent them from achieving their control objectives. These might include risks related to physical security, logical access, or system availability. Once these risks are identified, the organization must design and implement controls to address them. The service auditor’s role is to verify that these controls are in place and, in the case of a Type II report, that they are working as intended.

### Data Centers and SOC Reporting

Data centers are a prime example of why these standards are necessary. When a company moves its servers to a third-party facility, it loses direct oversight of the physical environment. It must rely on the data center to provide security, power, and cooling. An attestation report, such as a SOC 1 or SOC 2, provides the evidence needed to trust the data center’s operational activities.

For a data center, an SSAE 18 examination typically covers controls related to:

- Physical security and access logs
- Environmental protections like fire suppression and UPS systems
- Network monitoring and maintenance
- Backup and disaster recovery procedures

By providing a SOC report, the data center offers a universally accepted audit mechanism that satisfies the compliance requirements of its diverse client base. This reduces the need for each individual client to perform their own audit of the facility.

### Service Auditor Reports Type I And Type II

There are two types of service auditor reports available under the SSAE standards.

**Type I:** This report describes the service organization’s system at a specific point in time. The service auditor reports on whether the description is fairly presented and whether the controls are suitably designed to achieve the specified control objectives as of a certain date.

**Type II:** This report covers a period of time, usually six to twelve months. In addition to the requirements of a Type I report, the auditor tests the operating effectiveness of the controls. This is the preferred report for most user entities because it provides evidence that the controls were functioning consistently throughout the period.

The choice between Type I and Type II depends on the needs of the user organizations. Most business partners require a Type II report to fulfill their own internal audit and compliance mandates.

### The Role of the American Institute of Certified Public Accountants (AICPA)

The AICPA is the body that establishes the standards for attestation engagements. They provide the framework that CPA firms must follow when conducting these examinations. By adhering to AICPA standards, service auditors ensure that their reports are consistent, reliable, and recognized by the financial and regulatory communities.

The AICPA has also been instrumental in developing the SOC 2 and SOC 3 frameworks, which address non-financial controls. While SOC 1 focuses on financial reporting, SOC 2 is based on the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

### Accounting Principle Authority and Compliance

The authority of these standards is recognized across the auditing world. When a CPA firm issues a report under SSAE 18, it is providing a high level of assurance that can be trusted by shareholders, regulators, and clients. This trust is the foundation of the modern service economy. Without a universally accepted audit mechanism, the risk of data breaches and financial misstatements would be too high for many companies to consider outsourcing.

The use of these reports is also common in HIPAA compliance. While a SOC report is not a HIPAA certification, many of the controls tested in a SOC 2 audit overlap with HIPAA security rule requirements. For healthcare organizations, using a service provider with a current SOC 2 report is a major step in performing due diligence on their business associates.

### Subservice Organization Monitoring

As mentioned earlier, the management of subservice organizations is a key element of the new standard. Service organizations can choose two different methods for reporting on these subservices:

1. **The Carve-Out Method:** This method excludes the subservice organization’s controls from the report. However, the service organization must still describe the services provided by the vendor and explain how it monitors those services.
2. **The Inclusive Method:** This method includes the subservice organization’s controls within the scope of the audit. This requires the subservice organization to provide its own written assertion and allow the service auditor to test its controls.

Most organizations use the carve-out method because it is less complex, but the requirement for active monitoring remains. Service organizations must demonstrate that they are reviewing the SOC reports of their vendors, conducting site visits, or using other methods to ensure the subservice organization is meeting its obligations.

### Internal Controls and User Entities

The primary audience for any service auditor report is the user entity. These are the organizations that use the services of the service organization. The user entity’s internal control environment is directly affected by the controls at the service organization.

For example, if a company uses a cloud-based accounting system, the security of its financial data depends on the controls of the cloud provider. The company’s own auditors will look at the provider’s SOC 1 report to determine if they can rely on the data coming out of that system. If the service organization does not have a report, the user entity may be forced to perform its own audit, which is time-consuming and expensive for both parties.

## Benefits of SOC 1 and SOC 2 Reports

SOC 1 and SOC 2 reports are effective tools for service organizations seeking to provide assurance about their internal controls to clients and business partners. A SOC 1 report is specifically designed to address controls relevant to financial reporting, making it necessary for user entities that depend on accurate financial data from their service providers. In contrast, a SOC 2 report evaluates controls related to security, processing integrity, confidentiality, and availability.

The benefits of obtaining SOC 1 and SOC 2 attestation reports are significant. For user entities, these reports offer confidence that the service organization has implemented appropriate controls to protect their interests and support their own compliance requirements. For service organizations, the reports serve as evidence of a strong risk management culture.

Additionally, the process of preparing for and undergoing a SOC 1 or SOC 2 examination often helps service organizations identify areas for improvement within their systems. By addressing gaps and strengthening controls, organizations can reduce the risk of data breaches and other security threats. In today’s environment, SOC 1 and SOC 2 reports have become essential for compliance and risk management.

### SOC 2 and Processing Integrity

For many technology companies, a SOC 2 report is more relevant than a SOC 1. While a SOC 1 helps with financial statements, a SOC 2 provides assurance regarding the security and operational integrity of a system.

Processing integrity is a core component of SOC 2. It verifies that system processing is complete, valid, accurate, timely, and authorized. This is especially important for companies that handle large volumes of data or perform complex computations for their clients. A SOC 2 report proves that the company has the internal controls necessary to prevent data breaches and maintain system reliability.

## Establishing Long Term Trust as Standards Evolve

As technology continues to change, the standards for attestation engagements will also evolve. The ever-growing pool of service providers means that the demand for transparency will only increase. Organizations that stay ahead of these changes by maintaining strong internal controls and regular audit cycles will be better positioned to win the trust of business partners.

The shift from the dated SAS 70 to the modern SSAE 18 represents a move toward greater professional rigor and accountability. By focusing on the service organization’s system as a whole rather than just isolated controls, these standards provide a comprehensive view of operational health.

Relying on a service organization requires a significant amount of trust. Service auditor reports bridge the gap between that trust and the technical reality of the services performed. Whether it is through a SOC 1 report focused on financial reporting or a SOC 2 report focused on security and processing integrity, these documents provide the objective evidence that a service organization is meeting its obligations.

For any service company, the investment in an annual SSAE 18 examination is an investment in its own credibility. It demonstrates a commitment to excellence and a proactive approach to risk management. As the global de facto framework for service organization reporting, these standards remain the most effective way to provide assurance in an increasingly complex world.


---

# What Is PCI Compliance? 12 Requirements, PCI Levels, and Penalties

> URL: https://www.atlantic.net/pci-compliant-hosting/what-is-pci-compliance/ | Published: 2026-01-25 | Updated: 2026-06-23 | Author: Richard Bailey

## **What Is PCI Compliance?**

The Payment Card Industry (PCI) Security Standards Council (which is backed by the leading credit card institutions) developed a set of standards known as the Payment Card Industry Data Security Standard (PCI DSS), to [secure credit card transactions](https://www.atlantic.net/pci-compliant-hosting/four-novel-ways-to-secure-credit-card-payments/) and protect related data.

Payment card companies usually require organizations to comply with PCI standards under their network agreements. PCI standards cover merchant processing and additional requirements such as encryption of Internet transactions.

While there is no specific regulation mandating [PCI compliance](https://www.atlantic.net/pci-compliant-hosting/pci-compliance-in-the-cloud-challenges-and-key-requirements/), court precedent treats it as mandatory for all companies processing payment card data. The Federal Trade Commission (FTC) monitors credit card processing to protect consumers. Organizations processing payment card data must comply with standards to ensure the security of transactions and avoid legal penalties.

This is part of an extensive series of guides about [compliance management](https://www.exabeam.com/explainers/compliance-management/compliance-management-process-regulations-and-tools/).

## ![](https://www.atlantic.net/wp-content/uploads/2022/03/What-is-PCI-Compliance_Why-Is-PCI-Compliance-Important-to-an-Organization-.png)Why Is PCI Compliance Important?

Any organization that handles payment card transactions or data must ensure they comply with [PCI DSS](https://www.atlantic.net/pci-compliant-hosting/pci-dss-4-0-is-mandatory-a-hosting-checklist-for-2026/) and other applicable standards. The data security standards described in PCI DSS help organizations enhance their security profile and protect themselves against the business and legal repercussions of a data breach.

Regardless of an organization’s size, credit card companies such as American Express, Visa, and Mastercard require PCI compliance. Complying with PCI standards:

- ![](https://www.atlantic.net/wp-content/uploads/2021/09/icon-check.png)Allows organizations to accept payment cards or transmit, process, and store payment card data
- ![](https://www.atlantic.net/wp-content/uploads/2021/09/icon-check.png)Reduces the risk of payment card data loss
- ![](https://www.atlantic.net/wp-content/uploads/2021/09/icon-check.png)Reduces the risk of customer identity theft
- ![](https://www.atlantic.net/wp-content/uploads/2021/09/icon-check.png)Enables organizations to detect, prevent, and remediate data breaches

If an organization fails to maintain PCI compliance, it could result in fines or the inability to accept payment cards and online transactions.

## The 12 Requirements of PCI DSS

PCI DSS consists of 12 requirements organized into six goals. These PCI DSS requirements outline the specific security controls an organization must implement to maintain secure systems.

### Goal 1: Build and Maintain a Secure Network and Systems

#### 1. Install and Maintain Network Security Controls

Firewalls acts as the first line of defense, controlling traffic between your internal network and untrusted external networks (the internet). To be PCI compliant, you must configure secure configurations for firewalls and routers.

- **Restrict Traffic:** Configure rules to deny all traffic by default and only allow connections necessary for your specific business processes. Review these firewall and router rule sets at least every six months.
- **DMZ Implementation:** Place web servers in a Demilitarized Zone (DMZ) to separate them from the internal network where card data resides. No direct connections should occur between the internet and the Cardholder Data Environment (CDE).
- **Document Rules:** Maintain a current diagram of your CDE and document the business justification for every open port, protocol, and service allowed through the firewall.

#### 2. Apply Secure Configurations to All System Components

Vendor-supplied default passwords and settings are a primary vector for compromise. Hackers easily guess default credentials.

- **Change Defaults:** You must change all vendor-supplied defaults (passwords, SNMP strings) immediately upon installation. This applies to operating systems, databases, applications, and network devices.
- **Hardening:** Implement only one primary function per server to prevent vulnerabilities in one service from compromising another. For example, do not host a database and a web server on the same machine.
- **Inventory Management:** Maintain a complete and current inventory of all system components within the scope of PCI DSS.
- **Encryption:** Encrypt all non-console administrative access using strong cryptography.

### Goal 2: Protect Account Data

#### 3. Protect Stored Account Data

Minimizing data retention is the most effective way to reduce risk. You should only store cardholder data if absolutely necessary for business needs.

- **Data Retention:** Implement automated processes to delete data when it is no longer needed.
- **Encryption:** Render PAN (Primary Account Number) unreadable anywhere it is stored using strong cryptography like AES-256. Secure key management processes must also be in place, requiring dual control and split knowledge to access encryption keys.
- **Truncation:** If the full PAN is not needed, store a truncated version (generally only the first six and last four digits).
- **Prohibited Data:** Never store sensitive authentication data after authorization. This includes the full magnetic stripe data, the card verification code (CVV/CVC), or the PIN block. Even if encrypted, storing this data is a violation.

#### 4. Protect Cardholder Data with Strong Cryptography During Transmission

When transmitting cardholder data across open, public networks (like the internet or wireless networks), it is vulnerable to interception.

- **Encryption Standards:** Use strong cryptography and security protocols such as TLS 1.2 or higher. SSL and early TLS versions are no longer considered secure.
- **Wireless Security:** Ensure wireless networks transmitting payment card data use industry-best practices for encryption and authentication. Never send PANs via end-user messaging technologies like email or SMS.

### Goal 3: Maintain a Vulnerability Management Program

#### 5. Protect All Systems Against Malware

[Malware](https://www.atlantic.net/hipaa-compliant-hosting/what-is-malware-how-it-works-and-how-to-remove-it/) is a constant threat to data security.

- **Antivirus Software:** Deploy anti-malware software on all systems commonly affected by malicious software.
- **Active Scanning:** Configure software to perform periodic scans and generate audit logs.
- **Anti-Phishing:** Ensure mechanisms are in place to detect and block phishing attacks.
- **System Evaluations:** For systems not commonly targeted by malware (like mainframes), perform periodic evaluations to confirm that antivirus software is not required.

#### 6. Develop and Maintain Secure Systems and Software

Vulnerabilities in software applications provide an entry point for attackers.

- **Patch Management:** Install critical security patches within one month of release. This applies to operating systems, databases, and third-party applications.
- **Secure Coding:** Train developers in secure coding techniques (e.g., OWASP Top 10) to prevent common issues like SQL injection and cross-site scripting (XSS).
- **Environment Separation:** strictly separate development/test environments from production environments. Never use live cardholder data for testing or development.
- **Change Control:** Follow formal processes for all changes to system components to ensuring security impact is analyzed before deployment.

### Goal 4: Implement Strong Access Control Measures

#### 7. Restrict Access to Cardholder Data by Business Need to Know

Access to sensitive cardholder data should be restricted to only those individuals whose job requires it.

- **Least Privilege:** Grant users the minimum level of access necessary to perform their job functions.
- **Role-Based Access Control (RBAC):** Define access rights based on job classification and function rather than identity.
- **Access Control Systems:** Configure systems to deny all access unless explicitly allowed.

#### 8. Identify and Authenticate Access to System Components

Every user with access to the CDE must have a unique ID.

- **Unique IDs:** Never use shared or group accounts (e.g., “admin” or “root”) for system administration. This ensures that actions can be traced to a specific individual.
- **Multi-Factor Authentication (MFA):** Implement multi factor authentication for all non-console access into the CDE for administrators and for all remote network access.
- **Password Policies:** Enforce strong password policies, including minimum length, complexity, and rotation that meets PCI requirements.
- **Lockout Mechanisms:** Lock out user IDs after not more than six failed attempts. Set the lockout duration to a minimum of 30 minutes or until an administrator resets it.

#### 9. Restrict Physical Access to Cardholder Data

[Physical security](https://www.atlantic.net/hipaa-compliant-hosting/data-center-physical-security-hipaa-compliance/) is as mandatory as digital security. If an attacker can physically access your servers or credit card terminals, they can bypass many digital controls.

- **Access Controls:** Use badge readers, cameras, and locks to restrict physical access to sensitive areas like server rooms and data centers.
- **Visitor Procedures:** Log all visitors, issue visitor badges, and keep a log of entry and exit times. Retain this log for at least three months.
- **Media Control:** Strictly control and track the movement of any media (paper, backup tapes, USB drives) containing cardholder data security.
- **Device Inspection:** Periodically inspect Point of Interaction (POI) devices, such as card skimmers or terminals, for tampering or substitution.

### Goal 5: Regularly Monitor and Test Networks

#### 10. Log and Monitor All Access to System Components and Cardholder Data

Without logging, you cannot detect or analyze a security compromise.

- **Audit Trails:** Link all access to system components to a specific users unique ID.
- **Access Logs:** Capture details such as user ID, type of event, date and time, success or failure indication, and origination of the event.
- **Retention:** Retain audit trail history for at least one year, with a minimum of three months immediately available for analysis.
- **Review:** Regularly review logs for system components that store, process, or transmit sensitive payment data. Use automated tools to detect anomalies.

#### 11. Test Security of Systems and Networks Regularly

New vulnerabilities appear daily. Maintaining PCI compliance requires active testing.

- **Vulnerability Scanning:** Run internal and external network vulnerability scans at least quarterly and after any significant change in the network. External scans must be performed by an Approved Scanning Vendor (ASV).
- **Penetration Testing:** Perform external and internal [penetration testing](https://www.atlantic.net/vps-hosting/best-penetration-testing-practices-you-need-to-know/) at least annually to validate that your segmentation and security controls work as intended.
- **File Integrity Monitoring:** Deploy file integrity monitoring (FIM) tools to alert personnel to unauthorized modification of critical system files.

### Goal 6: Maintain an Information Security Policy

#### 12. Support Information Security with Organizational Policies and Programs

Technology alone cannot secure an environment; you need strong governance.

- **Policy Creation:** Establish, publish, and maintain a security policy that addresses all PCI compliance requirements. Review this policy at least annually and update it when the environment changes.
- **Risk Assessment:** Perform an annual risk assessment to identify threats to customer data.
- **Personnel Screening:** Screen potential hires to minimize the risk of internal attacks (e.g., background checks within the limits of local law).
- **Incident Response:** Develop and test an incident response plan to ensure you can respond immediately to a data breach. Designate specific personnel to be available 24/7 for alerts.

## **What Are the Four Levels of PCI Compliance?**

Here are the PCI compliance levels that apply to merchants based on the volume of payment card transactions they process.

## Merchant Levels

![](https://www.atlantic.net/wp-content/uploads/2022/03/What-is-PCI-Compliance_PCI-Compliance-Level-1.png)

### Level 1

A Level 1 merchant processes 6 million or more transactions per annum (e.g., a large international corporation). This compliance level requires third-party Quality Security Assessors (QSAs) to audit the merchant’s practices. QSAs define the audit scope, review the merchant’s data storage and paper trails, and determine PCI compliance in annual Reports on Compliance (ROCs).
 Level 1 merchants must also perform quarterly network scans to complement the yearly audits using Approved Scanning Vendors (ASVs). Each merchant must then submit Attestation of Compliance (AOC) forms.

![](https://www.atlantic.net/wp-content/uploads/2022/03/What-is-PCI-Compliance_PCI-Compliance-Level-2.png)

### Level 2

A Level 2 merchant processes less than 6 million but more than 1 million transactions per annum (e.g., a medium-sized corporation). PCI compliance level 2 does not require a third-party auditor, but Level 2 merchants must submit ROCs based on internal audits responding to Self-Assessment Questionnaires (SAQs).
 Level 2 merchants must also use ASVs to perform quarterly network scans and submit AOC forms.

![](https://www.atlantic.net/wp-content/uploads/2022/03/What-is-PCI-Compliance_PCI-Compliance-Level-3.png)

### Level 3

A Level 3 merchant processes less than 1 million but more than 20 thousand transactions per annum (e.g., a small corporation). The third compliance level does not require external audits or ROCs—only the completion of annual SAQs.
 A Level 3 merchant must also perform quarterly network scans and submit AOC forms.

![](https://www.atlantic.net/wp-content/uploads/2022/03/What-is-PCI-Compliance_PCI-Compliance-Level-4.png)

### Level 4

A Level 4 merchant processes fewer than 20 thousand transactions annually. This compliance level requires merchants to complete annual SAQs and AOCs, in addition to quarterly network scans performed by ASVs.
 A Level 4 merchant must use qualified resellers and integrators to install, integrate, and service point-of-sale applications and terminals.

## Service Provider Levels

![](https://www.atlantic.net/wp-content/uploads/2022/03/What-is-PCI-Compliance_PCI-Compliance-Level-1.png)

### Level 1

A Level 1 service provider is one that is storing, processing, or transmitting more than 300,000 credit card transactions annually.

.

![](https://www.atlantic.net/wp-content/uploads/2022/03/What-is-PCI-Compliance_PCI-Compliance-Level-2.png)

### Level 2

A Level 2 service provider handles fewer than 300,000 transactions per year.

.

## PCI DSS Versions

### PCI DSS 1.0

PCI DSS 1.0 was introduced in December 2004 as the first formal attempt to create a unified set of security standards for the payment card industry. Prior to this, individual credit card brands like Visa and Mastercard had their own security programs.

PCI DSS 1.0 established the foundation for protecting cardholder data by requiring organizations to implement basic security measures such as [firewalls](https://www.atlantic.net/vps-hosting/waf-web-application-firewall/), password protection, and encryption. Key requirements included building and maintaining secure systems and networks, protecting stored cardholder data, and maintaining a vulnerability management program.

### PCI DSS 2.0

Released in October 2010, PCI DSS 2.0 focused on improving clarity and flexibility in the standards. One of the major changes was the introduction of guidelines for risk-based security approaches, allowing organizations to prioritize remediation efforts based on risk assessments.

Additionally, PCI DSS 2.0 introduced more detailed requirements for encryption, especially around wireless networks, and clarified the responsibilities for third-party service providers in securing cardholder data. This version also expanded on the need for strong access control measures.

### PCI DSS 3.0

Launched in November 2013, PCI DSS 3.0 aimed to address emerging security threats and vulnerabilities, particularly those highlighted by high-profile data breaches in the retail sector. Key updates included stricter requirements for authentication mechanisms, the implementation of more detailed guidance on vulnerability management, and the introduction of physical security controls.

PCI DSS 3.0 placed greater emphasis on continuous monitoring of security controls, rather than treating PCI compliance as a point-in-time assessment. The introduction of regular penetration testing and more frequent vulnerability scans helped organizations proactively manage security risks.

### PCI DSS 4.0

Introduced in March 2022, PCI DSS 4.0 marked a significant evolution in the framework, reflecting the growing sophistication of cyber threats and changes in payment technologies. The new version introduced greater flexibility for organizations to use customized security approaches, allowing them to meet the intent of PCI DSS requirements through methods that fit their specific environments.

PCI DSS 4.0 also emphasized the need for stronger authentication measures, such as more robust [multi-factor authentication](https://www.atlantic.net/managed-services/multi-factor-authentication/) (MFA) and password controls. Additionally, this version of PCI DSS emphasizes the requirement for real-time threat detection and response capabilities.

## Is PCI Compliance Legally Required?

While there is no specific federal law in the United States mandating PCI compliance, companies that process, store, or transmit payment card data are contractually required to comply with the PCI Data Security Standard (PCI DSS).

Major credit card brands, such as Visa, Mastercard, American Express, and Discover, enforce PCI compliance through their network agreements with merchants and service providers. Failure to comply with these contractual obligations can result in significant financial and operational penalties, making PCI compliance functionally mandatory for businesses handling payment card transactions.

In addition, court rulings and state-level regulations have increasingly treated PCI DSS as a de facto standard for demonstrating due diligence in protecting consumer payment card data. Failure to comply may expose organizations to legal action under consumer protection laws, such as those enforced by the Federal Trade Commission (FTC), which holds businesses accountable for securing sensitive financial data.

Noncompliance could also lead to liability in the event of a data breach, increasing the risk of lawsuits and fines under various privacy and security laws, including the California Consumer Privacy Act (CCPA) and the General Data Protection Regulation ([GDPR](https://www.atlantic.net/vps-hosting/gdpr-compliance-for-global-managed-service-providers/)) in Europe.

## Navigating the Validation Process

To validate PCI compliance, organizations must demonstrate they meet the PCI DSS standards.

### Self-Assessment Questionnaire (SAQ)

For Level 2-4 merchants, the SAQ is a PCI Compliance checklist used to self-validate compliance. There are different types of SAQs depending on how you accept credit card payments:

- **SAQ A:** For merchants who outsource all cardholder data functions to compliant third-party service providers and retain no card data.
- **SAQ D:** For merchants who store cardholder data or do not fit into other SAQ categories. This is the most comprehensive type.

### Qualified Security Assessor (QSA)

Level 1 merchants and service providers require an onsite audit by a PCI Qualified Security Assessor. The QSA verifies that all controls are in place and effective. They produce the Report on Compliance (RoC), which is submitted to the acquiring bank.

### Approved Scanning Vendor (ASV)

Regardless of level, most organizations require quarterly external vulnerability scans. An Approved Scanning Vendor is a company authorized by the PCI SSC to perform these scans to validate that the external-facing IP addresses are free of known vulnerabilities.

## Common PCI Compliance Violations

Many organizations fail to maintain compliance due to oversight or negligence. Common violations include:

- **Storing Prohibited Data:** While merchants may store the Primary Account Number (PAN) if encrypted, storing “sensitive authentication data” is strictly forbidden. A frequent technical oversight occurs when debug logs or troubleshooting files inadvertently capture the full magnetic stripe data (Track 1 or Track 2 data) or the CVV2/CVC2 values during transaction processing.
- **Weak Access Controls:** This often manifests as the use of generic, shared administrative accounts (e.g., “admin,” “root,” or “administrator”) rather than unique user IDs. Additionally, failing to immediately revoke access credentials for terminated employees or vendors creates “orphan accounts” that attackers can exploit.
- **Unencrypted Transmission:** Violations occur when credit card data is transmitted over open protocols like FTP, Telnet, or HTTP. This also extends to internal ticketing systems or chat applications (like Slack or Microsoft Teams) where support staff might improperly copy-paste PANs to troubleshoot customer orders.
- **Outdated Software:** PCI DSS requirements mandate that critical security patches be installed within one month of release. Organizations often fail this due to a lack of automated patch management for third-party applications (like Java, Adobe Flash, or custom web apps), focusing only on the Operating System.
- **Insecure Wi-Fi:** Operating wireless networks that are not properly segmented via firewalls from the cardholder data environment (CDE) is a major violation. Furthermore, failing to perform quarterly scans for unauthorized “rogue” wireless access points allows attackers to attach hardware to the network physically.

## Penalties and Consequences for Noncompliance

Noncompliance with PCI DSS can lead to severe financial and reputational consequences for organizations. Penalties include:

- **Fines:** Credit card companies can impose fines ranging from $5,000 to $100,000 per month for PCI DSS violations, depending on the severity of the noncompliance and the size of the business.
- **Increased Transaction Fees:** Noncompliant businesses may be subject to higher transaction fees, raising operational costs.
- **Loss of Payment Processing Privileges:** In extreme cases, organizations can lose the ability to process credit card payments, crippling their ability to conduct business.
- **Liability for Data Breaches:** If a data breach occurs due to noncompliance, the organization could be held liable for damages, including the costs of forensic investigations, notification to affected individuals, card reissuance fees, and compensation for fraud losses incurred by cardholders.
- **Reputational Damage:** A data breach resulting from noncompliance can significantly harm an organization’s reputation, leading to a loss of customer trust and long-term revenue.

In sum, while PCI compliance is not technically a legal requirement, the contractual, financial, and legal risks associated with noncompliance make it essential for businesses that handle payment card data.

![](https://www.atlantic.net/wp-content/uploads/2022/03/What-is-PCI-Compliance_How-to-Implement-a-Successful-Incident-Response-Plan-for-PCI-DSS.png)

## How to Implement a Successful Incident Response Plan for PCI DSS

Two major PCI DSS requirements help organizations implement successful incident response plans—Requirement 10 refers to logging and log management, while Requirement 12 addresses documentation, [vulnerability, and risk management](https://www.aquasec.com/cloud-native-academy/vulnerability-management/vulnerability-management/).

In addition to considering these two requirements, you should apply the following steps to build a PCI-compliant incident response plan:

- **![](https://www.atlantic.net/wp-content/uploads/2021/09/icon-check.png)Prioritize assets**—locate critical assets such as applications and sensitive data and classify them according to the risk they present. Assign a budget and protection strategy for each risk category.
- **![](https://www.atlantic.net/wp-content/uploads/2021/09/icon-check.png)Document clear policies**—provide employees with clear procedures for responding to incidents, including details such as roles and responsibilities.
- **![](https://www.atlantic.net/wp-content/uploads/2021/09/icon-check.png)Build your response team**—the [incident response team](https://betterstack.com/community/guides/incident-management/on-call-scheduling) can include full-time incident response personnel or other security or IT employees who take on responsibilities. Every individual must have a clear role.
- **![](https://www.atlantic.net/wp-content/uploads/2021/09/icon-check.png)Educate your employees**—regularly train your staff to promote security awareness and safe business practices. Ensure that all employees learn to identify and avoid infiltration attempts such as social engineering attacks.
- **![](https://www.atlantic.net/wp-content/uploads/2021/09/icon-check.png)Inform stakeholders of the incident response plan**—all stakeholders across the organization should be familiar with the incident response plan. Encourage everyone from management, legal, HR, IT, and development departments to contribute to the plan.
- **![](https://www.atlantic.net/wp-content/uploads/2021/09/icon-check.png)Involve senior management**—your incident response plan cannot succeed without the support of senior management. For example, your organization must budget for incident response tools and procedures.
- **![](https://www.atlantic.net/wp-content/uploads/2021/09/icon-check.png)Test your incident response plan**—use realistic tabletop exercises to test the effectiveness of your incident response plan. Testing your plans allows you to identify and address any weaknesses.

![](https://www.atlantic.net/wp-content/uploads/2022/03/What-is-PCI-Compliance_The-Role-of-SIEM-in-PCI-DSS-Compliance.png)

### The Role of SIEM in PCI DSS Compliance

PCI DSS Requirements 10 and 11.5 include the implementation of regular monitoring of the network and configuration changes. PCI DSS focuses on these two aspects because system logs are critical for investigating and responding to security incidents.

When security auditing is enabled on systems in the cardholder environment, [security information and event management (SIEM)](https://www.exabeam.com/siem-guide/what-is-siem/) systems can be used to monitor systems and generate security alerts. SIEM solutions are able to collect and correlate data from across the IT environment, including a [PCI-compliant hosting](https://www.atlantic.net/pci-compliant-hosting/) environment, and from hundreds of security tools. They normalize security data and generate reports in a suitable format for regular reviews and PCI DSS audits.

## Maintaining PCI Compliance

Achieving PCI compliance is not a one-time event; it is an ongoing process. To effectively maintain secure systems, you must integrate security into your daily business processes and its recommended to hire internal security assessors.

1. **Continuous Monitoring:** Use automated tools to monitor access logs and network traffic 24/7.
2. **Regular Training:** Educate employees on data security standard PCI protocols and the importance of protecting sensitive data.
3. **Vendor Management:** Verify the compliance status of all third-party payment processor partners and hosting providers.
4. **Scope Reduction:** The most effective way to simplify compliance is to reduce the scope. Use tokenization or outsource payment pages to keep payment card industry data off your local networks.

## Partnering with a PCI Compliant Hosting Provider

Navigating the Payment Card Industry Security Standards Council regulations requires expertise and infrastructure. Atlantic.Net provides PCI compliant hosting solutions designed to help you meet these rigorous demands.

Our hosting environment addresses key physical and network security requirements, including:

- **Physical Security:** Our data centers feature multi-layered access controls, including biometric scanners and 24/7 surveillance, satisfying the requirement to restrict physical access.
- **Network Defense:** We provide managed firewalls and intrusion detection systems to protect cardholder data at the network edge.
- **Audit Support:** Atlantic.Net is audited by independent third parties for SOC 2, SOC 3, and HIPAA compliance, providing a solid foundation for your compliance efforts.

By choosing a provider that understands PCI compliance standards, you can focus on your core business while ensuring your customer data remains secure.

## Get Help with PCI Compliance

Do you need [PCI-compliant hosting](https://www.atlantic.net/pci-compliant-hosting/)? Atlantic.Net stands ready to help you attain fast compliance with a range of certifications, such as SOC 2 and SOC 3, HIPAA, and HITECH, all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282), or email us at [sales@atlantic.net](mailto:sales@atlantic.net).

![](https://www.atlantic.net/wp-content/uploads/2022/03/What-is-PCI-Compliance_PCI_PCI-1024x888.jpg)

---

### [PCI Compliant Hosting](https://www.atlantic.net/pci-compliant-hosting/)

*Authored by Atlantic.Net*

- [[Guide] PCI Hosting Solutions | 12-Point PCI-Compliant Hosting Checklist ](https://www.atlantic.net/pci-compliant-hosting/)
- [[Guide] PCI DSS Cybersecurity Requirements: A Practical Guide ](https://www.atlantic.net/pci-compliant-hosting/pci-dss-cybersecurity-requirements-a-practical-guide/)
- [[Blog] RTLS and Healthcare – Can Real Time Location System Security Improve Your Healthcare Operations? ](https://www.atlantic.net/hipaa-compliant-hosting/rtls-and-healthcare-can-real-time-location-system-security-improve-your-healthcare-operations/)
- [[Product]  HIPAA-Compliant Website Hosting Services Provider](https://www.atlantic.net/hipaa-compliant-hosting/)

### [GDPR Compliance](https://www.exabeam.com/explainers/gdpr-compliance/gdpr-compliance-a-practical-guide/)

*Authored by Exabeam*

- [[Guide] GDPR Compliance: A Practical Guide | Exabeam](https://www.exabeam.com/explainers/gdpr-compliance/gdpr-compliance-a-practical-guide/)
- [[Guide] GDPR Fines Structure and the Biggest GDPR Fines to Date ](https://www.exabeam.com/explainers/gdpr-compliance/gdpr-fines-structure-and-the-biggest-gdpr-fines-to-date/)
- [[Whitepaper] 2024 State of the Security Team Research](https://www.exabeam.com/blog/infosec-trends/a-cisos-analysis-the-2024-state-of-security-report/)
- [[Product] Exabeam | AI-Driven Security Operations](https://www.exabeam.com/)

### [DORA Regulation](https://faddom.com/dora-regulation-requirements-penalties-and-compliance-checklist/)

*Authored by Faddom*

- [[Guide] DORA Regulation: Requirements, Penalties & Compliance Checklist](https://faddom.com/dora-regulation-requirements-penalties-and-compliance-checklist/)
- [[Guide] How the DORA Regulation Impacts IT ](https://faddom.com/how-the-dora-regulation-impacts-it/)
- [[Product] Faddom | Instant Application Dependency Mapping Tool​](https://faddom.com/)


---

# RAID Standards and Data Redundancy Guide: RAID 0, 1, 5, 6, 10, 50 Explained

> URL: https://www.atlantic.net/dedicated-server-hosting/raid-0-1-5-6-10-50-advanced/ | Published: 2026-01-25 | Updated: 2026-06-24 | Author: Richard Bailey

Storage systems are absolutely fundamental for the future of the cloud, and there is a hunger for ultra-reliable, high-performance, and expansive storage systems. It is now commonplace to see flash-based storage, SSD arrays, and traditional mechanical disks in the data center. Storage hardware has progressed extensively in recent years, and RAID technology is an ever-present design choice.

To quickly recap, RAID technology underpins nearly every server environment and its purpose is to provide faster [IOPs](https://www.atlantic.net/vps-hosting/performance-matters-how-disk-throughput-and-iops-impact-your-business/) and preserve data integrity. There are several different RAID configurations that perform differently depending on the scenario: RAID that provides superfast I/O, RAID that creates multiple layers of data protection, and RAID that blends both I/O and data protection.

## RAID Standards and Data Storage

Data storage requirements for modern enterprises demand a balance between performance, capacity, and reliability. **RAID**, which stands for **Redundant Array of Independent Disks**, provides a method to manage these requirements by combining multiple storage devices into a single logical unit. Originally described by [researchers at the University of California](https://www2.eecs.berkeley.edu/Pubs/TechRpts/1987/CSD-87-391.pdf), Berkeley in 1987, the technology was initially referred to as a redundant array of inexpensive disks. The shift to independent disks demonstrates the application of RAID technology across various types of disk drives, including high-performance enterprise hardware and [solid-state drives (SSDs)](https://www.atlantic.net/hipaa-data-centers/what-is-solid-state-drives-non-experts-guide/).

## What Is a RAID System?

A RAID system consists of two or more disks working together to improve the performance of the storage system or provide data protection. By spreading data across multiple disks, the system can perform read and write operations faster than a single disk. Additionally, specific RAID configurations allow the system to continue functioning even if a disk fails. This capability is essential for mission-critical storage where downtime or data loss is unacceptable. At Atlantic.Net, we prioritize these configurations to ensure our clients’ high-availability needs are met.

The transition from the early days of simple storage to the modern redundant array of independent disks highlights a shift in how IT professionals view hardware reliability. In the past, hardware was expected to fail, and the goal was to use inexpensive disks to lower costs while adding a layer of safety. Today, the focus is on maximizing the storage system output and ensuring that a drive failure occurs without impacting the availability of file and application servers.

### How Data Redundancy and Fault-Tolerance Work

The primary purpose of implementing RAID standards is to achieve data redundancy and fault-tolerance. Data redundancy involves storing the same data or parity information in multiple locations within the disk array. This ensures that if a drive failure occurs, the information remains accessible from the remaining disks. Redundancy is not a replacement for a backup strategy, but it is a necessary component of high-availability infrastructure.

Fault-tolerance refers to the ability of the storage system to remain operational during a hardware failure. In a fault-tolerant RAID setup, the failure of one disk or, in some cases, multiple disk failures, does not lead to an immediate crash of the entire array. Instead, the RAID controller uses the redundant data or parity calculations to reconstruct the missing information in real time. This allows the administrator to replace the failed drive while the system continues to serve data to users and applications.

Achieving storage fault-tolerance requires a clear understanding of the mathematical trade-offs between different RAID configurations. While adding more disks to an array can increase storage capacity or performance, it also increases the statistical probability that a drive fails. RAID levels mitigate this risk by distributing data and parity block information so that the array can survive a single disk failure or multiple storage devices failing simultaneously.

### The Role of the RAID Controller

A RAID controller manages the physical disks and presents them to the operating system as one or more logical units. This controller can be a physical hardware RAID controller card or a software RAID driver integrated into the operating system. The choice between these two approaches significantly affects the write performance and overall reliability of the RAID storage.

#### Hardware RAID Architecture

Hardware RAID uses a dedicated disk controller to handle parity calculations and data distribution. This offloads the processing requirements from the system CPU, which is beneficial for high-performance environments. Hardware RAID controllers often include their own memory cache to speed up write operations and may feature battery backup modules to [protect data](https://www.atlantic.net/hipaa-compliant-hosting/how-to-best-mitigate-cybersecurity-risks-and-protect-your-data/) during power loss.

A dedicated disk controller typically features its own processor, often referred to as a RAID-on-Chip (ROC). This processor is specifically designed to handle the XOR operations required for parity data. Because the controller has its own memory and processor, it can manage the disk array independently of the host operating system. This is why hardware RAID is preferred for mission-critical storage and high-load accounting systems. We utilize high-performance hardware controllers in our dedicated hosting environments to ensure maximum uptime.

#### Software RAID and RAID Drivers

Software RAID depends on the host system processor to manage the [RAID array](https://www.atlantic.net/vps-hosting/how-raid-arrays-improve-performance-and-data-protection/). While this avoids the cost of a dedicated hardware RAID controller, it consumes system resources. Most modern operating systems include a RAID driver that supports basic RAID configurations like RAID 0, RAID 1, and RAID 5.

The performance of software RAID has improved with the increase in multi-core CPU power, but it still lacks the specialized write-back cache found in hardware RAID. Additionally, software RAID is managed at the operating system level, meaning that if the system crashes or the boot drive fails, recovering the RAID array can be more complex than with hardware-based systems.

## Comparing RAID Standards: Detailed Configuration and Performance Analysis

To select the appropriate storage strategy, one must analyze how different RAID standards utilize multiple drives to achieve specific goals. Below is a detailed breakdown of each configuration.

### RAID 0: High-Performance Striping

RAID 0 is designed for high performance and requires two or more disks. It uses a technique called striping, where data is written across multiple drives in blocks. Because the system can read and write data simultaneously from all disks in the array, it offers the fastest performance for both read and write operations.

- **Minimum Disks:** 2
- **Data Protection:** None. If one disk fails, the entire array is lost.
- **Storage Capacity:** 100% of total disk space.
- **Best Use Case:** Temporary data, video editing scratch disks, and non-critical high-speed caching.

### RAID 1: Disk Mirroring and Data Protection

RAID 1 focuses on data protection through disk mirroring. This **RAID** setup requires at least two disks. Every piece of data is written to both disks simultaneously. Because the same data exists on both drives, the system remains operational if one disk fails.

- **Minimum Disks:** 2
- **Data Protection:** High. Can survive a single disk failure.
- **Storage Capacity:** 50% of total disk space (size of the smallest disk).
- **Best Use Case:** Operating system boot volumes, small file servers, and mission-critical storage for small datasets.

### RAID 5: Distributed Parity and Efficiency

RAID 5 is one of the most common **RAID** standards for enterprise [data storage](https://www.atlantic.net/hipaa-compliant-hosting/pros-and-cons-of-onsite-and-offsite-data-storage/). It requires a minimum of three disks and uses block-level striping with distributed parity. Parity data is a mathematical shorthand for the data stored on the other disks. In RAID 5, this parity information is not stored on a dedicated parity disk; instead, it is distributed across all disks in the array.

- **Minimum Disks:** 3
- **Data Protection:** Survives a single disk failure.
- **Storage Capacity:** $(N – 1) \times \text{Smallest Disk Size}$
- **Best Use Case:** General file and application servers where capacity and safety must be balanced.

### RAID 6: Double Distributed Parity

RAID 6 expands on the architecture of RAID 5 by using double distributed parity. This RAID level requires a minimum of four disks. By storing two sets of parity data across the disks, the system can withstand two disk failures simultaneously without data loss.

- **Minimum Disks:** 4
- **Data Protection:** Very High. Survives two disk failures occurring simultaneously.
- **Storage Capacity:** $(N – 2) \times \text{Smallest Disk Size}$
- **Best Use Case:** Large storage arrays with high-capacity drives where rebuild times are long.

### RAID 10: Striping and Mirroring (Nested RAID)

[RAID 10](https://www.atlantic.net/hipaa-data-centers/raid-10/), also known as RAID 1+0, is a hybrid RAID configuration that combines RAID 1 and RAID 0. It requires at least four disks. In this setup, disks are mirrored in pairs, and then those mirrored pairs are striped.

- **Minimum Disks:** 4 (must be an even number)
- **Data Protection:** High. Can survive multiple failures if they occur in different mirrored pairs. If both drives in a single mirrored pair fail, the array will fail.
- **Storage Capacity:** 50% of total disk space.
- **Best Use Case:** High-load accounting systems, databases, and [virtualization](https://www.atlantic.net/vps-hosting/what-is-server-virtualization/) hosts.

### RAID 50: Striping of Parity Arrays

RAID 50, or RAID 5+0, combines the distributed parity of RAID 5 with the striping of RAID 0. It requires a minimum of six disks. This configuration consists of multiple RAID 5 sets that are then striped together.

- **Minimum Disks:** 6
- **Data Protection:** High. Survives one failure per RAID 5 sub-set.
- **Storage Capacity:** $(N – \text{number of sub-sets}) \times \text{Smallest Disk Size}$
- **Best Use Case:** Large-scale data storage requiring a balance of write speed and redundancy.

## Comparing RAID Performance Improvements and Technical Constraints

When evaluating **RAID** standards, the “write penalty” is a primary technical constraint. In parity-based systems like RAID 5 and RAID 6, every write requires the controller to read existing data, calculate new parity information, and then write both the data and parity back to the disks. This “Read-Modify-Write” cycle can slow down performance during heavy write operations.

### Performance Metrics Table (2026 Standards)

| **RAID Level** | **Read Performance** | **Write Performance** | **Fault-Tolerance** |
| --- | --- | --- | --- |
| RAID 0 | Excellent (Linear) | Excellent (Linear) | None |
| RAID 1 | High (Simultaneous) | Standard (No Gain) | 1 Disk |
| RAID 5 | High | Low (Parity Penalty) | 1 Disk |
| RAID 6 | High | Very Low (Double Penalty) | 2 Disks |
| RAID 10 | Excellent | High | 1 Disk per Mirror |
| RAID 50 | High | Moderate | 1 Disk per Sub-set |

## Managing Drive Failure and Recovery

When a drive failure occurs, the behavior of the RAID array depends on its configuration. In a fault-tolerant system, the RAID controller will alert the administrator through system logs, email notifications, or audible alarms.

In a RAID 1, 5, or 6 array, the system enters a degraded state. While the data remains accessible, the system is no longer protected against further failures in the same redundancy group. It is essential to replace the failed disk immediately. Once a new disk is inserted, the RAID controller begins the process to recover data and rebuild the parity information or mirrored data.

During the rebuild process, disk performance may be reduced as the RAID controller prioritizes data reconstruction. For mission-critical storage, we recommend using a hot spare disk. A hot spare is an idle disk already installed in the system that the RAID controller can automatically use to replace a failed drive.

## **Conclusin**

RAID technology is a critical element of data storage strategy for any IT department in 2026. By understanding the different RAID standards, IT professionals can design storage systems that meet the specific needs of their organization. Whether the priority is maximizing disk space, ensuring high performance, or creating a fault-tolerant environment, there is a RAID setup available to meet the challenge.

Implementing the correct RAID level ensures that when a drive failure occurs, the impact on the business is minimized. Through a combination of striping, mirroring, and parity, RAID provides the data protection necessary for modern server environments.


---

# Performance Matters – How Disk Throughput and IOPS Impact Your Business

> URL: https://www.atlantic.net/vps-hosting/performance-matters-how-disk-throughput-and-iops-impact-your-business/ | Published: 2026-01-25 | Updated: 2026-05-30 | Author: Richard Bailey

Whether your server runs an application, a website, a database, a file server, or any other service, storage performance is frequently the most overlooked aspect of a server environment. Yet, the speed of your storage system is often the primary factor in delivering a responsive product to your users.

To ensure your infrastructure meets business demands, you must understand the technical metrics that define speed: disk throughput and disk IOPS (Input/Output Operations Per Second). Furthermore, understanding other factors about the underlying storage technology—from traditional hard disk drives to modern solid state drives—allows you to select the optimal performance tier for your workload.

## What Is Disk Throughput?

**Disk throughput** is the measurement of how fast your storage device can read or write data per second. You have likely seen this number when examining specifications for a hard drive (HDD) or a new solid-state disk (SSD). This metric is typically measured in MB/s (megabytes per second).

Throughput measures the sheer volume of data moved. It is the bandwidth of your storage pipe. For example, if you copy a large video file from one folder to another, the speed at which that progress bar moves is your throughput.

Throughput measures are heavily influenced by the interface used. Traditional hard disk drives and SATA SSDs use the SATA interface, which was originally designed for spinning disks. The SATA interface has a theoretical limit of 600 MB/s. In contrast, NVMe SSDs connect directly to the PCIe bus, bypassing the legacy SATA bottleneck and allowing for significantly high throughput.

### Comparative Storage Performance by Device Type

To visualize the difference storage technology makes, consider the maximum sustained transfer rates for common enterprise drives:

- **HDD:** ~150 MB/sec
- **SATA SSD:** ~600 MB/sec
- **NVMe SSD:** ~7200 MB/sec

Even if a drive is rated for a specific maximum speed, actual performance varies based on the application, data block size, number of users, and server load. Sequential operations (like streaming media) usually reach these maximums, while random operations (like database queries) often yield lower throughput.

## What Are Disk IOPS?

**IOPS (Input/Output Operations Per Second)** is a specific measurement of HDD or SSD performance that tracks the number of individual read/write operations a storage device can complete in one second.

While throughput focuses on the volume of data (MB/s), IOPS measures the number of actions. Think of throughput as the speed of a car (mph) and IOPS as the number of passengers the car can drop off at different houses in an hour.

There is a direct mathematical relationship between these two metrics that system architects must calculate to avoid bottlenecks. The formula is:

**Throughput (MB/s) = IOPS times Block Size (KB) / 1024**

This equation reveals why high IOPS does not always equal high throughput. If your application writes data in tiny 4KB chunks (common in databases), you might achieve high IOPS but low total throughput. Conversely, writing large 1MB files (common in video rendering) yields high throughput but a low IOPS count. Understanding the “Block Size” of your specific application is the only way to accurately predict real-world performance.

Higher IOPS numbers matter significantly for transactional workloads. An increased IOPS value ensures that when a doctor pulls medical records, an accountant accesses receipts, and an internal ticketing system archives old files simultaneously, the system remains responsive.

Each of these actions generates write operations and read requests. The total IOPS capability of your storage array determines whether these requests are served instantly or placed in a queue, causing lag.

### Why IOPS Performance Numbers Matter

IOPS performance depends on the mechanical or electronic nature of the drive.

- **HDDs:** Rely on spinning platters and a moving actuator arm. The physical limitation of moving the head to the correct sector creates a ceiling of roughly 400 IOPS for 15K RPM drives.
- **SATA SSDs:** Use flash memory, removing moving parts. An enterprise Intel S4510 SATA SSD can deliver roughly 97,000 random read IOPS.
- **NVMe SSDs:** Utilize the NVMe protocol, designed specifically for flash drives. An Intel Optane DC P5800X can achieve up to 1.5 million IOPS on both IOPS (read and write) metrics.

## The Mechanics of SSD Performance: Garbage Collection and Write Amplification

While SSDs are faster than HDDs, they face a unique challenge known as “Write Amplification.” Unlike magnetic drives, SSDs cannot simply overwrite existing data. They must first erase the entire block of memory before writing new data. This process, combined with “Garbage Collection” (the drive’s internal maintenance), can cause performance inconsistencies under heavy sustained loads.

Enterprise-grade SSDs used by premium providers mitigate this via “Overprovisioning”—reserving a percentage of the flash storage for controller operations. This ensures that even when the drive is nearly full, there are enough empty blocks available to maintain high IOPS without the latency spikes associated with the erase-before-write cycle.

## The Hidden Cost of Latency

Latency is the delay before a data transfer begins following an instruction. In storage, it defines how long the processor waits for the drive to locate the data. Low latency is essential for a snappy user experience.

### Mechanical Latency in HDDs

In traditional hard disk drives, latency is physical. The disk must rotate to the correct position (rotational latency), and the head must move to the correct track (seek time). Spindle speed, measured in Revolutions Per Minute (RPM), directly dictates this delay.

| **Spindle Speed (RPM)** | **Rotational Latency (ms)** |
| --- | --- |
| 4,200 | 7.14 |
| 5,400 | 5.56 |
| 7,200 | 4.17 |
| 10,000 | 3.0 |
| 15,000 | 2.0 |

### Electronic Latency in SSDs

Solid state drives eliminate mechanical delays. A standard enterprise SATA SSD might have a latency of 36 microseconds (0.036 ms), while an NVMe drive can reach as low as 5 microseconds. This massive reduction in latency allows for faster data access and better performance for end-users.

### Small Differences Accumulate

In a single-user environment, a few milliseconds might seem negligible. However, in cloud computing environments with virtual machines serving hundreds or thousands of users, these delays compound.

Consider a scenario where the average number of users increases. If the storage system cannot clear the queue depth fast enough, requests stack up.

| **Concurrent Users** | **Total Latency (ms)** | **Impact** |
| --- | --- | --- |
| 1 | 3 | Negligible |
| 50 | 150 | Noticeable |
| 500 | 1,500 | 1.5 Second Delay |
| 5,000 | 15,000 | 15 Second Delay |

As the user count rises, a suboptimal performance tier like HDD storage creates a bottleneck that no amount of CPU or RAM can fix. Data intensive applications require the low latency of SSDs to prevent the system from locking up under load.

This is frequently exacerbated by the “Noisy Neighbor” effect in multi-tenant cloud environments. If a provider places your VM on the same physical storage array as another client running a high-load database, your IOPS availability drops as the queue fills up with their requests. High-performance hosting mitigates this by using storage technologies capable of handling massive queue depths, ensuring one neighbor’s activity does not degrade your service.

![Differences in Latency infographic](https://www.atlantic.net/wp-content/uploads/2026/01/Differences-in-Latency-infographic.jpg)

## Deep Dive: Queue Depth and Interface Logic

A critical but often ignored factor in storage performance is queue depth. This refers to the number of pending I/O requests a storage controller can handle at one time.

SATA SSDs are limited by the AHCI (Advanced Host Controller Interface) standard, which supports a single command queue with a depth of 32 commands. If your workload performance demands more than 32 simultaneous operations, the drive becomes a bottleneck.

NVMe SSDs use the NVMe protocol, which supports up to 64,000 queues, each with a capacity of 64,000 commands. NVMe reduces CPU overhead by streamlining the interrupt handling process. While AHCI requires uncacheable register reads to issue commands, NVMe uses a streamlined “doorbell” system. This advanced controller logic allows NVMe drives to process parallel requests efficiently, making them the ideal IOPS solution for modern multi-core servers. Focusing solely on the drive speed without considering the interface (SATA vs. NVMe) can lead to poor architectural decisions.

## RAID Configurations and Independent Disks

To achieve higher IOPS and reliable performance, enterprise servers often use a [Redundant Array of Independent Disks](https://www.atlantic.net/dedicated-server-hosting/raid-0-1-5-6-10-50-advanced/) (RAID). A RAID configuration combines multiple disks into a single logical unit.

- **RAID 0:** Stripes data across disks. It increases sequential IOPS and maximum sustained bandwidth but offers no redundancy.
- **RAID 1:** Mirrors data. It provides high availability and good read speeds but does not increase write speed efficiently.
- **RAID 10:** Combines mirroring and striping. It offers better performance for random IOPS and high redundancy, making it a preferred choice for database servers.
- **RAID 5/6:** Uses parity. While cost-effective, the calculation of parity data adds latency to write operations, effectively lowering the write IOPS potential compared to RAID 10. This is known as the “Write Penalty,” where a single write request forces the controller to read the data, read the parity, calculate the new parity, and then write both back to the disk.

When planning your storage solution, remember that adding more data disks in a RAID 0 or 10 array generally increases your total IOPS capacity, as the controller can read from multiple sources simultaneously.

## How Does Atlantic.Net Compare?

When evaluating cloud computing providers, you must look beyond the marketing usage of “SSD.” Not all SSD hosting is equal. Storage vendors often throttle IOPS or use lower-grade hardware to save costs.

Atlantic.Net built its cloud offering with a focus on performance characteristics and redundancy. Independent benchmarks reveal significant differences when comparing Atlantic.Net standard performance benchmark against AWS and Azure.

### Input Output Operations Per Second Comparison

**IOPS numbers** act as the primary benchmark for transactional speed.

- **Atlantic.Net:** Averages 9,525 IOPS per server.
- **AWS:** Averages 3,020 IOPS per server.
- **Azure:** Averages 446 IOPS per server.

Atlantic.Net provides IOPS capabilities that are up to 215% higher than AWS and over 2000% higher than Azure standard tiers.

### Throughput Comparison

High throughput is essential for large files, backups, and streaming.

- **Sequential Disk Writes:** Atlantic.Net averages **192.92 MB/s**, compared to AWS at 129.8 MB/s and Azure at 65.71 MB/s.
- **Random Disk Writes:** Atlantic.Net averages **34.63 MB/s**, outpacing AWS (12.70 MB/s) and Azure (22.38 MB/s).

This data demonstrates that for the same cost, Atlantic.Net offers a storage drive infrastructure that processes more data faster, avoiding the performance bottlenecks common in restrictive public cloud environments.

## Selecting the Right Drive for Specific Situations

Not every workload requires an NVMe SSD delivering a million IOPS. Choosing the correct storage technology depends on your specific IOPS requirements and throughput measures.

### 1. Archival and Backup (HDD)

Traditional hard disk drives remain relevant for cold storage. If you need to store terabytes of archived data that users essentially never access, the high latency and low random read IOPS of HDDs are acceptable trade-offs for the low cost per gigabyte.

### 2. General Web Hosting (SATA SSD)

For standard web servers, corporate intranets, or dev/test environments, SATA SSDs provide a massive upgrade over HDDs. They eliminate mechanical seek times and offer enough input output operations per second to handle moderate traffic without lag.

### 3. Mission-Critical Databases (NVMe SSD)

For data intensive applications, e-commerce platforms, and high-frequency trading, NVMe SSDs are the standard. The ability to handle a massive queue depth and deliver extremely low latency ensures that outstanding IOs never stall the CPU. If your performance required metric involves thousands of concurrent transactions, NVMe is the only logical choice.

## Performance Characteristics Checklist

When auditing your current infrastructure or planning a new deployment, evaluate these critical metric points:

1. **Workload Type:** Is it sequential (streaming/backup) or random (database/email)?
2. **Block Size:** Data block size affects performance. Small blocks (4k) stress IOPS; large blocks (64k+) stress throughput.
3. **Read/Write Mix:** A system doing 90% writes (like a log server) needs a different RAID configuration than one doing 90% reads (like a web server).
4. **Interface Limits:** Ensure your backplane supports the speed of your drives. Putting an NVMe drive in a SATA-limited path (via adapters) results in suboptimal performance.
5. **Driver Support:** specialized storage drivers (like VirtIO for KVM) are necessary to pass the physical speed of the disk through to the virtual machines.

## The Bottom Line

Storage performance is not just a spec sheet number; it is the foundation of user satisfaction. While HDDs range lowest in cost, their mechanical nature makes them unsuitable for modern, high-traffic applications. Solid state drives, particularly those using the NVMe interface, outperform HDDs by orders of magnitude in both random IOPS and sequential IOPS numbers.

If your business relies on how fast data is processed, high-speed databases, or real-time application delivery, you must prioritize IOPS input output operations and throughput measures.

Atlantic.Net offers [storage solutions](https://www.atlantic.net/cloud-platform/block-storage/) designed to eliminate the guesswork. With high availability architecture and performance that consistently beats major competitors, we ensure your data processed metrics never hit a wall. Whether you need the raw speed of NVMe or the density of SATA, our platform delivers the ideal IOPS value for your budget.

**Related Guides:**

- [HIPAA Compliant Hosting Solutions](https://www.atlantic.net/hipaa-compliant-hosting/)
- [PCI-Compliant Hosting Solutions](https://www.atlantic.net/pci-compliant-hosting/)
- [What Are Managed Services?](https://www.atlantic.net/managed-services/what-are-managed-services/)

**Related Products:**

- [Atlantic.Net Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/)
- [Atlantic.Net HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)
- [Atlantic.Net GPU Hosting](https://www.atlantic.net/gpu-server-hosting/)


---

# What Is Dedicated Server Hosting?

> URL: https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/ | Published: 2026-01-25 | Updated: 2026-05-30 | Author: Richard Bailey

## What Is Dedicated Server Hosting?

[Dedicated server hosting](https://www.atlantic.net/dedicated-server-hosting/) is a configuration in which a service provider leases an entire server to a single organization. This means the client has exclusive access to all the hardware resources available on that machine. In this type of server environment, you do not share computing power, memory usage, or disk space with other users. The physical server resides in our data center, which provides the necessary power, cooling, and network infrastructure to keep the machine fully operational around the clock.

This hosting solution is the opposite of shared hosting. In a shared server, many different user accounts reside on the same physical hardware resources. When one user experiences high-traffic, it can consume the same resources needed by others, leading to inconsistent performance.

With a dedicated hosting service, your online business has all the resources of the entire server. This leads to higher stability and faster processing speeds for resource-intensive applications.

## Dedicated Server Hardware

When you rent a dedicated server, you are paying for the physical hardware resources themselves. This includes the processors, storage drives, and RAM. Unlike virtualized infrastructure, where a single physical machine is split into multiple virtual units, a dedicated server gives you direct access to the metal.

The server is not shared; you have complete control over the server configurations. You can choose the specific hardware that matches your workload, such as high-core-count CPUs for heavy data processing or large amounts of memory for database management. The server’s CPU is never impacted by the processes of other users, ensuring that your applications have consistent access to the power they need.

## **Essential Features Of Dedicated Hosting**

To maximize the utility of a dedicated environment, certain features are necessary for enterprise operations.

These include:

- **High-Speed SSD and NVMe Storage:** Modern servers utilize Solid State Drives rather than traditional spinning disks to provide rapid data access and high IOPS.
- **Large RAM Capacities:** Large-scale applications require significant memory to handle concurrent user requests and database caching without slowing down.
- **IPMI and KVM over IP:** These tools allow for out-of-band management, giving you the ability to access the server at the BIOS level even if the operating system is unresponsive.
- **RAID Configurations:** Implementing RAID 1, 5, or 10 ensures that your data remains available even if a physical drive fails.
- **Redundant Power and Network:** Reliable providers ensure the server is connected to multiple power grids and network backbones.
- **Dedicated IP Addresses:** This ensures your reputation is not affected by other users and is required for certain SSL and security protocols.
- **DDoS Protection:** High-level mitigation helps prevent malicious traffic from reaching your hardware.
- **Choice of Operating System:** You have the freedom to select specific versions of Windows Server or various Linux distributions.
- **Physical Security:** The data center environment provides biometric access and surveillance that on-premise solutions often lack.

## Dedicated Hosting vs Shared Hosting vs Cloud Hosting

Understanding which hosting solution fits your needs requires comparing the three primary models. Your choice depends on your budget, technical expertise, and performance requirements.

Shared hosting is the entry-level option. It is cost-effective because the operating costs are split among hundreds of users. However, because you share the same resources, you lack complete control and may suffer from performance dips if a “noisy neighbor” consumes too much bandwidth or CPU. You should choose shared hosting only if you are running a low-traffic personal blog or a small static website.

Cloud hosting and virtualized infrastructure offer more flexibility than shared hosting. They use a hypervisor to split a physical server into several virtual private servers (VPS). This allows for easy scaling, but there is still a layer of software between your application and the hardware. You should choose cloud hosting if your traffic fluctuates and you need to scale resources up or down on demand.

Dedicated server hosting is the highest tier. It removes the hypervisor layer, providing the most computing power possible. You should choose dedicated hosting if your online business runs resource intensive applications, processes sensitive data requiring enhanced security, or handles high traffic volumes that a virtual environment cannot sustain.

### Virtualized Infrastructure vs Physical Hardware

While virtualized infrastructure such as cloud hosting offers flexibility, it cannot always match the raw power of physical hardware. In a virtual environment, a layer of software called a hypervisor manages the resources, which can introduce a small amount of latency. A dedicated server removes this layer, allowing the software to communicate directly with the hardware.

This direct access is why dedicated servers are preferred for high-performance tasks. There is no risk of other users on the same host machine affecting your disk I/O or network speeds. For resource-intensive applications, the consistent performance of a physical server is often the most reliable choice.

### How Dedicated Servers Work

The server acts as a remote computer that is always connected to the internet. When a user visits your website, their browser sends a request to your server’s IP address. Because it is a dedicated machine, all the resources of that server are available to process that single request.

The server’s CPU executes the code, the memory usage handles the active data, and the disk space provides the stored files. Because there are no other users on the machine, the processing happens as quickly as the hardware allows. This results in the high performance that users expect from modern web applications..

## Dedicated Hosting Service Features

A professional dedicated hosting service goes beyond providing a machine. It includes the environment and support needed to keep that machine running at its peak.

- **Network Reliability:** Includes high-speed network connections and redundant power supplies.
- **Continuous Monitoring:** Within our data center, your server is monitored to ensure it remains reachable.
- **Dedicated IP Addresses:** These are unique to your server and are not shared with other customers.

This is beneficial for email reputation and is a requirement for certain types of TLS certificates and specialized networking tasks. Having your own IP addresses ensures that your traffic is isolated and easily identifiable on the network.

### Complete Control and Root Access

When you own the environment, you have root access or administrative privileges throughout. This level of access allows you to install software that might be prohibited on a shared platform. You can change server settings at the kernel level if necessary to optimize performance for a specific application.

With complete control, you can choose the exact operating system that your team prefers, whether it is a specific distribution of Linux or a version of Windows Server. You can also implement custom security configurations that meet the specific compliance requirements of your industry.

This autonomy is essential for developers who need to build and deploy complex software stacks that require specific environment variables or libraries.

### Unmanaged Hosting Services and Root Access

Unmanaged hosting services are a cost-effective choice for those with significant technical expertise. In this model, the service provider is only responsible for the physical hardware and the network connection. You are responsible for the server setup, including the operating system installation and all software configurations.

With root access, you have the highest level of permission on the server. You can install software, change server settings, and manage all user accounts. However, this also means you are responsible for security configurations and backup solutions. If something goes wrong with the software, you must have the technical knowledge to fix it. This is a common choice for developers and IT departments that want total independence.

### Fully Managed Dedicated Hosting

Many businesses prefer to focus on their core competencies rather than server management. Managed services are essential for these organizations. In a fully managed environment, the hosting provider manages the technical details of the server.

- **Initial Setup:** Includes the initial server setup and configuration.
- **Ongoing Maintenance:** Ongoing server monitoring and software updates.
- **Security Patching:** Our support team handles security patches and operating system updates.

Fully managed dedicated servers are ideal for companies that do not have a dedicated system administrator on staff. This managed hosting service ensures that the server remains secure and optimized without requiring the client to have specialized technical knowledge.

### **Enhanced Security and HIPAA-Compliant Options**

Security is a primary concern for any online business. Enhanced security is one of the biggest advantages of dedicated hosting. Because you are the only user on the physical hardware, the risk of a “neighbor” on the same server causing a security breach is eliminated.

With a dedicated machine, you can implement your own security patches and software updates as soon as they are released. You can also install advanced firewalls and [intrusion detection systems to monitor for threats](https://www.atlantic.net/managed-services/intrusion-detection-service/).

This level of data protection is necessary for companies that handle sensitive customer information or financial records. For healthcare organizations, we provide HIPAA-compliant hosting environments that meet all regulatory standards for protecting ePHI (electronic Protected Health Information).

## Other Considerations for Dedicated Hosting

### Technical Requirements and Server Hardware

The server’s CPU is the brain of the machine. More cores and higher clock speeds allow the server to process more data simultaneously. Memory usage, or RAM, is where the server stores data for immediate access. Large databases, like those using Microsoft SQL Server, require significant RAM to maintain high performance.

Disk space is also a consideration. You can choose between traditional hard drives for high-capacity storage or NVMe SSDs for high-speed data access. RAID configurations can be used to protect your data; for example, RAID 1 mirrors data across two drives, so if one fails, the server continues to run. These technical requirements should be based on the specific needs of your applications.

### Data Center Infrastructure

The data center is the [physical location where your server is housed](https://www.atlantic.net/about-us/whitepapers/choosing-a-data-center/). A hosting provider’s data center is designed for maximum uptime.

- **Redundant Cooling:** Features redundant cooling systems to maintain the ideal temperature for server hardware.
- **Backup Power:** Includes backup power systems, such as large battery arrays and diesel generators, to ensure the server remains online during power grid failures.
- **Physical Security:** Access is restricted to authorized personnel and is monitored by surveillance cameras and biometric locks.

This level of data protection is superior to what most businesses can provide in an on-site office closet. By placing your server in a professional data center, you benefit from industrial-grade infrastructure.

### High-Performance Use Cases

Dedicated server hosting is often used for specific high-performance tasks. For instance, a dedicated gaming server requires low latency and high-speed processing to handle the real-time interactions of hundreds of players. When hosting multiplayer online games, the server must be able to process game logic and player data without delay.

The dedicated server hosting model ensures that all the server resources are focused on the game. This prevents the lag and downtime that may occur on a shared server. Beyond gaming, this type of hosting is used for large-scale e-commerce, media streaming, and big data analytics.

Any application that requires high performance and the ability to handle large volumes of simultaneous users will benefit from a dedicated environment.

### Advantages for Online Businesses

High-traffic websites require the robust performance that only a dedicated machine can provide. When a site loads quickly and reliably, it improves the user experience and can lead to higher conversion rates. Search engines also favor fast-loading sites, which can improve your rankings.

The ability to customize the server environment is also an advantage. You can install software specifically designed for your business processes. Whether you are running a custom CRM, a large e-commerce platform, or an internal data processing tool, dedicated hosting provides the computing power to handle the workload without compromise.

### Server Monitoring and Maintenance

Effective server management requires continuous server monitoring. This involves tracking the server’s CPU usage, memory usage, and disk space to ensure there are no bottlenecks.

- **Proactive Alerts:** Monitoring helps in identifying potential hardware failures or security threats.
- **Hardware Maintenance:** Over time, components like fans and power supplies can wear out. As your provider, we handle the replacement of these parts.

This ensures that your physical hardware resources are always in top condition, reducing the risk of unexpected downtime.

### Software Licenses and Operating Systems

When setting up a dedicated server, you must consider the software licenses needed for your environment. If you choose a Windows Server, you will need a license from Microsoft. If you are running a database, you may need a license for Microsoft SQL Server. We can often help you acquire these licenses as part of your hosting package.

The choice of operating system will dictate how you interact with the server. Linux distributions are popular for web servers due to their stability and low cost. Windows Server is often chosen for businesses that rely on Microsoft technologies. Regardless of the choice, having an entire server means you can optimize the operating system specifically for your applications.

### Data Protection and Backup Solutions

With a dedicated server, you have the ability to implement thorough backup solutions. You can back up your data to a second drive on the same server or to an external storage device in the same data center. Some businesses choose to back up their data to a completely different geographic location for maximum safety.

Because you have all the resources of the server, running a backup process does not slow down your website for other users. This allows you to perform frequent backups, ensuring that you can quickly recover in the event of a software failure or a data corruption issue.

### Server Setup and Configurations

Proper server configurations ensure that the server is both fast and secure. This includes:

- **Firewall Setup:** Establishing robust barriers against unauthorized access.
- **Software Optimization:** Tuning the web server software for maximum speed.
- **Database Configuration:** Aligning database settings with your specific application needs.

For an unmanaged server, this requires a person with high technical expertise. For a managed hosting service, we handle this for you based on your requirements.

## How to Pick the Right Hosting Solution

Choosing the right hosting solution involves balancing cost, performance, and management needs. If you are running high-traffic websites or resource-intensive applications, dedicated server hosting is the most effective choice. It provides the exclusive access and robust performance needed to handle modern web demands.

We can help you determine the best path forward. Whether you need the complete control of an unmanaged machine or the convenience of fully managed dedicated hosting, the move to a dedicated environment is a significant step in the growth of your online business.

### Choosing a Dedicated Server Provider

As your partner, we offer 24/7 technical support and a network uptime guarantee. Our team possesses extensive knowledge of server hardware and can provide advice on the best server configurations for your needs.

When evaluating a dedicated server provider, consider the location and quality of their data center. The facility should have enterprise-grade physical security and multiple internet service provider connections.

At Atlantic.Net, we offer both unmanaged hosting services and managed hosting services to cater to different levels of technical expertise.

## Dedicated Server Hosting Summary

Dedicated server hosting offers a level of performance and security that other hosting models cannot match. By renting a physical server, you gain exclusive access to all the hardware resources, ensuring consistent performance for your users. The ability to customize every aspect of the server environment, from the operating system to the security configurations, provides the flexibility that modern businesses require.

With the support of [Atlantic.Net and our high-quality data centers](https://www.atlantic.net/dedicated-server-hosting/), your server becomes a powerful tool for your online business. Whether you are hosting multiplayer online games or managing sensitive enterprise data, dedicated hosting provides the computing power and data protection you need to succeed.

## See Additional Guides on Key IaaS Topics

Together with our content partners, we have authored in-depth guides on several other topics that can also be useful as you explore the world of [IaaS](https://www.atlantic.net/dedicated-server-hosting/what-is-iaas/).

### [Load Balancer](https://www.radware.com/cyberpedia/application-delivery/what-is-load-balancing/)

*Authored by Radware*

- [[Guide] What is a Load Balancer? History, Key Functions, Pros and Cons](https://www.radware.com/cyberpedia/application-delivery/what-is-load-balancing/)
- [[Guide] What Is Global Server Load Balancing (GSLB) & Top 3 Benefits](https://www.radware.com/cyberpedia/application-delivery/what-is-global-server-load-balancing-gslb/)
- [[Guide] 4 Types of DNS Servers and How to Keep Them Secure](https://www.radware.com/cyberpedia/application-delivery/4-types-of-dns-servers-and-how-to-keep-them-secure/)

### [Cloud Cost Management](https://www.finout.io/blog/why-cloud-cost-management-5-tools-to-know-and-tips-for-success)

*Authored by Finout*

- [[Guide] Showback vs. Chargeback: 5 Differences & Evolution in a Cloud World](https://www.finout.io/blog/why-it-showback-is-so-complicated)
- [[Guide] Why Cloud Cost Management, 5 Tools to Know, and Tips for Success](https://www.finout.io/blog/why-cloud-cost-management-5-tools-to-know-and-tips-for-success)
- [[Webinar] Driving a Successful Company-Wide FinOps Cultural Change](https://www.finout.io/blog/driving-a-successful-company-wide-finops-cultural-change)
- [[Product] Finout | Enterprise-Grade FinOps Platform](https://www.finout.io/)

### [What is Cloud Hosting](https://www.atlantic.net/vps-hosting/what-is-cloud-hosting/)

*Authored by Atlantic.Net*

- [[Guide] What Is Cloud Hosting? | Cloud Hosting Defined & Explained ](https://www.atlantic.net/vps-hosting/what-is-cloud-hosting/)
- [[Guide] What is VMware?](https://www.atlantic.net/dedicated-server-hosting/what-is-vmware/)
- [[Blog] 9 Essential Features of Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/9-essential-features-of-dedicated-server-hosting/)
- [[Product] Atlantic.Net Dedicated Server Hosting | High Performance Dedicated Servers](https://www.atlantic.net/dedicated-server-hosting/)

**Related Guides:**

- [HIPAA Compliant Hosting Solutions](https://www.atlantic.net/hipaa-compliant-hosting/)
- [PCI-Compliant Hosting Solutions](https://www.atlantic.net/pci-compliant-hosting/)
- [What Are Managed Services?](https://www.atlantic.net/managed-services/what-are-managed-services/)

**Related Products:**

- [Atlantic.Net HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)
- [Atlantic.Net GPU Hosting](https://www.atlantic.net/gpu-server-hosting/)


---

# HIPAA Data Backup Plan: Requirements for Disaster Recovery and Business Continuity

> URL: https://www.atlantic.net/disaster-recovery/what-are-the-hipaa-compliant-online-data-backup-and-retention-requirements/ | Published: 2026-01-25 | Updated: 2026-06-23 | Author: Richard Bailey

## **Why Is HIPAA Compliance Required for Cloud Backup?**

[Healthcare organizations](https://www.atlantic.net/hipaa-compliant-hosting/healthcare-organizations-embracing-cloud-computing/) must protect sensitive patient records from loss and unauthorized access. The Health Insurance Portability and Accountability Act (HIPAA) sets specific standards for how a covered entity and their business associates handle electronic [Protected Health Information](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) (ePHI). A central requirement of the [HIPAA Security Rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/) is the creation of a formal HIPAA-compliant data backup plan. HIPAA-compliant data backup requirements specify the legal obligations, protocols, and safeguards organizations must follow to ensure proper backup, protection, and recovery of sensitive health data. This plan ensures that an organization can restore key patient information if a system failure, human error, or natural disaster occurs.

A HIPAA-compliant data backup plan is not just a technical recommendation; it is a legal necessity. Under the administrative safeguards of the Security Rule, organizations must establish procedures to create and maintain retrievable exact copies of ePHI. It is critical to understand and comply with all relevant HIPAA rules to avoid legal penalties and ensure the protection of sensitive patient information. This requires a strategy that goes beyond simple file copying. It involves a structured approach to data retention, offsite storage, and regular testing to confirm that backup copies remain viable. Failure to comply with HIPAA-compliant data backup requirements can lead to substantial fines and penalties during compliance investigations.

## **HIPAA Data Backup Plan Requirements**

The primary goal of a data backup plan is to guarantee data availability. When developing this plan, healthcare providers must determine which data is key to their operations. The process begins with a data criticality analysis. It is necessary to determine how much data needs to be backed up based on the organization’s specific needs and risk management strategies. The recovery point objective ([RPO](https://www.atlantic.net/disaster-recovery/rto-vs-rpo/)) measures how much data an organization can afford to lose in a disaster. This analysis identifies which software applications and data sets are mandatory for patient care and business operations during an emergency.

HIPAA regulations do not specify a single technology for backups. Instead, they require that the method chosen provides a reliable way to restore access to patient records. Many organizations now use cloud storage to fulfill these needs, as it allows for geographic separation between the primary data center and the backup location. Using offsite storage ensures that a local event, such as a fire or flood, does not destroy both the original data and the backups.

## **Data Backup Procedures and Frequency**

Effective data backup involves several technical components. To minimize the risk of data loss, many healthcare organizations implement a daily backup schedule. For environments with high volumes of data, an incremental backup strategy is often used. This method only saves the data that has changed since the last full backup, reducing the time and storage space required.

The backup media used must be secure. Whether using physical tapes, hard drives, or cloud-based repositories, the media must be protected by physical safeguards and restricted access. Only authorized personnel should have the ability to manage or move backup data. Additionally, organizations must maintain audit logs that track who accessed the backup systems and when.

## **Backup Plan Implementation**

A functional backup plan requires clearly defined roles and responsibilities. The HIPAA security officer typically oversees the implementation and monitoring of these systems. This individual ensures that the organization follows its internal data retention policy and complies with both federal and state laws regarding medical records.

### **Key Components of a Documented Backup Plan:**

- **Backup Frequency:** Detailed schedules for how often data is backed up.
- **Storage Location:** The geographic and physical locations where the backed-up data is stored.
- **Restoration Procedures:** The specific technical steps required for data restoration.
- **Authorized Personnel:** A list of staff members authorized to initiate a restore.
- **Failure Protocols:** Documented actions for how the organization handles backup failures.

## **Contingency Plan and Disaster Recovery**

A HIPAA-compliant data backup plan is one component of a larger contingency plan. While data backup focuses on the act of saving data, [disaster recovery](https://www.atlantic.net/disaster-recovery/disaster-recovery-plan/) focuses on the process of restoring operations after a disruption. The HIPAA Security Rule requires covered entities to have a written disaster recovery plan that outlines how to restore critical patient information and resume normal operations.

This plan must address different scenarios, ranging from a single server failure to a total site loss. It should include an emergency mode operation plan, which describes how the organization will protect the security of ePHI while operating in an emergency state. This might include using alternative communication methods or temporary hardware setups.

## **Testing and Revision Procedures**

A plan is only effective if it works during a real crisis. HIPAA requires organizations to implement testing and revision procedures. Healthcare providers must regularly test their ability to restore access to data from their backup copies. Testing reveals gaps in the strategy, such as slow restoration times or corrupted files, allowing the organization to fix these issues before an actual disaster occurs. Establishing a strong testing strategy is necessary for planning, implementing, and verifying backup and recovery procedures to ensure data integrity and compliance.

Based on the results of these tests, the organization must perform revision procedures. As the IT environment changes—such as when new software is added or hardware is upgraded—the backup and recovery plans must be updated to reflect the current technical environment. Documentation of these tests and revisions serves as evidence of compliance during regular audits by the Department of Health and Human Services (HHS). Mandatory testing of disaster recovery procedures is required at least once every 12 months to meet compliance.

## **Backup Services and Cloud Integration**

Many healthcare organizations use external backup services to manage their data protection needs. Moving to a cloud-based model can simplify the management of offsite storage and provide better scalability. However, moving data to the cloud does not absolve the covered entity of its HIPAA requirements.

When selecting a provider for backup services, the organization must ensure the vendor can support technical safeguards such as data encryption. [Encryption](https://www.atlantic.net/hipaa-compliant-hosting/why-is-encryption-so-key-to-hipaa-compliance/) is required both for data at rest (on the storage media) and data in transit. For data in transit, we ensure that the acceptable standards are TLS 1.2 or 1.3. This protects ePHI from being read by unauthorized parties even if the data is intercepted.

## **Business Associates and Compliance**

Under HIPAA, any third-party service provider that handles ePHI is considered a business associate. This includes cloud storage providers, managed service providers, and offsite backup companies. Business associates are directly liable for compliance with the HIPAA Security Rule.

The relationship between the covered entity and the service provider must be governed by a [HIPAA Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/). This contract specifies the responsibilities of each party regarding the protection of HIPAA data. It ensures that the business associate implements appropriate administrative, physical, and technical safeguards to protect the privacy and security of the information they handle.

## **Covered Entity Responsibilities**

A covered entity—such as a hospital, clinic, or private practice—retains the ultimate responsibility for the integrity of its patient records. Even when outsourcing to a business associate, the covered entity must perform risk assessments to identify potential vulnerabilities in their data handling processes.

The covered entity must ensure that its staff is trained on the HIPAA-compliant data backup plan. Employees need to understand their roles during an emergency and how to report potential security incidents. Accountability is a key part of the Health Insurance Portability and Accountability Act; therefore, the entity must maintain documentation of all HIPAA-related actions for the required retention period.

## **Business Associate Agreement Essentials**

The BAA is a critical document for regulatory requirements. Our HIPAA-compliant hosting solutions ensure that the BAA explicitly states the associate will:

- **Permitted Disclosures:** Not use or disclose ePHI other than as permitted by the contract or law.
- **Safeguard Implementation:** Use appropriate safeguards to prevent unauthorized use or disclosure.
- **Incident Reporting:** Report any security incidents or breaches to the covered entity.
- **Sub-contractor Management:** Ensure that any sub-contractors agree to the same restrictions and conditions.
- **Data Access:** Provide the covered entity with access to the data when needed.

Regular audits of the business associate’s practices can help confirm that they are adhering to the terms of the agreement and maintaining the necessary HIPAA security standards.

## **Access Controls and Accountability**

Controlling who can access data is a fundamental requirement of the HIPAA Security Rule. Access controls involve using technical mechanisms like unique user IDs, automatic log-offs, and encryption to manage data entry and retrieval. In the context of a HIPAA data backup plan, access controls prevent unauthorized modification or deletion of backup copies.

HIPAA standards require that every action taken on a system containing ePHI can be traced back to a specific user. This is why audit logs are essential. If a data loss event occurs, these logs help investigators determine the cause, whether it was a system error or an intentional act by a malicious actor.

## **Backup Copies and Data Integrity**

The goal of creating backup copies is to ensure data integrity. Data integrity means that the information has not been altered or destroyed in an unauthorized manner. During the backup process, the system must create exact copies of the original files. If the original data is corrupted, the organization must be able to rely on the backup copy to restore vital patient information to its original, accurate state.

Different states may have specific state laws regarding the retention of medical records. A data retention policy must account for both HIPAA requirements and these particular state mandates. For example, some states require that pediatric records be kept for a certain number of years after the patient reaches the age of majority. The backup plan must ensure these records remain retrievable throughout that entire duration.

## Data Retention and Destruction

A HIPAA-compliant data backup plan must address how data is stored, how long it is retained, and how it is destroyed. The HIPAA Security Rule requires covered entities and business associates to establish clear policies and procedures for the retention and destruction of compliance documentation. Typically, the minimum retention period for HIPAA-related policies and logs is six years from the date of creation or last use. However, medical records themselves (the ePHI) are often subject to state-specific retention laws which may exceed this timeframe.

During the retention period, it is critical that backup data is safeguarded with the same level of security as active records. This includes implementing strict access controls, encrypting data stored on electronic media, and ensuring that backup copies are stored in secure, HIPAA-compliant environments. Regular audits and risk assessments should be conducted to verify that data retention policies are being followed.

When the retention period expires, organizations must ensure that ePHI is destroyed in a manner that renders it completely unreadable and unrecoverable. For electronic media, this may involve methods such as degaussing, overwriting, or physically destroying hard drives. Documenting the destruction process is a key part of compliance. By maintaining a proper data retention and destruction policy, healthcare organizations can minimize risk and ensure ongoing [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-in-the-age-of-ai/).

## **Establishing a Resilient Technical Infrastructure**

To maintain a strong HIPAA security posture, healthcare organizations must invest in reliable hardware and software. This includes redundant power supplies, high-availability server clusters, and secure networking equipment. At Atlantic.Net, we provide the technical safeguards and comprehensive backup plans necessary to reduce the risk of prolonged downtime.

In the event of natural disasters, the infrastructure must be able to support the emergency mode operation plan. This might involve failing over to a secondary data center in a different geographic region. The speed at which an organization can restore access to its systems is often measured by the Recovery Time Objective (RTO) and Recovery Point Objective (RPO). These metrics should be clearly defined within the disaster recovery plan.

## **Final Steps in Plan Development**

Creating a HIPAA data backup plan is a continuous process. It begins with a thorough risk assessment to identify where ePHI is stored and how it is protected. From there, the organization develops the technical procedures for data backup and the administrative procedures for disaster recovery and business continuity.

The HIPAA Privacy Rule governs individual privacy rights, access, and disclosures of Protected Health Information (PHI), but does not specify exact data retention periods, which are often determined by state laws.

The final plan must be documented, approved by leadership, and communicated to all relevant stakeholders. Regular training ensures that the HIPAA security officer and the IT staff are prepared to act quickly when needed. Our team at Atlantic.Net is ready to partner with you to ensure your 2026 compliance goals are met through secure, HIPAA-compliant hosting and backup solutions.

Additionally, HIPAA requires certain types of documents to be maintained for six years from the date of their creation or from the date on which they were last in effect, whichever is later.

## Conclusion and Final Thoughts

A detailed data backup plan is a foundation of HIPAA compliance for healthcare organizations. The HIPAA Security Rule mandates that covered entities and business associates implement a contingency plan—including a solid data backup plan—to safeguard the confidentiality, integrity, and availability of ePHI. By establishing regular data backup procedures, utilizing offsite storage, enforcing strong access controls, and encrypting sensitive data, organizations can markedly reduce the risk of data loss.

Regularly testing and updating the backup plan is necessary to ensure it remains effective and aligned with evolving HIPAA regulations and organizational needs. A well-executed backup plan not only supports disaster recovery and business continuity but also helps healthcare organizations maintain the trust of their patients. Ultimately, prioritizing a HIPAA-compliant data backup plan and disaster recovery strategy is fundamental to meeting regulatory requirements, supporting uninterrupted patient care, and ensuring long-term organizational resilience.


---

# Top Dedicated Hosting Options for Ecommerce Platforms

> URL: https://www.atlantic.net/dedicated-server-hosting/top-dedicated-hosting-ecommerce-platforms/ | Published: 2026-01-27 | Updated: 2026-06-04 | Author: Robert Agar

Businesses that engage in ecommerce or run an online store often leverage cloud hosting to support their customer-facing computing environment. Cloud hosting gives companies an efficient way to implement a modern ecommerce platform without maintaining it in an on-premises data center.

This article focuses on the benefits of dedicated servers for ecommerce, and discusses the features customers should look for when selecting a hosting partner. We conclude with an examination of some of the top dedicated hosting providers for ecommerce businesses.

## Why Choose Dedicated Hosting for an Online Store?

Companies that host an ecommerce environment in the cloud have two main options when selecting a hosting plan. The two primary choices are dedicated or shared hosting.

- **Dedicated hosting** provides businesses with exclusive use of a server for their ecommerce site. The customer controls hardware and software configuration and can optimize the server to meet specific ecommerce performance objectives.
- **Shared hosting** uses a server and its resources to host multiple customers. This model is typically less expensive than the dedicated alternative, but entry-level shared hosting does not offer the same level of security or performance.

Ecommerce businesses should adopt the dedicated server approach, especially if they process payments. Companies gain enhanced security, consistent uptime, and improved performance, enabling them to support a revenue-critical ecommerce website effectively.

The table below summarizes the differences in these two cloud hosting models for ecommerce platforms.

| **Feature** | **Dedicated Hosting** | **Shared Hosting** |
| --- | --- | --- |
| Performance | The exclusive use of server resources enables teams to configure them for stable and optimal performance, addressing ecommerce business requirements. | Companies cannot count on consistent or high performance because they share server resources with other clients. |
| Uptime | Ecommerce businesses can obtain better uptime SLAs with dedicated servers. | Uptime can be affected by other clients or by provider-imposed limitations. |
| Security | High security with physical isolation, control over security configuration, and the ability to deploy advanced security tools. | Less secure due to exposure to other tenants’ security vulnerabilities and limited control over security configuration. |
| Customization | Teams have full control to customize the server, including selecting the operating system and application stack to support their online store. | Companies have limited customization options that may not align with ecommerce requirements. |
| Compliance Support | A dedicated server streamlines compliance with PCI-DSS. Providers often offer compliance support and compliant-ready server configurations. | The shared environment may not meet compliance requirements, and providers may not offer compliance support. |
| Scalability | Support vertical scaling by adding resources to support business growth. | Limited vertical scalability, which may require growing ecommerce stores to move to higher shared tiers. |
| Backup and disaster recovery | Automated backups and customized retention periods effectively protect ecommerce data. | Backup and recovery options are often limited. |
| Cost | Higher monthly costs, which can be increased with the addition of managed services. | Low monthly cost. |

## What Makes a Good Ecommerce Hosting Provider?

Ecommerce businesses must carefully select their web hosting provider to ensure they can deliver the performance needed to maintain high customer satisfaction. They must be certain that the hardware, software, and network bandwidth of their dedicated resources can effectively support their ecommerce stores. Companies with limited technical expertise may require more than the raw performance of dedicated servers and opt for a provider that offers managed services.

The decision-makers responsible for choosing a company’s ecommerce hosting provider should look for the following key features that differentiate prospective hosting vendors.

### Strong uptime guarantees

The provider should offer uptime SLAs of at least 99.99%. Premium managed hosting providers support the availability requirements of ecommerce businesses through load balancing and failover options, ensuring online stores remain open.

### Targeted and optimized performance

Ecommerce relies on database and transaction performance to ensure high customer satisfaction. A dedicated ecommerce server environment requires a high-performance infrastructure that delivers low latency and faster data access, with NVMe or SSD storage. Server performance should be optimized to support popular solutions such as WordPress hosting. The objective is to increase conversion rates and SEO rankings by improving page load speed.

### Robust security

Ecommerce businesses need more than the basic security features offered by most web hosting companies. For example, they require SSL certificates to enable the secure exchange of customer financial data, malware scanning, and DDoS protection to ensure the availability of online stores.

### Compliance support

Companies that process customer payments must comply with regulations like PCI-DSS. The hosting provider should support compliance with measures such as end-to-end data encryption and SOC 2-aligned security practices. Many hosting providers offer PCI-compliant servers that address ecommerce business requirements.

### Managed services

Companies may wish to engage the provider for managed services to focus on core business activities. The providers’ technical teams will perform server maintenance and infrastructure setup to support online stores. Small business owners who lack a strong IT team can enjoy the benefits of a dedicated ecommerce solution, like managed WooCommerce hosting, and compete more effectively with larger market rivals.

### Backup and disaster recovery

The web hosting provider must offer automated, encrypted, and validated backups, along with flexible restore options, to support customer-defined recovery point and time objectives. Businesses must be able to recover quickly from operational failures or cyberattacks. Providers can support enhanced resilience through georedundant and offline backups.

### Scalability

Prospective providers should support business growth through vertical and horizontal scaling. They should offer solutions to address seasonal or unexpected traffic spikes. Companies must ensure that hosting services can be scaled to maintain responsiveness as customer volume and monthly visits increase.

### Transparent pricing

The provider should offer clear pricing and a variety of hosting plans to address the needs of different ecommerce businesses. Customers should expect predictable monthly costs with no hidden fees for support or bandwidth.

### A responsive customer support team

A good hosting provider offers excellent customer service from a responsive team that addresses issues before they affect online store availability or performance. The support team must be available 24/7/365 and be ready to assist less tech-savvy users in dedicated server management.

## Top Dedicated Hosting Providers for Ecommerce Sites

The following ecommerce hosting providers offer businesses effective dedicated solutions.

![Atlantic.Net](https://images.surferseo.art/6183f23e-e376-413c-9257-2a970798f11a.png)

### [Atlantic.Net](https://www.atlantic.net/dedicated-server-hosting/)

Atlantic.Net offers multiple dedicated server options that align with ecommerce requirements, including fully managed hosting plans. The company offers custom-built dedicated servers with root access and complete control over resources. Atlantic.Net maintains data centers across multiple regions to minimize latency and improve website responsiveness.

Factors that make Atlantic.Net an excellent choice for hosting an ecommerce platform include:

- Over 30 years of experience providing secure hosting services that support ecommerce;
- High-performance Intel and AMD CPUs supporting multiple operating systems;
- 100% uptime SLA;
- Fully audited and PCI-compliant data centers.

![Kamatera icon](https://images.surferseo.art/a4747ed1-dc06-4219-aeb4-9353f2677e68.png)

### [Kamatera](https://www.kamatera.com/solutions/use-cases/e-commerce/)

Kamatera provides customers with dedicated and shared hosting plans tailored to ecommerce businesses. Server options support Windows and multiple Linux distributions, including Ubuntu and Debian. The company provides 24/7 technical support to address issues before they impact revenue-generating online stores quickly.

Kamatera’s noteworthy features include:

- Flexible monthly and hourly pricing plans;
- Fast server response times and 99.95% uptime guarantee.
- An extensive marketplace of pre-configured apps and services.

![GoDaddy icon](https://images.surferseo.art/fe9abf63-c05f-439a-95bc-aa74a734dc16.png)

### [GoDaddy](https://www.godaddy.com/)

GoDaddy is a popular cloud hosting provider that leverages AI website builder tools to streamline the creation of ecommerce platforms. They offer affordable, reliable WordPress and WooCommerce hosting plans designed to support business growth. The company’s professional email and marketing tools help businesses compete with SEO-friendly websites.

Nice features offered by GoDaddy include:

- One-click installs of the latest application versions;
- Themes and add-ons to customize an ecommerce site;
- GoDaddy Payments is a built-in payment gateway.

![Host Gator icon](https://images.surferseo.art/4b86f28e-e859-45cd-9b66-422c2b9f0808.png)

### [Host Gator](https://www.hostgator.com/web-hosting)

Host Gator offers affordable shared hosting and dedicated, managed, and unmanaged hosting plans. They support small and emerging businesses with one-click WordPress installation and SSD web storage. Their dedicated servers are optimized for ecommerce or other high-performance applications such as gaming platforms.

Host Gator offers features including:

- Support for WHM/cPanel and Plesk control panels;
- One-year free domain registration;
- Unlimited bandwidth to handle high-traffic online stores.

![Kinsta icon](https://images.surferseo.art/bc57dae0-0b32-4922-9660-cf7d8c8bc976.png)

### [Kinsta](https://kinsta.com/)

Kinsta specializes in managed WordPress hosting and offers customers the option of utilizing dedicated servers for their ecommerce platforms. They maintain 27 global data centers, allowing customers to host online stores locally for optimal performance. The MyKinsta dashboard lets teams manage databases, WordPress sites, and applications from a unified, user-friendly interface.

Kinsta’s outstanding features include:

- Edge caching to reduce WordPress page load times by 50%;
- Pricing plans based on required bandwidth or the number of monthly visits;
- A high-performance content delivery network leveraging over 300 worldwide locations.

## Conclusion

Ecommerce companies must partner with a reliable provider that offers dedicated server hosting plans tailored for online stores. We have discussed the reasons to use dedicated servers for ecommerce hosting, the factors to consider when selecting a partner, and some of the top dedicated hosting options. The right provider can help your ecommerce site and your business flourish with the resources required to support a growing customer base.

 


---

# Best Bare Metal Hosting Options for High-Performance Workloads in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/best-bare-metal-hosting-high-performance-workloads-2026/ | Published: 2026-01-27 | Author: Dr. Assad Abbas

High-performance workloads in 2026 require strong compute capability, fast storage, and stable, low-latency networking. These workloads include artificial intelligence and machine learning tasks, [High Performance Computing (HPC)](https://www.atlantic.net/gpu-server-hosting/the-role-of-high-performance-computing-in-advancing-ai-for-climate-solutions/) jobs, real-time analytics, big data processing, and latency-sensitive trading or streaming systems. Small changes in throughput or latency can lead to overlooked insights, failed service targets, or poor user experience. Predictable performance is required alongside high processing capacity.

However, shared and virtualized platforms often struggle to provide this level of stability. In multi-tenant environments, workloads compete for the same resources, which creates noisy neighbor effects. Hypervisor overhead also reduces CPU efficiency and slows memory access. Storage and network performance may vary without warning. These issues result in instability that real-time inference, tightly coupled HPC workloads, and critical transactional systems cannot accept.

Due to these limitations, many teams prefer [bare-metal servers](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) for performance-sensitive environments. With single-tenant physical hardware, organizations gain complete control over the operating system and system configuration. This control enables tuning kernel settings, filesystems, and network parameters based on known hardware behavior. Performance becomes stable and repeatable under both steady and heavy loads. This combination of control, isolation, and predictability makes bare metal a practical foundation for modern high-performance workloads.

## What Is a Bare Metal Server and Why Does It Matter for Performance and Control?

A bare metal server is a physical machine dedicated to one customer, without any shared virtualization layer. It provides direct access to CPU, memory, storage, and network interfaces, enabling teams to work with the hardware predictably and transparently. This setup also ensures greater control at the operating system level, since there are no intermediate layers between the user and the machine.

Since the server is fully dedicated, engineering teams can configure the environment to meet their workload needs. They can choose the operating system, adjust system parameters, and configure storage and network settings to match their performance goals. This flexibility is helpful for applications that require consistent behavior and clear visibility into resource usage.

Bare metal servers are also suitable for workloads that handle sensitive or regulated data. With hardware not shared with other customers, organizations can maintain stronger data separation and apply their own security controls. Requirements from standards such as HIPAA or GDPR can be addressed more easily in this type of environment. Bare metal is a suitable option for teams that must meet strict compliance expectations while maintaining performance, control, and predictable system behavior.

## How Do Bare Metal, Dedicated Servers, and Bare Metal Cloud Support Modern Performance Needs?

Bare metal servers, traditional dedicated servers, and bare metal cloud platforms all rely on physical hardware. They are often chosen for demanding workloads, yet they differ in flexibility, deployment speed, and day-to-day operation.

Conventional dedicated servers offer stable performance with fixed hardware configurations. Provisioning often takes hours or days, and automation options remain limited. They are suitable for environments that do not require frequent scaling or rapid deployment.

Bare metal cloud combines physical hardware with cloud-style automation. Servers can be provisioned in minutes via APIs, and teams can integrate tools such as Terraform, Ansible, or Kubernetes to manage infrastructure consistently. This model supports scalable workloads while maintaining the predictable performance of dedicated hardware.

Both bare metal and bare metal cloud avoid the overhead introduced by virtual machine–only environments. With no hypervisor layer, applications gain more direct access to hardware resources, helping maintain stable performance under sustained or bursty loads. This characteristic is essential for workloads that rely on consistent compute cycles or require access to specialized hardware.

These platforms also offer robust performance, further strengthening their suitability for demanding workloads. Bare metal servers exhibit predictable CPU behavior for compute‑heavy tasks, while modern NVMe storage supports low‑latency, high‑throughput data access. Similarly, high‑bandwidth network interfaces reduce jitter and support real‑time communication. Physical isolation prevents resource contention and helps sustain performance during peak periods, ensuring that workloads continue to operate consistently even when demand increases.

Bare metal and bare metal cloud environments are considered suitable for AI and ML pipelines, HPC workloads, real-time analytics, trading systems, and other applications that depend on consistent and reliable performance.

## How to Choose the Best Bare Metal Hosting Provider for High-Performance Needs

Selecting a bare metal hosting provider involves understanding which platform characteristics influence performance, stability, and long-term efficiency. The following criteria help teams evaluate providers in a structured and practical way.

### CPU and Accelerator Options

The choice of processors and hardware accelerators is a critical criterion. Providers should offer a range of CPU classes along with optional GPUs or other accelerators. This ensures that the platform can handle compute-heavy workloads such as AI, ML, HPC, and analytics. Teams can then match the hardware capabilities to the demands of their applications and avoid performance bottlenecks.

### Memory Capacity and Reliability

Memory size and reliability are equally important. Sufficient RAM allows efficient in-memory processing for large datasets or analytics workloads. Error-Correcting Code (ECC) memory or other reliability features reduce the risk of data corruption. Evaluating memory capacity and reliability is essential for long-running or sensitive workloads.

### Storage Type and Predictability

Storage performance is another key criterion. Providers offering fast SSD or NVMe drives with RAID options ensure low-latency and high-throughput storage. Predictable storage behavior under sustained load helps maintain application performance. Storage evaluation should consider both speed and stability to support data-intensive workloads.

### Network Quality and Regional Coverage

Network performance also plays a crucial role. High-bandwidth connections, low-latency paths, and private networking improve responsiveness. Providers with multiple regional data centers can support distributed and real-time workloads more effectively. Network quality and geographic coverage are essential criteria for teams that require consistent connectivity.

### Automation and Operational Support

It is also essential to review the operational tools and services a provider offers, as these affect deployment speed and day-to-day management. API-driven provisioning, monitoring capabilities, and optional managed services help reduce administrative effort and maintain stable performance as environments grow.

## Best Bare Metal Hosting Providers for High-Performance Workloads in 2026

The top 6 bare metal hosting providers for high-performance workloads are discussed below.

### 1. Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

[Atlantic.Net](http://www.atlantic.net) offers bare metal servers built to support stable, high-performance workloads that require predictable compute behavior and strong isolation. Its platform supports AI pipelines, analytics engines, and high-traffic applications that benefit from dedicated hardware. The provider also offers HIPAA-compliant hosting and optional Business Associate Agreements (BAA), which makes it suitable for regulated environments. With a focus on consistent performance, secure networking, and operational support, Atlantic.Net is a practical choice for organizations seeking reliable bare metal infrastructure in 2026.

#### *Key Characteristics*

- Atlantic.Net delivers dedicated bare metal servers with stable CPU, RAM, and NVMe performance, supporting workloads that depend on predictable compute behavior and low-latency data access.
- High-bandwidth networking with TLS 1.2 and 1.3 strengthens data security and supports real-time applications that require consistent throughput across different deployment scenarios.
- The platform’s performance-focused architecture benefits analytics engines and AI pipelines that rely on steady resource availability and minimal performance drift.
- Optional managed services from Atlantic.Net assist with monitoring, tuning, and operational oversight, helping teams maintain performance stability as workloads scale or become more complex.

### 2. AWS Bare Metal

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

[AWS](https://aws.amazon.com/) provides bare metal instances integrated with its hyperscale cloud ecosystem, enabling high-performance workloads to run on dedicated hardware while accessing a broad range of cloud services. These instances support HPC, ML, analytics, and enterprise applications that require high compute capacity and network throughput. With global data center coverage and extensive automation tools, AWS offers a flexible environment for organizations that need both performance and large-scale operational capabilities in 2026.

#### *Key Characteristics*

- AWS offers high-performance CPU and memory configurations that support compute-intensive workloads, including HPC clusters, ML training pipelines, and large-scale analytics engines.
- Global data center coverage enables low-latency deployments across multiple regions, supporting distributed applications that depend on consistent network responsiveness.
- Strong network throughput helps maintain stable performance for real-time and high-bandwidth workloads, especially those requiring sustained data movement.
- Integration with AWS automation and orchestration services helps teams manage bare-metal environments using familiar cloud-native workflows and operational tools.

### 3. Google Cloud Bare Metal Solution

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

[Google Cloud Bare Metal Solution](https://docs.cloud.google.com/bare-metal/docs) provides dedicated servers optimized for database, analytics, and enterprise workloads that require predictable performance and low-latency connectivity. The platform is designed for organizations migrating large on-premises systems or running high-performance applications that benefit from direct hardware access. With high-speed interconnects and integration with Google Cloud services, it supports hybrid deployments that require strong compute capacity and efficient data movement in 2026.

#### *Key Characteristics*

- Google Cloud Bare Metal Solution is optimized for database and analytics workloads that depend on consistent performance and direct access to hardware resources.
- Predictable storage performance supports data-intensive applications that require low-latency access and stable throughput under sustained load.
- High-speed interconnects enable efficient hybrid deployments, enabling on-premises systems and cloud services to operate with minimal latency.
- The platform supports large-scale enterprise environments, enabling organizations to run mission-critical workloads with high reliability and operational consistency.

### 4. Microsoft Azure Bare Metal

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

[Microsoft Azure](https://azure.microsoft.com/en-us) offers enterprise-grade bare metal servers designed for high-performance workloads across Windows and Linux environments. These servers support HPC, analytics, and large enterprise applications that require dedicated hardware and strong integration with cloud services. Azure’s global infrastructure and hybrid capabilities help organizations deploy performance-sensitive workloads close to users while maintaining consistent operational behavior across regions in 2026.

#### *Key Characteristics*

- Azure provides a global data center network that supports low-latency deployments and distributed high-performance workloads across multiple geographic regions.
- Enterprise-grade hardware delivers reliable compute capacity for HPC, analytics, and large-scale application environments that require consistent performance.
- High-performance networking supports real-time and distributed workloads that depend on stable throughput and low-latency.
- Integration with Azure DevOps and automation tools enables teams to provision, monitor, and manage bare-metal environments using established workflows.

### 5. Kamatera

![](https://www.atlantic.net/wp-content/uploads/2025/12/kamatera-logo-1.png)

[Kamatera](https://www.kamatera.com/) offers customizable bare-metal servers built for performance-sensitive workloads that require flexible hardware configurations and rapid provisioning. Its platform supports analytics engines, real-time applications, and compute-intensive tasks that benefit from dedicated resources. With a global network and API-driven automation, Kamatera enables teams to deploy and scale high-performance environments efficiently while maintaining predictable system behavior in 2026.

#### *Key Characteristics*

- Kamatera provides flexible CPU, RAM, and storage configurations, enabling teams to tailor hardware to the performance needs of specific workloads.
- Rapid provisioning enables the quick deployment of performance-tuned environments, enabling fast scaling for analytics, AI, and real-time applications.
- API-based automation helps DevOps teams manage infrastructure consistently, supporting stable performance across different deployment stages.
- A global low-latency network improves responsiveness for distributed workloads and applications that require consistent communication across regions.

### 6. Scala Hosting

![](https://www.atlantic.net/wp-content/uploads/2025/12/scala-hosting.jpg)

[Scala Hosting](https://www.scalahosting.com/) provides dedicated bare metal environments suited to performance‑sensitive workloads that require predictable compute behavior and consistent storage performance. While it is not designed for hyperscale HPC or large AI clusters, it supports mid‑range high‑performance applications that benefit from stable hardware and managed operational assistance. The platform is a practical option for teams seeking reliable compute resources, simplified management, and scalable configurations for growing workloads in 2026.

#### *Key Characteristics*

- Scala Hosting offers dedicated hardware that maintains stable compute and storage performance, supporting applications that rely on predictable system behavior under varying load conditions.
- Managed operational support assists with configuration, monitoring, and routine oversight, reducing the administrative burden for teams running performance‑sensitive environments.
- Scalable configurations allow organizations to adjust CPU, memory, and storage resources as workloads expand, helping maintain consistent performance over time.
- The platform provides a reliable foundation for analytics engines, real‑time applications, and high‑traffic services that require steady throughput without the complexity of hyperscale infrastructure.

## Aligning Workloads with Bare Metal Platforms

High-performance workloads operate under diverse conditions, which means no single bare metal provider is suitable for every use case equally well. For example, some environments require large memory capacity, specialized accelerators, or deployments across multiple regions. In contrast, other workloads rely on predictable compute behavior, stable storage performance, and close control over hardware. Therefore, selecting the right bare metal platform depends on the provider’s alignment with workload scale, latency requirements, and operational maturity.

Hyperscale providers such as AWS, Google Cloud, and Microsoft Azure are suitable for workloads that demand broad geographic coverage, advanced automation, or tight integration with cloud-native services. Consequently, their infrastructure can support large-scale analytics pipelines, HPC clusters, and enterprise applications that require steady throughput and rapid provisioning. In these scenarios, access to specialized hardware, high-bandwidth networking, and multi-region deployment provides a clear advantage, particularly for teams operating across multiple locations.

On the other hand, performance-focused providers like Atlantic.Net, Kamatera, and Scala Hosting cater to workloads that prioritize stability, isolation, and operational simplicity. For instance, Atlantic.Net is ideal for compliance-driven or long-running applications requiring consistent performance. Kamatera offers flexible configurations and rapid provisioning, enabling teams to match hardware precisely to their workload needs. Similarly, Scala Hosting, while not designed for hyperscale HPC or AI clusters, provides a reliable environment for mid-range workloads that depend on steady compute power and managed support.

Latency and operational preferences further influence provider selection. Workloads that must remain close to end-users often benefit from hyperscale platforms. Conversely, tightly coupled applications achieve more consistent performance on dedicated environments such as Atlantic.Net or Kamatera. Likewise, teams with strong DevOps practices may prefer hyperscalers for their automation tools, while organizations aiming to reduce administrative overhead often find performance-focused providers easier to manage.

By considering workload type, performance requirements, latency, scale, and regulatory obligations, organizations can align workloads with the most suitable bare metal platform. This approach ensures a reliable, scalable, and high-performing infrastructure, giving teams full control over their environment while supporting complex workloads efficiently.

## The Bottom Line

Selecting the right bare metal provider begins with understanding workload requirements, performance expectations, and operational priorities. Once these factors are clear, teams can compare hyperscale and performance-focused platforms to find the environment that offers predictable compute, low latency, and consistent throughput. Evaluating storage performance, multi-region capabilities, and automation tools ensures that both current and future needs are met.

Considering operational simplicity and compliance helps reduce risks and streamline management. By integrating these considerations, organizations can devise a bare-metal strategy that provides reliable, scalable infrastructure, complete control over the environment, and the ability to support complex workloads while preparing for long-term growth.

 


---

# How to Choose a Dedicated Server for High Traffic Websites

> URL: https://www.atlantic.net/dedicated-server-hosting/choose-dedicated-server-high-traffic-websites/ | Published: 2026-01-27 | Updated: 2026-06-23 | Author: Robert Agar

Businesses supporting high-traffic websites require top-tier performance to handle visitors effectively. [Shared hosting](https://www.atlantic.net/vps-hosting/vps-hosting-vs-shared-hosting-pros-cons-differences-and-expert-tips/) solutions often provide insufficient resources and stability to meet these needs. Dedicated servers offer organizations a powerful solution to obtain the resources and network bandwidth necessary to support high-traffic sites.

This article discusses the types of organizations that require high-traffic websites, the benefits of using dedicated servers, and how to choose the right dedicated server for your business.

## What Businesses Support High Traffic Websites?

Companies across industries need customer-facing websites that can handle high traffic. These organizations depend on managing heavy, sustained online customer demand. The following are examples of companies that require a high-traffic website.

- **E-commerce:** E-commerce businesses and online stores must support continuous customer browsing and transactions, including fast and secure payment processing. Their websites require consistent uptime, fast page loads, and high database throughput.
- **Media and Streaming:** Media and digital content companies, such as streaming services and news organizations, require superior network performance to handle large volumes of concurrent users and withstand traffic spikes driven by viral content or breaking news.
- **FinTech:** Financial services companies such as payment processors, crypto exchanges, and online banking platforms must support real-time transactions and reliable data availability. These organizations require minimal latency, excellent fault tolerance, and strong security measures to protect customer data.
- **SaaS Providers:** Software-as-a-service providers such as CRM, business applications, or analytics platforms require high availability, continuous monitoring, and support for user sessions around the clock. They will lose customers to rivals if they cannot deliver optimal performance.
- **Healthcare:** Healthcare organizations must address the needs of large patient populations, including appointment scheduling and telemedicine delivery. Their websites must include uptime guarantees and strong security to meet regulatory and [compliance guidelines](https://www.atlantic.net/hipaa-compliant-hosting/what-are-hipaa-compliance-rules-and-guidelines/).
- **Social Platforms:** Social media companies and online communities support high-traffic sites for user engagement and content creation. These sites need real-time updates and fast read/write operations to maintain user satisfaction.
- **Gaming:** Interactive entertainment companies support gaming servers and multiplayer games with high-traffic websites. They must deliver smooth, real-time interaction with low latency to provide a satisfactory user experience.

## What Is Dedicated Server Hosting?

Dedicated server hosting is a type of infrastructure hosting in which the customer has exclusive use of a physical server. This model is a stark contrast to shared cloud hosting, where multiple tenants use the same physical hardware. Companies supporting high-traffic applications and websites can more effectively meet their needs with a [dedicated hosting provider](https://www.atlantic.net/dedicated-server-hosting/the-best-dedicated-hosting-providers/).

### Benefits of dedicated servers

Companies can achieve the following benefits from a dedicated server setup.

- **Exclusive resources:** Customers have exclusive access to CPU, RAM, and storage, eliminating potential contention with other tenants and reducing the risk of performance degradation. Dedicated resource usage is essential for maintaining consistent performance for businesses supporting mission-critical, high-traffic, or resource-intensive applications.
- **Predictable performance:** The complete control of dedicated hardware resources ensures consistent response times and high performance for data-heavy applications. Customers can configure server settings to deliver fast, sustained, and reliable performance with low latency and high IOPS for I/O-intensive workloads and database management.
- **Improved security:** Dedicated servers are an excellent choice for customers who prioritize security. Their environment is isolated on a physical server that other tenants cannot impact. Teams can improve data protection by exercising full control over firewall configuration and access policies. Companies in regulated industries can implement and enforce compliance controls and use [intrusion detection systems](https://www.atlantic.net/dedicated-server-hosting/what-is-an-intrusion-detection-system-and-why-do-i-need-it/) to protect their systems and data resources.
- **Administrative control:** Organizations have complete control over the operating system, software stack, and server configuration with a dedicated hosting solution. The flexibility afforded by a dedicated server lets teams implement custom architectures and support legacy applications.
- **Customizable hardware:** Dedicated servers allow teams to configure hardware resources, such as CPU, RAM, or storage, to fine-tune performance for specific applications. Companies can opt for servers featuring high-performance CPUs or high-bandwidth networking to support faster data access.
- **Regulatory compliance:** Dedicated servers streamline compliance with regulations such as HIPAA, [PCI-DSS](https://www.atlantic.net/hipaa-compliant-hosting/how-to-effectively-establish-hipaa-and-pci-dss-regulatory-compliance/), and GDPR. Companies can configure the operating system and other components to meet compliance standards. In many cases, a [single-tenant](https://www.atlantic.net/dedicated-server-hosting/achieving-unparalleled-security-with-single-tenant-dedicated-hosting/) infrastructure is a compliance requirement that businesses can meet with dedicated hosting.
- **Stable costs:** Dedicated server providers typically offer fixed and transparent pricing that supports predictable budgeting. Companies won’t be surprised by varying usage charges, making dedicated servers a practical choice for workloads requiring heavy resource utilization.
- **Management flexibility:** Most hosting providers offer customers the choice between fully self-managed servers and vendor-managed services. Companies can choose the server management model that best fits their internal IT capabilities.

## How to Select a Dedicated Server Provider for High Traffic Websites

Organizations should employ a methodical approach to selecting the right dedicated server provider for high-traffic websites, including the following steps.

### Evaluate the workload

Various workloads may require different resources, such as CPU, RAM, and storage, to achieve optimal performance. The first step in selecting a dedicated server solution is to understand the workload the server will support. Decision-makers need to consider issues such as:

- **Traffic Volume:** Average and peak traffic volume, including the number of concurrent users.
- **Content Type:** Database usage and dynamic versus static content delivery.
- **Tech Stack:** The application stacks they will be supporting.
- **Security Needs:** The need to support secure TLS workloads.
- **Storage:** Data storage patterns and requirements.
- **Geography:** Traffic distribution over geographical regions.

### Choose the correct server hardware

Companies must choose the right dedicated server hardware to support their specific high-traffic environment and the operating system they wish to run. Organizations should consider how different hardware configurations affect their site’s performance, depending on the types of workloads running on the platform.

- Teams should favor high-performance CPUs to support multi-threading and advanced, complex applications.
- Memory is crucial for high-traffic websites to support caching and site responsiveness. Companies should look for at least 64 GB when supporting a high-traffic site.
- Companies must ensure the storage subsystem can sustain throughput during traffic spikes, using hardware such as NVMe SSDs. Businesses should avoid providers that offer only legacy HDD storage.
- High-traffic websites rely heavily on network performance, bandwidth, and throughput to meet user expectations. Decision-makers should insist on high-capacity network uplinks that support high-speed data transfer and bandwidth usage plans that align with business requirements.

### Assess the provider’s services

Businesses must examine the range of services offered by a prospective dedicated hosting provider. A reliable hosting provider will offer services designed to protect and optimize the existing environment while also supporting future growth.

- High-traffic websites must be easily scalable without service disruptions. The provider should offer load balancing support to ensure reliable performance. Customers should be able to scale vertically with CPU or RAM upgrades or horizontally by adding servers to the environment.
- Providers should offer uptime guarantees and redundant server configurations for enhanced resilience. Customers should insist on 99.99% [uptime SLAs](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/) and receive SLA credits for downtime. Businesses should look for dedicated hosting providers operating Tier 3 data centers with built-in power and cooling redundancy.
- Companies should examine the data protection measures the provider implements, including encryption, firewall controls, [DDoS protection](https://www.atlantic.net/vps-hosting/what-is-a-ddos-and-how-do-we-prevent-our-business-from-being-attacked/), and intrusion detection and response solutions. Businesses handling regulated data should work with providers that explicitly support their compliance requirements.
- Some organizations may require managed services to optimize their dedicated server solutions. Companies must realistically evaluate their in-house technical capabilities when deciding whether to contract for unmanaged servers or engage managed services from their provider. Businesses with limited IT teams may benefit from managed services, and must ensure that a candidate provider offers them.
- Backup and [disaster recovery](https://www.atlantic.net/disaster-recovery/disaster-recovery-plan/) are essential services that a dedicated hosting provider should offer. Companies supporting high-traffic environments require robust resiliency. The provider should offer encrypted and automated backups with fast restore capabilities. They should have well-documented, tested disaster recovery plans and adhere to SLA-defined RPOs and RTOs. Geo-redundant backups and storage add another layer of resilience and should be considered when selecting a provider.
- Teams should be able to perform resource monitoring via a user-friendly interface or control panel that provides real-time usage and performance data. Companies should have logs available for review and be able to set alert thresholds for resources such as CPU or memory. Providers that offer proactive monitoring reduce the risk of bottlenecks or outages.
- Quality customer support is vital for companies with high-traffic websites. These businesses cannot afford unexpected or lengthy outages and must have access to 24/7 technical support from the provider.

### Cost considerations

Businesses should understand the costs of the dedicated server hosting plan they choose, including:

- Monthly hosting costs;
- Overage fees for excessive bandwidth usage;
- Backup and disaster recovery costs;
- Scaling costs for vertical and horizontal scaling;
- The costs of additional managed services.

## Conclusion

Businesses can address the needs of high-traffic websites with dedicated hosting from the right dedicated server provider. Companies must find the right hardware and hosting environment to support their unique business needs and objectives. The wrong choice can minimize the potential benefits of dedicated servers and make it difficult to maintain an efficient, high-traffic site.

[Atlantic.Net](https://www.atlantic.net/) offers its customers a range of [dedicated server options](https://www.atlantic.net/dedicated-server-hosting/), featuring high-performance servers running Intel Xeon and AMD EPYC processors. Our dedicated servers are hosted in geographically distributed data centers, enabling customers to house their high-traffic websites with minimal latency. Atlantic.Net’s 100% Network Uptime SLA and 24/7/365 customer support make it the perfect platform for companies with high-traffic environments.

[Contact Atlantic.Net’s team of experts](https://www.atlantic.net/about-us/corporate-contact/) and learn how your business can thrive with the right dedicated server provider.


---

# Best Dedicated Server Hosting for Ecommerce in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/best-dedicated-server-hosting-for-ecommerce-in-2026/ | Published: 2026-01-28 | Updated: 2026-01-27 | Author: Dr. Tehseen Zia

In 2026, running an online store is much more demanding than it used to be. Today, ecommerce websites are resource-intensive with real-time AI tools and high-resolution media. Dedicated server hosting remains the gold standard for established ecommerce platforms. By providing exclusive access to hardware, these servers ensure predictable performance during traffic spikes and offer the robust security needed to protect customer data.

This article explains what makes dedicated hosting suitable for ecommerce today and then presents a carefully selected list of the best dedicated server hosting providers for ecommerce in 2026. The goal is not to rank winners and losers, but to help store owners understand which providers align with different business needs.

## Why Ecommerce Businesses Need Dedicated Servers in 2026

As we enter 2026, ecommerce is no longer just about listing products online. Today’s online stores are complex systems that handle real-time inventory updates, automated pricing, and AI-powered chatbots. These features need a lot of CPU power and memory. On a shared server, there is no guarantee that these resources will always be available.

The growing demand for [personalization](https://www.starkdigital.net/ai-in-e-commerce-personalization-pricing-and-predictive-buying-in-2026/) in ecommerce makes dedicated servers more vital than ever. When a shopper lands on an ecommerce site, AI systems quickly create custom layouts and product suggestions based on their history. This process can take a lot of computing power and can easily lag on over-subscribed servers. Dedicated servers [eliminate](https://technologycurated.com/data-science-and-analytics/why-do-ai-driven-businesses-need-dedicated-servers/) this bottleneck by providing raw power that is not shared with anyone else.

Reliability is also a [major factor](https://www.bettercommerce.io/blog/don-t-crash-on-black-friday-prevent-slowness-downtime-and-crashes) during big sales like Black Friday. A sudden spike in visitors can crash a site on a weaker host. With a dedicated server, you can control all the bandwidth and resources, so your store stays online when it matters most.

Finally, security is a massive concern in 2026. [AI-driven cyberattacks](https://securitybrief.com.au/story/ecommerce-platforms-face-ai-powered-cyber-threats-for-2025-season) are more common now. Since a dedicated server is physically isolated, you do not have to worry about a security hole on someone else’s website affecting yours. This isolation lets you use better tools like hardware encryption and custom firewalls. For many, security is no longer just a technical concern; it is a legal requirement. If you handle sensitive data, having a host that provides a HIPAA Business Associate Agreement (BAA) is essential to stay compliant with the law.

## Top Five Hosting Providers for Ecommerce in 2026

Here are the hosting companies that are leading the way for online businesses this year.

1. **Atlantic.Net**

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

Atlantic.Net has been in the hosting business for over 30 years. They focus heavily on security and reliability. The data centers have SOC 2 and SOC 3 certifications, which means experts regularly check their security.

They are a top choice for businesses that need [compliant hosting](https://www.atlantic.net/compliance-hosting/). They regularly sign [HIPAA BAAs](https://www.techtarget.com/healthtechsecurity/feature/What-Is-a-HIPAA-Business-Associate-Agreement-BAA) and follow standards like [PCI DSS](https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard) to provide vital legal and operational protection for businesses handling sensitive data. They offer enterprise-grade [hardware](https://www.atlantic.net/dedicated-server-hosting/) and provide 100% uptime guarantee to ensure continuous availability and reliability during peak sales.

**Key Features:**

- **Fully Managed Security**: 24/7 monitoring, managed firewalls, and intrusion detection.
- **Audit-Ready Compliance**: Simplified frameworks for HIPAA and PCI DSS, with necessary documentation.
- **Encrypted Backups**: Automated, [AES 256-bit](https://en.wikipedia.org/wiki/Advanced_Encryption_Standard) encrypted backups stored in separate locations for quick disaster recovery.

1. **Rackspace Technology**

![](https://www.atlantic.net/wp-content/uploads/2025/12/rackspace_logo.png)

[Rackspace](https://www.rackspace.com/managed-hosting) is an expert in enterprise hosting, known for supporting large, international brands. They are experts at “hybrid” setups, where you use both dedicated servers and cloud services together. They manage everything from the hardware to the operating system and the databases. This is a great choice for companies with larger budgets that want experts to handle the technical side. With data centers all over the world, they help your store load fast for customers in any country.

**Key Features:**

- **Fanatical Support:** Dedicated account managers and technical experts for high-touch service.
- **Global Reach:** Over 40 data centers worldwide to place data close to your customers.
- **Cloud Integration:** Expert integration of dedicated servers with public cloud platforms like AWS or Azure.

1. **InterServer**

![](https://www.atlantic.net/wp-content/uploads/2025/12/interserver.png)

[InterServer](https://www.interserver.net/dedicated/index.html) appeals to cost-conscious businesses and developers who want direct control. They are famous for their “[Price Lock](https://www.interserver.net/blog/interserver-price-lock-guarantee/)” guarantee. This means the price you sign up for is the price you pay forever; they won’t raise it later. They eliminate setup fees and allow you to customize almost every part of the server. This is an ideal option for teams with technical staff who want maximum power and flexibility on a predictable budget.

**Key Features:**

- **Custom Hardware:** You can pick your own processor, RAM, and storage type to fit your budget.
- **Unmetered Bandwidth:** 1 Gbps connections with no extra charges for high data transfer.
- **No Setup Fees:** Start with a high-end server without significant upfront cost.

1. **Hetzner Online**

![](https://www.atlantic.net/wp-content/uploads/2026/01/Hetzner.jpg)

[Hetzner](https://www.hetzner.com/) is a European company known for offering some of the lowest prices in the industry. They build their own hardware and run very efficient data centers.

In 2026, they are a top choice for brands that care about the environment, as they use 100% renewable energy. While they do not offer as much “hands-on” help as others, their hardware is excellent for those who know how to manage a server themselves.

**Key Features:**

- **Eco-Friendly Infrastructure:** Data centers in Germany, Finland, and the USA powered by green energy.
- **High-Density Storage**: Specialized servers with massive storage for large product catalogs.
- **Custom Control Panel:** An intuitive interface to manage reboots, firewalls, and monitoring.

1. **IBM Cloud Bare Metal Servers**

![](https://www.atlantic.net/wp-content/uploads/2025/06/ibm-logo.png)

[IBM’s dedicated servers](https://www.ibm.com/products/bare-metal-servers) are built for very large ecommerce operations. This is a strong choice if your business already uses IBM tools or if you need to do heavy data analytics.

By using their “bare metal” server, you get the full power of the physical server without any extra software slowing it down. It is a very predictable and powerful environment for stores that need to scale up quickly.

**Key Features:**

- **Enterprise Power:** High-performance servers built for demanding, scalable workloads.
- **AI and Analytics:** Native connectivity to IBM Cloud AI, analytics, and automation tools.
- **Advanced Networking:** Robust, secure networking options designed for distributed platforms.

## Selecting the Right Hosting Strategy for Growth

The right hosting choice in 2026 depends on your business priorities and growth plans. Hosting is no longer just about keeping your site online; it directly affects performance, security, and customer trust.

If security and compliance are critical, a fully managed provider like Atlantic.Net offers strong value through built-in protections and regulatory support. For businesses expanding globally or using hybrid infrastructure, Rackspace provides the scale and expertise needed to manage complex environments across regions.

Cost-focused teams with technical experience may prefer InterServer or Hetzner. These providers offer greater control and predictable pricing, making them suitable for stores that want to manage their own infrastructure while scaling steadily. At the enterprise level, IBM Cloud Bare Metal Servers are better suited for large operations that rely heavily on analytics, automation, and AI-driven workloads.

There is no one-size-fits-all solution. In 2026, your hosting platform is the foundation of your ecommerce operation. Choosing a dedicated server that aligns with your technical capabilities and growth goals helps ensure long-term stability, performance, and customer confidence.


---

# Best Dedicated Server Hosting Providers in the USA in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/best-dedicated-server-hosting-providers-in-the-usa/ | Published: 2026-01-29 | Updated: 2026-07-24 | Author: Dr. Tehseen Zia

For 2026, the best dedicated server hosting providers in the USA are Atlantic.Net for regulated industries (HIPAA/PCI), HostGator for scalable support, and IONOS for budget-conscious deployments.

Choosing a dedicated server means leasing an entire physical machine, with no shared CPU, RAM, or bandwidth. This infrastructure is critical for high-traffic applications, large databases, and regulated data handling. We evaluated the top US-based providers on hardware performance, compliance certifications, support responsiveness, and price-to-value ratio.

## What Does Dedicated Server Hosting Mean in 2026?

A[dedicated server](https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/) is a physical machine reserved for one customer. You’re not sharing CPU, RAM, or storage with other tenants. That’s still the main reason teams pay for dedicated: predictable performance, full control, and a cleaner security boundary than[shared hosting](https://www.atlantic.net/vps-hosting/vps-hosting-vs-shared-hosting-pros-cons-differences-and-expert-tips/).

What’s changed is the buying process. In 2026, the best providers make it easy to choose the management level, security controls, and[SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/).

## Top Dedicated Hosts

| **Provider** | **Best For** | **Starting Price (Est.)** | **Key Strength** |
| --- | --- | --- | --- |
| **Atlantic.Net** | Regulated industries | ~$138/mo | HIPAA/HITECH compliance, 100% SLA, and SOC 2/SOC 3 certification |
| **HostGator** | Growing businesses | ~$140/mo | Fully managed support, Tier III data centers, and easy scalability |
| **IONOS** | Budget and value | ~$45/mo | Low entry price, ISO 27001 certification, and unlimited traffic |
| **InterServer** | Flexibility | ~$45/mo | Unmetered bandwidth and deep customization options |
| **AccuWeb** | Windows and SMB workloads | ~$100/mo | Strong Windows server options and high configurability |
| **Hivelocity** | Performance | ~$100/mo | Instant deployment, bare metal focus, and 100% uptime SLA |

## #1. Atlantic.Net – Best for Compliance & Security

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

Atlantic.Net stands out in 2026 as the premier choice for organizations with strict regulatory needs. With over 30 years of experience, they specialize in hosting for healthcare (HIPAA), financial (PCI-DSS), and government sectors. Unlike generalist hosts, their infrastructure is audited for SOC 2 and SOC 3 compliance, making them a “safe harbor” for sensitive data.

Below is Atlantic.Net’s cloud control panel interface used to deploy and manage dedicated and GPU servers.

![Atlantic.Net Server Panel](https://www.atlantic.net/wp-content/uploads/2026/01/Atlantic.net-server-panel.png)

Image Source: Atlantic.Net

- **Key Specs:** Custom Intel Xeon Scalable/AMD Epyc processors, NVMe storage, unmetered bandwidth options.
- **Compliance:** HIPAA, HITECH,[PCI-DSS](https://www.atlantic.net/pci-compliant-hosting/what-is-pci-compliance/), SOC 2/SOC 3.
- **US Locations:** Five US regions: New York, Ashburn, VA, Orlando, FL, Dallas, TX, and San Francisco, CA.
- **Support:** 24/7/365 US-based support; 100% Uptime SLA.
- **Verdict:** If your business handles patient data or credit card transactions, the liability protection and compliance here are unmatched.

**What stands out**

- Dedicated hosting plans are published with example configurations and pricing (useful for budgeting).
- Dedicated server service level guarantee language is clearly stated (network/infrastructure components).
- Compliance hosting positioning is front and center for regulated workloads.

**Who should choose Atlantic.Net?**

- Healthcare, finance, SaaS teams with audits, and anyone who needs a vendor that can support security and compliance conversations as well as supply the hardware.

## #2. HostGator – Best for Support & Scalability

![](https://www.atlantic.net/wp-content/uploads/2025/08/Hostgator-logo.png)

HostGator remains a strong contender for businesses that need a “hands-off” managed experience. Their dedicated plans come with a full suite of management tools, making them ideal for growing companies that may not have a full-time sysadmin.

Below is a preview of HostGator’s cPanel dashboard, included with its managed dedicated server hosting plans, allowing users to control files, databases, domains, and server settings.

![HostGator-cPanel-dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/HostGator-cPanel-dashboard-1.png)

Image Source: HostGator

- **Key Specs:** Up to 100GB SSD / 2TB HDD, unmetered bandwidth.
- **Management:** Fully managed or semi-managed options with cPanel.
- **Support:** 24/7 live support with a reputation for helping beginners with dedicated servers.
- **Verdict:** A solid, reliable choice for businesses scaling up from shared or VPS hosting who need consistent uptime and support.

**What stands out**

- 99.9% uptime guarantee and Tier 3 data center positioning on the dedicated server page.
- [DDoS protection](https://www.atlantic.net/vps-hosting/what-is-a-ddos-and-how-do-we-prevent-our-business-from-being-attacked/) and[RAID](https://www.atlantic.net/hipaa-data-centers/raid-10/) storage are part of the dedicated offering.
- Guided setup is explicitly called out.

**Who should choose HostGator?**

- Small teams that want dedicated resources but don’t want to spend weeks designing an ops runbook before launch.

## #3. IONOS – Best Value & Entry-Level Pricing

![](https://www.atlantic.net/wp-content/uploads/2025/08/ionos-logo.png)

IONOS (formerly 1&1) aggressively targets the budget market without sacrificing enterprise-grade security. For 2026, they offer some of the lowest starting prices for dedicated hardware in the US market. Their “pay-per-use” and flexible contract models appeal to startups and developers; just be mindful of vendor lock-in.

Look at the IONOS Cloud control panel showing server image management, infrastructure configuration, and US data center deployment options.

![IONOS cloud panel](https://www.atlantic.net/wp-content/uploads/2026/01/IONOS-cloud-panel.png)

Image Source: IONOS

- **Key Specs:** Intel Xeon & AMD Ryzen options, unlimited traffic (1 Gbit/s).
- **Security:** ISO 27001-certified data centers, built-in DDoS protection.
- **Pricing:** Often starts under $50/mo for entry-level dedicated hardware.
- **Verdict:** The best option for developers and startups needing dedicated resources on a tight budget.

**What stands out**

- “Unlimited traffic” and **1 Gbit/s** standard bandwidth language is stated.
- Firewall filtering and DDoS interception language is included.
- US data centers and ISO certification are stated on the page.

**Who should choose IONOS?**

- Cost-conscious teams that still want dedicated hardware and published security/network statements.

## #4. InterServer – Best for Customization & Bandwidth

![](https://www.atlantic.net/wp-content/uploads/2025/12/interserver.png)

InterServer is a favorite among power users for its straightforward, no-nonsense approach to resources. They are one of the few providers offering true unmetered bandwidth on 1Gbps and 10Gbps ports without hidden caps.

Below is a look at the InterServer client dashboard for managing dedicated servers, bandwidth configurations, and service provisioning.

![interserver-server-panel](https://www.atlantic.net/wp-content/uploads/2026/01/interserver-server-panel-1.png)

Image Source: InterServer

- **Key Specs:** AMD EPYC & Intel Xeon configurations, up to 256GB RAM.
- **Network:** Route for low latency; US-based data centers (NJ/LA).
- **Features:** Price lock guarantee (renewal prices don’t hike unexpectedly).
- **Verdict:** Excellent for bandwidth-heavy applications like streaming, large file storage, or ad-tech platforms.

**What stands out**

- “Starting under $99 per month” positioning for budget dedicated servers.
- Feature callouts include DDoS protection, port options, remote access tools, and provisioning-related help.

**Who should choose InterServer?**

- Developers and operators who know what they want (ports, remote access, DDoS basics) and prefer a simple spec-first shopping experience.

## #5. AccuWeb Hosting – Best for Windows & SMBs

![](https://www.atlantic.net/wp-content/uploads/2025/08/accuweb-hosting-social-preview.png)

AccuWeb Hosting is new to our list for 2026 due to its specialized support for Windows Dedicated Servers. They offer a rare mix of high customizability and affordable management, making them a top pick for businesses running .NET applications or MSSQL databases.

Look at AccuWeb Hosting’s control panel interface for managing Windows and Linux dedicated servers, databases, email accounts, and domain configurations.

![Accuwebhosting cPanel Dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Accuwebhosting-cpanel-dashboard.png)

Image Source: AccuWeb Hosting

- **Key Specs:** 500+ customizable hardware configurations.
- **Locations:** Multiple global locations, including a strong US presence (Denver, etc.).
- **OS Support:** Strong focus on Windows Server editions, alongside standard Linux distros.
- **Verdict:** The go-to choice for small-to-medium businesses reliant on the Microsoft ecosystem.

**What stands out**

- AccuWeb explicitly lists Windows Server options for dedicated servers, from Windows Server 2016 through the current Windows Server 2025 release (Standard/DataCenter editions), alongside mainstream Linux choices.
- Dedicated server locations are published in the company knowledge base, including Denver, CO (USA).
- The dedicated servers page is built around custom configurations and includes DDoS protection and a hardware firewall.

**Who should choose AccuWeb Hosting?**

- A strong pick for small-to-medium businesses running Microsoft workloads who want Windows Server options clearly stated and a US location like Denver available.

## #6. Hivelocity – Best for High Performance & Instant Deploy

![](https://www.atlantic.net/wp-content/uploads/2025/08/Hivelocity_Logo_1680.jpg)

Hivelocity enters our 2026 rankings as a performance leader. Known for their “Instant Dedicated Servers,” they can deploy bare metal hardware in minutes rather than days. They cater specifically to the tech-savvy crowd, such as gaming servers, virtualization clusters, and high-frequency trading.

Below is Hivelocity’s server configuration dashboard, used to deploy dedicated and bare-metal servers instantly.

![Hivelocity Server Panel](https://www.atlantic.net/wp-content/uploads/2026/01/Hivelocity-server-panel.png)

Image Source: Hivelocity

- **Key Specs:** Powerful Intel & AMD processors, instant provisioning.
- **SLA:** 100% Network and Power Uptime SLA.
- **Management:** Primarily unmanaged/bare metal, giving you total root control.
- **Verdict:** Perfect for engineers and CTOs who need raw power immediately and don’t need hand-holding.

**What stands out**

- “Deploy… in less than 7 minutes” and “50 US data centers.”
- “99.99% uptime” guarantee.
- “From $65/mo” appears in its comparison materials.

**Who should choose Hivelocity?**

- Teams that need US location flexibility (latency, redundancy, customer distribution) and want fast procurement-to-deploy turnaround.

## Managed vs. Unmanaged: Which Do You Need?

- **Unmanaged (Bare Metal):** You get the hardware and the network. You install the OS, patch security, and fix errors.

Best for: Sysadmins and IT teams. (Examples: Hivelocity, IONOS).

- **Managed:** The provider handles hardware, OS updates, security patches, and monitoring.

Best for: Business owners and agencies. (Examples: Atlantic.Net, HostGator).

## Why a US-Based Dedicated Server Matters

The “USA” in this list is a technical requirement for many buyers, and it is worth being precise about what it buys you.

Latency. Physics sets the floor. A round trip between the US East and West coasts runs roughly 60–70ms; a user hitting a server in the same region sees more like 10–20ms. If your customers are in Chicago and your server is in Frankfurt, every page load, API call, and database round trip pays roughly another 100ms of transatlantic delay. Multi-region US providers let you place the workload near the traffic: Atlantic.Net runs five US regions (New York, Ashburn VA, Orlando FL, Dallas TX, and San Francisco CA), Hivelocity advertises dozens of US facilities, InterServer operates from New Jersey and Los Angeles, and AccuWeb publishes Denver among its locations.

Data residency and compliance. HIPAA and PCI-DSS do not strictly require US-based storage, but state privacy laws, federal contracts, and customer due-diligence questionnaires increasingly do. Keeping ePHI or cardholder data in a US data center with a US-based operator removes a whole category of audit questions: which jurisdiction the data sits in, which legal regime applies to a subpoena, and who can physically reach the hardware. Auditors can also visit a US facility; several of Atlantic.Net’s compliance certifications (SOC 2, SOC 3, HIPAA/HITECH) rest on exactly that kind of on-site verification.

Support hours that match yours. A dedicated server, especially an unmanaged one, occasionally needs a human at the other end during a US business day. US-based 24/7 support means the escalation engineer is awake, and often in the same time zone, when your outage happens at 2 p.m. Eastern.

One honest caveat: a US address alone does not make a provider compliant or fast. A single-location host in the wrong region can be slower for your users than a well-connected international one, and compliance depends on the provider’s audited controls and a signed HIPAA Business Associate Agreement (BAA), not the flag on the data center. Treat US presence as one requirement on the checklist, then verify the SLA, the audit reports, and the region list against your actual user base.

## FAQ: Dedicated Hosting in 2026

### What Is the Average Cost of a Dedicated Server in 2026?

Entry-level servers start around $45–$70 per month (IONOS, InterServer). Mid-range business servers typically cost $120–$250 per month. Enterprise/Compliance servers (like those from Atlantic.Net) are custom-quoted based on specific regulatory requirements.

### Do You Really Need a Dedicated Server Over a VPS?

You need a dedicated server if your application demands consistent high performance (no “noisy neighbors”), strict data isolation for compliance (HIPAA/PCI), or full root access with custom kernel modifications. For workloads without those requirements, a[VPS](https://www.atlantic.net/vps-hosting/) usually costs less and scales faster.

### Which Provider Is Best for HIPAA Compliance?

Atlantic.Net is the strongest choice for[HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-in-the-age-of-ai/). They offer a[BAA](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/)and an infrastructure specifically audited for healthcare data regulations, which most generic hosts do not provide.

### Who Has the Most Reliable Dedicated Hosting With a 99.99% Uptime SLA?

Atlantic.Net and Hivelocity both publish 100% uptime SLAs covering network and infrastructure, which exceeds the 99.99% bar; Hivelocity also states a 99.99% guarantee in its comparison materials. HostGator commits to 99.9%. Read what each SLA actually covers: most exclude scheduled maintenance and cover the network and power rather than your OS or application.

### Which Providers Offer Managed and Unmanaged Dedicated Server Plans?

Atlantic.Net and HostGator lead for managed plans, where the provider patches the OS, monitors the server, and handles hardware. Hivelocity, IONOS, and InterServer are primarily unmanaged/bare metal, which suits teams with their own sysadmins. The Managed vs. Unmanaged section above covers how to choose between them.

### How Do You Choose a Dedicated Server for a High-Traffic Website?

Start from your measured peak traffic, then size for it: modern multi-core CPUs (Xeon Scalable or AMD EPYC), 32GB+ RAM for busy database-backed sites, NVMe storage, and a 1 Gbit/s or faster port with generous or unmetered bandwidth. DDoS protection and a load-balancing path for future growth matter more than raw clock speed.

### Where Can You Buy Dedicated Servers With DDoS Protection Included?

Most providers on this list include a baseline: HostGator, IONOS, InterServer, and AccuWeb all state DDoS protection on their dedicated pages, and Atlantic.Net offers edge protection alongside a[managed firewall](https://www.atlantic.net/managed-services/firewall/) service. Check whether the included tier covers volumetric attacks only or application-layer attacks too, and what mitigation capacity is included before an overage applies.

### What Hardware Specifications Should You Evaluate When Selecting a Dedicated Server?

Evaluate the CPU (core count and generation), RAM capacity and type, storage class (NVMe over SATA for database work), RAID options, port speed and bandwidth allowance, and remote management access (IPMI/iDRAC) for out-of-band recovery. Also confirm the upgrade path: adding RAM or swapping drives on a dedicated server typically requires downtime, so if you need zero-downtime scaling, consider a[Private Cloud](https://www.atlantic.net/private-cloud-hosting/what-is-private-cloud-hosting/) or[Dedicated Cloud](https://www.atlantic.net/dedicated-cloud-hosting/what-is-dedicated-cloud-hosting/) environment instead.

Related Guides:

- [HIPAA-compliant Hosting Solutions](https://www.atlantic.net/hipaa-compliant-hosting/)
- [PCI-Compliant Hosting Solutions](https://www.atlantic.net/pci-compliant-hosting/)
- [What Are Managed Services?](https://www.atlantic.net/managed-services/what-are-managed-services/)

Related Products:

- [Atlantic.Net Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/)
- [Atlantic.Net HIPAA-compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)
- [Atlantic.Net GPU Hosting](https://www.atlantic.net/gpu-server-hosting/)

 


---

# What Makes Atlantic.Net HIPAA Compliant?

> URL: https://www.atlantic.net/hipaa-compliant-hosting/what-makes-atlantic-net-hipaa-compliant/ | Published: 2026-01-29 | Author: Richard Bailey

Atlantic.Net is a leading business in healthcare hosting; HIPAA Compliant Hosting is one of our most successful cloud-based services. Atlantic.Net complies with the required physical, technical, and administrative safeguards of HIPAA, and we offer a principal platform for our healthcare partners to become HIPAA-compliant in no time.

[Atlantic.Net is audited specifically for HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/), and we are audited at least once a year to ensure that we adhere to the mandatory best practices, business processes, and safeguarding measures needed to protect the integrity of electronic Protected Health Information (ePHI).

In reality, the checks and balances Atlantic.Net uphold far exceed the minimum requirements for HIPAA compliance. We always aim to go above and beyond to secure our healthcare clients’ cloud data. The company provides extensive managed services, managed security, and high-end encryption, and fully complies with SOC 2 and SOC3. Furthermore, Atlantic.Net is fully compliant and audited against the demanding HIPAA and HITECH standards.

## What Is HIPAA?

HIPAA is a Health Insurance Portability and Accountability Act that was signed and enacted into law on August 21, 1996. The law was created to uphold the data integrity of protected health information (PHI) and offer guarantees to patients about how their data was handled.

![](https://www.atlantic.net/wp-content/uploads/2021/02/What-is-HIPAA-05.jpg)

## Is Atlantic.Net HIPAA Compliant?

Absolutely **yes** for our in-scope HIPAA-Compliant Hosting! As a business, we thrive and excel giving our customers the best HIPAA platform for their needs. For clarity, we provide other (non-HIPAA-Compliant) hosting services in-house, and you will find [all HIPAA-Compliant services on our main page](https://www.atlantic.net/hipaa-compliant-hosting/).

## What Makes Atlantic.Net HIPAA Compliant?

In this article, we will examine what responsibilities belong to Atlantic.Net, what responsibilities our healthcare customers have, and what responsibilities are shared between Atlantic.Net and our customers.

![](https://www.atlantic.net/wp-content/uploads/2021/02/What-Makes-Atlantic.Net-HIPAA-Compliant-infographic.jpg)

## What Is Atlantic.Net Responsible for?

- **Cloud Servers** – Atlantic.Net manages the entire HIPAA compliant stack, including the servers, networking, and storage. This management includes support and maintenance on all proprietary cloud software.
- **Storage** – The maintenance and upgrades of the storage platform are the sole responsibility of Atlantic.Net. We will ensure the performance of the storage is always excellent and we will continue to improve and upgrade our storage to exceed industry needs. Our engineers will replace any failed disks within an agreed SLA and destroy the damaged media to HIPAA standards.
- **Networking** – The network layer is controlled and audited by Atlantic.Net. We segregate traffic per HIPAA regulations and operate a continuous upgrade program to ensure the infrastructure is protected to the highest standards.
- **Encryption at Rest** – Safeguarding PHI is our number one priority, and we provide encryption at rest on all Atlantic.Net Cloud platforms by default. The storage layer is protected by a minimum of AES256 encryption, and only Atlantic.Net has the private key to access and unlock the at-rest data.
- **Physical Security** – Our servers are located in highly secure data center compounds that are protected by access control systems. Physical access to and from the server room is limited to very few essential employees, and the building and premises are monitored by CCTV and security personnel 24×7.
- **Data Center** – We provide a 100% uptime guarantee with our Service Level Agreement. We do this by having our data centers configured in a way to allow co-maintainability along with the ability to lose any one point of failure without causing any physical data center issues for the power, cooling, and networking.
- **Initial Server Hardening** – All hosts on our HIPAA platform undergo pre-build server hardening, during which the server is customized to our required security standards. Any host drivers and firmware are updated to our required level to provide the best performance and security, and we ensure the base operating system is configured for enhanced security. We turn off any unused system services, close potential security exploits, and optimize each platform.

## What Is the Healthcare Customer Responsible for?

Atlantic.Net will do as much as possible to help our healthcare clients. We are always available for help and assistance, so do not hesitate to get in touch.

- **Applications **– It is the customer’s responsibility to manage and maintain any additional software and licenses used in day-to-day operations, including off-the-shelf applications or in-house custom software.
- **Database** – Clients are responsible for the day-to-day maintenance of any database applications hosted on the platform, including database security, user credentials, and privileges. This also includes the data contained within the database. If the customer requires the database to be additionally encrypted, this must be managed by the customer; this is highly recommended according to industry best practices.
- **Customer Data** – The customer is solely responsible for client data. Atlantic.Net has no access to any of the data files on your service, so it is the customer’s responsibility to ensure PHI is encrypted and that customer records are correct.
- **Identity and Access Management** – The client has ownership of the entire user lifecycle. Atlantic.Net provides the tools to complete the job; however, the customer must add, modify and delete users and handle all access queries including permissions.
- **Client-side data encryption and data integrity authentication** – Any frontend client-side encryption technology, such as PGP, BitLocker, and application-specific encryption, is the responsibility of the customer.
- **Service-Side Encryption (File System and/or Data)** – Any backend service-side encryption technology, typically database and application-specific encryption, is the responsibility of the customer outside of the physical disks since they are encrypted at rest by default by ACP.

## What Are the Shared Responsibilities between Atlantic.Net and Our Healthcare Customers?

Making HIPAA compliance work requires the creation of a shared responsibility matrix. Both parties have a joint responsibility to meet the compliance goals set out in HIPAA legislation.

- **Firewall**– A Fully Managed Firewall service is provided and maintained by Atlantic.Net for managed services customers. We ensure the availability and privacy of the service. Self-service customers can utilize the operating system’s built-in firewall features or another avenue that best fits their needs if they do not opt for the Fully Managed Firewall. Atlantic.Net also offers a Web Application Firewall (WAF) for added security – [get in touch](https://www.atlantic.net/hipaa-compliant-hosting/#GetStarted) to learn more.
- **Auto-Patching –** The customer is responsible for patching the base operating system, such as Windows Updates or Yum Updates for Linux, including scheduling. Customers can also opt for a managed service offering that includes patch management performed by our technical teams.
- **Operating System** – Atlantic.Net is responsible for the hardware layer firmware levels of the compute nodes, networking, and storage. This also includes patching and maintenance of the hypervisor of the cloud platform.
- **Log Inspection** – Atlantic.Net systems monitor all aspects of the HIPAA platform, and monitoring and logging events is a shared responsibility. Ensuring the logging is enabled is the responsibility of Atlantic.Net, and the customer must react to the findings in the logs.
- **VPN** – For managed services customers taking the Managed Firewall option, we offer a VPN service to secure and encrypt a point-to-point tunnel for end-users. Atlantic.Net maintains the hardware and software that provides this connectivity, but the customer must enforce its use and manage user activity over the VPN.
- **Backup** – Our highly redundant backup service is available to all our HIPAA clients. The service can be configured for On-site and Off-site backups. It is the customers’ responsibility to ensure that the backup services meet or exceed the requirements of the customer’s business. An enhanced replication service is available on request; please [contact our sales team](https://www.atlantic.net/hipaa-compliant-hosting/#GetStarted) for more information
- **Intrusion Prevention Service** – The IPS scans the network layer and sniffs for unusual activity. Atlantic.Net offers this as a fully managed service, and this IPS provides insights into who is trying what on your network along with your Fully Managed Firewall.
- **Trend Micro™ DEEP SECURITY System Security Package** – By monitoring critical operating system and application files, such as directories, registry keys, and values, Integrity Monitoring detects and reports malicious and unexpected changes to files, the hypervisor, and systems registry in real-time. Log inspection optimizes the identification of key security events buried in log files across the data center, which the SIEM system correlates, reports, and archives. Event tagging replicates actions for similar events across the entire data center, reducing cost, while agentless configuration adds security to virtual machines without adding footprint.
- **Integrity Monitoring** – The cloud monitoring service provides numerous real-time performance stats regarding the customers’ infrastructure. The customer is responsible for reacting to identified issues that might be caused by bad actors or malicious software.
- **Anti-Malware** – Malware is a serious concern for anyone with a cloud presence. Atlantic.Net provides new cloud servers that are free from malware, but we recommend our customers have anti-malware software installed and updated. Not all anti-malware will be suitable, so picking one of the best in the market and ensuring constant updates is a key part of HIPAA compliance.
- **********DNS** – Atlantic.Net hosts a highly efficient DNS platform to manage how your domain names interact with the HIPAA compliant hosting platform. Configuration of the platform is down to the individual customer, as well as managing domain name purchases and maintenance.  If you have any issues, Atlantic.Net is here to help with our Managed Services division.
- **Multi-Factor Authentication (MFA)** – MFA is a very effective way to reduce the attack surface of a healthcare customer. Token-based access is defined using either a local app or mobile phone. Atlantic.Net manages the infrastructure that provides the service, and the customer looks after user management, key management, and device management, including the revoking of user access.
- **Web DDoS Protection** – The DDoS managed service is a highly efficient platform for automatically detecting unexpected traffic spikes or DDoS attacks. The service is managed by Atlantic.Net, but we appreciate feedback and interaction with our clients, as sometimes the customer notices something is amiss first. A content delivery network (CDN) improves protection further and delivers significant performance boosts to high traffic customers. The CDN platform is managed by Atlantic.Net, but the customer has to ensure that no PHI is cached on the CDN.
- **Vulnerability Scanning** – Atlantic.Net offers vulnerability scans as part of our Managed Server offering.  This service will scan your entire environment while looking for any possible vulnerabilities that may be present. If you have the Managed Server offering, we will work hand in hand with you and your team to ensure these holes are patched.

As you can see, Atlantic.Net introduces several [safeguards](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/) and standards needed to uphold [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/). The service is durable and security-conscious and, working together with our healthcare customers, the platform has evolved and will continue to grow as our customer needs change.

For over 30 years, Atlantic.Net has helped thousands of businesses with industry-leading [HIPAA compliant cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA compliant website hosting solutions](https://www.atlantic.net/hipaa-compliant-hosting/).  Atlantic.Net Cloud is a far superior alternative to traditional providers, providing full control of your cloud server hosting software backed by either public or dedicated resources.  Contact an advisor at 866-618-3282 or email us at [sales@atlantic.net](mailto:sales@atlantic.net) to get started with a hosting solution for your business!


---

# The Best Bare Metal Hosting Services for 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/top-5-bare-metal-hosting-services/ | Published: 2026-01-29 | Updated: 2026-07-23 | Author: Dr. Assad Abbas

*Updated: July 2026*

Bare metal hosting is[single-tenant](https://www.atlantic.net/dedicated-server-hosting/achieving-unparalleled-security-with-single-tenant-dedicated-hosting/) physical hardware you rent from a provider, no shared neighbors and no hypervisor overhead. It’s the right fit when you need consistent latency, dedicated I/O, strict isolation for compliance, or direct access to hardware for demanding databases and compute workloads.

For mission-critical workloads in 2026, bare metal hosting remains the superior choice over standard virtualization. By giving you direct access to single-tenant hardware, bare metal eliminates resource contention, ensuring consistent latency for AI and database applications, and simplifies compliance with strict standards like HIPAA and[PCI-DSS](https://www.atlantic.net/pci-compliant-hosting/pci-dss-4-0-is-mandatory-a-hosting-checklist-for-2026/).

The best[bare metal hosting](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) services for 2026 are Atlantic.Net (Best for Compliance & Support), PhoenixNAP (Best for API-Driven DevOps), IONOS (Best for Enterprise Value), Hetzner (Best for Budget), and AWS (Best for Hyperscale )

## Compare Top Bare Metal Providers

| **Atlantic.Net** | Compliance (HIPAA) | Dedicated (Monthly) | SLA-backed; config-dependent | Multi-Region (US/Global) | Managed or Unmanaged |
| --- | --- | --- | --- | --- | --- |
| **PhoenixNAP** | DevOps & Automation | Bare Metal Cloud (Hourly) | 20 Gbps / API-driven | Global (US/EU/Asia) | Support + Self-Service |
| **IONOS** | EU/UK Enterprise | Bare Metal Servers | Unlimited traffic options | UK + Global | Self-Managed + Tooling |
| **Hetzner** | Budget / Value | Dedicated (Monthly/Auction) | Unmetered 1 Gbit/s | EU (DE/FI) + US | Unmanaged (Hardware only) |
| **AWS (EC2 Metal)** | Hybrid / Scalability | On-Demand (Hourly) | Egress fees apply | Global AWS Regions | Managed Cloud Service |
| **Oracle (OCI)** | HPC & AI Workloads | Cloud Bare Metal | High bandwidth; HPC-focused | Global OCI Regions | Managed Cloud Service |
| **OpenMetal** | Private Clouds | OpenStack Private Cloud | Included private networking | Multi-Region | Provider-Assisted |
| **IBM Cloud** | Custom Configs | Hourly or Monthly | Free private network traffic | 60+ Data Centers | Cloud-Managed |
| **InterServer** | Budget / Unmanaged | Dedicated Hardware | Clear bandwidth/port options | US-Focused | Unmanaged |

## Why bare metal hosting still matters in 2026

Bare metal is not a “bigger VM.” It’s single-tenant physical hardware reserved for your use, unlike a virtual server that shares host capacity; here, you get exclusive physical resources. That matters when you need:

- **Predictable performance:** dedicated performance without shared-resource contention, so workloads aren’t affected by other users or other tenants.
- **Isolation:** simpler segmentation for sensitive workloads.
- **Hardware control:** direct access to CPU, memory, and storage behavior, with full control over the software stack and server administration choices (useful for certain databases, virtualization stacks, and low-level tooling).

## 1. [Atlantic.Net](http://atlantic.net)

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

**Best for: Compliance-First Workloads (HIPAA/PCI) & Managed Support**

Atlantic.Net continues to lead the market in 2026 for organizations that cannot afford compliance risks. Unlike providers that offer “raw” hardware and walk away, Atlantic.Net specializes in secure, audited environments tailored for healthcare, fintech, and contractors. Their [bare metal](https://www.atlantic.net/dedicated-server-hosting/what-is-a-bare-metal-server-benefits-use-cases-and-best-practices/) solutions are designed to meet strict regulatory frameworks (HIPAA, HITECH, PCI-DSS, SOC 2/3) out of the box.

Below is Atlantic.Net’s cloud control panel interface used to deploy and manage dedicated and GPU servers.

![Atlantic.Net Server Panel](https://www.atlantic.net/wp-content/uploads/2026/01/Atlantic.net-server-panel.png)
 Image Source: Atlantic.Net

- **Compliance Ready:** All infrastructure is audited for HIPAA and SOC standards, making it the safest choice for processing [ePHI](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) or sensitive financial data.
- **High-Performance Specs:** Configurations support up to 128 vCPU threads, 1 TB+ RAM, and redundant NVMe storage, ideal for high-throughput databases.
- **Human-First Support:** Includes 24/7/365 US-based support that acts as an extension of your IT team, critical for preventing downtime in regulated sectors.
- **Flexible Deployment:** Offers both unmanaged options for total control and fully [managed hosting](https://www.atlantic.net/dedicated-server-hosting/what-is-managed-hosting/) where the provider handles OS updates, security patches, and firewalls.

What stands out

- Dedicated hosting plans are published with example configurations and pricing (useful for budgeting).
- Dedicated server service level guarantee language is clearly stated (network/infrastructure components).
- Compliance hosting positioning is front and center for regulated workloads.

Who should choose Atlantic.Net? Healthcare providers, fintech companies, SaaS teams undergoing audits, and anyone who needs a vendor that can support security and compliance conversations (not just sell hardware).

## 2. PhoenixNAP

![](https://www.atlantic.net/wp-content/uploads/2025/08/Phoenix-Nap-Logo.png)

**Best for: DevOps, Automation, and “[Bare Metal Cloud](https://www.atlantic.net/dedicated-server-hosting/bare-metal-cloud-servers-for-high-performance-workloads/)“**

PhoenixNAP has bridged the gap between dedicated hardware and cloud agility. Their “Bare Metal Cloud” platform allows developers to provision physical servers in minutes via API, CLI, or Terraform, rather than the days-long provisioning cycles of traditional hosts. This makes them a top choice for CI/CD pipelines and agile teams in 2026.

PhoenixNAP’s Bare Metal Cloud dashboard interface is used to deploy and manage dedicated servers, Kubernetes clusters, billing, and infrastructure resources.

![PhoenixNAP dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/PhoenixNAP-bmc-portal-home-page.webp)

 

Image Source: PhoenixNAP

What stands out

- **API-First Architecture:** fully compatible with Terraform, Ansible, and Pulumi for “Infrastructure as Code” deployments.
- **Hourly Billing:** One of the few bare metal providers offering true hourly billing, allowing you to spin up high-power instances for short-term rendering or compilation tasks.
- **Global Footprint:** Strong presence across the US, Europe, and Asia, ensuring low latency for globally distributed applications.

Who should choose PhoenixNAP? DevOps engineers, SaaS platforms needing automated scaling, and teams who want to treat physical servers like ephemeral cloud instances.

## 3. IONOS

![](https://www.atlantic.net/wp-content/uploads/2025/08/ionos-logo.png)

**Best for: Enterprise Value & European Presence**

IONOS (formerly 1&1) remains a powerhouse for businesses seeking reliable enterprise-grade hardware without the hyperscaler price tag. They are particularly strong in the European market but have a good US presence. Their commitment to sustainability, running data centers on renewable energy, is a key differentiator for ESG-focused companies in 2026.

Look at the IONOS Cloud control panel showing server image management, infrastructure configuration, and US data center deployment options.

![IONOS cloud panel](https://www.atlantic.net/wp-content/uploads/2026/01/IONOS-cloud-panel.png)
 Image Source: IONOS

- **Predictable Pricing:** Offers transparent monthly contracts that avoid the unpredictable egress fees common with larger public clouds.
- **Modern Hardware:** Extensive inventory of Intel Xeon and AMD EPYC processors with unlimited traffic options on 1 Gbit/s ports.
- **Security Standard:** ISO 27001-certified data centers with built-in SIEM and [DDoS protection](https://www.atlantic.net/vps-hosting/what-is-a-ddos-and-how-do-we-prevent-our-business-from-being-attacked/) included in most enterprise plans.

What stands out

- **Sustainability**: Data centers are powered largely by renewable energy.
- **Traffic Policy**: Unlimited traffic on many configurations eliminates egress anxiety.
- **Pay-as-you-go**: Offers hourly billing options alongside monthly contracts.

Who should choose IONOS? Companies doing business in the UK/EU, or US enterprises looking for a secondary provider with predictable monthly billing.

## 4. Hetzner

![](https://www.atlantic.net/wp-content/uploads/2026/01/Hetzner.jpg)

**Best for: Budget & Raw Performance Value**

For technical teams who are comfortable managing their own infrastructure, Hetzner offers the best price-to-performance ratio in the industry. While they offer minimal hand-holding (support is strictly hardware-focused), their pricing for high-core AMD Ryzen and EPYC servers is very good.

View the Hetzner dashboard interface designed to deploy cloud servers, configure networking, and monitor activities across global locations.

 

![hetzner-dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/hetzner-dashboard.png)

Image Source: Hetzner

- **Unbeatable Value:** High-performance servers often start at a fraction of the cost of major US competitors.
- **Hetzner Cloud:** Ability to mix bare metal servers with their cloud VPS offerings via private networks (vSwitch).
- **Auction Server Market:** Unique “Server Auction” allows users to bid on older, fully functional hardware for non-critical workloads at rock-bottom prices.

What stands out

- **No Contracts:** Most servers are available on a month-to-month basis with no long-term commitment.

Who should choose Hetzner? Bootstrapped startups, media streaming services, and technical teams who are comfortable managing their own Linux stack and want to minimize infrastructure costs.

## 5. AWS (Amazon EC2 Metal)

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

**Best for: Hybrid Cloud & Hyperscale Scalability**

Amazon Web Services offers “Bare Metal” instances (e.g., i3.metal, m5.metal) that allow applications to run directly on the underlying hardware while still integrating with the broader AWS ecosystem. While significantly more expensive than standalone providers, this option is for enterprises that need to run legacy applications (like VMware stacks) inside their existing AWS VPCs.

Here is the AWS EC2 dashboard, where you can control instances, monitor status, and configure settings.

 

![AWS Instance](https://www.atlantic.net/wp-content/uploads/2026/01/AWS-Instance.png)

Image Source: AWS

- **Deep** Bare metal instances sit inside your Virtual Private Cloud (VPC) and work seamlessly with AWS storage (EBS/S3) and security groups.
- **Legacy Support:** The only viable way to run legacy virtualization stacks that require direct hardware access within a public cloud environment.
- **Elasticity:** While it is physical hardware, it can be provisioned and terminated with the same ease as a virtual EC2 instance.

What stands out

- **Global reach**: Available in virtually every AWS region worldwide.

Who should choose AWS? Cloud-native teams needing temporary raw power, or enterprises migrating legacy applications that require direct hardware access but must live inside an AWS VPC.

## 6. Oracle Cloud Infrastructure (OCI)

![](https://www.atlantic.net/wp-content/uploads/2025/08/Oracle-cloud-infrastructure.png)

**Best for: HPC & AI Workloads**

Oracle has aggressively targeted the high-performance market in 2026. Their bare metal instances are designed for massive throughput, supporting clustered networking that is ideal for AI model training and complex simulations. They offer some of the highest core-count configurations available publicly.

Take a look at the Oracle Cloud dashboard, where you can set up load balancers, manage billing, and deploy resources from a single panel.

 

![Oracle-dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Oracle-dashboard.jpg)

Image Source: Oracle Cloud

- **Key Specs:** Up to 192 cores (AMD EPYC), 2TB+ RAM, NVIDIA GPU clusters.
- **Compliance:** Complete global and regional compliance certifications.
- **Support:** Oracle Cloud Support (included with paid accounts).
- **Verdict:** If your primary metric is raw compute performance per dollar, specifically for AI or database workloads, OCI is the heavy hitter.

What stands out

- **Cluster Networking:** Provides low-latency connectivity between bare metal instances, critical for HPC.
- **Aggressive pricing:** Outbound data transfer costs are often significantly lower than AWS or Azure.
- **Specific hardware focus:** Configurations are explicitly designed for Oracle Database and high-load scenarios.

Who should choose Oracle OCI? Data scientists, research institutions, and enterprises running massive Oracle Databases or training large language models (LLMs).

## 7. OpenMetal

![](https://www.atlantic.net/wp-content/uploads/2025/09/OpenMetal.png)

**Best for: Private Cloud & OpenStack**

OpenMetal disrupts the standard “rent a server” model by providing a private cloud core. Instead of a single standalone server, you typically deploy a cluster of three bare metal servers pre-configured with OpenStack. This gives you the autonomy of single-tenant hardware with the flexibility to create your own virtual machines.

Here is the OpenMetal dashboard, where you can manage hardware assets, monitor servers, and configure infrastructure resources.

 

![Openmetal-dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Openmetal-dashboard.png)

Image Source: OpenMetal

- **Key Specs:** Converged usage (Compute + Storage), Ceph storage, OpenStack control plane.
- **Compliance:** ISO 27001 certified data centers; hardware isolation aids compliance.
- **Support:** Provider-assisted; engineering support for OpenStack.
- **Verdict:** The best middle ground for teams who want the features of a public cloud (APIs, VM spinning) but want to own the underlying hardware physically.

What stands out

- **Open Source focus:** No vendor lock-in; you are using standard OpenStack.
- **Speed:** Deploys a full private cloud cluster in roughly 45 minutes.
- **Transparency**: Clear pricing on hardware versus software/support costs.

Who should choose OpenMetal? SaaS providers and DevOps teams who want to build their own internal cloud infrastructure without paying hyperscaler margins.

## 8. IBM Cloud

![](https://www.atlantic.net/wp-content/uploads/2025/06/ibm-logo.png)

**Best for: Custom Enterprise Configurations**

IBM Cloud differentiates itself with granular customization. While other clouds offer “T-shirt sizes” (Small, Medium, Large), IBM allows you to configure over 11 million combinations of processor, RAM, and drive types. It is built for complex, hybrid enterprise architectures.

Let’s see the IBM Cloud interface for creating resources, managing applications, and monitoring storage and services across your environment.

 

![IBM Cloud](https://www.atlantic.net/wp-content/uploads/2026/01/IBM-Cloud.png)

Image Source: IBM Cloud

- **Key Specs:** SAP-certified servers, extensive NVIDIA GPU options, and Intel/AMD custom builds.
- **Compliance:** FFIEC, HIPAA-ready options, rigorous enterprise standards.
- **Support:** Enterprise-grade support structures tailored for Fortune 500s.
- **Verdict:** The go-to choice for complex legacy migrations where the hardware must match specific vendor requirements exactly.

What stands out

- **Global Private Network:** Free data transfer between your IBM servers across different data centers.
- **Customizability:** You can pick the exact drive model and RAM speed you need.
- **Satellite:** Ability to extend IBM cloud services to your own on-prem infrastructure.

Who should choose IBM Cloud? Large financial institutions, SAP users, and enterprises that need exact hardware specifications to meet vendor software requirements.

## 9. InterServer

![](https://www.atlantic.net/wp-content/uploads/2025/12/interserver.png)

**Best for: Budget & Unmanaged Power**

InterServer focuses on delivering raw power at an accessible price point. They strip away the “[managed services](https://www.atlantic.net/managed-services/)” overhead to offer high-bandwidth dedicated servers for technical users. Their “Price Lock Guarantee” ensures your hosting costs won’t creep up over time.

Look at the InterServer client dashboard for managing dedicated servers, bandwidth configurations, and service provisioning.

![interserver-server-panel](https://www.atlantic.net/wp-content/uploads/2026/01/interserver-server-panel-1.png)

 

Image Source: InterServer

- **Key Specs:** 10Gbps port options, huge bandwidth allocations, Rapid Deploy servers.
- **Compliance:** Standard data center security (tier 3/4).
- **Support:** 24/7 ticket/phone, but scope is limited to hardware/network uptime.
- **Verdict:** Excellent value for users who are comfortable managing their own OS and security stack.

What stands out

- **High Bandwidth:** One of the most generous bandwidth policies for the price.
- **No Setup Fees:** Frequently waives setup fees on rapid deploy servers.
- **Simplicity**: A straightforward “you rent the box, you run the box” model.

Who should choose InterServer? Sysadmins, media streaming startups, and budget-conscious projects that need bandwidth without the enterprise markup.

## Bare Metal Servers vs Dedicated Servers vs Cloud VMs

In practice, “bare metal” and “dedicated server” often describe the same outcome: one tenant, one machine, unlike shared hosting where multiple customers use pooled resources on the same platform. The difference is usually the purchase experience:

- **Dedicated server hosts** tend to be monthly, hardware-catalog driven, and offer hands-on support options.
- **Cloud bare metal** (AWS/OCI/IBM) is provisioned like cloud infrastructure, often with on-demand billing and API-first workflows, so it can feel similar to cloud solutions operationally even though it still runs on physical hardware.

At the infrastructure level, bare metal technology gives you exclusive physical resources, unlike a virtual server that shares capacity.

If you need burst capacity and are tight on managed cloud services, bare-metal cloud often wins. If you need a provider-led compliance posture and predictable monthly operations, dedicated hosts are often simpler to run.

## 2026 watch-out: Equinix Metal shutdown (migration planning)

If you’re currently on Equinix Metal,[plan a migration now](https://docs.equinix.com/metal/). Equinix states the Equinix Metal service will sunset on June 30, 2026.

A practical path is first to map your current server shapes, networking requirements, and automation dependencies (Terraform, image pipelines, IP allocations), then decide whether you want:

- **Cloud bare metal** (Atlantic.Net/AWS/OCI/IBM) for API-first provisioning, or
- **Dedicated hosts/private cloud** (Atlantic.Net/OpenMetal/IONOS-type options) for steadier monthly operations.

## How to choose a bare metal provider (2026 checklist)

1. **Define the workload clearly.** CPU model preference, RAM, storage type (NVMe vs SATA), and whether you need RAID. NVMe is the safe default for high-performance databases and I/O-heavy workloads; SATA still makes sense for bulk and object storage tiers.
2. **Decide on management responsibility.** Unmanaged saves money and gives you full control, but patching, monitoring, and incident response stay on your side.
3. **Model bandwidth costs.** Look for published port speeds, including transfer, or a clear overage method.
4. **Pick locations for latency.** Shorter physical distance still matters for user experience and replication. Latency-sensitive workloads such as trading platforms and multiplayer game servers benefit most from bare-metal dedicated servers here: dedicated resources and uncontended I/O, plus a data center close to users, keep response times flat under load. Providers with global data centers make it easier to place capacity near each user base.
5. **Validate security/compliance fit.** Ask what the provider covers vs what you must configure (shared responsibility). Confirm whether anti-DDoS protection is included in the plan or sold as an add-on, and at what mitigation scope. Single-tenant resource isolation simplifies audits, but the network edge still needs defending.
6. **Check provisioning speed.** A bare metal cloud server can be live in minutes via API, and some platforms let you deploy with just a few clicks; a traditional custom build can take days. If your business relies on automation or short-lived capacity, instant provisioning and Terraform support belong on the requirements list.
7. **Confirm which operating systems are supported.** Verify the provider’s image list covers the operating systems your stack requires, and whether custom OS installs are possible via IPMI access or a mounted ISO. If recovery workflows matter, also check whether the provider includes full IPMI access. Windows licensing and unusual distributions are the common friction points.
8. **Plan for hybrid-cloud.** If your business runs bare metal dedicated servers alongside cloud VMs or object storage, confirm a private network connects the two (Hetzner’s vSwitch, AWS VPC placement, IBM’s global network) so replication and internal traffic stay off the public internet.
9. **Run a short trial.** Benchmark your real workload, not synthetic tests. Enterprise buyers should also verify published availability rates, especially when providers claim figures above 99.99%.

## Key Terms

- **Bare metal:** a single-tenant physical server rented from a provider, with no hypervisor layer between your software and the hardware resources. Unlike a virtual server, it gives you exclusive physical resources rather than shared capacity on the same host. Sold either as monthly bare-metal dedicated servers or as an hourly bare-metal cloud solution.
- **Single-tenant:** infrastructure reserved for one customer only; no other organization’s workloads run on the same physical machine, which gives you full resource isolation.
- **Hypervisor:** the software layer that divides one physical server’s hardware resources into multiple virtual machines. Bare metal removes it, which removes its overhead and its shared-tenancy risks.
- **Colocation:** renting rack space, power, cooling, and network connectivity for server hardware you own; the provider houses and powers the equipment, your business manages it.
- **NVMe:** a storage protocol that connects SSDs directly over PCIe, delivering lower latency and higher throughput than SATA. The default choice for high-performance database workloads.
- **IPMI:** an out-of-band management interface that lets you power-cycle, monitor, and reinstall a server even when its operating system is unresponsive. Some providers also include full IPMI access for remote hardware control and deeper maintenance tasks.

## Frequently Asked Questions

### What is bare metal hosting and how does it differ from virtualized cloud hosting?

Bare metal hosting rents you a single-tenant physical server with dedicated resources and no hypervisor between your workload and the hardware. In virtualized cloud hosting, a hypervisor splits one physical machine between multiple customers, so “noisy neighbors” can impact your speed. A virtual server shares hardware with other users, while bare metal avoids interference from other tenants. Bare metal guarantees 100% of the CPU, RAM, and I/O resources belong to you, which is critical for databases, AI training, and real-time processing. Note that “[dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/)” traditionally refers to renting a physical server on a monthly contract. At the same time, “Bare Metal Cloud” describes physical servers that can be provisioned and automated instantly (often hourly) like virtual cloud servers, a model often chosen for dedicated performance and full control.

### Is bare metal necessary for HIPAA compliance?

It is often preferred. While you can achieve HIPAA compliance in a shared cloud, single-tenant bare metal servers drastically reduce risk. Physical isolation eliminates the risk of data leakage between tenants and simplifies the auditing process required for handling ePHI.

### Can I scale a bare metal server?

Scaling bare metal is “vertical” (upgrading RAM/Disk) and usually requires downtime. Modern providers like Atlantic.Net and PhoenixNAP allow you to deploy additional servers quickly, enabling “horizontal” scaling by distributing workloads across multiple physical machines.

### Should I choose a managed or unmanaged plan?

If your team has strong Linux/Windows administration skills and can handle server administration, unmanaged is cheaper. If you need guaranteed uptime and help with security patching, firewalls, compliance audits, and maintaining the software stack, a Managed Service provider (like Atlantic.Net) is highly recommended to reduce operational risk.

### What is the typical provisioning time for a bare metal server?

Provisioning time depends on the deployment model. A bare metal cloud solution such as PhoenixNAP provisions physical servers in minutes through an API, CLI, or Terraform; OpenMetal deploys a full private cloud cluster in roughly 45 minutes. Traditional bare metal dedicated servers built to order can take hours to several days, particularly for unusual hardware combinations. If deployment speed matters for your business, confirm whether the provider keeps pre-racked, rapid-deploy inventory, ships operating systems as ready-made images, and offers automated provisioning across its global network of data centers.

### What are the benefits of using bare metal servers for databases?

Bare metal dedicated servers give a database full, uncontended access to the machine’s hardware resources, which keeps query latency predictable under load. There is no hypervisor overhead, and resource isolation means no neighboring tenant can compete for disk throughput during peak periods. Direct access to NVMe storage also lets you tune the kernel, filesystem, and RAID layout for the specific database engine, which virtualized environments limit. This is why high-performance transactional databases and large analytics workloads are among the most common business use cases for bare metal.

### What is the difference between bare metal hosting and colocation?

With colocation, you buy and own the server hardware and rent rack space, power, cooling, and network connectivity in someone else’s data center. With bare metal hosting, the provider owns and maintains the dedicated servers and rents them to your business on a monthly or hourly basis. Bare metal shifts hardware procurement, replacement, and lifecycle management onto the provider, while colocation gives you total control over the equipment at the cost of capital expense and hands-on maintenance. Most businesses choose bare metal unless they already own hardware or have unusual equipment requirements.

### How do you achieve high availability in a bare metal hosting environment?

High availability on bare metal comes from deploying multiple servers and removing single points of failure, since one physical machine cannot be live-migrated the way a virtual machine can, and true resilience depends on both server redundancy and network quality. Common patterns include load balancers in front of two or more application servers, database replication with automatic failover, and distributing servers across global data centers for geographic redundancy. A private network between servers keeps replication traffic isolated, anti-DDoS protection at the network edge stops a volumetric attack from taking every node down at once, and replicated object storage protects backups. Bare-metal cloud servers with API provisioning also make it faster to replace a failed node, which helps maintain consistent performance across the environment.


---

# OpenClaw (ClawdBot): Open-Source AI Agent — and How to Deploy It on Atlantic.Net Cloud

> URL: https://www.atlantic.net/cloud-platform/openclaw-open-source-ai-agent-and-how-to-deploy-it-on-atlantic-net-cloud/ | Published: 2026-01-29 | Updated: 2026-06-04 | Author: Richard Bailey

## OpenClaw (ClawdBot): Open-Source AI Agent — and How to Deploy It on Atlantic.Net Cloud

OpenClaw is an AI agent gaining extensive attention across the technology sector. Over the past year, autonomous, task-executing assistants have gained popularity, including tools like Cursor and Codex. OpenClaw(formerly known as Moltbot and ClawdBot) serves as a primary example of this trend. What began as a niche, self-hosted tool has changed into *the* widely discussed open-source project in 2026.

In this guide, we’ll explore why OpenClaw (Clawdbot) is going viral and walk through how to deploy it securely on Atlantic.Net Cloud.

## **What is OpenClaw?**

OpenClaw is an open-source autonomous agent framework designed to execute complex tasks through simple chat interfaces. Unlike standard chatbots that only provide text responses, OpenClaw can interact with your file system, execute code, and manage external APIs to act as a persistent digital helper. It serves as a bridge between high-level AI reasoning and practical, technical execution.

## **From ClawdBot to MoltBot to OpenClaw**

OpenClaw originally entered the scene under the name ClawdBot. Just to confuse matters, it was called MoltBolt for about 1 week in January 2026. It was initially developed as a specialized wrapper for the Anthropic Claude models, designed to give the AI more “agency” over local environments. As the project grew to support various models and sophisticated integrations, the developers rebranded it to OpenClaw in late 2025 to reflect its ability to “molt” or shed its original limitations and change into a model-agnostic powerhouse.

## Why Deploy OpenClaw on Atlantic.Net Cloud?

Running an always-on AI agent requires stability and connectivity that a home laptop can’t provide. Atlantic.Net is the ideal environment because:

- **Always-On Availability:** Your agent needs to be awake 24/7 to answer your commands.
- **Performance:** Our G3 instances handle the Node.js runtime and API handling effortlessly.
- **Privacy:** You retain full control. Unlike SaaS AI, OpenClaw runs on *your* server.

## Supported AI Models

OpenClaw is “model agnostic,” meaning it can connect to almost any major AI provider, as well as run local models for privacy. For OpenClaw to work, it’s recommended that you have a subscription to an AI provider.

### Major Cloud Providers:

- **OpenAI:** Supports GPT-4o, o1, and Codex (often used for the “Code” capabilities).
- **Anthropic:** Deep integration with Claude 3.5 Sonnet and Opus (OpenClaw “personality” is often optimized for Claude).
- **AWS Bedrock:** Access to models hosted on Amazon’s infrastructure.
- **Google Cloud:** via Vertex AI or Gemini models (often routed through open gateways).

### Local & Open Source (Privacy-Focused):

- **Ollama:** Run models like Llama 3 or Mistral locally on your Atlantic.Net cloud server. This ensures the logic remains on your hardware, requiring internet access only for the interface.
- **Local Inference:** Supports other local backends compatible with OpenAI-like APIs.

## Supported Communication Channels

OpenClaw can live inside almost any app you use to chat.

### Primary (Best Support):

- **Telegram:** The most stable and recommended experience. Supports rich media, voice notes, and easy setup via API tokens.
- **WhatsApp:** Supports QR-code-based login (Multi-Device). Great for daily use, though slightly less stable than Telegram.
- **Discord:** Runs as a bot user; excellent for community management or group usage.
- **Slack:** Integrates as a workspace app.

### Additional Integrations:

- **iMessage:** Requires a bridge running on macOS hardware.
- **Signal:** Prioritizes encrypted, privacy-first communication.
- **Microsoft Teams:** Designed for enterprise and corporate environments.
- **Matrix:** Built for decentralized, federated chat protocols.
- **Mattermost:** An open-source, self-hosted Slack alternative.
- **Google Chat:** Ideal for users deep in the Google Workspace ecosystem.
- **Line:** The dominant messenger in Japan and Southeast Asia; great for personal use in those regions.
- **Zalo:** The leading chat platform in Asia, fully supported for regional connectivity.

## Tutorial: Deploying OpenClaw on Atlantic.Net Cloud

### Prerequisites:

- An Atlantic.Net Cloud Account.
- An AI API Key – In this example, I will be using OpenAI Codex/GPT.
- A Telegram account (or any other account from the Supported Channels).

### Step 1: Create a Cloud Server

1. Log in to the[Atlantic.Net Cloud Portal](https://cloud.atlantic.net).
2. Click **Add Server**.
3. **Location:** Choose a region close to you (e.g., USA-East).
4. **Image:** Select **Ubuntu 24.04 LTS**.
5. **Plan:** The **G3.4GB** plan (2 vCPU, 4GB RAM) or higher is recommended.
6. Click **Create Server**.

![](https://www.atlantic.net/wp-content/uploads/2026/01/MoltBot-ACP-Page-1.png)

### ![](https://www.atlantic.net/wp-content/uploads/2026/01/MoltBot-ACP-Page-2.png)

### Step 2: Create a Secure User (Important)

Once connected via SSH (ssh root@), it is best practice to create a dedicated user so your AI doesn’t run with root privileges.

| # Create a new user (replace 'moltuser' with your name) adduser moltuser # Grant sudo privileges usermod -aG sudo moltuser # Switch to the new user su - moltuser |
| --- |

### Step 3: Install Node.js 24 via NVM

OpenClaw requires Node.js 24. The most reliable way to handle this on a fresh Cloud Server is using NVM (Node Version Manager).

| # Install NVM curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.3/install.sh \| bash # Activate NVM (or close and reopen terminal) source ~/.bashrc # Install Node 24 nvm install 24 |
| --- |

### Step 4: Get Your Telegram Bot Token

Before installing OpenClaw , you need a “home” for it on Telegram.

1. Open Telegram and search for **@BotFather** (the official bot builder).
2. Send the message: /newbot
3. Follow the prompts to name your bot (e.g., “MyAtlanticAgent”).
4. Copy the API Token it gives you (it looks like 123456:ABC-DEF…).

![](https://www.atlantic.net/wp-content/uploads/2026/01/MoltBot-Telegram-Final.png)

### Step 5: Install and Onboard OpenClaw

The Installation can be completed in two different ways. There is a quick Installer, but I recommend doing the manual installation so you have better granular controls, which also helps you to learn the UI.

#### Quick Installation

If you are in a hurry, run the official installer. This handles the heavy lifting, including setting up the background daemon automatically.

| # Install the package curl -fsSL https://molt.bot/install.sh \| bash # Run the setup wizard openclaw onboard --install-daemon |
| --- |

#### Install OpenClaw Manually (via NPM) – Recommended

Instead of running an opaque installation script, we will use the Node Package Manager (NPM) to install OpenClaw directly from the official registry. This gives you clear visibility into exactly what is being installed.

**Install the Package:**

Run this command to download and install the latest version of the OpenClaw CLI globally:

| npm install -g openclaw@latest |
| --- |

**Verify the Installation:**

Check that the CLI is accessible:

| openclaw --version |
| --- |

**Run the Onboarding Wizard:**

Now that the tool is installed, run the setup wizard to generate your configuration and set up the background service (daemon):

| openclaw onboard --install-daemon |
| --- |

### Wizard Settings:

**Authentication:**

- Choose “OpenAI”

![](https://www.atlantic.net/wp-content/uploads/2026/01/MoltBot-Select-OpenAI.png)

- Open the URL in your Browser

![](https://www.atlantic.net/wp-content/uploads/2026/01/MoltBot-OpenAI-Browser.png)

- Log in to your Codex/ChatGPT account

![](https://www.atlantic.net/wp-content/uploads/2026/01/MoltBot-Signin-Codex.png)

- Copy the URL callback code and paste it into OpenClaw

![](https://www.atlantic.net/wp-content/uploads/2026/01/MoltBot-localhost-code.png)

- **Providers:** Select **Telegram**.
- **Telegram Token:** Paste the token you got from BotFather in Step 4

![](https://www.atlantic.net/wp-content/uploads/2026/01/MoltBot-Telegram-Bot-Code.png)

- **Runtime:** Select **Node**.

### Step 6: Security & Pairing

By default, OpenClaw ignores strangers. You must introduce yourself.

1. Open your new bot in Telegram and send a Hello Message
2. The bot will not reply, but it will register the attempt.

Back in your terminal, check the pending pairing list:

| openclaw pairing list telegram |
| --- |

Approve your user ID using the code displayed:

| openclaw pairing approve telegram  |
| --- |

### ![](https://www.atlantic.net/wp-content/uploads/2026/01/MoltBot-Pair-Telegram.png)

### Step 7: Access the Dashboard Securely (SSH Tunnel)

Instead of opening port 18789 to the entire internet, we will use an SSH Tunnel. This allows you to view the OpenClaw dashboard on your local computer as if it were running there.

**On your local machine (not the server), run:**

| ssh -N -L 18789:127.0.0.1:18789 moltuser@ |
| --- |

*Note: This command will appear to “hang”—that means it’s working!*

![](https://www.atlantic.net/wp-content/uploads/2026/01/MoltBot-SSH-Tunnel.png)

Now, open your browser and go to: localhost:18789

![](https://www.atlantic.net/wp-content/uploads/2026/01/MoltBot-AdminPage.png)

### Step 8: Define Your “Digital Twin” (USER.md)

Most users just chat with their bot and hope it remembers. But as a pro user, you can manually architect its brain.

OpenClaw looks at a specific file called USER.md to understand who you are before every single interaction. Instead of just chatting, we will inject a “System Prompt” for your life directly into this file.

**Open the file for editing:** ****

| nano ~/clawd/USER.md |
| --- |

**Paste in a structured profile (Example below):** This gives the bot immediate, structured context about your projects and preferences.

| # User Profile: [Your Name] ## Core Identity I am a Senior DevOps Engineer at a fintech startup. I value brevity, clean code, and security above all else. When replying to me: Be direct. Do not use fluff. Use bullet points. ## Active Projects 1. ****Project Alpha:**** A migration from AWS to Atlantic.Net.   - Stack: Terraform, Ansible, Ubuntu 24.04.   - Current Status: Testing connectivity. 2. ****Home Automation:**** A Python script to control my lights. ## Preferences - ****Coding:**** Prefer Bash for scripts, Typescript for backend. CDK for IaC - ****Schedule:**** I am deep working from 9 AM to 12 PM. Do not disturb me unless the server is down. |
| --- |

**Save and Exit:** Press Ctrl+O, Enter, then Ctrl+X. *Your bot now instantly knows all of this context without you ever having to explain it in chat.*

## Going Pro: 3 Neat Tricks to Try Immediately

Now that your agent is running, here are three “Power User” features from the[OpenClaw documentation](https://docs.molt.bot/) that turn it from a chatbot into a proactive assistant.

### 1. The “Morning Briefing” (Heartbeat)

OpenClaw has a feature called “Heartbeat” that allows it to wake up and perform tasks even if you haven’t messaged it. You can use this to get a 7:00 AM briefing.

- Edit the heartbeat file:

| - nano ~/clawd/HEARTBEAT.md |
| --- |

Add a logic rule like this:

| - Every morning at 07:00, check the weather in [Your City] and my Google Calendar. - Send me a WhatsApp summary of my day and any urgent emails. |
| --- |

- Now, your agent will text *you* first thing in the morning.

### 2. Give It Internet Access (Brave Search)

By default, your bot can’t search the web. Give it “eyes” by adding the **Brave Search API** (which has a generous free tier).

Get a free API key from

[brave.com/search/api](http://brave.com/search/api).

![](https://www.atlantic.net/wp-content/uploads/2026/01/MoltBot-Brave-API.png)

Run the configuration command:

| openclaw configure --section web |
| --- |

Paste your key. Now you can ask: *“Search for the latest Atlantic.Net pricing and summarize it.”*

### 3. Install New Skills

OpenClaw has a “Skill Store” of sorts. You can teach it to read PDFs, manage GitHub issues, or check stock prices.

List available skills:

| openclaw skills list |
| --- |

Install a skill (e.g., GitHub integration):

| openclaw skills add github |
| --- |

## Final Thoughts

OpenClaw represents an interesting view of where AI might be heading: it’s open-source, runs on your terms, and lives on infrastructure you control. By deploying it on an[Atlantic.Net Cloud Server](https://cloud.atlantic.net/), you ensure it has the high availability and compute power to run 24/7 without slowing down your personal laptop.

You now have a persistent, always-on digital employee. Treat it well, update its USER.md as your life changes, and enjoy the productivity boost!

**Related Guides:**

- [HIPAA Compliant Hosting Solutions](https://www.atlantic.net/hipaa-compliant-hosting/)
- [PCI-Compliant Hosting Solutions](https://www.atlantic.net/pci-compliant-hosting/)
- [What Are Managed Services?](https://www.atlantic.net/managed-services/what-are-managed-services/)

**Related Products:**

- [Atlantic.Net Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/)
- [Atlantic.Net HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)
- [Atlantic.Net GPU Hosting](https://www.atlantic.net/gpu-server-hosting/)


---

# Reliable Cloud Hosting with SSD Storage and 24/7 Support in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/reliable-cloud-hosting-2026-ssd-24-7-support/ | Published: 2026-01-30 | Updated: 2026-06-24 | Author: Dr. Assad Abbas

[Cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) operates by running websites and applications on a group of virtual servers that share the same underlying infrastructure, instead of depending on a single physical machine. This structure reduces single points of failure and helps maintain stable performance even when individual components experience issues. As a result, it has become a practical choice for organizations that require predictable uptime and flexible resource allocation.

In 2026, high-quality SSD storage and real 24/7 human support are widely expected in any reliable cloud environment. Businesses cannot tolerate slow response times or unexpected outages, because these interruptions affect sales, limit customer access, and disrupt internal operations. Such issues result in direct risks and weaken user confidence. For this reason, companies look for hosting platforms that offer efficient infrastructure, fast storage, and continuous expert assistance.

Reliable cloud hosting also depends on consistent service quality under different conditions. SSD storage helps reduce delays and supports quick access to data, while round-the-clock support ensures that technical issues are addressed without unnecessary waiting. Together, these elements create a stable environment that supports long-term growth and steady operational continuity.

## Core Elements of Reliable Cloud Hosting and Storage Performance

Reliable cloud hosting depends on several elements that support stability, speed, and long-term performance. These elements work together to keep applications responsive and reduce the risk of service interruption. Storage performance plays a significant role in this structure because it affects both speed and reliability. Therefore, a strong [cloud platform](https://www.atlantic.net/cloud-platform/) must combine fast storage, stable infrastructure, and dependable support.

### Performance and Storage Consistency

Performance is one of the first aspects users notice when they access a website or application. Slow responses create frustration and reduce trust; therefore, a reliable cloud platform must offer predictable IOPS, low latency, and stable throughput. These factors help applications remain responsive during busy periods and support a smooth user experience.

Storage is a major part of this performance. SSD storage has become the standard because it provides fast read and write operations and supports consistent behavior under different loads. In 2026, most teams expect high‑quality SSD storage to keep performance steady as traffic increases. This expectation reflects a broader need for cloud environments that deliver both speed and reliability in everyday use.

## Infrastructure Resilience and Availability

Reliable cloud hosting depends on an infrastructure that can support steady operations under different conditions. Redundant power, cooling, and network systems help reduce outages and maintain consistent performance, making them central to long‑term reliability.

Clustered [virtualization](https://www.atlantic.net/vps-hosting/what-is-server-virtualization/) increases reliability by distributing workloads across servers. If one server fails, another can take over with limited disruption, which supports high availability and stable performance during changing demand.

Storage performance also contributes to this resilience. High‑quality SSD storage reduces bottlenecks during peak usage and helps keep operations smooth as traffic grows. Together, strong infrastructure and fast storage create a dependable hosting environment.

### 24/7 Human Support and Operational Stability

Operational stability also depends on dependable support. Many businesses operate around the clock, so they need access to skilled engineers at any time. Quick response times help resolve issues before they affect users, and clear escalation paths assist with more complex situations.

Human support is different from automated replies. Experienced engineers understand real scenarios and can guide customers through configuration, troubleshooting, and performance adjustments. This type of assistance helps maintain steady operations. In addition, many performance issues begin with storage settings or resource limits. Therefore, expert support plays a vital role in maintaining both reliability and storage performance.

## Storage Reliability and Data Protection in Cloud Hosting

Storage reliability is an essential aspect of cloud hosting because it determines the long‑term safety and availability of data. While performance focuses on speed, storage reliability focuses on the long‑term health and availability of data. Therefore, cloud platforms must use storage systems that support durability and safe handling of information.

[Redundancy](https://www.atlantic.net/disaster-recovery/what-is-redundancy-a-broad-view/) is a standard method for protecting stored data. In many environments, the same data is written to multiple drives or nodes. If one drive fails, another copy remains available. This helps prevent data loss and reduces the impact of hardware issues.

Data protection also depends on strong measures. [Encryption](https://www.atlantic.net/hipaa-compliant-hosting/encryption-for-hipaa-compliance/) at rest protects information stored on SSD drives, while encryption in transit protects data as it moves between servers and users. These measures help maintain confidentiality and support secure communication inside the hosting environment.

Backups also support storage reliability. Automated backups and snapshots create additional copies of important data. These copies can be restored if files are deleted by mistake or if a system issue occurs. Regular testing of backup restoration confirms that recovery processes work as expected.

Monitoring tools also contribute to storage reliability. They track disk activity, detect unusual patterns, and identify early signs of failure. This helps cloud providers act before a minor issue becomes a significant problem, supporting steady operations.

Overall, storage reliability and data protection are significant components of dependable cloud hosting. SSD storage supports consistent performance, while redundancy, encryption, backups, and monitoring help protect information and maintain long‑term stability. For this reason, storage reliability remains an important consideration when selecting a cloud hosting provider in 2026.

## Key Features to Look for in Reliable Cloud Hosting Providers

Choosing a reliable cloud hosting provider becomes easier when you understand the features that influence performance, stability, and long-term service quality. The following sections explain the main aspects that help identify a dependable provider.

### High-Performance Infrastructure

High-performance infrastructure is one of the most critical factors in cloud hosting. Providers should offer modern CPUs, SSD storage, and robust network capacity, as these components work together to ensure stable performance across different workloads. When the underlying design is efficient, applications respond consistently and handle varying levels of demand without interruption. SSD storage contributes to this stability by reducing delays during data access.

### Scalability Options

Scalability is essential for long‑term growth. As businesses expand, hosting plans must support both vertical and horizontal scaling without service disruption. Flexible scaling helps organizations adjust resources smoothly during busy periods and maintain steady operations as their needs evolve. Storage capacity and performance should scale in the same predictable manner to avoid bottlenecks as data volumes increase.

### Managed Backups and Disaster Recovery

A dependable cloud hosting provider should offer managed backups and a clear [disaster recovery plan](https://www.atlantic.net/disaster-recovery/disaster-recovery-plan/). Automated backups, frequent snapshots, and verified restore procedures show how well a provider can protect data during unexpected events. Providers that test these processes regularly offer stronger assurance that information can be restored quickly, helping businesses continue operations with minimal delay.

### Security, Monitoring, and Support

A reliable cloud hosting provider should offer strong security and continuous monitoring. Logging, audit trails, and proactive threat detection help maintain a safe environment and reduce the chance of unnoticed issues. Clear [SLAs](https://www.atlantic.net/cloud-service-level-agreement/) and transparent pricing give customers a realistic understanding of the service they will receive. In addition, access to real engineers through a dependable support model strengthens overall reliability by ensuring that technical problems are handled promptly and accurately.

## Top Cloud Hosting Providers with SSD Storage and 24/7 Support in 2026

Below are six providers that offer reliable cloud hosting with SSD storage and round-the-clock support. Each one has different strengths. Therefore, businesses can choose the provider that fits their needs.

### 1. Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

[Atlantic.Net](http://www.atlantic.net) provides cloud hosting designed for stable performance, simple management, and dependable support. Its cloud servers use enterprise-grade SSD storage to support fast response times for different workloads. The platform also includes redundant power, cooling, and network systems to reduce downtime. The support team is available 24/7 to assist with configuration and troubleshooting. Atlantic.Net offers flexible VPS and [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting) plans suitable for small projects and large production environments. The overall focus is on reliability, security, and predictable long-term performance.

#### *Key Characteristics *

- The storage platform offered by Atlantic.Net uses enterprise-grade SSD drives, which help applications load quickly and maintain stable performance during heavy activity. This also supports faster data access for databases and API-driven workloads.
- Customers have continuous access to experienced Atlantic.Net engineers who can respond to issues at any time. This reduces delays and supports smooth operations for production environments.
- Atlantic.Net uses redundant power, cooling, and network systems to reduce the risk of outages and support consistent uptime. This setup also helps maintain service stability during maintenance activities.
- The available Atlantic.Net plans support different performance requirements, and resources such as CPU, RAM, and storage can be scaled as applications grow. This flexibility helps prevent service interruptions and promotes long-term expansion.

### 2. Amazon Web Services (AWS)

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

[AWS](https://aws.amazon.com/) is a large cloud platform that offers SSD-backed compute instances and a wide range of hosting services. It supports businesses of all sizes and provides strong global coverage through multiple regions. Its infrastructure is designed to maintain stable performance for different workloads. AWS also includes tools for monitoring, automation, and resource management. Its support plans help teams maintain uptime and handle technical issues. This makes AWS a common choice for organizations that need flexible and scalable cloud hosting.

#### *Key Characteristics *

- SSD-based EBS volumes and instance storage support fast data access, helping applications handle frequent read/write operations. This also contributes to stable performance for databases and high-traffic websites.
- AWS operates data centers across many global regions, which helps reduce latency and improve reliability. Multi-region redundancy is also available for critical workloads.
- IAM, CloudWatch, GuardDuty, and other AWS tools help monitor activity, detect threats, and manage access. These features also support compliance and operational visibility.
- AWS offers Developer, Business, and Enterprise support plans. These tiers provide access to engineers and faster response times, helping teams resolve issues quickly.

### 3. Microsoft Azure

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

[Microsoft Azure](about:blank) offers cloud hosting with premium SSD storage and strong integration with enterprise systems. It supports virtual machines, databases, and application services across many global regions. Azure is designed to provide stable performance for organizations that need reliable cloud infrastructure. It also includes tools for monitoring, identity management, and resource optimization. Azure’s hybrid capabilities help businesses combine on-premises systems with cloud environments. Its support services operate around the clock to help teams maintain uptime.

#### *Key Characteristics *

- Premium SSD and Ultra Disk storage deliver high IOPS and low latency, supporting demanding workloads such as databases and analytics. Azure also maintains consistent performance during peak usage.
- Azure integrates with Windows Server, Active Directory, and Microsoft 365, helping businesses manage cloud and on-premises systems together. Hybrid identity and centralized management are also supported.
- Defender for Cloud, Sentinel, and built-in logging help detect threats and monitor system activity. These Azure tools also support compliance and operational insight.
- Azure provides multiple support tiers that include technical assistance, troubleshooting, and guidance. This helps organizations maintain stable operations at all times.

### 4. Google Cloud Platform (GCP)

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

[Google Cloud Platform](https://cloud.google.com/) offers SSD-backed virtual machines and a private global network for fast, stable performance. It supports different workloads, including Web applications, analytics, and machine learning systems. Google Cloud uses strong security controls and continuous monitoring to protect hosted services. Its infrastructure is built to maintain low latency and consistent throughput. The platform also provides tools for automation, scaling, and resource management. Its support tiers help businesses receive timely assistance.

#### *Key Characteristics *

- Persistent Disk, SSD, and Local SSD options provide high throughput and low latency for demanding workloads. These Google Cloud storage types also support fast boot times and stable performance.
- Google operates its own private fiber network across continents, improving speed and reducing congestion. This network also supports consistent performance for global applications.
- Identity and Access Management, Cloud Armor, and Security Command Center help detect threats and manage access. These tools also support strong protection for hosted applications.
- Google Cloud offers Basic, Standard, Enhanced, and Premium support tiers. These plans provide different response times and access to engineers, helping businesses maintain reliable operations.

### 5. Rackspace Technology

![](https://www.atlantic.net/wp-content/uploads/2025/12/rackspace_logo.png)

[Rackspace Technology](https://www.rackspace.com/) provides managed cloud hosting with SSD-backed infrastructure and strong operational support. It helps businesses run applications across AWS, Azure, Google Cloud, and private cloud environments. Rackspace focuses on simplifying cloud operations by offering monitoring, maintenance, and security services. Its managed approach helps teams reduce technical overhead and maintain stable performance. Rackspace also provides guidance for scaling and optimization. This makes it suitable for organizations that want expert assistance with complex cloud environments.

#### *Key Characteristics *

- SSD storage is used across Rackspace’s managed cloud environments, supporting fast data access and stable performance. This also helps reduce latency for high-traffic applications.
- Rackspace supports AWS, Azure, Google Cloud, and private cloud setups, helping businesses manage mixed environments with consistent performance. Migration and optimization assistance is also available.
- Managed detection and response, logging, and compliance support help protect applications and maintain visibility. These Rackspace services also reduce the burden on internal teams.
- Rackspace engineers monitor systems around the clock, handling incidents, maintenance, and troubleshooting. This helps reduce downtime and maintain service reliability.

### 6. Kamatera

![](https://www.atlantic.net/wp-content/uploads/2025/12/kamatera-logo-1.png)

[Kamatera](https://www.kamatera.com/) offers customizable [cloud VPS hosting](https://www.atlantic.net/vps-hosting/) with SSD-backed storage and flexible resource options. It supports businesses that need precise control over CPU, RAM, and storage configurations. Kamatera operates data centers in several regions to help reduce latency and improve performance. Its cloud servers are designed for fast deployment and easy scaling. The platform also includes security features and network controls to support stable operations. Kamatera’s support team is available 24/7 to assist with technical issues.

#### *Key Characteristics *

- Users can configure CPU cores, RAM, storage type, and network bandwidth to match specific workload needs. This flexibility also supports cost control and efficient scaling.
- Kamatera operates data centers in North America, Europe, Asia, and the Middle East, helping reduce latency for international users. Regional redundancy is also supported.
- [Firewalls](https://www.atlantic.net/managed-services/firewall/), private networks, and monitoring tools help maintain a stable, secure environment. These Kamatera features also support secure communication between servers.
- Continuous assistance is available through phone, chat, and tickets. Kamatera’s support team helps resolve issues quickly and maintain reliable operations.

## The Real‑World Differences in Cloud Reliability and Storage

Modern cloud hosting solutions may appear similar, but the fundamental differences emerge when teams depend on a platform for consistent uptime and predictable storage performance. Each provider handles reliability, data access, and operational consistency in its own way, and these choices define and these choices influence the overall experience for users. When viewed together, these practical differences reveal far more than any feature list.

Atlantic.Net offers a stable and dependable environment that many teams trust for consistent storage behavior. Its platform is simple to manage, and support is always within reach, helping organizations keep their data accessible without adding extra layers of complexity. This transparent and predictable approach allows businesses to focus on their applications rather than tuning storage or troubleshooting unexpected performance issues.

AWS provides a wide range of storage and reliability options, giving teams flexibility to design highly resilient systems. At the same time, this flexibility requires more responsibility. Managing storage tiers, cost behavior, and multi‑region reliability requires experience and careful planning. When teams have that background, they can use AWS to build resilient systems with flexible data handling. Without it, the platform can feel demanding, especially when storage decisions influence performance or cost.

Azure is suitable for environments that already rely on Microsoft tools and hybrid setups. Its storage services integrate smoothly with on‑premises systems, which is helpful for enterprises modernizing older environments. For teams outside the Microsoft ecosystem, however, Azure’s reliability and storage features can feel heavier, as they often expect a certain level of alignment with Microsoft’s broader platform.

Google Cloud has an emphasis on performance and clean tooling, and this extends to its storage layer. Its private global network and fast infrastructure support analytics and machine learning workloads that depend on quick, consistent access to data. The trade‑off is a smaller service catalog, but for teams that value speed and predictable storage performance, Google Cloud offers a smooth and efficient experience.

Rackspace adopts a managed approach to reliability and storage. Instead of expecting teams to handle everything themselves, it provides guidance across multiple clouds. This reduces operational pressure, particularly for organizations seeking help with managing backups, redundancy, and data availability. The trade‑off is relying more on a third party for daily reliability and storage decisions.

Kamatera provides users with detailed control over CPU, RAM, and storage configurations. This level of flexibility is helpful for technical teams that want to fine‑tune performance or adjust storage behavior closely. At the same time, it requires more hands‑on involvement, which may not suit every business. It also shows that some platforms offer more choice, but that choice brings more responsibility for keeping systems reliable.

Across these providers, one point becomes clear: cloud hosting is not a uniform experience. Each platform offers its own balance of reliability, storage performance, and operational simplicity. When these differences are viewed together, it becomes easier to see how each provider supports everyday workloads and why the experience varies so much from one platform to another.

**Table 1: Real-World Differences in Cloud Reliability and Storage**

| **Provider** | **Reliability Strength** | **Storage Behavior** | **Best Fit For** | **Main Trade-Off** |
| --- | --- | --- | --- | --- |
| **Atlantic.Net** | Steady, predictable uptime | Simple, consistent storage performance | Teams wanting clarity and stable operations | Smaller catalog in exchange for stability |
| **AWS** | Highly resilient when configured well | Many storage tiers with cost-performance choices | Teams with strong cloud experience | Flexibility requires more oversight |
| **Azure** | Strong for hybrid and enterprise setups | Smooth integration with Microsoft environments | Organizations modernizing older systems | Feels heavier outside Microsoft ecosystems |
| **Google Cloud** | Fast, consistent performance | Optimized for analytics and ML workloads | Teams valuing speed and clean tooling | Narrower service catalog |
| **Rackspace** | Managed reliability across clouds | Guided storage setup and maintenance | Teams wanting operational support | Greater reliance on a third party |
| **Kamatera** | Reliable when tuned properly | Highly configurable storage options | Technical teams wanting fine control | More hands-on management |

**Final Thoughts**

A dependable cloud environment relies on more than raw infrastructure. It depends on reliable data access, predictable storage behavior, and the confidence teams feel when they can plan their daily work without surprises. The differences seen across providers show that reliability is not a single idea but the result of multiple design and operational choices that influence the experience in real use. These choices matter even more when long‑term data management and day‑to‑day stability are priorities.

By looking at these variations with a practical and thoughtful view, it becomes easier to identify the environment that best supports specific operational needs. In conclusion, the right cloud partner is the one that keeps data accessible, maintains stable performance, and helps teams focus on their work without unnecessary interruptions.


---

# Best PCI Compliant Hosting 2026: Reviews & DSS 4.0 Guide

> URL: https://www.atlantic.net/pci-compliant-hosting/pci-hosting-reviews-choosing-a-host-for-secure-online-business/ | Published: 2026-01-30 | Updated: 2026-06-23 | Author: Richard Bailey

Credit and debit card payments accounted for approximately [62% of all financial transactions](https://www.frbservices.org/news/research/2024-findings-from-the-diary-of-consumer-payment-choice) in the United States in 2023, and there is evidence of a clear and continuing trend away from cash and towards card payments.

Whatever your views are on this change, it’s clear that credit card usage, in particular, has seen significant growth, nearly doubling its share since 2016. Securely handling credit or debit card transactions is now more critical than ever for your business.

Guaranteed security is essential when handling card payments, making Payment Card Industry Data Security Standard (PCI DSS) compliance vital. For 2026, [PCI DSS 4.0](https://www.atlantic.net/pci-compliant-hosting/pci-dss-4-0-is-mandatory-a-hosting-checklist-for-2026/) is the only standard that matters. The “best” host depends on whether you need a team to manage that compliance for you or if you have the internal engineering to handle it.

## Which PCI Compliant Host is Right for You?

- **Atlantic.Net:** Best for Managed Compliance. Includes an “Audit-Ready” environment, BAA signing, and built-in [intrusion detection](https://www.atlantic.net/dedicated-server-hosting/what-is-an-intrusion-detection-system-and-why-do-i-need-it/) for healthcare/fintech.
- **Rackspace:** Best for Enterprise Multi-Cloud. High-cost, high-touch support for complex infrastructure that requires 100% uptime.
- **AccuWeb Hosting:** Best for Budget [Dedicated Servers](https://www.atlantic.net/dedicated-server-hosting/). Good hardware specs and global locations for businesses needing isolation without the enterprise price tag.
- **AWS (Amazon Web Services):** Best for DIY Scalability. Infinite scale for developers who can configure their own [firewalls](https://www.atlantic.net/vps-hosting/waf-web-application-firewall/), encryption, and compliance controls.

## Managed vs. Unmanaged PCI Hosting

| **Provider** | **Best for** | **PCI Approach** | **Audit-Proof Evidence You Can Access** |
| --- | --- | --- | --- |
| **Atlantic.Net** | Managed PCI-ready environments | Shared responsibility + managed security options | PCI-focused hosting program + audited controls; SLA terms |
| **AWS** | Custom payment apps at scale | Shared responsibility | PCI DSS Level 1 Service Provider; AOC + responsibility summary via AWS Artifact |
| **Microsoft Azure** | Microsoft-centric stacks | Shared responsibility | Service Provider Level 1 validation; AOC available to customers |
| **Google Cloud** | GKE / Google-native architectures | Shared responsibility | PCI DSS 4.0.1 compliant services list + shared responsibility matrix |
| **Shopify** | Reduce PCI scope with hosted checkout | Platform-managed checkout | Level 1 PCI DSS compliance extends to stores by default |
| **Rackspace** | PCI-certified provider + managed environments | Provider-certified facilities + managed options | PCI DSS Level 1 provider status for facilities in multiple regions (per Rackspace) |
| **SiteGround** | Stores using off-site PCI payment processors | “Scope reduction” approach (don’t host card data) | SiteGround guidance says PCI compliance is typically handled by the payment processor, not your whole website hosting. |

## Reviews: Who Should Choose Which Provider?

Before you pick a “PCI compliant host,” separate two things:

1. **Provider compliance:** whether the vendor can produce PCI evidence (like an AOC) for the infrastructure/services they operate.
2. **Your compliance:** whether your environment, configs, apps, and processes meet PCI DSS (most vendors run a shared-responsibility model).

## Top PCI Compliant Hosting Providers Reviewed

The providers below are strong options in 2026, but they fit different payment architectures—from managed PCI-ready hosting to hyperscaler cloud to hosted checkout that reduces your PCI scope.

## Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

#### **Best for PCI-ready hosting with a managed path**

Atlantic.Net positions a dedicated “[PCI-compliant hosting](https://www.atlantic.net/pci-compliant-hosting/)” offering aimed at businesses running regulated workloads. If you want a host that leads with compliance use cases (instead of “general web hosting”), Atlantic.Net is one of the clearer “PCI-ready environment” options.

Below is Atlantic.Net’s cloud control panel interface used to deploy and manage dedicated and [GPU servers](https://www.atlantic.net/gpu-server-hosting/gpu-servers-for-deep-learning-a-practical-guide/).
 ![Atlantic.Net Server Panel](https://www.atlantic.net/wp-content/uploads/2026/01/Atlantic.net-server-panel.png)
 Image Source: Atlantic.Net

- **Key Specs:** [100% uptime SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/) for critical infrastructure components (excluding scheduled maintenance).
- **Compliance:** PCI-focused hosting offering; Atlantic.Net states its compliance hosting solutions are certified/audited by independent auditors and references SOC reports.
- **Verdict:** Choose Atlantic.Net if you want a PCI-forward provider and prefer a more guided, compliance-oriented hosting posture versus building everything from raw cloud services.

**What stands out:**

- **Program Focus:** Provider-led PCI hosting program (not just “PCI is your job”).
- **Reliability:** Uptime SLA published for core infrastructure components.
- **Audit Support:** Compliance positioning includes audited controls and SOC reporting references.

**Who should choose Atlantic.Net?**

Teams that want a PCI-ready hosting baseline and don’t want to assemble every control from scratch.

## AWS

#### ![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

#### **Best for building custom PCI workloads at scale**

AWS states it is certified as a PCI DSS Level 1 Service Provider and makes the PCI DSS Attestation of Compliance (AOC) and Responsibility Summary available to customers through AWS Artifact. This is a good fit if you’re building a custom payment stack and need strong audit evidence access.
 Here is the AWS EC2 dashboard, where you can control instances, monitor status, and configure settings.

![AWS Instance](https://www.atlantic.net/wp-content/uploads/2026/01/AWS-Instance.png)

Image Source: AWS

- **Key Specs:** PCI DSS Level 1 Service Provider; AOC and Responsibility Summary available via AWS Artifact.
- **Compliance:** PCI documentation and evidence distribution through AWS Artifact.
- **Verdict:** Choose AWS when you need flexibility for architecture (tokenization, microservices, multi-region), and you can run disciplined security operations under shared responsibility.

**What stands out:**

- **Access:** Clear “get the AOC” path via AWS Artifact.
- **Certification:** Explicit Level 1 Service Provider statement.
- **Clarity:** Strong documentation for audit expectations and responsibilities.

**Who should choose AWS?**

Engineering-led teams building custom payment systems with mature security operations.

## **Microsoft Azure**

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

#### **Best for Microsoft-first PCI environments**

Azure maintains a PCI DSS validation at Service Provider Level 1 and publishes [PCI compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-in-the-age-of-ai/) guidance through Microsoft documentation. If your identity, monitoring, and governance are already centered on Microsoft, Azure keeps payment workloads aligned with the rest of your platform.

Explore the Azure dashboard to organize resource groups, track usage, and manage cloud services from a centralized platform.

![Microsoft Azure](https://www.atlantic.net/wp-content/uploads/2026/01/Microsoft-Azure.png)

Image Source: Azure

- **Key Specs:** Azure maintains PCI DSS validation at Service Provider Level 1.
- **Compliance:** Microsoft publishes PCI DSS compliance guidance and scope information across services.
- **Verdict:** Choose Azure if you’re already standardized on Microsoft and want PCI workloads in the same governance and identity ecosystem.

**What stands out:**

- **Validation:** Service Provider Level 1 validation statement in Microsoft documentation.
- **Resources:** Clear compliance offering pages for PCI DSS.
- **Integration:** Practical alignment for Microsoft-centric orgs (identity + ops).

**Who should choose Microsoft Azure?**

Teams running a Microsoft-heavy stack who want PCI workloads under the same controls and governance.

## **Google Cloud**

![](https://www.atlantic.net/wp-content/uploads/2025/06/google-logo.png)

#### **Best for GKE and clear PCI scope boundaries**

Google Cloud publishes a PCI DSS compliance page listing services reviewed by an independent QSA and determined to be PCI DSS 4.0.1 compliant, plus a shared responsibility matrix. If you’re running PCI systems on GKE or Google-native services, this documentation helps clarify what’s “in scope” and who owns which controls.

Manage cloud services with the Google Cloud dashboard, where you can create virtual machines, deploy applications, and analyze data using built-in tools.

![Google Cloud Dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Google-Cloud-Dashboard.png)

Image Source: Google Cloud

- **Key Specs:** QSA-reviewed services determined PCI DSS 4.0.1 compliant (as listed by Google Cloud).
- **Compliance:** Shared responsibility matrix (PCI DSS v4 responsibility matrix PDF dated Dec 2025) and PCI reports via Compliance Reports Manager.
- **Verdict:** Choose Google Cloud if you want explicit PCI documentation (services in scope + responsibility matrix) and you’re comfortable with engineering segmentation, logging, and change control.

**What stands out:**

- **Service List:** Published list of PCI DSS 4.0.1 compliant services.
- **Matrix:** Shared responsibility matrix that’s audit-friendly.
- **Process:** Clear direction on how to request compliance reports.

**Who should choose Google Cloud?**

Teams building PCI workloads on GKE or Google-native services that want clear scoping documentation.

## **Shopify**

![](https://www.atlantic.net/wp-content/uploads/2026/01/shopify-logo-png_seeklogo-267188.png)

#### **Best for reducing PCI scope with hosted checkout**

Shopify states it is certified Level 1 PCI DSS compliant and that this compliance extends by default to all stores powered by Shopify. For many merchants, this is the simplest way to keep most card-data handling out of your own servers and reduce PCI overhead.

Explore the Shopify dashboard to build applications, manage deployments, and efficiently oversee store-related resources.

![shopify dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/shopify-dashboard.jpg)

Image Source: Shopify

- **Key Specs:** Certified Level 1 PCI DSS compliant; extends by default to all Shopify stores.
- **Compliance:** Shopify’s PCI statement is published on its security/compliance page.
- **Support:** Support varies by plan.
- **Verdict:** Choose Shopify if your priority is lowering PCI scope by using a hosted e-commerce platform and keeping card entry/checkout within the platform.

**What stands out:**

- **Coverage:** Direct Level 1 PCI DSS statement with “extends by default” language.
- **Architecture:** Strong fit for merchants who don’t want to build a cardholder data environment.
- **Speed:** Faster route to accepting payments compared with custom PCI builds.

**Who should choose Shopify?**

Merchants who want to minimize PCI scope and avoid self-hosting payment flows.

## **Rackspace**

![](https://www.atlantic.net/wp-content/uploads/2025/12/rackspace_logo.png)

#### **Best for PCI Level 1 provider status with managed options**

Rackspace states it has achieved PCI DSS Level 1 provider status for facilities in the U.S., U.K., Hong Kong, and Australia, and it positions PCI-capable solutions across public cloud, private cloud, dedicated, and hybrid environments. This is useful if you want a managed provider that publishes PCI certification positioning and can support multiple infrastructure models.

Control your environment through the Rackspace dashboard, designed for deploying applications, managing databases, and handling cloud resources.

![Rackspace](https://www.atlantic.net/wp-content/uploads/2026/01/Rackspace.jpg)

Image Source: Rackspace

- **Key Specs:** PCI DSS Level 1 provider status for specified facilities/regions (per Rackspace).
- **Compliance:** Rackspace publishes PCI compliance positioning and related service resources.
- **Support:** Offers “PCI DSS Core Services” positioning that includes QSA-led scoping and de-scoping options (as a paid service).
- **Verdict:** Choose Rackspace if you want a provider that publicly states Level 1 provider status and you want managed options across multiple environment types.

**What stands out:**

- **Global Reach:** Published Level 1 provider status statement with regional facility coverage.
- **Flexibility:** Multi-environment positioning (public/private/dedicated/hybrid).
- **Services:** Optional PCI services framed around scoping and de-scoping support.

**Who should choose Rackspace?**

Teams that want managed infrastructure choices plus PCI-focused consulting/services.

## **SiteGround**

![](https://www.atlantic.net/wp-content/uploads/2026/01/siteground-logo.png)

#### **Best for stores using off-site payment processing **

SiteGround does not market “PCI-certified hosting” as the default requirement for most small businesses. Its published guidance emphasizes that if you use a PCI-compliant payment processor, you typically don’t need to host your own “PCI-compliant server,” because the processor handles sensitive payment data.

Here is the SiteGround dashboard to manage caching, optimize assets, and enhance overall loading times.

![SiteGround](https://www.atlantic.net/wp-content/uploads/2026/01/SiteGround.jpeg)

Image Source: SiteGround

- **Key Specs:** N/A (Focus is on off-site processing).
- **Compliance:** SiteGround guidance frames PCI compliance as tied to the payment processor when sensitive data is handled off-site.
- **Verdict:** Include SiteGround in a 2026 PCI list only when your design keeps card data out of your server scope (hosted payment pages, redirects, or embedded checkout handled by a compliant processor).

**What stands out:**

- **Guidance:** Clear messaging that a PCI-compliant processor can keep you from needing “PCI-compliant servers.”
- **Simplicity:** Practical fit for small merchants, minimizing PCI scope.
- **Strategy:** Forces an architecture-first decision (where does card data flow?).

**Who should choose SiteGround?**

Merchants who will not store/process/transmit card data on the server and will rely on a compliant payment provider.

## The 2026 Standard: PCI DSS 4.0 is Non-Negotiable

As of March 31, 2025, PCI DSS v3.2.1 is retired. All assessments in 2026 must meet PCI DSS v4.0 standards. This update fundamentally changes hosting requirements. If your host isn’t proactive, you will fail your audit.

- **MFA Everywhere:** [Multi-Factor Authentication](https://www.atlantic.net/managed-services/multi-factor-authentication/) is now mandatory for *all* access to the Cardholder Data Environment (CDE), not just remote access. Your host must support MFA for your administrative portal.
- **Authenticated Scanning:** Internal vulnerability scans must now be authenticated. Your host must facilitate these deeper scans, not just surface-level pings.
- **Client-Side Protection:** For e-commerce, you must monitor and manage all JavaScript on payment pages to prevent skimming (Section 6.4.3). While this is largely your responsibility, a host offering a WAF (Web Application Firewall) makes this significantly easier.
- **Continuous Compliance:** 4.0 shifts focus from “annual checks” to “continuous security.” You need a host that provides logs and monitoring data in real-time, not just once a year.

## Checklist: What Are the New 2026 Mandates?

Use this when you shortlist vendors:

**Audit evidence you can actually obtain**

- Can you access the provider’s Attestation of Compliance (AOC)?
- Can they tell you which services are in scope for PCI?

**Clear shared responsibility boundaries**

- Do they publish a shared responsibility matrix or equivalent?
- Can they explain what you must configure (IAM, OS, logging, encryption, scanning)?

**Scope reduction support**

- Do they support architectures that keep card data out of your systems (hosted checkout, tokenization, segmented CDE)?
- Can you isolate payment systems from the rest of your environment?

**Security controls you will run every day**

- WAF and network controls
- Central logging and alerting
- Key management and encryption patterns
- Vulnerability management, patching, and remediation workflows

**Support that understands PCI**

- Can support explain scan findings and common remediation steps?
- Do they offer architecture guidance for PCI segmentation and evidence collection?

## FAQ: PCI Hosting in 2026

**Can I use shared hosting for PCI compliance?**

Technically, yes, but it is highly discouraged and often impossible to validate. In a shared environment, a “noisy neighbor” could introduce vulnerabilities that compromise your data. Most auditors (QSAs) will require a VPS or [Dedicated Server](https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/) to ensure data isolation. (Note: SiteGround’s GoGeek plan is a rare exception that isolates resources sufficiently for smaller merchants).

**Who is responsible for a data breach?**

You are. Even if you use a “PCI Compliant Host,” the merchant of record retains ultimate liability. A compliant host covers the infrastructure (power, network, physical security), but you are responsible for secure passwords, application code, and employee training.

**Does a “PCI Compliant” badge mean I am compliant?**

No. It means the host has passed their audit for the hardware/network. You must still complete your own Self-Assessment Questionnaire (SAQ) covering your software and business processes.

**Why is PCI DSS 4.0 harder for hosting?**

It removes ambiguity. “Best practices” like authenticated scanning and strict MFA are now hard requirements. Legacy hosts that haven’t updated their access controls will force you to implement costly workarounds.

**Related Guides:**

- [HIPAA Compliant Hosting Solutions](https://www.atlantic.net/hipaa-compliant-hosting/)
- [PCI-Compliant Hosting Solutions](https://www.atlantic.net/pci-compliant-hosting/)
- [What Are Managed Services?](https://www.atlantic.net/managed-services/what-are-managed-services/)

**Related Products:**

- [Atlantic.Net Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/)
- [Atlantic.Net HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)
- [Atlantic.Net GPU Hosting](https://www.atlantic.net/gpu-server-hosting/)


---

# Top LLM Development Tools and Platforms for 2026

> URL: https://www.atlantic.net/gpu-server-hosting/top-llm-development-tools-and-platforms/ | Published: 2026-02-05 | Updated: 2026-05-26 | Author: Richard Bailey

Building Large Language Model (LLM) applications involves much more than just prompt engineering. In 2026, production-ready LLM systems use Retrieval-Augmented Generation (RAG), agentic workflows, and new standards such as the Model Context Protocol (MCP). MCP sets rules for how models safely access tools, memory, and outside data. Modern LLM applications work like distributed systems.

They bring together several agents, handle ongoing reasoning tasks, pull context from vector databases, and use external tools reliably. Teams now look for platforms that offer strong orchestration, monitoring, testing, and control—not just good model quality. The following platforms are some of the most popular tools for building, testing, and scaling agentic LLM workflows. They help with RAG pipelines, tool use, multi-agent coordination, and production monitoring, making them a good fit for real-world, high-stakes AI projects. more

## A Look at LLM Development Tools

LLM development tools are used to build, train, and deploy large language models. The technology is built upon the transformer architecture, which enables powerful natural language understanding in modern AI. While early transformers used an encoder-decoder system, modern generative models like GPT and DeepSeek primarily use a decoder-only architecture to predict and generate text based on input.

In 2026, LLM applications are no longer limited to single-pass generation. Most production systems are designed around RAG, agentic workflows, and standardized ways for models to access tools and context.

Several types of development tools exist, including:

- **Frameworks:** Code toolkits that connect and manage all the components of an LLM application. A popular Python library like LangChain or LlamaIndex provides a structure for creating LLM-based applications. In modern use cases, these frameworks also support agent orchestration, tool calling, and multi-step reasoning loops, allowing developers to move beyond linear prompt chains. They simplify connecting to different model providers and assets from hubs like the Hugging Face Model Hub.
- **Vector Databases:** A library for storing and retrieving information based on semantic meaning, not just keywords. For applications that use RAG, a vector database is required. Beyond basic retrieval, many teams now evaluate vector search quality as part of their workflow to ensure relevance and grounding before passing context to an LLM. These databases allow for fast similarity search and support hybrid search, combining vector capabilities with traditional keyword search on structured data.
- **MLOps Platforms:** An end-to-end production line for managing the entire lifecycle of a machine learning model. These platforms support everything from initial data loading to deploying models into production, while also enabling monitoring, tracing, and evaluation of agentic and RAG-based systems. They assist with tuning model parameters, tracking performance, and integrating with cloud services, making them key for operating LLM systems at scale.
- **Development Partners:** An expert team you hire to build your application when you lack the internal resources. For organizations without in-house expertise, development companies provide the skills needed to design agent-driven architectures, implement RAG pipelines, and deploy reliable production systems. They typically manage the entire process, from ideation and architecture design to final deployment.

These components work together to enable the creation of sophisticated applications that perform natural language processing tasks, from simple question answering systems to agent-based systems that retrieve external context, call functions, and coordinate actions across multiple tools.

## Top 7 LLM Development Tools and Platforms

Now that we’ve covered the core components of a Generative AI application, let’s look at the top-tier tools and platforms that developers are using to build them. Selecting the right components for your development stack is a major decision, as each platform offers a unique set of capabilities for different project needs and scales.

### #1: Hugging Face

![](https://www.atlantic.net/wp-content/uploads/2025/08/Hf-logo-with-title.png)

Hugging Face is the definitive hub for the open-source AI community. More than just a repository, it is a complete platform providing tens of thousands of pre-trained deep learning models, including many specialized for tasks like language translation. It supports diverse data types and data formats, making it the essential starting point for nearly any team working with language models.

Use Hugging Face Spaces to experiment with AI, deploy demos, and showcase real-world applications powered by open models.
 ![Hugging Face](https://www.atlantic.net/wp-content/uploads/2026/02/Hugging-Face.png)
 Image Source: Hugging Face

**Advantages:**

- Direct access to a massive library of open-source models, perfect for running machine learning experiments.
- Standard libraries that simplify model interaction and training.
- Strong community support and extensive documentation for countless use cases.
- Tools for the entire workflow, including inference endpoints and model evaluation.

**Disadvantages:**

- The sheer number of choices can be overwhelming for beginners.
- While core use is free, enterprise-grade features like private hubs and dedicated inference come with hosting costs.
- Relies on community contributions, which can mean variable quality in models and documentation.

#### Best For:

Any development team that wants to use the power of open-source AI. It is essential for experimentation, building with a wide variety of models, and following community-driven best practices.

### #2: LangChain

![](https://www.atlantic.net/wp-content/uploads/2025/08/langchain-1.png)

LangChain is the premier open-source framework for orchestrating the components of an LLM application. It acts as the “glue,” providing a modular structure to connect language models with external data sources, APIs, and other integration tools. It enables developers to easily build complex machine learning workflows, and its ability to parse and manage language model outputs makes it invaluable for creating reliable agents.

Explore LangSmith by LangChain, where you can trace, debug, and evaluate your LLM applications with full visibility.
 ![LangChain](https://www.atlantic.net/wp-content/uploads/2026/02/LangChain.png)
 Image Source: LangChain

#### Advantages:

- Simplifies the creation of complex application logic.
- Enormous ecosystem of third-party integrations, supporting virtually every popular model, database, and API.
- Actively maintained with a strong community and rapid feature development.
- Declarative structure makes it easier to manage and modify complex chains.

#### Disadvantages:

- The framework’s rapid evolution can lead to breaking changes and occasionally outdated documentation.
- Adds a layer of abstraction that can sometimes make debugging underlying issues more difficult.

#### Best For:

Developers building any application that requires more than a single call to an LLM. It is the go-to tool for creating applications that are context-aware, data-driven, and interactive.

### #3: Pinecone

![](https://www.atlantic.net/wp-content/uploads/2025/08/Pinecone_Systems_Inc_Logo.jpg)

Pinecone is a leading managed vector database, a core component for any application using RAG. It allows applications to perform incredibly fast vector similarity search. This technology, pioneered by open-source libraries like Facebook AI Similarity Search (FAISS), is now available in a highly scalable managed service through Pinecone, enabling an LLM to pull in relevant information before generating a response.

Use Pinecone to power AI applications with scalable vector search while monitoring performance and optimizing data retrieval.
 ![pinecone-dashboard](https://www.atlantic.net/wp-content/uploads/2026/02/pinecone-dashboard.png)
 Image Source: Pinecone

#### Advantages:

- Fully managed service eliminates the need to handle complex database infrastructure.
- Engineered for high performance and low latency, making it suitable for real-time applications.
- Simple API makes it easy to integrate into any application stack.
- Serverless architecture scales automatically with usage, handling billions of vectors.

#### Disadvantages:

- As a proprietary service, it can lead to vendor lock-in compared to open-source alternatives.
- Costs can escalate quickly for very large datasets or applications with high query volume.
- Offers less configuration control than a self-hosted vector database.

#### Best For:

Businesses building production-grade RAG applications, which are a cornerstone of modern deep learning systems, that require high performance and reliability without managing database infrastructure.

### #4: Databricks

![](https://www.atlantic.net/wp-content/uploads/2025/08/Databricks_Logo.png)

Databricks provides a unified Data and AI platform designed to handle the entire machine learning lifecycle at an enterprise scale. It allows teams to manage everything from data preparation (handling many data types) and governance to model training, fine-tuning, and the ability to deploy models into production. This unified approach is a core principle of modern machine learning operations (MLOps).

Explore the Databricks compute dashboard, where you can manage database instances, clusters, and workloads in one place.
 ![Databricks](https://www.atlantic.net/wp-content/uploads/2026/02/Databricks.png)
 Image Source: Databricks

#### Advantages:

- A single, integrated platform for all data and AI workloads, reducing tool complexity.
- Excellent for ensuring data governance, security, and lineage, which is critical for enterprises.
- Provides scalable compute for demanding tasks like training foundation models from scratch.
- Strong integration between data processing and machine learning tools like MLflow, which provides reliable capabilities for model monitoring.

#### Disadvantages:

- The platform is powerful but complex, with a significant learning curve.
- Can be very expensive, making it less accessible for smaller companies or projects.
- May be overkill for teams whose needs don’t involve massive-scale data engineering.

#### Best For:

Large enterprises with established data teams that need a reliable, secure, and governable platform to manage the end-to-end LLM lifecycle at scale.

### #5: OpenAI Platform

![](https://www.atlantic.net/wp-content/uploads/2025/06/openai-logo.png)

The OpenAI Platform provides API access to some of the world’s most advanced and widely recognized language models, including the GPT series. Beyond just offering models, it is a complete development platform that allows developers to easily integrate state-of-the-art Generative AI capabilities into their applications. Tools like the Assistants API and fine-tuning capabilities enable the creation of highly sophisticated and specialized solutions.

Get started with OpenAI, search with ChatGPT, explore research tools, and build smarter solutions using AI.
 ![OpenAI](https://www.atlantic.net/wp-content/uploads/2026/02/OpenAI.png)
 Image Source: OpenAI

#### Advantages:

- Direct access to modern, state-of-the-art proprietary models.
- Extremely easy to get started with, thanks to a clean and well-documented API.
- Consistently high performance on a wide range of general-purpose reasoning and generation tasks.
- Continuously updated with new features and models.

#### Disadvantages:

- The models are “black boxes,” which can make their behavior difficult to explain or debug.
- Reliance on a single, proprietary provider creates vendor lock-in and dependency.
- Data privacy and usage policies may be a concern for organizations with sensitive information.

#### Best For:

Teams that need the strong general performance with the fastest time-to-market. It is excellent for prototyping and for building applications where access to the most powerful models is a competitive advantage.

### #6: LangGraph

![langgraph](https://www.atlantic.net/wp-content/uploads/2026/02/langgraph.png)

LangGraph is an agentic framework designed specifically for stateful, multi-step LLM workflows. Built by the LangChain team, it enables developers to define agent behavior as directed graphs, making it easier to implement loops, branching logic, retries, and human-in-the-loop checkpoints.

LangGraph differs from linear chains because it supports agents that can run for a long time, make decisions, take actions, observe results, and adjust their behavior next time. This makes it a good fit for complex applications such as research agents, planning tools, and systems where multiple agents work together.

#### Advantages:

- Has built-in support for agent loops, conditional routing, and memory.
- The graph-based setup helps make complex workflows easier to understand and debug.
- Works closely with LangChain tools, retrievers, and model providers.
- Built for reliable production use, not just for demos.

#### Disadvantages:

- Requires a stronger understanding of agent design patterns.
- For simple RAG or single-step tasks, the extra features might not be needed.

#### Best For:

It’s best for teams working on agent-based systems, autonomous workflows, or apps that need to keep state, coordinate tools, and reason in steps.

### #7: DeepSeek Integration Tooling

DeepSeek is now a key part of the open-source LLM community, with strong models designed for reasoning, coding, and cost savings. New integration tools and inference frameworks make it easier for teams to use DeepSeek models in their current RAG and agentic pipelines. Teams often use these tools alongside frameworks such as LangChain and LangGraph. This lets DeepSeek models replace proprietary APIs, while still giving teams control over how and where they deploy their models and manage their data.

Explore DeepSeek’s AI chat interface to ask questions, run searches, and generate intelligent responses in real time.
 Image Source: DeepSeek

#### Advantages:

- Strong reasoning performance from open-weight models.
- Lower inference costs compared to proprietary alternatives.
- Compatible with standard LLM orchestration frameworks.
- Suitable for self-hosted and regulated environments.

#### Disadvantages:

- Requires more infrastructure management than hosted APIs.
- Smaller ecosystem compared to long-established providers.

#### Best For:

This approach is best for organizations that want open-source, controllable LLM deployments. It works well for teams looking to integrate with RAG and agentic systems without depending on closed platforms.

## Key Features in Modern LLM Tooling

Remember that when evaluating LLM development tools, certain key features are essential for building effective AI applications. It’s important to ensure that your chosen LLM development tools feature:

- **Fine-Tuning and Model Customization:** Dev tools with the ability to perform fine-tuning on pre-trained models are critical. This process adjusts a general model, like a Generative Pre-trained Transformer (GPT), using a specific dataset. This improves performance on specific bespoke tasks and makes the model great at specific data analysis. In production systems, fine-tuning is often combined with agentic workflows, where specialized agents use adapted models for narrowly defined tasks. Businesses often train models on proprietary company data to make the LLM an expert in their business model.
- **Retrieval Augmented Generation (RAG):** RAG enhances LLM models by connecting them to external data sources. This is often achieved with a vector database. When a query is made, the system performs a similarity search to find relevant information, which is then provided to the LLM as context. In modern systems, teams also use RAG evaluation tools to measure context relevance, grounding, and answer faithfulness. This evaluation layer helps reduce errors and ensures the model is using retrieved data correctly.
- **Function Calling:** Modern language models can now use function calling. This allows the model to interact with external APIs and tools. For example, an LLM could use a function to get current weather data or book a meeting. This feature transforms generative models into agent-driven systems that can plan, act, and respond across multiple steps. Most AI agents rely on this capability, and the technology significantly expands how LLMs integrate with other software.
- **LLM Observability:** An LLM observability platform is used to monitor model performance. It tracks performance metrics, logs inputs and outputs, and helps teams understand how their LLM applications are being used. For agentic and RAG-based systems, observability also includes tracing multi-step reasoning, tool calls, and retrieval outcomes, which is essential for maintaining quality and identifying areas for improvement.

## Conclusion

When it comes to LLM development tools, the choice is no longer just about which language model to use, but about selecting a complete development environment that can orchestrate agents, manage retrieval pipelines, and monitor system behavior in production.

Choosing the right approach – whether it is a full-service development partner or an in-house MLOps solution, depends on internal expertise, project scope, and business goals. By prioritizing LLM tools that support agentic workflows, Retrieval-Augmented Generation (RAG), RAG evaluation, and end-to-end observability, organizations can build intelligent systems that are not only scalable, but also reliable and auditable.

Ultimately, the effectiveness of these software tools depends on the power and reliability of the underlying hardware. Deploying modern LLM systems, especially those running multi-agent reasoning loops or real-time inference—requires high-performance GPU infrastructure capable of consistent, low-latency execution. This is where a provider like Atlantic.Net can help, offering GPU-accelerated cloud services designed to support demanding AI workloads.

By pairing the right LLM development stack with high-performance infrastructure, organizations can move beyond experimentation and deploy production-grade, agent-driven AI systems that deliver real business value.

To learn more about [Atlantic.Net GPU hosting solutions](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/), powered by NVIDIA, contact our team today or deploy a dedicated A100 or H100 GPU server in seconds to power your AI applications.


---

# Best PCI-Compliant Hosting

> URL: https://www.atlantic.net/pci-compliant-hosting/best-pci-compliant-hosting/ | Updated: 2026-09-16

Get started with our top-notch PCI-Compliant Hosting today!

## Best PCI-Compliant Hosting Overview

PCI-compliant hosting is designed to keep your cardholder data environment (CDE) tightly secured and aligned with PCI DSS v4.0.1. Within this category, PCI-ready hosting is typically delivered as a cloud service by managed service providers, giving businesses a secure, pre-configured environment for processing credit card transactions. These environments combine numerous pre-built controls with a provider's Attestation of Compliance (AOC), giving small to midsize organizations a faster, more predictable path to completing their Self-Assessment Questionnaires (SAQs).

PCI-compliant infrastructure is typically delivered as part of a privately hosted environment, often built on a mix of dedicated bare metal hosts and cloud servers. Private hosting is the right choice when you need strict isolation for PCI DSS, want to design custom security architectures, or must support complex, high-volume cardholder data environments (CDEs) as a Level 1 merchant or service provider.

By contrast, cloud platforms with PCI-focused controls are most suitable when flexibility and global reach matter – and your team has the skills to configure segmentation, logging, encryption, and multi-factor authentication (MFA) correctly under a shared-responsibility model.

Whichever approach you take, you are still required to complete your Self-Assessment Questionnaire (SAQ) or Report on Compliance (ROC) and remain ultimately responsible for the security of your CDE and the business processes around it.

Why it matters: PCI DSS v4.0.1 is the current global standard, and organizations that process card data must demonstrate compliance via Self-Assessment Questionnaires (SAQs) or a Report on Compliance (ROC). The right hosting model can reduce in-scope systems, lower audit effort, and improve your overall security posture.

## Key Takeaways

To get real value from PCI-focused hosting, it helps to separate what your provider can do for you from what you must still own yourself:

### Hosting supports PCI DSS; it never replaces your validation.

You are still responsible for completing the appropriate Self-Assessment Questionnaires (SAQs) or a Report on Compliance (ROC) and for the security of your cardholder data environment (CDE) and business processes.

### Treat scope reduction and segmentation as non-negotiable.

Isolating the CDE from the rest of your network reduces the number of systems, controls, and evidence your assessor needs to review, making PCI more manageable.

### Use provider attestations as inputs, not substitutes.

A hosting provider's Attestation of Compliance (AOC) is valuable, but it only covers the services they operate. Your applications, configuration decisions, and internal procedures still require their own documented controls.

### Approach cloud platforms with PCI controls carefully.

PCI-focused cloud platforms offer flexibility and global reach, but misconfigurations in security groups, key management, or logging can quickly expand your PCI scope or introduce new risks under the shared-responsibility model.

### Design evidence collection and logging up front.

Centralized logging, file integrity monitoring (FIM), and security monitoring dramatically reduce audit effort by ensuring you already have the proof your QSA will ask for.

### Reserve private hosting for complex, high-risk, or highly regulated CDEs.

Full isolation and deep control support advanced architectures, but they also increase your operational workload and the expertise required to run them safely.

### Use PCI-ready hosting to accelerate smaller environments.

For many small and midsize enterprises (SMEs), pre-built controls, network segmentation, and a provider AOC make PCI-ready platforms the fastest route from "we take cards" to "we have defensible evidence of compliance."

## PCI DSS and the Role of Hosting

The Payment Card Industry Data Security Standard (PCI DSS) defines how any entity that stores, processes, or transmits cardholder data must protect it. A cardholder data environment (CDE) is the set of people, processes, and technologies that handle cardholder or sensitive authentication data, along with any connected system that could affect the security of that data.

Responsibilities:

Under PCI DSS, responsibilities are defined based on the role you play in handling cardholder data. Broadly, there are two primary entity types: merchants and service providers.

Hosting providers that can affect payment data are treated as service providers under PCI DSS. Their own PCI DSS compliance and Attestation of Compliance (AOC) give assurance about the underlying infrastructure and managed controls, but they do not extend to your application code, configuration decisions, internal procedures, or overall environment. Strong hosting can help reduce and harden your cardholder data environment (CDE); it cannot, by itself, make your business PCI compliant.

- Merchants: Businesses that accept card payments (e-commerce, in-store, call center, etc.).
- Service providers: Organizations that store, process, or transmit card data on behalf of others – or could impact the security of cardholder data (e.g., hosting providers, managed security providers).

## Benefits & Features of PCI-Compliant Hosting

PCI-focused hosting should deliver both strategic benefits for your compliance program and concrete, testable controls in the payment environment. Gaining PCI compliance is extremely challenging, however, PCI hosting can make it much easier to achieve compliance.

Here are some of the top benefits for PCI-hosting:

- Faster path to validation: Pre-built controls are available – such as firewalls, logging, multi-factor authentication (MFA), encryption, and vulnerability management – reduce the number of bespoke decisions you need to justify to a QSA.
- Reduced CDE risk. Strong segmentation, hardened management planes, and tightly controlled administrative access make lateral movement into cardholder data environment (CDE) systems significantly harder.
- Standardized controls aligned to PCI DSS v4.0.1. Stronger authentication models, modern encryption standards, and continuous monitoring help you maintain a resilient, forward-compatible security posture.
- Clear documentation trail. Provider Attestations of Compliance (AOCs), network diagrams, and control descriptions plug directly into SAQ/ROC documentation, cutting down on preparation time and consultancy costs.
- Predictable security posture. Instead of reinventing security patterns for each project or team, you inherit a consistent and secure platform.

## Core Features to Look For

If you are interested in PCI-hosting, here are some of the top features you should expect from the best PCI-Compliant Hosting Providers:

Controls & infrastructure capabilities

- Network segmentation, firewalls, and IDS. Expected isolated cardholder data environment (CDE) subnets and strict control traffic between CDE and non-CDE segments. Log allowed and blocked flows on next-generation firewalls, and use Intrusion Prevention Systems to detect suspicious patterns at the perimeter network and between layered network tiers.
- Vulnerability management and patching. Your provider should run regular external and internal vulnerability scans, including authenticated scans where appropriate. They must apply critical and high-severity patches within defined timelines (for example, within one month of release), and handle others according to a documented risk-based process.
- MFA and role-based access control (RBAC). Expect MFA for all access into the CDE and for remote administrative access. Map fine-grained roles to least-privilege principles (Ops, DBAs, Developers, Auditors) and back them with change approval, onboarding, and revocation workflows.
- Secure backups and disaster recovery. The provider must encrypt backups, test restores regularly, and define business-aligned recovery point and recovery time objectives (RPO/RTO), whilst ensuring that the disaster recovery environments preserve CDE segmentation and access controls.
- Centralized logging and File Integrity Monitoring (FIM). Aggregate logs from firewalls, operating systems, databases, WAF, and key applications into a central platform, typically a SIEM platform. Teams should monitor critical system and configuration files with FIM agents, retain for at least 12 months (with at least the most recent 3 months immediately available), and protect log data against alteration.
- TLS policies and key management. The hosting platform must enforce strong cryptography (such as TLS 1.2 or 1.3) and disable SSL/early TLS. Also, define ownership and rotation policies for keys (KMS/HSM), and clearly document responsibilities between you and the provider.

## Compare Service Types

PCI-Compliant Hosting vs Private vs Cloud with PCI Controls

| Service Type | Who It's For | Compliance Control | Security Responsibility | Operational Flexibility | Best Use Case |
| --- | --- | --- | --- | --- | --- |
| PCI-Compliant Shared Hosting | Small businesses | Limited | Provider-managed | Low | Simple eCommerce sites |
| PCI-Ready VPS Hosting | Growing businesses | Moderate | Shared responsibility | Medium | Custom applications |
| PCI-Ready Dedicated Servers | High-traffic organizations | High | Customer-managed | High | Enterprise workloads |
| Fully Managed PCI Hosting | Compliance-focused teams | Very High | Provider-managed | Medium | Hands-off PCI compliance |
| Summary | Shared hosting offers the lowest level of control for PCI needs, while VPS and dedicated servers provide increasing flexibility and responsibility. Fully managed PCI hosting minimizes operational overhead by shifting most compliance and security tasks to the provider. |  |  |  |  |

Ask to see the provider's responsibility matrix/RACI (to see who owns which controls) and their AOC scope (to see exactly what parts of their environment are PCI-assessed), so you know what's shared and what's still your responsibility.

## Important Considerations for PCI Hosting

Beyond features and price, PCI-focused hosting decisions should clarify who owns which controls and how your cardholder data environment (CDE) is protected in practice.

### Ownership of keys and logs

Decide whether your team or the hosting provider owns and operates the encryption keys (e.g., KMS/HSM) and who is permitted to decrypt cardholder data.

Ensure CDE logs remain accessible to you for forensics, incident response, and PCI evidence, even if the provider aggregates or normalizes them in a central platform.

### Segmentation models

Document how CDE networks are isolated from non-CDE networks, including DMZs, application tiers, and management planes.

Confirm that management, backup, and jump-host networks are clearly understood: either in-scope for PCI DSS or deliberately kept out of scope through strong access controls, one-way flows, and hardened boundaries.

### Change control and infrastructure as code

Treat firewall rules, IAM policies, routing tables, and security groups as controlled configuration items, not ad hoc tweaks.

Maintain approvals, testing, and rollback plans for changes that could affect the CDE – ideally enforced through infrastructure-as-code pipelines with peer review and audit trails.

Choosing between PCI-ready hosting, private hosting, and cloud with PCI controls is not just a cost comparison – it is about aligning responsibility, internal expertise, and acceptable risk with the right hosting model.

## Introducing Atlantic.Net PCI-Ready Options

Atlantic.Net aligns hosting services to PCI DSS requirement families, so you can build a cardholder data environment (CDE) that is secure and straightforward to audit – rather than stitching controls together from scratch.

### PCI-ready network foundations

Segmented CDE networks, secure VPN/remote access options, managed firewalls, and IDS/IPS to help meet PCI DSS secure network requirements while tightly controlling traffic between CDE and non-CDE zones.

### Data protection and key management

Encrypted storage and backups, enforced TLS, and integration with key-management workflows (KMS/HSM) to protect cardholder data at rest and in transit.

### Vulnerability management and hardening

Managed vulnerability scanning, OS patching options, and hardened baseline images to support vulnerability-management and secure-configuration controls.

### Identity, access, and MFA

Centralized user management, MFA for administrative access and all access into the CDE, and RBAC to support least-privilege designs that stand up to QSA scrutiny.

### Logging, monitoring, and incident-response hooks

Centralized log collection with export/integration into your SIEM to demonstrate monitoring, alerting, and incident-response practices.

### Assessment support and documentation

Access to applicable AOCs and supporting documentation upon request – plus network diagrams and control descriptions – to plug into SAQ/ROC packages.

By structuring services along PCI DSS control families, Atlantic.Net helps cut down the number of custom decisions you need to justify during assessment and lets you focus more on application logic and business processes.

## How to Get Started with Atlantic.Net

A structured onboarding path shortens the time from "project kickoff" to "PCI-ready".

### 1) Map your payment flows and CDE

Identify where cardholder data enters, moves, and exits your environment (web, mobile, POS, IVR, etc.), and distinguish in-scope vs out-of-scope systems.

### 2) Select the right hosting model

Choose between PCI-ready hosting, private hosting, or cloud with PCI controls (or hybrid) based on merchant level, expected traffic, and internal capabilities.

### 3) Design segmentation and access control

Build a network and IAM design that isolates CDE assets, defines management/support access, and documents trust boundaries for SAQ/ROC.

### 4) Integrate logging, monitoring, and backups

Enable centralized logging from day one, define retention/access, and ensure encrypted backups and DR environments follow PCI DSS controls.

### 5) Prepare for validation

Gather applicable AOCs, align internal policies and application controls, then engage a QSA or complete the SAQ with a clear evidence trail.

## PCI-Compliant Hosting FAQ

### Does using a PCI-compliant host make my business PCI compliant?

No. A hosting provider's PCI DSS compliance and Attestation of Compliance (AOC) cover the infrastructure and managed services they operate. Your applications, configuration decisions, internal procedures, and business processes still require their own documented controls. Strong hosting reduces and hardens your CDE – it cannot, by itself, make your business PCI compliant. You still need to complete the appropriate Self-Assessment Questionnaire (SAQ) or Report on Compliance (ROC).

### What's the difference between PCI DSS v3.2.1 and v4.0.1?

PCI DSS v3.2.1 was retired on 31 March 2024 and is no longer the standard against which assessments are performed. v4.0 was published in March 2022 with a transition period; v4.0.1 (the current version) was published in June 2024 with minor clarifications and corrections to v4.0. v4.0.1 brings stronger authentication requirements (including phishing-resistant MFA for personnel with access to the CDE), more prescriptive password requirements, expanded scope around scripts on payment pages, and a customized-approach option that lets organizations meet objectives via alternative implementations.

### What is a Cardholder Data Environment (CDE) and how do I reduce its scope?

The CDE is the set of people, processes, and technologies that store, process, or transmit cardholder data – plus any system component connected to or that could impact the security of the CDE. To reduce scope, isolate the CDE from the rest of your network with strong segmentation (firewalls, VLANs, dedicated subnets), tokenize or outsource card capture (e.g., redirect/iframe payment pages to a hosted page), and minimize the systems that touch raw card data. The fewer systems in scope, the fewer controls, evidence, and tests your QSA needs to review.

### Which SAQ should I complete?

The right SAQ depends on how you accept and process card data: SAQ A – card-not-present merchants who fully outsource the cardholder data environment to PCI-DSS-validated third parties (typical for sites using a hosted payment page or full redirect). SAQ A-EP – e-commerce merchants where the website affects the security of the payment transaction but does not directly receive card data (e.g., direct-post or JavaScript that forwards to a PSP). SAQ B / B-IP – merchants using only imprint or standalone terminal devices. SAQ C – merchants with payment-application systems connected to the internet. SAQ D – all other merchants and all service providers eligible to complete an SAQ. Service providers above defined transaction volumes are typically required to complete an on-site assessment with a Report on Compliance (ROC) instead of an SAQ. Your acquirer or QSA will confirm the appropriate SAQ for your specific environment.

### What's an Attestation of Compliance (AOC), and why does it matter?

An AOC is the official summary statement attached to a completed SAQ or ROC. It confirms that an entity has been assessed against PCI DSS and which requirements were validated. When choosing a PCI-focused hosting provider, ask for their AOC and read its scope carefully – the AOC tells you exactly which services and facilities the assessor evaluated, and which were excluded. Inheriting controls from a hosting provider's AOC is one of the fastest ways to shrink your own assessment effort.

### How long must I retain PCI logs and evidence?

PCI DSS requires audit log history to be retained for at least one year, with the most recent three months immediately available for analysis. File integrity monitoring, vulnerability scan results, incident records, and supporting evidence should follow the same minimum retention. Your business or contractual requirements may extend retention beyond this baseline.

### Is MFA mandatory under PCI DSS?

Yes. PCI DSS v4.0.1 requires multi-factor authentication for all access into the cardholder data environment and for all remote network access – both for administrators and for any user (including third parties) connecting from outside the company's trusted network. Where the standard previously allowed two-factor authentication, v4.0.1 requires it explicitly and applies it more broadly. MFA methods must be resistant to replay and bypass, and any remaining static-password factors must meet stronger length and complexity requirements.

### Can a single hosting provider host both PCI and HIPAA workloads?

Yes – Atlantic.Net hosts both PCI-aligned and HIPAA-aligned workloads on the same underlying audited infrastructure, and many of the underlying controls (segmentation, encryption, MFA, logging, hardening) overlap. The frameworks are different, however, so the documentation, attestations, and contractual instruments differ: PCI DSS uses SAQ/ROC and AOC; HIPAA uses BAAs and risk analyses informed by SOC 2 Type II / SOC 3 + HIPAA/HITECH attestations. Workloads should be logically segmented even if hosted in the same datacenter to keep PCI scope and ePHI flows clean.

## Conclusion and Next Steps

Choosing a PCI-focused hosting provider is ultimately about reducing scope, tightening controls, and making PCI validation repeatable – without overwhelming your team. Atlantic.Net's PCI-hosting gives you a structured foundation for secure networks, data protection, monitoring, and documentation, so you can spend more time on your applications and customers, and less time reinventing infrastructure controls.

If you are planning a new payment project or re-evaluating your current PCI strategy, talk to [Atlantic.Net about PCI-hosting](https://www.atlantic.net/pci-compliant-hosting/), private environments, or cloud with PCI controls – and design a CDE that is secure, auditable, and sustainable year after year.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Best HIPAA-Compliant Hosting for Protected ePHI

> URL: https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-hosting/ | Updated: 2026-09-16

Compare managed HIPAA hosting, private single-tenant infrastructure, and public cloud controls to choose an audit-ready foundation for safeguarding ePHI.

- SOC 2 Type II & SOC 3
- HIPAA/HITECH Assessed
- BAA Available
- Encryption, IAM & MFA

Infrastructure uptime SLA: 100%

Business Associate Agreement: BAA

## Best HIPAA-Compliant Hosting Overview

HIPAA-compliant hosting is a specialized infrastructure service designed to safeguard electronic Protected Health Information (ePHI) in accordance with the U.S. Health Insurance Portability and Accountability Act. HIPAA-compliant hosting is required for any Covered Entity (e.g., hospitals, clinics) or Business Associate (e.g., managed service providers, app developers) that creates, receives, maintains, or transmits ePHI.

Choosing a HIPAA-compliant hosting provider requires significant thought and consideration. Most HIPAA-aligned deployments use bare metal or dedicated infrastructure to simplify compliance, but it is possible for cloud servers to be compliant; however, this approach takes greater planning and consideration.

Choosing between private (single-tenant) bare metal and public cloud dedicated options depends largely on your internal technical resources and risk tolerance: private options provide maximum isolation and control; public cloud offers rapid scalability but requires rigorous configuration and monitoring to remain compliant.

Why it matters: Using non-compliant hosting is a violation of federal law and can trigger significant penalties (currently exceeding $2.1M per violation category per calendar year, subject to annual inflation adjustments), plus legal liability, breach response costs, and reputational damage. Operational compliance ensures your environment is audit-ready and sustains patient trust.

## Key Takeaways

### Compliance is a shared responsibility

Providers handle physical facilities and core infrastructure; you remain responsible for application security, identity and access management, and configuration of services within your environment.

### The BAA is non-negotiable

If a provider will not sign a Business Associate Agreement (BAA) for your specific use case, they are not suitable for hosting ePHI. Note: cloud providers are BAs even if they cannot view encrypted ePHI.

### Private hosting = maximum control

Single-tenant private cloud or dedicated servers eliminate "noisy-neighbor" contention and offer the highest isolation.

### Public cloud is viable with care

Major public clouds can support ePHI in production under a BAA, but typically require meticulous configuration (networking, IAM, keys, logging) and continuous monitoring.

### Logging matters for audits

HIPAA requires retaining required documentation for at least six years. Align audit-log retention to this requirement where logs evidence required actions/activities, and justify retention via risk analysis.

### Encrypt everything (risk-based)

Encrypt ePHI in transit (TLS 1.2/1.3) and at rest using NIST-recommended algorithms in FIPS-validated modules when feasible; if not feasible, document compensating controls per HIPAA's addressable specifications.

### Safeguards are holistic

Effective compliance integrates Administrative, Physical, and Technical safeguards across people, process, and technology.

## Benefits & Features of HIPAA-Compliant Hosting

Adopting a compliant hosting environment is about more than avoiding fines; it establishes a structure for operational excellence and data integrity. Patients expect their private data to be managed per HIPAA guidelines.

Benefits of HIPAA Hosting

There are several advantages to HIPAA-compliant hosting. These advantages highlight the positive business impact of running healthcare applications and services on compliant infrastructure.

- Risk reduction: Offloads facility and core infrastructure security to external experts, reducing exposure to common failure modes and misconfiguration.
- Audit readiness: Ensures availability of relevant certifications and attestations (e.g., SOC 2 Type II with a public SOC 3), BAAs, and policy documentation that OCR investigators commonly request, and maps evidence to your environment's scope.
- Standardized security: Encourages best practices like least-privilege access and change control.
- Patient trust: Demonstrates a clear commitment to protecting sensitive health information and builds partner confidence.

## Essential Features

To be HIPAA-compliant, it's essential to implement the mandatory technical controls to meet requirements and reduce risk. Hosting providers achieve this by creating an environment designed to meet and exceed the physical, administrative, and technical safeguards of HIPAA compliance.

- Encryption: ePHI encrypted at rest (e.g., AES with FIPS-validated modules) and in transit (TLS 1.2/1.3). Explicitly disable SSL and TLS 1.0/1.1.
- IAM & MFA: Centralized identity and access management with multi-factor authentication for administrative and remote access. (Best practice today; note that future rule updates may make MFA explicitly required.)
- Centralized, immutable logging: Comprehensive logs for authentication, access, system changes, and security events; time-synced and tamper-resistant.
- Disaster recovery (DR): Encrypted, off-site backups with routine restore testing and defined recovery objectives (RPO/RTO).
- Network segmentation: Firewalls, private networks/VLANs, and VPNs or private connectivity for administrative access and east-west isolation.
- BAA availability: Executed before any ePHI is moved to the environment; clearly defines roles, responsibilities, and liability.

## Which Service Type Fits Your Risk Profile?

Not all "HIPAA-compliant" hosting is created equal. Your choice depends on the division of responsibilities, desired isolation, and internal capabilities. You can take a do-it-yourself approach and take full responsibility, or outsource to a provider and share responsibility.

Use the following matrix to compare these options at a glance and choose the right ownership model for your healthcare business.

| Service Type | Ideal For | Isolation | Controls Coverage | BAA | Operational Effort (You) | Flexibility | Cost Predictability |
| --- | --- | --- | --- | --- | --- | --- | --- |
| Managed HIPAA Hosting (e.g., managed private cloud) | SMBs, clinics, lean IT teams | High (curated) | High (vendor manages facilities, hypervisor, managed OS/security stack; you manage app/IAM/data) | Yes | Low-Medium | Medium | High |
| Private Hosting (DIY) (dedicated servers/private cloud you operate) | Enterprises, large hospital systems | High | Custom (you build and operate controls) | Possible | High | High | Variable |
| Public Cloud with HIPAA Controls | Startups/scale-ups, production PHI with strong DevSecOps | Medium (logical isolation) | High if configured correctly (you own configs: network, IAM, keys, logging) | Yes (via vendor) | Medium-High | High | Variable |
| Summary | Managed HIPAA Hosting: high curated isolation, high coverage, BAA yes, lower operational effort; Private Hosting (DIY): high isolation with custom controls and higher effort; Public Cloud with HIPAA Controls: medium logical isolation, high coverage if configured correctly, BAA via vendor, variable cost predictability. |  |  |  |  |  |  |

Shared responsibility: In a managed environment, the provider typically secures the infrastructure (facilities, hardware, hypervisor, managed OS patching, IDS) and curated security services. In a public cloud, the provider secures the infrastructure of the cloud; you secure what you build in the cloud (OS hardening, network rules, key management, IAM, application security, data classification).

## Costs, Risk & Audit Readiness

The cost of HIPAA hosting is often a fraction of the cost of a breach. It's important to evaluate total cost of ownership (TCO), including tooling, staffing, and continuous monitoring.

Focus on these operational essentials to stay audit-ready year-round.

### Security risk analysis & risk management

Required under the Security Rule. Perform an initial analysis and update regularly (at least annually and upon material changes).

### Documentation

Retain required documentation for at least six years (policies, procedures, and documentation of actions/assessments). Align system log retention accordingly based on how logs evidence required activities.

### Logging

Confirm that your plan includes centralized log management and retention sufficient for investigations and audits, with time synchronization and tamper-evident controls.

### Incident response

Ensure 24×7×365 monitoring and escalation with tested playbooks, RTO/RPO alignment, and third-party contact trees. Ensure that the most serious incidents can be identified outside of business hours.

### Breach notification

Notify affected individuals without unreasonable delay and no later than 60 days. Notify HHS within 60 days only if ≥500 individuals are affected; for fewer than 500, report no later than 60 days after year-end (state-law obligations may be stricter).

### Crypto & protocols

Prefer TLS 1.2/1.3 and NIST-recommended algorithms in FIPS-validated modules where required. A VPN is commonly used for administrative access or private connectivity but is not a universal requirement if TLS is correctly applied: also enforce key-management hygiene (rotation, separation of duties).

## Introducing Atlantic.Net HIPAA-Compliant Hosting

With three decades of experience in high-availability hosting, Atlantic.Net excels at providing an infrastructure foundation specifically engineered for regulated healthcare workloads. Rather than relying on self-attestation, our HIPAA-compliant hosting platform undergoes rigorous third-party auditing.

We maintain SOC 2 Type II and SOC 3 certification, with specific assessments against HIPAA/HITECH standards by independent CPA firms. Since there is no official federal "HIPAA Certification," these independent audit reports act as critical evidence required for your own compliance documentation.

## Why Atlantic.Net?

Our platform is built on a rigorous audit framework rather than self-attestation. We maintain SOC 2 Type II and SOC 3 attestations, with specific assessments against HIPAA/HITECH standards conducted by independent auditors. Since the HHS/OCR does not offer an official "HIPAA Certification," these third-party audit reports provide the concrete evidence necessary to satisfy your own compliance documentation requirements.

- HIPAA audited: SOC 2 Type II-attested with a public SOC 3 report, and assessed against HIPAA/HITECH by independent third-party auditors.
- Flexible BAAs: We work with you to execute a Business Associate Agreement (BAA) that aligns with your specific workflows and data flows.
- Fully managed safeguards: Managed firewalls, Intrusion Prevention Systems (IPS), multi-factor authentication (MFA) enablement, and encrypted VPN options are available on HIPAA-compliant platforms.
- Uptime SLA: A 100% infrastructure uptime SLA (excluding scheduled maintenance and documented exceptions) helps ensure critical healthcare applications remain available at all times: scope applies to infrastructure components; see SLA for details.

## How to Get Started with Atlantic.Net

Want to know more about the Atlantic.Net award-winning HIPAA-compliant hosting service? HIPAA hosting is one of our most popular platforms, and we are proud to host a large number of healthcare organizations. At Atlantic.Net, we know that compliance is a difficult journey (especially when you are starting out) but we are standing by, ready to help and share our years of experience providing American healthcare businesses the best-in-class HIPAA hosting service available today.

Reach out today to start a conversation. We can then engage with you to discover:

### How your data flows

Identify where ePHI resides in your environment and how it moves around (email, local servers, SaaS, cloud, devices, integrations).

### What is your security risk analysis

Learn how to document risks, likelihood/impact, and selected controls, and how to update after significant changes.

### Speak to our architects

Contact Atlantic.Net for a consultation to map your current environment to a HIPAA-aligned private, managed, or hybrid design.

### Execute the BAA

Complete the Business Associate Agreement before ePHI is ingested into our HIPAA-compliant hosting.

### Migrate & encrypt

Plan and execute a migration strategy with encrypted transfer, encryption at rest, hardened images, and validated backups/DR.

### Validate monitoring & logging before go-live

Plan how to enable SIEM alerts, confirm retention settings, and ensure authorized stakeholders have dashboard access.

### Post-migration validation

Discover what the service looks like after you migrate to Atlantic.Net HIPAA hosting: learn how to verify incident response, troubleshoot backup/restores, and implement access controls across the new environment.

## HIPAA-Compliant Hosting FAQ

### Is there an official HIPAA certification I can buy?

No. The U.S. Department of Health and Human Services (HHS) does not issue or recognize an official "HIPAA certification", neither for organizations nor for software. What you and your hosting provider rely on instead is independent third-party evidence: SOC 2 Type II attestations, a public SOC 3 report, and HIPAA/HITECH-specific assessments performed by independent auditors. These reports become part of the evidence base you cite in your own compliance documentation.

### Do I need a Business Associate Agreement (BAA) before moving ePHI?

Yes, always. A signed BAA must be in place between you (the Covered Entity or upstream Business Associate) and the hosting provider before any ePHI is created, received, stored, or transmitted in the environment. The BAA defines the provider's permissible uses and disclosures, security obligations, breach-notification timelines, and termination rights. A provider who refuses to sign a BAA for your specific use case is not a viable partner for ePHI workloads.

### Can public cloud hosting be HIPAA-compliant?

Yes, with care. Major public clouds will execute a BAA and can support ePHI in production workloads, but only when you correctly configure networking, IAM, encryption keys, audit logging, and monitoring on top of their infrastructure. The cloud provider is responsible for the security of the cloud; you are responsible for the security in the cloud. Public cloud is operationally heavier than a managed HIPAA platform but offers elastic scale, which is why it works well for engineering-heavy startups and scale-ups.

### What encryption is required for ePHI?

Encryption is technically an "addressable" specification under the HIPAA Security Rule (not a strict mandate) but it is treated as the baseline industry expectation and is the safe-harbor for breach-notification liability under HITECH. In practice that means TLS 1.2 or 1.3 for data in transit (with SSL and TLS 1.0/1.1 explicitly disabled), and AES encryption (typically AES-256) for data at rest using NIST-recommended algorithms in FIPS-validated modules where feasible. If encryption isn't feasible for a specific data flow, document the compensating controls and the risk-analysis rationale.

### How long do I need to retain HIPAA documentation and audit logs?

HIPAA requires retention of documentation for a minimum of six years from the date of creation or last effective date, whichever is later. That covers policies, procedures, risk analyses, incident records, BAAs, and any documentation required by the rule. Audit logs themselves are not assigned an explicit retention period, but where a log is the evidence of a required action (access, change, security event), align its retention with the six-year rule. State laws may impose stricter requirements, check your state.

### What happens if I have a breach? When must I notify HHS?

Notify affected individuals without unreasonable delay and no later than 60 days after discovery. For HHS, the notification timing depends on scale: breaches affecting 500 or more individuals must be reported to HHS within 60 days of discovery; breaches affecting fewer than 500 individuals are reported in an annual log no later than 60 days after the end of the calendar year in which they were discovered. Some states require faster or additional notifications. Atlantic.Net's incident-response playbooks include 24×7 detection and stakeholder escalation to support these timelines.

### What's the difference between HIPAA and HITECH?

HIPAA (1996) established the privacy and security framework for Protected Health Information. HITECH (2009) extended HIPAA: it strengthened enforcement and penalties, introduced mandatory breach-notification rules, expanded direct liability to Business Associates, and incentivized adoption of electronic health records. In 2013 the Omnibus Final Rule consolidated the HIPAA Privacy, Security, Breach Notification, and Enforcement rules. When you see "HIPAA/HITECH compliance," it means the combined framework that applies to the modern healthcare data environment.

### How long does a HIPAA migration to Atlantic.Net typically take?

Migration timelines vary by environment complexity and data volume, but a typical small-to-medium clinic or healthcare SaaS provider lands in 4-8 weeks end-to-end: discovery and data-flow mapping (1-2 weeks), BAA execution and architecture design (1 week), provisioning and hardening (1-2 weeks), test migrations and DR validation (1-2 weeks), and a coordinated cutover with monitoring/SIEM verification before go-live. Larger hospital systems with multiple integrations are typically scoped on a per-engagement basis.

## Ready to secure your ePHI?

Engage our team today to map your environment, finalize your BAA, and ensure your go-live is fully compliant.

Contact us today to get started!

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# 7 Best HIPAA-Compliant Telehealth Platforms (2026)

> URL: https://www.atlantic.net/hipaa-compliant-hosting/top-7-hipaa-compliant-telehealth-platforms-2026/ | Published: 2026-02-12 | Updated: 2026-04-14 | Author: Dr. Assad Abbas

Telehealth is a fundamental component of healthcare in 2026. It has changed the way patients access care and the way providers interact with them. Many patients now expect the option to meet their providers online. Therefore, the demand for secure and reliable telehealth platforms has increased. These platforms must protect [electronic Protected Health Information (ePHI)](https://www.atlantic.net/hipaa-compliant-hosting/protecting-phi-cloud/) and support safe communication between patients and providers. They must also follow HIPAA regulations by using strong security controls such as end-to-end encryption, role-based access, and audit logging.

A HIPAA-compliant telehealth platform helps healthcare organizations offer virtual care with confidence. It protects patient data and supports clinical workflows. Moreover, it reduces the risk of security incidents and regulatory penalties. Therefore, selecting the right platform is important for any practice that offers virtual care. This article reviews the top HIPAA-compliant telehealth platforms for 2026 and explains how secure hosting protects ePHI across telehealth systems.

## Why HIPAA-Compliant Telehealth Platforms Matter in 2026

Telehealth systems manage sensitive patient information during every session. Therefore, they must follow strict rules to keep this information safe. Under HIPAA, any platform that handles must use strong technical and administrative measures. These safeguards include encryption for data in transit, controlled access for staff, and detailed activity logs. In addition, the platform must sign a [HIPAA Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/). This agreement explains the responsibilities of the vendor and confirms that patient information will be handled properly.

However, many general video tools do not meet these requirements. They may use weak encryption or offer limited control over user access. They may also lack proper logging or secure storage for sensitive files. Consequently, using such tools can expose healthcare organizations to penalties and compliance issues. It can also reduce patient confidence in virtual care. A HIPAA-compliant telehealth platform helps avoid these problems by offering a secure environment for communication. It keeps ePHI protected during video sessions, messages, and document exchanges. Moreover, it supports consistent and safe virtual care across different clinical settings.

## Benefits of HIPAA-Compliant Telehealth Platforms

**HIPAA-compliant** telehealth platforms offer several advantages that support both patients and healthcare teams. These benefits create safer communication and more organized clinical processes.

- **Improved Patient Access**: Patients gain easier access to appointments from different locations. This improves consistency in follow-up care and reduces missed visits.
- **Reduced Risk of Data Breaches**: Strong security controls reduce the chance of unauthorized access to ePHI. This lowers the risk of incidents that lead to penalties or investigations.
- **Streamlined Administrative Workflows**: Many platforms include tools for scheduling, reminders, and documentation. These tools reduce manual tasks and help staff manage workloads.
- **Better Patient Monitoring**: Some platforms connect with monitoring devices. This helps providers observe patient conditions more closely and respond when needed.
- **Support for Specialized Care**: Telehealth offers privacy and convenience for therapy, counseling, and other sensitive services.

## Key Features of a HIPAA-Compliant Telehealth Platform

A **HIPAA-compliant** telehealth platform must include several technical and administrative features to protect ePHI.

- **Data Encryption**: The platform must use strong encryption such as TLS 1.2 or TLS 1.3. This protects video, audio, and messages during transmission.
- **BAA Availability**: A **BAA** must be in place to confirm the vendor follows HIPAA rules.
- **Access Control and Audit Logs**: Role-based access control and audit logs track user activity and prevent unauthorized access to sensitive information.
- **Secure Communication Channels**: Secure video sessions and private waiting rooms support safe patient interactions.
- **Patient Portals**: Secure messaging supports communication outside the appointment.
- **Digital Documentation**: Electronic intake forms and secure file sharing reduce paperwork and improve information management.
- **EHR Integration**: Connection with EHR and practice-management systems keeps records consistent.

These features work together to create a safe and organized telehealth environment. They also help healthcare organizations maintain compliance while supporting daily operations.

## How to Evaluate Telehealth Platforms in 2026

Evaluating a telehealth platform requires a clear understanding of the organization’s needs. Small practices often prefer tools focusing on basic communication, whereas larger health systems may need broader functions, including EHR integrations and support for multiple departments.

It is also helpful to review how the platform manages documents and patient forms. Secure file sharing and digital consent forms support daily tasks and help maintain compliance. The platform should operate on reliable cloud infrastructure. Strong uptime, monitoring, and continuity planning help maintain service availability. These elements are important because interruptions can affect both patient care and staff efficiency. A stable platform reduces the risk of workflow delays and technical issues.

## Top 7 HIPAA-Compliant Telehealth Platforms in 2026

The following HIPAA-compliant telehealth platforms are widely used across healthcare settings. They support secure communication and follow the requirements needed to protect ePHI. Each platform offers different strengths. Therefore, organizations can select the option that matches their clinical needs, practice size, and workflow preferences.

![](https://www.atlantic.net/wp-content/uploads/2026/02/doxyme.jpg)

### 1. Doxy.me

[Doxy.me](https://doxy.me/en/) is a simple, browser-based telehealth platform that focuses on ease of use. It is popular among small clinics and solo practitioners because patients can join sessions without installing software. The interface is clean and straightforward, which helps reduce confusion during virtual visits. Moreover, the platform supports secure video communication and offers a free version for basic needs. Paid plans add more customization and advanced functions, making it suitable for clinics that want a flexible and affordable telehealth option.

#### Features

- Browser-based access that lets patients join sessions through a link, reducing setup time and technical issues.
- Virtual waiting room to support patient check-in and helps providers manage session flow more smoothly.
- Encrypted video sessions using secure protocols to protect communication during appointments.
- Custom branding options in paid plans, which help clinics present more professional and consistent experience.

![](https://www.atlantic.net/wp-content/uploads/2026/02/SimplePracticeLogo-Blue.png)

### 2. SimplePractice

[SimplePractice](https://www.simplepractice.com/) is a practice-management and telehealth platform widely used in mental health and small behavioral health clinics. It brings scheduling, documentation, billing, and secure video sessions into one system, which helps providers manage both administrative and clinical tasks more efficiently. The interface is simple and easy to navigate, and the platform supports customizable templates that fit different documentation styles. In addition, SimplePractice offers group sessions and a client portal that helps patients stay organized with forms, messages, and appointment details. These elements make it suitable for solo providers and small teams that prefer an integrated environment.

#### Features

- Integrated telehealth sessions for individuals and groups, supporting therapy, counseling, and other behavioral health services in a single environment.
- Customizable documentation templates that help providers maintain consistent notes and adapt forms to their preferred clinical style.
- Billing and claims tools that support insurance workflows, reduce manual work, and help clinics maintain organized financial records.
- Client portal for forms, communication, and scheduling, which improves patient engagement and reduces administrative follow-up.

![](https://www.atlantic.net/wp-content/uploads/2026/02/Mend.png)

### 3. Mend

[Mend](https://mend.com/) is a telehealth platform that focuses on patient engagement and efficient virtual care. It supports secure video visits, digital intake forms, and automated reminders, which help clinics reduce missed appointments. Many behavioral health organizations use Mend because its interface is simple for patients and its automation tools reduce manual administrative tasks. Moreover, the platform integrates with various EHR systems, allowing clinics to maintain consistent records across systems. These capabilities make Mend suitable for practices that want to streamline communication and improve attendance rates.

#### Features

- Secure video conferencing with encrypted browsers to protect communication during appointments and support HIPAA compliance.
- Digital intake and consent forms that help clinics collect information before sessions, reduce paperwork, and maintain organized records.
- Automated reminders through text and email, which help reduce no-shows and support more predictable scheduling.
- EHR integrations that maintain consistent patient information and reduce duplicate data entry across systems.

![](https://www.atlantic.net/wp-content/uploads/2026/02/ensora.png)

### 4. TheraNest (Ensora Health)

TheraNest, now part of [Ensora Health](https://ensorahealth.com/), is a platform developed for behavioral health professionals. It supports therapy, counseling, and rehabilitation programs with tools for telehealth, scheduling, documentation, and billing. The platform is suitable for solo providers, group practices, and larger behavioral health organizations. It offers strong support for mental health workflows and includes features that help track client progress over time. Moreover, its client portal and [scheduling tools](https://www.pluginhive.com/doctor-appointment-bookings-with-woocommerce/) help clinics maintain organized operations and reduce administrative burden. These elements make TheraNest a practical option for clinics that focus on long-term behavioral health care.

#### Features

- Telehealth sessions for individuals and groups, supporting a wide range of behavioral health services in a secure environment.
- Secure client portal for scheduling, forms, and communication, helping patients stay engaged and informed throughout their care.
- [Scheduling tools](https://www.pluginhive.com/doctor-appointment-bookings-with-woocommerce/) with reminders and calendar syncing, which support organized appointment management and reduce missed visits.
- Documentation and billing tools that help clinics maintain accurate records, manage financial tasks, and support compliance needs.

![](https://www.atlantic.net/wp-content/uploads/2026/02/zoomhealth.png)

### 5. Zoom for Healthcare

[Zoom for Healthcare](https://www.zoom.com/en/products/collaboration-tools/solutions/healthcare/) is a secure version of the widely used video communication platform. It supports HIPAA compliance and offers strong video quality, which makes it suitable for virtual consultations across different specialties. Many clinics adopt it because patients are already familiar with the interface, which reduces onboarding challenges. The platform integrates with major EHR systems and supports group visits, making it useful for therapy groups and educational sessions. In addition, Zoom for Healthcare provides reliable performance during high-volume periods, which is important for clinics that depend on stable video communication.

#### Features

- End-to-end encryption for video and messaging, which protects communication during sessions and supports privacy requirements.
- EHR and calendar integrations that help providers manage appointments, documentation, and scheduling in a more organized manner.
- Support for group visits, which is helpful for therapy groups, care coordination, and patient education activities.
- Simple patient access through secure links, reducing technical barriers for individuals who are new to virtual care.

![](https://www.atlantic.net/wp-content/uploads/2026/02/vseehealth.png)

### 6. VSee Health

[VSee Health](https://vseehealth.com/) is a flexible telehealth platform used by clinics and health systems that require customizable workflows. It supports remote patient monitoring, device integrations, and advanced configuration options. Providers can adjust the platform to match their clinical processes, which makes it suitable for organizations with specialized needs. Moreover, VSee offers API access for deeper integrations with existing systems. This flexibility helps clinics build a telehealth environment that aligns with their operational goals and long-term digital strategy.

#### Features

- Customizable medical workflows that support different clinical processes and specialty requirements, allowing clinics to adapt the platform to their needs.
- Remote patient monitoring with device syncing, which helps providers track patient conditions more closely and respond when needed.
- EHR integration and API access for organizations that require advanced technical connections and deeper system interoperability.
- User-friendly interface that supports both patients and providers with simple navigation and clear layout.

![](https://www.atlantic.net/wp-content/uploads/2026/02/Spruce.png)

### 7. Spruce Health

[Spruce Health](https://sprucehealth.com/) is a communication platform developed for healthcare teams. It supports secure messaging, telehealth visits, and patient communication in one system. Many primary care and behavioral health clinics use it to manage calls, messages, and video visits more efficiently. The platform also includes tools for digital intake forms and team collaboration, which help reduce administrative workload. In addition, its mobile-friendly design allows patients to stay connected and engaged with their care, even when they are away from a computer.

#### Features

- Secure messaging and telehealth to support private communication and virtual visits across different clinical settings.
- Shared inbox for clinical teams, helping staff manage calls, messages, and tasks in a more organized and coordinated way.
- Digital intake forms that reduce paperwork, support efficient onboarding, and help maintain organized patient records.
- Mobile-friendly access that allows patients to communicate easily from their phones and stay engaged with their care.

## Security, Compliance, and HIPAA-Compliant Hosting

Telehealth platforms must protect ePHI during video sessions, messaging, and file exchange. However, the hosting environment also plays an important role in maintaining overall security. A HIPAA-compliant hosting provider protects ePHI at rest and supports stable system performance. Therefore, the environment must include encrypted storage, firewalls, intrusion monitoring, and regular backups. It must also support TLS 1.2 or TLS 1.3 to ensure secure data transmission across the network.

A reliable hosting environment reduces operational risk and supports regulatory compliance. It also helps telehealth platforms remain stable during busy periods or unexpected spikes in usage. For this reason, healthcare organizations must select hosting that meets HIPAA requirements and provides the safeguards needed to maintain a secure and dependable telehealth system.

## How We Support Telehealth Providers at Atlantic.Net

We provide HIPAA-compliant hosting that meets the security and performance requirements of telehealth applications. Our environment protects ePHI with encrypted storage, strict access controls, and advanced security safeguards that help reduce exposure to unauthorized access. In addition, we sign a BAA with every healthcare client. This agreement establishes shared responsibility for protecting sensitive information and confirms our commitment to regulatory compliance.

Our infrastructure supports TLS 1.2 and TLS 1.3 to ensure secure data transmission during video sessions, messaging, and file exchange. It also includes firewalls, intrusion detection, and continuous monitoring to identify unusual activity and respond to potential risks. Moreover, we provide regular backups and disaster-recovery options to support business continuity during unexpected events. These measures help telehealth providers maintain stable operations, even during periods of high demand. Our goal is to offer a secure and dependable hosting environment that supports the long-term reliability of telehealth services.

## Integration, File Sharing, and Behavioral Health Considerations

Telehealth platforms must support secure file sharing and digital intake forms because many clinics now collect patient information before appointments. Instead of paper forms or unsecured email attachments, compliant systems provide encrypted forms, consent documents, and questionnaires that patients complete online. These functions reduce administrative delays, limit manual data entry, and ensure that providers have the necessary clinical details at the start of each session. This creates a more organized workflow and helps clinics prepare for virtual visits in a consistent manner.

Behavioral health practices require even stronger safeguards due to the sensitivity of their records. Their workflows involve detailed notes, progress updates, and long-term treatment information, so platforms must include private communication channels, secure documentation, and granular access controls. Encrypted messaging, protected session notes, and controlled sharing of treatment plans help clinicians maintain confidentiality while coordinating care with patients and, when appropriate, caregivers or other professionals. These features support trust and continuity in therapeutic relationships.

Organizations with multiple locations also depend on telehealth platforms that support team collaboration and consistent workflows across sites. Role-based permissions, shared calendars, and centralized patient records help clinicians and staff work from the same information, whether a visit is virtual or in person. This reduces duplication of effort, supports coordinated care, and helps maintain operational efficiency across different practice locations.

When these integration and file-sharing capabilities operate within a HIPAA-compliant hosting environment, every document, form, and message remains protected at rest and in transit. This combination supports secure telehealth workflows and enables healthcare organizations to focus on patient care while relying on a stable and compliant technical foundation.

## The Bottom Line

Telehealth is now a standard part of healthcare delivery. Selecting a HIPAA-compliant telehealth platform is a vital decision for any healthcare organization. The right platform supports secure communication, protects ePHI, and fits daily clinical workflows.

Software alone is not enough. A secure and compliant hosting environment is also required to protect data at rest and during transmission. When both the platform and the hosting meet HIPAA requirements, organizations can reduce risk and improve reliability.


---

# Best Bare Metal Hosting for Predictable Performance

> URL: https://www.atlantic.net/dedicated-server-hosting/best-bare-metal-hosting/ | Updated: 2026-09-16

Compare bare metal, managed dedicated, and cloud servers to find the right balance of raw performance, operational support, scalability, and cost predictability for your workload.

- Single-Tenant Physical Server
- No Virtualization Overhead
- Direct Hardware Access
- 24/7 U.S.-Based Support

Virtualization overhead: None

Hardware support: 24/7

## Best Bare Metal Hosting Overview

There are three types of dedicated hosting offered by most managed service providers, giving businesses a wide choice when selecting the appropriate platform for their required workloads. They are bare metal hosting, dedicated cloud hosting, and shared cloud servers. Each model solves a different problem: raw performance, operational simplicity, or maximum flexibility.

Bare metal hosting is the best fit when you need maximum, consistent performance from a single-tenant physical server, especially for IO-intensive databases, GPU-accelerated AI/ML, real-time streaming, or ultra-low-latency workloads.

In these scenarios, the absence of a cloud hypervisor, direct access to hardware, and predictable resource isolation deliver better throughput and lower latency than a shared-hypervisor cloud server.

Managed dedicated hosting is more appropriate when you want similar performance but prefer the provider to handle OS, patching, backups, and monitoring. Cloud Servers are ideal when elastic scaling, managed services, and rapid experimentation matter more than absolute performance per node.

Why it matters: Choosing the right model affects not just speed, but how much control you have over kernels, drivers, and networking, as well as how predictable your monthly bill will be at steady load. Bare metal often wins on price/performance when utilization is high and relatively stable, while managed dedicated reduces operational burden at the cost of some control. Cloud servers tend to be more expensive at constant 24×7 utilization but pay off when workloads are bursty, experimental, or tightly integrated with higher-level services.

## Key Takeaways

### Bare metal = maximum performance and control, but you own operations.

Ideal for high IO, GPU, or low-latency workloads where you can justify heavier sysadmin investment.

### Managed dedicated trades control for convenience and support.

You still get single-tenant hardware, but the provider handles OS, patching, backups, and often monitoring

### Cloud Servers win when elasticity and managed services are critical.

Autoscaling, serverless components, and fully managed databases can offset server overhead in many application architectures.

### Provisioning times differ significantly.

Some bare metal SKUs can be delivered in minutes via automation, while custom builds may take hours or days; Cloud servers are deployed nearly instantly.

### Hardware features such as GPUs, high-speed NICs, SR-IOV, and DPDK can be decisive for AI and real-time workloads

These features are more predictable and tunable on bare metal than on highly abstracted cloud platforms.

### Cost predictability favors bare metal and managed dedicated at steady load.

Cloud is more variable: economical for short-lived or low-duty workloads, but often more expensive for 24×7 heavy usage.

### Operational overhead is the main trade-off.

The more control you want (custom drivers, non-standard OS choices), the more you move toward bare metal and away from fully managed cloud.

## What Is Bare Metal Hosting?

Bare metal hosting means renting a physical single-tenant server with no hypervisor layer embedded by the provider. You get direct access to the hardware (CPU, RAM, disks, NICs) and install your own operating system and stack. No other tenant shares that hardware, which helps eliminate noisy-neighbor issues and virtualization overhead for CPU, memory, and IO.

Managed dedicated hosting uses similar dedicated hardware but adds a service layer: the provider's operations team takes on responsibilities such as OS installation, security patching, performance monitoring, backup orchestration, and incident response. You still benefit from customer-dedicated hardware, but you don't need in-house experts for day-to-day administration. Cloud Servers sit at the other end of the spectrum. Virtual machines in public cloud share underlying hardware with other customers via a hypervisor. You gain instant provisioning, rich APIs, autoscaling, and access to a wide range of managed services, but you accept some performance overhead and less direct control over the physical layer.

## Benefits and Features of Bare Metal

Core Benefits

- Performance: With no provider-managed hypervisor, workloads get direct access to CPU instructions, memory bandwidth, and storage, which is especially important for databases, analytics engines, and GPU workloads.
- Kernel-level control: You can select and tune the exact OS, kernel version, and drivers you need, including real-time kernels, custom NUMA policies, and specialized GPU or NIC drivers.
- Predictable latency: Dedicated hardware and consistent IO paths reduce jitter, making bare metal attractive for trading systems, real-time bidding, VoIP, and gaming backends
- Isolation and security: Single-tenant systems minimize attack surface related to multi-tenant hypervisor exploits and side-channel issues, while simplifying certain compliance narratives (e.g., "no other customer shares the hardware").
- Cost efficiency at high utilization: When a node runs hot 24×7, the flat monthly pricing of bare metal often undercuts equivalent performance on per-hour cloud VMs.

## Technical Features to Look For

If you are in the market for bare metal hosting, it's important to understand the options available to you. It helps to focus on concrete capabilities rather than generic marketing terms:

- Modern CPUs and GPUs: Recent CPU families (e.g., AMD EPYC, Intel Xeon Scalable) with high core counts and large caches; GPU SKUs such as NVIDIA L-series, H-series, or similar accelerators for AI, graphics, and scientific computing.
- High-performance storage: NVMe SSDs for primary storage; optional RAID for redundancy; separate boot volumes; and explicit IOPS/throughput guarantees where possible.
- Advanced networking: 10-40 Gbit/s (or higher) NICs, with support for SR-IOV (Single Root I/O Virtualization) and DPDK (Data Plane Development Kit) for low-latency, high-throughput packet processing.
- Out-of-band management: IPMI, Redfish, or similar interfaces for remote console access, power cycling, and PXE boot, enabling fully automated provisioning and recovery.
- Automation and APIs: REST or CLI APIs for provisioning, reprovisioning, and lifecycle operations so you can integrate bare metal into Terraform, Ansible, or CI/CD workflows.

## Comparing Service Types

The table below summarizes how bare metal, managed dedicated, and cloud VMs typically compare. Actual offerings vary, but these patterns are common and this should give you a good idea of what to expect.

| Service Type | Ideal For | Isolation | Scaling | Performance | Management Level | Op Overhead | Cost Predictability |
| --- | --- | --- | --- | --- | --- | --- | --- |
| Bare Metal | High-IO databases, GPU/AI, low-latency trading, demanding game backends | High | Manual / Automated | Highest | Self-managed | Medium | High |
| Managed Dedicated | Steady SaaS, regulated workloads, teams with small infra staff | High | Planned | Very high | Provider-managed | Low-Medium | High |
| Cloud (VM) | Spiky workloads, experiments, dev/test, microservices with many dependencies | Medium | Elastic | Good / Variable | Provider-managed | Low | Variable |
| Summary | Bare metal prioritizes maximum performance and isolation with more operational effort; managed dedicated keeps high isolation while reducing day-to-day management; cloud VMs trade some isolation and predictability for elasticity and speed of provisioning. |  |  |  |  |  |  |

## Notes on practical differences:

### Provisioning SLAs:

Cloud VMs spin up in seconds. Bare metal ranges from "instant" pre-stocked SKUs to multi-day custom builds. Managed dedicated often sits in the middle, with standardized SKUs provisioned within hours.

### GPU availability:

GPU bare metal can be capacity-constrained; popular accelerator models sell out quickly. Cloud offers fractional or spot GPUs, but with potentially higher hourly costs and preemption risk.

### Support boundaries:

Self-managed bare metal usually includes hardware support and network connectivity only; the OS and apps are your responsibility. Managed dedicated broadens the scope to OS and often middleware. Cloud VMs typically include platform reliability but not your guest OS configuration unless you buy managed add-ons.

## Low Latency Database Transactions or Real-Time Bidding: Choose Bare Metal Hosting

Trading platforms, real-time bidding engines, and similar systems care about microseconds and jitter as much as raw throughput. Bare metal lets you pin cores, tune NIC queues, exploit SR-IOV/DPDK, and run custom kernels without the unpredictability of a shared hypervisor. Networking stacks and interrupt handling can be tuned aggressively, which is harder to achieve on generalized cloud infrastructure.

## Steady SaaS with a Lean Operations Team: Choose Managed Dedicated

A subscription SaaS product with stable, 24×7 traffic often values reliability and predictable costs more than absolute peak performance. Managed dedicated hosting is a good fit here: you get single-tenant performance, but the provider's team handles OS-level operations, patching, and backups. This model keeps the infrastructure footprint understandable without requiring you to build a full in-house SRE or platform team.

## Unpredictable, Experiment-Heavy Workloads: Choose Cloud Servers

Early-stage products, experimentation with new architectures, or workloads tied to many managed services (queues, serverless, managed databases) tend to thrive in the cloud. Elastic scaling, regional diversity, and quick teardown give you optionality. Cloud servers are also ideal when you need to frequently recompose services, test different instance sizes, or integrate tightly with PaaS components.

## Costs, Performance, and Risk Trade-Offs

Financially, bare metal and managed dedicated feel closer to capex-like commitments even when paid monthly. You usually commit to specific servers for at least one billing period, sometimes longer for discounted terms.

Technically, bare metal gives the best single-node performance and the most control over IO paths, but it demands more skills in automation, configuration management, and observability. You will likely invest in tools such as Terraform, Ansible, Prometheus, and centralized logging to get cloud-like operability.

Risk concentrates differently across models. With bare metal, hardware failures, misconfigurations, and slow redeploys are your primary risks, mitigated by redundancy and tested runbooks. In managed dedicated, you partially outsource that risk to the provider's SLA and support processes. In cloud, you inherit platform risk (regional outages, noisy neighbors) but gain rapid failover and scale-out patterns, provided your architecture is designed for it.

## Introducing Atlantic.Net Bare Metal & Managed Options

Atlantic.Net is a provider of Bare Metal hosting that implements the very latest high-performance hardware from Intel and AMD, with modern automation and U.S.-based 24/7 responsive support.

Our Bare Metal Hosting typically includes:

### Rapid provisioning speed:

Standard bare metal SKUs that can be delivered in minutes to a few hours via API, with clear SLAs for both standard and custom configurations.

### GPU and NIC portfolios:

GPU options suitable for training and inference, plus high-bandwidth NICs that support SR-IOV/DPDK for packet-intensive workloads such as firewalls, proxies, or real-time analytics.

### Multiple service tiers:

Atlantic.Net offers various service tiers to match our dedicated and bare metal hosting plans.

- Self-managed bare metal for users that want full control.
- Managed dedicated plans where Atlantic.Net handles OS patching, backups, and monitoring.
- Optional advisory or professional services for migrations and performance tuning.

### Global data centers:

Facilities in strategically chosen metros to minimize latency to key markets, with options for private connectivity and compliance-aligned locations.

### Compliance and security posture:

Clear documentation for certifications, data handling, and segmentation, plus security-first defaults (e.g., restricted management interfaces, hardened base images).

## Bare Metal Hosting FAQ

### What's the difference between bare metal and a dedicated server?

The terms are often used interchangeably, but in practice "bare metal" usually emphasizes a self-managed, single-tenant physical server with no provider-installed hypervisor: you bring the OS and operate it yourself. "Dedicated server" is the broader umbrella that includes both self-managed bare metal and provider-managed dedicated hardware (where the host installs the OS, patches, and monitors). On Atlantic.Net you can take either path on the same underlying hardware.

### When is bare metal faster than a cloud VM?

Bare metal generally outperforms a comparable cloud VM whenever the workload is bottlenecked on the parts of the stack that a hypervisor abstracts: CPU instructions (especially with AVX-512 or specialized GPU work), high-IOPS NVMe access, predictable low-latency networking (SR-IOV, DPDK, kernel-bypass), and any workload sensitive to jitter or noisy neighbors. Steady-state databases, real-time bidding, AI/ML training, and financial-trading backends are the canonical wins. For bursty or microservice-heavy workloads dominated by network round-trips between managed services, the gap is smaller.

### How quickly can I get a bare metal server provisioned?

Standard, in-stock SKUs from Atlantic.Net are typically provisioned in minutes to a few hours via API, comparable to managed dedicated. Custom builds (specific GPU models, non-standard NIC configurations, or hardened images for compliance scopes) may take hours to a few days depending on parts availability and configuration review. If timing matters for your launch, we'll confirm an SLA for your configuration up front.

### Is bare metal cheaper than cloud at scale?

For 24×7 steady-state workloads, bare metal is usually meaningfully cheaper than the equivalent cloud VM: you're paying flat monthly pricing for the whole machine instead of an hourly rate that bakes in the cloud provider's overhead and managed-services premium. The breakeven shifts when workloads are bursty, short-lived, or tightly integrated with managed cloud services (queues, serverless, managed databases) where rebuilding the equivalent on bare metal would cost more in operational time than it saves in instance pricing.

### Can I run GPU workloads on Atlantic.Net bare metal?

Yes. Atlantic.Net offers GPU SKUs suitable for both training and inference, with modern NVIDIA accelerators and high-bandwidth interconnects. Because GPU bare metal gives you the full card with no virtualization tax, it's a good fit for sustained training or production inference where consistent throughput matters more than elastic scaling. For bursty experimentation or single-job training, fractional GPU cloud may be a better fit: talk to our solutions architects to scope the right option for your workload.

### What's included with self-managed bare metal vs managed dedicated?

Self-managed bare metal includes the hardware, datacenter facilities, network connectivity, IPMI/Redfish out-of-band management, and 24×7 hardware support: your team is responsible for the OS, patching, application monitoring, backups, and day-2 operations. Managed dedicated keeps the same single-tenant hardware but adds Atlantic.Net's operations team handling OS installation, security patching, system monitoring, and backup orchestration. Optional layers on either model include managed firewall, IDS/IPS, MFA, encrypted VPN, and SIEM integration.

### Can bare metal hosting support PCI DSS or HIPAA compliance?

Yes. Atlantic.Net's audited platform supports PCI DSS v4.0.1 and HIPAA/HITECH workloads on bare metal. Single-tenant hardware naturally simplifies many compliance narratives ("no other customer shares this physical server"), and the rest of the control set (segmentation, encryption, MFA, logging, hardening, BAA execution where applicable) sits on top of the underlying hardware. Documentation packages (AOCs for PCI, SOC 2 Type II + SOC 3 + HIPAA/HITECH attestations) are available on request.

### How do I migrate from cloud VMs to bare metal?

Most migrations follow a standard arc: benchmark your current workload to set a concrete performance target, pick a bare metal SKU sized to hit it (with headroom for growth), use Terraform/Ansible (or your existing IaC) to reproduce the runtime stack on the new host, run side-by-side with traffic shadowed or split between cloud and bare metal, validate, then cut over. Atlantic.Net offers advisory and professional services to help with the benchmarking, sizing, and cutover steps.

## How to Get Started with Atlantic.Net

Want to learn more about our Bare Metal Hosting platform? Take some time to consider your requirements and get in touch with our talent team to learn more.

Some important considerations should include:

### 1. Understand your workload profile

Identify whether you are optimizing for low latency, high throughput, GPU acceleration, or predictable SaaS-style traffic. Note any additional compliance needs or specific regions you would like to target.

### 2. Choose a service model

- Select Bare Metal if you want full control and have in-house expertise.
- Choose Managed Dedicated if your team prefers to focus on the application layer.

### 3. Select a reference configuration

Use Atlantic.Net's sizing guides to map required core counts, RAM, storage (NVMe/RAID), GPU requirements, and network bandwidth to recommended SKUs.

[Sizing guides](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/)

### 4. Engage support and sales engineering

For new deployments, schedule a short architecture review or migration workshop. This ensures that choices around network design, IP addressing, and failover align with your uptime and compliance targets.

### 5. Commit once validated

Once your configuration is validated, move to reserved or longer-term commitments where appropriate to lock in better price/performance.

Choosing between bare metal, managed dedicated, and cloud is ultimately about aligning your infrastructure with how your applications behave in the real world. If you run steady, performance-sensitive workloads or GPU-driven AI, bare metal and managed dedicated give you the control, predictability, and throughput that generalized cloud platforms often struggle to match.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Top PCI-Compliant Cloud Services for Startups (2026)

> URL: https://www.atlantic.net/pci-compliant-hosting/pci-compliant-cloud-services-for-startups-2026/ | Published: 2026-02-13 | Updated: 2026-06-23 | Author: Dr. Assad Abbas

Startups that store, process, or transmit payment card data must comply with the [Payment Card Industry Data Security Standard (PCI DSS v4.0)](https://www.atlantic.net/pci-compliant-hosting/what-is-pci-compliance/) regardless of company size. Even a single transaction can bring systems into PCI scope. Early compliance planning becomes important for long-term stability and customer trust.

In recent years, security incidents have increased significantly, and many have involved exposed payment information. When a startup experiences such an incident, the financial impact can be serious. However, the loss of customer confidence often causes even more lasting damage. For this reason, [PCI DSS](https://www.atlantic.net/pci-compliant-hosting/pci-dss-4-0-is-mandatory-a-hosting-checklist-for-2026/) has become a baseline expectation for any business that accepts card payments rather than an optional enhancement.

Due to these risks, many startups now look for safer and more structured environments. A PCI-compliant cloud service becomes an important part of their security planning. It can reduce the technical burden by offering structured security controls, hardened system configurations, and support during audit preparation. At the same time, it helps early-stage teams avoid configuration mistakes that often lead to compliance problems.

PCI DSS follows a shared responsibility model. The provider protects the underlying infrastructure, while the startup must configure its workloads correctly, manage access controls, and maintain internal policies and procedures. Both sides must work together to maintain a compliant environment and support a stable payment system.

## Understanding PCI Scope Before Choosing a Cloud Provider

Before selecting a hosting provider, startups should clearly understand PCI scope.

The **Cardholder Data Environment (CDE)** includes:

- Systems that store cardholder data
- Systems that process cardholder data
- Systems that transmit cardholder data
- Systems connected to those systems

Scope expands easily if environments are not segmented properly.

Startups can reduce scope by:

- Using hosted payment pages
- Implementing tokenization
- Avoiding card storage entirely
- Isolating payment services in segmented networks

These architectural decisions may allow validation under lighter Self-Assessment Questionnaires (SAQs) such as SAQ A or SAQ A-EP rather than SAQ D.

Choosing a provider without first defining scope often leads to unnecessary compliance overhead.

## PCI Compliance vs General Cloud Security

Cloud security and [PCI compliance](https://www.atlantic.net/pci-compliant-hosting/pci-compliance-in-the-cloud-challenges-and-key-requirements/) are related but not identical.

A secure system may still fail a PCI audit if it lacks required documentation and evidence.

PCI DSS requires:

- One year of log retention (three months immediately available)
- Daily log review
- Quarterly external ASV scans (if publicly accessible)
- Internal vulnerability scans
- Annual penetration testing
- Formal policies and procedures

Compliance is about demonstrable, repeatable controls — not just technical strength.

## Core PCI DSS Requirements Startups Must Understand

PCI DSS defines twelve main requirements that guide how payment systems should be designed and operated. They create the basic structure of a secure environment, and startups need to understand them early to avoid problems later.

- Firewalls must be in place and configured in a secure way to protect the network

- Default passwords and default system settings must be replaced with stronger options

- Stored cardholder data must be protected with encryption and limited access

- Cardholder data must be encrypted during transmission with secure protocols such as TLS 1.2 or TLS 1.3

- [Anti-malware](https://www.atlantic.net/vps-hosting/antivirus-vs-anti-malware-whats-difference/) tools must be used, and they must receive regular updates

- Systems must receive patches and vulnerability fixes to reduce security risks

- Access to cardholder data must follow job responsibilities and be limited to what is necessary

- Strong authentication methods, including multi-factor authentication, must be used for sensitive access

- Physical access to systems that handle card data must be controlled and monitored

- All access to the Cardholder Data Environment must be logged and reviewed

- Security controls must be tested regularly through scans and [penetration testing](https://www.atlantic.net/vps-hosting/best-penetration-testing-practices-you-need-to-know/)

- Clear security policies must be documented, communicated, and followed by staff

## Why Startups Use PCI-Compliant Cloud Services

Many startups choose [PCI-compliant cloud services](https://www.atlantic.net/pci-compliant-hosting/pci-compliant-cloud-services-for-startups-2026/) because the operational requirements of PCI DSS can be difficult to manage with small teams. A structured platform helps reduce this pressure by offering secure configurations, standard documentation, and a predictable environment.

This support makes audit preparation easier, since evidence is better organized and Qualified Security Assessors (QSAs) can review it with fewer delays. As a result, compliance projects typically move forward more smoothly.

Managed PCI platforms also help reduce common mistakes that often lead to security issues, such as misconfigured [firewalls](https://www.atlantic.net/managed-services/firewall/) or incomplete logging. Banks, insurers, and business partners frequently ask for proof of proper security, so a compliant environment can support early-stage business discussions.

PCI compliance also supports long-term growth. When the hosting environment scales with transaction volume, the startup avoids large architectural redesigns later. Early decisions about [PCI-compliant hosting](https://www.atlantic.net/pci-compliant-hosting/), therefore, play an important role in future stability.

## How to Choose a PCI-Compliant Cloud Provider

Choosing a PCI-compliant cloud provider becomes easier when the evaluation follows a clear structure. Since PCI DSS creates both technical and operational demands, the provider must support these areas in a balanced way.

### Security architecture and controls

A strong security foundation is essential. The provider should offer encryption, firewalls, intrusion detection, and clear network segmentation. When the PCI environment is well isolated, the audit process becomes easier.

### Compliance program and audit support

Compliance requires organized documentation. The provider should maintain required reports, including an Attestation of Compliance (AOC), and make them accessible upon request. Guidance from compliance specialists can help startups avoid mistakes during audits.

### Operational fit for the team

Startups work with different levels of internal capacity. Some teams prefer [managed services](https://www.atlantic.net/managed-services/) that reduce daily workload, while others choose self-managed options for greater control. The right choice depends on internal expertise and available time.

### Cost and scalability considerations

Pricing models vary across providers. Some charge per resource, while others include compliance features within structured plans. Understanding the full pricing model from the beginning helps avoid unexpected costs as the system grows.

## Top PCI-Compliant Cloud Services for Startups in 2026

### Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

[Atlantic.Net](https://www.atlantic.net) provides a PCI compliant hosting environment designed for startups that need a secure and organized platform for payment processing. The service reduces the workload on small teams by offering structured configurations, continuous monitoring, and clear documentation. The engineering team helps clients understand their responsibilities and prepare for assessments. In addition, the infrastructure supports cloud, dedicated, and hybrid deployments, which helps startups choose a model that fits their growth stage. The goal is to offer a stable and compliant foundation that supports safe handling of cardholder data.

- Atlantic.Net offers a pre-secured PCI environment that follows strict configuration standards, including segmentation and controlled access, which reduces the work required for the startup
- Continuous monitoring and intrusion detection are part of the Atlantic.Net environment, helping the team notice unusual activity early and supporting the reporting needed for PCI compliance
- The provider offers audit-ready documentation and guidance, including structured evidence and diagrams that support QSA reviews
- Flexible deployment models across cloud, dedicated, and hybrid environments enable startups to choose the setup that fits their workload and future growth

### Rackspace Technology

![](https://www.atlantic.net/wp-content/uploads/2025/12/rackspace_logo.png)

[Rackspace Technology](https://www.rackspace.com/) offers a managed PCI-friendly hosting service that supports startups that want to reduce operational tasks. Their team manages the infrastructure, security controls, and monitoring, so startups can focus on their applications instead of system maintenance. Rackspace also provides guidance during compliance reviews, which is helpful for companies that do not have internal security staff. Their experience with hybrid and multi-cloud environments supports teams that need a mix of hosting models.

- Rackspace provides continuous security operations with a team that reviews alerts and supports incident response, which helps maintain a stable environment
- Their PCI-ready configurations include secure network designs, access controls, and logging, reducing the internal workload for the startup
- The provider offers compliance assistance with documentation and guidance that helps startups prepare for QSA interviews and evidence requests
- Support for hybrid and multi-cloud environments helps teams design setups that combine different platforms when needed

### Kamatera

![](https://www.atlantic.net/wp-content/uploads/2025/12/kamatera-logo-1.png)

[Kamatera](http://www.kamatera.com) provides a flexible [cloud platform](https://www.atlantic.net/cloud-platform/) that can support PCI-friendly architectures when configured correctly. Their infrastructure is known for high performance and global availability. Startups can deploy custom server configurations and adjust resources as needed, which helps teams that want more control over their environment. However, the startup must configure the PCI controls on its own. Kamatera is suitable for companies that have some technical experience and want a cost-efficient cloud option.

- Customizable server configurations give startups the flexibility to choose CPU, RAM, and storage settings that match PCI-related needs and performance goals
- Kamatera offers a global data center presence, which supports low-latency deployments and geographic redundancy for different markets
- The platform is designed for high uptime and performance, supporting payment systems that must remain available
- Cost-efficient scaling helps startups adjust resources at any time and manage expenses during early growth stages

### Scala Hosting

![](https://www.atlantic.net/wp-content/uploads/2025/12/scala-hosting.jpg)

[Scala Hosting](https://www.scalahosting.com/) offers managed VPS environments that can support PCI-friendly setups when configured correctly. Their SPanel platform simplifies server management and reduces the need for manual configuration. This is helpful for startups that do not have large technical teams. The hosting environment includes strong isolation and monitoring features, which support secure payment applications. Scala Hosting becomes a practical option for small and mid-sized companies that want a balance of cost and security.

- Managed VPS with strong isolation helps separate workloads and supports a safer environment for sensitive data
- The SPanel management platform simplifies updates, access control, and monitoring, reducing operational effort
- Security-focused features such as firewalls, malware scanning, and automated updates support PCI-friendly operations
- Affordable pricing structures help startups maintain a secure environment without high monthly costs
- expenses during early growth stages

### Amazon Web Services (AWS)

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

[AWS](https://aws.amazon.com/) supports PCI-compliant cloud environments that can host sensitive payment workloads when configured according to the required controls. The platform offers a wide range of services that meet PCI DSS Level 1 standards, which helps startups build secure and scalable architectures. AWS provides detailed documentation, shared responsibility guidance, and tools that support monitoring, logging, and network isolation. Startups can design environments that match their technical skills while keeping compliance requirements in mind. The flexibility of the platform makes it suitable for teams that expect rapid growth or need global availability.

- AWS offers PCI-eligible services across compute, storage, networking, and databases, which helps startups build a compliant cardholder data environment when needed
- Network segmentation, security groups, and managed firewalls support controlled access and help reduce the PCI scope for different workloads
- Monitoring and logging tools such as CloudTrail, CloudWatch, and GuardDuty support continuous visibility and help teams prepare evidence for compliance reviews
- Global infrastructure across multiple regions allows startups to deploy applications close to their users and maintain redundancy without redesigning their environment

## Practical PCI Implementation Tips for Startups

Startups should begin PCI work by defining the scope of the cardholder data environment. This includes mapping every system, service, network segment, and data flow that stores, processes, or transmits cardholder data, including third-party integrations. A smaller and well-isolated environment reduces audit complexity and makes it easier to apply controls consistently. Techniques such as network segmentation, environment isolation, and least-privilege access help keep the scope controlled and easier to manage.

Once the scope is clear, it becomes important to standardize the deployment model through infrastructure as code. Tools such as Terraform or CloudFormation enable teams to build repeatable, version-controlled environments instead of relying on manual configuration. This supports consistent application of firewalls, security groups, encryption settings, and logging across all PCI-in-scope resources. Centralized logging should also be part of this model. Routing logs from application servers, databases, load balancers, and cloud services into a single platform with retention and alerting supports real-time monitoring and provides the evidence auditors expect for PCI logging requirements.

Working with a QSA early in the process helps avoid rework and surprises during the audit. A QSA can validate scope assumptions, review diagrams, and confirm that control choices align with PCI DSS requirements. They typically review architecture diagrams, data-flow diagrams, configuration samples, vulnerability scan results, logs, and written policies. A strong cloud provider simplifies this engagement by supplying attestations of compliance, detailed security documentation, and clear descriptions of shared responsibility, which makes it easier to demonstrate a well-designed and PCI-aligned environment.

## Common PCI Compliance Mistakes

Many startups assume that choosing a PCI-compliant provider covers all remaining obligations. In practice, the provider secures the underlying infrastructure, while your team must still manage application security, configuration choices, user access, and internal processes. When PCI is treated as something fully handled by the host, gaps often appear in areas such as input validation, key management, logging, and incident response.

Another frequent issue is viewing PCI as a one-time project instead of an ongoing practice. PCI DSS expects continuous security operations, including regular vulnerability scanning, prompt patching of operating systems and dependencies, and periodic penetration testing. When scans happen only before an audit or patches are delayed for long periods, the environment gradually loses its required security posture and becomes more exposed to attacks.

Weak access control also creates problems for many startups, and it often appears after the earlier issues with scope and patching. When teams rely on shared admin accounts, skip [multi-factor authentication](https://www.atlantic.net/managed-services/multi-factor-authentication/), or grant broad permissions, the environment becomes harder to monitor and secure. These gaps conflict with PCI requirements and make it difficult to maintain a predictable security posture.

Strong identity and access management help address these weaknesses. Enforcing least privilege roles, requiring MFA for administrative and remote access, rotating credentials regularly, and logging all privileged actions all contribute to a more controlled environment. When these access practices work together with consistent monitoring, timely patching, and solid application security, startups move toward a more stable and sustainable form of PCI compliance instead of a fragile, audit-focused posture.

## Final Thoughts

Choosing a PCI-compliant cloud provider is an important step for any startup that handles payment card data. The decision influences security, trust, and long-term stability.

A suitable provider offers structured infrastructure, clear documentation, and support during audits. At the same time, the shared responsibility model remains central, since the provider protects the infrastructure while the startup manages configurations, access controls, and operational processes.

PCI compliance continues beyond initial deployment. As the startup grows, the environment must remain secure through regular monitoring, timely patching, and consistent operational discipline. When these responsibilities are clearly understood, startups can build a stable and compliant foundation that supports sustainable growth.

 


---

# PCI-Compliant Hosting with Vulnerability Scanning (2026)

> URL: https://www.atlantic.net/pci-compliant-hosting/pci-hosting-vulnerability-scanning-2026/ | Published: 2026-02-14 | Updated: 2026-06-23 | Author: Dr. Assad Abbas

Payment card data is a common target for attackers, and this risk affects organizations of different sizes. The [Payment Card Industry Data Security Standard (PCI DSS)](https://www.pcisecuritystandards.org/standards/) provides this structure and defines how companies should protect cardholder data in 2026 and beyond This link between the standard and the hosting environment is important because technical controls depend on the platform that supports payment systems.

In addition, vulnerability scanning helps identify weaknesses before attackers use them. [PCI DSS v4.0](https://www.atlantic.net/pci-compliant-hosting/pci-dss-4-0-is-mandatory-a-hosting-checklist-for-2026/) strengthens vulnerability management requirements, including authenticated internal scans that provide deeper visibility into system configurations and patch levels. Selecting hosting providers that support strong vulnerability scanning and clear reporting is an important step in maintaining a secure payment environment.

## Understanding PCI Hosting Before Choosing a Provider

Before comparing hosting providers, it is important to understand what [PCI-compliant hosting](https://www.atlantic.net/pci-compliant-hosting/) actually requires and how vulnerability scanning fits into a secure payment architecture.

### What Is the Cardholder Data Environment (CDE)?

The Cardholder Data Environment (CDE) includes all systems that store, process, or transmit cardholder data, as well as any systems connected to them. This means:

- Web servers handling checkout pages
- Application servers processing transactions
- Databases storing payment information
- Supporting systems connected to those components

Because PCI DSS applies to everything within scope, proper segmentation is critical. Reducing scope lowers compliance overhead and minimizes risk exposure.

## How PCI Compliance Applies to Modern Hosting

PCI DSS applies to all organizations that store, process, or transmit cardholder data. Its role has become more significant as payment systems increasingly rely on online platforms, mobile applications, APIs, and external service providers. Each added component increases the exposure of sensitive information. Organizations must maintain a secure environment that consistently protects payment data.

Vulnerability scanning supports this goal by identifying weaknesses early. Regular scanning also strengthens trust among customers and payment partners because it demonstrates an active approach to protecting payment information.

The standard defines requirements for:

- Network security
- Segmentation
- Access control
- Encryption
- Logging and monitoring
- Incident response

These elements work together to limit unauthorized access to payment systems. PCI DSS v4.0 emphasizes continuous security processes rather than occasional checks. This expectation applies equally to hosting environments, which provide the technical foundation for payment applications and related systems.

PCI-compliant hosting refers to infrastructure configured to support PCI DSS technical requirements. The hosting provider typically manages physical security, infrastructure-level controls, and baseline hardening. However, the merchant remains responsible for application security, user access management, logging review, and daily operational processes. This shared responsibility model clarifies which tasks belong to each party.

Importantly, PCI DSS does not “certify” hosting providers. Providers may maintain a PCI DSS Service Provider Attestation of Compliance (AOC), but compliance ultimately depends on how the customer configures and maintains its specific environment.

## Shared Responsibility in PCI Hosting

PCI compliance is never “outsourced” entirely to a hosting provider. Even if a provider maintains a PCI DSS Service Provider Attestation of Compliance (AOC), customers remain responsible for:

- Application security
- Secure coding practices
- User access control
- Log review and incident response
- Vulnerability remediation

Hosting providers typically manage:

- Physical data center security
- Core infrastructure hardening
- Network controls
- Hypervisor and hardware security

Understanding this shared-responsibility model prevents compliance gaps.

## PCI DSS Scanning Requirements and Key v4.0 Updates

PCI DSS requires organizations to perform:

- Quarterly external vulnerability scans by an Approved Scanning Vendor (ASV)
- Quarterly internal vulnerability scans
- Annual penetration testing
- Testing after significant changes
- Ongoing monitoring of security controls

These activities help identify weaknesses in systems and networks and provide a structured approach to maintaining security in environments that handle cardholder data.

Internal scans examine systems within the firewall, including hosts, containers, and applications. External scans assess public-facing systems and exposed services. Both types of scans must be performed every quarter and after significant changes, such as infrastructure modifications or major application updates.

External scans must be conducted by an ASV. To pass an ASV scan, organizations must not have failing vulnerabilities, typically defined using CVSS scoring thresholds established by the [PCI Security](https://www.atlantic.net/pci-compliant-hosting/pci-security-services/) Standards Council. Internal scans may be performed by qualified internal staff or external specialists.

Vulnerability scanning uses automated tools to detect known issues, which provide a broad overview of potential risks. Penetration testing combines manual and automated techniques to determine whether vulnerabilities can be exploited. PCI DSS also requires segmentation testing if segmentation is used to reduce the scope of the Cardholder Data Environment (CDE).

PCI DSS v4.0 strengthens internal vulnerability scanning by introducing authenticated scanning expectations. Authenticated scans provide deeper insight into system configurations, installed software, and patch levels. Credentials used for scanning must be handled securely. After remediation, rescans must confirm that vulnerabilities have been resolved.

The updated standard also expands requirements for e-commerce environments and merchants completing the Self-Assessment Questionnaire (SAQ). For example, payment pages must be monitored for tampering under Requirement 11.6.1, and unauthorized script changes must be detected. These measures reduce the risk of skimming and Magecart-style attacks.

Organizations must choose hosting providers that support authenticated scanning, provide detailed reporting, and offer clear segmentation options. Providers should also offer guidance on remediation and scan preparation to help customers maintain compliance under PCI DSS v4.0.

## How to Evaluate a PCI-Compliant Hosting Provider

Choosing the right hosting provider is important for maintaining [PCI compliance](https://www.atlantic.net/pci-compliant-hosting/pci-compliance-in-the-cloud-challenges-and-key-requirements/). Therefore, several factors should be considered to ensure the provider can support secure and reliable operations.

### Mandatory PCI and Security Capabilities

A suitable provider should support internal and external vulnerability scanning for all systems within the cardholder data environment. Secure network segmentation is essential because it limits exposure if a system is compromised.

Providers should also support or facilitate:

- Annual penetration testing
- Segmentation validation testing
- Log retention aligned with PCI requirements
- Access control enforcement

These capabilities strengthen an organization’s overall security posture.

### Security Features That Strengthen PCI Compliance

Strong providers implement:

- Firewalls
- Intrusion detection systems (IDS)
- Encryption for data in transit and at rest
- Role-based access controls
- Centralized logging with continuous monitoring

Together, these controls support PCI DSS technical requirements and improve the detect-and-respond cycle for suspicious activity.

### Operational and Support Considerations

Organizations should consider uptime guarantees, scalability options, and 24/7 support availability. Clear documentation, structured reporting, and audit-friendly logs simplify compliance validation during assessments.

Providers that can supply compliance documentation, such as an Attestation of Compliance (AOC) or supporting audit artifacts, can significantly reduce preparation time during a Report on Compliance (ROC) or SAQ review.

## Top PCI Hosting Providers with Vulnerability Scanning in 2026

The following providers offer PCI-aligned hosting environments with built-in or supported vulnerability scanning, suitable for businesses of all sizes.

## Premium Enterprise & Managed Security Providers

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

### Atlantic.Net

[Atlantic.Net](https://www.atlantic.net) provides hosting environments designed to support organizations that must align with the PCI DSS. The platform includes secure configurations, controlled access, and clear segmentation options for cardholder data environments. Atlantic.Net supports both internal and external vulnerability scanning, which helps organizations maintain a stable security posture throughout the year. Its cloud, virtual private servers, and dedicated servers can be adjusted to meet PCI aligned requirements. The support team remains available at all times to assist with documentation, remediation planning, and configuration guidance, which helps organizations maintain a secure environment for payment data.

#### *Key Features*

- Atlantic.Net provides integrated vulnerability scanning support that includes internal and external scanning options aligned with PCI DSS expectations
- Segmented hosting environments are available through Atlantic.Net cloud, virtual private server, and dedicated configurations that support cardholder data isolation
- The platform supports TLS 1.2 and TLS 1.3 [encryption](https://www.atlantic.net/hipaa-compliant-hosting/encryption-for-hipaa-compliance/) to protect sensitive information during communication between systems
- Atlantic.Net offers compliance aware support at all times to assist with remediation steps, documentation, and audit preparation

![](https://www.atlantic.net/wp-content/uploads/2025/12/rackspace_logo.png)

### Rackspace

[Rackspace](http://www.rackspace.com) offers managed hosting environments that support PCI DSS requirements through hardened infrastructure, controlled network segmentation, and continuous monitoring. The service is designed for organizations that prefer a fully managed operational model with strong security oversight. Rackspace provides guidance for vulnerability scanning and remediation, which helps customers maintain a consistent compliance posture. Its managed security operations center monitors systems throughout the day and responds to potential issues. This approach is suitable for organizations that require a hosting provider with strong operational involvement and structured support for payment related workloads.

#### *Key Features*

- Rackspace offers managed PCI hosting environments that include secure configurations and segmentation controls for cardholder data
- The provider supplies vulnerability scanning and remediation guidance that helps organizations identify issues and plan corrective actions
- Rackspace manages firewall and [intrusion detection systems](https://www.atlantic.net/dedicated-server-hosting/what-is-an-intrusion-detection-system-and-why-do-i-need-it/) to reduce exposure to unauthorized access attempts
- Continuous monitoring is performed by Rackspace security operations teams that observe system activity and respond to potential threats

## Large-Scale Cloud Infrastructure Providers

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

### Google Cloud

[Google Cloud](https://cloud.google.com/) provides a global infrastructure that supports workloads aligned with PCI DSS requirements. Therefore, the platform includes strong security controls, automated monitoring, and detailed audit reporting for organizations that handle payment data. In addition, its security-first approach supports payment processing environments that operate at scale.

Google Cloud Security Command Center offers centralized visibility into vulnerabilities and configuration issues across cloud resources. As a result, organizations can address security risks in a timely way. Moreover, the platform includes network protection features that help maintain service availability during high traffic or attack conditions. Consequently, these characteristics make Google Cloud suitable for organizations that need a secure and high-performance environment for payment systems and related applications.

#### *Key Features *

- Google Cloud provides PCI validated infrastructure across global data centers, which supports geographically distributed payment workloads
- Security Command Center offers centralized insight into vulnerabilities, configuration issues, and potential threats across Google Cloud resources
- Network protection features in Google Cloud help reduce service disruptions during attack attempts and support stable access to payment applications
- Automated compliance reporting tools support audit preparation and help organizations produce documentation for assessments

## Flexible Mid-Range Scalable Cloud Providers

![](https://www.atlantic.net/wp-content/uploads/2025/12/kamatera-logo-1.png)

### Kamatera

[Kamatera](http://www.kamatera.com) provides flexible cloud servers that can be configured to support PCI DSS aligned environments. The platform includes strong access controls, customizable firewall rules, and optional integrations with vulnerability scanning tools. Kamatera operates global data centers that offer high performance and low latency, which supports stable payment applications. Its customizable approach gives organizations precise control over server resources and security settings based on their specific PCI requirements. These characteristics make Kamatera suitable for organizations that need detailed configuration options while maintaining alignment with PCI DSS expectations.

#### *Key Features*

- Kamatera provides flexible cloud configurations that support PCI aligned deployments and give organizations detailed control over system resources
- Optional scanning integrations in Kamatera environments support third party vulnerability scanning tools used for PCI assessments
- Global data centers operated by Kamatera deliver high performance infrastructure for responsive payment applications
- Configurable [firewalls](https://www.atlantic.net/managed-services/firewall/) in Kamatera environments support cardholder data isolation and reduce unnecessary exposure

## VPS & Budget-Friendly Hosting Providers

![](https://www.atlantic.net/wp-content/uploads/2025/12/scala-hosting.jpg)

### Scala Hosting

[Scala Hosting](http://www.scalahosting.com) provides virtual private server environments with security features that support PCI DSS alignment. Therefore, its SPanel management suite includes tools for scanning, monitoring, and managing server security. In addition, virtual environments are isolated to support segmentation. As a result, the risk of unauthorized access is reduced. Moreover, firewall and access control settings can be customized to meet PCI requirements. Consequently, Scala Hosting is suitable for small and medium sized businesses that need a secure and manageable environment for payment related workloads. At the same time, it avoids the complexity often associated with large scale cloud platforms.

#### *Key Features*

- The SPanel security suite in Scala Hosting environments provides tools for scanning, monitoring, and managing server security

- Scala Hosting offers isolated virtual environments that support segmentation and reduce the risk of unauthorized access

- Customizable firewall rules in Scala Hosting servers support PCI DSS requirements for restricted access

- Scalable [virtual private servers](https://www.atlantic.net/vps-hosting/virtual-private-cloud-server-a-comprehensive-guide/) from Scala Hosting support resource adjustments as transaction volume increases

![](https://www.atlantic.net/wp-content/uploads/2026/02/Kinsta_logo.png)

### Kinsta

[Kinsta](http://www.kinsta.com) uses a container-based architecture that supports strong isolation between environments, which makes it suitable for ecommerce platforms and payment aware workloads. The service includes malware scanning, security monitoring, and secure configurations that help maintain a stable security posture. Kinsta operates on Google Cloud data centers, so organizations benefit from consistent security controls and global availability. This combination of managed hosting, performance focused design, and continuous monitoring creates an environment that supports predictable operation for payment related systems. As a result, Kinsta is a practical option for organizations that want a managed platform with steady performance and clear security features.

#### *Key Features *

- Kinsta provides container-based isolation that separates environments and reduces the risk of cross site exposure
- Malware scanning and monitoring in Kinsta environments support PCI DSS expectations for identifying malicious activity
- Secure configurations offered by Kinsta support ecommerce and payment related workloads
- The global data center footprint used by Kinsta supports consistent performance across multiple regions

### ![](https://www.atlantic.net/wp-content/uploads/2025/08/Hostgator-logo.png)

### HostGator

[HostGator](http://www.hostgator.com) offers virtual private servers and dedicated servers that can be configured to support PCI DSS aligned environments. The platform includes security tools, firewall controls, and compatibility with third party scanning solutions. This compatibility helps organizations complete internal and external vulnerability scans required for PCI assessments. HostGator provides flexible hosting options that help organizations adjust resources based on transaction volume and security needs. Its support team remains available at all times to assist with hosting and security related issues. These characteristics make HostGator suitable for organizations that need adaptable infrastructure for payment processing.

*Key Features*

- HostGator provides configurable virtual private servers and dedicated servers that support PCI DSS expectations
- Third party scanning compatibility in HostGator environments supports external vulnerability scanning tools used in PCI assessments
- Firewall and access control settings offered by HostGator support restricted access to sensitive systems
- HostGator maintains support availability at all times to assist with hosting and security related issues

## Comparing PCI-Focused Hosting Options

Each category supports PCI-aligned operations differently:

- **Premium managed providers** reduce operational burden through security oversight and structured compliance support.
- **Large cloud platforms** offer automation and scale but require internal expertise to configure segmentation and scanning workflows correctly.
- **Mid-range scalable providers** offer flexibility and customization but demand careful documentation management.
- **VPS and budget providers** offer simplicity but may require additional preparation during formal PCI assessments.

The most appropriate hosting choice depends on internal expertise, compliance expectations, and desired provider involvement.

Different hosting models support PCI aligned operations in different ways. Therefore, each option tends to suit a specific organizational structure and compliance workflow. Because PCI DSS affects both technical controls and daily routines, these differences influence the long term stability of compliance efforts. Some services focus on managed security and continuous oversight, while others emphasize customization, scale, or simplicity.

Large cloud platforms such as Google Cloud introduce automation, global reach, and strong built‑in controls. However, they usually require steady internal expertise, particularly when teams must configure scanning workflows, segmentation, and monitoring tools on their own. Therefore, these platforms are more suitable for organizations that already have technical maturity and want to place PCI workloads inside broader cloud strategies.

Managed providers such as Rackspace concentrate on operational involvement. They guide vulnerability scanning, remediation, and monitoring tasks, which reduces the internal burden on customers. This approach is helpful for organizations that prefer predictable workflows and structured assistance. Yet the high level of management may feel restrictive for teams that want direct control over system settings and security decisions.

Customizable cloud environments such as Kamatera offer detailed configuration options and global performance. As a result, they are useful for organizations that want precise control over server resources and scanning integrations. Still, this flexibility requires careful planning, particularly when teams must prepare their own documentation and segmentation evidence for audits.

VPS oriented providers such as Scala Hosting and HostGator present straightforward environments with clear segmentation and manageable configurations. These services are often practical for small and medium-sized businesses that want simplicity without the complexity of large cloud ecosystems. However, they may require more attention during assessments, when scanning workflows or reporting tools are not fully integrated.

Within this context, Atlantic.Net appears as a balanced option. Its environments are accessible for smaller teams while still offering structured support for vulnerability scanning, segmentation, and compliance documentation. Because the platform avoids unnecessary complexity, organizations can maintain PCI aligned operations with greater confidence. Moreover, the availability of cloud, virtual private servers, and dedicated servers supports a wide range of payment workloads. Taken together, this mix of clarity, support, and technical flexibility offers stability without reducing operational control.

Overall, the most appropriate hosting choice depends on internal expertise, compliance expectations, and the desired level of provider involvement. Therefore, careful evaluation of these factors helps organizations select an environment that supports both security and long term operational confidence.

### Checklist for Selecting PCI Hosting with Vulnerability Scanning

- Alignment with the PCI DSS, including clear shared‑responsibility boundaries
- Integration or compatibility with ASVs for external scans and support for authenticated internal scans
- Scan frequency and coverage, including quarterly scans, scans after significant changes, and coverage across all in‑scope systems and networks
- Reporting quality, including prioritization of findings, remediation guidance, and evidence suitable for audits
- Security controls such as segmentation, firewalls, intrusion detection or prevention, encryption, and access control
- Support expertise in PCI DSS, including help with scoping, scan setup, and interpreting results
- Scalability and reliability, including uptime guarantees and capacity to grow with transaction volume

## Frequently Asked Questions

- **How often are PCI scans required?**

PCI DSS requires external vulnerability scans every quarter and after any significant change. Internal scans follow the same timing, and authenticated internal scans are expected under PCI DSS v4.0.

- **What happens if a PCI scan fails?**

A failed scan means that one or more high-risk or medium-risk vulnerabilities were detected. These issues must be fixed, and the environment must be scanned again until it passes.

- **Do hosting providers handle PCI compliance?**

Hosting providers support compliance by offering secure infrastructure, segmentation, and scanning compatibility. However, the organization using the hosting service is responsible for its own PCI compliance.

- **What is the difference between scanning and penetration testing?**

Vulnerability scanning is automated and identifies known weaknesses. [Penetration testing](https://www.atlantic.net/vps-hosting/best-penetration-testing-practices-you-need-to-know/) is manual and attempts to exploit weaknesses to understand real-world risk.

- **How long does a PCI scan take?**

Most scans complete within a few hours, but timing depends on system size, network complexity, and the number of in-scope assets.

- **How does PCI DSS v4.0 affect scanning?**

PCI DSS v4.0 introduces authenticated internal scans, expanded expectations for ecommerce environments, and stronger monitoring of payment pages to detect unauthorized changes.

## Final Thoughts

A stable [PCI hosting](https://www.atlantic.net/pci-compliant-hosting/pci-hosting-an-in-depth-buyers-guide/) choice depends on both technical needs and the daily routines that support secure operations. Therefore, a suitable environment should reduce unnecessary complexity while still giving teams the controls they need for scanning, segmentation, and monitoring. When providers define responsibilities clearly, organizations can manage their environments with fewer uncertainties.

At the same time, compatibility with scanning tools and strong reporting practices helps teams respond to issues in a timely way. Because each organization has different skills and expectations, selecting a hosting option becomes a matter of matching these needs with the right level of guidance. In this way, the final decision supports both long-term security and operational confidence.


---

# How to Find the Top Cloud Hosting Providers in 2026

> URL: https://www.atlantic.net/vps-hosting/how-to-find-the-top-cloud-hosting-providers/ | Published: 2026-02-15 | Updated: 2026-06-23 | Author: Robert Agar

A “top” [cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) provider is the one that matches your workload, risk profile, and operating model. Start by deciding what you actually need: regions close to users, predictable billing, security controls you can verify, and support that fits your team (self-serve vs managed). Then validate portability with a short pilot: deploy with Infrastructure as Code, test backups, and confirm how you’d exit. Once you have those basics, you can shortlist providers by category and pick the best fit for your business in 2026.

## Understanding Cloud Hosting Infrastructure

Before comparing individual providers, it is critical to understand the mechanics of cloud hosting. Unlike traditional [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/), where a single website or application lives on one physical server, cloud hosting distributes computing resources across a network of connected physical and virtual machines. This virtualization allows for rapid resource allocation, hardware redundancy, and high availability.

### The Shift Away from On-Premises Hardware

In the past, scaling IT operations meant purchasing, racking, and maintaining physical servers in a private data center. This required massive capital expenditure (CapEx). Cloud hosting shifts this to an operational expenditure (OpEx) model. Organizations rent virtualized CPU cores, RAM, and block storage on a pay-as-you-go or fixed-monthly basis. If hardware fails within a cloud cluster, the virtual machine automatically migrates to a healthy node, preventing downtime.

### IaaS vs. PaaS vs. SaaS Environments

When selecting a provider, buyers must differentiate between the three main tiers of cloud computing:

- **Infrastructure as a Service (IaaS):** The provider supplies the raw virtualized hardware (servers, storage, networking). The client manages the operating system, runtime, middleware, and applications.
- **Platform as a Service (PaaS):** The provider manages the underlying infrastructure and the operating system. The client simply deploys their application code onto a ready-made environment.
- **Software as a Service (SaaS):** A fully managed application hosted in the cloud, ready for end-user consumption such as Webmail or CRM software.

Most alternative cloud hosting providers operate primarily in the IaaS space, giving administrators full root access and control over their server environments.

## Why Look Beyond the “Big Three” Hyperscalers?

The cloud market is heavily concentrated around AWS, Microsoft Azure, and Google Cloud. However, migrating to a hyperscaler is not the correct operational move for every business. Alternative providers carve out their market share by fixing the common pain points of the massive public clouds.

### Predictable Billing vs. Variable Invoicing

Hyperscalers charge for every granular metric—API calls, ingress/egress data transfers, and specific storage operations. This variable billing often results in unexpected month-end invoices, known as “bill shock.” Alternative cloud hosts rely on flat-rate or simple hourly pricing models. Bandwidth is often bundled or completely unmetered, allowing financial departments to forecast IT budgets accurately.

### Direct vs. Tiered Technical Support

If an application goes down on a hyperscaler platform, standard support limits users to submitting a ticket and waiting. Access to an actual cloud engineer requires paying a high premium for enterprise support tiers. Alternative providers, specifically those targeting mid-market and compliance sectors, frequently include 24/7 direct phone support with level-3 engineers at no extra cost.

## Key Evaluation Criteria for 2026

When vetting cloud hosting providers, analyze the [service level agreements (SLAs)](https://www.atlantic.net/cloud-service-level-agreement/) and hardware specifications closely.

1. **Uptime Guarantees:** A 99.9% uptime SLA allows for about 43 minutes of downtime per month. A 99.99% SLA allows for just 4 minutes. High-availability providers back their SLAs with financial service credits if downtime exceeds the contract.
2. **Compliance Certifications:** If handling [protected health information](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) (PHI) or credit card data, the data center must maintain SOC 2 Type II, HIPAA, or [PCI-DSS](https://www.atlantic.net/pci-compliant-hosting/pci-dss-4-0-is-mandatory-a-hosting-checklist-for-2026/) validations. The host must also be willing to sign a Business Associate Agreement (BAA).
3. **Data Sovereignty:** European and localized regulations (like [GDPR](https://www.atlantic.net/vps-hosting/gdpr-compliance-for-global-managed-service-providers/)) often state that data must physically reside within specific borders. Providers with a diverse, global map of data centers allow you to control exact data residency.
4. **Storage Mediums:** Standard SSDs are no longer the peak of performance. Look for providers offering NVMe storage or specialized high-IOPS block storage for database-heavy applications.

### Cloud Workloads

Organizations typically move specific workloads to alternative cloud providers:

- **Web and Application Hosting:** Hosting high-traffic web portals where load balancers distribute requests across multiple virtual machines.
- **Development and Testing:** Spinning up isolated sandbox environments to test new code commits, then destroying the server to halt billing.
- **Regulated Data Storage:** Archiving sensitive medical or financial records in an air-gapped, audited environment.

## 2026 Cloud Hosting Comparison

| **Provider** | **Category** | **Starting Price (public “from”)** | **Key Advantage** | **Uptime / SLA (public)** |
| --- | --- | --- | --- | --- |
| **Atlantic.Net** | Premium & Specialized | $8.00/mo ([Atlantic.Net](https://www.atlantic.net/vps-hosting/pricing/)) | HIPAA-focused hosting options; BAA available ([Atlantic.Net](https://www.atlantic.net/compliance-hosting/)) | 100% uptime SLA for critical infrastructure components (exclusions apply) ([Atlantic.Net](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/)) |
| **Oracle Cloud (OCI)** | Premium & Specialized | Variable (service-based) ([Oracle](https://www.oracle.com/uk/cloud/sla/)) | Consistent “150+” services across regions ([Oracle](https://www.oracle.com/uk/cloud/distributed-cloud/service-availability)) | SLAs are service-specific; example compute SLA 99.95% (deployment-dependent) ([Oracle](https://www.oracle.com/uk/cloud/cloud-at-customer/dedicated-region/faq/)) |
| **Alibaba Cloud** | Premium & Specialized | Variable (service-based) ([AlibabaCloud](https://www.alibabacloud.com/en/pricing)) | Strong APAC coverage + broad global regions ([AlibabaCloud](https://www.alibabacloud.com/en/global-locations)) | ECS availability: 99.975% (single instance) / 99.995% (multi-zone) ([AlibabaCloud](https://www.alibabacloud.com/help/en/ecs/user-guide/what-is-ecs)) |
| **Kamatera** | Mid-Range Scalable | $4/month ([Kamatera](https://www.kamatera.com/cloud-vps/)) | Highly customizable VMs; hourly servers billed per minute ([Kamatera](https://www.kamatera.com/products/virtual-dedicated-servers/)) | 99.95% uptime guarantee ([Kamatera](https://www.kamatera.com/cloud-vps)) |
| **UpCloud** | Mid-Range Scalable | $3.30/mo ([UpCloud](https://upcloud.com/vps-hosting/)) | Developer-friendly plans + predictable pricing entry point ([UpCloud](https://upcloud.com/vps-hosting/)) | 99.999% SLA (effective May 1, 2025) ([UpCloud](https://upcloud.com/blog/introducing-the-five-9s-new-and-improved-service-level/)) |
| **Scaleway** | Mid-Range Scalable | €10.22/month ([Scaleway](https://www.scaleway.com/en/choose-the-right-instance/)) | EU-focused cloud building blocks + clear instance lineup ([Scaleway](https://www.scaleway.com/en/choose-the-right-instance/)) | Instance SLA is MAR-based (service-specific; see SLA terms) ([Scaleway](https://www.scaleway.com/en/virtual-instances/sla/)) |
| **IONOS** | Budget & Entry-Level | £1/month ([IONOS](https://www.ionos.co.uk/servers/vps)) | Unlimited traffic (1 Gbit/s connection) ([IONOS](https://www.ionos.co.uk/servers/vps)) | 99.99% uptime ([IONOS](https://www.ionos.co.uk/servers/vps)) |
| **Hostinger** | Budget & Entry-Level | £4.99/mo (term-based; paid upfront) ([Hostinger](https://www.hostinger.com/uk/pricing/vps-hosting)) | Beginner-friendly hPanel + NVMe + AMD EPYC positioning ([Hostinger](https://www.hostinger.com/uk/vps-hosting)) | 99.9% service uptime guarantee ([Hostinger](https://www.hostinger.com/uk/legal/hosting-agreement)) |
| **Hostwinds** | Budget & Entry-Level | $4.99/mo ([Hostwinds](https://www.hostwinds.com/vps/unmanaged-linux)) | Simple VPS entry point with high advertised uptime guarantee ([Hostwinds](https://www.hostwinds.com/product-docs/support/hostwinds-service-level-agreement)) | 99.9999% uptime guarantee ([Hostwinds](https://www.hostwinds.com/product-docs/support/hostwinds-service-level-agreement)) |

## Premium & Specialized Cloud Providers

These providers focus on highly regulated industries, mission-critical applications, and massive enterprise deployments.

### 1. [Atlantic.Net](https://www.atlantic.net/)

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

**Best for compliance-focused cloud hosting with direct engineer support**

Atlantic.Net is a strong fit when you want predictable infrastructure and a provider that’s comfortable supporting regulated environments. It also works well for teams that prefer a smaller-provider experience—clearer packaging, less platform sprawl, and access to human support.

Below is Atlantic.Net’s cloud control panel interface used to deploy and manage dedicated and GPU servers.
 ![Atlantic.Net Server Panel](https://www.atlantic.net/wp-content/uploads/2026/01/Atlantic.net-server-panel.png)
 Image Source: Atlantic.Net

- **Key Specs:** Cloud servers (VMs) with self-serve console and common infrastructure building blocks (compute, storage, networking).
- **Compliance:** Compliance support is contract- and workload-dependent; align requirements (e.g., regulated data) to the provider’s documented scope and agreements.
- **Support:** Support options are available across common channels; confirm coverage, escalation, and response expectations by plan.
- **Verdict:** Best for teams that want a compliance-aware hosting path and a provider that feels approachable during provisioning, troubleshooting, and change management.

**What Stands Out:**

- Clear provider-led operating model for teams that want less platform sprawl.
- HIPAA-focused hosting pages that explicitly reference BAAs.
- Balanced option for production hosting without hyperscaler complexity

**Who Should Choose Atlantic.Net?** Teams in regulated or sensitive-data environments that want predictable hosting plus real support escalation paths 24x7x365.

### 2. Oracle Cloud Infrastructure (OCI)

![](https://www.atlantic.net/wp-content/uploads/2025/08/Oracle-cloud-infrastructure.png)

**Best for enterprise apps needing a consistent service catalog across regions**

Oracle Cloud Infrastructure (OCI) is geared toward enterprises that want a broad cloud platform with a large, consistent service set across regions. It’s commonly shortlisted for data-heavy stacks, enterprise app modernization, and organizations already invested on Oracle’s database platforms.

Take a look at the Oracle Cloud dashboard, where you can set up load balancers, manage billing, and deploy resources from a single panel.
 ![Oracle-dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Oracle-dashboard.jpg)
 Image Source: Oracle Cloud

- **Key Specs:** Broad cloud service catalog plus a unified console for managing infrastructure and platform services.
- **Compliance:** Compliance posture varies by service and region; validate attestations, scope, and service eligibility for your specific workload.
- **Support:** Enterprise-grade support offerings; confirm support tier, escalation paths, and account coverage expectations.
- **Verdict:** Best for enterprises that want a deep cloud ecosystem and standardized governance across multiple teams and environments.

**What Stands Out:**

- Enterprise-aligned cloud platform depth for complex stacks
- Good fit for multi-team governance and standardized operating practices
- Strong option when your roadmap needs a wide service environment.

**Who Should Choose Oracle Cloud Infrastructure?** Enterprises that care about regional consistency and a deep cloud catalog for app modernization.

### 3. Alibaba Cloud

![](https://www.atlantic.net/wp-content/uploads/2025/08/alibaba.png)

**Best for global deployments with strong Asia coverage**

Alibaba Cloud operates as a dominant force in the Asia-Pacific region. Drawing on the infrastructure needs of its parent e-commerce group, Alibaba provides heavily integrated [content delivery networks](https://www.atlantic.net/hipaa-compliant-hosting/content-delivery-networks-theyre-powerful/) (CDNs), anti-DDoS scrubbing, and elastic scaling tools.

Here is the Alibaba Cloud dashboard, where you can control instances, monitor status, and configure settings.
 ![alibabacloud](https://www.atlantic.net/wp-content/uploads/2026/02/alibabacloud.png)
 Image Source: Alibaba Cloud

- **Key Specs:** Multi-region cloud infrastructure with standard [IaaS](https://www.atlantic.net/dedicated-server-hosting/what-is-iaas/) primitives and add-on platform services.
- **Compliance:** Compliance documentation and availability vary by region/service; confirm what applies to your deployment locations and data types.
- **Support:** Support options are available by plan; confirm coverage windows, channels, and severity handling.
- **Verdict:** Best for organizations that need strong APAC proximity and flexible regional deployment options.

**What Stands Out:**

- Practical fit for APAC latency-sensitive deployments
- Broad infrastructure footprint for multi-region planning
- Suitable for standard cloud stacks (compute, storage, networking)

**Who Should Choose Alibaba Cloud?** Teams expanding into APAC or running globally distributed workloads.

## Mid-Range Scalable Providers

These providers cater to developers, engineering teams, and mid-sized businesses requiring high performance, minute-by-minute scalability, and developer-friendly APIs.

### 4. Kamatera

![](https://www.atlantic.net/wp-content/uploads/2025/12/kamatera-logo-1.png)

**Best for highly customizable cloud servers**

Kamatera operates a highly adaptable cloud platform focused entirely on custom configuration and instant deployment. Administrators are not locked into pre-packaged server sizes. Instead, they choose exact core counts, RAM allocations, and disk space. Billing is calculated hourly, giving teams precise control over their spend.

Here is the Kamatera Cloud dashboard, where you can deploy virtual servers, manage storage, and monitor high-performance workloads.
 ![Kamatera cloud dashboard](https://www.atlantic.net/wp-content/uploads/2026/02/Kamatera-cloud-dashboard.jpg)
 Image Source: Kamatera Cloud

- **Key Specs:** Customizable VM configurations with self-serve provisioning and common server management workflows.
- **Compliance:** Compliance requirements should be validated against provider documentation and the specific infrastructure/services you plan to use.
- **Support:** Support is available with plan-based differences; confirm response expectations and escalation options before production.
- **Verdict:** Best for teams that want flexible sizing and a simple, direct path to running cloud servers.

**What Stands Out:**

- Custom sizing approach that can map closely to workload needs
- Straightforward VM-first hosting model
- Useful for teams that want control without a heavy platform layer

**Who Should Choose Kamatera?** Teams that want flexible VM sizing for application hosting and predictable operations.

### 5. UpCloud

![](https://www.atlantic.net/wp-content/uploads/2025/08/upcloud_logo_horizontal.png)

**Best for straightforward VM hosting with a clean console/API**

UpCloud is a European-based cloud provider famous for its proprietary MaxIOPS block storage technology, which performs significantly faster than standard SSD cloud environments. Targeting developers and performance-hungry applications, UpCloud maintains an aggressive 100% uptime SLA.

Here is an UpCloud dashboard, where you can create new VPS server and other resources.
 ![UpCloud server panel](https://www.atlantic.net/wp-content/uploads/2026/02/UpCloud-server-panel.jpg)
 Image Source: UpCloud

- **Key Specs:** VM hosting with console-driven management and automation options (API/automation-friendly workflows).
- **Compliance:** Validate any required certifications based on your data classification and region.
- **Support:** Support options vary by plan; confirm coverage, escalation, and incident communication processes.
- **Verdict:** Best for developer-led teams that want a clean VM experience and repeatable deployment workflows.

**What Stands Out:**

- Focused IaaS feature set without excessive platform complexity
- Good fit for automation-first teams
- Practical for standard web/app workloads and environments

**Who Should Choose UpCloud?** Teams that value a clean console/API and predictable VM operations.

### 6. Scaleway

![](https://www.atlantic.net/wp-content/uploads/2025/05/scaleway.png)

**Best for EU-focused cloud building blocks and console-led ops**

Scaleway provides highly flexible compute for engineering teams. They offer everything from basic development instances to Mac mini M1s and ARM-based servers. As a major player in the European market, they provide strict data sovereignty options and focus heavily on ecological efficiency in their data centers.

Explore the Scaleway GPU hosting panel designed for managing GPU workloads, deploying containers, and scaling compute infrastructure efficiently.
 ![Scaleway server panel](https://www.atlantic.net/wp-content/uploads/2026/02/Scaleway-server-panel.jpg)
 Image Source: Scaleway

- **Key Specs:** EU-oriented regions plus common cloud primitives (compute, storage, networking) and platform add-ons.
- **Compliance:** Confirm what compliance documentation applies to your chosen region and services; scope can vary.
- **Support:** Support is available by plan; confirm channels, response expectations, and escalation.
- **Verdict:** Best for teams running EU workloads that want practical cloud building blocks.

**What Stands Out:**

- Strong fit for EU placement priorities
- Builder/operator workflow orientation
- Good option when clear docs and console workflows matter

**Who Should Choose Scaleway?** Teams prioritizing EU regions and developer-led infrastructure workflows.

## Budget & Entry-Level Cloud Providers

These providers balance solid compute performance with low starting costs, making them ideal for small-to-medium enterprises (SMEs), agencies, and personal projects.

### 7. IONOS

![](https://www.atlantic.net/wp-content/uploads/2025/08/ionos-logo.png)

**Best for SMB cloud with panel-driven administration**

IONOS delivers cost-effective cloud server environments that bundle high-end features—like full root access and API management—into budget-friendly packages. Unlike most competitors, IONOS removes metered bandwidth limitations on its standard plans, protecting startups from unexpected traffic spikes.

Look at the IONOS Cloud control panel showing server image management, infrastructure configuration, and US data center deployment options.
 ![IONOS cloud panel](https://www.atlantic.net/wp-content/uploads/2026/01/IONOS-cloud-panel.png)
 Image Source: IONOS

- **Key Specs:** Panel-led cloud administration for standard server workflows and infrastructure basics.
- **Compliance:** For regulated workloads, validate scope and required documentation/agreements for your exact services and region.
- **Support:** Support options depend on plan; confirm hours, channels, and escalation.
- **Verdict:** Best for SMBs that want cloud servers with a more guided, panel-driven operating model.

**What Stands Out:**

- Familiar “control panel” style management approach
- Practical for small teams without dedicated ops staff
- Straightforward option for standard hosting needs

**Who Should Choose IONOS?:** SMBs that want a guided cloud panel experience for day-to-day hosting tasks.

### 8. Hostinger

![](https://www.atlantic.net/wp-content/uploads/2025/08/Hostinger-logo.png)

**Best for beginners who want an all-in-one dashboard**

Hostinger streamlines cloud and [VPS hosting](https://www.atlantic.net/vps-hosting/) for users who may not have deep systems administration experience. Their custom hPanel dashboard simplifies complex server management tasks. While prices start incredibly low, they utilize modern NVMe SSDs and AMD EPYC processors to ensure fast load times.

Let’s explore the Hostinger control panel, where you can manage your website, domains, and hosting performance from a modern dashboard.
 ![Hostinger cPanel](https://www.atlantic.net/wp-content/uploads/2026/02/Hostinger-cPanel.jpg)
 Image Source: Hostinger

- **Key Specs:** Dashboard-led management for common hosting tasks; suitable for basic site/app hosting workflows.
- **Compliance:** If you have compliance requirements, confirm what documentation and controls apply to your selected product and region.
- **Support:** Support options vary by plan; confirm coverage expectations.
- **Verdict:** Best for beginners and small teams who want a simple dashboard-first way to run websites or lightweight applications.

**What Stands Out:**

- UI-first onboarding and management experience
- Good fit for smaller workloads and simpler stacks
- Useful for teams optimizing for ease, not complexity

**Who Should Choose Hostinger?** Beginners and small teams that want a simple dashboard for everyday hosting.

### 9. Hostwinds

![](https://www.atlantic.net/wp-content/uploads/2025/08/hostwinds-logo.png)

**Best for straightforward VPS hosting with portal-led workflows**

Hostwinds offers unmanaged and fully managed cloud servers with a focus on maximum uptime. They offer standard, off-the-shelf Linux and Windows environments backed by an aggressive 99.9999% uptime guarantee. Their hourly billing mechanism ensures you only pay for active resource consumption.

Explore the Hostwinds cloud hosting panel designed for managing server resources, configuring security settings, and monitoring performance in real time.
 ![Hostwinds WHM](https://www.atlantic.net/wp-content/uploads/2026/01/Hostwinds-WHM.jpg)
 Image Source: Hostwinds

- **Key Specs:** VPS hosting with portal-driven provisioning and standard server administration workflows.
- **Compliance:** Compliance needs should be validated to the exact product scope and operational controls you require.
- **Support:** Support options depend on plan; confirm coverage, response expectations, and escalation.
- **Verdict:** Best for budget-focused teams that want straightforward VPS hosting and portal-led operations.

**What Stands Out:**

- Portal-first workflow for common VPS tasks
- Suitable for standard hosting use cases without platform overhead
- Practical option when budget and simplicity are primary drivers

**Who Should Choose Hostwinds?** Teams that want straightforward VPS hosting with portal-led management at a budget price point.

## Frequently Asked Questions

**What is the difference between cloud hosting and shared hosting?**

Shared hosting places multiple websites on a single physical machine, sharing its processor and memory. Cloud hosting isolates your environment into a virtual machine supported by a cluster of servers, preventing other users’ traffic spikes from impacting your performance.

**Why choose an alternative cloud provider over AWS or Azure?**

While hyperscalers offer massive scale, their variable pricing models often lead to budget overruns. Alternative providers offer simpler, flat-rate billing, highly specialized direct support teams, and targeted features like built-in compliance or unmetered bandwidth.

**Is cloud hosting secure enough for healthcare data?**

Yes, provided you choose a host with certified infrastructure. Providers like Atlantic.Net offer dedicated HIPAA-compliant environments, isolated networks, and sign [Business Associate Agreements (BAAs)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) to meet strict federal requirements.

**How does pay-as-you-go cloud billing work?**

Many cloud providers track resource consumption by the hour. If you spin up a server with 4 CPU cores and 8GB of RAM for a 5-hour test, you only pay for those 5 hours. Once the server is deleted, billing stops immediately.

**What does a 100% uptime SLA mean?**

A 100% Service Level Agreement (SLA) means the provider financially guarantees your server will not experience unscheduled downtime due to infrastructure or network failure. If downtime occurs, the provider issues a prorated service credit to your invoice.


---

# What Is a Bare Metal Server? Benefits, Use Cases, and Best Practices

> URL: https://www.atlantic.net/dedicated-server-hosting/what-is-a-bare-metal-server-benefits-use-cases-and-best-practices/ | Published: 2026-02-15 | Updated: 2026-05-30 | Author: Gilad Maayan

 

A bare metal server is a single-tenant physical server you rent for your exclusive use. You get direct access to dedicated CPU, memory, storage, and networking or GPU without sharing resources with other customers.

There is typically no preinstalled hypervisor, so you choose the operating system and can run your own virtualization stack if you want. Bare metal is a strong fit when you need predictable performance, low latency, specific hardware, or strict isolation for sensitive workloads. The tradeoff is simpler scaling and more operational responsibility compared to virtual servers.

## Bare Metal vs. Virtual Machines (VM)

| **What you need** | **Bare Metal Server** | **Cloud Server / VM** | **Shared Cloud Resources** | **Dedicated Host (provider-managed)** |
| --- | --- | --- | --- | --- |
| **Tenant isolation** | Single tenant | Isolated VMs on shared hardware | Shared platform/service | Single tenant (often with platform tooling) |
| **Virtualization layer** | Not required; you can add your own | Hypervisor-managed | Abstracted away | Typically included/managed by the provider |
| **Performance consistency** | Highest consistency (no “noisy neighbor”) | Can vary by host contention | Varies by service and tier | High; depends on platform design |
| **Scaling** | Hardware changes take planning | Fast resize/scale | Fast scale within service limits | Often faster than classic dedicated |
| **Control over OS + stack** | Full control | High, but within VM limits | Limited (service-managed) | High, with provider constraints |
| **Best fit** | Steady-state, performance-sensitive workloads | General workloads, dev/test, elastic apps | SaaS, managed storage, managed platforms | Teams wanting dedicated hardware plus platform convenience |
| **Ops responsibility** | Highest (unless managed) | Medium | Lowest | Medium (shared responsibility) |

## What is a Bare Metal Server?

A bare metal server is a physical machine assigned to a single customer, ensuring you never share CPU cores, RAM, disks, or GPU interfaces with other tenants. While “bare metal” and “dedicated server” are often used interchangeably, the primary difference lies in the delivery model.

Traditional dedicated servers typically involve manual provisioning and fixed contracts. In contrast, modern bare metal offers a “cloud-like” experience, featuring automated deployment, rapid provisioning, and flexible billing—all while maintaining the performance of a dedicated environment.

## How Does a Bare Metal Server Work?

In a bare metal environment, the operating system (OS) is installed directly on the server’s hard drive. There are no intermediate layers. This contrasts with virtualization, where a hypervisor creates multiple “guest” machines on a single physical host.

Since there is no hypervisor, the operating system can communicate directly with the underlying hardware components. This direct access allows for:

- **Instruction execution:** The CPU executes instructions without translation layers.
- **Memory access:** Applications utilize RAM without fighting for allocation.
- **I/O throughput:** Storage controllers deliver raw speed directly to the database or application.

### Why is it called “Bare Metal”?

“Bare metal” describes a deployment where the operating system runs directly on a physical server and schedules CPU time and manages memory without a host hypervisor (Type-1 or Type-2), abstracting the hardware into virtual machines. The kernel talks straight to the platform via native drivers and standard firmware interfaces (BIOS/UEFI, ACPI), with direct access to CPU features (including virtualization extensions if present), PCIe devices, storage controllers, and NICs.

In practical terms, you get exclusive control of the machine’s hardware resources and topology—NUMA layout, CPU pinning/isolcpus, huge pages, SR-IOV/NVMe device passthrough, IRQ affinity, etc.—because there’s no virtualization layer mediating or time-slicing those resources into VM constructs.

## Benefits of Bare Metal Servers

![](https://www.atlantic.net/wp-content/uploads/2026/02/what-is-a-bare-metal-server_HIPAA-compliant.png)

### Enhanced Physical Isolation

Bare metal gives you physical separation from other tenants. This helps when you want to reduce cross-tenant risk, avoid resource contention, and keep sensitive workloads in a single-tenant environment.

Where isolation matters most:

- **Regulated data handling:** Ideal for privacy, healthcare, and payments.
- **Internal systems:** Best for systems with strict access boundaries.
- **Risk mitigation:** Useful for workloads where performance variability creates business risk.

### Greater Processing Power

Dedicated hardware allows you to avoid common multi-tenant issues like contention and jitter.

This is essential when you have:

- Sustained CPU-bound workloads
- Storage-heavy workloads (high IOPS, low-latency I/O)
- Network-sensitive workloads (consistent throughput and latency)

### Complete Control of the Software Stack

You control the OS, kernel settings, drivers, agents, and security tooling.

This layer of control is useful when you need:

- A specific OS image or hardened baseline
- Custom libraries and dependencies
- Specialized runtime settings (CPU pinning, hugepages, tuned networking)

## Bare Metal Servers vs. Virtual Servers vs. Shared Cloud Resources

These options solve different problems:

- **Bare metal:** dedicated hardware for predictable performance and full control
- **Virtual servers (Cloud Server/VMs):** a dedicated slice of a shared host; easier scaling and faster provisioning
- **Shared cloud resources:** managed services (storage, SaaS, databases) that trade control for speed and simplicity

A simple decision rule:

- Choose bare metal when performance, isolation, or hardware control is required.
- Choose Cloud Server/VM when you want flexibility and fast change with acceptable performance variance.
- Choose shared cloud services when you want the provider to handle the platform layer.

## ![](https://www.atlantic.net/wp-content/uploads/2026/02/what-is-a-bare-metal-server_DataCenter-and-Network.png)

## Top Use Cases for Bare Metal in 2026

### Artificial Intelligence (AI) and Machine Learning (ML)

Training Large Language Models (LLMs) and running inference requires massive parallel processing power. Bare metal servers equipped with high-performance GPUs allow AI workloads to run without the latency or virtualization taxes found in public cloud instances.

### Big Data and High-Performance Computing (HPC)

Processing terabytes of data requires high Input/Output Operations Per Second (IOPS). Bare metal servers maximize disk I/O, making them ideal for:

- Hadoop and Spark clusters.
- Scientific modeling and simulations.
- Genomic sequencing.

### Fintech and Banking

Financial institutions require microsecond latency for high-frequency trading. The variable latency of a virtualized environment is often unacceptable. Bare metal ensures consistent execution speeds and meets strict regulatory data residency requirements.

### Healthcare (HIPAA Compliant Hosting)

Healthcare providers often choose bare metal to ensure strict physical separation of Electronic Health Records (EHR). Dedicated environments simplify the auditing process for HIPAA compliance by eliminating the complexity of shared responsibility in multi-tenant clouds.

## Bare Metal vs. Dedicated Servers: Is There a Difference?

In 2026, the terms are often used interchangeably, but there is a nuance:

- **Dedicated Servers** traditionally referred to physical boxes leased on monthly or yearly contracts, often with manual provisioning times (hours or days).
- **Bare Metal Cloud** often refers to the same physical hardware but with cloud-like automation—provisioned in minutes via API, with hourly or monthly billing.

Functionally, both provide the same single-tenant performance benefits.

## Best Practices for Managing Bare Metal Servers

### Maintain and Upgrade Hardware

Bare metal is physical infrastructure. Treat it like it:

- Track lifecycle and warranties (where relevant)
- Plan for component failure (drives, fans, power)
- Schedule maintenance windows for firmware and hardware work

### Optimize Security Measures

Start with a clear baseline, then enforce it:

- Least privilege and role-based access
- MFA for administrative access
- Patch OS and applications on a defined schedule – atleast monthly.
- Encrypt data at rest and in transit where appropriate
- Centralize logs and protect log integrity

### Manage Network Configurations and Traffic

Network choices show up as user experience:

- Segment networks for admin, app, and data paths
- Use firewalls and allow-listing for exposed ports
- Add DDoS protections and rate limits where needed
- Monitor for anomalies (unexpected egress, scanning, spikes)

### Monitor Performance for Optimization Opportunities

A bare metal server won’t tell you it’s struggling unless you watch:

- CPU saturation and load patterns
- Memory pressure and swapping
- Disk latency, IOPS, and queue depth
- Network throughput, packet loss, and latency
- Application-level indicators (p95/p99 latency, error rates)

### Ensure Compliance and Auditing

If compliance is part of your reason for choosing bare metal, operational proof matters:

- Keep access logs and change records
- Document security baselines and exceptions
- Run periodic configuration reviews and vulnerability checks
- Validate backup/restore procedures with real tests

## Atlantic.Net Bare Metal Dedicated Server Hosting

At Atlantic.Net, we offer single-tenant bare metal servers designed for customers who want direct control of the OS and application stack. You can choose from our preset configurations or request custom builds, depending on workload needs. Our storage options and redundancy choices are part of the configuration process, and we often pair bare metal with monitoring, backups, and security controls based on how you operate the environment.

We provide a stable foundation for your private cloud. If you’re running both bare metal and cloud resources, our common approach is to keep steady-state, performance-sensitive workloads on bare metal and use our cloud instances for burst capacity..

## Advantages of Bare Metal Hosting

Bare metal hosting is most compelling when you need a combination of:

- **Predictable performance** for steady workloads
- **Physical isolation** for sensitive systems
- **Full administrative control** over the OS and software stack
- **Hardware choice** aligned to your workload (compute, storage, network)
- **A stable foundation** for private cloud and specialized platforms

## ![](https://www.atlantic.net/wp-content/uploads/2026/02/what-is-a-bare-metal-server-data-center-and-network.png)

## FAQ

**What’s the difference between bare metal and a dedicated server?**

In many contexts, they refer to the same thing: single-tenant physical hardware. When providers separate the terms, “bare metal” often implies faster provisioning and more automation, while “dedicated server” can imply a more traditional lease model.

**Is bare metal more secure than a Cloud Server or VM?**

It can reduce certain multi-tenant risks because the hardware is not shared. Security still depends on how you configure access, patching, monitoring, encryption, and incident response.

**Can I run virtualization (VMware, Hyper-V, KVM, Proxmox) on bare metal?**

Yes. Many teams use bare metal as the base layer and run their own hypervisor and VM templates on top. That’s a common pattern for private cloud and controlled multi-workload environments.

**When should I choose bare metal instead of shared cloud resources?**

Choose bare metal when you need stable performance, specific hardware, or tighter control over the stack. Choose shared services when speed, managed operations, and rapid scaling matter more than low-level control.

**What are the most common bare metal mistakes?**

Underestimating ongoing operations is the big one. Teams often forget to plan for patching, monitoring, backups, on-call response, and maintenance windows until something breaks.

**How do I choose the right bare metal configuration?**

Start with your bottleneck: CPU, RAM, storage latency, or network. Use current telemetry (or load tests) to size the server, then add headroom for growth and failure scenarios.

**Can I connect bare metal to a cloud environment?**

Often, yes. Many providers support hybrid patterns where bare metal runs the steady core workload and cloud resources handle burst, testing, or supporting services. The best approach depends on networking, security boundaries, and how you manage identity and access.

**Is bare metal always more expensive?**

Not always. For steady workloads that run 24/7, bare metal can be cost-competitive because you’re paying for dedicated capacity. For bursty workloads, virtual servers and managed services can be cheaper because you scale down when you don’t need resources.

### See Additional Guides on Key Hybrid Cloud Topics

Together with our content partners, we have authored in-depth guides on several other topics that can also be useful as you explore the world of [hybrid cloud](https://cloudian.com/guides/hybrid-cloud/what-is-hybrid-cloud-examples-use-cases-and-challenges/).

#### [Cloud Migration](https://faddom.com/what-is-cloud-migration/)

*Authored by Faddom*

- [[Guide] Data Center Migration: Complete Guide 2025](https://faddom.com/what-is-data-center-migration/)
- [[Guide] Cloud Migration to AWS: 3 Phases, 7 Rs and 5 Free Tools to Get You Started](https://faddom.com/cloud-migration-to-aws-3-phases-7-rs-and-5-free-tools-to-get-you-started/)
- [[Blog] How Secure is the Cloud? ](https://www.atlantic.net/hipaa-compliant-hosting/how-secure-is-the-cloud/)
- [[Product] Faddom | Instant Application Dependency Mapping Tool​](https://faddom.com/)

#### [Nutanix](https://faddom.com/nutanix-history-products-and-top-5-alternatives/)

*Authored by Faddom*

- [[Guide] Nutanix: History, Products, and Top 5 Alternatives –](https://faddom.com/nutanix-history-products-and-top-5-alternatives/)
- [[Guide] Nutanix vs. VMware: 5 Key Differences and How to Choose](https://faddom.com/vmware-vs-nutanix/)
- [[Product] Faddom | Instant Application Dependency Mapping Tool​](https://faddom.com/)

#### [Colocation Hosting](https://www.atlantic.net/orlando-colocation-hosting-data-center/what-is-colocation-hosting/)

*Authored by Atlantic.Net*

- [[Guide] What is Colocation Hosting in 2025? Benefits of Colocation Hosting ](https://www.atlantic.net/orlando-colocation-hosting-data-center/what-is-colocation-hosting/)
- [[Guide] Finding the Best Colocation Facility: What to Consider ](https://www.atlantic.net/orlando-colocation-hosting-data-center/things-to-look-for-when-identifying-the-best-site-for-colocation/)
- [[Blog] How to Secure SSH Server on Arch Linux ](https://www.atlantic.net/dedicated-server-hosting/how-to-secure-ssh-server-on-arch-linux/)
- [[Product] Atlantic.Net Cloud Platform | Scalable, Secure Cloud Solutions](https://www.atlantic.net/cloud-platform/)

**Related Products:**

- [Atlantic.Net Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/)
- [Atlantic.Net HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)
- [Atlantic.Net GPU Hosting](https://www.atlantic.net/gpu-server-hosting/)


---

# VPS vs. Dedicated Server: 10 Key Differences for 2026

> URL: https://www.atlantic.net/vps-hosting/vps-vs-dedicated-server-6-key-differences-and-how-to-choose/ | Published: 2026-02-15 | Updated: 2026-06-23 | Author: Alexander Wise

The choice between a VPS (Virtual Private Server) and a [Dedicated Server](https://www.atlantic.net/dedicated-server-hosting) sets the performance ceiling and security posture of your infrastructure. The gap between “virtual” and “physical” performance is narrowing, but the structural differences remain.

A [VPS](https://www.atlantic.net/cloud-platform/virtual-private-cloud/) (sometimes called a Cloud Server) provides virtualized, scalable resource instances on a shared host, making it the most agile and cost-predictable choice for web apps and development.

A Dedicated Server offers 100% of a physical machine’s resources with zero virtualization overhead, essential for high-frequency trading, AI/ML training, and strict HIPAA/SOC compliance.

In 2026, the decision hinges on whether you value instant scalability (VPS) or deterministic performance (Dedicated). In practice: choose a VPS when you want faster scaling, simpler recovery options, and lower cost for moderate-to-growing workloads. Choose dedicated when you need consistently high performance, maximum isolation, and hardware-level customization for demanding or sensitive workloads.

## Comparison Table

To choose correctly, you must understand how resources are delivered to your applications.

| **Factor** | **VPS (Cloud Server)** | **Dedicated Server** |
| --- | --- | --- |
| **What you get** | Virtual machine on shared physical hardware | An entire physical machine for one customer |
| **Performance consistency** | Usually strong, but can vary with host contention | Most consistent (no contention) |
| **Scaling speed** | Typically faster to resize resources | Usually slower; may require hardware changes or migration |
| **Customization depth** | High at OS/app level; hardware is abstracted | Highest: more control over hardware and low-level setup |
| **Security isolation** | Strong isolation, but relies on hypervisor/management security | Physical isolation reduces shared-hardware exposure |
| **Operations burden** | Often easier to manage; many managed options exist | More hands-on unless you buy managed services |
| **Recovery options** | Commonly simpler to snapshot/clone and restore | Often needs more planning (imaging, spare capacity, failover) |
| **Typical fit** | Web apps, staging, SMB production, bursty traffic | High-traffic production, large databases, specialized stacks |

## What is a VPS?

A virtual private server (VPS) is a virtualized server that uses a portion of a physical server’s resources dedicated to one user. Multiple VPS instances can run on the same host while remaining isolated from each other. VPS is commonly used when you need more control than [shared hosting](https://www.atlantic.net/vps-hosting/vps-hosting-vs-shared-hosting-pros-cons-differences-and-expert-tips/), but don’t need a full physical server.

## What is a Dedicated Server?

A dedicated server is a physical server reserved for one customer. You get exclusive use of its CPU, RAM, storage, and network resources, plus deeper configuration flexibility. This is typically chosen for consistently high-load workloads, strict isolation preferences, or specialized configurations.

## Pros and Cons of VPS

### Advantages

- **Cost-effective:** You’re paying for a slice of a host instead of a whole server.
- **Scalable:** Resources can often be adjusted faster as needs change.
- **Isolation vs shared hosting:** Separate environments reduce cross-tenant risk compared to shared hosting.
- **Customization:** Root/admin access for OS and application stack choices.
- **Managed options:** Many providers offer maintenance and security help.

### Disadvantages

- **Performance variability:** Shared host contention can affect consistency.
- **Resource ceiling:** You’re bounded by the host’s hardware and plan limits.
- **Still needs expertise:** Patching, hardening, monitoring, and backups don’t disappear.
- **Host-level risk:** If the underlying host fails, multiple VPS instances can be impacted.

## Pros and Cons of Dedicated Servers

### Advantages

- **Exclusive resources:** No noisy neighbors competing for CPU or disk I/O.
- **Maximum performance headroom:** Strong fit for large databases and compute-heavy apps.
- **Deep customization:** More flexibility for specialized software and configurations.
- **Stronger isolation boundary:** Single-tenant physical server model.
- **Stability:** Well-suited to steady, high-load production workloads.

### Disadvantages

- **Higher cost:** Hardware exclusivity + potential management overhead.
- **Scaling is less elastic:** Capacity changes can mean migration or new hardware.
- **More operational responsibility:** Hardware, OS, and security posture need more planning.
 **Power/space footprint:** Dedicated hardware tends to consume more resources than shared hosts.

## The 10 Key Differences

### #1 – How are resources allocated?

In a VPS environment, a physical server is divided into multiple virtual instances using a hypervisor. While your resources (RAM, vCPU) are “dedicated” in name, they are still managed by software. A Dedicated server is single-tenant; you own the entire physical chassis, the CPU cores, and the memory bus.

### #2 – What is the “Noisy Neighbor” effect?

On a VPS, another user on the same physical host who generates massive I/O (disk read/writes) can occasionally impact your performance. Dedicated servers eliminate this risk. There is no sharing of the NIC (Network Interface Card) or the storage controller.

### #3 – I/O Latency and Throughput

Virtualization adds a thin layer of abstraction. For most websites, this is unnoticeable. However, for high-load databases or high-frequency trading where milliseconds matter, the direct-to-hardware access of a Dedicated server provides much lower and more consistent latency.

### #4 – How fast can you scale?

VPS wins here. If your traffic triples during a marketing campaign, you can upgrade your VPS resources in seconds with a simple dashboard click. Scaling a Dedicated server often requires a technician to physically install more RAM or drives, which can involve scheduled downtime.

### #5 – Physical vs. Logical Security

A VPS provides logical isolation—software ensures User A cannot see User B’s data. A Dedicated server provides physical isolation. For organizations with high-security profiles, having a “gap” of physical hardware between their data and the rest of the internet is a mandatory requirement.

### #6 – Regulatory Compliance (HIPAA/SOC 3)

Can you be HIPAA compliant on a VPS? Yes. But it is much easier to pass a SOC 3 or FISMA audit on a Dedicated server because you can point to the exact physical serial number of the machine holding the data, ensuring no other entity ever touched that hardware.

### #7 – Customization: BIOS and RAID

A VPS allows you to choose your OS and software. A Dedicated server allows you to go deeper: you can configure hardware-level [RAID arrays](https://www.atlantic.net/vps-hosting/how-raid-arrays-improve-performance-and-data-protection/) (RAID 10, 50, etc.), modify BIOS settings for power management, or install custom kernel-level security modules that hypervisors often block.

### #8 – Ready for AI and Machine Learning?

Modern VPS instances are great for running AI “inference” (using a model to answer questions). However, training a model requires sustained, 100% CPU/GPU utilization for weeks. Dedicated servers are the industry standard for ML training to avoid “throttling” that occurs in shared environments.

### #9 – Data Sovereignty

In regulated markets, you may need to prove your data resides in a specific jurisdiction. Dedicated servers offer “Data Sovereignty” clarity—you know exactly which rack and which data center your physical drives are located in, simplifying global legal compliance.

### #10 – Long-term Cost and ROI

VPS has a lower entry cost, making it ideal for startups. However, as a workload becomes stable and heavy, a Dedicated server often provides a better Total Cost of Ownership (TCO). You pay a flat monthly rate for massive resources rather than paying “cloud taxes” for high-tier virtual instances.

## VPS vs. Dedicated Server: How to Choose

### Choose a VPS when:

- Your traffic is variable, or you expect incremental growth
- You want faster scaling without a hardware migration
- You run multiple environments (dev/stage/prod) and want consistency
- Your workloads are moderate, and you’re optimizing for price/performance
- You value simpler recovery patterns (cloning, snapshots, redeployments)

### Choose a dedicated server when:

- Your workload is consistently heavy (databases, compute, high I/O)
- You need maximum performance consistency and low variance
- You want a clearer isolation boundary for sensitive workloads
- You require specialized configurations or deeper system control
- You have the ops maturity (or managed services) to handle ongoing maintenance

### Compliance note

Frameworks and regulations typically require safeguards and controls—not a specific server type. For example, HIPAA’s Security Rule is framed around administrative, physical, and technical safeguards, which can be implemented on different infrastructure models depending on your design and controls.

If compliance is a driver, evaluate: access controls, encryption, logging, backup/restore, segmentation, vendor contracts, and documented procedures—then decide which hosting model makes those easiest to implement and prove.

## Dedicated Server Hosting with Atlantic.net

Unleash the huge server power of Atlantic.Net dedicated server hosting services, America’s most experienced dedicated server hosting provider. Each private, physical dedicated server comes with full root access, backed by the latest hardware specifications and USA-based support.

Atlantic.Net provides various types of dedicated server hosting options, all available with discounts for long-term contracts. Dedicated Servers are a standalone hardware offering not tied into any existing Cloud platforms or hypervisors, such as the Atlantic.Net [Cloud Platform](https://www.atlantic.net/cloud-platform/). The hardware is solely set up for your requirements, along with any additional [Managed Services](https://www.atlantic.net/managed-services/), to ensure the hosting environment meets your needs.

## Dedicated Server Hosting Plans

Our Dedicated Servers are custom-built to your specification with your choice of CPU, Disk, and Memory. Each server includes:

- Full root access.
- Dedicated network IP address.
- Free TLS (formerly [SSL](https://www.atlantic.net/vps-hosting/what-is-ssl-certificate/)) certificate setup.
- Support for a wide selection of operating systems.

[Learn more about dedicated server hosting with Atlantic.Net](https://www.atlantic.net/dedicated-server-hosting/)

## FAQ

**Is a VPS “good enough” for production?**

Often, yes—especially for web apps, APIs, and moderate databases when you size the VPS correctly and monitor performance. If you see sustained CPU steal, disk I/O contention, or unpredictable latency, that’s a sign to reassess sizing or move to dedicated.

**What’s the biggest practical difference day-to-day?**

Consistency. Dedicated servers tend to deliver steadier performance because you don’t share the physical host. VPS tends to win on agility—faster resizing, easier redeploys, and simpler environment replication.

**Which is more secure: VPS or dedicated?**

Both can be secure. Dedicated reduces shared-hardware exposure, while VPS security depends heavily on the hypervisor and management plane being well secured and operated. Your own configuration and operational controls remain critical in both models.

**Does compliance require dedicated servers?**

Not automatically. Many compliance programs focus on safeguards, risk management, and evidence of controls. Evaluate what you need to implement and demonstrate, then choose the model that best supports those controls.

**When should I upgrade from VPS to dedicated?**

Common signals: consistently high resource usage, performance variability that affects users, growing database or I/O demands, or a need for hardware-level customization. Another signal is when your ops team needs a simpler [single-tenant](https://www.atlantic.net/dedicated-server-hosting/achieving-unparalleled-security-with-single-tenant-dedicated-hosting/) environment to standardize controls.

**What about GDPR and server choice?**

[GDPR](https://www.atlantic.net/vps-hosting/overview-of-ccpa-and-gdpr/) obligations focus on lawful processing, data protection, and organizational/technical measures. Your server model should support the controls you need (access control, auditability, [encryption](https://www.atlantic.net/hipaa-compliant-hosting/why-is-encryption-so-key-to-hipaa-compliance/), retention, and vendor management) rather than being treated as compliance by itself.

## [Learn more about dedicated server hosting with Atlantic.Net](https://www.atlantic.net/dedicated-server-hosting/)


---

# Best GPU Hosting for Deep Learning 2026

> URL: https://www.atlantic.net/gpu-server-hosting/best-gpu-hosting-deep-learning-2026/ | Published: 2026-02-15 | Updated: 2026-02-16 | Author: Dr. Assad Abbas

[Deep learning](https://www.ibm.com/think/topics/deep-learning) is a type of machine learning that works with large neural networks. These networks learn patterns by analyzing data across multiple layers. However, this learning process requires heavy computation. Traditional CPU systems often fail to handle such workloads efficiently. Therefore, GPU hosting has become a practical option for deep learning tasks.

GPU hosting provides on-demand access to high-performance GPUs through cloud platforms. As a result, teams can train models faster and manage workloads with more flexibility. Deep learning projects in 2026 are more demanding than before. They involve larger datasets, foundation models, and longer training cycles. Because of this, they require hardware that can support sustained and intensive computation.

Many organizations now choose cloud GPU hosting for operational reasons. It removes the burden of managing physical servers and hardware refresh cycles. In addition, it supports rapid experimentation, which is important for research and product development. GPU hosting has therefore become a core component of modern AI infrastructure, providing required performance while keeping systems scalable and manageable.

## Understanding GPU Infrastructure Before Choosing a Provider

Before comparing providers, it is important to understand how GPU infrastructure affects deep learning performance, cost, and deployment stability.

### Why GPUs Are Critical for Deep Learning

Deep learning workloads demand more computational resources than traditional machine learning tasks. Deep learning models are heavier and more complex, requiring:

- Large GPU memory capacity
- High memory bandwidth
- Fast interconnects
- Strong parallel processing

Modern workloads include Large Language Models (LLMs), multimodal systems, diffusion models, and distributed training pipelines. These workloads often rely on multi-GPU or multi-node environments with high-bandwidth networking such as NVLink or InfiniBand.

Without proper GPU infrastructure, training time increases significantly, experimentation slows down, and production deployment becomes unstable.

## Single-GPU vs Multi-GPU vs Multi-Node Training

GPU hosting providers differ in how they support scale:

- **Single-GPU instances** suit experimentation and small-to-medium models.
- **Multi-GPU nodes** support larger models and reduce training time.
- **Multi-node clusters** enable distributed training for foundation models and LLMs.

Distributed training introduces communication overhead. Therefore, networking strength directly affects performance. Providers offering high-speed interconnects reduce bottlenecks and improve training throughput.

## Operational Considerations for GPU Hosting

Cloud GPU hosting offers operational advantages:

- No hardware procurement delays
- No maintenance of on-prem clusters
- On-demand provisioning
- Regional deployment flexibility

Organizations can experiment early and scale later without infrastructure redesign.

For regulated industries such as healthcare, compliance matters. TLS 1.2/1.3 encryption, role-based access control (RBAC), IAM integration, and HIPAA Business Associate Agreement (BAA) (BAAs) are important considerations when training models on sensitive datasets.

## Cost Planning for Deep Learning Infrastructure

GPU hosting costs vary significantly based on:

- GPU model (A100 vs H100 vs mid-range accelerators)
- Runtime duration
- Storage volume
- Networking traffic
- Pricing model (on-demand, reserved, spot, marketplace)

High-end GPUs accelerate training but increase hourly cost. However, faster training may reduce total project cost. Therefore, cost optimization requires balancing performance and runtime.

Monitoring idle GPUs, optimizing storage tiers, and minimizing cross-region traffic help maintain efficient budgets.

## Best GPU Hosting Providers for Deep Learning in 2026

The following section highlights eight leading GPU hosting providers. Additionally, each platform offers distinct features that support deep learning workloads, including high-performance GPUs, multi-node setups, and flexible deployment options.

## Enterprise Cloud & Compliance-Oriented Providers

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

### Atlantic.Net

At [Atlantic.net](https://www.atlantic.net), we provide hosting services for organizations that need strong security and compliance. Our platform supports workloads that handle electronic Protected Health Information (ePHI (electronic Protected Health Information)), and we sign a BAA when required. This makes our environment suitable for healthcare, research, and analytics teams. Moreover, we offer GPU-enabled compute options that support deep learning and AI training. Our infrastructure is designed for stability and predictable performance. In addition, our support team is based in the United States and is available at all times. Therefore, clients can depend on us for reliable service and clear guidance.

#### *Key Characteristics*

- Atlantic.Net offers HIPAA-compliant hosting with a signed BAA (BAA), and we follow strict controls for handling electronic Protected Health Information (ePHI), including SOC 2 Type II measures and continuous monitoring.
- Atlantic.Net uses TLS 1.2 or 1.3 for data in transit and encrypted storage for sensitive information, which helps maintain confidentiality and integrity across all workloads.
- Atlantic.Net provides GPU-enabled compute for AI and analytics, supporting training, inference, and data processing tasks to help teams run deep learning models with stable performance.
- Atlantic.Net delivers 24/7 U.S.-based support, offering timely assistance that helps clients resolve issues quickly and maintain smooth operations.

### ![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

### Microsoft Azure

[Microsoft Azure](https://azure.microsoft.com/en-us) offers a broad cloud platform that supports large-scale AI and machine learning workloads. Its GPU-enabled virtual machines are designed for training, inference, and distributed computation across many nodes. Azure provides access to NVIDIA A100, H100, and other high-performance GPUs, along with high-bandwidth networking that supports demanding deep learning tasks. The platform integrates well with Azure Machine Learning, Kubernetes, and managed orchestration tools, which help teams automate pipelines and maintain consistent environments. Azure also supports regulated workloads and signs a BAA for organizations that handle ePHI. This combination of performance, tooling, and compliance makes Azure suitable for enterprise-level AI projects.

#### *Key Characteristics*

- Azure offers GPU-enabled virtual machines with NVIDIA A100, H100, and other accelerators that support large-scale training and inference tasks.
- Azure provides high-bandwidth networking options, including InfiniBand, which helps reduce communication delays in distributed training.
- Azure integrates with Azure Machine Learning and Kubernetes services, allowing teams to automate workflows and manage multi-node clusters efficiently.
- Azure supports HIPAA-eligible workloads and signs a BAA when required, making it suitable for organizations that handle ePHI.

## Specialized AI & High-Performance GPU Clouds

### ![](https://www.atlantic.net/wp-content/uploads/2025/05/coreweave.png)

### CoreWeave

CoreWeave is a specialized cloud platform designed for high-performance computing, visual effects, and large-scale AI workloads. Its infrastructure supports demanding deep learning tasks through fast provisioning, strong parallel processing, and high-bandwidth networking. Many research groups and engineering teams use CoreWeave for generative models, simulation pipelines, and distributed training jobs that require consistent throughput. In addition, the platform offers multi-GPU nodes and cluster-level scaling, which helps teams move from small experiments to large production workloads without major configuration changes. CoreWeave also provides predictable pricing and low-latency networking, which are important for continuous or batch-oriented training cycles.

#### *Key Characteristics*

- CoreWeave provides GPU instances with NVIDIA A100, H100, and other accelerators, supporting intensive AI workloads that require strong parallel processing and stable performance across long training cycles.
- CoreWeave supports high‑bandwidth networking, including InfiniBand, which reduces communication delays in distributed training and improves throughput for large‑scale deep learning tasks.
- CoreWeave offers large multi‑GPU nodes and cluster scaling that support generative models and simulation workloads, helping teams manage complex pipelines with consistent computational capacity.
- CoreWeave includes orchestration tools that help teams manage deployments, maintain reproducible environments, and coordinate multi‑node training jobs with predictable behavior.

![](https://www.atlantic.net/wp-content/uploads/2025/05/lambda.png)

### Lambda Labs

[Lambda](https://lambda.ai/) provides GPU cloud services designed for deep learning, scientific computing, and engineering workloads. Its platform includes on-demand GPU instances and dedicated multi-GPU servers that support long training cycles. Lambda offers access to NVIDIA A100, H100, and other accelerators, supported by high-bandwidth networking for distributed computation. In addition, Lambda Stack gives users a preconfigured environment with common deep learning frameworks, which reduces setup time and supports reproducible experiments across teams.

#### *Key Characteristics*

- Lambda provides GPU instances with NVIDIA A100, H100, and similar accelerators, supporting training and inference tasks that require consistent performance and strong computational throughput.
- Lambda supports high-bandwidth networking that improves communication efficiency in distributed training, helping teams manage large models and multi-node workloads effectively.
- Lambda includes Lambda Stack, which offers a preconfigured environment with widely used deep learning frameworks, reducing setup time and supporting consistent experimentation.
- Lambda offers dedicated multi-GPU servers suited for long-running or large-scale workloads, providing stable performance for research groups and engineering teams.

### ![](https://www.atlantic.net/wp-content/uploads/2026/02/hyperstack-logo.jpg)

### Hyperstack

[Hyperstack](https://www.hyperstack.cloud/) focuses on high-performance GPU infrastructure for AI, simulation, and data processing tasks. Its platform provides modern NVIDIA GPUs, including A100 and H100 models, supported by high-speed networking for distributed workloads. Hyperstack emphasizes predictable performance through dedicated GPU instances, which helps teams avoid resource contention during training. The platform also integrates with containerized workflows and orchestration tools, supporting consistent environments across experiments and production pipelines.

#### *Key Characteristics*

- Hyperstack offers dedicated GPU instances with NVIDIA A100 and H100 accelerators, supporting deep learning workloads that require stable performance and strong computational capacity.
- Hyperstack provides high-speed networking that supports distributed training and large-scale computation, helping teams manage communication overhead in multi-node environments.
- Hyperstack integrates with containerized workflows, supporting consistent environments for experimentation and deployment across research and production teams.
- Hyperstack focuses on predictable performance by using dedicated GPU nodes, reducing contention and supporting long training cycles with consistent throughput.

## Flexible & Cost-Optimized GPU Platforms

![](https://www.atlantic.net/wp-content/uploads/2025/08/runpod-logo.png)

### RunPod

[RunPod](https://www.runpod.io/) provides cloud GPU instances that focus on flexibility, ease of use, and cost-effective access to high-performance hardware. The platform is popular among researchers, independent developers, and small teams that need GPU resources without long-term commitments. RunPod offers both on-demand and community-based GPU options, enabling users to choose between dedicated performance and lower-cost shared environments. Its serverless GPU feature supports short tasks and rapid experimentation, while persistent pods enable users to maintain long-running training jobs. RunPod also integrates with containerized workflows, making it easier to deploy custom environments and manage reproducible experiments.

#### *Key Characteristics*

- RunPod offers on-demand GPU instances with NVIDIA A100, H100, and other accelerators for training and inference tasks.
- RunPod provides community GPU options that reduce cost for workloads that can tolerate shared environments.
- RunPod supports persistent pods for long-running training jobs and serverless GPU execution for short tasks.
- RunPod integrates with containerized workflows, helping teams maintain consistent environments and reproducible experiments.

![](https://www.atlantic.net/wp-content/uploads/2026/02/thundercompute.png)

### Thunder Compute

[Thunder Compute](https://www.thundercompute.com/) provides GPU cloud services designed for affordability, fast provisioning, and access to modern accelerators. Its platform includes NVIDIA A100 and H100 GPUs that support training and inference tasks across many AI domains. Thunder Compute is used by research groups, startups, and engineering teams that need flexible access to GPUs without long commitments. The platform supports containerized environments and simple deployment workflows, helping users begin training quickly and maintain consistent configurations.

#### *Key Characteristics*

- Thunder Compute offers GPU instances with NVIDIA A100 and H100 accelerators, supporting AI and machine learning tasks that require strong computational performance and stable throughput.
- Thunder Compute provides fast provisioning, helping teams begin training or inference jobs without delay and supporting rapid experimentation across different project stages.
- Thunder Compute supports containerized workflows that maintain consistent environments across experiments, helping teams manage reproducibility and reduce configuration overhead.
- Thunder Compute focuses on cost-effective access to GPUs, supporting teams with variable or exploratory workloads that benefit from flexible usage patterns.

### ![](https://www.atlantic.net/wp-content/uploads/2025/12/kamatera-logo-1.png)

### Kamatera

[Kamatera](http://www.kamatera.com) provides cloud infrastructure with a focus on flexibility, global reach, and customizable compute configurations. While it is not dedicated solely to GPU hosting, Kamatera offers GPU-enabled servers that support AI, rendering, and data processing tasks. The platform lets users configure CPU, RAM, storage, and GPU resources independently, helping teams match hardware to workload requirements. Kamatera also provides fast provisioning and a wide range of data center locations, supporting distributed teams that need consistent access to compute resources.

#### *Key Characteristics*

- Kamatera offers GPU-enabled servers suited for AI, rendering, and data processing workloads, supporting teams that require flexible access to specialized hardware.
- Kamatera supports independent configuration of CPU, RAM, storage, and GPU resources, helping teams match system specifications to the computational needs of each project.
- Kamatera provides fast provisioning and global data center locations that support distributed teams, helping maintain consistent access to compute resources across regions.
- Kamatera includes simple management tools and predictable pricing, supporting organizations that prefer customizable infrastructure without complex setup or long configuration cycles.

**Table 1: Comparative overview of GPU hosting providers**

| **Provider** **GPU Range** **Networking Strength** **Scale Orientation** **Compliance** **Deployment Maturity** **Pricing Flexibility** **Atlantic.Net** Mid-range GPUs Standard networking Small–medium workloads HIPAA-eligible Container support Fixed pricing **Azure** Broad (A100/H100) High-bandwidth options Medium–large workloads HIPAA-eligible Strong Kubernetes ecosystem Spot + reserved **RunPod** Broad (A100/H100) High-bandwidth options Small–medium workloads Not HIPAA-eligible Container-friendly Spot + marketplace **CoreWeave** Broad (A100/H100) High-bandwidth + InfiniBand Large-scale workloads Not HIPAA-eligible Strong orchestration tools Usage-based **Lambda** Broad (A100/H100) High-bandwidth options Medium–large workloads Not HIPAA-eligible Preconfigured deep learning stacks On-demand **Hyperstack** Broad (A100/H100) High-speed networking Medium–large workloads Not HIPAA-eligible Container-oriented Usage-based **Thunder Compute** Broad (A100/H100) Standard networking Small–medium workloads Not HIPAA-eligible Container-friendly Flexible pricing **Kamatera** Select GPU options Standard networking Small workloads Not HIPAA-eligible Customizable servers Fixed pricing |
| --- |
| **Provider** |
| **Atlantic.Net** |
| **Azure** |
| **RunPod** |
| **CoreWeave** |
| **Lambda** |
| **Hyperstack** |
| **Thunder Compute** |
| **Kamatera** |

## Why GPU Hosting Matters for AI and Machine Learning

Deep learning workloads demand more computational resources than traditional machine learning tasks. Deep learning models are heavier and complex, which requires more memory, faster interconnects, and strong parallel processing. Therefore, organizations rely on GPU hosting to meet these requirements. In addition, cloud-based GPU platforms provide high-performance clusters that reduce training time, enabling teams to test and update models more efficiently.

Moreover, AI workloads now extend beyond standard supervised learning. They often include Large Language Models (LLMs), multimodal systems, and distributed training across multiple GPUs. In this context, GPU hosting enables access to multi-GPU and multi-node setups without major changes to existing infrastructure. Consequently, organizations can conduct both early experimentation and full-scale production deployment effectively.

Furthermore, cloud GPU hosting provides operational and financial advantages. Organizations do not need to purchase or maintain physical hardware, and they can provision GPUs on demand. Similarly, they pay only for what they use, which helps with small operations to manage costs efficiently while large enterprises can support distributed workloads across regions.

Therefore, GPU hosting has become an effective choice for organizations. It enables faster development, broader experimentation, and reliable deployment of advanced AI systems.

## Key Factors for Choosing a GPU Hosting Provider

Choosing a GPU hosting provider requires understanding performance needs, pricing structure, scalability options, and security expectations. Each factor influences the platform’s ability to support deep learning workloads. Therefore, evaluating these elements carefully helps organizations make informed decisions.

Below are the main factors to consider when selecting a GPU hosting provider.

### Performance requirements

A provider should offer GPUs capable of handling large and complex models. For example, NVIDIA A100, H100, and H200 GPUs provide high memory bandwidth and compute power. In addition, multi-GPU support and high-speed interconnects such as NVLink or InfiniBand reduce communication delays and improve throughput. Consequently, these features are important for distributed training and high-volume workloads.

### Pricing and cost structure

Cost is an important factor in resource planning. On-demand instances suit shorter or irregular workloads, while reserved instances work better for longer or predictable training cycles. Similarly, spot or marketplace pricing can lower expenses when workloads tolerate interruptions. Therefore, understanding pricing options helps align infrastructure with budget and project requirements.

### Scalability and orchestration

Many deep learning workloads require multi-GPU nodes or multi-node clusters. Providers with mature Kubernetes support or built-in cluster management tools simplify scaling. In addition, orchestration tools help automate deployments and maintain consistent environments. Therefore, scalability options and orchestration capabilities are key factors in provider evaluation.

### Security and compliance

Ensuring the protection of sensitive or regulated data is a critical factor when choosing a GPU hosting provider. TLS 1.2/1.3 for data in transit, encryption at rest, and access controls such as RBAC and IAM help maintain secure environments. In addition, compliance documentation and agreements, including BAAs, ensure adherence to legal and regulatory standards. Consequently, security and compliance are key factors in provider selection.

## GPU Containers and Deployment Strategies for Deep Learning

GPU containers play an important role in hosting deep learning workloads because modern models depend on consistent execution environments. Deep learning pipelines often fail when software versions differ across systems. Therefore, containerization helps reduce configuration differences and supports reproducible training and inference.

Docker is commonly used to package deep learning frameworks such as PyTorch, TensorFlow, and JAX. In addition, containers include CUDA, cuDNN, and other required GPU libraries. By fixing exact software versions inside the container image, organizations reduce setup effort and maintain stable behavior during long training processes. Consequently, model development becomes more predictable across different environments.

At larger scale, Kubernetes supports orchestration of GPU workloads across multiple nodes. GPU-aware schedulers and device plugins treat accelerators as managed resources. Therefore, multi-GPU and distributed training workloads run in a more controlled manner. Moreover, these mechanisms align with existing platform engineering practices used for other services, which improves operational consistency.

Vendor ecosystems further support container-based deployment. NVIDIA NGC provides pre-built containers with optimized frameworks and GPU communication libraries. As a result, development groups spend less time creating custom environments. Cloud platforms also provide container-optimized operating systems and GPU-enabled runtimes that integrate with managed Kubernetes services. This integration reduces operational effort and improves deployment reliability.

Together, containerization and orchestration form the foundation of modern deep learning deployment. The same container images and configuration files run across local systems, private infrastructure, and cloud GPU platforms. Therefore, hybrid and multi-cloud strategies become easier to manage. In addition, updates to models and dependencies follow a structured process, which supports stable CI/CD workflows for machine learning systems.

## Pricing and Cost Optimization for GPU Hosting

Pricing is an important consideration in GPU hosting for deep learning because workloads differ in size, duration, and hardware needs. Therefore, training cost depends on GPU type, memory capacity, and total runtime. In addition, selecting the correct accelerator directly affects budget planning. High-performance GPUs such as NVIDIA A100 and H100 provide faster training. However, they also involve higher hourly charges. In contrast, mid-range GPUs may suit smaller models or inference tasks. Consequently, matching hardware selection with workload requirements helps control overall spending.

Cloud platforms also provide different pricing models that influence total cost. For example, on-demand pricing supports short experiments and irregular workloads. In comparison, reserved capacity provides stable pricing for long-running or predictable training jobs. Moreover, marketplace and spot GPUs offer lower hourly rates. However, these options may introduce interruptions, which can affect extended training cycles. Similarly, multi-GPU nodes increase hourly cost. Nevertheless, they reduce training time, which can lower total expense for LLMs and distributed workloads.

Additional cost factors further affect GPU hosting expenses. For instance, storage costs increase as datasets and model checkpoints grow. Likewise, networking charges rise during distributed training or when transferring data across regions. Therefore, monitoring resource usage helps identify idle GPUs and inefficient storage patterns. In addition, careful planning of data placement reduces unnecessary transfers. Consequently, cost optimization becomes a continuous process rather than a one-time decision.

Overall, effective pricing management depends on hardware selection, pricing model choice, and ongoing monitoring. Therefore, organizations can control GPU hosting costs while supporting active deep learning development and experimentation.

## Concluding Considerations for GPU Hosting Selection

Selecting a GPU hosting platform depends on workload size, regulatory requirements, and expected training duration. These factors influence hardware choice, networking configuration, and deployment architecture.

Cloud GPU hosting provides scalable compute resources, enabling distributed training and faster iteration cycles for LLMs and advanced architectures. Reviewing infrastructure, pricing, and deployment strategy together supports long-term planning and sustainable AI development.

.

 


---

# Dedicated Hosting – In-Depth Buyer’s Guide

> URL: https://www.atlantic.net/dedicated-server-hosting/dedicated-hosting-in-depth-buyers-guide/ | Published: 2026-02-15 | Updated: 2026-06-23 | Author: Richard Bailey

Dedicated hosting is still the simplest answer when you need consistent performance, full isolation, and predictable costs. A dedicated server is exactly what it sounds like: one physical machine, reserved for one customer, hosted in a provider’s data center. You rent the hardware and network, and you control what runs on it (OS, applications, security configuration, and day-to-day ops—unless you buy [managed services](https://www.atlantic.net/managed-services/)).

They are still the primary choice for resource-intensive workloads (high-traffic e-commerce, databases, AI inference), regulated industries requiring compliance ([HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/what-is-hipaa-cloud/), [PCI DSS](https://www.atlantic.net/pci-compliant-hosting/pci-dss-4-0-is-mandatory-a-hosting-checklist-for-2026/)), and organizations seeking to eliminate the variable costs of public cloud platforms. Today, we are seeing a shift toward “cloud repatriation,” utilizing dedicated hardware to stabilize IT budgets and maximize raw compute power.

Choose dedicated hosting if any of these are true:

- **Performance needs are non-negotiable**: You need predictable CPU, RAM, and disk I/O under load (databases, high-traffic sites, busy APIs, game servers).
- **Isolation is a requirement:** You want single-tenant hardware to reduce blast radius and simplify compliance boundaries.
- **Costs must be stable**: You prefer a fixed monthly bill instead of variable consumption charges.

Stick with cloud/VPS if you need rapid scaling up/down within minutes, or if workloads are unpredictable and you’re comfortable paying for burst billing.

## What is dedicated hosting, and how does it compare?

Dedicated hosting provides a single tenant (you) with a physical server. The provider manages power, cooling, and network connectivity, while you control the software stack from the operating system up.

### The 3 Main Hosting Models

| **Feature** | **Shared Hosting** | **Cloud Hosting** | **Dedicated Hosting** |
| --- | --- | --- | --- |
| **Resources** | Shared with hundreds/thousands | Partitioned (Virtual) | 100% Exclusive |
| **Performance** | Inconsistent | Good, but shared hardware | Maximum / Consistent |
| **Security** | High risk (neighbor impact) | Moderate (hypervisor isolation) | Physically Isolated |
| **Best For** | Small blogs, hobby sites | Scalable web apps | High traffic, Compliance |

## Understanding Dedicated Hosting

Dedicated hosting fits teams that have outgrown “good enough” infrastructure and now need a platform that behaves the same way every day—especially under peak load.

### Who is Dedicated Hosting For?

- **High-traffic websites:** Sustained heavy traffic where variability causes real revenue loss.
- **E-commerce:** Transaction-heavy stores that need speed, security, and stable database performance.
- **Resource-intensive apps:** Big databases, analytics jobs, media processing, ML workloads, game servers.
- **Security and compliance-driven businesses:** Single-tenant infrastructure can simplify controls and reduce shared-risk exposure.

### What to Look For in a Dedicated Hosting Provider

#### Hardware quality and options

- **Processor choices:** Look for modern, enterprise-grade CPU options (avoid providers still pushing decade-old chips).
- **RAM quality:** ECC RAM is the baseline for production stability.
- **Storage technology:** Ensure options for [SSD and NVMe](https://www.atlantic.net/dedicated-server-hosting/whats-the-difference-between-hdds-sata-ssds-and-nvme-ssds/) (and HDD where it makes sense for bulk storage/backup).

#### Data center and network infrastructure

- **Data center specs**: Power redundancy, cooling design, and physical security should be clearly stated.
- **Network performance:** Ask about backbone connectivity, capacity, and SLA language (not just marketing claims).
- **DDoS protection:** Prefer providers that include meaningful mitigation by default.

#### Support and SLAs

When physical hardware fails, the provider’s operational maturity shows up immediately.

- **24/7 on-site support:** Hardware incidents don’t wait for office hours.
- **Hardware replacement SLA:** You want a written guarantee that failed components are replaced fast.
- **Managed vs unmanaged:** Align support to your team’s skills and risk tolerance.

Atlantic.Net’s [Dedicated Server Service Level Guarantee](https://www.atlantic.net/dedicated-server-service-level-guarantee/) includes 100% network uptime (excluding scheduled maintenance) and a one-hour hardware replacement commitment once the cause is determined.

#### Pricing, contracts, and setup

- **Contract length:** Longer terms often reduce monthly cost, but reduce flexibility.
- **Setup fees:** Some providers charge for provisioning; confirm if it’s waived on longer commitments.
- **Customization:** The best providers let you size CPU/RAM/storage to the workload instead of forcing “cookie-cutter” bundles.

## What to buy: server hardware and services

### Processor

CPU selection is usually a trade between core count and per-core speed.

- **Cores:** Better for parallel workloads (web tiers, container density, background job queues).
- **Clock speed:** Better for latency-sensitive or single-thread heavy workloads (some DB operations, legacy apps).

### Memory

RAM is the most common bottleneck in real-world hosting.

- **Rule of thumb:** Size for peak usage with headroom; don’t run production memory at the edge.
- **Baseline:** ECC RAM for stability.

### Storage and RAID

Storage impacts both performance and fault tolerance.

#### Drive types:

- **SATA HDD:** Bulk storage/backups (very cheap, slow).
- **SAS HDD:** Better mid-range HDD option (faster/more reliable than SATA HDD).
- **SATA SSD:** Default for most production workloads.
- **NVMe SSD:** Best for database latency and high IOPS needs.

#### RAID configs:

- **RAID 1:** Simple mirroring, solid baseline for reliability.
- **RAID 5/6:** Balance of capacity and protection (with rebuild considerations).
- **RAID 10:** Best performance + redundancy, higher cost.

### Bandwidth and network

- **Port speed:** 10 Gbps is common; higher ports matter for heavy traffic, backups, and large file delivery.
- **Transfer allowance:** Many dedicated plans include a large monthly transfer at a flat rate—confirm overage pricing.

## Why use dedicated hosting?

- **Unmatched performance:** Full resources, no virtualization overhead, no contention.
- **Complete control:** OS, kernel tuning, security stack, and software layout are entirely yours.
- **Enhanced security and privacy:** [Single-tenant](https://www.atlantic.net/dedicated-server-hosting/achieving-unparalleled-security-with-single-tenant-dedicated-hosting/) environments reduce shared-risk exposure.
- **Predictable costs:** Stable monthly pricing supports simpler budgeting.

## Dedicated hosting trade-offs

### The good

- **Performance:** Dedicated resources.
- **Control:** Full administrative access.
- **Security:** Physical isolation.
- **Billing:** Predictable monthly cost.

### The bad

- **Cost:** Higher than entry-level cloud/shared options.
- **Ops responsibility:** Unmanaged servers require real admin and security ownership.
- **Scaling speed:** Upgrades are not instant; some changes require downtime.
- **Commitment:** Best pricing often means longer contracts.

## What to decide before you buy

### Your technical requirements

- **OS and stack:** Know exactly what you’re deploying and what it needs.
- **Capacity:** Validate CPU/RAM/storage/GPU with real metrics or testing.
- **Traffic:** Use analytics to estimate realistic bandwidth and growth.
- **RAID:** Plan for drive failure as a normal event, not a surprise.

### Your budget

- **Monthly max:** Include licenses, backups, and security tooling.
- **Fees:** Confirm setup fees and contract discounts.

### Your operational capability

- **Ownership:** Decide who is on-call for patching, incidents, and security alerts.
- **Managed help:** If you don’t have deep admin coverage, managed services reduce risk.

## Setting yourself up for success

### Strategy: design for hardware failure

**Solution:** Use RAID plus an enforceable hardware replacement SLA so a failed drive doesn’t become a multi-day outage.

### Strategy: size for growth, not just today

**Solution:** Choose configurations that keep peak utilization below a comfortable threshold so the server remains responsive under pressure.

### Strategy: build a secure baseline on day one

**Solution:** Patch discipline, minimal exposed ports, strong auth, and monitoring are mandatory—especially on unmanaged servers.

### Strategy: keep contract flexibility early

**Solution:** Start month-to-month if you’re uncertain, then commit longer once sizing is proven.

## Atlantic.Net vs “hyper scale” and volume providers

Some large providers operate on fixed, mass-market configurations, which can limit flexibility. This guide’s key point is straightforward: custom sizing and direct access to experienced engineers tend to matter more as workloads and risk increase.

If you want hard SLA specifics, Atlantic.Net publishes a Dedicated Server[Service Level Guarantee](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/) covering network uptime (100%), hardware replacement (one hour once the cause is determined), and infrastructure availability (100%), with refund terms and exclusions spelled out.

## Questions to ask a dedicated hosting expert

1. **Workload fit:** When is dedicated the better choice than cloud for my specific application?
2. **Sizing pitfalls:** What do customers most often under-spec, and how do we avoid it?
3. **Storage reality:** Should the database live on NVMe, and what RAID layout makes sense?
4. **Ops model:** Should we go managed, unmanaged, or hybrid?
5. **SLA clarity:** What is your written time-to-replace for failed components, and what triggers the clock?
6. **Security baseline:** What’s included by default vs what we must implement ourselves?

## FAQ

**Q: Is dedicated hosting more expensive than cloud?**

A: It depends on scale. For small, variable workloads, the cloud is cheaper. For steady, resource-heavy workloads (e.g., a database using 100% CPU 24/7), dedicated hosting is often 30–50% cheaper because you don’t pay per-minute compute or egress fees.

**Q: Can I run a hypervisor (VMware/Proxmox) on a dedicated server?**

A: Yes. This is a common use case. You can rent a high-power [dedicated server](https://www.atlantic.net/dedicated-server-hosting) and slice it into 20+ instances for your internal teams, effectively creating your own [private cloud](https://www.atlantic.net/private-cloud-hosting/what-is-private-cloud-hosting/).

**Q: How long does it take to provision a dedicated server?**

A: Standard configurations are often available in under 4 hours. Custom builds (specific CPU/RAM combos) may take 24–48 hours for physical assembly and testing.

**Q: Do I need a dedicated GPU server?**

A: Only if you are running specific parallel processing workloads like [AI/ML inference](https://www.atlantic.net/cloud-platform/inference-cloud/), video transcoding, or 3D rendering. For standard web and database hosting, a strong CPU is more cost-effective.

**Q: What happens if a drive fails?**

A: If you have [RAID 1 or RAID 10](https://www.atlantic.net/dedicated-server-hosting/raid-0-1-5-6-10-50-advanced/), your server keeps running. You open a ticket, and the provider physically swaps the failed drive for a new one. The RAID controller then rebuilds the data automatically. Without RAID, you face total data loss.


---

# Top Dedicated Server Hosting for Small Businesses in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/top-dedicated-hosting-for-small-businesses/ | Published: 2026-02-15 | Updated: 2026-03-17 | Author: Dr. Tehseen Zia

 

Small businesses usually choose dedicated hosting when a cloud server stops being predictable: traffic spikes hurt performance, compliance needs tighten, or downtime becomes expensive.

Modern small business dedicated servers now require NVMe storage and DDR5 RAM as standard to handle the demands of 2026 applications, including local AI processing and high-volume e-commerce.

The right dedicated provider gives you:

- **Dedicated resources**
- **Clear management options (DIY or managed help)**
- **Reliable backups and monitoring**
- **Functional security controls**

The best dedicated hosting for small businesses in 2026 balances raw performance with proactive management. For businesses requiring high-security or healthcare compliance, Atlantic.Net is the top pick due to its SOC 2/3 and HIPAA-compliant infrastructure. For those focused on budget, IONOS offers competitive entry-level pricing with rapid deployment.

## 2026 Dedicated Hosting Comparison

| **Provider** | **Best for** | **Management options** | **OS options** | **Backup/monitoring** | **Notes to know** |
| --- | --- | --- | --- | --- | --- |
| **Atlantic.Net** | Compliance-ready hosting + tailored builds | Managed or unmanaged | Multiple OS options available | Backup + security add-ons available | Emphasis on PCI/HIPAA/HITECH readiness and add-on security services |
| **HostGator** | Businesses that want a common control-panel workflow | Full or semi-managed | Linux or Windows | DDoS + firewall | Hosted in a US-based Tier 3 data center (per provider page) |
| **Namecheap** | Teams that want management tiers + a clear upgrade path | User-responsible, basic, or complete management | Linux templates; Windows can be user-installed via IPMI | Weekly backups are offered with complete management | Uptime guarantee details are in published terms |
| **Hostwinds** | Included monitoring + nightly backups on dedicated | Managed options available; customization emphasized | Varies by configuration | “Server Monitoring” + “Nightly Backups” | Good fit for businesses that want backup/monitoring baked in |
| **IONOS** | Dedicated servers with “unlimited traffic” positioning | Not clearly stated on the dedicated page | Linux or Windows | Varies by plan | Best for single-server workloads that need predictable transfer allowances |

## Why Small Businesses Need Dedicated Hosting

Small businesses hit a point where shared hosting and even cloud server plans stop being consistent. Dedicated hosting helps when you need:

- **Stable performance:** Your site and apps don’t share CPU/RAM with other customers.
- **More control:** You can tune the server for your stack (database, caching, runtime, security rules).
- **Stronger isolation:** Dedicated hardware reduces “noisy neighbor” risk and can simplify security reviews.
- **A cleaner growth path:** You can scale vertically (bigger box) or add dedicated nodes for specific roles.

Dedicated isn’t always the first step. If your workload is still moderate, a Cloud Server can be the simpler upgrade because scaling is usually faster. (See [FAQ](https://docs.google.com/document/d/1N2djioZyAKw33-lcb-yJrFQHzh25VRI4PuULLPfn9yc/edit?tab=t.0#heading=h.r01qbi9bk0ow)for a quick dedicated vs Cloud Server breakdown.)

## Why Dedicated Hosting Matters for Small Businesses in 2026

In 2026, the gap between shared resources and dedicated hardware has widened. Small businesses are increasingly moving away from “burstable” cloud instances in favor of dedicated servers to ensure consistent performance for resource-heavy tasks like data analytics, private AI model hosting, and secure database management.

### The Shift to NVMe and DDR5

Legacy SATA SSDs and HDDs are no longer the standard for business-critical applications. In 2026, NVMe storage provides read/write speeds exceeding 3,500 MB/s, which is essential for modern databases. Similarly, DDR5 memory has become the requirement for multitasking and high-traffic stability, offering nearly double the bandwidth of DDR4.

### Managed vs. Unmanaged

For most small businesses, Managed Dedicated Hosting is the correct choice. The provider handles security patches, OS updates, and hardware monitoring.

- **Managed Hosting:** Expect to pay $50–$120 more per month for the peace of mind that a sysadmin is monitoring your server 24/7.
- **Unmanaged (Bare Metal):** Best for businesses with in-house technical teams. You receive the hardware and a clean OS, but you are responsible for everything from firewalls to backups.

## Top Dedicated Hosting Providers for Small Business

### #1 – Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

**Best for compliance-ready dedicated hosting and tailored builds**

Atlantic.Net focuses on dedicated hosting with options to run managed or unmanaged servers and add security/backup services as needed. It’s a strong fit when you want a dedicated environment that can be shaped around compliance-driven requirements (or simply stronger operational controls) without building everything from scratch.

Below is Atlantic.Net’s cloud control panel interface used to deploy and manage dedicated and GPU servers.
 ![Atlantic.Net Server Panel](https://www.atlantic.net/wp-content/uploads/2026/01/Atlantic.net-server-panel.png)
 Image Source: Atlantic.Net

- **Key Specs:** Dedicated server options with managed or unmanaged deployments, multiple OS choices, and add-on security/backup services depending on needs.
- **Compliance**: Positioning includes PCI/HIPAA-compliant/HITECH readiness for our data center infrastructure. Provides a formal HIPAA Business Associate Agreement (BAA) for all healthcare clients. Once the BAA is signed, we work as your compliance partner.
- **Support**: 24x7x365 USA-based support via phone and email
- **Verdict**: Choose Atlantic.Net if you want a dedicated server that can be configured around security/compliance requirements, and you want optional managed help available.

**What stands out:**

- Managed or unmanaged server options
- Security and backup add-ons available (firewalls, IDS, backups, DDoS, WAF options)

**Who should choose Atlantic.Net?:** Small businesses handling sensitive data, regulated workloads, or complex environments that benefit from a compliance-ready posture and add-on security services.

### #2 – HostGator

![](https://www.atlantic.net/wp-content/uploads/2025/08/Hostgator-logo.png)

**Best for familiar control-panel workflows with managed vs semi-managed options**

HostGator’s dedicated offering provides full server resources with a choice between managed and semi-managed support. It includes DDoS protection and an IP-based firewall, which fits small teams that want baseline protection.

Here is the HostGator cPanel dashboard, where you can manage websites, databases, email accounts, and hosting settings from a centralized interface.

![HostGator-cPanel-dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/HostGator-cPanel-dashboard-1.png)

Image Source: HostGator

- **Key Specs**: Dedicated servers with a choice of managed vs semi-managed support and common hosting workflows for small teams that want dedicated resources.
- **Compliance**:  No specific certifications are stated; treat compliance as workload-specific.
- **Support**: 24/7/365 chat + phone support and server monitoring.
- **Verdict**: Choose HostGator if you want dedicated hosting with a clear “managed vs semi-managed” choice and you prefer a mainstream hosting workflow.

**What stands out:**

- Full or semi-managed options
- DDoS protection + IP-based firewall
- A US-based Tier 3 data center

**Who should choose HostGator?:** Agencies and small businesses that want dedicated resources but don’t want to fully own server operations.

### #3 – Namecheap

![](https://www.atlantic.net/wp-content/uploads/2026/01/NameCheap-Logo.png)

**Best for tiered management options and published uptime terms**

Namecheap offers dedicated servers with multiple management tiers. Its materials explain how scaling works—typically moving to a higher-tier plan—and it publishes formal uptime guarantee terms.
 Let’s see the Namecheap dedicated hosting interface used to manage domains, deploy servers, and control hosting services from one place.

![Namecheap dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Namecheap-dashboard.jpg)

Image Source: NameCheap

- **Key Specs**: Dedicated servers with tiered management levels, optional control panel add-ons, and remote management access for hands-on teams.
- **Compliance**: Namecheap’s hosting legal terms say services are not intended to provide a PCI-compliant environment without further compliance activity—plan on owning compliance requirements and validation
- **Support**: 24/7 customer support; management tiers (User-Responsible/Basic/Complete).
- **Verdict**: Choose Namecheap if you want a provider that clearly describes management tiers and publishes formal uptime guarantee language.

**What stands out:**

- Management tiers (from self-managed to more fully managed support)
- Control panel options are explicitly listed on the dedicated server pricing page
- Uptime guarantee language is published in legal terms.

**Who should choose Namecheap?**Small businesses that want clear “support levels” without committing to full management from day one.

### #4 – Hostwinds

![](https://www.atlantic.net/wp-content/uploads/2025/08/hostwinds-logo.png)

**Best for built-in monitoring and nightly backups on dedicated**

Hostwinds includes monitoring and nightly backups directly on its dedicated server page. This is useful for lean teams that need operational basics handled consistently without adding extra services manually.

Explore the Hostwinds cloud hosting panel designed for managing server resources, configuring security settings, and monitoring performance in real time.
 ![Hostwinds WHM](https://www.atlantic.net/wp-content/uploads/2026/01/Hostwinds-WHM.jpg)

Image Source: Hostwinds

- **Key Specs:** Dedicated servers positioned around customizable configurations, with monitoring and backup features prominently included/available on dedicated offerings.
- **Compliance:** No dedicated-specific compliance certifications are stated.; confirm any compliance needs (e.g., audits/attestations) directly.
- **Support:** 24/7/365 availability.
- **Verdict:** Choose Hostwinds if you want dedicated hosting where monitoring and nightly backups are clearly part of the core value proposition.

**What stands out:**

- “Server Monitoring”
- “Nightly Backups”
- Customization options (RAM/CPU/disks/RAID)

**Who should choose Hostwinds?:** Businesses that want dedicated hosting with backup + monitoring front-and-center, especially if you don’t have a dedicated ops person.

### #5 – IONOS

![](https://www.atlantic.net/wp-content/uploads/2025/08/ionos-logo.png)

**Best for dedicated servers positioned around “unlimited traffic.”**

IONOS positions its dedicated servers with “unlimited traffic,” which is useful for small businesses that need predictable transfer allowances without calculating monthly bandwidth costs.

Look at the IONOS Cloud control panel showing server image management, infrastructure configuration, and US data center deployment options.
 ![IONOS cloud panel](https://www.atlantic.net/wp-content/uploads/2026/01/IONOS-cloud-panel.png)
 Image Source: IONOS

- **Key Specs**: Multiple hardware categories (AMD/Intel/Storage/GPU) with Linux/Windows options.
- **Compliance**: FAQ mentions ISO-certified data centers and basic security measures like firewall rules.
- **Support**: 24/7 expert support via phone/chat/email.
- **Verdict**: Choose IONOS if your priority is predictable transfer allowances and you’re selecting a dedicated option for a straightforward single-server workload.

**What stands out:**

- “Unlimited traffic” positioning
- Dedicated servers are offered with Linux or Windows
- Multiple dedicated server categories are listed (AMD/Intel/storage/GPU)

**Who should choose IONOS?:** Small businesses that want a dedicated option with predictable traffic positioning and simple plan selection.

## Making Your Decision

Use this short process to avoid overbuying:

1. **Confirm the need:** If your issue is occasional load spikes, a cloud server upgrade may be enough.
2. **Pick a management model:** If you cannot patch, secure, and troubleshoot the OS, prioritize managed help.
3. **List non-negotiables:** Backups, monitoring, OS, control panel preference, and compliance needs.
4. **Test support:** Ask a pre-sales question about your specific stack or security needs.

## The Atlantic.Net Difference

When you purchase bare metal servers from [Atlantic.Net](https://www.atlantic.net/), you are investing in more than just hardware. You are partnering with a web hosting company that has a proven, decades-long history of delivering high-level performance, robust security, and expert support.

With a wide range of configurations, each of which can be tailored to your specific needs and requirements, it is hugely beneficial. We maintain a sharp focus on compliance, so you can build your infrastructure with confidence.

For businesses that need top performance from their hosting, [Atlantic.Net](https://www.atlantic.net/) presents a very strong option.

To explore the full range of our Dedicated Hosting Solution, email us at [sales@atlantic.net](mailto:sales@atlantic.net) or visit [https://www.atlantic.net/dedicated-server-hosting/](https://www.atlantic.net/dedicated-server-hosting/)

## FAQ

**Do I really need a dedicated server for a small business website?**

Not always. Many small businesses start with shared hosting, then move to Cloud Servers when traffic and app complexity increase. Dedicated makes sense when performance must stay stable under load, when you need deeper control over security settings, or when compliance reviews are pushing you toward hardware isolation.

**What’s the difference between cloud hosting and dedicated hosting?**

A dedicated server is an entire physical machine reserved for one customer. A Cloud Server is a virtualized slice of a physical server; it can be cost-effective and easier to scale, but you don’t control the full physical box. Dedicated can offer more isolation and consistent performance, while Cloud Servers are usually easier to resize quickly.

**What does “managed dedicated hosting” typically include?**

Managed offerings commonly cover OS-level updates, monitoring, and help with troubleshooting core services. The exact boundary matters: some providers won’t support custom software stacks, and some limit what they’ll change without a request. Always confirm what’s included before you assume patching and hardening are “handled.”

**What should I prioritize first: CPU, RAM, or storage?**

For many small business workloads, RAM and storage performance (SSD/NVMe) are the first bottlenecks, especially with databases and CMS platforms. CPU becomes the limiting factor when you run heavy compute tasks, lots of concurrent requests, or background jobs. Start by measuring what’s currently maxing out.

**How important are backups if the host offers monitoring?**

Monitoring tells you something broke; backups help you recover when it does. Ideally, you want both: monitoring for early warning and backups for rollback and disaster recovery. Also, confirm how restores work (self-serve vs support ticket) and how long backups are retained.

**Can I host multiple websites on one dedicated server?**

Yes. Dedicated servers are commonly used to host multiple sites, apps, and services—especially if you need consistent performance and full configuration control. The practical limit depends on your server resources and how heavy each site/app is.

**How do I choose a data center location?**

Choose the region closest to the majority of your customers if latency affects conversions or app responsiveness. If you serve multiple regions, consider a dedicated server near your primary audience and use a CDN for global static content. For regulated data, location may also be dictated by contractual or legal requirements.


---

# The Best Dedicated Server Hosting Providers for 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/the-best-dedicated-hosting-providers/ | Published: 2026-02-15 | Updated: 2026-06-23 | Author: Robert Agar

Dedicated server hosting remains the gold standard for organizations requiring maximum performance, strict data isolation, and total hardware control. Unlike shared or Cloud Server environments, a dedicated server provides 100% of the underlying CPU, RAM, and storage resources to a single tenant. In 2026, the market has shifted toward “[Bare Metal Cloud](https://www.atlantic.net/dedicated-server-hosting/bare-metal-cloud-servers-for-high-performance-workloads/)“—dedicated hardware that can be deployed via API in minutes rather than days.

[Dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/) means you get isolated physical resources for your workloads, which helps with predictable performance, tighter security controls, and more configuration freedom than shared hosting or many virtualized plans.

Dedicated hosting can mean two things: a traditional [single-tenant dedicated server](https://www.atlantic.net/dedicated-server-hosting/achieving-unparalleled-security-with-single-tenant-dedicated-hosting/), or a cloud model where you lease dedicated hosts or sole-tenant nodes to run VMs with hardware isolation. The best provider depends on whether you want hands-on control, managed operations, compliance support, or cloud-native scaling and placement control.

Use the table below to match the model to your use case.

## Comparison Table

| **Provider** | **Dedicated model** | **Best for** | **Automation/IaC fit** | **Security layer options** | **Notes** |
| --- | --- | --- | --- | --- | --- |
| **Atlantic.Net** | Dedicated servers / bare metal | Compliance-forward dedicated hosting | Varies by managed level | Depends on plan/architecture | Good fit for regulated workloads and controlled environments |
| **PhoenixNAP** | Bare Metal Cloud (BMC) | DevOps teams treating infra as code | Terraform + Ansible support | Depends on the architecture | API-first bare metal workflows ([phoenixNAP \| Global IT Services](https://phoenixnap.com/bare-metal-cloud)) |
| **Gcore** | Dedicated servers + CDN ecosystem | High-traffic media and gaming | Mix of product-driven tooling | CDN + DDoS options | Designed for edge delivery + protection ([gcore.com](https://gcore.com)) |
| **Amazon Web Services (AWS)** | EC2 Dedicated Hosts | BYOL + AWS ecosystem integration | Strong (cloud-native automation) | Broad security services | Host reservation + placement control |
| **Microsoft Azure** | Azure Dedicated Host | Microsoft-centric infrastructure | Strong (cloud-native automation) | Broad security services | Host isolation for Azure VMs |
| **Google Cloud Platform (GCP)** | Sole-tenant nodes | GCP VM isolation requirements | Strong (cloud-native automation) | Broad security services | Dedicated nodes for Compute Engine VMs |
| **Hostwinds** | Dedicated servers | Traditional dedicated hosting workflow | Depends on approach | Depends on add-ons | Familiar “rent a server” model |

## What is dedicated server hosting?

Dedicated server hosting is a model where one customer rents a physical server and gets isolated compute resources. This is often chosen for consistent performance under load, stronger isolation than shared environments, and deeper configuration control. The tradeoff is operational responsibility: you (or a managed provider) must secure, patch, monitor, and maintain the OS and application stack.

## Dedicated server vs Bare Metal Cloud vs Dedicated Host vs Sole-tenant Nodes

These terms are related but not identical:

- **Dedicated server (traditional):** A full physical machine assigned to one customer.
- **Bare Metal Cloud (BMC):** Bare metal delivered with cloud-like provisioning (API-first, fast deploy, automation workflows).
- **Dedicated host (cloud):** A physical host reserved for you, where you place virtual machines with host-level isolation.
- **Sole-tenant node (cloud):** A dedicated compute node reserved for your projects to run isolated VMs (GCP terminology).

If your requirement is “one tenant per physical hardware,” any of these can work. The right choice depends on whether you want traditional server administration, cloud-like provisioning, or VM placement controls inside a hyperscaler.

## The Best Dedicated Hosting Providers in 2026

### #1 – Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

**Best for compliance-forward dedicated hosting**

Atlantic.Net offers dedicated hosting aimed at organizations that want isolated infrastructure with a strong focus on security controls and compliance-aligned operations. It’s a fit for teams that value provider experience in regulated environments and want a dedicated model that can be tailored to internal governance needs.

Below is Atlantic.Net’s cloud control panel interface used to deploy and manage dedicated and [GPU servers](https://www.atlantic.net/gpu-server-hosting/a-guide-to-gpu-server-hosting-options/).
 ![Atlantic.Net Server Panel](https://www.atlantic.net/wp-content/uploads/2026/01/Atlantic.net-server-panel.png)
 Image Source: Atlantic.Net

- **Key Specs:** Dedicated servers commonly built on Intel Xeon Scalable and Intel Xeon E-series processor
- **Compliance:** Compliance hosting positioning across HIPAA/HITECH, PCI, GDPR, and SOC requirements; HIPAA hosting is described as SOC 2 and SOC 3 certified and HIPAA/HITECH audited.
- **Support:** 24/7/365 USA-based phone and email support (not outsourced) is stated for dedicated hosting.
- **Verdict:** Choose Atlantic.Net if you need dedicated infrastructure built for controlled, audit-aware operations and regulated workloads.

**What Stands Out:**

- Compliance-forward hosting positioning for regulated use cases
- Dedicated server and bare-metal options under one umbrella
- Operational focus on security controls and customer support

**Who Should Choose Atlantic.Net?:** Teams handling sensitive data that want dedicated infrastructure with compliance-ready operations.

### #2 – PhoenixNAP

![](https://www.atlantic.net/wp-content/uploads/2025/08/Phoenix-Nap-Logo.png)

**Best for infrastructure-as-code DevOps teams on bare metal**

PhoenixNAP has leaned hard into Bare Metal Cloud (BMC): bare metal delivered with cloud-style provisioning and automation. It’s designed for teams that treat infrastructure as code and want to spin up physical servers through APIs and repeatable workflows rather than manual tickets and one-off builds.

Explore PhoenixNAP’s Bare Metal Cloud dashboard interface used to deploy and manage dedicated servers, Kubernetes clusters, billing, and infrastructure resources.
 ![PhoenixNAP dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/PhoenixNAP-bmc-portal-home-page.webp)
 Image Source: PhoenixNAP

- **Key Specs:** Bare Metal Cloud with API-driven provisioning; official Terraform provider and an Ansible Galaxy collection for Bare Metal Cloud automation.
- **Compliance:** [PCI-DSS](https://www.atlantic.net/pci-compliant-hosting/pci-dss-4-0-is-mandatory-a-hosting-checklist-for-2026/) validated service provider messaging for selected services; SOC 1 and SOC 2 audited language is published for US/EU locations.
- **Support:** 24/7/365 support hours and direct support contacts are published in the developer support documentation.
- **Verdict:** Pick phoenixNAP if you want bare metal with IaC-native workflows (Terraform/Ansible) and you prefer API-first provisioning over ticket-based builds.

**What Stands Out:**

- Official Terraform provider for managing Bare Metal Cloud resources
- Ansible Galaxy collection for interacting with BMC resources (create/delete/power actions)
- Strong fit for repeatable environments, CI/CD-driven infra changes, and standardized builds

**Who Should Choose PhoenixNAP?:** DevOps teams running IaC pipelines that need physical servers without losing automation speed.

### #3 – Gcore

![](https://www.atlantic.net/wp-content/uploads/2025/08/Gcore_Logo.jpg)

**Best for high-traffic media and gaming stacks needing CDN + DDoS + dedicated**

Gcore pairs dedicated servers with an platform built around delivery and protection layers. If your workload depends on low-latency content delivery, traffic spikes, or exposure to DDoS risk, having dedicated compute integrated with CDN and DDoS capabilities can simplify architecture and vendor sprawl.

Let’s see the Gcore dedicated hosting interface used to configure servers, monitor performance, and manage infrastructure resources easily.
 ![Gcore hosting](https://www.atlantic.net/wp-content/uploads/2026/02/Gcore-hosting.jpg)
 Image Source: Gcore

- **Key Specs:** Dedicated servers with published 99.9% uptime claim on the dedicated server configurator; CDN positioned for handling traffic surges and mitigating DDoS risk.
- **Compliance:** Publishes compliance positioning including ISO/IEC 27001 and PCI DSS (plus [GDPR](https://www.atlantic.net/vps-hosting/gdpr-compliance-for-global-managed-service-providers/)).
- **Support:** Technical support is documented as 24/7 with multiple contact channels (ticket/chat/email/phone/WhatsApp).
- **Verdict:** Choose Gcore if you want dedicated compute where edge delivery and DDoS protection are part of the same vendor stack.

**What Stands Out:**

- CDN offering positioned to handle traffic surges and mitigate denial-of-service risk
- Dedicated-server [DDoS protection](https://www.atlantic.net/vps-hosting/what-is-a-ddos-and-how-do-we-prevent-our-business-from-being-attacked/) documented as a dedicated service (including baseline protection concepts)
- Suitable for architectures where edge delivery and protection are first-class requirements, not add-ons

**Who Should Choose Gcore?:** Media and gaming teams that need dedicated servers and want CDN + DDoS layers tightly aligned.

### #4 – Amazon Web Services

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

**Best for BYOL on dedicated hosts in a cloud ecosystem**

AWS EC2 Dedicated Hosts provide physical hosts reserved for a single customer, designed to run EC2 instances with host-level isolation. This model is commonly used when license terms or internal policy require dedicated hardware, while still keeping cloud-native services around the compute layer.

Here is the AWS EC2 dashboard, where you can control instances, monitor status, and configure settings.

![AWS Instance](https://www.atlantic.net/wp-content/uploads/2026/01/AWS-Instance.png)

Image Source: AWS

- **Key Specs:** Dedicated Hosts are physically isolated EC2 servers; supports BYOL and host-level placement controls.
- **Compliance:** AWS publishes a compliance program and compliance resource center for certifications and audit artifacts.
- **Support:** AWS Support plans are published and vary by tier (technical support via paid plans).
- **Verdict:** Pick AWS Dedicated Hosts when you need cloud-native orchestration plus host isolation for policy or licensing reasons.

**What Stands Out:**

- Dedicated host model built for host-level placement and visibility
- Strong fit for license-driven deployments (BYOL scenarios)
- Access to the broader AWS service ecosystem

**Who Should Choose Amazon Web Services?**Enterprises standardizing on AWS that need dedicated hardware for licensing or isolation requirements.

### #5 – Microsoft Azure

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

**Best for Microsoft-centric organizations needing host isolation**

Azure Dedicated Host is designed for organizations that want host-level isolation for Azure virtual machines and control over VM placement on dedicated physical servers. It’s typically used by teams that want dedicated hardware while staying inside Azure’s governance and operational model.

Explore the Azure dashboard to organize resource groups, track usage, and manage cloud services from a centralized platform.

![Microsoft Azure](https://www.atlantic.net/wp-content/uploads/2026/01/Microsoft-Azure.png)

Image Source: Azure

- **Key Specs:** Azure Dedicated Host is a physical-server resource for hosting Azure VMs; deployment is supported via portal/CLI/REST/PowerShell guidance.
- **Compliance:** Azure maintains a compliance documentation library covering global standards and audit reports.
- **Support:** Azure support is plan-based; Azure publishes support plan comparisons and 24×7 incident submission for standard support.
- **Verdict:** Use Azure Dedicated Host when you need host isolation and want to keep identity, governance, and tooling inside Azure.

**What Stands Out:**

- Host isolation model for Azure VM deployments
- Aligns with enterprise Azure governance patterns
- Works well for standardizing deployments inside Azure

**Who Should Choose Microsoft Azure?:** Microsoft-first IT teams needing host-level isolation for Azure workloads.

### #6 – Google Cloud Platform

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

**Best for GCP VM isolation on dedicated hardware**

GCP sole-tenant nodes let you run Compute Engine VMs on dedicated hardware reserved for your use. This is often used for licensing constraints, isolation requirements, or workloads that need more control over where VMs run at the physical layer.

Manage cloud services with the Google Cloud dashboard, where you can create virtual machines, deploy applications, and analyze data using built-in tools.

![Google Cloud Dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Google-Cloud-Dashboard.png)

Image Source: Google Cloud

- **Key Specs:** Sole-tenancy gives exclusive access to a physical Compute Engine server dedicated to your project’s VMs.
- **Compliance:** Google Cloud publishes a compliance resource center and [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-in-the-age-of-ai/) guidance for GCP workloads.
- **Support:** Google Cloud publishes support offerings; premium support includes 24/7 response coverage for high/critical impact cases.
- **Verdict:** Choose sole-tenant nodes if you want dedicated hardware isolation but still need GCP-native services and VM-based operations.

**What Stands Out:**

- Dedicated node model for Compute Engine VM isolation
- Designed to support isolation and placement requirements
- Fits teams building around GCP-native services

**Who Should Choose Google Cloud Platform?:** GCP builders who need dedicated hardware for Compute Engine VMs due to policy or licensing.

### #7 – Hostwinds

![](https://www.atlantic.net/wp-content/uploads/2025/08/hostwinds-logo.png)

**Best for a traditional dedicated server workflow**

Hostwinds offers a classic dedicated-server experience for teams that want to rent a physical machine and run it as they see fit. It’s commonly evaluated by buyers who prefer a straightforward hosting workflow and a familiar operational model.

Explore the Hostwinds cloud hosting panel designed for managing server resources, configuring security settings, and monitoring performance in real time.
 ![Hostwinds WHM](https://www.atlantic.net/wp-content/uploads/2026/01/Hostwinds-WHM.jpg)
 Image Source: Hostwinds

- **Key Specs:** Dedicated servers with managed options; IPMI access is described for most dedicated servers.
- **Support:** 24/7/365 support via live chat and tickets is documented across hosting services.
- **Verdict:** Pick Hostwinds if you want conventional dedicated servers and you value clearly documented support channels and SLA language.

**What Stands Out:**

- Traditional dedicated server model many admins already understand
- Practical option for teams that don’t need hyperscaler primitives
- Straightforward hosting workflow

**Who Should Choose Hostwinds?:** Teams that want classic dedicated servers without switching to cloud dedicated host/node constructs.

## Benefits of dedicated server hosting

Dedicated hosting is commonly selected for:

- **Predictable performance:** Full access to server resources without shared contention.
- **Stronger isolation:** Reduced cross-tenant risk compared with shared environments.
- **Customization freedom:** OS, security tooling, and software stacks can be tailored.
- **Scaling options:** Upgrade the box (vertical) or add servers/nodes (horizontal), depending on the provider model.
- **Dedicated networking patterns:** Easier to apply consistent firewalling, IP management, and segmentation.

## When should your business use a dedicated server?

Dedicated hosting is typically worth it when:

- You run **mission-critical applications** that cannot tolerate performance variability.
- You need **server-level control** for custom software, security baselines, or governance policies.
- You have **regulatory or contractual requirements** that push you toward isolated infrastructure.
- Your team can **operate the server** (or you’re buying [managed services](https://www.atlantic.net/managed-services/) to cover operations).

## Qualities of top dedicated hosting companies

Before you buy, pressure-test the provider on:

- **Isolation clarity:** Exactly what is dedicated (entire server vs BMC vs host vs node).
- **Automation support:** APIs, Terraform providers, Ansible collections, and repeatability.
- **Security layers:** DDoS options, network controls, and monitoring integrations.
- **SLA language:** How uptime is defined, what’s excluded, and how credits work.
- **Regions and latency:** Where you can deploy relative to your users.
- **Support model:** Hours, escalation, and what “managed” actually includes.

## FAQ

**What’s the difference between a dedicated server and a Cloud Server?**

A Cloud Server is a virtual machine sharing a physical host with other tenants. A dedicated server assigns the full physical machine to one customer. Dedicated servers usually provide more predictable performance and isolation, while Cloud Server plans are often easier to scale quickly.

**Is “bare metal cloud” different from a dedicated server?**

Yes. A dedicated server is typically a single rented machine with a more traditional management workflow. Bare metal cloud aims to deliver bare metal with cloud-like provisioning: API-first deployments, fast server creation, and automation-friendly operations.

**Which dedicated option is best for infrastructure as code?**

Look for a provider with official IaC support (Terraform provider, Ansible collection) and an API that can create and modify servers reliably. PhoenixNAP’s BMC includes an official Terraform provider and an Ansible Galaxy collection geared toward BMC operations.

**Do CDN and DDoS protection matter for dedicated hosting?**

If your workload is public-facing and sensitive to spikes or attacks (streaming, gaming, ticketing, large launches), pairing dedicated compute with CDN and DDoS layers can reduce downtime risk and smooth delivery. Gcore positions both CDN and dedicated-server DDoS protection as part of its stack.

**Managed vs unmanaged dedicated hosting: which should I choose?**

Choose managed if you want help with OS updates, monitoring, security hardening, and incident response. Choose unmanaged if you have an internal team that wants full control and can handle patching, hardening, backups, and troubleshooting.

**Do cloud dedicated hosts replace traditional dedicated servers?**

They solve a similar isolation problem but operate differently. Dedicated hosts/sole-tenant nodes are built to run VMs with placement control and cloud service integration. Traditional dedicated servers are simpler when you want a physical box with direct server administration.

**Can I bring my existing software licenses to dedicated infrastructure?**

Often, yes—but it depends on the provider model and the license terms. Dedicated host models are commonly used when license agreements require dedicated hardware. Validate license requirements with your software vendor before migrating.

**How do I decide which provider is “best” for my workload?**

Start with the dedicated model you need (dedicated server vs bare metal cloud vs dedicated host/node). Then decide how much management you want to own. After that, compare automation support, security layers (including DDoS), regions, and SLA terms.

## Conclusion

The best dedicated hosting provider in 2026 depends on your operating model and risk profile. If you want compliance-focused dedicated infrastructure, Atlantic.Net is a strong fit. If you want bare metal with infrastructure-as-code workflows, PhoenixNAP stands out. If your workload depends on high-traffic delivery with integrated edge and protection layers, Gcore is a practical shortlist candidate. For dedicated hosts and sole-tenant models inside hyperscalers, AWS, Azure, and GCP are strong options when you want cloud-native placement control and service integration.

Get in touch with [Atlantic.Net’s dedicated hosting experts](https://www.atlantic.net/about-us/corporate-contact/) today to get started with a dedicated server tailored to your business needs.


---

# How to Choose a Bare Metal Hosting Provider for Your AI Project in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/how-to-choose-a-bare-metal-hosting-provider-for-your-ai-project-in-2025/ | Published: 2026-02-15 | Updated: 2026-03-18 | Author: Dr. Assad Abbas

Artificial Intelligence (AI) projects require infrastructure that is both powerful and reliable. Whether the work involves training deep learning models, running high-speed inference, or processing real-time analytics, AI workloads depend on consistent throughput, low latency, and a hardened security posture.

However, traditional virtualized cloud servers often struggle to meet these demands due to shared resources and variable performance, which can reduce overall efficiency and responsiveness.

This is why bare metal servers are increasingly used for AI. By providing direct access to dedicated physical hardware, bare metal hosting eliminates virtualization overhead, ensuring maximum availability of computing resources. Additionally, it offers greater control and customization, enabling AI teams to optimize both hardware and software configurations for their specific projects.

The best bare metal hosting provider for an AI project is the one that matches your workload type (training vs inference), your data risk profile, and your operating model (self-managed vs assisted). Start by sizing for GPU memory and storage throughput, then validate networking if you plan multi-node training. Next, confirm how you will provision, rebuild, patch, and roll back systems without slowing the team down. Finally, align security and compliance to written artifacts and contract terms. Once those basics are clear, use a categorized shortlist to pick the best fit for 2026

## What is bare metal hosting and why does it matter for AI?

Bare metal hosting gives you dedicated physical hardware for your project. That matters for AI because performance variance can waste GPU time, and GPU time is usually the most expensive part of your stack.

With dedicated hardware, you can reduce “noisy neighbor” effects, keep configurations stable, and control the full software stack (drivers, runtimes, kernel settings, storage layout, and security tooling).

Bare metal is most useful when:

- You need predictable throughput for training runs that last hours or days
- You run production inference where latency and stability matter
- You have data isolation requirements that are easier with single-tenant hardware
- You want full control over drivers, images, and host-level optimization

## When should you choose GPU bare metal instead of GPU cloud instances?

GPU cloud instances are often the fastest way to start., however, GPU bare metal is usually the better choice once any of these are true:

- Your GPUs are busy most days (steady utilization beats burst pricing models)
- You need stable, repeatable benchmarking across runs
- Your team needs host-level control (driver pinning, kernel modules, storage tuning)
- You want cleaner isolation boundaries for security reviews and audits
- You want a simpler cost model for long-running workloads

A simple rule: if you can’t tolerate variable performance or you expect steady usage, prioritize bare metal.

## AI sizing checklist

Use this to avoid buying “more server” instead of the right server.

### GPU and VRAM

- Match VRAM to model size + batch size + context length (inference) or optimizer states (training).
- Plan for headroom. If you run near VRAM limits, you lose time to tuning and failures.
- If multi-GPU is likely, confirm supported topologies and whether you can grow from 1 GPU to more later.

### CPU and system RAM

- Don’t starve GPUs. Data loading, preprocessing, and networking still need CPU.
- For many workloads, more RAM helps keep datasets and cache hot.

### Storage

- Prefer NVMe for local scratch space, checkpoints, and frequent reads/writes.
- For large datasets, confirm your plan for object storage or network storage and how it connects.

**Networking**

- Single-node work can succeed on standard networking.
- Multi-node training is a different requirement. Confirm east-west throughput and latency expectations before you commit.

## Security and compliance fit

AI projects frequently touch sensitive data (customer records, proprietary datasets, regulated information, or internal knowledge bases). Treat compliance as a scope question:

- What services and systems are in scope?
- What provider artifacts can you review (audit reports, security docs, contract addenda)?
- What responsibilities stay with your team (IAM, encryption, logging, patching, key management)?

If your use case requires a BAA or other contract terms, confirm what’s included and what configuration responsibilities remain with you.

## Operational fit for real teams

Bare metal is “simple” only when operations are planned. Before choosing a provider, confirm:

- Provisioning method (portal/API), rebuild time, and imaging approach
- How you apply OS/driver updates safely (and roll back)
- Backup and restore strategy for model artifacts and training checkpoints
- Your exit plan: how to export data and redeploy elsewhere using IaC and portable images

## Top bare metal hosting providers for AI projects (2026 shortlist)

Below, the list is grouped into categories to make comparisons easier. The provider comparison table comes first, followed by consistent provider cards.

### Provider comparison

| **Provider** | **Category** | **Best fit** | **Hardware control** | **Compliance path** | **Support model** |
| --- | --- | --- | --- | --- | --- |
| Atlantic.Net | Premium & Specialized | Regulated workloads + GPU hosting | High | Published compliance resources + contract alignment | Direct support options |
| IBM Cloud | Premium enterprise | Enterprise AI stacks and hybrid patterns | Medium–High (varies by product) | Enterprise governance programs | Tiered enterprise support |
| AWS | Premium enterprise | Broad ecosystem + global scale | Medium–High (dedicated and bare metal options exist) | Large compliance program (service-dependent) | Tiered support plans |
| Oracle Cloud Infrastructure | Premium enterprise | GPU bare metal + cluster patterns | High | Enterprise compliance posture (service/region dependent) | Enterprise support offerings |
| OpenMetal | Mid-range scalable | Private cloud / open infrastructure + dedicated GPU | High | Compliance depends on architecture and controls | Engineering-led support options |

## Premium & Specialized (Compliance-first)

### #1 – Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

**Best for compliance-forward GPU hosting with a smaller-provider operating model**

Atlantic.Net is a strong fit when you want GPU hosting options while keeping packaging and escalation paths straightforward. It’s also a practical choice when you need a provider that’s comfortable supporting regulated deployments and audit-driven environments.

Below is Atlantic.Net’s cloud control panel interface used to deploy and manage dedicated and GPU servers.
 ![Atlantic.Net Server Panel](https://www.atlantic.net/wp-content/uploads/2026/01/Atlantic.net-server-panel.png)
 Image Source: Atlantic.Net

- **Key Specs:** GPU-focused infrastructure options across dedicated and cloud-style provisioning, sized for AI workflows.
- **Compliance:** Compliance support is scope-based; confirm which services are eligible for regulated workloads and whether a BAA (or equivalent) applies to your use case.
- **Support:** Always-available support options; confirm escalation paths and response expectations for production workloads.
- **Verdict:** Best for teams that want GPU hosting with a clearer support path and a compliance-forward posture.

**What Stands Out:**

- Clear alignment to regulated and security-reviewed deployments
- Practical for teams that want fewer platform layers
- Good fit for production AI workloads that value predictability

**Who Should Choose Atlantic.Net?:** Teams running regulated or sensitive-data AI workloads that need a provider comfortable with compliance-driven operations.

## Premium enterprise providers (platform depth)

### #2 – IBM Cloud

![](https://www.atlantic.net/wp-content/uploads/2025/06/ibm-logo.png)

**Best for enterprise AI programs that combine cloud + hybrid workflows**

IBM Cloud is often shortlisted when enterprises need AI infrastructure choices that integrate with broader governance, hybrid patterns, and enterprise support structures.

Let’s see the IBM Cloud interface used to create resources, manage applications, and monitor storage and services across your environment.
 ![IBM Cloud](https://www.atlantic.net/wp-content/uploads/2026/01/IBM-Cloud.png)
 Image Source: IBM Cloud

- **Key Specs:** Cloud infrastructure with GPU and AI accelerator options designed for enterprise deployments.
- **Compliance:** Compliance varies by service and region; confirm scope, artifacts, and required controls for your workload.
- **Support:** Tiered support offerings; align on severity handling and escalation for AI production systems.
- **Verdict:** Best for enterprises that want GPU choice within an enterprise governance and hybrid-friendly approach.

**What Stands Out:**

- Enterprise-first operational posture
- Broad accelerator choices (service-dependent)
- Strong fit for standardized governance

**Who Should Choose IBM Cloud?:** Enterprises building AI programs that must align with broader governance and hybrid architecture.

### #3 – AWS

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

**Best for teams that want bare metal options plus the widest ecosystem**

AWS is commonly chosen when your AI stack benefits from a large ecosystem: storage, networking, managed services, and many deployment patterns. It can be a fit when you want dedicated hardware options without leaving a single platform.

Here is the AWS EC2 dashboard, where you can control instances, monitor status, and configure settings.

![AWS Instance](https://www.atlantic.net/wp-content/uploads/2026/01/AWS-Instance.png)

Image Source: AWS

- **Key Specs:** Broad compute portfolio, including bare metal instance options and GPU-backed compute families (availability varies by region).
- **Compliance:** Large compliance program, but requirements are service- and configuration-dependent; validate what is in scope.
- **Support:** Tiered support plans; confirm response targets and escalation for critical inference or training pipelines.
- **Verdict:** Best for teams that want platform breadth and many integration options, and can manage operational complexity.

**What Stands Out:**

- Many architecture choices within one ecosystem
- Strong integration across storage and networking services
- Good for teams standardizing on a single cloud stack

**Who Should Choose AWS?:** Teams that value ecosystem breadth and want multiple ways to run AI workloads at scale.

### #4 – Oracle Cloud Infrastructure

![](https://www.atlantic.net/wp-content/uploads/2025/08/Oracle-cloud-infrastructure.png)

**Best for GPU bare metal clusters and HPC-style networking patterns**

Oracle Cloud Infrastructure is a strong option when you want GPU bare metal patterns and cluster-oriented designs for AI and HPC workloads.

Take a look at the Oracle Cloud dashboard, where you can set up load balancers, manage billing, and deploy resources from a single panel.
 ![Oracle-dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Oracle-dashboard.jpg)
 Image SOurce: Oracle Cloud

- **Key Specs:** Bare metal instance options including GPU-focused configurations and cluster networking patterns (service/region dependent).
- **Compliance:** Compliance posture varies by region and service; confirm what applies to your workload and data residency needs.
- **Support:** Enterprise support offerings; align on incident communications and escalation.
- **Verdict:** Best for teams planning multi-node GPU patterns and wanting bare metal control within an enterprise cloud.

**What Stands Out:**

- Cluster-oriented bare metal positioning
- Practical for HPC-style AI training needs
- Good fit for teams that want bare metal control in-cloud

**Who Should Choose Oracle Cloud Infrastructure?:** Teams that want GPU bare metal plus cluster/network options for large AI workloads.

## Mid-range scalable (open/private cloud patterns)

### #5 – OpenMetal

![](https://www.atlantic.net/wp-content/uploads/2025/09/OpenMetal.png)

**Best for private AI infrastructure on open building blocks**

OpenMetal is positioned for teams that want dedicated GPU hardware with a private-cloud approach and open infrastructure patterns.

Here is the OpenMetal dashboard, where you can manage hardware assets, monitor servers, and configure infrastructure resources.
 ![Openmetal-dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Openmetal-dashboard.png)
 Image Source: OpenMetal

- **Key Specs:** Dedicated GPU servers and clusters designed for private infrastructure patterns.
- **Compliance:** Compliance depends on the controls you implement and the contract scope; confirm artifacts and responsibilities before production.
- **Support:** Engineering-led support options; confirm how architecture help and escalation work for AI workloads.
- **Verdict:** Best for teams that want open infrastructure patterns and dedicated GPU resources without multi-tenant variability.

**What Stands Out:**

- Private-cloud style control with dedicated hardware
- Fit for teams that want open platform patterns
- Good for predictable performance planning

**Who Should Choose OpenMetal?:** Teams building private AI infrastructure and prioritizing dedicated hardware with open building blocks.

## A Quick Checklist for Choosing a Provider

Use this checklist to run a short, real evaluation (not a slide-deck selection):

- Define workload: training, fine-tuning, batch inference, or real-time inference
- Confirm GPU requirements: VRAM, single vs multi-GPU, expected utilization
- Validate storage plan: NVMe scratch + where datasets/checkpoints live
- Check networking needs: single-node vs multi-node, latency expectations
- Confirm provisioning: images, rebuild speed, IaC support, access model
- Review security/compliance scope: contracts, artifacts, and responsibilities
- Test support: how fast you can reach the right engineer when it matters
- Run a pilot: benchmark, failover/rebuild drill, restore test, and exit test

## Final Thoughts

Bare metal is a strong AI foundation when you need predictable performance, isolation, and host-level control. The right provider is the one that matches your workload shape and your operating reality. If you’re unsure, run a two-week pilot and score providers on rebuild speed, stable performance, and how quickly support resolves real problems.

## Frequently Asked Questions

**Do I need bare metal to run AI workloads in production?**

Not always. Many inference workloads run well on virtualized GPU instances or managed platforms. Bare metal becomes more compelling when you need stable performance, steady utilization, or tighter isolation boundaries.

**What’s the difference between GPU bare metal and a GPU cloud instance?**

GPU bare metal is single-tenant physical hardware. GPU cloud instances are usually virtualized and may share underlying resources. Bare metal typically gives you more control and more consistent performance, at the cost of higher operational responsibility.

**What should I prioritize first: GPU model, VRAM, or networking?**

Start with VRAM and model fit. If you can’t fit the model and batch size, nothing else matters. Next, validate storage throughput and data pipeline speed. Networking becomes the priority when you plan multi-node training or very high concurrency.

**How do I validate a provider quickly before committing?**

Run a short pilot with your real stack. Deploy via IaC, measure training/inference throughput, test checkpointing and restores, and perform a “rebuild drill” to confirm you can recover fast.

**What compliance questions should I ask a provider?**

Ask what is in scope, which artifacts are available for review, and what contract terms apply. Confirm your responsibilities for access control, encryption, logging, patching, and key management.

**How important is support for AI bare metal?**

Very. Driver issues, kernel changes, storage behavior, and networking constraints can block progress fast. You want clear escalation paths, predictable response expectations, and someone who can troubleshoot beyond basic hosting tickets.

**How can I reduce lock-in if I choose bare metal?**

Use portable images, IaC, and standard tooling. Keep model artifacts in formats that move easily. Document your provisioning steps so you can re-create environments elsewhere without manual rebuilds.


---

# Top Online Courses for AI in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/top-online-courses-for-ai/ | Published: 2026-02-17 | Updated: 2026-02-24 | Author: Richard Bailey

Artificial intelligence is no longer just a future idea. It is now used in products, workflows, and business systems. As a result, the way professionals learn about AI has changed. In 2026, employers and AI-powered search tools look for verified, role-specific skills rather than general knowledge of artificial intelligence.

Today’s job market values hands-on skills in generative AI, large language models (LLMs), retrieval-augmented generation (RAG), agentic systems, evaluation, and AI safety. Basic ‘Intro to AI’ courses are being replaced by specialized certifications for real job roles, like LLM Engineer and AI Product Manager.

This guide analyzes the most relevant online AI courses, focusing on how AI systems are built and used today. Rather than ranking platforms by popularity, we look at how well they verify skills, the range of skills they teach, and how useful they are for real work. This helps you pick the best learning path for your career.

## Leading AI Courses and Certifications

Now let’s take a look at the leading online courses for AI. With so many options available, it can be tough to know where to start. From multi-course programs to quick lessons on a single tool, there’s something for everyone.

To help you choose, we have broken down the most respected platforms for learning AI in 2026.

![](https://www.atlantic.net/wp-content/uploads/2025/06/coursera-logo.png)

### **#1: Coursera – Best for AI Product Managers**

Coursera has established itself as a top resource for online learning, collaborating with over 200 leading universities and companies to offer a vast catalog of courses, specializations, and degrees.

Think of it as a one-stop shop for learning and business training.

Coursera’s strongest advantage is its ability to bundle AI skills into structured Professional Certificates and Specializations developed by leading universities and technology companies. These programs increasingly emphasize how AI systems are scoped, evaluated, governed, and integrated into products, rather than how models are built from scratch.

#### **Advantages:**

- Extensive selection of AI courses, from beginner to advanced levels.
- Specializations and Professional Certificates offer a structured learning path.
- Courses are often developed and taught by renowned university professors and industry experts from companies like Google and IBM.
- The platform’s user-friendly interface and mobile app make learning accessible.
- Many courses include hands-on projects, allowing students to apply their knowledge to real-world applications.

#### **Disadvantages:**

- While many courses can be viewed for free, earning a certificate and accessing graded assignments requires payment.
- The sheer volume of courses can be overwhelming for beginners to navigate.
- The quality of peer-graded assignments can sometimes be inconsistent.

#### **Ideal for:**

- AI Product Managers and applied AI professionals who need structured, role-aligned learning.
- Learners who value verified certificates from recognized universities and technology companies.
- Professionals seeking credential-backed proof of AI competency to support career growth or role transitions.

#### **Recommended Courses:**

- [**Generative AI with Large Language Models**](https://www.coursera.org/learn/generative-ai-with-llms)
- [**AI For Everyone**](https://www.coursera.org/learn/ai-for-everyone?index=prod_all_products_term_optimization.&utm_medium=sem&utm_source=gg&utm_campaign=b2c_emea_x_multi_ftcof_career-academy_cx_dr_bau_gg_pmax_gc_gb_en_m_hyb_25-04_x&campaignid=22490486852&adgroupid=&device=c&keyword=&matchtype=&network=x&devicemodel=&creativeid=&assetgroupid=6577627676&targetid=&extensionid=&placement=&gad_source=1&gad_campaignid=22483915359&gbraid=0AAAAADdKX6YtWM4BnfKDcQT2MK3SenobH&gclid=Cj0KCQjw0qTCBhCmARIsAAj8C4ZCJ7kSh6R7IQX02Yq4uRyd3Hfd3ajROQVftynaczywsiNEVCE_4s0aArD-EALw_wcB)
- [**Generative AI for Everyone**](https://www.coursera.org/learn/generative-ai-for-everyone?index=prod_all_products_term_optimization.&utm_medium=sem&utm_source=gg&utm_campaign=b2c_emea_x_multi_ftcof_career-academy_cx_dr_bau_gg_pmax_gc_gb_en_m_hyb_25-04_x&campaignid=22490486852&adgroupid=&device=c&keyword=&matchtype=&network=x&devicemodel=&creativeid=&assetgroupid=6577627676&targetid=&extensionid=&placement=&gad_source=1&gad_campaignid=22483915359&gbraid=0AAAAADdKX6YtWM4BnfKDcQT2MK3SenobH&gclid=Cj0KCQjw0qTCBhCmARIsAAj8C4ZCJ7kSh6R7IQX02Yq4uRyd3Hfd3ajROQVftynaczywsiNEVCE_4s0aArD-EALw_wcB)

![](https://www.atlantic.net/wp-content/uploads/2025/06/deeplearning-ai-logo.png)

### **#2: DeepLearning.AI – Best for Production-Grade LLM Engineers**

If you click any of the links above, you will notice that most of the content was provided by our next entry at number two – DeepLearning.AI. Founded by Andrew Ng, they have become well-known for high-quality, accessible education in deep learning and machine learning.

DeepLearning.AI’s newer LLM-focused curriculum reflects current industry needs: fine-tuning foundation models, designing RAG architectures, evaluating model outputs, and managing safety and reliability concerns. This makes it one of the clearest signals of job-ready LLM engineering capability.

Their courses are often delivered through Coursera, but they also host their own content. All courses are celebrated for their clarity and practical focus.

#### **Advantages:**

- Curriculum designed and taught by one of the most respected figures in AI.
- Focus on building a deeper understanding of the core concepts of deep learning.
- Emphasis on real-world applications and practical skills.
- The self-paced nature of the courses provides flexibility for learners.
- Strong community forums for students to collaborate and seek help.

#### **Disadvantages:**

- The course content is highly specialized in deep learning, so it may not be suitable for those seeking a broader overview of artificial intelligence.
- A foundational understanding of programming, particularly Python, is a prerequisite for most courses.

#### **Ideal for:**

- Aspiring machine learning engineers and data science professionals want to specialize in deep learning.
- Software engineers transitioning into LLM-focused roles.
- ML engineers upgrading from classical models to generative AI.

#### **Recommended Courses:**

- 
  - [**Deep Learning Specialization**](https://www.deeplearning.ai/courses/deep-learning-specialization/)**(Multiple Courses)**
  - [**Generative AI with Large Language Models**](https://www.deeplearning.ai/courses/generative-ai-with-llms/)
  - [**LangChain for LLM Application Development**](https://www.coursera.org/learn/generative-ai-with-llms)

 

![](https://www.atlantic.net/wp-content/uploads/2025/06/stanford-logo.png)

### **#3: Stanford University – Research-First AI Education**

As a world-renowned institution at the forefront of AI research and innovation, Stanford University offers a selection of its rigorous AI courses to a global audience online. These courses provide a taste of world-class education from the comfort of your home.

Most courses are paid for, some are based in virtual classrooms, but one thing to mention is that the quality of teaching and instructors is superb. Stanford is especially valuable for learners interested in new model design, optimization research, or advanced architecture. Those who want to be ready for production work right away will need extra hands-on training.

#### **Advantages:**

- Access to the same high-quality curriculum and lectures offered to on-campus students.
- Courses are taught by leading academics and researchers in the field of artificial intelligence.
- In-depth and theoretically grounded content that fosters a deeper understanding of the subject matter.
- Some courses are available for free, providing incredible value.

#### **Disadvantages:**

- The courses can be highly demanding and time-intensive, often requiring a significant commitment each week.
- The prerequisites in mathematics and computer science are often more stringent than on other platforms.
- While some courses are free to audit, obtaining a formal certificate or university credit can be expensive.

#### **Ideal for:**

- Highly motivated learners with a strong academic background in computer science or a related field.
- Individuals who are passionate about the theoretical underpinnings of artificial intelligence and want to learn from top professors.
- Those considering pursuing a graduate degree in AI who want to experience a university-level curriculum.

#### **Recommended Courses:**

- [**CS224N Natural Language Processing with Deep Learning**](https://online.stanford.edu/courses/cs224n-natural-language-processing-deep-learning)
- [**AI in Healthcare Specialization**](https://online.stanford.edu/programs/artificial-intelligence-healthcare)
- [**CS324 Advances in Foundation Models**](https://bulletin.stanford.edu/courses/2233671)

![](https://www.atlantic.net/wp-content/uploads/2025/06/ibm-logo.png)

### **#4: IBM – Enterprise AI Deployment and Governance**

IBM has a long history of innovation in artificial intelligence. The company uses this expertise to offer a range of professional certificates and courses designed to equip learners, including engineers, with job-ready skills. Most courses focus on products and services created by or offered by IBM.

#### **Advantages:**

- The curriculum is heavily focused on practical, in-demand skills and tools.
- Professional Certificates are designed to prepare learners for specific jobs in the AI industry.
- Courses often include hands-on labs and projects using IBM’s own AI platforms and tools.
- Earning a Professional Certificate from IBM can be a valuable credential for your resume.

#### **Disadvantages:**

- The course content has a strong focus on IBM’s proprietary technologies, which might not be as universally applicable as open-source alternatives.
- Some of the more comprehensive certificate programs require significant time and financial investment.

#### **Ideal for:**

- Teams deploying AI within structured IT and governance frameworks
- Learners who want to gain experience with enterprise-level AI tools and platforms.
- Professionals working in industries that heavily utilize IBM technologies.

#### **Recommended Courses:**

- [**IBM AI Engineering Professional Certificate**](https://www.coursera.org/professional-certificates/ai-engineer?utm_medium=sem&utm_source=gg&utm_campaign=b2c_emea_ai-engineer_ibm_ftcof_professional-certificates_cx_dr_bau_gg_sem_pr_gb_en_m_hyb_25-05_x&campaignid=22613217027&adgroupid=179808706546&device=c&keyword=ibm%20ai%20engineering%20professional%20certificate&matchtype=p&network=g&devicemodel=&creativeid=755412537350&assetgroupid=&targetid=kwd-1261349748844&extensionid=&placement=&gad_source=1&gad_campaignid=22613217027&gbraid=0AAAAADdKX6Y7-pTT6x36I5U6diq6gbmgZ&gclid=Cj0KCQjw0qTCBhCmARIsAAj8C4a_WI3GUwy-yjKUxc00qOUmKW0CDdEvzjqdW7nFJlBXske_dnBOwHkaAnXyEALw_wcB)
- [**Agentic AI: Developing AI Agents**](https://www.edx.org/learn/artificial-intelligence/ibm-agentic-ai-developing-ai-agents)
- [**IBM RAG and Agentic AI Professional Certificate**](https://www.coursera.org/professional-certificates/ibm-rag-and-agentic-ai)

![](https://www.atlantic.net/wp-content/uploads/2025/06/edx-logo.jpg)

### **#5: edX – Academic Verification Over Production Readiness**

Founded by Harvard and MIT, edX is another leading MOOC (Massive Open Online Courses) provider that hosts a wide array of courses from top universities and institutions. Its offerings in artificial intelligence and computer science are known for their academic rigor and quality, essential for your daily tasks .

#### **Advantages:**

- Courses from prestigious universities like HarvardX and MITx provide access to world-class education.
- MicroMasters programs offer a series of graduate-level courses that can sometimes count as credit toward a master’s degree.
- Many courses can be viewed for free, allowing learners to explore the material before committing to a paid certificate.
- The platform features a wide range of subjects within AI, including ethics and the societal impact of this technology.

#### **Disadvantages:**

- The user interface and platform experience can sometimes feel less modern than some of its competitors.
- The cost of verified certificates can be higher than on other platforms.

#### **Ideal for:**

- Academically-minded learners who want to delve into the theoretical foundations of artificial intelligence.
- Individuals interested in pursuing advanced degrees who want graduate-level coursework.
- Those who want to learn from the instructors at some of the world’s most respected academic institutions.

#### **Recommended Courses:**

- [**Mastering Generative AI: Agents with RAG and LangChain**](https://www.edx.org/learn/computer-science/ibm-mastering-generative-ai-agents-with-rag-and-langchain)
- [**Professional Certificate in Computer Science for Artificial Intelligence (HarvardX)**](https://www.harvardonline.harvard.edu/course/professional-certificate-computer-science-artificial-intelligence)
- [**Mastering Generative AI: Advanced Fine-Tuning for LLMs**](https://www.edx.org/learn/computer-science/ibm-mastering-generative-ai-advanced-fine-tuning-for-llms)

![](https://www.atlantic.net/wp-content/uploads/2025/06/udacity-logo.png)

### **#6: Udacity – Best for Project-Based Learning**

Udacity is known in the online education market with its “Nanodegree” programs, which are project-based and designed in collaboration with leading tech companies.

Their AI and machine learning Nanodegrees are highly regarded for their hands-on approach.

#### **Advantages:**

- The project-based curriculum ensures that participants gain practical, hands-on experience.
- Nanodegree programs are developed with input from industry experts, ensuring the skills learned are relevant to current jobs.
- The platform provides access to mentors and a student community for support.
- Career services, including resume reviews and LinkedIn profile optimization, are often included.

#### **Disadvantages:**

- Nanodegree programs can be significantly more expensive than individual courses on other platforms.
- The fast-paced, project-intensive nature of the programs can be demanding.

#### **Ideal for:**

- Learners who are committed to a career change or significant upskilling in artificial intelligence.
- Individuals who learn best by doing and want to build a portfolio of projects to showcase to potential employers.
- Those who value mentorship and career support services as part of their learning experience.

#### **Recommended Courses**

- [**Master Building AI Agents**](https://www.udacity.com/course/agentic-ai--nd900)
- [**Become a Machine Learning Engineer**](https://www.udacity.com/course/machinelearning-engineer-nanodegree--nd009t)
- [**Deep Learning**](https://www.udacity.com/course/deep-learning-nanodegree--nd101)

![](https://www.atlantic.net/wp-content/uploads/2025/06/fastai-logo.png)

### **#7: Fast.ai – Best for Hands-On LLM & ML Practitioners**

Fast.ai offers a unique, top-down approach to learning deep learning, making it one of the most practical courses available to explore for aspiring practitioners. The course is offered for free and has a strong focus on getting students to build and train state-of-the-art models quickly.

#### **Advantages:**

- The “code-first” approach allows learners to achieve impressive results from the very first lesson.
- The course is entirely free and taught by industry experts with extensive practical experience.
- A strong emphasis on practical techniques and best practices for training deep learning models.
- The fastai library, built on top of PyTorch, simplifies many of the complexities of deep learning programming.

#### **Disadvantages:**

- The top-down approach may not be ideal for those who prefer to learn the underlying theory.
- The course is very fast-paced, which may be challenging for absolute beginners in programming.

#### **Ideal for:**

- Individuals who are eager to start building and experimenting with deep learning models right away.
- Programmers who want to add deep learning to their skillset and are comfortable learning by doing.
- Learners who are looking for a free, high-quality, and practical alternative to more traditional, theory-heavy courses.

#### **Recommended Courses:**

- [**Practical Deep Learning for Coders**](https://www.fast.ai/posts/2022-07-21-dl-coders-22.html)
- [**From Deep Learning Foundations to Stable Diffusion**](https://www.fast.ai/posts/2023-04-04-part2-2023.html)

### ![Vanderbilt University](https://www.atlantic.net/wp-content/uploads/2026/02/Vanderbilt-University.jpg)

### #8: Vanderbilt University – Best for Agentic & Autonomous Systems

Vanderbilt University offers a forward-looking course focused on agentic AI and autonomous systems, an area that has quickly moved from research into real-world production use. Unlike traditional AI courses that focus on single-model behavior, this program teaches how LLMs operate within multi-step, tool-using, decision-making systems.

The course is designed around how modern AI agents are built, coordinated, evaluated, and controlled—making it especially relevant as agentic workflows become standard in enterprise and product environments.

#### Advantages:

- Direct focus on agent-based and autonomous AI systems.
- Covers real-world concepts such as tool use, planning, orchestration, and multi-agent workflows.
- Strong academic rigor combined with applied system-level thinking.
- Aligns closely with how LLM-powered agents are deployed in production.
- Backed by a well-recognized research university, providing strong credibility.

#### Disadvantages:

- Assumes prior familiarity with AI or machine learning concepts.
- More specialized than general AI courses, making it less suitable for beginners.
- Not designed as a broad survey of artificial intelligence.

#### Ideal for:

- LLM Engineers and AI Architects working on agentic or multi-step AI systems.
- Engineers are moving beyond single-model prompts into autonomous AI workflows.
- Professionals who want verified, future-facing AI skills tied to real deployment patterns.

#### Recommended Courses:

- [**Agentic AI and AI Agents: A Primer for Leaders**](https://www.coursera.org/learn/agentic-ai?)
- [**From Data To Decision With AI Specialization**](https://www.coursera.org/specializations/data-to-decision-ai-vanderbilt)
- [**AI Systems Design and Governance**](https://www.coursera.org/specializations/ai-agents-java)

## **Self-Paced Learning**

Professionals are feeling the pressure to keep their skills up-to-date. This is why many are turning to online courses to supplement their learning. These courses are an accessible way to get a handle on AI, letting you balance learning with your work.

## **Learn AI Essential Skills**

Beyond the knowledge itself, earning an AI certificate gives you something tangible to show existing and new employers. It’s a powerful credential that tells potential employers you have what it takes. In a crowded job market, that proof can make all the difference, opening doors to opportunities you might not have otherwise considered.

Ready to turn your curiosity into a career-defining skill? We provide the hardware you need to actually build these systems. If you need an AI-ready hosting platform to assist your learning, Atlantic.Net features cloud and dedicated [GPU hosting options](https://www.atlantic.net/gpu-server-hosting/), Our servers are powered by NVIDIA H100 NVL and L40S GPUs, available on demand. For security, we ensure all data in transit is protected via TLS 1.2 or 1.3.

## **Free Online Course vs Paid Content**

There is a debate about free vs. paid content. traditionally, you may have thought free content was subpar. That isn’t the case in 2026, especially for AI. This has driven a surge in high-quality free content. Paid content from institutions is typically better for expert-level training or credentialing.

## **Conclusion**

Platforms like Coursera and edX provide academically rigorous courses from top universities, while innovators like DeepLearning.AI and Fast.ai offer practical, hands-on training to get you building models immediately. Whether you choose a free, code-first approach or invest in a comprehensive Nanodegree, the key is to start learning and applying your new skills.

As you progress from learning the theory to building your own complex projects, you’ll need powerful and reliable computing resources. Atlantic.Net’s on-demand GPU hosting, powered by NVIDIA, provides the high-performance infrastructure you need to train sophisticated AI models, turning your newfound knowledge into career-defining results.

Start your AI journey today and let Atlantic.Net power your projects. [Reach out to the team](https://www.atlantic.net/about-us/corporate-contact/) or [sign up today](https://cloud.atlantic.net/?page=userlogin).


---

# Best Dedicated Hosting for Your Workload

> URL: https://www.atlantic.net/dedicated-server-hosting/best-dedicated-hosting/ | Updated: 2026-09-16

Compare bare metal, dedicated cloud, public cloud, and hybrid hosting to choose the right balance of consistent performance, strict isolation, full control, scalability, and predictable costs.

- Single-Tenant Hardware
- Consistent Performance
- Hardware Isolation
- Full Control

Isolation: High

Performance: Consistent

## Best Dedicated Hosting

If you need consistent, high performance with strict isolation and full control, dedicated hosting is your best fit. For most buyers, that means choosing between bare metal (OS on physical hardware) and dedicated cloud hosting (your own single-tenant virtualized cluster).

If you prioritize rapid elasticity and lowest operational overhead, dedicated public cloud instances may be preferable. If your applications have a steady workload with periodic load spikes, or you're migrating in stages, hybrid hosting (dedicated core with public-cloud bursting) can help to balance cost, control, and agility.

Why it matters: The compute model you choose determines performance consistency, isolation for compliance, scaling mechanics, and how predictable your monthly costs will be.

## Key Takeaways

### Dedicated Hosting

single-tenant hardware (bare metal or dedicated cloud) with consistent performance & maximum control.

### Cloud Hosting

fastest elasticity & managed services; performance can vary under multi-tenant contention.

### Hybrid Hosting

steady core on dedicated; burst or augment with cloud as needed.

Isolation is highest on dedicated hosting and on the dedicated portion of hybrid.

Ease of scaling favors the public cloud; hybrid hosting balances fast bursts with a stable core.

Cost predictability is highest on dedicated for steady usage; public cloud varies depending on compute consumption.

## Benefits & Features

Features

These are the building blocks that deliver those benefits into practice. Use these features to customize your environment (from compute and storage to networking, security, operations, and optional GPUs) so it fits exactly what your workloads need.

- Latest-gen CPUs & high-memory tiers with options for CPU pinning and NUMA awareness.
- Storage flexibility: NVMe, RAID levels, and SAN/NAS attachment for tiered performance.
- High-throughput networking: 10-40 Gbps ports, private VLANs, and peering/interconnect options.
- Security stack: baseline DDoS protections, firewall/WAF options, micro-segmentation.
- Resilience & Ops: snapshots/backup/DR, automation/API, infrastructure-as-code, monitoring/alerting.
- GPU options (select SKUs): dedicated GPU servers for AI/ML, HPC, and rendering workload

## Benefits

When your business application relies on stable and reliable hardware, slowdowns or surprises can cause a major headache. Dedicated hosting keeps resources exclusively yours. Below are some of the real-world advantages that your business can rely on day to day.

- Predictable performance for latency-sensitive apps (databases, analytics, real-time APIs).
- Hardware isolation to avoid noisy neighbors and support compliance segmentation.
- Deep customization of OS, storage layout, networking, and security controls.
- Stable costs for steady, long-running workloads and reserved capacity planning.

## Definitions of the best dedicated hosting

Terms like "bare metal," "dedicated cloud," and "isolation" can mean different things to different businesses. This quick glossary spells out how we're using each term in this article, so you can skim the rest without ambiguity.

- Dedicated hosting: Single-tenant physical resources reserved for one customer. Includes bare metal and dedicated cloud hosting.
- Bare metal: OS runs directly on a physical server (no provider hypervisor layer).
- Dedicated cloud hosting: Your own single-tenant virtualization hosts (private/managed cloud, "dedicated hosts"), giving VM flexibility with hardware isolation.
- Cloud hosting (public VMs): Virtual machines on a shared hypervisor (multi-tenant).
- Hybrid hosting: Dedicated core platform integrated with public-cloud services or burst capacity.
- Isolation: Degree to which compute, storage, and network are single-tenant and segmented.
- Noisy neighbor: Performance impact caused by other tenants on shared infrastructure.

## Service Type Comparison

| Service Type | Ideal For | Compute Model | Isolation | Scaling | Performance | Security & Compliance Fit | Operational Overhead | Cost Predictability |
| --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Dedicated (Bare Metal or Dedicated Cloud) | Steady, high-throughput apps; databases; regulated workloads; fixed licensing; GPU/HPC | Single-tenant physical (optional virtualization) | High | Manual/Planned (add hosts/servers) | High/consistent | Strong (clear boundaries) | Med-High (you control stack) | High |
| Cloud (Public VMs) | Bursty traffic; experiments; fast time-to-market; managed PaaS | Shared hypervisor | Med | Elastic/Auto | Variable (multi-tenant) | Good with controls | Low-Med (provider manages more) | Variable (usage-based) |
| Hybrid | Steady core + bursts; phased migrations; cost control with agility | Mixed | High on core | Mixed (plan core, burst cloud) | Balanced | Strong if well-architected | Med-High (integration work) | Mixed |

## Introducing Atlantic.Net Dedicated Options

When your decision points to dedicated or hybrid, Atlantic.Net offers single-tenant compute from bare metal to private/dedicated cloud, and dedicated GPU servers for acceleration:

### Dedicated Server Hosting

Single-tenant servers with modern CPU families, high-memory profiles, NVMe options, private VLANs, and high-bandwidth ports.

### Bare Metal Servers

Direct-to-metal performance with OS control, BIOS/firmware tuning, and custom RAID/storage layouts for IO-intensive workloads.

### Managed Private Cloud

Your own single-tenant virtualization hosts for VM flexibility with hardware isolation, ideal when you want live migration-style agility, snapshots, and high density under your control plane.

### Dedicated GPU Servers

Purpose-built SKUs for AI/ML training and inference, rendering, and scientific computing; align GPU memory, PCIe bandwidth, and storage throughput to your accelerator profile.

## Pick Atlantic.Net Dedicated Hosting if…

- Your workloads are steady and resource-intensive (think OLTP/OLAP databases, video processing pipelines, or high-throughput APIs) and you want them on Atlantic.Net single-tenant bare metal for stable, low-jitter performance.
- You require strict isolation for latency-critical services and prefer having your own Atlantic.Net dedicated servers instead of sharing hosts with other tenants.
- Software licensing is tied to sockets/cores and you want to control consolidation density on fixed hardware in Atlantic.Net data centers.
- You care about cost predictability and hardware-level control (BIOS tuning, CPU pinning, custom RAID layouts) delivered on Atlantic.Net infrastructure rather than shared platforms.
- You need GPU acceleration for AI/ML training and inference, rendering, or CUDA-based HPC, and want those GPUs dedicated to your team on Atlantic.Net.

## Pick Public Cloud if…

- You face bursty or seasonal demand and most of the value is in scaling up and down rapidly on hyperscale clouds.
- You want fully managed services (databases, queues, serverless) to offload as many ops as possible, and you're comfortable with multi-tenant infrastructure.
- You prioritize rapid experimentation and broad global reach, using many regions and services your team already knows.

Atlantic.Net often fits alongside this: keep the most sensitive or performance-critical workloads on Atlantic.Net dedicated hosting, while experimental or short-lived projects run in the public cloud.

## Pick Hybrid with Atlantic.Net if…

- You have a stable baseline that belongs on Atlantic.Net dedicated servers and periodic spikes you handle by bursting into public cloud.
- You're migrating in phases or refactoring over time and want Atlantic.Net as the landing zone for your long-lived, stateful systems while the rest evolves.
- You want tight cost control for core systems on Atlantic.Net, with agile extension into the public cloud for analytics, edge, or event-driven workloads.

## Costs, Performance & Risks with Atlantic.Net Dedicated Hosting

Before you lock in an architecture, it helps to look at three angles through an Atlantic.Net lens: what your Atlantic.Net dedicated hosting will cost over time, how it will perform under real load, and what resilience you have when something fails.

Use the checklists below to firm up your assumptions, tune for consistent throughput and latency, and reduce exposure to common pitfalls, always tying decisions back to your SLOs and RTO/RPO targets.

### Costs (with Atlantic.Net in mind)

- Hardware lifecycle. With Atlantic.Net, servers are provisioned, monitored, and refreshed for you, effectively amortizing the host cost over 3-5 years without you owning hardware or dealing with parts.
- Licensing. Atlantic.Net can help you design around OS, hypervisor, database, and application licensing, optimizing core/socket counts and consolidation density on your dedicated nodes.
- Bandwidth & transit. Instead of unpredictable egress from public cloud, Atlantic.Net offers committed ports and bandwidth options, plus inter-DC connectivity and private cross-connects where needed.
- Support & management. Decide how far you want to go: run DIY on Atlantic.Net dedicated servers, or add managed services (monitoring, backups, security, DR testing) to reduce in-house SRE load.

### Performance on Atlantic.Net

- I/O consistency. Atlantic.Net dedicated hosting gives you direct access to NVMe and RAID-tuned storage, so you can design for low, stable latency instead of shared I/O pools.
- CPU/NUMA awareness. On Atlantic.Net bare metal or dedicated cloud, you can pin cores for critical threads and align memory locality for performance-sensitive workloads.
- Storage tiers. Build sensible tiers (hot NVMe, warm SAS/SATA, object storage for cold data) and let Atlantic.Net handle the underlying hardware and reliability.
- Network paths. Use private VLANs, redundant uplinks, and optional jumbo frames/QoS on Atlantic.Net networks to keep east-west traffic (app ↔ DB, replication, HA) efficient and predictable.
- GPU throughput. Atlantic.Net dedicated GPU servers can be sized for VRAM capacity, PCIe bandwidth, and interconnect requirements so your ML/HPC workloads aren't bottlenecked by I/O.

### Risks & Mitigations with Atlantic.Net

- Capacity planning (Dedicated/Hybrid). Atlantic.Net monitoring and capacity telemetry help you maintain headroom, plan rolling expansions, and avoid surprise saturation.
- Failover design. Use Atlantic.Net's backup, snapshot, and DR tooling, plus documented runbooks, to test restores and DR regularly, not just backups.
- Vendor lock-in (Public Cloud). If you're hybrid, keep core systems portable: containerize, favor open engines, and codify infra with IaC. Atlantic.Net's dedicated hosting gives you a stable, predictable base that's easier to target than rapidly changing cloud primitives.
- Security drift. On Atlantic.Net, you can enforce CIS-style baselines, patch windows, and periodic audits, and layer on firewalls, AV/EDR, and other managed security services.

## How This Maps to Your Goals with Atlantic.Net

This is where Atlantic.Net's platform turns into concrete outcomes for your team. Use it to map your requirements (performance, isolation, networking, security, resilience, day-2 operations, and hybrid integration) to specific Atlantic.Net capabilities.

### Performance & isolation.

Atlantic.Net bare metal delivers lowest jitter for databases and high-throughput services, while Atlantic.Net dedicated cloud gives you single-tenant hosts with VM-level flexibility.

### Networking.

Private VLANs, redundant uplinks, and inter-DC connectivity on Atlantic.Net support replication, HA, and DR without hair-pinning traffic through the open internet.

### Security.

Single-tenant servers by design, plus optional firewalls/WAF, segmentation, and HIPAA-ready environments, help you meet strict isolation and compliance goals.

### Resilience.

Snapshots, backups, and DR solutions on Atlantic.Net can be tuned to your RPO/RTO, with 24×7 support available when you need help designing or testing them.

### Operations.

Atlantic.Net offers 24×7 expert support and automation-friendly APIs so you can accelerate provisioning and day-2 operations instead of hand-building servers.

### Hybrid enablement.

Reference architectures and network options make it easier to burst to public cloud while keeping your stateful cores and regulated data on Atlantic.Net dedicated nodes.

## How to Get Started with Atlantic.Net

The path below takes you from a rough workload inventory to validated, production-ready Atlantic.Net dedicated infrastructure. It's designed to reduce implementation risk, accelerate time-to-value, and prove that performance, availability, and compliance goals are being met.

### Assess

Work with Atlantic.Net to inventory workloads, understand latency requirements, data gravity, and compliance obligations (e.g., HIPAA), and decide what belongs on dedicated vs. hybrid.

### Design

Choose Atlantic.Net server/host profiles, storage tiers, VLAN layout, and HA/DR patterns that align with your licensing model and growth plans.

### Provision

Use Atlantic.Net's automation and portal to roll out base images, configuration baselines, monitoring, and alerting on your dedicated servers.

### Migrate

Sequence databases and other stateful services onto Atlantic.Net first; use replication and parallel performance tests to validate behavior before cutover.

### Validate

Run failover drills, load tests, and cost/performance checks against your original assumptions, adjusting capacity or architecture with Atlantic.Net engineers if needed.

## FAQ

### What is dedicated hosting?

Dedicated hosting at Atlantic.Net provides single-tenant compute for one customer. Your CPU, memory, storage, and private network segments are not shared with other tenants, which delivers predictable performance and strong isolation for critical workloads.

### What is an example of dedicated hosting?

A common Atlantic.Net example is a transaction-heavy database or low-latency analytics engine running on a bare-metal server with NVMe storage and dedicated 10-40 Gbps networking. Another is an Atlantic.Net dedicated cloud cluster where only your VMs run on your reserved virtualization hosts.

### What are dedicated hosts?

At Atlantic.Net, a dedicated host is a physical server reserved for your use. In a dedicated cloud model, you consume these hosts through a virtualization layer (your VMs on your hosts). On bare metal, you install and manage the OS directly on the hardware.

### Who uses dedicated hosting?

Atlantic.Net dedicated hosting is used by organizations with steady, performance-critical workloads, regulated industries needing clear segmentation (for example, HIPAA-covered entities), teams optimizing license costs on fixed cores/sockets, and applications where I/O consistency and low jitter are non-negotiable.

### How is dedicated hosting different from cloud hosting or private hosting?

**Atlantic.Net Dedicated vs. Public Cloud:** Atlantic.Net gives you single-tenant hardware and consistent performance, while public cloud focuses on elasticity and a vast service catalog on multi-tenant infrastructure.

**Atlantic.Net Dedicated vs. Private Hosting/Private Cloud:** "Private hosting" can mean many things; with Atlantic.Net you can choose dedicated cloud (your own virtualization hosts) or bare metal (OS on hardware), both reserved for a single customer.

### When is hybrid hosting more suitable than dedicated hosting?

Hybrid is often ideal when you have a stable baseline that runs best on Atlantic.Net dedicated servers, plus sporadic peaks or analytics workloads that make sense in public cloud. You keep stateful systems and sensitive data on Atlantic.Net, and burst or offload stateless and analytic workloads to the cloud.

### How do I estimate the CPU/RAM/storage requirements?

Atlantic.Net can help, but a good starting point is:

- **CPU:** Profile peak usage and add 25-40% headroom for failover and growth.
- **RAM:** Size for dataset/resident set + OS overhead, with margin for caching.
- **Storage:** Use NVMe for hot data, choose RAID based on read/write patterns, and define IOPS/throughput targets from real traces. Plan backups and consider replication for HA on Atlantic.Net.

### Can I scale dedicated hosting without downtime?

Yes. On Atlantic.Net, you can design for horizontal scale (clusters, load balancers) and use rolling deployments to avoid downtime. Dedicated cloud options allow more flexibility (e.g., maintenance on hosts while VMs stay online), while bare metal may require brief maintenance windows for vertical upgrades.

### What about dedicated GPU servers?

Atlantic.Net dedicated GPU servers are well-suited for AI/ML training and inference, GPU rendering, and CUDA-based HPC. The Atlantic.Net team can help you match GPU memory and interconnect bandwidth to your model sizes and data pipelines, and ensure storage and network throughput keep up with the accelerators.

## Final Guidance

If you value control, isolation, and consistency, Atlantic.Net dedicated hosting is a strong place to start: choose bare metal for direct hardware control and lowest jitter, or Atlantic.Net dedicated cloud when you want single-tenant isolation plus VM flexibility. When you also need rapid bursts or fully managed services, add a hybrid strategy: anchor stateful, steady workloads on Atlantic.Net dedicated hardware and use public-cloud elasticity where it adds the most value.

Your critical applications deserve dedicated resources backed by an experienced partner. Atlantic.Net has been doing this for 32 years. Contact our sales team for help designing your ideal cluster, or deploy a dedicated cloud server instantly on the Atlantic.Net Cloud Platform and start building on a foundation of uncompromising speed and security.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Top ML Development Companies in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/top-ml-development-companies/ | Published: 2026-02-24 | Updated: 2026-09-09 | Author: Richard Bailey

Finding a machine learning partner in 2026 requires looking beyond basic data science and experimental models. Enterprises now prioritize firms with proven expertise in MLOps, RAG architectures, agentic AI systems, and hardware-efficient model deployment that can operate reliably at scale.

This guide evaluates top-tier machine learning development companies based on their technical depth, full-stack AI capabilities, and ability to build, deploy, and maintain production-grade ML systems in real-world environments. The focus is on teams that can manage the entire lifecycle – from data engineering and model training to continuous optimization in production. These firms are assessed on their capacity to support long-term AI operations, not short-term experimentation.

## Machine Learning App Development Services

The selection of a development company for machine learning solutions is a critical decision that can impact business growth. In 2026, this decision increasingly hinges on a partner’s ability to operationalize models in live environments, not just design them in isolation. The ideal partner has deep technical expertise, an understanding of specific business goals, and the capability to deliver tailored software solutions.

The best artificial intelligence companies provide guidance through the entire process, from data collection and data preparation to the deployment and continuous monitoring of machine learning models in production environments. This now extends to managing MLOps pipelines, supporting RAG-based systems, and maintaining agentic AI workflows that adapt over time. The objective is to understand business operations, enhance operational efficiency, and optimize processes through the use of intelligent systems.

## Cutting Edge AI Technologies

This article examines leading ML development companies in 2025, their strengths, and the types of businesses they are best suited to serve are highlighted. In 2026, the focus shifts toward firms that can translate advanced research into stable, production-grade systems. These organizations are at the forefront of implementing agentic AI, retrieval-augmented generation (RAG), and scalable MLOps frameworks, alongside proven machine learning algorithms.

This work enables businesses across various industries to optimize operations. Whether you require custom ML model development, smooth integration with existing systems, or ongoing machine learning consulting, the companies highlighted emphasize deployability, monitoring, and long-term performance of AI systems, offering a diverse set of capabilities.

## Leading ML Development Companies for 2026

Ten leading ML development companies are reviewed below. They are notable for their machine learning development services and custom solutions, offering unique strengths in AI and ML development. The list has been refined to emphasize AI-first engineering firms with full-stack delivery capabilities rather than generalist application development providers.

### #1: [H2O.ai](http://h2o.ai)

![](https://www.atlantic.net/wp-content/uploads/2025/07/h20.png)

H2O.ai is a leader in the artificial intelligence space, positioned as a core technology innovator. The company’s reputation is built on its open-source platform and its commercial H2O Driverless AI, which automates the machine learning workflow. In 2026, its value is strongest for organizations seeking to standardize ML pipelines and reduce friction between experimentation and production. This focus on automation has led to consistent recognition, including being named a “Visionary” in the [Gartner® Magic Quadrant™](https://www.gartner.com/reviews/market/data-science-and-machine-learning-platforms) for Data Science and Machine Learning Platforms.

A cloud platform is provided that enables data science teams to be more productive. H2O.ai places growing emphasis on production monitoring, model governance, and hardware-aware optimization to support enterprise-scale deployments. A key differentiator is its work in image recognition and Explainable AI (XAI), which provides transparent model predictions, a crucial feature for organizations in regulated sectors.

#### Advantages:

- **Automated Machine Learning (AutoML):** The Driverless AI platform automates time-intensive tasks like feature engineering, model selection, and tuning, helping teams move faster from raw data to deployable models.
- **Performance and Scalability:** Engineered for high-throughput workloads, the platform supports large datasets and accelerates training and inference in production environments.
- **Enterprise Adoption:** Global organizations use H2O.ai to operationalize machine learning across use cases such as customer analytics, risk modeling, and operational forecasting.

#### Disadvantages:

- **Steep Learning Curve:** While Driverless AI is accessible, the broader open-source ecosystem can be complex for teams without prior ML infrastructure experience.
- **Cost of Enterprise Features:** Advanced governance, support, and automation capabilities require commercial licensing, which may be a barrier for smaller teams.

#### Ideal for:

Large enterprises in finance, insurance, healthcare, and telecommunications that need a scalable, explainable, and production-ready ML platform to support full-stack AI initiatives and long-term model operations.

### #2: [Technology Rivers](https://technologyrivers.com/)

![](https://www.atlantic.net/wp-content/uploads/2026/02/technology-rivers.png)

Technology Rivers is a U.S.-based software development company that builds custom artificial intelligence and machine learning solutions, with particular strength in healthcare and other applications where security, data handling, and production reliability are important. Its AI/ML services span custom model development, predictive analytics, natural language processing, computer vision, intelligent automation, and data engineering.

The company takes a full-product approach to machine learning, combining AI development with cloud architecture, application engineering, and deployment. Its technology stack includes TensorFlow, PyTorch, Keras, and Scikit-learn, alongside cloud AI services from AWS, Google Cloud, and Microsoft Azure. Technology Rivers also supports containerized deployment using Docker and Kubernetes, making it suitable for organizations that need ML capabilities integrated into scalable applications rather than isolated experimental models.

#### Advantages:

- **End-to-End AI/ML Development:** Technology Rivers can support projects from data preparation and model development through application integration and deployment.
- **Strong Healthcare Expertise:** The company has extensive experience developing HIPAA-compliant healthcare applications and applying AI to areas such as predictive analytics, workflow automation, remote patient monitoring, and clinical data.
- **Broad ML Technology Stack:** Experience with Python-based ML frameworks, major cloud AI platforms, data processing technologies, and containerized deployment supports a wide range of machine learning projects.
- **Product-Focused Development:** Machine learning capabilities can be incorporated into complete web, mobile, SaaS, and cloud applications rather than delivered solely as standalone models.

#### Disadvantages:

- **Healthcare-Heavy Specialization:** Much of Technology Rivers’ strongest domain experience is concentrated in healthcare, so organizations looking for highly specialized ML expertise in areas such as industrial engineering or scientific research may prefer a sector-specific provider.
- **Services-Led Model:** Technology Rivers is primarily a custom development partner rather than a packaged machine learning platform, making it less suitable for businesses seeking a self-service ML product.

#### Ideal for:

Startups, healthcare organizations, and growing businesses that need a development partner capable of combining custom machine learning with production-ready software, cloud infrastructure, and secure application development.

### #3: Codiste

![](https://www.atlantic.net/wp-content/uploads/2026/02/codiste_logo.jpg)

Codiste is an AI-first engineering firm focused on building production-ready machine learning and generative AI systems. Unlike generalist development agencies, Codiste positions itself as an end-to-end AI delivery agency, covering data engineering, model development, MLOps, and deployment across cloud and on-prem environments. Its work centers on turning advanced ML concepts into systems that operate reliably under real-world business constraints.

The company has solid experience with agentic AI systems, retrieval-augmented generation (RAG), and custom LLM fine-tuning. This makes Codiste a good fit for organizations looking to use modern AI architectures. Codiste works closely with internal teams to ensure models align with business workflows and can be improved over time.

#### Advantages:

- **AI-First Engineering Focus**: Codiste creates solutions where machine learning is central, not just an extra feature.
- **Strong MLOps and Deployment Expertise**: Codiste has proven skills in CI/CD for machine learning, as well as monitoring and managing models throughout their lifecycle in production.
- **Modern AI Architectures**: Codiste has experience with RAG pipelines, autonomous agents, and generative AI solutions for enterprise needs.

#### Disadvantages:

- **Not a Low-Cost Vendor**: Codiste focuses on advanced AI systems and hires senior engineers, so its services may be too expensive for early-stage startups.
- **Selective Engagements**: Codiste works best with clear, well-defined machine learning projects, not with exploratory or loosely scoped work.

#### Ideal for:

Mid-sized companies and enterprises that want an AI-focused partner to design, deploy, and manage production-level machine learning and generative AI systems built for long-term growth.

### #4: Imaginary Cloud

![](https://www.atlantic.net/wp-content/uploads/2026/02/Imaginary_Cloud_logo.png)

Imaginary Cloud is an AI-first software engineering company with a strong emphasis on building scalable, production-ready machine learning systems. While known for high-quality engineering, the company has increasingly focused on integrating machine learning, data pipelines, and MLOps into core product architectures rather than treating AI as a standalone feature. Its teams work closely with clients to ensure ML systems are deployable, maintainable, and aligned with business objectives.

The company stands out in AI-driven product development by combining machine learning models with solid web and backend systems. Imaginary Cloud focuses on making its solutions reliable, easy to monitor, and high-performing in real-world use, which is important for organizations ready to move past pilot AI projects.

#### Advantages:

- **AI-First Product Engineering**: Machine learning is part of the system architecture from the start, not added later.
- **Strong Production Focus**: The team has experience launching ML-powered applications with tools for monitoring, versioning, and ongoing improvements.
- **Collaborative Delivery Model**: The company works closely with clients to make sure models fit into real workflows and products.

#### Disadvantages:

- **Less Research-Oriented**: The company focuses on practical ML and delivering systems, not on experimental or research-heavy model development.
- **Selective AI Scope**: Imaginary Cloud is best for product-focused ML projects, not for overhauling large data platforms.

#### Ideal for:

Product-led companies and digital businesses that want reliable, production-ready machine learning built into their customer-facing or internal software platforms.

### #5: STX Next

![](https://www.atlantic.net/wp-content/uploads/2026/02/STX_Next_Logo.png)

As one of Europe’s largest software houses specializing in Python, STX Next is a significant presence in the machine learning domain. Their large team of Python software engineers provides a distinct advantage. In 2026, their strength lies in operationalizing ML models within complete software systems rather than delivering standalone prototypes. The company’s philosophy is to engineer the entire software ecosystem required for ML models to function in a production environment.

STX Next places increased emphasis on MLOps, deployment automation, and long-term maintainability of machine learning systems. This approach ensures solutions are scalable and maintainable in real-world applications.

#### Advantages:

- **Unmatched Python Expertise:** With a large team of Python developers, they possess the specialized skills essential for machine learning software development and handling complex data.
- **Holistic Product Teams**: STX Next provides an integrated development team that covers the full software development lifecycle, from data science and QA to DevOps.
- **Focus on Production-Ready ML:** A strong emphasis on Machine Learning Operations (MLOps) ensures solutions are scalable and maintainable in real-world applications.

#### Disadvantages:

- **Broad Focus:** As a large software development company, ML is one of several core offerings. Companies seeking a highly specialized, AI-only firm might look elsewhere.
- **Geographic Focus:** Their core team’s location in Europe could pose time-zone challenges for clients in the Americas.

#### Ideal for:

Companies that need to develop a complete software product with a machine learning component at its heart and value having a single, integrated team to manage deployment and ongoing ML operations.

### #6: The Dot Collective

![](https://www.atlantic.net/wp-content/uploads/2026/02/dotcollective.png)

The Dot Collective operates on the premise that successful AI is built on a foundation of well-governed data. This specialized data consultancy focuses on data engineering, cloud architecture, and MLOps. In 2026, its role is increasingly aligned with enabling production-grade ML and agentic AI systems by fixing upstream data and operational gaps. Its primary mission is to build data platforms that enable organizations to execute their own data initiatives, often using robotic process automation.

#### Advantages:

- **Foundation-First Approach**: They specialize in creating the reliable data architecture and governance essential for successful and scalable machine learning.
- **MLOps and Production Enablement**: Strong capabilities in operational frameworks that support model versioning, monitoring, and long-term reliability.
- **Cloud-Native Proficiency**: They are experts in building bespoke, flexible data solutions on modern cloud platforms.
- **Strategic Partnership**: They act as strategic partners to align a company’s data infrastructure with its long-term business and AI ambitions.

#### Disadvantages:

- **Not a Pure ML Model Builder**: Their primary focus is on the data platform and infrastructure, not the custom development of specific ML algorithms.
- **Niche Focus:** They are best suited for a specific client, one that needs to build or modernize its core data platform before diving deep into ML development.

#### Ideal for:

Enterprises that must modernize data foundations and MLOps practices before scaling machine learning, agentic AI, or RAG-based systems in production.

#### #7: CodeTrade.IO

![](https://www.atlantic.net/wp-content/uploads/2026/02/codetrade.png)

CodeTrade.IO is focused on making AI and ML development accessible for startups and small to medium-sized businesses (SMBs) while ensuring reliable data security. In 2026, its positioning centers on helping smaller teams operationalize ML features without building large internal AI infrastructures. They provide tailored solutions in predictive analytics, computer vision, and NLP. The model uses advanced algorithms to improve customer engagement.

#### Advantages:

- **Focus on SMBs and Startups:** Their pricing and engagement models are structured to fit the budgets and needs of smaller businesses.
- **Practical ML Deployment:** Emphasis on integrating ML components into existing systems with maintainable deployment workflows.
- **Flexible Engagement Models**: Clients can choose from project-based work or hiring dedicated developers, offering significant control.
- **Full Source Code Ownership:** This unique offering provides clients with long-term security and freedom, preventing vendor lock-in.

#### Disadvantages:

- **Less Suited for Massive Enterprise Needs**: They may not have the extensive resources required for highly complex, large-scale AI deployments.
- **Diverse Service Portfolio:** Their focus spans multiple IT services, which may be less specialized than AI-only engineering firms.

#### Ideal for:

Startups and SMBs that need cost-conscious, production-ready ML integrations and value ownership and control over their AI implementations.

### #8: Accenture

![](https://www.atlantic.net/wp-content/uploads/2025/07/accenture.png)

Accenture is a global consulting business with a major presence in artificial intelligence. They offer end-to-end AI services, from strategic consulting to the implementation and operation of complex AI systems. In 2026, Accenture’s AI practice is increasingly focused on scaling ML, generative AI, and agentic systems across large enterprises with strict governance requirements. Accenture’s approach is to partner with large organizations to drive enterprise-wide transformation, integrating AI into the core of their business processes.

#### Advantages:

- **Strategic Enterprise Partnership:** Accenture excels at developing AI strategies that align with C-suite business objectives, focusing on initiatives that can be operationalized at scale.
- **Deep Industry and Functional Expertise:** With a presence across virtually all sectors, they bring strong domain knowledge and can deploy AI solutions for functions like supply chain, finance, and customer service.
- **Operational AI at Scale:** Strong capabilities in MLOps, responsible AI frameworks, and large-scale deployment across global organizations.
- **Global Scale and Ecosystem:** Their extensive global network provides access to a significant pool of talent and partnerships with major technology providers.

#### Disadvantages:

- **Premium Cost Structure:** The services of a top-tier global consultancy come at a significant cost, making it less accessible for mid-market companies or startups.
- **Corporate Overhead:** Engagements can move more deliberately than with smaller firms due to structured methodologies and organizational scale.

#### Ideal for:

Large, multinational enterprises seeking a long-term partner to design, govern, and operate AI systems across multiple business units and geographies.

### #9: Scale AI

![](https://www.atlantic.net/wp-content/uploads/2025/06/scale-logo.png)

Scale AI is a leader in the data-centric AI movement, built on the premise that high-quality data is the most critical component for building high-performance machine learning models. The company provides a data platform that helps AI teams manage the entire data lifecycle, from annotation and labeling to data curation and model evaluation. In 2026, its role is increasingly tied to supporting large language models, agentic AI systems, and RAG pipelines that depend on reliable, continuously updated data.

#### Advantages:

- **Expertise in High-Quality Data**: Scale AI specializes in delivering accurately labeled and curated datasets required for training advanced ML models, particularly in computer vision and generative AI.
- **Support for Modern AI Systems**: Strong alignment with LLM development, autonomous systems, and evaluation workflows used in production environments.
- **Enterprise-Grade Data Engine**: Their platform is designed to manage massive datasets with automation, quality control, and scalable annotation pipelines.

#### Disadvantages:

- **Focus on Data, Not Model Development:** Scale AI provides the data foundation but does not build or fine-tune custom ML models for clients.
- **Cost Can Be a Factor:** Their enterprise-grade services may exceed the needs or budgets of smaller teams or early-stage projects.

#### Ideal for:

Enterprises and AI-driven organizations developing advanced ML, LLM, or agentic systems that require high-quality data pipelines to support production-scale deployment.

### #10: Innowise

![](https://www.atlantic.net/wp-content/uploads/2025/05/innowise-logo.png)

Innowise develops machine learning solutions for real business challenges, with a strong portfolio spanning banking, healthcare, agriculture, and other regulated industries. They help companies automate routine tasks, implement forecasting systems, and improve customer experiences. In 2026, their focus increasingly centers on embedding ML into core business workflows with stable deployment and ongoing optimization. Their projects include fraud detection systems, predictive analytics tools, AI-powered mobile apps, and computer vision applications designed to deliver measurable outcomes.

#### Advantages:

- End-to-end ML development covering design, implementation, and deployment
- Expertise across multiple domains with applied machine learning use cases
- Emphasis on production support, monitoring, and continuous model improvement
- Strong team with 3,000+ IT professionals and a proven delivery track record
- Practical focus on operational impact rather than experimental AI

#### Disadvantages:

- Complex projects may require longer timelines for full deployment
- Highly specialized ML solutions often demand close, ongoing collaboration

#### Ideal for:

Organizations looking to integrate machine learning into core operations and maintain models over time, particularly in enterprise or regulated environments requiring long-term support.

## AI/ML Business Operations with Atlantic.Net

By 2026, the emphasis will shift toward reliably operating ML systems in production rather than simply building them. Whether complete ML development services, automated platforms, or specialized data engineering expertise are needed, businesses have many choices. The selection of the right partner for development services and ongoing support is a strategic decision that depends on a company’s internal expertise, business goals, and specific challenges.

The goal of this journey from initial data collection to deployment is to transform complex data into tailored machine learning solutions that provide business value. Modern deployments increasingly include agentic AI workflows, RAG pipelines, and continuous model optimization, all of which rely on advanced algorithms and sophisticated ML systems. These workloads require significant computational power for both training and real-time inference.

To support these applications, access to enterprise-grade hardware that can handle demanding AI and deep learning workloads is necessary. A powerful and reliable[GPU hosting service](https://www.atlantic.net/gpu-server-hosting/) is designed to build and scale innovative ai solutions. For teams that need GPU infrastructure for training or inference, Atlantic.Net offers dedicated and cloud GPU servers with options including NVIDIA L40S and NVIDIA H100 NVL, and the ability to choose shared or dedicated GPU allocation (including multi-GPU configurations).

When evaluating any GPU host, prioritize what will matter in production: predictable performance, provisioning speed, security controls, and operational support paths.


---

# Top 10 Essential Books on AI in 2026 for Anyone Curious About Technology

> URL: https://www.atlantic.net/gpu-server-hosting/essential-books-on-ai-for-anyone-curious-about-technology/ | Published: 2026-02-24 | Author: Richard Bailey

Artificial intelligence (AI) is a very popular subject for learners and readers, and staying informed on its key themes is essential, especially considering how quickly the technology changes and develops. Keeping pace with AI now requires high-signal resources rather than broad speculation. In 2026, the most valuable books focus on practical frameworks for engineering, deployment, and ethical decision-making. AI books, authored by leading experts, provide a critical resource for understanding complex AI subjects. Ever since ChatGPT was put on general release in November 2022, AI has gone mainstream, and generative AI has ushered in a new era in science and technology, making a foundational understanding of its basic concepts really important for anyone interested in the field.

Books are a great way of demonstrating how integrating AI into daily life and business operations is achieved. The strongest titles now clearly signal intent—whether they are written for engineers building systems, leaders managing adoption, or readers focused on governance and ethics. Personal stories from authors and the brief history of AI’s evolution offer valuable insights and perspective. Books on AI explain the fundamental science of neural networks, image recognition, and the concept of co-intelligence.

The best books on the subject are a must-read for those who wonder about the future, the challenges, and the ethical considerations that AI presents. From sci-fi-inspired concepts to practical applications, AI books offer a fascinating look at the potential impact of artificial intelligence on humanity. Understanding AI happens one concept at a time, and these texts provide an accessible path for teachers, students, and business professionals alike. As the field matures, the essential reading list has expanded – covering not just what AI is, but how it is built, governed, and used responsibly at scale.

## How to Choose an AI Book in 2026

Use this checklist before you buy:

- **Your goal:** learn theory, build systems, lead adoption, or govern risk
- **Your level:** math-heavy textbook vs. narrative + examples
- **Time horizon:** near-term practice (evaluation, deployment) vs. long-run strategy
- **What you’re building:** LLM apps, ML products, policy, or team workflows
- **Signal vs. noise:** prefer books with clear frameworks over trend-chasing
- **Complementarity:** pair one technical book with one governance/ethics book

## A Selection of Must-Read AI Books

We managed to narrow down a huge selection of books down to our ten favorites. For clarity and usefulness in 2026, the books are grouped by reader intent—such as foundational theory, engineering practice, or ethics and governance. We have chosen a varied selection, some old, some new. Several books offer a complete view of artificial intelligence, from its technical underpinnings to its societal implications. This intent-based structure helps readers quickly identify which books match their goals, whether they are building systems, shaping policy, or studying AI’s long-term impact. Here is a list of some of the best books available for gaining a deeper understanding of AI.

## Foundations and Theory

### #1: Artificial Intelligence: A Modern Approach by Stuart Russell and Peter Norvig (2021)

![](https://www.atlantic.net/wp-content/uploads/2026/02/book-AI-1.jpg)

**Intent: For Foundations & Theory**

**Introduction**: This volume is widely considered the standard text in the field of artificial intelligence. It provides a complete and detailed exploration of AI, covering a vast range of topics including search, knowledge representation, machine learning, and robotics. As a foundations-first book, it focuses on formal models and reasoning rather than applied tooling or organizational use of AI. The authors frame AI as the study of intelligent agents that perceive their environment and act to maximize success.

#### Key Takeaways:

- It offers a complete and authoritative overview of the foundational principles of AI.
- The concept of the “intelligent agent” is used as a unifying theme across all topics.
- It provides in-depth coverage of both classical and modern AI techniques, including probabilistic reasoning and deep learning.
- The theoretical framing supports later study in AI safety, ethics, and system control.

#### Points to Consider:

- Its complete nature results in a very long and dense book, which can be difficult for casual reading.
- A solid background in computer science and mathematics is necessary to grasp many of the concepts.
- Readers looking for guidance on deployment, governance, or real-world AI operations will need complementary, intent-specific titles.

**Ideal for:** This book is ideal for undergraduate or graduate students taking an AI course. It is best suited for readers whose primary intent is mastering core AI theory before moving on to engineering, ethics, or policy-focused books.

### #2: The Coming Wave: Technology, Power, and the Twenty-first Century’s Greatest Dilemma by Mustafa Suleyman and Michael Bhaskar (2024)

![](https://www.atlantic.net/wp-content/uploads/2026/02/book-coming-wave.jpg)

**Intent: For Ethics, Governance, and Global Risk**

**Introduction**: The co-founder of DeepMind, Mustafa Suleyman, delivers a clear-eyed analysis of the risks and rewards of the current technological wave. This book is positioned squarely for readers concerned with governance, control, and the systemic risks of deploying powerful AI at scale. It argues that AI and synthetic biology are poised to create unprecedented global change, presenting a difficult challenge: how to contain these powerful technologies without stifling progress or enabling authoritarian control.

#### Key Takeaways:

- It provides an insider’s perspective on the immense power and accelerating pace of AI development.
- The concept of the “containment problem” is clearly articulated as the central challenge of our time.
- It effectively explains the dual-use nature of technology, highlighting both its immense benefits and its potential for misuse.
- The book frames AI governance as a coordination problem involving states, firms, and institutions—not just technologists.

#### Points to Consider:

- The tone can be seen as alarmist, with a strong focus on worst-case scenarios.
- The proposed solutions for containment are acknowledged as difficult and potentially unattainable on a global scale.
- Readers seeking technical depth, engineering practices, or implementation details will find the discussion intentionally abstract.

**Ideal for**: This book is essential reading for policymakers, business leaders, and strategists. It is best suited for readers whose primary intent is understanding AI governance, global power dynamics, and long-term ethical risk rather than system design or engineering execution.

### #3: The Age of AI: And Our Human Future by Henry A. Kissinger, Eric Schmidt, and Daniel Huttenlocher (2022)

![](https://www.atlantic.net/wp-content/uploads/2026/02/book-Age-of-ai.jpg)

**Intent: For Strategy, Philosophy, and Global Order**

**Introduction**: This book brings together three influential thinkers—a statesman, a technology executive, and a computer scientist—to explore how AI will change society. Rather than focusing on systems or tools, the book examines AI as a civilizational force that reshapes human identity, knowledge, and power structures. The authors examine the impact of AI on human identity, knowledge, and global order, arguing that this technological shift is as significant as the Enlightenment.

#### Key Takeaways:

- It offers a unique, high-level perspective that combines foreign policy, technology, and academic viewpoints.
- The book effectively argues that AI is not just a tool but a new force that will reshape how we perceive reality and reason.
- It raises profound philosophical questions about the future of human consciousness and decision-making in partnership with machines.
- The strategic framing helps readers think about AI beyond market cycles and product timelines.

#### Points to Consider:

- The analysis is broad and philosophical, which may leave readers seeking concrete technical details or policy prescriptions wanting more.
- Some critics find the book raises more questions than it answers and can be abstract in its treatment of the subject.
- It does not provide operational guidance for engineering teams or governance bodies.

**Ideal for**: This work is well-suited for readers interested in the intersection of technology, philosophy, and global politics. It is best for leaders and strategists whose intent is long-term thinking about AI’s impact on institutions and the international order.

#### #4: Human Compatible: Artificial Intelligence and the Problem of Control by Stuart Russell

![](https://www.atlantic.net/wp-content/uploads/2026/02/book-human-compatable.jpg)

**Intent: For AI Safety, Ethics, and Alignment**

**Introduction**: AI pioneer Stuart Russell addresses the long-term implications of creating superintelligent machines. The book is a cornerstone text for understanding alignment, control, and the ethical constraints required as AI systems become more capable. It explores the existential risk that advanced AI could pose if not designed with provable beneficence toward humans at its core. Russell proposes a new model for AI development centered on this principle of control.

#### Key Takeaways:

- The book makes the complex “control problem” accessible to a general audience.
- It argues for a fundamental shift in AI research, moving from creating pure intelligence to creating beneficial intelligence.
- It effectively uses analogies and personal stories to explain difficult concepts about the future of AI.
- The arguments directly inform modern discussions around AI governance, oversight, and safety standards.

#### Points to Consider:

- The book focuses heavily on the potential long-term risks, which may seem speculative to some readers.
- While accessible, some arguments still require careful and focused reading to fully understand.
- Readers looking for implementation frameworks, audits, or engineering checklists will need more applied resources.

**Ideal for**: This is a must-read for technology enthusiasts, policymakers, ethicists, and any citizen concerned with the long-term societal impact of artificial intelligence. It is especially valuable for readers whose primary intent is understanding why AI safety and alignment must shape regulation and research priorities.

### #5: Co-Intelligence: Living and Working with AI by Ethan Mollick (2024)

![](https://www.atlantic.net/wp-content/uploads/2026/02/book-co-intelligent.jpg)

**Intent: For Knowledge Workers, Managers, and Educators**

**Introduction**: Professor Ethan Mollick delivers a practical guide to collaborating with AI in our professional and personal lives. Rather than treating AI as automation, the book frames it as a day-to-day partner for thinking, writing, and decision support. The book’s central idea is to treat AI as a “co-intelligence”—a partner that can augment human capabilities. Mollick provides clear principles for effective human-AI interaction.

#### Key Takeaways:

- It provides a positive and actionable framework for integrating AI into daily work.
- The four main principles—invite AI, be the human in the loop, treat AI like a person, and assume it’s the worst AI you’ll ever use—are easy to remember and apply.
- The book is filled with concrete examples and prompts for using AI in creative, analytical, and productive tasks.
- It emphasizes human judgment, oversight, and responsibility rather than full automation.

#### Points to Consider:

- The advice is focused on current large language models, and specific tactics may become dated as the technology evolves.
- The optimistic focus on augmentation may understate the legitimate concerns about job displacement.
- It does not address enterprise governance, risk controls, or system-level deployment concerns.

**Ideal for**: This book is perfect for business leaders, managers, educators, students, and any professional seeking to harness AI as a tool for productivity and creativity. It is best suited for readers whose intent is improving individual and team workflows rather than building or governing AI systems.

## Engineering, Deployment, and Production Systems

### #6: AI Engineering by Chip Huyen (2024)

![](https://www.atlantic.net/wp-content/uploads/2026/02/book-ai-engineering.jpg)

**Intent: For Engineering, Deployment, and Production Systems**

Introduction: This book serves as a technical guide for building real-world applications with foundation models. Authored by an expert with experience at top technology firms, it is explicitly focused on production readiness rather than experimentation or theory. It bridges the gap between machine learning theory and production-level AI engineering. The focus is on creating scalable, reliable, and maintainable AI products.

#### Key Takeaways:

- It offers a structured, end-to-end framework for developing and deploying AI applications.
- The content is highly practical and product-oriented, addressing real-world engineering challenges.
- It provides a clear distinction between traditional ML engineering and the newer discipline of AI engineering.
- The book directly addresses evaluation, failure modes, and operational constraints in deployed systems.

#### Points to Consider:

- It is written for a technical audience and assumes a foundational understanding of machine learning concepts.
- The book does not contain code, focusing instead on frameworks and best practices.
- Readers looking for ethical theory or policy guidance will need complementary governance-focused books.

**Ideal for**: This book is designed for AI engineers, machine learning engineers, data scientists, and technical product managers. It is best for readers whose primary intent is building, shipping, and maintaining AI systems in production environments.

### #7: Empire of AI: Dreams and Nightmares in Sam Altman’s OpenAI by Karen Hao (2025)

![](https://www.atlantic.net/wp-content/uploads/2026/02/book-empire-of-ai.jpg)

**Intent: For Accountability, Power, and Industry Oversight**

Introduction: This work of investigative journalism provides a critical account of OpenAI’s history and the broader AI industry. Rather than focusing on models or benchmarks, the book examines the organizational, economic, and environmental realities behind large-scale AI development. The author tracks the company’s evolution from a research-focused nonprofit to a commercial powerhouse, exposing the human and environmental costs behind the race for AI supremacy.

#### Key Takeaways:

- It offers a deeply researched, behind-the-scenes look at one of the most influential companies in AI.
- The book connects the abstract world of AI development to concrete global impacts, from data labor to water usage.
- It raises crucial questions about corporate power, ethics, and the concentration of resources required to build advanced AI.
- The reporting provides context for current debates on AI governance, transparency, and accountability.

#### Points to Consider:

- The book has a clear critical perspective on OpenAI and the current trajectory of AI development.
- The focus is more on the political and social story rather than the technical details of how the AI works.
- Its company-centric lens means broader industry practices are sometimes inferred rather than exhaustively compared.

**Ideal for**: This book is for readers interested in the business, politics, and ethics of technology. It is best suited for readers whose intent is understanding power structures, governance gaps, and the real-world costs of scaling AI systems.

### #8: Mastering AI in 2025 by Ryan Lever

![](https://www.atlantic.net/wp-content/uploads/2026/02/book-mastering-AI.jpg)

**Intent: For Practical Adoption, Skills, and Applied Understanding**

**Introduction**: Mastering AI in 2025 is a hands-on guide for readers who want to move beyond headlines and use AI effectively. Ryan Lever focuses on practical understanding—how modern AI systems work, how they are applied in business and creative contexts, and how individuals can build relevant skills without becoming engineers.

#### Key Takeaways:

- It breaks down core AI concepts in clear, accessible language.
- The book emphasizes real-world use cases across business, productivity, and creative work.
- Readers gain a framework for evaluating AI tools rather than chasing trends.
- It focuses on skill-building and mindset, not just tools.

#### Points to Consider:

- The book is not a deep technical or engineering reference.
- Enterprise governance and large-scale deployment are not primary topics.
- Some examples may date quickly as tools evolve.

**Ideal for**: This book is best for professionals, entrepreneurs, and career switchers who want to learn how to use AI effectively and responsibly in day-to-day work without a technical background.

### #9: Genesis by Henry A. Kissinger, Craig Mundie, and Eric Schmidt (2025)

![](https://www.atlantic.net/wp-content/uploads/2026/02/book-genesis-ai.jpg)

**Intent: For Strategy, Governance, and the Future of Power**

**Introduction**: Genesis builds on the authors’ previous work, exploring how AI is changing power, security, and the global order. The book examines the rapid growth of AI and the challenges of governing systems as they become increasingly autonomous.

#### Key Takeaways:

- The authors present AI as a strategic force, similar to past major technological revolutions.
- The book looks at how AI affects geopolitics, national security, and global stability.
- It points out the increasing gap between how fast AI is developing and how quickly governance can keep up.
- The authors urge readers to consider how institutions should respond to AI over the long term.

#### Points to Consider:

- The book takes a strategic and philosophical approach instead of a technical one.
- There is little practical advice for engineers or operators.
- The authors focus mainly on issues at the state and global level.

**Ideal for**: This book is ideal for policymakers, senior executives, strategists, and academics who intend to understand how AI reshapes power structures, governance, and global decision-making in the coming decade.

### #10: Artificial Intelligence: A Guide for Thinking Humans by Melanie Mitchell (2019)

![](https://www.atlantic.net/wp-content/uploads/2026/02/book-guide-for-ai.jpg)

**Intent: For Critical Thinking, Limits, and Realistic Expectations**

**Introduction**: Cognitive scientist Melanie Mitchell offers a practical, questioning look at what today’s AI can and cannot do. Instead of adding to hype or fear, she explains key AI ideas in simple terms and checks bold claims against real examples. The book’s main value is in showing the limits, trade-offs, and common misunderstandings about AI.

#### Key Takeaways:

- The book explains modern AI methods, such as deep learning, in clear, simple language.
- It questions and challenges overstated claims about AI’s general intelligence and independence.
- The book points out the difference between how AI performs on tests and how it works in real life.
- Readers learn how to think critically about AI claims instead of just believing what vendors say.

#### Points to Consider:

- The book is less focused on recent generative AI breakthroughs and production tooling.
- It does not provide step-by-step guidance for building or deploying AI systems.
- Readers seeking optimism or futuristic projections may find the tone deliberately cautious.

**Ideal for**: This book is ideal for readers who want to understand AI without hype, including journalists, educators, policymakers, and business leaders who need to make informed decisions about AI adoption and risk.

## Conclusion: From Knowledge to Application

A 2026 AI reading plan works best when it matches your goal: learn the fundamentals, ship systems, govern responsibly, or evaluate societal impact. The fastest path from insight to competence is still: read, then build—because production constraints, evaluation, and failure modes only become real when you run systems end-to-end.

Services like Atlantic.Net’s [**GPU Hosting**](https://www.atlantic.net/gpu-server-hosting/) provide the necessary infrastructure for this exploration. With access to high-performance NVIDIA GPUs, developers, students, and researchers can train models, run complex simulations, and build their own AI applications. This combination of intent-driven reading and hands-on work is what turns curiosity into real capability—allowing readers to move from passive learning to active participation in artificial intelligence.

## FAQ

**What’s the best AI book for complete beginners?**

If you want a non-technical start, begin with Melanie Mitchell for clarity and skepticism, then move to Mollick for practical usage patterns.

**Which book helps most with building real AI products?**

Chip Huyen’s *AI Engineering* focuses on production constraints: evaluation, reliability, and deployed-system failure modes.

**Which book best explains the risks of advanced AI?**

Stuart Russell’s *Human Compatible* is the cleanest introduction to the control problem and why mis-specified objectives can scale harm.

**What should leaders read before setting an AI strategy?**

Read one adoption book (*Co-Intelligence*) plus one governance/strategy book (*The Coming Wave* or *Genesis*). That combination covers workflows and institutional risk.

**Why do older books still appear on a 2026 list?**

Some titles remain foundational because they teach durable concepts: agents, uncertainty, learning, and reasoning. Newer books tend to change faster because they track tools and industry structure.

**Do I need to understand math to learn AI?**

Not to start. But if you want to build or debug systems, you’ll eventually need probability, linear algebra basics, and the ability to reason about evaluation and error modes.


---

# Top LLM Companies in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/top-llm-companies/ | Published: 2026-02-24 | Updated: 2026-04-10 | Author: Richard Bailey

The field of artificial intelligence is not just advancing; it’s accelerating at an unbelievable pace. The AI market is projected to be worth a staggering [**$1.81 trillion by 2030**](https://www.grandviewresearch.com/industry-analysis/artificial-intelligence-ai-market), evidence of the technology’s profound impact on our everyday lives. The LLM sector in 2026 is no longer a race for raw parameter size, but a race for reasoning depth, efficiency, and data sovereignty. At the heart of this transformation are large language models (LLMs), sophisticated AI systems that are powering a new generation of applications.

While legacy providers continue to dominate with general-purpose models, new leaders are emerging with specialized AI designed for regulated industries and regional compliance needs, including Sovereign AI initiatives for the EU market. As we move through 2026, a handful of LLM development companies have clearly separated themselves by model philosophy – open-source versus proprietary and by how well they balance performance, control, and deployment flexibility. LLMs are custom machine learning models designed for research and commercial use. They incorporate generative AI capabilities and advanced reasoning tasks, allowing users to chat with the model to learn or perform specific tasks.

This article highlights the leading LLM companies shaping the market in 2026, examining their flagship models, their underlying model philosophy, and how their approaches align with real-world business and regulatory requirements.more

## What Is the Purpose of an LLM in 2026?

A large language model (LLM) is a machine learning model trained to generate and transform language (and increasingly, code, images, and audio). In practice, organizations use LLMs to:

- **Reduce operational friction** (summaries, drafting, policy Q&A, ticket triage)
- **Automate knowledge work** (research synthesis, structured extraction, decision support)
- **Accelerate software delivery** (code generation, review assistance, test creation)
- **Improve data access** (natural-language interfaces to internal systems)
- **Keep sensitive workflows governed** (auditability, retention controls, data residency)

Adoption is now mainstream. Stanford’s 2025 AI Index reports [**78% of organizations used AI in 2024**,](https://hai.stanford.edu/ai-index/2025-ai-index-report) up sharply year over year. Bain reports [**74% of companies rank AI as a top-three strategic priority**](https://www.bain.com/insights/executive-survey-ai-moves-from-pilots-to-production/) (Q3 2025), reflecting the shift from experimentation to production programs

Here are some of the creative ways you can engage with an LLM.

### Generative AI: Content Creation

- Use generative language models to create articles, emails, and marketing copy for e-commerce.
- Generate human language to compose creative works such as poems, scripts, or song lyrics.
- Brainstorm ideas and create outlines for projects or essays.

In 2026, content teams increasingly rely on LLMs with built-in reasoning controls to ensure outputs align with brand, legal, and regional compliance requirements.

### AI Tools for Analysis

- Perform natural language processing tasks like summarizing lengthy research whitepapers.
- Apply natural language understanding to answer questions from text.
- Extract key information like names, dates, and topics from text.
- Explain complex subjects in simple, easy-to-understand language.

Advanced reasoning models now enable multi-step analysis, making LLMs suitable for regulated workflows such as policy review and financial analysis.

### AI Systems for Language & Text

- Translate content between two or more languages.
- Rewrite text to change its style or tone (e.g., formal to informal).
- Correct grammar and spelling errors in your writing.
- Sovereign AI deployments allow organizations, particularly in the EU, to perform these tasks while keeping language data fully within regional boundaries.

### AI Assistant Interactive AI

- Build a smart chatbot or voice assistant with a system of conversational controls built in.
- Use reasoning models to solve logic puzzles and mathematical problems.
- Modern assistants increasingly support configurable guardrails and auditability, which are critical for enterprise and public-sector use cases.

### Software Development

- Write code and debug your applications.
- Convert natural language input into structured data like JSON or tables.
- LLMs are now commonly embedded directly into CI/CD pipelines to assist with code review, test generation, and documentation.

### Multimodal Interaction

- Use advanced AI models to describe the contents of an image or answer questions about it.
- Multimodal reasoning has improved significantly, enabling models to correlate text, images, and diagrams to achieve more accurate real-world interpretation.

## Best Large Language Model AI Companies

The leading LLM companies in 2026 can be broadly categorized by Model Philosophy: Proprietary Models versus open-source, efficiency-first models. Below are the companies making the most significant impact this year.

### #1: OpenAI (ChatGPT)

![](https://www.atlantic.net/wp-content/uploads/2025/06/openai-logo.png)

**Model Philosophy: Proprietary**

OpenAI remains the most recognizable LLM provider for general-purpose capability. ChatGPT’s early growth set the pace for the category—Reuters reported it reached [**100 million monthly active users**](https://www.reuters.com/technology/chatgpt-sets-record-fastest-growing-user-base-analyst-note-2023-02-01/) about two months after launch.

By 2025, usage reached truly internet-scale. An NBER working paper reports that by July 2025, users were sending [**18 billion messages per week**.](https://www.nber.org/system/files/working_papers/w34255/w34255.pdf) OpenAI has also publicly discussed prompt volume at [**2.5 billion prompts per day**](https://techcrunch.com/2025/07/21/chatgpt-users-send-2-5-billion-prompts-a-day/)

As of February 13, 2026, OpenAI’s help documentation indicates ChatGPT’s default model moved to [**GPT-5.2**](https://help.openai.com/en/articles/20001051-retiring-gpt-4o-and-other-chatgpt-models).

Get started with OpenAI, search with ChatGPT, explore research tools, and build smarter solutions using AI.
 ![OpenAI](https://www.atlantic.net/wp-content/uploads/2026/02/OpenAI.png)
 Image Source: OpenAI

#### Advantages:

- **Strong Brand Recognition**: High public awareness due to ChatGPT’s success, which currently attracts [**billions of interactions**](https://explodingtopics.com/blog/chatgpt-users) a month.
- **Leading-Edge Performance:** Consistently develops state-of-the-art, powerful AI models and excels in image creation.
- **Developer-Friendly**: Features many easy-to-use APIs for integration.
- **Extensive Research**: A key contributor to fundamental AI advancements.

#### Disadvantages:

- **Closed-Source Models**: Lack of transparency into its most powerful AI systems.
- **High-Volume Costs**: API usage can be expensive for large-scale applications.
- **Ongoing Safety Debates**: Faces scrutiny over potential misuse and model bias.

#### Ideal for:

- **Startups & Developers**: For rapid AI feature integration and prototyping.
- **Content & Marketing Teams**: For creative text generation and brainstorming.
- **Academic Researchers**: For tracking major advancements in AI model capabilities.

### #2: Anthropic (Claude)

![](https://www.atlantic.net/wp-content/uploads/2025/06/anthropic-logo.png)

**Model Philosophy: Proprietary (Safety-First Reasoning Models)**

Anthropic was founded by former senior members of OpenAI with a primary focus on AI safety and research. The company is dedicated to building reliable foundation models, interpretable, and steerable AI systems. In 2026, Anthropic’s strategy centers on controllable reasoning models designed for high-trust and regulated environments rather than mass-market scale. Their flagship large language model, Claude, is designed with a “Constitutional AI” approach, where the model’s behavior is guided by a set of principles aimed at ensuring it remains [**helpful, harmless, and honest**](https://www.anthropic.com/news/claudes-constitution).

Anthropic differentiates through safety research and “steerability,” with models widely used for long-document work and enterprise use cases. Anthropic’s Claude 4 family was announced in 2025. In February 2026, coverage indicates Anthropic released[**Claude Sonnet 4.6**](https://www.axios.com/2026/02/17/anthropic-new-claude-sonnet-faster-cheaper) with a focus on speed/cost improvements and coding capability.

Use Anthropic Artifacts to turn your ideas into working tools—whether you’re drafting content, prototyping apps, or generating insights.
 ![Anthropic (Claude)](https://www.atlantic.net/wp-content/uploads/2026/02/Anthropic-Claude.png)
 Image Source: Anthropic

#### Advantages:

- **Forefront of AI Safety**: Focused on ethical and responsible AI development.
- **“Constitutional AI” Training**: Unique approach reduces the risk of harmful or unethical outputs.
- **Advanced Comprehension**: Excels at understanding nuance in long, complex documents.
- **Enterprise-Grade Reasoning**: Strong performance in policy analysis, legal review, and structured decision-making tasks.
- **Focus on Transparency**: Actively researches methods for more interpretable AI systems.

#### Disadvantages:

- **Slower Commercial Pace**: More cautious in releasing commercial products compared to rivals.
- **Lower Public Profile**: Less brand recognition outside of the dedicated AI community.
- **Fewer Resources**: Does not possess the vast computational power of tech giants.

#### Ideal for:

- **Regulated Industries**: Finance, healthcare, and legal fields requiring high ethical standards.
- **Brand-Conscious Organizations**: Prioritizing brand safety and predictable AI behavior.
- **AI Safety Researchers**: For academic and practical work on controllable AI systems.
- **Enterprises Seeking Guardrails**: Teams that value auditability and controlled outputs over unrestricted generation.

### #3: Google (Gemini / Vertex AI)

![](https://www.atlantic.net/wp-content/uploads/2025/06/google-logo.png)

**Model Philosophy: Proprietary (Ecosystem-Integrated & Multimodal)**

As a long-standing leader in artificial intelligence research, Google has used its immense resources and extensive talent pool to become a major player in the LLM space. Google announced Gemini 3 in late 2025 as its “most intelligent” model family, expanding multimodal and reasoning capabilities across the Gemini app, AI Studio, and Vertex AI, a family of multimodal models designed to understand and process information from text, code, images, and video.

In 2026, Google’s LLM strategy prioritizes deep ecosystem integration and scalable deployment over standalone model access. Google has spent a lot of time integrating its advanced language models into its product lines, such as Gmail, Google Docs, Google Sheets, and so on.

Get started with Gemini, ask anything, explore tools, and turn your ideas into results with Google’s AI platform.
 ![gemini](https://www.atlantic.net/wp-content/uploads/2026/02/gemini.png)
 Image Source: Gemini

#### Advantages:

- **Native Multimodality**: Gemini models are built to understand various data types (text, image, video).
- **Vast Ecosystem Integration:** AI is embedded into Google Search, Workspace (Google gSuite), and Cloud.
- **Massive Infrastructure:** Unparalleled computational resources for training massive models.
- **Pioneering Research:** Google DeepMind remains a world leader in AI breakthroughs.
- **Enterprise Tooling**: Strong MLOps, data pipelines, and managed AI services for production environments.

#### Disadvantages:

- **Complex Products:** The wide array of AI services on the Google Cloud Platform can be overwhelming to navigate.
- **Image Issues:** Google changes product names too often, remember Bard?
- **Privacy:** There are big question marks over Google’s privacy; literally every AI interaction is logged and analysed by default.
- **Poor at Imaging**: Google’s AI ability to draw images and artwork is significantly behind its competitors.

#### Ideal for:

- **Google Cloud Customers**: Enterprises that are already heavily invested in the Google Cloud platform and Google Workspace products.
- **Multimodal Developers**: Those creating applications that concentrate on processing text, images, and video.
- **Large Enterprises**: Organizations that value tight integration, global scale, and managed infrastructure over model-level control.

### #4: Meta AI (LLaMA)

![](https://www.atlantic.net/wp-content/uploads/2025/06/meta-logo.jpg)

**Model Philosophy: Open-weight, community-driven deployment (with license constraints)**

Meta AI, the artificial intelligence research lab of Meta Platforms, has taken the approach to open-source LLM development. LLaMA is a series of open models that have been [**made available**](https://www.llama.com/llama-downloads/) to the research and commercial communities. In 2026, Meta’s LLM strategy emphasizes openness and efficiency, enabling organizations to deploy models on their own infrastructure with full control over data and tuning. This approach has helped popularize do-it-yourself AI solutions.

Explore Meta AI, where you can chat, create images and videos, and discover personalized suggestions in a simple, modern interface.
 ![Meta](https://www.atlantic.net/wp-content/uploads/2026/02/Meta.png)
 Image Source: Meta AI

#### Advantages:

- **Open Source**: Freely releases powerful models in open source, allowing anyone to download and experiment.
- **Developer Focused**: A large, active community that contributes and builds upon LLaMA 3.
- **Great Customization**: Open access allows for fine-tuning on proprietary data.
- **Competitive Performance**: LLaMA models often rival the large-scale AI models’ capability of closed-source alternatives.
- **Cost Control**: Self-hosting enables predictable costs compared to usage-based APIs.

#### Disadvantages:

- **Limited Official Support**: Relies more on community support than dedicated enterprise services.
- **Risk of Misuse**: The open availability of models creates a significant potential risk for bias.
- **High Self-Hosting Costs**: Requires significant computational resources to run and fine-tune.

#### Ideal for:

- **AI Researchers & Academics:** Requiring open-source access for experimentation.
- **Tech-Savvy Startups:** For building highly customized and proprietary AI solutions.
- **Organizations Seeking Data Sovereignty:** Teams that need full control over model behavior and data locality.

### #5: xAI (Grok)

![](https://www.atlantic.net/wp-content/uploads/2025/06/xai-logo.png)

**Model Philosophy: Proprietary (Real-Time, Personality-Driven Models)**

Founded by Elon Musk, xAI is one of the newer LLM companies, but one that has quickly gained media attention. The company’s stated mission is to “understand the true nature of the universe.” Its primary product, Grok, is a conversational AI designed to be witty, rebellious, and have access to real-time information through its integration with the X (formerly Twitter) platform.

In 2026, xAI differentiates itself by prioritizing immediacy and conversational tone over enterprise-grade guardrails. xAI aims to create AI that is not only intelligent but also engaging and less constrained by what it perceives as the “politically correct” norms of other AI systems.

Explore xAI’s Grok, an AI assistant designed to answer questions, generate insights, and provide real-time information in a clean interface.
 ![xAI (Grok)](https://www.atlantic.net/wp-content/uploads/2026/02/xAI-Grok.png)
 Image Source: xAI

#### Advantages:

- **Real-Time Integration**: Access to live information from Twitter.
- **Distinctive AI Personality**: Offers a witty and less conventional tone than competitors.
- **Direct Approach**: Aims to provide more direct answers with fewer content restrictions.
- **Ambitious Vision**: Backed by Elon Musk’s high profile.
- **Fast Context Awareness**: Strong performance for trending topics and breaking discussions.

#### Disadvantages:

- **Higher Risk of Inaccuracy**: Real-time data can include misinformation and unverified claims.
- **Niche User Base**: The unique personality may not be suitable for professional or formal use cases.
- **New and Unproven**: Still establishing its track record compared to veteran AI labs.
- **Public Image**: Elon Musk’s high profile is seen as a problem in some circles.

#### Ideal for:

- **Heavy X Platform Users**: Seeking a seamlessly integrated and context-aware AI.
- **Alternative AI Seekers**: Looking for less filtered, unconventional AI responses.
- **Media and Trend Monitoring**: Applications that benefit from rapid awareness of live events.

### #6: Mistral AI

![](https://www.atlantic.net/wp-content/uploads/2026/02/Mistral-AI-Logo.png)

**Model Philosophy: Open-Source & Sovereign AI (Efficiency-Led)**

Mistral AI is a European company that builds efficient, open-weight language models. The company launched Le Chat and enterprise offerings (including Le Chat Enterprise powered by “Mistral Medium 3”), keeping data local and allowing organizations to use their own infrastructure.

This makes Mistral a good choice for organizations in the EU. Its models work well on smaller hardware but still compete with larger, proprietary systems.

This Mistral AI interface lets you chat, use tools, and switch between research and thinking modes for deeper insights.
 ![Mistral AI](https://www.atlantic.net/wp-content/uploads/2026/02/Mistral-AI.png)
 Image Source: Mistral AI

#### Advantages:

- **Open-Weight Models**: Enables full inspection, tuning, and self-hosting.
- **Efficiency Focused**: Offers strong reasoning without requiring much computing power.
- **Sovereign AI Ready**: Aligns with EU data residency and regulatory expectations.
- **Rapid Iteration**: Fast release cycles with clear technical documentation.

#### Disadvantages:

- **Younger Ecosystem**: Smaller community compared to Meta or Google.
- **Limited Enterprise Services**: Fewer managed offerings than hyperscalers.

#### Ideal for:

- **European Enterprises**: Organizations prioritizing data sovereignty.
- **Cost-Conscious Teams**: Teams that want strong performance but have limited hardware.
- **Developers**: Good for developers who want transparent, adjustable models without being tied to one vendor.

### #7: DeepSeek

![deepseek](https://www.atlantic.net/wp-content/uploads/2026/02/deepseek-1.png)

**Model Philosophy: Open Models (Efficiency & Reasoning-First)**

DeepSeek stands out from other LLM providers by focusing on reasoning efficiency rather than simply building bigger models. Its models handle logic tasks well and keep inference costs low, which is useful for large projects. DeepSeek is known for research-based models that excel at structured reasoning.

Explore DeepSeek’s AI chat interface to ask questions, run searches, and generate intelligent responses in real time.
 ![DeepSeek](https://www.atlantic.net/wp-content/uploads/2026/02/DeepSeek-2.png)
 Image Source: DeepSeek

#### Advantages:

- **High Reasoning Efficiency**: Performs well for its size.
- **Lower Inference Costs**: Suitable for projects with high volume or tight budgets.
- **Research-oriented**: Provides clear benchmarks and open performance goals.

#### Disadvantages:

- **Lower Brand Recognition**: Less familiar to people outside technical fields.
- **Limited Commercial Tools**: Offers fewer enterprise integrations and managed services.

#### Ideal for:

- **Engineering Teams**: Works best for applications that require structured reasoning and logic.
- **Scalable Deployments**: Helpful when keeping the cost per query low matters.
- **Researchers and Builders**: A good choice for teams that value efficiency over simply having larger models.

## Where the LLM market is heading next

### Sovereign AI becomes a board-level requirement

“Sovereign AI” has moved from a slogan to a procurement constraint in parts of Europe. McKinsey defines it as a region’s ability to develop and control critical AI capabilities to preserve autonomy and governance in its economic and social context. With EU AI Act obligations rolling forward, data locality and governance features increasingly shape model choice.

### Mixture of Experts (MoE) becomes the efficiency playbook

MoE architectures route each token through a subset of specialized “experts,” reducing the compute required per inference while keeping quality high. This isn’t theoretical—models like Mixtral (Mistral) and DeepSeek-V3 explicitly use MoE designs to improve cost/performance.

### Multimodal is now default, not a differentiator

Text-only is increasingly the minimum. Modern deployments expect models to interpret screenshots, diagrams, and mixed media—especially in support, engineering, and operational workflows.

## Conclusion

The AI scene is a vibrant, competitive, and complex ecosystem dominated by a handful of companies, each with a distinct vision for the future. From OpenAI’s mass-market dominance and Google’s deep integration into digital workflows, to Anthropic’s principled stance on controlled reasoning, Meta’s commitment to open-source models, and xAI’s focus on real-time interaction, the choice of LLM has never been greater. New entrants focused on efficiency and sovereignty are further reshaping the competitive market.

LLM technology is split between closed, proprietary models and open, community-driven development. This divide now extends beyond licensing into questions of governance, deployment control, and regional compliance. This isn’t just a technical difference between LLM businesses; it’s a fundamental disagreement about how these similar large language models should be built, controlled, and deployed. This means making a decision to adopt an AI solution whose approach to safety, transparency, data ownership, and innovation matches your own company’s values and long-term goals.

We are already seeing LLMs reshaping business operations across every industry, creating a new wave of AI-driven services that enhance productivity and enable creative potential. The continuous cycle of AI research and development means that what is considered state-of-the-art technology today will likely be surpassed within 12 months.

We can expect to see even more advanced models emerge in the near future, with capabilities that further merge text, image, and code generation, while becoming more efficient, auditable, and deployable outside centralized clouds.

Whichever LLM company you decide to back, fine-tuning and deploying advanced LLM systems demands immense computational power that standard servers simply cannot provide. This is where high-performance infrastructure becomes critical.

To build, train, and scale your own generative AI applications, you need access to enterprise-grade hardware. Atlantic.Net provides exactly that, with powerful NVIDIA GPU hosting designed for the most demanding AI workloads. By giving you the raw power and flexible infrastructure you need, you can move beyond the limitations of closed systems and start building the future of your business.

**Ready to build?** Explore [Atlantic.Net’s GPU hosting options](https://www.atlantic.net/gpu-server-hosting/) and deploy a production-grade AI stack with the performance, control, and flexibility modern LLM workloads demand.


---

# Best Dedicated Hosting for WordPress Sites in 2026

> URL: https://www.atlantic.net/hipaa-compliant-wordpress-hosting/best-dedicated-hosting-for-wordpress-sites-in-2026/ | Published: 2026-02-26 | Author: Dr. Assad Abbas

In 2026, a high-performing WordPress site is no longer just a collection of pages; it is a heavy, data-driven application. Modern WooCommerce stores and medical SaaS platforms need immediate server responses and strict security to function.

For healthcare providers, protecting electronic Protected Health Information (ePHI (electronic Protected Health Information)) is a legal requirement that determines how you build your infrastructure. Shared hosting fails here because it cannot offer the physical hardware isolation needed for data security or the steady processing power these applications demand.

Due to these data rules and hardware needs, dedicated hosting is the standard for enterprise WordPress. For many organizations, the real question isn’t “Who’s fastest?” It’s: What kind of dedicated environment do we need, and who can operate it reliably?

## Shared vs. Cloud vs. Dedicated: What Actually Changes?

### Shared hosting

Multiple sites run on the same server and compete for CPU, memory, and disk I/O. It can be cost-effective for small sites, but performance is inherently variable—another tenant’s spike can become your outage.

### Cloud hosting

A VPS provides an isolated OS environment, but it still shares underlying hardware. Even when resources are “allocated,” noisy-neighbor effects can show up in CPU scheduling and storage latency during contention.

### Dedicated hosting (bare metal)

One physical server is reserved for one customer. That removes multi-tenant contention at the hardware level and gives you predictable access to CPU, RAM, and storage I/O.

### “Dedicated” as single-tenant hosts

Some providers use “dedicated” to describe single-tenant virtualized hosts (you get the whole host, but run VMs on top). That can still be excellent—just make sure the contract is clear about single-tenancy, oversubscription, and performance isolation.

## Why Dedicated Hosting is Essential for WordPress in 2026

The fundamental limitation of shared and virtualized WordPress hosting in 2026 is the presence of the [hypervisor](https://www.geeksforgeeks.org/system-design/hypervisor/) and the noisy neighbor effect. In a Cloud Server environment, while resources are nominally “guaranteed,” the physical CPU cycles and disk I/O are still managed by a virtualization layer. This [introduces](https://www.youstable.com/blog/vps-slow-troubleshooting) unpredictable latency and performance jitter that may not matter for small sites but become serious challenge for enterprise applications that require real-time interaction.

Performance expectations have also evolved in recent times. Metrics like [Largest Contentful Paint (LCP)](https://web.dev/articles/lcp) have given way to interaction-focused measures such as [Interaction to Next Paint (INP)](https://web.dev/articles/inp). With the adoption of the Speculation Rules API, browsers now predict user behavior and pre-request resources before a click even occurs. This means servers must handle both active and speculative requests simultaneously.

In Cloud Server or shared hosting environments, other tenants compete for CPU resources, which slows background tasks and disrupts the smooth, low-latency experience users expect today. Dedicated servers eliminate this bottleneck by removing the hypervisor layer. This becomes even more critical as WordPress adopts deeper AI capabilities through the Abilities API roadmap. AI-driven content processing, natural language queries, and large-scale WooCommerce transactions demand sustained CPU access and high-performance NVMe storage. Virtualized platforms often struggle to deliver these capabilities reliably. As WordPress expands into regulated sectors such as healthcare and SaaS, dedicated infrastructure also provides the control and compliance alignment required for handling sensitive data under frameworks like HIPAA.

## The Standard for Dedicated WordPress Hosting in 2026

In 2026, best dedicated hosting is defined not by raw hardware alone, but by how precisely that hardware aligns with modern WordPress architecture.

### Processor Architecture

In 2026, server performance is largely defined by the [competition](https://www.bacloud.com/en/blog/185/server-cpu-showdown-amd-epyc-turin-vs-intel-xeon-granite-rapids-and-sierra-forest.html) between AMD’s 5th-Gen EPYC “[Turin](https://www.servermo.com/blogs/amd-zen5-turin/)” processors and Intel’s Xeon 6 “[Granite Rapids](https://www.servethehome.com/intel-xeon-6700p-and-6500p-granite-rapids-sp-for-the-masses-initial-benchmarks-and-first-look/4/)” lineup. For WordPress workloads, which rely on many short-lived PHP processes running in parallel, AMD’s higher core density delivers better overall throughput and more predictable performance under load.

Intel Granite Rapids performs well in scenarios that depend on very strong single-core execution, such as complex database queries or certain encryption tasks. But for most high-traffic WordPress setups, AMD’s Zen 5 cores give Turin the advantage, making it easier to handle many users simultaneously without slowing down.

### Memory and Storage Performance

In 2026, RAM is no longer about size, it’s about speed. High-bandwidth memory like [DDR5-6400](https://anafrashop.com/micron-64-gb-ddr5-6400mhz-ecc-rdimm-mtc40f2046s1rc64bd2-5) and newer has become essential, especially with features such as [Lazy Objects in PHP 8.5](https://www.php.net/manual/en/language.oop5.lazy-objects.php). While these features lower overall memory usage, they depend on rapid access to cached objects to work effectively. As a result, a modern dedicated WordPress server typically starts at 64 GB of RAM and can scale up to 1 TB for large, high-traffic enterprise deployments.

Storage has also moved forward. [NVMe Gen 5](https://www.igorslab.de/en/micron-technology-introduces-3610-nvme-ssds-worlds-first-pcie-gen5-qlc-ssds-in-m-2-2230-format-with-up-to-4-tb/) drives are now standard, providing sequential read speeds over 10,000 MB/s and IOPS that far exceed older SSDs. This makes them ideal for high-traffic WordPress sites, databases, and applications that need ultra-fast storage and low latency.

### Network and Security Foundations

A dedicated server in 2026 must be backed by a global, low-latency network. High-traffic WordPress sites require 10 Gbps or even 50 Gbps dedicated ports to handle the bursts of traffic associated with viral content or coordinated marketing campaigns. Furthermore, the networking stack must support modern protocols like [TLS 1.3](https://www.cloudflare.com/learning/ssl/why-use-tls-1.3/) as the default standard for data in transit, ensuring both speed and security.

| Feature | 2026 Enterprise Standard | Impact on WordPress |
| --- | --- | --- |
| CPU | AMD EPYC Turin / Intel Xeon 6 | High-throughput PHP execution |
| Storage | NVMe Gen 5 (RAID 1/10) | Zero-latency database queries |
| RAM | DDR5-6400+ | Fast object caching and JIT performance |
| Network | 10Gbps – 50Gbps | Handle traffic spikes without congestion |
| Security | Zero-Trust / Hardware Root of Trust | Protection against supply-chain attacks |

Table 1: A summary of the standard infrastructure requirements for WordPress Hosting.

## Leading Dedicated WordPress Hosting Providers

**Atlantic.Net**

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

For over 30 years, we have built a reputation for reliability, security, and hands-on support. Our [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) are made for organizations that cannot afford the performance drops or compliance risks often seen with large cloud providers. We work closely with our clients, acting as an extension of their IT teams. Our infrastructure uses the latest AMD EPYC Turin and Intel Xeon 6 processors, giving the core density and speed that modern WordPress sites need:

- **Fully Managed Compliance:** We offer a HIPAA-compliant environment and handle the [HIPAA Business Associate Agreement (BAA) process](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/). This makes us a preferred choice for healthcare and medical SaaS providers.
- **High-Bandwidth Networking:** Our servers [connect](https://www.atlantic.net/cloud-service-level-agreement/) to a 10Gbps+ redundant network with [100% uptime SLAs](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/). This keeps high-traffic sites accessible even during peak loads.
- **Security-First Architecture:** Every server comes with a managed firewall, intrusion detection (IDS), and daily off-site encrypted backups.
- **Operational Simplicity:** While technical teams can have full root access, our [managed services](https://www.atlantic.net/vps-hosting/how-to-backup-and-restore-a-wordpress-website/) take care of monitoring, patching, and tuning to keep WordPress running at peak performance.

**Kinsta**

![](https://www.atlantic.net/wp-content/uploads/2026/02/Kinsta_logo.png)

Kinsta provides [reliable performance](https://divicake.com/blog/kinsta-performance-test-wordpress-hosting/) by running on Google Cloud’s top-tier [C3D and C2 instances](https://kinsta.com/blog/google-c3d-speed-testing/). It is known for delivering better [global performance](https://kinsta.com/blog/fastest-wordpress-hosting/) and giving developers clear insights into how their sites are running.

- **Google Cloud Premium Tier:** Kinsta uses Google’s private network for data transfer, which reduces latency compared with the public internet.
- **Edge Caching:** They provide Cloudflare Enterprise integration, offering global edge caching and advanced DDoS protection as standard.
- **Custom APM Tool:** Kinsta’s own [Application Performance Monitoring (APM)](https://kinsta.com/apm-tool/) tool helps identify slow plugins or database queries in real time, making it easier to keep sites running smoothly.

**WP Engine**

![](https://www.atlantic.net/wp-content/uploads/2026/02/WP-Engine-Logo.png)

[WP Engine](https://wpengine.com/) is popular among agencies and development teams for its advanced workflows, staging environments, and its [EverCache](https://wpengine.com/blog/evercache-upgrade-brings-smart-performance-gains-to-woocommerce/) technology.

- **Advanced Workflows:** WP Engine [provides](https://mhthemes.com/blog/wp-engine-review-wordpress-hosting/) superior staging, development, and production environments, along with Git integration that is highly useful by agencies and large development teams.
- **Global Edge Security:** Their security setup is built specifically for WordPress, providing real-time threat detection and protection against the platform’s unique vulnerabilities.
- **Headless Expertise:** Their [Atlas platform](https://wpengine.com/builders/atlas-platform-features-deployment-previews-webhooks/) makes it easy to use WordPress in a “headless” setup, letting sites run fast and handle heavy front-end interactions.

**phoenixNAP**

![](https://www.atlantic.net/wp-content/uploads/2026/02/phoenixnap.png)

For organizations that need [API-driven infrastructure](https://phoenixnap.com/bare-metal-cloud) with the speed and control of [bare metal](https://canonical.com/blog/automating-server-provisioning-in-phoenixnaps-bare-metal-cloud-with-maas-metal-as-a-service), phoenixNAP is a solid choice in 2026. Their Bare Metal Cloud makes it possible to deploy dedicated servers in minutes, giving the flexibility of the cloud with the performance of physical hardware.

- **Automation-Driven:** Everything can be managed via [API, CLI, or WebUI](https://developers.phoenixnap.com/cli), which is ideal for teams using CI/CD pipelines.
- **Network Capacity:** With a 9+ Tbps backbone and 50 Gbps capacity for high-end instances, their network can handle the most demanding streaming and media workloads.
- **Security and Compliance:** phoenixNAP provides enterprise-grade security and compliance tools, including support for HIPAA and PCI-DSS environments.

**IONOS**

![](https://www.atlantic.net/wp-content/uploads/2025/08/ionos-logo.png)

[IONOS](https://european.cloud/provider/ionos/) appeals to value-oriented enterprises seeking [ISO-certified](https://www.ionos.com/digitalguide/server/security/iso-27001/) global infrastructure, predictable pricing, and accessible support, particularly for organizations with European data residency requirements.

- **Global Footprint:** With 10 data centers across multiple continents, IONOS provides a reliable platform for international brands requiring local data residency.
- **Unlimited Traffic:** Most IONOS dedicated plans include unlimited data transfer on a 1 Gbps port, providing predictable costs for high-traffic sites.
- **Ease of Use:** Their Launch Assist and 24/7 expert support make them accessible for businesses that need dedicated power but lack deep in-house technical expertise.

**Outlook for WordPress Infrastructure in 2026**

The trajectory of WordPress infrastructure in 2026 is driven by the convergence of edge computing and [artificial intelligence](https://make.wordpress.org/ai/2025/07/17/ai-building-blocks/). What was once an advanced or experimental setup is quickly becoming the standard for enterprise sites. [Decoupled architecture](https://wpvip.com/resource/decoupled-wordpress/) is no longer a niche option. Instead, it allows WordPress to keep its core data and logic on a dedicated server, while the front-end experience is delivered through global edge networks. These edge systems can run lightweight, PHP-like logic closer to users, reducing latency and making sites feel faster and more responsive no matter where visitors are located.

Furthermore, the rise of agentic AI will transform the server’s role from a passive responder to an active participant in content generation and user interaction. This will require the integration of GPU-accelerated dedicated servers into the WordPress stack, enabling real-time inference and personalization that current CPU-only architectures cannot achieve.

Sustainability is also taking center stage. Providers that combine high-performance dedicated hardware with energy-efficient designs for power and cooling will be better equipped to meet the growing demand for environmentally responsible hosting.

**The Bottom Line**

Choosing “the best dedicated hosting” for WordPress in 2026 starts with a simple clarification: Do you need bare metal dedicated hardware, or do you need dedicated resources with a highly managed platform?

If you need maximum isolation, deep control, and compliance-driven operations, bare metal providers like Atlantic.Net, phoenixNAP, and IONOS can be strong fits—assuming their contracts and controls match your requirements.

If you want a managed WordPress experience with excellent performance tooling and edge integration, platforms like Kinsta and WP Engine can be a better operational trade-off, even if they’re not single-tenant bare metal.

The winning choice is the one that matches your workload profile, your risk tolerance, and your team’s operational capacity—not the one with the loudest spec sheet.


---

# Top Cloud GPU Servers with On-Demand Scaling in 2026 

> URL: https://www.atlantic.net/gpu-server-hosting/top-cloud-gpu-providers-on-demand-scaling-2026/ | Published: 2026-02-26 | Updated: 2026-05-03 | Author: Dr. Tehseen Zia

AI infrastructure in 2026 looks different from the “train a model, ship it, repeat” era. Many organizations now spend more time and money running models in production—often with spiky demand—than they do on periodic training runs. [Some forecasts](https://www.deloitte.com/us/en/insights/industry/technology/technology-media-and-telecom-predictions/2026/compute-power-ai.html) put inference at roughly two-thirds of total AI compute in 2026, with the share still rising.

This shift has changed what enterprises need from their data centers. For CTOs and research leads, the challenge is no longer just finding available compute; it is finding providers that can balance high-end performance with on-demand scaling and audited compliance.

## Why Legacy Clouds Are Not Suitable for AI Workloads in 2026

General-purpose cloud infrastructure is no longer [sufficient](https://www.linkedin.com/pulse/why-legacy-cloud-architectures-struggle-ai-workloads-aws-cygnet-one-uqkff/) to support the demands of modern AI. While legacy clouds were architected for predictable, steady-state patterns such as web servers, databases, and standard batch processing, AI workloads in 2026 are highly [volatile](https://modal.com/blog/the-future-of-ai-needs-more-flexible-gpu-capacity) in nature.

For example, a research team might deploy 1,000 GPUs for a single week of fine-tuning, while a startup may need 10x of its inference capacity overnight to handle a viral surge. These workloads demand a specialized hardware stack and a rigorous approach to compliance: To meet these demands, we are witnessing a total shift in AI hosting.

Providers are [no longer](https://www.anyscale.com/blog/gpu-in-efficiency-in-ai-workloads) just focusing on adding “more GPUs” in their data centers. Instead, they are designing AI infrastructure from the ground up for AI to be AI-native. This includes a diverse ecosystem of specialized silicon accelerators alongside established GPU architectures, all optimized for a specialized AI workload. The compute is now inseparable from regulation.

Providers must now offer automated provenance tracking and sovereign data boundaries to ensure that highly sensitive training data and model weights meet evolving global standards (like the [EU AI Act](https://artificialintelligenceact.eu/) and updated [SOC3](https://cloud.google.com/security/compliance/soc-3?hl=en) requirements).

## What “On-Demand GPU Scaling” Really Means in 2026

In 2026, the term “on-demand” no longer just refers to a simple billing feature. It has become a technical standard where hardware and software work together to keep up with the specific needs of an AI workload. The goal now is to get high-level performance and stay compliant with regulations without losing control of the budget. Today, on-demand scaling is defined by how well a provider handles these core aspects:

- **Provisioning Time**: It means being able to set up a GPU cluster in minutes. If it takes days or weeks to get hardware ready, it is not truly on-demand. This speed is [necessary](https://www.gmicloud.ai/blog/whats-the-quickest-way-to-access-gpu-computing-for-ai-projects-in-2025) for both research and handling sudden jumps in user traffic.
- **Elasticity**: It refers to the [ability](https://cast.ai/blog/kubernetes-gpu-autoscaling-how-to-scale-gpu-workloads-with-cast-ai/) to add or remove GPUs as your workload changes. This should happen automatically or with a few clicks, and it should not cause your services to go offline.
- **Orchestration**: It means infrastructure should [work](https://sealos.io/blog/the-ultimate-guide-to-gpu-provisioning-and-management-in-kubernetes) directly with tools like [Kubernetes](https://kubernetes.io/) and [Kubeflow](https://www.kubeflow.org/). This makes it easier to manage the full lifecycle of AI jobs without having to manually configure every server.
- **Storage Throughput**: Fast GPUs are only useful if they aren’t waiting for data. On-demand systems must include [storage](https://introl.com/blog/object-storage-ai-gpu-direct-storage-200gb-throughput) that can feed large datasets to the processors at “line speed” to prevent idle time.
- **Networking:** For jobs that run across multiple machines, the connection between nodes must be [fast and have low latency](https://www.together.ai/blog/multi-node-gpu-training). This ensures the GPUs can communicate effectively during large-scale training.
- **Compliance & Governance:** In 2026, on-demand also [means](https://www.convotis.com/en/news/sovereign-cloud-in-2026-architecture-trade-offs-for-regulated-data-and-ai-workloads/) having built-in tools for data sovereignty and audit trails. You need to know that your scaling happens within a secure, [regulated environment](https://introl.com/blog/compliance-frameworks-ai-infrastructure-soc2-iso27001-gdpr) that meets global standards.
- **Cost Predictability:** You need access to the latest hardware with clear pricing. This means no hidden fees for moving data and no unexpected charges that could break a project’s budget.

### **Top GPU Cloud Providers in 2026**

1. **Atlantic.Net: The Compliance-Defined Leader**

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

While the industry often chases raw speed, sectors like healthcare, finance, and legal SaaS require infrastructure where security is integrated into the hardware layer. [Atlantic.Net](https://www.atlantic.net/) has positioned itself as the premier partner for organizations managing sensitive data, such as [Electronic Protected Health Information (ePHI (electronic Protected Health Information))](https://www.metomic.io/resource-centre/what-is-ephi).

- **Hardware:** Atlantic.Net focuses on [NVIDIA H100 NVL and L40S](https://www.atlantic.net/gpu-server-hosting/an-overview-of-popular-nvidia-gpus/) architectures, which offer stability and high-frequency inference needed for reasoning AI.
- **Compliance Core:** The platform is [audited](https://www.hipaahq.com/atlantic-net-review-hipaa-compliant-hosting/) for HIPAA/HITECH, [PCI DSS](https://www.techtarget.com/searchsecurity/definition/PCI-DSS-Payment-Card-Industry-Data-Security-Standard), [SOC 2](https://cloud.google.com/security/compliance/soc-2?hl=en), and [GDPR](https://en.wikipedia.org/wiki/General_Data_Protection_Regulation). For healthcare clients, Atlantic.Net provides a formal [HIPAA Business Associate Agreement (BAA) (BAA)](https://www.techtarget.com/healthtechsecurity/feature/What-Is-a-HIPAA-Business-Associate-Agreement-BAA).
- **Predictable Governance:** By offering dedicated and private infrastructure, they eliminate the “[noisy neighbor](https://www.techtarget.com/searchcloudcomputing/definition/noisy-neighbor-cloud-computing-performance)” risks found in shared public clouds.
- **Human Support:** Unlike many hyperscalers, Atlantic.Net offers 24/7/365 access to experienced engineers rather than tiered chatbots. This is critical, especially for production workloads that cannot afford downtime.

1. **Amazon Web Services (AWS)**

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

AWS remains the largest hosting provider for AI in 2026. The cornerstone of their current lineup is the [P6 instance](https://aws.amazon.com/ec2/instance-types/p6/) family. These instances incorporate [NVIDIA Blackwell and Blackwell Ultra architectures](https://aws.amazon.com/blogs/machine-learning/aws-ai-infrastructure-with-nvidia-blackwell-two-powerful-compute-solutions-for-the-next-frontier-of-ai/) to provide high-density compute for large-scale deployments.

- **Scaling:** The [P6e-gb200 UltraServers](https://aws.amazon.com/ec2/instance-types/p6/) deliver massive memory bandwidth via the Elastic Fabric Adapter (EFAv4).
- **Ecosystem:** Integration with [SageMaker and S3](https://aws.amazon.com/blogs/machine-learning/simplify-modelops-with-amazon-sagemaker-ai-projects-using-amazon-s3-based-templates/) remains its strongest selling point, though the complexity of the AWS interface can be a barrier for smaller teams.

1. **Microsoft Azure**

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

Azure has recently partnered with NVIDIA and made a transition toward “[AI superfactories](https://blogs.nvidia.com/blog/nvidia-microsoft-ai-superfactories/).” This partnership enables Azure to ensure immediate availability of the [Rubin platform](https://azure.microsoft.com/en-us/blog/microsofts-strategic-ai-datacenter-planning-enables-seamless-large-scale-nvidia-rubin-deployments/), a new benchmark for “extreme co-design.” This platform utilizes [Rubin GPU HBM4](https://developer.nvidia.com/blog/inside-the-nvidia-rubin-platform-six-new-chips-one-ai-supercomputer/) (High Bandwidth Memory 4) to achieve significant improvements in capacity and bandwidth over the previous Blackwell generation. This increased throughput is essential for overcoming the “memory wall” problem. By clearing this bottleneck, Azure’s infrastructure can handle the massive [Mixture-of-Experts (MoE)](https://www.datacamp.com/blog/mixture-of-experts-moe) architectures more efficiently .

- **Systems Approach:** Their [ND series VMs](https://learn.microsoft.com/en-us/azure/virtual-machines/sizes/gpu-accelerated/nd-series?tabs=sizebasic) are optimized by “[Azure Boost](https://learn.microsoft.com/en-us/azure/azure-boost/overview)” offload engines.
- **Identity Management:** Integration with [Microsoft Entra ID](https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-id) (formerly Azure AD) makes it a natural fit for enterprises already deep in the Microsoft ecosystem.

1. **Google Cloud Platform (GCP)**

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

Google’s “[AI Hypercomputer](https://docs.cloud.google.com/ai-hypercomputer/docs/overview)” concept combines hardware and software into a single environment. This [architecture](https://kartaca.com/en/decoding-the-engine-room-googles-ai-infrastructure-from-hypercomputer-to-tpu/) treats data center as a unified computer rather than a collection of separate servers.

- **A4X Max:** This instance is designed specifically for reasoning in AI. It features the [NVIDIA GB300 NVL72](https://www.nvidia.com/en-us/data-center/gb300-nvl72/) to provide the massive interconnect speeds required for models that process text, image, and video simultaneously.
- **Flexibility:** GCP provides the most flexibility in choosing CPU and memory combinations to attach to specific GPUs.

1. **CoreWeave**

![](https://www.atlantic.net/wp-content/uploads/2025/05/coreweave.png)

[CoreWeave](https://www.coreweave.com/) is an independent GPU cloud designed specifically for large-scale AI workloads. By focusing on high-end compute without the overhead of traditional general-purpose clouds, they have introduced specialized tools for managing massive clusters:

- **Mission Control:** Their Kubernetes-native orchestrator treats entire GPU racks as single programmable entities. This allows them for more efficient provisioning and management of the hardware at scale.
- **Straggler Detection:** They provide real-time [diagnostics](https://docs.coreweave.com/products/sunk/manage_sunk/straggler-detection) to identify specific GPUs causing latency bottlenecks in large training jobs.

1. **Lambd**

![](https://www.atlantic.net/wp-content/uploads/2025/05/lambda.png)

[Lambda](https://lambda.ai/blog/introducing-lambda-1-click-clusters-a-new-way-to-train-large-ai-models) is known for frictionless setup and academic-friendly pricing.

- **1-Click Clusters:** This [feature](https://lambda.ai/1-click-clusters) allows researchers to launch production-grade clusters via a simple API.
- **Lambda Stack:** To ensure teams can start working immediately, Lambda provides a pre-configured software [environment](https://lambda.ai/lambda-stack-deep-learning-software) where PyTorch, CUDA, and other essential libraries are optimized to work together out of the box.

1. **RunPod**

![](https://www.atlantic.net/wp-content/uploads/2025/08/runpod-logo.png)

[RunPod](https://www.runpod.io/) has positioned itself as the most [agile](https://www.runpod.io/articles/comparison/scaling-up-vs-scaling-out) choice for “bursty” workloads and rapid prototyping.

- **Serverless GPUs:** Their “[FlashBoot](https://apatero.com/blog/runpod-serverless-deployment-complete-guide-2025)” technology allows GPU workers to scale from zero to thousands in seconds.
- **Cost Efficiency:** They utilize a [per-second billing model](https://www.runpod.io/articles/guides/how-ai-startups-can-stay-lean-without-compromising-on-compute), ensuring that users only pay for active compute time. This eliminates the “idle tax” often associated with reserved instances in larger clouds.

## **Strategic Recommendations for 2026**

When evaluating a GPU provider in 2026, the decision should not be based only on raw processing power. Physical, legal, and regulatory constraints must also be considered. If your AI workload involves sensitive data such as Protected Health Information (PHI), compliance should be the starting point. Prioritize HIPAA-compliant providers that offer built-in HIPAA or SOC compliance and are willing to sign BAAs. This is especially critical in healthcare and finance, where the consequences of a data breach far outweigh any marginal gains in speed or performance.

Since inference now dominates total costs, it is critical to prioritize hardware with superior memory bandwidth, such as HBM4, and low-latency interconnects like the Rubin or MI400 architectures. To maintain agility, you should invest in containerized environments like Kubernetes that support multi-cloud and cross-regional migration, which allows you to navigate volatile pricing effectively. It is also necessary to verify a provider’s physical capacity by performing due diligence on their liquid cooling systems and power stability, as high-density loads can lead to thermal throttling in sub-standard facilities. Finally, you should plan for annual cycles by avoiding the sunk costs of on-premises hardware; the current pace of advancement is so rapid that hardware can become relatively obsolete within a single fiscal year


---

# Most Reliable Dedicated Hosting for Regulated Industries in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/reliable-dedicated-hosting-regulated-industries-2026/ | Published: 2026-02-27 | Updated: 2026-06-24 | Author: Dr. Tehseen Zia

For regulated industries, “reliable hosting” no longer means “the server stayed up.” Uptime is table stakes.

In 2026, reliability also means your environment can withstand an audit: strong physical and logical controls, clear accountability, and evidence (logs, access records, change history) that your organization maintained control of sensitive data. For healthcare, that includes protecting electronic [Protected Health Information](https://en.wikipedia.org/wiki/Protected_health_information) (ePHI) under HIPAA, and having the contractual and operational posture to prove it.

This guide reframes reliability for regulated workloads and reviews a short list of providers commonly used for compliance-sensitive infrastructure, including dedicated servers and [single-tenant](https://www.atlantic.net/dedicated-server-hosting/achieving-unparalleled-security-with-single-tenant-dedicated-hosting/) options.

## What Makes Hosting “Reliable” for Regulated Industries?

Before we examine the list of providers, we need to reframe the definition of reliability. In the context of critical workloads, reliable hosting essentially involves three key requirements. The first requirement is infrastructure stability, which essentially includes hardware redundancy, stable power supplies, and low network latency. The second requirement is compliance validation.

This means a reliable host for a critical workload (for example, a healthcare service) must understand and honor the HIPAA [Business Associate Agreement](https://www.techtarget.com/healthtechsecurity/feature/What-Is-a-HIPAA-Business-Associate-Agreement-BAA) (BAA). The agreement essentially indicates whether the provider stands behind its infrastructure legally and shares responsibility for physical security and hardware integrity. If a provider hesitates to sign a BAA, it is not reliable for your use case. The third requirement is operational transparency.

This means the hosting provider gives you clear, detailed, and real-time visibility into how your infrastructure is performing, how it is being managed, and how it is secured. It also means having direct access to a qualified technical expert whenever an issue arises. For regulated workloads, it is essential to have a support team that understands the difference between a routine server problem and a compliance-related logging requirement.

## What to Look for Before You Sign a Contract

Before evaluating any specific provider, it is helpful to translate the definition of reliability into a clear framework that can help you assess hosting providers.

- **BAA availability and scope:** If your hosting provider handles PHI, you need [BAA](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) as a legal requirement under HIPAA. The BAA should be specific, not generic. It should define responsibilities around breach notification, subcontractor oversight, and data destruction.
- **Physical and logical isolation:** [Dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) essentially mean no [noisy neighbors](https://www.techtarget.com/searchcloudcomputing/definition/noisy-neighbor-cloud-computing-performance), but you also want to understand how your environment is segmented at the network level. It is important to look for features such as [firewall](https://www.atlantic.net/managed-services/firewall/) management, [private VLANs](https://en.wikipedia.org/wiki/Private_VLAN), and clearly documented access control policies.
- **Uptime SLAs backed by redundancy**: A 99.99% uptime claim is only meaningful if it is backed by redundant power, diverse network connectivity, and a clear process for hardware replacement. It is vital to ask about mean time to replace failed components and whether spare hardware is kept on-site.
- **Security certifications**: [SOC 2 Type II](https://www.imperva.com/learn/data-security/soc-2-compliance/), [HITRUST](https://en.wikipedia.org/wiki/HITRUST), and [PCI DSS](https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard) certifications are indicators that a provider has had its controls independently verified. These are not guarantees, but they are far more meaningful than self-attestation.
- **Support quality**: For mission-critical healthcare systems, you need access to knowledgeable engineers. It is important to ask whether the provider offers 24/7 phone and chat support from staff who understand compliance requirements, not just server administration.
- **Data center location and sovereignty**: Depending on your organization’s contracts and regulatory environment, you may need your data to remain in specific geographic regions.

With that framework in mind, let’s look at the providers who consistently deliver on this criterion.

## The Most Reliable Dedicated Hosting Services in 2026

 

1. **Atlantic.Net**

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

[Atlantic.Net](https://www.atlantic.net/) has built a reputation by focusing on the specific needs of regulated industries. [Founded](https://www.atlantic.net/hosting-services-provider/history/) in1994, it predates most of the compliance regulations it now helps clients satisfy. That kind of longevity in the hosting is rare and usually indicates a stable, well-managed balance sheet and infrastructure. For healthcare organizations, their primary [focus](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-hosting-an-in-depth-buyers-guide/) is the combination of fully managed dedicated servers and a HIPAA-compliant stack. They offer a straightforward path to compliance that allows digital health founders to focus on their applications rather than the details of data center audits.

– **HIPAA-Compliant by Design:** Atlantic.Net [provides](https://www.atlantic.net/hipaa-compliant-hosting/) a comprehensive [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/what-is-a-hipaa-certification/) environment including signed BAA, physical safeguards, [data encryption](https://www.atlantic.net/hipaa-compliant-hosting/encryption-for-hipaa-compliance/), and redundant power.

– **Managed Dedicated Servers:** For SaaS providers who need raw power but do not want to manage the physical servers, their managed dedicated hosting removes the administrative overhead. They handle hardware monitoring, [security patching](https://www.acronis.com/en/blog/posts/security-patching-complete-guide/), and basic server administration, which is invaluable for companies that lack dedicated IT teams.

– **Flexible Deployment:** They offer both dedicated servers and [private cloud](https://www.atlantic.net/private-cloud-hosting/what-is-private-cloud-hosting/) options. This allows you to start with a predictable monthly cost and scale to a more complex virtualized environment as your data volume grows.

1. **AWS (Amazon Web Services)**

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

[AWS dedicated hosting](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/dedicated-hosts-overview.html) combines isolation of physical hardware with ecosystem of AWS. They [provide](https://www.justaftermidnight247.com/insights/aws-hipaa-compliance-checklist-healthtechs/) HIPAA-eligible [services](https://aws.amazon.com/compliance/hipaa-compliance/) to support complex SaaS architectures. The reliability of AWS, however, requires a high degree of internal expertise. They follow a [shared responsibility model](https://aws.amazon.com/compliance/shared-responsibility-model/), which means Amazon secures everything of the cloud (the infrastructure), while you are responsible for securing everything in the cloud (your data, applications, and settings). For a healthcare SaaS founder, building a HIPAA-compliant environment on AWS is like being given the keys to a city and having to build your own house from scratch. It is possible, and the materials are top-tier, but you need a strong architecture team.

– **Global Infrastructure**: With data centers all over the world, AWS allows regulated industries to keep data resident in specific geographic regions to satisfy local data sovereignty laws.

– **Depth of Services**: Besides dedicated instances, they offer a massive ecosystem for data lakes, machine learning, and analytics, which is attractive for research teams dealing with genomic data or large imaging files.

– **Compliance Scope**: They offer a detailed HIPAA eligibility [checklist](https://aws.amazon.com/compliance/hipaa-compliance/) and will sign a BAA. However, the onus is entirely on the customer to configure the services correctly, which often necessitates third-party consulting help.

1. **Microsoft Azure**

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

If AWS is the leader in scalable compute, [Azure](https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-hipaa-us) is the [leader](https://azure.microsoft.com/en-us/blog/microsoft-named-a-leader-in-the-2025-gartner-magic-quadrant-for-distributed-hybrid-infrastructure/) in hybrid workflows. For many regulated industries like healthcare, particularly those already built on the Microsoft ecosystem like [.NET](https://dotnet.microsoft.com/en-us/learn/dotnet/what-is-dotnet), Azure provides the most straightforward way to move those workloads to the cloud. For example, if an IT professional is tasked with modernizing a hospital’s infrastructure, Azure offers the reliability of familiar tools combined with the power of [cloud scalability](https://www.atlantic.net/hipaa-data-centers/cloud-scalability-for-a-limitless-app-launch/).

– **Hybrid Capability:**

[Azure Arc](https://azure.microsoft.com/en-us/products/azure-arc) and [Azure Stack](https://azure.microsoft.com/en-us/products/azure-stack/hub) enable organizations to manage both on-premises and cloud servers from a single dashboard. This is critical for research teams that need to process data locally but store it long-term in the cloud.

– **Industry-Specific Solutions:** Microsoft has invested heavily in healthcare-specific APIs and data models (like the [Azure API for FHIR](https://learn.microsoft.com/en-us/azure/healthcare-apis/azure-api-for-fhir/overview)), which accelerates development for digital health startups building interoperable solutions.

– **AI and Cognitive Services:** For organizations analyzing unstructured clinical notes or medical images, [Azure’s AI tools](https://azure.microsoft.com/en-us/products/ai-foundry/tools) offer powerful ways to extract insights while maintaining the compliance of the underlying dedicated infrastructure.

1. **Rackspace**

![](https://www.atlantic.net/wp-content/uploads/2025/12/rackspace_logo.png)

[Rackspace Technology](https://www.rackspace.com/library/what-is-dedicated-hosting) has been an active player in the dedicated hosting industry for years. The company built its reputation on what it calls “[Fanatical Support](https://www.rackspace.com/resources/fanatical-support-aws-solution-overview),” a commitment that matter for organizations with small IT teams. While Rackspace offers public cloud services, its core strength remains dedicated [bare-metal](https://www.ibm.com/think/topics/bare-metal-dedicated-servers) infrastructure. That experience is especially valuable for organizations operating in regulated environments. For compliance officers, it provides confidence that the underlying infrastructure is properly managed and monitored. For healthcare SaaS [providers](https://www.rackspace.com/industry/healthcare) that want to focus on developing their applications rather than managing hypervisors or physical network hardware, Rackspace is a reliable [solution](https://www.rackspace.com/compliance/hitrust).

– **Managed Operations:** Rackspace will manage your operating system and application stack (depending on the service level). This reduces the administrative burden on your internal team and ensures that critical patches are applied consistently.

– **Multi-Cloud Management:** They can manage infrastructure across various public clouds as well as your own dedicated data center. This provides a unified support experience for complex hybrid architectures.

– **Compliance Expertise:** Their support teams are trained on compliance requirements, meaning they understand the importance of audit logs and access controls. This level of understanding reduces the risk of misconfigurations that could lead to a breach.

1. **Google Cloud Platform (GCP)**

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

[Google Cloud](https://cloud.google.com/infrastructure?hl=en) provides reliability from a slightly different angle. Its global network is among the most advanced in the world and runs on the same infrastructure that powers services like Google Search and YouTube. For regulated industries and research teams working with large datasets such as genomics, proteomics, or medical imaging, Google Cloud provides [tools](https://cloud.google.com/?hl=en) that can process data quickly and efficiently. The platform also maintains strong security standards and offers clear guidance for organizations that need to meet [HIPAA requirements](https://cloud.google.com/security/compliance/hipaa). Where Google Cloud stands out is in combining a clean, developer-friendly environment with the scale of Google’s data centers. For startups building AI-driven diagnostic solutions, it [offers](https://cloud.google.com/blog/products/networking/google-global-network-principles-and-innovations) reliable compute resources along with advanced AI capabilities in a single, integrated platform.

– **Superior Network:** Google’s global fiber network ensures low latency and high throughput, which is essential for streaming data like large medical imaging files or running real-time analytics.

– **Big Data and Analytics:** Tools like [BigQuery](https://cloud.google.com/bigquery?hl=en) allow researchers to run SQL queries on petabytes of data in seconds. This makes it a powerful platform for population health studies and clinical research.

– **Security Infrastructure:** Google invests heavily in security, including hardware-level security features like [Titan security chips](https://docs.cloud.google.com/docs/security/titan-hardware-chip) on their servers. This provides a strong foundation for the physical layer of the compliance stack.

## The Bottom Line

Choosing the most reliable dedicated hosting service depends on aligning the provider’s strengths with your organization’s needs. If you have a large DevOps team, hyperscale clouds like AWS and Azure offer unmatched flexibility. If your focus is on advanced data analysis, Google Cloud provides powerful tools. But if you are a healthcare organization looking for a host who treats compliance as a baseline feature rather than an add-on and who offers the managed support to implement it, Atlantic.Net offers a stable, transparent, and dependable solution. The most reliable host is not just the one with the fastest processors. It is the one that ensures your data stays private, your access stays secure, and your infrastructure passes the audit.


---

# Best Fully Managed PCI-Compliant Hosting Providers 2026

> URL: https://www.atlantic.net/pci-compliant-hosting/fully-managed-pci-compliant-hosting-providers-2026/ | Published: 2026-02-28 | Updated: 2026-02-27 | Author: Robert Agar

Businesses that process credit card payments must comply with the Payment Card Industry Data Security Standard (PCI-DSS). Companies can meet PCI DSS requirements with a secure in-house IT environment or a PCI-compliant hosting solution. Organizations may choose to engage a managed services provider to ensure PCI compliance.

This article examines PCI compliance requirements and how to meet them with PCI-compliant hosting. We will discuss the primary features to look for in a fully managed PCI hosting solution to protect your business from non-compliance penalties. We will also identify several providers that offer the best PCI-compliant hosting.

## Introduction to PCI Compliance

PCI compliance is the process of adhering to the Payment Card Industry Data Security Standard (PCI DSS), a complete set of security standards established to safeguard cardholder data. Any business that accepts, processes, stores, or transmits credit card information is required to maintain a secure environment to protect sensitive cardholder data from unauthorized access and data breaches. PCI DSS outlines specific requirements for data encryption, secure authentication, and regular vulnerability scans to identify and address potential security risks. By following these security standards, organizations can significantly reduce the risk of financial loss and reputational damage associated with compromised payment data. Achieving and maintaining PCI compliance is not just a regulatory obligation—it is a critical step in building customer trust and ensuring the ongoing security of your business operations.

## Benefits of PCI Compliant Hosting

Opting for PCI compliant hosting brings a host of benefits to businesses, especially those operating online stores or handling credit card payments. The primary advantage is the reliable protection of cardholder data, which helps prevent costly data breaches and the negative publicity that can follow. By hosting your website or application in a PCI compliant environment, you demonstrate a commitment to meeting the highest security standards, which reassures customers that their sensitive information is safe. This trust can translate into increased sales and customer loyalty. Additionally, PCI compliant hosting helps businesses avoid the significant fines and penalties that can result from non compliance with PCI standards. By partnering with a compliant hosting provider, organizations can streamline their compliance efforts, ensuring their hosting environment is always up to date with the latest security protocols and allowing them to focus on growing their business.

## Choosing a PCI Compliant Host

Selecting a PCI compliant host is a crucial step for any business that handles credit card data. When evaluating hosting providers, look for those that offer fully managed PCI hosting solutions, which typically include regular vulnerability scans, advanced intrusion detection systems, and reliable data encryption. A strong security stack—featuring firewalls, access controls, and continuous monitoring—should be standard to ensure rapid detection and response to any security incidents. Turnkey compliance solutions can further simplify the process, providing pre-configured environments that meet PCI DSS standards out of the box. It’s also important to review the provider’s compliance documentation, such as their Attestation of Compliance (AOC), to verify that they meet all necessary PCI requirements. By carefully assessing these factors, businesses can confidently choose a hosting provider that will help them protect card data and maintain ongoing PCI compliance.

## Types of PCI Compliant Hosting

Businesses have several options when it comes to PCI compliant hosting solutions, each catering to different operational needs and budgets. Dedicated hosting offers the highest level of security and customization, making it ideal for large enterprises with complex requirements. Cloud hosting provides scalability and flexibility, allowing businesses to easily adjust resources as their needs change—perfect for companies experiencing variable traffic or rapid growth. Virtual Private Server (VPS) hosting strikes a balance between dedicated and shared hosting, offering a secure, isolated environment at a more accessible price point. For small businesses, shared hosting can be a cost-effective option, provided the hosting provider implements strong security measures and offers tools to help merchants achieve PCI compliance. By understanding the strengths of each hosting type, organizations can select the PCI compliant hosting solution that best fits their unique needs.

## What Are PCI-DSS Requirements?

Organizations that store, process, or transmit credit card data achieve and maintain PCI-DSS compliance by meeting the mandatory security requirements defined by the PCI Security Standards Council. PCI-DSS is a global standard supported by all major credit card companies that covers cardholder data, such as primary account numbers (PANs) and cardholder names, as well as sensitive authentication data, such as CVVs and PINs.

Twelve core PCI-DSS requirements are defined across the following six objectives to protect cardholder data.

### Build and maintain a secure network

The first objective is to ensure that cardholder data is processed in a secure network environment. Companies must meet two specific requirements to address this objective.

1. They must install and maintain firewalls to protect sensitive cardholder data.
2. Teams cannot use vendor defaults, such as passwords and base configurations, that can be easily compromised by threat actors.

### Protect cardholder data

Organizations must implement the following two requirements to protect cardholder data.

1. Teams must protect stored cardholder information by encrypting PANs at rest with strong AES-256 or equivalent encryption. PANs must be masked when they are displayed. Companies should never store PINs or CVVs.
2. All cardholder data must be encrypted during transmission across open or public networks.

### Maintain a vulnerability management program

PCI compliance requires companies to effectively manage system and security vulnerabilities, maintain a secure environment, and minimize risk.

1. Teams must implement anti-malware software and similar solutions to prevent threat actors from accessing card data. They must perform quarterly PCI scans to assess and address potential vulnerabilities.
2. Companies must develop and maintain a safe computing environment by implementing a complete patch management process and enforcing safe coding practices.

### Implement strong user access controls

Organizations must control access to the systems that store and process cardholder data by implementing the following three core requirements.

1. Teams must restrict access on a business need-to-know basis, essentially enforcing the principle of least privilege regarding sensitive cardholder data with strong internal controls.
2. All users with access to regulated data must be identified with unique IDs. Admin and remote access must be protected with multi-factor authentication (MFA) to minimize the risk of a data breach.
3. Companies must provide physical security and restrict physical access to systems containing payment data.

### Regularly monitor and test networks

Companies must monitor and test the networks used to process and transmit cardholder data to meet these two core PCI-DSS requirements.

1. All network access must be tracked and monitored using a centralized logging solution, with logs retained for at least 1 year.
2. Teams must regularly test the networks with security tools, including vulnerability scans, penetration testing, and intrusion detection and prevention solutions.

### Maintain an information security policy

The final objective for PCI compliance is to develop and maintain a security policy.

1. Companies must implement defined incident response and risk management policies and procedures. Organizations must provide security awareness training to all employees who handle cardholder data.

## What Are PCI-DSS Compliance Levels?

Businesses fall into one of four distinct PCI-DSS compliance levels based on the number and type of credit card payment transactions they process each year. The levels represent the degree of risk and are accompanied by varying compliance validation requirements.

### Level 1

Companies at Level 1 represent the highest risk and are subject to the most stringent compliance validation. These are large businesses and global ecommerce platforms that process over six million transactions annually. An organization can also be designated as Level 1 by a credit card provider after a data breach.

Organization at Level 1 must demonstrate PCI compliance by stringent validation requirements that include:

- Annual on-site audits by a qualified security assessor (QSA);
- An annual report on compliance (ROC);
- Submitting an attestation of compliance (AOC);
- Quarterly vulnerability scans by an approved scanning vendor (ASV).

### Level 2

Level 2 comprises companies that process one to six million transactions per year. They are considered medium risk and must meet validation requirements, including:

- An annual self-assessment questionnaire (SAQ);
- Submission of an AOC;
- Quarterly ASV scans.

### Level 3

Level 3 businesses process between 20,000 and one million ecommerce transactions, and fewer than one million total transactions. Companies in Level 3 often only support online stores. They are subject to the same validation requirements as Level 2 businesses, including an annual SAQ, an AOC, and quarterly ASV scans.

### Level 4

Businesses at Level 4 process fewer than 20,000 annual ecommerce transactions and up to one million total transactions. These companies are typically small businesses and startups, subject to less rigorous PCI-DSS validation requirements. They must perform an annual SAQ and may be required to conduct quarterly ASV scans and submit an AOC based on the credit card carriers involved.

## Essential Features of Managed PCI-Compliant Hosting Providers

Many organizations protect cardholder data through PCI-compliant hosting solutions. Decision-makers should insist that a compliant hosting vendor provide these essential features:

- A PCI-compliant infrastructure including hardened servers and a segmented cardholder data environment (CDE);
- reliable network segmentation to reduce PCI scope and firewall management;
- Strong data encryption for cardholder data at rest and in transit;
- Centralized logging and log retention;
- complete vulnerability management, patching, and scanning support;
- Intrusion detection to prevent threat actor access;
- Secure access controls limiting credential compromise;
- Managed backup and disaster recovery services;
- Compliance and audit support with PCI scan results;
- 24/7/365 security monitoring and incident response procedures;
- A clear shared responsibility security model.

PCI compliance hosting is essential for any business that stores, processes, or transmits credit card data. Maintaining PCI compliance can significantly reduce a business’s liability in the event of a data breach. The shared responsibility model means that while the hosting provider secures the infrastructure, the business is responsible for securing its own applications and data. Many fully managed PCI compliant hosting providers also offer PCI assistance, including guidance on PCI scans and compliance reviews, especially for customers on VPS or dedicated hosting plans.

## Hosting Provider Responsibilities

Hosting providers play a pivotal role in supporting businesses on their journey to PCI compliance. Their responsibilities include delivering a secure hosting environment that aligns with PCI DSS requirements, conducting regular security scans and audits to uncover vulnerabilities, and enforcing strict access controls to safeguard cardholder data. Providers should ensure that all payment processing data is encrypted both in transit and at rest, protecting sensitive information throughout every stage of the transaction. In addition, hosting providers are expected to assist customers with proper configuration, offer guidance on security best practices, and facilitate quarterly PCI scans to maintain compliance. By fulfilling these obligations, hosting providers help reduce the complexity of PCI compliance for their clients, allowing businesses to focus on their core operations while ensuring the ongoing security of their customers’ financial data.

## The Best Fully Managed PCI-Compliant Hosting Providers

The following list of hosting providers all offer solutions that meet the PCI Data Security Standard. Providers like Liquid Web, Atlantic.Net, and AWS offer tailored PCI DSS solutions ranging from shared to cloud and enterprise hosting. Businesses must also ensure that any third-party services they use are PCI compliant. In all cases, customers are responsible for understanding their role in securing the environment and ensuring PCI compliance.

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

### [Atlantic.Net](https://www.atlantic.net/pci-compliant-hosting/)

Atlantic.Net offers its customers a range of PCI-compliant hosting options to meet their specific business use cases. Clients can choose self-managed or [fully managed](https://www.atlantic.net/managed-services/server-management/) dedicated or cloud servers. The company provides encrypted backups with offsite replication for enhanced resilience. Features such as a managed firewall and an intrusion detection system keep threat actors from accessing sensitive cardholder data.

The benefits of Atlantic.Net’s managed PCI hosting services include:

- Turnkey compliance with pre-configured, fully PCI-compliant servers;
- Advanced monitoring and security stack;
- A SOC audit-ready environment;
- 24/7 U.S.-based support;
- Over 31 years of successfully meeting customer expectations.

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

### [Amazon Web Services (AWS)](https://aws.amazon.com/managed-services/)

AWS is a major cloud service provider with a wide variety of managed services to address its customers’ PCI compliance needs. AWS offers virtual servers (such as EC2 instances) as a core component of its PCI DSS compliant infrastructure, enabling scalable, secure application hosting and compliance management in the cloud. AWS promotes cost savings through automation to continuously improve customer outcomes. Over 150 services provide customers with an accelerated path towards meeting compliance certifications and attestations.

Features of AWS PCI-compliant hosting include:

- Data centers in multiple geographically diverse regions to reduce latency;
- complete security monitoring and automated remediation;
- 24×7 global support with Tier 1 response;
- Point-to-point encryption to protect card data.

![](https://www.atlantic.net/wp-content/uploads/2025/12/rackspace_logo.png)

### [Rackspace](https://www.rackspace.com/compliance/pci)

Rackspace offers PCI compliance through a full suite of managed services to simplify customers’ compliance efforts. The company’s team of PCI experts helps clients protect financial data by ensuring the proper configuration of infrastructure elements and security tools. Rackspace is an active member of the PCI Security Standards Council and is annually audited by a QSA.

Rackspace benefits include:

- PCI-certified data centers in the U.S., UK, Hong Kong, and Australia;
- Proactive monitoring and threat management;
- 24x7x365 support from certified cloud specialists;
- Expert guidance through the PCI audit process.

![](https://www.atlantic.net/wp-content/uploads/2025/04/godaddy-logo.png)

### [GoDaddy](https://www.godaddy.com/help/staying-pci-compliant-20226)

GoDaddy provides customers with a PCI-compliant hosting environment that enables small businesses to meet all PCI requirements. Companies operating as payment processors can leverage PCI-certified products such as GoDaddy Payments and its Online Store to protect customer data. The hosting provider safeguards the infrastructure and data resources with automated backups and disaster recovery procedures.

GoDaddy’s managed services feature set includes:

- Automatic patching to address emerging vulnerabilities;
- Three dedicated IP addresses;
- Configurable customer root access;
- Expert services to fine-tune server performance.

![](https://www.atlantic.net/wp-content/uploads/2025/04/wix-logo.png)

### [Wix](https://www.wix.com/free/web-hosting/cloud-hosting)

Wix provides managed cloud hosting services that meet PCI compliance requirements for a secure environment. They offer a 99.99% uptime guarantee to keep your online business running efficiently. Clients can opt for a custom solution that grows with this business while maintaining PCI-compliant cloud servers.

The features of managed services with Wix include:

- Fully encrypted data in transit and at rest;
- A 200+ node global content delivery network (CDN);
- 24/7 security monitoring and anti-DoS protection;
- PCI cloud quick start with expert help.

## Conclusion

PCI compliance is mandatory for companies worldwide that process credit card payments. Businesses can benefit from engaging managed services that provide a PCI-compliant hosting environment. We have outlined PCI compliance requirements and what to look for in a hosting provider. Decision-makers can use this information and our list of the best hosting providers when choosing a partner that meets PCI-DSS standards.

 


---

# Top Unmanaged Dedicated Server Hosting Providers 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/top-unmanaged-dedicated-server-hosting-providers/ | Published: 2026-03-01 | Updated: 2026-02-27 | Author: Dr. Assad Abbas

Unmanaged dedicated server hosting gives the customer full control over a physical machine. In this model, the provider only provides the hardware, network, and power. The customer manages the operating system, software, updates, and security. Since this structure exists, it is useful for organizations interested in having direct control over their environment. It is also suitable for workloads that need stable performance and predictable resources.

Many organizations choose unmanaged hosting when they want the freedom that shared or managed hosting cannot offer. more Some industries also work with sensitive information. For example, healthcare organizations manage electronic Protected Health Information (ePHI (electronic Protected Health Information)), which requires careful handling. In such cases, they may use a [HIPAA HIPAA Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) (BAA) when hosting data on external servers.

This agreement outlines the provider’s responsibilities. While unmanaged dedicated hosting is mainly chosen for its control and flexibility, many organizations prefer it when they want to configure the server to their own specifications and follow their internal security standards without relying on managed services.

## What Unmanaged Dedicated Server Hosting Involves

Unmanaged dedicated server hosting requires the customer to take full responsibility for the software environment. The provider delivers the physical server and maintains the underlying infrastructure. The customer handles everything above the hardware layer. This includes installing the operating system, configuring services, and managing updates. Teams that prefer to build and maintain their own setup without external intervention often find unmanaged hosting suitable.

Organizations often choose this model when they need a server that behaves consistently. Custom applications, development frameworks, and internal tools may depend on specific versions or configurations. Unmanaged servers support workloads that run for long periods and need stable performance. This makes the model useful for technical teams that want predictable behavior and full control over the environment.

Some users may assume that unmanaged hosting includes help with software or configuration tasks. This is not the case. The provider does not manage the operating system or applications. The customer must handle troubleshooting, security settings, and performance tuning. Unmanaged hosting is best for organizations with enough technical experience to manage the server independently.

## Key Benefits of Unmanaged Dedicated Hosting

Unmanaged dedicated hosting offers several practical advantages for teams that prefer direct control. Gaining an understanding of these benefits helps organizations decide whether this model fits their technical needs.

- **Administrative Sovereignty:** Users have full administrative control over the server environment. They can install their preferred operating system and software. They can configure the system according to their internal standards without depending on preset provider settings.
- **Dedicated Resources:** Performance is consistent and predictable because the server resources are not shared with others. This gives applications a stable environment. Technical teams can plan their workloads with more confidence and fewer interruptions.
- **Cost Efficiency:** In unmanaged environments, organizations with in-house expertise often reduce long-term costs. The provider does not manage the software layer, so there are no additional management costs. Teams with technical skills can manage the server independently and control their expenses more effectively.
- **Tailored Environments:** Specialized workloads benefit from the flexibility of unmanaged hosting. Organizations can tune performance settings and use specific framework versions that match their internal requirements. They can adjust the environment whenever needs change, which helps keep their tools and processes working consistently.
- **Reliability for Long-Running Tasks:** In unmanaged setups, long-running processes operate consistently and predictably. Many analytics tasks, internal services, and background jobs need continuous operation. Since the server is dedicated, these workloads function reliably over extended periods.
- **Security Customization:** Security configuration becomes fully customizable in unmanaged hosting. Organizations can define their own firewall rules, access controls, and monitoring tools in line with their internal standards. This approach helps them follow their security policies consistently and maintain a clear structure for system protection.
- **Control Over Updates:** In unmanaged hosting, update and change management follow the customer’s schedule. The organization decides when to apply updates or modify the system. This helps avoid unexpected changes that sometimes occur in managed environments and supports a more predictable workflow.

## Operating System, Configuration, and Security for Unmanaged Servers

Organizations can choose from several operating systems when setting up an unmanaged server. Linux distributions such as Ubuntu, AlmaLinux, and Rocky Linux are common because they support many server tools and have strong community support. Windows Server is also used for applications that rely on the Microsoft ecosystem. Some organizations use customized OS builds for specific workloads, for example, when they need tuned kernels, special drivers, or lightweight components that match their internal requirements.

Security is the customer’s responsibility in unmanaged hosting. Organizations must configure firewalls, set access rules, and create IP allowlists themselves. They also need to secure data in transit with TLS 1.2 or TLS 1.3, since these protocols help protect sensitive information. Continuous monitoring and regular patching are required because systems can face security issues if updates are delayed.

Backup and recovery require careful planning. Hardware faults, software errors, or accidental changes can lead to data loss. Organizations need to create backup schedules, check that backups work, and test recovery procedures. These practices reduce downtime during unexpected events and help maintain a reliable environment over time.

## Data Center and Network Considerations in Unmanaged Dedicated Hosting

In unmanaged hosting, the quality of the provider’s data center directly impacts overall performance. For example, physical security protects the hardware through controlled entry, surveillance, and restricted access. These measures help keep the server environment safe from unauthorized activity. Power redundancy is important; backup generators and UPS systems support uptime during electrical issues, while cooling systems maintain stable temperatures and protect the hardware from heat-related issues.

Network performance also affects server reliability. High throughput and low latency improve how applications respond to users. In unmanaged setups, routing quality influences how quickly data moves across the internet. The physical location of the data center affects speed for global users. Many organizations select facilities closer to their customers to reduce latency and improve responsiveness.

## How to Choose the Right Unmanaged Dedicated Server Provider

Selecting an unmanaged dedicated server provider requires a clear understanding of what the organization needs and how much technical responsibility it can handle.

- **Internal Expertise:** **Internal** technical skills are critical for daily operations. Organizations must be comfortable managing operating systems, security settings, updates, and troubleshooting. Reviewing in-house expertise is essential before evaluating providers.
- **Workload Requirements:** Performance requirements should be defined clearly. CPU, RAM, storage, and bandwidth must match the workload. Understanding these needs helps select a provider that can deliver the right hardware profile.
- **Compliance Needs:** Compliance expectations can influence the choice. Industries that handle regulated data, such as healthcare, may need HIPAA-compliant hosting and a BAA. Confirming these details early is necessary.
- **Budgeting:** Budget planning is also important to understand long-term costs. Pricing models vary across providers. Reviewing these details helps organizations plan expenses effectively.
- **Service Level Agreements (SLA):** In unmanaged environments, the SLA is an important indicator of reliability. Some providers offer financial credits if they do not meet their uptime commitment. These guarantees indicate how seriously a provider treats availability and accountability.

## Top Unmanaged Dedicated Server Hosting Providers in 2026

Below are the top unmanaged dedicated server hosting providers for 2026.

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

### Atlantic.Net

We at [Atlantic.Net](https://www.atlantic.net) offer unmanaged dedicated server hosting for organizations that need high performance and flexible configuration options. We provide a range of hardware options that support demanding workloads and long‑running applications. Our data centers follow strict security standards, and we support industries that handle sensitive information. For example, we offer HIPAA‑compliant hosting with a BAA when required. In unmanaged environments, our servers are suitable for organizations that prefer full control over their software stack. Moreover, we maintain a stable network and reliable infrastructure, which helps customers build long‑term hosting environments with predictable performance.

#### *Key Features*

- Atlantic.Net provides high‑performance bare-metal servers with customizable CPU, RAM, and storage options. These options help organizations match the server to their workload, whether they need high compute power, large storage capacity, or a balanced configuration for general applications. In unmanaged setups, this flexibility supports a wide range of deployment scenarios.
- Our unmanaged hosting gives customers full control over the operating system and software stack. Organizations can install their preferred Linux distribution or Windows Server version and configure the environment according to their internal standards. This level of control is useful for workloads that depend on specific frameworks, libraries, or custom configurations.
- Atlantic.Net supports HIPAA‑focused hosting with strong security controls and TLS 1.2 or TLS 1.3 for data in transit. These measures help organizations protect sensitive information and maintain compliance with industry requirements. In unmanaged environments, this combination of infrastructure security and customer‑controlled configuration provides a balanced approach to data protection.
- We maintain multiple data center locations with strong network connectivity. These facilities support low‑latency access and reliable routing for global users. In addition, our redundant power systems and environmental controls help maintain consistent uptime, which is important for organizations that depend on stable and predictable hosting environments.

### Amazon Web Services (AWS)

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

[AWS](https://aws.amazon.com/) offers unmanaged dedicated hosting through its bare metal and dedicated instance options, suitable for organizations that want cloud-grade infrastructure while still managing their own software stack. In unmanaged environments, AWS is often chosen by organizations that need integration with other AWS services, such as databases, storage, and networking tools. This combination supports complex architectures while keeping full control over the operating system and applications.

#### *Key Features*

- AWS provides dedicated and bare metal instances with a wide range of CPU, RAM, and storage options. Organizations can select instance families that match compute-heavy, memory-intensive, or storage-focused workloads. This flexibility helps align infrastructure with specific performance requirements.
- In unmanaged setups, customers manage their own operating system and software stack on AWS. They can choose from various Linux distributions or Windows Server images and configure them according to internal standards. This is useful for organizations that rely on specific frameworks or deployment pipelines.
- AWS includes strong security features at the infrastructure level, such as VPC isolation, security groups, and encryption options. These tools help organizations build secure environments while still retaining control over application-level security and configuration.
- Global data center coverage and a high-capacity network support low-latency access for users in different regions. Organizations can deploy dedicated resources close to their customers, which helps improve responsiveness and supports geographically distributed applications.

### Rackspace

![](https://www.atlantic.net/wp-content/uploads/2025/12/rackspace_logo.png)

[Rackspace](http://www.rackspace.com) provides unmanaged dedicated servers for organizations seeking enterprise-grade hardware, with the option to add managed services as needed. In unmanaged environments, customers can use Rackspace purely for infrastructure while keeping full control over the operating system, applications, and security configuration. This makes it suitable for organizations that want flexibility today and the option to layer on additional services later.

#### *Key Features*

- Rackspace offers a variety of dedicated server configurations with customizable CPU, memory, and storage. Organizations can select hardware that fits their workload profile, from general business applications to more demanding compute or database tasks.
- In unmanaged hosting, customers install and manage their own operating system and software stack. This enables organizations to maintain their preferred configurations, deployment tools, and internal standards without changes on the provider side.
- Rackspace data centers follow strict security and compliance practices that support regulated industries. While the provider handles physical and infrastructure security, organizations remain responsible for application-level controls in unmanaged setups.
- A strong global network and multiple data center locations help improve performance and availability. Organizations can choose regions that align with their user base, which helps reduce latency and support consistent application behavior.

### GoDaddy

![](https://www.atlantic.net/wp-content/uploads/2025/04/godaddy-logo.png)

[GoDaddy](http://www.godaddy.com) offers unmanaged dedicated servers for organizations seeking straightforward hosting with direct control over their environment. These plans are often used by organizations that are moving beyond shared or VPS hosting and need dedicated resources without managed services. In unmanaged setups, GoDaddy focuses on providing stable hardware and basic infrastructure support while customers handle the software layer.

#### *Key Features*

- GoDaddy provides dedicated servers with configurable CPU, RAM, and storage options. This helps organizations to choose a server size that matches their current workload and adjust as needs change.
- Unmanaged plans give customers full control over the operating system and installed applications. Organizations can deploy their preferred Linux distribution or Windows Server version and configure services according to internal requirements.
- GoDaddy includes basic infrastructure security features, such as network firewalls and DDoS protection. These measures help maintain a stable environment while leaving application-level security and configuration to the customer.
- Data centers with strong connectivity support reliable access for regional and international users. This helps organizations deliver consistent performance for websites, applications, and internal tools hosted on dedicated servers.

### HostGator

![](https://www.atlantic.net/wp-content/uploads/2025/08/Hostgator-logo.png)

[HostGator](http://www.hostgator.com) offers unmanaged dedicated servers for organizations that want full administrative control without relying on provider-side software management. Their plans are often selected by organizations that have moved beyond shared or VPS hosting and now require isolated resources with predictable performance. In unmanaged environments, HostGator focuses on delivering stable hardware, consistent network connectivity, and essential infrastructure protections while leaving all operating system, security, and application responsibilities to the customer. This approach is useful for organizations that prefer to maintain their own deployment processes, update cycles, and internal standards without external interference.

#### *Key Features*

- HostGator provides dedicated servers with multiple CPU, RAM, and storage configurations. These options help organizations match the hardware profile to their workload, whether they are running web applications, databases, or internal tools that require steady performance.
- In unmanaged hosting, HostGator offers customers full administrative access to the server. Organizations can install their preferred operating system, configure services according to internal requirements, and maintain their own update and patching routines.
- Infrastructure-level protections, such as firewalls and network monitoring, support a stable environment. Organizations can then build on this foundation with their own security tools, access controls, and monitoring systems.
- HostGator’s data centers and network design support reliable uptime and consistent connectivity. This is important for organizations that depend on steady response times for customer-facing applications and internal systems that run continuously.

### Kamatera

![](https://www.atlantic.net/wp-content/uploads/2025/12/kamatera-logo-1.png)

[Kamatera](http://www.kamatera.com) provides unmanaged dedicated and cloud-based servers designed for organizations that need flexibility, rapid provisioning, and full control over their software environment. Kamatera customers can configure their own operating system, security policies, and application stack while relying on the provider’s high-performance infrastructure. This combination supports both long-running applications and dynamic workloads that may require frequent adjustments. Organizations often choose Kamatera when they want dedicated performance but also expect their hosting needs to evolve, particularly in environments where scaling and customization are important.

#### *Key Features*

- Kamatera offers granular control over CPU, RAM, and storage across a wide range of server configurations. This helps organizations tailor the hardware profile closely to their workload and optimize both performance and cost.
- In unmanaged environments, customers manage their own operating system and software stack. Kamatera supports multiple Linux distributions and Windows Server options, enabling organizations to configure the environment to meet internal standards.
- Global data centers and advanced networking features support low-latency access. Organizations can deploy servers in regions that align with their user base, improving responsiveness and supporting distributed applications.
- Flexible scaling options make it easier to adjust resources over time. Organizations can add more servers or modify configurations as workloads grow, which is particularly useful for projects that start small and expand gradually.

### ScalaHosting

![](https://www.atlantic.net/wp-content/uploads/2025/12/scala-hosting.jpg)

[ScalaHosting](http://www.scalahosting.com) provides unmanaged dedicated and VPS-style solutions for organizations seeking a balance among control, performance, and cost efficiency. Their unmanaged dedicated servers are often selected by organizations that have outgrown shared hosting and now require isolated resources with full administrative access. In unmanaged environments, ScalaHosting emphasizes giving customers the freedom to manage their own software stack while maintaining a reliable infrastructure underneath. This approach is useful for organizations seeking predictable performance, consistent uptime, and the ability to configure the server to meet internal policies and operational requirements.

#### *Key Features*

- ScalaHosting offers dedicated servers with configurable CPU, RAM, and storage. These options help organizations select hardware that fits their workload, whether they are hosting web applications, databases, or internal services.
- Unmanaged plans provide full administrative access to the server. Organizations can install their preferred operating system, configure services, and manage updates in line with their internal processes and security standards.
- Infrastructure-level protections and monitoring support stable operation. Organizations can then implement their own security controls, such as firewalls, intrusion detection tools, and access policies.
- ScalaHosting’s data centers feature strong connectivity and redundant systems. These elements help maintain consistent uptime and predictable behavior, which is important for organizations that rely on continuous operation and long-term stability.

## Which Provider Is Best for Different Needs?

Each unmanaged dedicated server provider supports a different type of organization, and these differences become more meaningful once the responsibilities of unmanaged hosting are understood. Because the customer controls the operating system, security configuration, and software environment, the provider’s strengths must align with the organization’s internal capabilities and long‑term operational goals. This creates a practical distinction between providers that emphasize compliance, those that support rapid expansion, and those that offer a more accessible entry point for smaller teams.

Atlantic.Net is suitable for organizations that require strong security controls and may need HIPAA‑focused hosting with a BAA. This makes it a practical choice for healthcare, finance, and other regulated sectors that depend on predictable performance and clear documentation. AWS, by contrast, is appropriate for organizations that anticipate significant growth or require close integration with additional services such as storage, networking, and automation tools. Its environment supports distributed systems and complex deployments that benefit from broad configuration options.

Rackspace fits organizations that demand enterprise‑grade hardware and the flexibility to add managed services later, without committing to a fully managed model from the outset. GoDaddy and HostGator are often selected by small and medium businesses moving from shared or VPS hosting into dedicated environments, where they can maintain full control over the software layer while working within familiar operational patterns. Likewise, Kamatera is suitable for organizations whose requirements evolve and need flexible resource allocation and rapid provisioning. ScalaHosting supports organizations that want a balance between cost control and customization, particularly when they are ready to manage their own configurations but still value straightforward pricing and consistent behavior.

## Common Mistakes When Choosing Unmanaged Dedicated Hosting

Organizations often approach unmanaged hosting with clear goals, yet several recurring oversights can affect long-term stability. Presenting these considerations in a structured way helps clarify where difficulties typically arise and how to prevent them.

- Selecting unmanaged hosting without sufficient internal expertise. Some organizations underestimate the level of technical responsibility involved. Without administrators who can manage installation, configuration, security, and troubleshooting, the environment may become unstable over time.
- Overlooking the need for a structured backup and recovery plan can lead to data loss due to hardware faults, software errors, or accidental changes. Without tested backups and clear recovery procedures, restoring service becomes difficult and time-consuming.
- Assuming provider-level protections are enough, unmanaged hosting requires customers to configure firewalls, access controls, and monitoring tools. Relying solely on infrastructure-level safeguards leaves important gaps at the operating system and application layers.
- Not reviewing SLAs carefully, misunderstanding uptime commitments, or support boundaries can create unrealistic expectations. Clear knowledge of what the provider covers and what remains the customer’s responsibility prevents operational surprises.
- Choosing hardware only for current needs. Underestimating future growth can lead to resource constraints. Planning for expansion ensures that the environment remains stable as workloads evolve.

## Final Decision Framework

A structured evaluation process helps organizations consistently and practically select an unmanaged hosting provider. The following considerations support informed decision-making and long-term planning.

- #### *Confirm internal technical capability.*

Determine whether the organization has administrators who can manage installation, configuration, security, and ongoing maintenance without relying on provider-side assistance.

- #### *Define uptime and reliability expectations.*

Review the provider’s commitments and ensure that SLAs align with operational requirements, especially for workloads that must remain available.

- #### *Clarify compliance and documentation needs.*

Identify whether formal agreements, such as a BAA, are required and verify that the provider can supply the necessary documentation.

- #### *Assess geographic and performance requirements.*

Decide whether deployment in multiple regions is necessary and evaluate how data center location affects latency and user experience.

- #### *Plan for growth over the next one to two years*

Estimate how workloads may expand and confirm that the provider offers a clear path to scale resources without major disruption.

- #### *Establish a backup, recovery, and incident-response approach*

Since these responsibilities fall on the customer, defining them early supports resilience and reduces downtime during unexpected events.

## Concluding Remarks

Unmanaged dedicated hosting gives organizations full authority over their server environment, and this level of control introduces responsibilities that must be handled with care. Because the customer manages installation, configuration, security, and ongoing maintenance, the long-term quality of the environment depends on disciplined internal practices rather than provider-side intervention. This makes technical readiness, structured planning, and consistent oversight essential for stable operation.

When a provider is selected with clear awareness of these responsibilities, unmanaged hosting supports predictable performance and accommodates specialized or long-running workloads. The model works best when internal expertise is paired with thoughtful operational routines, allowing organizations to build an environment that aligns with their goals throughout 2026 and beyond.


---

# Bare Metal Backup & Restore Best Practices for IT Recovery

> URL: https://www.atlantic.net/dedicated-server-hosting/bare-metal-backup-restore-best-practices/ | Published: 2026-03-02 | Author: Dr. Assad Abbas

Modern IT environments face disruptions ranging from hardware failures and configuration mistakes to ransomware incidents. When systems go down unexpectedly, the difference between a short outage and a prolonged incident often comes down to preparation.

Bare-metal backup and restore is a proven approach for rebuilding an entire system from scratch. A [bare-metal](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) backup captures a full system image—including the operating system, applications, configuration, partitions, and boot information—so you can restore a working environment onto new or existing hardware. By contrast, file-level backups typically recover selected files and folders but do not rebuild a bootable system on their own.

Successful bare-metal recovery depends on more than choosing backup software. It requires a strategy, testing, and documentation so teams aren’t discovering gaps during an emergency.

## Foundational Concepts of Bare Metal Backup and Restore

A bare-metal restore rebuilds a machine when there is no usable operating system on the target disk (for example, after disk failure, corruption, or replacement). In most workflows, you boot the system using recovery media (a bootable ISO/USB) and then restore the system image onto the target storage.

### What Bare Metal Backup Covers

A bare-metal (image-based) backup typically includes:

- Operating system and system state
- Installed applications (where captured in the image)
- Configuration files and system settings
- Disk partitions/volumes and partition tables
- Boot components (for example, boot records and UEFI/EFI system partitions)
- User and application data on the imaged volumes

This is what enables a full rebuild: settings and dependencies return together, reducing post-restore configuration drift.

### What Bare Metal Restore Helps Achieve

Bare metal restore (BMR) allows engineers to rebuild systems on empty or replacement hardware. This supports restoration to different hardware when the original machine is unavailable. This flexibility is useful during hardware upgrades or emergency replacements. It also supports migration tasks such as physical-to-virtual (P2V) or virtual-to-cloud transitions. BMR is effective during ransomware recovery or severe system corruption, allowing organizations to return to normal operations faster and with fewer manual adjustments.

### Why Best Practices Improve Recovery Success

Many organizations discover backup issues only during a restore attempt. This situation creates delays and increases downtime. Best practices are vital because they help maintain reliable backups and predictable recovery times. Modern systems are complex; this increases the risk of restore failures. A structured approach reduces these risks and improves recovery outcomes. It supports smoother restoration during high-pressure situations and strengthens overall disaster recovery readiness.

## Best Practices for Bare Metal Backup

A reliable bare metal recovery strategy depends on disciplined backup practices. Therefore, organizations must follow structured methods that protect data, maintain integrity, and support predictable recovery outcomes. The following best practices explain how to strengthen bare metal backup processes.

### 1. Use Full Image Based Backups

Image-based backups are necessary for complete system recovery. File-level backups cannot rebuild the operating system or restore boot records. The backup must include system state, boot information, and partition tables. Block-level imaging improves consistency and reduces backup time.

*To build on this foundation, organizations must also ensure proper redundancy and storage planning.*

### 2. Apply the 3-2-1 Backup Strategy

The *3-2-1* strategy is widely used in disaster recovery planning. Specifically, it means keeping three copies of data on two different media types, with one copy stored offsite. This method protects against local failures and regional disasters. In addition, organizations can include immutable storage to protect against ransomware attacks. Consequently, this layered protection reduces the likelihood of total data loss.

*Beyond redundancy, operational discipline is equally important.*

### 3. Automate Backup Scheduling and Retention

Automated scheduling reduces human error. Therefore, backups occur consistently without manual intervention. Daily incremental backups combined with weekly full images create a balanced approach. Moreover, retention policies should define how long backups are kept for operational and archival needs. Backup alerts are also important because they help identify failed or incomplete jobs before they cause problems. As a result, organizations can correct issues early and maintain backup reliability.

*Security considerations must also be integrated into backup planning.*

### 4. Encrypt All Backup Images

Backup images contain sensitive information. Therefore, encryption is necessary. Encryption should be applied both at rest and in transit. In addition, strong key management practices are important to prevent unauthorized access. Many industries require encryption to meet compliance standards such as HIPAA, PCI DSS, and SOC 2. Consequently, encryption not only protects data but also supports regulatory requirements.

*Resilience further improves when storage locations are diversified.*

### 5. Store Backups in Multiple Locations

Storing backups in more than one location improves resilience. On one hand, local storage supports fast restores. On the other hand, cloud or off-site storage protects against disasters that affect the primary site. Moreover, geographic redundancy reduces the risk of losing all copies during a regional incident. Therefore, combining local and remote storage strengthens overall disaster preparedness.

*In addition to technical safeguards, preparation through documentation is essential.*

### 6. Maintain Updated System Documentation

Accurate documentation helps during recovery. For example, it should include disk layout, RAID configuration, network settings, driver versions, and firmware levels. This information reduces confusion during a restore. Furthermore, it shortens recovery time because technical teams know exactly what the system requires. Consequently, documentation improves efficiency and minimizes avoidable delays.

*Finally, backup reliability must be verified continuously.*

### 7. Verify Backup Integrity Regularly

Backup images can become corrupted over time. Therefore, regular verification is necessary. Hash checks and checksum validation help confirm data integrity. In addition, automated tools can detect corruption early. Periodic test mounts also help confirm that the image is usable. Consequently, organizations reduce the risk of discovering backup failures during an actual disaster.

## Best Practices for Bare Metal Restore

BMR is a sensitive stage in the system recovery process. Every step must be executed carefully. Small mistakes during this process can cause significant delays or restore failures. Restores often occur during emergencies, which increases pressure on technical teams. Consequently, following best practices helps ensure consistent, reliable recovery and reduces operational risk.

### 1. Keep Recovery Media Updated

Recovery media forms the foundation of a successful restore. Therefore, it is important to maintain an updated bootable ISO or USB media that matches the current system state. Update media after major operating system patches, driver updates, or firmware changes. In addition, verify that the recovery environment is compatible with BIOS or UEFI settings. If this step is ignored, outdated media may fail to boot or load drivers correctly.

### 2. Validate Hardware Compatibility Before a Disaster

Keeping recovery media up to date is only effective if the target hardware supports it. Therefore, organizations must confirm hardware compatibility in advance to avoid restore failures. This includes reviewing storage controllers, RAID configurations, and network drivers. Similarly, partition schemes such as GUID Partition Table (GPT) and Master Boot Record (MBR) must be verified. By performing these checks, organizations prevent errors during restoration and reduce unplanned downtime.

### 3. Choose Solutions That Support Dissimilar Hardware

Modern IT environments often require restores to different hardware platforms. Therefore, organizations should choose recovery tools that provide driver injection and hardware abstraction features. These capabilities reduce conflicts after restoration and make the process smoother. In addition, they are valuable for migration scenarios, such as physical-to-virtual or virtual-to-cloud environments.

### 4. Conduct Regular Bare Metal Restore Testing

Testing restore procedures is essential for verifying backup reliability. Therefore, organizations should perform scheduled restore drills, such as quarterly tests on spare hardware or isolated virtual machines. During testing, organizations must validate the boot process, critical services, database functionality, and network connectivity. Without regular testing, restore issues may only become apparent during actual incidents.

### 5. Automate Restore Workflows Where Possible

Manual restore steps increase the risk of errors, especially under high pressure. Therefore, organizations should automate restore workflows using scripts or predefined templates. Automation ensures consistent and repeatable procedures. In addition, it reduces dependency on individual personnel and minimizes the chance of mistakes.

### 6. Perform Structured Post-Restore Validation

Restoration is not complete until the system is fully validated. Therefore, after a restoration, organizations should verify that all applications function correctly, security policies are enforced, and system patches are applied. In addition, monitoring and logging tools should be reactivated to ensure ongoing oversight. Skipping this step may leave hidden issues that affect performance or security.

## Cloud Storage Best Practices for Bare Metal Backup and Restore

Cloud storage is a pillar of modern BMR strategies. Full system images include the operating system, boot records, partitions, and configuration settings. Since these images are large, organizations require scalable storage.

### 1. Use Object Storage for Full System Images

Bare metal recovery requires storing complete system images rather than selected files. Therefore, organizations should use object storage platforms such as Amazon S3, Azure Blob Storage, or Google Cloud Storage. These services provide high durability and availability for large image files. In addition, object storage integrates well with enterprise backup software that captures block level system images.

### 2. Enable Versioning to Protect System Image Generations

Bare metal environments depend on clean and consistent system images. However, recent backups may become corrupted due to misconfiguration or ransomware. Therefore, enabling versioning ensures that multiple generations of full system images remain available. In addition, older image versions can serve as recovery points if the most recent image fails validation.

### 3. Activate Immutability or Object Lock for Image Protection

Ransomware often targets backup repositories. Organizations should activate immutability or object lock for stored system images. These controls prevent deletion or modification for a defined retention period.

### 4. Apply Lifecycle Policies While Preserving Recovery Objectives

Lifecycle policies help move older images to lower-cost tiers without prematurely deleting critical restore points. Lifecycle management must balance cost efficiency with the performance requirements of bare-metal recovery.

### 5. Use Strong Identity and Access Controls to Protect Image Repositories

Implement Identity and Access Management (IAM) policies to restrict access to authorized administrators. Multi-factor authentication (MFA) and role-based permissions reduce the risk of unauthorized access.

### 6. Encrypt Full System Images in Transit and at Rest

Encryption is necessary because bare metal images contain complete system data. During transfer to the cloud, encryption protects images from interception. Similarly, encryption at rest protects stored images from unauthorized access. Organizations may use server-side encryption provided by the cloud platform or client-side encryption through backup tools. In addition, proper key management ensures long-term security.

### 7. Test Full Bare Metal Recovery from Cloud Storage

Cloud backup is only valuable if full restoration works during an incident. Therefore, organizations should regularly test bare metal restoration directly from cloud-stored system images. This testing must include retrieving the image, decrypting it, and rebuilding the complete system on new hardware or virtual infrastructure. In addition, network bandwidth and transfer times should be evaluated because large images can affect recovery time objectives.

## How Atlantic.Net Supports Bare Metal Backup and Restore Best Practices

Modern recovery strategies depend on reliable infrastructure, secure storage, and consistent performance. Therefore, it is useful to examine how a hosting provider implements these principles in practice. [Atlantic.Net](https://www.atlantic.net) offers an infrastructure environment that aligns with the best practices discussed in this article and supports reliable bare-metal backup and restore workflows.

### 1. Updated and Secure Recovery Environments

Atlantic.Net maintains current operating system templates and secure boot environments across its data centers. These resources help organizations create recovery media that match their production systems. In addition, BIOS and UEFI compatibility is supported across multiple hardware profiles, which contributes to predictable restoration.

### 2. Hardware Compatibility and Stable Infrastructure

The platform uses standardized hardware across its facilities, which reduces compatibility issues during restoration. Storage controllers, network interfaces, and virtualization layers follow consistent configurations. Therefore, organizations experience fewer hardware-related conflicts when rebuilding systems or migrating workloads.

### 3. Support for Dissimilar Hardware Restoration

Atlantic.Net provides virtualization layers that help organizations restore system images to different hardware configurations. These layers reduce driver conflicts and support restoration during hardware replacement or infrastructure upgrades. Consequently, organizations can maintain continuity even when the original hardware is unavailable.

### 4. Regular Testing Through Flexible Environments

The platform enables organizations to perform restore tests using on-demand virtual machines or dedicated hosts. These environments support validation of boot processes, services, databases, and network connectivity. Regular testing, therefore, becomes easier to schedule and integrate into disaster recovery planning.

### 5. Automation and Consistent Recovery Workflows

Atlantic.Net supports API-driven provisioning and scripted deployment workflows. These capabilities help organizations automate parts of the recovery process, maintain consistency, and reduce manual steps during critical events. Automation also supports faster restoration and minimizes operational errors.

### 6. Post-Restore Stability and Security Controls

After restoration, organizations can use Atlantic.Net’s monitoring, logging, and security controls to verify system stability. These controls help confirm that applications, policies, and patches function correctly.

### 7. Cloud Storage Integration for System Images

Atlantic.Net offers secure cloud storage options that support image-based backups. These options include encrypted storage, geographic redundancy, and strong access controls.

## Common Mistakes to Avoid in Bare Metal Backup and Restore

Bare-metal backup and restore require careful planning and ongoing attention. However, many organizations experience recovery issues due to certain mistakes. Therefore, identifying common mistakes early helps organizations maintain dependable recovery and reduce operational risk.

### Relying Only on Local Backups

Some organizations depend only on local storage for full system images. However, local storage is vulnerable to hardware failures, site outages, and ransomware attacks. If the primary location becomes unavailable, access to backups may be lost completely. Consequently, recovery efforts may stop at the most critical moment. Therefore, maintaining off-site or cloud copies is necessary for true bare metal resilience.

### Failing to Test Restore Procedures

A backup that has never been tested cannot be considered reliable. Missing drivers, corrupted images, or misconfigured boot settings often remain hidden until a real disaster occurs. As a result, organizations discover technical problems during high-pressure situations. This mistake increases downtime and creates uncertainty. Regular restore testing is essential to confirm that full system images can successfully rebuild servers.

### Using Outdated Recovery Media

Recovery media must match the current operating system and firmware environment. However, organizations sometimes forget to update bootable media after patches or hardware changes. Outdated drivers or mismatched boot configurations can prevent restored systems from starting..

### Overlooking Hardware Compatibility Requirements

Bare metal restore often involves replacement or dissimilar hardware. If storage controllers, RAID configurations, or network interfaces differ from the original system, boot errors may occur. This issue is common during emergency hardware purchases without prior compatibility checks

### Skipping Encryption for Backup Data

Full system images contain operating systems, application data, credentials, and configuration files. If these images are not encrypted, sensitive information becomes exposed to unauthorized access. In addition, regulatory compliance requirements may be violated.

### Underestimating Storage Capacity Needs

Bare metal images require significant storage space, particularly when multiple versions are retained. If capacity planning is insufficient, backups may fail or overwrite older restore points. This situation reduces the number of usable recovery options. Moreover, unexpected storage shortages create operational disruption.

### Ignoring Cloud Specific Safeguards

Cloud storage introduces additional responsibilities. Identity and access controls, immutability settings, and lifecycle policies must be configured correctly. However, some organizations treat cloud storage as simple remote disk space. As a result, backups may be exposed to accidental deletion or unauthorized modification.

### Not Documenting the Restore Workflow

Clear documentation supports accurate and fast recovery. Without written procedures, restore steps may be skipped or performed incorrectly. In addition, unclear responsibilities create confusion during emergencies. This lack of structure slows down system rebuilding. Maintaining updated restore documentation improves coordination and reduces recovery time.

### Treating Backup and Restore as a One Time Setup

IT environments change over time. New applications, operating system updates, and hardware refresh cycles affect backup requirements. However, some organizations treat backup and restore as a static configuration. Consequently, gaps appear between current infrastructure and existing recovery plans. These gaps often become visible only during system failure. Backup and restore strategies must be reviewed and adjusted regularly to remain effective.

## The Bottom Line

Bare metal backup and restore becomes far more dependable when every stage of the process receives continuous attention rather than reactive urgency. Recovery success does not depend on a single tool. Instead, it depends on preparation, validation, and disciplined execution. Organizations must treat backup and restore as an ongoing operational responsibility.

When recovery media is kept up to date, hardware planning is performed in advance, and cloud storage is configured carefully, the entire workflow becomes more stable. In addition, regular testing and proper documentation reduce uncertainty during high-pressure situations. Consequently, these practices work together and create a recovery path that is predictable even when systems fail unexpectedly.

However, IT environments do not remain static. Infrastructure evolves, applications change, and hardware is refreshed over time. For this reason, organizations should periodically review their bare metal strategies and strengthen weak areas. Selecting platforms that support secure storage, compatibility validation, and structured restore workflows improve long term recovery reliability.

With this connected, proactive approach, bare-metal recovery is no longer viewed as a stressful last resort. Instead, it becomes a structured and reliable component of overall operational resilience.


---

# Top Accessibility Companies in 2026

> URL: https://www.atlantic.net/managed-services/top-accessibility-companies-in-2026/ | Published: 2026-03-02 | Updated: 2026-06-05 | Author: Robert Agar

Digital accessibility has become a strict legal and operational requirement for all online platforms in 2026. The leading accessibility firms provide the technical audits and automated remediation necessary to meet global WCAG 2.2 standards. This guide identifies the companies providing the most accurate manual testing and long-term compliance monitoring for enterprise websites.

For 2026, the best web accessibility solution depends entirely on your risk tolerance and budget. Level Access is the top choice for enterprise-grade risk management and full remediation, especially following their acquisition of UserWay. UserWay remains the leading choice for small businesses needing a cost-effective widget. TabNav has emerged as a powerful tool for developers, offering free scans that simulate real user interactions. Skynet Technologies remains the industry standard for “shift left” code testing.

## What Is an Accessibility Company?

Accessibility companies help organizations test digital experiences against accessibility guidelines, fix issues, and prevent regressions as content and code evolve. They ensure that digital assets—such as websites, documents, applications, and internal tools—are usable by people with disabilities and aligned with the current WCAG 2.2 success criteria.

It’s important to distinguish between software overlays and full remediation services. Overlay tools typically provide front-end adjustments or automated fixes. At the same time, full-service accessibility firms deliver manual audits, code-level remediation, assistive technology testing, and governance support required for sustainable WCAG 2.2 compliance.

Most providers offer a mix of:

- **Accessibility audits**: Manual testing plus automated scans to find barriers. Manual audits typically include keyboard-only navigation, screen reader testing, focus management checks, and validation of dynamic components that automated tools often miss.
- **Remediation**: Fixing issues in code, design systems, templates, and content workflows.
- **Monitoring**: Ongoing scanning to catch regressions after releases and content updates. Continuous monitoring is especially important for teams shipping frequent updates or managing large content libraries.
- **Training**: Building internal capability across product, design, engineering, QA, and content teams.
- **Documentation support**: Helping teams prepare materials often requested in procurement and internal governance, including VPAT-based Accessibility Conformance Reports (ACRs).

## Software Overlay vs. Full Remediation Service

**Software Overlay**: A front-end script or widget that automates changes, such as adjusting contrast or resizing text. It also tries some basic AI fixes, but it does not change the website’s source code.

**Full Remediation Service**: A complete accessibility program. It includes manual WCAG 2.2 audits, assistive technology testing, fixing website code issues, providing documentation, and ongoing compliance checks.

**Key Difference**: Overlays only make surface-level changes. Full remediation services fix website code issues and confirm accessibility through human testing.

## What accessibility standards matter most in 2026?

Most teams start with WCAG because it is widely used as the technical reference for web accessibility work. In 2026, WCAG 2.2 Level AA is the practical benchmark for most commercial, enterprise, and public-sector digital properties, particularly for interactive web applications and SaaS platforms.

You may also need to map work to additional requirements:

- **United States (federal and procurement)**: Section 508 incorporates WCAG 2.0 Level AA success criteria, and many agencies expect alignment with WCAG 2.1 or 2.2 where applicable in practice.
- **European Union**: Organizations selling into the EU must adhere to the European Accessibility Act (EAA), which became enforceable in June 2025.
- **Procurement documentation**: Many buyers request documentation such as VPAT/ACR-style reporting for software and digital services, along with evidence of ongoing manual testing and remediation processes—not just automated scan results.

## Who needs to meet accessibility compliance standards?

Accessibility affects organizations that publish digital experiences for customers, employees, students, or the public. In 2026, WCAG 2.2 alignment is increasingly expected not only for public websites, but also for web applications, mobile experiences, and internal enterprise systems used by distributed teams.

Common examples include:

- Government and public sector organizations, where regulatory enforcement and procurement requirements explicitly reference WCAG-based standards.
- Education providers and edtech platforms, especially those delivering online coursework, portals, and testing environments.
- Healthcare, insurance, finance, and retail organizations, where inaccessible forms, checkout flows, or patient portals create both legal exposure and user barriers.
- Employers with internal tools used by a wide workforce, including HR systems, intranets, and training platforms that must support assistive technology, users.
- SaaS products selling into enterprise or public-sector procurement channels, where buyers frequently require VPAT/ACR documentation and evidence of manual accessibility testing—not just automated scan reports.

## Top Web Accessibility Companies for WCAG 2.2 Compliance in 2026

These providers combine automated scanning, software overlays, and manual remediation services to support sustainable WCAG 2.2 compliance.

![](https://www.atlantic.net/wp-content/uploads/2025/08/skynettechnologies.png)

### #1 – [Skynet Technologies](https://www.skynettechnologies.com/)

**Best for multilingual sites that want a widget layer plus optional manual remediation**

Skynet Technologies offers accessibility services alongside its [accessibility widget](https://www.skynettechnologies.com/all-in-one-accessibility) – All in One Accessibility. The company positions the widget as an entry point, while also providing manual audits and remediation services for organizations that need deeper WCAG 2.2 alignment. This blended model helps distinguish between surface-level overlay adjustments and full code-level accessibility fixes. Skynet Technologies’ [full website accessibility services](https://www.skynettechnologies.com/full-website-accessibility-remediation) are ideal for State and Federal governments, educational and university websites, banking institutions, non-profits, businesses of all sizes, and the public sector.

- **Key Specs**: “All in One Accessibility” AI Widget; Manual Audit & Remediation Services, including code-level fixes.
- **Compliance**: WCAG 2.1 & 2.2, ADA, Section 508, EAA, EN 301 549.
- **Support**: Standard email/chat support; dedicated project managers for remediation clients.
- **Verdict**: A practical option for organizations that want immediate front-end accessibility controls but also require a structured path toward manual auditing and long-term WCAG 2.2 compliance.

#### What Stands Out:

- **Modular Approach**: You can buy the widget for $25/month and add on manual remediation or PDF fixes only when you need them.
- **Global Reach**: Their widget supports over 190 languages, making it suitable for international brands managing multilingual content.
- **Manual + Automated Coverage**: Combines AI-based scanning with human review options to address interactive components that automated tools alone may miss.

#### Who Should Choose Skynet Technologies?

- Teams supporting multilingual sites that want a widget for immediate improvements, but understand that sustained compliance requires manual auditing and remediation beyond overlay functionality.

![](https://www.atlantic.net/wp-content/uploads/2025/08/Deque_Systems_Logo.png)

### #2 – Deque Systems

**Best for developer-first accessibility testing and manual validation workflows**

Deque Systems is known for accessibility testing tools and services that help teams find issues earlier in the build cycle. Many teams use Deque’s axe tooling during development, then pair it with expert services and structured training to improve accessibility maturity over time. Unlike overlay-based solutions, Deque focuses on identifying code-level defects through automated testing integrated into development pipelines, supplemented by manual audits for full WCAG 2.2 conformance.

- **Key Specs:** axe-core engine; DevTools for Chrome/Edge; enterprise auditing and reporting platform.
- **Compliance**: WCAG 2.2 and Section 508 alignment through automated testing plus manual verification services.
- **Support**: Developer-centric training, certification programs, and enterprise consulting.
- **Verdict**: A strong choice for teams building custom software or web applications that require accessibility embedded directly into design, development, and QA workflows.

#### What Stands Out:

- **Shift Left**: Identifies accessibility issues during the coding phase, helping reduce remediation effort later in the release cycle.
- **Integration**: Connects with Jira, GitHub, and CI/CD pipelines to automate accessibility checks during builds.
- **Manual + Automated Coverage**: Combines automated rule-based testing with human audits to validate dynamic components, user flows, and assistive technology behavior.

#### Who Should Choose Deque Systems?

- Teams that want accessibility enforced inside their development lifecycle, with both automated scanning and structured manual auditing to meet WCAG 2.2 requirements.

![](https://www.atlantic.net/wp-content/uploads/2025/08/tabnav.png)

### #3 – Tabnav

**Best for interaction-based WCAG 2.2 scans with developer-ready reporting**

[**Tabnav**](https://tabnav.com/accessibility-checker) provides a web accessibility checker designed to surface issues by scanning pages in a way that reflects real user behavior, not just static DOM analysis. Users enter a URL and quickly receive results with code-level findings and issue breakdowns. Its approach emphasizes interaction simulation, helping teams identify accessibility barriers in dynamic components that basic AI scanning tools may overlook. Tabnav also positions broader capabilities around monitoring and team collaboration for ongoing accessibility work.

- **Key Specs**: Real user interaction simulation; unlimited free scans with exportable reports.
- **Compliance**: Checks against WCAG 2.1/2.2 AA, ADA, and EAA-related criteria.
- **Support**: Automated reporting with optional manual audit services for deeper validation.
- **Verdict**: A practical entry point for teams that want immediate technical feedback, while recognizing that full WCAG 2.2 compliance still requires structured manual auditing.

#### What Stands Out:

- **Interaction Simulation**: Tests dynamic behaviors (like keyboard traps, modal focus handling, and interactive menus) that static scanners often miss.
- **Zero Friction**: No signup or configuration required to run scans.
- **Manual Audit Path**: Offers additional human-led testing services to validate findings and cover assistive technology use cases beyond automated detection.

#### Who Should Choose Tabnav?

- Teams that need rapid scans and practical findings for iterative remediation, especially developers who want automated interaction testing paired with the option for manual validation.

![](https://www.atlantic.net/wp-content/uploads/2025/08/Siteimprove_logo_2020.png)

### #4 – Siteimprove

**Best for continuous WCAG 2.2 monitoring and content-team governance**

Siteimprove provides accessibility tools that scan pages against WCAG and help teams identify and prioritize issues across large digital properties. Its platform focuses on ongoing monitoring rather than one-time audits, making it suitable for organizations that publish frequent content updates. While automated crawling handles large-scale detection, Siteimprove also offers expert testing services when manual review is required for complex templates and interactive elements.

- **Key Specs**: Automated site crawling; SEO and accessibility integration; policy-based issue flagging.
- **Compliance**: WCAG 2.2 monitoring with reporting that supports EAA alignment efforts.
- **Support**: Customer success managers, onboarding programs, and training academy resources.
- **Verdict**: A strong option for maintaining accessibility standards across content-heavy or decentralized websites, particularly where editorial teams need structured oversight.

#### What Stands Out:

- **Workflow**: Assigns issues directly to content editors or developers through integrated ticketing systems.
- **Visibility**: Connects accessibility findings with SEO and content quality metrics to support prioritization.
- **Governance** **Focus**: Emphasizes continuous automated scanning while enabling manual validation for high-impact user journeys.

#### Who Should Choose Siteimprove?

- Teams that want ongoing visibility, reporting, and governance across large web properties, with automated monitoring supplemented by manual audits when deeper WCAG 2.2 validation is necessary.

![](https://www.atlantic.net/wp-content/uploads/2025/08/AudioEyeInc_Logo.jpg) AudioEye, Inc. Logo (PRNewsFoto/AudioEye, Inc.)

### #5 – AudioEye

**Best hybrid managed service combining automation and manual remediation.**

AudioEye operates between a basic overlay tool and a fully manual consulting engagement. Its “Always-On” platform uses automated detection to identify and fix certain accessibility issues. At the same time, a team of specialists reviews and manually remediates more complex barriers that automated systems cannot reliably resolve. This structure reflects the difference between AI-based scanning and full human validation, which is critical for achieving sustainable WCAG 2.2 compliance across dynamic user flows.

- **Key Specs**: Hybrid automation plus human testing and remediation services.
- **Compliance**: Supports WCAG 2.2 alignment, ADA-related requirements, and structured reporting for procurement needs.
- **Support**: Continuous monitoring, issue validation, and compliance reporting for managed customers.
- **Verdict**: A balanced option for mid-market organizations that want automated coverage with ongoing manual oversight, without building a large internal accessibility team.

#### What Stands Out:

- **Visual Toolkit**: Provides users with a toolbar to adjust fonts, contrast, and navigation preferences.
- **Performance**: Designed to load asynchronously to minimize performance impact.#6 – Level Access

#### Who Should Choose AudioEye?:

- Organizations that want a blended approach rather than relying on tooling alone.

![](https://www.atlantic.net/wp-content/uploads/2025/08/levelaccess.png)

### #6 – Level Access

**Best for enterprise-wide WCAG 2.2 governance, manual auditing, and procurement documentation**

Level Access positions its offering as an end-to-end digital accessibility platform supported by dedicated experts. It is designed for organizations that require repeatable, defensible processes across multiple teams, with structured support for testing, remediation, monitoring, and reporting. Unlike overlay-only solutions, Level Access emphasizes formal manual audits, assistive technology testing, and documented remediation workflows aligned with WCAG 2.2 Level AA.

- **Key Specs**: Unified platform combining automated scanning, manual audit integration, remediation tracking, and governance tools; owns UserWay for the SMB tier.
- **Compliance**: Supports WCAG 2.2 AA, ADA, Section 508, and EAA-related requirements with enterprise reporting.
- **Support**: Dedicated accessibility experts, legal guidance programs, and structured compliance documentation.
- **Verdict**: A strong fit for large enterprises, government bodies, and regulated industries that need audit defensibility and cross-team accountability.

#### What Stands Out:

- **Legal Support Structure**: Provides formal compliance guidance and documentation support for organizations managing regulatory risk.
- **Unified Platform**: Centralizes automated scan results, manual audit findings, remediation tracking, and training records in one dashboard.
- **Manual + Automated Depth**: Combines AI-based scanning with human-led validation to address complex user journeys, custom applications, and procurement reporting requirements.

#### Who Should Choose Level Access?

- Organizations that need scalable governance, documented manual auditing processes, and enterprise-grade reporting to maintain WCAG 2.2 compliance over time.

![](https://www.atlantic.net/wp-content/uploads/2025/08/barrier-break-logo.png)

### #7 – BarrierBreak

**Best for accessibility-led manual audits and inclusive user testing**

BarrierBreak is a digital accessibility consulting firm that specializes in manual WCAG 2.2 audits, assistive technology testing, and usability validation with real users. Instead of relying on software overlays, BarrierBreak uses structured human evaluation, including screen reader testing, keyboard-only navigation, and user feedback on key tasks. Their services focus on finding issues that automated tools often miss, especially in custom applications and complex user flows.

- **Key Specs**: Manual WCAG 2.2 audits; assistive technology testing; usability testing with users with disabilities.
- **Compliance**: WCAG 2.2 AA alignment; Section 508 and EN 301 549 mapping support.
- **Support**: Remediation guidance, developer collaboration, training workshops, and VPAT/ACR documentation assistance.
- **Verdict**: A strong option for organizations that prioritize defensible manual auditing and inclusive usability validation over automated-only approaches.

#### What Stands Out:

- **Assistive Technology Coverage**: Screen reader, magnification, and keyboard testing across critical user journeys.
- **Usability Testing**: Incorporates feedback from users with disabilities to validate real-world accessibility.
- **Documentation Support**: Provides structured conformance reporting aligned with procurement requirements.

#### Who Should Choose BarrierBreak?

- BarrierBreak is a good fit for organizations that need independent manual WCAG 2.2 audits and inclusive usability testing to help with compliance, reduce risk, and support procurement documentation.

## How do you choose the right accessibility company in 2026?

Match vendor strengths to your operating model, internal resources, and legal risk exposure. In 2026, the core question is whether you need a software overlay, an automated scanning platform, or a full remediation partner capable of delivering documented WCAG 2.2 compliance.

Use these checks before you buy:

- **Ask how they test**: Manual testing plus automated scanning is the baseline. Confirm whether they perform structured manual audits with assistive technology (screen readers, keyboard-only navigation) or rely primarily on AI-based scanning. Ask how they validate dynamic UI, modals, forms, and key transactional user journeys.
- **Confirm remediation ownership**: Who fixes issues—your team, their team, or both? Make scope, timelines, and verification steps explicit.
- **Demand prioritization**: You want issues ranked by user impact and remediation effort, not a long unranked export from an automated tool.
- **Monitoring plan**: Accessibility changes with releases and content updates. Decide how you’ll prevent regressions through continuous scanning and periodic manual re-testing.
- **Request documentation early**: If procurement requires VPAT/ACR-style reporting, include it in scope from day one. Confirm that documentation reflects manual validation, not just automated scan summaries.
- **Validate workflow fit**: If you ship weekly, prioritize integrating the dev/QA workflow. If you publish daily, prioritize scalable monitoring and governance tools. If you operate in regulated industries, prioritize vendors with formal audit processes and defensible reporting aligned with WCAG 2.2 AA.

## Partner with a Reliable Cloud Provider

Digital accessibility work still needs a stable hosting foundation—performance, uptime, and infrastructure security directly affect user experience for everyone, including users relying on assistive technologies. Accessible front-end code cannot compensate for slow load times, unstable environments, or poorly configured application stacks that interrupt screen reader or keyboard interactions.

At [Atlantic.Net](https://www.atlantic.net), we provide cloud hosting and managed services for organizations running production websites and applications. Founded in 1994, we support businesses that need reliable infrastructure while they improve and maintain their digital experiences. Our infrastructure supports organizations implementing WCAG 2.2-compliant applications that require consistent performance, release management, and monitoring. Contact us to discuss cloud hosting options that fit your organization’s operational requirements.

Sustainable WCAG 2.2 compliance requires both automated monitoring and structured manual auditing — not software overlays alone.

## FAQ

### 1. What does a web accessibility audit include?

A credible audit combines automated scans with manual testing. Manual testing usually includes keyboard-only navigation checks, focus order validation, form and error-handling evaluation, and assistive technology testing across key user flows. Manual auditors also review dynamic components, modal dialogs, ARIA implementations, and interactive workflows that automated scanners frequently misinterpret or miss entirely. The output should include prioritized issues and clear remediation guidance aligned with WCAG 2.2 success criteria.

### 2. Is an automated accessibility scan enough?

Automated scans are useful for catching common issues at scale, but they don’t cover everything. AI-based tools typically detect only rule-based violations and cannot fully assess usability, context, or the behavior of real assistive technology. Manual testing is still needed for interactive components, complex flows, and user experience barriers that automated tools cannot reliably evaluate.

### 3. What is WCAG Level AA, and why do teams target it?

WCAG defines success criteria at Levels A, AA, and AAA. Many organizations aim for Level AA because it is commonly used as a practical target for broad accessibility coverage and is frequently referenced in policy, procurement, and regulatory enforcement contexts. In 2026, WCAG 2.2 Level AA is widely treated as the operational benchmark for public-facing websites and enterprise SaaS platforms.

### 4. What’s the difference between a VPAT and an ACR?

A VPAT is a standardized template for reporting accessibility conformance. An ACR (Accessibility Conformance Report) is the completed report produced using that template. Buyers often request this documentation during procurement. A credible ACR should reflect the results of manual validation, not just automated scan summaries.

### 5. What should you ask an accessibility vendor before signing?

Ask about testing methodology (manual + automated), what assistive technologies they use, remediation responsibilities, monitoring options, and the format of deliverables. Clarify whether they provide full remediation services or only overlay/automation tools. If you need procurement documentation, confirm how they support reporting and updates over time.

### 6. How long does accessibility remediation take?

It depends on site size, code quality, and the number of templates or components affected. Many teams start with a prioritized plan focused on high-traffic or high-risk user journeys, then expand to the full site or product over multiple release cycles. Applications with complex interactive workflows typically require phased remediation combined with periodic manual re-testing to confirm WCAG 2.2 conformance.

### 7. Are accessibility widgets or overlays enough on their own?

A widget can add user controls and may help with some surface-level adjustments, but it does not replace the underlying code or remediate content across all user flows. Overlays and AI-based fixes do not substitute for structured manual auditing, assistive technology testing, and documented remediation processes. Most organizations still need auditing, remediation work, and monitoring to sustain accessibility compliance over time.


---

# The Top Domain Registrars for Your Business in 2026

> URL: https://www.atlantic.net/vps-hosting/the-top-domain-registrars-for-your-business/ | Published: 2026-03-03 | Updated: 2026-06-24 | Author: Robert Agar

Companies or individuals who have a website typically associate the site with a domain. A domain is essential for enabling users to access the website easily. While an organization can have a website without a [domain name](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/how-to-choose-a-domain-name-that-builds-trust/), it is not the most efficient way to maintain a web presence.

Choosing a domain registrar is an important decision that impacts your brand’s security, pricing, and technical options for years to come. In 2026, the best registrars stand out for clear renewal pricing, free WHOIS privacy, DNSSEC support, and helpful AI tools for finding domains.

This article explains why owning a domain remains essential for brand control and search visibility, and how to secure one through a registrar that offers transparent pricing, DNSSEC support, and free WHOIS privacy. We’ll review the different types of domains, including high-demand extensions like .AI, and explain how to choose the right domain for your business goals.

## What Is a Domain?

A domain is the unique name that identifies a website on the Internet. A domain name can be seen as an alias that represents the website’s underlying IP address. An IP address, such as 123.47.89.23, is harder to remember and less intuitive than a well-chosen domain name. In addition to branding, a domain serves as a control layer for [DNS](https://www.atlantic.net/vps-hosting/what-is-dns-and-how-does-it-work/) configuration, email authentication (SPF, DKIM, DMARC), and security features such as DNSSEC. You obtain a domain from a domain registrar.

### Parts of a Domain Name

A domain is comprised of three parts. The domain name www.mybusiness.com consists of three distinct sections, separated by periods or dots.

The optional subdomain in this case is www

The second-level domain is your custom name; in this case, it is mybusiness.

The top-level domain, in this case, is .com. Businesses increasingly choose industry-specific or high-demand extensions such as .AI to align with their market positioning.

Since the subdomain is optional, you can search for this site by typing www.mybusiness.com or mybusiness.com in your web browser. Additional subdomains (such as app.mybusiness.com or api.mybusiness.com) can be configured through your registrar’s DNS management panel.

## Why Do I Need a Domain?

You need a domain for several reasons.

- A domain provides a professional and controlled online identity. Owning a domain gives businesses, individuals, and organizations multiple advantages over competitors without one.
- Custom domains, such as mybusiness.com, are more professional-looking than mybusiness.domainprovider.com, which can make a better first impression on potential visitors.
- Custom email addresses give you more legitimacy. For example, users are more likely to trust support@mybusiness.com than [mybusiness@gmail.com](mailto:mybusiness@gmail.com).
- A domain allows you to own your brand name. Once it is registered, it cannot be used by any other service or company.
- A domain gives you complete control over your digital identity, including where the address points to and how your brand appears online, to improve visibility and increase traffic.
- Search engines prioritize trusted and branded domains in their search results.
- A domain makes it easier to find your website with a searchable and straightforward digital address.
- Transparent renewal pricing protects your business from unexpected cost increases over time, which is critical for long-term brand continuity.
- Modern registrars also provide AI-powered domain discovery tools that suggest available names, premium alternatives, and relevant extensions based on your business keywords.

## Types of Domains

Several types of domains are used for different purposes on the Internet. You should understand the differences so you can make an informed decision when selecting a domain for registration. Beyond branding, your choice of extension can influence pricing stability, geographic targeting, and how easily customers recognize your industry focus.

### Top-Level Domains (TLD)

The TLD is the last part of a domain name, following the last dot. The Internet Corporation for Assigned Names and Numbers (ICANN) manages generic top-level domains.

The following are examples of the most common generic TLDs and the types of websites they represent.

- .com – Commercial sites
- .org – Nonprofit organizations
- .edu – Educational institutions
- .gov – U.S. government agencies
- .int – International organizations
- .net – Network services

Popular extensions like .AI are now widely used by tech and AI companies, but they often cost more to register and renew than standard domains. Check both the first-year and renewal prices before you register to avoid surprises.

### Country Code Top-Level Domains

Specific countries or territories may have an assigned two-letter TLD, as in the following examples. They are typically used for local businesses or audiences in the designated region.

- .ca – Canada
- .de – Germany
- .in – India
- .uk – United Kingdom
- .au – Australia
- .jp – Japan

Country-code domains (ccTLDs) sometimes require a local address or presence, and prices can vary widely across registrars. If your business is focused on a specific region, check whether the ccTLD supports DNSSEC and improves local search visibility before choosing one.

### Sponsored Top-Level Domains

These top-level domains are managed privately by specific industries or communities. Organizations desiring this type of domain will typically have to undergo an eligibility verification process.

- .jobs – Human resource management
- .edu – Accredited educational institutions
- .museum – Museums

Sponsored TLDs often require documentation or formal approval, which can extend registration timelines but may add credibility within specific sectors.

### New Generic Top-Level Domains

New generic TLDs are being introduced to support company branding, industry-specific domains, or creative domain names. Examples include:

- .tech
- .online
- .store
- .design
- .app

Many modern registrars now use AI-powered search tools to suggest available combinations across these newer extensions, helping businesses secure shorter or keyword-rich domains that may not be available under .com.

### Second-Level Domains (SLD)

The SLD is placed directly before the TLD and is typically selected by the domain owner. The SLD is the customizable portion of the domain and often contains a company name or a description of the website’s services. Creative use of the SLD enables organizations to differentiate themselves from other providers. Strong SLD selection also improves memorability and reduces reliance on paid advertising for brand recall.

For example, www.thebestusedguitars.com provides information that can help drive traffic from prospective customers.

### Subdomains

A subdomain is a prefix to a domain that can be useful for organizing content or dividing information. Subdomains are often used to designate separate areas of a site or services, for example:

- support.mybusiness.com
- blog.mywebsite.com
- info.myservices.org

Subdomains are managed through your registrar’s DNS settings, making reliable DNS management and DNSSEC support important features when choosing a provider.

### Internationalized Domain Names

Domain names may include characters from alternative languages, such as Arabic, Chinese, or Cyrillic, to increase their appeal to local users. These internationalized domain names (IDNs) allow businesses to reach native-language audiences while maintaining proper DNS configuration and security standards.

## Other Uses for Domains

While domains are typically used for websites, they can also be utilized for a variety of other purposes, as illustrated in the following examples.

- Professional email addresses, such as info@yourbusiness.com, can enhance credibility and brand recognition.
- Redirecting and URL forwarding let you route a domain to another website or social media profile, promoting your brand. For example, yourstore.com may link to your account on eBay, Etsy, or another online marketplace.
- Companies can create landing pages or forms, like event registration, using a domain to support marketing efforts without a fully operational website.
- Organizations can create subdomains for internal and external tools, such as support.mybusiness.com or portal.mybusiness.com.
- Domain-based authentication, utilizing technologies such as DMARC or SPF, supports secure email transmission and identity verification, protecting a company’s reputation.
- DNSSEC adds a layer of protection by preventing DNS spoofing and cache poisoning attacks, which is increasingly important for businesses handling customer data.
- Owning strategic domains (including common misspellings or alternative extensions like .AI) helps protect brand assets and prevents competitors from acquiring similar names.

## Key Features of Domain Name Registrars

Organizations purchase domains through domain name registrars. Customers should look for the following key features when selecting their domain name registrar.

- The company should handle the domain search and registration to help you locate and secure a domain that fits your requirements.
- Domain name server (DNS) management is necessary to connect the domain to the Internet and email services.
- The registrar should offer WHOIS privacy protection to secure your personal information.
- Most popular domain registrars offer auto-renewal to ensure continuity.
- The company should ensure domain locking to prevent unauthorized domain transfers.
- Subdomain support is essential if the customer wants to direct users to other services the customer provides.
- Customer support is vital, and customers should look for registrars that offer 24/7 phone or live chat support.
- The registrar may offer web hosting and email integration for additional convenience when setting up a site.
- The company should provide transparent pricing with no hidden fees. Some registrars may offer a free plan or special first-year pricing for new customers.
- Clear renewal pricing and upfront disclosure of transfer fees are critical to avoid unexpected cost increases after the first year.
- AI-powered domain discovery tools that suggest keyword-based, brandable, and available domain options can significantly reduce the time spent searching for the right name.
- Built-in DNSSEC support and easy [DNS record](https://www.atlantic.net/dedicated-server-hosting/cloud-hosting-getting-started-with-dns-records/) management (A, AAAA, MX, TXT, CNAME) are essential for businesses that require secure email authentication and cloud infrastructure integration.

## Seven of the Best Domain Registrars

The following domain registrars stand out in 2026 for transparent renewal pricing, free WHOIS privacy, DNSSEC support, and AI-powered domain discovery tools. Each provider listed below offers a balance of cost stability, security features, and flexible DNS management to help businesses secure and protect their digital identity long term.

### 1. Squarespace

![](https://www.atlantic.net/wp-content/uploads/2025/08/Squarespace_Logo.png)

Squarespace offers a wide variety of extra services, including email forwarding to up to 100 addresses, free WHOIS privacy, and free, updated SSL certificates for enhanced security. Domains are protected by two-factor authentication and premium DNS services to ensure the reliability and availability of your website. All domains registered through Google Domains were migrated to Squarespace in July 2024. Squarespace also supports DNSSEC for eligible domains and provides clear renewal pricing during checkout, reducing the risk of unexpected long-term cost increases. Its integrated search experience helps users quickly identify available names across multiple TLDs.

Here’s the Squarespace domains dashboard, where you can manage your domain portfolio and start building a modern website with AI-powered tools.
 ![Squarespace domain](https://www.atlantic.net/wp-content/uploads/2026/03/Squarespace-domain.png)
 Image Source: Squarespace

#### Advantages

- **Transparent, All-Inclusive Pricing**: When you register a domain, the price includes free WHOIS privacy. There are no surprise fees or aggressive upselling tactics during checkout. Renewal rates are displayed before purchase, improving price visibility.
- **Clean and Simple Domain Management**: Carrying over Google Domains’ philosophy, the management interface is minimalist and easy to use, focusing only on the essential tools you need. DNS records (A, MX, TXT, CNAME) can be edited directly from the dashboard with straightforward controls.
- **smooth Connection to Squarespace Sites**: If you use their website builder, connecting your domain is automatic, removing any technical hurdles related to DNS configuration.

#### Ideal For

- **Users Seeking Simplicity**: For those who want a clean, straightforward “set it and forget it” domain registration experience without being bombarded with offers for other products.
- **Former Google Domains Customers**: Users who appreciated Google Domains’ no-nonsense approach will find a familiar, reliable experience at Squarespace.
- Businesses that prioritize built-in privacy, DNSSEC support, and predictable renewal pricing over aggressive introductory discounts.

### 2. Wix

![](https://www.atlantic.net/wp-content/uploads/2025/04/wix-logo.png)

Wix lets users give their website a professional look with a custom domain name. They offer a free custom domain for a year when users purchase a premium plan. After domain registration, Wix has multiple tools to help customers build a compelling site, including premade templates and an AI website builder. The provider offers easy domain registration, [SSL](https://www.atlantic.net/vps-hosting/what-is-ssl-certificate/) certificate security, no hidden fees, and 24/7 customer support. Wix also includes free WHOIS privacy for eligible domains and displays renewal pricing before checkout, improving cost transparency for long-term planning.

Take a look at the Wix domain interface, designed to help you find the perfect domain name and launch your website quickly.
 ![wix domain](https://www.atlantic.net/wp-content/uploads/2026/03/wix-domain.png)
 Image Source: Wix

#### Advantages

- **Zero-Configuration Setup**: When you register a domain through Wix for your Wix website, it connects automatically. There are no DNS settings to manage or technical steps to follow.
- **Free for the First Year**: The domain cost is waived for the first year with the purchase of most annual premium plans, simplifying budgeting for a new site launch. Renewal pricing applies after the first year, so reviewing long-term costs is important.
- **Centralized Management**: Your domain billing and settings are managed directly in your Wix site dashboard, eliminating the need to log in to a separate registrar account. Basic DNS record management is available directly within the platform.

#### Ideal For

- **Non-Technical Website Builders**: Perfect for users intimidated by the technical aspects of domain management and who want the process to be completely automated.
- **Users Committed to the Wix Platform**: If you are certain you will build and host your site on Wix, registering your domain with them is the most convenient and smooth option.
- Small businesses that prefer bundled website, hosting, and domain management in one interface with built-in privacy protection.

### 3. DynaDot

![](https://www.atlantic.net/wp-content/uploads/2025/08/Dynadot_logo.png)

DynaDot offers users competitive domain prices, expert tools, and free privacy protection. Customers can search from over 500 TLDs to find their perfect domain names through its **[domain name registration](https://www.dynadot.com/domain/search)** process.  The company supports over eight million domains and offers a selection of new, premium, and expiring domains. DynaDot provides customers with a powerful control panel for domain management and protects your site with enterprise-grade domain and account security. The platform also supports DNSSEC and highlights renewal pricing during checkout, helping customers evaluate total ownership cost.

Here’s the Dynadot domain management dashboard, where you can track domain status, handle renewals, and manage your online assets with ease.
 ![DynaDot](https://www.atlantic.net/wp-content/uploads/2026/03/DynaDot.jpg)
 Image Source: Dynadot

#### Advantages

- **Excellent Long-Term Value**: DynaDot is known for its highly competitive renewal rates, making it one of the most affordable registrars for long-term domain ownership.
- **Powerful Tools for Portfolios**: The platform includes advanced features such as bulk search, a domain aftermarket, and detailed filtering, all of which are invaluable for managing multiple domains. AI-assisted search tools help identify brandable or keyword-based available names.
- **Vast TLD Selection**: With support for hundreds of TLDs, including many new and country-code extensions, it’s an excellent choice for finding unique and creative domain names.

#### Ideal For

- **Users Focused on Long-Term Costs**: Anyone who wants to avoid the common trap of low introductory prices followed by high renewal fees will appreciate DynaDot’s fair pricing model.
- **Domain Investors and Portfolio Managers**: Individuals who buy, sell, or manage a large collection of domains will benefit from the specialized tools and cost-effective pricing structure.
- Businesses seeking transparent pricing, DNSSEC support, and advanced search capabilities without bundled hosting requirements.

### 4. Cloudflare

![](https://www.atlantic.net/wp-content/uploads/2025/08/Cloudflare_Logo.png)

Cloudflare is widely recognized for its global DNS and security network, but it also offers a domain registrar focused on security and simple pricing. Cloudflare Registrar is designed for customers who want to manage domains and advanced DNS services in one place. The company keeps pricing simple by charging the registry cost plus a fixed fee, so there are no unexpected price increases at renewal. You can manage your domains using the same dashboard as your [CDN](https://www.atlantic.net/hipaa-compliant-hosting/content-delivery-networks-theyre-powerful/), [firewall](https://www.atlantic.net/managed-services/firewall/), and DNS settings.

Explore the Cloudflare dashboard to manage domains, improve website security, and optimize performance through a global network.
 ![Cloudflare](https://www.atlantic.net/wp-content/uploads/2026/03/Cloudflare.jpg)
 Image Source: Cloudflare

#### Advantages

- **Transparent, cost-based pricing**: Cloudflare sells domains at the registry cost plus a fixed fee, which helps businesses avoid large price increases at renewal.
- **Integrated DNS and security**: Domains automatically use Cloudflare’s DNS system, which includes built-in DNSSEC and fast global resolution.
- **Strong account protection**: Multi-factor authentication and domain locking help prevent unauthorized transfers.

#### Ideal For

- Businesses that already use Cloudflare for DNS, CDN, or security services and want to manage everything together.
- Technical teams that need advanced DNS controls, DNSSEC, and consistent renewal pricing without extra upsells.

### 5. Porkbun

![](https://www.atlantic.net/wp-content/uploads/2025/08/porkbun-logo.png)

Porkbun has built a strong reputation for flat, competitive pricing and included security features. The registrar clearly displays both registration and renewal rates upfront, making it one of the most transparent pricing models in the market. Domains typically include free WHOIS privacy, SSL certificates, and DNSSEC support at no additional charge. Porkbun also provides an intuitive search interface to help users quickly evaluate available names across a wide range of TLDs, including high-demand extensions like .AI.

Take a look at the Porkbun control panel designed to help you register domains, manage WHOIS settings, and control domain security features.
 ![Porkbun](https://www.atlantic.net/wp-content/uploads/2026/03/Porkbun.jpg)
 Image Source: Porkbun

#### Advantages

- **Flat and Transparent Pricing**: Registration and renewal costs are clearly listed, with minimal markup differences between first-year and renewal rates.
- **Free WHOIS Privacy and DNSSEC**: Security features are included by default for supported domains.
- **Clean Management Interface**: DNS records (A, MX, TXT, CNAME) can be edited easily without working in complex menus.

#### Ideal For

- Businesses focused on long-term ownership costs and on avoiding aggressive first-year discounts that lead to high renewal rates.
- Startups and AI-focused companies seeking competitive pricing for extensions, including AI, with included privacy protection.

### 6. Spaceship

![](https://www.atlantic.net/wp-content/uploads/2025/08/spaceship-logo.png)

Spaceship is a newer domain registrar that focuses on clear pricing and easy domain management. It shows renewal rates up front at checkout and does not use big discounts that jump in price later. Spaceship offers free WHOIS privacy for eligible domains and supports DNSSEC to help protect against [DNS attacks](https://www.atlantic.net/vps-hosting/how-to-domain-name-server-dns-amplification-attack/). The search tool gives smart suggestions to help users find available, brandable names across many domain extensions, including popular ones like .AI.

Take a look at the Spaceship interface designed to help you handle domain registration, transfers, and privacy settings with ease.
 ![spaceship](https://www.atlantic.net/wp-content/uploads/2026/03/spaceship.jpg)
 Image Source: Spaceship

#### Advantages

- **Clear Renewal Pricing**: You see both registration and renewal costs before you buy, so there are no surprises later.
- **Free WHOIS Privacy and DNSSEC**: Key security features come standard for supported domains.
- **Modern Dashboard**: You can manage DNS records like A, AAAA, MX, TXT, and CNAME from an easy-to-use control panel.

#### Ideal For

- Startups and small businesses that want steady, long-term pricing without pushy sales tactics.
- Anyone who wants built-in privacy and helpful domain search tools right from the start.

### 7. Atom

![](https://www.atlantic.net/wp-content/uploads/2025/08/atom-logo.png)

Atom is a domain marketplace and registrar specializing in brandable domains and using AI to help users find names. Its platform features an AI search tool that suggests available names based on keywords, industry, and brand style. Along with regular domain registrations, Atom also offers premium, curated domains for startups and online brands. Eligible domains come with WHOIS privacy, and users can manage DNS records for website and email setup.

Let’s explore the Atom.com dashboard, where you can discover premium domains, run AI-powered naming tests, and validate your brand ideas.
 ![Atom](https://www.atlantic.net/wp-content/uploads/2026/03/Atom.jpg)
 Image Source Atom

#### Advantages

- AI-powered domain discovery gives users smart suggestions, making it easier and quicker to find unique, available brand names.
- Users can browse curated and premium domains as well as standard registrations in the marketplace.
- Registration and renewal costs are clearly shown before you check out.

#### Ideal For

- Founders and marketing teams who want brandable, startup-ready domain names with helpful search tools.
- Businesses that care about naming strategy and discovery features, along with standard domain management.

## Top Domain Registrars: Quick Comparison

| **Registrar** | **Free WHOIS Privacy** | **DNSSEC Support** | **.AI Domain Cost (Approx.)** | **.AI Renewal Pricing** | **Pricing Model Notes** |
| --- | --- | --- | --- | --- | --- |
| Squarespace | Free | Supported | ~$80–$90/year | Similar to registration | Bundled ecosystem; higher overall pricing |
| Cloudflare | Free (at-cost model) | Enabled by default | ~$70/year | Same as cost pricing | No markup pricing structure |
| Wix | Free (with domain purchase) | Limited / Supported | ~$80–$90/year | Renewal often higher | Platform-focused, bundled services |
| DynaDot | Free | Supported | ~$70–$80/year | Competitive renewal | Strong long-term value |
| Porkbun | Free | Supported | ~$70–$80/year | Transparent flat pricing | Known for fair renewals |
| Spaceship | Free | Supported | ~$65–$75/year | Competitive renewals | Value-focused registrar |
| Atom | Free | Supported | ~$70–$80/year | Varies by listing | Premium marketplace focus |

## Conclusion

Organizations need to collaborate with domain name registrars to offer an intuitive user interface for accessing their websites. In 2026, the decision should also prioritize transparent renewal pricing, free WHOIS privacy, DNSSEC support, and AI-powered domain discovery tools that protect long-term brand value. Domain owners should choose names carefully to provide users with information simply by reading the name. Most companies do not want to go through the challenges of attracting customers to a new domain name.

Once you have completed domain registration, you can explore the web hosting options for your site. In some cases, you can work with a domain registrar that also offers shared hosting services. This type of hosting may work for small businesses or personal websites. Review renewal rates, transfer policies, and security features before bundling services to ensure predictable operating costs.

Companies that require more secure solutions should consider a cloud and [dedicated web hosting](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosting-in-depth-buyers-guide/) provider like Atlantic.Net. The company offers high-performance cloud and dedicated servers capable of handling the most [high-traffic websites](https://www.atlantic.net/dedicated-server-hosting/choose-dedicated-server-high-traffic-websites/). The servers provide the additional security many businesses require in today’s evolving cyberthreat market. Pairing a secure hosting environment with a registrar that supports DNSSEC and domain locking creates a stronger foundation for protecting business-critical infrastructure.


---

# Top Shared Hosting Providers in the USA in 2026

> URL: https://www.atlantic.net/vps-hosting/top-shared-hosting-providers-in-the-usa/ | Published: 2026-03-03 | Updated: 2026-03-18 | Author: Robert Agar

Shared hosting remains the easiest way for most people to launch a new website, but performance standards in 2026 are stricter than before. Today’s shared hosting offers features such as isolated resources, NVMe storage, and improved server-side caching to help prevent slowdowns caused by other users on the same server. Many small businesses and personal sites still use shared hosting, but there is now greater pressure to meet higher expectations for uptime, page speed, and Core Web Vitals.

In our review, we focus on clear performance metrics such as Time to First Byte (TTFB), a consistent uptime history, transparent renewal pricing, and provider reputation, including customer reviews and industry awards, to help US businesses choose a trustworthy service.

This article examines shared hosting services, outlines their pros and cons, and provides an overview of leading providers offering shared hosting plans tailored for small businesses, startups, personal websites, and individuals seeking web hosting, helping readers select the most suitable option for their specific needs.

## What Is a Shared Hosting Provider?

A shared hosting provider is a company that offers web hosting services to multiple customers using the same physical server and its associated resources. A single server is partitioned into multiple hosting accounts, with each account hosting a different website. The shared hosting provider is responsible for server management, including maintenance, security patching, monitoring uptime, and optimizing server-level performance.

In 2026, most reputable providers use account-level isolation (such as containerized or CloudLinux-style environments) and NVMe-based storage to reduce the “noisy neighbor” effect that historically impacted shared plans.

Shared hosting companies can maximize their hardware investment by supporting multiple users on one machine. While this model keeps costs low, customers should evaluate resource limits, storage type (SSD vs. NVMe), and historical uptime guarantees before selecting a provider. There are advantages and potential issues associated with this type of web hosting that customers should consider when selecting a hosting solution.

## What Are the Benefits of Shared Hosting Services?

Organizations or individuals typically select shared hosting to create and support a website for several reasons. Shared web hosting services provide the following benefits to customers.

- A shared hosting plan is the most cost-effective way to create a website and develop a web presence, helping small businesses and startups feel confident about their investment. It is more affordable than many other cloud hosting options, such as provisioning a dedicated server. Companies with limited financial resources or startups can save significant funds by choosing a shared web hosting plan. Modern shared plans now frequently include SSD or NVMe storage and built-in caching, improving baseline performance without increasing entry-level pricing.
- Shared web hosting companies handle server maintenance and management. The customer can focus on running their website while the provider ensures the hosting platform is secure, available, and performs acceptably. Many providers now publish uptime guarantees (often 99.9% or higher) and provide performance monitoring dashboards to help users track availability and response times. Organizations may choose a shared hosting provider to gain experience they can leverage later to support other cloud hosting plans, such as dedicated servers.
- Shared web hosting companies appeal to users with limited technical skills. Many users want to run a WordPress site or online store with minimal technical expertise requirements. Most providers offer simple control panels, such as Plesk or cPanel, making it easy for users to access and modify their accounts. One-click WordPress installs, automatic updates, staging environments, and free SSL certificates are now common baseline features that support better Core Web Vitals performance out of the box.

## Are There Potential Drawbacks to Shared Web Hosting?

Shared web hosting may not be the optimal solution for some organizations. The following are some key issues to consider when selecting this type of web hosting service.

- **Limited control** – Users have limited control over their website settings when sharing a server. Customers must work within the provider’s constraints and may not be able to optimize the account to meet their needs. Advanced server-level configurations, custom firewall rules, and deep performance tuning are typically restricted to shared plans. Potential clients should investigate the specific hosting features available with a provider’s shared plans.
- **Potential security risks** – Organizations that share a server with other customers may be exposed to additional security risks. A customer following security best practices may be affected by malware introduced to the server via another account. Although modern providers implement account isolation and malware scanning, shared environments still carry more inherent risk than isolated VPS or dedicated servers.
- **Inconsistent performance** – Companies may experience inconsistent performance when running a website on a shared platform. A customer can be negatively affected by other tenants’ resource usage, since the server does not have unlimited bandwidth. Website performance may fluctuate wildly if accounts use more resources than usual. This can directly impact Time to First Byte (TTFB), page load speed, and Core Web Vitals metrics, particularly during traffic spikes. Organizations that require support for tens of thousands of transactions or high-volume traffic may not be satisfied with a shared hosting plan.
- **Shared IP address** – The lack of a dedicated IP address puts companies at risk of being blocked due to malicious exploits by other tenants sharing the resources. A rogue tenant can make it difficult for users to operate their website effectively by blocking their IP address. Businesses that rely heavily on email deliverability or reputation-sensitive applications should consider whether a dedicated IP option is available.

## How Does Shared Hosting Compare to Dedicated Hosting?

Organizations seeking a web hosting plan might require more control and security than shared hosting offers. Companies with more stringent requirements may opt for a dedicated server solution. The decision often comes down to predictable performance benchmarks (such as uptime consistency and TTFB), compliance requirements, and long-term scalability. The following table highlights the key differences between shared and dedicated hosting solutions.

| **Feature** | **Shared Hosting** | **Dedicated Hosting** |
| --- | --- | --- |
| Cost | Affordable websites with low introductory pricing | More expensive with higher monthly operating costs |
| Control | Limited control over server resources | Extensive control over system resources and configuration |
| Security | Potential security issues with a shared server, even with account isolation | Strong security with a fully isolated environment |
| Performance | Inconsistent performance, based on the other sites’ usage patterns | Consistent performance and stable site speed with dedicated CPU, RAM, and storage |
| Storage Type | Typically, SSD or NVMe storage in modern plans | NVMe or enterprise-grade storage configurable per workload |
| Regulatory compliance | Shared servers typically will not meet strict regulatory compliance standards. | Dedicated servers provide the enhanced security necessary to meet compliance regulations. |
| Core Web Vitals Impact | May fluctuate under heavy multi-tenant load | More predictable Core Web Vitals performance due to reserved resources |
| Technical expertise requirements | Limited or no technical knowledge required | Technical knowledge is encouraged to optimize server usage |

## Who Should Use Shared Web Hosting Services?

Shared hosting services are ideal for many customers due to their low cost and reduced technical requirements. They are best suited for websites with predictable traffic levels and moderate performance expectations. The following are some of the most common use cases for shared web hosting providers.

- Small business websites and startups can save money by using budget-friendly hosting providers. Shared hosting is often sufficient for brochure sites, local service businesses, and early-stage ecommerce stores with low daily transaction volume.
- Users creating personal blogs will appreciate the user-friendly aspects of shared hosting. Built-in WordPress installers, automatic updates, and free SSL certificates make it easier to launch quickly without technical overhead.
- Low-traffic websites can operate effectively with the limited resources available from a shared server. Sites receiving a few thousand monthly visitors can typically maintain acceptable TTFB and uptime levels on modern NVMe-based shared plans.

## How to Select a Shared Hosting Company

Prospective customers should consider the following factors before selecting a shared hosting plan.

- A user-friendly platform is an essential feature for many shared hosting customers. Individuals and small companies are often drawn to this type of hosting service because they lack the technical expertise or resources. Providers should offer a user-friendly control panel allowing users to monitor their site. Look for features such as one-click installations, automated backups, and integrated performance monitoring tools.
- The provider must offer customers access to a support team that can assist them in resolving issues promptly. Ideally, the company should have a complete support center including 24/7 phone and live chat support. Response time and technical depth of support directly affect uptime during outages or traffic spikes.
- The provider should offer a range of web hosting plans to meet different customer needs. Some companies may specialize in specific WordPress hosting plans for customers who use that popular platform. Ensure that higher-tier shared plans include higher CPU and memory limits, as well as more caching options, to support growth.
- A money-back guarantee should protect companies if they are unsatisfied with the service. Also, review renewal pricing carefully, as introductory rates often increase significantly after the first term.
- Customers should look for providers with industry experience and an excellent reputation. Independent uptime records, performance benchmarks, and transparent pricing policies are stronger indicators than promotional claims.

## Top Shared Web Hosting Companies in the USA

The following companies are among the top web hosting service providers in the USA. Small organizations and individuals should consider a shared web hosting plan to host a WordPress site or other low-traffic websites. Our 2026 rankings prioritize providers that deliver consistent uptime (99.9% or higher), competitive renewal pricing, NVMe or SSD storage, and stable Time to First Byte (TTFB) performance for US-based visitors. The best web hosting companies typically offer a range of hosting plans tailored to meet diverse customer needs.

![](https://www.atlantic.net/wp-content/uploads/2026/01/NameCheap-Logo.png)

### 1. NameCheap

NameCheap offers shared hosting tailored to users building WordPress websites. Customers can choose from various web hosting plans and purchase a domain name starting at $0.99. The company also enables users to create email accounts with up to five mailboxes. Users can add SSL certificates to protect their website, and the company provides 24/7 support. Recent shared plans include SSD-based storage and free CDN integration to help improve load speed and Core Web Vitals performance for US audiences.

Let’s see the Namecheap shared hosting interface for managing domains, deploying servers, and controlling hosting services from one place.
 ![Namecheap dashboard](https://www.atlantic.net/wp-content/uploads/2026/03/Namecheap-dashboard.jpg)
 Image Source: Namecheap

#### Estimated Performance Benchmarks (US tests):

- **Uptime**: ~99.9% historical average
- **Average** **TTFB**: 400–600ms (shared plans)
- **Core** **Web** **Vitals**: Pass achievable with caching + CDN enabled

#### Advantages:

- **Cost-Effective Domain and Hosting Bundles**: NameCheap excels by offering affordable domain registration, bundled with hosting plans.
- **User-Friendly cPanel Interface**: The inclusion of cPanel simplifies website management, allowing users with minimal technical skills to manage files, databases, and email accounts easily.
- **Free Website Migration**: NameCheap provides a free migration service for existing websites, removing a significant technical barrier for users looking to switch from another provider.
- **Transparent Renewal Pricing**: Plans clearly distinguish between introductory and renewal rates, helping users avoid unexpected cost increases.

#### Ideal For:

- **Budget-Conscious Individuals**: Perfect for students, hobbyists, or individuals launching a personal blog who need reliable hosting without a significant financial investment.
- **First-Time Website Owners**: The straightforward setup process, combined with affordable domain names and integrated email, provides everything a new user needs to get online quickly.

![](https://www.atlantic.net/wp-content/uploads/2025/04/godaddy-logo.png)

### 2. GoDaddy

GoDaddy provides affordable and reliable WordPress and WooCommerce hosting to support customers’ online businesses. They offer a streamlined website builder and one-click installations with the latest software versions and features for your site. Users can customize their website with a wide variety of plugins and themes. Shared hosting plans include SSD storage, automated daily backups (on select tiers), and a global CDN to improve load times for US visitors.

Check out the GoDaddy control panel, designed to simplify domain management, website setup, and server configuration tasks.
 ![Godaddy](https://www.atlantic.net/wp-content/uploads/2026/03/Godaddy.jpg)
 Image Source: GoDaddy

#### Estimated Performance Benchmarks (US tests):

- **Uptime**: ~99.9% historical average
- **Average** **TTFB**: 350–550ms on optimized WordPress plans
- **Core** **Web** **Vitals**: Competitive when CDN and caching are enabled

#### Advantages:

- **Integrated Digital Services**: GoDaddy provides a vast environment of tools, including domain registration, professional email, and marketing services, allowing users to manage all aspects of their online presence in one place.
- **Optimized Performance**: The platform offers performance-optimized hosting for popular content management systems like WordPress, ensuring faster load times and a better user experience for visitors.
- **Strong Security Features**: Plans include 24/7 network monitoring and DDoS protection, ensuring your website is secure against common online threats.
- **Clear Upgrade Path**: Users can scale from shared hosting to VPS or dedicated servers within the same account dashboard as traffic grows.

#### Ideal for:

- **Small Business Owners**: GoDaddy’s all-in-one approach is perfect for startups that want a single provider for their domain, website, and marketing needs, simplifying billing and support.
- **Users Prioritizing Simplicity**: The streamlined user interface and easy integration with other GoDaddy products make it an excellent choice for those who value convenience and ease of use.

![](https://www.atlantic.net/wp-content/uploads/2025/12/scala-hosting.jpg)

### 3. ScalaHosting

ScalaHosting offers a range of different web hosting plans tailored to meet the needs of various user groups. The advanced shared hosting plans allow users to host multiple websites on a single account. ScalaHosting is a beginner-friendly hosting solution that gives users all the tools they need to succeed. The company has an unconditional money-back guarantee to protect unsatisfied customers. Shared plans are built on SSD storage with account-level resource isolation, helping maintain stable performance even in multi-tenant environments.

Here’s the ScalaHosting interface, built to simplify website management, performance monitoring, and server-level security configuration.
 ![ScalaHosting](https://www.atlantic.net/wp-content/uploads/2026/03/ScalaHosting.jpg)
 Image Source: ScalaHosting

#### Estimated Performance Benchmarks (US tests):

- **Uptime**: ~99.9% average
- **Average** **TTFB**: 300–500ms on optimized shared plans
- **Core** **Web** **Vitals**: Strong results when server caching and CDN are enabled

#### Advantages:

- **Proprietary SPanel Control Panel**: ScalaHosting offers its own SPanel, an alternative to cPanel, designed to be lightweight, fast, and highly secure, providing users with a modern, efficient management experience.
- **Advanced Security with SShield**: All shared hosting plans come with SShield Security. This real-time, AI-driven cybersecurity solution actively monitors for threats and blocks over 99.9% of web attacks before they can harm a website.
- **Free Daily Backups**: The service includes free daily disaster-recovery backups stored on an external server, allowing users to restore their website to a previous state with a single click.
- **Transparent Resource Allocation**: Higher-tier shared plans clearly define CPU and RAM limits, helping users anticipate performance under traffic growth.

#### Ideal For:

- **Security-Conscious Users**: Individuals and businesses who prioritize security will appreciate the proactive protection offered by SShield and the reliability of daily off-site backups.
- **Users Seeking to Host Multiple Sites**: The ability to host unlimited websites and databases on higher-tier shared plans makes ScalaHosting an economical choice for developers or entrepreneurs managing multiple web properties.

![](https://www.atlantic.net/wp-content/uploads/2025/08/Hostgator-logo.png)

### 4. HostGator

HostGator provides managed, scalable shared hosting plans to address a wide range of user requirements. Websites are protected with free SSL certificates and automated malware protection. The company offers user-friendly automatic WordPress installation and plugins to customize the website. Users benefit from HostGator’s support, which includes 24/7/365 customer support via chat or phone. Shared plans are SSD-based and include unmetered bandwidth, with optional performance upgrades for higher-traffic sites.

Here is the HostGator cPanel dashboard, where you can manage websites, databases, email accounts, and hosting settings from a centralized interface.
 ![HostGator-cPanel-dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/HostGator-cPanel-dashboard-1.png)
 Image Source: HostGator

#### Estimated Performance Benchmarks (US tests):

- **Uptime**: 99.9% guarantee
- **Average** **TTFB**: 400–650ms on standard shared plans
- **Core** **Web** **Vitals**: Acceptable for small sites; caching recommended for best results

#### Advantages:

- **Generous Resource Policies**: HostGator’s plans offer generous resource allocations, often marketed as ‘unmetered’ bandwidth and disk space. This is suitable for typical website traffic but is subject to a fair-use policy that limits excessive use.
- **User-Friendly Features**: All shared plans come with the industry-standard cPanel control panel, a free SSL certificate, and a one-click installer, making it incredibly easy to set up and manage a new website.
- **Excellent Uptime Guarantee**: The company backs its service with a 99.9% uptime guarantee, ensuring your website is reliably available to visitors with minimal downtime.
- **Scalable Upgrade Path**: Users can transition to VPS or dedicated hosting as traffic and performance requirements increase.

#### Ideal for:

- **Beginners**: The intuitive cPanel interface and extensive support documentation make it simple for first-time website owners to navigate the complexities of web hosting.
- **Small Businesses**: With features like free business email addresses and scalable plans, it provides a professional and affordable foundation for small companies to build their online presence.

![](https://www.atlantic.net/wp-content/uploads/2025/04/wix-logo.png)

### 5. Wix

Wix lets users build a site in minutes using its AI-powered website builder. Customers can choose from over 900 pre-made templates to get up and running quickly. The company’s advanced design tools enable users to customize their site, making it stand out from the crowd. A centralized and complete dashboard enables customers to manage their business efficiently. Wix is a fully managed platform; hosting performance, security patches, and infrastructure scaling are handled automatically without user intervention.

Take a look at the Wix interface, designed to help you find the perfect domain name and launch your website quickly.
 ![wix domain](https://www.atlantic.net/wp-content/uploads/2026/03/wix-domain.png)
 Image Source: Wix

#### Estimated Performance Benchmarks (US tests):

- **Uptime**: ~99.9% platform availability
- **Average** **TTFB**: 250–450ms (managed environment)
- **Core** **Web** **Vitals**: Strong out-of-the-box optimization, though customization flexibility can affect scores

#### Advantages:

- **Drag-and-Drop Editor**: Wix is known for its powerful and user-friendly website builder, which offers professionally designed templates and complete creative freedom over your site’s appearance.
- **All-in-One Solution**: The platform bundles hosting, security, design, and a suite of business tools (like booking systems and e-commerce) into a single subscription, eliminating the need to manage multiple services.
- **Managed and Secure Environment**: Wix handles all security updates, performance optimization, and server maintenance automatically, providing a worry-free experience for users.
- **Built-In Performance Optimization**: Automatic image compression, CDN delivery, and caching are enabled by default to support fast load times for US visitors.

#### Ideal for:

- **Creative Professionals**: Artists, designers, and photographers will find the editor and templates useful for creating online portfolios.
- **Technologically Inexperienced Users**: For anyone intimidated by the technical side of web hosting, Wix offers the simplest path to creating a professional, fully functional website from scratch.

![](https://www.atlantic.net/wp-content/uploads/2025/08/ionos-logo.png)

### 6. IONOS

IONOS offers low-cost shared hosting options to meet customer needs, ranging from creating an accessible online store to quickly building a test website. Hosting plans include managed WordPress sites with customizable updates and online store building with AI tools. The company provides customers with a personal consultant for tailored support 24/7/365. Shared plans include SSD storage, free SSL certificates, and optional performance upgrades designed to improve page load speed for US-based traffic.

Look at the IONOS Cloud control panel, which shows server image management, infrastructure configuration, and US data center deployment options.
 ![IONOS cloud panel](https://www.atlantic.net/wp-content/uploads/2026/01/IONOS-cloud-panel.png)
 Image Source: IONOS

Estimated Performance Benchmarks (US tests):

- **Uptime**: 99.9% availability target
- **Average** **TTFB**: 350–550ms on standard shared plans
- **Core** **Web** **Vitals**: Competitive when caching and image optimization are enabled

#### Advantages:

- **Dedicated Personal Consultant**: Each customer is assigned a dedicated support contact, providing a personalized and consistent support experience that is rare in the shared hosting market.
- **Geo-Redundant Infrastructure**: IONOS mirrors your website data in two separate data centers, ensuring higher reliability and availability. If one center goes down, your site remains online.
- **Competitive Pricing**: The company is known for its low introductory pricing, making it one of the most affordable ways to launch a website for the first year.
- **Transparent Tiered Plans**: Higher-tier shared packages clearly outline increased CPU resources and database limits for growing sites.

#### Ideal for:

- **Budget-Conscious Users**: For those seeking the lowest possible entry cost, IONOS offers some of the most competitive promotional deals available. Just be mindful of the costs you will incur once the promotional period ends.
- **Users Valuing Personalized Support**: The dedicated consultant model is a major benefit for anyone who wants a single point of contact to help them directly.

![](https://www.atlantic.net/wp-content/uploads/2025/08/Hostinger-logo.png)

### 7. Hostinger

Hostinger is known for offering budget-friendly shared hosting with low starting prices and up-to-date technology. It offers managed WordPress hosting, its own hPanel control panel, and LiteSpeed servers to help websites load faster. Shared hosting plans come with NVMe or SSD storage (depending on your location), built-in caching, and a global CDN to speed up load times for US visitors.

Let’s explore the Hostinger control panel, where you can manage your website, domains, and hosting performance from a modern dashboard.
 ![Hostinger cPanel](https://www.atlantic.net/wp-content/uploads/2026/02/Hostinger-cPanel.jpg)
 Image Source: Hostinger

#### Estimated Performance Benchmarks (US tests):

- **Uptime**: 99.9% uptime guarantee
- **Average** **TTFB**: 200–400ms on LiteSpeed-enabled plans
- **Core** **Web** **Vitals**: Strong results with default caching and CDN activated

#### Advantages:

- **Low Starting Prices**: Hostinger offers some of the most affordable entry-level shared hosting plans, making it a good choice for people starting their first website.
- **LiteSpeed Web Server**: Hostinger uses LiteSpeed technology and built-in server caching, helping websites load faster than on traditional Apache-based shared hosting.
- **Beginner-Friendly hPanel**: Hostinger’s custom control panel makes it easy to manage your site while still giving you access to advanced settings when you need them.
- **Easy Upgrades**: You can upgrade to cloud or VPS hosting with Hostinger without switching providers.

#### Ideal for:

- **Budget-Conscious Startups**: Great for new businesses that want good performance without spending a lot at the start.
- **Bloggers and Affiliate Sites**: Good for users who want faster page speeds to help with SEO and meet Core Web Vitals targets.

![](https://www.atlantic.net/wp-content/uploads/2026/01/siteground-logo.png)

### 8. SiteGround

SiteGround is a premium shared hosting provider that focuses on managed features and performance. It offers managed WordPress hosting, automatic updates, daily backups, and strong security monitoring. SiteGround’s shared hosting uses Google Cloud with SSD storage and built-in caching to improve reliability and speed.

Here is the SiteGround dashboard for managing caching, optimizing assets, and improving overall loading times.
 ![SiteGround](https://www.atlantic.net/wp-content/uploads/2026/03/SiteGround.jpeg)
 Image Source: SiteGround

#### Estimated Performance Benchmarks (US tests):

- **Uptime**: 99.9% availability guarantee
- **Average** **TTFB**: 150–350ms in US regions
- **Core** **Web** **Vitals**: Strong out-of-the-box performance with dynamic caching enabled

#### Advantages:

- **Managed WordPress Features**: Most plans include automatic updates, staging environments, and built-in caching.
- **Multi-Layer Caching**: SiteGround’s SuperCacher technology helps WordPress sites load faster, especially those with dynamic content.
- **Proactive Security**: AI-powered anti-bot systems and daily backups help keep your site safe.
- **Google Cloud Infrastructure**: Hosting on Google Cloud improves your site’s reliability and network performance.

#### Ideal for:

- **Growing Small Businesses**: Good for companies that want reliable uptime and steady performance without managing server settings themselves.
- **WordPress-Focused Sites**: Ideal for users who want managed updates, staging tools, and built-in performance features in their hosting plan.

## Conclusion

Shared hosting plans provide customers with an affordable way to establish a web presence, such as with a WordPress website or a startup e-commerce store. In 2026, the baseline expectation includes SSD or NVMe storage, consistent 99.9% uptime, and performance optimization features that support strong Core Web Vitals scores. The companies we have identified all offer low-cost shared hosting services suitable for many users. When comparing providers, pay close attention to renewal pricing, historical uptime, and average TTFB rather than relying solely on introductory discounts. Companies seeking more control, enhanced security, and improved reliability may benefit from a different hosting option.

[Atlantic.Net](https://www.atlantic.net/) offers customers a wide range of cloud and dedicated hosting options, including high-performance [GPU servers](https://www.atlantic.net/gpu-server-hosting/). Organizations that outgrow shared hosting due to traffic growth, compliance requirements, or performance benchmarks can transition to dedicated or cloud infrastructure for predictable resource allocation and improved scalability. [Contact us](https://www.atlantic.net/about-us/corporate-contact/) to discover how we can elevate your web hosting experience and support your long-term infrastructure strategy.

 


---

# Hybrid Hosting in 2026: Bare Metal + Cloud Flexibility

> URL: https://www.atlantic.net/dedicated-server-hosting/hybrid-hosting-bare-metal-cloud-flexibility/ | Published: 2026-03-03 | Updated: 2026-02-28 | Author: Dr. Assad Abbas

[Hybrid hosting](https://www.atlantic.net/hipaa-compliant-hosting/hybrid-hosting-one-size-not-fit/) has become an essential model for many organizations in 2026, offering reassurance through reliable, flexible infrastructure. Modern businesses can feel secure knowing they can support critical systems while adapting to new projects and fluctuating demand, fostering confidence in their IT strategy.

Dedicated bare metal servers provide the consistent performance and low latency required for intensive tasks. Enterprise resource planning systems, customer databases, and transaction processing applications run reliably on isolated hardware. These environments offer predictable resource allocation and a controlled cost structure. Organizations reduce operational risk and meet strict compliance requirements without service interruptions.

Cloud resources support workloads that require temporary expansion or broader geographic reach. The cloud allows organizations to adjust capacity quickly without heavy investment in new hardware. Distributing workloads across various regions improves response times and provides a safety net if one location faces issues.

Secure network links connect these two environments under a unified management system. Critical workloads stay on bare metal for stable performance and control, while cloud resources handle tasks that require variable capacity.

## Bare Metal Reliability and Cloud Flexibility

Hybrid hosting combines dedicated infrastructure and cloud capacity, giving organizations a sense of control and empowerment. Matching specific use cases to the right providers demonstrates how hybrid hosting enables effective workload management and operational confidence.

Dedicated bare-metal servers handle workloads that require consistent I/O performance and low latency. For instance, databases perform best on bare metal because they benefit from hardware isolation, predictable resource allocation, and a stable cost structure.

Hybrid hosting connects dedicated hosting to cloud platforms via secure network links and unified management. Because of this, the dedicated core manages sensitive and performance-critical tasks, while the cloud edge handles variable workloads and provides operational flexibility. This setup helps organizations maintain both stability and adaptability.

## Modern Hybrid Hosting Architecture

Building a hybrid hosting environment means strategically splitting your workloads. You keep your most sensitive applications on dedicated hardware while pushing temporary or scaling tasks to the cloud. Blending bare-metal with cloud resources gives you stability and makes meeting strict compliance requirements—like HIPAA—much easier. Drawing on 30 years of hosting experience, we know architecting this setup requires significant time and investment, but it provides the exact control you need..

### Dedicated Core Component

Think of the core as your foundation. You run your primary databases and authentication systems on bare metal servers or private infrastructure. Dedicated hardware delivers predictable performance and true physical isolation. Centralizing control this way reduces operational risk and makes audit reporting straightforward.

### Cloud Edge Component

The edge handles geographic reach and raw compute capacity. Public cloud platforms run your application tiers and testing environments when you need to scale fast. This lets you react to sudden spikes in traffic without buying and racking new physical hardware. Relying on global cloud regions also improves latency and builds in redundancy.

### Networking and Secure Connectivity Component

Encrypted network links connect your core to the edge. Most setups rely on site-to-site VPNs or dedicated circuits to quickly move large volumes of data. To protect data in transit and remain compliant, all traffic must use modern encryption standards such as TLS 1.2 or TLS 1.3.

### Identity and Access Management Component

You lock down both environments using role-based access control and multi-factor authentication. A single identity provider controls permissions across your dedicated servers and cloud instances. Keeping this uniform prevents configuration mistakes and keeps you ready for regulatory audits.

### Monitoring and Logging Component

Centralized monitoring tracks metrics across your bare metal and cloud setups. Administrators need to watch CPU, memory, disk usage, and application latency. Logging security events, such as login attempts and firewall traffic, catches problems before they become serious outages.

### Backup and Disaster Recovery Component

Your recovery plan must cover both the core and the edge. Bare-metal databases require secure backups and replication to off-site cloud regions. Meanwhile, cloud workloads rely on routine snapshots. Testing these failovers regularly takes time and resources, but it is the only way to guarantee they will function during an actual disaster.

## How to Choose a Hybrid Hosting Partner

When evaluating a hybrid hosting provider, organizations should consider criteria such as security standards, compliance certifications, support quality, and integration capabilities. Clear evaluation metrics help decision-makers compare providers objectively and select the best fit for their specific workload and regulatory needs.

1. Hybrid Placement Approach
 Consider whether the provider supports a clear separation between dedicated infrastructure for critical workloads and public cloud for flexible workloads. The connection between these environments should be secure and consistent. This ensures both reliability and responsiveness across operations.
2. Compliance Posture
 Examine available SOC reports and confirm PCI DSS readiness if required. Proper documentation can also support internal audits. Consequently, organizations gain confidence that regulatory and security obligations are maintained with minimal disruption.
3. Managed Services
 Assess the scope of managed services, including backups, security monitoring, patching, and operational support. Providers with complete services can reduce day-to-day effort and help maintain stability across both core and cloud resources.
4. Support Quality
 Evaluate the availability and responsiveness of technical staff. Providers with experienced teams can provide guidance on performance, troubleshooting, and operational planning, helping ensure smoother hybrid adoption.
5. Pilot Deployment
 Testing a noncritical workload in the hybrid environment can offer practical insights into performance and integration. Observing system behavior in this controlled setting allows organizations to confirm suitability before wider deployment.

## Top Hybrid Hosting Providers in 2026

Below are the top hybrid hosting providers in 2026.

### Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

[Atlantic.Net](https://www.atlantic.net) supports hybrid hosting through a structure that combines stable dedicated servers with flexible cloud resources. This approach helps organizations place sensitive or predictable workloads on reliable bare-metal systems while using cloud capacity for variable workloads. The platform is designed for organizations that need a balance between long-term stability and on-demand scalability. The company operates SOC 1- and SOC 2-audited data centers and provides HIPAA-compliant hosting for environments that handle electronic Protected Health Information (ePHI (electronic Protected Health Information)).

Atlantic.Net support for planning hybrid architectures, along with managed services such as monitoring and security, helps organizations feel supported and confident. Their SOC audits and HIPAA compliance further reinforce trust in their ability to maintain security and regulatory standards.

#### *Features*

- Atlantic.Net offers a hybrid structure that links dedicated servers to cloud resources, helping organizations manage stable and variable workloads in a controlled manner.
- The platform supports HIPAA-compliant hosting with HIPAA Business Associate Agreement (BAA) coverage. Consequently, healthcare organizations can deploy hybrid architectures while meeting regulatory requirements.
- Managed services include backup management, firewall administration, monitoring, and security operations. As a result, organizations can maintain reliability without increasing internal operational pressure.
- The company operates SOC 1- and SOC 2-audited data centers. Therefore, hybrid deployments in regulated industries benefit from an established compliance foundation.

### Microsoft Azure

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

[Microsoft Azure](https://azure.microsoft.com/en-us) is a global cloud platform that supports hybrid hosting for organizations of all sizes. It offers a wide range of computing, storage, and networking services. Azure is known for its strong identity management tools and enterprise-grade compliance support. It also provides many managed services that help teams deploy applications quickly. Azure works well with dedicated servers and private infrastructure, which makes it suitable for hybrid environments. Many organizations use Azure for scaling, analytics, and application hosting.

#### *Features*

- Azure provides global cloud regions that support hybrid deployments. This helps organizations place workloads near users and maintain consistent performance across different locations.
- Microsoft Azure includes strong identity and access tools. These tools help organizations manage users, permissions, and authentication across both dedicated and cloud environments.
- Azure offers managed services for analytics, storage, and application hosting. These services help teams deploy new workloads quickly and reduce the need for manual configuration.
- Microsoft Azure supports compliance needs with a wide portfolio of certifications. This helps organizations meet regulatory requirements while using cloud resources in a hybrid model.

### Google Cloud

![](https://www.atlantic.net/wp-content/uploads/2025/06/google-logo.png)

[Google Cloud](https://cloud.google.com/) provides a modern platform for hybrid hosting, with strong networking, flexible compute options, and consistent global performance. The platform is widely used for analytics, AI workloads, and scalable applications. It integrates well with dedicated infrastructure, helping organizations distribute workloads across on‑premises systems and cloud resources. Many organizations select Google Cloud for data‑heavy tasks because it offers fast processing, reliable storage, and a structured set of tools for monitoring, logging, and identity management.

#### *Features*

- Google Cloud offers strong networking performance, which helps hybrid environments maintain stable connections between dedicated systems and cloud workloads across different regions.
- The platform includes advanced analytics and AI tools, enabling teams to process large datasets and run machine learning tasks without building new infrastructure.
- Google Cloud provides secure compute and storage services that integrate smoothly with dedicated hardware, supporting structured workload placement in hybrid environments.
- The platform includes hybrid identity and logging tools, which help organizations maintain consistent access control and monitoring across both dedicated and cloud environments.

### HostGator

![](https://www.atlantic.net/wp-content/uploads/2025/08/Hostgator-logo.png)

[HostGator](http://www.hostgator.com) provides cloud hosting solutions that are simple to manage and suitable for small and mid-sized organizations. The platform offers scalable environments for websites and applications, supported by an easy control panel and a straightforward setup process. It also includes support options that help teams manage routine tasks. HostGator can be used in hybrid models where core components, such as databases or internal systems, remain on dedicated hardware. At the same time, the web tier or temporary workloads operate in the cloud.

#### *Features*

- HostGator offers cloud hosting with simple management tools that help small teams deploy applications and maintain them without complex technical steps.
- The platform supports scalable environments that adjust to traffic changes and help organizations handle peak periods without purchasing new hardware.
- HostGator includes monitoring and basic security features that contribute to stable performance and reduce the risk of downtime in hybrid setups.
- The platform offers affordable pricing options, helping growing organizations adopt hybrid hosting without putting pressure on their budgets.

### GoDaddy

![](https://www.atlantic.net/wp-content/uploads/2025/04/godaddy-logo.png)

[GoDaddy](http://www.godaddy.com) provides hosting and cloud services that support small businesses and growing organizations. The platform includes simple tools for managing websites, applications, and cloud workloads, supported by a user-friendly interface and global assistance. It also offers scalable cloud resources for hybrid environments, where sensitive workloads remain on dedicated servers while public cloud resources handle variable tasks. Many organizations adopt this structure to maintain cost control and flexible scaling.

#### *Features*

- GoDaddy provides cloud hosting that supports hybrid models, which helps small teams run web applications in the cloud while keeping sensitive data on dedicated hardware.
- The platform includes simple management tools that help teams deploy and maintain applications without advanced technical skills.
- GoDaddy offers scalable compute and storage resources that support variable workloads and seasonal traffic in hybrid environments.
- The platform includes global support and monitoring tools that help ensure stable operations and reduce downtime across both dedicated and cloud components.

### Kinsta

![](https://www.atlantic.net/wp-content/uploads/2026/02/Kinsta_logo.png)

[Kinsta](http://www.kinsta.com) provides managed cloud hosting designed for modern web applications, supported by high-quality infrastructure and global data centers. The platform is recognized for fast loading times, reliable uptime, and a structured set of monitoring and optimization tools. It works well in hybrid environments where the application front end operates in the cloud while databases or sensitive workloads remain on dedicated hardware. This arrangement supports both performance expectations and compliance needs for organizations that require a clear separation between components.

#### *Features*

- Kinsta delivers managed cloud hosting with strong performance, which helps organizations run web applications smoothly and maintain fast response times.
- The platform includes global data centers that help deliver content quickly to users and support hybrid deployments across different regions.
- Kinsta offers monitoring, security, and optimization tools that help maintain application health and reduce performance issues in hybrid environments.
- The platform provides managed support to help teams maintain hybrid hosting setups without requiring deep technical knowledge.

## Hybrid Hosting Use Case Mapping

Hybrid hosting in 2026 supports a wide range of operational requirements. However, not every provider fits every scenario. Because workloads vary in sensitivity, scale, and performance demand, selecting a provider requires alignment with specific business priorities. Therefore, mapping use cases to providers offers clearer guidance than reviewing features in isolation. As a result, organizations can make decisions that connect technical needs with long-term strategy.

When compliance and controlled infrastructure are the primary concerns, Atlantic.Net is a more suitable option. The platform offers dedicated infrastructure, audited data centers, and structured hybrid placement. Consequently, sensitive workloads can remain on stable bare-metal systems, while less-critical components operate in connected cloud environments. This balance supports regulatory requirements without sacrificing flexibility.

In contrast, when global scale and enterprise identity integration are more important, Microsoft Azure becomes relevant. Because Azure operates across a broad set of geographic regions and provides mature identity management capabilities, organizations can maintain centralized access control across distributed workloads. Therefore, enterprises with complex identity structures benefit from a hybrid environment that connects securely across locations.

Similarly, data-intensive or AI-focused workloads often align well with Google Cloud. Its networking performance and analytics services support high-volume processing, while integration with machine learning tools strengthens advanced workloads. As a result, organizations managing large datasets can extend analytics tasks into the cloud while maintaining controlled systems where necessary.

For smaller teams seeking simplicity, HostGator or GoDaddy may be the right choice. Both platforms provide straightforward management interfaces and scalable cloud environments. Consequently, organizations with limited internal resources can establish a basic hybrid structure without excessive complexity.

When managed performance for Web applications is the focus, Kinsta is a suitable option. The platform emphasizes optimized cloud hosting, integrated monitoring, and global delivery capabilities. Therefore, web-focused organizations can maintain performance consistency while benefiting from scalable infrastructure.

## Hybrid Hosting Decision Matrix

A structured decision matrix can help organizations compare hybrid hosting providers based on criteria that influence reliability, flexibility, and operational planning. Instead of repeating features, the matrix highlights how each provider aligns with specific priorities in 2026.

| **Criteria** | **Atlantic.Net** | **Microsoft Azure** | **Google Cloud** | **HostGator** | **GoDaddy** | **Kinsta** |
| --- | --- | --- | --- | --- | --- | --- |
| **Compliance Strength** | Strong | Strong | Moderate | Basic | Basic | Moderate |
| **Global Reach** | Moderate | Extensive | Extensive | Limited | Moderate | Moderate |
| **Managed Services Depth** | High | High | High | Basic | Basic | Moderate |
| **Ease of Use** | Moderate | Moderate | Moderate | High | High | High |
| **Cost Control** | Predictable | Variable | Variable | Affordable | Affordable | Moderate |
| **Suitability for Small Orgs** | Moderate | Moderate | Moderate | High | High | High |
| **Hybrid Integration Maturity** | Strong | Strong | Strong | Basic | Basic | Moderate |

## The Bottom Line

Hybrid hosting in 2026 gives organizations a practical way to meet both stable and changing needs. Bare metal offers steady performance for sensitive workloads, while cloud platforms add the flexibility required for new projects and sudden demand. Because of this combination, organizations can keep their core systems reliable and still respond quickly when conditions change.

Hybrid models help organizations manage resources more efficiently, since each workload can be placed where it works best. When these environments mature over time, organizations gain better control, stronger security, and smoother coordination across locations. Consequently, hybrid hosting supports steady progress and helps organizations prepare for future technical and operational challenges.

 


---

# Dedicated Server Cost in 2026: Pricing & TCO Guide

> URL: https://www.atlantic.net/dedicated-server-hosting/dedicated-server-cost-pricing-guide-tco/ | Published: 2026-03-04 | Updated: 2026-06-23 | Author: Dr. Assad Abbas

[Dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) are physical machines used by a single client. They do not share CPU, memory, or storage with others, giving users full control over the hardware. This exclusive access provides stable performance and avoids problems caused by other users on the same machine. For these reasons, many organizations carefully study the cost of dedicated servers to ensure predictable spending and clear long-term budgeting.

Cost stability is an important consideration in 2026, as cloud costs can vary month-to-month depending on usage. Data transfer, storage growth, and [on-demand compute](https://www.atlantic.net/life-sciences-pharma-biotech/on-demand-computing-advantages/) can unexpectedly increase expenses. Additionally, AI and high-performance workloads often require extra resources, and energy prices differ across regions. Consequently, teams prefer hosting options with predictable monthly pricing. Dedicated servers address this need effectively, as costs are determined by the chosen configuration and contract, rather than short-term spikes in usage.

It is important to understand the Total Cost of Ownership (TCO) when comparing hosting options, since the base monthly price represents only a portion of the overall cost. Hardware, bandwidth, storage, and support all contribute to the total expense. This article examines dedicated server pricing in 2026, identifies the factors that influence costs, and outlines strategies to optimize expenses while maintaining performance

## What Dedicated Servers Are and Who They Are For

A dedicated server is a [single-tenant](https://www.atlantic.net/dedicated-server-hosting/achieving-unparalleled-security-with-single-tenant-dedicated-hosting/) physical machine that provides full access to CPU, RAM, storage, and network ports. Since no other customer uses the same hardware, this isolation improves performance and reliability. It also gives more control over software, security, and resource allocation. By contrast, cloud virtual machines share underlying hardware among multiple users, which can result in performance variation during peak periods.

A wide range of organizations use dedicated hosting:

- **SaaS Platforms:** Rely on dedicated infrastructure to maintain stable application workloads.
- **E-commerce Websites:** Benefit from dedicated resources during peak traffic hours to prevent slowdowns.
- **Enterprises:** Value the predictable monthly cost when transitioning from on-premises environments.
- **AI and Analytics Teams:** Frequently use [GPU servers](https://www.atlantic.net/gpu-server-hosting/) for long-running computational tasks.

Organizations often choose dedicated servers for stable performance and predictable costs, which helps with budgeting. Hardware is reserved exclusively for a single client; therefore, utilization tends to be higher and more consistent. Dedicated servers support long-term planning by providing clear visibility into expenses for teams managing complex workloads. This model is well-suited to organizations that need both performance and financial predictability.

## Dedicated Server TCO and Cloud Economic Comparison

A complete understanding of dedicated server costs requires more than the base monthly price. A TCO model includes bandwidth usage, IPv4 and [IPv6](https://www.atlantic.net/vps-hosting/what-you-should-know-before-enabling-ipv6/) allocations, GPU upgrades, storage expansion, and support tiers. Each of these factors contributes to the total monthly expense. Therefore, using a TCO perspective provides a more accurate view of the long-term financial impact of hosting decisions.

It is also important to examine costs over several years. Dedicated hardware prices remain stable for periods of 12 to 36 months, which protects budgets from the unpredictable consumption charges that are common in public cloud environments. As a result, dedicated servers offer predictable spending for workloads that run continuously.

Dedicated servers follow a fixed OpEx model, where costs do not vary with CPU or RAM usage. Although initial entry costs may be lower, total spending can rise quickly when workloads run at high utilization. Continuous database operations, analytics pipelines, and AI training often result in spikes in costs due to data transfer fees, sustained compute usage, and GPU premiums.

The tables below show typical pricing ranges in 2026. These values reflect common industry patterns and provide a clear comparison between dedicated servers and [cloud virtual machines](https://www.atlantic.net/cloud-platform/cloud-virtual-machine-flexible-cost-effective-workloads/) under continuous use.

**Table 1:** Typical 2026 Dedicated Server Pricing

| **Server Tier** | **Monthly Range** | **Ideal Workload** |
| --- | --- | --- |
| **Entry-Level** | $50–$120 | Web hosting, staging, small VPNs |
| **Mid-Tier Production** | $150–$350 | E-commerce, application backends, SaaS |
| **High-Performance** | $350–$700 | Databases, virtualization, analytics |
| **GPU-Accelerated** | $500–$1,500+ | AI inference, rendering, model training |

**Table 2:** Typical Cloud VM Pricing for 24/7 Usage

| **Cloud VM Tier** | **Monthly Range** | **Notes** |
| --- | --- | --- |
| **General Purpose** | $80–$150 | Base price is lower, bandwidth is extra |
| **Compute Optimized** | $200–$450 | Higher cost for high-frequency cores |
| **Memory Optimized** | $500–$900 | High cost per GB of RAM |
| **Accelerated (GPU)** | $1,200–$3,000+ | Significant markup for GPU hardware |

These trends show a consistent pattern. Dedicated servers generally offer superior price-to-performance for workloads that run continuously, while cloud platforms are better suited for tasks with variable demand or that grow unpredictably. As a result, many organizations adopt a hybrid strategy, with stable workloads running on dedicated hardware to control costs and seasonal or fluctuating workloads using cloud resources when required. This strategy ensures predictable spending without sacrificing operational flexibility.

## What Influences Dedicated Server Pricing

Dedicated server pricing depends on several technical and operational factors:

- **Hardware Specifications:** Newer CPU generations cost more, and higher core counts or strong single-core performance increase the total. Additionally, RAM capacity directly affects application performance, and [NVMe storage](https://www.atlantic.net/dedicated-server-hosting/whats-the-difference-between-hdds-sata-ssds-and-nvme-ssds/) carries a premium over [SATA](https://www.atlantic.net/dedicated-server-hosting/whats-the-difference-between-hdds-sata-ssds-and-nvme-ssds/) due to higher throughput. GPU inclusions serve as premium components that significantly increase the base price.
- **Power Consumption:** Entry-level servers typically use 150 to 250 watts, whereas GPU nodes may exceed 800 watts under load. While standard leases bundle power into the monthly fee, colocation environments treat this energy use as a direct, recurring cost.
- **Data Center Efficiency**: Facilities assess operations through Power Usage Effectiveness (PUE). As electricity prices vary by region, the monthly power cost depends on wattage, local rates, and facility overhead.
- **Bandwidth Requirements:** Metered plans charge per terabyte of data transferred, while unmetered plans offer a fixed monthly rate. High-traffic platforms often view bandwidth as a large portion of their operating budget.
- **Geographic Location:** Regions with higher energy and real estate costs generally incur higher hosting rates. Deploying across multiple regions increases total costs, even though it enhances resilience and availability.

## Managed and Unmanaged Dedicated Servers

[Managed hosting](https://www.atlantic.net/dedicated-server-hosting/what-is-managed-hosting/) increases the base price because it includes operational support. This support often covers OS patching, monitoring, security hardening, backup management, and [incident response](https://www.atlantic.net/pci-compliant-hosting/incident-response-in-pci-dss/). This service reduces the workload on internal staff and helps keep operations running smoothly. It also improves reliability, since specialists handle routine tasks and address issues before they affect service quality.

Unmanaged servers follow a different approach. They cost less because the provider only supplies the hardware and network environment. Unmanaged servers are suitable for organizations with strong internal technical expertise or for environments with low change frequency. However, they can increase operational risk if internal expertise is limited. For workloads that require high uptime, unmanaged servers place full responsibility for maintenance and troubleshooting on the organization. As a result, internal labor costs may rise, as staff must manage all tasks, from updates to incident resolution.

In the end, the choice between managed and unmanaged hosting depends on an organization’s expertise, workload stability, and the level of operational involvement it is prepared to maintain.

## Security, Protection, and Hidden Costs

Security features and administrative add-ons play a major role in the overall cost of dedicated hosting. Several hidden costs are easy to overlook during initial planning:

- **Security Upgrades:** Basic [DDoS protection](https://www.atlantic.net/vps-hosting/what-is-a-ddos-and-how-do-we-prevent-our-business-from-being-attacked/) is often included, but higher levels of filtering require additional investment. Firewalls, intrusion detection tools, and proper encryption configurations (using TLS 1.2 or 1.3) increase management overhead and monthly expenses.
- **Setup and Migration:** Setup fees may apply for custom hardware. Migration work can require professional assistance, especially for large datasets.
- Software Licensing: Windows Server, SQL Server, and commercial control panels carry recurring monthly fees.
- **Backup and Disaster Recovery:** Snapshot retention, off-site replication, and periodic restore testing incur extra charges.
- **SLA Enhancements:** Upgrading your Service Level Agreement (SLA) for higher uptime guarantees or faster response times will increase baseline costs.

## Cost Optimization Strategies and Practical Cost Planning

Cost optimization is an important part of dedicated hosting because infrastructure decisions affect long-term financial stability. Hardware, licensing, bandwidth, and power all contribute to the total expense.

A practical strategy usually starts with right-sizing the hardware. When server resources exceed actual workload demand, organizations pay more each month without real performance benefits. By matching infrastructure to real usage patterns, unnecessary spending can be avoided.

Scaling design also has a financial impact. Vertical scaling is suitable for applications that need stronger individual components. In contrast, horizontal scaling is appropriate for systems that grow by adding more nodes over time. Many organizations now use bare-metal Kubernetes to manage this expansion, keeping infrastructure costs more predictable.

Contract planning is another key element. Multi-year agreements often reduce the effective monthly rate because providers can plan capacity with more certainty. Prepayment options support predictable budgeting and lower total spending. Simultaneously, continuous network monitoring helps detect bandwidth growth early, and CDN offloading can reduce origin egress traffic.

Licensing has become a major cost factor in recent years. Changes in virtualization pricing models have increased fees for commercial hypervisors. Therefore, many organizations evaluate open-source platforms such as Proxmox VE and XCP-ng to reduce recurring software costs. However, compliance requirements or enterprise workloads may still require commercial operating systems or database engines.

To combine these elements into practical planning, organizations often use a total cost model:

TCO = + Estimated Egress + Licensing and Compliance Fees + Setup or Migration Costs

When this formula is applied at the beginning of infrastructure planning, it provides a clearer long-term financial estimate, ensuring that cost optimization becomes a structured and informed strategy rather than a reactive adjustment.

## How We Approach Dedicated Server Cost at Atlantic.Net

At Atlantic.Net, we focus on transparent and predictable pricing because cost clarity is essential for long-term planning. Our approach avoids unexpected bandwidth charges and reduces the risk of unplanned expenses. We also help organizations understand the items that often become hidden costs in dedicated hosting, such as licensing, egress usage, and support requirements.

Our hardware options include modern CPU platforms, NVMe storage, and GPU configurations. These choices support a wide range of workloads, from small Web applications to high-performance analytics. We offer both managed and unmanaged environments. Managed hosting supports organizations that prefer operational assistance, while unmanaged hosting suits teams that maintain their own systems. Support levels are tailored to each organization’s needs to keep costs and responsibilities balanced.

We also help clients evaluate their complete TCO. This includes guidance on hardware selection, bandwidth planning, licensing considerations, and long-term budgeting. By doing so, organizations gain a clearer understanding of their expected cost over the full lifecycle of their infrastructure. We aim to provide stable, predictable, and transparent pricing for dedicated hosting.

## Frequently Asked Questions

**What is the average dedicated server cost in 2026?**

Most configurations range from $60 to $700 per month, depending on hardware and bandwidth needs. GPU servers cost more because they use premium components.

**Is dedicated hosting cheaper than cloud?**

It is usually cheaper for steady workloads. Cloud platforms become expensive at high utilization levels because costs increase with continuous resource usage and data transfer.

**What affects bandwidth pricing?**

Traffic volume, port speed, and the billing model. Metered, unmetered, and 95th-percentile plans each influence cost differently.

**How do I calculate TCO?**

Add all monthly costs and multiply by the contract duration. Include hardware, bandwidth, power, licensing, and support to get a complete estimate.

**Are GPU servers worth the cost?**

They are valuable for workloads that require parallel processing, such as analytics, rendering, and machine learning. Their value increases when utilization remains consistently high.

**How long does provisioning take?**

Most standard servers are ready within a few hours. Custom hardware or specialized configurations may require additional time.


---

# Leading AI in Healthcare Providers in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/leading-ai-in-healthcare-providers/ | Published: 2026-03-04 | Updated: 2026-03-18 | Author: Dr. Rachael Bailey

Clinical AI has become a regular part of medical practice, moving beyond experimental trials. By 2026, healthcare providers will use agentic systems to diagnose patients more accurately and streamline administrative tasks, while keeping patient information safe. Here are some organizations at the forefront of medical-grade AI and secure data management.

AI is driving innovation across the healthcare sector. As technology advances, AI is increasingly integrated into clinical care, diagnostics, and operational processes, transforming how healthcare providers deliver care.

In 2026, we are seeing a clear shift from experimenting with AI to implementing it. Healthcare providers are embracing AI-driven healthcare innovation and moving beyond pilot projects to adopt AI tools at scale. The emphasis has shifted toward measurable clinical ROI, ambient documentation tools that reduce provider burnout, and predictive analytics that prevent costly hospitalizations.

This article highlights leading AI in healthcare providers at the forefront of this transformation. These providers are using AI strategically to enhance their services, streamline their workflow, and deliver more responsive, data-driven care.
 more

## How Do Healthcare Providers Use Artificial Intelligence to Enhance Patient Care?

The healthcare industry employs AI technologies, such as natural language processing, deep learning, and machine learning, to enhance efficiency, improve diagnostics, and streamline patient care. These tools enable healthcare professionals to better analyze and organize patient data, support more accurate diagnoses, and deliver personalized treatment plans tailored to individual needs.

Here are some of the key ways that healthcare organizations are implementing AI tools across their services:

### Improving Medical Diagnosis and Disease Detection

AI algorithms, particularly deep learning models, are revolutionizing medical diagnosis and disease detection. By meticulously analyzing medical images such as X-rays, MRIs, and mammograms, as well as medical history records, these technologies help to enhance diagnostic accuracy. This advancement is particularly important in conditions such as breast cancer, Alzheimer’s disease, and cardiovascular conditions, where early-stage detection is paramount to achieving better health outcomes.

### Streamlining Electronic Health Records and Reducing Administrative Burdens

AI systems automate repetitive administrative tasks such as health data entry, leading to enhanced accuracy and freeing up clinicians’ valuable time for patient-centered activities. These tools also help to manage and extract crucial information from complex clinical data, providing actionable insights for diagnosis and treatment.

### Embrace Personalized Medicine

Through analyzing patient-specific data, AI supports precision medicine, allowing healthcare providers to tailor treatments based on an individual’s unique health concerns, as well as their biomarker profiles, lifestyle, environmental factors, and genetics.

### Support Population Health Management

As AI tools analyze data at scale, they can be used to track health trends, monitor outbreaks, and support decision-making for public health strategies. These insights are essential to organizations such as the World Health Organization that help to manage the health of large populations.

### Boost Patient Engagement with Virtual Assistants

To significantly boost patient engagement and experience, healthcare providers take advantage of virtual health assistants. These can answer routine questions, help with appointment scheduling and remind patients to take their medication.

### Reduce Healthcare Costs

By optimizing efficiency, minimizing waste and errors, and optimizing resource allocation, AI technologies continue to reduce costs across the whole of the healthcare sector.

### Accelerate Drug Discovery and Optimize Clinical Trials

In addition to transforming day-to-day medicine, AI models are also revolutionizing the drug development process and significantly speeding up clinical trials. AI excels at identifying novel drug targets by pinpointing critical biological pathways and proteins that can be precisely manipulated for therapeutic benefit. When it comes to clinical trials, AI helps to optimize protocol design, streamline data collection, and enhance analysis, significantly speeding up the trial process and reducing costs.

## Top Companies Using AI Technology to Reshape Health Care in 2025

So, which healthcare organizations are leading the way? Here are some of the top providers embracing AI to deliver smarter, faster, and more effective care in 2025:

![](https://www.atlantic.net/wp-content/uploads/2025/06/tempus-logo.png)

### #1: Tempus

**About Tempus:**

Tempus is a leader in AI-powered precision medicine, with a strong focus on oncology, neurology, psychiatry, cardiology, dermatology, and radiology. Their platform uses real-world clinical, molecular, and genomic data to allow healthcare professionals to diagnose conditions with more accuracy and devise personalized treatment recommendations that are tailored to each patient’s unique profile.

Here’s the Tempus analytics dashboard, built to help you interpret complex medical data, track outcomes, and support informed decision-making.
 ![Tempus](https://www.atlantic.net/wp-content/uploads/2026/03/Tempus.jpeg)
 Image Source: Tempus

**Advantages:**

- **Precision Oncology:** Analyzes tumor genomic data to identify mutations and biomarkers, guiding targeted therapies.
- **complete Data Integration:** Combines clinical, molecular, and patient health records for deeper insights.
- **Drug Development & Clinical Trials:** Uses AI, alongside a vast library of clinical data, to identify novel drug targets and optimize the drug development process.
- **Scalable Platform:** Enables healthcare providers to apply precision medicine across various specialties.

**Disadvantages:**

- **Implementation Complexity:** Integrating advanced AI tools into existing healthcare systems may require significant resources and training.
- **Data Privacy Concerns:** Handling extensive genomic and clinical data necessitates stringent compliance with privacy regulations.

**Target Audience:**

Healthcare providers and research institutions seeking to integrate AI-driven precision medicine into everyday healthcare delivery, particularly within the field of oncology and other complex specialties.

![](https://www.atlantic.net/wp-content/uploads/2025/06/cera-logo.png)

### #2: Cera

**About Cera:**

Cera is a UK-based healthcare provider that is transforming home care through the use of AI technology. It uses machine learning and data analytics to monitor patients remotely, anticipate health deteriorations and potential health risks, and automate their care planning, with the aim of reducing hospitalizations in patients with chronic diseases.

**Advantages:**

- **Proactive and Preventative Care:** Cera’s deep learning algorithms help to flag early signs of illness and predict potential health risks or deterioration, enabling timely intervention and reducing hospital admissions.
- **Remote Patient Monitoring:** The app-based platform uses AI tools to analyze real-time health data from in-patient home visits, which includes things like heart rate, temperature and blood pressure, as well as other health indicators such as sleep patterns and activity levels. This data can then be used to detect whether a patient’s condition is worsening so that health professionals can respond appropriately.
- **Enhanced Medication Management:** The technology can be used to enhance medication adherence by sending reminders and tracking intake, significantly reducing errors and improving patient safety at home.
- **Support of Caregivers:** Cera automates administrative tasks, including rostering and care documentation, freeing up staff to focus on delivering hands-on care.

**Disadvantages:**

- **Integration Challenges:** Cera relies on high-quality, consistent data input from both carers and their patients, which can be difficult to standardize at scale.
- **Maintaining Human Touch:** Cera’s extensive use of AI and automation, while efficient, requires careful management to ensure that the essential human element of compassionate care isn’t diminished, especially for vulnerable patients.
- **Data Privacy & Trust:** Handling sensitive health data in a highly integrated system requires strict cybersecurity and transparent data usage policies.

**Target Audience:**

Cera’s platform is ideal for national health systems, local authorities, and private care providers who are looking to use AI to modernize home healthcare services and to ease pressure on hospitals.

![](https://www.atlantic.net/wp-content/uploads/2025/06/pathai-logo.png)

### #3: PathAI

**About PathAI:**

PathAI, which is a Boston-based company, uses AI-powered technology to transform the workflow within biopharma and pathology laboratories. By applying deep learning to vast datasets of digital pathology images, PathAI is enabling more precise disease diagnosis, accelerating drug development, and uncovering novel biomarkers, ultimately pushing the boundaries of precision medicine in areas such as oncology and inflammatory diseases to improve patient outcomes.

Take a look at the PathAI analytics interface, designed to help you visualize slide volume, measure usage percentage, and manage lab data efficiently.
 ![PathAI](https://www.atlantic.net/wp-content/uploads/2026/03/PathAI.webp)
 Image Source: PathAI

**Advantages:**

- **Improve Diagnostic Accuracy:** PathAI’s deep learning models have demonstrated high accuracy in detecting malignancies and other diseases on pathology slides, often matching or surpassing the performance of experienced pathologists.
- **Optimize Workflow:** AI tools such as TumorDetect automate tumor assessment and quantification, enabling pathologists to focus on the most critical cases and reduce their turnaround times.
- **smooth Integration:** PathAI’s technology can integrate seamlessly into existing lab software, without the need for major system overhauls or lengthy onboarding.
- **Continuous Learning:** PathAI’s machine learning algorithms continuously improve over time, adapting to new data so that they align with evolving diagnostic standards.

**Disadvantages:**

- **Initial Setup Complexity:** Implementing PathAI’s solutions may require significant time and resources for setup and training.
- **Dependence on Data Quality:** The accuracy of any analysis is highly dependent on the quality of data input into the system, so if you have poor-quality pathology slides, then this can affect performance.
- **Cost Considerations:** The platform may be expensive for smaller laboratories or institutions with limited budgets.

**Target Audience:**

- Pathologists looking to improve the efficiency and accuracy of their work
- Large laboratories and medical institutions with high diagnostic workloads
- Researchers looking for advanced AI tools to aid in pathology and medical research

![](https://www.atlantic.net/wp-content/uploads/2025/06/butterfly-logo.png)

### #4: Butterfly Network

**About Butterfly Network:**

Butterfly Network has developed an AI-powered handheld ultrasound device that connects to a smartphone, bringing high-quality imaging directly to the point of care. This portable ultrasound system is practical for use even in diverse settings, such as remote communities, making diagnostic imaging more accessible than ever. Their devices make use of advanced AI algorithms to automate image capture and analysis, including rapid and accurate B-line counting from a six-second lung ultrasound clip (used in lung ultrasounds to assess fluid build-up), enhancing on-the-spot assessment of lung conditions.

Take a look at the Butterfly Network interface, designed to help you scan patients anywhere, document findings, and manage imaging workflows.
 ![Butterfly Network](https://www.atlantic.net/wp-content/uploads/2026/03/Butterfly-Network.png)
 Image Source: Butterfly Network

**Advantages:**

- **More Precise Disease Diagnosis:** Real-time, AI-assisted image analysis enhances diagnostic accuracy.
- **Improved Accessibility to Ultrasound Imaging:** Portable and smartphone-compatible, enabling versatile use in diverse settings.
- **Simplified Imaging Workflow:** Automates complex imaging tasks, reducing operator dependency.

**Disadvantages:**

- **User Training Needed:** While AI assists with image acquisition, proficient interpretation of the ultrasound images still requires significant user training and clinical experience.
- **Reliance on Good Connectivity:** Optimal functionality of the devices and integration of data rely heavily on stable smartphone connectivity, which can be a limitation in extremely remote or underdeveloped areas.
- **Diagnostic Scope Limitations:** Despite its advancements, the handheld device may not fully replace the advanced capabilities or specialized probes of traditional ultrasound systems for certain complex or in-depth diagnostic needs.

**Target Audience:**

- Healthcare providers needing mobile imaging solutions
- Clinics and emergency services in remote regions
- Medical professionals seeking AI solutions to improve ultrasound diagnostics

![](https://www.atlantic.net/wp-content/uploads/2025/06/xpertdox-logo.png)

### #5. XpertDox

**About XpertDox:**

Based in the U.S, XpertDox uses AI to automate medical coding, helping healthcare providers to speed up billing and reduce errors. Their flagship tool, XpertCoding, automatically pulls the right billing codes from clinical documents, helping hospitals and clinics to speed things up, cut down on admin errors, and get reimbursed faster.

Here’s the XpertDox business intelligence dashboard, built to help you analyze healthcare data, optimize coding accuracy, and improve financial outcomes.
 ![XpertDox](https://www.atlantic.net/wp-content/uploads/2026/03/XpertDox.png)
 Image Source: XpertDox

**Advantages:**

- **Fast and Efficient:** XpertCoding processes and submits medical claims within 24 hours, reducing manual effort and accelerating the billing process. It also automates approximately 94% of claims without human intervention, reducing the need for manual coding.
- **High Accuracy:** The platform achieves over 98% coding accuracy, minimizing claim denials and enhancing compliance.
- **smooth EHR Integration:** The XpertCoding platform can seamlessly connect with any existing EHR system.
- **Business Intelligence Platform:** Their Business Intelligence Platform provides real-time analytics, audit trails, and Clinical Documentation Improvement (CDI) feedback to optimize operational efficiency.

**Disadvantages:**

- **Initial Setup Requirements:** While integration is streamlined, initial setup and training may require dedicated resources to ensure optimal utilization.
- **Reliance on Accurate Data:** The effectiveness of the system relies heavily on the clarity and completeness of the clinical data and medical records that are input. Any incomplete notes or ambiguity can pose challenges.

**Target Audience:**

Hospitals, large multi-specialty clinics, healthcare systems, and third-party billing companies that are focused on optimizing their revenue cycle management.

![](https://www.atlantic.net/wp-content/uploads/2025/06/abridge-logo.png)

### #6: Abridge

#### About Abridge:

Abridge is a healthcare AI company that uses ambient listening technology to turn clinician and patient conversations into structured clinical notes. With advanced speech recognition and natural language processing, Abridge acts as an AI scribe to save time on documentation and help prevent provider burnout. The platform connects with major EHR systems, so clinicians can review and sign notes without writing them.

#### Advantages:

- **Ambient Documentation**: Records conversations in real time and automatically creates structured clinical notes.
- **EHR Integration**: Connects directly with existing electronic health record systems.
- **Burnout Reduction**: Cuts down on after-hours charting and administrative work.
- Clinical ROI Focus: Shows clear reductions in documentation time and boosts clinician satisfaction.

#### Disadvantages:

**Workflow Adjustment**: Clinicians might need some time to get used to the new documentation processes.

**Accuracy Dependence**: The system’s performance relies on clear audio and the clinical setting.

**Implementation Costs**: Rolling out the system may need IT support and staff training.

#### Compliance Corner:

- Operates within HIPAA-compliant environments when processing protected health information (PHI).
- Supports GDPR-aligned data protection practices for international healthcare organizations.
- Designed as clinical documentation support software and not classified as a medical device under current FDA frameworks.

#### Target Audience:

- Health systems seeking to reduce provider burnout
- Multi-specialty clinics aiming to improve documentation efficiency
- Organizations focused on measurable administrative ROI

## ![](https://www.atlantic.net/wp-content/uploads/2025/06/vis-ai-logo.png)

### #7: Viz.ai

#### About Viz.ai:

Viz.ai creates AI-powered tools to diagnose and coordinate care for urgent conditions such as stroke and heart disease. The platform uses machine learning to analyze medical images in real time and automatically alerts specialists to important findings. With predictive analytics and automated notifications, Viz.ai helps teams make faster treatment decisions and improve patient outcomes.

Let’s explore the Viz.ai platform, where you can analyze medical imaging, collaborate with care teams, and accelerate clinical decision-making.
 ![Viz.ai](https://www.atlantic.net/wp-content/uploads/2026/03/Viz.ai-.png)
 Image Source: Viz.ai

#### Advantages:

- **Real-Time Imaging Analysis**: Quickly spots large vessel blockages and other important findings.
- **Automated Care Coordination**: Instantly sends secure mobile alerts to specialists.
- **Improved TreaImproved Treatment Timelines**: Helps shorten the time from arrival to treatment in emergencies.Performance Tracking: Provides analytics dashboards to measure treatment speed and outcomes.

#### Disadvantages:

- **Hospital Integration Required**: Must be connected to PACS and imaging workflows.
- **Dependence on Imaging Quality**: The system’s accuracy relies on having high-quality diagnostic scans.
- **Infrastructure Investment**: Setting up the system may need teamwork between emergency and speciality departments.

#### Compliance Corner:

- Certain Viz.ai solutions have received FDA clearance for clinical use in the United States.
- Operates within HIPAA-compliant environments when processing protected health information (PHI).
- Supports secure data transmission with in-transit and at-rest encryption, along with audit logging and access controls.

#### Target Audience:

- Stroke centers and complete care hospitals
- Emergency departments seeking faster diagnostic workflows
- Health systems prioritizing time-to-treatment performance metrics

## Artificial Intelligence in Healthcare: What’s Next?

The providers leading in 2026 share three traits: measurable ROI, workflow-native integration, and regulatory readiness. AI has already made a huge impact on healthcare, from improving diagnostics and speeding up drug discovery to personalizing patient care, but we’re only just scratching the surface. The next phase centers on agentic clinical systems that not only analyze data but also actively assist clinicians with documentation, risk prediction, and real-time decision support.

As AI tools become more advanced and datasets more diverse, the potential for AI to transform everything from mental health care to surgical planning is enormous. Health systems are prioritizing solutions that demonstrate measurable clinical ROI, reduce provider burnout, and integrate directly into existing EHR and imaging workflows. As we progress, we can expect to see even more collaboration between AI companies and healthcare providers, as well as stronger safeguards to tackle data security. Regulatory oversight, including FDA review pathways and global data protection standards, will continue shaping how quickly AI tools move from pilot programs to enterprise-wide deployment.

Do you need a reliable way to build and scale your AI healthtech application? [Atlantic.Net](https://www.atlantic.net) offers fast, secure GPU cloud hosting, ideal for building, training, and deploying your AI models.


---

# Bare Metal Cloud vs. Traditional Dedicated Servers: A Guide for AI Workloads

> URL: https://www.atlantic.net/dedicated-server-hosting/bare-metal-cloud-vs-traditional-dedicated-servers-a-guide-for-ai-workloads/ | Published: 2026-03-04 | Updated: 2026-05-04 | Author: Robert Agar

## Executive Summary

Companies running AI workloads, such as training machine learning models or computer vision, require a powerful computing environment utilizing servers equipped with advanced graphics processing units (GPUs). Many businesses lack the financial and technical resources to implement and maintain the necessary infrastructure in an on-premises data center, creating a significant competitive disadvantage. Fortunately, cloud service providers (CSPs) offer alternative GPU cloud services for AI hosting infrastructure, enabling any company to leverage the benefits of high-performance computing.

Bare-metal cloud and traditional cloud-based dedicated servers are two hosting options that provide customers with single-tenant access to physical hardware. They can both address the performance needs of AI workloads, depending on the server’s processors. However, there are key differences in the way customers access, manage, and pay for their hardware.

## Introduction

AI infrastructure decisions increasingly determine product velocity, model quality, and unit economics. Teams that choose an environment that cannot keep GPUs fed with data, cannot scale experiments quickly, or cannot deliver stable inference latency may end up paying premium prices for idle capacity. In practice, many organizations are not deciding between “fast” and “slow” hardware; they are deciding between operating models, automation maturity, and cost-control mechanisms that determine how efficiently high-value AI compute is used.

This guide focuses on the most common single-tenant paths to AI compute: (1) bare-metal cloud delivered through cloud-like automation and APIs, and (2) traditional dedicated hosting leased on more fixed terms and managed through more manual workflows. It also covers when a hybrid approach can outperform either option on its own.

## Problem Statement

AI workloads are unusually sensitive to infrastructure bottlenecks. A cluster can have top-tier GPUs and still underperform if storage throughput is insufficient, networking cannot support distributed training efficiently, or environment rebuilds are slow and error-prone. Meanwhile, procurement and data-center buildouts often cannot keep pace with AI iteration, and many teams lack the specialized skills to design and operate GPU-ready environments.

The result is a common business problem: organizations need GPU-grade performance without the capital expense, staffing burden, and time-to-deploy of an on-premises build, while still maintaining control over security, compliance, and predictable spending. Bare-metal cloud and dedicated servers can both help, but they optimize different parts of the trade space.

## Overview of Bare Metal Cloud vs. Dedicated Servers

The following overview illustrates the similarities and important differences in these two solutions for modern AI workloads.

Bare-metal cloud delivers single-tenant physical servers through cloud-based orchestration that relies heavily on automation. Users quickly provision servers via APIs for flexible, on-demand deployment. The servers are supported by cloud and software-defined networking.

Traditional dedicated servers are leased typically on a fixed-term basis and are often provisioned through provider workflows that can range from hours to days (and longer for custom builds). The servers support a planned deployment approach. They use traditional networking and access methods.

## Definitions and Scope

In the market, “bare metal server” and “dedicated server” are sometimes used interchangeably to describe single-tenant physical hardware. In this paper, the difference lies in the delivery model: “bare-metal cloud” means bare-metal delivered with cloud-like provisioning, automation, and API-first operations; “traditional dedicated servers” means leased single-tenant hardware commonly managed through more manual or ticket-driven processes and longer-lived instances.

Also note that “dedicated instances” in public clouds can refer to isolated virtualized capacity. This guide focuses on single-tenant physical servers (no shared hypervisor layer) unless otherwise stated.

### Similarities between bare-metal cloud and dedicated servers

These two hosting solutions share several core characteristics.

- A physical server is dedicated to a single customer. This single-tenant hardware provides isolation and eliminates noisy neighbor issues.
- Teams have direct access to the hardware with no hypervisor overhead.
- Businesses can expect high performance thanks to dedicated resources, including CPU, memory, and storage.
- Teams can customize the environment with full administrative control over the operating system and applications.
- Companies can use either platform to maintain regulatory compliance. (when paired with appropriate controls, logging, encryption, and access governance).

### Key Differences between bare-metal cloud and dedicated servers

The key differences between the two platforms cover multiple categories that may significantly influence their choice for a given AI workload.

Bare-metal cloud offers faster, automated provisioning and deprovisioning via APIs, along with on-demand reconfiguration. Traditional dedicated servers are typically provisioned more slowly and may require manual intervention or provider support for hardware reconfiguration.

A bare-metal cloud can rapidly scale to meet fluctuating requirements. They are well-suited to burst workloads with elastic capacity. Scaling dedicated servers, while possible, is usually slower and depends on inventory and provider processes, making them less ideal for burst workloads.

Bare-metal cloud servers are billed often hourly, daily, or monthly. The cost of overprovisioning or maintaining idle resources is low because they can be easily shut down. This flexibility can make it difficult to predict long-term costs. Dedicated servers typically have a fixed monthly fee. Since resources are always on, idle costs are high, and overprovisioning is possible due to poor planning. The fixed billing structure makes it easier to budget for dedicated servers.

The operations and access methods used with the two platforms vary considerably. Bare-metal cloud provides native support for Infrastructure as Code and easy CI/CD integration. Users interact with servers through APIs, web portals, and dashboards focused on automation and self-service. Dedicated servers can be integrated into CI/CD pipelines, but it often requires more standardization and additional tooling (e.g., configuration management, golden images, and consistent provisioning workflows) and are usually less turnkey without API-first control planes.

### Bare-metal cloud vs dedicated servers comparison table

| **Component or attribute** | **Bare Metal Cloud Servers** | **Traditional Dedicated Servers** |
| --- | --- | --- |
| **Billing structure** | Pay-as-you-go (often hourly/daily/monthly) may be tiered | Fixed monthly fee (often with longer-term options) |
| **Hardware flexibility** | Selected from a list of available predefined configurations | Standard models with more frequent custom-build options |
| **Server provisioning** | Rapid in minutes via APIs | Often hours to days, depending on customization and process |
| **Performance** | Based on hardware capabilities | Based on hardware capabilities |
| **Automation** | Extensive automation for access, provisioning, and operations | Limited (varies by provider; commonly more manual) |
| **Cloud integration** | Strong cloud integration capabilities | Variable; often weaker integration with cloud-native services |
| **Flexibility** | Superior operational flexibility | Hardware customization flexibility |
| **Scalability** | Easily scalable with on-demand provisioning | Limited scalability with additional physical machines and inventory lead times |
| **Network** | Software-defined, cloud-based network | Traditional, data-center-centric network |
| **Storage options** | Flexible: local NVMe, SAN, tiered block storage | Fixed: local RAID drives; SAN optional |
| **Infrastructure as Code** | Native support | Possible but often less native; depends on provider APIs/tooling |

## AI Workload Requirements

For AI workloads, the “right” platform is often determined by constraints beyond basic CPU/RAM sizing. Teams should evaluate GPU compute, storage throughput, networking behavior, and the software stack as first-class requirements, because any one of these can become the bottleneck that dictates cost and performance.

**GPU considerations:** AI training and high-throughput inference may require specific GPU classes, VRAM capacity, and multi-GPU interconnect behavior. Even when two offerings list the same GPU model, practical outcomes can differ based on server topology, PCIe lane allocation, and how GPUs share access to local NVMe and network interfaces.

**Storage and data pipeline considerations:** GPUs deliver value only when continuously fed with data. Training pipelines that rely on large datasets, frequent checkpointing, and rapid restarts are sensitive to storage throughput and latency. Local NVMe can accelerate scratch space and caching, while networked storage and object storage can improve durability and collaboration—often at the cost of additional complexity and egress considerations.

**Networking and distributed training considerations:** If you plan multi-node training, networking becomes a primary architecture decision. Latency, bandwidth consistency, and support for advanced networking features can materially affect scaling efficiency. Teams should confirm whether they can achieve the networking model their framework expects—especially when moving from single-server training to multi-server clusters.

**Platform and operations considerations:** AI teams increasingly depend on containerized workflows, reproducible environments, and IaC-driven rebuilds. The best platform is the one that enables fast iteration (spin up → train/test → tear down) while maintaining security controls, auditability, and cost governance.

## Scalability and Flexibility for AI Projects

Teams supporting AI projects require a flexible, scalable computing environment to address evolving requirements and growth, and must consider the differences between these two single-tenant solutions. The two approaches may provide the same or similar physical hardware but vary substantially in how they support operational agility and growth.

Companies must understand their specific AI workload requirements to make an informed decision about their cloud hosting platform. Many of today’s AI workloads require at least one of the following scalability or flexibility characteristics.

- Parallel GPU/CPU performance for processes such as ML model training.
- Dynamic resource usage to support development and production environments.
- Real-time support that enables trained AI models to process high volumes of requests with minimal latency and high throughput.
- Support for DevOps workflows by integrating data pipelines across platforms.
- Elasticity for dynamic scaling of variable workloads.

### Scalability for AI workloads

Scalability is necessary to effectively support the following types of fluctuating AI workflows.

- Model training requires massive parallelism that is not needed once the process completes.
- AI experiments often demand high resource utilization, which drops once the results are obtained.
- Batch AI processing, performing tasks such as data labeling and image classification, typically has workloads triggered by the availability of new data and does not continuously consume resources.
- Consumer-facing AI applications such as chatbots address fluctuations driven by factors like time of day, marketing campaigns, and seasonal variations.
- Fraud detection and other event-driven inference solutions are subject to unpredictable bursts of activity but have low, steady-state baseline resource requirements.
- AI-powered reporting and analytics typically have predictable and ad hoc spikes, followed by long idle periods with no resource usage.
- Support for development bursts in CI/CD pipelines provides performance benchmarking, model testing, and validation.
- SaaS or multi-tenant AI platforms must handle unpredictable scaling requirements when responding to customer requests and may experience long periods of idle time.

Bare-metal cloud supports these types of AI workloads with more dynamic scaling. Companies with predictable, consistent workloads may find dedicated servers a better option. The chart below summarizes how these two single-tenant AI hosting options compare in scalability capabilities.

| **Scalability Characteristic** | **Bare-Metal Cloud** | **Traditional Dedicated Server** |
| --- | --- | --- |
| Provisioning speed | Fast through APIs. | Slow manual process. |
| Horizontal scaling | Requires re-provisioning. | Requires new physical servers. |
| Vertical scaling | Requires re-provisioning or resizing. | Based on hardware limitations. |
| Elasticity – turning resources on or off | High. Resources are provisioned as needed and then released. | None. Resources are continuously provisioned. |
| Bursting | Easy with fast reprovisioning. | Hard or expensive. |
| Automation integration | Native. Examples include API, DevOps, and Infrastructure as Code. | Limited |
| Modifying resource capacity | Automated through cloud orchestration. | Manual requiring planning and purchasing resources. |

### Flexibility for AI workloads

Organizations may need various types of flexibility, which they can address with bare-metal cloud or dedicated servers. The characteristics of each platform make it an attractive option for specific use cases.

Bare-metal cloud offers greater flexibility when teams need to quickly spin up new environments to address changing business requirements. They are excellent at supporting rapid iteration and experimentation and can be efficiently integrated into DevOps workflows.

Dedicated servers offer a different kind of flexibility. These servers can typically be provisioned with custom hardware and configured to meet specialized application or operating system requirements. Some technical teams may be more comfortable working with the physical infrastructure of dedicated servers.

The differences in flexibility between the two platforms are summarized in the table below.

| **Flexibility Aspect** | **Bare-Metal Cloud** | **Dedicated Servers** |
| --- | --- | --- |
| Provisioning | Self-serve, on-demand via APIs. | Manual, requiring ordering and setup time. |
| Hardware selection | Multiple, but limited to the provider’s options. | Custom configurations are possible. |
| Automation | Full operational automation. | Manual processes. |
| Network | Software-defined network. | Traditional network. |
| Workload migration | Simple to redeploy with automation and provisioning. | Difficult or impossible due to reliance on hardware. |
| DevOps and CI/CD integration | Strong. | Limited. |

## Choosing the Most Cost-Effective Platform

Use bare-metal cloud when you need speed and elasticity: short-lived training bursts, frequent environment rebuilds, rapid experimentation, CI benchmark spikes, or unpredictable inference surges. The ability to provision quickly and shut down cleanly can reduce idle waste if teams enforce governance and automation.

Use traditional dedicated servers when you need steady-state efficiency and predictability: 24/7 inference services with stable demand, long-running training cycles on consistently utilized GPUs, or regulated environments that benefit from fixed footprints and simpler budgeting. Dedicated servers can deliver strong cost/performance when utilization is consistently high.

Use a hybrid approach when your workload has a stable baseline plus spikes: keep “always-on” capacity on dedicated servers and burst to bare-metal cloud for peak demand, large experiments, or temporary projects. Hybrid models are especially effective when data gravity, compliance needs, or procurement realities prevent putting everything into one operating model.

## Cost Optimization Strategies

The costs of bare-metal cloud and traditional dedicated servers share several components, but their pricing differs significantly based on the scalability and flexibility of these high-performance computing solutions.

The following core elements contribute to the costs of bare-metal cloud servers.

- **Compute power:** Costs increase with the level of computing power, driven by CPU/GPU choice and memory.
- **Local storage:** The choice of NVMe or SSD storage affects the server’s cost.
- **Network bandwidth:** Providers may offer baseline data transfer limits after which customers pay additional egress fees.
- **Operating system licence:** Customers pay for Windows licenses.
- **Managed services:** Costs vary based on the specific managed services customers choose to adopt.
- **Additional support:** Costs may increase for access to premium support tiers or for stringent service-level agreements (SLAs).

Traditional dedicated servers are priced according to the following recurring core cost components.

- **Server rent:** Base rent includes the server’s CPU, RAM, and storage.
- **Network bandwidth:** Customers typically pay for outbound data after exceeding a default capacity baseline.
- **Operating system license:** Customers pay for Windows licenses.
- **Managed services:** The cost of managed backups, monitoring, or security increases total costs.
- **Support tier:** Costs vary by the customer’s choice of a standard or premium support tier.

The costs of these two AI hosting infrastructures differ for several reasons.

- **Flexibility and elasticity:** Customers pay more for the fast provisioning and API controls offered by bare-metal cloud servers. These features support the flexibility required by teams with dynamic AI workloads. Dedicated servers offer a lower price commensurate with the fixed set of resources they provide.

- **Cloud ecosystem integration:** Features such as autoscaling and object storage add value but come with flexible costs for bare-metal cloud servers. Dedicated servers have more predictable costs with fewer metered elements.

- **Dynamic cost control:** Bare-metal servers can be easily stopped and started to address fluctuating workloads, minimize resource usage, and optimize costs. A traditional dedicated server has lower base fees, no hourly overhead, and is typically less expensive for continuous use.

### Choosing the most cost-effective platform

Companies should select a bare-metal cloud solution for short-term, variable, and hybrid cloud workloads. Bare-metal is also recommended for workloads that may require fast reprovisioning or automated scaling.

Teams should choose traditional dedicated servers for predictable, stable, and long-running workloads. A dedicated server solution may offer the lowest price for base hardware performance.

In addition to monthly spend, AI teams should track outcomes-based metrics such as cost per training run, time-to-checkpoint, GPU utilization rate, and cost per 1,000 inferences at target latency. These measures reveal whether infrastructure choices are actually improving model velocity and unit economics.

### Cost breakdown and comparison chart

| **Cost Category** | **Bare Metal Cloud Servers** | **Traditional Dedicated Servers** |
| --- | --- | --- |
| Base compute cost | Pay-as-you-go hourly or monthly, may be tiered. | Fixed monthly fee. |
| Network bandwidth | Often usage-based. | Baseline limits are typically included in the plan. |
| Storage pricing | Usage-based, with multiple performance tiers available. | Often bundled into the base plan cost. |
| Management and support Fees | Optional managed services are available at an additional cost. | May be included or offered as a separately priced feature. |
| Security and compliance features | Add-ons or standard in higher tiers. | May be included or available as additional features. |
| Backup Solutions | Optional with varying costs. | Optional with varying costs. |
| OS and software licensing | May be billed hourly or monthly. | Typically, a one-time charge is included with the base plan. |
| Budgeting complexity | It can be high due to many moving parts. | Simple with stable resource utilization. |

## Hybrid Deployment Models

Organizations may find that a hybrid deployment of bare-metal and dedicated servers is the best solution for their unique AI workloads. A hybrid deployment allows companies to benefit from the cost stability and control of dedicated servers, as well as the elasticity and flexibility of bare-metal cloud. Teams can optimize for workload behavior and specifications with a hybrid architectural approach.

The objective of a hybrid deployment is to leverage the strengths of each platform rather than trying to fit complex, diverse workloads into a single solution.

Hybrid deployment provides the following advantages.

- Teams can host specific AI workloads on the most appropriate platform to maximize performance.
- The hybrid approach provides a flexible path for growth, as organizations can scale with either or both platforms.
- Companies can optimize resource utilization and IT spending by selecting the right platform for each workload and avoiding overprovisioning.
- Organizations minimize the risk of degraded performance or unacceptable results from using the wrong platform for specific tasks.

Companies may also face several challenges in managing a hybrid environment.

- Teams must address the additional architectural complexity of a hybrid cloud comprising bare-metal cloud and dedicated servers.
- The environment demands reliable monitoring and strong governance to maintain data integrity.
- Organizations must ensure that networking implementation decisions and identity management solutions are sufficient to support both platforms.

Organizations must consider potential issues in the following technical areas when integrating bare-metal cloud and traditional dedicated servers.

- **Networking:** Teams must implement consistent IP addressing, environment segmentation, and secure connectivity paths.
- **Identity and access:** Companies must leverage a centralized IAM solution and least-privilege access to protect all workloads. Teams should incorporate all systems into a unified logging and auditing solution.
- **Data management:** Businesses must plan for data growth and bandwidth costs.
- **Automation:** Teams can implement automated configuration management for both environments. Developers require efficient CI/CD pipelines that connect both platforms.

### Common hybrid deployment models

- Core-elastic models use dedicated servers for core, stable workloads with bare-metal cloud for bursting and rapid scaling. The model provides predictable costs for baseline functionality and scalable capacity without permanent hardware costs.

- The AI/ML compute model provides optimized GPU utilization and cost control by using dedicated servers for continuous training or inference, supplemented by a bare-metal cloud for burst training or experiments.

- Companies with regulated workloads may implement the compliance segmentation model. Teams process regulated workloads with dedicated servers, with bare-metal cloud servers used for tasks such as reporting and analytics. This model reduces the security overhead and simplifies compliance audits.

## Conclusion

Bare-metal cloud and traditional dedicated servers are both appropriate solutions for AI workloads. The enhanced scalability and flexibility of bare-metal cloud make it a better choice for organizations with fluctuating workloads or burst processing demands. Dedicated servers offer more predictable pricing and are better for customers with stable processing requirements.

Organizations must understand their current and future workload requirements when choosing between bare-metal cloud and traditional dedicated servers. A well-planned deployment of dedicated servers may address business objectives without the less predictable costs of a bare-metal cloud solution. The ability to easily scale bare-metal elastic resource capacity can provide cost savings when managed effectively.

In many cases, a hybrid deployment that leverages the best of both platforms may be the best solution for a specific use case. Companies should look to work with providers that offer both options to optimize the performance and capabilities of their AI workloads.

 


---

# Cloud Exit Strategy 2026: High-IOPS DBs to Bare Metal

> URL: https://www.atlantic.net/dedicated-server-hosting/cloud-exit-strategy-high-iops-databases-bare-metal/ | Published: 2026-03-05 | Author: Dr. Assad Abbas

Organizations across multiple sectors are re-evaluating their cloud deployments in 2026. This review frequently targets workloads dependent on high[Input/Output Operations Per Second (IOPS)](https://www.atlantic.net/vps-hosting/performance-matters-how-disk-throughput-and-iops-impact-your-business/), such as financial systems, healthcare databases, and real-time transactional platforms. Handling massive data volumes requires predictable performance and stable latency. Many organizations are now building structured cloud exit strategies to regain control over their infrastructure and operations.

A cloud exit strategy safely transitions workloads and data from a public cloud to a strictly controlled environment. Dedicated [bare metal servers](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) are a popular target, though hybrid approaches combining public cloud and dedicated hardware also work well. Selective [cloud repatriation](https://www.hpe.com/us/en/what-is/cloud-repatriation.html) moves predictable, IOPS-heavy databases back to dedicated servers. This shift stabilizes latency, makes costs predictable, and sharply reduces operational uncertainty.

Healthcare and financial organizations face strict regulatory burdens. Electronic Protected Health Information (ePHI) must be secured under a [HIPAA Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) framework. Payment systems must adhere to Payment Card Industry Data Security Standard (PCI DSS) requirements. These mandates demand reliable logging, encryption, and access controls. Data in transit must use TLS 1.2 or 1.3 to guarantee secure communication. complete audit mechanisms must also log all access to sensitive information to prove continuous compliance.

In 2026, rising operational costs and latency spikes in multi-tenant environments are deeply concerning to executives. Regulatory requirements continue to tighten. Boards and senior leaders demand clear visibility into infrastructure and absolute control over data residency. Many organizations are aggressively migrating high-IOPS databases from public cloud platforms to dedicated bare-metal environments to balance cost, performance, and strict compliance requirements.

## Motivations Behind Cloud Repatriation and Migration Planning

Companies reassess cloud deployments when cost, performance, or compliance metrics slip. These shifts become more pronounced as workloads scale, particularly for high-IOPS databases that require predictable hardware behavior. Understanding these core drivers explains why cloud repatriation is a long-term strategic maneuver rather than a knee-jerk reaction.

### Rising Operational Costs

High-IOPS workloads on public cloud platforms quickly inflate IT budgets. Managed database services charge steep premiums, and IOPS-optimized storage layers add massive overhead. Snapshots, backups, and inter-region network traffic multiply these expenses over time. Data egress fees also create a heavy financial burden during large-scale migrations. This compounding financial pressure pushes organizations toward dedicated servers, which offer flat, predictable billing.

### Performance and Latency Considerations

Applications pushing high IOPS absolutely depend on stable, sub-millisecond latency. Multi-tenant cloud environments frequently introduce noisy-neighbor effects, and underlying virtualization layers add compute overhead.

Latency jitter directly degrades real-time and Online Transaction Processing (OLTP) systems. Securing predictable performance drives the migration to dedicated infrastructure, eliminating shared-resource bottlenecks for sensitive workloads.

### Regulatory and Compliance Requirements

Healthcare and financial sectors operate under unforgiving regulatory frameworks. HIPAA-compliant hosting mandates airtight access controls and audit logging, with a BAA legally defining data handling responsibilities. Payment systems must satisfy strict PCI DSS requirements for encryption and logging. Public cloud platforms frequently obscure visibility into underlying security controls. Shifting workloads to dedicated or hybrid environments restores total compliance oversight and streamlines audit processes.

### Data Residency and Sovereignty Considerations

Regional governments increasingly enforce strict data residency laws. Cross-border data transfers demand heavy documentation and specific legal approvals. Defense, healthcare, and finance sectors often legally mandate localized infrastructure for sensitive workloads. Organizations must place data on geographically compliant platforms to minimize legal risks and maintain audit readiness.

### Strategic Motivation in 2026

Beyond immediate operational and regulatory pressures, organizations crave long-term infrastructural stability. Dedicated environments deliver predictable costs, raw performance, and reduced risk of vendor concentration. They also guarantee complete transparency for internal reporting and external audits. Driven by these distinct advantages, cloud repatriation in 2026 stands out as a deliberate, strategic maneuver. It directly aligns hardware planning with core business objectives, stringent compliance needs, and aggressive performance goals.

## Governance, Contractual Review, and Risk Assessment for a Cloud Exit

A successful cloud exit demands meticulous preparation long before a single byte of data moves. Organizations must audit existing cloud contracts, map out their legal obligations, and assess the risks of migrating high-IOPS databases to bare-metal infrastructure. This groundwork establishes a secure foundation, eliminates technical uncertainty, and streamlines cross-team coordination.

### Centralizing Contracts and Agreements

First, consolidate all cloud-related contracts. This repository should include Master Service Agreements (MSAs), Data Processing Agreements (DPAs), security addenda, BAAs, and historical order forms. Centralizing these documents exposes vendor limitations, data retention rights, and financial obligations that might derail the exit process. A single source of truth prevents critical compliance oversights.

### Termination, Egress, and Data Portability

Next, audit termination clauses, mandatory notice periods, and auto-renewal terms to dictate the migration timeline. Egress costs and data export rights require intense scrutiny.

Proprietary cloud database schemas or restricted export APIs severely throttle data portability. Verifying absolute data ownership and testing full-scale exports in open formats prevents vendor-induced delays and exorbitant ransom-like egress fees.

### Compliance Mapping and Security Requirements

Legal and compliance obligations must dictate the exit architecture. BAAs legally restrict how ePHI is handled, encrypted, and destroyed during and post-migration. PCI DSS mandates uninterrupted logging, strict access control, and reliable encryption throughout the cutover. All data in transit must utilize TLS 1.2 or 1.3. Enforcing these security protocols consistently throughout the migration phase shields the organization from compliance breaches, failed audits, and severe financial penalties.

### Identifying Vendor Lock-In Risks

Hyperscale cloud providers intentionally engineer vendor lock-in via proprietary database engines, custom Identity and Access Management (IAM) systems, specialized storage APIs, and proprietary serverless functions. Migrating these tightly coupled components mandates expensive re-architecture. Identifying these technical traps early allows engineering teams to accurately estimate labor, allocate resources, and chart a realistic migration path.

### Operational Continuity and Dependency Risks

Moving massive datasets inevitably affects Recovery Point Objectives (RPOs) and Recovery Time Objectives (RTOs). Maintenance windows shrink dramatically for always-on transactional systems. Failing to map hidden application dependencies guarantees post-migration outages. IT staff will also need rapid upskilling to operate the new bare metal environment effectively. Proactively documenting these operational risks and engineering-specific mitigation and fallbacks ensures smooth business continuity.

### Migration Volume and Egress Exposure

High-IOPS databases inherently house terabytes or petabytes of data. Archives, historical snapshots, and transaction logs aggressively inflate the total transfer payload, extending the migration timeline. High database change rates further compress the allowable cutover window. Running parallel environments (dual-run) during the transition spikes temporary compute costs. Teams must relentlessly calculate egress fees, as pulling massive datasets out of the public cloud triggers punishing financial penalties. Accurately modeling these variables yields realistic timelines and bulletproof budget allocations.

### Developing a Risk Register

High-IOPS databases inherently house terabytes or petabytes of data. Archives, historical snapshots, and transaction logs aggressively inflate the total transfer payload, extending the migration timeline. High database change rates further compress the allowable cutover window. Running parallel environments (dual-run) during the transition spikes temporary compute costs. Teams must relentlessly calculate egress fees, as pulling massive datasets out of the public cloud triggers punishing financial penalties. Accurately modeling these variables yields realistic timelines and bulletproof budget allocations.

## Planning the Cloud Exit for High-IOPS Workloads

Flawless planning dictates the success of a cloud exit. Engineering teams must dissect workload architectures, model financial realities, and architect the optimal migration pathway. These overlapping activities form a cohesive strategy to guarantee a predictable, zero-downtime transition to bare metal.

### Inventory and Dependency Mapping

The technical blueprint begins with an exhaustive inventory of all applications that interact with the high-IOPS database.

This map must capture third-party integrations, raw data flows, and hidden operational dependencies. CI/CD pipelines, IAM frameworks, observability agents, and automated backup routines must be meticulously documented. Exposing these deep-tier dependencies prevents catastrophic application failures during the final cutover.

### Workload Classification

Next, classify workloads by portability. Not all applications migrate seamlessly. Containerized, stateless workloads port easily. Legacy monoliths tied to proprietary cloud-native queuing or messaging services demand heavy refactoring. Mission-critical OLTP databases require specialized, high-availability migration sequencing. Segmenting workloads by architectural complexity allows teams to structure safe, phased migration waves.

### Decision Matrix for Selecting the Right Environment

A weighted decision matrix clarifies infrastructure targeting.

This matrix evaluates public cloud, bare-metal, and hybrid architectures, as well as approved hosting providers, against critical performance, cost, and compliance metrics. Public clouds excel at elasticity but fail at cost predictability. Dedicated bare metal guarantees maximum IOPS, sub-millisecond latency, and absolute data control. Hybrid setups bridge the gap for mixed-architecture deployments. Weighing latency thresholds against compliance mandates ensures workloads land on the optimal hardware.

The matrix below summarizes these comparisons:

**Table 1: Decision matrix for choosing the appropriate environment**

| Evaluation Area | Public Cloud | Bare Metal | Hybrid | Approved Provider |
| --- | --- | --- | --- | --- |
| Latency Stability | Moderate | High | High | Varies |
| IOPS Performance | Good | Excellent | Good | Varies |
| Cost Predictability | Low | High | Moderate | Moderate |
| Compliance Visibility | Limited | High | High | Varies |
| Data Sovereignty | Limited | High | High | Varies |
| Operational Control | Limited | High | Moderate | Moderate to High |
| Migration Complexity | Low to Moderate | Moderate to High | High | Moderate |
| Best Fit For | Elastic workloads | High-IOPS workloads | Mixed workloads | Regulated workloads |

### Total Cost of Ownership (TCO) Modeling

Cost modeling is another essential part of planning. TCO must be calculated for both cost modeling and planning, which are essential parts of planning. Therefore, TCO must be calculated for both the current cloud environment and the future bare metal infrastructure. Cloud compute, storage, and IOPS tiers contribute to ongoing cost, while managed database services add further overhead. In addition, network and egress charges must be included. Similarly, bare metal cost modeling should consider CPU, RAM, NVMe storage, and staffing. By using three-year and five-year projections, organizations can understand the long-term financial impact and justify the migration.

### Migration Approach Selection

The technical migration mechanism dictates downtime. Engineering teams choose among logical replication, block-level physical replication, snapshot-and-incremental syncs, or application-level dual writes. Zero-downtime environments rely heavily on complex blue-green deployments. Matching the replication strategy to the business’s Maximum Tolerable Downtime (MTD) guarantees data consistency without violating Service Level Agreements (SLAs).

## Selecting the Target Environment for High-IOPS Workloads

Sourcing the correct target infrastructure locks in performance, ensures compliance, and guarantees operational stability. This pivotal decision synthesizes the data gathered during workload classification and TCO modeling.

### Evaluating Bare Metal Suitability

Bare metal reigns supreme for high-IOPS databases by granting direct, hypervisor-free access to physical hardware. Dedicated silicon delivers unbreakable latency, sustained high throughput, and granular control over the storage controller. Engineers can map enterprise NVMe drives and custom RAID topologies directly to the database’s specific read/write I/O patterns. Bare metal simply eliminates the latency jitter inherent to virtualized public clouds.

### Working with Approved Providers

When selecting a hosting provider, organizations should focus only on approved and trusted platforms. Examples include [Atlantic.Net](https://www.atlantic.net), [AWS](https://aws.amazon.com/), [Azure](https://azure.microsoft.com/en-us), [Google Cloud](https://cloud.google.com/), [Rackspace](http://www.rackspace.com), [Kamatera](http://www.kamatera.com), [Scala Hosting](http://www.scalahosting.com), and [Kinsta](http://www.kinsta.com). Each provider has different strengths, and the final choice depends on compliance needs, performance expectations, and operational preferences. By including only approved providers, organizations can simplify procurement and ensure that the new environment meets internal standards.

### Toolchain and Capacity Validation

Before migrating a single byte, engineers must validate the DevOps toolchain in the new bare-metal environment. Teams must verify base OS compatibility, adjust Kubernetes or Docker orchestration configurations, and rewrite Terraform or Ansible Infrastructure-as-Code (IaC) pipelines. Observability agents require recalibration. Finally, aggressively load-testing the network bandwidth guarantees the new hardware can absorb production-level traffic spikes without buckling.

## Executing the Cloud Exit

Migration execution demands ruthless testing and a highly controlled cutover. Engineering builds an exact staging replica of the production environment, seeding it with sanitized, de-identified data. Stress tests bombard the new bare metal servers to validate peak IOPS, sustained throughput, and latency metrics. Administrators forcefully trigger failover and backup restoration protocols to prove architectural resilience.

Workloads transition in highly sequenced migration waves. Each wave dictates mandatory rollback triggers, parallel dual-run overlap, and initial canary routing to catch hidden anomalies. Security perimeters remain heavily fortified during transit. All live traffic flows exclusively over TLS 1.2 or 1.3. Strict IAM mappings, immutable audit logging, and active incident response protocols guarantee a secure, compliant cutover.

## Post-Migration Stabilization

Post-migration, operations teams shift to aggressive monitoring to lock in stability, efficiency, and continuous compliance. Engineers immediately track live performance telemetry against historical public cloud baselines, ensuring bare metal latency, throughput, and IOPS exceed legacy metrics.

Database Administrators (DBAs) fine-tune the environment by right-sizing hardware, defragmenting indexes, optimizing queries, and aggressively caching. Security teams must execute rigid data hygiene sweeps. This includes cryptographically shredding residual public cloud data, purging stale snapshots, rotating compromised access keys, and securing formal attestation that all BAA data-destruction mandates are met.

A formal post-mortem review documents architectural wins and engineering bottlenecks. Updating internal governance policies transforms this single cloud exit into a repeatable, standardized playbook for future infrastructure migrations. This disciplined stabilization phase secures long-term operational supremacy, slashes hosting costs, and permanently hardens the compliance posture.

## Concluding Remarks

Repatriating high-IOPS databases to bare metal requires precise preparation and ruthless execution. Auditing legal contracts, identifying vendor lock-in, and categorizing workloads expose hidden risks early. This intelligence drives the architectural design, perfectly matching database performance demands with dedicated, high-performance infrastructure. Controlled, staged execution and continuous compliance enforcement guarantee a zero-downtime transition.

Aggressive post-migration monitoring and strict data destruction policies secure the final environment. By executing this complete 2026 cloud exit playbook, enterprises eliminate public cloud uncertainty, secure dominant database performance, and build an unshakable infrastructure foundation for future scaling.


---

# Top AI Website Builders 2026 for Business & Ecommerce

> URL: https://www.atlantic.net/managed-services/top-ai-website-builders-business-ecommerce/ | Published: 2026-03-05 | Updated: 2026-05-27 | Author: Hitesh Jethva

Choosing the top website builder in 2026 is no longer just about picking a drag-and-drop builder and publishing a few pages. Today, businesses expect faster load times, built-in marketing tools, e-commerce features, and layouts that work smoothly across mobile devices.

Website creation has moved beyond traditional website builders. Modern platforms now include AI capabilities that can generate layouts, suggest content structure, and even create a near-complete site from a few prompts. Whether you want a one-page website, a full website for your company, or a scalable e-commerce site, many builders now combine AI-generated site setup with manual customization options.

Many AI website builders generate layouts, copy, and structure based on user prompts, significantly reducing the time needed to create a website.

AI website builders automate the design and development process, enabling users to create websites quickly without coding.

Small business owners and local businesses benefit the most from this shift. Instead of hiring developers for a custom website, you can launch your own website using structured templates, editing tools, and AI-assisted workflows. Many platforms now include:

- Built-in SEO features
- E-commerce tools for an online store
- Image editing and AI tools
- App market integrations
- Marketing tools for growth
- AI-powered layout and content suggestions

AI website builders also streamline repetitive tasks such as metadata creation, product descriptions, and page structuring, helping users reduce setup time while keeping control over design and customization.

At the same time, expectations are rising. Google’s Core Web Vitals standards are stricter, so site performance matters more than ever. A web builder that looks good but loads slowly can hurt search visibility. Builder costs also vary widely depending on paid plans, e-commerce upgrades, advanced features, and automation capabilities.

In this guide, we will compare the best website builders of 2026 based on features, pricing, AI capabilities, performance, and overall usability to help you choose the right platform for your needs.

## Best Website Builder Comparison (2026)

| **Platform** | **Category** | **AI Capabilities** | **Starting Price** | **Key Strength** | **Best For** |
| --- | --- | --- | --- | --- | --- |
| Wix | Drag-and-drop website builder | AI site generator + AI design & content tools | ~ $17/month | Balance of ease, customization, and built-in features | Small businesses, service websites |
| Squarespace | Design-first website builder | AI text + layout assistance | ~ $16/month | High-quality templates and brand-focused design | Creatives, consultants, visual brands |
| SuperNinja | AI-first website builder | Conversational AI builds a full website | ~ $16/month | Fully AI-generated websites from prompts | Entrepreneurs who want speed |
| WordPress | Open-source CMS | AI via plugins (varies by setup) | Free (hosting required) | Maximum customization and plugin ecosystem | Bloggers, advanced users, SEO-focused sites |

## Leading Website Builder for 2026

The leading website builder in 2026 combines strong design control, ecommerce features, built-in SEO tools, and fast site performance — all without requiring coding skills.

 

![](https://www.atlantic.net/wp-content/uploads/2025/04/wix-logo.png)

### 1. Wix – Best Overall Website Builder in 2026

Wix stands out as the top**website builder** in 2026 for its easy-to-use tools, strong design options, ecommerce features, and built-in marketing support. It’s a good choice for beginners starting their first site and for businesses that need advanced features. With over 900 templates, users have plenty of design choices.

#### Key Features

- True Drag and Drop Builder: Move elements anywhere on the page without layout restrictions.
- AI-Generated Site Setup: Guided prompts that automatically generate layouts and structure.
- AI Features for Content & Design: Helps create sections, text, and visual blocks quickly.
- App Market: Large marketplace for adding booking systems, forms, chat, and other tools.
- E-commerce Tools: Product management, payments, inventory, and shipping features.
- Marketing Tools: Email campaigns, automation flows, and analytics.
- Landing Page Builder: Easily create landing pages for ads and promotions.
- Built-in SEO Features: Structured tools to improve search visibility.

#### Who Should Choose Wix

Wix is designed for users who want flexibility without coding skills.

#### Best For

Small businesses, local businesses, ecommerce brands, freelancers, and anyone building a professional website or a full website quickly.

#### AI Builder Capabilities

Wix is a leading AI website builder in 2026. Its drag-and-drop editor and AI-powered design tools help you create layouts, structure, and content tailored to your needs. This speeds up setup, but you can still customize everything by hand. Keep in mind, you may need to edit AI-generated content to match your brand and ensure quality.

![](https://www.atlantic.net/wp-content/uploads/2025/08/Squarespace_Logo.png)

### 2. Squarespace – Best for Design-Focused Businesses

Squarespace is known for polished templates and a clean user interface, making it a strong choice for brands that care about visual identity. It is especially popular among creatives, consultants, and small to mid-sized companies building a professional website or modern business website. Squarespace offers high-quality, designer-made templates ideal for creative portfolios.

#### Key Features

- Strong Design Tool: High-quality templates with consistent typography and spacing.
- Custom Layouts: Flexible section-based editor for structured page design.
- Built-in Features: Blogging, scheduling, analytics, and email tools included.
- E-commerce Features: Product pages, subscriptions, digital products, and inventory management.
- One-Page Website Options: Ideal for portfolios, events, and focused landing pages.
- Landing Page Builder: Clean, conversion-focused layouts.
- Mobile Optimization: Templates adapt smoothly across mobile devices.
- Built-in SEO Features: Page-level controls for titles, descriptions, and structure.

Squarespace is recognized for its ease of use and is often recommended for small to mid-sized ecommerce brands and creatives.

#### Who Should Choose Squarespace

Squarespace is ideal for businesses that prioritize branding and presentation.

#### Best For

Design-focused entrepreneurs, consultants, creatives, and small businesses are building clean, professional websites without needing complex developer tools.

#### AI Builder Capabilities

Squarespace includes guided setup tools and content assistance, but it is not positioned as a leading AI website builder. It emphasizes structured design and curated templates over fully automated site generation.

![](https://www.atlantic.net/wp-content/uploads/2026/03/ninja-tech-logo.jpg)

### 3. SuperNinja – Best AI Builder for 2026

SuperNinja is a modern **AI website builder** designed for speed and simplicity. Rather than using templates, users describe their business and goals, and the platform creates a structured website in just a few minutes. Its main focus is fast deployment, built-in SEO tools, and automated workflows that reduce manual setup.

#### Key Features

- AI-Generated Site from Prompts: Enter a few details about your business, and the system builds the layout, sections, and starting content for you.
- Fast Full Website Creation: Build a complete website structure with a single, simple setup.
- Built-in SEO Features: Get automatic meta tags, sitemap creation, and formatting that’s ready for search engines.
- Landing Page Builder: Quickly make focused campaign pages.
- Agent-Style Workflows: handle repetitive tasks such as structuring pages and organizing content.
- Mobile Optimization: Pages automatically adjust to look good on any mobile device.
- Simple Dashboard: The clean interface is made for people without technical experience.

#### Builders Cost & Paid Plans

SuperNinja usually uses a subscription-based pricing model.

- Paid plans start at an entry-level tier for individuals
- Higher-tier plans offer advanced AI features, ecommerce tools, and more automation options.
- Pricing increases based on storage, website traffic, and which features you use.

Compared to most website builders, SuperNinja stands out for its speed and the amount of manual design work it saves you.

#### Who Should Choose SuperNinja

SuperNinja is made for people who want to get their website online fast, without spending hours tweaking layouts.

#### Best For

It’s best for small businesses, local businesses, consultants, and startups that want a fast, professional website without the hassle of complex design.

#### AI Builder Capabilities

SuperNinja is considered one of the top AI website builders in 2026. Its AI builder handles structure, layout, and initial content using guided prompts. You can customize your site after setup, but its biggest advantage is the speed at which you can launch a site thanks to its built-in AI features.

![](https://www.atlantic.net/wp-content/uploads/2026/03/Wordpress_Blue_logo.png)

### 4. WordPress – Best for Full Customization

WordPress remains the best option for users who want total control over their website. Unlike traditional website builders that operate inside closed systems, WordPress offers an open ecosystem where you control hosting, themes, plugins, and structure. It is noted for its unmatched flexibility, especially with the Gutenberg block editor.

#### Key Features

- Open Ecosystem: Full control over hosting, themes, and integrations.
- Custom Code Freedom: Edit HTML, CSS, PHP, and JavaScript without restrictions.
- Developer Tools: Access to themes, frameworks, and API integrations.
- Support for Complex Sites: Membership platforms, marketplaces, large content hubs.
- Static Sites & Dynamic Sites: Can be configured for fast static output or database-driven dynamic content.
- Advanced Features via Plugins: Extend functionality as needed.

#### Plugins Ecosystem & Ecommerce

One of WordPress’s biggest strengths is its plugin ecosystem. You can add:

- SEO tools
- Security layers
- Performance optimization
- Booking systems
- Learning management systems

If you want to run an online store, WooCommerce helps you build a full e-commerce site with product management, payment options, subscriptions, and [shipping rules](https://www.pluginhive.com/product/woocommerce-table-rate-shipping-pro-plugin/).

Because of this flexibility, WordPress works well for both small businesses and large organizations.

#### Learning Curve & Management

Learning WordPress can take longer than with simple drag-and-drop builders.

You are responsible for:

- Hosting setup
- Security updates
- Plugin management
- Performance optimization

#### Who Should Choose WordPress

WordPress is a good fit for people who need extensive customization and want their site to grow over time.

#### Best For

It’s ideal for developers, agencies, and growing businesses, as well as anyone building complex sites that need custom code and advanced features.

#### AI Builder Capabilities

WordPress itself is not an AI website builder. However, AI functionality can be added through plugins for content generation, SEO assistance, and automation. The platform’s flexibility allows integration of modern tools while maintaining full control over structure and performance.

## How to Choose the Right Website Builder?

With so many options across traditional platforms and AI website builders, choosing the top website builder in 2026 depends on your goals, skills, and budget. Use this quick framework to decide.

### 1. Purpose & Complexity

Start with what you need to build:

- **Portfolio site / Informational sites:** Choose a builder with strong design and image-editing tools.
- **One-page website / Landing page:** Look for fast setup and built-in features.
- **Business website:** Prioritize SEO features, marketing tools, and site performance.
- **Complex websites:** Pick platforms offering custom code, developer tools, and flexible customization options.

### 2. Technical Skills

Match the builder to your experience level:

- **Beginner-friendly tool:** Wix and Squarespace offer true drag-and-drop builders.
- **AI builder setup:** Many platforms can generate a full site from a few prompts.
- **Advanced control:** WordPress requires coding skills and has a higher learning curve.

A clean user interface is especially important for small business owners and local businesses.

### 3. Budget & Builders Cost

Look at the total cost, not just the starting price, when comparing website builders.

- Free plan
- Paid plans start pricing
- Long-term builders cost (apps, ecommerce fees, hosting)
- Scaling costs for multiple websites

Website builder prices can vary a lot. It’s important to think about long-term maintenance and upkeep before making your choice.

### 4. Design & Customization

Consider branding and flexibility:

- Custom layouts
- Customization options
- Custom code and developer tools
- Mobile optimization

Try out the platform’s performance, since some can slow down when you use many apps. Also, make sure you can export your site and that you own your content.

### 5. SEO, Performance & Scalability

To help people find your site in search engines, you’ll need:

- Built-in SEO features
- Marketing tools
- Fast loading speeds aligned with Core Web Vitals
- Ability to scale as your site grows

### 6. AI Capabilities

Today’s AI website builders can:

- Generate layouts and content automatically
- Assist with SEO setup
- Reduce setup time

If you care about speed and automation, pick a builder that offers both helpful AI features and the ability to make manual changes.

## Conclusion

The best website builder for 2026 depends on what you need. Wix is a good choice for most people because it’s flexible and easy to use. If branding is important for your business, Squarespace is worth considering. WordPress is better for complex sites that need custom code or advanced features. For a simple and clean portfolio, Pixpa is also a solid option.

Website builders now combine e-commerce, marketing, and built-in SEO features on one platform. At the same time, site performance and Core Web Vitals matter more for search visibility.

As your website grows, infrastructure becomes important. Providers like[Atlantic.Net](https://www.atlantic.net) support businesses that need reliable cloud hosting for high-traffic sites or scalable projects.


---

# Top 12 NVIDIA GPUs for AI Training & Inference in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/top-nvidia-gpus-for-ai-training-and-inference/ | Published: 2026-03-05 | Updated: 2026-03-06 | Author: Gilad Maayan

## What Are NVIDIA AI GPUs?

NVIDIA provides a range of GPUs (graphics processing units) specifically designed to accelerate artificial intelligence (AI) workloads, including the A100, H100, H200, and newer Blackwell-based platforms such as the B200. These GPUs are built to handle the computational demands of machine learning, deep learning, and large-scale data processing, supporting both model training and high-throughput inference.

more

Selecting the right hardware is often the main challenge in scaling AI. By 2026, the difference between consumer and enterprise GPUs has grown. Most demand is for Blackwell architecture and HBM3e memory, which are best for large-scale inference. Blackwell GPUs, such as the B200 and GB200 NVL72, are tuned for training large language models and handling long-context tasks. Hopper GPUs, such as the H100 and H200, are still common in enterprise settings. Older GPUs like the A100 (with HBM2e) are still used for cost-effective production when large amounts of memory aren’t needed.

NVIDIA also provides workstation and consumer-grade GPUs, such as the RTX 6000 Ada Generation, RTX A6000, and GeForce RTX series. These are not purpose-built data center AI accelerators and rely on GDDR memory rather than HBM, but they can effectively support model experimentation, fine-tuning, and mid-scale inference at a lower cost.

When choosing AI infrastructure, organizations should focus on memory type and how well the system can scale:

- **HBM3e (Blackwell)**: optimized for large-scale LLM training and dense inference
- **HBM3 (Hopper)**: enterprise production AI clusters
- **HBM2e (Ampere)**: mature, cost-controlled deployments
- **GDDR-based RTX GPUs**: developer, workstation, and budget-conscious AI

Although the latest Blackwell systems lead the 2026 performance charts, many businesses still use Hopper-based GPUs such as the H100 and H200. Cloud providers such as Atlantic.Net primarily offer established enterprise GPUs, since next-generation Blackwell platforms are still hard to obtain and are mostly aimed at very large AI operations.

This is part of a series of articles about [**GPU for AI**](https://www.atlantic.net/gpu-server-hosting/gpu-for-ai-platforms-top-gpus-and-key-features-to-consider/).

## Overview of NVIDIA GPU Product Line for AI Use Cases

### NVIDIA Data Center GPUs

NVIDIA’s data center GPUs, such as the A100 Tensor Core GPU, H100, H200, and newer Blackwell-based platforms like the B200 and GB200 NVL72, are engineered for high-performance computing environments. These GPUs provide processing power for AI workloads, allowing data centers to manage vast amounts of data with ease. They enable large-scale model training and accelerate AI and HPC applications.

In 2026, data center GPU selection is largely driven by architecture (Ampere, Hopper, or Blackwell) and memory type (HBM2e, HBM3, or HBM3e). Blackwell GPUs with HBM3e are designed for large-scale LLM training and high-density inference, while Hopper GPUs remain common in enterprise AI clusters. Ampere-based A100 systems continue to operate in mature production environments where infrastructure standardization matters more than peak memory scaling.

Equipped with massive memory capacity and multi-instance GPU capabilities, NVIDIA data center GPUs provide efficiency and scalable performance. They integrate into data center infrastructure, optimizing resource utilization and energy efficiency.

NVIDIA data center GPUs provide the following capabilities:

- **Tensor Cores and transformer acceleration**: Tensor Cores improve computation for AI tasks. These cores optimize matrix multiplications, a crucial operation in deep learning model training, enabling faster processing with less power. They provide efficient handling of AI operations, reducing training times. Tensor Cores also support mixed-precision training, improving performance without sacrificing accuracy. Newer architectures further optimize transformer workloads, which dominate modern generative AI systems.
- **High memory bandwidth and capacity**: NVIDIA AI GPUs can manage large datasets and execute complex AI models. Their high bandwidth ensures data moves rapidly between the processor and memory, which is crucial for performance in computation-heavy tasks like deep learning. The large memory capacity supports the storage and manipulation of large models and datasets. HBM3e in Blackwell systems significantly increases bandwidth and usable memory per GPU, reducing the need for complex model parallelism in large-context inference.
- **CUDA architecture and programming model**: These GPUs provide a platform for parallel computing. CUDA enables developers to harness GPU power for diverse applications, improving performance across a range of computing tasks by parallelizing processes. The programming model enables easy integration and optimization of AI workloads within the NVIDIA ecosystem. CUDA provides extensive library support and community resources.

### NVIDIA Consumer-Grade GPUs

NVIDIA also offers consumer-grade GPUs intended for creative professionals and engineers, offering performance and reliability for demanding applications. These GPUs, particularly the RTX series, are especially optimized for tasks like 3D rendering and simulations, but are also effective for AI workloads.

Consumer and workstation GPUs use GDDR memory rather than HBM and do not support large-scale NVLink clustering as data center models do. However, they remain practical for model experimentation, fine-tuning smaller LLMs, and cost-conscious AI development. High-end consumer GPUs such as the RTX 4090 and RTX 5090 are frequently used by developers building prototypes before migrating to enterprise HBM-based infrastructure.

NVIDIA consumer-grade GPUs support workflows in industries such as media, entertainment, and architecture, and are also widely used by AI developers and engineers.

**Related content: Read our guide to**[**GPU for deep learning**](https://www.atlantic.net/gpu-server-hosting/gpu-for-deep-learning-critical-specs-and-top-7-gpus-in-2025/)

## Common AI Use Cases for NVIDIA GPUs

NVIDIA AI GPUs are useful in several domains, accelerating AI solutions and improving computational capabilities. In 2026, usage patterns are increasingly segmented by architecture and memory type – Blackwell with HBM3e for large-model scaling, Hopper with HBM3 for enterprise production AI, and GDDR-based RTX GPUs for development and experimentation.

### AI Training and Inference in Data Centers

In data centers, NVIDIA AI GPUs drive AI training and inference workloads with greater efficiency. They allow vast datasets to be processed swiftly, enabling quicker AI model development and deployment. These GPUs handle AI tasks reliably, making them suitable for data centers aiming to implement or scale AI services.

For large language model (LLM) training, GPUs with HBM3e memory reduce memory bottlenecks and support larger batch sizes and longer context windows. Blackwell-based systems target frontier-scale training, while Hopper GPUs such as the H100 and H200 are widely used in enterprise AI clusters for high-throughput inference and fine-tuning workloads.

### Edge Computing and Intelligent Devices

NVIDIA GPUs support edge computing applications, optimizing intelligent devices to process data locally. This minimizes latency and boosts performance for real-time applications in autonomous vehicles, healthcare diagnostics, and IoT. By providing on-device AI capabilities, NVIDIA enables resource-efficient computation near where data is generated.

At the edge, memory efficiency and predictable latency are prioritized over maximum TFLOPS. Compact AI models and multimodal inference pipelines are commonly deployed on smaller GPUs optimized for power efficiency rather than on rack-scale clusters.

### Development of AI Applications

NVIDIA AI GPUs empower developers to build and optimize a wide range of AI applications. These GPUs enable efficient training and deployment of machine learning models for tasks such as computer vision, natural language processing, and robotics.

Developers can utilize NVIDIA’s software stack, including CUDA, TensorRT, and the TAO Toolkit, to streamline workflows and improve performance. These tools facilitate model optimization, precision tuning, and integration into production environments.

In practice, many AI teams prototype models on workstations or consumer RTX GPUs before migrating to HBM-based data center infrastructure for production deployment. This tiered approach helps control costs while aligning hardware selection with workload scale and memory requirements.

### Tips from the expert:

![](https://www.atlantic.net/wp-content/uploads/2026/03/Richard-Portrait-white-background.jpg)

#### Richard Bailey

##### Technical Editor

Richard Bailey brings over two decades of IT expertise, from traditional data centers to modern cloud solutions. As the founder of[turbogeek.co.uk](https://turbogeek.co.uk/) and a seasoned writer, he focuses on delivering authoritative content on our hosting services, HIPAA compliance, and related topics.

In my experience, here are tips that can help you better utilize and implement NVIDIA AI GPUs for optimized performance and scalability:

1. **Design workflows with NVLink for multi-GPU scaling:** NVLink interconnects enable GPUs to share memory and collaborate on large-scale models. When using multiple GPUs, design workflows to take full advantage of NVLink bandwidth, such as optimizing memory transfers between GPUs or using fused multi-GPU operations. Ensure memory access patterns are streamlined to avoid bottlenecks in large model training.
2. **Integrate NVIDIA BlueField DPUs for improved data management:** Pairing NVIDIA GPUs with BlueField Data Processing Units (DPUs) offloads data management tasks like storage, security, and networking, freeing up GPU resources for compute-intensive AI workloads. This is especially beneficial in data center environments running large AI models or HPC tasks.
3. **Optimize data preprocessing with RAPIDS:** Use NVIDIA’s RAPIDS toolkit to accelerate data preprocessing directly on GPUs. Moving preprocessing tasks (e.g., ETL, feature engineering) from CPUs to GPUs reduces overall training time. Integrating RAPIDS with frameworks such as Apache Spark can further accelerate distributed workflows.
4. **Deploy GPU clusters with Kubernetes and NVIDIA GPU Operator:** For scalable AI deployments, integrate NVIDIA GPUs with Kubernetes. Use the NVIDIA GPU Operator to automate GPU provisioning, monitoring, and updates in containerized environments. This ensures efficient resource allocation and management across GPU clusters for distributed training or inference.
5. **Implement energy-efficient computing with dynamic GPU utilization:** Optimize energy consumption by dynamically adjusting GPU clock speeds and voltages using NVIDIA tools such as nvidia-smi or the NVIDIA Management Library (NVML). Leverage NVIDIA’s power management APIs to fine-tune performance per workload, reducing operational costs in energy-intensive data centers.

## Best NVIDIA Data Center GPUs for AI in 2026

Below, we highlight the best NVIDIA data center GPUs for AI in 2026, organized around next-generation Blackwell architecture and high-bandwidth HBM3e memory, powering everything from large-scale LLM training to enterprise AI inference.

### 1. GB200 NVL72 (HBM3e & Blackwell)

The [NVIDIA GB200 NVL72](https://www.nvidia.com/en-us/data-center/gb200-nvl72/) is a data center solution for high-performance computing (HPC) and AI workloads. Featuring a rack-scale architecture with 36 Grace CPUs and 72 Blackwell GPUs, it delivers the performance required for trillion-parameter AI models. It offers components like the second-generation Transformer Engine, NVLink-C2C interconnect, and liquid cooling.

The GB200 NVL72 is designed for hyperscale AI training and ultra-large LLM inference, where HBM3e capacity and rack-level GPU interconnect bandwidth are the primary bottlenecks. Unlike single-GPU accelerators, NVL72 operates as a tightly integrated system optimized for massive model parallelism and high-context generative AI workloads.

#### Key features:

- **Blackwell architecture**: Enables exascale computing with performance and efficiency.
- **Second-generation Transformer Engine**: supports FP4 and FP8 precision, accelerating AI training and inference.
- **Fifth-generation NVLink**: Ensures high-speed GPU communication with 130 TB/s bandwidth for efficient multi-GPU operations.
- **Liquid cooling**: Reduces data center energy consumption and carbon footprint while maintaining high compute density.
- **Grace CPU**: Delivers performance with up to 17 TB memory and 18.4 TB/s bandwidth.
- **HBM3e memory scaling**: Designed to support extremely large model states and high-throughput inference with expanded high-bandwidth memory capacity compared to Hopper-based systems.

#### Specifications:

- **FP4 Tensor Core**: 1,440 PFLOPS
- **FP16/BF16 Tensor Core**: 360 PFLOPS
- **FP64**: 3,240 TFLOPS
- **GPU memory bandwidth**: Up to 13.5 TB HBM3e, 576 TB/s
- **Core count**: 2,592 Arm Neoverse V2 cores
- **Memory**: Up to 17 TB LPDDR5X, 18.4 TB/s bandwidth
- **NVLink bandwidth**: 130 TB/s

In practice, GB200 NVL72 systems are targeted at hyperscale AI operators and research institutions rather than typical enterprise deployments. Many enterprise cloud providers, including Atlantic.Net, currently focus on Hopper-class GPUs that balance performance, availability, and production readiness rather than on full rack-scale Blackwell systems.

### 2. B200 (HBM3e & Blackwell)

The [NVIDIA B200](https://www.nvidia.com/en-gb/data-center/dgx-b200/) is a data center GPU built on the Blackwell architecture, made for large-scale AI training and high-density inference. It sits between rack-scale systems like the GB200 NVL72 and Hopper-class GPUs. The B200 is aimed at organizations building advanced AI clusters that need more memory bandwidth and transformer performance than H100 or H200 setups.

The B200 uses Blackwell architecture and HBM3e memory, which are key factors for buyers focused on scaling large language models. It helps reduce memory bottlenecks in training models with trillions of parameters and supports longer context windows for production inference tasks.

#### Key features:

- **Blackwell architecture**: Brings improvements designed for transformer-based AI models and large-scale distributed training.
- **HBM3e memory**: Offers more memory capacity and bandwidth than HBM3-based Hopper GPUs, which boosts performance for memory-heavy LLM workloads.
- **Transformer Engine enhancements**: Support advanced precision formats such as FP4 and FP8, improving training efficiency and inference speed.
- **Next-generation NVLink**: Allows high-bandwidth communication between GPUs in multi-node AI clusters.
- **Energy efficiency improvements**: Built to provide better performance per watt than previous generations in large AI deployments.

#### Specifications:

- **Architecture**: Blackwell
- **Tensor Core Performance (FP16/BF16)**: Up to ~4+ PFLOPS (with sparsity, configuration dependent)
- **FP8 Tensor Performance**: Multi-PFLOPS class (significant improvement over H100)
- **FP4 Support**: Yes (AI acceleration optimized)
- **GPU Memory**: Up to 192GB HBM3e
- **Memory Bandwidth**: ~8 TB/s class (HBM3e)
- **Thermal Design Power (TDP)**: Estimated up to 1000W (SXM configuration dependent)
- **Form Factor**: SXM (data center optimized)
- **NVLink Interconnect**: Fifth-generation NVLink, multi-TB/s aggregate bandwidth.
- **PCIe Support**: PCIe Gen5 compatible

Although the B200 is at the forefront of NVIDIA’s AI plans for 2026, its availability and infrastructure requirements mean that many enterprise cloud providers, such as Atlantic.Net, still focus on Hopper-class GPUs. These GPUs offer a stable ecosystem and reliable performance for production use.

### 3. A100 Tensor Core GPU (Ampere & HBM2e)

The [NVIDIA A100 Tensor Core GPU](https://www.nvidia.com/en-us/data-center/a100/) is a solution to accelerate diverse workloads in AI, HPC, and data analytics. Offering up to 20X performance improvement over its predecessor, the Volta generation, it can scale dynamically, dividing into up to seven GPU instances to optimize resource utilization.

The A100 is based on Ampere architecture and uses HBM2e memory, not HBM3 or HBM3e. While newer Blackwell GPUs dominate searches around “HBM3e” and large-scale LLM scaling, the A100 remains widely deployed in established AI clusters where model sizes fit within 40GB–80GB memory constraints and infrastructure stability is prioritized over next-generation bandwidth gains.

#### Key features:

- **Third-generation Tensor Cores**: Deliver up to 312 TFLOPS of deep learning performance, supporting mixed precision and enabling breakthroughs in AI training and inference.
- **High-bandwidth memory (HBM2e)**: Up to 80GB of memory with 2TB/s bandwidth ensures rapid data access and efficient model processing.
- **Multi-instance GPU (MIG):** Allows partitioning of a single A100 GPU into seven isolated instances, each with dedicated resources, optimizing GPU utilization for mixed workloads.
- **Next-generation NVLink**: Provides 2X the throughput of the previous generation, with up to 600 GB/s interconnect bandwidth for smooth multi-GPU scaling.
- **Structural sparsity**: Improves AI performance by optimizing sparse models, doubling throughput for certain inference tasks.

#### Specifications:

- **FP64 Tensor Core**: 19.5 TFLOPS
- **Tensor Float 32 (TF32)**: 156 TFLOPS (312 TFLOPS with sparsity)
- **FP16 Tensor Core**: 312 TFLOPS (624 TFLOPS with sparsity)
- **INT8 Tensor Core**: 624 TOPS (1,248 TOPS with sparsity)
- **GPU memory**: 40GB HBM2 or 80GB HBM2e
- **Bandwidth**: Up to 2,039 GB/s
- **Thermal design power**: 250W (PCIe) to 400W (SXM)
- **Form factors**: PCIe and SXM4
- **NVLink**: Up to 600 GB/s interconnect
- **PCIe Gen4**: 64 GB/s
- **Supports NVIDIA HGX A100** systems with up to 16 GPUs.

Atlantic.Net prioritizes Hopper-based GPUs like the H100 NVL and balanced L40S accelerators over Ampere A100 systems, aligning with demand for higher memory bandwidth and better LLM inference performance.

### 4. H100 Tensor Core GPU (Hopper & HBM3)

The [NVIDIA H100 Tensor Core GPU](https://developer.nvidia.com/blog/nvidia-hopper-architecture-in-depth/) is built on the NVIDIA Hopper architecture, delivering performance, scalability, and security for workloads. With faster inference and training for large language models (LLMs) than its predecessor, the H100 includes fourth-generation Tensor Cores, Transformer Engine, and Hopper-specific features like confidential computing that redefine enterprise and exascale computing.

#### Key features:

- **Fourth-generation Tensor Cores**: Delivers performance across a range of precisions (FP64, FP32, FP16, FP8, and INT8), ensuring versatile support for LLMs and HPC applications.
- **Transformer Engine**: Specifically designed for trillion-parameter LLMs, offering up to 30X faster inference performance and 4X faster training for GPT-3 models.
- **High-bandwidth memory (HBM3)**: Provides up to 94GB of memory with 3.9TB/s bandwidth for accelerated data access and massive-scale model handling.
- **NVIDIA confidential computing**: Introduces a secure hardware-based trusted execution environment (TEE) to protect data and workloads.
- **Multi-instance GPU (MIG)**: Allows partitioning into up to seven GPU instances, optimizing resource utilization for diverse workloads with improved granularity.
- **Next-generation NVLink**: Features up to 900 GB/s interconnect bandwidth, enabling multi-GPU communication in large-scale systems.

#### Specifications:

- **FP64 Tensor Core**: 67 teraFLOPS
- **TF32 Tensor Core**: 989 teraFLOPS
- **FP16 Tensor Core**: 1,979 teraFLOPS
- **FP8 Tensor Core**: 3,958 teraFLOPS
- **Capacity**: 80GB (SXM) or 94GB (NVL)
- **Bandwidth**: Up to 3.9TB/s
- **Thermal design power**: Up to 700W (SXM) or 400W (PCIe)
- **Form factors**: SXM and dual-slot PCIe
- **NVLink bandwidth**: 900GB/s (SXM) or 600GB/s (PCIe)
- **PCIe Gen5**: 128GB/s
- **Compatible with NVIDIA HGX H100 systems**(4–8 GPUs) and NVIDIA DGX H100 systems (8 GPUs).

While Blackwell GPUs with HBM3e dominate next-generation headlines, the H100 remains a primary enterprise deployment choice due to its strong HBM3 bandwidth, mature ecosystem support, and broad availability in production AI clusters. Providers such as Atlantic.Net deploy H100 NVL configurations for multi-GPU AI workloads, making it a practical option for large-model training, fine-tuning, and high-density inference without requiring next-generation Blackwell infrastructure.

### 5. H200 Tensor Core GPU (Hopper & Blackwell)

The N[VIDIA H200 Tensor Core GPU](https://www.nvidia.com/en-gb/data-center/dgx-h200/) is built on the Hopper architecture. It introduces performance features, including HBM3e memory, improved energy efficiency, and higher throughput for large language models and scientific workloads.

The H200 is strongly associated with HBM3e memory—one of the dominant buyer considerations for large-context LLM inference. While not based on the newer Blackwell architecture, it delivers Blackwell-class memory bandwidth improvements within a Hopper-based platform, making it a practical upgrade path for enterprises not adopting full Blackwell systems.

#### Key features:

- **HBM3e memory**: Equipped with 141GB of HBM3e memory, delivering a bandwidth of 4.8TB/s. This enhancement significantly increases memory capacity and bandwidth compared to the H100, enabling faster data processing for LLMs and HPC applications.
- **Enhanced AI and HPC performance**: Provides up to 1.9X faster Llama2 70B inference and 1.6X faster GPT-3 175B inference compared to the H100, ensuring faster execution of generative AI tasks. For HPC workloads, it achieves up to 110X faster time-to-results over CPU-based systems.
- **Energy efficiency**: Maintains a similar power profile to the H100 while improving performance per watt for memory-intensive AI workloads.
- **Multi-instance GPU (MIG)**: Supports up to seven instances per GPU, allowing efficient partitioning for diverse workloads and optimized resource utilization.
- **Confidential computing**: Hardware-based trusted execution environments (TEE) provide secure handling of sensitive workloads.

#### Specifications:

- **FP64 Tensor Core**: 67 TFLOPS
- **FP32 Tensor Core**: 989 TFLOPS
- **FP16/FP8 Tensor Core**: 1,979 TFLOPS / 3,958 TFLOPS
- **GPU memory**: 141GB HBM3e
- **Memory bandwidth**: 4.8TB/s
- **MIG instances**: Up to 7 (18GB per MIG instance on SXM, 16.5GB on NVL)
- **TDP**: Configurable up to 700W (SXM) or 600W (NVL)
- **Form Factor**: SXM or dual-slot PCIe air-cooled options
- **Interconnect**: NVIDIA NVLink™: 900GB/s, PCIe Gen5: 128GB/s

The H200 offers strong HBM3e scaling without requiring rack-level architectural changes. Many enterprise environments evaluating next-generation memory performance may adopt Hopper-based H100 NVL systems—such as those offered by Atlantic.Net—before transitioning to full Blackwell deployments.

## NVIDIA Consumer & Workstation GPUs Used for AI

Below, we cover NVIDIA consumer and workstation GPUs for AI, designed for desktop model development, fine-tuning, and local LLM inference, featuring high-performance GDDR memory.

### 6. RTX 6000 Ada Generation (Workstation GDDR Memory)

The [NVIDIA RTX 6000 Ada Generation GPU](https://www.nvidia.com/en-gb/products/workstations/rtx-6000/) is engineered for professional workflows, including rendering, AI, simulation, and content creation. Built on the NVIDIA Ada Lovelace architecture, it combines next-generation CUDA cores, third-generation RT Cores, and fourth-generation Tensor Cores to provide up to 10X the performance of the previous generation.

The RTX 6000 Ada uses GDDR6 memory. It is not designed for training trillion-parameter models but is well-suited for model fine-tuning, smaller LLM inference, multimodal workloads, and GPU-accelerated visualization.

#### Key features:

- **Ada Lovelace architecture**: Provides up to 2X the performance of its predecessor for simulations, AI, and graphics workflows.
- **Third-generation RT Cores**: Delivers up to 2X faster ray tracing for photorealistic rendering, virtual prototyping, and motion blur accuracy.
- **Fourth-generation Tensor Cores**: Accelerates AI tasks with FP8 precision, offering higher performance for model training and inference.
- **48GB GDDR6 memory**: Supports large datasets and advanced workloads, including data science, rendering, and AI simulations. However, compared to HBM3e-equipped Blackwell GPUs, memory bandwidth is lower, making it better suited for mid-scale AI rather than hyperscale LLM training.
- **AV1 encoders**: Offers 40% greater efficiency than H.264, improving video streaming quality and reducing bandwidth usage.
- **Virtualization-ready**: Supports NVIDIA RTX Virtual Workstation (vWS) software, enabling resource sharing for high-performance remote workloads.

#### Specifications:

- **Single-precision**: 91.1 TFLOPS
- **RT Core performance**: 210.6 TFLOPS
- **Tensor Core AI performance**: 1,457 TOPS (theoretical FP8 with sparsity)
- 48GB GDDR6 with ECC
- **Bandwidth**: High-speed for demanding applications
- **Max power consumption**: 300W
- **Dimensions**: 4.4” (H) x 10.5” (L) dual-slot, active cooling
- **Display** **outputs**: 4x DisplayPort 1.4
- **Graphics bus**: PCIe Gen 4 x16
- **vGPU profiles supported**: NVIDIA RTX vWS, NVIDIA vPC/vApps

For organizations that do not require HBM-based data center GPUs, accelerators like the L40S—available through providers such as Atlantic.Net—offer a similar balance of AI inference and graphics performance in a cloud environment.

### 7. RTX A6000 (Workstation GDDR Memory)

The [NVIDIA RTX A6000](https://www.nvidia.com/en-gb/products/workstations/rtx-a6000/) is a GPU for advanced computing, rendering, and AI workloads. Powered by the NVIDIA Ampere architecture, it combines second-generation RT Cores, third-generation Tensor Cores, and 48GB of ultra-fast GDDR6 memory to deliver high performance for professionals.

The RTX A6000 uses GDDR6 memory, making it suitable for model development, simulation, and mid-scale AI workloads—but not optimized for large-scale LLM training where high-bandwidth HBM memory is critical. It is often used for experimentation and workstation-based AI before scaling to Hopper or Blackwell data center GPUs.

#### Key features:

- **Ampere architecture: CUDA**Cores deliver double-speed FP32 performance, improving performance for graphics and simulation tasks such as CAD and CAE.
- **Second-generation RT Cores**: Offer 2X the throughput of the previous generation for ray tracing, shading, and denoising, delivering faster and more accurate results.
- **Third-generation Tensor Cores**: Accelerate AI model training with up to 5X the throughput of the previous generation and support structural sparsity to increase inference efficiency.
- **48GB GDDR6 memory**: Scalable to 96GB with NVLink, providing the capacity for large datasets and high-performance workflows. However, memory bandwidth remains significantly lower than HBM3e-based GPUs, which limits performance for large-context LLM inference.
- **Third-generation NVLink**: Enables GPU-to-GPU bandwidth of up to 112 GB/s, supporting memory and performance scaling in multi-GPU configurations.
- **Virtualization-ready**: Allows multiple high-performance virtual workstation instances with support for NVIDIA RTX Virtual Workstation and other vGPU solutions.
- **Power efficiency**: A dual-slot design offers up to twice the power efficiency of previous-generation Turing GPUs.

#### Specifications:

- **CUDA Cores**: High-performance architecture for demanding workloads
- **RT Core throughput**: 2X over previous generation
- **Tensor Core training throughput**: 5X over previous generation
- **48GB GDDR6**with ECC (scalable to 96GB with NVLink)
- **Max power consumption**: 300W
- **Dimensions**: 4.4” (H) x 10.5” (L), dual-slot, active cooling
- **Display outputs**: 4x DisplayPort 1.4a
- **PCIe Gen 4 x16**: Enhanced data transfer speeds
- Supports NVIDIA vPC/vApps, RTX Virtual Workstation, and Virtual Compute Server

For organizations seeking cloud-based alternatives with stronger AI inference performance, GPUs such as the L40S—available from providers like Atlantic.Net—offer advantages in newer architecture and improved AI acceleration compared to Ampere-based workstation cards.

### 8. RTX A5000 (Workstation GDDR Memory)

The [NVIDIA RTX A5000 graphics card](https://www.nvidia.com/en-gb/products/workstations/rtx-a5000/) combines performance, efficiency, and reliability to meet the demands of complex professional workflows. Powered by the NVIDIA Ampere architecture, it features 24GB of GDDR6 memory, second-generation RT Cores, and third-generation Tensor Cores to accelerate AI, rendering, and simulation tasks.

The RTX A5000 uses GDDR6 memory, positioning it for model development, smaller training jobs, and inference workloads that do not require large-context LLM scaling. It is not designed for Blackwell-class AI infrastructure but remains relevant for teams building and testing models before moving to data center GPUs.

#### Key features:

- **Ampere Architecture CUDA Cores**: Delivers up to 2.5X the FP32 performance of the previous generation, optimizing graphics and simulation workflows.
- **Second-Generation RT Cores**: Provide up to 2X faster ray-tracing performance and hardware-accelerated motion blur for accurate, high-speed rendering.
- **Third-Generation Tensor Cores**: Enable up to 10X faster AI model training with structural sparsity and accelerate AI-enhanced tasks such as denoising and DLSS.
- **24GB GDDR6 Memory**: Equipped with ECC for error correction, ensuring reliability for memory-intensive workloads like virtual production and engineering simulations. However, compared to HBM3e-based GPUs, memory bandwidth and total capacity limit performance for training large language models beyond mid-scale parameter sizes.
- **Third-Generation NVLink**: Enables multi-GPU setups with up to 112GB/s interconnect bandwidth and a combined memory capacity of 48GB to handle larger datasets and models.
- **Virtualization-Ready**: Supports NVIDIA RTX Virtual Workstation (vWS) software to transform workstations into high-performance virtual instances for remote workflows.
- **Power Efficiency**: Offers a dual-slot design with improved power efficiency, fitting a wide range of professional workstations.
- **PCI Express Gen 4**: Improves data transfer speeds from CPU memory, improving performance in data-intensive tasks.

#### Specifications:

- **CUDA Cores**: High-performance architecture for advanced workflows
- **RT Core Performance**: 2X over the previous generation
- **Tensor Core Training Performance**: Up to 10X over the previous generation
- 24GB GDDR6 with ECC (scalable to 48GB with NVLink)
- **Max Power Consumption**: 230W
- **Dimensions**: 4.4” (H) x 10.5” (L), dual-slot, active cooling
- **Display Outputs**: 4x DisplayPort 1.4
- **PCIe Gen 4 x16**: Faster data transfers for demanding applications
- Supports NVIDIA vPC, vApps, RTX vWS, and Virtual Compute Server

For organizations requiring cloud-based AI acceleration with higher memory bandwidth, GPUs such as the L40S or H100 NVL—available from providers like Atlantic.Net—offer stronger performance for large-model inference than Ampere workstation cards.

### 9. GeForce RTX 4090 (Consumer GDDR Memory)

The [NVIDIA GeForce RTX 4090](https://www.nvidia.com/en-us/geforce/graphics-cards/40-series/rtx-4090/) is a specialized GPU for gaming and creative professionals powered by the NVIDIA Ada Lovelace architecture. With 24GB of ultra-fast GDDR6X memory, it delivers high-quality gaming visuals, faster content creation, and advanced AI-powered capabilities.

The RTX 4090 is frequently used by independent AI developers and research labs for local model training and inference. However, it uses GDDR6X memory rather than HBM3 or HBM3e, which limits its suitability for large-context LLM training compared to Hopper or Blackwell data center GPUs.

#### Key features:

- **Ada Lovelace Architecture**: Offers up to twice the performance and power efficiency, supporting demanding gaming and creative applications.
- **Third-Generation RT Cores**: Delivers faster ray tracing, enabling realistic lighting, shadows, and reflections.
- **Fourth-Generation Tensor Cores**: Improves AI performance and supports FP8 acceleration for AI-enhanced workflows.
- **24GB GDDR6X Memory**: Supports local AI experimentation, fine-tuning, and smaller-scale inference. For larger language models exceeding 24GB of memory, distributed setups or HBM-based GPUs become necessary.
- **NVIDIA DLSS 3**: AI-driven upscaling technology that boosts frame rates and image quality.
- **NVIDIA Reflex**: Reduces system latency for competitive gaming.
- **NVIDIA Studio**: Accelerates creative workflows with optimized tools such as RTX Video Super Resolution and NVIDIA Broadcast.
- **Game Ready and Studio Drivers**: Provide stability for gaming and professional workloads.

#### Specifications:

- **Core Count**: 16,384 CUDA Cores
- **Base/Boost Clock Speed**: 2,235–2,520 MHz
- **Ray Tracing Cores**: 128
- **Tensor Cores**: 512
- **Theoretical Performance**: 82.6 TFLOPS (FP32)
- **Capacity**: 24GB GDDR6X
- **Memory Bus Width**: 384-bit
- **Bandwidth**: 1,008 GB/s
- **Power Consumption**: 450W
- **Transistor Count**: 76.3 billion
- **Die Size**: 608 mm², 5nm process technology
- **API Support**: DirectX 12 Ultimate, Vulkan 1.3, OpenGL 4.6, OpenCL 3.0
- **Advanced Gaming Features**: Support for Shader Model 6.7

While the RTX 4090 is cost-effective for local AI development, production LLM training, and high-density inference typically require data center GPUs such as the H100 NVL or L40S, which are available through providers like Atlantic.Net.

### 10. GeForce RTX 4080 (Consumer GDDR Memory)

The [NVIDIA GeForce RTX 4080](https://www.nvidia.com/en-us/geforce/graphics-cards/40-series/rtx-4080-family/) is a high-performance GPU to handle demanding gaming and creative workloads. It offers technologies like third-generation RT Cores, fourth-generation Tensor Cores, and AI-accelerated DLSS 3. The RTX 4080 provides strong performance and efficiency for graphics, AI-assisted workflows, and productivity tasks.

The RTX 4080 is commonly used for local AI experimentation, fine-tuning smaller models, and inference workloads under 16GB memory constraints. Because it relies on GDDR6X rather than HBM3 or HBM3e, it is not designed for large-scale LLM training or high-density enterprise inference clusters.

#### Key features:

- **Ada Lovelace Architecture**: Offers improved performance and power efficiency for gaming and creative applications.
- **Third-Generation RT Cores**: Provides faster ray tracing for realistic lighting and reflections.
- **Fourth-Generation Tensor Cores**: Accelerates AI-driven features and supports FP8-based optimizations in compatible workflows.
- **16GB GDDR6X Memory**: Supports high-resolution creative workloads and smaller AI models. However, memory capacity limits its ability to run larger language models without quantization or model sharding.
- **NVIDIA DLSS 3**: Uses AI to boost frame rates and optimize rendering performance.
- **NVIDIA Reflex**: Minimizes system latency for competitive responsiveness.
- **NVIDIA Studio**: Improves creative productivity with optimized drivers and tools.
- **Game Ready and Studio Drivers**: Deliver stable performance across gaming and professional applications.

#### Specifications:

- **CUDA Cores**: 9,728 unified pipelines
- **Base/Boost Clock Speed**: 2,205–2,505 MHz
- **Ray Tracing Cores**: 76
- **Tensor Cores**: 304
- **Theoretical Performance**: 48.7 TFLOPS (FP32)
- **Capacity**: 16GB GDDR6X
- **Memory Bus Width**: 256-bit
- **Bandwidth**: 716.8 GB/s
- **Power Consumption**: 320W
- **Transistor Count**: 45.9 billion
- **Die Size**: 379 mm², 5nm process technology
- **API Support**: DirectX 12 Ultimate, Vulkan 1.3, OpenGL 4.6, OpenCL 3.0
- **Advanced Gaming Features**: Shader Model 6.7

For teams moving from local experimentation to production AI deployment, data center GPUs such as the H100 NVL or L40S—available through providers like Atlantic.Net—offer significantly higher memory bandwidth and multi-GPU scaling compared to consumer-class RTX 4080 systems.

### 11. GeForce RTX 4070 Ti (Consumer GDDR Memory)

The [NVIDIA GeForce RTX 4070 Ti](https://www.nvidia.com/en-gb/geforce/graphics-cards/40-series/rtx-4070-family/) is a high-performance GPU for gamers and creators who require advanced graphics capabilities and efficient performance. Built on the NVIDIA Ada Lovelace architecture, it features third-generation RT Cores, fourth-generation Tensor Cores, and 12GB of ultra-fast GDDR6X memory.

The RTX 4070 Ti is positioned for entry-level AI experimentation and lightweight model inference. With 12GB of GDDR6X memory, it is not suited for large language model training or high-context inference workloads that typically require HBM3 or HBM3e-based data center GPUs.

#### Key features:

- **Ada Lovelace Architecture**: Offers improved performance and power efficiency over the previous generation, supporting gaming and creative applications.
- **Third-Generation RT Cores**: Supports faster ray tracing, improving lighting and rendering realism.
- **Fourth-Generation Tensor Cores**: Enhance AI-driven tasks, including DLSS 3 acceleration and AI-assisted creative workflows.
- **12GB GDDR6X Memory**: Enables smaller AI models, inference testing, and development workloads. However, memory capacity becomes a constraint for modern LLMs beyond small parameter sizes without aggressive quantization.
- **NVIDIA DLSS 3**: Uses AI to increase frame rates and optimize rendering quality.
- **NVIDIA Reflex**: Reduces latency for competitive gaming performance.
- **NVIDIA Studio**: Provides optimized drivers and tools for content creation.
- **Game Ready and Studio Drivers**: Maintain performance stability across gaming and professional applications.

#### Specifications:

- **CUDA Cores**: 7,680
- **Base/Boost Clock Speed**: 2.31–2.61 GHz
- **Ray Tracing Cores**: 93 TFLOPS
- **Tensor Cores (AI)**: 641 AI TOPS
- **Capacity**: 12GB GDDR6X
- **Memory Bus Width**: 192-bit
- **Technology**: Ada Lovelace
- **Ray Tracing and AI Support:** Yes
- **Power Efficiency**: Improved over previous generations
- **DLSS 3.5**: Includes Super Resolution, Frame Generation, Ray Reconstruction, and DLAA

For teams progressing from local experimentation to scalable AI deployment, cloud-based GPUs such as the L40S or H100 NVL—offered by providers like Atlantic.Net—deliver significantly higher memory bandwidth and multi-GPU scaling compared to consumer-class RTX 4070 systems.

### 12. RTX 5090 (GDDR6 & GDDR6X)

The [NVIDIA RTX 5090](https://www.nvidia.com/en-gb/geforce/graphics-cards/50-series/rtx-5090/) is the next step in consumer GPUs, built on NVIDIA’s Blackwell architecture. It sits above the RTX 4090 and is designed for high-end gaming, creative work, and local AI development, offering better compute power and memory performance.

The RTX 5090 uses GDDR6 or GDDR6X memory instead of HBM3e, despite being built on the Blackwell architecture. This makes it strong for local LLM testing, fine-tuning, and multimodal inference, but it is not the best choice for large-scale enterprise AI training, where HBM-based GPUs are preferred.

#### Key features:

- **Blackwell consumer architecture**: Delivers improved AI acceleration and performance-per-watt compared to Ada-generation GPUs.
- **Next-generation Tensor Cores**: Enhance FP8 and AI inference performance for transformer-based workloads and generative AI applications.
- **High-speed GDDR6/GDDR6X memory**: Provides increased bandwidth over previous consumer generations, supporting larger local models and faster data throughput.
- **Ray tracing and AI rendering improvements**: Advance real-time rendering and AI-assisted content creation workflows.
- **Optimized drivers for creators and AI developers**: Supports AI-enhanced tools and content production environments.

#### Specifications:

- **CUDA Cores**: Next-generation Blackwell CUDA architecture (final core count varies by SKU)
- **Base/Boost Clock Speed**: Blackwell-optimized clocks with higher sustained boost performance
- **Ray Tracing Cores**: Fourth-generation RT Cores with improved throughput
- **Tensor Cores (AI)**: Next-generation Tensor Cores with enhanced FP8/AI acceleration
- **Capacity**: GDDR6 / GDDR6X (high-capacity consumer configuration)
- **Memory Bus Width**: High-bandwidth consumer memory interface
- **Technology**: Blackwell (consumer variant)
- **Ray Tracing and AI Support**: Yes
- **Power Efficiency**: Improved performance-per-watt over previous Ada generation
- **AI Features**: Supports DLSS, AI upscaling, and generative AI acceleration

Even with its upgrades, the RTX 5090 remains a consumer GPU and lacks HBM3 or HBM3e memory. For large-scale LLM training, high-density inference, or multi-GPU setups, data center accelerators like the H100 NVL or L40S, which are available from providers such as Atlantic.Net, offer much higher memory bandwidth and scalability.

## Technical Comparison: TFLOPS & Memory Bandwidth (2026)

The technical specifications table compares TFLOPS performance and memory bandwidth across Blackwell, Hopper, and GDDR-based GPUs, helping identify the right architecture for large-scale AI training, LLM inference, and enterprise deployment.

| **GPU** | **Architecture** | **FP16 / AI TFLOPS*** | **Memory Type** | **Memory Bandwidth** |
| --- | --- | --- | --- | --- |
| **B200** | Blackwell | Higher than Hopper (Gen FP8/FP4 optimized) | HBM3e | Higher than H200 (Gen-level increase) |
| **GB200 NVL72** | Blackwell | 360 PFLOPS (FP16/BF16 rack-scale) | HBM3e | 576 TB/s (rack-scale aggregate) |
| **H200** | Hopper | 1,979 TFLOPS (FP16) | HBM3e | 4.8 TB/s |
| **H100 NVL** | Hopper | 1,979 TFLOPS (FP16) | HBM3 | Up to 3.9 TB/s |
| **A100 (80GB)** | Ampere | 312 TFLOPS (FP16) | HBM2e | ~2.0 TB/s |
| **L40S** | Ada | ~1,466 AI TOPS (FP8 w/ sparsity) | GDDR6 | ~864 GB/s |
| **RTX 6000 Ada** | Ada | 1,457 TOPS (FP8 w/ sparsity) | GDDR6 | ~960 GB/s |
| **RTX 4090** | Ada | 82.6 TFLOPS (FP32) | GDDR6X | ~1,008 GB/s |
| **RTX 4080** | Ada | 48.7 TFLOPS (FP32) | GDDR6X | ~716.8 GB/s |
| **RTX 4070 Ti** | Ada | ~40 TFLOPS (FP32 class) | GDDR6X | ~504 GB/s |
| **RTX 5090** | Blackwell (Consumer) | Higher than 4090 (Gen improvement) | GDDR6 / GDDR6X | Higher than 4090 (Gen improvement) |

## Best Practices for Using NVIDIA GPUs in AI Projects

AI teams and organizations can apply the following practices to improve performance and efficiency when working with NVIDIA AI GPUs. In 2026, optimization strategies should also consider memory architecture (HBM3e vs. HBM3 vs. GDDR) and workload type—large-model training, high-density inference, or local development.

### 1. Optimize Workloads with CUDA and cuDNN

CUDA (Compute Unified Device Architecture) is the foundation of NVIDIA’s GPU programming ecosystem, enabling parallel processing for AI workloads. By optimizing workloads with CUDA, developers can leverage GPU acceleration to handle computationally intensive tasks. cuDNN (CUDA Deep Neural Network library) complements CUDA by providing optimized routines for deep learning, such as convolutions and activation functions.

To implement this best practice, ensure the software leverages CUDA’s APIs to distribute workloads across GPU cores. Use cuDNN for critical AI operations to improve performance in model training and inference. Proper tuning of parameters, such as block size and grid dimensions, further boosts efficiency. Profiling tools like NVIDIA Nsight Systems and Nsight Compute can help identify bottlenecks and optimize GPU utilization. On HBM3e-based GPUs, pay particular attention to memory-bound operations, as bandwidth improvements can significantly reduce training and inference latency.

### 2. Utilize NVIDIA’s Pre-Trained Models and SDKs

NVIDIA provides a suite of pre-trained models and SDKs, such as NVIDIA TAO Toolkit and NVIDIA DeepStream, that simplify AI deployment. These resources accelerate development by providing optimized architectures for tasks such as object detection, language processing, and video analytics.

Adopt pre-trained models to save time on training from scratch, especially for common use cases. Fine-tune these models with data to achieve domain-specific performance. Leverage SDKs like TensorRT for inference optimization, DeepStream for video analytics, or Riva for conversational AI. For enterprise deployments on Hopper-based GPUs such as H100 NVL systems, combining TensorRT with multi-GPU scaling improves inference density and throughput.

### 3. Utilize Multi-Instance GPU (MIG) for Resource Partitioning

NVIDIA’s Multi-Instance GPU (MIG) technology allows a single GPU to be partitioned into multiple independent instances, each with its own dedicated resources. This feature is particularly useful for environments with diverse workloads or shared GPU infrastructure.

To maximize the benefits of MIG, assess the workload requirements and allocate GPU instances accordingly. For example, assign separate instances to lightweight inference tasks while reserving larger instances for training or complex computations. Use NVIDIA tools such as NVIDIA GPU Cloud (NGC) and GPU Manager to configure and monitor MIG instances. MIG is especially effective in cloud environments offering H100 NVL GPUs, where workload isolation and resource efficiency directly impact cost control.

### 4. Leverage TensorRT for Optimized Inference

TensorRT is NVIDIA’s high-performance deep learning inference optimizer and runtime. It enables developers to maximize inference efficiency by optimizing models for deployment on NVIDIA GPUs. TensorRT reduces latency, minimizes memory usage, and boosts throughput through techniques such as layer fusion and precision calibration.

To implement this practice, convert trained models into TensorRT-optimized formats using its APIs. Pay attention to precision settings, such as FP16 or INT8, to balance performance and accuracy. Use TensorRT with the NVIDIA Triton Inference Server for scalable deployment across data centers and edge devices, ensuring consistent, high-speed AI inference. HBM3e-equipped GPUs further improve large-batch inference performance when paired with optimized precision settings.

### 5. Apply Mixed-Precision Training

Mixed-precision training leverages lower-precision formats (e.g., FP16 or BF16) alongside higher-precision formats (FP32) to accelerate computations without sacrificing model accuracy. NVIDIA GPUs, equipped with Tensor Cores, are optimized for mixed-precision operations.

To enable mixed-precision training, use frameworks like TensorFlow or PyTorch with automatic mixed-precision (AMP) support. Ensure the code utilizes Tensor Cores for compatible operations and monitor performance gains. Mixed-precision training reduces memory usage and speeds up computations, useful for scaling AI training on NVIDIA GPUs. On Blackwell and Hopper architectures, advanced precision modes (such as FP8) can further increase throughput for transformer-based workloads when accuracy thresholds permit.

## Next-Gen Dedicated GPU Servers from Atlantic.Net, Accelerated by NVIDIA

Experience high-performance AI infrastructure with dedicated cloud servers equipped with the NVIDIA accelerated computing platform.

Choose from the NVIDIA L40S GPU and NVIDIA H100 NVL to power generative AI workloads, train large language models (LLMs), and run high-throughput inference with strong memory bandwidth and multi-GPU scaling. While next-generation Blackwell GPUs with HBM3e lead frontier AI research, Atlantic.Net focuses on production-ready Hopper-based H100 NVL systems and balanced L40S accelerators that deliver reliable enterprise AI performance today.

High-performance GPUs are used across scientific research, 3D graphics and rendering, medical imaging, climate modeling, fraud detection, financial modeling, and advanced video processing.

[Learn more about Atlantic.net GPU server hosting.](https://www.atlantic.net/gpu-server-hosting/)


---

# Dedicated Server Hosting: Features, Benefits & Top Providers

> URL: https://www.atlantic.net/dedicated-server-hosting/dedicated-server-hosting-features-providers/ | Published: 2026-03-06 | Updated: 2026-03-10 | Author: Robert Agar

Companies have multiple options when choosing a cloud hosting plan that aligns with their business requirements. Some organizations are satisfied with the performance available with economical shared hosting services. However, businesses that require higher performance, stronger security, or more customization options may opt for dedicated server hosting. This article provides the information you need to find a dedicated hosting provider that fits your unique business requirements. We will examine the business benefits of dedicated hosting, which can provide a company with a significant competitive edge. Then, we discuss the features and services to expect from a reliable dedicated hosting plan. Finally, we offer some recommendations for the top dedicated hosting providers.

## What Are the Benefits of Dedicated Server Hosting?

Organizations that select a dedicated hosting solution obtain complete control over an entire server. They do not need to be concerned about resource sharing with other server tenants that may impact their applications or online business. A dedicated server offers customers a range of benefits that cannot be replicated with a shared hosting plan.

### Predictable performance

Companies achieve predictable, high performance due to the lack of resource contention from other tenants. Teams have total and consistent access to the physical server’s CPU, RAM, internal storage, and network throughput. Businesses running compute-intensive applications, multiple websites, high-traffic databases, or latency-sensitive workloads can benefit from the consistent performance of dedicated hosting.

### Enhanced security

Organizations can enhance their security posture with dedicated hosting. The physical isolation of their dedicated server eliminates the risk of a cross-tenant attack surface. Teams do not need to worry about the threat of a compromised shared hypervisor or about other tenants’ poor security measures. Companies can implement custom firewall rules and security controls that may not be available in a shared cloud server environment. Businesses in regulated industries or handling sensitive data benefit from the advanced security features of dedicated servers.

### Improved reliability

Businesses obtain improved reliability and stability by leveraging dedicated resources rather than sharing computing power with other customers. A dedicated server places fewer variables outside of your control and reduces the risk of degraded performance or availability. Dedicated web hosting services are ideal for customers running mission-critical web applications that require consistent uptime.

### Complete administrative control

Teams have complete administrative control over a dedicated server. This control includes full root access and the ability to install any operating system and software they desire. Root access enables customers to customize server resources to align with business requirements and exercise a level of control typically not possible with shared web hosting.

### Customized hardware configuration

Most dedicated hosting providers offer custom solutions and hardware configurations to meet customers’ unique requirements. Teams can tailor the server to support specific workloads, optimizing performance and driving cost efficiency. For example, they may need the speed of NVMe SSD storage for read/write-intensive applications, or modern GPUs for AI and ML workloads. A business may need a large amount of RAM to keep data in memory for faster processing.

### Regulatory compliance and data residency

Companies can meet regulatory compliance standards with dedicated hosting services. Regulations such as HIPAA require that sensitive patient data be stored in a separate and isolated environment to enhance security. Teams can more easily implement and demonstrate compliance by strengthening access controls and implementing complete logging for audit evidence.

Organizations can address data residency requirements with dedicated hosting. They can enter into a plan with a hosting provider that ensures the server is located in a specific geographic region. Controlling data residency may not be possible with a shared hosting solution leveraging a provider’s multiple data centers.

### Predictable long-term costs

Businesses typically incur higher upfront costs for dedicated hosting than for shared hosting. However, monthly costs are fixed and predictable, making budgeting easier. Companies can avoid unexpected usage bills from pay-as-you-go hosting models.

## How to Identify Reliable Dedicated Hosting Services

Decision-makers face a difficult choice when selecting a dedicated hosting plan. Many cloud service providers offer dedicated hosting services with a variety of plans. Organizations should consider the following factors when choosing their hosting provider.

### Data center quality

Providers must operate high-quality Tier III or Tier IV data centers featuring enterprise-grade hardware and redundant power supplies. Ideally, the hosting company will support multiple data centers in geographically diverse locations to minimize network latency for dedicated server customers.

### High uptime guarantees

Companies that use dedicated servers for business-critical applications cannot afford downtime. Dedicated hosting customers should insist on uptime guarantees of at least 99.95% by obtaining service-level agreements (SLAs) from their providers.

### A strong customer support team

Customers should expect responsive 24/7/365 customer support to address hardware or software issues with their hosting account quickly. Reliable providers offer multiple communication channels, such as phone support or online chat, for immediate response. Technical support should be provided by in-house experts, with well-defined escalation paths to engage senior personnel as needed.

### Managed versus self-managed hosting

Businesses may need the performance and security of a dedicated server, but lack the IT skills to manage it effectively. Customers should be able to choose between self-managed dedicated hosting and managed support, with access to the provider’s technical teams. Managed services may include guided server setup and management to help customers optimize their dedicated servers.

### Security and compliance capabilities

Organizations should look for providers with reliable security features, including DDoS protection and next-generation firewalls. Providers should demonstrate that they operate secure facilities with SOC 2 and SOC 3 certifications. Businesses processing regulated data must ensure the provider offers compliant hosting options and support.

### Backup and recovery

Dedicated hosting providers must protect customer data and uptime with automatic backups and fast recovery times. They can support business continuity with disaster recovery plans and off-site or redundant backups. A lack of backups presents a reliability risk that does not align with the needs of dedicated server customers.

## Top Dedicated Hosting Providers

Decision-makers can be confident when engaging the services of the following top dedicated hosting providers.

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

### [Atlantic.Net](https://www.atlantic.net/dedicated-server-hosting/)

Atlantic.net has provided dedicated hosting services to customers for over 30 years. The company offers a variety of advanced hosting plans to fit virtually any business requirements. Servers are equipped with dedicated IP addresses and free SSL certificates to ensure a secure website.

These features make Atlantic.Net an excellent choice in dedicated server hosting:

- Upgrade options such as managed monitoring, storage upgrades, and the Plesk dedicated server control panel.
- Dedicated servers powered by Intel and AMD CPUs or modern GPUs;
- 100% uptime guarantee;
- U.S.-based 24/7/365 customer support via phone and email;
- HIPAA and PCI-compliant servers to meet regulatory requirements.

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

### [Azure](https://learn.microsoft.com/en-us/azure/virtual-machines/dedicated-hosts)

Microsoft Azure’s Dedicated Host service provides customers with physical servers that can host multiple virtual machines assigned to a single Azure subscription. Customers can utilize their own Windows and SQL licenses to control costs. Users can optimize workloads by selectively choosing which applications share physical server resources.

Azure’s dedicated hosting features include:

- Provisioning dedicated hosts within specific regions or availability zones;
- Ultra disk support offering higher IOPS and disk throughput;
- Scheduling Azure maintenance windows to minimize service impacts.

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

### [Amazon Web Services](https://aws.amazon.com/ec2/dedicated-hosts/)

Amazon EC2 dedicated hosts are physical servers reserved for use by a single customer. Teams can use existing, eligible software licenses to improve cost efficiency while leveraging the flexibility and resilience of AWS infrastructure. Organizations can meet compliance requirements with the control and isolation of a single physical server.

Outstanding AWS features include:

- Tracking software licenses with the AWS License Manager;
- Scheduling server maintenance to fit operational needs;
- Affinity, which ensures VMs run on the same physical server after planned interruptions.

![](https://www.atlantic.net/wp-content/uploads/2025/12/interserver.png)

### [InterServer](https://www.interserver.net/dedicated/)

InterServer’s dedicated hosting services are fully customizable to meet customer requirements. Customers can define firewall rules from an intuitive interface for fine-grained network control. Business websites load fast due to server, network routing, and security optimization.

Features of InterServers offerings include:

- 30-day money-back guarantee on dedicated hosting plans;
- 24/7 support via phone, chat, or a ticketing system;
- 99.9% uptime SLAs.

![](https://www.atlantic.net/wp-content/uploads/2025/08/ionos-logo.png)

### [IONOS](https://www.ionos.com/servers/dedicated-servers)

IONOS provides dedicated servers with website performance suitable for e-commerce hosting or business-critical applications. The servers use RAID technology to keep customer data safe and accessible. Companies can choose from Intel and AMD CPUs and GPUs for advanced AI and ML workloads.

IONOS features include:

- Unmetered data transfer;
- Dedicated servers with up to 80 TB of storage;
- Advanced firewalls and DDoS protection.

![](https://www.atlantic.net/wp-content/uploads/2025/12/kamatera-logo-1.png)

### [Kamatera](https://www.kamatera.com/products/virtual-dedicated-servers/)

Kamatera provides dedicated virtual private server services that offer better performance than traditional VPS hosting. Companies enjoy consistent performance by dedicating CPU cores and RAM to specific workloads. The environment is protected by multi-layered security featuring advanced DDoS protection, network isolation, and intuitive firewall management.

Kamatera’s dedicated virtual servers feature:

- 99.95% uptime guarantees;
- 24/7 customer support;
- Unlimited scaling to address business growth.

## Conclusion

Organizations can achieve enhanced performance and security with dedicated server hosting services. Prospective customers should carefully evaluate providers to find a hosting company that has the hardware and features their business needs. Our list of top dedicated hosting providers offers decision-makers a solid starting point for finding the right dedicated hosting solution.


---

# HIPAA-Compliant Hosting for Clinics and Startups

> URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-hosting-clinics-startups/ | Published: 2026-03-08 | Updated: 2026-06-04 | Author: Robert Agar

## HIPAA-Compliant Hosting for Clinics and Startups

Healthcare providers must implement effective measures to safeguard the sensitive patient data they collect and process. All U.S. healthcare organizations must comply with the data privacy and security requirements of the Health Insurance Portability and Accountability Act (HIPAA). Healthcare clinics and startups must maintain HIPAA compliance to ensure the privacy and security of their protected health information (PHI) and electronic protected health information (ePHI (electronic Protected Health Information)). Achieving full compliance means addressing all aspects of HIPAA, including internal policies, staff training, risk assessments, and technical configurations—not just selecting the right hosting provider.

Healthcare companies can address HIPAA compliance with in-house data centers. This approach requires a substantial financial investment in infrastructure and high-level technical expertise. They can also leverage HIPAA-compliant hosting options from qualified, certified cloud providers. HIPAA compliance involves more than just encryption; it requires a wide range of security measures and documentation.

## Introduction to HIPAA Compliance

HIPAA compliance is essential for healthcare organizations seeking to protect the confidentiality, integrity, and availability of electronic protected health information (ePHI). The Health Insurance Portability and Accountability Act (HIPAA) establishes strict national standards for safeguarding sensitive patient data, making compliance with these standards a legal requirement for healthcare providers, insurers, and clearinghouses.

Selecting a HIPAA-compliant hosting provider is a critical step in this process, as it ensures that your digital infrastructure meets the necessary technical safeguards and access controls to protect protected health information. By partnering with a hosting provider that offers reliable compliance support and understands the complexities of the Accountability Act, healthcare organizations can confidently manage sensitive patient data and maintain the trust of their patients and partners.

## Why Choose HIPAA-compliant Web Hosting?

Healthcare startups and clinics often lack the in-house technical expertise or financial resources to implement and maintain an IT environment that meets HIPAA requirements. Digital health startups can avoid these obstacles and ensure HIPAA compliance with a compliant hosting solution. The following are some of the primary benefits of working with a cloud hosting provider.

- Organizations can reduce the legal risks associated with handling sensitive patient data by working with a HIPAA-compliant hosting provider. The cloud service provider (CSP) will deliver a HIPAA-compliant infrastructure and implement the required security measures to protect ePHI and avoid potentially expensive violations.
- Companies can leverage managed services from qualified providers to address skill gaps and achieve operational benefits by automating healthcare workloads. Organizations can focus on core business activities with a managed hosting provider handling the IT environment.
- Healthcare businesses enhance customer trust by partnering with a certified, HIPAA-compliant hosting provider. New and returning patients can be confident that their sensitive data is being handled securely.
- Companies can achieve long-term cost efficiency with a HIPAA hosting solution. Businesses eliminate the costs of maintaining and staffing an in-house IT environment to ensure HIPAA compliance.

## Benefits of Compliance

Investing in HIPAA-compliant hosting brings significant advantages to healthcare organizations. First and foremost, it strengthens data security, reducing the risk of unauthorized access or breaches involving sensitive patient data.

This heightened protection not only helps healthcare providers avoid costly penalties but also builds patient trust by demonstrating a commitment to privacy and compliance. Additionally, compliant hosting streamlines the secure exchange of health information between providers, insurers, and patients, supporting better care coordination and improved outcomes.

By maintaining HIPAA compliance, healthcare organizations can also enable new business opportunities, attract partnerships, and differentiate themselves in a competitive market—all while ensuring the ongoing integrity and confidentiality of their data.

## HIPAA Eligible Services

HIPAA-eligible services are cloud-based solutions that can be configured to meet HIPAA compliance requirements, provided they are used appropriately by healthcare organizations. These services typically include secure storage, computing resources, and database management tools designed to safeguard ePHI.

When evaluating a hosting provider, it is crucial to confirm that they offer HIPAA-eligible services and have a proven track record of supporting healthcare organizations. This ensures that the provider understands HIPAA requirements and can offer the necessary guidance and technical support to help you maintain compliance throughout your operations.

## Essential Features of HIPAA-Compliant Hosting Providers

Healthcare organizations need to verify that their provider offers HIPAA-eligible services that protect their ePHI. Dedicated servers are also a popular hosting option, providing physical separation, performance stability, and enhanced security, making them suitable for clinics and startups with stringent security or compliance requirements.

The following are key features of HIPAA-compliant hosting providers.

Vulnerability management is a critical aspect of maintaining compliance, requiring providers to have documented processes for risk assessment and ongoing vulnerability assessments. Healthcare hosting providers must conduct ongoing vulnerability assessments and support secure configurations to ensure the highest level of protection for sensitive healthcare data.

### Infrastructure certifications

The provider should demonstrate HIPAA compliance and a secure infrastructure by obtaining SOC 2 and SOC 3 certifications for their data centers that process ePHI. A HIPAA-compliant hosting environment should be audited by qualified third parties to ensure they meet security and regulatory standards, including HITECH compliance.

### HIPAA Business Associate Agreement (BAA) (BAA)

Customers must obtain a signed BAA from their hosting partner. The BAA defines the nature and limitations of the provider’s interaction with ePHI. BAAs also outline the security measures used to implement HIPAA safeguards. The lack of a BAA constitutes a violation, resulting in a non-compliant IT environment.

### Administrative safeguards

The provider must implement policies, procedures, and controls to protect ePHI that include:

- Assigning an individual or team with clear HIPAA responsibility to oversee HIPAA compliance, especially for organizations integrating with EHR or EMR systems;
- Performing risk assessments, technical, and non-technical evaluations to identify compliance gaps;
- Developing an access management framework, including role-based cont**r**ols;
- Providing employees with security awareness training;
- Creating contingency and incident response plans, including breach notification procedures;
- Implementing data backup and disaster recovery procedures.

### Physical safeguards

Physical security is required to protect healthcare systems, equipment, and devices that contain ePHI. HIPAA’s physical safeguards include:

- Monitoring and controlling physical access to health systems;
- Defining acceptable workstation functions;
- Implementing secure device and media disposal and reuse.

### Technical safeguards

Under HIPAA rules, providers must implement technical safeguards to secure systems that handle ePHI. These safeguards include:

- Access controls such as unique user identification and emergency access procedures;
- Audit readiness controls, which include retaining audit logs to demonstrate compliance;
- Data integrity controls to ensure ePHI is not improperly altered;
- Authenticating users and entities before granting access to ePHI;
- Encrypting data to secure it during transmission.
- Intrusion prevention and intrusion detection systems are used to prevent and identify unauthorized access attempts.

### Data protection and disaster recovery capability

Healthcare organizations must ensure PHI is available as a primary compliance responsibility. A HIPAA-compatible hosting solution provides encrypted backups, point-in-time restore, and disaster recovery capabilities to support business continuity.

## How to Select the Right Hosting Provider for Your Business

Healthcare organizations should consider the following points when choosing a HIPAA hosting solution.

- The provider must be willing to sign a complete BAA. Customers should immediately exclude vendors that will not sign a BAA.
- Prospective providers must effectively address all administrative, physical, and technical safeguards to protect ePHI. Vendors that fail to implement the necessary safeguards should not receive serious consideration.
- Decision-makers should look for immutable, tamper-proof backups that are not susceptible to compromise by sophisticated ransomware attacks.
- Providers must support data security with measures such as intrusion detection systems to prevent threat actors from entering the IT environment.
- The provider should offer a HIPAA-compliant infrastructure that aligns with your business requirements and objectives. Healthcare startups should look for providers that offer scalable, HIPAA-compliant services to support future growth.
- Organizations should look for providers offering HIPAA support, including enterprise-grade security, a signed BAA, and advanced security tools tailored for healthcare providers handling protected health information (PHI).

Ongoing support is critical for HIPAA-compliant hosting providers, including system updates and 24/7 incident response.

## Strategic Considerations

Choosing the right HIPAA-compliant hosting provider requires careful evaluation of several strategic factors. Healthcare organizations should prioritize providers with extensive experience supporting healthcare workloads and a deep understanding of compliance requirements. Look for hosting providers that offer reliable access controls, complete disaster recovery and business continuity plans, and detailed audit logs for compliance reporting. Scalability and flexibility are also important, ensuring your hosting environment can grow with your organization’s needs. Finally, assess the provider’s commitment to ongoing security updates and compliance support, so you can be confident your protected health information remains secure as regulations and threats evolve.

## Common Compliance Mistakes

Many healthcare organizations encounter common pitfalls when pursuing HIPAA compliance with a hosting provider. One frequent mistake is failing to secure a signed BAA (BAA), which is essential for defining compliance responsibilities and ensuring legal protection. Organizations may also overlook the importance of conducting regular risk assessments or providing adequate HIPAA training for staff. Another error is assuming that all cloud providers are automatically HIPAA-compliant, without verifying their credentials or understanding their compliance obligations. To avoid these issues, healthcare organizations should thoroughly vet potential hosting providers, ensure all compliance responsibilities are clearly defined, and maintain ongoing vigilance to protect sensitive patient data.

## Reliable HIPAA-compliant Hosting Providers

The CSPs listed below all offer HIPAA-compliant web hosting solutions that address the needs of digital health startups and healthcare clinics. Healthcare company decision-makers should evaluate these providers’ offerings when seeking a HIPAA-compliant, secure hosting partner.

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

### [Atlantic.Net](https://www.atlantic.net/hipaa-compliant-hosting/)

Atlantic.Net has been offering customers HIPAA-compliant hosting solutions for over 30 years. The company’s technical teams leverage their experience and expertise to deliver managed services that help customers meet their HIPAA responsibilities. Their hosting solutions support Linux and Windows environments and offer a variety of plans to meet their customers’ business objectives.

These are some of the top features of Atlantic.Net’s HIPAA hosting options:

- Dedicated hosting environments that meet all HIPAA compliance requirements;
- 100% uptime SLAs to maintain ePHI availability;
- Multiple high-quality data centers for enhanced resilience.
- Daily onsite and offsite backups to protect data resources;
- Scalable, low-latency, and redundant Secure Block Storage to support mission-critical healthcare applications;
- Intrusion detection to prevent unauthorized access to ePHI.

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

### [Google Cloud Platform](https://cloud.google.com/security/compliance/hipaa)

The Google Cloud Platform offers HIPAA-compliant hosting that stresses the shared responsibilities of the provider and customer in maintaining compliance. Google supports most of its cloud services and products as HIPAA-compliant solutions. The company will enter into a BAA with healthcare organizations and recommends that customers refrain from using Google products that the BAA does not explicitly cover.

Outstanding features of the Google Cloud Platform include:

- Annual security audits against standards such as ISO 27001 and SSAE 16;
- Google Cloud BAAs that cover the company’s entire cloud infrastructure;
- Multiple region service redundancy
- Similar pricing for HIPAA-compliant and standard hosting solutions.Cloud Healthcare API, which facilitates secure integration of healthcare data formats like FHIR and HL7.

Google Cloud Platform offers full HIPAA support and BAAs (BAAs), but requires careful configuration.

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

### [Microsoft Azure](https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-hipaa-us)

Azure offers HIPAA-compliant hosting that may appeal to healthcare startups that are heavily invested in Microsoft products. The platform is audited for ISO/IEC 27001 and HITRUST Common Security Framework (CSF) certifications and is covered by FedRAMP assessments. Azure’s healthcare-related features and data storage solutions are HIPAA-eligible. Still, clinics and startups need to verify the HIPAA eligibility of the specific services they plan to use. Customers with Linux environments are responsible for securing the virtual machines and applications running on Azure’s HIPAA-compliant infrastructure.

Features of Microsoft Azure include:

- A compliance dashboard for an aggregated view of the environment.
- Preserving HIPAA compliance by not replicating Office 365 data outside of designated regions;
- Azure OpenAI for text-based interaction with production systems;
- Targeted support for Microsoft products such as Office 365 and Windows 365.

Microsoft Azure provides HIPAA-eligible services and requires proper configuration to ensure compliance.

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

### [Amazon Web Services](https://aws.amazon.com/compliance/hipaa-compliance/)

Amazon Web Services (AWS) is a leading cloud hosting provider and offers HIPAA-compliant solutions that address the needs of healthcare startups. The company offers a complete BAA that covers the vast majority of available AWS cloud services. All features of HIPAA-eligible services can be used to process, maintain, and transmit ePHI.

These features support AWS’ HIPAA-eligible services:

- Aligning its HIPAA risk management program with FedRAMP and NIST 800-53;
- End-to-end data encryption using the AWS Key Management Service (KMS);
- Physically secure data centers with 24/7 monitoring;
- Network isolation to protect ePHI from other cloud tenants.

![](https://www.atlantic.net/wp-content/uploads/2025/12/rackspace_logo.png)

### [Rackspace](https://www.rackspace.com/industry/healthcare)

Rackspace provides healthcare companies with a compliant hosting environment backed by an experienced technical team. The company offers flexible, customizable solutions to meet the needs of startups and large healthcare providers—their AI Launchpad for Healthcare streamlines testing and deployment of AI workloads.

Features of Rackspace’s compliant solutions include:

- 99.999% uptime SLAs to meet availability requirements;
- Offline backups with immutable storage and air-gapped cyberthreat scanning;
- Machine learning tools to detect and minimize backup corruption;
- A full slate of managed services to provide compliance support.

![](https://www.atlantic.net/wp-content/uploads/2026/03/convesio.png)

### [Convesio](https://convesio.com/features/hipaa-compliant-wordpress-hosting/)

Convesio specializes in HIPAA-compliant WordPress hosting for healthcare professionals. It offers an excellent platform for clinics and startups supporting WordPress and WooCommerce websites. The company uses Docker containers to isolate customer sites and resources, enhancing security.

Convesio provides customers with these valuable features:

- Implementing malware prevention to protect the website from threat actors.
- Managing WordPress updates to maintain performance and security;
- End-to-end data encryption;
- Detailed audit logs to monitor access to sensitive data.

## Conclusion

Healthcare organizations that must comply with HIPAA must carefully select a cloud hosting provider. We have examined the benefits of a HIPAA-compliant cloud hosting solution and discussed the features customers should look for when choosing a provider. The CSPs listed above can all address the HIPAA compliance requirements of a healthcare clinic or startup. Decision-makers should evaluate these offerings and select a cloud provider that supports their business vision and protects sensitive ePHI.

 


---

# Affordable HIPAA-Compliant Hosting in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/affordable-hipaa-compliant-hosting/ | Published: 2026-03-09 | Updated: 2026-06-23 | Author: Dr. Tehseen Zia

Healthcare data is more valuable, more vulnerable, and more heavily regulated than ever. For any organization handling [electronic Protected Health Information](https://en.wikipedia.org/wiki/Protected_health_information) (ePHI) in 2026, security is the baseline cost of doing business. A single [breach](https://secureframe.com/blog/healthcare-data-breaches) can result in millions of dollars in federal fines, trigger grueling investigations, and permanently undermine patient trust. Yet, many healthcare startups and small medical practices still believe that HIPAA-compliant hosting is either prohibitively expensive or reserved for massive hospital systems.

The reality is that affordable HIPAA-compliant hosting exists. Finding it requires understanding what compliance looks like in practice, identifying hidden costs, and separating legitimate providers from those offering empty promises. This guide breaks down the current state of HIPAA-compliant infrastructure and the best options for your organization.

## The Evolution of Healthcare Infrastructure

A decade ago, healthcare IT was a closed-door operation. Small organizations ran in-house servers, and compliance was largely a matter of paperwork—if you locked the server room and used basic encryption, you were “secure.” That era ended as ransomware became a professionalized global industry.

Generic cloud platforms emerged as a powerful alternative, but they introduced a “shared responsibility” hurdle. While major providers offer the tools for compliance, the burden of configuration—managing TLS 1.3 encryption, audit logging, and access controls—falls entirely on you. For a lean telehealth startup, this technical debt can be overwhelming.

HIPAA-compliant hosting providers solved this by building infrastructure specifically for healthcare from the ground up. Key features that define a legitimate compliant solution include:

- **Physical Security:** Servers housed in [SOC 2](https://secureframe.com/hub/soc-2/what-is-soc-2) or SOC 3-certified facilities with biometric access controls.
- **Network Safeguards:** Fully [managed firewalls](https://www.atlantic.net/managed-services/firewall/) and Intrusion Detection Systems ([IDS](https://www.geeksforgeeks.org/ethical-hacking/intrusion-detection-system-ids/)) monitored 24/7.
- **Data Integrity:** Automated, encrypted backups distributed across different geographic regions.
- **Accountability:** Detailed audit logs capturing every instance of data access or modification.

In 2026, hosting is about “compliant availability.” Patient care systems cannot afford downtime, and clinicians need secure systems without sacrificing performance.

## Debunking the Trade-Off: Affordability vs. Security

There is a misconception that compliance requires a massive budget. While [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) costs more than a $10 “unlimited” plan, the savings found in non-compliant options are an illusion.

## The Danger of Shared Hosting

[Shared hosting](https://www.cnet.com/tech/services-and-software/what-is-shared-hosting/), in which hundreds of customers share a single physical server and OS, cannot meet [HIPAA requirements](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/). It lacks true isolation; if one neighbor is compromised, your data is exposed. HIPAA requires dedicated infrastructure, provided either through a dedicated physical server or a strictly isolated [Virtual Private Server](https://www.atlantic.net/vps-hosting/virtual-private-cloud-server-a-comprehensive-guide/) (VPS) with guaranteed resources.

## The True Cost of a Breach

When evaluating price, weigh the monthly fee against the [cost of failure](https://hipaauniversity.com/blog/hipaa-violation-fines-and-penalties/). In 2026, HIPAA penalties can exceed $100 per record, with an annual cap of $1.5 million. Beyond fines, your organization faces:

- **Legal Fees:** State-level lawsuits and class-action filings.
- **Forensics:** The high cost of investigators to pinpoint the breach source.
- **Reputation Loss:** Patients rarely return to a provider whose private data is lost.

Managing security patches and documentation on generic infrastructure often costs more in engineering hours than simply paying for a purpose-built HIPAA platform.

## Key Considerations for HIPAA-Compliant Hosting Solutions

When you start evaluating HIPAA-compliant hosting, the first thing you will notice is that there is no one-size-fits-all answer. You have to weigh cost against control and decide how much management you want to take on yourself.

Some organizations prefer dedicated physical servers. They want complete control and have the internal expertise to manage it. Others find virtual private servers more suitable for dedicated resources without the dedicated price tag. If your team is small, managed cloud platforms can handle server maintenance and much of the compliance paperwork for you.

But regardless of which path you take, there are a few things that are not negotiable. These are the features that separate a truly compliant hosting from one that merely offers a [HIPAA Business Associate Agreement (BAA)](https://ironcladapp.com/journal/contracts/business-associate-agreement) checkbox.

- 
  - **The BAA (BAA)**: It is a legal contract, not a checkbox. It defines who is responsible for what in protecting patient data. Before you sign anything, verify that the provider actually signs their BAA.
  - **Encryption everywhere**: This means [PHI](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) must be encrypted both at rest and in transit. It should be part of the standard offering. If a provider tries to sell you encryption as an expensive add-on, that is a red flag.
  - **Access and audit controls**: This means [multi-factor authentication](https://www.ibm.com/think/topics/multi-factor-authentication) should be required for every admin login. You also need detailed audit logs that tell you who accessed what, when, and from where. When something goes wrong, those logs are your only way to reconstruct what happened.

- **Reliability and real support.** Geographic redundancy protects your data against regional outages. Backup retention policies must align with record-keeping requirements. Crucially, evaluate the provider’s support responsiveness. In healthcare, response times measured in hours can affect patient care.

## Top HIPAA-Compliant Hosting Providers in 2026

The market now offers several credible options for organizations seeking both compliance and cost control. Each takes a different approach.

### Premium Enterprise Providers

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

**Atlantic.Net**

[Atlantic.net](https://www.atlantic.net/hipaa-compliant-hosting/) positions itself for teams that need clear pricing and practical compliance tools without enterprise budgets. Their [platform](https://www.atlantic.net/announcements/atlantic-net-launches-one-click-hipaa-compliant-cloud-hosting/) combines BAAs, encrypted storage, automated backups, and hosting in audited data centers. For small teams, that means fewer one-off engineering tasks and more predictable costs. Atlantic.net emphasizes hands-on support and operational experience with healthcare workloads, which shortens time to production and reduces the chance of misconfiguration. For organizations scaling from prototype to clinical use, this model offers a straightforward path with the operational guardrails healthcare systems require.

- **Why it is affordable:** We use a predictable, flat-rate pricing model that bundles essential security tools, such as Intrusion Prevention Systems (IPS), with daily backups. This eliminates the unpredictable data egress fees common with hyperscale clouds.
- **HIPAA Service Highlights:** Our solution includes a fully executed BAA, always-on TLS 1.3 encryption, and infrastructure housed in highly audited [SOC 2-](https://www.atlantic.net/hipaa-compliant-hosting/ssae-16-soc-1-soc2-care/) and SOC 3-certified data centers. We provide hands-on engineering support specifically trained in healthcare workloads, ensuring your environment is configured correctly from day one.

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

**Microsoft Azure**

Azure is an enterprise-grade [platform](https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-hipaa-us) with extensive services and compliance attestations. Its security tooling and global footprint support complex requirements like advanced threat detection and cross-region disaster recovery. However, realizing HIPAA compliance on a hyperscale platform requires substantial internal expertise or a trusted partner to implement and maintain the correct controls. Costs can grow quickly if teams do not actively optimize usage and architecture.

- **Why it is affordable:** Azure uses a pay-as-you-go model that becomes highly cost-effective when you commit to Reserved Virtual Machine Instances (1-3 years of compute). It is only affordable if you have the internal talent to aggressively optimize your architecture to prevent resource sprawl.
- **HIPAA Service Highlights:** The platform provides Azure Policy and Microsoft Defender for Cloud, which offer continuous compliance monitoring against HIPAA frameworks. Their standard BAA covers dozens of native services, allowing developers to build complex, compliant architectures ranging from AI diagnostics to secure SQL databases.

### Mid-Range & High-Value Scalable Providers

![](https://www.atlantic.net/wp-content/uploads/2026/03/ClearDATA-logo.png)

**ClearDATA**

ClearDATA [builds](https://www.cleardata.com/cloud-compliance/) a healthcare-first layer on top of major cloud platforms. Their offering focuses on automated compliance reporting, continuous monitoring, and a compliance center staffed with specialists. This approach suits organizations that need deep regulatory support and want to benefit from hyperscale infrastructure without owning compliance engineering. The tradeoff is a higher price point that reflects the breadth of managed compliance services.

- **Why it is affordable:** While their monthly fees are premium, they effectively replace the need to hire a full-time, in-house cloud security and compliance team. For mid-sized healthcare companies, outsourcing this liability is often cheaper than funding a dedicated DevOps security department.
- **HIPAA Service Highlights:** ClearDATA offers Automated Safeguards that actively monitor public cloud environments. If a developer accidentally spins up an unencrypted storage bucket, the ClearDATA software will automatically remediate and encrypt it in real-time, preventing a breach before it happens.

![](https://www.atlantic.net/wp-content/uploads/2026/03/hostdime.png)

**HostDime**

[HostDime](https://www.hostdime.com/blog/data-center-compliance/) emphasizes customizable dedicated infrastructure. Owning data centers gives them granular control over physical security, hardware replacement, and network configuration. This model is attractive to organizations with specific performance or regulatory needs that exceed standard cloud offerings. It requires internal expertise to manage application-level compliance, but for teams that need bespoke infrastructure, it can be the right choice.

- **Why it is affordable:** By owning their facilities—including their new Tier IV flagship data center in Orlando, opening in Q1 2026—they cut out the middleman. You avoid the heavy data egress fees and compute markups associated with hyperscale clouds, making it highly cost-effective for organizations that need raw, [dedicated server](https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/) power without the unpredictable monthly billing.
- **HIPAA Service Highlights:** Their wholly-owned facilities feature stringent physical security (biometrics, 24/7 on-site security personnel) and highly redundant power architecture to guarantee uptime. They execute a BAA for their dedicated server and colocation clients. As you are utilizing isolated bare-metal servers rather than a multi-tenant virtual cloud environment, meeting HIPAA’s strict data isolation requirements is fundamentally handled at the hardware level.

![](https://www.atlantic.net/wp-content/uploads/2025/12/rackspace_logo.png)

**Rackspace**

[Rackspace](https://www.rackspace.com/industry/healthcare) follows a managed services model with deep experience across regulated industries. They offer architectural guidance, multi-cloud management, and operational SLAs tailored to the healthcare industry. Rackspace’s model suits enterprises or growing [healthcare organizations](https://www.atlantic.net/hipaa-compliant-hosting/healthcare-organizations-embracing-cloud-computing/) that prefer to outsource day-to-day operations while keeping strategic control over their cloud footprint. Pricing typically reflects the service’s complete nature.

- **Why it is affordable:** Their affordability stems from operational scale. Growing enterprises save money by outsourcing their day-to-day patching, monitoring, and network management to Rackspace rather than scaling an expensive 24/7 internal IT operations center.
- **HIPAA Service Highlights:** Rackspace provides customized [SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/) (Service Level Agreement) guarantees tailored to healthcare uptime requirements. They assist with deep architectural design to ensure data routing, disaster recovery, and geographic redundancy meet strict federal compliance standards before a single server goes live.

**Final Thoughts**

In 2026, HIPAA compliance is no longer a barrier to healthcare innovation. Whether you are launching a mental health app or managing genomic research, there is a solution that fits your budget. Focus on providers willing to sign a BAA, those with a proven track record in healthcare, and those who offer responsive, human support.

 


---

# Industries Using Dedicated GPU Cloud Hosting

> URL: https://www.atlantic.net/gpu-server-hosting/industries-benefiting-from-dedicated-gpu-cloud-hosting/ | Published: 2026-03-10 | Author: Robert Agar

Dedicated GPU cloud hosting provides a customer with exclusive access to GPU servers in cloud environments. Cloud service providers (CSPs) reserve physical hardware for a single customer. Companies gain enhanced performance, security, and control with this dedicated hardware compared to shared or virtualized GPU servers.

This guide explores the advantages of dedicated GPU servers and highlights the specific industries that rely on them. For many organizations, cloud-hosted dedicated GPUs offer a path to massive computational power that would be prohibitively expensive to build and maintain on-premises.

## What Are the Advantages of Dedicated GPU Servers?

GPU servers use high-performance graphics processing units (GPUs) to handle parallel processing—something traditional central processing units (CPUs) aren’t built to do at scale. This architecture supports intensive tasks like scientific simulations, photorealistic rendering, and training large-scale deep learning models.

### Consistent performance

Customers don’t share a dedicated server’s GPU resources with other tenants, ensuring more reliable, consistent performance. Shared GPU server users may experience unpredictable performance degradation due to resource utilization by other tenants. Guaranteed performance levels support applications such as training AI models, inference, and graphics rendering.

### High compute density

Current GPU models, such as the NVIDIA H100 NVL and L40S, deliver massive parallelism. These cards feature thousands of cores designed to finish complex math in a fraction of the time a CPU would require. Dedicated servers are the ideal choice for financial modeling, deep learning, 3D rendering, and complex fluid simulations.

### Enhanced security

Businesses benefit from enhanced security provided by a dedicated server’s isolation. Security is improved by eliminating co-tenant access to GPU memory and reducing the attack surface. Companies in regulated industries, such as healthcare, that process sensitive data may require an isolated environment to ensure regulatory compliance. High security is essential for tasks such as enabling financial institutions to perform data analysis without risking client information or for AI startups to protect valuable proprietary ML models.

### Full Administrative control

Customers have complete administrative control over their dedicated GPU servers. Teams have root and admin access to server resources and can typically install custom operating system images. Companies exercising this level of control can tune and optimize server performance to align with business objectives. Shared hosting solutions do not provide this level of control or OS customization.

### Long-term cost-effectiveness

Decision-makers can budget IT services more efficiently with the predictable costs of dedicated servers. They are not subjected to pricing spikes that may affect a shared environment. Many organizations find dedicated servers more cost-effective than pay-as-you-go plans for continuous, always-on workloads.

### Low-latency access and performance

Businesses can reduce latency with a dedicated GPU server by reducing scheduling delays and virtualization overhead associated with shared GPU solutions. Low latency is essential for real-time workloads and for providing a satisfactory customer experience. Real-time processing is mandatory to support advanced applications such as autonomous vehicles and predictive analytics.

## What Industries and Businesses Benefit From Dedicated GPU Servers?

Many businesses in a wide range of industries and disciplines can directly benefit from dedicated GPU servers. The parallel processing power of graphics processing units enables the concurrent execution of multiple tasks or computations. GPU computing has become an essential part of many modern organizations’ IT environments.

### Artificial intelligence and machine learning

GPUs are crucial to the rapid proliferation of AI models and ML capabilities across consumer and business applications. AI developers and scientific research teams benefit from the guaranteed performance during long training sessions. They also achieve heightened security to safeguard proprietary models and data assets.

Use cases include:

- **Large-scale inference:** Running models against massive datasets.
- **Deep learning:** Training neural networks with billions of parameters.
- **NLP and Vision:** Powering chatbots and image recognition systems.

Smaller companies and startups can leverage parallel processing capabilities without the capital expenses by adopting dedicated GPU server hosting solutions.

### Financial services

Businesses such as hedge funds and high-frequency trading firms require the security, performance, and low latency provided by dedicated GPU servers. These companies rely on real-time analytics and reliable, complex computations to deliver accurate, timely information. Latency or performance lags can lead to unreliable or outdated data, which can be extremely costly for the company and its clients.

Use cases include:

- Identifying patterns for effective fraud detection.
- Performing Monte Carlo and other complex simulations;
- Supporting automated, algorithmic trading models;
- Data analytics for portfolio optimization.

### Healthcare and life sciences

Healthcare companies often process complex workloads with large datasets that require high throughput and secure isolation for regulated data. Businesses in medical imaging or pharmaceutical research and development benefit from the high-performance computing capabilities of dedicated GPUs.

Specific use cases include:

- Scientific research and simulations supporting drug discovery;
- DNA sequencing;
- Image analysis, treatment planning, and diagnostics.

### Media, entertainment, and gaming

Companies across diverse media niches, including animation studios, video streaming providers, game developers, and augmented/virtual reality researchers, benefit from the parallel processing power of dedicated GPUs. GPUs excel at 3D rendering and ray tracing, which are essential for smooth streaming and gaming performance that meet customer expectations. Dedicated servers ensure consistent performance during peak usage periods.

Use cases by these industries include:

- Video rendering, encoding, and transcoding;
- Supporting virtual production pipelines;
- Providing users with real-time interactions.

### Scientific research and high-performance computing (HPC)

Organizations performing research for the private sector or government agencies need the computational power of GPUs to support long-running processes without interruption. Many types of research benefit from parallel processing, which enables multiple tasks to run simultaneously. Researchers can process massive amounts of data with a GPU in a fraction of the time it would take on a CPU-based system.

Scientific use cases benefiting from GPUs include:

- Climate modeling and weather prediction;
- Computational physics and chemistry simulations;
- Astrophysics research.

### Manufacturing and engineering

Manufacturers and engineering firms benefit from predictable performance in iterative testing to improve products and processes. They can use dedicated GPU servers to create digital twins to model, study, and optimize processes and streamline operations. Companies that implement smart manufacturing can gain substantial technical advantages over rivals and achieve a significant competitive edge.

### Cybersecurity and analytics firms

The high computational power of GPU computing provides benefits to cybersecurity analysts and vendors. Research teams must perform real-time data analysis and risk assessment to identify emerging threats to the IT environment. They require high computing throughput and isolated environments for sensitive testing and analysis.

Specific use cases include:

- Pattern recognition;
- Password cracking for vulnerability testing;
- Malware analysis.

## Conclusion

GPUs are essential in many businesses and industries. The availability of dedicated GPU cloud environments is a notable change for small companies or those with financial constraints that preclude building an in-house solution. Companies of any size can leverage the power of GPUs by deploying a dedicated cloud-hosted GPU server.

Atlantic.Net offers a full line of[dedicated GPU servers](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/) with powerful NVIDIA GPUs, tailored to meet any company’s business requirements. They provide a viable way to level the playing field by making GPU-powered dedicated servers available to any organization.


---

# Atlantic.Net Joins the San Jose Earthquakes’ One Ball Can Change a Life Initiative

> URL: https://www.atlantic.net/press-releases/atlantic-net-joins-the-san-jose-earthquakes-one-ball-can-change-a-life-initiative/ | Published: 2026-03-11 | Updated: 2026-06-04 | Author: Editorial Team

*As it continues a strategic partnership with the Quakes, Atlantic.Net reinforces its commitment to empowering youth across Northern California*

SAN JOSE, Calif. (March 2, 2026) – Atlantic.Net is pleased to participate in the San Jose Earthquakes’ “One Ball Can Change a Life” initiative, uplifting youth throughout Northern California by helping them experience firsthand the life-transforming power of soccer. This news comes as Atlantic.Net [continues its partnership with the Quakes](https://www.atlantic.net/press-releases/atlantic-net-scores-multi-year-partnership-with-san-jose-earthquakes/) in 2026 as the Major League Soccer club’s Official Cloud Server Hosting Platform Provider.

The One Ball Can Change a Life campaign is dedicated to helping improve access to the game of soccer and the many benefits it offers, including building character, fostering creativity and values, providing safe spaces to play and dream, and opening doors to new possibilities. The Quakes will support the initiative by donating at least 15,000 soccer balls to aspiring players this year, along with additional programming provided by the Quakes Foundation.

Atlantic.Net will directly support the One Ball Can Change a Life mission to foster growth and opportunity through the power of soccer. As part of its collaboration, Atlantic.Net will sponsor children to attend an upcoming Quakes game so they can experience soccer live and donate soccer balls to the community. Every ball represents a life touched.

“We are delighted to help young kids have memorable experiences that will impact their lives for the better,” said Marty Puranik, founder and CEO of Atlantic.Net. “One ball and one game at a time, the Quakes are creating a ripple of positive influence in the lives of local children. We’re all in and encourage others to join us in these efforts.”

The One Ball Can Change a Life initiative is dedicated to inspiring youth through soccer and providing resources to local organizations that help kids. To learn how to support the campaign, visit the [Quakes Foundation](https://fundraise.givesmart.com/e/1lNeZQ?vid=1ox047).

**About Atlantic.Net**

Founded in 1994, [Atlantic.Net](https://www.atlantic.net/) is a privately held global cloud infrastructure provider with customers in over 100 countries, known for delivering secure, compliant, on-demand and customizable hosting solutions. With decades of experience, Atlantic.Net is one of the world’s most trusted and experienced hosting providers, offering 24/7 U.S.-based support. Specializing in security, compliance, and customer service, Atlantic.Net serves a diverse range of industries with solutions including HIPAA-compliant hosting and PCI-compliant hosting, backed by bare metal servers, dedicated hosting, GPU hosting, colocation, and its award-winning Cloud Platform. Operating from eight strategically located data center regions across the United States, Canada, the United Kingdom, and Asia, Atlantic.Net powers mission-critical workloads for organizations worldwide. For more information, visit[ Atlantic.Net](https://www.atlantic.net/) or connect with us on[ Facebook](https://www.facebook.com/Atlantic.Net),[ X (Twitter)](https://twitter.com/AtlanticNet),[ LinkedIn](https://www.linkedin.com/company/atlantic.net-inc./posts/?feedView=all), and[ YouTube](https://www.youtube.com/c/AtlanticNet).


---

# 2026 Bare Metal Adoption Trends: Why Enterprises Are Choosing Single-Tenant Infrastructure

> URL: https://www.atlantic.net/dedicated-server-hosting/bare-metal-adoption-trends-single-tenant-infrastructure/ | Published: 2026-03-12 | Updated: 2026-05-30 | Author: Dr. Tehseen Zia

For nearly a decade, a key infrastructure decision for many organizations has been migrating to the public cloud. Several factors made this option appealing. Cloud systems could be easily scaled, the provider handled hardware maintenance, and businesses could shift from high upfront costs to predictable operating expenses. It’s a model that worked well for years, but we are now seeing a shift. IT leaders are no longer simply choosing between cloud and on-premises infrastructure. Instead, they want to know which environment best suits their specific workload.

This shift has revived interest in [bare metal servers](https://www.ibm.com/think/topics/bare-metal-dedicated-servers). But this is not a nostalgic return to the data centers of the early 2000s. It is an adoption of single-tenant infrastructure designed to solve problems like performance unpredictability and complex compliance that hyperscale cloud environments were never built to address.

## The Certainty Gap in a Shared World

The public cloud’s greatest strength is also its greatest weakness for certain workloads. This factor is known as resource pooling. By design, multi-tenant environments allow providers to maximize utilization by running many customers on shared hardware. This model is exceptionally efficient for spiky, variable, and transient workloads.

However, this resource pooling introduces a “certainty gap.” When you share physical resources, you introduce variables that are hard to control. You can optimize your code, tweak your database queries, and implement advanced caching. Still, you cannot eliminate the performance variations caused by a “[noisy neighbor](https://neon.com/blog/noisy-neighbor-multitenant)” on the same physical host.

For an increasing number of applications, the traditional “usually fast” approach is no longer sufficient. In 2026, user experience has become a key differentiator. Even a small delay in a multiplayer game, lag in a real-time financial trading feed, or slower response from an AI inference system does not remain just a technical issue; it often leads to user frustration, support requests, and eventually lost revenue.

This is where bare metal has made its comeback. It provides predictable and consistent performance. With a dedicated server, the computing power, memory bandwidth, and storage I/O are reserved solely for one customer. There is no hypervisor layer consuming resources, and no other tenants competing for the same hardware. This level of predictability is a significant factor in the growing use of bare-metal infrastructure in 2026.

## The Four Pillars Driving the Shift to Single-Tenant

After carefully examining this shift towards bare-metal infrastructure, we have identified four main factors driving it.

1. **Compliance and the Need for Clean Audit Boundaries**

The regulatory requirements in 2026 are more complex than ever. For organizations handling electronic [Protected Health Information (ePHI)](https://www.techtarget.com/searchhealthit/definition/electronic-protected-health-information-ePHI) or payment card data, the shared responsibility model of the public cloud can feel like a shared liability model.

When you operate in a multi-tenant cloud, defining compliance boundaries is not easy. Auditors often raise eyebrows at the concept of logical separation on shared physical infrastructure. You need to spend many engineering hours showing that your virtual private cloud is isolated from others, just to meet audit requirements.

Single-tenant dedicated hosting simplifies this requirement. With a bare-metal server, the physical boundary is also the compliance boundary. The hardware does not contain any other customer’s data. For workloads that require a [HIPAA](https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html)

[HIPAA Business Associate Agreement (BAA),](https://www.techtarget.com/healthtechsecurity/feature/What-Is-a-HIPAA-Business-Associate-Agreement-BAA) this physical separation provides assurance that simplifies audit requirements. It reduces the risk to neighboring tenants and lets you know exactly where your data resides and who can access the hardware.

1. **Performance Consistency for High-Stakes Workloads**

As mentioned, the “[noisy neighbor](https://www.techtarget.com/searchcloudcomputing/definition/noisy-neighbor-cloud-computing-performance)” problem creates major challenges for certain applications. As a result, we are seeing significant adoption of bare metal, particularly for workloads that handle critical data. One important factor behind this trend is the rise of real-time AI and inference engines. While training large models often takes place in bursty, scalable cloud environments, running these models in production requires consistent, low-latency responses. In a shared setting where CPU resources vary, this can lead to inference errors or timeouts.

Similarly, high-transaction databases, search indexes, and gaming session hosts are returning to dedicated hardware. These workloads cannot tolerate unpredictable performance. Bare metal provides stability because the hardware resources are fixed and known. You are not guessing how many physical CPUs are available; you know exactly how many cores you have.

1. **The Cost Curve of Always-On Workloads**

The public cloud’s economic model assumes that workloads will scale up and down over time. You pay a premium for the flexibility to scale and shut resources off when they are not needed. But what if your workload never turns off?

Many modern businesses rely on steady-state workloads. [ETL pipelines](https://www.geeksforgeeks.org/software-testing/what-is-an-etl-pipeline/), data warehouses, [continuous integration/continuous delivery (CI/CD)](https://www.geeksforgeeks.org/devops/what-is-ci-cd/) infrastructure, and core business applications run around the clock. For these workloads, the cloud’s elasticity often becomes an expensive option because you are paying for flexibility you are not using. This realization has led many financial officers to take a closer look at their cloud bills. In many cases, they find that predictable workloads are more cost-effective on dedicated, predictable hardware. Bare metal offers a simpler, more predictable cost structure. You pay for the server and use its full capacity, while avoiding additional charges such as data egress fees and API call costs that can quickly increase monthly cloud expenses.

1. **Strategic Control and Licensing Optimization**

Finally, there is the question of control. In 2026, vendor lock-in has become a major concern for enterprise architects. Running on bare metal provides architectural freedom. It allows you to run any version of an operating system, use any container orchestration tool, and deploy any hypervisor you choose, without being restricted to a provider’s proprietary managed services.

Furthermore, for organizations with specific software licensing models (particularly those with CPU core-based licensing), running on dedicated hardware can offer significant cost advantages. You have full visibility and control over the hardware inventory, allowing you to optimize license expenses that are often unclear in a virtualized cloud environment.

## What Bare Metal Looks Like in 2026

The bare metal of 2026 looks very different from the physical servers of the past. It is not about ordering hardware and waiting weeks for delivery. The modern approach, often called “[Bare Metal as a Service](https://www.linkedin.com/pulse/introduction-bare-metal-service-kunal-pakhale-hjqvf/),” combines the control of dedicated hardware with the flexibility of the cloud.

Leading providers now offer API-driven provisioning, enabling organizations to deploy a high-performance bare-metal server in minutes rather than days. Many also offer flexible billing options, including hourly or monthly pricing. This makes it easier for enterprises to adopt a hybrid infrastructure approach.

In this model, core services such as databases and other critical applications run on single-tenant hardware to ensure stability and consistent performance. At the same time, edge services, experimental workloads, and bursty web applications remain in the public cloud, where organizations can take advantage of global scale and rapid elasticity.

### The Atlantic.Net Approach

At Atlantic.Net, we have spent over three decades refining this approach. For our clients, whether they are healthcare innovators requiring [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/), fintech platforms needing [PCI-DSS isolation](https://www.atlantic.net/pci-compliant-hosting/pci-dss-4-0-is-mandatory-a-hosting-checklist-for-2026/), or SaaS companies demanding predictable performance, the choice is often straightforward.

They choose Atlantic.Net not only for the hardware, but also for the compliance-ready infrastructure and the human support that ensures their infrastructure is configured correctly from the start. Our [bare-metal solutions](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) also offer the option of fully managed services. This allows organizations to maintain control over their hardware without taking on the operational burden of managing it themselves.

We provide a single-tenant foundation that helps organizations pass strict compliance audits with clearly defined physical boundaries. Our infrastructure includes modern AMD EPYC and Intel Xeon processors paired with NVMe storage to deliver consistent performance. At the same time, we offer transparent and predictable pricing so organizations can plan their infrastructure costs with confidence.

### The Bottom Line

The return to bare metal is not a rejection of the cloud; it is the maturation of it. In 2026, enterprises are moving from the “one-size-fits-all” approach towards adopting a hybrid strategy. They are recognizing that while the cloud is perfect for development and variable traffic, production stability, regulatory compliance, and economic efficiency often demand the certainty of single-tenant infrastructure.

If your organization is dealing with noisy neighbors, expanding compliance requirements, or raising public cloud bills, it may be worth rethinking the infrastructure layer. Sometimes, the most advanced strategy is the one that gives you the most control over your hardware and environment.

**Related Guides:**

- [HIPAA Compliant Hosting Solutions](https://www.atlantic.net/hipaa-compliant-hosting/)
- [PCI-Compliant Hosting Solutions](https://www.atlantic.net/pci-compliant-hosting/)
- [What Are Managed Services?](https://www.atlantic.net/managed-services/what-are-managed-services/)

**Related Products:**

- [Atlantic.Net Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/)
- [Atlantic.Net HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)
- [Atlantic.Net GPU Hosting](https://www.atlantic.net/gpu-server-hosting/)


---

# Why Virtual Machine Hosting Is Essential for Scalable IT Infrastructure in 2026

> URL: https://www.atlantic.net/cloud-platform/virtual-machine-hosting-scalable-it-infrastructure/ | Published: 2026-03-13 | Author: Robert Agar

Modern IT teams are under pressure to do two things at once: support current workloads reliably and stay ready for sudden growth, geographic expansion, and changing application requirements. For many organizations in 2026, virtual machine hosting remains a practical way to meet both goals because it combines workload isolation with faster provisioning and more flexible resource allocation than traditional one-application-per-server models.

At a high level, virtual machine hosting enables a provider or an internal IT team to run multiple isolated guest systems on shared physical infrastructure. That model does not eliminate the need for architecture, capacity planning, or security controls, but it does make infrastructure easier to deploy, scale, and manage than an all-physical footprint for many common business workloads

## What is Virtual Machine Hosting?

Virtual machine hosting is a cloud computing model that leverages physical servers and virtualization software to provide customers with multiple, isolated virtual private servers. Each virtual machine (VM) acts as an independent server and can be configured to meet customers’ requirements.

Cloud server hosting is a popular form of virtual machine hosting that offers more control and resources than shared hosting. Still, it is more affordable and flexible than a dedicated server.

In this setup, each server is dedicated to a single user, providing isolation and customization, whereas shared hosting divides resources among multiple users on the same server. A cloud server is a virtual server running on a physical server and includes its own operating system, bandwidth, and disk space. Dedicated servers, on the other hand, offer a more tailored and powerful infrastructure for growing or demanding businesses, with full physical hardware management and upgrade options.

A typical virtual machine hosting environment has three main components.

### Physical hardware

The foundation of a VM hosting solution is comprised of physical servers located in a CSP’s global data center. These servers provide dedicated resources, such as CPU, memory, and storage, to provision the VMs. Powerful servers with extensive resources can create and manage multiple virtual servers. The host also provides network access to the virtual machines. High-speed, reliable internet access is essential for optimal performance, secure connections, and remote management of virtual machines in a virtual machine hosting environment.

### The hypervisor

A hypervisor is specialized software that allocates and controls the VMs’ access to the host’s physical resources. Hypervisors are available in two varieties. A bare metal hypervisor runs directly on the physical hardware. A hosted hypervisor runs on an operating system, similarly to any other application.

Hypervisors perform critical functions in virtual machine hosting environments, including:

- Allocating resources to the individual VMs;
- Isolating the VMs to prevent interference or resource contention;
- Scheduling and managing VM access to CPU cycles;
- Presenting the VMs with a virtualized view of the hardware.

### Virtual machines

The hypervisor divides the physical server’s resources into multiple, software-defined virtual machines. Teams can configure each VM with different operating systems, application stacks, security settings, and resource limitations. Many virtual machine hosting solutions come with pre-installed apps and advanced features such as automation, backups, and enhanced security, making it easier to get started and manage workloads efficiently. Many virtual machine hosting solutions provide full root access, allowing users complete control to install and configure software as needed. Virtual machine solutions give users root access and complete control over their virtualized computers.

## How a VM Hosting Environment Supports Modern Businesses

A reliable virtual machine hosting solution provides modern businesses with the following benefits. These advantages are fundamental to success in a rapidly changing business environment.

### Rapid scalability

Organizations gain on-demand scalability through virtual machine hosting, enabling them to address traffic spikes and support business growth efficiently. Customers can spin up new VMs in minutes with just a few clicks and add computing resources, such as CPU or memory, without hardware replacement. Companies can scale vertically by increasing the capacity of their existing VMs or horizontally by adding additional virtual servers.

Most VM hosting providers allow you to upgrade or downgrade your plan at any time, providing flexibility to adapt to changing requirements. Many hosting plans also offer unlimited traffic, ensuring there are no additional charges regardless of visitor volume, which is essential for scalability and cost-effectiveness.

Businesses save money by supporting fewer physical servers and reducing their data center footprint. These financial savings support cost-effective scalability and enable companies to pay only for the resources they use. Organizations retain the ability to rapidly deploy additional VMs to address customer and industry trends.

### Resource efficiency

Businesses using traditional computing solutions with on-premises data centers often face challenges when provisioning hardware. Teams that underprovision risk not meeting business requirements, while overprovisioning wastes money. Physical servers are typically vastly underutilized, potentially wasting expensive computing resources.

Virtualization enables a single physical server to support multiple websites or workloads, reducing waste and optimizing resource utilization. VM hosting maximizes the use of available hardware, providing increased capacity through easy scaling without the capital expenditures of additional equipment. Choosing a reliable cloud server ensures high performance and stability, further maximizing resource efficiency.

### Portability

Virtual machine hosting supports portability through hardware abstraction, which separates VMs from the physical servers on which they run. Teams can move workloads between machines without disrupting operations. Organizations can deploy more powerful VMs to handle infrastructure growth without being dependent on specific hardware.

Businesses can migrate workloads freely across regions or data centers, which can be instrumental in meeting regulatory data residency requirements. Companies can also leverage global data centers to host applications for optimal low latency and high performance. The separation of VM from hardware provides unlimited flexibility, supporting the rapidly evolving needs of modern businesses.

An intuitive control panel can further simplify migrating and managing virtual machines across multiple data centers or regions.

### Isolation and security

Virtual machines operate in isolated environments, which provide enhanced security. A security breach or DDoS attack affecting one user’s virtual desktop or application can be confined to a VM and not affect other users. Isolation ensures that if one VM is compromised or crashes, other VMs remain safe and unaffected. Teams have more control over system configuration and can implement different security features to support production, development, and test VMs.

DDoS protection, including anti-DDoS measures, is commonly included in virtual machine hosting plans to safeguard against malicious attacks. Virtual private servers without anti-DDoS protection are automatically exposed to distributed denial-of-service (DDoS) attacks, which can cause outages and security issues. Built-in DDoS protection features help ensure service stability and data security for cloud virtual machine hosting solutions.

Isolating individual VMs allows teams to fine-tune scaling when scaling the environment. Teams can scale certain machines to address distinct workload requirements. Companies save resources and money by scaling only specific VMs and tailoring the infrastructure to their business needs.

### Workload flexibility

A virtual machine hosting solution provides organizations with workload flexibility, which can be invaluable for companies supporting diverse application stacks. Cloud solutions offer the flexibility to install your preferred software, customize server settings, and host multiple websites with dedicated resources. Teams can use the same server to run different operating systems on individual VMs, eliminating the need to purchase additional hardware. A single user can run Linux and Windows Server VMs side-by-side, sharing the same physical resources.

The flexibility of VM hosting enables companies to capitalize on shifting market trends by adopting the most efficient business solutions for their use cases. Businesses that previously deployed only Windows machines may decide that a Linux platform is the best host for their web applications.

### Resilience and high availability

A VM hosting environment has built-in features that make it highly resilient. VMs are easily protected from data loss with daily backups and snapshots. Daily automatic backups are included with many virtual machine hosting plans to protect data, and most solutions offer them for free, allowing quick data restoration. Virtual machine hosting ensures high availability and performance, making it suitable for businesses of all sizes. Teams can quickly recover a corrupted VM to a previous state, providing an additional layer of data protection. Companies can implement automated failover procedures to recover damaged VMs without operational disruptions.

Many providers offer advanced features and additional services, such as managed backups, security enhancements, and performance optimizations, to further enhance resilience and high availability. DDoS protection is commonly included in virtual machine hosting plans to safeguard against malicious attacks.

Organizations with a virtual machine environment can migrate between hosts with minimal downtime, providing a streamlined disaster recovery process and supporting business continuity. Teams can increase the environment’s complexity while maintaining a stable infrastructure.

### Automation for simplified management

Automation is a key to scalable IT infrastructure. Teams responsible for manually managing the environment can quickly be overwhelmed by its rapid growth. Automation is one of the advanced features available in modern virtual machine hosting platforms, enabling efficient management and scaling. Modern VM platforms integrate with monitoring and orchestration tools, enabling automated provisioning and scaling. The infrastructure can respond automatically to demand by scaling up or down to optimize performance and cost-efficiency.

## Choosing the Right Virtual Machine Hosting Solution

Selecting the right virtual machine hosting solution is a pivotal decision for businesses and individuals aiming to maximize the performance and reliability of their online presence. A reliable virtual machine hosting provider delivers dedicated resources, ensuring that your virtual servers operate at peak efficiency even during periods of high demand. This level of performance is essential for users who need to host multiple websites or run resource-intensive applications in a secure, customizable hosting environment.

When evaluating virtual machine hosting options, consider the specific requirements of your projects, such as the preferred operating system, storage, CPU, and RAM requirements, and the level of control you require over your environment. Advanced security features and reliable technical support are also crucial, providing peace of mind and reliable access to your virtual servers at all times. High availability and low latency are key benefits of a well-chosen solution, ensuring your users experience smooth service and your business scales efficiently as it grows. By prioritizing these factors, you gain more control over your resources and can confidently manage and expand your digital footprint.

## Data Center Infrastructure: Global Locations and Impact

The backbone of any reliable virtual machine hosting solution is its data center infrastructure. The geographic distribution of data centers directly influences the performance, security, and reliability of your virtual servers. Providers with a global network of data centers can deliver low latency and high availability to users, regardless of their location, ensuring that applications and websites load quickly and remain accessible around the clock.

Modern data centers are equipped with high-performance servers, advanced cooling systems, and complete security protocols to safeguard your data and maintain uninterrupted service. When choosing a virtual machine hosting provider, it’s important to assess the locations of their data centers and how these may impact your business operations or compliance requirements. A provider with a strong global presence can offer reliable virtual machine hosting that adapts to your needs, supports business expansion, and delivers consistent, secure access to your virtual servers.

## Operating System Options: Flexibility and Compatibility

A key advantage of virtual machine hosting is the flexibility to choose from a wide range of operating systems, including Linux, Windows, and even macOS. This versatility allows businesses and individuals to deploy the platforms that best suit their applications, whether they are running web hosting environments, specialized software, or multiple websites. Reliable virtual machine hosting providers offer smooth installation and management of different operating systems, ensuring compatibility with your preferred tools and workflows.

To further simplify management, many providers include intuitive control panels such as Plesk Web Host Edition. These tools empower users to efficiently manage multiple websites, domains, and databases from a single interface, streamlining administrative tasks and enhancing productivity. By selecting and managing multiple operating systems, users gain full control over their virtual servers, making it easy to adapt to changing business requirements and technological advancements.

## Backup and Recovery: Ensuring Business Continuity

Protecting your data is paramount in any hosting environment, and reliable virtual machine hosting providers prioritize reliable backup and recovery solutions. Daily backups, snapshots, and flexible recovery options ensure that your virtual servers can be quickly restored to a previous state in the event of data loss or system failure. This level of data protection minimizes downtime and helps maintain business continuity, even in the face of unexpected disruptions.

In addition to automated backup features, access to knowledgeable technical support is essential. A dedicated support team can assist users in managing backups, performing recoveries, and addressing any issues that arise, providing valuable resources and expertise. By choosing a provider that offers complete backup and recovery services, you can confidently manage your virtual machines, knowing that your data is secure and your business operations are protected against potential setbacks.

## Virtual Machine Hosting Best Practices: Optimization Techniques

To get the most out of your virtual machine hosting environment, it’s important to implement optimization techniques that enhance performance, security, and reliability. Start by fine-tuning resource allocation—adjust CPU, RAM, and storage settings to match the specific needs of your applications, ensuring that each virtual server operates efficiently without over- or under-provisioning resources.

Security settings should be carefully configured, including firewall rules and access controls, to protect your virtual machines from unauthorized access and potential threats. Optimizing network access is also crucial; consider implementing load balancers and content delivery networks to distribute traffic evenly and reduce latency for users worldwide. Regularly reviewing and updating your server configurations, monitoring performance metrics, and staying informed about the latest security best practices will help maintain a high-performance, secure hosting environment. By following these best practices, users can ensure their virtual servers deliver reliable, scalable, and efficient service for all their applications and services.

## Conclusion

Virtual machine hosting provides modern businesses with a cost-effective, flexible, and scalable IT infrastructure. Today’s dynamic business market demands the scalability and flexibility of a virtualized environment. Companies can implement this modern infrastructure and remain competitive in the market by partnering with a reliable virtual machine hosting provider.

[Atlantic.net](https://www.atlantic.net/) provides its customers with a wide range of VM hosting solutions tailored to their organization’s specifications. Our cloud, bare-metal, and dedicated servers all provide high-performance, effective virtual machine hosting. We protect your investment with a 24/7 technical support team and offer transparent pricing with no hidden fees.

[Get in touch with us](https://www.atlantic.net/about-us/corporate-contact/) and have all your virtual machine hosting questions answered by our experts.


---

# Public vs Private Cloud for AI: Hidden Training Costs

> URL: https://www.atlantic.net/dedicated-server-hosting/public-vs-private-cloud-for-ai-workloads-hidden-training-costs/ | Published: 2026-03-13 | Author: Dr. Assad Abbas

[Artificial Intelligence (AI)](https://www.ibm.com/think/topics/artificial-intelligence) drives system architecture, data management, and long-term infrastructure planning. Many companies rely on machine learning models for analytics, automation, and digital services. Running AI workloads demands a thorough analysis of evaluation metrics.

Training modern AI models requires reliable computing resources, including GPU clusters, fast storage, and stable data pipelines. Traditional cloud workloads, which primarily rely on CPUs and standard storage, fail to meet the demands of AI training. AI workloads mandate moving massive datasets and rely on high-speed node-to-node communication.

Public cloud platforms provide rapid access to GPUs and managed AI tools. Development teams can run experiments immediately without waiting for hardware installation. Cloud providers operate massive global data center networks supporting distributed workloads and flexible regional deployments. However, long training jobs often incur high operational costs. Surging GPU demand has made hyperscale cloud pricing volatile and unpredictable.

Faced with these challenges, many organizations turn to private GPU clusters. Dedicated infrastructure delivers consistent performance and tighter control over configurations, performance tuning, and data governance. Building this infrastructure requires skilled operational teams and precise capacity planning.

Comparing public, private, and hybrid cloud models helps organizations make informed, long-term decisions and mitigate AI deployment risks. This guide breaks down these options and provides a practical framework for selecting your AI infrastructure.

## Definitions of Key Concepts

For clarity, some important terms and concepts used in this article are defined below.

### Public Cloud

Shared infrastructure managed by large cloud providers. Customers consume computing resources on demand and pay only for what they use. Providers maintain the physical hardware and core platform services, reducing the operational burden.

### Private Cloud

Dedicated infrastructure owned or controlled by a single organization. The organization customizes hardware, storage, and networking to meet its exact specifications. This model ensures strict governance and deep customization.

### Hybrid Cloud

A combination of public and private environments. Workloads shift between them based on performance, cost, or compliance needs. Hybrid setups enable gradual migrations and flexible deployments.

### Multi-Cloud

Utilizing multiple public cloud providers (such as AWS and Google Cloud) to reduce reliance on a single vendor. This strategy boosts resilience and expands available service options.

### Edge Computing

Running inference or lightweight processing near the user or device. Edge systems slash latency, ensure the reliability of real-time applications, and minimize the need to transmit raw data back to central cloud environments.

### Common Misconceptions About AI Infrastructure

Several misunderstandings routinely derail cloud strategy. Addressing them early prevents costly mistakes.

Many assume public clouds always cost less. This rarely holds for AI workloads. Public clouds work well for short experiments. Long training cycles on massive GPU clusters quickly become prohibitively expensive, especially when data movement and storage are factored in.

Some believe private clouds cannot scale. While historically accurate, modern private GPU clusters scale exceptionally well when designed with high-performance networking and storage. Organizations frequently deploy large private clusters in colocation facilities equipped with high-density power and cooling.

Assuming compliance demands on-premises infrastructure is another mistake. Public cloud providers offer reliable compliance tools. True compliance hinges on data residency, sovereignty, and governance rules. The right choice depends entirely on specific regulations and data sensitivity.

AI workloads are not inherently portable. Training pipelines, storage formats, and managed services vary wildly between platforms. Migrating workloads requires meticulous planning.

## Key Differences Between Public and Private Cloud

Public and private clouds differ in ownership, scalability, operational responsibility, and service availability. In a public cloud, the provider owns and operates the infrastructure and shares resources among multiple tenants. Organizations relinquish control over hardware upgrades, maintenance schedules, and lifecycle management. While convenient, this limits performance tuning and configuration customization.

Private clouds offer infrastructure dedicated to a single organization, housed either in an enterprise data center or a colocation facility. Since the organization manages the hardware, networking, and storage, engineers have total freedom to optimize performance. This requires the organization to assume full operational responsibility, handling patching, network management, and system uptime.

Public cloud provides nearly instant access to GPU resources, ideal for burst workloads and temporary demand spikes. Private cloud scalability relies on installed hardware capacity; increasing resources requires procurement and facility upgrades. Private cloud scaling requires patience but yields predictable performance and absolute control.

Public cloud relies on a shared responsibility model, in which the provider manages the physical infrastructure and the customer secures the data. In a private cloud, the organization owns the entire operational stack.

## Advantages of Public Cloud for AI Workloads

- **Managed Services Reduce Operational Complexity**
 Public cloud platforms provide ready-to-use tools for training, tuning, and deploying AI models. Services like AutoML, feature stores, and vector databases help manage model selection, data versioning, and embeddings efficiently. End-to-end platforms, such as SageMaker, cover the entire workflow from data preparation to deployment, enabling teams to focus on development rather than infrastructure. This streamlines operations and shortens project timelines.

- **Global Reach Enhances Performance and Reliability**
 Multiple regions and availability zones allow inference endpoints to run close to users across continents. This placement reduces latency, improves user experience, and supports redundancy and disaster recovery.

- **Flexible Pricing Supports Experimentation**
 Cloud platforms allow GPU clusters to be provisioned temporarily and released when not needed. Spot instances offer significant discounts compared to on-demand pricing. This flexibility reduces upfront capital investment and encourages experimentation with models, workloads, and configurations.

- **Rapid Deployment Accelerates AI Projects**
 Pre-configured environments and managed services enable teams to quickly launch AI workloads. Cloud platforms handle underlying infrastructure management so that organizations can start experiments or proofs of concept without lengthy setup cycles.

- **Scalability Adapts to Workload Needs**
 Cloud platforms can scale resources up or down based on workload requirements. This elasticity ensures that short-term spikes or seasonal demands are met efficiently without permanent infrastructure investment.

## Private Cloud Infrastructure for AI Workloads

Private cloud environments provide dedicated hardware, granting organizations total control over networking and storage. This control proves vital for long training jobs and sensitive data governance.

AI clusters require high-density power, advanced cooling, and redundant networking. Many organizations use colocation facilities to ensure stable power and cooling, essential for continuous GPU operations.

Modern AI servers connect multiple GPUs via NVLink or PCIe, while high-bandwidth networking, such as InfiniBand, supports distributed training. Storage design must balance throughput, IOPS, and latency. NVMe scratch storage provides rapid local access, parallel file systems deliver throughput for distributed workloads, and object storage handles long-term dataset retention.

Private clouds facilitate deep customization. Organizations can tune kernels, optimize networking, and integrate specialized accelerators—levels of control impossible in standardized public cloud environments.

## Security and Compliance: Public Cloud vs Private Cloud

AI workloads frequently process highly sensitive data. Organizations must strictly govern how this data is protected.

### Shared-Responsibility and Single-Tenant Models

Public clouds utilize a [shared-responsibility model](https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility). The provider secures the facility, but teams must implement rigorous identity and access management (IAM) controls.

Private clouds operate on a [single-tenant model,](https://www.atlantic.net/dedicated-server-hosting/achieving-unparalleled-security-with-single-tenant-dedicated-hosting/) giving the organization complete authority over the entire stack. This enables advanced security measures, such as confidential computing for data in use. Managing this internal hardware demands highly skilled security staff.

### Regulatory Compliance and Data Sovereignty in Cloud Environments

Compliance rules dictate deployment choices. While public clouds provide built-in compliance features, a HIPAA-compliant private cloud offers unmatched control over data residency and auditability. Ensuring sensitive data remains within approved regions is critical for passing stringent regulatory audits.

### Security and Compliance Operational Steps

The following steps help maintain the security of AI workloads, and each supports a different part of the protection process.

- The first step is to perform threat modeling for AI workloads, which helps identify risks in data pipelines, training stages, and model outputs. It also brings attention to issues such as data poisoning and unauthorized access. Therefore, teams should document these risks and adjust controls to reduce exposure.
- The second step is to implement end-to-end encryption practices, ensuring that data remains protected at rest, in transit, and in use. Public cloud offers managed services, while private cloud enables custom solutions, such as confidential computing. Organizations must handle encryption keys carefully and follow a regular rotation schedule.
- The third step is to schedule regular security posture reviews to detect misconfigurations, weak access controls, and outdated certificates. It also confirms that identity and access policies remain effective over time. Organizations should examine logs, alerts, and audit trails, and update controls in response to new threats.

### Resource Allocation and Cost Considerations

Organizations must forecast how public and private cloud environments impact long-term spending. Developing Total Cost of Ownership (TCO) templates exposes hidden costs. Public cloud expenses include managed service fees, storage tiers, and hefty data egress charges. Private cloud costs involve hardware, power, cooling, and engineering labor.

GPU right-sizing dictates efficiency. Compute requirements vary by workload. Selecting the optimal GPU type, memory capacity, and interconnect bandwidth prevents unnecessary spending.

Data egress costs compound rapidly in public clouds. Providers often charge between $0.05 and $0.11 per [gigabyte](https://www.hokstadconsulting.com/blog/cloud-egress-costs-breakdown-and-forecasting)for outbound data transfers. Moving a 10-terabyte dataset can add hundreds of dollars to a monthly bill. Private clouds eliminate egress fees but require upfront investment in high-bandwidth switches and network adapters.

Vendor lock-in presents another financial risk. Workloads built on proprietary public cloud APIs require costly code rewrites to migrate to private infrastructure.

### Machine Learning Workflows Across Cloud Environments

Training massive models generally benefits from the flexible scaling of public clouds for short experiments, but relies on the predictable performance of private clouds for sustained training. Inference requires low latency, dictating placement closer to users. Feature extraction and preprocessing components must reside close to the compute layer to avoid network bottlenecks.

## Cloud Strategy: Hybrid, Multi-Cloud, and Edge Patterns

Organizations can adopt distinct deployment strategies to manage AI workloads effectively. Hybrid, multi-cloud, and edge patterns each serve a specific purpose, allowing teams to balance performance, cost, and compliance while maintaining operational flexibility. The following strategies illustrate how these approaches can be applied in practice.

### Hybrid Deployment Strategy

Hybrid architectures segment workloads. Highly regulated data remains in secure private clouds, while public cloud resources handle burst training and non-critical experimentation.

### Multi-Cloud Resilience Strategy

Distributing workloads across multiple providers mitigates vendor lock-in and protects against localized outages, guaranteeing AI pipeline continuity.

### Edge Deployment Strategy

Placing AI inference locally on edge devices drastically cuts latency. This strategy is critical for latency-sensitive workloads such as medical imaging analysis and industrial automation.

## Operational Readiness for AI Workloads

Preparing for AI workloads demands coordination across staffing, monitoring, and capacity planning.

Private clouds require engineers with experience in bare-metal GPUs and high-performance networking. Public clouds require cloud architects skilled in IAM governance and cost optimization.

AI workloads demand strict Service-Level Agreements (SLAs). Organizations must deploy granular monitoring to track compute, storage, and networking bottlenecks. Resources must precisely match workload demands, linking hardware procurement cycles with expected training volume.

## Decision Framework and Checklist: Public Cloud vs Private Cloud

Decision-making for AI workload placement requires a structured evaluation, and therefore, organizations must assess data sensitivity, performance expectations, long-term cost, and operational readiness before selecting an environment. The checklist below provides detailed criteria for comparing public and private clouds, and the decision matrix offers a concise view of the main differences.

### Checklist for Evaluating Public vs Private Cloud

#### *Data Sensitivity and Compliance*

- Score the sensitivity level of training and inference data and determine whether public cloud certifications are sufficient or if private cloud residency is required.
- Verify compliance obligations and confirm that the environment can provide the necessary auditability and governance.
- Assess data residency requirements and ensure the chosen environment meets jurisdictional constraints.

#### *Performance and Workload Behavior*

- Benchmark representative training and inference workloads and compare throughput and latency across environments.
- Evaluate storage and data-pipeline performance, and determine whether proximity to compute favors one model over the other.
- Review GPU availability and scaling patterns, and confirm whether burst capacity in the public cloud or predictable performance in the private cloud better aligns with workload needs.

#### *Cost and Financial Planning*

- Calculate three- to five-year cost projections, and include managed services, egress fees, hardware, power, and cooling.
- Estimate network and egress cost impacts and determine whether data movement patterns favor public cloud flexibility or private cloud predictability.
- Review the procurement cycle, refresh the timeline, and confirm whether the organization can sustain private cloud hardware planning or prefers public cloud elasticity.

#### *Operational Readiness and Migration Confidence*

- Assess staffing and skill requirements and verify whether the team can manage private cloud operations or prefers managed services in public cloud.
- Validate monitoring, logging, and SLA expectations, and ensure the environment supports the required visibility and reliability.
- Pilot the selected workload before full migration, and confirm that performance, cost, and integration behavior match expectations.

#### *Decision Matrix: Public Cloud vs Private Cloud*

The matrix below summarizes the main differences across the evaluation dimensions to make decision-making easier.

**Table 1: Decision Matrix Comparing Public and Private Cloud Across Core Evaluation Dimension**

| **Dimension** | **Public Cloud** | **Private Cloud** |
| --- | --- | --- |
| **Data Sensitivity** | Broad certifications; shared infrastructure. | Full control and isolation. |
| **Performance** | Flexible scaling; variable latency. | Predictable and stable. |
| **GPU Access** | Large catalog; fluctuating availability. | Guaranteed but limited by procurement. |
| **Cost Pattern** | Variable and usage-driven. | Upfront but stable long-term. |
| **Network Impact** | Egress fees and regional charges. | No egress fees; higher local investment. |
| **Operations** | Lower operational burden. | Higher responsibility and staffing needs. |
| **Migration Fit** | Easier to pilot and scale gradually. | Requires careful planning and validation. |

## The Bottom Line

Selecting an AI workload environment requires balancing performance, security, compliance, and cost. Public clouds accelerate prototyping through managed services and flexible GPU access, but extended training cycles incur significant egress fees and premium storage costs.

Private clouds guarantee dedicated hardware, predictable performance, and absolute control over sensitive data. While demanding upfront investment in infrastructure and engineering talent, a private cloud is the superior choice for long-term workloads, proprietary datasets, and strict regulatory governance.

Hybrid and multi-cloud strategies empower organizations to leverage the strengths of both environments. Running training on the public cloud while securing sensitive inference locally balances costs, eliminates bottlenecks, and ensures enterprise AI remains efficient, compliant, and highly secure.


---

# Why AI Models Run Faster on Bare Metal Servers

> URL: https://www.atlantic.net/dedicated-server-hosting/why-ai-models-run-faster-on-bare-metal-servers/ | Published: 2026-03-14 | Author: Dr. Assad Abbas

AI models have increased greatly in size and complexity over the past few years. Organizations now face massive requirements for GPU performance, storage throughput, and network capacity. These technical demands dictate infrastructure decisions; the underlying platform directly limits training speed and inference latency. The staggering growth in the number of model parameters also makes performance stability a top priority for engineering teams.

Many teams observe unstable behavior in virtualized GPU environments during long training jobs or real-time inference. Virtualization introduces extra software layers between the application and the physical hardware. These intermediate layers introduce scheduling delays and resource contention, reducing throughput and leading to latency spikes.

[Bare metal servers](https://www.atlantic.net/dedicated-server-hosting/what-is-a-bare-metal-server-benefits-use-cases-and-best-practices/) follow a different infrastructure approach. They provide direct access to GPUs, CPUs, and storage without the need for hypervisors. Training steps complete faster, inference latency remains lower, and performance is highly consistent. Single-tenant hardware removes the noisy neighbor effect, and this deep isolation maintains stable behavior for continuous computational tasks.

AI workloads rely heavily on GPU processing speed, memory bandwidth, and fast data movement. As model sizes scale, these factors become hypersensitive to micro-delays. Virtualized systems introduce overhead and shared resource conflicts. Bare-metal servers eliminate these bottlenecks, providing the raw, stable performance required for continuous AI workloads and large-scale training pipelines.

This article examines why AI models run faster on bare metal by breaking down infrastructure design, **2026** benchmark results, hardware requirements, and a practical framework for evaluating hosting providers.

## Why AI Models Run Faster on Bare Metal

AI workloads depend on uninterrupted access to GPUs, CPUs, and storage. The way a platform manages these resources dictates the success of training and inference tasks. On bare-metal servers, there are no virtualization layers between the hardware and the AI system. Resources are dedicated and predictable. This allows models to perform reliably under extreme computational load.

Several public sources report identical performance patterns for A100 and H100 GPUs across bare metal and virtualized environments. Vendor documentation from NVIDIA, virtualization studies, and benchmark reports published by AWS highlight clear differences in throughput, utilization, and latency when the same GPU models run under different infrastructure designs. Dedicated resources and single-tenant isolation enable AI workloads to run faster and fail less.

### Predictable Performance Advantage

AI workloads require continuous hardware access. The allocation method directly affects training throughput and inference latency. Bare metal servers provide direct hardware access without the overhead of virtualization. Training jobs finish earlier, and inference latency drops significantly. Vendor-reported results for A100 and H100 GPUs show that bare-metal systems achieve much higher effective GPU utilization during large-scale model training. Independent evaluations also show vastly lower [p95 and p99 latency](https://medium.com/javarevisited/mastering-latency-metrics-p90-p95-p99-d5427faea879) on bare metal, a critical metric for interactive and real-time applications.

Virtualized environments force shared resources and noisy neighbors onto your workloads. This causes uneven performance and unpredictable latency. During extended training runs, teams frequently experience variable epoch times and uncertain completion windows for jobs. By dedicating hardware to a single tenant, bare-metal servers maintain steady step times and consistent GPU and memory utilization. This reliability allows engineering teams to plan capacity and estimate costs accurately.

### Single-Tenant Isolation

Bare-metal servers are single-tenant: a single organization uses the entire machine. Cross-tenant interference is eliminated, neutralizing exposure to multiple side-channel security risks.

This isolation is incredibly valuable for AI workloads processing sensitive information, such as electronic Protected Health Information (ePHI (electronic Protected Health Information)) or cardholder data. A single-tenant environment vastly simplifies the management of data flows, logging, and access policies. Building architectures that are genuinely HIPAA-compliant or PCI-compliant requires this level of foundational consistency.

### Benchmark Observations

The following tables summarize common patterns reported across public cloud tests, vendor documentation, and independent evaluations of GPU performance.

**Table 1: AI Training Performance Comparison (2026)**

| **Infrastructure Type** | **GPU Type** | **Training Throughput** | **GPU Utilization** | **Latency Variability** |
| --- | --- | --- | --- | --- |
| Virtualized GPU Instance | A100 80GB | Lower | Moderate | Higher |
| Virtualized GPU Instance | H100 | Moderate | Moderate | Moderate |
| Bare Metal Server | A100 80GB | Higher | High | Low |
| Bare Metal Server | H100 | Highest | Very High | Very Low |

**Table 2: Inference Latency Comparison (13B LLM, 2026)**

| **Infrastructure** | **Model** | **p50 Latency** | **p95 Latency** | **p99 latency** |
| --- | --- | --- | --- | --- |
| Virtualized GPU | 13B LLM | Higher | Higher | Highest |
| Bare Metal GPU | 13B LLM | Lower | Lower | Lower |

Bare-metal servers offer predictable performance while providing single-tenant isolation with guaranteed hardware access. Organizations running large-scale AI training or latency-sensitive inference achieve significantly higher efficiency with bare-metal infrastructure.

### Cost Advantages for Sustained Workloads

Cloud GPU instances offer rapid provisioning, making them ideal for short-term or experimental projects. Long training cycles or steady-state inference services tell a different financial story. High cumulative cloud costs quickly outpace the fixed monthly billing for bare-metal servers. Bare metal significantly reduces the cost per GPU-hour when utilization remains high.

Bare metal is the economical choice for continuous training jobs and high-traffic inference workloads. This cost-benefit stacks with stable utilization, ensuring you actually use the GPU resources you pay for rather than losing compute cycles to virtualization overhead.

## AI Workloads, Model Sizes, and Infrastructure Requirements

Different AI workloads require radically different infrastructure. Understanding these categories prevents expensive hardware mismatches.

### AI Workload Types

AI workloads vary in the resources they require, and understanding these differences is key to planning infrastructure. Common workload types include:

- **Large-scale training**: Building models from scratch using massive datasets. Requires many GPUs and high memory bandwidth.
- **Fine-tuning**: Adjusting existing models for specific tasks. Needs fewer GPUs but must maintain steady processing.
- **Batch inference**: Running predictions on large datasets at once. Prioritizes high throughput over immediate responses.
- **Real-time inference**: Making predictions instantly for live applications. Requires low latency and predictable timing.
- [**Retrieval Augmented Generation (RAG)**](https://www.unite.ai/what-is-retrieval-augmented-generation/): Combines AI model computation with fast storage and search. Adds extra demand on GPUs and data pipelines.

Training requires sustained computing power. Inference relies on predictable timing. Data pipelines depend on rapid input/output (I/O). Matching the infrastructure to the workload guarantees operational efficiency.

### Resource Profiles by Workload

AI workloads use different combinations of CPU, GPU, memory, and storage depending on the task. For instance:

- Training workloads rely heavily on GPUs and large VRAM to store model states and gradients. They also need fast storage to efficiently feed large datasets.
- Inference workloads are sensitive to latency and require balanced GPU performance, sufficient memory, and fast network connections to deliver predictable response times.
- Data preprocessing depends more on CPU cores and storage speed to prepare inputs for training or inference.

Since each workload has distinct requirements, no single server type handles all tasks optimally. Organizations typically deploy dedicated node types for training, inference, and preprocessing.

### Model Sizes and VRAM Requirements

Model size dictates your VRAM footprint. Small models with fewer than 3 billion parameters fit comfortably on single consumer or entry-level enterprise GPUs. Medium-sized models (7–13 billion parameters) usually require tensor parallelism across two GPUs to achieve acceptable throughput. Large models (30–70 billion parameters) require at least 4 high-end GPUs when using high-precision formats. Extra-large models require multi-node clusters linked via high-speed interconnects.

Numerical precision directly controls VRAM usage. While FP16 and BF16 remain standard for training, FP8 and FP4 dominate production inference in 2026. Specialized quantization formats like GGUF, EXL2, and AWQ drastically compress models, slashing memory requirements while preserving accuracy. Proper VRAM planning requires calculating model size, precision, batch size, and KV-cache overhead to prevent hard bottlenecks.

### System Dependencies

Storage throughput is the silent killer of AI performance. Fast storage ensures GPUs receive data without interruption, eliminating idle time. Local NVMe drives deliver the high read/write speeds needed to move large datasets through the pipeline.

Network-attached storage frequently introduces I/O delays under heavy load. Multi-GPU setups rely entirely on high-speed interconnects like NVLink or PCIe Gen5 to bypass CPU bottlenecks during device-to-device transfers. Evaluating storage, network, and compute holistically is mandatory. A slow storage array renders a farm of H100s useless.

## Hardware Architecture for High-Performance AI Systems

Hardware design dictates the speed and efficiency of AI workloads.

### NUMA Topology and CPU–GPU Affinity

Memory access speed is governed by Non-Uniform Memory Access ([NUMA](https://www.redhat.com/en/blog/driving-fast-lane-cpu-pinning-and-numa-topology-awareness-openstack-compute)) topology in multi-socket servers. When processes access memory across distant NUMA nodes, latency spikes and performance plummets. Pinning CPU and GPU processes to their localized NUMA domains maintains high throughput.

Tools like numactl allow engineers to bind processes to specific NUMA nodes, and frameworks like PyTorch natively support NUMA-aware operations. Proper CPU-GPU affinity configuration drastically improves training speeds on large multi-socket servers.

### PCIe Topology and GPU Placement

Peripheral Component Interconnect Express ([PCIe](https://www.techradar.com/computing/computing-components/pcie-lanes-explained)) lanes dictate the bandwidth available to your GPUs. If multiple GPUs share a single PCIe root complex, data transfer speeds crash. Mapping the server’s PCIe layout is a mandatory step before deploying large AI workloads.

High-end AI servers utilize PCIe Gen5 with highly optimized lane distribution. Data flows freely between GPUs and storage, eliminating internal traffic jams. Strategic GPU placement ensures model parallelism and tensor fusion perform reliably under maximum load.

### High-Performance Networking

Distributed training lives and dies by server-to-server communication. RDMA protocols such as InfiniBand and RoCEv2 bypass CPU processing entirely. This drops latency to the floor and allows multi-node training to scale linearly.

Network tuning separates amateur setups from production clusters. MTU size, quality of service policies, and congestion control algorithms dictate data transfer speeds. Deploying 400 Gbps InfiniBand or high-speed Ethernet ensures your GPUs never wait for data.

### GPUs, CPUs, and Superchip Architectures

Modern GPUs vary wildly in memory size, bandwidth, and tensor core capability. NVIDIA A100 and H100 GPUs provide massive VRAM and specialized tensor cores for large-scale training. CPUs handle the data loading, preprocessing, and task scheduling. Superchip architectures natively integrate GPU and CPU memory, eradicating the overhead of PCIe device-to-device transfers.

**Table 3: GPU Hardware Comparison**

| **GPU** | **VRAM** | **Memory Bandwidth** | **Typical AI Use** |
| --- | --- | --- | --- |
| A100 | 40–80 GB | high | Large model training |
| H100 | 80 GB | very high | LLM training and inference |
| L40S | 48 GB | moderate | Inference and fine-tuning |
| MI300X | 192 GB | very high | Large-scale training |
| GH200 | Unified memory | extremely high | Extremely large models |

Therefore, selecting GPUs based on model size, precision, and throughput requirements is critical. CPUs must support GPU tasks efficiently to prevent pipeline bottlenecks, and high-speed interconnects ensure data movement does not limit performance.

## Bare Metal Cloud vs Traditional Bare Metal Hosting

Both bare-metal cloud and traditional bare-metal hosting provide direct access to physical hardware. Their operational models, however, are vastly different.

Bare metal cloud prioritizes rapid provisioning via APIs. Infrastructure spins up in minutes. This suits AI experimentation, short training cycles, and highly volatile environments. The tradeoff is limited hardware customization.

Traditional bare metal hosting relies on highly structured provisioning. You select exact server specifications, GPU counts, storage layouts, and network topologies. Deployment takes longer, but the resulting infrastructure perfectly matches the exact requirements of your AI workloads. Production inference systems and continuous training pipelines thrive here.

Billing structures align with these models. Bare-metal cloud relies on hourly pricing, which benefits intermittent workloads. Traditional hosting utilizes fixed monthly contracts, making continuous 24/7 operations mathematically cheaper.

## Security, Compliance, and Data Control for AI Projects

Security architecture dictates deployment environments. AI systems processing regulated data require hardware-level protection.

Shared cloud environments distribute resources across thousands of users, removing direct control over the hardware stack. Single-tenant servers provide dedicated, isolated resources. You control the security policies and system access directly. Given this added control, engineering teams heavily favor dedicated infrastructure for sensitive data.

Encryption in transit must be implemented strictly using TLS to protect data as it moves across networks. Encryption at rest secures the physical datasets and model weights on disk.

Encryption requires rigorous key management. Some teams utilize centralized cloud KMS, while others deploy strict Hardware Security Modules (HSMs). Additionally, data residency regulations often legally require your data to remain within specific geographic facilities.

Operational visibility ensures ongoing security. Dedicated servers provide unfiltered access to system logs, hardware metrics, and audit trails.

## Operational Practices and Validation Steps for Bare Metal AI Projects

Running AI workloads on bare metal requires strict operational discipline. Teams begin by standardizing the server provisioning workflow. Installing drivers, configuring GPUs, and tuning network settings must be automated via infrastructure-as-code to prevent manual configuration drift.

Once provisioned, rigorous monitoring under load is mandatory. Key metrics include:

- **GPU utilization:** Confirms models are saturating compute cores.
- **Memory usage:** Tracks how batch sizes impact system pressure.
- **Storage throughput:** Identifies I/O bottlenecks during dataset ingestion.
- **Network traffic:** Monitors the speed of checkpointing across cluster nodes.

Training jobs run for days; hardware interruptions are inevitable. Automated checkpointing to secure external storage ensures training resumes seamlessly after a node failure.

Always conduct a controlled pilot run before scaling. Run a realistic training job, measure the exact p95 latency, verify the checkpoint recovery process, and finalize your automated provisioning scripts.

## Provider Comparison Checklist and Quick Evaluation

Comparing bare metal providers requires a strict, standardized checklist.

### Hardware

- Check the CPU generation, GPU models, memory capacity, and storage options, since these components determine training and inference performance.
- Verify the number of GPUs per node and the available interconnects, as these affect large-scale model training and future scaling.
- Confirm that the provider offers current hardware and clear upgrade paths as workloads grow.

### Network

- Review bandwidth between servers and within the private network to understand how data moves during training.
- Examine latency and stability during large transfers, since slow links can delay dataset loading and checkpoint movement.
- Confirm support for multi-node training, including reliable connectivity for distributed workloads.

### Support

- Check support availability and response times to understand how quickly operational issues are resolved.
- Verify access to engineers familiar with GPU workloads, especially for driver issues or hardware failures.
- Ensure support remains reliable during long training runs, where interruptions can delay progress.

### Compliance

- Review security certifications and data handling policies to confirm they align with internal requirements.
- Verify isolation options for sensitive workloads, including storage and access controls.
- Confirm the availability of logging, auditing, and data protection mechanisms.

## Cost Analysis and the Situational Suitability of Bare Metal for AI Workloads

Cost is one of the main reasons organizations compare cloud infrastructure with bare metal servers for AI workloads. While cloud platforms offer flexibility through hourly pricing, long training jobs can quickly drive up costs. As a result, many organizations evaluate the Total Cost of Ownership (TCO) to understand how expenses change over time.

### TCO Model for Sustained Training

A simple TCO model usually starts with the number of hours that training jobs run in a typical month. This number is important because cloud infrastructure charges for every hour that GPUs remain active. Once the total hours are known, they are multiplied by the selected cloud GPU’s hourly price to estimate the basic compute cost.

However, compute pricing alone does not reflect the full cost of running AI workloads in the cloud. Storage space, network transfer, and additional services also contribute to the final bill. When these elements are added to the calculation, the monthly cost becomes more realistic.

At this point, organizations can compare the cloud estimate with the monthly price of a bare-metal server with a similar GPU. This comparison should also include support and bandwidth, since these factors influence the final cost. Looking at these factors together helps organizations see how pricing changes when training jobs run continuously.

### Cloud Hourly vs. Bare Metal Monthly

The difference between cloud and bare-metal pricing becomes clearer as workloads run for longer periods. Cloud platforms charge by the hour, which makes them ideal for short experiments or temporary workloads. Because resources can be stopped at any time, clients only pay for the hours they actually use.

However, the situation changes when training jobs run for many hours or days without interruption. In that case, hourly charges continue to accumulate, which gradually increases the monthly cost. Bare-metal servers follow a different model, offering fixed monthly pricing. Since the price does not change with usage time, long-running workloads often become easier to predict and manage financially.

### When Bare Metal Is Attractive

This cost difference explains why some AI projects eventually move to bare metal infrastructure. The model becomes attractive when training jobs run frequently and require stable access to hardware. It also helps when teams want to avoid shared environments and maintain full control over GPU resources.

Another factor is network usage. Large datasets and model checkpoints can result in significant data transfer, which can sometimes increase cloud expenses. Dedicated servers usually offer more predictable bandwidth costs, making budgeting simpler.

In many organizations, these cost patterns lead to running experiments in the cloud and later migrating long-running workloads to bare-metal systems. This transition preserves the flexibility of cloud platforms while providing the cost stability of dedicated infrastructure.

## How Atlantic.Net Aligns with AI Requirements

[Atlantic.Net](https://www.atlantic.net) provides dedicated bare-metal servers designed to support AI workloads that require stable, predictable hardware performance. Because these servers offer direct access to physical resources, organizations can run training and inference tasks without sharing GPUs or CPUs with other users. The platform also includes HIPAA-compliant hosting for environments that handle ePHI, and a HIPAA Business Associate Agreement (BAA) is available for projects that must meet regulatory requirements. Using the provider checklist discussed earlier, organizations can evaluate the platform across the same four areas: hardware, network, support, and compliance.

**Hardware:** Atlantic.Net provides modern CPUs, a range of GPU options, and flexible memory and storage configurations. This setup supports current workloads and scales as models or datasets grow.

**Network:** High-bandwidth connections and private networking from Atlantic.Net maintain steady data flow for AI pipelines. This ensures consistent throughput during dataset transfers, checkpoint operations, and distributed multi-node training.

**Support:** Technical staff familiar with GPU hardware and AI workloads are available to assist. This reduces downtime and ensures long-running training jobs stay on track.

**Compliance:** The platform is HIPAA-compliant, with logging, auditing, and isolation features. These measures help secure sensitive data and meet regulatory requirements.

**Overall Fit:** Evaluated against the provider checklist, Atlantic.Net delivers dedicated hardware, stable performance, strong support, and regulatory compliance, making it suitable for demanding AI training and inference workloads.

When evaluated through the provider checklist, Atlantic.Net aligns well with organizations that require dedicated hardware, strong compliance support, and stable infrastructure for AI training and inference workloads.

## Conclusion and Next Steps

Bare metal servers fundamentally improve AI performance. By stripping away hypervisors and virtualization overhead, dedicated GPUs deliver higher throughput and incredibly low tail latency.

A controlled pilot run is the best way to validate this performance leap. Deploy a representative training job and a small inference service, then measure your p95 latency and peak GPU utilization against your current cloud environment.


---

# Private Cloud for AI: Strategy, Infrastructure & Deployment

> URL: https://www.atlantic.net/cloud-platform/private-cloud-ai-strategy-infrastructure-deployment/ | Published: 2026-03-14 | Author: Dr. Assad Abbas

In 2026, organizations are increasingly evaluating where their Artificial Intelligence (AI) workloads should run. This decision has become more complex because modern AI systems require large computing capacity, stable GPU performance, and reliable data access. At the same time, many of these systems process sensitive information and must operate under strict regulatory requirements. For this reason, infrastructure planning has become an important part of enterprise AI strategy.

[Public cloud](https://aws.amazon.com/what-is/public-cloud/) platforms are often used for experimentation and short-term development because they provide quick access to computing resources. However, this model may not suit every situation, particularly when AI training requires continuous GPU availability over long periods. In addition, organizations that manage regulated data must maintain strict control over storage, access, and auditing. These operational and regulatory concerns have led many enterprises to consider [private cloud](https://aws.amazon.com/what-is/private-cloud/) environments as an alternative.

A private cloud provides a dedicated infrastructure environment that the organization controls directly. The enterprise manages the hardware, storage locations, and security policies, and maintains clear visibility into system operations and data handling. This level of control becomes particularly important when [AI workloads](https://www.atlantic.net/gpu-server-hosting/scaling-ai-workloads-why-hybrid-cloud-infrastructure-is-the-future-of-enterprise-ai/) involve regulated or sensitive information.

Predictable performance is another reason organizations consider private cloud for AI workloads. In shared environments, computing resources may compete with other workloads, affecting training speed and inference latency. In contrast, dedicated infrastructure allows GPU clusters and storage systems to operate without external interference. This stability is particularly important for large AI models that run continuous training jobs or high-volume inference services.

Regulatory compliance also plays an important role in infrastructure decisions. Healthcare organizations, for example, must protect electronic Protected Health Information (ePHI (electronic Protected Health Information)) in accordance with strict regulatory standards. Similarly, enterprises working with regulated datasets often require network isolation, detailed auditing, and controlled data residency. A private cloud environment can meet these requirements because infrastructure and security policies remain under organizational control.

Operational performance further strengthens the case for private infrastructure. Large-scale AI training depends on stable GPU clusters, high-throughput storage, and reliable networking. Production inference systems also require consistent response times to maintain application performance. Dedicated resources in a private cloud environment make it easier to maintain this operational consistency. For these reasons, many enterprises are evaluating private cloud infrastructure as part of their AI deployment strategy.

This article discusses when a private cloud is suitable for AI workloads and outlines the infrastructure, governance, and deployment considerations required for reliable operation.

## Strategic Rationale for Private Cloud AI

When organizations plan long-term infrastructure for AI workloads, the decision is not only about selecting a hosting platform. Infrastructure planning also includes understanding workload behavior, data management needs, and regulatory obligations. These elements are closely connected to AI operations, and many enterprises examine private cloud infrastructure as part of their broader strategy.

Operational predictability is an important consideration in this discussion. Large AI projects typically move through several stages, including data preparation, model training, validation, and production inference. These stages usually follow fixed project schedules. When computing resources are unavailable at the required time, development work can slow down, and project timelines may be affected. Many organizations, therefore, prefer an infrastructure that allows GPU resources and storage capacity to be planned. A private cloud environment can provide this level of planning because the hardware and network configuration remain under organizational control.

Infrastructure decisions also involve several leadership roles within the organization. The Chief Information Officer and Chief Technology Officer usually review the architecture and evaluate long-term infrastructure capacity. At the same time, the Chief Data or AI Officer focuses more on model development environments and data pipelines. Security leadership, including the Chief Information Security Officer, examines regulatory obligations and security controls that affect AI workloads.

Infrastructure and operations teams then evaluate whether existing data center facilities can support new GPU clusters, storage systems, and networking capacity. Business unit leaders also participate in the discussion because they define the expected outcomes of AI initiatives and the delivery timelines. Private cloud planning, therefore, becomes a collaborative effort involving technical teams, security specialists, and business leadership.

Project timelines create another important dependency. High-performance GPU systems usually require procurement, installation, and data center preparation before they become operational. AI teams must align their development schedules with infrastructure readiness and compliance approvals. When procurement, engineering preparation, and governance reviews are coordinated properly, private cloud deployments can support AI workloads stably and predictably.

## Architectural Components of Private AI Infrastructure

A private AI environment includes several layers that work together to run AI workloads. These layers mainly include compute, storage, networking, and management systems. Each component plays a different role in supporting performance, data movement, and operational control. Understanding these components and their hardware requirements is important because AI workloads depend on stable and well-coordinated infrastructure.

### Core Infrastructure and Hardware Requirements

The core infrastructure of a private AI environment provides the computing and data resources required for model training and inference. Compute resources typically include GPU clusters, CPU nodes, and, in some cases, specialized accelerators. These systems provide the processing capacity needed for large machine learning models. For example, training large models often requires GPUs with high memory bandwidth and fast interconnects to enable efficient distributed processing. In contrast, inference workloads may rely on smaller or optimized accelerators depending on the required response time and workload scale.

Storage systems also play an important role because AI workloads continuously read large datasets during training. High-throughput, low-latency storage helps ensure that GPUs receive data without interruption. Networking is equally important since data must move quickly between compute nodes, storage systems, and other services. Technologies such as RDMA, NVLink, and InfiniBand help improve data transfer speeds in multi-GPU environments.

Management platforms coordinate these resources and keep workloads organized. Orchestration systems such as Kubernetes, OpenShift, or Slurm schedule jobs and distribute workloads across available nodes. In addition, MLOps platforms assist with model training, deployment, and monitoring throughout the AI lifecycle. Security and identity management systems also remain important because they control access and protect sensitive data. When these components are properly combined, the infrastructure can support reliable and efficient AI operations.

### Integration with Enterprise IT Systems

Private AI infrastructure also needs to connect with existing enterprise IT systems to operate properly. When this connection is missing, AI environments can become isolated from the organization’s data sources and operational workflows. Identity and access management systems help address this issue by providing consistent authentication across different platforms. Similarly, data pipelines and ETL systems deliver training datasets in formats that AI frameworks can process efficiently. Through these connections, the AI environment becomes part of the broader enterprise infrastructure rather than a separate technical system.

Monitoring systems are also necessary because they track system performance and alert teams when operational problems appear. Backup and disaster recovery solutions protect important datasets and trained models from accidental loss or system failures. Logging platforms and SIEM tools further assist security teams by recording activity and supporting compliance requirements.

When these systems are integrated properly, the AI infrastructure becomes part of the broader enterprise environment. This integration helps maintain operational stability, data security, and consistent management across all systems.

## Data Center and Hybrid Cloud Considerations

Organizations must ensure their physical and virtual environments can efficiently support AI workloads. This includes evaluating power, cooling, data locality, and connectivity requirements before deployment.

### Data Center Readiness for AI

AI hardware often requires high power density. For example, many GPU racks consume several kilowatts per rack. At the same time, cooling systems must support liquid cooling or advanced airflow to maintain optimal temperatures. Similarly, rack space and floor load need careful evaluation to ensure safety and stability. Therefore, assessing the data center before deployment is essential to prevent infrastructure bottlenecks or failures.

### Hybrid Cloud Patterns for AI

Once data center readiness is established, organizations can consider [hybrid cloud](https://www.atlantic.net/ashburn-virginia-hosting/understanding-hybrid-cloud-examples/) patterns. For instance, training workloads may run on-prem, while inference occurs in the public cloud. Likewise, sensitive data can remain on-prem, while non-sensitive workloads use cloud capacity. In addition, federated learning allows distributed data processing across multiple sites. Hybrid patterns help balance performance, flexibility, and compliance requirements.

### Connectivity and Low-Latency Access

Once hybrid cloud patterns are chosen, organizations need to ensure their networks support fast, reliable communication between on-prem and cloud systems. This is important because AI workloads often involve frequent data transfer and synchronization. For example, direct cloud interconnects reduce round-trip times and improve system responsiveness. Similarly, SD-WAN or MPLS solutions help connect multiple sites efficiently, maintaining consistent performance. In addition, implementing zero-trust network segmentation protects sensitive data as it moves across networks. Therefore, careful network planning is essential to support both performance and security in hybrid AI deployments.

### AI Models and Generative AI Choices

Organizations that deploy AI in private cloud environments must also decide which models are suitable for their workloads. This decision is not limited to selecting a model architecture. It also involves deciding whether a [foundation model](https://aws.amazon.com/what-is/foundation-models/) is sufficient, whether customization is required, and how model governance will be maintained. These decisions affect infrastructure usage and data management; model selection must align with available compute resources, enterprise data policies, and organizational objectives.

### Foundation Model Use Cases

Foundation models support many enterprise AI applications. These models can process text, images, speech, and sometimes multiple data types simultaneously. Many organizations use them in knowledge retrieval systems, where large language models work together with retrieval-augmented generation. In addition, enterprises deploy foundation models for chat assistants, document analysis, and automated reporting.

These applications often require access to internal enterprise data. This information may contain sensitive or regulated content; organizations prefer environments where data access can be controlled. Private cloud environments provide this level of control, which explains why many enterprises run foundation model workloads within their own infrastructure.

### When to Fine-Tune Models

Although foundation models are useful for general tasks, they may not always perform well in specialized domains. In such situations, organizations consider fine-tuning the model using domain-specific datasets. This process enables the model to learn terminology, patterns, and context common to a particular industry.

Industries such as healthcare, finance, and legal services often require this level of specialization. These sectors usually expect higher accuracy and stronger contextual understanding in AI outputs. At the same time, regulatory expectations may require responses that are consistent and explainable. Fine-tuning can help address these requirements, but it also increases compute usage and operational complexity. Organizations, therefore, examine both technical requirements and business goals before introducing fine-tuning into their private AI infrastructure.

### Closed and Open-Source Generative AI Models

Another important decision concerns the choice between closed and open-source generative AI models. Closed models typically offer strong performance and vendor-supported services. Many providers also supply managed APIs and integrated development tools. These features can simplify deployment for enterprise teams.

However, closed models may impose limitations on licensing, customization, or data-handling policies. Open-source models offer a different approach. Enterprises can inspect the architecture, modify the training process, and adapt the system for specific use cases. This flexibility makes open models attractive for organizations that require deeper control over their AI systems.

Operating open models also requires internal expertise. Teams must manage deployment, optimization, and security responsibilities themselves. Due to these differences, organizations using private cloud infrastructure usually compare the two options before selecting a strategy.

### Model Lineage and Provenance

Model governance is another important aspect of enterprise AI deployment. One part of governance is [model lineage](https://aws.amazon.com/blogs/machine-learning/model-and-data-lineage-in-machine-learning-experimentation/), which records the history of an AI model’s development. This record typically includes the datasets used for training, the training runs that were executed, and the checkpoints generated during development.

Model provenance is closely related to lineage. It focuses on verifying the model’s origin and authenticity, as well as its training process. This information is important for organizations subject to regulatory oversight. When model behavior must be audited or explained, these records provide the required transparency.

For this reason, enterprises running AI systems in private cloud environments usually maintain detailed documentation and version control. Monitoring tools and experiment tracking systems are also used to record changes during model development. These practices help maintain accountability and support compliance reviews when required.

## AI Agents at Scale: Management and Enterprise Use Cases

Enterprises are steadily expanding AI deployments within private cloud environments, and as a result, AI agents are increasingly integrated into operational systems. These agents automate tasks, support decision-making, and interact with enterprise applications. Organizations must carefully plan their deployments, management, and governance to ensure agents operate efficiently and reliably at scale on private cloud infrastructure.

### Types of AI Agents

AI agents can perform different roles depending on the tasks they support. Some agents focus on executing specific actions. For example, task agents retrieve data, generate responses, or perform predefined operations on dedicated compute resources. Other agents coordinate processes across multiple applications. These workflow agents connect several systems and manage sequences of tasks across enterprise services running on private cloud infrastructure.

Decision agents represent another category. These agents analyze incoming data and recommend actions using predefined rules or machine learning models. All these agents rely on private cloud resources; their access to compute, storage, and network systems must be properly controlled. Identifying the different types of agents, therefore, helps organizations plan infrastructure capacity and maintain stable operations.

### Enterprise Use Cases for AI Agents

After defining the types of agents, organizations usually identify the practical areas where they can be used. Many enterprise teams already deploy agents to support operational activities. IT departments, for example, use automation agents to monitor systems and manage routine maintenance tasks. These agents help reduce manual work while operating within the controlled environment of the private cloud.

Customer service platforms represent another common use case. Conversational agents running on private cloud infrastructure assist users by answering questions and resolving routine issues. Knowledge retrieval agents also support employees by locating internal documents and information across enterprise repositories. Workflow agents extend these capabilities further by coordinating activities across business applications. Through these uses, AI agents gradually become part of daily enterprise operations.

### Managing AI Agents at Scale

As the number of agents grows, management becomes an important operational concern. Each agent consumes compute resources and interacts with other systems. Resource allocation must therefore be planned so that agents do not interfere with training jobs or other AI workloads. Scheduling systems help distribute tasks across available CPU and GPU resources.

State management also becomes necessary because many agents perform multi-step tasks across different applications. Monitoring tools further support operations by tracking performance and detecting unusual behavior. With these mechanisms in place, organizations can operate large numbers of AI agents while maintaining predictable system performance.

### Governance Controls for Agent Autonomy

Governance becomes particularly important when AI agents interact with enterprise systems and sensitive data. Organizations must ensure that agents operate within clearly defined boundaries. One common approach involves human-in-the-loop checkpoints for actions that affect business operations. These checkpoints allow human review before critical decisions are executed.

Access control policies also restrict agents to approved data sources and applications within the private cloud environment. Monitoring systems record agent activity and help identify unusual behavior that may require investigation. These controls are important for enterprises operating under regulatory obligations. Establishing governance frameworks early, therefore, helps maintain accountability and reduces operational risk when deploying AI agents at scale.

## Deploying AI From Pilot to Production

Organizations building AI systems on private cloud infrastructure usually begin with pilot deployments before moving to full production. This approach is useful because it allows teams to test models with enterprise data and controlled infrastructure. As a result, potential issues related to compute resources, storage access, and data pipelines can be identified early. Therefore, a structured transition from pilot testing to production is necessary for reliable AI deployment on private cloud platforms.

### Pilot Planning

Pilot planning begins with selecting datasets that represent real production data stored in the private cloud environment. This step is important because unrealistic datasets may produce misleading results during testing. In addition, teams must evaluate operational feasibility, including GPU availability, storage throughput, and network performance within the private cloud infrastructure. At the same time, clear success criteria should be defined so pilot progress can be measured. Therefore, careful planning helps determine whether the AI workload is ready for production deployment.

### Success Metrics

Once the pilot system is running on the private cloud, organizations must evaluate it using clear performance metrics. For example, latency and throughput measure how efficiently the infrastructure processes requests, while model accuracy shows how well predictions match expected outcomes. However, technical metrics alone are not enough. Therefore, user adoption and business impact should also be considered alongside infrastructure performance. As a result, pilot evaluation should combine both technical and business measures.

### CI/CD for AI Models

Once the pilot demonstrates reliable performance, the next step is to prepare models for consistent deployment. At this stage, [CI/CD pipelines](https://www.atlantic.net/pci-compliant-hosting/continuous-deployment-in-pci-dss-environments-considerations-and-best-practices/) become important because they automate packaging, validation, and testing processes before models are released.

These pipelines also support additional safeguards. Drift detection systems monitor changes in incoming data that could affect model accuracy. Deployment gates introduce review checkpoints to validate models before they enter production systems. With these mechanisms in place, organizations can manage model updates in a structured and repeatable manner.

### Production Monitoring

After deployment, attention shifts to maintaining stable production operations. Continuous monitoring becomes necessary because AI systems interact with live data and operational workloads. Monitoring platforms track inference metrics such as response time, request volume, and system utilization.

Data drift and model performance degradation must also be detected as early as possible. When such issues arise, rollback mechanisms allow teams to restore earlier model versions quickly. Integrating monitoring tools with the private cloud infrastructure, therefore,e helps maintain reliable and consistent AI operations over time.

## Deploying AI Models on Private Cloud

After AI workloads move into production, organizations must establish consistent deployment practices within private cloud infrastructure. This includes packaging models correctly, selecting suitable inference architectures, and managing model versions carefully. As a result, these practices help maintain reliable operations and efficient use of private cloud resources.

### Model Packaging

Model deployment begins with proper packaging so models run consistently across private cloud environments. For example, models may be packaged using containers or optimized formats such as ONNX or TensorRT. These formats are useful because they isolate dependencies and ensure consistent behavior across infrastructure nodes. Therefore, organizations running AI workloads on private cloud platforms should define clear packaging standards.

### Inference Serving Topology

Once models are packaged, they must be deployed using an appropriate inference architecture within the private cloud. In some cases, smaller workloads run on single nodes, while larger applications require distributed clusters. In addition, GPU partitioning and request batching improve efficiency when handling large workloads. Similarly, low-latency edge nodes connected to the private cloud can support real-time applications. The serving topology must match workload needs and infrastructure capacity.

### Model Versioning

After deployment, managing model versions becomes essential for stable operations on private cloud platforms. Versioning systems, therefore, track changes using semantic versioning and promotion workflows. These workflows allow models to move gradually from testing to production environments. At the same time, rollback procedures must be documented so earlier versions can be restored when necessary. Therefore, version management becomes an important part of governance for AI systems running on private cloud infrastructure.

## AI Infrastructure Performance and Economics

Running AI workloads on private cloud infrastructure involves both performance management and cost awareness. Since resources are dedicated, organizations can control compute, storage, and networking. At the same time, they must ensure these resources are used efficiently. Therefore, performance optimization and financial planning are closely linked and must be addressed together.

### GPU Scheduling and Resource Allocation

AI workloads often compete for GPU resources, creating bottlenecks. Scheduling policies help balance resource use across teams and projects. For instance, fair-share scheduling distributes capacity evenly, while priority queues allocate resources to urgent workloads. Multi-instance GPU setups allow multiple workloads to share the same hardware safely. By combining these approaches, organizations maintain predictable performance and reduce operational interruptions in the private cloud.

### Resource Quotas and Performance Benchmarking

Resource quotas further protect infrastructure by limiting GPU, storage, and network usage for each workload. This isolation ensures that critical AI systems remain stable even when other workloads demand heavy resources. Benchmarking for latency, throughput, and distributed training confirms that the infrastructure meets expectations. In addition, tracking GPU utilization and cost per inference provides insight into both efficiency and financial value. Together, quotas, benchmarking, and utilization monitoring create a reliable, efficient, and cost-aware AI environment.

### Financial Modeling and Deployment Choices

Investments in AI infrastructure can be substantial, which makes total cost of ownership models important for planning. By considering hardware, software, facilities, and staffing, organizations gain a realistic picture of long-term expenses. Choices between Capex procurement and consumption-based Opex models must also be evaluated. Linking financial modeling with resource utilization ensures that deployment strategies remain flexible, efficient, and cost-effective over time.

## Governance, Security, and Compliance for Private Cloud AI

AI workloads in private cloud environments often involve sensitive data and critical enterprise operations. Establishing strong governance, security, and compliance measures is as important as managing the infrastructure itself. Without clear policies, operational risk and regulatory exposure increase.

### Strategy Alignment, Data Governance, and Access Controls

Effective governance begins by linking AI initiatives to measurable business outcomes. Workload selection, therefore, should reflect operational priorities and long-term strategy. At the same time, data governance frameworks define classification, retention, and metadata management to ensure datasets remain secure and discoverable. Likewise, identity and access controls define permissions for developers, analysts, and automated systems. In combination, these practices provide a solid foundation for safely and effectively running AI in private cloud environments.

### Compliance, Confidential Computing, and Zero-Trust Security

Many enterprises operate under strict regulatory requirements such as HIPAA, GDPR, PCI DSS, FedRAMP, or CJIS. Therefore, mapping compliance obligations directly into infrastructure design is critical. For workloads involving sensitive information, confidential computing technologies such as trusted execution environments and encrypted memory help maintain protection during processing. At the same time, [zero-trust security](https://www.cloudflare.com/learning/security/glossary/what-is-zero-trust/) principles verify every request, segment network traffic, and encrypt data throughout the system. As a result, these measures together ensure AI workloads are secure, compliant, and reliable.

## Enterprise AI Platforms and Ecosystem

While private cloud provides the foundation for AI workloads, enterprises rarely rely solely on infrastructure. Therefore, understanding the surrounding ecosystem of platforms and partner offerings is essential to deploy AI efficiently.

### AI Platforms and Managed Services

Orchestration platforms, MLOps toolchains, and monitoring services simplify model deployment, workload management, and operational oversight. As a result, teams can focus on building AI applications while the platform handles routine operational tasks. At the same time, these services help maintain consistent performance across private cloud infrastructure.

### Partner Offerings and Reference Architectures

Many enterprises complement internal resources with managed offerings from providers such as Dell APEX, Lenovo TruScale, and Equinix Metal. Likewise, reference architectures from Hewlett Packard Enterprise, including HPE GreenLake, HPE Cray, and Apollo systems, provide tested configurations for compute, storage, and software. By combining internal capabilities with partner services and reference architectures, organizations can accelerate AI adoption while maintaining efficiency, reliability, and operational control in private cloud environments.

## Private Cloud AI in Practice with Atlantic.Net

[Atlantic.Net](https://www.atlantic.net) provides a private cloud platform that combines security, compliance, and reliable performance for AI workloads. It offers HIPAA-compliant hosting for workloads that handle ePHI and signs a [HIPAA Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) when required, ensuring sensitive data is protected. At the same time, its infrastructure delivers predictable GPU availability and stable performance, supporting both large-scale model training and real-time inference.

Healthcare, research, and analytics teams benefit from these features by running high-demand AI tasks with confidence. The platform also provides dedicated GPU nodes and hybrid private cloud options, which integrate smoothly into broader enterprise AI strategies. By combining regulatory compliance with operational reliability, Atlantic.Net enables organizations to deploy AI workloads efficiently while maintaining control over sensitive data.

## Roadmap for Implementing Private Cloud for AI

To start implementing a private cloud for AI, organizations can follow the roadmap below, which balances planning, responsibilities, and operational oversight.

- ### Phased Rollout Plan

Organizations should take a phased approach, beginning with assessing existing infrastructure and AI workloads. Next, move through design, build, pilot, and scale stages. Each phase should include clear deliverables, so progress is visible, and any issues can be addressed promptly.

- ### Roles and Responsibilities

At the same time, it is important to define responsibilities for each stage. IT operations handle infrastructure setup and maintenance, data science teams manage model development and deployment, and governance or compliance teams monitor regulatory adherence. Clarifying roles early helps ensure smooth execution and prevents gaps or overlaps.

- ### Performance Reviews and Cost Audits

Finally, organizations should schedule quarterly performance reviews to track utilization and efficiency, along with annual cost audits to evaluate financial sustainability. These steps maintain operational stability and support continuous improvement over time.

## Final Thoughts

Private cloud gives organizations direct control over their AI workloads, ensuring consistent performance and strong compliance. This makes it a practical choice for teams that handle sensitive data or need reliable GPU access. At the same time, hybrid setups can combine on-premises and cloud resources, keeping data secure while supporting flexible operations.

Careful planning, including defined roles, phased rollouts, and regular performance and cost reviews, helps maintain smooth AI operations and supports long-term growth. By connecting strategy, governance, and infrastructure, enterprises can run AI workloads confidently while meeting both technical and business objectives.


---

# Dedicated Servers vs Bare Metal Cloud for AI/ML 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/dedicated-servers-vs-bare-metal-cloud-ai-ml-pipelines/ | Published: 2026-03-15 | Updated: 2026-03-17 | Author: Dr. Assad Abbas

Artificial intelligence (AI) and machine learning (ML) pipelines process massive models and datasets. Training, fine-tuning, and inference require continuous, heavy GPU compute over long periods. High-speed storage and low-latency networking are critical to maintaining stable performance under data-intensive workloads, making your infrastructure choice a vital factor in efficiency and reliability.

Driven by these requirements, organizations frequently weigh [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/a-comprehensive-guide-to-dedicated-server-technology-for-your-business/) against [bare-metal cloud](https://www.atlantic.net/dedicated-server-hosting/bare-metal-cloud-vs-traditional-dedicated-servers-a-guide-for-ai-workloads/)environments for AI workloads. Both options provide single-tenant hardware with direct access to the CPU, GPU, memory, and storage. This architecture eliminates the performance variation common in shared, virtualized systems. The two models operate differently in practice. Dedicated servers prioritize long-term stability and deep hardware customization, while bare-metal cloud servers deliver rapid provisioning and automated management.

Choosing between these models dictates your performance ceiling, scalability, and operational costs. Many organizations also require infrastructure capable of securing highly sensitive data. A clear comparison between dedicated servers and bare-metal cloud will help you determine the best environment for your specific training, fine-tuning, or production inference needs.

## Understanding Bare Metal and Dedicated Servers

This section outlines the primary single-tenant infrastructure choices used for AI workloads and their respective advantages.

### Bare Metal Server

A bare-metal server is a physical machine assigned exclusively to one customer. Running without a hypervisor, it grants direct access to all compute and storage resources. Applications run natively on the operating system, slashing virtualization overhead and ensuring consistent performance under heavy, sustained workloads.

### Bare Metal Cloud Server

A bare-metal cloud server utilizes the same dedicated physical hardware but provisions it dynamically through a cloud platform. You can deploy instances rapidly via APIs or a web portal. This makes it ideal for workloads that require quick configuration changes, temporary scaling, or heavy automation.

### Dedicated Server

A dedicated server is a physical machine leased to a single customer, usually for an extended term. Its static configuration guarantees predictable performance and pricing, making it the perfect fit for stable, always-on workloads that rarely need scaling.

### Virtual Machines (VMs)

A [virtual machine](https://www.cisco.com/site/us/en/learn/topics/computing/what-is-a-virtual-machine.html) is a software-based environment hosted on shared physical hardware. A hypervisor allocates CPU, GPU, memory, and storage resources among multiple tenants. Since resources are split, performance can fluctuate wildly when several VMs compete for the same underlying hardware.

## Bare Metal and Dedicated Servers vs. Virtual Machines

Virtual machines rely on a hypervisor layer to manage resource sharing. While highly flexible, this architecture introduces performance variability as competing workloads vie for CPU cycles, memory bandwidth, and GPU capacity. For AI and machine learning tasks, these fluctuations can severely disrupt long training runs and large inference jobs where consistent computational throughput is mandatory.

Bare-metal and dedicated servers operate strictly as single-tenant environments. The entire physical machine belongs to one customer. Without a hypervisor managing resource sharing, the system completely avoids scheduling overhead and resource contention. GPU throughput remains perfectly stable, and latency stays predictable during marathon computational tasks.

Single-tenant infrastructure is the industry standard for production AI and ML pipelines requiring sustained performance. VMs remain highly practical for development, testing, and temporary experimentation, but workloads demanding consistent computational power run far more reliably in bare-metal or dedicated server environments.

## Pros and Cons of Bare Metal Servers

Bare-metal servers deliver raw computational power for AI workloads but come with specific operational considerations you should evaluate before deploying them for your pipelines.

### Performance Advantages for Demanding Workloads

- Bare metal servers provide direct access to GPUs. Therefore, training workloads run without the slowdowns that may occur in virtualized systems, and performance remains stable during long training cycles.
- In addition, AI training often relies on very large datasets and frequent checkpoint saves. For this reason, NVMe storage operates at full hardware speed, helping reduce delays during data loading and improving overall throughput.
- Furthermore, distributed AI training requires frequent communication between multiple nodes. Therefore, consistent network latency supports reliable synchronization during model training.

### Security Advantages of Single-Tenant Isolation

- Bare-metal servers provide complete control over the physical system. As a result, interference from other users decreases, and sensitive workloads operate in a more reliable environment.
- In addition, single-tenant isolation supports secure processing of regulated data because the hardware is not shared with other customers.
- Compliance procedures are easier to manage because dedicated infrastructure prevents workload mixing across multiple tenants.

### Provisioning and Cost Considerations for Bare Metal

Bare-metal cloud platforms typically use a usage-based pricing model billed by the hour or minute. Continuous workloads, like month-long AI training cycles, can become expensive as runtime accumulates. This pricing structure excels for short experiments or temporary burst training where resources are quickly activated and destroyed.

Deploying large AI clusters on bare metal requires structured automation. Tools like [Terraform](https://developer.hashicorp.com/terraform/intro)or [Ansible](https://developer.hashicorp.com/terraform/intro) are necessary to efficiently provision and configure instances, as manually setting up dozens of nodes is too slow and error-prone. Long-term cost planning can also be tricky; resource consumption varies wildly across the experimental phases of model development, making budget estimation complex.

## Pros and Cons of Dedicated Servers

Dedicated servers are the gold standard for stability and predictable reliability. They carry strict limitations regarding agility that you must consider before committing to them for dynamic AI workloads.

### Stability and Long-Term Reliability Benefits

- Fixed hardware provides steady performance over long periods, which is useful for production inference.
- Dedicated servers suit systems that run continuously, as they do not require rapid scaling or frequent changes.
- Capacity planning becomes easier because the hardware stays the same throughout the lease period.

### Customization Benefits at Hardware Level

- Hardware resources, such as RAM capacity, storage layout, and RAID configuration, can be selected according to workload requirements. Therefore, infrastructure can match the technical needs of specific AI or enterprise applications.
- Any operating system or specialized driver can be installed, which helps when running older or custom applications.
- Dedicated servers also support legacy enterprise systems that depend on specific hardware behavior or older software environments. Similarly, this configuration stability supports long-running enterprise platforms.

### Scaling and Deployment Limitations of Dedicated Servers

Dedicated servers present rigid operational constraints. Provisioning usually requires manual hardware assembly and racking, pushing deployment timelines out to several days or weeks. Meeting urgent infrastructure needs is incredibly difficult.

Expanding capacity requires procuring new hardware or updating physical service contracts. Dedicated servers lack built-in elasticity; you cannot instantly spin up resources to handle an unexpected spike in inference traffic. They are built for predictability, not adaptability.

**Table 1: Differences Between Bare Metal and Dedicated Servers**

| **Feature** | **Bare Metal Cloud Server** | **Dedicated Server** |
| --- | --- | --- |
| **Provisioning Speed** | Rapid deployment (minutes) via APIs and standardized configurations. | Slow deployment (days/weeks) due to customized, manually racked hardware. |
| **Performance Overhead** | Zero hypervisor overhead; direct hardware access. | Zero hypervisor overhead; performance relies on the specific leased hardware. |
| **Scalability** | Highly elastic; easy to scale up and down on demand. | Rigid scaling requires physical procurement and new contract terms. |
| **Automation Support** | Deep integration with APIs, IaC, and automated provisioning systems. | Limited automated provisioning; requires traditional IT management. |
| **Cost Model** | Usage-based (hourly/monthly), ideal for variable or burst workloads. | Fixed monthly/annual pricing, ideal for predictable long-term budgeting. |
| **Best Fit** | Dynamic workloads requiring fast scaling, newer GPUs, and automated deployment. | Stable, always-on workloads needing hardware customization and budget certainty. |

## Infrastructure Requirements for AI/ML Pipelines

AI and machine learning pipelines require specialized infrastructure to support intensive computational and operational demands. These traits dictate whether dedicated servers or bare-metal cloud environments will serve you better.

- ### Sustained GPU Compute

Deep learning frameworks like PyTorch and TensorFlow execute parallel processing across multiple high-memory GPUs. Large models rely on multi-GPU setups where distributed training demands perfect consistency across all nodes. If GPU throughput drops or fluctuates, training times extend, and model accuracy degrades.

- ### High-Throughput Storage

Pipelines constantly read massive datasets, save model checkpoints, and write intermediate outputs. NVMe storage is mandatory to prevent I/O bottlenecks during preprocessing and training. High IOPS performance ensures rapid batch loading, directly accelerating feature engineering and overall pipeline execution.

- ### Low Latency Networking

Distributed AI frameworks rely on immediate communication between nodes for gradient synchronization. Low-latency, high-bandwidth networks (100 Gbps+) reduce sync delays and speed up multi-node training. Without reliable networking, the scalability of your distributed training cluster collapses.

- ### Security and Compliance

AI workloads frequently ingest sensitive, regulated information, such as ePHI (electronic Protected Health Information). Infrastructure must provide strict hardware isolation. Hosting environments must be fully HIPAA-compliant and supported by a valid HIPAA Business Associate Agreement (BAA). All data transmitted between systems must be heavily encrypted using TLS to prevent interception.

- ### Power and Cooling Density

High-performance AI racks consume substantial amounts of power, ranging from 30 to 150 kW per rack (up to 1 MW in massive clusters). Infrastructure must deliver reliable power and advanced liquid cooling to prevent thermal throttling. Bare-metal cloud providers often build this density into their data centers, whereas leasing raw dedicated servers may require you to verify the facility’s cooling capacity.

- ### Orchestration and Management

Distributed pipelines rely on tools such as Kubernetes, Airflow, and Terraform to manage resources and monitor nodes. Bare-metal cloud platforms natively support Infrastructure-as-Code (IaC), making scaling and configuration simple. Dedicated servers require more manual integration with these orchestration frameworks.

## When to Use Bare Metal Cloud for AI/ML Pipelines

Bare-metal cloud shines when you value speed, elasticity, and immediate access to the newest GPU architectures over a fixed flat rate.

### Ideal Use Cases

- #### *Rapid model experimentation and short-term bursts*

Engineers testing multiple variants can deploy an eight-node H100 cluster in minutes, run automated benchmarks, and destroy the cluster instantly. This limits idle hardware costs.

- #### *Short-lived distributed training*

Fine-tuning large language models (LLMs) on fresh datasets often takes 24–72 hours. Bare-metal cloud allows for rapid setup, fast gradient synchronization, and immediate deprovisioning once the model is saved.

- #### *Unpredictable SaaS inference scaling*

Customer-facing AI applications (like chatbots) experience sudden traffic spikes. Elastic scaling handles these bursts without forcing you to permanently overprovision hardware.

- #### *Hardware benchmarking and proof-of-concept testing*

Teams evaluating new accelerators, such as NVIDIA Blackwell or AMD MI300X, can access them immediately via the cloud, bypassing massive upfront capital expenditures and procurement delays.

### When to Avoid Bare Metal Cloud

Running continuous 24/7 training clusters on an hourly billing cycle will drastically inflate your budget—often costing double or triple the rate of a fixed dedicated server lease. Heavy data egress between cloud nodes or external environments can also trigger massive bandwidth fees.

## When to Use Dedicated Servers for AI/ML Pipelines

Dedicated servers are best when your top priorities are rock-solid stability, fixed budgets, and deep hardware customization.

### Ideal Use Cases

#### *• Production inference at scale*

E-commerce recommendation engines require a latency of less than 50 milliseconds. Fixed GPU configurations ensure predictable response times without the risk of auto-scaling failures.

#### *• Long-running stable training*

Workloads that fine-tune models on fixed datasets for months require predictable storage layouts and NVMe performance. Dedicated servers support multi-month runs with stable budgeting.

#### *• Compliance-bound workloads*

AI platforms handling regulated data, including electronic Protected Health Information under HIPAA, benefit from single-tenant isolation. In addition, TLS encryption and dedicated hardware simplify auditing and reduce multi-tenant risks.

#### *• Legacy or custom system integrations*

Enterprise systems integrating AI with mainframes or ERP applications need exact CPU, memory, and network interface specifications. Therefore, dedicated servers allow precise hardware matching and avoid compatibility issues that arise in cloud setups.

### When to Avoid Dedicated Servers

Dedicated servers may not be suitable when agility and rapid experimentation are required. This is because provisioning usually takes two to four weeks, and this delay can slow down deployment. In addition, sudden demand spikes often require new hardware procurement, slowing scaling. GPUs older than 18 months may fall behind the latest cloud hardware, reducing performance for advanced AI workloads.

## Technical Comparison of Bare Metal Cloud and Dedicated Servers

Understanding the operational differences between these models will dictate how your engineering team manages the hardware lifecycle.

- ### Deployment and Availability

Bare-metal cloud compute resources are available in minutes. This is critical when experimentation demands spike. Dedicated servers require physical racking, BIOS configuration, and OS installation, pushing timelines to days or weeks and requiring strict capacity planning.

- ### Hardware Refresh and Lifecycle

Bare-metal cloud providers refresh their fleets continuously, granting you immediate access to modern GPUs to accelerate research. Dedicated server leases span years, meaning you may be stuck running workloads on older architectures while competitors utilize faster, newer hardware.

- ### Scalability and Resource Expansion

Bare-metal cloud allows clusters to expand horizontally on demand. Dedicated servers are strictly constrained by the physical boxes you already lease; scaling up requires signing new contracts and waiting for delivery.

- ### Integration with Operations

Bare-metal cloud seamlessly integrates with modern DevOps workflows via APIs. Dedicated servers rely on traditional, slower IT management practices, requiring heavy coordination between engineering and infrastructure teams.

- ### Security and Compliance

Both bare-metal cloud and dedicated servers ensure single-tenant isolation, which is essential for handling regulated workloads, such as ePHI under HIPAA. In addition, data moving between systems is generally protected with TLS encryption, supporting secure operations. Despite these common features, the way security is implemented differs between the two models. Bare metal cloud platforms often provide integrated monitoring and automated policy enforcement, helping teams maintain compliance without extensive manual effort.

In contrast, dedicated servers give organizations greater control at the hardware level, enabling stricter configurations and air-gapped deployments for environments with stringent regulatory requirements. Therefore, selecting the right infrastructure influences not only performance but also the methods used to uphold security and compliance across AI pipelines.

### Workload Mapping by Infrastructure Type

Bare metal cloud performs best when AI pipelines require fast deployment, flexible scaling, and access to the latest hardware. For example, distributed LLM training across hundreds of GPUs benefits from clusters that can be brought online quickly and expanded as demand increases. In addition, frequent model fine-tuning and hyperparameter testing become easier because temporary clusters can be created and destroyed without lengthy setup. As a result, idle compute is reduced and overall resource usage becomes more efficient.

Applications that experience sudden spikes in requests also benefit from this model because infrastructure can scale immediately and maintain stable response times. Similarly, hardware testing and proof-of-concept experiments benefit from quick access to newer GPU models, helping teams avoid delays associated with hardware procurement. Therefore, bare metal cloud is particularly useful when speed, flexibility, and access to modern hardware are more important than fixed infrastructure costs.

Dedicated servers, in contrast, provide steady performance and long-term reliability. Production inference workloads, such as e-commerce recommendations or real-time analytics, rely on stable GPU environments and continuous operation. In addition, long-running training jobs benefit from consistent storage performance and predictable input/output behavior. Likewise, regulated workloads, such as healthcare data, require strict isolation and carefully controlled infrastructure. Furthermore, legacy systems with specific hardware or software requirements operate more reliably on dedicated servers because configurations remain unchanged over time. Therefore, dedicated servers are more suitable when reliability, predictable cost, and operational consistency are the primary priorities.

In practice, many organizations combine both infrastructure types to balance flexibility and stability. Training and experimentation often run on bare metal cloud to take advantage of rapid provisioning and temporary expansion. Afterward, production inference may move to dedicated servers to maintain stable performance and predictable operational costs. For instance, a model may train on bare metal cloud for several weeks and then transition to dedicated servers for long-term serving. In this way, organizations gain the flexibility needed for experimentation while maintaining stability for production operations.

## Pricing and Total Cost of Ownership (TCO) Analysis

Cost is an important factor when choosing infrastructure because pricing models suit different workloads in different ways.

Bare-metal cloud typically uses either hourly or usage-based pricing. As a result, it works well for short training jobs that need large GPU clusters for a limited time. However, when workloads run continuously at full capacity, costs can rise quickly. In addition, network transfers during large checkpoint synchronizations may add to expenses. Even so, organizations can manage these costs by using automated scaling or spot instance pricing, which helps balance performance and budget.

Dedicated servers generally use monthly or annual contracts, which provide predictable costs for workloads that run continuously. This setup often lowers the cost per GPU hour for long-running inference workloads because the hardware remains allocated at all times. Moving large datasets within the infrastructure incurs no additional fees, further reducing operational costs.

A complete cost evaluation also considers how compute is distributed across training, inference, and experimentation. Training typically consumes the most GPU resources, while inference needs stable, continuous capacity. Additional factors such as high-speed storage, networking, and cooling can also affect the total cost. Therefore, organizations should consider the total cost of ownership rather than focusing only on hourly rates or individual components.

## Decision Framework for Selecting AI/ML Infrastructure

This section provides a structured framework to help organizations determine whether bare metal cloud or dedicated servers are more suitable for their AI/ML workloads.

- ### Workload Duration and Stability

The first factor concerns workload duration. When workloads run for short periods or change frequently, a bare-metal cloud is generally more appropriate, as it supports rapid provisioning and elastic scaling. In contrast, when workloads operate continuously and require long-term stability, dedicated servers are more suitable because they provide predictable performance and fixed resource availability.

- ### Elasticity Requirements

The second factor relates to elasticity. If compute demand fluctuates significantly across training cycles, a bare-metal cloud offers advantages because nodes can be added or removed as demand changes. However, when compute requirements remain stable over time, dedicated servers provide a more consistent environment and reduce the need for frequent capacity adjustments.

- ### Hardware Freshness and GPU Availability

The third factor concerns access to recent GPU hardware. When organizations require the latest accelerators for model training or benchmarking, a bare metal cloud is advantageous because providers refresh hardware more frequently. Conversely, when hardware stability is more important than hardware novelty, dedicated servers offer a consistent platform for long-running pipelines.

- ### Pricing Model Preference

The fourth factor involves cost structure. Usage-based billing in bare metal cloud is cost-efficient for short-term or variable workloads; however, it becomes less predictable for continuous operations. Therefore, when organizations prefer fixed monthly or annual pricing, dedicated servers provide clearer long-term budgeting and may reduce the total cost of ownership for always-on workloads.

- ### Compliance and Operational Control

The fifth factor relates to compliance and operational control. Both models support single-tenant isolation; however, dedicated servers may be preferred when organizations require strict control over hardware configuration or when legacy systems impose specific technical constraints. Bare metal clouds are suitable when compliance requirements can be met through provider controls and when operational agility is a priority.

- ### Organizational Maturity and Tooling

The final factor concerns operational maturity. When teams rely heavily on Infrastructure‑as‑Code and automated orchestration, bare-metal cloud integration flows more naturally into existing workflows. In contrast, when organizations operate established environments with fixed configurations and long‑term maintenance practices, dedicated servers align more closely with existing operational models.

## Recommendations and Next Steps

To ensure that the selected infrastructure model performs as expected, organizations should begin with a focused pilot that reflects representative training or inference workloads. During this pilot, it is important to measure throughput, latency, and cost under realistic operating conditions, since these metrics provide a clear view of how the environment behaves in practice.

Once the results are available, the choice should be refined by comparing observed performance and spending patterns against the organization’s technical objectives and budget targets. This iterative approach helps confirm that the final deployment aligns with the requirements of AI/ML pipelines and supports reliable long-term operation.

## How Atlantic.Net Supports AI/ML Infrastructure Decisions

While your workload characteristics dictate the infrastructure model, your provider’s capabilities dictate your ultimate success. We offer single-tenant GPU hosting, dedicated server configurations, and HIPAA-compliant environments specifically engineered for highly sensitive data.

Our platform provides predictable dedicated server options for heavy, long-running inference workloads alongside automated provisioning for dynamic deployments. When evaluating infrastructure for your AI/ML pipelines in 2026, partner with us to guarantee your architecture delivers the exact performance, security, and reliability your enterprise requires.


---

# Why Bare Metal Hypervisors Outperform Hosted Solutions

> URL: https://www.atlantic.net/dedicated-server-hosting/bare-metal-hypervisors-vs-hosted-solutions/ | Published: 2026-03-17 | Updated: 2026-05-20 | Author: Robert Agar

Hypervisors are a core technology supporting virtualization and cloud environments. They are the key to optimizing server hardware so it can be used by multiple, independent virtual machines (VMs). Hypervisors are vital and foundational elements of modern, agile, and flexible IT infrastructures.

Bare metal servers provide dedicated, single-tenant hardware hosting, offering high performance, full control, and resource isolation, especially for private clouds and compliance-sensitive workloads.

This article discusses the crucial role of hypervisors in virtualized environments and the multiple functions they perform. We examine the two main types of hypervisors used for virtualization in IT environments and why bare-metal hypervisors provide superior performance compared to hosted hypervisor solutions. Hardware compatibility is a key consideration when selecting a hypervisor, as certain hardware requirements and support limitations can impact performance and feature availability.

## The Essential Role of the Hypervisor

The hypervisor is specialized virtualization software or firmware that enables multiple virtual machines to run on a single physical machine. It serves as a control layer between the physical hardware resources and the virtual environment. Hypervisors are a core component of the virtualization technology that supports modern businesses.

A hypervisor enables multiple virtual servers to run on the same physical server. The host operating system’s hardware components provide the processing power to meet the VMs’ requirements. Each VM can run a different operating system and application stack. IT teams can enforce specific security policies across groups of VMs to ensure consistency and safeguard sensitive data assets.

Some hypervisors, such as Kernel-Based Virtual Machine (KVM), are integrated into the Linux kernel, offering high performance and scalability across various workloads. Windows Server includes Hyper-V, a hypervisor built into the operating system, providing integration with Microsoft products and licensing benefits.

### Primary hypervisor functions

The hypervisor performs the following essential functions to establish an efficient and manageable virtual environment.

- **Resource allocation and scheduling:** The hypervisor allocates physical hardware resources to multiple virtual machines. Each VM receives its allocated CPU, RAM, network bandwidth, and storage resources without interfering with other VMs. Hypervisors ensure efficient resource management in enterprise and cloud environments.
- **VM isolation:** Multiple VMs share a server’s underlying physical hardware and must maintain isolation to ensure stability and security. A hypervisor prevents VMs from accessing each other’s memory and ensures faults do not propagate across machines. Data is kept secure by logically separating workloads across the shared physical resources. Isolation is essential for creating multi-tenant environments, such as public cloud environments.
- **Hardware abstraction:** The hypervisor presents virtualized hardware resources to the VMs’ operating systems. Abstraction provides hardware independence and enables applications to migrate easily between servers, thereby eliminating vendor lock-in. Teams can upgrade the computing hardware without impacting workloads.
- **Performance optimization:** A hypervisor acts as a virtual machine monitor and can dynamically adjust resource allocation to ensure guest operating systems obtain optimal performance. Specific optimization techniques include managing network traffic, CPU scheduling, and storage I/O prioritization. Organizations can maintain high performance while maximizing hardware utilization and controlling spending.
- **Lifecycle management:** Hypervisors manage the entire lifecycle of virtual machines. They are responsible for multiple functions that simplify management and support automation, including:
  - Creating virtual machines;
  - Starting and stopping VMs to meet user requirements;
  - Producing snapshots and performing rollbacks;
  - Scaling VMs with dynamic resource allocation.
- **Fault tolerance and availability:** Hypervisors enhance resilience by automating processes that ensure the continuous availability of mission-critical applications. Hypervisor activities supporting enhanced resilience include:
  - Performing live migrations between hosts;
  - Ensuring consistent performance with load balancing;
  - Failing over clusters to address major disruptions;
  - Restarting VMs automatically after a host failure.

## What are the Two Types of Hypervisors?

Two primary types of hypervisors are utilized to create virtualized environments. The two types are bare metal hypervisors and hosted hypervisors. The main difference between the two hypervisor types is where the hypervisor runs.

Bare metal hypervisors run on dedicated hardware without an underlying operating system. Hosted hypervisors run on top of an operating system in the same way as other applications. Client hypervisors are hosted hypervisors that run within the host operating system, primarily used for end-user testing and software development, and typically exhibit higher latency than bare-metal hypervisors. Let’s take a closer look at these two alternative hypervisor solutions.

### Bare metal hypervisor type

A bare-metal hypervisor is installed directly on a server’s physical hardware without a traditional operating system. This type of hypervisor installation provides direct access, allowing the hypervisor to manage the server’s CPU, memory, storage, and network resources. Bare metal hypervisors can also be installed at the firmware level alongside the motherboard’s BIOS.

The hypervisor leverages the hardware resources to establish a virtualization layer that creates and manages virtual machines. Its direct hardware interaction eliminates contention with other applications and enables the hypervisor to deliver high performance across all its VMs.

The key characteristics of bare metal virtualization include:

- High performance because of direct access to computing resources;
- Enhanced security and isolation for individual virtual machines;
- Efficient scalability and flexibility;
- Efficient resource allocation and low latency;
- Superior resource efficiency compared to Type 2 hypervisors.

Bare-metal hypervisors are particularly suited for regulated industries due to their enhanced security and control over hardware. They are widely used in high-performance computing (HPC) and big data applications that require maximum hardware performance and low latency. They are ideal for latency-sensitive applications because they do not rely on an underlying operating system that slows performance. Bare-metal hypervisors are crucial for disaster recovery plans, as they enable high availability, fault tolerance, and easy environment replication. They also help deliver reliable and secure virtual desktop infrastructure (VDI) with consistent performance for organizations deploying remote or hybrid work models. Bare-metal hypervisors can be scaled by adding more servers or adjusting configurations, without the limitations of a host OS. Vendors typically provide reliable, centralized management consoles for monitoring and managing large-scale bare-metal hypervisor deployments.

However, the complexity of setup and maintenance for bare metal hypervisors requires specialized skills within IT teams, and the cost of implementation can be high, especially for smaller organizations. Bare-metal hypervisors may have limited hardware compatibility, limiting their use in certain environments. They can also lead to VM sprawl, where more VMs are created than needed, resulting in wasted resources. Despite these challenges, bare-metal hypervisors offer superior performance and security compared to hosted hypervisors.

Cloud computing providers use bare-metal hypervisors to deliver dedicated, secure environments. In regulated industries, keeping data isolated and secure is paramount, and bare-metal virtualization provides that isolation while enabling organizations to run multiple virtual machines on the same physical server. The global bare-metal cloud market was valued at $8.5 billion in 2023 and is projected to reach $19.1 billion by 2028.

The performance, scalability, and security that bare-metal hypervisors offer make them an excellent choice for production workloads in enterprise virtualization environments and data centers. When selecting the best bare-metal hypervisor, organizations should consider high-performance options that offer enhanced security, control, and compliance—especially in regulated industries such as healthcare and finance. Bare-metal hypervisors are often used to build cloud infrastructure and for large server consolidation projects. Teams require a degree of technical skills to manage a bare-metal hypervisor environment successfully and efficiently.

Microsoft Hyper-V and VMware ESXi are two of the top bare-metal hypervisors on the market. Citrix Hypervisor is another leading enterprise solution, offering reliable features, flexible licensing options, and a strong relationship with open-source projects such as Xen Project and XCP-ng, making it suitable for organizations seeking advanced capabilities and scalability.

### Hosted hypervisor type

A hosted hypervisor runs on an installed operating system, such as Windows, Linux, or macOS. It is a powerful software application that interacts with hardware through the host OS. The hosted hypervisor does not have direct access to the system’s hardware resources.

The key characteristics of a hosted hypervisor include:

- Lower performance than bare metal hypervisors;
- Runs on standard desktop or laptop computers;
- Hypervisor installation does not require technical expertise.

IT teams and individuals commonly use hosted hypervisors for multiple uses that include:

- Establishing software testing and development environments;
- Creating training platforms;
- Experimenting with multiple operating systems.
- Building a personal virtualization environment to enhance productivity.

Oracle VM VirtualBox and VMware Workstation are two examples of popular hosted hypervisors

## Why Bare-Metal Hypervisors Provide Better Performance

The primary reason bare-metal hypervisors outperform hosted hypervisors is their direct hardware access, which eliminates reliance on the operating system. The following specific technical aspects of bare-metal infrastructure enable it to deliver the high performance required by enterprise environments.

Bare-metal hypervisors have direct hardware access. The lack of a competing operating system gives the hypervisor complete control over resource allocation. This level of control over the underlying hardware provides more predictable performance and faster workload execution.

Eliminating the host operating system layer reduces the software stack, resulting in faster I/O processing and lower latency. Reduced contention with OS functions allows for more efficient resource allocation and improves system utilization.

Improved I/O performance for access to physical resources benefits network and storage operations. Communicating directly with hardware components results in faster disk read/write activity and improves network throughput. These factors are essential for supporting high-traffic web applications, big data processing, and AI**/**ML workloads.

Bare-metal hypervisors provide enhanced security due to the strong isolation between VMs. The hypervisor presents a reduced attack surface compared to a hosted solution and operating system. A bare-metal virtualized environment is more secure and reliable for business-critical workloads.

Companies establishing enterprise virtual environments benefit from the greater stability of bare-metal hypervisors. Businesses can enjoy advanced features such as automated failover, resource pooling, and high availability clustering to meet production requirements. Bare-metal hypervisors can support large numbers of VMs and integrate with enterprise orchestration tools to meet the scalability and flexibility needs of modern organizations.

## Use Cases for Bare Metal Hypervisors

Bare metal hypervisors are the backbone of high-performance virtualization in enterprise and cloud environments, offering unmatched efficiency, security, and scalability. Their ability to run multiple virtual machines directly on the same physical server—without the overhead of a host operating system—makes them the preferred choice for organizations seeking optimal performance and resource allocation.

In data centers, bare-metal hypervisors maximize server hardware utilization by efficiently managing multiple virtual machines on a single physical server. This approach reduces the need for additional hardware, lowers operational costs, and ensures that hardware resources are allocated precisely where they are needed. The result is a highly efficient infrastructure that delivers high performance with minimal overhead, even as workloads scale.

Cloud platforms also rely heavily on bare metal hypervisors to provide dedicated hardware resources to clients. Bare-metal cloud environments offer direct hardware access, enabling users to tailor their virtual machines to specific hardware configurations for consistent performance. This is especially valuable for applications demanding high processing power, low latency, and superior performance, such as real-time analytics, scientific computing, and machine learning workloads.

Virtualized environments, including virtual desktop infrastructure (VDI) and web servers, benefit from the enhanced security and efficient resource management that bare-metal hypervisors provide. By isolating virtual machines and providing dedicated resources, organizations can ensure high availability and reliability for critical applications and services.

In enterprise settings, bare metal hypervisors enable IT teams to run multiple operating systems and applications on the same physical server, supporting diverse departmental needs while maintaining strict control over resource allocation. This flexibility allows businesses to optimize their IT infrastructure, reduce costs, and improve operational efficiency. Advanced management tools and features—such as dynamic resource allocation, automated failover, and high-availability clustering—further enhance the value of bare-metal virtualization in these environments.

Security is another key use case, particularly for industries handling sensitive data, such as finance, healthcare, and government. Bare metal hypervisors provide reliable isolation between virtual machines, minimizing the risk of unauthorized access and ensuring compliance with stringent data protection requirements.

## Conclusion

Customers need a hypervisor to create a virtualized environment. A company’s or an individual’s use case should influence the type of hypervisor they choose to establish a virtual infrastructure. Businesses planning to use the environment for production workloads should strongly consider a solution built around a bare-metal hypervisor running directly on powerful hardware. Hosted hypervisors should typically be used for testing and development.

[Atlantic.Net](https://www.atlantic.net/) provides its customers with a full range of [bare-metal](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) and [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) that can be customized to meet your business requirements with specific hardware configurations. You can choose the operating system and hypervisor that best address your team’s needs and technical skill level.

Contact our team to learn more about how we can provide the foundation for a productive virtualized environment.


---

# Best Cloud Hosting Providers with SSD & 24/7 Support

> URL: https://www.atlantic.net/cloud-platform/best-cloud-hosting-providers-with-ssd-247-support/ | Published: 2026-03-19 | Author: Hitesh Jethva

Cloud hosting is the backbone for today’s websites, SaaS platforms, databases, and development tools. Companies use cloud infrastructure because it scales easily, launches quickly, and stays reliable. Two top features to look for are SSD storage and 24/7 technical support.

SSD (solid-state drive) storage has a big impact on how well servers run. SSDs are much faster than mechanical hard drives, so they help websites load more quickly, speed up database searches, and let apps support more users at once. Better storage can also boost site performance scores, which affect user experience and search rankings.

Good support matters as much as speed. Problems like server errors, sudden traffic spikes, or network issues can occur at any time. Providers with 24/7 technical support help businesses fix issues quickly, get services back up and running, and keep critical workloads online.

If your organization runs important websites or apps, choosing a cloud host with fast SSD storage and 24/7 support helps keep them running smoothly and reliably.

## Why SSD Storage Matters in Cloud Hosting

Storage performance directly affects cloud server performance. Older servers relied on mechanical hard drives (HDDs) that read and write data using spinning disks. SSDs (solid-state drives) use flash memory instead, which allows data to be accessed much faster.

In cloud environments, this difference affects how quickly applications respond to user requests. Faster storage reduces delays when servers read files, process queries, or handle background tasks.

Workloads run noticeably faster on SSD infrastructure. Faster disk access helps servers process more requests simultaneously without performance drops.

Below are several ways SSD storage improves cloud hosting performance.

### Faster website loading

Web servers frequently read images, scripts, and application files from storage.

SSD infrastructure helps by:

- Retrieving website files faster
- Reducing page load times
- Improving the overall browsing experience for visitors

Faster websites can also support better engagement and site performance metrics.

### Improved database performance

Many applications depend on databases to store and retrieve information.

SSD storage helps databases by:

- Reducing query response time
- Handling frequent read and write operations efficiently
- Supporting applications such as e-commerce platforms, SaaS tools, and content management systems

Faster database access leads to quicker application responses.

### Lower latency

Latency refers to the delay between a request and the server’s response.

SSD storage reduces this delay by:

- Reading data quickly from disk
- Writing logs and updates without long wait times
- Supporting real-time workloads such as APIs and analytics platforms

Lower latency helps applications respond faster to user actions.

### Better performance during high traffic

Websites and applications often receive many requests simultaneously.

SSD infrastructure helps manage heavy workloads by:

- Processing multiple read and write operations simultaneously
- Maintaining stable performance during traffic spikes
- Supporting applications with large numbers of active users

Because of these performance benefits, many organizations choose SSD-based cloud hosting for production workloads that require consistent speed and reliability.

## Why 24/7 Support Matters for Cloud Infrastructure

Cloud infrastructure operates 24 hours a day. Websites, APIs, SaaS platforms, and databases must remain available to users across different time zones. Having 24/7 technical support available should be a major factor when choosing your next hosting provider.

Even stable infrastructure can run into unexpected issues. Network interruptions, configuration mistakes, or sudden traffic increases can affect application availability. When experienced engineers are available at any time, problems can be diagnosed and fixed quickly before they impact users.

Below are common situations where round-the-clock support proves valuable.

### Server configuration issues

Incorrect firewall rules, networking settings, or operating system configurations can interrupt services.

Support engineers can help by:

- Identifying misconfigured firewall or security group rules
- Troubleshooting DNS or networking problems
- Fixing server configuration errors that prevent services from running

Quick troubleshooting gets things back to normal and keeps downtime short.

### Security incidents

Suspicious logins, malware warnings, or vulnerability reports need quick attention.

Support teams may assist with:

- Investigating unusual activity in server logs
- Blocking malicious IP addresses
- Advising on security patches and system updates

Responding quickly can limit damage and protect sensitive data.

### Infrastructure scaling during traffic spikes

Traffic can jump suddenly during marketing campaigns, product launches, or busy seasons.

Support engineers can guide administrators through steps such as:

- Adding compute resources
- Increasing storage capacity
- Adjusting load balancing or resource allocation

This keeps applications responsive even as user demand increases.

### Network and connectivity problems

Sometimes applications run into connectivity issues between services, regions, or external APIs.

With 24/7 support available, engineers can:

- Diagnose network routing problems.
- Investigate latency or packet loss.
- Coordinate fixes across the data center infrastructure.

Quick action helps keep services available for users.

Organizations that run production applications often prioritize cloud hosting providers with continuous technical support. Immediate assistance helps maintain uptime, resolve incidents faster, and keep systems operating reliably.

## Top Cloud Hosting Providers with SSD & 24/7 Support

Below are cloud hosting providers known for operating large-scale infrastructure platforms that offer SSD storage and continuous technical support.

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

### 1. Atlantic.Net

[Atlantic.Net](https://www.atlantic.net/) provides cloud hosting infrastructure designed for organizations that require reliable performance and responsive support. The platform offers cloud servers, dedicated servers, and managed services that run on SSD-based infrastructure.

Businesses use Atlantic.Net to host websites, applications, databases, and development environments. The company operates multiple data centers and focuses on secure, high-uptime cloud infrastructure.

#### Key Features

- SSD-based cloud servers: Atlantic.Net cloud infrastructure runs on SSD storage, allowing applications to access data faster and handle workloads efficiently.
- 24/7 technical support: Customers can reach support engineers at any time to troubleshoot server issues, networking problems, or configuration questions.
- Multiple deployment regions: Atlantic.Net operates several data center locations, which allows organizations to deploy workloads closer to users and reduce latency.
- Managed hosting options: Managed services are available for customers who want assistance with system updates, monitoring, and security management.

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

### 2. Amazon Web Services (AWS)

[Amazon Web Services](https://aws.amazon.com/) is one of the largest cloud infrastructure providers in the world. AWS offers a wide range of cloud services that support startups, enterprise platforms, and global web applications.

AWS provides hundreds of services for computing, storage, networking, and analytics. Many organizations use AWS for large projects because it has a global network and a wide range of services.

#### Key Features

- Elastic Block Storage with SSD options: Provides SSD-backed storage through services like Elastic Block Store (EBS), optimized for high-performance workloads.
- Global cloud infrastructure: Runs data centers in many regions around the world so that organizations can put their applications closer to their users.
- Enterprise support plans: Offers different support plans that give customers access to engineers and technical support when they need to resolve infrastructure issues.
- Scalable computing services: With services like EC2, businesses can scale computing power up or down as their workload changes.

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

### 3. Microsoft Azure

[Microsoft Azure](https://azure.microsoft.com/en-us/) is another major cloud computing platform used by enterprises, software companies, and government organizations. Azure provides cloud infrastructure that integrates closely with Microsoft technologies such as Windows Server, Active Directory, and SQL Server.

Many companies choose Azure to migrate their existing Microsoft systems to the cloud.

#### Key Features

- Premium SSD managed disks: Offer premium SSD storage for virtual machines that require consistent performance and quick response times.
- Global cloud regions: Have data centers in many locations so that organizations can set up infrastructure near their customers.
- Enterprise support services: Provides different support levels, including help with technical issues, troubleshooting, and access to support engineers.
- Integration with Microsoft services: Organizations that use Microsoft products often find it simpler to connect their workloads with Azure.

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

### 4. Google Cloud Platform (GCP)

[Google Cloud Platform](https://cloud.google.com/) is known for its powerful networking infrastructure and advanced data processing services. Many companies use Google Cloud to run analytics workloads, machine learning platforms, and web applications.

Google’s global network backbone enables services to communicate efficiently across regions, improving application performance.

#### Key Features

- SSD persistent disks: Offers SSD-backed persistent disks for applications that require consistent, reliable disk performance.
- High-performance networking: Google’s private global network connects data centers across regions, helping reduce service delays.
- Support plans for businesses: Has different support plans that give businesses access to engineers and technical help.
- Strong analytics ecosystem: Many organizations choose Google Cloud for data analytics, machine learning, and running containerized workloads.

![](https://www.atlantic.net/wp-content/uploads/2026/03/hetzner-logo.png)

### 5. Hetzner Cloud

[Hetzner](https://www.hetzner.com) is a European cloud hosting provider recognized for its affordable infrastructure and dependable performance. It runs modern data centers in Germany and Finland, offering cloud servers with NVMe SSD storage.

Many developers, startups, and small businesses choose Hetzner because it offers a good mix of price and performance. The platform works well for web hosting, app servers, development environments, and databases.

#### Key Features

- NVMe SSD storage: Cloud servers use NVMe SSD drives, which provide fast data access and help applications run better.
- Cost-efficient cloud servers: Hetzner’s compute resources are priced competitively compared to many bigger cloud providers.
- European data center locations: Infrastructure is available in Germany and Finland, making it a good choice for serving European users.
- Support availability: Technical support is available to help with server setup and infrastructure problems.

## How to Choose the Right Cloud Hosting Provider

Choosing a [cloud hosting provider](https://www.atlantic.net/cloud-platform/cloud-hosting/) comes down to your application needs, the amount of traffic you expect, and your budget. While most platforms have similar basic services, they can differ in performance, support, and pricing.

Here are some important things to consider:

- Infrastructure performance: Look for providers that use SSD or NVMe storage and dependable computing resources to keep your applications running quickly.
- Global availability: Providers with data centers across multiple regions can reduce latency and improve performance for users wherever they are.
- Support availability: Around-the-clock technical support helps resolve configuration issues, outages, and other problems quickly.
- Scalability: Ensure the platform supports adding more computing power, storage, or network resources as your needs grow.
- Pricing structure: Review how each provider charges for computing, storage, and bandwidth to estimate your long-term costs.

Looking at these factors can help you choose a provider that meets your needs now and as your business grows.

## Final Thoughts

Two things often matter most when picking a provider: SSD storage and reliable technical support. SSDs make your apps faster, and 24/7 support means you can get help whenever you need it.

The best provider for you will depend on your workload, performance needs, and budget. By comparing features, support, and pricing, you can find a platform that works for your business now and in the future.


---

# High-Performance Cloud Servers for Remote Teams

> URL: https://www.atlantic.net/dedicated-server-hosting/high-performance-cloud-servers-for-remote-teams/ | Published: 2026-03-20 | Updated: 2026-03-24 | Author: Hitesh Jethva

Remote work is the standard for modern companies. Distributed teams, global hiring, and cross-time-zone collaboration drive startups and enterprises alike. As teams operate from different regions, infrastructure speed and reliability directly impact productivity. Slow servers, network latency, or limited on-premise setups disrupt development workflows and hinder remote collaboration.

High-performance cloud servers give remote teams the computing power required to run applications, development environments, and collaboration platforms from anywhere. These platforms deliver raw compute, low-latency networking, and elastic infrastructure through globally distributed data centers. Armed with the right cloud backend, your organization can support remote development, application deployment, and global workloads in 2026 without relying on physical office hardware.

## Why Remote Teams Need High-Performance Cloud Infrastructure

Distributed teams depend on reliable, high-performance infrastructure to run applications, development tools, and internal systems. Traditional IT environments often rely on servers located in a single office or data center. When employees work remotely, this setup can cause slow connections, VPN bottlenecks, and inconsistent system performance.

Below are several reasons why high-performance cloud servers for remote teams are widely used by modern organizations.

### Global Access to Applications and Workloads

With cloud-based infrastructure, team members can access applications, development environments, and internal tools from anywhere with an internet connection. This allows distributed teams to work within the same environment without relying on office-based servers.

For companies with employees across multiple regions, global cloud infrastructure makes it easier to maintain consistent access to systems and data.

### Consistent Application Performance

Large cloud providers operate multiple global data center regions, allowing organizations to deploy workloads closer to their users. Shorter network distances reduce latency, improving application response times.

For remote teams using development tools, SaaS platforms, or internal applications, consistent performance helps maintain efficient workflows.

### Flexible Infrastructure Capacity

Remote organizations often experience changing workload demands. Cloud servers allow companies to scale compute resources up or down based on usage requirements.

Instead of purchasing and maintaining physical hardware, teams can allocate additional CPU, memory, and storage resources when needed.

### Shared Development and Collaboration Environments

Cloud infrastructure enables developers, engineers, and operations teams to work within a single, centralized cloud environment. This setup supports remote development workflows, including shared staging environments, CI/CD pipelines, and cloud-based testing systems.

Working from the same infrastructure environment reduces configuration issues between team members.

### High Availability and System Stability

Most cloud platforms include built-in redundancy, load balancing, and failover mechanisms. These systems help maintain application uptime if hardware failures or outages occur in a single location.

For distributed organizations operating across multiple time zones, stable infrastructure helps keep applications and services available to teams and customers worldwide.

## Key Performance Factors When Choosing a Cloud Server

Not every cloud server delivers the same level of speed, reliability, or capacity. When selecting high-performance cloud servers for remote teams, organizations should review several performance-related factors.

### Compute Performance

The CPU and GPU power of a cloud server affect how well applications perform. Tasks like analytics, software development, and running large apps need strong processing power to stay reliable.

### Network Latency

Network latency affects how fast users can connect to cloud servers. Providers with a global network and fast connections help reduce delays for teams working from different locations.

### Storage Throughput

Applications and databases need quick access to data. Fast cloud storage improves read and write speeds for development, web apps, and data processing tasks.

### Global Data Center Coverage

Providers with many cloud regions and data centers let companies run workloads closer to their users. This reduces latency and makes applications more available for remote teams.

### Infrastructure Scaling

Cloud platforms should let teams add or remove computing resources as their needs change. This flexibility supports growing apps and remote teams.

### Security and Compliance

Remote teams often handle sensitive data. Security features like encryption, access controls, and compliance standards help keep applications and infrastructure safe.

## Best High-Performance Cloud Servers for Remote Teams

Several cloud providers offer infrastructure designed for performance, scalability, and global accessibility. The following platforms are widely used by organizations that operate distributed teams.

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

### 1. Atlantic.Net

[Atlantic.Net](https://www.atlantic.net/) provides high-performance cloud servers with a strong focus on managed cloud hosting and reliable infrastructure. The platform offers both virtual cloud servers and dedicated cloud environments, enabling organizations to run applications, development environments, and business workloads without managing complex infrastructure.

For remote teams, managed cloud services can reduce operational work related to server maintenance. Atlantic.Net handles tasks such as monitoring, system updates, and infrastructure management so teams can focus on building applications and running their operations.

#### Key Features

- **Managed Cloud Services:** Atlantic.Net provides managed infrastructure services, including system monitoring, maintenance, and security updates for cloud servers.
- **Flexible Cloud Server Options:** Organizations can deploy virtual machines or dedicated cloud servers depending on application performance and workload requirements.
- **Secure Cloud Infrastructure:** The platform supports environments designed for businesses that require strong data protection and controlled access to infrastructure.
- **Global Data Center Locations:** Multiple data center regions allow companies to deploy cloud workloads closer to distributed teams and users.

#### Best For:

Companies that need managed cloud hosting with high-performance cloud servers for remote teams and distributed applications.

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

### 2. AWS

[Amazon Web Services](https://aws.amazon.com/) (AWS) is one of the most widely adopted cloud computing platforms used by startups, enterprises, and global organizations. Its infrastructure supports a wide range of workloads, making it a strong option for companies operating remote teams and distributed applications.

AWS offers a variety of high-performance cloud servers, enabling organizations to run applications with varying compute, memory, and storage requirements. This flexibility lets teams set up development, production, and data systems on a single platform.

#### Key Features

- **Elastic Compute Cloud (EC2):** With AWS EC2, teams can launch virtual servers and choose the CPU, memory, and storage setup that fits their needs.
- **Global Data Center Locations:** AWS has cloud regions and availability zones in many countries, enabling organizations to run applications closer to their remote users and teams.
- **Infrastructure Scaling:** AWS enables companies to automatically adjust compute capacity based on application demand and traffic patterns.
- **Developer and DevOps Tools:** The platform provides services for automation, CI/CD pipelines, container management, and infrastructure deployment.

#### Best For:

Large organizations and distributed teams require high-performance cloud infrastructure with flexible scaling and a wide range of cloud services.

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

### 3. Microsoft Azure

[Microsoft Azure](https://azure.microsoft.com/en-us/) is a widely used enterprise cloud platform designed to run business applications, development environments, and large-scale workloads. Many organizations choose Azure because it works closely with the Microsoft ecosystem, which includes widely used business and productivity tools.

For companies operating remote teams and distributed workforces, Azure provides infrastructure for both virtual machines and container-based applications. This allows organizations to run modern cloud workloads while continuing to support traditional enterprise systems.

#### Key Features

- **Virtual Machines and Container Services:** Azure allows teams to deploy cloud virtual machines and containerized workloads using managed orchestration services.
- **Hybrid Cloud Infrastructure:** Organizations can run applications across both on-premise systems and Azure cloud environments.
- **Enterprise Platform Integration:** Azure connects with widely used enterprise software and productivity platforms used by distributed teams.
- **Global Data Center Locations:** Azure operates cloud regions across many countries, allowing organizations to deploy applications closer to users and remote employees.

#### Best For:

Enterprises that use Microsoft-based technology stacks and require cloud infrastructure for remote collaboration, application hosting, and distributed workloads.

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

### 4. Google Cloud Platform (GCP)

[Google Cloud Platform](https://cloud.google.com/) (GCP) is a cloud computing platform used by engineering teams, SaaS companies, and data-focused organizations. It provides high-performance cloud infrastructure, strong networking capabilities, and services for large-scale data processing.

Many remote engineering teams choose GCP for workloads involving analytics platforms, machine learning systems, and large-scale application deployments. Google’s global infrastructure network supports distributed workloads by providing fast connectivity between cloud regions.

#### Key Features

- **Compute Engine Virtual Machines:** GCP lets you create virtual machines that you can adjust to fit heavy workloads or host applications.
- **Global Data Center Locations:** Google Cloud has data centers around the world so that organizations can run their workloads closer to their teams and users.
- **Data Processing and Analytics Services:** GCP includes services for large-scale data processing, analytics platforms, and machine learning applications.
- **Container and Kubernetes Support:** The platform provides managed Kubernetes services for running container-based applications and cloud-native environments.

#### Best For:

Remote engineering teams running data-intensive applications, analytics platforms, or machine learning workloads on high-performance cloud infrastructure.

![](https://www.atlantic.net/wp-content/uploads/2025/08/Oracle-cloud-infrastructure.png)

### 5. Oracle Cloud Infrastructure (OCI)

[Oracle Cloud Infrastructure](https://www.oracle.com/in/cloud/) (OCI) provides powerful cloud servers designed for enterprise applications and workloads that require high-performance computing. It focuses on reliable performance and predictable pricing, making it a solid option for organizations with high demands.

Many companies use OCI for large database environments, enterprise software, and compute-intensive workloads that require high CPU performance and large memory capacity.

#### Key Features

- **High-Performance Compute Instances:** OCI provides compute instances optimized for workloads that require high CPU performance and large memory.
- **High-Bandwidth Cloud Networking:** Oracle Cloud supports high-speed networking to help applications process large data volumes and handle heavy workloads.
- **Enterprise Database Support:** OCI infrastructure supports database-driven applications and large-scale enterprise systems.
- **Flexible Deployment Options:** Teams can use virtual machines, bare-metal servers, or containers based on their applications’ needs.

#### Best For:

Organizations that run compute-intensive applications, enterprise systems, or large database workloads on high-performance cloud infrastructure.

## How to Choose the Right Cloud Platform for a Remote Team

When choosing a cloud platform for your remote team, consider your team’s work, size, and infrastructure needs. Providers have different strengths, such as powerful computing, global reach, or developer-friendly tools.

When evaluating [high-performance cloud servers](https://www.atlantic.net/cloud-platform/cloud-hosting/), remote teams should keep a few key points in mind.

### Team Size and Future Growth

Small startups often look for flexible pricing and easy setup. Bigger companies usually need cloud infrastructure that can handle more work and support teams spread out in different locations.

### Application Requirements

Apps have different needs. Some require powerful CPUs, while others rely on fast storage, analytics, or machine-learning tools.

### Global Team Locations

If your team is spread across countries, choosing a provider with global data centers can make your apps faster and easier to reach.

### Infrastructure Management

Some teams prefer managed cloud services, while others want to handle server setup and management on their own.

### Security and Compliance Requirements

If your organization handles sensitive data, review the provider’s security features, encryption options, and compliance standards.

## Final Thoughts

High-performance cloud servers let remote teams use modern apps, development tools, and workflows. Cloud infrastructure enables organizations to host workloads in data centers worldwide, so teams in different locations can access them faster.

Platforms such as Atlantic.Net, AWS, Microsoft Azure, Google Cloud Platform, and Oracle Cloud Infrastructure all support remote teams and large applications. Each has unique strengths based on your workload, infrastructure needs, and company size.

As more companies use remote and distributed teams, cloud infrastructure remains essential for reliable systems, global app access, and steady performance for all users.


---

# Best Cloud Hosting Options for Developers Compared

> URL: https://www.atlantic.net/cloud-platform/best-cloud-hosting-options-for-developers/ | Published: 2026-03-21 | Updated: 2026-06-24 | Author: Hitesh Jethva

Choosing a [cloud platform](https://www.atlantic.net/cloud-platform/) sounds simple until you are the one responsible for performance, deployment speed, cost control, and long-term maintainability.

Do you need the deepest possible service catalog, or do you need infrastructure you can launch quickly and manage without a full platform team? Are you optimizing for enterprise scale, developer simplicity, container workloads, regulated data, or predictable monthly costs?

That is where many teams get stuck. The wrong platform can create unnecessary operational overhead, slow down releases, and make your infrastructure harder to manage as your application grows.

In this guide, we examine five [cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) platforms developers commonly use. These platforms support application deployment, testing environments, container workloads, and global infrastructure. Understanding how each provider works can help developers select a platform that fits their workflow and project requirements.

## What Developers Should Look for in Cloud Hosting?

Developers should look for a platform that makes shipping software easier without creating unnecessary operational drag. In practice, that means reliable compute, fast storage, good APIs and CLIs, enough geographic coverage for your users, and security features that match your risk profile.

When comparing providers, focus on a few practical questions:

How much control over infrastructure do you need? Some teams want direct control over virtual machines, storage, networking, and scaling. Others would rather rely on managed services to reduce operational work.

What kind of workloads are you running? A simple web application, an API, a Kubernetes-based platform, and a data-heavy AI application all have different infrastructure needs.

How important are pricing clarity and support? Usage-based flexibility can be powerful, but it can also make costs harder to predict. Some teams also need fast, direct support when something breaks.

Do you need specific security or compliance capabilities? If you handle sensitive data, your platform choice should support the controls, hosting model, and compliance posture your industry requires.

How well does the platform fit your current workflow? The right provider should work with your preferred tools, programming languages, deployment pipelines, and team skill set.

Let’s take a closer look.

### Compute Performance

Applications rely on stable CPU and memory resources. Developers run workloads such as APIs, backend services, container environments, and testing setups.

Cloud platforms provide different compute types for small apps, large systems, or container workloads. Some providers give full control over virtual machines, while others offer [managed services](https://www.atlantic.net/managed-services/) that reduce the need for infrastructure management.

### Storage Performance

Storage speed affects database queries, file processing, and app response time. Many cloud platforms use SSD or [NVMe storage](https://www.atlantic.net/dedicated-server-hosting/whats-the-difference-between-hdds-sata-ssds-and-nvme-ssds/) to boost read and write speeds.

Developers usually pick from these options:

- **Block storage** for databases and persistent data
- **Object storage** for backups, media files, and large datasets
- **Distributed file systems** for apps that run on several servers

### Developer Tools and APIs

Cloud platforms offer tools that help teams manage infrastructure with automation.

Common developer features include:

- Command line tools
- APIs for infrastructure control
- SDKs for multiple programming languages

With these tools, developers can deploy servers, configure networking, and manage resources using scripts rather than doing everything by hand.

### Global Infrastructure

Apps with users worldwide benefit from data centers in different regions. Running workloads closer to users reduces latency and boosts performance.

Cloud providers with regional infrastructure let developers run apps in different regions while managing everything from a single platform.

### Built-In Security and Compliance

Security is essential for many apps, especially in regulated industries.

Important security features include:

- **Role-based access control (RBAC)**
- **Encryption for data in transit and at rest**
- **Audit logging for activity tracking**

Many cloud platforms also comply with standards such as [GDPR](https://www.atlantic.net/vps-hosting/gdpr-compliance-for-global-managed-service-providers/), ISO 27001, and HIPAA. These help organizations meet data protection rules.

## Top Cloud Hosting Options for Developers

Below are several cloud hosting platforms developers use to deploy applications, run services, and scale workloads.

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

### 1. Atlantic.Net

[Atlantic.Net](https://www.atlantic.net/) provides cloud hosting designed for developers building web applications, APIs, and container-based services. The platform supports the full development lifecycle—from early MVP builds to production workloads for growing businesses.

Its infrastructure uses fast SSD instances and [RAID-10](https://www.atlantic.net/hipaa-data-centers/raid-10/) storage to maintain consistent application performance and low downtime. Developers can also increase server resources with the “Scale Up Servers Anytime” capability, which allows adjustments without complex migrations or downtime.

Atlantic.Net is known for its support model. Developers can talk directly with experienced engineers rather than relying solely on automated support. For teams handling regulated data, the platform also provides [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/), making it a good choice for healthcare and HealthTech applications.

#### Key Features

- **Virtual Cloud Servers:** Set up virtual machines you can customize with the CPU, RAM, and storage your applications need.
- **High-Performance Storage:** SSD instances with RAID-10 storage help your databases, testing environments, and applications access data faster.
- **API and Automation Support:** APIs let you automate infrastructure setup and connect your cloud resources to deployment pipelines.
- **Data Center Infrastructure:** With multiple data center locations, you can run your applications closer to your users, reducing latency.

#### Best For:

Atlantic.Net is a good choice for startups, small businesses, and development teams that need reliable cloud infrastructure with flexible resources. It is also well-suited for healthcare and regulated applications that need HIPAA-compliant hosting and direct technical support.

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

### 2. Amazon Web Services (AWS)

[Amazon Web Services](https://aws.amazon.com/) (AWS) is a widely used cloud platform that helps developers create large-scale and enterprise applications. It offers services such as EC2 for compute,

S3 for storage, CloudFront for content delivery, managed databases, serverless computing with AWS Lambda, and tools for AI and [machine learning](https://www.atlantic.net/gpu-server-hosting/top-gpu-hosting-providers-for-ai-and-machine-learning/).

AWS also offers developer tools such as CodeCommit, CodeBuild, and CodeDeploy to help with source control, continuous integration, and automated deployments. Its global data centers let developers run applications closer to users. Still, the many services and pricing choices can be complex, so experienced DevOps teams are often needed to manage them well.

#### Key Features

- **Elastic Compute (EC2):** Launch virtual servers and select the CPU, memory, and storage that match your requirements.
- **Object Storage (S3):** Store files, backups, and other data reliably.
- **Developer Toolchain:** CodeCommit, CodeBuild, and CodeDeploy support source control, continuous integration, and automated deployments.
- **Global Cloud Infrastructure:** Data centers in many regions allow applications to run closer to users and stay highly available.

#### Best For:

AWS is a great choice for enterprises and large development teams working on complex, distributed applications. It also works well for AI, machine learning, and big data projects that need advanced cloud services and a global network.

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

### 3. Microsoft Azure

[Microsoft Azure](https://azure.microsoft.com/en-us/) is a cloud platform that’s popular with organizations that already use Microsoft products. It works well with tools such as Visual Studio, .NET, and other Microsoft development environments, making it a practical choice for teams building Windows apps.

Azure offers services for computing, storage, web hosting, AI development, and container management. Developers can run apps on Azure Virtual Machines, use Azure Kubernetes Service (AKS) for containers, or build serverless apps with Azure Functions.

Azure also includes Azure DevOps, which provides tools for project management, source control, and CI/CD pipelines. If your organization uses Microsoft 365 or Active Directory, Azure helps you manage identities and share data between systems more easily.

#### Key Features

- **Virtual Machines:** Run Windows or Linux servers and pick the resources that fit your needs.
- **Azure DevOps:** Provides tools for source control, project tracking, and automated deployments.
- **Containers and Serverless:** Azure Kubernetes Service and Azure Functions support container workloads and event-driven apps.
- **Hybrid Cloud Support:** Let’s organizations run workloads on both on-premises systems and in the cloud.

#### Best For:

Azure is a strong option for companies already using Microsoft technologies such as Windows Server, .NET, and Microsoft 365. It also works well for teams that need hybrid cloud environments or developers building applications within the Microsoft ecosystem.

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

### 4. Google Cloud Platform (GCP)

[Google Cloud Platform](https://cloud.google.com/) (GCP) stands out for its data analytics, machine learning, and support for container-based apps. Developers often pick GCP when building data-driven systems or apps that use AI tools.

GCP provides tools such as BigQuery for large-scale data analytics, Vertex AI for machine learning, and App Engine for running apps without managing infrastructure. Developers can also use Google Kubernetes Engine (GKE) to manage containers and Cloud Functions for event-driven, serverless apps.

The platform includes tools such as Cloud Build, which supports continuous integration and deployment in the Google ecosystem. Google’s global network also ensures strong performance in different regions.

#### Key Features

- **BigQuery:** Analyze large datasets using Google’s fully managed data warehouse service.
- **Vertex AI:** Build, train, and deploy machine learning models using Google’s AI development tools.
- **Google Kubernetes Engine:** Run and manage containerized applications using Google’s managed Kubernetes platform.
- **Cloud Run Functions:** Build event-driven applications without managing servers.

#### Best For:

GCP works well for startups and development teams building AI, machine learning, and data analytics applications. It is also a good option for teams developing container-based or cloud-native applications using Kubernetes and serverless services.

![](https://www.atlantic.net/wp-content/uploads/2025/12/kamatera-logo-1.png)

### 5. Kamatera

[Kamatera](https://www.kamatera.com) offers cloud infrastructure that lets you quickly set up and customize servers. Developers use it to run web apps, development environments, and scalable backend services without spending much time on setup.

You can deploy cloud servers in just a few minutes and choose how much CPU, RAM, storage, and which operating system you need. Kamatera supports both Linux and Windows, making it suitable for a range of development needs.

Kamatera operates multiple global data centers, which help developers deploy workloads closer to users and maintain consistent application performance. Its pricing is based on hourly or monthly usage, allowing teams to adjust infrastructure costs as their projects grow.

#### Key Features

- **Custom Cloud Servers:** Create virtual servers with configurable CPU, RAM, storage, and operating systems.
- **Fast Server Deployment:** Launch cloud servers in minutes through a simple management interface.
- **Flexible Scaling:** Increase or decrease compute resources based on application demand.
- **Global Data Centers:** Deploy applications across multiple regions to improve performance and reduce latency.

#### Best For:

Kamatera is a solid option if you want flexible cloud servers that you can fully configure. It’s also a good fit for teams that need to launch projects quickly and scale their web app or development infrastructure.

## How to Choose the Right Cloud Platform for Development

The right cloud platform for you depends on the kind of applications you build, your infrastructure needs, and how your team handles deployments. Most developers consider a few key factors before making a decision.

### Application Requirements

Begin by looking at your application’s architecture. Platforms with a wide range of services are helpful if your project needs managed databases, serverless functions, or analytics tools.

If your application mostly needs virtual machines and [container hosting](https://www.atlantic.net/vps-hosting/container-hosting/), a provider that offers flexible compute options might be all you need.

### Infrastructure Performance

How well your application runs depends on compute power, storage speed, and network reliability. Check what instance types, SSD or NVMe storage, and data center locations are available.

These factors affect application response times, database performance, and system reliability.

### Pricing Structure

Cloud providers use different pricing models. Some platforms charge on an hourly or usage-based basis, while others offer predictable monthly plans.

Estimate expected workloads and compare pricing to avoid unexpected infrastructure costs as your application grows.

### Development Workflow Compatibility

Choose a platform that works well with your existing development tools. Support for APIs, SDKs, and automation tools allows teams to deploy infrastructure through scripts and CI/CD pipelines.

When the cloud platform aligns with the development workflow, teams can deploy applications faster and manage infrastructure with less manual effort.

## Conclusion: How to Choose the Best Cloud Hosting Platform for Your Project

Choosing the best cloud hosting provider comes down to your app’s needs, your team’s skills, and your future goals. For a small MVP or a new startup, look for easy deployment, clear pricing, and simple server management. Larger enterprise apps often need advanced features, global infrastructure, and support for more complex setups.

Your team’s experience is important as well. Developers with strong DevOps skills may want platforms that offer more control and customization. If your team is less familiar with infrastructure, it’s often better to pick a platform with managed services and built-in automation.

Cost is also important. Some providers charge by usage, while others charge a fixed monthly price. By estimating your compute, storage, and networking needs early, you can avoid unexpected costs as your app grows.

Security and compliance are important too, especially if your app handles sensitive or regulated data. Pick a platform that supports standards such as HIPAA or GDPR to keep user data safe and comply with legal requirements.


---

# Atlantic.Net Named Winner of the Coveted Global InfoSec Awards during RSAC Conference 2026

> URL: https://www.atlantic.net/press-releases/atlantic-net-named-winner-of-the-coveted-global-infosec-awards-during-rsac-conference-2026/ | Published: 2026-03-23 | Updated: 2026-06-04 | Author: Editorial Team

**Orlando, FL (March 23, 2026)** [Atlantic.Net](https://www.atlantic.net/), a global cloud infrastructure provider, has won a Global InfoSec award in the category of AI Healthcare Compliant Cloud. With the rapid application of AI in the healthcare industry, Atlantic.Net continues offering solutions to provide strict cybersecurity and compliance for the growing healthcare market. The award was presented today by Cyber Defense Magazine (CDM), the industry’s leading electronic information security magazine, at the RSAC Conference 2026.

“With top infosec experts judging this award, receiving this recognition is a tremendous achievement for our entire team,” said Marty Puranik of Atlantic.Net. “It reinforces our commitment to delivering secure, compliant, and reliable solutions that our customers can trust.”

In the Global InfoSec award submission, Atlantic.Net shared how it stands out in the industry as a leader in cloud hosting services for the healthcare market, providing the utmost in secure HIPAA-compliant Cloud Hosting services for healthcare providers, ensuring privacy, security, and compliance. In November 2025, Atlantic.Net unveiled its new[HIPAA-Compliant GPU Hosting service](https://www.atlantic.net/gpu-server-hosting/hipaa-gpu-hosting/), designed exclusively for healthcare, biotech, and medical companies seeking performance and regulatory peace of mind. 

“Atlantic.Net embodies three major features we judges look for to become winners: understanding tomorrow’s threats, today, providing a cost-effective solution and innovating in unexpected ways that can help mitigate cyber risk and get one step ahead of the next breach,” said Gary S. Miliefsky, Publisher of Cyber Defense Magazine.

CDM looks to award best of breed and next generation InfoSec solutions. The judges were CISSP, FMDHS, CEH, certified security professionals who voted based on their independent review of the company submitted materials. A list of all the winners is located here: [http://www.cyberdefenseawards.com/](http://www.cyberdefenseawards.com/)

**About Atlantic.Net**

Founded in 1994, [Atlantic.Net](https://www.atlantic.net/) is a privately held global cloud infrastructure provider with customers in over 100 countries, known for delivering secure, compliant, on-demand and customizable hosting solutions. With decades of experience, Atlantic.Net is one of the world’s most trusted and experienced hosting providers, offering 24/7 U.S.-based support. Specializing in security, compliance, and customer service, Atlantic.Net serves a diverse range of industries with solutions including HIPAA-compliant hosting and PCI-compliant hosting, backed by bare metal servers, dedicated hosting, GPU hosting, colocation, and its award-winning Cloud Platform. Operating from eight strategically located data center regions across the United States, Canada, the United Kingdom, and Asia, Atlantic.Net powers mission-critical workloads for organizations worldwide. For more information, visit[ Atlantic.Net](https://www.atlantic.net/) or connect with us on[ Facebook](https://www.facebook.com/Atlantic.Net),[ X (Twitter)](https://twitter.com/AtlanticNet),[ LinkedIn](https://www.linkedin.com/company/atlantic.net-inc./posts/?feedView=all), and[ YouTube](https://www.youtube.com/c/AtlanticNet).

**About Cyber Defense Magazine**

Cyber Defense Magazine is the premier source of cyber security news and information for InfoSec professions in business and government. We are managed and published by and for ethical, honest, passionate information security professionals. Our mission is to share cutting-edge knowledge, real-world stories and awards on the best ideas, products, and services in the information technology industry.  We deliver electronic magazines every month online for free, and special editions exclusively for the RSAC Conferences. CDM is a proud member of the Cyber Defense Media Group. Learn more about us at [https://www.cyberdefensemagazine.com](https://www.cyberdefensemagazine.com) and visit [https://www.cyberdefensetv.com](https://www.cyberdefensetv.com) and [https://www.cyberdefenseradio.com](https://www.cyberdefenseradio.com) to see and hear some of the most informative interviews of many of these winning company executives.  Join a webinar at [https://www.cyberdefensewebinars.com](https://www.cyberdefensewebinars.com) and realize that infosec knowledge is power. 

 


---

# Bare Metal for HPC in 2026: Engineer’s Guide

> URL: https://www.atlantic.net/dedicated-server-hosting/bare-metal-for-hpc-in-engineers-guide/ | Published: 2026-03-24 | Updated: 2026-05-30 | Author: Dr. Tehseen Zia

High-performance computing (HPC) has long supported advances in scientific research, artificial intelligence, and engineering. For many years, the systems needed to run these workloads were mostly limited to universities and specialized research centers. Large simulations and complex models required access to dedicated supercomputing infrastructure that most organizations simply could not afford.

That situation has changed. In 2026, compute-intensive workloads will have become part of everyday operations across many industries. Companies now run large data pipelines, AI training jobs, and compute-intensive simulations that demand more computing power than traditional cloud platforms were designed to handle. Generic shared cloud instances are often a poor fit for tightly coupled or latency-sensitive HPC workloads, although major cloud platforms now also offer HPC-optimized and bare-metal configurations.

This is one [reason](https://www.atlantic.net/dedicated-server-hosting/bare-metal-adoption-trends-single-tenant-infrastructure/) bare-metal infrastructure is gaining attention again. Bare-metal servers provide direct access to physical hardware without the overhead of a [hypervisor](https://www.vmware.com/topics/hypervisor). This allows these systems to behave more predictably than [virtualized cloud instances](https://www.geeksforgeeks.org/cloud-computing/virtualization-cloud-computing-types/), where multiple tenants share the same physical resources, and performance can fluctuate with the activity of neighboring workloads.

## Why Bare Metal Is a Strong Option for HPC

- **No Interference of Shared Resources **

Virtual machines and container platforms rely on [hypervisors or orchestration layers](https://www.techtarget.com/searchitoperations/definition/bare-metal-hypervisor) to allocate resources to multiple users. This approach works well for typical applications such as web services or business software. However, HPC workloads behave differently. They often use hardware to its limits and expect consistent access to CPU, memory, and network resources.

In a shared environment, one workload can affect another. A simulation might wait for memory access or compete with another job running on the same host for network bandwidth. These small interruptions may not seem significant, but when a workload runs across thousands of GPUs, they can add up to a significant performance loss and longer completion times.

bare-metal eliminates this uncertainty by providing a [single-tenant environment](https://www.atlantic.net/dedicated-server-hosting/bare-metal-adoption-trends-single-tenant-infrastructure/). In a dedicated setup, the entire server is dedicated to a single workload or team. No noisy neighbors and no hypervisor are competing for system resources. Every CPU cycle, memory access, and network operation operates more consistently. This level of stability is [vital](https://www.atlantic.net/dedicated-server-hosting/best-bare-metal-hosting-high-performance-workloads-2026/) for scientific simulations, such as weather modeling, molecular dynamics, or computational fluid dynamics, where consistent performance is critical for delivering reliable, timely, and reproducible results.

- **Control Over Hardware **

Another advantage of bare-metal is the [control](https://hostingstreets.com/how-bare-metal-servers-deliver-maximum-performance/) it gives engineers. Virtualization layers often hide the physical arrangement of the system, including the connections between CPU cores, memory channels, and devices. While this abstraction simplifies management, it limits the ability to optimize performance.

With bare-metal, engineers can work directly with the hardware. They can adjust BIOS settings, modify kernel parameters, configure device drivers, and understand the [system’s NUMA layout](https://en.wikipedia.org/wiki/Non-uniform_memory_access). This control makes it easier to optimize workloads at a lower level.

For example, techniques like [thread pinning](https://learn.arm.com/learning-paths/servers-and-cloud-computing/pinning-threads/background_info/) and [memory locality](https://www.geeksforgeeks.org/computer-organization-architecture/locality-of-reference-and-cache-operation-in-cache-memory/) help keep data close to the cores that process it. When data moves less within the system, latency decreases and throughput increases. For HPC workloads that continuously handle large datasets, these optimizations can create a significant difference.

- **High-Speed Interconnects**

Modern HPC systems depend on specialized hardware features to quickly transfer data between components. Technologies like [Remote Direct Memory Access (RDMA)](https://www.techtarget.com/searchstorage/definition/Remote-Direct-Memory-Access) allow one system to access another system’s memory directly, avoiding much of the operating system overhead. GPU interconnects like [NVLink](https://en.wikipedia.org/wiki/NVLink) let GPUs share data at very high speeds.

These technologies perform best when software communicates directly to the hardware. Virtualization layers can introduce additional steps between the application and the device, potentially reducing efficiency. Bare metal reduces software abstraction and lets applications use low-overhead driver and runtime paths to the hardware.

This difference becomes clearer in large workloads. Training a large AI model, for instance, involves GPUs exchanging large amounts of data. When those GPUs communicate directly without an abstraction layer in between, the training process can finish much faster.

- **Better for Large Parallel Workloads**

Many HPC workloads run across clusters of servers rather than a single machine. Frameworks based on the [Message Passing Interface (MPI)](https://en.wikipedia.org/wiki/Message_Passing_Interface) divide a problem into smaller tasks and distribute them across multiple nodes. These tasks constantly exchange data during execution.

The performance of these workloads relies on the speed and reliability of the network connecting the nodes. Bare-metal allows engineers to tune these interconnects to meet the requirements of the applications. Network configuration, topology, and communication libraries can be optimized for the algorithm instead of relying on default settings in a shared environment. This level of control helps reduce latency between nodes and improve the overall efficiency of parallel workloads.

- **Security and Compliance Advantages**

Dedicated hardware can also simplify security requirements. When sensitive data is involved, organizations may need strict isolation between workloads. Running on a dedicated physical server removes the risk of sharing resources with other tenants.

Dedicated hardware may simplify isolation and risk management, but compliance still depends on provider agreements, documented safeguards, and the organization’s own risk analysis.

- **Evaluating the Cost Trade-Off**

bare-metal servers often appear more expensive than virtual machines at first glance. However, the comparison changes when the total runtime of a workload is taken into account.

Since bare-metal systems operate directly on physical hardware, they avoid the overhead of virtualization and competition for shared resources. Consequently, workloads often finish faster. When large simulations or training jobs complete sooner, they require fewer compute hours. This improved efficiency can lower the overall cost of long-running projects.

For teams running continuous simulations, large AI training jobs, or other long-running HPC workloads, these efficiency gains can make bare-metal a practical and economical option.

## Hardware Choices That Matter in 2026

- **Choosing the Right Processors**

Processor selection remains the foundation of any HPC system. Many modern deployments use processors like [AMD EPYC](https://www.amd.com/en/products/processors/server/epyc.html), known for their large number of cores and strong memory bandwidth. Current AMD EPYC 9005 systems scale to 192 cores per socket, or 384 cores in dual-socket configurations.

This kind of architecture works well for highly parallel workloads. It distributes tasks such as molecular dynamics simulations and finite element analysis across multiple cores. The newer processor designs also manage power consumption more efficiently, which helps keep operating costs under control as clusters grow.

- **The Role of GPU Acceleration**

GPUs have become an essential part of many HPC environments, particularly for artificial intelligence workloads and data-intensive simulations. GPU servers such as the [NVIDIA H100](https://www.nvidia.com/en-us/data-center/h100/)/H200 provide the tensor processing power required for modern AI training and inference.

These GPUs are often connected via high-speed links such as NVLink, which allow them to exchange data directly. Bare-metal systems can fully utilize these connections because the software communicates with the hardware without a virtualization layer. Some organizations also deploy the AMD Instinct lineup. These accelerators can be advantageous when the software stack or budget favors AMD hardware.

- **Memory and Storage That Keep Up**

As compute performance increases, memory and storage must increase accordingly. Most modern HPC nodes now rely on [DDR5 ECC RAM](https://www.corsair.com/us/en/explorer/diy-builder/memory/is-ddr5-ecc-memory/#:~:text=DDR5%20does%20have%20some%20ECC,chip%20on%20the%20memory%20module.) that can scale to several terabytes per server. Large memory capacity helps avoid bottlenecks when applications process massive datasets.

Storage is equally important. [Fast NVMe](https://www.sandisk.com/solutions/what-is-nvme-ssd) drives provide the read and write speeds needed for checkpointing, temporary data staging, and rapid dataset access. Many clusters combine multiple NVMe drives in RAID or direct-attached configurations to deliver consistent throughput. If storage cannot keep up with the compute layer, it quickly becomes the system’s weakest point.

- **High-Speed Networking for Clusters**

Networking plays a central role when workloads run among multiple nodes. For clusters with more than a few servers, high-speed Ethernet is commonly used in current deployments. Many deployments start at 100-gigabit links and include support for Remote Direct Memory Access to decrease latency and CPU overhead during data transfers.

Some HPC environments still rely on [InfiniBand](https://en.wikipedia.org/wiki/InfiniBand) for extremely low latency. This is particularly useful for tightly coupled workloads that use the Message Passing Interface.

With bare-metal infrastructure, engineers can directly tune these network configurations. Traffic policies, node communication paths, and performance settings can all be adjusted without interference from a shared virtual network.

- **Power Efficiency and Thermal Design**

As HPC clusters continue to grow, power and cooling have become critical considerations. Although modern processors and accelerators are more efficient than earlier generations, large clusters still require considerable amounts of electricity. Selecting servers with effective power management tools allows teams to monitor usage and limit consumption when necessary. Well-designed cooling systems also help to stabilize performance and reduce energy costs.

## Practical Steps to Build and Run a Bare-Metal HPC Cluster

- **Start with Workload Requirements**

The first step is understanding what the cluster needs to run. Engineers need to identify the main workloads, estimate the number of nodes required, and determine the amount of data the system will handle. Some teams use bare-metal systems primarily for simulations, while others rely on them for AI training or large-scale analytics pipelines.

It is also important to decide how the system will handle long-term data. Some standalone clusters operate as individual systems, while others connect to external cloud storage. Clarifying these requirements early helps avoid redesigning the system later.

- **Prepare the Operating System**

Once the hardware is ready, install a stable Linux distribution on each node. Many HPC teams rely on Rocky Linux or Ubuntu because they offer long-term support and compatibility with HPC tools.

After installation, remove unnecessary background services and tune the system for performance. Kernel parameters should be adjusted for low-latency networking and large memory pages. These small system-level adjustments can help reduce overhead during heavy compute workloads.

- **Install the Cluster Software Stack**

A workload manager is essential for scheduling jobs and sharing resources across the cluster. The most widely used option today is [Slurm Workload Manager](https://en.wikipedia.org/wiki/Slurm_Workload_Manager). Administrators typically create partitions for different node types, such as CPU-only nodes and GPU nodes. GPU resources are defined in configuration files so the scheduler can allocate them correctly to each job.

Next comes the application runtime environment. MPI libraries such as [Open MPI](https://www.open-mpi.org/) and [MPICH](https://www.mpich.org/) enable applications to run across multiple nodes. GPU workloads also require software stacks such as [CUDA](https://developer.nvidia.com/cuda/toolkit) or [ROCm](https://en.wikipedia.org/wiki/ROCm), and applications should be built or configured for the target GPU architecture.

- **Build the Storage Layer**

For HPC, storage is essential for the speed and scalability of workloads. Parallel file systems such as [BeeGFS](https://www.beegfs.io/c/) or [Lustre](https://www.lustre.org/) are commonly used to provide high-throughput access across many nodes.

Local NVMe drives are often reserved for temporary data, scratch space, and checkpoints during long-running jobs. This combination allows fast local processing while keeping shared data accessible across the cluster.

- **Configure the High-Speed Network**

Networking becomes critical once workloads span multiple nodes. MPI traffic should be bound to the high-speed network connection, and features such as [Remote Direct Memory Access](https://en.wikipedia.org/wiki/Remote_direct_memory_access) should be enabled to reduce communication latency.

Testing the network early helps catch configuration issues. Tools such as [OSU Micro-Benchmarks](https://mvapich.cse.ohio-state.edu/benchmarks/) can measure latency and bandwidth between nodes to confirm that the cluster is performing as expected.

Many teams also add container support to simplify software deployment. Platforms such as [Apptainer](https://en.wikipedia.org/wiki/Apptainer) allow researchers to package applications with their dependencies for running them directly on bare-metal hardware.

- **Monitor and Automate the Environment**

Monitoring tools help keep the cluster stable during heavy workloads. Systems based on [Prometheus](https://prometheus.io/) and [Grafana](https://grafana.com/) can track CPU and GPU utilization, temperature, power consumption, and network activity.

Alerts should be configured for issues such as thermal throttling, hardware faults, or network drops. Automation also plays an important role. Scripts for node provisioning, configuration, and job submission make it easier for new users to start working without learning the entire infrastructure.

- **Validate Performance Before Production**

It is helpful to run a set of validation tests before putting a cluster into regular operation. Standard HPC benchmarks can help verify that CPU, GPU, memory, and network performance meet expectations.

It is also useful to run a real workload from your own domain, such as a sample simulation or a small training job. If the results do not match expectations, adjustments can be made at the BIOS, operating system, or scheduler level. Once performance is stable, the cluster is ready for production workloads.

Real-World Use Cases

- **Weather Modeling**

[Weather forecasting](https://www.atlantic.net/gpu-server-hosting/the-role-of-high-performance-computing-in-advancing-ai-for-climate-solutions/) teams employ bare-metal clusters to run large ensemble simulations. Each node processes independent forecast models and exchanges boundary data over low-latency network links. This setup helps reduce runtime and improve the reliability of time-sensitive predictions.

- **Genomics and Bioinformatics**

Genomics researchers use GPU-equipped bare-metal nodes to process massive sequencing datasets. Tasks like sequence alignment, genome assembly, and variant calling can benefit from direct hardware access and high memory bandwidth.

- **Financial Modeling**

Financial institutions risk analysis and [Monte Carlo simulations](https://www.ibm.com/think/topics/monte-carlo-simulation) across large numbers of CPU cores. Reporting cycles rely on predictable execution times, and bare-metal infrastructure provides the stability needed for daily risk calculations and scenario analysis.

- **AI and Model Training**

AI development teams [train](https://www.atlantic.net/dedicated-server-hosting/why-ai-models-run-faster-on-bare-metal-servers/) foundation models on multi-node GPU clusters. High-speed interconnects, such as NVLink and RDMA-enabled networking, enable efficient data exchange between accelerators. This reduces communication overhead during distributed training and shortens the path from experimentation to production-ready models.

Conclusion

In 2026, high-performance workloads demand predictable performance and direct hardware access. For many organizations, bare-metal has become a practical foundation for AI, simulations, and other compute-intensive tasks that cannot afford unnecessary overhead.

With powerful platforms such as AMD EPYC and accelerators like the NVIDIA H100, teams can achieve strong performance when systems are properly configured and tuned. Whether deployed as dedicated servers or through bare-metal cloud environments, the goal is the same: keep the workload as close to the hardware as possible.

For regulated industries, experienced infrastructure partners can help balance performance with security and compliance. As HPC continues to grow, bare-metal expertise will remain an important advantage for engineering teams.

**Related Guides:**

- [HIPAA Compliant Hosting Solutions](https://www.atlantic.net/hipaa-compliant-hosting/)
- [PCI-Compliant Hosting Solutions](https://www.atlantic.net/pci-compliant-hosting/)
- [What Are Managed Services?](https://www.atlantic.net/managed-services/what-are-managed-services/)

**Related Products:**

- [Atlantic.Net Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/)
- [Atlantic.Net HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)
- [Atlantic.Net GPU Hosting](https://www.atlantic.net/gpu-server-hosting/)


---

# Bare Metal Cloud Servers for High-Performance Workloads

> URL: https://www.atlantic.net/dedicated-server-hosting/bare-metal-cloud-servers-for-high-performance-workloads/ | Published: 2026-03-25 | Updated: 2026-06-24 | Author: Robert Agar

Many modern organizations run high-performance workloads to meet business requirements and objectives. Processing these demanding workloads effectively requires access to advanced, modern hardware. Unfortunately, the necessary hardware resources may not be readily available in a company’s on-premises data center.

Businesses can leverage bare-metal cloud servers to meet their high-performance computing needs. Companies can work with cloud service providers (CSPs) to obtain the hardware resources they need without incurring the costs of purchasing and supporting them. The combination of bare-metal technology and cloud computing offers organizations a cost-effective, flexible way to run a wide range of high-performance workloads.

## What is a Bare Metal Server?

A bare-metal server is a [dedicated server](https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/) in which a single tenant uses all the physical resources. Users have full control of the hardware and can configure it to meet specific operational and workload requirements. Companies can deploy traditional bare-metal servers in on-premises data centers if they have the financial resources and technical expertise to purchase and manage them.

A bare metal cloud server provides dedicated resources with the streamlined provisioning, automation, and scalability of cloud solutions. Customers can typically use a control panel to scale the server with just a few clicks, rather than physically adding infrastructure resources. Cloud-based bare metal servers offer users a hybrid environment that combines the flexibility of cloud computing with the performance of dedicated hardware.

### Benefits of bare metal servers

Bare metal servers offer multiple benefits that help meet the requirements of demanding workloads.

- **Superior performance:** Users enjoy optimal performance with direct access to the server’s physical hardware. Bare-metal dedicated servers eliminate the [virtualization](https://www.atlantic.net/vps-hosting/what-is-server-virtualization/) layer that can impact performance in cloud solutions.
- **Stability and reliability:** Users have exclusive access to server resources with no contention from noisy neighbors. The lack of shared infrastructure ensures reliable, stable performance while providing complete control over resource allocation.
- **Custom hardware:** CSPs typically offer multiple base [bare-metal server](https://www.atlantic.net/dedicated-server-hosting/what-is-a-bare-metal-server-benefits-use-cases-and-best-practices/) configurations that address a wide range of customer use cases. Most hosting providers will also work with their customers to customize server hardware to address specific requirements, such as additional onboard memory or higher bandwidth limits.
- **Administrative control:** Teams have complete control over all administrative functions. They can install whatever operating systems they need to support their applications. Companies can enforce a strong identity and access method (IAM) solution to ensure authorized use of data resources.
- **Enhanced security:** The resource isolation afforded by a dedicated server reduces risks posed by other tenants and supports applications that require confidential computing. Security teams can implement stringent controls to secure the environment from external threat actors.
- **Flexibility:** Teams can provision a bare metal server by installing a [hypervisor](https://www.atlantic.net/dedicated-server-hosting/bare-metal-hypervisors-vs-hosted-solutions/) to create and manage virtual machines. Using virtual instances allows users to run multiple operating systems on dedicated hardware.
- **Compliance support:** The isolated nature of bare-metal dedicated servers supports compliance with data security and privacy regulations such as [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/what-is-hipaa-cloud/) and [GDPR](https://www.atlantic.net/vps-hosting/gdpr-compliance-for-global-managed-service-providers/).
- **Cloud integration:** Cloud-based bare-metal servers offer the added advantage of easy integration with other cloud services, such as scalable, multi-tiered storage systems.

## What are High-Performance Workloads?

High-performance workloads are computing tasks that require substantial physical resources to process efficiently. They often use immense volumes of data and need more powerful environments than those available in many traditional on-site data centers.

### Core features of high-performance workloads

High-performance workloads exhibit one or more of the following core features.

- **High compute requirements:** These workloads typically require an organization to deploy powerful servers equipped with advanced GPUs and CPUs.
- **Parallel processing:** Teams may run tasks across multiple processor cores or nodes for enhanced performance. These tasks typically leverage the power and parallelism of GPUs.
- **Large data volumes:** Workloads may process and create massive datasets that require extensive processing and object storage resources.
- **Intensive memory usage:** Workloads may need to process large volumes of data in memory concurrently to provide real-time feedback and results.
- **High I/O throughput:** Workloads depend on optimized disk, storage, and network bandwidth to provide required performance levels.

### Examples of high-performance workloads

Modern organizations run a wide range of high-performance workloads, as illustrated by the following examples.

- Artificial intelligence (AI) and machine learning (ML) systems consume tremendous computing resources. Many of these tasks, such as training ML models and natural language processing, are computationally intensive and require extensive parallelism.
- Scientific simulations often perform complex computations on large datasets. Researchers need powerful processors to run molecular or physics simulations in realistic time frames. Climate and weather modeling is another type of simulation that can significantly affect public storm preparedness.
- Big data analytics platforms process large volumes of data to discover important insights for a variety of purposes. Businesses use analytics to better understand customer and market trends, driving competitiveness. Many companies rely on predictive analytics to ensure they service vital equipment before it fails.
- High-traffic web applications must simultaneously and efficiently handle a large number of users. Global ecommerce businesses, online gaming platforms, and streaming services require reliable network performance and scalable infrastructure to address usage spikes and fluctuations. Slow performance can lead to dissatisfied users and lost customers.
- Engineering and designing simulations, such as structural material analysis or digital twin construction, require complex calculations and powerful GPUs. Companies use these simulations for purposes ranging from ensuring product safety to streamlining and optimizing industrial processes.
- Media and video processing companies need superior performance for tasks such as visual effects generation, video encoding, and 3D rendering. These users typically need high storage bandwidth and fast GPUs.

## How do Bare Metal Servers Address High-Performance Workload Requirements?

Bare metal servers meet the needs of high-performance workloads in multiple ways. The servers can be equipped with the CPUs and GPUs required by these demanding applications, providing parallelism and computational power. Teams can use full control over hardware and software configurations to tailor servers to address specific use cases efficiently. The machines can leverage extensive storage and network resources to handle large volumes of data effectively.

Businesses may choose to deploy a [hybrid infrastructure](https://www.atlantic.net/gpu-server-hosting/scaling-ai-workloads-why-hybrid-cloud-infrastructure-is-the-future-of-enterprise-ai/) that runs less-demanding applications on-premises or in shared cloud environments, while relying on bare-metal servers when they need additional performance or resources. Their flexibility and scalability are essential for meeting the computational needs of modern, demanding workloads.

## Conclusion

Bare-metal cloud servers provide users with the computing power needed for high-performance workloads without the expense of purchasing and managing hardware in their data centers. Companies of any size, including small businesses and startups, can compete with larger organizations by engaging a reliable CSP that offers powerful, bare-metal dedicated servers. The servers enable teams to run modern applications and workloads cost-effectively.

[Atlantic.Net](https://www.atlantic.net/) provides customers with [cloud-based bare-metal dedicated servers](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) to meet the specific requirements of virtually any workload. All our servers are housed in high-quality data centers and backed by a 100% uptime service-level agreement, ensuring your server is always available. [Talk to our team](https://www.atlantic.net/about-us/corporate-contact/) today and learn how we can provide bare-metal servers to meet all your high-performance computing needs.


---

# Top CDN Services for 2026: Evaluating Provider Performance, Security, and Structure

> URL: https://www.atlantic.net/cloud-platform/best-cdn-providers-for-performance-security/ | Published: 2026-03-27 | Author: Editorial Team

When a user requests your application, the physical distance between their device and your server limits performance. You cannot bypass the speed of light, and routing traffic across public internet exchanges adds latency at every step. Content delivery solutions were created to address this problem by caching static files closer to end users. Whether you run a WordPress site, an e-commerce platform, or a global SaaS application, a good CDN enables faster, more reliable content delivery.

However, evaluating a CDN service in 2026 goes far beyond basic image caching. The modern edge is programmable. It runs code, manages TLS connections and SSL certificate termination, absorbs large attacks, and routes traffic smartly around internet congestion using modern protocols. Choosing among the best CDN providers is an important decision. Pick the wrong one, and you might face issues with inflexible cache invalidation, unexpected bandwidth overages, weak reporting tools, or security features that block legitimate traffic. This guide outlines the main criteria for evaluating the top CDN services, reviews the leading providers, and explains why even the best edge network still depends heavily on the quality of your origin server.

## Why Your Choice of CDN Matters in 2026

If you only serve static HTML pages, CSS, and other static content, almost any provider can do the job. Complications arise when you need to handle both static and dynamic content across multiple regions.

Today’s leading CDNs act as application runtimes. Instead of sending every API call or authentication request back to your main data center, developers can push logic directly to the edge. This is usually done through WebAssembly or lightweight JavaScript execution environments, like V8 isolates. By executing this code close to the user, applications feel instantly responsive. These edge computing capabilities now matter as much as raw cache capacity.

Additionally, the CDN serves as the main security perimeter. Malicious traffic, whether from automated bots or targeted application-layer attacks, hits the edge first. A capable CDN cleans up this traffic, improving website security and protecting your core infrastructure from becoming overloaded by modern cyber threats.

## Main Criteria: Global Reach, Latency, and Routing

When looking at providers, marketing materials often emphasize the total number of Points of Presence (PoPs). While a large footprint can help, merely counting nodes doesn’t provide the full picture. You need to consider network capacity, peering agreements, routing intelligence, and whether the provider can maintain global coverage for consistent performance.

### Peering and Backbone Capacity

A PoP is only useful if it has fast, reliable connections to local Internet Service Providers (ISPs). Top CDNs invest heavily in private networks and establish direct peering agreements with major ISPs. This helps them avoid the congested public internet. When comparing providers, check total network capacity, usually measured in Tbps, to see how much concurrent traffic they can handle. This is what supports global content delivery and reliable delivery during traffic spikes.

### Anycast Routing

Most major CDNs use Anycast routing. With Anycast, multiple edge servers across the globe share the same IP address. When a user sends a request, the Border Gateway Protocol (BGP) automatically routes it to the closest or most optimal server. This simplifies DNS management and helps deliver reliable content at scale; if one PoP goes offline, BGP quickly redirects traffic to the next-nearest location.

### Smart Routing and Origin Shielding

BGP doesn’t account for performance. It routes based on the shortest network path, not necessarily the fastest or least congested. High-end CDNs monitor the internet in real time and actively route your traffic around outages and high-latency links. Also, look for features like an Origin Shield. Instead of having many edge nodes request the same expired file from your origin server, an Origin Shield designates one specific CDN node to fetch the data, which then fills in the rest of the edge network.

This is one of several advanced caching techniques that help optimize content delivery and improve cache efficiency. Better platforms also include strong performance tracking and reporting tools so you can understand cache hit ratio, origin load, and bandwidth usage over time.

## Security at the Edge: WAF and DDoS Protection

Your CDN acts as your front door. It must identify and deal with threats before they reach your hardware. In practice, that means a provider’s reliable security features matter just as much as its raw performance.

### Volumetric DDoS Protection

Layer 3 and Layer 4 Distributed Denial of Service (DDoS) attacks aim to overwhelm your network with junk traffic, often in the form of UDP or SYN floods. A capable CDN absorbs these attacks at the edge, spreading the malicious traffic across its extensive global network so that no single node or origin server fails. This is a core part of secure content delivery.

### Web Application Firewall (WAF)

Layer 7 attacks are more advanced, targeting the application itself through methods like SQL injection, cross-site scripting (XSS), or malicious API calls. A modern WAF inspects incoming HTTP/HTTPS requests and blocks harmful payloads. The best providers keep their global rules automatically updated to protect against new vulnerabilities as soon as they are discovered. These advanced security features are no longer optional for public-facing applications.

### Bot Management

Not all automated traffic is harmful; search engine crawlers need access to your site. However, credential stuffing bots, scrapers, and inventory hoarders can disrupt an application and distort analytics. Top CDNs use behavioral analysis, browser fingerprinting, and machine learning to quietly block bad bots without forcing legitimate users through endless CAPTCHAs. Good bot controls are part of the broader security services and advanced security stack that leading providers now offer.

## Evaluating the Top CDN Providers

The market features a few main players, each with a different structure. Some focus primarily on edge delivery, while others combine content delivery, security, and origin infrastructure into a broader platform. Here’s how the top services compare.

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

### #1. Atlantic.Net

Atlantic.Net earns the top spot for organizations that need more than a standalone CDN. While many businesses focus on edge caching first, real-world performance still depends on the strength of the underlying hosting environment. Atlantic.Net combines CDN capabilities with Web Application Firewall protection, advanced DDoS protection, and secure hosting infrastructure, making it a strong choice for teams seeking performance, security, and reliable origin services from a single provider. Atlantic.Net also operates across eight global data center regions and has more than 30 years in business, making it particularly relevant for production workloads that require stability and compliance-focused support.

**Best for:** Businesses that want secure origin infrastructure, CDN support, and edge protection in a single platform.

**The Structure:** Atlantic.Net’s model is built around secure, dedicated, and managed hosting backed by edge services such as CDN, WAF, and DDoS protection. That makes it well-suited to organizations that care as much about origin resilience, compliance posture, and backend performance as they do about edge caching.

**Key Strength:** End-to-end infrastructure. Instead of treating the CDN as an isolated layer, Atlantic.Net supports the broader delivery path, from protected origin hosting to edge acceleration and attack mitigation. That is especially useful for workloads where dynamic requests, security controls, and backend responsiveness matter just as much as static asset delivery.

**The Trade-off:** Atlantic.Net is best positioned for businesses that want a combined hosting and edge strategy. Teams looking only for a standalone developer-led CDN platform may still compare it alongside providers that focus more narrowly on programmable edge delivery.

![](https://www.atlantic.net/wp-content/uploads/2025/08/Cloudflare_Logo.png)

### #2. Cloudflare

Cloudflare CDN is one of the most recognizable names in the market, known for its large Anycast network, advanced features, and developer-friendly tooling.

**Best for:** General web applications, serverless computing, and integrated security.

**The Structure:** Cloudflare runs a large global network where every server uses the same software stack. This means that every PoP can handle caching, WAF, and DDoS protection simultaneously.

**Key Strength:** Cloudflare Workers. This serverless platform allows developers to deploy code around the world in seconds. It uses V8 isolates instead of traditional containers; cold starts are usually under 5 milliseconds. It is one of the strongest examples of modern edge computing capabilities in a production CDN.

**The Trade-off:** While the lower tiers offer a free plan, making Cloudflare a common choice for teams exploring a free CDN, enterprise features such as advanced bot management or dedicated IP addresses come at a much higher price. The platform is easy to get started with, but costs can rise quickly once you need more specialized controls. Even so, smaller teams often view it as a strong option for competitive pricing.

![](https://www.atlantic.net/wp-content/uploads/2026/03/fastly-logo.png)

### #3. Fastly

Fastly is built around Varnish, a highly efficient HTTP accelerator. It is the CDN of choice for teams that need fine control over caching rules and low-latency delivery for dynamic and static content.

**Best for:** Highly dynamic content, major media publishers, and e-commerce platforms.

**The Structure:** Fastly lets developers write custom caching logic using Varnish Configuration Language (VCL). It also offers Compute@Edge, a serverless environment built on WebAssembly that provides strong performance and isolation.

**Key Strength:** Instant cache invalidation. Fastly can purge content globally in about 150 milliseconds. This allows publishers to cache constantly changing content, such as breaking news headlines or live sports scores, knowing they can instantly update the edge when needed.

**The Trade-off:** The platform has a steeper learning curve. Writing VCL requires specialized knowledge, making Fastly less accessible to smaller teams seeking simpler content delivery solutions.

![](https://www.atlantic.net/wp-content/uploads/2026/03/akamai-logo-1.png)

### #4. Akamai

Akamai is the oldest major name in the CDN industry. It handles a large volume of global web traffic and maintains strong relationships with ISPs worldwide.

**Best for:** Large-scale enterprise software delivery, video streaming, and organizations with strict compliance needs.

**The Structure:** Instead of relying solely on large, centralized PoPs, Akamai places thousands of server clusters directly within ISP networks worldwide. This deep-edge strategy often puts Akamai physically closer to the end user than its competitors, giving it exceptional reach for web content delivery and software distribution.

**Key Strength:** Unmatched scale and reliability. If you need to deliver a multi-gigabyte software update to millions of users at once or broadcast a live sporting event globally, Akamai can manage it without issue. Few providers can match its global CDN footprint or operational maturity.

**The Trade-off:** Akamai has a reputation for complex contracts, custom pricing, and an older user interface. It caters to enterprise budgets, but configuration changes can take longer to implement across its vast network than those of newer competitors.

![](https://www.atlantic.net/wp-content/uploads/2026/03/cloudfront.png)

### #5. Amazon CloudFront

CloudFront is Amazon Web Services’ native cloud CDN. It is closely integrated into the broader AWS ecosystem.

**Best for:** Organizations heavily invested in AWS infrastructure.

**The Structure:** CloudFront uses the private AWS global network. When a user requests data, the traffic enters the AWS network at the nearest edge location. It travels over Amazon’s private network to reach the origin, reducing exposure to public internet congestion.

**Key Strength:** smooth integration and IAM controls. CloudFront works smoothly with S3 buckets, EC2 instances, and Elastic Load Balancers. You can manage access controls and security settings using the same IAM policies as the rest of your infrastructure.

**The Trade-off:** Custom edge logic through Lambda@Edge is generally slower and more expensive to execute than Cloudflare Workers or Fastly’s Compute@Edge. In addition, AWS data transfer pricing can become complex and costly at scale. It fits teams already committed to AWS, but pay-as-you-go pricing does not always mean predictable bills.

### The Best of the Rest

Other CDN providers, including Google Cloud CDN and Microsoft Azure CDN (often called Azure CDN), may also make sense for teams already standardized on Google Cloud services or Azure services. Their appeal usually stems from tighter alignment with existing cloud services, identity controls, and platform-native workflows. However, their feature depth, advanced security, and analytics capabilities can vary by use case.

## The Role of the Origin Server: Why Infrastructure Still Dictates Speed

There is a common misconception in web architecture that a good CDN can compensate for a bad server. It cannot. A CDN functions as a caching layer. It only serves what it has stored. When a user requests a file not in the cache or submits a dynamic request, such as a checkout form or a database query, the CDN must forward the request to your origin server.

If your origin server is weak, misconfigured, or on a crowded network, the CDN will wait. The end user still experiences high latency, but now they are waiting on the CDN, which is waiting on your origin. Time to First Byte (TTFB) will increase, website performance will suffer, and the gains from the edge will be limited.

To get the best from a premium CDN, you need strong, reliable origin infrastructure. This is where Atlantic.Net stands out. With more than 30 years of experience and 8 secure data centers in the US, Canada, Europe, and Asia, Atlantic.Net builds infrastructure that helps CDNs perform well. Whether you need a highly available VPS cluster, a set of dedicated bare-metal servers for database tasks, or HIPAA-compliant hosting for sensitive healthcare applications, the origin must be dependable.

Take a healthcare portal, for example. A CDN can quickly deliver the static frontend framework, including static files such as HTML, CSS, and JavaScript, to the patient’s browser in milliseconds. But when the patient requests medical records, the CDN must securely send the API call back to the origin. That data cannot be cached at the edge. It must be handled by a compliant, secure, and highly responsive backend. Atlantic.Net provides managed infrastructure, encrypted backups, and 24/7 support needed for the secure delivery of those dynamic requests. A high-performing architecture needs a partnership between the edge and the core. The CDN handles distribution, while Atlantic.Net supports the backend systems that enable improved performance.

## Conclusion

Choosing the right CDN provider in 2026 means understanding your workload. If you need a massive global reach for media delivery, Akamai remains a top choice. If you need instant cache purging for highly dynamic applications, Fastly is a strong fit. For developer-friendly tooling and strong edge execution, Cloudflare remains one of the best CDN providers. If you are already deep in AWS, CloudFront is the logical option.

At the same time, the edge is only part of the picture. Review your core infrastructure first. Check your cache hit ratios, monitor your origin’s Time to First Byte, and make sure your database queries are efficient. If your origin server struggles with dynamic requests, upgrading your CDN will only mask the problem. The best results come from pairing the right CDN with infrastructure that supports secure content delivery, performance optimization, and long-term, reliable delivery.


---

# Secure Hosting Now as NAND & SSD Prices Rise in 2026

> URL: https://www.atlantic.net/cloud-platform/secure-hosting-now-nand-ssd-prices/ | Published: 2026-03-27 | Author: Richard Bailey

For many businesses, hosting costs are a predictable expense. You budget for cloud instances, dedicated servers, storage, backups, and CDN services, expecting next quarter to look like the last quarter in terms of costs.

[Market trends so far in 2026](https://counterpointresearch.com/en/insights/memory-price-tracker-january-2026) suggest that this assumption is proving challenging. Issues have arisen due to a major [supply squeeze](https://www.ibselectronics.com/resources/news/market-news-kioxia-2026-nand-is-sold-out”-—-ai-storage-demand-pushes-tight-supply-toward-2027/) across the memory and storage markets, driving up the cost of hardware used in modern hosting. What appears to be a semiconductor procurement issue is actually a direct cost problem for any company that relies on NVMe storage, GPU Graphics Cards, and DDR5 High-Speed Memory.

If you are using high-performance databases, virtual machines, cloud storage, or storage-heavy infrastructure, then the signals are serious. [TrendForce initially forecast](https://www.trendforce.com/presscenter/news/20260105-12860.html)NAND Flash contract prices to rise 33%–38% quarter over quarter in Q1 2026, then raised that outlook to 55%–60% as AI and data-center demand tightened supply further. It also said client SSD contract prices were expected to rise by at least 40% QoQ.

[NAND flash and SSD pricing](https://www.forbes.com/sites/tomcoughlin/2026/01/02/digital-storage-and-memory-projections-for-2026-part-2/) have moved sharply upward, especially in the first few months of 2026, and DRAM pricing is climbing right alongside them.

Providers cannot quietly absorb these fluctuations forever. At Atlantic.Net, we know firsthand that these increases force the industry to revisit hardware budgets, slow refresh cycles, delay expansion, and eventually reprice services.

We don’t operate outside the bounds of normal economics. When the cost of enterprise SSDs, DRAM, and storage-heavy server builds rises, that pressure moves downstream. It might first appear as fewer discounts, slower provisioning, or tighter capacity. It may end up on the customer invoice.

Businesses that move early can still secure capacity and lock in better terms. Those who wait might find themselves buying infrastructure after the market has already reset.

## Why Are Prices Going Up?

The global AI boom is a major contributor to this change. Training clusters, inference platforms, vector databases, retrieval systems, and storage-intensive AI pipelines consume massive amounts of DRAM and flash storage. The market has changed quickly over the last 6 months; server buyers aren’t just competing with each other anymore, they are up against hyperscalers and AI cloud platforms such as AWS, OpenAI, Claude, and Google.

That pressure is now visible at the manufacturer level too. In March, [Micron said](https://investors.micron.com/static-files/e089f8c0-065d-47b8-9d02-bfa863cdb357)it was seeing NAND demand “significantly in excess of our available supply” for the foreseeable future, and that both DRAM and NAND supply-demand conditions were expected to remain tight beyond calendar 2026.

Hyperscale clouds are buying up large volumes of hardware, signing long-term commitments, reserving capacity, and heavily influencing manufacturing priorities. As a result, enterprise buyers and regional providers are pushed down the supply chain, and prices rise as demand soars.

The hosting industry is feeling the squeeze as suppliers prioritize premium enterprise demand for AI infrastructure. They are no longer eager to flood the market with excess capacity after painful oversupply cycles. Manufacturers are being highly selective, and supply is being throttled.

Hosting might feel like software, but it still relies on physical hardware. Every cloud instance, VM, database platform, or storage node runs on real servers filled with NAND, DRAM, CPUs, controllers, and networking gear. If AI demand absorbs the world’s memory and storage output, the services built on that hardware get more expensive.

## AI Data Centers Are Reshaping Supply Priorities

AI data centers are redefining priority demand across the entire supply chain. Large deployments of accelerated servers demand massive volumes of high-performance memory and enterprise SSDs for data staging, checkpointing, local caching, and distributed storage.

Once suppliers see stronger margins and longer commitments from AI buyers, they serve those customers first. Prioritizing large, strategic buyers makes perfect commercial sense for manufacturers; however, it creates the harsh reality of a throttled market for ordinary enterprise buyers.

Products might technically be available, but dependability drops. High-capacity NVMe drives face delays, strict allocations, or massive price hikes. Lead times get fuzzy. Discounts vanish. Procurement teams can no longer bank on buying later under the same conditions.

When uncertainty hits the market, providers protect themselves. At Atlantic.Net, we constantly monitor these shifts across the industry. As a whole, we are starting to see sellers quote more cautiously, reserving stock aggressively, and pricing based on future replacement costs rather than past market conditions. Hosting prices are likely to rise well before the full impact of the shortage becomes apparent.

## Hyperscalers Are Securing Future Supply in Advance

As an aside for demand, the largest buyers are locking down future supply before anyone else gets a chance. When hyperscalers lock in multi-year arrangements, market flexibility shrinks for everyone else.

This creates a cascading effect across the infrastructure stack. Large providers commit early using their massive capital and scale. Mid-sized companies, regional providers, and enterprise buyers have less leverage and prefer shorter purchasing windows. Suppliers reward certainty, volume, and long-term visibility. Buyers without those advantages face worse pricing, longer lead times, and lower allocation priority.

Don’t assume your hosting provider can automatically shield you from market pressure. Even well-run providers can only buy from their specific position in the supply chain. If upstream vendors feel the squeeze, hardware prices will rise. Availability gets erratic. Replacement costs surge. Providers might still get what they need, but they will pay more, wait longer, and inevitably pass those costs along.

## Kioxia Is a Warning Sign for the NAND Market

To understand the tightening NAND market, look at major producers like [Kioxia, whose 2026 production is reportedly already sold out](https://www.trendforce.com/news/2026/02/13/news-kioxia-posts-record-¥543-6b-q3-fy25-revenue-confirms-2026-nand-fully-booked/). NAND flash isn’t a minor server component anymore. It sits at the absolute center of performance-focused infrastructure. NVMe hosting, virtualization nodes, database servers, analytics platforms, and modern storage layers all depend on it.

When a major producer’s output becomes tightly committed, the ripple effects move fast. Enterprise SSD availability shrinks, OEM pricing hardens, and procurement becomes cautious, leaving smaller buyers with no flexibility.

This highlights what heavy forward commitments mean for the rest of the market. By the time you notice significant price changes in your hosting bill, the supply chain decisions that caused them are already months old. Upstream warning signs matter right now.

## Rising Prices Are Changing Procurement Behavior

When memory and storage prices spike, the impact goes far beyond a more expensive parts list. In a stable market, companies optimize for flexibility. You can delay decisions, compare providers, stagger deployments, and expect similar pricing next quarter. In a rising market, that logic changes because organizations commit early and save substantially by avoiding another approval cycle.

This behavioral shift accelerates the squeeze. Once buyers believe prices will keep climbing, they act sooner. Procurement teams lock down budgets. Distributors cut back on generosity. Suppliers quote with caution. A basic supply issue quickly changes into a market-confidence issue. We are seeing this in the consumer GPU market too: graphics cards are significantly more expensive now than six months ago.

We are paying more for new hardware, which makes it difficult to maintain customer pricing based on last year’s assumptions. While we try to absorb part of the increase, it is rarely sustainable when SSDs, NAND, and DRAM all rise simultaneously.

Eventually, the pressure has to go somewhere and may show up as higher monthly fees, steeper setup costs, fewer promotions, lower included storage, or stricter resource allocations. Another reason why it’s important to lock in now!

## This Is Bigger Than One Component

The problem goes beyond NAND. The entire memory supply chain is tightening at once. Enterprise SSDs, flash, DRAM, server memory, GPU memory, and all of the related storage alternatives are driving up the cost of building and refreshing servers.

Server infrastructure is a tightly coupled system. High performance relies on the combined capabilities of storage, memory, compute, power, cooling, and board design. If both flash and DRAM rise at the same time, the cost of a new server node doesn’t just creep upward. It jumps.

This is where hosting economics bend. Providers refreshing fleets of NVMe-heavy, high-memory servers suddenly face much higher capital requirements, which, in turn, affect provisioning timelines, available configurations, expansion plans, and the future cost of high-performance services.

## Will Hosting Prices Rise?

By combining all of these trends we have discussed so far, the reality is clear: hosting prices face severe upward pressure. There is a good chance prices will go up. It depends on what workloads you are running. If you are AI-heavy, your chances are higher than for everyday cloud instance users.

When the raw ingredients get more expensive, the interface stays polished, but the underlying economics shift. The cost of performance-oriented hosting is rising, and buyers will soon foot the bill.

## What Companies Should Do Now

If your organization needs more NVMe storage, high-memory instances, dedicated servers, GPU infrastructure, or storage-heavy capacity later in 2026, secure it now. Do not wait.

[Reuters reported in January](https://www.reuters.com/world/asia-pacific/memory-chipmakers-rise-global-supply-shortage-whets-investor-appetite-2026-01-05/) that the memory shortage was being described by industry executives as “unprecedented,” and Micron now expects tight DRAM and NAND conditions to continue beyond 2026.

Multi-year hosting contracts, reserved capacity, and early renewal discussions drastically reduce your exposure to this tightening market. We strongly advise our partners to lock in their infrastructure needs immediately.

This urgency is critical for businesses running high-performance databases, analytics platforms, AI workloads, backup-heavy systems, latency-sensitive applications, or virtualization-heavy environments. These workloads lean heavily on the exact components currently under extreme price pressure.

Need to know more? Reach out to Atlantic.Net to discuss your hosting needs and to lock in prices for 2026 and beyond.


---

# Enterprise Hosting for High-Growth Organizations

> URL: https://www.atlantic.net/dedicated-server-hosting/enterprise-hosting-high-growth-organizations/ | Published: 2026-03-31 | Updated: 2026-06-04 | Author: Dr. Tehseen Zia

In IT infrastructure, the term “enterprise hosting” refers to the infrastructure that is stronger than shared servers. However, for organizations facing rapid growth, this definition is often too vague to act on. As a company transitions from a startup to expansion, the infrastructure that supported its initial customers can become a liability. What was once a strength can turn into a bottleneck.

Enterprise hosting involves more than just having access to a server. It is a complete approach to infrastructure that emphasizes performance, security, and, most importantly, predictability. For organizations in a growth phase, understanding the difference between standard hosting and enterprise-grade infrastructure can determine whether they scale successfully or face challenges.

## Defining Enterprise Hosting

At its core, enterprise hosting refers to a dedicated infrastructure built to handle high-traffic workloads, sensitive data, and complex regulatory requirements. Unlike shared hosting or simple [virtual private servers (VPS)](https://www.ibm.com/think/topics/vps), enterprise hosting relies on dedicated hosting. This usually involves single-tenant architecture, where your resources do not compete with other accounts for CPU cycles or memory.

For a growing organization, this separation provides better reliability. When you launch a marketing campaign that increases traffic by 400%, you need to be confident that your infrastructure can support it. With enterprise hosting, the hardware resources designated for you are yours alone. There is no “[noisy neighbor](https://www.techtarget.com/searchcloudcomputing/definition/noisy-neighbor-cloud-computing-performance)” effect in which another client’s increased activity slows down your application.

This environment typically includes dedicated bare-metal servers, enterprise-grade [storage area networks (SANs)](https://www.ibm.com/think/topics/storage-area-network), and private networking. It treats your organization’s digital operations as critical assets, not just another account in a shared pool.

## Performance and Reliability Under Pressure

High-growth organizations should not compromise on performance. In a scaling environment, milliseconds matter. [Studies](https://www.thinkwithgoogle.com/_qs/documents/9757/Milliseconds_Make_Millions_report_hQYAbZJ.pdf) show that even a one-second delay in page load time can lead to significant drops in conversion rates. In your race for market share, your infrastructure must support your growth rather than hinder it.

Enterprise hosting solves this by eliminating resource contention. Standard cloud hosting, while scalable, often operates on a multi-tenant model where resources are oversubscribed. This means a provider sells more capacity than physically exists, betting that not all customers will need their full allocation at the same time. For a growing business, this is a gamble.

True enterprise hosting relies on dedicated resources. Whether you are running a high-transaction e-commerce site, a SaaS platform, or a database handling millions of records, dedicated CPU, RAM, and storage ensure consistent performance during peak loads. This reliability builds trust with your customers. If your product is your revenue stream, your hosting infrastructure must be dependable.

## Security and Compliance

As organizations grow, they collect more data. With more data comes greater responsibility. High-growth organizations often deal with strict regulatory requirements. If you manage payment card information, you must comply with the [PCI-DSS framework](https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard). If you work with healthcare data, you follow [HIPAA](https://www.paloaltonetworks.com/cyberpedia/what-is-hipaa) rules.

Enterprise hosting is designed to tackle these challenges. It is not enough to just claim security; the infrastructure must be built for it. For instance, Atlantic.net provides HIPAA-compliant hosting, which requires a strict HIPAA [Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/). This ensures that the hosting environment meets the necessary physical and technical safeguards for protecting [electronic Protected Health Information](https://www.techtarget.com/searchhealthit/definition/electronic-protected-health-information-ePHI) (ePHI).

Enterprise hosting provides the isolation necessary for compliance. In a multi-tenant environment, showing logical separation between your data and other customers’ data can be challenging. With dedicated infrastructure, whether bare metal or private cloud, you have clearly defined boundaries. This simplifies audit trails and compliance management. For a growing company, failing a compliance audit can disrupt business operations. Enterprise hosting builds a foundation where compliance is built in rather than added at the last minute.

## Scalability Without Complexity

Many people think cloud hosting is the only way to achieve scalability. While public cloud providers like AWS and Azure offer great flexibility, they also introduce complexity. For a high-growth organization, complexity hinders speed. Managing large cloud environments often requires a dedicated team of DevOps engineers just to handle networking, security groups, and cost optimization.

Enterprise hosting provides a different kind of scalability: [vertical scaling](https://www.bare-server.com/blog/scaling-bare-metal-servers-vertical-vs-horizontal) and predictable growth. When your application runs on dedicated bare-metal servers, scaling up often means simply adding more resources to your existing setup. Since you are not paying for thousands of micro-transactions (API calls, [data egress](https://www.oracle.com/cloud/data-egress/), etc.), financial forecasting becomes more accurate.

For organizations that depend on databases or stateful applications, this predictability is vital. While containers and serverless architecture are popular, they are not always suitable for every workload. Enterprise hosting allows you to scale your infrastructure in line with your business growth. You can add new nodes, increase storage, or expand into new geographic data centers, without re-architecting your application every six months.

## The Role of Managed Services

One of the hidden costs of high growth is the distraction of infrastructure management. When a company is scaling, the development team should focus on building features and improving the product, not patching systems or troubleshooting network latency issues.

This is where the “enterprise” aspect of hosting becomes a service relationship rather than just renting hardware. Providers like [Atlantic.net](https://cybernews.com/best-web-hosting/atlanticnet-review/) offer managed solutions that connect raw infrastructure with in-house expertise. With [managed enterprise](https://gsdsolutions.io/why-use-managed-it-services/) hosting, your team gains access to system administrators, security specialists, and compliance officers to handle the technical aspects.

This allows a small IT team to achieve more. You get control of a dedicated environment while enjoying the operational support typically reserved for large companies with extensive IT departments. For a high-growth organization, this efficiency leads to rapid progress. You can move faster because the mechanical details of the infrastructure do not weigh you down.

Why Standard Cloud Is Not Always the Answer

Although providers like AWS, Google Cloud, and Azure are known for scalability, they are not always the right choice for every stage of growth. For high-growth organizations, the public cloud billing model can be a challenging obstacle. Costs that seem reasonable at first can quickly get out of control depending on your workload shape, architecture, and cost management discipline. Since pricing models are granular, it is easy to commit to resources you do not need or incur high egress fees.

Enterprise hosting, especially on dedicated infrastructure, provides cost predictability. With a fixed pricing model for dedicated servers and private cloud setups, you know exactly what your infrastructure costs will be each month. This financial predictability is a strategic advantage. It allows you to allocate budget to sales, marketing, and product development without worrying about unexpected cloud bills cutting into your profits.

Additionally, performance consistency often favors dedicated environments. For high-I/O applications like databases, big data analytics, or real-time communication platforms, the consistent performance of bare metal often outpaces the variable performance of virtualized public cloud instances.

## Future-Proofing Your Infrastructure

High-growth organizations keep changing continuously. The infrastructure that works for 50 employees and 1,000 customers may not be sufficient for 200 employees and 10,000 customers. Enterprise hosting is designed to handle these changes.

Dedicated servers and private clouds also offer flexibility for incorporating new technologies. Whether you are implementing AI-driven analytics, expanding into global markets, or transitioning to a microservices architecture, the underlying infrastructure remains stable. You do not need to switch platforms every time your business model evolves.

Additionally, enterprise hosting providers often adopt a hybrid approach. You can keep dedicated bare-metal servers for your main database while using cloud resources for fluctuating workloads or development environments. This hybrid strategy provides the best of both worlds: the performance and security of dedicated resources with the flexibility of the cloud.

## Conclusion

For high-growth organizations, hosting is not just an IT decision; it is part of the business strategy. The question is not simply, “How much bandwidth do I need?” but rather, “How do I ensure that my infrastructure grows with my goals?”

Enterprise hosting delivers the stability, security, and performance necessary for rapid expansion. It removes the uncertainty of resource allocation, simplifies compliance with regulations such as HIPAA and PCI-DSS, and provides the predictability needed for future planning.

The right hosting choice depends on workload requirements, compliance requirements, and internal IT capacity. Some companies need cloud-based flexibility. Others need dedicated servers or a hybrid approach. Many may need a mix of both.

What matters is choosing a platform that can support the business today and still make sense when traffic doubles, compliance needs expand, or new applications are added. Providers such as Atlantic.net are worth evaluating for that reason: the goal is not just to host systems, but to support growth with a stable, secure, and professional foundation.


---

# ADA, EAA & WCAG Compliance for Ecommerce: Hosting Requirements for Accessible Online Stores!

> URL: https://www.atlantic.net/cloud-platform/ada-eaa-wcag-ecommerce-hosting-requirements/ | Published: 2026-04-02 | Updated: 2026-05-04 | Author: Editorial Team

Accessibility should be in every facet of web design, whether front-end or back-end!

Most e-commerce accessibility discussions revolve around visible elements – such as contrast ratios, alt text, keyboard navigation, or form labels. While these elements are critical, ADA and WCAG compliance cannot be achieved solely through UI fixes.

Behind every accessible e-commerce experience lies a hosting environment that determines speed, stability, security, and adaptability. If hosting infrastructure fails, even a perfectly designed accessible interface can become unusable – especially for people with disabilities, depending on assistive technologies and predictable system behavior.

From an ADA, EAA, and WCAG standpoint, e-commerce websites function as digital public accommodations. Thus, their accessibility matters for businesses. And any technical limitation that restricts equal access, whether caused by slow servers, downtime, or unstable third-party integrations, can expose businesses to compliance gaps and legal risk.

## Hosting infrastructure directly impacts WCAG principles.

Hosting choices directly affect the four WCAG principles:

- **Perceivable**: Slow content delivery can prevent screen readers from announcing content correctly.
- **Operable**: Server delays break keyboard navigation and time interactions.
- **Understandable:** Inconsistent data loading confuses users with cognitive disabilities.
- **Robust:** Poor hosting reduces compatibility with browsers, devices, and assistive technologies.

In short, accessibility is only as strong as the infrastructure supporting it.

## Core ecommerce hosting requirements for ADA & WCAG compliance

### **Page loading speed and performance optimization**

Performance is a functional accessibility requirement, not just a UX metric. Users with disabilities often rely on:

1. Screen readers that process content sequentially.
2. Voice navigation tools that require predictable response times.
3. Alternative input devices that magnify delays.

Advanced hosting requirements:

1. High-performance SSD / NVMe-based servers.
2. Support for HTTP/2 or HTTP3.
3. Object and page-level caching (Redis, Memcached, Varnish).
4. Server-side image optimization and lazy loading support.
5. Brotli/GZIP compression at the server level.

Accessibility & compliance impact:

1. Faster DOM rendering improves screen reader flow.
2. Reduces cognitive overload caused by delayed responses.
3. Supports WCAG SC 2.2.1 (Timing Adjustable) and SC 2.4.3 (Focus Order) indirectly by ensuring smooth interactions.

### **Server reliability, uptime, and equal access**

Accessibility guidelines emphasize equal and consistent access. Hosting instability – frequent downtime, slow failover, or broken sessions – creates disproportionate barriers for users who require more time or assistance to complete tasks.

Hosting requirements:

1. 99.9% or higher uptime SLA
2. Redundant infrastructure across regions
3. Automatic failover and backup servers
4. Continuous monitoring and incident response systems.

Accessibility impact:

1. Prevents session loss for users who complete forms slowly.
2. Ensures that assistive technology users are not excluded during outages.
3. Aligns with ADA and EAA’s non-discrimination principles.

### **Security infrastructure and accessible transactions**

Secure hosting is essential for accessible e-commerce transactions, especially for users with disabilities, because they may be more vulnerable to fraud or data misuse.

Security hosting requirements:

1. Enforced HTTPS across all pages.
2. PCI-DSS compliant payment environments.
3. Secure session management.
4. Protection against bot attacks and DDoS incidents.

Accessibility impact:

1. Prevents forced logouts that disrupt screen reader navigation.
2. Ensures secure form submission without unexpected errors.
3. Supports trust and predictability for users with cognitive disabilities.

### **Database management and content consistency**

Accessibility relies heavily on stable, predictable content delivery. Delays or failures in database queries can break:

1. Product descriptions
2. ARIA labels
3. Error messages
4. Order confirmation flows

Hosting requirements:

1. Optimized relational or NoSQL databases.
2. Proper indexing for product-heavy catalogs.
3. High availability database clusters.
4. Automated backup and recovery systems.

Accessibility impact:

1. Ensures screen readers receive complete information.
2. Prevents missing labels or dynamic content failures.
3. Supports WCAG SC 4.1.3 (Status Messages).

### **Scalability and traffic management during peak loads**

Accessibility issues often surface during high-traffic periods – sales events, festive campaigns, or flash discounts – when servers slow down or crash.

Hosting requirements:

1. Auto-scaling infrastructure
2. Load balancers for traffic distribution
3. Rate limiting and request prioritization
4. Graceful degradation mechanisms

Accessibility impact:

1. Prevents timeouts affecting users who require longer interaction time.
2. Ensures checkout remains usable during traffic spikes.
3. Supports WCAG SC 2.2.1 (Timing Adjustable) in real-world scenarios.

### **CDN (Content Delivery Network) for inclusive global access**

A CDN is essential for e-commerce businesses serving diverse geographic and linguistic audiences.

Hosting requirements:

1. Global edge locations
2. Optimized delivery of images, fonts, and scripts
3. Accessible fallback strategies
4. Caching rules aligned with dynamic ecommerce content.

Accessibility impact:

1. Faster font and icon loading for screen readers.
2. Reduced latency for users in remote or low-bandwidth regions.
3. Improves accessibility consistency worldwide.

### **Third-party integrations and accessibility control**

Most e-commerce accessibility failures occur due to third-party tools, not core platforms.

Hosting requirements:

1. Secure API gateways
2. Script isolation and sandboxing
3. Performance monitoring for third-party services
4. Ability to disable or replace inaccessible integrations quickly.

Accessibility impact:

1. Prevents keyboard traps caused by chat or payment widgets.
2. Ensures compliance with WCAG SC 4.1.2 (Name, Role, Value).
3. Reduces ADA litigation risk linked to embedded tools.

### **Multilingual and multi-currency infrastructure**

Inclusive ecommerce means supporting language and regional accessibility, not just disability access.

Hosting requirements:

1. UTF-8 encoding.
2. Language-based routing or content negotiation
3. Server-side localization logic
4. Stable currency conversion services with error handling.

Accessibility impact:

1. Screen readers correctly announce language changes.
2. Improves comprehension for users with cognitive disabilities.
3. Supports WCAG SC 3.1.1 and 3.1.2.

### **Assistive technology compatibility and future readiness**

Hosting environments must support standards-compliant rendering to remain accessible as assistive technologies evolve.

Hosting requirements:

1. Modern browser and OS compatibility.
2. Stable HTML output without forced DOM manipulation.
3. Progressive enhancement support.
4. Long-term update and patch management.

Accessibility impact:

1. Ensures interoperability with screen readers, magnifiers, and voice tools.
2. Aligns with WCAG SC 4.1 (Robust) principle.
3. Future-proofs ecommerce accessibility investments.

## All-in-One Accessibility: A comprehensive accessibility widget!

At times, it is a smart strategy to integrate external solutions to fix accessibility issues. An [accessibility widget](https://www.skynettechnologies.com/all-in-one-accessibility) like All in One Accessibility is a tool designed (by Skynet Technologies) for implementing/improving the accessibility features at digital assets. It can be integrated in a few moments without code modification, and it works equally well for both front-end and back-end issues.

Unique Selling Proposition Points:

- Follows data protection and security practices aligned with HIPAA, SOC 2 Type II, GDPR, CCPA, COPPA, and ISO 9001:2005, and ISO 27001:2022.
- Compatible with WCAG, ADA, EAA, Section 508, RPD Act, and other accessibility guidelines.
- 72 plus features including screen-reader support, voice navigation, talk & type, virtual keyboard navigation, text resizing, color and contrast adjustments, dyslexia-friendly fonts, pause-motion controls, Real-time accessibility score from widget dashboard, Google Analytics 4 and Adobe Analytics tracking, accessibility statement, and custom widget settings.
- Supports 190+ languages.
- It is a comprehensive solution with paid add-ons, including a manual accessibility audit report, remediation, document/PDF accessibility remediation, VPAT report/ACR, white-label branding, live website translation, and accessibility menu modification.

- Multisite plans available.

## Hosting checklist for accessible e-commerce compliance

- High-performance, scalable hosting
- 99.9%+ uptime with redundancy
- Secure, PCI-compliant infrastructure
- CDN-backed global delivery.
- Third-party integration control.
- Multilingual and multi-currency readiness
- Assistive technology compatibility.

## Hosting as a strategic accessibility investment

ADA, EAA, and WCAG compliance for e-commerce begins at the infrastructure level. Hosting decisions influence performance, security, reliability, and inclusivity – making them a strategic accessibility investment, not just a technical choice.

E-commerce businesses that align hosting infrastructure with accessibility principles can:

- Reduce legal exposure.
- Improve conversion rates.
- Enhance trust among users with disabilities.
- Build resilient, future-ready digital stores.

**Contributed by Skynet Technologies:**

*Rajesh Bhimani is the Founder of *[*Skynet Technologies*](https://www.skynettechnologies.com/)*, a leading digital accessibility remediation solutions company specializing in accessibility audit, ADA WCAG EAA Section 508 compliance, VPAT / ACR documentation, and inclusive technology for any size of businesses. With extensive experience in delivering accessibility solutions across diverse industries, he focuses on helping businesses improve digital experiences for users of all abilities. Rajesh is committed to advancing accessible web practices through innovative tools and practical implementation strategies. When he isn’t working, you can find him cooking for his family or reading some fiction. You can connect with him on*[*Twitter*](https://x.com/skynet_lv)*.*


---

# Why Private Bare Metal Clusters Improve Security, Visibility, and Threat Detection in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/private-bare-metal-clusters-security-visibility-threat-detection/ | Published: 2026-04-02 | Updated: 2026-05-04 | Author: Dr. Assad Abbas

Many organizations handle sensitive data in their daily operations. This often includes [electronic Protected Health Information (ePHI)](https://www.atlantic.net/hipaa-compliant-hosting/protecting-phi-cloud/), financial records, and customer personal data. Therefore, they must use HIPAA-compliant systems and maintain a valid [HIPAA Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/). These requirements establish the need for environments that offer robust security, deeper visibility, effective threat detection, and full operational control.

However, [public cloud](https://azure.microsoft.com/en-us/resources/cloud-computing-dictionary/what-is-a-public-cloud) platforms, while convenient and easy to deploy, do not always meet these needs. They rely on shared hardware and multi-tenant models, which can make performance unpredictable. In addition, visibility at the system level is limited. Multi-tenant environments also increase the risk of cross-tenant exposure. Security teams face challenges when monitoring system behavior and detecting unusual patterns promptly.

In contrast, private [bare metal](https://www.atlantic.net/dedicated-server-hosting/what-is-a-bare-metal-server-benefits-use-cases-and-best-practices/) clusters offer a more controlled solution. In these clusters, all compute nodes run on single-tenant hardware under a unified management system. Organizations have direct control over hardware, firmware, and network paths. Therefore, they gain clearer visibility into system activity, more reliable threat detection, and better control over their security posture. This level of control helps teams identify abnormal behavior earlier and respond more effectively. As a result, many regulated industries now choose private bare metal for business-critical workloads.

## What Are Private Bare Metal Clusters

Private bare metal clusters are groups of physical servers assigned to a single organization. These servers do not share hardware with other users. Therefore, all compute, memory, and storage resources are reserved for one organization. In addition, this single-tenant structure provides full access to the operating system, hardware settings, and network configuration.

In contrast, multi-tenant environments place multiple users on the same physical host. This setup reduces visibility and limits customization. In multi-tenant environments, it becomes difficult to observe low-level activity or to adjust system behavior to specific workload needs. As a result, organizations may face challenges when detailed inspection or consistent performance is required.

Private bare metal clusters address these limitations. They provide clear monitoring, stable performance, and complete control over the system. Therefore, they are suitable for workloads that require isolation, consistency, and detailed system oversight.

## How Private Bare Metal Clusters Improve Security, Visibility, and Threat Detection

Dedicated bare metal servers offer clear benefits for security, visibility, and threat detection:

- They improve security by not sharing hardware, which reduces the attack surface.
- They provide better visibility, allowing administrators to observe system behavior at the hardware, kernel, and network layers.
- They support earlier threat detection, as abnormal activity can be detected at lower levels before it affects applications.
- They deliver consistent performance because there are no competing users, and all CPU, memory, and storage resources are available to one organization.
- They simplify compliance processes, as HIPAA- and PCI-compliant environments benefit from clear isolation and predictable audit trails.

Because of these advantages, bare metal clusters are well-suited for business-critical and regulated workloads, including those handling ePHI and financial data, that require consistent performance, clear monitoring, and controlled resource usage. Similarly, bare-metal clusters support compute-intensive workloads such as AI and ML, as well as analytics and real-time processing, where high CPU and GPU performance, low-latency storage, and predictable system behavior are essential.

## Private Bare Metal Clusters: Architecture and Orchestration

The architecture of private bare-metal clusters supports business-critical workloads that require isolation, consistent throughput, and early detection of anomalous activity.

### Physical Host Topology and Performance

Performance in private bare-metal clusters depends on aligning workloads with the servers’ physical layout. Modern servers include multiple CPU sockets, [Non-Uniform Memory Access (NUMA)](https://www.techtarget.com/whatis/definition/NUMA-non-uniform-memory-access) domains, several memory channels per CPU, and dedicated PCIe slots for accelerators such as GPUs, NPUs, or FPGAs. By placing memory-intensive processes on the same NUMA node as their memory channels, organizations can reduce latency and maximize bandwidth. Similarly, connecting accelerators to the CPU socket with the shortest data path prevents bottlenecks and ensures consistent performance. These topology-aware strategies are particularly important for real-time analytics, machine learning training, and high-performance databases, where delays or contention can significantly impact results.

### Hardware-Rooted Security and Isolation

Private bare-metal clusters use single-tenant hardware, reducing the risks associated with shared infrastructure. Physical isolation prevents unintended access between workloads and limits potential side-channel attacks. In addition, [Trusted Platform Modules (TPMs)](https://support.microsoft.com/en-us/topic/what-s-a-trusted-platform-module-tpm-705f241d-025d-4470-80c5-4feeb24fa1ee) and secure boot mechanisms ensure that only verified firmware and operating systems operate on the servers. This approach provides a clear separation of resources, supporting controlled environments and reliable monitoring. Therefore, organizations can maintain high security and system integrity without relying on multi-tenant infrastructure.

### Orchestration and Bare Metal as a Service (BMaaS)

[Bare Metal as a Service (BMaaS)](https://www.purestorage.com/solutions/application-development/bare-metal-as-a-service.html) provides a structured framework for managing private bare metal clusters through automation and orchestration. Through this framework, servers are provisioned, re-imaged, and scaled using API-driven mechanisms, thereby ensuring consistent operational control across the cluster.

Within this framework, provisioning is implemented as a controlled and repeatable process. Techniques such as network-based bootstrapping and automated imaging ensure that each node is deployed in a consistent state. In particular, the use of standardized system images reduces configuration variability across servers. This uniformity enhances auditability and supports compliance requirements, as each deployment follows a verifiable, predefined configuration.

In parallel, infrastructure automation extends this control by defining resources through declarative models. Network parameters, including address allocation and segmentation, as well as server lifecycle states, can be managed programmatically. As a result, manual intervention is reduced, thereby limiting the likelihood of configuration errors and improving the consistency of system behavior across the cluster.

At the orchestration layer, workload management frameworks coordinate the placement and execution of applications on physical nodes. These frameworks rely on defined network policies, traffic control mechanisms, and resource descriptors to ensure that workloads operate within controlled boundaries. For example, workload scheduling may depend on explicit resource labeling to match applications with appropriate hardware, such as accelerator-enabled nodes. This structured coordination improves visibility into workload distribution and supports more precise monitoring of system activity.

Furthermore, lifecycle management remains an integral component of the BMaaS model. Processes such as hardware discovery, health monitoring, operating system deployment, and secure decommissioning are executed through automated workflows. Accordingly, these processes generate consistent telemetry across all nodes, thereby enhancing monitoring capabilities and enabling early identification of irregular or unauthorized activity.

At the same time, out-of-band management interfaces provide an additional layer of administrative control. These interfaces enable remote operations, including power management, firmware updates, and direct console access, independent of the primary operating system. When isolated within secure network segments and protected through encrypted communication, they support administrative oversight while limiting exposure to potential security risks.

Overall, BMaaS integrates dedicated hardware with automated provisioning, orchestration, and management processes. Therefore, it improves system visibility, enforces consistent operational practices, and supports more effective threat detection in private bare-metal clusters.

## Networking and Storage for Private Bare Metal Clusters

Networking and storage design are essential for maintaining security, ensuring system visibility, and enabling effective threat detection in private bare-metal clusters. These components must be structured to ensure controlled data flow, consistent monitoring, and reliable access to system activity.

### Networking for Private Bare Metal Clusters

Network segmentation is a fundamental mechanism for controlling communication within the cluster. Separating management, storage, and application traffic into distinct segments reduces the scope of potential security incidents and enables more precise observation of each traffic type. This structure improves the ability to identify irregular patterns within specific network paths.

Logical isolation further strengthens this approach. When traffic between segments passes through defined routing and inspection points, the risk of unauthorized movement is reduced. This also improves the quality of network-level telemetry, as monitoring systems can capture and analyze traffic at controlled boundaries.

Network continuity is equally important for maintaining uninterrupted visibility. Techniques such as [interface bonding](https://www.loadbalancer.org/blog/what-is-networking-bonding-and-what-might-you-use-it-for/) ensure that connectivity is preserved during link failures. This continuity ensures that logging and monitoring processes remain active, which is necessary for consistent threat detection and accurate incident analysis.

### Storage for Private Bare Metal Clusters

Storage design influences the effectiveness of monitoring and analysis processes. Systems that provide low-latency data access ensure that logs and telemetry are recorded without delay. This improves the accuracy of real-time observation and supports timely detection of abnormal behavior.

In addition, storage systems with high input/output capacity maintain stable [data ingestion](https://www.ibm.com/think/topics/data-ingestion) during periods of increased system activity. This consistency ensures that monitoring tools can process data without interruption, even under heavy load.

Reliable storage also supports the retention and retrieval of historical data. Access to consistent historical records is necessary to identify long-term patterns and investigate security events. As a result, storage architecture plays a direct role in enhancing both visibility and threat detection in private bare-metal clusters.

## Integration With Cloud Services and Cloud Environments

Private bare metal clusters can be integrated with public cloud environments to create hybrid architectures that combine security, visibility, and operational control with the flexibility of cloud services. In such setups, steady or sensitive workloads run on dedicated bare metal servers, ensuring that security and monitoring requirements are fully met. At the same time, bursty workloads or scalable tasks can be directed to public cloud resources, providing additional capacity without affecting critical systems.

To support this integration, reliable connectivity becomes essential. Stable and secure connections ensure that data transfers, monitoring systems, and security processes operate without interruption. Without such connectivity, visibility gaps may arise, reducing the effectiveness of threat detection. Therefore, organizations rely on VPN technologies, including IPSec or TLS-based solutions, to protect data in transit between private clusters and cloud environments. In addition, high-availability VPN configurations help maintain continuous connections, supporting uninterrupted monitoring and analysis.

Beyond VPN-based connectivity, organizations often use dedicated network links to improve performance. Services such as AWS Direct Connect, Azure ExpressRoute, or Google Cloud Interconnect provide consistent bandwidth and lower latency compared to standard internet connections. As a result, large datasets can be transferred more efficiently, and integration with cloud-native services becomes more reliable. Similarly, network peering and controlled routing help synchronize data between private clusters and cloud platforms, ensuring that logs, analytics, and monitoring workflows remain consistent across environments.

Integrating private bare metal clusters with cloud services through these structured approaches enables organizations to expand their capabilities while maintaining strong security, system visibility, and reliable threat detection.

## Security and Compliance Controls for Private Bare Metal Clusters

Private bare metal clusters rely on several essential controls to strengthen security, maintain compliance, and improve system oversight. These measures span hardware, monitoring, and data protection layers, ensuring reliable operations across the cluster.

First, hardware-based isolation mechanisms, such as TPM, secure boot, and measured boot, verify the integrity of firmware and the operating system before workloads are executed. By doing so, nodes start in a validated state, which enhances both security and observability.

Building on this foundation, bare metal clusters also support a range of compliance frameworks. They can meet HIPAA and PCI requirements and align with broader standards, such as SOC 2 Type II, ISO 27001, or FedRAMP, as needed. The combination of single-tenant hardware and consistent configuration paths simplifies audits and ensures adherence to regulatory requirements.

Furthermore, monitoring tools extend visibility across the cluster. Host-based and network-based intrusion detection sensors track system activity and inspect internal traffic. Unusual patterns and potential threats can be identified promptly, improving response times.

Finally, encryption at rest protects sensitive information from unauthorized access. Techniques such as LUKS2 or hardware-accelerated AES are commonly applied, and proper key management ensures that only authorized systems can access the data.

## Cost Efficiency of Private Bare Metal Clusters in 2026

Building on the performance, scalability, and security considerations discussed earlier, cost considerations complement the operational and security benefits of private bare metal clusters. Public cloud platforms handle bursty workloads well, but their pay-as-you-go model, egress fees, and premium services can make long-running applications costly. In contrast, private bare metal clusters offer predictable monthly billing and dedicated hardware, helping organizations maintain a more stable total cost of ownership.

In this context, for workloads with consistent demand, reserved dedicated servers are commonly used, often under 12- or 36-month plans. This approach provides predictable budgeting and resource planning. Pricing varies by configuration; for example, CPU-focused servers support general-purpose applications, GPU-enabled nodes address AI and ML workloads, and storage-intensive systems are priced according to capacity, performance, and redundancy.

## Business Applications and Use Cases for Private Bare Metal Clusters

Private bare metal clusters support a variety of business-critical applications by providing dedicated resources and complete control. Enterprise systems such as CRM and ERP operate with stable performance, while sensitive customer data remains isolated and easier to manage for compliance purposes. Similarly, high-performance databases benefit from low-latency storage, strong CPU throughput, and NUMA-aware workload placement, creating a reliable environment for data-intensive operations.

Workloads that require heavy computation, such as machine learning, run efficiently on GPU-enabled clusters where accelerators are directly attached to the host. This reduces latency during both training and inference. In addition, real-time applications like gaming and streaming require consistent processing and network performance, which bare metal clusters provide. Therefore, the combination of isolation, visibility, and dedicated resources makes private bare metal clusters suitable for diverse enterprise and high-performance workloads.

## How Atlantic.Net Supports Private Bare Metal Deployments

[Atlantic.Net](http://www.atlantic.net) provides infrastructure that enhances the security, visibility, and control of private bare-metal clusters. By offering single-tenant bare-metal servers, the platform ensures dedicated compute, memory, and storage resources that deliver predictable performance while enabling detailed monitoring of system activity. This dedicated environment also helps administrators manage the operating system, network configuration, and workload placement, enabling consistent application of isolation and observation practices.

In addition, the platform includes features that strengthen operational governance, such as encrypted storage, private networking, and controlled administrative access. These capabilities help organizations meet compliance requirements, including HIPAA and PCI, by providing consistent audit trails and clearly defined operational boundaries.

With dedicated hardware combined with configurable networking and data-protection measures, Atlantic.Net enables organizations to maintain visibility, operational control, and workload-specific optimizations. It is highly suitable for business-critical applications that rely on stable performance and careful system oversight.


---

# How to Verify Cloud Server Disk Performance Before You Buy

> URL: https://www.atlantic.net/cloud-platform/verify-cloud-server-disk-performance-before-you-buy/ | Published: 2026-04-03 | Updated: 2026-04-02 | Author: Richard Bailey

 

For databases, logging stacks, indexing engines, analytics pipelines, and other disk-heavy applications, storage performance can become the real bottleneck long before CPU or RAM does. It’s critical to understand exactly what the server’s underlying performance is. Two cloud server plans can look similar on paper and behave very differently under sustained random I/O.

This is why it’s essential to validate server storage performance before you commit.

This guide explains how to evaluate cloud server disk performance in a practical way, what to ask a provider before buying, and which benchmark data is actually useful when deciding whether a plan can support your workload.

## Why It Is Worth Validating Storage Performance Up Front

Most cloud server product pages do a reasonable job listing vCPU, RAM, and storage capacity. What they often do not show is the information that matters most to performance-sensitive buyers:

- 4K random read and write IOPS
- latency at p99 and p99.9
- whether performance is capped per disk or per plan
- whether results are based on burst behavior or steady-state testing
- whether the published figures are general platform claims or plan-specific measurements

That gap matters because a storage layer that looks fine in a generic plan comparison can still perform poorly for real workloads, especially under random access or sustained write pressure.

Validating storage before purchase reduces the risk of picking the wrong plan, discovering limitations after deployment, and then having to migrate again.

## The Metrics That Matter Most

You do not need every possible storage metric to make a sensible buying decision, but you do need the right ones.

### Random Read IOPS

Random read IOPS is one of the most useful indicators for database-heavy and lookup-heavy workloads. It gives you a clearer picture of how well a platform handles many small reads rather than large sequential transfers.

For most buyers, this should be tested at a 4K block size, because that is a common reference point and makes results easier to compare.

### Latency

Latency matters just as much as raw IOPS, and often more.

Average latency can hide outliers. That is why percentile latency matters:

- **p50** shows typical responsiveness
- **p99** shows how the platform behaves near the tail
- **p99.9** shows whether rare slow operations are becoming a real problem

A storage platform can produce impressive top-line IOPS while still feeling inconsistent in production if tail latency is unstable.

### Random Write Performance

Write performance matters for more than just bulk data ingestion. It also affects logging, journaling, cache backends, and transactional workloads.

A provider may have strong read performance and still show materially higher write latency, so it is worth testing both.

## “SSD” Still Does Not Tell You Enough

“SSD” is a useful starting point, but it does not tell you:

- whether the storage is NVMe or another SSD class
- whether the storage is local or backed by a shared storage layer
- whether IOPS limits apply at the disk level
- whether performance is designed to burst or remain stable over time

Buyers with performance-sensitive applications should look past the label and focus on measured results.

## How to Benchmark a Cloud Server Properly

If a provider can offer a short evaluation window or hourly billing, the most reliable way to validate storage is to benchmark the actual plan you intend to use.

A good baseline test should:

- use a repeatable tool such as fio
- run with direct I/O where appropriate
- record block size, queue depth, runtime, and job count
- separate read and write tests
- include percentile latency, not just throughput or averages

For practical pre-purchase validation, a simple test set usually includes:

- 4K random read
- 4K random write
- percentile latency reporting
- additional low-queue-depth testing if the workload is latency-sensitive

## Example Results From a Tested Atlantic.Net Cloud Server Environment

To make this more practical, here is what a tested Atlantic.Net Cloud Server in USA-EAST-1 (Orlando) produced using fio 3.36 with 4K block size, direct I/O, iodepth=64, numjobs=1, and a 60-second runtime. These figures give buyers a clearer picture of what measured Cloud Server storage performance looks like when test conditions are properly stated.

![](https://www.atlantic.net/wp-content/uploads/2026/04/VPS-Performance-1.png)

### 4K Random Read

The tested Atlantic.Net environment delivered about 96,155 random read IOPS, with read latency of roughly:

- **p50:** 0.659 ms
- **p99:** 0.733 ms
- **p99.9:** 1.729 ms

![](https://www.atlantic.net/wp-content/uploads/2026/04/VPS-Performance-6.png)

That is a strong result for a VPS benchmark. For buyers running read-heavy databases, search workloads, caching layers, or other lookup-driven applications, this level of random read performance shows that a well-tested VPS environment can deliver both high throughput and low tail latency.

### 4K Random Write

The same Atlantic.Net test environment delivered about 40,191 random write IOPS, with write latency of roughly:

- **p50:** 1.581 ms
- **p99:** 3.719 ms
- **p99.9:** 13.304 ms

![](https://www.atlantic.net/wp-content/uploads/2026/04/VPS-Performance-5.png)

That is still solid write performance for a VPS test, but it also highlights an important reality: write behavior often differs materially from read behavior. For logging platforms, write-heavy databases, and journaled workloads, that is exactly why both directions should be benchmarked before making a final decision.

### What These Results Actually Tell You

![](https://www.atlantic.net/wp-content/uploads/2026/04/VPS-Performance-2.png)

The benchmark above supports several useful conclusions.

First, the tested Atlantic.Net VPS environment showed very strong 4K random read performance. At roughly 96K read IOPS with p99.9 read latency under 2 ms, it would be a credible fit for many read-heavy workloads where responsiveness and steady random access matter.

Second, it showed good random write throughput, but with a noticeably heavier latency tail on writes than on reads. That does not make the platform unsuitable. It simply reinforces the point that serious buyers should evaluate storage against their own workload profile rather than relying on a single headline number.

Third, the benchmark is useful because the test conditions are clear. Without the block size, queue depth, direct I/O setting, runtime, and region, the numbers would be much less valuable for comparison. That is also why provider responses backed by measured results are far more useful than generic “fast SSD” claims.

![](https://www.atlantic.net/wp-content/uploads/2026/04/VPS-Performance-4.png)

![](https://www.atlantic.net/wp-content/uploads/2026/04/VPS-Performance-3.png)

## Questions Worth Asking Before You Commit

Even with benchmark data, buyers should still ask a provider for a few practical details:

- what exact plan was tested
- whether IOPS are limited per disk or by plan
- whether performance is best-effort or guaranteed
- whether the published numbers are from a real plan or a broad platform average
- whether the tested region matches the intended deployment region

For performance-sensitive projects, those details matter as much as the benchmark itself.

## What You Should Look For in a Provider Response

A good provider response should include:

- the exact plan or nearest equivalent tested
- the region tested
- 4K random read and write results
- percentile latency
- whether any IOPS cap applies
- whether performance is best-effort or otherwise policy-limited
- the benchmark method used

The more specific the response, the easier it is to judge whether a plan is genuinely suitable for your workload.

## Final Thoughts

Cloud server disk performance should not be judged solely by storage labels.

If your project depends on strong random I/O and predictable latency, ask for measured results, review the test settings, and compare the numbers to your workload rather than relying on generic product-page language.

A short benchmark on the actual plan is ideal. If that is not available, plan-specific fio data is still far more useful than a vague promise of “fast SSD storage.”

What to know more? Did you know you can deploy a Cloud Server directly from the [Atlantic.Net Cloud console](https://cloud.atlantic.net/?page=userhome)? Try it now, deploy a server in your local region, and witness the breakneck performance of the ACP Cloud.


---

# The True Cost of Running Workloads in the Public Cloud vs Dedicated Hosting in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/public-cloud-vs-dedicated-hosting-costs/ | Published: 2026-04-04 | Updated: 2026-04-11 | Author: Dr. Assad Abbas

Many organizations are re-evaluating their approach to running workloads on [public cloud](https://www.atlantic.net/dedicated-server-hosting/public-vs-private-cloud-for-ai-workloads-hidden-training-costs/) platforms and [dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/). Due to rapid data growth, strict compliance requirements, and the need for reliable business continuity, infrastructure management has become increasingly complex. Organizations are paying closer attention to the total cost of ownership because unpredictable costs can affect both operational budgets and long-term financial planning.

Each hosting model uses a different pricing approach; understanding these differences is essential for making informed decisions. Public cloud platforms charge for resources based on actual usage, including compute time, storage, and network transfer. This usage-based pricing can cause monthly bills to fluctuate and complicate long-term budgeting. In contrast, dedicated hosting generally provides fixed monthly fees and complete control over hardware. Although it requires careful planning, dedicated hosting offers more predictable costs for workloads that run continuously.

Since these pricing methods affect more than computing, evaluating the true cost of each option requires considering all contributing factors. Network usage, storage behavior, and managed service fees also influence overall expenses. Therefore, organizations must look at these elements together to determine which hosting model meets both technical and financial needs.

This article explains the main cost components of public cloud and dedicated hosting, examines sources of cost variability, and provides guidance for assessing which model is most cost-effective for different workloads.

## How Billing Models Differ: Public Cloud vs Dedicated Hosting

Public cloud and dedicated hosting follow different cost structures. Therefore, a clear understanding of these billing models is necessary for accurate cost evaluation and financial planning. Furthermore, these differences influence both short-term expenses and long-term financial stability. Organizations must examine each model carefully before selecting an appropriate infrastructure approach.

Dedicated hosting adopts a fixed monthly pricing structure that typically includes server hardware, storage, bandwidth, IP addresses, and support services. As a result, the monthly cost remains stable unless the organization upgrades the server or adds additional services. In addition, providers often include a defined amount of outbound data transfer within the plan, and overage charges apply only when this limit is exceeded. Therefore, network-related expenses can be estimated with a high level of certainty.

Certain industries require compliance-related features as part of their infrastructure. For example, healthcare organizations may require HIPAA-compliant hosting along with a Business Associate Agreement (BAA). Although these requirements may increase the monthly fee, the cost remains fixed and predictable. Similarly, optional services such as backup, monitoring, and enhanced support are offered at fixed rates and therefore do not introduce cost variability. As a result, dedicated hosting provides a stable cost structure that supports consistent budgeting for long-running workloads.

In contrast, public cloud platforms use a usage-based billing model that charges for resources based on actual consumption. For instance, compute resources are billed according to usage duration, which may be measured in seconds, minutes, or hours. In addition, pricing varies by instance type and geographic region, so cost estimation requires careful consideration. While reserved and spot pricing options can reduce costs, they require prior planning and a commitment to usage.

Similarly, storage costs in public cloud environments are calculated based on the amount of data stored per month, and additional charges apply for provisioned input/output operations, snapshots, and API requests. Workloads with high storage demand or frequent data access may incur higher costs. Network-related charges add further complexity, as outbound data transfer, inter-region communication, and inter-availability-zone traffic are billed separately. In addition, services such as public IP addresses, [NAT gateways](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html), and load balancers introduce both hourly and data transfer charges.

Furthermore, managed services such as databases, container orchestration platforms, caching systems, and analytics tools reduce operational effort but increase total spending. In addition, pricing differences across regions affect deployments spanning multiple locations, leading to significant cost variation. As a result, total cloud expenditure depends on workload behavior, data volume, and service selection. Therefore, due to this variability, organizations must evaluate both pricing models in relation to their workload requirements and financial objectives. The table below summarizes the key differences in billing structure and cost behavior:

Table 1: Comparison of dedicated hosting and public cloud

| Aspect | Dedicated Hosting | Public Cloud |
| --- | --- | --- |
| Billing Method | Fixed monthly fee | Usage-based metered billing |
| Cost Predictability | High, stable month-to-month | Variable; depends on workload and service usage |
| Included Resources | Compute, storage, bandwidth, IP addresses, support | Compute, storage, network, and managed services are billed separately |
| Bandwidth Handling | Fixed allowance with overage charges | Billed per GB; inter-region and inter-AZ charges apply |
| Compliance Features | Optional; predictable | Optional; may add usage or service costs |
| Cost Drivers | Upgrades, optional services, exceeding limits | Traffic, storage volume, IOPS, managed services, and regional variation |
| Suitable Workloads | Steady, always-on workloads | Variable, burstable, or experimental workloads |

## Core Cost Drivers and Sources of Variability

Though billing structures help calculate charges, they do not reflect the full cost of running workloads. Organizations must consider other important factors that influence total spending in both public cloud and dedicated hosting environments. The factors are as follows:

### Resource Utilization

Resource utilization directly affects cost. In public cloud environments, higher use of compute, storage, and network resources increases costs proportionally. Inefficient allocation or over-provisioning can lead to unnecessary expenses. In contrast, dedicated hosting allocates resources in advance, and therefore, underutilization does not raise the bill. However, it can result in unused capacity, which may represent an opportunity cost. Therefore, organizations need to monitor resource usage carefully to balance efficiency and predictable spending.

### Data Transfer and Network Costs

Data movement is another major cost driver. Public cloud platforms bill outbound data transfer and inter-region communication separately. In addition, services such as NAT gateways, load balancers, and inter-availability-zone traffic incur additional charges. Workloads with high network activity can significantly raise total expenses. Dedicated hosting, however, typically includes a fixed bandwidth allowance, and some providers offer unmetered bandwidth. Therefore, network-heavy workloads often benefit from dedicated hosting. As a result, accurate measurement of expected outbound data is essential for estimating total infrastructure costs.

### Storage Behavior and Performance Costs

Storage usage also plays an important role in overall cost. In public cloud environments, pricing is based on the amount of data stored each month. Additional charges apply for provisioned input/output operations (IOPS), snapshots, retention policies, and API requests. As a result, workloads with large datasets, frequent access, or high IOPS requirements can lead to higher monthly expenses.

In contrast, dedicated hosting follows a simpler approach. Storage is usually included in the fixed monthly fee, and performance remains consistent since IOPS are not billed separately. As a result, organizations can plan storage expenses with greater clarity.

### Managed Services versus Self-Managed Infrastructure

Managed services help reduce operational effort, but they also increase overall spending. In public cloud environments, services such as managed databases, container orchestration platforms like [Kubernetes](https://kubernetes.io/), caching systems, and analytics tools are billed separately. Because of this, organizations need to balance the convenience of managed services with the impact on cost predictability.

In contrast, dedicated hosting usually relies on self-managed infrastructure. This approach requires technical expertise and additional staff time to maintain and operate systems. However, it avoids many variable service charges and can lower the total cost of ownership for steady workloads. Hence, the decision between managed and self-managed services depends on whether the priority is operational simplicity or long-term cost control.

### Geographic Distribution

The location of infrastructure also directly affects total cost. In public cloud environments, pricing varies across regions, and deployments spread across multiple locations can increase expenses due to regional price differences and inter-region data transfer charges.

In comparison, dedicated hosting costs remain more stable because servers are typically tied to a single data center unless additional locations are introduced. As a result, organizations running global or multi-region workloads need to account for these geographic factors when estimating overall infrastructure costs.

### Support and Compliance Requirements

Support and compliance needs also contribute to overall spending. In public cloud environments, higher support tiers and compliance-related tools are often billed separately. In comparison, dedicated hosting providers may include these features in the base price or offer them as optional add-ons. As a result, organizations need to account for these costs when evaluating total infrastructure expenses to maintain accurate financial planning.

By considering all these factors, organizations can gain a complete view of total infrastructure costs. Therefore, evaluating these cost drivers alongside billing models supports more precise budgeting and helps align infrastructure decisions with workload needs and financial objectives.

## Cost-Driven Hosting Framework: Evaluating Public Cloud vs Dedicated Hosting

Organizations can use a structured framework to determine which hosting model, whether public cloud or dedicated hosting, is most cost-effective for specific workloads. This framework considers workload characteristics, resource behavior, and financial impact. Following it helps organizations control costs while meeting performance and operational requirements.

The table below summarizes common workload types, the rationale for choosing a hosting model, and recommended actions to estimate costs effectively.

Table 2: Cost-driven comparison based on workload types

| Workload Type | Preferred Model | Rationale | Recommended Actions |
| --- | --- | --- | --- |
| Steady-State, High Utilization | Dedicated Hosting | Cost-effective when resources run near full capacity most of the time. | Compare the monthly cost of a fully utilized cloud instance to that of a dedicated server. Include storage, network, and optional services. Evaluate annual totals. |
| Variable-Demand, Autoscaling | Public Cloud | Scales with usage and avoids idle-resource charges. | Estimate peak and off-peak resource needs. Model monthly cost under autoscaling vs dedicated capacity sized for peak demand. |
| Storage-Heavy or IOPS-Intensive | Dedicated Hosting | Fixed storage and IOPS in the monthly fee; cloud charges are separate. | Quantify storage volume, access frequency, and IOPS. Compare cloud costs with dedicated server limits and overage rules. |
| Short-Lived or Ephemeral | Public Cloud | Billing is based on active runtime, reducing cost for temporary workloads. | Estimate average runtime per task or environment. Compare total monthly cloud runtime costs with the full-month dedicated server fee. |

By using this framework, organizations can match each workload to the hosting model that balances cost efficiency, operational convenience, and performance needs. Evaluating workloads systematically ensures that both short-term expenses and long-term total cost of ownership are considered.

## Atlantic.Net as a Dedicated Hosting Provider with Predictable Costs

[Atlantic.Net](http://www.atlantic.net) offers single-tenant dedicated hosting with a predictable monthly billing model, providing organizations with a stable alternative to the volatile per-minute pricing of public clouds. The platform includes bandwidth allowances and supports HIPAA compliance through an optional BAA. These features help organizations manage spending more accurately while meeting regulatory requirements.

For workloads that handle [electronic Protected Health Information (ePHI)](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) or that run steadily with high outbound traffic, Atlantic.Net’s dedicated hosting minimizes the risk of unexpected charges common in public cloud environments. This enables organizations to manage infrastructure spending accurately while maintaining strong security and compliance standards.

## The Bottom Line

Choosing between public cloud and dedicated hosting requires considering cost, workload patterns, storage and network needs, managed services, and compliance, as these factors influence total infrastructure spending. For example, dedicated hosting provides predictable monthly costs, including bandwidth, and optional compliance tools, which make it suitable for steady workloads, high outbound traffic, or sensitive data.

On the other hand, public cloud offers flexibility and scalability to handle variable-demand workloads, short-term projects, or experimental deployments. Although pay-for-use billing covers only active resources, it can create cost variability that must be monitored. Therefore, the right choice balances performance, finances, operations, and long-term strategy to support growth.

 


---

# Atlantic.Net Earns Multiple ‘Best’ Categories at HostingSeekers Web Hosting Awards 2026

> URL: https://www.atlantic.net/press-releases/atlantic-net-earns-multiple-best-categories-at-hostingseekers-web-hosting-awards-2026/ | Published: 2026-04-09 | Updated: 2026-06-04 | Author: Editorial Team

Orlando, FL (April 9, 2026) Atlantic.Net proudly announces that it has been recognized at the HostingSeekers Web Hosting Awards 2026, earning top honors across multiple key categories.

The company has been awarded Best Web Hosting Company, Best Customer Support, Best Hosting Security, and Best Uptime Performance.

These honors acknowledge Atlantic.Net’s commitment to delivering secure, reliable, and high-performing cloud and hosting solutions while maintaining exceptional support for customers worldwide.

The HostingSeekers Web Hosting Awards are recognized across the hosting industry for their objective, data-driven evaluation process. The awards analyze multiple performance indicators, including infrastructure reliability, customer satisfaction, security standards, and overall service excellence.

“This is a powerful affirmation of our mission,” said Marty Puranik, CEO at Atlantic.Net. “Every award from HostingSeekers underscores our promise: to provide secure, dependable, and innovative hosting so businesses can operate with complete confidence in the digital world.”

With these recognitions, Atlantic.Net continues to strengthen its position as a trusted hosting provider that prioritizes infrastructure stability, advanced security measures, and responsive customer service.

**About Atlantic.Net **

Founded in 1994, [Atlantic.Net](https://www.atlantic.net/) is a privately held global cloud infrastructure provider with customers in over 100 countries, known for delivering secure, compliant, on-demand and customizable hosting solutions. With decades of experience, Atlantic.Net is one of the world’s most trusted and experienced hosting providers, offering 24/7 U.S.-based support. Specializing in security, compliance, and customer service, Atlantic.Net serves a diverse range of industries with solutions including HIPAA-compliant hosting and PCI-compliant hosting, backed by bare metal servers, dedicated hosting, GPU hosting, colocation, and its award-winning Cloud Platform. Operating from eight strategically located data center regions across the United States, Canada, the United Kingdom, and Asia, Atlantic.Net powers mission-critical workloads for organizations worldwide. For more information, visit[ Atlantic.Net](https://www.atlantic.net/) or connect with us on[ Facebook](https://www.facebook.com/Atlantic.Net),[ X (Twitter)](https://twitter.com/AtlanticNet),[ LinkedIn](https://www.linkedin.com/company/atlantic.net-inc./posts/?feedView=all), and[ YouTube](https://www.youtube.com/c/AtlanticNet).

**About HostingSeekers**

HostingSeekers is a trusted global directory connecting businesses with leading web hosting and technology service providers. Through verified listings and transparent performance insights, the platform empowers organizations to make confident, well-informed decisions when choosing hosting companies, development agencies, and digital service partners across the hosting ecosystem.For more information, visit:   [https://www.hostingseekers.com/hostingseekers-web-hosting-awards-2026-winners](https://www.hostingseekers.com/hostingseekers-web-hosting-awards-2026-winners)


---

# High Traffic Hosting

> URL: https://www.atlantic.net/dedicated-server-hosting/high-traffic-hosting/ | Updated: 2026-09-16

Build for heavy traffic, frequent requests, and spikes with dedicated servers, Bare Metal Servers, or Dedicated Cloud Hosts, high bandwidth, SSD or NVMe storage, and 24/7/365 US-based support.

- Dedicated & Single-Tenant
- SSD, NVMe & RAID Options
- 100% Uptime SLA
- 24/7/365 US-Based Support

Outbound Data Transfer: 20 TB

Included Port Speed: 1 Gbps

## High Traffic Hosting from Atlantic.Net

High traffic hosting is for businesses that need unmatched performance and a reliable hosting environment for busy websites, applications, and customer-facing platforms.

Atlantic.Net has over 32 years of industry experience, providing high-traffic hosting solutions for organizations that need more from their web hosting. Whether you run a WordPress site, an e-commerce site, an online store, or a custom application, Atlantic.Net helps you deploy dedicated servers, Bare Metal Servers, and cloud hosting built for excellent performance, high bandwidth, and long-term scalability.

When your website supports revenue, customer access, or critical business operations, your hosting should do more than keep your site online. Top hosting providers help maintain site speed, support traffic spikes, protect performance during peak traffic, and give your team the resources to grow with confidence.

## What Is High Traffic Hosting?

High-traffic hosting is designed for high-volume websites and applications that receive large numbers of visitors, process frequent requests, and experience surges in demand, either continuously or at specific sales periods of the year.

As a site grows, shared hosting often becomes a limitation. More traffic, heavier data transfer, dynamic content, media assets, account activity, and database requests can all put pressure on shared server resources. Having your own server(s) provides a stronger hosting environment, giving your business access to dedicated machines, better server hardware, superfast SSD/NVMe storage, higher bandwidth options, and a platform designed for demanding workloads.

With Atlantic.Net dedicated hosting, you get some of the best value high-traffic hosting for businesses available today. A platform that can handle millions of concurrent requests, features a 100% class-leading uptime SLA, high-speed CPUs from Intel and AMD, and lots of operational flexibility with impactful managed service options.

## High Traffic Hosting Plans

Here is a sample of some of the hosting plans that are a great fit for High Traffic Hosting:

### Plan A, Dedicated Server 3

For established high-traffic websites

Reliable, dedicated performance for established high-traffic websites and mission-critical business-critical applications.

2 x 2.3GHz Xeon Gold 6140

36 cores / 72 threads

128GB DDR4 RAM

4 x 1.92TB RAID10 SSD

20TB transfer on a 1Gbps port

Sale price: $495/month

[Learn More](https://www.atlantic.net/dedicated-server-hosting/)

### Plan B, Bare Metal Server 6

For high performance workloads

High-core AMD EPYC bare-metal servers are built for demanding workloads, database-intensive platforms, and performance-sensitive environments.

2.0GHz AMD EPYC 7702P

64 cores / 128 threads

128GB DDR4 RAM

2 x 960GB NVMe SSD

20TB transfer on a 1Gbps port

Sale price: $709/month

[Learn More](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/)

### Plan C, Dedicated Cloud Host

For flexible growth and multi-instance

Configurable dedicated cloud infrastructure for teams that need dedicated resources with greater flexibility. Custom configuration available.

20–104 cores, 128GB–2TB RAM

Up to 90TB NVMe

Global data centers

Multi-instance capable

ACP console features

Sale price: $266/month

[Learn More](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/)

## High Bandwidth Dedicated Servers

### Built for high-traffic sites

Support high-traffic sites with infrastructure designed to maintain consistent performance during daily usage, seasonal growth, and sudden traffic spikes. SSD is available as standard; NVMe options are available.

### Designed for demanding workloads

From database-driven applications to media-heavy websites and e-commerce platforms, Atlantic.Net helps businesses support demanding workloads with the right mix of compute, storage, and bandwidth.

### Flexible hosting options

Choose from dedicated servers, bare metal, and cloud hosting based on your specific requirements, growth plans, and operational preferences. Pick bare metal for isolated breakneck performance or dedicated cloud servers for easy access to our cloud protection and managed services.

### Better support for growth

Move beyond shared hosting and build a hosting environment that delivers the performance, scalability, and support your business needs for future growth.

## Why Choose Atlantic.Net for High Traffic Hosting?

### High bandwidth and data transfer capacity

High-bandwidth servers are important for websites that serve large media libraries, handle frequent requests, support APIs, handle downloads, or support customer transactions. Atlantic.Net supports high-bandwidth hosting for businesses that need strong throughput and flexible bandwidth options.

### Dedicated resources for consistent performance

Atlantic.Net offers dedicated servers, Bare Metal Servers, and Dedicated Cloud Hosts that provide isolated resources for high-traffic websites and other performance-sensitive deployments. This helps reduce the unpredictability that often affects shared hosting environments.

### Security features and managed service options

Public-facing environments demand more than performance. Atlantic.Net supports your managed hosting environment with security, backups, SSL certificates, monitoring, and managed services to reduce operational overhead, with updates and maintenance available based on your deployment needs.

### Cloud flexibility, where it makes sense

Some workloads are better suited to dedicated infrastructure, while others benefit from cloud hosting scalability. Atlantic.Net helps businesses choose the right platform for growth.

### Fast SSD storage and modern server hardware

Fast SSD storage and NVMe-backed options help improve load times, data access, and overall site speed for websites and applications with demanding workloads.

### 24/7 support from a reliable hosting provider

For business-critical hosting, responsive support matters. Atlantic.Net provides 24/7 support to help customers maintain reliable operations and address issues quickly.

## Dedicated Hosting

Dedicated hosting is ideal for businesses that need predictable performance, isolated resources, and greater control over their server environment.

### Best for:

Established business websites

Larger WordPress site deployments

Customer portals

Content-driven platforms

Custom applications

### Why choose Dedicated Hosting?

Dedicated resources for consistent performance

More control over server configuration

Strong fit for steady daily traffic

Clear upgrade path from shared hosting

## Bare Metal Servers

Bare Metal Servers are designed for businesses that want direct access to dedicated machines and the full benefit of dedicated server hardware for the most demanding workloads.

### Best for:

E-commerce sites with active traffic and transactions

Database-heavy applications

Large websites with high volumes of requests

Resource-intensive platforms

Businesses with strict performance requirements

### Why choose Bare Metal Servers:

Dedicated physical infrastructure

Strong fit for demanding workloads

Predictable performance at peak times

Flexible platform for advanced deployments

## Dedicated Cloud Hosts

Dedicated Cloud Hosts provide dedicated resources with cloud flexibility, making them well-suited to businesses managing growth, seasonal changes, and traffic spikes.

### Best for:

Websites with fluctuating traffic

Product launches and campaigns

Expanding businesses

Hybrid hosting strategies

Teams planning for scalability

### Why choose Dedicated Cloud Hosts:

Dedicated performance with cloud flexibility

Easier scaling as traffic changes

Strong fit for growth-focused environments

More agility than traditional shared hosting

## Key Features

### Dedicated and single-tenant infrastructure

Atlantic.Net offers private physical Dedicated Servers with full root access, while Bare Metal Servers are single-tenant physical servers with direct access to the underlying hardware.

### SSD, NVMe, and RAID storage options

The current plans for Dedicated Server and Bare Metal hosting include SSD-based storage, NVMe SSD on the AMD EPYC configurations, and hardware RAID1 or RAID10 options available across all plans.

### Intel and AMD platform options

We offer both Intel Xeon and AMD EPYC-based Dedicated and Bare Metal platforms. On the bare metal side, AMD EPYC is recommended for computationally intensive tasks, large databases, virtualization, and big data analytics.

### Configurable server builds

Dedicated Servers are custom-built with your choice of CPU, disk, and memory. Bare Metal plans can be deployed from preset configurations or customized around your RAM and disk requirements, with room to upgrade as needs grow.

### 24/7/365 support and audited infrastructure

The Atlantic.Net dedicated infrastructure is monitored 24/7/365 by US-based support personnel, and we offer AICPA SOC 2- and SOC 3-certified facilities. Need HIPAA-Compliant hosting? We excel at healthcare hosting dedicated configurations.

### OS and control flexibility

Dedicated Server plans include support for a wide selection of operating systems and control panel options, plus full root access. Bare Metal Servers allow customers to install the operating system of their choice and configure hardware and software to meet their requirements.

### Managed and unmanaged options

Dedicated Servers are available in managed or unmanaged configurations. You get access to add-ons and managed services, including Managed Firewalls, Intrusion Detection, backups, CDN, Web Application Firewall, and Advanced DDoS Protection. At the same time, the Bare Metal servers can be configured with firewall, intrusion detection, server management, backups, and replication.

### High-bandwidth connectivity

Dedicated Server and Bare Metal plans include 20 TB of outbound data transfer on a 1 Gbps port. Atlantic.Net dedicated hosting is backed by a top-tier network and includes unlimited, unmetered inbound bandwidth. Whether you need this for content delivery, transactional applications, APIs, or data-intensive business systems, Atlantic.Net delivers reliable bandwidth at scale.

## Who Is This For?

Atlantic.Net high traffic hosting is a solid choice for businesses that need stronger web hosting for:

- High traffic websites with growing visitor demand
- WordPress site deployments with plugins, media libraries, and active publishing workflows
- E-commerce and online store platforms with carts, checkout flows, and customer accounts
- SaaS platforms and custom applications with database-intensive workloads
- Content platforms serving high volumes of traffic
- Businesses planning for traffic spikes, campaigns, promotions, or seasonal peak traffic

## Common Use Cases

### WordPress hosting for busy websites

A growing WordPress site can place heavy demands on infrastructure due to plugins, images, page builders, user activity, and database usage. Atlantic.Net helps businesses deploy WordPress hosting environments built for speed, reliability, and easier scaling.

### E-commerce hosting for online stores

An e-commerce site depends on fast load times, dependable checkout performance, and stable backend operations. Atlantic.Net helps businesses support browsing, purchasing, and customer account activity with a stronger hosting foundation.

### Content platforms with heavy visitor demand

For websites serving articles, videos, downloads, or member content, strong infrastructure is crucial for maintaining site speed and user experience as traffic increases.

### Custom applications and web servers

Custom platforms, APIs, and application stacks often require more flexibility than off-the-shelf hosting. Atlantic.Net helps businesses build solutions tailored to their specific requirements, preferred web servers, and workload behavior.

## Why It Matters

When a website outgrows shared hosting, the impact often becomes apparent quickly in site speed, load times, reliability, and user experience. Slow pages, unstable checkout flows, and interruptions during peak traffic can affect revenue, conversions, and customer trust.

A stronger hosting platform helps businesses:

- Improve performance during busy periods
- Maintain consistent performance during traffic spikes
- Better support high-traffic websites and applications
- Reduce operational strain with managed service and support options
- Build an infrastructure foundation that supports scalability and future growth

## Get a Hosting Platform Built for Growth

If your website is outgrowing shared hosting or your current server is struggling to keep up with traffic, Atlantic.Net can help you choose the right high-traffic hosting solution for your business.

Deploy on dedicated servers, Bare Metal Servers, or Dedicated Cloud Hosts with high bandwidth, SSD storage, security features, and 24/7 support from a reliable hosting provider.

## FAQ

### What is high traffic hosting?

High-traffic hosting is web hosting designed for websites and applications that receive significant traffic, process frequent requests, or require dependable performance during peak times.

### When should I move beyond shared hosting?

You should consider moving beyond shared hosting when your site slows down during busy periods, traffic spikes affect stability, or you need more control over your hosting environment.

### Are dedicated servers a good fit for high-traffic websites?

Yes. Dedicated servers are often a strong fit for high-traffic websites because they provide isolated resources, more predictable performance, and greater control over the environment.

### Is cloud hosting a good option for high-traffic workloads?

Cloud hosting can be a good fit when workloads change over time or when scalability is important. Dedicated cloud environments can offer greater flexibility while maintaining strong performance.

### Do I need high-bandwidth servers for my website?

If your website handles frequent requests, large files, media delivery, or significant data transfers, high-bandwidth servers may be the right fit. Look for unlimited bandwidth or unmetered bandwidth if your site is media-heavy.

### Does Atlantic.Net support WordPress and e-commerce hosting?

Yes. Atlantic.Net supports WordPress site deployments, e-commerce platforms, online stores, and custom applications with infrastructure designed for performance and growth.

### Does Atlantic.Net offer managed service options?

Yes. Managed service options offer advanced tools to reduce the burden of performance monitoring, updates, maintenance, and ongoing infrastructure operations.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Architecting a High-Performance Private Cloud for Enterprise Applications

> URL: https://www.atlantic.net/dedicated-server-hosting/high-performance-private-cloud-enterprise-applications/ | Published: 2026-04-13 | Updated: 2026-06-24 | Author: Dr. Tehseen Zia

For years, many people believed that [public cloud](https://www.atlantic.net/vps-hosting/cloud-public-private-somewhere/) was widely presented as the default solution for modern enterprise applications. This was because it promised unlimited scalability, no hardware maintenance, and a pay-as-you-go model that aligned well with modern business needs. However, many organizations that rely on enterprise applications are beginning to find problems with this promise.

Complex tasks like large-scale databases, custom [ERP systems](https://www.sap.com/mena/resources/what-is-erp), and real-time analytics can suffer in shared environments when performance isolation is insufficient or when traffic and egress patterns make costs unpredictable. The challenges typically stem from resource contention caused by noisy neighbors, leading to inconsistent performance and unpredictable latency, as well as rising cloud costs driven by increased [data egress](https://www.fortinet.com/resources/cyberglossary/data-egress) and API usage. What once seemed like a path to agility can become a limitation on both performance and budget.

This has led organizations to return to private cloud infrastructure gradually. A private cloud can provide a cloud-like operating model when built with [virtualization](https://www.atlantic.net/vps-hosting/what-is-server-virtualization/), automation, and self-service, with on-demand resources and scalability, while also delivering performance, security, and predictability that enterprise applications need. Building this environment requires a focus on the fundamentals. It involves making careful choices about hardware, storage, networking, and orchestration. When designed properly, a high-performance private cloud provides more than just infrastructure; it becomes a competitive advantage.

## Defining the Problem: Why Enterprise Applications Need More

Before discussing architecture, it is useful to understand why enterprise applications are particularly sensitive to infrastructure design.

Most enterprise applications are [stateful](https://www.certbolt.com/certification/understanding-stateful-and-stateless-applications-in-cloud-architecture/). They rely on consistent input/output operations per second ([IOPS](https://www.atlantic.net/vps-hosting/performance-matters-how-disk-throughput-and-iops-impact-your-business/)), low-latency storage, and predictable network performance. A sudden increase in storage latency by even a few milliseconds can lead to database replication issues. A congested network can disrupt [application clustering](https://docs.myq-solution.com/en/ovv/i/high-availability-with-application-clustering). In a public cloud setting, these variables are often out of your control. You share physical hardware with other users, and storage performance can vary depending on the activities of accounts you cannot monitor. This variability is usually acceptable for development environments and stateless web applications. However, for systems that support core business functions such as order management, financial processing, and supply chain logistics, unpredictability poses a risk.

A private cloud [addresses](https://www.mirantis.com/blog/advantages-private-clouds-for-enterprise-businesses/) this issue by providing dedicated resources and complete control over the infrastructure. You can define performance standards and build an environment where the infrastructure adapts to the application, rather than forcing the application to work with existing infrastructure.

## The Foundation: Compute with Purpose

Designing architecture for high-performance enterprise applications begins at the physical compute layer. In a [private cloud](https://www.atlantic.net/private-cloud-hosting/what-is-private-cloud-hosting/), every server belongs to you. This approach enables you to customize hardware specifications to the specific needs of your applications, rather than relying on generic, one-size-fits-all instances.

The most important decision is balancing core density with clock speed. Enterprise applications use performance in different ways. A [virtualized SAP environment](https://www.all-for-one.pl/en/whitepapers/virtualization-of-sap-environment-in-vmware/) with hundreds of concurrent users often needs more cores to manage many threads. Meanwhile, an Oracle database running complex queries may perform better with fewer cores operating at higher speeds to reduce single-thread latency.

When setting up compute nodes, it is useful to avoid the temptation to standardize on a single server configuration. A well-designed private cloud typically includes multiple node types. You might deploy high-frequency nodes for database tasks, high-memory nodes for caching systems like [Redis or Memcached](https://www.geeksforgeeks.org/dbms/difference-between-redis-and-memcached/), and dense storage nodes for data storage.

It is also important to ensure the [hypervisor layer](https://www.vmware.com/topics/hypervisor) has a proper size. Overprovisioning CPU cores is a common mistake that can lead to CPU ready times and degrade overall performance. Maintaining a conservative allocation ratio ensures that virtual machines receive the CPU cycles they require when needed.

For organizations using Atlantic.net private [cloud solutions](https://www.atlantic.net/dedicated-server-hosting/), this hardware selection process is carefully conducted. We prioritize enterprise-grade components, such as Intel Xeon or AMD EPYC processors, with configurations tailored to clients’ specific workloads. The goal is to prevent resource conflicts before they occur.

## Storage Architecture: The Critical Bottleneck

Storage is often the weakest link in private cloud performance. It is also where architectural choices have the most significant impact.

Centralized storage can add network overhead, but modern SANs can still be high-performance when properly designed. Storage traffic traverses the network to a centralized array, creating potential bottlenecks and complicating troubleshooting. For high-performance needs, this setup is increasingly being replaced by software-defined storage and hyperconverged solutions.

The best practice for performance-sensitive workloads is to use [NVMe](https://www.atlantic.net/dedicated-server-hosting/nvme-ssds-dedicated-hosting-performance-latency/) (Non-Volatile Memory Express) solid-state drives. NVMe delivers much lower latency and higher throughput than [SATA](https://www.lenovo.com/gb/en/glossary/sata-ssds/?srsltid=AfmBOoo41qMbccZcp7KQwGDILa7rwVDxbPWsv1OH3WXHQuTCpQo1OG5n) or SAS [SSDs](https://www.atlantic.net/dedicated-server-hosting/whats-the-difference-between-hdds-sata-ssds-and-nvme-ssds/). When combined with a modern storage fabric like NVMe over Fabrics, you can achieve storage performance similar to local direct-attached storage while gaining the benefits of shared storage.

For enterprise databases, a [tiered storage strategy](https://www.techtarget.com/searchstorage/definition/tiered-storage) is useful. This means placing active transaction logs and frequently accessed data on the fastest NVMe tier, while moving less active data to high-capacity SSDs or spinning disks. This strategy balances cost and performance without compromise.

Data replication and protection also affect performance. Synchronous replication ensures data consistency but adds latency. Asynchronous replication boosts performance but risks data loss during failover. The best choice depends on the application’s tolerance for recovery point objectives.

At [Atlantic.net](https://www.atlantic.net/announcements/atlantic-net-launches-next-generation-secure-block-storage-stability-security-and-scalability-without-the-guesswork/), we take these factors into account when building a storage system for a private cloud. We use all-flash NVMe storage for performance-critical workloads and offer flexible replication models to help clients balance data protection and performance needs. This approach leads to a storage infrastructure that operates reliably under load.

## Networking: Building for Low Latency and High Throughput

Networking in a private cloud is often overlooked until it becomes a problem. Enterprise applications generate significant communication between servers within the data center. This communication can overwhelm overloaded links.

The architecture should be built on a leaf-spine topology. This design ensures that any server can communicate with any other server with a consistent number of hops and predictable latency. It avoids the bottlenecks of traditional [three-tier network](https://intelligentvisibility.com/spine-leaf-network-architecture) designs, where traffic had to pass through a core switch and back.

For virtualized environments, it is vital to consider the networking overhead introduced by the hypervisor. Using [Single Root I/O Virtualization (SR-IOV)](https://learn.microsoft.com/en-us/windows-hardware/drivers/network/overview-of-single-root-i-o-virtualization--sr-iov-) allows virtual machines to bypass the hypervisor’s virtual switch and connect directly to physical network interfaces. This reduces latency and CPU load, which is especially helpful for applications sensitive to network delays.

[Network segmentation](https://www.cisco.com/site/us/en/learn/topics/security/what-is-network-segmentation.html) is also vital for performance. It is useful to separate storage, management, and application traffic across different VLANs or physical interfaces. When these traffic types compete for bandwidth, performance can drop unexpectedly. Proper traffic segmentation ensures that a spike in application traffic does not interfere with storage operations.

## Resilience and High Availability: Designing for Failure

High performance is meaningless if the system is not resilient. A well-architected private cloud assumes that hardware components will fail and plans accordingly. High availability should be ensured at all levels.

Compute nodes should form clusters with live migration capabilities, allowing virtual machines to move between physical hosts during maintenance or failure. Storage must be replicated across multiple fault domains. Network links should have redundancy with automated failover. But resilience is more than just taking hardware backups. It requires careful management of failure domains. Positioning all storage replicas on the same power distribution unit creates a single point of failure. Distributing replicas across different racks or even separate data center zones ensures that a localized issue does not lead to a complete system outage.

Backup and [disaster recovery](https://www.atlantic.net/disaster-recovery/disaster-recovery-plan/) are equally important. A high-performance private cloud should implement a backup strategy that meets recovery-point and recovery-time objectives. For enterprises, this often involves replicating critical workloads to a facility in a different location. Atlantic.net’s private cloud solutions are designed with this layered resilience. We operate multiple data center locations, and we design client environments with clear failure boundaries.

## Orchestration and Management: Bringing It All Together

The hardware is only part of the equation. A private cloud needs effective management to deliver on its promise.

The [orchestration layer](https://www.vmware.com/topics/cloud-orchestration) should provide self-service features without adding complexity. Your team should be able to provision resources, scale workloads, and monitor performance through a single interface. Automation plays a vital role. Manual processes can delay tasks and increase the risk of misconfigurations.

Monitoring is especially critical in a high-performance setting. You need detailed insights into CPU usage, storage latency, network throughput, and application performance. This information not only helps you detect issues before they affect users but also helps you plan capacity.

At Atlantic.net, we adopt a [managed approach](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/) to orchestration. Our private cloud solutions include proactive monitoring and management. We do not just provide hardware and leave it to you. Our engineers monitor client environments, manage the hypervisor layer, and provide optimization advice. This allows internal IT teams to focus on applications and business outcomes rather than on infrastructure maintenance.

## The Bottom Line

Architecting a high-performance private cloud for an enterprise application requires making the right decisions at every layer. From compute and storage to networking and orchestration, each component must be aligned with the specific demands of enterprise applications. Precision in design leads to consistency in performance. For organizations running critical workloads, a well-architected private cloud can deliver predictable performance, stronger cost control, and complete operational visibility. It removes the uncertainty of shared environments and replaces it with infrastructure that behaves reliably under heavy load.


---

# Top AI Video Editing Platforms of 2026: Choosing the Right Tool

> URL: https://www.atlantic.net/gpu-server-hosting/top-ai-video-editing-platforms-choosing-the-right-tool/ | Published: 2026-04-14 | Updated: 2026-04-15 | Author: Dr. Tehseen Zia

AI video editing now covers far more than filters or automated trims. By 2026, leading platforms will support generative scene creation, prompt-based b-roll insertion, automated captions, and voice-driven edits across long- and short-form video. Modern ai video generator platforms now combine text to video, image to video creation, and audio generation to create high quality videos with minimal manual effort. Professional editors, marketing teams, and media studios use these tools to reduce hands-on editing time by more than 60% while producing higher volumes of consistent content. This guide reviews the 10 best AI video editing platforms of 2026, comparing them based on speed, output quality, and the level of creative control they offer editors. It also reflects how ai video generation and ai models are reshaping video creation workflows across marketing videos, training videos, and social media clips. Real production use cases, including avatar-led corporate video, social content, and cinematic or generative video workflows, are evaluated for each tool.

## The 10 Best AI Video Editing Platforms of 2026

### Top AI Video Editing Platforms for Avatar and Corporate Content

These tools are designed for fast, repeatable video creation using scripts, AI avatars, and voice narration. They are commonly used for training, sales, internal communication, and product explainers, where clarity and speed matter more than visual effects. Many of these platforms act as AI video generator free or freemium tools, offering a few free credits to help teams generate videos quickly.

### HeyGen

![](https://www.atlantic.net/wp-content/uploads/2026/02/heygen.png)

**HeyGen** is an AI video platform that lets teams create professional presenter videos using avatars and scripts. There’s no need for cameras, studios, or live speakers, which makes it popular for business communication and training. Teams write a script, pick an AI avatar and voice, and export their video in minutes.

HeyGen supports multiple languages and keeps presentations on-brand, making it helpful for teams sharing the same message in different regions. Since everything is script-based, updates are quick and don’t require re-recording, so marketing and HR teams can easily keep videos up to date.

It is widely considered one of the best AI video tools for creating AI videos with consistent avatars, AI voiceover, and polished video output for enterprise use cases.

Create studio-quality avatar videos with HeyGen, turn scripts into engaging, AI-generated content using realistic voices and lifelike presenters.
 ![HeyGen](https://www.atlantic.net/wp-content/uploads/2026/02/HeyGen.jpg)
 Image Source: HeyGen

**Best For:** Sales videos, employee training, product explainers, and multilingual corporate communication at scale.

### Adobe Premiere Pro

![](https://www.atlantic.net/wp-content/uploads/2026/02/Adobe_Premiere_Pro_CC_.png)

Adobe Premiere Pro has integrated several AI features to speed up editing without significantly changing existing workflows. Features like Generative Extend add frames and extend clips, while object removal simplifies complex edits. AI also automates color correction, audio cleanup, and subtitle generation. The transcription tool makes subtitles easy, and audio ducking balances dialogue with background sound.

However, Premiere Pro remains expensive for independent creators, and beginners may find the learning curve steep. Since the AI tools require a Creative Cloud subscription, access can be limited. Still, Premiere Pro is a benchmark for professional video editing. It is especially well-suited for filmmakers, creative studios, and content teams that need precise control over every detail of their work.

Its integration with Creative Cloud and evolving AI video editor capabilities makes it a strong choice for creating cinematic videos with advanced camera control, audio integration, and visual style customization.

Edit and produce professional videos with Adobe Premiere Pro, organize media, refine timelines, and apply advanced effects with precision and control.
 ![Adobe Premiere Pro](https://www.atlantic.net/wp-content/uploads/2026/02/Adobe-Premiere-Pro.jpg)
 Image Source: Adobe Premiere Pro

**Best For:** Professional editors and creative teams working on long-form, branded, or cinematic videos that need detailed timeline control and AI support.

### Descript

![](https://www.atlantic.net/wp-content/uploads/2026/02/descript.png)

Descript reimagines editing by treating video like text. Users edit the transcript, and the video changes automatically. Delete a line of text, and the video clip disappears.

Key features include voice cloning, filler-word removal, and scene transitions. Collaboration tools allow teams to leave comments directly on the timeline. Its low learning curve makes it ideal for podcasts, interviews, and educational content.

However, Descript is less suited for cinematic or complex edits. While powerful, voice cloning also raises ethical concerns, so users should apply it carefully.

Descript is useful for generating AI videos from transcripts and quickly turning long-form content into engaging videos or social media clips.

Edit audio and video like a doc with Descript, transcribe, cut, and enhance your content using powerful AI-driven tools.
 ![Descript](https://www.atlantic.net/wp-content/uploads/2026/02/Descript.jpg)
 Image Source: Descript

**Best For:** Editing podcasts, interviews, webinars, and talking-head videos where the main focus is on spoken content.

### Filmora

![](https://www.atlantic.net/wp-content/uploads/2026/02/filmora.png)

Filmora emphasizes simplicity while offering creative effects. Its Beat Detection feature helps sync edits with music, and its AI tools include scene detection, smart cropping, and mood-based music recommendations. Motion tracking lets text or graphics follow moving objects.

Filmora is affordable and beginner-friendly, making it a popular choice for small businesses. However, it struggles with large projects and high-resolution footage. For users who want fine control, its automation may feel restrictive.

It is often considered the best AI video generator option for beginners who want to create videos quickly using templates, background music, and automated video editing features.

Create polished videos with Filmora, edit timelines, add effects, and apply ready-made templates to bring your stories to life quickly.
 ![Filmora](https://www.atlantic.net/wp-content/uploads/2026/02/Filmora.jpg)
 Image Source: Filmora

**Best For:** Beginners and small teams who want easy AI-assisted editing for short videos, tutorials, and social content, without a tough learning curve.

### InVideo AI

![](https://www.atlantic.net/wp-content/uploads/2026/02/InVideo.png)

InVideo AI is designed for quick, social-media-friendly editing. It enables users to make changes with simple commands and includes templates built for platforms like TikTok, Instagram, and YouTube. AI recommends stock footage, music, and text overlays to match themes. Voice generation and automatic resizing adjust videos to different aspect ratios, while collaboration tools help teams coordinate campaigns and track progress.

The platform works well for marketing teams producing high volumes of short videos. The drawback is heavy reliance on templates, which can lead to repetitive styles. Skilled editors may find its flexibility limited. This tool is widely used for generating AI videos for promo videos, marketing videos, and scalable content production across multiple platforms.

Create videos in minutes with InVideo AI, turn ideas into ready-to-publish content using automated scripts, visuals, and voiceovers.
 ![InVideo AI](https://www.atlantic.net/wp-content/uploads/2026/02/InVideo-AI.jpg)
 Image Source: InVideo AI

**Best For:** Quickly making promotional and social media videos using text commands and ready-made layouts.

### Pictory

![](https://www.atlantic.net/wp-content/uploads/2026/02/pictory.png)

Pictory is designed to turn existing written material into videos. Users can input blog posts, articles, or scripts, and Pictory generates complete videos with relevant visuals, voiceovers, and music. AI understands the content’s context well enough to select appropriate stock footage and images. The automatic summarization feature extracts key points from longer texts and creates concise video versions. The brand customization options help maintain a consistent visual identity across multiple videos.

The downside is limited flexibility for abstract or highly creative projects. Users who need full storytelling control may find the automation restrictive. Pictory is a powerful AI video tool for text-to-video workflows, helping users efficiently create AI-generated and explainer videos from blogs and other written content.

Turn scripts, blogs, or URLs into engaging videos with Pictory, automatically generate visuals, captions, and voiceovers in minutes.
 ![Pictory](https://www.atlantic.net/wp-content/uploads/2026/02/Pictory.jpg)
 Image Source: Pictory

**Best For:** Quickly turning scripts, blog posts, or written marketing content into short, narrated videos with little manual editing needed.

### Top AI Video Editing Platforms for Cinematic and Generative Video Creation

These platforms are built for visual storytelling, motion, and prompt-based video generation. They are used to create cinematic clips, concept scenes, and creative videos where style, pacing, and scene control matter more than presenter-led output or templates. They often rely on advanced ai video models such as Google Veo or similar video model systems to generate realistic videos with cinematic motion and dynamic camera movement.

### DaVinci Resolve Studio

![](https://www.atlantic.net/wp-content/uploads/2026/02/DaVinci_Resolve_Studio.png)

DaVinci Resolve offers a range of professional tools commonly used in high-end film and television production. Its Music Remixer feature enables users to separate different parts of a song, such as vocals, bass, guitar, and drums. This gives users the flexibility to adjust or mute instruments and create a mix that fits their video perfectly.

Another key feature is the Relight tool, which uses AI to adjust lighting during post-production. It can add virtual light sources, change shadows, and even alter the overall mood of a scene without the need for reshooting. DaVinci Resolve is particularly well-suited for cinematic work, advanced color grading, and for professionals who want reliable editing features without paying ongoing subscription fees.

It is also widely used to enhance videos and refine cinematic style projects that require high video quality and precise creative control.

Edit, color grade, and finish like a pro with DaVinci Resolve Studio, combine advanced editing, VFX, and audio tools in one powerful platform.
 ![DaVinci Resolve Studio](https://www.atlantic.net/wp-content/uploads/2026/02/DaVinci-Resolve-Studio.jpg)
 Image Source: DaVinci Resolve Studio

**Best For:** Professional editors and filmmakers who need advanced color grading, audio tools, and AI-assisted features within a full post-production workflow

### VEED.IO

![](https://www.atlantic.net/wp-content/uploads/2026/02/veedio-logo.png)

 [VEED.IO](https://www.veed.io/tools/ai-video/ai-video-editor) is an AI-powered online video editing platform designed to simplify content creation for individuals and teams. It integrates AI tools such as text-to-video generation, automatic subtitle creation, background noise removal, eye contact correction, and one-click translations to streamline production workflows. Since VEED is a browser-based editor, it eliminates the need for downloads, making it easy to edit and export videos quickly.

However, VEED may not offer the same level of frame-by-frame control or advanced compositing tools found in high-end desktop software. Complex cinematic workflows or highly technical post-production projects may require more specialized platforms. Still, VEED stands out for marketers, educators, startups, and content teams that need to quickly generate videos from text, collaboratively and without a steep learning curve.

Produce professional videos with VEED.IO, combining editing, screen recording, and AI tools in one easy-to-use platform.
 ![VEED.IO](https://www.atlantic.net/wp-content/uploads/2026/02/VEED.IO_.jpg)
 Image Source: VEED.AI

**Best for:** Improving accessibility with built-in transcription and subtitling tools, and for quick talking-head videos with AI Avatar and AI text-to-video.

### Luma Dream Machine

![](https://www.atlantic.net/wp-content/uploads/2026/02/dream-machine-luma.jpg)

**Luma Dream Machine** is a video tool that creates realistic motion and maintains scene consistency. It makes short video clips from text or image prompts, with smooth camera moves and natural-looking scenes.

People often use this platform for visual concepts, product shots, and cinematic sequences where realistic motion and camera work are important. It’s a good choice for creators who want natural movement without hand animation.

This platform excels in image-to-video workflows, generating AI videos with smooth motion, camera choreography, and consistent visual style across complex scenes.

Let’s explore Luma Dream Machine, turn your ideas into stunning AI-generated videos and visuals with simple prompts and cinematic results.
 ![Luma Dream Machine](https://www.atlantic.net/wp-content/uploads/2026/02/Luma-Dream-Machine.jpg)
 Image Source: Luma Dream Machine

**Best For:** Making realistic, cinematic video clips with smooth camera movement and consistent scenes.

### Sora (OpenAI)

![](https://www.atlantic.net/wp-content/uploads/2026/02/sora.png)

**Sora** is a text-to-video tool that generates longer, more complex video scenes from written prompts. It keeps scenes consistent, characters behaving naturally, and the visuals realistic throughout longer clips.

This tool is used for story-driven ideas, pre-visualization, and experimental video projects. It’s best for creative exploration, not for traditional editing tasks.

Let’s explore Sora, generate cinematic videos from simple prompts and bring your imagination to life with stunning realism.
 ![Sora (OpenAI)](https://www.atlantic.net/wp-content/uploads/2026/02/Sora-OpenAI.jpg)
 Image Source: Sora

**Best For:** Creating story-based and cinematic videos where you need consistent scenes and a clear narrative.

## Compare the Top 10 AI Video Tools

| **Software** | **Best Use Case** | **Pricing Model** | **Key AI Feature** |
| --- | --- | --- | --- |
| **1. HeyGen** | Corporate Training/Sales | Subscription (Credits) | AI Avatar Translation |
| **2. Adobe Premiere** | Pro Video Editing | Monthly Subscription | Generative Extend |
| **3. Descript** | Podcasts & Docs | Freemium / Sub | Text-Based Editing |
| **4. Filmora** | Creators/Social | Perpetual / Sub | Smart Cutout / Beat Sync |
| **5. InVideo AI** | Marketing Promos | Freemium / Sub | Prompt-to-Video |
| **6. Pictory** | Blog-to-Video | Subscription | Auto-Summarization |
| **7. DaVinci Resolve** | Cinematic Color/Audio | Free / One-time License | Neural Engine / Voice Isolation |
| **8. VEED.IO** |  Creators/Social/Marketers | Freemium / Sub | Text to Video AI, Multiple AI Video Models |
| **9. Luma Dream Machine** | 3D/Motion Clips | Credit-based | Ray 2 Model |
| **10. OpenAI Sora** | High-End Generation | Restricted/Enterprise | Text-to-Video Simulation |

## Key Considerations for Platform Selection

The best platform depends on your goals and workflow. Start by considering the type of content you produce. For example, Descript works well for talking-head videos, while tools like InVideo AI are better suited for short-form social media clips.

Budget is another important factor. Pricing varies widely across platforms, so it is important to align costs with your available resources.

Technical requirements also matter. Some platforms run locally and require powerful computers, while others rely on cloud processing and a stable internet connection. Team size also matters as certain platforms are designed with collaboration in mind, while others cater to solo creators.

Finally, consider your long-term strategy. Platforms built around current social trends may lose relevance as algorithms change. Professional software like Adobe Premiere Pro offers greater stability but requires a greater investment of time and money.

## Key Technical Considerations for 2026

Before integrating a new system, verify these technical requirements to avoid “tool sprawl” and security risks:

- **Data Residency:** If you handle sensitive corporate or HIPAA-compliant data, ensure the vendor uses local, secure hosting. Atlantic.Net provides specialized infrastructure for these high-security needs.
- **API and Pipeline Integration:** Avoid “islands” of content. Choose tools that can ingest data from your existing storage (like Dropbox or S3) and export directly to your publishing or review platforms (like Frame.io).
- **Credit Forensics:** Most 2026 tools use credit-based pricing. Track these the same way you track ad spend. A single experimental afternoon can burn a monthly budget if you do not set usage limits at the team level.
- **Model Consistency:** AI models are updated frequently. A prompt that worked in January might yield different colors or styles in June. Save “reference frames” and “style recipes” to maintain a consistent visual baseline over time.

## The Bottom Line

AI video editing tools are reshaping how content is created and shared. From high-end platforms like HeyGen, Premiere Pro, and DaVinci Resolve to quick solutions like InVideo AI, each tool has unique strengths. The best choice depends on your budget, team, and creative needs. As AI technology continues to evolve in 2026, businesses and creators can use these AI tools to create high-quality videos, scale video creation, and stay ahead in a rapidly changing digital landscape. By understanding these options, creators and organizations can select the right platform to produce engaging, professional-quality videos that meet both current and future demands.

## FAQ

**What’s the best AI video editor for professional timeline work?**

Adobe Premiere Pro and DaVinci Resolve Studio fit best when you need deep timeline control and finishing. Premiere’s Generative Extend addresses specific edge cases, while Resolve bundles edit, grade, VFX, and audio into one suite.

**Which tool is best for editing video by editing text?**

Descript is built around transcript-first editing. It also layers in AI tools for cleanup and repurposing (like removing filler words and generating clips) tied to plan tiers.

**Are AI avatar videos a good fit for corporate teams?**

Yes—when you need consistent messaging and frequent updates. HeyGen publishes clear plan limits and includes business features like SSO on higher tiers, which matters for company rollouts.

**Can these tools generate b-roll or scenes from prompts?**

Runway, Luma Dream Machine, and Sora 2 focus on prompt-generated video, with Runway emphasizing consistency and controllability. Treat them as “shot generators” and assemble the final piece in an editor.

**Do these platforms support 4K export?**

Some do, but it depends on the tier. For example, HeyGen lists 4K export on higher plans, and Descript lists 4K export on its Creator plan at the time of access. Always confirm export caps before standardizing.

**How should teams think about copyright and safe usage?**

Start with the vendor’s documentation on generation limits and constraints, then align on internal rules for voice/likeness use, brand safety review, and what qualifies for commercial release. For example, Adobe documents constraints around Generative Extend, and OpenAI describes Sora 2’s capability scope.

**Should you choose cloud tools or desktop editors?**

Cloud tools win on speed and collaboration. Desktop editors win on control, performance tuning, and finishing depth. Many teams use both: generate drafts in the cloud, and finish in a pro NLE.

Content updated: April 14, 2026


---

# Top Dedicated Hosting Services for Optimal Performance and Reliability (2026)

> URL: https://www.atlantic.net/dedicated-server-hosting/top-dedicated-hosting-services-for-optimal-performance-and-reliability/ | Published: 2026-04-14 | Updated: 2026-05-04 | Author: Dr. Assad Abbas

For 2026, the best dedicated hosting services allow you to isolate workloads for maximum security, compliance, and raw compute power.

Modern dedicated server hosting now emphasizes automation, real-time server monitoring, and hybrid integration with cloud hosting environments for better scalability and resilience.

Atlantic.Net is our top choice for regulated industries requiring compliant hosting and a 100% Uptime SLA. IONOS remains a standard for budget-conscious deployments, while PhoenixNAP and Hosting.com (formerly A2 Hosting) serve DevOps and speed-focused users, respectively.

When choosing a provider, prioritize NVMe storage, unmetered bandwidth, and verified compliance certifications (SOC 2/SOC 3) over introductory pricing. Dedicated hosting gives you exclusive access to a physical server’s resources—CPU, memory, storage, and network—so performance stays predictable under load.

Today’s best managed dedicated servers also include advanced management tools, proactive security service layers, and optional managed hosting services to reduce server management tasks.

The “best” dedicated host depends on your specific needs: compliance and audited controls, low-friction management, or maximum configuration control. Use a short checklist: confirm the uptime commitment, understand the bandwidth policy, choose storage (NVMe/SSD) and ECC memory for stability, and decide whether you want managed support or full root access.

## Why Use Dedicated Hosting?

Dedicated hosting is the preferred choice when you require stable performance, total isolation, or granular control. It is especially critical for high traffic websites, enterprise applications, and businesses that need guaranteed dedicated resources without performance interference.

- **Predictable performance:** Choose a provider that eliminates “noisy neighbor” issues by ensuring no shared tenant contention for physical resources.
- **Administrative control: You maintain full authority over the OS, software stack, and security hardening choices.**
- **Security posture:** Physical isolation reduces cross-tenant risks and allows for stricter access controls.
- **Scaling paths:** You can expand capacity by upgrading hardware or deploying multiple dedicated nodes behind a load balancer.

Unlike shared hosting or VPS hosting, dedicated server hosting ensures consistent throughput, reliable performance, and complete control over server configurations.

## Feature Comparison Table (2026 Edition)

| **Provider** | **Best for** | **Management options** | **Uptime commitment** | **Bandwidth approach** | **Notable verification point** |
| --- | --- | --- | --- | --- | --- |
| Atlantic.Net | Compliance-forward and mission-critical workloads | Managed and dedicated options available | 100% Uptime SLA (critical infrastructure; excludes scheduled maintenance) ([Atlantic.Net](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/)) | Plan/contract dependent | 100% uptime SLA terms ([Atlantic.Net](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/)) |
| Namecheap | Budget entry points to dedicated | Management depends on plan (incl. user-responsible options) | Uptime guarantee page states 99.9 monthly guarantee covers dedicated server accounts (review exceptions) ([Namecheap](https://www.namecheap.com/legal/hosting/uptime-guarantee/)) | Varies by configuration | Uptime guarantee includes dedicated accounts ([Namecheap](https://www.namecheap.com/legal/hosting/)) |
| HostGator | Guided setup + common control panels | Managed positioning on dedicated page | 99.9% uptime guarantee | Policy states unmetered for dedicated plans ([HostGator](https://www.hostgator.com/dedicated-server)) | guided setup + OS choice + 99.9% ([HostGator](https://www.hostgator.com/dedicated-server)) |
| IONOS | UK buyers prioritizing facility certification signals | Varies by product | Not consistently stated on the dedicated page | Varies | Dedicated servers page references ISO 27001 certification for UK data centres ([IONOS](https://www.ionos.co.uk/servers/dedicated-servers)) |
| Hostwinds | Hands-on teams wanting out-of-band management | Managed and unmanaged | Varies by plan | Varies | IPMI access and 24/7/365 assistance messaging (Hostwinds) |
| Hosting.com (formerly A2 Hosting) | Managed dedicated with an uptime commitment | Sales-led config | 99.9% uptime commitment (service credit framing for unscheduled downtime) ([hosting.com](https://hosting.com/about/99-9-uptime-commitment/)) | Not clearly standardized | uptime commitment ([hosting.com](https://hosting.com/dedicated-servers/)) |
| AccuWeb Hosting | Custom builds + “guaranteed network uptime” positioning | Varies by plan | Markets guaranteed network uptime (confirm SLA/credit terms for your plan) ([accuwebhosting.com](https://www.accuwebhosting.com/dedicated-servers)) | Varies | guaranteed network uptime ([accuwebhosting.com](https://www.accuwebhosting.com/dedicated-servers)) |
| phoenixNAP | API-driven provisioning + DevOps workflows | Self-service, automation-first | n/a | n/a | Dedicated servers page lists API/CLI/WebUI/IPMI control + hourly/monthly billing ([phoenixNAP \| Global IT Services](https://phoenixnap.com/dedicated-servers)) |

## Top Dedicated Hosting Services Reviewed

## #1. Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

**Best for compliance-ready dedicated hosting**

Atlantic.Net positions its dedicated hosting around uptime commitments, audited controls, and regional deployments for latency and data residency needs. A popular choice for sensitive workloads (healthcare, finance) or when downtime risk is expensive.

Below is Atlantic.Net’s cloud control panel interface used to deploy and manage dedicated and GPU servers.
 ![Atlantic.Net Server Panel](https://www.atlantic.net/wp-content/uploads/2026/01/Atlantic.net-server-panel.png)
 Image Source: Atlantic.Net

Their managed dedicated hosting offering includes server maintenance, security hardening, and continuous server monitoring handled by a dedicated team. Varies by configuration (dedicated server offerings are customized) Compliance-focused posture with audited programs 24/7/365 positioning is part of Atlantic.Net’s service model If you need dedicated resources plus a compliance-forward provider story, Atlantic.Net is a strong fit—especially when the SLA and audit posture matter as much as raw specs.

**Key Specs:** Varies by configuration (dedicated server offerings are customized)
 **Compliance:** Compliance-focused posture with audited programs
 **Support:** 24/7/365 positioning is part of Atlantic.Net’s service model

**Verdict:** If you need dedicated resources plus a compliance-forward provider story, Atlantic.Net is a strong fit—especially when the SLA and audit posture matter as much as raw specs.

**What stands out:**

- 100% Uptime SLA covering network, hardware, and infrastructure.
- Compliance-oriented posture with audited SOC 2 and SOC 3 reports.
- Multiple data center regions to reduce latency and support residency requirements

**Who should choose Atlantic.Net?** Teams running regulated or business-critical systems that need an SLA and documented controls.

## #2. Namecheap

![](https://www.atlantic.net/wp-content/uploads/2026/01/NameCheap-Logo.png)

**Best for budget-friendly dedicated options**

Namecheap is widely known for domains, but its dedicated server catalog appeals to buyers who want dedicated hardware without enterprise overhead. It’s a common choice for smaller teams that can self-manage or selectively add management.

This makes it a trusted hosting company for those seeking unmanaged dedicated server options with optional upgrades to managed dedicated server hosting.

Let’s see the Namecheap dedicated hosting interface used to manage domains, deploy servers, and control hosting services from one place.

![Namecheap dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Namecheap-dashboard.jpg)

Image Source: NameCheap

**Key Specs:** Dedicated server configurations vary (including NVMe/SSD options)
 **Compliance:** Not typically positioned as a compliance-first vendor
 **Support:** The support model depends on the management tier

**Verdict:** Choose Namecheap if you want a straightforward dedicated server purchase path, and your team can handle most sysadmin tasks

**What stands out:**

- Broad dedicated configuration list (review storage and CPU options per plan)
- Uptime guarantee explicitly includes dedicated server accounts
- Multiple management tiers so you can pay for the level of help you need

**Who should choose Namecheap?**Cost-sensitive teams that still want dedicated isolation and can operate the server.

## #3. HostGator

![](https://www.atlantic.net/wp-content/uploads/2025/08/Hostgator-logo.png)

**Best for guided setup and common control panels**

HostGator’s dedicated plans are designed to be approachable: guided setup, familiar control panels, and common OS choices. It’s aimed at growing sites that want dedicated resources but not a complicated onboarding process.

Their dedicated hosting plans are ideal for businesses transitioning from shared hosting to more powerful dedicated hosting services.

Here is the HostGator cPanel dashboard, where you can manage websites, databases, email accounts, and hosting settings from a centralized interface.

![HostGator-cPanel-dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/HostGator-cPanel-dashboard-1.png)

Image Source: HostGator

**Key Specs**: Varies by plan, but a good choice of hardware/
 **Compliance**: Not positioned as compliance-audited for regulated workloads—confirm independently
 **Support**: 24/7/365 chat and phone support

**Verdict**: If you want dedicated hosting with a “get it running fast” approach and mainstream tooling, HostGator is a practical pick.

**What stands out:**

- Guided server setup messaging (including help installing common tools)
- Good OS choice (Linux or Windows)
- Unmetered bandwidth for dedicated plans is stated in HostGator’s policy documentation.

**Who should choose HostGator?** Small businesses and agencies that value quick setup and easy administration over deep customization.

## #4. IONOS

![](https://www.atlantic.net/wp-content/uploads/2025/08/ionos-logo.png)

**Best for buyers prioritizing certified UK data centres**

IONOS is often considered by UK and EU buyers who want a large provider footprint and facility certifications as part of their vendor checklist. It’s a fit for general-purpose dedicated workloads where geography and documented facility standards are part of the decision.

It also appeals to enterprises needing dedicated web hosting with strong infrastructure governance and compliance visibility.

Look at the IONOS Cloud control panel showing server image management, infrastructure configuration, and US data center deployment options.
 ![IONOS cloud panel](https://www.atlantic.net/wp-content/uploads/2026/01/IONOS-cloud-panel.png)
 Image Source: IONOS

**Key Specs:** Varies by configuration
 **Compliance**: ISO 27001-certified UK data centres
 **Support**: The offer model varies by product.

**Verdict**: IONOS makes sense when you want dedicated hosting tied to a provider that foregrounds data centre security standards in the UK.

**What stands out:**

- ISO 27001-certified UK data centres referenced
- UK and global footprint messaging for latency and redundancy planning
- Security tooling references

**Who should choose IONOS?** UK/EU-focused teams that care about facility certification signals and a large provider platform.

## #5. Hostwinds

![](https://www.atlantic.net/wp-content/uploads/2025/08/hostwinds-logo.png)

**Best for hands-on control and remote management options**

Hostwinds is geared toward teams that want configuration control and operational access, including out-of-band management references (useful when the OS is unreachable). Plans vary, so it’s important to confirm what’s included versus optional.

This flexibility makes it a strong choice for users who require full root access and custom configurations across their server environment.

Explore the Hostwinds cloud hosting panel designed for managing server resources, configuring security settings, and monitoring performance in real time.
 ![Hostwinds WHM](https://www.atlantic.net/wp-content/uploads/2026/01/Hostwinds-WHM.jpg)
 Image Source: Hostwinds

**Key Specs**: Varies by configuration
 **Compliance**: Not typically positioned as audited for regulated workloads—confirm requirements
 **Support**: 24/7/365 support
 ****

**Verdict**: Hostwinds fits developers and admins who want more control over the server lifecycle and value remote management capabilities.

**What stands out:**

- IPMI access is referenced for most dedicated servers
- 24/7/365 support
- Focus on customizable dedicated deployments (plan-dependent)

**Who should choose Hostwinds?** Technical teams that want control, customization, and remote management features.

## #6. A2 Hosting (now Hosting.com)

![](https://www.atlantic.net/wp-content/uploads/2026/01/hosting-logo.png)

**Best for managed dedicated hosting with an uptime commitment**

A2 Hosting has rebranded to Hosting.com, and its dedicated server offering is positioned around managed help, configuration flexibility, and an uptime commitment. It’s a reasonable pick when you want dedicated hardware without running every operational task yourself.

It is a solid option for businesses looking for managed dedicated servers without handling day-to-day server management tasks internally.

Let’s see the Hosting.com interface used to manage products, track services, and configure account settings with ease.
 ![hosting.com control panel](https://www.atlantic.net/wp-content/uploads/2026/01/hosting.com-control-panel.jpg)

Image Source: Hosting.com

**Key Specs:** 99.9% uptime commitment (see terms)
 **Support**: 24/7/365 in-house support
 **Verdict**: Choose Hosting.com (A2) if you want managed dedicated options and clear messaging around uptime commitments and support availability.

**What stands out:**

- A2 Hosting → Hosting.com
- Dedicated servers positioned as “one machine, all yours,” with flexible RAM/storage language
- 99.9% uptime commitment page includes service-credit framing for unscheduled downtime

**Who should choose A2/Hosting.com?**Teams that want dedicated isolation but prefer managed support rather than full DIY operations.

## #7. AccuWeb Hosting

![](https://www.atlantic.net/wp-content/uploads/2025/08/accuweb-hosting-social-preview.png)

**Best for customizable dedicated servers and multiple server locations**

AccuWeb Hosting markets dedicated servers with configurable builds and use-case positioning (including performance-heavy scenarios like game hosting). Their dedicated server pages emphasize customization and “guaranteed network uptime” language, but plan details vary—so buyers should verify exact inclusions for bandwidth, SLAs, and management before checkout.

Their platform supports both Linux operating system and Windows servers, giving flexibility depending on application requirements.

Look at AccuWeb Hosting’s control panel interface used to manage Windows and Linux dedicated servers, databases, email accounts, and domain configurations.
 ![Accuwebhosting cPanel Dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Accuwebhosting-cpanel-dashboard.png)
 Image Source: AccuWeb Hosting

**Key Specs:** Wide choice of dedicated plans
 **Support**: 24×7 Support available
 **Compliance**: Not presented as an audited compliance

**Verdict**: AccuWeb is a fit when you want a configurable dedicated server, and you’re comfortable validating the exact SLA/uptime remedy, network policy, and what’s included in support for your chosen configuration.

**What stands out:**

- “Custom solutions” and build-to-requirement dedicated servers
-  “Guaranteed network uptime”

**Who should choose AccuWeb Hosting?**Buyers who want customizable dedicated hardware and will validate plan-level terms (support scope, uptime remedy, and network policy) before purchase.

## #8. phoenixNAP

![](https://www.atlantic.net/wp-content/uploads/2025/08/Phoenix-Nap-Logo.png)

**Best for API-driven dedicated servers and DevOps-style provisioning**

PhoenixNAP’s dedicated servers are built for teams who want to provision and manage infrastructure as code. Their dedicated server page highlights control via API/CLI/WebUI, plus IPMI access, and offers hourly or monthly billing options—useful for bursty environments or predictable long-term usage.

This aligns well with modern DevOps workflows where server hosting, deployment automation, and scalable infrastructure are tightly integrated.

Explore PhoenixNAP’s Bare Metal Cloud dashboard interface used to deploy and manage dedicated servers, Kubernetes clusters, billing, and infrastructure resources.
 ![PhoenixNAP dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/PhoenixNAP-bmc-portal-home-page.webp)
 Image Source: PhoenixNAP

**Key Specs:** Control via API, CLI, WebUI, or IPMI; hourly or monthly billing options

**Verdict**: Pick phoenixNAP when your priority is automation, repeatable deployments, and operational control (especially if your team already uses CI/CD and wants dedicated hardware that fits that workflow).

**What stands out:**

- Dedicated servers positioned as “deploy in minutes” with automation-first control paths
- IPMI and API/CLI/WebUI management
- The company site highlights a catalog of pre-configured dedicated instances and “manage as code”.

## Do I really need a dedicated server in 2026?

Yes, if you meet any of these criteria:

- **Regulatory Compliance:** You store sensitive data (HIPAA, PCI-DSS) and cannot risk “noisy neighbor” vulnerabilities found in shared or multi-tenant cloud environments.
- **Predictable Performance:** You run AI models, large databases, or high-traffic apps where CPU steal or I/O wait times are unacceptable.
- **Cost Control:** For heavy workloads, a fixed-price dedicated server is often 30-50% cheaper than equivalent resources on hyperscale clouds (AWS/Azure).

Dedicated hosting services are now widely used for hybrid cloud strategies where workloads require both isolation and integration with cloud hosting platforms.

## Managed vs. Unmanaged: Which is right for me?

- **Choose Managed** if you want the host to handle OS updates, security patches, and hardware monitoring. This lets you focus on your application code.
- **Choose Unmanaged** if you have a dedicated SysAdmin team, need custom kernel configurations, or want to install specialized software incompatible with standard management tools.

Managed dedicated hosting is ideal for teams that want to offload server maintenance, while unmanaged dedicated server plans are better suited for advanced users needing full control.

## How much RAM is enough?

- **32GB:** Minimum for modern web servers running a database and app server.
- **64GB – 128GB:** Recommended for virtualization, high-traffic e-commerce, or medium-sized databases.
- **256GB+:** Required for large-scale data processing, in-memory databases (Redis/Memcached), or AI inference tasks.

## Dedicated Performance for Heavy Workloads

Dedicated hosting is great for those looking for raw server performance. By getting exclusive access to the server, the CPU, RAM, Storage, and Network, your essential business applications will have the resources available to operate at peak efficiency 24x7x365.

With modern server hardware, optimized server configurations, and dedicated resources, businesses can achieve consistently high throughput and low latency.

Dedicated servers are well-suited for a variety of uses, including:

- **Popular Websites / E-commerce:** Manage large volumes of traffic even in peak hours with ease.
- **Databases and BI analytics**: Run an entire enterprise database with room to spare, process large datasets quickly and securely to give you unique insights into your business.
- **Deploy Resource-Hungry Apps:** Run any software you need, whether it’s for video rendering, scientific computing, AI, or machine learning. The experience is seamless with zero slowdown or unexpected bottlenecks.
- **Create a Private Cloud:** Build your private cloud with the security and control that only dedicated hosting provides.

These use cases benefit from reliable performance, enhanced security service layers, and the ability to scale with dedicated hosting plans.

Don’t just take our word for it; the customer reviews frequently praise our performance benchmarks. This highlights our commitment to speed, security, compliance, and reliability. Third-party tests evidence this: [Network tests reveal impressive throughput with high download and upload speeds](https://hostadvice.com/hosting-company/atlantic-net-reviews/), demonstrating Atlantic.Net high performance network infrastructure. All backed by a [100% uptime SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/), to give you further confidence that your services will remain online.

## Security and Compliance You Can Depend On

Atlantic.Net has built its security and compliance services with a strong focus on protecting your data integrity. All of our data centers are SOC 2 and SOC 3 certified, and offer a range of managed security services to help secure your servers.

Their managed servers include proactive monitoring, access controls, and compliance-ready infrastructure aligned with modern regulatory expectations.

For businesses in the healthcare and financial sectors, Atlantic.Net’s compliance-ready hosting is a major advantage. We are one of the providers that will sign a Business Associate Agreement (BAA) for HIPAA compliance, showing our commitment to safeguarding sensitive information. This makes Atlantic.Net a trusted partner for organizations that handle Protected Health Information (ePHI) or other confidential data.

## Frequently Asked Questions (FAQ)

### **What is the difference between Bare Metal and Dedicated Hosting?**

In 2026, the terms are often used interchangeably. However, “Bare Metal” frequently refers to automated, API-provisioned dedicated servers (like PhoenixNAP), while “Dedicated Hosting” implies a more traditional monthly rental model with manual provisioning. Both offer single-tenant physical hardware.

### **Does a dedicated server improve SEO?**

Indirectly, yes. Dedicated servers offer faster response times (TTFB) and higher uptime compared to shared hosting. Google’s Core Web Vitals prioritize speed and stability, so a faster server can contribute to better rankings.

### **Is dedicated hosting HIPAA-compliant by default?**

No. A physical server is *capable* of being HIPAA compliant, but the host must actively provide physical security, access logs, and a Business Associate Agreement (BAA). Only providers like Atlantic.Net specialize in certifying this layer of compliance.

### **Can I upgrade my dedicated server later?**

Most providers allow you to add RAM or storage drives with a brief maintenance window. However, upgrading the CPU usually requires migrating to a new chassis. Always over-provision your CPU slightly to account for growth.


---

# Top AI Development Companies in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/top-ai-development-companies/ | Published: 2026-04-14 | Updated: 2026-04-15 | Author: Richard Bailey

In 2026, the main challenge is turning AI prototypes into fully operational systems. AI development companies are now measured by how well they deliver reliable, secure, and scalable solutions, not just flashy demos or pilot chatbots.

Artificial intelligence development companies are increasingly evaluated on their ability to deliver measurable business outcomes through production-grade systems rather than experimental deployments.

Generative AI, machine learning, and natural language processing are now core building blocks for modern software. The winners aren’t the teams that demo the best chatbot—they’re the teams that can run governed RAG pipelines, production-grade copilots, and agentic workflows that stay measurable, maintainable, and safe over time.

## Why Use AI Development Services?

Businesses are increasingly seeking sophisticated AI development services to build AI-based software that helps to drive business growth, optimize operations, and provide actionable insights from real-world data. In 2026, businesses prioritize working with a reliable AI development company that can deliver customized AI solutions aligned with digital transformation goals. In 2026, the focus has shifted from experimentation to production-ready AI systems that can be deployed, governed, and maintained at scale. Choosing the right partner among the many AI companies available is vital for the successful implementation of an AI-powered platform. Organizations now look for an AI software development partner with a proven track record in delivering scalable AI solutions and enterprise software solutions. Enterprises now prioritize vendors that support evaluation, security, and long-term operational stability—not just initial model development. Whoever you choose to work with, remember that Atlantic.Net GPU Cloud Hosting, powered by NVIDIA, is readily available to host your AI/ML needs.

Below are some of the top AI development companies making a significant impact in 2026; in particular, we’ll explore AI development companies that are:

- Pioneering advancements and shaping the future of AI technology.
- Delivering production-ready AI systems with clear deployment and monitoring strategies.
- Developing impactful AI models and offering sophisticated AI tools.
- Delivering expert AI software development and complete solutions.
- Providing governance, red-teaming, and evaluation services for enterprise AI deployments.
- Leading progress in key AI domains such as large language models, computer vision, and conversational AI.

## Leading AI Development Companies and Their Offerings

The AI market is dynamic, with numerous companies offering specialized AI development services. The best AI development companies today are defined by their ability to combine technical expertise, AI expertise, and business alignment to deliver successful AI projects.

The following firms are recognized for their contributions to AI software development, their innovative AI models, and their ability to deliver effective AI solutions across various industries. In 2026, these leaders are increasingly evaluated on their ability to deliver production-ready systems, with built-in governance, evaluation, and operational reliability—not just model innovation.

## What “Enterprise-Ready AI” Means in 2026

Before selecting a vendor, align on the practical capabilities that separate demos from deployable systems:

- **Evaluation and test coverage:** offline evaluation + online monitoring; regression testing for prompts, tools, and retrieval.
- **Security and misuse resistance:** prompt injection defenses, data-leak prevention, access controls, sandboxing, and logging.
- **Governance:** audit trails, model/version tracking, policy enforcement, approval workflows, and documentation support.
- **Operational reliability:** observability, incident response, rollbacks, rate limiting, and cost controls.
- **Data grounding:** reliable retrieval, permissions-aware search, citation strategies, and data provenance.

## Leading AI Development Companies and Their Offerings

Below is a shortlist of widely used enterprise AI vendors and delivery partners. Each is strong in different areas—use this list to match capabilities to your environment, not as a one-size-fits-all ranking.

### #1: OpenAI

![](https://www.atlantic.net/wp-content/uploads/2025/06/openai-logo.png)

OpenAI has consistently been a prominent name in AI development, particularly known for its pioneering work with ChatGPT. OpenAI is widely considered one of the top artificial intelligence companies, known for enabling AI innovation across industries through advanced AI apps and developer tools. Their focus on advancing natural language processing and creating versatile AI agents has set industry benchmarks. More recently, OpenAI’s enterprise appeal has grown through a stronger focus on deployment tooling, safety alignment, and large-scale production use cases.

OpenAI continues to lead with its Generative Pre-trained Transformer (GPT) series of models. Anticipation is high for GPT-5.3, while the GPT-5, o3, and o4-mini models have already made a substantial impact. These models are increasingly used in agentic workflows, automated RAG pipelines, and enterprise copilots that require consistent performance in live environments. OpenAI’s work centers on conversational AI, NLP, and autonomous decision-making.

#### Advantages:

- modern research and development in large language models.
- Strong capabilities in natural language understanding and generation.
- Versatile models applicable to a wide range of AI applications, including conversational AI and content creation.
- Growing support for production deployment, including evaluation tools, safety testing, and model monitoring.
- Active community and extensive documentation for developers.

#### Disadvantages:

- Access to the most advanced models can come at a premium cost.
- Ethical considerations and potential for misuse of powerful generative models require careful management.
- Enterprises may need additional governance or red-teaming layers beyond core APIs.
- Some businesses may prefer more custom-tailored solutions than an off-the-shelf model access.

#### Ideal for:

- Organizations looking to integrate state-of-the-art generative AI and natural language processing into their products or workflows.
- Developers building innovative AI applications that require sophisticated text generation, summarization, or conversational AI capabilities.
- Enterprises deploying AI agents in production environments where evaluation, safety, and scalability are critical.

### #2 Google (including DeepMind)

![](https://www.atlantic.net/wp-content/uploads/2025/06/google-logo.png)

Google, through its DeepMind division and Google Cloud AI offerings, remains a dominant force in artificial intelligence. Google is a company specializing in AI integration across products, enabling businesses to deploy AI solutions at scale. Their contributions span from foundational research to practical AI solutions for businesses and consumers. In 2026, Google’s strength lies in turning advanced research into production-ready systems that can be deployed with governance and reliability at enterprise scale.

Some of Google’s key breakthroughs include progress in AI-driven healthcare solutions and self-learning neural networks. DeepMind’s AI-powered drug discovery has notably sped up medical research. The Gemini family of models, especially Gemini 3 Pro with its large context window of over 1 million tokens, excels in reasoning and managing vast amounts of information. Gemini’s long-context and multimodal features are positioned for large-document analysis, complex workflows, and agent-style systems.

#### Advantages:

- Extensive research capabilities leading to breakthroughs in machine learning models and AI technology.
- complete suite of AI tools and services through Google Cloud AI, facilitating full-cycle development.
- Leader in multimodal AI, combining text, image, audio, and video processing.
- Strong tooling for model evaluation, monitoring, and security within Google Cloud environments.
- Strong focus on data analytics and providing real-time insights.

#### Disadvantages:

- The breadth of offerings can sometimes be complex to navigate for newcomers.
- As with many large tech companies, data privacy and usage can be a concern for some users.
- Enterprises may face ecosystem dependency when deeply integrating Gemini and Google Cloud AI services.

#### Ideal for:

- Businesses of all sizes looking for scalable and powerful AI-powered solutions, particularly those already invested in the Google Cloud or G Suite ecosystems.
- Organizations requiring advanced data analysis, predictive analytics, and multimodal AI capabilities.
- Enterprises deploying long-running AI systems that require governance, evaluation, and secure production operations.

### #3: NVIDIA

![](https://www.atlantic.net/wp-content/uploads/2025/08/nvidia-logo.png)

Primarily known for its powerful Graphics Processing Units (GPUs), NVIDIA has successfully established itself as a foundational provider for the AI market, offering the hardware and software infrastructure that powers the majority of AI systems (including those [**at Atlantic.Net**](https://www.atlantic.net/press-releases/atlantic-net-joins-nvidias-cloud-service-provider-program/)). In 2026, NVIDIA’s role is less about experimentation and more about enabling production-scale AI across enterprises and data centers. NVIDIA powers the infrastructure that AI software development companies rely on for large-scale AI innovation.

NVIDIA is also well known for its enterprise-grade, AI-powered GPUs. The company’s AI-driven chips are transforming sectors like gaming, autonomous systems, and cloud computing. NVIDIA’s progress in 2026 includes humanoid robotics ([**Isaac GR00T-Dreams**](https://developer.nvidia.com/isaac/gr00t) platform), the NVLink Fusion platform, and AI supercomputers. These platforms are increasingly optimized for sustained training, inference reliability, and secure multi-tenant AI workloads.

#### Advantages:

- Industry-leading GPU technology crucial for training and deploying complex deep learning and machine learning models.
- Driving innovation in emerging areas like autonomous systems and humanoid robotics.
- Strong support for developers with SDKs and tools for various AI projects.
- Enables high-performance computing for demanding AI workloads.
- Critical backbone for production AI infrastructure, including monitoring, isolation, and performance optimization.

#### Disadvantages:

- The cost of specialized NVIDIA hardware can be substantial, particularly for smaller organizations or individual developers.
- Their primary focus is on infrastructure and enablement rather than direct end-user AI software development.
- Rapid hardware iteration cycles can increase long-term operational costs.

#### Ideal for:

- Companies and researchers requiring high-performance computing capabilities for training large AI models and running complex simulations.
- Organizations developing AI applications in graphics-intensive fields, autonomous driving, and robotics.
- Enterprises operating production AI systems that demand predictable performance, scalability, and infrastructure-level governance.

### #4: Microsoft AI

![](https://www.atlantic.net/wp-content/uploads/2026/02/MS-COPILOT.png)

Microsoft has embedded artificial intelligence across the vast majority of its products and services, making AI technology more accessible to businesses and individuals. Microsoft positions itself as a trusted AI development partner for enterprises seeking end-to-end AI integration and strategy consulting. It delivers its AI services through its Azure AI platform and Windows Operating Systems. In 2026, Microsoft positions itself as a leader in production-ready enterprise AI, with strong emphasis on security, governance, and operational control.

Microsoft has invested heavily in Microsoft 365 Copilot and has a strategic partnership with OpenAI to develop GPT models for Copilot, with a focus on embedding the technology into its Office and Software suites. Azure AI increasingly supports red-teaming, model evaluation, and compliance tooling to help enterprises deploy AI safely in regulated environments.

#### Advantages:

- Strong integration of AI solutions within widely used enterprise software (Microsoft 365, Dynamics 365, Windows Server).
- complete Azure AI platform offering a wide range of AI development services, from pre-built APIs to custom AI model development.
- Strategic partnership with OpenAI provides access to advanced large language models within the Azure ecosystem.
- Focus on creating AI agents to automate complex tasks such as writing code.
- reliable governance, security, and responsible AI frameworks designed for enterprise production deployments.

#### Disadvantages:

- Deep integration with the Microsoft ecosystem might lead to vendor lock-in for some businesses.
- The sheer number of tools and services on Azure can be overwhelming for new users.
- Costs for Azure AI services can escalate with extensive usage if not managed carefully.

#### Ideal for:

- Enterprises already using Microsoft products and looking to enhance their operations with integrated AI capabilities.
- Developers seeking a complete cloud platform for building, deploying, and managing AI applications and AI agents.
- Organizations requiring production-grade AI with built-in governance, evaluation, and red-teaming support.

### #5: IBM WatsonX

![](https://www.atlantic.net/wp-content/uploads/2025/06/ibm-logo.png)

IBM Watson has a long history in the AI market, providing enterprise-grade AI solutions with a focus on data analytics and cybersecurity. It specializing in AI for regulated industries, delivering tailored AI solutions focused on governance and compliance. In 2026, IBM’s differentiation centers on production-ready AI for regulated enterprises, with strong controls around governance, evaluation, and risk management.

IBM is concentrating on enterprise-grade generative AI, particularly with its Watson X platform, which focuses on integrating AI with dynamic enterprise data. Key announcements at IBM Think 2026 included Watson X Orchestrate for creating autonomous AI agents, no-code options for AI customization, and prebuilt domain agents for HR, sales, and procurement. Watson X also emphasizes model governance, auditability, and red-teaming capabilities to support real-world deployment at scale.

#### Advantages:

- Strong focus on enterprise-grade AI solutions for regulated industries.
- Watsonx platform allows for building, scaling, and managing AI with an emphasis on data security and regulatory compliance.
- Expertise in data science consulting and helping organizations manage their data engineering and data insights.
- Emphasis on responsible AI, AI ethics, and explainable AI, which is important for building trust.
- Built-in governance, evaluation, and red-teaming features suited for long-lived production AI systems.

#### Disadvantages:

- Can be perceived as more suited to large enterprises, potentially being less agile or cost-effective for smaller businesses.
- Integration with existing legacy systems is complex.
- The brand’s historical association with traditional IT might not appeal to cloud-native companies.

#### Ideal for:

- Large enterprises, especially in regulated industries like finance, requiring reliable, secure, and compliant AI powered solutions.
- Businesses looking to leverage AI for business analytics, cybersecurity, and automating business processes with a focus on governance.
- Organizations prioritizing production stability, explainability, and formal AI risk management.

### #6: Amazon AI (AWS)

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

Amazon Web Services (AWS) is a major provider of cloud computing services and offers an extensive array of AI and machine learning tools, making it a popular choice for developers and businesses looking to build and scale AI applications. In 2026, AWS’s AI strategy emphasizes production reliability, cost control, and governance for large-scale deployments.

Amazon SageMaker is a central platform for building, training, and deploying ML models. Recent developments from AWS re:Invent 2024 and early 2025 include Trainium2 and Trainium3 AI chips, the [**Project Rainier supercomputer**](https://www.wsj.com/articles/amazon-announces-supercomputer-new-server-powered-by-homegrown-ai-chips-18c196fc) (in partnership with Anthropic), the Nova family of AI models, and Amazon Q Developer for automating developer tasks. These offerings are increasingly positioned for governed, production-grade AI pipelines rather than experimental workloads.

#### Advantages:

- Broad and deep set of AI services and tools, catering to various needs from pre-trained models to full machine learning model development with Amazon SageMaker.
- Scalable infrastructure capable of handling demanding AI workloads and large datasets.
- New AI chips (Trainium), models (Nova family), and developer tools (Amazon Q Developer).
- Strong ecosystem and integration with other AWS services, facilitating end-to-end software solutions.
- Enterprise-grade controls for monitoring, evaluation, security, and governance of deployed AI systems.

#### Disadvantages:

- The vast number of services and configuration options can be complex, especially for users new to AWS.
- Cost management requires careful attention, as expenses can accumulate quickly with extensive use of AI services.
- Similar to other large cloud providers, there is a potential for vendor lock-in.

#### Ideal for:

- Developers and businesses of all sizes looking for a flexible and scalable platform to build, train, and deploy AI models and AI applications.
- Organizations that require a wide variety of AI tools, from data analysis and machine learning to generative AI and AI assistant development.
- Enterprises running long-term, production AI workloads that require governance, evaluation, and operational consistency.

### #7: Innowise

![](https://www.atlantic.net/wp-content/uploads/2025/05/innowise-logo.png)

Innowise is a global software development company that builds AI tools that solve real business challenges. It is recognized as a reliable partner for businesses seeking custom software development and AI integration services. The firm is based in Warsaw and has about 15 offices and 3,000 employees on board. They work with clients across multiple industries, including healthcare, fintech, logistics, retail, manufacturing, etc. In 2026, Innowise is increasingly positioned as a practical partner for taking AI systems from pilot to stable production.

Innowise engineers custom AI software systems using machine learning, computer vision, natural language processing and simple predictive models. They also build LLM chatbots for customer support, HR and internal services. A growing focus is on production-ready deployments, including workflow automation, RAG-based systems, and AI agents integrated into existing enterprise platforms.

Innowise covers data work, model training, automation and cloud setup. They take AI software development projects from data prep to deployment and ongoing support. The company has finished over 1,300 projects and usually focuses on clear communication and steady delivery. They increasingly support governance-oriented requirements such as model evaluation, access controls, and operational monitoring for live AI systems.

#### Advantages:

- Covers the full AI cycle — from data to deployment.
- Real experience with generative AI and automation tools.
- Can integrate AI into existing systems without major rebuilds.
- Transparent process and steady communication with clients.
- Practical focus on production readiness, stability, and maintainability.

#### Disadvantages:

- Medium-sized company, not as large as major cloud providers.
- Custom projects may need more time for setup and coordination.

#### Ideal for:

- Businesses that need a reliable AI development partner.
- Companies exploring AI chatbots, predictive analytics, or automation.
- Teams that want governed, production-ready AI systems without enterprise-cloud complexity.

### #8: LeewayHertz

![](https://www.atlantic.net/wp-content/uploads/2026/02/LeewayHertzLogo.png)

LeewayHertz is an AI development company that builds production-ready AI systems for enterprises. It is considered a reliable AI development company with strong capabilities in custom AI development and enterprise deployments. They help both startups and large organizations move AI projects beyond testing and into long-term use.

LeewayHertz creates custom AI solutions using large language models, computer vision, and predictive analytics. Lately, they have focused on building enterprise RAG pipelines, AI agents, and GenAI applications for regulated and sensitive environments. They also provide AI advisory services for evaluation, risk assessment, and deployment readiness.

#### Advantages:

- Strong focus on production deployment rather than PoCs.
- Experience building enterprise RAG systems and AI agents.
- Support for governance, access control, and evaluation workflows.
- End-to-end delivery from strategy to deployment.

#### Disadvantages:

- Not a platform provider; it relies on third-party cloud infrastructure.
- A custom engagement model may increase delivery timelines.

#### Ideal for:

- Enterprises are moving GenAI systems into production.
- Organizations require AI deployments that are governed and supported by clear operational controls.

### #9: JPLoft

![](https://www.atlantic.net/wp-content/uploads/2026/02/JPLoft.jpg)

JPLoft is a technology services company that creates custom AI solutions, focusing on AI-driven mobile app development and enterprise AI applications. They help businesses deploy AI models into their existing applications and workflows.

JPLoft develops AI solutions across natural language processing, machine learning, and automation. In 2026, they are focusing more on making their AI ready for real-world use, with features such as monitoring, careful rollout plans, and strong governance for live systems.

#### Advantages:

- Hands-on approach to deploying AI in production environments.
- Focus on maintainability and post-deployment support.
- Experience integrating AI into existing enterprise software stacks.

#### Disadvantages:

- Smaller global footprint compared to large consultancies.
- Limited proprietary AI tooling compared to platform vendors.

#### Ideal for:

- Companies transitioning AI models from pilot to production.
- Teams seeking practical AI delivery with governance awareness and long-term support.

## AI Security & Evaluation Services

As AI systems move into production, security and evaluation have become core requirements. AI development companies now provide advanced security frameworks to support the safe deployment of AI apps and intelligent systems. Enterprises deploying generative AI, autonomous agents, and RAG pipelines must ensure models behave predictably, resist misuse, and comply with internal and external controls. Leading AI development companies now offer AI security and evaluation services to reduce operational and reputational risk once systems are live.

Top firms offer several important AI security and evaluation services, such as:

- Model evaluation and benchmarking to validate accuracy, reliability, and task performance before and after deployment.
- Red-teaming and adversarial testing help identify risks such as prompt injection, data leaks, and unsafe model behavior.
- Governance frameworks for AI systems include access controls, audit logs, version tracking, and policy enforcement.
- Monitoring and observability for live models help spot issues like drift, lower performance, or unexpected results.
- Compliance and risk support help companies in regulated industries meet explainability and documentation rules.

Companies like Microsoft AI, IBM Watson, Google (DeepMind), and other enterprise-focused firms now stand out by offering these services. For organizations using AI in customer-facing or critical operations, security, evaluation, and governance are just as important as the model’s capabilities.

## Choosing the Right AI Development Partner

The AI development companies we have listed above represent some of the most influential players in the AI market in 2026. Selecting the right AI development company requires evaluating technical expertise, AI expertise, and a proven track record of delivering successful AI projects. Each offers unique strengths in AI software development, AI consulting (often part of broader consulting services), and the provision of AI tools and platforms designed to meet diverse business needs. However, the primary differentiator in 2026 is no longer model quality alone—it is the ability to deliver production-ready AI systems that operate safely, reliably, and under clear governance.

When selecting an AI development partner, carefully consider your specific business objectives, the scale of your AI projects, your existing technology stack, and your budget. Enterprises should also evaluate whether a provider can support AI systems after deployment, not just during initial development. To ensure you select a provider that aligns with your business needs and can help you achieve substantial business growth, consider the following:

- Look for demonstrated expertise in specific AI technologies like natural language understanding, computer vision, predictive analytics, and potentially advanced generative techniques such as stable diffusion or voice cloning if relevant to your project.
- Confirm the provider has experience deploying AI in production, including monitoring, evaluation, and ongoing optimization.
- Confirm they have experience and a track record in your specific industry, whether it’s e-commerce, optimizing financial operations, or another sector.
- Assess their approach to AI security, red-teaming, and governance, especially for customer-facing or regulated use cases.
- Ensure the company demonstrates a strong commitment to responsible AI practices.
- Verify the availability of ongoing support and complete software development services.
- Choose a partner that can define clear operational processes for updates, incident response, and model lifecycle management.
- Choose a partner who stays current by being able to track industry trends to offer the best AI approaches for your specific situation.

Access to powerful computing resources, such as those offered through Atlantic.Net GPU hosting, can be fundamental to training complex AI models and running demanding AI applications created by these top-tier firms. Equally important is selecting a partner that can help you evaluate, secure, and govern those AI systems once they are in live production.

Partnering with a forward-thinking development services provider, supported by reliable infrastructure, will be instrumental for staying competitive and harnessing the full potential of artificial intelligence. To find out how dedicated GPU hosting can underpin your AI initiatives, [**reach out to Atlantic.Net**](https://www.atlantic.net/about-us/corporate-contact/).

## FAQ

**What’s the difference between an AI platform vendor and an AI development company?**

Platform vendors provide models and tooling. Development companies implement AI in your environment, integrate with data and systems, and support operations after launch. Many enterprises use both.

**How do I evaluate whether a vendor can move beyond a prototype?**

Ask for evidence of evaluation coverage, monitoring, rollout strategy, incident response playbooks, and secure data access controls. A vendor that can’t describe these clearly usually can’t operate AI at scale.

**What should an enterprise RAG pipeline include in 2026?**

At minimum: permissions-aware retrieval, relevance evaluation, citation/provenance strategy, prompt and retrieval regression tests, and monitoring for retrieval failures and drift.

**How long does it take to ship a production copilot?**

Timelines vary, but the biggest determinants are data readiness, access controls, evaluation coverage, and operational maturity. Expect production readiness work to take as long as the model integration.

Content updated: April 14, 2026


---

# Top 10 Best Cloud ERP Solutions in 2026

> URL: https://www.atlantic.net/pci-compliant-hosting/best-cloud-erp-solution/ | Published: 2026-04-14 | Updated: 2026-04-17 | Author: Richard Bailey

By deploying an efficient cloud-based ERP solution, you can help to streamline and simplify your company’s work processes and set you ahead of the competition. Modern cloud ERP solutions now focus on unifying core business functions such as financial management, inventory management, and supply chain management within a single cloud-based platform. The market for such solutions is vast, meaning that whatever the size and scale of your business, there will be a suitable solution for you.

Here, we explore exactly what ERP software is and highlight some leading cloud-based solutions.

## What Is an ERP Solution?

An ERP, or Enterprise Resourcing Planning, solution refers to end-to-end management software businesses use to manage critical day-to-day operations. Enterprise resource planning software now integrates financial data, human resources, customer relationship management, and supply chain processes into one centralized system. As a single integrated solution, ERP software is an ideal choice for larger businesses that want to streamline their work processes between different departments via a shared database. ERP solutions can integrate functions across all aspects of business management, including accounting, inventory and order management, HR, customer relationship management, and many more.

## Why Choose a Cloud-Based ERP Solution?

When considering your options, you may be unsure whether an on-premises or cloud ERP system would be best. There are several key reasons why opting for a cloud-based ERP solution would be a wise choice. Cloud ERP software provides real-time access to business data from distributed data centers, enabling global operations without relying on legacy systems or on-premises ERP infrastructure. One of the significant benefits of a cloud-based ERP solution is that your chosen hosting provider takes care of your software’s implementation, hosting, and maintenance, freeing up your time and resources. Cloud-based ERP solutions also enable faster data migration, reduce business downtime, and improve operational efficiency through automation and predictive analytics. Cloud-based solutions are also more cost-effective and can be accessed from anywhere in the world at any time. As your business grows, your cloud-based ERP system can grow with you.

## Top 10 ERP/Payroll Solutions

Due to its vast capabilities, an ERP solution is a complex piece of software and must incorporate many functions to match the needs of a modern and agile business. Today’s ERP systems must support supply chain management, financial management, human capital management, and project management while maintaining enterprise-grade security. Choosing a suitable ERP solution for your business can be challenging, so we have compiled a list of some of the leading cloud-based ERP solutions available on the market. For this, we have considered functionality, integration with existing systems, scalability, cost, and ease of use.

## 1. Oracle NetSuite

Heading the top of the list, thanks to its feature-rich software and cost-effective price point, is Oracle NetSuite. Oracle NetSuite was established in 1998 and is used by more than 32,000 companies across the globe. This cloud-based software stands out from its competitors with the vast range of features it offers users, with access to financial management, customer relationship management (CRM), supply chain management, inventory management, project management, global business management, and analytics and reporting. As one of the most widely adopted cloud ERP vendors, NetSuite delivers strong financial data visibility and supports manufacturing and distribution operations. In addition, users benefit from easy-to-use and intuitive interfaces and the ability to scale as your business grows. This is an excellent ERP solution for midsize companies that incorporates all ERP functions into one powerful package.

## 2. Sage Intacct

Sage Intacct is a best cloud-based ERP system that offers a cheaper alternative to Oracle NetSuite for any business, from start-ups to global enterprises. Implementing and offering services such as budgeting, accounting, HR management, order management, and reporting is straightforward. It is particularly strong in financial management and accounting processes, making it a preferred ERP provider for finance-focused organizations. With Sage Intacct, users can automate processes to reduce business costs, improve security, and boost productivity. However, Sage Intacct lacks supply chain functionality, unlike some competitors.

## 3. SAP S/4 HANA Cloud

SAP Suite/4HANA Cloud was launched in 2015 and is a popular choice of ERP solution among large and midsize enterprises. It is powered by AI and analytics, allowing businesses to run critical processes in real-time from anywhere in the world. SAP S/4HANA is designed for global enterprises that require advanced supply chain visibility, asset management, and manufacturing processes optimization. For example, S/4HANA Cash Application harnesses the power of AI to generate real-time, intelligent invoice-matching by capturing customer- and country-specific behavior.

Users can choose between a ‘ready-to-run’ or a ‘tailored-to-fit’ cloud ERP solution, with SAP S/4HANA offering either a cloud-based or on-premise solution.

## 4. Odoo

Odoo is an open-source platform offering a suite of crucial business applications, including project management, accounting, invoicing, marketing, inventory, CRM, and eCommerce. Given the flexibility and scalability of the cloud platform, businesses of all sizes can benefit from deploying Odoo. Its modular approach makes it a flexible, cloud-based ERP system for small businesses that need tailored solutions without high upfront costs. In addition, all applications within the Odoo platform integrate seamlessly, allowing you to coordinate your business’s operations efficiently.

Odoo offers a pay-per-app pricing model, so you only pay for what you use. This makes it an ideal choice for smaller businesses on a tight budget. With over 1500 active contributors, the Odoo platform provides over 10,000 apps that integrate.

## 5. Epicor

With over 21,000 customers across 150 countries, Epicor provides industry-specific, cloud-based ERP solutions to SMEs within the manufacturing, building supply, and distribution industries. For businesses within these sectors, Epicor’s deep vertical expertise is unparalleled. Epicor supports discrete manufacturing, quality management, and supply chain optimization, making it ideal for manufacturing and distribution operations.

Epicor offers businesses a single platform to organize their supply chain, customer service, HR, and production processes and can be integrated with other standard SaaS and on-premise applications.

## 6. Syspro

With over 40 years of experience, Syspro provides ERP software solutions to companies operating within the manufacturing and distribution industries. Clients can opt to deploy Syspro on-premise, in the cloud, or a hybrid of both and benefit from multidimensional security levels, customizable solutions, and vast scalability. Thanks to its simplistic and user-friendly interface, Syspro boasts a retention rate of 98%. Its strong inventory management and production tracking capabilities support efficient manufacturing and distribution operations.

## 7. Workday

As a Leader in the 2022 Gartner Magic Quadrant for Cloud ERP for Service-Centric Enterprises, Workday offers a core package of payroll, HR, and accounting applications. In addition to this, clients can purchase additional modules to streamline their specific business processes. With a simple and easy-to-navigate interface, even employees with no experience can use the Workday platform immediately. However, some users have complained about potential migration issues due to some software incompatibility. Workday is especially strong in human capital management and financial data analytics for service-based organizations.

## 8. Microsoft Dynamics 365

Microsoft Dynamics 365 is a leading ERP provider ideal for small businesses, combining ERP functionality with an advanced CRM solution. As a modular ERP solution, Microsoft Dynamics allows users to choose the capabilities they require while leaving plenty of scope for scaling up in the future. Microsoft Dynamics 365 integrates deeply with the Microsoft ecosystem and Microsoft tools, making it a strong choice for businesses already using Microsoft Dynamics products. In addition, as a centralized platform, it enables employers and employees to manage all aspects of their business seamlessly, providing the option to automate routine tasks and unify operations across all departments.

## 9. Infor CloudSuite

Infor CloudSuite also offers a cloud-based ERP platform, with many industry-specific solutions falling within this umbrella. For example, Infor M3 and Syteline both provide solutions for the manufacturing industry, while Infor Nexus is a leading supply chain management solution. Infor clients must decide which product meets the specific needs of their business. Each solution provides pre-configured processes that align with the particular needs of its target industry. Infor CloudSuite delivers industry-specific ERP solutions with built-in predictive analytics for supply chain and manufacturing environments. In addition, Infor ERP includes built-in AI capabilities, game-changing analytics, and fast and secure deployment.

## 10. Acumatica

Acumatica is a cost-effective ERP platform ideal for businesses looking to scale shortly. Trusted by over 8,500 companies, Acumatica delivers a future-proof platform with AI-powered automation and real-time insights. Flexible and transparent licensing plans allow the platform to grow alongside your company. In addition, Acumatica cloud ERP will integrate seamlessly with your existing programs and provide your business with enterprise-grade security.

## Partner With a Leading Cloud Provider

The next step is to find a leading hosting provider to host your chosen cloud-based ERP solution. That’s where Atlantic.Net comes in. With over 30 years of proven experience, Atlantic.Net delivers top-level hosting services at cost-effective prices, making them an ideal partner for businesses of all sizes.

Modern cloud deployment environments rely on secure data centers, private cloud options, and enterprise-grade security to protect sensitive business data and ensure compliance.

Atlantic.Net is SOC 2, SOC 3 certified, HIPAA and HITECH audited, [PCI-DSS compliant](https://www.atlantic.net/pci-compliant-hosting/), and regularly audited by third-party, independent auditors. Contact our sales team today to learn more about how Atlantic.Net can help your business.

 


---

# Top 10 Best Cloud Payment, Finance, or Billing Solutions in 2026

> URL: https://www.atlantic.net/pci-compliant-hosting/top-10-best-cloud-payment-finance-or-billing-solutions/ | Published: 2026-04-14 | Updated: 2026-04-17 | Author: Dr. Rachael Bailey

The cloud is ubiquitous, with businesses and organizations using cloud-based tools and services across nearly every function. From data storage to SaaS platforms, the cloud continues to reshape how modern organizations operate. Today, cloud-based payment solutions are a core part of digital adoption strategies, enabling businesses to manage transactions, billing, and financial operations with greater efficiency and flexibility.

Cloud-based payment processing, [finance, and accounting software solutions](https://www.invensis.net/finance-accounting-services) are now the preferred choice for businesses looking to scale, automate operations, and improve customer experience. They offer key benefits such as faster payments, improved security, enhanced scalability, and reduced infrastructure costs. Additionally, these platforms provide instant access to transaction data, payment details, and real-time data insights, helping businesses stay ahead in a competitive market.

Technologies such as mobile payments, e-commerce, and embedded finance have significantly evolved the financial ecosystem. As the industry moves toward automation, analytics, and integration with CRM and banking systems, cloud-based payment platforms are becoming essential for future-proof business operations. This article explores the top 10 cloud payment, finance, and billing providers currently available. We evaluated each solution based on platform capabilities, scalability, compliance, and overall value to businesses.

## Top 10 Cloud Payment, Finance, and Billing Solutions

## 1. QuickBooksOnline

QuickBooks Online is the cloud-based version of the on-premise QuickBooks accounting software. It is aimed at small businesses, allowing users to manage their finances in real-time using a user-friendly platform. It enables businesses to centralize accounts, automate reconciliation, and gain actionable insights from financial data through integrated analytics tools. The advantages of using the online version include lower costs, accessibility from anywhere, increased collaboration, and extensive integrations like [QuickBooks BigQuery integration](https://www.coupler.io/bigquery-integrations/quickbooks-to-bigquery).

You will also benefit from access to a strong support team. In addition, a QuickBooks mobile app allows you to manage your business finances on the go. Security remains a priority, with encrypted data transmission, secure cloud infrastructure, and continuous monitoring to reduce risk and ensure compliance.

## 2. PaySimple

Established in 2006, PaySimple is a cloud-based online payment solution that helps streamline billing and payment acceptance. With PaySimple, businesses can accept payments, track customer data, set up recurring billing, and automate workflows. It is especially useful for businesses managing subscription services, enabling automation and improving operational efficiency.

PaySimple is ideal for small to medium enterprises handling recurring payments. Its cloud-based system reduces manual work, improves payment experience, and supports scalable growth without requiring additional hardware.

## 3. FreshBooks

FreshBooks is an all-in-one cloud-based [accounting software for small businesses](https://www.freshbooks.com/accounting-software/for-small-business) and freelancers. It integrates with over 100 apps, enables invoice customization, and supports automated payments. FreshBooks also helps businesses manage billing, track expenses, and generate financial reports with real-time data visibility.

The software is accessible across desktop, tablet, and mobile devices. Its mobile capabilities allow teams to manage payments, track transactions, and respond quickly to customer needs from anywhere.

## 4. GoCardless

GoCardless is a leading payment processing platform offering secure transactions with regulatory compliance and strong protection standards. It focuses on bank-to-bank payments, helping businesses reduce transaction fees and improve cash flow management.

They currently serve over 75,000 businesses globally and process billions in transactions annually. The platform integrates easily with accounting software, CRM systems, and billing tools, enabling seamless automation and reconciliation.

## 5. Scoro

Scoro provides a complete work management platform ideal for service-based businesses. It allows companies to automate financial processes, manage projects, and track performance in one system.

Its cloud-based infrastructure enables businesses to unify operations, billing, and analytics into a single platform, improving visibility and decision-making. Companies can generate quotes, manage payments, and automate reminders without complex setup.

## 6. Xero

Xero is a scalable, cloud-based accounting software designed for growing businesses. It offers competitive pricing and flexible plans tailored to different business sizes.

Xero enables businesses to integrate payments, banking, and financial reporting into one ecosystem, supporting automation and real-time financial insights. Features include payment processing, file storage, analytics, and [employee time tracking](https://apploye.com/best-employee-time-tracking-software).

## 7. Sage

Sage offers cloud-based financial solutions, including payroll, accounting, and integrated payment systems. Its platform is designed to help businesses improve efficiency, automate workflows, and maintain compliance with financial regulations such as PCI compliance. Customers can accept digital payments, integrate with banks, and automate financial operations.

## 8. Zoho Books

Zoho Books is a cloud-based accounting system designed to simplify business financial management. It automates tasks such as VAT calculations and transaction tracking.

The platform supports automation, analytics, and integration with other Zoho services, enabling businesses to streamline operations and improve financial accuracy. Features include a client portal, transaction approvals, and document scanning.

## 9. PayPal

Not to be left off a list of top payment solutions, PayPal is a world leader in this field. It successfully provides businesses worldwide with a suite of practical solutions for online billing. PayPal has also successfully teamed up with many clients to offer customized billing solutions. PayPal’s Invoicing tool allows users to send detailed electronic invoices, enabling customers to pay via credit card or PayPal. From its sleek dashboard, PayPal customers can manage bill payment history, provide reminders about invoices and keep track of unpaid invoices.

In addition, companies can register for PayPal without being charged directly and then simply pay transaction fees to PayPal based on the final cost of their transactions. It enables merchants to accept payments across multiple channels, including mobile, online, and in-store, while providing a secure and scalable payment experience. Its invoicing tools allow businesses to send detailed bills and track transactions efficiently.

## 10. Stripe

Stripe is a complete cloud-based payment processing gateway and platform trusted globally by millions of companies of all sizes. It allows businesses to send payouts, accept online payments, and manage their payments, billing, and transactions online through a flexible cloud based system. Stripe provides cardholder support in over 195 countries around the world.

It enables businesses to leverage real time data, analytics, and automation to improve payment experience, increase efficiency, and stay ahead in a competitive market. It will help your business to maximize and drive revenue using powerful machine learning to increase authorization rates and reduce decline rates.

## How Can Atlantic.Net Help?

With plenty of cloud-based payment, billing, and finance solutions available, we are confident that you will find one to meet the unique needs of your business. However, it is essential to remember that whichever solution you choose, make sure it is [PCI compliant](https://www.atlantic.net/pci-compliant-hosting/) to ensure secure handling of payment details, transaction data, and overall compliance with industry standards.

Your next decision may involve finding a leading hosting provider to host your payment and billing solution. Atlantic.Net can create the perfect hosting solution for your business or organization. For over 30 years, our talented team of professionals has delivered a full suite of managed IT services and always-available professional technical support.

Our cloud-based infrastructure is designed to support cloud-based payment processing, enabling businesses to manage transactions, billing, and data with greater efficiency, scalability, and flexibility. With SOC 2 and SOC 3, HIPAA, and HITECH certifications, 24x7x365 support, monitoring, and world-class data center infrastructure, you can trust us to protect the security and compliance of your business.

You can find out more information by [contacting our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)!

 


---

# Top 10 Best Cloud HR / HRMS Solutions in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/best-cloud-hr-hrms-solution/ | Published: 2026-04-14 | Updated: 2026-06-23 | Author: Dr. Rachael Bailey

Are you looking for a reliable HR/HRMS solution to streamline your company’s HR processes? This guide reflects the latest 2026 trends in cloud HRMS solutions and highlights several leading platforms for payroll, employee records, workforce management, benefits administration, recruiting, onboarding, performance management, and employee engagement.

Cloud-based HR software has become an important part of modern business operations. HR teams now need systems that can support hybrid work, distributed teams, compliance requirements, employee self-service, data-driven decision-making, and integrations with payroll, finance, and other business systems.

This article explains what HR/HRMS software does, why cloud-based HR platforms are useful, and which HR/HRMS solutions are worth considering in 2026.

## What Is an HR/HRMS Solution?

HR/HRMS software allows businesses to manage, streamline, and automate many daily HR tasks. These systems help organizations centralize employee records, manage payroll information, track leave and absence, support recruitment, organize onboarding, store documents, and generate useful reports.

Modern HR software now supports the full employee lifecycle, from hiring and onboarding through performance management, employee engagement, and offboarding. Many platforms also include employee self-service portals, giving staff access to payslips, benefits information, time-off requests, personal details, and HR documents without needing to contact the HR team for every request.

HR management systems are often divided into two categories:

- **HRIS, or Human Resource Information System:** A system used to organize and manage employee information, records, documents, and core HR data.
- **HRMS, or Human Resource Management System:** A broader system that typically includes HRIS features, as well as payroll, benefits, performance management, workforce management, employee engagement, reporting, and other advanced tools.

The terms HRIS, HRMS, and HCM are sometimes used interchangeably, but the goal is usually the same: to help businesses manage people, payroll, compliance, and workforce data more efficiently.

## What Are the Benefits of a Cloud-Based HR/HRMS Solution?

Many modern HR software services are cloud-based, eliminating the need to install and maintain on-premises software. Instead, users access the platform through a secure web portal or mobile app.

Cloud-based HR solutions offer several advantages:

- **Centralized employee data:** Employee records, payroll details, benefits information, documents, and HR workflows can be managed from one location.
- **Improved access:** HR teams, managers, and employees can access the system from different locations, which is important for remote, hybrid, and multi-site businesses.
- **Scalability:** Cloud HRMS platforms can grow with the business, supporting new employees, departments, locations, and features as needed.
- **Automation:** Routine HR tasks such as onboarding, approvals, time-off requests, payroll workflows, and reminders can be automated to reduce manual work.
- **Employee self-service:** Employees can update personal details, request leave, view pay information, and manage benefits through self-service portals.
- **Better reporting:** HR teams can use dashboards, analytics, and custom reports to track trends in hiring, retention, absence, performance, and workforce planning.
- **support:** Many cloud HR platforms integrate with payroll systems, accounting tools, applicant tracking systems, identity providers, collaboration platforms, and other business software.
- **Security and compliance support:** Leading HRMS platforms include access controls, audit trails, [encryption](https://www.atlantic.net/about-us/whitepapers/why-encryption-is-essential-in-healthcare-cybersecurity/), and compliance-focused features to help organizations protect sensitive employee data.

With HR information available through a centralized [cloud platform](https://www.atlantic.net/cloud-platform/), businesses can reduce paperwork, improve data accuracy, and give HR teams more time to focus on people strategy rather than manual administration.

## Top Cloud-Based HR / HRMS Companies in 2026

Below are some of the best-known cloud-based HR/HRMS solutions in 2026. The right choice depends on company size, budget, payroll , compliance needs, workforce structure, and the features your HR team needs most.

### 1. BambooHR

![](https://www.atlantic.net/wp-content/uploads/2026/04/bamboohr-logo-green.png)

BambooHR is a popular cloud-based HR platform designed mainly for small and mid-sized businesses. It gives HR teams a central place to manage employee information, hiring, onboarding, time-off tracking, performance management, reporting, and employee records.

BambooHR is known for its clean interface and straightforward user experience. For businesses that want to move away from spreadsheets and manual HR processes, it provides an accessible way to organize employee data and improve HR visibility.

The platform also includes tools for applicant tracking, onboarding, employee satisfaction, performance reviews, and custom reporting. BambooHR can integrate with many payroll, benefits, productivity, and HR applications, making it a flexible option for growing businesses.

Pricing is available through a customized quote, with packages based on the features and level of support required.

### 2. Gusto

![](https://www.atlantic.net/wp-content/uploads/2026/04/gusto-hr.jpg)

Gusto is a cloud-based HR and payroll platform that is especially popular with startups and small businesses. It combines payroll processing, tax filing, benefits administration, onboarding, compliance support, and employee self-service into one simple platform.

One of Gusto’s main strengths is ease of use. Businesses without a large internal HR department can use Gusto to manage payroll, employee records, benefits, and basic HR workflows without needing a complex enterprise system.

Gusto also supports employee self-service, allowing staff to access pay information, tax documents, benefits details, and onboarding materials. For growing teams, this can reduce administrative workload and make payroll and HR processes easier to manage.

Its pricing structure is designed to support smaller businesses, with the option to move into more advanced plans as the company grows.

### 3. TriNet HR Plus / TriNet Zenefits

![](https://www.atlantic.net/wp-content/uploads/2026/04/trinet_2c_rgb_lg.jpg)

Zenefits is now best understood in the context of TriNet. The platform is commonly referenced as TriNet Zenefits or TriNet HR Platform, while TriNet HR Plus combines HR technology with additional outsourced HR support.

TriNet HR Plus is designed for small and midsized businesses that need help managing payroll, benefits, employee records, compliance, time tracking, attendance, onboarding, and HR administration. It gives companies access to a cloud-based HR platform while also offering support services for businesses that want more guidance around HR, payroll processing, and compliance obligations.

This makes TriNet a practical option for businesses that want more than a self-service HR tool but do not necessarily need a large enterprise HR suite. The platform is particularly relevant for companies seeking technology, payroll, benefits administration, and HR support from a single provider.

Pricing is customized based on company size, selected services, and business needs.

### 4. Freshteam

![](https://www.atlantic.net/wp-content/uploads/2026/04/freshteam.png)

Freshteam, by Freshworks, is an HR software platform built for growing businesses that want to manage hiring and core HR processes in one place. It includes applicant tracking, onboarding, offboarding, employee information management, time-off tracking, and HR workflows.

Freshteam is particularly useful for companies that need to improve recruitment and onboarding. HR teams can manage job postings, candidate pipelines, interview workflows, offer processes, new-hire documentation, and employee records from the same platform.

A key advantage of Freshteam is its connection to the wider Freshworks product family. Businesses already using Freshworks tools may find it easier to connect HR workflows with customer support, sales, marketing, or internal service processes.

Freshteam offers pricing tiers for companies of different sizes, including options for smaller businesses just starting to formalize HR processes.

### 5. Workday

![](https://www.atlantic.net/wp-content/uploads/2026/04/workday-logo.jpg)

Workday is a cloud-based enterprise platform that combines human capital management, finance, planning, analytics, and workforce management. It is widely used by larger organizations that need advanced HR, payroll, talent, finance, and reporting capabilities in one system.

Workday supports a wide range of HR functions, including workforce planning, employee records, payroll, benefits, recruitment, learning, performance management, compensation, time tracking, and analytics. Its strength lies in connecting HR and finance data, giving leaders better visibility into workforce costs, headcount planning, skills, and business performance.

Workday is also investing heavily in AI, [machine learning](https://www.atlantic.net/gpu-server-hosting/8-of-the-most-popular-machine-learning-tools/), and predictive to support workforce planning, automation, and decision-making. For organizations with complex HR operations, multiple locations, and large employee populations, Workday provides a powerful cloud-based platform.

Because of its scope and requirements, Workday is usually best suited to mid-market, enterprise, and global organizations rather than very small businesses.

### 6. ADP

![](https://www.atlantic.net/wp-content/uploads/2026/04/ADP.png)

ADP is one of the longest-established names in payroll and HR services. Originally founded as a payroll processing company, ADP now offers a broad suite of cloud-based payroll, HR, tax, benefits, time tracking, compliance, and workforce management solutions.

ADP is a strong option for businesses that want mature payroll infrastructure and support for tax and compliance requirements. Its platforms can support companies of different sizes, from small businesses to large enterprises with more complex payroll and workforce needs.

The platform includes HR analytics, reporting, employee self-service, payroll automation, benefits administration, and integrations with third-party business systems. ADP also offers managed services and outsourcing options for organizations that want additional support with payroll and HR administration.

For businesses with multi-state, multi-location, or compliance-heavy payroll requirements, ADP remains one of the most established providers in the market.

### 7. Paylocity

![](https://www.atlantic.net/wp-content/uploads/2026/04/paylocity_logo.png)

[**Paylocity**](https://www.paylocity.com/) is a cloud-based HR, payroll, and workforce management platform that helps businesses manage core HR processes from a centralized system. It brings together tools for payroll, tax compliance, benefits administration, employee data management, time tracking, scheduling, recruiting, onboarding, performance management, and employee engagement.

The platform is designed for companies that want to reduce the number of disconnected HR tools and manage more of the employee lifecycle in one place. HR teams can use Paylocity to process payroll, manage employee records, track time and attendance, support recruiting workflows, onboard new hires, and handle benefits-related tasks.

Paylocity also includes employee self-service features, allowing staff to access pay information, request time off, update details, and manage benefits through the platform. For managers and HR teams, this can reduce routine administrative requests and improve visibility across the workforce.

Another notable strength is employee engagement. Paylocity includes tools such as surveys, peer recognition, communication features, and collaboration tools that help businesses improve workplace connection and employee feedback.

Paylocity also supports integrations with a wide range of third-party systems, making it easier for businesses to connect HR, payroll, finance, and workforce workflows. Pricing is customized based on company size, selected modules, and specific business requirements.

### 8. Namely

![](https://www.atlantic.net/wp-content/uploads/2026/04/Namely.png)

Namely is an HR platform designed mainly for mid-sized businesses. It combines core HR, payroll, benefits administration, talent management, compliance support, and employee engagement tools into a single system.

One of Namely’s strengths is flexibility. It provides HR teams with tools to manage employee data, performance reviews, reporting, and engagement while maintaining a user-friendly experience for both employees and managers.

Namely is often a good fit for businesses that have moved beyond basic HR tools but do not need a full enterprise platform. It supports companies that want more structure around HR workflows, payroll, benefits, and employee communications without overcomplicating day-to-day administration.

The platform also includes employee self-service features, allowing staff to access personal information, HR documents, and company updates from a single central portal.

### 9. Sage HR

![](https://www.atlantic.net/wp-content/uploads/2026/04/Sage-HR.png)

Sage HR is a cloud-based HR management platform used by businesses in the UK, the US, Canada, and many other countries. It helps companies manage core HR processes, including employee records, leave management, shift scheduling, timesheets, performance management, expenses, recruitment, and onboarding.

Sage HR can be accessed through an online portal and mobile app, making it useful for businesses with employees in different locations. Its modular structure allows companies to select the features they need rather than paying for a large system from the start.

The platform is particularly useful for small and growing businesses that want a scalable HR system with practical tools for day-to-day administration. Sage HR’s per-employee pricing model also makes it easier for companies to align costs with workforce size.

For businesses already using other Sage products, Sage HR may also fit naturally into the broader finance and business management environment.

### 10. UKG Ready

![](https://www.atlantic.net/wp-content/uploads/2026/04/UKG.png)

UKG Ready is a cloud-based HR, payroll, talent, and workforce management platform designed to help organizations manage people operations from one system. Previously associated with Kronos Workforce Ready, UKG Ready is now part of UKG’s broader workforce and HCM product family.

The platform includes tools for HR administration, payroll, time and attendance, scheduling, talent management, onboarding, reporting, and workforce analytics. It is especially useful for businesses that need reliable time tracking, labor management, and payroll capabilities, along with HR features.

UKG Ready can support small and mid-sized organizations, as well as businesses with more complex scheduling, workforce management, and compliance needs. It is a strong option for companies where labor planning, accurate time capture, and payroll are central to HR operations.

The platform has a broad feature set, so some teams may need training and support to get the most value from it.

## How Can Atlantic.Net Help?

Adopting a leading cloud-based HRMS solution can help your company streamline HR processes, improve employee access to information, reduce manual administration, and strengthen workforce reporting. These platforms can improve data accuracy, automate routine workflows, and support more consistent HR operations across multiple locations.

, HR software is only one part of the broader technology environment. Many organizations also need secure infrastructure for custom HR applications, employee portals, reporting systems, payroll integrations, document storage, analytics databases, identity services, or healthcare-adjacent workflows that may involve sensitive employee information or [protected health information](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/).

Atlantic.Net can help organizations design and host secure, reliable infrastructure for HR, payroll, and compliance-focused workloads. With over 30 years of experience, Atlantic.Net provides cloud, dedicated, and [managed hosting](https://www.atlantic.net/dedicated-server-hosting/what-is-managed-hosting/), backups, monitoring, and professional support for businesses that need secure, dependable infrastructure.

For organizations that handle protected health information, Atlantic.Net offers [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions supported by signed [HIPAA Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/), secure cloud and [dedicated server](https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/) environments, [managed firewalls](https://www.atlantic.net/managed-services/firewall/), encrypted [backups](https://www.atlantic.net/cloud-platform/backups/), intrusion prevention options, and layered administrative, technical, and physical safeguards.

Atlantic.Net is SOC 2 and SOC 3 certified, HIPAA- and HITECH-compliant, and provides 24x7x365 support, monitoring, and high-quality data center infrastructure.

If your business needs secure hosting for HR systems, payroll-related applications, healthcare-adjacent workflows, or compliance-sensitive data, [contact Atlantic.Net today to discuss a customized hosting solution](https://www.atlantic.net/about-us/corporate-contact/).


---

# What Is PIPEDA? 2026 Guide to PIPEDA

> URL: https://www.atlantic.net/hipaa-compliant-hosting/what-is-pipeda-and-who-does-pipeda-apply-to/ | Published: 2026-04-14 | Author: Dr. Rachael Bailey

## **What Is PIPEDA?**

The Personal Information Protection and Electronic Documents Act (PIPEDA), introduced in April 2000, is a Canadian federal law that governs the collection, use, and disclosure of personal information by the private sector. Often referred to as Canada’s federal privacy law, PIPEDA sets the ground rules for how private sector organizations collect, use or disclose personal information in a fair and lawful manner. Similar to the EU’s data protection rules laid out in the General Data Protection Regulation (GDPR), PIPEDA was enacted to ensure the security and privacy of protected data and to promote electronic commerce through responsible data handling and transparent data management practices. PIPEDA operates alongside provincial or territorial governments that may enforce their own privacy laws, provided they are recognized as substantially similar privacy laws under federal standards.

## **What Are the Benefits of PIPEDA?**

PIPEDA provides individuals with a right to:

- Access their personal information
- Challenge and correct the accuracy of any personal information
- Understand who is collecting their personal information and why they are doing so

Additionally, individuals have the right to expect that their personal information is handled in a timely and appropriate manner and safeguarded using appropriate security measures.

These rights are particularly important when collecting personal information, ensuring organizations rely on fair and lawful means and clearly defined purposes.

PIPEDA applies to any private sector businesses and organizations across Canada that process or disclose personal information for the purposes of commercial activity. This includes how private sector organizations collect, store, and manage all the personal information tied to an identifiable individual, including employee personal information and business contact information in some contexts.

PIPEDA also applies to non-Canadian organizations that collect and utilize personal information on behalf of Canadian citizens, particularly in cases involving interprovincial or international transfers of data across provincial or national borders.

PIPEDA does not apply in [Alberta, British Columbia, and Québec](https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/r_o_p/02_05_d_26/). These provinces have their own privacy legislation in place which is substantially similar to PIPEDA. These provincial laws are considered “deemed substantially similar” and operate alongside federal requirements, ensuring alignment with broader Canadian data privacy expectations.

## **What Is Common between PIPEDA and HIPAA?**

There are many shared synergies between the rules of PIPEDA and the legislation of Health Insurance Portability and Accountability Act (HIPAA)-Compliance. Both frameworks emphasize safeguarding personal health information and enforcing strict controls around how organizations collect, use, or disclose sensitive data. In this article, we will discuss if HIPAA-Compliant hosting is compatible with the PIPEDA legislature.

Both laws also reinforce personal health information privacy by requiring organizations to implement safeguards and limit access based on necessity.

## What Are the Ten PIPEDA Principles?

Businesses and organizations that are governed by PIPEDA must comply with the legislation’s [ten fair information principles](https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/p_principle/):

1. **Accountability** – an organization must take full responsibility for the personal data that they store and process
2. **Identifying Purposes** – the organization should confirm its need to collect personal data prior to doing so
3. **Consent** – the organization should obtain “meaningful consent” from an individual prior to data collection
4. **Limit Collection** – organizations must collect only the minimum amount of data necessary for their purpose
5. **Limit Use, Disclosure, and Retention** – data must only be used for its intended and consented purpose
6. **Accuracy** – all stored data must be up-to-date, complete, and accurate
7. **Safeguards** – adequate security measures must be put in place to maintain the integrity and security of data
8. **Openness** – organizations should be transparent about their data collection and handling processes
9. **Individual Access** – individuals have the right to view, assess and correct any information that is held about them
10. **Challenging Compliance** – individuals also have the right to challenge an organization’s compliance with the ten fair information principles

These ten principles form the foundation of personal information protection and electronic documents compliance, ensuring organizations adopt responsible data handling practices and maintain consumer trust.

They also reinforce that collecting personal information must always be justified, limited, and conducted through fair and lawful means.

## How Does PIPEDA Differ From HIPAA?

PIPEDA shares similarities with the United States’ HIPAA regulations. However, there are some key differences between the two legislations:

- HIPAA governs the use and disclosure of patient data within the United States, while PIPEDA relates to Canadian consumer data
- While HIPAA relates only to healthcare data, all forms of consumer data, from any industry, are covered under PIPEDA
- Under PIPEDA law, organizations must obtain consumer consent prior to data collection. HIPAA legislation does not always require a patient’s consent or even their prior knowledge
- HIPAA violations often lead to harsher penalties than PIPEDA breaches

Importantly, PIPEDA applies broadly to federally regulated organizations and businesses engaged in commercial activity, not just healthcare entities handling personal health information.

This includes certain federal government organizations listed under applicable regulations when they engage in commercial data handling activities.

## **How Do You Comply with PIPEDA?**

As made clear in the first of PIPEDA’s ten fair information principles, each organization must take responsibility for its use of personal information and PIPEDA compliance. Suitable policies and procedures must be established to ensure that consumer data is handled correctly.

Organizations must also ensure compliance by implementing structured data management practices, documenting how personal information is collected, and maintaining clear policies around safeguarding personal information.

While the onus is on an organization to adequately secure data, choosing [the right hosting provider](https://www.atlantic.net/vps-hosting/what-is-pipeda-and-how-does-it-affect-hosting-providers/) will make your compliance journey easier. A good hosting provider will help you to address all ten principles, with their main focus being on implementing the necessary safeguards to protect data.

## **What Are the Best Practice PIPEDA Hosting Safeguards?**

PIPEDA’s hosting safeguards principle does not directly specify what particular security safeguards must be implemented on the hosting infrastructure; instead, the [responsibility is placed on the hosting provider](https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/p_principle/principles/p_safeguards/) to “ensure it adequately protects the personal information in its care as technologies evolve and as new risks emerge.” This includes adopting appropriate security measures that align with modern data privacy expectations and addressing risks such as data breaches, unauthorized access, and misuse of credit records or loan records.

What this means is that the principle of safeguards is core to hosting providers because protective tools must be already implemented on the hosting infrastructure. A security policy must be created that encompasses protections to all digital records, preventing unauthorized alteration or use, access, replication, disclosure, loss, or theft.

Methods of protection are categorized in a similar manner to those enumerated in the Security Rule of the Health Insurance Portability and Accountability Act of 1996 (HIPAA). While HIPAA mandates the need for technical, administrative, and physical safeguards, PIPEDA references technical, organizational, and physical requirements of protection.

## Technical Safeguards

- Fully Managed Firewall
- Encrypted Offsite Backups
- Disaster Recovery Services
- Encrypted VPN and Storage
- Multi-Factor Authentication (MFA)
- SSL Certificates

These safeguards support responsible data handling and ensure that organizations collect, use, or disclose personal information strictly within defined and lawful purposes.

### Fully Managed Firewall

Offering a combination of hardware and software-managed firewalls, your network will be secured against unauthorized access and intrusion. For the protection of web servers, an organization may also consider introducing a robust [Web Application Firewall (WAF)](https://www.atlantic.net/hipaa-compliant-hosting/why-waf-configuration-matters-for-the-healthcare-industry/) as part of Atlantic.Net’s[Network Edge Protection](https://www.atlantic.net/managed-services/network-edge-protection/). Additional managed services can be leveraged to create an Intrusion Prevention Service (IPS), perfect for PIPEDA, as this intelligent service scans network traffic already accepted by the firewall, looking for unexpected trends in behavior and automatically logging any incidents. This automated service provides 24×7 protection at the network layer.

### Encrypted Offsite Backups

With data protection of utmost importance, Atlantic.Net offers fully automated onsite and offsite backups with additional replication services. These options can be tailored to meet the specific needs of your organization and can be enabled simply by ticking a checkbox on our Cloud Platform.

### Disaster Recovery Services

One of the key elements of PIPEDA is to ensure that members of the public have the right to view and amend any personal information held on them, an extra managed service offered by Atlantic.Net is a managed DR Service, production workloads can be failed over to a secondary location in the event of a major outage at the primary location. Only this month, a data center in [Strasbourg (Europe) burnt down](https://www.theregister.com/2021/03/10/ovh_strasbourg_fire/), emphasizing the importance of disaster recovery capabilities.

### Encrypted VPN and Storage

To comply with PIPEDA laws, an organization should employ suitable encryption methods to ensure the integrity of their collected and stored data. Atlantic.Net does this in two ways – we encrypt VPN traffic (either site-to-site or remote access) and we encrypt all of our storage platforms with a minimum of AES256 security ciphers.

### Multi-Factor Authentication (MFA)

In today’s climate, protecting data against loss, theft and unauthorized use is paramount. PIPEDA regulations declare that an organization must take “reasonable” measures to protect the integrity of personal data. Implementing MFA into your infrastructure can negate the risk of compromised credentials. MFA is relatively easy to set up, but it is incredibly effective at protecting servers containing data subject to PIPEDA. If a server is compromised, MFA will prevent the hacker from moving sidewards around your network, if indeed they can compromise a server to start with. Providing servers are secured appropriately, this is very unlikely.

### SSL Certificates

Ensuring your site is secured with TLS/SSL certificates will ensure that the user experience is exactly as intended and that data is encrypted, so no snooping of confidential data is possible. Any websites must be transitioned from HTTP to the secure HTTPS protocol. This protocol encrypts all data that is in motion between the client device and the server.

Web designers should know how to install SSL certificates, but you can always work with Atlantic.Net on[SSL-encrypting your site](https://www.atlantic.net/vps-hosting/what-is-ssl-certificate/) since it involves a (relatively simple) server installation.

## Physical Safeguards

- Facility Access Controls
- Workstation Use and Security
- Device and Media Controls

The Physical safeguards refer to how real-life physical controls are implemented to protect servers and end-user devices. Physical safeguards are essential to protect personal information collected and stored on devices, ensuring only authorized personnel can access sensitive systems.

#### Facility Access Controls

Physical access data centers hosting electronic information systems should be limited. Any access must be properly authorized and should be regularly audited. Data Centers should have 24×7 security personnel on-site and local/remote CCTV cameras, and preferably a nondescript secure compound.

#### Workstation Use and Security

Workstations typically include electronic computing devices like desktops or laptops, but the definition can also be extended to devices like smartphones and tablets that can function similarly and store electronic media. Workstations should be protected by adequate [physical safeguards](https://www.avigilon.com/blog/physical-security-guide) that restrict access to PIPEDA information to authorized users

#### Device and Media Controls

This refers to how you control the receipt, removal, and movement of any hardware or electronic media that might hold PIPEDA information out of and within a data center location.

## **What Are the Third-Party and Hosting Specific Guidelines for PIPEDA?**

Similar to the business associates agreement (BAA) requirement for HIPAA compliance within the US healthcare industry, PIPEDA mandates that you must maintain responsibility for all data whenever it is transferred to or handled by a third party.

Organizations must verify that third parties follow responsible data handling and maintain adequate protections, especially when handling personal health information or sensitive business address records.

The rules are not quite as strict as HIPAA’s BAA, which requires a contract. PIPEDA requires that each organization using a third party must check that data protections are properly in place via “contractual or other means.”

Any organization using a cloud provider or hosting service should verify that the system maintains the strictures of PIPEDA compliance – particularly paying attention to the contract language that addresses handling personal data.

## **What Is the 2018 PIPEDA Update?**

Since its original enactment, PIPEDA has mandated that every company operating in Canada must have implemented a data protection program. On November 1, 2018, the data security rules within PIPEDA were updated, mandating further due diligence and enhancing the strictness of the rules. Modern enforcement continues to emphasize breach accountability, requiring organizations to notify affected individuals and report data breaches where there is a real risk of significant harm.

Companies are now required to control and manage all data that is in their systems and to place appropriate access restrictions on systems to reasonably safeguard them. Organizations that handle Canadian citizens’ data, both domestic and foreign, will now need to perform the following new tasks:

- Send out notices to impacted users of any privacy breach that carries with it a “real risk of significant harm to an individual,” such as financial loss
- Report any privacy compromises to Canada’s Office of the Privacy Commissioner
- Maintain records of any privacy breaches

Cloud guidelines from the Office of the Privacy Commissioner were updated on December 14. These guidelines are specific to the cloud; however, they translate well to relationships with any hosting provider. The FAQs state that PIPEDA “does not prohibit cloud computing, even when the cloud provider is in another country.” However, organizations must ensure compliance with provincial privacy laws and ensure data transfers across provincial or national borders maintain equivalent protections. You can use the cloud then – that is very clear. The parameters beyond that are as follows:

- Make sure you get consent from each person
- Protect any data that you gather
- Make sure you collect personal data for appropriate purposes
- Restrict gathering of personal data to your stated purposes
- Make those purposes available to your users
- Make your privacy practices known to users

## **How Can Atlantic.Net Ensure PIPEDA Compliance?**

As a HIPAA-compliant hosting provider, Atlantic.Net can help to ensure that your organization meets, and even exceeds, PIPEDA requirements by providing the necessary technical and physical safeguards for your hosting environment. By supporting secure data handling practices and aligning with personal information protection act standards, organizations can confidently manage sensitive data while maintaining compliance with evolving privacy laws. Atlantic.Net has a data center presence in Canada, and we already provide compliancy hosting from that location for healthcare organizations.

With over 30 years of experience, Atlantic.Net is independently certified and audited by third-party compliance firms. Our fully compliant hosting solutions meet HIPAA, HITECH, PCI, GDPR, and SOC requirements. [Get in touch](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) to find out how Atlantic.Net can help you to meet PIPEDA compliance.

 


---

# How a Cloud Virtual Machine Powers Flexible and Cost-Effective Workloads in 2026

> URL: https://www.atlantic.net/cloud-platform/cloud-virtual-machine-flexible-cost-effective-workloads/ | Published: 2026-04-14 | Updated: 2026-05-04 | Author: Dr. Tehseen Zia

A moment comes in every growing business when the infrastructure question becomes impossible to ignore. A new application needs to be deployed by the end of the week. A development team needs isolated environments to test code without touching production. A database workload keeps spiking unpredictably, and the physical server underneath it either sits idle or gets overwhelmed. That is when the value of a [cloud virtual machine](https://cloud.google.com/learn/what-is-a-virtual-machine?hl=en) becomes clear as a practical solution to a real operational problem. This article explains how cloud virtual machines work, where they deliver value, and what to think about when choosing the right configuration for your workload.

## What a Cloud Virtual Machine Is

A cloud virtual machine (VM) is a software-defined computing instance that runs on physical hardware in a data center, yet is abstracted from it. The underlying server, including its CPU, memory, and storage, is divided among multiple virtual instances. A software application, known as a hypervisor, controls the allocation of physical resources among VMs.

From the user’s perspective, a VM behaves like a dedicated server. You have root access, can choose your operating system, install your software stack, and manage your configuration as needed. The key difference is that the underlying hardware is handled by the hosting provider, while you pay only for the resources you provision or, in some cases, only for what you use.

This is an important distinction because it completely changes the financial side of computing. Rather than making a Capital Expenditure (CapEx) purchase, you are making an Operational Expenditure (OpEx) purchase. In other words, rather than investing in a server that you hope will be suitable for you for the next three years, you pay for the compute capacity you need at the moment. Unlike CapEx, OpEx can also be adjusted at any time, allowing you to scale resources up or down as your requirements change.

## The Flexibility Argument and Why It Holds Up

One of the key advantages of a cloud VM is its flexibility to handle changing workload demands. This flexibility means different things for different workloads. In practice, it is typically achieved through different scaling strategies and environment management. Some of the key [approaches](https://ecosire.com/blog/infrastructure-scaling-load-balancing) are vertical scaling, horizontal scaling, and environment isolation:

- **Vertical scaling:** an increase in the resources allocated to a single VM instance. It includes a mechanism to resize instances by adding more vCPUs, RAM, and storage as requirements grow, and scaling them down as demand declines. This is particularly useful for workloads with predictable growth trends or seasonal peaks.
- **Horizontal scaling:** adding more VM instances to distribute a workload acros**s** multiple nodes. Most modern web applications and APIs are built around this model. Load balancers route traffic across multiple instances, and instances are terminated as traffic declines.
- [**Environmental isolation**](https://www.geeksforgeeks.org/ethical-hacking/what-is-virtual-machine-based-isolation/)**:** It is a less discussed but equally important form of flexibility. It provides a mechanism for development, testing, and production environments to run on separate virtual machines, each configured similarly. This setup helps eliminate the “it works on my machine” problem that often affects teams sharing infrastructure. It provides a mechanism for spinning up a new environment for a project or short-term requirement in minutes without incurring any additional costs.

## Cost-effectiveness: Where the Savings Are Real and Where They Don’t

A VM’s predictable sizing can help control costs, but it requires understanding how billing works and matching your VM configuration to your actual workload.

Most providers offer two primary pricing models: on-demand and reserved (sometimes called committed-use) instances. On-demand instances are billed per hour or per second, with no upfront commitment required. They are well-suited to variable workloads, short-term jobs, and unpredictable traffic patterns. Reserved instances require a commitment of one or three years in exchange for significantly lower hourly rates.

A practical approach for most organizations is to combine both: reserved capacity for steady, always-on workloads, and on-demand instances for peaks and spikes. This helps avoid overcommitting to capacity you do not use or paying high rates for infrastructure that runs continuously.

Storage costs also need careful attention. Cloud VMs usually rely on network-attached block storage, with pricing that varies by performance tier. High-performance NVMe-backed storage costs more than standard block storage.

One of the simplest ways to reduce monthly costs is to match your storage tier to your application’s actual I/O needs, rather than automatically selecting the highest tier. The cost of data leaving the data center, known as [egress fees](https://nzocloud.com/blog/egress-fees/), is often overlooked during initial planning and can show up as an unexpected charge on your invoice. If your application delivers large volumes of data to end users or frequently transfers data between regions, it is important to consider these costs upfront as part of your overall cost model.

## Common Workloads That Fit Cloud VMs Well

Cloud virtual machines are not appropriate for all scenarios. However, there are many common workloads for which cloud virtual machines are most suitable. These include:

- **Web applications and APIs:** Most web applications are well-suited for cloud VMs. The ability to integrate a load balancer and scale horizontally makes them well-suited for applications with variable traffic. Cloud platforms like [Atlantic.Net](https://www.atlantic.net/managed-services/load-balancing/) are built with this model in mind. It provides the ability to scale quickly, guarantee uptime, and handle production workloads.
- **On-premises-to-cloud migrations:** For organizations moving from on-premises to cloud, VMs allow you to rehost applications with minimal code change. This reduces migration risk and shortens deployment time.
- **Development and testing environments:** Development teams using cloud VMs do not have to spend an extra amount on maintaining physical machines. In addition, you can create development environments from snapshots or images. When testing is complete, the instance can be deleted to stop the associated cost.
- **Database servers**: Relational databases, caching layers, and search indexes all run effectively on cloud VMs when configured with the appropriate CPU and memory profile. For workloads with strict latency requirements, choosing a VM with local SSD storage or IOPS-attached storage can make a significant difference.
- **Batch processing and scheduled jobs**: Data transformation pipeline, report generation, and machine learning training runs have defined start and end points. Running them on on-demand VMs means you pay for compute only while the job is running, rather than maintaining dedicated hardware that sits idle between runs.
- **Compliance-regulated workloads**: Businesses operating in healthcare or financial services need infrastructure that supports their regulatory obligations. For these workloads, VMs make it easier to show configuration, patch history, and host-level controls required for audits. For example, Atlantic.Net offers [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) built on its cloud infrastructure. It provides the technical and administrative support organizations need when handling electronic [Protected Health Information (ePHI)](https://www.techtarget.com/searchhealthit/definition/electronic-protected-health-information-ePHI). Similarly, for organizations subject to PCI-DSS requirements, Atlantic.Net’s cloud platform is [PCI-compliant](https://www.atlantic.net/pci-compliant-hosting/), with infrastructure and support designed to help maintain secure environments for payment card data.

## Things Worth Getting Right from the Start

A few configuration choices made early in a deployment can significantly impact both performance and cost.

- **Right-sizing** is the [practice](https://visualoneintelligence.com/right-sizing-in-cloud-computing/) of matching your VM specifications to your actual workload requirements, rather than defaulting to a large available instance. Most cloud platforms provide monitoring tools that show CPU utilization, memory usage, and disk I/O over time. Using this data to choose the right size is a useful way to avoid paying for resources you don’t use.
- **Data encryption in transit** should be standard practice for any cloud workload. Connections between your application and its users, and between internal services, should use [Transport Layer Security (TLS)](https://www.geeksforgeeks.org/computer-networks/transport-layer-security-tls/) protocol. Most modern application frameworks handle this at the library level, but it requires properly configuring your certificates and load balancer.
- **Backup and snapshot policies**: It is worth noting that cloud-based VMs can fail. Automated [snapshots](https://hostafrica.co.za/blog/servers/vm-snapshots-best-practices/) taken on a regular schedule, daily at a minimum for production workloads, are a basic but essential safeguard. Knowing how quickly a snapshot can be restored can be critical in preparation for a potential failure.
- **Network configuration**: Understanding how your VMs are segmented into private and public networks can impact both security and cost. Internal traffic between VMs on the same private network is typically free or low-cost, keeping sensitive data off the public internet. Only the services that genuinely need public access should have public IP addresses.

## Choosing a Provider: What to Evaluate

Not all cloud providers of virtual machines are the same. Depending on your needs, one provider may be better suited to your environment than another. If your organization requires compliance support for HIPAA, [PCI-DSS](https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard), or both, it is essential to consider the provider’s history in these areas. There are some questions worth asking: Does the provider offer a [HIPAA Business Associate Agreement (BAA)](https://www.techtarget.com/healthtechsecurity/feature/What-Is-a-HIPAA-Business-Associate-Agreement-BAA) for HIPAA workloads? What does their shared responsibility model cover? What [SLA](https://www.techtarget.com/searchitchannel/definition/service-level-agreement) applies to compute uptime?

[Atlantic.Net](https://www.atlantic.net/dedicated-server-hosting/reliable-dedicated-hosting-regulated-industries-2026/) has built its cloud hosting platform specifically to serve businesses with these kinds of requirements. They have purpose-built data centers for their infrastructure and decades of experience supporting organizations like theirs. If your organization requires compliance-ready infrastructure but does not want to manage it in-house, Atlantic.Net can be a strong option.

## Conclusion

While cloud virtual machines are not the answer to every problem, they are the answer to a wide variety of real-world infrastructure needs for growing organizations. They strike the right balance between control and flexibility. They are the right environment for teams that need flexibility to adapt to changing workloads without being locked into the cost of underlying hardware.

In 2026, workloads will remain unpredictable in terms of scaling. However, cloud virtual machines are the answer for teams looking for a stable, flexible solution.


---

# HIPAA-Compliant Hosting Requirements 2026 Healthcare Hosting Guide

> URL: https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/ | Published: 2026-04-14 | Updated: 2026-06-23 | Author: Richard Bailey

What should you look for in a reliable HIPAA-compliant hosting provider? Healthcare hosting providers must comply with HIPAA, the Health Insurance Portability and Accountability Act of 1996, which requires them to safeguard and securely store patient records and other protected health information (PHI). Modern HIPAA hosting requirements now emphasize continuous monitoring, risk analysis, and layered security protections to safeguard sensitive data across hybrid and cloud environments. When evaluating [HIPAA-compliant hosting providers](https://www.atlantic.net/hipaa-compliant-hosting/top-hipaa-compliant-hosting-small-businesses-2026/), it is important to understand how well the provider is prepared for HIPAA audits and whether their infrastructure, policies, and operational procedures support ongoing compliance.

## HIPAA-Compliant Hosting Services Checklist

The first step in ensuring HIPAA compliance from your web hosting provider is to review HIPAA-compliant hosting requirements. The following 16-point [HIPAA Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) Checklist covers fundamental considerations. This checklist should also be aligned with current [hipaa guidelines](https://www.atlantic.net/hipaa-compliant-hosting/what-are-hipaa-compliance-rules-and-guidelines/), including implementing security measures that address evolving security risks and threat vectors. While it provides a useful starting point, it should not be considered a complete substitute for a full HIPAA compliance assessment:

- **Documented strategies for data security, access management, and staff training to reduce security incidents**
- **A system for creating unique user IDs and passwords, along with procedures for login, logout, decryption, and emergency access (Blankenspoor)**
- **Policies governing access to physical facilities and electronic systems that store or process [protected health information (PHI)](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/)**
- **Clear procedures for how healthcare data is stored, transferred, disposed of, and restored when necessary**
- **Auditing, logging, and monitoring systems to track data access and detect unauthorized activity**
- **Rules governing hosted data transmission across all scenarios (email, cloud platforms, and other communication channels)**
- **Quality control measures for hosted data, including deletion, modification, and backup management**
- **Reliable data availability to ensure systems remain accessible when required**
- **Separation between web servers, database servers, and production hosting environments**
- **Antivirus protection and [multi-factor authentication](https://www.atlantic.net/managed-services/multi-factor-authentication/) (MFA)**
- **Ongoing management and patching of the operating system (OS)**
- **Use of private IP (Internet Protocol) addresses within a secured hosting environment**
- **Strong [data encryption](https://www.atlantic.net/hipaa-compliant-hosting/encryption-for-hipaa-compliance/) protocols for data at rest and in transit**
- **[Disaster recovery](https://www.atlantic.net/disaster-recovery/disaster-recovery-plan/) and backup strategies, including offsite backups**
- **Network security controls such as firewalls, intrusion detection, and VPN protections**
- **A signed Business Associate Agreement (BAA)**

Click here to learn more about [HIPAA hosting](https://www.atlantic.net/hipaa-compliant-hosting/).

---

![](https://www.atlantic.net/wp-content/uploads/2023/09/What-is-HIPAA-Compliant-Healthcare-Hosting_First-class-Healthcare-HIPAA-hosting-vs.-economy-class-hosting-whats-the-difference-.png)

## First-Class Healthcare HIPAA Hosting vs. Standard Hosting: What’s the Difference?

One of the fundamental realities of the Internet is that applications and services ultimately run on physical or virtual machines, either hosted internally or provided by a third-party service. For healthcare organizations that prefer not to maintain servers in their own data centers, [HIPAA-compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/top-hipaa-compliant-web-hosting-services-for-secure-data-management/) is a practical alternative.

Not all hosting environments provide the same level of security or operational controls. HIPAA compliant servers are specifically designed with privacy and security protections that align with regulatory expectations, unlike standard hosting environments. Security standards and oversight can vary widely across providers; formal guidelines were established to ensure consistent protection of healthcare data. These standards are defined by the U.S. Department of Health and Human Services (HHS) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). As a result, organizations responsible for handling healthcare records must rely on HIPAA-compliant hosting environments, often referred to simply as HIPAA hosting, rather than standard web hosting services.

> “HIPAA recognizes all health care providers and their business associates as covered entities (CEs) and makes them responsible to safeguard the privacy and security of identifying information.” “Some CEs, particularly smaller sized CEs, don’t have the resources necessary to implement a system to handle and safeguard health data on their own, so they rely upon the services of HIPAA hosting.”
>
> Jacco Blankenspoor of HIPAA HQ[i]

Any hosting provider can offer HIPAA-compliant hosting services based on its own interpretation and implementation of healthcare regulatory requirements. Because there is no formal certification, organizations must evaluate providers based on their ability to implement specific security measures and maintain compliance over time. In other words, there is no official federal certification program that formally designates a hosting provider as “HIPAA-certified.” Because of this, the responsibility for evaluating the quality and reliability of the HIPAA hosting infrastructure supporting any hosted service ultimately falls on the healthcare organizations that use those services. In practice, this means healthcare-covered entities must perform their own due diligence to confirm that the hosting environment they rely on meets HIPAA compliance expectations.

Similarly, the federal government does not officially recognize any specific third-party certification bodies for HIPAA hosting providers. This has allowed a competitive ecosystem to develop where providers demonstrate credibility through independent audits and industry-recognized compliance frameworks. At the same time, it also means that [healthcare organizations](https://www.atlantic.net/hipaa-compliant-hosting/healthcare-organizations-embracing-cloud-computing/) must carefully evaluate the credibility of the auditing or certification body involved, as well as understand exactly which controls, safeguards, and review processes are included in that provider’s HIPAA compliance assessment.

---

![](https://www.atlantic.net/wp-content/uploads/2023/09/What-is-HIPAA-Compliant-Healthcare-Hosting_Healthcare-hosting-compliance-responsibilities-are-defined-by-the-HIPAA-Final-Rule.png)

## Responsibilities for Safeguarding Electronic Protected Health Information Are Defined by the HIPAA Final Rule

Given the broader lack of formal standards defining what specifically qualifies as “HIPAA-compliant hosting,” there is at least one important advantage for covered entities. Business associates (BAs), including HIPAA-compliant web hosting providers, are required to safeguard data in much the same way covered entities do. This includes implementing security measures aligned with the HIPAA Security Rule, which defines administrative, physical security, and technical safeguards required to protect patient data. Covered entities include healthcare providers, health plans, and healthcare clearinghouses. This shared responsibility became firmly established following the implementation of the Omnibus HIPAA Final Rule (commonly referred to as the Final Rule or Omnibus Rule), which took effect on March 26, 2013.

Under this rule, business associates that create, receive, maintain, or transmit electronic protected health information (ePHI) are directly accountable for complying with applicable HIPAA security and privacy requirements, rather than relying solely on contractual obligations with covered entities. As a result, hosting providers that support healthcare workloads must ensure that their infrastructure, administrative policies, and technical safeguards align with HIPAA requirements when handling sensitive healthcare data.

> Following passage of the rule, business associates “are liable for PHI uses and disclosures and HIPAA Security Rule compliance.” “Additionally, BAs with their subcontractors, while BAs – not covered entities – are also now responsible for responding to any noncompliant subcontractors.”
>
> Elizabeth Snell of HealthIT Security[ii]

Health and Human Services also established a process for randomly selecting covered entities for HIPAA compliance audits. These audits evaluate whether organizations are properly adhering to the core HIPAA requirements, including the Security Rule, the Privacy Rule, and the Breach Notification Rule. These audits now heavily evaluate risk analysis processes, breach notification procedures, and how organizations respond to security incidents. The purpose of these audits is to assess how healthcare organizations and their partners protect electronic protected health information (ePHI) and whether appropriate safeguards and reporting procedures are in place.

---

![](https://www.atlantic.net/wp-content/uploads/2023/09/What-is-HIPAA-Compliant-Healthcare-Hosting_HIPAA-_-HITECH.png)

## What Is HITECH?

HITECH (the Health Information Technology for Economic and Clinical Health Act of 2009) was introduced to support the transition from paper-based medical records to digital health data while maintaining strong safeguards around patient information. HITECH also strengthened enforcement of the [HIPAA Breach Notification Rule](https://www.atlantic.net/hipaa-compliant-hosting/sharp-focus-on-hipaa-breach-notification-rule/), requiring faster and more transparent reporting of data breaches involving sensitive data. While HITECH outlines how electronic health records can be shared and managed within modern healthcare systems, HIPAA establishes the responsibility for protecting that data. Under HIPAA, any organization or individual that accesses, stores, or processes electronic protected health information (ePHI) is responsible for maintaining its security.

Specific security controls are not rigidly prescribed in every situation. Instead, organizations must conduct regular risk analysis and implement security measures appropriate to their size, complexity, and risk exposure. As Blankenspoor noted, “[T]he HHS allows entities to implement their own chosen methods.” At the same time, established industry best practices play an important role. Healthcare organizations are generally expected to follow widely accepted security approaches or demonstrate that the alternative systems they implement provide an equivalent or stronger level of protection for sensitive healthcare data.

---

![](https://www.atlantic.net/wp-content/uploads/2023/09/What-is-HIPAA-Compliant-Healthcare-Hosting_What-are-examples-of-covered-entities-_-business-associates-.png)

## What Are Examples of Covered Entities and Business Associates?

The term “covered entity” specifically includes all healthcare providers, health plans, and healthcare clearinghouses operating in the United States. Like their business associates who are engaged through a [Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) as required under HIPAA, covered entities must independently comply with all applicable HIPAA regulations.

A Business Associate Agreement defines the responsibilities for protecting patient data between the covered entity and the business associate. It also outlines breach notification procedures and responsibilities under the HIPAA breach notification rule. This agreement establishes how protected health information (PHI) must be handled, secured, and reported in the event of an incident. For this reason, a Business Associate Agreement is an essential requirement when selecting a HIPAA-compliant hosting provider.

In general, covered entities are healthcare organizations and agencies whose core operations involve the use or management of protected health information. A business associate, on the other hand, is an organization that performs services or functions on behalf of a covered entity and may require access to PHI in order to do so. Business associates include hosting providers, SaaS vendors, and any organization handling patient data on behalf of healthcare services. HIPAA-compliant hosting providers are one example of a business associate under HIPAA. Other examples that typically require a Business Associate Agreement include [medical billing providers](https://technologyadvice.com/medical-billing-software/) and document shredding companies that handle sensitive healthcare records.

---

![](https://www.atlantic.net/wp-content/uploads/2023/09/What-is-HIPAA-Compliant-Healthcare-Hosting_Healthcare-hosting-HIPAA-violations-can-result-in-jail-time.png)

## HIPAA Violations Can Result in Jail Time

As with any regulatory requirement, some organizations may consider avoiding the investment required to meet HIPAA compliance standards. However, failure to implement adequate data security and security protections can result in severe financial and legal consequences. Under the law, intentionally failing to comply with HIPAA requirements is referred to as *willful neglect*. Financial penalties for this type of violation generally range from $10,000 to $50,000 per incident, with an annual maximum of $1.5 million per organization. Organizations that fail to address known security risks or ignore required safeguards may face higher penalties and increased scrutiny. In severe cases, particularly where willful neglect results in the exposure of sensitive patient data, criminal penalties, including potential jail time, may also apply.

Not all violations are categorized as willful neglect. In some cases, they may fall under the definition of *reasonable cause*. These situations typically involve circumstances where safeguards were insufficient or procedures were not properly followed, leading to the exposure of protected health information. For example, incidents involving the exposure of 500 or more individual medical records can result in fines ranging from $100 to $50,000 per violation. However, violations categorized under reasonable cause are generally not associated with criminal penalties or jail time.

![](https://www.atlantic.net/wp-content/uploads/2023/09/What-is-HIPAA-Compliant-Healthcare-Hosting_Top-10-HIPAA-Fines-by-Settlement-Through-2019.png)

## Top 11 HIPAA Fines by Settlement 2014-2024

![Top HIPAA Fines](https://www.atlantic.net/wp-content/uploads/2023/09/HIPAA-Fines-2024.png)
 Sources: Compliancy Group and the HIPAA Journal.

It is worth noting that 6 of the 11 largest HIPAA settlements occurred in 2018, 2020, 2021, or 2024. These cases highlight how enforcement activity has intensified in recent years as regulators continue to scrutinize how healthcare organizations and their partners handle sensitive patient data. Recent enforcement trends show a growing focus on access management failures, weak network security, and inadequate breach response processes. The largest HIPAA settlement to date occurred in 2018, when Anthem agreed to pay a [$16,000,000 fine](https://www.hhs.gov/about/news/2018/10/15/anthem-pays-ocr-16-million-record-hipaa-settlement-following-largest-health-data-breach-history.html) following a major data breach that exposed the protected health information of millions of individuals.

---

![](https://www.atlantic.net/wp-content/uploads/2023/09/What-is-HIPAA-Compliant-Healthcare-Hosting_The-HHS-audit-program.png)

## The HHS Audit Program

The random audit initiative began with a pilot program that involved 113 companies and organizations across the healthcare sector. Today, audits increasingly assess how organizations implement security measures, manage data access, and document compliance with HIPAA guidelines. This initial phase enabled the U.S. Department of Health and Human Services (HHS) to better evaluate how organizations were approaching HIPAA compliance and identify both effective practices and common areas of noncompliance. The insights gathered during the pilot program helped shape how HHS conducts compliance reviews and how enforcement actions are applied when violations occur.

> “[Atlantic.Net’s] financial strength and proven track record are something we view with great confidence.”
>
> Joseph Nompleggi, Vice President, Complete Healthcare Solutions

---

![](https://www.atlantic.net/wp-content/uploads/2023/09/What-is-HIPAA-Compliant-Healthcare-Hosting_What-is-the-HIPAA-Security-Rule-.png)

## What Is the *HIPAA Security Rule*?

The Privacy Rule focuses on safeguarding patient health information, including electronic health records. The Security Rule is particularly relevant in the context of HIPAA-compliant hosting because it establishes more detailed requirements for the storage, protection, and transmission of health data, especially for electronic protected health information (ePHI). The security rule defines how organizations must protect electronic PHI through administrative, physical security, and technical controls.

The [HIPAA Security Rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/) is organized into three primary safeguard categories: Administrative Safeguards, Physical Safeguards, and Technical Safeguards. These safeguards collectively ensure strong data encryption, access management, and network security across healthcare systems. Over time, the Security Rule has become increasingly important as healthcare organizations rely more heavily on digital systems, cloud infrastructure, and modern data management technologies.

As Blankenspoor explains, “*The same standards for the privacy and confidentiality of healthcare data apply to PHI and ePHI, but the processes used to keep data private are much more complex and technical for electronic data files and ePHI than they are for paper files.*”(iii)

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) required the Secretary of the U.S. Department of Health and Human Services (HHS) to establish regulations designed to protect the privacy and security of certain health information. To meet this requirement, HHS introduced the HIPAA Privacy Rule and the HIPAA Security Rule, now commonly known. The Privacy Rule, formally known as the *Standards for Privacy of Individually Identifiable Health Information*, establishes national standards for protecting certain types of health information. The Security Rule, known as the *Security Standards for the Protection of Electronic Protected Health Information*, establishes a national framework for securing health information that is stored or transmitted in electronic form.

The Security Rule builds upon the protections defined in the Privacy Rule by addressing both technical and non-technical safeguards that covered entities must implement to secure individuals’ electronic protected health information (ePHI). Within HHS, the Office for Civil Rights (OCR) is responsible for enforcing the Privacy and Security Rules through compliance oversight, voluntary resolution efforts, and civil monetary penalties when violations occur.

How Can You Get Healthcare Hosting That’s HIPAA-Compliant Right Now?

Are you evaluating [HIPAA-compliant cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and storage providers for your business, but not sure where to start? Atlantic.Net’s HIPAA-compliant hosting is HIPAA-Audited, HITECH-Audited, and backed by SSAE 18 (formerly SSAE 16) SOC 1 Type II and SOC 2 Type I reports. We can assist with healthcare hosting, from design to deployment, so you can continue to focus on your core business. Contact us today for a free healthcare hosting consultation

![](https://www.atlantic.net/wp-content/uploads/2023/09/What-is-HIPAA-Compliant-Healthcare-Hosting_Healthcare-Hosting-Checklist.jpg)

---

[i] [HIPAA compliant hosting explained](https://www.hipaahq.com/hipaa-compliant-hosting-explained/)

[ii] [http://healthitsecurity.com](http://healthitsecurity.com/)

[iii][laws regulations](https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html)

---

Updated 25th March 2026

**Related Guides:**

- [HIPAA Compliant Hosting Solutions](https://www.atlantic.net/hipaa-compliant-hosting/)
- [PCI-Compliant Hosting Solutions](https://www.atlantic.net/pci-compliant-hosting/)
- [What Are Managed Services?](https://www.atlantic.net/managed-services/what-are-managed-services/)

**Related Products:**

- [Atlantic.Net Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/)
- [Atlantic.Net HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)
- [Atlantic.Net GPU Hosting](https://www.atlantic.net/gpu-server-hosting/)


---

# Top 10 Firewalls in 2026 Choosing the Best Firewall Solution

> URL: https://www.atlantic.net/hipaa-compliant-hosting/top-10-firewalls/ | Published: 2026-04-14 | Updated: 2026-06-23 | Author: Richard Bailey

## **What Is a Firewall?**

A network firewall is the first line of defense for your business; it’s the frontline against the ever-present threat of cyberattacks. A modern firewall protects not just your local network but also cloud applications, remote users, and multi-cloud networks from evolving cyber threats.

With the rise of remote work and the increasing sophistication of hackers, choosing the right firewall is more critical than ever.

Today’s best firewall solutions combine firewall protection, intrusion prevention, and deep packet inspection to secure network connections and sensitive data in real time.

In this article, we will introduce the top 10 firewall solutions available on the market, from industry leaders like Cisco and Fortinet to open-source options like pfSense. We’ll also explore Atlantic.Net’s robust [Web Application Firewall](https://www.atlantic.net/vps-hosting/waf-web-application-firewall/) and how it can seamlessly integrate with your chosen firewall for comprehensive protection. Whether you’re securing a small business or a large enterprise, this guide will help you find the perfect firewall to safeguard your network.

## **Top Firewall Solutions**

Choosing the best firewall solution for your business or organization’s [HIPAA Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) or [PCI Compliant Hosting](https://www.atlantic.net/pci-compliant-hosting/) can prove difficult. Many firewalls now include advanced features such as threat intelligence, [network monitoring](https://www.atlantic.net/hipaa-compliant-hosting/top-10-network-monitoring-software-solutions/), and automated security patches to maintain consistent security across hybrid environments. In this article, we have compiled a list of the top 10 firewalls on the market to help make this choice easier for you.

## 1. Atlantic.Net Web Application Firewall (WAF)

Atlantic.Net offers a robust Web Application Firewall as part of our [Network Edge protection](https://www.atlantic.net/managed-services/network-edge-protection/). This cloud firewall security solution inspects internet traffic in real time and blocks suspicious activity using advanced threat intelligence and intrusion prevention techniques. The WAF examines web traffic looking for suspicious activity; it then automatically filters out illegitimate traffic based on rulesets that Atlantic.Net applies for you or custom rulesets applied at your request.

The WAF looks at both GET and POST-based HTTP requests and applies a rule set, such as the ModSecurity core rule set covering the OWASP Top 10 vulnerabilities, to determine what traffic to block, challenge or let pass. It also helps protect against phishing attacks, malicious sites, and other online attacks targeting web applications. The WAF is perfect for web servers. It features intelligent protection that can block zero-day exploits at the firewall layer, giving your system admins time to plan the fixes to the server infrastructure.

## 2. Cisco’s ASA and vASA

The Cisco Adaptive Security Appliance (ASA) is a common sight in the data center as it is a unified threat management device, combining several network security functions in one appliance. It delivers strong protection with integrated VPN, antivirus software, and intrusion prevention to secure network traffic across distributed environments. ASA and vASA boast firewall, antivirus, intrusion protection, and VPN capabilities. The appliance is user-friendly, powerful, and super reliable. The only negative is a high price tag for the appliances and licensing.

The ASA product line contains several models, each with a different capacity and price point. The ASA is managed by an easy-to-use Adaptive Security Device Manager (ASDM). One of the most popular features is the near real-time Syslog viewer.

## 3. Juniper SRX and vSRX

SRX is Juniper Networks’ latest generation services platform. These next generation firewalls provide granular control over outbound connection policies, helping advanced users secure complex network architectures. The firewall combines the advanced Junos operating system with popular security offerings on a high-speed, feature-rich platform. The Series Services Gateways are high-performance network security solutions for enterprises and service providers that deliver security, routing, and networking capabilities. It is also available as a virtual appliance known as vSRX.

## 4. Fortinet Fortigate

Fortinet FortiGate firewalls enable security-driven networking capabilities that focus on security, specifically its intrusion prevention system (IPS), web filtering, secure sockets layer ([SSL](https://www.atlantic.net/vps-hosting/what-is-ssl-certificate/)) inspection, and automated threat protection. FortiGate’s next generation firewalls also support SD-WAN, cloud firewall deployments, and deep packet inspection for high-performance network security. FortiGate’s next-generation firewalls provide high-performance, multilayered security and end-to-end protection across the network.

## 5. SonicWall

SonicWall next-gen firewalls feature advanced threat protection at the heart of the design, and SonicWall offers a range that is suitable for all businesses. These security solutions include real time protection, anti phishing tools, and advanced [malware](https://www.atlantic.net/hipaa-compliant-hosting/what-is-malware-how-it-works-and-how-to-remove-it/) protection for small businesses and large enterprises alike. The SOHO series is great for SMBs and branch offices, the NSa firewalls are great for big business, and the NSsp range is designed for the big players such as cloud providers and large distributed enterprise organizations. The SonicWall key feature is Real-Time Deep Memory Inspection (RTDMI) that uses deep learning to intelligently protect against vulnerabilities and ransomware.

## 6. Untangle NG Firewall

The Next-Gen (NG) Firewall comes in a light-free version or a fully-featured paid edition. It is a software-based firewall that offers flexible deployment across virtual machines and different platforms, making it ideal for hybrid environments. It has probably the best-looking user interface out there with a robust, information-rich dashboard. Features can be enabled and disabled on demand, but most are behind a paywall, requiring a subscription to untangle services.

NG Firewall’s main features focus on securing web applications, preventing malware, phishing, and more. It also includes parental controls, network monitoring, and detailed analytics for tracking suspicious activity. It has great filtering capabilities and a feature-rich analytics engine that can display exactly what you need from the logs.

## 7. Checkpoint

Checkpoint is another very popular maker of firewalls, arguably those with the best user interface: simple to use, but extremely powerful. Checkpoint next generation firewalls deliver consistent security across cloud applications, data centers, and mobile devices. The Check Point Firewall is part of the Software Blade architecture that supplies “next-generation” firewall features, including [VPN](https://www.atlantic.net/vps-hosting/what-is-vpn/), Intrusion Prevention, and mobile device connectivity.

Checkpoint was the first company to use stateful inspection of packets (what comes in must go out), and its firewalls are hugely popular in cloud architecture.

## 8. WatchGuard Firebox

Designed in Seattle, WatchGuard Firebox Firewalls come in 4 form factors. All Fireboxes are suitable for small- and medium-sized businesses. They provide strong protection for home network and business environments, including Wi Fi security, VPN encrypts traffic, and SD-WAN capabilities. They offer VPN connectivity and PoE for effortlessly expanding WIFI network and SD-WAN connectivity. Security is paramount on WatchGuard firewalls, and these devices are feature packed with strong network throughput and enterprise-grade security out-of-the-box.

## 9. PFSense

PFSense is a hugely popular open-source distribution. It is often considered one of the best firewall options for advanced users due to its granular control, customization, and free version availability. PFSense offers software appliances and also sells enterprise firewalls to businesses. It’s a completely customizable distribution of FreeBSD specifically tailored for use as a firewall and router.

PFSense is entirely managed via web interface and includes a fully featured firewall, router, and VPN solution for network edge protection and cloud secure networking. You get stateful packet inspection, GeoIP blocking, anti-spoofing, NAT Mapping, policy-based routing, IPV6 support, an IPS, Packet Analyser, VPN, IPSec, Dynamic DNS, and so much more… not bad for free!

## 10. OPNSense

Another open-source firewall is OPNSense, another FreeBSD distribution. It is a direct fork from PFSense, so it shares many of the same features. It is widely used as a cloud firewall and security service for protecting sensitive information across distributed networks. It is a web application firewall that focuses on intrusion protection, application control, web filtering, and antivirus. OPNSense is primarily used in virtual installations, it’s lightweight and very responsive.

You also get extra features such as support for multi-WAN, VPN, hardware failover, and two-factor authentication; it also offers free web filtering with Sunny Valley Networks, which is rare in a firewall solution.

## How Can Atlantic.Net Help?

Are you looking for a leading [hosting provider](https://www.atlantic.net/hosting-services-provider/) to host your firewall solution? Look no further than Atlantic.Net. Atlantic.Net provides a complete security solution with firewall protection, VPN support, and secure data centers designed to [protect sensitive data](https://www.atlantic.net/hipaa-compliant-hosting/protecting-patient-data-the-right-way-and-the-wrong-way/) and maintain data security.

With over 30 years of proven experience, our [full suite of managed services](https://www.atlantic.net/managed-services/) and always available professional support team can build the perfect solution for your business or organization. You can find out more about our leading [Web Application Firewall here](https://www.atlantic.net/managed-services/firewall/).

Atlantic.Net stands ready to help you attain fast compliance with a range of certifications, such as [SOC 2](https://www.atlantic.net/hipaa-compliant-hosting/ssae-16-soc-1-soc2-care/) and SOC 3, HIPAA, and HITECH, all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, visit us at www.atlantic.net, call 866-618-DATA (3282), or email us at [sales@atlantic.net](mailto:sales@atlantic.net).

---

#### Read More About Firewalls

- [Managed Firewall](https://www.atlantic.net/managed-services/firewall/) Service from Atlantic.Net
- [What Is a WAF?](https://www.atlantic.net/vps-hosting/waf-web-application-firewall/)
- [Cloud Data Breaches](https://www.atlantic.net/vps-hosting/are-data-breaches-in-the-cloud-getting-better-or-worse/)

---


---

# SQL Server High Availability: Architecture & Failover

> URL: https://www.atlantic.net/cloud-platform/sql-server-high-availability-architecture-failover-options/ | Published: 2026-04-14 | Author: Robert Agar

### Introduction

SQL Server downtime affects applications, reporting, transactions, and user access. Companies evaluating SQL Server high availability need to understand architecture choices, failover behavior, recovery expectations, and operational support before choosing a hosting or managed services provider.

## What Is SQL Server High Availability?

SQL Server high availability (HA) refers to specific Microsoft SQL Server features and architectures designed to ensure that data remains accessible despite hardware or software faults and maintenance activities. The goal is to enable applications to continue reading and writing data in the event of server, storage, network, or site failure

The core objectives of SQL Server high availability are:

- Minimizing downtime for SQL Server workloads.
- Ensuring production databases remain available despite server or infrastructure failures;
- Maintaining access to business-critical databases during operational disruptions.

Companies must differentiate between uptime planning for availability and basic backup to support recoverability. These two essential activities address different types of failures and are driven by different time constraints.

### Uptime planning

Uptime planning is a strategy designed to keep systems running continuously despite hardware failures, network outages, SQL Server instance crashes, and other data center incidents. Its primary goal is to eliminate downtime and maintain data availability with minimal recovery point and time objectives.

Core characteristics of uptime planning include:

- Redundancy with multiple servers, power sources, network paths, and multi-region deployment;
- Automatic failover mechanisms;
- Load balancing to avoid server overload.
- Monitoring for real-time issue detection and response.

### Basic backup

Backups are periodic copies of SQL Server data necessary for data protection. The goal is to support data redundancy and recovery from loss or corruption, such as accidental deletion or ransomware attacks. Teams typically work with longer recovery point and time objectives ranging from minutes to days.

Core characteristics of basic backup include:

- Point-in-time snapshots taken at defined time intervals;
- Offline or cold storage to separate backups from production data;
- Versioning to quickly roll back to previous states.
- A viable manual or automated restore process.

## Why SQL Server High Availability Matters for Business-Critical Workloads

SQL Server HA is essential to maintain business-critical database availability. Organizations require a high-availability solution to support a range of workloads.

- Transactional applications that perform business processes in real time, such as banking and e-commerce, require continuous availability to fulfill user requests.
- A company’s ERP and CRM solutions are elements of its business strategy and must be available to maintain productivity and capitalize on emerging opportunities.
- Many companies deploy SQL Server for critical line-of-business systems that must remain available to avoid financial losses.
- Customer-facing applications, such as user databases, must remain available to ensure reliable client connections and high customer satisfaction.
- Organizations running compliance-sensitive workloads may be subject to strict availability requirements that, if not met, can result in legal and financial penalties.

## Core SQL Server High Availability Options

Microsoft includes several SQL Server availability features, but they protect different scopes and solve different problems. Availability Groups (AGs) protect one or more user databases and can support high availability and disaster recovery. Failover Cluster Instances (FCIs) protect the entire SQL Server instance. Log shipping is primarily a manual disaster recovery method based on transaction log backups. At the same time, replication is primarily intended to distribute data to other systems rather than providing failover for the primary workload.

### Always On Availability Groups (AGs)

AGs replicate one or more user databases to secondary replicas. They support synchronous-commit and asynchronous-commit availability modes and can provide automatic failover when the primary and target secondary are configured correctly, and the secondary is synchronized. AGs also support a listener for a stable client connection endpoint and can fail over multiple databases within the same group.

SQL Server Standard Edition supports Basic Availability Groups, while Enterprise Edition adds advanced AG capabilities, including multiple databases per group, additional secondary replicas, readable secondaries, and backup offloading. Because AGs protect databases rather than the full SQL Server instance, instance-level objects such as logins, jobs, and some server-level settings require separate planning. AGs are usually the best fit for modern, business-critical workloads that need database-level HA and may also need DR.

### Failover Cluster Instances (FCI)

FCIs provide instance-level high availability for the entire SQL Server instance, including databases, logins, SQL Server Agent jobs, and instance-level configuration. An FCI runs across multiple Windows Server Failover Clustering nodes, but only one node owns the instance at a time.

Unlike AGs, an FCI uses shared storage across nodes for database and log files, and applications connect via the FCI’s virtual network name rather than the active node name. In multi-subnet deployments, the FCI can use a virtual IP in each subnet while preserving the same client-facing name. FCIs are often a strong fit for workloads that depend on instance-level objects or legacy applications that are difficult to redesign around database-level failover.

### Database Mirroring

Database mirroring is a legacy, per-database technology that Availability Groups have effectively superseded for new designs. It can still appear in older environments, but it should generally be avoided for new SQL Server HA deployments.

### Log Shipping

Log shipping sends transaction log backups from a primary database to one or more secondary databases and restores them on a schedule. It is simple, proven, and commonly used as a cost-effective disaster recovery option, but failover is a manual process, and recovery characteristics depend on how often logs are backed up, copied, and restored

### Replication

SQL Server replication is primarily a data distribution technology built around Publishers, Distributors, and Subscribers. It can be for reporting, scale-out reads, or moving selected data to other systems, but it is not a substitute for AG or FCI failover.

## Always On Availability Groups

AGs are SQL Server’s primary HA and DR feature designed to support modern businesses with mission-critical workloads. An Availability Group is a logical container of databases that fail over together between replicas. Key AG components include:

- The primary replica, which handles read/write operations;
- Secondary replicas that maintain copies of databases;
- An availability group listener provides a single connection endpoint for users.
- A Windows Server Failover Clustering (WSFC) layer to orchestrate failover and quorum.

Basic AGs available in SQL Server Standard Edition are limited to one database per AG and one secondary replica with no read scaling.

Enterprise AGs hold multiple databases per AG, multiple secondary replicas, backup offloading, and read-only replicas.

AGs support automatic failover in seconds with synchronous replication as well as manual failover with asynchronous replication for DR and planned maintenance scenarios. This HA approach delivers database-level replication and read scaling with read routing to secondary database replicas.

## Failover Cluster Instances

FCIs provide instance-level high availability, protecting the entire SQL Server instance, including logins and SQL Server Agent jobs. An FCI is a single SQL Server instance installed across multiple nodes in a cluster. Only one node is active at any time.

The failover cluster instances approach to high availability relies on its shared storage model. There is no replication, as all nodes operate on the same shared data.

FCI is a preferred solution when full instance protection is required for applications that rely on SQL logins, jobs, and instance-level configurations. It requires minimal application changes but relies on a reliable shared storage infrastructure, which introduces a single point of failure.

## Database Mirroring, Log Shipping, and Replication

Companies supporting mission-critical SQL Server HA environments typically choose an AG or FCI approach rather than database mirroring, replication, or log shipping. These alternate HA strategies provide limited functionality and are not suitable for automatic failover. , they can support data redundancy, warm standby, and reporting without querying the primary replica.

Microsoft has deprecated database mirroring, and it should only be used to support legacy deployments. Replication is useful for data distribution by replicating transactions from a publisher database to multiple servers, but it does not directly support HA.

Log shipping supports manual failover and is a common part of a disaster recovery solution. Teams ship transaction log backups and restore them sequentially to a secondary server. This approach provides slower recovery with RPO controlled by backup frequency.

## Automatic vs Manual Failover

SQL Server HA environments can ensure data availability with either automatic or manual failover. The primary difference lies in how the failover is initiated, as well as its speed and predictability.

### Automatic failover

In automatic failover, the system detects a failure through health checks and automatically switches to a secondary replica. No human intervention is required as a synchronized secondary replica is automatically promoted, and client connections are redirected. Recovery time is near zero with synchronous commit mode, minimizing downtime for business-critical applications.

Teams must support automatic failover with synchronous data replication and configure multiple nodes via AGs or FCIs. They must ensure proper quorum configuration to avoid split-brain situations where multiple nodes remain active after losing communication and assume the primary role. This situation can result in data corruption, inconsistency, and application outages.

Automatic failover ensures consistent, repeatable failover performance and eliminates reliance on human intervention. Teams must carefully configure health-check failure-detection thresholds to avoid excessive failovers caused by transient network issues. Businesses running real-time processing and latency-sensitive workloads benefit from automatic failover.

### Manual failover

An operator or database administrator initiates a manual failover. They evaluate the system state, validate the primary node status, and the data synchronization state. The database administrator then manually executes the failover command to a secondary node. Recovery speed depends on the team’s response time. Companies typically use manual failover for disaster recovery and to support scheduled maintenance.

Teams have full control over manual failover, eliminating the consequences of unnecessary automatic failovers. Manual failover can be safer in complex environments, but is slower than automatic alternatives. It may be affected by human error and requires continuous operational readiness to protect business-critical systems.

Organizations must consider the operational tradeoffs associated with automatic and manual failover. Automatic failover offers better speed and consistency. Manual failover gives teams more control, allowing them to exercise their judgment before failing over.

Companies must adopt AGs with synchronous replicas or FCIs to support automatic failover. Businesses using a log shipping approach are limited to manual failover. Teams should choose an HA option that aligns with their failover strategy.

Decision-makers must evaluate the failover options available from potential SQL Server HA hosting providers. The evaluation is especially important in a managed services setting where the vendor’s technical team may be an essential component of the failover strategy.

## Understanding RTO and RPO in SQL Server HA

Recovery time objective (RTO) and recovery point objective (RPO) are critical considerations in managing an SQL Server HA environment. The two objectives typically serve as the foundation of an organization’s disaster recovery plan and are incorporated into uptime planning and backup scheduling.

- RTO is the maximum allowable time an SQL Server can be down or unavailable following a failure or disaster. Teams must restore systems within the defined RTO to avoid business damage. For example, an RTO of two hours means the systems must be recovered within two hours or risk negative business consequences.
- RPO represents the maximum allowable data loss a company can tolerate during a disaster. Companies define an RPO to indicate how far back data must be restored to resume operations with minimal impact. The RPO is measured in time and is tightly bound to the backup schedule. For example, an RPO of one hour requires hourly backups, whereas an RPO of 24 hours means daily backups are sufficient.

An organization’s possible RTOs and RPOs are influenced by the SQL Server HA architecture it deploys. Companies that need fast, automatic failover to meet fast recovery objectives will benefit from an AG or FCI architecture. Organizations with less stringent recovery goals may opt for the cost-effectiveness of a log shipping configuration.

Prospective customers should request realistic RTO and RPO targets that align with their SQL Server environment and business requirements. Providers should offer firm uptime guarantees backed by service level agreements (SLAs).

## Synchronous vs Asynchronous Replication

The way transactional replication is performed directly affects a company’s RPO, failover methodology, and data latency profile. SQL Server supports synchronous and asynchronous replication. The two methods exhibit multiple key differences.

In synchronous replication, a transaction is not committed on the primary replica until it has been written to and acknowledged by the secondary replica. This approach results in zero data loss and strict RPOs. Automatic failover is supported for minimal RTOs with strong consistency across synchronized replicas. Synchronous replication is sensitive to network performance and may increase commit latency, making it a poor choice for long-distance replication.

Asynchronous replication commits transactions to the primary replica immediately without waiting for an acknowledgment from the secondary replica. This strategy introduces the risk of data loss and does not support a zero RPO. RTO depends on manual failover, and achieving consistency across replicas may take some time. Asynchronous replication enables companies to minimize transaction latency, support higher throughput, and replicate across long distances.

Organizations typically employ synchronous replication for:

- High-value online transaction workloads;
- Financial systems that require strict consistency;
- HA environments within the same data center.

Asynchronous replication is favored for:

- Creating replicas for reporting and backup;
- Supporting disaster recovery across regions;
- High-performance systems that can tolerate some inconsistency.

Companies need to develop disaster recovery plans that incorporate the appropriate replication type to meet business requirements. In some cases, organizations may use both types of replication to address business needs.

## Single Datacenter vs Multi-Datacenter High Availability Designs

Organizations implementing high-availability SQL Server environments can opt to house it in a single or multiple data centers.

In the single-data-center design, two or more HA nodes are in the same physical facility or availability zone. High-bandwidth networks connect the nodes with automatic failover enabled. The nodes’ proximity supports synchronous replication with minimal latency.

Advantages of this approach include fast failover, data redundancy and consistency, lower operational costs, and simpler networking. It does not protect companies from regional disasters or outages that affect the entire data center.

A multi-data-center, geographically distributed HA approach eliminates the single data center point of failure and supports disaster recovery and business continuity. Companies maintain an active primary site with an active or standby secondary site. They typically employ asynchronous replication and manual or controlled failover.

Performance may be affected by latency, making synchronous replication impractical. Teams implementing this approach face increased potential data loss and slower failover. This HA strategy safeguards businesses from full data center failures and regional outages.

Many companies use a hybrid model that combines both HA approaches. They implement local HA within a data center, using synchronous replicas and automatic failover to ensure zero data loss. A second data center is maintained for disaster recovery, with asynchronous replicas activated by a manual failover.

## Listener Endpoints and Application Connectivity

The listener endpoint is the SQL Server HA abstraction layer that decouples applications from physical database nodes. The listener provides a single logical database endpoint to support failover and application connectivity. It routes incoming connections to the current primary replica. The listener moves with the primary replica during failover.

Listener endpoints provide multiple benefits supporting application connectivity, including:

- Eliminating hardcoded server dependencies where applications must know the current active node;
- Streamlining failover to reduce downtime and misrouted traffic;
- Supporting read/write routing for workload isolation and read scaling.

The use of availability group listener endpoints simplifies operations by eliminating the need to reconfigure systems to point to active nodes. Users can always reliably connect to the primary database, enhancing resilience during failovers.

## Managed SQL Server High Availability vs Self-Managed Deployment

Customers using cloud-hosted SQL Server HA solutions have the following options for managing their environments.

- The organization can own the infrastructure and support it with an in-house technical team and database administrators. This approach offers companies the most control over the environment, but requires a degree of technical skills.
- Customers work with their hosting provider in the co-managed model, where each entity is responsible for well-defined aspects of the environment’s management.
- Providers may offer full managed hosting, in which they provide all technical resources necessary to manage SQL Server HA solutions.

Many businesses running critical SQL Server applications lack the technical expertise to manage their environments securely and efficiently. Reliable managed service providers can perform many functions that allow companies to focus on their core business, including:

- Monitoring the environment for performance;
- Implementing a patching regimen to keep systems up to date.
- Backing up systems for disaster recovery and resilience;
- Providing manual failover readiness to ensure SQL Server availability;
- Detecting and responding to security incidents to protect the environment.

## Monitoring, Backups, and Disaster Recovery Still Matter

Companies must protect their SQL Server HA environment with additional measures. High availability is not the same as data protection through backups, though copies of database objects are necessary for failover. Organizations need to implement viable backup operations that include the backups of the physical server running the SQL Server instances. Data-handling regulations, such as HIPAA and PCI DSS, mandate data retention policies to ensure compliance and avoid penalties for noncompliance.

High availability and disaster recovery are distinct concepts essential to modern business continuity. They address different types of failures and different time constraints. HA is primarily concerned with minimizing downtime and keeping systems continuously available during routine failures. Disaster recovery solutions are designed to restore business operations after catastrophic events that go beyond the capabilities of high-availability mode.

Support teams, whether in-house or vendor-provided, must perform complete monitoring to detect and address issues before they impact business operations. They must be ready to carry out their responsibilities if a failover is required or a disaster is declared.

## Choosing the Right SQL Server High Availability Strategy

Decision-makers should carefully consider the following factors when choosing the right SQL Server high-availability solution.

- Workload criticality: Businesses with critical SQL Server workloads may desire the speed and consistency of an AG architecture with automatic failover and synchronous replication consistency. Teams needing instance-level protection should favor FCI.
- Budget: Companies with tight budgets may not have the financial resources to implement an AG or FCI architecture. Log shipping offers the most cost-effective HA option, but provides slower failover and introduces the possibility of data loss.
- Performance sensitivity: Organizations with performance- or latency-sensitive SQL Server systems may benefit from architectures that use asynchronous replication, which are not affected by variations in network throughput.
- Failover requirements: Businesses that desire automatic failover to maintain SQL Server availability must allocate the resources to implement an AG or FCI architecture.
- Geographic resilience needs: Companies that require resilience across multiple geographic locations or regions need a solution built on asynchronous replication or log shipping.
- Internal staffing and DBA: Support staff’s skill set and experience must be considered. Implementing an AG solution requires greater skill than implementing log shipping.

## Managed SQL Server Hosting Options

Atlantic.Net has effective solutions for customers’ SQL Server HA environments. We offer bare-metal servers that give you complete control over the infrastructure and SQL Server. Our managed SQL Server environments let you focus on your core business activities while we handle the technical details.

Our experts work with you to design a hosting solution that meets your business and workload requirements. We have experience to assist with HA architecture planning, backups, and DR strategy.

[Contact us today](https://www.atlantic.net/about-us/corporate-contact/) and learn how we can help you implement the right SQL Server HA solution for your business.


---

# HFT Hosting: Low-Latency Infrastructure for Trading

> URL: https://www.atlantic.net/dedicated-server-hosting/hft-hosting-low-latency-trading-infrastructure/ | Published: 2026-04-14 | Author: Robert Agar

This article explores the infrastructure required to support the demands of high-frequency trading (HFT). We demonstrate how low latency provides financial firms with a competitive edge and the specific requirements of high-frequency trading servers. We also examine the benefits of HFT hosting and discuss how companies should select the right platform for a high-frequency trading infrastructure.

## What Is HFT Hosting?

High-frequency trading (HFT) hosting involves using specialized hardware and data center services to support ultra-low-latency trading systems for financial institutions that need to execute trades in microseconds or nanoseconds. HFT systems are performance-engineered and optimized for speed, determinism, and proximity to major financial centers. Businesses can lose profits due to even a microsecond delay when executing a trade.

Standard hosting solutions may not be sufficient for latency-sensitive trading workloads. HFT systems typically outgrow standard hosting for several reasons.

- Standard hosting utilizes shared internet routing and regional data centers. Network performance issues and a lack of proximity to major financial hubs can add unacceptable milliseconds to trading activities.
- HFT systems require deterministic performance and consistent latency that standard hosting cannot provide. A typical hosting environment may introduce variable latency due to network congestion and packet queuing, intolerable for effective HFT strategies.
- The hardware supporting standard hosting is not sufficiently optimized to address HFT system requirements. Workloads in trading require measures such as kernel bypass and fast CPUs to boost performance.
- High-frequency trading servers require precise time synchronization for order sequencing, event correlation, and regulatory compliance. Standard hosting environments often rely on Network Time Protocol (NTP), which is sufficient for general-purpose workloads but may not provide the consistency or precision needed for latency-sensitive trading. HFT systems typically use Precision Time Protocol (PTP) with hardware timestamping to achieve much higher accuracy, often at the microsecond level and, in optimized environments, even sub-microsecond or nanosecond-scale synchronization.

Businesses can optimize their high-frequency trading servers by leveraging dedicated infrastructure tailored to their requirements. A bare-metal server or a properly configured VPS with direct connectivity to a high-speed network will process HFT workloads more efficiently than shared cloud solutions.

## Why Low Latency Matters

Low latency is a critical competitive variable in high-frequency trading. The automated trading systems used in HFT operations execute trades at the microsecond or nanosecond scale. Execution speed is directly related to HFT profitability and reducing the risk of missed trading opportunities. Companies rely on low latency to gain a competitive advantage over rivals.

### Different types of latency

Companies executing trading strategies face three types of latency, each affecting them differently.

- Average latency is the arithmetic mean of all observed response times. It denotes the average time needed to fulfill a request. The average may mask outliers that take much longer to complete, thereby impacting trading performance.
- Jitter or variable latency is the variation in latency between consecutive requests. It measures the consistency of latency over time. High jitter indicates latency fluctuations and unpredictable performance. Systems can have similar average latency but widely varying jitter.
- Tail latency refers to the upper percentiles of the distribution and indicates the speed of the worst-performing requests. Users may experience rare slowdowns due to the system’s tail latency, which can be catastrophic for HFT strategies.

High-frequency trading businesses benefit from latency consistency rather than infrequent, high-throughput results. Traders can develop a viable strategy when transactions are executed with predictable timing. Successful HFT operations cannot tolerate high jitter and tail latency.

## Core Infrastructure Requirements for HFT Hosting

Companies engaged in high-frequency trading require systems with excellent performance and consistent, low latency. The following core infrastructure elements and features are essential for high-frequency trading servers.

- **Dedicated CPU resources: **HFT systems need dedicated CPU cores to achieve the execution speed and stable performance required to support HFT algorithms. Companies cannot risk the variability in shared cloud solutions, where other tenants can affect performance and the speed of trade execution.
- **Low-latency networking:** Minimal network latency is essential for HFT systems. Nanosecond delays can be the difference between a profitable trade and a missed opportunity. Traders need packet handling techniques, such as bypassing the operating system kernel and using hardware acceleration.
- **Fast storage and memory:** Fast memory and storage subsystems support data access and file loading. More available RAM reduces the need for processors to fetch data from storage systems. Businesses benefit from using NVMe SSDs to enable faster read/write operations for high-frequency trading servers.
- **Security: **The HFT infrastructure must be secured with strict access controls to minimize unauthorized access to sensitive company data. Companies should insist on additional security measures, such as network segmentation and DDoS protection, to ensure system availability.
- **Additional features:** High-frequency trading servers should be supported by measures such as synchronized timing and a precision time protocol to ensure data integrity, operational, and network performance. The servers must be monitored 24/7, with failover controls in place to address issues and minimize downtime quickly.

## HFT Hosting Options

Organizations have multiple options for hosting high-frequency trading servers.

- Dedicated bare-metal servers offer the best performance and the most customized platform for production HFT workloads by providing customers with complete control over the infrastructure.
- Dedicated cloud hosts provide an isolated environment and deliver enhanced flexibility, enabling businesses to scale to meet evolving requirements.
- Colocation services enable businesses with specialized hardware to house servers in the same facility as trading exchanges, minimizing latency and reducing capital costs associated with supporting their own infrastructure.
- Shared cloud environments are suitable for HFT development and testing. They can be an important component of a complete strategy that includes either cloud or dedicated bare-metal hosts.

## Singapore Data Center and Placement Considerations

Facility location directly affects the performance of high-frequency trading systems. The physical distance between a server and a trading exchange determines latency and jitter. Reducing this distance is essential for optimal HFT performance.

Companies located closer to an exchange data center have faster access to market data, enabling them to make informed trading decisions and obtain a better queue position to fill orders. A difference of several meters in proximity can significantly impact trading speed.

Businesses should verify the exact location of the exchange, broker servers, or service endpoint. They should strive to host their HFT systems as close to this location as possible. For example, companies focused on European markets benefit from hosting their servers in Europe rather than in the U.S. Our Singapore data center is located in an International Business Exchange (IBX) to minimize network latency for market feeds and trades in Southeast Asia.

Customers should select a hosting solution in a physical location that supports low latency. Teams should validate connectivity and evaluate the network to ensure predictable latency to support their trading infrastructure.

## Network Validation Before Purchase

It is essential for companies to validate the network they will use for high-frequency trading fully. A low-latency network interface is the foundation of profitable HFT strategies. Teams should follow the steps below to validate the network.

- Request traceroutes or MTR tests from the server to prospective target destinations. These tests analyze latency and packet loss between the server and target in real time to identify the source of potential connection issues.
- Companies considering a new hosting solution should compare their current network path and quality with that offered by the provider. Businesses should ensure that the new path minimizes latency to improve trading performance.
- Teams should carefully review the prospective network’s median and tail latency, as well as packet consistency, to ensure trades execute efficiently. It is critical to evaluate network performance based on jitter and tail latency, not its raw speed.
- Businesses must consider routing validation as a critical part of vendor qualification. A provider may have high-powered dedicated servers that meet HFT requirements, but their performance is hampered by high network latency, making them unsuitable for successful trading.

## Benefits of HFT Hosting

HFT hosting delivers multiple benefits to businesses, supporting their trading strategies.

- A dedicated bare-metal or virtual private server provides more predictable performance than a shared environment. Businesses are not affected by resource contention, which can limit performance and trading.
- Teams can exercise greater control over infrastructure tuning to ensure their HFT algorithms run at optimal performance. Companies running custom software can tune OS parameters, which is not possible in a shared cloud environment.
- Dedicated hosts eliminate the routing delays in shared cloud solutions. This reduced latency is essential to support the high-frequency trading logic required by institutional clients and financial firms.
- HFT hosting provides a strong foundation for monitoring systems, ensuring availability and enhanced resilience through real-time failover strategies. Companies can scale the infrastructure to address increased trading volume without sacrificing performance.

## Why Choose Atlantic.Net

Atlantic.net offers customers multiple solutions that support high-frequency trading servers.

- Our diverse data center locations enable companies to host systems near market exchanges, minimizing latency and optimizing trading performance.
- We work with you to identify and implement the best solution for your specific business requirements. Customers can choose from our dedicated bare-metal servers, shared cloud platforms, and colocation services.
- Our cloud hosts are fully configurable to meet your needs. You can choose from a range of dedicated hosting plans or tailor our hardware to align with your unique requirements.
- We back our hosting solutions with 100% uptime commitments and 24/7 support from an expert technical team.

## FAQs

**Q: Is VPS suitable for HFT hosting?**

A: VPS is usually not ideal for top-tier production HFT. VPS hosting does not offer the ultra-low latency, determinism, and hardware control required by HFT traders. The virtualized, multi-tenant nature of a VPS infrastructure increases latency and jitter, which negatively affect trading strategy.

**Q: When is bare metal a better fit than virtualized hosting?**

A: Bare metal is a better fit than virtualized hosting as the foundation for an organization’s HFT infrastructure. A bare-metal server delivers maximum performance and minimal latency to support an HFT trading strategy. Teams have full control over the hardware and operating system, allowing them to optimize the server to support an HFT trading engine.

**Q: Is cloud hosting appropriate for production HFT?**

A: Companies should refrain from using shared, public cloud solutions for production HFT due to inconsistent latency and performance. Businesses can use cloud-hosted dedicated and bare-metal servers to deliver the performance needed to run HFT algorithms.

**Q: What network tests should I request before buying?**

A: Businesses should demand repeatable network tests to evaluate latency, jitter, path quality, and determinism under real production conditions. Teams should insist on reviewing raw data rather than the provider’s summarized reports. Specific tests include:

- End-to-end latency;
- Jitter and tail latency;
- Packet loss;
- Market data feed latency
- Network path transparency;
- Kernel bypass performance;
- Time synchronization accuracy;
- Path stability and failover tests.

**Q: How should I evaluate hosting for latency-sensitive trading workloads?**

A: Companies can use the following framework when evaluating a hosting solution.

- Develop a list of providers that offer exchange colocation in the same facility or close physical proximity to trading markets.
- Request and review the complete network and hardware specifications for the solutions.
- Run controlled latency and jitter test and validate performance with real market data to compare determinism and tail latency.
- Make the final decision based on consistent performance and latency, not theoretical peak speed.

**Q: Can infrastructure location affect execution quality?**

A: Yes, infrastructure location can directly affect execution quality and speed. Companies can boost performance and access to market data feeds by running their HFT algorithms on servers in close physical proximity to exchanges. The right location can provide a substantial latency advantage, increasing profitability and customer satisfaction.


---

# How to Make a HIPAA-Compliant Website: 2026 Guide

> URL: https://www.atlantic.net/hipaa-compliant-hosting/how-to-make-website-hipaa-compliant/ | Published: 2026-04-14 | Updated: 2026-07-24 | Author: Richard Bailey

## **What Is a HIPAA-Compliant Website?**

A HIPAA-compliant website protects[protected health information](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) (PHI) from unauthorized access. This includes websites that collect, store, or transfer PHI, such as patient portals or logins. This is done through security and privacy controls, such as:

- **Policies:** Ensuring adherence to evolving[HIPAA rules](https://www.atlantic.net/hipaa-compliant-hosting/what-are-hipaa-compliance-rules-and-guidelines/) and maintaining up-to-date compliance documentation aligned with current HIPAA compliance requirements.
- **Encryption:** Encrypting electronic protected health information during storage and ensuring secure data transmission when transmitting protected health information across systems.
- **SSL certificate:** Ensuring the connection between the browser and the website is encrypted.
- **Third-party services:** Using HIPAA-compliant third-party services that support HIPAA compliance for websites and meet strict security standards.
- **Business associate agreement:** Ensuring relevant third parties commit to complying with HIPAA.
- **Secure hosting:** Using a HIPAA-compliant hosting company that offers encrypted connections, secure servers, and protection against cyber-attacks.
- **Secure data center:** Choosing a secure and audited data center.
- **Secure data disposal:** Having a strong data disposal policy.
- **Backups:** Backing up all PHI information in ways that ensure the data is recoverable.
- **Access:** Limiting user access to electronic protected health information using access controls, role based access controls, and ensuring only authorized users can retrieve sensitive data.
- **Safeguards:** Implementing safeguards like firewalls to prevent tampering with health logs.

Any website that handles electronic patient information must adhere to the[Health Insurance Portability and Accountability Act (HIPAA)](https://www.atlantic.net/hipaa-compliant-hosting/what-is-a-hipaa-certification/) standards to prevent data breaches. Websites that are only used to promote a business, such as providing contact information or hours, do not fall under HIPAA regulations.

The HIPAA legislation requires that any web server handling electronic protected health information complies with the administrative, technical, and physical safeguards defined under the HIPAA Security Rule and Enforcement Rule.

The bottom line is that you need a compliant site if you are collecting PHI (protected health information), and that means any individually identifiable healthcare information collected during the provision of healthcare.

## **Does Your Website Need to Comply with HIPAA?**

### **Definition of Protected Health Information (PHI)**

According to the HIPAA regulation, Protected Health Information (PHI) includes any information that can be used to identify a patient and is related to their health condition, healthcare provision, or payment for healthcare. This includes data that healthcare providers, health plans, healthcare clearinghouses, or any business associates collect or manage during the course of healthcare operations.

This also includes electronic protected health information (ePHI), such as medical records, stored data, and patient data transmitted through digital platforms and web applications.

Under HIPAA, PHI is classified into 18 distinct identifiers, such as names, geographic data smaller than a state, elements of dates (except year) related to an individual, phone numbers, and email addresses. Additionally, any unique identifying number, characteristic, or code is considered PHI when linked with an individual’s health information.

Any website or web application that collects, stores, or transmits PHI could be covered by the HIPAA regulation.

![](https://www.atlantic.net/wp-content/uploads/2023/09/How-to-make-HIPAA-Compliant-Website_What-is-PHI-.jpg)

### **Organizations and Websites Covered by the HIPAA Regulation**

It’s important to consult a legal expert to determine if your organization and its website are covered by HIPAA. Generally speaking, the following organizations are subject to the regulation:

- **Healthcare providers:** This includes doctors, clinics, psychologists, dentists, chiropractors, nursing homes, and pharmacies that transmit any health information in electronic form in connection with a HIPAA transaction.
- **Health plans:** This includes health insurance companies, HMOs, company health plans, and government programs that pay for healthcare, such as Medicare, Medicaid, and the military and veterans’ healthcare programs.
- **Healthcare clearinghouses:** Entities that process nonstandard health information they receive from another entity into a standard format (or vice versa).
- **Business associates:** Any organization supporting covered entities with services involving patient data, including web development teams, cloud providers, and analytics vendors, must comply with HIPAA[business associate agreement](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) requirements.

### **HIPAA Compliant Website Video**



## **HIPAA Compliant Website Checklist**

#### **What Is Needed to Make Your Website HIPAA Compliant?**

Below you can find our 10-step checklist to make your website HIPAA compliant, which includes steps like identifying PHI, applying[SSL](https://www.atlantic.net/vps-hosting/what-is-ssl-certificate/) encryption, and signing business associate agreements (BAAs).

The easiest way to achieve[HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-in-the-age-of-ai/) is to outsource this responsibility to a[hosting provider](https://www.atlantic.net/hosting-services-provider/) that specializes in[HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/). Atlantic.Net is a leading provider that specializes in HIPAA-compliant web hosting. Atlantic.Net provides dedicated, HIPAA-compliant web servers running Apache, Nginx, or Microsoft IIS, as well as a one-click[WordPress cloud](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/benefits-of-wordpress-cloud-hosting/) solution.

Here are key HIPAA compliance concerns that should guide your efforts:

- [Privacy Rule & Security Rule](https://www.atlantic.net/hipaa-compliant-hosting/how-to-make-website-hipaa-compliant/#1-adhere-to-the-privacy-and-security-rules)
- [SSL encryption](https://www.atlantic.net/hipaa-compliant-hosting/how-to-make-website-hipaa-compliant/#2-implement-ssl-certificate-encryption-tls)
- [HIPAA-compliant website platform](https://www.atlantic.net/hipaa-compliant-hosting/how-to-make-website-hipaa-compliant/#3-use-a-hipaa-compliant-platform-and-hipaa-compliant-web-forms)
- [Business associate agreements](https://www.atlantic.net/hipaa-compliant-hosting/how-to-make-website-hipaa-compliant/#4-sign-a-business-associate-agreement)
- [Healthcare focus of infrastructure](https://www.atlantic.net/hipaa-compliant-hosting/how-to-make-website-hipaa-compliant/#5-select-a-healthcare-specific-infrastructure-or-host)
- [Security of data center & auditing](https://www.atlantic.net/hipaa-compliant-hosting/how-to-make-website-hipaa-compliant/#6-select-a-regularly-audited-secure-hipaa-data-center)
- [Disposal of sensitive data](https://www.atlantic.net/hipaa-compliant-hosting/how-to-make-website-hipaa-compliant/#7-ensure-proper-disposal-of-sensitive-data)
- [Offsite CDP backups](https://www.atlantic.net/hipaa-compliant-hosting/how-to-make-website-hipaa-compliant/#8-perform-regular-off-site-backups)
- [Managed multi-factor authentication](https://www.atlantic.net/hipaa-compliant-hosting/how-to-make-website-hipaa-compliant/#9-implement-multi-factor-authentication)
- [Managed firewall](https://www.atlantic.net/hipaa-compliant-hosting/how-to-make-website-hipaa-compliant/#10-implement-a-managed-firewall)

![](https://www.atlantic.net/wp-content/uploads/2023/09/How-to-make-HIPAA-Compliant-Website_HIPAA-Compliant-Website-1024x810.jpg)

![](https://www.atlantic.net/wp-content/uploads/2023/09/How-to-make-HIPAA-Compliant-Website_What-is-the-Privacy-Rule.png)

## **1. Adhere to the Privacy and Security Rules**

The HIPAA Privacy Rule applies to all healthcare providers, plans, and clearinghouses, as well as to their business associates (any organizations handling health information on their behalf).

### **What Is the Privacy Rule?**

The Privacy Rule mandates that there should be protections in place to safeguard the privacy of health information. The rule also establishes rights that patients have related to their information, such as the right to get a copy of health information and to review it, as well as to ask for corrections.

The Privacy Rule mandates protecting patient data while giving individuals control over how their medical records are accessed and shared.

### **What Is the Security Rule?**

The[HIPAA Security Rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/) creates national standards to safeguard health information in electronic form, whether an organization is producing, receiving, sending, or storing it.

It requires comprehensive security measures, including access controls, audit logs, and protections against security incidents and security breaches.

It requires the adoption of “reasonable and appropriate” technical, physical, and administrative safeguards, so organizations can protect the security, integrity, and confidentiality of ePHI in a HIPAA-compliant manner. The easiest way for covered entities with a website to achieve compliance with the security rule is to use HIPAA-compliant website hosting providers (see section 4 below).

![](https://www.atlantic.net/wp-content/uploads/2023/09/How-to-make-HIPAA-Compliant-Website_Do-I-need-SSL-certificate-encryptionTLS-.png)

## 2. Implement SSL Certificate Encryption (TLS)

You must implement a secure sockets layer (SSL) [TLS] encryption certificate for your website, transitioning from HTTP to the secure HTTPS protocol. This protocol encrypts all data that is in motion between the client device and the server.

Web developers should know how to install SSL certificates, but you can also work with your hosting provider on[SSL-encrypting your site](https://www.atlantic.net/vps-hosting/what-is-ssl-certificate/).

![](https://www.atlantic.net/wp-content/uploads/2023/09/How-to-make-HIPAA-Compliant-Website_Does-my-website-platform-need-to-bee-HIPAA-compliant-.png)

## 3. Use a HIPAA-Compliant Platform and HIPAA-Compliant Web Forms

To make sure your website is HIPAA-compliant, you must use a compliant content management platform and HIPAA-compliant web forms. No platform is inherently HIPAA-compliant, but some platforms are HIPAA-compliant when the proper procedures and safeguards are in place. For example, Atlantic.net can help you set up a[HIPAA-compliant WordPress instance](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/).

For a compliant environment, think about how people will use your site. The ways that patients can use HIPAA-compliant websites inform the types of security measures needed. The concern is specifically related to ePHI – whether your organization is creating, transmitting, receiving, or maintaining it.

If you are collecting information through forms on your site, you will need to ensure all that data is protected per HIPAA regulations. Any form collecting health data should protect the information under HIPAA regulations for safeguarding ePHI; the form must defend any identifiable health information against unauthorized access and potential data breaches. Read our list of[the top HIPAA-compliant form tools here](https://www.atlantic.net/hipaa-compliant-hosting/top-10-hipaa-form-companies-in-2022/).

![](https://www.atlantic.net/wp-content/uploads/2023/09/How-to-make-HIPAA-Compliant-Website_Do-I-need-a-Business-Associate-Agreement-.png)

## 4. Sign a Business Associate Agreement

If you are going to work with any outside providers or businesses on any aspect of your site that involves the handling of ePHI, you need to sign a business associate agreement (BAA) with them. To meet HIPAA compliance rules, you must verify all health data that you store and that it is sent through your site securely (whether at rest or transmitting PHI in transit).

Be aware that your website developer is a direct business associate, but they will in turn have subcontractor business associates who independently perform services for them. Confirm that the website designer has BAAs with each of its third-party subcontractors – so that all applicable parties are included within HIPAA compliance upfront. Failure to identify business associates is no defense and led to a $1.5 million HHS fine in one case.

![](https://www.atlantic.net/wp-content/uploads/2023/09/How-to-make-HIPAA-Compliant-Website_Should-my-hosting-infrastructure-be-healthcare-specific-.png)

## 5. Select a Healthcare-Specific Infrastructure or Host

For organizations that handle individually identifiable medical information, choosing the right host for your ePHI is an important step. You need a hosting provider that is dedicated to following the Privacy Rule and Security Rule, and that has technical, administrative, and physical safeguards in place to protect PHI.

**Atlantic.Net is a leading provider of**[**HIPAA-compliant hosting services**](https://www.atlantic.net/hipaa-compliant-hosting/)**.**

![](https://www.atlantic.net/wp-content/uploads/2023/09/How-to-make-HIPAA-Compliant-Website_Should-my-provider-be-secure-and-audited-.png)

## 6. Select a Regularly Audited Secure HIPAA Data Center

Determine whether your host is secure and audited according to the appropriate HIPAA guidelines. One thing you can do to get a better sense of a host’s security stance is to look beyond those healthcare law certifications to an audit based on the insight of the American Institute for Certified Public Accountants (AICPA), [Statement on Standards for Attestation Engagements 18](https://www.atlantic.net/hipaa-compliant-hosting/ssae-16-soc-1-soc2-care/) (SSAE 18; formerly SSAE 16), SOC 2 and SOC 3. Look for environments that demonstrate compliance documentation and ongoing auditing aligned with modern HIPAA requirements.

**Atlantic.net provides its services within a**[**HIPAA-compliant data center.**](https://www.atlantic.net/hipaa-data-centers/)

![](https://www.atlantic.net/wp-content/uploads/2023/09/How-to-make-HIPAA-Compliant-Website_What-is-the-HIPAA-Security-Rule-.png)

## 7. Ensure Proper Disposal of Sensitive Data

Proper disposal of sensitive data, including PHI, is critical to maintaining HIPAA compliance. When data is no longer needed, it must be securely destroyed to prevent unauthorized access. This involves using methods such as degaussing, shredding, or secure digital wiping for electronic media. For paper records, shredding or incineration should be used. Organizations must maintain documentation of disposal practices and ensure that no stored data containing patient data can be reconstructed after deletion.

Ensuring that all data is irretrievably erased reduces the risk of data breaches, maintaining the confidentiality of patient information even after it is no longer in use. Additionally, organizations should have a documented data disposal policy and train employees on the correct disposal procedures to ensure consistency and compliance.

![](https://www.atlantic.net/wp-content/uploads/2023/09/How-to-make-HIPAA-Compliant-Website_Do-I-need-Off-site-Backups-.png)

## 8. Perform Regular Off-Site Backups

It is best practice to have a replicated offsite copy of the daily backups of your IT infrastructure for business continuity and disaster recovery capabilities, and this is also true for HIPAA-compliant websites.

At Atlantic.net, we can [back up your website data](https://www.atlantic.net/disaster-recovery/) to any of our eight data center locations. Replicated offsite backups are easily retrievable and you can quickly and easily restore them when needed.  Custom retention periods and backup frequency are available such as 5 minutes, 15 minutes, and hourly backups.

![](https://www.atlantic.net/wp-content/uploads/2023/09/How-to-make-HIPAA-Compliant-Website_What-about-Onsite-Backups-.png)

## What About Onsite Backups?

Onsite backups using the ACP Onsite Backup solution create daily backups of your required servers and store the data geographically locally in a protected secured area. These backups are easily retrievable and if a restore is needed, the process is incredibly quick.  Custom retention periods and backup frequency are available such as 5 minutes, 15 minutes, and hourly backups.

![](https://www.atlantic.net/wp-content/uploads/2023/09/How-to-make-HIPAA-Compliant-Website_Do-I-need-MFA-website-.png)

## 9. Implement Multi-Factor Authentication

You want a [managed multi-factor authentication](https://www.atlantic.net/managed-services/multi-factor-authentication/) access system that is available through one sign-on. The system should perform diagnostics on devices to ensure their health. Infected and high-risk devices can be blocked via scanning for outdated applications and enforcing security controls.

![](https://www.atlantic.net/wp-content/uploads/2023/09/How-to-make-HIPAA-Compliant-Website_Do-I-need-a-Managed-Firewall.png)

## 10. Implement a Managed Firewall

A strong [managed firewall](https://www.atlantic.net/managed-services/firewall/) will include powerful security response, routine device health checks, log monitoring, and control of network ingress and egress points. The system should include load balancing, redundancy via a secondary firewall, global blacklisting, [virtual private network](https://www.atlantic.net/vps-hosting/what-is-vpn/) (VPN) connectivity, stateful filtering, monitoring, reporting, and management of router IP addresses.

![](https://www.atlantic.net/wp-content/uploads/2023/09/How-to-make-HIPAA-Compliant-Website_Sample-HIPAA.jpg)

## **Frequently Asked Questions**

### **What Does HIPAA Require From a Hosting Provider Handling Protected Health Information?**

A hosting provider handling ePHI is a business associate under HIPAA, so it must sign a BAA and maintain the Security Rule’s administrative, technical, and physical safeguards: access controls, audit logging, encryption for data at rest and in transit, and physically secured, audited data centers. The provider carries the infrastructure controls; you remain responsible for how your application collects and uses PHI.

### **What Is a Business Associate Agreement and Why Is It Required for HIPAA Hosting?**

A Business Associate Agreement (BAA) is a contract in which a vendor that touches PHI on your behalf accepts its own HIPAA obligations and liability. Without a signed BAA, hosting PHI with any provider is a compliance violation regardless of how secure the infrastructure is. Step 4 above covers the subcontractor chain: your host, your developer, and their subcontractors all need agreements in place.

### **What Encryption Standards Are Required or Recommended for HIPAA-Compliant Hosting?**

HIPAA calls encryption an “addressable” safeguard and does not name specific algorithms, but in practice the bar is NIST-aligned: AES-256 for data at rest and TLS 1.2 or newer for data in transit. If you choose not to encrypt, you must document why the risk is acceptable, and after a breach of unencrypted PHI that argument rarely survives an HHS review.

### **Where Can You Find HIPAA Hosting With Multi-Factor Authentication and Audit Logs?**

Look for a HIPAA-specialized host that offers these as managed services rather than leaving them to you. Atlantic.Net includes[managed multi-factor authentication](https://www.atlantic.net/managed-services/multi-factor-authentication/) and logging/monitoring options across its HIPAA hosting plans, covering steps 9 and 10 of this checklist, and backs them with SOC 2 and SOC 3 audited data centers.

### **What Are the Penalties for a Hosting-Related HIPAA Data Breach?**

Civil penalties are tiered by culpability and can reach roughly $2.1 million per violation category per year, adjusted annually for inflation. Enforcement examples include a $1.5 million fine where an organization failed to identify a business associate relationship. Breaches affecting 500 or more individuals must also be reported to HHS and publicly listed, and organizations have 60 days from discovery to notify affected patients.

### **Does Every Healthcare Website Need to Be HIPAA-Compliant?**

No. HIPAA applies to websites that create, collect, store, or transmit PHI, such as patient portals, appointment forms that capture health details, or telehealth pages. A purely promotional site listing services, hours, and contact information does not fall under HIPAA, though adding something as small as a symptom-checker form can change that.

## Your HIPAA-Compliant Website

Many organizations work with third parties on their data systems, particularly if they are in rigorously controlled sectors such as healthcare. Contracting with outside organizations is not simply a way to push away off-focus work; it is also a way to tap expertise that is not present in-house. When you need a healthcare website, work with organizations that are HIPAA and HITECH certified, as well as SOC 2 and SOC 3 audited, so that they are prepared to meet their obligations to the Department of Health and Human Services. See our [HIPAA-compliant web hosting solutions](https://www.atlantic.net/hipaa-compliant-hosting/).

#### Get Help with Your Website to Make It HIPAA Compliant

Atlantic.Net can help make your website HIPAA-compliant with a range of certifications, such as SOC 2 and SOC 3, HIPAA, and HITECH, all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, call 866-618-DATA (3282), or email us at [sales@atlantic.net](mailto:sales@atlantic.net).


---

# Top 10 OTT and CTV Advertising Platform Providers in 2026

> URL: https://www.atlantic.net/vps-hosting/top-10-ott-and-ctv-advertising-platform-providers/ | Published: 2026-04-14 | Updated: 2026-04-17 | Author: Dr. Rachael Bailey

## What is Over-the-Top (OTT)?

OTT, short for ‘Over-the-Top,’ refers to the practice of streaming television and film content directly over a high-speed internet connection, i.e. a service that goes ‘over-the-top’ of an existing satellite or cable provider. Today, OTT platforms also power digital streaming ecosystems that include live and on-demand video content and audio streaming across multiple devices. Examples of popular OTT providers include Netflix, Amazon Prime Video, Hulu, and Disney+. When using OTT services, customers can stream content on mobile devices, tablets, PCs, and connected TVs, including Android TV, OTT apps, and web browsers.

## What is a Connected TV (CTV)?

This invites the question: what is a connected TV? A CTV, or a ‘smart TV,’ is a television set that streams video content directly over the internet. A CTV may also represent a device that enables a TV to connect to the Internet, for example, game consoles, such as Xbox, Playstation, or Nintendo, or an Internet-connected device, such as Chromecast, Firestick, or Apple TV. CTV is now a key access point for OTT TV consumption, supporting high quality streaming and advertising video delivery.

## What is the difference between OTT and CTV?

While OTT is the delivery service that supplies TV content online, CTV is the device that is used to watch this content. In modern streaming media environments, OTT platform services manage video delivery and media storage, while CTV ensures playback across multiple devices.

## What is the best OTT provider?

The OTT market continues to grow rapidly in 2026, driven by demand for high quality video content, subscription video models, and ad supported models. The global video streaming market is highly competitive, and there are many features to consider when choosing the perfect service provider. A good OTT solution will offer enhanced security features, monetization options, multi-platform capability, a powerful video content management system (CMS), dependable technical support, and a deep analytics feature. Modern OTT solution providers also prioritize adaptive streaming, video API access, granular access controls, and tools to track viewer engagement.

Here, we help you to choose the best platform for your OTT business model by providing a summary of our top 10 OTT providers.

## 1. Dacast

Dacast offers clients an end-to-end, self-service platform to broadcast both live and on-demand content. Dacast is set apart from its competitors through its accessibility and easy-to-use interface. The platform provides its customers with a comprehensive list of features, including ad-free streaming, white-label service, 24/7 support, an analytics dashboard, and video monetization opIts platform also supports enterprise-grade video management and advanced video APIs for large-scale streaming solutions.

## 2. Vimeo OTT

Vimeo OTT is one of the leading platforms available in the video streaming sector. Offering customers an all-in-one solution, Vimeo OTT has over 5 million end-users, 1500+ in-house apps, and boasts 3.5 million live streams annually. This white-label platform offers customers best-in-class analytics, a simple pricing structure, video monetization features, password-protected streams, CMS, 24/7 support, and deep, real-time insights. It is widely used by businesses building their own OTT platform with strong video CMS and media management capabilities.

## 3. IBM Watson Media

IBM Watson Media (formerly IBM Cloud Video) offers a powerful OTT solution, delivering both live streaming and VOD hosting. IBM’s OTT offering provides a fully scalable infrastructure, built to help customers to achieve a global presence. The key features of IBM Watson Media include an internal content delivery system, ad-based and subscription-based monetization models, multiplatform UX API, AI-powered speech-to-text, and powerful analytics. Its platform also supports enterprise-grade video management and advanced video APIs for large-scale streaming solutions.

## 4. VlogBox

[VlogBox](https://vlogbox.com/) is a one-stop-shop platform providing CTV app development services, video content distribution and monetization solutions, as well as PR and marketing support. With VlogBox, customers can get template-based channels or request a custom design for their new app. Apart from channel development, this platform can also assist with channel monetization and its promotion on leading streaming platforms. At VlogBox, customers receive detailed reports & analytics of their audience activation and conversion that allow them to analyze their channel’s performance. VlogBox offers various pricing plans starting from pure app development to management and promotion of a custom-built channel. This makes it a strong option among OTT service providers focused on advertising video and viewer engagement.

## 5. JWPlayer

JWPlayer helps customers to expand their business using their powerful and flexible platform. This OTT provider enables customers to deliver content via its HTML5 JW video player, supporting HLS and DASH adaptive live streaming. It is widely adopted for video hosting platforms that require adaptive streaming and support for various video formats.

With only custom-priced Enterprise plans offering digital rights management (DRM), the security features provided with cheaper plans are basic yet practical.

## 6. Wowza

Delivering industry-leading technology, Wowza provides scalable, flexible, and reliable live streaming for business-critical applications. This full-service platform helps businesses to expand their monetization opportunities and deploy high-quality video streams. This OTT provider allows businesses to utilize a full platform API and a vast array of third-party integrations. Wowza also offers multi-level security features, including encryption, token authentication, and DRM. It is commonly used by OTT platform providers needing high quality streaming and low-latency video delivery.

## 7. Kaltura

Kaltura, a leading online video cloud provider, is designed for scalability and accessibility. Offering solutions for both live streaming and VOD, Kaltura provides ad-based, subscription, and pay-per-view monetization models, interactive video tools, specialized tools for building educational platforms, and advanced security measures, such as encryption and password protection. Its platform supports diverse monetization models and advanced media management workflows.

Despite a high price point that makes it more suitable for large enterprises, media companies, and educational institutions, Kaltura does not include a CDN, so this would represent an additional cost.

## 8. Muvi

Muvi, a popular all-in-one white-label video streaming platform, employs a number of professional features that allow its customers to easily launch and manage their video content. The features available through this out-of-the-box, fully managed platform are geared mostly towards experienced broadcasters. Muvi’s key features include transcoding tools, insightful analytics and reporting, monetization tools, and advanced security options. It is a strong choice for businesses looking to build OTT apps and launch streaming and on demand services quickly.

## 9. VPlayed

VPlayed provides an adaptable OTT platform to broadcasters across many industries, including sports, education, enterprise, and film. With VPlayed, customers can expect a world-class streaming infrastructure that is built for scale. This platform also provides customizable monetization models, insightful video analytics, impactful marketing tools, and advanced security features, including DRM, SLS encryption, and password protection. A highly networked CDN ensures that customers receive a high-quality OTT streaming experience. It supports advertising video, subscription video, and hybrid revenue streams to help businesses generate revenue.

## 10. Uscreen.tv

Uscreen is a leading OTT platform, allowing customers to launch and maintain video streaming apps for smartphones and TV. Uscreen is one of the fastest providers in this sector, with a time-to-launch averaging at 30-60 days. Some of the stand-out features of this OTT platform include centralized CMS with dynamic changes, built-in detailed analytics, and a ‘try again for free’ option to regain clients who have canceled their subscription. UScreen is available to customers at an affordable, fixed fee. It is especially popular among video creators building subscription-based OTT video platforms with strong audience engagement tools.

## Bonus:

## Brightcove

Brightcove has provided its customers with an effective and robust OTT platform since 2004. Brightcove’s 15 years of innovation and vision set this OTT provider apart from its competitors. The platform delivers complex analytics and marketing tools and offers unmatched reliability and scalability. Security remains a priority for Brightcove, with customers benefiting from DRM, domain and IP restrictions, and geo-restriction. Brightcove is GDPR compliant and DPP certified. It remains one of the best OTT platform providers for enterprises requiring advanced video delivery and analytics integrations such as Google Analytics.

## How can Atlantic.Net help?

As part of a competitive sector, it is vital to ensure that your OTT platform provides the infrastructure, scalability, and speed needed for your customers to experience high-quality video streaming services. In 2026, this also includes support for video APIs, scalable media storage, and delivery across multiple devices.

Atlantic.Net has over 30 years of experience in designing a vast array of compliant hosting solutions, including [cloud VPS](https://www.atlantic.net/vps-hosting/), dedicated, private virtualization, colocation, and managed hosting. Many of the world’s top brands are powered by Atlantic.Net. We can help you to get more for less, and, most importantly, we can provide you with one of the fastest networks of globally redundant cloud. Our platform supports OTT platform services, video hosting, and high quality streaming for modern digital streaming businesses.

[Contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)to find out how Atlantic.Net can help you in your quest to efficiently and cost-effectively deliver video content to your users.

*This article was updated on April 14, 2026.*


---

# The Top Domain Marketplaces to Buy a Premium Domain Name in 2026

> URL: https://www.atlantic.net/managed-services/the-top-domain-marketplaces-to-buy-a-premium-domain-name/ | Published: 2026-04-14 | Updated: 2026-06-23 | Author: Editorial Team

A great [domain name](https://www.atlantic.net/vps-hosting/what-is-dns-and-how-does-it-work/) does more than just point people to your website. It builds trust, communicates what your brand is about, and makes it easier for people to remember you. In 2026, as more online businesses compete globally, securing the perfect domain name has become a critical step in standing out across multiple platforms. But in today’s crowded digital space, the perfect domain is rarely available for the standard registration fee. That’s where premium domains come in.

Premium domains are often short, brandable, and keyword-rich. These domains are usually owned by someone else and sold at a higher price due to their market value. They are considered high-value digital assets by domain investors and businesses looking to strengthen their domain portfolios. In this guide, we’ll explain what makes a domain premium, how it can benefit your business, and where you can buy one safely and easily.

## **What Is a Premium Domain?**

A premium domain is a domain name that’s already been registered but is listed for resale at a higher price. These names are considered more valuable because they’re short, easy to remember, brand-friendly, and often include popular keywords or clean branding potential.

Premium domains aren’t random. They’re carefully selected assets. Many aftermarket domains are curated based on domain quality, keyword searches, and brand relevance, making them attractive to serious buyers. When someone sees a premium domain like Brightly.com or Fintech.io, they immediately get a sense of professionalism and trust.

Premium domains are also scarce. As more businesses launch online, the demand for strong digital real estate grows. Current market trends show increased demand for aged domains and keyword-rich names across the domain market. And just like in real estate, the best locations are rarely cheap.

## **Domain Components**

Domains may seem simple, but two elements really determine their impact: the domain name itself and the extension, also known as the TLD (Top-Level Domain). Getting both right matters.

### **TLD: A Small Detail That Sends a Big Signal**

The TLD is the part of the domain that comes after the dot. It plays a bigger role than most people realize. While certain TLDs may indicate a trend or niche, others are linked to authority. A brief summary of popular high-value TLDs is provided below:

- **.com** – The original standard, still the most trusted. If your audience is broad, this is usually your best bet.
- **.io** – Popular with startups and tech companies. Modern and flexible.
- **.ai** – Common among [artificial intelligence](https://www.atlantic.net/vps-hosting/how-to-make-the-best-use-of-artificial-intelligence-in-cloud-computing/) brands. It’s become a signal of cutting-edge technology.
- **.co** – An alternative to .com, often used when the .com version is unavailable. Still professional, especially in global markets.

Choosing the right domain extension now depends on your audience, industry positioning, and global reach rather than just trends. Sending the appropriate message to the appropriate audience is crucial.

### **Domain Name: Keep It Clear and Brandable**

The domain name itself is where your creativity and clarity meet. This part should reflect your brand, product, or idea in a way that’s easy to understand, type, and remember. Here are some best practices:

- **Use exact-match domains when possible** (e.g., BrandName.com or BrandName.co). They make your brand easier to find and remember.
- **Avoid numbers and hyphens. These complicate your name and are easy to mishear or mistype.**
- **Keep it short and clean.** The fewer characters, the better.
- **Choose a name that looks good written out.** You want it to look right on business cards, social media, and emails.
- **A perfect domain name**should also be easy to discover through modern search behaviors and voice-based keyword searches.

A premium domain isn’t just a label; it’s a digital storefront. When it looks and feels premium, people take your brand more seriously.

## **How a Premium Domain Helps Your Business**

Purchasing a premium domain is more than just a branding choice. Long-term, it enhances discoverability, trust, and client retention.

- **It improves credibility.** Clean, identifiable domain names are trusted by customers. A domain like CloudSecure.com feels more reliable than Cloud-Secure247.biz.
- **It boosts brand recognition. A memorable domain helps you stay top-of-mind and increases word-of-mouth traffic.**
- **It enhances SEO indirectly.** While having keywords in your domain isn’t the golden ticket it once was, a clear and relevant name can attract more backlinks, mentions, and engagement, all of which benefit your search ranking.
- **It makes advertising more effective.** From Google Ads to radio mentions, a strong domain gets better results because people remember it.
- **It protects your brand.** Owning the best version of your name helps prevent confusion or competitor misuse.

For small business owners managing multiple domains, premium names also simplify branding across different products and services.

Premium domains function similarly to internet shops in busy locations. Although they don’t ensure success, they certainly increase your chances.

## **Domain Prices and Valuation**

The price of a premium domain can vary widely. Some cost a few hundred dollars. Others sell for six or even seven figures. What drives the price isn’t random—it’s based on real market factors.

### **What Makes a Domain Valuable?**

Here are the key things that affect a domain’s price:

- **Length** – Shorter names are more valuable. One-word and even two-word domains are in highest demand.
- **Clarity** – Easy-to-spell, easy-to-pronounce domains hold more value.
- **Keywords** – Domains that contain high-search-volume keywords are often priced higher.
- **Extension** – A .com domain will typically cost more than alternatives.
- **Industry relevance** – A domain that fits a trending niche or growing sector (like AI, finance, or health) may carry a premium.
- **Existing traffic or history** – Some domains have built-in value from prior use, backlinks, or existing brand recognition.

If you’re unsure what a domain is worth, many marketplaces offer **valuation tools** to help estimate pricing based on recent sales and search trends. Domain valuation today also considers buyer demand, comparable sales, and liquidity across the best domain marketplaces. These tools aren’t perfect, but they provide a helpful range. Some marketplaces also offer human-assisted appraisals, which can give more context around the asking price, especially for names in negotiation.

## **The Top Domain Marketplaces**

Not all domain marketplaces are the same. Some focus on premium listings, while others act as auction houses or reseller platforms. Here are five of the best places to buy a premium domain, each offering unique features.

### 1. [**Atom.com**](https://atom.com)

![](https://www.atlantic.net/wp-content/uploads/2025/10/Print-01-1024x640-1.jpg)

Atom.com is one of the most advanced domain marketplaces available today. What makes it stand out is its **AI-powered search engine**, which lets buyers describe their brand or idea in natural language and then find matching domains based on emotional tone, branding potential, and market fit.

Here’s what sets Atom apart:

- **AI-based semantic search** helps match your brand vision to available domains. Instead of relying on exact keywords, you can describe your business idea, target audience, or brand ethos in natural language.
- **Expert-curated listings**handpicked by branding professionals with experience working with major companies like Pepsi, Hilton, and Siemens.
- **Flexible payment plans** that make premium domains accessible to [startups](https://www.atlantic.net/dedicated-server-hosting/most-promising-start-ups-to-watch-in-2023/) and solo founders. Atom offers flexible ownership options, including lease-to-own and installment plans.
- **Full-service transfer support** ensures a smooth handoff once you purchase a domain. Their team manages the entire technical process of moving the domain to your preferred registrar, eliminating complexity and potential errors for a worry-free experience.
- **Its intuitive interface and smart filtering options make it easier for potential buyers to discover high-quality premium domain names quickly.**

If you’re looking for premium domains that feel tailored to your brand, Atom is the best place to start.

### **2. GoDaddy**

![](https://www.atlantic.net/wp-content/uploads/2025/04/godaddy-logo.png)

GoDaddy is the biggest name in the domain world. Along with being a traditional registrar, it also hosts a large marketplace for premium domains, including expired domains and private sellers. Key features:

- **Wide selection** of premium names, from startup-friendly to enterprise-level. This sheer volume means you can find options across nearly every market, keyword category, and price point.
- **Auction platform** for bidding on domains at competitive prices. This provides an opportunity to acquire desirable domains at market-driven prices,
- **Built-in valuation tool**that estimates a domain’s market worth. While not a formal appraisal, this feature serves as a useful benchmark for buyers and sellers to gauge a fair price during negotiations.
- **GoDaddy Auctions**remains one of the most active spaces for domain flipping and acquiring aged domains with existing traffic.

While the interface can feel cluttered, GoDaddy remains a top choice for buyers who want variety and industry scale.

### **3. Namecheap**

![](https://www.atlantic.net/wp-content/uploads/2025/08/unnamed.jpg)

Namecheap is known for its low-cost domain registration, but it also offers a growing collection of premium domains for sale. Namecheap’s marketplace is ideal for small businesses, entrepreneurs, and first-time premium buyers who are looking for a straightforward way to acquire a better domain name.

Why people choose it:

- **Simple, clean interface** that’s beginner-friendly. This beginner-friendly design removes the typical clutter and complexity, allowing you to focus solely on finding the right domain for your project.
- **No-pressure pricing**most premium listings are buy-it-now. Such transparency allows for a quick, simple transaction where you know the exact cost upfront, appealing to buyers who value efficiency.
- **WHOIS privacy** included with most purchases. This service shields your personal contact information from the public database, protecting you from spam and enhancing your security from day one at no additional cost.

Namecheap is a good fit for smaller businesses and solo projects looking for premium quality without a high-pressure sales environment.

### **4. Porkbun**

![](https://www.atlantic.net/wp-content/uploads/2025/10/porkbun-768x168-1.png)

Porkbun is known for being reasonably priced and surprisingly easy to use. It has some hidden gems, despite not being recognized for listing extremely expensive domains. Highlights:

- **Transparent pricing** with no surprises at checkout. The price you see is typically the price you pay, with minimal and clearly stated fees, ensuring there are no surprise charges during the checkout or transfer process.
- **Free WHOIS privacy** and email forwarding.These valuable extras provide immediate utility and represent significant cost savings for anyone launching a new website or project.
- **Modern TLD support** (.dev, .app, .ai, etc.).This focus makes it a decent platform for tech startups, developers, and modern brands looking for a short, relevant, and memorable web address.
- **I****t’s a strong option**for users comparing multiple platforms while prioritizing affordability and user friendly navigation.

Porkbun is a solid pick if you’re looking for something affordable, especially if your brand leans modern or tech-savvy.

### **5. Sedo**

![](https://www.atlantic.net/wp-content/uploads/2025/10/Sedo_logo.svg_.png)

Sedo is one of the largest domain marketplaces in the world, with millions of listings and a strong presence in the domain investor community. Best features:

- **Massive inventory** of both premium and everyday domains, listing over 19 million domains for sale.
- **Brokerage services** if you want help negotiating a sale. An experienced broker will act on your behalf to contact the owner, negotiate a price, and facilitate the sale, providing expertise and anonymity for sensitive transactions.
- **Escrow support** for [secure transactions](https://www.atlantic.net/pci-compliant-hosting/how-cloud-based-technology-detects-red-flags-and-suspicious-activities-in-transactions/). The buyer’s payment is held safely until the seller has successfully transferred ownership of the domain, at which point the funds are released, completely mitigating financial risk in the deal.
- **Sedo’s global reach**makes it ideal for connecting sellers with serious buyers across international markets.

Sedo caters to both buyers and sellers, which can make it slightly more complex to navigate but it’s a powerhouse when it comes to selection.

## **Conclusion**

Finding the right domain is more than just checking what’s available. A premium domain gives your brand instant credibility, better visibility, and a more professional identity. It’s one of the few digital assets that can increase in value over time, and one of the most important investments you’ll make early on.

Whether you’re starting a new company or leveling up an existing one, buying from a trusted marketplace can save you time, money, and stress. Start by defining what you want in a domain, explore platforms that align with your goals, and don’t be afraid to invest in a name that truly reflects the value of what you’re building.

With the right domain, you’re not just naming your brand, you’re claiming your space on the internet.


---

# What Is Protected Health Information (PHI) in 2026? Complete Guide to Protected Health Information

> URL: https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/ | Published: 2026-04-14 | Updated: 2026-09-15 | Author: Richard Bailey

## **What Is Protected Health Information (PHI)?**

Protected Health Information (PHI)  is patient data that is individually identifiable health information, something that is unique to the patient and something unique that can be traced back to an individual. The Health Insurance Portability and Accountability Act (HIPAA) regulation was created in part to ensure the confidentiality, integrity, and availability of PHI.

## **PHI Definition**

Understanding the protected health information definition is critical for any HIPAA covered entity handling healthcare data within a modern health care system. Of course, members of the public and healthcare professionals may have different viewpoints on what exactly constitutes PHI, but in reality, PHI is any individually identifiable health information held on file by the covered entities such as a healthcare provider (consumer health information), healthcare clearinghouses (insurance information and billing information), health care clearinghouses and health plan healthcare providers.

## **ePHI or e-PHI**

You may also encounter the acronym ePHI or e-PHI, or electronic protected health information. e-PHI refers to healthcare data stored, transmitted, or accessed in electronic systems, including cloud-based environments and distributed data sets used in healthcare operations.

![](https://www.atlantic.net/wp-content/uploads/2021/08/what-is-phi.png)

![](https://www.atlantic.net/wp-content/uploads/2021/08/baa_1.png)

### **Get a Business Associate Agreement today!**

Before you can go live with real PHI in your environment, you must get a Business Associate Agreement (BAA) in place. The BAA protects all parties, and both the covered entity (typically the healthcare institution) and any business associate (the 3rd party like Atlantic.Net) must comply with the rules protecting PHI.

The Health Insurance Portability and Accountability Act (HIPAA) has strict rules about this and requires a business associate agreement (BAA) in place.

![](https://www.atlantic.net/wp-content/uploads/2021/08/components_1.png)

#### **Components of a BAA**

A BAA has three central components:

- Outline exactly how the Business Associate interacts with PHI, including how the protected health information is used and if any disclosure takes place.
- Set clear limitations on what the third party must not do with the data, including any disclosure not stated in the agreement.
- Define appropriate measures to prevent the use or disclosure of PHI other than disclosure that is permitted or required by applicable HIPAA and HITECH mandates.

![](https://www.atlantic.net/wp-content/uploads/2021/08/what-is-phi_2.png)

## **What Is Protected Health Information (PHI) Exactly?**

To provide you with a detailed explanation of what exactly is PHI, we have broken this article into five sections:

- **Protected Health Information (PHI) Definition**
- **18 Identifiers of PHI**
- **Research Examples of Protected Health Information (PHI)**
- **Physical, Technical, and Administrative Safeguards**
- **Partners in PHI**

![](https://www.atlantic.net/wp-content/uploads/2021/08/medical-studies_1.png)

### **Protected Health Information (PHI) Definition**

What is PHI? The reason that the concept of **protected health information** exists is really to clarify the parameters of HIPAA. It delineates the specific type of data that is protected by the law.

PHI is any data contained within a designated record set or [electronic health record](https://www.medesk.net/en/blog/ehr-implementation/) that refers to a specific individual and is created, received, or maintained during healthcare operations.

The provisions of HIPAA permit teams conducting studies to use electronic protected health information (ePHI) to advance medical understanding. However, according to[UC Berkeley](http://cphs.berkeley.edu/hipaa/hipaa18.html), information is only protected by the law if it is contained within an electronic health record that was used for a healthcare service.

HIPAA law is overseen by the Office for Civil Rights under the U.S. Department of Health and Human Services (HHS), which continues to refine enforcement around healthcare data privacy.

The OCR offers a[definition of PHI health information](http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/De-identification/guidance.html) as data pertaining to:

- A patient’s health status at any point in time;
- Information regarding any healthcare operations
- Any instance of care provided to a patient;
- Any billing data “for the provision of health care to the individual, and that identifies the individual or for which there is a reasonable basis to believe can be used to identify the individual.” This applies to past, present, or future billing information from health care providers.

![](https://www.atlantic.net/wp-content/uploads/2021/08/identifiers_1.png)

### **18 Identifiers of PHI**

There are 18 elements of data that serve as identifiers, meaning that they are considered protected health information within the context of healthcare services.

If you as a HIPAA covered entity maintain a data set containing any of these identifiers, it must comply with the HIPAA Security Rule, including strict access controls and breach prevention measures.

- Any part of a person’s name;
- Any location information that is more specific than the state, such as a street address, town, or county (however, there is an exception: you can use the first three numbers within a ZIP Code if “[t]he geographic unit formed by combining all zip codes with the same three initial digits contains more than 20,000 people” or if you replace the first three digits with 000);
- The months and days of any patient services or events (birthdate, date of treatment, etc.), although the year is unprotected. Specifically, any data showing that someone is 90 years or older is considered an identifier unless it is brought together under the single heading of 90 and above;
- Any phone number or phone numbers belonging to the patient;
- Any patient fax number(s);
- Any Email address or email addresses;
- Social security numbers or a social security number;
- Medical record numbers;
- Numbers associated with health insurance or plans, such as health insurance beneficiary numbers;
- The ID number for the account;
- Numbers associated with state registrations or licenses;
- Car tags or vehicle identification numbers (including vehicle identifiers or license plate numbers);
- Device identifiers or any data related to particular computers, including serial numbers;
- URLs specific to individual patients;
- Internet Protocol (IP Address) of patient devices;
- Biometric identifiers such as fingerprints, retina scans, or voiceprints;
- Photographs in which the person’s face is visible; and
- Any other features or numbers that directly relate to the patient.

#### **![](https://www.atlantic.net/wp-content/uploads/2021/08/sharing-health-info_1.png)Exceptions When Sharing Health Information**

There are, of course, some circumstances when PHI can be shared by a covered entity. When there is a serious risk to the patient’s health, the immediate family may need to know health information urgently. Bulk PHI can be shared by the healthcare industry but only in specific scenarios, mostly regarding academic research. Data must be anonymized, obfuscated, and possibly have key data redacted or changed.

![](https://www.atlantic.net/wp-content/uploads/2021/08/research_1.png)

### **Research Examples of PHI**

One way that PHI is used by research teams is to look at the medical files of a certain group of people treated in a particular way for a diagnosed health condition – such as self-reported pain ratings of osteoarthritis patients six months after they were treated with total knee replacements (TKRs). In that case, PHI gives researchers a spotlight on the effectiveness of a particular approach.

![](https://www.atlantic.net/wp-content/uploads/2021/08/studies_1.png)

#### **Studies Generating PHI**

Another scenario in which research must follow HIPAA Compliance is when the study itself generates PHI. That occurs when patients are delivered healthcare services as part of the study, such as diagnostic tests or breakthrough treatments that are being compared to traditional options. One example is a clinical trial that involves people with a certain health condition taking an experimental pharmaceutical, with the PHI submitted to the FDA for the drug’s application.

![](https://www.atlantic.net/wp-content/uploads/2021/08/medical-studies_1.png)

#### **Medical Studies without PHI**

Now, keep in mind, the PHI identifiers listed above are critical. Any health data that is not associated with one of those 18 elements is not classified as protected by the government. For instance, a dataset that contains medical readings is not federally protected just on the basis that the readings were taken. A data set that contains only anonymized clinical readings without any unique identifying number or linkage to an individual is not considered PHI under current guidance. However, if a medical file is connected to a specific patient via the inclusion of an account number, all data within that file is legally protected.

Just because you are conducting research does not mean that you are necessarily working with PHI – in other words, you don’t always need to be concerned with HIPAA. Specifically, if you are conducting research with information that contains identifiers, it’s not protected information if it is unrelated to an interaction (such as outpatient care, transfer of files, or billing) that involves patients’ electronic health records.

![](https://www.atlantic.net/wp-content/uploads/2021/08/physical-safeguards_1.png)

## **What Are the Physical Safeguards for PHI / ePHI?**

All physical precautions refer to the implementation specifications for real-life physical controls on digital devices that store and handle e-PHI.

Some of the key areas for consideration are:

- How old or faulty equipment is replaced – for example, how ePHI media is destroyed
- What personnel access levels are granted to in-scope systems containing ePHI; specifically, covered entity / covered entities must ensure that access is only granted to employees with a relevant level of authorization
- How to train 3rd-party IT professionals when accessing the in-scope equipment for repairs

![](https://www.atlantic.net/wp-content/uploads/2021/08/technical-safeguards_1.png)

## **What Are the Technical Safeguards for PHI / ePHI?**

The technical assurances of the HIPAA Security Rule are more easily defined and include the technical aspects of any networked computers or devices that communicate with each other and contain PHI in their transmissions.

These precautions include enhanced network security, enhanced system security, data availability, perimeter firewalls, [cybersecurity](https://www.sailpoint.com/identity-library/five-types-of-cybersecurity/) authentication protocols, and more. Any security measures that can be implemented on system software or hardware belonging to the HIPAA security rules technical protections category.

![](https://www.atlantic.net/wp-content/uploads/2021/08/administrative-safeguards_1.png)

## **What Are the Administrative Safeguards for PHI / ePHI?**

The final standard, administrative guarantees, covers how covered entity / covered entities must set up their employee policies and procedures to comply with HIPAA’s Security Rule. Administrative safeguards must align with evolving guidance from health and human services, including workforce training on handling personally identifiable information and breach response protocols. Think of it as a separate, dedicated portion of employee training, both for management and labor defining who gets access and what they can and cannot do once access is granted.

![](https://www.atlantic.net/wp-content/uploads/2021/08/partners-in-phi_1.png)

### **Partners in PHI**

The security and integrity of health data are a must to be in compliance with HIPAA regulations. Hopefully, the PHI examples above are helpful to understand what you need to protect to be federally compliant. Organizations must ensure that any partner supporting healthcare operations understands responsibilities around PHI, data breaches, and secure data set management. However, you also need to know whether technology providers and business associates understand the needs of your organization.

A [HIPAA web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solution can help achieve your objective.

*“Atlantic.Net’s … financial strength and proven track record are something we view with great confidence,” Complete Healthcare Solutions Vice President***Joseph Nompleggi has said of our partnership.**

Atlantic.Net is a specialist in HIPAA Compliance, and we have 30 years of experience providing security-defined [hosting solutions](https://www.atlantic.net/hosting-services-provider/). For a covered entity or leading healthcare providers, becoming HIPAA Compliant is critical, and choosing the right HIPAA data storage partner can enable them to continue the best patient care possible.

![](https://www.atlantic.net/wp-content/uploads/2021/08/more-info_1.png)

### **Get More Information**

Here are a few links that could be beneficial to Covered Entities and Healthcare providers to comply with the HIPAA regulations:

- How to Become HIPAA-Compliant:[Our 10-Step Guide](https://www.atlantic.net/hipaa-compliant-hosting/how-to-become-hipaa-compliant/)
- Penalties for Non-Compliance of HIPAA –[What Is the Fine?](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-penalty-for-a-hipaa-violation/)
- HIPAA Compliant Hosting for a Web Application:[8 Questions to Ask](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-hosting-for-a-web-application-8-questions-to-ask/)
- HIPAA Business Associate Agreement –[What Is a BAA?](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/)
- [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)

![](https://www.atlantic.net/wp-content/uploads/2021/08/hosting-provider_1.png)

## **Atlantic.Net: Your HIPAA Compliant Hosting Provider **

**Whether you are a Covered Entity or healthcare clearinghouse,**[**HIPAA Compliant Hosting**](https://www.atlantic.net/hipaa-compliant-hosting/)**from Atlantic.Net can help protect and secure the integrity of your health data! Get started today with a free HIPAA Compliant Hosting trial by Phone at**866-618-DATA (3282) or email sales@atlantic.net today.

---

#### Read More About HIPAA Compliance

- [HIPAA Compliance Checklist](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/)
- [How to Become HIPAA Compliant](https://www.atlantic.net/hipaa-compliant-hosting/how-to-become-hipaa-compliant/)
- What Is the [HIPAA Security Rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/)?
- Top Considerations for [HIPAA File Storage](https://www.atlantic.net/hipaa-compliant-hosting/top-10-considerations-for-hipaa-compliant-file-storage/)
- [HIPAA Data Storage Requirements](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-cloud-storage/)
- Protecting [e-PHI](https://www.atlantic.net/hipaa-compliant-hosting/protecting-phi-cloud/) in the Cloud
- What Is [HIPAA Cloud Computing](https://www.atlantic.net/hipaa-compliant-hosting/what-is-hipaa-cloud/)?
- What Is [Healthcare Hosting](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/)?

---


---

# GPU for Deep Learning: Critical Specs and Top 7 GPUs in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/gpu-for-deep-learning-critical-specs-and-top-7-gpus/ | Published: 2026-04-14 | Updated: 2026-04-17 | Author: Gilad Maayan

## What Are GPUs?

GPUs, or graphics processing units, were originally created to render images and video. Today, GPUs are widely used for machine learning tasks, computer vision, and AI training, making them essential for handling demanding AI workloads across industries. Their primary function was to offload compute-intensive tasks from the CPU, managing the complex calculations necessary for rendering graphics quickly. Over time, their capabilities have expanded, positioning them as parallel processors capable of handling a variety of demanding computational tasks. This evolution has made GPUs critical for large scale AI training, including training deep neural networks and working with massive models.

Modern GPUs are highly parallel, allowing them to process many tasks simultaneously, making them ideal for applications requiring significant computational resources over numerous processes. Unlike CPUs, which are optimized for sequential task processing, GPUs can manage thousands of threads at once. This architecture delivers strong performance for GPU workloads such as fine tuning models, inference performance optimization, and computer vision pipelines. This architecture has proven useful for tasks that benefit from parallelism, such as matrix operations key to deep learning algorithms.

For students embarking on their deep learning journey, a well-structured [writing guide](https://essayhub.com/blog/how-to-write-an-appendix-explained-with-ease) can help simplify the process of understanding these advanced concepts, and platforms like EssayHub can provide additional insights into how GPUs impact various AI models.

This is part of a series of articles about [GPU for AI](https://www.atlantic.net/gpu-server-hosting/gpu-for-ai-platforms-top-gpus-and-key-features-to-consider/).

## Critical GPU Specs for Successful Deep Learning

### Tensor Cores

Tensor Cores are specialized hardware components within some modern GPUs that accelerate deep learning workloads. They are optimized for performing mixed-precision matrix operations, such as matrix multiplications and accumulation. Tensor Cores can handle operations in FP16 (16-bit floating point) and FP32 (32-bit floating point) simultaneously.

### Clock Speed

Clock speed, measured in MHz or GHz, determines how quickly the GPU cores can execute instructions. A higher clock speed usually means faster processing and more computations per second. For deep learning, while parallelism (number of cores) is more critical, clock speed aids in determining how fast individual computations within those parallel processes are performed.

### VRAM

VRAM (Video Random Access Memory) is the dedicated memory available on the GPU to store data needed for computations. When evaluating GPUs, one key question is how much memory is required, as model size and dataset size directly impact VRAM needs for large scale training. It stores the deep learning model parameters, input data, and intermediate computations during training and inference. Larger VRAM allows for bigger batch sizes and more complex models to be processed without memory overflow.

### Memory Bandwidth

Memory bandwidth refers to the speed at which data can be read from or written to the GPU’s memory. Higher bandwidth improves training speed and inference performance, especially for computer vision and large scale AI training workloads. A GPU with higher memory bandwidth allows for faster data transfer, which is critical for training large neural networks where delays in memory access can become a bottleneck.

### L2 Cache and L1 Cache

L2 and L1 caches are small, fast memory units closer to the GPU cores, which are used to temporarily store data that is frequently accessed. Caching helps reduce the need to fetch data repeatedly from the slower main memory (VRAM). The size and efficiency of these caches can impact the performance of deep learning models, reducing latency and improving throughput.

### CUDA Cores/Stream Processors

CUDA Cores (on NVIDIA GPUs) or Stream Processors (on AMD GPUs) are the primary processing units that execute compute operations on the GPU. The number of CUDA Cores or Stream Processors influences the GPU’s ability to handle parallel computations. For deep learning, a higher count typically means more concurrent operations can be executed.

### FP16/FP32/INT8 Performance

The performance of a GPU in various data precision formats determines its efficiency in different stages of deep learning. FP32 (single-precision) is the standard for training due to its accuracy, but FP16 (half-precision) has gained popularity for training and inference to improve speed and reduce memory usage. INT8 (8-bit integer) is often used for inference optimization as it requires even less memory and can accelerate model deployment, albeit with some precision trade-offs.

### Compute Capability (FLOPS)

FLOPS (Floating Point Operations Per Second) is a metric that indicates the raw computational power of a GPU. The higher the FLOPS, the more capable the GPU is at performing floating-point calculations. Both single-precision (FP32) and half-precision (FP16) FLOPS are important to consider to balance performance and accuracy.

### Multi-GPU Scalability

Multi-GPU scalability refers to the GPU’s ability to work effectively in parallel with other GPUs to accelerate computation. In deep learning, scaling up to multiple GPUs is often necessary to train large models quickly or handle large datasets. Efficient multi-GPU communication, enabled by interconnects like NVLink or PCIe, allows for faster data exchange between GPUs, reducing training times and enabling the distribution of workloads across several GPUs.

***Related content: Read our guide to GPU cloud computing***

## Top GPUs for Deep Learning in 2026

### 1. NVIDIA A100

**Specs:**

- CUDA cores: 6,912
- Tensor cores: 432
- GPU memory: 40 GB or 80 GB HBM2
- Memory bandwidth: 1,555 GB/s
- Power consumption: 250 to 400 Watts (depending on configuration)
- Clock speed: 1.41 GHz
- Thermal Design Power (TDP): 400 Watts

The NVIDIA A100, built on the Ampere architecture, the A100 brings significant performance improvements and excels in tasks involving deep learning model training and inference. It features Tensor Cores, specifically built for AI tasks, which accelerate matrix computations that are essential for deep learning. The A100 supports mixed-precision training, combining FP16 and FP32 formats to balance performance and accuracy.

A key advantage of the A100 is its high memory capacity, with up to 80 GB of HBM2 memory. This large memory pool allows for the handling of extremely large datasets and complex models, which are often required in advanced AI tasks.

Additionally, the A100 incorporates multi-instance GPU (MIG) technology, enabling the division of a single GPU into multiple instances for different tasks. This makes it ideal for data centers and large-scale AI deployments, as multiple workloads can run concurrently on a single A100, maximizing resource efficiency.

The A100 is widely used for large scale AI training, supporting massive models, high model size requirements, and delivering strong performance for demanding AI workloads such as computer vision and training deep neural networks.

### 2. NVIDIA RTX A6000

**Specs:**

- CUDA cores: 10,752
- Tensor cores: 336
- GPU memory: 48 GB GDDR6
- Memory bandwidth: 768 GB/s
- Power consumption: 300 Watts

The NVIDIA RTX A6000 is a high-performance GPU built for professional applications, including deep learning. Like the A100, it is also based on the Ampere architecture, offering substantial improvements over previous generations in terms of both speed and efficiency. The RTX A6000 comes with 48 GB of GDDR6 memory, which is sufficient for training deep learning models that require a significant amount of memory.

One of the key features of the RTX A6000 is its Tensor Cores, which are optimized for AI tasks and provide accelerated performance for deep learning computations. These Tensor Cores allow for efficient matrix operations, speeding up model training and inference. The RTX A6000 also supports mixed-precision training, which allows for a combination of FP16 and FP32 precisions to enhance both computational speed and memory usage efficiency.

### 3. NVIDIA RTX 4090

**Specs:**

- CUDA cores: 16,384
- Tensor cores: 512
- GPU memory: 24 GB GDDR6X
- Memory bandwidth: 1 TB/s
- Power consumption: 450 Watts
- Memory: 24 GB GDDR6X

The NVIDIA GeForce RTX 4090, though primarily marketed as a consumer-grade GPU that targets high-end gamers, however, it can also be used for deep learning tasks. It is based on the Ada Lovelace architecture and features a high number of CUDA cores—16,384—making it an option for researchers and developers working on smaller to medium-sized deep learning models. With 24 GB of GDDR6X memory, the RTX 4090 is capable of handling moderate dataset sizes.

One of the major advantages of the RTX 4090 is its affordability compared to more specialized GPUs like the A100 or A6000. It also benefits from full support for NVIDIA’s CUDA and cuDNN libraries, which are essential for deep learning development. While it lacks enterprise features like multi-instance GPU (MIG) or NVLink support, the RTX 4090’s high memory bandwidth of 1 TB/s allows for fast data transfers, reducing the time required for training and inference.

Among consumer GPUs, the RTX 4090 is one of the best GPUs for developers working on machine learning tasks, offering strong performance and good cost efficiency for smaller model size workloads.

### 4. NVIDIA V100

**Specs:**

- CUDA cores: 5,120
- Tensor cores: 640
- GPU memory: 16 GB
- Memory bandwidth: 900 GB/s
- Power consumption: 250 Watts
- Clock speed: 1.246 GHz

The NVIDIA V100 is a widely-used GPU for deep learning, created specifically for high-performance computing and AI workloads. Built on the Volta architecture, it includes Tensor Cores that are optimized for deep learning tasks, such as matrix multiplications, which are fundamental to training neural networks. The V100 excels in mixed-precision training, allowing for the combination of FP16 and FP32 calculations to optimize both performance and memory usage.

The V100 comes with 32 GB of HBM2 memory, which provides ample capacity for large-scale deep learning models and datasets. Additionally, the V100 supports NVLink, a high-speed interconnect technology that allows multiple GPUs to be linked together, enabling parallel processing across multiple GPUs.

The V100 remains relevant for AI training, especially for training deep neural networks and computer vision workloads that require stable tensor core performance.

### 5. NVIDIA A40

**Specs:**

- CUDA cores: 10,752
- Tensor cores: 336
- GPU memory: 48 GB GDDR6
- Memory bandwidth: 696 GB/s
- Power consumption: 300 Watts
- NVLink support
- Enhanced for deep learning with Tensor Cores

The NVIDIA A40 is another Ampere-based GPU that offers substantial performance for deep learning tasks. While it is primarily created for professional and data center applications, it can also be utilized effectively for AI workloads. The A40 features 48 GB of GDDR6 memory, providing ample capacity for handling large datasets and complex models that are often required in deep learning. The NVIDIA A40 is often selected for GPU workloads that require a balance between model size handling and training speed.

Similar to other GPUs in the Ampere lineup, the A40 is equipped with Tensor Cores that accelerate AI computations. The A40 also benefits from NVIDIA’s deep learning software ecosystem, including libraries like CUDA, cuDNN, and TensorRT, which optimize the use of GPU resources for AI tasks. While the A40 may not reach the same performance levels as the A100, it is a cost-effective alternative for teams or organizations that need a balance between price and power.

### 6. NVIDIA L40S GPU

**Specs:**

- CUDA cores: 18,176
- Tensor cores: 568
- GPU memory: 48GB GDDR6 with ECC
- Memory bandwidth: 864GB/s
- Power consumption: Watts
- Interconnect interface: PCIe Gen4 x16, 64GB/s bidirectional

The NVIDIA NVL40S Tensor Core GPU offers substantial computational power optimized for deep learning tasks, including neural network training and inference. It is based on the Ada Lovelace architecture and includes fourth-generation Tensor Cores and a large number of CUDA cores. L40S supports mixed-precision training and inference, utilizing FP8, FP16, and BF16 precisions.

Its 48 GB of GDDR6 memory allows for the handling of large and complex models common in deep learning workflows. Additionally, the L40S supports NVLink technology, enabling high-speed connectivity between GPUs for multi-GPU training and efficient data transfers. The L40S is designed for AI training, offering better performance for inference performance, fine tuning, and computer vision applications compared to previous generations.

### 7. NVIDIA H100 NVL

**Specs:**

- CUDA cores: 14592
- Tensor cores: 456
- GPU memory: 94GB HBM2e memory
- Memory bandwidth: 3.9TB/s
- Power consumption: 700 Watts (350 Watts per GPU)

The NVIDIA H100 NVL GPU is part of the Hopper architecture lineup, suitable for handling large-scale deep learning and high-performance computing (HPC) workloads. The H100 NVL is equipped with dual GPUs, delivering a massive combined 188 GB of HBM3 memory.

H100 NVL can scale across multiple GPUs, supporting advanced interconnect technologies like NVLink and NVSwitch. This multi-GPU scalability makes it suitable for large AI clusters and distributed training, as the GPUs can communicate at high speeds, reducing latency and improving overall throughput.

The NVIDIA H100 NVL is one of the best GPUs for large scale AI training, offering unmatched tensor core performance, training speed, and support for massive models. It is widely used by AI researchers working on demanding AI workloads and large scale training across cloud GPUs and platforms like Google Cloud.

## Key Metrics for Evaluating Your Deep Learning GPU Performance

Even after you choose the right GPU for your project, it’s important to measure how effective your GPU is performing. This will allow you to optimize and get the most out of your hardware.

### GPU Utilization

GPU utilization refers to the proportion of GPU resources being used during a task. It is a crucial performance indicator, reflecting how effectively a GPU is employed in processing tasks. High utilization indicates that the GPU is being well-used, which is desirable for maximum efficiency and throughput in deep learning contexts. Conversely, low utilization suggests that the GPU’s capabilities aren’t being fully tapped, possibly due to software inefficiencies or system bottlenecks.

Monitoring GPU utilization is essential in optimizing deep learning performance, as it provides insights into potential areas for improvement in resource allocation. Ensuring high GPU utilization might involve tuning software settings, optimizing model configurations, or balancing workloads to prevent underutilization.

### GPU Memory Access and Usage

GPU memory access and usage denote how efficiently a GPU can read and write data to its memory. These metrics significantly affect deep learning performance, where rapid data exchange and efficient memory management enhance modeling processes. Proper memory handling ensures that the GPU has timely access to data, which is crucial for maintaining a high computational throughput during the training and inference of AI models.

Effective GPU memory access and usage are essential for utilizing available resources optimally. Deep learning models often require significant memory bandwidth for data handling, so efficient memory use can prevent bottlenecks, ensuring smoother data flow.

### Power Usage and Temperatures

Monitoring power usage and temperatures is vital in maintaining GPU performance and longevity. High power consumption might suggest excessive resource demand, potentially indicating inefficiency, while elevated temperatures can lead to throttling or hardware damage. In deep learning tasks, balancing powerful processing with efficient thermal management ensures a GPU operates safely at optimal performance levels.

Efficient management of power and temperatures involves employing adequate cooling systems and optimizing workload distribution. These factors are important in preventing performance degradation caused by overheating. By understanding power and thermal characteristics, users can employ strategies to maintain GPUs at their peak performance.

### Time to Solution

Time to solution is a critical metric for assessing GPU performance, especially in deep learning applications. This metric defines the total time required to complete computational tasks, from training models to deploying them. A shorter time to solution implies high efficiency in terms of cost and productivity, as it reflects how swiftly a GPU can complete the necessary calculations to achieve desired outcomes in AI projects.

Evaluating time to solution involves analyzing performance across many factors, including GPU throughput, memory access, and overall resource management. By focusing on reducing time to solution, researchers and developers can maximize their productivity and streamline processes, enabling rapid iterations and refinements of AI models.

## **Next-Gen Dedicated GPU Servers from Atlantic.Net, Accelerated by NVIDIA**

Experience unparalleled performance with dedicated cloud servers equipped with the revolutionary NVIDIA accelerated computing platform.

Choose from the NVIDIA L40S GPU and NVIDIA H100 NVL to unleash the full potential of your generative artificial intelligence (AI) workloads, train large language models (LLMs), and harness natural language processing (NLP) in real time.

High-performance GPUs are superb at scientific research, 3D graphics and rendering, medical imaging, climate modeling, fraud detection, financial modeling, and advanced video processing.

[Learn more about Atlantic.net GPU server hosting.](https://www.atlantic.net/gpu-server-hosting/)

 


---

# Top 10 HIPAA Training Companies in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/top-10-hipaa-training-companies/ | Published: 2026-04-14 | Updated: 2026-05-03 | Author: Richard Bailey

Training is a mandatory requirement of the HIPAA Privacy and Security Rules first introduced in 2003. HIPAA, which stands for the Health Insurance Portability and Accountability Act, requires ongoing HIPAA compliance training to ensure employees understand how to handle protected health information and follow established compliance practices. HIPAA requires the continuous training of employees who access or process Protected Health Information (PHI), and this requirement applies to any workforce member of a Covered Entity (CE) or Business Associate (BA). Humans are considered by many experts to be one of the weakest links in the entire security ecosystem; the [Ponemon Institute](https://www.ibm.com/security/digital-assets/cost-data-breach-report/#/pdf) estimates that 23% of all data breaches in 2020 were caused by Human Error.

The rules for HIPAA training are very generalized, and there are no direct guidelines of what the training requirements should be; instead, HIPAA emphasizes creating a necessary and appropriate training program using information gathered during the initial risk assessment. Employers must then tailor a training program towards the relevant employees. Modern HIPAA training programs are often delivered through an online course format, allowing employees to learn at their own pace with self paced modules accessible via desktop computers and mobile devices.

Due to this lack of clarity, it is easy to see why outsourcing the training element to a specialist partner is becoming increasingly popular. Many HIPAA training providers now offer structured course content aligned with the latest HIPAA regulations, including the HIPAA privacy rule and HIPAA security rule. As there are many options out there for HIPAA training, we have compiled a list of the top 10 HIPAA training companies in 2026.

## 1. TeachMeHIPAA

[TeachMeHIPAA](https://teachmehipaa.com/)

TeachMeHIPAA offers the [lowest cost HIPAA training solution](https://teachmehipaa.com/) available. At $17.95 per trainee, they make it extremely simple and easy to set up your organization and train your whole team in just minutes. Their HIPAA training course includes essential course content focused on patient privacy, HIPAA terms, and handling protected health information. They are trusted by thousands of healthcare companies across the country, and appreciated for their easy to use modern platform and training content.

## 2. Accountable HQ

[accountable HQ](https://www.accountablehq.com/)

Accountable provides companies with a complete solution to all the administrative requirements set out under HIPAA. Their platform is streamlined in five key checklists, which include assigning privacy officers, adopting policies & procedures, employee training, compliance risk assessment, and Business Associate Agreement. Their training programs support healthcare providers and health plans in meeting HIPAA regulations and maintaining consistent compliance practices. What makes Accountable so popular is the quality of the training material and that their pricing options include Unlimited Employee Training, with costs ranging from $359 to $1349 per month.

## 3. HIPAATraining.com

[HIPPA training](https://www.hipaatraining.com/)

For more than 18 years, HIPAATraining.com, a Digital Compliance company, has been helping organizations attain fast HIPAA compliance with minimum administrative effort. Their comprehensive HIPAA Awareness training provides each course participant with a nationally recognized certification. Upon successful completion, users receive a HIPAA certificate that demonstrates their understanding of HIPAA compliance and patient rights. Their bilingual program provides cumulative discounts with no contracts and user support available 5 days/week.

## 4. **ComplianceOnline.com**

MetricStream’s ComplianceOnline.com is the largest advisory network and online community of GRC professionals and experts. It is the trusted source for GRC practitioners worldwide seeking information, best practices, training, products, and tools on corporate governance, risk management, regulatory compliance, and quality management.

Hundreds of companies worldwide that handle sensitive client information turn to ComplianceOnline’s[HIPAA training](https://www.complianceonline.com/hipaa-hitech-regulations-training-5050-c) each year to ensure that they and their employees learn to do everything they can to keep their clients’ private information safe. ComplianceOnline.com offers a variety of channels for the dissemination and exchange of information through online training, events, workshops, content feeds, information search, discussion forums, and best practices library services.

## 5. Total HIPAA

[Total HIPAA](https://www.totalhipaa.com/) Compliance offers a comprehensive solution for developing and implementing your organization’s personalized HIPAA compliance plan. Their compliance package provides interactive online HIPAA training, a thorough Risk Assessment, and compliance materials. Their programs also prepare employees for HIPAA certification while reinforcing compliance practices and security awareness.

## 6. MedTrainer

[MedTrainer](https://medtrainer.com/) is a cloud-based [healthcare compliance training solution](https://medtrainer.com/products/mt-learning/). HIPAA makes up only part of their content library, however, upon signup, you receive access to the full course library. Their training supports healthcare providers by delivering HIPAA compliance training focused on the healthcare industry and evolving security requirements. The system tracks employee training progress and certification status.

## 7. ProTrainings

[ProTrainings.com](http://protrainings.com/) is the first paid training course featured in our Top 10. ProTrainings offers a “ProHIPAA” certification training course for only $29.95. It has excellent content on HIPAA/HITECH requirements and the very latest healthcare compliance information. The HIPAA training course is self paced, allowing learners to complete modules at their own pace and receive a certificate upon completion. The course emphasizes the employee’s role under HIPAA law.

## 8. Medscape

Medscape is highly recommended by the [Department of Health and Human Services](https://www.hhs.gov/hipaa/for-professionals/training/index.html) (HHS). The content is primarily focused on the Final Omnibus Rules. It also includes course content covering patient rights, patient privacy, and updates to HIPAA regulations within the healthcare industry. This content is also free but requires registration.

## 9. The HIPAA Academy

The HIPAA Academy is a premium training company that targets large and enterprise-scale healthcare organizations. They offer a Certified HIPAA Professional (CHP) training course and certification that is extremely popular. Participants can earn a HIPAA certification and become HIPAA certified through structured programs designed around the latest HIPAA regulations. Currently, all courses are offered online, but classroom or onsite training is available under normal circumstances. What we liked were the detailed study guides and online support groups. The 3 day CHP course is $1295, plus around $700 for the exam, so it’s not cheap, but the content is well made and professional, and the online content delivery is superb.

## 10. The HIPAA Training Site

The HIPAA Training Site is another paid training resource, but all their content is dedicated to the legality side of HIPAA compliance. Their training emphasizes the HIPAA security rule, HIPAA privacy rule, and complex regulations tied to the accountability act. It was founded by a number of attorneys who have dissected the legislation in its entirety. Costs range from $25-$50 per employee, but only the $50 course for Compliance Officers offers a certification path.

## 11. Etactics K2 Akademy

Etactics’ K2 Akademy is a Learning Management System (LMS) as a service that provides over 40 different modules that cover a variety of HIPAA-related topics. Their course content includes interactive lessons on compliance practices, patient privacy, and handling protected health information in real-world scenarios. Its content is interactive and entertaining while using proactive learning techniques through quizzes, workbooks, and activities that ensure workforce retention. Mandated training doesn’t have to be lousy, and K2 Akademy proves that.

## Additional Resources:

### State Attorneys General

[state attorneys general](https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/state-attorneys-general/index.html)

The Office for Civil Rights (OCR) and the Department of Health and Human Services have published detailed training material online that focuses on HIPAA Rule Enforcement. It also gives a great overview of the HIPAA statute, the HITECH Act, the HIPAA Privacy, Security, and Enforcement Rules, and the Breach Notification Rule. 

## How Can Atlantic.Net Help?

Atlantic.Net has more than 25 years of experience exceeding the needs of health professionals and is one of the country’s leading healthcare technology companies. If you’re in this industry and you need help with IT, contact our sales team to find out how our managed services could help your organization.

If you are in the market for managed IT services for healthcare, make sure you choose an experienced HIPAA compliant provider that focuses on security, business continuity, and scalability: a provider that can grow with you, and one that focuses on collaboration and data interoperability. We know that the regulations of the industry are intense, but Atlantic.Net can take away the stress of managing your entire IT operation.

We have an extensive list of healthcare clients who have trusted us for many years, and our managed service packages really do allow you to forget about the complexities of IT and focus on your patients. Our services help protect sensitive environments, support handling protected health information, and align infrastructure with HIPAA compliance and certification standards. We will work with you to identify and secure PHI, protect you from ransomware attacks, and offer you the very best Healthcare Managed Services platform available. Atlantic.Net offers [HIPAA Web Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA Compliant Cloud Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)services to support IT Solutions for Healthcare.


---

# Top 10 HIPAA Consulting Companies in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/top-10-hipaa-consulting-companies/ | Published: 2026-04-14 | Updated: 2026-04-17 | Author: Dr. Rachael Bailey

## What Are HIPAA Consulting Companies?

HIPAA consulting companies are made up of a team of compliance experts with a vast understanding of the legal complexities surrounding HIPAA compliance and healthcare compliance requirements. These firms provide expert guidance to help organizations navigate complex regulations and align with evolving HIPAA rules and HIPAA privacy standards. Typically, members of the consulting team each specialize in different elements of HIPAA.

HIPAA consultants and HIPAA compliance consultants work to ensure that covered entities (CEs) and business associates (BAs) meet strict HIPAA regulations and maintain HIPAA compliance across all systems handling sensitive health data. A HIPAA consulting services firm can help to guide CEs and BAs through the whole process of HIPAA compliance or offer targeted support, for example, by reviewing current HIPAA policies, policies and procedures, and compliance gaps to identify areas for improvement. This support is critical throughout the HIPAA compliance journey, especially for organizations managing a complex patient data environment.

## What Do HIPAA Consulting Companies Do?

Maintaining HIPAA compliance is essential to ensure the safety of a patient’s personal health information and to maintain a high standard of patient care. However, the logistics of maintaining a compliant medical practice can make life difficult for busy healthcare providers. With countless rules and regulations to adhere to, healthcare organizations are turning towards HIPAA consulting companies to help them to address these challenges.

Modern HIPAA consulting services support healthcare organizations by performing risk assessments, risk analysis, and risk management planning to protect sensitive patient information and prevent data breaches. These consulting services also help healthcare providers implement technical safeguards, security controls, and security awareness training to strengthen their overall security posture.

They also establish security measures to reduce security risk and ensure healthcare organizations remain aligned with HIPAA rules and compliance requirements. Regular risk assessments are a key part of HIPAA compliance services, helping identify vulnerabilities before they lead to data breaches.

## Top HIPAA Consulting Companies

Engaging a HIPAA consultant can take the pressure off healthcare organizations and their BAs, maximizing their valuable time and minimizing the risk of non-compliance. A reputable HIPAA consulting company will formulate a tailored support plan to address an organization’s specific needs. With no shortage of options, choosing a suitable HIPAA consultant can be a bit of a minefield, so we have collated a list of the Top 10 HIPAA Consulting Companies:

1. CynergisTek, Inc.
2. Appinventiv
3. ScienceSoft
4. Clearwater Compliance
5. Arka Softwares
6. InCompliance
7. Healthicity, LLC.
8. Praetorian Secure
9. RSM US
10. Acevedo Consulting, Inc.

## 1. CynergisTek, Inc.

CynergisTek is a highly-ranked cybersecurity and information management firm which provides cybersecurity, privacy, and compliance services and solutions to the healthcare industry. The company primarily serves the healthcare industry, having formed a trusted partnership with hundreds of healthcare organizations since 2004. CynergisTek focuses heavily on regulatory compliance, risk management, and continuous monitoring to help organizations maintain HIPAA compliance under increasing regulatory scrutiny. CynergisTek has been recognized as a leader in the industry, which includes being named by KLAS as a top-performing firm within the field of healthcare cybersecurity and being awarded the 2019 Top Healthcare Cybersecurity Consults in Black Book IT Advisory Outcomes Survey.

## 2. Appinventiv

Delivering top-notch healthcare software development services for more than 7 years, Appinventiv is a globally recognized healthcare solution service provider. Automating various health and fitness businesses around the world, Appinventiv’s professionals develop world-class healthcare software solutions. The company also supports HIPAA compliant software development to protect patient data and sensitive patient health information across digital platforms. With its cutting-edge healthcare solutions that aim to streamline healthcare operations, the company hopes to create a more rapid ecosystem for streamlining medical business operations. With over 50 digital healthcare projects, Appinventiv, a custom [healthcare software development company](https://appinventiv.com/healthcare-software-development/?utm_source=atlantic_net&utm_medium=referral&utm_campaign=appinventiv-listing&utm_content=top-10-hipaa-consulting-companies-2023), has helped enterprises overcome their biggest issues, from clinical management to efficient and HIPAA-compliant patient treatment and diagnosis solutions.

## 3. ScienceSoft

[ScienceSoft](https://www.scnsoft.com/security/compliance/hipaa/consulting) is a US-headquartered international IT company. Since starting in healthcare IT back in 2005, ScienceSoft has successfully delivered more than 150 projects in the domain. ScienceSoft offers in-depth HIPAA compliance consulting services to healthcare organizations, software product companies, medical device manufacturers, and pharmaceutical companies. Their HIPAA consulting services include compliance assessment, risk analyses, and implementation guidance aligned with HIPAA requirements and the HIPAA security rule. ScienceSoft has been featured among the Top 25 Healthcare Software Companies of 2026. The vendor has ISO 27001 and ISO 9001 certificates proving their focus on data security and quality management, as well as an established quality management system for medical devices and Software as a Medical Device backed up by ISO 13485 certification. ScienceSoft’s Project Management Office helps align healthcare IT and compliance initiatives with business needs by ensuring strong project governance and proactive risk management.

## 4. Clearwater Compliance

Since it was founded in 2009, Clearwater Compliance has helped over 400 clients with their cyber risk management and HIPAA compliance needs. The company’s team of HIPAA compliance experts provides healthcare organizations with a fixed-cost consulting service, including compliance assessment and HIPAA policy and procedure development and training. Clearwater also supports breach notification processes and helps organizations align with breach notification rules and HIPAA regulations. Their platform-driven approach supports ongoing HIPAA compliance services and continuous monitoring of security measures. Clearwater Compliance combines technology (such as their IRM|Pro® enterprise cyber risk management software) with accompanying solutions to save time and money and reduce the likelihood of a breach.

## 5. Arka Softwares

[Arka Softwares](https://www.arkasoftwares.com/mobile-application-development) is an ISO 9001:2015 certified leading IT company with 200+ passionate developers and designers having offices in, the USA, UK, and Australia. Arka Softwares offers in-depth HIPAA compliance consulting services to healthcare organizations. Their HIPAA consulting approach includes compliance services, risk assessments, and secure handling of sensitive data within healthcare environments. They also assist organizations in implementing HIPAA policies and strengthening security measures across healthcare systems. They deliver healthcare software and 150+ successful medical projects since 2010.

## 6. InCompliance

InCompliance employs a team of attorney and non-attorney consultants with extensive practical experience in addition to their legal and regulatory expertise. This allows the team to have a unique understanding of the practical complexities that their clients face during the design and implementation of a HIPAA compliance program. Their services focus on policies and procedures, compliance program development, and managing compliance across healthcare organizations. The proactive approach adopted by InCompliance has resulted in its clients facing fewer investigations compared to other CEs, and any investigations that have arisen have been dealt with expeditiously.

## 7. Healthicity, LLC.

Healthicity provides a suite of user-friendly compliance software solutions and compliance services delivered by its team of industry-leading compliance experts. The company tailors its services to meet the specific requirements of each healthcare organization and offer a range of affordable solutions to match the budgets of its clients. Healthicity supports healthcare providers with compliance services, risk management, and security awareness training to protect sensitive health information.

## 8. Praetorian Secure

Praetorian Secure has developed its security expertise and experience by forming partnerships with some of the world’s leading healthcare, medical and insurance providers. What sets Praetorian Secure apart from many of its competitors is the multi-industry expertise of its team of consultants. Their HIPAA consulting services emphasize incident response, security testing, and protecting sensitive patient data from cyber threats. Working with a diverse range of clients has provided the team with extensive experience and understanding, allowing them to provide a high standard of support.

## 9. RSM US

RSM US works with healthcare partners to ensure full HIPAA compliance, utilizing both automated and manual testing to seek out vulnerabilities and validate findings. The company’s compliance-related services include a readiness review, compliance assessment, and risk assessment. RSM also helps define business associate agreements, improve access controls, and strengthen overall HIPAA security practices. Their services also support health plans and healthcare providers in maintaining compliance with complex regulations and HIPAA rules.

## 10. Acevedo Consulting Inc.

Offering combined experience exceeding 100 years, Acevedo Consulting’s team of compliance experts are nationally recognized for their expertise. Their HIPAA consulting includes compliance assessment, risk management, and tailored compliance services designed to protect patient health information. They also provide expert guidance on implementing HIPAA policies and strengthening the patient data environment. Instead of cookie-cutter solutions, Acevedo Consulting devises a tailored compliance plan, including assessments, recommendations, and training.

## Bonus: Colington Consulting

Colington Consulting works with all types of healthcare providers and organizations, helping them to achieve HIPAA compliance. The company’s team of compliance experts formulates a tailored HIPAA risk management plan for their clients. Their consulting services focus on regulatory compliance, risk assessments, and protecting sensitive patient information across healthcare systems. Boasting over 60 years’ worth of experience in areas including regulatory compliance, law enforcement, health information privacy requirements, healthcare policy writing, and risk mitigation, Colington Consulting has a vast understanding of compliance regulations.

## How Can Atlantic.Net Help?

Atlantic.Net has over 25 years of experience providing a vast array of hosting services, including cloud, dedicated, private virtualization, colocation, and managed hosting to healthcare organizations. Our extensive body of healthcare clients has trusted us for many years, allowing us to remove the complexities of IT out of their hands and allowing them to focus on their patients.

As a healthcare organization, it is important that you choose an experienced, [HIPAA-compliant server hosting](https://www.atlantic.net/hipaa-compliant-hosting/) that will support you as your business grows, ensuring that business continuity, scalability, and security are prioritized.

Atlantic.Net helps healthcare organizations maintain HIPAA compliance by offering secure infrastructure, strong data protection, and support for compliance requirements related to the Health Insurance Portability and Accountability Act (HIPAA).

Atlantic.Net provides healthcare professionals with secure and robust hosting through our world-class data center infrastructure, with an emphasis on security and compliance. We offer PCI Ready, [HIPAA hosting](https://www.atlantic.net/hipaa-compliant-hosting/), and SOC 2 TYPE II and SOC 3 TYPE II compliance, taking the complexities of regulatory compliance out of the hands of our clients.

[Contact our sales team](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) today to find out more information about how our managed services can benefit your organization.

Additionally, if you’re not sure if you’re engaging the right HIPAA consultant, check out our list of the [questions your HIPAA consultant should be asking you](https://www.atlantic.net/hipaa-compliant-hosting/top-13-difficult-questions-your-hipaa-consultant-should-be-asking-you/).

---

#### Read More About HIPAA IT Compliance

- [HIPAA IT Compliance](https://www.atlantic.net/hipaa-data-centers/hipaa-compliant-it-infrastructure-guide/) Guide
- Best [HIPAA Compliant Fax](https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-fax-services-in-2021/) Service
- Best [HIPAA Compliant Email Service](https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-email-service-in-2021/)
- Best [HIPAA Compliant VOIP](https://www.atlantic.net/hipaa-compliant-hosting/top-10-best-hipaa-compliant-voip-providers/) Service
- Top Considerations for a [HIPAA-Compliant Database](https://www.atlantic.net/hipaa-compliant-hosting/top-10-considerations-for-a-hipaa-compliant-database/)
- [What Is a BAA?](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/)
- [SSAE16, SAAE18, SOC1, SOC2](https://www.atlantic.net/hipaa-compliant-hosting/ssae-16-soc-1-soc2-care/) – Why You Should Care
- Best [Healthcare Software Development](https://www.atlantic.net/hipaa-compliant-hosting/top-10-healthcare-software-development-companies/) Companies
- Is It [HIPPA or HIPAA?](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-vs-hippa/)

---


---

# Top Open-Source AI/ML Frameworks in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/top-open-source-ai-ml-frameworks/ | Published: 2026-04-14 | Updated: 2026-04-17 | Author: Richard Bailey

An open-source AI/ML framework is a free, public toolkit with the essential building blocks for developers to create their own smart applications and engage in custom AI development without starting from scratch. These toolkits provide the foundational components for countless open-source AI projects, allowing developers to create and deploy AI efficiently.

These open source machine learning frameworks and AI platforms are widely used by organizations and professional developers alike to build AI-powered applications without vendor lock-in.

These platforms supply the necessary components for building and training machine learning models, permitting the creation of systems that can perform language translation, analyze visual data, and make predictions, as well as automate tasks.

They support a wide range of machine learning tasks, including supervised learning, image classification, speech recognition, and large-language model development, using both structured and unlabeled data.

Using an open-source AI framework speeds up the development process, encourages collaboration, and is a key driver in the widespread adoption of AI technology. The right AI tools and framework are necessary for any project, affecting everything from development speed to the final application’s performance.

In 2026, active development across these frameworks ensures support for new DL models, distributed training, and code-generation workflows for modern data science teams.

## Top Open-Source AI Frameworks for Machine Learning

The selection of an AI framework depends entirely on your project’s goals. Whether your focus is on predictive analytics or advanced reinforcement learning, the best tool for the job will differ. Some frameworks are built for robust, large-scale production, while others excel at the agile, iterative work of fast prototyping. Understanding these strengths is the key to efficient model training and project success.

Many frameworks now serve as both deep learning and Python frameworks, offering flexible architectures and pre-built components to build and deploy ML models faster.

### #1: TensorFlow

![](https://www.atlantic.net/wp-content/uploads/2025/08/TensorFlow_logo.png)

TensorFlow is an end-to-end, open-source platform developed by the Google Brain team. Initially designed for large-scale numerical computation, it has evolved into a comprehensive ecosystem for machine learning. It uses Eager Execution, which evaluates operations immediately with dynamic computation graphs, making the model-building process intuitive and easy to debug.

TensorFlow is a leading deep learning framework and open source software library widely used for building artificial neural networks and deploying ML models at scale across cloud and edge environments.

#### Advantages

- **Complete Production Ecosystem:** This is TensorFlow’s main advantage. It includes powerful tools like TensorFlow Extended (TFX) for building automated MLOps pipelines, TensorFlow Lite (TFLite) for optimized on-device deployment (mobile, IoT), and TensorFlow.js for running models [directly in the browser](https://www.atlantic.net/gpu-server-hosting/how-to-run-machine-learning-models-in-your-browser-with-tensorflow-js/). No other framework covers this entire spectrum so cohesively.
- **Unmatched Scalability and Performance:** Built for massive scale, TensorFlow is highly optimized for performance. It offers excellent support for GPUs and a unique, significant advantage when using Google’s proprietary TPUs (Tensor Processing Units), making it a top choice for training enormous models.
- **Mature and Stable Tooling:** With tools like TensorBoard for advanced visualization and a stable, well-documented API, TensorFlow provides a reliable environment for projects that will be in production for years.

#### Disadvantages

- **Ecosystem Complexity**: While incredibly powerful, mastering the full ecosystem (like TFX and its various components) can be complex and present a steep learning curve for newcomers compared to more focused, streamlined libraries.
- **Verbosity for Simple Tasks**: While its core API is now far more concise thanks to Eager Execution and deep Keras integration, building simple models can still feel more involved than in libraries designed purely for prototyping. The additional setup required to leverage the full production ecosystem can feel verbose for quick experiments.

#### Ideal For

TensorFlow should be your #1 choice if your primary goal is building large-scale, production-critical applications that need to be reliably deployed, monitored, and maintained. It excels in enterprise AI, MLOps pipelines, and projects that require deploying the same model across various targets.

### #2: PyTorch

![](https://www.atlantic.net/wp-content/uploads/2025/08/Pytorch_logo.png)

Developed by Meta’s AI Research lab, PyTorch has become the de facto standard for AI research and cutting-edge development. Its defining feature is its “Pythonic” design and use of dynamic computation graphs, which allows for a more flexible and intuitive model-building process. This define-by-run approach prioritises user experience and rapid iteration, making it the preferred tool for researchers and developers prototyping novel architectures, especially in deep learning research.

PyTorch is a deep learning framework and open-source Python library known for its flexible architecture and strong support for artificial neural networks and large language model development.

#### Advantages

- **Intuitive and Flexible:** PyTorch’s “Pythonic” nature and dynamic computation graphs make it feel like a natural extension of the language. This allows for easy, on-the-fly model adjustments, making it arguably the most intuitive platform for building and debugging complex models.
- **Access to State-of-the-Art Models:** The vast majority of new research papers release their code in PyTorch. This gives developers immediate access to the latest deep learning models and techniques in fields like natural language processing (NLP).
- **Production-Ready:** With tools like [LitServe](https://lightning.ai/docs/litserve/home/benchmarks) for deployment and high-level libraries like PyTorch Lightning, PyTorch is now fully capable of handling demanding production workloads.

#### Disadvantages

- **Historically Less Mature Deployment**: Although rapidly improving, PyTorch’s production deployment tools were historically less comprehensive than TensorFlow’s ecosystem. This gap is closing quickly, but some enterprises still prefer TensorFlow’s more established MLOps tooling.
- **Separated Visualization Tools**: Unlike TensorFlow’s tightly integrated TensorBoard, visualization in PyTorch often requires integrating third-party tools. While powerful alternatives exist, they are not as seamlessly connected out of the box.
- **Complex Mobile Deployment**: While PyTorch Mobile exists, it is often considered more complex to optimize and deploy models on mobile and edge devices compared to the streamlined workflow offered by TensorFlow Lite.

#### Ideal For

PyTorch should be your choice for research, rapid prototyping, and in production environments where model flexibility is critical. It is the undisputed leader for anyone working on cutting-edge NLP, computer vision, or creative AI applications where experimentation and speed are paramount.

### #3: Scikit-learn

![](https://www.atlantic.net/wp-content/uploads/2025/08/scikit-logo.png)

Scikit-learn is a fundamental machine learning library focused on traditional machine learning algorithms, benefiting from robust community support. It provides simple and effective tools for data mining and predictive data analysis, built on the scientific Python stack (NumPy, SciPy, Pandas).

This open-source library is widely used in data science for traditional models such as linear and logistic regression, clustering, and classification.

#### Advantages

- **Simple and Consistent API:** Scikit-learn is famous for its clean API. You use the same .fit(), .predict(), and .transform() methods across hundreds of algorithms, making it incredibly easy to learn and use.
- **Comprehensive Algorithm Library:** It includes a vast range of supervised and unsupervised learning algorithms for tasks like classification, regression, clustering, and dimensionality reduction.

#### Disadvantages

- **Not Designed for Deep Learning**: Scikit-learn is not built for creating or training deep neural networks. It lacks the core components like GPU acceleration, automatic differentiation, and a layer-based API that are essential for deep learning tasks.
- **Limited Scalability for Big Data**: Because it does not support GPU acceleration, training models on very large datasets can be slow. It primarily relies on the CPU, making it less suitable for big data workloads compared to frameworks like TensorFlow or PyTorch.
- **Focus on Batch Processing**: The library is primarily designed for batch processing, where the entire dataset is available at once. This makes it less suited for applications that require real-time or incremental learning on streaming data.

#### Ideal For

Scikit-learn is the standard tool for classic ML tasks like classification, regression, and clustering. It is ideal for rapid prototyping thanks to its gentle learning curve and famously consistent API.

### #4: Keras

![](https://keras.io/img/logo.png)

Keras is a high-level API designed for fast experimentation in building and training deep learning models, often noted for its intuitive interface, incorporating various optimization techniques, and considered one of the best AI tools available. Now fully integrated with TensorFlow, Keras 3 introduced multi-backend support, allowing it to run on top of TensorFlow, PyTorch, or JAX. Keras acts as both a deep learning framework interface and a Python library that simplifies the building of artificial neural networks using pre-built components.

#### Advantages

- **Unmatched Ease of Use:** Its API is clean, intuitive, and designed to let you build and test complex neural networks with minimal code. Clear error messages make debugging much simpler than in lower-level frameworks.
- **Multi-Backend Flexibility:** With the release of Keras 3, it is now backend-agnostic. You can write your code once and [run it on TensorFlow,](https://www.atlantic.net/gpu-server-hosting/how-to-convert-a-keras-model-to-a-tensorflow-lite-model-on-ubuntu-24-04-gpu-server/) PyTorch, or JAX!

#### Disadvantages

- **Limited Low-Level Control**: The high level of abstraction that makes Keras easy to use also limits direct control over granular operations. This can be a drawback for researchers trying to invent novel, highly customized model components.
- **Potential Performance Overheads**: While performant for most use cases, the abstraction layer can sometimes introduce minor overheads compared to writing code directly in a lower-level framework, especially for highly specialized, performance-critical applications.
- **Debugging Can Be Opaque**: When something goes wrong deep inside the model, the high-level API can sometimes obscure the root cause, making it more challenging to debug than frameworks that expose more of the underlying mechanics.

#### Ideal For

Keras is excellent for beginners and developers who need to build and test deep learning models quickly. Its simplicity makes it a popular choice for educational purposes and for creating new solutions without deep framework expertise.

### #5: Hugging Face Transformers

![huggingface](https://www.atlantic.net/wp-content/uploads/2025/09/huggingface.png)

[Hugging Face](https://www.atlantic.net/gpu-server-hosting/how-to-generate-videos-with-huggingface-modelscope-text2video-diffusion-model-on-atlantic-net-cloud-gpu/) provides a platform and a very popular library named Transformers. It has become a central point for the AI community, offering easy access to thousands of state-of-the-art, pre-built models for a variety of tasks, initially focused on natural language processing but now encompassing a vast range of tasks, including computer vision and audio. The framework is widely used for large-language model development, code generation, and the development of advanced AI models across multiple domains.

#### Advantages

- **The Model Hub:** Its core strength is a massive, searchable repository of models for nearly every task, from natural language processing to computer vision and audio.
- **Simple, Unified API:** The library’s API enables developers to download and implement complex models with just a few lines of code. It also supports interoperability between PyTorch and TensorFlow.

#### Disadvantages

- **Inherited Model Bias**: Relying on pre-trained models means you risk inheriting any biases present in their original training data. This is a significant concern for ethical AI development and requires careful model selection and evaluation.
- **High Resource Consumption**: State-of-the-art models are often enormous and can be very expensive to run and host. They require significant computational resources (like powerful GPUs) and memory, which can be a barrier to deployment.
- **Black Box Complexity**: Many models on the Hub can function as “black boxes.” Using them effectively and responsibly requires understanding their limitations, potential failure modes, and the risks of generating harmful or inaccurate content.

#### Ideal For

This platform is necessary for anyone working on NLP tasks. It is used by data scientists and engineers to quickly implement advanced machine learning capabilities, such as text classification, summarization, and object detection in images.

### #6: Microsoft AutoGen

![](https://www.atlantic.net/wp-content/uploads/2026/01/8867.Microsoft_5F00_Logo_2D00_for_2D00_screen-1024x376-1.jpg)

Microsoft’s AutoGen is a framework designed to simplify the development of AI systems using multiple, collaborating LLM agents. It allows agents to converse with each other to accomplish complex AI tasks, reducing the need for direct human intervention in multi-step processes.

#### Advantages

- **Multi-Agent Conversations:** The core concept is enabling agents with different roles (e.g., “coder,” “critic,” “project manager”) to converse and delegate tasks to accomplish a goal.
- **Customisable and Controllable:** Agents are highly customisable, and the framework supports human-in-the-loop workflows, so you can guide the conversation and maintain control.

#### Disadvantages

- **Smaller Community Support**: As a newer and more advanced framework, it has a smaller community support base than more established tools. This can mean fewer tutorials, public examples, and community-answered questions on platforms like Stack Overflow.
- **Complex Design and Debugging**: Designing and debugging effective multi-agent conversations is a complex art. It requires a different mindset than traditional programming, focusing heavily on prompt engineering and defining agent roles and interactions.
- **Steep Learning Curve**: The framework requires a good understanding of both LLM capabilities and agent-based system design. It is less suited for beginners and has a steeper learning curve for developers new to the agentic AI paradigm.

#### Ideal For

AutoGen is suited for advanced users, researchers, and developers building future AI applications. It is fitting for projects that involve automated problem-solving using various programming languages, software development, content generation, and other tasks that can be broken down for a team of specialized AI agents.

## Hosting AI and Machine Learning Workloads with Atlantic.Net

These open-source AI frameworks require substantial computing resources. Model training is a hardware-intensive process demanding high-performance CPUs, large amounts of RAM, and powerful Graphics Processing Units (GPUs) to effectively deploy machine learning models.

Modern deep learning framework workloads often require scalable cloud infrastructure to support distributed training and large-scale ML models.

This is where Atlantic.Net GPU Cloud Servers come in. Specifically engineered for demanding AI workloads, these servers are equipped with NVIDIA GPUs to train complex models in a fraction of the time.

By using a cloud-based GPU solution, developers and organizations can:

- **Access High-Performance Hardware:** Use enterprise-grade GPUs without the large capital expense.
- **Scale Resources on Demand:** Easily increase or decrease computing resources as project needs change.
- **Deploy Quickly:** Spin up a fully configured server with an OS like Microsoft Windows, Ubuntu, or AlmaLinux in minutes.

Atlantic.Net provides a [reliable and secure platform](https://www.atlantic.net/cloud-platform/), offering the necessary infrastructure to support the entire AI development lifecycle.

## Conclusion

The open-source AI field offers a wide array of machine learning frameworks, each with distinct advantages. The correct choice depends entirely on the specific requirements of a project, whether for academic research, fast prototyping, or deployment in a production environment. From the broad capabilities of TensorFlow and PyTorch to the specialized functions of AutoGen, a tool exists for nearly every AI task, including reinforcement learning.

However, the most advanced software is only as good as the hardware it runs on. A dependable infrastructure is the other half of the equation for successful AI development. Selecting a hosting provider that offers the required performance, scalability, and support is a critical step in turning an AI model into a functional, real-world application.

## Get Started with AI Development

Ready to deploy your AI application? Explore Atlantic.Net’s [GPU Cloud Hosting](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/) solutions today to find the right infrastructure for your bespoke AI solutions project.

[Contact our solutions team](https://www.atlantic.net/about-us/corporate-contact/) to learn more.


---

# What Is VPS: 2026 Buyer’s Guide and Expert Tips

> URL: https://www.atlantic.net/vps-hosting/what-is-vps-buyers-guide-and-expert-tips/ | Published: 2026-04-14 | Updated: 2026-07-13 | Author: Gilad Maayan

## What Is a VPS?

A virtual private server (VPS) combines the best aspects of shared and dedicated hosting. It operates as a separate server within a larger system, offering users a dedicated portion of resources in a virtual environment. This setup provides more control and higher performance compared to shared hosting, as each VPS functions independently.

In essence, VPS hosting provides a private server environment without the cost of a full dedicated server, making it a cost-effective solution for growing businesses. VPS stands for virtual private server hosting, where users get own dedicated resources within a shared physical server while maintaining isolation from other users.

VPS hosting uses virtualization technology to split a single physical server into multiple virtual ones. Each VPS instance has its own operating system, storage, and bandwidth capabilities. This separation ensures users can customize and manage their environments independently. VPS servers offer performance that can handle higher traffic loads and complex applications. This approach enables businesses to run modern web applications efficiently using scalable virtual resources and cloud infrastructure.

A VPS operates using a hypervisor, a software layer that sits between the physical server’s hardware and the virtual environments. The hypervisor divides the physical server’s resources, such as CPU, RAM, and storage, into isolated units, each of which becomes a separate virtual server. These virtual servers, or VPS instances, run their own operating systems and function independently from one another.

Each VPS has dedicated resources, which ensures that the performance of one VPS is not affected by the activities of others on the same physical server. This isolation is one of the main advantages of VPS hosting compared to shared hosting, where resources are shared among multiple users and can lead to performance bottlenecks. Unlike shared hosting environments, VPS hosting secure configurations help protect customer data and reduce risk from other users on the same server.

Users of a VPS have full control over the configuration of their server environment. They can install custom software, configure security settings, and choose their operating system. This level of control is similar to what you’d get with a dedicated server, but at a lower cost, since the physical hardware is still shared among several VPS instances.

This is part of an extensive series of guides about [compliance management](https://www.exabeam.com/explainers/compliance-management/compliance-management-process-regulations-and-tools/).

## Key Use Cases of VPS Hosting

VPS hosting offers a flexible and scalable solution for various business needs, providing dedicated resources and enhanced control at a lower cost than dedicated servers. Below are some of the key use cases where VPS hosting is particularly beneficial.

- **Hosting websites and applications:** VPS hosting is ideal for websites that have outgrown shared hosting but do not require a full dedicated server. With dedicated resources and greater control, businesses can ensure faster load times and better performance, especially during traffic spikes. This makes VPS hosting a popular choice for e-commerce sites, media-rich websites, and applications that need reliable uptime and security. It is especially valuable for businesses running dynamic web applications that require consistent performance and scalability.
- **Running custom software:** For businesses or developers who need to run specialized applications or scripts that are not supported by shared hosting, a VPS offers the flexibility to install and manage custom software. This is particularly useful for industries with specific software needs, such as financial services or healthcare, where unique configurations are required.
- **Testing and development environments:** VPS hosting is often used to create isolated environments for development and testing. Developers can use a VPS to run multiple instances of different operating systems or configurations, allowing them to test software or websites under various conditions without affecting the production environment.
- **Email servers:** Running a private email server on a VPS offers greater control over security and performance compared to using third-party email services. This is particularly important for businesses that need to ensure data privacy or comply with specific regulations related to email communication.
- **Backup and disaster recovery:** VPS hosting is also commonly used as a backup solution. Businesses can store critical data on a VPS as part of a disaster recovery plan, ensuring that data is securely stored and easily retrievable in the event of hardware failure or data corruption. Modern VPS solutions also integrate with cloud infrastructure for improved redundancy and storage resources.

## VPS Hosting vs. Other Types of Hosting

### Shared Hosting

Shared hosting is an entry-level offering where multiple websites reside on a single server. This means resources like RAM and CPU are shared among all sites. While cost-effective, performance can suffer due to resource limitations, especially if neighboring sites experience high traffic. Each site has limited control over server configurations, making it less suitable for sites requiring custom setups or advanced security measures.

Despite these drawbacks, shared hosting remains popular for beginners or small sites with low traffic expectations, offering a simple, affordable hosting solution. Additionally, since the host manages server maintenance and updates, it is suitable for users who lack the time or expertise to manage technical aspects of their website. However, in a shared hosting environment, performance can be impacted by other website owners and other users sharing the same server resources.

***Learn more in our detailed guide to***[***VPS hosting vs shared hosting ***](https://www.atlantic.net/vps-hosting/vps-hosting-vs-shared-hosting-pros-cons-differences-and-expert-tips/)

### Dedicated Hosting

[Dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/) provides an entire server for a single user’s exclusive use, ensuring maximum control and resource availability. This type of hosting is suitable for large enterprises or high-traffic sites requiring performance and customization capabilities. Users can optimize the server to their specific needs, installing custom software and implementing stringent security protocols.

While dedicated hosting offers power and flexibility, it comes with a higher cost. Users are responsible for server maintenance and management unless they opt for managed services, which incurs additional fees. This model gives access to an entire physical server, unlike traditional VPS setups that rely on a shared physical machine.

***Learn more in our detailed guide to***[***VPS vs dedicated server ***](https://www.atlantic.net/vps-hosting/vps-vs-dedicated-server-6-key-differences-and-how-to-choose/)

### Cloud Hosting

Cloud hosting involves multiple servers working in tandem to host websites. This configuration offers flexibility and scalability, as resources can be adjusted according to demand. Cloud hosting ensures high reliability by distributing data across several servers, ensuring availability even if one server fails.

Users benefit from pay-as-you-go pricing, making it cost-effective for handling variable traffic loads. Cloud hosting is ideal for businesses that experience seasonal traffic spikes or need disaster recovery solutions. Many VPS hosting providers now build VPS solutions on cloud infrastructure platforms such as Google Cloud to improve scalability and performance.

## Types of VPS Hosting

There are three primary types of VPS hosting: managed, unmanaged, and semi-managed. These options are often categorized as managed and unmanaged hosting, depending on how much control and support the hosting company provides.

### Managed VPS Hosting

Managed VPS hosting provides support where the hosting provider handles server management tasks, including maintenance, updates, and security patches. This service allows users to focus on their core business activities rather than technical server management. Managed VPS hosting is ideal for those lacking technical expertise or time to manage server-side responsibilities.

Users benefit from expert support, enhancing server reliability and performance. Providers often include monitoring services, ensuring prompt resolution of issues before they impact the business. While this service often comes with a higher price tag than unmanaged options, the peace of mind and professional expertise provided can be invaluable for businesses prioritizing uptime and stability.

### Unmanaged VPS Hosting

Unmanaged VPS hosting offers users full control over their server, including all technical aspects. This type of hosting is more affordable, appealing to businesses with a budget or those with in-house technical expertise capable of managing server tasks. Users are responsible for server setup, maintenance, security, and updates.

This hosting demands a deeper technical understanding, as users must resolve issues independently. However, it offers the flexibility to implement specialized configurations and optimizations. For experienced users or businesses with dedicated IT teams, unmanaged VPS can be a cost-effective and tailored solution, although it requires a hands-on approach for successful management.

### Semi-Managed VPS Hosting

Semi-managed VPS hosting strikes a balance between managed and unmanaged services. Providers offer basic server management, often covering critical updates, monitoring, and initial setup, while users handle application-level management. This approach delivers a compromise allowing cost savings while mitigating the burden of full server management.

Businesses benefit from provider support for complex infrastructure tasks while maintaining control over their applications. This model is ideal for organizations wanting a blend of professional assistance and personal server management.

## When Should You Upgrade to VPS Hosting?

Here are a few considerations for website owners currently running on shared hosting and considering an upgrade to VPS.

### High Traffic Volume

High-traffic websites often face issues on shared hosting due to resource limitations. VPS hosting can handle increased traffic by allocating dedicated resources, ensuring consistent performance and reliability. When web traffic begins exceeding the capabilities of shared environments, upgrading to a VPS becomes essential to maintain user satisfaction and operational efficiency.

### Need for Customization

Customization needs arise when standard hosting options cannot meet specific software or configuration requirements. VPS hosting offers flexibility and control, enabling users to tailor servers to their exact specifications, install custom applications, and run specialized software. Users gain root access, allowing comprehensive management and configuration freedom.

### Security Concerns

Enhanced security requirements often prompt a switch to VPS hosting. In shared environments, the risk of security breaches is higher due to resource sharing. VPS hosting offers isolated environments, significantly reducing vulnerability to attacks from neighboring users. Businesses dealing with sensitive data or requiring robust security measures benefit greatly from VPS hosting.

### Performance Issues

Performance issues, characterized by slow load times and server crashes, often necessitate a move to VPS hosting. Shared hosting may bottleneck resources, unable to sustain the computational demands of growing websites. VPS hosting allocates dedicated resources, enabling better performance even under heavy load conditions.

## Choosing the Right VPS Hosting Plan

Here are some of the important options you’ll need to choose from when deciding on a VPS hosting plan.

### Operating System Options

Choosing a suitable operating system (OS) for VPS hosting depends on application requirements and user familiarity. Common OS options include Linux and Windows, each offering distinct advantages. Linux is praised for its stability, security, and cost-effectiveness, making it popular among tech-savvy users and businesses running open-source technologies.

Windows VPS hosting, integrating seamlessly with Microsoft products, is suitable for those reliant on specific Windows applications. Understanding the OS’s compatibility with current applications and required support level is crucial in deciding.

### Resource Allocation (CPU, RAM, Storage)

Evaluating CPU, RAM, and storage allocations is vital when choosing a VPS plan. Adequate CPU ensures that applications run smoothly without bottlenecks, while sufficient RAM supports multiple processes and faster data handling. Storage should match current and anticipated data needs, scalable to accommodate growth.

It’s essential to assess typical workload demands and resource consumption patterns to choose a configuration that won’t restrict business operations. Under-provisioning can lead to performance degradation, while over-provisioning may increase costs unnecessarily.

### Reliability and Uptime Guarantees

Uptime guarantees are critical for ensuring service continuity. Most providers commit to uptime percentages, and it’s vital to choose one offering at least 99.9% uptime to minimize disruption risks. High uptime guarantees ensure website accessibility and operational stability, crucial for maintaining customer trust and satisfaction.

Reliability also encompasses the provider’s infrastructure, redundancy technologies, and disaster recovery capabilities. By selecting a hosting provider with reliability measures and solid uptime commitments, businesses can mitigate risks associated with downtime, directly protecting revenue and enhancing user experiences through consistent site availability.

### Customer Support

Customer support quality is crucial when selecting a VPS hosting plan. Prompt, reliable support can resolve technical issues quickly, minimizing downtime and impact on business. Opt for providers with 24/7 support, available through multiple channels like chat, email, and phone, ensuring accessibility when needed most.

Consider support inclusions such as technical assistance, planned maintenance updates, and security audits. Reliable support can mean the difference between swift recovery and extended outages. Evaluating customer feedback and support responsiveness can offer insights into prospective providers, guiding your decision towards a hosting plan that supports your operational success.

### Pricing Considerations

Pricing is an important factor in VPS plan selection. Evaluate cost against features and services offered to determine value. Ensure the plan includes essential features and support that justify its cost. Consider both initial prices and renewal rates, as these may vary significantly between providers.

Transparent pricing structures without hidden fees provide better budgeting predictability. Assess the scalability of plans to accommodate business growth, thus avoiding excessive costs from switching providers later. Carefully considering pricing relative to business needs and performance requirements can guide effective decision-making, balancing affordability with desired service levels.

## Expert Tips for Successfully Managing a VPS

### 1. Regular Security Updates

Consistently applying security updates is essential to protect VPS environments from vulnerabilities and cyberattacks. Regular updates to the operating system and installed software prevent exploitations due to known security flaws. Keeping software up-to-date is a proactive measure for securing data and operations.

Automating updates can help ensure timely application, reducing manual oversight. Regular security audits further enhance protection by identifying potential weaknesses before they are exploited.

### 2. Monitoring and Performance Optimization

Implementing robust monitoring tools allows for real-time tracking of server performance and resource utilization. Performance optimization involves adjusting resources like CPU and RAM based on usage patterns to prevent bottlenecks.

Monitoring helps identify and address issues swiftly, ensuring server operations run smoothly. Leveraging performance data to optimize configurations can enhance efficiency and response times.

### 3. Backup and Recovery Strategies

Regular backups and effective recovery plans are vital for data protection and business continuity. Implement automated backup solutions to ensure data is routinely saved, minimizing the risk of loss due to hardware failures or cyber threats. Backups should include all critical data and configurations for comprehensive recovery.

Designing and regularly testing recovery strategies ensure data can be restored swiftly, minimizing downtime. These strategies should include processes for different failure scenarios to enhance resilience.

### 4. Scalability Planning

Scalability planning ensures the VPS can adjust to growing business demands. Implementing a plan involves forecasting future resource needs based on current usage trends and potential growth spurts. It’s crucial to choose a VPS plan that offers easy scaling options to support seamless expansion without service interruption.

Regularly reviewing resource usage helps anticipate when to scale up resources like CPU, RAM, and storage. Planning for scalability ensures that performance remains consistent as demands increase, supporting a seamless user experience.

### 5. Compliance and Regulations

Managing a VPS requires adherence to industry compliance standards and regulations relevant to your business, such as GDPR or HIPAA. Ensure data handling practices comply with legal and regulatory requirements to protect against penalties and breaches. Regular audits and documentation policies support compliance efforts.

Opt for hosting providers offering compliance support, including encryption services and secure data centers. Providers often include compliance-friendly features tailored to industries with strict data regulations.

### **VPS Hosting in the Cloud with Atlantic.net**

VPS Hosting from Atlantic.Net gives you the freedom to create and deploy one or many virtual servers in seconds. By combining the most advanced VPS hosting innovations and resources available, the Atlantic.Net Cloud offers simplicity, security, scalability, and reliability that will not only improve your virtual private server performance but also reduce your costs.

With Atlantic.Net, you get the full suite of Cloud VPS hosting services: compute, redundant storage platforms, One-Click Apps, DNS, private networking, Onsite Backups, Offsite Backups, Secure Block Storage, and more, all backed by 24×7 support and a full range of managed services your business needs to succeed.

[**Learn more about Atlantic.net VPS Hosting**](https://www.atlantic.net/vps-hosting/)

### See Additional Guides on Key Compliance Management Topics

Together with our content partners, we have authored in-depth guides on several other topics that can also be useful as you explore the world of [compliance management](https://www.exabeam.com/explainers/compliance-management/compliance-management-process-regulations-and-tools/).

#### [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)

*Authored by Atlantic.Net*

- [[Guide] HIPAA-Compliant Hosting | 2025 Award Winning HIPAA Hosting ](https://www.atlantic.net/hipaa-compliant-hosting/)
- [[Guide] What is Protected Health Information (PHI) in 2025? Atlantic.Net ](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/)
- [[Blog] RTLS and Healthcare ](https://www.atlantic.net/hipaa-compliant-hosting/rtls-and-healthcare-can-real-time-location-system-security-improve-your-healthcare-operations/)
- [[Product] Atlantic.Net HIPAA Compliant Hosting ](https://www.atlantic.net/hipaa-compliant-hosting/)

#### [PCI Compliant Hosting](https://www.atlantic.net/pci-compliant-hosting/)

*Authored by Atlantic.Net*

- [[Guide] PCI Hosting Solutions | 12-Point PCI-Compliant Hosting Checklist ](https://www.atlantic.net/pci-compliant-hosting/)
- [[Guide] PCI DSS Cybersecurity Requirements: A Practical Guide ](https://www.atlantic.net/pci-compliant-hosting/pci-dss-cybersecurity-requirements-a-practical-guide/)
- [[Blog] How to Reduce Your PCI Scope When Accepting Payments ](https://www.atlantic.net/pci-compliant-hosting/reduce-pci-scope-accepting-payments/)
- [[Product] Atlantic.Net HIPAA Compliant Hosting ](https://www.atlantic.net/hipaa-compliant-hosting/)

#### [GDPR Compliance](https://www.exabeam.com/explainers/gdpr-compliance/gdpr-compliance-a-practical-guide/)

*Authored by Exabeam*

- [[Guide] GDPR Compliance: A Practical Guide](https://www.exabeam.com/explainers/gdpr-compliance/gdpr-compliance-a-practical-guide/)
- [[Guide] GDPR Fines Structure and the Biggest GDPR Fines to Date](https://www.exabeam.com/explainers/gdpr-compliance/gdpr-fines-structure-and-the-biggest-gdpr-fines-to-date/)
- [[Whitepaper] 2024 State of the Security Team Research ](https://www.exabeam.com/blog/infosec-trends/a-cisos-analysis-the-2024-state-of-security-report/)
- [[Product] Exabeam | AI-Driven Security Operations](https://cloudian.com/products/hyperstore/)


---

# 10 Best Enterprise WordPress Development Companies (2026)

> URL: https://www.atlantic.net/hipaa-compliant-wordpress-hosting/10-best-wordpress-development-companies-for-custom-websites/ | Published: 2026-04-14 | Updated: 2026-06-23 | Author: Editorial Team

In 2026, WordPress development is all about headless architectures and fast, reliable API integrations. As more businesses shift from bulky themes to custom, high-speed blocks, it’s important to choose a development partner who values technical flexibility, Core Web Vitals, and strong security. We’ve found the top firms that focus on custom enterprise builds, site speed, scalable infrastructure, Figma-to-Gutenberg workflows, and designs that drive conversions.

Modern enterprises now also prioritize search engine optimization, website optimization, and enhance user experience strategies to improve website traffic and long-term performance across search platforms.

What separates a forgettable WordPress site from one that truly drives business results? It’s the difference between a site bogged down by generic themes and plugin bloat, and one that feels responsive, secure, and intentionally crafted.

The professional edge comes from two key ingredients: a skilled development partner who understands your goals through strategic planning and a high-performance [cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) environment.

Today, a top rated WordPress agency is expected to combine technical knowledge with strong brand identity execution and measurable outcomes through tools like Google Analytics.

The best WordPress development companies do more than just assemble pre-made parts; they excel in creating custom websites that blend smart design, clean code, measurable Core Web Vitals performance gains, and a clear strategy for future growth in enterprise environments.

This guide features 11 top WordPress development agencies for 2026, all with a strong focus on enterprise projects, headless WordPress setups, and performance-driven engineering. Each agency has a solid history of handling complex integrations, Figma-to-Gutenberg projects, and platforms optimised for Core Web Vitals. These firms are a good fit for organisations that need scalable, secure solutions and a long-term technical plan.

They also provide WordPress services that include custom integrations, advanced functionality, and responsive design tailored to businesses operating across various industries.

## Top 10 Best WordPress Development Agencies for Enterprise Projects

A closer look at the WordPress development companies delivering enterprise WordPress engineering, headless architecture implementations, Figma-to-Gutenberg workflows, complex API integrations, and long-term performance optimisation for organisations operating at scale in 2026.

### 1. cmsMinds

![](https://www.atlantic.net/wp-content/uploads/2026/03/cmsminds-logo.png)

**Clutch Rating: 4.9/5**

cmsMinds has established itself as one of the most reliable [WordPress design and development companies](https://cmsminds.com/) with over a decade of hands-on experience. The team specializes in custom WordPress websites, redesigns, WooCommerce development, and plugin development, with increasing focus on block-based architecture, Core Web Vitals optimization, and scalable enterprise builds. Their approach combines technical expertise with a focus on long-term partnerships, ensuring every project is built to scale and last.

**What makes them stand out**: A clear focus on long-term partnerships. cmsMinds doesn’t just build websites and leave; they provide maintenance, ongoing support, and scalable solutions that grow with the client’s business. Their development model increasingly emphasizes performance benchmarks and structured Gutenberg block systems over heavy theme customization.

They also offer WordPress maintenance, support services, and provide ongoing support to keep your website secure, updated, and performing reliably.

**Industries or clients they serve**: From small businesses to large organizations, cmsMinds has worked across B2B, SaaS, non-profits, and digital publishers seeking high-performing WordPress solutions. Some of the clients are Philips, MIT (Massachusetts Institute of Technology), Panasonic, Johnson & Johnson, and Nestlé.

![](https://www.atlantic.net/wp-content/uploads/2025/03/wpinfotech.png)

**2. WPWeb Infotech**

**Clutch Rating:** 5/5

[**WPWeb Infotech**](https://wpwebinfotech.com/wordpress-development/) is a leading WordPress development company known for delivering high-quality WordPress, WooCommerce, and custom web solutions. With 10+ years of hands-on experience, the team focuses on building scalable, performance-driven digital products tailored to business needs. Their expertise spans custom plugin development, API integrations, headless WordPress solutions, and enterprise-grade applications, all backed by strong technical proficiency and agile methodologies.

**What makes them stand out:** A strong blend of development expertise and digital strategy. WPWeb Infotech goes beyond development by offering consultation, performance optimization, and long-term technical support, ensuring businesses achieve sustainable growth and measurable results.

**Industries or clients they serve:** WPWeb Infotech works with startups, SMEs, and large enterprises across industries like eCommerce, SaaS, healthcare, fintech, and education. They have delivered solutions for global clients seeking reliable, scalable, and conversion-focused web platforms.

### 3. WebDev Studios

![](https://www.atlantic.net/wp-content/uploads/2026/03/webdev-studios-logo.png)

**Clutch Rating: 5/5**

WebDev Studios is a U.S.-based WordPress web development company with a strong focus on user experience design and custom development. Their team handles new site builds, redesigns, and performance optimization. In recent enterprise projects, they have expanded into headless WordPress configurations, structured content modeling, and API-driven integrations to support multi-platform delivery. With a reputation for delivering scalable websites on tight deadlines, they have become a trusted partner for brands that need both creativity and technical expertise.

Their development team focuses heavily on user engagement and delivering a user friendly interface aligned with modern UX standards.

**What makes them stand out**: A proven track record of delivering strategic WordPress solutions on tight deadlines. Their approach blends technical depth with user-centered design. Their ability to translate Figma design systems into modular Gutenberg components helps maintain consistency while improving page speed metrics.

**Industries or clients they serve**: Large organizations and educational institutions, including Microsoft, Skype, and Starbucks, have trusted WebDev Studios with their WordPress projects.

They are known for timely delivery and managing strict project timelines without compromising performance.

### 4. Human Made (Headless Experts)

![](https://www.atlantic.net/wp-content/uploads/2026/03/humanmade-logo.png)

**Clutch Rating: 4.7/5**

Human Made is a global WordPress agency known for tackling enterprise-level solutions. They are widely recognized for architecting headless WordPress platforms that use REST and GraphQL APIs to power multi-channel publishing across web, mobile, and connected applications. With a strong reputation in the WordPress community, they bring deep technical expertise, offering WordPress web design, custom development, content publishing tools, and digital strategy. Their projects often involve large-scale websites, decoupled front-end frameworks, and complex integrations, making them a go-to partner for organizations that need stability and technical flexibility at scale. Their WordPress experts specialize in large-scale architecture that supports advanced functionality and multi-platform publishing ecosystems.

**What makes them stand out**: Their role in shaping the WordPress ecosystem itself. Human Made contributes heavily to WordPress core, positioning them as both practitioners and thought leaders in enterprise WordPress. Their enterprise builds a prioritized structured content architecture, Core Web Vitals performance benchmarks, and scalable infrastructure for high-traffic environments.

**Industries or clients they serve**: Trusted by global brands and digital publishers like USA Today, TechCrunch, and NewsUK, Human Made is a go-to agency for large-scale websites, headless implementations, and complex enterprise integrations.

### 5. Reaktiv

![](https://www.atlantic.net/wp-content/uploads/2026/03/reaktiv-studios-logo.png)

**Clutch Rating: 4.9/5**

Reaktiv is a U.S.-based WordPress agency specialising in enterprise WordPress engineering, headless implementations, and advanced API integrations. Their team focuses on building scalable digital platforms using modern development standards, structured content modelling, and block-based architecture. Reaktiv frequently works with decoupled front-end frameworks and custom Gutenberg development to support [high-traffic websites](https://www.atlantic.net/dedicated-server-hosting/choose-dedicated-server-high-traffic-websites/) that demand flexibility and performance.

They excel in custom integrations and building scalable platforms that align with evolving search engine requirements.

**What makes them stand out**: A strong emphasis on headless WordPress architecture and Core Web Vitals optimisation for large-scale publishers and enterprise brands. Their engineers prioritise clean code standards, composable systems, and measurable performance benchmarks over theme-heavy builds.

**Industries or clients they serve**: Reaktiv primarily partners with media organisations, digital publishers, and enterprise brands that require high-performance content platforms, complex integrations, and long-term technical scalability.

### 6. Multidots

![](https://www.atlantic.net/wp-content/uploads/2026/03/multidots_logo.png)

**Clutch Rating: 4.9/5**

Multidots is a full-service WordPress website development company with strong expertise in enterprise-grade WordPress solutions. Their services range from WordPress website design to migration, plugin development, and performance optimization. In recent years, they have expanded into headless WordPress implementations, structured Gutenberg block systems, and API-driven architectures tailored for high-traffic publishing environments. They are also known for delivering high-performance websites that meet strict Core Web Vitals benchmarks for digital publishers and large organizations. As a leading WordPress website development company, they deliver solutions that combine performance with scalable WordPress features.

**What makes them stand out**: Their work with large-scale publishers and digital media companies. Multidots is also a WordPress VIP Gold Agency Partner, which showcases their credibility. Their focus on scalable infrastructure, performance monitoring, and modular content workflows makes them well-suited for enterprise editorial teams.

**Industries or clients they serve**: Media, publishing, and entertainment brands, including Forbes, Sneaker News, and Accenture, rely on Multidots for scalable websites, headless deployments, and custom WordPress development built for long-term growth.

### 7. 10up

![](https://www.atlantic.net/wp-content/uploads/2026/03/10up-logo.png)

**Clutch Rating: 5/5**

10up is an enterprise WordPress agency that delivers headless WordPress platforms, advanced content management systems, and large-scale digital projects. Their team covers strategy, design, and engineering, creating custom solutions that connect WordPress with modern JavaScript frameworks, [SaaS](https://www.atlantic.net/vps-hosting/what-is-saas-hosting/) tools, and complex APIs. 10up is also known for contributing to open-source projects and Gutenberg development, helping shape the future of block-based WordPress. Their work emphasizes website optimization and scalable systems that improve website traffic and conversion outcomes.

**What makes them stand out**: Deep expertise in enterprise architecture and Figma-to-Gutenberg workflows that translate structured design systems into scalable, reusable block components. Their builds prioritise Core Web Vitals performance, accessibility standards, and maintainable codebases for long-term enterprise growth.

**Industries or clients they serve**: 10up works with government agencies, media companies, universities, and global brands that need secure, high-performance WordPress platforms for complex editorial and multi-site needs.

### 8. rtCamp

![](https://www.atlantic.net/wp-content/uploads/2026/03/rtcamp-logo.png)

**Clutch Rating: 4.7/5**

rtCamp is a global WordPress engineering agency that specialises in enterprise WordPress development, headless builds, and high-traffic publishing platforms. Their team focuses on scalable architecture, DevOps, and API-first development to support content across many digital channels. rtCamp also contributes to the WordPress open-source community, working on core and performance projects. Their engineering-led approach supports payment processors, SaaS integrations, and enterprise-grade infrastructure.

**What makes them stand out**: Strong technical capabilities in decoupled WordPress setups, structured content modelling, and Core Web Vitals optimisation for large-scale environments. Their engineering-led approach emphasises clean coding standards, CI/CD workflows, and measurable performance improvements.

**Industries or clients they serve**: rtCamp partners with enterprise publishers, eCommerce brands, and tech companies that need scalable, secure WordPress infrastructure and ongoing engineering support for important platforms.

### 9. DevriX

![](https://www.atlantic.net/wp-content/uploads/2026/03/devrix-logo.png)

**Clutch Rating: 4.8/5**

DevriX calls itself a “WordPress retainer agency,” focusing on long-term support and strategic partnerships. They offer WordPress web design, client satisfaction plugin development for client satisfaction, SaaS integrations, and scalable website solutions for growing businesses. In recent enterprise engagements, DevriX has expanded into headless WordPress setups, structured content architecture, and API-driven SaaS integrations designed for multi-product ecosystems. Their team is known for handling complex projects that require both technical expertise and a strong emphasis on continuous improvement and measurable Core Web Vitals gains. They provide WordPress maintenance and continuous improvements to enhance user experience and performance metrics over time.

**What makes them stand out**: Their emphasis on ongoing development services and continuous growth, rather than one-time projects. They specialize in complex WordPress development for enterprise-level clients. Their retainer model supports iterative performance optimization, conversion tracking, and structured Gutenberg enhancements over time.

**Industries or clients they serve**: DevriX works with digital publishers, startups, and enterprises that need continuous development, [SEO](https://www.atlantic.net/vps-hosting/top-seo-tools/) optimization, scalable infrastructure, and strategic engineering support.

### 10. XWP

![](https://www.atlantic.net/wp-content/uploads/2026/03/XWP-Logo.png)

**Clutch Rating: 4.9/5**

XWP is a global WordPress agency with strong roots in digital publishing. Their services include custom WordPress development, performance optimization, and design for mobile-responsive websites and large-scale websites with complex requirements. They are particularly known for headless WordPress implementations and decoupled architectures that support high-traffic, multi-platform publishing environments. They are best known for building high-performance websites that can handle heavy traffic without compromising speed or reliability while meeting strict Core Web Vitals benchmarks. They are widely recognized among WordPress designers and engineers for building scalable, high-performance publishing systems.

**What makes them stand out**: Their technical expertise in building high-performance websites that handle massive traffic without losing speed. XWP is also known for contributing to WordPress core. Their engineering standards emphasize scalable DevOps workflows, performance testing, and API-first development for enterprise media brands.

**Industries or clients they serve**: Leading digital publishers and media organizations, such as Rolling Stone, Google, and News Corp, trust XWP for mission-critical WordPress projects that require enterprise-grade performance and stability.

### 11. WisdmLabs

![](https://www.atlantic.net/wp-content/uploads/2026/03/wisdmlabs-logo.png)

**Clutch Rating: 4.6/5**

WisdmLabs is a specialized WordPress website development company that focuses on creating tailored solutions for businesses and educational institutions. Their services include custom plugin development, WooCommerce solutions, and mobile-friendly websites. They increasingly implement modular Gutenberg blocks and performance-focused builds to ensure learning platforms meet modern Core Web Vitals standards. The WisdmLabs team is also widely recognized for its expertise in building eLearning platforms and WordPress-based learning management systems. Their platforms often include custom integrations with LMS tools and payment processors for scalable eLearning ecosystems.

**What makes them stand out**: Their niche expertise in eLearning and WooCommerce. WisdmLabs has created WordPress plugins and solutions widely used in the WordPress community. Their ability to integrate WordPress with LMS platforms, [payment gateways](https://www.atlantic.net/pci-compliant-hosting/top-10-payment-processors/), and API-driven course management systems makes them a strong fit for education-focused enterprises.

**Industries or clients they serve**: Educational institutions, eLearning platforms, and eCommerce businesses benefit most from WisdmLabs’ deep understanding of scalable WordPress development, structured content systems, and learning management integrations.

## What to Look for in WordPress Development Services

Not all WordPress development companies are the same. The best ones bring more than coding skills; they bring strategy, architectural planning, and long-term engineering discipline. In 2026, that also means expertise in headless WordPress, structured content systems, and measurable Core Web Vitals performance. The right WordPress experts will build flexible systems that support evolving WordPress features and integrations.

Here are a few things worth checking before choosing a partner:

- **Experience with Custom and Headless Architectures**

Look for a company that creates custom WordPress solutions, not just cookie-cutter themes. Enterprise projects increasingly require decoupled (headless) builds, API integrations, and modular Gutenberg blocks rather than monolithic themes. Custom websites reflect your brand and scale better as your business grows.

- **A Proven, Performance-Driven Development Process**

The right agency should follow a clear WordPress development process, from discovery and planning to launch and ongoing support. This includes collaboration between WordPress designers and engineers to ensure a consistent brand identity and seamless UX. This process should include Figma-to-Gutenberg workflows, structured content modeling, performance testing, and security reviews before deployment. This ensures quality and consistency at every stage.

- **Expertise in SEO, Core Web Vitals, and Security**

High-performance websites don’t happen by accident. Strong search engine visibility now depends on technical SEO, structured data, and ongoing website optimization. A skilled WordPress development agency should know how to optimize site speed, strengthen SEO, and keep your website secure. Ask how they measure Largest Contentful Paint (LCP), Interaction to Next Paint (INP), and other Core Web Vitals metrics in production environments.

- **Ability to Scale with Custom Functionality and APIs**

As your needs grow, so should your site. Look for teams capable of delivering advanced functionality and scalable custom integrations. The best WordPress developers can handle complex projects, custom plugin development, and advanced integrations to support growth. This often includes REST or GraphQL APIs, third-party SaaS integrations, and multi-site or multi-brand architectures.

- **Reliable Ongoing Engineering Support**

A website isn’t finished at launch. Ongoing support services, WordPress maintenance, and proactive monitoring are critical to sustaining performance and security. Choose a WordPress web development company that offers maintenance services, updates, and strategic support to ensure your site remains current and effective. For enterprise teams, this should include performance monitoring, structured block updates, and continuous optimization sprints.

There’s no shortage of agencies offering WordPress development services, but only a few consistently deliver websites that feel solid, scalable, and built for enterprise growth. The companies on this list have earned their place by combining technical expertise with modern architectural standards and a practical understanding of what large organizations need from their WordPress platforms today. Choosing a top rated WordPress agency ensures access to a skilled development team that can provide ongoing support and long-term value. If you’re planning your next enterprise WordPress project, any of these teams would be a strong place to start.

## The Importance of WordPress Cloud Hosting

Choosing the right development partner is crucial, but so is the hosting foundation for your custom website. Reliable hosting directly impacts website traffic, uptime, and the ability to enhance user experience across devices. In enterprise and headless WordPress environments, infrastructure directly impacts API response times, Core Web Vitals scores, and overall application stability. An expertly built site can still suffer from poor performance if its hosting isn’t up to the task. Atlantic.Net offers class-leading [WordPress Cloud Hosting](https://www.atlantic.net/vps-hosting/wordpress-vps-hosting/) solutions designed for speed, security, and the scalability modern websites demand.

With features such as one-click installations, [NVMe SSD](https://www.atlantic.net/dedicated-server-hosting/whats-the-difference-between-hdds-sata-ssds-and-nvme-ssds/) storage, and a reliable global infrastructure, our hosting ensures your professionally developed website performs optimally for every visitor. For headless deployments and high-traffic publishing platforms, optimized server configurations, dedicated resources, and low-latency networking are critical to maintaining consistent Largest Contentful Paint (LCP) and Interaction to Next Paint (INP) metrics. Furthermore, for organizations with specific compliance needs, Atlantic.Net also provides specialized solutions, such as [HIPAA WordPress Hosting](https://www.atlantic.net/hipaa-compliant-wordpress-hosting/), to ensure the highest standards of data protection and regulatory alignment.


---

# Top 10 GPU Hosting Services in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/top-10-gpu-hosting-services/ | Published: 2026-04-14 | Updated: 2026-04-15 | Author: Richard Bailey

Choosing the right GPU hosting provider for your GPU server hosting or GPU dedicated servers is a key decision that directly impacts data processing, AI training, and compute-intensive tasks. The market continues to expand in 2026, with providers offering high-performance GPU instances, flexible pricing, and optimized environments for demanding AI workloads.

## **GPU Cloud Providers**

We take a look at five GPU Hosting Services providers, with a detailed breakdown to help you compare the GPU services offered.

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

### **#1 Atlantic.Net**

Atlantic.Net is a well-established hosting provider with over three decades of experience in the technology industry, providing cloud hosting, dedicated server hosting, and colocation services.

Atlantic.Net has developed a strong GPU hosting solution, featuring powerful NVIDIA GPU instances. The platform now supports advanced workloads such as AI inference, deep learning algorithms, computer vision, and big data analysis, all powered by modern tensor cores for maximum performance. The service is engineered for demanding applications such as AI model training, deep learning, high-performance computing (HPC), professional graphics rendering, and intensive video encoding tasks.

Below is Atlantic.Net’s cloud control panel interface used to deploy and manage dedicated and GPU servers.
 ![Atlantic.Net Server Panel](https://www.atlantic.net/wp-content/uploads/2026/01/Atlantic.net-server-panel.png)
 Image Source: Atlantic.Net

#### **Pros:**

- **Extensive Experience:** Over 30 years in the hosting industry, indicating stability and a deep understanding of infrastructure needs.
- **High-Performance Hardware:** Provides access to cutting-edge NVIDIA GPUs, including the NVIDIA H100 NVL and L40S, ensuring top-tier computing power.
- **Optimized Infrastructure:** Combines powerful GPUs with fast NVMe storage and high-bandwidth networking to prevent bottlenecks and maximize throughput for AI workloads.
- **Security and Compliance Focus:** Strong emphasis on security, with data centers and services meeting compliance standards such as HIPAA, PCI DSS, and SOC 2/3, which is beneficial for handling sensitive data.
- **Reliability:** Known for a dependable platform with a 100% uptime Service Level Agreement for its cloud services.
- **Comprehensive Support:** Offers 24/7/365 customer and technical support from an experienced team based in the United States.
- **User-Friendly Platform:** Features an intuitive control panel for managing GPU instances and other cloud resources within your cloud account.

#### **Ideal for:**

- Businesses and organizations that need high availability and secure GPU instances for critical AI/ML projects.
- Teams running neural networks, image recognition models, and data analytics workflows.
- Users who need access to the latest NVIDIA GPU technology, like the NVIDIA H100, for compute-intensive training of deep learning models or large-scale simulations.
- Companies in regulated industries (e.g., healthcare, finance) require a hosting provider with a strong compliance posture.
- Developers and researchers looking for a stable platform with strong support for both short-term projects and long-running, demanding applications.
- Those who appreciate a provider with a long track record and a commitment to hardware quality and network performance.

![](https://www.atlantic.net/wp-content/uploads/2025/05/lambda.png)

### **#2 Lambda Labs**

Lambda Labs has gained recognition within the Artificial Intelligence and Machine Learning communities by supplying GPU cloud services and physical hardware specifically geared towards deep learning and other AI workloads. The platform is widely used for AI training, AI inference, and building development environments for large-scale models.

Let’s see the Lambda interface for analyzing resource usage, managing filesystems, and monitoring spending across projects.
 ![Lambda gpu dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Lambda-gpu-dashboard.png)
 Image Source: Lambda

#### **Pros:.**

- **Powerful NVIDIA GPUs:** Access to a variety of high-end NVIDIA GPU options, such as the A100 and NVIDIA H100.
- **Large Cluster Capabilities:** Known for supplying GPU clusters equipped with high-speed InfiniBand interconnects, which are very useful for large-scale training of deep learning models.
- **Colocation Services:** Provides colocation options for companies looking to house their own AI infrastructure.

#### **Cons:**

- **Pricing:** On-demand rates for GPU instances can be higher compared to some more budget-oriented providers.
- **Regional Availability:** The number of self-service regions for their GPU cloud might be more limited than what is offered by hyperscale cloud providers.
- **Free Credits/Trials:** May have fewer free credits or trial programs compared to some larger competitors.

#### **Ideal for:**

- AI startups and enterprises that need robust multi-GPU instances and cluster capabilities for training very large or complex models.
- Projects that require a combination of cloud and on-premises hardware solutions.
- Users who prioritize access to well-configured, high-performance NVIDIA GPU clusters over having the lowest possible cost.

![](https://www.atlantic.net/wp-content/uploads/2025/05/coreweave.png)

### **#3 CoreWeave**

CoreWeave has rapidly established itself as a specialized GPU cloud provider. Their primary focus is on delivering large-scale GPU compute capacity, using an extensive inventory of NVIDIA GPUs. It is optimized for the massive computing power required in video rendering, video transcoding, and advanced AI projects.

Here is the CoreWeave Cloud dashboard, where you can deploy GPU-powered virtual servers, manage storage, and monitor high-performance workloads.
 ![CoreWeave Cloud](https://www.atlantic.net/wp-content/uploads/2026/01/CoreWeave-Cloud.avif)
 Image Source: CoreWeave Cloud

#### **Pros:**

- **Performance-Tuned Infrastructure:** Their platform is purpose-built and optimized specifically for high-performance GPU workloads, particularly for AI/ML and rendering.
- **Scalability for Large Deployments:** Designed to handle very large-scale training and inference workloads effectively.
- **Strong NVIDIA Partnership:** A close relationship with NVIDIA may help ensure a consistent supply of the latest GPU hardware.

#### **Cons:**

- **Niche Focus:** Primarily concentrates on high-end, large-scale GPU compute, so it might not offer the same breadth of general cloud services as major cloud providers.
- **Complexity for Smaller Users:** The platform and pricing might be geared more towards large enterprises rather than individual developers or small-scale projects with intermittent needs.
- **Cost Structure:** While potentially cost-effective for large volumes, pricing for smaller deployments might be less competitive than some alternatives.

#### **Ideal for:**

- AI-first companies and large enterprises with substantial and continuous demand for GPU computing power.
- Organizations undertaking very large-scale AI model training, particularly for generative AI and large language models.
- Visual effects studios and rendering farms that require massive parallel processing capabilities.
- Users who need access to the absolute cutting edge of available NVIDIA GPU technology at scale.

![](https://www.atlantic.net/wp-content/uploads/2025/05/scaleway.png)

### **#4 Scaleway**

Scaleway is a European cloud provider that furnishes a variety of cloud computing services. These include standard compute instances, bare metal servers, and AI-ready GPU instances. They often highlight their transparent pricing structure and a strong commitment to European data sovereignty, including GDPR compliance. Their GPU VPS and bare metal options offer flexible GPU configurations for data analysis, scientific computing, and virtual desktop infrastructure (VDI).

Explore the Scaleway GPU hosting panel designed for managing GPU workloads, deploying containers, and scaling compute infrastructure efficiently. ![Scaleway server panel](https://www.atlantic.net/wp-content/uploads/2026/02/Scaleway-server-panel.jpg)
 Image Source: Scaleway

#### **Pros:**

- **Transparent and Competitive Pricing:** Known for clear pricing models that can be quite competitive, especially for **users** within their target market.
- **European Data Sovereignty:** Strong focus on GDPR compliance with data centers located exclusively in Europe (e.g., Paris, Amsterdam, Warsaw), appealing to customers with specific data residency needs.
- **Modern GPU Selection:** Provides access to current NVIDIA GPUs, including options like the NVIDIA H100, L40S, and L4, suitable for various AI workloads.
- **Startup Friendly:** Offers a startup program that can provide credits and support, making it attractive for new ventures.
- **Sustainability Focus:** Actively works on sustainable infrastructure with attention to power usage efficiency (PUE).

#### **Cons:**

- **Limited Global Reach:** Data center presence is primarily concentrated in Europe, which might not be optimal for applications requiring low latency to users in other parts of the world.
- **Fewer Managed Services:** The range of managed services, particularly for advanced AI or database solutions, may be less extensive compared to hyperscale cloud providers.
- **Ecosystem Maturity:** Their marketplace and third-party integrations might be less developed than those of larger, global providers.
- **No HIPAA Compliance:** Not suitable for U.S. healthcare applications that require HIPAA compliance.

#### **Ideal for:**

- European startups and businesses that prioritize GDPR compliance and data sovereignty.
- Users looking for cost-effective GPU instances with transparent pricing for AI model training and other GPU-accelerated tasks.
- Development teams that value a clean user interface and easy onboarding.
- Organizations that prefer a European hosting provider may benefit from their startup programs.

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

### **#5 Microsoft Azure**

Microsoft Azure is a comprehensive cloud computing platform that provides a wide range of services, including powerful GPU instances optimized for AI/ML workloads. Azure offers a robust infrastructure, extensive integrations with other Microsoft services, and a broad global presence. Azure supports a wide range of GPU workloads, including natural language processing (human language models), computer vision, and large-scale data processing.

Explore the Azure dashboard to organize resource groups, track usage, and manage cloud services from a centralized platform.

![Microsoft Azure](https://www.atlantic.net/wp-content/uploads/2026/01/Microsoft-Azure.png)

Image Source: Azure

#### **Pros:**

- **Extensive Global Infrastructure:** Azure has data centers in numerous regions worldwide, offering low latency access for users globally.
- **Wide Range of GPU Options:** Azure provides various NVIDIA GPUs, from entry-level to high-performance models like the NVIDIA A100 and H100, catering to different workload needs.
- **Deep Integration with Microsoft Ecosystem:** Seamless integration with Microsoft products and services such as Visual Studio, .NET, and Azure Machine Learning.
- **Azure Machine Learning Service:** Offers a comprehensive platform for building, training, and deploying machine learning models at scale.
- **Enterprise-Grade Security and Compliance:** Azure meets numerous compliance standards and offers advanced security features, beneficial for regulated industries.

#### **Cons:**

- **Complexity for Beginners:** The vast array of services and options can be overwhelming for users new to cloud computing.
- **Cost Management:** Optimizing costs can be challenging due to the complexity of pricing models and the variety of services available.
- **Learning Curve for Microsoft-Specific Tools:** Users unfamiliar with Microsoft tools and technologies may need time to adapt.

#### **Ideal for:**

- Enterprises already invested in the Microsoft ecosystem and seeking seamless integration with Azure services.
- Organizations requiring a global presence and low latency access for their applications.
- Teams that are already using Azure Machine Learning for building, training, and deploying AI/ML models at scale.
- Users who need a wide variety of GPU options to match different workload requirements and budgets.

## **Dedicated Server vs. Cloud GPUs: Making the Right Choice**

Now let’s look into the different types of GPU hosting that are available. You’ll need to decide between exclusive access to physical hardware (dedicated server) or virtualized resources from a shared pool (cloud GPUs).

- - **Core Differences:**
    - **Resource Allocation:** Dedicated offers exclusive hardware; Cloud uses shared, virtualized resources.
    - **Performance:** Dedicated provides predictable raw performance; Cloud offers excellent performance but can have slight variability.
    - **Control:** Dedicated gives full hardware/software control; Cloud has provider-defined configurations.
    - **Scalability:** Dedicated scaling takes more time; Cloud is highly scalable and quickly scalable.
    - **Cost:** Dedicated is often fixed monthly (better for constant high usage); Cloud is pay-as-you-go (flexible for variable needs).
  - **When a Dedicated GPU Server Makes Sense:** For consistent heavy workloads, highly performance-sensitive applications, needs for maximum control and customization, or stringent security/compliance requiring data isolation.
  - **The Flexibility of Cloud Providers:** Cloud GPUs offer on-demand availability, rapid experimentation, variable workload management, no hardware lock-in, access to diverse instance types, and geographic distribution.

- **One Cloud for Diverse Needs:** Major cloud providers allow management of GPU instances alongside other cloud services (databases, storage) under a single account, simplifying IT management.
- **Multi-GPU Instances:** For very demanding applications, cloud providers offer instances with multiple GPUs or clustering capabilities, dramatically reducing training times and enabling larger models.

## **Practical Considerations for GPU Hosting Success**

Ready to take advantage of GPU Hosting? Take some time to consider these important considerations:

- **Selecting the Right GPU Models and Instance Types:** Match the GPU to your workload to balance performance and cost, avoiding overspending or underperformance.
- **Finding the Best Balance of Performance and Cost:** Benchmark your workloads, understand GPU generations (newer often means better performance per watt, older can be cost-effective), consider VRAM needs, and don’t neglect CPU/system RAM. Spot instances can offer large savings for fault-tolerant workloads, while reserved instances provide discounts for long-term needs. Continuously monitor GPU usage.
- **Refine Your Code:** Ensure your code is set up to take full advantage of the GPU’s parallel processing capabilities.
- **Pre-Configured Templates for Quick Deployment:** These accelerate deployment by providing instances with pre-installed OS, drivers, and frameworks, reducing setup errors and speeding time to productivity.

By carefully considering these aspects, you can make informed decisions and get the most from GPU hosting services.

## **Atlantic.Net: Cost-Effective GPU Cloud Built for AI Workloads**

GPU hosting services have become essential, transforming how organizations approach computationally intensive workloads. In 2026, businesses rely on gpu server hosting to power ai projects, big data analysis, and real-time ai inference at scale. A well-designed GPU cloud built with one or more GPUs is indispensable for tackling multiple tasks efficiently, from the demanding training process of ML models and complex deep learning tasks to scientific research and natural language processing.

Having this kind of accessibility is allowing users to innovate faster, though selecting the right provider is key to ensuring smooth operation and avoiding complications like hidden fees.

For those ready to deploy machine learning models or accelerate other GPU-dependent projects, Atlantic.Net offers a robust and reliable solution. Our platform supports the entire lifecycle, from development with tools like NVIDIA CUDA and NVIDIA cuDNN to the final deployment stage.

Atlantic.Net provides the high-performance NVIDIA GPU instances, security, and expert support needed for your most critical applications. We invite you to explore Atlantic.Net’s GPU hosting services; visit our website or[ contact our team](https://www.atlantic.net/about-us/corporate-contact/) to discuss how we can meet your GPU hosting needs.


---

# Atlantic.Net Inference Cloud

> URL: https://www.atlantic.net/cloud-platform/inference-cloud/ | Updated: 2026-09-16

Deploy and run your own models on self-serve GPU cloud infrastructure designed for performance-sensitive inference. Configure your own runtime and supporting stack, then engage Atlantic.Net when you need a more tailored deployment.

- NVIDIA H100 NVL & L40S
- Fractional, Single & Multi-GPU
- Your Models & Runtime
- Custom Deployment Support

GPU-Backed Infrastructure: H100

GPU Allocation Options: 3

## Self-serve infrastructure for customer-managed AI inference

H100-powered infrastructure from a cloud provider built for performance-sensitive workloads.

Atlantic.Net Inference Cloud is a self-serve GPU cloud platform designed for teams that need dedicated GPU infrastructure for inference workloads.

It enables engineering teams to deploy and manage their own AI models without relying on a fully managed platform, giving more control over runtime, scaling, and deployment architecture.

Atlantic.Net provides the H100-powered infrastructure layer, while your team manages the model, runtime, and supporting services required for production environments.

You can start quickly with a self-serve setup, and scale into more advanced, custom deployment configurations as your infrastructure needs grow.

## Inference workloads need infrastructure designed for runtime performance and operational control

Production inference deployments depend on consistent responsiveness, predictable runtime behavior, and an environment your team can configure around the model serving stack you choose.

General-purpose cloud environments can be suitable for experimentation, but production inference often demands a better fit between the infrastructure and the workload.

Teams need GPU access that supports real application traffic, deployment patterns they can repeat, and sufficient control to tune services based on model behavior, request handling, and downstream integrations.

For engineering teams shipping AI features into real products, infrastructure decisions affect more than raw throughput. They shape how quickly models can be deployed, how reliably services can be operated, and how much freedom the team has to build its own inference environment rather than adapt to a rigid managed platform.

Atlantic.Net Inference Cloud is positioned for that middle ground: self-serve infrastructure with serious GPU backing, plus a path to engage infrastructure specialists when deployment requirements become more involved.

## Why Atlantic.Net Inference Cloud

### Self-serve by design

Get access to GPU-backed infrastructure without waiting for a fully managed platform workflow. Teams can provision infrastructure and move forward with their own deployment approach.

### H100-backed for demanding inference workloads

Atlantic.Net Inference Cloud is positioned around NVIDIA H100 support for customers running performance-sensitive inference workloads that need high-end GPU infrastructure.

### Your models, your runtime, your deployment choices

Atlantic.Net provides the infrastructure. Your team manages the models, serving framework, containers, services, and integrations required for your use case.

### Better fit for teams that want control

Some organizations do not want to be locked into an opinionated AI platform. Atlantic.Net Inference Cloud gives teams the flexibility to deploy the stack that best matches their needs.

### Built for production-oriented AI infrastructure needs

This offering is designed for teams moving beyond experimentation and into repeatable inference environments that support real application workloads.

### Direct path to custom deployment support

When requirements go beyond a standard self-serve setup, Atlantic.Net can work directly with your team on deployment guidance, architecture planning, and environment design.

## How Atlantic.Net Inference Cloud works

### Provision infrastructure

Start with a self-serve deployment model to access GPU-backed cloud infrastructure for inference workloads.

### Deploy your own model and supporting stack

Bring your own models, containers, runtimes, and application components with full control over deployment.

### Configure inference services and access

Set up endpoints, networking, and access patterns required for your applications and systems.

### Run and expand workloads

Operate inference workloads and scale GPU usage as your application grows.

### Engage Atlantic.Net for more complex deployments

Work with experts for architecture planning and advanced deployment requirements.

## Practical inference use cases

### LLM-powered product features

Run customer-facing or internal AI features that depend on your own model deployment approach rather than a managed third-party stack.

### Internal AI assistants

Deploy models that support employee workflows, knowledge access, operational support, or internal productivity tools in a controlled environment.

### Chatbots and conversational applications

Support chatbot and conversational experiences using models and serving frameworks selected by your own engineering team.

### Document analysis pipelines

Run inference workloads for document processing, classification, extraction, summarization, or workflow automation tied to business systems.

### Real-time classification and extraction

Support applications that need fast model responses for labeling, routing, filtering, or structured data extraction.

### Private AI environments for business workloads

Create inference environments that enable teams to maintain tighter control over deployment design, access, and infrastructure choices.

## Infrastructure built for customer-managed inference

Atlantic.Net Inference Cloud provides customers with access to H100-based infrastructure in a GPU-backed cloud environment designed for inference workloads. The focus is straightforward: provide the infrastructure layer needed to deploy and run your own models.

This is a self-serve offering. Your team is responsible for model deployment, runtime configuration, and the surrounding software stack. That makes it a practical fit for organizations that want to keep control over how inference services are built and operated.

For teams with more advanced requirements, Atlantic.Net also provides an option to engage directly for custom deployment support. That can be useful when standard self-serve infrastructure is only part of the solution, and the environment needs more deliberate planning.

Platform foundations

- H100-based infrastructure for performance-sensitive inference deployments
- GPU-backed cloud environment designed for AI runtime workloads
- Self-serve deployment model for faster access and operational control
- Customer-managed models so your team chooses the stack and deployment method
- Optional custom deployment engagement when architecture needs are more involved

## Who Atlantic.Net Inference Cloud is for

### Teams deploying their own models

Built for organizations that want infrastructure for inference without handing off model deployment and runtime decisions to a managed platform.

### Engineering teams that want GPU access without platform lock-in

A strong fit for AI engineers, MLOps teams, platform engineers, and DevOps teams that need GPU infrastructure but want to retain control over how services are built.

### SaaS companies shipping AI features

Useful for software teams adding AI-powered functionality to products and looking for a practical infrastructure foundation for production inference.

### Enterprises with controlled or private deployment needs

Relevant for organizations that want to run inference workloads in an environment aligned to internal deployment, security, or operational preferences.

### Buyers who may start self-serve and evolve later

Some teams want to begin with a straightforward self-serve path, then engage on architecture or deployment planning as requirements become more complex.

## Need more than a standard self-serve setup?

Atlantic.Net Inference Cloud supports self-serve deployment, but some inference environments need more planning. If your team needs help shaping the right infrastructure approach, Atlantic.Net can engage directly to support deployment design and implementation planning.

- You need guidance on infrastructure architecture for a more complex inference environment.
- You want help designing the right deployment model for private or controlled workloads.
- You need a more tailored setup than a standard self-serve starting point

## Add an AI Agent to the Stack

Inference infrastructure runs the model. An AI agent gives people and applications a practical way to use it: through conversations, tools, schedules, memory, and multi-step workflows.

Atlantic.Net offers OpenClaw and Hermes Agent as one-click applications on persistent Cloud Servers. They complement the customer-managed model-serving layer described on this page, but they solve a different part of the stack. The current application images connect to a customer-supplied model provider such as OpenAI, Anthropic, or OpenRouter; model usage is billed separately from the Cloud Server.

### OpenClaw Hosting: An Assistant Available Through Chat

OpenClaw Hosting gives a self-hosted, messaging-first AI assistant an always-on Gateway. Connect supported chat applications, authorize users, maintain sessions and memory, and keep the Gateway state on a Cloud Server under your account.

Choose OpenClaw when conversation is the main interface, and users need to reach the same assistant from approved channels, a browser, or mobile devices.

[Deploy OpenClaw in One Click](https://cloud.atlantic.net/?page=signup)

### Hermes Agent Hosting: Tools, Skills, and Scheduled Work

Hermes Agent Hosting gives a tool-using agent a persistent environment for memory, reusable skills, browser and terminal work, delegation, messaging, and scheduled automation.

Choose Hermes when the main job is carrying out a bounded, repeatable procedure with approved tools, defined outputs, and clear execution limits.

[Launch Hermes in Minutes](https://cloud.atlantic.net/?page=signup)

### Two Operating Models, One Cloud Platform

OpenClaw and Hermes overlap, but they organize the experience differently. Start with OpenClaw for a messaging-first assistant. Start with Hermes for tool-driven automation. Run both in separate environments, each with a distinct job, credentials, and trust boundary.

[See the Atlantic.Net Cloud Platform](https://www.atlantic.net/cloud-platform/)

## FAQs

### What is Atlantic.Net Inference Cloud?

Atlantic.Net Inference Cloud is a self-serve GPU cloud offering for inference workloads. We provide customers with H100-backed infrastructure to deploy and run their own models.

### Is this a managed inference platform?

No. Atlantic.Net Inference Cloud is a self-serve infrastructure, not a fully managed inference platform. Customers are responsible for deploying and managing their own models and supporting stack.

### Can I deploy my own models?

Yes. This offering is intended for customer-managed models. Atlantic.Net provides the infrastructure layer, while your team deploys and operates the model environment.

### What GPUs are available?

The current Atlantic.Net GPU inventory includes the NVIDIA H100 NVL and NVIDIA L40S. You can access fractional GPUs, single-GPU, and multi-GPU configurations.

### Who is this platform for?

It is built for AI engineers, MLOps teams, platform engineers, DevOps teams, SaaS companies building AI features, and enterprises that need GPU-backed inference infrastructure.

### When should I contact Atlantic.Net for a custom deployment?

You should contact Atlantic.Net when your requirements go beyond a standard self-serve setup, especially if you need help with architecture planning or environment design. [Reach the team 24x7x365](https://www.atlantic.net/support/).

### Is this suitable for production inference workloads?

Yes, the offering is intended for teams running production-oriented inference workloads that need strong GPU infrastructure and control over deployment.

## How do I get started?

Visit our GPU pages for further information, or reach out to our sales team to discuss your options.

## Launch quickly. Scale with the right level of support.

Start with self-serve H100-backed infrastructure for your inference workloads, then engage Atlantic.Net when you need a more tailored deployment approach. Atlantic.Net Inference Cloud gives your team a practical path to run customer-managed models with speed, control, and room to grow.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Root Access Dedicated Servers with Complete Administrative Control

> URL: https://www.atlantic.net/dedicated-server-hosting/root-access-dedicated-server/ | Updated: 2026-09-16

Get a private physical server with full root access and the freedom to choose the operating system, control panel, storage type, software stack, and server management approach that fits your workload.

- Private Physical Server
- Full Root/Admin Access
- Linux, Windows & Custom Stacks
- 24/7/365 US-Based Support

Resource Isolation: Private Hardware

Support Coverage: 24/7/365

## Root Access Dedicated Servers

When your business needs more than basic hosting, a root-access dedicated server delivers the performance you need to build exactly what you want. There is no sharing of resources with other tenants. You are not boxed into a preset stack. You get a private physical server, full root access, and the freedom to choose the operating system, control panel, storage type, and server management approach that fits your workload. This flexibility matters when you are running high-traffic websites, online stores, extensive databases, custom APIs, AI, virtualization projects, or other resource-intensive applications that need stable performance and exclusive access to dedicated hardware.

Atlantic.Net is a strong fit for businesses that want root access on dedicated cloud or dedicated bare metal. Our dedicated server hosting is built around private physical servers, configurable CPU, disk, and memory options, support for a wide selection of operating systems and control panels, and the ability to choose managed or unmanaged service addons. All wrapped up in our 24x7x365 US-based technical support model.

You can pick from pre-designed dedicated cloud instances, or reach out to Atlantic.Net for a custom-built server tailored to your exact specifications. For growing teams, dedicated servers are about power and control. You can install any software, create user accounts, add a server management panel, run third-party software, deploy virtual machines, and optimize performance around your own needs.

You decide how much administrative control stays in-house and when to bring in outside help. Atlantic.Net supports both models. If you want to keep full admin access internally, you can. If you want managed services for backups, intrusion detection, firewall support, or server management, these options are available too.

Talk to Atlantic.Net today for root access to dedicated servers that can be planned around your application stack, storage needs, network needs, and match your growth ambitions.

## Benefits of Choosing a Root Dedicated Server

### Complete Control Over Your Environment

With root access, your team is not limited to a preset software stack or a locked-down server image. You can configure the operating system, install the tools you need, manage users and permissions, and tune the server around your workload instead of adapting your workload to the platform.

### Dedicated Performance Without Shared Resource Limits

A dedicated server gives your applications exclusive access to server resources, which is important for workloads that need more predictable performance. That makes root-access dedicated hosting a strong fit for high-traffic websites, large databases, virtualization, analytics, and other resource-intensive environments.

### Flexibility for Linux, Windows, and Custom Stacks

One of the biggest advantages of root access is the freedom to build around the tools your team already knows. Atlantic.Net dedicated hosting supports multiple operating systems and control panels, making it easier to deploy a server that matches your existing workflows rather than forcing a migration to someone else's default setup.

### Stronger Security and Governance Control

Root access makes it easier to apply your own hardening standards, access policies, patching schedules, and monitoring tools. For organizations with internal governance requirements or regulated workloads, that level of administrative control can be a major advantage. Atlantic.Net excels at compliance-oriented hosting, including HIPAA, PCI, HITECH, GDPR, and SOC-related solutions.

### Managed Help When You Want It

Some teams want full administrative access but do not want to handle every operational task alone. Atlantic.Net offers both managed and unmanaged dedicated hosting paths, along with add-on services such as backups, intrusion detection, firewalls, CDN, and DDoS protection. Giving customers room to keep control in-house while still bringing in support where it makes sense.

### A Clear Path to Future Growth

A root-access dedicated server should not leave you boxed in. Atlantic.Net offers both standalone dedicated bare-metal servers and Dedicated Hosts through our ACP cloud console, giving customers a path from traditional dedicated hardware to cloud-connected dedicated capacity when requirements change. This is useful for teams planning expansion, multi-environment deployments, or longer-term infrastructure flexibility.

### Support Backing the Infrastructure

For many buyers, the value of a dedicated server is not just the hardware but the ability to get help when it matters. Atlantic.Net dedicated hosting includes 24/7/365 USA-based phone and email support, which helps reinforce the platform for customers who want root access without losing access to experienced assistance.

## Built for Complete Control

If your team is comparing shared hosting, standard cloud instances, and dedicated root access servers, the difference is simple:

### Root-access dedicated servers

Root-access dedicated servers mean isolated hardware, dedicated resources, full administrative access, and a hosting environment built for serious workloads - a better choice when uptime, speed, security settings, and direct control matter to revenue.

### Shared Hosting

Shared Hosting: means sharing resources. Many virtual instances run on a virtualization layer that can limit your direct control over the physical server.

Atlantic.Net dedicated and bare-metal hosting provides full control from day one. Each system is a dedicated physical server with full admin permissions, a dedicated IP address, a control panel, and support for any popular operating system. Atlantic.Net bare-metal servers are not tied to existing cloud hypervisors, making them useful for teams that want direct access to the server's resources and a "cleaner" server environment.

## Root Access Dedicated Servers for Linux and Windows

One of the biggest advantages of dedicated root-access is the freedom to choose any operating system. Atlantic.Net supports multiple versions of Microsoft Windows Server and several Linux distributions on our dedicated hosting, including popular installations such as Ubuntu, RHEL, Rocky Linux, and Fedora. You can install whatever operating system you want on our bare-metal servers.

Giving your team the ability to choose the stack you already know, whether you need Windows-based workloads, a Debian Linux flavor, or a Linux-first hosting environment for web apps, containers, and automation.

With root access, you are free to install custom software, configure system services, lock down remote control access, and shape the operating system around the way your business actually works. Our bare-metal options support hypervisors like VMware, Proxmox, and Hyper-V. That is a major step up from plans that limit what you can install or how deeply you can modify the server.

## High-Performance Workloads

Not every application copes comfortably in a shared environment. Dedicated servers are a better fit for demanding workloads, particularly high-traffic websites, large databases, online stores, and AI projects that require stable computing power and predictable resource access.

The Atlantic.Net dedicated server lineup includes options with SSD and NVMe SSD storage, as well as AMD EPYC-based systems for customers who need high core density and memory bandwidth for more demanding workloads.

That makes dedicated servers a strong option for businesses running custom AI platforms, analytics jobs, database-heavy applications, private virtualization, and services where disk subsystem speed, local storage, and dedicated resources affect the user experience. When every second counts, having full control over the server helps optimize performance rather than work around platform limits.

## Full Root and Administrator Access

Some providers talk about flexibility, but still keep you behind layers of restriction. Full root access grants complete administrative control. You can create user accounts, set policies, deploy a control panel, manage firewalls, configure networking, add additional IP addresses, and decide exactly how the machine is used.

Atlantic.Net makes this easy with managed or unmanaged solutions. If you want to handle server management internally, you can. If you want help with server management, backups, intrusion detection, managed firewalls, web application firewalls, CDN support, or DDoS protection, Atlantic.Net offers these add-ons as part of our broader hosting services.

## Growth, Reseller Hosting, and Multi-Site Projects

Growth is easier when your hosting provider does not force you to rebuild everything later. Atlantic.Net gives you the space to host multiple websites, run custom billing and provisioning packages, set up a reseller stack, or deploy your own virtualization layer for virtual machines. If you need WHM, cPanel, database software, security tools, or a custom server management panel, you can install the tools that match your workflow.

For even greater flexibility, Atlantic.Net offers dedicated hosts through our ACP cloud console for customers who want cloud-connected dedicated hardware, enabling quick deployment and running multiple dedicated instances on the same physical server. This is useful for teams running resource-intensive applications that need easier instance placement, BYOL licensing, or faster expansion paths across multiple environments.

## Why You Need Root Access Dedicated Servers

You need affordable dedicated servers when your business has outgrown the limits of shared hosting or entry-level virtual servers. Once your application stack becomes more complex, your team needs more than disk space or a control panel login. You need unparalleled control of the actual server. You need the ability to install software, tune services, manage the server directly, and set security rules based on your risk level.

You also need performance to stay predictable. Busy online stores, SaaS platforms, content-heavy websites, customer portals, and internal business systems all need rock-solid connectivity. A dedicated server gives you exclusive access to CPU, DDR4/DDR5 RAM options, and SAN storage, so you are not dealing with noisy neighbors or hidden limits. Leading to more consistent speed, better handling of incoming traffic, and a better user experience.

Another reason companies choose dedicated root-access servers with Atlantic.Net is security and governance. Full administrative access lets your team implement advanced security measures, manage patches on your schedule, properly separate user accounts, restrict services, and install the monitoring or compliance tools your environment requires. For businesses in regulated industries, that level of administrative control is often not optional. Atlantic.Net offers industry-leading security and compliance-ready hosting, including PCI, HIPAA, HITECH, and SOC-related options.

You may also need root access to dedicated servers because your stack is unusual. Maybe you run custom software. Maybe you need specific Linux distributions. Maybe you want Windows Server with licensing support. Maybe you need additional IP addresses, NVMe storage, backup services, or a support team that can step in when needed. Atlantic.Net supports custom server builds with extra RAM, additional SSD or NVME storage, Windows operating system licensing, and control panels, all combined for maximum performance.

Dedicated root-access servers make sense when you want a server hosting solution that grows with you. All hardware specifications give you full control now and leave room for hardware upgrades, operating system changes, additional security layers, more sites, and more applications later.

## Why Choose Atlantic.Net for Root Access Dedicated Servers?

Atlantic.Net is not new to this market. We have been providing IT services for more than 32 years. We have been trusted since 1994, and operate as a global cloud services provider with managed and unmanaged hosting solutions. We have data center locations worldwide that support our bare-metal and dedicated services. This matters because dedicated servers are rarely a casual purchase. Most buyers want a hosting provider with experience, strong support, and a track record of helping businesses across the globe run serious infrastructure.

Support is another reason to look closely at Atlantic.Net. We offer 24/7/365 USA-based phone and email support and do not outsource support for our dedicated hosting. For customers running dedicated servers, this flexibility matters. There are times when you want complete control, and there are times when you want fast technical support from people who know the platform. Atlantic.Net is built from the ground up to support both.

Atlantic.Net also brings a wider infrastructure story. Our global data center footprint spans the United States, Canada, Europe, and Asia, and offers options ranging from standalone dedicated servers to bare-metal and dedicated cloud hosting. Giving buyers more paths forward when root-access dedicated servers need to connect to cloud services, support compliance projects, enable backups, or support future expansion plans.

If your business needs root access, dedicated servers with full control, real support, and room to grow, put Atlantic.Net on your shortlist.

## FAQs

### What are root access dedicated servers?

Dedicated root-access servers are private physical servers that give you the highest level of administrative access. You can choose the operating system, install custom software, manage user accounts, configure security settings, and control how the server is used.

### Are root-access dedicated servers better than shared hosting?

For demanding business workloads, dedicated root-access servers are usually a much better fit than shared hosting. Shared hosting means sharing resources and having limited control over them. A dedicated server gives you isolated hardware, dedicated resources, full root access, and more stable performance for high-traffic websites, online stores, and custom platforms.

### Can I install my own operating system and software?

Yes. One of the main reasons businesses choose dedicated root-access servers is the ability to install the software and run the operating system of their choice. Atlantic.Net supports Microsoft Windows Server, Ubuntu, CentOS, Rocky Linux, Fedora, and more, along with control panel choices and custom server configurations.

### Does Atlantic.Net offer managed help with root access on dedicated servers?

Yes. Atlantic.Net dedicated hosting can be managed or unmanaged. We offer managed services and add-ons, including firewalls, intrusion detection, backups, and server management. That means you can keep full administrative access while still getting help where you need it.

### Are root-access dedicated servers good for demanding workloads?

Yes. Root access dedicated servers are a strong fit for demanding workloads because they provide dedicated hardware, exclusive access to server resources, and more predictable performance. Atlantic.Net's offerings include SSD and NVMe options, Intel and AMD EPYC-based bare-metal choices, and custom-built dedicated servers for more demanding workloads.

### How quickly can Atlantic.Net deploy dedicated root-access servers?

Deployment speed depends on the product. Atlantic.Net's dedicated cloud hosts can be deployed through the ACP cloud console in seconds, while our standalone dedicated servers are custom-built to specification and confirmed before deployment. That gives buyers both instant provisioning paths and more customized build options. Contact our sales team for more information.

### Do root-access dedicated servers work for reselling hosting and multiple websites?

Yes. Root-access dedicated servers are often used for reseller hosting, multi-site hosting, private virtualization, and custom platform builds because you get full control over the server environment. You can install billing software, a server management panel, cPanel or WHM, security tools, and other third-party software as needed. Atlantic.Net also notes support for control panels and cloud-connected dedicated host options.

## Cloud Availability in Multiple Global Regions

Deploy close to your users from eight international data centers worldwide, with new regions on the way.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Moving Away From Rackspace: Why Legacy Windows Workloads Don’t Always Lift-and-Shift

> URL: https://www.atlantic.net/cloud-platform/moving-from-rackspace-legacy-windows-migration-guide/ | Published: 2026-04-23 | Updated: 2026-05-03 | Author: Richard Bailey

Some Rackspace customers start looking for a new hosting provider for many reasons. Rising costs, contract pressure, or product-fit concerns could be reasons behind shopping for other providers.

For standard workloads, migrating is usually a manageable project. Legacy environments are different. When a business depends on older systems that still need to run as they do today, moving away from Rackspace can become more complicated, especially if modernization is planned for later rather than as part of the initial move.

That was the situation for one such customer who contacted Atlantic.Net recently.. They needed to [move off Rackspace](http://docs.rackspace.com), but the immediate priority was not redesigning the platform; it was keeping the platform running as is with minimal disruption while creating space for future upgrades on a more realistic timeline.

This is a common issue for organizations still running Windows Server 2008 R2, Windows Server 2012 R2, or SQL Server 2008 R2, where operating system and database licensing are bundled into the monthly service.

A true lift-and-shift is rarely as simple as it sounds, and at Atlantic.Net, it is not an option on out-of-support versions of Windows Server. Even so, there is a workable path forward, and it is more achievable than the initial responses from prospective hosts may suggest.

## Why Leaving Rackspace With Legacy Windows Feels Different

These days, most cloud customers do not spend much time thinking about Windows or SQL Server licensing, as those costs are folded into the monthly server bill. Rackspace customers with legacy Windows workloads have operated that way for years, which has shielded many businesses from a difficult industry reality: older Microsoft platforms may still run, but moving them is no longer straightforward once support status, licensing, and provider policy come into play.

That reality usually becomes clear during the first round of migration quotes. A prospective host asks which operating systems and database versions are in use. The customer answers: Windows Server 2008 R2, Windows Server 2012 R2, or SQL Server 2008 R2. At that point, many providers either walk away or insist that upgrades happen before the migration can begin. For customers who expected a simple lift-and-shift, that can make the entire move feel unexpectedly complicated.

The real issue, though, is usually not the destination host. Legacy Microsoft workloads require a migration plan built around compatibility, licensing, and risk, not just infrastructure.

## Why Most Hosts Decline Windows Server 2008 R2 and 2012 R2

The assumption behind a clean lift-and-shift is that any qualified provider can pick up the workload as-is. For legacy Windows, that assumption breaks for a practical reason, not a regulatory one: reputable hosts cannot keep an unpatched operating system secure, and they will not take responsibility for one that cannot be patched.

Microsoft’s own dates make the problem concrete:

- **Windows Server 2008 R2** reached the end of extended support on [14 January 2020](https://learn.microsoft.com/en-us/lifecycle/products/windows-server-2008-r2). Extended Security Updates (ESU) through the general program ended on 10 January 2023, and the Azure-only extension ended on 9 January 2024. No security updates are available for this version anywhere today.
- **Windows Server 2012 R2** reached the end of extended support on [10 October 2023](https://learn.microsoft.com/en-us/lifecycle/products/windows-server-2012-r2). ESU Year 3 is still running as of this writing, covering 15 October 2025 to 13 October 2026, with about six months of coverage left.
- **SQL Server 2008 R2** reached the end of extended support on 9 July 2019. Azure ESU ended in July 2022.

A host that provisions an unpatched OS for a production workload becomes part of a shared responsibility. If a known, unpatched vulnerability compromises that workload, the host is partly accountable for running a platform it could not secure. Most providers, including Atlantic.Net, decline the work for that reason alone. Atlantic.Net’s position is direct: these operating systems are no longer supported, they are end of life, and Atlantic.Net cannot support or install patches for them.

This is a security decision, not a licensing one.

## What SPLA and ESU Actually Allow

A separate claim circulates among customers exploring this situation: that Microsoft’s Services Provider License Agreement (SPLA) forbids hosts from installing legacy Windows or SQL. That claim is not quite right, and it is worth clearing up.

SPLA is the licensing program hosting providers use to rent Microsoft software to customers monthly. [SPLA includes downgrade rights](http://microsoft.com/licensing), which means a provider with a current SPLA agreement can technically deploy older versions for a legitimate reason. Running an out-of-support version under SPLA is not automatically non-compliant from a paperwork perspective.

Windows Server 2012 R2 ESU is specifically eligible for SPLA customers, and a provider willing to run that plumbing could, in principle, keep a customer patched on 2012 R2 through 13 October 2026. A few providers do. Most do not. The reasons come back to operations rather than licensing: an ESU-covered 2012 R2 server still runs an OS that has been out of mainstream support since 2018, still requires specialized patching pipelines, and still becomes unpatched the moment ESU runs out. Atlantic.Net is one of many providers that decline to work on those grounds.

For Windows Server 2008 R2 and SQL Server 2008 R2, the question is simpler. No ESU program exists for either product today. There is no path to keeping them patched at any provider.

## Rackspace’s Own Guidance Points in the Same Direction

Rackspace publishes an end-of-support page that covers exactly this situation. When a Rackspace customer asks Rackspace what to do about Windows Server 2008 or SQL Server 2008, the answer is one of three: migrate to a modern OS on Azure with Rackspace support, stay on the legacy OS in Azure to pick up Extended Security Updates, or migrate to a modern OS in a Rackspace data center. The page calls doing nothing “the option that’s not an option.”

Rackspace is telling its own legacy customers that an upgrade, or a migration paired with an upgrade, is the only responsible path. When a prospective new host says the same thing, it is not being difficult; it is giving the same advice Rackspace would.

## The Realistic Path: In-Line Upgrade, Then Migrate

The honest way to leave Rackspace with a legacy Windows stack is to upgrade the operating system first, then move the workload. At Atlantic.Net, that happens as an in-line upgrade to a supported Windows Server release, scoped and priced as a separate Professional Services engagement before the servers land in a production hosting tier.

The preferred in-line targets are Windows Server 2022 or Windows Server 2025, with Windows Server 2019 accepted where an application dependency makes one of the newer releases impractical. Windows Server 2016 is not a target version; it is close enough to end of life that upgrading to 2016 trades one short runway for another.

Customers often assume that upgrading and migrating together doubles the risk. In practice, it usually reduces it: moving once to a modern stack is simpler than moving once to a legacy stack a new provider reluctantly hosts, then moving again when that platform is deprecated a year later.

A common Rackspace footprint maps directly onto a modern target. A web tier on IIS and ASP.NET moves to Windows Server 2022 with IIS 10; most classic ASP.NET Framework applications run unchanged once the .NET version and application pool settings are matched. A SQL Server 2008 R2 database moves to SQL Server 2019 or 2022, where backward-compatible database engines continue to support the older compatibility level after a backup-and-restore migration. A shared domain controller and utility box are moved to Windows Server 2022 Standard, with the Active Directory forest and domain functional levels raised once the last legacy domain controller is decommissioned.

Atlantic.Net’s engineering team can stage the servers on a single dedicated host with Hyper-V or VMware and cut over in a defined window, or run them as separate dedicated servers, depending on license economics and workload profile. For workloads where virtualization is ruled out, bare-metal options are available in Orlando, Florida, and Dallas, Texas.

## What Atlantic.Net Offers For A Rackspace Migration

Atlantic.Net regularly runs the combined in-line upgrade and migration path for Rackspace customers. The work is split into two scopes, priced and signed separately, so the customer knows exactly what the hosting tier covers and what the upgrade engagement covers.

The [in-line upgrade engagement](https://www.atlantic.net/managed-services/migration-services/). Upgrading Windows Server 2008 R2 or 2012 R2 to a supported release is handled by the Atlantic.Net Managed Services team under a [Professional Services Agreement](https://www.atlantic.net/managed-services/consulting/). Scope, effort, and fixed price are set on a case-by-case basis during discovery based on server inventory, application dependencies, and downtime tolerance.

The ongoing hosting tier. Once the upgrade is complete, the workload moves into a standard Atlantic.Net hosting tier:

- **Windows licensing included.** Windows Server 2016, 2019, and 2022 licensing on dedicated bare metal, and Windows Server 2012 through 2025 on the [Atlantic.Net Cloud Platform](https://www.atlantic.net/cloud-hosting/). No bring-your-own-license required.
- [**Dedicated single-tenant hardware**](https://www.atlantic.net/dedicated-server-hosting/) in US data centers, with RAID-10 NVMe storage, KVM for out-of-band recovery, and a triple 100% SLA on network, power, and hardware.
- **Multi-VM on a single host** via Hyper-V, VMware, or Proxmox, where that matches the workload.
- **Migration assistance on the hosting side.** Managed HIPAA customers receive 4 hours of free migration credit toward their server and database moves. Additional move work is billed at $165 per hour (discounted from $195) with a four-hour minimum. This does not cover the in-line OS upgrade, which sits under the Professional Services engagement above.

The split matters. Atlantic.Net provides the hosting foundation and the licensing for supported Windows on it, but does not take on the operational risk of running an unsupported OS in production. Where the stack needs to modernize to cross that line, Managed Services handles the upgrade as its own quoted engagement.

## Questions To Ask Any Host You Are Evaluating

Whether you are talking to Atlantic.Net or to another provider, this short list separates the hosts worth your time from the ones who will make the migration harder than it needs to be:

1. Do you include Windows Server licensing with the service, or do I need to bring my own?
2. What is your policy on hosting Windows Server versions that are past mainstream support? Past extended support?
3. Can you describe the migration assistance included with onboarding, including the hours included, any additional rates, and whether application migration is in scope?
4. If my OS or SQL version needs to be upgraded to meet your hosting policy, would you handle the upgrade under a separate Professional Services engagement, and what would that look like in terms of scope and price?
5. Which data centers are available, and is single-tenant bare-metal an option if needed?

A provider that answers those five questions clearly will not surprise you at week three of the migration.

## Moving Forward

A move away from Rackspace with a legacy Windows stack is not the same project as a typical hosting migration, but it is not the brick wall the first few phone calls can make it feel like. The constraint is real: unsupported operating systems cannot be kept secure, and most providers have a good reason not to try. The path around it is also real and well-trodden. Upgrade the OS to a supported Windows Server release, then move the workload to infrastructure and licensing that will support it for the next five to ten years.

To get a specific configuration and quote, share your server inventory with the Atlantic.Net solutions team. The conversation covers licensing, hardware, migration help, and the timeline, adds the inline upgrade engagement when pre-2016 Windows is involved, and ends with a fixed monthly price for infrastructure that won’t ask you to move again.


---

# How to Become HIPAA Compliant: A Practical 10-Step Checklist

> URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-10-step-checklist/ | Published: 2026-04-24 | Updated: 2026-05-01 | Author: Alexander Wise

Becoming HIPAA compliant means you build and run a program that protects PHI (and especially ePHI) using the HIPAA Privacy, Security, and Breach Notification Rules. There is no official HIPAA certification; instead, you demonstrate compliance through written policies, workforce training, signed vendor agreements (BAAs), and technical safeguards, supported by ongoing documentation. 

Having a quick, clear, and easy 10-step HIPAA compliance checklist to run through can be a major help, which is what we are doing here. We will also take a look at a series of hosting questions from an Atlantic.Net healthcare client interested in learning more about compliance specifics.

## What is HIPAA Compliance?

HIPAA compliance is an operating state; it’s not a badge, and you don’t “buy” compliance from a tool or a hosting provider. Vendors instead support your compliance program, but you still own policies, access decisions, training, and breach response.

If you handle electronic protected health information (ePHI), the HIPAA Security Rule requires administrative, physical, and technical safeguards tailored to your risks.

## Why is HIPAA compliance required?

The HHS recently updated the civil monetary penalties for HIPAA violations. Effective January 28, 2026, these adjusted values reflect a cost-of-living increase to account for inflation.

Violation Tiers: The penalty structure remains divided into four tiers based on your level of knowledge and intent.

- **Tier 1 (Lack of Knowledge):** The entity did not know and could not have known of the violation.
- **Tier 2 (Reasonable Cause):** The entity knew or should have known, but did not act with willful neglect.
- **Tier 3 (Willful Neglect – Corrected):** The violation was due to intentional neglect but was fixed within 30 days of discovery.
- **Tier 4 (Willful Neglect – Not Corrected):** The violation was due to intentional neglect and was not fixed within 30 days.

## 2026 Adjusted Penalty Table

These figures apply to penalties assessed on or after January 28, 2026, for violations occurring after November 2, 2015.

| **Penalty Tier** | **Culpability Level** | **Minimum (Per Violation)** | **Maximum (Per Violation)** | **Annual Cap (Identical Violations)** |
| --- | --- | --- | --- | --- |
| **Tier 1** | Lack of Knowledge | $145 | $73,011 | $2,190,294 |
| **Tier 2** | Reasonable Cause | $1,461 | $73,011 | $2,190,294 |
| **Tier 3** | Willful Neglect (Corrected) | $14,602 | $73,011 | $2,190,294 |
| **Tier 4** | Willful Neglect (Uncorrected) | $73,011 | $2,190,294 | $2,190,294 |

**Note on Enforcement Discretion:** While these are the official inflation-adjusted figures, OCR has previously applied “enforcement discretion” to lower the annual caps for Tiers 1, 2, and 3. However, the legal maximums remain at the higher levels shown above, and Tier 4 violations always carry the highest financial risk.

**Administrative Simplification**: Beyond data breaches, these penalties also apply to other HIPAA rules, such as failing to provide a Summary of Benefits and Coverage (SBC), which now carries a maximum penalty of $1,443 per failure.

## 10-Step HIPAA Compliance Checklist

Maintaining compliance in 2026 requires more than just a checklist; it requires a proactive partnership with your infrastructure provider. At Atlantic.Net, we ensure our HIPAA-compliant hosting solutions align with the latest federal requirements, including the February 16, 2026, deadline for updated privacy notices. To begin, you must understand electronic Protected Health Information (ePHI), which refers to any PHI that is covered by HIPAA security regulations and is produced, saved, transferred, or received in an electronic form.

![](https://www.atlantic.net/wp-content/uploads/2019/01/How-to-Become-HIPAA-Compliant_Step-1-–-Create-a-Security-and-Privacy-Policy.png)

## **Step #1 – Create a Security and Privacy Policy**

A security and privacy policy is a controlled set of documents mapping directly to your safeguards and workflows. We recommend including:

- **Scope and Definitions:** Define ePHI vs. PHI, systems in scope, and “minimum necessary” access.
- **Administrative Safeguards:** Document your risk management process and security incident procedures.
- **Technical Safeguards:** Define MFA policies, audit logging, and encryption standards.
- **Physical Safeguards:** Control facility access and device disposal.
- **Cloud/Shared-Responsibility Appendix:** Clearly state who secures specific layers of the IaaS/SaaS stack.

**Tracking-Tech Policy:** Address the use of pixels and cookies on authenticated pages, as OCR guidance confirms these generally have access to ePHI.

![](https://www.atlantic.net/wp-content/uploads/2019/01/How-to-Become-HIPAA-Compliant_Step-2-–-Name-a-Privacy-and-Security-Officer.png)

## **Step #2 – Name a Privacy and Security Officer**

These roles require defined authority and budget influence.

- **Privacy Officer:** Focuses on policy ownership, HIPAA Business Associate Agreements (BAAs), and patient rights.
- **Security Officer:** Manages the risk analysis program and incident response.

**Note:** You must establish a HIPAA Business Associate Agreement (BAA) with all relevant vendors.

![](https://www.atlantic.net/wp-content/uploads/2019/01/How-to-Become-HIPAA-Compliant_Step-3-–-Perform-Periodic-Vulnerability-Reviews.png)

## **Step #3 – Risk Analysis + Vulnerability Management**

NIST SP 800-66 Rev. 2 provides the current implementation guidance for these assessments.

- **Security Risk Analysis:** Map where ePHI is created and stored. Identify threats like ransomware pathways.
- **Vulnerability Management:** Perform authenticated scanning and patch management with remediation SLAs.

**Configuration Integrity:** Use CIS baselines to detect configuration drift.

![](https://www.atlantic.net/wp-content/uploads/2019/01/How-to-Become-HIPAA-Compliant_Step-4-–-Create-a-Specific-Policy-for-Email.png)

## **Step #4 – Create a Specific Policy for Email**

Encryption for ePHI is an “addressable” specification, meaning you must implement it or provide a documented, reasonable alternative.

- **TLS Standards:** All emails containing ePHI must use TLS 1.2 or 1.3 for data in transit. Avoid outdated SSL terminology.

**Approved Systems:** Use secure messaging portals to ensure your [email system is HIPAA compliant](https://www.paubox.com/blog/hipaa-compliant-email) rather than standard unencrypted email unless the patient is warned of the risk and explicitly consents.

![](https://www.atlantic.net/wp-content/uploads/2019/01/How-to-Become-HIPAA-Compliant_Step-5-–-Create-a-Specific-Mobile-Policy.png)

## **Step #5 – Create a Specific Mobile Policy**

Mobile devices are primary ePHI pathways. Your policy must cover:

- **Device Management:** Use Mobile Device Management (MDM) for remote wipes, encryption at rest, and screen locks.

**Storage Restrictions:** Prohibit ePHI storage in personal cloud backups or consumer messaging apps.

![](https://www.atlantic.net/wp-content/uploads/2019/01/How-to-Become-HIPAA-Compliant_Step-6-–-Train-Your-Staff.png)

## **Step #6 – Train Your Staff**

Training should be continuous.

- **Modules:** Use short, quarterly “micro” modules in addition to annual refreshers.

**Phishing Simulations:** Track and remediate repeat failures to reduce the risk of credential theft.

![](https://www.atlantic.net/wp-content/uploads/2019/01/How-to-Become-HIPAA-Compliant_Step-7-–-Develop-a-Privacy-Notice.png)

## **Step #7 – Update Your Notice of Privacy Practices (NPP)**

**Compliance with updated NPP requirements is mandatory by February 16, 2026.**

- **42 CFR Part 2:** Your NPP must now include specific language regarding the confidentiality of Substance Use Disorder (SUD) treatment records.

**Redistribution:** Ensure the updated NPP is posted on your website and available at all points of service.

![](https://www.atlantic.net/wp-content/uploads/2019/01/How-to-Become-HIPAA-Compliant_Step-8-–-Solidify-Business-Associate-Relationships.png)

## **Step #8 – Solidify Business Associate Relationships**

This is a frequent failure point.

- **Vendor Inventory:** Identify all vendors that touch ePHI.

**BAA Execution:** Ensure a signed BAA is in place before any data is shared. Atlantic.Net provides a BAA for all our HIPAA-compliant customers.

![](https://www.atlantic.net/wp-content/uploads/2019/01/How-to-Become-HIPAA-Compliant_Step-9-–-Establish-a-Protocol-for-Possible-Breaches.png)

## **Step #9 – Establish a Protocol for Possible Breaches**

Your plan must include a HIPAA four-factor risk assessment to determine if an incident is a reportable breach:

1. The nature and extent of the ePHI involved.
2. The unauthorized person who used the information.
3. Whether the information was actually acquired or viewed.
4. The extent to which the risk has been mitigated.

![](https://www.atlantic.net/wp-content/uploads/2019/01/How-to-Become-HIPAA-Compliant_Step-10-–-Make-Sure-the-Privacy-and-Security-Policies-are-Followed.png)

## **Step #10 – Evidence and Enforcement**

OCR audits now focus heavily on “recognized security practices.”

- **Audit Logs:** Regularly review logs for unauthorized access to ePHI.
- **Policy Attestation:** Require annual workforce sign-offs on all privacy and security policies.

**Immutable Backups:** Maintain offline or immutable backups to ensure resilience against ransomware.

![](https://www.atlantic.net/wp-content/uploads/2019/01/HIPAA-Compliant_HIPAA_Checklist_New.jpg)

![](https://www.atlantic.net/wp-content/uploads/2019/01/How-to-Become-HIPAA-Compliant_Spotlight-HIPAA-Technology-Provider-Questions.png)

## **FAQ**

### Is there a HIPAA certification?

No official government “HIPAA certification” exists. You demonstrate compliance through policies, safeguards, training, BAAs, and documentation that you can defend during audits and investigations.

### How often should we do a HIPAA risk analysis?

HIPAA doesn’t set a single calendar interval, but risk analysis must be accurate and thorough, and you should update it when systems, vendors, workflows, or threats change. Treat it as continuous program work, not a one-time report.

### Does HIPAA require encryption?

Encryption is “addressable” in key Security Rule specifications. If encryption is reasonable and appropriate based on your risk analysis, implement it. If not, implement an equivalent alternative or document why neither is reasonable and appropriate.

### Can we use cloud services for ePHI?

Yes—if you sign a HIPAA-compliant BAA with the cloud service provider and otherwise comply with HIPAA. Cloud does not absolve you of your responsibilities for configuration, access, and governance.

### Do we need a BAA with every vendor?

You need a BAA with vendors that create, receive, maintain, or transmit PHI/ePHI on your behalf as a business associate relationship. Not every vendor is a business associate, but you should document your decision either way.

### What are the HIPAA breach notification timelines?

HIPAA breach notification generally requires notification without unreasonable delay and, for certain notices, no later than 60 days after discovery. HHS also publishes instructions for reporting breaches to the Secretary.

### Covered entity vs business associate: what changes?

Covered entities have direct obligations, such as issuing a Notice of Privacy Practices. Business associates must comply with Security Rule requirements for ePHI, meet Privacy Rule limits through contract, and report breaches to covered entities under the Breach Notification Rule.

![](https://www.atlantic.net/wp-content/uploads/2019/01/How-to-Become-HIPAA-Compliant_The-Right-HIPAA-Information-Technology-Answers.png)

## **Conclusion**

Every healthcare company must ask for advice when they work with IT providers since any issues with the provider would pose a risk to their patient’s health information. After all, even going through a minor HIPAA violation can be disastrous to a healthcare IT organization.

Atlantic.Net is a trusted HIT provider. Our clients trust us because we are experts on the subject and are fully transparent in all communications, as evidenced by this customer testimonial below: “Atlantic.Net’s reputation for 100% up-time, their secure infrastructure, and expertise in Healthcare IT were key components in finalizing our partnership,” said Complete Healthcare Solutions Vice President Joseph Nompleggi.

Feel free to contact us today to see if we can help you meet your HIPAA compliance needs with any of our award-winning [HIPAA-Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) or [Dedicated Hosting](https://www.atlantic.net/dedicated-server-hosting/).

---

#### Read More About HIPAA Compliance

- [HIPAA Compliance Checklist](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/)
- What Is the [HIPAA Security Rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/)?
- Top Considerations for [HIPAA File Storage](https://www.atlantic.net/hipaa-compliant-hosting/top-10-considerations-for-hipaa-compliant-file-storage/)
- [HIPAA Data Storage Requirements](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-cloud-storage/)
- Protecting [e-PHI](https://www.atlantic.net/hipaa-compliant-hosting/protecting-phi-cloud/) in the Cloud
- What Is [HIPAA Cloud Computing](https://www.atlantic.net/hipaa-compliant-hosting/what-is-hipaa-cloud/)?
- What Is [Healthcare Hosting](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/)?
- [What Is PHI?](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/)

---

*This article updated with the latest information on April 24, 2026.*


---

# HIPAA-Compliant Cloud Storage and File Sharing in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-cloud-storage/ | Published: 2026-04-24 | Updated: 2026-04-26 | Author: Richard Bailey

### How to Make Cloud Storage HIPAA Compliant?

HIPAA (the Health Insurance Portability and Accountability Act) compliance is all about protecting the integrity of Protected Health Information (PHI), and a major part of the Federal law requires a wide range of security and privacy safeguards to protect patient data at rest or in transit according to the HIPAA Privacy Rule and HIPAA Security Rule. What this means is that when your medical files are traveling around cyberspace, it must be done with the utmost due diligence in a cloud computing environment that is designed to protect against any form of a data breach and prevent an unauthorized user’s attempt to access files.

Modern HIPAA cloud storage strategies prioritize continuous monitoring, strict access validation, and real-time threat detection to reduce breach risk.

![](https://www.atlantic.net/wp-content/uploads/2021/08/HIPAA_Compliant_Cloud_Storage_FAQ_HIPAA-Compliant.jpg)

**How can you take advantage of the incredible power of cloud hosting while still meeting HIPAA-compliant cloud storage requirements at all times?**

The best way currently available to store your medical files and share them between various parties is with [HIPAA-compliant hosting.](https://www.atlantic.net/hipaa-compliant-hosting/) Different cloud apps are designed for file-sharing (examples include Box, Dropbox, and Google Drive), allowing you to back up the files and synchronize data between various devices. However, general technological solutions are not designed for the particular case of healthcare concerning encryption of electronic protected health information, which is where HIPAA-compliant cloud storage services can help.

Teams now evaluate whether file-sharing tools support audit logs, access tracking, and signed BAAs before storing any PHI.

## How to Maintain HIPAA Compliance When Using Cloud Storage Services or File Sharing Services

When a public cloud provider declares it is HIPAA compliant, this means the underlying infrastructure is secure. HIPAA-covered entities are still responsible for using identifying out-of-scope HIPAA requirements that the HIPAA-compliant cloud provider is not responsible for, monitoring for security incidents, and auditing their activity. Below are the key activities covered entities must carry out after they start using a HIPAA-compliant cloud storage service (or any HIPAA enterprise cloud services).

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_Sign_a_BAA_Business_Associate_Agreement_with_Your_Cloud_Storage_Service_Provider.svg)

### Sign a BAA (Business Associate Agreement) with Your Cloud Storage Service Provider

The first step to HIPAA compliance is to sign a Business Associate Agreement (BAA) with the cloud storage services provider.  This should help establish the guidelines of the relationship between the two entities. BAAs now often include terms covering API access, third-party integrations, and defined breach response timelines.

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_Establish_Responsibility_Matrix_for_HIPAA_Controls.svg)

### Establish a Responsibility Matrix for HIPAA Controls

Most providers will have a responsibility matrix ready to share to establish what the HIPAA cloud storage service provider will and will not be covered in terms of required HIPAA controls.  Establishing which entity will be responsible for what is a key function to ensure nothing is missed when establishing HIPAA compliance. Shared responsibility models are now standard, especially in hybrid and multi-cloud deployments.

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_Set_Up_Appropriate_Access_Controls.svg)

### Set Up Appropriate Access Controls

The cloud user must ensure that access controls are carefully configured so that only authorized individuals can access PHI. It is necessary to establish procedures for granting, revoking, and periodically reviewing access. Best practice includes least-privilege access, role-based permissions, and mandatory multi-factor authentication (MFA).

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_Set_Up_Patch_Management.svg)

### Set Up Patch Management

Ensure that all cloud systems are upgraded to the latest versions of their respective operating system and software. Put monitoring in place, ensure operations staff are notified when a patch is needed, and have a convenient way to apply patches to cloud systems. Automated patching and vulnerability scanning help reduce delays and limit exposure to known threats.

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_etUp_Firewalls_with_Logging.svg)

### Set Up Firewalls with Logging

HIPAA requires that local cloud storage data centers and workstations should be behind a firewall. HIPAA rules also require recording, auditing, and monitoring of any access to PHI data. This means that logging should be enabled on any firewall, whether deployed on-premises or in the cloud. Organizations now combine firewall logs with SIEM systems for centralized visibility and faster threat detection.

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_Set_up_Controls_for_File_Integrity_Monitoring.svg)

### Set Up Controls for File Integrity Monitoring

The cloud user must set up measures that ensure PHI integrity. The organization should have a record of any unauthorized access to PHI and any changes made to the data and should be able to ensure any healthcare data is “authentic”. File integrity monitoring is often paired with automated alerts to detect unauthorized changes immediately.

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_Make_Sure_Encryption_is_in_Place.svg)

### Make Sure Encryption is in Place

End-to-end encryption is mandatory for any data transmitted to or stored in the cloud. Systems should be in place to coordinate encryption keys between on-premise and cloud storage services. Encryption standards commonly include AES-256 for storage and TLS 1.2+ for data in transit, supported by centralized key management.

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_Set_Up_Appropriate_Processes_for_a_Breach_Notification.svg)

### Set Up Appropriate Processes for a Breach Notification

When a data breach has occurred, both the cloud user (the covered entity) and the cloud provider (the business associate) should investigate and report their findings to the OCR. Organizations maintain documented incident response plans with defined escalation paths and reporting timelines.

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_Provide_Training_for_Employees.svg)

### Provide Training for Employees

Any employees who work with protected health information (PHI) or related systems must be aware of the relevant security procedures and what they are and are not allowed to do with the data. An ongoing training program is essential to ensuring HIPAA controls are enforced within the organization.

## How Does HIPAA Affect Cloud Service Providers and Users?

According to HIPAA guidelines, cloud services providers (CSP) are defined as business associates. Organizations now perform ongoing vendor risk assessments instead of relying only on initial compliance reviews. This implies the following requirements with regard to the use of cloud services like those of a cloud storage provider at healthcare organizations:

![](https://www.atlantic.net/wp-content/uploads/2021/08/HIPAA_Compliant_Cloud_Storage_FAQ_HIPAA_Affect.jpg)

- **BAA with the cloud provider**—covered entities may use cloud services to store or process ePHI; however, they must enter a BAA with the cloud service provider.
- **Ensure the CSP is in compliance**—it is not enough to sign a BAA. Covered entities must make sure that the cloud provider complies with all relevant HIPAA regulations.
- **Defining SLAs**—covered entities need to receive a Service Level Agreement (SLA) commitment from their cloud providers which addresses HIPAA requirements like system reliability andavailability, data backup, data recovery, security responsibilities, retention of PHI, disclosure, and more.
- **[Data encryption](https://cloudian.com/guides/secure-data-storage/data-encryption/)**—if the cloud provider stores encrypted PHI without an encryption key, they are still considered a “business associate” and are subject to the same responsibilities for securing the data.
- **Reporting incidents**—when a security incident happens, the cloud provider must report it to the covered entity (cloud user) as soon as the vendor discovers the incident. According to HIPAA, cloud providers are required to detect as well as respond to any security incident. The cloud vendor is also required to mitigate security threats as well as record the details of the incident and its consequences.

## Penalties for Cloud Computing-Related HIPAA Violations

If an organization carries out HIPAA violations, the state Attorney General may impose fines of up to $25,000 per year per category of violation, and the Office for Civil Rights (OCR) can impose fines of up to $1.5 million per year per category of violation. Recent enforcement actions frequently involve misconfigured cloud storage, ransomware exposure, and lack of access controls. Individuals who violate HIPAA can also face fines and criminal penalties of up to 10 years in prison. There were several cases tightly related to cloud services where HIPAA violations resulted in court settlements and large fines, including:

- **Phoenix Cardiac Surgery**—did not enter a business partner agreement with an Internet-based calendar and email service provider. PHI-related information was transmitted using the service.The organization settled its case with OCR for $100,000.
- **University of Oregon Health and Science University**—stored PHI in a cloud service without entering a BAA with the cloud provider. Settled the OCR lawsuit for $2.7 million.
- **St. Elizabeth Medical Center in Brighton, MA**—uploaded PHI to a cloud file-sharing service without assessing the risks and paid $218,000 in fines after a settlement with OCR.

## HIPAA-Compliant File Sharing and HIPAA-Compliant Cloud Storage Services FAQs

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_Is_Security_Awareness_Training_Mandatory.svg)

### Is Security Awareness Training Mandatory?

Yes, it is a mandatory requirement of HIPAA compliance for both covered entities, like healthcare providers, and their business associates to provide training to their employees about HIPAA compliance and the physical safeguards, administrative safeguards, and technical safeguards needed to protect patient data – including when using file-sharing services.

Your staff should know reasonable ways (as with phishing prevention) to guard against the intrusion of malware, and they should understand when it is appropriate and inappropriate to access health data, including as it relates to file-sharing solutions.

In order to prevent non-compliant password sharing, you want to have strong password policies implemented. An organizational culture that respects HIPAA compliance is founded on training that ensures your workforce has strong security knowledge and understands the physical, administrative, and technical safeguards employed to enforce data protection according to the Security Rule and Privacy Rule of HIPAA.

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_How_Do_I_Protect_PHI_Data_in_Transit.svg)

### How Do I Protect PHI Data in Transit? Do I Need to Protect PHI on Mobile Devices, Too?

Preventing unauthorized access to Protected Health Information is of the utmost importance, whether the data is moving or at rest. When considering data-in-transit, protections are critical because mobile devices are increasingly used to send health data and health information exchanges (HIEs). There are two key elements to consider regarding data security in transit:
 There are two key elements to consider:

1. Protect data in transit using security protocols, best practices, and secured systems
2. Encrypt all files in transit containing medical records/health data

To achieve this, each employee has the personal responsibility to consistently encrypt in-transit data, including when it is being sent using file-sharing services. It does not matter if your staff has no encryption expertise or background in data security; training must be provided. This training must explain the “dos and don’ts” when it comes to transmitting PHI and when it is not acceptable. A minimum of AES256 bit encryption must be used and PHI should not be sent via [email unless encrypted first](https://www.paubox.com/blog/hipaa-compliant-email). As mobile tools and mobile platforms are more frequently used to share such sensitive patient information, sensitive files must be encrypted there, too. Covered entities must have policies in place to send a secure file with robust mobile security, including encryption of data in transit and controls on mobile access as with other workstations and devices.

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_How_Do_Protect_Employee_Workstations-.svg)

### How Do I Protect Employee Workstations?

Healthcare organizations must put policies and procedures in place that address how their employees can access and use end-user devices, typically smartphones, tablets, laptops, and workstations. Create policies and procedures that control how media is transferred, decommissioned, thrown out, or reused. All pertinent health data must be destroyed prior to any equipment reuse.Key concerns for this aspect of physical security are:

- the number of individuals who use the workstation; and
- whether it is in a private or public setting.

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_Why_Do_i_Need_Security_Management_Plan.svg)

### Why Do I Need a Security Management Plan?

In order for your staff to properly follow administrative safeguard rules, you will need policies and procedures to support a comprehensive security management approach. A critical aspect of this effort is a risk analysis and management process. Overall, this plan is based on the need to maintain the availability, integrity, and confidentiality of health data.

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_What_Audit_Controls_are_Needed_to_Protect_PHI.svg)

### What Audit Controls are Needed to Protect PHI?

HIPAA compliance requires detailed logging of nearly all aspects of a system that hosts PHI. The logging and analysis of everything that occurs within these systems are essential.

Anyone handling health data, whether a covered entity or business associate, will want to assess what the intervals will be for auditing, the specific processes used to study the ePHI, the location of data for audit results, and the policy for personnel who do not follow guidelines.

Detailed logging to smart SIEM solutions can offload a large amount of the workload to AI, and combining intelligent monitoring, an intrusion protection service, and due diligence creates the best environment to protect and audit sensitive data.

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_How_Do_I_Respond_to_a_File_Sharing_Security_Incident.svg)

### How Do I Respond to a File Sharing Security Incident?

In order to comply with HIPAA, healthcare providers have to know how they will respond to security incidents in advance with documented policies and procedures. A key element is evaluating the spectrum of different incidents that could potentially occur when using HIPAA-compliant file-sharing services.

The procedures should specifically indicate an individual who is the organization-wide point-person to be notified if a security incident occurs (i.e., your HIPAA Security Officer, who may also be your HIPAA Privacy Officer).

Everyone who is working at your organization should know exactly what they need to do in various types of difficult scenarios in order to make sure digital health data is safe no matter the situation.

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_What_Authentication_Methods_Should_I_Use.svg)

### What Authentication Methods Should I Use?

You want robust and thorough steps in place to authenticate secure access to your systems and determine the real identities of all users – this applies to more than just HIPAA-compliant file sharing. MFA, single sign-on (SSO), and centralized identity management are widely used to control access. One such method to achieve this is by using user accounts (such as Active Directory) that have minimum password requirements, lockout capabilities, unique user IDs, and are centrally managed, either in-house or by your MSP.

The budget should be considered alongside training and the actual procedures and protocols that will be utilized. Authentication is necessary so you can determine whether someone has the correct permissions for ePHI or what the source of transmission is. Multi-factor authentication provides the best possible protection to sensitive healthcare data for HIPAA compliance. MFA and two-factor authentication are widely used, and just like it does with mobile banking, MFA will protect access to your secure file transfer accounts. The same principle applies to PHI in a HIPAA-compliant context; MFA helps greatly in protecting PHI when using a secure file transfer tool for HIPAA-compliant file sharing.

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_Establish_Responsibility_Matrix_for_HIPAA_Controls.svg)

### Who Protects Facility Access Controls?

Any facility where HIPAA-compliant file sharing is performed as part of procedures will also need to abide by HIPAA guidelines on access controls.

Separate from the question of HIPAA-compliant file sharing, a facility that is subject to HIPAA regulation can be any physical location that is used to house PHI; this may be a terminal in a hospital, the data centers of your managed services provider, or an employee cell phone. You need to go above and beyond protecting your workstations and devices, all the way to considering the whole building. Do you require a 24×7 security guard presence, CCTV monitoring, and potentially even further physical security measures in the facility?

Ensure your security measures restrict physical access to people without proper authorization. While all of the stipulations for access controls – maintenance records, access validation and control procedures, contingency operations, and a facility security plan – are “addressable” rather than “required,” you still must use any of these elements that you find are appropriate based on analysis of your situation.

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_Set_Up_Appropriate_Processes_for_a_Breach_Notification.svg)

### What Integrity Controls are Needed?

From an administrative perspective, ensuring the integrity of your data (verifying that it is not wrongly destroyed or changed) requires you to establish (via policies and procedures) rules against wrongfully destroying or changing health data.

Consider how to promote data integrity when information is at rest (stored) and in-motion (transmitting). Malicious individuals could threaten the smooth operation of your organization and potentially do severe damage to your finances and reputation. You want to know the extent to which your data’s integrity is protected against manipulation.

Notably, you can best protect your critical information through authentication as achieved via checksum technology, digital signatures, magnetic disks, and error-correcting memory.
 Any analysis of threats to integrity should include a look at outside individuals as well as people who are legitimately working for you but are error-prone or who may become disgruntled.

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_What_Authentication_Methods_Should_I_Use.svg)

### How Do I Control Access to PHI Data?

One of the greatest fundamentals of security is to only give information to the people who are supposed to be able to see it, blocking access to others. A HIPAA-compliant organization must assess the procedures they have deployed (including any that rely on HIPAA file sharing) and add defenses so that they can mitigate inappropriate ePHI access and disclosure of sensitive files.Information access is based on a need-to-know basis: make sure your management plan complies with the minimum necessary stipulations in the HIPAA Privacy Rule.

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_How_Do_I_Protect_PHI_Data_in_Transit.svg)

### **Which File Transfer Programs are HIPAA-Compliant?**

It is not necessarily the program that must be HIPAA-Compliant; rather, it’s critical that the environment where the program is used is abundantly secure. When dealing with PHI, companies must make sure that they are using a HIPAA-compliant file transfer platform to protect the integrity of sensitive data. Priority is given to platforms that provide encryption, audit trails, and integration with identity systems.

HIPAA legislation requires organizations to implement the following to ensure compliance:

- Access control
- Data encryption
- Audit logging
- User authentication
- Data backups and disaster recovery
- Business Associate Agreements (BAA)

![](https://www.atlantic.net/wp-content/uploads/2021/08/icon_Why_Do_i_Need_Security_Management_Plan.svg)

### What is a HIPAA-Compliant Business Associate?

HIPAA compliance goes beyond the above file transfer and HIPAA-compliant cloud storage methods to encompass consideration of your entire ecosystem, including sometimes trusting third parties (business associates) to strengthen your approach. Do you represent a HIPAA-covered entity looking for [HIPAA-compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) for your online healthcare presence, or do you need HIPAA-compliant cloud storage services for your practice or healthcare organization? At Atlantic.Net, over the years, we’ve steadily built a reputation as an exceptional healthcare [HIPAA storage company](https://www.atlantic.net/hipaa-compliant-hosting/), known for demonstrating trustworthiness to our healthcare industry clients and offering a Business Associate Agreement as part of our commitment to maintaining HIPAA compliance for healthcare providers and healthcare organizations who need help protecting PHI.

### Get Help with HIPAA Compliance

Atlantic.Net stands ready to help you attain fast compliance with a range of certifications, such as SOC 2 and SOC 3, HIPAA, and HITECH, all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, [HIPAA web hosting](https://www.atlantic.net/hipaa-compliant-hosting/), HIPAA-compliant cloud storage services, free IT architecture design, and assessment, call 866-618-DATA (3282), or contact our sales team at sales@atlantic.net.

## Your 10-Step HIPAA (Health Insurance Portability and Accountability Act) Checklist

![](https://www.atlantic.net/wp-content/uploads/2021/08/How_to_Be_HIPAA_Compliant_When_Sharing_Confidential_Files_HIPAA_Checklist.jpg)

 

---

#### Read More About HIPAA Compliance

- [HIPAA Compliance Checklist](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/)
- [How to Become HIPAA Compliant](https://www.atlantic.net/hipaa-compliant-hosting/how-to-become-hipaa-compliant/)
- What Is the [HIPAA Security Rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/)?
- Top Considerations for [HIPAA File Storage](https://www.atlantic.net/hipaa-compliant-hosting/top-10-considerations-for-hipaa-compliant-file-storage/)
- Protecting [e-PHI](https://www.atlantic.net/hipaa-compliant-hosting/protecting-phi-cloud/) in the Cloud
- What Is [HIPAA Cloud Computing](https://www.atlantic.net/hipaa-compliant-hosting/what-is-hipaa-cloud/)?
- What Is [Healthcare Hosting](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/)?
- [What Is PHI?](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/)

---

 


---

# HIPAA for Developers: 2026 HIPAA Compliant Developer Guide

> URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-developer-guide/ | Published: 2026-04-24 | Updated: 2026-04-26 | Author: Alexander Wise

If you’re a HIPAA developer, healthcare is a tricky field because there is an additional layer of concern beyond what is needed for the typical website: federal compliance. You need to meet the regulations mandated both by HIPAA and by HITECH.

Developers today must also account for modern architectures such as cloud-native apps, APIs, and distributed systems when handling PHI.

## HIPAA Developers Need to Know The Laws: HIPAA & HITECH

Before we unpack the impact of them on HIPAA developers, we need to understand the very basic function of these two laws; HIPAA was passed in 1996 to allow people to continue coverage when leaving a job or in similar scenarios (portability) and to establish guidelines for healthcare organizations related to safeguard protected health information, or PHI (accountability). HITECH, contained within the American Recovery and Reinvestment Act of 2009 (ARRA), updated some of the HIPAA stipulations and stimulated (through incentives) the adoption of electronic records. Current enforcement places stronger emphasis on how digital systems store, transmit, and audit access to PHI across platforms.

Through the Young Lawyers Division of the American Bar Association1, Kara J. Johnson explained that the core concern of HITECH was to make it easier for authorized providers and other organizations to access your healthcare records. “[H]owever, because of increased concerns associated with electronic records containing protected health information (‘PHI’),” she added, “heightened enforcement and sanctions provisions in the… [HIPAA] Privacy and Security Rules were implemented as well.”

HITECH is the basis of the HIPAA Final Rule2, otherwise known as the HIPAA Omnibus Rule3 or the HIPAA Omnibus Final Rule4. The standard, which went into effect in 2013, expanded direct responsibility under the law to third parties that handle PHI on behalf of healthcare organizations.

## As a Developer, Is HIPAA Relevant to Me?

The two types of organizations that need to meet [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/) are called covered entities (CEs) and business associates (BAs). While a CE must be within one of three categories specified by the HHS – healthcare plans (e.g., insurance carriers), providers (e.g., hospitals), and data clearinghouses – a BA is any company that comes into contact with a healthcare organization’s PHI. **If you’re a developer in a covered entity or a business associate of a covered entity, then yes, HIPAA applies to you.**

Examples of common business associates are shredding companies, [HIPAA compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) firms, and attorneys. Think of any type of service that might come into contact with its clients’ records, and you get the idea of a business associate.

## HIPAA Rules: Privacy, Security, and Breach Notification

Three of the core requirements of HIPAA that are often described in the same breath5 are the Privacy, Security6, and Breach Notification Rules7. All of these standards are within the HIPAA Administrative Simplification Provisions8.

For developers, these rules translate into requirements for data handling, access control, logging, and secure system design.

The HIPAA Privacy Rule is a regulation that must be met by all healthcare providers, plans, and data clearinghouses in the United States – as well as by their business associates – in their treatment of protected health information. It creates national standards that should be used to safeguard electronic health records and other types of confidential medical information. While a huge amount of focus today is put on electronic PHI (ePHI), protected health information must be safeguarded in all its forms and ways it can be communicated, extending to paper, film, and speech. Applications must enforce strict controls on how PHI is accessed, displayed, and shared across users and systems.

In order to defend against potential threats to the privacy of these highly sensitive files, the organizations that are regulated by HIPAA have to take action. First, they must actually set up technical protections for the ePHI (which is the core focus of the Security Rule). Second, CEs and BAs must set up controls, as indicated within policy and procedure documents, to prevent any unauthorized use or disclosure (i.e., anything that goes beyond your written agreement with the patient).

The Privacy Rule also established rights of patients within the United States related to health records. Beyond the broad right to protection of their records, US-based patients have the specific right of access; they can acquire and assess any or all of their records. They also have the right to have any mistakes within the information rectified.

As established above in the need for written agreement, another standard set forth within the Privacy Rule is that patients have to be given a notice of any ways that PHI might be disclosed and used, along with basic information on the responsibilities of the CE and rights of the individual.

*To actually enter the vortex and look at this requirement, see 45 CFR Part 160 and Subparts A and E of Part 164 in the HIPAA Administrative Simplification provisions*9*. You can also potentially make use of the tools and guidance provided through the HHS Privacy Rule Page*10*.*

The HIPAA Security Rule created guidelines with which organizations must safeguard the availability, integrity, and confidentiality of ePHI that is transmitted, maintained, received, or created by a CE or BA. This regulation has been in effect since April 20, 2005, for larger organizations and since April 20, 2006, for smaller organizations. Developers are expected to implement safeguards such as encryption, authentication, and audit logging directly within application architecture.

The Security Rule made it necessary for any organizations handling ePHI to set up defenses in three categories – called administrative, technical, and physical safeguards. The HIPAA regulations established broad needs for healthcare records without usually giving specific directions in terms of technologies, protocols, or methods. When you create launch specifications for a HIPAA-compliant environment, you should include a greater idea of how you intend to meet the demands of HIPAA; to meet compliance, the choices you make should be reasonable and based on industry best practices.

*If you really want to dig into the Security Rule, you can find it in 45 CFR Part 160, as well as in Part 164, Subparts A and C, within the Administrative Simplification provisions*11*. The tools and resources organized on the HHS Security Rule Page*12*may also be useful.*

The Breach Notification Rule13 is one of the other key regulatory concerns for covered entities and business associates. One thing should be clear and will help to explain the relationship between HIPAA and other core federal healthcare law. The Breach Notification Rule was introduced within HIPAA and updated within HITECH. Modern expectations also include rapid detection, internal escalation, and documented response workflows for security incidents.

The Breach Notification Rule established that healthcare organizations had to let any patients know right away when their records had been compromised; HITECH expanded this same requirement to business associates. Scope of a breach impacts the compliant reporting process. When the number of records breached is greater than 500, the breached organization should send notifications beyond those directly to patients) to the Secretary of the HHS and to the media. With any breaches that are considered small (fewer than 500 records) should be sent to the Secretary of the HHS
 once per year. Plus, there is the issue of breach notification communication occurring properly between business associates and covered entities. When a business associate experiences a compromise to the PHI it handles, it must promptly let the covered entity know, in writing, of the incident.

*To look over the regulations within the HIPAA regulations, you can find it in 45 CFR, 400-414 of Part 164 within the Administrative Simplification provisions*14*. The inclusion of business associates as responsible parties related to the need to communicate breaches is described within HITECH*15*, section 13407. You can get additional guidance and assistance through the information and resources on the HHS’s Breach Notification Rule Page*16*.*

Note that related to all of these other rules and other important elements of HIPAA and HITECH, it is necessary that you provide training to all your personnel – which is also in the best interests of your organization in terms of avoiding all the negative consequences of a breach.

## HIPAA Developer Checklist: HIPAA Mobile App Security

Development requirements will be a bit different depending on what type of environment is involved – such as a website, mobile app, or web app. Mobile apps now require stronger protections due to increased use of personal devices and remote healthcare access. There is not enough space in this ebook for comprehensive coverage of steps for all scenarios; however, it helps to get a bit more specific. To that end, we will drill more deeply with checklists for the development of HIPAA-compliant mobile applications and web applications, upping the ante with the granularity in the second of the two. This information should help with healthcare app development, and you certainly want to modify these
 parameters to suit your circumstances. First, to achieve HIPAA-compliant mobile app security, several steps are key, as indicated by mobile app security software firm NowSecure17. The checklist is organized into five sections:

### 1 – Know what your part is in ensuring HIPAA compliance

- You should know the data protections that are needed within healthcare software. A security professional should look over the design to ensure it suits the scenario. You do not need to become an expert on security or healthcare law to create the app, provided you get advice from competent parties.
- Consider the ways that the application will be used. Think about the types of data the software will be processing and the storage environment. Protecting in-transit and at-rest ePHI is key to maintaining compliance, so consider encryption and other security methods of all system components.
- Be aware if there are other laws that are pertinent to the application. You can use the Mobile Health Apps Interactive Tool18 from the Federal Trade Commission (FTC) to automatically determine the regulations that might apply.

### 2 – Reduce your risk

- Think in terms of minimizing the data that you are presenting, accessing, or storing. There is no reason to gather date-of-birth, for instance, unless it really is needed. You should have defined purposes for all personal data you collect.
- Develop an easily understandable privacy policy, and use it consistently. A privacy policy is important with all applications you develop, but it is particularly key to healthcare.
- One of the best ways to reduce your security vulnerability is not to store data that is highly sensitive. Whenever you do not need to store protected health information, do not do it. It is key to ensure that any data you remove from the system is completely wiped. It isn’t impossible to ensure SSD/flash data is completely erased, but it can be difficult if not in control of the systems. By allowing a HIPAA-compliant hosting company to manage the data, the erasure and disposal of sensitive information is taken care of with processes that are already tested and in place.
- It is crucial to consider secure transmission and storage of data when you use cloud technology. For cloud service providers or any other outside contractors, you will need a signed business associate agreement (BAA), as indicated within the HHS’s Guidance on HIPAA & Cloud Computing19.
- Be aware of data related to geolocation. You should not be getting specific about the location of a particular individual if you can help it – which, according to the HHS, means not getting any more specific to exact location than the US state. You might be handling information that does not seem that important or sensitive but that is turned into PHI because of geolocation.

### 3 – Send and store data using appropriate technical safeguards

- Encryption is a standard data security method. App Transport Security (ATS) should be included so that the application has to use HTTPS protocol to communicate with servers rather than the standard HTTP – a method that ensures encryption when data is in motion.
- There are many types of security tools available, and they should be used to keep data safe both when it is being transmitted and stored. Encryption methods allow you to verify data as well, which is another key point within the regulations.
- Consider any text messages, and be certain there is no health data within them since SMS and MMS are built without encryption.
- Do not come up with your own encryption algorithm when you are encrypting local storage. Instead, implement protocols that are already widely used.

### 4 – Set up security protections for the application itself

- You want to have a timeout period established for any local session so that people need to reauthenticate when they are not actively using the app. The determination of a good session timeout should be based on your use case for the app.
- Avoid push notifications. The problem with push notifications is that it is possible they reach the device, and someone other than the patient views it.
- You do not want to allow any leakage of your health information into areas that tend to have poor protections, such as log files. Within an Android device, access is typically problematic and leads to heightened risk because the permissions are often not tightly controlled.
- Use a comprehensive set of security methods that are considered industry standards.

### 5 – Perform security testing

- Security testing should be conducted to verify that everything is protecting the application properly in both static and dynamic contexts.
- Penetration testing through a third party can be a good idea, particularly if the provider has HIPAA expertise.

## HIPAA Developer Checklist: HIPAA Web App Security

There is a checklist for HIPAA developers building HIPAA-compliant web applications provided by the Open Web Application Security Project (OWASP)20. Modern web applications must also address API security, third-party integrations, and cloud infrastructure risks. There is a bit of overlap with the above checklist. However, as stated above, this checklist takes a different approach in getting very detailed with the steps that are advised. It is organized into 11 sections:

### 1 – Gather information

#### Assess the rendered site

- Look over the site.
- Use a spider to mine your data21 and check for any hidden or missing elements.
- Check for data leakage via webserver metafiles, such as .DS_Store, sitemap.xml, or robots.txt.
- Verify that you cannot be accessed through search by checking the caches of prominent engines.
- Verify that content does not differ based on the user, such as a search engine spider vs. mobile.
- Confirm that there is no data leakage22 via webpage metadata and comments.

#### Assess development

- Verify the framework used in the application’s design.
- Fingerprinting of the app.
- Check the implemented technologies.
- Assess user roles.
- Determine points of entry.
- Be aware of client-side scripts.
- Determine all channels or versions of delivery – such as mobile app, mobile web, and web.

### Assess the platform and hosting

- Determine any content that is served by independent parties.
- Assess all ports and hostnames used.
- Figure out what applications are co-hosted.
- Verify all web services system

### 2 – Manage configuration

- See what administrative or application URLs might be implemented that are too common to be secure.
- See what files are unreferenced, backups, or old.
- Confirm all supported HTTP techniques and that Cross Site Tracing (XST)23 is being prevented
- Verify the processing of file extensions.
- Assess your policy to control rich internet application (RIA) cross domain access.
- Confirm that there are secure HTTP headers in place.
- Check policies for all technologies (such as robots, Silverlight, and Flash).
- Determine if there is any confidential information, such as login credentials or API keys, within client-side script.

### 3 – Confirm transmission security

#### Look at encryption and protocols used. **TLS 1.2 or higher is expected for all data transmission involving PHI.**

- See what the key length is, the algorithms that are used, and the SSL version.
- Verify that you have valid digital certificates.
- Confirm that HTTPS is used any time that usernames or passwords are sent.
- Determine that HTTPS is implemented whenever the login form is sent.
- Be sure that HTTPS is in place for delivery of all session tokens.
- Verify the implementation of HTTP Strict Transport Security (HSTS).
- Confirm that requests cannot be forged.
- Assess HTML5 web messaging.
- Confirm the use of CORS, also applicable to HTML5.

#### Assess representational state transfer (REST) and web services

- Verify REST implementation.
- Check for any problems with web services.

### 4 – Verify authentication

#### Determine functionality of the app password

- Confirm that the password quality rules suffice.
- Verify the proper working of remember me.
- Check that recovery and reset options function correctly.
- Check that a password can be changed correctly.
- Make sure the CAPTCHA is functioning properly.
- Confirm proper working order of multi-factor authentication (MFA).
- Verify that logout functions correctly.
- Check for any default logins.
- Verify proper functionality of notifications related to password changes and account lockouts.
- Be certain that your authentication is consistent throughout applications with alternative channels and shared authentication schema/SSO.
- Determine question/answer issues that represent weak security.

#### Assess other functionality concerns with authentication

- Check to see if nefarious parties can successfully enumerate users.
- Determine if authentication bypass can occur.
- Verify your defenses against brute force attacks.
- Confirm that encryption on channels through which credentials are travelling is functional.
- Verify HTTP cache management (such as Max-age, Expires, and Pragma).
- Determine proper working order of any authentication history that is user-accessible.

### 5 – Manage the session

- Determine whether tokens in cookies, token in URL, or another session management method is in place.
- Look for cookie flags with session tokens (both secure and HTTP).
- Confirm the max-age and expiration related to duration of session cookies.
- Following a maximum lifetime, determine that session termination occurs.
- Following a relative timeout, verify that the session terminates.
- Following a logout, verify that the session terminates.
- Check if it is possible to open more than one simultaneous session per user.
- Gauge the randomness of session cookies.
- Confirm that when login, logout, and role changes occur, a new session token is created.
- When there is shared session management for the app, verify that session management is consistently applied.
- Determine if session puzzling is occurring.
- Assess to ensure protection from clickjacking and cross-site request forgery (CSRF)24.

### 6 – Verify that authorization is occurring properly

- Check on path traversal.
- Gauge the system for missing authorization.
- See if insecure direct object references25 are present.
- See if privilege escalation is occurring, which means you need stronger vertical access control.
- See if there are any issues with horizontal access control.

### 7 – Ensure your cryptography is working correctly

- Gauge for any instance of weak algorithms.
- See if algorithms are being utilized correctly based on the appropriate context.
- Assess the randomness functions within your system.
- See that salting is occurring as intended.
- See that encryption is actually occurring to the data.

### 8 – Confirm that data is validated correctly

#### Test for various types of injection

- SQL
- HTML
- LDAP
- ORM
- XML
- XXE
- SSI
- XPath
- XQuery
- IMAP/SMTP
- Code
- Expression language
- Command
- NoSQL

#### Perform additional validation tests

- See if reflected cross site scripting is occurring.
- Check for the occurrence of stored cross site scripting.
- Verify that DOM based cross site scripting is not taking place.
- Gauge the environment for cross site flashing.
- See if overflow is occurring.
- Check for any format string issues.
- Determine if any incubated weaknesses are present.
- See if smuggling or splitting of HTTP is occurring.
- Check if there is verb tampering with the HTTP.
- See if open redirection is occurring.
- Verify that remote file inclusion is not occurring.
- Check to see that local file inclusion is not taking place.
- See that the validation rules for the server-side and client-side are consistent.
- Check to see if parameter pollution is occurring with HTTP.
- See if auto-binding is taking place.
- Gauge for Mass Assignment
- See that NULL/Invalid Session Cookie is functioning properly.
- Check to see that the data integrity is maintained.
- See that work flows are not being circumvented26.
- Verify that you are protected against misuse of the application.
- Confirm that you cannot go beyond the limits of a feature or function.
- Check process timing27 for consistency.
- Related to HTML5, see if web storage SQL injection is taking place.
- Confirm that the application functions properly when it is offline.

### 9 – Check for denial of service (DoS) concerns

Gauge for anti-automation.

See that account lockout28 is working properly.

Verify that SQL wildcard DoS isnot occurring.

Check to ensure that the system is not vulnerable to HTTP protocol DoS.

### 10 – Work directly with functions that make you vulnerable

#### Verify that the uploading of files is secure

- Be certain that only the types of files on your whitelist will upload.
- See that the total file count, upload frequency, and size limits are correctly in place.
- Gauge to see that the file type and contents fit.
- See that anti-virus is implemented for all upload types.
- Verify that malicious files cannot be uploaded.
- Make sure sanitizing is taking place for any problematic filenames.
- Be certain that you cannot get to files you upload through the web root.
- Check to see that the same port/hostname is not serving uploads.
- Make sure that your authorization and authentication systems are being applied to all files you upload.

#### See if there are issues with payment

- Check both the application and server to see if known issues with configuration or weaknesses are present.
- Check to see if passwords are either guessable or default.
- See if buffer overflows are occurring.
- Check to see if there are any weaknesses that might allow injection.
- Determine if insecure cryptographic storage is present.
- Gauge for insufficient protection of the transport layer.
- See that error handling is proper.
- See if there are any weaknesses present that have a score greater than 4.0 according to CVSS v229.
- Determine if there are any problems related to authorization or authentication.
- Gauge the system for CSRF vulnerability.

### Verify correct handling of errors

- Gauge the stack traces.
- See that the error codes are working properly.

## Rooting your development project in a HIPAA-compliant host

That gives you a basic idea of key HIPAA requirements and terminology, as well as specific checklist elements that are important for mobile and web application development. Using the above guidelines, HIPAA developers should be well on their way to a HIPAA-compliant development environment. Developing websites and applications can always be challenging. Simply concerning oneself with usability, it is always possible to make it better. The same is true with privacy and security – and security requires a particularly in-depth exploration when you are handling ePHI.

## HIPAA Developers: Get Help with HIPAA Compliance

[HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) by Atlantic.Net is SOC 2 & SOC 3 certified and HIPAA & HITECH audited, designed to secure and protect critical healthcare data and records. Support now often includes guidance for secure application deployment, monitoring, and compliance validation across cloud environments. Get a free consultation today! Call 866-618-3282 or [contact us online](https://www.atlantic.net/about-us/corporate-contact/#GetStarted).

You can also [download the PDF version of this article, originally published as a whitepaper](https://www.atlantic.net/resources/documents/whitepapers/pdf/hipaa-compliant-it-infrastructure-guide-atlantic-net-whitepaper.pdf).

 

Learn more about our [HIPAA compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions.

## References

[https://www.americanbar.org/](https://www.americanbar.org/groups/young_lawyers/publications/the_101_201_practice_series/hitech_101.html)
 [https://www.hhs.gov/](https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/combined-regulation-text/omnibus-hipaa-rulemaking/index.html)
 [https://www.aaos.org/](https://www.aaos.org/AAOSNow/2013/Jul/managing/managing4/)
 [http://www.physicianspractice.com/](http://www.physicianspractice.com/compliance/two-essentials-hipaa-omnibus-final-rule-compliance)
 [http://www.himss.org/](http://www.himss.org/library/interoperability-standards/security-standards)
 [https://www.hhs.gov/hipaa/for-professionals/](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html)
 [https://www.hhs.gov/](https://www.hhs.gov/sites/default/files/hipaa-simplification-201303.pdf)
 [https://www.hhs.gov/](https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/administrative/combined/hipaa-simplification-201303.pdf)
 [combined/hipaa-simplification-201303.pdf](https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/administrative/combined/hipaa-simplification-201303.pdf)
 [HIPAA for professionals privacy](https://www.hhs.gov/hipaa/for-professionals/privacy/index.html)


---

# Top 15 HIPAA Software Developers in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/top-hipaa-software-developers/ | Published: 2026-04-25 | Updated: 2026-06-24 | Author: Dr. Rachael Bailey

A vast array of software is required to run a successful healthcare organization, and all software developed for this purpose must be fully HIPAA-compliant and hosted on HIPAA-compliant infrastructure. Building software for the healthcare sector now requires a zero-trust-by-default approach to data security, continuous identity verification, and real-time threat detection across users, devices, and cloud environments. In 2026, leading development firms are integrating secure AI workflows, automated compliance monitoring, and granular identity governance directly into patient systems to reduce PHI exposure and audit risk. We have vetted these 14 firms based on their history of HIPAA compliance, technical execution, HITRUST readiness, and their ability to build secure, scalable medical applications.

The Health Insurance Portability and Accountability Act (HIPAA) sets the standard for protecting sensitive patient data. Companies that handle protected health information (PHI) must implement and maintain physical, network, and process security measures to ensure HIPAA Compliance.

HIPAA regulations apply to all healthcare websites and software applications, and developers must comply with the mandatory HIPAA requirements, paying particular attention to how PHI is accessed and which data must be fully encrypted. This includes implementing stringent access controls, audit trails, and data encryption for information both in transit and at rest. Modern implementations also include continuous monitoring, anomaly detection, and automated alerting to identify unauthorized access in real time. Following these rules ensures that all protected health information (PHI) is safely stored, transmitted, and accessed by an application, safeguarding patient privacy and protecting the organization from penalties.

## Why Do You Need Help from a HIPAA-compliant Software Developer?

Because developers must to strict regulations, developing HIPAA-compliant software is a complex and time-consuming process. In 2026, healthcare platforms are also expected to support continuous compliance validation, automated audit readiness, and policy enforcement across distributed cloud systems. Modern healthcare platforms must also implement zero-trust architecture, enforce least-privilege access, maintain detailed audit logs, and align with HITRUST readiness requirements to satisfy enterprise buyers and compliance officers. Choosing a leading software company to develop HIPAA-compliant solutions is essential to meet your healthcare organization’s growing technical needs. You should research your options carefully and work with a [software development company](https://acodez.in/12-best-software-development-methodologies-pros-cons/) that has extensive experience building HIPAA-compliant software solutions — including secure cloud deployments, HIPAA Business Associate Agreement (BAA) signing policies, encrypted data pipelines, and EHR integrations, such as Epic or Cerner, where required.

To help you choose a trusted and experienced partner, we have collated a list of the top 14 [HIPAA-compliant software developers](https://flatirons.com/industries/healthcare/). These are development houses that meet and exceed HIPAA’s physical, technical, and administrative safeguards. Our evaluation also factors in each company’s approach to zero-trust security models, experience with HITRUST-aligned environments, ability to support automated compliance reporting, and transparency around BAA execution. Our evaluation now also considers each company’s ability to support continuous compliance reporting, zero-trust maturity, and secure AI/data processing practices. In compiling our list, we have considered each company’s experience in providing solutions to healthcare providers, reviews from previous clients, and its market presence.

## Leading HIPAA-Compliant Software Developers

The companies below have proven experience building HIPAA-compliant applications with strong security controls and scalable architecture. We evaluated them based on zero-trust maturity, support for automated compliance workflows, secure data handling practices, and EHR capabilities.

![](https://www.atlantic.net/wp-content/uploads/2025/05/arkenea_logo2-1.png)

### 1. Arkenea

[Arkenea](https://arkenea.com/healthcare-software-development/), ranked among the top preferred healthcare software development companies, provides healthcare organizations with reliable, scalable, HIPAA-compliant mobile and web applications. Arkenea is the only software development company that is fully dedicated to the healthcare industry. With more than 9 years of healthcare-focused delivery, Arkenea builds platforms aligned with HIPAA safeguards, HITRUST readiness requirements, and zero-trust security principles to protect PHI across cloud environments. With nearly a decade of healthcare-focused delivery, Arkenea continues to build platforms aligned with evolving HIPAA safeguards and modern zero-trust security expectations.

- **Exclusive Healthcare Focus**: Arkenea dedicates its entire practice to the healthcare sector, ensuring deep domain in building solutions like patient portals, EHR/EMR systems, and practice management software.
- **Regulatory Compliance & Zero-Trust Architecture**: The team embeds HIPAA controls, HITRUST-aligned frameworks, least-privilege access, encryption at rest and in transit, and automated audit logging directly into the software development lifecycle from the initial design phase.
- **Custom Web & Mobile Applications with EHR**: They specialize in creating bespoke, user-friendly applications for both web and mobile platforms, with experience integrating securely with major EHR systems where required, designed to improve clinical workflows and patient engagement securely.

![](https://www.atlantic.net/wp-content/uploads/2025/05/mobisoft-logo.png)

### 2. Mobisoft Infotech

Mobisoft Infotech is a leading software development company specializing in delivering [HIPAA-compliant healthcare solutions](https://mobisoftinfotech.com/services/hipaa-consulting-services) to organizations worldwide. With over 13 years of experience in developing mobile and web applications, Mobisoft Infotech offers end-to-end services from custom software development to testing and maintenance. The company now incorporates advanced identity management, automated audit trails, and policy-driven access controls to strengthen PHI protection across cloud environments. Mobisoft Infotech is committed to creating secure, scalable, and compliant solutions that meet healthcare regulatory standards and align with HITRUST security frameworks. Trusted by healthcare providers and digital health companies, Mobisoft Infotech empowers organizations with solutions that improve patient care and operational.

- **End-to-End Development Services**: Mobisoft Infotech manages the entire product lifecycle, from initial consultation and strategic planning through to development, deployment, and ongoing maintenance and support, embedding security and compliance validation into each phase.
- **Digital Health Solutions**: The company builds applications for telemedicine, remote patient monitoring, and digital therapeutics with strong encryption standards and structured access controls to minimize PHI exposure.
- **Custom Web & Mobile Applications with EHR**: They deliver secure web and mobile healthcare platforms and have experience integrating applications with major EHR systems such as Epic and Cerner when client infrastructure requires interoperability.
- **Global Delivery Model**: With a worldwide presence, they offer flexible engagement models and a structured delivery framework to support healthcare startups, providers, and enterprise organizations.

![](https://www.atlantic.net/wp-content/uploads/2025/05/technology-rivers-logo.png)

### 3. Technology Rivers

[Technology Rivers](https://technologyrivers.com/) is a Virginia-based custom software development firm that specializes in HIPAA-compliant web and mobile app development. The company increasingly focuses on secure-by-design architecture, ensuring compliance controls are embedded early in the development lifecycle rather than added later. Technology Rivers works with healthcare entrepreneurs, startups, and health-tech organizations to create secure and scalable healthcare solutions. The company incorporates zero-trust security architecture, encrypted data flows, and detailed audit logging into its development lifecycle to reduce the risk of PHI exposure. Their work includes native and cross-platform hybrid mobile apps, web applications, desktop applications, and integrations with EMR & EHR systems such as Epic and Cerner.

- **EMR & EHR Specialists**: The company is creating smooth integrations with major electronic health record systems, such as Epic and Cerner, ensuring that new applications operate securely within existing clinical IT ecosystems.
- **Startup and Innovator Focused**: Technology Rivers partners with health-tech entrepreneurs and startups, providing the technical needed to transform concepts into compliant, production-ready healthcare software platforms.
- **Cross-Platform Development with Secure Architecture**: They develop both native and hybrid mobile applications while implementing role-based access controls, encryption at rest and in transit, and structured monitoring to maintain HIPAA-aligned security standards.

![](https://www.atlantic.net/wp-content/uploads/2025/05/novelty-tech-logo.png)

### 4. Novelty Technologies

[Novelty Technologies](https://noveltytechnology.com/) provides end-to-end software solutions for a wide range of clients, including healthcare organizations. Novelty Technologies caters to the entire development lifecycle, from web and mobile app creation and UI/UX design to data analytics and API . The company applies zero-trust security principles, encrypted data management, and structured access controls to protect PHI across cloud-based environments. Novelty has extensive experience working with HIPAA-compliant hosting partners, and security is embedded into its architecture and deployment strategy.

- **Full-Lifecycle Project Management**: Novelty Technologies oversees every stage of development, from initial concept and UI/UX design to backend engineering, API , and analytics , ensuring compliance considerations are addressed throughout.
- **Security-First & Zero-Trust Architecture**: Security is a core component of their development approach, with role-based access, encryption at rest and in transit, and audit logging integrated into applications to meet HIPAA safeguards.
- **EHR & Secure Infrastructure Experience**: The team has experience integrating healthcare applications with major EHR systems, such as Epic and Cerner, as required, and collaborating with HIPAA-compliant hosting providers to deploy secure, resilient solutions.

![](https://www.atlantic.net/wp-content/uploads/2025/05/ZDI-logo.png)

### 5. ZDI

[ZDI](https://zdi.rocks/) is a leading digital marketing company and a proud partner of Atlantic.Net. ZDI has strong ties with HIPAA-compliant organizations and provides several services to healthcare clients, including website and mobile app design, brand creation, and content creation. The company incorporates zero-trust security principles, encrypted data transmission, and structured access controls when developing healthcare websites and applications that may handle protected health information (PHI). ZDI won the GDUSA Health + Wellness Design award in 2017 and has created some excellent web applications for our clients.

- **Healthcare Marketing and Design**: ZDI combines technical development with a strong focus on digital marketing, helping healthcare organizations create a powerful brand presence through compelling web design and content strategy, while maintaining HIPAA-aligned security safeguards.
- **Award-Winning Design Acumen**: As a winner of the GDUSA Health + Wellness Design award, ZDI demonstrates a proven ability to create visually appealing and highly functional web and mobile applications for the health sector.
- **Secure Capabilities**: ZDI can support major EHR systems such as Epic and Cerner when interoperability with clinical platforms is required.
- **complete Service Offering**: Their services extend beyond simple development to include brand creation, patient-facing content development, and strategic marketing, providing a solution for healthcare clients.

![](https://www.atlantic.net/wp-content/uploads/2025/05/lets-talk-logo.png)

### 6. Let’s Talk Interactive

[Let’s Talk Interactive](https://letstalkinteractive.com/) has been doing amazing things for our friends in healthcare before, during, and after the COVID-19 pandemic. Telemedicine has become the first choice for frontline healthcare workers, and Let’s Talk provides HIPAA-compliant teleconferencing services, along with industry-leading virtual and walk-in clinic software, empowering healthcare professionals to conduct remote patient assessments over the phone or via video chat. Their platforms are designed with zero-trust security architecture, encrypted video sessions, identity-based access controls, and structured audit logging to protect PHI across virtual care environments.

- **Telemedicine and Virtual Care Platforms**: They are a leader in providing complete, HIPAA-compliant telehealth solutions, including secure video conferencing and software for managing virtual clinics and patient appointments, built with encrypted data transmission and role-based access controls.
- **Remote Patient Assessment Tools with EHR**: Their software empowers clinicians to conduct remote assessments and integrates with major EHR systems such as Epic and Cerner, where interoperability is required.
- **Proven Pandemic Response**: The company has a proven track record of supporting healthcare providers with reliable, scalable virtual care technology, demonstrating its value during peak demand periods.

![](https://www.atlantic.net/wp-content/uploads/2025/05/mobidev-logo.png)

### 7. MobiDev

[MobiDev](https://mobidev.biz/) is a custom software development company awarded as Best Upwork Software Development Agency 2016-2019. With more than 10 years of complete experience, MobiDev provides HIPAA-compliant mobile and web solutions integrated with the latest technologies: Artificial Intelligence, Machine Learning, the Internet of Things, and Augmented Reality. The company implements a zero-trust security architecture, encrypted data processing, and detailed audit trails to protect PHI across AI-driven and connected health platforms.

- **Advanced Technology with Secure Architecture**: MobiDev embeds AI for diagnostics, IoT for remote monitoring, and AR for clinical applications while implementing role-based access controls and encryption safeguards aligned with HIPAA requirements.
- **Recognized Development Excellence**: With multiple awards for their quality and client satisfaction, MobiDev has established itself as a trusted partner for complex custom software projects in the healthcare domain.
- **EHR Experience**: MobiDev has experience integrating healthcare solutions with major EHR systems, including Epic and Cerner, where interoperability is required.
- **Cross-Domain**: Their decade of experience spans multiple industries, allowing them to bring fresh and approaches to solving unique challenges within healthcare technology.

![](https://www.atlantic.net/wp-content/uploads/2025/05/vairix-logo.jpg)

### 8. VAIRIX Software Development

[VAIRIX Software Development](https://www.vairix.com/) is a nearshore software development company with extensive experience building HIPAA-compliant health and wellness apps. From virtual consultations and e-prescriptions to mental health counseling and support group features, their team of experts crafts products that help your users seamlessly manage their medical needs. Based out of Montevideo, Uruguay (UTC-3), VAIRIX provides staff augmentation and end-to-end development services to clients across the United States. Their development process incorporates zero-trust access controls, encrypted communications, and structured monitoring to reduce PHI exposure risks in cloud-based healthcare systems.

- **Nearshore Development Model**: Based in a US-friendly time zone, VAIRIX offers real-time collaboration and cost-effective development services, making them an ideal partner for American healthcare companies.
- **Health and Wellness App Specialization**: The team has deep in creating consumer-facing applications for managing medical needs, including virtual consultations, e-prescribing, and mental health support platforms.
- **EHR Capabilities**: VAIRIX can support major EHR systems such as Epic and Cerner, where required to ensure interoperability with clinical environments.
- **Flexible Engagement Options**: VAIRIX provides both full end-to-end project development and staff augmentation, allowing clients to either outsource an entire project or supplement their in-house team with skilled developers.

![](https://www.atlantic.net/wp-content/uploads/2025/05/inoxoft.png)

### 9. Inoxoft

[Inoxoft](https://inoxoft.com/industries/healthcare/) is a certified custom healthcare software development company. It offers custom healthcare solutions done by highly skilled professionals with extensive domain. They’ve delivered top-notch medical software for a range of medical service institutions. Their clients include hospitals and healthcare startups, to whom they offer custom medical software development services. They’ll give you new ideas on how to medical care. Building custom healthcare solutions, Inoxoft engineers work with up-to-date technologies such as Python, .Net, Node.js, ReactJS, Flutter, and React Native. The company applies zero-trust security principles, encryption in transit and at rest, and structured audit logging to support HIPAA-aligned healthcare deployments.

- **Certified Domain**: As a certified healthcare development company, Inoxoft brings a high level of professionalism and domain-specific to projects for both established hospitals and startups.
- **Modern Technology Stack**: Their engineers are proficient in a wide range of modern technologies, including Python, .Net, and React, enabling them to build high-performance, scalable, and secure healthcare applications.
- **EHR Experience**: Inoxoft has experience integrating healthcare platforms with major EHR systems such as Epic and Cerner when required by hospital or provider workflows.
- **Client-Centric**: Inoxoft prides itself on empowering clients with new ideas and strategies to technology to improve patient care, streamline operations, and drive better clinical outcomes.

![](https://www.atlantic.net/wp-content/uploads/2025/05/bel-it-soft-logo.jpg)

### 10. Belitsoft

[Belitsoft](https://belitsoft.com/custom-application-development-services/healthcare-software-development) has delivered technology solutions and services to the healthcare industry since 2015. The company focuses on long-term partnerships with its clients from the United States, the UK, Europe, and Israel. Belitsoft’s clients include healthcare startups, medical ISVs, hospitals, healthcare centers, private medical practices, pharmacy organizations, and medical and research laboratories. Belitsoft engages with third-party security auditors, such as OWASP and TrueSec, to guarantee safety and compliance with health IT standards and regulations. The company incorporates zero-trust security architecture, encrypted data handling, and structured audit logging into healthcare applications to support HIPAA-aligned deployments.

- **Third-Party Security Validation**: Belitsoft reinforces its commitment to security by engaging reputable third-party auditors such as OWASP and TrueSec, while embedding role-based access controls and encryption safeguards into its development workflows.
- **Long-Term Partnership Focus**: The company culture is built around forming durable, long-term relationships with clients, ensuring continuous support and the evolution of its software solutions.
- **EHR Experience**: Belitsoft has experience integrating healthcare applications with major EHR systems, including Epic and Cerner, where interoperability is required.
- **Broad Healthcare Clientele**: They serve a diverse spectrum of the healthcare ecosystem, including hospitals, private practices, research labs, and pharmacies, giving them an understanding of the industry’s needs.

![](https://www.atlantic.net/wp-content/uploads/2025/05/tatvasoft-logo.png)

### 11. TatvaSoft

[TatvaSoft](https://www.tatvasoft.com/industries/healthcare-software-solutions) specializes in healthcare software development with over 18 years of experience developing custom software applications. They create HIPAA-compliant web, desktop, and mobile app solutions. They offer a broad spectrum of healthcare solutions, including EHR systems, telemedicine, and medical health applications for both patients and healthcare management professionals. TatvaSoft applies zero-trust access models, encryption at rest, and detailed monitoring controls to reduce PHI exposure across platforms.

- **Multi-Platform Development with Secure Architecture**: TatvaSoft has deep in creating integrated solutions across web, desktop, and mobile platforms while implementing structured access controls and audit-ready systems.
- **Wide Range of Healthcare Solutions**: Their portfolio includes everything from complex Electronic Health Record (EHR) systems to user-friendly telemedicine platforms and practice management tools, underscoring their versatility.
- **EHR Interoperability Capabilities**: TatvaSoft can support major EHR systems, including Epic and Cerner, enabling secure data exchange for healthcare providers.
- **Decades of Experience**: With over 18 years in the custom software industry, TatvaSoft brings a wealth of experience and a mature development process to every healthcare project it undertakes.

### ![](https://www.atlantic.net/wp-content/uploads/2025/05/sciencesoft.png)

### 12. ScienceSoft

[ScienceSoft](https://www.scnsoft.com/healthcare/services) is an ISO 13485:2016, ISO 9001:2015, and ISO 27001:2013 certified IT consulting and software development company with 20+ years of healthcare IT experience, headquartered in McKinney, Texas, US, with offices in Europe and the Middle East. Experienced in HIPAA-compliant software development, ScienceSoft delivers software to leading healthcare organizations. The company incorporates zero-trust security principles, encrypted data governance models, and structured compliance monitoring into its healthcare IT solutions.

- **Multiple ISO Certifications**: ScienceSoft’s adherence to major ISO standards for quality management, medical devices, and information security demonstrates a formal commitment to the highest levels of quality and security.
- **Deep Healthcare IT Consulting**: With over 36 years of experience in artificial intelligence, the company delivers expert healthcare IT consulting and software development, applying advanced AI technologies to optimize clinical workflows, patient care, and strengthen technology strategy.
- **EHR**: ScienceSoft has experience integrating healthcare applications with major EHR systems, including Epic and Cerner, to ensure secure interoperability across clinical systems.
- **Mature PMO Excellence**: ScienceSoft’s dedicated PMO ensures predictable and compliant delivery of healthcare IT projects through proven governance, proactive risk management, and full transparency across scope, timelines, and budgets.

### ![](https://www.atlantic.net/wp-content/uploads/2025/05/ITcraft.png)

### 13. IT Craft

[IT Craft](https://itechcraft.com/) is a leader within the software development industry, having recently been recognized as the “Top Web Developers, 2020” by Clutch, an independent research company based in Washington D.C. What sets IT Craft apart is its commitment to support clients through the completion of their project and beyond, providing all of its partners with high-quality post-launch support. This custom medical software provider delivers the development of new healthcare-related mobile and web applications, as well as the improvement and performance of existing applications. IT Craft incorporates zero-trust security architecture, encrypted communications, and structured access management to support HIPAA-aligned healthcare deployments.

- **Post-Launch Support Commitment**: IT Craft distinguishes itself with a strong focus on long-term partnerships, providing complete post-launch support and maintenance to ensure applications remain secure and effective over time.
- **Award-Winning Development Team**: Recognition as a top developer by industry research firms such as Clutch validates their technical skills and ability to deliver high-quality web and mobile applications for their clients.
- **EHR Experience**: IT Craft has experience integrating healthcare applications with major EHR systems, including Epic and Cerner, where interoperability with existing clinical infrastructure is required.
- **New and Legacy System**: They are skilled in building new healthcare applications from scratch and modernizing, improving, and optimizing legacy software systems for better performance.

![](https://www.atlantic.net/wp-content/uploads/2026/02/LeewayHertzLogo.png)

### 14. LeewayHertz

[LeewayHertz](https://www.leewayhertz.com/) is a custom software development company that creates HIPAA-compliant healthcare apps for both startups and large healthcare organizations. They have built secure digital health platforms, patient engagement tools, and AI-powered healthcare apps. LeewayHertz uses zero-trust security, encrypted data storage, and structured audit controls to protect patient health information in cloud-based healthcare systems.

- **Healthcare Software Development**: LeewayHertz develops custom web and mobile healthcare solutions, including telehealth platforms, remote patient monitoring systems, and clinical workflow applications.
- **Secure AI & Data Architecture**: The company adds AI-driven features and uses role-based access controls, encryption for data in transit and at rest, and monitoring tools that meet HIPAA security standards.
- **EHR Experience**: LeewayHertz has experience connecting healthcare platforms to major EHR systems, including Epic and Cerner, enabling interoperability with clinical environments.
- **Enterprise & Startup Support**: They work with both new health-tech startups and established healthcare providers, offering scalable software solutions that meet compliance requirements.

 

### ![](https://www.atlantic.net/wp-content/uploads/2026/04/2026-05-27-09_26_42-Greenshot.png)

### **15. TATEEDA**

TATEEDA is a San Diego-based custom healthcare software development company helping U.S. healthcare, biotech, pharma, and medical staffing organizations build HIPAA-compliant web, mobile, cloud, and AI-assisted software. Since 2013, TATEEDA has delivered patient portals, EHR/EMR integrations, healthcare mobile apps, remote patient monitoring systems, medical billing platforms, pharma automation tools, and software for large healthcare operations. TATEEDA’s experience includes large-scale healthcare staffing platforms with high-volume workflows, regulated data, and complex user roles across administrators, clinicians, and field staff.

- **Healthcare and Life Sciences Focus:** TATEEDA works with healthcare providers, healthtech startups, biotech companies, pharma businesses, laboratories, and medical staffing platforms to build systems for patient engagement, clinical operations, billing, remote monitoring, data capture, and workflow automation.
- **HIPAA-Compliant Architecture and Secure Development:** The team builds software with HIPAA, CCPA, GDPR, PCI DSS, role-based access, encrypted data flows, audit logging, and secure API in mind from the planning stage, rather than treating compliance as a late add-on.
- **Custom Web & Mobile Applications with EHR/EMR****:** TATEEDA develops web portals, mobile apps, internal platforms, AI-assisted healthcare workflows, and API-connected systems that integrate with EHR/EMR environments, FHIR/HL7 data exchange, billing tools, lab systems, and cloud infrastructure.

## HIPAA-Compliant Developer Comparison (2026)

 

 

| Developer | BAA Signing Policy | HITRUST Certification | Epic Experience | Cerner Experience |
| --- | --- | --- | --- | --- |
| Arkenea | Works with compliant hosting partners; BAA support available where required | HITRUST-ready; certification status should be verified per engagement | Yes | Yes |
| Mobisoft Infotech | Supports HIPAA-aligned deployments; BAA facilitation through infrastructure partners | Supports HITRUST-aligned environments | Yes | Yes |
| Technology Rivers | HIPAA-compliant development; BAA support depends on hosting configuration | No | Yes | Yes |
| Novelty Technologies | Works with HIPAA-compliant hosting providers; BAA depends on the infrastructure partner | No | Yes | Yes |
| ZDI | BAA support is dependent on hosting/infrastructure selection | No | No | No |
| Let’s Talk Interactive | HIPAA-compliant telehealth services; BAA is typically provided for healthcare clients | No | Yes | Yes |
| MobiDev | HIPAA-aligned deployments; BAA dependent on infrastructure environment | No | Yes | Yes |
| VAIRIX Software Development | BAA support is dependent on the client’s infrastructure setup | No | Yes | Yes |
| Inoxoft | Supports HIPAA-compliant environments; BAA dependent on hosting provider | No | Yes | Yes |
| Belitsoft | HIPAA-aligned development; BAA dependent on hosting configuration | No | Yes | Yes |
| TatvaSoft | HIPAA-compliant solutions; BAA dependent on infrastructure partner | No | Yes | Yes |
| ScienceSoft | HIPAA-compliant services; BAA available for healthcare engagements | No | Yes | Yes |
| IT Craft | HIPAA-aligned development; BAA dependent on hosting provider | No | Yes | Yes |
| LeewayHertz | Supports HIPAA-ready deployments; BAA dependent on infrastructure partner | No | Yes | Yes |
| TATEEDA | Builds HIPAA-compliant healthcare software; BAA support should be confirmed per engagement and hosting arrangement | No | No | No |

## How Can Atlantic.Net Help?

The rapidly evolving field of healthcare technology can be a minefield for many healthcare professionals looking for compliant software solutions. With an ever-increasing workload, medical professionals are embracing new cloud-based platforms to improve the quality and speed of patient care. While technological advances can make life much easier for already stretched medical staff, ensuring the safety and security of confidential patient information can bring a new headache. Modern healthcare environments now require zero-trust network controls, encrypted storage, continuous monitoring, and detailed audit logging to properly safeguard PHI in the cloud.

As a healthcare provider, no matter which software solution you purchase, you must choose a fully [HIPAA-compliant hosting platform](https://www.atlantic.net/hipaa-compliant-hosting/) that prioritizes security, privacy, and compliance to host the application. Atlantic.Net provides HIPAA-ready cloud infrastructure with encrypted data at rest and in transit, role-based access controls, secure backup options, and support for BAAs (BAAs). Atlantic.Net can offer you fully scalable, customizable cloud hosting solutions to meet your organization’s needs. [Contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) to find out how Atlantic.Net can help your organization.


---

# 8 of the Most Popular Machine Learning Tools in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/8-of-the-most-popular-machine-learning-tools/ | Published: 2026-04-25 | Updated: 2026-04-26 | Author: Richard Bailey

Today, machine learning workflows prioritize not just model accuracy but also deployment speed, reproducibility, and efficient GPU utilization across distributed systems. In 2026, leading tools emphasize end-to-end pipelines that move seamlessly from experimentation to scalable production environments. Libraries like PyTorch and TensorFlow remain industry staples, but newer workflows prioritize automation, reproducibility, and production readiness.

This guide analyzes the machine learning tools that data scientists and ML engineers use most in 2026. We focus on platforms actively used in production environments, where reliability, scalability, and integration matter more than experimentation alone. For each tool, we cover strengths, weaknesses, and factors to weigh before choosing it for your next deployment.

## Ease of Use vs. Performance Comparison

This comparison highlights how each machine learning tool balances developer friendliness against scalability and raw performance in real-world, production-focused workflows.

| Tool | Ease of Use | Performance at Scale | Production Readiness | Best Fit |
| --- | --- | --- | --- | --- |
| Scikit-learn | High | Low–Medium | Medium | Classical ML, baselines |
| TensorFlow 2.x | Medium | High | Very High | Enterprise deployment |
| PyTorch 2.x | Medium–High | High | High | Research → production |
| Keras | Very High | Medium | Medium | Rapid prototyping |
| MLflow | Medium | N/A | Very High | MLOps & lifecycle |
| NVIDIA cuML | Medium | Very High | High | GPU-accelerated ML |
| Apache Mahout | Low | High | High | Distributed data mining |
| AutoGluon | Very High | Medium–High | Medium | Automated ML |

## What Defines a Machine Learning Tool?

Machine learning tools (ML tools) are the software kits developers use to build, test, and analyze artificial intelligence models. They now commonly include capabilities for experiment tracking, deployment orchestration, and monitoring in addition to core modeling functions. They provide fundamental components in one place, ranging from prebuilt algorithms and data-cleaning utilities to methods for evaluating model performance.

Modern ML tools increasingly act as integrated platforms rather than standalone libraries, supporting the full lifecycle from data ingestion to inference. They enable systems that learn from examples and the complex trial-and-error learning used in robotics. Whether for analyzing customer data or generating images from text, these tools provide the core foundation needed to complete the task.

## Top ML Tools for 2026

While many machine learning tools exist, a small group has become the standard for professional use. These tools stand out in 2026 due to their ability to integrate with cloud-native infrastructure, support large models, and handle real-time inference workloads. This guide explains the key features of these top tools to help you determine which one fits your project requirements.

### #1: Scikit-learn

![](https://www.atlantic.net/wp-content/uploads/2025/08/scikit-logo.png)

Scikit-learn is an open-source software library for the Python programming language. It is recognized for its broad set of machine learning algorithms. The library is built on top of other Python libraries such as NumPy and SciPy. It is designed for classic data mining and data analysis.

Despite the rise of deep learning frameworks, Scikit-learn remains widely used in 2026 for fast experimentation, interpretable models, and structured data problems.

#### Pros

- The platform offers a wide range of supervised and unsupervised learning algorithms, including versatile support vector machines for reliable classification and anomaly detection.
- Efficient tools are included for data preprocessing and model evaluation.
- Extensive documentation and a large data science community offer strong support.
- It is interoperable with the scientific Python ecosystem.

#### Cons

- It is not optimized for deep learning or building neural networks.
- Performance can be slow when processing large datasets without acceleration.
- A graphical user interface is not natively supported.

**Ideal For:** Scikit-learn is ideal for individuals beginning their supervised learning journey, including those interested in computer vision . It is also well-suited for academic research and for building baseline models for problems not requiring deep learning.

### #2: TensorFlow

![](https://www.atlantic.net/wp-content/uploads/2025/08/TensorFlow_logo.png)

Developed by Google, TensorFlow is a complete, open-source platform for building and deploying large-scale deep learning models into production environments, from cloud platforms to mobile devices.

In 2026, TensorFlow continues to evolve with stronger support for production pipelines, edge deployment, and optimized inference across diverse hardware environments.

#### Pros

- Distributed computing is supported for model training on large datasets.
- reliable options for model deployment are offered across servers, mobile devices, and web browsers.
- The ecosystem includes powerful visualization tools like TensorBoard for model inspection.
- Its flexible architecture is suitable for building complex algorithms and deep neural networks.

#### Cons

- The learning curve can be steep for new users.
- The static computation graph in older versions can feel less intuitive for rapid development.
- Significant computational power is needed for training complex models.

**Ideal For:** TensorFlow is built for production-grade AI models and large-scale enterprise applications. It is a strong choice for projects that require dependable deployment solutions, especially those using google cloud’s services.

### #3: PyTorch

![](https://www.atlantic.net/wp-content/uploads/2025/08/Pytorch_logo.png)

PyTorch was developed by Meta AI’s research lab, and it is particularly effective for building deep learning models . It is another leading open-source machine learning framework. It is known for its flexibility and Python-first design, making it popular in the research community for deep learning.

By 2026, PyTorch has become a strong production contender, with improved deployment tooling and tighter integration with scalable infrastructure.

#### Pros

- A dynamic computation graph is used, which offers more flexibility during the model training process.
- The API is considered intuitive and easy to use, providing a more Pythonic experience.
- A strong and active community contributes to a growing number of tools and libraries.
- Rapid development and experimentation are facilitated.

#### Cons

- Model deployment tools were historically not as mature as TensorFlow’s, though this gap is closing.
- Native visualization tools are not as tightly integrated.
- More manual configuration can be required for production environments.

**Ideal For:** PyTorch is preferred by data scientists in research and development. It is excellent for projects in natural language processing and computer vision that involve custom model architectures.

### #4: Keras

![](https://www.atlantic.net/wp-content/uploads/2025/08/keras-logo.png)

Keras is an open-source library that acts as a high-level API for data visualization and artificial intelligence, enabling users to train models with minimal effort. It is designed to enable fast experimentation and to create machine learning models with minimal effort. The newest version, Keras 3.11.1, is multi-backend, which means it can run on top of TensorFlow, PyTorch, or JAX.

Its multi-backend flexibility is especially valuable in 2026, as teams increasingly switch between frameworks depending on workload requirements.

#### Pros

- A very user-friendly interface is provided to simplify the process of building machine learning models.
- Excellent documentation and a focus on user experience reduce the learning curve.
- Multi-backend support allows for greater flexibility and model portability.
- A selection of pre-built models is available for common tasks like object detection.

#### Cons

- Less granular control is offered compared to using a backend framework directly.
- Debugging can be more complex since issues may originate in the underlying backend.
- It is primarily focused on deep learning and not general-purpose ML tasks.

**Ideal For:** Keras is excellent for beginners in deep learning. It is also a powerful tool for rapid prototyping of AI models and for teams that need to train models quickly without deep technical expertise.

### #5: MLflow

![](https://www.atlantic.net/wp-content/uploads/2025/08/MLflow-logo.png)

MLflow is an open-source platform for managing the entire machine learning workflow and lifecycle. It was started by Databricks. It is designed to work with any ML library and language, making it a versatile tool for MLOps.

In 2026, MLflow is widely used as a standard layer for experiment tracking, model registry, and deployment coordination across teams.

#### Pros

- Experiments, code, and machine learning data are tracked to organize complex projects.
- Code is packaged in a reproducible format to ensure consistent results.
- A central model registry is included for versioning and managing learning models.
- The process of model deployment to various production environments is simplified.

#### Cons

- An additional tool is introduced into the technology stack, which can increase complexity.
- The user interface can become cluttered when managing many experiments.
- Disciplined adoption by the entire team is required for it to be effective.

**Ideal For:** MLflow is best for data science teams working on collaborative machine learning projects. It is also suited for enterprises that require governance, reproducibility, and a clear path to deploy high-quality models.

### #6: NVIDIA cuML

![](https://www.atlantic.net/wp-content/uploads/2025/08/nvidia-logo.png)

NVIDIA cuML is a library of machine learning algorithms that leverages NVIDIA GPUs, making it particularly useful for handling various machine learning tasks. It is part of the RAPIDS suite of software libraries. It provides a Scikit-learn-like API, which enables users to take advantage of GPU acceleration for big data processing.

GPU acceleration is no longer optional for many workloads in 2026, making cuML increasingly relevant for teams working with large-scale datasets.

#### Pros

- Significant performance gains are achieved for model training on large datasets.
- A familiar API reduces the learning curve for data scientists already using Scikit-learn.
- End-to-end data pipelines, from ETL to training, can be executed on GPUs.
- It integrates with other data science and deep learning frameworks, including those for predictive analytics.

#### Cons

- Specific NVIDIA GPU hardware is required.
- The library does not yet have coverage for all machine learning algorithms found in Scikit-learn.
- The environment setup can be more complex than CPU-only libraries.

**Ideal For:** cuML is designed for organizations that have access to NVIDIA GPUs and need to accelerate their data science workflows. It is particularly useful for handling various ML tasks that are too large or slow for traditional CPU-based tools.

### #7: Apache Mahout

![](https://www.atlantic.net/wp-content/uploads/2025/08/mahout-logo.png)

Apache Mahout is an open-source project designed to provide scalable machine learning algorithms for data mining tasks that run on distributed computing platforms. It is heavily focused on collaborative filtering, clustering, and classification, and is built to integrate with big data technologies like Apache Spark.

Its role in 2026 is more specialized, often supporting legacy systems or highly distributed recommendation engines within big data ecosystems.

#### Pros

- Designed for massive scalability to handle enterprise-level datasets.
- Provides proven, powerful algorithms for building recommendation engines.
- As an Apache project, it is fully open-source and vendor-neutral.
- Its modern architecture allows it to use engines like Spark for efficient processing.

#### Cons

- Requires familiarity with distributed systems, which comes with a steep learning curve.
- The setup and configuration are more complex than standalone libraries.
- It is a specialized tool not intended for general-purpose ML or deep learning.

**Ideal For:** Apache Mahout is built for large-scale data mining, particularly for companies creating sophisticated recommendation systems. It is best suited for teams already invested in the Apache big data ecosystem.

### #8: AutoGluon

![autogluon](https://www.atlantic.net/wp-content/uploads/2026/02/autogluon.png)

AutoGluon is an open-source AutoML tool that helps users get strong predictive results with little manual work. It works with tabular data, time series, text, and images, and automatically handles model selection, feature processing, and ensembling. In 2026, teams value AutoGluon because it quickly turns raw data into ready-to-use models, making it easier to get good results without spending much time on hyperparameter tuning.

AutoML adoption continues to grow in 2026 as teams look to reduce development time and make machine learning accessible to non-specialists.

#### Pros

- Offers automated model training, tuning, and ensembling right from the start.
- Performs well on tabular datasets and requires minimal setup.
- Supports various data types, including tabular, time-series, text, and image data.
- Helps save time by reducing manual testing and setup work.

#### Cons

- Gives you less transparency and control than building models by hand.
- Can be harder to use custom architectures or make specific optimizations.
- Automated ensembling can consume significant computing resources.

**Ideal For:** AutoGluon is a good choice for teams that need accurate models quickly, such as analysts, data scientists, or product teams working on tight deadlines. It works best for business data in tables, where speed and reliability are more important than custom model design.

## Powering Your ML Tools with the Right Hardware

The most powerful machine learning software is only as effective as the hardware it runs on. For modern deep learning, CPUs are often no longer sufficient. The parallel processing of NVIDIA GPUs has become the industry standard for training complex models.

In 2026, GPU usage has expanded further with support for large language models, real-time inference, and multi-node distributed training.

This is where GPU hosting comes in. Instead of incurring the high capital expense and maintenance overhead of buying dedicated servers, services like [Atlantic.Net GPU Hosting](https://www.atlantic.net/gpu-server-hosting/) allow you to rent access to GPU-enabled hardware on demand.

Cloud-based GPU access is now a common default, enabling teams to scale experiments quickly without upfront infrastructure investment.

This approach enables any developer or organization to:

- Access enterprise-grade NVIDIA GPUs instantly.
- Scale computational resources up or down based on project needs.
- Avoid hardware maintenance and focus solely on building models.
- Pay only for the resources you use, making modern AI more accessible.

## Choosing the Best Machine Learning Tools

The best tool is always the one that fits the job. Scikit-learn is your go-to for foundational tasks. When you need to build scalable, production-ready deep learning systems, TensorFlow and PyTorch are the dominant choices.

To maintain consistency across a collaborative project, MLflow is vital. If speed on massive datasets is the primary bottleneck, NVIDIA cuML paired with our NVIDIA GPU hardware remains the most effective solution. For teams that want results with minimal manual tuning, AutoGluon provides an accessible path, while Apache Mahout offers a scalable option for distributed environments.

As machine learning systems grow more complex, selecting tools that integrate well with your infrastructure is just as important as model performance.

By understanding these core strengths, you can build better, faster AI solutions. New developments in generative AI, multimodal models, and real-time analytics continue to influence how these tools are used in 2026. Understanding these key features allows you to make an informed decision for your machine learning journey today.

Ready to stop waiting and start building? Power up your ML workflows by deploying a high-performance GPU server from Atlantic.Net. [Get started in minutes](https://cloud.atlantic.net/?page=userlogin) and give your tools the hardware they deserve.


---

# Fastest-Growing AI Startups to Watch in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/fastest-growing-ai-startups-to-watch/ | Published: 2026-04-25 | Updated: 2026-04-26 | Author: Richard Bailey

The artificial intelligence market is entering a new phase in 2026. AI adoption in 2026 is being driven more by real business outcomes than experimental capability. Investors and business leaders are focusing less on general-purpose models and more on AI agents designed for specific tasks. Demand is highest in fields where errors can have legal, financial, or safety consequences, like software development, legal services, healthcare, security, and customer support.

The most successful startups are not competing to build the biggest models or top public benchmarks. Instead, they aim to cut expensive manual work in regulated industries. These companies build AI tools for one main job, train them with industry-specific data, and use them where accuracy and control are crucial. Enterprises are prioritizing tools that integrate directly into existing workflows rather than standalone AI products. Businesses are adopting these tools because they deliver clear results, such as faster task completion and lower costs.

This article features AI startups with the fastest growth and most funding as 2026 begins. These companies work in different regions and show where businesses are investing in AI this year. The focus has shifted toward companies that can demonstrate production deployment, not just technical capability. Many are already well-known, but the key question is which ones will keep growing and become lasting leaders as AI is used more in real-world operations. more

## The Rise of Generative AI and New Models

The rise of generative AI and powerful large language models (LLMs) is the main driver behind a new generation of AI startups. Access to new models and advanced algorithms is accelerating the pace of AI development, allowing founders to build highly focused AI applications that solve specific problems.

In 2026, the shift is toward production-ready AI systems that can reliably operate inside existing business workflows, not just experimental tools.

While much of the public focus has been on digital applications like content generation and code completion, a new trend is emerging: the application of AI to solve challenges in the physical world. This includes areas like robotics, industrial systems, and real-time monitoring where AI directly impacts operations. Startups are increasingly deploying sophisticated AI systems to collect and analyze data from critical infrastructure, providing insights for industries that form the backbone of society.

There are a huge number of startups that are using AI to develop new technology, trying to create the next best thing. However, in 2026, differentiation is increasingly based on domain expertise and data access rather than model size. Tech companies are giving early access to new platforms to gather real-time feedback to speed up the development process, resulting in updates that offer real value, high accuracy, and up-to-date information.

## Top AI Startups in 2026

The following startups represent some of the most promising ventures in the artificial intelligence industry. This list highlights seven businesses that are poised to make significant contributions to our daily lives over the coming years. They are chosen based on funding, technological innovation, and their potential impact on various industries.

## Vertical AI Agents

Vertical agents are built to perform defined job functions (e.g., software engineering tasks, legal drafting workflows, patient outreach) rather than act as general-purpose assistants. Buyers evaluate them on domain fit, workflow integration, and risk controls.

### Coding Agent

#### 1. Cognition (Devin)

![Cognition_AI](https://www.atlantic.net/wp-content/uploads/2026/02/Cognition_AI.png)

Cognition created Devin, an AI tool that works as an autonomous software engineer. Devin follows high-level instructions, writes and updates code in entire repositories, runs tests, and submits pull requests with little supervision. Teams are increasingly testing Devin in controlled production environments rather than just experimental use cases. Teams mostly use it for routine engineering tasks, allowing developers to spend more time on design and problem-solving.

##### Advantages

- Able to plan and execute multi-step development tasks from start to finish.
- Handles work across repositories, testing, and pull requests without needing frequent instructions.
- Helpful for repetitive engineering tasks like fixing bugs, refactoring code, and building internal tools.

##### Disadvantages

- Needs a thorough review before merging code.
- Not as effective when product requirements are unclear.
- How well teams adopt Devin depends on their comfort with letting an AI work independently.

#### 2. Cursor

![](https://www.atlantic.net/wp-content/uploads/2025/08/cursor-logo.png)

Cursor is an AI-first code editor created to accelerate software development. The platform is built as a fork of VS Code and is designed to allow developers to build software in partnership with artificial intelligence. It reflects the broader shift toward AI-native development environments in 2026. It enables complex tasks like editing, debugging, and understanding large codebases through natural language commands.

This is the Cursor editor, built for developers who want faster coding with built-in AI-powered suggestions and automation.
 ![cursor](https://www.atlantic.net/wp-content/uploads/2025/02/cursor.png)
 Image Source: Cursor

##### Advantages

- Deep integration of AI tools directly into the editor workflow.
- Ability to reason across an entire codebase for more accurate suggestions and edits.
- Significant time savings on tasks like writing boilerplate code, debugging, and documentation.

##### Disadvantages

- Can be resource-intensive compared to traditional code editors.
- Requires developers to adapt their workflow to a new, conversational style of coding.
- It is a proprietary platform built on an open-source foundation, which may be a concern for some organizations.

Ideal for: Developers and engineering teams who want to maximize their productivity and adopt an AI-native approach to writing and maintaining software. It is especially useful for working in and getting up to speed on large, unfamiliar codebases.

### Legal AI

#### 3. Harvey

![Harvey AI](https://www.atlantic.net/wp-content/uploads/2026/02/Harvey-AI.png)

Harvey creates AI tools designed for legal work. These tools are trained to understand case law, contracts, and legal reasoning. They help with research, drafting briefs, and answering legal questions specific to each firm. Law firms are increasingly integrating tools like Harvey into internal knowledge systems rather than using them as standalone tools.

Use Harvey to simplify legal work, connect your data sources, ask questions, and generate accurate, context-aware outputs in seconds.
 ![harvey ai](https://www.atlantic.net/wp-content/uploads/2025/02/harvey-ai.png)
 Image Source: Harvey

##### Advantages

- Made for legal professionals.
- Helps save time on research and drafting.
- Uses legal data that fits how firms work.

##### Disadvantages

- Needs review by experienced legal professionals.
- Not meant for use outside legal work.
- The quality depends on how current and detailed the firm’s data is.

**Best fit:** Firms with repeatable document workflows and strong knowledge-management practices.

#### 4. EvenUp

![EvenUp](https://www.atlantic.net/wp-content/uploads/2026/02/EvenUp.png)

EvenUp helps automate parts of the personal injury claims process. It reviews medical records, bills, and case materials to estimate damages and create reports. Plaintiff-side law firms and claims specialists use it to reduce manual work and speed up case preparation. The company announced a [$150M Series E](https://www.evenuplaw.com/blog/evenup-2b-valuation/) investment in October 2025

Get a complete view of your case with EvenUp, analyze treatment timelines, review billing summaries, and manage documentation efficiently.
 ![evenuplaw](https://www.atlantic.net/wp-content/uploads/2025/02/evenuplaw.png)
 Image Source: EvenUp

##### Advantages

- Cuts down on manual document review for claims cases.
- Creates organized estimates and reports.
- Helps firms handle more cases at once.

##### Disadvantages

- Needs a person to review results before filing or settling a case.
- It mainly works for personal injury cases, so it has limited use in other areas.
- How accurate it is depends on the quality of the original records.

### Healthcare AI

#### 5. Hippocratic AI

![Hippocratic AI](https://www.atlantic.net/wp-content/uploads/2026/02/Hippocratic-AI.jpeg)

Hippocratic AI creates voice-based AI tools to support patient outreach, follow-ups, and care coordination. In 2026, healthcare providers are focusing on safe deployment and patient trust when rolling out AI communication tools. These tools are made for clinical settings to improve communication with patients and reduce administrative work.

Use Hippocratic AI to streamline healthcare workflows, build AI agents, and track performance across real-world clinical use cases.
 ![Hippocratic AI](https://www.atlantic.net/wp-content/uploads/2025/02/Hippocratic-AI.png)
 Image Source: Hippocratic

##### Advantages

- Automates routine communication with patients.
- Helps clinicians spend less time on administrative calls.
- Works across different languages and schedules.

##### Disadvantages

- Needs clinical staff to oversee its use.
- Does not replace trained medical professionals.
- Response quality can change depending on how patients speak.

**Best fit:** Clinics and hospitals needing faster language access for routine encounters.

#### 6. Opalite Health

![Opalite Health](https://www.atlantic.net/wp-content/uploads/2026/02/Opalite-Health.png)

Opalite Health offers live medical interpretation with AI for situations where patients and providers speak different languages. Demand for multilingual healthcare AI tools continues to grow in 2026 due to global patient diversity.

##### Advantages

- Helps doctors and staff communicate in multilingual settings.
- Cuts down on delays from scheduling human interpreters.
- Operates in real time during patient consultations.

##### Disadvantages

- Does not fully replace professional medical interpreters.
- Performance depends on audio quality and different dialects.
- Limited by the available training data for rare languages.

**Best fit:** Clinics and hospitals needing faster language access for routine encounters.

### Robotics & Physical Labor

#### 7. Figure AI

![](https://www.atlantic.net/wp-content/uploads/2025/08/figure-logo.png)

Figure AI is a robotics company with a focus on creating autonomous humanoid robots. Its goal is to develop general-purpose robots that can perform a wide range of tasks in real-world environments, from manufacturing to logistics. The company’s use of computer vision and advanced control systems allows its robots to interact with and learn from their surroundings.

##### Advantages

- Addresses labor shortages in physical industries.
- It has secured significant funding and partners like OpenAI and Microsoft.
- Its robots are designed to operate in human-centric environments.

##### Disadvantages

- Hardware development is capital-intensive and has long development cycles.
- Mass-market deployment faces significant regulatory and safety hurdles.

**Best fit:** Large industrial operators evaluating multi-year automation roadmaps.

### Industrial Operations

#### 8. Remberg

![](https://www.atlantic.net/wp-content/uploads/2025/08/remberg-logo.jpg)

Remberg is a German software startup that secured a €15 million Series A in 2025. Remberg continues scaling its predictive maintenance platform into 2026 as demand for industrial AI increases. The company’s AI-driven platform provides predictive maintenance for industrial machinery. Analyzing machine data helps companies anticipate failures, streamline repairs, and extend the lifespan of their equipment.

Explore Remberg’s asset management dashboard, where you can organize equipment, track status, and manage maintenance operations in one place.
 ![Remberg](https://www.atlantic.net/wp-content/uploads/2025/02/Remberg.png)
 Image Source: Remberg

##### Advantages

- Directly improves operational efficiency and sustainability for industrial clients.
- Delivers a clear and demonstrable return on investment by reducing downtime and waste.
- As a software platform, its solution is highly scalable.

##### Disadvantages

- Requires successful integration with a client’s existing, and often legacy, industrial systems.
- The quality of its predictions is dependent on the quality of the client’s machine data.
- Competes in the crowded market for Industrial Internet of Things (IIoT) and asset management software.

**Best fit:** Manufacturers with measurable downtime costs and instrumented equipment.

## Developer Infrastructure

These companies provide platforms, models, and systems that enable enterprises to build, deploy, and control AI at scale.

### Enterprise Search

#### 9. Sierra

![Sierra](https://www.atlantic.net/wp-content/uploads/2026/02/Sierra.png)

Sierra creates AI agents that help customer support teams manage multi-step service tasks. These agents connect to backend databases and ticketing systems, enabling them to answer complex questions, update records, and resolve issues without a person at every stage. Companies use Sierra to speed up responses and automate routine support work. Sierra announced a [$350M raise at a $10B](https://sierra.ai/blog/theres-an-agent-for-that-and-it-runs-on-sierra) valuation in September 2025.

Explore the SIERA.AI dashboard to monitor inspections, track incidents, and manage operational safety in real time.
 ![Sierra](https://www.atlantic.net/wp-content/uploads/2025/02/Sierra.png)
 Image Source: Sierra

##### Advantages

- Manages organized service tasks across different systems.
- Lowers the workload for human support teams.
- Connects directly to tools like ticketing and CRM systems.

##### Disadvantages

- Needs setup to work with a company’s internal systems.
- Still requires people to review unusual or complex issues.
- How well it works depends on the quality of its connections to other systems.

#### 10. Glean

![Glean](https://www.atlantic.net/wp-content/uploads/2026/02/Glean.png)

Glean provides a search across internal company tools and data sources, including messaging platforms, file systems, and knowledge bases. Employees use Glean to find answers and documents without switching between apps, helping teams work more efficiently and reducing time spent tracking down information.

This is the Glean dashboard, designed to help teams find information, interact with AI agents, and streamline internal workflows.
 ![Glean](https://www.atlantic.net/wp-content/uploads/2025/02/Glean.png)
 Image Source: Glean

##### Advantages

- Searches across multiple internal platforms from one interface.
- Reduces time spent looking for documents and answers.
- Supports natural language queries rather than keyword-only search.

##### Disadvantages

- Requires the indexing of all connected systems before full effectiveness.
- Search quality depends on underlying permissions and metadata.
- Not designed for external customer search use cases.

**Best fit:** Mid-to-large orgs with many SaaS systems and heavy internal knowledge reuse.

#### 11. Operand

![](https://www.atlantic.net/wp-content/uploads/2025/08/operand-logo.png)

Operand is an AI platform created to automate and replace the functions of traditional business consulting. A 2025 graduate of Y Combinator, the company’s initial focus is on the e-commerce sector, where its software analyzes a client’s internal data to provide and execute optimal pricing and promotion strategies. Its ability to demonstrate a direct, positive impact on a company’s finances has generated significant early interest.

Connect your data once to Operand and let AI automatically organize, clean, and understand it across all your tools.
 ![Operand](https://www.atlantic.net/wp-content/uploads/2025/02/operand.png)
 Image Source: Operand

##### Advantages

- Delivers a clear and measurable return on investment for its clients.
- Targets a specific and high-value business problem.
- Has strong institutional backing from a top-tier accelerator program.

##### Disadvantages

- High reliance on accessing sensitive and complete client data.
- Proving its models are effective across different industries will be a key challenge.
- Its initial market is focused on e-commerce, which may limit broader growth until the platform expands.

**Ideal for:** E-commerce businesses and online retailers looking for a data-driven, automated solution to optimize pricing, manage inventory, and increase profitability.

### Model Providers

#### 12. Cohere

![](https://www.atlantic.net/wp-content/uploads/2025/08/cohere-logo.jpg)

Cohere specializes in building large language models specifically for enterprise use. The company’s platform allows businesses to deploy powerful AI that is customized for their specific needs, with a strong emphasis on data privacy and security. Their models can be used to improve tasks like customer support, summarization, and internal search.

Use Cohere to bring language AI into your workflow, from prompt testing to building scalable AI-driven applications.
 ![Cohere](https://www.atlantic.net/wp-content/uploads/2025/02/Cohere.png)
 Image Source: Cohere

##### Advantages

- A clear focus on the needs of enterprises.
- Offers flexible deployment options, including on a private cloud.
- Designed to work with a company’s unique data.

##### Disadvantages

- Less public brand recognition compared to consumer-facing AI companies.
- Enterprise sales cycles can be long and complex.

**Ideal for:** Large organizations that need to build and deploy secure, customized AI solutions to enhance their products and internal operations.

### AI Deployment & Infrastructure Serving

#### 13. Baseten

![Baseten](https://www.atlantic.net/wp-content/uploads/2026/02/Baseten.png)

Baseten provides infrastructure for deploying and serving open-source AI models at scale. It offers tools that help engineering teams host models such as Llama, manage endpoints, and monitor performance in production environments without building and maintaining their own serving layer. Organizations use Baseten to reduce the operational work tied to deploying custom models.

Manage your AI deployments in Baseten, track usage, monitor performance, and control infrastructure from a single interface.
 ![Baseten](https://www.atlantic.net/wp-content/uploads/2025/02/Baseten.png)
 Image Source: Baseten

##### Advantages

- Simplifies hosting and serving open-source models.
- Offers monitoring and endpoint management tools.
- Reduces the need for internal infrastructure development.

##### Disadvantages

- Requires engineering resources for integration.
- Less suited for highly customized enterprise stacks.
- The feature set depends on the supported model frameworks.

**Best fit:** Companies shipping AI features that need predictable latency and uptime.

### AI governance and security

#### 14. Airia

![Airia](https://www.atlantic.net/wp-content/uploads/2026/02/Airia.png)

Airia helps organizations control access, coordinate, and manage internal AI systems. It lets teams decide who can deploy models, what data those models use, and how outputs are tracked and reviewed. Security and risk teams rely on Airia to enforce AI policies across the company.

Get a clear view of your AI operations with Airia, analyze trends, compare providers, and optimize model performance.
 ![Airia](https://www.atlantic.net/wp-content/uploads/2025/02/Airia.png)
 Image Source: Airia

##### Advantages

- Gives organizations a single place to manage all internal AI deployments.
- Supports the enforcement of rules for how AI and data are used.
- Let’s teams monitor who accesses models and what changes are made.

##### Disadvantages

- Needs clear policies to be set up and regular updates to keep running smoothly.
- Can slow down fast-paced testing or experimentation.

**Best fit:** Regulated enterprises that need auditable controls around AI usage.

#### 15. Aurascape

![Aurascape](https://www.atlantic.net/wp-content/uploads/2026/02/Aurascape.png)

Aurascape provides tools to monitor AI behavior in production, helping detect unusual outputs, policy violations, and possible misuse. It shows how deployed models perform against operational and compliance standards. Companies with stringent regulatory or safety requirements use Aurascape to enhance oversight of AI-driven processes.

Here’s the Aurascape dashboard, designed to help teams track applications, assess risk scores, and control usage at scale.
 ![Aurascape](https://www.atlantic.net/wp-content/uploads/2025/02/Aurascape.jpg)
 Image Source: Aurascape

##### Advantages

- Gives insight into how models behave in real-world use.
- Helps spot output patterns that break internal standards.
- Supports teams responsible for compliance and risk.

##### Disadvantages

- Needs to be integrated with the systems that serve your models.
- Human teams are still needed to respond to detected issues.
- How well monitoring works depends on how alert thresholds are set.

**Best fit:** Security and compliance teams trying to inventory and control AI usage at scale.

## The Role of Cloud Platforms and Accelerators

The growth of these AI startups is not possible without outside help. They rely heavily on the infrastructure provided by major cloud platforms. Cloud hosting allows startups to build powerful systems without investing huge sums of money in their data centers.

In 2026, infrastructure competition is centered on GPU availability, inference pricing, and deployment speed.

A notable trend has emerged in AI funding: AI-focused venture capital (VC) funds are increasingly targeting early-stage startups. The primary battleground for investment is now at the Seed and Series A stages. VCs are making bold, early bets on promising teams with innovative ideas, hoping to get in on the ground floor before valuations skyrocket. This strategy is a direct response to the explosive potential of the market.

Investors recognize that a relatively small early-stage investment in a company that successfully scales can yield astronomical returns, far outweighing the risks of the ventures that fail. To even be considered for these opportunities, a startup must be structured correctly; for many AI-focused investment programs and accelerators, startups must have received prior equity funding to qualify, creating a formal pipeline from angel investment to major venture capital.

Angel investors and seed accelerators like Y Combinator play a critical role in establishing the next best startups. They provide essential pre-seed funding, mentorship, and a network that helps early-stage companies get started. Take a look at the [companies they have helped](https://www.ycombinator.com/companies) realize their impact on AI startups.

Many of the successful AI startups in this list are graduates of such programs, which provide them with the initial resources needed to develop their technology and find a place in the market.

### The Critical Role of GPU Infrastructure for Startups

The innovation showcased by these startups is not built on capital investment alone. The advanced algorithms and large language models demand a lot of computing power to become a reality.

[Cloud GPU hosting](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/) environments are used to perform the calculations needed for both training and inference. For an AI startup, access to powerful and scalable GPU infrastructure is a fundamental requirement of many startups. Most startups opt for greenfield Cloud GPU deployments to help meet their business objectives. In 2026, inference efficiency and cost optimization are becoming more important than raw training scale.

While going it alone is possible, do so presents a significant challenge. Building and maintaining a private data center with the latest GPU hardware is prohibitively expensive and complex, especially for a new company focused on AI development. This is where specialized GPU hosting providers like Atlantic.Net become critical enablers.

Atlantic.Net can provide startups with on-demand access to enterprise-grade GPU resources, such as clustered NVIDIA’s H100 NVL and L40S Tensor Core GPUs, allowing a startup to convert a massive capital expenditure into a manageable operational cost, allow startups to scaling compute resources up or down as their development and customer demands change.

The link between the infrastructure requirements and the companies on this list is direct. Reliable and powerful GPU hosting is the foundational layer that allows innovative AI applications to be built, tested, and deployed at scale.

## What to Watch in 2026

Across these companies, the common “next test” is no longer model quality in isolation. It’s operational reality:

- **Can the agent take actions safely (permissions, approvals, rollback, audit logs)?**
- **Can teams measure impact (time saved, costs reduced, error rates, SLA improvement)?**
- **Can the system be governed (policy enforcement, monitoring, escalation paths)?**
- **Can it run cost-effectively at scale (inference optimization, caching, workload routing)?**

That’s where 2026 winners will separate from impressive demos—and where this list is worth watching over the year ahead.

### Key Factors Driving Investment in AI

Investment from private equity and venture capital continues to flow into the AI sector. Investors are looking for companies that can analyze data in novel ways to produce actionable insights.

In 2026, investment decisions are increasingly tied to measurable ROI, retention, and real-world deployment success.

The potential to improve the customer experience, automate workflows, and create more efficient business processes is a major attraction. The ability to understand consumer behavior through data analysis provides a clear competitive advantage, driving sales and market share for organizations that adopt these AI solutions.

 


---

# A Guide to GPU Server Hosting Options in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/a-guide-to-gpu-server-hosting-options/ | Published: 2026-04-25 | Updated: 2026-04-26 | Author: Richard Bailey

## **GPU Hosting Options: Cloud, Bare Metal, and Dedicated Servers**

Finding the right GPU hosting solution means understanding several key considerations. In 2026, this includes not just raw performance but also workload orchestration, multi-GPU scaling, and support for AI-driven pipelines like large language models and real-time inference. You’ll want to weigh factors like raw computing power, the ability to scale, the pricing structure, and the specific needs of your AI workloads or deep learning tasks that require a high-performance GPU.

The best GPU providers offer a wide selection of hosting environments.

- **Cloud GPU Hosting**provides access to GPU resources within a provider’s shared cloud infrastructure, offering scalability and a pay-as-you-go model. These resources are available in various specifications. Importantly, cloud computing resources can utilize shared GPU resources—either a fraction of a GPU (e.g., using NVIDIA’s Multi-Instance GPU technology on supported GPUs), a single GPU, or multiple GPUs (often interconnected with technologies like NVIDIA NVLink for enhanced performance).
- **Dedicated GPU Hosting** is where the client has dedicated access to an individual host, they get all the CPU, memory and storage allocated to the host. It’s exclusive for you! No one else uses it, that includes any dedicated GPU cards attached to the server. Importantly, dedicated servers can also integrate with the hosting providers cloud platform and can be consumed on demand.
- **Bare Metal GPU Hosting** is where you own or lease the bare metal server. These servers are typically abstracted away from the cloud platform and configured within a colocation data center, or sometimes integrated with a client’s private cloud. They are usually very powerful servers with one or more GPUs. In 2026, bare metal setups are often used for large-scale AI training clusters where maximum performance and hardware-level control are required.

The type of GPU-optimized frameworks you need, such as TensorFlow, PyTorch, or CUDA libraries, depends on your circumstances. Modern deployments also frequently include orchestration layers like Kubernetes and containerized workflows for portability across environments. However, it’s critical to choose reliable, security-focused GPU infrastructure to get you started. We have been looking at some leading cloud GPU providers and specialists in cloud, dedicated servers, and bare metal GPU offerings.

Here is how we rank them specifically for strong GPU hosting options:

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

### **#1: Atlantic.Net**

#### **Introduction:**

With roots going back to 1994, Atlantic.Net has evolved into a versatile provider of cloud services. Their offerings include dedicated GPU server hosting and cloud GPU instances specifically engineered for high-performance computing (HPC) and demanding machine learning tasks. Clients can access a curated range of NVIDIA GPUs, such as the powerful NVIDIA L40S and the dual-GPU NVIDIA H100 NVL, distributed across their international data center footprint.

Here is Atlantic.Net’s cloud server panel for deploying and managing dedicated and GPU servers.
 ![Atlantic.Net Server Panel](https://www.atlantic.net/wp-content/uploads/2026/01/Atlantic.net-server-panel.png)
 Image Source: Atlantic.Net

#### **Advantages:**

- Access to specialized NVIDIA hardware, including the L40S and H100 NVL, meets the needs of advanced AI modeling and diverse high-performance workloads.
- Clients can choose between dedicated GPU servers, offering maximum control and resource isolation, or scalable cloud-based “GPU as a Service” (GaaS) options designed to optimize upfront investment.
- A significant emphasis on security is demonstrated by their SSAE 18 SOC 2 & SOC 3 certifications and readiness for HIPAA/HITECH audits, which is particularly beneficial for organizations handling sensitive data.
- The assurance of a 100% uptime Service Level Agreement (SLA) is complemented by 24/7 technical support headquartered in the United States.
- Operations are supported by a global network of data centers in the US, Canada, the UK, and Singapore, providing geographical diversity.

#### **Ideal for:**

- Organizations in specialized fields like AI/ML engineering, biotechnology, and healthcare that process sensitive data and therefore require services adhering to HIPAA compliance standards.
- Users whose projects demand substantial, uninterrupted computational power from dedicated GPU servers for intensive tasks such as deep learning model training, complex graphics rendering, or large-scale scientific simulations.
- Businesses that prioritize a provider’s extensive operational history, a demonstrable commitment to security, and readily available, U.S.-based customer support.
- Clients seeking cost-effective solutions for long-term GPU hardware rentals, especially when the hyper-scalability of larger cloud platforms isn’t the primary driver, will find Atlantic.Net’s pricing models attractive.

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

### **#2: Amazon Web Services (AWS)**

#### **Introduction:**

As a dominant hyper-scale cloud provider, AWS delivers a vast portfolio of IT services. This includes an extensive and frequently updated selection of GPU instances, such as the P-series optimized for high-throughput compute tasks and the G-series for graphics-intensive applications. AWS supports a wide spectrum of demanding workloads, from sophisticated machine learning model training to high-resolution video rendering, leveraging its massive global infrastructure.

Here is the AWS EC2 dashboard, where you can control instances, monitor status, and configure settings.

![AWS Instance](https://www.atlantic.net/wp-content/uploads/2026/01/AWS-Instance.png)

Image Source: AWS

#### **Advantages:**

- An unparalleled selection of NVIDIA GPU models and instance sizes allows users to precisely tailor resources to diverse performance and budgetary requirements.
- The platform’s inherent design allows for dynamic scaling of GPU resources, enabling businesses to efficiently adjust to fluctuating workload demands and optimize spend.
- Seamless integration with AWS’s comprehensive ecosystem of services—spanning storage, networking, databases, and AI/ML tools—can significantly streamline application development and deployment.
- A worldwide network of data centers ensures low-latency access for a global user base and facilitates disaster recovery planning.
- Developers benefit from broad support for various GPU-optimized frameworks and libraries, accelerating the development of AI models and other GPU-accelerated applications.

#### **Disadvantages:**

- AWS’s intricate pricing structure can be challenging, sometimes leading to higher-than-anticipated costs, particularly for sustained high-usage scenarios if not carefully managed.
- Data egress fees are an important budgetary consideration and can accumulate significantly depending on data transfer patterns.
- While powerful, the sheer breadth of service options and configurations can present a steep learning curve for users new to the AWS ecosystem

#### **Ideal for:**

- Large enterprises and rapidly growing startups that need highly scalable GPU instances for developing and deploying machine learning models, deep learning algorithms, and complex high-performance computing simulations.
- Development teams looking to leverage a rich, deeply integrated ecosystem of cloud services to build sophisticated, multi-component applications.
- Organizations with a global operational footprint that require robust, geographically distributed GPU infrastructure to serve their AI workloads with high availability and low latency.
- Users whose workflows involve performing complex big data analytics in concert with their GPU-accelerated computational tasks.

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

### **#3: Google Cloud Platform (GCP)**

#### **Introduction:**

GCP is another leading global cloud GPU provider, known for its strong capabilities in data analytics, machine learning, and natural language processing. They offer a variety of GPU instances equipped with powerful NVIDIA GPUs, designed for high computational power.

Manage cloud services with the Google Cloud dashboard, where you can create virtual machines, deploy applications, and analyze data using built-in tools.

![Google Cloud Dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Google-Cloud-Dashboard.png)

Image Source: Google Cloud

#### **Advantages:**

- GCP excels in AI model training and deep learning, offering direct pathways to Google’s cutting-edge AI research, tools like TensorFlow and Vertex AI, and alternative accelerator options like Google’s own Tensor Processing Units (TPUs).
- For certain NVIDIA GPU models, GCP presents a competitive pricing structure, which includes the flexibility of per-second billing, allowing for granular cost control.
- A high-capacity, private global network underpins GCP’s services, contributing to consistent performance and low-latency data transfer worldwide.
- Beyond virtualized instances, GCP also makes bare metal options available for specific high-performance scenarios, granting direct, unmediated access to underlying GPU hardware.
- Robust support for containers and Kubernetes (via Google Kubernetes Engine – GKE) simplifies the orchestration and scaling of distributed GPU workloads.

#### **Disadvantages:**

- The range of GPU hardware options, while good, might sometimes be less extensive than other cloud providers in specific regions.
- Some services have a steeper learning curve and require expert knowledge of existing GCP services.
- It can be costly if resources are not managed carefully.

#### **Ideal for:**

- Data scientists and researchers focused on machine learning and AI models.
- Organizations that are already invested in the Google Cloud Platform, often those looking for big data processing and analytics.
- Users requiring cutting-edge NVIDIA GPU technology for training large language models or natural language processing.
- Businesses looking for flexible GPU server hosting that scales with their AI workloads.

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

### **#4: Microsoft Azure**

#### **Introduction:**

Microsoft Azure provides a comprehensive suite of cloud services, including N-series Virtual Machines, which are GPU instances designed for compute-intensive and graphics-intensive applications. Azure supports a wide range of GPU resources suitable for AI/ML, video editing tasks, and scientific computing.

Explore the Azure dashboard to organize resource groups, track usage, and manage cloud services from a centralized platform.

![Microsoft Azure](https://www.atlantic.net/wp-content/uploads/2026/01/Microsoft-Azure.png)

Image Source: Azure

#### **Advantages:**

- Exceptional integration with the broader Microsoft ecosystem, including Windows Server, Microsoft Entra ID (formerly Azure AD), and Azure’s wide array of platform services, benefits enterprises already utilizing Microsoft technologies.
- Azure provides a diverse selection of NVIDIA GPU options, catering to visualization workloads (NV-series), AI/HPC (ND-series, NC-series), and general-purpose GPU compute.
- The platform offers a spectrum of GPU-accelerated VMs, some of which deliver performance characteristics approaching that of dedicated servers, alongside more traditional cloud GPU elasticity.
- Strong support for hybrid cloud scenarios, enabling organizations to consistently manage and deploy GPU workloads across on-premises environments and Azure.
- Microsoft continues to expand its focus on AI workloads, providing dedicated platforms like Azure Machine Learning and tools that streamline the AI development lifecycle on its GPU infrastructure.

#### **Disadvantages:**

- The Azure portal and service options can sometimes be complex to navigate.
- Costs can escalate if not carefully monitored, similar to other major cloud providers.
- Some of the newest GPU models might have limited regional availability initially and an extensive wait list.

#### **Ideal for:**

- Enterprises that are already invested in the Microsoft platform (Windows Server, Entra ID, or Azure Platform Services).
- Users who need GPU hosting options for professional graphics applications, video encoding, and complex engineering simulations.
- Organizations working on AI model training and inferencing that can benefit from Azure’s AI platform.
- Researchers needing computing power for scientific research and simulations.

![](https://www.atlantic.net/wp-content/uploads/2025/05/coreweave.png)

### **#5: CoreWeave**

#### **Introduction:**

CoreWeave has carved out a niche as a specialized cloud GPU provider, purpose-built from the ground up for extremely large-scale AI workloads, demanding deep learning tasks, high-fidelity visual effects (VFX) rendering, and other compute-heavy processing pipelines. They distinguish themselves by offering broad access to a diverse range of NVIDIA GPUs, often including the very latest generations, with a strong emphasis on high-performance bare metal and Kubernetes-native environments.

Here is the CoreWeave Cloud dashboard, where you can deploy GPU-powered virtual servers, manage storage, and monitor high-performance workloads.
 ![CoreWeave Cloud](https://www.atlantic.net/wp-content/uploads/2026/01/CoreWeave-Cloud.avif)
 Image Source: CoreWeave Cloud

#### **Advantages:**

- Access to a vast inventory of cutting-edge NVIDIA GPU models, often available sooner than larger, generalized clouds.
- Potentially significant cost savings (reportedly 30-80% less expensive) for GPU compute compared to traditional hyperscalers.
- Highly scalable infrastructure designed for massive AI model training and inference.
- Kubernetes-native platform, streamlining deployment and management for teams familiar with container orchestration.
- Offers flexible storage and high-performance networking optimized for GPU clusters.

#### **Disadvantages:**

- Does not offer the broad selection of general cloud services found in Atlantic.Net, AWS, GCP, or Azure; primarily focused on GPU compute.
- May require more DevOps expertise for setup and management if not leveraging their managed services, as it can be less of a turnkey solution for those unfamiliar with Kubernetes.
- Heavy reliance on NVIDIA for its GPU hardware could be a long-term strategic consideration.

#### **Ideal for:**

- AI research labs, machine learning engineers, and VFX studios requiring access to large quantities of the latest NVIDIA GPUs at scale.
- Organizations focused on training deep learning models, large language models (LLMs), or running complex scientific simulations that can benefit from bare metal performance.
- Users looking for potentially more cost-effective pricing on high-performance GPU hosting for power-hungry applications and comfortable with a specialized cloud environment.
- Teams that are adept with Kubernetes and looking for a GPU infrastructure that integrates well with it.

## **Why Traditional CPUs Can’t Always Keep Up:**

CPUs are not necessarily a problem; in fact, they are still essential for GPU hosting. What we mean is that there is a much better, more efficient way to develop AI/ML applications, handle large-scale rendering, or image analysis.

So what’s wrong with CPUs?

- **Sequential Processing:** CPUs excel at a wide range of general-purpose tasks and can handle serial operations or a limited number of parallel threads efficiently. However, for tasks requiring massive parallelism (like those in AI/ML), they process operations more sequentially per core compared to GPUs.
- **Limited Cores for Parallel Tasks:** While multi-core, the CPU cannot match GPUs for massively parallel jobs. GPUs are simply better at doing millions of simple tasks simultaneously.
- **Bottlenecks for Intensive Data:** Large-scale data analytics and complex calculations can overwhelm CPUs, resulting in applications that lag significantly.

## **Cloud GPUs**

What makes the GPU so good at handling AI/ML applications? It’s down to the simple reason that the GPU can do many more tasks simultaneously, and perform much quicker.

GPU servers are great at:

- Training complex deep learning models
- Performing big data analytics at speed
- Powering intricate graphics rendering, online gaming, and completing video editing tasks efficiently
- Driving high-performance computing tasks and complex engineering simulations

In 2026, GPUs are also widely used for large language models, generative AI workloads, and real-time AI inference at scale.

Choosing the right GPU hosting provider can help to improve your business goals and objectives almost immediately. This guide will uncover the various GPU hosting options that are available, helping you find the perfect match for your resource-hungry applications.

## **Final Pointers for Picking a Cloud GPU Provider**

GPU hosting has introduced superior performance, breakneck processing power and the very latest technology to global businesses en masse. If you’re feeling like your computing tasks are stuck in the slow lane, it may be time to level up to a GPU platform.

In 2026, GPU adoption continues to grow as AI workloads become more complex and require faster training cycles and scalable infrastructure.

For today’s most data-intensive applications, standard hosting options may not be powerful enough. This is because standard central processing unit (CPU)-based servers often just don’t cut it for modern AI workloads.

Despite being very powerful, there are better options available with graphics processing units (GPUs) that introduce incredible parallel processing capabilities, allowing users to get the best performance from one or more GPUs.

Selecting the right GPU hosting provider from the many GPU hosting options is a big decision. To make sure you get the best fit, keep these key factors in mind:

- **The Right GPU Hardware**: Do you need specific NVIDIA GPU models (e.g., for AI model training vs. graphics rendering)?
- **Scale of Your Workloads:** How much computing power do your resource-heavy processes really need? Will you need to scale up or down, or in and out?
- **Your Budget:** What pricing structure works best? Compare on-demand cloud GPUs with longer-term dedicated servers. Does the provider offer discounts for 1, 2, or 3-year commitments?
- **Control vs. Convenience**: Do you prefer the full control of bare metal solutions or the managed environment of cloud GPU instances?
- **Supported Frameworks**: Does the provider easily support the GPU-optimized frameworks critical for your AI/ML or deep learning tasks?
- **AI workload type**: Are you running training, fine-tuning, or real-time inference? Each has different infrastructure needs.

Whether you lean towards flexible cloud GPU instances, the raw power of dedicated GPU servers, or the direct control of bare metal solutions, the ideal hosting provider should have GPU hosting options with the computing resources needed.

GPU hosting enables your business to tackle any compute-intensive application, from cutting-edge AI/ML and deep learning projects to high-performance computing and smooth video editing tasks efficiently. Take the time to evaluate each GPU server hosting option, and you’ll unlock the performance your projects deserve, enabling businesses and researchers to push new boundaries while achieving unparalleled performance.


---

# Best GPU Hosting Providers for AI and Machine Learning (2026 Guide)

> URL: https://www.atlantic.net/gpu-server-hosting/top-gpu-hosting-providers-for-ai-and-machine-learning/ | Published: 2026-04-25 | Updated: 2026-04-26 | Author: Dr. Assad Abbas

The demand for high-performance GPU hosting has shifted from simple model training to complex, real-time inferencing for Generative AI and Large Language Models (LLMs). In 2026, the difference between a successful deployment and a stalled project often comes down to hardware availability—specifically NVIDIA H100, H200, and the new Blackwell B200 clusters—and regulatory compliance.

In 2026, GPU availability, interconnect speed, and access to next-generation architectures like NVIDIA Blackwell are key factors shaping AI infrastructure decisions.

If you’re choosing GPU hosting for AI/M, start by matching the workload to the right delivery model: dedicated GPU servers for steady training, GPU clouds for elastic runs, and serverless GPU for production inference. For regulated workloads (health data, payments), pick a provider that’s built around audited compliance workflows. Atlantic.Net is a strong fit when HIPAA/HITECH-style controls matter and offers current-generation NVIDIA options such as L40S and H100 NVL. For large-scale training, specialist GPU clouds (and hyperscalers) win on multi-GPU and multi-node scale.

Modern AI deployments also prioritize orchestration tools, data pipelines, and model lifecycle management alongside raw GPU performance.

Whether you are fine-tuning LLaMA 3, rendering generative video, or processing sensitive electronic Protected Health Information (ePHI), your infrastructure must match your workload. This guide ranks the top GPU hosting providers for 2026 based on performance, compliance, and value.

## Quick Verdict: The Top 3

- **For Healthcare & Enterprise Compliance:** Atlantic.Net. Offers HIPAA-compliant dedicated bare metal with H100 NVL/L40S.
- **For Massive Scale & Kubernetes:** CoreWeave. Built for training massive models with thousands of H100s.
- **For Developers & Short-Term Jobs:** RunPod. Best spot-pricing and community templates for rapid prototyping.

These categories reflect how teams now segment GPU usage across compliance, scale, and rapid experimentation workflows.

## Comparison: Top GPU Hosting Providers 2026

| **Provider** | **What you rent** | **GPU options (examples)** | **Scale model** | **Compliance focus (only when verifiable)** | **Best for** |
| --- | --- | --- | --- | --- | --- |
| Atlantic.Net | Cloud GPU + dedicated GPU servers | NVIDIA L40S, H100 NVL ([Atlantic.Net](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/?utm_source=chatgpt.com)) | Scale from cloud to dedicated | HIPAA/HITECH-audited positioning ([Atlantic.Net](https://www.atlantic.net/hipaa-compliant-hosting/?utm_source=chatgpt.com)) | Regulated AI/ML + secure deployments |
| CoreWeave | GPU cloud + bare metal | NVIDIA HGX H100/H200 (plus platform options) ([CoreWeave](https://www.coreweave.com/products/hgx-h100-h200?utm_source=chatgpt.com)) | Multi-GPU, multi-node | (Varies by engagement; validate per workload) | Distributed training and high-throughput pipelines |
| Lambda | GPU instances + clusters | B200, H100, A100, GH200 ([Lambda](https://lambda.ai/instances?utm_source=chatgpt.com)) | 1–8 GPU instances and larger clusters | (Not stated as a universal certification) | Builders who want ML-first infrastructure |
| Genesis Cloud | GPU cloud | H100, H200, B200 ([Genesis Cloud](https://www.genesiscloud.com/?utm_source=chatgpt.com)) | On-demand and longer-term capacity | EU positioning (confirm residency needs per project) | EU-centric deployments + modern GPU access |
| Runpod | Pods + serverless endpoints + instant clusters | (Varies by region/market) | Single GPU pods → multi-node clusters ([Runpod Documentation](https://docs.runpod.io/)) | (Confirm based on tier and data type) | Fast iteration, inference endpoints, burst workloads |
| AWS | GPU instances (EC2) | P5 (H100-powered) ([Amazon Web Services, Inc.](https://aws.amazon.com/ec2/instance-types/p5/?utm_source=chatgpt.com)) | Single instance → large fleets | Broad compliance programs (validate services in scope) | Enterprise pipelines + integrated cloud stack |

## What Does GPU hosting Mean in 2026?

GPU hosting has split into three practical choices:

- **Dedicated GPU servers:** You keep the same box for weeks/months. Good for steady training and stable data pipelines.
- **GPU cloud instances:** You spin up GPUs when you need them. Good for burst training and experimentation.
- **Serverless GPU endpoints:** You deploy an API and pay for execution. Good for inference and production apps that scale up/down.

A growing fourth model is hybrid infrastructure, where teams combine dedicated and cloud GPUs to balance cost, performance, and availability.

The “best” provider depends less on brand and more on your workload: model size (VRAM), training duration, scale-out needs, and compliance requirements.

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

## 1. Atlantic.Net

**Best for: Healthcare, Finance, and Compliant Dedicated Hosting**

We distinguish ourselves by offering dedicated bare metal servers rather than just virtual instances. This prevents the “noisy neighbor” effect common in public clouds, ensuring consistent performance for mission-critical AI workloads. Our infrastructure is audited for HIPAA, HITECH, and PCI compliance, making us the safest choice for organizations handling patient data (ePHI) or financial records. Dedicated GPU infrastructure remains critical for regulated AI environments where performance consistency and data isolation cannot be compromised.

Below is Atlantic.Net’s cloud control panel interface used to deploy and manage dedicated and GPU servers.
 ![Atlantic.Net Server Panel](https://www.atlantic.net/wp-content/uploads/2026/01/Atlantic.net-server-panel.png)
 Image Source: Atlantic.Net

- **Key Specs:** NVIDIA H100 NVL (94GB HBM3) and L40S (48GB GDDR6); Bare Metal.
- **Compliance:** HIPAA, HITECH, PCI-DSS, SOC 2, SOC 3.
- **Support:** 24/7/365 US-based support; managed services available.
- **Verdict:** The go-to choice for enterprises that cannot risk compliance violations or performance jitter.

**What stands out:**

- **Verified Compliance:** Atlantic.Net is one of the few providers willing to sign a Business Associate Agreement (BAA) for GPU hosting.
- **H100 NVL Availability:** We stock the powerful NVL variant designed for LLM inference and fine-tuning.
- **No Egress Fees (Dedicated):** Unlike hyperscalers, our dedicated plans often include massive bandwidth allowances.

**Who should choose Atlantic.Net?**

CTOs in healthcare/fintech and teams requiring predictable, dedicated hardware performance.

![](https://www.atlantic.net/wp-content/uploads/2026/01/Hetzner.jpg)

## 2. Hetzner

**Best for: Budget-Conscious Projects & European Data Residency**

Hetzner remains a favorite for developers and startups due to its great price-to-performance ratio. It continues to be a strong option for cost-sensitive inference workloads and development environments, especially within Europe. While they focus on consumer-grade cards (RTX 3080/4090) and older enterprise cards, their dedicated server auction (“Server Börse”) allows savvy users to snag powerful hardware for a fraction of the cost of major clouds.

View the Hetzner dashboard interface designed to deploy cloud servers, configure networking, and monitor activities across global locations.

![hetzner-dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/hetzner-dashboard.png)

Image Source: Hetzner

- **Key Specs:** NVIDIA RTX 3080/4090, some A100 availability.
- **Compliance:** GDPR (German/Finnish Data Centers).
- **Support:** Standard ticket-based support; minimal managed services.
- **Verdict:** Perfect for inference workloads, rendering, or development environments where enterprise SLAs aren’t critical.

**What stands out:**

- **Cost Efficiency:** Hourly rates often under €1.00 for capable RTX cards.
- **Bandwidth:** Generous traffic limits included in the base price.
- **Location:** Excellent connectivity within Europe.

**Who should choose Hetzner?**

Bootstrapped startups, students, and EU-based companies needing GDPR compliance on a budget.

![](https://www.atlantic.net/wp-content/uploads/2025/05/lambda.png)

## 3. Lambda

**Best for: Deep Learning Specialists & On-Demand Training**

Lambda sells virtually nothing but GPU compute, and they do it well. Its focus on pre-configured AI environments reduces setup time and supports faster experimentation cycles for ML teams. As an early partner of NVIDIA, they often have stock of high-end chips (H100, GH200, and the new B200). Their software stack comes pre-configured with PyTorch, TensorFlow, and JupyterLab, allowing data scientists to start training models seconds after booting.

Let’s see the Lambda interface used to analyze resource usage, manage filesystems, and monitor spending across projects.

![Lambda gpu dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Lambda-gpu-dashboard.png)

Image Source: Lambda

- **Key Specs:** NVIDIA H100, A100, GH200 Superchip, Blackwell B200.
- **Compliance:** SOC 2 Type 2.
- **Support:** Engineering-focused support.
- **Verdict:** A frictionless environment for machine learning engineers who want raw power without DevOps overhead.

**What stands out:**

- **1-Click Clusters:** Rapidly spin up multi-node clusters for distributed training.
- **Flash Storage:** High-speed local NVMe storage optimized for feeding data to hungry GPUs.
- **Persistent Storage:** Easily attach reliable storage to instances.

**Who should choose Lambda?**

AI research teams and ML engineers needing immediate access to top-tier hardware.

![](https://www.atlantic.net/wp-content/uploads/2025/05/coreweave.png)

## 4. CoreWeave

**Best for: Massive Scale & Kubernetes Native Workloads**

CoreWeave has grown into a major player by powering some of the world’s largest AI companies. Its Kubernetes-native approach aligns with modern MLOps practices and containerized AI workflows. Their infrastructure is built on top of Kubernetes, making it ideal for containerized workflows and serverless inference scaling. They specialize in massive clusters of H100s and B200s connected via NVIDIA Quantum InfiniBand for training foundation models.

Here is the CoreWeave Cloud dashboard, where you can deploy GPU-powered virtual servers, manage storage, and monitor high-performance workloads.

![CoreWeave Cloud](https://www.atlantic.net/wp-content/uploads/2026/01/CoreWeave-Cloud.avif)

Image Source: CoreWeave

- **Key Specs:** NVIDIA H100, A100, L40S; HGX Baseboards.
- **Compliance:** HIPAA, SOC 2, ISO 27001.
- **Support:** Enterprise-grade SLAs available.
- **Verdict:** The industrial-strength option for training Large Language Models (LLMs) from scratch.

**What stands out:**

- **Networking:** 3.2 Tbps Infiniband interconnects for bottleneck-free distributed training.
- **K8s Native:** No virtual machines to manage; you deploy containers directly.
- **Scale:** Capable of provisioning thousands of GPUs in a single cluster.

**Who should choose CoreWeave?**

AI Unicorns and enterprises performing foundational model training or large-scale batch inference.

![](https://www.atlantic.net/wp-content/uploads/2025/08/runpod-logo.png)

## 5. RunPod

**Best for: Community Developers & Flexible Spot Pricing**

RunPod has taken the developer community by storm in 2026. Its combination of serverless inference and community GPU access supports rapid iteration and cost-efficient experimentation. It operates a dual model: a “Secure Cloud” (datacenter reliability) and a “Community Cloud” (cheaper, peer-provided GPUs). This flexibility, combined with an easy-to-use interface and “Serverless GPU” endpoints for inference, makes it incredibly popular for hobbyists and agile teams.

Take a look at the RunPod dashboard, where you can compare GPU specs, check availability, and deploy cost-effective GPU servers in seconds.

![Runpod](https://www.atlantic.net/wp-content/uploads/2026/01/Runpod.png)

Image Source: RunPod

- **Key Specs:** Wide variety (RTX 3090/4090 to H100 PCIe); Serverless Inference.
- **Compliance:** SOC 2 Type II (Secure Cloud)**.**
- **Support:** Discord community & email support.
- **Verdict:** The most flexible “Swiss Army Knife” for testing, prototyping, and deploying API endpoints.

**What stands out:**

- **Templates:** One-click deploy for Stable Diffusion, vLLM, Text-Gen-WebUI, and more.
- **Serverless:** Pay-per-millisecond for inference endpoints (autoscaling to zero).
- **Pricing:** Extremely aggressive spot pricing on the Community Cloud.

**Who should choose RunPod?**

Independent developers, hackathon teams, and startups building GenAI applications on a budget.

![](https://www.atlantic.net/wp-content/uploads/2025/08/genesis.png)

## 6. Genesis Cloud

**Best for: Sustainability & Green Computing**

Genesis Cloud focuses on a specific niche: 100% renewable energy-powered GPU computing. Hosting primarily out of Iceland and Norway, they utilize geothermal and hydroelectric power to offer low-cost, low-carbon compute. This is increasingly important for companies reporting on ESG (Environmental, Social, and Governance) metrics.

This is the Genesis Cloud control panel, designed to track real-time analytics, manage workloads, and optimize GPU-based infrastructure.

![Genesis Cloud dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Genesis-Cloud-dashboard.png)

Image Source: Genesis Cloud

- **Key Specs:** NVIDIA HGX H100, RTX 3080/3090.
- **Compliance:** GDPR; 100% Green Energy Certified.
- **Support:** Direct technical support.
- **Verdict:** Excellent for batch processing and training where carbon footprint and energy costs are primary concerns.

**What stands out:**

- **Sustainability:** Drastically reduces the carbon impact of training large models.
- **Cost Stability:** Energy independence protects pricing from fossil fuel fluctuations.
- **Privacy:** Strong data privacy laws enforced by EEA jurisdiction.

**Who should choose Genesis Cloud?**

EU organizations and environmentally conscious tech firms.

## 7. AWS GPU Hosts

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

**Best for: Teams standardizing on hyperscale cloud**

AWS remains a default shortlist item for enterprise teams because it integrates GPUs into a broader cloud stack (networking, IAM, storage, observability). Its strength lies in integrating GPU workloads with a full cloud ecosystem, including storage, networking, and security services. For AI training specifically, AWS highlights EC2 P5 as H100-powered infrastructure.

Here is the AWS EC2 dashboard, where you can control instances, monitor status, and configure settings.

![AWS Instance](https://www.atlantic.net/wp-content/uploads/2026/01/AWS-Instance.png)

Image Source: AWS

- **Key Specs:** EC2 P5 instances are positioned as NVIDIA H100-powered
- **Compliance**: A large compliance catalog exists, but always validate which services and configurations are in scope.
- **Support**: Works best if you already have AWS operations maturity.
- **Verdict**: Choose AWS when you want GPUs inside a full enterprise cloud platform—and you can support the operational overhead.

**What stands out:**

- P5 positioning for H100-class training workloads
- Deep integration with enterprise cloud primitives (IAM, VPC, storage)
 Scale potential when capacity is available

**Who should choose AWS? **

Organizations already invested in AWS and want GPUs inside the same control plane. Enterprises already deeply integrated into the AWS ecosystem, and organizations needing FedRAMP-level compliance.

## Frequently Asked Questions

**Q: What is the best GPU for LLM Inference in 2026?**

A: For large models (70B+ parameters), the NVIDIA H100 NVL and the newer Blackwell B200 are the top choices due to massive memory bandwidth and Transformer Engine optimization. For smaller models or lower latency requirements, the NVIDIA L40S offers excellent price-per-performance without the high cost of the H100.

**Q: Do I need a dedicated GPU server, or is Cloud VPS enough?**

A: For experimentation, a Cloud VPS (like RunPod or Lambda) is sufficient. However, for production healthcare or finance workloads, a dedicated GPU server (like Atlantic.Net) is recommended to ensure data isolation, stable performance, and compliance with regulations like HIPAA.

**Q: Why is HIPAA compliance important for GPU hosting?**

A: If you are processing electronic Protected Health Information (ePHI) with AI—such as analyzing medical imaging or transcribing patient notes—you are legally required to use a HIPAA-compliant host. Standard “Terms of Service” from non-compliant clouds do not offer the legal protection required by US law (BAA).

**Q: Are consumer GPUs (RTX 4090) good for Machine Learning?**

A: They are excellent for development, fine-tuning small models, and inference. However, their license prevents their use in some datacenter deployments, and they lack the VRAM interconnects (NVLink) required for training massive models across multiple cards.


---

# What Is a HIPAA API in 2026?

> URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-api-explained/ | Published: 2026-04-25 | Updated: 2026-04-26 | Author: Richard Bailey

A **HIPAA API** is an **Application Programming Interface** (API) that is used to control interactions with **healthcare applications**, **systems**, and **websites**that handle protected health information and are subject to HIPAA (the **Health Insurance Portability and Accountability Act**).

In 2026, HIPAA APIs are also expected to support modern interoperability standards and stricter security controls due to increased regulatory scrutiny and expanded digital health ecosystems.

An API is an automated interface residing on a remote server and is used to receive requests and send responses over the Internet, allowing a user to complete an action on that server without directly interacting with a third party application, system, or website. Think of it as a messaging system that delivers your request to an API and then returns with an answer to your request.

Almost every interaction you perform using a device, website, or program relies on an Internet-based API. Buying movie tickets, booking a flight, paying for parking, or ordering drinks at the bar via an app are all actions that typically use an API.

HIPAA APIs are used to feed information to and from the server to the application, system, or website seamlessly throughout its performance. Importantly, when data contains Protected Health Information (PHI), it becomes bound by the rules and regulations of HIPAA compliance. Any health information that has the privacy and security information redacted is exempt.

As of 2026, organizations are placing greater emphasis on real-time data exchange and auditability when handling PHI through APIs, especially in telehealth, remote monitoring, and AI-assisted healthcare applications.

## **A brief background on HIPAA**

According to HIPAA legislation, an application that handles the PHI of US citizens must be safeguarded with standardized encryption mechanisms and other protections in every use-case scenario. Failure to use a HIPAA-compliant API can be disastrous for a healthcare industry firm’s bottom line and reputation.

Regulators now expect encryption standards such as TLS 1.2+ (preferably TLS 1.3) and strong key management practices to be consistently enforced across all API interactions.

One way that application developers and others working with protected health data can achieve compliance at all times is through a healthcare-specific service that processes and stores all PHI in full compliance – as is necessary for all business associates (such as[HIPAA Compliant Cloud Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)). APIs can be incredible tools that facilitate work with healthcare data, provided they are established within healthcare-specific architecture.

The HIPAA Privacy Rule applies to information held by covered entities that is usually processed by their business associates. A covered entity is the healthcare provider, typically a hospital, medical practice, clearinghouse, or a health insurance plan provider.

A business associate is any person or entity that performs tasks on behalf of the healthcare providers; for example, Atlantic.Net is a business associate. We must enter a business associate agreement with the covered entity.

In 2026, Business Associate Agreements (BAAs) increasingly include clauses covering API usage, third-party integrations, and incident response timelines tied specifically to API-level breaches.

For an API to be HIPAA compliant, HIPAA demands compliance with the Security Rule, the Privacy Rule, and the Breach Notification Rule.

## **Types of Healthcare API**

Many different kinds of healthcare APIs are available. The most common types use the RESTful API (**RE**presentational **S**tate **T**ransfer), which most developers are probably already familiar with. This API has an abundance of uses, as it utilizes HTTP requests to access and transfer data.

There are four data types in a REST API; GET, PUSH, POST and DELETE. A REST API can be used for many different applications, such as the transfer of information regarding medications, allergies, diagnoses, procedures, and a range of other information.

Next is the FHIR API (Fast Healthcare Interoperability Resources), FHIR is used exclusively for the exchange of electronic health records and is quickly becoming the global standard. FHIR is[commonly used for the transfer of medical care](https://digital.nhs.uk/services/transfer-of-care-initiative) information between practices, triaging day-case discharges, and emergency care, mental health, and outpatient clinic letters.

FHIR has become the dominant interoperability framework in 2026, driven by mandates such as the 21st Century Cures Act and widespread adoption across EHR vendors and digital health platforms.

While numerous different HIPAA healthcare APIs are available, here are some of the most popular. The ApiMedic Symptom Checker is a REST API that helps users to find out what possible illness they might have. Others include APIs that help to monitor how diet affects your illness, the Dexcom API, which can be used to track anonymized health information to treat diabetes, APIs for HIPAA compliant telephone exchanges, and more.

Newer API use cases now include AI-assisted diagnostics, wearable integrations, and patient-facing apps that require stricter validation and consent management workflows.

## **HIPAA API Safeguards**

Many additional physical, technical, and administrative safeguards need to be in place to protect healthcare API interactions. The quickest way to achieve compliance is to outsource some or all of your healthcare technical solutions to a HIPAA compliant managed service provider. Once onboard, you will have immediate access to a HIPAA compliant infrastructure. This means that any API transactions processed internally will be HIPAA compliant, assuming other aspects of the business are also maintaining compliance.

How do HIPAA compliant managed service providers achieve this? Data must be encrypted at rest and in transit, and most PHI is stored in a database, so if an API is programmed to query the database, the database must be encrypted. Securing the API data transmission as well as encrypting messages and responses are mandatory and can be achieved using an encrypted VPN tunnel between the Covered Entity and the Business Associates.

In 2026, many organizations are also implementing zero-trust architectures, API gateways, and token-based authentication (such as OAuth 2.0) to further secure API access.

Access controls must be in place for who or what can query an API, and users and computers with this access should be controlled by access control lists on a need-to-know basis. In particular, service accounts need to be secured with the correct privileges. Access and audit logging must be enabled for all calls to the API, and logs should be reviewed regularly.

Modern best practice also includes continuous monitoring, anomaly detection, and automated alerting for suspicious API behavior.

If an API is used to query a public cloud provider external to the HIPAA compliant network, only de-identified medical information can be used, and it is the covered entity’s responsibility to ensure this is set up.

This requirement remains critical in 2026, especially as multi-cloud and third-party API integrations become more common.

## **How Can Atlantic.Net Help?**

Atlantic.Net has more than 25 years of experience meeting and exceeding the needs of health professionals and is one of the country’s leading healthcare technology companies. If you’re in this industry and you need help with healthcare cloud hosting, contact our sales team to find out how our managed services could help your organization.

If you are in the market for managed IT healthcare services, make sure you choose an experienced HIPAA compliant provider that focuses on security, business continuity, and scalability: a provider that can grow with you, and one that focuses on collaboration and API data interoperability. We know that the regulations of the industry are intense, but Atlantic.Net can take away the stress of managing your entire IT operation.

We have an extensive list of healthcare clients who have trusted us for many years, and our managed service packages allow you to forget about the complexities of IT and focus on your patients.

We will protect your infrastructure from the very latest cybersecurity threats, as well as manage upgrades and maintenance behind the scenes. We will work with you to identify and secure PHI, protect you from ransomware attacks, and offer you the very best Healthcare Managed Services platform available.

In 2026, this also includes support for secure API development, monitoring, and compliance alignment with evolving interoperability standards.

Atlantic.Net offers [HIPAA Cloud Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA Compliant Web Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)services to support IT Solutions for Healthcare. Contact us today to learn more!


---

# 2026 HIPAA IT Compliance Guide

> URL: https://www.atlantic.net/hipaa-data-centers/hipaa-compliant-it-infrastructure-guide/ | Published: 2026-04-25 | Updated: 2026-04-28 | Author: Alexander Wise

With healthcare IT growing, the need for federally compliant infrastructure to process and store electronic protected health information (ePHI) that is protected by the Health Insurance Portability and Accountability Act (HIPAA) is on the rise as well.

HIPAA compliant IT infrastructure is a combination of physical systems, networks, cloud services, and security controls designed to protect ePHI. It must meet the requirements of the HIPAA Security Rule, which focuses on administrative, physical, and technical safeguards.

In practice, this means using secure data centers, encrypted storage, controlled access, continuous monitoring, and documented policies. Compliance is not tied to a single product or provider—it depends on how systems are configured, managed, and audited over time.

As of 2026, increasing cybersecurity threats and stricter enforcement trends have made properly designed HIPAA infrastructure a baseline requirement rather than a competitive advantage.

This is part of an extensive series of guides about [compliance management](https://www.exabeam.com/explainers/compliance-management/compliance-management-process-regulations-and-tools/).

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_HIPAA-IT-infrastructure-must-meet-evolving-standards.png)

## HIPAA IT infrastructure must meet evolving standards

HIPAA was passed in 1996 to allow United States citizens to keep their health insurance when they changed employment (the P in HIPAA, portability) while safeguarding their health records (the first A in HIPAA, accountability). Under the law, healthcare providers, plans, and data clearinghouses (called covered entities by HIPAA) were given guidelines they had to follow – in which case they would achieve HIPAA compliance and avoid violations. These covered entities were expected to sign contracts with all of their business associates (BAs), service providers that handled their patient information. The contracts themselves were called business associate agreements (BAAs).

While the core law remains unchanged, enforcement practices and technical expectations continue to evolve alongside modern cybersecurity threats and cloud adoption.

HIPAA was updated in 2009 through the Health Information Technology for Economic and Clinical Health Act, or HITECH. HITECH was contained within the American Recovery and Reinvestment Act, or ARRA – the economic stimulus package enacted by the 111th US Congress and signed by President Obama in response to the Great Recession. This new law made several changes, most notably reflecting changes in technology and including the BAs in the types of organizations covered by the regulations (making those firms directly responsible for meeting federal stipulations). HITECH also laid the groundwork for today’s emphasis on interoperability, secure data exchange, and increased penalties for non-compliance, which remain highly relevant in 2026.

The most critical aspect of HIPAA related to digital systems is the Security Rule1. Geared toward keeping unauthorized parties away from ePHI, this key HIPAA rule created standards that were to be used by healthcare organizations when generating, receiving, utilizing, or storing this highly confidential data. To protect this information (i.e., to be certain it is secure, has integrity, and is
 kept private), covered entities have to implement safeguards of three types: technical, administrative, and physical.

The regulations of HIPAA can be adapted to suit the specific situation. For example, the size of a business might impact what it includes its HIPAA-compliant infrastructure. Plus, since HIPAA does not mandate specific technologies – instead basing its expectations on the current industry standards – organizations must be aware that the law is dynamic and that keeping abreast of
 the changing nature of IT security is key to maintaining compliance. Organizations are now expected to regularly reassess risk as infrastructure changes, especially in hybrid and multi-cloud environments.

It is also important to know that HIPAA extends beyond what is in the code or tools that are in place to protect servers, as noted by Kayla Matthews in Data Center Journal2. Staff training is necessary, as is continuing education on the topic. Plus, it is necessary to have various policies and procedures in place that apply to data protections, how they are supported, and steps to follow in the event of a breach. Security awareness training and ongoing access reviews are now considered baseline expectations rather than optional enhancements.

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_Cost-of-HIPAA-compliant-IT-infrastructure.png)

## Cost of HIPAA-compliant IT infrastructure

Complying with HIPAA – including servers and all other aspects – is unfortunately costly, as noted by Jen Stone of Security Metrics3. For medium and large HIPAA-regulated firms, costs include a risk analysis and management plan ($20,000+); remediation (variable); policy creation and training ($5000+); onsite audit ($40,000+); penetration testing ($5000+); and vulnerability scans ($800). As those figures indicate, the total bill is usually $50,000 or more for entities of this size. Actual costs in 2026 vary widely depending on architecture choices, automation, and use of managed services, making fixed estimates less reliable than in earlier years.

Costs are not quite as extreme for small organizations. For those institutions, Stone estimated compliance at $4000 to $12,000, a figure that included a risk analysis and management plan ($2000); remediation ($1000 to $8000); and policy creation and training ($1000 to $2000). The total bill is approximately $4000-$12,000, per her estimate. Costs will vary based on the way that your organization handles ePHI.

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_HIPAA-IT-compliance-goes-beyond-audits-_-contracts.png)

## HIPAA IT compliance goes beyond audits & contracts

[Data centers](https://www.atlantic.net/hipaa-data-centers/) have to meet strict security requirements in order to comply with HIPAA. The complexity of achieving the rules is simplified through independent audits2 that determine whether HIPAA-compliance safeguards are implemented. Audits and consultation can to help validate the compliance of a system whether it is your own or that of a third-party hosting provider you are considering. Today, audits are often supplemented with continuous compliance monitoring tools rather than relying solely on periodic assessments.

When looking at services for colocation or hosting, organizations need to sign business associates agreements; however, these contracts do not absolve them of the need to comply with the law beyond that relationship. Plus, due diligence must be performed when selecting a healthcare business associate. Beyond healthcare-specific audits, you can also check for compliance with the Statement on Standards for Attestation Engagements 18, aka SSAE 18 (formerly SSAE 16), a widely recognized way to audit systems developed by the American Institute of Certified Public Accountants. The adoption of SSAE 18 certification4 in addition to a HIPAA compliance audit creates redundancy in third-party security evaluation of the infrastructure partner you choose.

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_HITECH-mandates-EDI-for-data-transmission.png)

## HITECH mandates EDI for data transmission

Especially since HITECH and its focus on interoperability (among its other concerns), easy and rapid transfer of medical data between systems has been critical to regulators. The sending and receiving of ePHI is to occur according to electronic data interchange (EDI) standards5. In 2026, interoperability efforts increasingly align with APIs and modern healthcare data standards like FHIR alongside traditional EDI formats.

The EDI rule5, which uses a protocol standard for data transmission as its basis, X12N EDI. The rule mandates that the protocol must be used in the vast majority of situations in which electronic data is sent. The rule contains guidelines for data transmission that severely control the manner in which data is sent between devices. The rule provides the various kinds of transactions for which HIPAA is relevant and advises the specific format that must be used for data transfer in that case. Instructions are included for electronic transactions such as coordination of benefits (COB); referrals and authorizations; eligibility verifications and responses; claims status and remittance advices (RA); and health care claims.

The reasoning behind the rule is to simplify the transmission of health data by reducing from the hundreds of possible ways in which healthcare data has been formatted to the one standard approach of EDI. The primary reason this approach is important is that it better enables the accessibility and portability of medical records and minimizes the amount of money that must be spent on administration to manage data transmission.

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_Checklist-for-HIPAA-compliant-IT-infrastructure-_-related-needs.png)

## Checklist for HIPAA-compliant IT infrastructure & related needs

The step-by-step needs for infrastructural compliance can be organized within a HIPAA compliance checklist. This one, based on the one created by AdviseTech6 and elaborated with the expertise of HIPAA engineers at Atlantic.Net7, provides an overview of core concerns when setting up servers for a compliant healthcare environment:

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_HIPAA-compliant-768x1024.jpg)

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_1.-Physical-security-before-data-access.png)

### 1- Physical security before data access

- Limited-access premises and parking
- Limited-access building
- No signs designating where the data center is
- Attendant or security guard at the entryway
- Need for photo ID at entrance
- Procedure for signing in and out of the facility

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_2.-Infrastructure-facility-and-security-.png)

### 2- Infrastructure facility and security: access privileges

- Access limited to the data center building
- Need for biometric access
- Access restriction signs
- Individual, distinct IDs for each staff member’s access
- Procedure to give access and take it away
- Vendor and guest rule for accompaniment by a staff member
- Reconciling of access with staff

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_3.-Infrastructure-facility-and-security-access-monitoring.png)

### 3- Infrastructure facility and security: access monitoring

- Real-time access tracking
- Ongoing digital door-access log
- Guest log written by hand
- Positioning of cameras at each cage, aisle, and door-access point

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_4.-Infrastructure-facility-and-security-.png)

### 4- Infrastructure facility and security: data safeguarding

- Availability of shredder
- Locked and secure server and communication cabinets
- Secure network sockets and cables

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_5.-Logical-access-controls.png)

### 5- Logical access controls

- Comprehensive delineation demarcating one client from the next, so that the setting is private
- Defined and distinct server roles
- Logging and [access control](https://www.esecurityplanet.com/products/network-access-control-solutions/) applied to all infrastructure handling PHI
- Firewall implemented in between private and public server environments
- Management of production changes
- Program to manage problems or incidents
- Response plan for security events
- Risk management and mitigation process

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_6.-Documented-controls-and-policies.png)

### 6- Documented controls and policies

- Access controls/policy
- Firewalls and related policy
- Password management system and policy
- Antimalware solution and policy
- Data classification system and policy
- Encryption mechanisms and policy
- Retention system and policy
- Destruction system and policy

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_7.-Firewall.png)

### 7- Firewall

- Firewall dedicated to each individual environment
- Total separation from other clients
- Redundant firewalls
- Point-to-point virtual private network (VPN)
- Triple DES (3DES) to apply the DES encryption algorithm three times per data block
- Multi-factor authentication (MFA)
- Remote access via SSL VPN
- Internet protocol security (IPsec) in tunnel mode
- Filters for ingress and egress

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_8.-Network.png)

### 8- Network

- Internal zone for the private server
- Public services demilitarized zone (DMZ; i.e., the part of the network that exposes the external-facing services to the Internet or other outside networks)
- Private virtual local area network (VLAN)

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_9.-Preventing-breaches.png)

### 9- Preventing breaches

- Intrusion prevention strategies
- Intrusion detection system (IDS) to know right away when anyone gets in
- Distributed denial of service (DDoS) mitigation solution
- Web application firewalls (WAF) as applicable
- Secure sockets layer (SSL) offloading of intrusion detection system / intrusion prevention system (IPS) SSL traffic

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_10.-Antimalware.png)

### 10- Antimalware

- Enterprise-quality antivirus solution
- Reporting that is centralized
- Logging of aberrant processes
- Intrusion prevention

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_11.-Business-associate-checklist.png)

### 11- Business associate checklist

- Organization is willing to sign a BAA
- Encryption of data throughout environment
- Insurance that is sufficient for the setting
- Backups both locally and off-site
- Logging and management of vulnerabilities
- Presence of HIPAA policies for HR, training, and security incident response
- Compliant with Statement on Standards for Attestation Engagements 18 (SSAE 18, formerly SSAE 16) SOC 1 and 2
- Willing to be part of your HIPAA audits
- HIPAA-trained personnel, organization-wide
- Training in general understanding of IT security

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_12.-Checklist-for-selecting-a-managed-host.png)

### 12- Checklist for selecting a managed host

- Security patching 24/7 complete oversight
- Easy access to clear performance metrics
- Host assumes the responsibility to restore any dropped service, respond appropriately to alarms, and escalate any serious issues as appropriate
- Secure portal for submission and management of tickets
- Access controls based on roles
- Specific, dedicated person to help you make any adjustments to your HIPAA-compliant infrastructure
- Tech support available 24/7

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_Summarized-steps-for-HIPAA-compliant-IT-infrastructure.png)

## Summarized steps for HIPAA-compliant IT infrastructure

If that checklist is a bit overwhelming, the basic summary of what you need to do for compliance is expressed in these nine key steps covered by Brandon Butler in NetworkWorld8:

- Put substantial and robust audit controls into place.
- Use your audit logs to assess the activity within your system.
- Deploy access management and identity controls, logging everyone who accesses a system and sending out notifications to administrators whenever configurations are adjusted.
- Install a disaster recovery system, making certain that all information is backed up so that you are prepared for your contingency plan, which should incorporate emergency response procedures.
- Perform penetration testing, code scanning, and vulnerability scanning on all parts of your infrastructure that process or store electronic health data.
- Sign a well-written, fair, and thorough business associate agreement with each of your service providers, establishing key expectations of your relationship, including how patients can get access to their records, what steps each of you are taking to ensure data security, and how each party should respond in the event of a breach.
- Control access by making certain that users are logged and unique. Make it possible to automatically log off users, have sophisticated authentication processes, and have groups that account for stateful security.
- Ensure that all PHI and other confidential data is encrypted by implementing a purpose-designed strategy to encrypt confidential data that is at rest and in motion.
- Secure transmissions through the use of object keys as possible, along with in-motion encryption via Advanced Encryption Standard 256 (AES 256; which is applicable to both SSL and transport layer security, or TLS).

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_Rules-for-HIPAA-IT-Companies-_-Cloud-Hosting.png)

## Rules for HIPAA IT Companies & Cloud Hosting

Organizations that must meet HIPAA regulations are increasingly concerned with how they can proceed in adoption of cloud services, one of which is cloud hosting or infrastructure as a service (IaaS). Note that the bulk of these rules apply to any third-party HIPAA hosting scenario. Cloud adoption is now the dominant model, with hybrid and multi-cloud strategies becoming more common in regulated environments.

The *“Guidance on HIPAA & Cloud**Computing”*9 document from the Department of Health & Human Services (HHS) notes that the most important concerns for covered entities and business associates are the Privacy, Security, and Breach Notification Rules. As the guidelines indicate, these rules together protect patient health data through restrictions on its disclosure and use, safeguards to protect against disclosure and use that is not permitted, and the rights of individuals related to their ePHI. These rules should be pivotal in determining strategy for HIPAA-compliant IT infrastructure.

The cloud parameters clarify that the establishment of a relationship between a HIPAA covered entity and IaaS provider that handles any electronic health data makes the cloud host a business associate. In turn, when a business associate signs up with an IaaS provider to process, store, or otherwise handle its electronic PHI, the cloud provider again becomes a business associate.

The cloud host is a BA in these cases, even if it is only in contact with health records that are encrypted and for which the service does not possess a key. Since a business associate relationship is created, a business associate agreement must be signed between the cloud provider and HIPAA-regulated firm that is using its services. The cloud host, in these cases, must meet the demands of the BAA and also has to meet direct compliance with the relevant HIPAA specifications.

The business associate agreement is critical in defining how the cloud service will perform. The BAA should include language that sets forth allowed and necessary ePHI uses and disclosures. The uses and disclosures will be a bit different depending on the nature of the relationship and services being performed. The BAA should also stipulate that the BA must protect the data that it is handling, a main crux of which is the tenets of the Security Rule.

The HIPAA Security Rule1, as a refresher, created standards to safeguard electronic protected health information. The Security Rule is concerned with the security, integrity, and privacy of digital information, as can be achieved through certain technical, physical, and administrative safeguards. There are various tools and resources provided by the HHS that pertain to the Security Rule:

- *HIPAA Security Risk Assessment Tool*10
- *NIST HSR Toolkit*11
- *Risk Analysis Guidance*12

Note that many organizations look for exceptions to the HIPAA law, hoping it might not apply to them. With cloud hosts, the desire is that they might fit the definition of a conduit for ePHI, as is true of the US postal service. It is unlikely that an IaaS provider will meet that same definition. The only way it does is if the service is transmission-only, with any storage that does occur being
 temporary and incident to the transmission.

Not knowing about the cloud environment, or any third-party infrastructure provider, is not compliance. A healthcare organization or one of its business partners that handles ePHI on its behalf must gather knowledge about the cloud system and setting so that they can perform a relevant risk analysis and, in turn, create the right risk management policies and BAAs. In performing this
 assessment, the HIPAA-regulated organization must name and analyze the environment for any weaknesses or risks that might undermine the ePHI so that it becomes unavailable, corrupted, or accessible to unauthorized parties.

This process should encompass health records at all levels – during their production, receipt, storage, and transmission. To be clear, the BAA will be crafted, in part, based on the risk analysis that is conducted and risk management plan that is created, which in turn are based on the particular configuration of cloud (public, private, or hybrid), among other factors.

The relationship between your firm and an IaaS provider should also be governed by a service level agreement (SLA). These documents establish what you expect of your relationship with the provider that is less technical and more business-related. These concerns are also often necessary components of HIPAA compliance, as with these common topics:

- commitments on the reliability and availability of the solution
- the nature of data recovery and backup systems, which would (in part) allow the cloud host to immediately recover from a disaster or cybercriminal attack
- the process through which any HIPAA-protected information is sent back to the client if they decide to end their use of the service assignment of responsibility to certain parties for elements of security
- any pertinent limitations related to disclosing, retaining, or using the ePHI.

One other specific thing to check is that neither the SLA or the BAA prevents you from being able to get to your data at any point.

You will need a BAA with the cloud host even for situations in which the data is encrypted and they do not have a key. While encryption is critical to ePHI protection, other parameters of HIPAA must be addressed as well (such as availability, protection from corruption, and administrative protocols). A cloud host must find and appropriately respond to any security events that it thinks or
 knows might have occurred. They also must minimize any damage that occurs as a result of the breach or incident. The IaaS provider should also let the client whose information was compromised know what has happened. The cloud host needs to have policies and procedures documents that cover the actions that must be taken and that log any security events that take place. The procedures should include contacting the impacted customer.

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_Looking-at-your-own-IT-infrastructure-to-understand-cloud-needs.png)

## Looking at your own IT infrastructure to understand cloud needs

A report by Brian Taylor in TechRepublic13 noted that being aware of risks within your own on-site infrastructure will give you a better sense of your vulnerabilities in cloud. That’s because signing on with a cloud host will not reduce the need for you to meet general compliance parameters (which extend beyond your relationships with infrastructure providers).

Conducting a HIPAA risk assessment and carefully reviewing your agreements with cloud hosts will give you an idea of where you have weaknesses, clarifying what you need in a provider to prevent any gaps in compliance.

![](https://www.atlantic.net/wp-content/uploads/2020/06/HIPAA-IT-Compliance-Guide_Infrastructural-expertise-to-avoid-HIPAA-violations.png)

## Infrastructural expertise to avoid HIPAA violations

For healthcare organizations and service providers that handle electronic PHI, knowing that your infrastructure meets the needs set forth by the Department of Health and Human Services is essential. Evaluating your own infrastructure can be extraordinarily costly, time-consuming, and inconvenient. While working with an external infrastructure provider does not mean that you are
 free from the many responsibilities of HIPAA, a carefully selected partner and well-constructed BAA can protect you both from data breaches and from liability.

## Get Help with HIPAA IT Compliance

[HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) by Atlantic.Net is SOC 2 & SOC 3 certified and HIPAA & HITECH audited, designed to secure and protect critical healthcare data and records. Get a free consultation today! Call 866-618-3282 or [contact us online](https://www.atlantic.net/about-us/corporate-contact/#GetStarted).

You can also [download the PDF version of this article, originally published as a whitepaper](https://www.atlantic.net/resources/documents/whitepapers/pdf/hipaa-compliant-it-infrastructure-guide-atlantic-net-whitepaper.pdf).

Learn more about [colocation hosting](https://www.atlantic.net/orlando-colocation-hosting-data-center/) from Atlantic.Net.

## HIPAA FAQs

#### What does HIPAA stand for?

HIPAA is the common abbreviation for the Health Insurance Portability and Accountability Act, a US federal law enacted during the Clinton Administration.

#### What is HIPAA?

HIPAA was signed and enacted into law on August 21, 1996. The law was created to uphold the data integrity of protected health information (PHI) and offer guarantees to patients about how their data was handled.

In 2003, the Privacy Rule and Security Rule amendments were introduced to govern the handling of electronically protected health information (ePHI) between healthcare practices and business associates. The Privacy and Security Rules outlined several safeguards designed to keep patient data safe.

#### Does HIPAA apply to electronic records?

Yes, electronic protected health information (ePHI) is subject to HIPAA regulations. HIPAA legislation has adapted as the healthcare industry and the technology it uses has changed throughout the years. If you handle ePHI, look for a hosting provider with HITECH accreditation, as HITECH specifically relates to electronic records and increases the legal liability for non-compliance, and enforces tougher penalties.

#### What is a Business Associate Agreement?

The 2003 HIPAA Privacy Rule amendment introduced a new administrative safeguard declaring that all covered entities must have a signed HIPAA Business Associate Agreement (BAA) in place with all Business Associates (BA) and Covered Entities (CE) that manage, process or archive Protected Health Information (PHI).

A BAA exists in order to keep personal health records safe and confidential. Having a BAA in place with a provider is absolutely key, but that document does not necessarily guarantee that your vendor is actually maintaining HIPAA compliance. Because that’s the case, every covered entity must vet different providers to gauge their true level of HIPAA compliance and, in turn, expertise in guiding you forward.

As a business associate, Atlantic.Net is happy to sign a BAA with our healthcare clients who need web hosting.

#### How is HIPAA enforced?

Overall, the US Department of Health and Human Services (HHS) is responsible for enforcing HIPAA safeguards. Controls are also built into the legislation that makes it mandatory for healthcare providers and institutions to self-report any expected breaches.

The Final Omnibus Rule of 2013 introduced further liability rulings for web hosting providers and instructed the Office for Civil Rights (OCR) to enforce the expectations of the Omnibus Rule.

#### What are the consequences of failing to meet HIPAA regulations?

The Breach Notification Rule enforces a legal obligation on the healthcare institutions to report any breaches, and this may include any failings discovered during the annual auditing of records.

The fines are very steep for HIPAA Violations. There are four tiers of fines and the fine paid depends on the severity of the incident:

- Tier 1: Minimum fine of $100 per violation, up to $50,000
- Tier 2: Minimum fine of $1,000 per violation, up to $50,000
- Tier 3: Minimum fine of $10,000 per violation, up to $50,000
- Tier 4: Minimum fine of $50,000 per violation

---

### See Additional Guides on Key Compliance Management Topics

Together with our content partners, we have authored in-depth guides on several other topics that can also be useful as you explore the world of [compliance management](https://www.exabeam.com/explainers/compliance-management/compliance-management-process-regulations-and-tools/).

#### [PCI Compliant Hosting](https://www.atlantic.net/pci-compliant-hosting/)

*Authored by Atlantic.Net*

- [[Guide] PCI Hosting Solutions | 12-Point PCI-Compliant Hosting Checklist](https://www.atlantic.net/pci-compliant-hosting/)
- [[Guide] PCI DSS Cybersecurity Requirements: A Practical Guide](https://www.atlantic.net/pci-compliant-hosting/pci-dss-cybersecurity-requirements-a-practical-guide/)
- [[Blog] How to Reduce Your PCI Scope When Accepting Payments](https://www.atlantic.net/pci-compliant-hosting/reduce-pci-scope-accepting-payments/)

#### [HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)

*Authored by Atlantic.Net*

- [[Guide] HIPAA-Compliant Hosting | 2025 Award-Winning HIPAA Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)
- [[Guide] What Is Protected Health Information (PHI) in 2025? Atlantic.Net](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/)
- [[Blog] RTLS and Healthcare](https://www.atlantic.net/hipaa-compliant-hosting/rtls-and-healthcare-can-real-time-location-system-security-improve-your-healthcare-operations/)
- [[Product] Atlantic.Net HIPAA Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/)

#### [Health Data Management](https://cloudian.com/guides/hipaa-compliant-cloud-storage/health-data-management/)

*Authored by Cloudian*

- [[Guide] What Is Health Data Management? Benefits, Challenges and Storage](https://cloudian.com/guides/hipaa-compliant-cloud-storage/health-data-management/)
- [[Guide] HIPAA Compliant Cloud Storage and On-Premises Alternatives](https://cloudian.com/guides/hipaa-compliant-cloud-storage/hipaa-compliant-cloud-storage/)
- [[Product] HyperStore Object Storage](https://cloudian.com/products/hyperstore/)

---

**References**
 1 https://www.hhs.gov/hipaa/for-professionals/security/index.html
 2 http://www.datacenterjournal.com/health-care-hipaa-data-centers/
 3 http://blog.securitymetrics.com/2015/04/how-much-does-hipaa-cost.html
 4 https://www.atlantic.net/why-atlantic-net/security-and-compliance/
 5 https://www.asha.org/practice/reimbursement/hipaa/hipaa_edi_faq/
 6 https://advisetech.com/wp-content/uploads/2017/07/HIPAA-Compliance-Checklist-2.pdf
 7 https://www.atlantic.net/hipaa-compliant-hosting/
 8 https://www.networkworld.com/article/3121967/cloud-computing/9-keys-to-having-a-hipaa-compliant-cloud.html
 9 https://www.hhs.gov/hipaa/for-professionals/special-topics/cloud-computing/index.html
 10 https://www.healthit.gov/providers-professionals/security-risk-assessment-tool
 11 http://scap.nist.gov/hipaa/
 12 https://www.hhs.gov/ocr/privacy/hipaa/administrative/securityrule/rafinalguidance.html?language=es
 13 https://www.techrepublic.com/


---

# Most Impactful AI Applications in Healthcare in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/most-impactful-ai-applications-in-healthcare/ | Published: 2026-04-25 | Updated: 2026-04-26 | Author: Dr. Rachael Bailey

AI is radically transforming healthcare, and 2026 is shaping up to be a defining year for practical, scaled AI adoption across clinical care, research, and operations. Competition has intensified, with both established medtech leaders and fast-moving AI startups delivering production-ready solutions rather than early-stage pilots.

In this article, we will take a look at some of the most impactful AI applications currently reshaping healthcare, highlighting the AI tools and companies behind them that are truly making a difference in this area.

## **How Are Artificial Intelligence Applications Being Used in the Healthcare Industry?**

AI applications are being used across the healthcare industry to solve complex medical challenges, improve patient outcomes, and streamline clinical workflows. Unlike traditional computer programs, these AI-driven tools can mimic important aspects of human cognition, such as reasoning, learning, and decision-making at a speed and scale that we’ve never seen before.

AI adoption is now moving beyond experimentation, with healthcare systems embedding AI directly into daily workflows, electronic health records, and clinical decision support tools.

In 2026, AI is making major strides in several key areas, fundamentally transforming how healthcare is delivered:

### **Early Detection and Improved Medical Diagnosis**

One of the most important ways that AI is making an impact in the healthcare sector is by allowing healthcare providers to make faster, more accurate diagnoses. AI machine learning algorithms are continuously refining their ability to identify patterns in vast datasets, leading to increasingly reliable diagnostic support.

As an example, AI applications are being used to scan complex medical images, including X-rays, MRIs, and digital pathology slides, with incredible precision, often spotting subtle patterns that the human eye could easily miss. Recent advancements now include multimodal AI systems that combine imaging, lab data, and patient history to improve diagnostic accuracy even further. This is particularly valuable for early detection of cancers, neurological conditions, and heart disease, where a prompt disease diagnosis can make all the difference to the outcome of the patient.

### **Accelerated Drug Discovery and Development**

Bringing a new drug to market can take over a decade and cost billions of dollars. AI tools dramatically speed things up by identifying promising compounds, predicting how they’ll behave in the body, and even suggesting new uses for existing drugs. In 2026, generative AI models are increasingly being used to design molecules from scratch and simulate early-stage trials digitally. These applications are helping to streamline the early stages of the drug development process, cutting both time and costs. They can also be used to flag compounds that are likely to fail early on, so teams can focus their resources where they matter most.

### **Personalized Treatment**

Given the powerful ability of AI tools to analyze massive, complex datasets quickly, clinicians can use these applications to make more informed, personalized treatment plans based on a patient’s genetic data, real-time patient monitoring, and medical history.

In practice, this could mean using AI to help choose the most effective cancer treatment for a specific tumor profile, or adjusting medication for someone with multiple health conditions. AI-driven personalization is increasingly supported by real-time wearable data and continuous patient monitoring, enabling more dynamic treatment adjustments. This could be especially valuable in the management of cancers, rare diseases, and chronic illnesses, where individual variation can have a huge impact on outcomes.

### **Enhanced Surgical Precision**

From robotic-assisted procedures to real-time image guidance, AI is also helping to make surgical procedures safer, more precise, and often less invasive. Notably, medical professionals can leverage AI tools to analyze patient scans ahead of time to map out the best surgical approach, and even assist during operations by highlighting key structures or flagging potential complications. Newer systems are also incorporating predictive analytics to anticipate complications before they occur, improving intraoperative decision-making.

### **Revolutionizing Healthcare Data Management**

Healthcare organizations generate a staggering amount of data every day, from patient medical records and clinical data to lab results and imaging scans. Artificial intelligence in healthcare is helping to bring order to the chaos by structuring, sorting, and analyzing this information in ways that are useful to medical practitioners and researchers.

Large language models are now being used to summarize clinical notes, extract insights from unstructured data, and reduce documentation burden across health systems.

### **Expanding Access to Mental Health Care**

Mental health services have been overstretched in recent years, but AI is helping to fill in some of the gaps. For example, AI-powered chatbots can offer patients 24/7 mental health support, while apps help people to track their mood and manage symptoms. These virtual health assistants are making mental health care more accessible, especially for those who might find traditional mental health services hard to reach.

There is also increasing use of hybrid care models, where AI tools support clinicians rather than replace them, improving outcomes while maintaining human oversight.

## **Top 5 AI Applications Transforming Clinical Practice in 2026**

Here are some of the standout AI applications that are shaping the healthcare industry in 2026:

### **#1: Aidoc**

![](https://www.atlantic.net/wp-content/uploads/2025/07/aidoc-logo.png)

#### **About Aidoc:**

Aidoc is a leading AI technology company that provides AI-powered solutions to help health care organizations detect and prioritize critical imaging findings. They specialize in offering real-time medical imaging analysis, which supports faster, more accurate diagnoses and coordination of care.

Aidoc’s sophisticated AI algorithms analyze medical images, for example, CT, MRI, and X-ray scans, to detect critical health conditions such as strokes, pulmonary embolisms, and brain hemorrhages. This helps to quickly identify and treat urgent cases, leading to better patient outcomes in critical care and emergency settings.

Enhance clinical decision-making with Aidoc, an AI-powered platform that analyzes medical data in real time to accelerate diagnosis and improve patient outcomes.
 ![aidoc](https://www.atlantic.net/wp-content/uploads/2025/07/aidoc.png)
 Image Source Aidoc

#### **Advantages:**

- **Faster Interventions:** Significantly reduces the time it takes to diagnose diseases and commence treatment, directly impacting overall health outcomes.
- **Optimized Workflow:** Prioritizes radiologists’ worklists, allowing healthcare professionals to focus on the most urgent cases first.
- **Broad Clinical Impact:** Compatible with multiple imaging types, supporting widespread use in clinical practice.

#### **Disadvantages:**

- **Requirement of High Quality Data:** The performance and accuracy of Aidoc’s AI models rely heavily on the quality, consistency, and diversity of the medical imaging data that they are trained on and analyze.
- **Complex Integration:** Integrating Aidoc into existing medical IT infrastructure can be challenging.
- **High Cost:** As a premium AI solution, the initial investment in Aidoc, as well as ongoing subscription fees, can be substantial. This can significantly limit the adoption of Aidoc for smaller organizations or those with tighter budgets.

#### **Target Audience:**

- Emergency, Critical Care, and Radiology departments in large hospitals
- Trauma or Stroke Centers
- Medical Research Centers
- Outpatient Imaging Centers and Teleradiology Groups

### **#2: Insilico Medicine**

![](https://www.atlantic.net/wp-content/uploads/2025/07/insilico-logo.png)

#### **About Insilico Medicine:**

Insilico Medicine is a pioneering biotechnology company that leverages end-to-end generative AI and deep learning to accelerate drug discovery and development. Its Pharma.AI platform integrates multiple AI models to accelerate the entire drug discovery process, including “PandaOmics” to identify disease targets and “Chemistry42” for designing novel drug candidates. By automating key steps in the drug discovery pipeline, Insilico Medicine drastically reduces both the time and cost of bringing new treatments to clinical practice, helping to enhance patient care.

#### **Advantages:**

- **Accelerated Drug Development:** Can significantly reduce the time required for early-stage drug discovery, with some pipelines now progressing from target identification to preclinical candidates in under 18 months.
- **Novel Chemical Insights:** Generative AI allows for the creation of entirely new molecular structures, potentially leading to truly novel and effective therapies.
- **Improved Efficiency:** By predicting efficacy and toxicity, Insilico minimizes the need for expensive and time-consuming laboratory experiments.

#### **Disadvantages:**

- **Downstream Validation Required:** While AI platforms, such as Insilico Medicine, can speed up the early stages of drug discovery, all findings must still go through rigorous lab validation and human clinical trials to ensure safety and effectiveness.
- **Limited Biological Context:** As AI models can only simulate based on what they’ve been trained on, they can lack the full complexity of real biological systems. This means they can miss the influence of immune responses, off-target effects, and interactions between organs, cells, and molecules, leading to gaps in prediction accuracy.

#### **Target Audience:**

- Pharmaceutical Companies and Biotech Startups
- Academic & Research Institutions
- Contract Research Organizations (CROs)

### **#3: Intuitive Surgical**

![](https://www.atlantic.net/wp-content/uploads/2025/07/intuitive-logo.png)

#### **About Intuitive Surgical:**

Intuitive Surgical is a California-based medtech company, best known for developing the da Vinci Surgical System, which is the world’s leading platform for robot-assisted, minimally invasive surgery. It has transformed how minimally invasive procedures are performed in specialties such as urology, gynecology, cardiothoracics, and general surgery.

Its AI technologies help to guide surgery in real time, improve the control of surgical tools, enhance images for better visibility, and make systems easier for doctors to use. It also reviews surgical data to give feedback on technique and results, helping to boost precision and patient safety.

Optimize surgical insights with Intuitive, an advanced platform that delivers data-driven analytics, case reports, and performance tracking for smarter clinical decisions.
 ![intuitive](https://www.atlantic.net/wp-content/uploads/2025/07/intuitive.jpg)
 Image Source: Intuitive Surgical

#### **Advantages:**

- **High Level of Precision & Control:** Robotic arms filter out hand tremors and allow for ultra-fine movements, improving surgical accuracy in delicate procedures, such as heart valve repair or microsuturing.
- **Proven Clinical Efficacy:** A[large meta-analysis](https://isrg.intuitive.com/node/21471/pdf) of 230 studies found that surgeries carried out using the da Vinci robotic system led to fewer complications, less blood loss, fewer transfusions, and shorter hospital stays compared to both laparoscopic and open surgery.
- **Continuous AI Development:** Intuitive Surgical continues to expand its AI capabilities with data-driven training tools and performance benchmarking for surgeons.

#### **Disadvantages:**

- **High Initial Investment:** The da Vinci system has a high initial purchase price, as well as the cost of ongoing maintenance and disposable instruments. This contributes to higher healthcare costs for facilities, meaning that it may not be viable for smaller hospitals or clinics.
- **Specialized Training Required:** Surgeons and care teams must complete structured training programs before operating the Intuitive Surgical systems, which can take time and resources to implement effectively.

#### **Target Audience:**

- Large Academic Medical Centers and Hospitals

### **#4: Suki AI**

![](https://www.atlantic.net/wp-content/uploads/2025/07/suki-logo.png)

#### **About Suki AI:**

Suki AI is an innovative AI-powered voice assistant that helps frontline healthcare workers to save time on administrative tasks, allowing them to focus on caring for their patients. It uses advanced natural language processing (NLP) and voice recognition to listen to natural human language during doctor and patient conversations and automatically generate structured clinical notes in real time. This key health data can then be seamlessly integrated into a patient’s electronic health records.

Streamline clinical workflows with Suki, an AI assistant that captures conversations, automates medical documentation, and helps healthcare professionals save time on charting.
 ![suki](https://www.atlantic.net/wp-content/uploads/2025/07/suki.png)
 Image Source: Suki AI

#### **Advantages:**

- **Significant Time Savings:** Continues to reduce documentation time substantially, with broader integrations into major EHR systems improving usability.
- **Enhanced Note Accuracy:** Captures key clinical details from real-time patient-clinician conversations, creating more thorough and accurate medical notes.
- **Improved Connection Between Patient and Healthcare Provider:** Allows healthcare professionals to maintain crucial eye contact and focus fully on their patient during appointments, fostering better communication and a more engaged patient experience.

#### **Disadvantages:**

- **Limited Speciality Coverage:** Currently, Suki AI is best suited for primary care and internal medicine and is less optimized for highly specialized or complex fields where documentation can be more nuanced or procedure-specific.
- **Voice Recognition Nuances:** While highly advanced in understanding human language and medical terminology, AI models can occasionally misinterpret complex jargon, diverse accents, or background noise, meaning that notes must be carefully reviewed and corrected if needed.

#### **Target Audience:**

- Healthcare Organizations & Clinics, including group practices, urgent care centers, and health systems
- Primary Healthcare Professionals

### **#5: Wysa**

![](https://www.atlantic.net/wp-content/uploads/2025/07/wysa-logo.png)

#### **About Wysa:**

Wysa is a leading conversational AI platform that is designed to support mental health and emotional well-being. It offers a confidential and non-judgmental space, allowing users to interact with an AI chatbot that’s available 24/7. Through guided conversations and clinically backed techniques, such as cognitive behavioral therapy (CBT), dialectical behavior therapy (DBT), mindfulness, and mood tracking, Wysa helps users to manage stress, anxiety, and low mood at their own pace.

Wysa also provides self-help tools, guided meditations, and therapeutic exercises, often serving as a crucial first line of support or a complementary tool to human therapy in health care. This accessibility and immediate, evidence-based support are more critical than ever, given the escalating global mental health crisis.

Improve your mental well-being with Wysa, an AI-powered companion that helps you manage stress, track emotions, and build healthier habits through guided conversations.
 ![wyasa](https://www.atlantic.net/wp-content/uploads/2025/07/wyasa.png)
 Image Source: Wysa

#### **Advantages:**

- **24/7 Accessibility:** Provides patients with on-demand support around the clock, removing the need to wait for appointments. This helps to overcome common barriers associated with accessing traditional mental health care services.
- **Scalability & Reach:** Adoption has expanded across employers and healthcare providers looking to extend mental health support at scale.
- **Anonymity:** This is especially important in the mental health space, where stigma or fear of judgment can prevent people from seeking help.

#### **Disadvantages:**

- **Use is Limited for Severe Conditions:** While Wysa is designed to support mild to moderate mental health concerns such as stress, anxiety, and low mood, it is not a substitute for professional therapy in cases of severe or complex mental health conditions.
- **Lack of Human Empathy:** Wysa AI systems are designed to simulate supportive conversations, but they do not possess genuine emotional understanding, lived experience, and human empathy. This means responses may lack the depth, nuance, and emotional resonance that come from interacting with a real human therapist.

#### **Target Audience:**

- Individuals seeking immediate, accessible, and confidential mental health support
- Individuals exploring self-help techniques to support their mental health
- Organizations or employers looking to provide scalable mental well-being solutions to their members or employees

## **Challenges and Considerations of Adopting AI Applications in Healthcare Delivery**

While AI is transforming healthcare, it’s not without its challenges. One major concern for healthcare professionals is data privacy, particularly when it comes to sensitive patient information being handled by automated systems. Protecting this sensitive patient data requires robust security and transparent consent processes.

Integrating innovative AI tools into complex healthcare systems and workflows can prove tricky, often slowing down the adoption of these advancements and limiting their impact in real-world settings. There is also the risk of bias, where AI tools can inadvertently reinforce existing health disparities when they haven’t been trained using diverse datasets.

Regulatory oversight is also increasing, with governments and healthcare bodies introducing stricter guidelines for AI validation, transparency, and clinical safety.

Recognizing and addressing these hurdles is key to ensuring AI’s benefits are accessible and equitable as the technology continues to evolve.

## **What Is the Future of AI in Healthcare?**

AI is continuing to redefine what’s possible in healthcare, enhancing early diagnosis, supporting clinical decision making, streamlining administrative tasks, accelerating drug development, and ultimately driving better health outcomes for patients and providers alike. The next phase will focus on integrating AI into end-to-end care pathways rather than isolated use cases. The near future will see even deeper integration of machine learning into every aspect of healthcare, from personalized precision medicine to advanced robotic surgeries. There is also growing emphasis on responsible AI, including explainability and clinical accountability.

As the digital transformation of healthcare accelerates, innovators need infrastructure that can keep pace.

That’s where[Atlantic.Net](https://www.atlantic.net/) comes in. Whether you’re training large language models, deploying real-time diagnostics, or scaling AI-powered platforms, Atlantic.Net’s GPU cloud hosting, powered by NVIDIA, delivers the performance, flexibility, and reliability you need to bring your vision to life. Built to meet the highest standards of data protection and regulatory readiness, Atlantic.Net’s hosting services are HIPAA audited, HITRUST certified, and fully compliant with SOC 2, SOC 3, PCI, and GDPR, making it ideal for healthcare-grade AI innovation.


---

# GPU Hosting for AI Projects: Top GPU Hosts for AI in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/gpu-hosting-for-ai-projects-top-gpu-hosts-for-ai/ | Published: 2026-04-25 | Updated: 2026-04-26 | Author: Richard Bailey

Training AI models, creating complex deep learning networks, and processing the large-scale datasets required for AI applications demands a significant level of processing power, often exceeding the capabilities of traditional server hardware. As AI adoption scales in 2026, compute demand is increasing not just for training but also for real-time inference workloads.

The Graphics Processing Unit (GPU) has become instrumental for AI and ML development in recent years. Initially engineered for gaming and rendering visuals, GPUs possess a complex architecture that’s optimized for the mathematical operations needed by AI workloads. In 2026, GPUs remain the standard for both training large models and serving production AI systems.

To unlock the full potential of AI workloads, organizations can deploy on cloud GPU hosting ([such as Atlantic.Net GPU Hosting](https://www.atlantic.net/gpu-server-hosting/)) for its scalable, cost-effective, and high-performance infrastructure. Cloud-based GPU access is now the default approach for most AI teams rather than on-premise deployments.

In this article, we’ll cover:

- Why GPUs outperform traditional CPUs for demanding AI workloads.
- The key advantages of accessing GPU instances via the cloud.
- A comparison of leading cloud GPU providers for AI projects.
- Factors in selecting the right GPU options, including examples of the best GPUs.
- Major AI applications where GPU acceleration provides significant benefits.
- Important considerations around environment setup, data security, and cost management when using cloud GPUs.

## **CPU and GPU Role in AI**

While Central Processing Units (CPUs) have traditionally been the primary workhorse in the data center, their architecture introduces some limitations when working with AI. The power of the CPU is still important, but the GPU has emerged as the king for processing AI tasks. This gap has widened further in 2026 as AI models grow in size and complexity.

- **Sequential Tasks:** CPUs are designed with fewer, but very powerful cores optimized for handling tasks one after another.
- **Parallelism:** Many AI and ML tasks, especially model training and deep learning, involve performing the same calculation across vast amounts of data simultaneously (like large-scale matrix operations).
- **CPUs Struggle with Parallel AI Tasks**: Their sequential design makes them inherently less suited for the massive parallelism required, leading to longer processing times.

In contrast, GPUs offer a different approach:

- **GPU Parallel Architecture:** GPUs contain thousands of smaller, specialized cores (like CUDA cores and Tensor Cores).
- **Simultaneous Calculation:** GPU architecture enables parallel processing at scale, executing thousands of calculations per second.
- **Faster for AI:** GPU acceleration makes them significantly faster than CPUs for the intense parallel tasks associated with AI and ML.

While CPUs remain important for general system operations, specialized GPU instances deliver the specific compute power needed for demanding AI workloads, drastically reducing calculation times.

## **Understanding Cloud GPU Hosting**

Cloud GPU hosting is a service where cloud providers offer remote access to high-powered GPU resources in a [secure data center](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/). This lets organizations bypass the substantial investment and overhead of managing on-premise GPU servers by allowing them to rent cutting-edge hardware on demand via the cloud.

This model is now widely used by startups and enterprises alike as AI workloads move into production environments.

GPU Hosting introduces several advantages:

- **Increased Scalability:** Organizations can dynamically adjust GPU resources based on project demand, paying only for the compute capacity used.
- **Forget About Hardware Management**: Cloud hosting removes the complexities of purchasing, housing, cooling, powering, and maintaining physical GPU hardware. You can sit back and relax, leaving the[complexities to the experts](https://www.atlantic.net/managed-services/).
- **GPU Choice and On-Demand Support:** Cloud environments offer various GPU options, with hardware based on the latest technologies. Typically cloud GPU hosting offers efficient and highly optimized software stacks and a comprehensive level of technical support, helping you improve performance and simplifying deployment.

In 2026, many providers also include pre-configured AI environments to reduce setup time.

## **Choosing Your Cloud GPU Provider**

Now let’s take a look at what the biggest GPU Hosting providers have to offer.

Selecting the right cloud provider is an important decision for optimizing both performance and cost for your AI projects. While many providers offer GPU instances, their specific hardware offerings, pricing structures, geographical reach, management tools, and focus areas can vary significantly. In 2026, this decision increasingly depends on inference pricing, GPU availability, and deployment speed.

Here’s a comparative look at some big players in the AI GPU hosting market:

### **#1: Atlantic.Net:**

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

Atlantic.Net offers high-performance computing with dedicated and cloud servers powered by the latest and greatest of NVIDIA accelerated GPUs. Its GPU portfolio continues to align with current AI workloads such as LLM inference and fine-tuning in 2026. With a focus on providing great power and personalized support, this provider truly shines with a no-nonsense approach to high-end computing. The GPU hosts all had the industry-leading NVIDIA H100 NVL or L40S GPU inside, making them extremely well-suited for demanding generative AI workloads, large language model (LLM) training and inference, natural language processing (NLP), high-performance computing (HPC), and advanced graphics rendering. If there is one thing that complements powerful hardware better, it’s expert support and impressive uptime SLA. Such Service Level Agreements ensure an ideal, robust environment for mission-critical projects. Atlantic.Net somehow combines affordability with impeccable, expert-driven service.

Below is Atlantic.Net’s cloud control panel interface used to deploy and manage dedicated and GPU servers.
 ![Atlantic.Net Server Panel](https://www.atlantic.net/wp-content/uploads/2026/01/Atlantic.net-server-panel.png)
 Image Source: Atlantic.Net

### Advantages:

- **Leading Hardware:** Offers direct access to some of the most powerful and sought-after NVIDIA GPUs, such as the H100 NVL, right from the marketplace for top-tier performance on demanding AI training and inference tasks.
- **Expert, Personalized Support:** Offers a high-touch support model, giving access to skilled engineers directly, which is priceless for teams needing guidance on complex deployments, performance optimization, and troubleshooting.
- **Transparent and Competitive Pricing:** Clearly projects transparent, straightforward pricing, often considerably more economical than larger hyperscale providers, whereby high-performance computing is made accessible without complex billing.

### Suitable For:

- **AI Startups and Research Teams:** These are organizations that badly need elite-level GPU power for their research and development but will prefer a provider which has easy pricing with dedicated technical support to speed up their projects.
- **High-availability** businesses that offer highly demanding requirements requiring powerful hardware with a strong uptime guarantee to ensure good uptime and performance consistently for mission-critical AI applications.
- **Large Language Model and Generative AI Development Team**s: Teams working on developing and fine-tuning large language models or other generative AI systems to take advantage of the full capabilities provided by the H100 and L40S GPUs’ high levels of VRAM and Tensor Core count.

### **#2: Amazon Web Services (AWS):**

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)
 As the long-standing market leader, AWS provides an extensive choice of cloud services. EC2 offers various GPU instance families, such as the P4 series (NVIDIA A100), P5 series (NVIDIA H100), and G5 series (NVIDIA A10G), catering to diverse AI/ML training, inference, and graphics workloads, but its pricing models (On-Demand, Reserved Instances, Savings Plans, Spot Instances) can be complex to navigate and very expensive. In 2026, AWS continues expanding its AI infrastructure with newer GPU instance types and optimized AI services.

Here is the AWS EC2 dashboard, where you can control instances, monitor status, and configure settings.

![AWS Instance](https://www.atlantic.net/wp-content/uploads/2026/01/AWS-Instance.png)

Image Source: AWS

### Advantages

- **Huge Service Platform**: With this, it provides frictionless integration with the industry’s largest portfolio of cloud services: S3 for storage, SageMaker for ML pipelines, and Redshift for data warehousing, among others, to develop an integrated end-to-end platform.
- **Global Reach and Scalability:** Offers the ability to deploy GPU instances in several geographic regions, delivering low latency to global users and essentially limitless scalability for large AI training clusters.
- **Variety of Instance Types:** Delivers very fine granularity in choosing between GPU instances to allow teams to perfectly match their hardware-from older, cheaper GPUs all the way to the most recent H100s-to the exact performance and cost requirements of a given workload.

### Ideal for:

- **Large Enterprises:** These have a considerable investment in the AWS ecosystem, who can deploy and manage AI workloads at scale by effectively leveraging their existing infrastructure, billing arrangements, and internal expertise.
- **Complex, integrated workflow**s are projects requiring more than pure computing power to be harnessed into a wide array of other managed services for data processing, application hosting, and automation of DevOps.
- **Diverse Teams:** Those who use a wide range of AI applications, from very low-cost inference endpoints to massive, multi-node training jobs, and can benefit from having all the options from the one provider.

### **#3: Microsoft Azure:**

**![](https://www.atlantic.net/wp-content/uploads/2025/05/azure.png)**
 Azure is another major cloud platform with deep integration within the Microsoft products. Azure offers N-series virtual machines equipped with a range of NVIDIA GPUs (e.g., T4, V100, A100, H100). It’s a great choice for businesses already embedded in Microsoft platforms, and the Reserved GPU pricing is competitive. However, limited open source support is available and typically costs more than their competitors. Azure’s AI ecosystem continues to grow in 2026 with tighter integration across enterprise tools and AI services.

Explore the Azure dashboard to organize resource groups, track usage, and manage cloud services from a centralized platform.

![Microsoft Azure](https://www.atlantic.net/wp-content/uploads/2026/01/Microsoft-Azure.png)

Image Source: Azure

### Advantages:

- **Deep Integration with Microsoft Products:** Provides unparalleled native integration with essential enterprise tools like Azure Active Directory, Office 365, and Microsoft’s suite of data platforms for frictionless security, identity management, and data workflows.
- **Strong Enterprise and Hybrid Cloud Focus:** It provides robust solutions for hybrid cloud deployments, hence, the provision of Azure Arc, which enables each business to manage on-premise and cloud GPU resources through one control plane.
- **All-in-One AI Platform:** Hosts the Azure Machine Learning platform for end-to-end model creation, publishing, and management; it will certainly fit into large enterprise desires seeking a totally managed AI lifecycle.

### Ideal for:

- **For enterprises** with deep commitment to the Microsoft stack, including Windows Server and SQL Server: They can quickly drive their AI initiatives by leveraging existing licenses and expertise on a platform they know.
- **Hybrid Cloud Environments:** For organizations that require keeping a mix of on-premise infrastructure with cloud resources due to regulatory, performance, or data sovereignty reasons and at the same time unify their manageability.

### **#4: Google Cloud Platform (GCP):**

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)
 GCP is great at data analytics, AI/ML tooling (e.g., Vertex AI platform), and high-performance networking. Their Compute Engine instances are available with NVIDIA GPUs (A100, T4, L4, H100) and also offer their proprietary Tensor Processing Units (TPUs) optimized for specific ML frameworks like TensorFlow. GCP features a strong global network and good availability, however, like all of the major cloud providers, they are expensive. In 2026, TPUs remain a strong alternative for specific ML workloads, particularly within Google’s ecosystem.

Manage cloud services with the Google Cloud dashboard, where you can create virtual machines, deploy applications, and analyze data using built-in tools.

![Google Cloud Dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Google-Cloud-Dashboard.png)

Image Source: Google Cloud

### Advantages:

- **AI and Data Tooling:** Provides the Vertex AI platform, a unified and powerful managed environment for the entire ML lifecycle, along with data analytics services like BigQuery
- **Access to Custom-Built TPUs:** Offers Tensor Processing Units (TPUs) as an alternative to GPUs, which can deliver good performance-per-dollar for training large models built with frameworks like TensorFlow and JAX.
- **High-Performance Networking:** Boasts a global fiber optic network that provides low latency and high throughput, which is an advantage for distributed training jobs that span multiple GPU or TPU nodes.

### Ideal For:

- **Data-Centric Organizations:** Companies whose AI strategies are deeply intertwined with large-scale data processing and analytics, allowing them integration between BigQuery and Vertex AI.
- **TensorFlow and JAX Developers:** Research and development teams that build their models using Google’s native frameworks and can take full advantage of the performance benefits offered by TPUs.
- **Large-Scale Distributed Training:** Projects that require training massive models across hundreds or thousands of nodes, where GCP’s high-performance networking and infrastructure can significantly reduce training times.

### **#5: Vultr:**

**![](https://www.atlantic.net/wp-content/uploads/2025/04/vultr.png)**
 A provider known for its developer-friendly approach and good pricing across a wide global network of data centers. Vultr has significantly expanded its NVIDIA GPU service (including A16, A40, A100, L40S, H100, GH200) and AMD Instinct accelerators (MI300X, MI325X). They offer both virtual machines and bare metal options, appealing to users seeking cost-effectiveness. One downside is that there is often limited capacity in specific regions, so double-check that your chosen region is available. Vultr continues expanding its GPU catalog into 2026, including newer NVIDIA and AMD accelerators.

Here is the Vultr cloud hosting interface. Where you can deploy new instances, manage Kubernetes clusters, and control storage and networking services.
 ![Vultr dashboard](https://www.atlantic.net/wp-content/uploads/2025/05/Vultr-dashboard.jpg)
 Image Source: Vultr

### Advantages:

- **Transparent Pricing:** Known for its clear, predictable billing model makes an attractive option for developers and startups who are highly sensitive to cost.
- **Broad GPU Selection (NVIDIA & AMD):** A diverse hardware selections, including the latest GPUs from both NVIDIA and AMD, providing users with more options to find the perfect price-to-performance ratio for their needs.
- **Bare Metal Options:** Provides dedicated bare metal servers, giving users direct, un-virtualized access to the underlying hardware for maximum performance and control over the software stack, which is ideal for specialized or performance-critical workloads.

### Ideal For:

- **Developers and Startups:** Individuals and small teams looking for an easy-to-use platform with affordable, on-demand GPU resources without the complexity and overhead of the larger cloud providers.
- **Cost-Conscious AI Inference:** Applications that need to run inference at scale and can benefit from the cost savings offered by Vultr’s fractional GPU instances or lower-cost hardware options.
- **Users Needing Hardware Flexibility:** Teams that want to experiment with different GPU architectures, including AMD’s Instinct accelerators, or require the raw performance and customization only available with bare metal servers.

### **#6: Lambda Labs:**

![](https://www.atlantic.net/wp-content/uploads/2025/05/lambda.png)
 A specialized cloud provider explicitly focused on serving AI and ML developers and researchers. Lambda offers on-demand and reserved access primarily to high-end NVIDIA GPUs (including H100, A100, GH200, and newer models like H200, B200). They are known for their pre-configured environments (Lambda Stack with popular ML frameworks), ease of setting up multi-GPU clusters with high-speed interconnects (InfiniBand), and transparent hourly pricing, making them a popular choice for demanding training tasks. Lambda remains popular in 2026 for its simplified setup and early access to new GPU hardware.

Let’s see the Lambda interface for analyzing resource usage, managing filesystems, and monitoring spending across projects.
 ![Lambda gpu dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Lambda-gpu-dashboard.png)
 Image Source: Lambda

### Advantages:

- **Purpose-Built for AI/ML:** The entire platform, from hardware selection to the software stack, is designed specifically for AI researchers and developers, eliminating the unnecessary complexity found in general-purpose clouds.
- **Pre-configured Environments:** The Lambda Stack comes pre-installed with drivers, CUDA, and major ML frameworks like PyTorch and TensorFlow, saving developers hours or even days of setup time and allowing them to start training immediately.
- **Access to new GPUs:** Often among the first providers to offer access to the very latest and most powerful NVIDIA GPUs, making it a top choice for researchers who need state-of-the-art hardware for their experiments.

### Ideal For:

- **AI Researchers and Practitioners:** Individuals and teams whose primary focus is building and training deep learning models and who value a streamlined, hassle-free environment that lets them focus on their work, not on infrastructure management.
- **Demanding Multi-GPU Training:** Projects that require training large models across multiple GPUs, as Lambda makes it simple to provision multi-node clusters with the high-speed interconnects necessary for efficient distributed training.
- **Users Who Prioritize Simplicity and Speed:** Developers who want to avoid the steep learning curve and operational overhead of AWS, Azure, or GCP and prefer a straightforward, “it just works” solution for high-performance GPU computing.

### **Key Advantages of Using GPU Instances for AI/ML**

Although deploying GPU instances in the cloud involves costs, this expense is often much lower than anticipated and is accompanied by significant benefits:

- **Speed and Performance:**

Powerful GPUs dramatically improve the processing speed for AI workloads. Don’t just take our word for it; check out our [AI Procedures](https://www.atlantic.net/author/hitesh-jethva/) to experience the performance improvements today.

- **Scalability:**

AI projects have fluctuating needs. Cloud GPU hosting offers great scalability, allowing users to easily scale compute capacity on demand. Teams can start small and expand to multiple GPUs as models grow in complexity or datasets increase in scale.

- **Cost-Effectiveness:**

On-premise GPU clusters require significant upfront capital and ongoing costs. For example, an NVIDIA H100 GPU costs upwards of $25,000 at retail, and the NVIDIA L40S GPU costs about $10,000. Cloud GPU services use a pay-as-you-go model, making high-performance computing accessible and cost-effective without massive capital expenditure.

## **The Best GPUs for Your AI Applications**

There are plenty of choices when it comes to selecting optimal GPU instances. In 2026, selection decisions are increasingly based on workload type, especially training vs inference. You need to consider the best for both performance and cost-efficiency. The ideal choice depends on specific tasks: the type of AI workload (e.g., training and inference, computer vision, natural language processing), model complexity, and data volume.

Cloud providers present various GPU options, with NVIDIA GPU technology prevalent. Understanding different tiers is necessary. Top-tier performance might be needed for training deep learning models on large datasets, while AI inference might suit more balanced or cost-effective GPUs.

Let’s take a further look at the options available.

### **Spotlight on NVIDIA GPUs: The Industry Standard**

NVIDIA significantly leads the AI and high-performance computing (HPC) GPU market, built on powerful hardware and a reliable CUDA software ecosystem. CUDA enables developers to unlock the parallel processing capabilities of NVIDIA GPUs. Its dominance continues in 2026 due to both hardware performance and its CUDA ecosystem.

What to look for:

- **CUDA Cores:** Fundamental units for parallel execution; more cores generally mean higher computing power.
- **Tensor Cores**: Specialized cores accelerating the matrix operations foundational to deep learning, boosting deep learning performance.
- **High Memory Bandwidth**: Needed for rapid data transfer to keep cores fed, especially with large datasets.

High-end NVIDIA GPU models like the NVIDIA H100 NVL GPU represent the cutting edge for demanding AI workloads, including large language models (LLMs). Newer GPU generations are also emerging to address growing demand for AI compute.

Other models, like the NVIDIA L40S GPU, cater to graphics rendering and simulation, alongside AI development.

#### **Understanding GPU Specifications**

When evaluating GPU options, several technical specifications are important:

- **VRAM (Video RAM):** Dedicated GPU memory. Training large deep learning models or processing high-resolution data demands substantial VRAM.
- **Memory Bandwidth:** The speed of data transfer between VRAM and cores. High memory bandwidth is necessary for preventing bottlenecks with large datasets.
- **FLOPS (Floating-Point Operations Per Second):** Quantifies raw computational throughput.

Take time to analyze these specs when selecting your next GPU instance.

## **Core Applications Accelerated by GPU Hosting**

Cloud GPUs provide the necessary power for a wide range of computationally intensive tasks.

Here are some key areas where GPU acceleration makes a significant difference:

- **Deep Learning Model Training:** This is often the most demanding AI workload. Training deep learning models, especially large language models (LLMs), requires immense computing power (CUDA Cores, Tensor Cores), substantial VRAM to hold models and large datasets, and high memory bandwidth. High-performance GPUs, such as the NVIDIA H100 NVL GPU, are favored, and using multiple GPUs is common to reduce training time.
- **AI Inference:** Once a model is trained, AI inference involves using it to make predictions on new data. While still requiring significant compute for complex models or real-time processing, the priorities often shift to low latency (fast responses) and high throughput (predictions per second), potentially using different classes of GPU instances optimized for efficiency.
- **Machine Learning:** Beyond deep learning, many advanced machine learning models operating on large datasets benefit from GPU acceleration, speeding up model training and analysis compared to CPU-only approaches.
- **Computer Vision:** Analyzing images and video requires processing large amounts of data. GPUs excel here due to their parallel processing capabilities and high memory bandwidth, enabling tasks like object detection and real-time processing of visual streams. Ample VRAM is also often necessary.
- **Natural Language Processing (NLP):** Similar to general deep learning, training large NLP models demands lots of GPU resources. Inference for applications like translation or chatbots benefits from GPU speeds, often focusing on responsiveness.
- **Scientific Simulations & High-Performance Computing (HPC)**: GPUs are essential tools in high-performance computing tasks, driving complex scientific simulations in physics, chemistry, climate modeling, and more. These applications often need the maximum available computing power and benefit from the GPU’s ability to handle large-scale parallel processing.
- **Graphics Rendering & Simulation:** For tasks like high-fidelity 3D rendering, animation, or complex engineering simulations, GPUs designed with strong graphics capabilities, like the NVIDIA L40S GPU, provide the necessary performance.

## **Setting Up and Securing Your Cloud GPU Environment**

Transitioning to cloud GPU hosting involves careful planning for both setup and ongoing security.

### **Environment Setup:**

Select a cloud provider based on GPU instance availability, pricing, location, reliability, and support. Then, configure your GPU instance by choosing an OS, installing drivers (NVIDIA drivers, CUDA toolkit), and setting up AI ML libraries/ML frameworks (TensorFlow, PyTorch).

Many providers offer pre-built images or templates with the required software stack to accelerate deployment and provide faster deployment times.

### **Ensuring Data Security in AI Models:**

It’s critical to secure your configured environment, especially when handling sensitive data or when adhering to regulations (GDPR, HIPAA, CCPA) or meeting compliance requirements.

Implement these key data security best practices for added protection:

- **Encryption:** Use strong encryption for data at rest and in transit.
- **Identity and Access Management (IAM):** Apply least privilege principles with strong authentication and role-based access controls for GPU instances, storage, and data.
- **Network Security:** Use VPCs, strict firewall rules, and private endpoints to isolate GPU resources.
- **Monitoring, Logging, and Auditing:** Log activities, monitor for anomalies, and conduct regular audits to meet compliance requirements.
- **Secure Artifact Management:** Store trained AI models and scripts in secure repositories.

In 2026, AI governance and model monitoring are becoming standard security practices.

## **Conclusion**

GPU hosting is foundational for advancing artificial intelligence. Accessing vast parallel processing power and specialized compute via the cloud allows organizations to tackle complex problems faster.

Cloud GPUs provide the necessary infrastructure, scalability, speed, and performance for everything from deep learning research to real-time processing in AI applications. As AI systems move from experimentation to production in 2026, reliable GPU infrastructure is a core requirement for success.

As AI and GPU capabilities co-evolve, their interdependence deepens, unlocking new possibilities.

Want to learn more about Atlantic.Net GPU Hosting? [Contact our team today](https://www.atlantic.net/about-us/corporate-contact/) to unlock our newest service.


---

# Best HIPAA-Compliant Email Service in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-email-service-in-2021/ | Published: 2026-04-25 | Updated: 2026-04-26 | Author: Dr. Rachael Bailey

## **What Is HIPAA-Compliant Email?**

HIPAA-compliant email should be used whenever Protected Health Information (PHI) is being sent or discussed. For an email service to be HIPAA-compliant, it should offer the necessary security measures including end-to-end encryption, access controls, multi-factor authentication, integrity controls, and a signed Business Associate Agreement (BAA). Modern HIPAA-compliant email platforms also increasingly include automated threat detection and advanced data loss prevention features to address evolving cybersecurity risks.

## **Why Emails Must Be HIPAA Compliant?**

Email communications are essential within the healthcare industry, allowing fast, secure and cost-effective communication between healthcare professionals and their patients. But with the security of patient data at the forefront of everyone’s minds, how do HIPAA guidelines affect the use of email within this sector?

[Standard email providers](https://www.neo.space/blog/best-email-for-small-business) do not offer their users a HIPAA-compliant service as standard, therefore healthcare organizations must research their options carefully to find a provider that complies fully with the HIPAA guidelines. This remains important as enforcement actions and data breach reporting requirements continue to increase in 2026.

## **Top 10 HIPAA-compliant Email Solutions**

To make this easier, we have compiled a list of top HIPAA-compliant email providers based on their best practices and the standard of service that they offer healthcare organizations. This list reflects current expectations for security, usability, and regulatory alignment in 2026.

## 1. Paubox

[Paubox](https://www.paubox.com/) provides healthcare organizations with an out-of-the-box and HITRUST CSF-certified HIPAA-compliant email service, securely and seamlessly encrypting all email traffic. Paubox is easy to set up and use and can integrate directly with popular existing email platforms, including Office 365 and G suite. [Paubox was rated as the #1 HIPAA Compliant Messaging and Email Encryption Software product](https://www.paubox.com/blog/the-g2-fall-2024-reports-are-out-and-paubox-is-a-leader-again) in the G2 Grid Reports, Fall 2020. All users of the paid subscription service receive a signed BAA. Paubox offers developers a Paubox Email API, allowing integration of a secure email service into their application. To mitigate insider threat risks, Email DPI enables monitoring of inbound and outbound emails. Recent platform updates have focused on improving deliverability without compromising encryption standards.

## 2. ProtonMail

ProtonMail was developed in Switzerland by a team of scientists and engineers from leading global research institutions. ProtonMail delivers a zero-access architecture, end-to-end encryption, storage in secure data centers, and self-destructing emails. When using this email service, no personally identifiable data is tracked or logged. As ProtonMail’s servers are located in Switzerland, user data is subject to Swiss data protection laws, some of the strictest in the world. Organizations should still confirm BAA availability and configuration requirements when using ProtonMail for HIPAA-regulated workflows.

## 3. Virtru

Virtru provides its secure email and file encryption products to over 6000 customers. This end-to-end encryption email platform can integrate seamlessly into existing G Suite and Outlook accounts, ensuring compliance with standards such as HIPAA and GDPR. Users will benefit from a signed BAA, access controls, and granular audit trails. Virtru continues to expand its secure data-sharing capabilities beyond email into broader collaboration environments.

## 4. Hushmail

Canadian-based Hushmail has been providing its clients with a cross-platform email encryption service for over 20 years. Serving organizations from industries including healthcare, finance, and law, Hushmail also offers secure web forms, electronic signatures, an email archive, and a signed BAA. This platform offers industry-leading security features, including OpenPGP encryption, a secure SSL/TLS connection, and two-step verification. Its healthcare-focused plans now include templates and workflows tailored for patient communication.

## 5. MailHippo

MailHippo provides an easy and affordable HIPAA-compliant email solution. It is very user-friendly, with no configuration or setup required, and allows you to keep your existing email account. Delivering end-to-end encryption, MailHippo works seamlessly across multiple devices from desktop to smartphone. As the platform is available as a 30-day free trial, users can ‘try before they buy.’ This simplicity makes it a practical choice for smaller practices with limited IT resources.

## 6. Egress

With offices in the UK and US, Egress provides email solutions to healthcare organizations, ensuring full compliance with HIPAA regulations. Egress uses contextual machine learning to gain real-time insights into their user’s behavior and data loss prevention tools to minimize insider threats. Notable features include AES-256 bit encryption both at rest and in transit, multi-factor authentication, and integration with Gmail and Outlook. Its adaptive security controls help prevent misdirected emails, a leading cause of healthcare data breaches.

## 7. NeoCertified

[NeoCertified](https://neocertified.com/) has delivered a commercial-grade secure communications platform to businesses, organizations, and individual users since 2002. Their HIPAA-compliant email service is provided through their Secure Email Portal or via integration with Gmail and Outlook. It offers audit and access controls, identity authentication, transmission security, a signed BAA, and access to 24/7 support. The platform remains a consistent option for organizations prioritizing reliability and compliance oversight.

## 8. Protected Trust

Protected Trust provides secure and encrypted email communication, ensuring compliance with HIPAA regulations in a simplified manner. With a fingerprint-secure app, Protected Trust provides access to your email through integration with multiple devices. As a community-driven platform, customers are able to contribute to modifications and improvements. Users are able to obtain a signed BAA. Its mobile-first security approach continues to appeal to distributed healthcare teams.

## 9. Aspida Mail

Based in North Carolina, Aspida Mail strives to deliver HIPAA-compliant solutions to healthcare organizations in an easy-to-use and affordable package. Aspida Mail is fully compatible with numerous devices and applications, allowing quick and seamless integration with existing infrastructure. The company also provides enterprise-grade data backup disaster recovery and business-class firewall protection. It is often selected by organizations looking for bundled security and continuity features.

## 10. MaxMD

MaxMD delivers a comprehensive suite of HIPAA-compliant security solutions to the healthcare sector. It is an Electronic Healthcare Network Accreditation Commission (EHNAC) accredited Health Information Service Provider (HISP), Registration Authority (RA), and Certificate Authority (CA), one of the first companies to achieve such accreditation. Their Max Direct mdEmail® solution offers the necessary HIPAA technical safeguards including email encryption, audit controls, and identity authentication, and a signed BAA will be issued once the service has been deployed. Its Direct messaging capabilities remain important for interoperability with healthcare systems.

## **Bonus**: Mailtrap

[Mailtrap](https://mailtrap.io/blog/hipaa-compliant-email/) is an email delivery platform for individuals, businesses, and developer teams who are looking to test, send, and control email infrastructure in one place. Its reliable SMTP service is one of its most prominent features. The platform has a free plan that allows users to send up to 1,000 emails per month, and also additional paid plans. It is primarily suited for testing and development rather than handling live PHI in production environments.

## Where Does Atlantic.Net Come In?

As a healthcare organization dealing with sensitive patient data, adhering to HIPAA regulations is essential. Choosing a leading HIPAA-compliant email provider, such as those discussed above, will ensure that your communications remain compliant. However, you must also choose a top [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) provider to secure the storage and handling of PHI.

The Atlantic.Net HIPAA Hosting platform can be used to self-host many of these email applications. With Paubox, Atlantic.Net has established a [partnership](https://www.atlantic.net/about-us/partners-directory/) where our sales engineers can work with Paubox to provide a secured and compliant hosting and email solution.

Atlantic.Net is one of the leaders within this space, offering fully compliant web and cloud hosting services for over 30 years. We hold both SOC 2 Type II and SOC 3 Type II certifications and are independently audited to ensure full HIPAA compliance. To find out more about the services that we offer, [contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)!

*This article was updated on April 25, 2026.*


---

# A Comprehensive Guide to Developing a Telemedicine Application in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/a-comprehensive-guide-to-developing-a-telemedicine-application-in-2021/ | Published: 2026-04-25 | Updated: 2026-04-26 | Author: Dr. Rachael Bailey

*Atlantic.Net has over 30 years of experience providing customer-oriented IT Solutions. We are renowned for our HIPAA-compliant cloud services, supported by a security-defined platform architected to the highest standards. Our HIPAA-compliant cloud is available as a managed service or via a self-service offering – the perfect choice for your next Telemedicine project.*

The COVID-19 pandemic and its necessary lockdown measures have resulted in the rapid global adoption of telemedicine solutions. Telemedicine tools limit patient and physician exposure to coronavirus while maintaining access to vital healthcare services.

Telemedicine has now matured into a core healthcare delivery model in 2026, driven by regulatory support, payer reimbursement expansion, and widespread patient adoption across both urban and rural populations.

With the telemedicine market projected to exceed USD 175 billion globally by 2026, investment in telehealth platforms continues to grow across startups, hospitals, and enterprise healthcare providers.

## What Makes Telehealth Apps So Popular?

The use of telehealth apps brings countless benefits to patients, physicians, and the healthcare system, including:

### 1. Improving patient access to healthcare services

Telemedicine has allowed patients to continue to access healthcare services despite the limitations of the current pandemic. Telehealth apps improve access for patients with disabilities, the elderly and vulnerable, and those living in remote locations. Virtual visits also allow patients to consult with their doctors without the need for childcare and time off work.

### 2. Reduced healthcare costs

Telehealth services can reduce costs for both the healthcare provider and their patient, removing the need for travel and expensive car parking charges. As virtual visits are typically less expensive than in-person consultations, financial barriers to treatment are broken down.

### 3. Improved quality of care and physician time management

Telemedicine tools allow patients to consult with leading physicians, regardless of their geographical location. These technologies also increase interdisciplinary collaboration and allow patient data to be efficiently accessed and shared. Telemedicine can help to improve patient outcomes by streamlining workflow and data management, allowing physicians to focus on providing their patients with an accurate diagnosis and an appropriate, personalized treatment plan.

### 4. Streamlined data management

Remote patient monitoring allows vast amounts of informative real-time data to be collected and stored. By using telemedicine apps, physicians and patients can easily and securely share data, informing healthcare decisions.

### 5. Improved patient engagement and satisfaction

The convenience and effectiveness of telehealth appointments appeal to physicians and patients alike. Recent studies (2024–2026) show sustained high satisfaction rates, with many patients preferring hybrid care models that combine virtual and in-person visits. According to [a study of 1000 patients](https://www.businesswire.com/news/home/20200624005096/en/New-Survey-Reveals-Patients-Overwhelmingly-Satisfied-Virtual), conducted on behalf of Kyruus in June 2020, telehealth visits resulted in high patient satisfaction, and patients reported that they were very keen to adopt virtual care in the future.

## What Should You Consider Before Developing Your App?

In a rapidly evolving market, your app must stand out among competitors. Healthcare Apps are unique as they are bound by specific laws designed to protect Protected Health Information (PHI). In this section, we discuss the measures you should take into account before developing your telemedicine app.

### 1. Adherence with regulatory compliance (HIPAA)

Your telemedicine app must adhere to all of the necessary regulatory requirements, such as HIPAA, HITECH, and CCPA. Navigating regulatory compliance can be a bit of a minefield, so you must research the appropriate guidelines and make sure that you fully understand them.

One of the quickest wins is to outsource the app hosting to a HIPAA-Compliant hosting company like Atlantic.Net. The healthcare app will still need to be built upon a HIPAA-defined framework, but making sure the hosting platform is compliant is an important first step that can save a lot of time.

### 2. Security

When developing a telehealth app, another significantly important consideration is how you will maintain the security of PHI. The primary goal of HIPAA compliance is to uphold the integrity of patient data. Both patients and physicians need to be able to trust that shared information remains safe and secure at all times. Modern telehealth platforms now implement zero-trust architecture, continuous monitoring, and AI-driven threat detection to reduce security risks.

Strict security measures should be implemented into your app, including encryption, secure multi-factor authentication measures, and possibly geolocation IP address security to allow only authorized traffic from a predefined IP range (over an encrypted peer-to-peer VPN tunnel).

Some of the key areas that should be at the forefront of a developer’s mind when it comes to Healthcare App security are:

- **User Controls:** Controls must be built in to protect unauthorized access to the application. Data should only be accessible by authorized personnel who have been pre-approved to access ePHI. This includes any in-scope member of the covered entity, typically doctors, nurses, physicians, and patients. Numerous administrative controls are required to document who these authorized users are, and what PHI they can access.
- Permission-based authority: It is an offense for an unauthorized user to access or change PHI; therefore, strict API controls must be implemented (GET/POST/PATCH, etc). A good example is a patient website where users can access and view medical test results or request repeat prescriptions. Application writers want the patient to access only data relevant to them.
- **Access Controls:** These work hand-in-hand with user authorization, with the key difference that application controls are written to restrict access to flagged confidential information. Code must be implemented that prevents the export of data, such as exporting to an Excel file or PowerShell or simply using copy & paste.
- **Encryption:** It is critical to ensure that the application database is encrypted if processing PHI, either in cache or at the database layer. Link sensitive data with a UID instead of a username, or at the least architect your system so data is not traceable back to a single user on a first name, last name basis. In the event the database is exploited, this will prevent hackers from being able to plainly see the data listed in the text; the data should be encrypted and need a key to decrypt as created.

### 3. Availability, reliability, and uptime

After the telemedicine app has been deployed, it must be adequately supported to ensure that users are offered reliable service. Partnering with a reputable and experienced HIPAA-Compliant managed hosting provider will help to ensure that your telehealth app is a success.

Atlantic.Net is a leading and trusted hosting solutions provider, offering a class-leading [100% uptime Service Level Agreement](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/). Our data centers are built to the highest of standards with security and high availability at the forefront of the design process. All the infrastructure is failsafe and highly redundant. We have dual power feeds from different power grids, redundant cooling and airflow systems, and each server, storage device, or network stack has at least one failover pair (in most cases it’s two or three!)

### 4. Know your target demographic

Before developing your app, you should spend some time defining your target audience. To ensure that your app is optimized to meet the user’s specific needs, you should consider demographics such as their age, income, and geographical location. Modern telemedicine apps also consider digital literacy, device usage patterns, and accessibility requirements such as multilingual support and voice interfaces. You should also make sure that you have a clear and [well-thought-through business plan](https://thrivemyway.com/business-plan-software/) before starting to develop your telemedicine app.

### 5. Scalability

Many custom telemedicine app developers forget the importance of scalability when building their platform. If your app quickly increases in popularity and your user base grows, the app must be scalable and consistent when rapidly scaling resources. Cloud-native architectures using containers (e.g., Docker) and orchestration platforms (e.g., Kubernetes) are now standard approaches for scaling telemedicine applications efficiently.

Scalability should be considered early in the design process of the app to negate the need for a complete rebuild further down the line. The easiest way to achieve scalability is to have an application that can live on multiple servers, commonly broken down into the frontend (a web server such as Apache/Nginx), the mid-tier (this is the programming layer), and the backend (typically a database such as MySQL). Providing the application is architected in a similar way, you can scale up your environment as much as you like.

### 6. Are you using robust and scalable cloud technology?

Cloud technology delivers a plethora of benefits to healthcare providers, including scalability, enhanced security, data interoperability, and efficient data storage. A cloud-based telemedicine app facilitates the sharing of patient data and enhances accessibility, allowing physicians to provide prophylactic and recovery advice in addition to active treatment.

You should research your choice of cloud provider carefully to ensure that they meet the specific needs of your app. The hosting provider must be HIPAA-Compliant and include all the mandatory administrative, technical, and physical safeguards of HIPAA.

### 7. What is your redundancy plan if something goes wrong?

You have your application up and running, but what do you do if you hit a major outage? Disaster Recovery is referenced directly in [HIPAA legislation](https://www.hhs.gov/sites/default/files/hipaa-simplification-201303.pdf): “Assess the relative criticality of specific applications and data in support of other contingency plan components”. Modern disaster recovery strategies now include automated failover, real-time replication, and defined RTO/RPO targets aligned with healthcare SLAs.

HIPAA legislation demands that PHI should be available at all times in the event of a crisis. There are typically two ways to do this. The first is to have a daily backup schedule that protects the integrity of PHI data, this data should be replicated offsite for added protection.

Backups are great, and with cloud providers like Atlantic.Net, the backup recovery times are very competitive, but there might be a better way. Atlantic.Net offers additional managed services that provide disaster recovery capabilities to the platform, enabling the failover of infrastructure to an alternative location if the worst should happen.

## Developing a Telemedicine App: What is a Good Tech Stack?

To ensure the best user experience and optimal functionality, you must choose the best app development stack. A good tech stack will ensure that your app is scalable, user-friendly, dynamic, and robust. So, how do you choose the right tech stack for your telehealth app?

A good tech stack for the development of a competitive telemedicine app would include:

### 1. Managed Firewall

A professionally managed firewall service gives the client peace of mind that each layer of the network is protected to the highest of standards. The network stack should be managed by an experienced network engineering team and should be designed to be logical, robust, and completely secure.

Atlantic.Net offers a fully managed firewall stack connected to the Atlantic.Net network, isolating your traffic from all other traffic. A redundant firewall stack configuration is available upon request; this service is designed with optimal affordability and security in mind.

Our proprietary stateful firewall enables us to provide our clients with customized solutions. One-size-fits-all does not apply here; we strive to go beyond basic security protocols and do more than necessary to keep you secure and in business.

### 2. Backend Infrastructure

Choosing a PHP framework will help to minimize cost and still allow you to create an effective and powerful telemedicine app. Laravel is one of the most popular and compatible PHP frameworks, favored by telemedicine app developers. With a selection of built-in integrations, Laravel helps to automate repeated procedures, such as authentication, routing, and caching, and to streamline workflow.

Atlantic.Net provides super-simple one-click applications that can help when using the PHP framework. We have LAMP (Apache) and LEMP (Nginx) stacks that start in less than 30 seconds, not only a perfect solution for rapid testing and development but also a pre-baked, security-enhanced cloud image that handles production workloads with ease.

### 3. Front-end Infrastructure

App development can be a long and difficult process, so you should choose a front-end framework that makes this as easy as possible. The Javascript-based, open-source React and React Native frameworks help to build a high-performing and scalable app. Frameworks like Next.js and modern frontend tooling are increasingly used to improve performance, SEO, and user experience across devices.

If you prefer using NodeJS instead of React, Atlantic.Net has you covered, we feature a one-click NodeJS base image that will launch in seconds, we also feature a number of beginner to advanced [users](https://www.atlantic.net/vps-hosting/how-to-set-up-apache-as-frontend-proxy-server-for-node-js-centos-8/) in our [technical blog](https://www.atlantic.net/blog/).

### 4. Cloud-Based Services

Employing cloud-based services in the development of a telemedicine app addresses data security concerns, improves data accessibility, and ensures high performance and seamless scalability. Serverless computing and managed cloud services are now commonly used to reduce infrastructure overhead and speed up development cycles.

The cloud platform empowers your developers to focus on writing code instead of battling the infrastructure, and the flexibility of a cloud service gives engineers the ability to conduct rapid testing and development in an agile environment.

### 5. Programming Languages

Various programming languages can be used in the development of a telehealth app, including Java and Kotlin (Android), and Swift (IOS). Additionally, TypeScript and Python are widely used in 2026 for building scalable APIs and integrating AI-driven features.

## What Other Technologies Are Used in Telemedicine App Development?

Additionally, your app may include tech used for the development of specific features, such as:

- **WebRTC**

WebRTC is an enabling technology for both web browsers and mobile apps, using basic application programming interfaces (API) to allow real-time communication, with features such as video and voice calling.

- **Electronic Health Record (EHR) integration**

Patients’ EHR and Electronic Medical Record (EMR) may be securely stored in digital form using technology, such as Rails and GraphXL.

- **Geolocation**

Embedding the Google Maps platform into your app will give access to real-time data for a patient’s location and the location of their nearby healthcare services.

- **Secure payment gateway**

To allow ease of payment, you will need to integrate suitable and secure international and national payment gateways into your apps, such as Stripe, Authorize.Net, PayPal, and ApplePay.

- **AI**

Implementing AI into your telemedicine app can improve a patient’s diagnosis and treatment recommendation. AI can also be used to automate administrative tasks, helping to maximize physicians’ time. You should consider building an AI chatbot into your app to provide rapid and clear answers to your user’s questions.

- **VR/AR**

Mixed reality technologies can also help to improve diagnoses by providing physicians with access to real-time patient data. Health sectors where this technology may have particular benefits include mental health and sports rehabilitation.

- **Automatic Logout**

A key design decision is to include an automatic logout function. This may seem like common sense, but setting a timeout is required for compliance. Session management policies are now stricter, often requiring adaptive authentication based on user behavior and device trust levels. Hospitals do not want strangers accessing PHI simply because a user forgot to log out of a terminal. After being timed out, typically between 30 seconds and 3 minutes of inactivity, the user will need to re-authenticate using Multi-Factor Authentication.

## Steps to Take When Building Your Telemedicine App

In the section below we give a summary of the steps involved in telemedicine app development, a process that can be broken down into two distinct stages – discovery and development.

### 1. Discovery

Before reaching the development stage, it is vital that you carefully evaluate your proposal, research the telemedicine market, and find out as much as you can about your competitors. Competitive analysis now includes benchmarking against digital health platforms offering integrated services like e-prescriptions, remote diagnostics, and AI triage.

You should start by defining your target audience – will your app focus on a specific demographic, such as the elderly or those with a chronic health condition?

You should also think about what your telemedicine app will do. The majority of telemedicine apps help to facilitate remote appointments between a physician and their patients. However, as you will be entering a highly competitive space, you will want your app to stand out amongst its competitors. So, how is your app going to be different from others already available on the market? What is the Unique Value Proposition (UVP) of your app?

Once you have carried out your preliminary research, you need to form a clear business plan, including details about costs, revenue, and required resources.

The final part of the discovery stage is creating a low-fidelity prototype of your app to fully understand its functionality and test for any bugs. Following this, you can move on to developing a UX design and finally a high-fidelity prototype.

### 2. Development

As the name suggests, this stage is where the app development finally begins. During this phase, multiple software development experts will work together in the deployment of your app. Detailed quality assurance and testing will be carried out on various devices and the ongoing support and maintenance of your app will be considered.

## How Much Does It Cost to Build and Maintain a Successful Telemedicine App?

It is difficult to define how much it will cost to develop a telemedicine app, as this depends on:

- Choice of the technology stack
- Cost of the development team
- The complexity of the app’s features and functionality
- Cost of any third-party services, such as Google Maps
- Length of time it takes to develop the app

In 2026, cost planning should also include ongoing expenses such as cloud scaling, compliance audits, cybersecurity tools, and AI model integration. When working out the cost of your telemedicine app project, you should consider what parts of the development you can complete yourself and what you would need to outsource. You should research your options for a HIPAA-compliant cloud hosting provider carefully to ensure value for money – Atlantic.Net always strives to be the most cost-effective hosting partner.

## Partnering With Atlantic.Net

With over three decades of experience, Atlantic.Net is a global cloud services provider that has formed strong partnerships with a significant number of leading healthcare clients.

As you embark on your telemedicine app development project, Atlantic.Net can offer you market-leading services, including HIPAA-compliant dedicated and cloud hosting. [Contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) to find out how Atlantic.Net can help you.

Learn more about our [HIPAA compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions.

*This article was updated on April 25, 2026.*


---

# Using SIEM for Compliance in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/using-siem-for-compliance-in-2025/ | Published: 2026-04-25 | Updated: 2026-04-28 | Author: Gilad Maayan

## What Is SIEM?

Security Information and Event Management (SIEM) is a cybersecurity solution that provides real-time analysis of security alerts, log management, and incident detection across an organization’s IT infrastructure.It help organizations meet compliance requirements by collecting, analyzing, and storing log data across their infrastructure. In 2026, SIEM is considered a baseline requirement for regulated environments rather than an optional layer—it supports audit readiness, detects suspicious activity in real time, and simplifies reporting for standards like HIPAA, PCI DSS, GDPR, and ISO 27001. A properly configured SIEM centralizes visibility, enforces retention policies, and automates alerts, making it easier to prove compliance and respond to incidents quickly.

[SIEM cyber security processes](https://www.cynet.com/siem/siem-cyber-security-capabilities-4-common-challenges-solutions/) work by collecting logs and event data from various sources, such as firewalls, servers, applications, and endpoint devices. It then creates a baseline and correlates this data to identify potential security threats, policy violations, and compliance risks. By using predefined rules, machine learning, and analytics, SIEM detects anomalies, generates alerts, and enables incident response.

Organizations deploy SIEM for several purposes, including threat detection, forensic investigations, compliance reporting, and security monitoring. Current deployments often integrate with automation and orchestration tools (SOAR) to accelerate response times and reduce alert fatigue. Modern SIEM solutions integrate with threat intelligence feeds and automation tools to improve detection accuracy and reduce response time.

## Why SIEM Is Essential for Regulatory Compliance

Many organizations face strict regulatory requirements, making it critical to ensure compliance with security standards. Security information and event management solutions help to monitor security events, detect threats, and maintain detailed logs necessary for audits.

SIEM provides real-time analysis of security alerts, consolidating logs and event data from various systems. This centralization supports compliance with regulations such as GDPR, HIPAA, PCI DSS, and SOX, which mandate strict security controls and detailed record-keeping. Regulators now expect continuous monitoring and rapid incident detection, which aligns directly with SIEM capabilities. By automating data collection, normalizing logs, and generating compliance-ready reports, SIEM simplifies adherence to these regulations.

Key benefits of SIEM for compliance include:

1. **Centralized data collection:** SIEM aggregates logs from different hardware, software, and cloud platforms, ensuring visibility into security events across an organization’s entire IT environment.
2. **Real-time monitoring and alerting:** It detects security breaches and policy violations as they occur, enabling swift responses to prevent compliance violations.
3. **Automated compliance reporting:** SIEM generates detailed audit reports with minimal manual effort, ensuring accuracy and consistency in meeting regulatory requirements.
4. **Long-term log retention:** Many regulations require organizations to maintain security logs for extended periods. SIEM ensures secure storage and easy retrieval of logs for forensic investigations and compliance audits.

Without a SIEM system, compliance management becomes complex and error-prone, especially for large enterprises dealing with vast amounts of security data. As data volumes and regulatory scrutiny increase, centralized monitoring is now expected rather than optional in most audited environments. By integrating SIEM, organizations can simplify compliance efforts while strengthening their cybersecurity defenses.

## Core Components of SIEM for Compliance

A security information and event management (SIEM) system consists of several key components that ensure compliance with regulatory standards. These components help organizations collect, analyze, and report security data while maintaining a strong security posture.

1. **Log collection and management**: SIEM collects logs from various sources, including network devices, servers, applications, and databases. These logs capture user activities, system events, and security incidents across the IT environment. Centralizing logs in one place allows organizations to analyze historical data, ensuring visibility into security events for compliance audits and investigations.
2. **Event correlation**: SIEM uses algorithms and predefined rules to correlate seemingly unrelated logs, identifying patterns and anomalies that indicate security threats. By analyzing data across multiple systems, SIEM detects complex attacks, unauthorized access, and system misconfigurations that might otherwise go unnoticed with manual log reviews.
3. **Real-time monitoring**: Continuous monitoring enables organizations to detect security threats and compliance violations as they occur. By identifying abnormal behavior in real time, SIEM reduces the window of exposure and allows for swift remediation before an incident leads to regulatory non-compliance or data breaches.
4. **Automated alerts**: SIEM generates instant alerts for suspicious activities based on deviations from normal behavior or predefined security rules. These automated notifications help organizations address policy violations and unauthorized access quickly, minimizing the risk of prolonged security exposure. Additionally, alerts and response actions are logged for audit purposes.
5. **Audit trails**: SIEM maintains detailed records of user actions, system modifications, and security events. These audit trails are essential for proving regulatory compliance by demonstrating accountability and transparency in data handling. They also support forensic investigations by tracking access to sensitive data and documenting security incidents.
6. **Compliance reporting**: SIEM solutions include reporting features that generate compliance-ready reports for standards like PCI DSS, HIPAA, and GDPR. These reports provide an overview of security events, policy violations, and response actions. Automated reporting reduces manual effort while ensuring organizations can present compliance documentation during internal reviews and external audits.

## Common Compliance Standards Addressed by SIEM

### SIEM for PCI DSS Compliance

The Payment Card Industry Data Security Standard (PCI DSS) mandates security measures for companies handling credit card transactions. SIEM helps meet PCI DSS requirements by tracking and managing user identities, detecting suspicious activity, and ensuring secure log storage.

Key SIEM features for PCI DSS compliance:

- **Log management:** Centralizes logs from all systems to meet **Requirement 10**, which mandates log tracking and monitoring.
- **User activity monitoring:** Tracks login attempts, privilege escalations, and access to payment data.
- **Threat detection & alerts:** Identifies unauthorized access or potential fraud in real-time.
- **Access control management:** Ensures proper user authentication and detects anomalies in account usage.

With SIEM, organizations can automate compliance reporting, maintain audit trails, and detect potential data breaches before they escalate, reducing the risk of **non-compliance penalties**.

### SIEM for HIPAA Compliance

The Health Insurance Portability and Accountability Act (HIPAA) protects the confidentiality of Protected Health Information (PHI) in healthcare organizations. SIEM improves HIPAA compliance by monitoring data access, detecting security breaches, and ensuring the integrity of electronic health records.

Key SIEM features for HIPAA compliance:

- **Threat detection & prevention:** Identifies cyberattacks, including ransomware and insider threats, that could expose PHI.
- **Log management & audit trails:** Ensures a record of system and user activity, crucial for compliance audits.
- **Access control monitoring:** Detects unauthorized access and tracks changes to user permissions.
- **Data exfiltration prevention:** Flags abnormal data movement to prevent breaches.

By automating security monitoring and reducing **false-positive alerts**, SIEM helps overburdened security teams focus on real threats, ensuring HIPAA-mandated data protection.

### SIEM for GDPR Compliance

The General Data Protection Regulation (GDPR) requires strict protection of Personally Identifiable Information (PII). SIEM helps organizations comply by tracking data access, enforcing security controls, and maintaining transparency in data processing.

Key SIEM features for GDPR compliance:

- **Data protection by design:** Audits security controls to prevent unauthorized access to personal data.
- **Log & access monitoring:** Tracks who accessed, modified, or transferred personal data.
- **Incident response & reporting:** Ensures organizations can detect and respond to data breaches within 72 hours, as required by GDPR.
- **Data flow visibility:** Provides insights into data movement across networks, ensuring compliance with GDPR’s transparency mandates.

SIEM enables organizations to demonstrate compliance, reducing the risk of massive fines like those imposed on Meta (€1.2 billion in 2022) for unauthorized data transfers.

### SIEM for SOX Compliance

The Sarbanes-Oxley Act (SOX) enforces controls on financial data security for publicly traded companies. SIEM helps meet SOX requirements by monitoring financial systems, detecting unauthorized access, and maintaining audit logs.

Key SIEM features for SOX compliance:

- **Access & privilege monitoring:** Tracks login attempts and changes to sensitive financial records.
- **Audit trails & compliance reporting:** Provides verifiable logs of financial data access and modifications.
- **Incident detection & alerts:** Identifies suspicious activity, such as unauthorized data transfers.
- **User activity analysis:** Monitors the actions of employees, third-party vendors, and former users.

### SIEM for NIST Compliance

The National Institute of Standards and Technology (NIST) Cybersecurity Framework provides best practices for securing IT environments, widely adopted across industries. SIEM helps organizations align with NIST’s Identify, Protect, Detect, Respond, and Recover framework.

Key SIEM features for NIST compliance include:

- **Protect:** Collects logs from access control systems to ensure proper security enforcement.
- **Detect:** Monitors IT environments for anomalies and potential security threats.
- **Respond:** Alerts security teams about incidents and provides forensic insights.
- **Recover:** Generates reports to assist in incident recovery and remediation.

### SIEM for ISO 27001 Compliance

ISO 27001 is an international standard for information security management systems (ISMS). SIEM helps organizations meet ISO 27001 requirements by centralizing security data, enforcing policies, and providing real-time monitoring.

Key SIEM features for ISO 27001 compliance:

- **Security data centralization:** Collects and secures logs across cloud and on-premises environments.
- **Threat intelligence & detection:** Identifies security incidents using predefined ISO 27001-aligned rules.
- **Incident response & reporting:** Supports forensic investigations and compliance documentation.
- **Access control & user monitoring:** Tracks login activities, privilege escalations, and unauthorized access attempts.

## Challenges in Implementing SIEM for Compliance

While SIEM solutions offer capabilities for regulatory compliance, their implementation comes with significant challenges. Organizations must weigh these difficulties against the benefits to determine if SIEM is the right fit for their compliance needs:

1. **High cost and complex deployment:** SIEM solutions are expensive, both in terms of initial investment and ongoing operational costs. Deployment can take anywhere from 6 to 12 months, with more complex implementations requiring even longer. Many organizations struggle to achieve a solid return on investment (ROI) due to stalled or unsuccessful SIEM projects.
2. **Continuous monitoring and maintenance:** Once deployed, SIEM requires regular updates and tuning to keep pace with evolving IT infrastructures, emerging threats, and changing compliance requirements. Maintaining a SIEM system can cost several times more than its initial purchase price, making it unaffordable for smaller businesses.
3. **Need for skilled SIEM professionals:** Managing a SIEM effectively requires specialized expertise. Organizations must either train existing IT staff or hire experienced SIEM professionals, who are both difficult to find and expensive to retain. Without the right personnel, a SIEM may fail to deliver the expected compliance benefits.
4. **Alert fatigue and false positives:** SIEM solutions generate a large volume of alerts, many of which are false positives. Security teams often struggle to triage and investigate every alert, leading to alert fatigue. This can result in genuine threats being overlooked, undermining both security and compliance efforts, though this is possible to mitigate by fine-tuning correlation rules, implementing threat intelligence feeds, using risk-based alerting, and implementing SOAR for automated triage.

## Best Practices for SIEM Implementation

Here are some of the ways that organizations can ensure effective SIEM implementation to improve compliance with cybersecurity regulations.

### 1. Map Compliance Requirements to SIEM Capabilities

Before deploying SIEM, organizations must clearly define their compliance requirements and ensure that SIEM functionalities align with these needs. Different regulations, such as PCI DSS, HIPAA, GDPR, SOX, NIST, and ISO 27001, have unique logging, monitoring, and reporting mandates.

To map compliance requirements effectively:

- **Identify key regulations:** Determine which regulatory frameworks apply to the organization based on industry and geographical location.
- **Define log sources:** Identify critical assets and systems (e.g., firewalls, databases, endpoint devices) that must be monitored to meet compliance requirements.
- **Ensure SIEM policy alignment:** Configure SIEM to generate reports, alerts, and log retention policies that comply with legal mandates. For example, GDPR requires organizations to detect and report data breaches within 72 hours, which means SIEM should support real-time monitoring and rapid response mechanisms.
- **Enable audit trails and reporting:** SIEM should generate automated compliance reports tailored to regulatory audits, reducing the need for manual effort.

### 2. Ensure Comprehensive and Secure Log Collection

SIEM is only as effective as the data it collects. Comprehensive log collection ensures that security teams have complete visibility into security events, enabling accurate threat detection and compliance verification.

To achieve secure and effective log collection:

- **Centralize logs from all relevant sources:** SIEM should collect logs from firewalls, intrusion detection/prevention systems (IDS/IPS), cloud applications, endpoint devices, identity and access management (IAM) systems, and network traffic monitors.
- **Normalize and correlate logs:** Different systems generate logs in varying formats. SIEM should normalize logs into a standardized structure for effective correlation and analysis.
- **Ensure secure log transmission and storage:** Use encryption (e.g., TLS, AES) to protect log data in transit and at rest. Implement access controls to prevent unauthorized log modifications or deletions.
- **Validate log integrity:** Apply cryptographic hashing or digital signatures to detect any tampering of collected logs.
- **Eliminate unnecessary data:** Configure log filtering to remove non-essential or redundant logs to optimize SIEM performance without losing critical information.

### 3. Ensure Proper Data Retention Policies

Compliance regulations mandate different log retention periods, ranging from several months to years. SIEM must be configured to store logs in a way that meets these requirements while optimizing storage and retrieval efficiency.

Key considerations for effective data retention policies:

- **Understand compliance-specific retention requirements:**
  - **PCI DSS** – Requires logs to be retained for at least one year, with at least three months of data readily available.
  - **HIPAA** – Security logs must be kept for six years in healthcare organizations.
  - **SOX** – Financial records and logs should be stored for seven years.
  - **GDPR** – Log retention should align with the organization’s privacy policies and data minimization principles.
- **Segment storage for performance optimization:** Store recent logs in high-performance storage for rapid query access, while older logs can be archived in cost-effective cold storage solutions.
- **Use tiered retention strategies:** Implement hot, warm, and cold storage tiers to balance cost and accessibility.
- **Automate log purging and archival:** Configure SIEM to automatically delete or archive logs that exceed retention periods to comply with data protection laws and prevent excessive storage costs.
- **Ensure secure and immutable log storage:** Use write-once, read-many (WORM) storage to prevent log tampering, which is critical for forensic investigations and compliance audits.

### 4. Conduct Periodic Compliance Audits and Assessments

A SIEM system should be continuously evaluated to ensure it remains compliant with evolving regulations and security standards. Regular audits help organizations detect compliance gaps before they lead to legal or financial penalties.

Best practices for compliance audits:

- **Schedule regular SIEM audits:** Conduct audits quarterly or annually, depending on regulatory requirements. Compliance teams should review log completeness, alert configurations, and reporting accuracy.
- **Validate log collection and correlation rules:** Ensure that SIEM is correctly ingesting logs from all critical assets and that correlation rules are detecting security threats as intended.
- **Assess incident response effectiveness:** Test SIEM’s ability to detect and respond to compliance-related incidents, such as unauthorized access attempts or data exfiltration.
- **Conduct internal and third-party audits:** While internal reviews help maintain daily compliance, hiring external auditors ensures unbiased validation of security controls and SIEM configurations.
- **Monitor policy changes and adjust SIEM settings accordingly:** Compliance regulations frequently change. Organizations should stay updated on regulatory updates and adjust SIEM settings to reflect new security requirements.

### 5. Provide Training for Security Personnel

Even the most advanced SIEM system is ineffective if security teams lack the expertise to configure, monitor, and respond to threats effectively. Regular training ensures that security analysts can maximize SIEM capabilities for compliance and threat detection.

Key areas of SIEM training:

- **Log analysis and threat correlation:** Teach security teams how to interpret logs, detect anomalies, and identify compliance violations using SIEM dashboards.
- **Incident response and alert triage:** Train teams to differentiate between true security threats and false positives, ensuring quick remediation of real incidents.
- **Compliance-specific reporting:** Educate personnel on how to generate regulatory compliance reports tailored for audits (e.g., PCI DSS, HIPAA, GDPR).
- **SIEM rule tuning and optimization:** Show IT teams how to create and modify detection rules to reduce noise and improve accuracy.
- **Simulated attack and response drills:** Conduct tabletop exercises and red-team simulations to test SIEM capabilities in real-world attack scenarios.


---

# The Best Bare Metal Hosting for AI Workloads in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/the-best-bare-metal-hosting-for-ai-workloads-in-2025/ | Published: 2026-04-25 | Updated: 2026-04-26 | Author: Richard Bailey

Artificial Intelligence (AI) workloads demand much higher computing resources than normal applications. For example, training a [deep learning](https://www.ibm.com/think/topics/deep-learning) model requires powerful processors and large memory. In addition, the processing of large datasets need steady throughput and fast input–output operations. Furthermore, real-time inference creates another challenge, since even minor delays can affect performance.

Modern AI workloads in 2026, especially generative AI and large language models, now require even higher GPU density, faster interconnects, and optimized storage pipelines to maintain performance at scale.

Virtualized cloud servers are not always the best option to meet such requirements. In shared environments, resources can fluctuate, which often results in longer training times and uncertain performance. For AI projects, these issues can reduce both efficiency and accuracy.

To that end, [bare metal hosting](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) appears a more suitable alternative. It offers dedicated physical servers without resource sharing. Providers such as [Atlantic.Net](https://www.atlantic.net) provide bare metal servers that give organizations full access to high performance computing resources and the flexibility to configure hardware according to their AI needs. This means all computing power is available to a single workload. It also allows customization of hardware according to the needs of specific AI frameworks. As a result, organizations can achieve faster processing, lower latency, and stable performance. Therefore, bare metal infrastructure has become a preferred choice for modern AI applications.

Bare metal adoption has increased as organizations shift from experimentation to production AI systems that require predictable performance and consistent throughput.

## What Makes Bare Metal Hosting Different?

Bare metal servers are physical machines that operate without hypervisors or shared resources. They provide exclusive access to hardware for a single user. Therefore, they offer several advantages that are highly relevant for AI workloads:

- **Direct access to hardware:** GPUs, CPUs, and NVMe storage are available without interference, which ensures maximum computational throughput.
- **No virtualization overhead:** Since there are no shared layers, resource contention is eliminated. This reduces latency and improves both performance and data handling.
- **Custom environments:** Users can install their own operating system and software stack. In this way, the environment can be tailored to the requirements of specific AI models.
- **Hardware-level control:** BIOS settings, memory allocation, and other configurations can be adjusted. This flexibility is essential for optimizing intensive AI computations.
- **Stronger isolation:** Dedicated physical servers also improve security and compliance. This is particularly important when working with sensitive datasets.

These characteristics are especially valuable when running GPU-intensive pipelines, distributed training jobs, or latency-sensitive inference systems in 2026.

**Table 1:** **Bare Metal vs. Virtualized Hosting**

| **Feature** | **Bare Metal Hosting** | **Virtualized Hosting** |
| --- | --- | --- |
| **Resource Sharing** | None (single-tenant) | Shared (multi-tenant) |
| **Performance** | Predictable, high throughput | Variable, subject to contention |
| **GPU/CPU Access** | Full passthrough | Often virtualized or restricted |
| **OS & Stack Customization** | Full control | Limited by the hypervisor |
| **Compliance & Isolation** | Strong physical separation | Logical isolation, less secure |

## Why AI Workloads Demand Bare Metal Servers

AI workloads are much heavier than everyday computing tasks. They also need specialized server infrastructure that can ensure reliable and consistent performance. Bare metal servers meet these needs well because they provide direct access to hardware without the limits of virtualization.

### GPU acceleration

Training and inference in AI rely on powerful GPUs, such as NVIDIA H100, A100, and L40S. Bare metal servers make these resources directly available. This ensures complete utilization of their computing power without loss from virtualization layers.

Newer deployments increasingly prioritize multi-GPU configurations with high-speed interconnects such as NVLink and PCIe Gen5 to support larger models and faster training cycles.

### High memory and bandwidth

AI projects often work with massive datasets and parallel tasks that have unique operational complexity. Therefore, they require fast memory and NVMe storage with stable throughput. Bare metal servers ensure this speed because resources are not shared with others.

High-bandwidth memory (HBM) and fast NVMe storage tiers are now standard requirements for handling large-scale AI pipelines efficiently.

### Low latency

Real-time AI applications, including fraud detection, autonomous systems, and live inference, depend on quick response. Since bare metal eliminates the delay caused by virtualization, performance remains predictable and fast.

This is especially critical for applications such as real-time recommendation engines, AI copilots, and streaming analytics systems.

### Scalability with precision

For larger projects, bare metal servers can be arranged in clusters to support distributed training. This makes it possible to expand computing power as required, while still keeping results consistent. Cluster orchestration tools such as Kubernetes and Slurm are now widely used to manage distributed AI workloads on bare metal infrastructure.

### Ensuring compliance through isolation

Some AI workloads involve sensitive data in healthcare, banking, or personal services. In such cases, bare metal servers are valuable because they provide physical separation. This helps organizations meet standards like HIPAA, PCI DSS, and SOC 2. Physical isolation continues to play a key role in meeting evolving regulatory expectations around data privacy and model governance.

In comparison, virtual cloud servers add extra layers that can cause delays and resource variation. This often results in unstable performance. For AI tasks, such uncertainty can reduce both speed and accuracy. Therefore, bare metal hosting has become a reliable choice to meet the requirement of high-end computing resources for AI tasks.

## Use Cases for Bare Metal Hosting in AI

AI workloads differ across industries, but many have similar infrastructure requirements. Bare metal servers meet these needs effectively in several demanding use cases.

### Training Large Language Models (LLMs)

Models such as GPT and BERT require large-scale parallel computing and high memory bandwidth. Multi-GPU bare metal setups with NVIDIA H100, A100, or L40S GPUs interconnected via NVLink or PCIe address these requirements well. They provide fast CPU–GPU communication, large, unified memory pools with DDR5 and NVMe storage, and optimized hardware for distributed training. Predictable scheduling with reduced jitter further ensures stable and efficient training.

### Real-Time Inference at the Edge

Applications such as autonomous driving, smart city systems, and fraud detection require responses within milliseconds. Bare metal servers are suitable for such tasks because they provide dedicated accelerators and support optimized runtimes like TensorRT and ONNX Runtime. As a result, inference pipelines are predictable and fast. Moreover, high availability and edge deployment with complete hardware control improve both reliability and compliance in critical environments. Edge AI deployments are expanding, with bare metal servers supporting inference closer to users to reduce latency and improve responsiveness.

### Federated Learning and Distributed AI

Federated learning makes it possible to train models together without sharing raw data. Clustered bare metal servers work well in this case. They give direct access to GPUs and CPUs for efficient local training and support fast communication between nodes. Hardware-level security features such as TPM also help keep data safe. This makes it easier to meet strict locality and governance rules, which are important in healthcare, finance, and government.

### AI in Regulated Industries

Industries such as healthcare, finance, and legal services face strict compliance requirements. Bare metal servers provide a robust solution because they offer physical isolation of workloads and complete control of hardware and networking. This makes it possible to apply encryption and other secure configurations directly. Furthermore, certified data centers strengthen audit readiness. In this way, organizations can build customized AI pipelines that handle sensitive data both safely and efficiently. Auditability and data traceability have become more important, making dedicated infrastructure a preferred choice.

## Top Bare Metal Hosting Providers for AI Workloads

### 1. Atlantic.Net

**![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)**
 Atlantic.Net offers bare metal and GPU servers built for AI and machine learning workloads. Its platform continues to evolve with improved GPU configurations and infrastructure designed to support modern AI pipelines in 2026. Its HIPAA-ready infrastructure and U.S.-based data centers make it a reliable option for regulated industries such as healthcare and finance. The platform is highly suitable for mission-critical AI tasks where both performance and compliance are essential. With flexible plans and strong regulatory support, Atlantic.Net serves the needs of mid-sized AI projects as well as large-scale enterprise deployments.

Below is Atlantic.Net’s cloud control panel interface used to deploy and manage dedicated and GPU servers.
 ![Atlantic.Net Server Panel](https://www.atlantic.net/wp-content/uploads/2026/01/Atlantic.net-server-panel.png)
 Image Source: Atlantic.Net

- **GPU acceleration:** Atlantic/Net supports [NVIDIA H100](https://www.atlantic.net/gpu-server-hosting/gpu-dedicated-hosting/) and L40S GPUs, which are among the most powerful options for AI tasks. These GPUs are best for deep learning, large language model training, and high-performance inference pipelines.
- **Compliance:** The infrastructure meets HIPAA, PCI DSS, and SOC 2 standards and makes it suitable for industries where security and data privacy are essential. This ensures that sensitive data can be processed and stored in accordance with strict regulatory requirements.
- **Custom builds:** Users can configure CPU, RAM, and NVMe storage according to the demands of their AI workloads. This flexibility helps teams to create an environment that matches their specific framework and performance needs.
- **Support:** Net provides 24/7 technical assistance to help with both routine and advanced issues. The service also includes operating system setup, licensing support, and guidance for optimizing server performance.
- **Bare metal pricing range:** Entry-level bare metal servers are available starting at about $412 per month. High-performance configurations can go up to around $1,150 per month, with further custom options available for enterprise-scale deployments.

### 2. IONOS

**![](https://www.atlantic.net/wp-content/uploads/2025/08/ionos-logo.png)**
 IONOS provides bare metal and GPU servers optimized for demanding workloads such as AI and machine learning. The platform continues to expand GPU and accelerator options to support both NVIDIA and alternative AI hardware ecosystems. With a strong European presence and ISO 27001-certified data centers across the EU, UK, and U.S., it is a reliable choice for organizations that must comply with GDPR and regional data sovereignty requirements. It is particularly suitable for AI teams working in Europe or in industries where strict data residency is necessary. By combining high-performance hardware with regulatory assurance, IONOS delivers a robust platform for both research and enterprise AI deployments.

Look at the IONOS Cloud control panel showing server image management, infrastructure configuration, and US data center deployment options.
 ![IONOS cloud panel](https://www.atlantic.net/wp-content/uploads/2026/01/IONOS-cloud-panel.png)
 Image Source: IONOS

- **GPU acceleration:** IONOS supports several advanced accelerators for deep learning and generative AI. These include NVIDIA H100 and H200 GPUs for large-scale AI training, NVIDIA L40S for inference and 3D workloads, and Intel Gaudi 2 and Gaudi 3 accelerators as an alternative to NVIDIA, offering flexibility for specific AI frameworks.
- **Compliance:** All data centers are ISO 27001-certified, following internationally recognized security practices. In addition, the infrastructure is entirely GDPR-ready, which is essential for organizations handling sensitive or regulated datasets.
- **Custom builds:** Users can configure their servers by selecting GPU type, CPU, RAM, and NVMe storage. This customization allows AI teams to design an infrastructure that meets the exact needs of their models and pipelines.
- **Support:** IONOS provides 24/7 technical support, with dedicated regional phone numbers for deployment and configuration assistance. This ensures consistent guidance and reliable help for AI teams operating across multiple regions.
- **Bare metal pricing range:** GPU servers start around [£550/month](https://www.ionos.co.uk/servers/gpu-server) for entry-level Tesla T4 configurations, scaling up to [£3,990/month](https://www.ionos.co.uk/servers/gpu-server) for H100/H200-powered servers.

### 3. CoreWeave

![](https://www.atlantic.net/wp-content/uploads/2025/05/coreweave.png)
 [CoreWeave](https://www.coreweave.com/) is a cloud provider explicitly established for GPU computing, offering both fractional and bare-metal GPU access. It has gained traction among AI teams working on large-scale generative models and high-throughput inference workloads. Its Kubernetes-native platform runs directly on bare metal, which allows AI workloads to scale efficiently without unnecessary overhead. With a focus on GPU-native performance and enterprise compliance, CoreWeave is widely used in generative AI labs, large language model training, and high-volume inference pipelines.

Here is the CoreWeave Cloud dashboard, where you can deploy GPU-powered virtual servers, manage storage, and monitor high-performance workloads.
 ![CoreWeave Cloud](https://www.atlantic.net/wp-content/uploads/2026/01/CoreWeave-Cloud.avif)
 Image Source: CoreWeave Cloud

- **GPU acceleration:** CoreWeave offers NVIDIA A100, H100, and L40S GPUs, which can be used either fractionally or as complete bare-metal resources. It also integrates NVIDIA DOCA and BlueField-3 DPUs to further improve performance for demanding AI tasks.
- **Compliance:** The platform follows enterprise-grade security practices and holds SOC 2 and ISO 27001 certifications. This makes it suitable for organizations that must maintain strict security and compliance standards while running advanced AI workloads.
- **Custom builds:** CoreWeave provides Kubernetes-native orchestration with support for tools such as Kubeflow, Slurm, and KServe. It also offers AI-optimized storage solutions, including AI Object Storage with LOTA caching, to handle large datasets efficiently.
- **Support:** Users benefit from specialized AI expertise and ongoing technical guidance. Real-time monitoring is available through its Mission Control system, which helps maintain reliability and performance during critical workloads.
- **Bare metal pricing range:** CoreWeave uses flexible usage-based pricing with clear billing structures. Fractional GPU access can start at just a few dollars per hour, while dedicated H100 clusters can scale into several thousand dollars per month, depending on configuration.

### 4. OpenMetal

**![](https://www.atlantic.net/wp-content/uploads/2025/09/OpenMetal.png)**
 [OpenMetal](https://openmetal.io/) provides on-demand hosted private cloud and bare metal solutions based on OpenStack and Ceph. Its approach appeals to organizations that want open-source flexibility while maintaining control over AI infrastructure. It combines the control of private infrastructure with the flexibility of the cloud, making it suitable for enterprises that need both performance and scalability. By avoiding the noisy neighbor effect of shared environments, OpenMetal ensures stable performance for demanding AI and machine learning workloads. It is particularly effective for mission-critical projects that require predictable costs, data control, and open-source flexibility. In addition, it prevents vendor lock-in and supports widely used AI frameworks such as PyTorch and TensorFlow.

Here is the OpenMetal dashboard, where you can manage hardware assets, monitor servers, and configure infrastructure resources.
 ![Openmetal-dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Openmetal-dashboard.png)
 Image Source: OpenMetal

- **GPU acceleration:** OpenMetal offers NVIDIA A100 and H100 GPUs, which can be deployed as standalone servers or within larger clusters. These configurations are highly effective for large language model training, distributed AI, and other intensive workloads.
- **Compliance:** The infrastructure provides enterprise-grade security with transparent pricing and complete hardware control. This makes it a strong option for industries such as healthcare, finance, and research, where data locality and security are essential.
- **Custom builds:** Deployments are fully customizable, with options for GPU counts, CPU and GPU pairings, and storage volumes. This flexibility allows organizations to align infrastructure with the requirements of specific AI pipelines.
- **Support:** Customers have access to engineering expertise for cluster design, deployment, and optimization. This guidance helps teams integrate AI workflows effectively and sustain performance at scale.
- **Bare metal pricing range:** GPU servers are billed on a fixed monthly basis, avoiding the unpredictability of usage-based billing. A single A100 80GB server is priced at about [$2,234.88 per month](https://openmetal.io/gpu-servers-clusters-pricing/), while a single H100 PCIe server costs around $2,995.20 per month.

### 5. Latitude.sh

![Latitude.sh | HashiCorp Tech Partner](https://www.datocms-assets.com/2885/1668810692-latitudesh-logotype-dark.svg)

[Latitude.sh](https://www.latitude.sh/) provides a global bare metal infrastructure designed for high-performance computing, AI workloads, and latency-sensitive applications. Its API-driven provisioning model aligns well with modern DevOps and MLOps workflows used in AI teams. Also, the platform focuses on fast provisioning, global coverage, and dedicated hardware that can be deployed via an API. They have data centers in North America, Europe, and South America. The mix of automation, performance, and geographic reach makes Latitude a strong option for organizations building AI workloads.

See the Latitude.sh interface, where you can select server types, compare hardware specs, and deploy infrastructure in minutes.
 ![latitude](https://www.atlantic.net/wp-content/uploads/2025/09/latitude.png)
 Image Source: Latitude.sh

- **GPU acceleration:**
Latitude.sh provides dedicated GPU bare-metal servers supporting NVIDIA A100 and L40S GPUs, which are suitable for deep learning training, fine-tuning large language models, or scaling inference workloads. Users can deploy single GPU servers or multi-GPU configurations, depending on throughput and model architecture needs. Their infrastructure is optimized for low-latency access, making it suitable for real-time inference, video processing, and other demanding compute workflows.
- **Compliance:**
The platform follows enterprise security practices and operates compliant-ready data centers across multiple regions. With optional private networking, encrypted traffic paths, and isolated single-tenant servers, organizations can maintain strong security boundaries while training or serving AI models. The infrastructure supports common compliance frameworks when customers need to design controlled environments for sensitive data.
- **Custom builds:**
Customers can configure CPU, memory, GPU type, and NVMe storage to match the performance characteristics of their AI models. Provisioning is automated through a robust API and Terraform support, enabling teams to spin up and tear down clusters programmatically. This flexibility appeals to engineering-driven AI teams that want cloud-like automation without giving up the performance advantages of bare metal.
- **Support:**
Latitude.sh provides engineering-focused support with guidance on provisioning, network configuration, and workload optimization. The platform includes real-time monitoring tools and API logs, helping teams maintain visibility across distributed GPU infrastructure.
- **Bare metal pricing range:**
Entry-level GPU servers typically begin around **$600–$800 per month**, depending on region and GPU type. High-performance configurations using NVIDIA A100 or L40S hardware can range from **$1,800 to $3,500+ per month**, with larger multi-GPU builds available for enterprise users

**Table 2: Comparison of Bare Metal Hosting Providers for AI Workloads**

| **Provider** | **GPU Options** | **Compliance & Security** | **Pricing Range (per month)** | **Best Fit Use Case** | **Region Strength** |
| --- | --- | --- | --- | --- | --- |
| **Atlantic.Net** | NVIDIA H100, L40S | HIPAA, PCI DSS, SOC 2 | $412 – $1,150+ | Mission-critical AI in healthcare & finance | Strong U.S. presence |
| **IONOS** | NVIDIA H100, H200, L40S, Intel Gaudi | ISO 27001, GDPR-ready | £550 – £3,990+ | AI teams needing GDPR compliance, EU data residency | Strong in Europe |
| **Latitude** | NVIDIA A100, L40S | Enterprise security practices; isolated single-tenant hardware | ~$600 – $3,500+ | Distributed GPU clusters, low-latency inference, API-driven AI deployments | North America, Europe, South America |
| **CoreWeave** | NVIDIA A100, H100, L40S (fractional/full) | SOC 2, ISO 27001 | Flexible usage-based; $/hr to $1,000s | Generative AI labs, LLM training, inference at scale | U.S. GPU-native |
| **OpenMetal** | NVIDIA A100, H100 | Enterprise-grade, full control | $2,234 – $2,995+ | Private AI clusters, federated learning, research | Open-source focus |

## Choosing the Right Provider for Bare Metal Dedicated Servers

Selecting a bare metal hosting provider for AI workloads depends on several key factors. First, performance is critical, since training and inference require powerful GPUs and fast storage. In addition, compliance is important for organizations in regulated sectors such as healthcare and finance. Scalability must also be considered, because many AI projects start small but later expand to clustered servers and distributed training. Finally, cost efficiency and regional availability often guide decisions for startups, academic groups, and enterprises with specific data residency needs. In 2026, teams also evaluate providers based on GPU availability, cluster networking performance, and support for AI orchestration tools.

Each provider has particular strengths. For example, IONOS is strong option in Europe, since they support GDPR and data sovereignty. Similarly, CoreWeave is well-suited for GPU-intensive tasks, including generative AI and large-scale inference. In contrast, OpenMetal provides an open-source option with the flexibility of a private cloud.
 However, Atlantic.Net offers the most balanced choice. It combines compliance-ready infrastructure with GPU-equipped servers and flexible pricing. Therefore, it is a strong option for both mid-sized AI projects and large enterprise deployments that cannot compromise on performance or regulatory assurance.

## Final Thoughts

AI workloads need reliable hardware, steady performance, and strong data protection. Bare metal hosting meets these needs by giving teams direct access to dedicated servers without the limits of virtualization. The shift toward production-grade AI systems has made bare metal infrastructure more relevant than ever in 2026.

Among the providers, Atlantic.Net is the best overall choice for AI workloads in 2026. Its HIPAA-ready setup, U.S. data centers, and GPU-powered servers make it suitable for industries where both compliance and efficiency are essential. Its pricing also works well for smaller projects as well as large enterprise deployments.

For organizations that want AI solutions that are fast, secure, and scalable, Atlantic.Net provides a level of reliability and trust that few others can match.


---

# Best HIPAA-Compliant Fax Services in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-fax-services-in-2021/ | Published: 2026-04-25 | Updated: 2026-04-26 | Author: Dr. Rachael Bailey

Despite a move towards digital and paperless alternatives such as email, the fax machine still has a place within many healthcare organizations, providing an effective means of sending and receiving Protected Health Information (PHI). While fax may seem outdated, there has recently been a shift to cloud-based fax services, improving usability and the security of shared information. Cloud fax solutions form a sort of hybrid between traditional fax and email, allowing users to transmit data in a digital format using a secure internet connection, negating the need for expensive machinery. In 2026, cloud fax is widely considered a standard approach for secure document exchange in healthcare environments that still rely on fax workflows.

## Top 11 HIPAA-Compliant Fax Providers

Healthcare providers must choose a fax provider wisely, ensuring the security of shared PHI at all times. Here, we have compared some leading HIPAA-compliant fax providers and compiled a list of our top 11. We have considered their functionality, security features, cost, and usability. Current evaluations also place increased emphasis on interoperability with EHR systems and automation capabilities.

## 1. WestFax

WestFax offers a HIPAA-compliant fax service to government bodies, healthcare providers, and financial organizations, delivered through a 100% cloud-based platform. WestFax API allows easy integration with existing systems and transition is simplified by access to a dedicated implementation team. WestFax is HIPAA-compliant right out of the box, either meeting or exceeding all HIPAA requirements. Data is encrypted using TLS 1.2 encryption in transit and AES 256 at rest, while users also benefit from security features, such as automatic logoff, authentication controls, and password complexity policies. WestFax has various different plans available to meet the needs of its clients and offers a free trial. Recent updates focus on improving API performance and integration speed for healthcare systems.

## 2. Concord

Concord is a leading provider of cloud-based fax services to healthcare organizations. It provides healthcare professionals with a HIPAA compliant, PCI-certified, SOC 2 audited fax solution. With industry-leading uptime and reliability, users can be reassured that their data will be transferred to the right place at the right time. Document workflow ensures that faxes are routed to the right recipient or team. Artificial Intelligence and Machine Learning are used to extract key data from inbound faxes.

To maintain the security of shared data, Concord offers AES 256-bit encryption, complex password requirements, active intrusion protection, and access and audit controls. An image retention policy can be deployed to automatically delete all images at set times. Automation and intelligent routing remain key differentiators for high-volume healthcare organizations.

## 3. Documo

Documo delivers a powerful suite of products, including mSign, mDrive, and mFax. mFax offers a cloud-based fax solution to organizations within regulated industries. With easy integration into existing systems, mFax is user-friendly with an intuitive interface. All mFax plans automatically include 1GB of file storage, allowing users to securely store and share their incoming faxes. Documo prioritizes security and compliance, ensuring that data is encrypted in transit and at rest and that access is appropriately restricted. They also provide audit trails, intrusion detection, and automatic time-outs. Documo continues to expand its integrations with major healthcare platforms and workflow tools.

## 4. Fax.Plus

Fax.Plus by Alohi is a secure cross-platform online fax provider that is trusted by over 2,000,000 customers globally. It serves individual clients as well as midsize and small healthcare providers and enterprises. With a high-performance multi-tier faxing infrastructure, Fax. Plus delivers a highly efficient high-volume faxing solution. The security of customer’s data is maintained through data encryption at rest and in transit, two-factor authentication, single sign-on (SSO), world-class server infrastructure, Swiss-based servers, access logging, and a signed BAA for users of the Enterprise plan. Its scalability makes it suitable for both small clinics and larger distributed healthcare networks.

## 5. FAXAGE

FAXAGE is considered the value leader within the cloud-based fax solutions market, operating its own infrastructure and providing its services to small and medium businesses and home users. FAXAGE’s services are competitively priced, offering unlimited fax storage and an unlimited number of users for no extra charge. All service plans deliver HIPAA compliance, with features including a signed BAA, SSL/TLS encryption for all web and API-based faxing, SSL/TLS email transport encryption, SSL/TLS secured Print to Fax print driver, and SSL/TLS secured Fax App for iOS and Android. FAXAGE also provides full Internet Fax System Auditing, allowing clients to monitor how data is being used. Its pricing model remains attractive for cost-conscious healthcare providers.

## 6. Innoport

Innoport offers HIPAA-compliant online fax service, striving to protect the confidentiality of sensitive patient information. Its services are available to organizations of all sizes, from large hospitals to individual healthcare professionals. Innoport ensures the security of shared information through many security features including 128-bit encryption, encrypted email TLS, fax to secure FTP, restricted server access, secure servers for information storage and retrieval, and a robust and highly secure HTTPS API. Organizations increasingly prioritize providers that offer flexible deployment and integration options like these.

## 7. Medsender

Medsender provides its clients with HIPAA-compliant faxing, email, SMS, signatures, and forms. This secure cloud platform can integrate seamlessly with most common EMRs. Medsender uses the latest in Artificial Intelligence to analyze document content, automate and streamline workflows, and eliminate repetitive tasks. Medsender’s platform meets or exceeds all HIPAA requirements by implementing physical and technical safeguards, such as data encryption at rest and in transit, access controls, auditing and logging, vulnerability scanning, intrusion detection, disaster recovery, and appropriate workplace HIPAA training. AI-driven document processing continues to improve operational efficiency in healthcare workflows.

## 8. eFax

eFAx is a global provider of HIPAA-compliant, cloud-based fax solutions, serving over 11 million subscribers. Their users benefit from a secure and reliable communications network, backed by a vast inventory of available numbers. eFax supports over 170 standard file formats, more than many of its competitors. If clients opt for the eFax Corporate solution, they will be provided with a signed BAA and a highly secure HIPAA-compliant faxing service. Advanced security features that are included within this plan include TLS 1.2 encryption for transmission of digital faxes and AES 256-bit SSL encryption for stored digital faxes, unique user identification, administration privileges, detailed reporting, and configurable storage retention. Its global reach makes it a common choice for organizations operating across multiple regions.

## 9. SRFax

RFax is a trusted provider of HIPAA-compliant online fax services, enabling medical professionals to exchange sensitive medical information. There are several plans available, each providing unlimited authorized email addresses and online storage. HIPAA-compliant plans are slightly more expensive than SRFax’s standard solutions but meet all the necessary security requirements. SRFax encrypts data using 2048-bit SSL certification, 2048-bit RSA public keys, and PGP encryptions. Additional security measures include two-factor authentication, SSO, and access control. Security-focused organizations often prioritize its encryption standards and flexibility.

## 10. Upland InterFAX

InterFAX provides fully cloud-hosted and enterprise-ready fax service to healthcare professionals across the world. Their developer fax API allows easy integration with a healthcare organization’s existing systems and their services are easily scalable, helping to support an organization’s growth. InterFax meets rigorous industry compliance standards and is HIPAA and PHIPA compliant, ISO 27001 accredited, and PCI DSS Level 1 certified. This company takes security seriously, employing TLS encryption of incoming and outgoing faxes, strict authentication measures, full audit trail, automatic deletion of delivered faxes, and automated activity reporting. Its API-first approach is well suited for organizations building custom healthcare applications.

## 11. iFax

[iFax](https://www.ifaxapp.com/fax-plan-trial/?utm_source=nomadseo&utm_medium=affiliates) is one of the best online fax services because it is reliable, affordable, and easy to use. With iFax, you can send and receive faxes without a dedicated fax line, and there are no maintenance fees and long-term contracts. You can also use iFax to send passports and other sensitive documents securely, with 256-bit end-to-end encryption. For healthcare professionals, it’s the best choice in handling sensitive data such as Protected Health Information because it’s HIPAA-compliant. You can send and receive faxes and track the progress of your fax straight from your mobile device, and receive real-time notifications all from your email inbox. Its mobile accessibility aligns well with modern remote and hybrid healthcare workflows.

## How can Atlantic.Net help?

Atlantic.Net has numerous partnerships with HIPAA-compliant cloud-based fax service providers. This uniquely places Atlantic.Net ahead of the competition as we can use our relationships to create direct peering between our services and the fax services, resulting in end-to-end encryption and high-performance interconnectivity, with your data never leaving our perimeter network.

Atlantic.Net has over 25 years of experience as a global provider of cloud services. We provide award-winning cloud servers, high-performance, managed security, secure storage, and compliance solutions. We are independently audited by third-party auditors to ensure our solutions fulfill HIPAA, HITECH, PCI, GDPR, or SOC requirements. To find out more about our [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions, [contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)!

---

#### Read More About HIPAA IT Compliance

- [HIPAA IT Compliance](https://www.atlantic.net/hipaa-data-centers/hipaa-compliant-it-infrastructure-guide/) Guide
- Best [HIPAA Compliant Email Service](https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-email-service-in-2021/)
- Best [HIPAA Compliant VOIP](https://www.atlantic.net/hipaa-compliant-hosting/top-10-best-hipaa-compliant-voip-providers/) Service
- Top Considerations for a [HIPAA-Compliant Database](https://www.atlantic.net/hipaa-compliant-hosting/top-10-considerations-for-a-hipaa-compliant-database/)
- [What Is a BAA?](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/)
- [SSAE16, SAAE18, SOC1, SOC2](https://www.atlantic.net/hipaa-compliant-hosting/ssae-16-soc-1-soc2-care/) – Why You Should Care
- Best [Healthcare Software Development](https://www.atlantic.net/hipaa-compliant-hosting/top-10-healthcare-software-development-companies/) Companies
- Best [HIPAA Consulting](https://www.atlantic.net/hipaa-compliant-hosting/top-10-hipaa-consulting-companies-in-2020/) Companies
- Is It [HIPPA or HIPAA?](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-vs-hippa/)

---


---

# Best HIPAA Patient Portal Software in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-patient-portal-software-in-2021/ | Published: 2026-04-25 | Updated: 2026-04-26 | Author: Dr. Rachael Bailey

As the world rapidly becomes digital, many healthcare organizations are implementing patient portals to enhance the patient-physician relationship, increasing accessibility and patient engagement. The coronavirus pandemic has served to drive the adoption of patient-centered care forward as healthcare providers increasingly rely on remote interactions with their patients. In 2026, patient portals are now a core component of digital healthcare delivery, supporting both in-person and virtual care workflows.

The best HIPAA-compliant patient portal software in 2026 combines secure messaging, appointment management, and EHR integration with strong access controls and audit logging. Leading platforms support encrypted communication, role-based permissions, and Business Associate Agreements (BAAs) to meet HIPAA requirements.

For most healthcare organizations, the right choice depends on size and workflow: smaller practices prioritize ease of use and fast setup, while larger systems need deep EHR integration and scalability. Below, you’ll find top options categorized by use case, along with a comparison of features that matter for compliance and patient experience.

## HIPAA-Compliant Patient Portal Software Comparison (2026)

| Provider | Best For | Core Capabilities | Integration | Security & Compliance Signals |
| --- | --- | --- | --- | --- |
| Cerbo | Custom workflows, functional medicine | Scheduling, messaging, records, vitals tracking, billing | Moderate (customizable workflows) | HIPAA-ready environment (BAA required), configurable access controls |
| Athenahealth | Small–mid practices needing all-in-one platform | EHR, billing, patient engagement, reminders, forms | Deep native integration | HITRUST CSF, EHNAC certifications; HIPAA-aligned controls |
| Epic (MyChart) | Large hospitals & health systems | Scheduling, messaging, e-visits, inpatient access | Very deep (enterprise EHR ecosystem) | Mature compliance framework, audit logging, role-based access |
| Ambra Health | Imaging-heavy workflows | Medical image sharing, portal access, cloud storage | Integrates with major EHRs | HIPAA-aligned data handling, secure image transfer |
| Elation Health | Clinical-first practices | Messaging, notes access, patient records | Native EHR integration | Encryption (TLS + AES-256), ONC-certified EHR |
| TheraNest | Mental health practices | Intake forms, scheduling, billing, messaging | Limited–moderate | HIPAA-compliant setup with encryption in transit/at rest |
| Bridge | Flexible EHR integrations | Registration, scheduling, messaging, billing | High (EHR-agnostic) | Third-party security audits, ONC-certified |
| Heno | Therapy & rehab clinics | EMR, billing, marketing, patient portal | Moderate | Encrypted storage (TDE), SSL encryption |
| Practice Harmony | Workflow automation | Scheduling, forms, billing, reminders | Moderate | HIPAA-aligned controls, secure access |
| RXNT | Cost-conscious practices | EHR, billing, telehealth, engagement tools | Flexible (modular or full suite) | SOC 2 Type II, HIPAA-compliant environment |
| SimplePractice | Solo & small mental health practices | Scheduling, telehealth, billing, intake | Limited–moderate | Encryption, access controls, disaster recovery |
| Mend | Telehealth-first organizations | Messaging, video visits, intake, scheduling | Moderate–high | HIPAA-compliant communications, predictive analytics |

## Top 12 HIPAA-Compliant Patient Portal Software

Choosing suitable software can be difficult, so we have compiled a list of some of the best Patient Portal applications, focusing on the security features that each one offers. Current evaluations also prioritize usability, mobile access, and automation capabilities in addition to compliance.

### 1. Cerbo – **Best for** customizable patient workflows

[Cerbo](https://cer.bo/) by MD HQ provides patients with a fully interactive, user-friendly, and secure patient portal. This enterprise-level, HIPAA-compliant, configurable software allows patients to schedule appointments, exchange secure messages, view and update their medical records and medications, monitor and record vital measurements, and manage their bills. Its flexibility makes it suitable for practices looking to customize patient engagement workflows.

### 2. Athenahealth – **Best for** all-in-one practice management

Athenahealth, recently awarded 2020 Best in KLAS: Small Practice Ambulatory EMR/PM, offers healthcare providers a cloud-based platform for managing electronic health records (EHR), telehealth, care coordination, patient engagement, and medical billing. Their patient engagement solution, athenaCommunicator, provides a patient portal that enables patients to take an active role in their healthcare, by scheduling appointments, signing medical forms, managing their bills, and receiving reminders via email, text message, or phone call. Athenahealth takes security seriously and has achieved HITRUST CSF Certification and EHNAC Certification demonstrating its compliance with HIPAA, HITECH/ARRA, ACA, Omnibus Rule, and other applicable state legislation. The platform continues to expand its patient engagement and communication features across multiple channels.

### 3. Epic – **Best for** large healthcare systems

Ranking Best in KLAS for the fourth year running, Epic System’s MyChart patient portal is a leader in this space. Epic’s MyChart allows patients easy access to personal and family health information, with the ability to schedule appointments, securely message their doctor and attend e-visits. This software allows patients to garner greater control over the management of their health. The MyChart Bedside offering enables inpatients to enjoy the benefits of the portal while in the hospital. Epic remains widely adopted by large healthcare systems for its integrated ecosystem and patient engagement tools.

### 4. Ambra Health – **Best for** medical imaging workflows

Ambra Health is an award-winning, cloud-based medical data and image management suite. Ambra Health offers an easy-to-use patient portal, replacing CDs as the traditional and less secure means of image sharing. This platform can also be easily integrated with other popular EHR systems, including Athenahealth. Ambra Health is committed to providing its clients with up-to-date and full healthcare compliance. Digital imaging access continues to be a key feature in improving patient experience and care coordination.

### 5. Elation Health EHR – **Best for** clinical-first usability

Elation Health’s cloud-based and ONC certified EHR platform delivers a clinical-first patient management solution. Their patient passport allows access to secure messaging, doctor’s notes, and medical information. Elation Health implements highly advanced, bank-grade information safeguards to secure patient data, including 256-bit SSL/TLS and AES-256 data encryption and password protection. Security and usability remain central to patient portal adoption and trust.

### 6. TheraNest – **Best for** mental health practices

TheraNest provides a web-based mental health practice management platform that is fully HIPAA-compliant. Patients can access an efficient portal, allowing them to complete and sign intake forms, build custom forms, schedule appointments, manage their bills, and exchange HIPAA-compliant messages with their physician. TheraNest ensures that all data remains HIPAA-compliant using SSL encryption in transit and at rest. Its focus on mental health workflows makes it a strong fit for therapy and counseling practices.

### 7. Bridge – **Best for** flexible EHR integrations

Bridge is a leading HIPAA-compliant and ONC-certified patient portal solution that can integrate seamlessly with any existing EHR. It offers a comprehensive selection of features including patient registration, appointment scheduling, secure messaging, bill management, and access to medical records. Complying with all HIPAA regulations, Bridge is routinely audited by third-party security auditors. Integration flexibility remains a key requirement for modern healthcare systems.

### 8. Heno – **Best for** therapy and rehab clinics

Heno is an online practice management system, designed for use by professionals within the physical, speech, and occupational therapy sectors. An all-in-one solution, Heno provides an EMR, software for billing, marketing, and sales, and a patient portal. Heno’s servers are hosted and maintained in a HIPAA-compliant data center, using SSL encryption. They also use Transparent Data encryption (TDE) to encrypt patient data at rest. Specialty-focused platforms like Heno continue to address niche healthcare workflows effectively.

### 9. Practice Harmony – **Best for** workflow automation

[Practice Harmony](https://mahlerhealth.com/MahlerHealth-PracticeHarmony), developed by Mahler Health, is one of the leaders in the practice management space, offering a complete cloud-based and HIPAA-compliant solution to streamline workflow. Their patient portal allows clients to receive reminders, fill out forms ahead of appointments, manage their bills, schedule appointments, and access their medical data. Patients can access the portal via their mobile devices for ease of use and increased accessibility. Mobile-first access is now a baseline expectation for patient engagement platforms.

### 10. RXNT – **Best for** cost-effective cloud solutions

Healthcare providers can rely on RXNT for a cost-effective, cloud-based integrated healthcare platform, providing solutions for practice management,  electronic health records, billing, patient engagement and access, and telehealth. These solutions can be deployed as stand-alone products or as a fully integrated system. RXNT complies with all HIPAA regulations and, as a cloud-based platform, is inherently more secure than server-based products, implementing automatic patches and updates. RXNT has achieved SOC 2, Type 2 certification. Cloud-native platforms like RXNT simplify maintenance and ongoing compliance requirements.

### 11. Simplepractice – **Best for** small private practices

Simplepractice is an intuitive cloud-based practice management platform that has partnered with over 100,000 practitioners, including some leading names in the industry. Offering solutions for scheduling, online booking, fully paperless intake, telehealth, patient billing, and client communication. Simplepractice is designed for small businesses within the mental health sector. It implements several privacy and security controls to ensure regulatory compliance, these include data encryption, access controls, vulnerability management, network protection, endpoint protection, and disaster recovery. It remains a popular choice for smaller practices due to its ease of use and focused feature set.

### 12. Mend – **Best for** telehealth-first care

Mend delivers complete cloud-based telehealth and patient engagement platform to medium and large healthcare organizations. Individuals and smaller practices may also take advantage of the platform via a free option that offers limited features. A patient portal offers access to many features, including HIPAA-compliant messaging, telehealth, digital intake forms, and patient scheduling. Mend’s innovative AI technology, PredictiveIQ, can predict no-shows and cancellations with 99% accuracy. Predictive tools like this are increasingly used to improve scheduling efficiency and reduce missed appointments.

## Atlantic.Net: Incorporating HIPAA-Compliant Hosting Solutions

Choosing a HIPAA-compliant patient portal software is the first challenge, but the next is choosing a leading [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) provider to host your chosen website or application. Focusing on your HIPAA compliance requirements, Atlantic.Net can offer you a turn-key [HIPAA hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solution. As a leader in the cloud services industry, we offer a robust and scalable hosting environment and fulfill all HIPAA, HITECH, PCI, or SOC requirements. We secure our infrastructure to industry standards and are independently audited by third-party auditing firms to assess our compliance. A secure hosting foundation is critical to maintaining compliance across all patient-facing applications.

To find out more about the solutions that we offer, [contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)!

*This article was updated on April 25, 2026.*


---

# Most Popular HIPAA File Sharing Applications in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/most-popular-hipaa-file-sharing-applications-in-2021/ | Published: 2026-04-25 | Updated: 2026-05-18 | Author: Dr. Rachael Bailey

Choosing a safe and secure file-sharing application is essential for any business. For healthcare providers who handle Protected Health Information (PHI), the stakes are even higher, and they must find a reputable file-sharing app that complies with HIPAA regulations.

Modern healthcare teams also evaluate file-sharing tools based on auditability, access control, and compatibility with existing security systems.

HIPAA-compliant file-sharing applications enable healthcare teams to securely send, receive, and store protected health information (PHI). The right tool must support encryption, access controls, audit logs, and offer a HIPAA Business Associate Agreement (BAA). In 2026, the most widely used options focus on simple collaboration while meeting strict compliance requirements. This guide covers the most popular HIPAA-compliant file sharing apps, what they’re best for, and how to choose based on your workflow, team size, and security needs.

## Top 10 HIPAA-Compliant File Sharing Apps

So, where do you start when choosing a HIPAA-compliant file sharing app for your healthcare organization? To help you, we have compiled a list of some of the most popular options.

### 1. Nextcloud – Best for Self-Hosted Control

![](https://www.atlantic.net/wp-content/uploads/2026/04/Nextcloud_Logo.svg_.png)

Boasting over 400,000 active servers online, Nextcloud delivers an industry-leading, self-hosted content collaboration platform. Nextcloud Files, their file-sharing offering, allows users to easily sync, share, and collaborate on their files. Security remains their key priority, with powerful end-to-end encryption, client-side encryption, enterprise-grade key handling, and built-in, rule-based File Access Control. Nextcloud supports private cloud deployments, making it a strong fit for healthcare teams with strict internal compliance policies.

- **Key Specs:** Self-hosted or private cloud deployment
- **Compliance:** Supports HIPAA configurations (BAA depends on hosting provider)
- **Support:** Enterprise support available

**Verdict**: Best for organizations that want full ownership of infrastructure and data.

**Who should choose Nextcloud?** Teams with internal IT resources that require maximum control over PHI.

### 2. Kiteworks – Best for Secure External Collaboration

![](https://www.atlantic.net/wp-content/uploads/2026/04/Kiteworks_logo.png)

**Kiteworks** is the control plane for secure data exchange in healthcare — unifying email, file sharing, SFTP, managed file transfer, data forms, and APIs under a single policy engine, audit log, and security architecture. The platform delivers the HIPAA Security Rule technical safeguards covered entities and business associates need, with a BAA available. Hospitals, payers, pharma, and life sciences companies use Kiteworks to share PHI with providers, business associates, regulators, and research partners without losing visibility or audit defensibility.

The platform enforces ABAC and RBAC policy controls on every transaction, applies AES-256 double encryption at rest (file-level plus disk-level with separate keys) and TLS 1.3 in transit, and produces tamper-evident audit logs delivered to SIEM in real time — with no throttling. Pre-built HIPAA dashboards generate Security Rule safeguard evidence on demand, compressing audit preparation from weeks to hours.

- **Key specs:** Single control plane across email, file sharing, SFTP, MFT, data forms, and APIs; single-tenant architecture that eliminates cross-tenant exposure; governed AI access via Secure MCP Server and AI Data Gateway
- **Validation stack:** FedRAMP Moderate Authorized (continuously since 2017), FedRAMP High In Process, SOC 2 Type II attested, ISO 27001/27017/27018 certified, IRAP Assessed (Protected), FIPS 140-2 validated cryptographic modules
- **Compliance breadth:** HIPAA/HITECH technical safeguards, BAA available; pre-mapped controls for CMMC 2.0, GDPR, PCI DSS, SOX, GLBA, and more from one deployment
- **Support:** Enterprise-grade, including federal-cleared staff for regulated workloads

**Verdict:** The strongest choice for healthcare organizations that need one platform — not five — to govern every channel where PHI moves to external parties.

**Who should choose Kiteworks?** Health systems, payers, pharma, medical device manufacturers, and life sciences companies exchanging PHI under HIPAA/HITECH and overlapping mandates—CMMC for federal health contractors, GDPR for multinational pharma, PCI DSS for payment data.

### 3. Box – Best for Enterprise Content Management

![](https://www.atlantic.net/wp-content/uploads/2026/04/box-logo.png)

Box delivers a secure file-sharing platform to some of the world’s leading organizations. Providing access across multiple devices, Box can seamlessly integrate with many of the productivity apps your organization uses. A standout feature of Box is its support for over 120 file types and the option to embed files directly into your blog or website. Box has security covered with built-in controls, including granular permissions, strong user authentication, and AES 256-bit encryption. When signing up for Box’s Enterprise plan, users will receive a signed BAA.

- **Key Specs**: Cloud-based enterprise content platform
- **Compliance:** HIPAA support with BAA (enterprise plans)
- **Support:** 24/7 enterprise support

**Verdict**: Best for large organizations needing structured collaboration and compliance.

**Who should choose Box?** Hospitals and large healthcare systems manage high volumes of files.

### 4. Syncplicity

![](https://www.atlantic.net/wp-content/uploads/2026/04/Syncplicity-logo.png)

Syncplicity, developed by Axway, provides a HIPAA-compliant file-sharing solution for healthcare providers, patients, and payers. Users can opt for a cloud or hybrid model as a cost-effective, flexible, and scalable solution, or for an on-premises deployment that allows them to use existing architecture, resources, and policies. Notable security features of Syncplicity include military-grade encryption, support for storage vaults, remote wipe, and policy controls.

- **Key Specs:** Hybrid and on-prem deployment options
- **Compliance:** Supports HIPAA-ready configurations
- **Support:** Enterprise support available

**Verdict**: Strong option for organizations balancing legacy systems with cloud adoption.

**Who should choose Syncplicity?** Teams transitioning from on-prem to cloud environments.

### 5. Tresorit – Best for Zero-Knowledge Encryption

![](https://www.atlantic.net/wp-content/uploads/2026/04/Tresorit.png)

Tresorit, based in Switzerland, provides an end-to-end encrypted, zero-knowledge cloud-based file-sharing service. Unlike other solutions in this space, Tresorit encrypts and decrypts data on the client’s device rather than using server-side encryption. Other security features include two-step verification, timeout policies, granular permission levels, and IP filtering. Users will receive a signed BAA and can take advantage of a 14-day free trial.

- **Key Specs:** End-to-end encrypted cloud storage
- **Compliance:** HIPAA support with BAA
- **Support:** Business-tier support

**Verdict**: Best for organizations prioritizing maximum data confidentiality.

**Who should choose Tresorit?** Privacy-focused healthcare providers and specialists.

### 6. FileCloud – Best for Healthcare Imaging Workflows

![](https://www.atlantic.net/wp-content/uploads/2026/04/FileCloud.png)

CodeLathe Technologies offers FileCloud, its powerful, HIPAA-compliant file-sharing platform. FileCloud maintains the integrity of shared data using encryption in transit and at rest, complete activity logs, two-factor authentication, and antivirus and ransomware protection. Healthcare providers can also access a built-in document to preview DICOM images, such as X-rays and CT scans. Users can opt for an on-premise or cloud-hosted solution, with cloud-based enterprise customers benefitting from a signed BAA.

- **Key Specs:** Cloud or on-prem deployment
- **Compliance:** HIPAA support with BAA (cloud plans)
- **Support:** Enterprise support available

**Verdict**: A great choice for providers handling clinical files such as DICOM images.

**Who should choose FileCloud?**Clinics and hospitals manage diagnostic files.

### 7. SmartFile – Best for Small Healthcare Teams

![](https://www.atlantic.net/wp-content/uploads/2026/04/SmartFile.png)

With over 1,500 customers, SmartFile offers a HIPAA-compliant file management service for pharma and research labs. To maintain HIPAA compliance, SmartFile lets its users establish granular user roles and permissions and password-protect file links. All files are encrypted end-to-end using AES-256, and access can be monitored and tracked. With multiple deployment options, including on-premises and cloud, SmartFile provides solutions that fit the needs of most small to midsize healthcare organizations.

- **Key Specs:** Cloud and on-prem options
- **Compliance:** Supports HIPAA configurations
- **Support:** Standard business support

**Verdict**: A good fit for smaller teams that need secure file sharing without an unnecessary platform.

**Who should choose SmartFile?**Small to mid-sized healthcare organizations.

### 8. Files – Best for Automated File Workflows

![](https://www.atlantic.net/wp-content/uploads/2026/04/files-com-logo-png_seeklogo-616732.png)

Founded in 2009, Files provides a secure online file-sharing service for businesses across many industries. Files can integrate seamlessly with existing apps, helping streamline workflows and improve productivity. Files is committed to helping its clients meet HIPAA compliance requirements by providing reliable security and redundancy. It utilizes 2048-bit SSL encryption for all FTP and HTTP connections, granular user permissions, and audit logs. Premier plan customers will receive a signed BAA.

- **Key Specs:** Cloud-based file automation platform
- **Compliance:** Supports HIPAA with appropriate setup
- **Support:** Business and enterprise support tiers

**Verdict**: Best for teams needing automated file movement and integrations.

**Who should choose Files.com?** Organizations handling large-scale file transfers.

### 9. OhMD – Best for Patient Communication

![](https://www.atlantic.net/wp-content/uploads/2026/04/OhMD-logo.png)

The OhMD platform provides a secure communication solution to over 30,000 healthcare providers. In addition to its file-sharing capabilities, OhMD offers several other communication solutions, including secure two-way SMS texting, telehealth visits, and live chat. OhMD supports HIPAA compliance in many ways, including automatically implementing a signed BAA, encrypting data in transit and at rest, and managing access. All OhMD staff have completed HIPAA training to ensure they understand the intricacies of maintaining compliance.

- **Key Specs:** Communication + file sharing platform
- **Compliance:** HIPAA support with BAA
- **Support:** Dedicated customer support

**Verdict**: Ideal for patient-facing communication workflows.

**Who should choose OhMD?** Practices focused on patient communication and engagement.

### 10. ownCloud – Best for Open-Source Flexibility

![](https://www.atlantic.net/wp-content/uploads/2026/04/owncloud.png)

The open-source file-sharing app ownCloud, owned by Kiteworks, is trusted by over 200 million users worldwide. ownCloud can be deployed on-premises, with a trusted service provider, or via the SaaS collaboration platform hosted in Germany. ownCloud can seamlessly integrate with your existing HIPAA-compliant infrastructure to ensure sensitive patient data is stored and transmitted securely.

- **Key Specs:** Open-source file sharing platform
- **Compliance:** Supports HIPAA when configured correctly
- **Support:** Enterprise support available

**Verdict**: Best for organizations needing customizable, open-source solutions.

**Who should choose ownCloud?** Teams that prefer open-source and customizable environments.

## Atlantic.Net: Working With a Trusted Hosting Provider

Choosing a leading HIPAA-compliant file-sharing solution is pointless if you don’t have the infrastructure to support it. If you need a hosting solution that is durable, feature-rich, and dedicated to maintaining the security of sensitive patient information, then Atlantic.Net is here for you.

Atlantic.Net can provide you with a fully managed HIPAA-compliant hosting solution that is SOC 2 and SOC 3 certified, and HIPAA and HITECH audited. With over 30 years of experience, we deliver high performance, a global presence, 100% uptime, and industry-standard security.

To find out how Atlantic.Net can help your healthcare organization, contact our sales team today!

*This article was updated on May 14, 2026.*


---

# Server Hosting with GPU Support: Our Top 5 Best Options in 2026

> URL: https://www.atlantic.net/gpu-server-hosting/server-hosting-with-gpu-support-our-top-5-best-options/ | Published: 2026-04-25 | Updated: 2026-04-26 | Author: Richard Bailey

## **Understanding Server Hosting with GPU Support**

What exactly is server hosting with GPU support?

- **Servers + GPUs:** You get servers equipped with both standard CPUs and powerful Graphics Processing Units. The great thing about cloud hosting is that you can opt for shared or dedicated server resources.
- **Beyond Graphics:** GPUs were initially created for gaming, but are now used for the heavy computation of AI due to their unique parallel design.
- **Parallel Power:** GPUs excel at advanced math problems that can be broken into many small pieces and solved simultaneously. That’s exactly how AI algorithms work! Making them a perfect match.
- **Faster Processing:** Instead of the CPU doing everything, parallel tasks are offloaded to the GPU, dramatically speeding things up and boosting overall processing power.

## **What Makes GPU Hosting Different?**

The key difference lies in how they work:

- **CPUs:** Have a few strong cores, great for handling tasks one after another (serially). CPUs are good all-rounders.
- **GPUs:** Contain hundreds or thousands of smaller cores (like NVIDIA CUDA cores). Designed for doing many calculations at the same time – known as parallel processing.
- **The Advantage:** Server hosting with GPU support specifically uses this parallel strength for tasks that benefit from it.

## **How Does GPU Hosting Work?**

Here’s a simplified look at the process:

- **Hardware:** Actual GPU hardware is installed in the physical servers.
- **Task Offload:** Programs designed for GPUs send parallel-friendly jobs from the central processing unit (CPU) to the graphics processing units via graphics and CUDA drivers.
- **Processing:** Using hardware like CUDA cores, tensor cores and RT Cores, the GPU’s many processing units work on these tasks simultaneously.
- **Results:** The answers are sent back much faster than a CPU could manage alone, delivering a big leap in performance.

We will explore GPU architecture in greater depth later, but first, let’s review which providers currently deliver strong GPU hosting options in 2026.

## **Comparing the Top 5 Server Hosting Providers with GPU Support**

Choosing a hosting provider involves comparing GPU models, pricing, speed, support, and more. They continue to offer modern NVIDIA GPU options such as the L40S and H100 NVL, which remain widely used for AI training, inference, and high-performance workloads in 2026. Here’s a quick comparison of five leading providers for server hosting with GPU support. This helps weigh options for deep learning, data analytics, or graphics rendering, considering GPU memory and other features.

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

### **#1: Atlantic.Net – The Leading Dedicated Server with GPU Power**

Atlantic.Net is notable for its combination of strong hardware, flexible options (Cloud GPU and Dedicated GPU), solid reliability, and great customer support. They offer high-end NVIDIA GPU choices like the L40S (good for general AI, graphics, and video) and the H100 NVL (great for large-scale AI/HPC with lots of GPU memory and bandwidth).

Below is Atlantic.Net’s cloud control panel interface used to deploy and manage dedicated and GPU servers.
 ![Atlantic.Net Server Panel](https://www.atlantic.net/wp-content/uploads/2026/01/Atlantic.net-server-panel.png)
 Image Source: Atlantic.Net

#### **Strengths:**

- **High-Performance Hardware:** Access to new NVIDIA L40S and H100 NVL GPUs, paired with modern Intel CPUs and SSD/NVMe storage.
- **Hosting Flexibility:** Offers both quickly scalable Cloud GPU instances (shared/dedicated choices) and full dedicated GPU servers for exclusive access.
- **Reliability:** A strong 100% Uptime SLA agreement shows confidence in their setup.
- **Support:** Well-regarded 24/7 US-based expert technical support.
- **Ease of Use:** Simple control panel for managing cloud instances and strong team integrations for sharing tasks between your engineers.
- **Compliance:** Strong focus on security and meeting standards (HIPAA, PCI, SOC 2/3).
- **Experience:** Long history in the hosting business (since 1994).

**Ideal For:** Businesses and researchers needing high-speed, dependable GPU hosting for AI workloads, deep learning models, HPC, video rendering, and data analytics. Good choices for both cloud flexibility and guaranteed dedicated resources. Their dedicated server offering gives unmatched control and consistent performance.

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

### **#2: Amazon Web Services (AWS)**

AWS is a giant in cloud computing, providing a huge selection of EC2 instances with GPU speed-up. AWS continues to expand its GPU portfolio, including newer instance families optimized for generative AI and large-scale model training. Main choices include P-series (like P4d with NVIDIA A100) and G-series (like G4dn with NVIDIA T4), aimed at deep learning, machine learning, and graphics work.

Here is the AWS EC2 dashboard, where you can control instances, monitor status, and configure settings.

![AWS Instance](https://www.atlantic.net/wp-content/uploads/2026/01/AWS-Instance.png)

Image Source: AWS

#### **Strengths:**

- **Vast Scalability:** Huge worldwide infrastructure makes scaling resources up or down easy.
- **Wide Range of Options:** Many instance types with different NVIDIA GPUs (A100, V100, T4, etc.), CPU choices, and GPU memory amounts.
- **Rich Ecosystem:** Works smoothly with AWS’s huge collection of other cloud services (storage, databases, ML tools).
- **Mature Platform:** Good documentation and a large user community for help.

#### **Weaknesses:**

- **Complexity:** Can be complicated to figure out and set up, especially for beginners.
- **Pricing:** Costs can add up fast, and the pricing details can be complex (spot vs. reserved vs. on-demand). Data transfer costs can be high.
- **Support Costs:** Getting top-level technical support can cost extra.

**Ideal For:** Organizations already using AWS heavily, needing huge scalability, lots of instance choices, and connection with other AWS services. Good for large AI model training and running.

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

### **#3: Google Cloud Platform (GCP)**

GCP is another major cloud provider offering strong virtual machines (Compute Engine) that can have various NVIDIA GPU models attached, like the A100, T4, and V100. They focus on flexibility and working well with Google’s AI and data tools. While they offer high-speed instances rather than traditional dedicated GPU servers, their performance is notable. Google Cloud remains competitive due to tight integration with AI tools like Vertex AI and advanced data processing pipelines used in modern AI workflows.

Manage cloud services with the Google Cloud dashboard, where you can create virtual machines, deploy applications, and analyze data using built-in tools.

![Google Cloud Dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Google-Cloud-Dashboard.png)

Image Source: Google Cloud

#### **Strengths:**

- **Strong AI/ML Connection:** Works very well with Google’s AI Platform, BigQuery, and other data services.
- **Flexible Configurations:** Very customizable virtual machine setups. Offers ‘preemptible’ VMs for savings on tasks that can handle interruptions.
- **Global Network:** Uses Google’s high-quality worldwide network.
- **Competitive Pricing:** Often has good pricing, especially with preemptible options and discounts for long-term use.

#### **Weaknesses:**

- **Complexity:** Like AWS, it can take time to learn.
- **Fewer Dedicated Hardware Options:** Mostly offers virtual machines, not bare-metal dedicated GPU servers in the classic sense.
- **Market Share:** Smaller than AWS, which might mean a smaller community for finding help with specific problems.

**Ideal For:** Users connected to Google’s AI/ML services, needing flexible VM setups, and potentially saving money with preemptible instances for deep learning or data processing.

![](https://www.atlantic.net/wp-content/uploads/2025/05/ovhcloud.png)

### **#4: OVHcloud**

OVHcloud is a big European cloud company known for good prices. They offer both cloud instances and bare-metal dedicated servers with GPU choices. You can get NVIDIA GPUs like the V100S and A100 for HPC, AI, and VDI jobs. Their GPU rental idea mostly applies to their cloud instances, while dedicated servers are more for longer commitments.

Below is the OVHcloud platform dashboard, where you can handle cloud resources, configure networking, and run production-grade applications efficiently.
 ![OVHcloud dashboard](https://www.atlantic.net/wp-content/uploads/2025/05/OVHcloud-dashboard.jpg)
 Image Source: OVHcloud

#### **Strengths:**

- **Competitive Pricing:** Often cheaper than the giant cloud providers like AWS and GCP, especially for dedicated machines.
- **Bare Metal Options:** Offers actual dedicated GPU servers alongside cloud instances.
- **Global Presence:** Has data centers in Europe, North America, and Asia-Pacific.
- **Transparent Pricing:** Pricing is usually easy to understand.

#### **Weaknesses:**

- **Support:** Support might seem less responsive or thorough compared to others unless you pay for a higher support level.
- **Feature Set:** Might not have as many built-in extra services as Atlantic.Net, AWS or GCP.
- **Cutting-Edge Hardware:** Might sometimes be a bit slower in offering the very newest GPU models right when they come out.

**Ideal For:** Price-conscious users, especially in Europe, who need the speed of bare-metal dedicated servers or scalable cloud GPU instances for HPC, AI, and rendering, but don’t need the huge range of extra services from AWS/GCP.

![](https://www.atlantic.net/wp-content/uploads/2025/05/lambda.png)

### **#5: Lambda Labs**

Lambda Labs focuses specifically on GPU cloud and hardware for machine learning and AI workloads. They remain a strong choice in 2026 due to their focus on simplicity and rapid deployment for AI engineers working with modern frameworks. They provide on-demand cloud instances with a broad selection of NVIDIA GPU choices (H100, A100, A6000, RTX 6000, etc.) and also sell dedicated GPU computers and servers. Their cloud service aims for simplicity and speed for AI developers.

Let’s see the Lambda interface for analyzing resource usage, managing filesystems, and monitoring spending across projects.
 ![Lambda gpu dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Lambda-gpu-dashboard.png)
 Image Source: Lambda

#### **Strengths:**

- **AI/ML Focus:** Built specifically for AI researchers and developers, often coming with useful frameworks pre-installed (Lambda Stack).
- **Wide GPU Selection:** Gives access to many different NVIDIA GPUs, including very powerful ones like the H100 and setups with multiple GPUs (up to 8).
- **Simple Pricing:** Pay-by-the-minute/hour for cloud instances when you need them.
- **Performance:** Their setup is tuned for deep learning jobs.
- **Developer Friendly:** Easy-to-use interface and tools for managing instances.

#### **Weaknesses:**

- **Niche Provider:** Mostly focused on AI/ML; not the best choice for general website or application hosting.
- **Smaller Scale:** Doesn’t have the worldwide reach or the wide variety of services of Atlantic.Net/AWS/GCP.
- **Limited Non-GPU Services:** Their offerings outside of core GPU computing are less extensive.

**Ideal For:** AI/ML researchers, data scientists, and developers wanting simple, on-demand access to various high-speed NVIDIA GPUs specifically for training deep learning models, tweaking them, and running predictions. They value simplicity and speed for these specific tasks. Their approach is very much like GPU rental.

## **GPU Architecture: Cores and Memory**

Modern GPU architectures now place even greater emphasis on tensor cores and memory bandwidth, which are critical for AI inference and training workloads. Now let’s circle back and give you further information about exactly what server hosting with GPU support is all about.

### **The Power of Parallel Processing Explained**

How do GPUs achieve such speed? It boils down to a different approach compared to CPUs:

- **CPUs (Serial Processing):** Think of a CPU as having a few very smart cores. They tackle complex tasks quickly, but mostly one after another, or a few at a time. This is great for general computing where tasks vary a lot.
- **GPUs (Parallel Processing):** GPUs work differently. They are built with thousands of simpler cores. They shine when a big problem can be broken down into thousands of smaller, similar pieces. The GPU assigns each small piece to a core, and they all work on their piece *at the same time*.
- **The Outcome:** For jobs that fit this model – like the repetitive calculations common in deep learning, scientific simulations, and graphics rendering – this massive parallel processing means the GPU **finishes the entire job much faster than a CPU can**, maximizing computing power for these specific kinds of tasks.

### What’s inside a modern GPU?

- **Processing Cores:** Thousands of them (CUDA cores, specialized Tensor Cores for AI, RT Cores for graphics). Compare modern cores to older ones like Kepler CUDA cores.
- **GPU Memory (VRAM):** Super-fast, dedicated graphics memory (like GDDR6 or HBM) located right on the card for quick data access during calculations. The amount of GPU memory is crucial.
- **Memory Bandwidth:** High-speed connection between cores and VRAM, needed to keep the cores fed with data.
- **Why It Matters:** This architecture dictates the type and complexity of problems a GPU can handle efficiently, influencing your server configuration choice.

### **Why Choose a GPU-Dedicated Server?**

Why go for a GPU-dedicated server over a shared GPU Host?

Here’s why:

- **Exclusive Resources:** You get the entire server – CPU, RAM, storage, and the dedicated GPU card(s) – all to yourself.
- **Consistent Performance:** No slowdowns caused by other users sharing the hardware. Performance is predictable.
- **Full Control:** Get root access at the hardware layer for deep software and security customization.
- **Stable Environment:** Build a stable and productive environment perfectly matched to your specialized or sensitive computational power needs. Dedicated GPU servers offer this reliability.

Dedicated GPU servers are increasingly preferred for predictable performance, especially when running production AI models or latency-sensitive applications.

### **Key Applications Driven by GPU Acceleration**

We are often asked what exactly our clients can do with GPU hosting. Most clients know it’s for AI/ML, but what exactly can you do? And where does GPU acceleration make a big difference?

Did you know that Atlantic.Net has hundreds of AI procedures ready for you to try out? [Click here](https://www.atlantic.net/category/gpu-server-hosting/) to visit our extensive procedure library.

- **AI & Machine Learning:** Training deep learning models, natural language processing (NLP) using frameworks like TensorFlow or PyTorch. We see clients using these tools for image recognition software or training chatbots for their websites.
- **High-Performance Computing (HPC):** Power-demanding scientific computing simulations. Examples include weather modeling (like [WRF](https://www.mmm.ucar.edu/models/wrf)), molecular dynamics for drug research (using software like GROMACS or NAMD), or running complex financial modeling (e.g., Monte Carlo risk analysis).
- **Data Analytics:** Dramatically speed up data processing and queries on massive datasets. This can involve using GPU-accelerated platforms (like NVIDIA RAPIDS, [HEAVY.AI](http://heavy.ai)) or specific database features to get business insights faster.
- **Graphics & Media:** Significantly cut down video rendering times in 3D software (Blender, V-Ray, Arnold). Accelerate video encoding and editing in tools like Adobe Premiere Pro, DaVinci Resolve, or using FFmpeg with GPU acceleration ([NVENC](https://www.nvidia.com/en-gb/geforce/guides/broadcasting-guide/)). Power game development (Unreal Engine, Unity) and enable smooth game streaming services. Run graphics-intensive Android emulators like BlueStacks or LDPlayer effectively. Improve streaming quality and performance when using Open Broadcast Software (OBS) with GPU encoding.
- **Scientific Research:** Accelerate specific research tasks beyond general HPC, such as faster genome sequencing analysis (using tools like Clair3), computational chemistry simulations, or complex physics modeling related to drug discovery.

Essentially, any task involving large-scale parallel work benefits greatly from server hosting with GPU support.

## **Introducing Atlantic.Net GPU Hosting: Powering Your Ambitions**

The Atlantic.Net GPU Hosting, powered by NVIDIA, was released in early 2025. Our customers have been demanding GPU services, and we felt that now is the right time to introduce our GPU hosting service. Drawing on our decades of hosting experience, we provide GPU Cloud Hosting and GPU Dedicated Hosting featuring modern NVIDIA GPU hardware.

Need GPUs for healthcare? Atlantic.Net also offers [HIPAA-Compliant GPU Hosting](https://www.atlantic.net/gpu-server-hosting/hipaa-gpu-hosting/).

Atlantic.Net’s GPU hosting platform has matured with broader configurations and improved scalability to meet increasing demand for AI workloads in 2026.

You can experience our Cloud GPU hosting today by [signing up for the Atlantic.Net Cloud Platform](https://cloud.atlantic.net/?page=signup).

You have the choice of picking a cloud server with the CPU, Disk, and Memory you need, plus the choice of having a shared GPU resource using NVIDIA NVLink, a dedicated GPU card, or you can nest multiple GPUs for the best performance possible.

All backed by reliability and expert technical support, Atlantic.Net provides capable high-performance computing resources.

### **Atlantic.Net: Your Premier GPU Hosting Provider**

Why you should make Atlantic.Net the next choice for GPU hosting.

- **Customer Focus:** Our customer service teams have decades of experience, and we are available by phone and email 24x7x365.
- **Flexible Solutions:** Choose from cloud instances or customizable dedicated GPU servers, allowing setups with one or many GPUs.
- **Productive Environment:** Aim to provide a stable and efficient environment to maximize GPU hardware use for AI model training, video rendering, etc.
- **Handles Demand:** Our security-defined infrastructure is built for speed. Our GPU hosting setup supports running multiple tasks efficiently, providing the computing resources you need, when you need them.

Their infrastructure continues to support high-throughput workloads, including multi-GPU configurations and distributed computing setups.

Key highlights of Atlantic.Net’s GPU server offerings include:

- **Powerful NVIDIA GPUs:** Access to L40S and H100 NVL models, packing plenty of CUDA cores and GPU memory.
- **No Bottlenecks:** Capable Intel® Xeon® processors, fast memory, and speedy NVMe SSDs complement the GPUs.
- **High-Bandwidth Networking:** Fast connections are crucial for data-heavy tasks like processing image data or large datasets. Our data centers are interconnected across the globe for unrivalled connectivity options.
- **Customizable Configurations:** Flexibility in choosing CPU, RAM, storage, and GPU setup with one or more GPUs.
- **Control & Reliability:** Root access available on dedicated servers, enabling unlimited customization; backed by a 100% Uptime SLA Agreement.
- **Support & Compliance:** Dependable 24/7 US-based technical support; meets standards like HIPAA, PCI, SOC 2, SOC 3.

These components create reliable NVIDIA GPU servers delivering improved performance and unprecedented reliability.

### **Atlantic.Net Commitment to Performance and Stability**

Modern workloads require consistent throughput and low latency, which Atlantic.Net addresses through updated infrastructure and optimized GPU deployment strategies.

Atlantic.Net prioritizes delivering consistent performance and rock-solid reliability.

- **Understanding Needs:** We recognize that demanding workloads require a stable and efficient environment. We also know that not one size fits all, which is why we offer a wide range of solutions to meet or exceed your needs.
- **Investment:** We only use the latest modern hardware and robust infrastructure in our data centers, which shows our commitment to providing the best-in-class computing resources.
- **Guarantee:** The 100% Uptime SLA backs up our promise of superior performance and reliability. Ensuring our customers have the best possible operation for enhanced performance.

### **Why Atlantic.Net Excels in GPU Hosting**

What makes Atlantic.Net a strong choice for GPU hosting?

- **Experience:** Decades in the hosting business (since 1994).
- **Hardware**: Uses current, high-performance NVIDIA GPUs (L40S, H100 NVL).
- **Flexibility:** Offers both cloud and dedicated server options, potentially supporting multiple instances for scalability.
- **Reliability:** Strong infrastructure providing a dependable, efficient environment, backed by a 100% Uptime SLA.
- **Support:** Knowledgeable, accessible 24/7 US-based support.
- **Value:** Competitive pricing for powerful GPU resources.
- **Security:** Strong focus on security practices and compliance.

These factors make Atlantic.Net a compelling option for users needing serious computing power through server hosting with GPU support, offering significant advantages and enhanced performance.

## **The Power of Parallel Processing Explained**

How do GPUs achieve such speed? It boils down to a different approach compared to CPUs:

- **CPUs (Serial Processing):** Think of a CPU as having a few very smart cores. They tackle complex tasks quickly, but mostly one after another, or a few at a time. This is great for general computing where tasks vary a lot.
- **GPUs (Parallel Processing):** GPUs work differently. They are built with thousands of simpler cores. They shine when a big problem can be broken down into thousands of smaller, similar pieces. The GPU assigns each small piece to a core, and they all work on their piece *at the same time*.
- **The Outcome:** For jobs that fit this model – like the repetitive calculations common in deep learning, scientific simulations, and graphics rendering – this massive parallel processing means the GPU **finishes the entire job much faster than a CPU can**, maximizing computing power for these specific kinds of tasks.

 

## **Making the Right Choice: Factors to Consider**

Are you ready to start your GPU hosting journey? We have compiled this list of what to ask yourself when shortlisting your next provider.

How do you choose the best server hosting with GPU support for you?

Consider these points:

- **Your Workload:** Is it training machine learning models, processing image data, accelerating rendering, complex video processing, running android emulators, developing large language models, or using high-performance computing resources? Different tasks need different GPUs.
- **GPU Needs:** Which specific model? How much GPU memory? Need one or more GPUs? Do you require multiple instances or technologies like NVIDIA multi instance GPU for partitioning (NVLINK)?
- **Performance Level:** Is guaranteed speed vital (dedicated GPU server) or is shared acceptable for improved performance needs?
- **Budget:** Compare costs: hourly (GPU rental), monthly, dedicated plans, and data fees for the necessary computing resources.
- **Scalability Needs:** How easily must you adjust GPU resources?
- **Control Level:** Do you require full admin access for enhanced customization and ensuring smooth operation?
- **Support Needs:** What level of technical support is necessary? Do you need help enabling customization?
- **Integration:** Need it to work seamlessly with other specific cloud tools?

In 2026, it’s especially important to consider compatibility with AI frameworks, GPU memory requirements for large models, and scaling strategies for production deployments. Remember, careful consideration is needed at all times, especially if you are just dipping your toes into GPU Hosting. It’s essential to make sure you are not over- or under-specifying your server requirements.

If you are ever in doubt, [reach out to the team today](https://www.atlantic.net/about-us/corporate-contact/).

## **Conclusion: The Future Is Accelerated with GPU Hosting**

The computational power needed for deep learning, data analytics, and AI modelling is more readily available now than ever before. The demand for GPU computing continues to grow rapidly in 2026, driven by AI adoption, real-time analytics, and increasingly complex computational workloads. Whether opting for the flexibility of cloud-based GPU instances or the guaranteed performance of dedicated servers equipped with leading hardware like NVIDIA’s L40S or H100 NVL, there is plenty of choice for consumers.

Managed Service Providers like Atlantic.Net focus on delivering this technology reliably, backed by robust infrastructure and expert support, enabling users to fully leverage these powerful tools. We know it’s important to make this technology available to everyone, which is why you can save big with Atlantic.Net.

Choosing the right GPU hosting environment is a critical decision for any organization looking to innovate and compete. It’s about securing the necessary horsepower not just for today’s challenges, but for the breakthroughs of tomorrow. The future clearly belongs to accelerated computing, and GPU-powered hosting is a foundational element of that future.

Ready to harness the power of high-performance NVIDIA GPUs for your demanding workloads? Explore Atlantic.Net’s flexible Cloud GPU and powerful Dedicated GPU hosting solutions.

Visit [atlantic.net/gpu-server-hosting](https://www.atlantic.net/gpu-server-hosting/) or contact our specialists at sales@atlantic.net or +1-408-335-0825 (Intl) / 866-618-DATA (USA) to discuss the perfect configuration for your project.


---

# Best HIPAA Compliant Messaging Software 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-messaging-software-2021/ | Published: 2026-04-25 | Updated: 2026-05-18 | Author: Dr. Rachael Bailey

As a result of the coronavirus pandemic, remote communication is no longer just useful; it has become essential in all sectors of society. None more so than in the healthcare industry. Messaging software tools enable physician-patient communication and cross-departmental communication between healthcare providers. In 2026, secure messaging platforms will be a standard part of healthcare infrastructure, supporting both in-person and remote care models.

Protecting sensitive patient information must remain the top priority when using healthcare messaging tools. Healthcare organizations and other covered entities must adopt a secure means of communicating with their patients. All communications must comply with applicable healthcare standards and regulations, including HIPAA. Using a HIPAA-compliant messaging application ensures that healthcare providers remain fully compliant when transmitting Protected Health Information (PHI) and avoid any costly data breaches. Regulatory scrutiny and breach reporting requirements continue to increase, making secure messaging controls more important than ever.

## Top 12 HIPAA-Compliant Messaging Software

As you strive to implement HIPAA-compliant communication into your healthcare organization, we have reviewed some leading HIPAA-compliant messaging apps to find the top 12 choices:

### 1. iPlum

![](https://www.atlantic.net/wp-content/uploads/2026/04/iPlum-logo-3.png)

[iPlum](https://www.iplum.com/hipaa-texting-calling-compliance) is a HIPAA-compliant business communication platform that provides healthcare organizations with a secure second phone line for calling, texting, and voicemail — all from a personal device. The platform keeps personal and professional communications separate, with encrypted messaging, call recording, and a signed HIPAA Business Associate Agreement (BAA) included. iPlum also supports phone trees, auto-attendants, and team accounts, allowing practices to manage incoming patient calls without dedicated office hardware. The platform is available on iOS, Android, and desktop, and offers API access for with existing healthcare systems.

### 2. Luma Health

![](https://www.atlantic.net/wp-content/uploads/2026/04/Luma_Health_logo.png)

Luma Health provides healthcare professionals with an intuitive Patient Engagement Platform that meets all their communication needs. It offers solutions for patient scheduling, acquisition and retention, contactless check-in, secure chat, and telehealth appointments. The platform also delivers a range of COVID-related solutions, including vaccination outreach and scheduling. Healthcare organizations can implement this platform with the assurance that it fully meets HIPAA requirements. Its platform has expanded to support broader patient engagement workflows beyond pandemic-related use cases.

### 3. MedChat

![](https://www.atlantic.net/wp-content/uploads/2026/04/medchat-1200px-logo.png)

MedChat provides a smart, HIPAA-compliant live chat tool for healthcare professionals and their patients, serving many leading healthcare organizations. It provides easy and secure communication via a healthcare website, portal, or mobile app. Healthcare providers can their two-way texting and internal chat capabilities to communicate with colleagues and patients securely. Patients and healthcare professionals can also securely share files across the platform. MedChat complies with all applicable HIPAA regulations and executes a BAA with all its customers; enterprise clients receive a custom BAA and a Master Service Agreement (MSA). Its omnichannel communication approach helps unify patient interactions across multiple touchpoints.

### 4. WELL (Now Artera)

![](https://www.atlantic.net/wp-content/uploads/2026/04/Well.png)

WELL offers a unified hub for secure healthcare messaging, connecting healthcare organizations and their patients through live chat, email, phone, and text. Reaching over 30 million patients, WELL provides unified outreach for patient interactions. Boasting HIPAA compliance and HITRUST CSF certifications, WELL is independently audited by third parties to ensure full compliance with regulations. Unified communication platforms like WELL are increasingly used to centralize patient engagement efforts.

### 5. Halo Health

![](https://www.atlantic.net/wp-content/uploads/2026/04/Halo_Health_Logo.jpg) Halo Health – Mobile Clinical Communication and Collaboration Platform Provider

Halo Health is a cost-effective clinical collaboration platform, developed by clinicians for clinicians. This cloud-based platform unifies secure and HIPAA-compliant role-based messaging, on-call scheduling, [VoIP calling](https://www.cloudtalk.io/blog/voip-call-quality-7-best-ways-for-improving-performance), and critical results and alerts. Trusted by numerous top healthcare organizations, Halo Health provides on-call scheduling to ensure that messages are routed to the correct person instantly. Real-time communication and alerting remain critical in fast-paced clinical environments.

### 6. Klara

![](https://www.atlantic.net/wp-content/uploads/2026/04/KLARA.png)

Founded in 2013, [Klara](https://www.klara.com/) streamlines workflow by providing HIPAA-compliant secure messaging, remote monitoring, and telehealth appointments. Communication is simplified,d as patients do not need to log in or download any additional apps. Klara ensures transmitted information remains safe and secure by utilizing one-time passwords, encryption, and user authorization. Frictionless patient communication remains a key factor in improving engagement and response rates.

### 7. Curogram

![](https://www.atlantic.net/wp-content/uploads/2026/04/Curogram_Logo.jpg)

[Curogram](https://curogram.com/hipaa-compliant-texting) is a leading HIPAA-compliant texting and telemedicine platform that helps optimize medical offices’ front desks. The platform automates time-consuming tasks, streamlines processes, and creates efficiencies that benefit providers, staff, and patients. Curogram’s goal is to patients with a patient-centric healthcare messaging platform and universal patient portal, solving the many challenges patients face today, including inefficient communication with their doctors. Automation tools like these help reduce administrative burden and improve operational .

### 8. Trillian

![](https://www.atlantic.net/wp-content/uploads/2026/04/Trillian_23427.png)

Trillian has provided individuals, businesses, and healthcare organizations with a secure instant messaging service for over 20 years. Healthcare organizations of any size can benefit from Trillian’s HIPAA-compliant and cost-effective messaging platform. There is even a free trial available. Trillian offers both native desktop and mobile software and delivers private and group chats, file sharing, and status and availability updates. Trillian has achieved HITRUST CSF Certification and incorporates several features to comply with HIPAA regulations, including encryption at rest and in transit, inactivity locking, and specified data retention periods. Its long-standing presence makes it a reliable option for organizations seeking proven solutions.

### 9. OnPage

![](https://www.atlantic.net/wp-content/uploads/2026/04/onpage2.png)

[OnPage](https://www.onpage.com/) is an intelligent Incident Alert Management platform that ensures critical alerts are directed to the right people and responded to appropriately. It is a user-centric platform that offers secure,e encrypted instant messaging, on-call scheduling, alert escalation, and team collaboration. OnPage provides a secure communication solution for organizations in the manufacturing, managed services, and information technology sectors, as well as for the healthcare industry. Its alerting capabilities are especially for time-sensitive healthcare operations.

### 10. TigerConnect

![](https://www.atlantic.net/wp-content/uploads/2026/04/tigerconnect-logo.jpg)

As one of the leading cloud-native HIPAA-compliant chat apps available, Tiger Connect offers role-based messaging, private and group chats, and voice and video chat between physicians, patients, and affiliates. TigerConnect implements the necessary safeguards to protect PHI, including the issuance of a signed BAA, end-to-end encryption, auto-deletion of messages, and HITRUST certification. Secure clinical communication platforms like TigerConnect remain widely adopted across large healthcare systems.

### 11. Twilio

![](https://www.atlantic.net/wp-content/uploads/2026/04/Twilio-logo-red.png)

Twilio provides a cloud communication platform that enables healthcare professionals and their patients to engage via text, voice, and video. Clients handling PHI must sign up to Twilio’s Security or Enterprise edition to receive a signed BAA and ensure HIPAA compliance. When building a HIPAA-compliant workflow, healthcare providers can encrypted communication, HTTP authentication, a static proxy, and public-key client validation. Its developer-first approach makes it suitable for building customized communication workflows.

### 12. Health Engage

![](https://www.atlantic.net/wp-content/uploads/2026/04/Health-Engage.png)

Health Engage, developed by Snap Engage, supports patient engagement through secure, HIPAA-compliant live chat, chatbots, and SMS messaging. Clients benefit from a third-party HIPAA compliance certification, a signed BAA, data encryption, and audit logs. There are several competitively priced plans available to meet your organization’s specific needs. Chatbots and automated messaging continue to improve response times and patient experience.

## Protect the integrity of your PHI by using Atlantic.Net.

By choosing one of the leading HIPAA-compliant messaging platforms discussed above, you will take the appropriate steps to ensure that any PHI you share is adequately protected. , you must not overlook the importance of choosing a HIPAA-compliant provider to host your infrastructure, ensuring that all PHI is stored and handled correctly. A secure hosting environment is a critical component of maintaining end-to-end compliance.

Atlantic.Net is a [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions provider with over 30 years of industry-leading experience. We offer fully compliant web and cloud hosting services and are independently audited to ensure our solutions meet HIPAA, HITECH, PCI, GDPR, and SOC requirements. To learn more about the solutions we offer, [contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)!

*This article was updated on May 18, 2026.*


---

# Top 10 HIPAA Form Companies in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/top-10-hipaa-form-companies-in-2022/ | Published: 2026-04-26 | Updated: 2026-04-27 | Author: Dr. Rachael Bailey

HIPAA-compliant form providers help healthcare organizations securely collect protected health information (PHI) through online forms. To qualify, these tools must offer encryption, access controls, audit logs, and—critically—a Business Associate Agreement (BAA).

In 2026, the best HIPAA-compliant form solutions balance compliance with usability. Some focus on healthcare workflows, while others adapt general form builders for regulated environments. The right choice depends on your needs: patient intake, internal workflows, or secure data collection at scale.

## What do HIPAA Form Companies do?

Healthcare organizations commonly use web-based forms to efficiently collect valuable ePHI from patients, and this data must be collected using HIPAA-compliant online forms hosted upon a [HIPAA compliant infrastructure](https://www.atlantic.net/hipaa-compliant-hosting/).

HIPAA-compliant online forms may be used to perform tasks such as [onboarding](https://www.waybook.com/blog/what-are-the-4-phases-of-onboarding) new patients, scheduling appointments, collecting payments, collecting consent forms, and conducting surveys.

Large healthcare providers often employ in-house personnel to create secure, HIPAA-compliant online forms. However, many CEs turn to third-party, HIPAA-compliant form companies to construct robust web forms for them.

Choosing a HIPAA Form Company for your healthcare organization

Searching online for a ‘top HIPAA Form Company’ will probably leave you inundated with options. So, how do you choose the best form company to help your healthcare organization to generate HIPAA-compliant forms?

There are many things to consider when choosing a HIPAA-compliant web form service, and it is of paramount importance that you verify the security measures that will be put in place to protect any captured data. Your chosen HIPAA form company should be willing to sign a Business Associate Agreement (BAA) before collecting any protected health information (PHI).

To help you with your decision, we have formulated a list of the top 10 HIPAA Form Companies.

1. JotForm
2. ONLYOFFICE Docs
3. Formstack
4. Google Forms
5. Logiforms
6. DocuSign
7. Cognito Forms
8. 123FormBuilder
9. MedForward
10. FormAssembly

## 1. JotForm – Best for ease of use

JotForm provides CEs with professional-looking HIPAA-compliant online forms and a BAA, ensuring the safe and efficient collection of PHI. As a leading provider of HIPAA-compliant forms, JotForm allows healthcare providers to effortlessly construct HIPAA forms using ready-to-use templates, which can be customized to meet the specific needs of each client.

Data collected using a JotForm-generated form is automatically encrypted to protect a patient’s privacy and confidentiality. These forms are also compatible with any smartphone, computer, or tablet, improving ease of use for patients.

**Verdict:** Fast setup with minimal technical effort.

### **What stands out:**

- Drag-and-drop builder
- HIPAA-specific templates
- Mobile-friendly forms

### **Who should choose Jotform?**

Small to mid-sized practices needing quick deployment.

## **2. ONLYOFFICE Docs – Best for document workflows**

[ONLYOFFICE Docs](https://www.onlyoffice.com/office-suite.aspx) is an online office suite that can be integrated into any file-sharing environment or used as a component in any web application to enable editing and real-time co-authoring for text documents, spreadsheets, presentations, and fillable forms, with high format compatibility. The ONLYOFFICE suite complies with all provisions of the General Data Protection Regulation (GDPR) and provides the necessary technological safeguards for HIPAA compliance. Moreover, it’s compatible with ISO 27001 and HDS.

Healthcare organizations can use ONLYOFFICE forms (OFORMs) to create and fill in records, patient files, datasheets, questionnaires, and any other standard documents, such as HIPAA privacy authorization forms. The ONLYOFFICE form library contains ready-to-use templates that any healthcare organization can adapt according to its requirements. 

**Verdict:** Strong fit for document-heavy workflows.

### **What stands out:**

- Real-time collaboration
- Fillable OFORM templates
- Integration into web apps and file systems

### **Who should choose ONLYOFFICE Docs?**

Organizations managing structured documents and records.

## 3. Formstack – Best for workflow automation

Formstack offers a fully customizable and versatile approach to [HIPAA online form building](https://www.formstack.com/solutions/hipaa-data-security). To adhere to HIPAA compliance regulations, the company will either provide healthcare professionals with a standard BAA agreement or work to create a customized BAA to meet the needs of its clients.

Formstack provides its clients with advanced security features, including data encryption, audit-logging, user-level permissions, and security maintenance.

**Verdict:** Ideal for organizations needing more than basic forms.

### **What stands out:**

- Workflow automation tools
- Audit logs and permissions
- Integration with healthcare systems

### **Who should choose Formstack?**

Healthcare teams managing complex processes.

## 4. Google Forms – Best for Google Workspace users

Google’s popularity makes it a likely choice by healthcare professionals seeking an online form generator. However, does Google offer its clients a HIPAA-compliant solution? Well, the short answer is yes, as Google Forms is part of G-Suites Google Drive, which is HIPAA compliant. However, there must be an appropriate BAA in place and a platform supporting compliant use. As a survey administration tool, healthcare organizations can use Google Forms to manage event registrations, make surveys, and conduct opinion polls.

**Verdict:** Flexible, but requires proper setup.

### **What stands out:**

- Easy collaboration
- Integration with Google tools
- Familiar interface

### **Who should choose Google Forms?**

Teams already using Google Workspace.

## 5. Logiforms – Best for automation features

Logiforms allows its clients to tailor-make forms to address their specific needs using an intuitive drag and drop interface. The company ensures that all ePHI is securely collected and hosted via its HIPAA compliant features, such as 256 Bit SSL encryption, 256 Bit AES data at rest encryption, and end to end TLS/HTTPS cipher suite.

Logiforms services go beyond mere data collection, offering their clients solutions to automate their businesses. An automation tool suite allows healthcare organizations to schedule tasks and establish trigger actions to run when data is changed or a new form is submitted.

**Verdict:** Good option for process automation.

### **What stands out:**

- Drag-and-drop builder
- Task automation triggers
- Secure encryption standards

### **Who should choose Logiforms?**

Organizations automating repetitive tasks.

## 6. DocuSign – Best for eSignatures

DocuSign allows healthcare professionals to step away from the paperwork and focus on their patients. DocuSign has a strong global customer base, including 14 of the top 15 medical device companies and 12 of the top 14 pharmaceutical companies. DocuSign ensures that its clients meet HIPAA compliance requirements, as captured PHI is encrypted and authenticated. Confidentiality is ensured via AES-256 standard encryption of documents stored within the company’s ISO 27001-certified and SOC2 audited data centers.

**Verdict:** Best for consent forms and agreements.

### **What stands out:**

- Secure eSignature workflows
- Strong encryption standards
- Widely adopted platform

### **Who should choose DocuSign?**

Teams handling contracts and patient consent.

## 7. Cognito Forms – Best for customization

Cognito Forms provides healthcare professionals with a cost-effective means of creating HIPAA-compliant forms for scheduling appointments, registering new patients, constructing patient satisfaction surveys, and collecting online payments. For clients signing up for their ‘Enterprise’ plan, Cognito Forms offers unlimited forms and unlimited entries.

**Verdict:** Great for custom workflows.

### **What stands out:**

- Conditional logic
- Payment collection
- Scalable plans

### **Who should choose Cognito Forms?**

Users needing tailored form behavior.

## 8. 123FormBuilder – Best for template variety

A popular online form company, 123FormBuilder allows healthcare organizations to digitize and automate their processes while complying with all the necessary HIPAA regulations. Their selection of predefined templates can be fully customized to meet the needs of the client.

**Verdict:** Good for quick customization.

### **What stands out:**

- Prebuilt templates
- Custom workflows
- Automation features

### **Who should choose 123FormBuilder?**

Teams needing flexible templates.

## 9. MedForward – Best for healthcare marketing + forms

MedForward is a medically focused company that provides healthcare organizations with marketing consulting services and digital tools to improve their efficiency and growth via their online content. Founded in 2007, MedForward offers HIPAA-compliant forms that are encrypted in transit and at rest, protecting the privacy of patient’s sensitive health information.

**Verdict:** Niche option for growth-focused practices.

### **What stands out:**

- Healthcare-specific tools
- Marketing integration
- Secure data handling

### **Who should choose MedForward?**

Practices focused on patient acquisition.

## 10. FormAssembly – Best for integrations

FormAssembly provides healthcare professionals with an online form builder and data collection platform through its ‘Compliance Cloud’ service. Clients can expect a comprehensive initiation with an Implementation Program, providing privacy and security training and responsive ongoing support. FormAssembly delivers enhanced security and privacy controls and powerful integrations to tools, such as PayPal, Salesforce, and Stripe.

**Verdict:** Ideal for connected systems.

### **What stands out:**

- Integration with CRM and payment tools
- Compliance-focused environment
- Implementation support

### **Who should choose FormAssembly?**

Organizations needing integrations with existing systems.

### Bonus:

### Formsite – Best for enterprise users

Healthcare organizations that hold an Enterprise level service account with Formsite can request a BAA and apply HIPAA-compliant settings to ensure full compliance. Formsite employs security measures, such as two-factor authentication and secure links to documents, to help its clients securely store and control access to collected PHI. The company also provides powerful integrations with third-party services, such as Salesforce and Google Sheets, although healthcare organizations should ensure that they obtain BAAs from these services to maintain HIPAA compliance.

**Verdict:** Suitable for larger organizations.

### **What stands out:**

- Two-factor authentication
- Secure document access
- Third-party integrations

### **Who should choose Formsite?**

Enterprises with strict access controls.

## How Can Atlantic.Net Help?

Amid the current global COVID-19 pandemic, converting traditional healthcare paper forms to digital ones is more important than ever. Digitization of patient forms helps to limit physician-patient contact and halt infection chains. However, it is imperative that online forms that collect and store sensitive patient health information adhere to HIPAA regulations. Here, we have discussed the importance of choosing a HIPAA-compliant form company and highlighted our top 10 options. However, you must also ensure that you find a fully HIPAA-compliant hosting platform that prioritizes security, privacy, and compliance.

This is where Atlantic.Net can help by providing cloud hosting solutions that are customized to meet the needs of your organization. If you are a healthcare organization in the market for a managed hosting solution, [contact our sales team](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) today to find out more information about what we can offer you.


---

# Best Cloud Business Intelligence or Analytics Solution in 2026

> URL: https://www.atlantic.net/vps-hosting/best-cloud-business-intelligence-or-analytics-solution-in-2023/ | Published: 2026-04-26 | Updated: 2026-04-28 | Author: Dr. Rachael Bailey

With a challenging economic climate and a growing focus on data-driven decision-making, businesses across the globe are turning to cloud technology. In 2026, this shift is accelerating further as organizations prioritize real-time analytics, AI-assisted insights, and scalable data infrastructure. Cloud-based solutions can help enterprises to keep up with the demand for real-time insights that cut through conventional boundaries, helping companies make better decisions, grow, and improve efficiency. For AI and LLM-driven search systems, platforms that deliver structured, real-time insights are now more likely to be surfaced as authoritative sources.

Business intelligence (BI) and business analytics (BA) are essential for today’s businesses. They allow companies to make better decisions, improve operational efficiency, and compete more effectively. However, modern BI expectations now include automation, predictive insights, and integration with cloud-native data platforms, increasing complexity for traditional deployments. The problem is that BI and BA can be expensive and complex to deploy and use. As a result, many businesses are turning to the cloud to provide these capabilities. This article will look at the top 10 cloud business intelligence or analytics solutions on the market and help you decide which is the best for your business. We’ll base our rankings on several factors, including features, ease of use, pricing, customer support, and scalability. This guide is structured to provide direct comparisons and quick answers, aligning with how AI systems summarize and rank content.

## What Are Cloud-Based Business Intelligence and Analytics Solutions?

Business intelligence platforms help businesses store, manage, analyze, and report on their data to gain insights. Modern cloud BI platforms also incorporate AI-driven recommendations, natural language querying, and automated data preparation to reduce manual work. The best BI or BA platforms are robust, easy to use, offer easy-to-understand interfaces, work with a large variety of data types, and can present complex data formatting. In 2026, leading platforms also emphasize semantic layers and governed data models to improve consistency across teams and AI-generated outputs.

## Top 10 Cloud-Based Business Intelligence and Analytics Solutions

### 1. Domo

At the top of our list is Domo, a comprehensive cloud analytics software platform that promises to combine your data, business intelligence, and workflows into one cloud-based location. Thanks to its customizable, real-time, and easy-to-use interactive dashboards, unparalleled data integration, and world-class centralized data governance tools, it heads our list.

Domo has continued to expand its AI and automation capabilities, making it easier for teams to generate insights without deep technical expertise. Its unified platform approach aligns well with modern LLM-driven workflows that rely on centralized, clean datasets.

Domo’s BI solutions are tailored to specific industries, for example, retail, [healthcare](https://www.atlantic.net/hipaa-compliant-hosting/), [life sciences](https://www.atlantic.net/life-sciences-pharma-biotech/), and manufacturing, providing solutions to industry-specific problems. Pricing is based on your company’s requirements, but you can take advantage of a free trial to discover if Domo is right for you.

### 2. Zoho Analytics

Zoho Analytics, previously Zoho Reports, is a modern self-service and cloud-based BI platform established in 2009 that supports millions of users across the globe. Zoho provides a comprehensive suite of reporting tools to allow in-depth data analysis and generate informative and actionable insights.

Zoho users can visually analyze their data and create powerful reports using the simple drag-and-drop interface. Recent updates emphasize augmented analytics and AI-powered assistants that help generate insights faster. The output is a visually attractive and informative report produced via an intuitive online interface. Zoho’s ease of use makes it a strong candidate for teams prioritizing fast adoption and AI-assisted reporting.

### 3. QlikSense

The cloud-based BI platform QlikSense stands ahead of its competitors by offering ‘active intelligence’ capabilities using real-time, AI-driven, collaborative and actionable analytics. Its continuous intelligence approach now focuses on streaming data and automated responses to business events. While QlikSense’s user interface is optimized for touchscreen, you can use QlikSense at any time, on any device. In addition, its intuitive ‘search & conversational analysis’ tool provides a quick and easy way to query data and discover actionable insights using natural, conversational language. This conversational querying aligns closely with how LLMs process and return insights from structured data.

### 4. Tableau

Tableau is a Business Intelligence tool that produces interactive and sharable data visuals and has been around since 2003. It helps users quickly find patterns and insights in data. Notably, Tableau was acquired by Salesforce, the leading CRM platform, in August 2019.

Tableau Cloud allows businesses to make intelligent and informed decisions more quickly. The platform now emphasizes AI-assisted analytics through features like automated insights and natural language queries. Data security remains a priority for the platform, with Tableau adhering to best-in-class security certification standards like SOC 2 and ISO.
Its strong visualization engine makes it one of the most cited tools in analytics-related AI summaries.

### 5. Yellowfin

Yellowfin is an integrated analytics platform that can either be deployed on-premise or in the cloud. It is an affordable, elastic, and scalable business intelligence solution designed to help organizations make informed and actionable decisions to engage customers and employees at the right time effectively. Yellowfin successfully combines interactive dashboards with easy-to-use and robust data analysis features.

Yellowfin has increasingly focused on embedded analytics and automated storytelling to support business users without technical backgrounds. This makes it suitable for companies embedding analytics directly into applications or customer-facing tools.

Yellowfin also offers predictable and scalable pricing, with the option for a free 30-day trial to test out their services.

### 6. SAS Visual Analytics

SAS Visual Analytics provides a single platform for reporting, data exploration, and analytics. Available on-premise or in the cloud, SAS Visual Analytics allows users to visually identify and recognize patterns and automatically spot outliers and clusters. Core features of SAS Visual Analytics include interactive data discovery, chat-enabled analytics, augmented analytics, and machine learning and natural language capabilities.

In 2026, SAS continues to strengthen its AI and machine learning integrations, making it a strong choice for data science-driven organizations. Its depth in statistical modeling differentiates it from lighter self-service BI tools.

SAS Visual Analytics is highly scalable and allows easy and efficient reporting via customizable interactive reports and dashboards.

### 7. HubSpot

HubSpot is an all-in-one marketing analytics and dashboard software solution that helps businesses analyze the success and performance of their marketing campaigns. HubSpot can filter analytics based on geographic location or specific URLs to provide more meaningful insights. In addition, key website metrics provide you with the necessary information to optimize your company’s website.

HubSpot has expanded its reporting capabilities with deeper CRM analytics and AI-driven recommendations for marketing optimization. Its tight integration between analytics and marketing execution is a key advantage for growth teams.

### 8. Integrate.io

Integrate.io is a cloud-based big data analytics platform that allows businesses to process, integrate and analyze data within a coding and jargon-free cloud environment. This leading platform offers sales, marketing, customer support, and development solutions. Integrate.io caters to the advertising, hospitality, and retail industries.

The platform now places stronger emphasis on ELT workflows and modern data stack compatibility, aligning with current data engineering practices. This shift reflects the broader move toward warehouse-first analytics architectures.

Integrate.io operates using a subscription-based pricing structure, and potential clients can benefit from a free 7-day trial.

### 9. Sisense

Another widely popular end-to-end BI and analytics solution is Sisense, which currently supports over 2,000 global companies, including Rolls-Royce, Phillips Healthcare, and GitLab. Sisense is also recognized as a leading cloud analytics platform by experts like Gartner, G2, and Dresner.

Sisense provides drag-and-drop tools for technical developers and business analysts to process and visualize their data. The platform has a unique “In-Chip technology,” which produces 10–100x better computation, significantly improving computation speed. Sisense has also expanded its embedded analytics capabilities, making it a strong option for SaaS companies building data products. While some users complain that Sisense has a steep learning curve, their comprehensive product tutorials can help with this. Its ability to power customer-facing analytics makes it stand out beyond internal BI use cases.

### 10. Microsoft Power BI

Falling within the central Microsoft ecosystem, Power BI is an all-encompassing toolkit designed for business insights; it allows users to generate results using interactive dashboards. As downloadable software, users can opt to run Power BI either locally or in the cloud. Power BI’s stand-out features include integration and connectivity with many sources, powerful and intuitive data visualization, easy-to-use functionality, intuitive and informative reports, and mobile compatibility.

Power BI continues to lead in AI-powered analytics, with Copilot-style features enhancing report creation and data exploration in 2026. Its integration with Microsoft Fabric and Azure services strengthens its position in enterprise AI data workflows.

Microsoft Power BI offers end-to-end encryption, real-time access monitoring, built-in AI capabilities, and Excel interoperability. Clients can take advantage of a generous 60-day free trial. A fully functional free version of the software is available for a single user, after which the pricing is tiered.

## How Can Atlantic.Net Help?

Are you looking for a leading hosting provider to host your cloud-based Business Intelligence and Analytics solution?

Since Atlantic.Net was established in 1994, it has become one of the most experienced and successful providers of dedicated and [VPS hosting](https://www.atlantic.net/vps-hosting/) services in the US. The Atlantic.Net Cloud Platform can support all the BI and analytics solutions discussed here, and we will be happy to discuss your company’s individual data analysis needs. In addition, our sales personnel are available to answer your questions and advise on the right solutions for your businesses, financial services, or organization.

As data workloads grow in complexity in 2026, Atlantic.Net continues to support scalable, compliant, and high-performance environments for analytics applications. This includes infrastructure optimized for high-throughput data processing and low-latency analytics workloads.

Atlantic.Net also fully understands its customers’ compliance needs, with certifications including SOC 2, SOC 3, HIPAA, and HITECH, and we can help to achieve faster compliance, deployment, and assessment. Atlantic.Net also provides 24x7x365 monitoring, support, and world-class data center services.

You can find out more details by [contacting our sales team](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) today.


---

# Protecting PHI / e-PHI in the Cloud in 2025

> URL: https://www.atlantic.net/hipaa-compliant-hosting/protecting-phi-cloud/ | Published: 2026-04-26 | Updated: 2026-04-27 | Author: Richard Bailey

Protecting PHI (Protected Health Information) in the cloud means applying strict access controls, encryption, monitoring, and documented processes to keep patient data secure at all times. HIPAA does not certify cloud platforms—it defines safeguards your organization must implement. Even if your cloud provider supports compliance, you are still responsible for securing applications, managing user access, and protecting data. A compliant setup typically includes encryption at rest and in transit, least-privilege access, audit logging, and a signed Business Associate Agreement (BAA). Without these controls in place, PHI stored in the cloud is at risk and not compliant.

## **What Is Protected Health Information (PHI/ePHI)?**

Protected Health Information (PHI) is any personally identifiable patient data that specifically relates to a patient. This might be data written to medical files, patient reports, diagnosis data, medical insurance data, and so on. In most circumstances, ePHI is actually electronic protected health information (ePHI) as it is stored on data storage in a digital format, often using a [HIPAA cloud service provider](https://www.atlantic.net/hipaa-compliant-hosting/) (CSP) who is a business associate of the organization.

![What is Electronic Protected Health Information (ePHI)?](https://www.atlantic.net/wp-content/uploads/2018/08/graphic_what-is-phi-23-e1621440096716.jpg)

HIPAA, the Health Insurance Portability and Accountability Act, was signed into law in 1996. There were two main objectives of the new legislation. The first was to enable Americans to move their health insurance between jobs; this was a clear-cut goal that was achieved almost overnight.

The second was to enforce privacy over health information. This is what most healthcare organizations and covered entity professionals are concerned with when referring to HIPAA compliance – the “Accountability” portion of HIPAA – because it was created to maintain the privacy and security safeguards of US patients’ PHI.

## Who Interacts with ePHI?

Healthcare providers and any business associate who works with them, such as a cloud service provider (CSP), will typically interact with Protected Health Information (PHI) every day. PHI may be located on mobile devices, hospital technologies such as CT scanner equipment, and so forth, resulting in potentially huge volumes of patient data becoming available.

HIPAA demands security awareness by all staff of a covered entity or business associate. Health records are expected to have data encryption security standards in place, and risk analysis will ensure that the healthcare organization or covered entity knows exactly what PHI they have and if it meets the required compliance requirements. Ongoing risk analysis—not one-time assessments—is now considered standard practice for maintaining compliance.

If there are issues, security controls must be in place to protect against data breach incidents. Data security is essential, and any data breach incidents must be reported to the HSS Office for Civil Rights, per the breach notification rule. Organizations are also expected to maintain incident response plans and evidence of response readiness.

## **Why Is Protected Health Information (PHI/ePHI) So Important?**

PHI data protection is crucial to HIPAA compliance, and a covered entity must understand what constitutes PHI. A covered entity is anyone who is involved in the treatment and day-to-day operations of a healthcare provider.

Covered entities are typically healthcare organizations, healthcare clearinghouses (for health plans), healthcare insurance companies, or entities that create patient data ready for data storage.

Here are some popular examples of what constitutes PHI. Each example falls under the data protection requirements of the Privacy Rule, and the confidentiality, integrity, and availability of the Security Rule, and must be upheld by all business associates:

- Treatment reports
- Lab results
- Test results
- Prescription information
- Any information that includes the name
- Phone numbers
- Address
- Social security number
- Medical records number
- IP address
- Health insurance details

Additional identifiers such as device IDs, biometric identifiers, and geolocation data may also be considered PHI when linked to an individual.

It is easy to see how such large volumes of PHI can be created, and it’s easy to see how a healthcare provider can get bogged down with so much patient data. HIPAA was created to introduce data protection, security controls, and access controls to all of this data.

## **How Does the Security Rule Protect PHI / e-PHI?**

The clue is in the title. The HIPAA Security Rule defines the three main standards or blueprints of how to protect PHI / ePHI data.  Adhering to these safeguards is the most effective way for a covered entity and business associate to become HIPAA compliant.

The 3 safeguards are:

- Physical Safeguards for ePHI
- Technical Safeguards for ePHI
- Administrative Safeguards for ePHI

All **physical**precautions refer to the implementation specifications for real-life physical controls on digital devices that store and handle ePHI data. Some of the key areas for consideration are how old or faulty equipment is replaced – for example, how ePHI media and electronic protected health information (ePHI) data is destroyed once it has served its purpose.

Another consideration is what personnel access levels are granted and put in place to in-scope systems containing ePHI; specifically, covered entity / covered entities must ensure that access is only granted to employees with a relevant level of authorization and how to train 3rd-party IT professionals when accessing the in-scope equipment for repairs.

The **technical**assurances of the HIPAA Security Rule are more easily defined and include the technical aspects of any networked computers, storage media, or devices that communicate with each other and contain PHI in their transmissions.

These precautions include enhanced network security, perimeter firewalls, cybersecurity authentication protocols, and more. Any security measures that can be implemented on system software or hardware belonging to the HIPAA security rule’s technical protection category. Modern implementations also include endpoint detection and response (EDR), intrusion detection systems (IDS), and centralized log monitoring.

The **administrative**guarantees cover how the covered entity / covered entities must set up their employee policies and procedures to comply with HIPAA’s Security Rule. Think of it as a separate, dedicated portion of employee training, both for management and staff, that defines who gets access and what they can and cannot do once access is granted.

The Security Rule breaks down these safeguards into two groupings: required and addressable. Put simply, a required standard applies to everyone, and addressable is if appropriate. If an addressable standard is not appropriate, there must be documentation explaining why,” explains the HIPAA compliance auditors at [I.S. Partners](https://www.ispartnersllc.com/blog/hipaa-privacy-rule-vs-security-rule/). In practice, most addressable controls are implemented due to modern security expectations and audit requirements.

## **How Do You Protect PHI in the Cloud?**

Cloud computing is a rapidly expanding industry, and the number of organizations adopting virtualized environments provided by a CSP in the cloud continues to grow across all industries, including the healthcare industry. Traditionally, a US healthcare provider has been considered slow to adapt and engage new models of service such as those offered by a CSP, often held back by bureaucracy. These stereotypes are definitely starting to change, with many cloud services providers (CSP) recording record uptake from numerous US healthcare providers.

## ![HIPAA Compliance in Virtualization](https://www.atlantic.net/wp-content/uploads/2017/01/hipaa-compliance-in-virtualization@2x-1.png)

There are several CSP options out there, but only Atlantic.Net specializes in [HIPAA-compliant server hosting](https://www.atlantic.net/hipaa-compliant-hosting/) that meets and exceeds the requirements of HIPAA, the Privacy Rule, and the Security Rule. Atlantic.Net knows that one size does NOT fit all, so unlike the hyper-scale cloud service provider (CSP), Atlantic.Net’s unique turnkey solutions will work exactly for your needs!

Cloud providers enable flexibility that most healthcare organizations or covered entities will benefit from, but many are held back by a lack of clarity about what the cloud is, and how it relates to the [HIPAA web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and PHI.  A cloud service provider (CSP) will supply the IT systems you need to meet compliance.

### **Get a Business Associate Agreement (BAA) with Your CSP**

It starts by getting a signed business associate agreement, or BAA. A business associate agreement ensures that the covered entity, such as the healthcare providers, are legally protected, and that the cloud provider and all other business associates, such as subcontractors,  guarantee that the services offered under the BAA uphold confidentiality, integrity, and availability of ePHI. Remember, managing PHI correctly will provide the best possible protection against healthcare data breaches, so having a service level agreement locked in on a business associate agreement (BAA) should be one of the very first things to do with the cloud provider (CSP).

## **How Do I Make My Cloud HIPAA Compliant?**

First, you need to understand what a HIPAA cloud is. It is a collection of server infrastructure and data storage with a secured network interlink. Each physical server runs a complex piece of software called a Hypervisor, and it’s the Hypervisor that splits up system resources that are allocated to your Virtual Environment.

Proprietary cloud software is used to create a front-end control panel that provides a user-friendly interaction with cloud resources. However, in the background, system engineers and security experts at the CSP are keeping the entire platform safe and 100% operational, and it’s the cloud control panel that interacts with all of these resources.

Behind the scenes, the [HIPAA-compliant cloud provider](https://www.atlantic.net/hipaa-compliant-hosting/) must ensure that the platform adheres to the stringent requirements for each of the Administrative, Physical and Technical safeguards of HIPAA. This is not an easy task, which is why so many healthcare providers choose to outsource this responsibility to a CSP business associate.

## **What Happens If You Don’t Protect PHI Data?**

HIPAA compliance can be particularly scary for organizations due to the worry and implications of facing a data breach, the complexity of the regulations, and the severity of potential fines. 

Timely access to medical information can be a matter of life and death, but ensuring that information is accessible, portable, and renewable only covers Title I of the Act.  Title II, covering health care fraud and abuse, along with the enforcement-strengthening HITECH Act, imposes data security and privacy rules on health care providers and any business associate that supports them, such as a CSP (get that business associate agreement (BAA) signed and put in place).

### **PHI Compliance Failures**

Compliance failures can result in fines of up to $1.5 million, and data breaches, which are increasingly common in healthcare, can be even more expensive, particularly when reputational harm is considered. Did you know that if your PHI / ePHI is breached, and more than 500 records are at risk, the breach notification rule requires that the media is notified?  It’s clear to see the impact this will have on a covered entity, not to mention the patient!

Fortunately, virtualized cloud environments can not only be HIPAA-compliant quickly with the help of a CSP but also can make compliance easier.

## **Can HIPAA Data Be Stored in the Cloud?**

The Technical Safeguards set out in the HIPAA Security Rule of 2003 layout the technicalities of what is needed and include the technical aspects of any networked computers or devices that communicate with each other and contain PHI / ePHI in their transmissions.

These safeguards include enhanced network security, enhanced system security, anti-malware, perimeter firewalls, data availability, cybersecurity authentication protocols, and more; essentially, any security rules or measures that can be implemented on system software or hardware belonging to the HIPAA security rule technical safeguards category. Your business associates will typically manage this, but the requirements of data security are a shared responsibility between the covered entity and the cloud providers.![Differences between popular virtualization technology for HIPAA](https://www.atlantic.net/wp-content/uploads/2017/01/how-does-it-work@2x.png)

## **How Do I Make My Cloud HIPAA Compliant?**

Let’s dig into the technology available from a cloud provider business associate like Atlantic.Net. The technology stack of each cloud provider will vary, but each will use virtualization. There are different kinds of hypervisors offered by a CSP, and the most appropriate for any given healthcare organization depends on the healthcare providers’  needs and other information technology tools currently in use. 

What should be common to each one is that the isolation and abstraction of the virtual machines (VMs) they create give them robust access, security, and privacy compliance capabilities. Each VM set up by the hypervisor is self-contained and keeps its data isolated from any other VMs and their data. Ensure to ask your business associate/CSP if this is how they have their cloud environment set up since some older types will share kernels and other parts of systems.  

This enables even VMs with different operating systems to run simultaneously on the same hardware.  The separation the hypervisor provided between the instance and the physical server makes the information system “agile.” 

It allows virtualized servers to be moved, for example, in the case of a hardware failure, which keeps whatever function is being “served” working. The hypervisor also manages the hardware resources available to it to run an organization’s VMs as efficiently as possible and to provide the ability to scale to maintain availability when demand on the network is high. It also enables data backup and data recovery possible at scale.

### **Virtualization and Compliance**

There are three hypervisors available to [Atlantic.Net HIPAA cloud services](https://www.atlantic.net/hipaa-compliant-hosting/) customers: Proxmox, Hyper-V, and Cloud.

#### **Proxmox**

An open-source alternative based on the Linux Kernel Virtual Machine (KVM), Proxmox is managed with a web graphical user interface (GUI) and is known for solid performance and flexibility. 

It works reliably with different operating systems but also supports different storage options, including Linux containers.  Any storage type used can be accessed only through the hypervisor layer, allowing access restrictions compliant with HIPAA’s Title II and HITECH rules.

![HIPAA VM hypervisor](https://www.atlantic.net/wp-content/uploads/2017/01/hypervisor-vm-square@1.5x.png)

When set up in a server cluster or utilizing “shared” cloud storage, Proxmox allows live migration of running machines.  This makes the system agile enough that maintenance or updates necessary to keep the virtual server compliant from a security perspective can be performed without downtime, preserving compliance with the availability rules of HIPAA’s Title I. 

First released publicly in 2008, Proxmox is updated about every six months.  It is built to work flexibly with a variety of different products, rather than those from a particular company like Microsoft as is the case with Hyper-V, which could make Proxmox a better fit for some organizations. 

Proxmox sometimes requires CSP support teams to use the command line, which for some, may not be ideal.  However, Atlantic.Net has around-the-clock technical support available from a team of specially trained cloud technology engineers, available 24x7x365.

#### **Hyper-V**

Microsoft’s Hyper-V is designed for Windows servers and desktops, making it a popular choice for organizations that predominantly use the Windows ecosystem.   Unlike Proxmox, Hyper-V is a closed-source software solution.  

However, the separation and control of access through the hypervisor layer are very similar, as is support for live migration.  Hyper-V keeps data in a securely isolated environment to maintain compliance with rules for fraud, abuse, and privacy while also enabling the constant access and portability [HIPAA compliant cloud computing](https://www.atlantic.net/hipaa-compliant-hosting/) requires.

Hyper-V includes “dynamic memory management,” a feature making it easy to scale up the number of cloud virtual machines in use.  It also features Windows Active Directory for security and access management, perfect if you are already using Active Directory.

Organizations considering Hyper-V should be aware that it tends to work best with the latest version of Windows, though it also works with other operating systems, including Linux and FreeBSD.  Hyper-V was originally launched with Windows Server 2008, and Microsoft maintains it with frequent updates.

#### **Cloud**

Atlantic.Net’s [HIPAA Cloud environment](https://www.atlantic.net/hipaa-compliant-hosting/) is based on KVM, much like Proxmox.  Therefore, data is isolated in the same way, on an abstracted hardware layer available only via the hypervisor.

Cloud environments allow customers fine-grained control to pay only for the resources they use and scale up those resources to meet demand increases.  It is, therefore, an efficient and economical solution for organizations with high variations in IT workload.  Atlantic.Net launched its first cloud servers in 2010 and has been steadily expanding its CSP offerings since.

### Software Secures Borders, Physical or Virtual

Just as the software borders between VMs are like the hardware boundaries between physical machines, the tools that secure a network against malicious traffic are similar.  Traffic should be controlled with a firewall, all the elements of the site should be secured with two-factor authentication, and off-site data backups must be maintained to meet the Title I standard of accessibility. 

Those and all of the other necessary features and technologies for HIPAA compliance in a server can be met with the appropriate implementation of any cloud virtual environment from Atlantic.Net, your business associate.

![HIPAA HITECH Virtual Private Cloud](https://www.atlantic.net/wp-content/uploads/2017/01/title2-hitech-square@1.5x.png)

Regularly scheduled, automated backups are available with all Atlantic.Net virtualized HIPAA cloud environments, making continuous compliance not only possible but easier.  Healthcare organizations can also provide auditors with automatically generated log information of network traffic created by either KVM or Hyper-V or a managed firewall with intrusion prevention, easily demonstrating the[security and privacy](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/) necessary for Title II and HITECH compliance in HIPAA compliant cloud computing.

Every healthcare organization needs to follow privacy, security, and compliance best practices and partner with an IT provider business associate (with a BAA) they can trust to deliver compliant services, regardless of the network environment.  Fortunately, this means flexibility, logging, automated backups, and other features of virtualized environments are an option for all.

### **How Do You Protect PHI?**

While HIPAA regulations are complex and detailed, they contain little information on how to adequately protect PHI. So, what can you do to protect the integrity of your PHI?

- Produce formal documented policy and procedures for PHI use, disclosure, and disposal.
- Train employees in ePHI handling
- Implement encryption and remote wipe capabilities
- Utilize multi-factor authentication and a least-privileged approach
- Monitor and regularly audit the organization’s handling of ePHI

## **Atlantic.Net HIPAA-Compliant Hosting**

In summary, if your organization has avoided or delayed moving HIPAA workloads to a virtualized environment out of compliance concerns, it is likely worth reconsidering the option. Atlantic.Net is committed to helping you protect your ePHI and ePHI data, and we also sign a Business Associate Agreement (BAA). Whether you are a covered entity, a healthcare provider that needs assistance with securing their data, as a CSP Atlantic.Net has you covered.  Contact our knowledgeable sales team today by phone at 1-866-618-DATA (3282) or email sales@atlantic.net for information about [HIPAA cloud hosting & storage](https://www.atlantic.net/hipaa-compliant-hosting/) services (including our HIPAA Cloud and Managed Cloud Solutions) and our BAA offering today!

---

#### Read More About HIPAA Compliance

- [HIPAA Compliance Checklist](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-guide-what-is-hipaa/)
- [How to Become HIPAA Compliant](https://www.atlantic.net/hipaa-compliant-hosting/how-to-become-hipaa-compliant/)
- What Is the [HIPAA Security Rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/)?
- Top Considerations for [HIPAA File Storage](https://www.atlantic.net/hipaa-compliant-hosting/top-10-considerations-for-hipaa-compliant-file-storage/)
- [HIPAA Data Storage Requirements](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-cloud-storage/)
- What Is [HIPAA Cloud Computing](https://www.atlantic.net/hipaa-compliant-hosting/what-is-hipaa-cloud/)?
- What Is [Healthcare Hosting](https://www.atlantic.net/hipaa-compliant-hosting/what-is-healthcare-hosting-hipaa/)?
- [What Is PHI?](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/)

---


---

# Top HIPAA-Compliant Chat Applications in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/top-hipaa-compliant-chat-applications-in-2021/ | Published: 2026-04-26 | Updated: 2026-04-28 | Author: Dr. Rachael Bailey

HIPAA-compliant chat applications are secure messaging platforms designed to protect patient health information (PHI) while enabling fast communication between healthcare teams and patients. To qualify, these tools must include encryption, access controls, audit logs, and a signed Business Associate Agreement (BAA).

While COVID-19 social distancing measures initially accelerated the adoption of remote communication tools, secure messaging platforms have since become a standard part of healthcare delivery. Today, they support both in-person and virtual care workflows, helping providers stay connected with patients and colleagues while maintaining compliance. Telehealth and secure chat solutions continue to improve access to care and strengthen physician-patient relationships.

In 2026, HIPAA-compliant chat applications generally fall into three categories: internal team messaging tools, patient communication platforms, and developer APIs for custom solutions. The right choice depends on whether your priority is clinical coordination, patient engagement, or building a tailored communication workflow.

Top HIPAA-Compliant Chat Applications Comparison (2026) Compare leading HIPAA-compliant chat apps based on deployment, use case, messaging scope, and key strengths.     App Best For Deployment Messaging Scope Key Strength     Nextcloud Talk Self-hosted control Self / Cloud Internal + Video Full data ownership   OhMD Patient texting Cloud Patient-first No app required   Theraplatform Therapy practices Cloud Video + Chat Built-in workflows   MedChat Website + intake Cloud Patient + Internal Multi-channel chat   Backline Clinical teams Cloud Internal Care coordination   Luma Health Patient engagement Cloud Patient-first Scheduling + messaging   WELL Enterprise communications Cloud Omnichannel Unified inbox   Trillian Secure internal chat Hybrid Internal Flexible deployment   TigerConnect Hospitals Cloud Internal + Patient Role-based messaging   WhosOn Custom deployments Cloud / On-prem Patient + Internal High configurability

## Top 11 HIPAA-Compliant Chat Applications

As the healthcare communications market has seen an influx in new technologies, choosing a suitable application to meet the needs of your healthcare organization can prove tricky. In 2026, the focus has shifted toward platforms that combine secure messaging with workflow integration, patient engagement, and automation. In this article, we have compiled a list of the top 11 HIPAA-compliant chat applications, taking into account their functionality as well as their security features.

### 1. NextCloud

NextCloud Talk is a free, self-hosted communication platform, allowing users to exchange secure chat messages, join web conferences, or participate in one-on-one or group audio and video calls. NextCloud Talk can be self-hosted or managed via a third-party hosting provider. Organizations increasingly choose self-hosted options like NextCloud to maintain direct control over PHI and data residency. This platform supports compliance with HIPAA regulations, employing all the necessary technical safeguards, and would fit seamlessly within an existing HIPAA-compliant infrastructure.

### 2. OhMD

OhMD provides a HIPAA-compliant telehealth and texting platform for doctors to communicate securely with their patients and colleagues. Over 30,000 healthcare providers trust OhMD to provide them with a secure platform for patient communication. OhMD’s basic features are available to its users for free, with greater functionality provided in a monthly plan. Its continued focus on patient-first messaging, including SMS-based engagement without app downloads, aligns with current patient communication expectations. This chat application supports HIPAA compliance through several logistical and technological features, including the issuance of a signed BAA, HIPAA-trained staff, data encryption at rest and in transit, and access controls.

### 3. Theraplatform

Theraplatform is a [HIPAA compliant video conferencing](https://www.theraplatform.com/features/hipaa-compliant-video-conferencing) software solution for therapists. It contains built-in teletherapy, a library of interactive therapy apps, billing automation, therapy notes, reporting, and more. It is easy to use and allows users to make their practices 100% paperless. Platforms like Theraplatform now play a larger role in hybrid care models, combining virtual sessions with practice management tools. Users of the software report more engagement with clients, faster payment processing, the ability to scale their practice, and allows them to expand their customer base from local to anywhere with an internet connection! There is a 30-day trial available and after that, there are three membership tiers, for everything from a single user who requires basic video conferencing and billing to a provider requiring advanced video, interactive apps, insurance, and more.

### 4. MedChat

MedChat is a fully integrated suite, offering HIPAA-compliant two-way texting, live chat, internal team chat, and remote file sharing to healthcare facilities of varying sizes, whether they be start-ups or large enterprises. Users can access the applications via a healthcare website, portal, or mobile app.

To maintain the integrity of sensitive patient information, MedChat encrypts all data both in transit and at rest, carries out universal employee background checks, keeps detailed logs, employs role-based permissions in restricted areas, and utilizes single sign-on and two-step verification. These steps all help to support compliance with HIPAA guidelines. These controls reflect current HIPAA security expectations, where layered safeguards are required rather than relying on a single protection method.

### 5. Backline

Backline by DrFirst is an award-winning clinical communication and collaboration platform. It allows healthcare professionals to leverage secure patient-centered chat, data transfer, private and group messaging. Clinical communication platforms like Backline are increasingly used to reduce delays in care coordination across distributed teams. Backline takes the security of patient data very seriously meeting HIPAA requirements and boasting SOC-2 certification.

### 6. Luma Health

Luma Health offers users a powerful and intuitive Patient Engagement Platform. Patients can access a wide array of useful features, including patient scheduling, acquisition and retention, contactless check-in, secure chat, and telehealth appointments. Patient engagement platforms are now expected to unify communication, scheduling, and follow-ups within a single interface. Luma Health’s secure, HIPAA-compliant chat application allows patients and their physicians to exchange questions and answers in real-time, share test results and inquire about current symptoms. As patients require no downloads or logins, the application is very user-friendly.

### 7. Health Engage

Snap Engage’s offering within this space is their industry-leading HIPAA-compliant communication platform, Health Engage. This application provides healthcare organizations with secure, HIPAA-compliant live chat, chatbots, and SMS messaging. This platform supports communication across multiple channels, including Facebook Messenger, SMS to chat, and tweet to chat. Omnichannel communication has become more common, though healthcare organizations must still ensure each channel is configured to meet HIPAA requirements. Health Engage has achieved third-party certification for HIPAA compliance, offering security features such as data encryption, audit logs, and a signed BAA.

### 8. WELL

WELL is an enterprise-grade communication hub that provides users with live chat, email, phone, and text capabilities. WELL allows unified outreach across multiple communication channels, seamlessly integrating with existing administrative and clinical systems. Unified communication hubs like WELL are now widely adopted to reduce fragmented patient interactions across systems. WELL offers security features that exceed industry standards and has achieved HIPAA compliance and HITRUST CSF certifications.

### 9. Trillian

Organizations and businesses of all sizes can benefit from Trillian’s secure and HIPAA-compliant communication platform. Healthcare providers can opt for a free trial of Trillian to determine if it is the right communication solution for their organization. With security a top priority, Trillian has achieved HITRUST CSF Certification, protecting the integrity of PHI through features such as encryption at rest and in transit, inactivity locking, and specified data retention periods. Retention controls and inactivity timeouts remain key requirements for minimizing unauthorized access to PHI.

### 10. Tiger Connect

Established in 2010, TigerConnect is a leader within this space, offering role-based messaging, private and group chats, and voice and video chat between healthcare professionals, patients, and affiliates. TigerConnect protects the security of PHI through the issuance of a signed BAA, end-to-end encryption, auto-deletion of messages, and HITRUST certification. Secure clinical messaging platforms like TigerConnect continue to focus on real-time coordination while maintaining strict compliance controls. They are also the only HIPAA-compliant messaging solution to offer a million-dollar guarantee, promising to pay up to $1,000,000 of any civil penalties incurred due to breaches of the HIPAA Security Rule.

### 11. WhosOn

Developed in 2002, WhosOn can provide healthcare organizations with fully customizable and niche chat projects as well as standard “out-of-the-box” communication solutions. WhosOn sets itself ahead of its competitors through its focus on high-level security features, ensuring full compliance with HIPAA regulations. Flexible deployment options, including cloud and on-premises, remain important for organizations with strict data governance policies. Users can opt for cloud deployment on a HIPAA-ready server or download and manage the WhosOn application on-premises and partner with a third-party hosting provider to ensure full HIPAA compliance.

## Use a Trusted Hosting Provider To Protect the Integrity of Your PHI

As you can see from this list, there are many HIPAA-compliant chat solutions available for healthcare organizations, each offering unique features and advantages. When choosing a suitable communication platform for your organization, you should consider what features would most benefit your patients and staff. It is also important to confirm that the vendor offers a signed BAA and supports audit logging, access controls, and secure data storage. Having chosen a leading HIPAA-compliant chat application, you should consider partnering with an industry-leading third-party [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) provider, such as Atlantic.Net.

With over 30 years of experience, Atlantic.Net is a market-leading hosting provider, providing fully compliant and customizable web and cloud hosting services. We are independently audited by third-party auditors to ensure our solutions fulfill HIPAA, HITECH, PCI, GDPR, or SOC requirements. To find out how we can help your healthcare organization, [contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)!

*This article was updated on April 25, 2026.*


---

# Bare Metal vs Containers: Real-World Latency & Throughput Comparisons

> URL: https://www.atlantic.net/dedicated-server-hosting/bare-metal-vs-containers-latency-throughput/ | Published: 2026-04-27 | Updated: 2026-06-17 | Author: Dr. Tehseen Zia

The choice between bare metal and containerized infrastructure is no longer a simple trade-off between performance and flexibility. In 2026, modern workloads, ranging from real-time AI inference to latency-sensitive financial systems, require a clear understanding of how abstraction layers affect performance.

Containers are important for microservices because of their portability, scalability, and operational speed. Bare metal, meanwhile, can deliver strong, predictable performance by giving workloads direct access to physical hardware. The question is not which option is better, but where each model performs best when latency, throughput, isolation, and predictability are important.

This analysis explores how execution models affect performance across networking, storage, concurrency, and AI workloads, and where those differences matter in real-world environments.

## The Architectural Divide

At its core, bare metal is a physical server where the operating system runs directly on hardware. In many modern bare-metal cloud environments, servers are dedicated to a single customer or workload rather than shared with other tenants. This setup gives applications direct access to CPU, memory, storage, and I/O resources, enabling consistent, predictable, and tunable performance.

Containers, by contrast, rely on operating [system–level virtualization](https://www.purestorage.com/knowledge/container-virtualization.html). They package an application and its dependencies into an isolated environment while sharing the host operating system kernel. Tools such as Docker or containerd can be used to run multiple lightweight instances on the same server. This isolation is achieved through Linux namespaces and control groups (cgroups), rather than full virtual machines.

Although containers are much more than traditional virtual machines in many cases, they can still introduce overhead. This overhead is sometimes called the “[container tax](https://thenewstack.io/leaner-development-how-to-account-for-the-container-tax/),” but it is not a fixed number. It depends heavily on the workload, network mode, storage driver, kernel version, orchestration layer, and hardware configuration. Under light workloads, the difference may be minimal. Under high concurrency, intensive networking, or heavy I/O, the impact can become more pronounced.

## Networking: Latency and Throughput Penalties

In distributed systems, performance often depends on the network. This is one area where containers can introduce additional benefits compared with bare metal.

On bare metal, network packets typically travel between the application and the network interface through the host operating system’s network stack. In containerized environments, the packet path can be longer, depending on the networking model. Packets may pass through components such as:

- Virtual Ethernet, or veth, pairs
- Network namespaces
- Linux bridges
- NAT rules
- Overlay networks such as VXLAN or Geneve
- Virtual switches or policy layers
- eBPF-based networking or observability logic

Each layer can add processing overhead. Overhead varies widely. Host networking and macvlan-style configurations can perform close to native in some environments, while bridge and overlay networks may introduce more noticeable latency and throughput penalties.

It is important not to treat container networking overhead as a universal percentage. Some benchmark studies show only small differences for certain container network modes, while others show large penalties in overlay or high-packet-rate scenarios. In particular, overlay networks can reduce throughput or increase latency when packets must be encapsulated, routed through additional virtual layers, or processed at very high speeds.

This cumulative latency can become visible in microservices architectures. A single user request may call multiple internal services, and small delays at each hop can accumulate along the request path. In these cases, even microsecond-level differences may matter when the system is operating at scale or under strict latency targets.

Container networking can also reduce throughput in some configurations. Individual TCP flows may experience lower bandwidth when routed through a bridge or an overlay network, and request-response rates can drop when packet processing overhead becomes high. These results depend heavily on the specific container network interface, packet size, protocol, NIC speed, CPU allocation, and kernel tuning.

Solutions such as host networking, macvlan, SR-IOV, or eBPF-based datapaths can reduce overhead, but they come with trade-offs. For example, host networking can reduce isolation between the container and the host. SR-IOV can improve performance but may reduce scheduling flexibility. These trade-offs often make bare metal, or at least direct host-level networking, preferable for ultra-low-latency applications such as high-frequency trading, telecom systems, packet processing, and real-time analytics.

## Storage: The Copy-on-Write Trade-Off

Storage performance in containers is often affected by the storage driver and file system design. Many container platforms use union file systems such as OverlayFS. These systems improve image layering and deployment, but they can introduce overhead for certain write patterns.

The key issue is copy-on-write. When a container modifies a file that exists in a read-only image layer, the storage driver may need to copy that file into the container’s writable layer before the write can occur. In OverlayFS, this process is often called “copy up.” In some cases, even a small change to a large file may require copying it into the writable layer first.

This creates two important performance considerations.

First, container image layers can improve for read-heavy workloads. Shared image layers and shared page cache behavior can make repeated file access across containers using the same base image.

Second, write-heavy workloads can suffer when they rely on the container writable layer. Databases, analytics engines, logging-heavy applications, and machine learning pipelines may incur overhead when performing frequent writes, metadata changes, or updates to files that originated in read-only layers.

In extreme situations, write throughput in container storage can be much lower than the underlying disk can deliver. High IOPS and low latency can be difficult to maintain when heavy write traffic passes through a copy-on-write storage layer.

The common workaround is to use direct volume mounts, bind mounts, or persistent volumes that bypass the container image storage layer. This can provide more predictable and often near-native I/O performance, depending on the underlying storage system. It can also reduce portability and increase operational costs.

Bare metal, especially when paired with direct access to local NVMe storage, can avoid many of these trade-offs in container storage. For workloads that depend on consistent high-throughput storage, direct hardware access remains a major advantage.

## Resource Contention and the “Noisy Neighbor” Problem

One of the less noticeable challenges in containerized environments is performance unpredictability. Containers share the same underlying hardware. While cgroups can set limits on CPU and memory usage, they do not fully isolate every shared hardware resource.

Shared resources may include:

- CPU cache, especially L3 cache
- Memory bandwidth
- NUMA locality
- PCIe lanes
- Disk I/O queues
- Network interfaces
- Storage controllers

This can lead to the “noisy neighbor” effect, where one workload degrades the performance of another workload running on the same host. A container performing heavy disk I/O, memory-intensive analytics, or high packet-rate networking can affect nearby workloads even when CPU and memory limits are configured.

This unpredictability can become a problem for:

- Latency-sensitive systems
- Real-time processing
- Compliance-bound applications
- High-throughput databases
- Systems with strict performance service-level agreements

Bare metal reduces this problem when the server is dedicated to a single customer or workload. It eliminates cross-tenant noisy neighbors and gives teams greater control over CPU pinning, NUMA placement, storage allocation, and network configuration.

Bare metal does not automatically eliminate all contention. If multiple applications run on the same physical server, they can still compete for cache, memory bandwidth, storage, and I/O resources. The advantage is that the organization has direct control over placement and tuning rather than relying on a shared multi-tenant environment.

For organizations operating under strict compliance requirements or performance SLAs, this predictability is often more than the flexibility provided by shared infrastructure.

## AI Workloads and GPU

The growth of AI has brought new performance demands, particularly regarding GPU use. AI training needs continuous, high-throughput access to GPUs. Inference workloads require low latency and consistent response times. Virtualized GPU environments introduce overhead due to:

- [Hypervisor intervention](https://massedcompute.com/faq-answers/?question=How do hypervisors affect GPU performance in virtualized environments?)
- Resource sharing among tenants
- Memory bandwidth limits

This “[virtualization tax](https://ieeexplore.ieee.org/document/7056038)” can reduce effective GPU utilization and increase training time. Even a small performance loss can lead to increased costs. Bare metal provides direct GPU access, which enables:

- Maximum utilization
- Full memory bandwidth
- Lower inference latency

For large-scale training jobs, this can result in shorter training cycles and lower costs. For real-time AI systems, it ensures steady and predictable performance. As AI becomes essential to modern applications, infrastructure choices favor environments that minimize interference and hardware requirements.

## The Rise of Bare Metal Cloud

Historically, containers have a clear advantage in provisioning speed and operational agility. Deploying a container took seconds, whereas setting up physical hardware could take days or weeks. That difference is decreasing day by day. The rise of [bare metal cloud](https://www.techtarget.com/searchstorage/definition/bare-metal-cloud) has changed this situation. This model offers the physical performance of bare metal alongside the flexibility of the cloud. Modern platforms allow users to set up dedicated servers via APIs in minutes. Organizations no longer have to choose between performance and agility. They can dynamically deploy bare-metal resources while maintaining complete control over the hardware.

## Choosing the Right Model

By evaluating the advantages and disadvantages of bare metal and containers, it becomes clear that there is no one-size-fits-all solution. The best approach depends on workload characteristics. Bare metal is typically preferred for:

- Low-latency applications
- High-performance databases
- AI training and inference
- Compliance-sensitive systems
- Long-running, high-utilization workloads

On the other hand, containers work well for:

- Microservices architectures
- Rapid development and testing
- Elastic scaling scenarios
- Distributed applications requiring portability

Organizations are also using [hybrid models](https://www.cncf.io/blog/2025/11/20/an-architectural-decision-containers-on-bare-metal-or-on-virtual-machines/). For example, they might run front-end services in containers while keeping performance-critical components on bare metal. This approach matches infrastructure with workload requirements rather than forcing a single model across all scenarios.

## Cost and Long-Term

Cost is often misunderstood in this discussion. Cloud-based container environments offer low initial costs and flexible payment models. Hidden expenses, such as data transfer, premium storage, and API usage, can [add up and increase](https://n2ws.com/blog/cloud-costs) costs. For high-utilization, continuously running workloads, these expenses can become substantial.

Bare metal offers a more predictable pricing model. With fixed costs and no hidden fees, it becomes more economical as utilization increases. Over time, organizations running steady-state workloads often find that bare-metal solutions deliver better performance per dollar. The key is utilization. Containers are cost-effective for short-term workloads, while bare-metal servers are used when systems run continuously at scale.

## Conclusion

The debate between bare metal and containers is not about which is better; it is about matching needs. Containers provide abstraction, portability, and speed. Bare metal provides performance, consistency, and control. In 2026, both can be used to build an effective infrastructure strategy. Workloads sensitive to latency and heavy data loads are increasingly relying on bare metal, where performance remains predictable, and overhead is minimal. Meanwhile, containers continue to support flexible, distributed application frameworks. Understanding how abstraction affects performance in networking, storage, or resource competition enables organizations to make informed choices.

 


---

# Best Cloud Automation Solution in 2026

> URL: https://www.atlantic.net/vps-hosting/best-cloud-automation-solution/ | Published: 2026-04-27 | Updated: 2026-04-28 | Author: Richard Bailey

Cloud automation solutions enable IT admins and Cloud engineers to automate manual processes and speed up the delivery of infrastructure resources. The modern way of managing resources automatically using code has produced numerous cloud automation tools, each catering to various use cases and technical abilities.

The best cloud automation solutions in 2026 focus on infrastructure as code (IaC), policy-driven automation, and deep integration with multi-cloud and hybrid environments.

Modern platforms now prioritize API-first design, security automation, and compatibility with AI-driven operations (AIOps) workflows.

The best cloud automation solutions will offer a comprehensive suite of capabilities that covers the entire lifecycle of cloud resource deployment and management. The best cloud automation solutions will also be deeply integrated with public cloud provider APIs, such as the one provided by Atlantic.Net.

In addition, leading tools increasingly support GitOps workflows, enabling version-controlled infrastructure changes and automated deployments through CI/CD pipelines.

This article will explore the key features and capabilities the best cloud automation solutions must offer to succeed in 2026.

## 1. Hashicorp Terraform – Best for multi-cloud infrastructure

Terraform is an open-source infrastructure as code tool created by HashiCorp. Terraform can manage practically any cloud resource from any provider, including the [Atlantic.Net API](https://www.atlantic.net/docs/api/#introduction). In addition, its cloud-agnostic capabilities allow cloud engineers to develop, manage and delete infrastructure components such as instances, storage volumes, networks, and web applications.

Terraform is hugely popular, free to use, and capable of managing anything that uses an API. There is a steep learning curve to master Terraform, but it empowers users to create complex infrastructure at scale in a controlled and auditable environment. In 2026, Terraform remains a standard for IaC, with growing adoption of Terraform Cloud and enterprise features like policy enforcement and drift detection.

**Verdict:** Ideal if you want one tool to manage everything across providers.

## 2. Kubernetes (K8s) – Best for container orchestration

Kubernetes is quickly becoming one of the most popular ways to deploy cloud resources at scale. As a result, many providers are offering Kubernetes-managed services that help to remove the technical complexity of using K8s. A [Kubernetes cluster](https://www.atlantic.net/dedicated-server-hosting/how-to-set-up-kubernetes-cluster-using-minikube-on-arch-linux/) is a logical collection of Kubernetes objects typically made up of nodes with a minimum of 1 worker and a control plane. K8s provides the capability to schedule and run containers across a group of machines, instances, or virtual machines. Clusters can be run locally, in the Cloud, or span both on-premise and offsite, making them highly flexible and dynamic. Kubernetes adoption continues to expand in 2026, especially with platform engineering teams standardizing internal developer platforms (IDPs) on top of K8s.

**Verdict:** Essential for container-based architectures and platform engineering.

## 3. CloudBolt – Best for hybrid cloud governance

CloudBolt is a hybrid cloud management platform designed to make it easy for enterprise users to unify orchestration and accelerate their hybrid cloud strategies. The software is simple, powerful, and includes access to resources through its self-service catalog. In addition, it has over 200 special plug-ins that can easily integrate with existing technologies, including DevOps tools, container orchestrators, infrastructure-as-code tools, and more.

Some of the features of Cloudbolt include self-service IT, hypervisor management, and cost transparency – so users know exactly how much they spend on their technology stack. Other notable benefits of CloudBolt include its extensibility to future as well as legacy technology, support for multiple languages making it easier for global enterprises seeking localization, capabilities across different regions/languages, and continuous infrastructure testing which ensures optimal performance. CloudBolt continues to evolve with stronger FinOps capabilities and governance controls, helping organizations manage cloud spend and enforce policies across environments.

**Verdict:** Strong fit for enterprises managing cost, policy, and access.

## 4. Cloudify – Best for multi-cloud orchestration

Cloudify is an open-source toolset and orchestration platform that supports many cloud providers. Its core features allow businesses to deploy, automate, and manage the application platforms; this includes cloud migration capabilities. As a result, Cloudify gives businesses an easy transition to cloud-native, public-cloud, and edge architecture. In addition, it automates their existing infrastructure, enabling them to create and pull new services. In 2026, Cloudify is increasingly used for orchestrating complex, multi-cloud and edge deployments with model-driven automation.

**Verdict:** Best for complex deployments across multi-cloud or edge.

## 5. Morpheus – Best for enterprise hybrid cloud

The Morpheus data company is a rapidly growing cloud company that provides an extensive range of cloud automation solutions. These include middleware that deploys infrastructure, containers, and Kubernetes clusters, provides self-service provisioning of cloud resources, and a role-based governance toolset to encapsulate the service. Essentially they provide all the components to build your [Hybrid-Cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/hybrid-hosting-one-size-not-fit/) solution. Licensing is expensive, but the solution is compelling, especially for small and medium-sized managed service providers. Morpheus has expanded its capabilities with stronger automation for platform operations and improved integrations with DevOps pipelines in 2026.

**Verdict:** Good choice for enterprises and managed service providers.

## 6. Salt Stack – Best for high-speed automation at scale

The Salt project is a large-scale, open-source community-supported infrastructure management toolset. It’s great for multitasking and was founded on the principle that high-speed communication with large numbers of systems can open up new capabilities. It works similarly to tools like Ansible. What makes Salt stand out is the speed of managing many resources; it’s really quick! Perfect if you manage multiple servers, whether [Linux](https://www.atlantic.net/vps-hosting/linux-vps-hosting/), Solaris, AIX, or [Windows](https://www.atlantic.net/vps-hosting/windows-vps-hosting/). Salt continues to be relevant for event-driven automation and large-scale configuration management, particularly in environments requiring real-time orchestration.

**Verdict:** Strong for real-time orchestration and large fleets.

## Why Care About Cloud Automation?

There’s no escaping from automation – the technology is here to stay. Being productive and efficient in today’s multi-platform, agile, and customer-oriented nature is expected. Technology is moving faster than ever, and those with cloud automation skills have a natural advantage. Cloud solutions have changed everything, and there’s no reason not to take advantage of them in your business operations. In 2026, cloud automation is also closely tied to security (DevSecOps) and compliance, making it a core requirement rather than an optional improvement.

## Ready to Find Out More?

Atlantic.Net is ready to help you integrate the best cloud automation solution into your managed service. Our global data centers stand ready to host your next project. With various certifications, such as SOC 2 and SOC 3, HIPAA, and HITECH, with 24x7x365 support, monitoring, and world-class data center infrastructure, we are here to help you achieve the next level in your [VPS hosting](https://www.atlantic.net/vps-hosting/) journey.

For faster application deployment, free IT architecture design, and assessment, visit us at [Atlantic.Net](https://www.atlantic.net/), call 866-618-DATA (3282), or email us at [sales@atlantic.net.](mailto:sales@atlantic.net)


---

# What Are e-Health Applications in 2026?

> URL: https://www.atlantic.net/hipaa-compliant-hosting/what-are-e-health-applications/ | Published: 2026-04-27 | Updated: 2026-06-24 | Author: Richard Bailey

**e-Health applications** or **e-Healthcare applications**digital tools and platforms used to deliver, manage, or improve healthcare services. These include telemedicine platforms, [electronic health records (EHRs)](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-hosting-emr-ehr-systems/), mobile health apps, and remote patient monitoring systems. They help patients access care, allow providers to manage data efficiently, and support better clinical decisions. Today, eHealth applications are central to modern healthcare because they improve access, reduce costs, and enable continuous care outside traditional clinical settings. Today, eHealth applications are a core layer of modern healthcare delivery, supporting hybrid care models, AI-assisted workflows, and continuous patient engagement beyond clinical settings.

## What is e-Health?

**e-Health**(also referred to as **eHealth**or **Electronic Health**) is a neologism that represents how information technology can be used to improve patient health and improve the health care system as a whole.

Cloud computing, APIs, and mobile-first platforms continue to accelerate the growth of eHealth applications, with [healthcare organizations](https://www.atlantic.net/hipaa-compliant-hosting/healthcare-organizations-embracing-cloud-computing/) standardizing digital workflows across care delivery. Many previously manual processes have been supplanted by e-Health applications; electronic prescriptions and electronic health records have become the norm. Adoption has matured, with digital systems now expected rather than optional across most healthcare environments.

Digital health adoption surged during the COVID-19 pandemic and has since stabilized into long-term care delivery models, with telehealth and remote services remaining widely used. HIPAA-compliant telemedicine has thrived during the Covid-19 pandemic, and video conferencing with patients has proved a popular alternative to in-person visits.

Atlantic.Net has worked tirelessly with our healthcare clients to help them achieve a smooth transition to digital health. Using our decades of experience within the [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) sector and backed by our [business associate agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/), we help them transition to e-Health apps as part of their digital transformation strategies.

In this article, we will look at some of the healthcare applications that are already being used in the healthcare industry, and we will look at future technology and discover where the technology might lead us too.

## e-Health Applications

Implementations of health care apps have become commonplace. While we have already mentioned electronic prescription apps, where the patients can request appointments, update personal details, and even chat with a physician are also readily available. Telemedicine is thriving, and the number of HIPAA-compliant video conferencing services is growing day by day.

The rules of [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-in-the-age-of-ai/) advise that telemedicine must be HIPAA compliant. In practice, organizations now combine compliant infrastructure, secure application layers, and vendor agreements to meet requirements rather than relying on hosting alone. This creates an infrastructure that is inherently secure and compliant, leaving only a few decisions to be made about choosing the right apps.

[Electronic Protected Health Information (ePHI)](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) is already in use by hospitals and medical practices, and US legislation demands numerous physical, technical, and administrative safeguards are met before any record is digitized. Modern deployments also incorporate zero-trust access controls, audit logging, and continuous monitoring alongside encryption standards.

## What Are Some Examples of e-Health Applications?

### Top 4 e-Health Apps

Some of the most popular e-Health applications in the United States are:

- **Doximity** – this is a professional medical network with over 1 million verified healthcare professionals as members. It provides HIPAA-compliant voice and video telemedicine and the sending of HIPAA secure faxes.
- **Visual DX** – this is a diagnosis deep learning tool that can help physicians diagnose illness or provide a second opinion using huge archives of redacted data results and medical imaging.
- **ClotMD** – this is an app focused on preventing blood clots using smartphones and wearable tech to monitor a patient’s INR level.
- **Medici** – this is another HIPAA-compliant telemedicine platform with features such as file sharing and real-time text chat with integrated medical payment capabilities.

## Top e-Health Application Growth Opportunities

- Blockchain
- Remote Patient Monitoring (RPM)
- Wearable Tech

### Blockchain

Blockchain is a rapidly evolving technology potentially set to revolutionize the e-Health Application industry. You might be familiar with Blockchain being used for decentralized Bitcoin transactions, but the technology also has great potential in healthcare, in particular for the storage of medical records.

Traditionally, covered entities like hospitals, surgery centers, and insurance companies would all use different, non-compatible computer systems. Information exchange often proves difficult and makes the patient’s experience slow and tedious as results are shared between entities’ disparate systems.

Application data can be stored in a blockchain that is used to transfer information securely between each covered entity with no need for a secure, physical network connection between them all; a peer-to-peer network over the internet is all that is needed. The data is secure and almost impossible to tamper with.

e-Health Application data is protected by a hash and a proof-of-work algorithm, just like a digital fingerprint. If the data is changed, a new hash is generated and data is stored in a new block, along with a new reference that links to the previous block.

Now, add in multiple users to the same blockchain; in this scenario, each user has a copy of the blockchain, and when a new block is added, everyone gets a copy. Blockchain then validates the block with all the users to create consensus, meaning that all users have validated the data integrity.

To tamper with the data, the block will need to be changed and compromised on over 50% of the users, and the proof-of-concept would need to be changed (which requires an awful lot of CPU power). If every hospital in the United States adopted this technology, it would prove nearly impossible to crack.

Blockchain technology allows the development of a vast interoperable network, ensuring valuable real-time patient data can be exchanged rapidly and efficiently between healthcare providers, patients, and authorized third parties, such as insurance companies. The technology can reduce operational costs, maximize the accuracy of [electronic health records](https://www.medesk.net/en/blog/how-to-organise-electronic-health-records/), and promote strong data security practices.

### Remote Patient Monitoring (RPM)

The global Remote Patient Monitoring (RPM) market leverages innovative new technology, allowing patients, in particular the elderly and those with chronic conditions, to effectively monitor their health and improve access to high-quality care and patient outcome. RPM is already commonly used to monitor patients’ blood pressure, pulse rate, oxygen level, and heart rates.

RPM adoption has expanded significantly, with many healthcare systems integrating it into standard chronic care management programs and post-discharge workflows.

The data is used for early detection of illness or health issues or to track ongoing ailments. Despite the clear benefits of RPM, there are several risks associated, including the threat of a data breach, potential device malfunction, and application vulnerabilities to ransomware, malware, and viruses.

HIPAA-compliant hosting for RPM will mitigate these risks, as patients may understandably have privacy concerns about how sensitive RPM data is collected, processed, and deleted by e-Health Applications.

### Wearable Tech

What makes Remote Patient Monitoring work is the use of wearable tech. Hospitals can provide patients with wearable medical devices, and the data from those devices can either be downloaded after the treatment cycle or uploaded directly over the cloud. Wearable tech is everywhere; smartwatches, smart glasses, and smartphones work seamlessly with applications such as Strava, Run Keeper, and others.

Wearable devices have become more clinically relevant, with FDA-cleared devices and tighter integration into provider systems improving reliability and usability.

One group of medical researchers benefiting from wearable tech are those who study of diabetes. The future of diabetes self-management is set to be revolutionized by continuous glucose monitoring (CGM) technology, which provides real-time feedback to inform and guide healthy food choices and lifestyle changes.

Continuous glucose monitoring is now widely adopted, with real-time data syncing directly into mobile apps and provider dashboards for proactive care.

[Dexcom](https://www.dexcom.com/home) aimed to launch a next-gen CGM system in late 2020 and is partnering with Apple to allow diabetics to access their glucose tracking data on an Apple Smartwatch. Meanwhile, Fitbit has teamed up with San Francisco-based tech company Sano to develop a wearable, coin-size patch using tiny needles to track glucose levels. These technologies will enable patients to gain a greater understanding of how their body responds to food and exercise and allow them to adapt their lifestyle choices based on better information.

To conclude, e-Health applications and the associated technology are only going to thrive in the future. The Covid-19 pandemic has proven that this technology is reliable and gets the job done. Any e-Health application must be running on a HIPAA-compliant hosting platform, as data integrity and the protection of patient health information are essential to the success of the apps.

It is debatable whether blockchain or future technologies that employ it will ever become HIPAA-compliant. Regardless, e-Health applications will continue to thrive, as they have proven that they can become everyday parts of our healthcare system and processes, such as digital prescriptions. Other applications that are already the norm include Internet forums and health-related social platforms, Internet-based literature related to healthcare, web apps directly used by patients, patient-generated health data (PGHD), Internet messages between patient and clinician, and of course, electronic health record portals.

## Ready to Get Started with e-Health Applications?

Atlantic.Net stands ready to help you attain fast compliance with a range of certifications, such as [SOC 2](https://www.atlantic.net/hipaa-compliant-hosting/importance-of-soc-type-2-hipaa-and-gdpr-compliance-in-website-accessibility/) and SOC 3, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/what-is-a-hipaa-certification/), and HITECH, all with 24x7x365 support, monitoring, and world-class data center infrastructure. For faster application deployment, free IT architecture design, and assessment, visit us at [www.atlantic.net,](about:blank) call 866-618-DATA (3282), or email us at [sales@atlantic.net](mailto:sales@atlantic.net).

Learn more about our [HIPAA compliant web hosting](https://www.atlantic.net/hipaa-compliant-hosting/) and [HIPAA cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/) solutions.


---

# From HIPAA Hosting RFQ to Live Django Deployment

> URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-hosting-rfq-django-architecture/ | Published: 2026-04-28 | Author: Richard Bailey

The engineering and professional services team here at Atlantic.Net responds to customer requests for quotes almost every day. A HIPAA hosting RFQ often arrives as a checklist stating the client’s requirements and expectations. Today, we are focusing on a recent request from a customer who wanted to onboard into our award-winning HIPAA-Compliant Hosting Services.

The RFQ was clear; the customer wanted a Django application on its own VM, a separate database VM, a signed HIPAA Business Associate Agreement (BAA), a managed firewall with intrusion prevention, encrypted backups in more than one location, multi-factor authentication, vulnerability scanning, and VPN access

To our clients, every detail matters. But the checklist is not the architecture.

The real work was turning a sensible HIPAA hosting wishlist into a secure, provisionable environment. The RFQ arrived on a Monday, the quote was signed the following week, and shortly after, Atlantic.Net began provisioning a two-VM Django deployment behind a managed FortiGate firewall in Dallas, with encrypted offsite backups stored in Ashburn, Virginia.

The result was a clean, public-facing application tier, a private database tier, a managed security perimeter, and the compliance controls needed before ePHI entered the stack.

## The HIPAA Hosting Wishlist

The customer was building a Django application that would handle electronic Protected Health Information, payment activity, and webhook traffic from external systems. They had already ruled out a single-server deployment. That was the correct decision and a great sign that everyone was working on the same page.

A HIPAA workload that combines a public web application with a database containing ePHI should not start with everything on one VM unless there is a strong reason to do so.

The customer’s RFQ included:

- An application VM with roughly 6 vCPU, 16GB of RAM, and 200GB of SSD storage
- A database VM with roughly 4vCPU, 16GB of RAM, scalable storage, and private-network access
- A signed HIPAA BAA before ePHI was introduced
- A managed FortiGate firewall or equivalent
- Private networking between the two VMs
- VPN connectivity for external integrations
- Encrypted backups stored onsite and offsite
- Multi-factor authentication for administrative access
- Vulnerability scanning and patching
- Dallas is the preferred primary region

Every line item was reasonable. The job of our proposal was to demonstrate what each item meant in practice: what was included, what needed to be quoted, and what would be a one-time charge.

## The Architecture: Two VMs Behind a Managed Firewall

Atlantic.Net proposed a two-VM HIPAA-compliant environment behind a FortiGate firewall-as-a-service. The first VM would run the Django application, and the second VM would run the database. Both would sit on a private network behind the firewall, a critical matter of separation.

The application VM is the part of the stack that needs controlled exposure to the internet. It receives web traffic, terminates TLS connections, runs the Django application, handles API requests, and accepts webhook requests. The database VM does not need to be exposed to the public internet. It’s only required network neighbors are the application VM and the approved management path via a customer VPN connection.

In the proposed environment, traffic from the internet first reaches the FortiGate firewall. The firewall inspects traffic and forwards only approved ports to the application VM. The database VM remains unreachable from the public internet. This is the practical difference between having the right list of security requirements and having an architecture that supports them.

## The Application VM

The proposed application VM included 6 vCPU, 16 GB of RAM, and 200 GB of SSD storage. The sizing made it a comfortable starting point for an early production Django workload. It allows the application VM to run the reverse proxy, the Django application process, internal API services, webhook endpoints, and background workers without requiring additional infrastructure on day one.

A typical configuration would include Caddy or Nginx terminating TLS, with Django running behind Gunicorn or uWSGI. Background jobs could run through a queue, such as Celery or Redis Queue (RQ), on the same VM at this stage.

Splitting background workers or the reverse proxy onto separate VMs may make sense later, and is absolutely an option going forward for the customer. But right now, it was not required for the initial deployment.

## The Database VM

The proposed database VM included 4 vCPU, 16 GB of RAM, and scalable block storage. For a Django deployment, PostgreSQL or MySQL would both be suitable. Atlantic.Net’s HIPAA-compliant hosting environment supports both database engines, so the final choice can align with the application team’s preference and existing development stack.

The important architectural point is that storage can scale independently of the VM size. That is critical for databases because storage growth and CPU pressure change over time. A database will typically need more disk storage long before it needs a larger compute profile.

By placing the database on its own VM, the customer gained a cleaner security model, a simpler auditing model, and more flexible scaling. It was a great balance that met the customers’ expectations from day one.

## The Security and Compliance Layer

The BAA is signed before any ePHI enters the environment. For Atlantic.Net HIPAA-compliant hosting, the BAA is included as part of the tier and is signed prior to going live. It is not treated as a separate upsell and is embedded in the service we offer our healthcare customers.

At the edge of the environment, the FortiGate Firewall as a Service provides the managed perimeter. Intrusion prevention is enabled on the firewall, and traffic is restricted only to the application ports that need to be exposed.

The managed hosting package also includes bi-weekly vulnerability scanning and patching. Trend Micro Deep Security provides anti-malware and host-level intrusion detection on the VMs. Detailed access and administrative action logging runs on the firewall and VMs, providing the customer with audit traceability when required.

For administrative access, the proposal included five Duo MFA licenses. That covered the customer’s expected administrative users with some room to grow. Additional licenses can be quoted as needed.

## VPN Connectivity

The RFQ requested VPN connectivity for external systems but did not specify whether the customer needed a site-to-site VPN, a client VPN, or both. The FortiGate firewall supports both models.

Client-based VPN gives individual administrators secure access into the environment. Site-to-site VPN connects the Atlantic.Net environment to an office, partner network, or external system. Atlantic.Net’s HIPAA hosting includes five VPN tunnels at no additional charge, so the customer did not need a separate tier to support the initial VPN requirement.

In this case, the customer later confirmed they needed a site-to-site VPN between the FortiGate firewall and an on-premise SonicWall. That is a common pairing, and the FortiGate can establish an IPsec tunnel with a standards-compliant peer such as SonicWall, with Atlantic.Net’s network team coordinating setup during provisioning.

## Encrypted Backups in Two Locations

Daily encrypted backups were included for both VMs. Backups are encrypted at rest and stored in two locations. The local backup copy remains in the Dallas data center alongside the production environment. The off-site copy is stored in Atlantic.Net’s Ashburn, Virginia, facility.

Having a regional split is intentional; Dallas and Ashburn are separate fault domains. They operate in different physical locations, on different infrastructure, and under separate facility controls. That is what an off-site backup copy is supposed to provide.

For an early production environment, thirty-day retention is often sufficient, but we work with our customers to create an RTO that meets their needs. Customers with stricter internal policies, contractual requirements, or tighter recovery objectives can extend the design with longer retention, more frequent snapshots, streaming replication, or application-level replication.

Those enhancements are quoted as add-ons when required. They do not need to be built into the first deployment unless the recovery requirements demand them.

## Region Choice: Dallas Primary, Ashburn Offsite

The customer preferred Dallas as the primary region, and Atlantic.Net operates a HIPAA-audited data center in Dallas that directly meets the requirement. Dallas became the production region. Ashburn became the off-site backup region.

For a customer with business operations and partners concentrated in the central United States, Dallas also made sense from a latency perspective. The application runs close to the expected user and partner base. The Ashburn copy is there for recovery, not for every production transaction. Having this distinction is important because the off-site backup location improves resilience without adding latency to normal application traffic.

## Three Confirmations Before Provisioning

After accepting the proposed two-VM environment, the customer returned with three final questions. Each one was common, practical, and important enough to answer clearly before provisioning began.

### Can the reverse proxy and Django run on the same VM?

Yes.

At the proposed VM size, running Caddy or Nginx on the same VM as Django is a normal starting pattern. The reverse proxy terminates TLS and forwards traffic to Gunicorn or uWSGI. The Django application then handles application logic, APIs, and webhook endpoints.

Splitting the reverse proxy onto another VM is possible later, but it was not required for launch.

### Can the FortiGate connect to an on-premise SonicWall?

Yes.

The FortiGate firewall can support an IPsec site-to-site VPN with a SonicWall or another standards-compliant peer. The setup falls within the five included VPN tunnels. Atlantic.Net’s network team configures the FortiGate side during provisioning and coordinates with the customer’s SonicWall administrator to ensure a matching configuration.

### Can the environment host multiple domains and subdomains?

Yes.

There are no infrastructure-level restrictions preventing the application VM from serving multiple domains, subdomains, or virtual hosts. TLS certificates can be issued through Let’s Encrypt using DNS or HTTP validation, or the customer can provide certificates if they prefer to manage them centrally.

None of these confirmations required a change to the quote. They were configuration decisions, not architecture changes.

## What Was Included, What Was Quoted, and What Was One-Time

The proposal separated costs into three clear categories. The monthly recurring price covered the application VM, the database VM, the signed BAA, FortiGate Firewall as a Service, intrusion prevention, bi-weekly vulnerability scanning, managed patching, encrypted daily on-site and off-site backups with 30-day retention, 5 Duo MFA licenses, and 5 VPN tunnels.

The one-time charge was limited to a single item: a $150 onboarding fee for the FortiGate firewall. There were no other setup or onboarding fees.

Items quoted case by case included future scaling and post-launch add-ons. That could mean moving the application VM from 6 to 8 vCPU, increasing memory on the database VM, expanding storage, adding VPN tunnels beyond the included 5, adding Duo MFA licenses, extending backup retention, or introducing replication to achieve a tighter recovery point objective.

## Why the Two-VM Split Was the Right Starting Point

A single-server Django deployment is technically possible. For a HIPAA workload, it is usually not the best starting point. Keeping the application and database on separate VMs gives the customer three immediate advantages.

1. The database does not receive public internet traffic.
2. The application cannot consume the same CPU and memory resources that the database depends on.
3. Each tier can scale independently as usage grows.

The cost difference between a single-server deployment and a two-VM deployment at this size is modest. The compliance and operational benefits are much larger. That is why the proposal did not shrink the environment into one machine, even though the initial workload might have fit there. The two-VM design gave the customer a cleaner security boundary from the beginning.

## From Signed Quote to Live Environment

Once the quote and BAA were complete, the deployment moved through a predictable sequence. Atlantic.Net provisioned the FortiGate firewall, built the VMs on the private network, applied the managed security controls, scheduled encrypted backups, enabled Duo MFA, prepared VPN connectivity, and coordinated the site-to-site tunnel with the customer’s network team.

From there, the customer’s application team could deploy Django onto the prepared environment. Having a division of responsibility is important for managed HIPAA hosting. Atlantic.Net handles the underlying infrastructure, perimeter security, backup framework, access controls, and managed services. The customer focuses on the application.

For teams building a Django, Rails, Node, or PHP application that will handle ePHI, the hard part is rarely naming the controls. Most RFQs already include the right words: BAA, firewall, MFA, VPN, backups, scanning, patching, and private networking. The harder part is turning those words into an environment that can be provisioned, managed, audited, restored, and scaled.

For this customer, that meant a Dallas-based two-VM Django deployment behind a managed FortiGate firewall, with a private database tier, encrypted onsite and offsite backups, Duo MFA, vulnerability scanning, VPN connectivity, and a signed BAA in place before ePHI entered the environment.

That is the difference between a HIPAA hosting checklist and a live production architecture.


---

# Best Cloud Consultancy or MSP in 2026

> URL: https://www.atlantic.net/vps-hosting/best-cloud-consultancy-or-msp/ | Published: 2026-04-28 | Author: Dr. Rachael Bailey

In today’s business environment, organizations rely on Managed Service Providers (MSPs) to handle critical IT operations, from cloud infrastructure to cybersecurity and ongoing support.

But not all MSPs deliver the same value. Choosing the right partner requires understanding your business needs, technical requirements, and long-term scalability goals.

To help you evaluate your options in 2026, we’ve curated a list of leading Cloud Consultancy firms and MSPs that continue to support organizations with cloud adoption, security, and modernization initiatives.

## What Is a Cloud Consultancy?

Cloud consultancies, which offer consultancy assistance and services, benefit customers in many ways, including providing insights into cloud adoption strategies, planning processes, and managing the organization’s [migration to the cloud](https://www.atlantic.net/hipaa-data-centers/common-mistakes-made-during-cloud-migration/).

They support architecture design, migration planning, cost optimization, governance, and multi-cloud strategy—ensuring businesses align cloud investments with measurable outcomes.

## What Is an MSP?

Managed cloud service providers (MSPs) help employees adopt, assess, and practice cloud security best practices. Modern MSPs now extend beyond infrastructure support to include cloud security, compliance management, DevOps enablement, and continuous optimization of cloud workloads.

MSPs help organizations move away from traditional IT models and adopt a cloud-first strategy. They offer various services, from infrastructure support and migration to application development and management. In addition, an MSP can provide guidance and mentorship to businesses during their implementation.

As cloud adoption accelerates, MSPs are increasingly expected to provide automation, AI-driven monitoring, and proactive incident management rather than reactive support models.

Cloud consultancies are in high demand as companies move away from traditional IT models and adopt a cloud-first strategy. Industry projections continue to show strong growth in cloud spending through 2026, driven by AI workloads, data platforms, and hybrid infrastructure adoption.

## Top 10 Cloud Consultancy or MSPs in 2026

## 1. All Covered

The industry-leading All Covered, part of Konica Minolta and founded in 1997, heads up our list. Winner of the “Best Cloud Consultancy or MSP” in the International Cloud Computing Awards program, The Cloud Awards, All Covered delivers tailored and scalable managed IT solutions to businesses of all sizes.

All Covered offers many services, including application development, cloud services, IT helpdesk, and security. The company boasts over 35 locations worldwide, including the United States, Latin America, Mexico, and the Caribbean. With All Covered, you will receive a customized service plan and benefit from 24/7 support via phone, live chat, and a handy client portal.

## 2. Accenture

Founded in 1989, Accenture is a prominent and flexible MSP that provides solutions tailored to specific businesses, spanning across the globe with a reach that extends across industries. Accenture serves over 9,000 clients across 120 countries worldwide and delivers managed services that aim to fast-track growth and efficiency.

Accenture continues to invest heavily in cloud, AI, and industry-specific platforms, helping enterprises modernize legacy systems and build data-driven operations.

Accenture’s expertise helps them to secure their clients’ operations and achieve business resilience. The company provides a broad range of services, including consulting, digital marketing, operations solutions, business process outsourcing, and cloud services. Accenture serves many high-profile clients, including Unilever, Marriott, BMW Group, and Vodafone.

## 3. ANS Group

ANS Group is a UK-based cloud services provider offering comprehensive digital transformation solutions and is an ideal option for small to mid-size companies. ANS is passionate about delivering enterprise-grade technology, expertise, and processes to businesses of all sizes at an affordable price. As a result, ANS clients can limit the cost of new hardware, scale workloads, only pay for necessary resources, and gain access to leading Azure and AWS engineers. ANS continues to focus on Microsoft Azure and AWS ecosystems, supporting businesses with cloud-native development and managed services aligned to modern application requirements.

## 4. Burwood Group

Burwood Group is a leading IT consulting and managed services firm based in Chicago and benefitting from over 29 years of experience. The company has 5 US-based offices, which include 24/7 operations centers in San Diego, CA, and Normal, IL, and employs 250 staff. Clients can benefit from strategic consulting services and 24×7 IT infrastructure monitoring and event management for on-premises, hybrid, and cloud environments.

Burwood Group has expanded its capabilities in hybrid cloud and security operations, helping organizations manage increasingly distributed IT environments. Burwood Group allows small businesses to outsource their infrastructure, disaster recovery, and cybersecurity processes successfully.

## 5. CyberDuo

Founded in 2008 and based in Los Angeles, CyberDuo is an award-winning MSP that provides managed IT, cloud, and cybersecurity services. CyberDuo primarily supports small and mid-size businesses and prioritizes cybersecurity. Access to 24/7 top-level tech support ensures that clients are delighted with the service that they receive. CyberDuo places a strong emphasis on zero-trust security frameworks and ransomware protection, reflecting current threat landscapes.

CyberDuo provides businesses with security, endpoint protection, vulnerability scanning, firewall services, and more. Their remarkable time-to-resolution is excellent, and they prefer to avoid downtime where possible.

## 6. NexusTek

Over two decades, NexusTek has been trusted by thousands of small to mid-size businesses. It offers an extensive list of services, including IT consulting, end-user services, cloud, infrastructure, and cybersecurity. NexusTek continues to focus on integrated IT solutions that combine cloud management with cybersecurity and compliance oversight.

NexusTek can help you review your overall technology roadmap to find solutions that optimize everything in your IT operations. It is an SSAE 18 SOC II certified company and undergoes stringent annual security audits.

Unlike many of its competitors, NexusTek offers transparent fixed-monthly, per-user pricing.

## 7. Dataprise

Founded in 1995 and headquartered in Maryland, Dataprise also has offices in Virginia, Tennessee, California, New York, New Jersey, Florida, Texas, Pennsylvania, and Washington, D.C. Dataprise has expanded its managed detection and response (MDR) and cloud security services to address rising cyber threats. With its many branch offices, Dataprise provides fully-managed IT services and solutions, end-user services, cybersecurity, and disaster recovery.

Dataprise is recommended for small businesses looking for managed IT services to conserve cash while letting them still have the level of support in-house IT staff would offer.

## 8. Electric

Established in 2016, Electric, also known as Electric.ai, supports over 50,000 users and is based in New York. Electric continues to position itself as a modern MSP with automation-driven IT support and centralized device management for distributed teams.

Electric provides clients with IT-managed services, cybersecurity, HR services, strategic IT consulting services, and application management and support. A cost-effective solution, Electric claims to cut its clients IT spending by an average of 50%. In addition, Electric’s solutions are quick, scalable, and easy to understand and use.

## 9. Infosys

Infosys has over 40 years of experience within the consultancy and managed services industry. With headquarters in Bangalore, India, Infosys has a global presence in over 50 countries. Infosys is increasingly focused on AI-led cloud transformation and enterprise automation across industries. Infosys provides a broad spectrum of services and solutions but specializes in using data analytics and an AI-powered core to improve IT infrastructure. Infosys clients benefit from a conventional and transparent pricing model.

## 10. ScienceSoft

ScienceSoft was established in 1989 and provides high-quality managed IT services, IT consulting, data analytics, cybersecurity, and software development. ScienceSoft continues to support regulated industries with cloud solutions that prioritize compliance, performance, and operational stability. This leading MSP solution serves over 30 industries, including non-IT enterprises, with a strong focus on healthcare and financial services.

## How Can Atlantic.Net Help?

When partnering with an MSP, you must consider your options carefully and choose one that will meet the specific needs of your business. In 2026, the right MSP should not only manage infrastructure but also support security, compliance, performance optimization, and long-term cloud strategy. Selecting the right MSP will lead to a strong partnership that will benefit your company for years.

With so many excellent Cloud Consultancy and MSPs on the market, choosing the best one for your company can take time and effort. Look no further than Alantic.Net! With over three decades of experience, Atlantic.Net is a trusted web hosting company supplying reliable and dependable services to its SMB to enterprise clients.

Atlantic.Net supports businesses with customizable cloud and hosting solutions designed to meet modern workload demands, including high availability and compliance-driven environments. We can assist by creating customized solutions that fit your business’s needs with an array of hosting services, including [cloud](https://www.atlantic.net/vps-hosting/), dedicated, colocation, private virtualization, and managed hosting.

Our state-of-the-art infrastructure is SSAE 18, HIPAA, and HITECH compliant and housed in secure, climate-controlled facilities with constant monitoring and multiple direct connections to the Internet backbone to ensure the availability and safety of your data.

---

#### Read More About Consulting Services

- [IT Consulting Services](https://www.atlantic.net/managed-services/consulting/)
- [Healthcare IT Consulting Services](https://www.atlantic.net/hipaa-compliant-hosting/top-13-difficult-questions-your-hipaa-consultant-should-be-asking-you/)

---


---

# Top 11 Systems Integration Software in 2026

> URL: https://www.atlantic.net/vps-hosting/best-systems-integration-software/ | Published: 2026-04-28 | Updated: 2026-06-23 | Author: Richard Bailey

To stay competitive in a rapidly changing economy, businesses must quickly adopt and integrate new technologies with their existing systems. This process is known as systems integration.

## Why Is Systems Integration Important?

Systems integration is complicated to achieve, especially when integrating legacy or mainframe systems into new environments. Not all applications are cloud-enabled, especially specialist in-house software. Systems integration software can help businesses to integrate their various systems effectively and efficiently. It allows companies to connect different systems, share data, and automate data transfer between other applications.

Systems integration software now plays a central role in modern IT architecture, especially with the rise of [SaaS platforms](https://www.atlantic.net/vps-hosting/top-8-best-usa-based-software-as-a-service-solutions-for-smbs/), APIs, and distributed cloud environments. As a result, it will become even more crucial for companies to have adequate systems integration software to stay competitive.

This article highlights the top systems integration software in 2026 and explains how each platform supports automation, scalability, and data-driven operations.

## 1. Geniusee

Geniusee is a systems integration software house based in Kyiv, Ukraine. They specialize in helping businesses manage their data more effectively by providing users with a centralized platform to collect data from multiple sources to enhance business operations.

Geniusee provides many features to simplify data management, such as importing data from various sources, including databases, [API integration](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-api-explained/), text files, and emails. With an approach that improves [business intelligence](https://www.atlantic.net/vps-hosting/best-cloud-business-intelligence-or-analytics-solution-in-2023/), boosts data accessibility, and data integrity, Geniusee increases productivity and enhances performance. In addition, the integration enables authorization through social networks, online payments, better reports, and the ability to integrate with other software to create more streamlined and efficient workflows.

## 2. deltAlyz Corp

DeltAlyz Corp writes integration software that offers solutions for enterprise application integration, third-party system integration, business-to-business (B2B), and legacy integration. The application features include data cleansing, integration, reporting, and analytics.

DeltAlyz Corp provides API development services that use HTTP webhooks, SOAP, REST, or GraphQL. The API acts as an intermediary between two or more software endpoints and helps businesses manage their data more effectively and improve their operations.

The company’s software is available in various formats and can be used to integrate multiple systems. deltAlyz Corp’s design solutions provide users with a wide range of reporting and analytics tools.

## 3. N-iX

N-iX is a systems integration software creator that helps organizations connect and automate their business processes across multiple industries, including manufacturing, logistics, fintech, and retail. N-iX creates bespoke software for your specific needs, making them unique in their approach to customized solutions.

They are experts in digital acceleration, technology modernization, R&D, and technology advisory and have a solid track record for creating software capable of automating business processes.

## 4. iTechArt Group

iTechArt Group is a custom software development company that provides solutions for everyone from dedicated software engineers to venture-capital-funded startups. With a focus on software development, project management, and systems integration, iTechArt Group offers a comprehensive suite of tools to help organizations achieve their goals.

## 5. Cyclr

The Cyclr Group provides a variety of solutions for managing complex IT systems. Cyclr provides a scalable connectivity framework and easy low-code tools to design and build integrations. In addition, they feature over 400 custom APIs to let you create any UI/UX you like, and they provide a simple method to deliver integration directly inside your SaaS application.

Cyclr is widely used in 2026 for embedded integrations within [SaaS](https://www.atlantic.net/vps-hosting/what-is-saas-hosting/) products, helping software vendors offer native integrations without building everything from scratch. Cyclr solutions are designed to help users manage and monitor complex systems, including those involving the cloud. CyclrConnect allows users to connect systems and share data quickly and easily. Cyclr also provides users with real-time insights into system performance.

## 6. Zapier

Zapier is a systems integration software allowing users to connect different apps. This can be helpful for tasks like sending a reminder to a colleague in a separate app or ordering a product from a different store. Zapier continues to be a leading no-code [automation](https://www.atlantic.net/vps-hosting/best-cloud-automation-solution/) platform in 2026, supporting thousands of integrations for business workflows.

Zapier integrates with many popular tools, like Dropbox, Google Drive, Gmail, Slack, Mailchimp, and any webhook app. It’s easy to use and navigate, and if you’re looking for a way to connect different apps, Zapier is a great option.

## 7. Hevo

Hevo is a data-driven integration platform that creates an end-to-end data pipeline. In modern business, data is stored in countless locations across the company. Hevo is a comprehensive, user-friendly system that streamlines the integration of new systems into existing data infrastructure.

Hevo is commonly used for real-time data replication and ELT pipelines, making it suitable for analytics teams working with cloud data warehouses. In addition, it offers advanced searching and filtering capabilities that make locating the information you need easy as well as a wide range of reports and statistics that help you track system performance and make informed decisions.

## 8. Rivery

Rivery is a comprehensive low-code and no-code platform that helps organizations integrate different data systems and create automated business processes using informed decision-making. Some of the critical features of Rivery include its ability to manage workflow with over 200 connectors to popular data sources like Google, LinkedIn, TikTok, SAP, Oracle, and Twitter.

Rivery focuses on data orchestration and modern ELT workflows, helping teams centralize data pipelines across cloud environments. Rivery enables data ingestion, creates integrations, and automates business processes using data orchestration.

## 9. Workato

Workato helps businesses manage their projects efficiently by creating a single platform for integration and workflow automation across your business. It has various features that make it ideal for managing projects, including a project management tool, a resource management system, and a collaboration tool.

Workato is widely adopted by enterprise teams for automation across departments, including HR, finance, and IT operations. Some standout integrations are Salesforce, Slack, ServiceNow, Snowflake, Box, and Active Directory.

## 10. OmniConnect (NXTsoft)

OmniConnects integrations quickly and seamlessly deploy to create purposefully built unified commerce integrations that increase automation and transactional performance between your business central, ERP or CRM. Onmiconnect tends to focus on clients in the FinTech or financial services industries.

The OmniConnect software integration enables seamless experiences for opening new bank accounts and transferring money to and from different providers. In addition, it is a security-defined service that allows other finance apps to integrate.

## 11. CloverDX

CloverDX is a system integration software that helps companies manage complex integrations and connectivity between different systems. It offers various features to make this process easier, such as a robust connector library, a user-friendly interface, and the ability to connect to just about any data source or output. This approach helps eliminate data silos, avoid vendor lock-in, and create a connection native to your business.

CloverDX is often used for data-heavy integration scenarios, including batch processing and enterprise data transformation workflows. CloverDX features the Connector library, a tool that easily connects to various systems, including ERP, CRM, and supply-chain management systems, helping achieve flexible integration to a wide range of integration options, making it suitable for diverse businesses.

## Partner With a Leading Cloud Provider

You must partner with a leading [VPS hosting](https://www.atlantic.net/vps-hosting/) provider if you choose to leverage the power of cloud-based systems integration software and tools. Atlantic.Net brings 30 years of experience, offering top-level services at cost-effective prices. In addition, we will work closely with your business to provide a [cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) solution tailored to your specific needs.

Modern integration workloads in 2026 often require high-performance cloud environments capable of handling APIs, [containers](https://www.atlantic.net/cloud-platform/cloud-containers/), and real-time data pipelines. The Atlantic.Net [cloud platform](https://www.atlantic.net/cloud-platform/) is the perfect solution for all your systems integration needs. The high-performance infrastructure can run large-scale integration tools and containerized application stacks, and our Cloud Storage availability will host large-scale application images to use in your environment without skipping a beat; great when ingesting large volumes of data, but great for general usage too.

[Contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) to find out how Atlantic.Net can help you on your mission to streamline the process of systems integration using cloud-based software.


---

# The Best Cloud Data Management Solution in 2026

> URL: https://www.atlantic.net/vps-hosting/the-best-cloud-data-management-solution/ | Published: 2026-04-28 | Updated: 2026-04-29 | Author: Richard Bailey

Cloud data management is the process of organizing, controlling, securing, and optimizing data stored in cloud environments to ensure accessibility, compliance, and performance across modern workloads, including AI and analytics.

Today, cloud data management goes beyond storage and backup—it plays a critical role in enabling AI pipelines, real-time analytics, and scalable application architectures. Choosing the right cloud data management solution depends on your use case, such as AI workloads, compliance requirements, or enterprise-scale data operations.

Many different cloud data management solutions are available on the market, and deciding which is right for your business can be challenging.  Cloud data management services enable geographical dispersion, allow greater efficiency in company operations and initiatives, and empower businesses to reach new levels of technological innovation.

This article reviews leading cloud data management solutions and explains how to evaluate them based on performance, scalability, security, and AI readiness.

## Nextcloud

Nextcloud is an enterprise cloud storage solution with multiple add-ons that create a unique ecosystem for business operations. In addition, it is open-source and has comprehensive support options.

Nextcloud is functionally similar to Dropbox, Office 365, or Google Drive when used with its integrated office suites Collabora Online or OnlyOffice. It can be hosted in the cloud or on-premises and is highly scalable, from basic home-based office solutions to complete data center solutions that support millions of users.

Nextcloud is a module application, which means that countless plugins are available to customize it to your requirements. Popular plugins include browser-based editors, cloud service integrations, web analytics, and featured media viewers. Nextcloud is particularly useful for organizations that require full data control, privacy, and flexible deployment across hybrid environments.

Did you know that Nextcloud is available on the [Atlantic.Net Cloud](https://cloud.atlantic.net/?page=userlogin)? You can spin up a Nextcloud instance using our 1-click applications. It will be ready to use in about 30 seconds! [Click here for more information](https://www.atlantic.net/press-releases/atlantic-net-announces-nextcloud-one-click-app-public-cloud/).

## Internxt

[Internxt](https://internxt.com/) is an open-source cloud storage provider designed for individuals and teams to store and manage their data with Internxt Drive and its other encrypted suite of secure services. Internxt is an alternative to Google Drive and will never store, share or sell the personal data of its users. 

With Internxt, you can manage your important documents or projects with your colleagues thanks to Internxt’s advanced sharing feature, making it easier to manage who can access or edit your files. 

Internxt is available across all platforms, making it easy for anyone to access and manage their cloud storage anytime from any device. As an additional feature, Internxt also allows secure, encrypted data delivery on the cloud with password-protected links, making managing your data in this cloud service efficient, private, and secure.

Internxt stands out for its privacy-first architecture, making it a strong option for users prioritizing encrypted and zero-knowledge storage.

## Tableau

With Tableau, you can quickly and easily find actionable insights from any data source. Users can simply drag and drop from almost any source to create custom formulas and visualize and slice/dice data. In addition, Tableau business services offer training services, insights, and strategies, and the unparalleled community of Tableau experts is available and keen to offer help, making your data work for you.

With role-based licensing, Tableau enables users of all skill levels to interact with data in the same intuitive and accessible way. With augmented analytics insights, Tableau helps anyone needing data to uncover insights faster—data scientists, business users, and data engineers.

Tableau is best suited for organizations that need advanced data visualization and business intelligence layered on top of cloud data systems. Its augmented analytics capabilities also support faster insights, which are increasingly important for AI-assisted decision-making.

## Wasabi HotCloud

Wasabi is a cloud-based object storage service developed for individuals and organizations that need a substitute for cloud storage and requires a high-performance, reliable, and secure data storage infrastructure.

HotCloud allows you to protect and manage data at any stage automatically. This tool uses automated techniques to protect data and respond in real time when it detects a potential error. It is suitable for any external and internal cloud setup because it uses a REST API such as those at Alibaba, Amazon, Google, Microsoft, and Atlantic.Net. Wasabi is particularly effective for high-volume storage use cases such as backups, media storage, and archival data.

HotCloud helps guarantee security by discovering, removing, and preventing errors with the cloud object analyzer. In addition, it connects tracking information to help you and your team keep up with the status of your data, regardless of the number of records or objects in the cloud data set.

## Snowflake

Created in 2012, Snowflake is a fully managed SaaS tool that centralizes data warehousing, data lakes, data engineering, data science, and data application development on any of the leading public and private clouds.

The tool works equally well on a single server in the cloud as in a deployment spanning hundreds of servers and hundreds of terabytes of data. Snowflake’s unique selling point comes from its layered architecture. At the base is the Database Storage layer, where Snowflake stores data loaded into the platform.

Snowflake is widely used for AI and analytics workloads due to its ability to process structured and semi-structured data at scale. Its separation of compute and storage enables efficient scaling for data-intensive applications.

The Compute layer is made up of multiple node clusters. At each data warehouse, any data loaded does not compete for the same resources. In addition, Snowflake uses a common language, SQL, to interact with the Snowflake technical architecture.

## Hortonworks Data Platform

Hortonworks HDP is the only open-source project on our list. This is an alternative to Apache Hadoop focused on Apache Spark and Apache Pheonix. Hortonworkds is now owned by Cloudera, focusing on a massively scalable cluster computing engine that processes large data flow at scale.

The open-source community created an industry with HDP, enabling the world’s largest enterprises to transform their organizations and entire sectors using data streaming. HDP includes the open-source toolset, and the project aims to use data science to advance relevant programs, devices, and systems.

## IBM Netezza

IBM Netezza is one of the most commonly known options for Business Intelligence, operational analytics, and cloud data management solutions. It uses data warehousing, ETL processing, analytical services, and Netezza’s newest feature, Query Optimizer, which solves the problem of “dimensional growth” in your data. Netezza is particularly valuable for enterprises that require high-performance analytics with simplified data warehousing operations.

Netezza also has a proprietary SQL language called DynaSQL. DynaSQL supports views, triggers, partitioning, asynchronous processing, global variables, stored procedures, native concurrency support, triggers, and Oracle Synchronization, among other features.

## About Atlantic.Net

As healthcare technology continues to rapidly evolve, researchers believe that cloud services will continue to be leveraged by companies to access new and innovative data management technologies.

Atlantic.Net is a global [VPS hosting](https://www.atlantic.net/vps-hosting/) provider with over 30 years of experience, specializing in Windows, Linux, and managed server hosting solutions. Atlantic.Net provides business-class dedicated and cloud hosting solutions focusing on security, compliance, and simplifying the user experience.

Additionally, Atlantic.Net offers fully managed environments, security, and compliance-focused solutions across all its hosting facilities in San Francisco, New York, London, Toronto, Dallas, and Orlando. With a range of certifications and SSAE 16 (SOC 2 and SOC3), HIPAA and HITECH audited data center infrastructure. The company is also known for its reliability, as dictated by its 100 percent uptime service-level agreement (SLA). For more information, please visit[www.atlantic.net.](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/)


---

# Top 10 “Best in Mobile” Cloud Solutions in 2026

> URL: https://www.atlantic.net/vps-hosting/top-10-best-in-mobile-cloud-solutions-in-2023/ | Published: 2026-04-28 | Updated: 2026-04-29 | Author: Dr. Rachael Bailey

Mobile cloud platforms in 2026 are no longer limited to hosting applications—they power real-time data processing, AI-driven features, and global scalability. Businesses have been moving to the cloud for years, and this shift continues to accelerate as enterprises migrate more of their operations online. In this increasingly mobile-first environment, organizations need solutions that are not only cloud-native but also optimized for mobile performance, ensuring seamless access and functionality across devices.

The best mobile cloud platforms now combine backend services (authentication, APIs, storage) with serverless architecture, real-time synchronization, edge computing, and AI/LLM integrations. These capabilities enable advanced features like chatbots, automation, and personalized user experiences at scale. For businesses looking to stay competitive, choosing a “best in mobile” cloud solution means prioritizing performance, flexibility, and AI readiness to support modern, intelligent applications.

## What Is a Mobile Cloud Solution?

A Mobile Cloud Solution is a comprehensive system that allows businesses to securely access their data and applications from any mobile device anywhere in the world. It provides users with the flexibility to work on the go without sacrificing security or performance.

A modern mobile cloud solution now goes beyond basic access—it powers real-time data processing, AI-driven features, and globally distributed app performance. A mobile cloud solution allows businesses to run their apps and processes in the cloud, which delivers many benefits, including scalability, flexibility, and efficiency.

## Top 10 “Best in Mobile” Cloud Solutions

The global mobile cloud market is thriving and is predicted to reach $202.4 billion by 2028. Do you need help deciding on the best mobile cloud solution for your business? This article will look at 10 of the best mobile cloud solutions in 2026. We will discuss what makes each provider unique and how they can help your business to thrive in the digital age.

## 1. Back4App

Back4App is an MBaaS (Mobile Backend as a Service) offering that aims to streamline and accelerate backend development. Using Back4App, developers can readily conduct expedient, safe, cost-effective, and scalable development of mobile applications. Back4App now supports modern app requirements such as API-first development, scalable backend logic, and integration with AI-powered services.

Key features of Back4App include real-time data management, database storage, scalability, and cross-platform software development kits. Back4App is a trusted name within this space and a developer’s favorite, as it is elastic, scalable, global, and reliable. Users can opt to use the free plan with limited functionality or commit to one of their paid plans for enhanced features.

### **What stands out:**

- Easy backend setup
- Scalable infrastructure
- Developer-friendly tools

## 2. Firebase

Trusted by development teams around the world, Firebase is another popular BaaS solution.

Developed in 2011 and acquired by Google in 2014, Firebase is easily integrated on the Web, Android, and iOS. Firebase remains a top choice in 2026 due to its real-time database, serverless architecture, and built-in support for AI-driven features like predictions and analytics.

With a pay-as-you-go price structure, you only pay for the resources you use. Also, Firebase does offer some limited features and products for free. Core features of this BaaS offering include a highly secure end-to-end identity solution, ready-to-use machine learning APIs, real-time database solutions, and multiple release and monitoring products.

### **What stands out:**

- Real-time sync
- Strong developer ecosystem
- Fast deployment

## 3. Domo

Founded in 2010, Domo Server is a fully cloud-based operating system that unites every part of your business on your phone. It is a comprehensive and easy-to-use platform trusted by some leading companies, including Unilever, ESPN, NBA, and Cisco. Domo has evolved into a data-first mobile cloud platform, emphasizing real-time analytics and AI-powered decision-making.

Focused on end-user self-service, the Domo Appstore provides users access to hundreds of business-oriented apps. Domo also incorporates advanced analytics, including a smart alert center, data science and machine learning, embedded analytics, and predictive analytics.

### **What stands out:**

- Mobile-first analytics
- AI-powered insights
- Business intelligence focus

## 4. Backendless

Another popular MBaaS offering, Backendless, was developed by Mark Piller in 2012. It is an easy-to-use, intuitive visual app development platform requiring no code. APIs required for the development of your application are all generated automatically by the software.

Backendless is compatible with popular client-side mobile and web development languages, including Swift, Objective-C, Java, JavaScript, .NET, and Flutter. Notable features include SQL and NoSQL databases, top-level file security and user authentication, geolocation, and messaging security.

Startups and small businesses can opt for a specific price plan, while medium and large enterprises will benefit from custom functions and should request an individual quote.

### **What stands out:**

- No-code/low-code approach
- Built-in backend services
- Fast prototyping

## 5. IBM Cloud

Coming in at number 5 on our list of the top “best in mobile” cloud solutions for 2023 is IBM Cloud. IBM Cloud can help you to develop, host, and run your mobile applications within the cloud. This platform enables users to integrate it with various external software applications by providing an API. With IBM Cloud, you can deploy mobile apps faster and enhance the existing features of your apps using the AI capability of IBM Watson. Its strength lies in AI integration, particularly through Watson services, making it suitable for intelligent mobile apps.

### **What stands out:**

- Strong AI capabilities
- Enterprise-grade security
- Hybrid cloud flexibility

## 6. DigitalOcean

DigitalOcean is a popular cloud platform widely used to host web or mobile applications. The company boasts 14 globally distributed data centers and supports over 600,000 customers worldwide. DigitalOcean remains a strong choice in 2026 for startups and developers building lightweight mobile backends and API-driven applications, with growing support for AI workloads via simplified infrastructure and integrations.

This flexible and scalable developer-friendly platform is ideal for startups and small businesses looking to grow. Some of the notable features of DigitalOcean are SSD-based block storage, an intuitive and easy-to-use control panel, automatically-generated back-ups, and ‘DigitalOcean Droplets’ or Linux-based virtual machines.

A flat pricing structure and monthly price caps mean that Digital Ocean users benefit from affordable and predictable pricing.

### **What stands out:**

- Simple and developer-friendly interface
- Predictable and transparent pricing
- Strong ecosystem for startups and API-based apps

## 7. Vultr

Founded in 2014, Vultr has 27 secure data centers strategically located around the globe. It is a popular cloud platform with over 1.5 million customers served and over 45 million instances deployed. Clients benefit from DDoS protection, 100% SSDs, a seamless custom control panel, and dedicated IP addresses. Vultr is well-suited in 2026 for developers needing high-performance compute with flexible deployment options, including support for GPU instances for AI and machine learning workloads.

Vultr avoids long-term contracts, offering standard hourly billing for their products and services.

### **What stands out:**

- Flexible hourly billing model
- Wide range of compute options including GPU
- Global data center availability

## 8. Heroku

Owned by Salesforce, Heroku is a cloud service provider that helps businesses quickly build, deploy, and scale dynamic and efficient apps. It can be used by developers, teams, and businesses of all sizes. Heroku continues to be a strong platform in 2026 for rapid application development, especially for teams prioritizing speed, simplicity, and continuous deployment workflows. Many prominent companies, including Facebook, Unsplash, and Toyota, use Heroku. This PaaS offering supports many popular programming languages, including Ruby, Java, Python, Node.js, and Scala.

The Heroku platform is feature-rich, with core features including app metrics for monitoring response time, throughput, and CPU usage, compliance with PCI, HIPAA, ISO, and SOC, and 24/7 access to the operations and security team.

### **What stands out:**

- Fast deployment and minimal setup
- Strong developer experience
- Easy integration with third-party AI services

## 9. Kinvey

Kinvey is an MBaaS platform that helps mainstream businesses to deliver their cross-platform applications more efficiently. As a platform, Kinvey provides solutions to a variety of developer problems. It has many pre-built components that make setting up a productive working environment accessible. Along with those tools, Kinvey lets developers focus on what is core to their product and what positively impacts the user’s experience. In 2026, Kinvey is positioned as a backend platform that simplifies complex app development while supporting API-driven architectures and scalable mobile experiences.

Core features of Kinvey include a serverless backend, code sharing, streamlined user authentication, complete integration, and a drag-and-drop builder. In addition, Kinvey offers affordable annual plans with the option to scale up as needed.

### **What stands out:**

- Pre-built backend services
- Strong enterprise integration capabilities
- Faster development with reduced backend complexity

## 10. Linode

Since 2003, developers have trusted the Linode platform to build and support their mobile applications. Linode (now part of Akamai) has evolved to support modern workloads, including edge computing and performance-focused application delivery.

The platform is known for its durability, dependability, speed, and wide network of connectivity. With an award-winning support team, a transparent flat pricing structure, and the ability to scale efficiently, Linode is an excellent choice for businesses of all sizes worldwide.

### **What stands out:**

- Reliable and performance-focused infrastructure
- Transparent and predictable pricing
- Growing focus on edge and distributed delivery

## How Can Atlantic.Net Help?

Atlantic.Net is a cloud services provider with over 30 years of experience providing award-winning and highly durable infrastructure services for global businesses. We have dedicated and virtual private servers that can offload your web application’s backend. In addition, our security-defined platform provides premium-grade components on an SSD-based storage architecture.

Atlantic.Net is SOC 2, and SOC 3 certified, HIPAA and HITECH audited via qualified and independent third-party auditors. In addition, we provide 24x7x365 support, monitoring, and world-class data center infrastructure. You can find out more information by[contacting our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)!


---

# Top 9 Best Software as a Service Solutions Based Outside the USA in 2026

> URL: https://www.atlantic.net/vps-hosting/top-9-best-software-as-a-service-solutions-based-outside-the-usa-in-2023/ | Published: 2026-04-28 | Updated: 2026-04-29 | Author: Dr. Rachael Bailey

The software as a Service (SaaS) industry is booming and shows no signs of slowing down. By 2032, Precedence Research predicts that the [SaaS market will reach $1 trillion](https://www.precedenceresearch.com/software-as-a-service-market). Are you looking for the best software as a service? There are countless available cloud-based SaaS solutions available to your business.

The United States leads the way in SaaS technology businesses and startups, and all major enterprise-scale SaaS solutions are American companies. However, what else is out there? Europe, Asia, and the rest of the world have some outstanding tech companies making waves in the industry.

So who are the best SaaS companies outside of the USA in 2026? This guide now focuses on non-US SaaS providers with strong data privacy, regional hosting, and compliance advantages (e.g., GDPR)—with clearer comparisons, use-case-based picks, and structured insights designed for faster evaluation and AI-driven search visibility.

## 1. Seedata.io (London, United Kingdom) – Best for cloud data security and third-party risk visibility

Seedata.io is a software-as-a-service company that offers a wide range of cybersecurity products and services designed to protect cloud workloads. Their products include a cloud-based platform for managing projects, a marketplace for selling software applications, and a suite of cybersecurity developer tools.

Seedata.io is headquartered in London, England, and has a team of over 80 employees. Their products have been praised for their ease of use and ability to streamline development. Some advantages of using Seedata.io include that their products are cloud exclusive and have a customer base comprising some of the world’s largest companies.

Seedata is a platform that integrates with existing cloud services and can detect data leakage, provide control assurances over your data, and send notifications to alerts if 3rd Parties mishandle sensitive data. Seedata.io fits teams that need continuous monitoring of sensitive data across cloud apps and vendors, especially where third-party access is a risk.

### **Who should choose Seedata.io?**

Security teams managing multi-cloud environments or working with multiple external vendors handling sensitive data.

## 2. BCN3D (Barcelona, Spain) – Best for 3D printing workflow and production management

BCN3D is a product development SaaS startup that helps users plan, build and ship their products. It provides a centralized platform connecting the different product lifecycle parts. In addition, you can manage your contracts and access third-party design, manufacturing, or outsourcing tools.

BCN3D specializes in robotics and 3D printing at scale, but also provides two SaaS platforms that manage the entire ecosystem, BCN3D Cloud and BCN3D Stratos. Their SaaS tools manage digital libraries and print queues, categorizing 3D printing resources and taking automated actions based on usage or alerts. BCN3D is best suited for teams running distributed or high-volume 3D printing operations that need centralized control and automation.

### **Who should choose BCN3D?**

Engineering teams, manufacturers, or labs managing multiple printers and needing better production coordination.

## 3. Campaign Monitor (Sydney, Australia) – Best for email marketing automation with global reach

Campaign Monitor is a leading software-as-a-service (SaaS) provider that ensures effective digital marketing campaigns. With a strong focus on Australia and supporting local languages, Campaign Monitor offers a variety of products and services to help businesses of all sizes achieve their marketing objectives.

Some key benefits of using Campaign Monitor include easy-to-use tools and templates, comprehensive reporting, and a wide range of integrations with other popular software. As a result, businesses can save time and money while still achieving high levels of success with their marketing campaigns. Campaign Monitor remains a strong option for businesses that want simple, reliable email marketing without heavy complexity, especially for global or region-specific campaigns.

### **Who should choose Campaign Monitor?**

Small to mid-sized teams that need straightforward email marketing tools without a steep learning curve.

## 4. Aditus (Porto, Portugal) – Best for website accessibility compliance and inclusive marketing

Aditus provides a SaaS platform that helps businesses to manage their websites and ad campaigns but does it with customer accessibility at the forefront of the design decision. There are more than one billion people with disabilities worldwide, and Aditus was created to provide simple yet detailed accessibility testing for the disabled audience.

It helps you to perform advanced campaigns, accurate advertisement targeting, and website optimization. Aditus is also helpful for all types of traders by allowing you to manage all your campaigns in a single platform. Besides, it offers bid management, ad creation, audience management, campaign management, and data segmentation. Aditus is best suited for businesses that need to improve website accessibility while running targeted digital campaigns, especially where compliance and inclusive user experience matter.

### **Who should choose Aditus?**

Businesses prioritizing inclusive design, accessibility compliance, and broader audience reach through optimized campaigns.

## 5. Payvoice (Vancouver, Canada) – Best for embedded payments and invoicing on custom websites

Payvoice is a platform that allows you to accept payments from your clients using your own website and the global stripe payment system. It is popular with eCommerce and online store owners that need quotes and invoice service, pricing pages, and detailed information about sales conversions.

Alternatively, with Payvoice, you can even accept payments from your clients through mobile apps and websites, and Payvoice is quickly becoming a viable alternative to the market leader, PayPal. Payvoice works well for businesses that want flexible payment collection integrated directly into their websites or apps, without relying entirely on third-party checkout platforms.

### **Who should choose Payvoice?**

eCommerce stores, freelancers, and SaaS businesses that need embedded payments with more control over the user experience.

## 6. FreshBooks (Canada) – Best for small business accounting and invoicing

FreshBooks is one of the Top 10 SaaS Companies in the world. This Canadian company offers a cloud-based accounting system that works in real-time so that you can access your data anytime and anywhere. It has over 10 million customers worldwide, with over 60,000 companies and over 400,000 US businesses using its cloud accounting solution.

FreshBooks is a subscription-based SaaS platform that features invoicing, accounts payable, expense tracking, time tracking, retainers, fixed asset depreciation, purchase orders, payroll integrations, mileage tracking, double-entry accounting, and many more. FreshBooks is ideal for small businesses and service-based professionals that need simple accounting, invoicing, and expense tracking in one place.

### **Who should choose FreshBooks?**

Freelancers, agencies, and small businesses looking for easy-to-manage accounting without enterprise complexity.

## 7. Mable (Melbourne, Australia) – Best for connecting independent caregivers with clients

Mable is an online software-as-a-service company based in Melbourne, Australia. They offer a wide range of products, including a CRM and email marketing platform, as well as a range of business tools that allow users to search for caregivers, book appointments, and take payments.

Mable targets users who need domestic help, nursing, social support, personal care, travel assistance, independent living, therapy support, and work support. Support workers can create their profiles on the platform to get appointments. Mable operates as a service marketplace platform focused on care and support services, enabling direct connections between clients and independent caregivers.

### **Who should choose Mable?**

Individuals and families seeking flexible care options, as well as independent support workers looking to connect with clients directly.

## 8. Authlete (Tokyo, Japan) – Best for API-based authentication and OAuth/OpenID infrastructure

Authlete is a highly respected software-as-a-service provider based in Japan. They offer a wide range of products, including a cloud-based platform for managing and collaborating on projects and a suite of tools for managing and tracking customer data. Their flagship product is a middleware that controls SSO sign-on to any application that supports OAuth authorization servers and OpenID Connect identity providers.

Any application you run can integrate with your company directory service and remain compliant with MFA authentication. This is useful because only some people use Azure AD, on-premise Active Directory, or LDAP. The advantages of using Authlete’s products include the company’s experience and expertise in the SaaS market, its global reach, and its commitment to customer service and support. Authlete is best suited for teams that need fine-grained control over authentication flows, especially when building custom identity systems using OAuth 2.0 and OpenID Connect.

### **Who should choose Authlete?**

Developers and enterprises building custom identity layers, APIs, or platforms requiring flexible authentication infrastructure.

## 9. Babbel (Berlin, Germany) – Best for structured language learning for individuals and teams

Babbel is a software-as-a-service company that provides language learning tools to students, businesses, and professionals. It was founded in Berlin, Germany, in 2007 and has since expanded to offer various products, including a translation service, a transcription service, and a learning platform.

Babbel’s language learning tools are some of the best in the market, and its translation service is particularly valued. The transcription service is also popular, citing its accuracy and speed as advantages. Babbel’s learning platform is also well-regarded, with users citing its ease of use and comprehensive features as advantages. Best of all, Babbel offers a subscription plan that makes it highly affordable. Babbel is a strong option for practical, structured language learning, with a focus on real-world conversations and guided lessons.

### **Who should choose Babbel?**

Individuals or teams looking for a guided, easy-to-follow language learning platform without needing advanced customization.

## How Can Atlantic.Net Help?

Implementing an effective SaaS platform will help your business streamline its efficiency, boosting productivity and sales and improving customer service. Once you have chosen a leading cloud [SaaS solution](https://www.atlantic.net/vps-hosting/what-is-saas-hosting/), you should consider partnering with an industry-leading web hosting provider, such as Atlantic.Net.

As a leading [cloud computing](https://www.atlantic.net/vps-hosting/) provider, Atlantic.Net is uniquely capable of meeting your company’s or organization’s needs. We have more than 30 years of experience in the industry and are driven to provide a customized solution to meet your requirements. [Contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) for more information on the solutions we offer!


---

# Most Popular Penetration Testing Tools In 2026

> URL: https://www.atlantic.net/vps-hosting/most-popular-penetration-testing-tools-in-2021/ | Published: 2026-04-28 | Updated: 2026-04-29 | Author: Dr. Rachael Bailey

## **What Is Penetration Testing?**

Penetration testing, commonly known as pen testing, uses an ethical hacking attack to test the security of an organization’s systems, applications, and networks. This allows organizations to identify and rectify any weaknesses within their infrastructure before they are subjected to a genuine cyberattack.

In 2026, penetration testing increasingly includes:

- AI-assisted vulnerability discovery
- Automated attack simulation
- Cloud and container security testing

No single tool covers everything. Most teams use a combination of tools to test different layers of their infrastructure.

Technological advances mean that we now have a plethora of automated penetration testing tools at our fingertips. Modern pen-testing tools allow us to simulate fast and effective cyber-attacks at the touch of a button. It is important to remember that you are unlikely to find a single testing tool to meet all of your organization’s needs; instead, you may need to deploy several tools to fully test your network.

## **How to Choose Penetration Testing Tools?**

In the current age of heightened security threats, organizations must deploy penetration testing tools to identify vulnerabilities in their infrastructure. While penetration testing can be outsourced to third parties, this can be costly, so many organizations are seeking effective penetration testing tools to use independently.

When evaluating tools in 2026, prioritize automation, integration with CI/CD pipelines, real-time reporting, and support for cloud-native and containerized environments. So, how do you choose the best penetration testing tools for your company with this in mind? Below is a curated list of widely used and actively maintained penetration testing tools relevant for modern security teams.

## Top 11 Penetration Testing Tools in 2026

### 1. Netsparker – Best for Automated Web Security

Netsparker provides a web application security scanner, suitable for small to large businesses, and is built to be user-friendly, ensuring that you don’t need extensive security experience to use it. This highly effective and scalable automated scanner detects vulnerabilities, including Cross-site scripting and SQL injection in web applications and web services.  It also boasts dedicated compliance reporting for HIPAA, PCI DSS, and ISO 27001.

Modern deployments also benefit from improved automation workflows and integration with DevSecOps pipelines, helping teams remediate vulnerabilities faster. Netsparker has been successfully deployed within the government, healthcare, finance, education, and IT sectors, and users can opt for either a managed service or self-hosted solution.

#### What stands out:

- Detects XSS and SQL injection
- Scalable for large environments
- Compliance reporting

### 2. Acunetix – Best for Fast Web Scanning

Acunetix is a specialized web security testing tool designed to detect and report on over 7000 vulnerabilities including XSS, SQL injection, weak passwords, and exposed databases. With its high detection rate, ease of use, and fast scanning speed, Acunetix stands ahead of many of its competitors. It includes a built-in vulnerability management system and an API, allowing integration with other popular 3rd party applications. Recent updates emphasize automation, scheduled scanning, and integration with issue tracking tools for faster remediation workflows.

#### What stands out:

- High detection rate
- Fast scans
- API integrations

### 3. Burp Suite – Best for Web Application Testing

Over 14,000 organizations globally from all industries trust PortSwigger’s Burp Suite to detect web vulnerabilities. As one of the more cost-effective pen-testing tools available on the market, Burp Suite offers an excellent option for those less experienced in the ins and outs of cybersecurity.

Users can choose between the Enterprise or Professional Edition of the tool based on their individual needs. Burp Suite is supported across multiple platforms, including Windows, Linux, and Mac OS X. Burp Suite remains a core tool in modern web security testing, especially with its extensions marketplace and active community support.

#### What stands out:

- Intercepting proxy
- Extensions marketplace
- Strong community

### 4. Metasploit – Best for Exploitation

Metasploit is a popular open-source penetration testing framework backed by 200,000 users and contributors and used by security personnel and ethical hackers alike. Currently, Metasploit provides access to over 2074 disclosed exploits and over 592 payloads covering multiple operating systems and applications, but this number is forever changing. Its active community and frequent module updates make it a reliable framework for testing modern vulnerabilities, including cloud and IoT attack vectors. As the open-source community is the backbone of Metasploit, users can use code developed by other hackers to identify vulnerabilities.

#### What stands out:

- Large exploit library
- Modular framework
- Active community

### 5. Security Onion – Best for Threat Hunting

Security Onion is a popular open-source Linux distribution based on Ubuntu and is available for free. Its name was coined to represent the analytical tools that it offers as defensive layers, offering an effective alternative to enterprise-level solutions. Security Onion is widely used for threat hunting, network monitoring, and intrusion detection in modern SOC environments. Security Onion provides users with network-based and host-based intrusion detection systems, full packet capture, and visualization and analysis tools through a user-friendly interface.

#### What stands out:

- Full packet capture
- SOC-focused tools
- Visualization features

### 6. OWASP – Best for Open Standards

The Open Web Application Security Project® (OWASP) is a global non-profit foundation dedicated to enhancing software security. Several pen-testing tools are available under the umbrella of OWASP, including Zed Attack Proxy (ZAP), OWASP Dependency Check, and OWASP Web Testing Environment Project.

OWASP resources, including the Top 10 vulnerabilities list, continue to guide security testing priorities for developers and enterprises in 2026. OWASP provides a comprehensive web security testing guide, highlighting best practices for the testing of web applications and web services.

#### What stands out:

- Industry-standard guidelines
- Free tools
- Strong community adoption

### 7. Kali Linux – Best All-in-One Toolkit

Kali Linux is a powerful open-source penetration testing and security auditing operating system, only available through Linux. This OS comprises many tools and is popular with professional pen testers, offering a multitude of in-built tools to identify vulnerabilities. Kali Linux remains a standard toolkit for penetration testers, with frequent updates and expanded support for cloud and wireless testing scenarios. Some notable features of Kali Linux include full customization of Kali ISOs, Live USB boot, full disk encryption, and Kali Everywhere, which increases the accessibility of Kali by allowing it to be run across other Unix systems.

#### What stands out:

- Pre-installed tools
- Customizable environment
- Widely used by professionals

### 8. Nessus – Best for Vulnerability Scanning

Nessus, developed by Tenable Network Security, is a comprehensive vulnerability assessment tool designed with security practitioners in mind. Boasting 2 million downloads worldwide and a user base of over 30,000 organizations, Nessus is one of the most widely deployed security tools. It continues to provide regularly updated plugins and vulnerability intelligence aligned with emerging threats. This is probably best suited for professionals with vast experience in the security sector, given that others may struggle to master the interface. Nessus offers users up-to-date vulnerability coverage, with new plugins added daily and the industry’s lowest false positive rate.

#### What stands out:

- Frequent plugin updates
- Large vulnerability database
- Reliable scanning

### 9. Fiddler – Best for API Debugging

Fiddler provides a distinct package of tools designed to test the security of your web applications. Using this tool, pen testers can capture and decrypt HTTP(S) web traffic, providing the ability to quickly identify, diagnose, and correct any network issues. Fiddler is commonly used for debugging APIs, testing web sessions, and analyzing encrypted traffic in modern web applications. It is available for free and can be used across any platform, browser, or system. There is also a paid subscription model available that provides access to extended features.

#### What stands out:

- API debugging
- Traffic inspection
- Cross-platform support

### 10. W3af – Best for Open-Source Web Testing

Fully written in Python, W3af is an open-source Web Application and Audit Framework. As W3af is available for free, it is an ideal option for organizations with a lower budget, lacking the ability to access enterprise-class testing tools. It remains relevant for identifying common web vulnerabilities and is often used alongside other tools for broader coverage. This framework can be used to identify more than 200 vulnerabilities including cross-site scripting, SQL injection, guessable credentials, and PHP misconfigurations. W3af is very well documented and easy to use, providing both a graphical and console user interface.

#### What stands out:

- Python-based
- Free and open-source
- GUI and CLI support

### 11. Aircrack-ng – Best for Wireless Security

Aircrack-ng provides a comprehensive suite of tools for analyzing the security of wireless networks. This network toolkit includes a packet sniffer, an encryption key cracker, a detector, and a decryption tool for captured files. Aircrack-ng is still widely used for wireless security auditing, particularly in testing WPA/WPA2 network configurations. Although primarily designed for Linux, Aircrack-ng does work across multiple platforms, including Windows, OS X, and Solaris. As the tools within the suite use a command-line interface, this allows users the flexibility to manipulate commands and target-specific parameters.

#### What stands out:

- Packet capture
- Password cracking
- Wireless auditing

## Other Penetration-Related Tools

As well as pen testing, there are several effective security and analysis tools available, including:

### WireShark

WireShark is a free, open-source tool that is widely used by non-profit and commercial businesses, network experts, security professionals, and educational institutions and can be run across multiple platforms. It remains one of the most trusted tools for real-time packet analysis and troubleshooting network issues. A popular network protocol analyzer, WireShark allows users to examine the traffic running across their network in real-time, enabling quick identification of any vulnerabilities. Wireshark offers pen tester key features, including rich VoIP analysis, live-capture and offline analysis, industry-leading powerful display filters, and comprehensive analysis of hundreds of protocols.

### John the Ripper

John the Ripper is a free, open-source password cracking and recovery tool, originally released in 1996 for UNIX-based operating systems. It can now be used across multiple operating systems, making it a valuable tool for those keen to check password vulnerability. It continues to be used for password auditing, especially when testing password strength and policy enforcement. As it is available for free, many organizations opt to use John the Ripper alongside other penetration testing tools to provide a more comprehensive assessment of vulnerability across entire infrastructures.

## How Can Atlantic.Net Help?

An industry-leading cloud hosting services provider, Atlantic.Net brings over 30 years of experience, hosting the infrastructure of top organizations. We support modern security practices including regular penetration testing, vulnerability management, and compliance-driven infrastructure design. We regularly conduct penetration testing across our estate and perform security and vulnerability lifecycle management frequently. All personnel is trained to high-security standards, and Atlantic.Net is audited, boasting PCI compliance, and holds HIPAA compliance accreditations. We can help you to achieve a fully secure and protected environment.

[Contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) to find out more about how Atlantic.Net can benefit your organization.


---

# Top 11 Cloud-Based Software Testing Tools in 2026

> URL: https://www.atlantic.net/vps-hosting/top-11-cloud-based-software-testing-tools-in-2021/ | Published: 2026-04-28 | Updated: 2026-06-23 | Author: Dr. Rachael Bailey

The best cloud-based software testing tools in 2026 combine automation, AI-assisted test creation, and scalable infrastructure to support modern development workflows. Teams now prioritize tools that reduce manual effort, integrate with CI/CD pipelines, and support UI, API, and performance testing in one platform. Cloud testing platforms also increasingly include AI features such as self-healing tests and automated test generation, making them more efficient than traditional tools.

## What Is Cloud-Based Software Testing?

Just as it sounds, cloud-based software testing leverages cloud resources to test web, cloud, or locally installed software and applications, as opposed to using an on-premises testing environment. Cloud-based software testing provides businesses with an easy, on-demand means of testing an application’s reliability, scalability, and performance. The Cloud provides major advantages for testing mobile applications as multiple SDKs can be run from a single location.

**Key benefits:**

- No hardware maintenance
- Faster execution at scale
- Easy collaboration across teams
- Integration with CI/CD pipelines

## Top Cloud-Based Software Testing Tools (2026)

As cloud-based testing gains traction, there is no shortage of good software testing tools on the market. To help you to make the best choice for your business, we have compiled a list of our top 11 cloud-based testing tools.

### CloudTest (Akamai) – Best for large-scale performance testing

CloudTest from Akamai is one of the most popular cloud-based testing tools currently available on the market. Launched in 2008, CloudTest provides users with a robust load and performance testing platform to test both mobile and web applications. Providing real-time performance analytics, reporting, and seamless integration, this favored tool supports the complete development cycle allowing experts to test in both a pre-and post-production environment.

Akamai offers new users access to CloudTest Lite, a free, open-source version of the tool which offers limited features.

#### **What stands out:**

- Real-time performance monitoring with detailed analytics dashboards
- Scalable cloud infrastructure for high-traffic simulation
- Supports testing across pre-production and live environments

#### **Who should choose CloudTest?**

Enterprises and high-traffic applications that require advanced performance and load testing at scale.

### BlazeMeter -Best for scalable open-source performance testing

BlazeMeter is an open-source, on-demand performance and load testing platform. This tool simplifies the process of testing and analysis, delivering real-time reporting and comprehensive analytics. With BlazeMeter you can run highly scalable performance tests in a matter of minutes,

BlazeMeter supports some of the popular open-source apps, including JMeter, Selenium, Gatling, and WireMock. It extends open-source testing frameworks into a fully managed cloud environment, making it easier to scale tests without managing infrastructure.

#### **What stands out:**

- Native support for popular open-source tools like JMeter, Selenium, and Gatling
- Scalable cloud execution for high-load and distributed testing
- Real-time reporting with actionable performance insights

#### **Who should choose BlazeMeter?**

Teams leveraging open-source testing tools that need [cloud scalability](https://www.atlantic.net/hipaa-data-centers/cloud-scalability-for-a-limitless-app-launch/) and faster execution without infrastructure overhead.

### Apache JMeter – Best for open-source load and performance testing

JMeter is an open-source, Java-based application designed to test the functionality and performance of web applications. It is primarily used as a load testing tool for web applications but has been improved to incorporate many different features, including stress testing and stability testing. JMeter is great for testing cloud servers to ensure that the cloud plan you choose can handle the predicted load of your website. It is highly extensible and supports distributed testing, making it suitable for simulating traffic at scale without licensing costs.

#### **What stands out:**

- Completely open-source with strong community support
- Supports load, stress, and API testing across multiple protocols
- Can be extended with plugins and integrated into CI/CD pipelines

#### **Who should choose Apache JMeter?**

Engineering teams that need a flexible, cost-effective performance testing tool with full control over test configuration.

### LoadStorm – Best for simple, cloud-based load testing

A cloud-based load testing tool used to determine the scalability of web and mobile applications, LoadStorm from CustomerCentrix is cost-effective and user-friendly. Users can take advantage of a free trial of LoadStorm, after which they will get the option of a subscription-based plan or a one-time purchase. This testing tool streamlines the process of scripting, provides in-depth, real-time analytics, and offers test script reviews. It is designed for simulating user traffic in the cloud, helping teams validate application performance before scaling or deploying updates.

#### **What stands out:**

- User-friendly interface with simplified test creation
- Cloud-based load generation without infrastructure setup
- Real-time analytics for performance monitoring

#### **Who should choose LoadStorm?**

Small to mid-sized teams looking for an easy-to-use load testing tool without the complexity of enterprise platforms.

### Locust – Best for developer-driven load testing with Python

Locust is another popular open-source load testing tool that uses Python code. The tool is easy to use and allows distributed and scalable testing across multiple platforms. The key benefit of Locust is that it allows testers to write their testing scripts in pure Python, eliminating the need for complex UIs or XML. By using an event-based framework, Locust becomes highly scalable and demands fewer resources than alternative testing tools. Its Python-first approach makes it a strong fit for engineering teams that prefer scripting over GUI-based tools and want full control over test logic.

#### **What stands out:**

- Pure Python scripting for flexible and readable test scenarios
- Event-driven architecture for efficient, scalable load generation
- Supports distributed testing across multiple machines or cloud instances

#### **Who should choose Locust?**

Developers and engineering teams who prefer code-based testing and need a lightweight, scalable load testing solution.

### Cypress – Best for modern frontend and end-to-end testing

Cypress provides its users with a complete end-to-end testing framework written in JavaScript. A whole host of high-profile organizations use this tool to offer quick and effective testing of web applications. Built on an entirely new, non-Selenium-based architecture, Cypress runs directly in the web browser with native access to everything. A useful and distinguishing feature of this tool is the automatic waiting function which ensures that Cypress waits for your commands. It is designed for developer experience, offering real-time reloading, built-in debugging, and tight integration with modern development workflows.

#### **What stands out:**

- Automatic waiting reduces the need for manual timeouts
- Real-time reloads and interactive debugging
- Strong support for modern JavaScript frameworks

#### **Who should choose Cypress?**

Frontend teams and JavaScript developers who need fast, reliable end-to-end testing with minimal setup.

### Artillery – Best for lightweight load and API testing with Node.js

Another tool trusted by leading commercial enterprises, Artillery is a powerful load testing and smoke testing tool built using Node.js. This is an open-source and cost-effective tool that can be used to apply a load to any backend system and check that the system is functioning correctly. Artillery is available as either a free version with limited functionalities or as a subscription-based pro version with access to a self-service testing platform for large-scale tests. It focuses on simplicity and developer-first workflows, allowing teams to define tests using YAML or JavaScript.

#### **What stands out:**

- Lightweight setup with YAML or JavaScript-based scripting
- Strong support for API and microservices testing
- Easy integration with CI/CD pipelines

#### **Who should choose Artillery?**

Teams building Node.js or API-driven applications that need fast, scriptable load testing.

### Visual Studio App Center Test – Best for mobile app testing on real devices

Previously Xamarin Test Cloud, this tool is now available as an add-on for Visual Studio, offering cloud-based testing for native and hybrid mobile apps. There is a free trial available, and users can benefit from a competitive and flexible pricing structure. App Center Test runs tests over physical devices hosted within their infrastructure, providing an excellent simulation of a users’ environment. A useful feature of this tool is the ability to capture screenshots for each testing step and to store these, alongside device logs and test results, for up to six months. It is designed to help developers identify device-specific issues and ensure consistent performance across different operating systems and screen sizes.

#### **What stands out:**

- Access to a large pool of real devices for accurate testing
- Detailed logs, screenshots, and test reports
- Integration with Visual Studio and CI/CD pipelines

#### **Who should choose Visual Studio App Center Test?**

Mobile development teams that need reliable testing across real devices without maintaining physical hardware.

### Nessus – Best for vulnerability scanning and security testing

Nessus, from Tenable Inc., is the gold standard for [vulnerability](https://www.atlantic.net/vps-hosting/top-10-vulnerability-scanners/) scanning, currently trusted by over 30,000 organizations globally. Built for security practitioners, Nessus can detect vulnerabilities in network devices and cloud infrastructure. Easy and intuitive, this vulnerability scanner offers pre-built policies and templates, customizable reporting, and real-time plug-in updates. Nessus is widely used within the healthcare and banking industries and is a favorite of Security Professionals. It helps organizations proactively detect misconfigurations, outdated software, and potential attack vectors before they can be exploited.

#### **What stands out:**

- Extensive vulnerability database with frequent updates
- Pre-built templates for quick security assessments
- Detailed reporting for compliance and risk management

#### **Who should choose Nessus?**

Security teams and organizations that need continuous vulnerability scanning as part of their testing and compliance workflows.

### AppPerfect – Best for legacy web and application testing

AppPerfect, founded in 2003, is a cloud-based testing tool that provides robust testing and monitoring of web and Windows applications. This platform can provide cloud security testing, cloud load testing, and cloud-hosted testing. Some of the notable features of this tool include test script design and recording, comprehensive reporting, [encryption](https://www.atlantic.net/hipaa-compliant-hosting/encryption-for-hipaa-compliance/), and security compliance. Two versions of this tool are available – the Starter Pack or the Annual Tech Support Pack. It is primarily used in environments where older systems and traditional testing workflows are still in place.

#### **What stands out:**

- Supports multiple testing types including load, security, and functional testing
- Built-in scripting and test recording features
- Suitable for legacy application environments

#### **Who should choose AppPerfect?**

Organizations maintaining legacy systems that require stable, traditional testing tools.

### CloudBees (Jenkins Dev@Cloud) – Best for CI/CD-driven testing and automation

The industry-leading tool CloudBees delivers an automated end-to-end software delivery platform. CloudBees provides users with the ability to build and test android and iOS applications at scale. As part of the Continuous Integration, Continuous Delivery (CICD) platform, there is a large selection of testing tools that can be implemented during the software development process. This approach allows Developers and Infrastructure teams to work together on the entire software stack.

#### **What stands out:**

- Deep integration with Jenkins and CI/CD pipelines
- Supports automated testing across multiple environments
- Scales testing as part of the software delivery lifecycle

#### **Who should choose CloudBees?**

DevOps teams that need to integrate testing into automated CI/CD workflows at scale.

## Partner With a Leading Cloud Provider

If you choose to leverage the power of cloud-based testing tools, you must partner with a leading [VPS hosting](https://www.atlantic.net/vps-hosting/) provider. Atlantic.Net brings 30 years of experience, offering top-level services at cost-effective prices. We will work closely with your business to offer a [cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) solution that is tailored to meet your specific needs.

The Atlantic.Net [cloud platform](https://www.atlantic.net/cloud-platform/) is the perfect solution for all of your testing needs. The high-performance infrastructure can run large-scale CICD and containerized application stacks, and our Cloud Storage availability will host large-scale application images to use in your testing without skipping a beat, great if you need to test mobile SDK, but great for general usage too.

[Contact our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted) to find out how Atlantic.Net can help you on your mission to streamline the process of software testing using a cloud-based testing tool.

*This article was updated on April 28, 2026.*


---

# Top Cloud Hosting Solutions for Developers in 2026

> URL: https://www.atlantic.net/vps-hosting/top-cloud-hosting-solutions-for-developers/ | Published: 2026-04-28 | Updated: 2026-06-23 | Author: Dr. Tehseen Zia

Modern software development demands infrastructure that is agile, scalable, and capable of handling global traffic. Traditional hosting solutions often struggle to meet these requirements.

[Cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) gives developers on-demand infrastructure, flexible scaling, and global availability without managing physical servers. The right provider depends on your use case—some prioritize simplicity and cost control, while others focus on advanced services like AI/ML, Kubernetes, or enterprise-grade networking.

For developers, cloud hosting is typically evaluated on:

- How quickly you can deploy and scale applications
- Support for modern stacks (containers, APIs, serverless)
- Pricing flexibility as usage grows
- Availability across regions for low-latency delivery
- Level of control ([managed vs unmanaged](https://www.atlantic.net/vps-hosting/managed-vps-vs-unmanaged-vps/) environments)

In this guide, we break down the top cloud hosting solutions for developers based on real-world use cases—so you can choose the platform that fits your workflow, budget, and scaling needs.

## What Developers Need from Cloud Hosting

A strong cloud hosting platform should support every step of the development process. Here are the key features to consider when making a choice.

### Automatic Scalability

Developers need hosting that can automatically scale up during busy periods and scale down when things are quiet. This means both adding power to current servers and spinning up new servers as needed. Platforms that can adjust resources on the fly help keep apps running smoothly, even with heavy traffic or large teams. Look for real-time autoscaling, horizontal scaling (multiple instances), and support for container orchestration like Kubernetes for production-grade workloads.

### Seamless Tool Integration

Modern development relies on continuous integration and delivery pipelines. An effective platform provides easy integration with DevOps tools such as [Jenkins](https://www.jenkins.io/), [GitLab](https://about.gitlab.com/) [CI/CD](https://www.redhat.com/en/topics/devops/what-is-ci-cd), and [Azure DevOps](https://azure.microsoft.com/en-us/products/devops). This integration allows developers to build, test, and deploy from a single environment. Browser-based access to development environments, such as [Visual Studio Code](https://code.visualstudio.com/), eliminates the “works on my machine” problem. Prioritize platforms that support Git-based workflows, API-first automation, and native integrations with CI/CD pipelines to reduce deployment friction.

### Smart Cost Management

Flexible, pay-as-you-go pricing is important for teams with changing needs. Features like auto-hibernation for idle environments help developers avoid paying for unused resources. This allows developers to keep costs under control while maintaining performance. Evaluate pricing transparency, usage-based billing, and cost-monitoring tools to avoid unexpected spikes as your application scales.

### Built-In Security and Compliance

For regulated industries, security is a must-have requirement. Essential security features include role-based access control, encryption, and comprehensive audit logging. Besides, it requires the platform’s compliance with standards such as [GDPR](https://gdpr-info.eu/), [ISO 27001](https://www.iso.org/standard/27001), and [HIPAA](https://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act). Choose providers that offer built-in security defaults, regular compliance certifications, and clear shared-responsibility models for infrastructure and application security.

### Expert Support and Global Performance

Access to technical support could be crucial for resolving technical issues to minimize downtime. For international applications, distributed data centers and intelligent load balancing ensure fast performance worldwide. Global regions, low-latency networking, and responsive support teams are critical for maintaining uptime and delivering consistent user experience across geographies.

## Top Cloud Hosting Providers

### Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)
 [Atlantic.Net](https://www.atlantic.net/) delivers stable, high-performance infrastructure to developers who need robust and [managed hosting](https://www.atlantic.net/dedicated-server-hosting/what-is-managed-hosting/) without complexity. The platform is designed to support a range of development lifecycles, from MVPs for startups to established business applications. Their infrastructure is built with fast [SSD](https://www.atlantic.net/hipaa-data-centers/what-is-solid-state-drives-non-experts-guide/) instances and RAID-10 storage to ensure rapid response times and minimal downtime. The “Scale Up Servers Anytime” capability allows dynamic resource adjustment without complex migrations. Their pricing mechanism is transparent, starting at $10 per month on demand for general-purpose workloads.

Atlantic.Net’s emphasis on human-centered support sets them apart from other platforms. Their experienced cloud support team provides personalized guidance for complex issues. For regulated industries, they offer [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) that meets stringent security standards. This makes them a suitable choice, especially for HealthTech projects.

The platform easily handles large-scale CI/CD pipelines and containerized applications. A startup developing microservices would benefit from Atlantic.Net’s robust infrastructure, which supports frequent deployments, container management, and fast storage for testing.

Below is Atlantic.Net’s cloud control panel interface used to deploy and manage dedicated and GPU servers.
 ![Atlantic.Net Server Panel](https://www.atlantic.net/wp-content/uploads/2026/01/Atlantic.net-server-panel.png)
 Image Source: Atlantic.Net

**You’ll like them for:**

- **Real, Human Support:** You can get an experienced engineer on the phone to help you with complex problems instead of fighting with a chatbot or a tiered support system.
- **Rock-Solid Performance**: They use high-end hardware to make sure your application is fast and stays online, even when things get busy.
- **Serious HIPAA Compliance:** If you work in healthcare, their audited, compliant hosting is a massive advantage and gives you peace of mind.

**A great fit for:**

- **Startups and Small Businesses:** Gives you enterprise-grade infrastructure and support without the enterprise-level complexity or management overhead.
- **HealthTech and Regulated Apps:** Their deep expertise in [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-in-the-age-of-ai/) makes them a go-to choice for any project handling sensitive health information.
- **Teams That Value Support**: If you’d rather have an expert to call than spend hours digging through documentation, their support model will be a perfect match.

### Amazon Web Services

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)
 [Amazon Web Services](https://aws.amazon.com/) (AWS) remains the largest cloud provider, offering an extensive catalogue of services for developers working on complex, enterprise-level applications. The ecosystem includes foundational services such as [EC2](https://aws.amazon.com/ec2/), [S3](https://aws.amazon.com/s3/), and [CloudFront](https://aws.amazon.com/cloudfront/getting-started/), while advanced offerings include managed databases, [Lambda](https://aws.amazon.com/lambda/) serverless computing, and comprehensive AI/ML tools.

The platform provides a development toolchain including [CodeCommit](https://aws.amazon.com/codecommit/) for source control, [CodeBuild](https://aws.amazon.com/codebuild/) for continuous integration, and [CodeDeploy](https://aws.amazon.com/codedeploy/) for automated deployments. These tools are integrated with existing development workflows and support a wide range of programming languages and frameworks. The global reach of AWS data centers ensures low latency, regardless of the location of users.

However, AWS comes with significant complexity. With numerous services and optimizations which require considerable expertise, the learning curve can be steep for developers new to cloud infrastructure. The pricing model, while comprehensive, can be challenging to predict and optimize. AWS works best for large development teams with dedicated DevOps resources who can fully benefit from its extensive feature set. Smaller teams might find the complexity counterproductive to their development goals.

Here is the AWS EC2 dashboard, where you can control instances, monitor status, and configure settings.

![AWS Instance](https://www.atlantic.net/wp-content/uploads/2026/01/AWS-Instance.png)

Image Source: AWS

**You’ll like them for:**

- **Wide Range of Services:** No matter what you’re trying to build, there’s a very good chance AWS has a managed service for it, which can save you a ton of development time.
- **Global Reach and Reliability:** Its massive, worldwide network of data centers means you can build highly available applications with low latency for a global audience.
- **Developer Friendly:** The integrated “Code” suite of tools lets you build a powerful, automated deployment pipeline without leaving the AWS ecosystem.

**A great fit for:**

- **Huge Enterprise Apps:** For complex, mission-critical systems that need endless scalability and a massive feature set.
- **Teams with DevOps Experts:** If you have engineers who specialise in cloud infrastructure, they can use the full power of AWS to build highly distributed systems.
- **AI/ML and Big Data Projects:** If you’ve got the budget, its powerful computing options and specialised services are perfect for applications that need to process massive amounts of data.

### Google Cloud Platform

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)
 [Google Cloud Platform](https://cloud.google.com/) is a suitable choice in areas where Google has natural advantages, particularly artificial intelligence, machine learning, and data analytics. For developers working with these technologies, GCP provides highly valuable solutions to support the development process.

Key services include [BigQuery](https://cloud.google.com/bigquery) for data analytics, [Vertex AI](https://cloud.google.com/vertex-ai) for machine learning, and [App Engine](https://cloud.google.com/appengine) for building, deploying, and scaling applications without managing infrastructure. Other services include [Cloud Build](https://cloud.google.com/build), [Cloud Functions](https://cloud.google.com/functions), and [Google Kubernetes Engine](https://cloud.google.com/kubernetes-engine). Cloud Build provides continuous integration and deployment that easily integrates with Google’s development ecosystem. Cloud Functions allows serverless computing for event-driven applications. The Kubernetes Engine enables container orchestration based on Google’s original Kubernetes development.

GCP’s global network infrastructure delivers high performance, often matching or surpassing AWS in benchmark tests. Its pricing is typically more competitive, especially for compute-heavy workloads. However, GCP’s market share is smaller than AWS, which means there are fewer third-party integrations and community resources available. This can make it more difficult to find solutions to specific challenges.

Manage cloud services with the Google Cloud dashboard, where you can create virtual machines, deploy applications, and analyze data using built-in tools.

![Google Cloud Dashboard](https://www.atlantic.net/wp-content/uploads/2026/01/Google-Cloud-Dashboard.png)

Image Source: Google Cloud

**You’ll like them for:**

- **Great Data Center Options:** Google own all of the availability zones and have a great global presense.
- **Integration into Google Products: **If you are already invested in Google technnology, GCP is a good choice to expand your cloud footprint.
- **Kubernetes Experience:** If you’re building with containers, GKE is a great tool to work with, automating most of the complexity of managing a Kubernetes cluster.

**A great fit for:**

- **AI-Powered Startups:** If your core product involves machine learning or data analytics, GCP’s specialised tools are an advantage.
- **Modern, Cloud-Native Apps**: Its leadership in Kubernetes and serverless makes it GCP a good home for applications built on a microservices architecture.
- **Projects Where Price-for-Performance Matters:** It’s often more cost-effective than AWS for heavy computing tasks, so you can get more bang for your buck.

### Microsoft Azure

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)
 [Azure](https://azure.microsoft.com/en-us/) is a popular cloud platform that offers a wide range of services, especially for businesses already using Microsoft products. It works well with Visual Studio, .NET, and other Microsoft development tools. This makes it a natural fit for organizations that rely on Windows or are part of the Microsoft ecosystem.

[Azure DevOps](https://azure.microsoft.com/en-us/products/devops) gives developers tools for project management, source control, and deployment. If they are already using Microsoft Office 365 or other Microsoft services, Azure makes it easy to connect everything. This helps them with identity management and sharing data across different systems.

Azure’s key services include virtual machines, web hosting, and advanced AI tools. It also offers powerful options for containers and serverless computing, such as Azure Kubernetes Service and Azure Functions. Security is strong, with certifications like [HIPAA](https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-hipaa-us) and [ISO 27001](https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-iso-27001).

One of Azure’s biggest advantages is its [hybrid cloud](https://www.atlantic.net/gpu-server-hosting/scaling-ai-workloads-why-hybrid-cloud-infrastructure-is-the-future-of-enterprise-ai/) support. Developers can keep some of your infrastructure on-premises while using the cloud, which is helpful if you have existing Windows Server setups or face rules that don’t allow full cloud adoption.

Azure’s pricing is competitive, especially when bundled with other Microsoft products. However, Azure is most suited to Windows-based solutions. If your team mainly works with Linux or open-source tools, Azure may not be the best fit.

Explore the Azure dashboard to organize resource groups, track usage, and manage cloud services from a centralized platform.

![Microsoft Azure](https://www.atlantic.net/wp-content/uploads/2026/01/Microsoft-Azure.png)

Image Source: Azure

**You’ll like them for:**

- **Seamless Microsoft Integration:** If you’re a .NET developer using Visual Studio, the experience is incredibly polished. Everything just works together perfectly.
- **Strong Hybrid Cloud Tools**: It’s a popular choice if you need to run some of your infrastructure in your own data center and some in the cloud.
- **A Powerful, All-in-One DevOps Platform:** Azure DevOps is a really strong competitor to tools like Jira and GitLab, offering planning, source control, and CI/CD in one package.

**A great fit for:**

- **Companies Already on the Microsoft Stack**: If your organisation runs on Windows Server, .NET, and Office 365, choosing Azure will make your life much, much easier.
- **Hybrid Setups:** Perfect for businesses that need to keep some servers on-premise for regulatory or legacy reasons but still want a cloud first strategy.
- **C# and .NET Developers:** Azure offers a supportive environment for developers working in the Microsoft programming ecosystem.

### Kamatera

![](https://www.atlantic.net/wp-content/uploads/2026/04/kamatera-logo.png)

[Kamatera](https://www.kamatera.com/products/cloud-servers/) is an excellent choice for developers and businesses that need highly customizable cloud infrastructure without the complexity often associated with enterprise [cloud platforms](https://www.atlantic.net/cloud-platform/). The platform allows users to build virtual servers with precisely the CPU, RAM, storage, and networking resources they require, making it ideal for everything from small development environments to large-scale production workloads.

Kamatera offers a wide range of cloud services, including cloud servers, managed Kubernetes, load balancers, [block storage](https://www.atlantic.net/vps-hosting/what-is-block-storage/), private networking, and managed cloud solutions. Its global data center presence helps businesses deploy applications closer to their users while maintaining performance and reliability.

One of Kamatera’s biggest strengths is flexibility. Developers can rapidly provision cloud servers, scale resources on demand, and choose from multiple operating systems and application templates. This makes it particularly attractive for startups, SaaS companies, and development teams that need infrastructure capable of growing alongside their applications.

Here is the Kamatera cloud management platform, where users can deploy virtual servers, scale resources instantly, configure networking, and manage cloud workloads from a centralized dashboard.

![Kamatera Panel](https://www.atlantic.net/wp-content/uploads/2026/04/kamatera-panel.png)

**Image Source:** Kamatera

**You’ll like them for:**

- **Highly Customizable Infrastructure:** Configure exactly the amount of CPU, RAM, storage, and bandwidth your workload requires without paying for unnecessary resources.
- **Instant Scalability:** Resources can be added or adjusted quickly, making it easy to handle traffic spikes, application growth, or changing business requirements.
- **Global Cloud Network:** Multiple worldwide data center locations help reduce latency and improve application performance for international users.

**A great fit for:**

- **Growing Startups and SaaS Companies:** Businesses that need cloud infrastructure capable of scaling as customer demand increases.
- **Developers and DevOps Teams:** Teams that want complete control over server configurations, networking, and deployment environments.
- **Organizations Running Dynamic Workloads:** Applications with changing resource requirements that benefit from flexible, on-demand cloud infrastructure.
- **Developers Who Need Enterprise-Level Flexibility:** Users who want advanced cloud capabilities without the complexity and pricing structure of larger hyperscale cloud providers.

## Choosing the Right Cloud Hosting Solution

Selecting the right cloud hosting provider involves evaluating several essential factors. Consider the scale and complexity of your project before making a choice. Simple MVPs (Minimum Viable Products) have different requirements than large-scale enterprise applications designed for a global audience.

The expertise of the development team is also a key factor to consider when choosing a platform. If your team has strong DevOps capabilities, you might prefer a cloud provider that offers more control over configurations and management. On the other hand, teams with limited experience in infrastructure may benefit from highly managed cloud services.

Budget is another crucial factor to consider. You must decide whether a predictable pricing model or a flexible pay-as-you-go approach is suitable for your project. Features such as automatic hibernation can help optimize costs.

Security should also be a top priority, especially for applications dealing with sensitive data. You must ensure that your cloud provider complies with relevant standards, such as HIPAA or [GDPR](https://www.atlantic.net/vps-hosting/gdpr-compliance-for-global-managed-service-providers/), to safeguard your data.

Finally, it’s important to recognize that the geographic distribution of your platform can significantly impact performance. Choosing a provider with data centers near your target audience helps ensure faster load times and lower latency.


---

# Top 8 Best USA-Based Software as a Service Solutions for SMBs in 2026

> URL: https://www.atlantic.net/vps-hosting/top-8-best-usa-based-software-as-a-service-solutions-for-smbs/ | Published: 2026-04-28 | Updated: 2026-04-29 | Author: Richard Bailey

The best SaaS solutions for SMBs in 2026 combine ease of use, flexible pricing, and built-in AI features that automate everyday tasks. Tools like CRM platforms, accounting software, marketing automation, and collaboration apps help small businesses operate efficiently without large IT teams.

When choosing SaaS tools, SMBs should focus on three factors:

- Fit for their core business function
- Ability to scale as the business grows
- Built-in automation or AI to reduce manual work

We’ve created this best Software-as-a-Service article to recognize the best software for U.S.-based SMBs. The nominees are all SaaS solutions that offer innovative customization or solve a universal problem.

## What Is SaaS?

SaaS is software [hosted in the cloud](https://www.atlantic.net/vps-hosting/) that you can access through the internet. It can be accessed remotely, typically via a web browser, and does not usually require specific installation data files or software packages on your company or home computer.

A SaaS vendor provides the entire software product and all future updates and patches, so there is no need to worry about updating programs, upgrading your internet connection, or other technical difficulties.

## 1. TalkDesk – Best for AI-Powered Customer Experience Automation

TalkDesk is a SaaS-based customer communication platform that helps businesses improve customer engagement through chat and email. With TalkDesk, companies can easily manage customer conversations, contact information, and email messages in one place. Talkdesk now emphasizes AI-driven customer service, including virtual agents, sentiment analysis, and real-time agent assistance to improve response times and customer satisfaction. Plus, TalkDesk offers a variety of features to make managing customer communication easy, including:

- **Real-time communication**: TalkDesk lets businesses chat with customers in real time, so you can quickly address any issues.
- **Customizable messages:** You can customize your notifications to match your brand and style.
- **Email integration:** TalkDesk lets you easily integrate with your email system to send and receive messages.
- **AI capabilities:** Includes virtual agents, automated call routing, and real-time insights to reduce manual support workload.

## 2. Slack – Best for Team Communication and Collaboration

Slack is a cloud-based communication platform that helps teams work better together. You can get more done with Slack by letting your team chat and share information instantly. Slack has many advantages, such as managing your communication with bots and integrating other tools. In addition, Slack offers effortless integration with ticketing systems, cloud applications, and anything with an API to improve knowledge sharing across the business.

Slack is hugely popular, and its integrations and capabilities make it easy to communicate with coworkers, customers, and teams. It stands out in a crowded instant messaging market and it’s an easy way to stay connected with your team and a great way to share information.

Slack now includes built-in AI features such as conversation summaries, automated workflows, and intelligent search, making it easier for SMB teams to manage large volumes of communication efficiently.

## 3. Trello – Best for Simple Project and Task Management

Trello is a popular Kanban-style project management tool. Some of the critical features of Trello include its easy-to-use interface, collaboration features, and ability to track progress and changes. The platform allows teams to track progress and changes in their projects. In addition, the Kanban boards enable users to assign tasks to team members, post a project to a person, and set reminders to ensure their team can manage multiple tasks simultaneously.

Trello integrates with Google Docs, Gmail, and YouTube, to name a few. It has been designed to make teamwork more accessible than ever, thanks to its easy-to-use interface, intuitive organization, ability to group cards, and easy-to-use clients. The Trello app is available for various mobile phones and tablets.

Trello includes automation features like rule-based workflows and AI-assisted task prioritization, helping SMB teams streamline project management with less manual effort.

## 4. Toggl – Best for Time Tracking and Productivity Insights

Toggl is a cloud-based time tracking and productivity tool that helps employees capture and manage their work on a single platform. With key features like remote access and automatic export to many popular productivity tools, Toggl is an excellent choice for freelancers and big or small businesses.

Toggl has intelligent ways to manage your time, projects, and employees’ time. Time management is essential to track costs and direct your team’s focus. In addition, it can track the team’s workflow and helps to prevent the siloing of team information.

Toggl now includes smarter reporting and automation features, helping SMBs analyze productivity trends, identify time leaks, and optimize team performance with minimal manual tracking.

## 5. Bit.ai – Best for Collaborative Documentation and Knowledge Sharing

Bit is a robust shared documentation and collaboration tool. Bit is a workflow solution that allows users to manage and share content effectively; you can create, edit and share from the same place. It also has a content management system and a document editor that is compatible with all the latest office suites, making it ideal for creating and managing content.

Bit also has end-to-end sharing capabilities that make it perfect for sharing documents with teammates, with an easy-to-use frontend. Finally, Bit offers a variety of branding and security options that make it a top choice for businesses.

Bit.ai increasingly supports smarter content workflows, including document tracking, embedded media, and structured collaboration, helping SMB teams centralize knowledge and reduce fragmented documentation.

Atlassian tools now include AI-assisted features such as automated issue summarization, smart search, and workflow recommendations, helping SMBs and technical teams streamline development and operations.

## 6. Atlassian Suite – Best for DevOps and Scalable Project Management

The Atlassian Suite is a comprehensive SaaS platform that provides users with various tools to manage their work and projects. Their target audience is DevOps engineers and Developers. It includes popular collaboration tools such as the agile ticket system Jira and the related Jira Service Manager for tracking change management and tech support.

Jira is a popular project management tool that allows users to manage their work and projects efficiently. In addition to tracking tasks, deadlines, and changes, Jira provides users with various other features, such as task boards, chat features, and integrations with other software.

All Atlassian products integrate and use similar user interfaces, which makes them super user-friendly. In addition, the suite includes the popular Confluence documentation hub and the BitBucket source code repository service.

## 7. Zoho – Best for All-in-One SMB Business Suite

Zoho is a cloud-based business software company that offers a suite of products that helps businesses manage their data, collaborate, and get work done. Zoho features include a drag-and-drop interface, a powerful CRM, and a robust email platform. Zoho’s benefits include a simple, user-friendly interface, a wide range of parts, and a support team that is available 24/7.

Zoho has over 45 SaaS products for almost all industries, and popular products include social and marketing, support desk, human resources, accounting, and operations. In addition, each product can be integrated with enterprise SaaS products such as GSuite, Microsoft 365, and Shopify.

Zoho has expanded its AI capabilities through its assistant (Zia), enabling features like predictive sales insights, workflow automation, anomaly detection, and intelligent data analysis across its suite, making it a strong choice for SMBs looking for an integrated, AI-enhanced platform.

## 8. Miro – Best for Visual Collaboration and Team Brainstorming

Miro is a visual cloud-based project management tool that creates a virtual space for virtual collaboration. With Miro, users can create and edit pictorial boards with various tools and templates. In addition, users can create visualizations such as the Storyboard, which helps users to create a video with a pre-determined structure.

Miro is quite a unique collaboration product that increases efficiency and productivity by managing projects more effectively and efficiently and reducing the time needed to complete the work. In addition, it offers greater transparency and communication by making it easy for team members to share and collaborate on projects.

Miro now includes AI-powered features such as automatic diagram generation, meeting summaries, and intelligent templates, helping SMB teams speed up brainstorming sessions and convert ideas into actionable plans faster.

## How Can Atlantic.Net Help?

If you are looking for a [cloud partner](https://www.atlantic.net/vps-hosting/), consider adopting a leading cloud service provider as your partner to power the technology your business demands. With over 30 years of proven experience, our full suite of managed services and trusted professional support team will build the perfect customized hosting solution to support your business or organization.

Atlantic.Net is SOC 2, and SOC 3 certified, HIPAA and HITECH audited via qualified and independent third-party auditors. In addition, we provide 24x7x365 support, monitoring, and world-class data center infrastructure. You can find out more information by[contacting our sales team today](https://www.atlantic.net/about-us/corporate-contact/#GetStarted)!


---

# Best Cloud Migration Solution in 2026

> URL: https://www.atlantic.net/vps-hosting/best-cloud-migration-solution/ | Published: 2026-04-28 | Author: Richard Bailey

The Cloud Computing market is surging in popularity. The Covid-19 pandemic cemented the need for global businesses to be more agile and adaptable to successfully navigate the troubled waters of the pandemic. The cloud provided these capabilities, and companies embarked on migrating critical IT services to their preferred cloud provider at an unprecedented scale.

In 2026, cloud migration is no longer optional for most organizations—it is a core part of IT modernization, cost control, and AI readiness strategies.

Migrating production workloads is a big task. One that requires careful planning and deep consideration. It needs clear guidelines and goal objectives to be successful. Businesses often outsource this responsibility to a cloud services provider or business partner.

Modern migration strategies now focus on minimizing downtime, maintaining data integrity, and aligning workloads with cloud-native architectures such as containers and microservices.

A cloud migration tool is software that helps to move your files, folders, and applications from your current computing environment to the cloud. While there are many different types of migration tools on the market, the best ones offer a comprehensive solution that can handle all aspects of the migration process for you. Today’s leading migration tools also include automation, real-time monitoring, and compatibility assessments to reduce risk during complex migrations.

This article will discover the best cloud migration solutions and how they can help you move your business to the cloud. We’ll also introduce you to some of the best tools on the market and show you how to choose the right one for your business.

## 1. Atlantic.Net Cloud Migration Service

Atlantic.Net understands that migrating your production and development environments can be daunting for IT departments that are often already stretched thin.

Atlantic.Net offers three migration plans:

- **Standard:** The Standard Migration service includes migrating defined data directories from your current system, either on-premise or at another provider. Atlantic.Net’s Security Operations Center (SOC) handles the data migration and will ensure that your desired data makes it into your new environment. Our skilled team of experts performs migrations for new clients daily, including cPanel migrations, file share migrations, and Plesk migrations.
- **Advanced:** Your migration will be assigned to a dedicated engineer who will discuss your current and new environment plans, review your current and new environments to ensure compatibility, and assist with planning the migration. A dedicated engineer will then complete the migration on your behalf.
- **Enterprise:** Enterprise Migrations include everything from the Standard and Advanced migration services with the added feature of allowing our engineering department to perform complete bare metal restores (BMR) or Physical to Virtual migrations (P2V).

In 2026, enterprises increasingly choose managed migration services like Atlantic.Net to reduce internal workload and accelerate compliance readiness.

## 2. Velostrata (Migrate for Compute Engine)

Velostrata is a cloud migration tool exclusively used with the Google Cloud Platform. Its purpose is to migrate infrastructure and applications to GCP in a simple, user-friendly package. It offers automatic workload sizing, automated deployment, and quick recovery and integrates with many on-premise application stacks, including VMware, HyperV, and physical and virtual servers. You can also migrate workloads from other cloud providers into GCP, but there is no feature to migrate out of GCP. It remains a strong option for organizations standardizing on Google Cloud and prioritizing rapid workload mobility.

## 3. CloudEndure

CloudEndure is a software-as-a-service (SaaS) platform that enables organizations to create runbooks to automate migrating their cloud-based applications to AWS. With CloudEndure, you can automate cloud-based tasks, such as application deployment, update management, and compliance testing.

CloudEndure also offers a range of features to help keep all on-premise and migrated data in sync. For example, you can use CloudEndure’s Runbook Designer to create and edit migration strategies, and the Runbook Manager will manage data synchronization automatically. If you are looking to automate your cloud-based migration process, CloudEndure is a valuable tool. Automation-driven migration platforms like CloudEndure are widely used in 2026 to reduce manual intervention and improve migration consistency across environments.

## 4. DataDog

DataDog is a cloud-based data migration tool that makes it easy to move your data from one cloud storage provider to another. With DataDog, you can quickly move your data between Amazon AWS, Google Cloud Platform, Microsoft Azure, and Rackspace Cloud. DataDog also offers a migration advisor to help you make the most informed decision about which cloud storage provider to use. Its strength in observability and real-time monitoring helps teams track migration performance and quickly identify issues during data transfers. In addition, DataDog takes the hassle out of data migration by automating the process of moving your data to the cloud.

## 5. Dynatrace

Dynatrace is a comprehensive cloud migration management solution that helps organizations migrate their workloads to the cloud quickly, accurately, and confidently. Dynatrace provides a complete end-to-end platform to manage migrations, including pre-and post-migration planning, migration execution, and post-migration support. Its AI-driven monitoring capabilities are especially valuable in 2026 for identifying performance bottlenecks during and after migration. Dynatrace is also unique in its ability to integrate with other cloud-based tools to provide a holistic cloud migration experience.

## 6. AppDynamics

AppDynamics is a global leader in cloud migration solutions. It offers robust features to help customers move their applications to the cloud, including on-demand migration, automation, and integration with other cloud-based solutions. As a result, AppDynamics helps customers move their applications to the cloud quickly, efficiently, and cost-effectively.

The AppDynamics agent can scan deep inside your network to determine how your existing infrastructure hangs. AppDynamics helps customers move their applications with minimal disruption with its on-demand migration and automation capabilities. Application performance monitoring is a critical requirement in 2026 migrations, and AppDynamics provides visibility across complex distributed systems. In addition, AppDynamics integrates with other cloud-based solutions to help customers advance their applications faster and more efficiently.

## 7. Carbonite Migrate

Carbonite Migrate is a cloud migration tool that helps users move their data and applications to different cloud platforms. It offers a variety of features that can make the migration process more manageable.

Carbonite Migrate creates a virtual copy of the data and applications that will be moved. This virtual copy can then test the migration process before it is executed. This approach—often called “non-disruptive testing”—is widely used in 2026 to validate migrations before cutover. Once the migration is complete, the virtual copy can get deleted to free up space on the original system.

## 8. Turbonomic

Turbonomic is the latest in a long line of cloud-based business automation tools. It offers a comprehensive set of features to help businesses streamline their workflows.

Turbonomic is perfect for migrating your business to the cloud. It offers a simple, easy-to-use interface and integrates seamlessly with other cloud-based applications. Its resource optimization capabilities help ensure workloads are correctly sized after migration, which is a key cost-control factor in 2026. Plus, it provides a wide range of features to help you manage your business more efficiently.

## 9. Flexera

Flexera is a cloud-based migration platform designed to help organizations move their applications and data to the cloud. It features many features, including migration tools, data management, and security.

There are several reasons why organizations might want to use Flexera. For example, it can help streamline the migration process by providing various tools and features. In addition, Flexera can help to protect data by providing a range of security features. Flexera is also widely used for cloud cost management and governance, which are critical considerations in modern multi-cloud environments. Finally, it can help to reduce the costs associated with moving to the cloud by providing a range of cost-effective options.

## 10. Corent Surpass

Corent Surpass is a cloud migration tool that helps organizations move their applications and data to the cloud.

Features of Corent Surpass include:

- Automatic application and data migration
- Real-time tracking and reporting
- Customizable migration plans
- Secure data transfers

Corent Surpass is a powerful and efficient cloud migration tool that can help organizations move their applications and data to the cloud quickly and easily. Tools like Corent Surpass are increasingly used for application discovery and transformation into cloud-ready architectures. Its real-time tracking and reporting features make it easy to keep track of the migration’s progress and make changes as needed. In addition, its customizable migration plans make it easy to find the perfect solution for each situation.

## Ready to Find Out More?

Atlantic.Net is ready to help you attain fast compliance with various certifications, such as SOC 2 and SOC 3, HIPAA, and HITECH, with 24x7x365 support, monitoring, and world-class data center infrastructure for [VPS hosting](https://www.atlantic.net/vps-hosting/) and more.

For faster application deployment, free IT architecture design, and assessment, visit us at [Atlantic.Net](https://www.atlantic.net/), call 866-618-DATA (3282), or email us at [sales@atlantic.net.](mailto:sales@atlantic.net)

---

#### Read More About Data Migration

- [Migration Services](https://www.atlantic.net/managed-services/migration-services/) from Atlantic.Net
- [WordPress Migration Services](https://www.atlantic.net/vps-hosting/migrate-wordpress-website-downtime-5-steps-1-day/)

---


---

# Dedicated Hosting vs Public Cloud TCO in 2026

> URL: https://www.atlantic.net/cloud-platform/dedicated-hosting-vs-public-cloud-tco/ | Published: 2026-04-29 | Updated: 2026-04-30 | Author: Editorial Team

Public cloud has carried the conversation about modern infrastructure for more than a decade. Elasticity, near-limitless scale, and a pay-as-you-go meter changed how teams provisioned capacity, and for a large class of workloads, it still earns its keep.

The conversation in 2026 is different. Companies that once spun up cloud accounts to experiment have spent several years running production on them, and the bills for steady-state workloads do not match the early projections. Finance teams have started asking harder questions, and engineering teams have begun taking them seriously.

That was the situation for one customer Atlantic.Net recently worked with. A workload that had run on a hyperscaler for three years was generating predictable, steady traffic, and the monthly invoice had grown faster than the workload itself. The conversation was no longer about whether the cloud was the right platform on day one. It was about whether the same platform was still the right one on day one thousand.

The choice between dedicated hosting and public cloud is not an ideological question in 2026. It is an analysis question, and the analysis is the total cost of ownership over the application’s real life.

## Price and Total Cost of Ownership Are Not the Same Number

Total cost of ownership (TCO) is often confused with the monthly invoice. The invoice is one input. TCO is the full economic picture across the application’s life, shaped by how the underlying infrastructure is priced, billed, scaled, and operated.

Public cloud unbundles infrastructure into very small pieces. Compute seconds, storage tiers, API calls, inter-zone traffic, and egress are all metered separately. The granularity is genuinely useful for some workloads. It is also the reason a modest first-month bill can grow into shapes the original budget never modeled.

Dedicated hosting prices the same resources differently. Capacity is bundled. The cost is set by the hardware allocated, not by the operations the workload performs against it. The economic question shifts from elasticity to , and the line items shrink to a count a finance team can hold in their head.

## Where Public Cloud Economics Still Win

Public cloud is designed for variability. The pricing model assumes demand will swing, sometimes dramatically, and the customer benefits when their cost follows their demand curve down as well as up.

That is the right fit for unpredictable or short-lived workloads. Development and test environments, seasonal traffic peaks, batch jobs that run for an hour and then disappear, and applications still searching for product-market fit all benefit from compute that costs nothing when it is not running.

The economics work less well when a workload reaches a steady state. Continuous compute billing on a server that runs twenty-four hours a day starts to resemble a long-term lease at short-term-lease prices. Storage is charged by capacity, by access, and by redundancy choices. Egress sits in the background and quietly turns into a real number on multi-terabyte data flows.

The result is a category of workload that started in the cloud for the right reasons and stayed there beyond the point where those reasons no longer applied. Cloud repatriation is the recalibration that follows. Most repatriation projects are not a wholesale exit from public cloud. They are a sorting exercise: which workloads belong on a metered platform, and which belong on a fixed-capacity one.

## Predictability as a Financial Feature

Dedicated hosting prices a fixed slice of hardware. The cost does not change with traffic, API call volume, or the level of chatty communication between zones. That predictability has two financial consequences worth naming.

The first is planning. Capacity planning replaces cost firefighting. Annual budgets stop being forecasts that have to absorb monthly surprise variances. The conversation between engineering and finance becomes “do we need a larger server next quarter,” not “why was the bill twenty percent higher in March?”

The second is performance per dollar. A dedicated server is not a multi-tenant slice. The CPUs and memory are not shared with other workloads, and the noisy-neighbor effect that occasionally surfaces on shared cloud instances does not apply. For workloads where consistent throughput matters more than bursty scale, transactional databases, real-time data pipelines, and anything tied to a strict service-level agreement (SLA), deterministic performance is the feature, not the price.

## Compliance and Control

Cost and performance dominate most TCO conversations. Regulated industries have a third axis that often outweighs both. Healthcare, finance, payments, and any sector handling sensitive personal data work to compliance frameworks such as the Health Insurance Portability and Accountability Act (HIPAA) and the Payment Card Industry Data Security Standard (PCI-DSS). Those frameworks govern not only the security posture of the infrastructure but also the controls for how data is stored, processed, and accessed.

Public cloud providers offer compliant environments under a shared-responsibility model. The provider secures the underlying platform. The customer is responsible for configuration, identity and access management, network controls, and day-to-day governance. The model works, and it also creates surface area. Misconfigured object storage and overly permissive identity policies are the two most common causes of compliant platforms producing noncompliant outcomes.

Dedicated hosting narrows the surface area. Resources are not shared with other tenants. Isolation is a hardware property, not a configuration property. Audit trails are simpler, the layers below the application are fewer, and the boundary between the customer’s controls and the provider’s controls is easier to draw on a whiteboard. For workloads that have to demonstrate that boundary to an auditor, the simpler diagram has measurable value.

## Hybrid Is Not a Compromise

The most common pattern Atlantic.Net sees in 2026 is hybrid by design. The same organization runs steady-state production workloads on dedicated infrastructure. It uses public cloud for the work the public cloud is best at: development environments, burst capacity, geographically distributed front ends, and applications whose demand profile genuinely flexes.

Hybrid is not a hedge. It is the recognition that workloads have different economic shapes, and a single platform optimized for one shape is paying a tax on the others. Cloud repatriation is the visible half of this trend. The less visible half is companies that never went all-in on public cloud and have spent the last several years quietly running production on dedicated infrastructure, with public cloud for the elastic edges.

## Matching Workloads to the Right Model

The decision is workload-by-workload, not platform-by-platform.

, unpredictable workloads belong in the public cloud. E-commerce platforms with seasonal peaks, startups with growth curves nobody can forecast, batch processing that runs for hours and then idles, and short-lived development environments all benefit from instant scale and zero cost when idle.

Steady, resource-intensive workloads belong on dedicated hosting. Production databases, enterprise applications with predictable load, transactional systems with strict latency requirements, and anything covered by a compliance framework with a clear isolation requirement run more cheaply, more predictably, and often more performantly on dedicated hardware.

The mistake is not picking the wrong platform on day one. The mistake is leaving a workload on the platform that fits it on day one and never re-evaluating it when it changes.

## How Atlantic.Net Fits the 2026 Picture

Atlantic.Net’s portfolio is built for that re-evaluation. Bare-metal and dedicated hosting address workloads that require predictable costs, deterministic performance, and clear compliance boundaries. Public cloud hosting on the same platform supports workloads that require elastic capacity and pay-as-you-go economics. HIPAA- and PCI-DSS-compliant tiers wrap both controls and the documentation that regulated industries need.

The value is not a single tier. It is the ability to move workloads between tiers as their economics evolve, on a single provider relationship, without re-architecting the surrounding compliance and operations work. A workload that starts elastic in the cloud tier and matures into a steady-state production system can be moved to a dedicated tier without changing vendor, account team, or compliance scope.

## Closing: Decisions With Clarity

The cleanest way to think about dedicated hosting versus public cloud in 2026 is to stop framing it as a choice between platforms and start framing it as a question about workloads. Public cloud is the right answer for variability, agility, and short time horizons. Dedicated hosting is the right answer for predictability, isolation, and long horizons.

The successful infrastructure strategies share one habit. They re-examine each workload on a clock, ask whether its shape has changed, and move it when the answer is yes. Atlantic.Net’s role in that conversation is to make the move cheap and the decision boring, so the cost question stops being a surprise and starts being a planning input.


---

# Hyperconverged Made Simple: Proxmox VE 9, Ceph, and OPNsense on Atlantic.Net Dedicated Servers

> URL: https://www.atlantic.net/dedicated-server-hosting/hyperconverged-made-simple-proxmox-ve-9-ceph-and-opnsense-on-atlantic-net-dedicated-servers/ | Published: 2026-04-30 | Author: Richard Bailey

Growing MSPs, cybersecurity firms, and compliance-driven service providers regularly approach us with detailed Requests for Quotation (RFQs) and ambitious infrastructure requirements. They are not looking for basic hosting. They need modern hypervisor clusters, high-speed private networking for Ceph, dedicated security appliances, dense storage, flexible networking, audited data center environments, and aggressive migration timelines.

A recent RFQ captured the real of modern infrastructure design projects: demanding technical specifications, clear compliance obligations, and a deployment window with little margin for delay. On paper, that is seven servers, three operating systems, fourteen network interfaces, ten VLANs, and a data center audit trail. In practice, it is a normal Tuesday for Atlantic.Net.

This post walks through the hyperconverged stack MSPs are building in 2026, the buying questions that come up in every RFQ, and where Atlantic.Net’s dedicated server platform and managed services fit into a customized solution.

## The Hyperconverged Stack MSPs Are Building in 2026

Hyperconverged infrastructure (HCI) collapses compute, storage, and networking onto a single cluster of commodity servers. The software layer handles the job that dedicated SAN arrays and top-of-rack switches used to. Proxmox runs the virtual machines. Ceph, an open-source distributed storage platform, pools drives across every node and replicates each write three times. A next-generation firewall guards the perimeter. Ceph calls each per-drive process an Object Storage Daemon, or OSD.

Proxmox VE 9.1 with hyperconverged Ceph has quietly become the platform MSPs choose when they want predictable cost, modern hardware, and open licensing. Proxmox VE 9 ships with Ceph v19.2 “Squid” by default, LZ4 compression enabled, and improved BlueStore handling for snapshot-heavy workloads. Pair it with a next-generation firewall for the edge and a storage-dense NAS running Proxmox Backup Server and an ELK stack (Elasticsearch, Logstash, and Kibana, the open-source log analytics trio), and you cover compute, storage, security, and observability in one bill of materials.

The architectural shape is consistent across almost every RFQ we see:

- Four or more hypervisor nodes running Proxmox VE with hyperconverged Ceph OSDs
- A dedicated 25 Gbps Layer 2 (L2) private fabric carrying Ceph cluster and Ceph client (public) traffic
- Two perimeter firewall appliances are the only internet-facing machines in the environment
- One storage-dense NAS and backup and observability server with both HDD capacity and NVMe hot tiers
- A routed /26 public subnet assigned exclusively to the firewalls, which NAT every other server

## Hypervisor Nodes: Proxmox VE 9 on Current-Generation Silicon

A hypervisor node in a Ceph cluster has three jobs: run the virtual machines, serve Ceph storage to every other node in the cluster, and survive a peer going down without hesitation. The spec list MSPs tend to map cleanly to those jobs.

- **CPU:** Current-generation AMD EPYC 9004 or 9005 (Genoa, Turin) or Intel Xeon 4th, 5th, or 6th Gen Scalable (Sapphire Rapids, Emerald Rapids, Granite Rapids).
- **RAM:** 512 GB DDR5 ECC per node runs a four-node cluster with virtual desktop infrastructure (VDI) workloads under HIPAA scope, Ceph OSD services, and monitor daemons comfortably. 2 TB cluster total.
- **Boot and OS drives:** 2× 480 GB or larger SSD or NVMe in a hardware RAID-1 or a ZFS mirror (ZFS is the copy-on-write filesystem with checksums and snapshots built in), kept separate from the OSD drives. Proxmox, monitors, and logs live here.
- **Ceph OSDs:** 4× 3.84 TB enterprise NVMe drives per node (NVMe is the PCIe-attached flash standard that replaced SATA SSDs for latency-sensitive work), passed through as individual block devices. No hardware RAID on the OSD drives. The host bus adapter (HBA) runs in IT mode, also known as JBOD (“just a bunch of disks”), so Ceph owns the disk layer end to end.

Hardware compatibility with the Proxmox VE 9.1.5 matrix (CPU, NIC, HBA, IPMI) is a pre-provisioning conversation between customer and provider, not a post-delivery surprise.

## The 25 Gbps Private Ceph Fabric

Ceph performance is a network problem before it is a disk problem. With NVMe OSDs and three-way replication, every write has to hit two additional nodes across the Ceph fabric before it is acknowledged, and a single drive failure triggers a cluster-wide rebuild that shifts gigabytes between nodes in seconds.

A 10 Gbps link collapses under that recovery storm and chokes even ordinary writes. 25 Gbps absorbs it. The Proxmox project documents 10 Gbps as the floor and 25 Gbps as the working minimum for production Ceph clusters. 100 Gbps on the backend with data center NVMe is the gold standard.

A hyperconverged build scoped for this RFQ looks like:

- 2× 25 Gbps dedicated private interfaces for Ceph cluster and Ceph public (client) networks, isolated on their own virtual LAN (VLAN)
- 2× 10 Gbps interfaces bonded with LACP, two NICs joined into one logical link for throughput and automatic failover, for VM traffic and Proxmox management on a separate private VLAN
- Zero internet exposure on the hypervisors. All egress routes through the perimeter firewalls.

The network separation keeps Ceph recovery traffic from starving VM I/O and keeps the attack surface on the hypervisors at zero.

## Firewall Appliances: Customer-Managed OPNsense or Managed FortiGate as a Service

MSPs approach the perimeter firewall in two different ways, and both patterns appear in RFQs.

The first pattern is customer-managed OPNsense Business. OPNsense runs on FreeBSD, and FreeBSD is picky about network cards. Pick the wrong NIC, and a firewall deployment becomes a two-day driver-debugging session. Mellanox, Broadcom, and Realtek parts range from flaky to unusable under FreeBSD production load. Intel X710, X550, and I350 silicon has mature FreeBSD drivers and behaves. RFQs asking for OPNsense typically specify:

- Single-socket Xeon E3 or E5 class, 4 to 8 cores
- 64 GB DDR4 ECC
- 2× 1 TB or 2 TB SSD in RAID-1
- 2× 10 Gbps Intel NICs with LACP and VLAN support
- IPMI (Intelligent Platform Management Interface, effectively KVM-over-IP baked into the motherboard) with remote ISO mount, so the customer installs OPNsense Business from their own image

The second pattern is managed FortiGate Firewall as a Service. Atlantic.Net offers FortiGate FaaS through a partnership with Fortinet, which suits MSPs that would rather not operate the firewall layer themselves. FortiGate brings FortiOS with thirty integrated security and networking functions (firewall, VPN, NGFW, segmentation, distributed NGFW, DDoS defense, SSL inspection, secure SD-WAN, ZTNA) and FortiGuard AI-powered threat intelligence covering IPS, anti-malware, application control, web and DNS filtering, botnet command-and-control detection, data loss prevention, anti-spam, and inline malware prevention. The Fortinet use cases that map to this RFQ shape are Data Center Perimeter, Virtual Firewall, and Hyperscale.

Either way, the /26 routes to the firewall interfaces. The firewalls NAT every hypervisor, VM, and backup target behind them. No public IPs touch the cluster itself.

## NAS and ELK Server: Bulk HDD, Hot NVMe, Elasticsearch Heap

The NAS box is the workhorse in most MSP stacks. It holds NFS home directories for VDI users, SMB file shares for corporate workloads, the Proxmox Backup Server datastore, and the ELK hot, warm, and cold tiers. Customers asking for this role typically specify a single storage-dense chassis:

- Dual-socket Xeon with 20 or more cores. ELK indexing is CPU-bound, and Elasticsearch benefits from every core you give it.
- 384 GB DDR4 ECC for Elasticsearch heap and ZFS’s in-memory read cache, the ARC.
- 12× 8 TB or larger SATA or SAS HDD in ZFS RAIDZ2 or RAIDZ3. That is the bulk capacity layer. NFS, SMB, Proxmox Backup Server, and ELK cold data all live here.
- 4 to 5× 3.84 TB NVMe for ELK hot and warm indices, plus ZFS’s write-log (SLOG) and flash read-cache (L2ARC) accelerators.
- 4× 10 Gbps LACP for high-throughput NFS serving to the hypervisor cluster.

A chassis with 12 or more 3.5-inch HDD bays and NVMe slots in the same box is standard enterprise hardware, and storage-dense dedicated server builds accommodate that form factor.

## Network Control: Self-Service VLANs, Routed Subnets, BGP

MSPs do not want to open a NOC ticket every time a new client VLAN goes live, and the larger ones want to announce their own IP space via Border Gateway Protocol (BGP), the routing protocol the public internet runs on. Self-service VLAN creation, modification, and deletion is the expected baseline in 2026, and a BGP announcement should be a phone call rather than a project. Modern MSP stacks look for:

- **Self-service VLANs** via portal and API, with no ticket required. Starting with 10 or more VLANs at launch (Ceph cluster, management, WAN, DMZ, per-client segments) is normal.
- **Routed /26 subnets** delivered to specific firewall interfaces. Public IPs bind only to the firewall appliances, not to every server.
- **BGP announcement** of the customer IP space when the customer is ready.
- **Network-level DDoS mitigation** at the edge.
- **Flat-rate bandwidth** without 95th-percentile billing games. A 54 Mbps p95 and 15.5 TB monthly transfer profile fits cleanly.

## Compliance: SOC 2 Type II, HIPAA, and PCI DSS 4.0 Built In

MSPs serving healthcare and payment clients can’t treat compliance as a bolt-on. Atlantic.Net’s data centers are SOC 2 Type II and SOC 3 Type II audited, with controls for HIPAA (the US Health Insurance Portability and Accountability Act, which governs patient data), HITECH, and PCI DSS 4.0 (Payment Card Industry Data Security Standard, the rules for handling cardholder data) in place. The HIPAA Business Associate Agreement (BAA) is available for infrastructure that handles electronic Protected Health Information (ePHI). Infrastructure compliance is the customer’s floor, not the ceiling. Their application, access controls, and operational processes still matter, but they start from a data center that has already passed the audit.

For MSPs, the heavy lifting on the audit packet (data center SOC 2, BAA language, encryption at rest, access logging, 24/7 SOC monitoring) is already in place on day one.

## Peering That Makes Both VPN Workarounds Disappear

Atlantic.Net peers aggressively in Ashburn, Dallas, and New York, with low-latency reach to both US coasts. A well-performing location eliminates the need for a VPN relay to fix site-to-site connectivity and for a third-party remote-access VPN to fix end-user connectivity. Both workarounds tend to disappear on day one of the migration.

## Questions Every Hyperconverged RFQ Asks

The same ten questions surface in every hyperconverged RFQ. Short, practical answers:

1. **Can boot and OS drives be separated from Ceph OSD drives, with OSDs passed through as JBOD?** They should be. OSD HBAs want to ship in IT mode, with no hardware RAID on OSDs, so Ceph sees every drive natively and can act the moment one starts to fail.
2. **What NICs are available for the 25 Gbps private Ceph network?** Mellanox ConnectX-5, Mellanox ConnectX-6, and Intel E810 are the common options.
3. **Is self-service VLAN creation available without NOC tickets?** Portal- and API-driven self-service is the expected baseline. Ten or more VLANs at launch is normal for a multi-tenant MSP stack.
4. **What is the hardware replacement SLA?** 4-hour replacement for failed drives and nodes, including parts and labor, is the benchmark for dedicated server providers at this tier.
5. **Is there a discount for a 12-month commitment?** Longer billing terms typically carry a standard discount against month-to-month pricing.
6. **What is the lead time for seven servers?** Weeks, not months. Firm dates belong in the quote.
7. **Can the NAS chassis take 12 or more 3.5-inch HDD bays plus NVMe slots in the same box?** Storage-dense chassis that take both form factors are standard enterprise hardware.
8. **Does IPMI support remote ISO mount for customer-installed operating systems?** No OS should be preloaded when the customer plans to install Proxmox VE 9.1.5 and OPNsense Business themselves. Customers opting for managed FortiGate FaaS avoid the install step at the firewall layer entirely.
9. **Can a /26 subnet be routed to specific firewall interfaces?** Yes. Public IPs should bind only to the firewall appliances, not to every server.
10. **Is the BGP announcement of the customer IP space supported?** A BGP announcement needs a Letter of Authorization for the prefixes being originated and a peering relationship with the upstream, and should be part of the scoping call.

## Hyperconverged Does Not Have to Be Hard

Hyperconverged Proxmox and Ceph are technically dense, operationally unforgiving on the network side, and expensive to get wrong. The thing MSPs actually want from a hosting provider is the removal of the parts that should not have been their problem to begin with: hardware compatibility, data center compliance, peering quality, VLAN control, and, for some customers, firewall operations.

Atlantic.Net runs HIPAA-compliant, SOC 2 Type II audited dedicated servers out of well-peered US data centers, with BAAs available, 24/7 US-based support, and FortiGate Firewall as a Service available for customers that prefer a managed edge. Every hyperconverged build is scoped and quoted as a customized solution rather than a fixed catalog SKU, which is what a seven-server RFQ needs by the time it hits the rack.

If your next cluster build looks anything like the RFQ above, we would rather have the conversation than the excuse. Request a dedicated server quote or reach our US-based team 24/7/365.


---

# From Remote Clinic Request to HIPAA Virtual Desktop Plan

> URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-virtual-desktops-remote-clinics/ | Published: 2026-04-30 | Author: Richard Bailey

Not every HIPAA hosting inquiry is about servers; sometimes it is about people. This request came from a medical clinic with eleven remote employees. The team needed a HIPAA-compliant virtual desktop solution that would give staff centralized access to RingCentral, Google Workspace, and ICA Notes.

The employees were located in the United States and Costa Rica. The clinic wanted secure access, U.S.-based connectivity, encrypted storage, and a simple way to disable access quickly when an employee leaves. Here, the customer was not asking us to host a custom application; instead, they needed a controlled workspace where remote staff could do their jobs securely.

In this article, we will discuss another Request For Quote (RFQ) we recently received from a potential new customer, explain how one email request turned into a bespoke HIPAA Hosting solution, and onboard a new customer with Atlantic.Net.

## The Customer’s Main Concern

The customer knew exactly what they needed before reaching out to our pre-sale team. The clinic’s priorities were clear:

- Compliance
- Security
- Ease of management
- U.S.-based access
- Fast user offboarding

Those are the right priorities for a remote healthcare team, especially when users are working from different locations. The risk is not only where the application runs, but also where the work happens. Are files being downloaded to local devices? Are users connecting from unmanaged networks? Can access be removed quickly? Does the clinic know where sensitive work is taking place?

A HIPAA-compliant virtual desktop can help by providing users with a central, controlled environment to work from, rather than relying solely on local endpoints.

## The Virtual Desktop Environment

The proposed direction was to deploy a virtual desktop for 11 users in U.S. data centers. The U.S. location was essential because some of the customer employees were located outside the United States. The clinic wanted connections to the compliance infrastructure to be exclusively from U.S. IP addresses, so the hosted desktop environment had to provide customers with a U.S.-based access point.

From the user’s perspective, the model is straightforward:

- The employee connects securely to the virtual desktop.
- The work is done within the hosted environment.
- Approved applications are accessed from the desktop.
- Sensitive files that must remain inside the HIPAA environment stay there.
- The clinic manages user access centrally.

This is one of the core values of using a virtual desktop model. It provides a distributed team with a more controlled environment in which to work.

## Application Ownership

The clinic needed access to numerous shared applications, including RingCentral, Google Workspace, and ICA Notes. They also confirmed that they wanted to manage those applications themselves. Application management is an important scope detail to understand.

Atlantic.Net’s role would be to provide the HIPAA-compliant virtual desktop environment and the service’s included hosting controls. The clinic would remain responsible for the applications, including installation, updates, licensing, configuration, and day-to-day administration.

This was a great match, and it keeps responsibilities clear.

- If RingCentral needs an update, the clinic owns that.
- If Google Workspace permissions need to change, the clinic is responsible for making those changes.
- If ICA Notes needs configuration, the clinic is responsible for it.
- If a desktop user needed access provisioned or removed, that belongs in the virtual desktop access process.

A good virtual desktop deployment depends on having this kind of clarity before the service is built.

## Storage Requirements

The clinic did not need a large storage footprint. Most documentation lived in Google Workspace, so the virtual desktops only needed enough encrypted storage for system operations, application installs, and any sensitive files that needed to remain inside the HIPAA-compliant desktop environment.

Some clinics need heavy file storage in the desktop environment. Others mainly need a secure workspace for SaaS applications and only a modest amount of encrypted desktop storage.

This clinic did not need a large archive; instead, they opted for protected workspace storage that suited how their users worked.

## User Access and Offboarding

The clinic specifically wanted the ability to disable access quickly when an employee leaves. Not only is this essential for HIPAA-Compliance, but it’s also one of the strongest reasons to consider a virtual desktop model.

In a remote team, offboarding can become messy if users have worked from personal devices, saved files locally, or accessed systems from unmanaged environments. A hosted desktop provides the clinic with a central place to revoke access to the work environment.

There is one important caveat: application access must still be managed separately. Deactivating the virtual desktop account prevents the user from entering that hosted workspace. But if the same user also has separate accounts for Google Workspace, RingCentral, or ICA Notes, those accounts must be disabled through the clinic’s application management process.

We advised the customer that this should be part of the clinic’s offboarding checklist and suggested that the virtual desktop provides the clinic with a stronger control point. It does not replace every application’s user management, but it simplifies the process.

## Support and Scalability

The clinic also asked about setup, support, and scalability. For an eleven-user deployment, the quote needed to cover the current user count, U.S. deployment, encrypted access, encrypted storage needs, and the support model.

Scalability had to be handled practically because the clinic should know how additional users would be added later, how pricing changes as the team grows, and whether additional storage or applications would require a revised scope.

For a clinic, this matters because user count can change quickly. New hires, contractors, part-time staff, and offshore support roles may all need access at different times. The deployment should make the first 11 users easy to support without complicating future expansion.

## What Needs to Be Confirmed Before the Quote

As with every RFQ, we work with the client to create a suitable, often bespoke solution to meet their needs from Day 1. Before finalizing any quotation, we had to confirm:

- How many users need access on day one?
- Will all users need the same desktop configuration?
- Which U.S. data center location is preferred or required?
- How much encrypted storage is needed per user?
- Will users connect from managed or unmanaged devices?
- Who at the clinic can approve new users?
- Who can request user removal?
- Will the clinic install and manage all applications itself?
- Are any files expected to be stored locally inside the desktop environment?
- Are there any application licensing requirements that affect deployment?

These questions keep the quote grounded and help Atlantic.Net understand how the clinic actually worked.

## From Request to Virtual Desktop Plan

The customer initially asked for pricing; the real pre-sales conversation was about workflow. Our engineers needed to know: Who are the users? Where are they located? What applications do they need? Where should the work happen? How much storage is required?

Who manages the applications? How is access removed when someone leaves? How does the clinic add users later?

Once those answers were made clear, the virtual desktop quote became much easier to build. For this clinic, the right plan was a secure, U.S.-hosted virtual desktop workspace for eleven remote users, with encrypted access, modest encrypted storage, clinic-managed applications, and a clear process for user access.

That is how a remote-work inquiry becomes a HIPAA-compliant desktop deployment plan. Need a secure virtual desktop environment for remote healthcare staff? [Contact Atlantic.Net](https://www.atlantic.net/about-us/corporate-contact/) to discuss HIPAA-compliant virtual desktop hosting, encrypted access, user management, and scalable support.


---

# From PostgreSQL Question to HIPAA SaaS Launch Plan

> URL: https://www.atlantic.net/hipaa-compliant-hosting/postgresql-hipaa-saas-launch-plan/ | Published: 2026-04-30 | Author: Richard Bailey

Today, we are going to take another look at a recent Request for Quote that came in to our pre-sales team here at Atlantic.Net. Many HIPAA hosting conversations start with a broad question: “Do you support healthcare workloads?” This one started in a much more useful place.

The customer was launching an online service for mental health professionals. They were building the application from the ground up for HIPAA compliance and already knew one important part of the stack: they needed PostgreSQL 16 or newer with JSONB support.

Customers who know exactly what they need are really helpful early on in the pre-sales conversation. It tells us the customer has moved beyond the idea stage and they are not simply asking for “HIPAA hosting.” They want to know whether a specific application architecture can be launched, supported, backed up, and covered under a HIPAA Business Associate Agreement (BAA) before electronic protected health information, or ePHI, enters the environment.

Alongside PostgreSQL, they needed a hardened Linux instance and wanted automated backups. They needed to confirm that the database would be covered under the BAA. The customers wanted to start small and leave plenty of room to scale nationally if the platform gained the traction they were expecting.

This was an RFQ to be involved in. Join us in the article as we explain how the initial conversations grew into a HIPAA-compliant platform for one of our fantastic customers. Starting with a small environment, making sure the compliance foundation was correct, then expanding once the product and usage justified it.

## Do You Offer PostgreSQL Support?

Despite being a hugely popular Database platform, you would be surprised how few managed hosting providers support it. Our customer required PostgreSQL 16 or newer with JSONB support for a HIPAA-compliant application. They also asked whether our managed services team could support installation and automated backups on a hardened Linux instance.

That question sounds simple, but it has three separate parts.

- PostgreSQL installation was supported.
- The application-specific database was outside the standard support scope.
- Backups would follow the existing HIPAA hosting backup offering.

Installing PostgreSQL is an infrastructure task. A long-term database is much more application-specific. Query tuning, index design, connection pooling, vacuum strategy, partitioning, schema decisions, and performance troubleshooting all depend on how the application is built and how users interact with it over time.

The customer was delighted that Atlantic.Net could support the PostgreSQL installation, with the customer’s application team remaining responsible for the application-level database. The database itself would sit inside the HIPAA-Compliant hosting environment and follow the same backup schedule as the rest of the system.

## What Are We Really Scoping?

On paper, this may seem like ‘just’ a PostgreSQL request. In practice, we were scoping the first production environment for a new healthcare SaaS platform. That meant PostgreSQL was only one piece of the plan. The customer also needed a hardened Linux instance, HIPAA-compliant hosting, a signed BAA, daily backups, encrypted backup storage, a realistic deployment window, and a clean upgrade path if the application outgrew the entry package.

These are the RFQ details that make a hosting environment usable in production. A database engine alone does not make a healthcare platform ready to launch. The goal was not to overbuild the first environment. The goal was to build the first environment on the right foundation, with enough structure to support compliance, security, recovery, and future growth.

## Is a Signed BAA Available?

The BAA came up early, as it should, and the customer needed to know whether PostgreSQL would be covered under the BAA. We provided Atlantic.Net’s standard BAA for review and confirmed that changes to the document could not be considered.

That can sometimes feel restrictive from the customer side, but it is an important part of a standardized HIPAA hosting service. The BAA needs to align with the service being delivered, the controls in place, and the responsibilities Atlantic.Net can support consistently.

The sequence is straightforward:

- The customer reviews the BAA.
- The agreement is signed.
- The environment is provisioned.
- ePHI is introduced only after the proper agreement and controls are in place.

That was the right path for this customer as well.

## Do you Offer Backup and Recovery?

Once the BAA position was clear, the customer asked the next practical question: Would the PostgreSQL database be on the same backup schedule as the rest of the system? In a SaaS application, the database is usually the most important recovery point. Application code can often be redeployed onto an immutable instance, and servers can be rebuilt, and configuration can be restored. But the database contains the live operational record.

We confirmed that the environment would follow the same daily backup schedule, including the PostgreSQL database. For this launch scope, the backup offering included local and off-site fully managed daily cloud backups stored on separate storage devices, with encrypted-at-rest storage. There was no separate PostgreSQL backup schedule to manage at launch. The database would be included in the same daily backup cadence as the rest of the environment.

If the customer later needed a tighter recovery point objective, that would become a separate architecture discussion. More frequent database-level backups, replication, or a more formal disaster recovery design could be considered as the platform matures. For the initial launch, daily backups answered the requirement.

## What About Scalability?

The next question was just as practical: How hard would it be to upgrade from the entry package to a larger hosting package once the application started to hit performance limits? This was another good question to ask before launch, not after the customer is already under pressure.

The answer was that an upgrade would require a signed addendum aligned with the terms of the initial agreement. Once signed, the upgrade would typically take two or three days, giving the customer realistic expectations.

Scaling is available, but it would be handled as a documented service change. In a HIPAA hosting environment, that is the right approach. Resource changes, contract terms, support expectations, and service scope must all stay aligned.

For a startup, this means they can start in an entry-level environment without feeling locked in permanently. They can launch responsibly, watch real usage, and upgrade when the application justifies the additional resources.

## The Deployment Timeline

The initial deployment could take up to five days from receipt of the signed agreement. A window that gives the team time to process the agreement, prepare the environment, apply the required controls, configure backups, and coordinate the handoff.

For the customer, this answered the final planning question. They knew what needed to be signed, what would be installed, what would be backed up, what was outside standard support, and how long the first deployment could take. Having this level of clarity is key before any healthcare SaaS platform goes live.

## What the Customer Needed to Know

The first email was about PostgreSQL, but the real conversation was about a startup’s launch readiness. By the end of the exchange, the customer had clear answers:

- PostgreSQL installation could be supported.
- PostgreSQL was outside the scope of standard support.
- The database would follow the same daily backup schedule as the rest of the environment.
- Atlantic.Net’s standard BAA would be provided for review and signature.
- Changes to the BAA could not be considered.
- Initial deployment could take up to five days after the signed agreement is received.
- Upgrades would require a signed addendum and typically take two or three days after signature.
- Support would be U.S.-based and available 24x7x365 by phone or ticket.

That is how a good HIPAA pre-sales conversation should work. The customer came in asking whether PostgreSQL could run in a HIPAA hosting environment. We walked through the database, the BAA, the backup cadence, the support boundary, the upgrade path, and the deployment timeline. By the end, we were ready to sign and build.

Ready to launch a HIPAA-compliant SaaS environment with PostgreSQL support? [Contact Atlantic.Net to discuss your hosting requirements](https://www.atlantic.net/about-us/corporate-contact/), BAA needs, backup expectations, and upgrade path.

 


---

# Moving Away From Rackspace: Why Legacy Windows Workloads Don’t Always Lift-and-Shift

> URL: https://www.atlantic.net/cloud-platform/legacy-windows-migration/ | Published: 2026-04-30 | Updated: 2026-05-03 | Author: Richard Bailey

Some Rackspace customers start looking for a new hosting provider for many reasons. Rising costs, contract pressure, or product-fit concerns could be reasons behind shopping for other providers.

For standard workloads, migrating is usually a manageable project. Legacy environments are different. When a business depends on older systems that still need to run as they do today, moving away from Rackspace can become more complicated, especially if modernization is planned for later rather than as part of the initial move.

That was the situation for one such customer who recently contacted Atlantic.Net. They needed to [move off Rackspace](http://docs.rackspace.com), but the immediate priority was not redesigning the platform; it was keeping the platform running as is with minimal disruption while creating space for future upgrades on a more realistic timeline.

This is a common issue for organizations still running Windows Server 2008 R2, Windows Server 2012 R2, or SQL Server 2008 R2, where operating system and database licensing are bundled into the monthly service.

A true lift-and-shift is rarely as simple as it sounds, and at Atlantic.Net, it is not an option on out-of-support versions of Windows Server. Even so, there is a workable path forward, and it is more achievable than the initial responses from prospective hosts may suggest.

## Why Leaving Rackspace With Legacy Windows Feels Different

These days, most cloud customers do not spend much time thinking about Windows or SQL Server licensing, as those costs are folded into the monthly server bill. Rackspace customers with legacy Windows workloads have operated that way for years, which has shielded many businesses from a difficult industry reality: older Microsoft platforms may still run, but moving them is no longer straightforward once support status, licensing, and provider policy come into play.

That reality usually becomes clear during the first round of migration quotes. A prospective host asks which operating systems and database versions are in use. The customer answers: Windows Server 2008 R2, Windows Server 2012 R2, or SQL Server 2008 R2. At that point, many providers either walk away or insist that upgrades happen before the migration can begin. For customers who expected a simple lift-and-shift, that can make the entire move feel unexpectedly complicated.

The real issue, though, is usually not the destination host. Legacy Microsoft workloads require a migration plan built around compatibility, licensing, and risk, not just infrastructure.

## Why Most Hosts Decline Windows Server 2008 R2 and 2012 R2

The assumption behind a clean lift-and-shift is that any qualified provider can pick up the workload as-is. For legacy Windows, that assumption breaks for a practical reason, not a regulatory one: reputable hosts cannot keep an unpatched operating system secure, and they will not take responsibility for one that cannot be patched.

Microsoft’s own dates make the problem concrete:

- **Windows Server 2008 R2** reached the end of extended support on [14 January 2020](https://learn.microsoft.com/en-us/lifecycle/products/windows-server-2008-r2). Extended Security Updates (ESU) through the general program ended on 10 January 2023, and the Azure-only extension ended on 9 January 2024. No security updates are available for this version anywhere today.
- **Windows Server 2012 R2** reached the end of extended support on [10 October 2023](https://learn.microsoft.com/en-us/lifecycle/products/windows-server-2012-r2). ESU Year 3 is still running as of this writing, covering 15 October 2025 to 13 October 2026, with about six months of coverage left.
- **SQL Server 2008 R2** reached the end of extended support on 9 July 2019. Azure ESU ended in July 2022.

A host that provisions an unpatched OS for a production workload becomes part of a shared responsibility. If a known, unpatched vulnerability compromises that workload, the host is partly accountable for running a platform it could not secure. Most providers, including Atlantic.Net, decline the work for that reason alone. Atlantic.Net’s position is direct: these operating systems are no longer supported, they are end of life, and Atlantic.Net cannot support or install patches for them.

This is a security decision, not a licensing one.

## What SPLA and ESU Actually Allow

A separate claim circulates among customers exploring this situation: that Microsoft’s Services Provider License Agreement (SPLA) forbids hosts from installing legacy Windows or SQL. That claim is not quite right, and it is worth clearing up.

SPLA is the licensing program hosting providers use to rent Microsoft software to customers monthly. [SPLA includes downgrade rights](http://microsoft.com/licensing), which means a provider with a current SPLA agreement can technically deploy older versions for a legitimate reason. Running an out-of-support version under SPLA is not automatically non-compliant from a paperwork perspective.

Windows Server 2012 R2 ESU is specifically eligible for SPLA customers, and a provider willing to run that plumbing could, in principle, keep a customer patched on 2012 R2 through 13 October 2026. A few providers do. Most do not. The reasons come back to operations rather than licensing: an ESU-covered 2012 R2 server still runs an OS that has been out of mainstream support since 2018, still requires specialized patching pipelines, and still becomes unpatched the moment ESU runs out. Atlantic.Net is one of many providers that decline to work on those grounds.

For Windows Server 2008 R2 and SQL Server 2008 R2, the question is simpler. No ESU program exists for either product today. There is no path to keeping them patched at any provider.

## Rackspace’s Own Guidance Points in the Same Direction

Rackspace publishes an end-of-support page that covers exactly this situation. When a Rackspace customer asks Rackspace what to do about Windows Server 2008 or SQL Server 2008, the answer is one of three: migrate to a modern OS on Azure with Rackspace support, stay on the legacy OS in Azure to pick up Extended Security Updates, or migrate to a modern OS in a Rackspace data center. The page calls doing nothing “the option that’s not an option.”

Rackspace is telling its own legacy customers that an upgrade, or a migration paired with an upgrade, is the only responsible path. When a prospective new host says the same thing, it is not being difficult; it is giving the same advice Rackspace would.

## The Realistic Path: In-Line Upgrade, Then Migrate

The honest way to leave Rackspace with a legacy Windows stack is to upgrade the operating system first, then move the workload. At Atlantic.Net, that happens as an in-line upgrade to a supported Windows Server release, scoped and priced as a separate Professional Services engagement before the servers land in a production hosting tier.

The preferred in-line targets are Windows Server 2022 or Windows Server 2025, with Windows Server 2019 accepted where an application dependency makes one of the newer releases impractical. Windows Server 2016 is not a target version; it is close enough to end of life that upgrading to 2016 trades one short runway for another.

Customers often assume that upgrading and migrating together doubles the risk. In practice, it usually reduces it: moving once to a modern stack is simpler than moving once to a legacy stack a new provider reluctantly hosts, then moving again when that platform is deprecated a year later.

A common Rackspace footprint maps directly onto a modern target. A web tier on IIS and ASP.NET moves to Windows Server 2022 with IIS 10; most classic ASP.NET Framework applications run unchanged once the .NET version and application pool settings are matched. A SQL Server 2008 R2 database moves to SQL Server 2019 or 2022, where backward-compatible database engines continue to support the older compatibility level after a backup-and-restore migration. A shared domain controller and utility box are migrated to Windows Server 2022 Standard, and the Active Directory forest and domain functional levels are raised once the last legacy domain controller is decommissioned.

Atlantic.Net’s engineering team can stage the servers on a single dedicated host with Hyper-V or VMware and cut over in a defined window, or run them as separate dedicated servers, depending on license economics and workload profile. For workloads where virtualization is ruled out, bare-metal options are available in Orlando, Florida, and Dallas, Texas.

## What Atlantic.Net Offers For A Rackspace Migration

Atlantic.Net regularly runs the combined in-line upgrade and migration path for Rackspace customers. The work is split into two scopes, priced and signed separately, so the customer knows exactly what the hosting tier covers and what the upgrade engagement covers.

The [in-line upgrade engagement](https://www.atlantic.net/managed-services/migration-services/). Upgrading Windows Server 2008 R2 or 2012 R2 to a supported release is handled by the Atlantic.Net Managed Services team under a [Professional Services Agreement](https://www.atlantic.net/managed-services/consulting/). Scope, effort, and fixed price are set on a case-by-case basis during discovery based on server inventory, application dependencies, and downtime tolerance.

The ongoing hosting tier. Once the upgrade is complete, the workload moves into a standard Atlantic.Net hosting tier:

- **Windows licensing included.** Windows Server 2016, 2019, and 2022 licensing on dedicated bare metal, and Windows Server 2012 through 2025 on the [Atlantic.Net Cloud Platform](https://www.atlantic.net/cloud-hosting/). No bring-your-own-license required.
- [**Dedicated single-tenant hardware**](https://www.atlantic.net/dedicated-server-hosting/) in US data centers, with RAID-10 NVMe storage, KVM for out-of-band recovery, and a triple 100% SLA on network, power, and hardware.
- **Multi-VM on a single host** via Hyper-V, VMware, or Proxmox, where that matches the workload.
- **Migration assistance on the hosting side.** Managed HIPAA customers receive 4 hours of free migration credit toward their server and database moves. Additional move work is billed at $165 per hour (discounted from $195) with a four-hour minimum. This does not cover the in-line OS upgrade, which sits under the Professional Services engagement above.

The split matters. Atlantic.Net provides the hosting foundation and the licensing for supported Windows on it, but does not take on the operational risk of running an unsupported OS in production. Where the stack needs to modernize to cross that line, Managed Services handles the upgrade as its own quoted engagement.

## Questions To Ask Any Host You Are Evaluating

Whether you are talking to Atlantic.Net or to another provider, this short list separates the hosts worth your time from the ones who will make the migration harder than it needs to be:

1. Do you include Windows Server licensing with the service, or do I need to bring my own?
2. What is your policy on hosting Windows Server versions that are past mainstream support? Past extended support?
3. Can you describe the migration assistance included with onboarding, including the hours included, any additional rates, and whether application migration is in scope?
4. If my OS or SQL version needs to be upgraded to meet your hosting policy, would you handle the upgrade under a separate Professional Services engagement, and what would that look like in terms of scope and price?
5. Which data centers are available, and is single-tenant bare-metal an option if needed?

A provider that answers those five questions clearly will not surprise you at week three of the migration.

## Moving Forward

A move away from Rackspace with a legacy Windows stack is not the same project as a typical hosting migration, but it is not the brick wall the first few phone calls can make it feel like. The constraint is real: unsupported operating systems cannot be kept secure, and most providers have a good reason not to try. The path around it is also real and well-trodden. Upgrade the OS to a supported Windows Server release, then move the workload to infrastructure and licensing that will support it for the next five to ten years.

To get a specific configuration and quote, share your server inventory with the [Atlantic.Net solutions team](https://www.atlantic.net/support/). The conversation covers licensing, hardware, migration help, and the timeline, adds the in-line upgrade engagement when pre-2016 Windows is involved, and ends with a fixed monthly price for infrastructure that won’t ask you to move again.


---

# Managed Drupal Hosting for High-Traffic Sites: What a Migration Actually Needs

> URL: https://www.atlantic.net/managed-services/managed-drupal-hosting-high-traffic-sites/ | Published: 2026-04-30 | Author: Richard Bailey

A high-traffic Drupal site can run reliably for years on the same hosting platform, right up until the platform no longer fits. We see this often with established sites that have grown well beyond a basic VPS or shared hosting environment but do not want to take server management in-house.

One recent example was a Drupal site attracting two to three million unique visitors a month. It had been hosted with the same provider for nearly two decades, but that provider was winding down its bare-metal offering in favor of VPS. The customer did not want to manage the infrastructure themselves. They needed a managed hosting partner that understood Drupal, could protect years of email-sending reputation, and could run the migration without disrupting the business.

The obvious parts of a migration — copying files, moving the database, updating DNS — are rarely the hard parts. The problems usually appear later, when traffic spikes, cache layers are incomplete, or email deliverability drops after the sending environment changes.

For a high-traffic Drupal migration, three areas matter most: realistic hardware sizing, a Drupal-aware caching stack, and a proper email deliverability plan.

## Why Drupal Migrations Are Different

A small WordPress, Joomla, or brochure-site migration can often move cleanly onto a standard LAMP stack. The site is copied across, a caching plugin is enabled, DNS is updated, and the migration is complete.

High-traffic Drupal sites are different.

Drupal performs best when several layers work together. Internal Page Cache and Page Cache reduce application work. Render caching helps avoid repeated processing. CSS and JavaScript aggregation reduce front-end overhead. Redis, Varnish, PHP OPcache, and a properly configured web tier then keep repeated requests away from PHP and the database wherever possible.

When those layers are aligned, Drupal can handle large volumes of traffic efficiently. When one layer is missing or poorly configured, PHP and the database start doing work that should have been handled earlier in the request path.

That is where generic hosting often falls short. A larger server with default templates is not the same as a Drupal-ready environment. The issue may not show up on launch day. It often appears during the first major traffic spike, when uncached requests hit the database, and the stack runs out of headroom faster than expected.

A managed Drupal platform should be prepared for this before the first file is moved.

## The Hardware Reality for 2M+ Monthly Visitors

Early migration briefs often underestimate the hardware needed for a busy Drupal site. A developer may specify 8 GB of RAM, 4 CPU cores, and SSD storage. That might work for a smaller site, but it is usually too light for a Drupal site serving two million or more unique visitors per month.

The monthly average is not the real problem. Peak traffic is.

During busy periods, cache misses can arrive together. Authenticated users may bypass the ‘easiest cache wins’ rule. AJAX requests can stack up. Crawlers may arrive at the worst time. If the infrastructure has little spare capacity, PHP workers and the database can quickly become bottlenecks.

For sites at this level, dedicated infrastructure with proper headroom is usually the safer starting point. That often means 32 to 64 GB of RAM, modern multi-core CPUs, and fast NVMe storage for database and cache-heavy workloads.

The extra cost is small compared with the cost of an outage during a campaign, launch, or seasonal traffic surge. A managed Drupal host should be willing to have that conversation early, rather than simply quoting the smallest possible server.

## The Drupal Caching Stack That Matters

Performance does not come from enabling one cache and hoping for the best. It comes from reducing work at every layer.

At the front of the stack, Nginx can serve static assets efficiently, handle modern TLS and HTTP/2 configurations, and pass requests to PHP-FPM. In front of Drupal, Varnish can absorb a large share of anonymous traffic before those requests ever reach PHP.

For Varnish to work properly with Drupal, cache invalidation needs to be tied back to Drupal’s cache tags, often through the Purge module. Without that, teams either cache too cautiously or risk serving stale content.

Redis is commonly used for Drupal’s cache bins, keeping render cache, Page Cache, and other high-churn cache activity out of the database. That allows MySQL or MariaDB to focus on the data work that only the database can perform.

The application layer should run on a supported PHP 8.x release with OPcache enabled and tuned appropriately. The exact PHP version should match Drupal core support, module compatibility, and the hosting provider’s supported stack.

The database layer also matters. MariaDB 10.6+ or MySQL 8.0 should be configured to align with Drupal’s query patterns, with a healthy InnoDB buffer pool and slow-query logging enabled during migration and early tuning. This gives the team visibility into performance issues before they become outages.

A complete Drupal hosting environment should also include the tools teams expect to use: Composer, Drush, Git, and Node.js with npm, as needed for front-end builds. If cPanel/WHM is part of the customer’s existing workflow for email, databases, or domain management, the operating system choice may also need to align with cPanel’s support for managed environments.

The goal is simple: Drupal should not be forced to run on a generic stack. The hosting platform should be built around how Drupal actually behaves under load.

## Protecting Email Deliverability During the Migration

Email is one of the easiest parts of a migration to under-plan.

A site that has been running on the same provider for many years may have a mature email setup. SPF records may be carefully built. DKIM may be configured for multiple sending domains. DMARC may have been tightened over time to p=reject. Marketing platforms, transactional email tools, and website-generated mail may all rely on specific DNS records and sending infrastructure.

That reputation can be damaged quickly if the sending IP changes and the DNS cutover is handled casually.

Email deliverability should be treated as its own migration workstream. The plan should include:

Inventory every sender. List every service and subdomain that sends mail for the site’s domain. This includes the website itself, marketing platforms, transactional email services, CRM tools, and any legacy systems still sending messages.

Rebuild SPF carefully. The new sending infrastructure needs to be added to the SPF record before production traffic moves. The old provider’s records should be removed only after the cutover is confirmed.

Stage DKIM before cutover. DKIM signing should be configured and tested on the new environment before the old environment is retired. Low-volume test messages can reveal DNS or key-path issues early.

Watch DMARC during the move. A strict DMARC policy can block legitimate mail if alignment breaks during migration. The cutover plan should include monitoring DMARC aggregate reports and tightening policy only once mail is flowing cleanly.

Preserve BIMI alignment where used. If the domain uses BIMI, the DMARC policy, SVG logo, and certificate alignment need to remain intact. The migration should not accidentally break brand indicators that were already working.

Warm the new sending IP if needed. A cold IP should not receive full production email volume on day one. If the sending IP changes, the volume should ramp gradually over 1 to 2 weeks.

If SPF, DKIM, DMARC, BIMI, and sending-IP reputation are not discussed during the hosting conversation, assume email deliverability has not been properly scoped.

## What Fully Managed Drupal Hosting Should Include

For a high-traffic Drupal site, “fully managed” should mean more than server provisioning. It should mean the provider is responsible for the infrastructure foundation on which the site depends every day.

At a minimum, a managed Drupal hosting service should include:

- A Drupal-ready stack with Nginx, Varnish, Redis, PHP-FPM, and OPcache configured properly.
- Operating system patching, security updates, and baseline hardening.
- Firewall management and brute-force protection for Drupal login and admin paths.
- Off-server backups covering the web root, uploaded files, private files, configuration exports, and database snapshots.
- Periodic restore testing, not just backup creation.
- 24/7 monitoring that detects downtime before the customer has to report it.
- Migration assistance that covers DNS, cutover planning, and email deliverability.
- Clear response commitments for business hours and out-of-hours support.

It is also important to separate infrastructure management from application support.

Drupal module debugging, custom-theme work, database index tuning, query, replication design, web application firewall tuning, vulnerability scanning, and intrusion detection may all be available, but they are often separate professional services.

A good proposal makes this clear. It shows what is included, what is optional, and what can be added later if the site needs deeper support.

## How Atlantic.Net Approaches a High-Traffic Drupal Migration

Atlantic.Net helps customers move high-traffic Drupal workloads onto dedicated bare-metal servers or the Atlantic.Net Cloud Platform. The first stage is usually a practical discovery conversation to understand the current environment, the traffic profile, and the operational risks associated with the move.

Typical questions include:

- What Drupal core version is the site running?
- Which contributed and custom modules are in use?
- What are the current traffic patterns, including authenticated-user activity?
- What is the current caching stack?
- Is Varnish already in use?
- Are Drupal cache bins stored in Redis?
- How large is the database working set?
- What does peak traffic look like?
- Which systems send email for the domain?
- What SPF, DKIM, DMARC, BIMI, and sending-IP dependencies exist today?
- Which DNS records and third-party services must be rehearsed before cutover?

From there, Atlantic.Net can scope a hardware configuration, a managed-services package, a backup plan, and a fixed monthly cost.

For a Drupal site in the two-million-unique-visitors range, a typical starting point may be a dedicated server with 64 GB of RAM, 12 to 16 CPU cores, and RAID-10 NVMe storage. The final design depends on the site’s cache hit rate, database size, authenticated traffic, file storage, and operational requirements.

The stack is built for Drupal rather than a generic LAMP template. Backups are stored off-server, with retention shaped around the customer’s content update pattern and recovery needs. Atlantic.Net’s 24/7 engineers handle infrastructure monitoring, patching, escalation, and operational response. Deeper Drupal application tuning or database can be scoped separately, where required.

The migration itself should be staged. A full build is created on the new infrastructure, followed by testing, traffic rehearsal, email deliverability checks, and a planned production cutover. The old environment remains available until the new platform is confirmed stable.

## Moving Forward

A high-traffic Drupal migration is not a file copy. It is an infrastructure project with several moving parts that need to be planned before cutover night.

The most successful migrations start with honest hardware sizing, a Drupal-tuned stack, and an email deliverability plan that treats SPF, DKIM, DMARC, BIMI, and sending-IP reputation as production systems.

A hosting partner that asks about these areas early is usually the partner most likely to run the migration cleanly.

To scope a specific Drupal migration, share the current stack, traffic profile, caching setup, and email-sending footprint with the Atlantic.Net solutions team. The conversation may start with server sizing, but the real value is in building a runbook that protects performance, uptime, and deliverability throughout the move.


---

# Object Storage Vs. Block Storage – What’s the Difference?

> URL: https://www.atlantic.net/cloud-platform/object-storage-vs-block-storage/ | Published: 2026-04-30 | Updated: 2026-04-28 | Author: Dr. Assad Abbas

Data volumes have increased significantly in recent years, introducing new challenges in selecting and managing storage systems. This growth directly influences decisions on [object](https://aws.amazon.com/what-is/object-storage/)and [block storage](https://www.atlantic.net/vps-hosting/what-is-block-storage/), as organizations must handle data from sources such as AI systems, healthcare platforms, connected devices, and everyday business applications. As a result, storage is no longer a minor technical detail but a key factor in system performance and stability.

With this increase in data scale, storage decisions have become far more important throughout the system lifecycle. The choice of storage model directly affects performance, cost, and long-term scalability. Even small mismatches in the early design may surface later in real-world use. If the selected storage model is not well aligned from the beginning, issues can gradually emerge over time. For example, systems may start to respond more slowly, and operational costs can rise in ways that are harder to anticipate or control. Once the system is in production, resolving these problems is often far more difficult than initially expected.

Along with these performance and cost concerns, many industries also operate under strict data regulations. Healthcare is a clear example of a sector where sensitive information, such as electronic health records, must be protected and properly managed. Because of this requirement, storage design needs to balance both performance needs and compliance rules when comparing object storage with block storage.

In this context, modern cloud environments commonly rely on three main storage models, namely object storage, block storage, and file storage. Among these, object storage and block storage receive more attention because they serve very different workload needs. Therefore, understanding their differences helps organizations make better and more informed decisions.

## Understanding Object Storage: Architecture, Metadata, and Access Patterns

Object storage follows a different approach compared to traditional storage models. Instead of dividing data into files or blocks, it stores data as complete objects. Each object contains the data itself, along with system metadata, user-defined metadata, and a unique identifier. Therefore, all related information remains bundled, improving data organization.

In addition to this structure, object storage uses a flat and distributed architecture. There is no folder hierarchy as found in traditional file systems. Instead, all objects exist within a single namespace that spans multiple systems. This design allows object storage to scale to very large sizes without increasing structural costs, making it suitable for large datasets such as images, logs, backups, and media files. This helps organizations classify and manage data more effectively over time.

Metadata plays a key role in object storage. Each object can include rich metadata in key-value form. This additional information improves searchability and supports indexing and automation. For example, in regulated environments such as healthcare, data can be tagged for compliance tracking and auditing purposes. Organizations can classify and manage their data more effectively over time.

In addition to its structure and metadata capabilities, object storage’s access model differs. Data is accessed via RESTful APIs over HTTP or HTTPS, rather than through traditional file system methods. S3-compatible APIs are also widely used in cloud environments. This makes it more straightforward with modern applications and distributed systems.

These architectural and operational characteristics together make object storage suitable for large-scale, unstructured data workloads. As a result, many cloud platforms, such as [Amazon S3](https://aws.amazon.com/pm/serv-s3/), [Azure Blob Storage](https://azure.microsoft.com/en-us/products/storage/blobs), [Google Cloud Storage](https://cloud.google.com/storage), and [Atlantic.Net](https://www.atlantic.net/cloud-platform/block-storage/) Object Storage, provide object storage services.

## Block Storage Design and Performance Characteristics

Block storage follows a traditional storage approach. In contrast to object storage, it divides data into fixed-size blocks, each stored separately with a unique identifier. This structure allows data to be written and retrieved in smaller parts, providing precise control at the system level.

This structure affects system behavior directly. From the operating system perspective, block storage appears as a raw storage volume. A file system such as NTFS, ext4, or XFS must be created before use. After this layer is added, the system combines blocks into complete files, giving applications greater control over data organization and access.

This control contributes to one of block storage’s main strengths: performance. It delivers low latency and high input/output operations. This makes it suitable for applications that require fast and stable responses. For this reason, block storage is commonly used in databases, virtual machines, and enterprise systems.

This performance focus affects metadata handling. Block storage does not store detailed metadata at the block level. Instead, metadata is managed by the file system or the application layer. As a result, data classification and search remain limited compared to object storage.

Since block storage focuses strongly on performance rather than metadata handling, scaling also needs careful planning. Capacity can be increased by expanding volumes or selecting higher-performance tiers. In some cases, multiple volumes are combined using methods such as RAID or striping, which helps meet performance and capacity needs. These approaches also introduce additional operational.

This balance between performance and operational effort makes block storage suitable for structured, performance-sensitive workloads, such as SQL and NoSQL databases, virtual machine disks, boot volumes, and other business-critical systems.

## File Storage Role in Object and Block Storage Comparison

File storage is often used as a reference point when comparing object storage and block storage. It follows a traditional model where data is organized in a hierarchy of files and folders. Because of this structure, it is widely used in standard computing environments and remains familiar to most users.

Between object storage and block storage, file storage falls. It offers simple usability and shared access, making it suitable for everyday collaboration and general-purpose use. It does not scale like object storage or deliver the same performance as block storage, so it is not suited for large-scale systems or performance-heavy workloads.

Due to these limitations, file storage is mainly used in shared environments where ease of use is more important than scalability or speed. For example, team-based file sharing often relies on this model. Many legacy applications also rely on file storage because they are built around traditional file systems.

In practical environments, file storage is implemented through network-attached storage using protocols such as NFS and SMB. Cloud providers also offer managed services such as Amazon EFS, Azure Files, and Google Filestore. File storage remains relevant where shared access and simplicity matter more than high performance or large-scale scalability.

## Key Architectural Differences Between Object Storage and Block Storage

The differences between object storage and block storage become clear when examined across their core design areas. These differences are explained below.

### Scalability and Data Structure

Object storage uses a flat structure in which each data object has a unique identifier. This design supports horizontal scaling across distributed systems. It can store very large datasets without relying on a fixed hierarchy.

In comparison, block storage depends on volumes that are expanded or added when needed. It follows a more structured approach, which works well in controlled environments but requires planning for growth.

### Performance and Data Handling

Building on differences in structure, performance behavior also varies between the two models. Block storage is designed for low latency and high IOPS. It splits data into fixed-size blocks, which can be updated independently. Therefore, it is suitable for databases, virtual machines, and transactional systems.

On the other hand, object storage focuses more on throughput than response time. It treats data as complete objects, so updates usually require rewriting the entire object. Because of this, it is better suited for large, unstructured data such as backups, logs, and media files.

### Metadata and Data Management

Beyond performance and structural differences, metadata handling also varies significantly. Object storage supports rich metadata associated with each object. This helps in classification, indexing, and automation. For example, data can be tagged for retention or compliance purposes.

In contrast, block storage provides only minimal metadata at the storage level. The operating system or application layer handles most data organization and structure. Therefore, it offers less flexibility for data classification.

### Access Methods

Beyond differences in metadata, the way data is accessed also distinguishes these two storage types. Object storage is typically accessed through APIs, such as REST or S3-compatible interfaces over HTTP or HTTPS. Because of this, it fits naturally with cloud-native applications and distributed systems.

In contrast, block storage is presented to the operating system as a physical disk. It relies on protocols such as iSCSI or NVMe-oF, enabling direct, low-level access to data.

### Durability and Data Distribution

Finally, looking at data reliability, both models handle durability differently. Object storage distributes data across multiple systems and often uses techniques like replication or erasure coding. This improves durability at scale.

Block storage usually relies on volume-level replication or storage system-level redundancy. It remains reliable but is less widely distributed than object storage.

Table 1: Object Storage vs Block Storage Comparison

| Feature | Object Storage | Block Storage |
| --- | --- | --- |
| Structure | Flat, object-based | Fixed-size blocks, volume-based |
| Scalability | Horizontal, highly scalable | Vertical or volume-based scaling |
| Performance | High throughput, higher latency | Low latency, high IOPS |
| Metadata | Rich, customizable | Minimal, system-managed |
| Access method | API-based (REST, S3) | OS-mounted storage (iSCSI, NVMe-oF) |
| Best suited for | Unstructured data, backups, analytics | Databases, VMs, transactional workloads |
| Durability model | Distributed replication/erasure coding | Volume-level redundancy |

## Use Cases and Storage Selection Framework

Storage choice depends on workload type, data structure, and performance needs. Object storage and block storage are therefore applied in different scenarios based on system behavior and access patterns.

### Object Storage Use Cases

Object storage is used for large and unstructured datasets such as images, videos, logs, and analytics data. This includes backups, archives, and long-term retention where data volume increases over time.

AI and machine learning workflows also depend on object storage. Large training datasets are stored and processed in distributed systems. Compliance-oriented storage is another common use case, including electronic Protected Health Information (ePHI), where tagging and retention rules are required.

### Block Storage Use Cases

Block storage is used for structured and performance-focused workloads. It is commonly used in databases, virtual machines, and transactional applications.

Block storage offers low latency and stable performance, making it suitable for systems that require fast, consistent data access. Because of these capabilities, it is often used in business-critical applications.

### Hybrid Storage Usage

Many systems use both storage types together. Block storage supports active workloads that require high performance, while object storage manages backups, logs, and historical data. This combination balances performance requirements with storage cost.

Table 2: Decision Framework for Object Storage and Block Storage Selection

| Requirement / Workload Need | Storage Type | Reason |
| --- | --- | --- |
| Low-latency response | Block storage | Provides fast and consistent access |
| Large unstructured data | Object storage | Scales easily for large datasets |
| Strong metadata and search needs | Object storage | Supports rich metadata and indexing |
| Databases and transactional systems | Block storage | Designed for high-performance access |
| Backups and long-term storage | Object storage | Cost-effective at scale |
| Compliance workloads (ePHI) | Both | Depends on active vs archival use |

## Cost Models and Operational Considerations

Cost structure differs between object storage and block storage. In object storage, cost mainly depends on the amount of data stored, how often it is accessed, and the number of requests made. In addition, data transfer and retrieval can increase the cost.

In contrast, block storage follows a different pricing model. Cost is linked to provisioned capacity and selected performance levels, such as IOPS and throughput. Features like snapshots and replication add to the final cost. As a result, spending is more predictable for stable workloads.

Operational effort also varies across both systems. Object storage requires minimal day-to-day management, since most operations are handled via APIs. Meanwhile, block storage requires more manual work, as provisioning, monitoring, and performance tuning are part of regular operations.

Capacity planning also differs between the two models. Object storage can scale as data grows, reducing the need for advanced planning. On the other hand, block storage requires more deliberate preparation, since capacity and performance adjustments must be configured in advance.

Backup and disaster recovery strategies further highlight these differences. Object storage is commonly used for long-term retention and archival data, where durability and scale are the primary concerns. In contrast, block storage is better suited for active workloads that require fast recovery and consistent performance.

## Security and Compliance Requirements

Security plays an important role in both object storage and block storage, particularly in regulated environments. Because of this, healthcare and similar industries must adhere to strict compliance rules, such as HIPAA, which require controlled access to sensitive data and proper governance.

In addition, data protection measures such as encryption are required both at rest and during transmission. At the same time, access control must rely on identity-based policies to ensure only authorized users can reach the data. Furthermore, audit logs are necessary since they help track system activity and support compliance checks.

Both object storage and block storage can meet these security requirements when configured correctly. The difference between them lies in workload suitability rather than security capability.

## How Atlantic.Net Supports Object and Block Storage Needs

[Atlantic.Net](http://www.atlantic.net) supports both object storage and block storage, giving organizations the flexibility to align their storage approach with specific workload needs in modern cloud environments.

For large-scale, unstructured data, Atlantic.Net Object Storage provides a practical solution. It is well-suited for use cases such as backups and archives, and its horizontally scalable design supports environments where data grows over time, while API-based access enables straightforward integration with cloud-native applications and data pipelines.

For performance-sensitive workloads, Atlantic.Net Block Storage offers distinct strengths. It is designed for databases, virtual machine disks, and other business-critical applications that require fast, consistent access. With low latency and high IOPS, it supports workloads that require reliable and predictable read and write performance.

In addition to performance and scalability, security and compliance remain important considerations. For organizations operating in regulated environments, Atlantic.Net provides HIPAA-compliant infrastructure with ePHI support. Both storage options include encryption at rest and encryption in transit using TLS, along with access controls and monitoring features that help meet security and compliance requirements.


---

# How to Reduce Cloud Hosting Infrastructure Costs in 2026: 7 Architectural Tips Every CTO Should Know

> URL: https://www.atlantic.net/cloud-platform/reduce-cloud-hosting-costs/ | Published: 2026-05-01 | Updated: 2026-04-28 | Author: Dr. Assad Abbas

[Cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) costs are rising in 2026. Many organizations are running AI workloads, working with large datasets, and using multiple cloud providers simultaneously. Most business-critical applications now operate in multi-cloud or hybrid cloud environments. They require stronger security, higher availability, and careful control over data movement. Therefore, cloud budgets face steady upward pressure.

Cloud has become a modern system architecture. Most business-critical applications now operate in cloud environments. The way these systems are built directly influences long-term spending. In practice, cloud cost is not merely a billing issue. It is mainly the result of architectural decisions made early in the design process. For example, scaling patterns, data placement, and service communication all influence long-term cost behavior.

Because of this, many teams try to manage spending using discounts or monitoring tools. These approaches improve visibility, but they do not remove inefficiencies already built into the system. FinOps practices also support better tracking and accountability, yet they remain limited when the underlying design is inefficient. As a result, engineering teams influence cost through design decisions, and cost control starts at the design stage rather than after deployment.

This article presents architectural tips that CTOs can use to reduce cloud hosting infrastructure costs. It highlights the impact of migration decisions, pricing models, and daily operations on spending, with a focus on HIPAA-compliant and business-critical workloads.

## What Determines Cloud Hosting Infrastructure Costs

Cloud hosting costs are driven by interconnected components, including compute, storage, network, and managed services. To apply cost strategies effectively, understanding these components is essential.

A portion of cloud spending is associated with compute resources. Oversized or idle instances create avoidable waste and increase cost. Storage costs also increase over time as snapshots, logs, backups, and unused volumes accumulate without regular review, making storage a hidden expense. Network costs are frequently underestimated, as data egress and cross-region traffic can increase monthly spending, particularly for data-intensive workloads. This becomes more critical in distributed architectures where multiple services communicate across regions. In such setups, managed services also contribute to costs. They reduce operational effort, but their use should be justified based on cost and business need.

Since these cost components are interconnected, system design becomes a key factor in spending. Many systems are built for peak demand rather than for average usage, leading to underutilized resources and higher costs. Poor data placement also increases both cost and latency due to higher data transfer needs. In addition, the lack of lifecycle policies and the unnecessary use of managed services increase resource waste. Cloud hosting costs are primarily determined by system design decisions across compute, storage, network, and managed services, rather than by isolated pricing factors alone.

## How Migration Decisions Determine Long-Term Cloud Costs

Migration decisions play a critical role in shaping long-term cloud costs by establishing the initial architecture, resource usage patterns, and pricing commitments that persist after deployment.

One common migration decision is to adopt a lift-and-shift approach, where applications are moved without redesign. This choice preserves existing inefficiencies from on-premise environments and transfers them into the cloud. As a result, systems begin operation with higher compute and storage requirements that remain difficult to reduce later.

Another important decision concerns provisioning during migration. Many teams allocate excess compute and storage resources to reduce risk during transition. While this may support short-term stability, it also establishes a higher baseline level of resource usage. These unused or underutilized resources continue to generate costs even after migration is complete.

Data migration decisions also have a long-term cost impact. When data access patterns and placement are not redesigned, systems generate unnecessary cross-region traffic. Poor data locality increases network traffic and results in recurring data egress charges, especially in distributed environments.

Capacity planning and risk decisions made during migration further influence long-term spending. Conservative planning often includes additional resources and contingency buffers to handle uncertainty. While this reduces migration risk, it also increases initial and ongoing cost exposure.

Pricing model decisions also contribute to long-term cost structure. In this context, pay-as-you-go pricing offers flexibility but can lead to unpredictable spending without governance. Reserved capacity reduces unit cost but becomes inefficient when workload forecasts are inaccurate, as unused capacity continues to incur costs. In contrast, spot pricing offers lower compute costs but requires a fault-tolerant system design; otherwise, instability increases indirect operational costs.

## The 7 Architectural Tips Every CTO Should Know

The following strategies address the main causes of cloud cost inefficiency from a CTO’s perspective. Each one improves resource use, reduces waste, and supports more stable cloud spending over time.

1. ### Design for Autoscaling Instead of Peak Capacity

CTOs must avoid designing for peak traffic, as this approach leads to continuous overprovisioning in cloud environments. In traditional on-premises systems, average utilization typically remains around [12–18%,](https://aws.amazon.com/blogs/aws/cloud-computing-server-utilization-the-environment/) whereas cloud environments can reach nearly 65% when proper scaling strategies are applied. When systems rely on fixed provisioning rather than adaptive scaling, idle compute accumulates continuously, resulting in unnecessary and recurring costs.

#### What to do?

Enable autoscaling based on CPU and memory usage thresholds. Scheduled shutdowns should also be applied to development and testing environments to eliminate unnecessary runtime during idle periods.

#### Why does this work?

Costs align with actual demand rather than peak-based planning. As a result, unused compute resources are significantly reduced, and non-production waste can be eliminated without affecting system reliability.

1. ### Architect Stateless and Ephemeral Workloads

Stateful servers are limited in scalability because they store session data locally. This requires instances to remain active beyond their actual processing needs, leading to continuous, always-on infrastructure costs. Replacing stateful servers introduces operational risk, since session data loss or service interruption can occur during transitions.

#### What to do?

Session state should be externalized to systems such as Redis or a database. In parallel, container-based workloads should be designed to start and terminate on demand, without dependency on persistent server memory.

#### Why does this work?

Compute resources are no longer tied to persistent state. As a result, infrastructure scaling becomes a process of replacing identical stateless units rather than maintaining long-running servers, thereby reducing costs and improving scalability.

1. ### Align Data and Compute to Reduce Network Cost

Cross-region data movement incurs high costs because each gigabyte transferred between regions is billed separately. In many systems, this becomes a hidden expense since data flows increase gradually with scale. Most applications do not require frequent global data duplication, so a large portion of this transfer is unnecessary.

#### What to do?

Databases should be placed near application servers. Read replicas should be introduced only when there is a clear performance or availability requirement.

#### Why does this work?

Reducing the distance between compute and data eliminates most cross-region transfers, significantly lowering egress costs. At the same time, system performance improves due to reduced latency and fewer network hops.

1. ### Implement Tiered Storage and Lifecycle Policies

Storing data in premium storage is inefficient because not all data requires high-performance access. For example, logs or historical records from several months ago rarely need SSD-level speed, yet they continue to incur premium storage costs. Over time, this creates a hidden but steadily growing cost burden.

#### What to do?

- Use hot storage for frequently accessed data (active files, recent logs)
- Move older data to warm storage (backups, secondary data)
- Shift rarely used data to cold storage (long-term backups)
- Archive legal/compliance data to the archive storage

#### Why does this work?

Storage costs decrease significantly for inactive data while ensuring that frequently accessed data remains quickly available. This balance reduces storage spending without affecting system performance or data accessibility.

1. ### Use Managed Services Selectively

Managed services always cost more than self-managed. The provider charges extra for handling backups, scaling, patching, and maintenance. Simple Web servers rarely need this extra layer. Complex databases often make the added cost worthwhile through reduced operational work.

#### What to do?

- Self-manage stable workloads like web servers and simple applications
- Use managed services only for:

- Complex databases (Postgres, MySQL)
- Container orchestration (Kubernetes)
- Caching systems (Redis, Memcached)

#### Why does this work?

Simple workloads get enterprise reliability at lower cost. Engineering teams spend less time on routine maintenance for complex systems, which saves money directly.

1. ### Design for Spot and Interruptible Compute

Spot instances save a0-90% ocompared toon-demand pricing for suitable models. Most batch jobs can pause and resume safely, for example, analytics, ML training, and rendering work well here. Customer-facing systems need stable capacity.

#### What to do?

- Add retry logic and checkpoints to batch jobs
- Run CI/CD pipelines on spot instances
- Use persistent storage (S3/GCS) for job state

#### Why does this work?

Non-critical work runs at much lower cost. Meanwhile, production capacity remains reliable for business-critical systems.

1. ### Implement Caching and CDN Layers

Repeated data access places an unnecessary load on the core infrastructure. For example, frequently accessed pages such as homepages are often generated or fetched from the origin server thousands of times per day. This means each request consumes compute resources and generates network traffic, which can accumulate into high costs at scale. Therefore, CTOs should implement app-layer caching (e.g., Redis), a CDN for static assets, and edge caching for API responses.

#### What to do?

Cache at the app layer with Redis. Use CDN for static assets. In addition, edge-cache API responses.

#### Why does this work?

CDN cache hit ratios of around [95%](https://www.cloudflare.com/learning/cdn/what-is-a-cache-hit-ratio/) reduce origin requests dramatically. Compute, and egress costs drop together.

Table 1: Cloud Cost Map for CTOs

| Area | Key Architectural Decision | Cost Impact |
| --- | --- | --- |
| Compute | Autoscaling instead of fixed capacity | Reduces idle compute cost |
| Compute design | Stateless and ephemeral workloads | Lowers always-on infrastructure cost |
| Data movement | Co-location of compute and storage | Reduces network transfer cost |
| Storage | Tiered storage with lifecycle policies | Reduces the cost of inactive data |
| Service usage | Selective use of managed services | Controls recurring service overhead |
| Compute strategy | Spot and interruptible workloads | Reduces cost for non-critical workloads |
| Delivery layer | Caching and CDN usage | Reduces origin load and network cost |

## Operational, Financial, and Strategic Layers of Cloud Cost Control

While architectural decisions play the main role in cloud cost, operational practices, workload placement, and financial governance also contribute to long-term cost stability. These layers do not replace architecture; instead, they help ensure that design intent is maintained in production environments.

### Operational Practices for Sustained Cost

Architectural decisions define resource usage patterns, and maintaining that alignment over time incurs costs. In production, workloads evolve, usage fluctuates, and inefficiencies accumulate. As a result, operational practices ensure that infrastructure consistently reflects actual demand rather than outdated assumptions.

As systems evolve, resource consumption gradually shifts away from original assumptions. Because of this, regular evaluation of compute, storage, and memory allocations becomes necessary. Without periodic adjustment, excess capacity builds up, increasing costs without delivering proportional value.

At the same time, visibility into resource ownership strengthens cost control. When infrastructure is associated with teams, services, or business functions, spending becomes easier to track and interpret. This clarity improves accountability and supports more consistent decision-making across engineering and financial planning.

Similarly, logging and monitoring require structured management. Logs remain necessary for compliance, auditing, and troubleshooting; their importance declines over time. When all historical data is stored in high-cost systems, unnecessary expenses increase. Therefore, moving older logs to lower-cost tiers preserves required records while keeping storage growth under control.

### Workload Placement Beyond Cloud-First Assumptions

Cloud is not always the most cost-effective environment for every workload. Cost outcomes depend heavily on usage patterns, data movement intensity, and operational requirements.

Systems with stable and predictable workloads may benefit from dedicated or single-tenant infrastructure, where costs remain fixed and easier to forecast. This is particularly relevant for long-running applications with minimal scaling variability.

Applications with high data egress requirements can also experience disproportionate network costs in cloud environments. In such cases, alternative hosting models may offer more balanced cost structures.

Regulated environments, including HIPAA-compliant systems, often require strict isolation, auditability, and performance guarantees. Depending on the architecture, dedicated or hybrid setups may better support both compliance and cost stability.

### Financial Impact of Architectural Decisions

Cloud costs reflect the financial outcomes of architectural choices made across the system. As a result, the total cost of ownership must be considered across compute, storage, network, and operational overhead over time, rather than at isolated billing intervals.

In this context, utilization becomes a key factor. Systems with lower idle capacity, data movement, and controlled service use tend to produce more stable, predictable cost patterns over the long term.

At the same time, cost accountability strengthens this alignment. When resource usage is associated with specific teams or services, spending becomes more transparent. This clarity encourages closer alignment between engineering decisions and financial outcomes.

## Common Architectural Cost Pitfalls

Despite awareness of cloud cost principles, many organizations continue to follow design patterns that lead to long-term inefficiencies. These issues often appear small at first but accumulate steadily over time.

Common pitfalls include:

- Designing for peak demand instead of average usage, which leads to persistent overprovisioning and underutilized resources
- Weak data architecture, where unnecessary data movement increases both network cost and latency
- Excessive use of managed services without clear justification, resulting in avoidable recurring expenses
- Lack of storage lifecycle policies, allowing logs, backups, and unused data to grow unchecked
- Inactive or orphaned resources remaining in use, which silently add to monthly spending

## The Bottom Line

From a CTO’s perspective, cloud cost in 2026 reflects the cumulative effect of decisions made across system design, data handling, and service usage. With expanding environments and more data-intensive, compliance-driven workloads, even small inefficiencies can lead to financial impact over time.

The architectural practices discussed in this article provide a practical direction for reducing unnecessary compute, storage, and network usage. When combined with disciplined operations and careful workload allocation, they help maintain stable, predictable cost behavior as systems grow.


---

# Atlantic.Net Recognized by Business Intelligence Group with 2026 Excellence in Customer Service Award

> URL: https://www.atlantic.net/press-releases/atlantic-net-recognized-by-business-intelligence-group-with-2026-excellence-in-customer-service-award/ | Published: 2026-05-01 | Updated: 2026-06-04 | Author: Editorial Team

ORLANDO, FL (May 1, 2026) – [Atlantic.Net](http://atlantic.net/), a global cloud infrastructure provider, has been named a winner of the [2026 Excellence in Customer Service Awards](http://www.bintelligence.com/posts/2026-excellence-in-customer-service-awards-from-scripts-to-strategy-the-winners-who-proved-that-how-you-treat-people-still-wins) by the Business Intelligence Group (BIG), a global independent awards organization recognizing outstanding achievement across business disciplines. Atlantic.Net earned recognition in the Transformation of the Year category.

The [Excellence in Customer Service Awards](https://www.bintelligence.com/awards/excellence-in-customer-service-awards) honor the companies, products, teams, and individuals delivering measurable, human-centered customer experiences in a rapidly evolving service landscape. This year’s program attracted nominations from organizations across more than 20 industries worldwide and was evaluated by a panel of experienced business executives using objective scoring benchmarks.
 “Atlantic.Net’s 30-year track record of hosting mission-critical workloads for clients in more than 100 countries is the foundation that makes their recognition in Transformation of the Year meaningful. Sustaining that trust while scaling globally across eight data center regions requires a service organization as disciplined as the infrastructure it supports,” said [Russ Fordyce](https://www.linkedin.com/in/russfordyce/), Chief Recognition Officer at the Business Intelligence Group.

[Atlantic.Net](http://atlantic.net/) was recognized by how tightly it has integrated real-time operations, disciplined processes, and customer-facing communication in a 24/7/365 data center environment, without treating support as a “ticket factory.” With a security and observability service mindset, [Atlantic.Net](http://atlantic.net/) also pairs strong operational controls with monitoring and security tooling and clear ownership boundaries.
 “We are constantly evolving our customer service to match our rapid pace of innovation. In the last year, we successfully launched GPU Cloud Hosting and completed a major data center migration – with zero customer-impact events,” said Marty Puranik, founder and CEO of [Atlantic.Net](http://atlantic.net/). “These forward-thinking initiatives have maintained a high level of trust with our customers.”

**About Atlantic.Net**

Founded in 1994,[Atlantic.Net](https://www.atlantic.net/) is a privately held global cloud infrastructure provider with customers in over 100 countries, known for delivering secure, compliant, on-demand and customizable hosting solutions. With decades of experience, Atlantic.Net is one of the world’s most trusted and experienced hosting providers, offering 24/7 U.S.-based support. Specializing in security, compliance, and customer service, Atlantic.Net serves a diverse range of industries with solutions including HIPAA-compliant hosting and PCI-compliant hosting, backed by bare metal servers, dedicated hosting, GPU hosting, colocation, and its award-winning Cloud Platform. Operating from eight strategically located data center regions across the United States, Canada, the United Kingdom, and Asia, Atlantic.Net powers mission-critical workloads for organizations worldwide. For more information, visit[Atlantic.Net](https://www.atlantic.net/) or connect with us on[Facebook](https://www.facebook.com/Atlantic.Net),[X (Twitter)](https://twitter.com/AtlanticNet),[LinkedIn](https://www.linkedin.com/company/atlantic.net-inc./posts/?feedView=all), and[YouTube](https://www.youtube.com/c/AtlanticNet).
 **About the Excellence in Customer Service Awards**

The [Excellence in Customer Service Awards](https://www.bintelligence.com/awards/excellence-in-customer-service-awards) recognize the companies, teams, and individuals who set the standard for what customer service can deliver when it is resourced, led, and measured with intention. Established by the Business Intelligence Group, the program evaluates performance across award categories including Organization of the Year, Transformation of the Year, Technology of the Year, Team of the Year, Outsource Partner of the Year, Manager of the Year, Front-Line Pro of the Year, and Executive of the Year – spanning every major industry segment and organizational size. Judged by experienced business executives who provide detailed scoring and transparent feedback, the awards honor those who demonstrate that exceptional customer service is a measurable, repeatable, and commercially significant discipline.

**About Business Intelligence Group**

[Business Intelligence Group](https://www.bintelligence.com/) (BIG) is an independent awards organization that has been recognizing outstanding achievement in business since 2012. Now in its 14th awards season, BIG operates more than 10 annual programs spanning innovation, artificial intelligence, cybersecurity, customer service, cloud computing, sustainability, sales and marketing, workplace culture, and women’s leadership.
 Unlike popularity contests, BIG programs use professional [judging panels](https://www.bintelligence.com/judges) and objective scoring benchmarks to identify organizations, products, and individuals making real, measurable impact. Winners receive a complete promotional toolkit – including blockchain-verified credentials, press release support, social media assets, and featured placement across BIG’s global community of more than one million business professionals. For more information, visit [bintelligence.com](http://bintelligence.com/).


---

# Protecting Workloads and Sensitive Data: Security Best Practices on Bare Metal in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/bare-metal-security-best-practices/ | Published: 2026-05-02 | Updated: 2026-04-28 | Author: Dr. Assad Abbas

Bare-metal[ servers](https://www.atlantic.net/dedicated-server-hosting/what-is-a-bare-metal-server-benefits-use-cases-and-best-practices/) remain an important choice in 2026 for workloads that require reliable performance, stable operations, and complete control over infrastructure. This setup is particularly common in healthcare, fintech, SaaS, and public sector environments, where systems process sensitive data such as [electronic Protected Health Information (ePHI)](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) and financial records. In bare-metal setups, workloads run directly on physical servers without a hypervisor layer that manages or isolates multiple virtual machines on the same hardware. As a result, any configuration or security error can directly affect the system running on that server.

To reduce these risks, protecting workloads and sensitive data requires a clear, layered approach. In this context, physical security, identity and access control, network segmentation, system hardening, firmware protection, and continuous monitoring function as interconnected components of a single security model rather than isolated controls. At the same time, the effectiveness of each layer depends on the strength of the others, and a weakness in one area can influence the security posture. When applied consistently, these controls make risks easier to quantify and manage. This article presents compliance-focused practices to secure bare-metal infrastructure and protect sensitive data.

## Shared Responsibility and Key Security Considerations in Bare Metal Environments

Bare-metal environments operate under a shared responsibility model, in which security tasks are divided between the infrastructure provider and the customer. In this model, the provider is responsible for the physical environment, including the data center facility, hardware lifecycle, power supply, cooling systems, physical access control, and hardware replacement. These elements form the foundation of the infrastructure and directly support the stability and security of all higher-level systems.

On the other hand, the customer is responsible for the systems that run on this infrastructure. This includes operating system configuration, application deployment, identity and access management, encryption, and data protection at rest and in transit. In addition, monitoring, compliance requirements, and incident response often involve coordination between the provider and the customer. As a result, clear separation of responsibilities is important, since unclear boundaries can create security gaps.

Along with this model, several key security considerations must also be addressed. One important aspect is identifying critical assets within the environment. These include physical servers, firmware components such as the [Baseboard Management Controller (BMC)](https://www.gigabyte.com/Glossary/bmc), operating system configurations, credentials, secrets, and sensitive data such as ePHI. Each of these assets has a different level of risk, and therefore each requires consistent protection.

In addition, it is how data moves across the same environment. Data does not remain in one place; instead, it enters from external sources, moves between internal services, and passes through management channels. At the same time, it is stored, backed up, and transferred to external systems or users. Each stage of this flow introduces potential exposure points. Therefore, security controls must be applied across all stages to maintain system integrity and reduce risk.

## Choosing a Secure Bare Metal Provider

The security of a bare-metal environment depends heavily on the provider selection. Therefore, key security capabilities must be ensured before finalizing a provider. The following aspects should be carefully evaluated:

- **Physical security controls: **The provider should enforce strict access restrictions at the data center. This includes biometric authentication, mantrap entry systems, continuous surveillance, and properly logged and monitored visitor access. These measures reduce the risk of unauthorized physical access.
- **Compliance readiness: **The provider must support regulated workloads through HIPAA-compliant hosting and a [HIPAA Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/). In addition, certifications such as SOC 2 Type II, PCI-DSS, and ISO 27001 indicate that structured security practices are implemented and reviewed regularly.
- **Environmental and operational stability**: The provider should demonstrate reliable power infrastructure, cooling systems, and effective fire-suppression systems. In addition, it is important to verify that the provider follows secure hardware lifecycle practices, including controlled handling, tamper-evident processes, and proper decommissioning. These factors indicate whether the provider can maintain consistent and secure operations over time.

Finally, the provider should present evidence of regular audits and penetration testing. This helps confirm that security controls are not only defined but also validated over time.

## Physical Security Controls for Bare Metal Environments

Physical security is critical in bare-metal environments because direct access to hardware can compromise the entire system. Therefore, the following controls must be maintained around physical access and handling of infrastructure.

- Servers should be installed in locked racks with tamper-evident seals to detect any unauthorized physical interaction.
- Access to the data center should remain limited to authorized personnel, with proper verification before entry is granted.
- Maintenance activities should be escorted and recorded to ensure accountability during all physical interventions.
- Identity checks for personnel should remain consistent and supported with proper documentation to reduce gaps in verification.
- Access logs should be reviewed regularly to identify unusual activity or unauthorized attempts.
- Hardware disposal should follow secure sanitization procedures to prevent exposure of sensitive data during decommissioning.

As a result, these controls help maintain strict physical access discipline and reduce the risk of unauthorized interference with bare metal infrastructure.

## Access Control and Privilege Management for Bare Metal Systems

Access control is a core requirement in bare-metal environments, as direct system access can affect both the infrastructure and sensitive workloads. For this reason, identity and privilege management must be enforced consistently and in a controlled manner.

Role-based access control separates responsibilities across administrators and operational teams, reducing unnecessary privilege allocation. In addition, privileged access must be protected with multi-factor authentication to reduce the risk of unauthorized entry.

The following controls are essential for maintaining secure access:

- Protecting privileged accounts with multi-factor authentication
- Avoiding shared credentials to maintain accountability
- Enforcing the scheduled rotation of privileged credentials
- Securing credential storage and access through centralized secrets management

Beyond these controls, system-level access must remain tightly restricted. Default accounts should be disabled, and unused service ports should be closed to reduce exposure, while least-privilege principles limit access to only required operations. At the same time, administrative activity must remain visible through logging and regular review of privilege escalation events.

## Network Segmentation and Perimeter Security Controls

Network security in bare metal environments depends on strict segmentation and controlled traffic flow. Therefore, a [default-deny](https://www.cybersecuritytribe.com/articles/the-case-for-default-deny) model is required, allowing only explicitly approved traffic. To enforce this structure effectively, controls must be applied across traffic rules, system design, and perimeter protection.

- **Traffic control and segmentation: **Network access is structured via an Access Control List (ACL) for inter-segment control, with each rule documented with justification and reviewed regularly to remove stale entries. At the same time, VLANs isolate workloads based on sensitivity, while management interfaces are separated into dedicated networks to prevent exposure from production systems. In addition, micro-segmentation is applied for high-risk services to limit lateral movement.
- **Perimeter and host-level protection: **Host-based firewalls enforce strict policies across systems, while [Intrusion Detection and Prevention Systems (IDPS)](https://www.redhat.com/en/topics/security/what-is-an-IDPS) are deployed and tuned to highlight meaningful alerts. Additionally, provider-level DDoS protection is enabled to mitigate large-scale attack attempts and maintain service stability.

## Host, Firmware, and System Hardening Practices

System hardening practices reduce the attack surface and improve consistency across bare metal infrastructure. Therefore, operating system configurations must align with recognized benchmarks, such as [CIS](https://www.cisecurity.org/cis-benchmarks) or [DISA STIG](https://ldra.com/disa-stigs) guidelines, to maintain a secure, standardized baseline.

To ensure clarity in control , system-level and firmware-level practices are addressed separately.

### System-Level Hardening Practices

System-level hardening focuses on reducing unnecessary components and maintaining consistent configurations across systems. This includes removing unused services, modules, and packages, using standardized system images to limit configuration drift, and applying immutable infrastructure to enable controlled, repeatable deployments.

In addition, patch management must follow a structured workflow where updates are tested in staging environments before production rollout. Where appropriate, unattended security updates may be enabled in controlled scenarios to reduce delays in vulnerability remediation.

### Firmware-Level Integrity Practices

Firmware-level security focuses on maintaining system integrity and preventing unauthorized modification of system components. Secure boot and measured boot must be enabled to validate trusted system states during startup, while TPM 2.0 should be used for hardware-based attestation.

Furthermore, firmware inventory and verification scans must be performed regularly, and firmware updates should be applied through controlled processes to minimize exposure to known vulnerabilities.

## Data Security: Encryption and Backup Controls

In bare-metal environments, data protection must be enforced throughout the lifecycle of information, since infrastructure-level controls remain with the organization. Therefore, data at rest on physical servers must be protected with full-disk or volume-level encryption to reduce exposure in the event of unauthorized access.

In addition, data in transit across bare-metal networks must always be protected with TLS to prevent interception. Encryption keys must be managed through centralized and secure key management systems to maintain strict control at the infrastructure level. Backup protection in bare metal deployments must include the following controls:

- Encrypted off-site backups to ensure resilience against data loss or hardware failure
- Defined retention policies aligned with compliance requirements such as HIPAA and PCI-DSS
- Regular recovery testing to validate backup integrity and restoration capability

These practices ensure both the confidentiality and recoverability of sensitive data within single-tenant bare-metal infrastructure.

## Monitoring, Detection, and Incident Response

Monitoring is essential for visibility across bare-metal environments, as there is no intermediate abstraction layer between workloads and hardware. Therefore, all logs must be collected in a centralized [Security Information & Event Management (SIEM)](https://www.splunk.com/en_us/blog/learn/siem-security-information-event-management.html) platform with protected integrity to ensure reliable and consistent security visibility across systems.

In this context, monitoring must focus on early identification of security-relevant events. This includes detecting authentication anomalies, monitoring privilege escalation activity, analyzing network behavior for unusual patterns, and maintaining restricted, controlled access to logs to prevent unauthorized viewing or modification.

In addition, incident response must be structured to ensure timely and consistent handling of security events. Therefore, response playbooks should be formally documented and tested regularly. Tabletop exercises further support this process by validating readiness and improving coordination during real incidents.

## Compliance and Continuous Improvement

Compliance frameworks such as HIPAA, PCI-DSS, SOC 2, and ISO 27001 define structured expectations for secure operations in bare metal environments. Therefore, all security controls for bare-metal servers must be mapped to these frameworks to ensure consistent alignment with regulatory requirements.

To maintain audit readiness, documentation must remain complete and continuously updated. In addition, regular vulnerability assessments and penetration testing help identify weaknesses before they can be exploited.

Security performance should be measured through defined KPIs, including:

- Mean time to detect (MTTD)
- Mean time to respond (MTTR)
- Patch latency across systems
- Backup recovery success rate

Finally, quarterly security reviews support continuous improvement and help ensure that controls remain effective against evolving risks in bare metal infrastructure.

## Roadmap for Bare Metal Server Security

A structured approach helps apply security controls consistently and measurably across bare-metal environments. Therefore, improvements are introduced in phases to reduce operational disruption and ensure stable adoption.

- **First 30 days:** Establish a security baseline by enforcing SSH key-based authentication, strengthening firewall rules, and removing weak or unused access configurations to reduce immediate exposure.
- **Next 60 days: **Focus should shift toward broader system improvements, including network segmentation to isolate workloads and deployment of centralized monitoring systems to improve visibility across infrastructure.
- **Months 3–6:** Deeper security enforcement should be applied through firmware and hardware integrity validation, strengthened system trust mechanisms, and alignment with compliance frameworks such as HIPAA, PCI-DSS, and SOC 2.

This phased approach ensures security controls are implemented progressively while maintaining operational stability in bare-metal environments.

## Atlantic.Net as a Compliance-Ready Bare Metal Infrastructure Partner

Selecting a provider that with strong security practices is important in bare-metal environments, as infrastructure design directly affects isolation, compliance readiness, and operational control. For this reason, it is important to rely on a platform that supports secure deployment requirements without introducing gaps or unnecessary .

In this context, Atlantic.Net provides bare metal hosting designed for regulated workloads, including environments that process ePHI. To support organizations operating under HIPAA obligations, the platform also provides a BAA.

In addition, Atlantic.Net offers single-tenant bare-metal servers, reducing exposure associated with shared infrastructure. Dedicated resources improve workload isolation, while data center operations enforce restricted access, continuous monitoring, and detailed logging of entry events.

At the infrastructure level, the platform supports encryption, network segmentation, and centralized monitoring through customer-managed configurations. As a result, organizations can implement security controls without major architectural changes. Compliance alignment is also supported across frameworks such as HIPAA, SOC 2, and PCI DSS, depending on deployment scope.

## The Bottom Line

Bare-metal environments offer strong performance and complete control over infrastructure, but this level of control also increases security responsibility. As discussed throughout this article, protecting workloads and sensitive data depends on applying layered controls consistently across physical security, identity management, network segmentation, system hardening, firmware integrity, encryption, monitoring, and compliance practices.

These controls do not operate in isolation. Instead, each layer supports the others, and a weakness in one area can affect the environment. Therefore, continuous monitoring, regular reviews, and alignment with compliance requirements remain important to maintain stability and reduce exposure to continuously evolving risks.


---

# How to Choose a Bare Metal Hosting Provider for Enterprise Workloads in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/choose-bare-metal-hosting-provider/ | Published: 2026-05-03 | Updated: 2026-06-17 | Author: Dr. Assad Abbas

Enterprise systems in 2026 can process larger datasets and run more complex workloads than in earlier years. Infrastructure selection is now a critical part of planning, particularly when applications depend on steady and predictable performance over long periods. This becomes more important in workloads such as AI model training, high-performance computing, and real-time analytics, where even small changes in CPU, memory, or storage behavior can affect results.

At the same time, virtualized cloud environments are not always suitable for every use case. While they work well for general workloads, their shared infrastructure model can sometimes lead to performance variation. As a result, some organizations consider dedicated infrastructure when consistency is more important than flexibility.

In such cases, [bare metal hosting](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) becomes relevant. It provides direct access to physical servers without a virtualization layer. Since there is no shared layer between users in bare metal hosting, resources are not shared with other tenants, so performance remains stable and easier to predict. This characteristic makes bare-metal hosting suitable for workloads that require consistent compute behavior and low variation in system performance, such as AI training, high-performance computing, and real-time analytics.

Therefore, selecting a bare metal hosting provider requires careful evaluation of performance, security, compliance, and operational factors. This article presents a structured approach to the selection process, intended for IT managers, system architects, and compliance-focused professionals.

## Understanding Bare Metal Hosting and When It Is the Right Choice

Bare-metal hosting is a deployment model in which a physical server is assigned to a single customer. In such a model, the hardware is not shared with other users, and all computing resources are dedicated to a single environment. This often results in stable performance and more predictable system behavior, even during long-running workloads.

On bare-metal servers, applications run directly on the physical hardware without a virtualization layer in between. The direct access helps maintain consistent CPU and I/O performance. It also provides greater control over system configuration, including storage setup and hardware-level tuning. Since there is no shared layer beneath the system, performance is not affected by other users’ activity.

In contrast, virtualized cloud environments operate differently. They divide a single physical server among multiple users using a hypervisor. The model is flexible and supports easy scaling, which is useful for many general workloads. Because resources are shared, performance can vary depending on system usage.

Due to these differences, bare metal hosting is often preferred when consistent performance is more important than flexibility. It suits workloads that require stable CPU and I/O behavior over time without variation. In such environments, stronger isolation and more direct control over hardware are also important, particularly for applications with specific performance or configuration requirements.

## Performance Advantages of Bare Metal Infrastructure

Performance consistency is one of the main reasons organizations use bare metal infrastructure. Without shared compute resources, workloads run in a more controlled environment, which helps maintain steady system behavior even under sustained demand.

These advantages are reflected in several clear performance outcomes:

- ### Predictable CPU and I/O Performance in Bare Metal Infrastructure

With bare metal hosting, resource availability remains stable because no other workloads compete for the same hardware. This reduces variation in processing speed and storage access, which is important for long-running tasks such as batch processing, analytics, and continuous service workloads.

- ### Stronger Isolation in Bare Metal Servers

Each bare-metal server is dedicated to a single customer, preventing external workloads from affecting CPU, memory, or disk usage. This improves performance stability and reduces the fluctuations common in multi-tenant environments.

- ### Hardware-Level Tuning in Bare Metal Environments

Bare-metal systems allow configuration changes at the hardware level, including BIOS settings, storage layouts, and network parameters. These adjustments help align the system with workload requirements and improve under sustained usage.

- ### No Noisy Neighbor Impact in Bare Metal Hosting

Since resources are not shared across tenants, there is no interference from other workloads. This removes sudden spikes in resource consumption, helping maintain stable latency and consistent response times.

- ### Stronger Performance Control for Critical Applications on Bare Metal

Applications that require steady processing and low latency benefit from a bare metal environment where performance variation is minimal. This supports more reliable execution for business-critical and performance-sensitive workloads.

## Enterprise Use Cases for Bare Metal Hosting

Bare metal hosting is used in enterprise environments where workloads require stable performance and consistent system behavior. It is suitable for applications that depend on predictable CPU, memory, storage, and network performance. The following use cases illustrate where bare-metal hosting is commonly used in enterprise systems.

### ERP Systems

ERP systems in business operations are a common use case for bare metal hosting. These systems process a high volume of transactions and require steady throughput to support daily financial and operational activities. Consistent infrastructure performance helps maintain reliable response times during both regular and peak usage periods.

### CRM Platforms

CRM platforms for customer management also benefit from bare metal hosting. These applications rely on fast access to customer data and stable response times for sales, support, and marketing operations. A consistent infrastructure helps maintain smooth user interaction, particularly when large datasets and continuous activity are involved.

### Database Workloads

Database workloads for enterprise data storage and processing are another important use case. Databases require high I/O performance and storage access for query execution and data retrieval. Bare-metal servers provide dedicated resources, helping maintain stable performance and reducing delays caused by resource contention.

### AI and Machine Learning Workloads

AI and machine learning workloads for model training and inference require compute capacity, especially during training. Bare-metal servers with GPU support are commonly used for these workloads, as they provide sustained performance over long-running jobs.

### High-Performance Computing (HPC)

High-performance computing workloads for scientific and engineering simulations also run effectively on bare metal infrastructure. These workloads depend on low-latency processing and consistent CPU performance, especially in complex simulations and mathematical computations.

### Real-Time Analytics

Real-time analytics systems for continuous data processing require uninterrupted data flow with minimal delay. Bare-metal hosting meets these requirements by maintaining stable throughput under sustained processing.

## Key Factors for Choosing a Bare Metal Hosting Provider

Choosing a bare metal hosting provider requires a structured review of technical, operational, security, and cost-related requirements. A detailed comparison helps ensure that the selected infrastructure meets the workload needs, particularly where performance, reliability, and control are important. The following factors are commonly used to evaluate providers consistently and reduce reliance on cost alone.

### SLAs and Uptime Commitments

SLA terms are a key factor in selecting a bare metal hosting provider. They define the expected level of service availability, commonly ranging from 99.9% to 99.99% percent uptime. Higher SLA commitments are more important for production workloads where downtime directly impacts business operations. It is also important to confirm whether hardware replacement timelines are included, since some providers exclude repair periods and limit coverage to network uptime only. This distinction often affects service reliability in bare metal environments.

### Hardware Customization and Specifications

Hardware flexibility is a critical factor in selecting bare-metal solutions. CPU and memory options determine compute capacity and performance stability. In addition, storage choices such as NVMe, SSD, or SATA directly affect I/O performance and workload. GPU availability is also a deciding factor for workloads such as AI training, rendering, and high-performance computing. These configuration options directly affect workload in bare-metal environments.

### Global Data Center Presence

Data center distribution is an important selection factor for bare metal hosting. Providers with multiple geographic locations support lower end-user latency and improved system resilience. This becomes more important for applications that require regional deployment, disaster recovery planning, or globally distributed access.

### Managed and Self-Managed Options

Managed and self-managed service models are important factors in selecting a bare-metal provider. Managed bare-metal services typically include monitoring, patching, and system administration, thereby reducing internal operational workload. Self-managed environments, on the other hand, provide complete control over server configuration and ongoing maintenance. The decision between these models depends on internal technical capacity and the level of operational responsibility an organization can support.

### Network Architecture and DDoS Protection

Network design has a direct impact on both reliability and performance. To maintain service continuity, providers rely on redundant network paths, which help reduce the risk of downtime and improve system stability. In addition to reliability, network-level security is equally important. DDoS protection is essential for internet-facing workloads, and providers should clearly specify mitigation capacity in Gbps and Mpps. Alongside these considerations, internal network performance also becomes important for latency-sensitive applications, where consistent data transfer speeds directly affect system responsiveness.

### Provisioning Speed and Automation Capabilities

Provisioning speed is the time required to make bare-metal infrastructure available for use. In bare-metal environments, where physical hardware must often be allocated per request, faster provisioning directly supports timely deployment and scaling. Some providers support near-instant deployment, while others require manual configuration for custom hardware setups. Because manual processes can slow down deployment and introduce inconsistencies in bare-metal provisioning, API access, and Infrastructure-as-Code compatibility (e.g., Terraform or Ansible), support automation and repeatable deployment practices. Such capabilities help maintain consistency while enabling scalability in bare-metal environments.

### Security and Compliance Requirements

Security and compliance are key factors in selecting a bare-metal hosting provider for enterprise workloads. Providers are expected to support standards such as SOC 2 Type II and ISO 27001, as well as industry-specific requirements such as HIPAA or PCI-DSS, where applicable. Encryption for data at rest and TLS for data in transit are standard expectations in secure bare metal environments. In regulated use cases, support for agreements such as a [HIPAA Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) may also be required.

### Pricing Models and Contract Terms

Alongside technical and operational considerations, the pricing structure also plays a role in selecting a bare-metal hosting provider. Pricing models vary based on usage patterns and deployment duration. Hourly billing is typically suitable for short-term or temporary workloads, while monthly or reserved pricing is more appropriate for long-term infrastructure use. Beyond base compute costs, additional charges such as bandwidth, storage, backup services, and managed support should also be reviewed, as they can significantly affect the total cost of ownership. These cost structures are often tied to contractual terms, including cancellation policies and minimum commitments, which influence long-term flexibility and should be evaluated as part of the decision process.

### Monitoring, Support, and Operational Visibility

Monitoring and support capabilities play a key role in maintaining system stability in a bare metal environment. Providers should offer access to system metrics, hardware health data, logging, and alerting tools, as well as to external monitoring platforms. In addition to visibility, support responsiveness, and clear escalation processes, maintaining uptime and resolving issues quickly is critical for production workloads.

In practice, the importance of these factors varies by case. For example, production environments place greater emphasis on SLAs, security, and network reliability, while development and testing scenarios often prioritize provisioning speed and pricing.

## Migration and Deployment Considerations

After selecting a bare-metal hosting provider, migration and deployment planning are necessary to ensure a smooth transition. This stage focuses on preparing workloads for the new environment while reducing operational risk during the move.

A structured migration process typically includes the following steps:

- Workload inventory: Identify applications, services, and data that require migration.
- Dependency mapping: Understand component relationships to avoid disruptions.
- Data transfer planning: Define methods for secure data movement.
- Cutover sequencing: Plan the transition timeline to minimize downtime.

Deployment templates are often used to standardize common environments such as LAMP, LEMP, or database clusters. These templates help reduce configuration errors and maintain consistency across deployments in bare metal environments.

## Examples of Bare Metal Hosting Providers in 2026

Bare-metal providers differ in their focus areas, including performance consistency, infrastructure flexibility, compliance readiness, and automation support. Instead of treating them as interchangeable options, it is more useful to evaluate them against the key selection factors discussed in this article.

Table 1: Provider Comparison Based on Key Selection Factors

| Provider | Best Fit Use Case | Strengths in Selection Factors |
| --- | --- | --- |
| [Atlantic.Net](http://www.atlantic.net) | Compliance-sensitive workloads | Strong focus on security and compliance, HIPAA-ready infrastructure, stable enterprise bare metal environments |
| [phoenixNAP](https://phoenixnap.com/) | Hybrid enterprise infrastructure setups | Flexible deployment models, global data center presence, security-oriented infrastructure design |
| [Hivelocity](https://www.hivelocity.net/) | Performance-focused dedicated hosting | High-performance bare metal, strong infrastructure control, flexible server configurations |
| [Servers.com](http://www.servers.com) | Scalable and automated infrastructure | API-driven provisioning, Infrastructure-as-Code support, flexible bare metal scaling |

Each provider prioritizes different aspects of bare-metal selection rather than competing on identical capabilities. In practice, these differences become clear when looking at their typical use cases. Atlantic.Net is commonly used in environments with strict compliance and security requirements. In contrast, phoenixNAP is often selected for hybrid infrastructure scenarios that require flexibility across deployments. Hivelocity focuses on performance-oriented dedicated hosting, while Servers.com emphasizes automation and scalable infrastructure management. Cherry Servers, on the other hand, positions itself as a pure bare-metal provider with a strong focus on performance and simplicity. These examples highlight the alignment of bare-metal providers with different workload priorities, making the selection process dependent on specific technical and operational requirements rather than on a universal ranking.

## The Bottom Line

Selecting a bare metal hosting provider involves balancing multiple factors rather than relying on a single criterion. Performance, compliance, pricing, and operational support all play a role, but their importance varies depending on workload requirements and business priorities.

In production environments, stability, consistent performance, and operational reliability typically take priority. In contrast, development and testing environments place more emphasis on flexibility, faster provisioning, and cost.

A structured evaluation of both workload needs and provider capabilities helps narrow down choices and supports more reliable infrastructure decisions with reduced long-term operational risk.


---

# Bare Metal as the Performance Foundation for Modern SaaS Architectures

> URL: https://www.atlantic.net/dedicated-server-hosting/bare-metal-saas-performance-architecture/ | Published: 2026-05-05 | Author: Dr. Assad Abbas

Modern [Software as a Service (SaaS)](https://www.salesforce.com/saas/) platforms operate in an environment where fast response times and consistent performance are no longer optional. With stricter SLAs, even brief latency spikes can cause noticeable disruptions to user experience and downstream business impacts. Infrastructure decisions, therefore, play a direct and increasingly critical role in application reliability.

Cloud-native architectures remain widely used for their flexibility, scalability, and support for rapid deployment across regions. They are well-suited to workloads and evolving application requirements. , because these environments rely on shared infrastructure, their performance can become inconsistent under sustained load. Resource contention, often called the “noisy neighbor” effect, can cause latency and throughput to fluctuate over time.

Due to these limitations, many SaaS teams have started re-evaluating their infrastructure approach. Bare-metal systems are attracting more attention in this context. They provide direct access to physical hardware without a virtualization layer, which reduces interference between workloads. As a result, applications run with more stable and predictable performance, particularly in production environments where workloads remain active for long periods.

Beyond performance gains, bare metal provides greater operational control and more predictable costs. With clearly defined resource boundaries and stable usage patterns, it provides a strong foundation for modern SaaS applications running on bare-metal infrastructure.

## Bare Metal in Modern SaaS Architecture and Deployment Models

Bare metal refers to single-tenant physical servers in which a single customer uses the entire machine without sharing it with others. Unlike virtual machines or multi-tenant cloud systems, no hypervisor layer divides resources across workloads; as a result, CPU, memory, and storage remain fully dedicated to a single environment. This leads to more stable performance since no other workloads compete for the same hardware resources.

In contrast, shared cloud environments run multiple workloads on the same physical infrastructure, and because it is shared, resource usage changes based on activity from other tenants. As a result, CPU cycles, memory access, and I/O operations may not remain steady during heavy or long-running workloads. This often leads to small but noticeable variations in latency and throughput in systems that depend on consistent response times.

Within many SaaS architectures, bare metal is used as the execution layer for performance-sensitive workloads. At the same time, cloud services handle functions such as authentication, monitoring, and global traffic routing. Core processing tasks run on dedicated hardware. Therefore, this separation helps maintain stable application behavior while still keeping flexibility in non-critical parts of the system.

Deployment models differ based on operational requirements. For example, dedicated servers are selected when strict isolation and consistent performance are needed. In addition, private cloud setups are used when controlled multi-tenant environments are required within a governed infrastructure. Managed bare-metal services offer another option, with provisioning and maintenance handled by the provider. Since each model has different trade-offs, SaaS teams select the most suitable deployment approach based on workload stability, compliance needs, and internal operational capacity.

## Why Bare Metal Provides a Performance Advantage

Bare metal plays an important role in modern SaaS architecture, enabling stable, predictable execution for performance-sensitive workloads. In SaaS systems, consistent behavior is often more important than peak performance, since user experience and service-level targets depend on steady response times. This makes bare metal a critical performance foundation through three main advantages.

### Eliminating Virtualization Overhead

Since bare metal servers run workloads directly on physical hardware without a hypervisor layer, CPU, memory, storage, and networking resources are accessed without additional abstraction. As a result, scheduling delays are reduced and [CPU steal time](https://www.site24x7.com/learn/linux/cpu-steal-time.html) is eliminated, leading to more stable execution under sustained load.

From an architectural perspective, direct hardware access reduces variability in workload behavior over time. Cache improves, and I/O contention drops significantly compared to shared environments. SaaS services that depend on steady throughput and predictable processing tend to perform more reliably when deployed on bare-metal infrastructure.

### Predictable, Low-Variance Latency

From a SaaS architecture perspective, consistent latency is a core requirement for systems that support real-time interactions and continuous user requests. SaaS architects often rely on metrics such as p95 and p99 latency to understand system behavior under normal and peak conditions, as these values better reflect real production performance than averages.

In shared cloud environments, multiple workloads run on the same underlying physical infrastructure. This results in competition for CPU, memory, and I/O resources across different services. Therefore, performance can vary with system activity, leading to instability in response times during sustained traffic. From an architectural standpoint, this variability becomes a concern when designing systems with strict SLA targets.

Bare metal reduces this issue by eliminating shared-resource contention at the hardware level. Each workload runs on dedicated resources, so execution behavior remains more stable under continuous load. For SaaS architects, this stability is important when defining service tiers, designing data-intensive components, or planning systems that require predictable response times.

### Operational and Cost Predictability for Steady-State SaaS

Many SaaS workloads run continuously with steady demand patterns, where performance stability over time becomes more important than rapid scaling. In such environments, infrastructure predictability directly influences system design and operational planning.

Bare metal supports this requirement by maintaining consistent performance behavior across long-running workloads. In addition, cost patterns are easier to estimate compared to usage-based cloud models, where resource consumption may fluctuate over time.

Over longer periods, steady-state workloads often perform better on dedicated hardware due to stable resource allocation. Therefore, bare metal is commonly used as a performance layer in SaaS architectures that prioritize consistent response times and long-term operational stability.

## Architectural Patterns for SaaS on Bare Metal

SaaS architectures built on bare metal often adopt hybrid, layered designs. The main idea is to keep performance-sensitive components close to physical hardware while using cloud services for orchestration and global reach. Bare metal serves as the performance backbone, particularly for workloads requiring stable execution over time. Below are common SaaS architectural patterns that use bare metal as a performance layer within hybrid systems.

### Kubernetes on Bare Metal

[Kubernetes](https://kubernetes.io/) manages containerized workloads effectively on bare metal, where cluster behavior stays stable due to direct hardware access without virtualization overhead. Some hybrid SaaS architectures place orchestration or management services in the cloud while running selected worker/data-plane nodes on bare metal. This ensures flexible orchestration with consistent runtime performance across microservices, API gateways, and service-mesh components.

### Containerized Workloads on Physical Infrastructure

After deploying Kubernetes on bare metal, containerized workloads can also run directly on physical hardware without a hypervisor. Such deployment reduces the abstraction between applications and the underlying infrastructure, thereby improving consistency in service-to-service communication.

### Hybrid SaaS Architectures

Many SaaS platforms combine cloud-native services (elasticity, global distribution, managed services) with bare-metal infrastructure for performance-critical components such as databases, caching, and ML inference. This role separation keeps core processing stable on dedicated hardware while maintaining architectural flexibility.

### Reference SaaS Architecture Pattern

A reference SaaS architecture describes the typical structure of modern SaaS systems that combine cloud services with bare-metal infrastructure. It illustrates the organization of different system layers in real deployments.

A common SaaS architecture follows a layered structure. At the top, the edge or API layer runs in the cloud or through a CDN to manage global traffic and request routing. Below that, the application layer runs on Kubernetes clusters deployed on bare-metal nodes, providing stable execution for core services.

In this architecture pattern, the data layer, including databases, caching systems, and storage, is also hosted on bare metal infrastructure to maintain predictable performance under load. Centralized observability and deployment pipelines connect all layers, ensuring coordinated operation across environments.

## Performance Workloads and Benchmarking in SaaS Architectures

Workload behavior is critical in infrastructure decisions for SaaS systems. In most cases, selecting an appropriate deployment model depends on the nature of the workload and its performance requirements rather than on general infrastructure capabilities.

Certain SaaS workloads require consistent execution under sustained load. For example, high-throughput databases, real-time analytics systems, fraud-detection pipelines, and machine-learning inference services. These workloads depend on stable CPU, memory, and I/O behavior since variations in resource performance directly affect system reliability. Distributed processing systems also require steady network and storage performance to maintain predictable throughput.

Based on these requirements, performance evaluation is carried out through benchmarking across different environments, where workload behavior is first identified before testing begins. After this step, workloads are categorized by resource demand into CPU-intensive, GPU-intensive, memory-bound, and I/O-heavy patterns. These patterns are then mapped to real-world SaaS workload types such as databases, analytics systems, AI inference services, web applications, and distributed processing pipelines.

These mapped workloads are evaluated using the metrics shown in the table below.

Table 1: Workload Suitability Comparison Between Cloud and Bare Metal Environments

| Workload Type | Cloud Suitability | Bare Metal Suitability | Primary Consideration |
| --- | --- | --- | --- |
| Bursty web applications | High | Low | Elastic scaling needs |
| High-throughput databases | Medium | High | Consistent I/O performance |
| Real-time analytics | Medium | High | Low-latency consistency |
| AI/ML inference | Medium | High | Predictable execution |
| Development and testing | High | Low | Rapid provisioning |
| HPC workloads | Low | High | Sustained compute demand |

Interpretation of these results depends on workload stability and system requirements. Workloads with unpredictable demand patterns generally align better with cloud environments, given their flexible scaling. In contrast, steady-state and performance-sensitive workloads benefit from bare-metal environments due to more controlled, predictable execution. Therefore, infrastructure choice is determined by workload behavior, performance consistency requirements, and operational maturity rather than a single predefined model.

## Security and Compliance Considerations in Bare Metal SaaS Architectures

Security and compliance requirements play an important role in SaaS systems that operate in regulated environments. Bare metal is often used in these cases because each workload runs on dedicated physical hardware without sharing underlying resources with other tenants. Bare metal reduces co-tenancy risks and gives teams greater control over the host-level security boundary, enabling stronger oversight of system configuration, including kernel settings and update processes.

Regulatory frameworks, such as HIPAA-compliant hosting and PCI DSS, also influence deployment decisions for SaaS platforms that handle sensitive or financial data. Meeting these requirements depends not only on software controls but also on infrastructure transparency and auditability. Bare-metal environments support this through clearly defined physical security controls, including controlled facility access, entry logs, surveillance, and documented hardware-handling procedures. These measures provide essential evidence of compliance during formal audits.

## Concluding Remarks

Bare metal has become an important part of modern SaaS architecture where consistent performance, predictable latency, and operational control matter. It works best for steady workloads and performance-heavy systems, while cloud environments are useful for scaling quickly and handling changing demand. In real deployments, both are often used together, with cloud services managing orchestration and global access, and bare metal handling core processing and data-intensive tasks.

Bare metal also meets stringent security and compliance requirements for regulated environments. Dedicated hardware, single-tenant isolation, and clear audit trails simplify compliance with HIPAA and PCI DSS standards, particularly for SaaS platforms that handle sensitive data, such as electronic Protected Health Information (ePHI).

In practical deployments, providers like Atlantic.Net offer single-tenant bare-metal infrastructure designed for performance-focused,d compliance-driven workloads. These services effectively integrate with hybrid SaaS designs, where core systems need stable execution while cloud components provide flexibility and global reach.

, consistent performance, predictable latency, operational control, and strong compliance support make bare metal a reliable option in modern SaaS architectures, while still working alongside cloud environments for flexibility and scale.


---

# Atlantic.Net Resources

> URL: https://www.atlantic.net/resources/ | Updated: 2026-09-16

Browse our knowledge base, downloads, policies, and foundational guides on cloud, dedicated, HIPAA, and PCI hosting. Everything you need to evaluate, plan, and operate hosting infrastructure from a 30-year-old US-based provider.

## Browse

Hubs that group ongoing content by type - updated regularly with new articles, guides, and customer stories.

### [Blog](https://www.atlantic.net/blog/)

Industry guides, technical deep dives, product announcements, and hosting knowledge from the Atlantic.Net team.

### [Tutorials](https://www.atlantic.net/tutorials/)

Step-by-step technical tutorials covering Linux, Windows Server, Docker, databases, and DevOps workflows.

### [Glossary](https://www.atlantic.net/resources/glossary/)

Definitions for the hosting, cloud, virtualization, database, and compliance terms you'll encounter when choosing infrastructure.

## Downloads & Policies

Long-form research, customer success stories, and the policies that govern Atlantic.Net hosting services.

### [White Papers](https://www.atlantic.net/about-us/whitepapers/)

Downloadable technical whitepapers on HIPAA compliance, virtualization, disaster recovery, and infrastructure best practices.

### [Case Studies](https://www.atlantic.net/press-room/case-studies/)

Real-world customer success stories spanning healthcare, AI/HPC, ecommerce, and data center modernization.

### [Brochures](https://www.atlantic.net/brochures/)

Downloadable product and service brochures spanning GPU hosting, cloud, compliance, security, and data centers.

### [Service Policies](https://www.atlantic.net/service-policies/)

Hosting, support, acceptable use, and service-level policies that apply to Atlantic.Net customers.

## Featured Guides

Foundational explainers covering the hosting and compliance topics our customers ask about most often.

### [What Are Managed Services?](https://www.atlantic.net/managed-services/what-are-managed-services/)

How managed services work, what they typically cover, and when they're the right fit for your team.

### [What Is HIPAA IT Compliance?](https://www.atlantic.net/hipaa-data-centers/hipaa-compliant-it-infrastructure-guide/)

Infrastructure-level requirements for HIPAA-compliant IT environments, from data centers to controls.

### [What Is HIPAA Compliance?](https://www.atlantic.net/hipaa-compliant-hosting/what-is-hipaa-compliance-history-rules-and-requirements/)

The history, rules, and current requirements of the Health Insurance Portability and Accountability Act.

### [What Is PCI Compliance?](https://www.atlantic.net/pci-compliant-hosting/what-is-pci-compliance/)

An overview of PCI DSS, who it applies to, and what it requires of merchants and service providers.

### [What Is Cloud Hosting?](https://www.atlantic.net/vps-hosting/what-is-cloud-hosting/)

How cloud hosting works and where it fits compared to dedicated, VPS, and colocation.

### [What Is Colocation Hosting?](https://www.atlantic.net/orlando-colocation-hosting-data-center/what-is-colocation-hosting/)

How colocation works, what it includes, and when to choose it over cloud or dedicated hosting.

### [What Is Block Storage?](https://www.atlantic.net/vps-hosting/what-is-block-storage/)

How block storage works, where it's used, and how it differs from object and file storage.

### [What Is VPS?](https://www.atlantic.net/vps-hosting/what-is-vps-2024-buyers-guide-and-expert-tips/)

A comprehensive buyer's guide covering virtual private server technology and how to choose one.

### [What Is a VPN?](https://www.atlantic.net/vps-hosting/what-is-vpn/)

How virtual private networks work, where they're used, and what they protect against.

### [What Is IaaS?](https://www.atlantic.net/dedicated-server-hosting/what-is-iaas/)

Infrastructure as a Service explained, with use cases, trade-offs, and how it compares to PaaS and SaaS.

## Award-Winning Hosting Solutions & Services

Simple, Fast, Reliable Server Hosting

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# From HIPAA Hosting Checklist to Production Platform Scope

> URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-hosting-checklist-production-scope/ | Published: 2026-05-06 | Updated: 2026-05-07 | Author: Richard Bailey

To continue our series of request-for-quote deep dives, today we are going to look at a recent query we received. Some HIPAA hosting requests arrive as a short question; others (like this) arrive as a detailed technical checklist.

The customer was considering Atlantic.Net for HIPAA-compliant hosting and wanted to schedule a technical meeting. Before meeting, they sent over their intended setup, technical requirements, and questions.

From a pre-sales engineering perspective, this is extremely helpful, as it means the initial discussions can quickly move to scope, ownership, pricing, support boundaries, and any design risks that need to be addressed before production.

This customer required a HIPAA-compliant hosting solution that includes PostgreSQL, RabbitMQ, PHP 8.2, Redis, Postfix, Node.js, Chromium, Puppeteer, supervisor, systemctl, daily backups, storage encryption, IPS, firewall controls, two-factor authentication, integrity monitoring, immutable logging, and documentation.

That is a lot of detail, but it’s a checklist that the Atlantic.Net HIPAA hosting platform was designed for. Our job is to turn the checklist into a scalable production hosting scope.

## The Starting Point

The customer’s environment was split between QA, staging, and demo environments. These were already running with another provider. Production was the environment being considered for Atlantic.Net.

This approach provided a sensible starting point for the conversation. We did not have to assume every environment was moving on day one. We could focus first on the production workload, then decide later whether to include non-production environments.

First, we needed to understand if the QA, staging, or demo contained any patient health information (ePHI), production data, production logs, credentials, or anything derived from real patient records?

If the answer is yes, those environments may require the same level of compliance attention as production. If the answer is no, we can scope production first and leave the other environments as they are for now. As a compliance leader, our engineers needed to understand the bigger picture so we could advise this potential customer in the best possible way.

## The Initial Hardware Target

The customer listed a current configuration of:

- 4 CPU
- 8 GB RAM
- 60 GB SSD

This was a useful starting point for pricing, but sizing still needs to be checked against how the application was expected to behave in production. Stacks like this have several moving parts. PostgreSQL, RabbitMQ, Redis, PHP, Postfix, Node, Chromium, and Puppeteer can all compete for CPU, memory, storage, and I/O.

For a modest production launch, some of those services may run on a single VM. That can keep the first deployment simple and cost-effective. For a busier workload, separation may make more sense. PostgreSQL may deserve its own resources. Puppeteer workers can be memory-intensive, and RabbitMQ and Redis may need closer monitoring depending on queue volume, persistence requirements, and how the application handles background jobs.

## The Application Stack

The customer’s application stack was specific:

- PostgreSQL for the database.
- RabbitMQ for message handling.
- PHP 8.2 for the application.
- Redis for caching or queue support.
- Postfix for mail flow.Node, Chromium, and Puppeteer for worker tasks.
- supervisor and systemctl for process control.

Our engineers have no concerns about hosting the stack, but there are many important questions about ownership that we need to ask the customer.

- Who installs each service?
- Who patches it?
- Who monitors it?
- Who restarts it if it fails?
- Who tunes it when traffic grows?
- Who reviews logs when something behaves unexpectedly?

These questions needed to be answered before the order is signed, not during an incident. In many cases, Atlantic.Net provides the HIPAA hosting foundation while the customer manages the application stack. If the customer wants Atlantic.Net to manage specific services, those services need to be quoted, included in the scope, and provided by Atlantic. Net-managed services.

HIPAA compliance relies on shared ownership to be successful, and part of that is having clear boundaries that protect both teams. The customer knows what support Atlantic.Net would cover, and the customer’s in-house team knows what it is responsible for, and the application team knows what remains under their control. Drawing this line in the sand is essential to creating a service that serves everyone’s needs.

## The Deployment Pipeline

One particular area the customer needed advice on was how their current CI/CD pipeline model would fit with HIPAA compliance. Should GitLab and the deployment procedure be HIPAA-compliant?

The best answer is: it depends on what the deployment process can access.

If GitLab or the deployment pipeline stores production credentials, pushes code into the HIPAA environment, contains secrets, generates logs with sensitive data, or gives users access to production systems, then it needs to be included in the compliance discussion.

That does not automatically mean GitLab has to be hosted by Atlantic.Net. But it does mean the deployment path should be documented and controlled.

A few practical questions help clarify the risk:

- Where are production secrets stored?
- Who can deploy to production?
- Are deployments approved or automatic?
- Do build logs contain PHI or sensitive configuration?
- Do runners connect directly to the production environment?
- How is deployment access removed when an engineer leaves?

A HIPAA hosting environment can be well-designed, but a careless deployment process can still pose a risk. That is why the deployment pipeline belongs in the pre-sales conversation.

## Backups and Recovery

The customer asked about daily on-site backups, a recent off-site backup, and possible RTO/RPO expectations. The customer needed to know what is backed up, how often it is backed up, where the backup copy lives, how it is protected, and what a realistic recovery expectation is.

For this stack, the recovery discussion should be broken down by component. PostgreSQL is likely the most important recovery target. RabbitMQ may matter if queued messages cannot be lost. Redis may or may not require persistence, depending on how the application uses it.

Application files would need to be restored on the server. Logs mattered for compliance, troubleshooting, and incident response. Puppeteer jobs may also create files or artifacts that need retention.

A daily backup model would be suitable for the first production environment. Still, if the customer needed a tighter recovery point objective, a separate architecture discussion involving database-level backups, replication, disaster recovery planning, or a more advanced recovery design may be needed.

The important point is simple: recovery expectations should be defined before production goes live.

## Security Controls

The customer’s security list included vulnerability scans, storage encryption, IPS, firewall controls, integrity monitoring, two-factor authentication for OS accounts, immutable logging, OS compliance audits, and setup documentation. These are all services available in the Atlantic.Net Managed service offerings.

Most of these controls are part of the hosting layer; others need to be configured inside the operating system. Some depend on how the customer manages the application and may require additional managed services.

For example, “firewall” sounds straightforward until we define ports, source IPs, VPN requirements, administrative access, and change control. “Immutable logging” sounds straightforward until we define which logs are shipped, where they are stored, who can access them, how long they are retained, and whether the application itself logs PHI.

“Two-factor authentication” also needs detailing. Does it apply to portal users, VPN users, OS users, application administrators, or all of the above?

## Regional Scope and Pricing

The customer asked about support for at least the EU and U.S., with Asia as a nice-to-have. They also asked for pricing for the full configuration and pricing for only the U.S.

For a first production deployment, it usually makes sense to quote the cleanest required footprint first. If U.S.-only production is enough for launch, quote that clearly. If an EU deployment is mandatory, scope it as a separate regional design. If Asia is only a future possibility, keep it out of the initial production quote unless there is a real launch requirement.

## What Needs to Be Decided Before the Quote

By the end of this kind of pre-sales review, the customer should be able to answer a few key questions:

- Is Atlantic.Net hosting only production, or also QA, staging, and demo?
- Do any non-production environments contain PHI?
- Will all services run on one VM, or should some be separated?
- Which services does Atlantic.Net manage?
- Which services does the customer manage?
- What backup cadence is acceptable?
- What RTO and RPO does the business actually need?
- Which security controls are included in the standard HIPAA hosting tier?
- Which requirements need a custom scope or documentation?
- Does the deployment pipeline need additional compliance controls?

## From Checklist to Production Scope

The customer did the right thing by sending a detailed technical checklist before the technical meeting, and we were delighted to onboard them onto Atlantic.Net’s HIPAA-compliant hosting platform recently.

That early detail allowed our engineering team to treat the request as a real production environment, not just a collection of software packages. PostgreSQL, RabbitMQ, PHP 8.2, Redis, Postfix, Node.js, Chromium, Puppeteer, supervisor, backups, firewall rules, MFA, logging, monitoring, and documentation all matter. But in a HIPAA environment, the larger question is how those components are hosted, secured, supported, monitored, backed up, and managed over time.

This is where Atlantic.Net’s HIPAA-compliant hosting platform becomes the foundation. The production environment can be built on an audited, HIPAA- and HITECH-ready infrastructure, supported by a HIPAA Business Associate Agreement (BAA), secure cloud or dedicated hosting, encrypted storage, managed firewall protection, intrusion prevention, vulnerability scanning, log management, multi-factor authentication, encrypted backups, VPN access, and disaster recovery.

If the customer wants Atlantic.Net to provide the compliant infrastructure while their internal team manages the application, that boundary can be clearly documented. If they want Atlantic.Net to take on more operational responsibility, managed services can be added to the design, including server management, managed firewall, MFA, Trend Micro Deep Security, Network Edge/DDoS protection, managed Veeam backup, load balancing, migration services, consulting, database hosting, database administration, backup management, patching, troubleshooting, performance tuning, and high availability planning.

For this customer, that meant the proposal was not simply about quoting CPU, RAM, and storage. It needed to define the production region, VM sizing, security controls, backup model, access controls, deployment assumptions, support boundaries, documentation requirements, and any optional managed services required to operate the environment safely.

Have a HIPAA hosting checklist that needs to be turned into a production-ready scope? [Contact Atlantic.Net to review your application stack,](https://www.atlantic.net/hipaa-compliant-hosting/) security requirements, backup model, and managed hosting options.


---

# Hosting and Cloud Glossary

> URL: https://www.atlantic.net/resources/glossary/ | Updated: 2026-09-16

Understand the terms used to choose and manage hosting infrastructure. Browse definitions for servers, cloud platforms, storage, databases, security, and recovery. Links lead to explanatory resources or clearly labeled hosting services.

81 terms across 18 letters

## A

### AI (Artificial Intelligence)

Artificial intelligence is the field of developing computer systems that perform tasks such as recognizing patterns, understanding language, making predictions, or generating content. It includes machine learning and other approaches. In hosting, AI workloads can involve training models or running inference, with resource requirements determined by the model and application.

[Read more about Artificial Intelligence](https://aws.amazon.com/what-is/artificial-intelligence/).

### AI Inference

AI inference is the process of using a trained model to produce an output from new input. Examples include generating a response to a prompt, classifying an image, or predicting demand. The model, response-time target, and request volume determine the computing resources required.

[Read more about AI Inference](https://www.nvidia.com/en-gb/glossary/ai-inference/).

### Apache HTTP Server

Apache HTTP Server is open-source web server software maintained by the Apache Software Foundation. It serves website content over HTTP and HTTPS and can pass requests to application services. Administrators use its modules and configuration files to control functions such as authentication, logging, and request routing.

[Read more about Apache HTTP Server](https://www.atlantic.net/vps-hosting/what-is-an-apache-server/).

### API (Application Programming Interface)

An application programming interface defines how software components communicate and request functions or data from one another. Hosting APIs can automate tasks such as creating servers, managing storage, or retrieving account information. Available operations, authentication requirements, request limits, and response formats are described in the provider's API documentation.

[Read more about APIs](https://aws.amazon.com/what-is/api/).

## B

### BaaS (Backup as a Service)

Backup as a Service delivers backup capabilities through a service provider, usually with subscription or usage-based pricing. The service can include backup software, storage, scheduling, monitoring, and restoration support. Customers should confirm which systems are protected, how long copies are retained, where data is stored, and who performs and tests restores.

[Explore Managed Backup services](https://www.atlantic.net/managed-services/veeam-services/).

### Backup

A backup is a recoverable copy of data kept for use when the original is lost, damaged, or unavailable. Backups can cover files, databases, or entire systems. Their usefulness depends on the recovery points retained, protection against deletion or attack, and successful restoration testing.

[Explore Backup services](https://www.atlantic.net/cloud-platform/backups/).

### Bandwidth

Bandwidth is the data-carrying capacity of a network connection, usually expressed in megabits or gigabits per second. Actual transfer speeds also depend on congestion, latency, and the systems at each end. Hosting plans sometimes use “bandwidth” to describe a monthly data-transfer allowance, so check whether a stated limit measures capacity or total usage.

[Read more about Bandwidth](https://developer.mozilla.org/en-US/docs/Glossary/Bandwidth).

### Bare Metal Server

A bare metal server is a physical server allocated to one customer, with direct access to its hardware resources. The customer can install an operating system or virtualization software. Hosting providers often use “bare metal server” and “dedicated server” for closely related offerings.

[Explore Bare Metal Server services](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/).

### Big Data

Big data describes datasets whose volume, speed of arrival, or variety makes them difficult to process with conventional tools. Examples include large collections of application logs, transaction records, and sensor readings. Big data systems often distribute storage and processing across multiple machines to support analysis, reporting, or machine learning.

[Read more about Big Data](https://aws.amazon.com/what-is/big-data/).

### Block Storage

Block storage presents data to a server as individually addressable blocks, usually within a volume that the operating system treats as a disk. The server can format that volume with a file system or use it for database storage. Performance depends on the underlying storage and connection.

[Read more about Block Storage](https://www.atlantic.net/vps-hosting/what-is-block-storage/).

### Business Continuity

Business continuity is an organization's ability to maintain essential operations during and after a disruption. Planning covers people, facilities, suppliers, communications, and technology, including alternative ways to deliver critical services. Disaster recovery supports business continuity by restoring IT systems, while the broader continuity plan addresses how the organization continues operating.

[Read more about Business Continuity](https://www.ibm.com/think/topics/business-continuity).

## C

### CDN Service

A content delivery network (CDN) service uses distributed servers to deliver website content closer to users. It can cache files such as images, stylesheets, and videos, reducing requests to the original hosting server. Some CDNs also accelerate dynamic traffic or provide security features. Results depend on caching rules, content type, and network coverage.

[Read more about CDN services](https://aws.amazon.com/what-is/cdn/).

### Cloud Hosting

Cloud hosting runs websites or applications using computing resources supplied through a cloud platform. Resources can be provisioned and adjusted as workloads change. Infrastructure as a Service (IaaS) is one cloud service model; cloud hosting can also include services that manage more of the application environment.

### Cloud Infrastructure

Cloud infrastructure is the collection of hardware and software that supports cloud computing services. It includes servers, storage, networking, virtualization, and management systems used to allocate resources to workloads. This infrastructure can support public, private, or hybrid cloud environments, with capacity and availability shaped by the underlying architecture.

[Read more about Cloud Infrastructure](https://aws.amazon.com/what-is/cloud-infrastructure/).

### Cloud Migration

Cloud migration is the process of moving applications, data, or other IT resources into a cloud environment or between cloud providers. A migration may transfer an existing system largely unchanged or redesign parts of it for new services. Planning includes dependencies, security, data transfer, testing, service cutover, and a rollback approach.

[Explore Cloud Migration services](https://www.atlantic.net/managed-services/migration-services/).

### Cloud Native

Cloud native describes an approach to building and operating applications that uses cloud capabilities such as automated deployment, flexible scaling, and service-based architecture. Containers, APIs, and microservices are common components, though the implementation varies. Cloud-native applications can run in public, private, or hybrid environments; moving an existing application to cloud hosting alone does not make it cloud native.

[Read more about Cloud Native](https://aws.amazon.com/what-is/cloud-native/).

### Cloud Platform

A cloud platform brings together computing services and the tools used to provision and manage them. It may offer virtual servers, storage, networking, databases, and application services through a control panel or API. Available features, supported software, billing methods, and the division of management responsibilities vary between platforms.

[Explore Cloud Platform services](https://www.atlantic.net/cloud-platform/).

### Cloud Portability

Cloud portability is the ability to move applications and data between cloud environments while preserving their intended operation. It depends on compatible runtimes, data formats, APIs, and supporting services. Containers and open standards can reduce migration work, while provider-specific features and dependencies can make a move more difficult.

[Read more about Portability Across Cloud Environments](https://www.redhat.com/en/topics/cloud-computing/what-is-multicloud).

### Cloud Provider

A cloud provider is a company that supplies computing services such as virtual servers, storage, networking, or hosted applications. The provider operates the infrastructure needed to deliver its services. Customer responsibilities for software, access controls, data protection, and recovery depend on the service model and the terms of the agreement.

[Explore Cloud Hosting services](https://www.atlantic.net/cloud-platform/).

### Cloud Storage

Cloud storage holds data on infrastructure accessed through a cloud service over a network. It can provide object storage, block volumes, or shared file systems, each suited to different access patterns. Capacity, performance, data location, access controls, and charges for requests or transfers depend on the selected service.

[Read more about Cloud Storage](https://aws.amazon.com/what-is/cloud-storage/).

### Cluster

A cluster is a group of connected computers or service instances, called nodes, that work together on a workload. Clusters can distribute processing, pool resources, or help services remain available when a node fails. Their behavior depends on the software, networking, storage, and failure-handling design; having multiple nodes alone does not guarantee uninterrupted service.

[Explore Infrastructure Cluster services](https://www.atlantic.net/dedicated-server-hosting/infrastructure-cluster-solutions/).

### Colocation Hosting

Colocation hosting places customer-owned servers in a provider’s data center. The provider supplies agreed facilities such as rack space, power, cooling, connectivity, and physical security. The customer retains ownership of the equipment, while hardware maintenance and any additional management services follow the contract.

[Read more about Colocation Hosting](https://www.atlantic.net/orlando-colocation-hosting-data-center/what-is-colocation-hosting/).

### Container

A container is an isolated environment for running an application and its required files and dependencies. Operating-system containers share the kernel of the system on which they run, rather than each requiring a separate guest operating system. Their portability and isolation depend on compatible platforms, runtime configuration, resource limits, and security controls.

[Read more about Containers](https://docs.docker.com/get-started/docker-concepts/the-basics/what-is-a-container/).

### cPanel

cPanel is a web-based control panel for managing hosting accounts on supported Linux servers. It provides tools for tasks such as managing website files, domains, email accounts, databases, and backups. Its companion product, WebHost Manager (WHM), supports server-level and account administration. Available features depend on the hosting plan and administrator's configuration.

[Read more about cPanel](https://docs.cpanel.net/cpanel/).

## D

### Database Hosting

Database hosting supplies the infrastructure on which a database system, such as MySQL or Microsoft SQL Server, runs. The customer may administer the database themselves or purchase management services. Responsibilities for patching, backups, replication, and recovery depend on the agreed service scope.

### Data Center

A data center is a facility that houses servers, storage systems, and networking equipment. It supplies supporting infrastructure such as electrical power, cooling, connectivity, and physical security. Data centers may serve a single organization or multiple customers. Redundancy, maintenance procedures, and the services included vary between facilities.

[Explore Data Center facilities](https://www.atlantic.net/hipaa-data-centers/).

### DDoS (Distributed Denial of Service)

A distributed denial-of-service attack attempts to make a system unavailable by overwhelming its network, services, or application with traffic from multiple sources. Attacks can exhaust bandwidth, connection capacity, or application resources. Protection may combine upstream traffic filtering, rate limits, application controls, and a response plan suited to the services being protected.

[Read more about DDoS attacks and protection](https://aws.amazon.com/shield/ddos-attack-protection/).

### Dedicated Hosting

Dedicated hosting is a service that provides one or more physical servers for a single customer's use. The customer receives access to the server's allocated hardware resources without sharing that server with other hosting customers. The service may be managed or self-managed, with maintenance, monitoring, backups, and security responsibilities defined in the agreement.

[Explore Dedicated Hosting services](https://www.atlantic.net/dedicated-server-hosting/).

### Dedicated Hosting Provider

A dedicated hosting provider supplies physical servers reserved for individual customers, together with agreed data center facilities and connectivity. Providers differ in their hardware options, deployment locations, support arrangements, and management services. The contract should identify responsibilities for hardware replacement, operating system maintenance, security controls, backups, and incident response.

[Explore Atlantic.Net Dedicated Hosting](https://www.atlantic.net/dedicated-server-hosting/).

### Dedicated Server

A dedicated server is a physical server reserved for one customer’s use. Its processor, memory, and local storage are allocated to that customer, who can run applications directly or install virtualization software. Operating system maintenance, backups, and monitoring depend on the hosting agreement.

[Explore Dedicated Server services](https://www.atlantic.net/dedicated-server-hosting/).

### Disaster Recovery

Disaster recovery is the planned process of restoring IT systems and data after a serious disruption. It covers recovery priorities, people, procedures, and the infrastructure needed to resume service. Backups can support recovery, while testing establishes whether applications and their dependencies can return within agreed targets.

[Explore Disaster Recovery services](https://www.atlantic.net/disaster-recovery/).

### DNS (Domain Name System)

The Domain Name System is a distributed naming system that associates domain names with records used by internet services. These records can identify server IP addresses, mail servers, and other configuration information. DNS resolvers retrieve and cache the records, so changes may not reach every user immediately when an existing cached record remains valid.

[Read more about DNS](https://aws.amazon.com/route53/what-is-dns/).

### Docker

Docker is a set of tools for building, distributing, and running containerized applications. Developers package application code and dependencies into images, which a compatible runtime uses to create containers. Docker can make development and deployment environments more consistent. Persistent data, networking, image updates, and access permissions still require configuration and management.

[Read more about Docker](https://docs.docker.com/get-started/docker-overview/).

## F

### Firewall

A firewall allows or blocks network traffic according to configured rules. It can run on a server, in a network appliance, or as a hosted service. Rules may consider addresses, ports, connection state, or application information. Effective protection depends on appropriate configuration and ongoing maintenance.

[Explore Firewall services](https://www.atlantic.net/managed-services/firewall/).

### FTP (File Transfer Protocol)

File Transfer Protocol is a network protocol for transferring files between a client and a server. Standard FTP does not encrypt credentials or file contents in transit. Encrypted alternatives include FTPS, which adds TLS protection to FTP, and SFTP, a separate file-transfer protocol that operates over SSH.

[Read more about FTP, FTPS, and SFTP](https://docs.aws.amazon.com/transfer/latest/userguide/what-is-aws-transfer-family.html).

## G

### GPU

A graphics processing unit (GPU) is a processor designed to perform many calculations in parallel. GPUs handle graphics rendering and can accelerate workloads such as machine learning and scientific computing. Available memory, software support, and the workload’s processing pattern affect whether a particular GPU is suitable.

[Explore GPU services](https://www.atlantic.net/gpu-server-hosting/).

## H

### HIPAA Business Associate Agreement (BAA)

A HIPAA Business Associate Agreement (BAA) sets out a business associate’s obligations when handling Protected Health Information (PHI) for a covered entity or another business associate. It addresses permitted uses, safeguards, and reporting duties. Signing a BAA is one part of meeting applicable HIPAA requirements.

[Read more about HIPAA Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/).

### Host

A host is a physical or virtual computer that runs software or provides services on a network. In virtualization, the host is the system that runs the hypervisor and its guest virtual machines. In web hosting, the term can also refer to the company supplying hosting services.

[Read more about Hosts](https://developer.mozilla.org/en-US/docs/Glossary/Host).

### Hybrid Cloud

Hybrid cloud connects public cloud services with private cloud or on-premises infrastructure so that applications and data can work across environments. Organizations may use it to retain existing systems while adding cloud-based capacity or services. Effective operation requires suitable connectivity, identity management, security controls, monitoring, and clearly defined responsibilities across the connected systems.

[Read more about Hybrid Cloud](https://aws.amazon.com/what-is/hybrid-cloud/).

### Hyper-V

Hyper-V is Microsoft's hardware virtualization technology, available in Windows Server and supported editions of Windows. It creates virtual machines with their own operating systems, virtual disks, and network connections. Server deployments can use features such as live migration, clustering, and replication, subject to the Windows edition, hardware, and configuration.

[Read more about Hyper-V](https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/overview).

### Hypervisor

A hypervisor is the software layer that creates and runs virtual machines while managing their access to physical computing resources. Type 1 hypervisors operate directly on hardware, while Type 2 hypervisors run through a host operating system. Resource scheduling, isolation, device support, and management features differ between implementations.

[Read more about Hypervisors](https://aws.amazon.com/what-is/hypervisor/).

## I

### Infrastructure

IT infrastructure is the combination of hardware, software, networks, and supporting facilities used to operate technology services. It includes components such as servers, storage, operating systems, switches, power, and cooling. Infrastructure may be located on premises, supplied by a hosting provider, or distributed across several environments.

[Explore Infrastructure Cluster solutions](https://www.atlantic.net/dedicated-server-hosting/infrastructure-cluster-solutions/).

### Infrastructure as a Service (IaaS)

Infrastructure as a Service supplies processing, storage, and networking resources that customers use to run software. The provider manages the underlying cloud infrastructure; the customer controls operating systems and deployed applications. Additional management services can change who performs particular tasks, so responsibilities should be documented.

[Read more about Infrastructure as a Service (IaaS)](https://www.atlantic.net/dedicated-server-hosting/what-is-iaas/).

### Internet Information Services (IIS)

Internet Information Services is Microsoft’s web server software for Windows. It serves web content and hosts applications through a configurable request-processing system. Application pools provide boundaries between groups of applications, but several applications can share a pool and its worker process, depending on configuration.

[Read more about Internet Information Services (IIS)](https://www.atlantic.net/vps-hosting/what-is-an-iis-server/).

### IP Address

An Internet Protocol address identifies a network interface and helps direct traffic to its destination. IPv4 uses 32-bit addresses, while IPv6 uses 128-bit addresses. Public addresses can be routed across the internet; private addresses are used within private networks. A device can have multiple addresses, and an address does not necessarily identify one person or website.

[Read more about IP Addresses](https://developer.mozilla.org/en-US/docs/Glossary/IP_Address).

## K

### KVM (Kernel-based Virtual Machine)

Kernel-based Virtual Machine is an open-source virtualization technology built into the Linux kernel. It uses hardware virtualization support to run virtual machines with their own operating systems and resources. KVM is commonly combined with QEMU, which provides virtual hardware and other supporting functions, and management tools that handle provisioning, networking, and storage.

[Read more about KVM](https://linux-kvm.org/page/Main_Page).

## L

### Load Balancer

A load balancer distributes incoming traffic across multiple servers or application instances. Depending on its configuration, it can check backend health and direct requests to available destinations. It supports capacity and availability, while session handling, application design, and the load balancer’s own resilience still need consideration.

[Explore Load Balancer services](https://www.atlantic.net/managed-services/load-balancing/).

## M

### Managed Hosting

Managed hosting includes agreed administration tasks alongside the hosting infrastructure. These may cover operating system updates, monitoring, backups, or security controls. Coverage varies between providers and plans. The service agreement should identify who maintains applications, responds to alerts, restores data, and handles work outside the standard scope.

[Read more about Managed Hosting](https://www.atlantic.net/dedicated-server-hosting/what-is-managed-hosting/).

### Microsoft SQL Server (MSSQL)

Microsoft SQL Server is a relational database management system that stores structured data and supports queries using Transact-SQL (T-SQL). Applications use it to read and update records, enforce data relationships, and process transactions. Available features and deployment options depend on the selected version and edition.

[Read more about Microsoft SQL Server (MSSQL)](https://www.atlantic.net/vps-hosting/what-is-mssql/).

### ML (Machine Learning)

Machine learning is a branch of artificial intelligence that develops models by learning patterns from data. These models can support tasks such as forecasting demand, detecting unusual transactions, or classifying images. Training develops the model, while inference applies it to new inputs. Accuracy depends on data quality, model design, and evaluation.

[Read more about Machine Learning](https://aws.amazon.com/what-is/machine-learning/).

### Multi-Factor Authentication (MFA)

Multi-factor authentication requires evidence from at least two different categories: something you know, something you have, or something you are. A password combined with a security key is one example. Two passwords belong to the same factor category. Protection varies with the authentication method and account-recovery process.

[Explore Multi-Factor Authentication (MFA) services](https://www.atlantic.net/managed-services/multi-factor-authentication/).

### MySQL

MySQL is an open-source relational database management system that uses SQL to store, retrieve, and update structured data. It organizes information into tables and supports applications such as WordPress. Hosting a MySQL database also requires decisions about access controls, backups, software updates, and recovery.

[Read more about MySQL](https://www.atlantic.net/dedicated-server-hosting/what-is-mysql/).

## N

### NFS (Network File System)

Network File System is a protocol that allows a computer to access files and directories stored on another system over a network. It is commonly used for shared storage in Linux and Unix environments, with support also available on other platforms. Permissions, identity mapping, network access, and protocol configuration determine how clients can use a share.

[Read more about NFS](https://learn.microsoft.com/en-us/windows-server/storage/nfs/nfs-overview).

### NVMe (Non-Volatile Memory Express)

Non-Volatile Memory Express is a storage interface and protocol designed for efficient access to non-volatile storage, especially solid-state drives. Local NVMe drives commonly connect through PCI Express, while NVMe over Fabrics extends access across a network. Performance depends on the drive, connection, queue handling, and workload, rather than the NVMe label alone.

[Read more about NVMe](https://www.ibm.com/think/topics/nvme).

## O

### Object Storage

Object storage holds data as objects, each containing the data itself, metadata, and an identifier. Applications usually access objects through an API within a bucket or similar container. It is commonly used for images, videos, backups, and large datasets. Object storage has different access behavior from a mounted block volume or shared file system.

[Read more about Object Storage](https://aws.amazon.com/what-is/object-storage/).

### One-Click Application

A one-click application is a preconfigured software deployment available through a hosting platform or control panel. It automates steps such as installing a web server, database, or content management system. Users still need to review credentials, configure the application, and arrange updates, security controls, and backups after deployment.

[Explore One-Click Applications on the Cloud Platform](https://www.atlantic.net/cloud-platform/).

### OS (Operating System)

An operating system manages a computer's processor, memory, storage, devices, and access to hardware. It also provides the environment in which applications run. Server operating systems include Linux distributions and Windows Server. Software compatibility, licensing, security updates, administration tools, and support requirements influence which operating system suits a workload.

[Read more about Operating Systems](https://www.ibm.com/think/topics/operating-systems).

### OVN/OVS

Open Virtual Network (OVN) and Open vSwitch (OVS) are related open-source networking technologies. OVS provides software switching that forwards traffic between virtual interfaces and networks. OVN adds logical switches, routers, and access policies that are translated into configurations for OVS. Together, they support software-defined networking for virtualized and cloud environments.

[Read more about OVN](https://www.ovn.org/en/). [Read more about Open vSwitch](https://www.openvswitch.org/).

## P

### PCI Hosting

PCI hosting describes hosting services intended to support Payment Card Industry Data Security Standard (PCI DSS) requirements. The provider’s assessed services and responsibilities should be clear. A customer’s compliance also depends on its applications, access controls, processes, and the full scope of its payment environment.

[Explore PCI Hosting services](https://www.atlantic.net/pci-compliant-hosting/#WhatisPCIHosting).

### Platform as a Service (PaaS)

Platform as a Service provides an environment for deploying applications while the provider manages the underlying infrastructure, operating systems, and supported runtime components. Customers manage their application code and data. Supported languages, database services, configuration options, and operational responsibilities vary between platforms.

[Read more about Platform as a Service (PaaS)](https://www.atlantic.net/dedicated-server-hosting/what-is-paas/).

### Plesk

Plesk is a hosting control panel available for supported Linux and Windows servers. It provides a web interface for managing websites, domains, email, databases, certificates, and hosting subscriptions. Extensions can add application and administration tools. Available features depend on the operating system, license, installed extensions, and settings chosen by the administrator.

[Read more about Plesk](https://docs.plesk.com/en-US/obsidian/).

### Private Cloud Hosting

Private cloud hosting provides cloud infrastructure for the exclusive use of one organization. It can be operated on the organization’s premises or by a hosting provider. Resources remain available to multiple internal users or teams, with cloud capabilities such as self-service provisioning and resource pooling.

[Read more about Private Cloud Hosting](https://www.atlantic.net/vps-hosting/what-is-private-cloud-hosting/).

### Private Hosting

Private hosting is a broad marketing term whose meaning varies between providers. It may describe a virtual private server, dedicated hardware, or a private cloud. Check what is reserved for your organization: a VPS can provide a separate operating system while sharing the physical server with other customers.

### Proxmox

Proxmox Virtual Environment, commonly called Proxmox VE, is an open-source platform for managing virtual machines and containers. It combines KVM virtualization and LXC containers with tools for storage, networking, backups, and clustering. Administrators use its web interface or command-line tools to manage hosts and workloads, with availability features dependent on the deployment design.

[Read more about Proxmox VE](https://www.proxmox.com/en/products/proxmox-virtual-environment/overview).

### Public Cloud

Public cloud provides computing services offered by a provider to many customers. Customers can provision resources such as virtual servers, storage, or managed applications without owning the underlying infrastructure. Physical resources are often shared, with access controls separating customer environments. “Public” describes service availability and does not mean that a customer's data is publicly accessible.

[Read more about Public Cloud](https://aws.amazon.com/what-is/public-cloud/).

## R

### Recovery Point Objective (RPO)

Recovery point objective describes the point in time to which data must be recovered after an outage. It is commonly expressed as an acceptable data-loss interval. An RPO of 15 minutes means planning to recover data to a point no more than 15 minutes before disruption.

[Read more about Recovery Point Objective (RPO)](https://csrc.nist.gov/glossary/term/recovery_point_objective).

### Recovery Time Objective (RTO)

Recovery time objective is the target time for restoring a system or service after disruption. An RTO of two hours means planning to resume the agreed service within that period. Recovery procedures must account for dependencies, data restoration, checks, and the people needed to complete the work.

[Read more about Recovery Time Objective (RTO)](https://csrc.nist.gov/glossary/term/recovery_time_objective).

## S

### Server Migration

Server migration moves a server's applications, data, or complete operating environment to another physical or virtual server. It may involve a hardware replacement, operating system change, or move to another hosting provider. The migration plan should cover compatibility, data synchronization, configuration changes, testing, service cutover, and recovery if the new environment does not work as expected.

[Explore Server Migration services](https://www.atlantic.net/managed-services/migration-services/).

### Server Virtualization

Server virtualization uses a software layer called a hypervisor to run multiple virtual machines on physical hardware. Each virtual machine has its own operating system and allocated resources. This allows workloads to share a server, while performance and isolation depend on resource allocation and configuration.

[Read more about Server Virtualization](https://www.atlantic.net/vps-hosting/what-is-server-virtualization/).

### Snapshot

A snapshot records the state of a storage volume or virtual machine at a particular time. It can provide a recovery point before a change or help create another environment. How snapshots are stored and restored varies between platforms. A snapshot is not automatically an independently protected backup; its usefulness depends on consistency, storage location, and retention.

[Explore Snapshot and Backup services](https://www.atlantic.net/cloud-platform/backups/).

### Software as a Service (SaaS)

Software as a Service delivers a provider-hosted application that customers access through a browser, client, or API. The provider manages the underlying infrastructure and application software. Customers typically control their data and available settings. Pricing may use subscriptions, usage charges, or other commercial arrangements.

[Read more about Software as a Service (SaaS)](https://www.atlantic.net/vps-hosting/what-is-saas-hosting/).

### Storage Area Network (SAN)

A storage area network connects servers to shared block storage through a specialized network. Technologies such as Fibre Channel and iSCSI carry storage traffic, allowing servers to access volumes as disks. Access controls and suitable file systems are needed when multiple servers use shared storage.

[Read more about Storage Area Network (SAN)](https://www.atlantic.net/dedicated-server-hosting/what-is-a-san/).

## V

### Veeam

Veeam is a provider of backup, recovery, and data-protection software and services. Its products protect supported virtual, physical, and cloud workloads, with capabilities such as scheduled backups, replication, and file-level restoration. Supported platforms and recovery options vary by product and license. A Veeam deployment still requires appropriate storage, access controls, monitoring, and restoration testing.

[Explore Managed Veeam services](https://www.atlantic.net/managed-services/veeam-services/).

### Virtualization

Virtualization uses software to represent physical computing resources as logical resources that can be allocated and managed separately. It can apply to servers, storage, networks, or desktops. Server virtualization uses hypervisors to run virtual machines, while other forms use different techniques. Resource sharing can improve utilization, but capacity planning and isolation remain important.

[Read more about Virtualization](https://aws.amazon.com/what-is/virtualization/).

### Virtual Machine (VM)

A virtual machine is a software-defined computer with virtual processors, memory, storage, and network interfaces. It runs its own operating system and applications, with a hypervisor managing access to the host's hardware. Multiple virtual machines can share one physical server, although their performance and isolation depend on the resources allocated and the virtualization configuration.

[Read more about Virtual Machines](https://aws.amazon.com/what-is/virtualization/).

### Virtual Private Server (VPS)

A virtual private server is a virtual machine used to host websites or applications. It has its own operating system and allocated computing resources, while the physical server may also host other customers’ virtual machines. The hosting plan determines which resources are shared and which are reserved.

[Read more about Virtual Private Server (VPS)](https://www.atlantic.net/vps-hosting/what-is-vps-buyers-guide-and-expert-tips/).

### VMware

VMware is a brand of virtualization and infrastructure software. Its technologies include the ESXi hypervisor, which runs virtual machines on physical servers, and vCenter Server, which manages virtualized environments. Specific capabilities, licensing, and supported configurations depend on the products and versions selected.

[Read more about VMware](https://www.atlantic.net/dedicated-server-hosting/what-is-vmware/).

### vSphere

vSphere is VMware's server virtualization platform, built around the ESXi hypervisor and centralized management through vCenter Server. It provides tools for managing virtual machines, hosts, storage, and networking. Capabilities such as live migration, high availability, and resource scheduling depend on the selected product entitlement, hardware compatibility, and configuration.

[Read more about vSphere](https://www.vmware.com/products/cloud-infrastructure/vsphere).

## W

### Web Server Hosting

Web server hosting supplies an environment for software such as Apache HTTP Server, NGINX, or IIS to deliver website content over HTTP and HTTPS. The environment may use shared hosting, virtual servers, or dedicated hardware. Responsibility for configuring and maintaining the web server depends on the service.

[Read more about Web Server Hosting](https://www.atlantic.net/dedicated-server-hosting/what-is-web-server-hosting/).

### Website

A website is a collection of related web pages and resources, usually accessed through a domain name. Its content may consist of stored files or be generated by applications and databases when a visitor makes a request. Hosting supplies the environment that delivers the site, while DNS helps visitors locate it.

[Read more about Website Hosting](https://www.atlantic.net/dedicated-server-hosting/what-is-web-server-hosting/).

### WordPress

WordPress is an open-source content management system used to create and manage websites. It provides an editing interface, themes for site design, and plugins for additional functionality. Self-hosted WordPress runs on a compatible web server with PHP and a MySQL or MariaDB database. Updates, access controls, and backups require ongoing attention.

[Read more about WordPress](https://wordpress.org/about/).

## Award-Winning Hosting Solutions & Services

Simple, Fast, Reliable Server Hosting

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# When Shared Hosting Is No Longer Enough for a PHP/MySQL Application

> URL: https://www.atlantic.net/dedicated-server-hosting/php-mysql-shared-hosting-migration/ | Published: 2026-05-07 | Author: Richard Bailey

PHP/MySQL applications frequently outgrow their shared hosting environment, especially because they typically start on a mainstream shared provider. Atlantic.Net engineers commonly handle PHP/MySQL migrations from shared to private hosting.

Recently, our engineering team helped a customer migrate their PHP/MySQL application from a modest GoDaddy plan that was once ideally sized, but now fell short. 

GoDaddy served the customer well, but over several years, the application grew, the database grew, and Stripe integrations and background jobs were added. The hosting plan did not change, and as a result, issues started to creep in; report pages took longer to render, cron jobs overran their start windows, and some outbound API calls timed out under load. Such examples are often hosting-tier problems, not necessarily application defects, but it’s not uncommon for the two to be routinely confused.

Using this scenario as a foundation, this article covers the real-world decisions our engineers help customers make when moving a production PHP/MySQL application to managed dedicated infrastructure: hardware sizing, PHP version strategy, the cPanel-or-not question, and the four workstreams that account for most post-cutover problems: email, database integrity, outbound API reliability, and DNS.

## Why Shared Hosting Became the Bottleneck

Shared hosting is sized for large numbers of small, predictable workloads on a single machine. GoDaddy and other mainstream providers have run low-traffic brochure sites, static portfolios, and small ecommerce stores reliably on this model for years. A PHP/MySQL application with a real database, real concurrency, and background jobs may often require a different class of tenant.

Three things happen as the application grows past the tier:

- **Resources stop being predictable.** A shared server packs dozens or hundreds of tenants onto the same hardware. When a neighbor’s cron job runs, or a neighbor’s site is crawled, the application’s query times can be impacted.
- **Background and CPU-intensive work gets throttled.** Shared plans cap execution time, memory per process, and concurrent connections. A report that runs in a single query on a dedicated server may need to be split into five smaller queries on a shared server and risk timing out on a long join or failing on a subsequent cron iteration.
- **Outbound reliability degrades under load.** Applications calling Stripe, email APIs, or payment gateways need steady outbound connectivity. Shared tenants share outbound IP reputation and rate limits, so a percentage of timed-out checkouts may appear to be a payment-provider issue when the real cause is more likely a shared-IP reputation problem or overloaded outbound infrastructure.

## The Hardware Profile for a Business-Critical PHP App

A PHP/MySQL application handling payments, large queries, and background jobs at a moderate scale typically needs more capacity than developer briefs initially suggest. A production-appropriate profile for this class of workload would typically be:

- **128 GB of RAM** so the MySQL InnoDB buffer pool can hold the working set of a 15 GB database in memory, with room for PHP-FPM, the operating system, and application caches.
- **2 × 1 TB NVMe in RAID 1** (or an equivalent mirrored configuration) for fast local storage with disk-level redundancy.
- **At least 1 Gbps network** for API chatter and the bandwidth volume generated by a few hundred GB of outbound Stripe traffic per month.
- **Modern Intel Xeon or AMD EPYC** processors with strong single-thread performance, because PHP serves a request on a single core, and MySQL’s execution stage is often single-threaded per query.

Meaningful sizing guidelines need to focus on CPU-bound or I/O-bound workloads on the database. Most PHP/MySQL applications at this size benefit more from NVMe storage and a generous buffer pool than from a faster processor. But hardware is only the starting point.

A database-heavy PHP application also needs professional MySQL or MariaDB tuning: an appropriately sized InnoDB buffer pool, enough connections for the PHP-FPM worker model, slow-query logging during the stabilization period after cutover, and storage settings aligned with NVMe rather than older spinning-disk assumptions. The right hardware choices create the headroom for the application, and tuning determines how much of that headroom the application uses.

## PHP 7.4 Is a Legacy Dependency, Not a Supported Choice

Any long-running PHP application faces a versioning question during migration. Applications in production for several years are often still on PHP 7.4, which reached [end of life](https://www.php.net/eol.php) on 28 November 2022. PHP.net has issued no security updates for it in over three years. For a payment-processing application in 2026, PHP 7.4 is not a supported runtime — it is a legacy dependency.

Hosting an application on PHP 7.4 in the short term is possible, but only as a bridge while the code is modernized. A managed provider may be able to support legacy PHP through hardened or specially maintained builds, but that should be treated as a temporary compatibility measure rather than a long-term hosting tier. The goal is to keep the application stable, reduce immediate migration risk, and give the development team time to move the codebase onto a supported PHP 8.x release. The migration plan should name a modernization target date from the first conversation, so PHP 7.4 does not quietly become the new permanent state.

A current PHP 8.x release should be your starting point, with the exact minor version chosen by application compatibility and the hosting provider’s supported stack. Modernizing as part of the migration, rather than deferring the problem.

- Target a server that runs a vendor-supported PHP version from day one.
- Choose a provider that is not constrained by legacy-PHP availability.
- Ensure any payment-processing application does not rely on an end-of-life PHP runtime.

For applications where the code change is complex, the practical sequence is a migration to managed dedicated infrastructure on CloudLinux Hardened PHP 7.4 as a short bridge, with a committed modernization project running alongside, cutting over to PHP 8.x on the same server once the code is ready. The bridge should be measured in weeks, not years.

## The Workstreams That Get Forgotten

Sizing, PHP version, and operating system are the visible parts of the migration. Four less-visible workstreams account for most late-stage problems:

- **Email.** A move changes the outbound IP reputation. Applications sending transactional email need SPF updated for the new sending infrastructure, DKIM keys staged on the new host before cutover, and DMARC temporarily softened to p=none during IP warm-up before tightening back. Mailbox data does not migrate itself either: IMAP sync, mail-server cutover, and the DNS MX change need to be sequenced.
- **Database integrity.** A 15 GB production database is small enough for a controlled dump-and-restore, but not casually. Migrations can be performed using mysqldump, a Snapshot hot copy, or a staged cutover with a brief read-only window. You should work with the hosting provider to choose an approach based on write volume, acceptable downtime, the storage engine, and consistency requirements.
- **Stripe and outbound API reliability.** Payment-processing applications depend on reliable outbound HTTPS to Stripe and equivalent services. Outbound connectivity on managed dedicated hosting is typically a non-event, but should be confirmed rather than assumed. Work with your provider to test the outbound stability.
- **DNS.** A change of IP is a DNS change, and a DNS change is a propagation window. Short TTLs set before cutover, a well-rehearsed record change on the night of the move, and monitoring of propagation should be part of the migration planning.

## Why Migration Discovery Matters

Shared hosting environments often depend on details that are not obvious from the outside. A site may rely on custom PHP extensions, specific Apache or LiteSpeed rewrite rules, email account settings the customer no longer has documented, or .htaccess behavior that only works because of undocumented server configuration.

Proper migration discovery catches these issues before the quote is finalized. That means reviewing the current PHP configuration, loaded extensions, DNS records at both the registrar and the existing host, cron jobs, mail settings, and any hosting-level dependencies the customer may have forgotten about. The result is a quote that reflects the real work required, and a cutover that is far less likely to produce late-night surprises.

## What “Fully Managed” Should Include

When choosing your next hosting provider, understand what “[Fully managed](https://www.atlantic.net/managed-services/)” really means. Does it include cPanel management, additional managed services, and 24/7 engineering support?

For a business-critical PHP/MySQL application, the minimum recommended Managed Service should be:

- **OS patching and security updates** on a regular cadence
- **Managed firewall** with ruleset updates, port management, and brute-force protection via Fail2ban or equivalent
- **24/7 monitoring and alerting** on the host and core services
- **Off-server backups** with daily full backups, a reasonable retention window, and both file- and database-level restore options
- **Response-time commitments** during business hours and out of hours, such as a [100% Uptime SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/).
- **Migration assistance** covering the cutover sequencing, DNS, and email

You should also consider if any additional professional services are needed before or after the migration. Consider discussing these points with your prospective provider:

- **Is Application-Level Support Available?.** Code debugging, schema work, and application performance tuning are paid consulting, not standard managed services.
- **Do you provide Database Administration?** Index tuning, query performance work, and replication setup are often a separate service line.
- **Is Advanced Managed Security an Option?** Web application firewalls, vulnerability scanning, and intrusion detection are common add-ons.

A proposal that itemizes these makes the monthly bill easier to predict and easier to trim if a specific line is not needed.

## How Atlantic.Net Approaches the Migration

Atlantic.Net is an expert at migrating almost any workload to either our dedicated or cloud hosting platforms. We welcome you to reach out to our skilled engineers to discuss your requirements.

Our first interactions with the customer are usually grounded in fact-finding, with the aim of providing the customer with the facts of how Atlantic.Net hosting and our vast range of managed services can improve the reliability, performance, and stability of the customer’s critical PHP/MySQL applications.

Here are the typical questions we would ask:

1. **What is the current shared environment**?
 Typically, GoDaddy or a similar mainstream shared host — and what does it expose: OS, PHP version, cPanel or other control panel, email volume, database size, outbound traffic?
2. **What is the target CPU and memory profile?**
 Based on the database working set and the concurrency, what does the application see?
3. **Is the application already on PHP 8.x?******If still on PHP 7.4, what is the modernization timeline, and does the migration need a short CloudLinux Hardened PHP bridge?
4. **Do you still need cPanel?**
 Does cPanel need to come along, or can the environment run on plain, one-click Ubuntu LTS?
5. **What sits on the DNS, email, and API dependency list?**
 These are just the introductory due diligence questions we will ask to determine if the client needs to be rehearsed before cutover.

We use the initial due diligence to create a plan for a potential hardware configuration, a managed-services package, a backup plan, and a fixed monthly cost. Atlantic.Net scopes the environment around the application’s actual footprint, the RAM for the database working set, NVMe sized for files and database growth, cPanel and CloudLinux licensing where required, managed firewall and monitoring, backup retention tuned to recovery targets, and migration assistance covering files, database, email, DNS, and cutover. The final environment may be dedicated bare-metal or a Private Cloud, depending on performance, management, and isolation requirements.

## Moving Forward

A PHP/MySQL application outgrowing shared hosting is a healthy problem — it’s doing enough work to justify better infrastructure. The work that separates a clean migration from a painful one is the work done before the first file moves: honest sizing, a PHP version strategy, the cPanel-or-not decision, and a migration plan that names email, database integrity, Stripe connectivity, and DNS as separate workstreams.

To scope a specific migration, share the current shared-hosting footprint — PHP version, database size, email volume, outbound dependencies — with the [Atlantic.Net solutions team](https://www.atlantic.net/about-us/corporate-contact/).


---

# Bare Metal Cloud vs. Traditional Dedicated Servers

> URL: https://www.atlantic.net/about-us/bare-metal-cloud/ | Updated: 2026-09-16

A guide for AI workloads.

## Download this helpful guide to:

- Understand the benefits of bare-metal cloud vs. dedicated hosting: learn how both bare-metal cloud and traditional dedicated servers provide single-tenant physical hardware for AI workloads, but bare-metal cloud is more automated, API-driven, and elastic, while traditional dedicated servers are more fixed, manually provisioned, and predictable.
- Apply the best-fit solution to your use cases: explore how bare-metal cloud is positioned as the better choice for short-lived training bursts, rapid experimentation, CI/CD benchmarking, and unpredictable inference spikes, while dedicated servers are better for stable, long-running workloads with consistent utilisation and simpler budgeting.
- Know whether a hybrid model is best for you: your organisation may benefit from a hybrid model that uses dedicated servers for steady baseline workloads and bare-metal cloud for burst capacity, temporary projects, or scaling AI/ML experiments.


---

# How SSL/TLS Certificate Providers Work: A Technical Overview (2026)

> URL: https://www.atlantic.net/managed-services/how-ssl-tls-certificate-providers-work/ | Published: 2026-05-08 | Author: Editorial Team

Every login, checkout, and API call on the public web depends on the same trust assumption: that the server on the other end is who it claims to be, and that the bytes in transit cannot be read or altered. SSL/TLS certificates enforce that assumption, and the entities issuing them — Certificate Authorities — are some of the most consequential infrastructure providers on the internet.

Although the protocol itself is now TLS (Transport Layer Security), the certificates are still universally referred to as SSL certificates. The name persists; the cryptography has moved on.

This article is not a ranked product list. It is a technical look at what Certificate Authorities actually do, how they fit into Public Key Infrastructure (PKI), the trust models they operate under, and how the CA market is changing in 2026.

## What a Certificate Authority Actually Does

A Certificate Authority (CA) is a trusted third party that signs digital certificates that bind a public key to a verified identity — usually a domain, sometimes an organization, or an individual. CAs are not just certificate sellers. They are operators of trust.

A CA’s core responsibilities:

- **Issuing digital certificates.** Binding a public key to a verified identity, such as a domain, organization, or individual.
- **Establishing trust chains.** Building certificate hierarchies that link end-entity certificates back to root certificates pre-installed in browsers and operating systems.
- **Validating identity.** Checking, at varying levels of rigor, that the requester actually controls the domain or represents the organization on the certificate.
- **Maintaining revocation infrastructure.** Running Certificate Revocation Lists (CRLs) and Online Certificate Status Protocol (OCSP) responders to enable clients to detect compromised or revoked certificates.

Browsers ship with a fixed list of root certificates. Inclusion in that list — the root store — is what makes a CA commercially viable. A CA that loses root trust in major browsers loses its business overnight, which is why CAs operate under strict baseline requirements set by the CA/Browser Forum.

## CAs in the Public Key Infrastructure Model

To see why CAs matter, it helps to place them in the wider PKI picture. PKI is the framework that enables two parties who have never met to communicate securely over a network that neither of them controls.

In PKI, trust is hierarchical:

- **Root CAs** sit at the top, with self-signed root certificates embedded in browser and OS root stores.
- **Intermediate CAs** are signed by the root and used to issue certificates to end entities. Roots are kept offline; intermediates handle day-to-day signing.
- **End-entity certificates** are the certificates that websites present to clients during the TLS handshake.

When a browser connects to a site, it walks the certificate chain back to a trusted root. If every signature checks out and no certificate in the chain has been revoked, the connection is trusted.

This chain model is why CAs are central to web security. They are the trust anchors. A compromised intermediate or a misissued certificate is a serious incident, which is why incidents like the DigiNotar collapse in 2011 and the Symantec distrust in 2018 reshaped the industry.

## Validation Tiers: DV, OV, and EV

CAs offer different validation tiers, and the differences matter more than the marketing usually suggests. They reflect different definitions of what “trust” means.

Domain Validation (DV) confirms only that the requester controls the domain, typically via an email challenge, a DNS record, or an HTTP file. Issuance is fast and fully automated. DV says nothing about who is behind the domain.

Organization Validation (OV) confirms domain control plus the existence of the requesting organization, typically by checking business registries and publicly listed contact details. Issuance takes longer and embeds verified organization details in the certificate.

Extended Validation (EV) adds documented legal, physical, and operational checks defined in the CA/Browser Forum EV Guidelines. EV was once distinguished by a green address bar; modern browsers no longer treat EV any differently in the URL bar, which has reduced its visible value but not its evidentiary value in regulated industries.

In practice, DV demonstrates technical control, OV demonstrates organizational existence, and EV demonstrates legal accountability. Most public web traffic now runs on DV. Regulated workloads — such as banking portals, payment systems, and government services — still favor OV and EV.

## How the CA market Has Changed

The CA market in 2026 looks very different from what it was a decade ago. Several forces are reshaping it:

- **Shorter certificate lifetimes.** The maximum public certificate validity has been repeatedly reduced — from 3 years to 2 years to 398 days — with the CA/Browser Forum and major root programs now driving toward 90 days. Shorter lifetimes shrink the blast radius of a key compromise and force automation.
- **The ACME protocol.** The Automated Certificate Management Environment (ACME), originally developed for Let’s Encrypt, is now a standard. Issuance, renewal, and installation can run end-to-end without human input.
- **Certificate Transparency.** Every publicly trusted certificate must now be logged to multiple append-only CT logs. Domain owners can monitor the logs for unauthorized issuance, and browsers reject certificates that aren’t logged.
- **Post-quantum readiness.** NIST has standardized initial post-quantum algorithms (ML-KEM, ML-DSA, SLH-DSA), and CAs are beginning hybrid issuance trials. Production-grade post-quantum certificates for the public web are still on the horizon, not yet routine.
- **Zero trust.** Internal PKI is no longer a back-office concern. CAs are increasingly issuing short-lived certificates for service-to-service authentication in zero-trust architectures, where every connection is verified rather than relying on network position.

## Categories of SSL Providers

Ranking CAs head-to-head misses the more useful distinction: they operate under different business and trust models. Four categories cover most of the market.

1. **High-Assurance Enterprise CAs** Examples: DigiCert, Entrust, GlobalSign, and Sectigo’s enterprise tier.

These providers focus on rigorous OV and EV issuance, document signing, code signing, and certificate lifecycle management for large estates. They sell into banking, healthcare, government, and any environment where misissuance carries regulatory or legal consequences. Cost is secondary; auditability and process maturity are the product.

1. **Scalable Commercial CAs** Examples: GoDaddy, Sectigo’s retail tier, Network Solutions.

These CAs issue at volume, primarily DV with some OV, and bundle certificates with hosting, domains, and other web services. The validation is standardized rather than rigorous. Trust here is mass-produced — the certificate confirms the connection is encrypted, not who is on the other end.

1. **Automated and Open CAs** Examples: Let’s Encrypt, ZeroSSL, Google Trust Services, Buypass Go.

These providers redefined the market. Certificates are free or near-free, issued via ACME, and renewed automatically. Validation is purely DV. The model treats trust as control over digital assets rather than as verified identity, which is why TLS is now effectively universal on the public web.

1. **Hybrid CAs.** Many providers — including Sectigo and DigiCert — span more than one category. They offer free or low-cost DV alongside OV and EV, and they sell to both individual site owners and large enterprises through the same root infrastructure.

## Where SSL Providers Are Heading

Several shifts are likely to define the next few years of the CA market:

- **Post-quantum migration.** Hybrid certificates combining classical and post-quantum signatures will move from pilots to production. The transition will be measured in years, not months, because root stores, libraries, and hardware must all follow.
- **Full automation as default.** Manual issuance is becoming a liability. With validity periods trending toward 90 days, any workload not on ACME or an equivalent automated workflow is one missed renewal away from an outage.
- **Convergence with digital identity.** CAs are starting to interoperate with decentralized identity frameworks and verifiable credentials, particularly in the EU under eIDAS 2.0. The line between a TLS certificate and a verifiable identity assertion will blur.
- **Continuous trust validation.** Static trust — issued once, valid for a year — is giving way to short-lived certificates and continuous attestation, especially in zero-trust environments.

## Choosing a Certificate for a Hosted Workload

For most public-facing websites, a free DV certificate from an automated CA is the right answer. For a regulated workload — anything storing payment data, electronic Protected Health Information (ePHI), or other sensitive records — OV or EV from a high-assurance CA is usually expected by auditors and easier to defend.

Atlantic.Net includes free SSL with all dedicated server plans and supports certificates from any CA in the cloud, as well as HIPAA-compliant hosting environments. The choice of certificate is independent of where the workload runs; what matters is that the validation tier matches the regulatory and trust requirements of the application sitting behind it.

CAs are not interchangeable vendors. They sit at the foundation of how the web decides who to trust, and the differences between them — validation rigor, automation maturity, root store inclusion, post-quantum readiness — translate directly into the security posture of every site that depends on them.


---

# Choosing Between Bare Metal and Dedicated Hosting for Healthcare Compliance

> URL: https://www.atlantic.net/hipaa-compliant-hosting/choosing-between-bare-metal-and-dedicated-hosting-for-healthcare-compliance/ | Published: 2026-05-08 | Author: Dr. Tehseen Zia

Healthcare organizations need to be careful when choosing their hosting solutions. Sensitive patient data and complex regulations make security and compliance crucial. The right hosting environment can help healthcare providers comply with strict regulations and deliver safe, reliable services. Bare metal and dedicated hosting often stand out as strong options for healthcare compliance. Understanding the differences and knowing what matters most is key to making the best decision.

## The Core Distinction: Control vs. Convenience

At its core, the choice between bare metal and dedicated hosting in healthcare comes down to a trade-off between full control and managed convenience. Both models provide a dedicated physical server for a single customer. This isolation is the first and most important step away from the shared, multi-tenant risks of standard virtualized cloud servers. In a shared environment, the activities of one tenant can potentially impact the security and performance of others, a risk that is unacceptable when handling sensitive health information. A dedicated server, whether bare metal or managed, eliminates this “[noisy neighbor](https://www.techtarget.com/searchcloudcomputing/definition/noisy-neighbor-cloud-computing-performance)” problem, providing a hardened, isolated environment from the ground up.

## Bare Metal Hosting: Maximum Control and Performance

Bare metal hosting represents the purest form of dedicated infrastructure. You have direct access to physical hardware. There is no underlying hypervisor, which is the software layer that creates and runs virtual machines. This direct access translates to raw performance and total control for healthcare applications that demand high computational power, such as medical imaging, genomic research, or complex data analytics. Bare metal servers deliver unparalleled efficiency. For example, providers like Atlantic.Net offer [bare-metal hosting services](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) tailored for such demanding environments, with [HIPAA-compliant](https://www.atlantic.net/hipaa-compliant-hosting/) setups, extensive hardware customization, and options for high-speed NVMe SSD storage to guarantee top-tier performance and reliability.

In bare metal hosting, you can fine-tune every aspect of the server, from the BIOS settings to the operating system, to meet the exact specifications of your applications. This granular level of control is often necessary to enforce HIPAA-required security policies. You know exactly which software is running and can configure it to meet stringent access-control and audit-trail requirements.

## Dedicated Hosting: Managed Convenience

Dedicated hosting, in the way most providers describe it, refers to a managed service. You still get a physical server allocated entirely to you, but the hosting provider takes responsibility for the hardware, its availability, and often the underlying operating system. That model lifts the operational work of patching, monitoring, and maintaining the physical layer from your in-house team. For many healthcare providers — especially those without large infrastructure teams — the managed approach is a real practical advantage. Clinical and administrative staff can focus on patient care rather than firmware updates and uptime monitoring, while the provider keeps the platform stable and secure.

## Healthcare Compliance and the Shared Responsibility Model

When mapping these options to healthcare compliance, the shared responsibility model matters more than the labels. HIPAA does not mandate a particular technology. It sets rules for safeguarding electronic Protected Health Information (ePHI). Both bare metal and dedicated hosting can support HIPAA compliance, but the responsibilities are split differently between the two.

With a bare-metal server, your organization takes on a larger share of the work. That includes securing the operating system, configuring firewalls, applying encryption, managing user access, and maintaining detailed audit logs. Those tasks call for specialist in-house knowledge.

With a managed dedicated server, the provider takes on more of that load. A provider experienced in healthcare hosting provides a baseline of security that covers physical access controls, network protection, and operating system hardening. That partnership can shorten your route to compliance — provided the provider is willing to sign a HIPAA Business Associate Agreement (BAA). The BAA is a non-negotiable HIPAA requirement that legally binds the provider to its security and privacy obligations. Atlantic.Net, in business since 1994, has built its services around regulatory standards, including HIPAA, HITECH, SOC 2 Type II, and PCI-DSS 4.0, and signs a BAA as part of every HIPAA-compliant engagement.

## Making the Right Choice for Your Organization

The decision between these two models often boils down to your internal resources and specific application needs. Choose a bare metal server if your healthcare organization has a strong, experienced IT security team that requires maximum performance and granular control over the entire software and hardware stack. This is typical for large hospital systems or research institutions developing custom applications. Choose a managed dedicated server if you are a hospital, clinic, or health tech startup that needs the security and performance of dedicated hardware but prefers to offload the operational complexity of infrastructure management. This allows you to deploy electronic health record systems, patient portals, and telehealth platforms more quickly.

## The Importance of Support

Support is another critical differentiator, particularly during a security incident or unexpected outage. In healthcare, when patient care systems are down, every minute matters. Direct access to skilled support engineers who understand both the urgency and the compliance requirements can make a significant difference. A provider like Atlantic.Net, with U.S.-based support and 24/7 technical assistance, can ensure clearer communication and a stronger alignment with HIPAA obligations during critical situations.

## The Bottom Line

Neither bare metal nor dedicated hosting is the universally better choice for healthcare compliance. The right path depends on your organization’s technical capabilities, performance requirements, risk tolerance, and the scope of your environment — whether that is a HIPAA-compliant WordPress site or a full healthcare IT platform. Bare metal hosting gives the power and control to those equipped to manage it. Managed dedicated hosting gives healthcare organizations access to secure, compliant infrastructure without the operational burden of running it themselves.

The deciding factor is not the label on the service but how well it supports your compliance posture. Choose a provider with a proven record in healthcare hosting, clear accountability for its responsibilities, and an isolated environment built to protect ePHI. Atlantic.Net brings that combination — a dedicated foundation for healthcare workloads, independently audited HIPAA, HITECH, SOC 2 Type II, and PCI-DSS 4.0 environments, and a 100% uptime SLA backed by a signed BAA.


---

# Managed Windows and Microsoft SQL Server Hosting: How Atlantic.Net Answers an RFQ

> URL: https://www.atlantic.net/cloud-platform/managed-windows-sql-server-hosting-rfq/ | Published: 2026-05-12 | Updated: 2026-05-10 | Author: Richard Bailey

Continuing our series of request-for-quote deep dives, this article looks at a recent managed Windows hosting RFQ reviewed by the Atlantic.Net pre-sales team. The request covered a migration involving Windows Server, Microsoft SQL Server, and SmarterMail in a single managed environment.

An RFQ is the formal document a buyer sends to hosting providers when comparing migration options. It typically sets out the required compute, storage, networking, licensing, security, backup, support, and pricing expectations, then asks each provider to respond line by line. For buyers, the value is not just in whether a provider says “yes” to each requirement, but in how clearly they explain what is included, what is conditional, and what falls outside the managed scope.

In this case, the customer was a small IT consultancy running a hosting reseller business on the East Coast. The existing managed cloud VM had become less predictable: performance was inconsistent, support response had declined, and monthly costs had increased. The customer wanted to move a Windows Server, Microsoft SQL Server, and SmarterMail stack to a new managed hosting provider within a few weeks.

On paper, many managed hosting proposals can look similar. Daily backups, managed firewalls, 24x7x365 support, IPv4 allocation, security tools, and multi-year discounts are common line items. The difference is in the detail. A credible RFQ response explains where the platform is strong, where support boundaries apply, how pricing works, and what trade-offs the customer should understand before migration begins.

Atlantic.Net’s response covered storage redundancy, firewall capabilities, backup policy, support response targets, multi-year pricing, migration-phase pricing, data center selection, and the support boundary around SmarterMail. The sections below walk through those categories and show how a managed Windows and Microsoft SQL Server hosting quote can be evaluated line by line.

## What Atlantic.Net Can Deliver from Day One

Atlantic.Net offers cloud deployments on shared infrastructure and dedicated hosts. We also have a unique set of managed services that can be wrapped around the customer’s environment.

Storage and redundancy. The cloud platform runs on [NVMe SSD storage](https://www.atlantic.net/press-releases/atlantic-net-unveils-ssd-cloud-vps-hosting-platform-100-times-faster-speed/https://www.atlantic.net/press-releases/atlantic-net-unveils-ssd-cloud-vps-hosting-platform-100-times-faster-speed/) with RAID 10 at the local storage level and cluster-level redundancy above it. The platform is designed for high availability. Planned host maintenance can be handled through VM migration, while host-failure behavior depends on the underlying cluster design and may involve failover. Storage is encrypted at rest. The configuration scoped to this customer’s brief was 8 vCPU, 64 GB RAM, and 400 GB of NVMe SSD storage.

IPv4 and IPv6. A /29 IPv4 allocation and full IPv6 support are included at no extra charge on this configuration. The customer had asked about IPv6 filtering in the context of firewall rules; the answer was that both IPv4 and IPv6 are handled by the [managed FortiGate firewall.](https://www.atlantic.net/managed-services/firewall/)

Operating system and database. The customer wanted Windows Server 2025 and SQL Server 2022. Both were supported for the scoped environment. SQL Server 2022 Web Edition is supported for eligible hosted web workloads, subject to Microsoft service-provider licensing terms.

Firewall. The managed firewall is [FortiGate-based](https://www.atlantic.net/managed-services/firewall/)and is fully managed by the Atlantic.Net 24x7x365 US-based support team. The customer specifically asked about both geographic and IPv6 filtering. Custom allow and deny rules can be configured, and country-level geo-blocking is supported.

DDoS. DDoS mitigation runs via Cloudflare. The Atlantic.Net data centers are directly peered with Cloudflare, which matters for both latency and reliability during an active mitigation event.

Endpoint security. The [Trend Micro Security Suite](https://www.atlantic.net/managed-services/trend-micro-deep-security-suite/) provides protection against malware and ransomware, as well as endpoint protection. This runs as a managed layer, not a self-managed installation.

Backups. Daily managed backups are included, with file-level restore capability. Backup storage runs on separate storage nodes, not the same physical storage as the VM, and is encrypted at rest. The combination of cluster-level VM redundancy and a separate encrypted backup tier means the customer has two distinct layers of data protection rather than a single system doubling as both.

## How Atlantic.Net Handles Support Response Targets

Support response time is one of the most-requested items in a managed-hosting RFQ and one of the most inconsistently answered. Many providers publish response-time SLAs as hard contractual commitments with remediation clauses; others qualify them so heavily in the body of the contract that the headline number is effectively meaningless. Atlantic.Net’s approach is different, and it is worth explaining why.

Atlantic.Net publishes Service Level Objectives for support response times. The targets are: Critical issues: 15 minutes; High severity: 1 hour; Normal requests: 4 business hours. Phone calls are prioritized over portal-submitted tickets, particularly when an issue is active and service-impacting.

The reasoning is operational rather than legal. Support response handling depends on the nature of the issue, the accuracy of the priority the customer assigned, the depth of investigation the issue requires, and whether the ticket is tied to an active service-impacting event or a routine change request. A rigid SLA that commits to a 15-minute response regardless of those variables creates the wrong incentives: it rewards fast first-contact acknowledgment over competent triage, and it penalizes the team for being honest when an investigation exceeds the SLA window.

An SLO is an operational target that the team manages against. It exists to be met consistently. Pairing that with US-based phone-priority routing for active issues means that the customer who calls with a production problem reaches a technician who can actually work the issue, rather than a ticket queue that has already missed its first-response window.

For customers who have come from providers with rigid SLA structures and found that the legal commitment didn’t translate into faster resolution, that distinction may be more meaningful than it first appears. The commitment here is to the outcome. Atlantic.Net’s[Cloud Service Level Agreement](https://www.atlantic.net/cloud-service-level-agreement/) covers infrastructure-layer availability separately; the 100% SLA on network, hardware, and power is a distinct and contractual commitment. The SLO framework applies to support response.

## What We Can and Cannot Do

Two requests in this RFQ received direct negative answers. Both are worth recording in full because providers who decline are easier to plan around than those who hedge.

No migration-phase discount. The customer asked twice. The first ask was a standard request for a reduced rate during the migration window. The second was to start on a smaller configuration during migration, scale to the full spec at go-live, and apply the discount to the smaller-configuration period. Atlantic.Net presented the best available customized options. Atlantic.Net offers a 10 percent discount on a 24-month commitment and a 20 percent discount on a 36-month commitment. Those discounts apply throughout the term of the agreement.

Atlantic.Net offers a discount structure that is tied to the full agreement term rather than a temporary migration period. Atlantic.Net’s role during a migration is to deliver a fully configured environment on day one from the delivery date, which requires the full specification from the start. A reduced-spec migration environment that must be reconfigured at go-live adds a change event to what is already a complex transition period. The discount structure Atlantic.Net offers is applied to the commitment term, not to a partial service period. Regardless, [Atlantic.Net](http://atlantic.net) stands ready to assist clients with a customized solution that is a win-win for all.

No data center pricing or capability differential. The customer asked whether Ashburn, Virginia, or New Jersey offered better pricing or capabilities for their use case. The answer was no: for this scoped configuration, Ashburn, Virginia, and New Jersey offered the same capabilities at the same price. The customer can choose the location that best fits their geography, latency requirements, or client base, and they will get the same configuration at the same price either way.

For a small to mid-size reseller managing a portfolio of client environments, predictability has genuine value. Uniform pricing is a simpler model to plan around.

## SmarterMail

Atlantic.Net does not normally provide full application-level support for SmarterMail from the outset; , we were more than happy to install SmarterMail and configure it for the customer’s environment. Atlantic.Net’s Migration Assistance Team can assist with mailbox and domain configuration migration from the previous provider. The caveat is that ongoing application-level support for SmarterMail is limited.

What that means in practice: the managed environment covers the layers that Atlantic.Net operates. Windows Server, IIS, the SQL Server instance on which SmarterMail depends, the FortiGate firewall, OS-level patching, daily backups, and the Trend Micro endpoint suite.

All of those layers are fully managed. SmarterMail itself sits on top of that infrastructure. The customer brings the SmarterMail license, and either the customer or SmarterTools’ own support team leads on application-level questions: delivery rules, spam filter configuration, webmail interface issues, domain-specific mail routing, and anything that requires knowledge of SmarterMail’s internal configuration model.

Setting up the right expectation was a sensible choice for both sides. The customer running SmarterMail for a portfolio of reseller clients typically knows the application well enough to manage it at the application layer. What they need from a managed host is a stable, well-secured, well-patched foundation underneath it, and that is exactly what is in scope. A provider that promises full SmarterMail application support without a SmarterTools certification to back it up may find that commitment does not hold under complex domain configurations or during a version upgrade. Stating the right expectations up front avoids that problem entirely.

## What the RFQ Looks Like as a Production Configuration

The customer joined Atlantic.Net this year and is currently running from the Ashburn, Virginia, data center. The production configuration is 8 vCPU, 64 GB of RAM, and 400 GB of NVMe SSD storage. Storage uses RAID 10 at the local storage level, with cluster-level redundancy across the platform and encryption at rest. Planned host maintenance can be handled through VM migration, while host-failure behavior depends on the underlying cluster design and may involve failover. A /29 IPv4 allocation and full IPv6 support are included with the configuration.

The operating environment is Windows Server 2025. Microsoft SQL Server Web Edition 2022 runs on the same managed basis. The FortiGate-managed firewall provides IPv4 and IPv6 filtering, custom allow and deny rules, and country-level geo-blocking, fully managed by Atlantic.Net’s 24x7x365 US-based support team. The Trend Micro Security Suite provides malware and ransomware protection, as well as endpoint protection. DDoS mitigation runs through Cloudflare via the direct peering at the Atlantic.Net data center. Daily managed backups with file-level restore are stored on separate encrypted storage nodes.

SmarterMail installation and configuration were included. Support runs 24x7x365, is US-based, and response SLOs are 15 minutes for Critical, 1 hour for High, and 4 business hours for Normal. The[Atlantic.Net managed cloud hosting](https://www.atlantic.net/cloud-hosting/) platform carries a 100% SLA on infrastructure availability.

## Reading the Quote You Receive

A managed-hosting RFQ response is, in the end, a document that has to survive contact with a real production environment.

Atlantic.Net’s response to this customer’s RFQ is a worked example of what that pattern looks like across a Windows, Microsoft SQL Server, and SmarterMail stack. The caveat in SmarterMail names the boundary in terms of what is and is not managed. A customer can set that document next to two or three competitor responses and read each provider’s pattern instead of just totaling the bullet points.

If you are evaluating Atlantic.Net for a similar Windows stack migration, walk us through your application stack, storage and redundancy requirements, firewall and backup expectations, preferred data center, and the multi-year commitment you are willing to make. Atlantic.Net’s pre-sales team [can review the requirements line by line](https://www.atlantic.net/about-us/corporate-contact/) and define what is included, what is conditional, and where support boundaries apply.

 


---

# Microsoft Cloud Cost: Azure Pricing, Services, and Savings

> URL: https://www.atlantic.net/cloud-platform/microsoft-cloud-cost-azure-pricing-savings/ | Published: 2026-05-13 | Updated: 2026-05-10 | Author: Robert Agar

This article examines the services, pricing, and cost strategies available to organizations using Microsoft Azure. Microsoft cloud costs are the total monthly or annual spend on Azure services. These costs are driven by factors such as usage, licensing, and architectural choices rather than the fixed infrastructure costs of traditional data centers.

Components of Azure cloud costs include:

- Compute to support VMs and containers;
- Storage for objects and backups;
- Networking for data transfer;
- Platforms and services for analytics and AI;
- Licensing for Windows, SQL Server, and Microsoft 365.

The Azure cloud lets customers pay for the resources they use as they use them. Businesses can avoid paying for idle data center resources during anticipated usage peaks and be prepared for changes in business needs.

## How Azure Pricing Works and the Pay-As-You-Go Model

One of the most attractive aspects of Azure cloud services is the elimination of upfront hardware costs for setting up an IT environment. The pay-as-you-go pricing option allows customers to only pay for the Azure resources they actually consume. Teams can fine-tune usage for substantial savings, while companies can quickly scale resources to meet evolving business demands.

Azure offers resource-based billing for essential components, including compute, storage, and network. Customers can choose from different performance levels and tiers that align with operational realities while remaining cost-effective.

Regional pricing and currency conversion can significantly impact Azure costs. The same workload can be priced differently based on factors such as the deployment region, billing currency, exchange rate, taxes, and data residency requirements. Azure prices across regions are affected by issues such as local energy costs, regional demand, hardware availability, taxation, and currency fluctuations.

## Azure Pricing Calculator: How To Estimate Costs

The[Azure pricing calculator](https://azure.microsoft.com/en-us/pricing/calculator/) is a free tool from Microsoft that helps customers estimate the monthly cost of Azure services. The calculator enables users to configure products and services, such as virtual machines, databases, or storage. They can select regions and evaluate different usage tiers to generate real-time cost projections.

Azure’s pricing calculator is menu-driven and easy to use. Customers select an Azure resource from the left-hand panel, such as storage or compute, and then choose specific related services that they want to add to the environment. The upfront and estimated monthly costs are displayed immediately at the top of the calculator screen. Teams can navigate to saved estimates and modify or remove specific items to generate a new cost estimate.

Users can select key parameters, such as region, instance size, and usage hours, for each service. Choose the specific service when adding it to a new estimate or when reviewing a previously generated estimate. A drop-down menu is available to select regions, while hours and instance sizes can be entered in the appropriate input fields. For instance, teams may only need certain services during normal business hours.

Teams can create multiple estimates, which can be saved and exported as Excel spreadsheets. Decision-makers can share and review these estimates as they determine how to size and populate the Azure environment. Companies can try different approaches to identify the most productive and cost-effective solution.

## Azure Pricing Options And Hybrid Benefit Savings

Azure offers customers reserved pricing and hybrid cost savings opportunities. Reserved instances (RIs) offer discounted pricing for customers who commit to using specific Azure compute resources for 1 or 3 years. RIs may be less expensive than pay-as-you-go options for customers with stable and predictable usage requirements.

Azure Hybrid benefits reduce licensing fees and are available to customers with qualifying Microsoft Windows Server or SQL Server licenses with active Software Assurance (SA) or eligible subscription rights that allow cloud use. Companies with an on-premises investment in Microsoft solutions can substantially reduce cloud costs with hybrid benefits.

Customers should conduct a complete evaluation of their prospective Azure environment before migrating. The evaluation should focus on comparing the costs of a pay-as-you-go solution with those of a reserved instance solution. An effective approach is to evaluate 1 and 3-year commitments with RIs against a consumption-based pay-as-you-go strategy.

## Azure Hybrid: Licensing, Migration, And Cost Impact

Azure Hybrid is a Microsoft licensing program that lets customers use eligible on-premises licenses to reduce Azure infrastructure costs. It lets you reuse existing licenses, so you don’t pay full costs in Azure. The program is primarily focused on Windows Server and SQL Server licenses.

Azure Hybrid reduces migration costs and preserves a company’s licensing investments. Teams should calculate the cost savings of hybrid benefits per workload when developing migration plans. Organizations should inventory and document their Microsoft licenses before migrating to take advantage of hybrid savings.

## Azure Services And Cloud Services Cost Drivers

The cost of Microsoft Azure services is typically affected by the following cost drivers.

- **Compute:** Compute often accounts for the largest component of Azure spending. Consumption is affected by factors such as VM size, GPU usage, runtime hours, and autoscaling options.
- **Storage:** Azure storage costs are influenced by a company’s total data volume, performance tiers, redundancy, cross-region replication, and retention duration.
- **Network egress:** While ingress traffic is free, egress traffic is not and can be a major cost driver. These costs can add up due to content delivery networks (CDNs), cross-region transfers, and large analytics or backup workloads.
- **Managed databases:** Platform services such as Azure SQL Database may use transaction-based or throughput pricing, which increase as scaling increases.
- **Data processing and analytics:** Analytics workloads are a fast-growing cost in Azure, driven by query volume, compute runtime, and data scan size. Poor query can result in higher costs.
- **Licenses:** Licensing for products such as Windows Server, SQL Server, and Microsoft 365 affects Azure costs.
- **Availability and redundancy:** Companies that require higher availability typically incur higher costs. Multi-zone, multi-region, and disaster recovery environments increase Azure pricing.

Companies should analyze the costs of these drivers to optimize spending whenever possible. An effective approach is to profile peak and idle service usage to right-size the environment size and hours of operation.

## Cloud Storage Pricing And

Organizations should be aware that storage pricing is not simply a matter of dollars per GB. Pricing is based on how often you access the data, where the data is stored and moved, and how it is protected and managed. Vendors price cloud storage based on the following factors and key metrics.

- **Capacity:** Companies are charged per GB or TB per month, and rates vary by storage class.
- **Storage tier or access class:** Teams can select a tier that with their data availability requirements. Hot storage is used for frequently accessed data and provides the lowest latency at a premium cost. Cool storage lower cost but higher access fees and lower costs for infrequently used data. The archive tier is the least expensive option, but it has the slowest data retrieval.
- **Data transfer charges:** Companies are typically charged per GB for egress (outbound) traffic. Inbound data is usually free, but it consumes storage space. Teams may be charged retrieval fees for accessing archived data.
- **Redundancy:** Customers must pay for multi-zone or cross-region data replication. The additional resiliency of redundant storage comes at a higher price.

Businesses can significantly reduce storage costs with data lifecycle management that moves data to the appropriate tier. Azure implements automated migration between storage tiers using Lifecycle Management policies or Smart Tiering. Teams can define policies to optimize costs for data older than 30 days.

A simple policy would move data that hasn’t been modified in 30 days to cool storage. Data that has not been accessed for 90 days can be moved to cold storage, with the archive tier used for data not accessed for 180 days.

## Microsoft 365 Licensing And Its Impact On Cloud Cost

Many companies rely heavily on their Microsoft 365 environment for critical business processes. Microsoft 365 licensing can significantly affect Azure costs by leveraging its built-in capabilities to replace separate solutions. Specific areas where Microsoft 365 licensing materially affects Azure costs include:

- Recurring SaaS subscription costs;
- Security and compliance tools;
- Azure identity and management dependencies;
- Operational ;
- Storage growth and retention costs.

Companies can optimize costs by taking several steps, including:

- Right-sizing Microsoft 365 licenses by user role;
- Avoiding overlicensing and fragmented tooling;
- Evaluating how Microsoft 365 affects total cloud costs rather than as a standalone subscription.

## Billing, Purchase Options, And Pricing Policies

Organizations can choose from multiple Microsoft Azure billing, purchasing, and pricing options. Companies should evaluate the following choices to determine which provides the most cost-effective cloud solution.

- **Enterprise Agreement (EA):** This option is tailored toward large enterprises and provides complete invoicing for all Azure services and Microsoft Marketplace purchases.
- **Microsoft Customer Agreement (MCA):** These agreements offer customers a simplified, direct alternative with consolidated billing and the option to add purchase order numbers to invoices. MCAs are more flexible and consumption-oriented than EAs.
- **Cloud Solution Provider (CSP/Partner):** In this model, customers purchase managed Azure services through a Microsoft partner.
- **Pay-As-You-Go:** Customers purchase Azure services directly on the website and are billed monthly via invoice or credit card.

Azure is typically billed in U.S. dollars. Microsoft [supports multiple local currencies](https://learn.microsoft.com/en-us/marketplace/currencies) and performs monthly foreign exchange rate calculations, which can affect costs. Customers should verify that their currency is supported to accurately budget for Azure services.

## Cost Tactics For Microsoft Azure Cloud Cost

Businesses typically seek a cost-effective solution for their computing needs. Companies have multiple opportunities to optimize Azure Cloud costs, saving money while maintaining an environment that meets business requirements and remains competitive. Organizations can substantially reduce the cost of a Microsoft Azure solution by leveraging the following tactics.

Teams should right-size their VMs by aligning their resources, such as CPU, memory, and storage, with workload requirements. Companies can avoid paying for unused capacity while maintaining acceptable performance and availability. Right-sizing involves:

- Eliminating overprovisioned VMs;
- Aligning the VM family with workloads;
- Minimizing bottlenecks by scaling up undersized VMs.

Businesses can take advantage of Azure spot instances for workloads that can tolerate interruptions. Azure spot instances are discounted VMs that use the same hardware as standard Azure VMs. They are offered at a discounted rate, but users can be evicted if Azure needs to reclaim capacity or if the configured maximum price is exceeded.

Companies can achieve substantial savings by combining Azure Hybrid Benefits (AHB) and reserved instances. AHB reduces Windows Server and SQL Server licensing costs by using existing on-premises licenses and subscriptions. Reserved instances offer discounts on Azure compute infrastructure to companies committing to usage terms of 1 to 3 years.

## Tools, Resources, And Next Steps

Prospective Microsoft Azure customers should review [Microsoft’s Azure pricing page](https://azure.microsoft.com/en-us/pricing) and use the[Azure pricing calculator](https://azure.microsoft.com/en-us/pricing/calculator/). Companies can run an[Azure Migrate assessment](https://learn.microsoft.com/en-us/azure/migrate/concepts-overview?view=migrate) that evaluates their on-premises and cloud workloads. The assessment analyzes the environment to provide a migration strategy for cloud-ready workloads and to help right-size Azure infrastructure.

Organizations considering Microsoft Azure should create an action plan that balances performance and functionality with cost. Tools like the pricing calculator are effective for planning, as they let teams evaluate the costs and benefits of different migration strategies.

Atlantic.Net offers its customers alternative cloud solutions that meet strict security, privacy, and compliance requirements, delivered through a scalable hosting environment. We provide customized Cloud, GPU Cloud, Dedicated, Bare Metal Hosting, and Managed Services to address your business needs. Our compliant hosting platforms ensure your regulated data is handled securely.

[Contact Atlantic.Net’s cloud experts](https://www.atlantic.net/about-us/corporate-contact/) to learn more about our hosting solutions.

 


---

# How to Improve CDN Performance in 2026: Metrics, Monitoring, and Strategies

> URL: https://www.atlantic.net/managed-services/improve-cdn-performance/ | Published: 2026-05-14 | Author: Robert Agar

[Content Delivery Networks (CDNs)](https://www.atlantic.net/hipaa-compliant-hosting/content-delivery-networks-theyre-powerful/) are now a basic part of modern Web applications. Today, many services operate across different regions and depend on fast, stable performance. Therefore, improving CDN performance has become an important task for engineering teams. In 2026, this is even more important because applications now serve users globally, respond in real-time, and are more affected by delays. As a result, even small performance issues can affect the users’ experience.

At the same time, user expectations regarding website and application performance have increased. Most users expect near-instant loading. When performance is slow, users often leave without waiting. This behavior affects engagement, revenue, and long-term trust. Therefore, performance is not only a technical concern, but also a business concern.

To meet these performance expectations, CDNs play a key role in improving content delivery. A CDN helps reduce delays by placing content closer to users. In addition, it reduces load on the origin and improves reliability during traffic spikes. Using a CDN alone is not sufficient. Its performance depends on how well it is configured, monitored, and optimized over time. Therefore, improving CDN performance requires a clear, structured approach that involves measuring the right metrics, continuously monitoring performance, and applying effective strategies.

This article presents these aspects in a structured manner to support practical understanding and application of CDN performance improvement.

## What a CDN Is and How Its Architecture Affects Performance

A CDN is a system of distributed servers that deliver Web content to users based on their geographic location, rather than relying on a single origin server. It stores copies of content across multiple regions so users can access data from a nearby server, reducing distance, improving speed, and increasing reliability. , CDN performance varies across situations because it depends on system design and the movement of requests across internal layers. Therefore, understanding CDN architecture is important before focusing on performance improvement. The following sections describe its main components, including edge locations and [Points of Presence (PoPs)](https://www.cloudns.net/blog/what-is-a-point-of-presence-pop-and-why-does-it-matter/), request routing via [Anycas](https://www.cloudflare.com/learning/cdn/glossary/anycast-network/)t, and edge cache behavior.

### Edge Locations and Points of Presence (PoPs)

A CDN operates through a global network of PoPs, each containing [edge servers](about:blank) that store cached content closer to users. User requests are directed to the nearest PoP, reducing the physical distance and improving response time. This improves consistency across regions. In addition, a larger number of PoPs increases global coverage and reduces latency differences; , an uneven distribution can still cause regional variation. Therefore, PoP placement and density are important for content delivery.

### Anycast Routing and Request Delivery

CDNs commonly use Anycast routing, in which multiple PoPs share the same IP address and traffic is directed to the nearest healthy location. This approach improves performance by connecting users to closer servers without manual routing decisions, and it also improves reliability because traffic can shift to another PoP if one becomes unavailable. In contrast, unicast routing sends all traffic to a single fixed destination, increasing delay and reducing flexibility. Anycast routing is widely used in modern CDN systems to support low latency and high availability.

### Cache Behavior at the Edge

Caching is a key mechanism in CDN performance because it decides whether content is served from the edge or fetched from the origin server. When content is available at the edge, it is called a cache hit. As a result, response time improves, and origin load decreases.

In contrast, a cache miss occurs when the content is not available at the edge. In this situation, the request goes to the origin, which increases latency. This is why cache directly impacts performance.

It is important to mention that the cache behavior depends on TTL settings, cache-control headers, and cache hierarchy rules. Therefore, the correct configuration of these parameters is necessary for consistent performance. If they are not configured properly, performance can degrade even in a well-distributed CDN system.

## Key CDN Performance Metrics to Monitor

Monitoring performance metrics helps identify issues early and supports evaluating efforts over time. Therefore, tracking the right set of metrics is important for maintaining stable CDN performance. The key metrics used for this purpose are discussed below.

### Latency Percentiles

Latency percentiles represent distribution-based measurements of response time, including p50, p90, p95, and p99. These values indicate performance across different user groups. Higher percentiles represent slower responses experienced by a smaller portion of users. Therefore, latency percentiles are used to assess tail performance in CDN systems.

### Time to First Byte (TTFB)

Time to First Byte (TTFB) measures the time between a user request and the first byte of the response. It includes DNS resolution, TLS handshake, routing, and origin processing. TTFB is used to evaluate responsiveness across edge and origin layers. In practice, a sudden increase in TTFB often indicates routing delays, origin overload, or edge inefficiencies.

### Error Rates by Status Code

Error rates represent the proportion of failed HTTP requests identified through status codes. *4xx* status codes indicate client-side or configuration-related issues, while *5xx*status codes indicate server-side or CDN-related failures. These values are used to assess system stability and detect reliability issues across different regions. These values are used to assess system stability and detect reliability issues across different regions. In practice, spikes in error rates are particularly useful for isolating misconfigurations, origin failures, or regional CDN disruptions.

### Throughput and Bandwidth

Throughput measures the amount of data transferred over time, while bandwidth usage represents total data consumption within a given period. These metrics are used to assess traffic load and data delivery capacity in CDN systems, helping identify congestion patterns and understand whether the network is operating within expected performance limits.

### Cache Hit Ratio (CHR)

Cache Hit Ratio (CHR) is defined as the ratio of cache hits to total requests. It indicates the proportion of requests served from edge caches rather than from the origin. CHR is used to evaluate caching and to reduce origin load.

## CDN Monitoring and Performance Testing

CDN monitoring and performance testing provide continuous visibility into system behavior. They help identify issues before they affect end users. In addition, they support performance evaluation under controlled and real-world conditions. Therefore, a combination of monitoring and testing methods, as mentioned below, is required for accurate performance assessment.

### Synthetic Monitoring

Synthetic monitoring uses automated test requests from multiple global locations. These tests run at regular intervals and measure latency, TTFB, DNS resolution, and availability. Since the conditions are controlled, the results remain consistent. Therefore, synthetic monitoring is used for both performance benchmarking and early detection of regional performance issues. It also helps validate fixes after performance issues are resolved.

### Real User Monitoring (RUM)

Real User Monitoring (RUM) collects performance data from actual users. It captures variation across devices, networks, and geographic locations. Since this data reflects real-world conditions, it provides that controlled tests may not capture. Therefore, RUM complements synthetic monitoring in performance evaluation. It also helps detect recurring performance issues in real traffic conditions.

### Benchmarking CDN Performance

Benchmarking involves running identical tests across multiple regions or providers. The same assets and request patterns are used. This ensures a consistent and fair comparison of performance. Therefore, benchmarking is a structured method for performance testing and evaluation of CDN configurations.

### Monitoring Tools and Observability Support

Monitoring tools support both performance monitoring and testing activities. They provide global visibility, real-time alerts, and logging and observability systems. In addition, log analysis helps identify performance issues and supports detailed investigation. These tools also support continuous detection of performance anomalies in production systems.

### Advanced CDN Strategies

CDN focuses on improving performance, reducing reliance on origins, and maintaining stability under varying traffic conditions. It also supports the use of network resources. The following strategies help achieve consistent and predictable performance.

### Improve Cache Through Controlled Caching Policies

Cache should be improved through controlled caching policies. Cache-control headers must be configured to ensure appropriate content storage at the edge. In addition, query strings and cookies should be limited where possible to reduce cache fragmentation. As a result, a larger portion of requests is served from the cache. Therefore, improved cache increases cache hit ratio and reduces origin load.

### Adjust Cache TTL Settings Based on Content Characteristics

Cache TTL settings should be adjusted according to content type and update frequency. Static assets require longer TTL values since they change less frequently, while content requires shorter or adaptive TTLs to reflect frequent updates. In this context, mechanisms such as stale-while-revalidate and stale-if-error help maintain availability during revalidation or when a temporary origin issue occurs. Therefore, appropriate TTL configuration improves both performance and content consistency.

### Reduce Content Size Through Compression and Asset

Content size should be reduced through compression and asset techniques. Since large files increase transfer time, reducing their size improves delivery. Methods such as Brotli and gzip are commonly used for compression. In addition, CSS and JavaScript files should be minified to remove unnecessary data. Image also plays an important role, and modern formats such as WebP and AVIF further improve. As a result, reduced payload size leads to lower transfer time and improved performance.

## Execute Application Logic at the Edge for Latency-Sensitive Workloads

Application logic should be executed at edge locations for workloads that require low latency. This reduces the need to contact the origin server for each request. As a result, the travel distance and processing delays are reduced. Therefore, response time improves for and interactive content.

## Operating CDN Performance at Scale

At scale, CDN performance management shifts from individual tuning activities to coordinated system-level operation. It requires alignment between monitoring signals, log data, and actions across distributed environments.

Therefore, maintaining consistent visibility across regions becomes essential for understanding system behavior in a unified manner. This visibility is achieved through monitoring systems that track performance in real time, while logs provide detailed request-level context that helps verify and interpret those signals.

In addition, performance adjustments are applied as part of an ongoing cycle, guided by trends over time rather than isolated incidents, which helps ensure that CDN performance remains stable and manageable in large, distributed infrastructures.

## CDN Performance Reporting, SLAs, and Provider Accountability

CDN performance management requires structured reporting and clear accountability with service providers. This ensures that performance expectations are measurable and enforceable in real environments.

### SLA Metrics to Track

SLA evaluation is based on key indicators such as uptime percentage, p95 and p99 latency, TTFB, cache hit ratio, and error rates across regions. Each metric highlights a different aspect of service quality, including availability, responsiveness, and caching. Compliance is determined by evaluating these metrics together rather than in isolation.

### Monthly Performance Reporting

Monthly reports aggregate SLA metrics to provide a clear view of system performance. They track regional trends in latency, availability, cache, and error patterns. The reports also include summaries of incidents and any deviations from expected thresholds. This creates a consistent reference point for evaluating performance over time.

### Escalation Steps for SLA Breaches

When SLA thresholds are violated, a structured escalation process is followed:

- Internal validation is performed using monitoring data and logs to confirm the issue.
- Once verified, the issue is formally reported to the CDN provider with supporting evidence.
- The provider investigates the incident and initiates resolution steps.
- If the issue persists or appears again, escalation is moved to higher support levels.
- In critical or unresolved cases, a reassessment of the CDN architecture or provider strategy may be required.

## How Origin Infrastructure Impacts CDN Performance

Origin infrastructure directly impacts CDN performance by determining how quickly edge servers retrieve content that is not in cache. When origin response time is high, TTFB increases, and cache misses take longer to resolve, which makes origin performance a critical part of the end-to-end delivery chain.

The effect becomes more visible during traffic spikes, where slow or unstable origin systems introduce delays even when the CDN edge layer is properly optimized. These delays also affect cache refresh behavior, since edge servers depend on timely origin responses to update content efficiently.

The hosting environment further influences origin stability. Well-isolated and controlled systems tend to deliver more consistent performance under heavy load than highly shared environments. Infrastructure providers such as Atlantic.Net offer high-availability hosting solutions that support this level of stability for production workloads.

Reliable origin infrastructure reduces processing delays at the source and improves consistent CDN performance across distributed regions.

## The Bottom Line

CDN performance depends on several interconnected layers, including edge delivery, monitoring, , and origin behavior. If any of these layers is weak, it can affect response time, stability, and the user experience.

One key takeaway from this discussion is that performance metrics should not be interpreted in isolation. Indicators such as latency percentiles, TTFB, error rates, and cache hit ratio are meaningful only when they are linked to system behavior. In practice, they serve as signals to identify where delays or inefficiencies originate, rather than as standalone performance scores.

Effective CDN management depends on continuous attention across all layers of the delivery chain, where measurement, monitoring, and work together as a single system rather than separate activities.


---

# Dedicated Hosting for Compliance: Auditability, Data Control, and Risk Reduction

> URL: https://www.atlantic.net/dedicated-server-hosting/dedicated-hosting-compliance-auditability-data-control-risk-reduction/ | Published: 2026-05-15 | Updated: 2026-06-24 | Author: Richard Bailey

Compliance requirements in 2026 focus significantly on continuous control and verifiable system behavior. Organizations in healthcare, financial services, and [SaaS](https://www.salesforce.com/saas/) environments must not only protect sensitive data but also demonstrate that their systems operate under clearly defined and consistently enforced controls. As a result, compliance is no longer based solely on periodic documentation, but on ongoing, verifiable evidence.

To meet these expectations, infrastructure plays a key role in compliance readiness. [Dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) is widely used for regulated workloads because it provides a [single-tenant](https://www.atlantic.net/dedicated-server-hosting/achieving-unparalleled-security-with-single-tenant-dedicated-hosting/) environment where physical resources are not shared with other customers. The model reduces external dependencies and offers clear control over system behavior, including configuration, logging, and access activity.

As control becomes more important, auditors involved in regulatory and compliance assessments expect detailed logs, configuration records, and access histories, along with evidence that systems remain stable and predictable over time. These requirements extend beyond documentation review and depend on direct visibility into system operation. As a result, infrastructure decisions directly influence audit outcomes, system stability, and operational risk exposure.

Even under these conditions, written policies are necessary; their value is limited when the underlying infrastructure lacks consistency, visibility, and control. Therefore, compliance depends not only on documented procedures but also on whether the infrastructure can maintain reliable control and consistent system behavior under real operating conditions.

## Single-Tenant Architecture and Infrastructure Isolation in Dedicated Hosting

[Dedicated hosting](https://www.atlantic.net/dedicated-server-hosting) uses a single-tenant setup, where a physical server is assigned to a single organization. No other customer shares the same hardware. As a result, all system activity remains within a defined and isolated boundary.

The isolation applies across compute, storage, and networking components. These components operate under a single administrative control and do not depend on shared virtualization or [multi-tenant](https://www.atlantic.net/dedicated-server-hosting/multi-tenant-bare-metal-data-collection/) scheduling. Configuration changes and operational activity remain limited to one environment and are not influenced by external workloads.

With this level of isolation, system behavior becomes more stable during normal operations. Since resources are not shared across multiple tenants, variation caused by competing workloads is removed. This leads to more consistent performance patterns under typical operating conditions.

At the same time, operating within a single-tenant environment simplifies infrastructure management. All system components follow a single ownership and control model, reducing coordination across different layers of the environment. This makes system behavior easier to manage over time.

Single-tenant architecture keeps system activity and resource usage within a single controlled environment. Therefore, operational uncertainty is reduced, and system behavior becomes consistent across ongoing operations.

## Dedicated Hosting vs Cloud and Shared Infrastructure

Compliance teams often evaluate dedicated hosting together with cloud and shared infrastructure when selecting environments for regulated workloads. Each model differs in control, isolation, and operational consistency, which directly affects system management and audit preparation.

The main distinction between dedicated hosting and cloud or shared infrastructure lies in the level of tenancy. Dedicated hosting uses single-tenant hardware assigned to a single organization, while cloud and shared environments use multi-tenant systems that share resources across multiple users. As a result, system operations in dedicated hosting remain clearly separated from other workloads.

Control in dedicated hosting is significantly higher because organizations have full root access and kernel-level configuration control, which enables security settings and system baselines to be defined according to internal requirements. In cloud and shared environments, parts of the infrastructure are managed by the provider, reducing direct control over underlying system components and limiting the depth of configuration.

System behavior also differs across these models since dedicated hosting delivers more consistent performance due to non-shared resources. Cloud environments, though scalable, may vary depending on resource distribution at the platform level. This variation can affect operational consistency in regulated workloads that require stable system behavior.

These technical differences lead to distinct compliance considerations. Dedicated hosting provides transparent operational boundaries, which simplifies internal governance and external review processes. Cloud and shared environments introduce a shared responsibility model between the provider and the customer, requiring closer coordination in maintaining compliance documentation and audit evidence.

Furthermore, risk exposure varies similarly because shared and multi-tenant environments introduce indirect exposure through common infrastructure layers. At the same time, dedicated hosting reduces this exposure by isolating hardware and network components for a single organization. This results in more controlled, predictable operating conditions for regulated workloads.

Table 1: Comparison of Dedicated Hosting, Cloud, and Shared Infrastructure

| **Aspect** | **Dedicated Hosting** | **Cloud Infrastructure** | **Shared Hosting** |
| --- | --- | --- | --- |
| **Tenancy** | Single-tenant hardware assigned to one organization | Multi-tenant virtual environment | Multi-tenant shared servers |
| **Control** | Full root and kernel-level configuration control | Partial control with provider-managed layers | Limited control |
| **Performance** | Consistent performance due to dedicated resources | Variable based on resource distribution | Affected by other users |
| **Compliance Model** | Clear operational boundaries for audits | Shared responsibility between provider and customer | Limited suitability for strict compliance needs |
| **Risk Exposure** | Lower due to physical and network isolation | Moderate due to shared infrastructure layers | Higher due to shared system usage |

## Compliance Requirements Across Major Regulatory Frameworks

Compliance frameworks define the protection, processing, and auditing of sensitive data, and these requirements directly influence infrastructure selection and management. Although each framework introduces specific obligations, they share a common expectation of transparent control, traceability, and consistent system behavior. These shared expectations establish the foundation for the security controls, operational practices, and risk considerations discussed in the following sections.

### HIPAA for Healthcare Systems

In healthcare environments, HIPAA requires organizations to protect [electronic Protected Health Information (ePHI)](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) and maintain visibility over where that data is stored and how it is accessed. This requirement is easier to meet in dedicated hosting environments because data remains within a defined infrastructure boundary, which simplifies documentation and audit preparation. This also means [encryption](https://www.atlantic.net/hipaa-compliant-hosting/why-is-encryption-so-key-to-hipaa-compliance/) at rest and in transit, access control, and audit logging must be in place to protect data and track activity. A [HIPAA Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) then defines the responsibilities between the organization and the hosting provider.

### GDPR for Data Protection and Residency

In data protection contexts, the [General Data Protection Regulation (GDPR)](https://gdpr-info.eu/) focuses on where personal data is stored and how it is handled, making data residency and jurisdiction key concerns for organizations that handle personal data. To meet these expectations, organizations must know where personal data is stored and ensure it is processed under controlled conditions. Dedicated hosting helps support this by keeping data placement predictable and consistent. Additionally, data processing agreements and safeguards for cross-border data transfers must be established and properly documented.

### PCI DSS for Payment Systems

In payment systems, the [PCI DSS](https://www.atlantic.net/pci-compliant-hosting/) requires a clear definition and isolation of the cardholder data environment. This includes network segmentation, restricted access, and continuous monitoring of system activity. These controls are easier to maintain when the system environment is clearly separated, which helps protect sensitive payment data.

### SOC 2 and ISO 27001

Frameworks such as [SOC 2](https://www.atlantic.net/hipaa-compliant-hosting/ssae-16-soc-1-soc2-care/) and ISO 27001 focus on validating operational controls through independent audits. These frameworks require evidence of physical security, logical access control, and consistent operational practices. Dedicated hosting supports this validation process by maintaining stable environments where control can be clearly demonstrated and reviewed.

## Security, Operational Controls, and Provider Requirements

Compliance requirements depend on both the selected infrastructure and the consistency of security and operational controls. Dedicated hosting provides a controlled environment, while organizations are responsible for enforcing safeguards across all system layers.

Access control is a primary component of these safeguards. Administrative access must be restricted to authorized users and protected through multi-factor authentication. Role-based permissions limit access to defined responsibilities, reducing unnecessary exposure and supporting accountability.

Data protection is another essential requirement in compliance-driven environments. This includes encryption of data at rest and in transit using TLS, along with the secure management of encryption keys. Hardware-based key management strengthens protection by isolating key storage from general system operations.

In addition to data protection controls, logging and monitoring are required to provide visibility into system activity and the effectiveness of controls. System activity must be recorded through structured logs that capture access events, configuration changes, and system operations. These records provide verifiable audit evidence and support continuous oversight.

Alongside these controls, network security measures reduce exposure and maintain system stability by segmenting sensitive workloads and limiting access to critical systems. Building on these controls, operational practices ensure consistency through defined patch management, vulnerability remediation, and controlled change management processes. Provider evaluation is also necessary, including the review of audit reports, physical security controls, and service-level agreements that define uptime and incident response expectations.

## Cost, Risk, Data Sovereignty, and Continuous Compliance Lifecycle

Compliance considerations extend beyond system deployment and remain relevant throughout the operational lifecycle. The outline below brings together the main aspects of cost, risk, data residency, and continuous compliance that organizations typically manage in regulated environments.

- Compliance-driven environments require evaluation of both financial and operational risk, since regulatory obligations extend well beyond initial deployment.
- Costs include infrastructure provisioning and ongoing operational commitments, such as monitoring, managed services, and compliance validation activities. At the same time, additional expenses arise from audit preparation, security assessments, and certification processes that require long-term planning.
- Risk considerations include potential security incidents and compliance violations that may lead to financial and reputational impacts, underscoring the importance of stability and operational predictability when selecting infrastructure.
- Data sovereignty requirements define where data is stored and processed. Dedicated hosting supports these requirements through predictable data placement and clear control over infrastructure.
- Compliance is a continuous requirement across the system lifecycle, from migration to ongoing operations, with early gap identification and sustained operational discipline needed to maintain alignment with regulatory expectations.

## Atlantic.Net As a Compliance-Ready Dedicated Hosting

Organizations working in regulated environments often select hosting providers that support predictable control and clear documentation. Atlantic.Net offers [HIPAA-compliant dedicated hosting](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-dedicated-server-a-real-world-scenario/) with single-tenant servers, which helps maintain stable system behavior and a consistent audit framework. The platform supports encryption at rest and data encryption in transit using TLS, along with detailed logging for audit evidence. It also provides the HIPAA-compliant BAA and maintains independent audit reports such as SOC 2 and ISO 27001. Therefore, organizations can use these services to build environments that support compliance requirements and reduce operational uncertainty in regulated workloads.

## The Bottom Line

In practice, compliance depends not only on documentation but also on the consistency with which infrastructure supports control enforcement during day-to-day operations. Dedicated hosting contributes to this by providing stable environments where system behavior can be better managed and audited. Dedicated hosting serves as a practical foundation for regulated workloads, where compliance depends on both policy design and the reliability of the underlying infrastructure.

 


---

# Hosting Offshore Medical Billing Teams: Why the Desktop Belongs in HIPAA-Covered Hosting

> URL: https://www.atlantic.net/hipaa-compliant-hosting/offshore-medical-billing-hipaa-covered-hosting/ | Published: 2026-05-16 | Updated: 2026-05-11 | Author: Richard Bailey

To continue our series of request-for-quote deep dives, today, we are going to look at how we address the complexities some health practices face in maintaining HIPAA Compliance when using support teams scattered across the globe.

Here, we will investigate an offshore back-office model that is now common in US specialty medicine. A small practice in New York, Florida, or Texas hires a billing team in Bangalore, Manila, or Cebu, and the team works the practice’s claims queue from twelve time zones away. This model can make HIPAA-Compliance complex, but this article is about how Atlantic.Net overcame these challenges.

Atlantic.Net’s pre-sales team has been answering these types of requests with growing regularity: how does an offshore team actually access the electronic medical record (EMR) in real time?

Do they need a contractor laptop with access and credentials configured, and hope nothing leaks? Or a secure, US-based HIPAA-compliant environment, one that can be audited, configured, and inspected on your own terms?

This was the situation for one pain management practice in Queens, New York, that recently contacted Atlantic.Net. The practice had moved its EMR to a cloud platform a year earlier and was setting up a three to five-person billing team in India to work the claims queue.

The Request for Quotations (RFQ) asked for a HIPAA-compliant Managed VPS or virtual desktop, a signed HIPAA Business Associate Agreement (BAA) (BAA), no-leak controls, multi-factor authentication, and a confirmed uptime SLA.

## The Decision That Sits Underneath the RFQ

The customer was on the right track when requesting a cloud server or a virtualized desktop solution, and it doesn’t matter where your support teams are based, provided that the workspace the team uses is a controlled environment the practice can audit, not a trusted endpoint it cannot inspect.

The difference matters because electronic Protected Health Information (ePHI) does not have to be stored somewhere to create a HIPAA liability. , how ePHI is accessed is critical for compliance.

A billing clerk in India who opens a patient chart through a browser on their own laptop has touched ePHI on a device the practice has never seen, running software the practice cannot configure, connected to a network the practice cannot monitor. The BAA the practice signed with its EMR vendor does not extend to that laptop. Nothing does.

The answer Atlantic.Net built toward an access model workspace that belongs inside a HIPAA-covered hosted environment, and the offshore team works inside via virtual desktops rather than connecting from outside.

## The Four Questions a Practice Should Be Ready to Answer

A practice owner does not need to understand Group Policy or Remote Desktop Services licensing. Still, it’s essential to have answers for these questions to determine whether a deployment lands cleanly. Getting clear on them before the quote stage saves time on both sides.

### Who Signs the BAA, and What Does It Actually Cover?

The BAA is the legal instrument that makes HIPAA-compliant hosting meaningful. Without one, a provider is handling infrastructure that may contain ePHI without taking on the obligations of a business associate, creating a compliance gap regardless of how strong the security controls are.

Atlantic.Net includes the BAA at no extra charge with the[Windows Business HIPAA hosting](https://www.atlantic.net/hipaa-compliant-hosting/) plan. It is part of the tier, not a separate negotiation, and it covers Atlantic.Net’s role as a business associate for the data, traffic, backups, and operational records that pass through the hosted environment.

What it does not cover is the chain upstream. The practice has its own BAA with the EMR vendor. The two are separate instruments that cover distinct legs of the ePHI journey. The practice owns the chain; the hosted environment is one covered link in it.

### Where Does ePHI Physically Live During a Working Session?

When a billing clerk in India opens the EMR platform via the hosted Windows desktop, the ePHI resides in the cloud. The hosted server holds the operating system, a browser, and session logs. It does not hold patient charts or claims files in any persistent form. The browser session opens, the clerk works the queue, and the session closes. The EMR vendor’s cloud is where the data rests.

The server’s role is to serve as the authorized workspace where the billing clerk’s credentials and the EMR’s data meet. If that meeting were to happen on a contractor’s laptop instead, the practice would lose two things at once: the audit trail of what was accessed, and the policy layer that controls what can leave the system.

[HIPAA-compliant cloud storage](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-cloud-storage/) on Atlantic.Net’s platform means that what does sit on the server, session logs, temporary files, and encrypted backups, falls under the same compliance posture as the compute layer.

### What Is Refused at the Desktop Layer?

The security question that matters most for an offshore billing team is not what the server enables. It is what the server refuses.

Atlantic.Net can deliver a no-leak policy bundle as part of the Windows Business HIPAA hosting configuration for this use case. At the operating system level, every path that would let a file leave the server or a clipboard string travel back to a contractor’s device can be closed: drive redirection, clipboard redirection, printer redirection, removable media, and port and plug-and-play device access can be blocked at the policy layer. The billing team has a working Windows session and a browser. What they may not have is any mechanism to move ePHI from the server to the device in front of them.

A browser-level control layer sits on top. The session browser can be locked to the EMR domain and a short list of supporting URLs. Downloads can be disabled independently of the OS-level block. Print to PDF can be turned off. The session functions as a window onto the EMR platform and nothing else.

Atlantic.Net applies hardening during provisioning for HIPAA customers with offshore back-office teams. The practice’s part is to confirm whether an exception is needed for a specific peripheral, and in most cases, including this one, none is.

### Who Brings the Microsoft Licensing?

This is the question most practices do not think to ask before the quote stage, and it is the one most likely to affect the go-live timeline if left unanswered early.

A Windows Server included in a hosting plan ships with a built-in RDP license that supports two concurrent administrative sessions. That is a Microsoft licensing rule that applies to every cloud provider in this category. For three to five concurrent billing users, the practice needs Remote Desktop Services (RDS) User CALs, purchased separately from a Microsoft partner.

Atlantic.Net’s Services Provider License Agreement (SPLA) with Microsoft does not permit reselling or leasing RDS User CALs. That boundary applies to every Atlantic.Net Windows plan, and it is not unusual in managed hosting. What Atlantic.Net does provide, at no extra charge, is installation and activation of the License Server role on the cloud server, pointing the RD Session Host at it, and validating the per-user licensing mode. The practice brings the CALs; Atlantic.Net brings the infrastructure they run on.

Microsoft’s 120-day RDS licensing grace period is available, allowing the team to start working on day one while CAL procurement runs in parallel. For an offshore billing team that is often onboarded faster than a Microsoft partner’s procurement cycle, that window is the practical answer to whether licensing will delay the go-live.

## Why a Cloud EMR Doesn’t Eliminate the Hosting Question

The most common objection Atlantic.Net encounters is straightforward: “Our EMR is already in the cloud. Why do we need a server at all?” It is a fair question. If the patient data lives in the cloud and the billing team just opens a browser to access it, the server can feel like an unnecessary layer between the contractor and the work.

The answer is that the EMR vendor’s cloud holds the data, but it does not provide the workspace. The workspace, wherever it is, is what gets audited. If the workspace is a contractor’s personal laptop, the practice has no visibility into what happens to ePHI during the session: whether the screen is photographed, whether the browser caches data that persists after the session, or whether files are downloaded before the tab is closed. The EMR vendor’s security posture covers its infrastructure. It does not extend to the device at the other end of the browser.

A HIPAA-covered hosted desktop brings both things back. The audit trail comes back because session activity is logged on a server that the practice controls. The policy layer comes back because the no-leak controls apply to the session, not to the device. The contractor’s personal laptop is irrelevant to the compliance model because it ends at the server, not at the contractor’s front door.

For customers who assumed the cloud EMR had already solved the access-control problem, the need for a hosted workspace can feel like unexpected overhead. It is not overhead. It is the piece that the EMR vendor’s cloud cannot provide on the practice’s behalf.

## The Operational Reality of an Offshore Working Day

The productive window between an Indian working day and a New York business day is narrow. A billing team in India starting work at 9:30 in the morning is several hours into its shift before the Queens practice opens its phones. The overlap where questions can be answered and escalations handled runs to perhaps two hours in the afternoon, New York time.

In that context, uptime is not an abstract SLA metric. An hour of unplanned downtime during that window does not slow the billing team down. It stops them. The overlap is so short that an outage that would cost a colocated team a coffee break and a restart can cost an offshore team the productive portion of an entire day.

Atlantic.Net’s published[100% Cloud Service Level Agreement](https://www.atlantic.net/cloud-service-level-agreement/) applies to the cloud platform on which the Windows VPS runs. The weight of that commitment is higher, not lower, when the users depending on the server are twelve time zones away. It is also why the 24/7 managed support included in the Windows Business HIPAA plan matters: support availability at 3 in the morning US Eastern time is the relevant metric when the team working the server is in India during business hours.

## What a Production Deployment Looks Like at Atlantic.Net

The configuration Atlantic.Net provisions for a practice in this situation is built around a single Windows Business HIPAA hosting plan, sized for the team’s workload. For three to five concurrent billing users working in a cloud EMR via a browser, the baseline is a 4 vCPU, 16 GB RAM instance with 200 GB of encrypted SSD storage. That allocation runs the Windows Server, the browser sessions, and a year’s worth of audit logs comfortably, with headroom if the team grows.

Included in the plan: the Windows Server license, the BAA, mandatory MFA on initial server login, daily onsite and offsite encrypted backups, vulnerability scanning, anti-malware, host intrusion detection, and 24×7 managed support. The no-leak GPO bundle, covering drive, clipboard, printer, removable media, and port redirection at the policy layer, plus browser-level URL controls and download restrictions as a second layer, is applied at provisioning. The License Server role is installed and activated at no extra charge, configured for per-user licensing, and ready to accept the practice’s CAL pack, with the 120-day Microsoft grace period bridging provisioning and CAL delivery.

Monthly billing is a flat, recurring charge. This workload shape, RDP sessions inbound and HTTPS traffic outbound to the EMR cloud, does not generate the per-gigabyte egress charges that make cloud billing unpredictable for data-heavy workloads. The practice gets a predictable number every month against a server it does not have to manage.

## Designing From the Compliance Boundary Inward

You may have seen the pattern throughout this article: a practice that designs offshore-team access from the compliance boundary inward, starting with the BAA and working out toward the desktop, ends up with a hosted Windows session, a no-leak policy layer, predictable licensing, and an SLA that holds. A practice that starts on the contractor’s laptop and extends outward ends up arguing with its auditor.

Atlantic.Net’s role is to provide the environment that makes the compliance boundary real: the BAA, the Windows Business HIPAA hosting tier, server installation, the 100% Uptime Service Level Agreement, and 24×7 managed support that covers the offshore team’s working hours. The practice’s role is to bring the CALs, identify any peripherals that need an exception, and onboard the team. The work splits cleanly along that line.

If you are evaluating Atlantic.Net for a HIPAA-compliant offshore billing deployment, the four questions above are the ones to raise during the first call. Walk us through your EMR, team size, and compliance posture, and the Atlantic.Net pre-sales team can scope a[HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) configuration that fits.

 


---

# How Does Physical Security in Data Centers Support HIPAA Compliance?

> URL: https://www.atlantic.net/hipaa-compliant-hosting/data-center-physical-security-hipaa-compliance/ | Published: 2026-05-17 | Updated: 2026-05-11 | Author: Dr. Assad Abbas

Physical security plays an important role in protecting [electronic Protected Health Information (ePHI)](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/). Healthcare organizations depend on [data centers](https://www.cisco.com/site/us/en/learn/topics/computing/what-is-a-data-center.html) to host, store, and keep their digital systems operational. Therefore, the physical environment must be secured through clear procedures and documented safeguards. In 2026, this requirement will become even more important as healthcare systems rely on cloud platforms, remote access, and distributed infrastructure. The physical protection of data centers serves as the foundation for HIPAA safeguards.

The [Health Insurance Portability and Accountability Act (HIPAA)](https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html) defines requirements for protecting sensitive health information through administrative, technical, and physical measures. Each category has a distinct role, yet they function together to protect ePHI. In this framework, physical safeguards focus on protecting facilities, equipment, and infrastructure from unauthorized access and damage. Therefore, they act as a necessary layer that supports both technical and administrative controls.

Modern healthcare systems operate in cloud and hybrid environments. They still depend on physical servers and storage infrastructure located in data centers. Because of this dependency, attention to the physical setting becomes necessary. Software-based protections alone cannot address risks related to physical access or environmental conditions. Failures in power, cooling, or facility access can affect system availability. Physical security supports both data protection and system reliability, thereby strengthening HIPAA compliance in data center environments.

## What Are HIPAA Physical Safeguards?

HIPAA physical safeguards are the controls that protect the physical environment where ePHI is stored, processed, or accessed. These safeguards are defined under the HIPAA *Security Rule* and are intended to reduce physical risks to systems and infrastructure that handle sensitive healthcare data.

The main components of physical safeguards include:

- ***Facility access controls*** that manage entry into buildings and restricted areas such as server rooms and equipment cages.
- ***Device and media controls*** that focus on tracking, protecting, and securely disposing of hardware and storage media.
- ***Workstation security***, which applies to end-user systems, is limited in data center environments due to restricted access zones.

These safeguards support the confidentiality, integrity, and availability of ePHI by addressing physical risks in data center environments. Limited physical access reduces the chance of unauthorized exposure. In the same way, proper device handling helps maintain data accuracy and prevents the loss of sensitive information. Environmental and facility controls also contribute to stable system operation by reducing disruptions caused by power or cooling outages or physical incidents.

Physical safeguards also work alongside technical safeguards. For example, encrypting data at rest and in transit with TLS protects data at the data level, while physical controls prevent direct access to underlying systems and infrastructure. Technical controls cannot prevent physical access to infrastructure. Therefore, physical safety measures remain a necessary layer in the protection model.

Because of this layered structure, physical safeguards also play an important role during HIPAA audits. They provide documented evidence that access is controlled and monitored. Auditors often review access logs, surveillance records, and media handling procedures. This documentation supports compliance verification in a clear, structured manner.

## How Physical Security in Data Centers Supports HIPAA Compliance

Physical security in data centers supports HIPAA compliance by structuring access controls, protecting infrastructure, and maintaining stable operating conditions. It reduces risks, such as unauthorized entry, equipment interference, and operational disruption. These controls, as discussed below, work to protect both systems and the data they handle.

### Preventing Unauthorized Physical Access

Data centers use controlled zones to regulate movement within facilities, and access is limited based on job roles and operational needs. Entry is managed through badge systems, biometric authentication, and monitored checkpoints, while entry points are continuously observed through surveillance systems and access logs. These controls reduce unnecessary exposure to sensitive infrastructure.

### Protecting Hardware Systems

Physical safeguards also protect servers, storage systems, and network equipment from theft or tampering. These components are usually placed in locked racks or secured cages. Such controls reduce the possibility of direct physical interference.

In addition, protection is not limited to equipment alone. Internal access within secure areas is also controlled through strict policies and monitoring systems. Even authorized personnel operate under defined access limits. In addition, sensitive systems are physically separated to reduce unnecessary exposure.

### Ensuring Operational Integrity

Physical security also supports stable and continuous system operations. Data centers maintain controlled environments for temperature, humidity, and power supply. These conditions are necessary for the reliable performance of infrastructure hosting ePHI.

As a result, systems remain available and functional even under environmental stress. This helps meet the HIPAA availability requirement and reduces the risk of service interruptions.

## HIPAA Facility Access Controls in Data Centers

Facility access controls define entry and movement within a data center environment and are implemented in layers to reduce exposure to sensitive infrastructure. A typical data center includes an outer perimeter, controlled entry points, and restricted internal zones, with access progressively limited at each stage to reduce the risk of unauthorized entry. Within these controlled layers, authentication methods include access cards, biometric verification, and mantrap systems, which restrict entry to one person at a time and reduce tailgating risks.

In the same controlled environment, surveillance systems continuously monitor key areas, storing video recordings for review and triggering alerts during unusual activity. At the same time, access logs maintain detailed records of entry and exit events. Based on these records, access rights are updated when roles change and revoked when individuals leave the organization, and visitor access is strictly controlled, with escorts required in restricted zones.

## HIPAA Device and Media Controls

Device and media controls govern how hardware and storage systems are managed in data centers and ensure that every asset is properly tracked, protected, and handled throughout its lifecycle. Each device is recorded in an inventory system using a unique identifier, allowing it to be tracked from deployment to retirement. At the same time, storage media are clearly labeled to avoid confusion during handling.

With this tracking in place, chain-of-custody records are maintained for every transfer or movement, so responsibility is always clear across operational steps, and encryption is applied to data stored on physical devices to reduce risk if a device is lost or stolen. Along with these measures, movement of devices between secure areas is strictly controlled and logged, which supports both operational security and compliance needs while keeping hardware handling traceable at every stage.

## Media Disposal and Environmental Security Controls

Media disposal and environmental security controls address two connected aspects of physical protection. One part focuses on handling equipment at the end of its lifecycle, while the other maintains a stable data center environment during daily operations. Both are important for maintaining the security and availability of ePHI.

When devices are no longer in use, they are not simply removed and discarded. HIPAA requires that no recoverable data remain on the devices. Therefore, proper sanitization steps are applied before any device leaves the facility. Guidelines such as [NIST SP 800-88 Rev. 2](https://csrc.nist.gov/pubs/sp/800/88/r2/final) state that sanitization should make data access infeasible, depending on the level of effort. Organizations select methods based on data sensitivity. In practice, this includes clearing, purging, or physical destruction. Each step is documented to confirm correct handling. In many cases, media is transported off-site for destruction. Therefore, secure handling must continue during transit until the process is fully completed.

At the same time, attention is given to the environment in which systems operate. Data centers are designed to manage conditions that can affect system performance and stability. Fire suppression systems respond to incidents, while redundant power systems maintain operations during outages. Similarly, cooling systems keep hardware within safe temperature ranges. Sensors monitor humidity, temperature, and potential leaks to identify issues early. In addition, protection measures account for external risks, such as flooding or physical damage. These controls help maintain continuous system operation and reduce downtime in environments that process sensitive healthcare data.

## Business Associate Responsibilities for Physical Security

Data centers that store or handle ePHI usually operate as business associates under HIPAA, which makes them directly responsible for meeting physical safeguard requirements defined in a [HIPAA Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/). This agreement defines the protection requirements for facilities, infrastructure, and systems that store or process sensitive healthcare data.

Responsibility for physical security is shared between the data center provider and the healthcare organization. The provider manages the physical infrastructure, including facility access, hardware protection, and environmental controls. The healthcare organization remains responsible for system configuration and access control within that environment. This separation becomes important in cloud and hosted deployments, where control is divided across different layers.

In addition, subcontractors are often involved in service delivery. These parties must follow the same security requirements, and these obligations are extended through formal agreements across the vendor chain. As a result, physical security expectations remain consistent across all levels.

Organizations should not rely only on contractual commitments. They should also confirm that safeguards are properly implemented in practice. This is typically done through vendor risk assessments, audit reviews, and verification of supporting documentation.

[Atlantic.Net](http://www.atlantic.net) is one example of a HIPAA-compliant hosting provider that operates within this shared responsibility model. It maintains secure data center environments through controlled access, monitored infrastructure, and defined media-handling procedures. It also supports compliance through a BAA and documented operational controls. Such providers help healthcare organizations meet physical security requirements while maintaining stable and reliable systems.

## HIPAA Compliance Checklist for Data Center Physical Security

The checklist below is intended for audit and compliance review of data center environments that handle ePHI. It reflects the expected physical security controls required by HIPAA and helps evaluate whether safeguards are properly implemented and maintained.

### Facility Controls Checklist

- Restricted access areas should be clearly defined and enforced
- Entry points should use approved physical access control systems
- Multi-layer security zones should exist within the facility
- Surveillance systems should cover all critical and sensitive areas
- Security footage is expected to be stored and reviewed according to the defined policy
- Environmental controls should address fire, water, heat, and power risks
- Physical access logs need to be maintained and reviewed regularly

### Device Controls Checklist

- Hardware and storage assets should be recorded in a complete inventory system.
- Each device should carry a unique identifier for tracking
- Data on storage devices should remain encrypted at rest
- Media handling procedures need to be documented and consistently followed
- Chain of custody should be maintained for all hardware and removable media
- Backup media is expected to be stored in secure and controlled environments
- Device movement between secure areas should be logged and monitored

### Business Associate Verification Checklist

- A HIPAA BAA should be active and signed
- Physical safeguard responsibilities should be defined within the agreement
- Vendor physical security controls are expected to be reviewed during assessments
- Subcontractor obligations should be included through formal agreements
- Compliance evidence needs to be available for audit and verification

### Emergency Preparedness Checklist

- Emergency access procedures should be documented and accessible
- Disaster recovery plans should include physical facility scenarios
- Backup systems should be tested on a defined schedule
- Evacuation procedures should be documented and reviewed periodically
- Incident response procedures should be validated through drills or tabletop exercises

## The Bottom Line

Physical security is a core requirement of HIPAA compliance because it protects the environment where ePHI is stored and processed. Even when strong technical and administrative safeguards are in place, weaknesses in physical controls can expose systems to risks that other layers cannot fully mitigate.

Effective facility controls reduce the likelihood of unauthorized access and help maintain stable system operations within data centers. This also makes the selection of hosting providers an important consideration, since compliance depends not only on documented policies but also on the actual strength of physical safeguards in place.

In practice, organizations use structured tools, such as HIPAA-compliant physical security checklists for data centers, to consistently review facility controls, device management, and emergency preparedness. These checks help confirm that safeguards are not only defined but also applied in daily operations.

A consistent, structured approach to physical security supports the long-term protection of sensitive healthcare data and contributes to reliable system operation.


---

# PCI Encryption: Standards, Keys, Drivers, and Best Practices

> URL: https://www.atlantic.net/pci-compliant-hosting/pci-encryption-standards-keys-best-practices/ | Published: 2026-05-19 | Updated: 2026-05-21 | Author: Richard Bailey

PCI DSS is a mandatory security framework for all companies that store, process, or transmit credit card information. The PCI Security Standards Council (PCI SSC) developed a framework with multiple key requirements to ensure cardholder data remains secure. This article examines the details of the Payment Card Industry Data Security Standard (PCI DSS) surrounding the key requirement of data encryption.

## Encryption Standards and Encryption Requirements

The following[key PCI encryption requirements](https://www.pcisecuritystandards.org/standards/) must be implemented to maintain compliance with the data protection standards.

- Encrypt cardholder data such as Primary Account Numbers (PANs) when stored in databases, file systems, logs, or backups. This sensitive data also must be encrypted or rendered unreadable when transmitted over public networks.
- Employ strong cryptographic algorithms such as AES, RSA, or ECC with secure key lengths.
- Protect encryption keys with complete management and strict access controls.
- Mask cardholder data when displayed on screens or in reports.
- Encryption controls should be regularly tested with measures such as vulnerability scans and penetration testing.

Merchants and providers must comply with PCI DSS encryption requirements. Both entities share responsibility for ensuring cardholder data remains secure. Providers have to meet the following additional PCI DSS requirements.

- **Document shared responsibilities:** Providers must supply clear documentation regarding which PCI controls they manage and which are the customers’ responsibility.
- **Environment isolation:** Service providers must validate segment controls and ensure the regulated environment cannot be accessed by other customers.
- **Enhanced monitoring:** Providers must implement measures such as intrusion detection to identify cybersecurity threats, failure detection to ensure the availability of systems containing sensitive data, and change monitoring.
- **Cryptographic architecture:** Providers are responsible for securing customer encryption keys and enforcing strict key lifecycle management. They must document the cryptographic architecture and maintain separate tenant encryption environments.
- **Access governance:** Providers are expected to implement strict access management and authentication controls. They should perform effective background screening and enforce workflow segregation to protect sensitive cardholder data.
- **PCI compliance validation:** Providers typically require annual assessments by a Qualified Security Assessor (QSA).

## Encryption Algorithms

Teams typically use multiple encryption algorithms to protect sensitive information and maintain PCI compliance.

- The Advanced Encryption Standard (AES) is the recommended algorithm for meeting PCI encryption requirements. AES is a symmetric-key algorithm in which the same key is used for both encrypting and decrypting data. It transforms plaintext blocks into ciphertext by performing multiple rounds of cryptographic operations. AES can be implemented with different key sizes. AES-256, with a 256-bit key length, is the most commonly used variation.
- RSA is primarily used for asymmetric key exchange. The algorithm is an asymmetric encryption algorithm that uses two related keys. A public key is used to encrypt data, while a private key is used to decrypt it. The public key can be shared openly, but access to the private key is controlled. Longer key lengths provide enhanced security; RSA-2048 is the recommended minimum.
- Elliptic Curve Cryptography (ECC) is a modern asymmetric cryptographic algorithm that uses elliptic curve mathematics to generate public and private keys. ECC can achieve security levels equivalent to RSA with much smaller key sizes, making it a good choice for mobile and resource-constrained devices.
- The Triple Data Encryption Standard (TDES) is a legacy, symmetric-key encryption algorithm. It is being phased out in favor of modern encryption protocols such as AES that offer stronger security and better performance. Companies using TDES should strongly consider migrating to a more modern solution.

## Managing Encryption Keys

Teams must manage and protect encryption keys effectively to safeguard sensitive cardholder data. Organizations often use a dedicated physical or virtual Hardware Security Module (HSM) to generate, store, manage, and protect cryptographic keys. HSMs are commonly deployed as network-attached appliances, USB devices, PCIe cards, and virtual cloud solutions.

Key access must be logged with userids and timestamps for accountability and auditability. Keys must be rotated to meet company standards and PCI DSS compliance. PCI general requirements recommend annual rotation for data encryption keys (DEKs) and every two years for key encryption keys (KEKs).

### Key Management Procedures

The following is an example of typical PCI encryption key management procedures.

- Keys are generated by authorized personnel as needed using organizationally approved encryption tools and cryptographically secure random number generators (CSPRNGs). The keys should be created on approved platforms, in hardware security modules (HSMs), and in key management systems (KMSs).
- Key access must be restricted to authorized users. The keys should be stored in an encrypted form, with key metadata including the key’s owner, its creation date, length, purpose, and rotation or expiration schedule. All key-related events, such as creation, access, rotation, and deletion, should be logged.
- Teams should rotate keys to meet compliance requirements and company policy. Obsolete keys should be securely destroyed. Compromised keys should be revoked and replaced immediately to provide reliable security.

## Index Tokens and Tokenization

Index tokens enable searchability while protecting sensitive, encrypted data. An index token is a non-sensitive surrogate value that represents sensitive data. The tokens are designed to support lookup and indexing operations without exposing regulated data.

Tokens are widely deployed in databases, search indexes, and application workflows to streamline operations and secure sensitive data. Typical uses of tokens include fast database indexing, separating operational identifiers from protected data, and reducing the scope of PCI DSS compliance.

Businesses strengthen their protection of payment card data by leveraging a combination of tokenization and reversible encryption. Tokenization should be employed to reduce PCI DSS scope and minimize exposure of sensitive data in applications that do not frequently require plaintext. Examples include payment card data processing and creating account identifiers.

Reversible encryption is useful for databases, backups, and full-disk encryption, where the original data is recovered regularly.

## Encryption Practices and Access Controls

Businesses must restrict access to encryption keys with strict Identity and Access Management (IAM) policies. Only authorized personnel should be able to access and use the keys. A weak IAM posture exposes cardholder data to risks from external and internal threat actors.

Companies should implement least-privileged access control for key stores. This approach limits access to this essential information on a need-to-know basis. Teams should use multi-factor authentication for key administrators to protect sensitive data from credential compromises involving authorized personnel.

Teams should document their encryption protocols and publish them so they are accessible throughout the organization. Clear documentation eliminates confusion about the PCI encryption workflow and specifies which business roles require access to encryption keys.

## PCI Encryption Decryption Controller and Chipset Driver

The encryption/decryption controller helps protect data. It is responsible for managing cryptographic operations as data moves through a system. The controller determines when data should be encrypted or decrypted, which keys are used, and how protected data flows throughout the environment.

Chipset driver dependencies can significantly affect the performance of encryption/decryption controllers. The chipset manages communication between the controller, CPU, memory, and other components. Missing, outdated, or incompatible chipset drivers can cause controllers to fail to initialize, exhibit degraded performance, or lose advanced features.

Teams should always perform firmware compatibility checks before driver updates to eliminate unintended consequences that could affect the encryption/decryption controller and the environment.

## Update Drivers: Automatically, Device Manager, Manufacturer

Teams can eliminate a potential point of failure by automatically updating drivers rather than relying on manual processes. The automatic update process makes it easy for non-technical users to keep their drivers up to date and ensures optimal controller performance. The automatic updates system stabilizes and prevents the use of outdated drivers that may introduce performance issues.

Users must ensure they use the recommended driver update tools or processes. They should opt for native operating system functionality or vendor-supplied installation utilities.

### Update via Device Manager

Users can update device drivers manually in Windows Device Manager using the following procedure.

1. Open Device Manager.
2. Expand the category containing the controller driver.
3. Right-click the controller and select Update Driver.
4. Choose to Search automatically for drivers.
5. Install the driver and reboot the system.

### Download Chipset Driver from the Manufacturer

1. Press Windows + R.
2. Type msinfo32.
3. Record the system manufacturer, system model, and BaseBoard Product.
4. Visit the manufacturer’s support site and download the driver for your OS version.
5. Run the manufacturer’s installer as an Administrator.
6. Follow on-screen prompts and steps.
7. Reboot the system and verify the driver has been installed.

## Device Manager Troubleshooting for Encryption Controllers

Use the following procedure to check the driver version in Device Manager.

1. Open Device Manager.
2. Expand the category containing the controller.
3. Right-click the selected controller.
4. Select Properties and open the Driver tab.
5. Review the driver information.

You can roll back newly installed drives if they fail by following these steps.

1. Open Device Manager.
2. Expand the category containing the controller.
3. Right-click the selected controller and choose Properties.
4. Open the Driver tab.
5. Select Roll Back Driver and confirm the activity.
6. Restart the system if needed, and verify that the previous driver has been restored and that encryption services are operating normally.

If the Roll Back Driver option is not available, you must manually reinstall the previous good driver. Teams should always collect and save system event logs for further analysis after a driver failure.

## Securing Data In Transit and At Rest

Organizations must protect regulated data in transit and at rest to meet PCI standards. Payment transactions typically involve leveraging public networks to transmit data. All public network traffic should be protected with point-to-point encryption provided by Transport Layer Security (TLS), ideally version 1.3. Teams can version 1.2 for compatibility, but versions 1.0 and 1.1 should be disabled.

Businesses must implement encryption at rest for databases that store cardholder data. The industry standard is AES-256, which we recommend to protect confidential data.

Teams must also ensure that backups of sensitive data are encrypted to prevent unauthorized access. Threat actors can use unencrypted backups to steal PCI-regulated data.

## Performance, Challenges, and Trade-Offs

Decision-makers must understand that from the perspective of their IT environment, strong encryption is not free. Companies implementing PCI encryption may face performance degradation requiring more powerful computing capabilities. Encryption may add to existing processes that must be addressed effectively to maintain PCI DSS compliance.

The performance impacts of strong encryption include:

- Increased CPU consumption;
- Greater latency;
- Slower storage access.

Symmetric encryption algorithms are faster and require fewer computational resources than asymmetric ones. Hardware security modules (HSMs) speed up secure key operations and are widely used in payment processing solutions.

Companies should test the impact of encryption in a test or staged environment that does not affect production systems. Teams can evaluate the effects of encryption on performance and latency to make appropriate modifications and avoid disrupting production workflows.

Organizations should adopt a similar mindset when integrating new PCI encryption processes or solutions into existing legacy environments. Companies will benefit from a methodical approach that protects cardholder data without compromising legacy system performance.

## Compliance Audit Checklist

Companies may be audited to ensure they meet PCI DSS encryption requirements. Teams will need to provide appropriate evidence to demonstrate PCI DSS compliance and avoid fines or penalties. The following artifacts must be provided on request by auditors.

Teams must provide evidence of the cryptographic methods used to meet PCI encryption standards. This evidence includes detailing the systems used to encrypt data and the measures taken to protect encryption keys.

Organizations must make key management logs available for auditor review. The auditors must verify that only authorized personnel have access to encryption keys and that these keys are managed effectively to maintain compliance.

Teams should provide documentation for all cardholder data workflows to validate the scope of PCI encryption and compliance efforts. Auditors should be able to easily verify the flow of sensitive data through the system to ensure it is encrypted and used appropriately throughout the workflow.

## FAQs and Resources

Teams should consider using encryption policy templates as a starting point for policy creation.

- [National Cybersecurity Society](https://nationalcybersecuritysociety.org/wp-content/uploads/2019/10/Encryption-Policy-Template-FINAL.pdf)
- [FRSecure](https://frsecure.com/encryption-policy-template/)
- [University of Texas at Austin](https://security.utexas.edu/policies/encryption)

Users can find additional information about tokenization and point-to-point encryption at the following sites.

Tokenization:

- [Mastercard](https://www.mastercard.com/us/en/news-and-trends/stories/2025/what-is-tokenization.html)
- [PCI SSC](https://listings.pcisecuritystandards.org/documents/Tokenization_Guidelines_Info_Supplement.pdf)

P2PE options:

- [PCI SSC](https://listings.pcisecuritystandards.org/documents/P2PE_Program_Guide_v2.0.pdf)
- [Global Payments Integrated](https://help.globalpaymentsintegrated.com/1/payment-devices/semi-integrated/countertop/what-is-p2pe/)


---

# Cookie Policy

> URL: https://www.atlantic.net/cookie-policy/ | Updated: 2026-09-16

**Last Updated:** September 12, 2026

Atlantic.Net, Inc. (“Atlantic.Net,” “we,” “us,” or “our”) uses cookies and similar technologies on atlantic.net and related Atlantic.Net web properties to operate our website, protect our services, improve performance, support analytics, and provide relevant communications.

## Introduction

This Cookie Policy explains how cookies and similar technologies may be used when you visit our website, interact with our services, use customer-facing tools, or access related online resources.

This policy should be read together with our Privacy Policy, Terms of Service, Acceptable Use Policy, AI Policy, and other applicable Atlantic.Net service policies.

## 1. What Are Cookies?

Cookies are small text files that may be placed on your computer, browser, mobile device, or other internet-connected device when you visit a website.

Cookies can help a website remember information about your visit, such as your preferred settings, session status, consent choices, and how you interacted with pages or services.

For purposes of this Cookie Policy, “cookies” also includes similar technologies, such as tracking pixels, web beacons, tags, local storage, session storage, and similar online identifiers.

Cookies may be set directly by Atlantic.Net or by third-party service providers that support website functionality, analytics, advertising, security, communications, or embedded content.

## 2. Why We Use Cookies

Atlantic.Net may use cookies and similar technologies for the following purposes:

- To operate and secure our website and online services.
- To remember user preferences and cookie consent choices.
- To support account login, customer portal functionality, and session management.
- To monitor website performance and improve the user experience.
- To analyze website traffic and understand how visitors use our content.
- To help detect fraud, abuse, suspicious traffic, and malicious activity.
- To support customer support tools, contact forms, and communication features.
- To measure marketing performance and improve campaign relevance.
- To support embedded content, such as videos, forms, chat tools, or third-party integrations.
- To comply with legal, regulatory, security, and operational obligations.

**Security note:** As a cloud infrastructure and hosting provider, Atlantic.Net may also use certain security and operational technologies to help protect our website, network, customer portals, and related infrastructure from unauthorized access, abuse, malicious automation, and other security threats.

## 3. Types of Cookies We Use

Atlantic.Net may use the following categories of cookies, depending on your location, consent choices, browser settings, and the services or pages you access.

### Strictly Necessary Cookies

Strictly necessary cookies are required for the website and services to function properly. These cookies may be used for security, fraud prevention, consent management, load balancing, session management, account access, and basic website functionality.

These cookies generally cannot be disabled through our cookie consent tool because they are required to provide the website or services requested by the user.

Examples may include cookies used for website security, login authentication, customer portal sessions, cookie consent storage, network traffic routing, abuse prevention, and form submission protection.

### Functional Cookies

Functional cookies help provide enhanced website features and remember choices you make.

These cookies may support language or region preferences, display preferences, form-related preferences, chat or support settings, accessibility preferences, and previously selected website options.

If functional cookies are disabled, certain website features may not work as intended.

### Analytics and Statistics Cookies

Analytics and statistics cookies help Atlantic.Net understand how visitors interact with our website and content.

These cookies may collect information such as pages visited, time spent on pages, referring websites, approximate geographic region, browser and device information, website performance data, and error or diagnostic information.

Atlantic.Net may use analytics tools to improve website performance, usability, accessibility, content quality, and service information.

Where required by law, analytics or statistics cookies will only be used after consent is provided.

### Marketing and Advertising Cookies

Marketing and advertising cookies may be used to measure advertising performance, support remarketing, improve campaign relevance, and understand the effectiveness of Atlantic.Net marketing efforts.

These cookies may be set by Atlantic.Net or third-party advertising and marketing platforms.

Marketing cookies may track browsing activity across websites and over time. Where required by law, these cookies will only be used after consent is provided.

### Embedded Content and Third-Party Cookies

Some pages may include embedded content or third-party integrations, such as videos, maps, forms, social media features, analytics tools, chat systems, advertising platforms, or support tools.

These third parties may place their own cookies or similar technologies. Their use of cookies is governed by their own privacy and cookie policies.

## 4. Cookies Placed on This Website

Atlantic.Net manages cookie consent, regional consent settings, and cookie-policy disclosures with its own consent tool, built into this website.

The cookie list below is generated from this website’s own configuration rather than from a scan, so it reflects what the site is actually set up to use and changes whenever an integration is switched on or off.

Where enabled, the following third-party services may also set cookies through our tag manager: Google (Analytics and Ads), Microsoft Advertising (Bing), HubSpot, Hotjar, Improvely, Simpli.fi, and OpenAI (ChatGPT Ads). Embedded media such as YouTube and Wistia may set cookies when you play a video. Each service is governed by its own privacy and cookie policy.

### Strictly necessary

| Cookie | Set by | Retention | Purpose |
| --- | --- | --- | --- |
| `anet_consent` | Atlantic.Net (first party) | 180 days | Stores your cookie consent choices so we do not ask again on every page, and so consent-gated scripts know whether they may run. |

### Embedded third-party content (loads only when you click)

| Cookie | Set by | Retention | Purpose |
| --- | --- | --- | --- |
| `_calendly_session` | Calendly | Session | Keeps your place in the booking calendar while you pick a time. Set only after you load the calendar on the contact page. |
| `__cf_bm` | Cloudflare, on behalf of Calendly | 30 minutes | Bot protection for the Calendly booking service. Set only after you load the calendar. |
| `__stripe_mid, __stripe_sid` | Stripe, on behalf of Calendly | 1 year, 30 minutes | Fraud prevention for Calendly's payment platform, loaded by the calendar even though our bookings are free. Set only after you load the calendar. |
| `NID` | Google (docs.google.com) | 6 months | Set inside the Google Slides presentation frame on the sales demo page, only after you load the presentation. |

No analytics or advertising cookies are currently in use on this website. If that changes, the categories and cookies will be listed here and will only be set after you consent to them.

## 5. Managing Your Cookie Preferences

You can manage your cookie preferences through the cookie banner or preference center available on our website.

Where applicable, you may choose whether to accept, reject, or customize non-essential cookies by category.

You can review or update your consent settings at any time using the consent management tool below.

You may also manage cookies through your browser settings. Most browsers allow users to block cookies, delete cookies, restrict third-party cookies, or receive alerts before cookies are placed.

Please note that disabling certain cookies may affect website functionality, login access, customer portal features, support tools, form submissions, security protections, and user experience.

## 6. Consent by Region

Cookie and privacy requirements may vary depending on where you are located.

Atlantic.Net’s consent tool supports region-based consent handling, including jurisdictions where consent may be required before non-essential cookies are placed.

Depending on your location, the cookie banner or preference center may provide different options, disclosures, or consent settings.

## 7. Do Not Track and Browser Signals

Some browsers may send “Do Not Track” or similar signals.

Because there is not a single uniform legal or technical standard for responding to these signals, Atlantic.Net may not respond to all browser-based tracking signals in the same manner.

Where required by applicable law or supported by the website’s consent management configuration, Atlantic.Net may honor legally recognized opt-out preference signals through supported consent tools or browser mechanisms.

## 8. Security and Infrastructure Monitoring

Atlantic.Net may use necessary cookies, logs, and similar technologies to support security, service reliability, infrastructure monitoring, and abuse prevention.

These technologies may help us detect malicious traffic or suspicious activity, prevent unauthorized access, maintain website availability, protect customer-facing systems, investigate security incidents, and support compliance and operational obligations.

These activities are important to the secure operation of Atlantic.Net’s website, hosting services, and infrastructure-related platforms.

## 9. Relationship to the Privacy Policy

Information collected through cookies may be considered personal information under certain privacy laws.

For more information about how Atlantic.Net collects, uses, discloses, protects, and retains personal information, please review our Privacy Policy.

## 10. Updates to This Cookie Policy

Atlantic.Net may update this Cookie Policy from time to time to reflect changes in technology, law, website functionality, third-party providers, analytics tools, marketing platforms, or service operations.

When this Cookie Policy is updated, the “Last Updated” date above will be revised.

Users are encouraged to review this Cookie Policy periodically.

## 11. Contact Information

If you have questions about this Cookie Policy, Atlantic.Net’s use of cookies, or our privacy practices, please contact us through the contact methods provided on our website.

**Atlantic.Net, Inc.**

**Website**
 [https://www.atlantic.net](https://www.atlantic.net/)

**Support**
 [https://www.atlantic.net/support/](https://www.atlantic.net/support/)

**Contact**
 [Contact us](https://www.atlantic.net/about-us/corporate-contact/)

## 12. Related Policies

For additional information, please review the following Atlantic.Net policies and resources:

- [Privacy Policy](https://www.atlantic.net/privacy-policy/)
- [Terms of Service](https://www.atlantic.net/service-policies/)
- [Acceptable Use Policy](https://www.atlantic.net/acceptable-use-policy/)
- [AI Policy](https://www.atlantic.net/ai-policy/)
- [Service Policies](https://www.atlantic.net/service-policies/)


---

# Bare Metal for FinTech: High Performance Infrastructure Playbook for 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/bare-metal-fintech-infrastructure/ | Published: 2026-05-22 | Author: Dr. Assad Abbas

[Financial Technology (FinTech)](https://www.fintechweekly.com/fintech-definition) platforms in 2026 process very large amounts of data and transactions every second. Trading systems, payment gateways, fraud detection engines, and AI-based financial analytics all depend on infrastructure that can respond quickly and consistently. In these environments, even small delays can affect transaction execution, customer experience, and operational stability.

Financial organizations require strong audit controls, clear infrastructure isolation, and detailed logging. As a result, decisions about infrastructure affect technical performance, regulatory readiness, and operational reliability.

Many FinTech companies still use cloud infrastructure because it is flexible and quick to deploy. [Multi-tenant cloud](https://www.zscaler.com/resources/security-terms-glossary/what-is-multitenant-cloud-architecture) environments can bring challenges for transaction-heavy systems. Shared resources may lead to uneven I/O performance, latency variation, and noisy-neighbor effects. In addition, consumption-based billing can make infrastructure spending difficult to predict over time. These issues can create operational uncertainty for workloads that require stable and continuous performance.

Many organizations are considering [bare metal](https://www.atlantic.net/dedicated-server-hosting/what-is-a-bare-metal-server-benefits-use-cases-and-best-practices/) infrastructure for business-critical financial workloads. Bare metal servers provide direct access to dedicated hardware, preventing resources from being shared with other tenants. As a result, they offer more predictable performance, stronger isolation, and greater operational control for latency-sensitive systems. These qualities make bare metal a practical option for FinTech platforms that require stable throughput, compliance alignment, and predictable operating costs.

## Why Bare Metal Suits Financial Workloads

Bare metal infrastructure is widely used in environments where stable performance and low latency are critical. Many financial systems process transactions and requests in real-time under continuous load. Therefore, infrastructure consistency and predictable response times are important operational requirements.

Several characteristics, such as direct hardware access, stronger workload isolation, stable performance under sustained demand, and more predictable operating costs, make bare-metal infrastructure well-suited to these workloads, as discussed below.

### Direct Hardware Access and Predictable Performance

In virtualized environments, applications share physical hardware via a hypervisor. While this model supports flexible scaling, it can also introduce variability in CPU scheduling, memory allocation, and storage performance. Such variability can lead to performance inconsistencies in transaction-heavy financial systems that require stable, predictable response times.

On the other hand, bare metal servers remove this abstraction layer and provide direct access to physical hardware resources. This enables workloads such as high-frequency trading, fraud detection, payment processing, and financial analytics to maintain more stable performance under sustained demand, and can help reduce latency variability when properly configured.

### Single-Tenant Isolation and Compliance Benefits

Bare metal infrastructure uses a single-tenant model, in which physical hardware resources are dedicated to a single organization rather than shared across multiple customers. This approach reduces cross-tenant interference and helps maintain more consistent performance for payment processing systems, trading platforms, and real-time fraud detection workloads. It also more effectively supports PCI-compliant segmentation by creating clearer infrastructure boundaries for sensitive financial systems.

In addition, bare-metal environments give FinTech organizations greater direct control over logging, network segmentation, access policies, and security monitoring than shared multi-tenant platforms. These controls support detailed auditability, stronger operational visibility, and tighter management of sensitive transaction data.

### Stable Performance and Predictable Costs

Financial systems often process transactions continuously throughout the day. During periods of high activity, shared cloud environments may experience inconsistent performance because physical resources are distributed among multiple tenants. In contrast, bare metal infrastructure delivers more stable CPU, storage, and network performance under sustained load, helping maintain reliable transaction throughput for latency-sensitive financial operations.

Predictable infrastructure cost is another important consideration for FinTech organizations. Cloud pricing models are usually based on resource consumption, which can make long-term costs difficult to estimate for continuously active workloads. Bare metal infrastructure, on the other hand, typically uses fixed monthly pricing. As a result, organizations can plan infrastructure spending more accurately for systems such as fraud detection platforms, real-time analytics workloads, and high-throughput transaction-processing environments.

## Combining Bare Metal and Virtualized Infrastructure for FinTech

Most FinTech organizations do not migrate all workloads to bare metal infrastructure at once. Instead, they often use hybrid environments that combine dedicated hardware with virtualized platforms. This approach helps organizations balance stable performance for business-critical systems with the flexibility and scalability of cloud infrastructure.

Workloads with strict latency or throughput requirements, such as transaction processing, fraud scoring, and real-time analytics, are usually placed on bare metal. Development environments, internal tools, and temporary workloads continue on virtualized systems. This separation helps financial organizations use infrastructure efficiently without overprovisioning dedicated hardware.

Workload placement also affects infrastructure planning. Before deploying bare metal systems, organizations typically evaluate transaction volume, concurrency requirements, storage throughput, GPU utilization, and network latency targets to select appropriate hardware configurations. Geographic placement may also influence deployment decisions, particularly for systems that require lower transaction latency.

Hardware configurations should also match workload requirements. Financial systems often use high-frequency CPUs, NVMe storage arrays, GPU acceleration, NUMA-aware setups, and high-throughput network interfaces to maintain stable performance under continuous demand.

Monitoring and maintenance are equally important after deployment. Many organizations use centralized monitoring and logging platforms to track infrastructure health, storage performance, latency, and resource utilization across their environments. For low-latency systems, additional techniques such as CPU pinning, RDMA networking, kernel tuning, and regular benchmarking may also be implemented to maintain consistent performance over time.

## Performance Critical FinTech Workloads on Bare Metal

Financial workloads in trading, analytics, and machine learning require stable throughput, low-latency execution, and consistent resource availability over extended periods. To meet these demands, organizations often deploy bare-metal infrastructure for workloads that cannot tolerate performance variability. Some of the most common examples of these workloads include low-latency trading systems, financial analytics workloads, and machine learning environments, as discussed below.

### Low Latency Trading and Fraud Scoring

Trading systems process transactions within extremely short time windows, where even minor variations in latency can affect execution consistency. Similarly, fraud scoring platforms analyze large transaction streams in real time and must respond before transactions are approved or blocked.

Because these workloads depend heavily on response-time consistency, organizations often optimize bare metal infrastructure for low-latency processing. Techniques such as DPDK, CPU pinning, and kernel-level tuning help reduce packet-processing overhead and maintain stable latency behavior during periods of high transaction activity.

### High Performance Computing and Financial Analytics

In addition to transaction processing systems, many financial institutions use high-performance computing for Monte Carlo simulations, quantitative modeling, portfolio analysis, and stress testing. These workloads continuously process large datasets and often require strong parallel processing capability, large memory capacity, and fast storage access.

Bare metal infrastructure is commonly used in these environments because it supports sustained compute performance and high-throughput storage for continuously active analytics pipelines.

### Machine Learning Training and Inference

Machine learning has also become an important part of modern financial systems. Financial organizations now use machine learning models for fraud detection, customer analytics, forecasting, and risk scoring. Large-scale model training often requires GPU acceleration and stable resource allocation, while inference systems depend on predictable response times for real-time financial applications.

For these reasons, many organizations deploy machine learning workloads on bare metal infrastructure to maintain dedicated GPU access and achieve more consistent performance during both training and inference. Containerized machine learning pipelines and reproducible deployment environments also help maintain operational consistency between training and production systems.

## Bare Metal vs Virtualized Infrastructure for FinTech

Both bare metal and virtualized infrastructure are commonly used in financial environments. Each approach is suitable for different workloads and operational requirements. The following table summarizes the key operational differences between bare-metal and virtualized infrastructure for FinTech workloads.

Table 1: Comparison of Bare Metal and Virtualized Infrastructure for FinTech Workloads

| **Category** | **Bare Metal** | **Virtualized Infrastructure** |
| --- | --- | --- |
| Latency Predictability | High and consistent | May vary under shared load |
| Performance Consistency | Stable under sustained demand | Can fluctuate |
| Tenant Isolation | Dedicated hardware | Shared resources |
| Scalability | Moderate | High |
| Cost Predictability | Fixed monthly pricing | Consumption-based pricing |
| GPU Access | Direct access | Shared or virtualized access |
| Compliance Segmentation | Easier to manage | More complex to separate |

 

Virtualized infrastructure is often suitable for development environments, elastic workloads, and rapidly scaling applications. In contrast, bare metal infrastructure is commonly preferred for financial systems that require more predictable resource behavior and sustained performance consistency.

## Security and Compliance for Bare Metal FinTech Infrastructure

Financial systems process highly sensitive transaction data and often operate under strict regulatory requirements. Therefore, organizations deploying FinTech workloads on bare-metal infrastructure must implement governance controls to support auditability, operational visibility, and secure infrastructure management across dedicated hardware environments. The following sections describe key areas of governance, including PCI-compliant controls, physical security at the data center, and encryption, logging, and key management practices.

### PCI-Compliant Infrastructure Controls

Payment-processing systems running on bare metal infrastructure commonly require controlled access policies, infrastructure segmentation, centralized logging, authentication monitoring, and security event tracking. Because physical hardware resources are dedicated to a single organization in this model, infrastructure boundaries are often easier to define and audit in PCI-compliant environments.

### Physical Security and Facility Controls

Physical security is also an important consideration for FinTech workloads running on bare metal infrastructure, as these systems operate on dedicated hardware within data center facilities. Therefore, financial organizations commonly evaluate controls such as biometric access systems, CCTV monitoring, visitor logging, restricted cabinet access, and environmental monitoring before deploying regulated workloads on dedicated servers.

These controls help organizations maintain stronger operational oversight and support compliance with requirements for infrastructure access and auditability.

### Encryption, Logging, and Key Management

In addition to physical and infrastructure-level controls, financial environments also require reliable protection for data in transit and system activity. Therefore, organizations operating bare metal infrastructure commonly implement encryption, centralized logging, and secure key management practices to maintain operational visibility and support regulatory compliance.

Data encrypted in transit using TLS helps protect communication between financial systems, applications, and users. Similarly, immutable audit logs, centralized SIEM, secure key management systems, and controlled access policies help organizations monitor infrastructure activity and support forensic investigations during security incidents.

## Cost Planning and Infrastructure Strategy for FinTech

Infrastructure decisions in financial environments are often influenced by long-term operational planning as well as raw performance requirements. Organizations operating continuously active workloads may prefer dedicated infrastructure because resource allocation, hardware capacity, and operational behavior are easier to plan over longer deployment cycles.

Bare metal infrastructure is commonly used for workloads that maintain relatively stable utilization over time, such as transaction-processing systems, analytics pipelines, and machine learning environments. In these cases, organizations can reserve infrastructure capacity in advance and manage hardware resources more directly in line with workload requirements.

Many financial organizations also use phased deployment strategies when adopting bare metal infrastructure. Instead of migrating entire platforms immediately, teams often begin with selected workloads that require stricter latency targets, sustained throughput, or dedicated GPU resources. This approach helps organizations evaluate operational behavior and infrastructure before wider deployment.

## Practical Results and Business Impact

Real-world deployment examples illustrate the operational impact of bare-metal infrastructure in production environments. In FinTech systems, these infrastructure decisions can directly affect transaction consistency, API response behavior, and long-term operational cost planning.

A published migration report by [OneUptime](https://oneuptime.com/blog/post/2023-10-30-moving-from-aws-to-bare-metal/view) described the company’s transition from AWS to a bare metal deployment hosted in a colocation facility. According to the report, the migration significantly reduced long-term infrastructure spending, with estimated annual savings exceeding $230,000 after accounting for operational costs.

Similarly, benchmark testing of a FinTech API workload reported measurable performance improvements after migrating from virtualized infrastructure to bare-metal environments. The deployment achieved lower latency variation, higher throughput, and p99 latency below 3 ms under production workloads.

These examples show that bare metal infrastructure can improve operational stability for continuously active financial workloads that depend on predictable response times and sustained throughput.

## Bare Metal Infrastructure for FinTech Workloads with Atlantic.Net

[Atlantic.Net](http://www.atlantic.net) provides bare metal hosting environments for FinTech organizations running performance-sensitive, business-critical workloads. The platform includes dedicated compute infrastructure, customizable storage configurations, and flexible network architecture for applications that require stable throughput and predictable operational behavior.

Organizations can deploy latency-sensitive systems, such as transaction processing platforms, analytics workloads, and machine learning environments, on dedicated hardware while integrating them with cloud and virtualized infrastructure as needed. Atlantic.Net also provides infrastructure monitoring, backup management, and deployment configurations suitable for regulated financial environments that require stronger operational control and long-term infrastructure stability.

These capabilities can help financial organizations manage continuously active workloads more efficiently while maintaining greater consistency across production infrastructure.


---

# Bare Metal Hosting and Hybrid Cloud Integration: The 2026 Enterprise Guide

> URL: https://www.atlantic.net/dedicated-server-hosting/bare-metal-hybrid-cloud-integration-guide/ | Published: 2026-05-22 | Author: Dr. Assad Abbas

Enterprises in 2026 manage larger datasets and increasingly demanding applications, which require hosting solutions that deliver predictable performance and comply with strict regulations. To meet these demands, systems must also scale efficiently to handle growing workloads without disrupting critical operations.

[Hybrid cloud](https://www.atlantic.net/ashburn-virginia-hosting/understanding-hybrid-cloud-examples/) models offer a practical way to balance these needs by combining [bare metal servers](https://www.atlantic.net/dedicated-server-hosting/bare-metal-cloud-servers-for-high-performance-workloads/) with cloud platforms. Bare metal servers provide direct access to physical hardware, eliminating the unpredictability of shared environments. They also support regulatory compliance, which is particularly important for industries such as healthcare and finance. By integrating bare metal servers with cloud resources, enterprises can scale capacity while maintaining stable, predictable performance.

This article provides a guide for integrating bare metal with hybrid cloud and offers IT architects and compliance teams practical guidelines for managing enterprise workloads efficiently and reliably.

## Understanding Bare Metal Hosting in Enterprise

Bare metal servers are physical machines dedicated to a single organization. They provide applications with direct access to CPU, memory, storage, and network resources. Since they operate without a virtualization layer, workloads achieve predictable performance and strong isolation. This is particularly important for enterprise applications that handle sensitive data or require high reliability.

Bare metal cloud extends these capabilities by combining dedicated hardware with cloud-style provisioning. Enterprises can deploy servers through APIs and manage them with orchestration tools. This setup supports automated management and flexible scaling while maintaining complete control over the hardware. As a result, critical workloads perform consistently even when resource demands change.

It is also important to understand the differences between the three main hosting models, namely traditional dedicated servers, bare metal servers, and bare metal cloud, because each affects performance, flexibility, and operational costs. Traditional dedicated servers are physical machines that require manual provisioning, which can slow deployments and reduce agility. Bare metal servers, in contrast, include management tools while keeping the hardware dedicated. This combination provides both control and operational capabilities for enterprise workloads. Bare-metal cloud, on the other hand, offers API-driven provisioning and integrates with cloud workflows. It supports automated management and scaling, helping organizations respond to changing demands without sacrificing performance.

By understanding these distinctions, enterprises can plan hybrid environments that meet performance requirements while maintaining compliance standards. The following table summarizes these hosting models.

Table 1: Hosting Model Comparison

| **Feature** | **Dedicated Server** | **Bare Metal Server** | **Bare Metal Cloud** |
| --- | --- | --- | --- |
| Tenant Type | Single | Single | Single |
| Hardware Control | Full | Full | Full |
| API Provisioning | Limited | Moderate | Full |
| Scalability | Low | Medium | High |
| Automation | Low | Medium | High |

Hybrid bare-metal architectures connect bare-metal servers to cloud platforms, enabling workloads to move between environments based on performance, compliance, or scaling requirements. In this way, each workload runs in the environment that best supports its objectives. Combining dedicated hardware with cloud resources delivers stable performance and flexible capacity, making hybrid bare metal solutions well-suited for modern enterprise operations.

## Benefits of Bare Metal and Bare Metal Cloud

Bare-metal and bare-metal cloud servers deliver enterprise workloads with predictable performance, operational control, and cost. These qualities make them suitable for applications that demand reliability, low latency, and regulatory compliance. Understanding these benefits helps IT teams select the appropriate infrastructure and plan hybrid environments effectively.

One of the primary benefits of bare metal servers is predictable performance. Since there is no virtualization layer, latency and throughput can be more predictable than in shared environments. This level of reliability is critical for workloads that process large volumes of data or require real-time processing. Applications that particularly benefit from the predictable performance of bare metal servers include High Performance Computing (HPC), Artificial Intelligence (AI), and Machine Learning (ML) pipelines, financial trading systems, and large-scale analytics. Additionally, workloads that require strict isolation or must meet regulatory standards benefit from the consistent performance provided by dedicated hardware.

Another important benefit of bare metal servers is complete control over the hardware and the operating system. IT teams can configure BIOS and firmware settings, apply custom kernels, and access GPUs or NVMe storage directly. This level of control allows organizations to optimize performance for specialized workloads, such as AI training or intensive analytics, while ensuring compliance and operational reliability.

Enterprises can deploy bare-metal cloud servers via APIs and manage workloads with orchestration tools, enabling them to set up applications and maintain consistent performance quickly. On these servers, Kubernetes clusters can run directly to manage containers efficiently, and hybrid container platforms can integrate bare metal with cloud-managed Kubernetes services. This setup ensures that workloads scale effectively and remain stable even as demands change.

Cost is also an important benefit of bare-metal and bare-metal cloud servers. Bare metal servers provide a predictable total cost of ownership and reduce virtualization licensing costs. They are particularly suited for steady, long-running workloads, enabling enterprises to plan budgets accurately and avoid unexpected costs. Likewise, bare-metal cloud delivers similar financial benefits and enables resource scaling, reducing idle capacity and improving operational efficiency.

Table 2: Comparison of Bare Metal and Bare Metal Cloud Benefits

| **Feature** | **Bare Metal Server** | **Bare Metal Cloud** |
| --- | --- | --- |
| Performance | Predictable latency and throughput | Predictable latency with cloud provisioning |
| Hardware/OS Control | Full access to BIOS, firmware, kernels, GPUs, and NVMe | Full access with automation via APIs |
| Flexibility | Moderate (manual scaling and management) | High (rapid provisioning, orchestration, Kubernetes support) |
| Cost | Predictable TCO, reduced licensing | Predictable TCO with scalable resource usage |

How Hybrid Architectures Support Enterprise Workload

Hybrid architecture uses bare metal, cloud, and edge resources to meet different workload requirements. Each environment provides specific capabilities that complement the others and support different types of enterprise workloads.

Bare metal servers are suitable for performance-critical workloads that demand consistent throughput and low latency. They are particularly effective for applications with compliance or regulatory requirements because dedicated hardware simplifies isolation and auditing. These characteristics make bare metal servers the preferred choice for workloads that require reliability and predictability.

In contrast, workloads with variable demand or that require a broader geographic reach are better suited to cloud platforms. Applications with seasonal spikes, batch processing tasks, or content delivery for distributed users perform efficiently on cloud platforms because resources can scale dynamically. This elasticity helps enterprises meet demand without over-provisioning dedicated infrastructure, maintaining both cost and operational performance.

Finally, some workloads require low-latency processing near users or devices, which is best supported by edge nodes. Processing data close to the source improves responsiveness for real-time applications, such as IoT analytics, video streaming, and autonomous device monitoring. By placing workloads at the edge, enterprises reduce latency and the user experience for time-sensitive services, completing the hybrid architecture strategy.

### Workload Placement and Container Management

Proper workload placement ensures that applications operate in the environment best suited to their performance, compliance, and latency requirements. Specifically, performance-sensitive or regulated workloads are typically deployed on bare metal servers, while workloads with fluctuating demand or global distribution are better suited to cloud platforms. Low-latency or localized processing tasks should run on edge nodes, therefore ensuring reliability.

Additionally, [containers](https://www.snowflake.com/resource/containers-on-the-cloud/) and [orchestration](https://www.freshworks.com/freshservice/it-operations-management/cloud-orchestration/) tools support management across these environments. For example, Kubernetes can run on both bare metal and cloud platforms, while hybrid container platforms combine bare metal and cloud-managed services to provide coordinated management. Unified CI/CD pipelines maintain reliability and enforce policies across environments, therefore supporting consistent deployment and smooth scaling. Planning container strategies early ensures workloads remain stable and compliant throughout their lifecycle.

### Networking and Performance Validation

Networking is essential for ensuring consistent performance in hybrid architectures. To achieve this, private connections such as dedicated fiber links, MPLS, and SD-WAN provide secure and stable communication between environments. Additionally, cloud peering reduces reliance on public networks and improves throughput. Before migrating workloads, teams should assess network performance by measuring latency, throughput, jitter, and packet loss to ensure that applications operate efficiently across the entire hybrid infrastructure.

Table 3: Hybrid Workload Placement Overview

| **Workload Type** | **Recommended Environment** | **Reason** |
| --- | --- | --- |
| Performance-sensitive / low-latency | Bare Metal | Stable throughput and predictable latency |
| Variable or bursty workloads | Cloud | Elastic scaling reduces cost and resource strain |
| Globally distributed applications | Cloud regions | Reduces latency for distributed users |
| Compliance-critical or sensitive data | Bare Metal | Strong isolation and regulatory compliance |
| Real-time processing near users | Edge | Minimizes latency and improves responsiveness |

## Operational Reliability, Security, and Compliance

Ensuring operational reliability, security, and compliance is critical for enterprise workloads in hybrid environments. The following practices help maintain stable, secure, and compliant operations:

### Planning Disaster Recovery

- Disaster recovery runbooks should be hardened, and multi-region replication may be configured to ensure continuity.
- Recovery Point Objectives (RPO) and Recovery Time Objectives (RTO) need to be defined for each workload to prioritize critical systems.
- Backup schedules should be maintained daily, weekly, and monthly, with immutable storage to protect against data loss.

### Security

- Hardware and operating systems should be hardened with BIOS/firmware updates, OS baselines, and network segmentation.
- Monitoring and identity management may be applied centrally, with SIEM dashboards collecting logs across environments.
- Access control needs to include Role-Based Access Control (RBAC), multi-factor authentication, and physical security to prevent unauthorized access.

### Compliance

- HIPAA regulations for electronic Protected Health Information (ePHI) should be followed, including the requirement for a HIPAA Business Associate Agreement (BAA).
- Data in transit may be encrypted using TLS, with logging and access documentation maintained for audits.

## Migration and Planning

Migration planning ensures workloads move safely across hybrid environments while maintaining operational reliability, security, and compliance. Key steps include:

### Workload Assessment

- Workloads should be evaluated for performance, compliance, and data size before migration.
- Large or isolated datasets may be prioritized to reduce risk.
- Critical applications need to be classified for migration order and validation.

### Network and Storage Mapping

- VLANs, subnets, routing, and storage replication should be configured to maintain smooth communication post-migration.
- Network paths may be tested for throughput, latency, and packet loss before cutover.
- Storage and replication settings need to be verified for consistency across hybrid environments.

### Cutover and Rollback Planning

- Phased migration should be used to validate each stage and reduce operational risk.
- Snapshots and rollback points can be created to enable quick recovery if issues arise.
- Staging environments need to simulate production workloads for testing failover and performance before full deployment.

## Cost Strategy and Enterprise

Evaluating costs is essential for enterprises managing hybrid workloads. The following practices help optimize spending while maintaining performance and flexibility:

### Pricing Models

- Bare metal servers should be evaluated for fixed monthly or annual commitments that suit steady workloads.
- Cloud platforms may use on-demand, reserved, or spot pricing, depending on workload variability.
- Each pricing model must align with the workload type and expected usage to prevent unnecessary expense.

### Total Cost of Ownership (TCO)

- Compute, storage, interconnect, egress, and licensing should be included in TCO calculations.
- Cost drivers such as licensing, data transfer, and reserved capacity may be identified early to avoid financial surprises.
- Budget planning needs to account for differences among providers and workload patterns to ensure accurate forecasting.

### Savings

- Reserved pricing, commitment discounts, rightsizing, and lifecycle automation should be applied to reduce costs.
- Idle virtual machines and unused storage may be audited regularly to prevent cloud sprawl.
- Cost management processes need to be continuously monitored to maintain and optimize spending.

## Implementing Hybrid Bare Metal with Atlantic.Net: A Practical Example

[Atlantic.Net](http://www.atlantic.net) provides bare-metal and cloud hosting for enterprises to build a hybrid infrastructure. Its dedicated servers run on enterprise-grade hardware, while cloud servers support API-driven provisioning, enabling automation, and use infrastructure-as-code tools. IT teams can deploy bare metal servers for performance-sensitive or compliance-critical workloads and use cloud servers for variable-demand workloads.

The platform is audited for frameworks such as HIPAA, PCI DSS, and SOC 2, and supports HIPAA BAA for ePHI workloads. Enterprises can configure TLS encryption, logging, and other controls to meet audit requirements. By planning workload placement, performance objectives, and costs, organizations can allocate Atlantic.Net resources to build hybrid architectures that maintain reliability, meet compliance requirements, and scale efficiently.

## The Bottom Line

Hybrid bare metal architectures give enterprises the performance, flexibility, and compliance they need to manage demanding workloads. Bare-metal servers offer consistent latency and full hardware control, while cloud platforms enable scalable, globally distributed operations.

In 2026, businesses face growing demands for compute and storage alongside stricter regulatory requirements. Hybrid bare metal models address these challenges by supporting high-performance applications, elastic cloud scaling, and modern container orchestration within a single framework, enabling enterprises to meet evolving workload demands while maintaining reliability, security, and compliance.


---

# Cloud Pricing Models in 2026: Savings Plans, Reserved Instances, and Cost Optimization Strategies

> URL: https://www.atlantic.net/cloud-platform/cloud-pricing-models-savings-plans-reserved-instances/ | Published: 2026-05-23 | Updated: 2026-05-22 | Author: Dr. Assad Abbas

Cloud pricing directly affects organizations that rely on compute and storage resources for their operations. Organizations run workloads of different sizes, store sensitive data, and must manage strict budget limits. Therefore, understanding basic pricing models is the first step before considering long-term commitments or cost management strategies.

On-Demand pricing is the simplest model in cloud computing. It follows a [pay-as-you-go](https://dealhub.io/glossary/pay-as-you-go-pricing/) model, in which organizations pay only for the resources they use. There is no upfront commitment or fixed contract. This model is suitable for workloads that are still developing or that need flexibility. In addition, organizations can test systems and estimate resource needs without incurring unnecessary costs.

[Billing granularity](https://docs.aws.amazon.com/cost-management/latest/userguide/ce-granular-data.html) also affects total cost. Some providers charge per second, while others charge per minute or per hour. Workloads that run for short periods or in bursts are more cost-effective when billed in smaller units. For example, a task that runs for less than a minute costs less under per-second billing than under per-minute billing. Therefore, knowing how billing is applied helps organizations calculate the real cost of temporary or experimental workloads.

On-Demand pricing works best for early-stage projects, unpredictable workloads, and short-term testing. These workloads usually do not follow stable patterns, so committing to long-term plans may not be practical. When workloads are consistently high, on-demand pricing can become expensive because applications operating over extended periods gradually incur higher costs. In such cases, organizations can switch to [Reserved Instances](https://aws.amazon.com/aws-cost-management/aws-cost-optimization/reserved-instances/) or Savings Plans, which still charge for resource usage but rely on structured commitments to make long-term costs more predictable. These models still charge for usage but help control long-term expenses with structured commitments.

The following sections describe these models in detail and show how they help organizations plan infrastructure efficiently while keeping budgets predictable.

## Understanding Reserved Instances and Their Role in Cost Planning

Reserved Instances are long-term pricing options offered by cloud providers for workloads that run consistently over extended periods. Instead of paying regular pay-as-you-go pricing continuously, organizations commit to a specific compute configuration for a fixed term, typically 1 to 3 years. In return, providers offer lower prices than standard pay-as-you-go rates. Therefore, Reserved Instances are commonly used when infrastructure requirements are predictable and unlikely to change frequently.

This pricing model is suitable for applications that require stable and uninterrupted operation. For example, relational databases, internal business systems, and long-running analytics platforms often operate year-round without major configuration changes. In such environments, Reserved Instances help organizations reduce recurring compute expenses while maintaining predictable monthly costs. Budgeting and long-term infrastructure planning become easier.

Reserved Instances provide less flexibility than on-demand pricing. They are typically associated with a specific instance family, region, and operating system. If workload requirements change significantly, organizations may not fully benefit from the original reservation. Therefore, workload forecasting becomes an important part of cost planning.

Reserved Instances are easier to manage when organizations have a clear understanding of baseline compute requirements. Workloads with predictable CPU and memory usage align more closely with reserved capacity. In contrast, rapidly fluctuating workloads may lead to underused reservations or require additional demand-priced resources. Organizations often review workload performance and usage trends regularly before committing to long-term Reserved Instances.

## Managing Costs with Flexible Savings Plans

Savings Plans provide organizations with a way to reduce cloud expenses over a longer term while maintaining some flexibility. Instead of committing to a fixed instance configuration, organizations commit to a consistent level of resource usage for 1 to 3 years in exchange for discounted rates. Compared with Reserved Instances, Savings Plans allow organizations to adjust instance sizes or switch between instance families while maintaining the discounted pricing. This feature is helpful when workloads are generally stable but may require occasional adjustments.

Savings Plans are suitable for workloads with predictable usage that may vary slightly over time. For example, applications that run consistently year-round but occasionally require more or fewer resources can benefit from this model. By committing to a predictable usage level, organizations can reduce costs while keeping the ability to respond to small changes in workload requirements.

This model supports more flexible long-term planning than Reserved Instances because it does not tie organizations to a single configuration. Organizations can align Savings Plans with their baseline workloads and use them alongside demand-priced resources for periods of variability. This approach allows organizations to balance cost with operational flexibility, making budgeting and infrastructure planning more manageable over multiple years.

## Comparing Pricing Models for Flexibility, Cost, and Suitability

Organizations should consider the differences between On-Demand Pricing, Reserved Instances, and Savings Plans to choose the model that fits their workloads and budgets. Each option has advantages depending on workload patterns, operational needs, and cost predictability.

On-Demand Pricing offers the highest flexibility because organizations pay only for the resources they use, without committing to a fixed term or configuration. This model is suitable for unpredictable, temporary, or development workloads. Costs can rise quickly if workloads run continuously, which makes budgeting less predictable.

Similarly, Reserved Instances reduce per-unit costs by committing to a fixed term and are intended for workloads that run steadily with predictable resource requirements. Their main limitation is lower flexibility compared with pay-as-you-go pricing, as changes in instance type, region, or operating system can reduce potential savings. Therefore, organizations using Reserved Instances need to plan and forecast usage carefully.

In contrast to Reserved Instances, Savings Plans provide an option for workloads that are mostly stable but may require occasional adjustments. By committing to a baseline level of resource usage, organizations receive discounted rates while retaining the ability to change instance sizes or switch families. This approach helps maintain predictable budgets while accommodating minor variations in workload demand, complementing pay-as-you-go pricing or Reserved Instances as needed.

The table below summarizes the main differences between these models.

Table 1: Comparison of Cloud Pricing Models

| **Pricing Model** | **Flexibility** | **Cost Predictability** | **Typical Use Cases** |
| --- | --- | --- | --- |
| On-Demand Pricing | High – no long-term commitment | Low cost varies with usage | Early-stage projects, variable workloads, short-term testing |
| Reserved Instances | Low – fixed configuration | Highly stable monthly cost | Continuous workloads, core applications, and databases |
| Savings Plans | Medium – adjustable instance sizes/families | Medium – predictable within committed usage | Mostly stable workloads with occasional changes |

## Evaluating Compute and Storage Costs Across Cloud Infrastructure

Cloud costs depend not only on the selected pricing model but also on the compute and storage resources required by workloads. Therefore, organizations evaluating On-Demand Pricing, Reserved Instances, or Savings Plans must also consider the infrastructure factors that affect long-term operational expenses. The following considerations commonly influence cloud spending.

### Compute Resources and Runtime Costs

Compute pricing is affected by CPU allocation, memory capacity, runtime duration, and network usage. As workloads run continuously or process larger datasets, resource consumption also increases, leading to higher operational costs over time. In addition, the type of infrastructure influences pricing. Dedicated single-tenant infrastructure generally costs more than shared multi-tenant environments, but it provides stable and predictable performance for business-critical workloads.

### Storage Performance and Retention Costs

Storage costs also vary by storage type, including block, object, and file storage. Performance requirements, such as IOPS, throughput, and replication, also influence monthly expenses. Workloads with frequent read/write operations or long-term backup requirements often require higher-performance storage, which gradually increases storage costs over time.

### Compliance and Infrastructure Requirements

Compliance requirements further influence infrastructure spending. Organizations handling [electronic Protected Health Information (ePHI)](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) often require dedicated infrastructure, controlled access policies, encrypted backups, and extended retention practices to maintain HIPAA-compliant operations. In contrast, shared multi-tenant environments may reduce upfront costs but can introduce performance variability for latency-sensitive or business-critical workloads. Therefore, infrastructure planning should consider both operational cost and long-term performance consistency.

## Optimizing Cloud Costs Through Infrastructure Planning and Governance

Reducing cloud expenses involves selecting appropriate pricing models, managing resource usage, planning storage strategy, evaluating infrastructure design, and maintaining governance practices. These decisions directly affect operational cost, performance stability, and compliance management over time. The following strategies can help optimize long-term cloud costs.

### Rightsizing Compute and Resource Allocation

Organizations should regularly monitor CPU, memory, and storage utilization to ensure infrastructure resources align with actual workload requirements. Over-provisioned instances increase unnecessary spending, while under-provisioned resources can reduce application performance and operational stability. Reviewing workload behavior and adjusting instance configurations over time helps improve both resource and cost control.

Organizations should also adopt a mixed pricing strategy based on workload patterns, as a single pricing model may not suit all workloads equally. For example, On-Demand Pricing can support temporary or unpredictable workloads, whereas Reserved Instances or Savings Plans can provide lower-cost baseline capacity for stable environments. Using these pricing models together helps reduce long-term infrastructure costs while maintaining flexibility to accommodate changing operational requirements.

### Storage Tiering and Retention Planning

Organizations should classify data by access frequency and performance requirements to reduce unnecessary storage costs. Frequently accessed workloads may require high-performance storage, while archival or infrequently accessed data can move to lower-cost storage tiers. This approach helps control long-term storage growth without affecting operational requirements. In addition, retention policies should be reviewed regularly because backup frequency, replication settings, and archival practices can gradually increase monthly storage costs.

### Selecting Infrastructure According to Workload Requirements

Infrastructure selection should align with workload behavior and operational priorities. Compute-intensive workloads may require dedicated high-performance instances, while storage-heavy applications often depend on scalable storage environments with consistent throughput. Similarly, high-availability workloads require reliable regions and redundancy planning.

Compliance-sensitive workloads also introduce additional requirements. For example, environments that handle ePHI often require HIPAA-compliant infrastructure, encrypted backups, controlled access policies, and HIPAA HIPAA Business Associate Agreement (BAA) (BAAs). Therefore, provider selection should consider compliance capabilities alongside pricing and operational performance.

### Governance and Contract Management

Long-term cloud cost control also depends on structured governance practices. FinOps teams, cloud architects, procurement specialists, and compliance officers often collaborate to review infrastructure planning, monitor resource consumption, and identify unnecessary expenses.

In addition, contract management directly affects long-term cloud expenditure. Commitment-based pricing, support tiers, and volume discounts should be reviewed according to workload scale and operational requirements. Regular reviews of infrastructure utilization and cloud spending also help organizations adjust commitments before unnecessary costs increase further.

## Atlantic.Net Commitment Pricing for Long-Term Workloads

Atlantic.Net offers multi-year billing options that help organizations plan and reduce cloud

costs for predictable workloads. In addition to standard pay-as-you-go pricing, the platform provides [one-year and three-year](https://www.atlantic.net/cloud-platform/) commitment terms for cloud infrastructure services. These options are intended for workloads that run continuously and require more predictable monthly expenses.

Longer commitment periods reduce monthly costs because resource usage becomes more predictable for the provider. One-year terms provide moderate discounts while preserving operational flexibility. Three-year commitments offer larger savings for organizations with stable workloads that can plan infrastructure requirements over an extended period.

For example, a cloud instance priced at $10 per month on demand may cost approximately $9 per month with a one-year commitment and around $8 per month with a three-year commitment. Across different workloads and configurations, Atlantic.Net states that multi-year commitments can reduce costs by up to 30 percent compared with standard on-demand billing.

These commitment options are particularly useful for predictable workloads such as databases, analytics platforms, long-running production systems, and compliance-sensitive applications. In addition, Atlantic.Net supports HIPAA-compliant infrastructure and offers a BAA for environments that handle ePHI. This enables organizations to combine long-term cost reductions with compliance-focused planning when managing cloud infrastructure budgets.

## The Bottom Line

Effective cloud cost management requires a strategic combination of pricing models, infrastructure planning, and governance. Organizations can use On-Demand Pricing for flexible or unpredictable workloads, while Reserved Instances or multi-year commitments help reduce expenses for stable environments with predictable resource requirements. Savings Plans are useful for workloads that remain mostly consistent but may require occasional resource adjustments over time.

Beyond pricing models, compute and storage decisions, compliance requirements, and provider capabilities, operational expenses are also influenced by other factors. Organizations should regularly monitor resource usage, optimize storage and instance allocation, and maintain structured governance practices to control long-term infrastructure costs. By aligning workload patterns, commitment strategies, and compliance requirements, organizations can maintain predictable spending while supporting stable, scalable, and business-critical cloud operations.


---

# Estimating Dedicated Server Provisioning Time in 2026: What Businesses Should Expect

> URL: https://www.atlantic.net/dedicated-server-hosting/dedicated-server-provisioning-time/ | Published: 2026-05-24 | Updated: 2026-06-23 | Author: Dr. Assad Abbas

[Dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) remain an important infrastructure option in 2026 for organizations operating databases, AI environments, financial applications, and production systems that require stable performance, resource isolation, and direct control over hardware resources.

Deploying a dedicated server involves selecting infrastructure and [provisioning](https://www.servers.com/kb/how-it-works/server-provisioning), as the provisioning process determines when the environment is ready for production use. Therefore, provisioning time directly affects project schedules, application launches, migration activities, and operational planning.

Provisioning time refers to the period between order confirmation and server readiness. Standard deployments are often completed quickly because they use predefined environments and ready inventory. In contrast, custom configurations and enterprise deployments usually require additional preparation and validation activities. Therefore, understanding provisioning timelines helps organizations plan deployments more effectively and set realistic expectations.

## How Does Dedicated Server Provisioning Work?

To prepare the server for production use, providers perform several provisioning activities before handover. These activities commonly include operating system installation, network configuration, testing, and environment validation. The meaning of “*ready*” may differ among providers. Some providers deliver the server after the operating system is installed. In contrast, others also include updates, baseline configuration, and validation procedures.

In most cases, provisioning includes:

- hardware preparation
- operating system deployment
- network configuration
- testing and validation
- credential delivery and handover

The scope of these activities may vary across deployment environments. Therefore, organizations should carefully review provisioning requirements, as they directly affect deployment timelines and planning.

## Typical Dedicated Server Provisioning Timelines

Provisioning timelines vary according to deployment requirements and infrastructure. Standard environments are usually deployed faster because they require limited preparation. In contrast, customized and enterprise environments often require additional configuration, validation, and coordination activities. Provisioning timelines and common deployment scenarios for dedicated servers are presented below.

### Standard Dedicated Server Deployments

Standard deployments are generally the fastest option because they use ready inventory and preconfigured operating system templates. Providers usually complete these deployments within 1 to 6 hours. These environments are commonly used for Web hosting, business applications, and production workloads where standard hardware configurations are sufficient.

### Semi-Custom Dedicated Environments

Semi-custom environments require moderate changes to standard server configurations. Organizations may request additional storage, memory upgrades, [RAID](https://www.atlantic.net/hipaa-data-centers/raid-10/) configurations, secondary network interfaces, or private networking options based on workload requirements.

These deployments usually require additional preparation beyond standard provisioning. Providers may need to configure storage layouts, update networking settings, and perform validation checks before deployment. Provisioning timelines typically range from 24 to 72 hours.

### Enterprise and Large-Scale Deployments

Enterprise deployments usually require additional planning and coordination because they often involve multiple servers and more complex infrastructure requirements. Organizations may implement private networking, clustering, dedicated storage environments, or staged deployment approaches.

Similarly, AI and high-performance workloads may require GPUs, high-memory systems, and specialized configurations. Therefore, these environments require additional preparation, validation, and activities. Provisioning timelines may range from several days to multiple weeks.

## Key Considerations Affecting Provisioning Timelines

Dedicated server provisioning timelines are affected by several technical and operational factors. The following factors affect provisioning timelines.

### Hardware Availability and Inventory Readiness

Hardware availability is one of the first factors affecting deployment speed. Providers with *ready*inventory usually provision servers faster because the hardware is already on-site.

Specialized systems such as [GPU servers](https://www.atlantic.net/gpu-server-hosting/gpu-servers-for-deep-learning-a-practical-guide/), high-memory nodes, [NVMe](https://www.atlantic.net/dedicated-server-hosting/nvme-ssds-dedicated-hosting-performance-latency/) storage arrays, and custom processors may increase lead times. Supply chain conditions in 2026 may also affect component availability. Therefore, organizations should confirm inventory availability before ordering.

### Custom Hardware Configuration and Validation

Custom hardware requirements often increase provisioning timelines because providers must perform additional setup and preparation activities before deployment. Organizations may request CPU upgrades, memory expansion, RAID configurations, storage customization, or dedicated backup disks based on workload requirements.

These changes usually require configuration updates and validation procedures. Some environments may also require firmware updates and storage configuration adjustments before deployment.

After preparation, providers commonly perform validation and burn-in testing to verify hardware stability and operational readiness. Customized environments often take longer than standard deployments.

### Operating System Selection and Deployment Methods

Operating system selection can also affect provisioning timelines because deployment requirements vary across environments. The level of preparation often depends on whether organizations use standard operating system templates or custom installations.

Standard operating system templates are usually deployed more quickly because providers commonly maintain ready-made images for distributions such as Ubuntu, Debian, AlmaLinux, and Windows Server. These templates already include baseline settings and therefore require limited preparation.

In contrast, custom ISO installations often require additional activities such as manual image mounting, compatibility checks, and validation procedures. Custom deployments usually take longer than standard operating system templates.

### Network Preparation and Infrastructure Configuration

Network preparation is another activity that affects provisioning timelines. Providers commonly configure IP assignment, routing settings, and connectivity requirements before deployment completion.

Additional preparation may be required for private networking environments. Organizations may implement VLAN configurations, isolated network segments, or internal routing policies based on infrastructure requirements. These activities increase deployment effort and preparation time.

Organizations planning immediate production deployment should also confirm networking and [DNS](https://www.atlantic.net/vps-hosting/what-is-dns-and-how-does-it-work/) requirements early to avoid deployment delays.

### Verification and Order Approval Procedures

Verification and order approval procedures can also affect provisioning timelines, as infrastructure preparation typically begins after approval.

Before deployment starts, providers commonly perform identity verification, payment confirmation, and fraud screening to validate customer information and transaction details. In some cases, enterprise environments and first-time customers may require additional approval procedures or supporting documentation.

Therefore, submitting accurate information and completing verification requirements early can help reduce delays and support faster provisioning.

The factors discussed above affect provisioning timelines differently depending on infrastructure requirements and deployment scope. Table 1 summarizes their impact on dedicated server provisioning.

Table 1: Factors Affecting Dedicated Server Provisioning Time

| **Factor** | **Typical Impact on Provisioning** | **Example Considerations** |
| --- | --- | --- |
| Hardware availability | Affects deployment speed | Ready inventory, GPUs, high memory systems |
| Hardware customization | Increases preparation time | RAID setup, storage layouts, CPU upgrades |
| Operating system selection | Changes the deployment effort | Linux templates, Windows Server, custom ISO |
| Network configuration | Adds setup activities | VLANs, private networking, and DNS |
| Verification procedures | May delay deployment start | Identity checks, payment approval |

## How Hosting Providers Affect Provisioning Timelines

Provider capabilities directly affect deployment timelines because infrastructure preparation and operational workflows vary across hosting environments.

One important difference is the deployment model used by providers. Some providers maintain ready inventory in their facilities, with servers already assembled and ready for deployment. Provisioning is usually faster because hardware preparation is completed in advance. In contrast, providers using build-to-order workflows begin hardware preparation after order confirmation, which often increases deployment time.

Provider operations also affect provisioning speed. Activities such as rack placement, power connection, cable installation, and network influence deployment readiness. Similarly, technician availability, rack capacity, and operational workload can affect scheduling, particularly in large deployments.

The hosting model selected by organizations can also influence deployment timelines, as deployment responsibilities differ across environments. In [managed hosting](https://www.atlantic.net/dedicated-server-hosting/what-is-managed-hosting/) environments, providers commonly assist with activities such as operating system installation, patching, monitoring preparation, and baseline configuration. Therefore, customers usually require less preparation after handover. In contrast, unmanaged environments require customers to perform deployment and configuration activities independently before production use.

Provisioning timelines may also vary according to provider capabilities and deployment services. Providers that maintain ready inventory, have established data center operations, and offer deployment support services often complete standard environments more efficiently. For example, [Atlantic.Net](http://www.atlantic.net) offers dedicated hosting services with managed deployment options and infrastructure management capabilities. Actual provisioning timelines still depend on deployment requirements, customization level, and infrastructure scope.

Communication practices should also be reviewed during planning. Organizations should confirm provisioning commitments, deployment definitions, order tracking availability, and escalation procedures before ordering infrastructure. Clear communication helps reduce uncertainty and supports more accurate deployment planning.

The provider characteristics discussed above affect provisioning timelines differently depending on deployment requirements and operational workflows. Table 2 below summarizes their impact on dedicated server provisioning.

Table 2: Provider Characteristics and Their Impact on Provisioning Timelines

| **Provider Characteristic** | **Typical Provisioning Impact** | **Example Considerations** |
| --- | --- | --- |
| Ready inventory model | Faster deployment | Preassembled servers and standard configurations |
| Build-to-order model | Longer preparation time | Hardware assembly after order confirmation |
| Data center operations | Affects deployment readiness | Technician availability, rack capacity, operational workload |
| Managed hosting | Reduces customer preparation effort | OS installation, monitoring setup, and configuration support |
| Communication and SLAs | Improves deployment planning | Timeline commitments, order tracking, escalation procedures |

## Dedicated Server Provisioning Workflow

Dedicated server provisioning usually follows a clear sequence of steps after order approval. The process begins with payment confirmation and includes validation checks, as provisioning does not start until the order is fully approved.

After approval, the server is prepared inside the data center. The hardware is mounted in the rack and connected to power and network systems. Diagnostic checks and hardware testing are then conducted to confirm that the server is operating properly and is ready for deployment.

Once the hardware is verified, the selected operating system image is installed. Initial setup activities are also completed, including system settings and access preparation. In addition, network configuration is performed, including IP assignment, routing configuration, connectivity checks, and DNS setup when required.

Before handover, final validation checks confirm hardware status, network availability, and system readiness. The customer then receives deployment credentials and related documentation, which marks the completion of the provisioning process.

## Reducing Dedicated Server Provisioning Delays

Organizations can reduce provisioning delays through better preparation and clearer deployment planning before ordering infrastructure. In many cases, delays occur because deployment requirements change during provisioning or because additional verification and configuration activities are needed after deployment begins.

One practical approach is to select ready inventory configurations and standard operating system templates whenever rapid deployment is important. These environments usually require less preparation because hardware assembly and baseline configuration have already been completed. In contrast, custom installations and specialized configurations often increase deployment effort and preparation time.

Early planning is also important for reducing delays. Organizations should define hardware, networking, storage, and software requirements before deployment begins, as changes during provisioning may require reconfiguration and extend timelines. Similarly, completing verification procedures and submitting required information early can help avoid approval-related delays.

Communication also supports smoother deployment planning. Organizations should request provisioning updates, deployment milestones, and escalation contacts during provisioning to improve coordination and visibility into deployments.

## Frequently Asked Questions

#### *How long does dedicated server provisioning usually take?*

Provisioning time depends on deployment requirements and infrastructure. Standard environments using ready inventory and predefined configurations may be completed within hours. In contrast, customized and enterprise deployments may require several days or weeks.

#### *What factors affect dedicated server provisioning time?*

Several technical and operational factors affect provisioning timelines. Common examples include hardware availability, customization requirements, operating system selection, networking configuration, provider capabilities, and verification procedures.

#### *Do custom hardware configurations increase provisioning time?*

Yes. Custom environments often require additional preparation activities before deployment. Examples include CPU upgrades, memory expansion, RAID configuration, storage customization, firmware updates, and validation procedures. Provisioning timelines are usually longer than for standard deployments.

#### *How can organizations reduce the time required to provision dedicated servers?*

Organizations can reduce delays by planning and preparing early. Confirming hardware requirements, completing verification procedures, selecting ready inventory configurations, and using standard operating system templates may help shorten deployment timelines.

#### *Does the hosting provider affect provisioning speed?*

Yes. Provider capabilities can influence provisioning timelines. Ready inventory models, operational capacity, [managed deployment services](https://www.atlantic.net/managed-services/), and communication practices may affect deployment readiness and provisioning speed.

## The Bottom Line

Estimating [dedicated server](https://www.atlantic.net/dedicated-server-hosting/what-is-dedicated-server-hosting/) provisioning time in 2026 requires careful planning rather than assigning a fixed deployment window. Provisioning timelines vary because each environment has different infrastructure requirements, operational procedures, and deployment objectives. Therefore, organizations planning migrations, application launches, or infrastructure expansion should avoid assuming that all dedicated server deployments follow the same schedule.

Several factors influence provisioning timelines, including hardware availability, customization requirements, provider capabilities, and deployment scope. The time required for server delivery may vary across standard, customized, and enterprise environments.

For this reason, organizations should define infrastructure requirements early, confirm deployment expectations with providers, and include reasonable deployment buffers during planning. This approach helps reduce uncertainty and supports a smoother transition of dedicated servers into production environments.


---

# Hosting Agreements in 2026: Essential Clauses and Compliance Requirements

> URL: https://www.atlantic.net/dedicated-server-hosting/hosting-agreements-clauses-compliance/ | Published: 2026-05-25 | Updated: 2026-05-22 | Author: Dr. Assad Abbas

A hosting agreement is a contract between a hosting provider and a client. It defines the services to be delivered, each party’s responsibilities, and the rules governing security, payment, and termination. For organizations that host critical applications, sensitive business data, or [electronic Protected Health Information (ePHI)](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/), this agreement is an important operational document. It establishes accountability and helps both parties clearly understand their obligations.

In 2026, businesses commonly use [cloud hosting](https://www.ibm.com/think/topics/cloud-hosting), [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/), and multi-cloud infrastructure. The contractual requirements for hosting services still require careful review. Therefore, a hosting agreement should clearly and in a structured manner describe service levels, encryption requirements, breach notification procedures, backup responsibilities, and data return processes. Without these clauses, both the provider and the client may face uncertainty during outages, disputes, or security incidents.

This article explains the essential clauses commonly included in hosting agreements. It focuses on security obligations, compliance requirements, and practical considerations involved in reviewing hosting contracts. The discussion is intended to help technical teams, legal departments, and procurement professionals evaluate hosting agreements more effectively.

## Why Hosting Agreements Matter in 2026

Modern infrastructure environments are more complex than before. Many organizations now run workloads across cloud, dedicated, hybrid, and multi-cloud systems simultaneously. Some keep regulated workloads on single-tenant infrastructure while using public cloud platforms for scalability. Others combine managed hosting with distributed deployments across multiple regions. As a result, operational responsibility is often shared among internal teams, hosting providers, and third-party partners.

This makes clear service obligations more important. Organizations need defined terms for uptime, maintenance, backups, incident response, and access control. Without these terms, even a small outage or security issue can create confusion and delay response actions.

Several factors have made hosting agreements more important in 2026:

- distributed cloud and multi-cloud deployments.
- stricter compliance and audit requirements.
- large dependence on continuous application availability.
- more coordination between providers and internal teams.
- Higher expectations for backup and disaster recovery planning.

Currently, the majority of businesses depend on digital services that must remain available. Even short downtime can affect revenue, customer trust, and daily operations. Therefore, many organizations now treat hosting agreements as part of broader operational risk management rather than viewing them only as procurement documents.

Compliance obligations have also become more detailed across many industries. For example, healthcare organizations, financial institutions, SaaS providers, and legal firms often face strict security and privacy requirements. In that context, hosting agreements now commonly include provisions for logging, retention, audit support, encryption standards, and access management.

Business continuity is another major factor. Organizations want clear expectations for disaster recovery, service restoration timelines, and backup availability before they deploy production workloads. Well-written agreements reduce uncertainty and support more stable infrastructure operations.

## Defining the Parties and Service Scope

Every hosting agreement should clearly identify the legal entities involved in the contract. This section of the agreement generally includes the full legal names of the hosting provider and the customer organization. It should also specify authorized contacts for technical communication, billing matters, and security incidents. Clear contact information helps reduce delays when operational problems occur.

This section of the agreement should also define the infrastructure and operational services covered under the contract. Hosting services may include:

- cloud infrastructure
- virtual servers
- dedicated servers
- storage resources
- backup systems
- managed monitoring
- disaster recovery support
- network connectivity

Many organizations use single-tenant infrastructure for workloads that require stronger isolation or compliance support. Therefore, the agreement should specify whether the hosting environment is shared or dedicated. Businesses should also carefully review scalability provisions to understand how additional storage, compute resources, or bandwidth will be provisioned as operational demands increase.

Onboarding procedures are equally important and should be documented clearly. These procedures may include deployment timelines, DNS configuration, firewall setup, access provisioning, and infrastructure testing. Clear onboarding steps help reduce confusion during deployment and support smoother operational transitions.

## Service Level Agreements (SLAs) and Uptime Expectations

[Service Level Agreements (SLAs)](https://www.ibm.com/think/topics/service-level-agreement) define measurable service expectations between the provider and the customer. In hosting agreements, these sections are among the most important because they set clear performance standards.

Most hosting providers specify uptime guarantees as percentages, such as 99.9% availability. The uptime figure alone does not provide the complete picture. Organizations should also review the method used to measure uptime and the events excluded from the calculation. Scheduled maintenance windows, for example, are commonly excluded. Therefore, the agreement should clearly define maintenance schedules, advance notice requirements, and emergency maintenance procedures.

The SLA should also define procedures for operational incidents. This commonly includes:

- incident severity levels
- response timelines
- escalation procedures
- communication expectations
- resolution targets

These terms become particularly important when businesses operate customer-facing or business-critical applications. Even short periods of downtime may affect users, internal operations, or revenue generation.

In addition, the agreement should explain the remedies available if the provider fails to meet the defined service levels. Some hosting providers offer service credits or partial refunds after extended outages. Liability limitations may also apply under the agreement. Therefore, organizations should review SLA terms carefully rather than relying solely on the advertised uptime percentage.

## Security Obligations in Modern Hosting Agreements

Security obligations are a major part of modern hosting agreements. Organizations expect hosting providers to maintain secure infrastructure environments and follow documented operational procedures. This has become more important as businesses increasingly host sensitive applications and regulated workloads in cloud and dedicated hosting environments. As a result, hosting agreements now include more detailed technical safeguards and operational requirements. Many contracts require data encrypted in transit using TLS to protect communication between systems, applications, and users.

Hosting agreements should also clearly define backup and disaster recovery responsibilities. These provisions commonly include:

- backup frequency
- retention schedules
- restoration procedures
- testing responsibilities

Organizations should also review [Recovery Point Objectives (RPOs)](https://www.f5.com/glossary/recovery-point-objective-rpo) and [Recovery Time Objectives (RTOs)](https://www.druva.com/learning-center/glossary/what-is-recovery-time-objective-definitions-and-related-faqs). These metrics define acceptable recovery expectations after outages, cyber incidents, or operational failures.

Access control requirements are equally important in modern hosting environments. Many providers implement role-based access control, multi-factor authentication, and administrative activity logging to reduce the risk of unauthorized access.

Security incident reporting procedures should also be clearly documented in the agreement. Security incident reporting procedures should also be clearly documented in the agreement. This section of the agreement typically defines breach-notification timelines, communication responsibilities, and remediation expectations. These obligations become more important in regulated industries where legal reporting requirements may apply.

## Compliance Requirements for Regulated Environments

Compliance requirements influence many hosting decisions. Organizations operating in healthcare, finance, legal services, and SaaS environments often handle sensitive information that must be carefully protected. As a result, hosting agreements now include more detailed compliance and data protection provisions.

Healthcare organizations, for example, must protect ePHI. Therefore, many businesses select HIPAA-compliant hosting environments for healthcare applications and patient systems. In such cases, providers may also sign a [HIPAA Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) that defines their responsibilities for handling and protecting regulated healthcare information.

Financial and payment processing environments may also require PCI-compliant infrastructure controls. These controls commonly include:

- network segmentation
- authentication monitoring
- centralized logging
- infrastructure access restrictions

Hosting agreements should also clearly define confidentiality obligations. Providers may require limited administrative access during maintenance or troubleshooting activities. Therefore, agreements should specify how sensitive information will be protected and which personnel may access customer systems.

Data retention and deletion requirements are equally important. Organizations should understand:

- backup retention timelines
- data deletion procedures
- post-termination data handling policies

Some industries may also require audit support during compliance assessments. Therefore, hosting agreements should specify the operational records, logging information, or infrastructure documentation that are available upon request.

## Intellectual Property and Data Ownership

Hosting agreements should clearly define ownership rights related to hosted applications, databases, customer content, and infrastructure tools. Clear ownership terms help reduce disputes and improve operational transparency throughout the hosting relationship.

In most cases, the customer retains ownership of hosted data, applications, and business content. The provider may retain ownership of infrastructure management systems, automation software, monitoring platforms, and other proprietary tools used during service delivery.

The agreement should also define whether the provider may access customer systems for maintenance, troubleshooting, or security purposes. The agreement should also define whether the provider may access customer systems for maintenance, troubleshooting, or security purposes. Administrative access procedures and authorization requirements should be documented clearly and consistently to maintain operational accountability.

## Payment Terms and Financial Responsibilities

Payment terms define the financial responsibilities between the hosting provider and the customer organization. Clear billing terms help reduce disputes and improve transparency throughout the hosting relationship.

This section of the agreement commonly includes:

- billing schedules
- payment deadlines
- monthly or annual pricing
- resource overage charges
- invoice procedures

Cloud hosting environments may also incur additional costs for bandwidth consumption, storage growth, or backup retention. Therefore, the agreement should clearly define the calculation method for variable usage charges.

Late payment policies should also be reviewed carefully. Some providers may suspend services after missed payments or unresolved billing disputes. Organizations should understand the operational impact of delayed payments before signing the agreement.

Tax responsibilities are equally important, particularly in international hosting arrangements where regional tax obligations may differ between jurisdictions.

## Termination Procedures and Service Handover

Termination clauses define the conditions under which the hosting agreement may end and the procedures that apply afterward. Clear termination terms help reduce operational disruption and support smoother infrastructure transitions.

Most hosting agreements include notice periods, renewal conditions, termination-for-breach provisions, and service-cancellation requirements. Organizations should review termination timelines carefully because infrastructure migrations often require planning, coordination, and data transfer preparation.

The agreement should also define:

- data export procedures
- account deactivation steps
- credential revocation
- backup retention timelines
- infrastructure access removal

A structured handover process supports safer workload migration and helps reduce operational disruption during provider transitions.

## Co-Hosting and Third-Party Responsibilities

Some hosting environments involve multiple providers. For example, a managed service provider may support systems hosted on infrastructure owned by another cloud provider. In these situations, the hosting agreement should clearly define each party’s responsibilities.

The agreement should also clearly document access permissions and operational authority. Third-party access without proper controls may create security and compliance risks. Therefore, organizations should understand which providers may access customer systems and the conditions under which such access is permitted.

Responsibility allocation is equally important during outages, infrastructure failures, or security incidents involving multiple providers. Clear contractual terms help improve coordination and reduce confusion when operational issues arise. In addition, well-defined responsibilities support stronger accountability across complex hosting environments.

## Evaluating Hosting Providers Through Contractual and Compliance Requirements

Organizations should evaluate hosting providers not only on infrastructure capabilities, but also on the quality and clarity of their hosting agreements. Well-structured agreements help businesses understand operational responsibilities, compliance obligations, and service expectations before workloads are deployed into production environments.

Hosting providers should clearly document:

- uptime commitments
- backup and disaster recovery procedures
- incident response processes
- security responsibilities
- compliance support capabilities

Organizations operating regulated workloads should also verify whether the provider supports HIPAA-compliant hosting, PCI-compliant infrastructure, and TLS-secured communication. Similarly, agreements should clearly define breach notification procedures, data retention policies, and administrative access controls.

Disaster recovery expectations and operational visibility should also be reviewed carefully before signing a hosting agreement. Disaster recovery expectations and operational visibility should also be reviewed carefully before signing a hosting agreement. Clear contractual language helps organizations reduce uncertainty and maintain stronger accountability during outages, security incidents, or infrastructure transitions.

Providers such as Atlantic.Net offer managed cloud, dedicated, and compliant hosting services with documented SLAs and operational procedures that support organizations operating regulated or business-critical workloads.

## The Bottom Line

Hosting agreements have become an important operational and compliance document in 2026. They cover much more than server access or infrastructure pricing. Modern agreements define uptime expectations, security responsibilities, compliance obligations, disaster recovery procedures, and operational accountability between the provider and the customer.

A well-structured hosting agreement helps organizations reduce uncertainty and establish clear expectations regarding infrastructure management and service delivery. It also supports better preparation for outages, compliance reviews, security incidents, and infrastructure transitions.


---

# Atlantic.Net CEO: Ten Tech Predictions That Will Shape AI, Cybersecurity, and Infrastructure in 2026

> URL: https://www.atlantic.net/press-releases/atlantic-net-ceo-ten-tech-predictions-that-will-shape-ai-cybersecurity-and-infrastructure-in-2026/ | Published: 2026-05-25 | Updated: 2026-06-04 | Author: Editorial Team

ORLANDO (Jan. 13, 2026) Marty Puranik, founder and CEO of [Atlantic.Net](https://edge.prnewswire.com/c/link/?t=0&l=en&o=4594606-1&h=1936715099&u=https%3A%2F%2Fwww.atlantic.net%2Fgpu-server-hosting%2Fhipaa-gpu-hosting%2F&a=Atlantic.Net), a global cloud infrastructure provider specializing in security and compliance, shares his top ten predictions for 2026, with an eye toward AI, cybersecurity, and the evolving infrastructure landscape. These predictions offer insight for tech leaders balancing enormous innovation with growing pressure for security, resiliency, and adaptability.

1. **Physical Data Centers Become National Security Assets**

[Data centers](https://edge.prnewswire.com/c/link/?t=0&l=en&o=4594606-1&h=1529602435&u=https%3A%2F%2Fwww.atlantic.net%2Fhipaa-data-centers%2F&a=Data+centers) are now more critical than ever, says Puranik. “AI-driven data centers could become targets because of negativity around AI—especially if people perceive AI as replacing jobs.” Modern facilities deploy multi-layer defenses, but Puranik warns that data centers hosting AI workloads must be treated similarly to power plants or telco hubs. In the past, we saw cyberattacks target U.S. water utilities, and as AI grows, security protocols will escalate. “AI workloads introduce higher stakes,” he notes, and successful attacks could mean widespread economic disruption, driving new standards and separating ‘AI-critical’ from ‘general-purpose’ sites.

1. **Splitting Cloud Workloads**

Puranik predicts organizations will intentionally segment traditional, lower-risk workloads away from high-value AI operations. “A significant attack on an AI hub could ‘be a pretty big deal, similar to the shift we saw after 9/11,” he says. Mission-critical operations will require new redundancy measures, influencing global compliance and data sovereignty strategies.

1. **The Rise of ‘Agentic AI Networks’**

2026 will see [agentic AI](https://edge.prnewswire.com/c/link/?t=0&l=en&o=4594606-1&h=4048272065&u=https%3A%2F%2Fwww.atlantic.net%2Fgpu-server-hosting%2Fai-vs-agentic-ai%2F&a=agentic+AI)—networks of AIs collaborating and reasoning—expand rapidly. “It’s a change in traffic patterns, throughput requirements, and what’s considered valuable,” explains Puranik. Today’s cloud is built for low-latency, but agentic AI demands throughput, not latency. “Imagine an AI in an ambulance coordinating with an emergency room’s AI,” he says, highlighting the need for secure, privacy-centric data enclaves designed ‘compliant-by-design.’

1. **GPU Market Fragmentation**

The global AI boom has spotlighted a critical bottleneck: [GPUs](https://edge.prnewswire.com/c/link/?t=0&l=en&o=4594606-1&h=2468937119&u=https%3A%2F%2Fwww.atlantic.net%2Fgpu-server-hosting%2Fgpu-dedicated-hosting%2F&a=GPUs). Today, there is a heavy reliance on a single chip maker. This has made them one of the most valuable companies in the world, but this demand is unsustainable.

“OpenAI’s insatiable demand for chips is a prime example,” Marty says. “AMD chips are very capable, especially at inference, but they lack another company’s traction and validation.” He predicts a major diversification in chosen hardware platforms by 2026. “AMD gets in the game in a big way, while OpenAI retains optionality by not being singularly reliant on another company.”

1. **Rethinking Cybersecurity ‘From First Principles’**

Puranik criticizes the industry’s habit of ‘fighting the last war.’ “Start with the basics—define what you’re trying to protect and why.” He urges regular reviews, measurable metrics, robust backup checks, and third-party audits: “[Cybersecurity](https://edge.prnewswire.com/c/link/?t=0&l=en&o=4594606-1&h=3401218795&u=https%3A%2F%2Fwww.atlantic.net%2Fcompliance-hosting%2F&a=Cybersecurity) is a moving target—threat actors are always adapting.” Proactive, adaptable security frameworks are essential as threats evolve faster each year.

1. **AI Inequality Drives a Social Divide**

An ‘AI-driven intelligence divide’ could fuel inequality, predicts Puranik. “If the best models are reserved for the most affluent, we’ll see a new form of stratification.” Bridging this gap will be a policy focus, echoing net neutrality debates. Vendors enabling open, affordable AI access will lead the charge as regulators and the public push for ethical data policies and broad inclusivity.

1. **Healthcare AI Must Be ‘Compliant-by-Design’**

Healthcare AI must prove itself not just in smart models but in [strict compliance](https://edge.prnewswire.com/c/link/?t=0&l=en&o=4594606-1&h=1496640760&u=https%3A%2F%2Fwww.atlantic.net%2Fhipaa-compliant-hosting%2Fwhat-is-hipaa-cloud%2F&a=strict+compliance). “The real challenge isn’t the model itself—it’s ensuring the entire data pipeline is compliant,” Puranik stresses. With HIPAA and global privacy laws, institutions must architect cloud and AI infrastructure to embed privacy and security from the start, enabling new AI-driven diagnostics and patient care without risking sensitive data.

1. **AI-Driven Misinformation Becomes a Top Threat**

AI’s power to fabricate and spread disinformation will intensify, warns Puranik. “AI can generate and disseminate all kinds of disinformation, especially on social media—and if it’s effective, it could destabilize society.” Expect 2026 to bring government policies and new safeguards such as digital watermarking and provenance standards like C2PA, as the tech world works to maintain public trust.

1. **AI Models Will Specialize**

Massive, general-purpose models won’t solve every challenge. “It’s not about one model doing everything—it’s about the right models doing their part efficiently,” says Puranik. He points to trends like DeepSeek, which break problems into specialties, expecting modular frameworks to become standard for large-scale deployments.

    10**.The Talent War: From Knowledge to Adaptability**

[AI-driven automation](https://edge.prnewswire.com/c/link/?t=0&l=en&o=4594606-1&h=156910183&u=https%3A%2F%2Fwww.atlantic.net%2Fabout-us%2Fwhitepapers%2Frapid-diagnostics-precise-insights%2F&a=AI-driven+automation) is shifting hiring priorities. “By 2026, the real talent war won’t be for the person with the longest list of certifications—it will be for the ‘passionate doer’ who thrives in chaos,” Puranik explains. Adaptability, curiosity, and courage to adopt new tools or sunset legacy systems will matter most, as the pace and uncertainty of technology surpass static credentials.

**About Atlantic.Net**
 Founded in 1994, [Atlantic.Net](https://edge.prnewswire.com/c/link/?t=0&l=en&o=4594606-1&h=3829917881&u=http%3A%2F%2Fatlantic.net%2F&a=Atlantic.Net) is a privately held global cloud infrastructure provider with customers in over 100 countries, known for delivering secure, compliant, on-demand and customizable hosting solutions. With decades of experience, Atlantic.Net is one of the world’s most trusted and experienced hosting providers, offering 24/7 U.S.-based support. Specializing in security, compliance, and customer service, Atlantic.Net serves a diverse range of industries with solutions including HIPAA-compliant hosting and PCI-compliant hosting, backed by bare metal servers, dedicated hosting, GPU hosting, colocation, and its award-winning Cloud Platform. Operating from eight strategically located data center regions across the United States, Canada, the United Kingdom, and Asia, Atlantic.Net powers mission-critical workloads for organizations worldwide. For more information, visit [Atlantic.Net](https://edge.prnewswire.com/c/link/?t=0&l=en&o=4594606-1&h=522078021&u=https%3A%2F%2Fwww.atlantic.net%2F&a=Atlantic.Net) or connect with us on[ Facebook](https://edge.prnewswire.com/c/link/?t=0&l=en&o=4594606-1&h=733693447&u=https%3A%2F%2Fwww.facebook.com%2FAtlantic.Net&a=%C2%A0Facebook),[ X (Twitter)](https://edge.prnewswire.com/c/link/?t=0&l=en&o=4594606-1&h=3504827918&u=https%3A%2F%2Ftwitter.com%2FAtlanticNet&a=%C2%A0X+(Twitter)),[ LinkedIn](https://edge.prnewswire.com/c/link/?t=0&l=en&o=4594606-1&h=1080627862&u=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fatlantic.net-inc.%2Fposts%2F%3FfeedView%3Dall&a=%C2%A0LinkedIn), and[ YouTube](https://edge.prnewswire.com/c/link/?t=0&l=en&o=4594606-1&h=2809624830&u=https%3A%2F%2Fwww.youtube.com%2Fc%2FAtlanticNet&a=%C2%A0YouTube).

 


---

# Understanding Bare Metal Server Provisioning Time

> URL: https://www.atlantic.net/dedicated-server-hosting/understanding-bare-metal-server-provisioning-time/ | Published: 2026-05-26 | Updated: 2026-06-23 | Author: Dr. Assad Abbas

This guide is for IT leaders, infrastructure architects, DevOps engineers, and anyone involved in making decisions about computing infrastructure. It addresses a practical question that team leaders frequently ask when comparing bare metal to virtual cloud servers: “How long does it take to receive a physical server ready for production?”

Whether you are capacity planning for a database cluster, working on deploying an AI training platform, or trying to determine if a highly regulated workload justifies dedicated hardware, there will come a time when you need to understand how long it will take to receive that server. This will impact not just your timelines but your project costs and potentially some architectural decisions. This post will walk through what happens during bare-metal provisioning, why the process takes longer than provisioning a virtual server, which factors can speed it up or slow it down, and how automation is changing the game these days.

## Overview of Bare Metal Provisioning

Bare metal refers to a physical server rather than a virtual machine, with the operating system running directly on the hardware. These servers provide dedicated resources, giving full access to the machine’s CPU, memory, storage, and networking. Unlike virtual servers, there is no hypervisor layer sitting between the operating system and the physical hardware.

Bare metal provisioning is the process of turning a physical server into a workload-ready machine. The process begins with a powered-off computer in a data center rack. It ends with an operating system installed, along with network connectivity and other configurations, to enable the server to run applications.

Bare metal provisioning requires physical interaction with real hardware, including racking, cabling, firmware validation, and disk imaging, before any software layer can be installed. This hands-on setup process takes longer than deploying a virtual server. Virtual servers can usually be deployed within minutes because they use a preconfigured pool of compute, storage, and networking resources. Despite taking longer to set up, [bare metal servers](https://www.atlantic.net/dedicated-server-hosting/what-is-a-bare-metal-server-benefits-use-cases-and-best-practices/) provide dedicated resources, predictable latency, and complete control over the operating system that virtualized environments cannot match.

## What Bare Metal Provisioning Involves

Provisioning a bare-metal server involves a sequence of physical and logical steps, each with its own time requirement.

Physical Hardware Discovery: The process begins with identifying available hardware in inventory. Data center technicians locate the server chassis, check serial numbers, and confirm that the machine matches the order specification. If the server is not already racked, that step comes first and can add hours or days, depending on the data center’s workflow.

Firmware and BIOS Validation: Before installing the operating system on the server disk, the server’s firmware and BIOS must be thoroughly verified. Technicians usually begin by checking the installed [BIOS or UEFI version](https://www.techtarget.com/searchenterprisedesktop/tip/How-IT-admins-can-check-BIOS-or-UEFI-versions-in-Windows-11) to confirm it matches the deployment requirements. They also review boot priority settings and test whether remote management interfaces such as [iDRAC or iLO](https://servermall.com/blog/idrac-vs-ilo-vs-ipmi-remote-management/?srsltid=AfmBOoquC_07pzQNf3G1sOOp-wFNcAwOEtSvdMGJDoB356cM9wV5VKML) can be accessed without issues. These verifications are as outdated firmware releases can lead to compatibility issues, unforeseen crashes, or security concerns later in production.

Operating System Installation: Once the hardware passes validation, the operating system deployment can begin. The operating system can be installed manually using installation media, via [PXE boot](https://www.techtarget.com/searchnetworking/definition/Preboot-Execution-Environment) over the network, or with automated OS imaging tools.

Private Network Setup: In many production settings, servers also require a specialized private network for internal communication. Engineers set up [private VLANs](https://www.geeksforgeeks.org/computer-networks/private-vlan/), allocate internal IP address ranges, and implement [VLAN tagging](https://deepstrike.io/blog/what-is-vlan-tagging) on the correct switch ports. Routing between internal systems is then verified to make sure application traffic flows correctly. This part of the process usually involves coordination between the networking and infrastructure teams.

Public Network Configuration: If the server needs to handle external traffic, additional networking steps are also required. [Public IP addresses](https://www.atlantic.net/vps-hosting/atlantic-net-cloud-how-to-add-an-additional-public-ip-to-your-atlantic-net-cloud-server/) are assigned, gateway information is configured, and firewall policies are applied based on security requirements. Network administrators also verify VLAN membership and configure any required access control rules before the server is exposed to external connections.

## Why Bare Metal Servers Often Take Longer Than Virtual Servers

The main reason is straightforward: bare-metal deals with physical objects; hardware virtual servers operate on software.

Virtual server provisioning is largely a software task. The physical host is already powered on, cabled, and running a [hypervisor](https://www.atlantic.net/dedicated-server-hosting/bare-metal-hypervisors-vs-hosted-solutions/). Creating a new VM requires allocating virtual CPU, memory, and storage from a shared resource pool, then booting from a prebuilt template. This entire process can be completed in under a minute.

Bare metal provisioning requires hands-on hardware tasks. A physical machine must be located, possibly racked, connected to power and network infrastructure, and powered on for the first time. Each physical task introduces delays that software cannot overcome.

Racking and cabling can significantly increase the time required for provisioning. If the server is already mounted in a rack and connected to the top-of-rack switch, deployment can move faster. When the hardware still needs to be unpacked, installed in the rack, and fully cabled, the physical setup alone can take several hours.

[Firmware testing](https://www.wetest.net/blog/difference-between-software-testing-and-fireware-testing-247.html) and [hardware burn-in](https://neweraelectronics.com/blog_posts/everything-you-need-to-know-about-burn-in-computer-testing/) add more time. Many organizations run diagnostic tools on new hardware to catch early failures before production workloads start. Burn-in testing can take a few hours to several days, depending on organizational policy and the criticality of the workload. These steps are because hardware failures during production can be very costly compared to pre-deployment validation.

## Timeline Factors: Physical Hardware, Provisioning Process, and Cloud Service

In essence, several factors combine to determine the total provisioning time:

Data center lead times: Even with available inventory, data center technicians work on scheduled workflows. Remote hands service-level agreements, ticket queues, and shift patterns affect when physical work actually occurs. A server that could be racked in minutes might wait hours for a technician to become available.

OS image building and validation: Prebuilt images help speed up deployment, but creating custom images takes time. Validating the image and ensuring that the operating system boots properly, drivers load correctly, and core services start can take anywhere from a few minutes to several hours.

Provider scheduling and SLA windows: Most [bare metal providers](https://www.atlantic.net/dedicated-server-hosting/best-bare-metal-hosting-providers-secure-workloads-2026/) offer specific provisioning timeframes. A typical turnaround is within one business day for standard configurations, though custom hardware or specialized OS requirements can extend that timeline.

Procurement and shipping delays: If the provider does not have the requested hardware configuration in stock, procurement timelines become a key factor. Transporting physical servers from a distributor to a data center can take days or weeks. This delay does not exist in the virtual server world.

## Provisioning Stages: From Rack to Application

### Physical Deployment for Metal Server Installations

The first physical step in the process is racking the server. A technician installs the chassis in the assigned rack position, secures it using rail kits, and connects the power cables to the appropriate power distribution units.

The next stage involves verifying the hardware inventory. The technician checks that all physical components match the original order, including the correct CPU model, memory capacity, storage drives, and network interface cards. Serial numbers are also recorded for asset tracking and documentation purposes. If any mismatch or missing component is identified at this stage, the provisioning process is paused until the issue is resolved.

### Network Configuration and Operating System Installation

Once the server is powered on and physically connected, the network configuration process begins. Private IP ranges are assigned for backend communication, management interfaces, and storage networks if required.

The next step is the [switch configuration](https://www.geeksforgeeks.org/computer-networks/switch-concepts-and-configuration/). Ports are assigned to the appropriate VLANs, [trunking](https://en.wikipedia.org/wiki/Trunking) is configured if required, and routing is configured for public-facing traffic. This step requires coordination between the network engineering team and the data center operations staff.

Once networking is established, the operating system is installed. Whether through viat, a provisioning tool such as [MAA, such](https://canonical.com/maas) as [Digital Rebar](https://www.slideshare.net/slideshow/what-is-digital-rebar-provision-and-how-rackn-extends/135012309), or manual installation, the OS image is deployed to disk. Post-installation scripts apply security hardening, install management agents, and configure monitoring. The installation is validated by checking that the system boots properly and all required services are running.

### Application Installation and Validation

The final stage prepares the server for production use after provisioning is complete. Applications or [container runtimes](https://www.wiz.io/academy/container-security/container-runtimes) are deployed. This might involve installing [Docker](https://www.docker.com/), [Kubernetes components](https://kubernetes.io/docs/concepts/overview/components/), database software, or custom application stacks.

Functional tests make sure the server is working properly and performing as expected. Performance benchmarks verify that storage I/O, network throughput, and CPU performance meet the required specifications. Once these checks are completed successfully, the server is handed over to the operations team.

### Automation and Cloud Bare Metal Servers

Automation is closing the gap between bare metal provisioning and cloud speed.

An advancement comes from [zero-touch provisioning](https://www.paloaltonetworks.com/cyberpedia/what-is-zero-touch-provisioning-ZTP) systems. This allows servers to be automatically identified, configured, and deployed as soon as they are turned on. Tools like Digital Rebar and Canonical MAAS detect new hardware on the network, execute pre-defined workflows for firmware updates and [RAID](https://www.atlantic.net/hipaa-data-centers/raid-10/) configuration, install the operating system, and integrate the server into the infrastructure without any manual work.

[Infrastructure-as-code](https://www.ibm.com/think/topics/infrastructure-as-code) tools enable repeatable provisioning. Platforms like [Terraform](https://developer.hashicorp.com/terraform) and [Ansible](https://docs.ansible.com/) allow teams to write the server configurations in version-controlled code. This reduces manual mistakes and maintains consistency. API-driven orchestration facilitates bare metal setup within [CI/CD workflows](https://www.redhat.com/en/topics/devops/what-is-ci-cd). Developers can order and set up physical servers using the same interfaces they use for cloud resources. This gives teams the speed and flexibility of the cloud while still providing the performance benefits of dedicated hardware.

Compared to manual provisioning, which can take days due to handoffs among data center technicians, network engineers, and systems administrators, automated processes reduce the software portion to just minutes. While physical tasks like racking and cabling still require time, many subsequent steps can be completed much more quickly through automation.

## Choosing Between Bare Metal, Dedicated Servers, and Virtual Servers

The right choice depends on your workload characteristics, not on industry trends.

Decision matrix based on workload needs: If your workload demands consistent low latency, high I/O throughput, or strict [single-tenant](https://www.atlantic.net/dedicated-server-hosting/achieving-unparalleled-security-with-single-tenant-dedicated-hosting/) isolation, bare metal is the best choice. If you require rapid scaling, variable capacity, or short-lived environments, virtual servers can be more flexible. [Dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) occupy a middle ground, offering single-tenant hardware, [managed services](https://www.atlantic.net/managed-services/), and predictable billing.

Cost versus performance: Bare metal has a higher initial cost but a lower unit cost for workloads that use resources heavily over time. Virtual servers cost less initially but can become expensive at scale for compute-intensive applications. The break-even point depends on utilization patterns and workload duration.

Full OS control: Bare metal gives you control over the operating system, kernel parameters, and hardware-level tuning. If your application requires custom kernel modules, specific BIOS settings, or direct hardware access, bare metal is the only option that can meet these requirements.

## Scaling, Reliability, and Troubleshooting the Provisioning Process

Provisioning at scale can introduce a range of potential failure points that are important to understand and plan for. Some of these failures include firmware incompatibility, incorrect BIOS boot mode settings, IP address conflicts, and switch port misconfiguration. [Redfish](https://www.paessler.com/it-explained/redfish) or [IPMI](https://www.ibm.com/docs/en/power8/8001-12C?topic=ipmi-overview) communication failures between the provisioning tool and the [baseboard management controller](https://www.techtarget.com/searchnetworking/definition/baseboard-management-controller) (BMC) are also common problems.

[Preflight tests](https://en.wikipedia.org/wiki/Preflight_checklist) can reduce failure rates. Before starting provisioning, it is important to verify that the BMC is reachable, that firmware versions are compatible with the target OS, that switch ports are correctly configured, and that [DNS](https://www.atlantic.net/vps-hosting/what-is-dns-and-how-does-it-work/) entries exist for the planned hostnames. A ten-minute preflight checklist can save you hours of troubleshooting.

Monitoring metrics for provisioning time should track the period from order submission to OS boot completion, the time spent in each provisioning stage, and the success rate of first-attempt provisioning. These key performance indicators can help identify bottlenecks and assess the impact of automation efforts.

## Typical Timelines and Benchmarks for Bare Metal Server Provisioning

The time required to provision a bare metal server depends on how complex the setup is and how much of the process is automated.

Single-server turnkey example: A typical setup with available hardware, a prebuilt operating system image, and automated provisioning usually takes 30 minutes to 4 hours from order to being ready for production. When manual processes involve team handoffs, they can take one or two business days.

Rack-scale provisioning example: Setting up a full rack of servers takes longer due to physical installation tasks—many systems to be set up simultaneously. With zero-touch provisioning tools, a whole rack can often be reset and reprovisioned in under an hour. The physical installation and preparation in the data center can take anywhere from several hours to a few days, depending on the facility’s readiness.

KPIs to measure: Some key metrics include time to OS boot, the success rate of first-attempt provisioning, time to recover from provisioning failures, and total elapsed time from order to production readiness. Monitoring these metrics over time shows whether automation investments are yielding results.

## Conclusion

Bare-metal provisioning can take days. With modern automation, the software side of the process can now be finished in just hours or even minutes. While the physical steps, such as racking, cabling, and hardware validation, are still required, they can be completed more efficiently with proper inventory planning and well-organized data center workflows.

To reduce provisioning time in your environment, start by standardizing hardware configurations. Using pre-validated firmware versions and golden OS images can prevent delays caused by troubleshooting and setup inconsistencies. It is also important to adopt zero-touch provisioning tools that integrate well with your existing infrastructure-as-code workflows.

If you are using bare metal for the first time, it is best to start by testing automation on a small group of servers before expanding further. Begin by measuring your current provisioning times, then introduce automation and track how it improves performance over time. The objective is not to make bare metal as fast as cloud virtual machines, but to make provisioning fast enough that the added performance, control, and reliability justify the extra time.

[Atlantic.Net](https://www.atlantic.net/?utm_source=chatgpt.com) provides bare metal server configurations across multiple U.S. data centers, with infrastructure designed for regulated workloads and deployment options that support automation. Whether you are deploying a single high-performance database server or planning a rack-scale environment, understanding provisioning timelines helps you set realistic expectations and build infrastructure that meets your operational requirements.

 


---

# Understanding Hosting Resource Limits in 2026: CPU, RAM, Storage, I/O, and Hosting Performance

> URL: https://www.atlantic.net/dedicated-server-hosting/hosting-resource-limits-cpu-ram-storage-io/ | Published: 2026-05-27 | Updated: 2026-05-28 | Author: Dr. Assad Abbas

Modern websites, applications, and online services rely on hosting resources to operate. Each action, such as a page request, a file upload, a database query, an email transaction, and a background activity, consumes server capacity. Therefore, hosting providers set resource limits to control usage and maintain stable performance.

These limits define how much CPU, memory, storage, bandwidth, and related resources an application can use within a hosting environment. They are applied across [shared hosting](https://www.atlantic.net/vps-hosting/top-shared-hosting-providers-in-the-usa/), VPS platforms, cloud infrastructure, and managed services. The actual limits vary depending on the hosting model and underlying infrastructure.

Managing these resources has become more important because websites and applications handle larger workloads involving content, growing databases, media files, and background processes. Resource consumption increases over time, and performance issues may arise when usage is not monitored regularly.

Understanding hosting resource limits is therefore important for maintaining performance and system stability. It helps administrators identify bottlenecks early, optimize resource allocation, and reduce the risk of service disruption. This article explains CPU usage, RAM allocation, disk space, [Inodes](https://www.greengeeks.com/support/article/inodes-explained/), bandwidth, disk I/O, and database activity, and their roles in performance management in modern hosting environments.

## Hosting Resource Limits and Their Impact on Performance

Resource limits play an important role in maintaining stable hosting environments, particularly when infrastructure resources are shared among multiple users. In such environments, excessive consumption by one workload may affect the performance and availability of other applications operating on the same server.

Resource contention is common in shared hosting environments because multiple customers use the same physical infrastructure. In such environments, without resource controls, a single account may consume excessive CPU time, create excessive processes, or generate high storage activity. Other websites operating on the server may experience slower response times and reduced performance. This condition is commonly known as the [noisy neighbor](https://www.techtarget.com/searchcloudcomputing/definition/noisy-neighbor-cloud-computing-performance) problem.

To that end, hosting providers apply resource controls to maintain a balanced resource distribution and mitigate the impact of unexpected workload growth. These controls help manage traffic spikes and inefficient resource-consuming applications.

The number of resource limits also varies by hosting model, as resource allocation differs across environments. Shared hosting typically imposes stricter limits on CPU usage, memory allocation, Inode counts, and processes because resources are shared among multiple users. In contrast, VPS environments provide isolated allocations, with users generally receiving dedicated virtual CPU and memory resources. [Dedicated hosting](https://www.atlantic.net/dedicated-server-hosting/dedicated-hosts/) takes a different approach because hardware resources are dedicated to a single customer, reducing competition for infrastructure resources.

Variations in resource allocation also influence application performance across different hosting environments. For example, CPU exhaustion may reduce processing speed, while memory shortages may interrupt workloads and generate errors. Likewise, storage limitations may delay database operations and file processing.

As these limitations begin to affect workload execution, performance degradation usually appears gradually. As a result, actions like page loading often become slower initially. Afterward, response times increase and background activities begin to experience delays. Therefore, monitoring resource usage remains important for maintaining uptime and stable hosting operations.

Table 1: Common Hosting Resource Limits and Their Effect on Application Performance

| **Resource Limit** | **Primary Function** | **Common Performance Effect** |
| --- | --- | --- |
| CPU Usage | Processing workload activity | Slow page loading and delayed requests |
| RAM Allocation | Active workload memory | Application errors and interrupted processes |
| Disk Space | Storage capacity | Upload failures and backup limitations |
| Inode Limits | File and directory counts | File creation and email delivery issues |
| Bandwidth | Network data transfer | Transfer slowdowns and traffic restrictions |
| Disk I/O | Storage read and write activity | Slow database and file operations |

## Managing Disk Space and Inode Usage

Storage resources are closely associated with hosting performance and operational stability. Websites, databases, backups, email services, and cache systems all depend on available storage capacity during normal operation. Uncontrolled storage growth may gradually affect application behavior and account functionality.

### How Disk Space Is Used in Hosting Environments

Disk space refers to the total storage capacity assigned to a hosting account. Many users initially associate storage only with website files. Hosting environments also use storage for databases, email, backups, system logs, cache files, uploaded media, and temporary application data.

As a result, storage usage often increases from multiple sources simultaneously rather than a single workload. Media libraries, automated backups, and retained logs may gradually consume storage capacity.

Because of this, storage monitoring should include all account components, not just visible website content. Regular monitoring and reviews help identify unnecessary backups, unused media files, archived logs, and temporary data before storage limits begin affecting account performance.

### How Inodes Affect Storage Usage

Along with disk space, Inode limits also play an important role in storage management within hosting environments. An Inode is a file system entry that stores information about a file or directory within a hosting account. Hosting providers use Inode limits to control the total number of files and directories an account can create.

Every stored object consumes one Inode. Therefore, images, cache files, emails, temporary files, and log files all contribute to Inode usage. As the number of stored files increases, Inode consumption also rises even when disk usage appears moderate. A hosting account may approach its Inode limit even when disk space is still available.

Caching plugins, archived emails, and backup files commonly increase Inode counts over time. High Inode usage may eventually affect normal hosting operations. Backup creation, file uploads, email delivery, and application processes may become slower or fail when Inode limits are reached. Therefore, Inode monitoring is important for maintaining stable hosting performance and avoiding unexpected storage restrictions.

## CPU Usage, Memory Limits, and Workload Performance

Processing resources play an important role in application responsiveness and hosting stability. Websites, databases, APIs, and background tasks all depend on CPU and memory resources during execution. Excessive workload activity may gradually increase processing delays and reduce application performance.

### CPU Usage in Hosting Environments

CPU usage represents the processing activity generated by workloads within a hosting environment. Websites commonly consume CPU resources during PHP execution, database queries, API requests, [*cron jobs*](https://dev.to/aasik_20409e3305686b324ec/what-is-a-cronjob-and-understanding-syntax-2p6p), and other background operations. CPU demand often increases during traffic spikes and resource-intensive tasks, while inefficient plugins and poorly optimized queries may gradually reduce application responsiveness. Therefore, hosting providers commonly monitor CPU activity through usage dashboards and resource limits to maintain stable hosting performance.

### CPU Allocation Across Different Hosting Models

CPU allocation varies according to the hosting environment and available infrastructure resources. Shared hosting environments commonly apply CPU shares or percentage-based limits because processing resources are distributed among multiple customers. In contrast, VPS platforms generally provide dedicated virtual CPU cores and isolated allocations, while dedicated hosting environments provide full processor access because hardware resources belong to a single customer.

Table 2: Resource Allocation Differences Across Shared, VPS, and Dedicated Hosting Environments

| **Hosting Environment** | **Resource Allocation Model** | **Performance Characteristics** |
| --- | --- | --- |
| Shared Hosting | Resources shared among multiple users | Lower cost with stricter resource limits |
| VPS Hosting | Isolated virtual resources | More predictable workload performance |
| Dedicated Hosting | Full hardware access for one customer | Greater resource control and stability |

These differences in resource allocation directly affect workload capacity and application responsiveness. Websites handling large numbers of simultaneous requests commonly require additional processing power to maintain stable performance. CPU demand also increases when multiple processes run concurrently, including PHP workers, scheduled tasks, backups, indexing operations, and bot traffic. Hosting providers commonly apply process limits and throttling mechanisms to maintain stable operation across shared environments.

## Memory Limits and RAM Allocation

Along with CPU resources, memory allocation also affects application stability and workload execution. RAM stores active workload data while applications, databases, Web servers, and cache systems operate within the hosting environment.

Hosting providers commonly apply account-level and process-level memory limits to prevent excessive consumption and maintain balanced resource distribution. Inadequate memory allocation may interrupt application execution and affect hosting stability.

### How Low Memory Affects Hosting Performance

Memory shortages commonly affect application responsiveness and workload execution. When available memory becomes insufficient, applications may terminate unexpectedly or fail during operation.

Common effects of low memory availability include:

- HTTP 500 errors
- interrupted scripts
- failed background processes
- unstable application behavior
- delayed database operations

As memory pressure increases, responsiveness may gradually decline. Therefore, monitoring RAM usage remains important for maintaining stable hosting performance.

## Bandwidth, Disk I/O, and Database Resource Usage

In addition to CPU and memory resources, bandwidth, disk I/O, and database activity affect application performance in hosting environments. Websites processing large numbers of visitors, downloads, media files, and database requests commonly generate network and storage activity during normal operation.

Bandwidth measures the amount of data transferred between users and the hosting infrastructure. In contrast, disk I/O measures storage read and write activity occurring within the server itself. Website traffic, downloads, APIs, uploads, backups, cache generation, and logging operations all contribute to resource consumption across these areas.

The effect of these resources on performance also varies with workload activity. High bandwidth usage is common during large downloads and media delivery, while high disk I/O activity is common during backups, caching, and database workloads. Storage throughput limitations may reduce application responsiveness even when CPU and memory usage appear stable.

Database activity further increases resource consumption because queries simultaneously use CPU, memory, and storage during execution. Slow queries, missing indexes, and excessive simultaneous database connections may therefore increase workload pressure and gradually affect hosting performance.

## How Hosting Providers Enforce Resource Limits

Hosting providers use monitoring and enforcement systems to maintain stable infrastructure performance and balanced resource distribution across hosting environments. These systems continuously track CPU activity, memory consumption, storage usage, process growth, bandwidth activity, and disk I/O during workload execution.

Shared hosting platforms commonly enforce resource limits through:

- CPU throttling
- process limits
- memory restrictions
- Inode quotas
- disk I/O controls

These controls help reduce the effect of excessive workload growth and maintain stable operation for other users sharing the same infrastructure.

[CloudLinux](https://cloudlinux.com/) is widely used in shared hosting environments because it isolates customer workloads and applies account-level resource controls more effectively. Its Lightweight Virtual Environment technology helps providers limit CPU usage, memory allocation, disk I/O, entry processes, and process counts separately for each account. Excessive activity from a single customer is less likely to affect neighboring workloads running on the same server.

Hosting providers may also apply automated restrictions when resource limits are repeatedly exceeded. CPU throttling, temporary process suspension, or reduced workload priority may occur during periods of excessive activity. Repeated resource warnings often indicate the need for workload adjustments, better monitoring, or infrastructure upgrades to maintain stable hosting performance.

Providers offering managed hosting environments, such as [Atlantic.Net](http://www.atlantic.net), commonly provide monitoring dashboards and resource management tools that help administrators more effectively review CPU usage, memory allocation, storage activity, and workload behavior.

## Monitoring and Resource Planning

Maintaining stable hosting performance requires continuous monitoring and regular workload. Resource usage often increases gradually as websites, databases, media libraries, and background processes expand. Administrators should regularly review CPU usage, memory consumption, storage growth, Inode activity, bandwidth usage, and disk I/O patterns to identify abnormal workload behavior before performance issues affect application stability.

Monitoring alone is not sufficient for long-term performance management. Workload also helps reduce unnecessary resource consumption and improve hosting. In that context, page caching, removal of unused plugins from the database, and review of scheduled background tasks are commonly used to reduce server load and improve responsiveness. At the same time, repeated resource warnings may indicate increasing workload demand and the need for additional CPU resources, increased memory capacity, storage allocation, or higher-performance hosting environments.

## The Bottom Line

Hosting resource limits directly affect application performance, system stability, and hosting reliability. Resources such as CPU usage, memory allocation, disk space, Inode limits, bandwidth activity, disk I/O, and database workloads all contribute to resource consumption within hosting environments. Therefore, understanding and monitoring these limits helps administrators identify bottlenecks early, improve workload, and reduce the risk of service disruption.


---

# AdTech and MarTech Server Hosting Built for Speed and Compliance

> URL: https://www.atlantic.net/adtech-server-hosting/ | Updated: 2026-09-16

Ad platforms run on milliseconds. Atlantic.Net adtech server hosting gives your DSP, SSP, or marketing platform the dedicated resources, low latency, and audited compliance it needs to process millions of bid requests without missing a deadline.

- 0% CPU Steal Time
- 10–25Gbps Unmetered Bandwidth
- SOC 2, PCI DSS & NIST Controls
- 24/7 US-Based Support

RTB Transaction Window: 100–150ms

Infrastructure Experience: Since 1994

## What Is AdTech and MarTech Hosting?

Since 1994, we have hosted infrastructure for businesses in over 100 countries. Our strategically located data center regions across North America, Europe, and Asia, including New York, Ashburn, Orlando, Dallas, San Francisco, Toronto, London, and Singapore, put your adtech servers close to major ad exchanges, cutting network round-trip times and keeping your bids competitive.

AdTech (advertising technology) covers the platforms that buy, sell, and deliver digital ads: demand-side platforms (DSPs), supply-side platforms (SSPs), ad exchanges, ad servers, and data management platforms. MarTech (marketing technology) includes the tools that run campaigns, track attribution, score leads, and personalize content at scale.

Both depend on high-performance hosting. Real-time bidding (RTB) transactions must complete within 100-150 milliseconds. Google Authorized Buyers requires 85% of bid responses to arrive within the deadline, or it throttles your bidder. Marketing platforms process terabytes of user and campaign data daily. Shared hosting cannot keep up.

## Why AdTech Operations Need Dedicated Servers

Shared cloud environments introduce two problems that break adtech infrastructure: variable latency and resource contention.

In a shared environment, other tenants compete for CPU, memory, and network bandwidth. This "noisy neighbor" effect adds unpredictable jitter to response times. For a DSP that needs to calculate bids within 50 milliseconds of computation time, even 2 to 3 milliseconds of added latency means lost auctions and lost revenue.

Dedicated servers eliminate this. You get 0% CPU steal time, deterministic network performance, and full control over your hardware stack. A mid-size DSP processes 2-3 million queries per second. At that volume, consistent low latency determines whether you win or lose auctions.

Security isolation matters too. AdTech platforms handle user tracking data in compliance with GDPR, CCPA, and PCI-DSS. Dedicated hardware ensures your data never shares physical resources with another tenant.

### Variable Latency

### Resource Contention

### Security Isolation

### Lost Auctions / Lost Revenue

## Atlantic.Net AdTech Hosting Features

Atlantic.Net provides high-performance adtech servers built for sustained, latency-sensitive workloads:

### NVMe SSD Storage and High-Speed Hardware

Intel Xeon and AMD EPYC processors with up to 64 cores and 1TB of ECC RAM. NVMe drives deliver sub-millisecond read latency for in-memory bid caching and user profile lookups.

### Dedicated, Cloud, and Bare Metal Options

Choose dedicated servers for steady-state RTB workloads, cloud VPS for burst capacity during campaigns, or bare metal for maximum single-tenant performance. Run all three from one provider.

### US Data Centers Close to Ad Exchanges

Facilities in New York, Ashburn (VA), Orlando, Dallas, and San Francisco. Proximity to major exchanges reduces network transit time, which directly affects whether your bids arrive within the RTB deadline. Additional facilities in Canada, London, and Asia extend coverage to region-specific markets, supporting localized traffic, compliance needs, and global campaign performance.

### Audited Compliance Certifications

SOC 2 Type II, SOC 3 Type II, HIPAA AT-C 105 and 205, HITECH, PCI-DSS, and NIST 800-53. A third-party CPA firm independently audits all certifications. Atlantic.Net signs Business Associate Agreements (BAAs) for health-sector advertisers.

### Top Bandwidth with Flat Pricing

10Gbps to 25Gbps unmetered dedicated bandwidth included, no metered IOPS, no data egress fees. Your monthly cost stays fixed regardless of traffic volume.

### Full Root Access and REST API

Complete control over your server environment. Provision, configure, and scale infrastructure programmatically through the Atlantic.Net API.

### 24/7 Managed Support

US-based technical support available around the clock by phone and email. Optional managed services include firewall management, IPS, monitoring, and DDoS protection.

## AdTech and MarTech Use Cases

### Real-Time Bidding Infrastructure

Host your DSP or SSP on dedicated servers with sub-100ms response capability. Atlantic.Net's NVMe storage and low-latency network handle high-QPS auction traffic from exchanges like Google AdX and The Trade Desk.

### Marketing Automation Platforms

Email campaign engines, lead scoring systems, and workflow automation tools on cloud or dedicated infrastructure. Scale compute resources during campaign launches without migrating providers.

### Attribution and Analytics Pipelines

Process billions of impressions and conversion events with high-memory dedicated servers. GPU instances with NVIDIA L40S or H100 accelerators support machine learning models for attribution modeling and audience segmentation.

### Ad Serving and Creative Delivery

Serve display, video, and native ad creatives from data centers with guaranteed bandwidth. Consistent throughput prevents ad delivery failures during traffic spikes.

### Personalization Engines

Power real-time content personalization with in-memory data processing. Atlantic.Net's dedicated resources ensure your recommendation engine responds within the latency window your users expect.

### Customer Data Platforms (CDPs)

Consolidate user data from ad networks, CRM systems, and analytics tools onto infrastructure that meets data protection requirements. Atlantic.Net's compliance certifications cover GDPR, CCPA, and PCI-DSS, so your CDP operates within regulatory boundaries from day one.

## Cloud Hosting vs. Dedicated Servers for AdTech

| Feature | Cloud VPS | Dedicated Server | Bare Metal |
| --- | --- | --- | --- |
| Best for | Burst capacity, dev/test, campaign spikes | Steady-state RTB, production DSP/SSP | Maximum performance, single-tenant isolation |
| CPU | Shared vCPU resources, variable performance | Dedicated cores, deterministic performance | Dedicated cores with full hardware access |
| Latency | Variable, with noisy-neighbor risk | Consistent and low | Lowest possible |
| Pricing | From $10/mo | From $139/mo | Custom quote |
| Compliance | Available | Available | Available |
| Scaling | Minutes | Hours, often via API | Hours |

Most adtech companies start with dedicated servers for their core bidding infrastructure and add cloud instances for analytics, staging, and overflow. Atlantic.Net supports this hybrid approach from a single account, with all compliance certifications applied across both environments.

## Frequently Asked Questions

### What server specs do I need for real-time bidding?

A production RTB platform requires dedicated servers with high-speed CPUs (Intel Xeon or AMD EPYC), 64GB to 512GB of ECC RAM for in-memory bid decisioning, NVMe SSD storage, and 10Gbps or higher, unmetered bandwidth. The total RTB transaction window is 100-150 milliseconds, with approximately 50 milliseconds allocated to DSP bid computation. Every business use case and solution is different, and a customized solution can help meet and exceed the deployment requirements.

### Is cloud or dedicated hosting better for adtech?

Dedicated servers are better for production RTB workloads because they eliminate CPU steal time and provide deterministic latency. Cloud VPS works well for development, testing, analytics, and handling traffic bursts. Many adtech companies use both, running core bidding on dedicated hardware and scaling analytics on cloud instances.

### Does Atlantic.Net offer PCI-compliant adtech hosting?

Yes. Atlantic.Net infrastructure is PCI-DSS-ready and has been independently audited for SOC 2 Type II, SOC 3 Type II, HIPAA, and HITECH compliance. We also hold NIST 800-53 certification for government and defense advertising contracts.

### How fast can I deploy an adtech server?

Cloud instances deploy in 30 seconds. Dedicated servers are ready within hours. Both include full root access from day one, and the Atlantic.Net REST API supports programmatic provisioning for automated infrastructure management.

## Get Started with Atlantic.Net AdTech Hosting

Atlantic.Net has provided hosting solutions for businesses since 1994. Our adtech and martech hosting combines audited compliance, dedicated infrastructure, and flat-rate pricing so your team can focus on building your platform instead of managing servers.

Talk to our team to configure an adtech server that matches your workload. You can also explore our dedicated server options, cloud hosting plans, or GPU server hosting for ML-powered ad optimization. Every plan includes our full compliance stack and 24/7 support.

## Cloud Availability in Multiple Global Regions

Deploy close to your users from eight international data centers worldwide, with new regions on the way.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Multi-Tenant Bare Metal Architectures for High-Performance Data Collection in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/multi-tenant-bare-metal-data-collection/ | Published: 2026-05-28 | Author: Dr. Assad Abbas

High-performance data collection has become an important requirement for Telemetry platforms, [observability](https://www.redhat.com/en/topics/devops/what-is-observability) systems, IoT deployments, AI pipelines, and streaming analytics that continuously generate logs, metrics, and events. Infrastructure must process large volumes of data while maintaining stable throughput, low latency, and predictable performance.

At the same time, these workloads have become more demanding because many of them operate continuously and process information in real time. Maintaining consistent performance in shared environments is often difficult because infrastructure resources are distributed among multiple users.

Many organizations are considering multi-tenant [bare-metal](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) architectures for modern data collection workloads. This model combines dedicated hardware with controlled tenant separation. Therefore, it provides a balance between the flexibility of public cloud and single-tenant isolation. In 2026, this approach has gained more attention because enterprises increasingly rely on continuous ingestion pipelines, large analytics environments, and business-critical systems that require both performance stability and stronger operational control.

## Architectural Suitability of Multi-Tenant Bare Metal for High-Performance Data Collection Workloads

High-performance data collection workloads often operate under sustained load conditions and require stable resource behavior over long periods. Unlike many traditional applications that process intermittent requests, these workloads continuously process incoming data streams, generating persistent storage and network activity. Therefore, infrastructure must maintain predictable throughput, low latency, and consistent performance.

Another important requirement involves workload isolation. Data collection environments frequently support multiple teams, services, or tenants within the same infrastructure. Architecture must provide separation while maintaining resource utilization.

Multi-tenant bare metal architecture addresses these requirements by combining dedicated hardware with controlled tenant isolation. Workloads access CPU, memory, storage, and networking resources directly, while separation is maintained through dedicated nodes, clusters, and scheduling mechanisms. Therefore, organizations can support multiple workloads and tenants without fully isolating infrastructure for every environment.

This approach is suitable for environments requiring both performance stability and workload isolation. Multi-tenant bare-metal architecture becomes a practical model for high-performance data collection environments.

## Bare Metal Architecture and Multi-Tenant Models

Understanding tenancy models first requires an understanding of bare-metal architecture. Bare metal refers to physical servers operating without a [virtualization](https://www.atlantic.net/about-us/whitepapers/introduction-to-virtualization/) layer between the operating system and the hardware. Therefore, applications access the processor, memory, storage devices, and networking resources directly. This direct interaction improves resource control and supports more predictable workload behavior.

In contrast, virtual environments introduce a hypervisor layer that allows multiple virtual machines to share the same physical infrastructure. Under heavy load, performance may vary because processor scheduling, memory allocation, and storage access are shared across workloads. As a result, maintaining consistent performance can become more difficult under sustained data-collection workloads.

Bare metal environments also offer greater flexibility for infrastructure tuning. Organizations can optimize processor allocation, [NUMA](https://techdocs.broadcom.com/us/en/storage-and-ethernet-connectivity/ethernet-nic-controllers/bcm957xxx/adapters/Tuning/tcp-performance-tuning/nic-tuning_22/numa-local-vs-non-local.html) locality, memory placement, and storage configuration according to workload requirements. For this reason, bare metal is often chosen for performance-sensitive data-collection environments.

Multi-tenant bare metal architectures generally follow four tenancy models.

### Shared Cluster Model

The [shared cluster model](https://medium.com/@masonarmani38/exploring-cluster-architectures-shared-non-shared-and-multi-cluster-shared-88ffe5227826) places multiple tenants within the same cluster while software controls maintain separation. This approach improves infrastructure utilization by sharing resources across tenants. In this model, isolation is comparatively lower because workloads operate in the same environment.

### Dedicated Node Model

Dedicated nodes assign specific hardware resources to individual tenants within a shared cluster. Scheduling mechanisms such as labels, selectors, affinity rules, taints, and tolerations keep workloads on designated nodes. Therefore, this model provides a balance between tenant isolation and infrastructure.

### Dedicated Cluster Model

Dedicated clusters allocate complete clusters to individual tenants. In this model, tenants receive independent resources, independent governance controls, and scaling policies. Therefore, the model provides stronger isolation and commonly supports regulated or latency-sensitive workloads.

### Hybrid Tenancy Model

Hybrid tenancy combines dedicated and shared resources within the same environment. Critical workloads may operate on dedicated nodes, while supporting services use shared infrastructure. In this way, organizations gain flexibility while maintaining performance for priority workloads.

Selecting an appropriate tenancy model depends on workload sensitivity, compliance requirements, tenant size, performance objectives, and operational requirements. Therefore, architecture decisions should follow workload requirements rather than be driven solely by infrastructure preferences.

## Selecting Between Dedicated Nodes and Dedicated Clusters

Selecting between dedicated nodes and dedicated clusters is one of the most important architectural decisions in multi-tenant bare metal environments. This choice affects not only workload isolation but also performance, scalability, governance, and operational management.

Dedicated nodes are commonly used when organizations need stronger workload separation while still maintaining infrastructure utilization. In this model, tenants operate inside a shared cluster, but workloads remain isolated through scheduling mechanisms such as node labels, selectors, affinity rules, taints, and tolerations. Therefore, organizations can maintain predictable performance without fully separating infrastructure resources.

This approach is often suitable for ingestion pipelines, streaming workloads, and large shared analytics environments where multiple workloads must coexist while remaining isolated at the node level.

Some environments require stronger operational separation. Regulated systems, latency-sensitive applications, and business-critical workloads may require independent governance, scaling policies, and resource management. In such cases, dedicated clusters are more appropriate, as each tenant operates in an isolated cluster environment.

Dedicated clusters are frequently selected for:

- regulated environments
- high availability systems
- latency-sensitive pipelines
- business-critical ingestion workloads

The following mapping provides general guidance.

Table 1: Workload Mapping for Dedicated Nodes and Dedicated Clusters

| Workload Type | Recommended Model |
| --- | --- |
| Shared analytics environments | Shared clusters |
| Streaming ingestion | Dedicated nodes |
| AI preprocessing | Dedicated clusters |
| Regulated workloads | Dedicated clusters |

Therefore, the choice between dedicated nodes and dedicated clusters should be guided by workload requirements, isolation needs, and operational objectives rather than by infrastructure preferences alone.

## Control Plane Architecture and Tenant Isolation

After selecting tenancy models and isolation strategies, organizations must also evaluate [control plane](https://www.ibm.com/think/topics/control-plane) architecture. Control plane design influences tenant management and operational isolation. Therefore, it directly affects how high-performance data collection environments are managed and scaled.

Organizations generally choose between shared and dedicated control planes.

Shared control planes place multiple tenants under the same management layer. This approach reduces operational overhead by centralizing administration, monitoring, and configuration. Therefore, it commonly supports environments where workloads share infrastructure and governance requirements are moderate.

Some environments require greater operational separation. In such cases, dedicated control planes are more suitable because each tenant operates independently, with its own management, upgrade cycles, and scaling policies. Therefore, this model commonly supports regulated workloads, latency-sensitive pipelines, and business-critical ingestion systems.

Control plane design also requires evaluating several architectural components, including API server placement, [etcd strategy](https://www.ibm.com/think/topics/etcd), control plane separation, and TLS encryption in transit.

High-availability planning is equally important because control-plane stability affects operational management. Therefore, organizations commonly implement redundancy, quorum mechanisms, recovery validation, and failover testing.

Control plane architecture should therefore align with tenancy boundaries and workload requirements. This helps organizations maintain both tenant isolation and operational stability in high-performance data collection environments.

## Workload and Storage Architecture for High-Performance Data Collection

Workload characteristics directly influence infrastructure design in multi-tenant bare metal environments. High-performance data collection systems process different workload types, and each workload has different requirements for compute, storage, and network resources. Therefore, infrastructure design should align with workload behavior rather than using a uniform deployment approach.

Streaming ingestion workloads generally prioritize network throughput and fast storage because they process continuous event streams. In contrast, batch processing environments depend more on processor and memory resources. Similarly, analytics workloads often require a balance between storage performance and compute capacity.

This variation can be observed in commonly used frameworks. For example, Apache Kafka and Apache Flink commonly support streaming environments, while Apache Spark and Apache Hadoop support large-scale analytics workloads. Likewise, ClickHouse is commonly used for analytics storage and query processing. Table 2 summarizes common workload priorities.

Table 2: Infrastructure Priorities for High-Performance Data Collection Workloads

| **Workload Pattern** | **Infrastructure Priority** |
| --- | --- |
| Streaming ingestion | Network and NVMe |
| Batch ETL | CPU and memory |
| Log aggregation | IOPS |
| Telemetry collection | Throughput |
| Analytics workloads | Storage and compute |

The workload priorities shown in Table 2 also influence storage decisions, as different data collection patterns yield distinct storage requirements. Streaming and ingestion workloads often require low latency and fast *write* performance, while analytics environments may prioritize scalability and long-term retention. Therefore, many multi-tenant bare-metal environments combine local NVMe storage for active ingestion workloads with distributed storage systems, such as [Ceph](https://ceph.io/en/), for retention, resilience, and recovery.

## Performance and Observability

Maintaining performance stability is a primary objective of multi-tenant bare-metal architectures for high-performance data collection. Since ingestion pipelines and analytics workloads often operate continuously, organizations must monitor system behavior and validate whether infrastructure performance meets workload requirements.

Performance evaluation commonly uses metrics such as throughput, p95 and p99 latency, IOPS, queue depth, and jitter. These indicators help measure workload behavior under both normal and peak operating conditions and assist in identifying performance bottlenecks.

Resource also contributes to performance consistency. Techniques such as NUMA pinning, CPU isolation, [Huge Pages](https://www.netdata.cloud/blog/understanding-huge-pages/), interrupts, and NIC tuning help improve resource locality and reduce latency variation. Therefore, these methods are commonly used in ingestion-intensive, latency-sensitive environments.

Observability is also important in high-performance data collection environments because continuous ingestion pipelines generate persistent storage, network, and processing activity. Therefore, organizations require visibility into infrastructure and workload behavior to identify bottlenecks and performance variation. This visibility commonly comes from node health indicators, storage activity, network statistics, and workload metrics. Similarly, performance baselines and centralized logging help identify anomalies and trace activity across distributed data collection pipelines.

## Tenant Isolation, Validation, and Architecture Recommendations

Tenant isolation is important in multi-tenant bare-metal environments because high-performance data collection systems often process continuous ingestion traffic spanning multiple workloads and tenants. Therefore, separation mechanisms should maintain stable performance while keeping workloads independent.

Network controls help achieve this separation. Organizations commonly use VLAN segmentation, software-defined networking, micro segmentation, and quality of service policies to separate tenant traffic and reduce interference between workloads.

Security controls are also required because multi-tenant data collection environments may process operational, telemetry, and regulated data across multiple tenants. Therefore, organizations commonly implement namespace separation, Role-Based Access Control (RBAC), TLS encryption, and audit logging to strengthen workload isolation and operational oversight. Regulated environments may also require HIPAA- or PCI-compliant controls.

After defining isolation and security controls, organizations should evaluate whether the selected architecture matches workload requirements. Common evaluation factors include workload sensitivity, performance objectives, scalability targets, compliance obligations, and operational, as they influence tenancy selection.

Validation should then be completed before production deployment. Organizations commonly perform ingestion stress testing, failover testing, workload contention analysis, and isolation verification to evaluate infrastructure performance under expected workload conditions.

Table 3 summarizes common tenancy recommendations for high-performance data collection workloads.

Table 3: Recommended Tenancy Models for High-Performance Data Collection Workloads

| **Workload Type** | **Recommended Model** |
| --- | --- |
| Shared analytics environments | Shared clusters |
| Streaming ingestion | Dedicated nodes |
| Regulated workloads | Dedicated clusters |
| Latency-sensitive pipelines | Dedicated clusters |

### Architecture Recommendations

- Use shared clusters when infrastructure utilization is more important than strict isolation requirements.
- Select dedicated nodes for streaming ingestion, telemetry pipelines, and log-collection workloads that require balanced performance.
- Use dedicated clusters for regulated environments, latency-sensitive pipelines, and business-critical data collection systems that require stronger isolation.
- Apply network and security controls, including VLAN segmentation, quality of service policies, RBAC, TLS, and audit logging, to maintain tenant separation.
- Perform validation testing before deployment through ingestion stress testing, failover testing, workload contention analysis, and isolation verification.

Therefore, tenancy selection should align with workload behavior, isolation requirements, and operational objectives to maintain stable performance in high-performance data collection environments.

## The Bottom Line

Multi-tenant bare metal architecture has become an important model for high-performance data collection environments in 2026. Dedicated hardware improves predictability because workloads access compute, storage, and network resources directly. At the same time, tenant isolation mechanisms improve workload separation and operational control across shared environments.

Effective architectural design requires evaluating tenancy models, control-plane design, storage strategy, networking, and workload behavior, as these factors collectively influence scalability and operational performance. Therefore, organizations should validate workload requirements and benchmark infrastructure before production deployment.

In modern data collection systems, multi-tenant bare metal provides a practical balance between performance, scalability, and tenant isolation.


---

# Atlantic.Net Honored as Bronze Stevie® Award Winnerin 2026 American Business Awards®

> URL: https://www.atlantic.net/press-releases/atlantic-net-honored-as-bronze-stevie-award-winnerin-2026-american-business-awards/ | Published: 2026-05-28 | Updated: 2026-06-04 | Author: Editorial Team

ORLANDO, FL (May 26, 2026) Atlantic.Net was named the winner of a Bronze Stevie® Award in the Healthcare Technology Solution category in The 24th Annual American Business Awards®.

Atlantic.Net earned this recognition for its significant upgrade of its HIPAA-compliant hosting environment. In Nov. 2025, Atlantic.Net unveiled its[HIPAA-Compliant GPU Hosting service](https://www.atlantic.net/gpu-server-hosting/hipaa-gpu-hosting/), designed exclusively for healthcare, biotech, and medical companies seeking performance and regulatory peace of mind. The company has provided HIPAA-compliant Cloud Hosting services for healthcare providers since 2010, ensuring “As we continue to innovate and forecast what our healthcare clients will need in the future, our upgrade of the HIPAA-Compliant Hosting product was simply the right timing to help our customers have access to enhanced privacy, security, and compliance in the age of AI,” said Marty Puranik, founder and CEO of Atlantic.Net.

The American Business Awards are the U.S.A.’s premier business awards program. More than 3,700 nominations from individuals and organizations of all sizes and in virtually every industry were submitted this year for consideration in a wide range of categories. More than 230 professionals worldwide participated in the judging process to select this year’s Stevie Award winners.

“Organizations across the United States continue to set a high standard for innovation and performance,” said Stevie Awards president Maggie Miller. “The breadth and quality of nominations submitted to The 2026 American Business Awards reflect a dynamic and competitive business environment, where organizations are finding new ways to drive growth, deliver value, and make an impact. We congratulate all of this year’s Stevie Award winners and look forward to celebrating their accomplishments at our June 9 awards ceremony in New York.”

Details about The American Business Awards and the list of 2026 Stevie winners are available at [https://ABA.StevieAwards.com](https://aba.stevieawards.com/). 

**About Atlantic.Net**

Founded in 1994, [Atlantic.Net](https://www.atlantic.net/) is a privately held global cloud infrastructure provider with customers in over 100 countries, known for delivering secure, compliant, on-demand and customizable hosting solutions. With decades of experience, Atlantic.Net is one of the world’s most trusted and experienced hosting providers, offering 24/7 U.S.-based support. Specializing in security, compliance, and customer service, Atlantic.Net serves a diverse range of industries with solutions including HIPAA-compliant hosting and PCI-compliant hosting, backed by bare metal servers, dedicated hosting, GPU hosting, colocation, and its award-winning Cloud Platform. Operating from eight strategically located data center regions across the United States, Canada, the United Kingdom, and Asia, Atlantic.Net powers mission-critical workloads for organizations worldwide. For more information, visit[ Atlantic.Net](https://www.atlantic.net/) or connect with us on[ Facebook](https://www.facebook.com/Atlantic.Net),[ X (Twitter)](https://twitter.com/AtlanticNet),[ LinkedIn](https://www.linkedin.com/company/atlantic.net-inc./posts/?feedView=all), and[ YouTube](https://www.youtube.com/c/AtlanticNet).

**About the Stevie Awards**
 Stevie Awards are conferred in nine programs: the Asia-Pacific Stevie Awards, the German Stevie Awards, the Middle East & North Africa Stevie Awards, The American Business Awards®, The International Business Awards®, the Stevie Awards for Women in Business, the Stevie Awards for Great Employers, the Stevie Awards for Sales & Customer Service, and the new Stevie Awards for Technology Excellence. Stevie Awards competitions receive more than 12,000 entries each year from organizations in more than 70 nations. Honoring organizations of all types and sizes, as well as the people behind them, the Stevies recognize outstanding workplace performance worldwide. Learn more about the Stevie Awards at [http://www.StevieAwards.com](http://www.stevieawards.com/).

 


---

# The 2026 Infrastructure & Cloud HealthTech Award Goes to Atlantic.Net

> URL: https://www.atlantic.net/press-releases/the-2026-infrastructure-cloud-healthtech-award-goes-to-atlantic-net/ | Published: 2026-05-28 | Updated: 2026-06-04 | Author: Editorial Team

**Orlando (May 28, 2026)** Atlantic.Net has won HealthTechNode’s 2026 Infrastructure & Cloud HealthTech Award for its[HIPAA-Compliant GPU Hosting service](https://www.atlantic.net/gpu-server-hosting/hipaa-gpu-hosting/). Designed exclusively for healthcare, biotech, and medical companies seeking performance and regulatory peace of mind, this service is a significant upgrade of its HIPAA-compliant hosting environment services offered since 2010, ensuring privacy, security, and compliance.

The impact for[Atlantic.Net](http://atlantic.net/)’s clients includes having the ability to solve AI Healthcare compliance and security.  It is callable and can be scalable in seconds. HIPAA-Compliant GPU is also[SOC 2 and SOC 3 certified, HIPAA and HITECH audited](https://www.atlantic.net/compliance-hosting/), and designed to secure and protect critical health data, electronic protected health information, and records.

This new service redefines standards by providing seamless, high-performance HIPAA hosting without custom builds, empowering providers to innovate securely.

In reviewing this year’s submissions, HealthTechNode looked for infrastructure solutions that do more than provide raw cloud capacity. The strongest entries demonstrated healthcare-specific compliance readiness, operational reliability, scalability, and practical support for mission-critical workloads. Atlantic.Net stood out for bringing those elements together in a way that is highly relevant to healthcare’s current infrastructure demands.

“Atlantic.Net stood out by showing what modern healthcare infrastructure needs to deliver right now,” said Jordan Hayes, HealthTechNode awards coordinator. “Atlantic.Net’s platform gives healthcare organizations a more secure and scalable path to AI-ready cloud deployment, while reinforcing the compliance, reliability, and operational support that regulated, mission-critical environments demand. That combination made Atlantic.Net a clear winner in this category.”

The Infrastructure & Cloud HealthTech Award recognizes the platforms, hosting environments, and cloud services that make secure, scalable health technology possible behind the scenes. Atlantic.Net distinguished itself by aligning cloud performance with healthcare-specific compliance and operational requirements, an increasingly important need as AI and data-intensive applications become more common across the industry.

**About Atlantic.Net**

Founded in 1994, [Atlantic.Net](https://www.atlantic.net/) is a privately held global cloud infrastructure provider with customers in over 100 countries, known for delivering secure, compliant, on-demand and customizable hosting solutions. With decades of experience, Atlantic.Net is one of the world’s most trusted and experienced hosting providers, offering 24/7 U.S.-based support. Specializing in security, compliance, and customer service, Atlantic.Net serves a diverse range of industries with solutions including HIPAA-compliant hosting and PCI-compliant hosting, backed by bare metal servers, dedicated hosting, GPU hosting, colocation, and its award-winning Cloud Platform. Operating from eight strategically located data center regions across the United States, Canada, the United Kingdom, and Asia, Atlantic.Net powers mission-critical workloads for organizations worldwide. For more information, visit[ Atlantic.Net](https://www.atlantic.net/) or connect with us on[ Facebook](https://www.facebook.com/Atlantic.Net),[ X (Twitter)](https://twitter.com/AtlanticNet),[ LinkedIn](https://www.linkedin.com/company/atlantic.net-inc./posts/?feedView=all), and[ YouTube](https://www.youtube.com/c/AtlanticNet).

**About the Award**

The Infrastructure & Cloud HealthTech Award honors the platforms, hosting environments, cloud architectures, and infrastructure services that help health technology operate securely, reliably, and at scale. This category recognizes the foundation behind modern healthcare innovation, spotlighting solutions that strengthen uptime, compliance, performance, and long-term operational readiness.


---

# Recommended HIPAA Hosting Services for EMR and EHR Systems in 2026

> URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-hosting-emr-ehr-systems/ | Published: 2026-05-28 | Updated: 2026-06-23 | Author: Richard Bailey

Choosing HIPAA hosting for an [Electronic Medical Record](https://www.atlantic.net/hipaa-compliant-hosting/electronic-medical-records-made-easy-with-managed-server-hosting/) (EMR) or Electronic Health Record (EHR) system is not the same as choosing ordinary web hosting. Healthcare applications must protect electronic protected health information (ePHI), support reliable clinical workflows, and provide the documentation needed to prove that the right safeguards are in place.

The most important requirement is simple: before ePHI is stored, processed, backed up, logged, or transmitted through a hosting environment, the provider must be willing to sign a HIPAA-compliant [Business Associate Agreement](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) (BAA). A host that refuses to sign a BAA should be removed from consideration immediately.

A BAA does not automatically make an organization HIPAA-compliant. It defines the hosting provider’s contractual responsibility for safeguarding ePHI and clarifies which safeguards the provider manages versus which remain the customer’s responsibility. For EMR and EHR systems, that distinction is critical because uptime, access control, auditability, backup integrity, and disaster recovery all affect patient care and compliance readiness.

For many small and mid-sized healthcare organizations, a fully managed HIPAA hosting provider such as Atlantic.Net is the most practical choice because it reduces the internal burden of configuring, monitoring, patching, and documenting the infrastructure layer. Larger health systems and software teams may prefer AWS, Microsoft Azure, Google Cloud, Aptible, or Heroku Shield. Still, these platforms typically require more in-house expertise in cloud, DevOps, and compliance.

## Why HIPAA Hosting Matters for EMR and EHR Systems

EMR and EHR platforms often contain some of the most sensitive data a healthcare organization handles, including patient identifiers, diagnoses, treatment histories, prescriptions, lab results, billing records, clinical notes, and appointment information. If this data is stored or transmitted electronically, it is ePHI and must be protected under the HIPAA Security Rule.

HIPAA applies to covered entities, such as healthcare providers, health plans, and healthcare clearinghouses, as well as business associates that create, receive, maintain, or transmit PHI on behalf of a covered entity. Cloud hosting providers, managed service providers, backup vendors, and application infrastructure providers can all become business associates when their services involve ePHI.

A healthcare organization can use cloud hosting for ePHI, but it must implement appropriate contractual and technical safeguards. In practice, that means choosing a provider that will sign a BAA, operate secure infrastructure, support HIPAA technical safeguards, and provide clear documentation for audits, risk analysis, and vendor management.

## What Makes Hosting HIPAA-compliant?

There is no single server, certificate, or hosting label that makes an entire organization HIPAA-compliant. [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-in-the-age-of-ai/) depends on administrative, physical, and technical safeguards working together. A HIPAA hosting provider supports the infrastructure portion of that compliance program.

At a minimum, healthcare organizations should look for the following capabilities.

### 1. Signed BAA

A BAA is mandatory when a hosting provider creates, receives, maintains, or transmits ePHI on behalf of a covered entity or another business associate. The BAA should cover the full hosting environment, including servers, databases, storage, backups, logs, monitoring tools, support access, and subcontractors where applicable.

Ask the provider:

- Will you sign a BAA before any ePHI is uploaded?
- Which services are covered by the BAA?
- Are backups, logs, snapshots, and support systems covered?
- Do subcontractors also sign appropriate agreements?
- What breach notification and incident escalation obligations are included?

If the provider cannot answer these questions clearly, it is not a good fit for EMR or EHR hosting.

### 2. Encryption at Rest and in Transit

HIPAA is technology-neutral, but modern healthcare hosting should use strong encryption for data at rest and in transit. For practical purposes, healthcare buyers should expect encryption such as AES-256 or an equivalent standard for stored data, encrypted backups, and secure network transmission over TLS.

Encryption should apply to:

- Server disks and block storage
- Databases
- File storage and object storage
- Backups and snapshots
- Administrative access channels
- Application traffic between users, APIs, and backend systems

Encryption is only as strong as the associated key management, access control, and monitoring practices. Ask how encryption keys are managed, who can access them, and whether key access is logged.

### 3. Unique Identity, MFA, and Access Control

Every user with access to systems containing ePHI should have a unique identity. Shared administrative accounts should be avoided because they make it difficult to prove who accessed or changed data.

A HIPAA-ready hosting environment should support:

- Unique user IDs
- Strong password policies
- Multi-factor authentication (MFA)
- Automatic session timeouts
- Role-based access control (RBAC)
- Least-privilege permissions
- Privileged access logging
- Secure administrative access through VPN, bastion host, or other controlled methods

For EMR and EHR hosting, access control must apply to both the application and the infrastructure. A hosting provider may secure access to the infrastructure. The customer is still responsible for application-level users, roles, and permissions unless those functions are included in a managed service agreement.

### 4. Immutable Audit Logs and Monitoring

HIPAA audit controls require organizations to record and examine activity in systems that contain or use ePHI. For hosting, this means the environment should generate logs showing administrative access, authentication events, configuration changes, network activity, security alerts, backup events, and system activity.

For EMR and EHR workloads, audit logs should help answer:

- Who accessed the system?
- What system, database, or file was accessed?
- What changes were made?
- When did the activity occur?
- Was the action authorized?
- Were any suspicious or failed access attempts detected?

Logs should be protected against tampering, retained in accordance with the organization’s compliance policy, and made available for investigations and audits. The most useful providers do not merely generate logs; they help customers preserve and review them.

### 5. Secure Data Centers and Physical Safeguards

Physical infrastructure still matters in cloud hosting. Data centers supporting HIPAA workloads should use layered physical security controls, including restricted access, surveillance, visitor logging, environmental controls, redundant power, and network resiliency.

Ask prospective hosts about:

- Data center access controls
- Video surveillance
- Visitor logging
- Environmental monitoring
- Fire suppression
- Redundant power and network connectivity
- Third-party audits or independent control reports

A provider’s physical safeguards should align with the sensitivity and availability requirements of clinical systems.

### 6. Server Isolation and Network Segmentation

Standard shared web hosting is usually a poor fit for ePHI because it lacks the isolation, administrative control, auditability, and contractual clarity required for healthcare workloads.

For EMR and EHR systems, consider:

- Dedicated servers
- Virtual private servers with proper isolation
- Private cloud environments
- Dedicated cloud hosts
- Segmented networks
- Firewalls and intrusion detection/prevention
- VPN or private connectivity for administrative access

Isolation helps reduce the risk that another customer’s misconfiguration, traffic pattern, or security incident could affect systems that handle ePHI.

### 7. Backup, Disaster Recovery, and High Availability

Availability is a core part of the HIPAA Security Rule because healthcare systems must remain accessible when needed. EMR and EHR downtime can disrupt patient care, billing, prescribing, scheduling, and clinical decision-making.

A HIPAA hosting provider should support:

- Encrypted backups
- Off-site or geographically redundant backup storage
- Documented retention policies
- Routine backup testing
- Disaster recovery planning
- Recovery point objective (RPO) and recovery time objective (RTO) planning
- High-availability architecture where required

Do not rely on a provider’s generic “backup included” statement. Ask how often backups run, where they are stored, whether they are encrypted, how restoration is tested, and who is responsible for initiating recovery.

## HIPAA Hosting Models Compared

The best HIPAA hosting option depends on the organization’s technical maturity, compliance resources, budget, application architecture, and operational requirements.

| **Hosting model** | **Examples** | **Pros** | **Cons** | **Best for** |
| --- | --- | --- | --- | --- |
| Fully managed HIPAA specialist | Atlantic.Net, | BAA support, managed infrastructure, security controls, backups, patching, monitoring, and compliance documentation support | Higher base cost than unmanaged hosting; less DIY flexibility | Clinics, practices, healthcare SaaS teams, and SMBs without large internal security teams |
| Public cloud infrastructure | AWS, Microsoft Azure, Google Cloud | Massive scalability, broad service catalogs, global infrastructure, and strong native security tooling | Shared responsibility is complex; misconfiguration risk is high; it requires skilled cloud engineers. | Large healthcare organizations, enterprises, and software companies with mature DevOps and compliance teams |
| Compliance-focused PaaS | Aptible, Heroku Shield | Faster deployment workflows, developer-friendly platform controls, and integrated compliance features | Premium pricing, platform constraints, and potential vendor lock-in | Modern software teams deploying containerized or cloud-native healthcare applications |
| Dedicated or private cloud hosting | Atlantic.Net private cloud, dedicated servers, bare metal | Strong isolation, predictable performance, clearer control boundaries | Requires more planning than commodity shared hosting | EMR/EHR systems that need performance, isolation, or custom architecture |

## Recommended HIPAA Hosting Services for 2026

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

### 1. Atlantic.Net — Best for Managed HIPAA Hosting

Atlantic.Net is a strong fit for healthcare organizations that need a HIPAA hosting environment without taking on the full burden of configuring and operating the infrastructure themselves. Atlantic.Net offers [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/), managed services, cloud servers, [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/), [private cloud](https://www.atlantic.net/private-cloud-hosting/what-is-private-cloud-hosting/) options, encrypted storage and backup capabilities, firewalls, [intrusion detection](https://www.atlantic.net/dedicated-server-hosting/what-is-an-intrusion-detection-system-and-why-do-i-need-it/) and prevention, and documented compliance support.

Atlantic.Net will sign a BAA and operate an audited infrastructure designed for regulated workloads. Its HIPAA hosting model is especially relevant for EMR and EHR systems because it combines infrastructure security with managed support, helping to reduce the operational burden on healthcare organizations without dedicated DevOps and security teams.

Atlantic.Net is a good choice when you need:

- A hosting provider willing to sign a BAA
- Managed HIPAA infrastructure
- Cloud, dedicated, or private hosting options
- Security controls such as firewalls, VPNs, encryption, and intrusion detection/prevention
- Backup and disaster recovery options
- Compliance-focused documentation and support
- A provider with long-standing hosting experience and healthcare compliance services

Best for: Small and mid-sized healthcare organizations, healthcare SaaS vendors, clinics, practices, billing providers, and EMR/EHR deployments that need managed compliance-ready infrastructure.

### 2. AWS — Best for Highly Scalable Public Cloud HIPAA Workloads

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

AWS offers a large ecosystem of HIPAA-eligible services and a Business Associate Addendum for eligible customers. It can support complex healthcare workloads, analytics, machine learning, storage, APIs, and large-scale application architectures.

AWS is not a “set it and forget it” HIPAA solution. Customers must understand the shared responsibility model and use only HIPAA-eligible services for PHI; they must also configure appropriate encryption, IAM, logging, backups, monitoring, network controls, and application security.

Best for: Large healthcare organizations and software teams with experienced AWS engineers, security architects, and compliance personnel.

### 3. Microsoft Azure — Best for Microsoft-Centric Healthcare Environments

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

Microsoft Azure offers in-scope services and a HIPAA BAA through Microsoft’s product terms for eligible customers. It can be a strong fit for healthcare organizations that already rely on Microsoft identity, productivity, endpoint, and security tooling.

As with AWS, Azure customers remain responsible for configuring applications and services securely. Azure may be most useful for healthcare teams that already use the Microsoft cloud and want to integrate identity, security monitoring, databases, application services, and analytics.

Best for: Healthcare organizations standardized on Microsoft cloud, identity, and security platforms.

### 4. Google Cloud — Best for Data, AI, and Analytics-Focused Healthcare Teams

![](https://www.atlantic.net/wp-content/uploads/2025/05/gcp.png)

Google Cloud supports HIPAA compliance under a BAA and provides services commonly used for data processing, analytics, application hosting, and machine learning. It may be attractive to healthcare organizations building modern data pipelines, clinical analytics systems, or cloud-native healthcare applications.

Google Cloud emphasizes shared responsibility, meaning the customer must evaluate, configure, and secure the environment. Healthcare organizations should confirm which services are covered by the BAA and ensure that PHI is used only in approved services and architectures.

Best for: Healthcare technology teams with strong cloud engineering skills and data-focused workloads.

### 5. Aptible — Best for Digital Health Development Teams

![](https://www.atlantic.net/wp-content/uploads/2026/05/Aptible_logo.jpg)

Aptible is a compliance-focused platform designed for digital health teams who want secure application and database deployments without having to manage every underlying cloud component directly. It emphasizes isolated environments, encryption, auditability, and compliance-focused workflows.

Aptible can be useful for healthcare startups and SaaS teams that need to deploy applications quickly while keeping infrastructure controls aligned with HIPAA expectations.

Best for: Digital health startups, healthcare SaaS companies, and engineering teams deploying containerized applications.

### 6. Heroku Shield — Best for Regulated Apps in the Heroku Ecosystem

![](https://www.atlantic.net/wp-content/uploads/2026/05/Heroku_logo.png)

Heroku Shield is designed for applications with higher compliance needs, including healthcare and life sciences use cases. It can support developer-friendly workflows for regulated applications, but it is usually most relevant to teams already committed to the Heroku/Salesforce ecosystem.

Buyers should confirm BAA availability, covered services, pricing, logging, network isolation, and operational responsibility before using Heroku Shield for ePHI.

Best for: Development teams already using Heroku or Salesforce and building regulated healthcare applications.

## HIPAA Hosting Vendor Evaluation Checklist

Before choosing a provider, ask these questions and document the answers.

### Legal and Contractual

- Will you sign a BAA before ePHI is uploaded?
- Which services, systems, regions, backups, logs, and support tools are covered by the BAA?
- Do appropriate agreements cover subcontractors?
- What breach notification obligations are included?
- What happens to data at contract termination?

### Technical Safeguards

- Is data encrypted at rest and in transit?
- Which encryption standards and protocols are used?
- How are encryption keys managed?
- Is MFA available or required for administrative access?
- Are unique user IDs enforced?
- Are role-based access controls supported?
- Are audit logs immutable or protected from tampering?
- How long are logs retained?
- Is privileged access logged?

### Infrastructure and Physical Security

- Are workloads isolated from other customers?
- Is the environment VPS, dedicated, private cloud, or [shared hosting](https://www.atlantic.net/vps-hosting/vps-hosting-vs-shared-hosting-pros-cons-differences-and-expert-tips/)?
- What physical access controls are used in the data center?
- Are third-party audit reports available?
- Are firewalls, VPNs, IDS/IPS, and network segmentation available?

### Backup and Disaster Recovery

- Are backups encrypted?
- Are backups stored off-site or in another region?
- How often are backups performed?
- What retention policies are available?
- Are the restores tested?
- What RPO and RTO options are supported?
- Is high availability available for critical systems?

### Support and Operations

- Is support available 24/7/365?
- Does support understand HIPAA hosting requirements?
- Which tasks are managed by the provider?
- Which tasks remain the customer’s responsibility?
- Are OS patching, vulnerability management, monitoring, and incident response included?
- Can the provider support migration from an existing EMR/EHR hosting environment?

## Atlantic.Net’s Position: Managed HIPAA Hosting for Healthcare Workloads

Atlantic.Net is the best choice for organizations that need more than raw cloud infrastructure. EMR and EHR hosting requires a secure infrastructure, operational discipline, availability of support, backup planning, audit evidence, and clear shared responsibility.

Atlantic.Net helps address those needs through:

- Signed BAAs for HIPAA hosting customers
- Independently audited compliance hosting infrastructure
- SOC 2 and SOC 3 reporting
- HIPAA and HITECH-audited hosting services
- Cloud, dedicated, and private hosting options
- [Managed firewalls](https://www.atlantic.net/managed-services/firewall/), encrypted VPNs, encrypted storage, and backup options
- Intrusion detection and prevention capabilities
- 24/7/365 support and monitoring
- More than 30 years of hosting experience

This makes Atlantic.Net especially relevant for healthcare organizations seeking a managed hosting partner rather than a complex public cloud platform that their internal team must design, secure, monitor, and document from scratch.

## Final Recommendation

For EMR and EHR systems, the best HIPAA hosting provider is the one that can clearly answer three questions:

1. Will you sign a BAA that covers every system touching ePHI?
2. Which HIPAA safeguards do you manage, and which remain our responsibility?
3. Can you provide technical controls, audit evidence, backups, disaster recovery, and support that match our clinical risk?

Atlantic.Net is a recommended choice for organizations seeking managed HIPAA hosting with reliable infrastructure controls and compliance support. Public cloud platforms such as AWS, Azure, and Google Cloud can also support HIPAA workloads, but they generally require more extensive internal configuration and careful attention. PaaS options such as Aptible and Heroku Shield can be effective for developer-led healthcare applications, provided the organization understands the coverage, costs, and shared responsibilities.

The safest approach is to start with the BAA, confirm the provider’s technical safeguards, verify the audit documentation, and align the hosting model with the organization’s internal capabilities. For healthcare organizations without a large security and DevOps team, managed HIPAA hosting from a specialist provider such as Atlantic.Net is often the most direct path to a secure, auditable, and reliable EMR/EHR hosting environment.

 


---

# Hybrid Architecture Is Permanent: Enterprises Now Need to Govern It Properly 

> URL: https://www.atlantic.net/dedicated-server-hosting/hybrid-architecture-governance-enterprises/ | Published: 2026-05-28 | Author: Richard Bailey

Atlantic.Net works with organizations that no longer fit neatly into one infrastructure model. A [public cloud platform](https://www.atlantic.net/cloud-platform/cloud-hosting) may suit an elastic web tier that scales up during traffic spikes and scales back down when demand falls. A database tier may require [predictable latency](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers), strict access controls, and a clear backup and recovery plan. An analytics layer may need to replicate production data without disrupting live applications. A regulated workload may need an environment that can produce audit evidence quickly, consistently, and without panic before every review.

That is the reality behind modern hybrid architecture. It is not simply a compromise between cloud and on-premises infrastructure. It is a practical response to the way enterprise workloads behave.

For years, infrastructure decisions were often framed around a single destination: move everything to the cloud, keep everything in the data center, or consolidate on a single preferred platform. This approach made sense when applications were simpler, and workload patterns were more predictable. It makes less sense when different parts of the same application estate have different requirements for latency, compliance, resilience, cost, and operational control.

Hybrid architecture is becoming more popular because enterprise applications no longer behave like one fixed system. The question is no longer whether hybrid environments will exist. They already do. The more important question is whether the organization governs them deliberately or lets them fragment.

## Application Placement Starts With Data, Compliance, and Risk

Many hybrid strategy problems begin with the wrong first question. Teams start by asking which platform they prefer, which vendor they already use, or which option appears to be the cheapest in the short term. Those inputs matter, but they shouldn’t drive the placement decision.

A stronger starting point is more direct:

What data does this workload touch?

What obligations apply to that data?

What performance, resilience, and availability requirements does the workload need to meet?

These questions narrow the field before the organization starts comparing platforms. They also reduce the risk of a workload landing in a convenient but unsuitable location.

For regulated data, this becomes especially important. A healthcare workload that creates, receives, maintains, or transmits electronic protected health information may require a HIPAA-compliant hosting model, a HIPAA Business Associate Agreement (BAA), strong access controls, audit-traceable administrative activity, encryption where required or risk-justified, and documented operational processes. The hosting environment matters, but so do the customer’s application controls, user access policies, data-handling procedures, risk assessments, and incident response processes.

This is where hybrid architecture can become extremely. Public cloud may suit stateless application tiers and rapid scaling. Dedicated infrastructure may suit latency-sensitive systems or workloads that need stronger isolation. [Managed private cloud](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/) or compliant hosting may suit regulated environments where operational accountability and audit evidence matter as much as raw compute capacity.

Remember, a more controlled environment can cost more and may not scale as elastically as a purely cloud-native model. That does not make it a bad decision. It means the cost is visible, planned, and linked to a real requirement. Discovering the same requirement after deployment usually costs far more.

## Strategic Hybrid Adoption Is Different From Tactical Hybrid Adoption

Most fragmented hybrid estates did not start with a bad strategy; instead, they grew through a series of reasonable short-term decisions. It’s a pattern we have seen several times, often caused by one team moving a web application to the cloud to meet a launch date. Another team wants to keep the database on dedicated infrastructure due to potential migration risks. A reporting workload was assigned elsewhere because that was the fastest way to solve an immediate problem. Each decision made sense in isolation. Together, they created an architecture that nobody fully owned.

That is tactical hybrid adoption. It solves local problems quickly, but it often creates larger operational problems later. Security controls vary by team. Logging standards drift. Costs become harder to predict. Data flows become harder to map. Audit evidence becomes a manual process rather than a normal output of the platform.

Strategic hybrid adoption works in the opposite direction. The organization defines placement criteria before workloads move. It agrees on which patterns are approved, which controls are mandatory, which teams own which decisions, and how success will be measured.

The model improves cost predictability by mapping workloads to known patterns. It improves compliance readiness by building audit requirements into the placement decision. It improves delivery speed because teams can choose from approved infrastructure patterns rather than reopening the same architectural debate for every project.

New technology can make teams faster, but security and compliance define the operating boundary. A workload that cannot meet its audit, access control, recovery, or data protection requirements is not ready for production, even if the platform looks attractive in terms of cost or speed.

## Centralize The Guardrails, Delegate The Execution

Hybrid governance works best when organizations separate guardrails from execution.

Some decisions should remain centralized because inconsistent choices create organizational risk. These include identity and access management, security architecture, compliance standards, data classification, audit logging, network segmentation, backup and retention requirements, key management, and approved infrastructure patterns.

Other decisions can sit closer to the application team. These include deployment configuration within an approved pattern, scaling thresholds, environment-specific tuning, service selection within a permitted tier, release timing, and operational refinements that do not weaken the control model.

Centralization does not have to mean every infrastructure request disappears into a slow approval queue. It means the major security, compliance, and operational questions have already been answered before the team starts building.

Good governance gives teams room to move without forcing them to reinvent the risk model each time. That is how hybrid architecture supports speed instead of fighting it.

## Hybrid Architecture Needs A Clear Owner

Hybrid environments expose a coordination problem that simpler infrastructure models can sometimes hide.

Application teams optimize for delivery speed. Finance teams optimize for cost control. Security teams optimize for risk reduction. Infrastructure teams optimize for stability. Business leaders optimize for customer outcomes. None of those priorities is wrong, but they can quickly conflict when a workload spans multiple environments, vendors, budgets, and operating models.

Without clear ownership, placement decisions follow the nearest budget or the loudest constraint. Performance problems fall between teams. Compliance evidence becomes a scramble because logging, retention, and reporting weren’t designed as a single requirement. Cost management becomes reactive because resources are spread across platforms without consistent tagging or accountability.

A hybrid architecture needs a named owner for the combined outcome. That owner may be a platform engineering function, an enterprise architecture group, a senior infrastructure leader, or another accountable team with the authority to resolve trade-offs.

Someone must own the balance among placement, cost, performance, security, compliance, and operations.

Ownership also has to extend beyond server uptime. A poorly placed workload may not first appear as a CPU alarm or a failed health check. It may show up as slow ERP processing, inconsistent customer records, late reports, poor user experience, or support tickets that are difficult to reproduce. Hybrid accountability has to reach the business process, not just the infrastructure layer.

## Preventing Hybrid From Becoming Fragmented Architecture

Fragmentation rarely comes from one big mistake. It usually comes from many small, local decisions that were never joined together. One team builds its own monitoring stack. Another uses a different backup method. A third document data flows in a wiki that no one else reads. A fourth creates cloud resources without consistent tagging. Over time, the organization has a hybrid estate, but not a coherent hybrid architecture.

The controls that prevent this are not complicated, but they do require discipline. Architecture review should happen before major placement decisions, not after a production issue. Approved deployment patterns should provide teams with a safe path to follow without having to design from scratch. Infrastructure as Code should define environments in version control so that teams can detect and correct drift. Data-flow documentation should show where each component runs, what data flows between systems, and which controls apply.

Logging and audit requirements need to span every tier. A cloud log that excludes the dedicated or managed hosting tier does not describe the system. It describes one part of it. Cost allocation and tagging should map resources to workloads, teams, and cost centers, making shadow infrastructure visible. RPO and RTO expectations should be defined before placement and tested regularly. Placement reviews should be scheduled because workloads, traffic patterns, regulations, and provider capabilities all change.

The goal is not perfect control. The goal is enough shared structure to make drift visible before it becomes technical debt.

## Hybrid Workflows Create New Performance And Consistency Questions

Hybrid architecture gives organizations flexibility, but it also introduces more variability. Latency, jitter, replication lag, and cross-tier dependencies can affect applications in ways that are harder to see than in a more centralized environment.

A record written to a production database may not appear immediately in an analytics replica. Two systems may temporarily see different states of the same data. An API request may depend on several internal services, with each hop adding response time and network overhead. An ERP-to-reporting process may run later than expected, competing with daytime traffic. CRM delays may appear as out-of-sequence records rather than obvious errors.

These are not reasons to avoid hybrid architecture. There are reasons to design for it properly.

Network paths between tiers should be treated as architecture requirements. Consistency models should match what the application and business process can tolerate. Monitoring should separate within-tier latency from cross-tier latency. Connectivity choices, routing, DNS dependencies, firewall ownership, VPNs, private links, and failover paths should be decided before production, not discovered during an incident.

Hybrid environments reward teams that think several steps ahead. They punish teams that treat connectivity and data flow as details.

## Observability And Audit Logs Are Mandatory, But Dashboards Are Not The Goal

Visibility across a hybrid estate is not optional. Without it, teams make decisions about placement, governance, and support without proper feedback.

A useful observability model needs metrics, logs, traces, and audit logs across the full environment. That includes public cloud, private cloud, dedicated infrastructure, managed hosting, and any other tier that supports the workload. If one part of the system falls outside the logging model, the organization has a blind spot.

The common mistake is confusing dashboards with visibility. A wall of green panels does not prove the environment is healthy, compliant, or resilient. It only proves that the dashboard is showing green.

Good observability answers practical questions. Is the system healthy? Are users receiving the expected service? Are controls working? Can the team investigate a security event? Can the organization produce audit evidence without manually rebuilding the story? Are alerts tied to service impact or only to raw resource utilization?

Granularity also matters. Too little data leaves teams blind. Too much unmanaged data creates noise. The right model gives teams enough detail to act without turning every dashboard into a distraction.

Atlantic.Net’s managed services can help organizations close this operational coverage gap, especially where internal teams need to extend monitoring, support, and operational control across compliant hosting, dedicated infrastructure, private cloud, and other hybrid tiers.

## A Practical Hybrid Governance Model

A useful governance model works at the workload level. Organization-level policies matter, but they often become too abstract. Workload-level governance forces specific decisions about data, placement, controls, ownership, and measurement.

## Classify The Workload And Data

Start by defining the workload’s purpose and the data it handles. Identify the sensitivity of the data, the compliance obligations, the availability requirements, the recovery targets, and the performance envelope.

A public marketing site, an internal reporting tool using anonymized data, and a patient-facing healthcare application do not belong in the same category. Classification determines which placement options are acceptable before the organization considers cost.

## Choose The Placement Pattern

Once the classification is clear, choose the environment that fits the workload. That may be public cloud, private cloud, dedicated bare metal, managed hosting, colocation, or a combination.

If elasticity matters most and the compliance profile is straightforward, a cloud tier may be the best fit. If isolation, predictable performance, or stronger operational control matter more, dedicated infrastructure or managed private cloud may make more sense. If the workload is regulated, the organization must validate the provider’s controls, contractual commitments, BAA terms (where applicable), and the shared-responsibility model.

Placement should follow the workload requirements. Please don’t start with platform preference.

## Define The Control Plane

The control plane defines how the workload will be secured, monitored, recovered, and audited. It should cover identity and access management, privileged access, MFA, network segmentation, encryption requirements, key management, secrets management, monitoring and alerting, backup frequency, retention, restore testing, incident response, and audit-log requirements.

These controls should exist before production. Adding them later usually means retrofitting security and compliance around decisions that were already made.

## Assign The Owner

Every workload needs a clear owner for placement, cost, performance, security coordination, compliance evidence, and business outcome. That owner does not need to operate every system directly, but they need the authority to resolve trade-offs when teams disagree.

Without ownership, governance becomes documentation. With ownership, it becomes decision-making.

## Measure The Outcome

Define success before go-live. Cost should sit within an agreed range. Response times should meet a defined envelope. Compliance evidence should be available within a known timeframe. Recovery targets should be tested, not assumed. Change velocity should be measured against a realistic baseline.

If the organization does not define success before deployment, it cannot properly evaluate the placement decision afterward.

## Review The Decision Regularly

Placement decisions should not be treated as permanent. Traffic changes. Regulations change. Cost models change. Provider services improve. Application dependencies shift.

A workload that once fit in one environment two years ago may now fit better elsewhere. Regular placement reviews help prevent yesterday’s correct decision from becoming tomorrow’s constraint.

## The Future Is Messy. Plan For It Anyway.

Enterprise technology will not become simpler. Workloads will keep diverging. Regulations will keep tightening. Teams will continue to push for faster delivery. Security, compliance, and operational control will continue to set the boundaries for what can safely reach production.

The wrong response is to keep the organization within a single, fixed infrastructure model that no longer aligns with how its applications operate. The better response is to plan properly, communicate clearly, and build a governance model that application, finance, security, infrastructure, and business teams can all support.

Hybrid architecture gives enterprises more options, but it also creates more ways for decisions to drift apart. That is the double-edged sword. It enables more flexible ways to build and run systems, but it also introduces new ways for systems to fail, fragment, or become difficult to govern.

We help organizations design and operate infrastructure where performance, compliance, and operational control must work together. For enterprises evaluating hybrid architecture, the first step is not choosing a platform. It is deciding where each workload belongs, who owns the outcome, and which controls need to be in place before it becomes fragmented.


---

# High Performance Servers

> URL: https://www.atlantic.net/high-performance-servers/ | Updated: 2026-09-16

Run sustained AI training, scientific computing, and data-intensive workloads on single-tenant bare metal with Intel Xeon or AMD EPYC processors, NVIDIA L40S or H100 NVL GPUs, ECC RAM, NVMe storage, and up to 25Gbps networking.

- Single-Tenant Bare Metal
- 0% CPU Steal Time
- 64 GB to 1 TB ECC RAM
- Full Root or Administrator Access

Maximum AMD EPYC Cores: 64

Network Upgrades: 25Gbps

## High Performance Servers

Standard servers handle standard workloads. When you are training deep learning models, running computational simulations, or processing massive datasets in real time, you need hardware built specifically for the task. Atlantic.Net high-performance servers deliver raw compute power on bare metal: no hypervisor overhead, no shared resources, no performance compromises. Workloads run at the hardware's full rated throughput from the first request to the last.

Choose from Intel Xeon and AMD EPYC processors, NVIDIA GPU configurations, NVMe SSD storage, and up to 25Gbps networking, all housed in Atlantic.Net's SOC 2 Type II, HIPAA, and PCI-DSS audited data centers.

## What Makes a High-Performance Server?

High-performance computing requires every component to be optimized for sustained, intensive workloads. A general-purpose server bottlenecks on CPU single-thread limits, slow storage I/O, or memory bandwidth constraints. Atlantic.Net high-performance servers are configured to eliminate these bottlenecks across every layer of the stack.

### Processor

AMD EPYC processors with up to 64 cores and 128 threads per socket deliver the parallelism that HPC and AI workloads depend on. Intel Xeon Scalable processors are well-suited for workloads that require high clock speed and strong single-thread performance.

### Memory

ECC (Error-Correcting Code) RAM, available in configurations from 64GB to 1TB, detects and corrects memory errors automatically. In AI training, genomics, and financial modeling, a single silent memory error corrupts results. ECC prevents this.

### Storage

NVMe SSD drives reduce I/O bottlenecks with sub-millisecond read/write latency. For sequential throughput, including reading large model checkpoints and writing simulation outputs, NVMe is the difference between a bottleneck and a fast path. SATA drives are available for cost-effective bulk storage capacity alongside NVMe high-performance storage.

### GPU Acceleration

NVIDIA L40S and H100 NVL GPUs, available through Atlantic.Net as an official NVIDIA Partner Network Cloud Partner, provide the parallel compute required for deep learning, inference, rendering, and GPU-accelerated scientific applications.

### Network

1 Gbps as standard, upgradeable to 10 Gbps or 25 Gbps. High-bandwidth ports matter for HPC clusters transferring large datasets between nodes, distributed training runs, and high-throughput data pipelines.

### Bare Metal Access

Every Atlantic.Net high-performance server is a physical, single-tenant machine. No hypervisor. No virtualization layer between your workload and the hardware. CPU steal time is 0%. Storage IOPS are yours entirely. This is what "dedicated" means.

## High Performance Computing Solutions from Atlantic.Net

### AI Training and Deep Learning

Atlantic.Net GPU servers with NVIDIA L40S (48GB GDDR6, 91.6 TFLOPS FP32) and NVIDIA H100 NVL (94GB HBM3, 3.9TB/s memory bandwidth) support large-scale model training. Fine-tune foundation models, train convolutional neural networks, and run distributed training jobs across multi-GPU configurations. Atlantic.Net is an official NVIDIA Partner Network Cloud Partner, with GPU instances available from $1,121/Month.

### HPC and Scientific Computing

High-performance computing (HPC) applications, including computational fluid dynamics, climate modeling, genomics, seismic analysis, and finite element analysis, require sustained parallel computing for hours or days. AMD EPYC dedicated servers with 64 cores and 128 threads handle multi-threaded simulation software without resource contention. Long-running jobs complete on schedule.

### AI Inference and Real-Time Analytics

Deploy trained models for live prediction workloads. GPU-accelerated inference with NVIDIA L40S supports real-time object detection, recommendation engines, and natural language processing at scale. Low-latency bare-metal access keeps inference response times within the milliseconds required by production applications.

### Big Data and Data-Intensive Workloads

Process petabyte-scale datasets on servers with high memory bandwidth and NVMe storage. Distributed analytics frameworks, including Apache Spark and Hadoop, run faster on dedicated hardware with consistent I/O performance and no multi-tenant storage contention.

### AI HPC Infrastructure for Regulated Industries

Atlantic.Net's audited compliance certifications (SOC 2 Type II, HIPAA, HITECH, PCI-DSS, and NIST 800-53) apply to GPU- and high-performance dedicated servers. Run AI workloads on healthcare data, financial records, or government datasets within a certified compliance environment. Atlantic.Net signs Business Associate Agreements for healthcare customers.

## Atlantic.Net High Performance Server Specifications

| Component | Configuration |
| --- | --- |
| CPU | Intel Xeon (6 to 36 cores), AMD EPYC 7702P (64 cores / 128 threads) |
| RAM | 64 GB to 1 TB ECC DDR4 |
| Storage | NVMe SSD (up to 3.84 TB per drive), SATA SSD, or HDD |
| GPU | NVIDIA L40S (48 GB), NVIDIA H100 NVL (94 GB) |
| Network | 1 Gbps standard, with 10 Gbps or 25 Gbps upgrades available |
| Bandwidth | 20 TB included, with unmetered options available |
| Tenancy | Single-tenant bare metal |
| Root access | Full root or administrator access |
| Setup fee | None |
| Starting price | Dedicated servers from $139/mo; GPU servers from $1,121/mo |

## High Performance Servers vs. Cloud Compute for AI and HPC Systems

| Feature | Atlantic.Net Bare Metal | Public Cloud GPU | Shared Cloud VPS |
| --- | --- | --- | --- |
| CPU steal time | 0% | Variable | High |
| GPU access | Dedicated NVIDIA L40S or H100 | Shared or dedicated | None |
| Storage I/O | Dedicated NVMe IOPS | Shared, throttled | Shared |
| Latency | Deterministic | Variable | Variable |
| Compliance | SOC 2, HIPAA, and PCI DSS audited | Varies by service | Typically none |
| Pricing | Fixed monthly | Metered, potentially unpredictable | Fixed, lower spec |
| Best for | Sustained HPC, AI training, and deep learning | Burst GPU workloads | General workloads |

Cloud providers meter GPU usage and charge for storage I/O, data egress, and inter-region transfers. For sustained workloads, including AI training runs that take days and simulation jobs that run continuously, bare-metal at a fixed monthly price is significantly cheaper than metered cloud NVIDIA GPUs. Atlantic.Net's flat-rate pricing includes bandwidth. There are no egress surprises.

## Who Uses Atlantic.Net High Performance Servers

### Artificial Intelligence and Machine Learning teams

training, fine-tuning, and deploying large language models and computer vision systems

### HPC researchers

running computational fluid dynamics, climate models, genomic analysis, and finite element simulations

### Financial services

running Monte Carlo simulations, risk modeling, and algorithmic trading systems requiring ECC memory and PCI-DSS compliance

### Healthcare and life sciences

processing medical imaging, genomic data, and clinical trial datasets within HIPAA-certified infrastructure

### Media and VFX studios

rendering 3D animation, compositing, and GPU-accelerated visual effects pipelines

### Government and defense

are deploying AI and analytics on NIST 800-53 and SOC 2-certified infrastructure

### Independent software vendors

building GPU-accelerated product features on certified infrastructure without investing in on-premises hardware

## Frequently Asked Questions

### What is a high-performance server?

A high-performance server is a physical machine configured for compute-intensive, data-intensive, or latency-sensitive workloads that standard servers cannot handle reliably. It typically includes multi-core enterprise processors (Intel Xeon or AMD EPYC), large ECC RAM configurations, NVMe SSD storage for fast I/O, and high-bandwidth network ports. GPU-equipped high-performance servers add parallel compute acceleration for AI training, deep learning, and scientific simulation. Atlantic.Net high-performance servers are bare metal: single-tenant, no hypervisor, giving your workloads direct, unshared access to every hardware resource.

### How does bare metal differ from a cloud GPU instance for AI training?

A bare metal server gives you exclusive, non-virtualized access to the physical hardware. A cloud GPU instance shares underlying infrastructure with other tenants, introducing variable CPU performance, storage I/O limits, and network jitter. For AI training runs that last hours or days, bare metal provides consistent throughput from start to finish. Cloud GPU instances are well-suited for bursty workloads or experimentation. For production training, the predictability and fixed cost of bare metal typically outperforms metered cloud compute both in performance and total cost.

### What GPU options does Atlantic.Net offer?

Atlantic.Net is an official NVIDIA Partner Network Cloud Partner and offers NVIDIA L40S and NVIDIA H100 NVL GPU configurations. The L40S (48GB GDDR6, 91.6 TFLOPS FP32) suits inference, rendering, and mid-scale AI training. The H100 NVL (94GB HBM3, 3.9TB/s bandwidth) is designed for large-scale deep learning, foundation model training, and scientific HPC solutions. Multi-GPU configurations are available up to 8x H100 NVL per server.

### Can I run HPC applications on Atlantic.Net servers?

Yes. Atlantic.Net Supermicro dedicated servers with AMD EPYC (64 cores/128 threads) and large ECC RAM configurations run HPC software such as ANSYS, OpenFOAM, GROMACS, NAMD, and custom simulation stacks. Full root access means you install and configure the software environment exactly as required. There are no restrictions on which HPC frameworks, MPI libraries, or job schedulers you deploy.

### Does Atlantic.Net offer compliance-certified GPU and HPC hosting?

Yes. This is a significant differentiator. All Atlantic.Net data centers, including those hosting GPU and high-performance dedicated servers, carry SOC 2 Type II, SOC 3 Type II, HIPAA AT-C 105 and 205, HITECH, PCI-DSS, and NIST 800-53 certifications, all of which are independently audited. Healthcare organizations running AI on patient data, financial services firms running quantitative models, and government contractors deploying AI infrastructure can all operate within a certified compliance environment. Atlantic.Net signs Business Associate Agreements for healthcare customers.

### What support is available for high-performance server customers?

Atlantic.Net provides 24/7/365 US-based phone and email support. For high-performance and GPU server customers, our engineers can assist with hardware configuration, NVIDIA driver installation, GPU health monitoring, storage tuning, and networking setup. Optional managed services extend this to proactive monitoring, OS management, and disaster recovery configuration.

## Cloud Availability in Multiple Global Regions

Deploy close to your users from eight international data centers worldwide, with new regions on the way.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# High Availability Bare Metal Architectures and Deployment Guide in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/high-availability-bare-metal-infrastructure/ | Published: 2026-05-29 | Author: Dr. Assad Abbas

High availability has become an important consideration in bare metal infrastructure design in 2026. Modern organizations deploy bare metal environments for Artificial Intelligence (AI) workloads, analytics platforms, healthcare systems, financial services, and other business-critical applications that require continuous availability and predictable performance.

These environments require stable resource allocation and direct access to hardware resources. [Bare-metal](https://www.atlantic.net/dedicated-server-hosting/what-is-a-bare-metal-server-benefits-use-cases-and-best-practices/) infrastructure can help meet these requirements when paired with appropriate HA, monitoring, and recovery architecture. Many providers position bare metal for performance-sensitive workloads such as AI, analytics, databases, and regulated environments.

Dedicated hardware alone is not sufficient for high availability in bare metal environments. Service availability also requires infrastructure components and recovery mechanisms that support continuous operations during failures. Therefore, architecture design, redundancy planning, networking, failover mechanisms, disaster recovery preparation, and operational visibility collectively influence reliability and recovery capability.

This article discusses the architectures, operational considerations, and deployment practices for building reliable bare metal environments in 2026.

## Bare Metal Infrastructure for High Availability

Bare metal servers are physical machines dedicated to a single tenant. In this model, all hardware resources belong to one organization. Therefore, applications access compute, storage, and network resources directly without sharing them with other workloads.

This approach differs from shared and virtualized environments, where resources may be distributed across multiple users through virtualization layers. On the other hand, bare metal infrastructure removes that additional layer. Applications communicate directly with hardware resources, resulting in more predictable resource utilization.

This direct access also improves workload consistency. Since resources are not shared across tenants in bare metal environments, applications avoid [noisy neighbor](https://www.techtarget.com/searchcloudcomputing/definition/noisy-neighbor-cloud-computing-performance) effects and receive stable CPU allocation and predictable memory access. Similarly, direct access to storage devices improves the consistency of throughput.

In addition, the absence of hypervisor overhead in the bare-metal model further improves. Instead, applications communicate directly with processors, GPUs, NVMe storage devices, and other hardware accelerators. Therefore, latency and performance consistency can improve for suitable workloads, but the results depend on hardware, software, storage, and network design.

Bare-metal servers are often compared with dedicated servers because both provide single-tenant environments and workload isolation. Modern bare metal environments commonly integrate with APIs, provisioning workflows, and orchestration platforms. In contrast, dedicated servers traditionally focus more on long-term hardware allocation and managed hosting.

This distinction becomes increasingly important in modern infrastructure environments as operations teams increasingly automate provisioning, monitoring, and lifecycle management. Therefore, API-driven bare metal infrastructure often integrates more effectively with these environments and supports workloads that require continuous availability, stable performance, and greater operational control. Such workloads commonly include AI workloads, analytics platforms, large databases, healthcare systems processing [electronic Protected Health Information (ePHI)](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/), high-performance computing applications, and latency-sensitive financial systems.

## Designing High Availability Bare Metal Architectures

High-availability architecture requires careful planning because service continuity depends on the infrastructure design rather than hardware alone. Therefore, availability models, redundancy mechanisms, component placement, and recovery paths collectively influence resilience and fault isolation in bare metal environments. The following architectural approaches support these design objectives and improve availability in bare metal deployments.

### Architectural Models for High Availability

High-availability architecture begins with selecting an appropriate deployment model, as this decision influences redundancy, workload distribution, and recovery behavior. Bare metal environments commonly use [*Active-Active* and *Active-Passive*](https://www.geeksforgeeks.org/system-design/active-passive-active-active-architecture-for-high-availability-system/) architectures, depending on workload requirements and availability objectives.

*Active-Active* architecture distributes workloads across multiple nodes simultaneously. Therefore, services continue to operate even when a node becomes unavailable. In addition, workload demand remains distributed across available resources, which improves service continuity and resource utilization.

In contrast, *Active-Passive* architecture separates production and recovery resources. Primary nodes process workloads during normal operations, whereas standby nodes remain available for failover. Workloads move toward secondary systems during failures, and services resume operation.

These deployment models are commonly supported by cluster-based architectures, where multiple nodes cooperate to distribute services across the infrastructure. Similarly, fault domain separation improves resilience by distributing compute resources, storage systems, and networking components across independent racks, power zones, and network segments. Failures affecting one domain have less impact on the environment.

### Control Plane and Data Plane Architecture Design

Separation of the control plane and data plane is an important architectural design decision in high-availability environments because failures in management services should not interrupt workload execution.

The control plane manages orchestration, scheduling, configuration management, and infrastructure coordination activities. Therefore, its availability directly affects platform operations. Organizations commonly distribute control plane services across multiple management nodes to ensure infrastructure coordination continues even when a node becomes unavailable. [Quorum-based mechanisms](https://dev.to/jaiminbariya/understanding-quorum-based-approaches-in-distributed-systems-jaimin-bariya-5h1b) further improve resilience because cluster decisions require agreement among several nodes. , split-brain conditions become less likely, and the platform state remains consistent during failures. Distributed coordination stores such as *etcd* commonly support these functions in clustered environments.

Similarly, the data plane should be designed with redundancy, as it directly supports workload execution and service delivery. Applications should operate across multiple nodes and independent failure domains whenever possible, so that workloads continue running on healthy systems during failures. Replication mechanisms further resilience by distributing data across multiple systems or storage environments. Likewise, load balancing improves availability by automatically redirecting traffic toward healthy nodes and available services.

### Recovery Architecture and Automated Failover Design

Recovery architecture should be planned during system design because recovery capability directly influences availability objectives. Therefore, high-availability environments commonly combine monitoring systems, automated failover mechanisms, and recovery workflows to reduce service interruption.

Recovery usually begins with fault detection. Health monitoring systems observe infrastructure status, including CPU activity, memory utilization, storage behavior, application health, and network availability. Similarly, heartbeat mechanisms improve fault detection by enabling infrastructure nodes to continuously exchange operational information.

After failures are detected, automated workflows initiate recovery procedures. Applications may restart on healthy nodes, while workloads and storage services may move toward replicated environments. Network recovery mechanisms also support failover operations. For example, [Border Gateway Protocol (BGP)](https://aws.amazon.com/what-is/border-gateway-protocol/) may redirect traffic to available paths, whereas DNS-based failover may direct requests to secondary environments.

Therefore, automated recovery architecture reduces downtime and improves service continuity because recovery begins immediately after fault detection.

Table 1: High Availability Architecture Components and Their Roles in Bare Metal Environments

| **Architecture Component** | **Purpose** | **Availability Contribution** |
| --- | --- | --- |
| Active-Active Architecture | Distributes workloads across multiple active nodes | Maintains service continuity during node failures |
| Active-Passive Architecture | Uses standby resources for recovery | Simplifies failover and recovery workflows |
| Cluster-Based Deployment | Distributes services across cooperating nodes | Reduces dependency on individual servers |
| Control Plane Redundancy | Replicates management and orchestration services | Maintains infrastructure coordination during failures |
| Data Plane Redundancy | Distributes workloads and data services | Improves workload continuity |
| Replication Mechanisms | Maintains synchronized data copies | Improves recovery capability |
| Load Balancing | Distributes traffic across nodes | Reduces dependency on individual systems |
| Automated Failover | Initiates recovery automatically | Reduces downtime |
| Fault Domain Separation | Isolates infrastructure components across domains | Limits failure impact |

## Physical Infrastructure and Network Architecture for High Availability

High-availability architecture also depends on the physical and network design, as logical redundancy alone cannot eliminate infrastructure failures. Therefore, workloads should be distributed across independent racks, power zones, and network segments to improve fault isolation and reduce the impact of localized failures.

Similarly, modern bare metal environments commonly use a [spine-leaf architecture](https://www.hpe.com/us/en/what-is/spine-leaf-architecture.html) because it provides predictable network paths and supports resilient east-west communication between systems. Multi-site deployments further improve availability by distributing services across geographically dispersed environments, while cross-site replication improves recovery readiness in the event of failures.

Power and network redundancy are equally important for service continuity. Organizations commonly deploy dual power feeds, UPS systems, backup generators, redundant switches, and multiple uplinks to reduce dependency on individual components.

Networking architecture also contributes to availability through mechanisms such as Border Gateway Protocol (BGP), Bidirectional Forwarding Detection (BFD), and Equal Cost Multipath (ECMP), which improve route availability, failure detection, and traffic resilience. Similarly, load-balancing mechanisms such as MetalLB and FRRouting (FRR) distribute traffic across available nodes and maintain service continuity in bare-metal environments.

## Disaster Recovery Strategies for Bare Metal Infrastructure

Disaster recovery planning supports high availability by preparing infrastructure for major failures and recovery events. Recovery architecture is commonly designed around Recovery Time Objective (RTO) and Recovery Point Objective (RPO). RTO defines acceptable downtime duration, whereas RPO defines acceptable data loss. Organizations use these targets when designing recovery environments because they directly influence recovery capability.

Common disaster recovery strategies include:

- **Recovery runbooks** to document recovery procedures, responsibilities, and incident response actions.
- **Offsite backups** to maintain data copies outside primary environments and reduce data loss risk.
- **Remote replication** to synchronize data across recovery sites and improve recovery readiness.
- **Failover environments** to support service restoration when primary systems become unavailable.
- **Active-Passive recovery sites** to maintain standby infrastructure for disaster recovery operations.
- **Cross-site replication** to maintain data availability across geographically separated environments.

Recovery plans also require validation because untested procedures may not perform as expected during incidents. Therefore, regular testing improves operational readiness and service continuity.

## Deployment Operations and Availability Management

Deployment operations support high availability because infrastructure consistency directly affects service reliability. Therefore, organizations commonly automate provisioning and lifecycle management in bare-metal environments. [Preboot Execution Environments (PXE)](https://heimdalsecurity.com/blog/what-is-pxe-boot/) provisioning automates operating system deployment across server fleets and reduces manual configuration effort. Similarly, standardized images improve deployment consistency by enabling systems to use uniform configurations. Infrastructure—as—Code (IaC) tools further support lifecycle management by automating configuration updates and infrastructure changes. Deployment processes become more consistent, and operational errors decrease.

Deployment consistency alone is insufficient; high-availability environments also require continuous operational visibility. Therefore, organizations implement monitoring and observability mechanisms to track infrastructure behavior and service status. This visibility commonly depends on infrastructure telemetry collected across compute, storage, and network layers. At the host level, telemetry includes CPU utilization, memory activity, storage behavior, and hardware status, whereas network telemetry provides visibility into traffic flow and connectivity. Synthetic health checks further improve observability by evaluating service availability from the user’s perspective. Monitoring data also supports capacity planning and infrastructure scaling decisions.

## High Availability Bare Metal Deployment Checklist

Before deploying a high-availability bare metal environment, organizations should verify that the infrastructure, redundancy mechanisms, and recovery processes are properly configured. This step helps reduce risk and improve system reliability. The following checklist supports deployment readiness and operational stability:

- Validate infrastructure inventory, resource allocation, and capacity requirements
- Design redundant compute, storage, and network architecture
- Configure monitoring, telemetry, and observability mechanisms
- Implement failover workflows and automated recovery processes
- Configure backup, replication, and disaster recovery strategies
- Verify control plane and data plane redundancy
- Test failover procedures and recovery operations
- Validate network resilience and traffic continuity mechanisms

This checklist helps organizations confirm deployment readiness. It supports service continuity before the production rollout.

## High Availability Bare Metal Deployments with Atlantic.Net

Organizations implementing high-availability bare metal environments often require infrastructure that supports redundancy planning, operational visibility, and reliable service delivery. In this context, [Atlantic.Net](http://www.atlantic.net) offers bare-metal servers and cloud infrastructure options for workloads requiring dedicated hardware and operational control.

Its bare-metal servers provide single-tenant physical infrastructure with direct hardware access, whereas managed load-balancing services can support traffic distribution and high-availability deployments. Similarly, the platform may support hybrid deployment architectures in which bare metal infrastructure operates alongside cloud resources or secondary recovery environments, depending on workload, recovery, and availability requirements.

## The Bottom Line

Building high-availability bare metal environments requires coordination across architecture, networking, recovery planning, and operations. Availability depends not only on redundancy mechanisms but also on how infrastructure components, workloads, and recovery processes are designed and managed together.

Effective deployments combine fault-tolerant architectures, resilient networking, automated failover, disaster recovery planning, and continuous observability to reduce service interruption and improve recovery capability. Similarly, deployment consistency and operational visibility improve long-term reliability as infrastructure environments grow.

Organizations deploying performance-sensitive, business-critical workloads should evaluate availability as an end-to-end design objective. This approach helps create reliable, scalable bare metal environments that maintain service continuity in modern infrastructure operations.


---

# DDoS Protected Dedicated Servers Built to Stay Online

> URL: https://www.atlantic.net/ddos-protected-servers/ | Updated: 2026-09-16

Add optional managed, network-level DDoS mitigation that analyzes, filters, and scrubs malicious traffic before it reaches your dedicated server, while legitimate users stay connected.

- Upstream Traffic Filtering
- Full Root Access
- 100% Uptime SLA
- 24/7/365 SOC Monitoring

Uptime SLA: 100%

SOC Monitoring: 24/7/365

## Add Managed DDoS Mitigation to Your Dedicated Server Environment

A distributed denial-of-service attack doesn’t announce itself. One moment, your site is running; the next, your server is buried under millions of requests from thousands of hijacked machines, and your customers are staring at a timeout error. Every minute offline means lost revenue, lost trust, and a brand reputation taking damage in real time. DDoS protection provides critical benefits for businesses by helping maintain uptime, reduce slow performance, and keep online services accessible during attacks.

Atlantic.Net offers DDoS protection for dedicated servers as an optional managed service. When added to your dedicated server environment, DDoS protection helps filter malicious traffic before it reaches your infrastructure, allowing legitimate users to stay connected while your business remains online.

Dedicated servers do not include DDoS protection by default. The service requires additional setup and configuration, allowing Atlantic.Net to align mitigation with your server environment, traffic profile, and security requirements.

## What Is a DDoS Attack and Why Does It Matter?

A distributed denial-of-service (DDoS) attack floods your server or network with traffic it cannot process. Unlike a hack, the goal isn’t to steal data. It’s to make your services unavailable to customers, partners, and your own team.

DDoS protection refers to the set of security measures designed to identify and filter out malicious traffic, defending your infrastructure against these attacks and helping maintain service availability.

Attackers rent botnets made up of thousands of compromised machines and direct them at a single target. The traffic volume overwhelms the server’s resources: bandwidth saturates, CPU spikes, connections queue up and time out, and the site goes down. This is a volumetric attack.

More sophisticated attacks go after specific weaknesses in application layers, connection state tables, or DNS resolution. These attacks may be smaller in volume but harder to distinguish from legitimate traffic.

Any online service can be a target, but some are particularly vulnerable to DDoS attacks:

- E-commerce websites during peak sales periods, where downtime costs thousands per minute
- Game servers, where even brief outages push players to competitors
- Financial services platforms, sometimes attacked to mask fraud or cause market disruption
- SaaS applications are relied on by business customers with their own SLAs to meet
- Healthcare and critical infrastructure, where service availability is non-negotiable

## How DDoS Protection Works

Effective DDoS protection intercepts malicious traffic before it reaches your server. Dedicated DDoS protection solutions are essential for mitigating large-scale attacks, especially as threats become more sophisticated. For customers who add the managed DDoS protection service to their dedicated server environment, Atlantic.Net can configure network-level mitigation designed to help identify, filter, and absorb malicious traffic before it impacts the server.

### Traffic Analysis

All incoming traffic passes through monitoring systems that analyze packets in real time. Normal traffic patterns are established as a baseline. Detection and analysis of traffic anomalies are conducted using behavioral analysis and AI-driven algorithms. When traffic deviates from this baseline, sudden spikes, unusual source distributions, protocol anomalies, the system flags it.

### Traffic Filtering

Malicious traffic is identified and filtered at the network level. Rate limiting drops requests from suspicious sources. Comprehensive Packet Inspection analyzes incoming network traffic, inspecting each data packet for malicious characteristics. Packet inspection separates legitimate requests from volumetric floods. Only clean traffic reaches your server.

### Scrubbing Centers

During a large-scale attack, traffic is rerouted through scrubbing centers, where it is inspected in bulk. Global Anycast routing distributes incoming traffic across multiple data centers, limiting the impact of large scale attacks. Malicious packets are dropped. Legitimate traffic is forwarded to your server with minimal added latency.

### Machine Learning and Pattern Recognition

Atlantic.Net’s protection systems learn from attack patterns over time. Advanced DDoS mitigation systems employ AI and machine learning to differentiate between legitimate traffic and bots. Emerging attack signatures are incorporated into filtering rules. The system adapts as attackers change tactics, maintaining protection against sophisticated DDoS attacks without requiring manual intervention.

The result: your server sees legitimate traffic. Attackers see their requests going nowhere, thanks to robust measures for mitigating attacks and continuous monitoring for suspicious activity.

## Managed DDoS Protection Features for Dedicated Servers

### Always-On Protection, No Configuration Required

DDoS protection is available as an optional managed service for Atlantic.Net dedicated servers. It is not enabled by default and requires additional setup so traffic routing, mitigation policies, and response procedures are aligned with your environment. Once configured, the service can provide continuous monitoring and mitigation support when suspicious or attack-level traffic is detected.

### Network-Level Mitigation

When the managed DDoS protection service is added to your dedicated server, mitigation operates upstream of the server. Malicious traffic can be identified and filtered before it consumes server CPU, memory, or bandwidth. This helps your server continue serving legitimate users during an attack instead of being overwhelmed by unwanted traffic.

### Free CDN Integration

Atlantic.Net's managed services include Content Delivery Network (CDN) options that distribute your traffic across multiple points of presence. Distributing traffic across a global network reduces the attack surface for volumetric floods while simultaneously improving load times for legitimate users. DDoS protection and performance optimization work together.

### Full Control Over Your Server

DDoS protection runs transparently at the network edge. It does not change how you access or manage your dedicated server. You retain full root access, complete control over your operating system and software stack, and the same management interfaces you use every day.

### Managed Firewall and IDS Options

For businesses that need a more comprehensive security posture, Atlantic.Net offers managed firewall configuration and Intrusion Detection System (IDS) services as add-ons to DDoS-protected dedicated servers. These services layer application-level filtering and anomaly detection on top of the network-level DDoS mitigation.

### 24/7/365 Security Operations Center Monitoring

Atlantic.Net's security team monitors infrastructure around the clock. During an active DDoS attack, our engineers can escalate mitigation, adjust filtering rules, and communicate status directly with your team. You are not left watching dashboards alone while attackers drain your uptime.

### 100% Uptime SLA

Atlantic.Net guarantees 100% uptime on the network, hardware, and infrastructure. Our DDoS protection is part of this commitment. An attack on your server does not void your SLA. If our network-level protection fails to keep your services available during an attack, the SLA applies.

### Audited Compliance Certifications

Atlantic.Net data centers are independently audited for SOC 2 Type II, SOC 3 Type II, HIPAA, HITECH, PCI-DSS, and NIST 800-53. DDoS protection is part of a security infrastructure that meets these standards, not bolted on afterward. For businesses in regulated industries, this means your server's security posture can be cited in audit documentation.

## Why DDoS Protection Matters for Your Business

### Financial Losses

Every minute of downtime costs money. E-commerce sites lose sales. SaaS platforms face SLA penalties. Internal tools taken offline cost employee productivity. The average DDoS attack lasts between hours and days. Recovery costs, engineering time, emergency support, lost contracts, add up beyond the direct revenue impact.

### Customer Trust

Customers notice when your service goes down. Repeat outages erode confidence in your platform. A DDoS attack that takes your site offline during a product launch, a sales peak, or a critical client demonstration is damage that survives well beyond the attack itself. DDoS protection guards the reputation your business has spent years building.

### Business Continuity

Businesses with DDoS-protected infrastructure maintain service continuity when competitors on unprotected hosting go dark. For services with regulatory uptime requirements, such as healthcare platforms, financial services, and critical infrastructure, continuity is not optional. It is a contractual and compliance obligation.

### Staying Ahead of Attackers

DDoS attacks are growing in scale and sophistication. Attack volumes measured in terabits per second are now documented in public threat reports. Attacks increasingly combine volumetric floods with application-layer techniques to bypass basic protection. Protecting your server today means investing in a system that keeps pace with how attacks evolve.

## Who Needs DDoS-Protected Dedicated Servers

| Business Type | DDoS Risk | Why Protection Matters |
| --- | --- | --- |
| E-commerce | High, targeted during peak sales | Downtime during sales events means direct, measurable revenue loss. |
| Gaming platforms | Very high, frequently targeted | Players abandon servers that drop, and competitors benefit immediately. |
| Financial services | High, targeted for disruption and fraud concealment | Regulatory uptime requirements apply, and attacks may be used to mask fraudulent activity. |
| Healthcare platforms | High, critical service availability required | Patient safety and HIPAA compliance require continuous uptime. |
| SaaS applications | Medium-high, any paying customer SLA is at risk | SLA penalties and customer churn can follow repeated outages. |
| Media and content | Medium, traffic spikes can mask attacks | CDN and DDoS protection work together to handle both legitimate traffic surges and malicious attacks. |

## Frequently Asked Questions

### What is DDoS protection?

DDoS protection systems identify and filter malicious traffic during a distributed denial-of-service (DDoS) attack, keeping your server and services accessible to legitimate users. A DDoS attack floods a server or network with traffic from thousands of sources, usually compromised machines in a botnet, to exhaust its resources and make it unavailable. DDoS protection intercepts this traffic at the network edge, before it reaches your server, using traffic analysis, rate limiting, packet inspection, and scrubbing to separate attack traffic from genuine requests.

### Do I need DDoS protection if I already have a firewall?

A firewall manages access rules and blocks known threats, but it sits on or near your server and processes traffic that has already consumed your network bandwidth. During a volumetric DDoS attack, the attack traffic saturates your connection before a firewall can inspect it. DDoS protection operates upstream, at the network edge, intercepting malicious traffic before it ever reaches your server or consumes your bandwidth. Firewall and DDoS protection serve different functions and work best together.

### How does DDoS protection affect my server's performance during normal operation?

Atlantic.Net's DDoS protection operates at the network edge and does not add measurable latency to normal traffic. Monitoring and analysis happen in real time at the infrastructure level, transparent to your applications and users. During a detected attack, some legitimate traffic may experience minor additional processing time while scrubbing is active, but the alternative, no protection, results in total service unavailability.

### What types of DDoS attacks does Atlantic.Net's protection cover?

Atlantic.Net's network-level DDoS protection covers volumetric attacks, such as UDP floods, ICMP floods, and similar bandwidth-saturating techniques, as well as protocol attacks that target connection-state exhaustion. For application-layer attacks (HTTP floods, slow-rate attacks), managed firewall and WAF add-on services provide additional coverage. Contact the support team to discuss the protection profile best suited to your specific threat landscape.

### Can a dedicated server protect itself from DDoS without external protection?

A standard dedicated server cannot effectively defend against large-scale DDoS attacks on its own. The attack traffic overwhelms the server's network connection before any on-server software can process or block it. Effective DDoS mitigation requires network-level intervention upstream of the server, at the data center or ISP level, with the capacity to absorb and filter attack volumes measured in gigabits or terabits per second.

### Is DDoS protection included in my dedicated server plan, or is it an add-on?

Atlantic.Net includes basic DDoS protection across all dedicated server plans as part of our network infrastructure. Advanced DDoS protection with enhanced mitigation capacity, managed firewall integration, and IDS is available as a managed services add-on. Contact the sales team to discuss the right protection level for your workload and threat exposure.

### What should I do if my server is actively under a DDoS attack?

Contact Atlantic.Net technical support immediately at +1-866-618-3282. Our support team is available 24/7/365 by phone and email. Provide your server IP address and describe what you are observing. Our engineers will assess the attack, escalate mitigation as needed, and keep you informed throughout. If you have managed services, your account team will proactively notify you when our systems detect unusual traffic patterns.

## Cloud Availability in Multiple Global Regions

Deploy close to your users from eight international data centers worldwide, with new regions on the way.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Healthcare Organizations Hosting: Guide to HIPAA-Compliant Cloud Providers

> URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-cloud-hosting-healthcare/ | Published: 2026-05-30 | Updated: 2026-06-24 | Author: Robert Agar

U.S. covered entities and business associates that create, receive, maintain, or transmit PHI/ePHI must comply with applicable Health Insurance Portability and Accountability Act (HIPAA). Companies must maintain a secure infrastructure to meet [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/what-is-a-hipaa-certification/) requirements and protect patient health information. One of the most effective ways for organizations to safeguard patient data is with a HIPAA-compliant cloud hosting solution.

This article examines the essential features that HIPAA-compliant hosting providers must offer healthcare organizations to help them meet [HIPAA guidelines](https://www.atlantic.net/hipaa-compliant-hosting/what-are-hipaa-compliance-rules-and-guidelines/). This information is essential for IT decision-makers and compliance teams who are selecting a provider for a secure web hosting solution.

## Quick Overview: HIPAA-compliant Cloud For Healthcare Organizations

The [HIPAA Security Rule](https://www.atlantic.net/hipaa-compliant-hosting/what-is-the-hipaa-security-rule-safeguard-checklist/) specifically addresses safeguarding electronic [protected health information](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) (ePHI). The rule defines how ePHI must be secured, who can access it, and how it can be shared. An organization that chooses a cloud hosting solution must ensure that it supports [HIPAA compliance](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliance-in-the-age-of-ai/).

Unfortunately, there is no official HIPAA compliance program that allows providers to demonstrate compliance with HIPAA regulations. Hosting providers must demonstrate compliance with the guidelines through third-party security reviews and compliance audits. Prospective customers must evaluate cloud hosting vendors to ensure they provide the security and data protection required by HIPAA.

Healthcare organizations that process ePHI are considered covered entities (CEs) under HIPAA. Their cloud hosting provider and other third parties that interact with patient data are referred to as business associates (BAs). Both the CE and their BAs share responsibility for protecting ePHI and must comply with HIPAA rules.

## Healthcare Providers: Who Needs HIPAA Hosting

All CEs, ranging from large hospital networks to digital health startups, need [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) or must process the protected health information in secure on-premises data centers. While larger organizations may be able to support a dedicated data center, smaller companies, such as clinics and doctors’ offices, can efficiently meet HIPAA compliance requirements through a cloud hosting provider.

Third-party SaaS vendors and billing services that handle ePHI for covered entities are BAs and must also use HIPAA-compliant hosting solutions. Covered entities must ensure HIPAA compliance by all companies involved in processing or storing their sensitive patient data. CEs formalize third-party compliance by entering into a HIPAA [Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/) with their vendors.

## BAA (BAA): Verify Before You Sign

Customers subject to HIPAA compliance must obtain a signed BAA from their hosting provider. A signed BAA is a core HIPAA requirement. Decision-makers should immediately walk away from providers that will not sign a BAA.

IT and compliance teams should closely review the BAA to understand the scope of covered services. The document should define the activities that the provider will perform to support its HIPAA hosting solution. Teams must ensure there are no misunderstandings that could result in risks to ePHI security.

It is essential that the BAA explicitly define the breach-notification terms. The providers must notify the covered entity of security incidents, unauthorized disclosures, and confirmed breaches involving protected health information. The BAA should outline the specific breach-notification procedures and timelines the provider will follow.

## How To Choose HIPAA Hosting Providers

Decision-makers in healthcare organizations should create a detailed checklist that includes all compliance and technical requirements. A company’s HIPAA compliance scope can vary widely, from a secure email system to a fully HIPAA-compliant hosting environment. Customers need to understand their needs to evaluate providers effectively.

Healthcare organizations should favor cloud hosting providers with prior experience handling healthcare data and offering HIPAA-compliant cloud solutions. A vendor with demonstrated experience meeting HIPAA requirements offers customers peace of mind that inexperienced providers cannot match.

Companies should require prospective providers to submit [SOC 2](https://www.atlantic.net/hipaa-compliant-hosting/ssae-16-soc-1-soc2-care/) and SOC 3 certifications demonstrating that their infrastructure can protect ePHI. Reliable providers will be HITECH-audited by qualified, independent third parties to validate their services and operational controls.

Customers should feel free to schedule interviews with the vendors’ technical security teams. Decision-makers must be confident that the teams have the necessary skills and experience to safeguard their sensitive ePHI.

### Evaluate Data Security And Controls

Companies must evaluate the data security features and access controls to ensure they meet HIPAA compliance standards. The following specific security aspects should be assessed.

- Teams must verify that encryption at rest and in transit is available where reasonable and appropriate, based on risk analysis, or that equivalent safeguards are documented.
- Providers should implement intrusion detection systems to prevent threat actors from accessing the environment.
- Companies must confirm that role-based access control and [multi-factor authentication](https://www.atlantic.net/managed-services/multi-factor-authentication/) (MFA) are implemented to safeguard ePHI.
- Organizations should ensure that the provider’s logging and audit trail capabilities align with business requirements and HIPAA rules.

### Assess Cloud Environment And Public Cloud Options

Healthcare companies typically have systems that do not process ePHI and that run in less-secure public cloud environments. If this is the case, the company should look for a provider that supports hybrid cloud deployments to balance security with cost-effectiveness.

Technical teams can evaluate how the vendor provides network segmentation in the cloud environment. Providers must implement and support segmentation to isolate patient data and prevent its unencrypted transmission over public networks.

### Check HIPAA Eligible Services And Provider Certifications

Customers should check potential providers to verify they offer the specific HIPAA-compliant services they need. Decision-makers can evaluate providers based on the scope and pricing of the desired services. It is also important to confirm which services are covered by the provider’s BAA.

A reputable provider will make compliance certificates and recent audit summaries available for customer review. Organizations should use this documentation to narrow their search to providers that produce the necessary credentials.

### Consider Dedicated Hosting Versus Shared Hosting

Companies should consider the costs and benefits of dedicated versus [shared hosting](https://www.atlantic.net/vps-hosting/vps-hosting-vs-shared-hosting-pros-cons-differences-and-expert-tips/) solutions. Typically, dedicated hosting is the preferred method for processing sensitive, HIPAA-regulated workloads. The chosen provider should offer dedicated hosting options.

Teams may wish to assess the performance differences between dedicated and shared hosting options. In cases where workloads require consistent performance, a dedicated [HIPAA-compliant cloud hosting](https://www.atlantic.net/hipaa-compliant-hosting/hipaa-compliant-cloud-hosting-healthcare/) is usually a better choice. Other tenants’ activities may disrupt performance in a shared setting.

Customers who opt for a dedicated option should request isolation guarantees from their provider. The vendor must be able to demonstrate that the cost and promised secure performance platform is truly isolated from other cloud clients.

## Disaster Recovery And Business Continuity

Healthcare providers must ensure their cloud-hosted environments are protected by [disaster recovery plans](https://www.atlantic.net/disaster-recovery/disaster-recovery-plan/) to maintain business continuity and meet HIPAA data availability requirements. Teams should define recovery time and recovery point objectives for ePHI resources that meet business objectives.

Recovery time objectives (RTOs) define the maximum time allowed to recover specific systems or data assets. Recovery point objectives (RPOs) define the maximum allowable data loss. The company’s backup frequency controls the extent of data loss. For example, if the company can tolerate no more than 8 hours of data loss, backups must be performed at least every 8 hours.

All backups should be encrypted to prevent unauthorized access to ePHI. Companies must be able to meet their RTOs and RPOs in alternate locations in the event of localized disasters. Cloud providers should offer geographic redundancy with multiple data centers to safeguard against widespread disasters or outages.

Companies should develop disaster recovery plans and runbooks to be prepared to address a real disaster. Teams should test the plans at least annually to ensure they meet organizational expectations. Plans should be modified to mitigate issues and integrate new infrastructure components.

## Dedicated Hosting And Isolation Strategies

Healthcare systems often require dedicated hosting and isolation to maintain HIPAA compliance. Companies can implement strict access controls and network segmentation to prevent unauthorized access to patient data. Dedicated hosts reduce the attack surface and allow customers to deploy effective backup and disaster recovery services. Examples of systems that require isolation include EHR platforms, telehealth solutions, and clinical databases.

Customers should be provided with evidence of physical or virtual tenant isolation upon request. Vendors that cannot provide this evidence should be excluded from serious consideration when clients need an isolated environment.

In most cases, a dedicated hosting solution is more expensive than a shared cloud one. Customers must balance the increased cost of isolation against the enhanced security it offers. Decision-makers must factor in the costs of HIPAA violations and data breaches, which may be more likely in a shared environment.

## Migration Checklist For Healthcare Data

Healthcare organizations should develop a complete migration checklist when adopting a HIPAA-compliant hosting solution. The checklist should include pre-migration and post-migration activities to ensure compliance and protect patient data. The following steps should be included in all HIPAA-related migration plans.

- Teams must inventory the complete environment to identify health data assets and sensitive endpoints that must be protected in the new infrastructure. They should evaluate the environment to ensure that all healthcare systems and dependencies are slated for migration and develop a structured plan to migrate the data.
- Companies should conduct a pre-migration security risk assessment to verify that the cloud hosting provider complies with HIPAA requirements. Examples of aspects of the hosting environment that must be confirmed include data encryption, strict access controls, and the physical security of systems that process ePHI.
- Best practices include performing a test migration in a non-production cloud environment. This testing enables healthcare organizations to identify potential issues with the migration and address them before the move. Teams can fine-tune procedures to streamline the migration and ensure its success.
- After the migration to the cloud is complete, teams must validate that the appropriate access controls are in place. Users should verify access to healthcare systems to maintain business operations. Customers must also confirm that system access logging and compliance reporting within the hosting environment meet HIPAA requirements.

## Data Security Monitoring And Incident Response

HIPAA-compliant organizations should evaluate whether 24/7 monitoring is appropriate based on risk, workload criticality, and contractual obligations. Customer and provider teams should be notified immediately when an issue affects the security or performance of systems containing ePHI. These teams should have well-defined response plans to address the issue and mitigate its environmental impact.

Customers should evaluate providers’ performance by requesting incident response playbooks and entering into service-level agreements (SLAs). The SLAs guarantee system availability, which is a critical HIPAA requirement. Healthcare organizations should insist on uptime SLAs of at least 99.9%.

Ideally, the customer should plan and execute tabletop exercises to test incident response. The tests should include the CE’s and providers’ security teams, with each performing the roles outlined in the BAA. Healthcare organizations must be confident that security issues are handled effectively and efficiently.

## FAQs For Healthcare Organizations Hosting

Q: Who is responsible for protecting ePHI under the shared security model?

A: Both the covered entity that directly collects and processes protected health information and third parties that assist them are responsible for protecting ePHI. The covered entity is responsible for ensuring that all third parties involved in processing patient data sign a BAA.

Q: When is a BAA required for a third party?

A: BAAs are typically required when a third party stores, processes, or transmits ePHI for a covered entity. A BAA is required when a vendor hosts systems containing ePHI, manages healthcare applications, or provides cloud or managed services involving ePHI. HIPAA rules require companies to obtain BAAs from their cloud hosting providers.

Q: What are the main differences between public cloud and private options?

The main differences between public cloud and private [HIPAA hosting solutions](https://www.atlantic.net/hipaa-compliant-hosting/) revolve around performance and security. The private option provides a dedicated hosting environment; other cloud tenants do not impact tenants. Companies using a public cloud solution may experience degraded performance or be exposed to security vulnerabilities due to other customers’ activities on the shared platform.


---

# Unmanaged Dedicated Servers with Complete Administrative Control

> URL: https://www.atlantic.net/unmanaged-dedicated-servers/ | Updated: 2026-09-16

Run your chosen operating system and software stack on a custom-built, single-tenant physical server with exclusive CPU, RAM, storage, and network resources. Your team owns configuration, patching, security, backups, and day-to-day administration.

- Single-Tenant Physical Hardware
- Full Root & Admin Access
- No Shared Hypervisor
- 24/7/365 USA-Based Support

Dedicated Hosting Uptime SLA: 100%

Hosting Experience: 32 Years

## Unmanaged Dedicated Servers

Atlantic.Net unmanaged dedicated servers are built for organizations that want complete control over the operating system, software stack, security settings, and server management process. Atlantic.Net's dedicated server platform is custom-built by specification, supports a wide selection of operating systems and control panel options, and can be delivered as managed or unmanaged depending on how much responsibility your team wants to keep in-house.

This is dedicated server hosting for experienced users, DevOps teams, and organizations with technical expertise that do not want a shared hosting plan, an abstracted virtual private server, or a managed dedicated server hosting package handling every server management task. You keep full control; Atlantic.Net provides the physical server, reliable infrastructure, and an upgrade path to managed services when needed.

## What Is Unmanaged Dedicated Server Hosting?

Unmanaged dedicated server hosting gives you a physical machine dedicated to your business. Unlike virtual servers, cloud servers, or shared hosting, your workloads run in dedicated environments with direct, exclusive access to CPU, RAM, storage, and network resources, without a shared hypervisor. Giving you the dedicated resources, more predictable performance, and full administrative access.

In our unmanaged hosting model, we provide the enterprise-grade hardware and maintain the underlying infrastructure. Your team handles operating systems, server setup, patching, software stacks, firewall rules, security protocols, backups, monitoring, and day-to-day server management tasks above the hardware layer. Atlantic.Net explicitly supports both managed and unmanaged hosting services to match different levels of technical expertise, so if you need managed service addons, just ask!

### Complete Control Over the Server Environment

You choose your preferred operating system, install your own control panel or skip one entirely, define user access policies, configure services, harden security settings, and tune the web server, database, and application stack to your requirements.

Control matters when standardized templates are not enough, when you need custom configurations, or when internal governance requires specific build standards. Atlantic.Net's dedicated platform is designed around that flexibility, with full root access and support for Windows, Linux, and Midrange software.

### More Freedom Than Shared Hosting or VPS Hosting

Shared hosting is built for simplicity, not control. VPS hosting and virtual private server plans offer flexibility, but they still run inside a virtualized environment with shared underlying hardware. If your team needs its own dedicated server for custom kernel modules, specialized workloads, self-managed virtualization, older supported software, or tighter control over disk space and server resources, unmanaged dedicated hosting gives you more room to build the exact hosting environment you want.

### Dedicated Resources for Consistent Performance

A dedicated server gives your workloads access to dedicated resources on a single-tenant physical server. There is no noisy-neighbor contention from other tenants sharing the same physical machine. For high-traffic websites, databases, APIs, large web applications, and other resource-intensive applications, that isolation can improve consistency, make troubleshooting easier, and help you boost performance under sustained demand.

### Keep Server Management In-House

Some organizations prefer to own the operating model internally. They already have in-house expertise, established physical security measures, and experienced users who want to manage updates, configure firewall rules, deploy automation, and maintain compliance processes themselves. For those teams, unmanaged dedicated can be the right balance: you avoid the extra abstraction of managed hosting while keeping the option to add support where it makes sense.

## Why Choose Atlantic.Net for Unmanaged Dedicated Servers?

### Custom-Built Dedicated Servers for Demanding Workloads

Atlantic.Net's dedicated servers are custom-built to specification, with CPU, disk, and memory options tailored to workload requirements. Its current dedicated and bare metal offerings span Intel Xeon and AMD EPYC platforms, making the service suitable for everything from web hosting and database servers to more demanding workloads and specialized deployments.

### Full Root Access and Full Administrative Access

This service should appeal to buyers looking for complete control. Atlantic.Net provides full root access for complete server control, and we hand over full admin privileges and the ability to choose the operating system or hypervisor. That is exactly what technical teams expect from a true unmanaged server.

### Reliable Infrastructure from an Established Hosting Provider

Atlantic.Net has more than 32 years of hosting experience and provides business-class dedicated and cloud hosting solutions through data centers in New York, London, San Francisco, Singapore, Toronto, Dallas, Ashburn, and Orlando.

### Operating System Flexibility

Atlantic.Net supports a wide selection of operating systems and control panel options, including current and older supported releases of Microsoft Windows Server, Ubuntu Server, CentOS, Rocky Linux, Fedora, and more. For buyers comparing managed servers with unmanaged hosting, this matters: you are not locked into a narrow template when your preferred operating system or software stack has specific requirements.

### Security-Ready Foundation with Optional Add-Ons

For unmanaged dedicated server hosting, Atlantic.Net provides the data center and infrastructure foundation; your team manages the server-layer security posture. Atlantic.Net's data center infrastructure is routinely inspected and audited, with SOC 2 Type II and SOC 3 Type II certification, and compliance-oriented solutions for PCI and HIPAA. On top of that, Atlantic.Net offers optional managed firewall security, managed monitoring, backups, CDN, web application firewall, and DDoS protection services for customers who want to strengthen security measures without moving to a fully managed dedicated server.

### Support Team Available When You Need It

Unmanaged does not mean unsupported. Atlantic.Net support teams are available 24/7/365, backed by decades of experience, and are based right here in the USA, with onsite technicians for all of our USA data center operations. Making Atlantic.Net a practical fit for teams that want full control over the server but still want responsive help around infrastructure, access, and service options.

## Deployment / Engagement / Service Options

### Unmanaged Dedicated Servers

A single-tenant physical server with full root access, dedicated resources, and complete control over server setup, operating system, software installation, enhanced security settings, and administration. It is best for organizations with technical knowledge and clear internal ownership of server management.

### Unmanaged Dedicated Hosting with Add-On Services

Some buyers want an unmanaged server environment but still need help with specific functions. Atlantic.Net already offers upgrade paths, including managed monitoring, managed data backup, managed firewall security services, control panel options, and DDoS protection services. This lets customers keep core administrative access while selectively outsourcing operational tasks.

### Move to a Managed Dedicated Server Hosting Model Later

Not every environment stays unmanaged forever. A business may start with full control, then later decide to offload server management tasks as workloads grow or staffing changes. Atlantic.Net's dedicated platform already supports both managed and unmanaged delivery models, making unmanaged dedicated servers a great starting point with a managed dedicated server path available when needed.

## Key Features

### Full Root Access = Full Control

Direct administrative access gives your team the ability to configure services, install packages, automate provisioning, adjust kernel-level settings where required, and maintain complete control of the hosting environment.

### Dedicated Single-Tenant Hardware

Your workloads run on a dedicated physical server rather than on shared hosting or virtual servers. That means dedicated resources, stronger isolation, and a server environment built for steady performance.

### Custom Server Configurations

Choose the CPU, memory, storage, and overall server configuration that best fits your applications. Atlantic.Net's dedicated servers are custom-built to customer specifications rather than locked into a single fixed profile.

### Choice of Operating System

Support for multiple Linux distributions and Windows Server options makes it easier to align the hosting service with your preferred operating system, internal standards, or application dependencies.

### SSD and NVMe Storage Options

Atlantic.Net's dedicated servers offer SSD and NVMe disk choices, giving buyers flexibility to optimize for capacity, IOPS, or cost across different server configurations.

### Optional Control Panel and Managed Services

Need Plesk, backup services, monitoring, or managed firewall support? Atlantic.Net's dedicated hosting platform already supports these options, which is useful for teams that want unmanaged hosting without giving up access to operational add-ons.

### Optional DDoS Protection

For internet-facing web applications and high-traffic websites, Atlantic.Net offers DDoS protection through our network-edge protection services, along with web application firewall and CDN options.

## Who Is This For?

Atlantic.Net unmanaged dedicated servers are best suited to organizations with real technical expertise, including DevOps teams, SaaS operators, agencies and resellers, internal IT departments, and businesses moving off a virtual private server because they need more dedicated resources, more predictable performance, or more freedom in the software stack. It is also a strong fit for organizations that prefer to retain control over server management, security settings, and update policies rather than hand them over to a managed hosting provider.

## Common Use Cases

Unmanaged dedicated hosting is well-suited to high-traffic websites, busy e-commerce platforms, database-backed web applications, private web server deployments, API infrastructure, and self-managed business systems that need stable access to server resources. Atlantic.Net supports multiple database-driven sites, streaming media, complex e-commerce sites, email, DNS, and SQL servers.

It is also a good option for specialized workloads where a team needs to install a custom software stack, run a specific hypervisor, maintain older supported operating system versions, or enforce internal security protocols and firewall rules without provider-level restrictions. When organizations prefer single-tenant infrastructure but have the in-house expertise to manage it themselves, unmanaged dedicated servers become a practical middle ground between owning hardware outright and buying a fully managed service.

## Why It Matters

As applications grow, the limits of shared hosting and smaller virtual servers become more obvious. Performance becomes less predictable. Security boundaries become less customizable. Server management becomes harder to standardize. Unmanaged dedicated servers solve these problems by providing your team with a physical machine, dedicated environments, and full control over the operating system and application stack.

Just as important, unmanaged dedicated hosting lets you decide where responsibility sits. If you have the technical knowledge, it can be a more direct and cost-conscious way to run serious workloads. If you later need operational assistance, Atlantic.Net already offers managed services and managed dedicated server hosting paths that can grow with you.

Need an unmanaged server with full control, dedicated resources, and a hosting provider that can support custom requirements?

Talk to Atlantic.Net about unmanaged dedicated servers built around your preferred operating system, server configurations, performance needs, and security requirements. Start with the physical server you need now, then add managed services only where they create value.

## FAQ

### What is the difference between an unmanaged dedicated server and a managed dedicated server?

With an unmanaged dedicated server, your team handles the operating system, updates, security settings, backups, and ongoing server management. With a managed dedicated server, some or all of those responsibilities are outsourced to the hosting provider. Atlantic.Net supports both models.

### Do I get full root access with Atlantic.Net unmanaged dedicated servers?

Yes. Atlantic.Net's dedicated servers includes full root access for complete server control and admin privileges.

### Which operating systems can I run?

Atlantic.Net provides support for a wide range of operating systems, including Microsoft Windows Server, Ubuntu Server, CentOS, Rocky Linux, Fedora, and others. That makes the service flexible for teams with a preferred operating system or legacy dependency.

### Is unmanaged dedicated hosting better than VPS hosting?

It depends on the workload and your team. A virtual private server is usually easier and cheaper to start with. Still, a dedicated server gives you a full physical machine, dedicated resources, no virtualization overhead, and more control over the server environment. That is often a better fit for demanding workloads and organizations with in-house expertise.

### Can Atlantic.Net help with DDoS protection, backups, or firewall services?

Yes. Atlantic.Net offers managed monitoring, managed data backup, managed firewall security services, web application firewall, CDN, and DDoS protection as optional add-ons for our hosted infrastructure.

### Who is responsible for security in an unmanaged server environment?

Atlantic.Net is responsible for the underlying infrastructure and data center foundation. At the same time, your team is responsible for operating system configuration, user access, patching, firewall rules, software security, and the rest of the server-layer configuration in an unmanaged environment.

### Can I start unmanaged and move to managed services later?

Yes.

### What kind of infrastructure is behind the service?

Atlantic.Net infrastructure is audited and certified, with SOC 2 Type II and SOC 3 Type II data center certifications, support across multiple global regions, 24/7/365 support availability, and a 100% uptime SLA for dedicated hosting.

## Cloud Availability in Multiple Global Regions

Deploy close to your users from eight international data centers worldwide, with new regions on the way.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Custom Configured Dedicated Servers Built for Your Exact Workload

> URL: https://www.atlantic.net/custom-configured-dedicated-servers/ | Updated: 2026-09-16

Choose the CPU, RAM, storage, operating system, and network configuration for a single-tenant physical server with full root access, a 100% uptime SLA, and 24/7/365 US-based support.

- Custom CPU, RAM & Storage
- Single-Tenant Physical Hardware
- Full Root Access
- 24/7/365 US-Based Support

Uptime SLA: 100%

Maximum ECC RAM: 1 TB

## Custom Dedicated Servers

Tired of squeezing your applications into a pre-configured box that almost fits? Atlantic.Net custom-configured dedicated servers let you choose exactly the CPU, RAM, storage, operating system, and network configuration your business requires. Pay only for what you need. Get full root access from day one.

Every custom dedicated server runs on hardware you select, housed in Atlantic.Net's SOC 2 Type II, HIPAA, and PCI-DSS audited data centers, with a 100% uptime SLA and 24/7/365 US-based support backing every deployment.

## Why Choose a Custom Dedicated Server?

Unlike shared hosting, a dedicated server gives you exclusive use of the physical hardware. No noisy neighbors consuming your CPU. No other users competing for memory or bandwidth. Your server, your resources, your performance.

Custom configuration takes this further. Standard dedicated server packages work well for common workloads. But if you run resource-intensive applications, high-traffic databases, real-time analytics, or compliance-regulated workloads, you need exact specifications rather than the closest available option.

### Predictable performance

With dedicated resources and a fixed price, your monthly costs stay constant regardless of traffic spikes or processing demands.

### Full control

Root access gives you complete authority over the operating system, installed software, control panels, and server configuration. Unlike shared hosting or managed cloud tiers, nothing is locked down.

### Reduced latency

Your applications run directly on bare metal. No hypervisor overhead, no virtualization layer between your workload and the hardware. Direct access to CPU, memory, and NVMe SSD storage means faster load times and lower response latency for your users.

### Cost Transparency

Atlantic.Net offers custom dedicated server configurations with straightforward monthly pricing. You pay a fixed rate based on your selected hardware, starting from month one.

## What You Can Configure

Atlantic.Net custom dedicated servers are built to your exact specifications across every major hardware component.

## Processor (CPU)

Choose from Intel Xeon and AMD EPYC processor families, covering a range of core counts, clock speeds, and instruction set support:

If you need processing power beyond these configurations, contact the Atlantic.Net sales team for a custom quote.

### Intel Xeon E-2236

6 cores / 12 threads, 3.4GHz.

Strong single-thread performance for latency-sensitive applications.

### Intel Xeon Gold 6140

18 cores / 36 threads per socket, available in dual-socket configurations up to 36 cores / 72 threads.

Built for parallel processing and enterprise workloads.

### AMD EPYC 7702P

64 cores / 128 threads, 2.0GHz.

Maximum core density for compute-intensive, multi-threaded workloads and large-scale virtualization

### NVIDIA CPU/GPU

Available for AI, machine learning, rendering, and GPU-accelerated workloads.

High parallel performance and support for modern frameworks and libraries.

## Memory (RAM)

Configure RAM from 64GB to 1TB ECC (Error-Correcting Code) memory. ECC RAM detects and corrects single-bit memory errors automatically, protecting data integrity for financial processing, healthcare applications, and any workload where silent data corruption is unacceptable.

### 64GB

for standard web and application hosting

### 128GB–256GB

for databases, caching layers, and mid-tier virtualization

### 512GB–1TB

for in-memory databases, large-scale analytics, and high-density VM hosting

## Storage

Select from three storage types based on your access patterns and capacity requirements:

Software RAID configurations (RAID 1 for mirroring, RAID 10 for striping with redundancy) are available to protect against drive failure without relying on a dedicated RAID controller.

Most production deployments combine storage types: NVMe SSD for the operating system, active databases, and application data; SATA SSD or HDD for logs, backups, and infrequently accessed storage.

### NVMe SSD

Low-latency read/write, databases, and caching

Up to 3.84 TB per drive

### SATA SSD

General-purpose workloads with balanced cost and performance

Up to 1.92 TB per drive

### HDD

High-capacity archival, backups, and bulk storage

Up to multiple terabytes per drive

## Network and Bandwidth

All custom dedicated servers include a 1Gbps port with 20TB of monthly bandwidth as standard.

Upgrade options include:

Remote reboots and out-of-band management are included, so your support team can restart or access the server without raising a ticket.

### 10Gbps Port

High-throughput applications, media delivery, and large data transfers

### Additional IP Addresses

Multi-domain hosting, load balancing, and IP-based routing

### Private Network Connectivity

Secure communication between your servers without traversing the public internet

## Operating System

Choose your operating system from a broad list of supported options:

Atlantic.Net does not restrict which control panels, databases, or software you install. cPanel, Plesk, DirectAdmin, or a bare OS, the choice is yours.

### Linux Distributions

CentOS, Ubuntu, Debian, AlmaLinux, Rocky Linux, Fedora, and others on request.

### Windows Server

Windows Server 2019 and 2022 are available. Ideal for .NET applications, Active Directory, MSSQL, and Windows-native workloads.

## Atlantic.Net Custom Dedicated Server Features

### Full Root Access

From the moment your server provisions, you have complete root or administrator access. Install any software, modify any configuration, and manage every aspect of your environment without requesting permission from a support team.

### 100% Uptime SLA

Atlantic.Net guarantees 100% uptime on network, hardware, and infrastructure, one of the strongest SLAs available from any dedicated hosting provider. Most providers offer 99.9% or 99.99%. We offer 100%.

### Audited Compliance Certifications

Atlantic.Net data centers carry independently audited certifications across the compliance frameworks most commonly required by regulated industries:

SOC 2 Type II and SOC 3 Type II

HIPAA AT-C 105 and 205

HITECH

PCI-DSS

NIST 800-53

All certifications are audited by a third-party CPA firm. Atlantic.Net signs Business Associate Agreements (BAAs) for healthcare and health-sector customers. These certifications apply to custom-configured servers hosted in our facilities, not as an add-on tier.

Predictable Pricing. Atlantic.Net offers custom dedicated server configurations with straightforward monthly pricing. You pay a fixed rate based on your selected hardware, starting from month one.

### 24/7/365 US-Based Support

Phone and email support from US-based engineers, available every day of the year. Spanish language support is also available. Optional managed services extend this to include proactive monitoring, firewall management, IPS, patch management, and DDoS protection.

### Multiple US Data Center Regions

Deploy your custom server in the Atlantic.Net data center regions closest to your users or business operations:

New York, NY, Financial district proximity, carrier-neutral facility

Ashburn, VA, One of the most interconnected data center markets in the US

Orlando, FL, Strategically located to support low-latency connectivity to South America, while supporting compliance-ready workloads

Dallas, TX, Central US location, strong connectivity to southern and midwestern US users

San Francisco, CA, West coast coverage, low latency to Pacific markets

All facilities carry the same compliance certifications. Choose your location based on latency requirements, data residency preferences, or proximity to your users.

### Remote Management and Reboots

Hardware-level remote management is included on all custom dedicated servers. Perform remote reboots, access out-of-band management consoles, and diagnose hardware issues without physical data center access. This keeps your support team productive and your server recoverable even during software-level failures.

### High Availability Configuration

For workloads that cannot tolerate downtime, Atlantic.Net supports high availability architecture across custom dedicated server configurations. Options include:

Hardware RAID (RAID 1 or RAID 10) to protect against single-drive failure without interrupting service

Software RAID for environments where you want OS-level control over the storage configuration

Multiple servers across data center locations for geographic redundancy and disaster recovery

Private network connectivity for direct, low-latency communication between servers in your infrastructure without routing through the public internet

High availability configurations are quoted individually. Contact the sales team to design a resilient infrastructure that matches your uptime and recovery requirements.

### Scalable Infrastructure

Custom dedicated servers are not a dead end. As your business grows, Atlantic.Net can provision additional servers configured to match or extend your existing setup. You can expand into Atlantic.Net's cloud hosting for burst capacity, or add colocation rack space if you want to bring your own hardware into our facilities alongside your hosted servers. Your infrastructure scales with your business, all under one provider relationship.

## Custom Dedicated vs. Standard Dedicated vs. Bare Metal

| Feature | Custom Dedicated | Standard Dedicated | Bare Metal Cloud |
| --- | --- | --- | --- |
| Hardware Selection | You choose CPU, RAM, and storage | Pre-configured | Pre-configured |
| Tenancy | Single-tenant | Single-tenant | Single-tenant |
| Root Access | Yes | Yes | Yes |
| Predictable Performance | Yes | Yes | Yes |
| Setup Fee | None | None | None |
| Compliance Certifications | Included | Included | Included |
| Billing | Fixed monthly | Fixed monthly | Hourly or monthly |
| Best For | Specific hardware requirements | General workloads | Elastic scaling |

## Workloads That Benefit from Custom Configuration

Custom dedicated servers are particularly well-matched to:

### High-frequency trading and financial applications

requiring low latency, ECC RAM, and PCI-DSS compliance

### Healthcare and clinical data platforms

requiring HIPAA and HITECH-certified infrastructure with BAAs

### Large relational and NoSQL databases

needing high RAM, fast NVMe storage, and dedicated IOPS

### AI and machine learning training

on AMD EPYC systems with high core counts and large memory configurations

### Media and video processing

requiring fast storage throughput and high bandwidth ports

### Multi-tenant hosting platforms

where resource density and isolation matter across customer workloads

### Development and staging environments

that must mirror exact production hardware specifications

### Colocation rack expansions

where existing infrastructure requires specific hardware to match existing configurations

## FAQ

### What is a custom-configured dedicated server?

A custom-configured dedicated server is a physical server built to your exact hardware and software requirements before deployment. You choose the CPU, RAM, storage, network configuration, and operating system. The server is exclusively yours with no shared resources.

### How does custom configuration differ from shared hosting?

Shared hosting places multiple customers on the same server, sharing CPU, RAM, and storage. A custom dedicated server gives you the entire physical machine, providing predictable performance and full root access without resource sharing.

### Which CPU is best for my workload?

Intel Xeon processors are ideal for latency-sensitive applications and high clock-speed workloads, while AMD EPYC processors are optimized for multi-threaded virtualization and large-scale computing. NVIDIA GPUs are available for AI and machine learning workloads.

### Do I need root access to manage my custom server?

Yes. Root access for Linux and administrator access for Windows Server are included by default, giving you full control over software, security, and server configuration.

### What operating systems are available?

Supported operating systems include Ubuntu, Debian, AlmaLinux, Rocky Linux, CentOS, Windows Server 2019, and Windows Server 2022.

### Are there hidden fees?

No. Dedicated server pricing is fixed monthly with no hidden setup or deployment fees.

### What compliance certifications apply?

Data centers include SOC 2 Type II, SOC 3 Type II, HIPAA, HITECH, PCI-DSS, and NIST 800-53 compliance certifications audited by independent third parties.

### What support is available?

24/7/365 US-based technical support is available by phone and email, with optional managed services for monitoring, patching, firewall management, and disaster recovery.

### Can I upgrade my server after deployment?

Yes. RAM, storage, and networking upgrades can usually be added after deployment. Larger hardware changes may require a new server configuration.

### What is the difference between dedicated servers and colocation?

Dedicated servers are owned and maintained by the hosting provider, while colocation means you own the hardware and place it inside the provider’s data center for power, cooling, networking, and security.

## Cloud Availability in Multiple Global Regions

Deploy close to your users from eight international data centers worldwide, with new regions on the way.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# The 2026 HIPAA Security Rule Update: Why Healthcare Organizations Should Prepare Their Hosting Environment Now

> URL: https://www.atlantic.net/hipaa-compliant-hosting/hipaa-security-rule-hosting-readiness/ | Published: 2026-05-31 | Updated: 2026-09-15 | Author: Richard Bailey

Healthcare cybersecurity is changing; for years, HIPAA-covered entities and business associates have been required to protect electronic protected health information, using administrative, physical, and technical safeguards. But ransomware attacks, cloud adoption, remote work, telehealth, connected medical devices, and increasingly complex vendor platforms have stretched the original HIPAA Security Rule far beyond the environment for which it was created.

That is why the U.S. Department of Health and Human Services Office for Civil Rights proposed major updates to the HIPAA Security Rule. The proposal was designed to strengthen the cybersecurity requirements for health plans, healthcare clearinghouses, most healthcare providers, and their business associates. While the rule is not yet final as of this writing, the direction is clear: healthcare organizations will be expected to demonstrate that ePHI is protected by [modern, documented, and tested security controls](https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/factsheet/index.html).

## What Is Changing In The Proposed HIPAA Security Rule?

The proposed rule would make HIPAA security requirements more [specific and measurable](https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/index.html). One of the biggest changes is the proposed removal of the distinction between “required” and “addressable” specifications. In practice, this means safeguards that some organizations previously treated as optional or flexible could become mandatory, subject only to limited exceptions.

HHS has also proposed written documentation for Security Rule policies, procedures, plans, and analyses; annual technology asset inventories and network maps; more detailed risk analysis requirements; annual compliance audits; stronger contingency planning; and more rigorous business associate oversight.

The technical requirements are especially important for organizations that host, store, process, or transmit ePHI. The proposal includes encryption of ePHI at rest and in transit, multi-factor authentication, vulnerability scanning at least every six months, penetration testing at least once every 12 months, network segmentation, anti-malware protection, backup and recovery controls, and periodic testing of security measures.

Even before a final rule is published, OCR’s January 2026 [cybersecurity guidance](https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/factsheet/index.html) shows where enforcement attention is already focused. OCR emphasized system hardening, patching known vulnerabilities, removing unnecessary software and services, changing default passwords, using security baselines, and conducting risk analysis that identifies vulnerabilities such as unpatched software.

## Why Hosting Is Central To HIPAA Readiness

Many healthcare organizations think of HIPAA compliance as a policy exercise. Policies matter, but modern HIPAA readiness also depends on the infrastructure where ePHI lives.

If your EHR, patient portal, billing platform, healthcare SaaS application, analytics system, telehealth service, or backup environment touches ePHI, your hosting environment becomes part of your compliance story. You need to know where the data is stored, how it is encrypted, who can access it, how activity is logged, how systems are patched, how backups are protected, and how quickly services can be restored during an incident.

HHS guidance is clear that covered entities and business associates may use cloud services for ePHI. Still, they must enter into a HIPAA-compliant Business Associate Agreement (BAA) with the cloud service provider and must conduct appropriate risk analysis and risk management. A cloud provider is a business associate. Making your hosting provider one of the most important vendors in your HIPAA program.

## How Atlantic.Net HIPAA Hosting Helps Close The Gap

Atlantic.Net HIPAA-compliant hosting is designed for organizations that need secure, compliant-ready infrastructure for healthcare workloads. Atlantic.Net offers a BAA as a standard part of its HIPAA hosting offering, helping define responsibilities between the healthcare organization and Atlantic.Net as a business associate.

Atlantic.Net’s HIPAA hosting platform includes a wide array of optional security features that align closely with the proposed Security Rule update, including multi-factor authentication, managed firewalls, intrusion prevention, vulnerability scanning, encrypted storage, encrypted backups, encrypted VPN connections, log management, anti-malware protection, off-site backups, and disaster recovery services.

Compliance matters because the proposed rule is pushing healthcare organizations toward documented, repeatable, testable safeguards. A hosting environment with built-in security services, managed support, and clear BAA coverage can reduce the operational burden on internal IT teams.

Remember, a HIPAA server alone does not make an organization HIPAA-compliant. Compliance depends on the organization’s adherence to HIPAA’s Privacy, Security, and Breach Notification requirements.

That is exactly why choosing the right hosting partner matters. Atlantic.Net provides the secure infrastructure layer, but your organization still needs appropriate policies, workforce training, access controls, risk analysis, application security, vendor management, business continuity, disaster recovery, and breach response procedures.

## Preparing Now Is The Smart Move

Waiting for the final rule may feel safer, but it creates risk. Many of the proposed requirements, including encryption, MFA, vulnerability scanning, asset inventories, backups, and network segmentation, take time to implement properly. They also require documentation and testing.

Healthcare organizations should start with a hosting and infrastructure review:

- Identify every system that stores, processes, or transmits ePHI.

- Confirm whether ePHI is encrypted at rest and in transit.

- Review MFA coverage for administrators, users, VPN access, and remote access.

- Check whether backups are encrypted, tested, and stored securely.

- Verify that logs are collected and reviewed.

- Review firewall, segmentation, vulnerability scanning, and disaster recovery capabilities.

- Most importantly, confirm that every vendor handling ePHI has a signed BAA.

Atlantic.Net HIPAA Hosting gives healthcare organizations a stronger foundation for this work. Whether you are a medical practice, hospital, healthcare SaaS provider, billing company, telehealth platform, or business associate, Atlantic.Net can help you host sensitive workloads in an environment built around HIPAA security expectations.

The proposed 2026 HIPAA Security Rule update sends a clear message: healthcare cybersecurity must be proactive, documented, and resilient. Atlantic.Net helps healthcare organizations move in that direction with [HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/), managed security services, encrypted infrastructure, disaster recovery, and BAA-backed support.

[Reach out to the team today.](https://www.atlantic.net/about-us/corporate-contact/)


---

# Hosting Security Features: What To Look for in a Secure Web Host

> URL: https://www.atlantic.net/cloud-platform/hosting-security-features-secure-web-host/ | Published: 2026-06-01 | Updated: 2026-06-05 | Author: Dr. Assad Abbas

Web hosting security features have become an important factor when selecting a hosting provider. Modern hosting environments support websites, applications, customer databases, and broader business operations. Therefore, organizations evaluate hosting providers not only for performance and uptime but also for their security capabilities.

The importance of security for hosting environments has increased as the threat environment has changed considerably. Cyber-attacks have become more frequent and more complex over time. Organizations must protect their hosting environments not only against infrastructure failures but also against security threats, including [ransomware](https://www.fbi.gov/how-we-can-help-you/scams-and-safety/common-frauds-and-scams/ransomware)[, Distributed Denial of Service (DDoS) attacks](https://www.atlantic.net/vps-hosting/what-is-a-ddos-and-how-do-we-prevent-our-business-from-being-attacked/), credential theft, cloud misconfigurations, and application vulnerabilities. Under these conditions, the choice of a Web host directly affects business continuity, service availability, operational reliability, and data protection.

Because of these security concerns, hosting security features have become an important part of provider evaluation. Such features help protect hosted workloads against unauthorized access, service disruption, data loss, and cyber threats across servers, networks, applications, and administrative environments. Therefore, organizations should evaluate security capabilities offered by hosting providers, including encryption, access controls, backup and recovery services, DDoS mitigation, monitoring systems, network protection mechanisms, and compliance support before selecting a Web host.

This article examines the security features to consider when choosing a secure Web host. It also discusses the security controls, hosting considerations, and operational factors that influence security decisions for hosting.

## Overview of Web Hosting Security

Web hosting security refers to the protections implemented across servers, networks, applications, and administrative systems to secure hosted workloads. These protections support service availability, operational resilience, and infrastructure stability. In addition, reliable security measures help organizations maintain business operations and protect sensitive information.

Hosting security also follows a shared-responsibility[model](https://www.crowdstrike.com/en-us/cybersecurity-101/cloud-security/shared-responsibility/): providers secure infrastructure, networks, and hosting platforms, while customers manage applications, configurations, credentials, and user access. Therefore, effective security depends on both parties fulfilling their responsibilities.

Below are some common security risks that can affect hosting environments across servers, networks, and applications.

### Server Level Risks

Server-level risks affect the systems that host websites, applications, and business workloads. Security issues at this level can influence service availability, system stability, and hosting protection. Such risks commonly arise from unpatched operating systems, insecure configurations, exposed services, malware infections, and weak permissions. Delayed updates create additional risk because attackers often target known vulnerabilities.

### Network Level Risks

Network-level risks affect communication, connectivity, and service availability within hosting environments. Such risks commonly include DDoS attacks, traffic interception, spoofing, and lateral movement across systems. DDoS attacks can overwhelm infrastructure resources, while traffic interception and spoofing may affect network integrity. Therefore, traffic monitoring, filtering, and network protection mechanisms become important components of secure hosting.

### Application-Level Risks

Application-level risks originate from the software components used within hosting environments. Modern websites commonly rely on content management systems, plugins, APIs, and third-party integrations, and vulnerabilities within these components can increase security exposure. Common examples of application-level vulnerabilities include [SQL injection](https://learn.microsoft.com/en-us/sql/relational-databases/security/sql-injection?view=sql-server-ver17), cross-site scripting, outdated plugins, and exposed APIs. Therefore, application security should be evaluated alongside hosting infrastructure.

## Choosing a Secure Web Hosting Provider

Hosting providers differ in their security capabilities and operational practices. Therefore, organizations should evaluate security features carefully before selecting a service. A secure Web hosting provider should offer several baseline protections, as these capabilities help maintain a reliable, secure hosting environment.

When evaluating a hosting provider, organizations should review the following security features because they influence infrastructure protection, service availability, and operational reliability:

- **Transport Layer Security (TLS)** is used to encrypt data in transit and protect communication between users and servers.
- **Automated backup and recovery capabilities** for restoring data and services during system failures, accidental deletion, data loss, or security incidents.
- **Built-in DDoS protection** for maintaining service availability through traffic filtering and mitigation.
- **Continuous monitoring and alerting systems** for improving visibility into system activity and supporting earlier detection of unusual events and security incidents.
- **Multi-factor authentication (MFA)** for strengthening administrative security beyond passwords.
- **Vulnerability scanning and security assessments** for identifying known weaknesses and supporting remediation efforts.

These capabilities indicate the security maturity of a hosting environment.

, technical features alone do not provide a complete assessment, as hosting reliability also depends on the provider’s reputation and operational practices. Several indicators can help evaluate these aspects. For example, uptime history reflects long-term reliability, while customer feedback provides insight into service performance. In addition, transparency regarding security practices, incident handling, and [Service Level Agreements (SLAs)](https://aws.amazon.com/what-is/service-level-agreement/) helps organizations understand provider commitments and response expectations. Therefore, technical capabilities and operational practices should be evaluated together when selecting a hosting provider.

## Core Hosting Security Features to Expect

Organizations should expect secure hosting providers to include protections that support communication security, service availability, recovery readiness, threat visibility, and access protection. These capabilities directly affect hosting security and operational reliability. The following features are commonly expected because they help strengthen protection across hosting environments and support secure service operation.

### Secure Connections and TLS Protection

Organizations should expect secure hosting providers to support TLS because secure communication is necessary to protect data in transit among users, applications, and hosting environments. Providers may also offer different certificate types based on validation requirements, including Domain Validated (DV), Organization Validated (OV), and Extended Validation (EV). In addition, HTTPS enforcement is commonly expected to keep communication encrypted across websites and applications, while HTTP Strict Transport Security (HSTS) provides additional protection against connections over insecure protocols.

### Backup Protection and Recovery Readiness

Organizations may expect backup and recovery capabilities because failures can still occur due to hardware issues, software problems, human error, accidental deletion, or security incidents. Secure hosting providers commonly provide features such as automated backups, retention policies, encrypted backup storage, and recovery procedures to improve recovery readiness. In addition, off-site backups provide additional protection, as local failures may affect primary systems, and recovery testing helps confirm successful restoration during an incident.

### DDoS Protection and Network Availability

Organizations should also expect protections against traffic-based attacks because service availability is an important part of hosting security. Secure hosting providers implement capabilities such as traffic filtering, mitigation systems, traffic scrubbing, and rate limiting to reduce the effect of DDoS attacks. In addition to these protections, Content Delivery Networks (CDNs) may provide further support by distributing traffic across multiple locations, helping reduce pressure on origin infrastructure and improving availability during high-traffic events.

### Monitoring and Threat Visibility

Organizations may also seek monitoring and alerting capabilities, as continuous visibility helps identify operational issues and security events earlier. Monitoring systems commonly track traffic activity, service availability, performance metrics, and security events, while alerting mechanisms notify administrators when unusual activity occurs. These capabilities improve visibility across hosting environments and enable faster response times.

### Access Protection and Authentication Controls

Organizations should expect secure hosting providers to implement stronger administrative controls, as compromised accounts can affect entire environments. Common access protection capabilities offered by hosting providers include multi-factor authentication, password policies, least privilege permissions, and periodic access reviews to improve access management. Since administrative access directly affects hosting environments, these controls also help limit unauthorized access and improve visibility into account activity.

Table 1: Hosting Security Features and Their Purpose

| **Security Feature** | **Primary Purpose** | **Security Area** |
| --- | --- | --- |
| TLS / HTTPS | Protect data in transit | Communication security |
| Backups | Support recovery | Data protection |
| DDoS protection | Maintain availability | Network security |
| MFA | Protect accounts | Access control |
| WAF | Filter malicious requests | Application security |
| Monitoring | Improve visibility | Operations |

## Infrastructure Hardening and Data Protection

Core hosting security features help protect communication, availability, monitoring, and access. Hosting security also depends on infrastructure management, as insecure configurations and weak protection controls can increase security exposure. Therefore, secure hosting environments should also include protections for system hardening, application security, and data protection, as discussed in the following sections.

### Patch Management and Secure Configurations

Organizations should expect secure hosting providers to maintain patch management processes because vulnerabilities regularly affect operating systems, applications, libraries, and dependencies. Regular updates, security patches, and automated vulnerability scanning help identify [Common Vulnerabilities and Exposures (CVEs)](https://www.ibm.com/think/topics/cve), outdated software, and configuration weaknesses.

In addition, secure hosting environments commonly implement hardened system images, firewall configurations, secure SSH settings, removal of default credentials, and restricted ports. These measures help reduce unnecessary services, limit exposure to attacks, and improve infrastructure protection.

### File, Application, and Administrative Protection

Data protection also extends to file transfers, applications, and administrative interfaces because information continuously moves across hosting environments. Secure hosting providers support Secure File Transfer Protocol (SFTP), granular file permissions, and administrative access controls to enhance file security and reduce unauthorized access.

In addition, websites and applications remain exposed to malicious traffic and software threats. Therefore, secure hosting environments often include Web Application Firewalls (WAFs) and malware scanning systems to reduce application exposure and strengthen protection.

## Hosting Types and Security Considerations

Hosting type also affects security, as isolation levels, resource sharing, and management responsibilities differ across environments. Therefore, organizations should consider the following when selecting a hosting model:

- Shared hosting may be suitable for low-risk websites, but resource sharing can reduce isolation and increase exposure between neighboring workloads.
- Dedicated hosting provides stronger isolation because infrastructure resources are allocated to a single organization. Therefore, it may suit workloads requiring greater control and security.
- Managed hosting transfers operational responsibilities to providers and may suit organizations that require security support but have limited internal resources.

Table 2: Security Considerations Across Hosting Types

| **Hosting Type** | **Isolation Level** | **Administrative Control** | **Typical Use** |
| --- | --- | --- | --- |
| Shared Hosting | Lower | Limited | Low-risk websites |
| Dedicated Hosting | High | High | Sensitive workloads |
| Managed Hosting | Moderate to high | Provider assisted | Limited internal teams |

## Monitoring, Incident Response, and Compliance Requirements

Security features are more effective when supported by operational visibility, response readiness, and compliance controls. Therefore, organizations should also evaluate monitoring capabilities, incident-response preparedness, and compliance support when selecting a hosting provider.

### Monitoring and Incident Response Capabilities

Monitoring supports operational visibility because performance issues, availability problems, and suspicious activity can develop into larger incidents when detection is delayed. Therefore, secure hosting providers commonly track traffic activity, service availability, system performance, and security events. In addition, alerting systems, Intrusion Detection Systems (IDS), and Intrusion Prevention Systems (IPS) improve detection capabilities and support earlier response. Since security events may still occur despite preventive controls, incident response procedures are also important because they define containment, recovery, and communication activities during an incident.

### Compliance Requirements and Hosting Standards

Compliance requirements may also affect hosting decisions, as some workloads are subject to regulatory obligations. For example, healthcare environments may require HIPAA-compliant hosting and a HIPAA Business Associate Agreement (BAA) for the storage of electronic Protected Health Information (ePHI). Similarly, payment environments may require a PCI-compliant infrastructure. In addition to industry-specific requirements, organizations may also review ISO 27001, SOC reporting frameworks, data residency requirements, and backup retention policies when compliance support or audit readiness is important.

## Example of a Secure Hosting Provider

Organizations seeking secure hosting solutions often evaluate providers based on the security capabilities outlined in this article. For example, providers such as [Atlantic.Net](http://www.atlantic.net) offer security-focused hosting services that may include infrastructure protections, compliance-oriented environments, backup capabilities, monitoring support, and managed hosting options.

This example highlights the importance of comparing provider capabilities against workload sensitivity, security expectations, and compliance requirements. Therefore, organizations should evaluate whether hosting services align with their operational and security needs before selecting a provider.

## Conclusion

Hosting security has become an important consideration in provider selection because modern hosting environments support a variety of operations. Therefore, evaluating a hosting provider only on pricing, performance, or uptime may not provide a complete picture. Secure hosting depends on multiple layers of protection, including communication security, backup readiness, infrastructure hardening, monitoring capabilities, and compliance support.

At the same time, security requirements vary based on workload sensitivity, operational needs, and regulatory obligations. Therefore, organizations should evaluate security features for hosting in relation to their own requirements rather than applying a general approach. A carefully selected hosting environment not only improves protection but also supports long-term reliability, resilience, and stable operations.


---

# High-Performance Public Cloud Instances Deployed in Under 30 Seconds

> URL: https://www.atlantic.net/public-cloud-instances/ | Updated: 2026-09-16

Launch enterprise-grade virtual servers with dedicated CPU, RAM, and SSD storage, hourly billing, your choice of over 40 operating systems, and a 100% uptime SLA.

- 100% Uptime SLA
- Deploy in Under 30 Seconds
- 40+ Operating Systems
- US-Based 24/7 Support

Global Data Centers: 8

Plans Start At: $10/mo

Atlantic.Net public cloud instances give you enterprise-grade virtual servers on demand. Choose your instance type, pick your operating system, and go live in under 30 seconds, with a 100% uptime SLA backing every deployment.

From $10 per month, you get dedicated CPU, RAM, and SSD storage in a multi-tenant cloud environment. No long-term contracts. No shared resources eating into your performance. Just clean, reliable cloud infrastructure built for modern workloads.

## What Are Public Cloud Instances?

A public cloud instance is a virtual server running on physical hardware managed by a cloud provider. Multiple virtual machines share the same underlying infrastructure through virtualization technology, but each instance runs in isolation, with its own operating system, dedicated resources, and private network access.

You pay only for what you use. That's the pay-as-you-go model that makes public cloud services affordable for startups and enterprises alike.

## How Public Cloud Instances Work

Cloud providers use virtualization technology to partition physical servers into multiple independent virtual servers. Each instance gets a guaranteed allocation of CPU, RAM, and storage. You control the instance through a web-based control panel or RESTful API, creating, scaling, or deleting servers whenever your workload demands change.

## Types of Public Cloud Instances

Atlantic.Net offers five instance families, each optimized for a different class of workload. Picking the right instance type from the start saves you money and avoids performance bottlenecks.

### General Purpose Instances

General purpose instances (G3 series) balance compute, memory, and storage at the lowest entry price. They suit web servers, small databases, development environments, and business applications that don't push CPU or RAM to the limit.

Starting from $10/month, 1 vCPU, 2GB RAM, SSD storage.

### Memory Optimized Instances

Memory optimized instances (M2 series) carry more RAM per vCPU than any other instance type. They're the right choice for relational and in-memory databases, real-time analytics, and applications that hold large datasets in memory to reduce disk I/O.

Starting from $163/month, optimized for RAM-intensive workloads.

### Compute Optimized Instances

Compute optimized instances (C2 series) deliver the highest number of vCPUs relative to RAM. Use them for CPU-intensive applications: batch processing, media transcoding, high-performance computing, and scientific modeling.

Starting from $211/month, built for raw processing power.

### Storage Optimized Instances

Storage optimized instances (S2 series) pair large SSD volumes with compute resources for data-intensive workloads. Each instance includes between 500GB and 4TB of dedicated SSD storage, ideal for log aggregation, data warehousing, and large-scale databases.

Starting from $248/month, up to 4TB NVMe SSD included.

## High Performance Accelerated Compute Instances

GPU-backed accelerated compute instances (AL40S and AH100NVL) run NVIDIA L40S and H100 NVL hardware. These are purpose-built for artificial intelligence workloads, machine learning model training, and GPU-accelerated inference pipelines.

| Instance Type | Best For | RAM | Entry Price |
| --- | --- | --- | --- |
| General Purpose (G3) | Web servers, development, and mixed workloads | 2 GB to 192 GB | From $10/mo |
| Memory Optimized (M2) | Databases, analytics, and caching | 16 GB to 128 GB | From $163/mo |
| Compute Optimized (C2) | HPC, batch processing, and rendering | 8 GB to 64 GB | From $211/mo |
| Storage Optimized (S2) | Data warehousing and large databases | 16 GB to 128 GB, plus 500 GB to 4 TB SSD | From $248/mo |
| Accelerated Compute (GPU) | AI, machine learning, and inference | 192 GB to 240 GB | From $1,120/mo |

## Public Cloud vs. Private Cloud vs. Hybrid Cloud

Choosing the right cloud model depends on your workload, compliance requirements, and budget. Here's what each model delivers.

### Public Cloud

Public cloud instances run on shared physical infrastructure managed by the cloud provider. You get on-demand scalability, pay-as-you-go billing, and no hardware to manage. It's the default choice for most web applications, databases, and development environments.

### Private Cloud

A private cloud is a single-tenant environment, physical hardware dedicated to one organization. It gives you maximum control over your data and computing resources. Healthcare organizations and financial services firms often choose private cloud to meet strict regulatory requirements.

### Dedicated Cloud

Dedicated cloud sits between public and private. You get dedicated physical hardware but the provider manages the underlying infrastructure for you. It's a strong fit when you need the isolation of a private environment without the overhead of running your own data centers.

### Hybrid Cloud

Hybrid cloud combines public and private cloud infrastructure. Sensitive workloads stay on private or dedicated cloud, while less critical applications run on public cloud instances. This approach lets businesses control costs while keeping regulated data in a compliant environment.

### Which Cloud Model Is Right for Your Business?

Most businesses start with public cloud instances for speed and cost efficiency, then move sensitive workloads to private or dedicated cloud as compliance demands grow. Atlantic.Net offers all three models, so you can build the architecture that fits your needs.

## Benefits of Public Cloud Services

### On-Demand Scalability

Public cloud instances scale up or down without hardware procurement. When traffic spikes, you launch additional instances in seconds. When demand drops, you shut them down and stop paying. This elasticity makes public cloud the right backbone for SaaS applications, eCommerce platforms, and high-traffic web services.

### Cost Savings with Hourly Billing

Hourly billing means you pay only for what you use. There are no upfront infrastructure costs, no wasted capacity from idle servers, and no long-term contracts forcing you to over-provision. Commit to a 1-year or 3-year term and save up to 20%.

### High Availability

Atlantic.Net public cloud instances run on RAID-10 NVMe storage with redundant networking and power systems. The infrastructure is built to keep your applications online, backed by a 100% uptime service-level agreement. That's a stronger guarantee than most cloud providers offer.

### Wide Range of Operating Systems

Choose from over 40 Linux, BSD, and Windows Server images. Supported distributions include Ubuntu, Debian, CentOS, Rocky Linux, Oracle Linux, AlmaLinux, FreeBSD, and Arch Linux. Windows Server users can deploy from 2008 R2 through Windows Server 2025, including Datacenter and Standard editions.

### Simple Resource Management

Every instance launches with a dedicated allocation of CPU, RAM, and storage. No shared resources. No noisy neighbors competing for the same pool. The Atlantic.Net control panel gives you full control over your cloud instances without the complexity of hyperscaler dashboards.

## Atlantic.Net Public Cloud Instances

### 100% Uptime SLA

Atlantic.Net backs every public cloud instance with a 100% uptime guarantee. Most cloud providers promise 99.9% or 99.99% availability. We commit to 100%, with redundant infrastructure at every layer to back it up.

### Deploy in 30 Seconds

New cloud instances go live in under 30 seconds. Select your instance type, choose your operating system, configure your storage, and your server is ready. No provisioning queues. No waiting.

### HIPAA, SOC 2, and SOC 3 Compliance

Atlantic.Net is SSAE 18 SOC 2 and SOC 3 certified, and HIPAA and HITECH audit-ready. If your business handles protected health information or financial data, you need cloud infrastructure built for compliance.

### US-Based 24/7 Support

Our support team is based in the United States and available 24 hours a day, 365 days a year. When something goes wrong, you talk to a cloud engineer, not a chatbot or a ticket queue.

### RAID-10 NVMe Cloud Infrastructure

Every Atlantic.Net instance runs on enterprise-grade NVMe SSDs in a RAID-10 configuration. RAID-10 means your data has both performance and redundancy built in at the storage layer.

### 8 Global Data Centers

Deploy your cloud instances in New York, London, San Francisco, Singapore, Toronto, Dallas, Ashburn, or Orlando. Select the location closest to your users to minimize latency.

## Public Cloud Pricing and Billing

### On-Demand Hourly Billing

On-demand instances are billed by the hour. The G3.2GB instance runs at $0.0149 per hour, roughly $10 per month for continuous use. You can terminate an instance at any time and stop accruing charges.

### Reserved Instances

Commit to a 1-year term for approximately 10% off on-demand pricing. A 3-year term saves around 20%. Reserved pricing works well for production workloads with predictable demand.

### Transparent Costs

Inbound bandwidth is unlimited. Outbound bandwidth overages are billed at $0.02 per GB. Additional IPv4 addresses cost $3.65 per month. Optional daily backups cost 20% of the server cost. No surprise fees.

## Security in Public Cloud Instances

### Data Isolation and Private Networks

Each cloud instance runs in its own isolated environment. Private networks let your instances communicate securely without exposing traffic to the public internet. Every instance has dedicated IP addresses and isolated storage, other customers on the same physical host cannot access your data.

### Compliance Certifications

Atlantic.Net maintains SOC 2, SOC 3, HIPAA, HITECH, and PCI-ready certifications. These certifications aren't marketing claims, they're independently audited each year. If your industry requires a specific compliance posture, ask our team for the relevant audit documentation.

### Access Controls

You control who accesses your cloud instances through SSH keys, firewall rules, and IP address whitelisting. Add load balancers, configure private networking between instances, and restrict inbound traffic to only the ports your applications need.

## Service Level Agreements for Public Cloud Instances

Atlantic.Net's SLA commits to 100% uptime for all public cloud instances. The underlying infrastructure uses redundant network paths, redundant power systems, and RAID-10 storage to support this guarantee. In the event of an outage attributable to Atlantic.Net, we provide service credits as defined in our SLA documentation.

## Frequently Asked Questions

### What is the difference between public cloud and private cloud instances?

Public cloud instances run on shared physical hardware managed by the provider. You share the underlying infrastructure with other customers, but each instance is fully isolated. Private cloud instances run on hardware dedicated to a single organization, giving you full control over the physical environment. Public cloud is more cost-effective; private cloud offers greater control and stricter isolation for regulated workloads.

### What operating systems can I run on Atlantic.Net public cloud instances?

Atlantic.Net supports over 40 operating systems, including Ubuntu, Debian, CentOS, Rocky Linux, Oracle Linux, AlmaLinux, Fedora, FreeBSD, and Arch Linux. Windows Server images are available from 2008 R2 through Windows Server 2025, in both Standard and Datacenter editions. Windows instances carry a licensing surcharge of $6.50 to $8 per month.

### What compliance certifications does Atlantic.Net hold?

Atlantic.Net is SSAE 18 SOC 2 and SOC 3 certified, and maintains HIPAA- and HITECH-compliant audit-ready infrastructure. The data centers are also PCI-ready. All certifications are independently audited annually.

### How quickly can I deploy a public cloud instance?

New instances go live in under 30 seconds. Select your instance type and operating system in the Atlantic.Net cloud portal, confirm your configuration, and your server is ready. You can also deploy instances programmatically through the Atlantic.Net API.

### Is there a free tier for Atlantic.Net cloud instances?

Atlantic.Net does not currently offer a free tier. General purpose instances start at $10 per month for the G3.2GB configuration.

### Can I scale my cloud instances on demand?

Yes. You can launch additional instances at any time through the control panel or API. Instances deploy in under 30 seconds, so you can respond to traffic spikes without pre-provisioning capacity. Scaling down is equally straightforward, terminate instances you no longer need and stop paying immediately.

## Get Started with Atlantic.Net Public Cloud Instances

Atlantic.Net has been running cloud infrastructure since 1994. Over 32 years of experience, eight global data centers, and a 100% uptime SLA, that's what you get with every public cloud instance you deploy.

Create your account and have a server running in 30 seconds.

## Cloud Availability in Multiple Global Regions

Deploy close to your users from eight international data centers worldwide, with new regions on the way.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Windows Dedicated Hosting with Full Administrator Access and a Triple 100% SLA

> URL: https://www.atlantic.net/windows-dedicated-hosting/ | Updated: 2026-09-16

Run Windows Server on an entire physical machine with dedicated CPU, RAM, storage, and network capacity, full administrator access, no setup fees, and 24/7/365 US-based support.

- Triple 100% SLA
- Full Administrator Access
- No Setup Fees
- 24/7/365 US-Based Support

Dedicated Configurations: 6

Plans Start At: $139/mo

## Windows Dedicated Hosting with a 100% Uptime SLA

Windows dedicated hosting gives you a bare-metal server provisioned exclusively for your workload, running the Windows operating system of your choice. You get full administrator access from day one, dedicated hardware no other customer touches, and the predictable performance that shared hosting and virtual machines cannot deliver.

Atlantic.Net Windows dedicated servers run on Intel Xeon and AMD EPYC processors, backed by a triple 100% SLA covering network uptime, hardware replacement, and infrastructure availability. Five US data centers. US-based support, 24/7/365, no outsourcing. Founded in 1994.

## What is Windows dedicated hosting?

Windows dedicated hosting is a web hosting model in which you lease an entire physical server running Windows. Unlike shared hosting, where hundreds of users divide a single server's resources, or a virtualized environment where workloads compete for the same underlying hardware, a dedicated server gives you exclusive access to all of its CPU cores, RAM, storage, and network capacity.

The Windows operating system on a dedicated server runs natively on the physical hardware, not inside a virtual machine layer. This means your applications get the full processing power and memory of the machine, with no hypervisor overhead and no noisy neighbors consuming system resources at unexpected times.

Dedicated servers running Windows are suited to workloads that need the Windows platform specifically: .NET applications, SQL Server databases, Active Directory infrastructure, ASP.NET web applications, online stores built on Windows-native commerce platforms, and business applications that require Windows Server licensing.

## Windows dedicated server configurations

Atlantic.Net offers six dedicated server plans. All plans include 20TB monthly outbound data transfer, a 1Gbps port, unlimited inbound bandwidth, no setup fees, and up to 30% off with longer billing terms.

Custom builds are available. Contact the Atlantic.Net sales team if none of the standard server options match your specifications.

| Plan | CPU | RAM | Storage | Price |
| --- | --- | --- | --- | --- |
| Dedicated Server 1 | 6-core Intel Xeon E-2236 | 64 GB | 2 × 480 GB SSD (RAID 1) | $139/mo |
| Dedicated Server 2 | 12-core dual Intel Xeon E5-2620 v3 | 64 GB | 2 × 960 GB SSD (RAID 1) | $189/mo |
| Dedicated Server 3 | 36-core dual Intel Xeon Gold 6140 | 128 GB | 4 × 1.92 TB SSD (RAID 10) | $495/mo |
| Dedicated Server 4 | 36-core dual Intel Xeon Gold 6140 | 256 GB | 4 × 1.92 TB SSD (RAID 10) | $599/mo |
| Dedicated Server 5 | 36-core dual Intel Xeon Gold 6140 | 256 GB | 4 × 3.84 TB SSD (RAID 10) | $699/mo |
| Dedicated Server 6 | 64-core AMD EPYC 7702P | 128 GB | 2 × 960 GB NVMe SSD | $709/mo |

### Entry-level Windows dedicated server

Dedicated Server 1 runs a 6-core Intel Xeon E-2236 with 64GB of RAM and 960GB of RAID1 SSD storage. At $139/mo, it covers small business websites, entry-level ASP.NET applications, and staging environments that need genuine dedicated hardware without the cost of a high-core-count machine.

### Mid-range multi-core options

Dedicated Servers 2 through 5 step through dual-socket Intel Xeon configurations, reaching 36 cores and 256GB of RAM. These are the configurations businesses turn to when running multiple Windows services on a single machine: Active Directory domain controllers, SQL Server instances, IIS farms, and business applications that require substantial hardware resources and room to grow.

### High-density NVMe with AMD EPYC processors

Dedicated Server 6 pairs a 64-core AMD EPYC 7702P with 128GB of RAM and NVMe SSD storage. The EPYC architecture delivers high memory bandwidth and per-core performance that suits compute-intensive Windows workloads, including large SQL Server databases, data processing pipelines, and high-traffic Windows web hosting.

## Benefits of Windows dedicated hosting

### Dedicated hardware, not a shared pool

When you run on dedicated servers, every CPU cycle, every gigabyte of RAM, and every IOPS of disk throughput belongs to your workload. Shared servers divide these resources among every tenant on the machine. VPS hosting places your workload inside a virtual machine that still competes for the same physical hardware. Dedicated hosting removes that competition entirely. Your disk space doesn't shrink. Your processing power doesn't fluctuate because someone else's workload spiked.

### Full administrator control

Atlantic.Net gives you full root access and full administrative privileges from the moment your server is provisioned. You choose the Windows Server version. You install the software, configure the services, set the security policies, and manage the machine as you see fit. Nothing is locked down at the hosting provider level. You can create virtual machines on the server using Hyper-V, install VMware ESXi, configure Active Directory, or run any Windows-compatible software your business needs.

### Windows Server licensing options

Atlantic.Net supports Windows Server 2016, 2019, and 2022 across all editions, with Windows Server licenses available. You specify the edition that matches your workload. The Datacenter edition is an option for environments that require creating virtual machines at scale using Hyper-V. The standard edition covers most dedicated server deployments where you run services directly on the host OS.

### Cost-effective dedicated resources

Windows dedicated hosting is cost-effective compared to on-premises server ownership, given hardware procurement, power, cooling, data center space, and maintenance. Atlantic.Net absorbs those costs. You pay a monthly fee that includes hardware, connectivity, data transfer, and the physical data center infrastructure, with no capital expenditure or depreciation planning required.

### Scalability through hardware upgrades and custom builds

When your workload grows beyond your current server's capacity, Atlantic.Net's custom build option lets you specify higher core counts, more RAM, additional disk space, or faster NVMe storage. You're not locked into fixed hosting plans. The server options range from 6-core entry-level machines to 64-core AMD EPYC configurations, covering small-business deployments to large enterprise workloads.

### Predictable performance for business-critical workloads

Shared hosting and cloud VPS instances can introduce latency variability, affecting business-critical data processing, database performance, and application response times. Dedicated server hosting eliminates that variable. Your server's performance reflects your workload, not the activity of strangers on the same hardware. That predictabilitymatters in production environments where SLAs and user experience depend on consistent response times.

## Security and compliance

### SOC 2, HIPAA, and PCI DSS

Atlantic.Net data centers carry independent audit certifications for SOC 2 Type II, SOC 3 Type II, HIPAA, HITECH, and PCI DSS. These compliance requirements apply to hosting providers that handle regulated data, including payment card information, protected health records, and financial data. If your business serves financial institutions, processes cardholder data, or handles patient records, your hosting provider's compliance posture is part of your own compliance story.

### Enhanced security through isolation

Dedicated server hosting provides enhanced security that a shared hosting or VPS environment cannot match. You are the only tenant on your hardware. A security incident affecting another customer's workload on a shared server cannot propagate to your machine, because there are no other customers on your machine. Your server's network traffic, storage, and compute resources are physically isolated from all other systems in the data center.

### Active Directory and Windows security controls

Running Windows Server on dedicated hardware gives you full control over Active Directory, Group Policy, Windows Firewall, and the full suite of Windows security features. You configure your own password policies, access controls, and audit logging. Security hardening happens at your level, not shared across hundreds of tenants with different requirements.

### Managed security add-ons

Atlantic.Net offers managed security services you can layer onto your dedicated server: Security Firewall, Intrusion Detection System (IDS), DDoS Protection, Web Application Firewall, CDN, and managed backups. These add-ons convert a self-managed server into a managed server environment where Atlantic.Net handles the security infrastructure while you retain control of your applications and data.

## Managing Windows dedicated servers

### Remote Desktop and server access

You access your Windows dedicated server through Remote Desktop Protocol (RDP), the standard Windows remote administration interface. From your local Windows, Mac, or Linux machine, you connect directly to the server desktop and manage it exactly as you would a physical machine in front of you. Full control panel access means you can install software, configure IIS, manage services, and perform system administration without restriction.

### Hyper-V and Virtualization

Windows Server includes Hyper-V, Microsoft's native hypervisor. With a dedicated server running Hyper-V, you can create virtual machines on top of the physical host, partitioning its resources across multiple isolated Windows or Linux environments. This is useful for hosting providers using reseller hosting plans, development teams running multiple isolated test environments, or businesses that want a private cloud architecture on dedicated hardware.

### Server monitoring and managed support

Atlantic.Net provides server monitoring as part of its managed services offering. Round-the-clock infrastructure monitoring tracks hardware health, network availability, and system events. US-based technical support is available 24/7/365 by phone at 866-618-3282 and by email, in both English and Spanish. When something needs attention, you reach engineers directly. There is no outsourced call center and no ticket queue that routes overseas.

### Windows Updates and Patch Management

On a self-managed dedicated server, Windows update scheduling is your responsibility. You control when patches apply, how the server restarts, and which updates are approved for your environment. If you prefer to delegate patch management, Atlantic.Net's managed server add-ons cover this. Managed patching keeps your Windows server up to date with security fixes without requiring you to manually schedule maintenance windows.

## Windows vs Linux Dedicated Servers

Both Windows and Linux servers run on the same underlying dedicated hardware at Atlantic.Net. The choice comes down to your application stack and tooling preferences.

Windows dedicated servers suit workloads that depend on Windows: IIS web hosting, ASP.NET applications, SQL Server databases, Active Directory, Exchange-compatible mail systems, and any commercial software distributed only as a Windows binary. If your development team works in .NET and your organization runs Microsoft products, Windows dedicated server hosting keeps your stack consistent from development through production.

Linux servers suit open-source stacks such as LAMP (Linux, Apache, MySQL, PHP), Python, and Node.js applications, containerized workloads, and environments where engineers prefer Linux tooling. Linux generally has lower licensing costs, since Linux itself is free, while Windows server licenses add to the monthly price.

Some workloads run comfortably on either platform. In those cases, Linux is often preferred for cost reasons. But if your applications are Windows-native, running them on Linux adds complexity and compatibility risks that outweigh the licensing savings. Atlantic.Net offers both, so you choose the operating system that fits your work rather than the one your hosting provider defaults to.

## Atlantic.Net Windows dedicated hosting

### Five US data centers

Atlantic.Net operates five US data centers: New York (11 miles from Manhattan), San Francisco, Ashburn, VA, Dallas, TX, and Orlando, FL. Each facility carries full SOC and compliance certifications. You choose the location closest to your users or required by your compliance framework. Businesses with disaster recovery requirements can split workloads across multiple data centers.

### Triple 100% uptime SLA

Atlantic.Net backs every dedicated server with a triple 100% SLA covering network uptime, hardware replacement time, and infrastructure availability. That's not the typical "99.9% network SLA" that permits several hours of downtime per year. When the SLA says 100%, it means hardware failures get replaced, not worked around, and the network stays up. If Atlantic.Net falls short, the SLA credit applies.

### Founded in 1994, privately owned

Atlantic.Net has operated since 1994. The company is privately owned and profitable, without the acquisition pressure or investor timelines that affect publicly traded hosting companies. Your dedicated server runs in a data center operated by a business that has been in this industry for over 32 years and plans to be here for 30 more.

### Support services with no outsourcing

Every call to 866-618-3282 is routed to a US-based engineer. Atlantic.Net does not route support to outsourced call centers. The team that answers knows the infrastructure and understands the products, and has the authority to resolve issues directly. Support services run 24/7/365, including holidays. When your server has a problem at 3 am on a Sunday, the response is the same as at 9 am on a Monday.

## Pricing and billing

Atlantic.Net Windows dedicated server plans start at $139/mo for a 6-core Intel Xeon E-2236 with 64GB RAM and SSD RAID1 storage. The 64-core AMD EPYC configuration with NVMe storage costs $709/mo. All plans include 20 TB of outbound data transfer per month, a 1 Gbps port, unlimited inbound bandwidth, and no setup fees.

Longer billing terms unlock discounts of up to 30% compared to month-to-month pricing. Windows Server licenses are priced separately and quoted at the time of order based on edition and version. Contact the sales team for custom server configurations or volume pricing for multiple dedicated servers.

## Frequently Asked Questions

### What Windows Server versions are available on Atlantic.Net dedicated servers?

Atlantic.Net supports Windows Server 2016, Windows Server 2019, and Windows Server 2022. All editions are available, including Standard and Datacenter. Datacenter edition is the right choice when you plan to create virtual machines using Hyper-V, as it includes unlimited Windows Server guest licenses on the same host. Standard edition covers most single-host dedicated server deployments.

### Can I install Hyper-V and create virtual machines on my Windows dedicated server?

Yes. You have full administrator access to your dedicated server, which means you can install and configure Hyper-V to create virtual machines on the host. This lets you partition a single physical server into multiple isolated Windows or Linux environments. Atlantic.Net also supports VMware ESXi as an alternative hypervisor if your team prefers the VMware management toolchain.

### How does Windows dedicated server hosting differ from VPS hosting?

A Windows VPS hosting instance runs inside a virtual machine on shared physical hardware. Multiple VPS instances share the same server's CPU, RAM, and storage, managed by a hypervisor. A Windows dedicated server gives you the entire physical machine with no sharing. You get all the CPU cores, all the RAM, and all the storage. There is no virtualized environment between your workload and the hardware. Dedicated server hosting costs more, but delivers more consistent performance and stronger isolation.

### Is Windows dedicated hosting suitable for compliance-regulated workloads?

Atlantic.Net's data centers are independently audited for SOC 2 Type II, SOC 3 Type II, HIPAA, HITECH, and PCI DSS. Windows dedicated servers run in these certified facilities, giving you the physical infrastructure compliance that regulated workloads require. Healthcare platforms, financial services applications, and online stores processing payment cards can cite Atlantic.Net's audit certifications in their own compliance documentation.

### What level of technical support is included?

All dedicated server plans include 24/7/365 access to US-based technical support by phone at 866-618-3282 and by email. Support covers hardware issues, network problems, and infrastructure-level questions. Application-level management and Windows administration support is available through managed server add-ons. Atlantic.Net does not outsource its support. The engineers you reach are based in the US and work directly on the infrastructure.

### Can I get a custom Windows dedicated server configuration?

Yes. The six standard server options cover most use cases, but Atlantic.Net can build custom configurations to your specifications. If you need a different CPU, more RAM, additional storage, a specific RAID configuration, or hardware that doesn't appear in the standard lineup, contact the sales team to discuss a custom build. Custom servers are quoted individually and provisioned to your requirements.

## Get your Windows dedicated server

Atlantic.Net Windows dedicated servers start at $139/mo with no setup fees and a triple 100% uptime SLA. Choose from six standard configurations or request a custom build.

Questions? Call the Atlantic.Net team at 866-618-3282, available 24/7/365. Or visit the dedicated server hosting page to compare all server options.

## Cloud Availability in Multiple Global Regions

Deploy close to your users from eight international data centers worldwide, with new regions on the way.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Linux Dedicated Hosting with Full Root Access and a Triple 100% SLA

> URL: https://www.atlantic.net/linux-dedicated-hosting/ | Updated: 2026-09-16

Run your workload on an entire physical server with dedicated CPU, RAM, storage, and bandwidth, your choice of Linux distributions, no setup fees, and 24/7/365 US-based support.

- Triple 100% SLA
- Full Root Access
- No Setup Fees
- 24/7/365 US-Based Support

Dedicated Configurations: 6

Plans Start At: $139/mo

## Linux Dedicated Hosting with a Triple 100% Uptime SLA

Your applications deserve more than a shared slice of a server. Atlantic.Net Linux dedicated hosting gives you a physical server to yourself, full root access, and a choice of Linux distributions, backed by a triple 100% SLA covering network uptime, hardware replacement, and infrastructure availability.

Plans start at $139 per month with no setup fees. US-based support answers the phone 24/7/365.

## What is Linux dedicated hosting?

Linux dedicated hosting is a web hosting service in which you rent an entire physical server running Linux. Unlike shared hosting, where many customers share the same server resources, a dedicated server reserves all CPU cores, RAM, storage, and bandwidth for your use alone.

You get full root access to the server, meaning you can install any software, configure the operating system as you see fit, load any Linux distribution, and set custom configurations that shared web hosting providers simply cannot offer. The hosting provider owns and maintains the physical hardware, while you control everything above the operating system level.

This model suits businesses and developers who need consistent computing power, resource-intensive applications, and complete freedom over their server environment.

## Linux dedicated server configurations

Atlantic.Net offers six dedicated server plans. All include 20TB monthly outbound transfer, a 1Gbps port, and no setup fees. Longer billing terms reduce the price by up to 30%.

Server 6 pairs AMD EPYC processors with NVMe storage for workloads that demand the highest sequential read and write throughput. Custom builds are also available if none of these configurations match your exact requirements.

All RAID configurations protect against drive failure without interrupting your server. RAID1 mirrors data across two drives; RAID10 combines mirroring and striping across four drives for both redundancy and performance.

| Plan | CPU | RAM | Storage | Price |
| --- | --- | --- | --- | --- |
| Dedicated Linux Server 1 | 6-core Intel Xeon E-2236 | 64 GB | 2 × 480 GB SSD RAID 1 | $139/mo |
| Dedicated Linux Server 2 | 12-core dual Intel Xeon E5-2620 v3 | 64 GB | 2 × 960 GB SSD RAID 1 | $189/mo |
| Dedicated Linux Server 3 | 36-core dual Intel Xeon Gold 6140 | 128 GB | 4 × 1.92 TB SSD RAID 10 | $495/mo |
| Dedicated Linux Server 4 | 36-core dual Intel Xeon Gold 6140 | 256 GB | 4 × 1.92 TB SSD RAID 10 | $599/mo |
| Dedicated Linux Server 5 | 36-core dual Intel Xeon Gold 6140 | 256 GB | 4 × 3.84 TB SSD RAID 10 | $699/mo |
| Dedicated Linux Server 6 | 64-core AMD EPYC 7702P | 128 GB | 2 × 960 GB NVMe SSD | $709/mo |

## Linux distributions for dedicated hosting

Atlantic.Net supports the most widely used Linux distributions. Your choice of operating system costs nothing extra, and custom OS configurations are available on request.

### Ubuntu

Ubuntu is the most popular Linux distribution for server hosting globally. It ships with five years of long-term support on LTS releases, an enormous package repository, and excellent documentation. It suits web servers, application servers, and developer workstations equally well. If you are new to Linux dedicated server hosting, Ubuntu is the most straightforward starting point.

### CentOS

CentOS has a long history as a stable, enterprise-grade Linux server distribution derived from Red Hat Enterprise Linux source code. Many sysadmins chose it for its predictable release cycle and close compatibility with RHEL tooling. Atlantic.Net continues to support CentOS on dedicated servers for teams with existing CentOS environments.

### Rocky Linux

Rocky Linux was built specifically to fill the gap left by CentOS's shift in model. It delivers full binary compatibility with Red Hat Enterprise Linux, making it the natural migration path for former CentOS users. Rocky Linux suits mission-critical workloads that need long-term stability and RHEL-compatible package management.

### Fedora Linux

Fedora Linux runs closer to the leading edge of the Linux ecosystem than most distributions. Red Hat sponsors its development, and it frequently previews features that later appear in RHEL. Choose Fedora Linux when you want access to the latest kernel versions and software packages without waiting for a slower release cycle.

### Debian

Debian is one of the oldest and most respected Linux distributions. Its package management is thorough, its releases are conservative, and its community is enormous. Debian underpins Ubuntu and dozens of other distributions. It works particularly well for servers that need to run for years without major disruptions.

### Arch Linux

Arch Linux follows a rolling release model, meaning your system updates continuously rather than jumping between major versions. It gives you a minimal base to build from, with complete freedom to install only what you need. Arch Linux suits experienced administrators who want precise control over every package on their server.

### Red Hat Enterprise Linux

Red Hat Enterprise Linux is available to teams that require direct Red Hat commercial support, along with access to the RHEL ecosystem of certified software and compliance tooling. RHEL is a strong choice for regulated industries and enterprises with existing Red Hat relationships.

## Benefits of Linux dedicated hosting

### Full root access and complete control

Every Atlantic.Net Linux dedicated server ships with full root access enabled. You can install any package, compile software from open source code, configure networking, run virtual machines, or modify the kernel. Shared hosting providers limit what you can install and how you can configure the server. A dedicated server removes those limits entirely.

### No noisy neighbours

On shared hosting, other tenants consume CPU cycles, RAM, and disk I/O that directly affect your application. A dedicated server is yours. High-traffic spikes from another customer never slow down your application. Your database queries run against dedicated resources, not a shared queue used by dozens of other sites.

### Predictable, high performance

Dedicated servers deliver consistent performance because you are not competing for resources. High-performance applications that need low-latency responses benefit directly from this predictability. You know exactly how much CPU and RAM are available, and you can tune the Linux operating system to extract full performance from the hardware.

### Cost-effective at scale

Shared hosting looks cheap until you factor in the performance ceiling, the restrictions on what you can run, and the cost of downtime. For high-traffic applications and resource-intensive workloads, a dedicated server is a cost-effective choice because you pay for capacity you fully use rather than sharing capacity you never fully use. Plans start at $139 per month, and longer billing terms bring costs down further.

### Wide choice of operating systems

Linux dedicated hosting gives you access to a range of mature operating systems. Popular Linux distributions like Ubuntu, Debian, Rocky Linux, Fedora Linux, Arch Linux, and CentOS all run well on dedicated hardware. You are not locked into a single vendor's stack, and you can run different distributions on different servers to match the needs of each workload.

### Compliance-ready infrastructure

Atlantic.Net holds SOC 2 Type II, SOC 3 Type II, HIPAA, HITECH, and PCI-ready certifications across its data center network. If your application handles healthcare records, payment data, or other regulated information, you can build on infrastructure that has already been audited.

### Free migration assistance

Switching hosting providers is disruptive. Atlantic.Net provides free migration assistance to reduce the time and risk of migrating your workloads to a new dedicated server. The support team handles the technical side, and you keep the downtime window as short as possible.

## Use cases for Linux dedicated servers

### Web hosting at scale

A Linux dedicated server handles far more web traffic than shared hosting providers can support on a shared environment. You run your own web server configuration, set your own connection limits, and deploy custom caching layers. For agencies managing dozens of client sites or publishers handling millions of monthly page views, dedicated server hosting provides the throughput and the control that shared hosting cannot.

Linux server hosting providers also support load balancers as managed add-ons, letting you spread traffic across multiple servers as your audience grows. Dedicated IP addresses simplify SSL certificate management and improve email deliverability.

### Game servers

Game servers demand consistent low-latency responses and the ability to handle sudden spikes in concurrent connections. A Linux dedicated server gives you the raw computing power to run popular game server software, configure tick rates, install mods, and manage multiple game instances. Atlantic.Net operates five US data centers, so you can place your game server close to your player base and reduce latency for everyone in the match.

### e-commerce and online stores

An online store cannot afford downtime. Payment processing, inventory management, and checkout flows are all mission-critical workloads where even a few minutes of unavailability cost real revenue. Linux dedicated hosting with RAID storage protects against drive failure, the triple 100% SLA covers hardware replacement, and the compliance certifications mean you can meet PCI requirements without building your own audit program.

### High-traffic applications and APIs

APIs, SaaS platforms, and content delivery all generate high traffic patterns that benefit from dedicated resources. You control the server, so you can tune the Linux operating system, configure connection pools, and optimize the network stack for your specific access patterns. When your application needs more capacity, you scale to a higher-tier server or add managed load balancers rather than waiting for a shared hosting provider to lift a resource cap.

### Mission-critical workloads

Databases, analytics pipelines, and real-time data processing all qualify as mission-critical workloads where uninterrupted operation matters more than initial cost. A dedicated server with NVMe storage handles intensive read/write operations without the I/O contention you see on virtual machines in shared environments. The AMD EPYC 7702P plan, with 64 cores and NVMe storage, suits the most demanding workloads on the list.

## Security and DDoS protection

Atlantic.Net includes a managed Security Firewall as an add-on, along with IDS (intrusion detection), DDoS protection, a Web Application Firewall, and CDN integration. DDoS attacks are a constant threat to publicly accessible servers, and having mitigation built into the network layer keeps your server online even when attack traffic spikes.

All plans include unlimited inbound bandwidth. Outbound transfer is 20TB per month on every plan. Free SSL certificates are available, and you can manage your own SSL certificates if you prefer to use an external certificate authority.

The data centers themselves are physically secured, with controlled access and environmental monitoring. Atlantic.Net holds SOC 2 Type II accreditation, which means independent auditors have reviewed the security controls across the infrastructure.

## Full root access and custom configurations

Root access on a dedicated server means you control the entire software stack. You choose which packages to install, which services to run at boot, how to configure the firewall, and what monitoring agents to deploy. Custom configurations that shared hosting cannot support, custom kernel parameters, non-standard ports, specialist software dependencies, all become straightforward.

Atlantic.Net also offers custom builds if the standard server configurations do not match your requirements. If you need a specific CPU, a different RAM configuration, or a particular storage layout, the team will put together a configuration that works.

Server monitoring is available as a managed add-on for teams that want visibility into CPU, RAM, disk, and network metrics without building their own monitoring stack from scratch.

## Linux vs Windows dedicated servers

| Feature | Linux | Windows Server |
| --- | --- | --- |
| Licensing Cost | Free for most distributions | Licensed, which adds to the monthly cost |
| Root Access | Full root access | Administrator access |
| Web Server Software | Apache, Nginx, LiteSpeed | IIS, Apache |
| Scripting and Automation | Bash, Python, Ruby, PHP | PowerShell, Python |
| .NET and ASP.NET | Supported via .NET | Native support |
| Control Panel | cPanel, Plesk, Webmin, or custom setups | Plesk or custom setups |
| Security Model | Open source code with a large community patch cycle | Proprietary code with Microsoft-managed patching |
| Ideal For | Web apps, databases, APIs, and development workloads | .NET applications, Exchange, and Active Directory |

Windows Server is the right choice if your applications depend on .NET Framework (not Core), IIS-specific features, or Microsoft middleware like Active Directory. For almost everything else, Linux dedicated hosting delivers the same or better performance at a lower total cost because you are not paying for a Windows Server licence.

## Atlantic.Net Linux dedicated hosting

Atlantic.Net has operated since 1994. It is privately owned and profitable, which means decisions are made for the long term rather than for quarterly targets.

A few things distinguish Atlantic.Net from other Linux server hosting providers:

- The triple 100% SLA covers three separate guarantees: network uptime, hardware replacement, and infrastructure availability. Most providers offer a single uptime guarantee. Atlantic.Net's SLA commits to all three.
- Support is US-based, available 24/7/365, and operates in both English and Spanish. There is no offshore outsourcing. You reach the same team that manages the infrastructure. The support line is 866-618-3282.
- Five US data centers give you geographic options: New York (11 miles from Manhattan), San Francisco, Ashburn, VA, Dallas, TX, and Orlando, FL. You can place workloads close to your users or distribute them across data centers for redundancy.
- The compliance certifications, SOC 2 Type II, SOC 3 Type II, HIPAA, HITECH, and PCI-ready, cover the entire infrastructure, so your dedicated server inherits those certifications without additional audit work on your part.
- additional audit work on your part. Managed add-ons include backups, load balancers, CDN, Security Firewall, IDS, DDoS Protection, and Web Application Firewall. You can build out a complete hosting stack around your dedicated server without sourcing each component from a different provider.

## Frequently Asked Questions

### What Linux distributions does Atlantic.Net support?

Atlantic.Net supports CentOS, Ubuntu, Rocky Linux, Fedora Linux, Debian, Arch Linux, and FreeBSD on dedicated servers. Red Hat Enterprise Linux is available for teams that need it. Custom OS configurations are also supported.

### Do Linux dedicated servers include full root access?

Yes. Every Atlantic.Net Linux dedicated server includes full root access. You control the entire software stack and can install, configure, or modify any component of the Linux operating system.

### Is there a setup fee for dedicated servers?

No setup fee applies to any dedicated server plan. You pay the monthly rate from your first invoice.

### What uptime guarantee does Atlantic.Net offer?

Atlantic.Net provides a triple 100% SLA that covers network uptime, hardware replacement, and infrastructure availability. Each guarantee operates independently, so all three are active simultaneously.

### Can I migrate my existing server to Atlantic.Net?

Yes. Atlantic.Net provides free migration assistance to help you move your workloads from another hosting provider. The support team handles the technical migration process to minimize downtime.

### How does Linux dedicated hosting differ from a VPS?

A dedicated server gives you an entire physical server. A VPS runs as one of many virtual machines on a single physical host, sharing CPU, RAM, and storage with other tenants. Dedicated hosting eliminates the resource contention that affects VPS performance under load and gives you full access to the underlying hardware resources without limits imposed by hypervisor overhead.

## Get started with Linux dedicated hosting

Atlantic.Net dedicated servers are available from $139 per month with no setup fees, full root access, and a triple 100% SLA.

Or call 866-618-3282 to speak with the team about which plan fits your workload.

## Cloud Availability in Multiple Global Regions

Deploy close to your users from eight international data centers worldwide, with new regions on the way.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Data Center Location Guide: Markets, Maps, and Siting Strategy

> URL: https://www.atlantic.net/cloud-platform/data-center-location-guide/ | Published: 2026-06-02 | Updated: 2026-06-05 | Author: Dr. Tehseen Zia

Choosing a data center location is a decision. It can impact latency, costs, compliance risks, and the speed at which a site can go live. The ideal location is generally not the cheapest part of land. It is usually the one that balances connectivity, utility access, regulation, and room to grow. Today, the physical location of servers determines everything from application response times to the final figure on a monthly power bill.

This guide is written for operators, infrastructure teams, and business leaders who need to make decisions about data center locations. It is especially useful for teams planning new deployments, migrating workloads, or expanding into a second region. This guide provides a practical framework for evaluating markets, understanding regional trade-offs, and making decisions based on real-world constraints. While we cover global trends, our examples are rooted in the operational experiences of [Atlantic.Net](https://www.atlantic.net/), a company established in 1994 and now operating across multiple regions/continents.

The focus is on three key areas to selecting a data center location: mapping, counting, and site selection. Mapping deals with identifying where demand is and where important infrastructure exists. This includes fiber networks, carriers, cloud connections, and submarine cable routes. Counting focuses on measuring real-world limitations, particularly power availability and the time required to deliver that power. Site selection focuses on narrowing down the best locations by evaluating factors such as permitting requirements, tax incentives, and access to skilled labor. Recent market data highlights the importance of these factors. According to [CBRE](https://www.cbre.com/insights/briefs/north-america-data-center-trends-h1-2025-ai-and-hyperscaler-demand-lead-to-record-low-vacancy), power availability and delivery timelines heavily influence data center site selection, while many planned projects are experiencing delays due to permitting, zoning, and power procurement challenges.

## Why Data Center Location Matters

This section highlights three key factors that make data center location selection essential: latency, power availability, and regulatory requirements.

Latency: The physical path a packet must travel affects response time, especially for interactive applications, trading systems, streaming, and distributed cloud services. [Cable landing stations](https://blog.equinix.com/blog/2024/10/15/what-is-a-cable-landing-station/) matter here because they connect undersea cables to land-based networks, and nearby data centers often play a role in this connection. Generally, shorter and more network paths lead to better performance for users.

Power: Since 2020, electricity demand in the United States has been rising, with data centers [contributing](https://www.eia.gov/todayinenergy/detail.php?id=65264) to that growth. On the other hand, power availability and delivery timelines also play [important](https://www.cbre.com/insights/briefs/north-america-data-center-trends-h1-2025-ai-and-hyperscaler-demand-lead-to-record-low-vacancy)roles in site selection and data center pricing. A site that seems cheap on paper can turn out to be expensive once utility upgrades, backup systems, and interconnection delays are added in. A good site is generally [one](https://www.eia.gov/todayinenergy/detail.php?id=67344) where power is available, reliable, and scalable enough to support future load growth.

Regulations and tax policy: State and local policies [can affect](https://graham.umich.edu/media/files/Data-Center-Guidebook-2026-02-06.pdf) property taxes, water use, zoning, and the pace of development, while tax breaks and waivers can significantly alter project costs. In other words, a location is evaluated not just by what it costs to build but by what it costs to operate over time.

## Atlantic.Net Data Center Locations and Hubs

Atlantic.Net has eight [data center regions](https://www.atlantic.net/hipaa-data-centers/) globally, including New York City, Northern Virginia/Ashburn, Orlando, Dallas, San Francisco, Toronto, London, and Singapore. Each location was selected for its connectivity, infrastructure, and regional advantages.

New York provides low-latency access for financial and enterprise customers. Ashburn, located in Virginia’s well-known Data Center Alley, is one of the largest internet exchange hubs worldwide. Orlando serves as Atlantic.Net’s headquarters and flagship HIPAA-audited facility with strong carrier connectivity. Dallas connects central U.S. markets to Latin America. San Francisco focuses on technology companies across the West Coast. Toronto supports Canadian data residency requirements, London provides access to UK and European markets, and Singapore SG5 extends Atlantic.Net’s cloud presence into Asia-Pacific with renewable-powered infrastructure and extensive subsea cable connectivity.

Globally, major data center hubs are found in regions with high demand, reliable power, and dense fiber networks. Key markets include Northern Virginia, New York/New Jersey, Silicon Valley, Dallas, Chicago, London, Amsterdam, Frankfurt, Singapore, Tokyo, Seoul, Sydney, São Paulo, and Mexico City. These locations support large cloud and enterprise workloads while offering strong internet and carrier connectivity.

Access to submarine cables is crucial when planning a data center. Locations like Singapore, Virginia Beach, New York/New Jersey, Boston, Los Angeles, San Francisco, and Seattle serve as major landing points for cables connecting North America, Europe, Latin America, and Asia. If a data center is located near these routes, it will have lower latency, better connectivity, and improved reliability. Atlantic.Net has positioned several of its facilities in carrier-neutral environments, including Equinix-operated sites, to provide access to these global network connections.

Power availability and network infrastructure continue to play a major role in defining leading data center markets. Northern Virginia and Northern New Jersey remain key locations due to their reliable utility infrastructure and extensive fiber connectivity. Singapore remains a key hub for global subsea traffic, despite land and energy challenges. Dallas and Atlanta are growing because of their dependable power grids and increasing connectivity. Other markets, like Phoenix and Salt Lake City, have infrastructure but may face challenges with water supply, environmental regulations, or sustainability requirements.

## Where Data Centers Are Located

Choosing the right location for a data center requires evaluating infrastructure, connectivity, regulations, and workforce availability. Several factors influence the decision.

### Grid Capacity and Energy Planning

Any data center requires reliable and scalable power. Markets with planned energy expansion projects are often more appealing because they can accommodate future growth. California, for example, continues to [invest](https://pv-magazine-usa.com/2025/08/08/californas-2-billion-solar-and-energy-storage-facility-is-activated/) in solar and battery storage projects. Virginia [expects](https://servercountry.org/power/virginia/) an increase in power capacity by 2035 to fulfill the demand of data centers.

On the other hand, regions with aging power grids or restrictions can present challenges. [Amsterdam](https://www.worldstream.com/en/power-grid-congestion-in-amsterdam-rotterdam-emerges-as-colocation-hub/) has temporarily limited new data center projects due to electricity constraints. Organizations should consider utility expansion plans, renewable energy initiatives, and long-term grid reliability when choosing a location. New solutions like [microgrids](https://www.ibm.com/think/topics/microgrid) and [district heating systems](https://www.danfoss.com/en/about-danfoss/our-businesses/heating/knowledge-center/heating-school/how-does-district-heating-work/) are becoming part of modern energy planning.

### Fiber, Carrier, and Cloud Connectivity

Reliable connectivity is just as important as power availability. Data centers [benefit](https://broadbandbreakfast.com/dateline-ashburn-the-interplay-between-ixps-and-data-centers/) from being located near major [fiber routes, internet exchange points](https://www.areadevelopment.com/data-centers/q2-2023/data-center-sites-whats-your-connection.shtml), and carrier hubs. Large clusters in the U.S. often develop near major [network corridors](https://www.coresite.com/blog/top-10-u-s-data-center-markets-and-why-they-are-hot), such as Boston to New York and Ashburn on the East Coast, and Los Angeles to San Francisco on the West Coast.

Atlantic.Net and many other providers use [carrier-neutral facilities](https://www.digitaledgedc.com/resources/interconnection/carrier-neutral-data-centers-and-their-benefits-to-customers/) for direct access to telecom carriers and cloud platforms. When evaluating a market, planners should consider local fiber infrastructure, internet exchange points, and upcoming network expansion projects.

### Taxes, Incentives, and Regulations

Government incentives can play a role in the development of a data center. [Several U.S. states](https://www.datacenters.com/services/capacity/tax_incentives), including Texas, Georgia, New York, and Ohio, have offered tax incentives to attract investment. These programs may change as energy demand grows and governments reassess infrastructure costs.

Regulations also vary by region. Ireland has attracted cloud providers with lower [corporate tax rates](https://qz.com/523787/tech-giants-stay-in-ireland-and-pay-even-less-in-corporate-tax), while countries such as [China](https://www.chinafy.com/blog/what-is-data-localization-in-china) and [India](https://www.techpolicy.press/data-localization-indias-tryst-with-data-sovereignty/) enforce stricter data localization rules. Organizations should also evaluate environmental regulations, construction requirements, energy policies, and data sovereignty laws when selecting a location.

### Workforce and Training

Access to skilled workers is another consideration. Data centers rely on trained technicians, engineers, and IT professionals to support daily operations. Established markets such as Silicon Valley and Northern Virginia already have strong talent pools, while growing markets like Atlanta and Raleigh are expanding workforce development programs.

Partnerships among technology companies, colleges, and local governments are helping build skilled labor pipelines—initiatives such as [Google’s STAR Program](https://datacenters.google/workforce-development-program/) and [Microsoft’s Datacenter Academy](https://careers.microsoft.com/v2/global/en/datacenteracademy.html) focus on training future data center professionals. Organizations should review local education programs and workforce initiatives when evaluating new markets.

## Atlantic.Net Data Center Hosting Features

Atlantic.Net’s global sites all provide the core managed hosting and cloud services of the Atlantic.Net Cloud Platform, but each location has its own distinguishing features:

- [Ashburn, Virginia](https://www.atlantic.net/hipaa-data-centers/ashburn-virginia-hosting/): Located in “[Data Center Alley](https://www.digitalrealty.com/resources/blog/northern-virginia-ashburn-data-centers)” near Washington D.C., this facility provides IPv6 support, HIPAA-compliant hosting, cloud VPS, and colocation, along with a guaranteed 100% uptime SLA. As a carrier-neutral provider, it connects to nearly every major network. Ashburn’s infrastructure is audited for [HIPAA](https://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act) and [PCI DSS](https://www.pcisecuritystandards.org/standards/pci-dss/), reflecting Atlantic.Net’s focus on compliance in this hub.
- [New York City (NJ Metro)](https://www.atlantic.net/hipaa-data-centers/new-york-hosting/): Located 11 miles from Manhattan in a Telx/Digital Realty facility, this center offers low-latency access to NYC and the Northeast. It provides the full range of Atlantic.Net services, including cloud hosting, HIPAA and PCI-compliant hosting, dedicated servers, and managed services. IPv4/IPv6 dual stack is available. The top-notch connectivity of this site serves financial and enterprise clients.
- [Dallas, Texas](https://www.atlantic.net/hipaa-data-centers/dallas-texas-hosting/): As the central U.S. hub for Atlantic.Net, the Dallas center is carrier-neutral (NTT’s TX1 campus) and serves clients nationwide and into Latin America. It supports dedicated hosting, cloud hosting, HIPAA, PCI, and more, with IPv6 options. This facility is designed for high availability (100% SLA) with strong Texas power reliability.
- [San Francisco (Silicon Valley)](https://www.atlantic.net/hipaa-data-centers/san-francisco-california-hosting/): Atlantic.Net’s Bay Area facility in Santa Clara, with Digital Reality,y provides West Coast latency to tech markets. It is SOC 2, SOC 3, and HIPAA-compliant, supporting both IPv4 and IPv6. Like other regions, it offers a full range of Atlantic.Net VPS/cloud hosting plans at competitive prices.
- [Toronto, Canada](https://www.atlantic.net/hipaa-data-centers/toronto-canada-hosting/): Located in Scarborough and partnered with [Cologix](https://cologix.com/), this site facilitates Canadian data residency. It provides core services, including cloud and dedicated servers, compliant with Canada’s [PIPEDA](https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/) privacy laws. All services hold PCI, HIPAA/HITECH, and [SSAE-16](https://en.wikipedia.org/wiki/SSAE_16) certifications. The Toronto center has strong physical security features and redundant power supplies. Like other Atlantic sites, this site also provides a 100% uptime SLA.
- [London, UK](https://www.atlantic.net/hipaa-data-centers/london-uk-hosting/): Atlantic.Net’s presence in London is at the Virtus London4 data center (near Heathrow). This Tier III facility has 34 MVA capacity and a 23 MW IT load with N+N UPS. It is fully audited for ISO and environmental standards and provides both cloud servers and dedicated servers. Customers in London get low-latency European connectivity along with a wide choice of OS and one-click apps. The site also has green credentials to ensure reliability.
- [Orlando, Florida](https://www.atlantic.net/orlando-colocation-hosting-data-center/): Atlantic.Net’s headquarters and flagship HIPAA facility, Orlando is a carrier-neutral colocation hub. It supports compliance workloads (PCI, HIPAA) and SOC 2/SOC 3 certification. Multiple Tier 1 providers connect here for Internet access. Colocation options include flexible rack and cabinet space backed by redundant HVAC and fire suppression.
- [Singapore](https://www.atlantic.net/hipaa-data-centers/singapore-hosting/): Atlantic.Net’s newest site is in a state-of-the-art [Equinix SG5](https://www.equinix.com/data-centers/asia-pacific-colocation/singapore-colocation/singapore-data-center/sg5) International Business Exchange (IBX) facility. It offers all cloud and VPS services to customers in APAC, including dedicated cloud hosts and managed services. Key features include 100% renewable energy, advanced cooling, and backup power systems. SG5 provides direct connectivity to over 70 global Internet backbones, ensuring high-speed, low-latency connections worldwide. Like other Atlantic sites, it provides a 100% SLA.

## Regional Data Center Case Studies and Trends

Northern Virginia is a classic example of how data center clusters develop and the challenges that eventually limit their growth. [CBRE reports](https://www.cbre.com/insights/books/north-america-data-center-trends-h2-2025) that this market led North America in net absorption in 2025, but many planned projects continue to face delays due to permitting, zoning, and power procurement challenges. This is the classic trade-off of clusters: the market attracts demand because of its ecosystem, but that same success can slow growth when land, power, and approvals become limited.

East Coast subsea links remain important, as they provide connectivity between North America and Europe. [Cable landing stations](https://blog.equinix.com/blog/2024/10/15/what-is-a-cable-landing-station/) connect submarine systems to terrestrial networks, allowing data centers near these sites to benefit from shorter backhaul and improved routing. This is why locations like New York, New Jersey, Virginia, and nearby coastal interconnection hubs remain, even in a cloud-first environment.

South America is growing, but power and infrastructure remain the deciding factors. [CBRE’s 2025 report](https://www.cbre.com/insights/reports/global-data-center-trends-2025) shows São Paulo as the leader in absorption, followed by Santiago, while energy restrictions limited growth in Querétaro. Regional reports also raise concerns about energy supply, sustainability, and water pressure. Emerging hubs can provide opportunities, but only if the power plan can adequately support development.

## Actionable Market Analysis Steps

### 1. Identify Priority Markets

Start by focusing on regions with strong infrastructure, reliable power, and growing demand for cloud and enterprise services. In the United States, leading expansion markets include Atlanta, Phoenix, Chicago, and Northern Virginia. In Europe, major hubs include Frankfurt, London, and Paris, while Singapore, Tokyo, Sydney, and India continue to grow across the Asia-Pacific. In Latin America, Mexico City, Querétaro, and São Paulo remain important locations.

Within each market, evaluate sub-regions based on fiber connectivity, subsea cable access, internet exchanges, and power availability. Locations close to major network routes and cable landing stations often provide better performance and long-term scalability.

### 2. Model Power and Procurement Timelines

Power planning should begin early because utility approvals and infrastructure upgrades can take years. In some markets, connecting a large data center to the grid may take between two and six years due to permitting, transmission work, or substation construction.

Organizations should consider local utility timelines, approvals, and construction. If a project needs new transmission lines or substations, additional delays are expected. Atlantic.Net’s experience in markets such as New York and Florida shows that utility upgrades and renewals can also require years, making early coordination essential.

### 3. Estimate Permitting and Construction Timelines

Permitting and construction schedules vary by region. In the United States, approvals may take one to two years, while projects in Europe or Asia might face longer environmental and zoning reviews. Cities like Paris and Amsterdam have implemented stricter local regulations that can delay development timelines.

Construction planning should also account for supply chain delays in essential equipment, such as transformers and generators. Generally, organizations should expect a full data center project to take approximately three to five years from planning to operational launch.

## The Bottom Line

The decision about data center location should be based on a range of factors, not just land cost. The best location should combine low latency, reliable and expandable power, strong fiber connectivity, practical permitting, and favorable tax and regulatory conditions. Markets with dense infrastructure can provide benefits, but longer utility timelines, zoning regulations, and power limitations can hinder growth and restrict expansion.


---

# Atlantic.Net Launches Fortress Portfolio to Reinforce Commitment to Secure, High-Performance Cloud and Hosting Solutions

> URL: https://www.atlantic.net/press-releases/atlantic-net-launches-fortress-portfolio-to-reinforce-commitment-to-secure-high-performance-cloud-and-hosting-solutions/ | Published: 2026-06-09 | Updated: 2026-06-23 | Author: Editorial Team

ORLANDO (June 9, 2026) As business leaders across the globe are seeking more security and observability in its cloud infrastructure, [Atlantic.Net](http://atlantic.net/) heeds the call with the rollout of its new Fortress cloud service portfolio. This strategic initiative highlights the company’s continued focus on security-first infrastructure to ensure businesses continue to stay and operate securely online.

The move reflects a broader industry shift toward security-centric cloud environments, where protection against cyber threats, data breaches, and compliance risks are critical to maintaining operations. Atlantic.Net’s Fortress offerings are designed to provide customers with hardened infrastructure, built-in compliance capabilities, and reliable uptime—ensuring they can operate securely in a digital-first world.

“In today’s rapidly evolving threat landscape, security is no longer optional—it is foundational,” said Marty Puranik, CEO of Atlantic.Net. “The introduction of our Fortress portfolio underscores our commitment to delivering infrastructure that not only performs but protects. Businesses need confidence that their systems are secure, compliant, and always available.”

As part of this update, Atlantic.Net has enhanced its offerings to reflect its commitment in providing robust security, resilience, and operational continuity. Plans include:

- [Dedicated Server Hosting](https://www.atlantic.net/dedicated-server-hosting/) includes the popular Fortress Enterprise Plan built for compliance ready security for regulated and mission-critical workloads.

  - Other plans include standard, business and custom solutions
- [HIPAA-Compliant Hosting](https://www.atlantic.net/hipaa-compliant-hosting/) designed to secure and protect critical health data, electronic protected health information (ePHI), and records,
- [PCI-Compliant Hosting](https://www.atlantic.net/pci-compliant-hosting/) includes its Fortress Custom plan that offers maximum security, customization and premium SLAs,
- [Cloud Platform](https://www.atlantic.net/cloud-platform/): Engineered to deliver fault-tolerant, ultra-fast performance for the workloads driving your computing strategy forward.

With cyber threats continuing to rise globally, organizations across industries are prioritizing secure cloud adoption. Atlantic.Net’s Fortress portfolio aims to deliver the confidence and performance businesses need to scale safely and maintain uninterrupted service.

This evolutionary offering reinforces the company’s long-standing, 32-year reputation for providing secure hosting while aligning with the future direction of cloud infrastructure.

**About Atlantic.Net**

Founded in 1994, [Atlantic.Net](https://www.atlantic.net/) is a privately held global cloud infrastructure provider with customers in over 100 countries, known for delivering secure, compliant, on-demand and customizable hosting solutions. With decades of experience, Atlantic.Net is one of the world’s most trusted and experienced hosting providers, offering 24/7 U.S.-based support. Specializing in security, compliance, and customer service, Atlantic.Net serves a diverse range of industries with solutions including HIPAA-compliant hosting and PCI-compliant hosting, backed by bare metal servers, dedicated hosting, GPU hosting, colocation, and its award-winning Cloud Platform. Operating from eight strategically located data center regions across the United States, Canada, the United Kingdom, and Asia, Atlantic.Net powers mission-critical workloads for organizations worldwide. For more information, visit[Atlantic.Net](https://www.atlantic.net/) or connect with us on[Facebook](https://www.facebook.com/Atlantic.Net),[X (Twitter)](https://twitter.com/AtlanticNet),[LinkedIn](https://www.linkedin.com/company/atlantic.net-inc./posts/?feedView=all), and[YouTube](https://www.youtube.com/c/AtlanticNet).


---

# How to Set and Change Hostname in Rocky Linux

> URL: https://www.atlantic.net/dedicated-server-hosting/how-to-set-and-change-hostname-in-rocky-linux/ | Published: 2026-06-17 | Updated: 2026-06-18 | Author: Hitesh Jethva

When working in a local environment, each system is assigned an IP address to distinguish it from other hosts on the network. However, remembering IP addresses for every **server** can be difficult, especially in large infrastructures. A hostname provides a more user-friendly way to identify systems and allows machines to communicate using names instead of IP addresses.

This guide explains how to perform a Rocky Linux change hostname operation using several methods. The instructions apply to both Rocky Linux 9 and Rocky Linux 10. If you are migrating from CentOS or another Linux distribution, the process is very similar.

## Step 1 – Check Your Current Hostname

Before you change hostname settings, it is important to check the current hostname configured on your system.

You can check it using the following command:

```
hostnamectl
```

You should see the current hostname of your system in the following output:

```
     Static hostname: rocky
           Icon name: computer-vm
             Chassis: vm 🖴
          Machine ID: c0b9710ec77a40fd91a1887844dc0166
             Boot ID: af19459c03a44f9383ba620f61dd6f44
        Product UUID: c0b9710e-c77a-40fd-91a1-887844dc0166
      Virtualization: kvm
    Operating System: Rocky Linux 10.0 (Red Quartz)       
         CPE OS Name: cpe:/o:rocky:rocky:10::baseos
      OS Support End: Thu 2035-05-31
OS Support Remaining: 9y 7month 2w                        
              Kernel: Linux 6.12.0-55.21.1.el10_0.x86_64
        Architecture: x86-64
     Hardware Vendor: QEMU
      Hardware Model: Standard PC _i440FX + PIIX, 1996_
    Firmware Version: 1.15.0-1
       Firmware Date: Tue 2014-04-01
        Firmware Age: 11y 6month 2w
```

The output provides useful system information, including the **static hostname**, **KVM operating system** details, **computer VM chassis** information, **VM machine ID**, **cpe os** identifier, and **Red Hat hardware model** compatibility details.

As you can see, the current hostname of your system is rocky.

#### Also Read

[How to Set Path in Linux](https://www.atlantic.net/vps-hosting/how-to-set-path-variable-in-linux/)

## Step 2 – Change the Hostname Temporarily

If you want to change the hostname of your system temporarily, you can use the following syntax:

```
hostname new-hostname
```

After a reboot, logout, or restart, the **new hostname** will revert to the previous hostname.

For example, to change the hostname to **newpc**, run the following command:

```
hostname newpc
```

This method is useful for testing changes in a development **environment** before applying them permanently.

## Step 3 – Change the Hostname Permanently

The recommended method is to use the **hostnamectl command**. This utility updates the system’s **static hostname** and allows you to **modify** hostname settings without editing configuration files manually.

Use the following syntax:

```
hostnamectl set-hostname new-hostname
```

For example, to change the hostname of your system to **newpc**, run the following command:

```
hostnamectl set-hostname newpc
```

After running the command, **verify** the change with:

```
hostnamectl
```

The system will immediately **update** the hostname for the current session and future reboots.

### Optional: Set a Pretty Hostname

Linux systems also support a **pretty hostname**, which is a more descriptive display name that can contain spaces and special characters. This is useful for desktop systems and virtual machines.

Example:

```
hostnamectl set-hostname "Production Web Server" --pretty
```

The pretty hostname does not replace the actual hostname used by the **network**.

## Step 4 – Change the Hostname Using /etc/hostname File

You can also change the hostname by editing the hostname configuration file. In this case, you will need to restart your system to apply the changes.

To change the hostname, edit the **/etc/hostname** file:

```
nano /etc/hostname
```

Replace the old hostname with a new hostname:

```
newpc
```

Save the file and **exit** the editor. Then restart your system to apply the changes:

```
reboot
```

#### Also Read

[How to Change or Set User Password in Linux](https://www.atlantic.net/vps-hosting/how-to-change-or-set-user-passwords-in-linux/)

## Step 5 – Update the /etc/hosts File

After changing the hostname, it is a good practice to **modify** the **etc hosts** file so local hostname resolution continues to work correctly.

Open the file:

```
nano /etc/hosts
```

You may see entries similar to:

```
127.0.0.1   localhost localhost.localdomain
127.0.1.1   newpc
```

Ensure the new hostname is associated with **localhost** or the appropriate local IP address.

If your **server** uses a **domain**, you can also configure an **FQDN** (Fully Qualified Domain Name):

```
192.168.1.10   server.example.com server
```

This helps applications resolve the hostname correctly across the **network**.

## Step 6 – Change the Hostname Using NMTUI Tool

You can also change the hostname using the Network Manager Text User Interface (NMTUI).

To **start** the utility, run:

```
nmtui
```

You should see the following dialog box:
 ![nmtui dialog page](https://www.atlantic.net/wp-content/uploads/2022/02/p1-3.png)
 Select **Set system hostname** and press the **Enter** key. You should see the following dialog box:
 ![nmtui set new hostname page](https://www.atlantic.net/wp-content/uploads/2022/02/p2-2.png)
 Type your new hostname and click on the **OK**. You should see the following dialog box:
 ![nmtui save new hostname page](https://www.atlantic.net/wp-content/uploads/2022/02/p3-1.png)
 Click on the **OK** button to change the hostname.

## Verify the New Hostname

Once you have changed the hostname using any method, verify the change with:

```
hostnamectl
```

You can also confirm hostname resolution through the **etc hosts** file and test communication between systems on the **network**.

For systems connected to a **domain**, verify that the configured **FQDN** resolves correctly.

## Conclusion

In this tutorial, we demonstrated several ways to perform a **Rocky Linux change hostname** operation. We covered the **hostnamectl command**, editing the /etc/hostname file, updating **etc hosts**, configuring a **static hostname**, and using the NMTUI interface. We also discussed hostname verification, **localhost** configuration, **FQDN** setup, and hostname management in virtualized **kvm operating system** deployments.

Whether you manage a single **server** or hundreds of **hosts** in a production **environment**, following this **guidance** will help you efficiently **change hostname**, **add** proper hostname mappings, and **update** system identification settings in Rocky Linux.


---

# How to Use AUR with Arch Linux

> URL: https://www.atlantic.net/dedicated-server-hosting/how-to-use-aur-with-arch-linux/ | Published: 2026-06-17 | Updated: 2026-06-18 | Author: Hitesh Jethva

AUR, also known as the Arch User Repository, is a community-driven repository for Arch-based Linux distributions. It allows Arch Linux users to compile and install packages from source code using package build scripts called PKGBUILDs. The repository AUR contains thousands of community-maintained applications that are not available in the official repositories.

This guide is designed for Linux administrators, developers, and Arch users who want to expand their software options beyond the default repositories. It explains how to configure your system, install an AUR helper, perform a package search, and manually build packages from source.

The AUR is valuable because it provides access to new packages, development tools, and applications that may not yet be included in the official repositories. However, AUR packages are user-created and come with risks. While Trusted Users help maintain package quality, they cannot guarantee complete safety.

Some important facts about AUR include:

- AUR packages are built from PKGBUILDs using makepkg.
- Install base-devel to compile AUR packages from source.
- The command to build and install AUR packages manually is makepkg -si.
- AUR helpers can lead to safety risks if users do not review the PKGBUILD.
- Malicious code has been found in AUR packages.
- Trusted Users monitor AUR but cannot guarantee safety.
- Inspect PKGBUILDs and install files before building packages.
- Using an AUR helper is the preferred method for many Arch users.
- Popular AUR helpers include Yay, Yaourt, and Packer.

In this post, we will show you how to use AUR with Arch Linux.

## Understanding How AUR Works

Unlike the official repositories, AUR generally does not host precompiled software packages. Instead, it provides package descriptions, metadata, PKGBUILD scripts, and install instructions that tell your system how to download source code, resolve required dependencies, and build packages.

The typical build process works as follows:

1. Perform a package search.
2. Review package descriptions and package details.
3. Download or clone the package repository using git.
4. Review PKGBUILD and other related files.
5. Install dependencies.
6. Build packages using makepkg.
7. Install the package with pacman.

This approach gives users flexibility while allowing the AUR community to contribute new software and package updates.

## Step 1 – Configure Repository

Before working with AUR, it is a good idea to update your mirror configuration. Configuring a fast mirror list can improve download speeds and reduce package synchronization issues.

By default, the default repository is outdated in Arch Linux, so you will need to modify the default mirror list if you have not done so already. You can do it by editing the mirrorlist configuration file:

```
nano  /etc/pacman.d/mirrorlist
```

Remove all lines and add the following lines:

```
## Score: 0.7, United States
Server = http://mirror.us.leaseweb.net/archlinux/$repo/os/$arch
## Score: 0.8, United States
Server = http://lug.mtu.edu/archlinux/$repo/os/$arch
Server = http://mirror.nl.leaseweb.net/archlinux/$repo/os/$arch
## Score: 0.9, United Kingdom
Server = http://mirror.bytemark.co.uk/archlinux/$repo/os/$arch
## Score: 1.5, United Kingdom
Server = http://mirrors.manchester.m247.com/arch-linux/$repo/os/$arch
Server = http://archlinux.dcc.fc.up.pt/$repo/os/$arch
## Score: 6.6, United States
Server = http://mirror.cs.pitt.edu/archlinux/$repo/os/$arch
## Score: 6.7, United States
Server = http://mirrors.acm.wpi.edu/archlinux/$repo/os/$arch
## Score: 6.8, United States
Server = http://ftp.osuosl.org/pub/archlinux/$repo/os/$arch
## Score: 7.1, India
Server = http://mirror.cse.iitk.ac.in/archlinux/$repo/os/$arch
## Score: 10.1, United States
Server = http://mirrors.xmission.com/archlinux/$repo/os/$arch
```

Save and close the **file**, then update all package indexes with the following command:

```
pacman -Syu
```

This command synchronizes your system with the latest packages available in the official repositories.

## Step 2 – Create a New User

For security reasons, it is recommended not to build AUR packages directly as root. Since package builds can execute scripts during installation, creating a regular user helps reduce **risk**.

You can now use the AUR package as a root user, so you will need to create a new user to use the AUR package.

First, create a new user with the following command:

```
useradd -m user1
```

Next, set a password for a user with the following command:

```
passwd user1
```

Next, edit the sudoers file:

```
nano /etc/sudoers
```

Uncomment the following line:

```
 %wheel ALL=(ALL:ALL) NOPASSWD: ALL
```

Save and close the file, then add the user to the wheel group:

```
usermod -aG wheel user1
```

## Step 3 – Install AUR Helper Script

The **simplest way** to work with AUR is by using an **AUR helper**. An AUR helper automates package downloads, dependency resolution, package builds, updates, and package removal.

Popular AUR helpers include:

- Yay
- Yaourt
- Packer

However, remember this important warning:

**Warning AUR packages:** AUR helpers can lead to safety risks if users do not review the PKGBUILD.

Before installing software, inspect:

- PKGBUILD
- Install files
- Package descriptions
- Dependencies
- Related files
- Source URLs

This is considered a good packaging technique.

First, log in as user1 and install the necessary build tools using the following command:

```
su - user1
sudo pacman -S --needed base-devel git
```

You will be asked to choose which you’d like to install.
 ![AUR select package to install](https://www.atlantic.net/wp-content/uploads/2022/10/p1-3.png)
 Select “all” option and press the Enter key. You should see the following screen:
 ![AUR proceed with installation](https://www.atlantic.net/wp-content/uploads/2022/10/p2-3.png)

Type Y and press the Enter key to proceed with the installation.

Next, download the YAY tool with the following command:

```
git clone https://aur.archlinux.org/yay.git
```

The **git clone** command downloads the package source into a local **directory**.

Next, navigate to the downloaded directory and build the package with the following command:

```
cd yay
makepkg -si
```

AUR packages are built from PKGBUILDs using makepkg.

The makepkg -si command performs the complete build process, installs required dependencies, creates a package, and installs it using Pacman.

### Searching for Packages in AUR

Before installing software, you can perform a package search to find available packages and review package descriptions.

For example:

```
yay -Ss package-name
```

This command displays package descriptions, package details, popularity information, and other useful information.

## Step 4 – How to Use YAY to Install AUR Package

The basic syntax to use YAY is shown below:

```
yay -S package-name
```

For example, to install the unzip command, run the following command:

```
yay -S unzip
```

This command downloads source files, resolves dependencies, performs package builds, and installs the package.

If you want to uninstall the package, run the following command:

```
yay -Rns unzip
```

To remove unwanted dependencies, run the following command:

```
yay -Yc
```

Yay works similarly to **pacman**, making package management easier for Arch Linux users.

## Step 5 – Install AUR Package Manually

Although Yay is convenient, some users prefer manual installation. This method provides greater visibility into package source code and package builds.

You can install packages from the AUR entirely manually by following official guidelines.

Let’s download the Google Chrome package with the following command:

```
git clone https://aur.archlinux.org/google-chrome.git
```

Next, navigate to the downloaded package and compile it with the following command:

```
cd google-chrome
makepkg -si
```

The command above downloads source code, resolves dependencies, compiles software, creates a package, and installs it.

This approach is often preferred when auditing package contents, troubleshooting an error, creating your **own package**, or learning how package builds work.

## AUR Security Best Practices

Before installing software from AUR, keep the following recommendations in mind:

- AUR packages are user created and come with risks.
- Malicious code has been found in AUR packages.
- Trusted Users monitor AUR but cannot guarantee safety.
- Inspect PKGBUILDs and install files before building packages.
- Review package descriptions and package details.
- Verify the software uses a **compatible license**.
- Review package dependencies carefully.
- Check package comments and update history.
- Use AUR packages at your **own risk**.
- Prioritize official repositories whenever possible.

Some organizations maintain a **custom repository** internally instead of relying entirely on community packages.

## AUR vs Official Repositories

The official repositories start with software packages reviewed and maintained by Arch developers. AUR, on the other hand, is maintained by the community.

Official repositories provide:

- Better security
- Better testing
- Faster updates
- Greater stability

AUR provides:

- New packages
- Community software
- Development versions
- Niche applications
- Popular packages inclusion before they reach official repositories

Because of these differences, many users install software from official repositories first and use AUR only when necessary.

## Conclusion

In this post, we explained how to use the Arch User Repository in Arch Linux. You learned how to configure mirrors, install development tools, use sudo pacman and Yay, perform a package search, and manually build packages using makepkg.

You also learned why AUR packages require additional attention. While the AUR community provides access to thousands of useful applications, package quality can vary. Always inspect PKGBUILDs, install files, dependencies, and package details before installation. Review source code, logs, and package information carefully to minimize security risks.

For most Arch Linux users, using an AUR helper such as Yay is the preferred method because it simplifies package management. However, understanding the manual build process is valuable when troubleshooting software, auditing package contents, creating your own package, or contributing improvements back to the community.

By following the best practices outlined in this guide, you can safely install software from the AUR while maintaining a stable and secure Arch Linux system. You can now use AUR to install additional software that is not available in the Arch Linux default repository and take advantage of the vast ecosystem maintained by the Arch community.

 


---

# How to Install Asterisk and FreePBX on Ubuntu

> URL: https://www.atlantic.net/vps-hosting/how-to-install-asterisk-and-freepbx-on-ubuntu/ | Published: 2026-06-18 | Updated: 2026-06-22 | Author: Hitesh Jethva

Asterisk is an open-source communications platform used to build a modern VoIP infrastructure on Linux systems. It supports voicemail, conference calling, IVR menus, call recording, SIP trunk connectivity, SIP endpoints, and outbound calls using the Session Initiation Protocol (SIP).

FreePBX is a free web-based management interface for Asterisk that simplifies administration through a browser. It allows administrators to create extensions, configure trunks, manage users, control permissions, and deploy a basic PBX copy of existing configurations for testing or migration purposes.

Ubuntu 24.04 LTS provides a stable and secure foundation for deploying Asterisk and FreePBX. Ubuntu 24.04 LTS receives security patches until April 2036, while Canonical provides timely security updates, with critical CVEs often patched in under 24 hours. Combined with Asterisk 20 LTS, which is supported until 2027, this platform offers a reliable long-term solution for building and managing business communications systems.

This guide explains how to install Asterisk on Ubuntu 24.04, perform a complete Asterisk installation, and deploy FreePBX using Asterisk 20 LTS.

## Step 1 – Install Required Dependencies

Before starting, update your package index and enable the Universe repository.

```
sudo add-apt-repository universe -y
sudo apt update
```

Asterisk requires libraries like libxml2-dev and libssl-dev and git package for several build scripts and development workflows. You can install all required dependencies, development libraries, and build tools:

```
sudo apt-get install sox pkg-config libedit-dev unzip git gnupg2 curl libnewt-dev libssl-dev libncurses5-dev subversion libsqlite3-dev build-essential libjansson-dev libxml2-dev uuid-dev subversion -y
```

Once all packages installed successfully, you can proceed with the installation.

## Step 2 – Install Asterisk

First, download the latest version of Asterisk from the Asterisk official website using the following command:

```
wget https://downloads.asterisk.org/pub/telephony/asterisk/asterisk-20-current.tar.gz
```

Once the download is completed, extract the downloaded tar package file with the following command:

```
tar -xvzf asterisk-20-current.tar.gz
```

Next, use the cd command to change the directory to the extracted directory and install the required dependencies with the following command:

```
cd asterisk-20.*/
sudo contrib/scripts/get_mp3_source.sh 
sudo contrib/scripts/install_prereq install
```

Next, run the following configure script to configure Asterisk:

```
sudo ./configure
```

The configure script prepares the source code for your Ubuntu environment and Linux kernel.

Next, set the menu options with the following command:

```
sudo make menuselect
```

Before continuing, you can save a menuselect copy of your selected build options. This is useful when deploying newer versions of Asterisk later.

You can use **the Arrow** key to navigate and **the Enter** key to select.

**Enable required add-ons:**

![](https://www.atlantic.net/wp-content/uploads/2020/12/Asterisk1.png)

**Enable Core Sound Packages**

![](https://www.atlantic.net/wp-content/uploads/2020/12/Asterisk2.png)

**Enable MOH packages**

![](https://www.atlantic.net/wp-content/uploads/2020/12/Asterisk3.png)

**Enable Extra Sound Packages**

![](https://www.atlantic.net/wp-content/uploads/2020/12/Asterisk4.png)

Once all the components are installed, build Asterisk with the following command:

```
sudo make -j2
```

Next, install Asterisk using the following command:

```
sudo make install
```

Next, install configs and samples using the following command:

```
sudo make samples
sudo make config
sudo ldconfig
```

## Step 3 – Configure Asterisk

Running Asterisk as the root user poses a major security risk so never run Asterisk as root.

You must create a separate Asterisk user and group. You can create them with the following command:

```
sudo groupadd asterisk
sudo useradd -r -d /var/lib/asterisk -g asterisk asterisk
```

Next, add some required users to the Asterisk group with the following command:

```
sudo usermod -aG audio,dialout asterisk
```

Next, set proper permissions and ownership using the following command:

```
sudo chown -R asterisk:asterisk /etc/asterisk
sudo chown -R asterisk:asterisk /var/{lib,log,spool}/asterisk
sudo chown -R asterisk:asterisk /usr/lib/asterisk
```

Next, edit the /etc/default/asterisk file and set the asterisk user as a default user:

```
sudo nano /etc/default/asterisk
```

Change the following lines:

```
AST_USER="asterisk"
AST_GROUP="asterisk"
```

Save and close the file, then edit the Asterisk default configuration file and define the “run as” user and group:

```
sudo nano /etc/asterisk/asterisk.conf
```

Change the following lines:

```
runuser = asterisk ; The user to run as.
rungroup = asterisk ; The group to run as.
```

Save and close the file, then restart the Asterisk service and enable it to start at system reboot with the following command:

```
sudo systemctl restart asterisk
sudo systemctl enable asterisk
```

Next, verify the status of the Asterisk service with the following command:

```
sudo systemctl status asterisk
```

In some cases, you should get the following error:

```
radcli: rc_read_config: rc_read_config: can't open /etc/radiusclient-ng/radiusclient.conf: No such 
file or directory
```

You can resolve this error using the following commands:

```
sudo sed -i 's";\[radius\]"\[radius\]"g' /etc/asterisk/cdr.conf
```

```
sudo sed -i 's";radiuscfg => /usr/local/etc/radiusclient-ng/radiusclient.conf"radiuscfg => /etc/radcli/radiusclient.conf"g' /etc/asterisk/cdr.conf
```

```
sudo sed -i 's";radiuscfg => /usr/local/etc/radiusclient-ng/radiusclient.conf"radiuscfg => 
/etc/radcli/radiusclient.conf"g' /etc/asterisk/cel.conf
```

Next, start the Asterisk service again with the following command:

```
sudo systemctl start asterisk
sudo systemctl status asterisk
```

Check the installed Asterisk version:

```
sudo asterisk -V
```

Review the installation details carefully before moving forward.

Next, connect to the Asterisk CLI with the following command:

```
sudo asterisk -rvv
```

You should get the following output:

```
Asterisk 20.4.0, Copyright (C) 1999 - 2022, Sangoma Technologies Corporation and others.
Created by Mark Spencer 
Asterisk comes with ABSOLUTELY NO WARRANTY; type 'core show warranty' for details.
This is free software, with components licensed under the GNU General Public
License version 2 and other licenses; you are welcome to redistribute it under
certain conditions. Type 'core show license' for details.
=========================================================================
Running as user 'asterisk'
Running under group 'asterisk'
Connected to Asterisk 22.4.0 currently running on ubuntu2404 (pid = 89531)
```

Exit out of the CLI type:

```
Exit
```

## Step 4 – Install FreePBX

Before installing FreePBX, configure the firewall to allow web access, SIP signaling, and RTP traffic required by Asterisk. Web services such as HTTP and HTTPS use the TCP protocol, while SIP and RTP communications rely primarily on UDP ports for real-time voice transmission.

Asterisk requires dedicated SIP ports for call signaling and a dedicated UDP port range for RTP audio streams. Opening the correct ports ensures that extensions, SIP trunks, and VoIP calls can connect and transmit audio properly.

Run the following commands to allow the required traffic through UFW:

```
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw allow 5060/udp
sudo ufw allow 5061/tcp
sudo ufw allow 10000:20000/udp
sudo ufw enable
```

Next, install the Apache, MariaDB, PHP and other required packages with the following command.

```
sudo apt install mariadb-server apache2 php libapache2-mod-php php-intl php-mysql php-curl php-cli php-zip php-xml php-gd php-common php-mbstring php-xmlrpc php-bcmath php-json php-sqlite3 php-soap php-zip php-ldap php-imap php-cas -y
```

Once all the packages are installed, download the latest version of FreePBX using the following command:

```
wget http://mirror.freepbx.org/modules/packages/freepbx/freepbx-17.0-latest.tgz
```

Once downloaded, extract the downloaded tar file with the following command:

```
tar -xvzf freepbx-17.0-latest.tgz
```

Next, change the directory to the extracted directory and install the Node.js package with the following command:

```
cd freepbx
sudo apt-get install nodejs npm -y
```

Next, set the required permissions with the following command:

```
sudo ./install -n
```

You should get the following output:

```
Setting specific permissions...
30690 [============================]
Finished setting permissions
Generating default configurations...
Finished generating default configurations
You have successfully installed FreePBX
```

Next, install the pm2 package with the following command:

```
sudo fwconsole ma install pm2
```

Next, change the Apache user to Asterisk and turn on the AllowOverride option with the following command:

```
sudo sed -i 's/^\(User\|Group\).*/\1 asterisk/' /etc/apache2/apache2.conf
```

```
sudo sed -i 's/AllowOverride None/AllowOverride All/' /etc/apache2/apache2.conf
```

Next, set upload_max_filesize to php.ini file with the following command:

```
sudo sed -i 's/\(^upload_max_filesize = \).*/\120M/' /etc/php/*/apache2/php.ini
```

```
sudo sed -i 's/\(^upload_max_filesize = \).*/\120M/' /etc/php/*/cli/php.ini
```

Next, enable the Apache rewrite module and restart the Apache service with the following command:

```
sudo a2enmod rewrite
sudo systemctl restart apache2
```

After installation, you can use the FreePBX interface to search for extensions, modules, and trunks. The FreePBX dashboard provides the simplest way to manage Asterisk from a browser.

## Step 5 – Access FreePBX

Now, open your web browser and access the FreePBX web interface using the URL **http://your-server-ip/admin**. You will be redirected to the Admin user creation page:

![](https://www.atlantic.net/wp-content/uploads/2020/12/p5-1024x516.png)

Provide your Admin user details and click on the **Setup System** button. You should see the following page:

![](https://www.atlantic.net/wp-content/uploads/2023/11/p2.png)
 Click on the FreePBX Administration button. You should see the FreePBX login page:
 ![](https://www.atlantic.net/wp-content/uploads/2023/11/p3.png)
 Provide your admin username and password, and click on the **Continue** button. You should see the FreePBX dashboard on the following page:

![](https://www.atlantic.net/wp-content/uploads/2023/11/p5.png)

## Asterisk Security Best Practices

For production deployments, follow these security recommendations:

- Use strong, unique passwords for SIP accounts.
- Restrict SIP ports to trusted IP addresses.
- Enable TLS encryption for SIP communications.
- Keep Ubuntu and Asterisk updated regularly.
- Apply security updates daily for Asterisk and dependencies.
- Use fail2ban and firewall protection.
- Grant only necessary sudo access to administrators.
- Review system log files regularly.
- Exposing SIP services directly to the Internet without restrictions creates a security risk.
- If an error occurs during compilation, verify that all dependencies are installed correctly.

## Conclusion

In this tutorial, you learned how to install Asterisk on Ubuntu 24.04 and deploy FreePBX using Asterisk 20. You installed required Asterisk packages, compiled the source code, configured an Asterisk user, secured the Asterisk server, and configured firewall rules using sudo ufw.

Asterisk is a powerful communications program that runs on modern Linux platforms and supports enterprise telephony features through open-source software. The platform includes features such as voicemail, IVR, conference bridges, call recording, SIP trunk integration, and support for large-scale VoIP infrastructure deployments.

Always verify the release date of downloaded packages before deployment, review installation details, and test configurations before production use. Developers can also clone the source repository to evaluate changes and contribute improvements back to the project. After validating your configuration, you can safely proceed with production deployment on your server, whether it runs on an Ubuntu Server or Ubuntu Desktop environment.

Asterisk remains one of the most widely used open-source PBX platforms available today, with many components licensed under the GNU General Public License and other open-source licenses.

 


---

# How to Find the Top Memory Consuming Processes in Linux

> URL: https://www.atlantic.net/vps-hosting/find-top-10-running-processes-by-memory-and-cpu-usage/ | Published: 2026-06-18 | Updated: 2026-06-24 | Author: Hitesh Jethva

Linux is a powerful open-source operating system and one of the most popular choices for servers, cloud deployments, and enterprise applications. Every Linux distribution includes built-in monitoring tools that help administrators troubleshoot performance issues, analyze resource usage, and identify the top memory consuming process in Linux.

When a website, database, application, or background script becomes slow, excessive RAM usage may be the problem. Common memory-consuming processes include web browsers and databases. In some situations, a process continuously increases its memory allocation, and an increasing RES value in a process might indicate a memory leak.

This article explains how to use Linux commands such as ps, top, htop, free, vmstat, and smem to identify memory-intensive processes, analyze RAM consumption, and learn how Linux manages memory resources.

## Understanding Linux Memory Metrics

Before identifying high-memory processes, it is important to understand several memory-related details displayed by Linux monitoring tools.

| Column | Description |
| --- | --- |
| VSZ | Virtual memory size allocated to a process |
| RSS | Resident Set Size (actual memory stored in RAM) |
| %MEM | Memory usage percentage |
| PID | Process ID |
| USER | Process owner |
| COMMAND | Program name or executable |

Memory values may be displayed in **KB**, **megabytes**, or **gigabytes**, depending on the command and system configuration.

The /proc/meminfo file provides a detailed breakdown of RAM usage on a Linux or **Unix** system.

You can view memory information with:

```
cat /proc/meminfo
```

## Use ps Command to Find Top Processes

The ps command is a Linux command-line utility that displays information about running processes.

To list all running processes:

```
ps aux
```

This command displays process **details** including CPU usage, memory usage, and command information.

```
USER       PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND
root         1  0.1  0.1 160716  9904 ?        Ss   16:58   0:06 /sbin/init splash
root         2  0.0  0.0      0     0 ?        S    16:58   0:00 [kthreadd]
root         3  0.0  0.0      0     0 ?        I<   16:58   0:00 [rcu_gp]
root         4  0.0  0.0      0     0 ?        I<   16:58   0:00 [rcu_par_gp]
root         6  0.0  0.0      0     0 ?        I<   16:58   0:00 [kworker/0:0H-kb]
root         9  0.0  0.0      0     0 ?        I<   16:58   0:00 [mm_percpu_wq]
root        10  0.0  0.0      0     0 ?        S    16:58   0:00 [ksoftirqd/0]
root        11  0.1  0.0      0     0 ?        I    16:58   0:05 [rcu_sched]
root        12  0.0  0.0      0     0 ?        S    16:58   0:00 [migration/0]
```

### Find Top Processes by Memory Usage

To display processes sorted by memory usage:

```
ps aux --sort -%mem
```

Output:

```
USER       PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND
vyom      2806  4.4  4.5 17562832 343688 tty2  SLl+ 17:01   3:26 /opt/google/chrome/chrome --enable-crashpad
vyom      8115  7.8  3.0 25770108 232204 tty2  Sl+  17:58   1:38 /opt/google/chrome/chrome --type=renderer --enable-crashpad --crashpad-handler-pid=2815 --enable-crash-reporter=373d0de2-e0c8-419c-b983-084c773fcd79, --display-capture-permissions-policy-allowed --change-stack-guard-on-fork=enable --lang=en-GB --num-raster-threads=1 --renderer-client-id=82 --launch-time-ticks=3564377766 --shared-files=v8_context_snapshot_data:100 --field-trial-handle=0,i,7343938639469663677,16234295293987540603,131072 --enable-features=PasswordImport
vyom      8164  6.1  3.0 25705000 230116 tty2  Sl+  17:58   1:16 /opt/google/chrome/chrome --type=renderer --enable-crashpad --crashpad-handler-pid=2815 --enable-crash-reporter=373d0de2-e0c8-419c-b983-084c773fcd79, --display-capture-permissions-policy-allowed --change-stack-guard-on-fork=enable --lang=en-GB --num-raster-threads=1 --renderer-client-id=85 --launch-time-ticks=3576904510 --shared-files=v8_context_snapshot_data:100 --field-trial-handle=0,i,7343938639469663677,16234295293987540603,131072 --enable-features=PasswordImport
```

The process at the top of the output is usually the **top memory consuming process in Linux** at that moment.

To show only the top 10 memory-consuming processes:

```
ps aux --sort -%mem | head -10
```

To display only important process information:

```
ps -eo pid,ppid,cmd,comm,%mem,%cpu --sort=-%mem | head -10
```

The RSS value is typically displayed in **KB**, while %MEM shows the percentage of physical memory consumed.

### Find Top Processes by CPU Usage

To sort processes by CPU usage:

```
ps aux --sort -%cpu
```

Output:

```
USER       PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND
vyom      8115  7.8  3.0 25770108 233784 tty2  Sl+  17:58   1:37 /opt/google/chrome/chrome --type=renderer --enable-crashpad --crashpad-handler-pid=2815 --enable-crash-reporter=373d0de2-e0c8-419c-b983-084c773fcd79, --display-capture-permissions-policy-allowed --change-stack-guard-on-fork=enable --lang=en-GB --num-raster-threads=1 --renderer-client-id=82 --launch-time-ticks=3564377766 --shared-files=v8_context_snapshot_data:100 --field-trial-handle=0,i,7343938639469663677,16234295293987540603,131072 --enable-features=PasswordImport
vyom      8164  6.2  3.0 25705000 233456 tty2  Sl+  17:58   1:16 /opt/google/chrome/chrome --type=renderer --enable-crashpad --crashpad-handler-pid=2815 --enable-crash-reporter=373d0de2-e0c8-419c-b983-084c773fcd79, --display-capture-permissions-policy-allowed --change-stack-guard-on-fork=enable --lang=en-GB --num-raster-threads=1 --renderer-client-id=85 --launch-time-ticks=3576904510 --shared-files=v8_context_snapshot_data:100 --field-trial-handle=0,i,7343938639469663677,16234295293987540603,131072 --enable-features=PasswordImport
vyom      2806  4.4  4.5 17565904 343660 tty2  SLl+ 17:01   3:26 /opt/google/chrome/chrome --enable-crashpad
vyom      2314  4.3  2.9 3472696 222248 tty2   Rl+  17:00   3:22 /usr/bin/gnome-shell
```

#### **Also Read**

[How to Check Linux CPU Usage or Utilization](https://www.atlantic.net/vps-hosting/how-to-check-linux-cpu-usage-or-utilization/)

## Use the top Command to Find Top Processes by Memory and CPU Usage

top is another built-in Linux command-line utility that can be used to show all running processes in Linux. You can use various options with the top command to filter the output based on your requirements.

You can use the top command with the **-o** flag to show the top memory consuming processes:

```
top -o %MEM
```

Output:

```
Tasks: 329 total,   1 running, 281 sleeping,   0 stopped,   0 zombie
%Cpu(s):  1.5 us,  0.7 sy,  0.0 ni, 94.6 id,  3.2 wa,  0.0 hi,  0.0 si,  0.0 st
KiB Mem :  7580260 total,  2602168 free,  2668376 used,  2309716 buff/cache
KiB Swap:  2097148 total,  2097148 free,        0 used.  4486960 avail Mem 

  PID USER      PR  NI    VIRT    RES    SHR S  %CPU %MEM     TIME+ COMMAND                                                                   
 2806 vyom      20   0 16.753g 343596 183124 S   0.0  4.5   3:37.39 chrome                                                                    
 8164 vyom      20   0 24.516g 241968 103164 S   0.0  3.2   1:44.22 chrome                                                                    
 8115 vyom      20   0 24.570g 237756 113464 S   0.0  3.1   2:04.79 chrome                                                                    
 2314 vyom      20   0 3472696 222248  97556 S   1.3  2.9   3:49.13 gnome-shell                                                               
 8074 vyom      20   0 24.508g 187804 110344 S   0.0  2.5   0:11.59 chrome                                                                    
 7520 vyom      20   0 24.563g 185760 104852 S   0.0  2.5   0:06.98 chrome                                                                    
 2996 vyom      20   0 24.503g 185316  85720 S   0.0  2.4   0:27.90 chrome                                                                    
 8175 vyom      20   0 24.518g 171224 100040 S   0.0  2.3   0:04.96 chrome
```

Once inside top, press Shift+m in top orders processes by memory usage.

If you want to display only the top 10 memory consuming processes, run the following command:

```
top -o %MEM | head -n 16
```

Output:

```
top - 18:31:11 up  1:32,  1 user,  load average: 0.32, 0.41, 0.65
Tasks: 330 total,   1 running, 282 sleeping,   0 stopped,   0 zombie
%Cpu(s): 14.3 us,  3.5 sy,  0.1 ni, 78.8 id,  3.1 wa,  0.0 hi,  0.1 si,  0.0 st
KiB Mem :  7580260 total,  2623576 free,  2655868 used,  2300816 buff/cache
KiB Swap:  2097148 total,  2097148 free,        0 used.  4508812 avail Mem 

  PID USER      PR  NI    VIRT    RES    SHR S  %CPU %MEM     TIME+ COMMAND                                                                   
 2806 vyom      20   0 16.749g 343920 183192 S   0.0  4.5   3:39.02 chrome                                                                    
 8164 vyom      20   0 24.513g 232772 103276 S   0.0  3.1   1:45.33 chrome                                                                    
 8115 vyom      20   0 24.557g 230336 111896 S   0.0  3.0   2:05.62 chrome                                                                    
 2314 vyom      20   0 3472696 222880  97560 S   0.0  2.9   3:59.60 gnome-shell                                                               
 8074 vyom      20   0 24.508g 187740 110344 S   0.0  2.5   0:11.61 chrome                                                                    
 7520 vyom      20   0 24.563g 185724 104852 S   0.0  2.5   0:06.99 chrome                                                                    
 2996 vyom      20   0 24.503g 185012  85720 S   0.0  2.4   0:27.98 chrome                                                                    
 8175 vyom      20   0 24.518g 171224 100040 S   0.0  2.3   0:04.97 chrome                                                                    
 2735 vyom      20   0 37.371g 168668 119056 S   0.0  2.2   0:05.57 skypeforlinux
```

If you want to display only the top 10 CPU-consuming processes, run the following command:

```
top -o %CPU | head -n 16
```

Output:

```
top - 18:32:05 up  1:33,  1 user,  load average: 0.48, 0.43, 0.64
Tasks: 330 total,   1 running, 282 sleeping,   0 stopped,   0 zombie
%Cpu(s): 14.2 us,  3.5 sy,  0.1 ni, 78.9 id,  3.1 wa,  0.0 hi,  0.1 si,  0.0 st
KiB Mem :  7580260 total,  2621204 free,  2662180 used,  2296876 buff/cache
KiB Swap:  2097148 total,  2097148 free,        0 used.  4506588 avail Mem 

  PID USER      PR  NI    VIRT    RES    SHR S  %CPU %MEM     TIME+ COMMAND                                                                   
 2314 vyom      20   0 3472696 223296  97560 S  11.8  2.9   4:03.68 gnome-shell                                                               
 2161 vyom      20   0  998276  86120  55136 S   5.9  1.1   2:30.95 Xorg                                                                      
 8822 vyom      20   0   44368   4188   3364 R   5.9  0.1   0:00.02 top                                                                       
    1 root      20   0  160716   9904   6644 S   0.0  0.1   0:06.65 systemd                                                                   
    2 root      20   0       0      0      0 S   0.0  0.0   0:00.00 kthreadd                                                                  
    3 root       0 -20       0      0      0 I   0.0  0.0   0:00.00 rcu_gp                                                                    
    4 root       0 -20       0      0      0 I   0.0  0.0   0:00.00 rcu_par_gp                                                                
    6 root       0 -20       0      0      0 I   0.0  0.0   0:00.00 kworker/0:0H-kb                                                           
    9 root       0 -20       0      0      0 I   0.0  0.0   0:00.00 mm_percpu_wq
```

#### **Also Read**

[How to Check Size of Files and Directory on Linux](https://www.atlantic.net/vps-hosting/how-to-check-size-of-files-and-directory-on-linux/)

## Use htop for an Interactive Display

Many administrators prefer htop because it provides a more user-friendly and interactive interface.

Install htop:

Ubuntu/Debian:

```
sudo apt install htop
```

RHEL/Rocky Linux/AlmaLinux:

```
sudo dnf install htop
```

Launch htop:

```
htop
```

Output:

```

```

The htop command provides an interactive display of memory usage. The top section displays CPU utilization, RAM usage, swap utilization, and process statistics in real time.

## Use the free Command to Check RAM Usage

The free command provides a quick overview of system memory usage.

```
free -h
```

Example output:

```
              total        used        free      shared  buff/cache   available
Mem:            15G        4.2G        5.3G        210M        5.5G         10G
Swap:            2G          0B         2G
```

The free command shows total, used, and free memory.

The -h option displays memory values in human-readable **gigabytes** and **megabytes**.

## Use the vmstat Command to Monitor Memory Statistics

The **vmstat command** provides system-wide memory, process, and disk statistics.

Run:

```
vmstat 2
```

Example output:

```
procs -----------memory---------- ---swap-- -----io---- -system-- ------cpu-----
 r  b   swpd   free   buff  cache
 0  0      0 512000  40960 850000
```

Important **vmstat** columns include:

| Column | Description |
| --- | --- |
| free | Free memory |
| buff | Buffer memory |
| cache | Cached memory |
| si | Swap in |
| so | Swap out |

The **vmstat command** is useful for identifying memory pressure, swap activity, and I/O bottlenecks.

## Use smem for Accurate Memory Reporting

Traditional Linux tools may not always calculate shared memory accurately.

Install smem:

Ubuntu/Debian:

```
sudo apt install smem
```

RHEL-based systems:

```
sudo dnf install smem
```

Display memory usage:

```
smem -r
```

The smem command calculates the Proportional Set Size (PSS) to accurately measure memory consumption.

## Troubleshooting High Memory Usage

If your machine experiences slow performance, excessive waiting times, or application crashes, check for:

- Memory leaks
- Runaway applications
- Excessive caching
- Database processes are consuming RAM
- Browser processes use large amounts of memory
- Insufficient swap space

You can also add monitoring tools and regularly update your system to improve stability. Increasing RES value over time may indicate a memory leak.

## Security Verification Note

When accessing monitoring dashboards or server management portals, you may occasionally encounter a security verification page.

Some websites use a security service to protect resources from automated traffic. A website uses a security mechanism that verifies visitors before granting access. While performing security verification, the security service may analyze browser behavior to protect against malicious bots.

If verification is successful, access is granted automatically. Otherwise, the page may display messages such as:

- “This website uses a security service.”
- “Protect against malicious bots.”
- “Please respond ray id when contacting support.”
- “You are being verified.”
- “Verification in progress.”

These messages are commonly displayed while the website checks incoming traffic and are unrelated to Linux memory monitoring.

## Conclusion

Monitoring memory usage is an essential part of Linux administration. Tools such as ps, top, htop, free, vmstat, and smem help identify resource-intensive processes and troubleshoot performance issues quickly. By understanding metrics such as RSS, %MEM, PSS, cache utilization, and swap activity, you can accurately determine the top memory-consuming process in Linux and take corrective action before performance degrades.

Whether you manage a personal Unix workstation, an enterprise server, a virtual machine, or a production website, these tools provide valuable insights into memory utilization. Regular monitoring helps optimize applications, improve system stability, and maintain overall security and performance.


---

# How to Install and Use the Ping Command in Linux (Debian & Ubuntu)

> URL: https://www.atlantic.net/vps-hosting/how-to-install-and-use-the-ping-command-in-linux/ | Published: 2026-06-18 | Updated: 2026-06-19 | Author: Hitesh Jethva

Ping stands for Packet Internet Groper and is an essential tool used by Linux administrators and developers to test network connectivity between two systems. It helps verify whether a remote host, server, website, or device is reachable over a network and measures the round trip time required to send and receive packets.

The Ping utility uses ICMP Echo Request packets and ICMP Echo Reply messages to test communication between devices. It is commonly used for network troubleshooting, diagnosing network connectivity issues, checking internet connection quality, identifying network congestion, and verifying that a remote host is working correctly.

Whether you manage an Ubuntu server, troubleshoot Docker containers, maintain a shared hosting environment, or work as a system administrator, the Ping command remains one of the most useful network diagnostic tools available across different Linux distributions.

This tutorial explains how to install ping Debian, Ubuntu, and other Linux systems, and demonstrates practical examples for testing and troubleshooting network connections.

## Install Ping on Linux

In most Linux environments, Ping is installed by default. However, some minimal installations, cloud images, containers, and lightweight operating systems may not include the Ping utility.

If you receive the error:

```
ping: command not found
```

it means the Ping utility is missing from the system’s path or the required package is not installed.

### Install Ping on Debian and Ubuntu

Before installing Ping, update the system package index:

```
sudo apt update
```

The Ping utility is included in the **iputils-ping package**. You can install it using either of the following commands:

```
sudo apt install iputils-ping -y
```

The **apt package manager** will download and install the latest version of the package from the configured repositories.

### Install Ping on RHEL, CentOS, and Fedora

For Red Hat-based operating systems, install Ping using:

```
dnf install iputils -y
```

Older Linux distributions may use:

```
sudo yum install iputils -y
```

Package managers automatically resolve dependencies and install the required package.

### Verify Installation

After installation, verify that Ping was installed correctly:

```
ping -V
```

Example output:

```
ping utility, iputils-s20161105
```

You can also verify installation by sending test packets to Google’s servers:

```
ping -c 4 google.com
```

### Ping Permissions on Debian

Modern Debian systems use file capabilities to allow non-root users to run Ping without requiring **root privileges**.

You can verify whether Ping exists and has the correct permissions:

```
which ping
```

```
getcap $(which ping)
```

Example output:

```
/usr/bin/ping cap_net_raw=ep
```

#### Also Read

[How to Install and Use Telnet on Debian 11](https://www.atlantic.net/vps-hosting/how-to-install-and-use-telnet-on-debian/)

## Basic Syntax of the Ping Command

The basic syntax of the ping command is shown below:

```
ping [option] [hostname] or [IP address]
```

To get a list of all options used with the Ping command, run the following command:

```
ping -help
```

You should see the following output:

```
Usage: ping [-aAbBdDfhLnOqrRUvV64] [-c count] [-i interval] [-I interface]
            [-m mark] [-M pmtudisc_option] [-l preload] [-p pattern] [-Q tos]
            [-s packetsize] [-S sndbuf] [-t ttl] [-T timestamp_option]
            [-w deadline] [-W timeout] [hop1 ...] destination
Usage: ping -6 [-aAbBdDfhLnOqrRUvV] [-c count] [-i interval] [-I interface]
             [-l preload] [-m mark] [-M pmtudisc_option]
             [-N nodeinfo_option] [-p pattern] [-Q tclass] [-s packetsize]
             [-S sndbuf] [-t ttl] [-T timestamp_option] [-w deadline]
             [-W timeout] destination
```

## Check Connectivity Using the Ping Command

The most common use of Ping is to test network connectivity to a remote server, website, or IP address.

Syntax:

```
ping hostname
```

or

```
ping IP-address
```

For example:

```
ping facebook.com
```

Example output:

```
PING facebook.com(edge-star-mini6-shv-02-pnq1.facebook.com) 56 data bytes
64 bytes from edge-star-mini6-shv-02-pnq1.facebook.com:
icmp_seq=1 ttl=53 time=70.1 ms
```

You can also use Google’s public DNS server to verify internet access:

```
ping 8.8.8.8
```

Or test Google’s servers:

```
ping google.com
```

This is often the first step when diagnosing network issues, DNS failures, or a connectivity problem.

Press **CTRL+C** to stop the Ping process.

### Understanding Ping Output

```
64 bytes from server:
icmp_seq=1 ttl=53 time=70.1 ms
```

- **from** – Displays the destination host and IP address.
- **icmp_seq – Sequence number of each ICMP packet.**
- **ttl – Time To Live value.**
- **time – Response time in milliseconds.**
- **round trip time (RTT) statistics:**

```
rtt min/avg/max/mdev
```

- **min** – Minimum response time.
- **avg** – Average response time.
- **max** – Maximum response time.
- **mdev** – Mean deviation.

[How to Find Files with fd Command in Linux](https://www.atlantic.net/vps-hosting/how-to-find-files-with-fd-command-in-linux/)

## Specify the Number of Ping Packets

You can use the **-c** option with the Ping command to stop the Ping command automatically after sending a certain number of packets.

```
ping -c 5 google.com
```

This command sends five **ICMP Echo Request packets** and then stops automatically.

```
PING google.com(bom07s30-in-x0e.1e100.net (2404:6800:4009:820::200e)) 56 data bytes
64 bytes from bom07s30-in-x0e.1e100.net (2404:6800:4009:820::200e): icmp_seq=1 ttl=55 time=82.0 ms
64 bytes from bom07s30-in-x0e.1e100.net (2404:6800:4009:820::200e): icmp_seq=2 ttl=55 time=224 ms
64 bytes from bom07s30-in-x0e.1e100.net (2404:6800:4009:820::200e): icmp_seq=3 ttl=55 time=451 ms
64 bytes from bom07s30-in-x0e.1e100.net (2404:6800:4009:820::200e): icmp_seq=4 ttl=55 time=372 ms
64 bytes from bom07s30-in-x0e.1e100.net (2404:6800:4009:820::200e): icmp_seq=5 ttl=55 time=292 ms

--- google.com ping statistics ---
5 packets transmitted, 5 received, 0% packet loss, time 4005ms
rtt min/avg/max/mdev = 82.018/284.782/451.970/126.884 ms
```

## Set Time Intervals Between Ping Packets

By default, the time interval between each packet is set to one second. You can use the -i option to change the default time interval.

```
ping -i 2 google.com
```

The command will wait two seconds before sending the next packet.

Some interval values may require **elevated privileges**.

## Change the Ping Packet Size

The ping packet size is set to 56 (84) bytes by default. You can change it using the **-s** option.

For example, to set the Ping packet size to **500** bytes, run the following command:

```
ping -s 500 google.com
```

You should see the packet size in the following output:

```
PING google.com(bom12s20-in-x0e.1e100.net (2404:6800:4009:830::200e)) 500 data bytes
76 bytes from bom12s20-in-x0e.1e100.net (2404:6800:4009:830::200e): icmp_seq=1 ttl=55 (truncated)
76 bytes from bom12s20-in-x0e.1e100.net (2404:6800:4009:830::200e): icmp_seq=2 ttl=55 (truncated)
76 bytes from bom12s20-in-x0e.1e100.net (2404:6800:4009:830::200e): icmp_seq=3 ttl=55 (truncated)
```

Changing packet sizes can help identify MTU problems and diagnose network connectivity issues.

## Set the Time Limit for the Ping Command

You can use the **-w** option to stop receiving a ping output after a specific amount of time.

For example, to stop the Ping command output after **20** seconds, run the following command:

```
ping -w 20 google.com
```

This command terminates after 20 seconds regardless of how many packets were transmitted.

## Add a Timestamp Before Each Line in the Ping Output

You can use the**-D** option with the Ping command to print a timestamp before each line in the Ping output:

```
ping -D google.com
```

You should see the following output:

```
PING google.com(bom12s20-in-x0e.1e100.net (2404:6800:4009:830::200e)) 56 data bytes
[1646212673.335469] 64 bytes from bom12s20-in-x0e.1e100.net (2404:6800:4009:830::200e): icmp_seq=1 ttl=55 time=305 ms
[1646212674.256155] 64 bytes from bom12s20-in-x0e.1e100.net (2404:6800:4009:830::200e): icmp_seq=2 ttl=55 time=225 ms
[1646212675.485228] 64 bytes from bom12s20-in-x0e.1e100.net (2404:6800:4009:830::200e): icmp_seq=3 ttl=55 time=453 ms
```

The timestamp displayed before each line can help correlate network events during troubleshooting.

## Flood a Network with Ping Command

You can use the Ping command with the **-f** option to send 100 or more packets per second to the remote host. It is very useful if you want to test your website’s performance.

```
ping -f google.com
```

This flood mode can generate hundreds of packets per second and is useful for stress testing and advanced network troubleshooting.

Because it generates significant traffic, it typically requires root privileges. Use caution when testing a production website or remote server.

## Print only Summary Statistics in Ping Command.

You can use the Ping command with the **-q** option to suppress the output to print only summary statistics.

```
ping -q google.com
```

You should see the following output:

```
--- google.com ping statistics ---
6 packets transmitted, 6 received, 0% packet loss, time 5007ms
rtt min/avg/max/mdev = 84.909/175.073/317.982/77.991 ms
```

This option is useful when monitoring a host while reducing terminal output.

## Conclusion

The Ping utility is an essential tool for testing network connectivity, diagnosing network issues, verifying internet access, and troubleshooting latency problems on Linux systems. Whether you are working on an Ubuntu desktop, Ubuntu server, cloud instance, containerized environment, or another Linux distribution, Ping provides a fast and reliable way to verify that hosts are reachable and functioning correctly.

In this guide, you learned how to install ping, verify the installation, use Ping to test network connectivity, adjust packet counts and intervals, analyze round trip time, and troubleshoot common connectivity errors. You also learned how Ping interacts with ICMP traffic, firewalls, permissions, and system configuration. With these examples, you can quickly identify connectivity problems, investigate network congestion, confirm access to Google’s public DNS server, and determine whether a remote host or website is reachable.


---

# Cloud Metal Hosting for Dedicated Performance and Cloud Flexibility

> URL: https://www.atlantic.net/cloud-metal-hosting/ | Updated: 2026-09-16

Run dedicated instances on reserved single-tenant physical hosts with cloud console management, predictable performance, BYOL support, and hybrid cloud flexibility, designed around your workload.

- Single-Tenant Dedicated Hosts
- Multiple Dedicated Instances
- Cloud Console Management
- BYOL Support

Host Memory: Up to 8 TB

Transfer Included: 10 TB

## What Is Cloud Metal Hosting?

Cloud Metal Hosting gives you the performance and isolation of dedicated physical hardware with the flexibility, security, and managed services businesses expect from cloud infrastructure.

Atlantic.Net Cloud Metal is built on single-tenant bare-metal resources under the hood and wrapped with cloud-style networking, backup, security, and management options. Choose a Cloud Metal package with bundled security services, or request a custom deployment designed around your workload.

Cloud Metal Hosting is a hybrid infrastructure model that combines dedicated bare-metal hardware with the cloud-style service flexibility of the Atlantic.Net Cloud Platform.

Instead of choosing between public cloud convenience and traditional bare metal control, Cloud Metal gives you both: physical server resources reserved for your workload, plus managed networking, backup, security, VPN, migration, and support options that make the environment easier to operate.

Bare metal is the underlying architecture. Cloud Metal is the service model.

That distinction matters. A standard bare metal server gives you dedicated hardware. Cloud Metal provides dedicated hardware as part of a comprehensive infrastructure environment.

## Cloud Metal Hosting with Dedicated Hosts

Atlantic.Net Cloud Metal Hosting is delivered through Dedicated Hosts: reserved physical servers that support dedicated instance placement, cloud console management, hybrid cloud use cases, and bring-your-own-license workloads.

This makes Cloud Metal a practical fit for organizations that want:

- dedicated physical resource isolation
- predictable performance
- cloud-style instance deployment
- control over where workloads run
- support for multiple dedicated instances on the same host
- BYOL options for server-bound software
- hybrid cloud deployment flexibility
- pricing based on the host rather than each launched instance

Dedicated Hosts allow customers to deploy multiple dedicated instances on the same physical host up to the available CPU, memory, and storage capacity. Atlantic.Net also states that customers pay for the dedicated physical server, with no additional charge to launch instances or deploy multiple instance types on that host.

## Cloud Metal Dedicated Host Pricing

Choose a Dedicated Host plan based on the CPU, memory, storage, and term commitment your workload requires. Atlantic.Net Dedicated Hosts currently support on-demand, 1-year, and 3-year term pricing, with pricing confirmed prior to deployment because Dedicated Host pricing is subject to change.

| Plan | RAM | CPU / vCPU | Storage | Transfer | On-Demand | 1-Year Term | 3-Year Term |
| --- | --- | --- | --- | --- | --- | --- | --- |
| D2.B | 128 GB | 6 cores / 12 threads @ 3.4GHz | 960 GB SATA RAID 1 | 10 TB | $598/mo | $386/mo | $266/mo |
| D5.A | 256 GB | 20 cores / 40 threads @ 2.4GHz | 4.8 TB NVMe RAID 10 | 10 TB | $1,568/mo | $1,011/mo | $697/mo |
| DH1.A | 128 GB | 10 cores / 20 threads @ 2.7GHz | 1.6 TB NVMe RAID 1 | 10 TB | $1,671/mo | $827.82/mo | $498.73/mo |
| DH2.A | 256 GB | 20 cores / 40 threads @ 2.7GHz | 3.2 TB NVMe RAID 10 | 10 TB | $2,151/mo | $1,095.58/mo | $641.53/mo |
| DH2.B | 256 GB | 20 cores / 40 threads @ 2.7GHz | 6.4 TB NVMe RAID 10 | 10 TB | $2,423/mo | $1,247.07/mo | $722.32/mo |
| DH2.C | 256 GB | 20 cores / 40 threads @ 2.7GHz | 12.8 TB NVMe RAID 10 | 10 TB | $2,770/mo | $1,440.49/mo | $825.48/mo |
| DH3.A | 512 GB | 20 cores / 40 threads @ 2.7GHz | 3.2 TB NVMe RAID 10 | 10 TB | $2,436/mo | $1,254.13/mo | $726.09/mo |
| DH3.B | 512 GB | 20 cores / 40 threads @ 2.7GHz | 6.4 TB NVMe RAID 10 | 10 TB | $2,616/mo | $1,354.39/mo | $779.56/mo |
| DH3.C | 512 GB | 20 cores / 40 threads @ 2.7GHz | 12.8 TB NVMe RAID 10 | 10 TB | $3,074/mo | $1,609.68/mo | $915.72/mo |
| DH4.A | 1,024 GB | 20 cores / 40 threads @ 2.7GHz | 3.2 TB NVMe RAID 10 | 10 TB | $2,509/mo | $1,294.99/mo | $747.88/mo |
| DH4.B | 1,024 GB | 20 cores / 40 threads @ 2.7GHz | 6.4 TB NVMe RAID 10 | 10 TB | $2,724/mo | $1,414.68/mo | $811.72/mo |
| DH4.C | 1,024 GB | 20 cores / 40 threads @ 2.7GHz | 12.8 TB NVMe RAID 10 | 10 TB | $3,182/mo | $1,669.96/mo | $947.87/mo |
| DH5.A | 2,048 GB | 40 cores / 80 threads @ 2.7GHz | 3.2 TB NVMe RAID 10 | 10 TB | $2,794/mo | $1,453.55/mo | $832.45/mo |
| DH5.B | 2,048 GB | 40 cores / 80 threads @ 2.7GHz | 6.4 TB NVMe RAID 10 | 10 TB | $2,951/mo | $1,541.36/mo | $879.28/mo |
| DH5.C | 2,048 GB | 40 cores / 80 threads @ 2.7GHz | 12.8 TB NVMe RAID 10 | 10 TB | $3,467/mo | $1,828.52/mo | $1,032.43/mo |
| DH6.A | 4,096 GB | 40 cores / 80 threads @ 2.7GHz | 3.2 TB NVMe RAID 10 | 10 TB | $3,586/mo | $1,894.91/mo | $1,067.84/mo |
| DH7.A | 8,192 GB | 40 cores / 80 threads @ 2.7GHz | 6.4 TB NVMe RAID 10 | 10 TB | $5,684/mo | $2,113.76/mo | $1,184.56/mo |

Pricing is subject to change and will be confirmed prior to deployment. Windows Server licensing may apply where Microsoft products are used. Optional backups, managed services, and custom deployment requirements can be scoped with Atlantic.Net.

## Need a Custom Cloud Metal Deployment?

Standard Dedicated Host plans are a strong fit for many workloads, but some environments require a more specific configuration. Atlantic.Net can help scope custom Cloud Metal deployments based on CPU, memory, storage, operating system, networking, licensing, backup, and support requirements.

Use a custom Cloud Metal deployment when your workload needs a larger host, a specific storage profile, higher memory density, software licensing alignment, private networking, or a more advanced hybrid architecture.

## Why Choose Atlantic.Net for Cloud Metal Hosting?

### Dedicated Hardware with Cloud Control

Cloud Metal provides your workloads with reserved physical server capacity while allowing your team to operate on a cloud platform model. You get the isolation of dedicated hardware with the convenience of cloud console management.

### Single-Tenant Resource Isolation

Each Dedicated Host is allocated to one customer. That means your workloads do not share the physical host with other organizations, helping reduce resource contention and noisy-neighbor concerns.

### Deploy Multiple Dedicated Instances

Run multiple dedicated instances on the same physical host, subject to available CPU, memory, and storage capacity. This gives your team more control over instance placement and resource allocation than standard shared cloud hosting.

### Pay for the Host, Not Every Instance

Dedicated Host billing is designed around the physical host. Atlantic.Net states that there is no additional charge to launch instances or deploy multiple instance types on the host, which can make Cloud Metal attractive for multi-instance workloads.

### BYOL Support for Licensed Workloads

Cloud Metal is well-suited to bring-your-own-license scenarios where physical host visibility matters. Atlantic.Net references BYOL use cases for software such as Oracle, Microsoft SQL Server, and Exchange Server on Dedicated Hosts.

### Hybrid Cloud Flexibility

Use Cloud Metal alongside Atlantic.Net cloud infrastructure. Run workloads on Dedicated Hosts where isolation and licensing matter, while using cloud instances for other parts of the environment.

## How Cloud Metal Hosting Works

### Choose a Dedicated Host

Select the Dedicated Host plan that matches your workload's CPU, memory, storage, and transfer requirements. Choose on-demand pricing for flexibility or term pricing for longer-running workloads.

### Deploy Dedicated Instances

Deploy dedicated instances on the host through the Atlantic.Net Cloud Control Panel. Instance placement controls allow workloads to run on the selected Dedicated Host.

### Configure the Environment

Install the operating system, applications, databases, control panels, containers, services, and supporting components your workload requires.

### Connect to Cloud Services

Use Cloud Metal as part of a broader Atlantic.Net environment. Connect Dedicated Hosts with cloud instances, backup services, private networking, security services, or other infrastructure components as needed.

### Scale or Customize

As the workload grows, add additional Dedicated Hosts, migrate workloads to larger hosts, or work with Atlantic.Net on a custom deployment design.

## Cloud Metal Deployment Options

### On-Demand Cloud Metal

Use on-demand Dedicated Host pricing when you need committed physical resources without a longer-term contract.

This is useful for projects, migrations, testing, or workloads where requirements may change.

### 1-Year Term Cloud Metal

Choose a 1-year term when the workload is expected to run continuously, and you want a lower monthly rate than on-demand pricing offers.

### 3-Year Term Cloud Metal

Choose a 3-year term for stable, long-running workloads where predictable infrastructure planning and lower monthly pricing are priorities.

### Custom Cloud Metal

Request a custom deployment when standard Dedicated Host plans do not meet the workload's CPU, RAM, storage, licensing, backup, network, or compliance requirements.

### Hybrid Cloud Metal

Combine Dedicated Hosts with Atlantic.Net cloud instances to support architectures that need both dedicated physical resources and flexible cloud capacity.

## Key Features

### Dedicated Hosts

Cloud Metal is powered by Dedicated Hosts: physical servers reserved for your organization and integrated into the Atlantic.Net Cloud Platform.

### Dedicated Instance Placement

Deploy instances onto a specific Dedicated Host and keep workloads on reserved physical infrastructure.

### Cloud Console Management

Manage hosts, instances, and resources through the Atlantic.Net cloud console.

### High-Memory Host Options

Choose from Dedicated Host plans with RAM ranging from 128 GB to 8 TB, depending on workload requirements.

### NVMe and SATA Storage Options

Select host plans with SATA RAID 1 or NVMe RAID 10 storage profiles based on performance, capacity, and workload needs.

### Bring Your Own License

Use Dedicated Hosts for server-bound licensing scenarios where physical host visibility and license affinity are important.

### Optional Backups

Atlantic.Net lists daily, hourly, and 15-minute onsite and offsite backup options for Dedicated Host instances.

### Hybrid Cloud Support

Launch cloud instances on Dedicated Hosts and Atlantic.Net's public cloud platform based on project needs.

## Who Is Cloud Metal Hosting For?

Cloud Metal Hosting is designed for organizations that need dedicated physical infrastructure without giving up cloud-style flexibility.

| Buyer / Team | Why Cloud Metal Fits |
| --- | --- |
| SaaS platforms | Run production services on dedicated infrastructure while managing instances through a cloud platform |
| Database teams | Host SQL Server, Oracle, MySQL, PostgreSQL, and other databases on isolated physical resources |
| Enterprises with BYOL software | Align server-bound licensing with dedicated host visibility and instance placement |
| Healthcare organizations | Use dedicated physical infrastructure for workloads with stronger security and compliance requirements |
| Financial services teams | Support sensitive applications on isolated hosts with predictable resource allocation |
| Hosting providers and agencies | Run multiple customer environments or websites on a single Dedicated Host |
| DevOps and platform teams | Control instance placement, operating systems, containers, and deployment architecture |
| Hybrid cloud teams | Combine dedicated physical hosts with flexible cloud infrastructure |

## Build for Performance, Licensing, and Control

Cloud Metal is especially valuable when infrastructure design affects cost, performance, compliance, or licensing. A standard cloud server may be convenient, but it may not provide the host-level control or isolation your workload requires.

With Cloud Metal Dedicated Hosts, your team can reserve the physical host, control where dedicated instances run, and align the environment with operational and licensing requirements.

That makes Cloud Metal a strong fit for organizations modernizing from traditional dedicated servers, consolidating licensed workloads, building private cloud-style infrastructure, or moving sensitive systems into a more flexible hosting model.

## Frequently Asked Questions

### What is Cloud Metal Hosting?

Cloud Metal Hosting is dedicated to physical infrastructure delivered through a cloud platform model. With Atlantic.Net, Cloud Metal is powered by Dedicated Hosts that allow customers to run dedicated instances on reserved physical hardware.

### Is Cloud Metal the same as bare metal?

No. Bare metal refers to the underlying physical server architecture. Cloud Metal uses dedicated physical hardware under the hood, but delivers it through a cloud-style model using Dedicated Hosts, instance placement, and cloud console management.

### What is a Dedicated Host?

A Dedicated Host is a physical server allocated to a single customer. Dedicated instances run on that host, giving your workloads dedicated physical resources and greater control over where instances are placed.

### What is the difference between a Dedicated Host and a dedicated instance?

A Dedicated Host is the physical server. A dedicated instance is a server instance that runs on that host. You can run multiple dedicated instances on the same Dedicated Host, subject to the host's available CPU, memory, and storage resources.

### Do I pay for each dedicated instance?

Atlantic.Net Dedicated Host billing is based on the physical host. Atlantic.Net states that customers pay for the dedicated physical server and are not charged separately for launching instances or deploying multiple instance types on that host.

### When should I choose Cloud Metal instead of public cloud?

Choose Cloud Metal when your workload needs dedicated physical resources, stronger isolation, predictable performance, BYOL support, or control over instance placement. The public cloud is often better suited to highly elastic workloads that do not require dedicated host-level control.

### Can I bring my own software licenses?

Yes. Dedicated Hosts are suitable for BYOL use cases where software licensing depends on physical server visibility or license affinity. Common examples include Oracle, Microsoft SQL Server, Windows Server, and Exchange Server.

### Can Cloud Metal be used for compliance-sensitive workloads?

Yes. Cloud Metal can support compliance-sensitive workloads that require dedicated infrastructure, resource isolation, and greater control over the hosting environment. Specific compliance requirements should be reviewed with Atlantic.Net before deployment.

### Can I use Cloud Metal with other Atlantic.Net cloud services?

Yes. Cloud Metal Dedicated Hosts can be used alongside Atlantic.Net cloud instances and other cloud services to support hybrid cloud architectures.

### Are backups included?

Backups should be scoped based on the deployment. Atlantic.Net lists optional onsite and offsite backup options with daily, hourly, and 15-minute frequencies for Dedicated Host instances.

### Can I request a custom Cloud Metal configuration?

Yes. Atlantic.Net can help scope custom Dedicated Host requirements, including CPU, memory, storage, and other infrastructure needs. The Dedicated Hosts page notes that customers can contact Atlantic.Net with physical server CPU, RAM, storage, and other requirements for custom plans.

## Get Dedicated Infrastructure with Cloud Flexibility

Atlantic.Net Cloud Metal Hosting gives you reserved physical resources via Dedicated Hosts, with cloud-style deployment, instance placement, BYOL support, hybrid cloud options, and flexible-term pricing.

Choose a Dedicated Host plan or work with Atlantic.Net on a custom Cloud Metal deployment designed around your workload.

Call Us: +1-866-618-3282.

## Cloud Availability in Multiple Global Regions

Deploy close to your users from eight international data centers worldwide, with new regions on the way.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Real Audits vs Paper Audits: What “HIPAA Compliant” Should Actually Mean

> URL: https://www.atlantic.net/hipaa-compliant-hosting/real-vs-paper-hipaa-compliance-audits/ | Published: 2026-06-19 | Author: Richard Bailey

The phrase “HIPAA-compliant” appears on the marketing pages of nearly every hosting provider serving the healthcare industry. It is a reassuring claim and one of the easiest to make in the industry. It is also one of the hardest to verify from the outside.

Two providers can display the same compliance language, while the work behind the scenes couldn’t be more different. One has commissioned an independent auditor to spend weeks testing controls, sampling a year of operating evidence, and verifying physical safeguards on the data center floor. The other has paid a fraction of the price for a document-only review that confirmed a folder of policies looked complete, without testing whether any of it reflected in what the environment actually does. , from the outside, the two badges are indistinguishable.

For any organization that places electronic Protected Health Information (ePHI) on that infrastructure, the difference remains invisible right up until the moment it matters: during a breach investigation, a customer’s due diligence audit, or a cyber insurance claim. By then, the compliance badge has already done its job of winning the business.

The distinction that counts comes down to who audited the provider, how recently, and what that auditor actually examined. A real audit and a paper audit produce the same badge by completely different means, and the gap between them is where compliance either holds up or falls apart.

## What “HIPAA-compliant” Actually Means

No government agency issues a HIPAA compliance certificate. The Department of Health and Human Services does not certify hosting providers, software vendors, or any other covered entity or business associate. When a provider displays a “HIPAA-compliant” badge, that badge is a claim, and the weight behind it comes entirely from the independent audit that produced it.

HIPAA compliance is the organization’s own legal obligation, and no government body will grade it with a pass or fail. What a provider can actually give a customer is independent evidence that its controls were tested, most often an examination performed by a qualified, independent CPA firm under the American Institute of Certified Public Accountants (AICPA) attestation standards AT-C 105 and AT-C 205. These are general attestation standards rather than anything HIPAA itself prescribes. Still, an examination under them means a CPA firm tested the provider’s controls against HIPAA’s technical, administrative, and physical safeguard requirements and issued a formal opinion. It is the strongest independent verification a provider can show to a customer. A provider who says “HIPAA-compliant” is either misstating their situation or describing a third-party badge program with no regulatory standing.

The second thing the badge does not tell you is scope.[HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) establishes a compliant infrastructure foundation. The controls at the data center level, at the network perimeter, and in the managed environment are the provider’s responsibility to maintain and verify. The customer’s application code, database configurations, access controls, staff training, and operational policies sit on the customer side of the shared-responsibility line. A provider can hold a thoroughly audited environment, and a customer’s insecure application can still expose ePHI in a way that constitutes a HIPAA violation. The audit is a necessary condition, but it is not the whole picture.

Understanding this separation matters before you evaluate any provider’s claim of compliance. The questions worth asking are straightforward: who audited you, when, and what did they actually examine?

## Real Audits vs Paper Audits

Not every hosting provider that claims to support HIPAA-regulated workloads undergoes the same level of independent auditing.

At one end is an independent, qualified auditor performing hands-on fieldwork: examining evidence in place, testing whether controls operate as described, observing system configurations, and verifying on-site physical access controls.

At the other end is what the industry sometimes calls a paper audit or checkbox review, a cheap, document-only exercise in which an auditor collects policies from the provider, reads them, and confirms they appear to say the right things, without ever verifying that those policies reflect what the environment actually does.

A paper audit is not always easy to identify from a distance. It typically looks like a compliance report. It may reference the same regulatory frameworks. The difference is in what the auditor did to reach their conclusions. Did they visit the facility? Did they observe access controls in operation? Did they sample logs, interview staff, and test configurations, or did they accept a folder of documents at face value? Document-only reviews are frequently completed remotely and at considerably lower cost than fieldwork-based audits. Lower cost is a signal worth paying attention to: a rigorous annual audit across multiple frameworks costs meaningfully more than a checkbox review assembled from submitted paperwork.

The problem with a paper audit is methodological, not geographic. Where the auditor sits matters far less than whether they actually tested anything. Plenty of logical controls can be verified remotely from system-generated evidence: an auditor can pull live configurations, sample access logs, and interview operators over video. What a document-only review skips is the testing itself. It accepts that a backup runs nightly because a policy says so, and that physical access controls work because a procedure document lists them, neither of which is the same as confirming they operate. Those are the gaps that surface during a breach investigation, a customer due diligence audit, or a cyber-insurance claim. Signed policies cannot substitute for real-world, evidence-based testing.

## What a Real Auditor Does That a Paper Audit Skips

A qualified independent auditor does not accept a policy document about physical access controls as evidence that those controls exist. They visit the facility, walk through the environment, observe the controls in operation, and document their findings.

For Atlantic.Net’s Orlando data center, that means an auditor verifying a physical security configuration that includes biometric palm scanners and proximity card readers at access points, a man-trap entry vestibule, closed-circuit television with 24-hour recording and 30-day retention, and VESDA (very early smoke detection apparatus) air-sampling fire detection supported by dry-pipe pre-action suppression. No document review can confirm a palm scanner is operational. The auditor has to be there.

This is the kind of verification A-LIGN, Atlantic.Net’s independent US-based CPA firm, performs in each engagement: directly examining the physical and administrative environment, with eyes on the controls and the operations behind them.

The same fieldwork discipline applies to logical controls. Walkthroughs of system configurations, evidence sampling from access logs and change records, interviews with operations staff, and verification of monitoring procedures are all part of a SOC 2 Type II engagement. Each of these requires access to the live environment and the people who run it.

## Why SOC 2 Type II and PCI DSS Raise the Bar

Some audit frameworks make a paper-only review structurally impossible, which is part of why they carry more weight than a self-attestation or a checkbox report.

SOC 2 Type II is one of them. A Type I report is a point-in-time examination: the auditor evaluates whether a provider’s controls are designed appropriately as of a specific date. A Type II report is different in kind. The auditor observes whether those controls operated effectively over an observation period, typically three to twelve months. To produce a Type II opinion, the auditor must examine evidence that controls functioned during that window, rather than a snapshot of their configuration on the day of the visit. You cannot manufacture twelve months of consistent operational evidence from documents assembled the week before an audit.

PCI DSS Level 1 service providers face an even more explicit requirement. At Level 1, which applies to organizations processing the highest volumes of payment card transactions, an annual assessment by a Qualified Security Assessor (QSA) is required, and the QSA produces a Report on Compliance (ROC) documenting the findings. The self-assessment questionnaire (SAQ) pathway used by lower-volume merchants is not available to Level 1 service providers. A QSA-led examination with independent testing, not a self-attestation, is what validates compliance at this level.

Atlantic.Net’s annual audit scope covers HIPAA/HITECH AT-C 105/205, SOC 2 Type II, SOC 3 Type II, and PCI DSS 4.0. Each of those engagements involves substantive independent examination rather than self-attestation, so the compliance posture is tested every year, and the evidence of that examination is maintained in a formal record.

For customers evaluating[PCI-compliant hosting](https://www.atlantic.net/pci-compliant-hosting/) options, the [ROC](https://blog.pcisecuritystandards.org/pci-ssc-releases-roc-template-for-pci-dss-v4-0-1) is the document to ask for. A provider who cannot produce one or who offers a self-assessment questionnaire as an equivalent is operating at a different level of verification.

## The Hidden Cost of a Weak Audit

A compliance badge backed by a paper audit looks identical to one backed by a rigorous annual fieldwork engagement, until something goes wrong. Three specific situations tend to surface the difference.

**A cyber-insurance claim**. Cyber liability applications increasingly ask the insured to represent that specific controls are in place and independently verified. Those representations carry weight: insurers have moved to deny or rescind coverage when a post-breach forensic review finds that a control the policyholder attested to was not operating as represented. A compliance posture that was never independently tested is harder to stand behind on that application, and a misrepresentation there, even an unintentional one, can put a claim at risk.

**A downstream audit.** Healthcare SaaS vendors, medical billing platforms, and telehealth providers are regularly audited by the hospital systems and covered entities that use them. Those upstream customers request their vendors’ compliance documentation as part of the procurement or contract renewal process. A vendor whose hosting provider’s compliance rests on a paper review may find that the covered entity’s compliance team does not accept it. The weak foundation at the infrastructure level propagates upward through the supply chain.

**Liability under the BAA.** Atlantic.Net provides a HIPAA Business Associate Agreement (BAA) as standard with all HIPAA hosting plans. The BAA defines what the hosting provider is responsible for and what remains the customer’s responsibility. Liability flows in both directions: the provider is accountable for the infrastructure controls they have committed to maintaining, and the customer is accountable for the application, access policies, and operational practices on their side of the line. A provider whose compliance was never independently verified in depth has, in practice, made commitments the audit cannot support.

The pragmatic point worth stating plainly is this: the hosting provider’s audit is necessary, but the customer still owns their application security, staff access controls, and operational procedures. A well-audited host does not make a poorly secured application compliant. Both sides of the shared-responsibility line need to be in order.

## How to Vet a Hosting Provider’s Compliance

Asking whether a provider is “HIPAA-compliant” is a reasonable place to start, though it rarely tells you enough on its own. The following questions will help to gather more useful information.

Who is the auditor, and are they independent? The auditor should be an independent firm without business ties to the provider that would compromise its objectivity. An internal team, or a firm that also sells the provider the controls it audits, constitutes a conflict of interest that undermines the value of the report.

Is the SOC 2 report a Type II? Ask specifically. A Type I report confirms controls were designed appropriately at a point in time. A Type II report confirms that they operated effectively during the observation period. These are materially different assurances, and the Type II is the one worth asking for.

Does an actual report exist, or is this a self-attestation? A legitimate SOC 2 engagement produces a formal report. A provider who describes their compliance in marketing materials but cannot produce an NDA-protected report on request has not completed an independent audit in the standard sense.

When was the most recent audit completed? Annual cadence is the standard across SOC 2, HIPAA/HITECH AT-C 105/205, and PCI DSS. An audit more than 12 months old may no longer reflect the current environment.

Is a BAA offered as standard for HIPAA workloads? A legally binding BAA must be in place before any hosting provider creates, receives, stores, or transmits ePHI on behalf of a covered entity. The law requires that an adequate agreement exist, not that it be free or bundled into every plan, so a provider that treats the BAA as an obstacle, or will not commit to one as standard, is worth scrutinizing.

Are physical and environmental controls within the audit scope? Ask the provider to confirm that physical access controls, environmental monitoring, and facility security are addressed in their audit report. A report scoped only to logical controls leaves a material gap in the evidence base.

## How Atlantic.Net Approaches Compliance Audits

Atlantic.Net commissions A-LIGN, a US-based independent CPA firm, to perform its annual compliance audits. Each engagement covers HIPAA/HITECH AT-C 105/205, SOC 2 Type II, SOC 3 Type II, and PCI DSS 4.0, with A-LIGN conducting the fieldwork required by each standard.

For HIPAA and SOC 2 Type II, A-LIGN auditors verify physical and environmental controls at the facility level, review operating evidence across the observation period, and examine the[managed services](https://www.atlantic.net/managed-services/) and administrative controls that support the hosted environment. The PCI DSS 4.0 assessment follows the Level 1 QSA pathway, producing a Report on Compliance instead of a self-assessment questionnaire.

“Compliance built-in, not bolt-on” describes the operational reality that the compliance infrastructure at Atlantic.Net, the physical access controls, the managed FortiGate firewalls with intrusion prevention, the encrypted VPN, the bi-weekly vulnerability scanning, the 24/7 SOC monitoring, and the audit trail through the Log Management System, are standard components of HIPAA-compliant hosting plans, not features a customer needs to request or add. A legally binding BAA is standard with every HIPAA plan.

Where the shared-responsibility line sits is worth making clear. Atlantic.Net’s audited controls cover the physical environment, the network perimeter, the hypervisor layer, and the managed platform components. The customer’s application code, database security configurations, internal user access policies, and staff training are the customer’s responsibility. A well-audited hosting environment provides a verified foundation; building on it correctly is the customer’s part of the arrangement. (Atlantic.Net will, of course, offer assistance on request) The SOC 3 Type II report is publicly available; the full SOC 2 Type II report is available under NDA for customers who want to review the details of what was examined and what A-LIGN found.

## Compliance You Can Verify

A compliance badge is the beginning of a conversation, not the end of one. The question that actually protects a healthcare or payments workload is who audited the provider, how recently, and what the auditor examined in person. Atlantic.Net built its compliance program around answers it can demonstrate: a named US-based independent auditor, A-LIGN; annual engagements across HIPAA/HITECH AT-C 105/205, SOC 2 Type II, SOC 3 Type II, and PCI DSS 4.0; and fieldwork that verifies controls in operation, not on paper.

If you are evaluating a hosting provider for a HIPAA or PCI-regulated workload and want to separate a verifiable compliance posture,[contact the Atlantic.Net solutions team](https://www.atlantic.net/about-us/corporate-contact/). We will walk through your compliance requirements, where the shared-responsibility line falls for your application, and what our audit reports actually cover.


---

# E-Commerce Hosting for Secure, High-Performance Online Stores

> URL: https://www.atlantic.net/e-commerce-hosting-for-secure/ | Updated: 2026-09-16

Cloud, dedicated, and hybrid infrastructure for the storefronts, catalogs, databases, and checkout flows your revenue depends on.

- Dedicated Resources
- PCI DSS 4.0 Audited
- Daily Encrypted Backups
- 24/7/365 US-Based Support

Uptime SLA: 100%

US-Based Support: 24/7/365

An online store is only as dependable as the infrastructure it runs on. When a product page stalls during a sale, a checkout times out, or the database falls over on the busiest trading day of the year, the cost shows up as abandoned carts and lost revenue, well beyond a spike on a server graph. E-commerce workloads also handle customer- and payment-related data, which raises the security and compliance bar well above that of a typical brochure site.

Atlantic.Net hosts ecommerce workloads on cloud, dedicated, and hybrid infrastructure built for performance, isolation, and security. You get dedicated resources for high-traffic websites, RAID-10 NVMe/SSD storage as standard, managed security options, daily encrypted backups, and a 100% uptime SLA, backed by US-based engineers available 24/7/365. If your online store handles cardholder data, we can provide a PCI-compliant hosting foundation on which you can build a compliant environment.

## What Is E-Commerce Hosting?

E-commerce hosting is infrastructure configured specifically to run online stores and the associated backend systems: the storefront application, the product catalog, the customer and order databases, cart and session data, media assets, and the payment-adjacent services that connect to a gateway or processor. It also has to absorb transactional database load, traffic that spikes hard during promotions, and the security obligations that come with handling customer and payment data, more than a typical brochure site demands.

Atlantic.Net delivers e-commerce hosting across our cloud platform, dedicated and bare metal servers, and hybrid combinations of the two. You can run self-managed platforms such as WooCommerce, Magento (Adobe Commerce), PrestaShop, or a custom application, and host the databases, caches, and APIs behind a headless or composable storefront. Security, backups, and managed services are layered on to match the sensitivity of the workload.

## What's Included

### Cloud, Dedicated, or Hybrid Hosting

Run your store on the Atlantic.Net cloud platform for fast scaling, on Fortress dedicated and bare metal servers for predictable single-tenant performance, or a hybrid of both. Cloud servers deploy in about 30 seconds; dedicated servers give you isolated CPU, memory, and disk resources.

### Dedicated Resources for High-Traffic Stores

Single-tenant cloud hosts and bare metal remove the noisy-neighbor problem, so a flash sale or product launch is not competing with other tenants for CPU and disk I/O. Configurations scale up to high-core-count Xeon servers with up to 1TB of ECC RAM.

### PCI-Ready Infrastructure

Host inside Atlantic.Net's PCI-compliant hosting environment, audited against PCI DSS 4.0. Managed firewall, intrusion detection, encryption, and network segmentation give the payment layer a compliant foundation to build upon.

### Managed Firewall and Security Add-Ons

Add a fully managed FortiGate firewall with intrusion prevention, multi-factor authentication, and the Trend Micro security suite where the workload calls for it. Network Edge Protection puts upstream DDoS mitigation and a ModSecurity WAF (OWASP Top 10) in front of your store at fixed pricing, so a flood of malicious traffic during an attack does not turn into a surprise bill.

### Database Hosting and Performance

Host transactional databases (MySQL, PostgreSQL) and caching layers (Redis) on right-sized infrastructure, fully managed if you want it, with administration, tuning, high availability, and replication available so the catalog and checkout stay responsive under load.

### Daily Encrypted Backups and Disaster Recovery

Managed Veeam backups run daily to on-site and off-site encrypted storage, with replication and disaster-recovery options so that order and customer data can be restored quickly after an incident.

### Scalable Storage for Catalogs and Media

Secure Block Storage adds elastic, replication-enabled volumes with snapshots for product images, transactional data, and a catalog that keeps growing, so storage expands with the store and never caps it.

### Support for Custom Deployments

Run the stack your store actually needs: specific OS and database versions, custom application servers, load balancing, private networking, and VPC isolation. If the requirements do not fit a standard plan, the team will scope a custom build.

## Built for Checkout, Catalog, and Customer Data Workloads

E-commerce sites typically run several workloads at once, and each one stresses the infrastructure differently. Atlantic.Net hosting is sized and configured around that reality:

### Storefront and application tier

front-end and application servers with dedicated CPU and memory, load-balanced for steady response times under traffic.

### Product catalog and search

fast NVMe/SSD storage and caching for large catalogs and search-heavy browsing.

### Transactional database

isolated, tunable database hosting for orders, customers, and inventory, with replication for high availability.

### Cart, session, and cache

low-latency in-memory layers (Redis) so carts and sessions stay responsive at peak.

### Media and static assets

scalable block storage and CDN delivery for product images and rich media.

### Payment-adjacent services

segmented, monitored infrastructure for the components that connect to your gateway or processor.

## PCI-Ready Infrastructure for Payment Environments

If your store, process, or transmit cardholder data, it falls under PCI DSS 4.0. Atlantic.Net provides a PCI-compliant hosting environment, audited by an independent third-party CPA firm, with managed firewall and IPS, encryption in transit and at rest, network segmentation, vulnerability scanning, and detailed access logging.

One point worth stating plainly: hosting does not, on its own, make your business PCI compliant. PCI compliance is a shared responsibility. Atlantic.Net is responsible for the security of the underlying infrastructure and the controls listed above; you remain responsible for your application code, how cardholder data flows through it, your access policies, and your operational processes. We provide a compliant foundation and a documented control set for your QSA to review, so you start from an audited base and skip building the secure environment from scratch.

## Business Outcomes

### Revenue-Ready Performance

Dedicated resources, RAID-10 NVMe/SSD storage, and load balancing keep product pages and checkout fast when it matters most. Faster pages and reliable checkout protect conversion and keep customers moving toward the sale.

### A Compliant Foundation for Payments

A PCI-compliant hosting environment gives your payment workloads an audited starting point. You inherit the infrastructure controls and the documentation, then layer your application and policies on top. The compliant stack is already in place for you to build on.

### Continuity Through Peak Events

Daily encrypted backups, replication, and disaster-recovery options mean that a hardware fault or data incident does not result in a multi-day outage. Your catalog and order history stay recoverable.

### Security Without an In-House Team

Managed firewall, IPS, MFA, WAF, and 24/7 monitoring are delivered as services. You get a managed security posture without hiring a full-time security engineer to run it.

## Who Needs E-Commerce Hosting

| Business Type | Why Atlantic.Net Fits |
| --- | --- |
| Direct-to-consumer retailers | Dedicated resources and managed security for a store that is the whole business. |
| High-growth and seasonal stores | Headroom and scaling for promotions, launches, and seasonal peaks |
| Subscription and recurring-billing businesses | PCI-compliant hosting foundation for repeat cardholder transactions |
| Marketplaces and multi-vendor platforms | Isolated database and application tiers for heavier, mixed workloads |
| B2B and wholesale commerce | Predictable single-tenant performance for large catalogs and account portals |
| Headless and composable builds | Hosting for the databases, caches, and APIs behind a decoupled storefront |
| Agencies hosting client stores | Cloud, dedicated, and managed options across a portfolio of stores |

## A Platform You Can Trust

Atlantic.Net has hosted business-critical workloads since 1994. E-commerce hosting runs on the same audited infrastructure as our HIPAA-compliant and PCI-compliant hosting services, with security and compliance built in from the start.

Your store runs on a platform backed by:

- SOC 2 Type II, SOC 3 Type II, HIPAA, HITECH, PCI DSS 4.0, and NIST 800-53 audited environments
- RAID-10 NVMe/SSD storage standard, across data centers in the US, Canada, the UK, and Singapore
- 100% uptime SLA on network, hardware, and power
- 24/7/365 US-based support by phone, email, and chat, never outsourced
- Atlantic.Net since 1994: 32 years hosting revenue-generating infrastructure

## Frequently Asked Questions

### What is e-commerce hosting?

E-commerce hosting is infrastructure configured to run online stores and the systems behind them: the storefront application, product catalog, customer and order databases, cart and session data, media, and payment-adjacent services. It is built to handle transactional load, traffic spikes during promotions, and the security and compliance requirements that come with handling customer and payment data. Atlantic.Net provides it across cloud, dedicated, and hybrid infrastructure.

### Is Atlantic.Net e-commerce hosting PCI compliant?

Atlantic.Net provides a PCI-compliant hosting environment, audited against PCI DSS 4.0 by an independent third-party CPA firm. That is the infrastructure half of the equation. PCI compliance is a shared responsibility: we secure the underlying infrastructure and provide the documented controls, while you remain responsible for your application, how cardholder data flows through it, and your access and operational policies. Hosting alone does not make a business PCI compliant.

### Can I host WooCommerce, Magento, Shopify-adjacent apps, or custom e-commerce applications?

Yes, for self-managed platforms such as WooCommerce, Magento (Adobe Commerce), PrestaShop, OpenCart, and custom applications. Shopify itself is a hosted SaaS platform run by Shopify, so you do not self-host it, but Atlantic.Net can host the backend services, databases, and APIs that integrate with a hosted commerce platform or power a headless storefront.

### Should I choose cloud or dedicated hosting for my store?

Cloud hosting suits stores that need fast scaling, quick deployment, and flexible sizing. Dedicated and bare-metal suit high-traffic stores that want isolated, predictable performance and full control over the hardware. Many stores run a hybrid cloud for the front end and a dedicated cloud for the database. The Atlantic.Net team will recommend a model based on your traffic, catalog size, and compliance needs.

### Can Atlantic.Net help with high-traffic sales events?

Yes. We size infrastructure ahead of promotions and seasonal peaks, add load balancing and caching, and put Network Edge Protection in front of the store for DDoS mitigation at fixed pricing. Talk to the team before a major event so the environment is provisioned for the expected load.

### Can my e-commerce database be hosted separately from the storefront?

Yes. Databases can run on dedicated or cloud instances, separate from the application tier, with managed administration, tuning, high availability, and replication. Separating the database is a common way to protect checkout performance and isolate sensitive data.

### What security features are available for e-commerce hosting?

Managed FortiGate firewall with IPS, multi-factor authentication, encryption in transit and at rest, the Trend Micro security suite, vulnerability scanning, Network Edge Protection (DDoS mitigation plus a ModSecurity WAF and CDN), load balancing, and 24/7 monitoring from a US-based team. The set you deploy is matched to the workload and any compliance requirements.

## Talk to an Atlantic.Net Hosting Expert

Tell us about your store, your traffic patterns, and any compliance requirements, and we will design e-commerce hosting scaled to your workload, from a single cloud server to a hybrid environment with a dedicated database and managed security.

Atlantic.Net: Secure Cloud Hosting & Infrastructure Since 1994.

[Call Us: 866-618-3282](tel:+18666183282)

## Cloud Availability in Multiple Global Regions

Deploy close to your users from eight international data centers worldwide, with new regions on the way.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Storage-Optimized Servers for High-Capacity Workloads

> URL: https://www.atlantic.net/storage-optimized-servers-for-high-capacity-workloads/ | Updated: 2026-09-16

Configurable dedicated, bare metal, and cloud infrastructure for large datasets, databases, backups, archives, and anything where capacity is the constraint.

- Custom CPU, RAM & Disk
- RAID-10 NVMe/SSD Storage
- 100% Uptime SLA
- 24/7/365 US-Based Support

S2 Cloud SSD Capacity: Up to 4TB

Dedicated ECC RAM: Up to 1TB

Some workloads are defined by compute. Others are defined by how much data they hold and how fast they need to read and write it. Backup repositories, large databases, media libraries, log and analytics stores, and compliance archives all grow steadily, and a general-purpose server runs out of disk long before it runs out of CPU.

Atlantic.Net builds storage-optimized servers for exactly those workloads. You choose the balance of CPU, memory, and disk on dedicated or bare-metal hardware or on a cloud platform, and add block storage, backups, replication, and managed services as the data set grows. Capacity is sized to the workload, so the configuration follows the data, and custom builds are scoped directly with our team.

## What Is a Storage-Optimized Server?

A storage-optimized server is infrastructure weighted toward capacity and disk throughput, with right-sized CPU and memory paired with high-capacity, high-performance storage, so the cost and the configuration follow the data. The disk leads the design, and the processor is matched to it.

Atlantic.Net offers storage-optimized infrastructure in several forms: Storage Optimized cloud servers (the S2 line, scaling to 16 vCPUs, 128GB RAM, and 4TB of SSD per instance), Fortress dedicated and bare metal servers with custom storage configurations and up to 1TB of ECC RAM, and Secure Block Storage volumes that attach elastic, replication-enabled capacity to either. You can run one of these on its own or combine them into a hybrid design.

## Designed for Capacity, Control, and Data Growth

Storage-heavy workloads share a few demands that general-purpose hosting may not handle as well: capacity that scales without a forklift upgrade, predictable performance under heavy read/write loads, and durability so that data survives a hardware fault. Atlantic.Net storage-optimized servers are configured around those demands.

### Capacity First

Disk is sized to the data, with room to grow well past a six-month ceiling.

### Throughput That Holds Up

RAID-10 NVMe/SSD storage and dedicated hardware keep performance steady when many reads and writes hit at once.

### Durability Built In

Replication, snapshots, and daily encrypted backups protect the data itself, beyond just the server.

### Room to Expand

Add block storage volumes or scale the build as the workload grows, with custom sizing scoped by the team.

## What's Included

### Configurable CPU, RAM, and Disk

Choose the ratio that fits the workload. Memory-light archive targets, balanced database servers, and analytics nodes that need both capacity and throughput are all sized to order and built to their own specs.

### Dedicated and Bare Metal Options

Run storage workloads on single-tenant Fortress dedicated and bare metal servers for isolated, predictable disk performance, full root access, and hardware-level control, with custom storage configurations available.

### Scalable Block Storage

Secure Block Storage attaches elastic, replication-enabled volumes with snapshots, so you can grow capacity without rebuilding the server. It is one storage option among several; the right mix depends on the workload.

### Backup and Replication

Managed Veeam backups run daily to on-site and off-site encrypted storage. High-availability and replication options keep data accessible through hardware events, and disaster-recovery configurations add an off-site copy you can fail over to.

### Private Networking and VPC

Keep storage traffic off the public internet. Private networking and VPC isolation connect storage nodes to application and database servers over a private path, which matters for both performance and security.

### Managed Services for Storage Workloads

Add server management for monitoring, patching, and operational support, plus database administration and backup management, so a growing storage estate does not become a growing operational burden.

### Built for Data-Heavy Workloads

Sized for large databases, backup repositories, file and media libraries, log and event stores, analytics data sets, and compliance or healthcare archives, the workloads where capacity, durability, and steady throughput matter more than peak clock speed.

### Custom Builds for Unusual Requirements

When the storage requirement does not fit a standard configuration, the team scopes a custom build: specific disk layouts, larger capacity, particular RAID levels, or a hybrid of dedicated hardware and cloud block storage.

## Dedicated Storage Servers vs Cloud Block Storage vs Hybrid Storage

There is no single right answer; it depends on how the data is used. This comparison is a starting point, and exact sizing still needs to be checked with the team.

|  | Dedicated Storage Servers | Cloud Block Storage | Hybrid Storage |
| --- | --- | --- | --- |
| Best for | Large databases, heavy sustained I/O, and single-tenant control | Elastic capacity attached to cloud servers and growing data sets | Mixed environments with fast primary storage on dedicated infrastructure and elastic capacity in the cloud |
| Capacity model | Fixed at deployment and expandable through custom scoping | Elastic volumes that grow on demand | Combines both models according to workload requirements |
| Performance | Predictable, isolated, hardware-level performance | Strong performance over a shared cloud fabric | Tiered, with hot data on dedicated storage and cooler data in the cloud |
| Management | Self-managed or fully managed | Managed by Atlantic.Net | Management selected per component |
| When to choose | You need isolation and consistent throughput | You need flexibility and rapid growth | You need both models across different storage tiers |

## When Should I Use a Storage-Optimized Server for a General-Purpose Cloud Workload?

Choose storage-optimized infrastructure when the data set drives the requirement ahead of the compute: when you are adding disk far faster than CPU, when backups or archives keep growing, when a database's working set is large, or when throughput under heavy read/write load is becoming a bottleneck. A general-purpose cloud server is the better fit when compute and memory are the leading requirements and storage is modest.

## Business Outcomes

### Capacity That Grows With Your Data

Disk is sized to the workload and expanded via block storage or a custom build, so storage growth is planned and stays off the emergency list.

### Predictable Performance for Heavy I/O

Single-tenant hardware and RAID-10 NVMe/SSD storage keep read and write performance steady, so a busy backup window or analytics job does not stall everything else.

### Data You Can Recover

Daily encrypted backups, replication, snapshots, and disaster-recovery options protect the data itself. A failed disk or a bad night leaves a restore job, and the data survives.

### Control Without the Operational Load

Managed monitoring, patching, backup management, and database administration are available as services, so a large storage estate does not pull your team into day-to-day operations.

## Who Needs Storage-Optimized Servers

| Workload | Why It Fits |
| --- | --- |
| Backup and archive targets | High-capacity, durable storage with replication and off-site copies |
| Large databases | Isolated, high-throughput storage for large working sets and intensive queries |
| Media and content libraries | Scalable capacity for images, video, and large file repositories |
| Log and analytics stores | Sustained write throughput and expandable capacity for event and log data |
| Healthcare and compliance archives | Encrypted, audited storage within HIPAA- and PCI-ready environments |
| Research and scientific data sets | Large, expandable capacity for data-intensive processing |
| MSPs and agencies | Consolidated and managed storage across multiple clients and projects |

## A Platform You Can Trust

Atlantic.Net has run data-intensive infrastructure since 1994. Storage-optimized servers run on the same audited platform as our compliance hosting, so capacity, durability, and security come together in a single build.

### Audited Environments

SOC 2 Type II, SOC 3 Type II, HIPAA, HITECH, PCI DSS 4.0, and NIST 800-53 audited environments.

### RAID-10 NVMe/SSD Storage

Standard on every build, with encrypted on-site and off-site backups.

### 100% Uptime SLA

Covering network, hardware, and power.

### 24/7/365 US-Based Support

By phone, email, and chat, never outsourced.

### Atlantic.Net Since 1994

32 years operating data center infrastructure.

## Frequently Asked Questions

### What is a storage-optimized server?

A storage-optimized server is infrastructure weighted toward disk capacity and throughput, with right-sized CPU and memory paired with high-capacity, high-performance storage, so the configuration and cost follow the data. Atlantic.Net offers it as Storage-Optimized cloud servers, dedicated and bare-metal builds with custom storage, and Secure Block Storage volumes.

### When should I choose a dedicated storage server?

Choose dedicated when you need single-tenant isolation, consistent throughput under heavy load, or hardware-level control, common for large databases and sustained-I/O workloads. Cloud block storage is the better fit when you need elastic capacity that scales on demand, and a hybrid design uses both: fast primary storage on dedicated hardware and elastic capacity in the cloud.

### Can Atlantic.Net support large databases or file repositories?

Yes. Databases run on dedicated, bare metal, or cloud instances sized for the working set, with managed administration, tuning, high availability, and replication available. File and media repositories use high-capacity storage with backups and replication. For very large or unusual requirements, the team scopes a custom build.

### Is Secure Block Storage available?

Yes. Secure Block Storage provides elastic, replication-enabled volumes with snapshots that can be attached to cloud or dedicated infrastructure. It is one of several storage options; depending on the workload, dedicated storage servers or a hybrid design may suit better, which is what the consultation works out.

### Can storage capacity be expanded over time?

Yes. Block storage volumes can scale with the data set, and dedicated builds can be scoped for expansion. Because some growth paths involve a hardware change, it helps to talk to the team early so capacity is planned and built in from the start.

### Can Atlantic.Net help with backup and disaster recovery?

Yes. Managed Veeam backups run daily to on-site and off-site encrypted storage, with replication and disaster-recovery configurations that keep an off-site copy ready to fail over to. Backup and DR can be applied to both storage servers and the workloads that depend on them.

### Are managed services available for storage servers?

Yes. Server management covers monitoring, patching, and operational support; database administration covers configuration, tuning, and security; and backup management handles the backup and replication estate. You can run storage servers self-managed or hand over day-to-day operations to Atlantic.Net engineers.

## Request a Storage Quote

Storage-optimized infrastructure is sized to the workload, so custom builds start with a short consultation. Tell us how much data you hold, how it grows, and how it is used, and a storage specialist will scope dedicated, cloud, or hybrid capacity with the backups and replication to match.

Call Us: 866-618-3282

Atlantic.Net: Secure Cloud Hosting & Infrastructure Since 1994.

## Cloud Availability in Multiple Global Regions

Deploy close to your users from eight international data centers worldwide, with new regions on the way.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Best HIPAA-Compliant Hosting Providers for Medical Practices (2026)

> URL: https://www.atlantic.net/hipaa-compliant-hosting/best-hipaa-compliant-hosting-providers-medical-practices/ | Published: 2026-06-25 | Author: Richard Bailey

HIPAA-compliant hosting is a hosting environment that meets the technical and physical safeguards of the HIPAA Security Rule for storing, transmitting, or processing electronic Protected Health Information (ePHI), backed by a signed HIPAA Business Associate Agreement (BAA).

Medical practices store ePHI across electronic health records, billing platforms, patient portals, file systems, and backups. The infrastructure supporting those systems forms part of the practice’s HIPAA compliance model, determining how patient data is protected, which safeguards the provider manages, and which responsibilities remain with the practice.

Search for “HIPAA hosting,” and every provider displays a “HIPAA-ready” or “HIPAA-compliant” badge. Still, the badge rarely explains what is included: whether the provider signs a BAA, whether its controls have been independently audited, and where its responsibility ends, and the practice’s begins.

For a small or mid-size medical practice without a dedicated security team, the scope of the hosting service matters. Providers that sign a BAA, operate audited controls, and manage the security stack reduce the amount of infrastructure the practice must secure and maintain.

The list below compares the providers most relevant to medical practices, focusing on what each service includes and which responsibilities remain with the customer.

## Key Takeaways

- A signed BAA is non-negotiable. Without one, hosting cannot be HIPAA-compliant, regardless of the security features it lists.
- Managed security reduces the practice’s burden. Favor providers that run the firewall, patching, and monitoring instead of leaving configuration to you.
- Independent audits carry the weight. SOC 2 Type II and HIPAA attestations from a third-party CPA firm beat self-certification.
- Atlantic.Net bundles all three (BAA, managed security, and annual audits) into standard plans aimed at healthcare.
- Hosting alone does not make you compliant. Workforce training, access policies, risk assessments, and application security stay with the practice.

## What “HIPAA-Compliant Hosting” Actually Means

“HIPAA-compliant hosting” refers to an environment designed to meet the technical and physical safeguards required by the HIPAA Security Rule for systems that store, transmit, or process electronic Protected Health Information (ePHI). Any server holding appointment records, lab results, insurance details, or other individually identifiable health information is in scope.

The first requirement is a signed BAA. A hosting provider that handles ePHI on behalf of a covered entity (a medical practice, health plan, or healthcare clearinghouse) qualifies as a business associate. Without a signed BAA, the arrangement is not HIPAA-compliant by definition, regardless of what the marketing page says. The BAA binds the provider to the same confidentiality and security obligations that the practice itself is subject to.

Encryption is the second baseline. HIPAA requires covered entities and business associates to protect ePHI in transit and at rest. In transit means TLS-encrypted connections for any web application, API, or data transfer that carries patient information. At rest, the disks and backup media must be encrypted, so physical access to hardware does not mean access to readable data.

Audit trails and access controls are equally non-negotiable. The Security Rule requires covered entities to track every interaction with ePHI: who accessed a record, when, and what they did with it. Access must be restricted by role; a billing clerk does not need to read clinical notes. A compliant host provides the infrastructure through detailed logging, role-based access control (RBAC), and multi-factor authentication, but the practice configures those controls inside its applications.

Hosting alone does not make a practice HIPAA-compliant. A compliant host provides a secure, audited infrastructure foundation. Still, the HIPAA Privacy Rule, workforce training, written policies and procedures, physical safeguards at the practice’s own offices, and the annual risk assessment all remain the practice’s obligations regardless of who hosts its systems. The shared-responsibility line runs through the middle of every HIPAA hosting relationship.

## How to Choose a HIPAA Host for a Medical Practice

A HIPAA host for a medical practice must do five things, each of which is covered below.

**Signed BAA.** The BAA must be included with the hosting plan and be available before any ePHI is moved to the provider’s infrastructure. Some providers offer it as an add-on or only on enterprise contracts. A provider that bundles it as standard across all plan tiers eliminates the need for a separate procurement for a small or solo practice.

**Independent audits.** A provider that self-certifies HIPAA compliance carries less weight than one audited by an independent CPA firm under the AT-C 105/205 attestation standard. SOC 2 Type II reports, produced under that framework, cover security, availability, and confidentiality controls over 12 months and give a third party’s opinion on whether stated controls actually operated. A HIPAA attestation tells you the environment was tested against the Security Rule by someone with no stake in the outcome.

**Managed security**. Few medical practices employ a full-time security operations team. A host that manages the firewall, runs intrusion detection, patches the operating system, and scans for vulnerabilities transfers much of that burden off the practice. “HIPAA-eligible” infrastructure (the label AWS and Azure use) can be configured to support HIPAA workloads, but the configuration work falls to the customer. A fully managed HIPAA host owns that configuration and its ongoing maintenance.

**Backups and disaster recovery.** The Security Rule requires contingency planning: a data backup plan and a disaster recovery plan, meaning automated, encrypted backups retained offsite and a documented procedure for restoring systems after an incident. High-availability architecture, verified restoration testing, and a clear recovery time objective (RTO) are the operational translation of that requirement.

**Enforcement reality.** The Office for Civil Rights (OCR) enforces HIPAA. It can issue civil monetary penalties of up to approximately $1.5 million per violation category per calendar year for wilful neglect that is not corrected. , inflation-adjusted figures published by HHS have cited annual caps as high as $2.19 million per category. Breaches affecting 500 or more individuals must be reported to HHS and the affected individuals within 60 days of discovery; smaller breaches are recorded in an annual log. Annual risk assessments and written policies are required by regulation, not optional. Fifteen of the seventeen patient rights cases OCR investigated in 2022 ended in settlements, an indication of the enforcement posture. Providers that score well treat HIPAA compliance as continuous operational controls, not a badge applied at signup.

## The Best HIPAA-Compliant Hosting Providers for Medical Practices

The seven providers below are evaluated against the five-point rule. Atlantic.Net leads because it is the only one here to bundle all five into a standard hosting plan for medical practices and similar covered entities.

### HIPAA Hosting Provider Comparison

| **Provider** | **BAA Included** | **Managed Security** | **Independent Audits** | **Best For** |
| --- | --- | --- | --- | --- |
| **Atlantic.Net** | Yes, standard on all tiers | Full stack: managed firewall, IPS, and 24/7 SOC | SOC 2 Type II, SOC 3 Type II, HIPAA, HITECH | Small to mid-size practices that want turnkey compliance |
| **ClearDATA** | Yes | Compliance management layer | SOC 2, HIPAA | Large health systems running on multi-cloud |
| **MedStack** | Yes | Platform-level controls | SOC 2, HIPAA | Healthtech developers building applications |
| **US Signal** | Yes | Available | SOC 2, HIPAA | Regional practices that need disaster recovery coverage |
| **LightEdge** | Yes | Available | HIPAA, HITRUST, SOC 2 | Organizations colocating existing hardware |
| **AWS** | Yes, via BAA addendum | Customer-configured | SOC 2, HIPAA infrastructure controls | Teams with in-house cloud engineering capacity |
| **Microsoft Azure** | Yes, via Online Services Terms | Customer-configured | SOC 2, HIPAA infrastructure controls | Microsoft 365 organizations with internal engineering teams |

### 1. Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

Atlantic.Net has provided[HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) for healthcare organizations since before most of today’s HIPAA enforcement regime existed. The core offering is the Fortress HIPAA platform, in Developer, Business, DR, and Custom tiers, on Linux or Windows. A BAA is standard on every HIPAA plan, no negotiation required. The entry Business configuration runs on 6 vCPU, 16 GB of RAM, 200 GB of SSD storage, and 10 TB of transfer on a 12-month term, a defined, audited starting point for a small or mid-size practice.

The[managed services](https://www.atlantic.net/managed-services/) layer separates Atlantic.Net from providers that supply compliant infrastructure but leave the security configuration to the customer. Every Fortress plan includes a fully managed FortiGate firewall with intrusion prevention (IPS) and intrusion detection, bi-weekly vulnerability scanning, file integrity monitoring, MFA, RBAC, and a managed encrypted VPN with 5 accounts. Business tier and above add Trend Micro Deep Security for host-based endpoint protection. Encrypted backups run daily, both on-site and offsite. The 24/7 US-based security operations center is Atlantic.Net staff, never outsourced, and the[100% uptime SLA](https://www.atlantic.net/hosting-services-provider/100-uptime-sla/) exceeds the standard 99.9% hyperscaler commitment.

A third-party CPA firm independently assesses Atlantic.Net each year under SOC 2 Type II, SOC 3 Type II, SSAE 18, HIPAA, and HITECH. HIPAA customers are placed in private, dedicated hosting environments, removing the cross-tenant risk shared infrastructure introduces for ePHI, and detailed audit logging supports the access-trail requirement. Atlantic.Net also includes four hours of managed migration for HIPAA customers moving from an existing host.

What stands out:

- **BAA is included as standard** across all Fortress tiers, with no additional contract process.
- **Fully managed security stack:** FortiGate with IPS, bi-weekly vulnerability scans, Trend Micro Deep Security (Business+), file integrity monitoring, daily encrypted offsite backups, and a 24/7 US-staffed SOC.
- **Independent annual audits:** SOC 2 Type II, SOC 3 Type II, SSAE 18, HIPAA, and HITECH attestation by an independent CPA firm.

Best fit: Practices that want the host to own infrastructure security end-to-end, with the BAA, managed controls, and audit reports available without procurement.

### 2. ClearDATA

![](https://www.atlantic.net/wp-content/uploads/2026/03/ClearDATA-logo.png)

ClearDATA operates as a healthcare-exclusive managed cloud, deploying to AWS, Azure, and GCP, with a compliance management layer built for healthcare workloads. It focuses on large health systems, hospital networks, and digital health companies that manage regulated workloads across multiple clouds. A BAA is available, and the platform includes compliance safeguards and automated monitoring aligned to HIPAA requirements.

Its pricing and architecture suit organizations with dedicated cloud or compliance teams that need governance across a multi-cloud estate. A small practice running a single application would pay for itself, as it does not need to.

What stands out:

- **Healthcare-exclusive cloud management** across AWS, Azure, and GCP with a dedicated compliance monitoring layer.
- **Automated compliance controls** that map to HIPAA technical safeguards and generate audit-ready evidence.
- **Strong multi-cloud fit,** with a single compliance governance layer across providers as the priority.

Best fit: Mid-to-large health systems and digital health companies on existing AWS, Azure, or GCP infrastructure needing managed compliance governance across clouds.

### 3. MedStack

![](https://www.atlantic.net/wp-content/uploads/2026/06/medstack-logo.png)

MedStack is a compliance-as-a-platform product that gives software teams building digital health applications a compliant hosting foundation, with HIPAA and PIPEDA controls built into the infrastructure layer. Developers deploying patient-facing applications use its container-based environment to inherit a baseline compliance posture rather than build it from scratch.

For a practice running off-the-shelf EHR or practice management software from a named vendor, MedStack is a poor fit. It is structured around application development, and the operational controls a clinic needs (managed firewall, patch management, 24/7 monitoring, a BAA with a managed hosting provider) are not its primary use case.

What stands out:

- **Compliance-as-a-platform model** that embeds HIPAA controls into the container environment.
- **Developer-oriented tooling** for teams building HIPAA-regulated applications from the ground up.
- **BAA is available** to covered entities and business associates who use the platform.

Best fit: Healthtech developers and digital health companies building regulated applications; less suited to clinical practices that host third-party EHR or practice management software.

### 4. US Signal

![](https://www.atlantic.net/wp-content/uploads/2026/06/US-Signal.png)

US Signal is a Michigan-based managed services provider offering HIPAA-compliant cloud hosting, colocation, and disaster recovery across US data centers. It signs BAAs and positions itself as a managed alternative to the hyperscalers for mid-market healthcare organizations that prefer a domestic provider with direct support. Its DR product includes failover environments relevant to the HIPAA contingency planning requirement.

Its product set is broader than HIPAA-specific hosting, serving a range of regulated industries. That breadth helps a practice that also needs DR or colocation alongside cloud hosting, though the healthcare-specific depth of a dedicated HIPAA host is less pronounced.

What stands out:

- **US-only data centers** with managed hosting and DR options that address HIPAA contingency planning directly.
- **BAA is available** alongside managed cloud and colocation services.
- **Mid-market positioning** with direct support and pricing between hyperscalers and healthcare specialists.

Best fit: Regional practices and mid-market healthcare organizations in the US Midwest and Great Lakes area wanting a domestic managed provider with DR coverage.

### 5. LightEdge

![](https://www.atlantic.net/wp-content/uploads/2026/06/lightedge.jpg)

LightEdge operates compliance-focused colocation and managed hosting facilities, with a compliance posture that spans HIPAA, HITRUST, SOC 2, and PCI DSS. It maintains dedicated data centers with independent audits and offers managed security services alongside its colocation racks. BAAs are available for healthcare customers.

Colocation is the core LightEdge use case. A practice that owns server hardware and needs a compliant, audited facility finds a clear path here. Managed cloud hosting is also viable, though the product set is geared toward organizations with on-premises infrastructure to place.

What stands out:

- **Compliance-audited colocation** with HIPAA, HITRUST, SOC 2, and PCI-DSS attestations.
- **Managed security services** are available alongside colo and hosted infrastructure.
- **BAA available** for healthcare workloads, with physical and environmental controls independently verified.

Best fit: Practices and healthcare organizations with existing hardware that need a compliant colocation environment, or organizations in LightEdge’s regions seeking audited managed hosting.

### 6. Amazon Web Services (AWS)

![](https://www.atlantic.net/wp-content/uploads/2025/04/aws.png)

AWS offers a large set of HIPAA-eligible services and will sign a BAA under its AWS Business Associate Addendum. The BAA covers a defined list of services, and workloads that store or process ePHI must run exclusively on those within a compliant architecture. AWS holds independent SOC 2 and HIPAA audit reports for its underlying infrastructure.

The caveat is the shared-responsibility model. AWS secures the physical infrastructure, hypervisor, and networking layer; the customer configures every service, encryption key, access policy, security group, and logging rule. A misconfigured S3 bucket, an overpermissive IAM role, or a missing CloudTrail log can each introduce a HIPAA violation on infrastructure AWS itself has audited, substantial operational risk for a small practice without dedicated cloud engineering.

What stands out:

- **Broad HIPAA-eligible service catalog** and a signed BAA for qualifying accounts.
- **AWS infrastructure audits** cover the physical and hypervisor layers; SOC 2 and HIPAA attestations are available.
- **Maximum architectural flexibility** for organizations with cloud engineering teams designing custom HIPAA-compliant environments.

Best fit: Healthcare technology companies and larger health systems with dedicated cloud engineering and compliance teams that need AWS’s breadth and can own the configuration. Not recommended for small practices without managed compliance support.

### 7. Microsoft Azure

![](https://www.atlantic.net/wp-content/uploads/2025/05/azure-logo.png)

Azure’s HIPAA and HITECH offerings follow the same model as AWS. Microsoft signs a BAA as part of its Online Services Terms, which covers a defined set of Azure services. It holds independent third-party audit reports for its infrastructure. Azure adds compliance tools, including Azure Policy, Microsoft Defender for Cloud, and prebuilt HIPAA/HITRUST blueprints that provide engineering teams with a starting configuration.

The same shared-responsibility caveat applies. Microsoft secures the underlying platform; the customer configures and operates the services on it. For practices already invested in Microsoft 365, Azure is a natural extension, with familiar identity management through Azure Active Directory. Building a compliant Azure environment from scratch still requires cloud engineering work, either performed by the customer or by a managed partner.

What stands out:

- **BAA is included** in Microsoft’s Online Services Terms for covered Azure services.
- **Microsoft Defender for Cloud and HIPAA/HITRUST blueprints** give a documented starting point for compliant configuration.
- **Strong** with Microsoft 365, Azure Active Directory, and existing Microsoft enterprise tooling.

Best fit: Healthcare organizations and practices already operating in Microsoft 365 with cloud engineering capacity to configure and maintain a compliant Azure deployment.

## What hosting cannot do for your HIPAA Compliance?

A signed BAA and an independently audited hosting environment are necessary conditions for HIPAA compliance, but not sufficient. The Security Rule divides its requirements into administrative, physical, and technical safeguards. A hosting provider covers the technical safeguards at the infrastructure layer and the physical safeguards at the data center; the administrative and technical safeguards within the practice’s own operations remain the practice’s responsibility.

**Application security.** The host secures the server and the network; the application running on it is a separate question. A patient portal with an authentication flaw, a contact form that stores unencrypted submissions, or an EHR that transmits ePHI without TLS are all application-layer issues that compliant hosting cannot fix. The practice, or its software vendor, owns that surface.

**Workforce training.** HIPAA requires annual training for all workforce members with access to ePHI on the relevant policies and procedures. Hosting providers do not deliver it, and no configuration substitutes for it.

**Access policies and user management**. A compliant host provides RBAC infrastructure and audit logging. The practice must implement the following: creating unique user accounts, assigning roles that reflect the minimum necessary access standard, promptly disabling accounts when staff leave, and reviewing access logs for anomalous activity. These administrative responsibilities are the practice’s.

**Annual risk assessment.** HIPAA requires covered entities to conduct a risk analysis identifying risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI across the entire information environment. That covers the hosted infrastructure, workstations, mobile devices, paper records, fax machines, and any other medium that handles patient information. A hosting provider cannot perform it; it must be conducted, documented, and reviewed annually.

**Written policies and procedures.** HIPAA requires covered entities to maintain written policies and procedures that implement the Security Rule and to retain them for 6 years. They are the practice’s documents, not the hosting provider’s.

**The shared-responsibility model** is the honest foundation of every HIPAA hosting relationship: the right host substantially reduces the infrastructure compliance burden, but does not eliminate the work the practice must do on its own side of the line.

## Frequently Asked Questions

**What does “HIPAA-compliant hosting” actually mean?**

HIPAA-compliant hosting refers to an environment built to meet the technical and physical safeguards required by the HIPAA Security Rule for systems that store, transmit, or process electronic Protected Health Information (ePHI). It must include a signed BAA, encryption in transit and at rest, audit logging, and role-based access controls.

**Does a HIPAA hosting provider have to sign a BAA?**

Yes. Any hosting provider that handles ePHI on behalf of a covered entity is legally a business associate, and a signed BAA is required by law. A provider that refuses to sign one, or only offers it at an enterprise tier, cannot be used for ePHI workloads without exposing the practice to liability.

**Is cloud hosting HIPAA-compliant automatically?**

No. Cloud hosting can support HIPAA workloads, but the word “cloud” does not make an environment compliant. The environment must still meet encryption, access control, audit trail, and BAA requirements, and platforms like AWS or Azure require the customer to configure and maintain a compliant architecture themselves.

**What security features should a HIPAA host include?**

A HIPAA host should provide encryption at rest and in transit, a managed firewall with intrusion detection, role-based access control, multi-factor authentication, detailed audit logging, regular vulnerability scanning, and automated encrypted backups with offsite retention.

**Can a small medical practice afford HIPAA-compliant hosting?**

Yes. Managed HIPAA hosting is available at price points accessible to solo and small-group practices, and bundling security controls such as firewall management, vulnerability scanning, and 24/7 monitoring into a single plan typically costs less than building and maintaining the same environment independently.

**Does using a major cloud provider like AWS or Azure guarantee HIPAA compliance?**

No. AWS and Azure offer HIPAA-eligible services and will sign a BAA. Still, they operate under a shared-responsibility model where the customer is responsible for configuring services, managing access policies, and maintaining a compliant architecture. A misconfigured setting can lead to a HIPAA violation within the infrastructure that the provider itself has audited.

**What does hosting not cover in a HIPAA compliance program?**

A compliant host covers infrastructure-level technical and physical safeguards. Still, the practice remains responsible for application security, annual risk assessments, workforce training, written policies and procedures, and user access management. Hosting is a necessary foundation, not a complete compliance solution.

**What happens if a practice experiences a data breach?**

Under the HIPAA Breach Notification Rule, a covered entity must notify affected individuals and HHS within 60 days of discovering a breach of unsecured ePHI. Breaches affecting 500 or more individuals also require notification to prominent local media, and OCR may impose civil monetary penalties of up to roughly $1.5 million per violation category per year for wilful neglect not corrected.

## Key Terms

**Business Associate Agreement (BAA):** The contract HIPAA requires between a covered entity and any vendor that stores, processes, or transmits ePHI on its behalf, setting out each party’s safeguards.

**Electronic Protected Health Information (ePHI)**: Individually identifiable health information created, stored, transmitted, or received electronically, including records, billing, and clinical data.

**Covered Entity**: A health plan, healthcare clearinghouse, or healthcare provider that transmits health information electronically and is directly accountable under HIPAA.

**Shared Responsibility Model**: The split between the provider’s infrastructure-level controls and the customer’s application security, access policies, and compliance program.

## Choosing the Right HIPAA Host for Your Practice

Atlantic.Net builds its HIPAA hosting around the parts a medical practice cannot reasonably carry alone: the signed BAA, the managed FortiGate firewall with IPS, bi-weekly vulnerability scanning, encrypted offsite backups, and 24/7 US-based monitoring, all on infrastructure independently audited under SOC 2 Type II, SOC 3 Type II, HIPAA, and HITECH. That leaves the practice to own half of compliance, only it can: its application, access policies, staff training, and annual risk assessment.

If your practice is weighing a HIPAA host or moving off one that never explained where its responsibilities ended, Atlantic.Net can first review your application stack, compliance requirements, and migration path.[Contact the Atlantic.Net team](https://www.atlantic.net/about-us/corporate-contact/) to scope HIPAA-compliant hosting for your practice.


---

# Fully Managed HIPAA-Compliant Cloud Hosting for Healthcare Startups and Clinics

> URL: https://www.atlantic.net/hipaa-compliant-hosting/fully-managed-hipaa-compliant-cloud-hosting-for-healthcare-startups-and-clinics/ | Published: 2026-06-25 | Author: Richard Bailey

Fully managed, HIPAA-compliant cloud hosting provides healthcare organizations with infrastructure designed to support workloads that contain electronic Protected Health Information (ePHI). The provider signs a HIPAA Business Associate Agreement (BAA) and manages defined infrastructure controls, including encryption, system patching, audit logging, backups, vulnerability management, and security monitoring.

Healthcare startups and smaller clinics often need these controls before they have the internal staff to operate them. A telehealth company may need to secure its first production application, while a clinic moving from paper records may need to protect patient data across servers, databases, backups, and remote access systems.

Building that environment internally requires more than deploying a cloud server. The organization must configure network controls, encryption, logging, backups, identity management, vulnerability scanning, monitoring, and recovery procedures. It must then maintain those controls as the application, workforce, and regulatory risk change.

A fully managed service reduces that infrastructure workload by assigning defined operational responsibilities to the hosting provider. The value depends on the scope of the service: whether the provider signs a BAA, manages the security controls, monitors the environment, applies patches, protects backups, and provides evidence that its controls have been independently assessed.

The customer still retains responsibility for its application, users, data handling, policies, risk assessments, and wider HIPAA compliance program. The purpose of fully managed hosting is to provide a secure, well-managed infrastructure layer, with a clear division between the controls handled by the provider and those retained by the healthcare organization.

## Key Takeaways

- “Fully managed” only counts when the provider runs the technical safeguards, holds the BAA, and keeps the environment patched and monitored.
- The shared-responsibility line is fixed: the provider owns infrastructure controls; the team owns application security, access policies, training, and risk assessments.
- A managed tier lets a lean team launch on audited controls (SOC 2 Type II, SOC 3 Type II, HIPAA, HITECH) from day one.
- The most common startup mistakes are deploying without a signed BAA and deferring compliance until after launch.

## What Fully Managed HIPAA-Compliant Hosting Actually Means

HIPAA-compliant hosting is a specific operational claim, not a badge a provider sticks on a pricing page. For any infrastructure handling electronic Protected Health Information (ePHI), the HIPAA Security Rule mandates a set of technical safeguards: encryption in transit and at rest, access controls, audit logging, integrity controls, and transmission security. A compliant provider must maintain those safeguards on the infrastructure it controls, sign a BAA acknowledging its responsibilities under the law, and produce evidence when asked.

“Fully managed” tightens that definition. The provider’s engineers handle OS and software patching, firewall configuration and rule management, regular vulnerability scanning, server monitoring, backup execution, and incident response at the infrastructure layer. The customer pays a monthly fee and receives a running, monitored, patched environment instead of a raw server to configure from scratch.

The BAA is the legal anchor. Without a signed BAA, no provider qualifies as HIPAA-compliant, regardless of its data centers or security tools. It defines what the provider is responsible for, what the customer retains, and what happens in the event of a breach. Any HIPAA hosting provider that has not raised the BAA in the initial conversation is missing a foundational requirement.

Data encryption is mandatory across the board. For ePHI at rest, AES-256 is the accepted standard; in transit, TLS 1.2 or higher applies. A managed HIPAA host should configure encryption at the infrastructure layer, including encrypted storage volumes and backup sets, so the customer is not left managing disk-level keys on a server it cannot fully control.

## What a Managed Provider Handles (And What You Still Own)

Teams that expected fully managed hosting to remove HIPAA compliance work entirely run into the shared-responsibility model. A managed provider covers the infrastructure-level controls HIPAA’s Security Rule defines; the customer owns everything above that layer.

The provider’s side includes OS patching, firewall policy management, intrusion detection and prevention, server monitoring, vulnerability scanning, backup execution, off-site replication, encryption at the storage layer, physical data-center security, and audit logging of infrastructure-level events. A well-managed provider can produce that documentation when an auditor requests evidence of patch management, access logs, or backup retention. That is the foundation a startup or clinic inherits.

The customer’s side of the line includes:

- **Application security.** How the application handles ePHI: input validation, output encoding, session management, API authentication. The provider cannot see inside the application.
- **User access policies.** Who can access ePHI systems, under what conditions, and what happens when someone leaves? Server-level role-based access controls help, but the policies governing who gets access belong to the customer.
- **Workforce training.** HIPAA’s Security Rule requires covered entities and business associates to train staff on security policies. No provider can satisfy this on a customer’s behalf.
- **Risk assessments.** HHS requires regular, documented risk assessments of ePHI systems. The provider can supply infrastructure documentation to feed the assessment, but the assessment itself is the customer’s responsibility.
- **Breach notification procedures.** After an incident, the provider handles the infrastructure side; the customer notifies affected individuals, HHS, and the media where required.

Atlantic.Net’s[HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) is explicit about this split: the platform delivers the technical safeguards, and the customer owns the application layer and the operational compliance program around it. Treating the provider’s BAA as a complete compliance solution rather than as one part of a broader program is the most common HIPAA hosting misunderstanding a startup can make.

### What the Provider Handles vs. What You Own

| **Provider handles (infrastructure)** | **You own (application and program)** |
| --- | --- |
| **OS and software patching** | Application security, including input validation, session management, and API authentication |
| **Managed firewall and IDS/IPS** | User access policies and provisioning |
| **Vulnerability scanning** | Workforce HIPAA training |
| **Encrypted backups and offsite repoffsiten** | Risk assessments and documentation |
| **Storage-layer encryption** | Breach notification to individuals, HHS, and the media |
| **Physical data center security** | Security policies governing ePHI access |
| **Infrastructure audit logging** | Application-level logging and monitoring |

## Why Startups and Clinics Choose Managed Over DIY

The DIY path is achievable, but its cost in time, staffing, and risk is rarely proportionate to what a lean team can absorb. Building a HIPAA-compliant infrastructure from scratch means standing up a firewall and IPS rules, deploying intrusion detection, managing encrypted storage, running vulnerability scans, establishing off-site backup, maintaining detailed audit logs, and finding a third-party auditor to verify it all. For a founding team of four or five, that is overhead, not the product: weeks added to launch and ops headcount the team lacks.

The managed alternative starts elsewhere. A team deploying on a managed HIPAA tier walks into an environment where the firewall is configured and managed, the IDS/IPS is running, vulnerability scans happen on a fixed cycle, encrypted daily backups run automatically, and the BAA is signed as part of the plan. The team still builds and secures the application, manages user access policies, and runs a risk assessment, but the technical safeguard layer is ready on day one.

Consider a two-person engineering team building a patient-facing telehealth application that needs HIPAA-compliant infrastructure before its first video consultation. Deploying on a managed HIPAA cloud tier that inherits audited controls covering SOC 2 Type II, SOC 3 Type II, HIPAA, and HITECH lets them spend the first two weeks on the application instead of configuring infrastructure. The foundation is documented, the BAA is signed, and if a healthcare system partner asks for evidence of their hosting compliance posture, the team has something to show.

Two benefits compound over time. First, breach risk and liability drop when a team runs the technical safeguard layer focused entirely on infrastructure security. Healthcare cyberattacks have increased year over year, and OCR fines for HIPAA violations can reach $1.5 million per violation category per year. A misconfigured firewall rule or a missed patch on a self-managed server is a real exposure, not a theoretical one. Second, investors and healthcare system partners increasingly ask compliance questions during due diligence, and a signed BAA with an audited[managed services](https://www.atlantic.net/managed-services/) provider, plus documented controls, is a more credible answer than a self-attested security posture.

## The Managed Security Stack to Expect

The controls that make up a credible managed HIPAA hosting environment are well defined. Any provider making the “fully managed HIPAA-compliant” claim should specify each of the following in writing.

**Firewall management**. A managed FortiGate firewall with integrated Intrusion Prevention System (IPS) should be included, not an add-on. The provider configures and maintains the rules; the customer never touches the firewall console. Atlantic.Net’s Fortress Business and DR tiers include FortiGate with IPS; the Fortress Developer tier includes FortiGate without IPS.

**Intrusion detection and prevention (IDS/IPS)**. Active intrusion detection and prevention monitors traffic for known threat signatures and automatically blocks malicious activity; a passive alerting system is insufficient. This feeds 24/7 SOC monitoring, so a flagged signature triggers a response and investigation, with the log entry as the record.

**Vulnerability scanning**. Bi-weekly scanning on a fixed schedule, with results reported and remediated by the provider, satisfies the HIPAA Security Rule’s requirement for regular evaluation of security controls. On-demand-only scanning is a gap that surfaces in audits.

**Encryption**. Encrypted storage volumes for ePHI at rest, TLS in transit, and encrypted onsite and offsite backups. Backup encryption is most often skipped on DIY builds; an unencrypted backup set is a HIPAA exposure, well the live environment is secured.

**Endpoint and server security.** Trend Micro Deep Security Suite, included on Fortress Business tiers and above, handles anti-malware, virtual patching, and file integrity monitoring at the server level. Operating between the hypervisor and the OS, it detects threats that OS tools may miss.

**Identity controls**. Multi-factor authentication (MFA) and role-based access controls (RBAC) are mandatory, not optional add-ons. The managed VPN (5 accounts included on Atlantic.Net Fortress plans) gives authorized administrators encrypted remote access without exposing the environment to the public internet.

**Audit logging and retention**. HIPAA requires that audit logs be retained for a minimum of 6 years. The provider’s Log Management System should capture detailed access and administrative action logs with full traceability in a format that satisfies an auditor. Immutable retention is the standard; logs that can be altered afterward are not compliant.

**Disaster recovery and backups**. On-site enforces daily backups to satisfy the backup requirement; a formal DR tier (such as Atlantic.Net’s Fortress DR Hosting) adds replication and a tested recovery path. Backups without a recovery test are a common audit finding.

**24/7 SOC monitoring**. A US-based Security Operations Center with continuous monitoring detects and responds to incidents at 2 am as readily as at 2 pm. Remote, outsourced, or business-hours-only monitoring does not meet the standard for a regulated workload.

Atlantic.Net’s Fortress HIPAA tiers start with 6 vCPU, 16 GB of RAM, 200 GB of SSD storage, and 10 TB of transfer. The BAA is included as standard across all tiers, and[server management](https://www.atlantic.net/managed-services/server-management/) covers OS patching, monitoring, and troubleshooting, handled by certified engineers, not a ticket queue.

### HIPAA Hosting Requirements Checklist

Before choosing a provider, confirm each of these is in place:

1. Signed BAA (BAA) included as standard
2. Encryption at rest (AES-256) and in transit (TLS 1.2+)
3. Role-based access controls with multi-factor authentication
4. Audit logging is retained for at least six years
5. Encrypted onsite backups, with a tested recovery path
6. Documented incident-response and breach-notification procedures
7. Regular vulnerability scanning (bi-weekly on Atlantic.Net Fortress tiers)
8. Intrusion detection and prevention (IDS/IPS)
9. 24/7 security monitoring
10. Current attestations: SOC 2 Type II, SOC 3 Type II, HIPAA, HITECH

## Common HIPAA Hosting Mistakes Startups Make

Most HIPAA compliance failures in startups do not trace back to sophisticated attacks. They trace back to early build decisions that were never revisited.

**Delaying compliance planning until after launch.** A founding team often decides to “add HIPAA later” once the product is validated. But HIPAA obligations attach the moment ePHI enters the environment, not when the team decides to comply. Retro-fitting compliance onto a running application is far more expensive and disruptive than building on a compliant foundation, and choices made in the first sprint can create gaps that take months and outside consultants to close.

**Deploying without a signed BAA.** Using a hosting provider without a signed HIPAA BAA is a HIPAA violation regardless of how the infrastructure is configured. The BAA is a legal requirement under HIPAA’s Privacy and Security Rules, not a formality. Some general-purpose cloud providers sign a BAA upon request but require the customer to find, negotiate, and manage it separately. A managed HIPAA provider includes it in the plan.

**Weak access controls.** Shared administrative credentials, no MFA on server access, and no formal process for revoking access when someone leaves are among the most common findings in HIPAA breach investigations. RBAC limits the blast radius of a compromised account; MFA limits the impact of credential theft. Configure both before a single byte of ePHI touches the environment.

**Thin documentation.** HIPAA audits are documentation reviews as much as technical assessments. A team with secure infrastructure but no documented policies, access-control decisions, or risk-assessment methodology will struggle during an audit. Managed providers supply infrastructure-level documentation; the customer produces the application-level and organizational policies.

**Skipping regular risk assessments**. The HIPAA Security Rule requires covered entities and business associates to conduct an accurate, thorough assessment of the risks to the confidentiality, integrity, and availability of ePHI. This is not a one-time activity. A startup that ran a risk assessment at launch and never repeated it after the application changed, the team grew, or new integrations were added is sitting in a compliance gap. Annual assessments, at a minimum, keep it current.

## Frequently Asked Questions

**What is fully managed HIPAA-compliant hosting?**

Fully managed HIPAA-compliant hosting means the provider handles OS patching, firewall configuration, intrusion detection, vulnerability scanning, encrypted backups, and 24/7 monitoring, while including a signed BAA as part of the plan. The customer inherits a compliant infrastructure foundation without building it from scratch.

**Is a BAA required even if a provider claims to be HIPAA-compliant?**

Yes, a signed BAA is a legal requirement before any ePHI is placed on a provider’s infrastructure. A provider that markets itself as HIPAA-compliant but has not signed a BAA with your organization does not satisfy the requirement; using it for ePHI workloads constitutes a HIPAA violation.

**What does the customer still own under the shared-responsibility model?**

The customer remains responsible for application security, user access policies, workforce training, documented risk assessments, and breach notification procedures. A managed provider covers the infrastructure layer, but nothing above it.

**Does HIPAA certify or approve hosting providers?**

No, HIPAA does not certify or officially approve any hosting provider. Compliance depends on how the environment is configured, whether a BAA is signed, and whether the required technical safeguards are in place and documented.

**What technical safeguards should a managed HIPAA hosting environment include?**

A credible managed HIPAA environment should include a managed firewall with IPS, intrusion detection and prevention, bi-weekly vulnerability scanning, AES-256-encrypted storage and backups, MFA and role-based access controls, audit logging retained for at least 6 years, and 24/7 SOC monitoring.

**Why do startups and clinics choose managed HIPAA hosting over building their own stack?**

Building a compliant stack from scratch requires weeks of firewall, backup, scanning, and audit work, which delays the product and demands ongoing ops headcount that most lean teams lack. Managed hosting consolidates those controls into a predictable monthly fee with the compliant foundation ready on day one.

**What is the difference between HIPAA-compliant hosting and a HIPAA-compliant application?**

HIPAA-compliant hosting covers infrastructure-level safeguards such as encrypted storage, firewall management, and audit logging. A HIPAA-compliant application handles ePHI correctly at the code level, including authentication, encrypted API calls, and proper access controls. Both are required, and the provider’s BAA does not cover application-layer decisions.

**How quickly can a team launch on managed HIPAA hosting?**

Infrastructure provisioning is fast, but the practical timeline depends on the application build and the compliance work the team still owns, such as risk assessments and access policy documentation. Managed HIPAA hosting removes infrastructure configuration from the critical path, enabling a production-ready environment within the first sprint cycle.

## Key Terms

**Business Associate Agreement (BAA)**: The contract HIPAA requires between a covered entity and any vendor that stores, processes, or transmits ePHI on its behalf, setting out each party’s safeguards.

**Electronic Protected Health Information (ePHI):** Individually identifiable health information created, stored, transmitted, or received electronically, including patient records, billing, and clinical data.

**Technical Safeguards**: The HIPAA Security Rule requires technical controls, including access controls, audit controls, integrity controls, and transmission security.

**Shared Responsibility Model:** The split between the provider’s infrastructure-level controls and the customer’s application security, access policies, and compliance program.

## Inheriting a Compliant Foundation From Day One

Atlantic.Net runs its[HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) as a fully managed environment. Its engineers run the FortiGate firewall with IPS, intrusion detection, biweekly vulnerability scans, MFA, encrypted onsite and off-site audit logging, and 24/7 US-based monitoring, with the BAA included as standard and SOC 2 Type II, SOC 3 Type II, HIPAA, and HITECH attestations in place. A startup or clinic deploying there inherits that compliant foundation on day one and focuses on the application, access policies, and staff training that only it can own.

If you are launching a telehealth product or moving a clinic’s systems to the cloud and want technical safeguards handled, Atlantic.Net can scope a managed HIPAA environment tailored to your application and growth plans.[Contact the Atlantic.Net team](https://www.atlantic.net/about-us/corporate-contact/) to start.


---

# PCI-Compliant Cloud Hosting for Payment Processing Applications

> URL: https://www.atlantic.net/pci-compliant-hosting/pci-compliant-cloud-hosting-payment-applications/ | Published: 2026-06-25 | Author: Richard Bailey

PCI-compliant cloud hosting provides infrastructure that has been independently assessed against the PCI DSS requirements, with the provider responsible for the assessment. Depending on the service, those controls may include physical security, network protection, encryption, vulnerability management, access controls, logging, and system maintenance.

Any application that stores, processes, or transmits cardholder data must account for the systems supporting those activities. The PCI scope may also extend to connected components that can affect the security of the cardholder data environment, including servers, databases, administrative access systems, logging platforms, and deployment pipelines.

The size of that environment directly affects the amount of compliance work required. A broader scope means more systems to secure, document, monitor, test, and include in the organization’s PCI validation process. Strong network segmentation, controlled data flows, and the use of independently assessed infrastructure can reduce that burden by limiting the systems exposed to cardholder data and assigning defined infrastructure controls to the hosting provider.

PCI-compliant hosting, therefore, provides a stronger starting point for payment applications, but it does not make the application compliant by default. The customer remains responsible for application security, access management, secure development, cardholder data handling, configuration, and every other control outside the provider’s documented scope.

The right hosting provider should be independently assessed, support effective segmentation, protect the underlying infrastructure, and clearly document which PCI controls it manages and which remain with the customer.

## Key Takeaways

- Scope is the lever. The more of the cardholder data environment you push onto audited infrastructure, the smaller and cheaper the audit will be.
- Only infrastructure controls are inherited. Application security, access policies, and data-flow design stay the customer’s job.
- Tokenization, a hosted payment page, and network segmentation are the highest-impact scope-reduction moves.
- The right host shows independent SOC 2 Type II and SOC 3 Type II audit evidence and documents the shared-responsibility line in writing.

## What PCI-Compliant Hosting Means for a Payment Application

PCI DSS, the Payment Card Industry Data Security Standard, governs how cardholder data is stored, processed, and transmitted. Launched on September 7, 2006, it was created jointly by American Express, Discover, JCB International, Mastercard, and Visa to replace five separate card-brand programs with a single unified set of requirements. Version 4.0 became mandatory in March 2025, replacing version 3.2.1.

The standard organizes its requirements around the cardholder data environment (CDE): the combination of people, processes, and technologies that store, process, or transmit cardholder data, plus any system components that connect to or could affect the security of that data. Every system inside the CDE boundary must comply with all applicable PCI DSS requirements; every system cleanly outside it does not. That boundary drives compliance cost and audit effort.

PCI DSS 4.0 contains 12 core requirements and over 300 individual security controls covering network security, encryption, access control, logging, and regular security testing. For a payment application, hosting is the layer where a large portion of those controls live, from the physical data center and network perimeter to firewall, storage encryption, and transmission security. A PCI-compliant host provides them in an audited, pre-validated state.

In practice, “PCI-compliant hosting” means the provider has built, operates, and maintains the infrastructure-layer controls required by PCI DSS, with audited evidence. No hosting plan makes the application PCI-compliant on its own. The framework is explicit: a merchant or service provider is responsible for the security of the systems and applications it operates, regardless of where those systems are hosted.

## What the Host Covers, and What Your App Still Owns

Understanding PCI-compliant hosting comes down to drawing the shared-responsibility line precisely, where teams most commonly miscalculate their scope.

A PCI-compliant hosting provider covers the infrastructure layer: physical access controls at the data center (biometric entry, CCTV, restricted cages), network firewalls and segmentation that separate customer environments from each other and from the public internet, managed VPNs for encrypted remote access, the hardware and hypervisor underlying each server, encryption at rest, encrypted backups, and regular vulnerability scanning.[Atlantic.Net’s PCI-compliant hosting](https://www.atlantic.net/pci-compliant-hosting/) includes a managed FortiGate firewall with IPS, managed IDS/IPS, disk encryption standard on all cloud hosts and virtual machines, a managed encrypted VPN with five accounts, bi-weekly vulnerability scans, on-site and off-site daily encrypted backups, and a compliance posture verified by an independent third-party auditor.

The customer owns everything above that layer, starting with application security. That means the code itself: input validation, handling of authentication tokens, and whether it introduces SQL injection or cross-site scripting vulnerabilities. It means access control policies: who can access which data, how privileges are granted and revoked, and whether multi-factor authentication is enforced at the application level. It means data flow design: whether the application stores raw primary account numbers it does not need, and how it routes and encrypts cardholder data between its own components. And it means the content of the application’s own logs and the monitoring built on them.

A hosting provider can give you an audited network perimeter and encrypted storage; it cannot audit your code for injection flaws or enforce your internal access policies. The host’s audit covers the infrastructure, while the application’s audit is a separate exercise. The Qualified Security Assessor (QSA) reviewing your compliance assesses both.

This split is not unique to Atlantic.Net; it reflects the structure of PCI DSS itself. Cloud providers certify their infrastructure for PCI compliance, and that certification stops at the boundary of what they operate, not your application.

### What the Host Covers vs. What Your App Owns

| Host responsibilities (infrastructure) | Customer responsibilities (application) |
| --- | --- |
| **Physical data center security**, including biometric entry, CCTV, and restricted cages | Application code security, including input validation and authentication handling |
| **Network firewalls and segmentation** between environments | Application-level access policies and MFA |
| **Managed VPN** for encrypted remote access | Data-flow design and cardholder data routing |
| **Hardware and hypervisor security** | Prevention of SQL injection, XSS, and other application vulnerabilities |
| **Disk encryption at rest and encrypted backups** | Decisions about what cardholder data to store |
| **Infrastructure vulnerability scanning and IDS/IPS** | Application vulnerability scanning and penetration testing |

## The PCI DSS Requirements and Levels, at a Glance

PCI DSS 4.0’s 12 requirements group around six core objectives, mapping where infrastructure controls appear and where application controls take over:

- **Network and system security** (requirements 1-2): installing and maintaining network security controls, and applying secure configurations to all system components. Heavily infrastructure-oriented, covering firewall rules, default password policies, and hardened server configurations.
- **Protecting cardholder data** (3-4): storing account data securely with strong encryption for any data that must be retained, and protecting cardholder data with strong cryptography in transmission over open networks. Transmission security, such as TLS, is shared: the infrastructure provides the channel, and the application must use it correctly.
- **A vulnerability management program** (5-6): protecting all systems and networks from malicious software, and developing and maintaining secure systems and software. The host can scan the infrastructure layer; application vulnerability scanning is the customer’s task.
- **Access control** (7-9): restricting access to system components and cardholder data to those whose job requires it, identifying and authenticating users, and restricting physical access to cardholder data. The host handles physical access to the data center; logical access controls are the customer’s responsibility.
- **Monitoring and testing** (10-11): logging and monitoring all access to system components and cardholder data, and testing systems and networks regularly, including quarterly external vulnerability scanning by an Approved Scanning Vendor (ASV) and penetration testing at least annually.
- **Information security policies** (12): supporting information security with organizational policies and programs.

The four merchant levels determine how merchants validate compliance. Level 1 applies to merchants processing more than six million card transactions per year and requires an annual assessment by a QSA producing a Report on Compliance (ROC). Level 2 covers one to six million transactions per year; Level 3, 20,000 to one million e-commerce transactions; Level 4, fewer than 20,000 e-commerce transactions or up to one million through any channel. Levels 2 through 4 are typically validated through a Self-Assessment Questionnaire (SAQ), with the variant depending on how the merchant handles cardholder data.

PCI DSS requires annual validation, but compliance is not a point-in-time achievement: merchants must maintain it year-round, and quarterly ASV scans of external-facing systems are a standing requirement.

### PCI DSS Merchant Levels and Validation

| **Level** | **Annual card transactions** | **Validation** |
| --- | --- | --- |
| **Level 1** | More than 6 million on-site | ITE assessment by a QSA, resulting in a Report on Compliance (ROC) |
| **Level 2** | 1 million to 6 million | Self-Assessment Questionnaire (SAQ) |
| **Level 3** | 20,000 to 1 million e-commerce transactions | Self-Assessment Questionnaire (SAQ) |
| **Level 4** | Fewer than 20,000 e-commerce transactions, or up to 1 million transactions across any channel | Self-Assessment Questionnaire (SAQ) |

Validation is annual, but compliance is continuous: quarterly ASV scans of external-facing systems run year-round.

## How the Right Host Shrinks Your PCI Scope

The PCI scope for a payment application is the set of systems that must be assessed and validated. A larger scope means more controls to implement, more evidence to gather, a longer audit, and more exposure. Reducing scope is the fastest lever for cutting cost and risk, and the hosting environment is where most of that work happens.

**Network segmentation** is the foundational lever. When the systems that process cardholder data are isolated on a separate network segment, with firewall rules restricting traffic to only what the payment flow requires, adjacent segments fall outside the CDE. A flat network instead puts every server, developer workstation, and internal tool that can reach the payment systems in scope.

**Tokenization** removes raw card numbers from the application entirely. The payment terminal or checkout page sends the primary account number to a tokenization service; the application then receives a token, a surrogate value that has no meaning outside that system. From there, it stores and processes only tokens, and token-only systems are out of PCI scope. Combined with a certified hosted payment gateway that handles card capture and processing, a SaaS billing platform can reduce its CDE to a thin slice: the systems that generate the checkout session and receive the token, instead of the entire application stack.

**Not storing cardholder data unless necessary** is the simplest scope-reduction step. PCI DSS prohibits storing sensitive authentication data after authorization under any circumstances, and the retention of stored account data, such as the primary account number, must be justified, minimized, and encrypted. If the application does not need to store card numbers, it should not: data that does not exist cannot be breached.

**Synthetic test data in development environments** keeps development and test systems out of scope. Real cardholder data in dev, staging, or QA expands the CDE to those environments, and everyone with access to them; synthetic card numbers that pass the Luhn algorithm check but correspond to no real account prevent that expansion.

**A mirrored staging environment** that replicates the production infrastructure without real cardholder data allows the team to test updates, patches, and configuration changes before they reach production. This is the model auditors look for: changes land on tested, known-configuration systems, not directly on the production CDE.

To make this concrete, consider a SaaS billing platform that uses a certified hosted payment page and tokenizes all card transactions through the gateway. The checkout form is served from the gateway’s domain, not the application’s; the application receives only a token and a transaction status, and stores subscription records and billing history, none of which contains cardholder data. In a segmented hosting environment with clean firewall rules separating the billing application from other internal systems, that team’s CDE may consist of the API layer that communicates with the gateway, plus the servers that carry that traffic. The team completes an SAQ A or SAQ A-EP instead of a full ROC, with the audit scope covering a handful of systems rather than the entire platform. The hosting environment that makes this possible provides segmentation as a standard control, not an add-on to architect from scratch.

### Common Misconceptions

| Misconception | Reality |
| --- | --- |
| **Hosting on a PCI-compliant infrastructure makes my application compliant.** | The provider’s audit covers ionly ts infrastructure controls  Your application code, access policies, and cardholder data handling require separate validation. |
| **PCI DSS applies only to large enterprises.** | PCI DSS applies to any entity that stores, processes, or transmits cardholder data. Transaction volume determines the validation level, not whether the standard applies. |
| **Passing the annual assessment means I am compliant for the entire year.** | Compliance is continuous. Organizations must maintain controls throughout the year and complete any required quarterly vulnerability scans. The annual assessment validates compliance at a specific point in time. |

## What to Look For in a PCI-Compliant Hosting Provider

The checklist for evaluating a PCI-compliant hosting provider maps onto the controls PCI DSS requires at the infrastructure layer, plus two easy-to-overlook items: independent audit evidence and explicit shared-responsibility documentation.

**Independent audit evidence.** Marketing copy that says “PCI-compliant” is not the same as a provider that has undergone an independent third-party audit; the audit report is what matters. Atlantic.Net holds SOC 2 Type II and SOC 3 Type II attestations, audited under SSAE 18 by an independent third-party CPA firm. The SOC 3 report is publicly available; the SOC 2 report is available under NDA. Both give your QSA audited evidence of the controls in place. Validated certifications a provider can show, including SOC 2, SOC 3, and HIPAA audit documentation, signal that the posture has been independently tested rather than self-asserted.

**Managed firewall with IDS/IPS.** A managed FortiGate firewall with intrusion prevention covers the network perimeter and enforces the segmentation rules that shrink your CDE. The managed component matters because the firewall must be actively maintained, with rules updated, alerts reviewed, and changes documented; a firewall that is not actively managed does not satisfy the requirement. Atlantic.Net includes managed IDS/IPS alongside the firewall, so traffic monitoring runs around the clock between scheduled scans.

**WAF coverage**. A Web Application Firewall that covers application-layer attacks such as SQL injection and cross-site scripting addresses PCI DSS Requirement 6.[Atlantic.Net’s Network Edge Protection](https://www.atlantic.net/managed-services/network-edge-protection/) deploys ModSecurity with the OWASP Top 10 core rule set upstream of the hosting environment at fixed pricing, with CDN and DDoS mitigation bundled. Transparent deployment requires no code or hardware changes to an existing environment.

**Encryption at rest and in transit**. Disk encryption across all cloud hosts and virtual machines meets the at-rest requirement. A managed, encrypted VPN with five accounts provides encrypted remote access, which PCI DSS applies to any remote administrative access to the CDE. Look for providers that treat these as standard inclusions, rather than premium add-ons.

**Quarterly vulnerability scanning.** PCI DSS requires quarterly ASV scans of all external-facing IP addresses and domains in the CDE. Atlantic.Net runs bi-weekly vulnerability scans using the Trend Micro Security Suite on the hosting infrastructure, exceeding the quarterly minimu**m. On-site and off-site**** encrypted backups.** Automated, offsite, fully encrypted backups address both the PCI DSS data protection requirements and disaster recovery obligations. Atlantic.Net includes daily encrypted backups with onsite and offsite copies as standard, so a physical incident at the primary data center does not leave unencrypted data accessible outside a controlled environment.

**Explicit shared-responsibility documentation.** A provider that states in writing which controls it owns and which the customer owns is one whose compliance posture you can rely on during an audit. Look for this documentation before you sign, not after your QSA asks for it.

[Atlantic.Net’s managed services](https://www.atlantic.net/managed-services/) include 24/7/365 US-based monitoring and support across all PCI hosting environments, operating across eight global data center regions with a 100% uptime SLA covering network, hardware, and power independently.

## PCI-Compliant Hosting Provider Checklist

- Independent third-party audit evidence (SOC 2 Type II, SOC 3 Type II)
- Managed firewall with IDS/IPS
- Web Application Firewall (Atlantic.Net uses ModSecurity with the OWASP Top 10 rule set)
- Disk encryption standard on all servers and VMs
- Managed encrypted VPN for remote access
- Vulnerability scanning that meets or beats the quarterly ASV requirement
- Automated encrypted backup on-site and off-site
- Network segmentation is supported as a standard control
- Written shared-responsibility documentation
- 24/7 monitoring and a defined uptime SLA

## Frequently Asked Questions

**Does PCI compliance apply to my payment application?**

Yes, if your application stores, processes, or transmits cardholder data, PCI DSS applies. Transaction volume determines your validation level, not whether compliance is required.

**Does choosing a PCI-compliant host make my application PCI-compliant?**

No. A PCI-compliant host provides audited infrastructure controls, but the security of your application code, access policies, and data flow design remains your responsibility. Your QSA assesses both layers separately.

**What is the cardholder data environment (CDE)?**

The CDE is the set of people, processes, and technologies that store, process, or transmit cardholder data, plus any systems that connect to it or could affect its security. All systems inside the CDE boundary must comply with applicable PCI DSS requirements.

**How do I reduce my PCI scope?**

The primary levers are tokenization, a certified hosted payment gateway, network segmentation, avoiding unnecessary storage of cardholder data, and using synthetic test data in development environments. Each approach removes systems from the CDE or prevents new ones from entering it.

**How often must I validate PCI compliance?**

PCI DSS requires annual validation, either a QSA-produced Report on Compliance for Level 1 merchants or a Self-Assessment Questionnaire for Levels 2 through 4. Quarterly external and internal vulnerability scans are also required.

**What infrastructure controls does a PCI-compliant host provide?**

A PCI-compliant host covers physical data center security, network firewalls and segmentation, disk encryption, managed VPN, and vulnerability scanning. These satisfy the infrastructure-layer requirements of PCI DSS but do not extend to application-level security.

**What is point-to-point encryption, and does my host provide it?**

Point-to-point encryption (P2PE) encrypts cardholder data from the capture point through to the payment processor, keeping it out of cleartext within your systems. P2PE is a solution-level control provided by the payment gateway or terminal vendor, not the hosting provider.

**Why does independent audit evidence matter when choosing a host?**

Marketing copy claiming PCI compliance is not the same as a provider that has completed an independent third-party audit. Audit documentation, such as SOC 2 Type II or SOC 3 Type II reports, gives your QSA verified evidence of the controls in place.

## Building Your Payment App on an Audited Ground

Atlantic.Net provides[PCI-compliant hosting](https://www.atlantic.net/pci-compliant-hosting/) as an audited, segmented foundation for payment applications: a managed FortiGate firewall with IDS/IPS, ModSecurity-based Network Edge Protection for application-layer attacks, disk encryption as standard, a managed encrypted VPN, bi-weekly vulnerability scans, and encrypted onsite and offsite backups, all assessed under SOC 2 Type II and SOC 3 Type II by an independent CPA firm. That foundation carries the infrastructure controls and segmentation that shrink a payment app’s cardholder data environment, leaving the team to secure the one thing only it can: its own application.

If you are building or scaling a payment application and want to reduce your PCI scope on audited infrastructure, Atlantic.Net can map your cardholder data flows to the right hosting architecture and a clear shared-responsibility boundary.[Contact the Atlantic.Net team](https://www.atlantic.net/about-us/corporate-contact/) to scope PCI-compliant hosting for your app.


---

# Our Contributors

> URL: https://www.atlantic.net/authors/ | Updated: 2026-09-16

The engineers, writers and subject-matter experts behind our tutorials, guides and how-tos.

## [Hitesh Jethva](https://www.atlantic.net/author/hitesh-jethva/)

927 articles

Hitesh Jethva is a regular contributor to the Atlantic.Net blog. With over 15 years of experience in Linux and open-source technologies, he founded Linux Buz, a…

[Website](https://linuxbuz.com)[LinkedIn](https://www.linkedin.com/in/hitesh-jethva/)

## [Alexander Wise](https://www.atlantic.net/author/alexander-wise/)

421 articles

Alexander Wise is Content Editor for Atlantic.Net. He has over 15 years of experience in editing, copywriting, and managing content.

[LinkedIn](https://www.linkedin.com/in/alexandermwise/)

## [Richard Bailey](https://www.atlantic.net/author/richard-bailey/)

254 articles

Richard Bailey brings over two decades of IT expertise, from traditional data centers to cutting-edge cloud solutions. As the founder of turbogeek.co.uk and a seasoned writer,…

[LinkedIn](https://www.linkedin.com/in/richbailey/)

## [Kent Roberts](https://www.atlantic.net/author/kroberts/)

69 articles

## [Dr. Assad Abbas](https://www.atlantic.net/author/assad-abbas/)

68 articles

Dr. Assad Abbas, holds a Ph.D. from North Dakota State University, USA and is a Tenured Associate Professor at COMSATS University. His research focuses on advanced…

[LinkedIn](https://www.linkedin.com/in/assad-abbas-9984b264/)

## [Gilad Maayan](https://www.atlantic.net/author/gilad/)

58 articles

Gilad David Maayan is a technology writer who has worked with over 150 technology companies including SAP, Imperva, Samsung NEXT, NetApp and Check Point, producing technical…

[Website](https://agileseo.co.il/)[X (Twitter)](https://twitter.com/gilad_maayan)[LinkedIn](https://www.linkedin.com/in/giladdavidmaayan/)

## [Sam Guiliano](https://www.atlantic.net/author/sguiliano/)

53 articles

## [Robert Agar](https://www.atlantic.net/author/ragar/)

44 articles

Robert is a regular contributor and blogger for Atlantic.Net living in Northeastern Pennsylvania who specializes in various information technology topics. He brings over 30 years of…

[LinkedIn](http://www.linkedin.com/in/ragar88)

## [Atlantic.Net NOC](https://www.atlantic.net/author/anetnoc/)

41 articles

## [Dr. Rachael Bailey](https://www.atlantic.net/author/rachael-bailey/)

40 articles

Dr. Rachael Bailey, Ph.D. brings a strong research background in cell biology and cancer sciences alongside extensive medical writing expertise. She has established a successful career…

[LinkedIn](https://www.linkedin.com/in/drrachaelbailey/)

## [Jose Velazquez](https://www.atlantic.net/author/jvelazquez/)

38 articles

## [Dr. Tehseen Zia](https://www.atlantic.net/author/tehseen-zia/)

34 articles

Dr. Tehseen Zia is a tenured Associate Professor of Computer Science at COMSATS University and a seasoned AI researcher and consultant with over 15 years of…

## [Jason Mazzota](https://www.atlantic.net/author/jmazzota/)

16 articles

## [Brandon Schroth](https://www.atlantic.net/author/brandon-schroth/)

11 articles

## [Editorial Team](https://www.atlantic.net/author/editorial-team/)

11 articles

## [Josh Simon](https://www.atlantic.net/author/jsimon/)

9 articles

## [Glenn](https://www.atlantic.net/author/griverside/)

7 articles

## [Michael Douse](https://www.atlantic.net/author/mdouse/)

7 articles

## [Ariel Beltre](https://www.atlantic.net/author/abeltre/)

6 articles

## [Andrew Mora](https://www.atlantic.net/author/amora/)

6 articles

## [Chelsea Fieler](https://www.atlantic.net/author/cfieler/)

5 articles

## [Mason Moody](https://www.atlantic.net/author/mmoody/)

5 articles

## [Eddie](https://www.atlantic.net/author/eauthorini/)

4 articles

## [Joel](https://www.atlantic.net/author/jgoldstein/)

3 articles

## [Marty](https://www.atlantic.net/author/mpuranik/)

2 articles

## [Arnaldo Arrieta](https://www.atlantic.net/author/aarriete/)

1 articles

## [Angel Leon-Glass](https://www.atlantic.net/author/aleon/)

1 articles

## [Ernest Coleman](https://www.atlantic.net/author/ecoleman/)

1 articles

## [Jennifer Rey](https://www.atlantic.net/author/jrey/)

1 articles

## [Kristopher Fieler](https://www.atlantic.net/author/kfieler/)

1 articles


---

# Write for Atlantic.Net

> URL: https://www.atlantic.net/write-for-us/ | Updated: 2026-09-16

Share your expertise with our audience of developers, sysadmins and IT leaders. Tell us about yourself and include a content sample.


---

# Shared vCPU vs Dedicated vCPU: How to Choose Between Shared vCPUs and Dedicated vCPUs

> URL: https://www.atlantic.net/dedicated-server-hosting/shared-vs-dedicated-vcpu/ | Published: 2026-06-29 | Updated: 2026-06-26 | Author: Dr. Assad Abbas

Cloud instances are often compared by price and[vCPU](https://www.techtarget.com/whatis/definition/virtual-CPU-vCPU) count, but these numbers do not always reflect the actual CPU performance a workload will receive. A shared vCPU setup may appear cost-effective because several virtual machines use the same physical CPU resources. In contrast, a dedicated vCPU setup usually costs more, but it provides more reliable access to CPU capacity.

The difference between shared CPU access and reserved CPU capacity matters in 2026 because CPU allocation affects both performance and cost. The right choice depends on workload behavior, latency requirements, cost tolerance, and performance risk. Web applications, APIs, databases, and background jobs may perform well on shared vCPU plans when CPU demand is light or bursty. Workloads with sustained CPU usage or strict response time requirements may require dedicated vCPUs to ensure more predictable performance.

Therefore, developers, Site Reliability Engineers (SREs), cloud architects, and procurement teams must evaluate CPU usage patterns, latency needs, performance risk, and business impact before choosing between shared and dedicated vCPU instances. This article explains the main differences between shared and dedicated vCPU instances and outlines the workload, performance, and cost factors that should guide the final choice.

## vCPU Allocation and CPU Oversubscription in Cloud Environments

A vCPU is a virtual processor assigned to a virtual machine by the[hypervisor](https://www.atlantic.net/dedicated-server-hosting/bare-metal-hypervisors-vs-hosted-solutions/). It is not always equal to a full physical CPU core. In many cloud environments, one vCPU maps to one logical CPU thread. This logical thread may be part of a physical CPU core through simultaneous multithreading.

The hypervisor manages the relationship between virtual CPUs and physical CPU resources. It schedules vCPUs onto available host CPU capacity through time-slicing, run queues, and scheduling rules. When enough CPU capacity is available, a virtual machine can receive CPU time without noticeable delay. When several virtual machines require CPU resources simultaneously, some workloads may wait before execution.

In shared cloud environments, CPU scheduling becomes more important because multiple tenants may run workloads on the same physical host. To use hardware capacity more efficiently, cloud providers may oversubscribe CPU resources. CPU oversubscription means assigning more virtual CPU capacity than the physical host can provide simultaneously. Providers use this model because many workloads are idle, intermittent, or bursty rather than CPU-intensive at all times.

Oversubscription helps reduce infrastructure cost, but it can also create CPU contention. For example, one workload on a shared host may suddenly consume heavy CPU resources. Other virtual machines on the same host may then receive less CPU time. This condition is commonly called the noisy-neighbor effect. It can increase latency, reduce throughput, and make CPU performance less predictable.

Therefore, the price difference between shared and dedicated vCPUs is closely tied to CPU allocation. Shared vCPU instances cost less because CPU resources are distributed across multiple workloads. In contrast, dedicated vCPU instances cost more because CPU capacity is reserved, isolated, or more strictly controlled.

## When Shared vCPU Plans are a Practical Choice

Shared vCPU plans are appropriate when a workload does not require continuous CPU access. They are usually selected for applications with light or bursty CPU demand, where cost control is more important than strict performance consistency.

Development and testing environments often work well under this model because their CPU use is irregular. Low-traffic websites, small internal tools, dashboards, and admin panels may also perform well when performance requirements are moderate. Similarly, small databases can use shared vCPU plans when query volume is low and predictable. Flexible batch jobs may also run on shared vCPUs if completion time is not strict.

Shared vCPU plans become less suitable when a workload requires sustained processing capacity over an extended period. High-traffic APIs, busy databases, CI/CD runners, analytics jobs, video encoding, compression, and encryption-heavy services, real-time processing, and scientific computing may suffer when CPU resources are shared with other active workloads.

A practical sign that shared vCPUs may no longer be suitable is sustained CPU usage at 80 —90 percent for extended periods. Rising p95 or p99 latency, CPU steal time, CPU ready time, and long run queues may also indicate CPU contention. Therefore, teams should consider dedicated vCPU plans when contention affects service level objectives, user experience, or job completion time.

## When Dedicated vCPU Instances are the Better Choice

When shared CPU access begins to affect performance, dedicated vCPU instances become a stronger option. These instances provide CPU capacity that is reserved, isolated, or controlled more strictly than shared vCPU plans. Therefore, they are useful for workloads that need stable CPU access over longer periods.

Dedicated vCPU instances are often appropriate for production APIs, busy databases, analytics services, high-traffic web platforms, CI/CD runners, and business-critical applications. These workloads usually depend on sustained CPU usage, predictable throughput, and stable latency. If they run on shared CPU resources, performance may become less consistent during periods of host contention.

The way dedicated CPU capacity is assigned can vary by provider and instance type. Some platforms reserve logical CPU threads, while others provide stronger physical core isolation. In some environments, CPU pinning may bind vCPUs to specific host CPU resources for better consistency. Similarly, larger workloads may need proper NUMA placement to reduce memory access delays.

Choosing dedicated vCPUs should still be based on profiling rather than core count alone. More cores improve performance only when the application can use parallel processing effectively. Therefore, teams should review CPU usage, thread behavior, request latency, queue depth, and database waits before selecting a larger instance.

## Dedicated vCPU Instances Compared with Dedicated Servers

Dedicated vCPU instances and[dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) both provide stronger isolation than shared vCPU plans, but they operate at different infrastructure levels. A dedicated vCPU instance still runs in a virtualized cloud environment. It provides more predictable CPU access for the workload while retaining cloud features such as faster provisioning, snapshots, managed networking, and easier scaling.

A dedicated server provides full hardware isolation because the customer uses the physical server rather than an isolated CPU allocation inside a virtualized environment. This model is more suitable when a workload needs direct hardware access, maximum throughput, strict single-tenant separation, custom virtualization, or more predictable storage and network behavior.

In practice, dedicated vCPU instances are often sufficient for production APIs, managed databases, analytics services, and high-traffic Web platforms because these workloads usually need predictable CPU access without full hardware control. Some workloads require a higher level of isolation than a virtualized dedicated CPU can provide. Large databases, virtualization hosts, high-performance computing, AI workloads, licensing-sensitive systems, and workloads requiring direct hardware control may therefore require dedicated servers. Dedicated servers may also be preferable for regulated workloads that require stronger isolation, audit logging, access controls, and data encrypted in transit using TLS.

## CPU Performance and Cost Comparison

CPU performance should not be evaluated by vCPU count alone, as the same number of vCPUs can yield different results across providers, instance families, processor generations, and allocation models. A useful comparison should therefore examine both the cost of the instance and the consistency of its CPU performance.

Table 1: Comparison of shared vCPU, dedicated vCPU, and bare metal

| **Allocation type** | **CPU isolation** | **Cost profile** | **Performance variance** | **Best fit** | **Testing focus** |
| --- | --- | --- | --- | --- | --- |
| **Shared vCPU** | Low to moderate | Lowest | Highest under contention | Bursty, low-budget, non-critical workloads | CPU steal time, p99 latency, burst tests |
| **Dedicated vCPU** | Moderate to high | Higher | Lower variance | CPU-intensive and latency-sensitive workloads | Single-thread and multi-thread tests |
| **Bare metal dedicated server** | Highest | Higher fixed cost | Lowest variance | Maximum throughput and strict isolation | Sustained throughput, p99 latency, and hardware behavior |

The table indicates that lower cost is generally associated with higher performance variability. Shared vCPU plans usually have the lowest initial cost, but their CPU performance may change when other workloads on the same host become active. Therefore, this option is more appropriate when the workload can tolerate some variation in response time, throughput, or job completion time.

When performance variability affects service-level objectives or user experience, dedicated vCPU instances and bare-metal servers offer a more predictable alternative. These options usually require a higher budget, but they reduce the risk of CPU contention and provide more consistent access to CPU resources. Therefore, the final decision should consider both the monthly price and the level of performance risk the workload can tolerate.

## Choosing the Right CPU Allocation by Workload

CPU allocation should be selected according to workload behavior, performance sensitivity, and cost tolerance. Table 2 summarizes the general placement of common workloads across shared vCPU, dedicated vCPU, and dedicated server options.

Table 2: Recommended CPU allocation by workload type

| **Workload type** | **Recommended allocation** |
| --- | --- |
| Development and testing | Shared vCPU |
| Low-traffic websites | Shared vCPU |
| Internal dashboards | Shared vCPU |
| Flexible batch jobs | Shared vCPU or dedicated vCPU after testing |
| Production APIs | Dedicated vCPU when latency matters |
| Busy databases | Dedicated vCPU or dedicated server |
| CI/CD runners | Dedicated vCPU for sustained builds |
| Analytics and encoding | Dedicated vCPU or bare metal |
| Real-time systems | Dedicated vCPU or bare metal |
| Strict isolation workloads | Dedicated server |

This mapping should be treated as a starting point rather than a fixed rule because workload behavior can vary across applications, users, and deployment environments. Each workload should still be tested under realistic traffic, peak CPU demand, and expected concurrency. In addition, procurement teams should review licensing terms, performance guarantees, and isolation requirements before selecting a larger or more isolated option.

The final choice should be the lowest cost allocation tier that meets CPU, latency, throughput, and reliability targets under realistic operating conditions.

## Atlantic.Net Options for vCPU and Dedicated CPU Workloads

Atlantic.Net offers cloud VM hosting for workloads that need virtual compute resources, as well as Dedicated Hosts for customers who require an entire physical hypervisor node for their own virtual machines. This distinction is relevant to the shared vCPU versus dedicated vCPU decision because light, flexible, or bursty workloads may use cloud VM resources. In contrast, workloads with predictable performance or stricter isolation needs may require a dedicated host environment.

For workloads that require full hardware access, Atlantic.Net also offers bare-metal and dedicated-server options. These servers provide direct access to physical server resources and are better suited to workloads that require greater performance consistency, customization, and isolation. Therefore, teams should compare the Atlantic.Net cloud VM, Dedicated Host, and bare metal options based on vCPU requirements, CPU predictability, workload criticality, isolation needs, and total cost of ownership.

## Conclusion

Choosing between shared vCPU and dedicated vCPU is mainly a balance between cost control and predictable CPU performance. Shared vCPU plans can reduce infrastructure spending when workloads are light, bursty, and not highly sensitive to latency. Applications with sustained CPU usage, steady throughput needs, or strict response time targets may require dedicated vCPU or dedicated server infrastructure.

Measured workload behavior rather than assumptions should guide the final decision. Therefore, teams should review CPU use during normal and peak periods, run practical load tests, and compare performance results with the cost of each instance type. This process helps determine whether shared vCPU capacity is sufficient or whether dedicated CPU access is justified. The most suitable option is the one that provides the required CPU performance at an acceptable cost.


---

# Secure Web Hosting: Services, Providers, and Best Practices

> URL: https://www.atlantic.net/managed-services/secure-web-hosting-services-providers-best-practices/ | Published: 2026-06-29 | Updated: 2026-06-25 | Author: Robert Agar

Many modern companies require secure web hosting services to support e-commerce and applications that process sensitive data. Company decision-makers must choose from among hosting options that offer varying levels of security. The wrong choice can put business-critical applications and data at risk.

This guide is intended to help users select the right type of secure web hosting for their unique requirements. We examine the core security features to look for when selecting a partner for secure web hosting services. The examination includes a discussion of the various secure hosting options offered by reliable vendors. The guide also reviews WordPress hosting plans that address the large WordPress user base.

## Overview of Web Hosting Services and Secure Web Concepts

Web hosting services provide customers with the infrastructure and associated technologies required to host websites and web applications on the Internet. Hosting providers typically offer multiple hosting options designed to meet the needs of a varied client base. These options range from free domains with limited security to highly secure dedicated server hosting.

Businesses running an e-commerce site or processing sensitive or regulated data need hosting that prioritizes data security and reduces the risk of data breaches. Secure website hosting also supports SEO because search engines favor HTTPS sites in rankings and may penalize unsecured websites. Strong hosting security also helps preserve brand trust and customer loyalty when breach risks arise.

Prospective web hosting customers should consider the following core security pillars when evaluating a provider.

- Physical and infrastructure security, including hosting from a secure data center.
- Network security features such as firewalls, segmentation, and DDoS mitigation.
- Application security with web application firewalls and input validation.
- Data and platform protection with strong encryption and identity and access management, including two-factor authentication.
- Malware and anomaly monitoring, detection, and incident response.
- Backup and recovery with automated backups, immutable storage, and disaster recovery plans.
- Automated patch and vulnerability management.
- Multi-tenant isolation to protect sensitive data resources.

## Types of Hosting: Cloud Hosting, Dedicated Hosting, and More

Organizations should select the hosting solution that best suits their business requirements and objectives from the following primary hosting options.

- **Cloud hosting:** A website consumes computing resources from a cluster of servers to ensure reliability and resilience. This approach protects customers from traffic spikes with autoscaling, but can be challenging to manage efficiently; some managed platforms build on infrastructure such as Google Cloud. For teams that need more flexibility than shared plans, cloud VPS hosting is a common step up.
- **Shared hosting:** In shared web hosting, customers share resources such as RAM, CPU, and bandwidth with other tenants. A basic shared hosting plan is usually the lowest-cost entry point, but storage and bandwidth are often more limited. A shared hosting plan exposes the client to potential performance degradation due to traffic spikes from other tenants and to security risks if another tenant is hacked.
- **Dedicated servers:** Companies that host web applications on dedicated servers can fully tailor the resources to address business requirements and objectives. A dedicated server can be configured to provide the most secure hosting service, but it requires a technically skilled team to manage it effectively.
- **Free web hosting:** Some hosting providers offer free plans suitable for home users and for testing business applications, and they can also suit a static site during testing. These plans are not appropriate long-term solutions for critical systems or sensitive data resources, but are ideal for development work or testing creative ideas.

Average pricing is roughly $2 to $23 per month for shared hosting, $2 to $110 per month for VPS hosting, and $47 to $540 per month for dedicated hosting.

Some plans advertise unlimited bandwidth or unmetered bandwidth to handle growth and traffic spikes, while others set visitor or data transfer limits.

Reseller hosting is another option for users or companies that want to buy hosting services and sell them to others.

## Managed Hosting and Managed WordPress Options

Managed hosting providers handle various technical aspects related to implementing and maintaining a website, which can make a hosting account easier to manage. Organizations often choose managed hosting services to address a lack of skilled staff or to devote more focus on core business activities. Some managed plans also support multiple websites under one account. [Managed hosting options](https://www.atlantic.net/managed-services/) enable single users or small businesses to create and manage a secure website or WordPress site.

The best web hosts also make setup simple with a clear purchase flow and an intuitive dashboard for managing hosted websites.

While managed hosting services minimize the need for technical skills, some tradeoffs may make them inappropriate for some customers. A self-managed hosting solution gives the customer more control over aspects such as security, performance, and data protection.

## Security Features to Look For in Hosting Providers

Customers should search for web hosting providers that offer at least the following basic security features for secure servers.

- The provider should automatically issue SSL/TLS certificates to ensure data encryption.
- Customer data should be protected through automatic backups, with copies stored separately from the production infrastructure.
- A secure web hosting provider will implement the necessary intrusion detection and prevention security tools, supported by proactive monitoring with 24/7 human or AI-driven oversight for unusual activity and intrusion attempts.
- On shared plans, account isolation should keep user directories strictly separated so a compromised neighboring site cannot leak into yours.
- Companies need DDoS protection to prevent malicious threat actors from overwhelming a website with a large volume of automated requests.

### DDoS Protection and Network Defenses

DDoS protection and network defenses are elements of secure web hosting. DDoS mitigation levels protect different aspects of the web hosting environment.

- Layer 3/4 focuses on network and transport attacks by performing deep packet inspection, rate limiting, and preventing malicious traffic from reaching the server.
- Layer 7 focuses on application-specific threats and includes behavioral analysis, WAF rules, and bot management to restrict access to legitimate traffic.
- The optimal approach is to cover all bases with Layer 3-7 to protect the infrastructure and applications.

Secure hosting plans should include effective traffic-scrubbing methods to route incoming traffic through scrubbing servers or centers. The goal is to filter out malicious packets and only forward legitimate traffic to the server.

A reliable provider will protect its secure web hosting solutions with network redundancy and effective failover procedures to maintain application availability in the event of a DDoS attack.

### Web Application Firewalls and Malware Scanning

Businesses can secure their web applications with a web application firewall (WAF), and many providers pair it with a malware scanner. A WAF provides security at the application layer, augmenting standard network firewalls by identifying threats in real time before they can impact a website. Core protections offered by a WAF include:

- Blocking common exploits such as SQL injections, remote file inclusion, and cross-site scripting;
- Inspecting payload components for suspicious patterns or behavior;
- Stopping automated attacks such as credential stuffing and application-layer DDoS attacks.

Customers should request malware scanning reports from prospective providers to verify that the site is protected effectively. Some providers also bundle a WordPress security plugin to further harden applications. Reliable hosting providers will also confirm that automatic patching and vulnerability scanning solutions are in place.

## How To Evaluate Hosting Providers And Find The Most Secure Hosting

Prospective web hosting customers must adopt a methodical approach to determine the provider with the best secure web hosting services when comparing SiteGround with other hosting companies. Decision-makers can make an informed choice of a secure web hosting provider by following the steps below.

Create a checklist to compare the security-focused aspects of prospective cloud hosting vendors. The checklist should cover basic security features, such as encryption, as well as advanced solutions, such as malware scanners. Compare uptime guarantees against the 99.9% industry standard, and note that some providers offer 99.99%.

Potential secure web hosting providers must be scored objectively based on the security features they offer and independently tested response times, with strong hosts often averaging under 200 milliseconds and weaker ones exceeding 1 second. Companies cannot be overly influenced by factors such as price when searching for a secure hosting partner. Introductory discounts often require commitments of one to four years. Shared hosting renewal pricing also commonly rises by $10 or more per month after the initial term.

Organizations can verify a web hosting provider’s ability to deliver a secure platform by reviewing their compliance certifications and third-party security audit reports. These certifications provide customers with evidence that the provider can address their secure hosting requirements. Look for the following specific certifications.

- ISO/IEC 27001 is a globally recognized standard that proves a data center manages information and physical security effectively.
- SOC 2 Type II audits verify that secure web hosting services address the trust principles of security, availability, processing integrity, confidentiality, and privacy.
- Companies processing regulated data need to confirm that their provider meets specialized compliance standards, such as HIPAA for healthcare information and PCI DSS for credit card data.

Teams should compare response times for various incident types affecting website and application security. Reliable providers will guarantee their web hosting services through strict service-level agreements (SLAs) to ensure system security and availability.

## WordPress Site And Website Builder Considerations

WordPress is a very popular content management system (CMS) for websites and web applications. It enables teams to create and manage websites without extensive coding. Companies that rely on the platform should look for a provider that offers dedicated WordPress hosting plans, especially for e-commerce sites.

Businesses with limited technical resources should strongly consider managed WordPress hosting. Their hosting provider is then responsible for managing the website, allowing customers to focus on running their core business. Managed hosting plans enable companies to utilize the provider’s skilled staff for optimal WordPress performance.

WordPress users can minimize a site’s attack surface and security by using plugins sparingly. Plugins are executed directly within a website’s environment, providing threat actors with additional entry points for malicious activity. Each additional security plugin or general plugin can increase the attack surface if it is poorly maintained. Fewer plugins typically equate to a lower risk of exploitation.

Teams must use plugins intelligently when they provide specific required features. Plugins should only be installed from reputable developers. Users should avoid cracked plugins that may be infected with malware. Inactive plugins should be deleted from the environment to improve security by eliminating potentially exploitable vulnerabilities.

Teams should adopt these plugin hardening best practices:

- Enabling automatic updates or checking for updates regularly to avoid outdated and vulnerable plugins;
- Limiting the users who can install or modify plugins;
- Avoiding pirated plugins that present an elevated risk of exploitation by threat actors.

Companies may be motivated to use a website builder to streamline the site’s design and functionality. Teams must understand the security tradeoffs associated with using a website builder. The tool’s convenience must be seen in the context of developing a secure web hosting solution. Here are some potential issues with website builders.

- Vendor lock-in can expose a site to risk if the underlying platform is targeted for exploitation.
- Businesses have no visibility into specific security features and cannot modify code to address unique requirements.
- Open source website builders may rely on abandoned plugins that introduce security vulnerabilities.

Organizations should strongly consider the following backup cadence to protect their specific type of WordPress hosting environment.

- The databases on e-commerce sites should be backed up hourly or replicated in real time. Full site files should be backed up daily to safeguard against a site crash.
- Teams should back up databases on active blogs and news sites daily, and back up full site files weekly or after updates.
- Static sites should be backed up monthly or whenever changes are made.
- Teams should always initiate an on-demand backup before updating WordPress files, themes, or plugins.

### Migrating A WordPress Site Securely

Companies that need to migrate a WordPress site securely should follow these best practices. An optimal migration will incur zero downtime and result in a secure site creation at the new destination.

- Teams should begin with pre-migration hardening activities, including updating all WordPress code and plugins, deleting inactive plugins, deactivating security plugins, and turning off caching plugins.
- Perform a full, off-site backup to local, secured storage.
- Choose a reliable, secure migration plugin, or move files manually via SFTP or SSH. Export the database and store the file in a secure location.
- Create the new server environment that is inaccessible to the public using a temporary staging area. Generate a new database and import the exported SQL file to the new host. Delete all residual files after the import is complete.
- Update credentials and cycle the WordPress security salts to generate new, unique keys. Teams should configure file permissions to prevent access from unauthorized entities.
- Perform a complete inspection of all staged components in preparation for a live cutover.
- Update database references, validate the SSL certificate, and point nameservers to the new host. Reduce the DNS Time-to-Live (TTL) before the move to propagate changes quickly.
- Re-enable security software, such as firewalls and malware scanners, on the new live site.

## Free Web Hosting: Risks And When To Use It

Free web hosting provides customers with a cost-effective way to run a website or content delivery network. Some plans include a free domain or a free domain name for the first year, but that promotional value does not offset weak security. A free provider typically does not offer the essential security features required to support a business website. Hosting companies typically provide the reliable security measures businesses require with paid hosting plans.

Companies concerned with the security of their websites should only use free hosting for testing. Teams can use a free website to optimize applications and add new features before introducing them to the production site. The security limitations of free options make them a risky choice for processing sensitive data or supporting e-commerce sites.

Customers opting for free hosting services should choose a provider that offers free TLS/SSL certificates to encrypt their web traffic. Encryption is one of the most basic security features and is necessary to protect data from unauthorized use. A company can use a provider that offers free SSL certificates as a temporary measure until it moves to a paid, more secure web hosting plan, especially since domain offers are often limited to certain extensions or initial signup periods.

## Performance, CDN, And Cloud Hosting Optimizations

Companies can increase site speed and deliver information efficiently with a content delivery network (CDN). A CDN leverages a distributed network of servers to cache data closer to users. This concept reduces latency and leads to a more satisfactory user experience. Teams can adopt two distinct approaches to data caching.

- **Cache-aside:** An application checks the cache first to service a request. If the data does not currently reside in the cache, it is fetched from the database and then stored in the cache for future use.
- **Write-through:** This caching writes data to the database and cache at the same time. It slows down the operations but keeps the cache continually updated.

Cloud computing provides avenues enabled by virtually limitless computing resources. Companies can implement autoscaling to ensure they always have sufficient capacity to handle traffic spikes while reducing resource utilization to minimize costs when possible.

## Dedicated Hosting Security Hardening Checklist

Organizations should implement the following best practices to harden dedicated hosts for which they have control over security tools and policies.

- Teams should enforce SSH key access, which uses cryptographic key pairs to log in to the server rather than traditional credentials that threat actors may compromise.
- Administrators should apply all OS and software patches promptly to address known vulnerabilities.
- Companies should segment networks to keep sensitive data and applications separate from less critical resources.

## FAQs And Common Security Troubleshooting

Q: What is the most secure type of web hosting?

A: The most secure hosting services are provided with dedicated servers that eliminate the security risks in a shared environment. Customers have complete control over a dedicated, physical server and can implement application and security stacks aligned with their business requirements.

Q: How can teams mitigate an ongoing DDoS attack?

A: The following steps should be taken to mitigate an ongoing DDoS attack.

- Reroute incoming traffic through a cloud-based protection service.
- Implement rate limiting to cap the number of requests from specific IP addresses.
- Scale cloud resources to handle traffic spikes and distribute requests across multiple servers.
- Perform blackhole routing to prevent all traffic from reaching the targeted server.
- Enable strong WAF rules to identify and restrict traffic from malicious bots.
- Engage the cloud provider’s incident response team for specialized assistance.

Q: What are the expected costs for advanced security features and data protection?

A: Companies should expect additional charges for advanced security features and data protection. The fees are typically based on the organization’s size and the number of users or systems to be protected. Examples include data loss prevention software and advanced endpoint threat detection and protection.

## Next Steps for Secure Web Hosting

Customers seeking a secure web hosting solution should begin by evaluating their security requirements and choosing from among shared, cloud, and dedicated server options. Once they have determined the secure hosting approach that best suits their business, they can compare vendors to identify the best web hosting services and develop a migration plan.

Atlantic.net offers customers a wide array of options, including [dedicated servers](https://www.atlantic.net/dedicated-server-hosting/), [bare-metal servers](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/), cloud hosting plans, [HIPAA](https://www.atlantic.net/hipaa-compliant-hosting/) and [PCI-compliant servers](https://www.atlantic.net/pci-compliant-hosting/), and VPS hosting. The company’s expert technical teams provide excellent customer support and secure managed hosting services that let you concentrate on running your business. [Contact us](https://www.atlantic.net/about-us/corporate-contact/) to learn more about how we can help you create and manage a secure web hosting solution.


---

# PCI DSS Network Segmentation: Architecting and Validating CDE Isolation

> URL: https://www.atlantic.net/pci-compliant-hosting/pci-dss-network-segmentation-architecting-and-validating-cde-isolation/ | Published: 2026-07-03 | Author: Robert Agar

The Payment Card Industry Data Security Standard (PCI DSS) regulates how organizations handle cardholder data. Managed by the [PCI Security Standards Council](https://www.pcisecuritystandards.org/), it sets 12 core requirements for securing the cardholder data environment (CDE), and organizations that fail to meet them can face fines, increased scrutiny, and even the loss of merchant status.

Network segmentation divides an IT environment by placing sensitive systems in separate networks, away from other infrastructure elements. In PCI DSS, network segmentation means isolating sensitive data and the systems that store, process, or transmit it, so fewer assets fall within scope, a practical way to protect cardholder data while reducing the number of system components subject to PCI DSS compliance. A reduced PCI DSS scope provides multiple benefits, including:

- Lowering compliance costs;
- Minimizing the attack surface;
- Facilitating network segmentation;
- Simplifying compliance efforts;
- Reducing breach impacts.

For organizations and IT or security teams responsible for PCI DSS compliance, segmentation also strengthens day-to-day security operations. In flatter environments without clear boundaries, a compromise in one area can spread across the entire network; with segmentation, teams can focus controls, testing, and monitoring on the limited network segments that contain cardholder data. The sections that follow cover the practical work behind that approach, including data-flow mapping, network and asset inventory, physical and logical segmentation design, validation and testing, access control, third-party connections, documentation, reporting, and the maintenance of continuous compliance.

## Cardholder Data Environment and Cardholder Data

The cardholder data environment comprises the people, processes, and technology used to store, process, or transmit cardholder or authentication data. The CDE defines the scope boundary used by PCI DSS to identify the systems and processes that must meet the security standards. The PCI DSS scope includes any system components on the same network, even if they do not directly interact with secure cardholder data, that can be used as a gateway to that sensitive information.

Organizations must protect specific elements of cardholder data to achieve PCI DSS compliance. The main data element is the Primary Account Number (PAN), the full 14 to 19-digit card number that identifies a cardholder’s account. Businesses that are not processing, transmitting, or storing the PAN are generally not subject to PCI DSS compliance. Teams must document the storage locations that contain PANs so they can be included in PCI DSS compliance efforts.

Additional data elements, such as the cardholder’s name, card expiration data, and service code, are considered cardholder data only when they are connected to the PAN. This information is not considered regulated data when stored away from the PAN. Systems that touch the PAN must meet compliance standards and should be located in the PCI DSS network segment. Applications and systems that only view truncated or tokenized PANs are typically outside of the PCI DSS scope.

Businesses must also protect the sensitive authentication data (SAD) associated with cardholder data. SAD includes information such as a card’s magnetic stripe, chip data, CVV security code, and PIN. SAD can never be stored, even if encrypted, and must be securely deleted after being processed.

## Map Data Flows and Scope Cardholder Data

The first step in architecting a secure network for PCI DSS compliance is to map the way cardholder data flows across an organization’s IT systems. Teams must identify all systems and applications that handle cardholder data and determine whether they interact with the full PAN or with supplemental data that PCI DSS does not directly regulate. A company’s infrastructure and software assets can then be classified as either in scope or out of scope for PCI DSS protection.

## Inventory Network Components and Modern Network Architectures

Organizations must inventory all physical and virtual network components and devices to identify those that transmit cardholder data. Companies with cloud environments must include all cloud services and resources that handle cardholder data to ensure the necessary security measures protect them. The inventory must include all containers and microservice endpoints that may require safeguarding with PCI DSS controls.

## Design Principles for Implementing Network Segmentation and Data Security

Companies can implement PCI DSS network segmentation using either physical or logical methods.

### Physical network segmentation

This approach uses dedicated hardware, such as switches, routers, firewalls, and servers, to isolate sensitive data and critical systems from the rest of the IT environment. Physical network segmentation offers the following advantages.

- The lack of shared infrastructure provides stronger CDE isolation.
- Misconfigured general network security controls do not provide access to the CDE.
- It is easier to demonstrate compliance to a Qualified Security Assessor (QSA) to verify PCI DSS compliance.

The disadvantages of this segmentation method include:

- Increasing IT expense for dedicated hardware;
- Reducing flexibility and scalability to meet evolving business needs;
- Potentially underutilized hardware in the CDE.

### Logical network segmentation

Businesses can logically segment the cardholder data environment with software and configuration controls on shared physical infrastructure. Common methods of logical segmentation include:

- [Virtual Local Area Networks](https://csrc.nist.gov/glossary/term/virtual_local_area_network) (VLANs);
- Firewalls and strict access control lists (ACLs);
- Software-defined networking (SDN);
- Isolating workloads in virtual environments and containers.

The advantages of logical segmentation include reduced costs, increased flexibility, and enhanced scalability in cloud environments.

Companies that choose a logical segmentation approach must address several disadvantages.

- A misconfiguration can expose the CDE to the broader IT environment.
- Teams must continually test the environment and regularly monitor controls to ensure proper segmentation remains in place to protect the CDE.
- It may be more difficult to demonstrate effective network isolation to a QSA due to the shared hardware.

### Common network segmentation activities

Companies must perform several activities regardless of the method they use to implement network segmentation, and strong segmentation efforts begin by limiting exposure within the environment.

- Organizations should reduce the CDE’s attack surface by eliminating unnecessary components within the segmented environment.
- Teams must develop and enforce least-privilege access controls to restrict unauthorized users from the environment.
- Cardholder data must be encrypted when transmitted over a network, and at rest when stored in on-premises or cloud storage solutions.

PCI DSS compliance supports both methods and requires that the segmentation process be adequate, verified, and maintained to ensure ongoing compliance. Teams must test segmentation controls at least annually and when the network experiences a substantial change. Logical segmentation may require stronger documentation to demonstrate that the controls meet PCI DSS compliance standards. QSAs will typically perform a more thorough examination of logical segments due to the risk of misconfigurations that could lead to data breaches.

Most modern environments, especially in small and medium-sized businesses, favor logical segmentation for its cost-effectiveness and flexibility. These companies must implement reliable network configurations to achieve PCI DSS compliance.

## Implement Logical Network Segmentation: Step-by-Step

Companies should implement logical network segmentation of their PCI DSS scope by following these steps.

1. Create an isolated CDE network segment with VLANs or Virtual Routing and Forwarding (VRF) solutions. The PCI DSS network segmentation should be based on the company’s prior data and network resource inventory.
2. Implement and deploy dedicated firewalls at the boundaries between the CDE and all other segments and zones. These firewalls are essential for segregating the CDR from less critical systems and business processes.
3. Design and implement access control lists to protect data traveling through Layer 3 routers or switches, rather than relying on dedicated firewalls. Inbound and outbound network traffic should be filtered using ACLs, and denied attempts should be logged for review by the security team.
4. Teams should enforce microsegmentation with granular, policy-based segmentation controls to protect against malicious east-west traffic moving laterally through the environment. Microsegmentation prevents granting access to additional CDE resources if threat actors compromise one system.
5. PCI DSS network segmentation must be tested, verified, and documented to simplify compliance efforts. Teams should be prepared to provide a QSA with complete details of the company’s PCI DSS segmentation.

### Deploy Intrusion Detection Systems and Continuous Monitoring

Companies should protect the CDE by deploying intrusion detection systems (IDS) at segment boundaries to deter threat actors from accessing sensitive data within the PCI DSS network. Effective network segmentation must include solutions for detecting and responding to CDE incursions.

Alerts generated by the IDS should be integrated into the organization’s security information and event management (SIEM) solution so they can be addressed effectively to protect the segmented environment. Teams must implement continuous monitoring for CDE traffic, including external and internal access requests. Failed access attempts should be analyzed for patterns that may indicate the need for firewall or ACL changes.

## Validate Segmentation: Testing and Penetration

Organizations must validate network segmentation by testing networks and document the results for an internal or external PCI DSS assessment. The following activities are essential for ensuring the validity of a PCI DSS segmentation.

- Teams should perform annual penetration testing on the CDE and immediately address any identified vulnerabilities.
- Firewall rule reviews must be conducted regularly for all paths into the CDE with appropriate changes made to strengthen network defense.
- Companies should run internal and external network scans to verify that all sensitive data and systems are in the CDE.
- Teams must verify that no unprotected paths to the CDE exist from out-of-scope systems.

## Continuous Monitoring, Logging, and Incident Response

Companies must guard against data breaches that can undermine PCI DSS compliance and erode customer trust. Teams should implement automated tools to support monitoring, logging, and incident response for the CDE. Specific activities they can take include:

- Centralizing logs for a complete view of CDE activity;
- Defining and enforcing alerting thresholds for anomalies or suspicious behavior;
- Testing incident response playbooks at least quarterly to ensure they remain effective.

## Enhanced Security Controls and Access Controls

Teams must implement and enforce enhanced security controls to ensure that only authorized personnel can access systems and applications within the PCI DSS network segment. Companies should protect cardholder data using the following strong access controls.

- All individuals attempting to access the CDE should use multi-factor authentication (MFA). These stricter access controls are necessary to meet PCI DSS requirements and prevent unauthorized access.
- Companies must limit access to the secure environment on a business-need-to-know basis. Access management is essential for effective network segmentation. Teams must implement role-based access controls for all users in the cardholder data environment.
- Companies must implement strong cryptography to encrypt cardholder data both in transit over public networks and at rest. Teams must manage and protect encryption keys, including rotating them regularly and limiting access to authorized personnel.

## Third-Party and Service Provider Considerations

Organizations need to control access to the CDE by third parties and service providers. Teams must assess the level of vendor access to the CDE for business activities such as payment processing. Firewall rules should be leveraged to limit network paths that allow third-party access to systems that store cardholder data.

Companies should require segmentation evidence from service providers to support a PCI DSS audit. This evidence is for companies implementing logical segmentation with a cloud service provider (CSP).

## Reporting, Documentation, and DSS Network Segmentation Evidence

Organizations must be prepared to pass a PCI DSS audit triggered by data breaches, major infrastructure changes, transaction volume, or business reclassification. Teams will need to provide QSAs with segmentation reports that demonstrate PCI compliance. They should periodically test networks and retain reports as audit evidence. QSAs will expect updated network diagrams and data flows that complete the CDE.

## Tools, Automation, and Continuous Compliance

Teams should use advanced tools and automation to enhance security by enforcing firewall policies, performing intrusion detection, and streamlining incident response. Strong configuration policies should be automated and implemented to minimize misconfiguration that can expose sensitive data to threat actors.

Organizations should strive to maintain ongoing compliance through regularly scheduled automated compliance checks. Issues identified through regular monitoring of those checks and controls over time should be addressed promptly before they lead to data breaches. Companies must remain compliant with new requirements and protect the environment from evolving cyber threats.

## Checklist: Implementing Network Segmentation for PCI DSS

The following checklist outlines the steps and practices discussed above to create a segmented cardholder data environment.

- Map the flow of cardholder data.
- Inventory network and infrastructure components.
- Design a logical or physical segmentation strategy.
- Implement the appropriate segmentation controls.
- Verify the segmentation with complete testing.
- Monitor the segmentation continuously and address vulnerabilities promptly.

## Next Steps and Resources

Company decision-makers should draft a team and assign business and technical owners to the CDE segmentation project. Teams should conduct testing to reevaluate the environment after network or application changes. Businesses are encouraged to engage an independent QSA to validate the PCI DSS scope and network configuration.

Atlantic.net offers its customers [PCI-compliant cloud and dedicated hosting solutions](https://www.atlantic.net/pci-compliant-hosting/) audited by a third-party QSA. [Contact their team](https://www.atlantic.net/about-us/corporate-contact/) to learn more about protecting your sensitive cardholder data.


---

# Artificial Intelligence in Networking: Models, Infrastructure, and Strategy

> URL: https://www.atlantic.net/gpu-server-hosting/ai-in-networking-models-infrastructure-strategy/ | Published: 2026-07-04 | Updated: 2026-06-25 | Author: Dr. Tehseen Zia

Artificial intelligence and networking are coming together in two important ways. The first is AI for networking, which uses AI to enhance network management through automation, security, observability, performance optimization, and predictive analytics. The latter is networking for AI, which centers on creating high-performance infrastructure to support AI workloads for training and inference. From this perspective, AI in networking encompasses both the infrastructure that supports AI systems and the intelligent technologies used to manage, automate, and optimize network operations.

On the backend, it includes network fabrics that connect compute resources such as GPUs and support large-scale AI training and inference workloads. On the front end, it uses AI for routing, security, observability, and service assurance in networking. Together, these two domains help maximize network performance and support modern AI applications through intelligent systems, high-performance network fabrics, and automated operations. This means that AI in networking includes everything from AI-assisted traffic management and predictive assurance to GPU interconnects, lossless fabrics, and distributed training networks.

## AI in Networking vs. Traditional Networking

Traditional networking was built mainly for general business traffic. It often relied on manual configuration, static policies, and best-effort delivery. That approach works well for office apps, web traffic, and routine enterprise workloads. 

AI networking has a different profile. It must support synchronized GPU communication, high packet rates, and workloads that are very sensitive to delay. Even small losses or congestion can slow training jobs and waste expensive compute time. Traditional enterprise networks can usually tolerate moderate retransmission and variable latency. But AI-driven networks often need much higher throughput and much tighter latency control. These requirements become especially important in large-scale distributed training clusters, where thousands of GPUs must exchange data efficiently and remain synchronized throughout the training process.

Another key difference lies in network operations. Traditional networks are typically managed through alerts and manual troubleshooting. We often react to issues after they occur. In contrast, AI networking uses automation, predictive analysis, and closed-loop remediation to take a more proactive approach. By continuously analyzing telemetry data, AI-enabled networks can detect anomalies, identify performance trends, infer likely root causes, and recommend or initiate corrective actions before users or applications are significantly affected. 

## How AI in Networking Works

The integration of AI and networking can be viewed at three distinct levels. The first is the data center backend, where models are trained, and large-scale inference is executed. At this layer, networks are specifically designed to support the demands of AI workloads. The second is the enterprise frontend, where AI is used to improve network operations such as path selection and routing. The third is the management layer, which is where AI can be used to manage the network itself. The last two layers focus on applying AI technologies to network operations, management, security, and optimization.

## Data Center Backend (AI Workloads)

This is the most challenging part of AI networking. It focuses on building network infrastructure specifically for AI workloads. Collective communications like all-reduce and all-to-all are used to exchange gradients and parameters continuously during distributed training.  This communication leads to bursts of synchronized traffic, and any packet delay or loss can slow down the entire job. For this reason, lossless transport has become crucial for AI networking.  

RDMA (Remote Direct Memory Access) has also become an essential part of AI networks. It enables communication of the GPU memory directly over the network without involving the host CPU. This helps AI networks to reduce the latency significantly. Priority Flow Control (PFC) and Explicit Congestion Notification (ECN) are typically used with RDMA to provide reliability. In this way, packet losses are minimized, and GPU clusters remain productive. 

Physical topology also matters. A non-blocking Clos or leaf-spine design is commonly used to provide predictable access to the fabric for each GPU node. This architecture also helps remove bandwidth bottlenecks with deep packet buffers that handle the incast traffic patterns common in AI workloads.

## Enterprise Frontend and WAN

The frontend side is about serving users. AI applications such as copilots, recommendation engines, fraud checks, and real-time analytics all depend on fast and consistent response times. In this part of the network, predictive path selection and continuous assurance are more useful than static routing.

AI models on the enterprise side analyze historical and live traffic data to make smarter routing decisions. Rather than reacting to congestion, predictive path selection routes traffic proactively. Real-time assurance workflows continuously monitor application performance and automatically reroute traffic when a degrading path is detected. Placing inference workloads at edge nodes reduces round-trip latency for latency-sensitive applications.

## Agentic AI Systems and AI Agents

Agentic AI is introducing a new level of automation to network operations. Unlike traditional AI systems that primarily analyze data, summarize logs, or generate alerts, AI agents can reason about problems, recommend corrective actions, and execute approved tasks within defined policy boundaries. These systems can autonomously take remediation measures, such as quarantining a device, rerouting traffic, or adjusting firewall rules in response to a detected threat. Some typical use cases include automated incident response, configuration drift correction, and capacity rebalancing.

Human-in-the-loop governance is a critical component of an [AgenticOps](https://medium.com/@OpenCSG/agenticops-the-missing-operating-system-for-enterprise-ai-4f536de1a844) framework. Each automated action must have rules of engagement, tracking logs, approval thresholds, and rollback steps. The [National Institute of Standards and Technology AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) emphasizes governance, mapping, measurement, and management as key elements of trustworthy AI systems. These principles align closely with the requirements of modern network operations. 

## Core AI Technologies for Networking

The integration of AI and networks is operationalized through a set of technologies that form the backbone of modern intelligent networking systems. At the core of this stack are AI models, which analyze large volumes of telemetry data and uncover patterns that would be difficult to identify through manual inspection. By learning the network’s normal behavior, these models can detect anomalies, unusual traffic patterns, and early signs of potential failures.

Data Processing Units (DPUs) and smart Network Interface Controllers (NICs) are used to offload processing tasks from the CPU. This improves overall efficiency and allows host resources to be dedicated primarily to AI workloads. In addition, GPU interconnects such as NVLink and PCIe facilitate high-speed data movement between accelerators. They reduce communication overhead and minimize bottlenecks before traffic even reaches the external network fabric.

Another important aspect is streaming telemetry. Instead of relying on periodic polling of network devices, modern networks continuously stream live operational data to analytics systems. This enables AI models to detect trends and evolving behavior patterns across the network and respond to changes in near real time. The ability to process real-time network data and respond accordingly significantly improves both visibility and overall network responsiveness.

It is also becoming popular to tokenize network events for language models. Log, alert, and flow records can be converted to structured text so that an LLM can summarize incidents, answer questions, or provide a troubleshooting guide.

## AI Models and AI Workloads

The AI networking supports two types of workloads. Training workloads are large, synchronized, and expensive. They depend on many GPUs working together and are highly sensitive to delays between nodes. Inference workloads are usually smaller and more distributed. They focus on delivering predictions quickly and consistently to users.

LLMs can also support [NetOps](https://www.cisco.com/site/us/en/learn/topics/networking/what-is-netops.html). They can help operators query configurations in plain language, summarize incidents, or explain traffic patterns. Used carefully, they can make network data easier to access for teams that are not deep in CLI syntax or telemetry tools.

The traffic patterns are different, too. Training traffic is often bursty and synchronized, while inference traffic is usually asynchronous and spread across many requests. That means the infrastructure must be designed for both predictable collective flows and less structured user traffic.

## AI Systems, AI Tools, and AI Agents

The role of AI in networking relies on a wider range of tools. Machine-learning-based monitoring platforms detect anomalies, reduce false alert rate, and surface correlated issues before manual review. This information is then translated into actions or playbooks by automation platforms. There is growing use of LLMs (Large Language Models) as tools for natural-language queries. An operator can request bandwidth trends, view the latest alarms, or provide root-cause hints. The system can convert these requests into a telemetry search or an API call. This helps lower the barrier to operating and managing complex networks.

As systems mature, Agent Orchestration is gaining significance. A monitoring agent can identify a fault, a diagnostic agent can diagnose an issue, and a remediation agent can suggest a solution. The orchestration layer organizes those actions in order and within policy.

Organizations also need to decide between open and closed models. Open models can provide more control and private deployment. In contrast, the closed models can provide better performance or greater simplicity. The right choice depends on privacy, cost, compliance, and how much the team needs the internal control.

## AI Infrastructure and AI Solution Design

The network fabric is the first step in building a strong AI-ready network. A leaf-spine design is typically employed for its ability to scale cleanly and to handle low oversubscription. For training clusters, it’s worth the additional cost of a non-blocking or near-non-blocking design, since GPU idle time is costly.

It is just as critical to have high-bandwidth NICs and optics. AI environments typically require 100, 200, 400, or even 1000+ service speeds, low-latency transport, and lossless features. The goal is to prevent the network from becoming the “bottleneck”.

AI Networking-as-a-Service is becoming vital for organizations seeking AI-optimized connectivity without having to build their own fabric. For organizations that do not want to build AI networking in-house, a managed cloud or dedicated environment may speed up the deployment. Atlantic.net, for example, provides GPU cloud hosting, virtual private cloud, dedicated hosting, private virtualization, and managed hosting, which can help teams run AI workloads before committing to a larger, permanent build-out. 

Different workloads also have different infrastructure requirements. Certain workloads may be better suited to an on-premises environment, such as those with high data sensitivity, low-latency requirements, or predictable capacity. Others can take advantage of the scalability and flexibility of cloud environments. For some workloads, a hybrid deployment model is often the most practical approach because it allows each workload to run where it provides the better operational and economic advantage.

## AI in Networking Strategy

The first step in an effective AI networking strategy is ensuring the availability and quality of data. It involves a strategy for collecting telemetry, logs, flow records, and incident data. It also requires a labeling procedure to ensure that past events can become useful training material for models.

Another important factor is the use of real, well-defined KPIs to measure success. In this regard, valuable metrics include latency, utilization, incident response time, automation success, model accuracy, and training throughput. It is also important that these metrics are directly connected to business outcomes. 

Governance should be an integral part of the strategy. Privacy controls, audit trails, access management, and review processes are essential for AI systems. This is particularly crucial in areas where AI can influence routing, security, or customer services.

Change management is another crucial aspect of AI in networking. As these systems evolve rapidly, network teams need time to understand the tools, build trust in their outputs, and adapt their working practices accordingly. Training, documentation, and staged rollouts are essential to ensure smooth adoption and that AI enhances operations rather than disrupts them.

## Implementation Roadmap

The first step to applying AI in networking is to evaluate the environment. This involves understanding what types of telemetry data are already available, identifying gaps in visibility, and determining which operational tasks are still being performed manually.

The next step is to choose a focused pilot project with clearly defined success metrics. An effective pilot should be specific, measurable, and easy to evaluate. Common starting points include anomaly detection, WAN optimization, and accelerating troubleshooting within a particular network environment.

For use cases involving sensitive data, approaches such as Retrieval-Augmented Generation (RAG) can be particularly useful. This allows AI models to generate responses based on private documents and internal telemetry without broadly sharing raw underlying data.

It is also important to implement the pilot in phases. Start with observation-only mode to understand behavior without making changes. Then, move to recommendation-only mode where the system suggests actions. After that, introduce limited automation in a controlled way. Once this approach is stable and reliable, it can be gradually scaled across other parts of the network.

## Enterprise Use Cases and AI Benefits

The integration of AI and networking offers significant benefits for both domains. One key advantage is faster training. A well-designed AI fabric keeps GPUs highly utilized, reduces idle time, and ultimately shortens model development cycles while improving overall resource efficiency.

Another important use case is WAN assurance. AI can detect weakening paths, predict issues with experience, and reroute traffic before users notice major disruption.

Security is also a major area of value. AI can help identify suspicious patterns, correlate signals across different systems, and accelerate response when unusual activity is detected across the network.

## Risks, Limitations, and Mitigations

When using AI in networking, it is crucial to be vigilant, as AI systems are not infallible. LLMs can provide incorrect answers, misunderstand the context, or draw incorrect conclusions, especially when dealing with incomplete or poor-quality data. For this reason, organizations should ensure that critical decisions and high-impact actions remain subject to human review and approval. 

Privacy and regulatory compliance are other aspects that require careful consideration. Network telemetry and operational data can contain sensitive information about users, applications, and business processes. When cloud-based AI services process this data, organizations may face compliance and data sovereignty concerns, particularly in highly regulated sectors. To address these risks, organizations handling sensitive workloads should consider private AI deployments or on-premises inference environments.  

Robust AI-driven systems must also have controls to mitigate the risk of automation failures. Humans must authorize a high-impact change, or a fallback mechanism must be implemented to ensure that if the AI-driven change fails or an unreliable change is generated, a known-good configuration is applied without causing disruption or additional downtime.

## Monitoring, Observability, and Continuous Improvement

Like traditional network operations, AI systems also require continuous monitoring. Teams should collect per-link, per-flow, and per-device telemetry to gain granular visibility into network behavior. Adaptive baselining can help to reduce false positives by replacing static thresholds with dynamic models that learn normal behavior based on time of day, workload patterns, or specific site characteristics.

[OpenTelemetry](https://opentelemetry.io/) provides a practical framework for standardizing the collection of traces, metrics, and logs across diverse environments. In addition, model retraining should be planned and systematic rather than ad hoc. As traffic patterns, applications, and policies evolve, models can drift over time. This makes periodic validation essential to ensure that AI systems remain aligned with the network’s actual behavior.

## Future Trends and Next Steps

The next phase of AI networking will likely bring faster fabrics, wider use of telemetry-driven control, and more agentic operations. Current vendor roadmaps already point toward 800G-class switching, AI fabrics that span multiple data centers, and hardware-assisted congestion management designed to support increasingly demanding AI workloads. 

As networking environments become more intelligent and automated, the skills required to manage them will also evolve. Network professionals will need a stronger understanding of data management, AI model governance, automation frameworks, and operational oversight. Success will depend not only on deploying AI technologies but also on managing them responsibly and effectively.


---

# Guide to Unlimited Bandwidth Hosting in 2026: Plans, Providers, and Performance

> URL: https://www.atlantic.net/managed-services/unlimited-bandwidth-hosting/ | Published: 2026-07-05 | Updated: 2026-06-26 | Author: Dr. Assad Abbas

Bandwidth is the amount of data transferred between a website, its hosting server, and its users. It is used when visitors open pages, view images, stream media, download files, submit forms, or use an application. In hosting plans, unlimited bandwidth means that the provider does not set a fixed monthly data transfer limit for normal website traffic.

Unlimited bandwidth does not mean unlimited hosting capacity. A hosting account still depends on server resources, network conditions, and fair use rules. Port speed, CPU, RAM, storage, disk activity, database usage, and concurrent connections may also limit it. Therefore, buyers should review the actual bandwidth policy before selecting a plan, even when the plan is advertised as unlimited.

Bandwidth directly affects website speed, uptime, user experience, and monthly cost. In 2026, bandwidth planning has become more important because many websites depend on larger images, video content, APIs, customer portals, and applications. This article explains what unlimited bandwidth hosting means, compares common hosting plans, and shows what buyers should check before choosing a provider.

## Understanding Bandwidth Models in Hosting Plans

Hosting plans usually use three bandwidth models, namely, metered, unmetered, and unlimited. These terms are related, but they describe different billing methods and usage limits. Therefore, buyers should understand these models before comparing hosting plans or provider claims.

### Metered Bandwidth Plans

Metered bandwidth includes a fixed monthly data transfer allowance. For example, a plan may include 5 TB, 10 TB, 20 TB, or more each month. If usage exceeds that allowance, the provider may charge an overage fee, reduce speed, or require a larger plan.

This model is suitable when traffic is predictable. It offers buyers a clear monthly allowance and makes usage easier to estimate. Users must monitor bandwidth usage regularly because unexpected traffic growth can increase costs.

### Unmetered Bandwidth Plans

Unmetered bandwidth uses a different approach, in which the provider usually does not charge for each GB transferred. Instead, the plan is controlled by port speed, such as 1 Gbps, 10 Gbps, or higher.

This model can make monthly billing more predictable because the cost is not directly based on every GB of traffic. Unmetered bandwidth still has a technical limit. The server can transfer data only within the capacity of its network port. Therefore, buyers should compare port speeds carefully, not just the word “*unmetered*”.

### Unlimited Bandwidth Plans

Unlimited bandwidth is different from both metered and unmetered bandwidth. It usually means there is no fixed monthly transfer cap for normal website use. Fair use rules and account limits can still apply.

This model may be suitable for normal business websites, blogs, and content sites. It may not be appropriate for streaming platforms, large downloads, file hosting, backup storage, or high-volume media delivery. These workloads can use large amounts of traffic and may trigger provider restrictions.

### Questions to Ask Before Choosing a Plan

Before buying a plan, users should ask clear questions about bandwidth terms:

- **Monthly transfer:** What data transfer is included in the plan?
- **Port speed:** Is the plan limited by 1 Gbps, 10 Gbps, or another port speed?
- **Overage fees:** What extra charges apply if monthly bandwidth use exceeds the plan’s included transfer allowance?
- **Speed limits:** Can the provider reduce speed after heavy usage?
- **Fair use rules:** Does the policy restrict streaming, downloads, file hosting, or backup storage?

These questions help buyers understand the real value of a bandwidth plan before making a decision.

## Choosing the Right Hosting Plan for Bandwidth Needs

After understanding bandwidth models, buyers should choose a hosting plan based on traffic patterns, content types, and resource needs. The decision should be based on actual bandwidth terms, not solely on a provider’s unlimited-bandwidth claim.

Shared hosting is usually enough for small websites, blogs, portfolios, and local business pages. It is not designed for heavy or continuous traffic because server resources are shared. When a website begins to receive more visitors or uses heavier content, VPS hosting can provide better control and stronger resource separation.

In addition to VPS hosting,[cloud hosting](https://www.atlantic.net/cloud-platform/cloud-hosting/) may be useful when traffic changes frequently or when an application needs flexible capacity. Outbound data transfer in cloud hosting may increase monthly costs. Therefore, users should estimate expected bandwidth before deploying cloud applications.

For workloads with steady, high traffic,[dedicated servers](https://www.atlantic.net/dedicated-server-hosting/) and[bare-metal hosting](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) are usually stronger options. These plans provide greater control over server resources and network capacity. They are more suitable for streaming services, gaming platforms, software download sites, busy SaaS platforms, and media-heavy applications.

The following table compares common hosting plans by bandwidth model, main limit, and intended use.

Table 1: Bandwidth models and usage limits across common hosting plans

| **Hosting Plan** | **Common Bandwidth Model** | **Main Bandwidth Limit** | **Suitable Use** |
| --- | --- | --- | --- |
| **Shared Hosting** | Often marketed as unlimited | Fair use policy, CPU, RAM, and account limits | Small websites, blogs, and local business pages |
| **VPS Hosting** | Metered or generous transfer allowance | Monthly transfer cap or shared node resources | Growing websites and business applications |
| **Cloud Hosting** | Usually metered outbound transfer | Per-GB data transfer cost | Applications with varying traffic needs |
| **Managed Hosting** | Varies by provider and plan | Plan-level traffic rules and service limits | Business websites that need technical support |
| **Dedicated Server Hosting** | Metered or unmetered | Port speed or monthly transfer allowance | High-traffic websites, SaaS platforms, and large downloads |
| **Bare Metal Hosting** | Metered or unmetered | Network terms, port speed, and server capacity | Sustained high-bandwidth workloads |

## Hosting Provider Features to Review After Selecting a Plan Type

After selecting the hosting plan type, buyers should evaluate the hosting provider. Bandwidth should not be reviewed in isolation, as performance also depends on network quality, server resources, security controls, support, and pricing terms. The following criteria can help buyers compare providers more carefully before choosing a hosting plan.

### · Bandwidth Policy and Port Speed

The provider should clearly explain whether the plan is metered, unmetered, or marketed as unlimited. The plan should also state port speed, monthly transfer allowance, fair use terms, and overage fees. If these details are unclear, the customer may face performance limits or billing issues later.

### · Uptime SLA

Uptime SLA should be compared across providers because availability terms are not always the same. Buyers should review the written SLA, service credit policy, and any exclusions. For business-critical websites, availability can affect orders, customer access, and service continuity.

### · Network Peering and Global Presence

Network quality also affects hosting performance. A provider with strong routing, network peering, and multiple data center locations can serve users more effectively across regions. This is important for websites that receive traffic from different cities, countries, or continents.

### · Cost and Renewal Terms

Cost terms should be reviewed along with technical features. Buyers should compare renewal prices, overage fees, control panel charges, backup costs, DDoS protection fees, and managed service costs. A low base price may become expensive if bandwidth use increases or important features are billed separately.

### · Security and Management Features

Security and management features should also be checked. Firewalls, DDoS protection, account protection, routine backups, and control panel access can reduce operational risk. In addition, many providers market free SSL certificates. In current security terminology, these are TLS certificates used to encrypt data in transit.

### · Upgrade Path

A good provider should offer a clear upgrade path. A website may start on shared hosting and later move to VPS, dedicated, or bare-metal hosting as traffic grows. This makes the hosting environment easier to expand without a difficult migration.

## Provider Comparison: High Bandwidth Hosting Options

After reviewing bandwidth models, hosting plan types, and provider selection criteria, buyers can more clearly compare available providers. The following table compares selected hosting providers based on their main strengths, bandwidth considerations, dedicated or bare-metal options, and suitability for different workloads.

Table 2: Comparison of selected hosting providers for high-bandwidth and dedicated hosting needs

| **Provider** | **Main Hosting Strength** | **Bandwidth Consideration** | **Dedicated / Bare Metal Options** | **Suitable Workloads** |
| --- | --- | --- | --- | --- |
| [Atlantic.Net](http://www.atlantic.net) | Dedicated hosting, bare metal, cloud hosting, and compliance-focused infrastructure | Suitable for high-bandwidth workloads; exact plan terms should be reviewed | Yes | Business websites, SaaS platforms, high-traffic hosting, and compliance-focused workloads |
| Rackspace | Managed bare metal and managed cloud services | Depends on the selected product and service level | Yes | Managed infrastructure and enterprise hosting |
| IBM Cloud | Bare metal servers and enterprise infrastructure | Depends on the selected configurations | Yes | Enterprise systems and data-heavy workloads |
| phoenixNAP | Bare metal cloud | Relevant for traffic-heavy and performance-sensitive workloads | Yes | Gaming, streaming, SaaS, and analytics platforms |
| Hivelocity | Dedicated servers and bare metal hosting | High-bandwidth or unmetered options may depend on the selected plan | Yes | Custom dedicated hosting and sustained traffic |
| Leaseweb | Global dedicated server hosting | Relevant for international traffic and high-bandwidth hosting needs | Yes | Global websites, media delivery, and large applications |

Atlantic.Net offers dedicated hosting, bare metal infrastructure, cloud hosting, managed services, and compliance-focused hosting. These services may be relevant for organizations that need stronger control over resources, security, and performance than shared hosting can provide.

Other providers in the comparison also offer managed infrastructure, bare metal servers, global dedicated hosting, and high-bandwidth hosting options. Therefore, buyers should verify transfer limits, port speeds, fair-use policies, overage fees, uptime SLA, DDoS protection, backups, and TLS certificate availability before selecting any provider.

## Dedicated Server and Unmetered Dedicated Server Options

A dedicated server is useful when shared hosting, VPS hosting, or standard cloud hosting cannot meet the bandwidth and performance needs of the workload. It gives one customer dedicated CPU, RAM, storage, and network capacity. Therefore, it can provide better control for high-traffic websites, SaaS platforms, gaming servers, software download services, and media-heavy applications.

After choosing dedicated infrastructure, the next decision is the bandwidth model. Some dedicated servers are sold with a fixed monthly data transfer allowance. This is the metered model. For example, a provider may include 10 TB, 20 TB, or more per month. This option can work well when monthly traffic is predictable, and the offered transfer allowance is sufficient.

In contrast, an unmetered dedicated server is usually controlled by port speed rather than total GB transferred. For example, a 1 Gbps unmetered port gives predictable billing, but it still has a maximum transfer rate. A 10 Gbps port can handle more traffic, but it usually costs more.

Therefore, metered bandwidth is suitable when usage is stable and easy to estimate. Unmetered dedicated servers are better when traffic is heavy, steady, or difficult to predict. Bare-metal hosting may also be suitable when the workload requires stronger hardware control, single-tenant infrastructure, and more consistent performance.

## Managing Bandwidth Usage and Improving Performance

Even a generous bandwidth plan requires regular management. Unnecessary traffic can consume transfer capacity, increase monthly cost, and reduce website performance. Therefore, administrators should first review bandwidth usage through hosting dashboards, cPanel metrics, server monitoring tools, and monthly usage reports. This review helps identify normal traffic levels, peak usage periods, and sudden increases that may require attention.

After bandwidth usage is measured, the next step is to reduce unnecessary data transfer. Many websites send the same files repeatedly, such as images, scripts, stylesheets, and static pages. Caching helps reduce this repeated transfer by allowing stored content to be served again without sending a fresh request to the origin server each time. Caching can reduce server load and improve response time.

Media is also important because large files often consume most bandwidth. Therefore, images should be compressed, suitable file formats should be used, and video delivery should be carefully planned. Large video files are usually better served via a CDN or a media delivery platform rather than the origin server.

A CDN can further reduce origin bandwidth by serving static content from locations closer to users. This can reduce server load and improve response times, especially for websites serving visitors across different regions. In addition, automated alerts should be configured to warn administrators when traffic increases suddenly or approaches plan limits.

## The Bottom Line

Unlimited bandwidth hosting should be assessed through its actual terms, not through the marketing claim alone. A reliable plan should clearly explain the included traffic policy, fair use limits, port speed, and possible charges when usage increases. This clarity is important because bandwidth affects both performance and long-term cost.

The right hosting choice depends on the nature of the website. A small business site or blog may work well on an unlimited shared hosting plan. Websites that deliver videos, large files, application traffic, or frequent user requests may require dedicated servers, unmetered bandwidth, or bare-metal hosting.

Therefore, buyers should compare bandwidth terms together with infrastructure quality, security controls, backup options, uptime SLA, and upgrade paths. This careful review can reduce billing surprises and help the hosting environment support traffic growth in a more controlled and predictable way.


---

# Custom Enterprise Hosting Solutions Built Around Your Workload

> URL: https://www.atlantic.net/custom-enterprise-hosting/ | Updated: 2026-09-16

When standard plans do not fit, Atlantic.Net designs the cloud, dedicated, private, hybrid, and colocation options your requirements actually call for.

- 100% Uptime SLA
- 24/7/365 US-Based Support
- Audited Compliance Environments
- One Provider Across the Stack

Enterprise Infrastructure: Since 1994

US-Based Engineer Support: 24/7/365

Enterprise requirements rarely fit a pricing page. A regulated workload, a hybrid environment, a migration with hard constraints, or a performance target that a standard plan cannot meet: each requires infrastructure designed for the specifics, built for that workload, and not pulled from a predefined list.

The usual answer from a hyperscaler is a console and a support tier; the usual answer from a budget host is "that is not something we can do."

Atlantic.Net sits between those, with the ability to build it and the support to run it. We design and operate custom environments across cloud, dedicated, bare metal, private cloud, colocation, and hybrid models, with managed services, compliance-ready infrastructure, backup, and disaster recovery layered in as required.

## What Are Custom Enterprise Hosting Solutions?

Custom enterprise hosting solutions are infrastructure environments designed around a specific set of requirements. Each one is built for the workload in front of us, not assembled from fixed plans. This can mean a particular mix of cloud and dedicated hardware, compliance controls tied to a regulated workload, a private cloud for isolation, colocation for hardware you already own, or a hybrid that spans several of these, all under one provider and one support relationship.

Atlantic.Net brings the full range to bear: the cloud platform, dedicated and bare-metal servers, single-tenant private cloud, colocation, and managed services for security, monitoring, databases, backups, and disaster recovery. The job is to match those building blocks to your workload, then deploy and support the result.

## Infrastructure Designed Around Your Workload

A custom environment starts from what the workload needs. The design follows the requirements rather than the closest standard plan. In practice, this involves making decisions across several workstreams, including:

### Pick a Compute Model

Cloud, dedicated, bare metal, private cloud, or a hybrid, chosen per tier, so each tier gets the model it needs.

### Any Compliance Posture Requirements

Do you need controls and audited environments aligned with HIPAA, PCI DSS 4.0, SOC 2, or NIST 800-53 obligations?

### Performance and Isolation

Do you need single-tenant hardware and private networking where predictability and separation matter?

### Data protection

What backup, replication, and disaster recovery are sized to the recovery targets the business actually has?

### 24/7/365 Operations

Do you need managed services for the operational areas you would rather not handle in-house, or self-managed infrastructure for the systems you want to retain direct control over?

## What's Included

### Custom Cloud, Dedicated, Bare Metal, Private Cloud, or Hybrid

Build the environment from any combination of Atlantic.Net infrastructure. Run a single-tenant private cloud, bare metal for performance-critical tiers, cloud for elastic capacity, or a hybrid that uses each where it fits.

### Compliance-Oriented Infrastructure

Host regulated workloads inside audited environments for HIPAA and PCI DSS 4.0, with SOC 2 Type II, SOC 3 Type II, and NIST 800-53 controls. A HIPAA Business Associate Agreement (BAA) is available with regulated plans. Compliance remains a shared responsibility, so we provide the audited foundation and documentation, and you keep ownership of your application and policies.

### Managed Services Add-Ons

Add managed firewall and IPS, multi-factor authentication, Network Edge Protection, server management, managed databases, load balancing, and 24/7 monitoring, individually, so you manage what you want and hand off the rest.

### Backup and Disaster Recovery Planning

Managed Veeam backups, replication, high availability, and disaster-recovery configurations are sized to your recovery point and recovery time objectives. Each is scoped to your targets and never applied as a one-size-fits-all template.

### Private Networking and VPC

Connect environments via private networking and VPC isolation, including links between cloud, dedicated, and collocated infrastructure, so the estate behaves as a single private network.

### Colocation and Dedicated Infrastructure

Place your own hardware in Atlantic.Net facilities, or run fully managed dedicated and bare-metal alongside it when you want physical control of part of the stack.

### Migration and Deployment Planning

Atlantic.Net provides migration assistance and deployment support to move workloads to the new environment, with scope agreed up front so the cutover is planned and predictable.

### Architecture That Scales With the Business

Designs account for growth, acquisitions, application modernization, and changing compliance needs, so the environment has room to expand without a redesign each time the business changes.

## From Requirements Review to Deployment

Custom work is only as good as the process behind it. Atlantic.Net runs a straightforward engagement process, so you know what happens at each stage and where decisions are made.

### Discovery

We review your workloads, performance targets, compliance obligations, data-residency needs, and constraints. This is where the real requirements surface, beyond the initial wish list.

### Architecture recommendation

Atlantic.Net proposes an environment: the compute models, compliance controls, networking, and data-protection design, with the trade-offs stated plainly.

### Deployment planning

We agree on the build sequence, migration approach, cutover windows, and responsibilities to avoid surprises during implementation.

### Implementation

The environment is provisioned and configured, with migration assistance and deployment support to the agreed scope.

### Ongoing management or support

Choose fully managed operations, self-managed with support on hand, or a split, backed by 24/7/365 US-based engineers.

## Business Outcomes

### One Partner Across the Stack

Cloud, dedicated, private cloud, colocation, compliance, backup, and managed services come from a single provider with a single support relationship. You manage one account, not a stack stitched together across several vendors.

### Compliance Built Into the Design

For regulated workloads, the audited environment and documented controls are part of the architecture from the start. Compliance is designed in from day one, so there is nothing to retrofit under audit pressure.

### Continuity by Design

Backup, replication, and disaster recovery are sized to your recovery objectives during the design phase, so resilience matches the importance of the workload.

### A Team That Stays After Go-Live

The same provider that designs and deploys the environment runs it, with US-based engineers available around the clock. The relationship continues past handover.

## Who Needs a Custom Enterprise Solution

| Situation | Why Custom Fits |
| --- | --- |
| Regulated enterprises (healthcare, finance, legal) | Compliance controls and audited environments are designed into the architecture |
| Companies outgrowing standard plans | Larger, mixed environments that no fixed package covers |
| Mergers, acquisitions, and consolidations | Infrastructure that absorbs new systems and scales with the combined business |
| Application modernization | Hybrid designs that move workloads in stages, one at a time |
| Multi-environment and hybrid operators | Cloud, dedicated, private cloud, and colocation under one private network |
| Data-residency requirements | Region selection and placement matched to regulatory constraints |
| High-security workloads | Single-tenant isolation, private networking, and managed security |

## A Platform You Can Trust

Atlantic.Net has designed and operated infrastructure for business-critical workloads since 1994. Custom enterprise environments run on the same audited platform as our compliance hosting and offer the same US-based support.

SOC 2 Type II, SOC 3 Type II, HIPAA, HITECH, PCI DSS 4.0, and NIST 800-53 audited environments.

Cloud, dedicated, bare metal, private cloud, and colocation under one provider.

100% uptime SLA on network, hardware, and power.

24/7/365 US-based support by phone, email, and chat, never outsourced.

Privately owned, profitable, and debt-free, with data centers across the US, Canada, the UK, and Singapore.

Atlantic.Net since 1994: 32 years operating enterprise infrastructure.

## Frequently Asked Questions

### What are custom enterprise hosting solutions?

They are infrastructure environments designed around a specific set of requirements, built for the workload in front of us, and not chosen from fixed plans. A custom solution can combine cloud, dedicated, bare metal, private cloud, and colocation, with compliance controls, managed services, backup, and disaster recovery, all from one provider. Atlantic.Net designs, deploys, and supports the result.

### When should I choose a custom solution over a standard hosting plan?

Choose custom when a standard plan does not cover the requirement: a regulated workload that needs specific controls, a hybrid environment, a large or mixed estate, strict data-residency rules, or a performance target a fixed plan cannot meet. If a standard cloud or dedicated plan fits, that is usually the simpler choice, and the team will say so.

### Can Atlantic.Net support compliance-sensitive workloads?

Yes. Custom environments can run inside Atlantic.Net's audited HIPAA and PCI DSS 4.0 environments, with SOC 2 Type II, SOC 3 Type II, and NIST 800-53 controls, and a HIPAA BAA is available with regulated plans. Compliance is a shared responsibility: Atlantic.Net provides the audited foundation and documentation, and you remain responsible for your application, access controls, and policies.

### Can Atlantic.Net combine cloud and dedicated infrastructure?

Yes. Hybrid designs are a core part of custom work. You can run elastic workloads on the cloud platform and performance-critical or isolated workloads on dedicated, bare-metal, or private cloud, connected over private networking, so the environment behaves as one.

### Are managed services available?

Yes. Managed firewall and IPS, multi-factor authentication, Network Edge Protection, server management, managed databases, load balancing, backup, and 24/7 monitoring are all available and added individually. You can run the environment fully managed, self-managed with support on hand, or a mix.

### Can Atlantic.Net help with migration planning?

Yes. Atlantic.Net provides migration assistance and deployment support, with the scope agreed during deployment planning, so the cutover is planned and predictable. The aim is to move workloads onto the new environment with the sequence, windows, and responsibilities settled up front.

### How do I request a custom enterprise quote?

Start with a short discovery conversation. Tell us about your workloads, compliance obligations, performance targets, and constraints, and an Atlantic.Net specialist will propose an architecture and a custom quote scoped to it.

## Speak with an Enterprise Specialist

If a standard plan does not fit, the next step is a conversation. Tell us what the workload has to do, where it has to run, and what it has to comply with, and Atlantic.Net will design an environment around it, then deploy and support it with US-based engineers.

Call Us: 866-618-3282

Atlantic.Net: Secure Cloud Hosting & Infrastructure Since 1994.

## Cloud Availability in Multiple Global Regions

Deploy close to your users from eight international data centers worldwide, with new regions on the way.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Low-Latency Hosting for Performance-Sensitive Applications

> URL: https://www.atlantic.net/low-latency-hosting/ | Updated: 2026-09-16

Place cloud, dedicated, bare metal, and colocation infrastructure closer to your users, data, partners, and systems to shorten round-trip time and keep performance predictable under load.

- 8 Regional Locations
- Cloud, Dedicated, Bare Metal & Colocation
- Private Networking & VPC
- 24/7/365 US-Based Support

Regional Locations: 8

Uptime SLA: 100%

In many applications, the slowest part is the distance the data travels. Every request that crosses the country and back adds milliseconds, and those milliseconds add up across a checkout, an API call chain, a trading decision, or a video stream. Past a certain point, a faster server does not help; the path itself has to be shorter.

Atlantic.Net helps you shorten that path. We host on cloud, dedicated, and bare metal infrastructure, and on colocation, across data center regions in North America, Europe, and Asia, so you can place workloads closer to the people and systems that depend on them. The right choice depends on where your users are, where your data must live, and how traffic flows, so we start with the workload and wrap the infrastructure around it.

## What Is Low-Latency Hosting?

Low-latency hosting is infrastructure positioned and configured to reduce the round-trip time between an application and whoever, or whatever, talks to it: end users, partner systems, APIs, data sources, or other parts of the same platform. It combines two things: physical placement, putting the workload in a region close to its traffic, and a clean infrastructure design, dedicated resources, and private networking so performance stays predictable under load.

You choose a region near the traffic that matters most, so a single distant location does not serve everything. Atlantic.Net supports this across [cloud servers](https://www.atlantic.net/cloud-platform/), [dedicated and bare-metal](https://www.atlantic.net/dedicated-server-hosting/), and colocation, so you can fit the model to the workload.

## Reduce Distance Between Applications, Users, and Data

Latency comes from several places, and good placement addresses the largest one: physical distance. When you host near the traffic that matters, the gains are structural, not incremental tweaks.

### Closer to users

place the workload in the region where most of your users are, so requests travel a shorter distance.

### Closer to data

keep compute resources near the data they process, which is especially important for noisy databases and analytics workloads.

### Closer to partners and systems

position near the exchanges, APIs, or partner systems your application talks to most.

### Cleaner internal paths

connect your own tiers via private networking so traffic between them does not detour through the public internet.

The result is infrastructure designed to reduce latency for your specific traffic pattern. The exact numbers depend on your users, your routes, and your application, which is what an assessment works out.

## What's Included

### Regional Placement Strategy

Choose where each workload runs from data center regions across North America, Europe, and Asia. Placement is determined by workload, based on where your traffic concentrates and where your data must reside.

### Cloud, Dedicated, Bare Metal, and Colocation

Match the infrastructure model to the performance need: cloud for flexibility; dedicated and bare-metal for isolated, predictable performance; and colocation when you want to place your own hardware in our facilities.

### Dedicated Resources for Predictable Performance

Single-tenant cloud hosts and bare metal remove contention for CPU, memory, and disk, so response times stay steady even when a shared neighbor's load would otherwise cause them to fluctuate.

### Private Networking and VPC

Connect application, database, and cache tiers over private networking and VPC isolation, keeping internal traffic on a private path for both performance and security.

### High-Throughput Networking

For workloads that move a lot of data fast, dedicated servers support 10Gbps SFP+ and 25Gbps SFP28 uplinks, the networking used for high-throughput AdTech, real-time bidding, and trading-adjacent infrastructure.

### Hybrid Designs

Combine cloud flexibility with dedicated performance: a latency-sensitive tier on bare metal, elastic capacity on cloud, connected over private networking.

### Custom Architecture Planning

For multi-region or unusual topologies, the team helps plan placement, routing, redundancy, and data residency before anything is deployed.

### Performance-Focused Deployment Review

Before go-live, Atlantic.Net engineers review the deployment against your performance goals and recommend adjustments to the region, model, and networking.

## Choose the Right Hosting Region and Infrastructure Model

Two decisions shape the outcome: which region, and which infrastructure model. Region is about the distance to your traffic; model is about how predictable the performance needs to be.

| Region | Useful Proximity |
| --- | --- |
| New York | The Northeast corridor and financial-sector systems near Manhattan |
| Ashburn, VA | Northern Virginia's dense interconnection and East Coast routing |
| Dallas, TX | Central US, balancing coast-to-coast reach |
| Orlando, FL | The Southeast US |
| San Francisco, CA | The West Coast and Silicon Valley |
| Toronto | Canadian users and data-residency needs |
| London | The UK and Western Europe |
| Singapore | Southeast Asia and the wider APAC region |

On the model: choose cloud for flexible, fast-scaling workloads; dedicated or bare metal when you need isolated, consistent performance; and colocation when you want to run your own hardware in a well-connected facility. Many performance-sensitive deployments combine a region close to users with dedicated resources to ensure predictability.

## Business Outcomes

### Responsiveness Where It Counts

Placing workloads near their traffic shortens the longest part of many requests. Applications feel faster to the users and systems that matter most.

### Placement Matched to Your Users and Data

Per-workload region selection lets you balance performance against data residency and routing requirements, so a single location no longer has to serve everything.

### Predictable Performance Under Load

Dedicated resources and private networking keep response times steady as traffic climbs, so performance does not degrade at the exact moment it matters.

### A Path That Scales

Start in one region and expand to others, or shift from cloud to dedicated, as traffic grows. The architecture is planned so that growth does not mean a rebuild.

## Who Needs Low-Latency Hosting

| Workload | Why Proximity Helps |
| --- | --- |
| SaaS platforms and APIs | Faster response for users and the systems calling your endpoints. |
| E-commerce stores | Quicker page loads and checkout for a concentrated user base. |
| Media and streaming | Lower start-up delay and steadier delivery for nearby viewers. |
| Gaming-adjacent services | Reduced round-trip times for matchmaking, state, and session services. |
| AdTech and real-time bidding | High-throughput networking near exchanges for faster bid cycles. |
| Analytics and data processing | Compute is placed near the data it reads, reducing transfer time. |
| Healthcare applications | Regional placement with data residency inside HIPAA-ready environments. |

## A Platform You Can Trust

Atlantic.Net has operated data center infrastructure since 1994 and runs performance-sensitive workloads, from high-traffic sites to trading-adjacent systems, on the same audited platform.

### Cloud, dedicated, bare metal, and colocation

under one provider.

### 100% Uptime SLA

hardware, and power.

### 24/7/365 US-based support

by phone, email, and chat, never outsourced.

### Data center regions across North America, Europe, and Asia

including New York, Ashburn, Dallas, Orlando, San Francisco, Toronto, London, and Singapore.

### SOC 2 Type II, SOC 3 Type II, HIPAA, HITECH, PCI DSS 4.0, and NIST 800-53

audited environments.

### Atlantic.Net since 1994

32 years operating network infrastructure.

## Frequently Asked Questions

### What is low-latency hosting?

Low-latency hosting is infrastructure positioned and configured to reduce the round-trip time between an application and the users, systems, or data it communicates with. It combines physical placement, hosting near the relevant traffic, with a clean design that uses dedicated resources and private networking to keep performance predictable. Atlantic.Net provides it across cloud, dedicated, bare-metal, and colocation options.

### What is proximity hosting?

Proximity hosting is the placement side of low-latency hosting: choosing a data center region close to the users, partners, exchanges, or data sources that matter most, so one distant location does not serve everything. Shorter physical distance is usually the largest single factor in round-trip time, so placement is where the biggest gains tend to come from.

### How do I choose the best hosting location?

Start with where your traffic concentrates, where your data is allowed to live, and which systems your application talks to most. Atlantic.Net offers regions across North America, Europe, and Asia, and a proximity assessment maps your traffic and requirements to the regions and infrastructure model that best fit.

### Can Atlantic.Net guarantee a specific latency?

No, and any provider that promises an exact number for your traffic without measuring it should be treated with caution. Real-world latency depends on your users' locations, network routing, your application design, and the path between systems, much of which sits outside any single host's control. What Atlantic.Net does is design infrastructure to reduce latency by placing workloads close to their traffic, using dedicated resources and private networking, and validating it against your goals during the assessment.

### Is dedicated hosting better for low-latency workloads?

It often is, because single-tenant dedicated and bare metal servers remove contention for CPU, memory, and disk, which keeps performance predictable under load. Cloud hosting can also work well, especially when flexibility matters, and many deployments use a hybrid: dedicated for the latency-sensitive tier, cloud for elastic capacity.

### Can proximity hosting help SaaS or e-commerce applications?

Yes. Both benefit when the application sits close to its users: SaaS platforms see faster API and dashboard response, and e-commerce stores see quicker page loads and checkout. For a geographically concentrated audience, choosing the nearest region is one of the simplest performance improvements available.

### Can Atlantic.Net support hybrid low-latency deployments?

Yes. You can combine a latency-sensitive tier on dedicated or bare metal with elastic cloud capacity, connected over private networking, and place components in different regions where it helps. The team plans the topology so that placement, routing, and redundancy fit the workload.

## Request a Proximity Assessment

Tell us where your users are, where your data has to live, and which systems your application depends on, and an Atlantic.Net specialist will recommend the regions, infrastructure model, and networking designed to reduce latency for your workload. No guesswork, and no promised numbers we cannot stand behind.

Atlantic.Net: Secure Cloud Hosting & Infrastructure Since 1994.

[Call Us: 866-618-3282](tel:+18666183282)

## Cloud Availability in Multiple Global Regions

Deploy close to your users from eight international data centers worldwide, with new regions on the way.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Unmetered Dedicated Server Hosting Guide for 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/unmetered-dedicated-server-hosting/ | Published: 2026-07-10 | Updated: 2026-06-26 | Author: Dr. Assad Abbas

Unmetered dedicated server hosting refers to a physical server assigned to a single customer, with network transfer based on a fixed port speed rather than a strict monthly data quota. In this model, traffic is limited by the assigned port speed, such as 1 Gbps or 10 Gbps, rather than billed per GB or TB under normal use.

Unmetered dedicated server hosting helps bandwidth-heavy businesses control monthly costs by using dedicated bare metal hardware and a fixed network port for large data transfers. It is relevant in 2026 because many websites, SaaS platforms, media services, game servers, VPN networks, and data pipelines need steady throughput and reliable infrastructure.

For regulated workloads, such as healthcare systems handling [electronic Protected Health Information (ePHI)](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/), unmetered dedicated servers can also be used when proper security and compliance controls are in place. Therefore, buyers should compare port speed, CPU, RAM, storage, DDoS protection, network quality, management level, and monthly price before choosing a plan.

## Benefits of Unmetered Dedicated Server Hosting

Unmetered dedicated servers are suitable when bandwidth demand is high or difficult to predict. In a metered hosting plan, the server usually includes a fixed monthly transfer limit, such as 10 TB, 20 TB, or 50 TB. If traffic exceeds that limit, the provider may charge extra fees, reduce speed, or require a larger plan.

In contrast, unmetered hosting is based on server configuration and network port speed (e.g., 1 Gbps or 10 Gbps) rather than a fixed monthly transfer quota. Under normal use, data transfer is not billed per GB or TB. Therefore, this model provides several practical benefits:

- **Cost predictability:** Organizations can plan monthly hosting expenses with greater accuracy because normal data transfer is not measured against a fixed monthly quota. This is important for services with seasonal traffic, frequent downloads, regular backups, or changing user activity.
- **Reduced exposure to overage charges:** High-traffic workloads are less likely to create sudden bandwidth charges when transfer volume increases. This gives businesses greater financial stability when traffic increases due to campaigns, software releases, media delivery, or backup activity.
- **Stable resource allocation:** A dedicated server allocates CPU, RAM, storage, and network capacity to a single customer. This reduces resource competition and improves performance consistency for applications that need steady throughput.
- **Stronger capacity planning:** Buyers can select port speed, hardware resources, storage type, and management options according to expected transfer volume. This makes it easier to plan infrastructure for sustained traffic instead of reacting to monthly bandwidth limits.

## Unmetered Bandwidth Versus Unlimited Bandwidth

Unmetered bandwidth and unlimited bandwidth may sound similar, but they describe different hosting models. The difference matters because each model can affect billing, throughput, traffic control, and provider policy.

Unmetered bandwidth means that data transfer is not billed against a fixed monthly quota under normal use. Instead, the service is limited by the assigned network port speed, such as 1 Gbps or 10 Gbps. A server with a 1 Gbps unmetered port can transfer large amounts of data over the course of a month, but it cannot exceed that port’s capacity.

Unlimited bandwidth usually means that the provider does not advertise a fixed monthly data cap. Fair-use rules, shared network capacity, throttling policies, or account review may still limit the service. Therefore, buyers should not assume that unlimited bandwidth means unrestricted transfers.

The difference between the two concepts is that unmetered bandwidth has a defined technical limit, while unlimited bandwidth often depends more on provider policy. With unmetered bandwidth, buyers can review the port speed and estimate practical throughput before ordering a plan. With unlimited bandwidth, buyers should read the acceptable use policy carefully, as the actual limits may be less clearly stated.

Therefore, unmetered bandwidth should be understood as port-speed-based transfer, not unlimited data transfer without technical or policy limits.

## Metered Dedicated Servers Compared with Unmetered Servers

The choice between a metered and an unmetered dedicated server depends mainly on traffic volume, traffic patterns, and billing risk. Both models can be useful, but they are not designed for the same type of workload.

### When a Metered Dedicated Server Makes Sense

A metered dedicated server can be suitable when the monthly data transfer is stable and easy to estimate. For example, a business website, internal application, or smaller download service may use a similar amount of bandwidth each month. In such cases, a fixed monthly transfer quota may be enough.

This model becomes less suitable when traffic changes quickly. For example, a software release, a media campaign, a backup migration, or a sudden increase in users can exceed the included bandwidth quota. The provider may then charge overage fees, reduce speed, or require a larger plan. Therefore, metered hosting works best when the buyer can estimate the monthly transfer with reasonable accuracy.

### When an Unmetered Dedicated Server Is Better

An unmetered dedicated server is more suitable when traffic is heavy, variable, or difficult to predict. In this model, the main limit is the network port speed. The customer pays for a server with a fixed port, such as 1 Gbps or 10 Gbps, and normal transfer is not billed per GB or TB.

This structure is useful for workloads that regularly move large amounts of data. For example, streaming platforms, VPN services, CDN origins, backup systems, analytics pipelines, media libraries, and large-file delivery services often need steady bandwidth. Unmetered hosting can make monthly cost planning easier for these bandwidth-heavy services.

### What Buyers Should Compare

Unmetered hosting can reduce uncertainty in bandwidth billing, but it does not remove all technical or policy limits. Server performance is still affected by port speed, routing quality, hardware capacity, DDoS rules, and the provider’s acceptable use policy. Therefore, buyers should not base their decision solely on the monthly price.

For metered plans, the most important details are the monthly transfer quota, the overage rate, and the provider’s policy after the quota is used. For unmetered plans, buyers should review the port speed, network quality, fair-use terms, DDoS protection, and any speed control policy. These factors determine whether the plan can support expected traffic without unexpected cost or performance problems.

The following table summarizes the main decision factors:

Table 1: Comparison of Metered and Unmetered Dedicated Server Billing Models

| **Decision Factor** | **Metered Dedicated Server** | **Unmetered Dedicated Server** |
| --- | --- | --- |
| **Billing basis** | Fixed monthly data transfer quota | Fixed network port speed |
| **Common limit** | Total monthly transfer, such as 10 TB or 50 TB | Port speed, such as 1 Gbps or 10 Gbps |
| **Cost concern** | Overage charges after quota use | Higher fixed cost, but fewer transfer surprises |
| **Best fit** | Workloads with stable and predictable traffic | Workloads with heavy, variable, or continuous traffic |
| **Possible provider action** | Extra fees, speed reduction, or plan upgrade | Fair-use review or speed control if the policy is violated |
| **The buyer should check** | Monthly quota, overage rate, and quota policy | Port speed, network quality, and acceptable use terms |

In practical terms, metered hosting is preferable when bandwidth usage is predictable and unlikely to exceed the included quota. In contrast, unmetered hosting is better when the workload needs steady data transfer and clearer monthly cost planning.

## Unmetered Dedicated Server Plans and Pricing

Unmetered dedicated server plans vary by hardware capacity, network port speed, storage type, DDoS protection, management level, data center location, and optional services. Therefore, buyers should compare plan tiers carefully and review the current rate card or configuration builder before selecting a server. A useful way to evaluate these plans is to group them by workload size and performance demand. This helps buyers compare entry-level, mid-tier, and enterprise-tier configurations according to expected traffic, resource needs, and budget.

Entry-level unmetered servers are suitable for smaller hosting projects, development environments, modest media delivery, and lower-volume downloads. These plans usually focus on cost control while still providing a dedicated physical server and predictable bandwidth use. A common entry-level configuration may include 4 to 8 CPU cores, 16 GB to 64 GB of RAM, a 1 Gbps unmetered port, and a SATA SSD or entry-level NVMe storage.

For workloads that need more processing capacity and higher transfer volume, mid-tier unmetered servers are more suitable. These plans are useful for SaaS platforms, game hosting, analytics nodes, streaming libraries, and busy websites. A typical mid-tier configuration may include 8 to 24 CPU cores, 64 GB to 256 GB RAM, NVMe storage, RAID 1 or RAID 10, and a 1 Gbps to 10 Gbps unmetered port.

At the highest traffic levels, enterprise-tier unmetered servers offer greater hardware capacity and more reliable network options. These plans are intended for CDN origins, VPN platforms, large-file distribution, AI data movement, analytics pipelines, and high-traffic media services. A typical enterprise configuration may include AMD EPYC or Intel Xeon Scalable CPUs, 256 GB RAM to 1 TB or more, enterprise NVMe arrays, advanced DDoS mitigation, private networking, and 10 Gbps, 25 Gbps, 40 Gbps, or custom port options.

Table 2: Common Unmetered Dedicated Server Plan Tiers and Workload Use

| **Plan Tier** | **Typical Resources** | **Port Speed** | **Suitable Workloads** |
| --- | --- | --- | --- |
| Entry-level | 4 to 8 CPU cores, 16 GB to 64 GB RAM, SATA SSD or entry NVMe storage | Usually, 1 Gbps | Small websites, simple file delivery, backups, development environments, and modest media delivery |
| Mid-tier | 8 to 24 CPU cores, 64 GB to 256 GB RAM, NVMe storage, RAID 1 or RAID 10 | 1 Gbps to 10 Gbps | SaaS platforms, game hosting, streaming libraries, analytics nodes, and busy websites |
| Enterprise-tier | AMD EPYC or Intel Xeon Scalable CPUs, 256 GB to 1 TB+ RAM, enterprise NVMe arrays | 10 Gbps, 25 Gbps, 40 Gbps, or custom port options | CDN origins, VPN platforms, large-file distribution, AI data movement, and business-critical workloads |

The billing model also affects budget planning and deployment planning. Monthly billing is common for unmetered dedicated servers because it provides predictable costs for long-running production workloads. In contrast, hourly billing may be suitable for testing, migration, temporary workloads, or performance validation before a longer commitment.

Optional services can also change the final cost. These may include additional IPv4 or IPv6 addresses, reverse DNS, managed backups, snapshots, DDoS upgrades, control panels, private networking, managed firewall service, and technical support. Therefore, buyers should compare these items with the base server price to understand the total deployment cost.

Organizations comparing unmetered dedicated server plans should also review data center locations, management options, network features, and custom configuration choices before selecting a provider. This is important because the base server price may not reflect the full cost or operational value of the deployment.

For businesses that need dedicated hardware, predictable infrastructure, and performance-sensitive deployments, [Atlantic.Net](http://www.atlantic.net) offers dedicated server and bare metal hosting options. Buyers with custom bandwidth, compliance, or management requirements can request a tailored configuration before deployment.

## Common Use Cases for Unmetered Dedicated Server Hosting

Unmetered dedicated server hosting is most useful when data transfer is high, continuous, or difficult to predict. These workloads often require predictable bandwidth costs, stable server resources, and sufficient network capacity to sustain traffic.

### Streaming, Media Delivery, and Large-File Distribution

Streaming platforms, media libraries, software download sites, and CDN-style services can consume large amounts of bandwidth every month. Video files, audio content, images, software patches, backup images, and public mirrors often create steady outbound traffic. In these cases, an unmetered dedicated server can make bandwidth planning more predictable because transfer is based on port speed rather than a fixed monthly data quota.

### Game Hosting, VPNs, and Proxy Services

Game hosting, VPN platforms, and proxy services need reliable network performance. Game servers require low latency, regional data center placement, DDoS protection, and stable CPU performance. Similarly, VPN and proxy services require steady throughput, clean routing, IP planning, and clear acceptable-use terms. Therefore, buyers should review port speed, network quality, DDoS protection, and provider policy before deploying these workloads.

### Big Data, Analytics, and AI Data Movement

Big data, analytics, and AI workloads often involve large data transfer between storage, compute, and reporting systems. Common transfer activities include data ingestion, ETL jobs, log movement, database migration, model file transfer, checkpoint storage, and movement of processed datasets. Unmetered dedicated servers can help these teams control bandwidth costs while using dedicated hardware for sustained transfer and processing tasks.

## Deployment, Migration, and Monitoring for Unmetered Dedicated Servers

After selecting an unmetered dedicated server, deployment should follow a clear and practical sequence. The aim is to confirm that the selected server, port speed, and network path can support production traffic before the workload is moved.

### Step 1: Review Traffic and Workload Requirements

Deployment should begin with a review of actual and expected traffic. Buyers should check monthly data transfer, peak usage periods, traffic regions, file sizes, concurrent users, and expected growth. This helps confirm whether the selected port speed and server capacity are suitable for the workload.

### Step 2: Validate Hardware and Network Capacity

Once traffic needs are clear, the server hardware and network path should be checked together. CPU performance, RAM size, disk I/O, RAID configuration, NIC capacity, latency, packet loss, and routing stability can all affect real throughput. A high-speed port may not deliver expected results if storage, processing, or network quality becomes a bottleneck.

### Step 3: Plan the Migration

Migration should follow a controlled process. The team should create a system inventory, take backups, test restore procedures, synchronize data, test the new server environment, plan DNS updates, complete the final data sync, and then move production traffic. This reduces downtime and lowers the risk of data loss.

### Step 4: Set Backup and Monitoring Controls

After migration, backup and monitoring controls should be active. Backup planning should include frequency, retention, offsite storage, restore testing, Recovery Point Objective (RPO), and Recovery Time Objective (RTO). Monitoring should track CPU, memory, disk I/O, network throughput, packet loss, uptime, backup status, login activity, and security events.

## FAQs About Unmetered Dedicated Servers

#### *Does unmetered mean unlimited?*

No. Unmetered means that data transfer is not billed against a fixed monthly quota under normal use. The server is still limited by port speed, hardware capacity, network policy, and acceptable use terms.

#### *What is the difference between port speed and monthly throughput?*

Port speed is the maximum network rate available at a given time, such as 1 Gbps or 10 Gbps. Monthly throughput is the total amount of data transferred during the billing period.

#### *Can multiple websites run on one unmetered dedicated server?*

Yes. A dedicated server can host multiple websites or applications if CPU, RAM, storage, IP allocation, licensing, isolation, and security controls are planned correctly.

What is the risk of fair-use policies?

*Fair-use policies can limit usage that affects network stability or violates acceptable use terms.* In such cases, a provider may reduce speed, request an upgrade, or review the account.

## The Bottom Line

Unmetered dedicated server hosting is a practical option for workloads with high, variable, or difficult-to-predict bandwidth use. It helps organizations plan monthly transfer costs more clearly while using dedicated hardware and a fixed network port. The term “*unmetered*” should be reviewed carefully, as actual performance still depends on CPU capacity, RAM, storage speed, port size, network quality, DDoS protection, and support level. Therefore, buyers should choose a plan based on measured traffic needs, expected growth, and the provider’s actual network and service terms.


---

# Cloud Elasticity in 2026: Benefits & Use Cases

> URL: https://www.atlantic.net/cloud-platform/cloud-elasticity/ | Published: 2026-07-11 | Updated: 2026-06-26 | Author: Dr. Assad Abbas

Cloud workload demand is rarely constant in modern computing environments. A Web application may receive moderate traffic at certain times and much heavier traffic during peak periods, while usage may decline late at night. Similarly, analytics and AI workloads often require high compute capacity only for limited durations. Therefore, fixed infrastructure often results in either idle resources or performance constraints.

[Cloud elasticity](https://azure.microsoft.com/en-us/resources/cloud-computing-dictionary/what-is-elastic-computing) has therefore become an important concept in modern cloud computing. Its relevance has grown further in 2026 because many organizations now operate SaaS platforms, public APIs, and data-intensive applications with variable usage patterns. In such environments, infrastructure must respond to changing demand with greater flexibility.

Earlier approaches to managing variable workload demand often relied on provisioning infrastructure for peak demand. Although this practice reduced the risk of service disruption, it resulted in long periods of underuse. In contrast, limiting infrastructure helped control spending, but it frequently caused performance problems during busy periods. Cloud platforms addressed this limitation by enabling cloud elasticity, which provides a more adaptive model of resource management. The following section defines cloud elasticity more clearly and explains its significance within cloud computing.

## Cloud Elasticity Definition

In practical terms, cloud elasticity means that infrastructure resources can scale up or down in response to variations in workload demand. In such cases, compute, memory, storage, and network capacity are adjusted to meet current requirements. Therefore, resource allocation remains more closely aligned with actual workload needs.

The term elastic cloud computing is often used in the same sense as cloud elasticity. Both terms describe an environment in which resources can change over a short period rather than remain at a predefined level. This distinction is important because elasticity includes both expansion and reduction. It refers not only to increasing capacity during busy periods, but also to reducing capacity when demand declines.

Within cloud computing, elasticity supports resource management rather than static capacity planning. Traditional infrastructure usually depends on predefined capacity that remains active regardless of actual usage. In contrast, cloud environments support faster provisioning and deprovisioning of resources. Resource capacity can be increased or reduced with fewer delays as workload demand changes. This flexibility is made possible by resource allocation, automation, and demand-based provisioning. It also fits pay-as-you-go pricing, in which costs correspond more closely to actual resource consumption.

It is important to distinguish cloud elasticity from cloud scalability. Cloud elasticity refers to short-term resource adjustment in response to changing demand. In contrast, cloud scalability refers to the ability of a system to support growth in workload over a longer period. Therefore, elasticity addresses variation over time, whereas scalability refers to broader capacity growth.

## Why Cloud Elasticity Matters?

Cloud elasticity is important because it provides organizations with a practical way to manage fluctuating demand without compromising service quality. In modern cloud environments, many applications support user access, transactions, analytics, and other time-sensitive operations. When resource capacity cannot respond appropriately to demand variation, service continuity and operations may be affected. Cloud elasticity has become important in environments that depend on stable digital services.

Its importance is also evident in application performance. If resource capacity does not correspond to workload intensity, systems may experience slower response times, reduced availability, and weaker performance. In contrast, when capacity can be adjusted in accordance with workload conditions, the operating environment becomes more stable. Therefore, cloud elasticity contributes to more consistent service performance during periods of demand variation.

Cloud elasticity is also important for cost because infrastructure spending should reflect actual workload demand. When capacity is maintained primarily for peak demand, substantial resources may remain underused during normal periods, leading to unnecessary expenditure. In contrast, when capacity is reduced only to limit spending, additional costs may arise from performance disruption, delayed processing, or emergency scaling measures. By aligning resource allocation more closely with actual workload requirements, cloud elasticity supports more infrastructure spending. Organizations can reduce waste, improve cost control, and make better use of their cloud budget.

## Key Benefits of Cloud Elasticity

The main benefits of cloud elasticity are as follows:

- Reduced Infrastructure Cost
 With cloud elasticity, resource capacity can be adjusted to match workload demand, reducing unnecessary spending during routine periods.
- Improved Service Reliability
 Elastic scaling makes additional capacity available during periods of higher demand. Applications are less likely to experience overload or service interruption.
- More Stable Application Performance
 By aligning resource availability with workload intensity, cloud elasticity helps applications operate more consistently as demand changes.
- Faster Resource Provisioning
 Elastic environments enable faster provisioning of infrastructure for testing, staging, deployment, and temporary workloads.
- Lower Administrative Burden
 Automation within cloud elasticity reduces the need for repeated manual resource adjustment, allowing operations teams to manage infrastructure more efficiently.
- Greater Flexibility for Temporary Workloads
 Cloud elasticity supports pilot projects, short-term tasks, and experimental deployments without requiring permanent excess capacity.

## Cloud Elasticity Through Autoscaling, Monitoring, and Triggers

The benefits discussed above depend on the operational process by which cloud elasticity is implemented. In cloud environments, this process is based mainly on [autoscaling](https://www.vmware.com/topics/auto-scaling). Under autoscaling, infrastructure resources increase or decrease according to predefined policies, observed metrics, and current workload conditions. Accordingly, cloud elasticity depends not only on the addition or reduction of capacity but also on the rules that determine when such changes should occur. The main components of the autoscaling process in cloud elasticity are discussed below.

### Reactive and Predictive Autoscaling

Autoscaling commonly follows two approaches. The first is [reactive autoscaling](https://arxiv.org/html/2510.10166v1), in which the system responds after a threshold has been exceeded. For example, additional instances may be provisioned when CPU utilization exceeds a defined threshold for a fixed period. This approach is appropriate when scaling decisions must follow actual workload changes.

The second approach is predictive autoscaling. In this case, historical workload patterns are used to plan capacity ahead of an expected increase in demand. This is useful in environments with recurring activity, such as monthly processing, scheduled campaigns, or routine reporting periods. Predictive autoscaling can reduce response delays when periods of higher demand are already anticipated.

The difference between the two approaches lies mainly in timing. Reactive scaling responds after demand has increased, whereas predictive autoscaling prepares capacity in advance. Therefore, the choice depends on workload regularity, traffic patterns, and service requirements.

### Monitoring, Metrics, and Triggers

Cloud elasticity also depends on continuous monitoring, as resource adjustments must reflect current workload conditions. Monitoring systems collect data from servers, virtual machines, [containers](https://www.atlantic.net/cloud-platform/cloud-containers/), databases, applications, and network components. This data is then evaluated against scaling policies. When a measured condition matches a policy rule, the system initiates the required scaling action.

These decisions rely on measurable indicators such as CPU utilization, memory usage, network traffic, request rate, queue length, and response time. In some environments, workload-specific indicators such as active users, API requests, or transaction volume are also included. Once these metrics cross defined thresholds, they act as scaling triggers. Therefore, threshold selection is important. If thresholds are set too low, repeated scaling may occur within short intervals. In contrast, if they are set too high, the response may begin too late. In addition, separate scale-out and scale-in rules, along with cooldown periods, further support stable threshold-based scaling by reducing unnecessary or repeated adjustments.

### Capacity Adjustment Mechanisms

Once a scaling rule has been triggered, the environment must determine the form through which capacity will be adjusted. One common method is [horizontal scaling](https://www.geeksforgeeks.org/system-design/system-design-horizontal-and-vertical-scaling/), which involves adding or removing instances and is often suitable for distributed applications and microservice architectures. A second method is vertical scaling, which changes the capacity of a single instance and is better suited to workloads that are difficult to distribute across multiple machines.

Another option is serverless rapid elasticity, in which the platform adjusts capacity automatically without direct server management by the user. This model is useful for event-driven functions, bursty APIs, and temporary processing tasks. In this way, cloud elasticity operates through a connected process in which monitoring, threshold-based triggers, and capacity adjustment work together.

## Real-World Use Cases

Common use cases of cloud elasticity include the following:

- E-commerce platforms

Online retail systems often experience sharp increases in traffic during flash sales, holiday campaigns, and promotional events. In such periods, cloud elasticity helps increase capacity quickly and reduce it again after demand falls.

- SaaS applications

SaaS platforms often face demand variation across regions, user activity levels, and time periods. Cloud elasticity helps these applications maintain more stable performance without always requiring fixed high capacity.

- AI and analytics workloads

AI training, inference, and batch analytics often require high compute capacity for limited durations. Cloud elasticity is useful in these cases because it enables temporary resource expansion in response to processing demand.

- Development and testing environments

Development, testing, and staging workloads do not always require full infrastructure capacity throughout the day. Cloud elasticity provides temporary resources when needed and scales them down during inactive periods.

These cases show that cloud elasticity is relevant in environments where workload demand varies over time and infrastructure must respond efficiently and under control.

## Implementing Elastic Cloud Computing Effectively

The effectiveness of cloud elasticity requires attention to the following areas:

- Policy design

Teams should first examine workload behavior before defining autoscaling rules. Minimum and maximum capacities, scale-out conditions, scale-in conditions, and cooldown periods should be specified in advance. In addition, the choice between reactive and predictive autoscaling should be based on workload needs.

- Infrastructure selection and configuration

The selected cloud provider should support autoscaling, monitoring, and load balancing. It should also support the required resource model, such as virtual machines, containers, or serverless services. After selection, the environment should be configured consistently through templates, health checks, and load balancers. Where regulated workloads are involved, compliance requirements should also be reviewed at this stage.

- Testing before production use

Load testing is necessary to verify that scaling rules respond at the correct time and that new capacity becomes available without excessive delay. It also helps identify unstable scaling behavior and poorly configured thresholds. Therefore, it should be treated as a planned process rather than a purely technical setup.

## Challenges, Security, and Best Practices

Though cloud elasticity improves resource management, it also introduces technical and operational concerns. These concerns should be addressed carefully so that scaling actions improve service quality rather than create instability.

### Common Challenges

- Provisioning delays can reduce the effectiveness of elastic scaling because new capacity may become available only after demand has already begun to affect application performance.
- Weak threshold design can make elasticity-driven scaling behavior unstable because inaccurate values may lead to repeated scaling, delayed response, or unnecessary infrastructure cost.
- Heavy reliance on provider-specific services can limit the flexibility of elastic environments because migration, redesign, or multi-environment management may become more difficult.

### Security Considerations

Security requires consistent attention in elastic environments because resource capacity changes continuously, and temporary instances may appear and disappear within short periods. The following considerations are particularly important:

- Short-lived resources should follow the same security standards as long-running resources because temporary instances can still pose risks related to access control, patching, and configuration.
- Data in transit should use TLS throughout the environment to ensure communication remains protected during both routine operations and scaling activities.
- Identity and access policies should be applied consistently to both new and existing resources because elastic environments frequently create and remove capacity.
- Logs, metrics, and traces should be preserved across temporary resources to prevent scaling events from reducing operational visibility.

### Best Practices

Effective cloud elasticity depends on disciplined operational practice. Scaling rules alone are not sufficient unless they are tested, reviewed, and monitored over time. To support more stable and manageable elastic environments, the following practices are recommended:

- Scaling policies should be tested before production use because load testing can identify delayed responses, unstable thresholds, and configuration errors.
- Thresholds and cooldown settings should be reviewed regularly because workload behavior may change over time, and earlier values may no longer remain appropriate.
- Alerts should be configured for failed scaling events, rising latency, queue buildup, and abnormal cost growth because early detection improves operational control and reduces the risk of larger service problems.

## The Bottom Line

Cloud elasticity has become a practical requirement for digital systems that operate under changing demand. It offers organizations a more disciplined way to balance performance, cost, and operational control without relying on fixed capacity or repeated manual adjustment. In 2026, its value extends beyond technical, as it enables cloud environments to respond with greater precision and stability. As a result, cloud elasticity is now an essential part of effective and reliable infrastructure management.


---

# What Is IPMI? Intelligent Platform Management Interface Explained in 2026

> URL: https://www.atlantic.net/cloud-platform/what-is-ipmi/ | Published: 2026-07-12 | Updated: 2026-06-26 | Author: Dr. Assad Abbas

Modern data centers require reliable remote server management to maintain access, availability, and operational control. This requirement applies to[dedicated servers](https://www.atlantic.net/dedicated-server-hosting/),[bare metal hosting](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/), private cloud systems, and hybrid infrastructure. In these environments, administrators must be able to access servers even when the main system is not functioning properly. This is important because hardware faults, failed updates, boot errors, and network service failures can make normal access methods such as SSH or RDP unavailable.

When normal access is unavailable, a separate management method becomes necessary. The[Intelligent Platform Management Interface (IPMI)](https://www.intel.com/content/www/us/en/products/docs/servers/ipmi/ipmi-home.html) provides this capability through hardware-level access for remote monitoring, power control, and system recovery. IPMI helps teams respond when the main system is frozen, powered off, or unable to boot.

This type of remote management is also relevant in compliance-sensitive environments, including HIPAA-compliant hosting. In such settings, system availability, controlled administrative access, and documented recovery procedures are important. This article explains IPMI as a practical server management standard and discusses its role in improving remote access, recovery, and operational control.

## What Is Intelligent Platform Management Interface (IPMI)?

Server management can occur through two main methods:[in-band and out-of-band](https://community.spiceworks.com/t/daily-challenge-network-management-fundamentals-in-band-vs-out-of-band-oob-2026-mar-23/1251322). In-band management depends on the host operating system and its normal network services. For example, administrators may use SSH, RDP, or monitoring agents when the system is running properly.

In contrast, out-of-band management uses a separate management channel. This channel does not depend on the host operating system. Therefore, it is useful when normal access methods are unavailable.

The Intelligent Platform Management Interface (IPMI) is one of the most common hardware-based standards used for out-of-band server monitoring and management. It helps administrators check hardware status, control server power, review event logs, and access low-level management functions remotely.

IPMI works through a dedicated management component known as the Baseboard Management Controller (BMC). This design separates server management from the main operating system and normal network services. Therefore, administrators can use IPMI for low-level monitoring and control when standard management tools are insufficient.

For example, a server may freeze after a failed update, which can make SSH access unavailable and take the application offline. In this situation, IPMI gives administrators another way to check hardware status, control power, and open remote console access. This helps them investigate and recover the server without having to visit the data center.

## Main Features of IPMI

IPMI includes several management functions that help administrators monitor, control, and recover physical servers remotely. The following features are commonly used in server maintenance, troubleshooting, and low-level system recovery.

### · Sensor monitoring and reporting

IPMI provides direct access to hardware sensor data from the server platform. This includes CPU temperature, system board temperature, fan speed, voltage levels, power supply status, chassis alerts, and other hardware conditions.

### · Remote power management

IPMI includes power management controls for remote server operation. Administrators can power on, power off, reset, or power cycle a server through the management interface without physical access to the machine.

### · Hardware event logging

IPMI maintains a System Event Log for hardware-level events. This log records thermal alerts, fan failures, voltage issues, power faults, memory errors, chassis activity, and other platform events detected by the server.

### · Remote virtual media mounting

Many IPMI implementations include virtual media support. This feature lets administrators attach an ISO image remotely for operating system installation, firmware utilities, rescue environments, or system recovery.

### · Serial console redirection over LAN

IPMI supports Serial Over LAN for remote text-based console access. This feature is useful for boot diagnostics, Linux recovery, low-level troubleshooting, and headless server management.

### · Remote console access through KVM-over-IP

Many BMC-based IPMI environments provide KVM-over-IP access where the server platform supports it. This feature gives administrators remote keyboard, video, and mouse control for BIOS or UEFI settings, operating system installers, boot messages, and recovery tools.

## IPMI Architecture and the Role of the BMC

The architecture of IPMI is designed to keep server management separate from the main computing system. This separation is what makes IPMI useful for out-of-band management. Instead of depending on the host operating system, IPMI uses a dedicated hardware management layer to communicate with the server platform.

The key component in this layer is the BMC, an embedded microcontroller on the server motherboard. It operates separately from the main CPU and runs its own firmware. Through this design, the BMC can receive IPMI commands, collect hardware information, and perform management actions without relying on the host operating system.

The BMC connects to IPMI and provides several server-level functions. It communicates with hardware sensors, power controls, event logs, and management interfaces. In many servers, the BMC uses a dedicated management network port. Some platforms also provide access through a shared network interface. This gives administrators a separate path for remote monitoring, power control, and recovery.

Another important part of IPMI architecture is standby operation. The BMC can continue to function when the server is powered off, provided standby power is available. Therefore, administrators can power on the system, check sensor readings, and review hardware events even when the main system is not active.

The BMC also monitors several hardware conditions. These commonly include CPU temperature, system board temperature, fan speed, voltage levels, and power supply condition. It may also track chassis intrusion, memory error indicators, and storage backplane alerts where supported.

In addition, the BMC stores important management data in nonvolatile memory. This may include event logs, user accounts, firmware settings, and network configurations. Therefore, these settings can remain available even after the host operating system is reinstalled.

The BMC may also support additional management functions depending on the server platform. Some systems provide remote video functionality through the BMC for KVM-over-IP access. Similarly, selected enterprise, hyperscale, and research environments may use OpenBMC as an open-source BMC firmware option.

The BMC is the component that turns IPMI from a management standard into a working remote management system. It provides the hardware-level path that enables IPMI to monitor, control, and recover servers when ordinary access methods are not available.

## Accessing IPMI Remotely

After the BMC is configured, administrators can access IPMI through different management paths. The exact method depends on the server vendor, firmware version, licensing model, and network design. Most IPMI implementations support a combination of network access, browser-based management, command-line tools, Serial Over LAN, and remote console functions.

IPMI access usually begins with configuring the management network. Many servers include a dedicated IPMI management port. Some systems also support IPMI access through a shared network interface. The management interface normally requires its own IP address, subnet, gateway, DNS settings, and VLAN configuration.

IPMI should be placed on a private management network. It should not be exposed directly to the public Internet. The management interface can control server power, firmware functions, virtual media, and console access. Therefore, open access can create serious security risks.

The following table summarizes common IPMI access methods and their practical use.

Table 1: IPMI access methods and their practical use

| **Access method** | **Main purpose** | **Common use** |
| --- | --- | --- |
| Dedicated management port | Separates IPMI traffic from production traffic | Secure management network design |
| Shared network interface | Uses an existing server network interface for management | Systems with limited physical ports |
| Web GUI | Provides browser-based access to BMC functions | Power control, sensors, logs, users, and virtual media |
| ipmitool | Provides command-line access to IPMI functions | Scripts, sensor checks, event logs, and power commands |
| Serial Over LAN | Provides text-based console access | Boot diagnostics and Linux recovery |
| KVM-over-IP | Provides remote keyboard, video, and mouse access | BIOS or UEFI access, OS installation, and recovery |

Many vendors provide a browser-based interface for IPMI or BMC management, including Dell iDRAC, HPE iLO, Lenovo XClarity Controller, Cisco IMC, and Supermicro IPMI. Although these tools serve similar management purposes, they may differ in interface design, licensing, security settings, and remote console support.

Command-line access is also common through[ipmitool](https://github.com/ipmitool/ipmitool). Administrators use it to check sensors, view event logs, manage power state, and support repeatable tasks during maintenance or incident response.

For access to the server console through the management interface, Serial Over LAN provides a text-based console, while KVM-over-IP provides graphical access where supported. These options are useful during firmware configuration, operating system installation, and boot troubleshooting.

## IPMI Versions and Redfish Comparison

IPMI has changed over time, but its main purpose has remained the same. It provides a standard method for hardware-level server management. IPMI 1.5 expanded LAN-based remote management, while IPMI 2.0 added stronger session handling, Serial Over LAN, encryption options, and improved authentication mechanisms.

IPMI follows a request-and-response model. An administrator or management tool sends a command to the BMC, and the BMC returns a response. These commands cover tasks such as chassis control, power state checks, sensor readings, access to the System Event Log, user settings, and LAN configuration.

For remote management, IPMI-over-LAN uses the management network to communicate with the BMC. IPMI 1.5 used Remote Management Control Protocol, while IPMI 2.0 added RMCP+ and RAKP-based authentication. Older firmware or weak configurations may still pose security risks, so administrators should review vendor guidance before enabling remote access.

[Redfish](https://www.dmtf.org/standards/redfish) is a newer management standard that addresses many of the same needs through RESTful APIs, JSON, and HTTPS. It is better suited to modern automation and large-scale infrastructure management. Many servers still support both IPMI and Redfish. Therefore, IPMI remains important for existing systems, while Redfish is useful for newer management workflows.

## Securing the IPMI Interface

IPMI security requires careful planning because the interface provides hardware-level control over the server. A compromised BMC can affect power state, console access, firmware settings, and remote media functions. Therefore, IPMI should be protected like any other privileged administrative interface. The following practices can help reduce risk and maintain proper administrative control over IPMI access.

- Default BMC credentials should be changed during initial setup. Each server should use a strong and unique password because shared or default passwords can expose the management interface to unauthorized access.
- IPMI should run on an isolated management VLAN or private administrative network. It should not be exposed to the public Internet or mixed with general production traffic.
- Access to the IPMI interface should be limited to trusted administrator workstations, VPN users, bastion hosts, or approved internal networks. This reduces unnecessary exposure and makes access easier to control.
- BMC firmware should be updated regularly. These updates may include security patches, stability fixes, authentication improvements, and remote console updates.
- User accounts should be created with role-based permissions. Administrators should avoid shared accounts and assign only the access level required for each user.
- Multi-factor authentication should be enabled where the vendor platform or management gateway supports it. This adds protection to remote administrative access.
- Browser-based IPMI access should use data encrypted in transit using TLS. Older plugins, weak ciphers, unused services, anonymous access, and unnecessary virtual media functions should be disabled.

## Troubleshooting IPMI Access

IPMI can become unavailable due to network errors, incorrect credentials, disabled management ports, BMC firmware issues, standby power problems, or browser compatibility limitations. Therefore, troubleshooting should begin with the most basic access checks.

Administrators should confirm the management IP address, switch port status, VLAN configuration, routing, firewall rules, and access control lists. If the Web interface does not respond, command-line testing with ipmitool can help confirm whether the BMC is still reachable.

The following commands cover common IPMI checks and recovery tasks.

*ipmitool -I lanplus -H  -U  chassis power status*

*ipmitool -I lanplus -H  -U  sensor list*

*ipmitool -I lanplus -H  -U  sel list*

*ipmitool -I lanplus -H  -U  chassis power cycle*

These commands check power status, list hardware sensors, review the System Event Log, and perform a remote power cycle. The power cycle command should be used carefully because it can interrupt active workloads.

If local access to the operating system is available, administrators may reset the BMC from the host system. If the BMC firmware is corrupted or fully unresponsive, vendor recovery documentation should be followed. After recovery, the incident should be documented so that repeated network, firmware, or access problems can be corrected.

## Compatible Systems and Deployment Considerations

IPMI is most common in server environments where remote hardware control is important, including enterprise rack servers, blade servers, dedicated servers, bare metal cloud servers, HPC nodes, private cloud systems, colocation hardware, and remote edge servers. In these deployments, physical access may be limited, delayed, or managed by a separate data center team.

Although these systems follow the same general management purpose, vendor implementations can differ. Dell iDRAC, HPE iLO, Lenovo XClarity Controller, Cisco IMC, and Supermicro IPMI may vary in remote console access, virtual media support, firmware update process, licensing, and Redfish.

Deployment planning should also reflect the environment in which IPMI is used. In an on-premises data center, the organization usually controls the management network, access rules, firmware updates, and recovery procedures. Therefore, the internal IT team is responsible for securing and maintaining the BMC interface.

In a hosted bare-metal or colocation environment, some aspects of IPMI access may be managed by the provider. For example, the provider may restrict direct BMC access, offer console access through a customer portal, or handle certain recovery actions through support processes.

## Conclusion

IPMI should be viewed as part of a wider server management strategy, not only as an emergency reboot tool. Its main value becomes clear when organizations combine remote access, secure network design, firmware maintenance, and documented recovery procedures.

In 2026, IPMI still has practical importance for dedicated servers, bare-metal platforms, and private infrastructure. Administrators should treat the BMC as a sensitive management layer. A well-secured IPMI setup can reduce recovery delays, improve operational control, and support more reliable server administration.


---

# What Is Network Isolation? A Practical Guide for 2026

> URL: https://www.atlantic.net/cloud-platform/what-is-network-isolation/ | Published: 2026-07-15 | Updated: 2026-06-26 | Author: Dr. Assad Abbas

[Network isolation](https://learn.microsoft.com/en-us/security/zero-trust/sfi/network-isolation) is the practice of separating systems, users, devices, applications, and workloads into controlled network segments. Each segment follows defined rules for communication. Therefore, systems do not exchange traffic freely unless there is a clear business, operational, or technical need. The aim of network isolation is not to disconnect the entire network. Instead, it aims to create safer, more manageable communication across different parts of the IT environment.

Network isolation has become more important in 2026 because modern networks span data centers, cloud platforms, remote users, IoT devices, and third-party connections. One exposed system can pose a risk to other systems if proper boundaries are missing. Network isolation reduces this risk by limiting access paths and controlling traffic between sensitive and less sensitive areas.

This article explains what network isolation means, why it is important, and which methods organizations can use to apply it in secure IT environments.

## Network Isolation Concepts and Benefits

Network isolation is implemented using a combination of network, access, and security controls. These controls may include VLANs, subnets, Access Control Lists (ACLs), firewall rules, identity-based access, and[microsegmentation](https://www.cisco.com/site/us/en/learn/topics/security/what-is-micro-segmentation.html). In highly sensitive environments, physical separation may also be used to introduce stronger boundaries between systems.

The main purpose of network isolation is to control communication between different parts of the network. Most applications cannot operate in complete separation because they need to exchange data with users, databases, storage systems, or other services. Therefore, network isolation defines which systems can communicate, which ports they can use, and which traffic must be blocked.

These controls work at different levels of the network. A subnet divides the network by IP address range, while a VLAN separates traffic logically within shared network hardware. Subsequently, ACLs and firewall rules decide which traffic can pass between these separate areas. For example, they can allow a Web server to access an application server while blocking the same server from accessing backup storage. In this way, segments become meaningful security zones rather than only technical divisions. At a more detailed level, microsegmentation can apply similar controls to individual workloads, hosts, or applications.

Network isolation provides several practical benefits:

- **Smaller breach impact:** Network isolation reduces the damage that can result after a single system is compromised. If an attacker gains access to a user device or application, isolation limits the systems that can be reached from that entry point.
- **Stronger protection for sensitive systems:** Network isolation helps protect databases, backup repositories, identity systems, and management tools from unnecessary access. Therefore, sensitive systems are less exposed to user devices, guest networks, IoT devices, and lower-trust workloads.
- **Reduced malware and ransomware movement:** Network isolation limits the spread of malware by blocking unwanted communication between systems. Ransomware has fewer paths to reach file shares, backup systems, and other resources.
- **Better compliance and audit readiness:** Network isolation makes it easier to separate regulated systems from general business systems. It also provides clear evidence of access paths, security policies, rule ownership, and system boundaries.
- **Improved network management:** Network isolation makes it easier to monitor, troubleshoot, and manage the network. In addition, it reduces unnecessary traffic and helps teams understand which systems depend on each other.

## Methods for Implementing Network Isolation

Network isolation can be implemented through physical, virtual, logical, and workload-level controls. Most organizations use a combination of these methods because each method gives a different level of separation and control.

### Physical Isolation

Physical isolation separates systems through dedicated hardware. This may include separate switches, routers, network cards, cabling, racks, or firewall interfaces. It is commonly used for high-security workloads, storage networks, backup systems, management networks, and single-tenant environments.

For example, out-of-band management interfaces such as IPMI, iDRAC, and iLO should not be exposed to public or user-facing networks. They should be placed on a dedicated management network with strict administrative access. Similarly, backup infrastructure may need physical or strong logical separation so that compromised production systems cannot easily reach backup data.

Physical isolation provides strong separation. It can increase costs and operational workload. Therefore, it is usually used when the risk level, compliance requirement, or business impact justifies stronger controls.

### Virtual and Logical Isolation with VLANs, ACLs, and Firewalls

Virtual isolation separates traffic within the shared network infrastructure. VLANs are commonly used to separate user devices, servers, guest Wi-Fi, IoT devices, storage, backup systems, and management networks. VLANs provide limited protection if traffic can move freely between them. Therefore, ACLs should be applied per VLAN or subnet to permit only required communication.

In many environments, ACLs are supported by firewall rules to create stronger boundaries between network zones. Firewalls inspect and control traffic between these zones, defining which communication is permitted or denied. Firewall rules should be based only on required traffic. Broad rules, such as *any-to-any*, should be avoided unless there is a documented, temporary need.

For example, guest Wi-Fi may be permitted to access the internet, but it should not access internal file servers. Similarly, an application server may connect to a database only on the approved port. Administrative access should also be limited to approved users, managed devices, and approved management paths.

These controls should be reviewed and tested regularly. Teams should test both permitted paths and blocked paths. This confirms that applications work correctly and that unnecessary communication is blocked.

### Microsegmentation and Least Privilege

Microsegmentation is a more detailed form of network isolation. Instead of separating only large network zones, it applies policies between workloads, hosts, containers, applications, or endpoints. This approach is useful in data centers, cloud platforms, hybrid environments, and multi-cloud systems where workloads may change or move frequently.

Microsegmentation is based on the principle of least privilege, in which each workload communicates only with the systems required for its operation. For example, a Web server may need to communicate with an application server, but it should not access backup repositories. Similarly, a database should accept connections only from approved application servers, and development systems should not directly access production databases.

Microsegmentation policies may use user identity, service accounts, workload labels, application tags, device attributes, or device posture. This helps connect policies to workload function rather than only a fixed network location. In addition, lateral-movement simulations can help confirm that the isolation rules are working as intended.

### Planning and Deploying Network Isolation

A network isolation project should begin with planning rather than immediate firewall changes. The following structured process helps reduce errors and keeps the rollout easier to manage.

- Identify the responsible teams: network, security, compliance, DevOps, application, and business. Each network segment should have a clear purpose and a responsible owner.
- Build an asset inventory: List servers, endpoints, databases, cloud workloads, IoT devices, storage systems, backup platforms, and management interfaces. This helps teams understand what needs protection.
- Classify each asset by data sensitivity, business impact, internet exposure, compliance scope, and application dependency. This classification helps determine the level of isolation required.
- Prioritize high-risk systems: Start with business-critical and sensitive systems. These may include management networks, identity systems, databases, backup platforms, payment systems, internet-facing applications, regulated workloads, and legacy systems.
- Define required communication paths: Decide which systems must communicate with each other. Firewall rules and access control lists should permit only the minimum required access.
- Document each rule: Record the source, destination, protocol, port, purpose, owner, and review date for each rule. This makes later audits, troubleshooting, and cleanup easier.
- Use a phased rollout: Begin with a pilot segment, test application behavior, apply controls, monitor traffic, and then expand to other areas. A rollback plan should also be prepared before major changes.

## Monitoring, Logging, and Measuring Effectiveness

Network isolation should be monitored after deployment to confirm that segment boundaries work as intended. Firewalls, routers, VPN gateways, cloud security groups, and segmentation gateways should send logs to a SIEM or centralized logging platform. These logs help detect denied connections, unusual cross-segment traffic, administrative access from unknown devices, and traffic from guest or IoT networks toward sensitive systems. The number of blocked unauthorized attempts can measure the effectiveness of network isolation, the use of fewer broad firewall rules, timely rule reviews, and periodic penetration tests or lateral movement simulations.

### Real-World Applications and Use Cases

Network isolation is most useful when an organization needs to control communication between systems with different risk levels. The following use cases show where it is commonly applied and what problem it helps solve:

#### · Use case 1: Preventing development systems from affecting production.

A company may run development, testing, and production systems on the same broader infrastructure. Development systems often undergo frequent changes, have test data, and have less strict controls. Network isolation separates these environments so that a misconfigured test server or compromised developer machine cannot directly reach production applications or databases.

#### · Use case 2: Protecting backup and management systems from ransomware.

Backup repositories and management tools are high-value targets during ransomware attacks. Therefore, they should not be reachable from ordinary user devices or general application networks. By placing backup systems and administrative interfaces in isolated segments, organizations reduce the chance that a compromised endpoint can delete backups, change server settings, or access recovery data.

#### · Use case 3: Separating regulated systems from general business traffic.

A healthcare organization may operate patient portals, billing systems, internal applications, and office networks within the same broader IT environment. , these systems do not carry the same level of risk. Systems that store, process, or transmit electronic Protected Health Information (ePHI) should, where appropriate, be separated from guest networks, unmanaged devices, and general user traffic. Network isolation helps create this separation by limiting unnecessary access paths between regulated systems and lower-trust areas. If these workloads are hosted outside the organization’s own facility, a provider such as Atlantic.Net may be considered for HIPAA-compliant hosting and a[HIPAA Business Associate Agreement (BAA)](https://www.atlantic.net/what-is-baa-hipaa-business-associate-agreement/). The organization must still manage access controls, logging, user permissions, and application-level security correctly.

## Common Challenges and Mitigations

Network isolation can improve security, but it can also create management issues if it is not planned carefully. The following challenges should be addressed during design and operation:

- Challenge: Configuration drift
  - Firewall rules, ACLs, and access policies may change over time without proper review.
- Mitigation**:** Use change control, version control, automated checks, and scheduled rule reviews to keep configurations aligned with approved policies.
- Challenge: Application connectivity problems
  - Some applications depend on services that are not fully documented. New isolation rules may block required communication.
- Mitigation**:** Map traffic flows before enforcement and test changes in a staging environment before applying them to production.
- Challenge: Administrative overhead
  - Many segments, rules, and exceptions can become difficult to manage over time.
- Mitigation: Use templates, naming standards, automation, ownership records, and regular cleanup cycles.
- Challenge: Shadow IT and unknown devices
  - Unregistered devices or informal systems may create unmanaged access paths.
- Mitigation: Use asset discovery, device onboarding policies, and network access control to identify and manage unknown systems.

## Best Practices for Network Isolation

Effective network isolation depends on consistent rules, regular testing, and clear ownership. The following practices can help organizations maintain stronger and more manageable isolation over time:

- Use least privilege by default: Permit only required traffic between systems and deny unnecessary communication.
- Separate sensitive systems early: Prioritize databases, backup systems, identity services, payment systems, healthcare systems, and management networks.
- Automate rule deployment: Use templates, infrastructure-as-code, and configuration management to reduce manual errors.
- Detect configuration drift: Compare approved rules with deployed rules on a regular schedule to identify unauthorized or accidental changes.
- Test changes before production: Validate permitted traffic and blocked traffic in a controlled environment before applying new rules.
- Schedule security assessments: Use audits, penetration testing, and segmentation reviews to verify that isolation controls function as intended.

## The Bottom Line

Network isolation works best when it is planned as part of the security design, not treated only as a network setting. Organizations should begin with areas where uncontrolled access can cause serious damage, such as management networks, backup systems, databases, regulated workloads, and internet-facing applications.

After these high-risk areas are identified, the focus should move to practical control and ownership. Every segment should have a defined purpose, every rule should have an owner, and every change should be tested before production use. This is important in 2026 because infrastructure spans data centers, cloud platforms, remote users, and connected devices. Organizations that deploy isolation in phases, monitor it regularly, and keep documentation up to date can reduce risk while keeping the network manageable.


---

# Approved Scanning Vendor (ASV): PCI Compliance Guide

> URL: https://www.atlantic.net/pci-compliant-hosting/approved-scanning-vendor-asv-pci-compliance-guide/ | Published: 2026-07-17 | Author: Robert Agar

An approved scanning vendor (ASV) is a company authorized to perform external vulnerability scanning of internet-facing systems in scope for PCI DSS compliance. All ASVs must be qualified and approved by the PCI Security Standards Council (PCI SSC) to conduct this scanning role.

Companies in scope for PCI DSS compliance must have scans performed by approved ASVs. Non-approved scanning vendors do not satisfy compliance requirements and cannot be used to verify the security of a company’s internet-facing systems. Businesses can only meet PCI compliance standards by working with a qualified ASV.

## PCI Security Standards Council and PCI Approved Scanning Vendor List

The PCI SSC owns and manages the ASV program. The SSC is responsible for designing the qualification framework, setting the technical and operational standards for ASVs, testing and approving candidates, and maintaining oversight of approved ASVs.

The PCI SSC defines the rules for the ASV program in a formal document titled the [ASV Program Guide](https://docs-prv.pcisecuritystandards.org/Programs%20and%20Certification/Approved%20Scanning%20Vendor%20(ASV)/ASV-Program-Guide-v4.0r2.pdf). The guide specifies the following requirements for acceptance into the ASV program:

- What an ASV must be able to scan and the vulnerabilities it must detect;
- The technical capabilities that are necessary for the ASV’s scanning solution;
- The way ASVs must conduct vulnerability scans and interact with merchants;
- How to handle disputes between ASVs and customers;
- The business and ethical standards ASVs must meet;
- The content and format requirements of scan reports and attestations.

Businesses can find an ASV on the [PCI SSC’s ASV list](https://www.pcisecuritystandards.org/assessors_and_solutions/approved_scanning_vendors/). The list includes the ASV’s company name, place of business, the regions it serves, and email contact information.

ASV approval does not grant permanent status to the vendor. ASV status is a credential that must be earned and renewed each year. The annual requalification serves the following purposes.

- The process ensures that the ASV’s scanning solution is adequate for handling the evolving threat landscape.
- Requalification ensures that ASVs are tested against SSC’s current security testing procedures.
- The SSC reassesses the ASV organization as a whole, not just its testing procedures.
- Annual renewal maintains the integrity of the ASV program.

## How ASV Scans Support PCI DSS Compliance

PCI DSS Requirement 11.3.2 states that organizations must perform external vulnerability scans at least every three months and after any change to internet-facing systems. A PCI SSC-approved scanning vendor must perform the scans to ensure the systems are hardened to withstand public attacks. The PCI Security Standards Council requires that scans be conducted by a certified ASV at least once every three months.

In addition to the scheduled quarterly scans, companies must scan all affected components when changes are made to internet-facing systems. These changes may include adding servers, upgrading network components, and modifying firewall rules.

ASV scans play a role in PCI compliance for smaller companies that perform a Self-Assessment Questionnaire (SAQ), as well as larger organizations, whose merchant level requires a full Report on Compliance (ROC) conducted by a Qualified Security Assessor (QSA). The data contained in the scan are essential elements of SAQs and ROCs.

## Approved Scanning Vendor ASV Qualifications and ASV Company Requirements

Prospective ASVs must first be a recognized legal entity and be authorized to conduct business, then complete the registration process with the PCI Security Standards Council qualifications by having to register, submit an attestation of compliance, and provide the following documentation across multiple categories:

- Corporate and business documentation, including incorporation and insurance certificates, as well as administrative information and technical details submitted during registration;
- Documentation that demonstrates the veracity of their technical scanning solution;
- Operational policies related to scanning procedures, report templates, and dispute resolution;
- Data security and privacy policies regarding access control, encryption, and incident response;
- Legal and contractual documents, such as customer agreement templates and signed PCI SSC compliance attestations;
- Personnel qualifications, including staff credentials, training procedures, background checks, and at least two full-time employees validated to perform scanning services with relevant industry experience;
- Updated policies and solutions to support ongoing requalification.

Prospective and requalifying ASV candidates can submit scanning solutions for evaluation through remote testing against the PCI SSC’s test environment. The test infrastructure is designed to provide a controlled and repeatable method of evaluating ASV scanning solutions. The testing environment is constructed to meet the following requirements.

- Simulate a company’s vulnerable systems.
- Provide a consistent evaluation baseline.
- Evaluate the accuracy of detection and classification procedures.
- Validate that the report output meets PCI SSC format requirements.

## ASV Scan Process and ASV Scans

The ASV scanning process comprises several steps designed to identify and remediate vulnerabilities that affect the security of in-scope PCI DSS environments. Customers should expect a verified ASV to perform the following activities when conducting external vulnerability scans.

### Identify all in-scope external assets.

The initial step is to identify the internet-facing assets that must be scanned. Scan customers need to determine the scan scope across the organization’s network and internet-facing assets to avoid security and compliance gaps. Potential in-scope assets, including systems that are part of the cardholder data environment, include:

- Customer-facing websites;
- Public IP addresses;
- Payment portals;
- Cloud resources;
- Remotely accessible servers and infrastructure.

Disputes about scope, inclusion, or failed scan results must be handled directly between the scan customer and the ASV, not by the PCI SSC.

### Configure and schedule scans

The client works with their ASV to configure and schedule the scan. Internal teams must be aware of the scan timing, including after infrastructure or data security changes, to avoid mistaking it for real malicious activity. Specific aspects of the scan preparation include:

- Defining scan targets;
- Validating IP ownership;
- Configuring the scanning parameters;
- Scheduling the recurring quarterly scans to help meet PCI DSS external scanning requirements.

### Conduct external vulnerability scans.

The next step is to perform the scheduled automated external vulnerability scans that ASVs perform. The objective is to simulate what an unauthorized external attacker can discover about the protected infrastructure, helping with determining what someone outside the environment can see. AN ASV will perform specific checks for items affecting security, such as:

- Missing security patches that address known vulnerabilities;
- Weak TLS encryption configuration;
- Utilizing vendor default credentials;
- Open ports and services;
- Misconfigured web servers.

### Review scan findings

The merchant and the ASV then review the scan findings to assess their impact on PCI compliance, which helps determine whether the findings affect compliance and what remediation is needed. Security teams must then address the findings by developing remediation strategies. Common findings include:

- Software vulnerabilities, such as an unpatched web server;
- Weak encryption that affects data security;
- Unnecessarily open ports;
- Expired certificates;
- Configuration errors, including enabled default settings.

### Remediate the identified vulnerabilities.

Organizations then remediate any identified vulnerabilities to reduce non-compliance risk and reduce the infrastructure’s attack surface. A failed scan may result from vulnerabilities, scan interference, or an unresolved dispute, and each outcome requires different remediation before rescan. Common examples of remediation activities include:

- Applying necessary security and software patches;
- Replacing expired certificates;
- Disabling vulnerable and unnecessary services;
- Hardening server access settings;
- Strengthening encryption configuration.

### Rescan the in-scope environment.

The ASV rescans the environment after the vulnerabilities are remediated. Most ASVs include rescans as part of their standard service offering. It may take multiple iterations of scanning and remediation to achieve compliance and a passing score.

## Reporting, Disputes, and ASV Scanning Quality

ASV reports are highly structured and standardized to provide merchants with an auditor-verifiable compliance artifact that demonstrates external attack-surface security meeting PCI DSS requirements. The ASV report contains the following sections:

- The executive summary indicates whether the merchant passed or failed a scan.
- The scope definition identifies all assets included in the scan.
- Scan configuration details demonstrate how the scanning was performed.
- The vulnerability findings are listed in the core technical section of the report. It includes vulnerability severity, affected asset, evidence, and remediation guidance.
- The PCI DSS compliance mapping determines whether the findings cause a failure and references the applicable PCI DSS requirements. This section forms the basis for the ASV pass/fail status.
- The final attestation is the ASV’s official statement of compliance.

ASVs must have a structured dispute workflow in place to address disagreements between the merchant and scanning vendor. Merchants can challenge findings they believe are incorrect, not applicable, or have already been remediated. Common reasons for disputes include:

- Detecting False Positives;
- Identifying assets that are not externally exposed;
- Scanning assets that are not in scope for PCI compliance;
- Flagging remediated vulnerabilities in a scan.

Companies typically submit disputes through the ASV’s reporting system. The ASV will review the dispute and validate the issue. These disputes must be handled directly between the scan customer and the ASV and cannot be escalated to the PCI SSC. After review, the ASV will either accept the dispute and remove the vulnerability from the report or reject it as a valid finding. In some cases, the ASV may request further information to resolve the dispute.

Merchants should request a sample scan report from prospective vendors to verify that it contains the necessary information and is formatted for clear understanding by management and technical teams.

## Choosing Approved Scanning Vendors and ASV Company Evaluation

Companies should always select an ASV that is on the PCI SSC’s list of approved vendors, including service providers that help businesses maintain compliance. Decision-makers should evaluate ASV companies to gauge the quality of their remediation guidance and whether the vendor also offers related security services. Merchants should expect a clear remediation process to address identified vulnerabilities.

The search for the right ASV should also include verifying that its processes integrate with a merchant’s existing security tools. Teams should try to streamline scanning without modifying their security solutions.

It is important to assess the dispute turnaround time for potential ASVs. The turnaround time can be instrumental in meeting the compliance deadlines and avoiding penalties that may affect merchant status.

## Integrations, Continuous Monitoring, and PCI Compliance Maintenance

Customers should investigate the potential to integrate ASV scanning activities with existing ticketing systems. This can streamline remediation efforts and a company’s compliance posture.

Some ASVs offer continuous external monitoring solutions designed to identify vulnerabilities as soon as they appear.

Companies should work with their ASV to schedule scans after network or infrastructure changes. These ad-hoc scans protect a business from vulnerabilities that the changes may have unintentionally introduced.

## Costs, Contracts, and Service Models for PCI Approved Scanning

Many ASVs offer per-scan pricing and a subscription model. Merchants should consider the following factors when signing a contract with an ASV.

- Per-scan pricing is best for small in-scope environments. It is difficult to budget efficiently with this model because it is usage-based, and rescans may incur additional costs.
- The subscription model offers companies with larger PCI DSS environments predictable costs, making budgeting easier. This model often includes rescans in the service’s price.

In either case, customers should clarify SLA support in the contract so they are not surprised when addressing disputes or remediation activities.

## ASV Training, Certification, and Internal Quality Assurance

The ASV vendor should be willing to demonstrate that their staff is trained to perform scanning processes effectively. An ASV’s personnel should be up to date on scanning methodology, PCI requirements, and vulnerability assessment standards. Individuals and organizations that want to operate as an ASV must meet standards that include:

- Passing the PCI SSC ASV program qualification requirements;
- Demonstrating scanning capabilities in test scenarios;
- Validating correct reporting methods;
- Maintaining procedural consistency and independence.

Merchants should verify the vendor’s staff certifications to ensure they comply with PCI regulations. The ASV must demonstrate annual requalification to align with new PCI DSS requirements, updated vulnerability scoring standards, changes in scan validation rules, and evolving, sophisticated attack techniques.

## Frequently Asked Questions About Approved Scanning Vendor and PCI Compliance

Q: Do internal scans replace ASV scans?

A: No, internal scans do not replace ASV scans. ASV scans are required to maintain PCI DSS compliance. Companies may perform internal scans to supplement ASV scans and identify vulnerabilities, enhancing their security posture.

Q: When are ASV scans necessary for hosted checkouts or redirect setups?

A: An ASV scan solution may be necessary for hosted checkout or redirect setups under certain conditions. Scans are required when the merchant has internet-facing systems in scope for PCI DSS. They may not be required when a merchant has no in-scope internet-facing systems or website, and a third-party provider handles the entire payment process.

Q: What is the relationship between penetration testing and ASV scans?

A: Penetration testing and ASV scans are processes that are often both required to meet PCI DSS requirements. ASV scans are automated and focus on addressing known vulnerabilities in externally accessible systems. Penetration tests go further and attempt to exploit vulnerabilities, escalate privileges, and access sensitive data. Used together, ASV scans and penetration tests provide insight into issues that may affect the security of a PCI-compliant infrastructure.

## Conclusion: Selecting the Right PCI Approved Scanning Vendor

Companies subject to PCI DSS compliance must exercise care when selecting an approved scanning vendor. Ideally, the ASV should be seen as a partner to ensure the data security of the in-scope infrastructure. A reliable ASV is instrumental in maintaining the security level required for PCI compliance.

Organizations should consider these factors when choosing an ASV:

- Inclusion on the SSC’s approved ASV list;
- Scan accuracy and reliability;
- The quality of remediation support;
- Automation and reporting capabilities;
- Responsive customer support;
- Cost.

Merchants leveraging a reputable cloud service provider (CSP) such as Atlantic.net for their [PCI DSS infrastructure](https://www.atlantic.net/pci-compliant-hosting/) can focus on running their business while the provider handles maintaining a secure computing environment. [Learn how Atlantic.net](https://www.atlantic.net/about-us/corporate-contact/) supports your PCI DSS compliance with a variety of PCI-compliant hosting solutions that stand up to stringent ASV scans.


---

# What AI Companies Want From GPU Infrastructure

> URL: https://www.atlantic.net/gpu-server-hosting/ai-companies-gpu-infrastructure-requirements/ | Published: 2026-07-17 | Author: Editorial Team

AI projects are getting bigger, and so are the infrastructure conversations behind them.

At Atlantic.Net, discussions with AI startups, SaaS companies, and healthcare technology providers often start with a question about GPU availability. Those conversations rarely end there.

Today’s buyers want to know which GPU models are available, how many nodes they can scale across, what networking options are supported, and whether the environment can support containerized workloads. Some organizations also have questions around compliance, storage performance, and deployment flexibility.

That shift reflects how AI infrastructure has evolved over the last few years. Organizations are no longer looking for a server with a GPU attached. They’re looking for an environment that can support training, fine-tuning, and inference workloads as projects grow.

The GPU remains an important part of the equation, but it is only one piece of a much larger platform.

## It Is No Longer Just About GPU Availability

A few years ago, many companies evaluating GPU hosting were primarily concerned with finding available capacity.

That has changed.

Customers speaking with Atlantic.Net still ask about GPUs, but the conversation usually expands quickly. Once compute requirements are established, attention often turns to storage, networking, deployment models, and scalability.

This shift makes sense. Modern AI workloads place demands on the entire infrastructure stack. A powerful accelerator alone cannot compensate for slow storage, network bottlenecks, or an environment that becomes difficult to manage as requirements grow.

Different workloads bring different priorities.

A startup training large language models may need multiple servers connected through high-speed networking. A SaaS company running inference workloads may be more concerned with predictable performance and operational flexibility. Development teams building cloud-native applications frequently want Kubernetes support and container orchestration capabilities.

These are the kinds of discussions Atlantic.Net increasingly sees from customers evaluating GPU infrastructure.

Instead of asking for hardware alone, organizations are looking for environments that can support long-term growth.

## H100, H200, and B200 Are Leading the Conversation

Not surprisingly, GPU selection remains one of the first topics many customers bring up.

Organizations evaluating AI infrastructure frequently ask about NVIDIA H100, H200, and newer B200 GPUs. These accelerator families have become closely associated with training, fine-tuning, and large-scale inference workloads.

In many cases, customers are less interested in benchmark numbers and more interested in understanding how the hardware fits within the broader environment.

Questions quickly move beyond specifications.

- How many GPUs can be deployed?
- Can workloads scale across multiple nodes?
- How quickly can infrastructure be provisioned?
- Is dedicated hardware available?

Those questions reflect a broader change in the market. Buyers are increasingly evaluating platforms instead of individual components.

For many organizations, GPU selection is just the starting point.

## Why Bare Metal GPU Servers Continue to Matter

Another trend Atlantic.Net continues to see is demand for bare-metal GPU servers.

Virtualized environments have their place, but many organizations prefer dedicated physical infrastructure for AI workloads that require consistent performance and greater control.

Training jobs can run for days or even weeks. Engineering teams often want direct access to compute resources without the additional layers introduced by virtualization. Dedicated environments also make it easier to customize operating systems, frameworks, and supporting infrastructure.

Performance predictability is another factor.

When resources are dedicated to a single customer, teams have more confidence that workloads will perform consistently. That level of control becomes especially important for organizations running production inference environments or building larger clusters.

As a result, many customers evaluating Atlantic.Net’s GPU hosting solutions also ask about bare metal options.

They’re thinking beyond immediate requirements and planning for future growth.

## Networking and Storage Are Critical

One lesson many organizations learn early in their AI journey is that GPUs are only part of the performance equation.

As workloads scale across multiple servers, networking becomes increasingly important. Data must move efficiently between systems, and delays can directly impact training performance.

That’s why customers frequently ask Atlantic.Net about technologies such as InfiniBand when designing larger environments.

Storage plays an equally important role.

AI workloads depend on access to massive datasets, checkpoints, model artifacts, and inference data. If storage cannot keep up, expensive compute resources may sit idle while waiting for data.

High-performance NVMe storage has become a common requirement for many customers because it helps reduce bottlenecks and improve.

Checkpointing is another area organizations pay close attention to. Training jobs often run for extended periods, and teams want the ability to resume progress without having to start over if an interruption occurs.

In practice, compute, storage, and networking all work together. Focusing on one component while overlooking the others can limit the performance of the entire environment.

## Kubernetes and Container Support Are Part of the Conversation

Containerized applications have become standard across modern IT environments, and AI workloads are no exception.

Many customers ask Atlantic.Net about Kubernetes support to achieve consistency across development, testing, and production environments.

Container orchestration provides flexibility, simplifies deployment, and helps teams manage resources more efficiently. For organizations supporting multiple workloads or multiple users, Kubernetes can also improve scalability and operational consistency.

As AI projects mature, container platforms are becoming less of a nice-to-have and more of an expected part of the infrastructure stack.

That trend mirrors what many organizations have already experienced with cloud-native applications.

## Healthcare AI May Require Compliance Support

Healthcare technology companies often face additional requirements when evaluating infrastructure.

Not every AI project involves protected health information, and not every deployment requires a compliance-focused environment. Organizations handling sensitive data usually want to address regulatory considerations early.

Customers in the healthcare space frequently ask Atlantic.Net whether HIPAA-aligned environments are available and whether a HIPAA Business Associate Agreement (BAA) can be provided when necessary.

Addressing those requirements upfront helps reduce and can prevent costly architectural changes later.

For healthcare organizations, compliance has become another important part of infrastructure planning rather than a separate discussion.

## Questions to Ask Before Requesting GPU Hosting

Before evaluating GPU hosting providers, it helps to answer a few practical questions:

- Which GPU model best fits the workload?
- How many GPUs or nodes will be required?
- Is the workload focused on training, fine-tuning, or inference?
- Is dedicated bare metal infrastructure necessary?
- Will the deployment benefit from InfiniBand networking?
- What level of storage performance is required?
- Will Kubernetes or container orchestration be part of the environment?
- Is HIPAA support or a BAA required?
- How much flexibility is needed in terms of deployment and contract duration?

Having clear answers to these questions can make infrastructure planning much easier and help ensure the environment is aligned with both current requirements and future growth.

## Conclusion

AI infrastructure conversations have evolved significantly over the last few years.

Today’s buyers are looking far beyond GPU availability. They’re evaluating complete environments that can support training, fine-tuning, and inference workloads at scale.

Atlantic.Net continues to see this shift firsthand. Customers are increasingly asking about dedicated servers, cluster design, networking, storage performance, Kubernetes support, compliance requirements, and GPU availability.

Successful AI deployments depend on much more than accelerator hardware alone.

Whether you’re evaluating GPU servers, bare metal hosting, or compliance-aware infrastructure, taking a broader view of the environment can help position your projects for long-term success.

If you’re exploring GPU hosting options, Atlantic.Net can help you design an infrastructure environment that meets your workload requirements. Learn more about Atlantic.Net’s GPU hosting and bare metal solutions, or contact the team to discuss your AI infrastructure needs.


---

# Best Cloud Hosting Providers for Small and Mid-Size Businesses in 2026

> URL: https://www.atlantic.net/cloud-platform/best-cloud-hosting-providers-small-businesses/ | Published: 2026-07-23 | Author: Richard Bailey

**Last updated: July 2026**

**Quick Answer:** The best cloud hosting provider for small businesses in 2026 is Atlantic.Net, offering $10-per-month entry pricing, a 100% uptime SLA, compliance-ready hosting options, and 24/7/365 US-based phone support.

Cloud hosting is a type of web hosting that uses virtual servers to store and deliver websites, applications, and data on demand from a network of physical servers.

## Key Takeaways

- Atlantic.Net ranks first for small and mid-size businesses with $10-per-month entry pricing, a 100% uptime SLA, compliance-ready infrastructure, and 24/7 human phone support.

- Cloud hosting infrastructure and cloud software services are separate purchases that require different evaluation criteria.

- The breadth offered by AWS, Microsoft Azure, and Google Cloud can create billing and support for small teams.

- Seven providers are compared on entry price, billing granularity, support model, SLA, and compliance options.

- Steady, high-utilization workloads may be better served by dedicated servers or private cloud infrastructure.

Most lists of the best cloud hosting providers for small businesses are written like enterprise procurement guides and scored primarily on catalog size. The provider with the most services, regions, and certifications wins, and the resulting list looks the same whether the reader runs a 40,000-person company or a 14-person one.

For a small business, that scoring is backward. A company without a dedicated infrastructure team experiences a cloud provider through three main surfaces: the monthly bill, the support line, and the uptime record. A catalog of hundreds of services does little for a WooCommerce store or client portal, and the hyperscalers’ flexibility can sometimes arrive as a surprise invoice at the end of a busy month.

This guide ranks seven cloud providers on the dimensions a small business actually experiences: entry price, billing granularity, support model, SLA, and compliance options. It also distinguishes between cloud hosting and cloud software services and identifies workloads for which cloud hosting may not be the best answer.

## Cloud Hosting vs. Cloud Services: What Small Businesses Actually Need

Small business owners searching for “cloud” often encounter two different product categories under the same label.

Cloud software services are the SaaS side: Google Workspace for email and documents, cloud storage platforms for file sharing, cloud backup services, and software applications such as accounting platforms or CRMs delivered through a browser. These services are typically purchased per user and require no direct infrastructure management.

Cloud hosting is the infrastructure side. It includes cloud-based servers, virtual machines, and hosting platforms that run a company’s website, application, or database. A small business operating a WooCommerce store, client portal, or line-of-business application may need cloud hosting while also using SaaS products such as Google Workspace, cloud storage, and backup software.

Most small businesses purchase both, but the two behave differently in the budget. SaaS products usually cost a predictable per-user subscription. Cloud infrastructure is more likely to involve usage-based pricing, variable bandwidth costs, and optional services that affect the final bill.

That asymmetry is why this guide focuses on infrastructure providers. A poor SaaS selection may result in wasted subscription fees. A cloud hosting mistake can affect uptime, performance, data protection, and regulatory obligations.

## How to Choose a Cloud Hosting Provider

The main factors to consider when choosing a cloud hosting provider are billing, support, uptime, security, backup, compliance, and the ability to scale.

Marketing pages describe normal operations. The criteria below matter most when traffic spikes, hardware fails, a deployment breaks, or a compliance question appears.

### Pricing Models and Billing Granularity

Cloud pricing generally follows three models:

- **Pay as you go:** Resources are billed hourly or by another usage unit, with no long-term commitment.

- **Reserved or committed use:** The customer agrees to a one-year or three-year term in exchange for a lower rate.

- **Spot or preemptible capacity:** Spare infrastructure is sold at a discount but may be reclaimed with limited notice.

Most small businesses benefit from pay-as-you-go pricing with a clearly defined monthly ceiling. Reserved pricing can make sense once usage becomes predictable. Spot capacity is normally better suited to fault-tolerant batch processing, development, testing, and other workloads that can survive interruption.

For many small companies, the most cost-effective pattern is a flat or capped plan sized to the workload and reviewed quarterly as demand becomes clearer.

### Support: Humans or Ticket Queues

“24/7 support” can mean several different things. A provider may offer immediate phone access, live chat, email, or only a ticket queue with response times tied to the customer’s support plan.

Ask the following questions before choosing a provider:

- Is phone or live-chat support included at the entry tier?

- Is technical support included, or only billing support?

- Are faster response times available only through a paid plan?

- Does the provider assist with operating systems and infrastructure, or only its own control panel and network?

For a small business without internal infrastructure staff, the support model may matter more than small differences in CPU or storage specifications.

### SLA and Uptime Guarantees

An SLA is a contractual uptime commitment. Headline figures such as 99.9%, 99.99%, and 100% correspond to different amounts of permitted downtime.

Over a 365-day year:

- A 99.9% availability level allows approximately 8.76 hours of downtime.

- A 99.99% availability level allows approximately 52.56 minutes of downtime.

The headline percentage is only part of the agreement. Customers should also review:

- What systems the SLA covers

- Which events are excluded

- How downtime is measured

- Whether the customer must submit a claim

- What service credits are available

- Whether network, power, hardware, and virtual-machine availability are treated separately

A 100% SLA is generally a service-credit commitment, not a guarantee that an outage can never happen.

### Security and Data Protection

Baseline security controls should include TLS support, firewalling, DDoS mitigation, access controls, and backup options. Encryption at rest and in transit is also important when servers contain customer records, payment data, health information, or other sensitive business data.

Customers should confirm which protections are included by default and which require additional configuration or fees. A provider may secure its physical infrastructure and network while leaving operating-system hardening, application security, identity management, and backup configuration to the customer.

Cloud security is therefore a shared responsibility.

### Data Storage and Backup

Different workloads require different forms of storage.

- Databases commonly use low-latency block storage.

- Backups, media, logs, and static files are often suitable for object storage.

- Shared team documents generally belong in a separate cloud file-storage or SaaS collaboration platform.

Confirm what the provider’s backup service covers, how often backups run, where copies are stored, how long they are retained, and how restores are performed.

Do not assume that a low-cost cloud server includes automated backups by default.

### Compliance Requirements

Healthcare, financial, legal, government, and e-commerce businesses may need infrastructure that supports frameworks such as HIPAA, PCI DSS, SOC 2, ISO/IEC 27001, or NIST 800-53.

A provider’s certification or audited environment does not automatically make the customer compliant. Customers remain responsible for application configuration, identity and access management, policies, logging, data handling, workforce practices, and other controls.

Look for:

- Independently audited certifications

- A clearly defined scope of coverage

- Current audit reports

- A signed HIPAA Business Associate Agreement (BAA) when required

- Encryption and logging capabilities
- Documented shared-responsibility requirements

### Room to Grow

A small business cloud server may need to support significantly more traffic in the future. Confirm that the provider offers:

- Straightforward CPU, RAM, and storage upgrades

- Supported operating systems and application stacks

- Snapshots or migration tools

- Load balancing and additional network services

- Assistance with cloud migration

- Clear procedures for moving to larger or more managed infrastructure

For a company moving away from its own IT infrastructure, migration assistance can be the difference between a weekend cutover and a quarter-long project.

## Cloud Hosting Provider Comparison

| **Provider** | **Entry Price** | **Billing Granularity** | **Support Model** | **Compliance Options** | **SLA** |
| --- | --- | --- | --- | --- | --- |
| Atlantic.Net | $10/mo for G3.2GB | Hourly with monthly cap | 24/7/365 US-based phone, email, and chat | SOC 2/3, HIPAA/HITECH, PCI DSS 4.0, NIST 800-53-related environments and BAAs | 100% uptime SLA |
| DigitalOcean | $4/mo Droplet | Hourly with monthly maximum | Ticket support; live support and faster response options vary by plan | BAAs available for eligible HIPAA workloads; additional published security and compliance programs | 99.99% Droplet SLA |
| Vultr | $2.50/mo IPv6-only instance | Hourly with monthly maximum | Ticket-first support | SOC 2 Type II, ISO/IEC 27001, and PCI DSS coverage, with scope varying by service and location | Varies by product |
| Liquid Web | $5/mo self-managed Cloud VPS | Hourly or monthly | 24/7 phone, chat, and ticket support | HIPAA-ready hosting and BAAs available for eligible environments | 100% network and power SLA on qualifying services |
| IONOS | $2/mo VPS with term commitment | Monthly | Phone, chat, and email support | ISO 27001-certified data centers | 99.99% availability |
| phoenixNAP | $0.08/hr Bare Metal Cloud | Hourly | Infrastructure-oriented technical support | SOC 2, PCI DSS, and HIPAA-ready options | Varies by service and SLA scope |
| OVHcloud | $4.54/mo VPS | Monthly | Phone, email, and ticket support options | Regional certifications and data-residency options | 99.9% VPS SLA |

Prices and plan terms can change. The lowest advertised rate may require an extended commitment, use IPv6-only networking, exclude management, or omit backups and other services.

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

## **1. Atlantic.Net, Best for Small and Mid-Size Businesses**

Best for: Small businesses needing compliance-ready hosting, human phone support, and predictable billing.

Atlantic.Net is a cloud hosting provider built around the idea that many small businesses need predictable pricing and access to a support team more than they need an enormous services catalog.

The cloud platform starts at $10 per month for the G3.2GB plan, which includes 1 vCPU, 2 GB of RAM, 50 GB of SSD storage, and 3 TB of transfer. The instance is billed hourly up to its monthly rate.

For small businesses, the value appears less in the raw specifications than in the services surrounding them. Atlantic.Net publishes a 100% uptime SLA and offers compliance-ready hosting environments supporting SOC 2, HIPAA/HITECH, PCI DSS 4.0, and NIST 800-53-related requirements.

Signed BAAs are available for eligible HIPAA environments. Compliance depends on the selected service, contractual scope, and the customer’s own configuration and operating practices.

Support is available 24/7/365 through phone, email, and chat, with US-based personnel.

A small retailer could, for example, run a WooCommerce store on a G3.8GB server with 4 vCPUs, 8 GB of RAM, and 160 GB of SSD storage. A typical software stack might include Nginx, PHP-FPM, MariaDB, and Redis. Optional daily backups add approximately 20% to the server price.

### Pros

- 100% uptime SLA with service-credit provisions

- Compliance-ready hosting options

- 24/7/365 US-based phone, email, and chat support

- Hourly billing with a monthly maximum

- Straightforward general-purpose plans

### Cons

- Smaller services catalog than AWS, Azure, or Google Cloud

- Fewer global regions than the hyperscalers

- Backups and some managed services cost extra

### The Honest Limitation

Atlantic.Net’s catalog is narrower than those of Amazon Web Services or Microsoft Azure. A business that needs a large portfolio of managed AI tools, specialized analytics platforms, global edge services, or hundreds of infrastructure products may find the available menu limiting.

Most small businesses do not require that breadth, but rapidly growing software companies may.

![](https://www.atlantic.net/wp-content/uploads/2026/07/DigitalOcean_logo.png)

## 2. DigitalOcean, Best for Developer-Led Teams 

Best for: Small businesses with in-house developers who prefer API-driven deployments, accessible documentation, and a streamlined platform.

DigitalOcean built its reputation around a clean developer experience, straightforward APIs, and extensive technical documentation.

For a small business with one or two developers who are comfortable managing Linux servers, deploying applications, and automating infrastructure, Droplets are relatively easy to operate.

Basic Droplets start at $4 per month. DigitalOcean also offers managed databases, Kubernetes, object storage, app hosting, and other developer-focused services.

DigitalOcean now offers BAAs for eligible HIPAA workloads. Customers must use covered products, enter into the required agreement, and configure their workloads in accordance with DigitalOcean’s HIPAA guidance and the customer’s own compliance obligations.

The availability of a BAA does not mean that every DigitalOcean service or configuration is automatically suitable for protected health information.

### Pros

- Clean API and strong documentation

- Predictable entry pricing from $4 per month

- Large developer community

- BAAs available for eligible HIPAA workloads

- Managed application and database services available

### Cons

- The platform assumes some terminal and infrastructure familiarity

- Real-time support and faster response commitments vary by support plan

- HIPAA eligibility depends on using covered services and completing the required agreement

### The Honest Limitation

DigitalOcean is designed primarily for developers. A business owner who wants a fully managed server and immediate telephone troubleshooting may find that the platform requires more technical independence than a managed hosting provider.

For a development-led team, its documentation, API, and product simplicity remain major advantages.

![](https://www.atlantic.net/wp-content/uploads/2025/04/vultr.png)

## **3. Vultr, Best Budget Global Footprint**

Best for: Small businesses with geographically distributed users that need low-cost infrastructure in multiple regions.

Vultr’s main advantages are geographic reach, hourly billing, and low-cost compute options. It operates infrastructure across more than 30 global locations.

Its lowest advertised cloud compute price is $2.50 per month, although that entry configuration is IPv6-only and is not directly comparable with a conventional dual-stack VPS. Businesses requiring standard IPv4 connectivity should compare the next applicable plan rather than relying only on the headline price.

Vultr also publishes a more substantial compliance posture than some comparisons suggest. Its available documentation includes SOC 2 Type II, ISO/IEC 27001, and PCI DSS coverage.

The exact scope depends on the service, facility, region, and customer configuration. A certification applying to part of the platform should not be assumed to cover every workload automatically.

### Pros

- More than 30 global locations

- Entry pricing from $2.50 per month

- Hourly billing with monthly maximums

- Published SOC 2 Type II, ISO/IEC 27001, and PCI DSS coverage

- Multiple compute, storage, and bare-metal options

### Cons

- The lowest-cost plan is IPv6-only

- Support is primarily ticket-based

- Compliance scope varies by product, region, and facility

- Less hands-on assistance than a fully managed host

### The Honest Limitation

Vultr’s service model is best suited to customers capable of managing their own infrastructure. Its global footprint and pricing are attractive, but small businesses should verify the support plan and compliance scope before deploying a production or regulated workload.

A company that rarely needs assistance may be satisfied. A company that expects immediate, hands-on troubleshooting may prefer a managed provider.

![](https://www.atlantic.net/wp-content/uploads/2026/07/liquid_web_logo.png)

## **4. Liquid Web, Best Fully Managed Option**

Best for: Small businesses willing to pay more for hands-on server management and included support.

Liquid Web is known for managed hosting and its “Heroic Support” branding. Its managed services can include operating-system patching, monitoring, security assistance, and first-line infrastructure troubleshooting.

Customers remain responsible for their application code, content, business processes, and application-level security unless those responsibilities are covered under a separate service agreement.

Liquid Web advertises Cloud VPS plans beginning at $5 per month, but that entry product is self-managed. Customers choosing Liquid Web specifically for fully managed administration should compare the managed configurations rather than assuming management is included in the lowest price.

HIPAA-ready hosting and BAAs are available for eligible regulated environments.

### Pros

- Fully managed hosting options

- 24/7 phone, chat, and ticket support

- Monitoring and operating-system assistance on managed plans

- HIPAA-ready environments and BAAs available

- Strong fit for companies without infrastructure staff

### Cons

- Managed plans cost more per unit of compute

- The $5 entry VPS is self-managed

- Management may be redundant for businesses with experienced technical teams.

- Application development and code maintenance remain the customer’s responsibility.

### The Honest Limitation

Liquid Web makes the most sense when the customer values administration and support more than the lowest possible infrastructure price.

For a small business without technical staff, the premium can save meaningful time. For a company with capable system administrators, that same premium may purchase services it does not need.

![](https://www.atlantic.net/wp-content/uploads/2025/08/ionos-logo.png)

## **5. IONOS, Lowest Entry Cost**

Best for: Budget-conscious small businesses willing to accept a term commitment to obtain the lowest advertised price.

IONOS offers VPS plans beginning at $2 per month. That price is tied to a multi-year commitment, so buyers should compare the total contract cost rather than treating it as equivalent to an hourly, no-commitment cloud server.

IONOS operates ISO 27001-certified data centers and provides phone, chat, and email support. Its European operational heritage may appeal to customers concerned with European hosting and data-residency requirements.

### Pros

- Very low advertised entry price

- ISO 27001-certified data centers

- Phone, chat, and email support

- Multiple US and European hosting options

### Cons

- The lowest price requires a long-term commitment

- Optional services can increase the effective cost

- The administrative experience emphasizes additional products and upgrades

- Less flexible than hourly infrastructure for short-lived workloads

### The Honest Limitation

IONOS is attractive for businesses prioritizing a low fixed monthly cost, the commitment period matters.

A customer comfortable with the contract structure may obtain good value. A company that needs temporary servers, rapid changes, or short-term testing may prefer an hourly platform.

.

![](https://www.atlantic.net/wp-content/uploads/2026/02/phoenixnap.png)

## **6. phoenixNAP, Best Bare-Metal Cloud for Infrastructure-Led Teams**

Best for: Small businesses with infrastructure that require dedicated physical hardware and hourly provisioning.

phoenixNAP offers Bare Metal Cloud instances billed by the hour, with configurations starting at approximately $0.08 per hour.

Bare metal gives customers access to a physical machine without a shared virtualization layer. This can benefit workloads requiring consistent performance, specialized licensing, hardware-level isolation, or dedicated resources.

phoenixNAP also publishes compliance-related offerings supporting SOC 2, PCI DSS, and HIPAA-ready use cases. As with any provider, the exact coverage depends on the selected facility, product, agreement, and customer configuration.

### Pros

- Dedicated physical hardware

- Hourly bare-metal billing

- SOC 2, PCI DSS, and HIPAA-ready options

- Strong performance for sustained workloads

- API-based provisioning

### Cons

- Requires infrastructure and security

- Not directly comparable with entry-level virtual machines

- More complex networking and administration

- Support is oriented toward technically experienced customers

### The Honest Limitation

phoenixNAP’s fit is narrower than those of most providers in this comparison. It assumes the customer understands server provisioning, operating-system security, networking, monitoring, and recovery planning.

It can be a strong option for a small company with an infrastructure engineer. It is unlikely to be the best first cloud platform for a nontechnical business owner.

![](https://www.atlantic.net/wp-content/uploads/2025/05/ovhcloud.png)

## **7. OVHcloud, Best for Data-Sovereignty-Conscious Small Businesses**

all Businesses

Best for: Small businesses with data-residency or jurisdictional requirements involving Europe or the United States.

OVHcloud operates data centers across Europe, North America, and other regions, making it a practical option for companies that need to choose where their data and workloads are hosted.

US VPS pricing begins at approximately $4.54 per month. Anti-DDoS protection is included, and current VPS plans also advertise daily backup features, although specifications can vary by market and plan.

OVHcloud provides phone, email, and ticket-based support options. Support features and response targets depend on the customer’s plan.

### Pros

- Strong European and North American presence

- Competitive VPS pricing

- Anti-DDoS protection included

- Data-residency and regional hosting options

- Daily backup included on applicable current VPS plans

### Cons

- Support level and response commitments depend on the plan

- The product catalog and documentation can be harder for new users to navigate

- Some services differ between the US and European platforms

### The Honest Limitation

OVHcloud is attractive for technically capable companies that value regional infrastructure and competitive pricing.

Customers should verify the exact support plan, product availability, certification scope, and contract terms for the country in which they open their account.

## When Cloud Hosting Is Not the Answer

Cloud hosting fits variable, growing, and unpredictable workloads well. It is less compelling for some steady or hardware-dependent workloads.

A small business running a high-utilization database or compute server at nearly full capacity around the clock may pay more for cloud infrastructure than for a dedicated physical server. The outcome depends on the complete cost model, including:

- Hardware

- Bandwidth

- Redundancy

- Backups

- Licensing

- Technical labor

- Monitoring

- Disaster recovery

- Replacement and maintenance

Cloud pricing rewards elasticity. A workload that never scales down receives less benefit from usage-based infrastructure.

Licensing-bound applications can also be difficult to operate in a virtual cloud environment. Physical processor, core, server, or hardware identity licenses some legacy software.

Strict data-residency, isolation, or contractual requirements may also lead a company toward private cloud or dedicated hardware in a named facility.

Hybrid infrastructure is often the practical middle ground. A business might place public-facing web applications in a public cloud while keeping a regulated database or licensing-bound application on dedicated infrastructure.

### FAQ: Cloud Hosting for Small Businesses

**What Features Should a Business Cloud Hosting Provider Include? **

A business cloud hosting provider should offer SSD or NVMe storage, backup options, firewall controls, DDoS protection, TLS support, monitoring, and 24/7 support with a documented response process.

For a small business, predictable billing and a clearly defined SLA are also important.

Not every provider includes all of these features in its entry plan. Customers should distinguish between included services, optional add-ons, and controls they must configure themselves.

**What Are the Most Common Cloud Hosting Pricing Models? **

The three main pricing models are:

- **Pay as you go:** Resources are billed according to actual usage.

- **Reserved or committed use:** Customers agree to a term in exchange for discounted pricing.

- **Spot or preemptible pricing:** Providers sell unused capacity at a discount, but the instance may be interrupted.

Spot or interruptible capacity is offered by major hyperscalers, including Amazon Web Services through EC2 Spot Instances, Microsoft Azure through Azure Spot Virtual Machines, and Google Cloud through Spot VMs.

Because these instances can be interrupted, they are best for workloads designed to restart, move, or tolerate loss of capacity. They are generally not the safest default for a single production server supporting a small business website or database.

Most small businesses should begin with pay-as-you-go or capped monthly pricing. Reserved pricing can be considered after usage becomes predictable.

**What Is an SLA, and What Should It Cover? **

An SLA, or service level agreement, is the provider’s contractual availability or performance commitment. It usually defines:

- The service being measured

- The target percentage

- Measurement procedures

- Excluded events

- The customer’s claim process

- Available service credits

A complete review should consider network availability, power, hardware replacement, storage, and virtual-machine availability separately.

The remedy is generally a credit against future service, not compensation for lost sales or business interruption.

**How Does Cloud Hosting Provide Redundancy? **

Redundancy can include:

- RAID or replicated storage

- Multiple network paths

- Backup power

- Redundant cooling

- Hardware failover

- Snapshots and backups

- Replication across availability zones or regions

A single cloud server is not automatically highly available. True application redundancy may require multiple instances, load balancing, database replication, automated failover, and tested recovery procedures.

**How Does Cloud Hosting Differ From Dedicated Server Hosting? **

Cloud hosting usually provides virtualized instances that can be provisioned quickly and billed hourly or monthly.

Dedicated hosting provides a full physical server reserved for one customer, usually billed monthly.

Cloud hosting is often better for variable or growing workloads. Dedicated hosting can be more economical for steady high-utilization workloads or applications requiring dedicated hardware.

**What Is the Difference Between Public, Private, and Hybrid Cloud Hosting? **

Public cloud uses provider-owned infrastructure shared among multiple customers, with logical isolation between accounts and workloads.

Private cloud dedicates infrastructure to one organization and may provide greater control, customization, or isolation.

Hybrid cloud combines public cloud, private cloud, dedicated infrastructure, or on-premises systems.

A hybrid model can help a company separate ordinary applications from workloads with stricter licensing, performance, residency, or compliance requirements.

**Which Cloud Hosting Platforms Are Best for Compliance-Heavy Industries? **

Look for providers that offer:

- Independently audited certifications

- Clearly documented audit scope

- Current SOC reports

- HIPAA BAAs where applicable

- PCI DSS support

- Encryption capabilities

- Identity and access controls

- Logging and monitoring

- Documented shared-responsibility requirements

No provider can make a business compliant through infrastructure alone. Compliance also depends on application design, access policies, employee practices, contracts, documentation, and ongoing risk management.

**How Do You Move From On-Premises Infrastructure to the Cloud? **

Begin by inventorying:

- Applications

- Databases

- Storage

- Dependencies

- Operating systems

- Network connections

- Authentication systems

- Backup requirements

- Compliance obligations

Estimate resource requirements before selecting an instance size. Test the migration with a noncritical workload first.

A phased migration can reveal configuration, performance, and dependency issues before customer-facing systems rely on the new environment.

Ask each provider which migration services are included and which are billed separately.

## Key Terms

**Cloud hosting:** Infrastructure hosting that uses virtualized or dedicated cloud resources to run websites, applications, databases, and related workloads.

**Cloud services:** A broad category covering software, platforms, and infrastructure delivered over a network. SaaS, PaaS, and IaaS are all forms of cloud services.

**Software as a service:** Applications delivered through the internet, such as email, accounting software, document collaboration, and CRM platforms.

**Infrastructure as a service:** Compute, storage, and networking resources that customers configure to run applications and workloads.

**Public cloud:** Provider-operated infrastructure shared across customers with logical isolation.

**Private cloud:** Cloud infrastructure dedicated to a single organization.

**Hybrid cloud: **A combination of public cloud, private cloud, dedicated servers, or on-premises infrastructure.

**Cloud server: **A virtual machine or server instance provisioned from a provider’s infrastructure.

**Virtual private cloud**: A logically isolated network within a larger public cloud platform, with customer-controlled IP ranges, routing, and firewall rules.

**Auto-scaling:** The automatic addition or removal of resources according to demand.

**SLA: **A contractual service-level commitment with defined measurements, exclusions, and remedies.

**Disaster recovery: **Processes and infrastructure used to restore systems after an outage, breach, or data-loss event.

**Recovery time objective:** The target amount of time required to restore a service.

**Recovery point objective:** The maximum acceptable amount of data loss measured in time.

**Object storage:** Storage that holds files or data objects with metadata and is commonly used for backups, archives, logs, media, and static assets.

**Block storage: **Storage presented to a server as a volume, commonly used for databases and applications requiring low-latency reads and writes.

**Cloud migration:** The process of moving applications, data, or workloads from on-premises systems or another provider into a new cloud environment.

## The Bottom Line for Small Businesses

Atlantic.Net earns the top position in this comparison because its services align closely with the priorities of many small businesses: predictable hourly billing with a monthly maximum, plans beginning at $10 per month, a 100% uptime SLA, compliance-ready hosting options, and 24/7/365 US-based phone, email, and chat support.

The other providers each suit a different scenario:

- DigitalOcean is a strong choice for developer-led teams.

- Vultr combines low pricing with a broad global footprint and published compliance programs.

- Liquid Web is best suited to businesses seeking fully managed administration.

- IONOS offers one of the lowest advertised fixed entry prices for customers willing to accept a term commitment.

- phoenixNAP provides hourly bare-metal infrastructure for technically experienced teams.

- OVHcloud is a strong option for businesses focused on regional hosting and data residency.

The right provider depends on the workload, support requirements, technical skills, compliance obligations, contract terms, and total cost, not the size of the provider’s services catalog alone.

Atlantic.Net has operated for more than three decades and provides cloud, dedicated, managed, and compliance-oriented hosting services. Businesses comparing infrastructure for an online store, client portal, or regulated application can review its plans or consult its team about an appropriate deployment.


---

# GPU Server vs Workstation: Which Is Right for You?

> URL: https://www.atlantic.net/gpu-server-hosting/gpu-server-vs-workstation/ | Published: 2026-07-24 | Author: Dr. Tehseen Zia

The choice between a GPU server and a GPU workstation is not just a hardware decision. It is a business infrastructure decision that affects performance, scalability, security, cost, and user experience. A GPU Workstation is a specialized high-performance desktop computer for a single user. Typically, it consists of one or two GPUs and is optimized for interactive workloads such as 3D rendering, CAD, video editing, engineering simulations, data science, and smaller AI applications. A GPU server, on the other hand, is designed for shared, large-scale or production workloads.

It is typically employed in a data center or cloud setting and configured with multiple GPUs. These features make GPU servers well suited for organizations that require scalable, high-utilization infrastructure for production workloads. This article examines the key differences between GPU servers and GPU workstations, explores where each platform performs best, and provides a practical framework for selecting the right GPU infrastructure based on workload requirements, operational goals, and long-term costs.

## Key differences between GPU server and workstation

A key difference between a GPU server and a workstation is not the GPU itself. It is essentially the operating model. Typically, a workstation is built for one person and one workflow. It provides users with control and local experience. A GPU server, by contrast, is designed to support multiple users, larger workloads, and more structured workflows. It can be accessed via containers, virtual desktops, notebooks, batch schedulers, SSH, or APIs.

Another difference is scalability. You can install one, two, or more GPUs to a workstation, depending on the type. But a workstation has limitations in cooling, power, noise, chassis space, and PCIe lanes for supporting more GPUs. GPU servers, by contrast, are purpose-built for dense GPU deployments. They support multiple GPUs with stronger airflow, larger memory capacity, high-speed interconnects and continuous operations. This makes them well-suited for large-scale and compute-intensive workloads.

Scalability is another key difference. A typical GPU workstation supports one or two GPUs. While some high-end models can accommodate additional GPUs, they still have limits in terms of power delivery, cooling capacity, noise, chassis space, and the number of available PCIe lanes. GPU servers are designed for dense GPU configurations, stronger airflow, larger memory capacity, faster interconnects, and continuous operation.

Reliability further sets them apart. Servers often include redundant power supplies, remote management, ECC memory options, hot-swap drives, monitoring tools, and better thermal design. Workstations can be dependable, but they are not always designed for continuous multi-user production workloads.

Cost is another key factor that distinguishes GPU workstations from GPU servers. A workstation is typically a capital investment. You buy it, maintain it, depreciate it, and replace it. Hosted GPU servers and cloud GPUs operate on different models. They shift cost towards operating expenses through recurring service fees. This approach offers greater flexibility because GPU capacity can be scaled as workload demands change. Organizations must actively monitor resource utilization to avoid unnecessary costs associated with idle GPU instances, excessive bandwidth consumption, and data transfer charges

Latency is another consideration. A local workstation typically offers the best interactive experience. A remote GPU server may perform well, but only if it is nearby and set up with the right network, access protocol, and session design. A powerful GPU loses its advantage if users face lag, poor display quality, packet loss, or unstable connections.

## High-performance GPU computing for AI workloads

AI workloads often complicate the choice between GPU workstations and GPU servers. This is primarily because different stages of the AI lifecycle place different demands on the underlying infrastructure. Training, fine-tuning, inference, data preparation, and model evaluation each have distinct requirements for compute, memory, storage, and scalability.

Large model training usually benefits from throughput. Teams need multiple GPUs working together, enough VRAM, high memory bandwidth, fast storage, and strong communication between GPUs. Multi-GPU interconnects and libraries such as NCCL are required to reduce communication overhead when models are split across GPUs or when multiple GPUs train on different batches simultaneously.

Inference is a different workload. A chatbot service for many users may need throughput, batching, monitoring, and uptime. An interactive AI assistant may need low single-request latency. A workstation may be sufficient for local testing or low-volume inference. As inference evolves into a production service with multiple users, uptime requirements, workload queues, and service-level expectations, a GPU server becomes a more appropriate platform.

VRAM often presents the first hard limit. If a model, scene, dataset, or simulation does not fit into GPU memory, performance may drop significantly, or the job may fail. Memory bandwidth is also important because many AI workloads spend more time moving data, rather than performing computations.

## Cost, lifecycle, and total cost of ownership

The first step in selecting a workstation is proper sizing. Teams should identify the target applications, GPU memory needs, CPU requirements, RAM, storage, monitors, operating system, warranty, and software certifications. They should also consider hidden costs such as power, cooling, noise, spare parts, IT support, backups, and the risk of downtime.

Cloud GPUs and hosted GPU servers require a different approach to cost planning. Instead of focusing on upfront hardware costs, organizations should first estimate recurring expenses, including GPU usage, storage, snapshots, bandwidth, private networking, backups, support, and managed services. Cloud infrastructure can become costly when GPU resources are provisioned continuously or left idle. They are often most cost-effective for workloads that are bursty, seasonal, experimental, or unpredictable.

A practical way to compare both options is to perform a three-year total [cost of ownership (TCO)](https://www.ibm.com/think/topics/total-cost-of-ownership) and break-even analysis. For GPU workstations, consider factors such as purchase price, warranty, expected resale value, electricity costs, support time, and refresh timing. For servers, include hosting or colocation, power, network, remote hands, monitoring, backups, and software licenses. For cloud GPUs, estimate expenses for hourly usage, storage, image management, data transfer, and idle resources. Evaluating these costs over a common timeframe provides a more accurate comparison than considering hardware prices alone.

## Remote access, cloud GPU, and scalability

Remote access is an important consideration when choosing between a GPU workstation and a GPU server. Even the most powerful GPU infrastructure can deliver a poor user experience if network latency, packet loss, or display quality becomes a bottleneck. GPU servers support a range of access methods, including remote desktop solutions, virtual desktop infrastructure (VDI), high-performance display protocols, browser-based notebooks, SSH with Jupyter, and APIs. The right approach depends on the workload, user requirements, security needs, and level of interactivity.

Interactive workloads place the greatest demands on remote access performance. Applications such as CAD, 3D design, animation, visualization, and video editing require low latency, smooth graphics, and high display quality to maintain productivity. AI training workloads, by contrast, are generally less sensitive to display latency. Their performance depends more on factors such as data transfer rates, storage throughput, checkpointing, job scheduling, and the ability to recover from interruptions. Understanding these differences helps organizations select a remote access strategy that meets both user experience and workload requirements.

Cloud GPU placement also matters. Deploy GPU resources close to either the users or the data to reduce latency, minimize data transfer costs, and improve performance. Organizations should also design their network architecture carefully using technologies such as VPNs, private networking, dedicated connections, or private links where appropriate. A hybrid deployment model often provides the greatest flexibility. Routine workloads can remain on local workstations or on-premises infrastructure. At the same time, compute-intensive tasks such as large AI training jobs, batch rendering, or temporary demand spikes can burst to cloud GPU resources.

[Atlantic.Net](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/) can support this planning through GPU hosting, cloud infrastructure, colocation, private networking, and managed services. Rather than forcing every workload into a single deployment model, the objective should be to align infrastructure with actual operational requirements. By selecting the right combination of on-premises, hosted, and cloud resources, organizations can achieve the right balance of performance, scalability, security, and cost.

## GPU workstations: Benefits and tradeoffs

GPU workstations remain the right choice for many users. They provide direct, low-latency interaction and a familiar desktop experience. Artists, engineers, editors, researchers, and analysts can work without depending on remote access. Large files can stay local, peripherals are easier to manage, and troubleshooting is often faster.

Their main limitation is utilization. A workstation may sit idle at night, during meetings, or between projects. It may be tied to a single desk or user. Sharing it across a team can create scheduling problems. Sensitive data stored locally may also be harder to secure.

Before purchasing a workstation, teams should define the performance requirements of the intended users and workloads. They should consider how the system will be used in practice. For example, how many hours each day will the GPU operate near full utilization? How much VRAM does the primary application require? Will the workload involve long-running renders that demand sustained performance or shorter, interactive tasks? It is also important to verify whether the software vendor certifies specific GPU models or driver versions, as certified hardware can improve stability, compatibility, and long-term reliability.

## GPU server strengths: Reliability and data processing

GPU servers are the preferred choice for workloads that require shared access, sustained performance, and high throughput. They are well suited for AI training pipelines, inference services, batch rendering, scientific computing, large-scale data processing, and collaborative development environments where multiple users share GPU resources.

Reliability should be built into the infrastructure from the outset rather than added later. In practice, this means equipping a production GPU server with backup power wherever possible, temperature and hardware health monitoring, tested backups and recovery procedures, alerting systems, and extra capacity to maintain service continuity during failures or maintenance. For systems that operate continuously, it is practical to assume hardware failures will occur eventually and to design the infrastructure to minimize downtime and recover quickly when they do.

Shared scheduling is also. Without proper policies, one user can consume all GPU memory or leave jobs running for days. Job scheduling, queueing systems, containers, resource quotas, namespaces, and role-based access controls can help keep usage fair. Monitoring is equally important. It is used to track GPU utilization, memory usage, job duration, failed jobs, and user activity. This visibility helps improve utilization, control costs, and identify workloads that need.

GPU servers can also enable more data pipelines by integrating closely with centralized storage and high-speed networks. They can process large batches overnight, continuously ingest new data, and feed results directly into downstream analytics, AI, or business applications without relying on manual data movement. For production AI inference, infrastructure monitoring should extend beyond GPU utilization. Teams should also track application-level metrics such as request queue depth, response latency, error rates, and GPU memory utilization to ensure the service continues to meet performance and reliability objectives.

## Gaming GPU, NVIDIA RTX, and professional cards

The GPU market can be confusing because “RTX” appears across gaming, creator, and professional products. Consumer NVIDIA GeForce RTX cards can be excellent for learning, hobbyist AI, gaming, content creation, and early prototyping. Professional workstation cards are built for different needs.

Professional GPUs may offer larger VRAM capacities, ECC memory, certified drivers, longer support periods, virtualization support, and better compatibility with enterprise software. These features are important when downtime is costly or when software vendors require certified hardware for support. Drivers also affect stability and compatibility. Game Ready drivers focus on new game support. Studio drivers focus on creative application stability, while enterprise or professional drivers support certified business and technical workloads.

The safest approach is to test real applications before buying. Run CAD tools, rendering engines, AI frameworks, simulation workloads, or video pipelines using actual project files. A cheaper GPU that crashes often may cost more than a professional card that runs reliably.

## Data security, compliance, and on-prem versus cloud

Security and compliance requirements often play a critical role in infrastructure selection. Some organizations require on-premises deployments to support air-gapped environments, classified research, sensitive intellectual property, or regulatory policies that prohibit external hosting. In these cases, a local GPU workstation or a privately managed GPU server may be the most appropriate solution to ensure sensitive data remains within a controlled, secure environment. Cloud and hosted GPU servers can also support regulated workloads, but the provider, architecture, and controls must meet compliance requirements. Before deployment, teams should review security attestations, audit reports, data center controls, incident response procedures, and the shared responsibility model.

Encryption should be enforced for data both in transit and at rest, with customer-managed encryption keys used where greater control is required. Access should follow the principle of least privilege, limiting who can provision GPU instances, mount storage volumes, download data, export model weights, or access administrative consoles. Organizations should also establish clear policies for data residency by understanding where datasets, backups, snapshots, logs, and replicas are stored. Where appropriate, techniques such as tokenization or data masking can further reduce risk by ensuring workloads do not require direct access to sensitive information.

These considerations highlight that selecting GPU infrastructure is not just about performance. Organizations in healthcare, financial services, and other industries that handle sensitive data require infrastructure providers with secure hosting, compliance, and operational resilience. Providers like [Atlantic.Net](https://www.atlantic.net/compliance-hosting/) can help address these requirements with secure GPU hosting solutions to support business-critical workloads.

## Deployment considerations: Power, cooling, and colocation

High-end GPUs consume power and generate substantial heat. A workstation may require a dedicated circuit, room ventilation, and noise planning. A GPU server may require rack power planning, 240V service, redundant feeds, validated cooling, and proper airflow. Noise is easy to underestimate. Rackmount GPU servers are not designed for quiet offices. They belong in a server room, lab, or data center. Even tower workstations can become loud under sustained GPU load.

Colocation can be a useful middle path for teams that want to own hardware but do not want to operate a data center. It provides power, cooling, network connectivity, physical security, remote hands, and cross-connect options. It also makes hybrid architecture easier because colocated servers can connect to cloud, storage, backup, and network services more easily than office-based hardware.

## When to upgrade from workstation to GPU server

A workstation is no longer the right choice when its limitations become part of the daily workflow. Frequent out-of-memory errors are one clear indicator. Thermal throttling is another. If performance drops under sustained workloads because the system cannot maintain adequate cooling, the workstation is no longer keeping pace with the workload’s demands. Multi-user demand is another signal that a workstation is no longer serving the requirements. If people wait for access, manually copy data, or ask who is using the machine, it may be time to consider a shared GPU server or a cloud GPU pool.

Production requirements are another point where GPU servers have a clear advantage. A workstation is rarely the right platform for hosting a production inference API, an overnight data processing pipeline, or any service that must meet defined [service-level agreements (SLAs)](https://www.atlantic.net/cloud-service-level-agreement/). As availability and reliability become business-critical, organizations need infrastructure that supports continuous monitoring, redundancy, automated backups, remote management, and well-documented disaster recovery procedures. These capabilities are fundamental to maintaining service continuity and minimizing downtime in production environments.

## Decision checklist: Server, workstation, or cloud GPU

Start by understanding how GPU resources are actually used. Measure average GPU hours per month, peak demand, and the number of users who need concurrent access. If a GPU is heavily utilized by a single user every day, a workstation or dedicated hosted GPU server may offer the best value. If workloads are intermittent, experimental, or unpredictable, cloud GPUs often provide greater flexibility and cost.

Latency is another important consideration. Interactive applications such as CAD, 3D design, video editing, and visualization depend on responsive performance and low latency. In contrast, batch AI training and offline rendering are generally more tolerant of latency, while production inference typically requires both high throughput and consistent response times.

VRAM requirements should also be defined early in the evaluation process. A model or 3D scene that requires 48 GB of GPU memory will not run effectively on a 16 GB GPU, regardless of benchmark performance. For larger AI workloads, assess whether techniques such as quantization, model parallelism, or multi-GPU deployment will be required.

Finally, establish security and compliance requirements before selecting an infrastructure platform. Determine whether sensitive data can leave the organization, which geographic regions are approved for data storage and processing, what provider certifications are required, and how encryption keys will be managed. Addressing these requirements early helps ensure the chosen infrastructure meets both technical and regulatory needs.

## Pilot plan for comparing cloud GPU and workstation

A short pilot can reduce deployment risk. Conduct a two-week evaluation using real workloads instead of synthetic benchmarks. Include actual files, datasets, models, render settings, training scripts, and users. Throughout the pilot, measure practical metrics such as throughput, latency, cost per workload, failed jobs, time to first result, GPU utilization, VRAM usage, setup time, infrastructure cost, and user satisfaction.

The evaluation should also include resilience testing. Restart active jobs, intentionally exhaust GPU memory, simulate network interruptions, and verify recovery after events such as driver failures or full storage volumes. These tests provide insight into how the infrastructure performs under real operating conditions rather than ideal scenarios.

Where possible, use representative benchmarks alongside production workloads. For AI inference, frameworks such as [MLPerf Inference](https://mlcommons.org/benchmarks/inference-datacenter/) can provide standardized performance measurements. For deep learning training, NVIDIA Deep Learning Examples or a representative PyTorch training workload provide practical comparisons. Large language model deployments should be evaluated using a production-relevant open model with consistent prompts while measuring metrics such as tokens per second, time to first token, VRAM utilization, and cost per generated response. Rendering teams should benchmark both a standard Blender scene and an internal production project to capture performance under realistic conditions. This combination of standardized testing and real-world validation provides a far more reliable basis for infrastructure decisions than hardware specifications alone.

## FAQs and next steps

**Is a GPU server always faster than a workstation?**

No. A well-configured workstation can feel faster to a single user doing interactive work. A GPU server becomes more valuable when you need shared access, more GPUs, higher throughput, reliability, or 24/7 operation.

**Is cloud GPU cheaper than buying hardware?**

It depends on utilization. Cloud GPU is often better for bursty or uncertain demand. Owned hardware can be cheaper when usage is steady and high. Compare three-year cost and cost per completed task.

**Can gaming GPUs be used for AI work?**

Yes. Gaming GPUs can work well for learning, prototyping, and smaller AI models. For enterprise workloads, evaluate VRAM, ECC memory, drivers, warranty, software certification, and support requirements.

**When should a team consider Atlantic.Net?**

Atlantic.Net is worth considering when your GPU requirements extend beyond a single workstation. Its GPU hosting, cloud infrastructure, private networking, colocation, and managed services can help organizations deploy scalable, secure, and production-ready GPU environments.

**What should we do before buying?**

Run a pilot using your own workloads. Compare workstation, server, and cloud GPU options with the same datasets, scripts, and users. Review results with technical, financial, and security stakeholders. Many teams choose a hybrid model because no single GPU infrastructure strategy fits every workload forever.


---

# AI in Networking: Models, Infrastructure & Strategy

> URL: https://www.atlantic.net/gpu-server-hosting/ai-in-networking-models-infrastructure-strategy-2/ | Published: 2026-07-24 | Author: Dr. Tehseen Zia

Artificial intelligence and networking are coming together in two important ways. The first is AI for networking, which involves using AI to automate network management across security, observability, performance, and predictive analytics. The latter is networking for AI, which centers on creating a high-performance infrastructure that can support AI workloads of training and inference. From this perspective, AI in networking encompasses both the infrastructure that supports AI systems and the intelligent technologies used to manage, automate, and optimize network operations. On the backend, it includes network fabrics that connect compute resources such as GPUs and support large-scale AI training and inference workloads. On the frontend, it includes the use of AI for routing, security, observability, and service assurance in networking. Together, these two domains enhance network performance and support modern AI applications through intelligent systems, high-performance network fabrics, and automated operations. This means that AI in networking includes everything from AI-assisted traffic management and predictive assurance to GPU interconnects, lossless fabrics, and distributed training networks.

## AI in Networking vs. Traditional Networking

Traditional networking was built mainly for general business traffic. It often relied on manual configuration, static policies, and best-effort delivery. That approach works well for office apps, web traffic, and routine enterprise workloads.

AI networking has a different profile. It must support synchronized GPU communication, high packet rates, and workloads that are very sensitive to delay. Even small losses or congestion can slow training jobs and waste expensive compute time. Traditional enterprise networks can usually tolerate moderate retransmission and variable latency. But AI-driven networks often need much higher throughput and much tighter latency control. These requirements become especially important in large-scale distributed training clusters, where thousands of GPUs must exchange data efficiently and remain synchronized throughout the training process.

Another key difference lies in network operations. Traditional networks are typically managed through alerts and manual troubleshooting. We often react to issues after they occur. In contrast, AI networking uses automation, predictive analysis, and closed-loop remediation to take a more proactive approach. By continuously analyzing telemetry data, AI-enabled networks can detect anomalies, identify performance trends, infer likely root causes, and recommend or initiate corrective actions before users or applications are significantly affected.

## How AI in Networking Works

The role of AI and networking can be viewed at three distinct levels. The first one is the data center backend, where models are trained, and large-scale inferences are executed. At this layer, networks are specifically designed to support the demands of AI workloads. The second is the enterprise frontend, where AI is used to improve network operations such as path selection and routing. The third is the management layer, which is where AI can be used to manage the network itself. The last two layers essentially deal with applying AI technologies to network operations, management, security, and.

### Data Center Backend (AI Workloads)

This is the most challenging part of AI networking. It focuses on building network infrastructure specifically for AI workloads. Collective communications like all-reduce and all-to-all are used to exchange gradients and parameters continuously during distributed training. This communication leads to bursts of synchronized traffic, and any packet delay or loss can slow down the entire job. For this reason, lossless transport has become the norm in AI networking.

RDMA (Remote Direct Memory Access) has also become an essential part of AI networks. It enables communication of the GPU memory directly over the network without involving the host CPU. This helps AI networks significantly reduce latency. Priority Flow Control (PFC) and Explicit Congestion Notification (ECN) are typically used with RDMA to provide reliability. In this way, packet losses are minimized, nd GPU clusters remain productive.

Physical topology also matters. A non-blocking Clos or leaf-spine design is commonly used to provide predictable access to the fabric for each GPU node. This architecture also helps remove bandwidth bottlenecks with deep packet buffers that handle the incast traffic patterns common in AI workloads.

### Enterprise Frontend and WAN

The frontend- serving frontend applications such as copilots, recommendation engines, fraud checks, and real-time analytics all depend on fast and consistent response times. In this part of the network, predictive path selection and continuous assurance are more useful than static routing.

AI models on the enterprise side analyze historical and live traffic data to make smarter routing decisions. Rather than reacting to congestion, predictive path selection routes traffic proactively. Real-time assurance workflows continuously monitor application performance and automatically reroute traffic when a degrading path is detected. Placing inference workloads at edge nodes reduces round-trip latency for latency-sensitive applications.

### Agentic AI Systems and AI Agents

Agentic AI is introducing a new level of automation to network operations. Unlike traditional AI systems that primarily analyze data, summarize logs, or generate alerts, AI agents can reason about problems, recommend corrective actions, and execute approved tasks within defined policy boundaries. These systems can autonomously take remediation measures, such as quarantining a device, rerouting traffic, or adjusting firewall rules in response to a detected threat. Some typical use cases include automated incident response, configuration drift correction, and capacity rebalancing.

Human-in-the-loop governance is a critical component of an [AgenticOps](https://medium.com/@OpenCSG/agenticops-the-missing-operating-system-for-enterprise-ai-4f536de1a844) framework. Each automated action must have rules of engagement, tracking logs, thresholds for approval, and the steps to roll back. The [National Institute of Standards and Technology AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) emphasizes governance, mapping, measurement, and management as key elements of trustworthy AI systems. These principles align closely with the requirements of modern network operations.

## Core AI Technologies for Networking

The intersection of AI and networks is operationalized through a set of technologies that form the backbone of modern intelligent networking systems. At the core of this stack are AI models, which analyze large volumes of telemetry data and uncover patterns that would be difficult to identify through manual inspection. By learning the network’s normal behavior, these models can detect anomalies, unusual traffic patterns, and early signs of potential failures.

Data Processing Units (DPUs) and smart Network Interface Controllers (NICs) are used to offload processing tasks from the CPU. This improves and allows host resources to be dedicated primarily to AI workloads. In addition, GPU interconnects such as NVLink and PCIe enable high-speed data movement between accelerators. They reduce communication overhead and minimize bottlenecks before traffic even reaches the external network fabric.

Another important aspect is streaming telemetry. Instead of relying on periodic polling of network devices, modern networks continuously stream live operational data to analytics systems. This enables AI models to detect trends and evolving behavior patterns across the network and respond to changes in near real time. The ability to process real-time network data and respond accordingly significantly improves both visibility and network responsiveness.

It is also becoming popular to tokenize network events for language models. Logs, alerts, and flow records can be converted to structured text so an LLM can summarize incidents, answer questions, or provide a troubleshooting guide.

## AI Models and AI Workloads

AI networking supports two types of workloads. Training workloads are large, synchronized, and expensive. They depend on many GPUs working together and are highly sensitive to delays between nodes. Inference workloads are usually smaller and more distributed. They deal with serving predictions quickly and consistently to users.

LLMs can also support [NetOps](https://www.cisco.com/site/us/en/learn/topics/networking/what-is-netops.html). They can help operators query configurations in plain language, summarize incidents, or explain traffic patterns. Used carefully, they can make network data easier to access for teams that are not deep in CLI syntax or telemetry tools.

The traffic patterns are different too. Training traffic is often bursty and synchronized, while inference traffic is usually asynchronous and spread across many requests. That means the infrastructure must be designed for both predictable collective flows and less structured user traffic.

## AI Systems, AI Tools, and AI Agents

The role of AI in networking relies on a wider range of tools. Machine-learning-based monitoring platforms detect anomalies, reduce the false-alert rate, and surface correlated issues before manual review. This information is then translated into actions or playbooks by automation platforms. There is growing use of LLMs (Large Language Models) as tools for natural-language queries. An operator can request bandwidth trends, view the latest alarms, or receive root-cause hints. The system can convert these requests into a telemetry search or an API call. This helps lower the barrier to operating and managing complex networks.

As systems grow mature, Agent Orchestration is gaining significance. A monitoring agent can identify a fault, a diagnostic agent can diagnose an issue, and a remediation agent can suggest a solution. The orchestration layer organizes those actions in order and within policy.

Organizations also need to decide between open and closed models. Open models can provide more control and private deployment. In contrast, the closed models can provide better performance or a more manageable simplicity. The right choice depends on privacy, cost, compliance, and the extent to which the team needs internal control.

## AI Infrastructure and AI Solution Design

The network fabric is the first step in building a strong AI-ready network. A leaf-spine design is typically employed for its ability to scale cleanly and to handle low oversubscription. For training clusters, it may be worthwhile to incur the additional cost of a non-blocking or near-non-blocking design, since GPU idle time is costly.

It is just as critical to have high-bandwidth NICs and optics. AI environments typically require 100, 200, 400, or even 1000+ speed of service, low-latency transport, and lossless features. The goal is to prevent the network from becoming the “bottleneck”.

AI [Networking-as-a-Service](https://www.cisco.com/site/us/en/learn/topics/networking/what-is-network-as-a-service-naas.html) is becoming for organizations that want to use AI-optimized connectivity without building the fabric. For organizations that do not want to build AI networking in-house, a managed cloud or dedicated environment may speed up the deployment. Atlantic.net, for example, provides GPU cloud hosting, virtual private cloud, dedicated hosting, private virtualization, and managed hosting, which can help teams run AI workloads before committing to a larger, permanent build-out.

Different workloads also have different infrastructure requirements. Certain workloads may be better suited to an on-premises environment, such as those with high data sensitivity, low-latency requirements, or predictable capacity. Others can take advantage of the scalability and flexibility of cloud environments. For some workloads, a hybrid deployment model is often the most practical approach because it allows each workload to run where it provides the better operational and economic advantage.

## AI in Networking Strategy

The first step in an effective AI networking strategy is ensuring the availability and quality of data. It involves a strategy for collecting telemetry, logs, flow records, and incident data. It also requires a labeling procedure to ensure that past events can become useful training material for models.

Another important factor is the use of real, well-defined KPIs to measure success. In this regard, some of the metrics include latency, utilization, incident response time, automation success, model accuracy, and training throughput. It is also important that these metrics are directly connected to business outcomes.

Governance should be a part of the strategy. Privacy controls, audit trails, access management, and review processes are essential for AI systems. This is particularly in areas where AI can influence routing, security, or customer services.

Change management is another aspect of AI in networking. As these systems evolve rapidly, network teams need time to understand the tools, build trust in their outputs, and their working practices accordingly. Training, documentation, and staged rollouts are essential to ensure smooth adoption and that AI enhances operations rather than disrupts them.

## Roadmap

The first step to applying AI in networking is to evaluate the environment. This involves understanding what types of telemetry data are already available, identifying gaps in visibility, and determining which operational tasks are still being performed manually.

The next step is to choose a focused pilot project with clearly defined success metrics. An effective pilot should be specific, measurable, and easy to evaluate. Common starting points include anomaly detection, WAN, and accelerating troubleshooting within a particular network environment.

For use cases involving sensitive data, approaches such as Retrieval-Augmented Generation (RAG) can be particularly useful. This allows AI models to generate responses based on private documents and internal telemetry without broadly sharing raw underlying data.

It is also important to implement the pilot in phases. Start with observation-only mode to understand behavior without making changes. Then, move to recommendation-only mode where the system suggests actions. After that, introduce limited automation in a controlled way. Once this approach is stable and reliable, it can be gradually scaled across other parts of the network.

## Enterprise Use Cases and AI Benefits

AI and networking offer benefits for both domains. One key advantage is faster training. A well-designed AI fabric keeps GPUs highly utilized, reduces idle time, shortens model development cycles, and improves resource utilization.

Another important use case is WAN assurance. AI can detect weakening paths, predict issues with experience, and reroute traffic before users notice major disruption.

Security is also a major area of value. AI can help identify suspicious patterns, correlate signals across different systems, and accelerate response when unusual activity is detected across the network.

## Risks, Limitations, and Mitigations

When using AI in networking, be vigilant, as AI systems are not infallible. LLMs can provide incorrect answers, misunderstand the context, or draw incorrect conclusions, especially when dealing with incomplete or poor-quality data. For this reason, organizations should ensure that critical decisions and high-impact actions remain subject to human review and approval.

Privacy and regulatory compliance are other aspects that require careful consideration. Network telemetry and operational data can contain sensitive information about users, applications, and business processes. When cloud-based AI services process this data, organizations may face compliance and data sovereignty concerns, particularly in highly regulated sectors. To address these risks, organizations handling sensitive workloads should consider private AI deployments or on-premises inference environments.

Reliable AI-driven systems must also have controls to limit the risk of automation failures. Humans must authorize a high-impact change, or a fallback mechanism must be implemented to ensure that, if the AI-driven change fails or an unreliable change is generated, a known-good configuration is applied without causing disruption or additional downtime.

## Monitoring, Observability, and Continuous Improvement

Like traditional network operations, AI systems also require continuous monitoring. Teams should collect per-link, per-flow, and per-device telemetry to gain granular visibility into network behavior. Adaptive baselining can help to reduce false positives by replacing static thresholds with models that learn normal behavior based on time of day, workload patterns, or specific site characteristics.

[OpenTelemetry](https://opentelemetry.io/) provides a practical framework for standardizing the collection of traces, metrics, and logs across diverse environments. In addition, model retraining should be planned and systematic rather than ad hoc. As traffic patterns, applications, and policies evolve, models can drift over time. This makes periodic validation essential to ensure that AI systems remain aligned with the network’s actual behavior.

## Future Trends and Next Steps

The next phase of AI networking will likely bring faster fabrics, wider use of telemetry-driven control, and more agentic operations. Current vendor roadmaps already point toward 800G-class switching, AI fabrics that span multiple data centers, and hardware-assisted congestion management designed to support increasingly demanding AI workloads.

As networking environments become more intelligent and automated, the skills required to manage them will also evolve. Network professionals will need a stronger understanding of data management, AI model governance, automation frameworks, and operational oversight. Success will depend not only on deploying AI technologies but also on managing them responsibly and effectively.


---

# Bare Metal Automation in 2026: Provisioning, Tools, and Lifecycle Management

> URL: https://www.atlantic.net/dedicated-server-hosting/bare-metal-automation-provisioning-tools-lifecycle-management/ | Published: 2026-07-24 | Author: Dr. Assad Abbas

[Bare metal servers](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) are used for workloads that require predictable performance, direct hardware access, and clear isolation from other systems. In 2026, these requirements are common in AI platforms, high-performance computing, edge deployments, regulated applications, and business-critical systems. Physical servers can become difficult to manage when provisioning, patching, rebuilding, and retirement depend on manual steps.

Bare-metal automation addresses this challenge by offering infrastructure teams a controlled process for managing physical servers throughout their lifecycles. It connects provisioning, configuration, monitoring, patching, and decommissioning into repeatable workflows. Therefore, teams can reduce manual errors, improve deployment consistency, and maintain audit records that are easier to review.

This article explains bare-metal automation in 2026, focusing on provisioning, tools, and lifecycle management.

## What Is Bare Metal Automation?

Bare metal automation is the programmatic provisioning, configuration, management, and retirement of physical servers with minimal manual intervention.

Bare metal automation differs from virtualized infrastructure because no hypervisor sits between the workload and the physical machine. Therefore, the automation process works directly with firmware, BIOS or UEFI settings, RAID controllers, network cards, storage devices, boot order, and Baseboard Management Controllers.

In addition, the deployment of bare metal servers depends on physical conditions. Rack location, cabling, switch ports, power feeds, cooling capacity, and network topology influence the provisioning process. Bare-metal automation has a broader operational scope than standard virtual machine provisioning.

Bare metal automation helps data center teams manage physical servers with consistent, controlled workflows. Common goals of bare metal automation include [zero-touch provisioning](https://www.paloaltonetworks.com/cyberpedia/what-is-zero-touch-provisioning-ZTP), hardware discovery, consistent OS deployment, firmware control, inventory updates, remote power actions, compliance logging, and secure decommissioning. These goals help data center teams build a reliable foundation for physical server operations.

## Bare Metal Infrastructure and Provisioning Process

Bare metal automation depends on physical servers, management interfaces, provisioning networks, control-plane services, and inventory systems. Each part supports a specific stage of automated deployment. The following subsections explain the infrastructure components and the provisioning process in the order they are presented.

### Core Infrastructure Components

Bare-metal automation relies on physical servers, management interfaces, network paths, control-plane services, and inventory records. Physical servers provide the compute, memory, storage, and network capacity required for bare metal workloads. In data centers, these servers may appear as 1U and 2U rack servers, blade systems, GPU-dense nodes, storage-dense systems, or edge appliances. Each server type has different requirements for rack space, power, cooling, cabling, and network placement.

Most enterprise servers also include a Baseboard Management Controller (BMC). The BMC provides hardware-level access for power actions, boot settings, sensor readings, and remote console access. In addition, top-of-rack switches connect physical servers to production, provisioning, and management networks. This separation helps automation tools control workload, installation, and hardware management traffic through separate network paths.

After the physical servers and network paths are identified, the automation workflow requires a control layer to link infrastructure records to provisioning actions. The control plane provides this layer by using inventory data, images, credentials, server profiles, and workflow rules to apply the correct configuration to each server.

A Configuration Management Database (CMDB) or inventory platform stores asset tags, MAC addresses, BMC addresses, rack positions, switch ports, ownership, and lifecycle state. Accurate records help the automation workflow select the correct image, network profile, and hardware configuration.

### Inventory and Rack Readiness

A reliable provisioning process depends on accurate inventory and verified rack conditions before installation starts. Therefore, teams record hardware details, validate BMC credentials, confirm rack positions, map switch ports, and review power feeds. Accurate records help the control plane select the correct image, network profile, and hardware configuration.

Rack readiness is part of the same preparation process. In addition, rack power budgets, redundant PDU capacity, airflow direction, and cooling limits are reviewed before dense server deployments. This review is important for GPU servers and storage-heavy nodes because higher heat and power demand can affect system stability.

### Network Boot and OS Installation

When inventory and rack checks are complete, the provisioning workflow moves to network boot. At this stage, the control plane applies DHCP reservations, PXE or iPXE boot settings, boot image delivery rules, VLAN assignments, DNS records, and firewall rules. These settings prepare the server for installation through a controlled network path.

The server then boots from the network and starts automated OS installation. Kickstart, Preseed, Cloud-Init, or similar workflows apply partitioning templates, storage settings, users, SSH keys, certificates, and network configuration. In addition, post-provision scripts install monitoring agents, logging tools, baseline packages, and security settings.

Through this process, the server moves from bare hardware to a configured operating system with limited manual work. The control plane can also record the installation result, update inventory status, and prepare the server for validation.

### Provisioning Validation

The validation stage completes the provisioning process by confirming that the server is ready for production use. Automated checks cover hardware health, RAID layout, disk configuration, host naming, firmware state, network reachability, network throughput, time synchronization, patch level, security baseline, compliance logs, and handoff readiness.

Validation records also reduce production issues by identifying configuration problems before a workload is assigned to the server. In addition, these records make each provisioning result easier to audit. When all checks pass, the control plane can assign the server to a workload or add the server to a resource pool.

## Out-of-Band and Network Provisioning

Bare metal automation often requires hardware control before the operating system is available. Out-of-band management provides this control through a separate management interface. Through this interface, automation tools can power on a server, restart it, change the boot order, mount virtual media, collect hardware inventory, and check hardware health without physical access to the machine.

Redfish is commonly used for modern API-based hardware control. A provisioning system can use Redfish to set the next boot device, restart the server, apply BIOS settings, read sensor data, and prepare the machine for OS installation. Therefore, Redfish turns hardware preparation into a repeatable workflow rather than a manual console task.

Older server environments often still use IPMI for similar hardware actions. Automation tools can use IPMI for remote power control, sensor readings, and serial-over-LAN access. IPMI has known security limitations, so access to it is usually restricted to an isolated management network. Shared passwords are also removed, and administrative actions are logged where possible.

Network-based installation follows hardware preparation. At this stage, PXE or iPXE provides the boot path that starts the installation process from the provisioning environment. In addition, iPXE can fetch installation content over HTTP or HTTPS and use scripted boot logic for different hardware profiles. Through this workflow, a server can move from remote power-on to OS installation with limited manual work.

## Lifecycle Management and Decommissioning

Bare-metal automation applies across the entire server lifecycle, not just during the initial installation. A physical server may pass through several defined states before retirement. Common lifecycle states for bare metal servers include:

- Received
- Racked
- Discovered
- Commissioned
- Provisioned
- Active
- Maintenance
- Quarantine
- Decommissioning
- Retired

These lifecycle states give infrastructure teams a clear way to track the condition and purpose of each physical server. A server can move from early inventory stages into provisioning, then into active use after the operating system and required configuration are applied. If a problem arises later, the server can be moved to maintenance or quarantine until patching, repair, reimaging, or validation is complete.

The same lifecycle model also guides the final removal of a server from production. During decommissioning, a retired server may still contain credentials, configuration data, logs, or sensitive records. Therefore, the decommissioning workflow removes the server from production pools, revokes credentials, removes SSH keys and certificates, wipes local disks, resets BMC users, clears firmware settings where required, and updates asset records.

Once decommissioning tasks are complete, asset recovery records the hardware’s final destination. The record shows whether the server was reused, returned to inventory, sent back to a vendor, recycled, or disposed of through an approved process.

## Automation Tools, DevOps, and BMaaS

Bare metal automation is not handled by a single tool. A practical workflow usually separates infrastructure assignment, server configuration, change approval, and provider-managed deployment. Therefore, teams often use Terraform for infrastructure state management, Ansible for server configuration, CI/CD pipelines for review and testing, and Bare Metal as a Service (BMaaS) platforms to provision dedicated servers via a provider API.

Terraform is an Infrastructure-as-Code tool. It helps teams describe infrastructure resources in configuration files instead of creating them manually. In a bare-metal environment, Terraform can provision servers, assign network profiles, request a BMaaS instance, and connect server changes to DNS, IPAM, firewall, or load balancer resources. Terraform is not usually used to install the operating system. Its main role is infrastructure state management and resource assignment.

Once the server is provisioned, Ansible completes the configuration stage. Ansible is a configuration management tool that installs packages, applies OS hardening, configures users and services, adds monitoring agents, sets up logging, and prepares application dependencies. In this sequence, Terraform defines and tracks the infrastructure, while Ansible prepares the server for operational use.

CI/CD adds review and validation before infrastructure changes are applied to production infrastructure. Git commits, approval steps, validation runs, rebuild workflows, and retained logs help teams review changes and keep evidence of what was changed. In larger bare-metal environments, tools such as Digital Rebar, MAAS, and OpenStack Ironic can extend this workflow through hardware discovery, machine provisioning, workflow orchestration, and private cloud support.

The same automation approach can also extend beyond privately managed data centers. BMaaS platforms provide access to provider-managed physical servers through an API. Through this model, teams can request dedicated hardware without directly managing all data center facilities. This option is useful when teams want bare metal performance but prefer provider-managed provisioning, hardware replacement, networking, and maintenance coordination.

## Common Bare Metal Automation Use Cases

Bare metal automation is useful when physical servers must be deployed, rebuilt, and managed consistently. Its value is most visible in environments that require predictable performance, remote operation, or repeatable testing. The following use cases illustrate where bare-metal automation is commonly applied.

### HPC and AI Clusters

HPC and AI clusters often use GPU servers, shared storage, schedulers, and low-latency networking. In these environments, automation helps teams apply the same firmware baseline, operating system image, driver version, and health checks across compute nodes. Therefore, new nodes can be added to a cluster with less manual work and fewer configuration differences.

### Edge Deployments

The same need for consistency also appears in edge deployments, where servers often run in remote sites with limited staff and bandwidth. Bare metal automation helps teams deploy standard images, configure remote BMC access, apply local recovery settings, and manage bandwidth-aware updates. Operations teams can manage distributed servers with fewer on-site tasks.

### DevOps CI Infrastructure

Bare-metal automation is also useful for DevOps CI infrastructure because test environments often require clean, repeatable server states. Dedicated test runners can be rebuilt between jobs for kernel, driver, container, and performance testing. As a result, development teams receive more reliable test results and fewer environment-related errors.

## Security and Operational Best Practices

Security controls are essential to reliable bare-metal automation because the same tools that provision servers can also modify boot settings, credentials, and system images. Administrative access to controllers, BMCs, CI/CD tools, and automation platforms should follow RBAC and the principle of least privilege. In addition, teams should use MFA, secrets vaulting, credential rotation, and separate management networks to reduce the risk of unauthorized access.

After access controls are defined, management and provisioning traffic also need protection. Provisioning traffic carries boot instructions, images, and configuration data, while management traffic may include administrative actions against BMCs and control plane services. Therefore, these communication paths should use TLS-encrypted data in transit where available. Firmware and OS patching should also follow a tested schedule before broad deployment, because untested updates can affect server stability.

These security controls are more useful when their use can be verified later. Therefore, audit records should include provisioning events, BMC actions, image versions, patch records, wipe evidence, change approvals, and asset IDs. These records show that servers were built, modified, and retired in accordance with documented procedures.

## Migration, Scaling, and Team Adoption

Bare metal automation is usually adopted in stages because physical infrastructure has many dependencies. A rushed rollout can create provisioning errors, network issues, and operational confusion. Therefore, a controlled pilot gives teams a safer way to test the workflow before wider production use.

### Pilot Deployment

A pilot deployment uses representative hardware, a defined source of truth, one provisioning workflow, and clear success measures. During this stage, teams check inventory accuracy, BMC access, network boot, OS installation, validation checks, and rollback procedures. The pilot can also expose problems such as incorrect VLAN assignments, missing hardware records, or outdated firmware before automation is applied to a larger server group.

### Team Readiness

Once the pilot workflow is stable, the focus moves from technical validation to operational readiness. At this stage, SREs, DevOps engineers, and infrastructure teams should become familiar with the control plane, inventory process, approval workflow, and failure handling. Clear documentation for server profiles, OS images, firmware baselines, reimage steps, and rollback procedures reduces reliance on a single expert and makes the process easier to repeat.

### Gradual Scale-Out

After the team and workflow are ready, automation can expand by rack, workload type, hardware profile, or location. Before each expansion, switch ports, VLANs, rack templates, asset records, and batch discovery workflows should be prepared. In addition, each expansion stage should be reviewed through provisioning success rates, failed steps, rollback events, and validation results.

## The Bottom Line

Bare metal automation is most effective when physical infrastructure is managed through clear records, repeatable workflows, and controlled lifecycle processes. It is not only a faster way to install servers. It also helps infrastructure teams reduce configuration errors, improve recovery, and make server operations easier to verify.

In 2026, bare-metal environments for AI, HPC, edge, regulated, and business-critical workloads require practical, measurable automation. This approach depends on accurate inventory, tested provisioning, secure management access, and gradual rollout. With these elements in place, teams can manage physical servers with better consistency, fewer manual errors, and stronger operational control.


---

# Best Enterprise Data Hosting Alternatives to AWS (2026)

> URL: https://www.atlantic.net/cloud-platform/best-enterprise-data-hosting-alternatives-to-aws/ | Published: 2026-07-24 | Author: Hitesh Jethva

The best enterprise data hosting alternatives to AWS in 2026 are Atlantic.Net, IONOS, Hetzner, Contabo, UpCloud, Kamatera, and Leaseweb. Atlantic.Net is the strongest choice for regulated workloads, while the others fit specific needs around cost, performance, dedicated infrastructure, IaaS control, and global reach.

AWS remains a strong platform for teams that need a large service catalog, managed databases, serverless tools, AI services, and deep ecosystem support. But many enterprise workloads do not need hyperscaler, unpredictable billing, or heavy internal platform management.

This guide compares providers by infrastructure options, compliance fit, support model, pricing clarity, workload isolation, and enterprise use case. The goal is not to find a cheaper AWS clone. It is to help you choose the right hosting model for your data, risk, budget, and operational needs.

## What is Enterprise Data Hosting?

Enterprise data hosting is infrastructure built to store, process, secure, and deliver business-critical data at production scale. It is not just “a server.” It is the combination of compute, storage, networking, security controls, support, uptime commitments, and operational processes that keep important applications running.

For small projects, a basic VPS may be enough. Enterprise workloads need uptime, backups, security controls, and support escalation. They often require high-availability design, documented recovery processes, dedicated or isolated resources, stronger access controls, predictable support escalation, and contracts that define what happens if service levels are missed.

The category usually includes managed cloud servers, dedicated servers, bare metal, private cloud, hybrid cloud, compliant hosting, database hosting, backup infrastructure, and disaster recovery environments. In regulated sectors, the hosting platform may also need to support HIPAA, PCI, SOC reporting, audit evidence, encryption, logging, network segmentation, and role-based access.

Healthcare workloads add another layer. When a cloud service provider creates, receives, maintains, or transmits electronic Protected Health Information (ePHI) for a covered entity or business associate, [HHS says](https://www.hhs.gov/hipaa/for-professionals/faq/2075/may-a-hipaa-covered-entity-or-business-associate-use-cloud-service-to-store-or-process-ephi/index.html?) the parties must enter into a HIPAA-compliant HIPAA Business Associate Agreement (BAA), and the customer must still run its own risk analysis and risk management process.

Enterprise data hosting requires support that can handle production issues, audit requests, migrations, backups, access controls, and network changes under real business pressure. The question is not only “Can this provider run a server?” The better question is “Can this provider help when production systems, audits, migrations, backups, access policies, or network rules become urgent?” That is where managed service depth, documentation, escalation paths, and real engineers separate enterprise hosting from commodity hosting.

## Why Look Beyond AWS in 2026?

AWS remains a major cloud platform and is often the right choice for teams that need a huge service catalog, global regions, managed databases, serverless tooling, advanced AI services, and deep ecosystem support. The case for looking beyond AWS is not that AWS is weak. Many enterprise workloads do not need AWS’s full service catalog or billing.

Cost predictability is often the first reason enterprises evaluate AWS alternatives. Hyperscaler billing can be difficult to forecast when workloads use many services, data transfer, snapshots, managed databases, monitoring, support plans, and discount commitments.

Vendor lock-in is another reason enterprises consider AWS alternatives. The more a workload depends on provider-specific databases, queues, IAM policies, serverless services, deployment templates, and monitoring tools, the harder it becomes to move. That does not make those services bad. It means the architecture should match the business’s tolerance for migration risk.

Support overhead is another reason enterprises look beyond AWS. Large hyperscalers give teams powerful controls, but the customer often owns design, tuning, security configuration, incident response, cost governance, and service selection. That works for mature platform teams. It can slow down companies that want managed infrastructure, direct engineering support, and fewer moving parts.

[Gartner’s cloud cost management guidance](https://www.gartner.com/en/documents/7066498) emphasizes aligning cloud spending with business value through better architecture, vendor choices, and pricing model decisions. That shift favors enterprise hosting providers that make infrastructure costs easier to predict, allocate, and connect to real business outcomes.

## What Should Enterprises Check Before Choosing a Data Hosting Provider?

Use this checklist before choosing a provider:

- Does the provider support the required compliance model, such as HIPAA-compliant hosting, PCI-compliant hosting, or audit-ready dedicated infrastructure?
- Will the provider sign a BAA when ePHI is involved?
- Are workloads isolated through single-tenant, dedicated, private cloud, or clearly segmented cloud resources?
- Are backup, restore, monitoring, firewall, VPN, and incident response options included or sold separately?
- Are support tiers clear, including after-hours escalation and engineer access?
- Does the pricing model match the workload, or will traffic, backups, licensing, support, and storage create surprise costs?
- Can the provider support high-availability architecture across zones, data centers, or regions?
- Are SLA terms specific enough to evaluate credits, exclusions, and customer responsibilities?
- Can the platform support migration without forcing a complete application rebuild?
- Does the provider fit the team’s skills: managed, semi-managed, or self-managed?

## Top 7 Enterprise Data Hosting Solutions 2026

### #1 – Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

Best for: Regulated enterprises that need managed cloud, dedicated infrastructure, HIPAA-compliant hosting, PCI-compliant hosting, U.S.-based support, and strong SLAs without a hyperscaler.

Atlantic.Net is the strongest fit for regulated businesses that need secure enterprise data hosting without adopting a large hyperscaler model. It supports managed cloud, dedicated servers, bare metal, GPU hosting, and custom infrastructure for teams that want direct hosting accountability. Atlantic.Net is not trying to copy a hyperscaler catalog. It is a focused hosting provider for secure, managed, compliance-aware infrastructure.

Key Specs: Managed cloud, dedicated servers, bare metal, GPU hosting, private cloud, compliant hosting, and custom configurations.

Compliance: HIPAA-compliant and PCI-compliant hosting options, with BAA support for workloads involving electronic Protected Health Information (ePHI).

Support: 24/7 support options with access to technical hosting specialists.

What Stands Out:

- Supports regulated workloads where ePHI, BAA terms, encryption, backups, firewalling, VPNs, and audit-ready safeguards matter.
- Reduces internal overhead by giving teams a managed path for production hosting, security controls, monitoring, and infrastructure support.
- Offers dedicated, bare metal, GPU, private cloud, and custom hosting options when workload isolation or performance matters.

Who Should Choose Atlantic.Net?: Choose Atlantic.Net when compliance, managed operations, and dedicated infrastructure matter more than access to hundreds of cloud-native services.

### #2 – IONOS

![](https://www.atlantic.net/wp-content/uploads/2025/08/ionos-logo.png)

Best for: Enterprises that want straightforward cloud, VPS, and dedicated hosting with clearer packaging than a hyperscaler.

IONOS is a strong AWS alternative for teams that want broad hosting options without a sprawling service catalog. IONOS offers VPS, cloud, and dedicated hosting for more demanding business and ecommerce sites, with data centers in the U.S. and Europe and support through a knowledge base, phone, live chat, and email.

Key Specs: VPS hosting, cloud hosting, dedicated hosting, Windows and Linux options, and business hosting plans.

Compliance: Better suited to general business hosting than compliance-first workloads. Verify HIPAA, PCI, or audit-specific needs before use.

Support: Knowledge base, phone, chat, email, and localized support options depending on plan and market.

What Stands Out:

- Covers common infrastructure needs without forcing buyers into a large cloud-native service catalog.
- Fits websites, ecommerce systems, internal tools, Windows workloads, Linux apps, and standard business hosting.
- Gives buyers a clearer path to VPS, cloud, or dedicated hosting than a complex consumption-based platform.

Who Should Choose IONOS? Choose IONOS when you need straightforward business hosting with less platform overhead than AWS.

### #3 – Hetzner

![](https://www.atlantic.net/wp-content/uploads/2026/03/hetzner-logo.png)

Best for: Experienced teams that want no-frills, reliable infrastructure at strong value.

Hetzner is widely respected by developers and infrastructure teams that want practical cloud and dedicated resources without excessive abstraction. Hetzner Cloud uses KVM virtualization on its own hardware in its own data centers, giving it direct control over maintenance windows and hardware replacement.

Key Specs: Cloud servers, dedicated servers, storage options, KVM-based cloud infrastructure, and owned infrastructure.

Compliance: Better for general enterprise infrastructure than regulated healthcare or payment workloads requiring specialized managed compliance support.

Support: Best suited to self-managed teams with infrastructure, Linux, networking, and security skills.

What Stands Out:

- Strong value for teams that can configure, secure, and maintain infrastructure themselves.
- Useful for app hosting, development, staging, internal tools, test clusters, and self-managed production systems.
- Keeps the platform simple by focusing on infrastructure rather than a large catalog of managed services.

Who Should Choose Hetzner?: Choose Hetzner when price-performance and direct infrastructure control matter more than managed compliance support.

### #4 – Contabo

![contabo_logo](https://www.atlantic.net/wp-content/uploads/2025/10/contabo_logo.png)

Best for: Cost-effective enterprises that need VPS or dedicated capacity and can tolerate trade-offs in support and performance consistency.

Contabo is attractive because it offers large resource allocations at low prices. Contabo is known for affordable VPS plans, but it also flags performance and support limitations, including no phone support and weaker performance results in testing.

Key Specs: VPS, storage-focused VPS, dedicated servers, NVMe or SSD options, high RAM allocations on larger plans.

Compliance: Better for cost-controlled infrastructure than specialized regulated hosting.

Support: Email, ticket, and live chat options

What Stands Out:

- Offers a strong price-to-resource ratio for teams that need more CPU, RAM, or storage for the money.
- Fits development, staging, internal tools, batch jobs, sandboxes, and secondary workloads.
- Requires production testing for disk performance, network behavior, support response, restore times, and failover assumptions.

Who Should Choose Contabo?: Choose Contabo if infrastructure cost is the top constraint and your team can test, monitor, and manage risk carefully.

### #5 – UpCloud

![](https://www.atlantic.net/wp-content/uploads/2025/08/upcloud_logo_horizontal.png)

Best for: Teams that want high-performance cloud servers with simple, predictable pricing.

UpCloud is a strong AWS alternative for performance-sensitive cloud workloads that do not require the full hyperscaler catalog. UpCloud stands out for its 24/7 support, fast server deployment, global data center network, flexible pricing, and high-performance MaxIOPS storage. However, it may feel less beginner-friendly than simpler hosting platforms.

Key Specs: Cloud servers, MaxIOPS block storage, simple and flexible pricing structures, public and private cloud options.

Compliance: Suitable for general enterprise workloads; verify sector-specific compliance needs before hosting regulated data.

Support: 24/7 support through live chat, email, and phone.

What Stands Out:

- Good fit for databases, APIs, SaaS platforms, ecommerce apps, and other I/O-heavy systems.
- Easier to model than complex consumption-based architectures because the cloud model is simpler.
- Gives technical teams control over server sizing, deployment, networking, backups, and monitoring.

Who Should Choose UpCloud?: Choose UpCloud if you want fast cloud servers and simpler pricing without the service sprawl of a hyperscaler.

### #6 – Kamatera

![](https://www.atlantic.net/wp-content/uploads/2025/12/kamatera-logo-1.png)

Best for: Enterprises that want granular IaaS control without taking on AWS-level service.

Kamatera offers a highly configurable IaaS model for buyers that want to tune CPU, RAM, storage, operating system, data center location, and management level. Kamatera is a flexible, scalable, and highly customizable cloud platform suited to enterprise workloads, though it is a better fit for experienced users than beginners.

Key Specs: Cloud servers, virtual private cloud, firewalls, load balancers, block storage, managed service options, global data centers.

Compliance: Useful for enterprise infrastructure, but regulated workloads should verify contractual and technical compliance requirements before deployment.

Support: Offers 24/7 support and multiple management levels for teams that want extra operational help.

What Stands Out:

- Lets teams tune cloud servers around workload needs instead of buying fixed bundles.
- Supports global and variable workloads that need location choice and flexible scaling.
- Offers unmanaged and managed paths, giving buyers more control over the operating model.

Who Should Choose Kamatera?: Choose Kamatera if you want fine-grained IaaS control and global reach without adopting a hyperscaler operating model.

### #7 – Leaseweb

![](https://www.atlantic.net/wp-content/uploads/2026/07/logo-login-lsw.png)

Best for: Enterprises that need global dedicated server hosting with a straightforward commercial model.

Leaseweb is a good fit for companies that want dedicated servers, hybrid hosting, and infrastructure services across multiple regions. [Gartner Peer](https://www.gartner.com/reviews/product/leaseweb-managed-hybrid-cloud-hosting-services) recognizes Leaseweb under managed hybrid cloud hosting and provides verified customer review data for its managed hybrid cloud hosting services.

Key Specs: Dedicated servers, hybrid cloud hosting, managed hosting, colocation, and infrastructure services.

Compliance: Better suited to dedicated and hybrid infrastructure planning than out-of-the-box regulated hosting; confirm compliance scope by workload and region.

Support: Enterprise support depends on service type and contract terms.

What Stands Out:

- Strong fit for workloads that need physical hardware, single-tenant deployments, or predictable dedicated capacity.
- Useful for SaaS, ecommerce, media, gaming, and high-traffic platforms with regional infrastructure needs.
- Dedicated and hybrid contracts can be easier to model than complex consumption-based cloud billing.

Who Should Choose Leaseweb?: Choose Leaseweb if you need global dedicated servers and want a more direct infrastructure model.

## Comparison Table: Best Enterprise Data Hosting Solutions

| **Provider** | **Best For** | **Infrastructure Fit** | **Compliance Fit** | **Support Fit** | **Main Trade-off** |
| --- | --- | --- | --- | --- | --- |
| Atlantic.Net | Regulated enterprise data hosting | Managed cloud, dedicated, bare metal, GPU | Strong fit for HIPAA-compliant and PCI-compliant hosting | 24/7 support with technical escalation | Less hyperscaler service breadth |
| IONOS | Straightforward cloud and dedicated hosting | VPS, cloud, dedicated | General business hosting | Phone, chat, email, knowledge base | Less specialized for regulated hosting |
| Hetzner | Value-focused infrastructure | Cloud and dedicated servers | General infrastructure | Better for self-managed teams | Less managed compliance support |
| Contabo | Low-cost VPS and dedicated capacity | VPS, storage VPS, dedicated | General infrastructure | Email, ticket, live chat | Performance and support trade-offs |
| UpCloud | High-performance cloud servers | Cloud servers and private cloud options | General enterprise workloads | 24/7 support | Better for technical teams |
| Kamatera | Flexible IaaS control | Cloud servers, VPC, firewalls, load balancers | General enterprise workloads | 24/7 support and management tiers | Management costs need planning |
| Leaseweb | Global dedicated servers | Dedicated, hybrid, colocation | Contract-specific | Enterprise support by service | Less cloud-native service breadth |

## How should enterprises choose an AWS alternative?

Choose the hosting provider based on the workload’s technical, compliance, and support requirements. A healthcare SaaS platform that stores ePHI has different needs from a media delivery platform, an internal analytics server, or a staging environment. The right provider depends on risk, compliance, latency, support, and cost control.

For regulated workloads, begin with compliance scope. Ask whether the provider supports HIPAA-compliant hosting, whether it will sign a BAA, and which safeguards are included. HHS makes clear that a BAA is required when a cloud service provider handles ePHI for a covered entity or business associate. However, the customer still owns risk analysis and policy decisions.

For cost-sensitive workloads, model the full monthly bill. Include compute, storage, backups, snapshots, bandwidth, licenses, monitoring, support, and migration costs. Low server pricing can still become expensive if backups, traffic, or hands-on support are billed separately.

For high-availability systems, verify the infrastructure design behind the uptime claim. Ask how the environment is built. Look for redundant power, redundant network paths, restore testing, failover design, backup retention, incident response, and SLA exclusions.

For platform teams, decide how much control you want. Hetzner, Contabo, UpCloud, and Kamatera can be a good fit for technical users. Atlantic.Net and Leaseweb fit buyers that want more direct infrastructure or managed hosting. IONOS works well for teams that want a broad but familiar hosting model.

## When should an enterprise not choose a smaller AWS alternative?

Do not choose a smaller provider only because the base server price looks lower. That can backfire if the workload needs managed databases, event streaming, advanced IAM, global edge services, AI tooling, or deep automation that the provider does not offer.

Also avoid under-scoping support. If your team cannot manage Linux hardening, firewall rules, backups, patching, monitoring, restore tests, access control, and incident response, choose a provider with managed service depth. A lower monthly bill does not help if your team loses time during outages or audits.

Smaller providers are strongest when the workload is clear, the infrastructure design is simple, and the business values predictable hosting over a huge platform catalog.

## When is Atlantic.Net the right choice?

Atlantic.Net is the right choice when compliance, managed support, and dedicated infrastructure matter more than access to hundreds of cloud-native services. It is especially strong for healthcare, payments, SaaS, and private data workloads where teams want a hosting partner that understands regulated infrastructure.

Atlantic.Net is a strong fit for enterprises that want managed, compliance-focused infrastructure without having to assemble a hosting stack from many separate services. Instead of requiring buyers to assemble a hosting platform from multiple services, Atlantic.Net offers managed cloud, dedicated servers, bare metal, GPU hosting, and compliance-oriented hosting under a single provider model. As per [TechRadar’s review](https://www.techradar.com/pro/website-hosting/atlantic-net-review), Atlantic.Net is positioned as a technical, compliance-focused hosting provider, with specific mention of its HIPAA and PCI hosting options.

Atlantic.Net is a strong fit for enterprises that need secure, managed, compliance-focused hosting without a hyperscaler. It is not trying to mirror AWS. It is a more direct option for companies that want managed infrastructure, compliance support, and fewer architectural decisions.

## FAQ

**What is the best enterprise data hosting alternative to AWS in 2026?**

Atlantic.Net is the best choice for regulated enterprise data hosting. It combines managed cloud, dedicated servers, HIPAA-compliant hosting, PCI-compliant hosting, and U.S.-based support.

**Why do enterprises look for AWS alternatives?**

Enterprises often want simpler billing, less lock-in risk, direct support, dedicated infrastructure, and managed compliance hosting. AWS fits complex cloud-native systems, but many data workloads need reliability, compliance, and support first.

**Which provider is best for HIPAA-compliant data hosting?**

Atlantic.Net is the best fit on this list for HIPAA-compliant data hosting. It supports compliance-focused hosting and BAA requirements for electronic Protected Health Information (ePHI).

**Which AWS alternative is cheapest?**

Contabo and Hetzner are strong cost-focused options. Hetzner fits experienced teams. Contabo can work for lower-cost workloads, but buyers should test performance and support first.

**Is enterprise data hosting the same as cloud hosting?**

No. Cloud hosting is one delivery model. Enterprise data hosting can include managed cloud, dedicated servers, bare metal, private cloud, hybrid hosting, backups, compliance controls, and disaster recovery.

**Are smaller cloud providers safe for enterprise workloads?**

Yes, when security, backups, compliance, support, and SLAs match the workload.

**What is the best AWS alternative for healthcare data?**

Atlantic.Net is the strongest fit from this list for healthcare workloads because it supports HIPAA-compliant hosting and BAA-backed hosting models for ePHI.

**Is multi-cloud better than choosing one provider?**

Not always. Multi-cloud can reduce vendor dependence, but it also adds cost and operational complexity. Many enterprises do better by choosing the right primary host and keeping key workloads portable.


---

# Best Rackspace Alternatives for Enterprise Hosting (2026)

> URL: https://www.atlantic.net/cloud-platform/best-rackspace-alternatives-enterprise-hosting/ | Published: 2026-07-24 | Author: Hitesh Jethva

The best enterprise data hosting alternatives to Rackspace in 2026 are Atlantic.Net, Oracle Cloud Infrastructure, Flexential, Expedient, DataBank, Ntirety, and TierPoint. Atlantic.Net is the strongest direct alternative for companies that need managed cloud hosting, dedicated infrastructure, private cloud, HIPAA-compliant hosting, PCI-compliant hosting, and U.S.-based support.

Rackspace still serves enterprises that need managed cloud and infrastructure services. But many teams now want clearer pricing, stronger compliance fit, more direct support, or infrastructure that better matches their workload.

This guide compares Rackspace alternatives by managed hosting capabilities, compliance support, private and hybrid cloud options, disaster recovery, data center reach, support model, and enterprise use case. The goal is not to find a one-for-one Rackspace clone. It is to help you choose the right provider for your data, risk, budget, and operational needs.

## What Is Enterprise Data Hosting?

Enterprise data hosting is managed infrastructure for organizations that need secure, reliable, and closely supported environments for business-critical data and applications. It can include managed cloud hosting, dedicated server hosting, private cloud, colocation, storage, backup, disaster recovery, network security, monitoring, and compliance support.

This is not the same as basic web hosting. A brochure website can run on a simple hosting plan. Enterprise data hosting supports systems that affect revenue, operations, patient care, customer trust, or regulatory exposure. These systems often need high-availability design, controlled access, encrypted backups, documented support processes, and clear recovery plans.

Enterprise buyers usually care about more than CPU, RAM, and storage. They need to know who patches the operating system, who monitors alerts, who restores backups, who handles firewall changes, who responds during an outage, and who can provide documentation during an audit. That is why managed hosting remains important in 2026.

Compliance also shapes the buying process. Healthcare workloads that create, receive, maintain, or transmit electronic Protected Health Information (ePHI) must protect that data under the HIPAA Security Rule. [HHS](https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html) states that covered entities and business associates must use administrative, physical, and technical safeguards to protect ePHI. HHS also states that a cloud service provider handling ePHI on behalf of a covered entity or business associate generally needs a HIPAA Business Associate Agreement (BAA).

For payment-related workloads, buyers often need PCI DSS support. For SaaS, healthcare, finance, legal, and public-sector vendors, the real need is usually broader: infrastructure that can support customer security reviews, vendor risk questionnaires, access control policies, backup evidence, incident response plans, and separation between production and non-production systems.

The best enterprise data hosting provider does not simply rent servers. It helps reduce operational risk.

## Why Look Beyond Rackspace In 2026?

Rackspace is still known for managed hosting and managed service delivery. Rackspace’s managed hosting background shapes what buyers expect from alternatives. A company searching for a Rackspace alternative is usually not looking for a cheap, unmanaged cloud account. The buyer often wants the same managed model, but with clearer pricing, stronger compliance fit, more flexible architecture, and support that understands production systems.

The reasons to compare alternatives usually fall into four groups.

First, pricing can become harder to forecast as environments grow. Enterprise hosting contracts may include compute, storage, backup retention, firewall services, migration work, monitoring, support tiers, compliance services, and bandwidth. A renewal can look very different from the original quote if those parts are not separated clearly.

Second, managed service scope can vary. Some providers manage the full infrastructure stack. Others monitor only basic availability. A buyer should know whether the provider handles patching, backup and restore support, firewall policy changes, operating system issues, incident coordination, and disaster recovery testing.

Third, lock-in can slow modernization. Many Rackspace customers run mature workloads with databases, private networking, legacy dependencies, and strict maintenance windows. Moving those systems requires planning. The best alternative should support staged migration, hybrid IT, private cloud, dedicated infrastructure, and multi-cloud connectivity where needed.

Fourth, support expectations are higher in 2026. IT teams want fast escalation to people who understand infrastructure. They do not want to explain a production outage repeatedly through a generic ticket queue. They want clear ownership, named responsibilities, and engineers who can help during migrations, audits, and incidents.

The providers below are not generic cloud names. They are options for enterprises that still value managed infrastructure.

## How To Choose An Enterprise Data Hosting Provider

Choose a provider based on workload risk, compliance needs, recovery goals, and support scope.

A healthcare SaaS application that handles ePHI has different needs than an internal analytics platform. A payment application has different needs than a legacy ERP system. A private database cluster has different needs than a public-facing web app.

Use these checks before you shortlist providers:

- **Managed responsibility:** Confirm who owns patching, monitoring, backup jobs, firewall changes, operating system issues, and incident response.
- **Compliance support:** Ask whether the provider can support HIPAA-compliant hosting, PCI-compliant hosting, audit evidence, access controls, and a BAA where required.
- **Migration process:** Look for dependency mapping, test restores, cutover planning, rollback steps, and post-migration validation.
- **Architecture fit:** Decide whether you need cloud servers, private cloud, dedicated servers, colocation, DRaaS, or a hybrid design.
- **Support depth:** Ask whether 24/7 support includes engineer escalation, not only ticket intake.
- **Cost clarity:** Separate infrastructure costs from managed services, backup retention, bandwidth, support tiers, and migration work.

A good Rackspace alternative should make those answers clear before the contract is signed.

## Best Enterprise Data Hosting Solutions That Aren’t Rackspace

### #1 – Atlantic.Net

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

Atlantic.Net is the best direct alternative for organizations that want the managed hosting model without moving into a low-touch cloud account. It offers managed cloud hosting, dedicated hosting, private cloud, backup, security, HIPAA-compliant hosting, and PCI-compliant hosting. [TechRadar](https://www.techradar.com/pro/website-hosting/atlantic-net-review) describes Atlantic.Net as a long-running hosting provider focused on infrastructure and compliance-driven hosting, with cloud hosting, GPU servers, dedicated servers, bare metal, HIPAA hosting, and PCI hosting.

Atlantic.Net fits regulated teams that need managed infrastructure plus HIPAA or PCI support. It is especially strong for buyers who want to move from one managed hosting provider to another, not rebuild operations from scratch.

- **Managed cloud and dedicated infrastructure:** Atlantic.Net supports cloud, dedicated, and private hosting patterns. This helps teams isolate databases, separate regulated workloads, and design around application limits.
- **HIPAA-compliant and PCI-compliant hosting:** Atlantic.Net is a strong fit for healthcare workloads that handle ePHI and need a BAA. It also fits payment-related environments that need PCI-compliant hosting support and clear infrastructure controls.
- **Migration-friendly managed model:** Rackspace buyers often need help with cutover timing, backup validation, firewall rules, and dependency checks. Atlantic.Net is a better fit when the migration requires provider help with cutover, firewall rules, and backup validation.
- **US-based support and direct infrastructure focus:** Atlantic.Net works well for teams that want engineer-led help with infrastructure issues. That is important when the workload is regulated, customer-facing, or tied to revenue.
- **Where it may not fit:** Atlantic.Net may not be the right first choice for companies that want a hyperscale cloud marketplace with hundreds of native platform services. It is better for buyers that value managed hosting, compliance support, and direct infrastructure control.

### #2 – Oracle Cloud Infrastructure

![](https://www.atlantic.net/wp-content/uploads/2025/08/Oracle-cloud-infrastructure.png)

Oracle Cloud Infrastructure is a strong choice for large enterprises that need cloud infrastructure, database depth, data residency options, and formal governance. It is not a like-for-like managed host in the same way as Atlantic.Net, but it works well for enterprise cloud programs with strong internal IT teams. [Gartner](https://www.gartner.com/reviews/product/oci-dedicated-region) describes OCI Dedicated Region as a managed cloud environment that can run in a customer data center while supporting compute, storage, databases, networking, security, data residency, and regulatory needs.

OCI is best for organizations with complex application estates, database-heavy systems, and internal cloud operations maturity. It gives enterprises more platform depth than a traditional managed hosting provider, but it also demands stronger cloud architecture discipline.

- **Enterprise cloud and database fit:** OCI fits database-heavy workloads that need private connectivity, governance, and enterprise cloud controls. It gives large teams a way to standardize infrastructure without forcing every system into one deployment style.
- **Dedicated and regulated deployment options:** OCI Dedicated Region can support workloads that need tighter control over location, governance, and operating boundaries. That matters for organizations with data residency or sector-specific requirements.
- **Hybrid and multi-cloud planning:** OCI can support enterprise modernization projects where some workloads move to cloud while others remain closer to private infrastructure. Buyers should define identity, networking, logging, backup, and operating responsibility before migration.
- **Internal skills requirement:** OCI is powerful, but it is not the easiest replacement for a team that wants the provider to manage most infrastructure details. Companies should plan for cloud architecture, cost management, and platform governance.
- **Where it may not fit:** OCI may be too platform-heavy for organizations that only want managed servers, compliance hosting, and hands-on infrastructure support.

### #3 – Flexential

![](https://www.atlantic.net/wp-content/uploads/2026/07/flexissential.jpeg)

Flexential is a strong option for enterprises that need hybrid IT, colocation, cloud connectivity, disaster recovery, and managed infrastructure. It is well positioned for companies that cannot move everything to public cloud and need a provider with data center depth.

Flexential fits regulated industries, regional enterprises, and companies with complex physical and virtual infrastructure. It is useful when the migration away from Rackspace includes private equipment, hosted systems, cloud links, and recovery planning.

- **Hybrid IT strength:** Flexential works well when an environment includes colocated hardware, managed infrastructure, private cloud, and cloud connectivity. That gives enterprises a bridge between legacy systems and newer deployment models.
- **Data center-backed reliability:** [Gartner’s](https://www.gartner.com/reviews/product/flexential-data-center-colocation-services) colocation category description highlights the role of secure space, remote monitoring, access control, environmental management, backup power, connectivity, and compliance support in colocation decisions. Those are the controls buyers should validate during evaluation.
- **Interconnection and private networking:** Flexential is a practical fit when applications need low-latency connectivity to users, clouds, carriers, or partner systems. That can matter more than raw compute pricing for enterprise data hosting.
- **Good fit for staged migrations:** Enterprises leaving Rackspace may need to move in phases. Flexential’s hybrid IT focus helps when some systems stay on dedicated hardware while others move to cloud or managed platforms.
- **Where it may not fit:** Flexential may be more infrastructure-heavy than a smaller team needs if the requirement is only a managed cloud server or one compliant application stack.

### #4 – Expedient

![](https://www.atlantic.net/wp-content/uploads/2026/07/Expedient.png)

Expedient is a strong alternative for enterprises where disaster recovery, backup, and business continuity are central to the hosting decision. It provides managed infrastructure, cloud, colocation, security, and DRaaS capabilities. [Gartner](https://www.gartner.com/reviews/market/disaster-recovery-as-a-service) lists Expedient Push Button Disaster Recovery in the DRaaS category, where DRaaS tools are evaluated for backup, recovery, failover, failback, and downtime reduction.

Expedient is especially useful when a company is leaving Rackspace because the current environment does not meet recovery expectations. If the board, insurer, regulator, or customers are asking about recovery time, recovery testing, and outage impact, Expedient belongs on the shortlist.

- **Disaster recovery focus:** Expedient is strongest when buyers need tested failover, restore validation, and documented recovery plans.
- **Managed infrastructure plus resilience planning:** Backups alone are not enough; buyers should verify recovery testing, failback steps, and RTO/RPO targets. Expedient fits organizations that need to prove they can restore systems, not just store backup files.
- **Hybrid workload support:** Expedient can make sense when recovery planning spans cloud, private infrastructure, and colocated systems. That is common in mature enterprise environments.
- **Good for audit-driven recovery requirements:** Regulated companies may need evidence that recovery plans are tested. Expedient’s DRaaS orientation helps teams align hosting with business continuity expectations.
- **Where it may not fit:** Expedient may be less compelling if disaster recovery is not a major priority and the buyer mainly needs compliant managed cloud hosting.

### #5 – DataBank

![](https://www.atlantic.net/wp-content/uploads/2026/07/DATABANK_Logo.jpg)

DataBank is a strong fit for organizations that want managed hosting backed by a large data center and interconnection footprint. It supports enterprise data center, cloud, interconnection, and managed service needs.

DataBank fits larger enterprise environments where facility location, network access, data center operations, and managed services are all part of the decision. It is less about simple server replacement and more about where critical infrastructure should live.

- **Facility-backed hosting:** DataBank fits teams that need controlled data center space, private cabinets, redundant power, cooling, and secure facility access.
- **Interconnection value:** DataBank is a good fit for workloads that need private connections to carriers, clouds, customers, or partner systems. Private interconnection can lower latency and keep sensitive traffic off the public internet.
- **Managed services for larger environments:** DataBank can support companies that need help operating infrastructure across hosted systems, data centers, and cloud-connected environments. That is useful when internal teams are stretched.
- **Compliance-ready hosting foundation:** Data center-backed providers can support audit needs tied to physical security, access logs, redundancy, and operational controls. Buyers should confirm which controls apply to the exact facility and service package.
- **Where it may not fit:** DataBank may be more than needed for a small application team that only wants managed cloud hosting with compliance support.

### #6 – Ntirety

![](https://www.atlantic.net/wp-content/uploads/2026/07/Ntirety.png)

Ntirety is a strong choice for regulated organizations that need managed infrastructure, security, and compliance lifecycle support. It fits buyers that want a provider involved in more than server uptime. [Gartner](https://www.gartner.com/reviews/vendor/ntirety) lists Ntirety in enterprise software and services reviews, including risk and compliance tools. At the same time, DataCenters.com states that Ntirety operates data centers under an ITIL-based control environment validated for HIPAA, PCI DSS, and SOC.

Ntirety fits teams that need ongoing compliance support, evidence collection, monitoring, and remediation help. That includes healthcare, finance, SaaS, and professional services companies facing customer security reviews or formal audit requirements.

- **Compliance lifecycle support:** Ntirety is a good fit when the buyer needs assessment, remediation support, monitoring, and evidence collection. That is different from a provider that only offers infrastructure and leaves compliance operations to the customer.
- **Security and infrastructure alignment:** Regulated workloads need security controls that match the hosting design. Ntirety’s positioning around managed infrastructure, security, data services, and compliance helps teams align those areas.
- **Useful for lean IT teams:** Some enterprises do not have enough internal compliance engineering staff. Ntirety can help close that gap by supporting ongoing control management and risk reduction.
- **Good fit for customer-facing regulated SaaS:** SaaS companies that sell into healthcare, finance, or enterprise accounts often need to answer detailed vendor risk questionnaires. Ntirety’s compliance focus can support that process.
- **Where it may not fit:** Ntirety may not be the best match for buyers that only want straightforward infrastructure hosting without managed security or compliance involvement.

### #7 – TierPoint

![](https://www.atlantic.net/wp-content/uploads/2026/07/TierPoint.jpg)

TierPoint is a practical alternative for enterprises that need managed cloud, colocation, disaster recovery, cybersecurity, and regional data center services. It works well for companies that want a provider with both cloud and physical infrastructure capabilities. [Gartner](https://www.gartner.com/reviews/product/tierpoint-data-center-colocation-services) reviewers describe TierPoint colocation and DRaaS use cases.

TierPoint is a good fit for mid-market and enterprise buyers that want managed IT services without losing access to physical data center support. It is also relevant for healthcare and compliance-aware environments when scoped correctly.

- **Managed cloud plus colocation:** TierPoint fits companies that need cloud services and physical hosting under one provider relationship. That can reduce costs when workloads are split between virtual platforms and hardware.
- **Regional data center presence:** TierPoint can be useful when location matters for latency, staff access, customer proximity, or regional recovery. This helps teams that still need physical access, regional recovery sites, or hardware support.
- **Disaster recovery and managed services:** TierPoint is a strong fit when hosting is tied to DR planning, cybersecurity, and infrastructure operations. Buyers should define recovery targets, backup retention, and testing expectations in writing.
- **Physical security and operations support:** TierPoint can work well for organizations colocating equipment or running hybrid IT environments that require controlled facilities, stable operations, and hands-on infrastructure support.
- **Where it may not fit:** TierPoint may not be the best choice if the buyer wants a cloud-only provider with a large catalog of native platform services.

## Comparison Table: Best Rackspace Alternatives In 2026

| **Provider** | **Managed Hosting Fit** | **Hybrid IT Fit** | **Compliance Fit** | **DR Strength** | **Best For** | **Watch For** |
| --- | --- | --- | --- | --- | --- | --- |
| Atlantic.Net | High | Medium | High | Medium | Direct managed cloud and compliance hosting replacement | Better for managed infrastructure than hyperscale platform services |
| Oracle Cloud Infrastructure | Medium | High | High | Medium | Enterprise cloud, databases, governance, and data residency | Requires stronger internal cloud skills |
| Flexential | High | High | High | Medium | Colocation, cloud connectivity, and hybrid IT | Best fit for larger infrastructure projects |
| Expedient | High | High | Medium | High | DRaaS, business continuity, and managed infrastructure | Most when recovery is a top requirement |
| DataBank | High | High | High | Medium | Data center-backed hosting and interconnection | Better for larger environments than simple cloud hosting |
| Ntirety | High | Medium | High | Medium | Managed compliance, security, and regulated workloads | Less relevant for basic hosting needs |
| TierPoint | High | High | Medium | High | Managed cloud, colocation, and regional data center services | Confirm exact compliance scope by service and facility |

## Final Recommendation

For most companies searching for “best enterprise data hosting solutions that aren’t Rackspace,” Atlantic.Net should be the first provider to evaluate. It keeps the managed hosting model, supports regulated workloads, and gives teams a clear path to managed cloud hosting, dedicated hosting, private cloud, HIPAA-compliant hosting, and PCI-compliant hosting.

Oracle Cloud Infrastructure is better when the project is part of a large enterprise cloud program. Flexential, DataBank, and TierPoint are stronger when data center facilities, colocation, and hybrid IT matter. Expedient should be high on the list when the main issue is disaster recovery. Ntirety is a strong fit when security and compliance operations need more structure.

The right choice depends on what you are replacing. If you want managed hosting with compliance support and direct infrastructure help, evaluate Atlantic.Net first. Then compare every other provider against migration risk, compliance scope, recovery targets, and support depth.

## FAQs

**What Is The Best Rackspace Alternative For Managed Enterprise Hosting?**

Atlantic.Net is the best direct alternative for companies that want managed cloud hosting, dedicated infrastructure, HIPAA-compliant hosting, PCI-compliant hosting, private cloud, and US-based support. It matches the managed hosting intent better than self-service cloud platforms.

**Is Enterprise Data Hosting The Same As Cloud Hosting?**

No. Cloud hosting is one model inside enterprise data hosting. Enterprise data hosting can include cloud servers, private cloud, dedicated servers, colocation, backup, disaster recovery, managed security, monitoring, and compliance support.

**What Should Healthcare Companies Check Before Choosing A Hosting Provider?**

Healthcare companies should confirm whether the provider can sign a HIPAA BAA, support safeguards for electronic Protected Health Information (ePHI), document security responsibilities, and assist with backup, access control, logging, and incident response requirements.

**Which Rackspace Alternative Is Best For Disaster Recovery?**

Expedient is the strongest disaster recovery option in this list. It is best for organizations that need DRaaS, recovery testing, failover planning, backup validation, and documented business continuity support.

**What Is The Safest Way To Migrate Away From Rackspace?**

Start with discovery. Map applications, databases, DNS, firewall rules, backup schedules, access controls, dependencies, and maintenance windows. Then test backup restores, define rollback steps, migrate lower-risk workloads first, and validate performance before moving business-critical systems.


---

# How to Install OpenClaw on an Atlantic.Net Cloud Server

> URL: https://www.atlantic.net/cloud-platform/how-to-install-openclaw-on-an-atlantic-net-cloud-server/ | Published: 2026-07-29 | Updated: 2026-09-15 | Author: Hitesh Jethva

OpenClaw is a self-hosted AI agent that connects a language model to practical tools, files, messaging channels, and automation workflows. Depending on the integrations you enable, the agent can answer chat messages, organize an inbox, interact with external services, run code, and perform tasks from Telegram, Discord, WhatsApp, or the browser-based Control UI.

You can run OpenClaw on a local Linux machine, dedicated Ubuntu server, VPS, Oracle Cloud instance, or another cloud platform. This guide walks through two primary deployment methods: Atlantic.Net’s OpenClaw Marketplace application and a manual Ubuntu 24.04 installation. It also covers Docker, onboarding, model providers, API keys, the OpenClaw gateway, Telegram, Discord, security, updates, and troubleshooting.

Because an agent may read files, execute commands, use tools, and interact with external systems, a dedicated terminal environment, virtual machine, or cloud server is safer than installing it on a personal laptop containing sensitive data. Docker provides environment isolation and reproducibility, although a standard host installation is usually simpler for beginners.

## Method 1: Install With Atlantic.Net’s OpenClaw Marketplace Application

First, sign in to the [Atlantic.net cloud control panel](https://cloud.atlantic.net).

![OpenClaw install screenshot 1](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/2cd9b0c3-b00d-41d7-bf0a-bad09b02242e.webp)

Go to Servers and click Add Server.

![OpenClaw install screenshot 2](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/3fe81d6f-e3a8-487a-8857-5b41efe90742.webp)

Define your server name in the Server.

Name field, click the Application tab, select OpenClaw, then select the nearest data center location.

![OpenClaw install screenshot 3](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/75bdb9ca-6301-41f6-b30b-7777b1c0b819.webp)![OpenClaw install screenshot 4](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/622879b3-81fd-4553-8286-9a431e5575a8.webp)

Select Term and Plan, then click Create Server. Once the Server is provisioned, you should see the image below.

![OpenClaw install screenshot 5](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/cd69e300-1b37-467b-ab1a-49abd263cd97.webp)

The control panel displays the public IP address and initial login credentials.

Now, open a terminal from your local machine and connect to the OpenClaw instance via SSH using the above credentials:

```
ssh root@YOUR_SERVER_IP
```

You will see a welcome message indicating that OpenClaw is already installed. It recommends completing the initial setup with openclaw onboard –install-daemon.

![OpenClaw install screenshot 6](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/d041bd55-7d44-44b2-b602-92ace9db890d.webp)

## Run The OpenClaw Onboarding Wizard

For a Marketplace installation, you may update the package before onboarding:

```
openclaw update
openclaw --version
```

Start the wizard and install the background daemon:

```
openclaw onboard --install-daemon
```

The wizard walks through model authentication, workspace creation, gateway configuration, channels, skills, and optional tools. QuickStart normally takes only a few minutes, although provider sign-in, downloads, channel pairing, and optional plugins can extend the process.

### Step 1: Accept The Security Disclaimer

![OpenClaw install screenshot 7](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/40cf3ea1-3bbd-4463-a6ba-bffd37242273.webp)

Read the warning carefully. OpenClaw may access files and run tools when those capabilities are enabled. Select Yes and press Enter.

### Step 2: Select Quickstart

![OpenClaw install screenshot 8](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/4c5a4e09-9ba1-41d0-a33c-02cdc06d97a9.webp)

Choose Quickstart for a standard local gateway configuration.

### Step 3: Choose A Model Provider

![OpenClaw install screenshot 9](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/3ba572d3-efd5-4dc0-a750-2e53c02717e4.webp)

Select OpenAI, Anthropic, Google, xAI, OpenRouter, or another supported provider. You may also choose Skip for now. You can complete the onboarding process without API keys, but the agent cannot produce normal AI answers until model access is configured.

![OpenClaw install screenshot 10](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/e33f4b09-899d-4c3b-9759-790fa9278f6e.webp)

When asked for a default model, select Keep

Current or enter a supported model manually.

### Step 4: Configure A Channel

![OpenClaw install screenshot 11](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/8ffe7d73-3331-4684-aeb6-7f94f9b65f01.webp)

Choose a channel such as Telegram or Discord, or select Skip for now. You can add channels later using openclaw configure or openclaw channels add.

### Step 5: Configure Web Search And Skills

![OpenClaw install screenshot 12](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/587455f2-cb6e-40f7-92eb-ce64e8275d09.webp)

Choose a search provider or select Skip for now.

![OpenClaw install screenshot 13](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/54bfc2f4-fb92-4870-8ce4-71d771ac19e3.webp)

When the wizard asks whether to configure skills, select Yes. Review the missing dependencies and install only the tools you need.

![OpenClaw install screenshot 14](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/5e270b66-2afd-4933-9de2-ec49a9f58bcf.webp)

Selecting Skip for now is appropriate when you want to complete the base installation first.

The wizard may prompt for Google, OpenAI, or ElevenLabs API keys required by optional skills.

![OpenClaw install screenshot 15](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/556c3fb4-9775-4dff-8b03-f154588b52dc.webp)![OpenClaw install screenshot 16](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/96385bbd-b563-4254-89f3-2a384d495b2c.webp)![OpenClaw install screenshot 17](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/a9d1fd1d-75b9-4930-8c4c-1e7342ad94c9.webp)

Select No when you do not use the related service.

![OpenClaw install screenshot 18](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/1d5a45e5-d693-4027-bbcf-9db01795853b.webp)

It may also offer hooks such as command logging, session memory, boot files, and notifications. You can select Skip for now and enable them later.

### Step 6: Hatch The Agent

![OpenClaw install screenshot 19](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/c8ca2f69-b796-47de-9470-46ec0b22de40.webp)

The Control UI screen displays the local web URL, WebSocket address, and authentication information.

Choose Hatch in Browser and press Enter. After onboarding finishes, the Dashboard ready screen displays the local browser URL.

![OpenClaw install screenshot 20](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/d04be2d8-9666-4e28-8ef6-a0b3482494af.webp)

Note the OpenClaw web URL shown in the image above; you will need it later when you access OpenClaw.

## Verify The OpenClaw Gateway

The gateway manages sessions, channels, authentication, tools, and agent state. Verify it after onboarding.

```
openclaw gateway status
```

You should see the OpenClaw gateway listening on port 18789. This is the standard verification step before opening the dashboard.

You can also run a complete installation and configuration check.

```
openclaw doctor
```

openclaw doctor checks gateway health, channels, plugins, skills, model routing, configuration migrations, and local state.

Apply supported repairs.

```
openclaw doctor --fix
```

Follow logs in real time:

```
openclaw logs --follow
```

Use these commands when the web interface does not load, the agent does not answer, the gateway fails to start, a provider reports an authentication error, or a Telegram or Discord channel does not connect.

## Access The OpenClaw Control UI Securely

If you have installed OpenClaw on a local machine, run the command below.

```
openclaw dashboard
```

This launches the browser-based Control UI.

If you have installed OpenClaw on Atlantic.Net or other remote Ubuntu VPS, do not expose port 18789 directly to the public internet. The OpenClaw gateway binds to loopback by default, and SSH tunneling is the universal fallback for secure remote access.

From your laptop or local PC, create an SSH tunnel.

```
ssh -N -L 18789:127.0.0.1:18789 root@YOUR_SERVER_IP
```

The command appears to hang because it is maintaining the tunnel. Leave that terminal open.

Now, open a web browser on your local machine and visit the URL below.

```
http://127.0.0.1:18789/#token=515bfb6da0d4cbbcf7c211cc457607a66e3b2a71749a8256
```

You will see the Openclaw dashboard.

![OpenClaw install screenshot 21](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/24bc313c-ef14-4cac-add2-fdba80bc72e2.webp)

Click on the Overview tab. You will see the status of the Openclaw gateway.

![OpenClaw install screenshot 22](https://www.atlantic.net/wp-content/themes/anet/img/tutorials/openclaw/c450ccc3-d11d-4447-bde9-f0a0f5822237.webp)

The Control UI allows you to:

- Chat with the agent.
- Inspect provider and gateway status.
- Manage channels.
- View sessions and logs.
- Change configuration.
- Manage agents, tools, and nodes.

## Configure Models And API Keys

OpenClaw needs a model provider before it can answer messages and perform AI tasks. Reopen the configuration wizard at any time:

```
openclaw configure
```

Select your provider, authentication method, default model, workspace access, and runtime permissions. The onboarding system can detect existing AI access, test provider authentication, and verify that the selected model can generate a real response.

## Connect OpenClaw To Telegram

Open Telegram and confirm that you are communicating with the official @BotFather.

Run:

```
/newbot
```

Follow the prompts to create a new bot, choose its username, and copy the bot token.

Add the token to OpenClaw:

```
openclaw channels add --channel telegram --token "YOUR_TELEGRAM_BOT_TOKEN"
```

Telegram direct messages use pairing by default. Send your new bot a message, then list pending requests:

```
openclaw pairing list telegram
```

Approve the displayed code:

```
openclaw pairing approve telegram YOUR_CODE
```

Pairing codes expire, so approve the request soon after sending the first message.

## Connect OpenClaw To Discord

Create a new application in the Discord Developer Portal, open its Bot section, and create a bot user.

Under Privileged Gateway Intents, enable:

- **Message Content Intent**, which is required.
- **Server Members Intent**, which is recommended for role allowlists, name resolution, and channel access groups.

Invite the bot to your Server with permission to view the required Discord channel, read messages, and send replies.

Add the bot token:

```
openclaw channels add --channel discord --token "YOUR_DISCORD_BOT_TOKEN"
```

Probe the configured channels:

```
openclaw channels status --probe
```

If the bot appears online but does not answer, verify Message Content Intent, channel permissions, Server and channel allowlists, and mention requirements. Then inspect the logs:

```
openclaw doctor
openclaw logs --follow
```

Discord direct messages also use pairing controls by default, helping prevent unknown users from immediately accessing the agent.

## Method 2: Install OpenClaw Manually On Ubuntu 24.04

Skip to Run the OpenClaw Onboarding Wizard if you do not need to install OpenClaw manually.

### Option 1: Use The Official Installer Script

Use the installer script for the fastest installation method:

```
curl -fsSL --proto '=https' --tlsv1.2 https://openclaw.ai/install.sh | bash
```

This is the correctly formatted version of commonly searched phrases such as “curl fssl https openclaw.ai install.sh bash” or “fssl https openclaw.ai install.sh.” The valid option is -fsSL, and the downloaded script is piped to bash.

The installer script detects Linux, verifies the Node.js version, installs Node when needed, checks for Git, installs OpenClaw, and starts onboarding when an interactive terminal is available.

To install OpenClaw without launching onboarding immediately, run:

```
curl -fsSL --proto '=https' --tlsv1.2 https://openclaw.ai/install.sh   | bash -s -- --no-onboard
```

### Option 2: Use The Local-Prefix Installer

The local-prefix installer keeps Node and OpenClaw under a user-owned directory such as ~/.openclaw. It does not require a global Node installation or root access:

```
curl -fsSL --proto '=https' --tlsv1.2 https://openclaw.ai/install-cli.sh | bash
```

This method is useful when you cannot modify system directories, want simpler file permissions, or need an isolated per-user installation.

### Option 3: Install OpenClaw Using Docker

Docker deployment is recommended when you want stronger isolation and reproducibility. Docker is optional, but it works well for a dedicated gateway environment or a host where you do not want a local package installation.

Create the APT keyring directory and import Docker’s signing key:

```
install -m 0755 -d /etc/apt/keyrings
```

```
curl -fsSL https://download.docker.com/linux/ubuntu/gpg  -o /etc/apt/keyrings/docker.asc
```

```
chmod a+r /etc/apt/keyrings/docker.asc
```

Add the Docker repository:

```
tee /etc/apt/sources.list.d/docker.sources > /dev/null <> ~/.openclaw/.env
```

Restrict access to OpenClaw’s state and configuration:

```
chmod 700 ~/.openclaw
```

```
chmod 600 ~/.openclaw/.env
```

```
chmod 600 ~/.openclaw/openclaw.json
```

Treat a shared Gateway token as operator-level access. Do not distribute it as though it were a limited end-user credential. OpenClaw documents token generation through **openclaw doctor** and requires a valid authentication path for non-loopback bindings.

## 4. Use a Safe Remote-Access Pattern

For personal administration, create an SSH tunnel:

```
ssh -L 18789:127.0.0.1:18789 admin@openclaw-server
```

Then open:

```
http://127.0.0.1:18789
```

Traffic travels through the SSH connection while the Gateway remains bound to loopback.

Tailscale Serve is another supported private-access option. Tailscale identity may protect the Control UI and WebSocket surface when configured correctly, but do not assume it replaces Gateway authentication for every HTTP API endpoint.

For organisational access, use an identity-aware proxy that:

- Authenticates every user.
- Removes untrusted identity headers.
- Writes its own forwarding and identity headers.
- Cannot be bypassed through another route.
- Restricts access to approved users.

Do not enable trusted-proxy mode merely because a proxy terminates TLS. OpenClaw warns that trusted-proxy authentication is safe only when the proxy controls the identity boundary and is the only path to the Gateway.

Apply a host firewall policy:

```
sudo ufw default deny incoming
```

```
sudo ufw default allow outgoing
```

```
sudo ufw allow OpenSSH
```

```
sudo ufw deny 18789/tcp
```

```
sudo ufw enable
```

```
sudo ufw status numbered
```

Docker users should also review published container ports and the **DOCKER-USER** chain. A published port may not behave as expected under ordinary host firewall assumptions.

## 5. Protect API Keys and Channel Credentials

API keys, bot tokens, OAuth credentials, webhook secrets, and model-provider credentials should not be committed to repositories, embedded in container images, copied into screenshots, or retained in shell history.

OpenClaw supports SecretRefs for supported credential fields. SecretRefs reduce plaintext storage, but they are not a process-isolation boundary. A secret remains exposed if it sits in a file the agent can read through shell or filesystem tools.

Start with an audit:

```
openclaw secrets audit --check
```

Migrate supported credentials:

```
openclaw secrets configure --apply
```

Then repeat the audit and reload the active secret snapshot:

```
openclaw secrets audit --check
```

```
openclaw secrets reload
```

Do not treat the migration as complete until the audit reports no unresolved references or plaintext residue. Use separate credentials for testing and production, apply provider spending limits where available, and revoke credentials that are no longer required.

## 6. Restrict Who Can Message the Agent

A private Gateway can still receive hostile instructions through a connected messaging channel.

Use **pairing** or an explicit allowlist for direct messages. Set **session.dmScope** to **per-channel-peer** when several people can message the same bot. This keeps each sender’s direct messages in a separate session.

For example:

```
{
session: {
dmScope: "per-channel-peer"
},

channels: {
whatsapp: {
dmPolicy: "pairing",
groupPolicy: "allowlist",
groupAllowFrom: ["+15555550123"],

groups: {
"REPLACE_WITH_APPROVED_GROUP_ID": {
requireMention: true
}
}
}
}
}
```

Replace the sender and group identifiers with approved values.

Do not confuse mention gating with access control. **requireMention** controls when the agent responds. The group policy, approved senders, and configured group identifiers determine who may trigger it and where.

## 7. Minimize Tools and Sandbox Execution

No. OpenClaw sandboxing is off by default.

When sandboxing is enabled without another backend, OpenClaw uses Docker. Its documented Docker defaults include no network access, a read-only root filesystem, and dropped Linux capabilities. The Gateway itself and native plugins remain outside the sandbox, so sandboxing does not isolate every part of the system.

Begin with a restrictive tool policy:

```
{
tools: {
profile: "messaging",

deny: [
"group:automation",
"group:runtime",
"group:fs",
"sessions_spawn",
"sessions_send"
],

fs: {
workspaceOnly: true
},

exec: {
security: "deny",
ask: "always"
},

elevated: {
enabled: false
}
}
}
```

When an agent needs shell, browser, or filesystem access, enable sandboxing:

```
{
agents: {
defaults: {
sandbox: {
mode: "all",
backend: "docker",
scope: "session",
workspaceAccess: "ro",

docker: {
readOnlyRoot: true,
network: "none",
capDrop: ["ALL"]
}
}
}
}
}
```

Do not mount high-risk host paths such as:

```
/var/run/docker.sock
~/.ssh
~/.aws
/root
/etc
```

Mounting the Docker socket can give a sandboxed process control over the Docker host.

## 8. Treat Plugins and Skills as Trusted Code

Plugins can register tools, access configuration, communicate over the network, and run inside the Gateway process. Enabling a plugin is closer to installing server software than adding passive content.

Prefer official catalog entries or established publishers, but do not treat catalog inclusion as proof of a full security review.

Before installation:

- Review the source and dependencies.
- Check requested tools and permissions.
- Pin an exact version.
- Use an explicit plugin allowlist where practical.
- Remove extensions that are no longer required.

After any plugin or skill change, run:

```
openclaw security audit --deep
```

Deep auditing adds plugin and skill scans and attempts a live Gateway probe, but it does not replace manual code review.

## 9. Audit, Monitor, Back Up, and Update

Run these checks after changes to networking, authentication, channels, plugins, tools, or proxies:

```
openclaw config validate
```

```
openclaw doctor
```

```
openclaw security audit
```

```
openclaw security audit --deep
```

```
openclaw status --deep
```

OpenClaw also provides limited automatic remediation:

```
openclaw security audit --fix
```

Review every resulting change. Automatic fixes can tighten selected permissions and policies, but they do not replace a manual security review.

Create a verified backup before upgrades or major configuration changes:

```
mkdir -p ~/Backups/openclaw
```

```
openclaw backup create --output ~/Backups/openclaw --verify
```

The **–verify** option validates the archive after it is written. Treat the backup as sensitive because OpenClaw state may include conversations, credentials, tool output, sessions, and authentication data. Store it in encrypted storage with restricted access.

## 10. What Should You Do After a Suspected Compromise?

Act quickly:

1. Stop the Gateway and remove public or remote exposure.
2. Rotate the Gateway token, model keys, bot tokens, OAuth credentials, and webhook secrets.
3. Disable affected channels, plugins, skills, and scheduled tasks.
4. Review logs, sessions, configuration changes, and installed extensions.
5. Restore from a known-good verified backup when system integrity is uncertain.
6. Run **openclaw security audit –deep** before reconnecting channels.

Do not assume that changing one password removes every persistence path. A malicious plugin, exposed API credential, modified scheduled task, or altered configuration may survive a partial cleanup.

## Conclusion

Securing OpenClaw requires several independent controls. Keep the Gateway private, authenticate every access path, restrict messaging users, deny unnecessary tools, and isolate risky execution. Protect credentials at rest, treat plugins as trusted code, and separate users who do not share the same trust boundary.

Security also requires verification. Confirm the listening address, inspect firewall rules, audit secrets, test backups, and rerun deep security checks after every material change. A secure deployment is not defined by one token or firewall rule. It is defined by limited access, limited permissions, tested recovery, and regular review.

## Frequently Asked Questions

### 1. Is OpenClaw safe to self-host?

It can be operated securely when the Gateway is private, authentication is enabled, tools are restricted, and credentials are protected. Its ability to execute tools makes careless configurations high risk.

### 2. Should port 18789 be publicly accessible?

No, not under the recommended baseline. Keep it on loopback and use an SSH tunnel, private network, or correctly configured identity-aware proxy.

### 3. Is OpenClaw sandboxing automatic?

No. Sandboxing is disabled by default and must be enabled in the agent configuration.

### 4. Can several users share one Gateway?

Trusted users can share a Gateway, but mutually untrusted users should use separate instances. Session separation is not full tenant isolation.

### 5. How often should security audits run?

Run an audit after every exposure, channel, plugin, tool, proxy, or authentication change. Schedule additional recurring audits for production systems.


---

# Dedicated Server for Game Hosting: High-Performance Dedicated Game Servers in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/dedicated-server-game-hosting/ | Published: 2026-07-31 | Author: Dr. Assad Abbas

Multiplayer games require a stable server response to process player actions in real time. Every movement, shot, build action, or voice message must pass through the game server without avoidable delay. Therefore, even a small delay in server response or packet delivery can result in lag, desynchronization, unstable tick rate, and reduced gameplay quality.

To address these challenges, a dedicated game server provides a game environment with full access to a physical server. In this setup, CPU, memory, storage, and network capacity are not shared with unrelated workloads. As a result, performance becomes more consistent, improving multiplayer stability, reducing latency, and giving developers more control over the hosting environment.

This article explains the main factors to consider when choosing a dedicated server for game hosting, including performance, latency, DDoS protection, server management, backups, and deployment planning.

## Overview and Benefits of Dedicated Game Servers

A dedicated game server is a physical server assigned to a single customer or gaming environment. It provides direct access to CPU, RAM, storage, bandwidth, operating system settings, and game server configuration. Therefore, the server can be adjusted according to the game type, player count, target region, and network requirements.

The way server resources are allocated distinguishes dedicated hosting from [shared](https://www.atlantic.net/vps-hosting/vps-hosting-vs-shared-hosting-pros-cons-differences-and-expert-tips/) and [VPS hosting](https://www.atlantic.net/vps-hosting/vps-hosting-vs-shared-hosting-pros-cons-differences-and-expert-tips/). Shared hosting divides resources among many users and offers limited control. VPS hosting offers greater flexibility, but it still relies on a physical host that may serve other tenants. In contrast, a dedicated server assigns the entire physical machine to a single gaming environment. CPU, memory, disk, and network resources become more predictable during active gameplay.

This predictability is important for multiplayer stability. Games require steady CPU time, sufficient available memory, fast disk response times, and stable network behavior. If any of these resources become inconsistent during gameplay, players may experience lag, delayed actions, desynchronization, or unstable tick rate.

For game server hosting, the main benefits include:

- **Smoother multiplayer sessions:** Dedicated hardware gives the game server consistent access to CPU, memory, storage, and network resources. Therefore, player actions can be processed with fewer delays during normal sessions, peak activity, and competitive matches.
- **More stable tick rate and hit registration:** Many multiplayer games rely on fast, steady server-side processing. A dedicated server helps maintain a consistent tick rate, movement response, physics calculations, and hit registration, all of which directly affect gameplay quality.
- **Full control over game rules and server settings:** Administrators can manage maps, mods, plugins, anti-cheat tools, player slots, server files, ports, firewall rules, and update scripts according to the needs of the game community.
- **Safer testing before public release:** Development teams can test patches, new builds, mods, maps, and multiplayer behavior in a controlled server environment. In addition, QA teams can run load testing and regression testing before changes affect active players.
- **Better control for gaming communities:** Community owners can manage player access, moderation rules, saved worlds, backups, custom settings, and long-term server data. This is useful for private servers, modded servers, survival worlds, and e-sports practice environments.

Dedicated game servers are therefore suitable for FPS games, survival games, sandbox worlds, [MMO backend](https://edgegap.com/blog/how-mmo-games-architecture-scales-with-a-smart-fleet-manager) services, e-sports tournaments, private communities, and development environments.

## Dedicated Game Server Hardware for Stable Multiplayer Performance

Hardware choices should reflect the workload created by the game server. Multiplayer servers process movement, combat, voice routing, map changes, and player state in real time. Therefore, the configuration should be based on the game engine, expected player count, use of mods, and number of active server instances.

In this configuration, processor performance is usually the primary factor to evaluate, as many game servers rely on fast per-core execution. Strong per-core performance can improve tick rate, physics calculations, AI behavior, movement response, and hit registration. A higher core count becomes important when the same machine also runs several game instances, databases, voice services, control panels, or backend tools. For example, AMD Ryzen is often suitable for tick-rate-sensitive servers, while AMD EPYC is better for multi-instance hosting and larger communities. Intel Xeon processors are also common in dedicated hosting and can handle mixed server workloads.

In addition to processor selection, memory and storage should be planned according to the same workload. RAM requirements vary by game engine, map size, player count, mods, and plugins. A small vanilla server may require moderate memory, while a large modded server may require a larger RAM allocation. Similarly, storage capacity should account for maps, logs, updates, player data, and backup retention. NVMe storage is generally preferred for active game files because it improves map loading, world saves, update operations, and database activity.

The hardware plan should include reliability measures. RAID 1 or RAID 10 can improve disk resilience, but separate backups are still required. Adequate cooling, redundant power, disk health monitoring, and planned hardware replacement help maintain a stable game environment during sustained use.

Table 1: General hardware guidance for dedicated game server planning

| **Game server type** | **Typical RAM range** | **Main hardware priority** |
| --- | --- | --- |
| Small vanilla server, 10–20 players | 8–16 GB | High CPU clock speed |
| Medium community server, 20–64 players | 32–64 GB | Balanced CPU and RAM |
| Large or modded server, 64+ players | 64–128 GB+ | More RAM and NVMe storage |
| Multi-instance setup | 128 GB+ | Higher core count and separate storage |

## Low-Latency Networking for Multiplayer Game Hosting

Multiplayer performance depends on both server resources and network quality. A dedicated game server may have strong CPU and memory capacity. Player experience can still suffer when the data center is far from users or when the network path has high latency, packet loss, or jitter. Therefore, network planning should be completed together with hardware selection.

Latency directly affects real-time player interaction. Player inputs must reach the server quickly, and the server’s response must be returned with minimal delay. When latency is high, players may experience poor hit registration, delayed movement, voice disruption, and unstable synchronization. Therefore, network quality should be tested under real gameplay conditions rather than judged only through advertised ping values.

Since latency depends on distance, server location is an important planning factor. The game server should be placed near the main player base so data has less distance to travel between players and infrastructure. For North American players, U.S. Central, East, or West locations may be suitable, depending on user distribution. Similarly, European and Asia-Pacific players usually require nearby regional locations. Global games may require multiple regions and region-based matchmaking.

Regional proximity alone does not ensure stable gameplay. The route between the player and the server also affects connection quality. Direct peering, fewer network hops, lower packet loss, and enough public bandwidth can improve stability during normal sessions and peak events. Likewise, private networking can improve internal communication when databases, control panels, monitoring tools, or backend services are part of the same game environment.

## DDoS Protection for Dedicated Game Servers

DDoS protection is an important part of public game server design because service availability directly affects gameplay continuity. Attacks can disrupt active matches, tournaments, paid communities, and launch events. Even a short outage may reduce player confidence in the hosting environment. Therefore, DDoS protection should be included before the server is made publicly accessible.

At the traffic level, DDoS protection depends on early filtering. In an always-on protection model, suspicious traffic is inspected and filtered at the network edge before it reaches the dedicated server. Attack traffic is less likely to consume server CPU, memory, or bandwidth during active gameplay.

In addition, a layered DDoS protection plan is necessary because attacks can target different parts of the network and application stack. Layer 3 filtering helps address volumetric floods, ICMP floods, and IP-based attacks. Similarly, Layer 4 filtering helps reduce UDP and SYN floods, as well as TCP connection exhaustion. Layer 7 filtering can protect web panels, APIs, login pages, and other services connected to the game environment.

Filtering alone is not enough for reliable incident handling. A complete DDoS plan should define mitigation capacity, detection time, automated rules, manual escalation, and post-incident reporting. These details help server administrators respond faster during attacks and review the event after service stability has been restored.

Table 2: Network and DDoS checks before dedicated game server deployment

| **Planning factor** | **What to check** | **Why it matters for game hosting** |
| --- | --- | --- |
| Server region | Location near the main player base | Reduces latency and improves response time |
| Routing quality | Peering, packet loss, jitter, and network hops | Improves gameplay stability |
| Public bandwidth | Port speed, monthly transfer, and peak traffic capacity | Handles updates, events, and traffic growth |
| Private networking | Backend, database, control panel, and monitoring traffic | Keeps internal services more controlled |
| DDoS protection | Layer 3, Layer 4, and Layer 7 filtering | Protects game availability during attacks |
| Escalation process | Detection time, response path, and reporting | Improves incident response during outages |

## Dedicated Game Server Control and Operational Management

A dedicated game server also needs a structured control process for installation, updates, monitoring, restarts, and recovery. These tasks affect server stability during active player sessions. Therefore, the management approach should reflect the game type, update frequency, player community size, and the team’s technical ability.

Control panels help organize common game server tasks. For example, Pterodactyl, TCAdmin, AMP by CubeCoders, and LinuxGSM are often used for game server templates, user permissions, scheduled restarts, updates, and basic monitoring. In addition, access methods should match the server environment. Linux-based game servers usually use SSH, while Windows-based servers often use Remote Desktop. Similarly, SFTP is useful for uploading maps, mods, plugins, and configuration files.

For development and community hosting, repeatable processes are important. Scheduled restarts can reduce instability, while version-controlled configuration files make server changes easier to trace. Deployment scripts can reduce manual errors during the transition from testing to production. Development teams may also connect server updates with GitHub Actions, GitLab CI, or Jenkins for QA, patch testing, multiplayer regression testing, and controlled release workflows.

A clear operational model helps maintain server stability after deployment. Administrators should be able to review logs, restore backups, adjust configurations, and respond quickly when gameplay is affected. Management tools should support routine control without limiting access to important server functions.

## Deployment Planning for Dedicated Game Server Hosting

Deployment planning connects earlier technical decisions with the actual launch process. Before public access is opened, teams should confirm player capacity, server region, operating system, control panel, game files, firewall rules, backup schedule, and testing steps. Therefore, the launch timeline should include provisioning, configuration, validation, and rollback planning.

Cost review should also be linked to expected gameplay use. Processor class, RAM, NVMe storage, RAID, bandwidth, DDoS filtering, managed services, and backup retention can affect monthly cost. The lowest price may pose a risk if the plan has weak network capacity, limited incident response capabilities, or unclear upgrade options.

In addition, provider selection should consider reliability after launch. Active game worlds depend on saved maps, player progress, configuration files, and logs. Therefore, backups should be stored separately and tested through a restore process. Similarly, pre-update snapshots can help before major patches, mod changes, and map rotations.

At the provider-selection stage, [Atlantic.Net](https://www.atlantic.net) may be evaluated as a dedicated server and bare metal hosting option for game environments that require configurable resources, bandwidth planning, DDoS protection, managed services, backups, and technical assistance. Teams can review their data center location, network capacity, recovery options, and suitability for multiplayer workloads.

Technical assistance should also be reviewed before purchase, as launch events, traffic spikes, and attacks may require a timely response. The selected provider should assist with the initial deployment and ongoing game server operations.

## Dedicated Game Server Launch Checklist

A dedicated game server should be reviewed before public access is opened. The checklist below helps verify whether the environment is ready for active players, peak traffic, and possible service incidents.

- Review the expected number of concurrent players, peak traffic levels, and possible growth during launch events.
- Select a server region close to the main player base to reduce latency.
- Confirm that CPU performance matches the game engine, tick rate, and number of active server instances.
- Allocate RAM according to player count, map size, mods, plugins, and saved world data.
- Use NVMe storage for active game files, world saves, logs, and update operations.
- Plan public bandwidth for normal gameplay, downloads, voice services, tournaments, and launch traffic.
- Complete load testing before public release to identify CPU, memory, storage, or network limits.
- Prepare DDoS mitigation settings, escalation contacts, detection steps, and reporting procedures.
- Schedule backups and verify restore steps before the first public player session.
- Define maintenance windows and player communication channels for updates, outages, and recovery notices.

## The Bottom Line

Dedicated game hosting should be evaluated based on long-term gameplay stability, not just initial server size. A well-planned dedicated server gives administrators better control over performance, updates, backups, and incident response. Therefore, the hosting decision should reflect player demand, technical requirements, and future growth. When the server is tested before release and managed through clear processes, it can provide a more reliable foundation for reliable multiplayer sessions and community trust.


---

# Bare Metal vs RTOS: Choosing the Right Embedded Approach in 2026

> URL: https://www.atlantic.net/dedicated-server-hosting/bare-metal-vs-rtos-embedded-design/ | Published: 2026-07-31 | Author: Dr. Assad Abbas

Choosing between [bare metal](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) and a [Real-Time Operating System (RTOS)](https://www.ibm.com/think/topics/real-time-operating-system) is one of the first software architecture decisions in embedded system design. This choice determines whether the firmware runs directly on the hardware or uses a lightweight operating system layer to manage execution. A bare metal design keeps firmware close to the hardware, with direct control over timing, interrupts, and peripherals. In contrast, an RTOS-based design manages task scheduling, timing, and system services through a structured software layer. Therefore, the decision affects timing behavior, memory usage, power control, debugging, security, and long-term maintenance.

This article compares bare metal firmware and RTOS-based firmware to help teams choose the right embedded approach for their system requirements.

## Understanding Bare Metal and RTOS

Bare metal and RTOS-based designs are two common approaches in embedded system development. Both approaches control hardware, but they organize firmware execution differently.

In a bare metal design, firmware runs directly on the processor without an operating system. The software initializes hardware, configures peripherals, handles interrupts, and manages timing through a main loop, timer routines, or a state machine design. Therefore, this approach provides direct control over the device and keeps resource usage very low. The design becomes difficult to manage when multiple time-sensitive activities must run together.

In contrast, an RTOS-based design introduces a lightweight software layer between firmware and hardware. This layer includes task scheduling, timers, queues, and synchronization tools. In addition, it may provide drivers and middleware. As a result, tasks such as sensing, communication, logging, and control can be handled in a more structured manner. This structure increases RAM and flash usage and requires more configuration effort.

In some cases, real-time coordination alone is not sufficient. Certain devices also require application-level features such as networking, filesystems, logging, and remote access. In such situations, embedded Linux becomes a suitable option. It requires hardware with higher CPU performance, memory, and storage capacity.

## When Bare Metal Is the Right Embedded Approach

Bare metal is the right embedded approach when the device has a narrow function, limited resources, and timing behavior that can be checked directly. It is most useful when the firmware has only a few tasks and the control paths are short. In such systems, adding an RTOS may increase memory usage and configuration effort without providing much practical benefit.

Bare metal is usually suitable when the device has the following conditions:

- **The firmware has only a few tasks:** A simple bare metal design works well when the device performs limited actions, such as reading a sensor, controlling an output, or sending a short message. In such cases, an RTOS may add scheduling overhead without solving a real coordination problem.
- **The hardware has limited resources:** Devices with very small RAM, flash, or CPU capacity often benefit from direct firmware execution. Since there is no kernel, scheduler, or separate task stack structure, more of the available memory can be used for the actual application logic.
- **The timing path is short and measurable:** Bare metal gives engineers direct control over interrupt routines and control paths when those paths are small enough to test clearly. Response time, execution time, and jitter can be measured without also accounting for context switches or scheduler behavior.
- **The device depends on low-power operation:** Battery-powered devices often wake, perform a small task, and return to sleep. In such designs, direct control over clocks, wake-up sources, and sleep states can reduce unnecessary processing.
- **The product requirements are stable:** Bare metal is easier to maintain when the product is not expected to add many features. If future versions will require networking, logging, OTA updates, or several parallel tasks, an RTOS may provide better structure.

These conditions are common in small and purpose-built devices, such as sensor-only nodes, ultra-low-power IoT endpoints, simple appliance controllers, environmental sensors, and small motor-control boards. For example, a soil sensor may wake, read moisture data, transmit a short packet, and return to sleep.

A bare-metal design should not be chosen solely because the initial firmware version appears simple. A small control loop may work well in the early stage, but it can become difficult to manage as new features are added. For example, long interrupt handlers, blocking routines, shared global variables, and weak module boundaries can create timing problems that are difficult to trace and fix.

## When Does an RTOS Become the Better Embedded Approach

An RTOS becomes useful when firmware requires more coordinated execution than a simple main loop can provide. A simple main loop can work well for a small device. It becomes difficult to manage when the same firmware must read sensors, handle communication, store logs, control outputs, and respond to time-sensitive events together. At that stage, an RTOS can provide a clear structure for execution.

An RTOS is usually more suitable when the device has the following conditions:

- **The main loop can no longer clearly organize execution:** An RTOS can separate sensing, communication, logging, and control logic into individual tasks rather than keeping all work in a single large loop. With priorities, timers, and queues, each activity can run in a controlled manner, making the firmware easier to test and maintain.

- **Tasks have different timing needs:** Some work may need immediate attention, while other work can wait. For example, a control task may require faster response than a logging or status-reporting task. An RTOS helps organize such work through task priorities.
- **Interrupts carry too much logic:** Interrupt routines can slowly become responsible for many actions in bare metal firmware. This can increase latency and make timing behavior harder to predict. An RTOS helps move longer work out of interrupts and into scheduled tasks.
- **Communication features require organized services:** An RTOS can help manage Bluetooth, TCP/IP, MQTT, filesystems, and OTA updates through separate tasks, drivers, and middleware. This structure is useful when communication work must run beside sensing, logging, and control logic without blocking time-sensitive operations.

- **The codebase needs clearer separation:** An RTOS can divide growing firmware into tasks, queues, timers, and synchronization units. This separation helps teams update one part of the system without disturbing unrelated timing, communication, or control logic.

Common RTOS services include:

- **Task management and scheduling:** Tasks, priorities, timers, and context switching help organize activities with different timing needs.
- **Task coordination:** Queues, semaphores, mutexes, memory pools, and inter-process communication help tasks share data and resources safely.
- **Device and middleware support:** Many RTOS environments include device drivers, networking stacks, filesystem support, and protocol libraries.
- **Testing and debugging tools:** Tracing tools, stack monitoring, and debugging support help engineers check timing behavior and resource use.

An RTOS should not be selected solely because the firmware has several functions. The benefit of an RTOS depends on careful task design, correct priority assignment, and proper use of synchronization. Poorly designed tasks can still create timing problems, even with a scheduler. For example, context switching, priority inversion, blocking calls, shared resources, and incorrect stack sizing can affect real-time behavior. In addition, unnecessary tasks can increase RAM and flash usage, making debugging harder. Therefore, teams should confirm that the hardware can support the RTOS overhead and that the firmware actually benefits from task-based organization.

## When is Embedded Linux a Practical Option

Embedded Linux becomes relevant when an embedded product needs application-level features in addition to device control. These features may include advanced networking, filesystems, process separation, logging, remote access, or a graphical interface. Such requirements usually appear in gateways, smart cameras, industrial interfaces, robotics systems, network appliances, and edge AI devices.

This option requires more reliable hardware than bare metal or RTOS-based firmware. The device usually requires higher CPU performance, larger memory capacity, persistent storage, and a memory management unit. With these resources, Linux can run user-space services and application frameworks that are difficult to manage in a small firmware environment.

The decision between an RTOS and embedded Linux depends on the main software requirement. An RTOS is suitable when predictable timing and task coordination are the main concerns. On the other hand, embedded Linux is suitable when the product requires richer software services and application-level flexibility. For hard real-time control, teams may still use a microcontroller running bare metal firmware or an RTOS alongside Linux.

Tools such as Yocto Project and Buildroot are commonly used to create custom embedded Linux images. OpenWrt is also useful for router and network appliance designs. These tools help teams build Linux systems that are smaller and more controlled than general-purpose Linux distributions.

## Maintenance and Security Across Bare Metal, RTOS, and Linux

The architecture choice also affects maintenance, portability, and security. A smaller system may be easier to manage with bare metal. At the same time, a growing product may benefit from the structure of an RTOS or the broader software environment of embedded Linux.

Table 1: Comparing Bare Metal, RTOS, and Embedded Linux for Maintenance and Security

| **Area** | **Bare Metal** | **RTOS** | **Embedded Linux** |
| --- | --- | --- | --- |
| **Maintenance** | Simple when the firmware is small | Clearer task and driver structure | Strong application and system separation |
| **Portability** | Often hardware-specific | Improved through HALs and BSPs | Better at the application level |
| **Security** | Mostly custom | Some libraries and update support | Larger security ecosystem |
| **Updates** | Usually, the custom firmware process | Easier with RTOS middleware | Advanced but more complex |
| **Best fit** | Small, fixed-function devices | Multi-task real-time devices | Connected, application-rich devices |

Device-level security is part of a wider connected architecture. Many embedded devices send data to backend platforms for telemetry, dashboards, OTA updates, and monitoring. Once device data moves to a hosted backend, the hosting environment also becomes part of the security and compliance plan.

In healthcare workflows, backend systems that handle electronic Protected Health Information (ePHI) may require a HIPAA Business Associate Agreement (BAA), HIPAA-compliant hosting, and TLS-encrypted data in transit. Organizations using dedicated backend infrastructure may consider providers such as [Atlantic.Net](https://www.atlantic.net), which offers HIPAA-compliant hosting and bare metal server options for connected embedded systems. This hosted layer does not replace device-level controls, but it completes the security planning for products that exchange data outside the device.

## Final Decision Checklist

The best embedded approach depends on the device’s purpose, hardware constraints, timing requirements, connectivity needs, and expected product life. A small sensor node, a multi-sensor controller, and an edge gateway do not require the same software model. Therefore, the final choice should be based on measured requirements rather than early assumptions.

The following checklist can be used before choosing between bare metal, RTOS, and embedded Linux:

- **Timing:** Does the device require strict worst-case latency, low jitter, or fast interrupt response?
- **Hardware resources:** Does the hardware provide enough RAM, flash, CPU capacity, storage, and power budget for the selected approach?
- **Task:** Does the firmware have only a few simple tasks, or must several activities run together?
- **Connectivity:** Does the device require Bluetooth, TCP/IP, MQTT, OTA updates, filesystems, or remote access?
- **Power use:** Does the device need frequent sleep cycles, fast wake-up times, or very low energy consumption?
- **Security:** Does the system require secure boot, signed updates, TLS, access control, logging, or recovery controls?
- **Maintenance:** Will the firmware remain small, or is the codebase expected to grow over time?
- **Compliance:** Does the product fall under safety, medical, industrial, or HIPAA-compliant requirements?

The checklist provides initial guidance, but the selected approach should still be validated on the target hardware. Teams should measure timing, memory use, CPU load, boot time, power behavior, and update reliability under realistic operating conditions. These measurements show whether the system can meet its performance, power, and maintenance requirements before production.


---

# Hot Standby Server Guide to High Availability and Disaster Recovery in 2026

> URL: https://www.atlantic.net/cloud-platform/hot-standby-server-high-availability-disaster-recovery/ | Published: 2026-08-06 | Updated: 2026-08-07 | Author: Dr. Assad Abbas

In 2026, many organizations depend on digital systems that support customer access, financial transactions, healthcare services, and internal operations. Even a short outage can affect service availability, data processing, and compliance obligations. Therefore, business-critical systems require a recovery design that responds quickly when a server, storage device, network path, or site becomes unavailable.

Backups are an important part of this design, but they do not provide immediate service continuity. A backup can restore lost data, but the system still needs time to recover, configure, and validate. During this period, users may not be able to access the service.

[A hot standby](https://www.geeksforgeeks.org/operating-systems/what-is-hot-standby-mode/) server addresses this limitation by keeping a secondary system ready for use. It receives continuous updates from the primary system and can take over when the primary server fails. Hot standby supports both high availability and disaster recovery by reducing downtime and improving recovery predictability.

This article explains hot standby server design from a practical operational view, including architecture, replication, failover testing, standby capacity, security, backups, and recovery readiness.

## What Is a Hot Standby Server?

A hot standby server is a fully provisioned secondary system that remains synchronized with the primary server. The standby server receives continuous updates and is maintained in a ready state, allowing service to be restored with minimal delay after a primary server failure.

During normal operation, the primary server handles production activity. It receives user requests, runs applications, processes transactions, and writes data. In parallel, the standby server receives replicated data, configuration updates, and system state. This continuous synchronization keeps the standby environment aligned with the production environment and prepares the server for promotion during failover.

A hot standby model differs from a traditional backup. Traditional backups preserve recoverable copies of data. Backups do not provide immediate service continuity because restoration, configuration, and validation are usually required before users can access the service again. In contrast, a hot standby server is already operational and prepared for failover.

Therefore, hot standby improves availability by reducing the time required to restore service following a server or storage failure or a site outage. The same design also strengthens disaster recovery by enabling a faster path to recovery. Independent backups, recovery runbooks, and regular failover testing remain necessary because replication alone cannot protect against all types of data loss.

## Hot Standby System Architecture and Components

The architecture of a hot standby environment is based on several connected components. These components include the primary server, the standby server, the replication layer, and the access layer that directs users or applications to the active system. Together, these components keep the standby environment prepared for recovery when the primary system becomes unavailable. Each of the components is briefly discussed below:

### Primary Server

The primary server handles normal production activity. It receives user requests, runs applications, processes transactions, writes data, and records system changes. In addition, the primary server sends updates to the standby environment. These updates may include database records, application files, configuration changes, or storage-level data, depending on the workload.

### Standby Server

The standby server receives updates from the primary server and applies them according to the selected replication method. In many environments, the standby server remains passive until a failover occurs. In some designs, the standby server may also handle read-only tasks, such as reporting or analytics. Read-only activity requires careful planning because heavy queries can delay replication and affect recovery readiness.

### Replication Layer

The replication layer keeps the standby environment aligned with the production environment. Common methods for synchronizing data and system changes include database replication, file-level replication, block-level storage replication, and configuration management. For example, databases may use transaction log shipping, streaming replication, or binary log replication. Similarly, storage systems may replicate disk blocks between primary and standby storage. Data encrypted in transit should use TLS.

### Access Layer

The access layer defines the route through which users and applications reach the active system. Common elements include load balancers, virtual IP addresses, DNS records, routing rules, and cluster management tools. During a recovery event, the access layer redirects traffic from the failed primary system to the promoted standby system.

A well-designed access layer is important because recovery is incomplete until users and applications can reach the new active server. Therefore, traffic redirection should be tested together with replication and server promotion.

## Hot Standby Synchronization and Data Loss

Synchronization determines the extent to which the standby environment matches the primary environment at the time of failure. Therefore, replication mode directly affects [the Recovery Point Objective (RPO)](https://csrc.nist.gov/glossary/term/recovery_point_objective), application performance, and the risk of data loss.

In synchronous replication, the primary server confirms a *write* only after the standby system receives the update. This method reduces the risk of data loss because both systems remain closely aligned. Synchronous replication may increase latency because the primary system waits for acknowledgment from the standby system. Therefore, this model is more suitable when both systems are located close enough to maintain low network delay.

In asynchronous replication, the primary server confirms *writes* before all updates reach the standby system. This model usually performs better across longer distances and is often used for geographically distributed recovery designs. Asynchronous replication can create replication lag. If the primary system fails before pending updates reach the standby system, recent transactions may be lost.

A database system is a useful example of synchronization and data loss behavior. In a primary-to-standby database setup, the application writes to the primary database. The primary database then sends transaction logs or replication events to the standby database. The standby database applies these changes in sequence, so the data remains close to the primary database state. Common methods for keeping the primary and standby databases synchronized include write-ahead log shipping, streaming replication, binary log replication, and block-level mirroring.

The delay between the primary and standby databases is known as replication lag. This delay is due to the fact that any unapplied change may be at risk in the event of a sudden failure. Therefore, replication lag should be monitored during normal operation and compared with the accepted RPO. Workloads with strict data-loss limits may require synchronous replication, whereas distant disaster recovery sites may require asynchronous or hybrid replication.

## Failover Processes and Testing

Synchronization keeps the standby environment ready, but recovery also depends on a controlled failover process. Therefore, teams should test the hot standby design before an outage occurs. An untested process may fail during the first real incident.

In automated failover, a heartbeat or monitoring system first detects that the primary system is unavailable. Health checks then confirm whether the service has actually failed. After confirmation, the cluster software or automation activates the standby system. Traffic is then redirected via a load balancer, a virtual IP address, a DNS update, or a routing change, and applications reconnect to the new active system.

Accurate detection is important because early activation can create data consistency problems. Heartbeat and health checks may include network probes, API endpoint checks, database queries, replication status checks, storage checks, and load balancer health probes. These checks help confirm that the standby system is ready before traffic moves to it.

Manual failover is useful when automation is not suitable. Situations where manual failover may be needed include planned maintenance, controlled migration, unclear failure signals, or cases where data consistency requires review before activation. Manual control can also reduce the risk of split-brain when both systems appear active or partially available.

Whether failover is automated or manual, regular testing is necessary to confirm that the process works as expected. Each test should record recovery time, data status, failed steps, manual actions, and required improvements. This record helps teams improve the process before a real outage.

## Hot Standby Versus Cold Standby and Warm Standby

Standby models differ in recovery speed, data loss risk, cost, and operational effort. Therefore, organizations should compare cold, warm, and hot standby models against Recovery Time Objective (RTO), RPO, and business criticality before selecting a design.

Cold standby has the lowest cost, but recovery takes the longest. In this model, the standby environment is offline or not fully provisioned. Systems may require provisioning, restoration, configuration, and validation before service returns. Therefore, cold standby is suitable for low-impact workloads where extended downtime is acceptable.

Warm standby provides moderate recovery speed. Some infrastructure is already in place, and data may be updated via scheduled synchronization or partial replication. Manual steps are often required before production traffic can be moved to the standby environment. This model is suitable for important internal systems that can tolerate limited recovery delay.

Hot standby provides the shortest recovery time because the secondary environment is already running and synchronized. This design requires higher costs and operational effort, including duplicate compute resources, storage, replication bandwidth, monitoring, and regular testing. Therefore, hot standby is suitable for customer-facing platforms, transactional systems, healthcare applications, financial workloads, and other business-critical services.

The following table summarizes the main differences between the three standby models.

Table 1: Standby Server Models Compared by RTO, RPO, Cost, and Use Case

| **Standby Type** | **System State** | **RTO** | **RPO** | **Cost** | **Best Use** |
| --- | --- | --- | --- | --- | --- |
| Cold standby | Offline or not fully provisioned | Hours to days | Higher data loss risk | Lowest | Low-risk workloads |
| Warm standby | Partially running and periodically updated | Minutes to hours | Moderate | Medium | Important systems with moderate recovery needs |
| Hot standby | Running, synchronized, and ready | Seconds to minutes | Lowest, depending on the replication mode | Highest | Business-critical systems |

## Hot Standby Best Practices for

The following best practices help teams prepare a hot standby environment for reliable recovery, consistent performance, and controlled failover.

Configuration parity: Primary and standby systems should use consistent operating system versions, patches, application settings, libraries, certificates, firewall rules, and dependencies. Consistent configuration reduces the risk of errors during recovery.

Standby capacity: The standby server should be sized for production traffic after promotion. Capacity planning should include peak demand, database writes, background jobs, storage I/O, and network throughput.

Redundancy planning: Teams should select N+1 or N+2 redundancy according to workload importance. N+1 provides one extra capacity unit, while N+2 provides additional protection during maintenance, failure, or traffic spikes.

Monitoring and alerts: Monitoring should track server health, application availability, replication lag, storage use, network delay, and recovery readiness. Alert thresholds should align with RTO and RPO targets so teams can respond before recovery risk increases.

Traffic redirection: Load balancers, virtual IPs, DNS records, routing rules, or cluster tools should be configured before production use. These controls help move users and applications to the promoted standby system during recovery.

Recovery documentation and testing: Teams should maintain a runbook with owners, escalation paths, validation checks, failback actions, and communication steps. Staged failover drills should verify the runbook and record recovery time, data status, failed steps, and required improvements.

## Security, Data Integrity, and Backups

A standby system often contains the same data and configuration as the production system. Therefore, the same security controls should apply to both environments. If the standby server has weaker protection, it can become a separate source of risk during normal operation or recovery.

Security controls should include role-based access control, least privilege, multi-factor authentication for administrative accounts, audit logging, and restricted access to replication and management interfaces. In addition, replication traffic and administrative sessions should be protected by encrypting data in transit using TLS. Together, these controls help protect the standby environment during normal synchronization and recovery operations.

Compliance requirements should also be considered when sensitive data is involved. Systems that process [electronic Protected Health Information (ePHI)](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) may require HIPAA-compliant hosting and a HIPAA Business Associate Agreement (BAA) when a hosting provider handles ePHI. Similarly, PCI-compliant systems should maintain network segmentation, logging, encryption, and controlled administrative access.

After the standby system becomes the active production system, teams should verify data integrity before resuming normal operations. This includes reviewing transaction logs, validating database consistency, confirming application writes, and checking delayed jobs or replication errors.

Finally, hot standby should remain separate from the organization’s backup strategy. Although replication keeps the standby system updated, it can also copy corrupted, deleted, or ransomware-encrypted data. Therefore, organizations should maintain independent backups, define clear retention policies, and test restore procedures regularly.

## Atlantic.Net for Hot Standby and Disaster Recovery Environments

Atlantic.Net can be considered by organizations planning hot standby environments for high availability and disaster recovery. Its cloud hosting and dedicated server options can provide the infrastructure needed for primary and standby systems, replication, standby capacity, monitoring, backups, and tested recovery procedures.

For compliance-sensitive workloads, Atlantic.Net also offers HIPAA-compliant hosting options where applicable. This can be useful for organizations that need secure infrastructure when designing hot-standby systems for healthcare, finance, SaaS, or other business-critical applications.

## The Bottom Line

Hot standby servers are effective when planned as part of a wider recovery strategy, rather than treated as a separate backup system. They reduce the delay between failure and service restoration, but only when replication, monitoring, security controls, and failover testing are properly managed.

A hot standby design should therefore focus on recovery readiness, not server availability alone. The standby system should be able to become active safely, quickly, and with verified data integrity. This provides business-critical environments with a stronger foundation for high availability and disaster recovery.


---

# Zero Trust Implementation Roadmap: Step-by-Step Guide

> URL: https://www.atlantic.net/cloud-platform/zero-trust-implementation-roadmap/ | Published: 2026-08-07 | Author: Robert Agar

Modern businesses face a wide variety of external and internal threats that require a complete approach to security. Organizations can improve their security posture by implementing the zero trust model to closely control how users gain access to sensitive data and critical assets.

Zero trust acknowledges that internal threats exist and must be mitigated to protect the business. Zero trust eliminates implicit trust, treats all access requests as potential security breaches, and takes necessary steps to protect the IT environment.

The entire company must be involved in zero-trust adoption. Executive buy-in and strong cross-team support are essential for successful zero trust transformation. Zero trust offers a more effective security strategy than traditional security models.

## Zero Trust Security Model and Principles

The zero trust model is built on the precept of “Never Trust, Always Verify.” No implicit trust is granted based on network location or previous activity. The foundation of the zero trust architecture comprises the following core principles.

- **Explicit verification:** Activity must be authenticated and authorized with strict access controls based on more than network position. All available signals, such as identity, device health, location, and behavior, are considered regardless of whether the request comes from within or outside of the corporate network.
- **Least privilege access:** Users, systems, and devices are granted only the minimum level of access needed to perform a given task or job role.
- **Assume a breach:** The zero trust architecture is designed to address attackers that have already breached the network, unlike traditional security models that focus on keeping intruders out.
- **Micro-segmentation:** Network security is strengthened by segmenting the network into small zones. The purpose of this segmentation is to restrict broad access to the entire IT environment if one system is compromised.
- **Continuous verification:** Trust must be reevaluated for every session and user request. All access requests must pass strong identity verification before permission is granted to proceed, even if previously authenticated.

The main objective of a company’s zero trust efforts is to ensure all access requests are verified at every step through the environment. These core principles support the strong system and data security required to protect business-critical resources.

## Define the Attack Surface

Organizations must define their [attack surface](https://www.cloudflare.com/learning/security/what-is-an-attack-surface/) and build a security framework that protects their Data, Applications, Assets, and Services (DAAS). Teams must inventory and identify critical assets and sensitive data to accurately define the attack surface that needs to be defended. All external dependencies that interact with these assets and expand the attack surface must be included in this inventory.

Businesses can prioritize the identified assets when developing their zero trust strategy. They can focus on protecting critical assets first, then move on to the remaining infrastructure elements to improve their security posture across the organization while maintaining operations.

## Map Network Traffic and Transaction Flows

Access management for users already inside the corporate network is an aspect of the zero trust security model. Teams should map all network traffic between users, applications, and data stores. The objective is to identify the most effective policy enforcement points for all critical data flows that protect resources while facilitating smooth business operations.

Zero trust security extends to network access attempts by remote workers and third parties trying to connect with on-premises or cloud resources. Companies should record and review connection patterns to determine whether security controls should be modified to protect business-critical systems and data better.

## Architect the Trust Network

Security teams must design the architecture to protect the defined attack surface. They should use a methodical approach when developing the zero trust architecture, addressing the following characteristics.

- The architecture must be designed around the defined attack surface. The primary goal of zero trust is to protect these and sensitive infrastructure components by restricting broad network access.
- Teams should implement microsegmentation controls to ensure that access to a specific system does not allow lateral movement through the entire network to other critical resources. All access attempts must be verified to align with zero trust principles.
- Businesses must select the locations where policy decisions on user identity and access requests should be made. Some users may be entirely prohibited from accessing certain network segments, while others will have limited permissions within those segments.
- Policy decision points should be tightly coupled with policy enforcement points. Strict access controls should prevent unauthorized and unauthenticated users from accessing network segments or specific resources.

## Implement Zero Trust Identity and Access Management

The key to the zero trust model is a reliable, centralized Identity and Access Management (IAM) platform that enforces multi-factor authentication (MFA) for all access requests. Strong identity verification is mandatory to support a zero trust approach.

Users can only be granted access to a subset of the IT environment. Organizations must develop and implement role-based access controls (RBACs) for all users, aligned with their job functions. Attribute-based policies should be defined to control contextual access decisions.

Admin accounts require special consideration when developing IAM policies. These accounts provide privileged access that must be tightly controlled and restricted to specific systems and resources. Admin privileges should always be provided on a limited basis to minimize insider threats.

### Define Access Policies

Organizations can use the Kipling Method to build explicit, auditable, and secure access policies. The method defines the following criteria for every access policy based on six related questions. After each question is answered, the access request can be allowed to continue or terminated based on policy definitions.

- **Who:** Which user or device is requesting access?
- **What:** What application or resources are they attempting to access?
- **When:** When is the entity permitted to use the resource?
- **Where:** Where is the protected resource located, and where does the access request originate?
- **Why:** Why is access being requested?
- **How:** How will access be granted?

Every job role or service should be granted least-privilege access for a given system or resources. Decision-makers should periodically review these privileges and make the necessary modifications to address changes in the environment or role.

## Secure Zero Trust Network Access

Zero Trust Network Access (ZTNA) enforces per-application and identity-verified access to IT resources. A ZTNA approach replaces the broad access enabled by traditional virtual private network (VPN) solutions with conditional access tied to user identity and device health and status.

A VPN typically enables users to access multiple internal systems once they are connected and verified. ZTNA’s application-level access connects a user only to the specific application they are authorized to use. The zero trust network approach reduces the blast radius if threat actors compromise credentials.

## Device Trust, IoT Devices, and Endpoint Security

Zero trust network access controls must be designed to ensure secure access for users and devices. Modern businesses often deploy a range of automated IoT devices and endpoint solutions to support remote work. Teams should implement policies to verify device health before granting access. Device health checks are essential for identifying outdated firmware or patching vulnerabilities that threat actors can exploit.

One method of preventing IoT devices from accessing unauthorized resources is to limit access to specific dedicated network segments. This type of control involves planning to ensure IoT-connected applications live on an appropriate segment. All IoT access attempts to other segments should be refused.

Companies that engage managed service providers such as Atlantic.Net should expect them to [provide complete edge security](https://www.atlantic.net/managed-services/edge-security/) aligned with their zero-trust access policies.

## Continuous Monitoring and Network Traffic Analysis

Companies must implement a continuous monitoring solution to support a zero trust security posture. Teams should collect identity and network activity telemetry in real time and be prepared to address incidents that may indicate threats or malicious activity. Security teams should implement advanced anomaly detection solutions leveraging threat intelligence and behavioral analysis.

When potential incidents are detected, automated alerts should be generated to trigger recovery and mitigation playbooks. The immediate goal is to reduce the business impacts of an unauthorized incursion by locking down the rogue user or device. All monitoring logs should be retained and archived for use in forensic investigations and to provide audit evidence.

## Automate Policy Enforcement

Companies should deploy a policy engine to automate decisions and enforcement. Zero-trust security violations must be addressed in real time to protect the IT environment fully. Teams can evaluate unauthorized access attempts that were denied after the fact to determine if policies should be modified.

Organizations should define remediation workflows for non-compliant devices that fail health checks and result in denied access attempts. These devices should be serviced promptly to address their issues. Teams should strongly consider [implementing policy-as-code](https://aws.amazon.com/blogs/infrastructure-and-automation/a-practical-guide-to-getting-started-with-policy-as-code/) to achieve more consistent deployments that comply with governance and compliance requirements.

## Governance, Compliance, and Attack Surface Reduction

Organizations must exercise effective governance to avoid control drift, which can undermine the viability of zero trust. Governance efforts should incorporate the following elements.

- Businesses should establish ownership and accountability by designating a zero-trust program owner and forming a cross-functional governance committee to make decisions about access policies and exceptions. The committee should formally document access policy standards and processes for handling exceptions.
- Companies must support identity lifecycle governance that enforces zero-trust policies across an entity’s changing roles and revokes all access immediately when access is no longer needed. Access policies should be periodically reviewed and recertified to ensure they still align with business and security objectives.
- Decision-makers should continuously review and tune zero trust policies. Excessive privileged access should be trimmed to eliminate the risk if credentials are compromised. Teams should use metric-driven tuning to make changes based on real-world events.

Companies must implement zero trust to support any applicable compliance frameworks such as HIPAA or PCI DSS. Access controls for sensitive and regulated data should align with compliance standards. Teams must document policies and retain logs to provide evidence for compliance audits.

Businesses should consider attack surface reduction to be an ongoing process. Efforts to reduce entry points for threat actors should be security-focused. Teams should schedule attack surface reduction exercises and use the results to inform infrastructure changes that support a zero-trust architecture.

## Pilot, Rollout, And Iterative Expansion

Companies should begin their zero trust journey by selecting a high-impact pilot case to validate controls and processes. Teams can collect and evaluate key KPIs to gauge the impact of zero trust principles on user access to sensitive data and on operational metrics.

Once the organization is satisfied with the details of its zero trust strategy, security controls can be scaled across additional applications and cloud resources. Ideally, replicating the strict access controls across all critical assets can be done with minimal impact on business operations.

## Zero Trust Checklist

Teams can consult the following checklist of the major components of zero trust.

1. Identify the critical DAAS that must be protected and the attack surface that provides threat actors access to these resources.
2. Inventory all users, devices, and applications to determine how they fit into the security and grant them least-privilege access to authorized assets.
3. Deploy strong authentication methods including MFA and passwordless solutions when possible.
4. Enforce infrastructure microsegmentation and device trust policies.
5. Implement continuous monitoring and alerting solutions to identify and address threats in real time.
6. Review policies and logs regularly to fine-tune access controls and address identified vulnerabilities.

## Operationalize Maturity, Metrics, and Next Steps

Organizations that implement zero trust typically proceed through the following stages as the process matures.

- **Stage 0 -Traditional:** Perimeter-based security via VPNs that support implicit trust once inside the network.
- **Stage 1 – Initial:** Pilot program that implements ZTNA and MFA on select critical applications.
- **Stage 2 – Developing:** ZTNA protects most applications, and companies introduce policy-as-code and define identity lifecycle processes.
- **Stage 3 – Defined:** All applications are covered by ZTNA with minimal VPN usage and standardized policy-as-code deployment.
- **Stage 4 – Optimized:** Characteristics include continuous verification, automated policy tuning, and adaptive risk-based access.

Teams commonly measure many KPIs to evaluate the effectiveness of their zero trust environment, including:

- The percentage of users subject to MFA;
- The percentage of applications migrated to ZTNA;
- Mean time to detect (MTTD) anomalous behavior;
- Mean time to respond (MTTR) to incidents;
- Time to revoke access when offboarding employees;
- Number of stale access grants revoked upon review.

Companies should schedule quarterly reviews of the zero trust policy’s scope and controls. The review provides an opportunity to refine controls to better protect sensitive resources. Businesses in the early stages of zero trust adoption should plan to cover all remaining assets and services and reach the phase as soon as possible.

 


---

# GPU Memory Bandwidth: Calculation & Optimization Guide

> URL: https://www.atlantic.net/gpu-server-hosting/gpu-memory-bandwidth/ | Published: 2026-08-07 | Author: Dr. Tehseen Zia

If you have ever seen a GPU struggle to work efficiently during a training run, you might have wondered why it could not finish the task faster. The reason usually comes down to memory bandwidth. This guide explains what GPU memory bandwidth is, how to calculate it, and why it often matters more than raw VRAM capacity or core count in machine learning and HPC.

This guide is written for engineers, data scientists, and infrastructure teams who want a working understanding of the topic. It helps them to read a spec sheet critically, run a benchmark, and make a sensible hardware decision. We will cover GPU architecture basics, the bandwidth formula with a worked example, how to measure bandwidth on real hardware, and how to optimize models when bandwidth is the bottleneck.

## Introduction To GPU Memory Bandwidth

GPU memory bandwidth is the rate at which data moves between a GPU’s memory chips and its processing cores. It is usually expressed in bytes per second or gigabytes per second (GB/s). While it may seem like just another specification on a datasheet, it plays a critical role in real-world performance by determining how quickly the GPU can access the data it needs to perform computations.

A GPU may have thousands of processing cores and operate at very high clock speeds, but those advantages mean little if the cores cannot receive data fast enough. When memory cannot keep pace, the cores remain idle, waiting for the next batch of data to arrive. This is a common bottleneck in machine learning and high-performance computing (HPC) workloads, where gigabytes of data must be transferred every second between memory and the GPU’s compute units. Without sufficient memory bandwidth, even the fastest processors spend time waiting for data instead of performing computations.

## Prerequisites for Understanding GPU Memory

You do not need to be a GPU expert to follow this guide, but having a basic understanding of a few concepts will make the discussion easier.

- **How GPUs differ from CPUs:** A GPU uses thousands of simpler processing cores to execute many operations in parallel, whereas a CPU relies on a smaller number of more powerful cores optimized for sequential tasks.
- **Bits versus bytes:** GPU specifications often use both units, so understanding the difference will help you interpret memory bandwidth figures correctly.
- **Basics of neural network training:** If your primary interest is machine learning, a general understanding of how data moves between memory and compute units during training will provide useful context.

If you would like to explore the topic in more depth, NVIDIA’s architecture whitepapers (Ampere, Hopper, Blackwell) cover useful technical details without becoming overly technical. It is helpful to have access to a GPU system with the appropriate drivers and toolkit installed so you can follow along with the examples later in this guide. If you do not have access to a local workstation, a cloud-based GPU instance can also be used to evaluate a GPU with specific memory technology.

## GPU Anatomy: Graphics Card and GPU Memory

A graphics card consists of several key components. At the center of these components is the GPU die, which performs the computations. Surrounded by the GPU die are the memory chips that store data, the memory controller that manages data transfers, a memory bus that connects the GPU to its memory, a PCIe interface for communicating with the rest of the system, and the power and cooling hardware to keep the card operating reliably.

The GPU’s processing cores do not communicate directly with the memory chips. Instead, every read and write request passes through the memory controller, which coordinates the flow of data over the memory bus (an electrical pathway that connects memory to the die). The controller ensures that data reaches the right location at the right time while maximizing memory access efficiency.

The amount of data that can be transferred per second depends primarily on two factors: the width of the memory bus, measured in bits, and the memory’s transfer rate, often referred to as memory speed. An easy way to visualize these concepts is to imagine the memory bus as a highway. A wider highway allows more vehicles to travel side by side, while faster traffic increases the number of vehicles passing a given point each second. Likewise, a wider memory bus moves more data in parallel, and faster memory transfers that data more quickly. Together, these two characteristics determine the GPU’s available memory bandwidth.

### Memory Types: GDDR vs. HBM

GPUs primarily use one of two memory technologies: GDDR (Graphics Double Data Rate) or HBM (High Bandwidth Memory). While both serve the same purpose, they differ significantly in their design and performance characteristics.

Most consumer graphics cards and many professional GPUs use GDDR6 or GDDR6X memory. In these technologies, the memory chips are mounted separately around the GPU die on the circuit board. GDDR achieves bandwidth by operating at very high data transfer rates. This makes it more suitable for gaming, graphics rendering, and a wide range of professional workloads.

By contrast, the highest-end AI and HPC accelerators increasingly rely on HBM3 and HBM3e. Instead of placing memory chips around the GPU, HBM stacks multiple memory dies vertically and connects them to the GPU through a [silicon interposer](https://anysilicon.com/semipedia/interposer/). This design dramatically reduces the distance data must travel and enables a wide memory interface. While HBM operates at lower clock speeds than GDDR, it delivers substantially higher bandwidth by transferring data across thousands of parallel connections simultaneously.

#### *HBM vs GDDR: Bandwidth*

The biggest architectural difference between GDDR and HBM lies in the memory bus width. Most GPUs equipped with GDDR6 or GDDR6X use a 256-bit or 384-bit memory bus. In contrast, each HBM stack provides a 1,024-bit interface, and a single GPU can incorporate multiple HBM stacks. For example, the [NVIDIA H100](https://www.nvidia.com/en-us/data-center/h100/) combines several HBM3 stacks to achieve a total memory bus width in the thousands of bits.

Bandwidth depends on more than just bus width. The physical arrangement of the memory also plays a role. In GDDR, the memory chips are distributed around the GPU on the circuit board. This design requires data to travel relatively long electrical traces. In HBM, memory is placed much closer to the GPU, allowing data to travel along much shorter electrical pathways. This design reduces signal loss, improves signal integrity, and lowers power consumption. These advantages allow HBM to implement much wider memory interfaces and provide significantly higher memory bandwidth than GDDR-based GPUs.

## How GPU Memory Bandwidth Is Calculated

As mentioned before, peak GPU memory bandwidth relies on two factors: memory bus width and the memory transfer rate (often called the effective memory clock speed). To find the theoretical peak bandwidth, we can multiply these two values, consider the memory’s data rate, convert bits to bytes, and get:

Bandwidth (bytes/sec) = Memory Clock Speed (Hz) × Bus Width (bits) × Data Rate Multiplier ÷ 8

Dividing by 8 converts bits to bytes, since memory bus width and data rates are measured in bits, while bandwidth is conventionally reported in bytes. The data rate multiplier accounts for double data rate (DDR) memory, which transfers data on both the rising and falling edges of each clock cycle, effectively doubling throughput.

GDDR6, GDDR6X, and HBM all use DDR technology, although the exact multiplier varies. For example, GDDR6X uses PAM4 signaling, which allows it to transfer more than two bits per clock cycle and achieve a higher effective data rate. Most GPU specifications already report the effective memory clock speed, so you can use that value directly when calculating memory bandwidth.

### Calculation Example: 256-bit GDDR6 16 Gbps

To calculate the memory bandwidth, consider a GPU with a 256-bit memory bus and GDDR6 memory rated at 16 Gbps per pin. This configuration is common for many mid-range graphics cards. First, you should confirm the effective memory speed. GDDR6 specifications already report the effective data rate, so the listed 16 Gbps per pin can be used directly.

You can then apply the bandwidth formula:

Bandwidth = 16 Gbps × 256 bits ÷ 8 = 512 GB/s

The result is a peak theoretical memory bandwidth of 512 GB/s. In real applications, sustained bandwidth is usually lower because memory access is not perfect. Well-optimized workloads often achieve around 80–90% of the theoretical peak, providing a helpful benchmark for evaluating real-world GPU performance.

## Why High Memory Bandwidth Matters for Machine Learning And HPC

Machine learning and high-performance computing (HPC) workloads move enormous amounts of data between memory and the GPU’s compute cores. During neural network training, the GPU repeatedly reads model weights, activations, and gradients from memory and writes back the updated values. If the memory subsystem cannot supply data fast enough, the GPU’s compute cores remain idle. In these situations, adding more cores or increasing clock speeds does little to improve performance because memory bandwidth has become a bottleneck.

This bottleneck often appears before a GPU utilizes its advertised peak FLOPS. A useful concept for understanding this phenomenon is arithmetic intensity, which measures the number of floating-point operations performed per byte of data transferred from memory. Many neural network operations, including convolutional and attention layers, have relatively low arithmetic intensity. This makes them more likely to be limited by memory bandwidth than by raw compute performance.

The impact becomes even greater as model size increases. Training models with billions of parameters can involve moving tens of gigabytes of data during every training step. At that scale, the difference between 500 GB/s and 2 TB/s of memory bandwidth can significantly reduce training time.

It is also important to distinguish memory bandwidth from VRAM capacity. VRAM determines whether a model fits into GPU memory, while bandwidth determines how quickly the GPU can access that data. A GPU with ample VRAM but limited bandwidth may still perform poorly on data-intensive AI and HPC workloads. Both specifications are important, but they measure different aspects of GPU performance.

## Measuring And Benchmarking GPU Memory Bandwidth

While manufacturer specifications provide a theoretical peak, it is often more useful to measure memory bandwidth directly on the hardware you plan to use. Benchmarks such as STREAM and its GPU counterpart, [GPU-STREAM](https://research-information.bris.ac.uk/ws/files/79450418/gpu_stream_2.pdf), are widely used for this purpose.

To measure bandwidth, you can install and build GPU-STREAM for your GPU platform. Then run its standard copy, scale, add, and triad benchmarks. Each test reports sustained memory bandwidth in GB/s. This gives a realistic measure of performance under typical workloads rather than an idealized theoretical value.

It is used to compare the measured bandwidth with the manufacturer’s peak specification. A result that is 10–20% below the theoretical maximum is generally expected because of normal hardware and software overheads. A significantly larger gap may indicate issues such as outdated drivers, thermal throttling, or an improperly configured system that should be resolved before relying on the results for performance analysis or capacity planning.

### Tools And Commands

The nvidia-smi utility, included with NVIDIA GPU drivers, provides a quick overview of GPU memory usage:

nvidia-smi –query-gpu=memory.used, memory. total, utilization.memory –format=csv

This command shows memory usage, but it does not directly report memory bandwidth. The utilization.memory metric indicates how much the memory subsystem is used. When memory utilization is high,h but GPU compute utilization is low, the workload is memory-bandwidth-limited.

For a detailed analysis, [NVIDIA Nsight Compute](https://developer.nvidia.com/nsight-compute) profiles individual GPU kernels. It reports memory bandwidth, cache usage, and other performance metrics. This helps us determine which parts of an application are memory-access limited and which are computation-limited. To obtain consistent results, automate your benchmarks. Run GPU-STREAM with batch sizes, precision settings, or GPU configurations. Log the results to a CSV file. Collecting measurements over time makes it easier to compare hardware. It also helps evaluate optimizations and detect performance regressions.

## Optimizing Models to Reduce GPU Memory Bandwidth Usage

When memory bandwidth becomes a bottleneck, we can apply several techniques to improve performance without requiring new hardware.

Mixed precision training is one way to do this. It uses FP16 or BF16 instead of FP32 to reduce the amount of data that is transferred during training. This technique often provides one of the largest performance gains for modern AI workloads.

We can also use gradient checkpointing to reduce memory traffic. This stores intermediate activations during the forward pass and then recomputes them as needed during backpropagation. A closely related technique is called activation rematerialization. This technique discards some values and recomputes them rather than keeping all of them in memory. This helps reduce the bandwidth demands of large models.

Reducing the batch size is another option. This reduces the amount of data moved during each training step. Although this may reduce training, it can improve performance on bandwidth-constrained systems.

Finally, we can optimize the data pipeline for our models. We can use data loaders, prefetching,g and asynchronous data transfers to keep the GPU supplied with data. This reduces idle time caused by slow disk or system memory access. While these techniques do not increase memory bandwidth, they can help make better use of the available bandwidth.

## Choosing A Graphics Card for Bandwidth-Heavy Workloads

For bandwidth-intensive workloads, GPUs equipped with HBM generally outperform those using GDDR, even when their compute specifications appear similar on paper. For example, the NVIDIA H100 Graphics Card can deliver up to 3.9 TB/s of bandwidth using HBM3. On the other hand, a high-end GDDR6X consumer card can only deliver roughly 900 GB/s to just over 1 TB/s. This difference is particularly important for large-scale AI training, where memory bandwidth often has a greater impact on performance than core count alone.

For systems with multiple Graphics Cards, the bandwidth between the cards is just as important as the memory bandwidth on each card. A GPU with excellent memory bandwidth can still become a bottleneck if data cannot move quickly enough between GPUs during distributed training. If you plan to use multiple GPUs for your workload, look for systems that support NVLink, as it offers substantially higher inter-GPU bandwidth than PCIe alone.

Cloud GPU instances are also worth considering, especially for organizations that want to avoid investing in hardware that may become outdated within a few years. Providers offer both GDDR and HBM options to match the hardware to your workload. For example, Atlantic.Net’s GPU Cloud Hosting provides NVIDIA L40S cards with GDDR6 memory and NVIDIA H100 NVL cards with HBM3 memory, each with roughly 3.9 TB/s of bandwidth. These options allow you to scale resources as project requirements evolve without the upfront cost of purchasing hardware. When comparing cloud offerings, you should consider the cost per gigabyte-per-second of memory bandwidth rather than focusing only on the hourly rental price.

### Cost Vs Performance Considerations

When comparing GPUs, consider not only the hourly cost but also the amount of memory bandwidth you get for that price. A simple way to compare options is to calculate the cost per GB/s by dividing the hourly cost of a GPU instance by its rated memory bandwidth. For example, a GPU that costs $2.50/hour and provides 900 GB/s of bandwidth works out to about $0.0028 per GB/s per hour, while a GPU costing $4.50/hour with 3.9 TB/s (3,900 GB/s) of bandwidth comes to roughly $0.0012 per GB/s per hour. If your application can take advantage of the additional bandwidth, the more expensive GPU may offer better value.

The key is to match the hardware to your workload rather than simply choosing the GPU with the highest bandwidth. Compute-bound applications with high arithmetic intensity may not benefit much from HBM. In contrast, bandwidth-intensive workloads, such as training large transformer models, can often achieve significantly better performance on GPUs with higher memory bandwidth.

## FAQs About GPU Memory Bandwidth

What does memory bandwidth measure? It measures how much data can be transferred between a GPU’s memory and its processing cores each second, typically expressed in gigabytes per second (GB/s). It reflects data transfer speed, not the GPU’s computational power.

Can bandwidth be increased after purchase? Not significantly. It is largely determined by the GPU’s hardware, including the memory type, bus width, and memory clock speed. While some GPUs support modest memory overclocking, the underlying memory architecture cannot be changed after the card is manufactured.

What’s the difference between bandwidth and VRAM size? VRAM determines how much data the GPU can store at one time, while memory bandwidth determines how quickly that data can move between memory and the GPU’s compute cores. A GPU can have a large amount of VRAM but relatively low bandwidth, or vice versa, so both specifications should be evaluated independently.

Which GPUs suit machine learning best? It depends on the workload. For large-scale model training, HBM-equipped GPUs such as the NVIDIA H100 provide better memory bandwidth and are generally the best choice. For smaller models, fine-tuning, or inference workloads, GDDR6-based GPUs such as the NVIDIA L40S often provide excellent performance at a lower cost.

Where can I test a workload before committing to hardware? Cloud GPU platforms are often the most practical option. They allow you to run your actual workloads on different GPU types before making a purchase. This makes it easier to compare performance, evaluate costs, and choose the hardware that best fits your application.

## Conclusion And Next Steps for Machine Learning And HPC

GPU memory bandwidth is one of the most overlooked specifications when choosing hardware, yet it often determines how quickly machine learning and HPC workloads complete. When evaluating a GPU, consider the memory bus width and effective memory clock speed together; treat VRAM capacity and memory bandwidth as separate specifications; and use techniques such as mixed-precision training, gradient checkpointing, and data loading to reduce bandwidth bottlenecks.

Before investing in new hardware, benchmark your actual workload instead of relying solely on specification sheets. Running a quick STREAM or GPU-STREAM benchmark on a cloud GPU instance can reveal how a GPU performs under real conditions. Cloud platforms such as Atlantic.Net’s GPU Cloud Hosting let you evaluate workloads on GPUs like the NVIDIA L40S and NVIDIA H100 NVL on an hourly basis. This makes it easier to compare performance and choose the right hardware before committing to a larger investment.


---

# GPU vs TPU vs NPU: Choosing the Right AI Accelerator

> URL: https://www.atlantic.net/gpu-server-hosting/gpu-vs-tpu-vs-npu-ai-accelerators/ | Published: 2026-08-14 | Updated: 2026-07-20 | Author: Dr. Tehseen Zia

Choosing the right AI accelerator is one of the most important decisions when building or scaling AI infrastructure. GPUs, TPUs, and NPUs are all designed to accelerate AI workloads, but they are built for different purposes. The best choice depends on the type of workload, performance requirements, deployment environment, and budget. This guide is written for infrastructure architects, DevOps engineers, and technical decision-makers who need practical guidance. Instead of comparing specifications, it explains where each accelerator falls short and the trade-offs to consider before investing.

We will see how GPUs, TPUs, and NPUs are used across four common deployment environments: public cloud, on-premises data centers, edge servers, and embedded devices. Rather than asking which accelerator is “best,” the more useful question is which one is the best fit for your workload. Understanding these differences can help you make more informed infrastructure decisions, improve performance, and avoid unnecessary costs.

## Quick Comparison: GPU vs TPU vs NPU

Before diving into the details, let’s start with a quick comparison of the three accelerators.

| **Accelerator** | **Primary Role** | **Typical Location** | **Power Draw** | **Relative Cost** |
| --- | --- | --- | --- | --- |
| GPU | General-purpose parallel compute, training and inference | Cloud, data center, workstation | High (150–700W per card) | Moderate to high |
| TPU | Large-scale tensor math for training and serving | Cloud (Google’s data centers) | High, but per operation | High, usage-based |
| NPU | Low-power inference for trained models | Phones, laptops, cameras, embedded boards | Low (under 5W typically) | Built into the device |

We can summarize the use of each accelerator as follows:

- GPUs provide flexibility to handle AI training, graphics rendering, scientific simulations, and many other parallel computing tasks on the same hardware.
- TPUs are purpose-built to accelerate large-scale AI training and inference, providing high throughput for matrix-intensive workloads.
- NPUs are designed for energy-efficient AI inference, enabling real-time predictions on devices such as smartphones, cameras, and IoT systems while minimizing power consumption.

## Central Processing Unit (CPU) and Graphics Processing Unit (GPU)

The CPU remains the backbone of every AI system. It handles tasks that are not well suited to parallel execution, such as reading and preprocessing data, managing memory, scheduling workloads, coordinating AI accelerators, and executing branching or decision-based logic. While GPUs, TPUs, and NPUs accelerate AI computation, the CPU orchestrates the workflow and keeps the entire system running efficiently. Even the most powerful GPU cluster still needs a CPU host to manage traffic between storage, network, and accelerator.

When your model is small, your batch size is one, or latency requirements are measured in microseconds rather than milliseconds, the CPU may be the simplest choice. It is the best for workloads that involve branching logic, small datasets, or sequential operations where each step depends on the previous one. Examples of workloads suitable for CPUs include data preprocessing, API request handling, business logic, and rule-based processing.

## CPU vs GPU: When to Offload

The core difference between a CPU and a GPU comes down to how each handles latency versus throughput. A CPU has a handful of powerful cores designed to complete one instruction sequence as fast as possible. In contrast, a GPU contains thousands of smaller cores for performing the same operation across many data elements simultaneously. This parallel architecture enables GPUs to outperform CPUs on highly parallel workloads, such as the large matrix multiplications used to process batches of images or text tokens during AI training. In contrast, workloads that involve sequential or dependent operations, such as parsing configuration files or evaluating conditional branches, are better suited to CPUs. As a general rule, we should use GPUs for highly parallel computations and CPUs for tasks that depend on sequential execution and complex control flow.

### The Origins of GPUs

GPUs were originally developed to accelerate computer graphics, not to train AI models. Rendering a 3D scene requires processing millions of pixels simultaneously, so GPU architecture was designed to perform thousands of calculations in parallel. As deep learning emerged, researchers realized that this same parallel architecture was ideally suited to the large matrix computations at the core of neural networks. As a result, GPUs quickly became the preferred hardware for AI training and later for many inference workloads.

Modern GPUs build on this architecture by adding tensor cores, specialized processing units designed to accelerate the matrix multiplications. These cores support mixed-precision computing, enabling faster AI training and inference while reducing computational overhead. As a result, today’s data center GPUs can deliver performance that once required much larger computing clusters.

It is also important to distinguish between integrated and discrete GPUs. Integrated GPUs share memory and power with the CPU, making them better suited for graphics tasks, multimedia applications, and basic AI experimentation. Discrete GPUs include dedicated high-bandwidth memory and substantially more computing resources, which make them the preferred choice for training AI models and running production-scale inference workloads.

### Tensor Processing Unit (TPU)

A [TPU](https://cloud.google.com/tpu) is Google’s custom-designed AI accelerator built specifically for machine learning workloads. Unlike a GPU, which uses a general-purpose parallel architecture, a TPU is built around a systolic array. In this design, data flows through a grid of processing elements, with each element performing a computation and passing the result to the next. By keeping data moving through the chip rather than repeatedly accessing memory, TPUs significantly reduce memory traffic, a key bottleneck in large-scale AI training and inference.

Google’s latest TPU generation introduces separate designs for AI training and low-latency inference. Its newest inference-focused architecture, Ironwood, scales to pods with up to 9,216 interconnected chips for high-performance AI inference. This architecture is built to support the demanding inference workloads of large foundation models and reasoning applications while maintaining low latency and high throughput.

TPUs are only available through Google Cloud, and they are tightly integrated with TensorFlow and JAX. Although PyTorch support has improved, organizations that rely heavily on PyTorch or need the flexibility to deploy workloads across multiple cloud providers should carefully consider these constraints before adopting a TPU-based infrastructure.

### Neural Processing Unit (NPU)

An NPU is a specialized AI accelerator designed to run trained models efficiently while consuming very little power. It is typically integrated into a [system-on-chip (SoC)](https://www.synopsys.com/glossary/what-is-system-on-a-chip.html), where it works alongside the CPU and GPU on the same chip. Examples include Apple’s Neural Engine, Qualcomm’s Hexagon NPU, Intel’s AI Boost, and AMD’s XDNA architecture. These architectures enable on-device AI capabilities in modern smartphones, laptops, and AI PCs.

A key advantage of an NPU is its exceptional power. It can continuously run vision, speech, or other lightweight AI models using a little power. This makes it well suited for battery-powered devices. Common on-device applications include face enable, real-time photo enhancement, wake-word detection, live translation, and background noise suppression during calls. In each case, the AI model has already been trained elsewhere. The role of the NPU is to execute inference locally, without sending data to the cloud.

## GPUs, TPUs, NPUs in Artificial Intelligence Workflows

A typical AI project consists of two main phases, and each type of accelerator plays a different role. The first phase is training, where AI models learn patterns from large datasets over many hours or even days. This compute-intensive process is typically performed on GPUs or TPUs in cloud or on-premises data centers. The second phase is inference, where a trained model generates predictions on new data. Depending on the deployment scenario, inference can run in the cloud, on edge servers, or directly on end-user devices using an NPU. Throughout both phases, CPUs play an essential role in data loading, preprocessing, workload orchestration, and pre- and post-processing during inference.

Before committing to hardware architecture, it is important to profile your model on the hardware you are considering. A model that trains efficiently on a GPU cluster might behave very differently once quantized and deployed on an NPU. Evaluating performance early helps identify bottlenecks, optimize deployment, and avoid costly redesigns later in the development cycle.

## GPU vs. TPU vs. NPU: Performance and Precision

For AI compute throughput, high-end GPUs and TPUs can deliver comparable performance. The better choice depends on factors such as the model architecture, batch size, software framework, and workload characteristics. GPUs provide greater flexibility and support for a wider range of AI and high-performance computing workloads. TPUs, on the other hand, are optimized for large-scale, homogeneous training and inference tasks that can fully utilize Google’s specialized architecture.

Inference latency presents a different set of requirements. NPUs are built for single-digit-millisecond responses on small models, which matters when a camera needs to detect a face before the next frame arrives. GPUs and TPUs also support inference workloads, but they are typically optimized for serving large AI models in cloud and data center environments rather than for low-latency, on-device execution.

Support for numerical precision also differs across AI accelerators. Modern GPUs efficiently support a wide range of data formats, including FP32, FP16, bfloat16, FP8, and integer formats such as INT8, depending on the hardware generation. TPUs are optimized for lower-precision formats, particularly bfloat16, mainly for training and inference at scale. NPUs typically rely on INT8 or even lower-precision integer arithmetic to reduce memory usage and power consumption for on-device AI.

## Data Centers and Hybrid AI Architectures

For many organizations running production AI training workloads, GPU clusters remain the most versatile option. They support a broad range of model architectures, integrate with virtually every major machine learning framework, and can be deployed across multiple cloud providers or on-premises environments. Providers such as Atlantic.net offer GPU Cloud Hosting with NVIDIA H100 NVL and L40S GPUs. They allow teams to provision either shared or dedicated GPU resources on demand without investing in their own hardware. TPU Pods become an attractive alternative when workloads are already optimized for TensorFlow or JAX and can benefit from Google’s large-scale TPU infrastructure.

Choosing an accelerator is only one aspect of the infrastructure decision. A modern AI platform also depends on high-performance networking, fast storage, and data movement. Data Processing Units (DPUs) offload networking, storage, and infrastructure services from CPUs and AI accelerators, freeing GPUs and TPUs to focus on AI computation. Similarly, high-speed interconnects such as NVLink and InfiniBand play a critical role in multi-accelerator systems. Even the most powerful GPU cannot perform efficiently if it has to wait for data.

## Edge, Embedded, and On-Device AI Inference

For real-time inference on a phone, camera, or embedded controller, an NPU is usually the right choice. It delivers low-latency predictions while operating within the tight power constraints of battery-powered systems. That said, not every model operation is supported by a given NPU runtime. For this reason, production applications should include a CPU fallback path for unsupported operations. A model that runs slightly slower is far more reliable than one that fails because part of the computation cannot be executed on the NPU.

Memory capacity and memory bandwidth are often the first limitations we encounter when deploying AI models. Edge devices typically have much less memory than data center GPUs, so models that run efficiently in the cloud may need to be pruned, quantized, or otherwise optimized before they can run on the target hardware. It’s also important to validate performance on the actual device rather than relying solely on a simulator, because thermal throttling, power management, and memory behavior can significantly affect real-world performance.

## AI Accelerators: Software, Frameworks, and Toolchains

Each accelerator comes with its own software stack, and choosing hardware without checking framework support is a common mistake. NVIDIA GPUs integrate with PyTorch, TensorFlow, and JAX through CUDA, while AMD GPUs rely on ROCm. TPUs are optimized for TensorFlow and JAX through the XLA/OpenXLA compiler stack, which transforms computation graphs for Google’s hardware. NPUs typically rely on vendor-specific compilers, such as Apple’s Core ML tools or Qualcomm’s SNPE.

A practical approach is to train the model in your preferred framework, export it to ONNX or another supported intermediate format, compile it with the target accelerator’s toolchain, and then validate the deployed model on the actual hardware. Quantization and graph optimizations can change outputs in ways that are only visible once you run real test cases. It is essential to validate accuracy and performance using representative production workloads rather than assuming the compiled model will behave the same as the original.

## Cost, Power, and Sustainability Trade-Offs

The hourly price of an accelerator tells only part of the story. What matters is the cost of completing the workload. For example, a TPU Pod may cost more per hour than a GPU cluster but finish a training run faster, resulting in a similar (or even lower) cost. GPUs also benefit from a broad cloud ecosystem, with many providers offering flexible pricing options, including on-demand, reserved, and hourly instances.

Energy becomes increasingly important as AI moves closer to the edge. In data centers, a modest increase in power consumption may be an acceptable trade-off for higher throughput. On an edge device, every milliwatt affects battery life, making an NPU’s energy a core design requirement rather than simply a performance advantage.

When evaluating AI infrastructure, consider the total cost of ownership rather than just hardware or rental costs. This includes power and cooling, networking, engineering effort to optimize models for a specific accelerator, software portability, and the operational cost of deploying and maintaining AI workloads over time. Cloud providers such as [Atlantic.net](https://www.atlantic.net/gpu-server-hosting/gpu-cloud-hosting/) can help reduce deployment risk by offering flexible GPU instance sizes, hourly billing, and both dedicated and shared GPU options. This makes it easier to benchmark different configurations before scaling to production.

## Choosing the Right AI Accelerator for Your Workload

The right accelerator depends on where your AI workload runs and what you need it to accomplish. For training large models from scratch, GPUs and TPUs are the strongest choices. GPUs provide broad framework support, deployment flexibility, and portability across cloud providers, while TPUs are an excellent option for TensorFlow and JAX workloads.

For low-latency inference on smartphones, cameras, and embedded devices, NPUs are typically the best choice. They deliver real-time AI inference while operating within the power constraints of edge devices.

CPUs continue to play a critical role throughout the AI pipeline. Tasks such as data loading, preprocessing, request routing, orchestration, and post-processing are generally better suited to CPUs. Offloading these operations to a GPU or NPU often increases system without delivering meaningful performance gains.

## Checklist for Deploying AI Accelerators

Before committing to any single accelerator for a production workload, run through this list:

- Benchmark your actual model on each candidate accelerator.
- Measure latency, throughput, and power consumption under realistic load.
- Validate accuracy after quantization, since compressed models can behave differently than their full-precision originals.
- Plan network and storage I/O for any distributed training or multi-node serving setup, since accelerators are only as fast as the data pipeline feeding them.

## Appendix: Acronyms and Chip Types

CPU (Central Processing Unit): The general-purpose processor that handles sequential logic, orchestration, and system control in every computing environment.

GPU (Graphics Processing Unit): A parallel processing chip originally built for rendering graphics, now widely used for training and running AI models.

TPU (Tensor Processing Unit): Google’s custom chip built around a systolic array design, optimized for large-scale tensor math in training and serving AI models.

NPU (Neural Processing Unit): A low-power chip built into mobile and embedded devices, designed to run trained AI models efficiently on-device.


---

# What Is an Attestation of Compliance (AoC): PCI DSS Guide

> URL: https://www.atlantic.net/pci-compliant-hosting/pci-dss-attestation-of-compliance-aoc/ | Published: 2026-08-14 | Updated: 2026-07-20 | Author: Robert Agar

A PCI DSS Attestation of Compliance (AoC) is a formal document that records the outcome of a PCI DSS assessment. When an organization is assessed as compliant, the AoC states that it met the applicable PCI DSS requirements within the defined assessment scope.

Merchants and service providers that process, store, or transmit payment card data may be required to provide an AoC as evidence of compliance. The precise validation and submission requirements depend on the applicable payment brands, acquiring bank, contractual arrangements, transaction volumes, and assessment program.

The AoC identifies the organization being assessed, the assessment scope, the assessment method, the applicable PCI DSS version, and the compliance status. It is normally completed alongside a Self-Assessment Questionnaire (SAQ) or a Report on Compliance (RoC).

This article explains what an AoC does, who may need one, how the PCI DSS assessment process works, how to prepare for and maintain compliance, how an AoC differs from a Report on Compliance, the common issues that slow validation, and how to complete the attestation process more efficiently.

An AoC may also carry contractual or commercial significance. An organization that cannot provide requested evidence of PCI DSS compliance may face consequences under its acquiring agreement, payment-brand program, customer contracts, or insurance terms. The exact consequences depend on the applicable agreements, rules, circumstances, and law.

## DSS Attestation of Compliance

A PCI DSS AoC is an industry-specific document based on templates published by the PCI Security Standards Council (PCI SSC). It has several features that distinguish it from more general attestations or certifications:

- The PCI DSS assessment framework is maintained by a private industry standards organization rather than a governmental agency.
- PCI DSS AoCs use standardized templates. Annual compliance validation is commonly required, although an AoC records assessment results at a particular point in time rather than serving as a certificate that guarantees compliance for a fixed 12-month period.
- The attestation process addresses the protection of payment account data within the defined PCI DSS assessment scope.
- PCI DSS applies to entities that store, process, or transmit payment account data, as well as entities that can affect the security of the cardholder data environment. Formal assessment and AoC submission requirements depend on the applicable payment brand, acquirer, and contractual rules.
- Compliance programs are generally administered by payment brands and acquiring banks. Depending on applicable rules and agreements, non-compliance may result in contractual penalties, increased fees, additional validation requirements, or restrictions on card-processing privileges.

The AoC is an attestation of the assessment results and uses information from an SAQ or RoC. The SAQ or RoC contains the detailed evaluation of the organization’s security controls, while the AoC provides a standardized summary of the assessment scope, method, and outcome.

The AoC should not be described as a general PCI DSS certification or as a guarantee of continuing compliance. It records the assessment result based on the environment and evidence reviewed during the assessment period.

## Who Needs a PCI Attestation to Determine Compliance?

Entities that process, store, or transmit cardholder data must comply with applicable PCI DSS requirements. Not every entity is required to submit the same validation documents.

Whether a merchant must complete an SAQ, undergo a formal assessment, prepare an RoC, or submit an AoC depends on the merchant’s payment brands, acquiring bank, transaction volumes, risk profile, contractual obligations, and any instructions from the entity receiving the compliance documentation.

Merchants with lower transaction volumes may be permitted to complete an eligible SAQ and the associated AoC. Higher-volume or higher-risk merchants may be required to complete an RoC, frequently with the involvement of a Qualified Security Assessor (QSA). The specific assessment method should be confirmed with the merchant’s acquirer or payment brands.

Service providers, including payment gateways and cloud service providers, may also be required to complete an AoC. Service providers are generally evaluated under separate payment-brand classification and validation programs rather than receiving the compliance level of the merchants they support.

Merchants that have experienced a cardholder-data compromise or have been identified as presenting additional risk may be required to follow a higher level of validation. Companies should review the specific requirements of their payment brands and acquiring banks.

## Determine Compliance Level and Assessment Methodology

Merchant validation levels are established by individual payment brands and acquiring banks rather than universally defined by the PCI Security Standards Council. The thresholds and requirements can therefore differ between payment programs.

The following levels reflect the commonly cited Visa merchant-level framework and should not be treated as universal PCI SSC classifications:

## Level 1

Level 1 generally covers merchants processing more than six million Visa transactions annually. A merchant may also be assigned Level 1 status following a cardholder-data compromise or when Visa or an acquiring bank determines that additional validation is appropriate.

Level 1 merchants are generally required to complete an RoC and the associated AoC. A QSA often performs the assessment, although the specific assessor and validation requirements depend on the applicable payment brand and acquirer rules.

The assessed organization’s authorized representative signs the AoC. When a QSA or other approved assessor performs the assessment, the relevant assessor representatives also complete and sign the applicable sections.

## Level 2

Level 2 generally covers merchants processing between one million and six million Visa transactions annually.

Subject to payment-brand and acquirer rules, these merchants may be permitted to complete an eligible SAQ and associated AoC instead of undergoing a QSA-led RoC assessment.

## Level 3

Level 3 generally covers merchants processing between 20,000 and one million Visa e-commerce transactions annually.

Subject to payment-brand and acquirer rules, these merchants may be permitted to complete an annual SAQ and associated AoC.

## Level 4

Level 4 generally covers merchants processing fewer than 20,000 Visa e-commerce transactions annually or up to one million Visa transactions through other channels, such as physical stores or telephone orders.

The acquiring bank commonly determines the validation requirements for Level 4 merchants. An SAQ and associated AoC may be required or recommended depending on the applicable program.

Companies must confirm their assessment and submission requirements with their acquiring bank or payment brands rather than relying solely on transaction-volume thresholds.

## Self-Assessment Path

The self-assessment path generally includes the following steps:

- Confirming with the acquirer or payment brand that the organization is eligible to self-assess;
- Determining the correct SAQ for the organization’s payment environment;
- Completing the applicable testing and questionnaire;
- Completing any required Approved Scanning Vendor scans;
- Remediating identified compliance gaps and vulnerabilities;
- Completing and signing the associated AoC through an authorized organizational representative; and
- Submitting the SAQ, AoC, scan documentation, or other materials requested by the acquiring bank, payment brand, or customer.

The representative signing the AoC must have sufficient authority to bind the organization legally. The signer does not necessarily need to hold a particular job title such as “executive officer,” unless the applicable form or compliance program specifies otherwise.

## QSA-Led Assessment Path

A QSA-led assessment generally requires the organization to take the following steps:

- Engage a QSA Company listed by the PCI Security Standards Council;
- Accurately define the cardholder data environment and assessment scope;
- Provide the QSA with access to relevant systems, personnel, documentation, and evidence;
- Allow the QSA to evaluate the environment and applicable security controls using on-site and, where appropriate, remote assessment techniques;
- Support independent testing of the applicable PCI DSS controls;
- Address any gaps identified during the assessment;
- Complete a detailed RoC covering the applicable PCI DSS requirements;
- Review and sign the assessed entity’s sections of the AoC;
- Obtain the applicable QSA signatures; and
- Submit the AoC, RoC, or other requested documentation to the acquiring bank, payment brands, customers, or other receiving entities.

The QSA does not sign the AoC solely on behalf of the merchant or service provider. The assessed organization and the assessor each complete and sign the sections applicable to their responsibilities.

## How to Prepare for a Compliance Assessment

Organizations should prepare for a PCI DSS assessment by performing several activities related to their payment account data and cardholder data environment.

## Map Cardholder Data Flows

Teams should map cardholder-data flows to identify the scope of the cardholder data environment, including the systems, applications, people, and processes involved in storing, processing, or transmitting cardholder data.

Systems that can connect to or affect the security of the cardholder data environment may also be in scope, even when they do not directly store cardholder data.

Teams should apply the required security controls to all systems and processes included in the assessment scope.

## Consider Network Segmentation

Organizations may use network segmentation to isolate the cardholder data environment from other networks.

Segmentation is strongly recommended because properly implemented segmentation can reduce PCI DSS scope, security risk, and assessment effort. Network segmentation is not, by itself, a universal PCI DSS requirement.

Where segmentation is used to reduce scope, the organization must verify that the controls effectively isolate the cardholder data environment.

## Collect Documentation and Evidence

Companies should collect PCI-relevant policies, procedures, system configurations, scan reports, testing records, access reviews, training records, and other evidence in a secure repository.

Centralizing this information can make it easier to complete an SAQ or support a QSA-led assessment.

## Conduct Readiness Reviews

Businesses should conduct internal readiness reviews to identify gaps in security controls before beginning the formal validation process.

Internal audit, compliance, security, or other qualified personnel may support these reviews. An internal audit department is not universally required to complete every self-assessment.

## Assessment Methodology

Whether an organization uses an SAQ or undergoes a QSA-led assessment, it must evaluate the PCI DSS requirements applicable to its environment and document the results.

When a QSA is not involved, the organization performs a self-assessment using qualified personnel and the applicable SAQ instructions. Internal audit may support the assessment, but it is not automatically the function responsible for validation.

External vulnerability scans by an Approved Scanning Vendor must be completed when required by the applicable PCI DSS requirements and validation path. Internal vulnerability scanning and penetration testing must also be performed where the applicable requirements call for them.

Vulnerability scans and penetration tests are not automatically required for every AoC or SAQ. Their applicability depends on the organization’s environment, assessment scope, SAQ eligibility, and relevant PCI DSS requirements.

During an assessment, the assessor may interview subject-matter experts responsible for maintaining the payment environment. These interviews help the assessor understand the implemented controls and resolve discrepancies between documentation, observed practices, and technical evidence.

## What the AoC Document Contains

The precise structure varies between merchant and service-provider forms, but an AoC commonly includes the following sections:

## Assessment Information

This section identifies the entity being assessed, the organization performing the assessment, the applicable PCI DSS version, relevant dates, and the type and scope of the assessment.

Supporting assessment information may come from either a self-assessment or an independent assessor-led review.

## Executive Summary

The executive summary describes the organization’s payment environment and how it stores, processes, or transmits account data.

It may identify:

- The assessment methodology;
- The cardholder data environment;
- Relevant business locations;
- Payment channels;
- Service providers;
- Network segmentation;
- Technologies used in the environment; and
- Requirements determined not to be applicable, together with the supporting explanation.

## Validation and Attestation Details

This section records the assessment result and confirms the accuracy of the information provided.

The assessed entity’s authorized representative signs the applicable attestation. When a QSA, Internal Security Assessor, or another approved assessor participates, the relevant assessor signatures are also included where required.

## Action Plan for Non-Compliant Requirements

An action plan may be included when requirements are marked non-compliant, and the receiving entity requests one.

The action plan may identify:

- The non-compliant requirements;
- A description of the identified gaps;
- Planned remediation activities; and
- Target remediation dates.

The action-plan section is not necessarily completed for every compliant assessment.

Companies may also be required to provide supporting documentation, including an SAQ, RoC, Approved Scanning Vendor reports, or other evidence requested by an acquiring bank, a payment brand, a customer, or a business partner.

## PCI AoC vs. RoC

AoCs and RoCs are both PCI DSS compliance documents, but they differ significantly in purpose and scope.

An AoC is a standardized attestation summarizing the scope, assessment method, and outcome of the compliance assessment. Depending on the form and circumstances, the recorded status may include:

- Compliant;
- Non-Compliant;
- Compliant with a Legal Exception;
- Full assessment; or
- Partial assessment.

For this reason, an AoC should not always be described as delivering only a simple pass-or-fail judgment.

The assessed entity completes and signs the applicable portions of the AoC. When a QSA or other approved assessor performs the assessment, that assessor also completes and signs the applicable sections.

An RoC is a detailed technical report describing the environment, assessment procedures, evidence reviewed, testing performed, and conclusions for the applicable PCI DSS requirements.

RoCs are commonly required for higher-volume merchants and certain service providers. The precise circumstances in which an RoC is mandatory—and who is permitted to perform the assessment—depend on the applicable payment brand, acquiring bank, and validation program rules.

A merchant that has experienced a cardholder data compromise may be required to complete an RoC or follow a higher validation level, but this is not an automatic, universal rule across all payment programs.

## How Long Is an Attestation Valid?

PCI DSS compliance is not established once and then guaranteed for a fixed 12-month period.

An AoC records the result of an assessment conducted for a specified scope and assessment period. Payment brands, acquirers, and contractual programs commonly require organizations to revalidate compliance annually.

Organizations must maintain the applicable PCI DSS controls continuously between assessments. An AoC does not guarantee that the environment will remain compliant after the assessment is completed.

A change to the cardholder data environment or a cardholder data compromise may require additional testing, a scope review, or reassessment, depending on the applicable PCI DSS requirements and on instructions from the organization’s acquirer or payment brands.

Organizations should plan their annual reassessments to meet the submission deadlines set by the entity that receives their compliance documentation.

## How to Complete the Attestation of Compliance Form

Businesses must select the correct AoC template for their assessment type and applicable PCI DSS version.

All organizational, assessment, and scope information must be accurately entered in the form.

An authorized representative of the assessed organization must review and sign the applicable portions of the document and accept responsibility for the accuracy of the information. When an assessor is involved, the assessor completes and signs the sections assigned to the assessor.

The organization should submit the AoC and any supporting documents to the parties that require them, such as an acquiring bank, a payment brand, a customer, or a business partner.

## Maintaining Compliance After Attestation

Organizations must maintain PCI DSS compliance after completing an AoC. Compliance is an ongoing responsibility for businesses that accept or process payment cards.

## Continuously Monitor the Environment

Teams should continuously monitor the cardholder data environment to ensure required security controls remain in place and operate effectively.

Logs, alerts, access reviews, configuration records, and other evidence should be retained according to applicable PCI DSS requirements and organizational policies.

## Complete Required Security Testing

Companies should schedule external vulnerability scans with an Approved Scanning Vendor when required by their PCI DSS scope and validation path.

Internal vulnerability scanning, penetration testing, and other security testing should be performed at the frequencies and under the circumstances required by the applicable PCI DSS requirements.

## Monitor Third-Party Service Providers

Businesses should obtain appropriate evidence that third-party service providers responsible for storing, processing, transmitting, or securing account data are meeting their PCI DSS responsibilities.

An AoC is one form of evidence that may be reviewed. The organization should also confirm:

- The services and locations covered by the provider’s assessment;
- The date and scope of the assessment;
- Any excluded services;
- The PCI DSS responsibilities assigned to the provider; and
- The responsibilities retained by the customer.

Not every provider is required to make its AoC publicly available. Organizations should obtain appropriate evidence of compliance through contracts, due diligence processes, or direct requests.

## Update the Assessment Scope

The organization should review and update its PCI DSS scope when systems, networks, applications, processes, locations, payment channels, or vendors change.

New components that store, process, transmit, or can affect the security of account data must be evaluated to determine whether they belong within the PCI DSS assessment scope.

## Common Challenges in PCI Attestation and Compliance Assessment

Organizations should be aware of common issues that can delay an assessment or make it difficult to demonstrate PCI DSS compliance.

## Scope Misidentification

Incorrectly defining the PCI DSS scope can create substantial compliance and security risks.

Scope errors may result from:

- Underestimating connected systems that do not directly store cardholder data but can connect to or affect the cardholder data environment;
- Relying on ineffective network segmentation;
- Excluding legacy systems without sufficient evidence;
- Allowing shadow IT solutions to bypass required security controls; or
- Missing cardholder-data flows involving third parties.

## Time Pressure

Companies may face time pressure when asked to collect evidence demonstrating PCI DSS compliance.

Organizations with extensive infrastructure or decentralized documentation may find it difficult to gather the policies, configurations, logs, test results, and other records needed to support an assessment.

Maintaining evidence throughout the year can reduce the burden during annual validation.

## Control Drift After Initial Attestation

An AoC records the outcome of an assessment based on the environment and evidence reviewed during the assessment period. It does not ensure that controls will continue to operate effectively after the assessment.

Control drift may occur when:

- Teams temporarily disable firewall rules or security controls;
- Security patches are delayed;
- The business introduces new systems or applications without applying PCI DSS controls;
- Employees with critical security knowledge leave the organization;
- Documentation is not updated;
- Access privileges are not regularly reviewed; or
- Required monitoring and testing activities are not maintained.

Organizations must continue to operate and monitor their controls after the assessment is complete.

## Practical Tips to Obtain PCI Attestation Faster

Companies can take several steps to reduce the time and effort required to complete PCI DSS validation.

- Use properly implemented network segmentation where appropriate to reduce the scope of the cardholder data environment.
- Use automation to support evidence collection, control monitoring, vulnerability management, and recurring compliance activities.
- Maintain PCI DSS documentation and evidence in a centralized, access-controlled repository.
- Conduct internal readiness reviews to identify areas requiring remediation before beginning the formal assessment.
- Engage a qualified Internal Security Assessor (QSA) or other appropriate specialist when additional expertise is needed.
- Strengthen access controls to prevent unauthorized access to the cardholder data environment.
- Schedule required QSA assessments early enough to allow identified issues to be remediated before submission deadlines.
- Confirm the required validation path with the acquiring bank or payment brand before beginning the assessment.

## Resources, Templates, and Next Steps

Organizations should contact their acquiring bank, payment brand, QSA, or another qualified PCI DSS specialist when they are uncertain about their validation obligations or the correct SAQ for their environment.

PCI SSC publishes separate AoC documents and reporting templates for:

- Merchants; and
- Service providers.

Organizations should use the current templates published in the PCI SSC document library and confirm that they are assessing against the currently supported PCI DSS version.

Companies may also review publicly available AoCs to understand how completed forms are structured. For example, Akamai Technologies has publicly posted a PCI DSS v4.0.1 AoC dated June 30, 2026.

Atlantic.Net states that its PCI-focused hosting services include security controls and that its provider AoC can be made available to customers. Using a compliant hosting provider may support an organization’s compliance activities, but it does not automatically make the customer PCI DSS compliant. Each customer remains responsible for its own systems, configurations, applications, processes, assessment scope, and shared-responsibility obligations.


---

# OpenClaw Hosting: Your AI Assistant, Always On

> URL: https://www.atlantic.net/cloud-platform/openclaw-hosting-your-ai-assistant-always-on/ | Updated: 2026-09-16

Deploy OpenClaw in one click on Atlantic.Net Cloud and give your AI assistant a persistent home. Connect the model provider and chat channels you choose, keep the Gateway under your control, and reach the same assistant from wherever you work.

- Self-Hosted Gateway
- Persistent Sessions & Memory
- Multi-Channel Messaging
- Bring Your Own Model

Application Deployment: One Click

Eligible Infrastructure SLA: 100%

An assistant installed on a laptop is only available while that laptop is awake, connected, and within reach. OpenClaw Hosting moves the Gateway to an Atlantic.Net Cloud Server, where it can stay online for messages, sessions, tools, and scheduled work.

Atlantic.Net prepares the server and OpenClaw application through a [one-click deployment](https://cloud.atlantic.net/?page=userlogin). You bring access to a supported model provider, authorize the people who can use the assistant, and connect the channels that fit your workflow. The result is a self-hosted OpenClaw environment without having to assemble the base server and runtime by hand.

## What Is OpenClaw Hosting?

OpenClaw is an open-source, self-hosted Gateway that connects chat applications to an AI assistant. One Gateway can serve multiple configured channels, maintain sessions and memory, route work between agents, and expose a browser-based Control UI.

OpenClaw Hosting runs that Gateway on a persistent Atlantic.Net Cloud Server under your account. The server is a stable operating environment for OpenClaw's configuration, channel connections, session state, tools, and logs. Your phone, browser, or chat application is the way in; the Gateway remains available in the cloud.

The current one-click application uses a customer-supplied model provider. Connect OpenAI, Anthropic, OpenRouter, or another provider supported by OpenClaw, and manage model usage separately from the Cloud Server. That separation lets you change models without rebuilding the Gateway or moving its channels and state.

## Why Put the OpenClaw Gateway in the Cloud?

### Stay Available When Local Devices Are Offline

Keep the Gateway running when a desktop sleeps, a laptop changes networks, or a team member signs off. A persistent host is a better foundation for an assistant reached through chat, scheduled jobs, and longer-running tools.

### Give Every Channel One Stable Home

Connect supported services such as Telegram, Slack, Discord, Signal, WhatsApp, Microsoft Teams, Google Chat, Matrix, and more. One Gateway coordinates the channels and sessions you configure instead of scattering state across user devices.

### Keep the Gateway Under Your Account

OpenClaw's configuration and server-side state remain in an environment you administer. You decide how the Gateway is accessed, where backups are stored, which updates are applied, and which users and integrations are granted access.

### Choose Models Independently of the Host

Bring your own model provider and change models or routing as your requirements change. Infrastructure cost and provider usage stay visible as separate parts of the service.

## Deploy OpenClaw in One Click

Give your AI assistant a persistent Gateway on Atlantic.Net Cloud.

## What's Included

### One-Click OpenClaw Deployment

Select OpenClaw in the Atlantic.Net Cloud Portal, choose a Cloud Server plan and region, and launch a prepared application image. Start from a consistent installation rather than building the operating system, Node.js runtime, and base application manually.

### Persistent Gateway, Sessions, and Memory

Give OpenClaw one always-available source of truth for channel connections, routing, sessions, and working state. Persistent storage supports repeatable channel pairing, controlled backups, and continuity between devices.

### Multi-Channel Messaging

Use the supported chat and collaboration services that align with how your team already communicates. Configure each channel's bot credentials, approved users, group behavior, and routing rules from the Gateway.

### Bring Your Own Model

Connect OpenClaw to a supported provider such as OpenAI, Anthropic, or OpenRouter. Keep provider choice separate from the server so you can evaluate model quality, latency, and cost without moving the deployment.

### Tools, Skills, and Scheduled Work

OpenClaw supports tools, skills, webhooks, cron jobs, and multi-agent routing. Begin with the smallest capability set the assistant needs, validate the workflow, and expand permissions deliberately.

### Full Server Administration

Control network access, operating-system policy, monitoring, storage, and backups at the Cloud Server level. Atlantic.Net supports the infrastructure underneath the deployment while you control OpenClaw, its credentials, and its integrations.

## From One Click to Your First Conversation

### 1. Choose OpenClaw in the Cloud Portal

Select the application, server plan, and deployment region.

### 2. Connect a Model Provider

Add credentials for an OpenClaw-supported provider, then select the model you want the Gateway to use.

### 3. Authorize Access

Pair an approved user, connect a channel, and keep the browser Control UI behind a protected network path.

### 4. Test, Observe, Then Expand

Confirm sessions, model billing, logs, backups, and recovery with one user and one channel before adding broader access or more powerful tools.

## OpenClaw Hosting Use Cases

| Use case | What a persistent Gateway adds |
| --- | --- |
| Personal AI assistant | Reach the same assistant from a phone, browser, or approved chat channel without leaving a workstation online |
| Team knowledge and operations | Provide a stable front door for approved users, shared procedures, alerts, and carefully scoped tools |
| Scheduled summaries and monitoring | Run recurring jobs from an environment that stays online outside a user's working hours |
| Agency or client workflows | Separate deployments, credentials, and state by client or project instead of mixing trust boundaries |
| Model evaluation | Keep channels and Gateway state stable while comparing providers, models, routing, and API cost |
| Remote-first work | Make an assistant available through communication tools the team already uses across locations and devices |

## Clear Control of the Deployment

| Atlantic.Net provides | You configure and manage |
| --- | --- |
| Cloud Server infrastructure and one-click application image | OpenClaw onboarding, updates, and application health |
| Root-level server access and networking controls | Model-provider credentials and usage charges |
| Cloud storage, snapshots, and backup options | Users, pairing, channels, tools, skills, and schedules |
| 24/7/365 infrastructure support | Gateway access, logs, recovery tests, and data-handling policy |
| A 100% uptime SLA for eligible infrastructure commitments | Availability of OpenClaw, connected channels, and external model providers |

Self-hosting gives you control of the Gateway; it does not remove external data paths. Prompts sent to a model provider are processed under that provider's terms, and connected messaging services handle messages under their own terms. Review each service before using the assistant with sensitive information.

## Secure the Gateway Before You Add Powerful Tools

Treat Gateway access as privileged access. Use explicit pairing or allowlists, keep the Control UI on localhost or a protected private route, and require strong Gateway authentication. Run the service under a dedicated operating-system account, restrict provider keys and channel tokens, and keep OpenClaw and the host updated.

Separate users or workloads that do not share the same trust boundary. A dedicated Gateway or Cloud Server gives each environment its own credentials, tools, writable data, and recovery path. OpenClaw also provides a security audit command; run it after configuration changes and resolve critical findings before expanding access.

## Why Atlantic.Net for OpenClaw Hosting?

Atlantic.Net has operated cloud and hosting infrastructure since 1994. OpenClaw runs on a Cloud Server with predictable infrastructure pricing, full administrative control, multiple global deployment regions, and direct access to the team responsible for the host.

- One-click application deployment from the Atlantic.Net Cloud Portal
- 100% uptime SLA for eligible network, hardware, and power commitments
- 24/7/365 support by phone, email, and chat
- Multiple global regions for placing the Gateway closer to users and connected services
- Root-level control for network policy, monitoring, storage, and backups
- 32 years of hosting experience supporting always-on business infrastructure

## Frequently Asked Questions

### Does OpenClaw Hosting Include an AI Model?

No. The current Atlantic.Net one-click application requires access to a supported external model provider. OpenAI, Anthropic, and OpenRouter are common choices. Provider charges are separate from the Atlantic.Net Cloud Server.

### Is OpenClaw Hosting Fully Managed?

The Cloud Server infrastructure is supported by Atlantic.Net, but OpenClaw is self-managed. You configure the Gateway, model provider, channels, users, tools, updates, monitoring, and backups. Atlantic.Net managed services may be added separately where available and appropriate.

### Is a Self-Hosted OpenClaw Deployment Private?

The Gateway, configuration, and server-side state run in an environment under your account. Messages still pass through the chat services and model providers you connect. Their terms and data-handling practices remain part of your privacy assessment.

### How Much Server Capacity Does OpenClaw Need?

Capacity depends on active users, channels, concurrent sessions, enabled tools, browser automation, stored files, and whether any models run locally. Start with a measurable workload, monitor CPU, memory, storage, and process health, and resize when usage shows the need.

### Can I Change Model Provider Later?

Yes. Provider configuration is separate from the server. You can change supported providers or models while keeping the same Gateway, channels, and server-side state, subject to the configuration and credentials required by the new provider.

### How Is OpenClaw Different From Hermes Agent?

OpenClaw is the stronger starting point for an always-available, messaging-first assistant. Hermes is the stronger starting point for tool-driven, scheduled work that benefits from a learning loop and reusable skills. Their capabilities overlap, and some teams run both with separate credentials and clearly divided responsibilities.

[Compare OpenClaw and Hermes](https://www.atlantic.net/cloud-platform/openclaw-vs-hermes-which-ai-agent-should-you-deploy/)

## Deploy OpenClaw in One Click

Give your AI assistant a persistent Gateway on Atlantic.Net Cloud. Choose OpenClaw in the Cloud Portal, connect your preferred model provider, authorize the channels you trust, and keep the deployment under your control.

[Contact Atlantic.Net](https://www.atlantic.net/about-us/corporate-contact/) [Call Us: 866-618-3282](tel:+18666183282)

## Cloud Availability in Multiple Global Regions

Deploy close to your users from eight international data centers worldwide, with new regions on the way.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Hermes Agent Hosting: Always-On AI for Real Work

> URL: https://www.atlantic.net/cloud-platform/hermes-agent-hosting-always-on-ai-for-real-work/ | Updated: 2026-09-16

Launch Hermes Agent in one click on Atlantic.Net Cloud and give repeatable AI workflows a persistent place to run. Connect your preferred model provider, choose the tools the agent may use, and keep its memory, skills, schedules, and outputs under your control.

- One-Click Deployment
- Persistent Memory & Reusable Skills
- Scheduled & Background Work
- Bring Your Own Model

Built-In Tools: 60+

Messaging Platforms: 20+

Hermes Agent Hosting moves the Hermes agent to an Atlantic.Net Cloud Server, where approved tool use, scheduled jobs, memory, learned procedures, and messaging connections can continue from a stable environment.

Atlantic.Net prepares the server and the Hermes application via one-click deployment. You connect a supported model provider, select the capabilities the workflow needs, and define the users, credentials, files, and services the agent may reach. This removes much of the base installation work while keeping the agent self-hosted and under your account.

## What Is Hermes Agent Hosting?

Hermes Agent is the open-source, self-improving AI agent built by Nous Research. It combines conversation with a broad tool registry, persistent memory, a built-in learning loop, reusable skills, delegation, and scheduled automation.

Hermes Agent Hosting runs that application on a persistent Atlantic.Net Cloud Server. The server provides the agent with a single operating environment for its configuration, memory, skills, tool backends, schedules, messaging gateway, and logs. The work is no longer tied to a local shell session or a user's device.

The current one-click image requires a customer-supplied model provider. Connect OpenAI, Anthropic, OpenRouter, Nous Portal, or another compatible option documented by Hermes, and manage model usage separately from the Cloud Server. The host, the model, and any external services remain visible as distinct parts of the workflow.

## Why Run Hermes on an Always-On Cloud Server?

### Turn Successful Work Into Reusable Skills

Hermes can capture useful procedures as skills and improve them during later use. Persistent storage gives those procedures a stable home, so the agent can reuse them across sessions instead of starting from a blank prompt each time.

### Run Schedules Without a User Device

Built-in cron support lets approved jobs run when a workstation is offline. Recurring research, summaries, file processing, and operational checks can start from the same controlled environment on a defined schedule.

### Give Tools a Deliberate Execution Boundary

Hermes can work with the terminal, files, the web, browsers, code, memory, delegation, and integrations. Hosting those capabilities on a dedicated server makes it easier to isolate projects, restrict access to credentials, monitor resource usage, and choose local, Docker, SSH, or other supported execution backends.

### Keep Infrastructure and Model Choice Separate

Bring your own provider and change models as requirements evolve. The Cloud Server remains the stable home for skills, schedules, tools, and outputs while provider cost and performance can be evaluated independently.

## Launch Hermes in Minutes

Give repeatable AI workflows a persistent place to run on Atlantic.Net Cloud.

## What's Included

### One-Click Hermes Deployment

Select Hermes in the Atlantic.Net Cloud Portal, choose a Cloud Server plan and region, and launch a prepared application image. Begin with a consistent server and Hermes installation instead of building the base Python environment manually.

### Persistent Memory and Learning Loop

Retain relevant context across sessions and create procedural skills from experience. Reviewable skills reduce the need for repeated prompting and provide recurring workflows with a clearer, reusable method.

### 60+ Built-In Tools

Hermes documents more than 60 built-in tools across web search, browser automation, terminal execution, file editing, memory, delegation, scheduled tasks, messaging, code execution, and integrations. Enable toolsets per workflow so each deployment carries only the capabilities it needs.

### Scheduled and Background Work

Create, run, pause, resume, and remove scheduled jobs through Hermes' cron tooling. A persistent server supports ongoing work and background processes without requiring an open laptop session.

### Messaging Across 20+ Platforms

Make approved workflows available through Telegram, Discord, Slack, WhatsApp, Signal, Microsoft Teams, Google Chat, Matrix, and other supported services. Configure bot credentials and user authorization before opening a workflow to a team.

### Bring Your Own Model

Connect a supported model provider and keep the model decision separate from the host. Compare capability, latency, and cost without moving the agent's skills, schedules, or working files.

### Isolated Tool Backends

Choose the execution model that best fits the task's risk. Docker and other sandboxed backends can add filesystem and resource boundaries; SSH can keep an agent from modifying its own installation; local execution suits trusted, carefully scoped work.

### Full Server Administration

Control network access, operating-system policy, storage, monitoring, and backups at the Cloud Server level. Atlantic.Net supports the infrastructure underneath the deployment while you control Hermes, its tools, credentials, and workflows.

## From One Click to a Controlled Workflow

### 1. Choose Hermes in the Cloud Portal

Select the application, server plan, and deployment region.

### 2. Connect a Model Provider

Authenticate a provider supported by Hermes and verify a basic conversation.

### 3. Define One Bounded Job

Enable only the required toolsets, use low-privilege credentials, and assign the workflow dedicated input and output locations.

### 4. Validate Before Scheduling

Review the result, logs, learned skill, error behavior, and recovery path before adding cron, more users, or broader tool access.

## Hermes Agent Hosting Use Cases

| Use case | What a persistent Hermes environment adds |
| --- | --- |
| Recurring research and reporting | Combine approved web, browser, memory, and file tools in a repeatable procedure with a defined output |
| Operations checks | Run scheduled checks, preserve logs, and deliver results through an approved messaging service |
| Development and DevOps workflows | Give terminal, file, code, and delegation tools a dedicated host with explicit credentials and boundaries |
| Content operations | Reuse documented research, transformation, QA, and handoff procedures without recreating every prompt |
| Agency or client work | Separate deployments, service accounts, skills, and data by client or project |
| Internal agent prototypes | Test models, tools, memory, schedules, and container limits under full server control before wider adoption |

## Clear Control of the Deployment

| Atlantic.Net provides | You configure and manage |
| --- | --- |
| Cloud Server infrastructure and one-click application image | Hermes onboarding, updates, and application health |
| Root-level server access and networking controls | Model-provider credentials and usage charges |
| Cloud storage, snapshots, and backup options | Tools, skills, schedules, users, and messaging integrations |
| 24/7/365 infrastructure support | Execution backends, approval policy, logs, and recovery tests |
| A 100% uptime SLA for eligible infrastructure commitments | Availability of Hermes, connected services, and external model providers |

Self-hosting gives you control of the agent environment; it does not make every connected service local. Prompts sent to a model provider, data opened in a browser, and messages delivered through a chat platform remain subject to those services' terms and security controls.

## Secure the Agent Before You Automate

An agent can act with every permission attached to its shell, API keys, browser sessions, integrations, and writable directories. Run Hermes under a dedicated non-root account, limit credentials to the specific job, enable only required toolsets, and keep secrets out of prompts and general-purpose workspaces.

Use command approval and write-safety controls where the workflow allows them. Put higher-risk terminal, browser, and code execution in an isolated backend with CPU, memory, storage, and filesystem limits. Keep the application and host updated, monitor logs, test backups, and review learned skills before scheduling them without supervision.

Separate projects that do not share a trust boundary. A dedicated Cloud Server gives each environment its own users, credentials, tools, skills, outputs, and recovery path.

## Why Atlantic.Net for Hermes Agent Hosting?

Atlantic.Net has operated cloud and hosting infrastructure since 1994. Hermes runs on a Cloud Server with a predictable infrastructure price, full administrative control, multiple global deployment regions, and direct access to the team responsible for the host beneath it.

- One-click application deployment from the Atlantic.Net Cloud Portal
- 100% uptime SLA for eligible network, hardware, and power commitments
- 24/7/365 support by phone, email, and chat
- Multiple global regions for placing the agent closer to users and connected services
- Root-level control for network policy, monitoring, storage, and backups
- 32 years of hosting experience supporting always-on business infrastructure

## Frequently Asked Questions

### Does Hermes Agent Hosting Include an AI Model?

No. The current Atlantic.Net one-click application requires a supported external model provider. Provider charges are separate from the Atlantic.Net Cloud Server.

### Is Hermes Agent Hosting Fully Managed?

The Cloud Server infrastructure is supported by Atlantic.Net, but Hermes is self-managed. You configure the model, tools, users, schedules, updates, monitoring, and backups. Atlantic.Net managed services may be added separately where available and appropriate.

### What Does the Hermes Learning Loop Do?

Hermes can preserve useful information across sessions, create procedural skills from completed work, and improve those skills during use. A learned procedure should still be reviewed before it receives broader permissions or runs unattended.

### Can Hermes Run Scheduled Work?

Yes. Hermes includes cron tooling for scheduled automations and can deliver results through configured services. The Cloud Server, Hermes process, model provider, and any external dependency must all be available for the job to complete.

### How Much Server Capacity Does Hermes Need?

Capacity follows the workflow. A light conversation using an external model has a different footprint from concurrent browser sessions, containers, code execution, large files, or several scheduled jobs. Start with the tools you will actually use, apply resource limits, monitor demand, and resize from evidence.

### How Is Hermes Agent Different From OpenClaw?

Hermes is the stronger starting point for tool-driven, scheduled work that benefits from memory, a learning loop, and reusable skills. OpenClaw is the stronger starting point for an always-available assistant reached through familiar messaging channels. Their capabilities overlap, and some teams run both in separate environments.

[Compare OpenClaw and Hermes](https://www.atlantic.net/cloud-platform/openclaw-vs-hermes-which-ai-agent-should-you-deploy/)

## Launch Hermes in Minutes

Give repeatable AI work a persistent, controlled environment on Atlantic.Net Cloud. Choose Hermes in the Cloud Portal, connect your preferred model provider, define one bounded workflow, and expand only after the result and security boundaries are proven.

[Contact Atlantic.Net](https://www.atlantic.net/about-us/corporate-contact/) [Call Us: 866-618-3282](tel:+18666183282)

## Cloud Availability in Multiple Global Regions

Deploy close to your users from eight international data centers worldwide, with new regions on the way.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# OpenClaw vs. Hermes: Which AI Agent Should You Deploy?

> URL: https://www.atlantic.net/cloud-platform/openclaw-vs-hermes-which-ai-agent-should-you-deploy/ | Published: 2026-08-15 | Author: Hitesh Jethva

Choose OpenClaw when the primary goal is to provide users with an always-available AI assistant via familiar messaging channels. Choose Hermes when the main job is giving an agent tools, schedules, memory, and reusable skills for multi-step work.

Both products can cross that boundary once configured, so the decision follows the workflow you want to make the primary one.

OpenClaw organizes sessions, channels, model access, and tools behind a self-hosted Gateway. Hermes organizes its experience around a learning loop and tool-driven execution. That distinction describes the strongest starting point for each product, not a hard limit on what either one can do.

Atlantic.Net offers OpenClaw Hosting and Hermes Agent Hosting as one-click applications on the On-Demand Cloud platform. Both current images require credentials for an external model provider, and both leave user access, secrets, tools, and workload isolation under your control.

## OpenClaw vs. Hermes at a Glance

OpenClaw and Hermes cover much of the same ground. Both accept messages, call external model providers, retain state, and use tools. The clearest distinction is the job each product organizes first. OpenClaw starts with access to an always-available assistant through messaging channels. Hermes starts with an agent that learns skills and performs multi-step tasks.

| Area | OpenClaw | Hermes |
| --- | --- | --- |
| **Default operating model** | Messaging-first assistant | Tool-driven task agent |
| **Core design** | Self-hosted Gateway, channel routing, Control UI, sessions, and memory | Learning loop, persistent memory and skills, scheduled work, and delegation |
| **Messaging** | Broad channel support with pairing and routing controls | More than 20 messaging platforms |
| **Automation** | Tools, routing, and multi-agent options | More than 60 tools across terminal, file, web, browser, memory, delegation, and cron toolsets |
| **Runtime** | Supported Node.js runtime | Python-based stack managed by the installer |
| **Model providers** | OpenAI, Anthropic, OpenRouter, and other supported providers | OpenAI, Anthropic, OpenRouter, Nous Portal, and compatible endpoints |
| **Strongest starting point** | An assistant reached through familiar chat channels | Bounded jobs that use tools, schedules, and repeatable skills |

Atlantic.Net makes both applications available as one-click deployments on its [On-Demand Cloud platform](https://www.atlantic.net/cloud-platform/). One-click deployment prepares the server and application. You still supply a model provider, configure user access, add channel credentials, store secrets, and set the agent’s security boundaries.

## Which Agent Fits Your Work?

### Choose OpenClaw for a Messaging-First Assistant

OpenClaw is the clearer starting point when chat is the front door. Its [self-hosted Gateway](https://docs.openclaw.ai/) connects messaging channels to an always-available AI assistant and manages routing, sessions, memory, and model access throughout the conversation.

That structure suits teams that want an assistant available from communication tools they already monitor. Pairing limits who reaches the Gateway, the Control UI exposes sessions and configuration, and multi-agent routing can separate assistants or contexts. OpenClaw also uses tools and automation, while keeping the messaging relationship at the center of the deployment.

The practical caveat is that a Gateway represents a trusted-operator boundary. A shared deployment should serve people who can operate within the same trust model. Separate teams with different credentials, data access, or risk limits may need separate Gateways.

[Deploy OpenClaw in One Click](https://cloud.atlantic.net/?page=signup)

### Choose Hermes for Tool-Driven Automation

Hermes is the stronger default when the agent’s main job is to execute a sequence of actions. Its built-in learning loop can retain useful procedures as skills, while persistent memory carries relevant context into later work. Scheduled tasks allow jobs to continue without waiting for a person to open a conversation.

Its registry covers [more than 60 tools](https://hermes-agent.nousresearch.com/docs/user-guide/features/tools/) across terminal, file, web, browser, memory, delegation, and cron toolsets. A scheduled reporting workflow, for example, can read an approved source, run a browser step, write to a dedicated directory, and retain the procedure as a skill. Container and remote execution backends help bound that work.

Hermes also supports messaging across more than 20 platforms. Persistent skills, schedules, and broad access to tools make it the better starting point when execution carries more weight than the conversational front end.

[Launch Hermes in Minutes](https://cloud.atlantic.net/?page=signup)

**Deploy on Atlantic.Net Cloud.** One-click OpenClaw and Hermes Agent Hosting on the On-Demand Cloud platform. [Get Started Now](https://cloud.atlantic.net/?page=signup)

## Compare Setup, Models, and Resource Needs

### Runtime and Initial Setup

OpenClaw uses a supported Node.js runtime. Its standard installation path prepares the application, configures the Gateway, and can register it as a daemon so the assistant remains available after the operator logs out.

Hermes uses a Python-based stack, with its installer handling environment setup. Atlantic.Net’s one-click image setup removes much of the initial installation work for both products. You still enter provider credentials, approve users, connect messaging accounts, and test persistence and recovery.

### Model Provider Support

Both products connect to OpenAI, Anthropic, or OpenRouter. The [Hermes provider guide](https://hermes-agent.nousresearch.com/docs/integrations/providers) also documents Nous Portal and compatible endpoints, while [OpenClaw provides](https://docs.openclaw.ai/concepts/model-providers) provider selection and failover controls.

Atlantic.Net’s current images require a customer-supplied external provider. The agent service and stored state run on your Atlantic.Net server, while that provider processes prompts under its own terms. External inference remains a separate data path to review.

### Resource Planning

Resource needs follow the configured workload. A lightweight messaging Gateway that calls an external model can use far less CPU and memory than an agent running several browser sessions, container backends, concurrent jobs, or local inference.

Atlantic.Net’s G3.4GB Linux plan provides 2 vCPU, 4 GB RAM, an 80 GB SSD, and 5 TB of transfer for $20 per month. It is a measurable test point for a light deployment, not a universal minimum. Browser automation, parallel tools, and retained logs can require more capacity. Local inference may call for [Inference Cloud GPU capacity](https://www.atlantic.net/cloud-platform/inference-cloud/).

Start with the actual channels and tools the agent will use, then measure peak memory, CPU, storage growth, and concurrent sessions. This avoids publishing a universal minimum that fits a basic chat test and fails once automation begins.

## Secure the Agent Before You Give It Work

An AI agent can act with every permission attached to its account, API keys, shell, browser session, and writable directory. Limit those permissions before adding tools or users.

- Apply explicit user allowlists or pairing controls. Keep each OpenClaw Gateway within one trusted-operator boundary. For Hermes, restrict approved users and enable dangerous-command approval and write-safety controls where the workflow permits them.
- Run each service under a dedicated non-root account. Keep model keys, messaging tokens, and service credentials outside prompts and writable workspaces. Give each tool the narrowest credential it can use.
- Isolate shell, browser, and file workloads with the product’s sandbox or container backend, or a separate VM. Keep dependencies updated, restrict inbound access, test backups, and review logs for leaked secrets.

These controls remain customer-owned after one-click deployment.

## Can You Run OpenClaw and Hermes Together?

Yes. Some teams will find that the cleanest design gives each product a separate job. OpenClaw can own conversational access for approved users, while Hermes runs bounded automation with its learning loop, schedules, and tool registry.

Place OpenClaw on one VM with its channel credentials and Hermes on another with a dedicated output directory. Give each service its own non-root account, model key, backups, and firewall rules. If they exchange work, pass only the required fields through a narrow, authenticated interface and keep approval checks around high-impact actions.

## Frequently Asked Questions

### Is Hermes Better Than OpenClaw?

Hermes is the better default for scheduled, tool-driven work that benefits from persistent skills, delegation, and a broad tool registry. OpenClaw is the better default when users need an always-available assistant through messaging channels. Either product can move into the other’s territory after configuration.

### Do OpenClaw and Hermes Support OpenAI and Anthropic?

Yes. Both support OpenAI and Anthropic, along with OpenRouter. Atlantic.Net’s current one-click images require customers to supply credentials for an external model provider.

### Can I Host OpenClaw or Hermes on a VPS?

Yes. Both can run on a cloud VPS with a supported operating environment, enough resources for the chosen tools, and persistent storage. Atlantic.Net offers both as one-click applications on its On-Demand Cloud platform.

### Which Agent Needs More Server Resources?

The configured workload determines resource use. Browser sessions, concurrent jobs, container backends, growing workspaces, and local inference can outweigh the difference between the two applications. Test with the intended channels and tools, then size from measured CPU, memory, and storage demand.

### Are Self-Hosted AI Agents Private?

Self-hosting keeps the agent service, configuration, memory, and stored state under your control. Prompts sent to OpenAI, Anthropic, OpenRouter, or another external provider remain subject to that provider’s terms. Messaging platforms may also process channel traffic before it reaches the server.

### Can I Deploy Both Agents?

Yes. OpenClaw can handle conversational access while Hermes runs bounded automation. Use separate service accounts, credentials, writable directories, and, preferably, separate containers or VMs so that one agent does not inherit the other’s full access.

## Deploy the Agent That Fits the Work

OpenClaw is the stronger first deployment for a messaging-led assistant. Hermes is the stronger choice for first deployment of recurring tool-driven work. Teams that need both operating models can separate them across servers and credentials, then connect only the narrow workflow that has to pass between them.

Atlantic.Net prepares the server and application through its one-click Cloud Portal images. Deploy OpenClaw in one click or launch Hermes in minutes, connect your model provider, and add permissions only after the first bounded workflow has been tested.

[Deploy OpenClaw in One Click](https://cloud.atlantic.net/?page=signup) | [Launch Hermes in Minutes](https://cloud.atlantic.net/?page=signup)


---

# Hyper-Converged Infrastructure Vs. Traditional Three-Tier Infrastructure: A Practical Comparison For 2026

> URL: https://www.atlantic.net/cloud-platform/hyper-converged-vs-traditional-infrastructure/ | Published: 2026-08-21 | Updated: 2026-07-29 | Author: Dr. Assad Abbas

Hyper-converged infrastructure (HCI) is generally suitable for organizations that want unified management and standardized expansion. Traditional three-tier infrastructure may be preferable when compute and storage must scale independently, or applications require specialized hardware.

The difference is mainly architectural. Traditional infrastructure separates compute, storage, and networking into distinct tiers. HCI combines virtualized compute, software-defined storage, and centralized management across clustered servers. Networking varies by platform.

The right choice depends on workload growth, staff, existing investments, and the required level of hardware control.

## Understanding Traditional, Converged, And Hyper-Converged Infrastructure

Traditional, converged, and [hyper-converged infrastructure](https://www.atlantic.net/dedicated-server-hosting/hyperconverged-made-simple-proxmox-ve-9-ceph-and-opnsense-on-atlantic-net-dedicated-servers/) organize computing resources differently. Understanding these designs is necessary before comparing management, scalability, performance, and cost.

## Traditional Three-Tier Infrastructure

[Traditional infrastructure](https://www.atlantic.net/dedicated-server-hosting/managed-private-cloud/) separates compute, storage, and networking into independent layers. Physical servers provide computing resources, while shared storage commonly comes from a Storage Area Network, although other storage architectures may also be used. Network switches connect the servers and storage systems.

Because the tiers remain separate, an organization can add servers without purchasing more storage or expand a storage array without increasing compute capacity. This flexibility is useful when resource requirements grow at different rates.

Hardware and software from multiple vendors may require separate management tools, support contracts, and specialist skills. Traditional infrastructure therefore offers extensive component-level control but may increase management and operational overhead.

## Converged Infrastructure

Converged infrastructure combines compute, storage, and networking into a prevalidated system. Unlike an environment assembled from unrelated products, its components are tested together for compatibility.

Converged and hyper-converged infrastructure are not the same. In a converged system, servers, storage arrays, and networking components remain separate resource tiers. They may retain their own management tools and can usually be expanded independently.

Converged infrastructure can simplify procurement and deployment while preserving dedicated storage and component-level control. It may suit applications that depend on a SAN or require specific server and network configurations.

## Hyper-Converged Infrastructure

HCI combines virtualized compute, software-defined storage, and centralized infrastructure management across clustered servers. It commonly uses standard x86 server designs, although vendors usually require certified or validated hardware and firmware configurations.

HCI platforms generally offer three main advantages:

- Centralized management through a common control platform
- Node-based expansion and resource allocation
- Automated deployment, monitoring, and lifecycle operations

Prevalidated systems can deploy faster than infrastructure assembled from separate components. Actual deployment time still depends on the platform, cluster size, networking, hardware preparation, and site requirements.

Storage is another major architectural difference. Converged infrastructure retains separate storage arrays, while conventional HCI pools storage installed within cluster nodes.

Some modern HCI platforms also support compute-only nodes, storage-only nodes, external storage, or disaggregated configurations. Independent compute and storage expansion is therefore possible on certain platforms, although conventional HCI still commonly scales through nodes that contribute both resources.

Standard Nutanix clusters commonly use at least three nodes, while supported two-node and single-node configurations are available for specific remote and edge deployments.

Major HCI technologies include Nutanix, Microsoft Azure Local, and [VMware vSAN](https://www.atlantic.net/dedicated-server-hosting/what-is-vmware/). VMware vSAN primarily provides the software-defined storage layer and is normally combined with the broader VMware virtualization and management stack.

## HCI Vs. Traditional Infrastructure Comparison

| Comparison area | HCI | Traditional three-tier infrastructure |
| --- | --- | --- |
| Best suited to | Standardized virtual workloads and edge sites | Specialized workloads and environments using independent tiers |
| Cost structure | Nodes, subscriptions, licenses, and support | Separate hardware, software, and maintenance costs |
| Management | Centralized cluster management, although external tools may remain | Separate tools for servers, storage, networking, and backups |
| Scalability | Primarily node-based scale-out; some platforms support independent compute or storage expansion. | Compute, storage, and networking can expand independently |
| Data protection | Native snapshots, replication, and backup integrations | Array features and separate backup platforms |
| Edge suitability | Compact, standardized deployments with centralized management | Specialized or highly customized configurations |
| Resource flexibility | Compute and storage often expand together in conventional designs | Resource tiers expand independently |
| Hardware control | Limited to supported or validated configurations | Greater component-level control |

HCI can reduce management effort, rack space, and separate storage infrastructure in suitable environments. Traditional infrastructure provides greater flexibility when workloads require specialized components or uneven resource growth.

Any operational or financial savings should be confirmed through a workload-specific Total Cost of Ownership analysis rather than assumed from vendor estimates.

## Key Decision Factors

### Scalability

Conventional HCI clusters expand by adding nodes that contribute processors, memory, and storage. Traditional infrastructure allows compute, storage, and networking to expand as separate tiers.

HCI is a strong fit when resources grow at similar rates. Traditional infrastructure may be preferable when one resource must expand independently.

Some current HCI platforms support compute-only nodes, storage-only nodes, external SAN storage, or disaggregated architectures. Buyers should review the capabilities of the specific platform rather than assume that all HCI systems scale identically.

Component upgrades and cluster expansion may also require maintenance, rebalancing, or data movement. Nondisruptive expansion depends on the product and configuration.

### Centralized Management

HCI commonly uses a unified control plane for virtual machines, cluster health, compute and storage resources, policies, and upgrades.

Traditional infrastructure often uses separate tools for servers, storage arrays, networking, virtualization, and backups. This can increase operational costs but also gives administrators more direct control over each layer.

HCI may shorten routine administration, although network infrastructure, backup products, security tools, and application platforms may still require separate management.

### Cost And Total Cost Of Ownership

HCI costs commonly include:

- Cluster nodes
- Platform subscriptions
- Virtualization licenses
- Networking
- Backup services
- Vendor support

Traditional infrastructure requires separate spending on servers, storage arrays, network equipment, software, maintenance, and support.

A complete TCO comparison should also include staffing, training, migration, power, cooling, rack space, future expansion, and contract-exit costs.

HCI may be economical for standardized environments with limited administrative staff. Traditional infrastructure may remain economical when existing equipment is still usable, or resource growth is highly uneven.

### Data Protection And Disaster Recovery

HCI platforms may provide snapshots, native replication, storage policies, and integrations with backup and disaster-recovery tools.

Traditional infrastructure commonly uses array-based replication and separate backup platforms. It may remain preferable when existing protection systems already meet recovery requirements.

Snapshots and replication do not replace independent backups. Both architectures require protected off-site copies, appropriate retention, and regular recovery testing.

### Edge And Remote Sites

HCI is often suitable for edge and remote locations because it combines a compact footprint with centralized management. This can be where local technical staff is limited.

Traditional infrastructure may be more suitable when a site requires specialized hardware, independent storage, or a custom network configuration.

### Interoperability And Vendor Lock-In

HCI uses validated configurations that can simplify deployment but may restrict hardware selection and future migration.

Traditional infrastructure requires more work but may allow broader component choice and multi-vendor interoperability.

Organizations evaluating HCI should review:

- Hardware compatibility rules
- Licensing and renewal terms
- Upgrade rights
- Data portability
- Supported migration paths
- Contract-exit assistance

### Deployment And Migration

HCI can reduce initial work because its hardware and software components are validated together.

Traditional infrastructure may be retained when existing systems continue to meet requirements and replacement would add unnecessary cost.

Migration to HCI should include workload assessment, a representative pilot, staged virtual-machine migration, backup validation, and recovery testing.

## Which Architecture Is Suitable By Scenario?

### When To Consider HCI

HCI commonly suits:

- Standardized virtual machines and private-cloud services
- Compute and storage requirements that grow at similar rates
- Smaller IT teams that benefit from centralized management
- Repeatable edge and remote-site deployments
- Virtualized edge workloads such as local analytics, AI inference, or computer vision

### When To Consider Traditional Or Converged Infrastructure

Traditional or converged infrastructure may be preferable for:

- Independent compute and storage expansion
- Specialized storage, networking, or hardware
- Existing SAN and server investments
- Applications requiring direct component-level control
- Environments built around established backup and replication systems

When neither internally managed architecture is suitable, provider-operated cloud, managed infrastructure, private-cloud services, or hosted bare-metal servers may reduce internal hardware-management requirements.

## Data Center Operations, Compliance, And Security

Both architectures can support security and compliance requirements when properly configured and operated.

HCI platforms may provide centralized access control, encryption, logging, virtual networking, and microsegmentation. Availability depends on the selected product and licensing level.

Traditional infrastructure can provide comparable controls through separate storage, networking, virtualization, and security products.

Compliance depends on configuration, documentation, monitoring, backups, access management, and recovery testing rather than the architecture alone.

HCI can reduce rack space, cabling, and separate storage equipment. Dense nodes and replicated storage may still require substantial power, cooling, and network capacity.

Traditional infrastructure often requires more separate equipment but allows each resource tier to be expanded independently.

## Azure Local Pricing Example And Five-Year TTCO

HCI pricing varies by platform, hardware, configuration, and licensing model.

At publication, Microsoft lists the following standard recurring prices for a conventional Azure Local hyper-converged deployment without external storage:

- Azure Local host service: $10 per physical core per month
- Optional Windows Server subscription: $23.30 per physical core per month

For a deployment with 64 total physical cores operating for five years, the full-rate software charges would be:

| Cost component | Five-year calculation | Estimated cost |
| --- | --- | --- |
| Azure Local host service | $10 × 64 cores × 60 months | $38,400 |
| Windows Server subscription | $23.30 × 64 cores × 60 months | $89,472 |
| Total if both apply |  | $127,872 |

This example shows 60 months at the standard recurring rates for simplicity. A 60-day trial, Azure Hybrid Benefit, or eligible OEM licensing may reduce the actual cost. Benefits and pricing differ for external-storage and disaggregated configurations.

The calculation excludes hardware, networking, backups, services, staffing, power, and cooling.

## Evaluation And Procurement Recommendations

### Profile The Workload

Measure processor and memory use, storage capacity, input/output patterns, network throughput, GPU requirements, and expected growth.

### Review Vendor Proposals

Compare hardware compatibility, expansion options, platform licenses, virtualization costs, backup integrations, renewals, portability, and contract-exit support.

### Run A Representative Pilot

Test production-like workloads and measure application latency, storage throughput, recovery time, resource utilization, management effort, and expansion behavior before making a final decision.

## Frequently Asked Questions

**What Is The Difference Between HCI And Virtualization?**

Virtualization allows multiple virtual machines to share physical hardware. HCI combines virtualized compute with software-defined storage and centralized infrastructure management.

**Is Nutanix Hyper-Converged?**

Yes. Nutanix provides HCI technologies that combine compute, distributed storage, virtualization support, and centralized management across clustered nodes.

**What Is An Example Of Hyper-Converged Infrastructure?**

A cluster of servers that pools compute and local storage through a common software platform is an example of HCI. Nutanix, Azure Local, and VMware environments using vSAN are commercial examples.

**What Are The Four Types Of IT Infrastructure?**

Four commonly discussed models are traditional, converged, hyper-converged, and cloud-based infrastructure. This is a useful comparison rather than a universal or exhaustive classification.

**Does HCI Replace A SAN?**

Conventional HCI can replace an external SAN by pooling storage within cluster nodes. A SAN may still be used for specialized workloads or by HCI platforms that support external and disaggregated storage.

## Final Recommendation

HCI suits standardized virtualized workloads that benefit from centralized management and node-based expansion. Traditional or converged infrastructure may be preferable when applications require specialized hardware, independent scaling, or extensive component-level control.

The decision should consider workload requirements, existing investments, staff, recovery objectives, migration effort, and five-year cost. A representative pilot can then confirm whether the selected architecture meets performance, operational, and financial requirements.


---

# On-Premise vs Colocation vs Cloud — Which Is Right for 2026?

> URL: https://www.atlantic.net/cloud-platform/on-premises-vs-colocation-vs-cloud-2026/ | Published: 2026-08-21 | Updated: 2026-07-29 | Author: Dr. Assad Abbas

For a typical small or medium-sized business evaluating on-premises vs colocation vs cloud in 2026, Cloud is often a strong starting point for organizations with variable demand or limited appetite for upfront infrastructure investment, but it is not universally the least expensive or most appropriate model. On-premises is the right fit when the priority is maximum hardware control, and the business can justify the capital expense and operational responsibility. At the same time, colocation sits in the middle by letting you own the hardware but place it in a third-party facility instead of running a private data center yourself.

That choice directly affects cost, scalability, security, performance, and day-to-day IT ownership, so the right model depends on how much control you need, what compliance or technical constraints you have, and how elastic your workloads are. This comparison is written for SMBs making that decision and breaks down the definitions and strengths of each model, then compares them on cost, control, security, scalability, performance, operational responsibility, and when a hybrid architecture makes more sense than choosing a single approach.

## What Is On-Premises Infrastructure?

On-premises infrastructure refers to IT systems that an organization owns and operates within its own building or private data center. These systems commonly include servers, storage, networking gear, and software.

The main strengths of on-premises infrastructure include the following.

- On-premises infrastructure provides full hardware control so that internal teams can select and configure equipment according to their technical requirements.
- It provides direct physical access, enabling authorized staff to inspect, repair, replace, or reconfigure equipment when required.
- It also strengthens internal governance by allowing the organization to control the physical location of its data and access to its infrastructure.

Maintaining this level of control requires upfront investment in hardware, software licenses, power, cooling, backup systems, and physical security, especially for teams running on-premises software in-house. In addition, the organization must employ skilled staff to operate and maintain both the equipment and the facility, which is one reason this model remains common for sensitive data and strict compliance requirements where companies want direct oversight of systems and location.

## What Are Colocation Services?

Colocation is a service in which a business places its own servers and networking equipment in a third-party data center run by a colocation provider. The customer keeps its own hardware, while the provider manages rack space, power, cooling, physical security, and internet connectivity.

The main strengths of colocation include the following.

- Businesses gain access to redundant power, cooling, fire protection, environmental monitoring, and controlled physical access.
- Customers retain ownership of the hardware and can select their server, storage, operating system, and network configurations, including dedicated hardware when they need custom setups.
- Carrier-neutral facilities may offer multiple network carriers, cross-connects, private VLANs, and direct cloud connections.

Colocation reduces the burden of operating a private data center. The customer is generally responsible for purchasing, configuring, patching, and replacing the servers. Day-to-day support and break/fix usually remain in-house unless extra services are purchased. Some providers also offer remote hands services for physical tasks.

## What Are Cloud Hosting And Cloud Computing?

Cloud hosting and cloud computing provide rented computing resources through infrastructure operated by a third-party service provider. Unlike on-premises and colocation models, the customer does not purchase or own the physical hardware.

The main strengths of cloud services include the following.

- Virtual servers, storage, and managed services can often be provisioned within minutes.
- Computing capacity can increase or decrease according to application demand.
- Customers pay for the resources they use on an as-needed basis instead of investing in hardware or a private data center.

Public cloud services use shared infrastructure with logical separation between customers, typically delivered by cloud providers. A private cloud provides a dedicated environment for one organization, while a hybrid cloud connects private infrastructure with public cloud environments.

Cloud services provide faster deployment and greater elasticity than on-premises infrastructure or colocation. Customers have less control over the physical hardware and must monitor usage to avoid unexpected costs.

## On-Premises Vs Colocation Vs Cloud Comparison

The following table summarizes the key differences among the three deployment models.

| **Area** | **On-Premises** | **Colocation** | **Cloud** |
| --- | --- | --- | --- |
| **Best for** | Maximum control and strict internal policies | Stable workloads on customer-owned hardware | Variable demand and rapid deployment |
| **Cost model** | High CapEx and ongoing operating costs | Hardware CapEx and recurring facility fees | Mainly OpEx, usage-based fees, and lower upfront capital expenses |
| **Hardware ownership** | Customer | Customer | Provider |
| **Physical access** | Direct | Scheduled access or remote hands | No access to physical hardware |
| **Hardware control** | Full | Full | Limited |
| **Scalability** | Slow | Moderate | Fast |
| **Performance** | Highly customizable | Predictable and customizable | Depends on the selected resources and service tier |
| **Internal staffing** | High | Moderate | Lower |
| **Main trade-off** | Greater control with higher overhead | Hardware ownership with provider dependence | Greater elasticity with less hardware control |

The comparison shows that each model distributes costs, IT infrastructure responsibilities, and management differently. On-premises infrastructure provides the highest level of ownership and control, but the organization must manage both the equipment and facility. Colocation retains hardware ownership while transferring power, cooling, physical security, and connectivity to a data center provider. In contrast, cloud replaces hardware investment with usage-based charges and provider-managed physical infrastructure. The financial effect of these differences becomes clearer when costs are compared over three to five years.

## Cost Structure, CapEx Vs OpEx, And Cost-Effective Choices

The cost structure of each model affects both initial spending and long-term expenses, and any comparison should match the model to actual business needs, not just monthly price. On-premises infrastructure and colocation rely mainly on Capital Expenditure (CapEx) because the business purchases its hardware. In contrast, cloud hosting mainly relies on Operating Expenditure (OpEx) because resources are rented. A three-to-five-year comparison should also include licensing, staffing, backups, connectivity, security, maintenance, and migration. The following sections examine the main costs associated with each model.

### On-Premises Costs

Among the three models, on-premises infrastructure normally requires the highest initial CapEx. For example, if four servers cost $5,000 each, the initial server expense would be $20,000. Storage, networking equipment, backup systems, and software licenses would increase this amount. In addition, power, cooling, maintenance, and staff create continuing OpEx.

Despite the higher initial cost, on-premises infrastructure may be cost-effective when the organization already has a suitable server room in its own data centers and technical team. Equipment depreciation, replacement parts, energy use, and staff time should still be included in the total cost of ownership. It can also make sense for legacy systems that are difficult to move or refactor.

### Colocation Costs

Colocation requires a similar hardware investment, but the provider manages the data center facility. Therefore, the customer avoids the cost of operating private power, cooling, fire protection, and physical security systems while retaining full control over customer-owned infrastructure.

The recurring cost of colocation depends mainly on rack space, location, power, and connectivity. Published estimates for[1U and 2U colocation](https://www.quotecolo.com/1u-colocation/) start near $50 per month in lower-cost markets and commonly range from $95 to $240 in major U.S. markets. For larger deployments, Colocation America currently lists a[10U quarter rack at $399 per month and a 42U full rack at $999 per month](https://www.colocationamerica.com/colocation/quarter-rack-colocation/).

Based on the advertised quarter-rack rate of $399 per month, the base colocation fee would total $14,364 over three years and $23,940 over five years. Hardware, additional power, bandwidth, cross-connects, setup fees, and advanced remote hands services may increase the total cost, so colocation is strongest for predictable workloads that run steadily over time.

### Cloud Costs

Unlike the other two models, cloud hosting requires little initial CapEx because the business does not purchase servers or prepare a facility. It can also reduce upfront capital expenses by replacing hardware purchases with rented services. Cloud is often cost-effective for development systems, pilot projects, seasonal applications, and workloads with uncertain demand.

Cloud costs depend on the selected processors, memory, storage, region, operating system, and data transfer, and pricing can also vary across different cloud platforms and regions. Therefore, a reliable price comparison requires the same configuration and workload for all three models. Continuously running large instances may become expensive, while storage, managed services, public IP addresses, backups, and data egress can further increase monthly OpEx.

### Which Model Is Most Cost-Effective?

For a typical small or medium-sized business, cloud is usually the strongest fit when workload patterns are variable, and the priority is flexibility to support broader business goals. Colocation may provide better long-term value for stable systems with high resource use, especially when utilization is steady, and the setup supports long-term business needs. On-premises infrastructure may also be economical when the required facility and technical staff are already available. Therefore, the main trade-off is between lower initial spending and greater control over long-term infrastructure costs.

## Control, Security, And Compliance

Cost is only one aspect of the infrastructure decision. Organizations must also consider the level of control, data security, and security responsibility associated with each model. On-premises infrastructure provides the greatest direct control because the organization owns both the hardware and facility. Colocation offers similar hardware control, but physical access is subject to the provider’s procedures. In contrast, cloud customers control virtual resources while the provider manages the physical platform. Therefore, on-premises infrastructure is the winner for direct control.

The level of control also determines the division of security responsibilities. On-premises teams protect the entire environment, while colocation providers secure the facility and customers manage their systems and data. Similarly, cloud follows a shared responsibility model between the provider and customer.

These responsibilities become particularly important for regulated workloads. HIPAA-regulated and PCI DSS workloads, especially those involving sensitive data, can operate in all three models when the required safeguards are implemented. A provider handling[electronic Protected Health Information (ePHI)](https://www.atlantic.net/hipaa-compliant-hosting/what-is-protected-health-information/) generally requires a HIPAA Business Associate Agreement (BAA). Customers must still manage encryption, access controls, logging, backups, and network segmentation. Qualified hosted providers and cloud solutions may reduce the facility-level burden, but compliance depends on the complete configuration and division of responsibilities.

## Scalability, Performance, And Operations

Beyond security and compliance, businesses must consider growth, performance, and daily management. Cloud resources can scale quickly because virtual servers and storage can be provisioned within a short time, and cloud is strongest when teams need to scale across different cloud environments. Therefore, cloud is suitable for seasonal applications and workloads with changing demand. In contrast, on-premises and colocation environments take longer to expand because new hardware must be purchased and installed. Cloud is therefore the most suitable option for scalability, although changing usage may lead to less predictable costs.

While cloud offers faster scaling, on-premises and colocation provide greater control over processors, storage, and networking. In addition, colocation may reduce latency through multiple carriers, private connections, and cloud connectivity for low-latency access to external services. Greater control brings additional operational responsibilities. On-premises teams manage both the hardware and facility, while colocation customers manage the hardware and leave facility operations to the provider. Cloud reduces the operational burden further because the provider manages the underlying physical infrastructure, and the performance and operational trade-offs also depend on what level of provider support the business wants.

## Combining Colocation, Bare Metal, And Cloud

Businesses do not always have to select only one model, and this mix is one of several hybrid cloud solutions. Many enterprises use it to keep steady core workloads on colocation or hosted bare-metal infrastructure while using cloud capacity for elastic demand. Cloud resources can then handle testing, analytics, Web applications, or temporary traffic spikes.

These environments can connect through VPNs, private VLANs, interconnection services, cloud interconnects, or dedicated links to cloud providers and cloud platforms to maintain consistent operations across hybrid environments. Private connectivity may improve network consistency and reduce cloud data transfer costs. Hosted bare metal is also suitable when a business wants single-tenant hardware without purchasing servers or renting rack space. For example[,](https://www.atlantic.net/dedicated-server-hosting/bare-metal-servers/) Atlantic.Net bare-metal servers can integrate with cloud services when both stable performance and flexible capacity are required.

## Which Option Should You Choose?

- The right model depends on workload, control, and broader business needs.
- Choose on-premises infrastructure when maximum physical control or specialized equipment is required, and the organization has a suitable facility and technical team.
- Choose colocation when the business wants to own its hardware without managing power, cooling, physical security, and carrier connectivity.
- Choose cloud when demand changes frequently, rapid deployment is important, or the internal infrastructure team is small.
- Choose a hybrid model when stable and variable workloads have different performance and scalability requirements across on-premises systems and cloud solutions.
- Consider migration effort and lock-in before making the final decision. Colocation may require hardware transport and network changes, while cloud migration may require data transfer and application changes.
- Complete the migration in stages and include performance testing, security checks, and a rollback plan.
- Prepare a three-year TCO model and run a limited pilot to confirm cost, performance, security, and operational requirements.

## Frequently Asked Questions

**What Is The Difference Between Colocation And Cloud?**

Colocation customers own and control their hardware, while cloud customers rent resources from a service provider. Colocation offers greater hardware control, whereas cloud provides faster scaling and lower initial costs.

**Is On-Premises Infrastructure Cheaper Than Cloud?**

On-premises infrastructure may cost less over time when equipment is heavily utilized, and the required facilities and staff are already available. Cloud is often less expensive for temporary or variable workloads.

**What Is The Difference Between Bare Metal And Colocation?**

Bare metal is a physical server dedicated to one customer. Colocation is a service in which customer-owned equipment is placed in a third-party data center.

**Can A Hybrid Setup Combine All Three Models?**

Yes. A business can use on-premises infrastructure for internal systems, colocation for customer-owned production hardware, and cloud resources for variable demand, backups, or disaster recovery. This is common when organizations need to keep some workloads on-site while using public cloud in connected hybrid environments.

**What Are The Typical SLA Differences?**

Cloud and colocation providers commonly offer uptime SLAs that vary by the selected service and architecture. On-premises availability depends on the organization’s own redundancy, maintenance practices, and internal support. At the same time, buyers should compare covered services, exclusions, service credits, customer responsibilities, and any provider connectivity or hardware support included.


---

# Cloud Vs. Traditional Data Center: Which Is Right For You In 2026?

> URL: https://www.atlantic.net/cloud-platform/cloud-vs-traditional-data-center/ | Published: 2026-08-21 | Updated: 2026-07-29 | Author: Dr. Assad Abbas

Cloud computing is generally well suited to organizations that need rapid deployment and capacity that can change with workload demand. A traditional data center may be more appropriate when direct control over hardware, facilities, and data location is a priority.

The decision is not simply a choice between flexibility and ownership. Cost, staffing, security, compliance, performance, application design, migration effort, and existing infrastructure also affect which model is most suitable.

Both approaches depend on physical data center facilities, but they assign ownership and management responsibilities differently. In a traditional data center, the organization owns and operates the infrastructure. In a conventional public-cloud model, a service provider owns and manages the underlying physical platform while customers rent computing services.

Understanding how these responsibilities differ is essential before comparing costs or planning a migration.

## Understanding Traditional And Cloud Data Centers

The ownership model determines who manages the physical infrastructure and day-to-day data center operations. Modern data centers may use similar servers, storage systems, network equipment, and security technologies, but responsibility for those systems varies considerably.

## Traditional Data Center Ownership And Operations

A traditional data center is owned and operated by the organization using it. It may be located at a company office, campus, or privately controlled facility.

Under this model, the organization generally manages three main areas.

### Hardware Selection And Configuration

Internal teams select and configure processors, servers, storage systems, network equipment, and security devices according to workload requirements.

This level of control is used when applications require specialized hardware, direct physical access, custom network configurations, or close coordination with local equipment.

### Infrastructure Lifecycle Management

The organization manages procurement, installation, monitoring, maintenance, repairs, upgrades, warranties, and equipment replacement.

It is also responsible for supporting facility systems such as power distribution, backup power, cooling, fire protection, physical access controls, and environmental monitoring.

### Capacity Planning And Expansion

Infrastructure teams must estimate future demand because purchasing, delivering, and installing new equipment takes time. Facility space, electrical capacity, cooling systems, and network connectivity may also limit expansion.

Organizations therefore often maintain some unused capacity to support future growth, equipment failure, or temporary increases in demand.

## Public-Cloud Services And Responsibilities

According to the National Institute of Standards and Technology, cloud computing provides on-demand access to a shared pool of configurable computing resources that can be rapidly provisioned and released.

In a conventional public-cloud model, the provider owns and operates the underlying data centers and physical hardware. Customers access computing resources as services rather than purchasing the physical equipment.

Public-cloud delivery generally includes three important characteristics.

### Access To Rented Services

Customers can use virtual machines, cloud storage, databases, networking, analytics, and other services without owning the underlying servers.

These services are usually accessed through management portals, application programming interfaces, command-line tools, or automated deployment systems.

### On-Demand Resource Provisioning

Customers can create, resize, or remove resources with limited provider interaction.

This enables organizations to respond to workload changes without waiting for new physical equipment to be purchased and installed. Provisioning may take only minutes for common services, although quotas, regional availability, specialized hardware, and configuration requirements can cause delays.

### Shared Management Responsibilities

The provider manages the facility and physical platform, but the customer still has important responsibilities.

The exact division depends on the service model:

- With Infrastructure as a Service, the customer normally manages operating systems, applications, data, identities, permissions, and many security configurations.
- With Platform as a Service, the provider manages more of the operating system and application platform.
- With Software as a Service, the provider manages most of the technical stack. At the same time, the customer remains responsible for areas such as account access, data governance, user permissions, and appropriate use.

Moving to the cloud can reduce facility and hardware-management responsibilities, but it does not eliminate the need for operational oversight, security management, cost control, and data governance.

Provider-managed options may also include bare-metal servers for workloads that require dedicated physical resources without customer-owned facilities.

## Four Common Data Center Categories

Data centers can also be grouped by purpose, scale, location, and operating model. Four common categories are enterprise, colocation, hyperscale, and edge data centers.

These categories are not mutually exclusive. A facility may fit more than one category, and other classifications are also used within the industry.

### Enterprise Data Centers

An enterprise data center serves one organization and may be located at an office, campus, or private site.

Businesses, government agencies, universities, and other institutions may use enterprise facilities for internal systems, business-critical applications, research computing, or specialized workloads.

### Colocation Data Centers

A colocation data center houses customer-owned equipment while providing rack space, power, cooling, physical security, environmental controls, and network connectivity.

The customer generally manages its servers, storage, operating systems, and applications. The provider operates the facility. Additional services, such as monitoring, managed networking, or remote technical support, may be available separately.

Colocation differs from public cloud because the customer normally owns the installed equipment.

### Hyperscale Data Centers

A hyperscale data center is a large facility designed for standardized, repeatable expansion.

Major cloud providers, internet companies, and large technology organizations use automation, high-density infrastructure, and modular designs to operate at scale.

Some hyperscale facilities are owned by the organizations using them, while others are leased from specialized data center operators.

### Edge Data Centers

An edge data center places computing resources closer to users, devices, or data sources.

Reducing the physical and network distance between systems can lower latency and reduce the amount of data that must travel to a distant centralized facility.

Edge infrastructure may support industrial systems, telecommunications, content delivery, gaming, autonomous systems, video processing, and other latency-sensitive applications.

## Traditional And Public-Cloud Data Center Comparison

The differences between traditional data centers and public-cloud environments affect capacity, cost, staffing, security, performance, and availability.

| Comparison area | Traditional data center | Public-cloud environment |
| --- | --- | --- |
| Ownership | The organization owns the infrastructure | The provider owns the underlying physical infrastructure |
| Capacity expansion | New equipment must be purchased and installed | Resources are provisioned from available provider capacity |
| Cost structure | Capital investment plus continuing facility and operating expenses | Usage-based charges, service fees, or committed-spend agreements |
| Hardware control | Direct access and extensive configuration control | Limited or no access to physical hardware |
| Deployment time | Depends on procurement, installation, and testing | Common resources may be available within minutes |
| Scalability | Limited by installed equipment and facility capacity | Elastic within service, account, regional, and provider limits |
| Staffing | Internal teams manage the facility and equipment | The provider manages the facility and physical platform |
| Security | The organization manages the full environment | Responsibilities are divided between provider and customer |
| Performance | Infrastructure can be designed for specific workloads | Performance depends on the selected service, configuration, and architecture |
| Availability | Depends on internal architecture and operations | Depends on service design, region, architecture, and applicable SLA |

The central trade-off is between direct infrastructure control and access to elastic, provider-managed capacity.

That trade-off also affects capital requirements, operating costs, technical staffing, and the speed at which new systems can be deployed.

## Cost, Operations, And Security

A fair comparison should examine total costs over three to five years rather than comparing hardware purchase prices with a single monthly cloud bill.

### Traditional Data Center Costs

Traditional infrastructure commonly requires Capital Expenditure for servers, storage, networking equipment, backup systems, facility improvements, power equipment, and cooling systems.

Operating Expenditure may include:

- Technical staff
- Software licensing
- Electricity
- Cooling
- Internet and private connectivity
- Security systems
- Hardware maintenance
- Equipment replacement
- Backup and disaster-recovery systems

An existing data center may be economical for stable, highly utilized workloads when the organization already has suitable facilities, staff, and equipment.

Unused capacity, maintenance, depreciation, lifecycle replacement, and facility costs should all be included in the total cost of ownership.

### Public-Cloud Service Costs

Public-cloud expenses depend on the services used and how they are configured.

Common cost components include:

- Computing resources
- Cloud storage
- Databases
- Managed services
- Backups and snapshots
- Monitoring
- Public IP addresses
- Network connections
- Data transfer
- Support plans
- Software licenses

Cloud services may be cost-effective for temporary, seasonal, or uncertain workloads because resources can be reduced or removed when they are no longer needed.

Costs can become difficult to predict when resources remain active unnecessarily, data-transfer volumes are high, or teams use managed services without appropriate financial controls.

Providers may offer on-demand pricing, reservations, savings plans, or other committed-use arrangements. These options can reduce rates for predictable workloads but may also create financial commitments.

### Operational Responsibilities

Moving to public cloud reduces the need to operate a physical facility, but it does not eliminate IT operations.

Organizations may still need staff with in:

- Cloud architecture
- Identity and access management
- Security configuration
- Application operations
- Monitoring and incident response
- Data governance
- Backup and recovery
- Cost
- Vendor management

Staffing needs depend heavily on the services selected. Managed platform and software services generally transfer more responsibility to the provider than basic infrastructure services.

### Security Responsibilities

Data center security includes both physical protection and digital safeguards.

In a traditional data center, the organization is responsible for securing the facility, hardware, networks, operating systems, applications, identities, and data.

In public cloud, the provider and customer divide responsibility. The provider generally protects the facility and underlying physical platform, while the customer remains responsible for the areas assigned to it under the selected service model.

Customers should clearly document responsibility for:

- Identity and access controls
- Security configuration
- Data classification
- Encryption
- Logging
- Monitoring
- Backups
- Vulnerability management
- Incident response
- Regulatory compliance

Using a compliant cloud provider does not automatically make the customer’s workload compliant. The complete system must be configured and operated in accordance with the applicable requirements.

## HIPAA And Cloud Services

When a cloud service provider creates, receives, maintains, or transmits electronic Protected Health Information on behalf of a HIPAA-regulated entity, the provider is generally considered a business associate.

In those circumstances, a HIPAA-compliant HIPAA Business Associate Agreement (BAA) is generally required.

The customer must also apply reasonable and appropriate safeguards to protect the information. These may include access controls, audit logging, encryption, backups, risk assessments, and incident-response procedures.

Transport Layer Security is a common method for encrypting information in transit. HIPAA is technology-neutral and does not prescribe one specific encryption protocol. Organizations must assess their risks, select appropriate safeguards, and document their decisions.

## Data Center Location And Latency

Data center location can affect application performance because shorter distances to users, devices, or data sources may reduce network latency.

Distance is not the only factor. Response times may also be affected by:

- Internet routing
- Network congestion
- Private connectivity
- Peering arrangements
- Application design
- Database architecture
- Security inspection
- Protocol configuration
- Processing time

Organizations should test workloads from expected user locations and measure latency, throughput, reliability, and variation in response times.

For applications that require local processing, edge data centers or edge-computing systems may further reduce latency by placing resources near users, equipment, or connected devices.

## AI Data Centers And Infrastructure Requirements

AI infrastructure supports workloads such as machine learning, generative AI, natural-language processing, computer vision, and large-scale data analysis.

Many AI workloads use dense servers equipped with GPUs or other accelerators. Training large models can require processing capacity, storage throughput, network bandwidth, electricity, and cooling.

Inference workloads can also be demanding, particularly when models serve large numbers of users or require low response times.

As power density increases, organizations may need to consider:

- Electrical capacity
- Backup power
- Cooling technology
- Rack density
- Network bandwidth
- Storage performance
- Hardware availability
- Equipment lead times
- Redundancy requirements

Not every AI workload requires a specialized AI data center. Smaller models, lightweight inference, and limited experiments may run on conventional servers, cloud services, workstations, or edge devices.

An organization may operate AI infrastructure in its own facility when workloads are stable, utilization is high, and sufficient power, cooling, staff, and accelerator capacity are already available.

Public-cloud AI infrastructure may be more suitable for experiments, short-term training, uncertain demand, or projects that require access to several accelerator types.

The cost comparison should include:

- GPU or accelerator availability
- Reservation and commitment terms
- Expected utilization
- Storage
- Data transfer
- Network performance
- Software licensing
- Idle capacity
- Support requirements

## Which Option Is Most Suitable For Your Organization?

The most appropriate model depends on the organization’s existing resources, applications, risk tolerance, and workload requirements.

## When To Choose A Traditional Data Center

A traditional data center may be suitable when the organization already has an appropriate facility and experienced technical staff.

Owned infrastructure may also be appropriate when workloads require:

- Specialized hardware
- Direct physical access
- Custom network configurations
- Strict control over data location
- With local industrial equipment
- Stable, long-term utilization
- Predictable internal network performance

For example, a manufacturing company may operate production systems locally when they connect directly to factory equipment and require reliable internal communications even when external connectivity is interrupted.

## When Public Cloud Is More Suitable

Public cloud may be suitable when rapid deployment and elastic capacity are priorities.

It can be particularly useful for:

- Temporary projects
- Seasonal demand
- Development and testing
- New applications
- Uncertain growth
- Geographic expansion
- Managed databases and platform services
- Organizations with limited facility-management capacity

For example, an online retailer may increase public-cloud capacity during a busy shopping period and reduce it after traffic returns to normal.

Cloud is not automatically less expensive, but its flexibility can reduce the need to purchase physical capacity before demand is fully understood.

## When To Consider A Hybrid Environment

A hybrid environment combines private infrastructure with public-cloud services.

For example, stable systems may operate in a private facility while public-cloud resources support development, analytics, backups, disaster recovery, or temporary demand.

A university might operate administrative systems in a private facility while using public-cloud resources for short-term research projects and data analysis.

The term hybrid cloud is more specific. Under the NIST definition, it combines two or more distinct cloud infrastructures that remain separate but are connected by technology that enables data or application portability.

An environment that combines a conventional data center with public cloud may therefore be more accurately described as a hybrid IT environment unless the private side also operates as a cloud.

Regardless of terminology, it requires careful planning for:

- Identity management
- Network connectivity
- Data movement
- Monitoring
- Security controls
- Backup and recovery
- Application dependencies
- Cost allocation

## Making The Final Decision

The final decision should be based on evidence rather than general assumptions about cloud or owned infrastructure.

Organizations should:

1. Create a three-to-five-year total cost comparison.
2. Identify current and expected workload utilization.
3. Test application performance from relevant user locations.
4. Document provider and customer security responsibilities.
5. Assess internal staffing and facility capacity.
6. Evaluate migration effort and application dependencies.
7. Review regulatory and data-location requirements.
8. Consider vendor lock-in and exit costs.
9. Run a limited pilot before making a large commitment.
10. Define success criteria for cost, performance, security, and operations.

A pilot can reveal issues that are difficult to identify through estimates alone, including latency, staffing demands, unexpected service charges, application compatibility, and operational issues.

## Frequently Asked Questions

**What Is A Traditional Data Center?**

A traditional data center is owned and operated by the organization using it. The organization manages the facility, hardware, power, cooling, physical security, networking, maintenance, and equipment lifecycle.

**What Is The Difference Between A Hyperscale And Traditional Data Center?**

Hyperscale describes a large, standardized data center designed for extensive and repeatable expansion.

A traditional data center is generally owned and operated by one organization. It may be small or large, but it is usually designed around that organization’s specific requirements rather than hyperscale expansion.

**What Are The Main Cloud Service Models?**

NIST defines three established cloud service models:

- Infrastructure as a Service
- Platform as a Service
- Software as a Service

Serverless computing, including Function as a Service, is also a widely used modern cloud model. It is not a fourth NIST service model and is often treated as a form of, or closely related to, Platform as a Service.

**What Is The Difference Between Public, Private, And Hybrid Cloud?**

A public cloud is made available for use by the general public and is normally operated by a cloud service provider.

A private cloud is provisioned for the exclusive use of one organization. It may be owned and operated by the organization, a third party, or both, and may exist on or off premises.

A hybrid cloud combines two or more distinct cloud infrastructures that remain separate but are connected by technology that enables data or application portability.

**Is Cloud Cheaper Than A Traditional Data Center?**

Cloud may cost less for temporary, seasonal, or variable workloads because resources can be adjusted as demand changes.

A traditional data center may be economical for stable, highly utilized workloads when the organization already has suitable facilities, staff, and infrastructure.

Actual costs depend on factors such as staffing, electricity, cooling, licensing, utilization, migration, data transfer, support, equipment replacement, and service configuration. A workload-specific total cost comparison is necessary before concluding.


---

# Discrete GPU: Integrated Graphics vs. Discrete Graphics

> URL: https://www.atlantic.net/gpu-server-hosting/integrated-vs-discrete-graphics/ | Published: 2026-08-28 | Author: Dr. Tehseen Zia

When you buy a laptop, build a desktop, or choose hardware for demanding tasks, you will come across two types of graphics processors: integrated graphics and discrete graphics. The main difference is that integrated graphics are built into the processor or processor package and usually share system memory (RAM) with the CPU. A discrete GPU is a separate graphics processor, and discrete graphics cards have their own dedicated memory, known as VRAM, plus dedicated or system-provided cooling. This difference in memory design is one reason why discrete GPUs can provide much higher graphics and computing performance. In contrast, integrated graphics are typically more power-efficient and affordable. The best choice depends on your computer’s intended use. For most everyday tasks like productivity, streaming, web browsing, word processing, casual gaming, and light content creation, integrated graphics may be sufficient. For gaming, professional video production, 3D rendering, scientific computing, and AI tasks, a discrete GPU often benefits, including high-end options like GeForce RTX.

## What Are Integrated Graphics?

An integrated GPU, sometimes referred to as an iGPU, is a graphics processing unit built into the processor or processor package. It normally does not have its own dedicated memory; instead, integrated graphics use a portion of the computer’s system RAM for graphics processing. Because the graphics processor is integrated into the processor platform, a separate graphics card is not necessary. This setup reduces the physical size of the system, uses less power, and generally generates less heat. These features make integrated graphics commonly found in laptops, compact PCs, and other systems where battery life, size, and energy are important. Common examples of iGPUs include Intel’s Iris Xe and UHD lines, AMD’s Radeon graphics within Ryzen chips, and the GPUs in Apple’s M-series chips, which use unified memory.

## What Is A Discrete GPU?

A discrete GPU, also known as a dedicated GPU, is a separate graphics processor rather than part of the CPU, with its own VRAM and dedicated or shared cooling. Consumer discrete graphics cards commonly have about 4GB to 32GB of VRAM, while professional and data-center models can have much more. In a desktop PC, it is typically installed as a graphics card in a PCIe slot. In a laptop, the GPU may be mounted on the motherboard as a separate chip rather than as a removable card. However, a discrete GPU still requires extra space, power delivery, and cooling capacity.

In a discrete GPU, VRAM works closely with the GPU to provide fast access to data needed for rendering images, processing video, running 3D applications, or performing parallel computations. The VRAM on a discrete card generally provides higher graphics bandwidth than standard system RAM and is not normally shared with CPU tasks. However, some systems can also allocate shared system memory to a discrete GPU.

Discrete GPUs usually consume more power and generate significantly more heat than integrated graphics. They also increase the cost and size of a system. In return, they often deliver much higher performance for demanding workloads.

## Integrated Vs. Discrete Graphics: Key Differences

| Feature | Integrated Graphics | Discrete Graphics |
| --- | --- | --- |
| Location | Integrated into the processor or package | Separate GPU |
| Memory | Shares system RAM | Uses dedicated VRAM |
| Performance | Suitable for everyday and lighter workloads | Better for demanding graphics and compute |
| Power use | Generally lower | Generally higher |
| Heat | Generally lower | Generally higher |
| Cost | Usually lower system cost | Adds to system cost |
| Physical space | Compact | Requires extra hardware or board space |
| Upgradeability | Usually cannot be upgraded separately | Desktop cards can often be replaced |
| Best suited for | Productivity, media, most everyday tasks, light gaming | Gaming, rendering, AI, content creation, demanding compute |

## When Integrated Graphics Are Enough

If your computer is mainly used for Microsoft Office, web applications, programming, online meetings, video streaming, word processing, and general productivity, spending more on a discrete GPU may provide little practical benefit.

This is also true for users who prioritize portability and battery life. A laptop with integrated graphics is often lighter, quieter, uses less power, and is more energy-efficient than one with a powerful discrete GPU.

Modern integrated GPUs can also handle some light content creation and casual gaming. Basic photo editing and straightforward video editing may run well, and some games are playable at reduced settings, particularly on newer systems. The experience depends on the application, resolution, codecs, and project.

The key question is not whether a discrete GPU is “better.” It is whether the added performance justifies the extra cost, power consumption, and heat output.

## When Do You Need A Discrete GPU?

A discrete GPU becomes more useful when your workload is consistently graphics- or compute-intensive.

Gaming is an obvious example. Higher resolutions, advanced lighting, complex textures, and high frame rates require considerable GPU resources. A discrete GPU also provides dedicated VRAM for graphics assets, which becomes increasingly important as game and display resolutions increase.

Video editing is another area where a discrete GPU can benefit. Modern editing software can use GPU acceleration for effects, color processing, encoding, decoding, and timeline playback. The GPU is just one part of the system. CPU performance, system RAM, storage speed, and software support are also important.

For 3D rendering, engineering applications, and scientific tasks, a discrete GPU can make a huge difference. These applications can divide certain calculations across thousands of parallel processing units, allowing them to complete work that would take much longer on a CPU alone.

AI is another area where discrete GPUs offer an advantage. Training a deep learning model is fundamentally different from rendering a desktop or playing a game. Modern AI frameworks can distribute many mathematical operations across GPU processing units, significantly reducing training times compared to a CPU.

This highlights an important distinction that often gets overlooked in discussions about integrated and discrete graphics.

## Discrete GPUs in Servers And The Cloud

For personal computers, the decision usually revolves around whether you need a dedicated graphics card. In a data center, the question shifts to which type of computing architecture suits your workload best.

A traditional CPU server may include multiple high-performance CPUs, large system RAM, fast storage, and network capabilities. This setup works well for web applications, databases, enterprise software, and many general-purpose workloads.

A GPU server integrates one or more high-performance GPUs. In these systems, the CPUs still manage the operating system, application logic, data loading, and other tasks, while GPUs accelerate workloads that benefit from massive parallel computation.

This is fundamentally about architectural differences rather than just graphics. For deep learning, for example, a GPU server may spend much of its time performing matrix operations and tensor calculations. The CPU coordinates the workload and manages the system, while the GPU handles much of the computationally intensive processing.

## Why VRAM Can Be The Gating Specification

For AI workloads, VRAM capacity can sometimes be more important than raw GPU performance.

Consider a neural network model that needs more GPU memory than what a single GPU can provide. The GPU’s processing cores cannot be fully used if the model and necessary working data do not fit into available memory without techniques such as quantization, offloading, or multi-GPU distribution. This is why GPU selection for AI should not be based only on metrics such as TFLOPS. Memory capacity, memory bandwidth, interconnect technology, and software compatibility are all important.

For example, NVIDIA’s data-center H100 provides 80GB of GPU memory in its SXM configuration, while the L40S provides 48GB of ECC GDDR6 memory. These GPUs also target different workloads and system configurations. The H100 is designed around high-end accelerated computing and AI workloads, while the L40S is positioned as a versatile data-center GPU for AI, graphics, and other workloads.

This explains why comparing a data-center GPU directly with a consumer graphics card can be misleading. A consumer RTX card may offer excellent performance for gaming and creative applications at a relatively accessible price. Data-center GPUs, by contrast, are designed for sustained server operation and demanding compute workloads. They can offer larger memory capacities, enterprise features, specialized AI hardware, and server-oriented deployment options.

## Renting Vs. Buying GPU Capacity

For organizations running AI or high-performance computing workloads, another important decision is whether to purchase GPU hardware or rent GPU capacity from a cloud provider.

Buying GPUs can make sense when utilization is consistently high, and the organization needs long-term control over its infrastructure. High-end GPUs come with a hefty price tag, require suitable servers, and demand sufficient power, cooling, networking, and maintenance.

Cloud and hosted GPU infrastructure present another option. Organizations can access GPU capacity when needed without purchasing and maintaining the underlying hardware themselves. This solution is particularly useful for burst workloads. A research team may need several GPUs for model training for a few days and then less capacity afterward. A company developing an AI application may require GPU resources during development and testing before its production workload becomes predictable.

Atlantic.Net GPU Server Hosting offers dedicated GPU servers and cloud GPU options for workloads that require accelerated computing. The main advantage is flexibility because organizations can select infrastructure around the workload instead of treating GPU hardware as a permanent, fixed investment.

## The Bottom Line

The difference between integrated and discrete graphics comes down to architecture, memory, and performance, beginning with how they are built. Integrated graphics are built into the processor or processor package and usually use shared system memory. They are compact and suitable for everyday computing. Discrete graphics are separate components with dedicated memory. They consume more power and cost more but provide significantly more resources for demanding graphics and compute workloads.

For a typical office laptop on a tight budget, integrated graphics may be all you need. For gaming, professional creative applications, 3D rendering, or demanding AI workloads, a discrete GPU is often the better choice. At the server and cloud level, the decision becomes more complex. Factors such as VRAM capacity, memory bandwidth, GPU architecture, interconnects, software support, and expected workload utilization can all influence which GPU solution is the right fit.

The key takeaway is this: do not choose a GPU based only on performance numbers. Consider your workload, memory requirements, expected utilization, and the total cost of running the system. The right GPU is the one that best matches your specific needs and not necessarily the one with the highest performance specifications.

## Frequently Asked Questions

**How Do I Know If I Have A Discrete GPU?**

On Windows, open Device Manager and expand “Display adapters.” If you see one integrated adapter from Intel or AMD and a separate NVIDIA or AMD Radeon adapter, you probably have both types. Two entries are not conclusive, and the system may switch between GPUs depending on the application. On a Mac, check “About This Mac” under System Report, in the Graphics/Displays section.

**Is Nvidia A Discrete Graphics Card?**

NVIDIA is best known for discrete GPUs, with GeForce RTX as its main consumer line and data-center products such as the H100 and L40S. NVIDIA also makes Grace CPUs and Tegra- or Jetson-based systems that combine CPU and GPU components. Still, an NVIDIA GPU listed in a conventional Windows PC is usually a discrete adapter.

**What Are The Disadvantages Of Dedicated Graphics Cards?**

Higher cost, more power draw, and more heat. Because a discrete GPU requires space for the chip, power components, and cooling, it can add physical size and weight; in compact laptops, it may also reduce battery life. In desktops, they require adequate case airflow and often a stronger power supply.

**Is Integrated Or Dedicated Graphics Better For Video Editing?**

For basic trimming and light editing, integrated graphics can manage, but heavy content creation work and larger videos benefit from discrete graphics. For 4K footage, color grading, effects, or frequent exporting, a discrete GPU can substantially reduce processing time when the software and codec support GPU acceleration. A slow CPU can still bottleneck playback and exports, so system balance matters.

**What GPUs Do Cloud Providers Typically Offer?**

Cloud providers offer a wide range of GPUs, although the specific models available can vary by provider, region, and time. Depending on the platform, you may find everything from consumer-oriented graphics cards to dedicated data-center accelerators such as the NVIDIA A10, L40S, A100, and H100. Atlantic.Net, for example, offers GPU instances powered by NVIDIA H100 NVL and L40S GPUs, providing options for demanding AI, machine learning, and other GPU-accelerated workloads.


---

# Server Hardening Standards for Security and Compliance

> URL: https://www.atlantic.net/managed-services/server-hardening-standards-security-compliance/ | Published: 2026-08-28 | Author: Robert Agar

Server hardening standards are formal security guidelines and benchmarks—such as CIS Benchmarks, DISA STIGs, and NIST guidelines—that define the configurations and controls used to secure servers by reducing attack surface and known vulnerabilities.

For IT security teams, system administrators, and organizations that need stronger protection and regulatory alignment, server hardening is one of the most effective ways to protect the IT environment from sophisticated threat actors, reduce the risk of breaches and downtime, and improve incident detection and security posture. This article explains what server hardening is, why it matters, which standards to use, the core server hardening checklist to apply, key compliance considerations and best practices, and when managed service provider support may make sense.

## What Is Server Hardening?

Server hardening is the process of securing a server by reducing its attack surface. The objective is to minimize and eliminate vulnerabilities and features that threat actors can exploit. A hardened server improves security by removing unnecessary services and shrinking the attack surface.

### What Is A Server’s Attack Surface?

A server’s attack surface comprises all points an unauthorized user or process can exploit to compromise the system. A larger attack surface provides threat actors with more opportunities to gain access to the system. Once inside, an attacker can extract or corrupt data, plant malware, or cause other types of damage to the IT environment.

The attack surface consists of the following categories.

Network-facing elements such as open ports and network services, including web and mail servers, are easily attacked. Endpoints that accept external requests can expose APIs. The use of insecure or obsolete protocols, such as unencrypted FTP, dangerously expands the attack surface.

Software and applications present potential attack surfaces, even when installed but not in use. Web applications and third-party libraries are vulnerable to attack. Companies increase their risk of attack by running unpatched, outdated software versions with known vulnerabilities that can easily be exploited.

User accounts are part of the attack surface. Specifically, default, unused, shared, and service accounts are vulnerable. Administrator accounts and other privileged local accounts with weak passwords or authentication are prime targets for threat actors.

Server configuration issues can expand the attack surface, making it easier for malicious actors to compromise a system. Examples include default settings and passwords left unchanged, as well as misconfigured permissions that allow broad access to sensitive resources. Servers configured with unnecessary services and features present a larger attack surface that can be exploited.

Physical and hardware access points such as USB ports are part of the attack surface. The hardware itself, including console access, can be exploited if physical access to the server is inadequate. Outdated firmware can expose additional vulnerabilities ripe for attack.

## Why Is Server Hardening Important?

Server hardening is essential in today’s dangerous threat market for multiple reasons that contribute to the security of individual production servers and the larger IT environment. The important results of server hardening include:

- Reducing the attack surface to provide fewer opportunities for exploitation;
- Addressing and closing known vulnerabilities that typically are leveraged for real-world data breaches and ransomware attacks;
- Limiting lateral movement and an attack’s blast radius;
- Supporting regulatory and compliance requirements;
- Preventing privilege escalation;
- Improving incident detection with a minimal configuration;
- Minimizing the cost of ongoing security;
- Protecting the server from external and internal threats;
- Reducing downtime and business impacts.

Server hardening is the foundational level upon which all other security controls are built. A hardened server will be better protected by measures such as a Windows firewall than a machine with unnecessary software and poor account management.

## What Are The Three Main Server Hardening Standards?

Organizations typically use one of the following three main standards as the basis of their server hardening efforts.

### Center For Internet Security (CIS) Benchmarks

The [CIS Benchmarks](https://www.cisecurity.org/) are vendor-agnostic, consensus-based configuration guidelines that address the hardening of specific technologies, such as software, servers, and operating systems, to ensure security. The nonprofit CIS publishes them to help organizations improve their security posture.

A CIS Benchmark is a detailed document that specifies the precise steps necessary to configure a given technology securely. The benchmarks cover Windows, Linux, and macOS operating systems, cloud platforms, web browsers, server software, and network devices. They are developed by a global community of security professionals and industry experts, peer-reviewed, and updated continuously to address new vulnerabilities and threats.

### Disa Stigs (Security Technical Guides)

[DISA STIGs](https://www.cyber.mil/stigs/) are detailed and specific hardening guides published by the Defense Information Systems Agency (DISA), the U.S. Department of Defense’s IT and cybersecurity agency. The STIGs define exactly how systems, applications, and network devices must be configured to meet DoD security requirements.

While CIS Benchmarks define best practices, the STIGs are mandatory for systems operating within DoD and other U.S. federal government environments. STIGs are stricter and more detailed than CIS Benchmarks, and are often implemented by organizations operating in regulated industries.

### Nist Guidelines

The [National Institute of Standards and Technology](https://www.nist.gov/) (NIST) produces special publications (SPs) that offer cybersecurity guidance mandatory for U.S. federal agencies and widely adopted by industry as a trusted security baseline. An example is NIST SP 800-123, which is a guide to general server security settings and principles. It does not provide the granular, product-specific configuration steps of CIS Benchmarks or STIGs.

NIST SP 800-123 covers the following aspects essential to server hardening:

- Server planning and deployment, including promoting security considerations to address before deployment, such as network placement and environmental architecture;
- Server installation and configuration issues, removing unused services, patching before deployment, and strong user account management, including implementing the principle of least privilege;
- Guidance on securing the server’s operating system and server applications software by maintaining secure configuration throughout the server’s lifecycle;

Best practices include ongoing patch management, monitoring and retaining security logs, conducting periodic vulnerability assessments, and backup and recovery planning.

NIST SP 800-123 is a strategic and procedural framework for server security. Organizations typically use the document as a guide for strategy and lifecycle planning. CIS Benchmarks and DISA STIGs are used to implement that framework on specific technologies.

## The Core Server Hardening Checklist

The following OS-agnostic checklist covers core hardening across Windows, Linux, and other operating systems. Teams should approach hardening methodically and adopt a security model that incorporates these essential protective measures.

### Access And Account Management

Strong access and account management are essential for successful system hardening. In Windows Server environments, this also includes securing the built-in administrator account and disabling the local guest account when not required. Teams should take multiple measures that include:

- Disabling default, unused, and guest accounts;
- Enforcing a strong password policy that requires complex passwords with forced expiration;
- Disabling direct logins by root or administrators;
- Enabling an account lockout policy after failed login attempts;
- Enforcing least privileged access and multi-factor authentication for admin and domain accounts;
- Disabling password-based SSH logins for Linux systems.

On domain-joined systems, coordinate these account controls with Active Directory policies and review them carefully on any domain controller.

### Network And Services

- Hardening the network and services requires:
- Disabling or removing all unnecessary services and protocols;
- Disabling anonymous enumeration to prevent unauthenticated listing of accounts and shared resources;
- Closing unused ports;
- Configuring host-based firewalls such as Windows Firewall with default-deny rules that allow only approved traffic;
- Restricting administrative access to designated IPs and VLANs;
- Reviewing older Windows services to use the least-privileged built-in account appropriate to the task, such as local service, network service, or local system;
- Disabling insecure protocols such as old TLS/SSL versions;
- Enforcing time synchronization with the Network Time Protocol so logs and authentication events remain consistent across systems.

### Patch And Update Management

Teams must focus on patching and updates to ensure servers remain hardened with activities including:

- Developing a defined schedule to apply OS and application security patches, prioritizing each production system and using testing plus staged rollout to avoid disrupting the production server;
- Teams should configure automatic updates for appropriate server classes to receive critical security patches, while staggering deployment where testing is required, since older unpatched flaws are often used to cause a data breach;
- Track end-of-life software and upgrade or replace it before support ends.

### File System And Data Protection

Safeguarding data assets is a primary reason for server security and requires these measures:

- Ensuring file and directory permissions follow the principle of least privilege;
- Protecting sensitive data at rest with disk encryption and in transit with TSL/SSL solutions.
- Restricting access to configuration files and disabling world-writable resources whenever possible.

### Logging And Auditing

Teams need to monitor server security with logging and auditing capabilities, including:

- Enabling centralized monitoring, provisioning the maximum log size for the environment, and using synchronized timestamps to improve investigations and support security audits;
- Implementing a reliable event log retention method;
- Enabling audit logging for authenticated users and privileged activity;
- Retaining logs to meet compliance requirements;
- Monitoring to identify and address unauthorized configuration changes by tracking drift from approved server configurations and broader system configuration baselines.

### Application And Service Hardening

Steps to harden server applications and services include:

- Removing unnecessary software and sample files as part of security hardening to reduce exposure from unnecessary components;
- Hardening all exposed services such as web servers and databases using specific CIS Benchmarks;
- Running services with dedicated, non-privileged accounts, and installing and updating anti-virus software and other security tools to protect those services;

### Backup And Recovery

Backups and recovery procedures are essential to maintain a hardened environment and include:

- Implementing schedules and tested backups;
- Restricting access to backup processes to authorized backup operators;
- Encrypting and storing backups away from production systems;
- Developing and regularly testing disaster recovery procedures.

### Monitoring And Maintenance

The hardened environment should be maintained with procedures that keep secure server configurations in place over time, such as:

- Running vulnerability scans regularly;
- Scheduling periodic reviews of user accounts and permissions;
- Performing configuration audits against the chosen hardening standard to help protect the wider IT infrastructure from drift and unauthorized changes.

Teams should also account for the Windows Server version in use, since newer releases include stronger native security capabilities.

Windows-specific hardening activities include:

- Securing remotely accessible registry paths;
- Protecting secure channel data and network traffic with strict local or Group policies;
- Enabling Credential Guard and Microsoft Defender protection;
- Addressing LAN Manager authentication levels in older Windows Server versions or Windows NT.

Ubuntu and Linux-specific hardening activities include:

- Updating all packages and performing a minimal installation;
- Creating named admin users and disabling direct root login via SSH;
- Hardening the SSH configuration to force key-based authentication;
- Verifying AppArmor is active for access control.

## Hardening For Compliance

While hardening is considered best practice for all business-critical servers, it is mandatory for compliance with regulations such as PCI DSS or HIPAA. Organizations should consult the specific regulations for their regulatory framework. For example, PCI DSS Requirement 2 specifies that vendor-supplied default passwords cannot be used and must be changed.

HIPAA also defines specific requirements around access controls and encryption for protected health information (PHI). Event log settings must be sufficient to support secure audits and a complete audit policy. Organizations benefit from a hardened hosting environment as it reduces the scope of compliance audits.

## Best Practices For Keeping Servers Hardened

Teams must understand that server hardening is not a one-and-done proposition. The initial hardening activities should be augmented by these best practices to ensure the servers remain hardened and help protect the broader IT infrastructure:

- Automate configuration management with defined hardened images and templates for consistent server configurations;
- Exercise patch management discipline and follow a well-defined schedule;
- Strictly enforce the principle of least privilege;
- Monitor the server environment with centralized logging and alerts for unauthorized activity;
- Maintain strict firewall rules and segment servers by function;
- Run vulnerability scans regularly and promptly address their results;
- Test backup and recovery procedures regularly;
- Require review and approval for changes to hardened systems;
- a security-first culture across the organization.

## The Managed Option

Some companies, especially small and medium-sized businesses (SMBs), may lack the in-house technical resources to harden their servers effectively. These businesses, especially those processing regulated data, should strongly consider partnering with a reputable [managed service provider (MSP)](https://www.atlantic.net/compliance-hosting/) to realize the additional security protection that hardening provides. A reliable and experienced MSP will handle IT security, including hardening, enabling customers to focus on core business activities.

## FAQ

**Q: What is OS hardening?**

A: OS hardening secures an operating system by reducing its attack surface and vulnerabilities. It leverages many of the same techniques used in server hardening targeted exclusively at the operating system. The goal is to eliminate unnecessary services and default accounts to prevent unauthorized access to a computer.

**Q: What is the most basic step in OS hardening?**

The most basic step in OS hardening is to remove or disable all services and features not needed for business purposes. This process drastically reduces the attack surface and eliminates the need to patch and monitor unused server elements. All subsequent hardening activities are streamlined by attack surface reduction.

**Q: What is the server hardening process?**

The server hardening process should be seen as ongoing rather than a one-time task. Teams should work to continually reduce the attack surface to prevent anonymous access to the environment. Organizations must maintain hardened servers to align with their adopted hardening standard.

**Q: How to harden Windows Server?**

You should take the following specific steps for Windows Server hardening in addition to more general hardening procedures.

- Disable LM hashes to protect against exploitable legacy Lan Manager hash values;
- Disable remote registry and print spooling if not necessary.
- Block inbound traffic by restricting RDP with Windows Firewall.
- Set an account lockout threshold of no more than five invalid attempts.

**Q: How often should hardening be reviewed?**

Teams should review hardening based on the organization’s risk tolerance and change frequency. The following practical approach is suitable for most companies.

- Companies should implement continuous and automated patch management and log reviews.
- Vulnerability scans should be performed weekly to check critical patch status.
- A monthly patch compliance review should be conducted, including an audit policy for privileged accounts.
- Companies should schedule a quarterly complete hardening baseline audit with a review of firewall rules and a backup and restore test.
- An annual review should align with benchmarks, penetration testing, and a review of policies and documentation.


---

# Web Hosting Red Flags: 10 Signs You’re With The Wrong Provider

> URL: https://www.atlantic.net/cloud-platform/web-hosting-red-flags/ | Published: 2026-08-28 | Author: Richard Bailey

A bad web hosting provider can quietly damage website performance, security, customer trust, and search visibility. The clearest web hosting red flags include frequent downtime, slow load times during low traffic, hidden fees, weak customer support, missing backups, outdated software, and no practical way to scale or leave.

One isolated server error does not mean you have bad web hosting. Look for repeated problems, weak explanations, and support teams that cannot provide evidence. A reliable hosting provider should publish clear service commitments, state resource limits, maintain current systems, protect customer data, and give you control over your website and domain.

## Key Takeaways

The three biggest red flags are repeated unexplained downtime, poor performance during low website traffic, and support that cannot resolve technical issues.

What good looks like: transparent pricing, a published uptime SLA, current infrastructure, tested backups, baseline security, and qualified support available around the clock.

Choosing a hosting company based only on its introductory price can be expensive. Compare reliability, server resources, security features, renewal terms, and support quality before committing to a hosting plan.

Here are ten warning signs that your current provider may be holding your site back.

## 1. Why Does Your Website Keep Going Offline?

Every hosting provider experiences planned maintenance and occasional faults. Frequent downtime becomes a clear sign of bad hosting when outages repeat, status updates remain vague, or the provider refuses to explain the cause.

Reliable hosting providers typically guarantee uptime of 99.9% or higher. At 99.9% uptime, a site could still be unavailable for about 43 minutes during a 30-day month. By comparison, 0.5% downtime permits roughly 216 minutes, or 3.6 hours. Do not treat 0.5% downtime as a strong reliability target.

Hosts should explain uptime SLAs clearly, including:

- How downtime is measured.
- Which events are excluded.
- Whether maintenance is included.
- What compensation is offered for outages.

Websites that go offline regularly indicate poor hosting reliability. Frequent downtime can frustrate users, interrupt sales, weaken a brand’s reputation, and make it harder for search engines to access the site.

Use independent uptime monitoring instead of relying only on the host’s status page.

## 2. Is Your Hosting Plan Causing Slow Page Loads?

Slow websites are not always caused by web hosting. Large images, inefficient code, database problems, and excessive plugins can also affect page speed.

Consistently slow server response during low-traffic periods points toward the hosting environment.

This often happens with poorly managed shared hosting. Multiple customers use the same server and compete for the same resources. Responsible providers set and disclose CPU, memory, storage I/O, and process limits. Oversold providers may place too many customers on each server, causing poor performance even when your own website traffic is low.

Test:

- Time to First Byte on a simple or cached page.
- CPU and memory use.
- Disk I/O limits.
- Performance at different times of day.

A website should ideally load its main content within two to three seconds. Google defines a good Largest Contentful Paint result as 2.5 seconds or less at the 75th percentile. Core Web Vitals contribute to page experience, although speed alone does not guarantee better search engine rankings.

Slow websites can lead to declining conversions, fewer page views, and weaker SEO performance.

## 3. The Low Price Disappears At Renewal

A discounted introductory price is not automatically a red flag. The problem starts when the hosting company hides the standard renewal price or adds charges for services customers reasonably expected to receive.

Watch for hidden fees related to:

- TLS certificates.
- Website migrations.
- Backups or restores.
- Malware removal.
- Email accounts.
- Control panel access.
- Higher resource limits.

Some hosts charge low initial prices but impose steep renewal rates after the first term. Others advertise a monthly rate that requires several years of advance payment.

Providers that charge high recurring fees for basic TLS certificates or routine backups may be relying on an outdated pricing model. Free domain-validated TLS certificates are widely available, although specialized certificates and managed security services can carry legitimate costs.

Seek hosts with transparent pricing structures, clear renewal terms, and an accessible cancellation policy. Always check the terms of service for hidden costs before paying.

A trustworthy host typically provides a money-back guarantee, but you should still check its exclusions and claim deadline.

## 4. Support Is Slow, Scripted, Or Ticket-Only

Quality customer support can save hours of downtime. Poor customer service can leave an online business dealing with unresolved errors while customers move elsewhere.

Watch for hosts that lack 24/7 support or claim to offer it while providing only an automated ticket form. Ticket-based support can work well, but urgent problems need clear response targets and a defined escalation process.

Warning signs include:

- Generic answers that ignore the reported issue.
- Repeated requests for information already supplied.
- No phone support or emergency phone number.
- Agents who cannot access server logs.
- Tickets closed before the problem is fixed.

Test support before a crisis. Open a non-critical technical ticket outside regular business hours. Note how quickly a human responds, whether the agent understands the issue, and whether the case can reach a qualified engineer.

Reliable hosting providers typically offer 24/7 customer support through more than one contact method. Hosts should also provide clear, accessible contact information.

## 5. What Should A Hosting Backup Policy Include?

“Backups included” tells you very little.

Ask what data is backed up, how often backups run, how long copies are retained, and where they are stored. A backup kept on the same server as the live site may disappear during a major hardware failure or security incident.

The hosting service should also explain:

- Whether database backups are consistent.
- Whether restoration costs extra.
- How often restores are tested.
- The expected recovery time.
- How much recent data could be lost.

These last two points are often defined as the recovery time objective (RTO) and the recovery point objective (RPO).

Regular backups are essential for website data protection, but a backup has limited value if nobody can restore it. Hosts should have a transparent backup and recovery policy and should test disaster recovery procedures.

Keep at least one current copy of your files, database, and configuration under your own control. Poor hosting can lead to malware or spam issues, and you should not depend on the affected provider for your only clean backup.

## 6. The Infrastructure Is Unsupported Or Poorly Maintained

Old hardware is not automatically unreliable. The stronger warning sign is a host that cannot explain its storage technology, maintenance cycle, operating systems, or software support policy.

Active website hosting should generally use SSD or NVMe storage. Mechanical drives may still serve valid archival purposes, but relying on slow storage for active databases can create performance issues.

Check whether the host offers supported versions of:

- PHP.
- Database software.
- Web server software.
- Operating systems.
- Control panels.

The PHP project publishes a clear support schedule. Once a version reaches end of life, it no longer receives official fixes.

Unsupported software can create compatibility issues and leave known security weaknesses unpatched. Ask how quickly the provider applies operating system and security updates.

A hosting provider that forces customers to run obsolete software puts the site owner’s security and hard work at risk.

## 7. Basic Security Is Missing Or Sold As An Expensive Extra

No hosting company can prevent every hacking attempt. Customers must still secure applications, passwords, plugins, and user accounts.

The provider should supply a reasonable security baseline, including:

- TLS certificates with automatic renewal.
- Account isolation.
- Patch management.
- Multi-factor authentication.
- Network-level DDoS protection.
- Security logging.
- Firewall options.
- Malware scanning or detection.

TLS certificates encrypt data between the website and its visitors. They do not prevent stolen credentials, vulnerable software, malicious uploads, or every type of data breach.

Inadequate security can leave websites vulnerable to cyberattacks, malware, spam, and service disruption. Cheap hosting is not always insecure, but suspiciously cheap plans may reduce security protections or charge separately for essential controls.

Advanced services such as managed web application firewalls, malware remediation, large-scale DDoS mitigation, and incident response may cost extra. The provider should clearly distinguish included security features from paid managed services.

## 8. Can The Provider Support Future Growth?

A hosting plan that works today may struggle as traffic, data, or application demands increase.

The provider should offer a clear path from shared hosting to virtual servers, dedicated infrastructure, or other scalable options. Ask whether CPU, memory, storage, and bandwidth can be increased without an emergency migration.

Vague claims of “unlimited” resources usually come with hidden limits. Every server has finite capacity. A reliable provider states those limits and explains what happens when customers exceed them.

Warning signs include:

- No intermediate upgrade options.
- Long outages for routine upgrades.
- Forced control panel changes.
- No support for load balancing.
- No migration assistance.

The right hosting service should allow your business to grow without rebuilding the entire environment each time resource requirements change.

## 9. The Host Makes It Difficult To Leave

A provider should retain customers through good service, not lock-in tactics.

Be cautious if the hosting company refuses to provide a full website export, limits database access, withholds DNS records, or delays a domain transfer without a valid reason.

Keep your domain registration in an account controlled by your business whenever possible. Confirm that the administrative contact belongs to you and that you can obtain the transfer authorization code.

Before signing a contract, review:

- Early termination charges.
- Cancellation notice periods.
- Data export formats.
- Backup access after cancellation.
- Domain transfer terms.
- Forced contract lengths.

Some transfer holds are legitimate security or registry requirements. The red flag is deliberate obstruction, invented charges, or a provider attempting to hold your domain or data hostage.

Your files, databases, email, DNS records, and customer data should remain portable.

## 10. When Do Compliance Gaps Become A Business Risk?

Compliance matters when a website processes payment data, health information, or other sensitive records.

A host does not need every certification. It must understand its responsibilities and provide accurate documentation for the services it claims to support.

For SOC 2, ask which Trust Services Criteria are covered and whether the report addresses security, availability, processing integrity, confidentiality, or privacy.

For HIPAA workloads, determine whether the provider will sign a HIPAA Business Associate Agreement (BAA) when it creates, receives, maintains, or transmits electronic protected health information.

For payment environments, request relevant PCI DSS evidence and a responsibility matrix. Using a third-party provider does not remove the customer’s responsibility to protect payment data.

A host that cannot answer basic SOC 2, HIPAA, or PCI questions may not be suitable for regulated workloads.

## What Should You Ask Before Switching Web Hosts?

Do not migrate because of one poor support interaction. Collect evidence, research different companies, and compare each provider using the same questions.

Use this checklist:

- What uptime SLA applies to my exact plan?
- How is downtime measured?
- What server resources and limits are included?
- What is the full renewal price?
- Which services carry extra fees?
- Is qualified technical support available 24/7?
- How often are backups created and tested?
- Which software versions are supported?
- Which security controls are included?
- Can I upgrade without a complete migration?
- Can I export all files, databases, email, and DNS records?
- Which compliance reports or agreements are available?

Look for customers’ specific feedback in independent reviews. Useful reviews describe actual outages, renewal charges, support cases, or migration experiences. A lack of independent third-party reviews can signal a less established or less trustworthy host, while repeated vague praise may indicate fake positives.

Also inspect the provider’s website. Broken account pages, missing legal terms, outdated documentation, and inaccessible contact details may reflect poor operational discipline.

## Frequently Asked Questions

**What Does “Bad Host” Mean?**

A bad host repeatedly fails to meet reasonable expectations for uptime, speed, security, support, pricing, or customer control. One technical issue does not prove that the provider is unreliable. Repeated failures without clear explanations or corrective action are stronger warning signs.

**What Should I Look For In A Web Host?**

Look for a published uptime commitment, clear renewal pricing, stated server resource limits, supported software, tested backups, included TLS certificates, security controls, and accessible customer support. Compare reliability and features rather than choosing only by price.

**How Do I Know Whether Hosting Is The Problem?**

Check Time to First Byte, CPU and memory use, disk I/O, application errors, and performance on a simple cached page. If server response remains slow during low traffic after application issues have been ruled out, the hosting environment may be responsible.

**When Is It Time To Switch Hosting Providers?**

Consider switching when downtime, slow page loads, poor customer support, security gaps, or unexpected charges form a repeated pattern. Move sooner if the provider cannot meet a legal, security, or compliance requirement.

**How Hard Is Migrating Hosts?**

Migration difficulty depends on the website, database, email setup, DNS, and application. A small site may move quickly. Ecommerce, membership, and custom applications need testing, final data synchronization, a maintenance plan, and a rollback option.

**Can Changing Hosts Improve SEO?**

Changing hosts can help when the existing server causes slow response times, frequent downtime, or recurring errors. Hosting quality affects user experience and SEO performance, but a new host will not fix weak content, poor architecture, or unrelated technical SEO issues.

**What Does A Reliable Hosting Provider Look Like?**

A reliable hosting provider publishes measurable commitments, communicates during incidents, and gives customers access to qualified support. It maintains current systems, tests backups, applies clear security controls, explains pricing, and offers a practical scalability path.

Customers should also retain control of their domain, website data, DNS records, and backups.

[Atlantic.Net Managed Services](https://www.atlantic.net/managed-services/) provides 24/7 technical support, infrastructure monitoring, security management, backup and disaster recovery options, and migration assistance for organizations that need additional operational support.

The right provider should reduce technical risk without making support, billing, growth, or migration harder than necessary.


---

# Atlantic.Net Adds One-Click Agentic AI Deployments for OpenClaw and Hermes Agent

> URL: https://www.atlantic.net/press-releases/atlantic-net-adds-one-click-agentic-ai-deployments-for-openclaw-and-hermes-agent/ | Published: 2026-08-29 | Author: Editorial Team

*New Cloud Portal images let organizations easily run autonomous AI agents on isolated, always-on infrastructure, with full control over credentials, tools, and data*

ORLANDO, Fla. (August 28, 2026) — [Atlantic.Net](https://www.atlantic.net/), a global cloud infrastructure provider specializing in security and compliance, today announced one-click deployments for two open-source agentic AI applications, OpenClaw and Hermes Agent, on its On-Demand Cloud platform. Both applications give organizations a private, dedicated environment for AI agents that browse the web, run commands, and act on files, rather than running that software on employee laptops or shared systems.

Unlike chatbots, agentic AI takes real actions on real systems. Where an agent runs is therefore a security decision as much as an infrastructure one. A dedicated Atlantic.Net Cloud Server isolates agent activity from corporate endpoints, keeps API credentials off personal machines, and keeps the agent available around the clock.

OpenClaw is a widely adopted open-source agent framework with the broadest library of ready-made skills and the widest support for messaging platforms. Atlantic.Net recommends OpenClaw when the goal is an always-available AI assistant that employees reach through the channels they already work in, with sessions, model access, and tools organized behind its self-hosted gateway. It is the stronger fit for teams that include non-developers.

Hermes Agent is built to improve over time. It combines persistent memory across sessions, scheduled tasks, and a closed learning loop that turns repeated work into reusable skills. An OpenAI-compatible API lets developers build their own applications on top of the agent, which suits engineering teams and API-first workflows.

“Agentic AI is moving from experiment to production, and the operational questions are catching up fast. Where does this run? Who holds the credentials? What can it reach?” said Marty Puranik, CEO of Atlantic.Net. “Our answer is the same one we have given for every other production workload: put it on infrastructure you control, isolated from everything else, on a platform built for security and compliance.”

Deployment follows the standard Atlantic.Net one-click application workflow. Customers select OpenClaw or Hermes Agent from the Applications section of the Add Server page in the Cloud Portal, launch and login to the server, connect their preferred AI model provider, and follow the rest of the guided setup steps.

“While they have many similarities, the difference between the two comes down to who the agent serves,” Puranik added. “OpenClaw is the assistant your whole team can talk to from wherever they already work. Hermes is the agent your developers build on and teach. Both start conservative and scale as confidence grows, and in either case the organization retains full control over user access, credentials, tools, data, and workload isolation.”

Both applications connect to a customer-supplied model provider such as OpenAI, Anthropic, OpenRouter, etc. Model usage is billed by that provider, separately from Cloud Server charges.

OpenClaw Hosting and Hermes Agent Hosting are available now on Ubuntu 26.04 Cloud Servers. Learn more at [Open Claw Hosting](https://www.atlantic.net/cloud-platform/openclaw-hosting-your-ai-assistant-always-on/) and [Hermes Agent Hosting](https://www.atlantic.net/cloud-platform/hermes-agent-hosting-always-on-ai-for-real-work/).

About Atlantic.Net

Founded in 1994,[Atlantic.Net](https://www.atlantic.net/) is a privately held global cloud infrastructure provider with customers in over 100 countries, known for delivering secure, compliant, on-demand and customizable hosting solutions. With decades of experience, Atlantic.Net is one of the world’s most trusted and experienced hosting providers, offering 24/7 U.S.-based support. Specializing in security, compliance, and customer service, Atlantic.Net serves a diverse range of industries with solutions including HIPAA-compliant hosting and PCI-compliant hosting, backed by bare metal servers, dedicated hosting, GPU hosting, colocation, and its award-winning Cloud Platform. Operating from eight strategically located data center regions across the United States, Canada, the United Kingdom, and Asia, Atlantic.Net powers mission-critical workloads for organizations worldwide. For more information, visit[Atlantic.Net](https://www.atlantic.net/) or connect with us on[Facebook](https://www.facebook.com/Atlantic.Net),[X (Twitter)](https://twitter.com/AtlanticNet),[LinkedIn](https://www.linkedin.com/company/atlantic.net-inc./posts/?feedView=all), and[YouTube](https://www.youtube.com/c/AtlanticNet).


---

# Infrastructure Cluster Solutions

> URL: https://www.atlantic.net/dedicated-server-hosting/infrastructure-cluster-solutions/ | Updated: 2026-09-16

Deploy an Entire Production Infrastructure Cluster as One Managed Environment

Get the compute, networking, security, backups, monitoring, and infrastructure management required to run demanding production workloads, delivered together as a single Atlantic.Net-managed solution.

Choose a three-host Managed Private Cloud or Bare Metal cluster, with Linux and Windows configurations available. Atlantic.Net provides the data center infrastructure, high-availability firewalls, secure remote access, backup services, monitoring, and ongoing infrastructure support.

Private Cloud from $19.5K/month | Bare Metal from $20.2K/month

- 3-Host Managed Infrastructure
- 1-10Gbps Connectivity
- 200TB Monthly Transfer
- HA FortiGate Firewalls
- Daily Local + Off-Site Backups
- 24/7/365 Support

## Complete Infrastructure Cluster

A production environment needs more than servers. Networking, security, backups, secure access, monitoring, and operational support all need to work together.

Atlantic.Net brings these components into a single managed cluster, reducing complexity and the need to coordinate with multiple providers.

| Infrastructure Requirement | Atlantic.Net Infrastructure Cluster |
| --- | --- |
| Compute infrastructure | Three-host Managed Private Cloud or Bare Metal cluster |
| Network connectivity | 1-10Gbps connectivity with 200TB monthly transfer |
| Perimeter security | Two managed FortiGate firewalls in an HA configuration |
| Intrusion prevention | Included |
| Backup | Daily local and off-site backups |
| Secure remote access | Five managed VPN connections |
| Multi-factor authentication | DUO MFA for five users |
| Host security | Trend Micro security across all three hosts |
| Monitoring | Included as part of the managed environment |
| Infrastructure operations | Managed by Atlantic.Net |
| Support | 24/7/365 US-based support |

Get a complete infrastructure platform, fully integrated and managed by a single provider.

## Choose the Right Infrastructure Cluster

Choose between Private Cloud for pooled, virtualized resources and Bare Metal for dedicated, physical infrastructure. Then choose Linux or Windows as the base operating system.

## Clustered Private Cloud

A three-host KVM private cloud with pooled compute, memory, and storage. Ideal for organizations running virtualized applications, databases, Kubernetes, or private cloud workloads, including those evaluating VMware alternatives.

| Resource | Included Capacity |
| --- | --- |
| Compute | 192 Xeon vCPUs |
| Memory | 768GB DDR5 |
| Storage | 19.2TB NVMe SSD RAID 10 |
| Hosts | Three fully managed hosts |
| Data Transfer | 200TB/month |
| Connectivity | 1Gbps |
| Virtualization | KVM |

Linux: From $19.5K/month. Windows: From $21.8K/month, including Windows Server 2025 Datacenter licensing.

12-month agreement. A one-time $300 installation charge applies for the two FortiGate firewalls. Private Cloud is covered by Atlantic.Net's standard [100% uptime SLA](https://www.atlantic.net/cloud-service-level-agreement/).

## Clustered Bare Metal

Three dedicated Dell PowerEdge R650 servers for workloads requiring direct access to physical compute, memory, storage, and networking resources.

Across the cluster: 216 physical CPU cores, 432 threads, and 1.5 TB RAM.

| Component | Per Server |
| --- | --- |
| Server | Dell PowerEdge R650, 8SFF NVMe |
| Processor | 2 × 36-core Intel Xeon Platinum 8360Y |
| CPU | 72 cores / 144 threads |
| Memory | 512GB DDR4 |
| Boot Storage | 2 × 480GB M.2 SATA SSD |
| Primary Storage | 4 × 6.4TB U.2 NVMe SSD |
| Hosts | Three fully managed hosts |
| Networking | 4 × 10Gb ports |

Linux: From $20.2K/month. Windows: From $21.1K/month, including Windows Server Standard licensing and Proxmox.

12-month agreement. A one-time $300 installation charge applies for the two FortiGate firewalls. Bare Metal is governed by the applicable [Dedicated Server MSA](https://www.atlantic.net/hosting-master-services-agreement/) and service-level terms.

## Private Cloud or Bare Metal?

| Attribute | Private Cloud | Bare Metal |
| --- | --- | --- |
| Architecture | Virtualized three-host cluster | Three dedicated physical servers |
| Resources | Pooled | Dedicated per server |
| Compute | 192 vCPUs | 216 physical cores / 432 threads |
| Memory | 768GB DDR5 | 1.5TB DDR4 |
| Storage | 19.2TB NVMe RAID 10 | 12.8 TB of dedicated NVMe SSD storage in RAID 10 per server |
| Hosts | Three fully managed hosts | Three fully managed hosts |
| Best For | Virtualization and flexible workloads | Dedicated performance and isolation |
| Starting Price | $19.5K/month | $20.2K/month |

Choose Private Cloud for pooled virtualized infrastructure. Choose Bare Metal when dedicated physical resources and greater hardware control are required.

## Everything Included With Every Standard Cluster

### Three-Host Infrastructure

Three managed hosts provide the foundation for clustered and highly available workloads.

### HA FortiGate Firewalls

Two managed FortiGate firewalls provide perimeter security and intrusion prevention.

### Daily Local and Off-Site Backups

Managed daily backups provide both local and off-site protection.

### Secure Remote Access

Five managed VPN connections with DUO MFA for five users.

### Trend Micro Security

Trend Micro security is included across all three hosts.

### High Connectivity

Includes 200 TB of monthly data transfer over a 1-10 Gbps connection.

### Managed Infrastructure Operations

Atlantic.Net handles deployment, monitoring, infrastructure management, and ongoing support.

## Infrastructure for Demanding Production Workloads

| Use Case | How the Cluster Helps |
| --- | --- |
| Business-Critical Applications | Run critical applications on a managed three-host infrastructure platform built for performance and availability. |
| Database Platforms | High CPU, memory, NVMe storage, and 1-10Gbps connectivity support demanding database workloads. |
| Kubernetes and Containers | Three-host infrastructure provides a strong foundation for clustered Kubernetes and container environments. |
| Private Cloud and Virtualization | Run virtualized workloads on pooled infrastructure using KVM as an alternative to VMware or Hyper-V. |
| Disaster Recovery | Multi-host infrastructure with daily local and off-site backups can support broader disaster recovery and continuity strategies. |
| Regulated Environments | Deploy workloads within Atlantic.Net environments designed to support applicable security and compliance requirements. |

## One Managed Infrastructure Provider

Compute, networking, perimeter security, backups, authentication, monitoring, and infrastructure support are delivered together in a single Atlantic.Net environment. This provides a clear operational relationship for the core infrastructure components included within the service.

## More Than 32 Years of Hosting Experience

Atlantic.Net has provided hosting and infrastructure services since 1994, giving organizations access to decades of experience operating production hosting platforms.

## Global Infrastructure

Atlantic.Net operates across eight global data center regions in the United States, Canada, the United Kingdom, and Singapore.

## 24/7/365 US-Based Support

Customers have access to round-the-clock US-based support for the infrastructure environment.

## Security and Compliance Experience

Atlantic.Net environments support requirements associated with:

- SOC 2 Type II
- SOC 3 Type II
- HIPAA
- HITECH
- PCI DSS 4.0

Compliance applicability depends on the selected service, configuration, location, customer responsibilities, and contractual requirements.

## Need More Than a Standard Cluster?

Custom infrastructure platforms from $50,000/month

For requirements beyond the standard configurations, Atlantic.Net can design custom infrastructure around your compute, memory, storage, networking, security, availability, and growth needs.

## Frequently Asked Questions

### What is an Atlantic.Net Infrastructure Cluster?

A managed three-host environment combining compute, networking, security, backups, monitoring, and infrastructure support. Private Cloud and Bare Metal configurations are available.

### Should I choose Private Cloud or Bare Metal?

Choose Private Cloud for pooled virtualized resources. Choose Bare Metal for dedicated physical compute, memory, storage, and networking. The best option depends on your workload, performance, and isolation requirements.

### Can the standard configurations be customized?

Yes. Atlantic.Net can design custom infrastructure for requirements beyond the published standard configurations.

### What is included with every standard cluster?

Every standard cluster includes:

- Three hosts
- HA FortiGate firewalls with intrusion prevention
- Daily local and off-site backups
- Five VPN connections
- DUO MFA for five users
- Trend Micro security
- 200TB monthly transfer
- 10Gbps connectivity
- Monitoring, management, and support

### Does Private Cloud use VMware or Hyper-V?

No. Atlantic.Net Private Cloud uses KVM. Windows Server licensing can be added where required.

### How is Windows licensed?

Private Cloud includes Windows Server 2025 Datacenter licensing. Bare Metal uses Windows Server Standard licensing with Proxmox.

### What happens if a host fails?

Atlantic.Net manages the underlying hardware, while workload-level failover depends on how the applications, virtual machines, and databases are architected. Failover requirements should be defined during solution design.

### Can I run Kubernetes?

Yes. Both Private Cloud and Bare Metal can provide infrastructure for Kubernetes and other clustered container platforms.

### What backups are included?

Every standard cluster includes managed daily local and off-site backups.

### What SLA applies?

Atlantic.Net's [Cloud Service Level Agreement](https://www.atlantic.net/cloud-service-level-agreement/) covers Private Cloud. The applicable [Dedicated Server MSA](https://www.atlantic.net/hosting-master-services-agreement/) and service-level terms govern Bare Metal.

## Build Your Production Infrastructure With Atlantic.Net

Choose a managed Private Cloud, Bare Metal, or custom infrastructure platform built around your workload requirements.

- Private Cloud from $19.5K/month
- Bare Metal from $20.2K/month
- Custom Infrastructure from $50K/month

Atlantic.Net: Dedicated Server Hosting Since 1994.

## Cloud Availability in Multiple Global Regions

Deploy close to your users from eight international data centers worldwide, with new regions on the way.

## Dedicated to Your Success

Jason Coleman

VP of Information Technology,  Orlando Magic

> "After evaluating a range of managed hosting options to support our data operations, we chose Atlantic.Net because of their superior infrastructure and extensive technical knowledge."

Joseph Nompleggi

VP of Product Development,  Complete Healthcare Solutions

> "As our reliable Healthcare IT compliance partner for the past ten years, Atlantic.Net continues to deliver advanced IT architectural design and security guidance and support to CHS. With their flexible, customized solutions and high touch approach, we look forward to continuing to grow and work with this distinguished team of professionals."

Gilad Shainer

Senior Vice President of Networking,  NVIDIA

(Formerly Vice President of Market Development at Mellanox Technologies)

> "Leveraging InfiniBand's performance, efficiency and scalability capabilities, Atlantic.Net is able to provide its customers with a high-performance, reliable and scalable on-demand public cloud hosting platform."

Erin Chapple

General Manager for Windows Server,  Microsoft Corp.

> "Atlantic.Net's support for Windows Server Containers in their cloud platform brings additional choice and options for our joint customers in search of flexible and innovative cloud services."

## Enterprise Hosting Designed Around Your Needs

From single servers to fully managed clusters, we'll help you build the ideal infrastructure for your business.

Call or email us now.

[**USA:** 866-618-DATA (3282)](tel:+18666183282) [**INTL:** +1-408-335-0825](tel:+14083350825) [**EMAIL:** sales@atlantic.net](mailto:sales@atlantic.net)

### Let's Discuss Your Infrastructure Needs

Contact an advisor at **866-618-DATA (3282)**, email **sales@atlantic.net**, or fill out the form below to get started.

### See What Sets Atlantic.Net Apart and How We Help Customers Succeed.

Recognized with the **2026 Excellence in Customer Service Award** from the **Business Intelligence Group**, Atlantic.Net is committed to delivering industry-leading support and an exceptional customer experience.


---

# Why Atlantic.Net Is a Strong HIPAA Hosting Alternative to LuxSci

> URL: https://www.atlantic.net/hipaa-compliant-hosting/atlantic-net-hipaa-hosting-alternative-luxsci/ | Published: 2026-09-04 | Author: Richard Bailey

Healthcare organizations expect their hosting provider to protect electronic Protected Health Information (ePHI). Under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the provider must also sign a HIPAA Business Associate Agreement (BAA) when its services handle ePHI. Customers need clear answers about server management, security controls, backups, migration, and technical support.

LuxSci is an established healthcare communications provider. Founded in 1999, the company serves more than 1,900 customers and offers secure email, marketing, forms, and hosting. Organizations reviewing the market may still find that a different provider is a better fit for a particular infrastructure requirement.

Atlantic.Net is a strong option for teams that want managed HIPAA hosting across cloud, dedicated, and custom environments. Our service combines independently audited controls, a standard BAA, managed security, daily backups, migration help, and round-the-clock support from a provider with more than three decades of hosting experience.

The difference comes down to fit. A new client was looking at moving away from LuxSci, the request was for a Linux workload that needed four or more cores, 16 GB of memory, about 300 GB of storage, host five websites, and featured restricted SFTP access, encryption at rest, and full server management, Atlantic.Net were invited to scope the infrastructure and managed services as one solution, this is how we did it.

## Why Consider Atlantic.Net For HIPAA Hosting?

[Atlantic.Net’s HIPAA-compliant hosting](https://www.atlantic.net/hipaa-compliant-hosting/) is designed for healthcare organizations, software providers, and other businesses that store or process ePHI. The platform is SOC 2 and SOC 3 certified and HIPAA and HITECH audited by an independent USA-based third-party CPA firm.

Our HIPAA plans bring together several controls and services that would otherwise need to be sourced and managed separately:

- **Contractual Coverage:** A BAA is available with every HIPAA hosting plan.
- **Managed Security:** Managed FortiGate firewall service, scheduled vulnerability scanning, multi-factor authentication, and managed VPN access are included in the published packages.
- **Backup Planning:** Onsite and offsite daily backups support recovery planning.
- **Engineering Help:** Server management and migration time give customers direct access to engineers during setup and ongoing operations.
- **Infrastructure Choice:** Linux and Windows options are available across managed cloud, dedicated, and custom designs.

This combination suits organizations that want one provider to take responsibility for the hosting platform and its defined managed-services boundary. Atlantic.Net has operated since 1994, giving customers access to a team with extensive experience in production infrastructure and regulated hosting.

## A Managed Platform With Clear Responsibilities

HIPAA hosting works best when the provider and customer document who owns each control. The provider can operate the infrastructure, firewall, backups, monitoring, and other services named in the agreement. The customer remains responsible for its application, user access, staff policies, risk analysis, data handling, and correct use of the environment.

[US Department of Health and Human Services guidance](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html) states that a cloud service provider that creates, receives, maintains, or transmits ePHI is a business associate and must enter into a BAA with the covered entity or the business associate. The guidance also explains that customers retain responsibilities under the HIPAA Rules.

The shared-responsibility position is clear: a HIPAA server supports part of the customer’s compliance program, while organizational compliance also depends on administrative and technical safeguards. This clarity helps IT and compliance teams build a responsibility matrix without assuming that the hosting package covers application-level duties.

During discovery, confirm ownership of operating-system patching, application patching, firewall policy, privileged access, SFTP configuration, logging, alert response, backups, restore tests, incident notification, and secure data deletion. A written division of duties makes the environment easier to operate and audit.

## How Atlantic.Net Fits the Client’s Requirements

Atlantic.Net offers standard HIPAA plans and custom configurations. The current HIPAA Developer Linux plan is a useful starting point for a client’s workload with four or more cores and 16 GB of memory.

| **Requirement** | **Atlantic.Net Starting Point** | **Detail to Confirm** |
| --- | --- | --- |
| **Linux** | HIPAA Developer supports Linux | Distribution, version, runtime, packages, and update path |
| **4+ cores** | 6 vCPU | Sustained CPU usage and database demand |
| **16 GB RAM** | 16 GB RAM | Peak usage and expected growth |
| **300 GB storage** | 200 GB SSD in the standard plan | Custom capacity, backup space, and growth allowance |
| **About five sites** | Five-account cPanel license is listed | Domain layout, account isolation, and control panel requirements |
| **Restricted SFTP** | Can be configured during the server build | User directories, key policy, permissions, logging, and test cases |
| **Encryption at rest** | Encrypted storage is a published HIPAA feature | Storage, backup, and key management scope in the proposal |
| **No hosted email** | Email can remain outside the hosting scope | Application relay, notifications, and ePHI handling |
| **Managed operations** | Firewall, server management, scans, VPN, MFA, and backups are listed | Response, patching, monitoring, and recovery duties |

The standard plan’s 200 GB storage allocation fell short of the client’s desired 300 GB requirement. Atlantic.Net’s HIPAA Custom option supported extended VM sizes, so the solutions team was able to quote the required capacity once current use, backup volume, and projected growth had been measured.

## Security And Operations In One Service

A managed HIPAA environment needs ongoing operational work after the initial server build. Atlantic.Net’s managed service packages include server management, scheduled vulnerability scans, a managed firewall, multi-factor authentication, managed VPN accounts, and daily onsite and offsite backups.

The Developer tier features a managed FortiGate firewall, and the Business and Custom tiers add explicit intrusion prevention system options. If IPS is part of the security requirement, we’ve got you covered!

Customers can also review Atlantic.Net’s[wider compliance program](https://www.atlantic.net/compliance-hosting/), including our published alignment with standards such as NIST SP 800-53. Our compliance services support vendor due diligence, while the signed order and responsibility matrix define the controls delivered for the individual environment.

For day-to-day operations, Atlantic.Net provides 24/7 support by phone and email, especially useful during a migration, a security review, or an out-of-hours production issue.

## A Practical Migration Path

Atlantic.Net includes 4 hours of migration service with our HIPAA packages. A well-planned move begins with an inventory of the current application and ends after the new environment has passed technical and recovery testing.

Customers should give the solutions team a record of the sites, databases, runtimes, extensions, certificates, scheduled jobs, DNS records, SFTP users, external services, and IP allowlists. Map where ePHI is stored, transmitted, backed up, and logged, so that every relevant system stays within the approved design.

Before cutover, clients work with our engineering team to:

1. Build the destination in accordance with the signed BAA and the agreed security design.
2. Configure the firewall, named administrative accounts, restricted SFTP users, multi-factor authentication, logging, monitoring, and backups.
3. Copy and validate the sites and data, then test database transactions, scheduled tasks, uploads, certificates, external APIs, and notifications.
4. Run a restore test to confirm that the application and its data can be recovered within the agreed target.
5. Plan the DNS change, validation window, rollback trigger, and final data synchronization.

This process gives the customer and Atlantic.Net a shared view of the work, the acceptance tests, and the operating model that will apply after launch.

## Moving Forward With Atlantic.Net

LuxSci holds a respected position in secure healthcare communications, and customers may have had positive experiences with its services. Choosing Atlantic.Net as an alternative is a decision about the needs of the next hosting environment and the level of infrastructure management the organization wants.

Atlantic.Net brings together audited HIPAA hosting, a standard BAA, flexible cloud and dedicated infrastructure, managed security services, daily backups, migration assistance, and 24/7 support for organizations seeking a closely managed home for healthcare applications, making Atlantic.Net a compelling provider to consider in 2026.

Our first conversation usually covers the application footprint, ePHI flow, resource measurements, access model, recovery targets, audit needs, and operational responsibilities. We use that information to recommend a suitable HIPAA tier and prepare a clear proposal for the migration and ongoing service.

Share your current server inventory and growth requirements with the[Atlantic.Net solutions team](https://www.atlantic.net/about-us/corporate-contact/). We can help map the workload to a managed HIPAA environment and plan the move before any ePHI is transferred.


---

# How to Prepare for Black Friday 2026 with PCI-Compliant Hosting

> URL: https://www.atlantic.net/pci-compliant-hosting/black-friday-pci-compliant-hosting/ | Published: 2026-09-04 | Author: Richard Bailey

Black Friday concentrates a large volume of online spending into a short window. Adobe Analytics reported[$11.8 billion in US online sales on Black Friday 2025](https://news.adobe.com/news/2026/01/adobe-holiday-shopping-season), up 9.1% year over year. Each retailer experiences demand differently, but the infrastructure question remains consistent: can the complete checkout path continue processing legitimate orders when traffic, database workload, fraud screening, and logging all rise together?

Payment security has to hold up under the same conditions. A storefront can remain visible while its checkout API, session store, payment gateway connection, or audit-log pipeline is struggling. Even partial failure can result in abandoned carts, failed and repeated payment attempts, missing evidence, or a hurried failover into an environment with different controls.

For Black Friday 2026, capacity testing and Payment Card Industry Data Security Standard (PCI DSS) testing should be combined into a single readiness exercise. The goal is a payment path that stays responsive while its segmentation, access controls, monitoring, and evidence remain intact.

## Why Black Friday Readiness And PCI DSS Matters

PCI DSS applies to entities that store, process, or transmit cardholder data, as well as systems that could affect the security of the cardholder data environment (CDE). The[PCI Security Standards Council’s scope definition](https://www.pcisecuritystandards.org/standards/pci-dss/) means the review may extend beyond the checkout server. Load balancers, identity services, administrative systems, logging platforms, and connected infrastructure can also be in scope, depending on the architecture and connectivity.

The current standard is PCI DSS v4.0.1. PCI SSC published v4.0.1 in June 2024 and[retired v4.0 on 31 December 2024](https://blog.pcisecuritystandards.org/just-published-pci-dss-v4-0-1). PCI DSS v3.2.1 had already been retired on 31 March 2024. The future-dated v4.x requirements became effective on 31 March 2025.

Current assessments need to account for requirements such as stronger payment-page script controls, change detection, multi-factor authentication for access to the CDE, and more formal log review processes.

## What A Traffic Spike Exposes In The Payment Cycle

Checkout depends on more than the web page a customer sees. A typical request will touch the storefront application, session storage, inventory, tax and shipping services, a payment processor, fraud screening, a database, and several logging destinations in between. Peak load can expose the slowest dependency in that chain.

A timeout can prompt a customer to retry. The application and payment must ensure those retries are safe through idempotency controls, a clear transaction state, and reconciliation. Monitoring should distinguish a slow gateway from a failed application request, while the audit trail needs enough detail to reconstruct what occurred.

Load testing should exercise the real payment journey in a safe test environment. Test login, cart updates, checkout, payment authorization, declined cards, retries, refunds, and downstream dependency failures. Measure response time and error rate, then confirm that logs arrive complete, clocks remain synchronized, alerts fire, and support teams can trace a transaction across systems.

The test also needs an agreed stopping point. If error rates or queue depth cross a threshold, the platform team should know which traffic to shed, which features to disable, and when to invoke failover. Documenting such decisions before the sale reduces the risk that an emergency change weakens the CDE.

## How Fraud And Automated Abuse Change Capacity Planning

Legitimate shoppers are only part of the Black Friday workload. Automated card testing, credential stuffing, scraping, and application-layer denial-of-service traffic can consume the same checkout resources.

[Stripe describes card testing](https://docs.stripe.com/disputes/prevention/card-testing?locale=en-GB) as the automated validation of large quantities of stolen card details. Recommended controls include rate limits, session validation, CAPTCHA triggers where appropriate, and continuous monitoring for unusual behavior. Credential stuffing uses username and password pairs stolen from another service. The[OWASP prevention guidance](https://cheatsheetseries.owasp.org/cheatsheets/Credential_Stuffing_Prevention_Cheat_Sheet.html) recommends layered controls because attackers can distribute requests across many addresses and bypass simple per-IP limits.

Payment-page integrity also deserves a separate check. PCI DSS v4.x Requirements 6.4.3 and 11.6.1 address authorization, integrity, inventory, and tamper detection for scripts and security-impacting headers on payment pages. PCI SSC’s[payment-page security guidance](https://blog.pcisecuritystandards.org/new-information-supplement-payment-page-security-and-preventing-e-skimming) explains how these controls reduce the risk of e-skimming in the customer’s browser.

A web application firewall (WAF), intrusion detection and prevention, rate limiting, and distributed denial-of-service protection can filter hostile traffic before it consumes application capacity. The application still needs secure authentication, payment controls, script governance, and fraud rules. These layers work together, and each one should generate telemetry that an operations team can monitor during Black Friday.

## What PCI-Compliant Hosting Covers

PCI-compliant hosting supplies documented infrastructure controls for a defined environment. Depending on the service and contract, controls typically include data center security, network segmentation, managed firewalls, encrypted storage and backups, administrative access controls, vulnerability scanning, monitoring, and audit evidence.

The merchant retains responsibility for its side of the shared model, normally the application code, plugins and dependencies, payment-page scripts, user access, data flows, retention, incident procedures, and the correct Self-Assessment Questionnaire (SAQ) or assessor-led validation. The merchant or its Qualified Security Assessor (QSA) also determines scope for the actual deployment.

Ask a provider to map every supplied control to the service description and evidence available to your assessor. An audited platform can reduce the amount of infrastructure a merchant needs to build and operate, but hosting alone does not automatically make the merchant compliant.

## How To Add Capacity Without Losing Control Of Scope

Start with measurements from the current checkout path. Record sustained and burst request rates, database latency, queue depth, payment-processor response time, log volume, and resource saturation. Use those results to agree on the test load profile.

Keep product browsing, images, and cacheable content away from the payment environment where the architecture permits. A content delivery network and separate storefront tier can absorb public traffic while the segmented checkout tier handles only payment-related requests. Confirm the boundary through data-flow diagrams, firewall rules, and segmentation testing.

When adding nodes, keep configuration and controls consistent. New checkout capacity should inherit hardened images, access policies, logging, vulnerability management, and monitoring. Confirm with the QSA how cloud scaling, standby systems, and failover affect scope. A new node does not become out of scope simply because it was created for a temporary sales event.

Recovery capacity needs the same attention. Test backup restoration, database recovery, DNS changes, and the failover path before a production change freeze. Confirm that recovery systems produce the same security logs and use the same administrative controls as the primary environment.

## How Atlantic.Net Supports Peak-Season Payments

[Atlantic.Net’s PCI-compliant hosting](https://www.atlantic.net/pci-compliant-hosting/) combines managed infrastructure with controls to support a PCI DSS assessment. Features include managed FortiGate firewalls with intrusion prevention, multi-factor authentication, encrypted VPN access, disk encryption, scheduled vulnerability scanning, onsite and offsite backups, disaster recovery, and 24/7/365 US-based support. Atlantic.Net has operated since 1994 and has more than 32 years of hosting experience.

PCI DR Hosting plans start with 6 vCPUs, 16 GB RAM, 200 GB storage, and 10 TB of data transfer. Linux pricing starts at $973.27 per month and Windows at $1,026.62 per month, based on a 12-month term. A standard DR plan includes Network Edge Protection and load balancing as add-ons. Further custom options include WAF, content delivery network, distributed denial-of-service protection, and load balancing, with sizing and pricing supplied by quote.

Retailers can combine the PCI-ready managed environment with Atlantic.Net cloud, dedicated, bare metal, or hybrid infrastructure. Atlantic.Net’s[e-commerce hosting options](https://www.atlantic.net/e-commerce-hosting-for-secure/) cover high-traffic storefronts and payment-adjacent services, while[Network Edge Protection](https://www.atlantic.net/managed-services/network-edge-protection/) adds WAF, content delivery, and denial-of-service filtering where required.

## Black Friday 2026 Compliance And Capacity Checklist

- **Confirm the standard and validation route.** Use PCI DSS v4.0.1, identify the applicable SAQ or Report on Compliance, and involve the acquirer, payment brand, or QSA when eligibility or scope is unclear.
- **Map the payment path.** Document cardholder-data flows, connected systems, third-party scripts, administrative access, logs, backup systems, and failover components.
- **Test realistic transactions.** Exercise successful payments, declines, retries, refunds, fraud checks, and dependency failures at the load profile supported by your own measurements.
- **Protect evidence under load.** Verify log completeness, time synchronization, alert delivery, retention, and the team’s ability to trace a transaction from the storefront to the payment processor.
- **Review automated-abuse controls.** Test WAF rules, card-testing rate limits, credential-stuffing defenses, bot signals, and escalation procedures without blocking a large share of genuine customers.
- **Check payment-page scripts.** Maintain an authorized inventory, verify integrity controls, and confirm that tamper detection covers scripts and relevant HTTP headers.
- **Prove segmentation and recovery.** Test network boundaries, restore backups, exercise failover, and confirm that recovery systems retain the primary environment’s controls.
- **Freeze with an exception process.** Set a production change freeze before the sale and define who can approve an emergency change, how it will be tested, and how evidence will be retained.

## Plan The Review Before Traffic Arrives

Black Friday readiness is strongest when performance, payment security, fraud controls, and recovery are tested against the same architecture. The result should be a measured capacity plan, a current PCI DSS v4.0.1 control set, and a runbook the operations team can follow under pressure.

Our first discussion with a retailer usually starts with the current checkout architecture, measured demand, payment-data flow, assessment route, recovery targets, and support model. We use that information to scope an environment and identify which controls Atlantic.Net manages and which remain with the retailer.

Contact the[Atlantic.Net solutions team](https://www.atlantic.net/about-us/corporate-contact/) to review your Black Friday 2026 payment infrastructure and build a capacity and compliance plan before the production freeze.


---

# AI Infrastructure Hosting: Complete Guide for AI Workloads

> URL: https://www.atlantic.net/gpu-server-hosting/ai-infrastructure-hosting-guide/ | Published: 2026-09-04 | Author: Hitesh Jethva

AI infrastructure hosting provides the computing power, data storage, networking, security controls, and software layers needed to build, train, fine-tune, deploy, and manage AI models. Your infrastructure choices affect model training speed, inference latency, data privacy, scalability, and cost.

This guide is for AI researchers, data scientists, developers, infrastructure teams, technical leaders, and businesses planning AI projects. You will learn how to choose between cloud hosting, private cloud, dedicated infrastructure, hybrid infrastructure, and edge environments. You will also learn how to match GPUs, storage, networking, security, and orchestration to your AI workloads.

## What Is AI Infrastructure Hosting?

AI infrastructure hosting combines specialized hardware, software, storage, networking, and data center resources for artificial intelligence and machine learning workloads. You use this infrastructure for model training, fine-tuning, inference, data processing, AI agents, computer vision, natural language processing, and other AI applications.

### Core Compute Components

Your compute layer usually includes GPUs, CPUs, and sometimes TPUs. GPUs and TPUs process many calculations in parallel, which is well-suited to deep learning and large language models. CPUs remain important for preprocessing, data movement, application logic, orchestration, databases, and supporting services. Google Cloud currently offers GPU and TPU infrastructure for machine learning, generative AI, data processing, and high-performance computing workloads.

Your required computational resources depend on model size, precision, batch size, dataset size, and workload type. Small AI development jobs often need less specialized hardware than training large language models across several GPU servers.

### Core Storage Components

Your storage layer needs sufficient capacity and throughput to supply compute resources with data. Local NVMe storage is well-suited for active training data, caches, temporary files, and checkpoints. Distributed storage is well-suited to large datasets shared across several compute nodes. Object storage works well for datasets, model artifacts, backups, and long-term data retention.

### Core Network Components

Your network connects GPU servers, storage systems, applications, users, and services. High-speed networking matters for distributed training because several nodes exchange model data throughout each training step.

Common AI workloads include large language models, recommendation systems, AI agents, image generation, speech processing, computer vision, anomaly detection, predictive analytics, retrieval systems, and custom models.

## Why AI Infrastructure Is Important For Artificial Intelligence

The right AI infrastructure keeps compute, memory, storage, and networking aligned with your workload. Traditional IT infrastructure often lacks the accelerator density, memory bandwidth, storage throughput, and network capacity required by large AI systems.

### Performance Requirements

Training models places sustained demand on computational resources. Large models also place heavy pressure on GPU memory and data movement. High-performance GPU clusters work best when storage and networking keep pace with accelerator processing.

A storage bottleneck leaves GPUs waiting for data. A slow network increases communication time during distributed model training. Your design needs balanced resources rather than one high-specification component.

### Data Sovereignty And Compliance

Your data sovereignty requirements affect where you store datasets, logs, model artifacts, backups, and recovery copies. A private environment often fits projects where sensitive data needs strict location or access controls.

Your security and compliance plan should align with applicable requirements, such as GDPR or HIPAA. SOC 2 reports also help you evaluate service-provider controls. For HIPAA-regulated workloads, HHS requires appropriate administrative, physical, and technical safeguards for electronic protected health information.

### Scalability

Your AI infrastructure should grow with model sizes, large datasets, inference traffic, and new AI workflows. Cloud infrastructure offers on-demand resource scaling, while dedicated infrastructure often suits steady workloads requiring consistent performance.

## Types Of Cloud Hosting And Cloud Infrastructure For AI

Your workload pattern, data sensitivity, scaling needs, and operations team should determine your AI hosting model.

| Hosting Type | Best For | Control | Scalability | Main Limitation |
| --- | --- | --- | --- | --- |
| Public cloud | Experiments, temporary training, variable workloads | Medium | High | Variable spending |
| Private cloud | Sensitive data, regulated workloads, stable usage | High | Medium | More administration |
| Hybrid infrastructure | Mixed cloud and private workloads | High | High | More complex architecture |
| Edge hosting | Local and real-time inference | High | Limited | Restricted local resources |

### Public Cloud Hosting

Public cloud hosting works well for experiments, variable model training, temporary GPU workloads, and teams seeking access to newer specialized hardware without physical purchases.

You gain access to GPU instances, storage, managed AI services, and development platforms. Google Cloud, for example, offers GPU infrastructure and Vertex AI for training and deploying machine learning models and AI applications.

Cloud-based AI infrastructure also gives you flexibility in managing compute costs because you select different resource types for different jobs.

### Private Cloud Hosting

A private cloud gives you more control over hardware, data storage, network policies, software versions, and user access. Private infrastructure often suits regulated industries, sensitive data, stable GPU demand, and production environments subject to strict regulations.

You also take on more responsibility for maintenance, orchestration, monitoring, security, capacity planning, and hardware lifecycle management.

### Hybrid Infrastructure

Hybrid infrastructure combines private and cloud resources. You might keep sensitive datasets in a private environment while running approved model training jobs on external GPU cloud resources.

Another option involves developing and training models in cloud infrastructure, then moving inference to dedicated or private infrastructure.

### Edge Hosting

Edge hosting places inference close to local devices or data sources. Computer vision near cameras, factory systems, retail devices, and other low-latency applications often fit this model.

Your edge design requires careful model sizing, as local devices typically have fewer computational resources than centralized data centers.

## AI Platform And AI Services: Managed Vs Self-Hosted

Managed AI services reduce infrastructure administration, while a self-hosted AI platform gives you more control over hardware, data, software, and operating policies. Your workload requirements should drive the choice.

### Managed AI Services

Managed AI services provide compute, notebooks, model training, endpoints, storage connections, monitoring, and other AI services through a managed platform. Your provider handles much of the underlying hardware and network management.

This model fits your team when fast setup, variable demand, and limited infrastructure staffing matter most.

### Self-Hosted AI Platform

A self-hosted AI platform runs on infrastructure under your control. You choose GPU servers, storage, networking, AI frameworks, orchestration tools, security controls, and monitoring systems.

This approach often fits custom models, dedicated infrastructure, sensitive data, predictable workload demand, or software requirements outside a managed service.

Before migration, document your current AI workflows, dependencies, dataset volumes, GPU use, network requirements, data retention rules, security controls, backup plans, recovery objectives, and monitoring requirements. Run a proof of concept before moving production environments.

## Designing AI Infrastructure For AI Workloads And AI ML

You should design AI infrastructure from the workload backward. Your model type, dataset size, GPU memory needs, latency target, and production traffic should determine your compute, storage, networking, and orchestration choices.

### Assess Your AI Workloads And Datasets

Separate experimentation, model training, fine-tuning, batch inference, real-time inference, AI agents, and data processing. Each workload demands different levels of processing power and memory.

Next, estimate dataset size and movement. Large datasets require high throughput between data storage and compute. Track how much information moves during preprocessing, training, checkpoint creation, and inference.

### Choose The GPU Class

Match GPU class to model scale, memory requirements, precision, and workload duration. RTX-class hardware suits many development, prototyping, and smaller fine-tuning workloads. Data-center GPUs such as the NVIDIA A100 and H100 are well-suited to larger AI/ML workloads with higher memory and throughput requirements.

### Plan Your Cluster And Orchestration

Plan cluster growth before demand increases. Define how you add GPU servers, storage capacity, and network bandwidth.

Containerization helps you standardize AI development and production environments. Kubernetes supports GPU scheduling through device plugins and resource allocation mechanisms, enabling you to assign specialized hardware across clustered workloads.

### Monitor Infrastructure And Model Services

Track GPU utilization, GPU memory, CPU use, RAM, storage throughput, storage latency, network throughput, job queue time, model training duration, inference latency, request volume, and error rate.

Your observability plan should also cover application logs, model endpoints, retrieval services, AI agents, and supporting databases.

### Plan Backup And Disaster Recovery

Protect datasets, model checkpoints, experiment records, configurations, secrets, and deployment definitions.

Define your recovery point objective and recovery time objective. Keep recovery copies outside the main failure domain and test restoration procedures before relying on your backup strategy.

## GPU Choices For AI ML Workloads

Your GPU choice affects model capacity, training speed, inference throughput, and AI hosting cost. Select hardware based on measured workload requirements rather than defaulting to the highest GPU class.

### RTX Gpus

RTX-class GPUs suit AI researchers, developers, and data scientists running prototypes, smaller models, local development, inference tests, and selected fine-tuning workloads.

They often provide an economical starting point when your workload fits available GPU memory and does not require large multi-node clusters.

### Nvidia A100

NVIDIA A100 remains suitable for data-center AI, large model training, inference, analytics, and high-performance computing. NVIDIA offers A100 configurations that support several numerical precision formats and Multi-Instance GPU functionality to divide GPU resources across workloads.

A100 infrastructure fits established training workflows where your model and software stack already target Ampere-based GPU systems.

### Nvidia H100

NVIDIA H100 targets demanding transformer workloads, training large language models, high-throughput inference, and large-scale AI systems. H100 adds FP8 Tensor Core support via the Hopper architecture, with features optimized for AI training and inference.

Your decision between RTX, A100, and H100 should focus on GPU memory, precision, model architecture, training duration, concurrency, network design, and total job cost.

## Storage And Networking For AI Workloads

Fast storage and low-latency networking keep your GPU resources supplied with data. Slow data movement reduces effective performance, even when your GPU servers deliver high processing power.

### High-Throughput Distributed Storage

Use distributed storage when several training nodes need access to the same large datasets. Measure real read and write throughput with your target files and access patterns.

Object storage is well-suited for model artifacts, datasets, archives, and backups. Local NVMe is well-suited for active training data, caches, checkpoints, and temporary processing.

### Low-Latency Networking

Distributed training needs high bandwidth and low latency between GPU nodes. Network delays increase synchronization time across large clusters.

Design separate paths for management and heavy data traffic when your architecture requires stronger performance isolation.

## AI Development Environments And AI Model Training

Your AI development environment should give your team consistent access to notebooks, machine learning frameworks, datasets, GPU drivers, and experiment records. Standard environments reduce configuration differences between researchers and production teams.

### Managed Jupyter Notebook Hosting

Managed Jupyter notebook hosting suits centralized AI development. JupyterHub provides multi-user notebook environments and shared computational resources for researchers and data scientists.

Include PyTorch, TensorFlow, Hugging Face tooling, required CUDA libraries, version control, approved data access, and secrets management based on your AI projects. TensorFlow remains an end-to-end machine learning platform, while Hugging Face provides tooling for transformer model training and fine-tuning.

### Fine-Tuning Workflow

Start fine-tuning with a selected base model and validated dataset. Define training objectives, evaluation metrics, checkpoint intervals, and hardware requirements. Run a smaller validation job before scaling training.

Track model version, dataset version, hyperparameters, GPU configuration, training duration, checkpoints, and evaluation results. TensorBoard supports experiment metrics and visualization. MLflow also provides experiment tracking and model lifecycle tooling.

## Deployment, Inference, and AI Model Hosting

Your inference infrastructure should match request volume, latency targets, and workload consistency. Real-time services require low-latency endpoints, whereas batch workloads prioritize throughput and resource utilization.

### Low Latency Inference

Keep frequently used models loaded in GPU memory where your latency requirements justify dedicated resources. Monitor p50, p95, and p99 latency alongside throughput, request rate, GPU memory, and errors.

### Serverless Or Dedicated Hosts

Serverless inference is well-suited to bursty workloads with long idle periods. Dedicated hosts are well-suited for stable traffic, large models, or production environments where consistent throughput matters.

Your autoscaling policy should respond to useful workload signals such as queue depth, request rate, latency, GPU utilization, and memory pressure. Define minimum capacity for latency-sensitive AI applications and maximum capacity for cost control.

## Security, Compliance, and Data Privacy For AI Infrastructure Hosting

Secure AI infrastructure requires controls across data, identities, networks, models, storage, and backups. Your provider’s certification forms only one part of your security and compliance responsibilities.

Encrypt sensitive data at rest across storage volumes, databases, backups, and object storage. Encrypt data in transit between users, services, GPU nodes, and storage.

Use role-based access control to limit permissions. Add multi-factor authentication for privileged access. Review API keys, service accounts, credentials, and administrative roles on a defined schedule.

For regulated workloads, validate the provider’s compliance documentation against your own scope. HIPAA, GDPR, and SOC 2 address different requirements and assurance needs. HHS guidance emphasizes safeguards for electronic protected health information and appropriate protection of ePHI in transit and at rest.

Document where primary data, replicas, logs, backups, and disaster recovery copies reside. This record supports your data residency and data sovereignty requirements.

## Cost Strategies For AI Hosting

AI hosting costs depend on GPU class, runtime, utilization, storage, networking, and purchasing model. You should measure cost per training run or inference workload rather than comparing GPU prices alone.

### Use Interruptible Capacity For Suitable Jobs

Spot instances work well for restartable training, batch processing, hyperparameter jobs, and experiments with reliable checkpointing. Google Cloud currently offers Spot VMs at discounted rates, with the risk of interruption when capacity needs change. Preemptible VMs follow a similar model with defined operating limits.

Use these resources only where your AI workflows tolerate interruption.

### Use Mixed Precision Where Appropriate

Mixed-precision training reduces memory requirements and improves training performance for supported models and hardware. Current PyTorch automatic mixed-precision tools support mixed-data-type execution in training workflows.

Right-size GPU allocations for each job. Shut down idle development systems and notebooks. Track GPU utilization, idle time, training duration, checkpoint overhead, and cost per inference request.

## Choosing A Provider Or Building A Private AI Cloud

Your provider decision should focus on GPU inventory, availability, pricing, support, security, and workload fit. A private AI cloud gives you more control, while hosted infrastructure shifts more hardware operations to the service provider.

### Evaluate GPU Inventory And Availability

Confirm exact GPU models, GPU memory, server design, storage options, network capacity, and regional availability.

Ask how quickly your provider adds capacity when your AI ambitions expand. A listed GPU option does not help your project when capacity is unavailable during deployment.

### Request Clear Commercial Terms

Request pricing for GPU resources, CPU, RAM, data storage, backups, network traffic, support, and longer commitments. Ask whether custom pricing applies to larger or sustained deployments.

Run a proof-of-concept training job before a long commitment. Measure startup time, GPU utilization, storage throughput, network performance, model training duration, inference latency, and support quality.

### Where Atlantic.Net Fits

Atlantic.Net offers GPU cloud and dedicated GPU server hosting for AI, machine learning, deep learning, and high-performance computing workloads. Its current dedicated GPU offering lists NVIDIA L40S and H100 NVL configurations, along with NVMe storage and high-bandwidth networking.

Atlantic.Net also publishes compliance hosting options that cover HIPAA, HITECH, SOC 2, SOC 3, PCI DSS, and GDPR-related requirements across its supported services. You should confirm the exact scope of services, audit documentation, data center location, contractual terms, and customer responsibilities before selecting a regulated environment.

If you build a private AI cloud instead, compare hardware purchases, rack space, power, cooling, networking, spare capacity, support staffing, replacement cycles, orchestration, security, and disaster recovery against hosted options.

## FAQs

**Do I Need My Own GPU?**

No. Your hosting options include GPU cloud services, dedicated GPU servers, managed AI services, and private infrastructure.

Owning physical GPU hardware makes more sense when you have stable demand, internal operations, strict data requirements, or long-term workloads with predictable resource use. Hosted GPU servers suit teams seeking specialized hardware without having to manage physical purchases or data center operations.

**What Should You Prepare For Your First Deployment?**

Use this onboarding checklist:

1. Define your model and AI workload.
2. Estimate dataset size and GPU memory needs.
3. Set storage throughput and network requirements.
4. Define training or inference performance targets.
5. Document data privacy, compliance, and data residency requirements.
6. Set access controls, backups, monitoring, and recovery targets.
7. Run one proof-of-concept workload.
8. Measure performance and cost before production.

**Where Should You Go Next?**

Review migration guides for your chosen AI platform before moving production workloads. Document framework versions, model dependencies, storage paths, secrets, network rules, and rollback steps.

Review benchmark reports for the exact GPU, model, framework, precision, and workload you plan to run. A benchmark from a different model or server configuration gives you limited guidance.

Your right AI infrastructure should support your current AI workflows while leaving a clear path for larger datasets, new AI services, additional GPU instances, and growing production demand.


---

# Best Cloud Disaster Recovery Providers in 2026

> URL: https://www.atlantic.net/disaster-recovery/best-cloud-disaster-recovery-providers/ | Published: 2026-09-04 | Author: Robert Agar

A reliable disaster recovery (DR) solution is essential for modern businesses. Organizations must be prepared to recover from various data loss and outage scenarios, which are best addressed through disaster recovery strategies. DR services should be a foundational component of risk management to ensure companies can maintain business continuity in an emergency.

Many companies engage a cloud service provider (CSP) for disaster recovery services. Businesses that partner with a reliable CSP can gain advantages over on-premises disaster recovery solutions, including greater flexibility. This article looks at some of the best cloud disaster recovery services available to protect your business.

## What Is Disaster Recovery?

Disaster recovery refers to the methods and processes an organization uses to restore its IT infrastructure, systems, and data after an emergency. A complete disaster recovery plan includes procedures for data backups, acceptable restoration times for critical systems, and alternative communication options to enable users to access the recovered environment.

The following are key aspects of disaster recovery.

- **Backups:** Teams must have access to copies of all data necessary to restore the infrastructure components in scope for their disaster recovery solution. The backups should be stored separately from the production environment. Businesses should strongly consider improving failover processes with immutable backups that threat actors cannot corrupt.
- **Recovery Time Objective (RTO):** The RTO specifies how quickly systems must be restored and brought online. The backup system must be capable of meeting the RTOs to avoid excessive downtime.
- **Recovery Point Objective (RPO):** The RPO specifies the maximum amount of data loss the business can tolerate. Organizations must ensure that the backup frequency meets the RPO. Teams must implement frequent backups or continuous replication to meet aggressive RPOs.

## Why Do You Need Disaster Recovery Services?

Modern businesses need to protect themselves with reliable disaster recovery services for multiple reasons.

### Safeguard The IT Environment From Cyberattacks

An organization needs effective recovery strategies to withstand a ransomware attack or other type of cyberattack. Threat actors are constantly refining their techniques for delivering malware. Companies must be prepared to use DR services in the event of a successful attack.

### Natural Disasters

Natural disasters such as hurricanes or earthquakes can damage large geographic regions, making it impossible to access and recover a company’s physical servers. An organization must be prepared for these disaster scenarios with plans to recover systems in an alternate location. Cloud infrastructure can be instrumental in facilitating recovery when a natural disaster strikes.

### Flood Or Fire Damage

The IT environment can be destroyed by localized flooding or fires not caused by natural disasters. Businesses without a competent disaster recovery solution can experience extended downtime after an emergency that impacts their data center.

### Accidental Or Deliberate Data Loss

A complete disaster recovery plan can be instrumental in preventing data loss, whether intentional or unintentional. Companies must be able to recover from data loss caused by human error or external threat actors. In many cases, a subset of a complete DR solution is used to restore affected data resources.

### Maintain Business Continuity

Disaster recovery services are an essential component of a company’s business continuity plan. Companies that do not exercise disaster preparedness, or assess vulnerabilities and operational dependencies as part of business continuity planning, put their businesses at risk. Teams must recover critical IT systems and resources during the initial phases of a business continuity strategy to minimize downtime, maintain internal operations, and deliver customer service.

## Advantages Of Cloud Disaster Recovery Services

Organizations with on-premises data centers have two choices for disaster recovery solutions. They can maintain an alternate site with physical hardware capable of restoring data backups. This approach is expensive and requires a coordinated effort to get backups and technical personnel to the recovery site. Traditionally, this was the method used by large companies with extensive IT budgets.

The adoption of cloud environments for DR services enables small and medium-sized businesses (SMBs) and large organizations to modernize and streamline their disaster recovery operations. The following advantages of cloud disaster recovery solutions make them an excellent choice for businesses of any size.

- **Cost-effectiveness:** CSPs provide their customers with the hardware and disaster-recovery software needed to restore their IT environment on an as-needed basis. This eliminates the capital expenditures associated with traditional DR solutions.
- **Better RTOs and RPOs:** Customers can attain better RTOs and RPOs with cloud disaster recovery services. The CSP’s experience, combined with advanced automation, can streamline the recovery of critical databases and applications, minimizing operational disruption.
- **Geographic redundancy:** Cloud providers often operate multiple data centers across geographically diverse regions. Customers gain enhanced resilience by implementing their recovery strategies in advance, rather than when disaster strikes.
- **Scalability and flexibility:** Companies can reconfigure cloud environments to accommodate evolving workloads. CSPs can scale up DR solutions to meet increasing demands, and scale back so customers only pay for what they actually need.
- **Managed recovery:** Many small businesses lack staff with disaster recovery experience. The CSP’s technical team offers assistance that is instrumental to companies with limited technical capabilities.

## Essential Features Of A Cloud Disaster Recovery Solution

Companies that partner with a reliable CSP for disaster recovery services make a commitment that affects their business viability. Customers should look for the following essential features when evaluating prospective providers.

### Core Recovery Capabilities

- A provider should offer automated failover and failback to detect outages, support the rapid deployment of recovery resources during outages, and switch workloads to secondary resources.
- The CSP should perform near-continuous replication of critical data to avoid having to recover from stale backups.
- Customers must be able to define and meet low RTOs and RPOs to minimize downtime and maintain business operations.
- Teams must be able to perform granular recoveries that align with the scope of the disaster, whether that means restoring individual assets or broader systems.

### Security And Compliance Support

- Production and backup data must be encrypted in transit and at rest to stay compliant with regulatory standards.
- CSPs should provide immutable, resilient **backup systems** to protect against ransomware attacks that attempt to corrupt backups, rendering recovery impossible.
- Customers in regulated industries require audit reporting and logs of data access and recovery tests to demonstrate compliance, and **analysis** of configuration drift can help identify unauthorized changes over time.

### Infrastructure And Architecture

- The chosen providers should support multiple regions and cloud environments to mitigate regional outages.
- Backup solutions must preserve application states to rebuild the environment after an emergency.
- Customers should pay only for the recovery infrastructure when a disaster occurs. CSPs should spin up the necessary resources on demand rather than always maintaining a recovery environment.

### Operational Features

- Providers should offer clear and predictable pricing that includes the costs of steady-state replication and failover for recovery.
- Teams should be able to perform non-disruptive DR testing to identify gaps in their processes. Testing allows them to verify disaster recovery plans before they are needed to respond to an emergency.
- The provider should employ automated runbooks that execute predefined recovery procedures to enable rapid restoration of business-critical infrastructure and applications.
- The environment should have complete monitoring and alerting to ensure data is being replicated and is ready for recovery.

## Top Cloud Disaster Recovery Providers

The following are some of the best CSPs offering effective disaster recovery services to their customers. Companies should

![Atlantic.Net Logo](https://www.atlantic.net/wp-content/uploads/2024/05/atlantic-net-logo.png)

### [Atlantic.Net](https://www.atlantic.net/)

Atlantic Net has been providing cloud infrastructure and disaster recovery services for over 30 years. One of their specialties is supporting the stringent data protection, availability, and [disaster recovery requirements](https://www.atlantic.net/disaster-recovery/) of HIPAA-compliant environments. Their outstanding features include multiple backup frequency tiers to meet customers’ RPO requirements and reliable monitoring tools.

Atlantic Net’s teams of DR experts offer managed disaster recovery designed to recover applications and data within a pre-agreed service-level agreement. The company’s experience with regulated industries enables it to provide all its customers with excellent DR solutions.

Advantages:

- Eight geographically diverse data centers for offsite storage and enhanced resilience
- Audit-ready SOC 2 Type II and SOC 3 Type II data centers
- 100% uptime SLAs
- Supports Windows and Linux environments

Disadvantages:

- Disaster recovery services may require an additional service agreement or add-on, depending on the customer’s configuration and requirements.

![](https://www.atlantic.net/wp-content/uploads/2025/04/wix-logo.png)

### Wix

WIX is a popular website hosting platform that provides automatic disaster recovery to maintain site availability in the event of a system disruption. Customers can expect 99.99% uptime and can choose from a variety of plans to fit their business needs. The company runs websites on Google Cloud, AWS, and Fastly, and automatically reroutes traffic if a platform fails. It is a good solution for protecting a website.

Advantages:

- 24/7 real-time monitoring
- Automated disaster recovery protocols
- Enterprise-grade data encryption

Disadvantages:

- Customers cannot direct websites to specific servers
- Only supports websites and web-based applications

![](https://www.atlantic.net/wp-content/uploads/2025/12/kamatera-logo-1.png)

### Kamatera

Kamatera provides disaster recovery services designed to prevent data loss and minimize downtime. They have data centers in North America, Europe, Asia, and Australia, allowing customers to minimize operational latency and recover in a safe geographic region. Kamatera supports Windows and a wide range of Linux distributions. The company’s Server Recovery Option (SRO) add-on solution addresses outages by seamlessly bypassing the original production system through electronic switching and replacing it with a backup machine.

Advantages:

- 24/7 real-time data replication
- Instant failover mechanism
- Continuous server monitoring

Disadvantages:

- Server cloud backups incur an additional monthly charge
- Payment must be made by credit card or PayPal deposit

### Azure Site Recovery

Azure, Microsoft’s cloud platform, offers customers dedicated disaster recovery services through Azure Site Recovery. It reduces costs by eliminating the need for on-premises disaster recovery infrastructure. Customers only pay for compute resources when running applications in the recovery region. While Azure focuses on Windows solutions, its disaster recovery solutions support most applications running on virtual machines or physical servers.

Advantages:

- Users can recover almost any IT environment to the Azure platform
- Customizable and automated recovery plans
- Over 400 secure data centers in over 70 regions

Disadvantages:

- Pricing can be unpredictable with variable charges for some services
- The Azure ASR tool can present teams with a steep learning curve

![](https://www.atlantic.net/wp-content/uploads/2026/07/DigitalOcean_logo.png)

### DigitalOcean

DigitalOcean targets customers in the startup, developer, and small-business segments. They offer managed PostgreSQL and MySQL databases that streamline the creation of effective recovery solutions. Replica promotion reduces downtime by enabling customers to a replica to their primary database node quickly.

Advantages:

- Read-only database nodes to ensure data is always available
- Automated backups with point-in-time recovery
- Smooth replication across regions

Disadvantages:

- Backups stored in the same regions as production servers
- Cross-region failover may require extensive manual configuration

## Final Thoughts On Cloud Disaster Recovery Services

Organizations should strongly consider cloud disaster recovery services as an essential component of a business continuity strategy. A cloud disaster recovery solution provides a cost-effective way to protect an IT environment when disaster strikes. The companies discussed above all offer the security and resilience of effective recovery in the event of an emergency.

Decision-makers must evaluate their disaster recovery needs to find the right provider. A reliable and reputable partner like Atlantic Net can be the difference between successfully working in a disaster and experiencing extended downtime, operational disruption, and loss of business. Companies that fail to develop a disaster recovery plan, including identifying a DR service provider, risk their business daily.


---

# Public vs Private vs Hybrid Cloud: Key Differences

> URL: https://www.atlantic.net/cloud-platform/public-vs-private-vs-hybrid-cloud/ | Published: 2026-09-04 | Author: Hitesh Jethva

The main difference between public, private, and hybrid cloud is how cloud infrastructure is allocated, controlled, and connected. A public cloud uses provider-operated infrastructure shared across customers. A private cloud provides infrastructure for the exclusive use of a single organization. A hybrid cloud connects private and public environments so applications, data, or computing resources can use both where appropriate.

There is no single right cloud model for every organization. Public cloud often suits variable demand and rapid deployment. Private cloud works well when dedicated resources and greater control matter. Hybrid cloud fits organizations that need different environments for different workloads.

## Public, Private, And Hybrid Cloud At A Glance

These three cloud computing models solve different infrastructure problems. The comparison below shows how each cloud deployment model typically differs.

| Factor | Public Cloud | Private Cloud | Hybrid Cloud |
| --- | --- | --- | --- |
| Infrastructure | Provider-operated, usually multi-tenant | Dedicated to one organization | Connects public and private resources |
| Initial investment | Usually lower | Usually higher | Depends on existing infrastructure |
| Scaling | Fast access to provider capacity | Limited by provisioned capacity | Can use public capacity when architecture allows |
| Infrastructure control | Moderate | Greater control | Varies by workload |
| Cost structure | Consumption or subscription-based | Dedicated capacity and operating costs | Combination of both |
| Management effort | Low to moderate | Higher | Often highest |
| Compliance fit | Depends on services, controls, and configuration | Supports tighter infrastructure control | Can separate workloads by requirement |
| Typical use | Variable demand, web apps, dev/test | Stable, dedicated, or specialized workloads | Mixed requirements and phased migrations |

The simplest way to compare public, private, and hybrid cloud is to focus on workload requirements rather than company size.

## Which Cloud Model Should You Choose?

Start your cloud strategy by evaluating the workload itself.

Choose public cloud when rapid provisioning, elastic capacity, low initial infrastructure investment, or access to managed cloud services matters most. Public cloud is often a practical choice for web applications, analytics, temporary workloads, and development and testing environments.

Choose private cloud when dedicated infrastructure, specialized configuration, predictable capacity, or stricter control over systems and data placement provides clear value.

A hybrid cloud strategy makes sense when different workloads have materially different requirements and the environments need to interact. Hybrid can also support gradual migration when moving everything at once would introduce unnecessary risk.

Business size alone should not decide the outcome. Instead, choose cloud environments based on security, cost, performance, compliance, scalability, operational skills, and application architecture.

## What Is Public Cloud?

Public cloud delivers cloud computing resources through infrastructure operated by a cloud service provider and made available to many customers.

Major public cloud providers include Microsoft Azure and Google Cloud Platform, often referred to as Google Cloud. These platforms operate large physical data centers and provide virtual machines, storage, databases, networking, analytics, and other computing services.

Customers access virtualized computing resources without owning the underlying servers. This reduces the need to purchase and maintain physical infrastructure before deploying applications.

One major advantage is elasticity. Organizations can add or remove public cloud resources as demand changes. A retailer, for example, can increase application capacity during a seasonal traffic spike and reduce it later.

Public cloud can also support global deployment because major cloud vendors operate infrastructure in multiple regions.

The trade-off is less direct control over the underlying infrastructure. Customers also need to manage usage carefully because compute, backups, databases, monitoring, support, storage, and network traffic can all contribute to monthly spending.

A public cloud is therefore often a strong option when flexibility and fast access to cloud resources matter more than direct control over hardware.

## What Is Private Cloud?

A private cloud provides cloud infrastructure exclusively for one organization.

Private cloud infrastructure may run in the company’s own data center, a colocation facility, or infrastructure operated by a third-party service provider. A private cloud may be hosted on-premises or externally. Its defining feature is organizational exclusivity rather than physical location.

Some organizations use a private data center because they already own substantial infrastructure. Others use hosted private cloud services when they want dedicated capacity without having to operate their own facility.

Private cloud can provide more control over networking, virtualization, storage, hardware configuration, security policies, and capacity planning. Organizations seeking maximum control over specific infrastructure choices may therefore consider private deployment.

That does not mean private cloud is automatically more secure, compliant, or economical. Those outcomes depend on architecture and operations.

Private cloud deployments also require planning. Capacity cannot always expand as quickly as public cloud capacity, and teams may need expertise in virtualization, networking, operating systems, data storage, backup, automation, monitoring, and security.

A dedicated cloud environment is most suitable when dedicated capacity and customization provide enough benefit to justify the added management responsibility.

## What Is Hybrid Cloud?

A hybrid cloud connects distinct computing environments, allowing an organization to use private and public resources as part of a coordinated architecture.

In simple terms, hybrid cloud combines different deployment environments. More specifically, hybrid cloud combines public cloud capabilities with private infrastructure when an application, workload, or business process needs both.

This distinction matters. Operating unrelated public and private cloud environments does not automatically produce a useful hybrid architecture. Effective hybrid cloud environments need networking, identity, security, management, or applications that support the intended flow of data and workloads.

A common hybrid cloud approach might keep a database or legacy application in a private environment while customer-facing application components run on public infrastructure.

Another hybrid cloud solution may support a phased migration. Existing systems remain private while newer applications move to public cloud over time.

Some hybrid cloud models also support cloud bursting, in which public capacity supplements private infrastructure during peak periods. This requires careful application design. Networking, identity, automation, licensing, state management, and data placement must all support the process.

Hybrid cloud offers flexibility, but that flexibility comes with greater operational complexity.

## Public Cloud Vs Private Cloud: What Are The Main Trade-Offs?

The public cloud vs private decision usually comes down to flexibility versus infrastructure control.

Public cloud infrastructure provides organizations with rapid access to capacity without requiring them to purchase servers upfront. It works well when demand fluctuates, applications need frequent changes, or teams want access to managed public cloud services.

A private cloud gives the organization greater control over infrastructure configuration and resource allocation. It can suit workloads with predictable demand or specialized technical requirements.

Comparing public cloud vs private cloud solely on monthly server cost gives an incomplete picture.

Public cloud costs can include compute, storage, backups, snapshots, databases, network transfer, observability, and support. Private cloud costs can include equipment, hosting, networking, software, administration, security, maintenance, replacement cycles, and spare capacity.

The better question is which model meets the workload requirements at an acceptable total cost.

## Private Cloud Vs Hybrid Cloud: When Does Each Fit?

The private cloud vs. hybrid decision depends on whether the workload benefits from a dedicated environment or requires additional cloud capacity.

Choose private cloud when workloads can run effectively within dedicated infrastructure and the organization values consistent capacity, customization, or direct control.

A private and hybrid cloud comparison changes when requirements vary between systems. Hybrid becomes more useful when some applications benefit from private infrastructure while others need public-cloud scale or managed services.

The vs hybrid cloud decision also depends on operational maturity. Hybrid introduces additional requirements for networking, monitoring, security, policy, and identity across different cloud environments.

Organizations should not adopt hybrid simply because it appears to combine the advantages of every model. A hybrid design is justified when the benefits of using multiple environments exceed the cost and management effort required to connect them.

## Which Cloud Model Provides Better Cost?

Cost depends on utilization, architecture, workload behavior, and operating costs.

Public cloud often has the lowest entry barrier because organizations can consume resources without first buying infrastructure. It can also be when demand changes frequently because capacity can increase and decrease with usage.

Stable workloads can yield different results. If a system runs at high utilization for years, private or dedicated infrastructure may become financially attractive.

A meaningful cost comparison should include more than compute.

For public cloud, consider storage, network traffic, managed services, backup, support, monitoring, idle capacity, and engineering time. For private cloud, include hardware or dedicated infrastructure, facilities, licensing, operations, security, support, refresh cycles, and disaster recovery.

Hybrid adds costs such as cross-environment monitoring, connectivity, identity, security tools, and operational coordination.

Cost should therefore be evaluated over the expected life of the workload rather than from the lowest advertised infrastructure price.

## Is Private Cloud Better For Sensitive Data?

A private cloud can provide stronger isolation and more direct control over infrastructure, but it is not inherently safer for sensitive data.

Security depends on architecture, identity management, encryption, patching, monitoring, logging, access controls, backups, incident response, and staff.

Public cloud can also support sensitive workloads when organizations use the right services, contractual terms, configurations, and security controls.

Some organizations prefer private cloud environments for specific regulated or mission-critical systems because they want dedicated hardware or greater control over infrastructure placement. Others use public cloud environments for regulated workloads while applying appropriate security and compliance controls.

A hybrid design can separate workloads when requirements differ. For example, mission-critical workloads may remain on dedicated infrastructure while less sensitive application components use public services.

Atlantic.Net is one provider offering public, private, dedicated, and hybrid hosting configurations. That range can support organizations that want to select infrastructure based on workload requirements rather than use a single deployment model everywhere.

The deployment model is only one part of security and compliance. Controls and operating practices remain essential.

## Does Hybrid Cloud Improve Network Flexibility?

Hybrid cloud can provide flexible workload placement, but connectivity becomes more important.

Applications running across hybrid cloud environments may communicate through dedicated links, virtual private networks, or other secure network connections. Routing application traffic directly over the public internet may not provide the security, performance, or predictability required for every workload.

Data movement also affects architecture.

If an application in the public cloud constantly transfers large datasets to systems within a private environment, latency, bandwidth constraints, transfer fees, and reliability issues can reduce the design’s value.

Tightly coupled application components should generally remain close enough to meet performance requirements. A hybrid architecture works best when separating components provides a clear business or technical benefit.

## How Does Vendor Lock-In Affect Cloud Strategy?

Vendor lock-in occurs when moving a workload to another platform becomes difficult, expensive, or disruptive.

The level of dependency depends more on architecture than on the deployment model itself.

Applications based largely on standard virtual machines, common database engines, containers, and portable software may be easier to move. Applications tightly integrated with provider-specific databases, identity tools, serverless runtimes, APIs, event services, or management products can be harder to migrate.

Private cloud can also create dependencies. Virtualization platforms, storage technologies, hardware configurations, licensing, and management systems can all restrict portability.

Organizations trying to avoid vendor lock-in should first identify which components genuinely need portability. Standard technologies, independent backups, documented dependencies, and tested exit procedures can reduce migration risk.

Containers and Kubernetes can help in some cases, but no cloud technology guarantees complete portability if critical parts of the application depend on proprietary services.

## How Do IaaS, PaaS, And SaaS Relate To Cloud Deployment?

A cloud deployment model and a cloud service model describe different parts of cloud computing.

Public, private, and hybrid describe how infrastructure is deployed and who can use it.

IaaS, PaaS, and SaaS describe what type of service the customer consumes and which responsibilities remain with the provider.

Infrastructure as a Service provides fundamental computing resources such as virtual machines, networking, and storage. Platform as a Service provides a managed cloud platform for deploying applications. Software as a Service delivers completed software applications to users.

These cloud computing models can exist across different deployment architectures.

Understanding the difference prevents a common mistake: directly comparing a deployment choice, such as private cloud, with a service type, such as SaaS. They answer separate questions.

## How Should You Plan A Cloud Migration?

A successful migration starts with workload discovery.

Map applications, dependencies, data flows, authentication, networking, storage, compliance obligations, downtime limits, backup processes, and recovery objectives before choosing a destination.

Large data sets deserve special attention. Moving data volumes between environments can affect migration time, network costs, and application availability.

Start with a workload that provides useful learning without creating excessive business risk. Development systems, internal applications, backup services, and stateless web applications are often practical candidates.

For hybrid migration, test connectivity between environments under realistic traffic. For private cloud migration, confirm that capacity planning accounts for sufficient room for growth and failures.

A rollback process is equally important. Keep the source environment available until applications, security controls, data integrity, networking, backups, and performance have been validated.

## How Does Cloud Management Differ Across Models?

Public cloud often reduces responsibility for physical infrastructure because the provider manages data centers, servers, network hardware, and other foundational systems.

Private cloud shifts more operational responsibility toward the organization or its managed infrastructure partner.

Hybrid usually introduces the most cloud management because teams must coordinate policies, visibility, identity, monitoring, networking, and security across multiple platforms.

Automation, infrastructure-as-code, centralized monitoring, and configuration management can help standardize operations across environments.

Internal skills therefore matter when selecting a model. The technically possible option is not always the operationally practical one.

## Final Recommendation: Match The Cloud Model To The Workload

There is no universal winner among public, private, and hybrid clouds.

The public cloud is often the strongest starting point for variable demand, rapid application deployment, managed services, and environments where purchasing physical infrastructure would incur unnecessary costs or delays.

Organizations should choose private cloud when dedicated infrastructure, specialized configurations, predictable capacity, or additional infrastructure control creates clear operational or business value.

Hybrid cloud makes sense when different workloads require different environments and those environments need to work together. A well-designed hybrid cloud can support gradual migration, workload separation, and selective use of public capacity.

The best computing model is therefore workload-specific.

Ask how predictable demand is, what data controls apply, where applications and data can reside, what latency is acceptable, what technical skills are available, and how much operational overhead the organization can support.

A successful cloud strategy does not force every workload into the same architecture. It matches cloud infrastructure to measurable security, cost, performance, scalability, and operational requirements.

## FAQ: Public Vs Private Vs Hybrid Cloud

**Is Hybrid Cloud Always Better Than Private Cloud?**

No. Hybrid cloud is useful when multiple environments provide a clear benefit. If a workload operates effectively in one dedicated environment, adding a hybrid may not add enough value to justify it.

**Can Public Cloud Support Sensitive Workloads?**

Yes, depending on the applicable requirements, services, contracts, architecture, and security controls. Sensitive data does not automatically require private infrastructure.

**Is A Private Cloud The Same As An On-Premises Data Center?**

No. A private cloud may run in an organization’s own data center, but a third party can also host it. Private cloud also includes cloud characteristics such as virtualization, resource pooling, automation, and controlled provisioning rather than simply referring to privately owned servers.

**What Is The Biggest Advantage Of Hybrid Cloud?**

Hybrid cloud lets organizations place different workloads in different environments when doing so provides a clear technical, security, performance, or business benefit. Its main trade-off is the additional effort required to integrate and manage those environments.

**Which Cloud Model Scales Fastest?**

Public cloud typically provides the fastest access to additional provider capacity. Private infrastructure can scale when capacity is available, while hybrid can use public resources for selected workloads if the architecture supports it.

**Can Hybrid Cloud Help With Disaster Recovery?**

Yes. A hybrid design can use separate environments as part of a disaster recovery architecture, but the deployment model alone does not create a recovery plan. Organizations still need replication, backups, recovery procedures, testing, and defined recovery objectives.

**How Can Organizations Reduce Vendor Lock-In?**

Use portable technologies where portability has business value, keep tested backups, document provider-specific dependencies, and create exit procedures for critical workloads. Avoiding all provider-specific services is rarely necessary; the goal is to understand and manage dependency risk.

**What Is The Main Difference Between Public And Private Cloud?**

Public cloud uses infrastructure operated for multiple customers, while private cloud infrastructure is reserved for one organization. The practical decision depends on cost, workload variability, infrastructure control, technical requirements, and operational responsibility.


---